From 533a73fdd1bf9988853f3eb1a23c3f28a87454b8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 5 Oct 2017 15:10:47 -0400 Subject: [PATCH 001/304] New upstream prerelease (1.16-beta1) --- .gitignore | 3 + Add-German-translation.patch | 9333 ----------------- Add-KDC-policy-pluggable-interface.patch | 994 -- Add-PKINIT-UPN-tests-to-t_pkinit.py.patch | 101 - ...IT-test-case-for-generic-client-cert.patch | 51 - Add-certauth-pluggable-interface.patch | 1146 -- Add-hostname-based-ccselect-module.patch | 293 - Add-k5test-expected_msg-expected_trace.patch | 96 - ...rt-to-query-the-SSF-of-a-GSS-context.patch | 419 - ...est-case-for-PKINIT-DH-renegotiation.patch | 45 - ...est-cert-generation-to-make-certs.sh.patch | 968 -- Add-test-cert-with-no-extensions.patch | 1120 -- Add-the-client_name-kdcpreauth-callback.patch | 58 - Add-timestamp-helper-functions.patch | 80 - Add-timestamp-tests.patch | 599 -- Add-y2038-documentation.patch | 59 - ...-Werror-implicit-int-where-supported.patch | 23 - ...me-pkiDebug-messages-to-TRACE-macros.patch | 422 - ...t-error-handling-bug-in-prior-commit.patch | 32 - Deindent-crypto_retrieve_X509_sans.patch | 263 - Fix-bugs-in-kdcpolicy-commit.patch | 130 - Fix-certauth-built-in-module-returns.patch | 124 - ...ck_skew-and-use-it-in-AS-client-code.patch | 58 - Fix-more-time-manipulations-for-y2038.patch | 83 - Improve-PKINIT-UPN-SAN-matching.patch | 151 - Make-timestamp-manipulations-y2038-safe.patch | 1844 ---- Remove-incomplete-PKINIT-OCSP-support.patch | 134 - Use-GSSAPI-fallback-skiptest.patch | 2 +- Use-expected_msg-in-test-scripts.patch | 2584 ----- Use-expected_trace-in-test-scripts.patch | 75 - ...ck-realm-for-GSSAPI-ccache-selection.patch | 185 - Use-krb5_timestamp-where-appropriate.patch | 327 - ...onical-client-principal-name-for-OTP.patch | 28 - krb5-1.11-kpasswdtest.patch | 2 +- krb5-1.11-run_user_0.patch | 2 +- krb5-1.12-api.patch | 2 +- krb5-1.12-ksu-path.patch | 2 +- krb5-1.12-ktany.patch | 2 +- krb5-1.12.1-pam.patch | 12 +- krb5-1.13-dirsrv-accountlock.patch | 10 +- krb5-1.15-beta1-buildconf.patch | 4 +- krb5-1.15.1-selinux-label.patch | 54 +- krb5-1.3.1-dns.patch | 6 +- krb5-1.9-debuginfo.patch | 2 +- krb5.spec | 48 +- sources | 6 +- 46 files changed, 66 insertions(+), 21916 deletions(-) delete mode 100644 Add-German-translation.patch delete mode 100644 Add-KDC-policy-pluggable-interface.patch delete mode 100644 Add-PKINIT-UPN-tests-to-t_pkinit.py.patch delete mode 100644 Add-PKINIT-test-case-for-generic-client-cert.patch delete mode 100644 Add-certauth-pluggable-interface.patch delete mode 100644 Add-hostname-based-ccselect-module.patch delete mode 100644 Add-k5test-expected_msg-expected_trace.patch delete mode 100644 Add-support-to-query-the-SSF-of-a-GSS-context.patch delete mode 100644 Add-test-case-for-PKINIT-DH-renegotiation.patch delete mode 100644 Add-test-cert-generation-to-make-certs.sh.patch delete mode 100644 Add-test-cert-with-no-extensions.patch delete mode 100644 Add-the-client_name-kdcpreauth-callback.patch delete mode 100644 Add-timestamp-helper-functions.patch delete mode 100644 Add-timestamp-tests.patch delete mode 100644 Add-y2038-documentation.patch delete mode 100644 Build-with-Werror-implicit-int-where-supported.patch delete mode 100644 Convert-some-pkiDebug-messages-to-TRACE-macros.patch delete mode 100644 Correct-error-handling-bug-in-prior-commit.patch delete mode 100644 Deindent-crypto_retrieve_X509_sans.patch delete mode 100644 Fix-bugs-in-kdcpolicy-commit.patch delete mode 100644 Fix-certauth-built-in-module-returns.patch delete mode 100644 Fix-in_clock_skew-and-use-it-in-AS-client-code.patch delete mode 100644 Fix-more-time-manipulations-for-y2038.patch delete mode 100644 Improve-PKINIT-UPN-SAN-matching.patch delete mode 100644 Make-timestamp-manipulations-y2038-safe.patch delete mode 100644 Remove-incomplete-PKINIT-OCSP-support.patch delete mode 100644 Use-expected_msg-in-test-scripts.patch delete mode 100644 Use-expected_trace-in-test-scripts.patch delete mode 100644 Use-fallback-realm-for-GSSAPI-ccache-selection.patch delete mode 100644 Use-krb5_timestamp-where-appropriate.patch delete mode 100644 Use-the-canonical-client-principal-name-for-OTP.patch diff --git a/.gitignore b/.gitignore index c78f6a3..df05a67 100644 --- a/.gitignore +++ b/.gitignore @@ -154,3 +154,6 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.15.2-pdfs.tar /krb5-1.15.2.tar.gz /krb5-1.15.2.tar.gz.asc +/krb5-1.16-beta1-pdfs.tar +/krb5-1.16-beta1.tar.gz +/krb5-1.16-beta1.tar.gz.asc diff --git a/Add-German-translation.patch b/Add-German-translation.patch deleted file mode 100644 index bb3ecb3..0000000 --- a/Add-German-translation.patch +++ /dev/null @@ -1,9333 +0,0 @@ -From 914be6ccfa5e3cb52d0e0e72720eca8f2e528250 Mon Sep 17 00:00:00 2001 -From: Chris Leick -Date: Wed, 6 Apr 2016 18:14:40 -0400 -Subject: [PATCH] Add German translation - -ticket: 8515 (new) -(cherry picked from commit 0c9a4d9734c29a77d3c7ac267e8e885a75f44b4f) ---- - src/po/Makefile.in | 2 +- - src/po/de.po | 9301 ++++++++++++++++++++++++++++++++++++++++++++++++++++ - 2 files changed, 9302 insertions(+), 1 deletion(-) - create mode 100644 src/po/de.po - -diff --git a/src/po/Makefile.in b/src/po/Makefile.in -index fdaf872a1..6753447dc 100644 ---- a/src/po/Makefile.in -+++ b/src/po/Makefile.in -@@ -18,7 +18,7 @@ ETSRCS= $(BUILDTOP)/lib/gssapi/generic/gssapi_err_generic.c \ - $(BUILDTOP)/lib/krb5/error_tables/kv5m_err.c \ - $(BUILDTOP)/lib/krb5/error_tables/krb524_err.c - # This is a placeholder until we have an actual translation. --CATALOGS=en_US.mo -+CATALOGS=en_US.mo de.mo - - .SUFFIXES: .po .mo - .po.mo: -diff --git a/src/po/de.po b/src/po/de.po -new file mode 100644 -index 000000000..2144d7833 ---- /dev/null -+++ b/src/po/de.po -@@ -0,0 +1,9301 @@ -+# German translation of mit-krb5. -+# This file is distributed under the same license as the mit-krb5 package. -+# Copyright (C) 1985-2013 by the Massachusetts Institute of Technology. -+# Copyright (C) of this file 2014-2016 Chris Leick . -+# -+msgid "" -+msgstr "" -+"Project-Id-Version: mit-krb5 13.2\n" -+"Report-Msgid-Bugs-To: krbdev@mit.edu\n" -+"POT-Creation-Date: 2015-05-06 14:59-0400\n" -+"PO-Revision-Date: 2016-04-07 08:15+0200\n" -+"Last-Translator: Chris Leick \n" -+"Language-Team: German \n" -+"Language: de\n" -+"MIME-Version: 1.0\n" -+"Content-Type: text/plain; charset=UTF-8\n" -+"Content-Transfer-Encoding: 8bit\n" -+"Plural-Forms: nplurals=2; plural=n != 1;\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:62 -+#, c-format -+msgid "Usage: %s [-A] [-q] [-c cache_name]\n" -+msgstr "Aufruf: %s [-A] [-q] [-c Zwischenspeichername]\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:63 -+#, c-format -+msgid "\t-A destroy all credential caches in collection\n" -+msgstr "\t-A vernichtet alle Anmeldedatenzwischenspeicher in der Sammlung.\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:64 -+#, c-format -+msgid "\t-q quiet mode\n" -+msgstr "\t-q stiller Modus\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:65 -+#: ../../src/clients/kswitch/kswitch.c:45 -+#, c-format -+msgid "\t-c specify name of credentials cache\n" -+msgstr "\t-c gibt den Namen des Zwischenspeichers für Anmeldedaten an.\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:98 -+#: ../../src/clients/kinit/kinit.c:383 ../../src/clients/ksu/main.c:284 -+#, c-format -+msgid "Only one -c option allowed\n" -+msgstr "Nur eine »-c«-Option ist erlaubt.\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:105 -+#: ../../src/clients/kinit/kinit.c:412 ../../src/clients/klist/klist.c:182 -+#, c-format -+msgid "Kerberos 4 is no longer supported\n" -+msgstr "Kerberos 4 wird nicht mehr unterstützt.\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:126 -+#: ../../src/clients/klist/klist.c:253 ../../src/clients/ksu/main.c:131 -+#: ../../src/clients/ksu/main.c:137 ../../src/clients/kswitch/kswitch.c:97 -+#: ../../src/kadmin/ktutil/ktutil.c:52 ../../src/kdc/main.c:926 -+#: ../../src/slave/kprop.c:102 ../../src/slave/kpropd.c:1052 -+msgid "while initializing krb5" -+msgstr "beim Initialisieren von Krb5" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:133 -+msgid "while listing credential caches" -+msgstr "beim Auflisten der Anmeldedatenzwischenspeicher" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:140 -+msgid "composing ccache name" -+msgstr "Ccache-Name wird zusammengesetzt." -+ -+#: ../../src/clients/kdestroy/kdestroy.c:145 -+#, c-format -+msgid "while destroying cache %s" -+msgstr "beim Zerstören des Zwischenspeichers %s" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:157 -+#: ../../src/clients/kswitch/kswitch.c:104 -+#, c-format -+msgid "while resolving %s" -+msgstr "beim Auflösen von %s" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:163 -+#: ../../src/clients/kinit/kinit.c:501 ../../src/clients/klist/klist.c:460 -+msgid "while getting default ccache" -+msgstr "beim Holen des Standard-Ccaches" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:170 ../../src/clients/ksu/main.c:986 -+msgid "while destroying cache" -+msgstr "beim Zerstören des Zwischenspeichers" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:173 -+#, c-format -+msgid "Ticket cache NOT destroyed!\n" -+msgstr "Ticketzwischenspeicher NICHT vernichtet!\n" -+ -+#: ../../src/clients/kdestroy/kdestroy.c:175 -+#, c-format -+msgid "Ticket cache %cNOT%c destroyed!\n" -+msgstr "Ticketzwischenspeicher %cNICHT%c vernichtet!\n" -+ -+#: ../../src/clients/kinit/kinit.c:213 -+#, c-format -+msgid "\t-V verbose\n" -+msgstr "\t-V detaillierte Ausgabe\n" -+ -+#: ../../src/clients/kinit/kinit.c:214 -+#, c-format -+msgid "\t-l lifetime\n" -+msgstr "\t-l Lebensdauer\n" -+ -+#: ../../src/clients/kinit/kinit.c:215 -+#, c-format -+msgid "\t-s start time\n" -+msgstr "\t-s Startzeit\n" -+ -+#: ../../src/clients/kinit/kinit.c:216 -+#, c-format -+msgid "\t-r renewable lifetime\n" -+msgstr "\t-r verlängerbare Lebensdauer\n" -+ -+#: ../../src/clients/kinit/kinit.c:217 -+#, c-format -+msgid "\t-f forwardable\n" -+msgstr "\t-f weiterleitbar\n" -+ -+#: ../../src/clients/kinit/kinit.c:218 -+#, c-format -+msgid "\t-F not forwardable\n" -+msgstr "\t-F nicht weiterleitbar\n" -+ -+#: ../../src/clients/kinit/kinit.c:219 -+#, c-format -+msgid "\t-p proxiable\n" -+msgstr "\t-p Proxy nutzbar\n" -+ -+#: ../../src/clients/kinit/kinit.c:220 -+#, c-format -+msgid "\t-P not proxiable\n" -+msgstr "\t-P Proxy nicht nutzbar\n" -+ -+#: ../../src/clients/kinit/kinit.c:221 -+#, c-format -+msgid "\t-n anonymous\n" -+msgstr "\t-n anonym\n" -+ -+#: ../../src/clients/kinit/kinit.c:222 -+#, c-format -+msgid "\t-a include addresses\n" -+msgstr "\t-a bezieht Adressen ein.\n" -+ -+#: ../../src/clients/kinit/kinit.c:223 -+#, c-format -+msgid "\t-A do not include addresses\n" -+msgstr "\t-a bezieht Adressen nicht ein.\n" -+ -+#: ../../src/clients/kinit/kinit.c:224 -+#, c-format -+msgid "\t-v validate\n" -+msgstr "\t-v überprüft\n" -+ -+#: ../../src/clients/kinit/kinit.c:225 -+#, c-format -+msgid "\t-R renew\n" -+msgstr "\t-R erneuert\n" -+ -+#: ../../src/clients/kinit/kinit.c:226 -+#, c-format -+msgid "\t-C canonicalize\n" -+msgstr "\t-C bringt in Normalform\n" -+ -+#: ../../src/clients/kinit/kinit.c:227 -+#, c-format -+msgid "\t-E client is enterprise principal name\n" -+msgstr "\t-E Client ist der Principal-Name des Unternehmens\n" -+ -+#: ../../src/clients/kinit/kinit.c:228 -+#, c-format -+msgid "\t-k use keytab\n" -+msgstr "\t-k verwendet Schlüsseltabelle\n" -+ -+#: ../../src/clients/kinit/kinit.c:229 -+#, c-format -+msgid "\t-i use default client keytab (with -k)\n" -+msgstr "\t-i verwendet die Standardschlüsseltabelle des Clients (mit -k).\n" -+ -+#: ../../src/clients/kinit/kinit.c:230 -+#, c-format -+msgid "\t-t filename of keytab to use\n" -+msgstr "\t-t Dateiname der zu verwendenden Schlüsseltabelle\n" -+ -+#: ../../src/clients/kinit/kinit.c:231 -+#, c-format -+msgid "\t-c Kerberos 5 cache name\n" -+msgstr "\t-c Kerberos-5-Zwischenspeichername\n" -+ -+#: ../../src/clients/kinit/kinit.c:232 -+#, c-format -+msgid "\t-S service\n" -+msgstr "\t-S Dienst\n" -+ -+#: ../../src/clients/kinit/kinit.c:233 -+#, c-format -+msgid "\t-T armor credential cache\n" -+msgstr "\t-T gehärteter Anmeldedatenzwischenspeicher\n" -+ -+#: ../../src/clients/kinit/kinit.c:234 -+#, c-format -+msgid "\t-X [=]\n" -+msgstr "\t-X [=]\n" -+ -+#: ../../src/clients/kinit/kinit.c:301 ../../src/clients/kinit/kinit.c:309 -+#, c-format -+msgid "Bad lifetime value %s\n" -+msgstr "falscher Wert für die Lebensdauer %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:343 -+#, c-format -+msgid "Bad start time value %s\n" -+msgstr "falscher Wert für die Startzeit %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:362 -+#, c-format -+msgid "Only one -t option allowed.\n" -+msgstr "Nur eine -t-Option ist erlaubt.\n" -+ -+#: ../../src/clients/kinit/kinit.c:370 -+#, c-format -+msgid "Only one armor_ccache\n" -+msgstr "nur ein gehärteter Ccache\n" -+ -+#: ../../src/clients/kinit/kinit.c:391 -+#, c-format -+msgid "Only one -I option allowed\n" -+msgstr "Nur eine -I-Option ist erlaubt.\n" -+ -+#: ../../src/clients/kinit/kinit.c:401 -+msgid "while adding preauth option" -+msgstr "beim Hinzufügen der Option »preauth«" -+ -+#: ../../src/clients/kinit/kinit.c:425 -+#, c-format -+msgid "Only one of -f and -F allowed\n" -+msgstr "Nur eine der Optionen -f und -F ist erlaubt.\n" -+ -+#: ../../src/clients/kinit/kinit.c:430 -+#, c-format -+msgid "Only one of -p and -P allowed\n" -+msgstr "Nur eine der Optionen -p und -P ist erlaubt.\n" -+ -+#: ../../src/clients/kinit/kinit.c:435 -+#, c-format -+msgid "Only one of -a and -A allowed\n" -+msgstr "Nur eine der Optionen -a und -A ist erlaubt.\n" -+ -+#: ../../src/clients/kinit/kinit.c:440 -+#, c-format -+msgid "Only one of -t and -i allowed\n" -+msgstr "Nur eine der Optionen -t und-i ist erlaubt.\n" -+ -+#: ../../src/clients/kinit/kinit.c:447 -+#, c-format -+msgid "keytab specified, forcing -k\n" -+msgstr "Schlüsseltabelle angegeben, -k wird erzwungen\n" -+ -+#: ../../src/clients/kinit/kinit.c:451 ../../src/clients/klist/klist.c:221 -+#, c-format -+msgid "Extra arguments (starting with \"%s\").\n" -+msgstr "zusätzliche Argumente (beginnend mit »%s«)\n" -+ -+#: ../../src/clients/kinit/kinit.c:480 -+msgid "while initializing Kerberos 5 library" -+msgstr "beim Initialisieren der Kerberos-5-Bibliothek" -+ -+#: ../../src/clients/kinit/kinit.c:488 ../../src/clients/kinit/kinit.c:644 -+#, c-format -+msgid "resolving ccache %s" -+msgstr "Ccache %s wird ermittelt" -+ -+#: ../../src/clients/kinit/kinit.c:493 -+#, c-format -+msgid "Using specified cache: %s\n" -+msgstr "Angegebener Zwischenspeicher wird verwendet: %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:515 ../../src/clients/kinit/kinit.c:595 -+#: ../../src/clients/kpasswd/kpasswd.c:28 ../../src/clients/ksu/main.c:238 -+#, c-format -+msgid "when parsing name %s" -+msgstr "wenn der Name %s ausgewertet wird" -+ -+#: ../../src/clients/kinit/kinit.c:523 ../../src/kadmin/dbutil/kdb5_util.c:307 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:391 -+#: ../../src/slave/kprop.c:203 -+msgid "while getting default realm" -+msgstr "beim Holen des Standard-Realms" -+ -+#: ../../src/clients/kinit/kinit.c:535 -+msgid "while building principal" -+msgstr "beim Erstellen des Principals" -+ -+#: ../../src/clients/kinit/kinit.c:543 -+msgid "When resolving the default client keytab" -+msgstr "beim Auflösen der Standardschlüsseltabelle des Clients" -+ -+#: ../../src/clients/kinit/kinit.c:550 -+msgid "When determining client principal name from keytab" -+msgstr "beim Bestimmen des Dienst-Principal-Namens anhand der Schlüsseltabelle" -+ -+#: ../../src/clients/kinit/kinit.c:559 -+msgid "when creating default server principal name" -+msgstr "wenn der Standard-Principal-Name des Servers erstellt wird" -+ -+#: ../../src/clients/kinit/kinit.c:566 -+#, c-format -+msgid "(principal %s)" -+msgstr "(Principal %s)" -+ -+#: ../../src/clients/kinit/kinit.c:569 -+msgid "for local services" -+msgstr "für lokale Dienste" -+ -+#: ../../src/clients/kinit/kinit.c:590 ../../src/clients/kpasswd/kpasswd.c:42 -+#, c-format -+msgid "Unable to identify user\n" -+msgstr "Benutzer kann nicht identifiziert werden\n" -+ -+#: ../../src/clients/kinit/kinit.c:605 ../../src/clients/kswitch/kswitch.c:116 -+#, c-format -+msgid "while searching for ccache for %s" -+msgstr "beim Suchen nach Ccache für %s" -+ -+#: ../../src/clients/kinit/kinit.c:611 -+#, c-format -+msgid "Using existing cache: %s\n" -+msgstr "Existierender Zwischenspeicher wird verwendet: %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:620 -+msgid "while generating new ccache" -+msgstr "beim Erstellen von neuem Ccache" -+ -+#: ../../src/clients/kinit/kinit.c:624 -+#, c-format -+msgid "Using new cache: %s\n" -+msgstr "Neuer Zwischenspeicher wird verwendet: %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:636 -+#, c-format -+msgid "Using default cache: %s\n" -+msgstr "Standardzwischenspeicher wird verwendet: %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:649 -+#, c-format -+msgid "Using specified input cache: %s\n" -+msgstr "Angegebener Eingabezwischenspeicher wird verwendet: %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:657 ../../src/clients/ksu/krb_auth_su.c:160 -+msgid "when unparsing name" -+msgstr "beim Rückgängigmachen der Auswertung des Namens" -+ -+#: ../../src/clients/kinit/kinit.c:661 -+#, c-format -+msgid "Using principal: %s\n" -+msgstr "verwendeter Principal: %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:752 -+msgid "getting local addresses" -+msgstr "Lokale Adressen werden geholt." -+ -+#: ../../src/clients/kinit/kinit.c:771 -+#, c-format -+msgid "while setting up KDB keytab for realm %s" -+msgstr "beim Einrichten der KDB-Schlüsseltabelle für Realm %s" -+ -+#: ../../src/clients/kinit/kinit.c:780 ../../src/clients/kvno/kvno.c:201 -+#, c-format -+msgid "resolving keytab %s" -+msgstr "Schlüsseltabelle wird ermittelt: %s" -+ -+#: ../../src/clients/kinit/kinit.c:785 -+#, c-format -+msgid "Using keytab: %s\n" -+msgstr "Schlüsseltabelle wird verwendet: %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:789 -+msgid "resolving default client keytab" -+msgstr "Standardschlüsseltabelle des Clients wird ermittelt." -+ -+#: ../../src/clients/kinit/kinit.c:799 -+#, c-format -+msgid "while setting '%s'='%s'" -+msgstr "beim Setzen von »%s«=»%s«" -+ -+#: ../../src/clients/kinit/kinit.c:804 -+#, c-format -+msgid "PA Option %s = %s\n" -+msgstr "PA-Option %s = %s\n" -+ -+#: ../../src/clients/kinit/kinit.c:849 -+msgid "getting initial credentials" -+msgstr "Anfängliche Anmeldedaten werden geholt." -+ -+#: ../../src/clients/kinit/kinit.c:852 -+msgid "validating credentials" -+msgstr "Anmeldedaten werden geprüft." -+ -+#: ../../src/clients/kinit/kinit.c:855 -+msgid "renewing credentials" -+msgstr "Anmeldedaten werden erneuert." -+ -+#: ../../src/clients/kinit/kinit.c:860 -+#, c-format -+msgid "%s: Password incorrect while %s\n" -+msgstr "%s: Passwort bei %s falsch\n" -+ -+#: ../../src/clients/kinit/kinit.c:863 -+#, c-format -+msgid "while %s" -+msgstr "bei %s" -+ -+#: ../../src/clients/kinit/kinit.c:871 ../../src/slave/kprop.c:224 -+#, c-format -+msgid "when initializing cache %s" -+msgstr "beim Initialisieren des Zwischenspeichers %s" -+ -+#: ../../src/clients/kinit/kinit.c:876 -+#, c-format -+msgid "Initialized cache\n" -+msgstr "initialisierter Zwischenspeicher\n" -+ -+#: ../../src/clients/kinit/kinit.c:880 -+msgid "while storing credentials" -+msgstr "beim Speichern der Anmeldedaten" -+ -+#: ../../src/clients/kinit/kinit.c:884 -+#, c-format -+msgid "Stored credentials\n" -+msgstr "gespeicherte Anmeldedaten\n" -+ -+#: ../../src/clients/kinit/kinit.c:891 -+msgid "while switching to new ccache" -+msgstr "beim Wechsel zum neuen Ccache" -+ -+#: ../../src/clients/kinit/kinit.c:946 -+#, c-format -+msgid "Authenticated to Kerberos v5\n" -+msgstr "Authentifiziert für Kerberos v5\n" -+ -+#: ../../src/clients/klist/klist.c:91 -+#, c-format -+msgid "" -+"Usage: %s [-e] [-V] [[-c] [-l] [-A] [-d] [-f] [-s] [-a [-n]]] [-k [-t] [-K]] " -+"[name]\n" -+msgstr "" -+"Aufruf: %s [-e] [-V] [[-c] [-l] [-A] [-d] [-f] [-s] [-a [-n]]] [-k [-t] [-" -+"K]] [Name]\n" -+ -+#: ../../src/clients/klist/klist.c:93 -+#, c-format -+msgid "\t-c specifies credentials cache\n" -+msgstr "\t-c gibt den Anmeldedatenzwischenspeicher an\n" -+ -+#: ../../src/clients/klist/klist.c:94 -+#, c-format -+msgid "\t-k specifies keytab\n" -+msgstr "\t-k gibt die Schlüsseltabelle an.\n" -+ -+#: ../../src/clients/klist/klist.c:95 -+#, c-format -+msgid "\t (Default is credentials cache)\n" -+msgstr "\t (Voreinstellung ist Anmeldedatenzwischenspeicher)\n" -+ -+#: ../../src/clients/klist/klist.c:96 -+#, c-format -+msgid "\t-i uses default client keytab if no name given\n" -+msgstr "" -+"\t-i verwendet die Standardschlüsseltabelle des Clients, falls kein Name " -+"angegeben wurde.\n" -+ -+#: ../../src/clients/klist/klist.c:97 -+#, c-format -+msgid "\t-l lists credential caches in collection\n" -+msgstr "\t-l listet gesammelte Anmeldedatenzwischenspeicher auf.\n" -+ -+#: ../../src/clients/klist/klist.c:98 -+#, c-format -+msgid "\t-A shows content of all credential caches\n" -+msgstr "\t-A zeigt den Inhalt aller Anmeldedatenzwischenspeicher an.\n" -+ -+#: ../../src/clients/klist/klist.c:99 -+#, c-format -+msgid "\t-e shows the encryption type\n" -+msgstr "\t-e zeigt den Verschlüsselungstyp.\n" -+ -+#: ../../src/clients/klist/klist.c:100 -+#, c-format -+msgid "\t-V shows the Kerberos version and exits\n" -+msgstr "\t-V zeigt die Kerberos-Version und wird beendet.\n" -+ -+#: ../../src/clients/klist/klist.c:101 -+#, c-format -+msgid "\toptions for credential caches:\n" -+msgstr "\tOptionen für Anmeldedatenzwischenspeicher:\n" -+ -+#: ../../src/clients/klist/klist.c:102 -+#, c-format -+msgid "\t\t-d shows the submitted authorization data types\n" -+msgstr "\t\t-d zeigt die übertragenen Autorisierungsdatentypen.\n" -+ -+#: ../../src/clients/klist/klist.c:104 -+#, c-format -+msgid "\t\t-f shows credentials flags\n" -+msgstr "t\t-f zeigt die Anmeldedatenschalter.\n" -+ -+#: ../../src/clients/klist/klist.c:105 -+#, c-format -+msgid "\t\t-s sets exit status based on valid tgt existence\n" -+msgstr "" -+"\t\t-s setzt den Exit-Status auf Basis der Existenz eines gültigen TGTs.\n" -+ -+#: ../../src/clients/klist/klist.c:107 -+#, c-format -+msgid "\t\t-a displays the address list\n" -+msgstr "\t\t-a zeigt die Adressliste.\n" -+ -+#: ../../src/clients/klist/klist.c:108 -+#, c-format -+msgid "\t\t\t-n do not reverse-resolve\n" -+msgstr "\t\t\t-n löst nicht rückwärts auf.\n" -+ -+#: ../../src/clients/klist/klist.c:109 -+#, c-format -+msgid "\toptions for keytabs:\n" -+msgstr "\tOptionen für Schlüsseltabellen:\n" -+ -+#: ../../src/clients/klist/klist.c:110 -+#, c-format -+msgid "\t\t-t shows keytab entry timestamps\n" -+msgstr "\t\t-t zeigt die Zeitstempel der Schlüsseltabelleneinträge.\n" -+ -+#: ../../src/clients/klist/klist.c:111 -+#, c-format -+msgid "\t\t-K shows keytab entry keys\n" -+msgstr "\t\t-K zeigt die Schlüssel der Schlüsseltabelleneinträge.\n" -+ -+#: ../../src/clients/klist/klist.c:230 -+#, c-format -+msgid "%s version %s\n" -+msgstr "%s Version %s\n" -+ -+#: ../../src/clients/klist/klist.c:282 -+msgid "while getting default client keytab" -+msgstr "beim Holen der Standardschlüsseltabelle des Clients" -+ -+#: ../../src/clients/klist/klist.c:287 -+msgid "while getting default keytab" -+msgstr "beim Holen der Standardschlüsseltabelle" -+ -+#: ../../src/clients/klist/klist.c:292 ../../src/kadmin/cli/keytab.c:108 -+#, c-format -+msgid "while resolving keytab %s" -+msgstr "beim Ermitteln der Schlüsseltabelle %s" -+ -+#: ../../src/clients/klist/klist.c:298 ../../src/kadmin/cli/keytab.c:92 -+msgid "while getting keytab name" -+msgstr "beim Holen des Schlüsseltabellennamens" -+ -+#: ../../src/clients/klist/klist.c:305 ../../src/kadmin/cli/keytab.c:399 -+msgid "while starting keytab scan" -+msgstr "beim Start des Schlüsseltabellen-Scans" -+ -+#: ../../src/clients/klist/klist.c:326 ../../src/clients/klist/klist.c:500 -+#: ../../src/clients/ksu/ccache.c:465 ../../src/kadmin/dbutil/dump.c:550 -+msgid "while unparsing principal name" -+msgstr "beim Rückgängigmachen des Auswertens des Principal-Namens" -+ -+#: ../../src/clients/klist/klist.c:350 ../../src/kadmin/cli/keytab.c:443 -+msgid "while scanning keytab" -+msgstr "beim Scannen der Schlüsseltabelle" -+ -+#: ../../src/clients/klist/klist.c:354 ../../src/kadmin/cli/keytab.c:448 -+msgid "while ending keytab scan" -+msgstr "beim Beenden des Schlüsseltabellen-Scans" -+ -+#: ../../src/clients/klist/klist.c:371 ../../src/clients/klist/klist.c:434 -+msgid "while listing ccache collection" -+msgstr "beim Aufführen der Ccache-Sammlung" -+ -+#: ../../src/clients/klist/klist.c:411 -+msgid "(Expired)" -+msgstr "(abgelaufen)" -+ -+#: ../../src/clients/klist/klist.c:466 -+#, c-format -+msgid "while resolving ccache %s" -+msgstr "beim Ermitteln des Ccaches %s" -+ -+#: ../../src/clients/klist/klist.c:504 -+#, c-format -+msgid "" -+"Ticket cache: %s:%s\n" -+"Default principal: %s\n" -+"\n" -+msgstr "" -+"Ticketzwischenspeicher: %s:%s\n" -+"Standard-Principal: %s\n" -+"\n" -+ -+#: ../../src/clients/klist/klist.c:518 -+msgid "while starting to retrieve tickets" -+msgstr "während das Abfragen der Tickets beginnt" -+ -+#: ../../src/clients/klist/klist.c:539 -+msgid "while finishing ticket retrieval" -+msgstr "während das Abfragem der Tickets endet" -+ -+#: ../../src/clients/klist/klist.c:545 -+msgid "while closing ccache" -+msgstr "beim Schließen des Ccaches" -+ -+#: ../../src/clients/klist/klist.c:555 -+msgid "while retrieving a ticket" -+msgstr "beim Abfragen eines Tickets" -+ -+#: ../../src/clients/klist/klist.c:667 ../../src/clients/ksu/ccache.c:450 -+#: ../../src/slave/kpropd.c:1225 ../../src/slave/kpropd.c:1285 -+msgid "while unparsing client name" -+msgstr "beim Rückgängigmachen des Auswertens des Client-Namens" -+ -+#: ../../src/clients/klist/klist.c:672 ../../src/clients/ksu/ccache.c:455 -+#: ../../src/slave/kprop.c:240 -+msgid "while unparsing server name" -+msgstr "beim Rückgängigmachen des Auswertens des Server-Namens" -+ -+#: ../../src/clients/klist/klist.c:701 ../../src/clients/ksu/ccache.c:480 -+#, c-format -+msgid "\tfor client %s" -+msgstr "\tfür Client %s" -+ -+#: ../../src/clients/klist/klist.c:713 ../../src/clients/ksu/ccache.c:489 -+msgid "renew until " -+msgstr "erneuern bis " -+ -+#: ../../src/clients/klist/klist.c:730 ../../src/clients/ksu/ccache.c:499 -+#, c-format -+msgid "Flags: %s" -+msgstr "Schalter: %s" -+ -+#: ../../src/clients/klist/klist.c:749 -+#, c-format -+msgid "Etype (skey, tkt): %s, " -+msgstr "Etype (Skey, TKT): %s, " -+ -+#: ../../src/clients/klist/klist.c:766 -+#, c-format -+msgid "AD types: " -+msgstr "AD-Typen" -+ -+#: ../../src/clients/klist/klist.c:783 -+#, c-format -+msgid "\tAddresses: (none)\n" -+msgstr "\tAdressen: (keine)\n" -+ -+#: ../../src/clients/klist/klist.c:785 -+#, c-format -+msgid "\tAddresses: " -+msgstr "\tAdressen: " -+ -+#: ../../src/clients/klist/klist.c:818 -+#, c-format -+msgid "broken address (type %d length %d)" -+msgstr "kaputte Adresse (Typ %d Länge %d)" -+ -+#: ../../src/clients/klist/klist.c:838 -+#, c-format -+msgid "unknown addrtype %d" -+msgstr "unbekannter »addrtype« %d" -+ -+#: ../../src/clients/klist/klist.c:847 -+#, c-format -+msgid "unprintable address (type %d, error %d %s)" -+msgstr "nicht druckbare Adresse (Typ %d Fehler %d %s)" -+ -+#: ../../src/clients/kpasswd/kpasswd.c:12 ../../src/lib/krb5/krb/gic_pwd.c:396 -+msgid "Enter new password" -+msgstr "Geben Sie ein neues Passwort ein." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:13 ../../src/lib/krb5/krb/gic_pwd.c:404 -+msgid "Enter it again" -+msgstr "Geben Sie es erneut ein." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:33 -+#, c-format -+msgid "Unable to identify user from password file\n" -+msgstr "" -+"Der Benutzer kann nicht anhand der Passwortdatei identifiziert werden.\n" -+ -+#: ../../src/clients/kpasswd/kpasswd.c:65 -+#, c-format -+msgid "usage: %s [principal]\n" -+msgstr "Aufruf: %s [Principal]\n" -+ -+#: ../../src/clients/kpasswd/kpasswd.c:73 -+msgid "initializing kerberos library" -+msgstr "Kerberos-Bibliothek wird initialisiert." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:77 -+msgid "allocating krb5_get_init_creds_opt" -+msgstr "krb5_get_init_creds_opt wird reserviert." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:92 -+msgid "opening default ccache" -+msgstr "Standard-Ccache wird geöffnet." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:97 -+msgid "getting principal from ccache" -+msgstr "Principal wird vom Ccache geholt." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:104 -+msgid "while setting FAST ccache" -+msgstr "beim Setzen des FAST-Ccaches" -+ -+#: ../../src/clients/kpasswd/kpasswd.c:111 -+msgid "closing ccache" -+msgstr "Ccache wird geschlossen." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:118 -+msgid "parsing client name" -+msgstr "Client-Name wird ausgewertet." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:135 -+msgid "Password incorrect while getting initial ticket" -+msgstr "Passwort beim Holen des anfänglichen Tickets falsch" -+ -+#: ../../src/clients/kpasswd/kpasswd.c:137 -+msgid "getting initial ticket" -+msgstr "Anfängliches Ticket wird geholt." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:144 -+msgid "while reading password" -+msgstr "beim Lesen des Passworts" -+ -+#: ../../src/clients/kpasswd/kpasswd.c:152 -+msgid "changing password" -+msgstr "Passwort wird geändert." -+ -+#: ../../src/clients/kpasswd/kpasswd.c:174 -+#: ../lib/kadm5/chpass_util_strings.c:30 -+#, c-format -+msgid "Password changed.\n" -+msgstr "Passwort geändert\n" -+ -+#: ../../src/clients/ksu/authorization.c:369 -+#, c-format -+msgid "" -+"Error: bad entry - %s in %s file, must be either full path or just the cmd " -+"name\n" -+msgstr "" -+"Fehler: falscher Eintrag – %s in Datei %s muss entweder ein vollständiger " -+"Pfad oder nur ein Befehlsname sein.\n" -+ -+#: ../../src/clients/ksu/authorization.c:377 -+#, c-format -+msgid "" -+"Error: bad entry - %s in %s file, since %s is just the cmd name, CMD_PATH " -+"must be defined \n" -+msgstr "" -+"Fehler: falscher Eintrag – %s in Datei %s. Da %s nur ein Befehlsname ist, " -+"muss CMD_PATH definiert sein.\n" -+ -+#: ../../src/clients/ksu/authorization.c:392 -+#, c-format -+msgid "Error: bad entry - %s in %s file, CMD_PATH contains no paths \n" -+msgstr "" -+"Fehler: falscher Eintrag – %s in Datei %s. CMD_PATH enthält keine Pfade.\n" -+ -+#: ../../src/clients/ksu/authorization.c:401 -+#, c-format -+msgid "Error: bad path %s in CMD_PATH for %s must start with '/' \n" -+msgstr "Fehler: falscher Pfad %s in CMD_PATH für %s muss mit »/« beginnen\n" -+ -+#: ../../src/clients/ksu/authorization.c:517 -+msgid "Error: not found -> " -+msgstr "Fehler: nicht gefunden -> " -+ -+#: ../../src/clients/ksu/authorization.c:723 -+#, c-format -+msgid "home directory name `%s' too long, can't search for .k5login\n" -+msgstr "" -+"Name des Home-Verzeichnisses »%s« ist zu lang, Suche nach .k5login nicht " -+"möglich\n" -+ -+#: ../../src/clients/ksu/ccache.c:368 -+#, c-format -+msgid "home directory path for %s too long\n" -+msgstr "Home-Verzeichnispfad für %s zu lang\n" -+ -+#: ../../src/clients/ksu/ccache.c:461 -+msgid "while retrieving principal name" -+msgstr "beim Abfragen des Principal-Namens" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:57 -+#: ../../src/clients/ksu/krb_auth_su.c:62 ../../src/slave/kprop.c:247 -+msgid "while copying client principal" -+msgstr "beim Kopieren des Client-Principals" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:69 -+msgid "while creating tgt for local realm" -+msgstr "beim Erstellen des TGTs für lokalen Realm" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:84 -+msgid "while retrieving creds from cache" -+msgstr "beim Abfragen der Anmeldedaten aus dem Zwischenspeicher" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:95 -+msgid "while switching to target uid" -+msgstr "beim Umschalten auf die Ziel-UID" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:100 -+#, c-format -+msgid "" -+"WARNING: Your password may be exposed if you enter it here and are logged \n" -+msgstr "" -+"WARNUNG: Ihr Passwort könnte offengelegt werden, falls Sie es hier eingeben " -+"und\n" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:102 -+#, c-format -+msgid " in remotely using an unsecure (non-encrypted) channel. \n" -+msgstr "" -+" in der Ferne mittels eines unsicheren (unverschlüsselten) Kanals\n" -+" angemeldet sind.\n" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:114 ../../src/clients/ksu/main.c:464 -+msgid "while reclaiming root uid" -+msgstr "beim erneuten Beanspruchen der Root-UID" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:121 -+#, c-format -+msgid "does not have any appropriate tickets in the cache.\n" -+msgstr "hat keine geeigneten Tickets im Zwischenspeicher.\n" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:133 -+msgid "while verifying ticket for server" -+msgstr "beim Prüfen des Tickets für Server" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:167 -+msgid "while getting time of day" -+msgstr "beim Holen der Tageszeit" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:171 -+#, c-format -+msgid "Kerberos password for %s: " -+msgstr "Kerberos-Passwort für %s: " -+ -+#: ../../src/clients/ksu/krb_auth_su.c:175 -+#, c-format -+msgid "principal name %s too long for internal buffer space\n" -+msgstr "Principal-Name %s für den internen Pufferbereich zu groß\n" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:184 -+#, c-format -+msgid "while reading password for '%s'\n" -+msgstr "beim Lesen des Passworts für »%s«\n" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:191 -+#, c-format -+msgid "No password given\n" -+msgstr "kein Passwort angegeben\n" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:204 -+#, c-format -+msgid "%s: Password incorrect\n" -+msgstr "%s: Passwort falsch\n" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:206 -+msgid "while getting initial credentials" -+msgstr "beim Holen der Anfangsanmeldedaten" -+ -+#: ../../src/clients/ksu/krb_auth_su.c:226 -+#: ../../src/clients/ksu/krb_auth_su.c:240 -+#, c-format -+msgid " %s while unparsing name\n" -+msgstr "%s beim Rückgängigmachen der Namensauswertung\n" -+ -+#: ../../src/clients/ksu/main.c:68 -+#, c-format -+msgid "" -+"Usage: %s [target user] [-n principal] [-c source cachename] [-k] [-D] [-r " -+"time] [-pf] [-l lifetime] [-zZ] [-q] [-e command [args... ] ] [-a " -+"[args... ] ]\n" -+msgstr "" -+"Aufruf: %s [Zielbenutzer] [-n Principal] [-c Quellenzwischenspeichername] [-" -+"k] [-D] [-r Zeit] [-pf] [-l Lebensdauer] [-zZ] [-q] [-e Befehl [Argumente " -+"…] ] [-a [Argumente …] ]\n" -+ -+#: ../../src/clients/ksu/main.c:147 -+msgid "" -+"program name too long - quitting to avoid triggering system logging bugs" -+msgstr "" -+"Programmname zu lang – wird beendet, um das Auslösen von " -+"Systemprotokollierungsfehlern zu vermeiden" -+ -+#: ../../src/clients/ksu/main.c:173 -+msgid "while allocating memory" -+msgstr "bei Reservieren von Speicher" -+ -+#: ../../src/clients/ksu/main.c:186 -+msgid "while setting euid to source user" -+msgstr "beim Setzen der EUID auf dem Quellbenutzer" -+ -+#: ../../src/clients/ksu/main.c:196 ../../src/clients/ksu/main.c:231 -+#, c-format -+msgid "Bad lifetime value (%s hours?)\n" -+msgstr "falscher Wert für Lebensdauer (%s Stunden?)\n" -+ -+#: ../../src/clients/ksu/main.c:208 ../../src/clients/ksu/main.c:292 -+msgid "when gathering parameters" -+msgstr "beim Zusammenstellen der Parameter" -+ -+#: ../../src/clients/ksu/main.c:251 -+#, c-format -+msgid "-z option is mutually exclusive with -Z.\n" -+msgstr "Die Optionen -z und -Z schließen sich gegenseitig aus.\n" -+ -+#: ../../src/clients/ksu/main.c:259 -+#, c-format -+msgid "-Z option is mutually exclusive with -z.\n" -+msgstr "Die Optionen -Z und -z schließen sich gegenseitig aus.\n" -+ -+#: ../../src/clients/ksu/main.c:272 -+#, c-format -+msgid "while looking for credentials cache %s" -+msgstr "beim Suchen nach dem Anmeldedatenzwischenspeicher %s" -+ -+#: ../../src/clients/ksu/main.c:278 -+#, c-format -+msgid "malformed credential cache name %s\n" -+msgstr "falsch gebildeter Anmeldedatenzwischenspeichername %s\n" -+ -+# ksu ist eine Kerberos-Variante von su -+#: ../../src/clients/ksu/main.c:336 -+#, c-format -+msgid "ksu: who are you?\n" -+msgstr "ksu: Wer sind Sie?\n" -+ -+#: ../../src/clients/ksu/main.c:340 -+#, c-format -+msgid "Your uid doesn't match your passwd entry?!\n" -+msgstr "Ihre UID passt nicht zu Ihrem Passworteintrag.\n" -+ -+#: ../../src/clients/ksu/main.c:355 -+#, c-format -+msgid "ksu: unknown login %s\n" -+msgstr "ksu: unbekannter Anmeldename %s\n" -+ -+#: ../../src/clients/ksu/main.c:375 -+msgid "while getting source cache" -+msgstr "beim Holen des Quellenzwischenspeichers" -+ -+#: ../../src/clients/ksu/main.c:381 ../../src/clients/kvno/kvno.c:194 -+msgid "while opening ccache" -+msgstr "beim Öffnen des Ccaches" -+ -+#: ../../src/clients/ksu/main.c:389 -+msgid "while selecting the best principal" -+msgstr "beim Auswählen des besten Principals" -+ -+#: ../../src/clients/ksu/main.c:397 -+msgid "while returning to source uid after finding best principal" -+msgstr "" -+"bei der Rückkehr zur Quell-UID, nachdem der beste Principal gefunden wurde" -+ -+#: ../../src/clients/ksu/main.c:417 -+#, c-format -+msgid "account %s: authorization failed\n" -+msgstr "Konto %s: Autorisierung fehlgeschlagen\n" -+ -+#: ../../src/clients/ksu/main.c:442 -+msgid "while parsing temporary name" -+msgstr "beim Auswertens des temporären Namens" -+ -+#: ../../src/clients/ksu/main.c:447 -+msgid "while creating temporary cache" -+msgstr "bei Erstellen des temporären Zwischenspeichers" -+ -+#: ../../src/clients/ksu/main.c:453 ../../src/clients/ksu/main.c:693 -+#, c-format -+msgid "while copying cache %s to %s" -+msgstr "beim Kopieren des Zwischenspeichers %s nach %s" -+ -+#: ../../src/clients/ksu/main.c:471 -+#, c-format -+msgid "" -+"WARNING: Your password may be exposed if you enter it here and are logged\n" -+msgstr "" -+"WARNUNG: Ihr Passwort könnte offengelegt werden, falls Sie es hier eingeben " -+"und\n" -+ -+#: ../../src/clients/ksu/main.c:473 -+#, c-format -+msgid " in remotely using an unsecure (non-encrypted) channel.\n" -+msgstr "" -+" in der Ferne über einen unsicheren (unverschlüsselten) Kanal " -+"angemeldet\n" -+"sind.\n" -+ -+#: ../../src/clients/ksu/main.c:479 -+#, c-format -+msgid "Goodbye\n" -+msgstr "Auf Wiedersehen\n" -+ -+#: ../../src/clients/ksu/main.c:483 -+#, c-format -+msgid "Could not get a tgt for " -+msgstr "Es konnte kein TGT geholt werden für " -+ -+#: ../../src/clients/ksu/main.c:505 -+#, c-format -+msgid "Authentication failed.\n" -+msgstr "Authentifizierung fehlgeschlagen.\n" -+ -+#: ../../src/clients/ksu/main.c:513 -+msgid "When unparsing name" -+msgstr "beim Rückgängigmachen der Namensauswertung" -+ -+#: ../../src/clients/ksu/main.c:517 -+#, c-format -+msgid "Authenticated %s\n" -+msgstr "Authentifiziert %s\n" -+ -+#: ../../src/clients/ksu/main.c:524 -+msgid "while switching to target for authorization check" -+msgstr "beim Wechsel des Ziels der Autorisierungsprüfung" -+ -+#: ../../src/clients/ksu/main.c:531 -+msgid "while checking authorization" -+msgstr "beim Prüfen der Autorisierung" -+ -+#: ../../src/clients/ksu/main.c:537 -+msgid "while switching back from target after authorization check" -+msgstr "beim Zurückwechsel vom Ziel nach der Autorisierungsprüfung" -+ -+#: ../../src/clients/ksu/main.c:544 -+#, c-format -+msgid "Account %s: authorization for %s for execution of\n" -+msgstr "Konto %s: Autorisierung für %s zum Ausführen von\n" -+ -+#: ../../src/clients/ksu/main.c:546 -+#, c-format -+msgid " %s successful\n" -+msgstr " %s erfolgreich\n" -+ -+#: ../../src/clients/ksu/main.c:552 -+#, c-format -+msgid "Account %s: authorization for %s successful\n" -+msgstr "Konto %s: Autorisierung für %s erfolgreich\n" -+ -+#: ../../src/clients/ksu/main.c:564 -+#, c-format -+msgid "Account %s: authorization for %s for execution of %s failed\n" -+msgstr "Konto %s: Autorisierung für %s zum Ausführen von %s fehlgeschlagen\n" -+ -+#: ../../src/clients/ksu/main.c:572 -+#, c-format -+msgid "Account %s: authorization of %s failed\n" -+msgstr "Konto %s: Autorisierung von %s fehlgeschlagen\n" -+ -+#: ../../src/clients/ksu/main.c:587 -+msgid "while calling cc_filter" -+msgstr "beim Aufruf von »cc_filter«" -+ -+#: ../../src/clients/ksu/main.c:595 -+msgid "while erasing target cache" -+msgstr "bei Löschen des Zielzwischenspeichers" -+ -+#: ../../src/clients/ksu/main.c:615 -+#, c-format -+msgid "ksu: permission denied (shell).\n" -+msgstr "ksu: Zugriff verweigert (Shell)\n" -+ -+#: ../../src/clients/ksu/main.c:624 -+#, c-format -+msgid "ksu: couldn't set environment variable USER\n" -+msgstr "ksu: Umgebungsvariable USER kann nicht gesetzt werden\n" -+ -+#: ../../src/clients/ksu/main.c:630 -+#, c-format -+msgid "ksu: couldn't set environment variable HOME\n" -+msgstr "ksu: Umgebungsvariable HOME kann nicht gesetzt werden\n" -+ -+#: ../../src/clients/ksu/main.c:635 -+#, c-format -+msgid "ksu: couldn't set environment variable SHELL\n" -+msgstr "ksu: Umgebungsvariable SHELL kann nicht gesetzt werden\n" -+ -+#: ../../src/clients/ksu/main.c:646 -+#, c-format -+msgid "ksu: initgroups failed.\n" -+msgstr "ksu: »initgroups« fehlgeschlagen\n" -+ -+#: ../../src/clients/ksu/main.c:651 -+#, c-format -+msgid "Leaving uid as %s (%ld)\n" -+msgstr "UID bleibt %s (%ld)\n" -+ -+#: ../../src/clients/ksu/main.c:654 -+#, c-format -+msgid "Changing uid to %s (%ld)\n" -+msgstr "UID wird zu %s (%ld) geändert\n" -+ -+#: ../../src/clients/ksu/main.c:680 -+msgid "while getting name of target ccache" -+msgstr "beim Holen des Ziel-Ccache-Namens" -+ -+#: ../../src/clients/ksu/main.c:700 -+#, c-format -+msgid "%s does not have correct permissions for %s, %s aborted" -+msgstr "%s hat nicht die korrekten Rechte für %s, %s wird abgebrochen." -+ -+#: ../../src/clients/ksu/main.c:721 -+#, c-format -+msgid "Internal error: command %s did not get resolved\n" -+msgstr "Interner Fehler: Befehl %s wurde nicht aufgelöst\n" -+ -+#: ../../src/clients/ksu/main.c:738 ../../src/clients/ksu/main.c:774 -+#, c-format -+msgid "while trying to execv %s" -+msgstr "beim Versuch von »execv %s«" -+ -+#: ../../src/clients/ksu/main.c:764 -+msgid "while calling waitpid" -+msgstr "beim Aufruf von »waitpid«" -+ -+#: ../../src/clients/ksu/main.c:769 -+msgid "while trying to fork." -+msgstr "beim Versuch zu verzweigen." -+ -+#: ../../src/clients/ksu/main.c:791 -+msgid "while reading cache name from ccache" -+msgstr "beim Lesen des Zwischenspeichernamens aus dem Ccache" -+ -+#: ../../src/clients/ksu/main.c:797 -+#, c-format -+msgid "ksu: couldn't set environment variable %s\n" -+msgstr "ksu: Umgebungsvariable %s kann nicht gesetzt werden\n" -+ -+#: ../../src/clients/ksu/main.c:820 -+#, c-format -+msgid "while clearing the value of %s" -+msgstr "beim Leeren des Werts von %s" -+ -+#: ../../src/clients/ksu/main.c:828 -+msgid "while resetting target ccache name" -+msgstr "beim Zurücksetzen des Ziel-Ccache-Namens" -+ -+#: ../../src/clients/ksu/main.c:842 -+msgid "while determining target ccache name" -+msgstr "beim Bestimmen des Ziel-Ccache-Namens" -+ -+#: ../../src/clients/ksu/main.c:881 -+msgid "while generating part of the target ccache name" -+msgstr "beim Erzeugen eines Teils des Ziel-Ccache-Namens" -+ -+#: ../../src/clients/ksu/main.c:887 -+msgid "while allocating memory for the target ccache name" -+msgstr "beim Reservieren von Speicher für den Ziel-Ccache-Namen" -+ -+#: ../../src/clients/ksu/main.c:906 -+msgid "while creating new target ccache" -+msgstr "bei Erstellen von neuem Ziel-Ccache" -+ -+#: ../../src/clients/ksu/main.c:912 -+msgid "while initializing target cache" -+msgstr "beim Initialisieren des Zielzwischenspeichers" -+ -+#: ../../src/clients/ksu/main.c:952 -+#, c-format -+msgid "terminal name %s too long\n" -+msgstr "Terminal-Name %s ist zu lang.\n" -+ -+#: ../../src/clients/ksu/main.c:980 -+msgid "while changing to target uid for destroying ccache" -+msgstr "beim Ändern der Ziel-UID für das Zerstören von Ccache" -+ -+#: ../../src/clients/kswitch/kswitch.c:44 -+#, c-format -+msgid "Usage: %s {-c cache_name | -p principal}\n" -+msgstr "Aufruf: %s {-c Zwischenspeichername | -p Principal}\n" -+ -+#: ../../src/clients/kswitch/kswitch.c:46 -+#, c-format -+msgid "\t-p specify name of principal\n" -+msgstr "\t-p gibt den Namen des Principals an.\n" -+ -+#: ../../src/clients/kswitch/kswitch.c:69 -+#, c-format -+msgid "Only one -c or -p option allowed\n" -+msgstr "Nur eine der Optionen -c oder -p ist erlaubt.\n" -+ -+#: ../../src/clients/kswitch/kswitch.c:88 -+#, c-format -+msgid "One of -c or -p must be specified\n" -+msgstr "Entweder -c oder -p muss angegeben werden.\n" -+ -+#: ../../src/clients/kswitch/kswitch.c:110 ../../src/clients/kvno/kvno.c:211 -+#: ../../src/clients/kvno/kvno.c:245 ../../src/kadmin/cli/keytab.c:350 -+#: ../../src/kadmin/dbutil/kdb5_util.c:576 -+#, c-format -+msgid "while parsing principal name %s" -+msgstr "beim Auswerten des Principal-Namens %s" -+ -+#: ../../src/clients/kswitch/kswitch.c:124 -+msgid "while switching to credential cache" -+msgstr "beim Wechsel auf den Anmeldedatenzwischenspeicher" -+ -+#: ../../src/clients/kvno/kvno.c:46 -+#, c-format -+msgid "usage: %s [-C] [-u] [-c ccache] [-e etype]\n" -+msgstr "Aufruf: %s [-C] [-u] [-c Ccache] [-e Etype]\n" -+ -+#: ../../src/clients/kvno/kvno.c:47 -+#, c-format -+msgid "\t[-k keytab] [-S sname] [-U for_user [-P]]\n" -+msgstr "\t[-k Schlüsseltabelle] [-S Sname] [-U für_Benutzer [-P]]\n" -+ -+#: ../../src/clients/kvno/kvno.c:48 -+#, c-format -+msgid "\tservice1 service2 ...\n" -+msgstr "\tDienst1 Dienst2 …\n" -+ -+#: ../../src/clients/kvno/kvno.c:103 ../../src/clients/kvno/kvno.c:111 -+#, c-format -+msgid "Options -u and -S are mutually exclusive\n" -+msgstr "Die Optionen -u und -S schließen sich gegenseitig aus.\n" -+ -+#: ../../src/clients/kvno/kvno.c:126 -+#, c-format -+msgid "Option -P (constrained delegation) requires keytab to be specified\n" -+msgstr "" -+"Die Option -P (eingeschränkte Abtretung) erfordert zur Angabe eine " -+"Schlüsseltabelle.\n" -+ -+#: ../../src/clients/kvno/kvno.c:130 -+#, c-format -+msgid "" -+"Option -P (constrained delegation) requires option -U (protocol transition)\n" -+msgstr "" -+"Die Option -P (eingeschränkte Abtretung) erfordert die Option -U " -+"(Protokollübergang)\n" -+ -+#: ../../src/clients/kvno/kvno.c:175 ../../src/kadmin/cli/kadmin.c:280 -+msgid "while initializing krb5 library" -+msgstr "beim Initialisieren der Krb5-Bibliothek" -+ -+#: ../../src/clients/kvno/kvno.c:182 -+msgid "while converting etype" -+msgstr "bei der Etype-Umwandlung" -+ -+#: ../../src/clients/kvno/kvno.c:218 -+msgid "while getting client principal name" -+msgstr "beim Holen des Client-Principal-Namens" -+ -+#: ../../src/clients/kvno/kvno.c:256 -+#, c-format -+msgid "while formatting parsed principal name for '%s'" -+msgstr "beim Formatieren des ausgewerteten Principal-Namens für »%s«" -+ -+#: ../../src/clients/kvno/kvno.c:267 -+msgid "client and server principal names must match" -+msgstr "Die Principal-Namen von Client und Server müssen übereinstimmen." -+ -+#: ../../src/clients/kvno/kvno.c:284 -+#, c-format -+msgid "while getting credentials for %s" -+msgstr "beim Holen der Anmeldedaten für %s" -+ -+#: ../../src/clients/kvno/kvno.c:291 -+#, c-format -+msgid "while decoding ticket for %s" -+msgstr "beim Dekodieren des Tickets für %s" -+ -+#: ../../src/clients/kvno/kvno.c:302 -+#, c-format -+msgid "while decrypting ticket for %s" -+msgstr "beim Entschlüsseln des Tickets für %s" -+ -+#: ../../src/clients/kvno/kvno.c:306 -+#, c-format -+msgid "%s: kvno = %d, keytab entry valid\n" -+msgstr "%s: KVNO = %d, Schlüsseltabelleneintrag gültig\n" -+ -+#: ../../src/clients/kvno/kvno.c:324 -+#, c-format -+msgid "%s: constrained delegation failed" -+msgstr "%s: eingeschränkte Abtretung fehlgeschlagen" -+ -+#: ../../src/clients/kvno/kvno.c:330 -+#, c-format -+msgid "%s: kvno = %d\n" -+msgstr "%s: KVNO = %d\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:118 -+#, c-format -+msgid "" -+"Usage: %s [-r realm] [-p principal] [-q query] [clnt|local args]\n" -+"\tclnt args: [-s admin_server[:port]] [[-c ccache]|[-k [-t keytab]]]|[-n]\n" -+"\tlocal args: [-x db_args]* [-d dbname] [-e \"enc:salt ...\"] [-m]\n" -+"where,\n" -+"\t[-x db_args]* - any number of database specific arguments.\n" -+"\t\t\tLook at each database documentation for supported arguments\n" -+msgstr "" -+"Aufruf: %s [-r Realm] [-p Principal] [-q Abfrage] [clnt|lokale Argumente]\n" -+"\tclnt Argumente: [-s Admin-Server[:Port]] [[-c Ccache]|\n" -+"\t[-k [-t Schlüsseltabelle]]]|[-n] lokale Argumente: [-x DB-Argumente]*\n" -+"\t[-d Datenbankname] [-e \"enc:Salt …\"] [-m]\n" -+"wobei\n" -+"\t[-x DB-Argumente]* - eine beliebige Anzahl datenbankspezifischer " -+"Argumente\n" -+"\tist. Die unterstützten Argumente finden Sie in den jeweiligen " -+"\tDatenbankdokumentationen\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:292 ../../src/kadmin/cli/kadmin.c:333 -+#, c-format -+msgid "%s: Cannot initialize. Not enough memory\n" -+msgstr "%s: Zu wenig Speicher zum Initialisieren\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:353 ../../src/kadmin/cli/kadmin.c:804 -+#: ../../src/kadmin/cli/kadmin.c:1084 ../../src/kadmin/cli/kadmin.c:1634 -+#: ../../src/kadmin/cli/keytab.c:159 ../../src/kadmin/dbutil/kdb5_util.c:591 -+#, c-format -+msgid "while parsing keysalts %s" -+msgstr "beim Auswerten der Schlüssel-Salts %s" -+ -+#: ../../src/kadmin/cli/kadmin.c:376 -+#, c-format -+msgid "%s: unable to get default realm\n" -+msgstr "%s: Standard-Realm kann nicht geholt werden\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:396 -+msgid "while opening default credentials cache" -+msgstr "beim Öffnen des Standardanmeldedatenzwischenspeichers" -+ -+#: ../../src/kadmin/cli/kadmin.c:402 -+#, c-format -+msgid "while opening credentials cache %s" -+msgstr "beim Öffnen des Anmeldedatenzwischenspeichers %s" -+ -+#: ../../src/kadmin/cli/kadmin.c:424 ../../src/kadmin/cli/kadmin.c:479 -+#: ../../src/kadmin/cli/kadmin.c:487 ../../src/kadmin/cli/kadmin.c:494 -+#, c-format -+msgid "%s: out of memory\n" -+msgstr "%s: Speicherplatz reicht nicht aus\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:433 ../../src/kadmin/cli/kadmin.c:448 -+#: ../../src/slave/kpropd.c:681 -+msgid "while canonicalizing principal name" -+msgstr "während der Principal-Name in die normale Form gebracht wird" -+ -+#: ../../src/kadmin/cli/kadmin.c:442 -+msgid "creating host service principal" -+msgstr "Principal des Rechnerdienstes wird erstellt" -+ -+#: ../../src/kadmin/cli/kadmin.c:455 -+#, c-format -+msgid "%s: unable to canonicalize principal\n" -+msgstr "%s: Principal kann nicht in die normale Form gebracht werden\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:499 -+#, c-format -+msgid "%s: unable to figure out a principal name\n" -+msgstr "%s: Es kann kein Principal-Name herausgefunden werden.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:507 -+msgid "while setting up logging" -+msgstr "beim Einrichten der Protokollierung" -+ -+#: ../../src/kadmin/cli/kadmin.c:516 -+#, c-format -+msgid "Authenticating as principal %s with existing credentials.\n" -+msgstr "Authentifizierung als Principal %s mit existierenden Anmeldedaten\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:522 -+#, c-format -+msgid "Authenticating as principal %s with password; anonymous requested.\n" -+msgstr "" -+"Authentifizierung als Principal %s mit Passwort; Anonymität erwünscht\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:529 -+#, c-format -+msgid "Authenticating as principal %s with keytab %s.\n" -+msgstr "Authentifizierung als Principal %s mit Schlüsseltabelle %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:532 -+#, c-format -+msgid "Authenticating as principal %s with default keytab.\n" -+msgstr "Authentifizierung als Principal %s mit Standardschlüsseltabelle\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:538 -+#, c-format -+msgid "Authenticating as principal %s with password.\n" -+msgstr "Authentifizierung als Principal %s mit Passwort\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:546 ../../src/slave/kpropd.c:728 -+#, c-format -+msgid "while initializing %s interface" -+msgstr "beim Initialisieren der Schnittstelle %s" -+ -+#: ../../src/kadmin/cli/kadmin.c:560 -+#, c-format -+msgid "while closing ccache %s" -+msgstr "beim Schließen von Ccache %s" -+ -+#: ../../src/kadmin/cli/kadmin.c:566 -+msgid "while mapping update log" -+msgstr "beim Abbilden des Aktualisierungsprotokolls" -+ -+#: ../../src/kadmin/cli/kadmin.c:581 -+msgid "while unlocking locked database" -+msgstr "beim Entsperren der Datenbank" -+ -+#: ../../src/kadmin/cli/kadmin.c:590 -+msgid "Administration credentials NOT DESTROYED.\n" -+msgstr "Verwaltungsanmeldedaten NICHT VERNICHTET\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:639 -+#, c-format -+msgid "usage: delete_principal [-force] principal\n" -+msgstr "Aufruf: delete_principal [-force] Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:644 ../../src/kadmin/cli/kadmin.c:819 -+msgid "while parsing principal name" -+msgstr "beim Auswerten des Principal-Namens" -+ -+#: ../../src/kadmin/cli/kadmin.c:650 ../../src/kadmin/cli/kadmin.c:825 -+#: ../../src/kadmin/cli/kadmin.c:1217 ../../src/kadmin/cli/kadmin.c:1339 -+#: ../../src/kadmin/cli/kadmin.c:1409 ../../src/kadmin/cli/kadmin.c:1858 -+#: ../../src/kadmin/cli/kadmin.c:1902 ../../src/kadmin/cli/kadmin.c:1948 -+#: ../../src/kadmin/cli/kadmin.c:1988 -+msgid "while canonicalizing principal" -+msgstr "während der Principal in die normale Form gebracht wird" -+ -+#: ../../src/kadmin/cli/kadmin.c:654 -+#, c-format -+msgid "Are you sure you want to delete the principal \"%s\"? (yes/no): " -+msgstr "" -+"Sind Sie sicher, dass Sie den Principal »%s« löschen möchten? (yes/no): " -+ -+#: ../../src/kadmin/cli/kadmin.c:658 -+#, c-format -+msgid "Principal \"%s\" not deleted\n" -+msgstr "Principal »%s« nicht gelöscht\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:665 -+#, c-format -+msgid "while deleting principal \"%s\"" -+msgstr "beim Löschen von Principal »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:668 -+#, c-format -+msgid "Principal \"%s\" deleted.\n" -+msgstr "Principal »%s« gelöscht\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:669 -+#, c-format -+msgid "" -+"Make sure that you have removed this principal from all ACLs before " -+"reusing.\n" -+msgstr "" -+"Stellen Sie sicher, dass Sie diesen Principal aus allen ACLs entfernt haben, " -+"bevor Sie ihn erneut benutzen.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:686 -+#, c-format -+msgid "usage: rename_principal [-force] old_principal new_principal\n" -+msgstr "Aufruf: rename_principal [-force] alter_Principal neuer_Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:693 -+msgid "while parsing old principal name" -+msgstr "beim Auswerten des alten Principal-Namens" -+ -+#: ../../src/kadmin/cli/kadmin.c:699 -+msgid "while parsing new principal name" -+msgstr "beim Auswerten des neuen Principal-Namens" -+ -+#: ../../src/kadmin/cli/kadmin.c:705 -+msgid "while canonicalizing old principal" -+msgstr "während der alte Principal in die normale Form gebracht wird" -+ -+#: ../../src/kadmin/cli/kadmin.c:711 -+msgid "while canonicalizing new principal" -+msgstr "während der neue Principal in die normale Form gebracht wird" -+ -+#: ../../src/kadmin/cli/kadmin.c:715 -+#, c-format -+msgid "" -+"Are you sure you want to rename the principal \"%s\" to \"%s\"? (yes/no): " -+msgstr "" -+"Sind Sie sicher, dass Sie den Principal »%s« in »%s« umbenennen möchten? " -+"(yes/no): " -+ -+#: ../../src/kadmin/cli/kadmin.c:719 -+#, c-format -+msgid "Principal \"%s\" not renamed\n" -+msgstr "Principal »%s« wurde nicht umbenannt.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:726 -+#, c-format -+msgid "while renaming principal \"%s\" to \"%s\"" -+msgstr "beim Umbenennen von Principal »%s« in »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:730 -+#, c-format -+msgid "Principal \"%s\" renamed to \"%s\".\n" -+msgstr "Principal »%s« wurde in »%s« umbenannt.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:731 -+#, c-format -+msgid "" -+"Make sure that you have removed the old principal from all ACLs before " -+"reusing.\n" -+msgstr "" -+"Stellen Sie sicher, dass Sie den alten Principal aus allen ACLs entfernt " -+"haben, bevor Sie ihn erneut benutzen.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:746 -+#, c-format -+msgid "" -+"usage: change_password [-randkey] [-keepold] [-e keysaltlist] [-pw password] " -+"principal\n" -+msgstr "" -+"Aufruf: change_password [-randkey] [-keepold] [-e Schlüssel-Salt-Liste] [-pw " -+"Passwort] Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:772 -+msgid "change_password: missing db argument" -+msgstr "change_password: fehlendes Datenbankargument" -+ -+#: ../../src/kadmin/cli/kadmin.c:778 -+#, c-format -+msgid "change_password: Not enough memory\n" -+msgstr "change_password: zu wenig Speicher\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:786 -+msgid "change_password: missing password arg" -+msgstr "change_password: fehlendes Passwortargument" -+ -+#: ../../src/kadmin/cli/kadmin.c:797 -+msgid "change_password: missing keysaltlist arg" -+msgstr "change_password: fehlendes Schlüssel-Salt-Listenargument" -+ -+#: ../../src/kadmin/cli/kadmin.c:813 -+msgid "missing principal name" -+msgstr "fehlender Principal-Name" -+ -+#: ../../src/kadmin/cli/kadmin.c:837 ../../src/kadmin/cli/kadmin.c:874 -+#, c-format -+msgid "while changing password for \"%s\"." -+msgstr "beim Ändern des Passworts von »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:840 ../../src/kadmin/cli/kadmin.c:877 -+#, c-format -+msgid "Password for \"%s\" changed.\n" -+msgstr "Passwort von »%s« geändert\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:846 ../../src/kadmin/cli/kadmin.c:1290 -+#, c-format -+msgid "while randomizing key for \"%s\"." -+msgstr "beim Erzeugen eines zufälligen Schlüssels für »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:849 -+#, c-format -+msgid "Key for \"%s\" randomized.\n" -+msgstr "Es wurde ein zufälliger Schlüssel für %s erzeugt\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:854 ../../src/kadmin/cli/kadmin.c:1250 -+#, c-format -+msgid "Enter password for principal \"%s\"" -+msgstr "Geben Sie das Passwort für Principal »%s« ein." -+ -+#: ../../src/kadmin/cli/kadmin.c:856 ../../src/kadmin/cli/kadmin.c:1252 -+#, c-format -+msgid "Re-enter password for principal \"%s\"" -+msgstr "Geben Sie das Passwort für Principal »%s« erneut ein." -+ -+#: ../../src/kadmin/cli/kadmin.c:861 ../../src/kadmin/cli/kadmin.c:1256 -+#, c-format -+msgid "while reading password for \"%s\"." -+msgstr "beim Lesen des Passworts von »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:915 -+#, c-format -+msgid "Not enough memory\n" -+msgstr "Speicher reicht nicht aus\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:945 ../../src/kadmin/dbutil/kdb5_util.c:623 -+msgid "while getting time" -+msgstr "beim Holen der Zeit" -+ -+#: ../../src/kadmin/cli/kadmin.c:994 ../../src/kadmin/cli/kadmin.c:1007 -+#: ../../src/kadmin/cli/kadmin.c:1020 ../../src/kadmin/cli/kadmin.c:1033 -+#: ../../src/kadmin/cli/kadmin.c:1546 ../../src/kadmin/cli/kadmin.c:1558 -+#: ../../src/kadmin/cli/kadmin.c:1601 ../../src/kadmin/cli/kadmin.c:1618 -+#, c-format -+msgid "Invalid date specification \"%s\".\n" -+msgstr "ungültige Datumsangabe »%s«\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1118 ../../src/kadmin/cli/kadmin.c:1333 -+#: ../../src/kadmin/cli/kadmin.c:1404 ../../src/kadmin/cli/kadmin.c:1852 -+#: ../../src/kadmin/cli/kadmin.c:1896 ../../src/kadmin/cli/kadmin.c:1942 -+#: ../../src/kadmin/cli/kadmin.c:1982 -+msgid "while parsing principal" -+msgstr "beim Auswerten des Principals" -+ -+#: ../../src/kadmin/cli/kadmin.c:1127 -+#, c-format -+msgid "usage: add_principal [options] principal\n" -+msgstr "Aufruf: add_principal [Optionen] Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1128 ../../src/kadmin/cli/kadmin.c:1155 -+#: ../../src/kadmin/cli/kadmin.c:1657 -+#, c-format -+msgid "\toptions are:\n" -+msgstr "\tEs gibt folgende Optionen:\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1130 -+#, c-format -+msgid "" -+"\t\t[-randkey|-nokey] [-x db_princ_args]* [-expire expdate] [-pwexpire " -+"pwexpdate] [-maxlife maxtixlife]\n" -+"\t\t[-kvno kvno] [-policy policy] [-clearpolicy]\n" -+"\t\t[-pw password] [-maxrenewlife maxrenewlife]\n" -+"\t\t[-e keysaltlist]\n" -+"\t\t[{+|-}attribute]\n" -+msgstr "" -+"\t\t[-randkey|-nokey] [-x DB-Principal-Argumente]* [-expire Ablaufdatum] [-" -+"pwexpire Passwortablaufdatum] [-maxlife maximale_Ticketlebensdauer]\n" -+"\t\t[-kvno KVNO] [-policy Richtlinie] [-clearpolicy]\n" -+"\t\t[-pw Passwort] [-maxrenewlife maximale_Dauer_bis_zum_Erneuern]\n" -+"\t\t[-e Schlüssel-Salt-Liste]\n" -+"\t\t[{+|-}Attribut]\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1136 -+#, c-format -+msgid "\tattributes are:\n" -+msgstr "\tEs gibt folgende Attribute:\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1138 ../../src/kadmin/cli/kadmin.c:1164 -+#, c-format -+msgid "" -+"\t\tallow_postdated allow_forwardable allow_tgs_req allow_renewable\n" -+"\t\tallow_proxiable allow_dup_skey allow_tix requires_preauth\n" -+"\t\trequires_hwauth needchange allow_svr password_changing_service\n" -+"\t\tok_as_delegate ok_to_auth_as_delegate no_auth_data_required\n" -+"\n" -+"where,\n" -+"\t[-x db_princ_args]* - any number of database specific arguments.\n" -+"\t\t\tLook at each database documentation for supported arguments\n" -+msgstr "" -+"\t\tallow_postdated allow_forwardable allow_tgs_req allow_renewable\n" -+"\t\tallow_proxiable allow_dup_skey allow_tix requires_preauth\n" -+"\t\trequires_hwauth needchange allow_svr password_changing_service\n" -+"\t\tok_as_delegate ok_to_auth_as_delegate no_auth_data_required\n" -+"\n" -+"wobei\n" -+"\t[-x DB-Principal-Argumente]* - eine beliebige Zahl\n" -+"\tdatenbankspezifischer Argumente ist.\n" -+"\t\t\tDie unterstützten Argumente finden Sie in der jeweiligen\n" -+"Datenbankdokumentation.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1154 -+#, c-format -+msgid "usage: modify_principal [options] principal\n" -+msgstr "Aufruf: modify_principal [Optionen] Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1157 -+#, c-format -+msgid "" -+"\t\t[-x db_princ_args]* [-expire expdate] [-pwexpire pwexpdate] [-maxlife " -+"maxtixlife]\n" -+"\t\t[-kvno kvno] [-policy policy] [-clearpolicy]\n" -+"\t\t[-maxrenewlife maxrenewlife] [-unlock] [{+|-}attribute]\n" -+msgstr "" -+"\t\t[-x DB-Principal-Argumente]* [-expire Ablaufdatum] [-pwexpire " -+"Passwortablaufdatum] [-maxlife maximale_Ticketlebensdauer]\n" -+"\t\t[-kvno KVNO] [-policy Richtlinie] [-clearpolicy]\n" -+"\t\t[-maxrenewlife maximale_Dauer_bis_zum_Erneuern] [-unlock] [{+|-}" -+"Attribut]\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1224 ../../src/kadmin/cli/kadmin.c:1362 -+#, c-format -+msgid "WARNING: policy \"%s\" does not exist\n" -+msgstr "WARNUNG: Richtlinie »%s« existiert nicht.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1230 -+#, c-format -+msgid "NOTICE: no policy specified for %s; assigning \"default\"\n" -+msgstr "" -+"HINWEIS: Für %s wurde keine Richtlinie angegeben, es wird »default« " -+"zugewiesen\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1235 -+#, c-format -+msgid "WARNING: no policy specified for %s; defaulting to no policy\n" -+msgstr "" -+"WARNUNG: Für %s wurde keine Richtlinie angegeben, es wird die Vorgabe " -+"»keine\n" -+"Richtlinie« verwandt.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1276 -+#, c-format -+msgid "Admin server does not support -nokey while creating \"%s\"\n" -+msgstr "" -+"Der Administrationsrechner unterstützt beim Erstellen von »%s« kein -nokey\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1298 -+#, c-format -+msgid "while clearing DISALLOW_ALL_TIX for \"%s\"." -+msgstr "beim Löschen von DISALLOW_ALL_TIX für »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:1345 -+#, c-format -+msgid "while getting \"%s\"." -+msgstr "beim Holen von »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:1371 -+#, c-format -+msgid "while modifying \"%s\"." -+msgstr "beim Ändern von »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:1375 -+#, c-format -+msgid "Principal \"%s\" modified.\n" -+msgstr "Principal »%s« wurde geändert.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1396 -+#, c-format -+msgid "usage: get_principal [-terse] principal\n" -+msgstr "Aufruf: get_principal [-terse] Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1415 -+#, c-format -+msgid "while retrieving \"%s\"." -+msgstr "beim Abfragen von »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:1420 ../../src/kadmin/cli/kadmin.c:1425 -+msgid "while unparsing principal" -+msgstr "beim Rückgängigmachen der Auswertung des Principals" -+ -+#: ../../src/kadmin/cli/kadmin.c:1429 -+#, c-format -+msgid "Principal: %s\n" -+msgstr "Principal: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1430 -+#, c-format -+msgid "Expiration date: %s\n" -+msgstr "Ablaufdatum: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1431 ../../src/kadmin/cli/kadmin.c:1433 -+#: ../../src/kadmin/cli/kadmin.c:1444 -+msgid "[never]" -+msgstr "[niemals]" -+ -+#: ../../src/kadmin/cli/kadmin.c:1432 -+#, c-format -+msgid "Last password change: %s\n" -+msgstr "Letzte Passwortänderung: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1434 -+#, c-format -+msgid "Password expiration date: %s\n" -+msgstr "Passwortablaufdatum: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1436 ../../src/kadmin/cli/kadmin.c:1478 -+msgid "[none]" -+msgstr "[keins]" -+ -+#: ../../src/kadmin/cli/kadmin.c:1437 -+#, c-format -+msgid "Maximum ticket life: %s\n" -+msgstr "maximale Ticketlebensdauer: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1438 -+#, c-format -+msgid "Maximum renewable life: %s\n" -+msgstr "maximale verlängerbare Lebensdauer: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1440 -+#, c-format -+msgid "Last modified: %s (%s)\n" -+msgstr "zuletzt geändert: %s (%s)\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1442 -+#, c-format -+msgid "Last successful authentication: %s\n" -+msgstr "letzte erfolgreiche Authentifizierung: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1448 -+#, c-format -+msgid "Failed password attempts: %d\n" -+msgstr "Fehlgeschlagene Anmeldeversuche: %d\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1450 -+#, c-format -+msgid "Number of keys: %d\n" -+msgstr "Anzahl der Schlüssel: %d\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1457 -+#, c-format -+msgid "" -+msgstr "" -+ -+#: ../../src/kadmin/cli/kadmin.c:1464 -+#, c-format -+msgid "" -+msgstr "" -+ -+#: ../../src/kadmin/cli/kadmin.c:1470 -+#, c-format -+msgid "MKey: vno %d\n" -+msgstr "MKey: vno %d\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1472 -+#, c-format -+msgid "Attributes:" -+msgstr "Attribute:" -+ -+#: ../../src/kadmin/cli/kadmin.c:1480 -+msgid " [does not exist]" -+msgstr " [existiert nicht]" -+ -+#: ../../src/kadmin/cli/kadmin.c:1481 -+#, c-format -+msgid "Policy: %s%s\n" -+msgstr "Richtlinie: %s%s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1517 -+#, c-format -+msgid "usage: get_principals [expression]\n" -+msgstr "Aufruf: get_principals [Ausdruck]\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1522 ../../src/kadmin/cli/kadmin.c:1794 -+msgid "while retrieving list." -+msgstr "beim Abfragen der Liste." -+ -+#: ../../src/kadmin/cli/kadmin.c:1647 -+#, c-format -+msgid "%s: parser lost count!\n" -+msgstr "%s: Auswertungsprogramm verlor Anzahl!\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1656 -+#, c-format -+msgid "usage; %s [options] policy\n" -+msgstr "Aufruf: %s [Optionen] Richtlinie\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1659 -+#, c-format -+msgid "" -+"\t\t[-maxlife time] [-minlife time] [-minlength length]\n" -+"\t\t[-minclasses number] [-history number]\n" -+"\t\t[-maxfailure number] [-failurecountinterval time]\n" -+"\t\t[-allowedkeysalts keysalts]\n" -+msgstr "" -+"\t\t[-maxlife Zeit] [-minlife Zeit] [-minlength Länge]\n" -+"\t\t[-minclasses Anzahl] [-history Nummer]\n" -+"\t\t[-maxfailure Anzahl] [-failurecountinterval Zeit]\n" -+"\t\t[-allowedkeysalts Schlüssel-Salts]\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1663 -+#, c-format -+msgid "\t\t[-lockoutduration time]\n" -+msgstr "\t\t[-lockoutduration Dauer]\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1682 -+#, c-format -+msgid "while creating policy \"%s\"." -+msgstr "beim Erstellen der Richtlinie »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:1703 -+#, c-format -+msgid "while modifying policy \"%s\"." -+msgstr "beim Ändern der Richtlinie »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:1715 -+#, c-format -+msgid "usage: delete_policy [-force] policy\n" -+msgstr "Aufruf: delete_policy [-force] Richtlinie\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1719 -+#, c-format -+msgid "Are you sure you want to delete the policy \"%s\"? (yes/no): " -+msgstr "" -+"Sind Sie sicher, dass Sie die Richtlinie »%s« löschen möchten? (yes/no): " -+ -+#: ../../src/kadmin/cli/kadmin.c:1723 -+#, c-format -+msgid "Policy \"%s\" not deleted.\n" -+msgstr "Richtlinie »%s« nicht gelöscht\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1729 -+#, c-format -+msgid "while deleting policy \"%s\"" -+msgstr "bei Löschen der Richtlinie »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:1741 -+#, c-format -+msgid "usage: get_policy [-terse] policy\n" -+msgstr "Aufruf: get_policy [-terse] Richtlinie\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1746 -+#, c-format -+msgid "while retrieving policy \"%s\"." -+msgstr "beim Abfragen der Richtlinie »%s«." -+ -+#: ../../src/kadmin/cli/kadmin.c:1751 -+#, c-format -+msgid "Policy: %s\n" -+msgstr "Richtlinie: »%s«\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1752 -+#, c-format -+msgid "Maximum password life: %ld\n" -+msgstr "maximale Passwortlebensdauer: %ld\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1753 -+#, c-format -+msgid "Minimum password life: %ld\n" -+msgstr "minimale Passwortlebensdauer: %ld\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1754 -+#, c-format -+msgid "Minimum password length: %ld\n" -+msgstr "minimale Passwortlänge: %ld\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1755 -+#, c-format -+msgid "Minimum number of password character classes: %ld\n" -+msgstr "minimale Anzahl von Passwortzeichenklassen: %ld\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1757 -+#, c-format -+msgid "Number of old keys kept: %ld\n" -+msgstr "Anzahl aufbewahrter alter Schlüssel: %ld\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1758 -+#, c-format -+msgid "Maximum password failures before lockout: %lu\n" -+msgstr "maximale Anzahl falscher Passworteingaben vor dem Sperren: %lu\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1760 -+#, c-format -+msgid "Password failure count reset interval: %s\n" -+msgstr "Rücksetzintervall für zu viele falsch eingebene Passwörter: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1762 -+#, c-format -+msgid "Password lockout duration: %s\n" -+msgstr "Passwortsperrdauer: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1765 -+#, c-format -+msgid "Allowed key/salt types: %s\n" -+msgstr "erlaubte Schlüssel-/Salt-Typen: %s\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1789 -+#, c-format -+msgid "usage: get_policies [expression]\n" -+msgstr "Aufruf: get_policies [Ausdruck]\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1811 -+#, c-format -+msgid "usage: get_privs\n" -+msgstr "Aufruf: get_privs\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1816 -+msgid "while retrieving privileges" -+msgstr "beim Abfragen von Rechten" -+ -+#: ../../src/kadmin/cli/kadmin.c:1819 -+#, c-format -+msgid "current privileges:" -+msgstr "aktuelle Rechte:" -+ -+#: ../../src/kadmin/cli/kadmin.c:1845 -+#, c-format -+msgid "usage: purgekeys [-all|-keepkvno oldest_kvno_to_keep] principal\n" -+msgstr "" -+"Aufruf: purgekeys [-all|-keepkvno älteste_KVNO_die_behalten_wird] Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1865 -+#, c-format -+msgid "while purging keys for principal \"%s\"" -+msgstr "beim vollständigen Löschen der Schlüssel für Principal »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:1870 -+#, c-format -+msgid "All keys for principal \"%s\" removed.\n" -+msgstr "Alle Schlüssel für Principal »%s« wurden entfernt.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1872 -+#, c-format -+msgid "Old keys for principal \"%s\" purged.\n" -+msgstr "Alte Schlüssel für Principal »%s« wurden entfernt.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1889 -+#, c-format -+msgid "usage: get_strings principal\n" -+msgstr "Aufruf: get_strings Principal\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1909 -+#, c-format -+msgid "while getting attributes for principal \"%s\"" -+msgstr "beim Holen von Attributen für Principal »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:1914 -+#, c-format -+msgid "(No string attributes.)\n" -+msgstr "(keine Zeichenkettenattribute)\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1933 -+#, c-format -+msgid "usage: set_string principal key value\n" -+msgstr "Aufruf: set_string Principal Schlüssel Wert\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1955 -+#, c-format -+msgid "while setting attribute on principal \"%s\"" -+msgstr "beim Setzen eines Attributes für Principal »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:1959 -+#, c-format -+msgid "Attribute set for principal \"%s\".\n" -+msgstr "Attribute für Principal »%s« wurden gesetzt.\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1974 -+#, c-format -+msgid "usage: del_string principal key\n" -+msgstr "Aufruf: del_string Principal Schlüssel\n" -+ -+#: ../../src/kadmin/cli/kadmin.c:1995 -+#, c-format -+msgid "while deleting attribute from principal \"%s\"" -+msgstr "beim Löschen eines Attributs von Principal »%s«" -+ -+#: ../../src/kadmin/cli/kadmin.c:1999 -+#, c-format -+msgid "Attribute removed from principal \"%s\".\n" -+msgstr "Attribut von Principal »%s« wurde gelöscht.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:56 -+#, c-format -+msgid "" -+"Usage: ktadd [-k[eytab] keytab] [-q] [-e keysaltlist] [-norandkey] " -+"[principal | -glob princ-exp] [...]\n" -+msgstr "" -+"Aufruf: ktadd [-k[eytab] Schlüsseltabelle] [-q] [-e Schlüssel-Salt-Liste] [-" -+"norandkey] [Principal | -glob Principal-Ausdruck] […]\n" -+ -+#: ../../src/kadmin/cli/keytab.c:59 -+#, c-format -+msgid "" -+"Usage: ktadd [-k[eytab] keytab] [-q] [-e keysaltlist] [principal | -glob " -+"princ-exp] [...]\n" -+msgstr "" -+"Aufruf: ktadd [-k[eytab] Schlüsseltabelle] [-q] [-e Schlüssel-Salt-Liste] " -+"[Principal | -glob Principal-Ausdruck] […]\n" -+ -+#: ../../src/kadmin/cli/keytab.c:67 -+#, c-format -+msgid "" -+"Usage: ktremove [-k[eytab] keytab] [-q] principal [kvno|\"all\"|\"old\"]\n" -+msgstr "" -+"Aufruf: ktremove [-k[eytab] Schlüsseltabelle] [-q] Principal " -+"[kvno|»all«|»old«]\n" -+ -+#: ../../src/kadmin/cli/keytab.c:81 ../../src/kadmin/cli/keytab.c:102 -+msgid "while creating keytab name" -+msgstr "beim Erstellen des Schlüsseltabellennamens" -+ -+#: ../../src/kadmin/cli/keytab.c:86 -+msgid "while opening default keytab" -+msgstr "beim Öffnen der Standardschlüsseltabelle" -+ -+#: ../../src/kadmin/cli/keytab.c:147 -+#, c-format -+msgid "-norandkey option only valid for kadmin.local\n" -+msgstr "Die Option »-norandkey« ist nur für »kadmin.local« gültig.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:176 -+#, c-format -+msgid "cannot specify keysaltlist when not changing key\n" -+msgstr "" -+"Schlüssel-Salt-Liste kann nicht angegeben werden, wenn der Schlüssel nicht " -+"geändert wird\n" -+ -+#: ../../src/kadmin/cli/keytab.c:192 -+#, c-format -+msgid "while expanding expression \"%s\"." -+msgstr "beim Expandieren des Ausdrucks »%s«." -+ -+#: ../../src/kadmin/cli/keytab.c:211 ../../src/kadmin/cli/keytab.c:251 -+msgid "while closing keytab" -+msgstr "beim Schließen der Schlüsseltabelle" -+ -+#: ../../src/kadmin/cli/keytab.c:275 -+#, c-format -+msgid "while parsing -add principal name %s" -+msgstr "beim Auswerten von »-add Principal-Name %s«" -+ -+#: ../../src/kadmin/cli/keytab.c:289 -+#, c-format -+msgid "%s: Principal %s does not exist.\n" -+msgstr "%s: Principal %s existiert nicht.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:292 -+#, c-format -+msgid "while changing %s's key" -+msgstr "beim Ändern des Schlüssels von %s" -+ -+#: ../../src/kadmin/cli/keytab.c:299 -+msgid "while retrieving principal" -+msgstr "beim Abfragen des Principals" -+ -+#: ../../src/kadmin/cli/keytab.c:311 -+msgid "while adding key to keytab" -+msgstr "beim Hinzufügen des Schlüssels zur Schlüsseltabelle" -+ -+#: ../../src/kadmin/cli/keytab.c:317 -+#, c-format -+msgid "" -+"Entry for principal %s with kvno %d, encryption type %s added to keytab %s.\n" -+msgstr "" -+"Der Eintrag für Principal %s mit KVNO %d und Verschlüsselungstyp %s wurde " -+"der Schlüsseltabelle %s hinzugefügt.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:326 -+msgid "while freeing principal entry" -+msgstr "beim Freigeben des Principal-Eintrags" -+ -+#: ../../src/kadmin/cli/keytab.c:373 -+#, c-format -+msgid "%s: Keytab %s does not exist.\n" -+msgstr "%s: Schlüsseltabelle %s existiert nicht.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:377 -+#, c-format -+msgid "%s: No entry for principal %s exists in keytab %s\n" -+msgstr "" -+"%s: Für Principal %s existiert kein Eintrag in der Schlüsseltabelle %s.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:381 -+#, c-format -+msgid "%s: No entry for principal %s with kvno %d exists in keytab %s\n" -+msgstr "" -+"%s: Für den Principal %s mit der KVNO %d existiert kein Eintrag in der " -+"Schlüsseltabelle %s.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:387 -+msgid "while retrieving highest kvno from keytab" -+msgstr "beim Abfragen der höchsten KVNO der Schlüsseltabelle" -+ -+#: ../../src/kadmin/cli/keytab.c:420 -+msgid "while temporarily ending keytab scan" -+msgstr "beim Unterbrechen des Schlüsseltabellen-Scans" -+ -+#: ../../src/kadmin/cli/keytab.c:425 -+msgid "while deleting entry from keytab" -+msgstr "beim Löschen eines Eintrags aus der Schlüsseltabelle" -+ -+#: ../../src/kadmin/cli/keytab.c:430 -+msgid "while restarting keytab scan" -+msgstr "bei der Wiederaufnahme des Schlüsseltabellen-Scans" -+ -+#: ../../src/kadmin/cli/keytab.c:436 -+#, c-format -+msgid "Entry for principal %s with kvno %d removed from keytab %s.\n" -+msgstr "" -+"Der Eintrag für Principal %s mit KVNO %d wurde aus der Schlüsseltabelle %s " -+"entfernt.\n" -+ -+#: ../../src/kadmin/cli/keytab.c:458 -+#, c-format -+msgid "%s: There is only one entry for principal %s in keytab %s\n" -+msgstr "" -+"%s: Es gibt nur einen Eintrag für Principal %s in der Schlüsseltabelle %s.\n" -+ -+#: ../../src/kadmin/cli/ss_wrapper.c:49 ../../src/kadmin/ktutil/ktutil.c:58 -+msgid "creating invocation" -+msgstr "Aufruf wird erstellt" -+ -+#: ../../src/kadmin/dbutil/dump.c:165 -+msgid "while allocating temporary filename dump" -+msgstr "beim Reservieren des temporären Dateinamenspeicherauszugs" -+ -+#: ../../src/kadmin/dbutil/dump.c:176 -+msgid "while renaming dump file into place" -+msgstr "während das Umbenennen der Auszugsdateien Gestalt annimmt" -+ -+#: ../../src/kadmin/dbutil/dump.c:192 -+msgid "while allocating dump_ok filename" -+msgstr "beim Reservieren des »dump_ok«-Dateinamens" -+ -+#: ../../src/kadmin/dbutil/dump.c:199 -+#, c-format -+msgid "while creating 'ok' file, '%s'" -+msgstr "beim Erstellen der Datei »ok«, »%s«" -+ -+#: ../../src/kadmin/dbutil/dump.c:206 -+#, c-format -+msgid "while locking 'ok' file, '%s'" -+msgstr "beim Sperren der Datei »ok«, »%s«" -+ -+#: ../../src/kadmin/dbutil/dump.c:248 ../../src/kadmin/dbutil/dump.c:277 -+#, c-format -+msgid "%s: regular expression error: %s\n" -+msgstr "%s: Fehler im regulären Ausdruck: %s\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:260 -+#, c-format -+msgid "%s: regular expression match error: %s\n" -+msgstr "%s: Fehler beim Abgleich mit regulärem Ausdruck: %s\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:361 -+#, c-format -+msgid "%s: tagged data list inconsistency for %s (counted %d, stored %d)\n" -+msgstr "" -+"%s: Unstimmigkeit in der markierten Datenliste für %s (%d gezählt, %d " -+"gespeichert)\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:519 -+#, c-format -+msgid "" -+"Warning! Multiple DES-CBC-CRC keys for principal %s; skipping duplicates.\n" -+msgstr "" -+"Warnung! Mehrere DES-CBC-CRC-Schlüssel für Principal %s, Duplikate werden " -+"übersprungen.\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:530 -+#, c-format -+msgid "" -+"Warning! No DES-CBC-CRC key for principal %s, cannot generate OV-compatible " -+"record; skipping\n" -+msgstr "" -+"Warnung! Kein DES-CBC-CRC-Schlüssel für Principal %s, es kann kein OV-" -+"kompatibler Datensatz erzeugt werden, wird übersprungen\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:558 -+#, c-format -+msgid "while converting %s to new master key" -+msgstr "beim Umwandeln von %s in den neuen Hauptschlüssel" -+ -+#: ../../src/kadmin/dbutil/dump.c:579 -+#, c-format -+msgid "%s(%d): %s\n" -+msgstr "%s(%d): %s\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:622 -+#, c-format -+msgid "%s(%d): ignoring trash at end of line: " -+msgstr "%s(%d): Müll am Zeilenende wird ignoriert: " -+ -+#: ../../src/kadmin/dbutil/dump.c:685 -+msgid "cannot read tagged data type and length" -+msgstr "Markierter Datentyp und Länge können nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:692 -+msgid "cannot read tagged data contents" -+msgstr "Inhalt der markierten Daten kann nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:726 -+msgid "cannot match size tokens" -+msgstr "Größenmerkmale können nicht zugeordnet werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:755 -+msgid "cannot read name string" -+msgstr "Namenszeichenkette kann nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:760 -+#, c-format -+msgid "while parsing name %s" -+msgstr "beim Auswerten des Namens %s" -+ -+#: ../../src/kadmin/dbutil/dump.c:768 -+msgid "cannot read principal attributes" -+msgstr "Principal-Attribute können nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:821 -+msgid "cannot read key size and version" -+msgstr "Schlüssellänge und -version können nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:832 -+msgid "cannot read key type and length" -+msgstr "Schlüsseltyp und -länge können nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:838 -+msgid "cannot read key data" -+msgstr "Schlüsseldaten können nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:848 -+msgid "cannot read extra data" -+msgstr "Zusätzliche Daten können nicht gelesen werden." -+ -+#: ../../src/kadmin/dbutil/dump.c:857 -+#, c-format -+msgid "while storing %s" -+msgstr "beim Speichern von %s" -+ -+#: ../../src/kadmin/dbutil/dump.c:896 ../../src/kadmin/dbutil/dump.c:935 -+#: ../../src/kadmin/dbutil/dump.c:981 -+#, c-format -+msgid "cannot parse policy (%d read)\n" -+msgstr "Richtlinie kann nicht ausgewertet werden (%d gelesen)\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:904 ../../src/kadmin/dbutil/dump.c:943 -+#: ../../src/kadmin/dbutil/dump.c:1001 -+msgid "while creating policy" -+msgstr "beim Erstellen der Richtlinie" -+ -+#: ../../src/kadmin/dbutil/dump.c:908 -+#, c-format -+msgid "created policy %s\n" -+msgstr "erstellte Richtlinie %s\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1038 -+#, c-format -+msgid "unknown record type \"%s\"\n" -+msgstr "unbekannter Datensatztyp »%s«\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1167 -+#, c-format -+msgid "%s: Unknown iprop dump version %d\n" -+msgstr "%s: unbekannte Iprop-Auszugsversion %d\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1270 ../../src/kadmin/dbutil/dump.c:1498 -+#, c-format -+msgid "Iprop not enabled\n" -+msgstr "Iprop nicht aktiviert\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1308 -+msgid "Conditional dump is an undocumented option for use only for iprop dumps" -+msgstr "" -+"Bedingter Auszug ist eine nicht dokumentierte Option, die nur für Iprop-" -+"Auszüge benutzt wird." -+ -+#: ../../src/kadmin/dbutil/dump.c:1321 -+msgid "Database not currently opened!" -+msgstr "Die Datenbank ist zur Zeit nicht geöffnet!" -+ -+#: ../../src/kadmin/dbutil/dump.c:1335 -+#: ../../src/kadmin/dbutil/kdb5_stash.c:116 -+#: ../../src/kadmin/dbutil/kdb5_util.c:479 -+msgid "while reading master key" -+msgstr "beim Lesen des Hauptschlüssels" -+ -+#: ../../src/kadmin/dbutil/dump.c:1341 -+msgid "while verifying master key" -+msgstr "beim Prüfen des Hauptschlüssels" -+ -+#: ../../src/kadmin/dbutil/dump.c:1360 ../../src/kadmin/dbutil/dump.c:1370 -+msgid "while reading new master key" -+msgstr "beim Lesen des neuen Hauptschlüssels" -+ -+#: ../../src/kadmin/dbutil/dump.c:1364 -+#, c-format -+msgid "Please enter new master key....\n" -+msgstr "Bitte geben Sie den neuen Hauptschlüssel ein …\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1388 -+#, c-format -+msgid "while opening %s for writing" -+msgstr "beim Öffnen von %s zum Schreiben" -+ -+#: ../../src/kadmin/dbutil/dump.c:1403 -+msgid "while reading update log header" -+msgstr "beim Lesen der Aktualisierungsprotokollkopfzeilen" -+ -+#: ../../src/kadmin/dbutil/dump.c:1418 ../../src/kadmin/dbutil/dump.c:1425 -+#, c-format -+msgid "performing %s dump" -+msgstr "Auszug von %s wird durchgeführt" -+ -+#: ../../src/kadmin/dbutil/dump.c:1455 -+#, c-format -+msgid "%s: error processing line %d of %s\n" -+msgstr "%s: Fehler beim Verarbeiten von Zeile %d von %s\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1507 -+msgid "while parsing options" -+msgstr "beim Auswerten der Optionen" -+ -+#: ../../src/kadmin/dbutil/dump.c:1522 -+#, c-format -+msgid "while opening %s" -+msgstr "beim Öffnen von %s" -+ -+#: ../../src/kadmin/dbutil/dump.c:1527 ../../src/kadmin/dbutil/dump.c:1626 -+msgid "standard input" -+msgstr "Standardeingabe" -+ -+#: ../../src/kadmin/dbutil/dump.c:1532 -+#, c-format -+msgid "%s: can't read dump header in %s\n" -+msgstr "%s: Kopfzeilen des Auszugs in %s können nicht gelesen werden.\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1540 ../../src/kadmin/dbutil/dump.c:1557 -+#, c-format -+msgid "%s: dump header bad in %s\n" -+msgstr "%s: falsche Kopfzeilen des Auszugs in %s\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1566 -+#, c-format -+msgid "Could not open iprop ulog\n" -+msgstr "Iprop-Ulog kann nicht geöffnet werden.\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1571 -+#, c-format -+msgid "%s: dump version %s can only be loaded with the -update flag\n" -+msgstr "" -+"%s: Die Auszugsversion %s kann nur mit dem Schalter -update geladen werden.\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1580 ../../src/kadmin/dbutil/dump.c:1585 -+msgid "computing parameters for database" -+msgstr "Parameter für die Datenbank werden berechnet." -+ -+#: ../../src/kadmin/dbutil/dump.c:1591 -+msgid "while creating database" -+msgstr "beim Erstellen der Datenbank" -+ -+#: ../../src/kadmin/dbutil/dump.c:1600 -+msgid "while opening database" -+msgstr "beim Öffnen der Datenbank" -+ -+#: ../../src/kadmin/dbutil/dump.c:1610 -+msgid "while permanently locking database" -+msgstr "beim dauerhaften Sperren der Datenbank" -+ -+#: ../../src/kadmin/dbutil/dump.c:1628 -+#, c-format -+msgid "%s: %s restore failed\n" -+msgstr "%s: Wiederherstellen von %s fehlgeschlagen\n" -+ -+#: ../../src/kadmin/dbutil/dump.c:1633 -+msgid "while unlocking database" -+msgstr "beim Aufheben der Datenbanksperre" -+ -+#: ../../src/kadmin/dbutil/dump.c:1643 ../../src/kadmin/dbutil/dump.c:1662 -+msgid "while reinitializing update log" -+msgstr "beim erneuten Initialisieren des Aktualisierungsprotokolls" -+ -+#: ../../src/kadmin/dbutil/dump.c:1653 -+msgid "while making newly loaded database live" -+msgstr "beim Aktivieren der neu geladenen Datenbank" -+ -+#: ../../src/kadmin/dbutil/dump.c:1669 -+msgid "while writing update log header" -+msgstr "beim Schreiben der Aktualisierungsprotokollkopfzeilen" -+ -+#: ../../src/kadmin/dbutil/dump.c:1683 -+#, c-format -+msgid "while deleting bad database %s" -+msgstr "beim Löschen der falschen Datenbank %s" -+ -+#: ../../src/kadmin/dbutil/kadm5_create.c:84 -+msgid "while looking up the Kerberos configuration" -+msgstr "beim Nachschlagen der Kerberos-Konfiguration" -+ -+#: ../../src/kadmin/dbutil/kadm5_create.c:111 -+msgid "while initializing the Kerberos admin interface" -+msgstr "beim Initialisieren der Kerberos-Administrationsoberfläche" -+ -+#: ../../src/kadmin/dbutil/kadm5_create.c:169 -+#, c-format -+msgid "getaddrinfo(%s): Cannot determine canonical hostname.\n" -+msgstr "" -+"getaddrinfo(%s): Die Normalform des Rechnernamens kann nicht bestimmt " -+"werden.\n" -+ -+#: ../../src/kadmin/dbutil/kadm5_create.c:190 -+#: ../../src/kadmin/dbutil/kadm5_create.c:196 -+#, c-format -+msgid "Out of memory\n" -+msgstr "Speicherplatz reicht nicht aus.\n" -+ -+#: ../../src/kadmin/dbutil/kadm5_create.c:270 -+msgid "while appending realm to principal" -+msgstr "beim Anhängen des Realms an den Principal" -+ -+#: ../../src/kadmin/dbutil/kadm5_create.c:275 -+msgid "while parsing admin principal name" -+msgstr "beim Auswerten des Principal-Namens des Administrators" -+ -+#: ../../src/kadmin/dbutil/kadm5_create.c:286 -+#, c-format -+msgid "while creating principal %s" -+msgstr "beim Erstellen des Principals %s" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:175 -+#: ../../src/kadmin/dbutil/kdb5_util.c:241 -+#: ../../src/kadmin/dbutil/kdb5_util.c:248 -+msgid "while parsing command arguments\n" -+msgstr "beim Auswerten der Befehlsargumente\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:198 -+#, c-format -+msgid "Loading random data\n" -+msgstr "Zufällige Daten werden geladen.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:201 -+msgid "Loading random data" -+msgstr "Zufällige Daten werden geladen." -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:211 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:242 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:435 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:591 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1149 -+#: ../../src/kadmin/dbutil/kdb5_util.c:423 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:606 -+msgid "while setting up master key name" -+msgstr "beim Einrichten des Hauptschlüsselnamens" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:222 -+#, c-format -+msgid "" -+"Initializing database '%s' for realm '%s',\n" -+"master key name '%s'\n" -+msgstr "" -+"Datenbank »%s« für Realm »%s« wird initialisiert,\n" -+"Hauptschlüsselname »%s«\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:227 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:516 -+#, c-format -+msgid "You will be prompted for the database Master Password.\n" -+msgstr "Sie werden nach dem Master-Passwort der Datenbank gefragt.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:228 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:260 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:517 -+#, c-format -+msgid "It is important that you NOT FORGET this password.\n" -+msgstr "Es ist wichtig, dass Sie dieses Passwort NICHT VERGESSEN.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:234 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:266 -+msgid "while creating new master key" -+msgstr "beim Erstellen des neuen Hauptschlüssels" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:242 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:527 -+msgid "while reading master key from keyboard" -+msgstr "beim Lesen des Hauptschlüssels von der Tastatur" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:252 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:285 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:618 -+msgid "while calculating master key salt" -+msgstr "beim Berechnen des Hauptschlüssel-Salts" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:260 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:294 -+#: ../../src/kadmin/dbutil/kdb5_util.c:465 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:630 -+msgid "while transforming master key from password" -+msgstr "beim Umwandeln des Hauptschlüssels vom Passwort" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:270 -+msgid "while initializing random key generator" -+msgstr "beim Initialisieren des Zufallsschlüsselgenerators" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:275 -+#, c-format -+msgid "while creating database '%s'" -+msgstr "beim Erstellen der Datenbank »%s«" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:293 -+msgid "while creating update log" -+msgstr "beim Erstellen des Aktualisierungsprotokolls" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:304 -+msgid "while initializing update log" -+msgstr "beim Initialisieren des Aktualisierungsprotokolls" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:320 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:642 -+msgid "while adding entries to the database" -+msgstr "beim Hinzufügen von Einträgen in die Datenbank" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:348 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:339 -+#: ../../src/kadmin/dbutil/kdb5_stash.c:133 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:667 -+msgid "while storing key" -+msgstr "beim Speichern des Schlüssels" -+ -+#: ../../src/kadmin/dbutil/kdb5_create.c:349 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:340 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:668 -+#, c-format -+msgid "Warning: couldn't stash master key.\n" -+msgstr "Warnung: Hauptschlüssel kann nicht gelagert werden.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_destroy.c:57 -+msgid "while initializing krb5_context" -+msgstr "beim Initialisieren von »krb5_context«" -+ -+#: ../../src/kadmin/dbutil/kdb5_destroy.c:63 -+#: ../../src/kadmin/dbutil/kdb5_util.c:259 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:291 -+msgid "while setting default realm name" -+msgstr "beim Einstellen des Standard-Realm-Namens" -+ -+#: ../../src/kadmin/dbutil/kdb5_destroy.c:83 -+#, c-format -+msgid "Deleting KDC database stored in '%s', are you sure?\n" -+msgstr "" -+"Die in »%s« gespeicherte KDC-Datenbank wird gelöscht. Sind Sie sicher?\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_destroy.c:85 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1166 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:360 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1482 -+#, c-format -+msgid "(type 'yes' to confirm)? " -+msgstr "(Geben Sie als Bestätigung »yes« ein)? " -+ -+#: ../../src/kadmin/dbutil/kdb5_destroy.c:92 -+#, c-format -+msgid "OK, deleting database '%s'...\n" -+msgstr "OK, Datenbank »%s« wird gelöscht …\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_destroy.c:97 -+#, c-format -+msgid "deleting database '%s'" -+msgstr "Datenbank »%s« wird gelöscht." -+ -+#: ../../src/kadmin/dbutil/kdb5_destroy.c:106 -+#, c-format -+msgid "** Database '%s' destroyed.\n" -+msgstr "** Datenbank »%s« vernichtet\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:218 -+#, c-format -+msgid "%s is an invalid enctype" -+msgstr "%s ist ein ungültiger Verschlüsselungstyp" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:250 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:443 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:599 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:986 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1157 -+#, c-format -+msgid "while getting master key principal %s" -+msgstr "beim Holen des Hauptschlüssels von Principal %s" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:256 -+#, c-format -+msgid "Creating new master key for master key principal '%s'\n" -+msgstr "" -+"Es wird ein neuer Hauptschlüssel für den Hauptschlüssel-Principal »%s« " -+"erstellt.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:259 -+#, c-format -+msgid "You will be prompted for a new database Master Password.\n" -+msgstr "Sie werden nach einem neuen Datenbank-Master-Passwort gefragt.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:275 -+msgid "while reading new master key from keyboard" -+msgstr "beim Lesen des neuen Hauptschlüssels von der Tastatur" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:304 -+msgid "adding new master key to master principal" -+msgstr "dem Haupt-Principal wird ein neuer Hauptschlüssel hinzugefügt" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:310 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:402 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:843 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1356 -+msgid "while getting current time" -+msgstr "beim Holen der aktuellen Zeit" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:317 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:544 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1363 -+msgid "while updating the master key principal modification time" -+msgstr "beim Aktulisieren der Änderungszeit des Hauptschlüssel-Principals" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:325 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:553 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1374 -+msgid "while adding master key entry to the database" -+msgstr "beim Hinzufügen des Hauptschlüsseleintrags zur Datenbank" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:383 -+msgid "0 is an invalid KVNO value" -+msgstr "0 ist kein gültiger KVNO-Wert" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:394 -+#, c-format -+msgid "%d is an invalid KVNO value" -+msgstr "%d ist kein gültiger KVNO-Wert" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:410 -+#, c-format -+msgid "could not parse date-time string '%s'" -+msgstr "»date-time«-Zeichenkette »%s« konnte nicht ausgewertet werden" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:452 -+msgid "while looking up active version of master key" -+msgstr "beim Nachschlagen der aktiven Version des Hauptschlüssels" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:491 -+msgid "while adding new master key" -+msgstr "beim Hinzufügen eines neuen Hauptschlüssels" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:529 -+msgid "there must be one master key currently active" -+msgstr "ein Hauptschlüssel muss derzeit aktiv sein" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:537 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1342 -+msgid "while updating actkvno data for master principal entry" -+msgstr "beim Aktualisieren der Actkvno-Daten für den Haupt-Principal-Eintrag" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:581 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:948 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1116 -+msgid "master keylist not initialized" -+msgstr "Hauptschlüsselliste ist nicht initialisiert" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:607 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:994 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1254 -+msgid "while looking up active kvno list" -+msgstr "beim Nachschlagen der Liste aktiver KVNOs" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:615 -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1002 -+msgid "while looking up active master key" -+msgstr "beim Nachschlagen des aktiven Hauptschlüssels" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:627 -+msgid "while getting enctype description" -+msgstr "beim Holen des Verschlüsselungsbeschreibung" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:644 -+#, c-format -+msgid "KVNO: %d, Enctype: %s, Active on: %s *\n" -+msgstr "KVNO: %d, Verschlüsselungstyp: %s, aktiviert auf: %s *\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:649 -+#, c-format -+msgid "KVNO: %d, Enctype: %s, Active on: %s\n" -+msgstr "KVNO: %d, Verschlüsselungstyp: %s, aktiviert auf: %s\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:653 -+#, c-format -+msgid "KVNO: %d, Enctype: %s, No activate time set\n" -+msgstr "KVNO: %d, Verschlüsselungstyp: %s, keine Aktivierungszeit gesetzt\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:658 -+msgid "asprintf could not allocate enough memory to hold output" -+msgstr "" -+"Asprintf konnte nicht genug Speicher reservieren, um die Ausgabe " -+"bereitzuhalten" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:793 -+msgid "getting string representation of principal name" -+msgstr "Principal-Name wird im Klartext geholt" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:817 -+#, c-format -+msgid "determining master key used for principal '%s'" -+msgstr "Hauptschlüssel, der für Principal »%s« benutzt wird, wird bestimmt" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:823 -+#, c-format -+msgid "would skip: %s\n" -+msgstr "würde übersprungen: %s\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:825 -+#, c-format -+msgid "skipping: %s\n" -+msgstr "wird übersprungen: %s\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:831 -+#, c-format -+msgid "would update: %s\n" -+msgstr "würde aktualisiert: %s\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:835 -+#, c-format -+msgid "updating: %s\n" -+msgstr "wird aktualisiert: %s\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:839 -+#, c-format -+msgid "error re-encrypting key for principal '%s'" -+msgstr "Fehler beim erneuten Verschlüsseln des Schlüssels für Principal »%s«" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:850 -+#, c-format -+msgid "while updating principal '%s' modification time" -+msgstr "beim Aktualisieren der Änderungszeit von Principal »%s«" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:857 -+#, c-format -+msgid "while updating principal '%s' key data in the database" -+msgstr "" -+"beim Aktualisieren der Schlüsseldaten von Principal »%s« in der Datenbank" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:889 -+#, c-format -+msgid "" -+"\n" -+"(type 'yes' to confirm)? " -+msgstr "" -+"\n" -+"(Geben Sie als Bestätigung »yes« ein) " -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:942 -+msgid "while formatting master principal name" -+msgstr "beim Formatieren des Haupt-Principal-Namens" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:959 -+#, c-format -+msgid "converting glob pattern '%s' to regular expression" -+msgstr "Platzhalter »%s« wird in einen regulären Ausdruck umgewandelt" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:977 -+#, c-format -+msgid "error compiling converted regexp '%s'" -+msgstr "Fehler beim Kompilieren des umgewandelten regulären Ausdrucks »%s«" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1010 -+#, c-format -+msgid "Re-encrypt all keys not using master key vno %u?" -+msgstr "" -+"Sollen alle Schlüssel neu verschlüsselt werden, die nicht die Hauptschlüssel-" -+"VNO %u verwenden?" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1012 -+#, c-format -+msgid "OK, doing nothing.\n" -+msgstr "Ok, es wird nichts getan.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1018 -+#, c-format -+msgid "Principals whose keys WOULD BE re-encrypted to master key vno %u:\n" -+msgstr "" -+"Principals, deren Schlüssel mit dem Hauptschlüssel VNO %u neu verschlüsselt " -+"WÜRDEN:\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1021 -+#, c-format -+msgid "" -+"Principals whose keys are being re-encrypted to master key vno %u if " -+"necessary:\n" -+msgstr "" -+"Principals, deren Schlüssel mit dem Hauptschlüssel VNO %u neu verschlüsselt " -+"werden, falls nötig:\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1037 -+msgid "trying to process principal database" -+msgstr "es wird versucht, die Principal-Datenbank zu verarbeiten" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1042 -+#, c-format -+msgid "%u principals processed: %u would be updated, %u already current\n" -+msgstr "" -+"%u Principals verarbeitet: %u würden aktualisiert, %u bereits aktuell\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1046 -+#, c-format -+msgid "%u principals processed: %u updated, %u already current\n" -+msgstr "%u Principals verarbeitet: %u aktualisiert, %u bereits aktuell\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1164 -+#, c-format -+msgid "" -+"Will purge all unused master keys stored in the '%s' principal, are you " -+"sure?\n" -+msgstr "" -+"Sind Sie sicher, dass alle nicht verwendeten Hauptschlüssel, die für " -+"Principal »%s« gespeichert sind, vollständig entfernt werden sollen?\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1175 -+#, c-format -+msgid "OK, purging unused master keys from '%s'...\n" -+msgstr "" -+"Ok, die nicht verwendeten Hauptschlüssel von »%s« werden vollständig " -+"entfernt …\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1183 -+#, c-format -+msgid "There is only one master key which can not be purged.\n" -+msgstr "" -+"Es gibt nur einen einzigen Hauptschlüssel, der nicht vollständig entfernt " -+"werden kann.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1192 -+msgid "while allocating args.kvnos" -+msgstr "beim Reservieren von »args.kvnos«" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1208 -+msgid "while finding master keys in use" -+msgstr "bei der Suche nach den gerade verwendeten Hauptschlüsseln" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1217 -+#, c-format -+msgid "Would purge the following master key(s) from %s:\n" -+msgstr "" -+"Der/Die folgende(n) Hauptschlüssel würden/würde von %s vollständig " -+"entfernt:\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1220 -+#, c-format -+msgid "Purging the following master key(s) from %s:\n" -+msgstr "" -+"Der/Die folgende(n) Hauptschlüssel werden/wird von %s vollständig entfernt:\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1232 -+msgid "master key stash file needs updating, command aborting" -+msgstr "" -+"Ablagedatei des Hauptschlüssels erfordert Aktualisierung, Befehl abgebrochen" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1238 -+#, c-format -+msgid "KVNO: %d\n" -+msgstr "KVNO: %d\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1243 -+#, c-format -+msgid "All keys in use, nothing purged.\n" -+msgstr "Alle Schlüssel sind in Gebrauch, keiner wurde vollständig entfernt.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1248 -+#, c-format -+msgid "%d key(s) would be purged.\n" -+msgstr "%d Schlüssel würde(n) vollständig entfernt.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1261 -+msgid "while looking up mkey aux data list" -+msgstr "beim Nachschlagen der Mkey-Aux-Datenliste" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1269 -+msgid "while allocating key_data" -+msgstr "beim Reservieren von »key_data«" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1350 -+msgid "while updating mkey_aux data for master principal entry" -+msgstr "beim Aktualisieren der Mkey-Aux-Daten für den Haupt-Principal-Eintrag" -+ -+#: ../../src/kadmin/dbutil/kdb5_mkey.c:1378 -+#, c-format -+msgid "%d key(s) purged.\n" -+msgstr "%d Schlüssel vollständig entfernt\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_stash.c:97 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:538 -+#, c-format -+msgid "while setting up enctype %d" -+msgstr "beim Einrichten des Verschlüsselungstyps %d" -+ -+#: ../../src/kadmin/dbutil/kdb5_stash.c:123 -+msgid "while getting master key list" -+msgstr "beim Holen der Hauptschlüsselliste" -+ -+#: ../../src/kadmin/dbutil/kdb5_stash.c:127 -+#, c-format -+msgid "Using existing stashed keys to update stash file.\n" -+msgstr "" -+"Zur Aktualisierung der Ablagedatei werden existierende gelagert Schlüssel " -+"verwendet.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:80 -+#, c-format -+msgid "" -+"Usage: kdb5_util [-x db_args]* [-r realm] [-d dbname] [-k mkeytype] [-M " -+"mkeyname]\n" -+"\t [-kv mkeyVNO] [-sf stashfilename] [-m] cmd [cmd_options]\n" -+"\tcreate [-s]\n" -+"\tdestroy [-f]\n" -+"\tstash [-f keyfile]\n" -+"\tdump [-old|-ov|-b6|-b7|-r13|-r18] [-verbose]\n" -+"\t [-mkey_convert] [-new_mkey_file mkey_file]\n" -+"\t [-rev] [-recurse] [filename [princs...]]\n" -+"\tload [-old|-ov|-b6|-b7|-r13|-r18] [-verbose] [-update] filename\n" -+"\tark [-e etype_list] principal\n" -+"\tadd_mkey [-e etype] [-s]\n" -+"\tuse_mkey kvno [time]\n" -+"\tlist_mkeys\n" -+msgstr "" -+"Aufruf: kdb5_util [-x Datenbankargumente]* [-r Realm] [-d Datenbankname] [-k " -+"Mkeytype] [-M Mkeyname]\n" -+"\t [-kv MkeyVNO] [-sf Ablagedateiname] [-m] Befehl [Befehlsoptionen]\n" -+"\tcreate [-s]\n" -+"\tdestroy [-f]\n" -+"\tstash [-f Schlüsseldatei]\n" -+"\tdump [-old|-ov|-b6|-b7|-r13|-r18] [-verbose]\n" -+"\t [-mkey_convert] [-new_mkey_file mkey-Datei]\n" -+"\t [-rev] [-recurse] [Dateiname [Principals …]]\n" -+"\tload [-old|-ov|-b6|-b7|-r13|-r18] [-verbose] [-update] Dateiname\n" -+"\tark [-e Etype-Liste] Principal\n" -+"\tadd_mkey [-e Etype] [-s]\n" -+"\tuse_mkey kvno [Zeit]\n" -+"\tlist_mkeys\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:98 -+#, c-format -+msgid "" -+"\tupdate_princ_encryption [-f] [-n] [-v] [princ-pattern]\n" -+"\tpurge_mkeys [-f] [-n] [-v]\n" -+"\n" -+"where,\n" -+"\t[-x db_args]* - any number of database specific arguments.\n" -+"\t\t\tLook at each database documentation for supported arguments\n" -+msgstr "" -+"\tupdate_princ_encryption [-f] [-n] [-v] [Principal-Muster]\n" -+"\tpurge_mkeys [-f] [-n] [-v]\n" -+"\n" -+"dabei sind\n" -+"\t[-x Datenbankargumente]* - eine beliebige Anzahl datenbankspezifischer " -+"Argumente.\n" -+"\t\t\tWelche Argumente unterstützt werden, finden Sie in der Dokumentation " -+"der jeweiligen Datenbank.\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:211 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:260 -+msgid "while initializing Kerberos code" -+msgstr "beim Initialisieren von Kerberos-Code" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:217 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:267 -+msgid "while creating sub-command arguments" -+msgstr "beim Erstellen von Unterbefehlsargumenten" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:235 -+msgid "while parsing command arguments" -+msgstr "beim Auswerten von Befehlsargumenten" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:264 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:298 -+#, c-format -+msgid ": %s is an invalid enctype" -+msgstr ": %s ist kein gültiger Verschlüsselungstyp" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:272 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:307 -+#, c-format -+msgid ": %s is an invalid mkeyVNO" -+msgstr ": %s ist kein gültiger MkeyVNO" -+ -+# FIXME s/retreiving/retrieving/ -+#: ../../src/kadmin/dbutil/kdb5_util.c:317 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:431 -+msgid "while retreiving configuration parameters" -+msgstr "beim Abfragen der Konfigurationsparameter" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:368 -+msgid "Too few arguments" -+msgstr "zu wenige Argumente" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:369 -+#, c-format -+msgid "Usage: %s dbpathname realmname" -+msgstr "Aufruf: %s Datenbankpfadname Realm-Name" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:375 -+msgid "while closing previous database" -+msgstr "beim Schließen der vorherigen Datenbank" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:412 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:877 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1497 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:564 -+msgid "while initializing database" -+msgstr "beim Initialisieren der Datenbank" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:429 -+msgid "while retrieving master entry" -+msgstr "beim Abfragen des Haupteintrags" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:448 -+msgid "while calculated master key salt" -+msgstr "beim Berechnen des Hauptschlüssel-Salts" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:480 -+msgid "Warning: proceeding without master key" -+msgstr "Warnung: Es wird ohne Hauptschlüssel fortgefahren" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:498 -+msgid "while seeding random number generator" -+msgstr "beim Erzeugen des Startwerts des Zufallszahlengenerators" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:508 -+#, c-format -+msgid "%s: Could not map log\n" -+msgstr "%s: Protokolldatei konnte nicht abgebildet werden\n" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:535 -+msgid "while closing database" -+msgstr "beim Schließen der Datenbank" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:582 -+#, c-format -+msgid "while fetching principal %s" -+msgstr "beim Abrufen von Principal %s" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:605 -+msgid "while finding mkey" -+msgstr "beim Suchen nach Mkey" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:630 -+msgid "while setting changetime" -+msgstr "beim Setzen der Änderungszeit der Datei" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:638 -+#, c-format -+msgid "while saving principal %s" -+msgstr "beim Speichern von Principal %s" -+ -+#: ../../src/kadmin/dbutil/kdb5_util.c:642 -+#, c-format -+msgid "%s changed\n" -+msgstr "%s geändert\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:73 -+#, c-format -+msgid "%s: invalid arguments\n" -+msgstr "%s: ungültige Argumente\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:78 -+msgid "while freeing ktlist" -+msgstr "beim Freigeben von »ktlist«" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:89 -+#, c-format -+msgid "%s: must specify keytab to read\n" -+msgstr "" -+"%s: Die Schlüsseltabelle, die gelesen werden soll, muss angegeben werden.\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:94 -+#, c-format -+msgid "while reading keytab \"%s\"" -+msgstr "beim Lesen der Schlüsseltabelle »%s«" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:104 -+#, c-format -+msgid "%s: must specify the srvtab to read\n" -+msgstr "%s: Die zu lesende Dienstschlüsseltabelle muss angegeben werden.\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:109 -+#, c-format -+msgid "while reading srvtab \"%s\"" -+msgstr "beim Lesen der Dienstschlüsseltabelle »%s«" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:119 -+#, c-format -+msgid "%s: must specify keytab to write\n" -+msgstr "%s: Die zu schreibende Schlüsseltabelle muss angegeben werden.\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:124 -+#, c-format -+msgid "while writing keytab \"%s\"" -+msgstr "beim Schreiben der Schlüsseltabelle »%s«" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:131 -+#, c-format -+msgid "%s: writing srvtabs is no longer supported\n" -+msgstr "" -+"%s: Schreiben der Dienstschlüsseltabelle wird nicht länger unterstützt\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:169 -+#, c-format -+msgid "usage: %s (-key | -password) -p principal -k kvno -e enctype\n" -+msgstr "" -+"Aufruf: %s (-key | -password) -p Principal -k KVNO -e Verschlüsselungstyp\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:176 -+msgid "while adding new entry" -+msgstr "beim Hinzufügen eines neuen Eintrags" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:186 -+#, c-format -+msgid "%s: must specify entry to delete\n" -+msgstr "%s: zu löschender Eintrag muss angegeben werden\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:191 -+#, c-format -+msgid "while deleting entry %d" -+msgstr "beim Löschen von Eintrag %d" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:219 -+#, c-format -+msgid "%s: usage: %s [-t] [-k] [-e]\n" -+msgstr "%s: Aufruf: %s [-t] [-k] [-e]\n" -+ -+#: ../../src/kadmin/ktutil/ktutil.c:259 -+msgid "While converting enctype to string" -+msgstr "beim Umwandeln des Verschlüsselungstyps in eine Zeichenkette" -+ -+#: ../../src/kadmin/ktutil/ktutil_funcs.c:162 -+#, c-format -+msgid "Password for %.1000s" -+msgstr "Passwort für %.1000s" -+ -+#: ../../src/kadmin/ktutil/ktutil_funcs.c:179 -+#, c-format -+msgid "Key for %s (hex): " -+msgstr "Schlüssel für %s (hexadezimal): " -+ -+#: ../../src/kadmin/ktutil/ktutil_funcs.c:191 -+#, c-format -+msgid "addent: Error reading key.\n" -+msgstr "addent: Fehler beim Lesen des Schlüssels\n" -+ -+#: ../../src/kadmin/ktutil/ktutil_funcs.c:206 -+#, c-format -+msgid "addent: Illegal character in key.\n" -+msgstr "addent: unerlaubtes Zeichen im Schlüssel\n" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:48 -+#, c-format -+msgid "Unauthorized request: %s, client=%s, service=%s, addr=%s" -+msgstr "unberechtigte Anfrage: %s, Client=%s, Dienst=%s, Adresse=%s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:49 -+#: ../../src/kadmin/server/ipropd_svc.c:212 -+#, c-format -+msgid "Request: %s, %s, %s, client=%s, service=%s, addr=%s" -+msgstr "Anfrage: %s, %s, %s, Client=%s, Dienst=%s, Adresse=%s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:146 -+#: ../../src/kadmin/server/ipropd_svc.c:271 -+#, c-format -+msgid "%s: server handle is NULL" -+msgstr "%s: Server-Identifikator ist NULL" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:156 -+#: ../../src/kadmin/server/ipropd_svc.c:284 -+#, c-format -+msgid "%s: setup_gss_names failed" -+msgstr "%s: setup_gss_names fehlgeschlagen" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:166 -+#: ../../src/kadmin/server/ipropd_svc.c:295 -+#, c-format -+msgid "%s: out of memory recording principal names" -+msgstr "%s: Speicher reicht nicht zur Aufzeichnung der Principal-Namen aus" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:195 -+#, c-format -+msgid "%s; Incoming SerialNo=%lu; Outgoing SerialNo=%lu" -+msgstr "%s; eingehende Seriennummer=%lu; ausgehende Seriennummer=%lu" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:201 -+#, c-format -+msgid "%s; Incoming SerialNo=%lu; Outgoing SerialNo=N/A" -+msgstr "%s; eingehende Seriennummer=%lu; ausgehende Seriennummer=N/A" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:320 -+#, c-format -+msgid "%s: getclhoststr failed" -+msgstr "%s: getclhoststr fehlgeschlagen" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:342 -+#, c-format -+msgid "%s: cannot construct kdb5 util dump string too long; out of memory" -+msgstr "" -+"Ausgabenzeichenkette des KDB5-Hilfswerkzeugs nicht konstruierbar, da zu " -+"lang; Speicher reicht nicht aus.%s: Die Ausgabezeichenkette des KDB5-" -+"Hilfswerkzeugs kann nicht erstellt werden, weil sie zu lang ist. Der " -+"Speicherplatz reicht nicht aus." -+ -+#: ../../src/kadmin/server/ipropd_svc.c:362 -+#, c-format -+msgid "%s: fork failed: %s" -+msgstr "%s: Verzweigen fehlgeschlagen: %s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:374 -+#, c-format -+msgid "%s: popen failed: %s" -+msgstr "%s: popen fehlgeschlagen: %s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:388 -+#, c-format -+msgid "%s: pclose(popen) failed: %s" -+msgstr "%s: pclose(popen) fehlgeschlagen: %s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:405 -+#, c-format -+msgid "%s: exec failed: %s" -+msgstr "%s: exec fehlgeschlagen: %s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:421 -+#, c-format -+msgid "Request: %s, spawned resync process %d, client=%s, service=%s, addr=%s" -+msgstr "" -+"Anfrage: %s, hervorgebrachter Neusynchronisationsprozess %d, Client=%s, " -+"Dienst=%s, Adresse=%s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:485 -+#: ../../src/kadmin/server/kadm_rpc_svc.c:275 -+#, c-format -+msgid "check_rpcsec_auth: failed inquire_context, stat=%u" -+msgstr "check_rpcsec_auth: inquire_context fehlgeschlagen, Stat=%u" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:515 -+#: ../../src/kadmin/server/kadm_rpc_svc.c:304 -+#, c-format -+msgid "bad service principal %.*s%s" -+msgstr "falscher Dienst-Principal %.*s%s" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:538 -+#, c-format -+msgid "authentication attempt failed: %s, RPC authentication flavor %d" -+msgstr "" -+"Authentifizierungsversuche gescheitert: %s, PRC-Authentifizierungsvariante %d" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:572 -+#, c-format -+msgid "RPC unknown request: %d (%s)" -+msgstr "unbekannte PRC-Anfrage: %d (%s)" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:580 -+#, c-format -+msgid "RPC svc_getargs failed (%s)" -+msgstr "RPC-»svc_getargs« fehlgeschlagen (%s)" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:590 -+#, c-format -+msgid "RPC svc_sendreply failed (%s)" -+msgstr "RPC-»svc_sendreply« fehlgeschlagen (%s)" -+ -+#: ../../src/kadmin/server/ipropd_svc.c:596 -+#, c-format -+msgid "RPC svc_freeargs failed (%s)" -+msgstr "RPC-»svc_freeargs« fehlgeschlagen (%s)" -+ -+#: ../../src/kadmin/server/kadm_rpc_svc.c:325 -+#, c-format -+msgid "gss_to_krb5_name: failed display_name status %d" -+msgstr "gss_to_krb5_name: display_name fehlgeschlagen, Status %d" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:86 -+#, c-format -+msgid "" -+"Usage: kadmind [-x db_args]* [-r realm] [-m] [-nofork] [-port port-number]\n" -+"\t\t[-proponly] [-p path-to-kdb5_util] [-F dump-file]\n" -+"\t\t[-K path-to-kprop] [-P pid_file]\n" -+"\n" -+"where,\n" -+"\t[-x db_args]* - any number of database specific arguments.\n" -+"\t\t\tLook at each database documentation for supported arguments\n" -+msgstr "" -+"Aufruf: kadmind [-x Datenbankargumente]* [-r Realm] [-m] [-nofork]\n" -+"\t\t[-port Portummer] [-p Pfad_zum_KDB5-Hilfswerkzeug] [-F Auszugsdatei]\n" -+"\t\t[-K Pfad_zu_Kprop] [-P PID-Datei]\n" -+"\n" -+"dabei sind\n" -+"\t[-x Datenbankargumente]* - eine beliebige Anzahl datenbankspezifischer " -+"Argumente.\n" -+"\t\t\tWelche Argumente unterstützt werden, finden Sie in der Dokumentation " -+"der jeweiligen Datenbank.\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:111 -+#, c-format -+msgid "%s: %s while %s, aborting\n" -+msgstr "%s: %s bei %s, wird abgebrochen\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:113 -+#, c-format -+msgid "%s while %s, aborting\n" -+msgstr "%s bei %s, wird abgebrochen\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:115 -+#, c-format -+msgid "%s: %s, aborting\n" -+msgstr "%s: %s, wird abgebrochen\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:116 -+#, c-format -+msgid "%s, aborting" -+msgstr "%s, wird abgebrochen" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:282 -+#, c-format -+msgid "" -+"WARNING! Forged/garbled request: %s, claimed client = %.*s%s, server = %.*s" -+"%s, addr = %s" -+msgstr "" -+"WARNUNG! Gefälschte/verstümmelte Anfrage: %s, geforderter Client = %.*s%s, " -+"Server = %.*s%s, Adresse = %s" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:288 -+#, c-format -+msgid "" -+"WARNING! Forged/garbled request: %d, claimed client = %.*s%s, server = %.*s" -+"%s, addr = %s" -+msgstr "" -+"WARNUNG! Gefälschte/verstümmelte Anfrage: %d, Client = %.*s%s, Server = " -+"%.*s%s, Adresse = %s" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:302 -+#, c-format -+msgid "Miscellaneous RPC error: %s, %s" -+msgstr "sonstiger PRC-Fehler: %s, %s" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:318 -+#, c-format -+msgid "%s Cannot decode status %d" -+msgstr "%s: Status %d kann nicht dekodiert werden" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:336 -+#, c-format -+msgid "Authentication attempt failed: %s, GSS-API error strings are:" -+msgstr "Authentifizierungsversuch fehlgeschlagen: %s, GSS-API-Fehlermeldungen:" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:341 -+msgid " GSS-API error strings complete." -+msgstr " GSS-API-Fehlermeldungen vollständig" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:378 -+#, c-format -+msgid "%s: cannot initialize. Not enough memory\n" -+msgstr "%s: kann nicht initialisiert werden: Speicher reicht nicht aus.\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:445 -+#, c-format -+msgid "%s: %s while initializing context, aborting\n" -+msgstr "%s: %s beim Initialisieren des Kontextes, wird abgebrochen\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:456 -+msgid "initializing" -+msgstr "wird initialisiert" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:460 -+msgid "getting config parameters" -+msgstr "beim Holen der Konfigurationsparameter" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:462 -+msgid "Missing required realm configuration" -+msgstr "erforderliche Realm-Konfiguration fehlt" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:464 -+msgid "Missing required ACL file configuration" -+msgstr "erforderliche ACL-Dateikonfiguration fehlt" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:468 -+msgid "initializing network" -+msgstr "Netzwerk wird initialisiert" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:473 -+msgid "Cannot build GSSAPI auth names" -+msgstr "GSS-API-Authentifizierungsnamen können nicht gebildet werden." -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:477 -+msgid "Cannot set up KDB keytab" -+msgstr "Die KDB-Schlüsseltabelle kann nicht eingerichtet werden." -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:480 -+msgid "Cannot set GSSAPI authentication names" -+msgstr "GSS-API-Authentifizierungsnamen können nicht gesetzt werden." -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:497 -+msgid "Cannot initialize GSSAPI service name" -+msgstr "GSSAPI-Dienstname kann nicht initialisiert werden" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:501 -+msgid "initializing ACL file" -+msgstr "ACL-Datei wird initialisiert" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:504 -+msgid "spawning daemon process" -+msgstr "Daemon-Prozess wird erzeugt" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:508 -+msgid "creating PID file" -+msgstr "PID-Datei wird erstellt" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:511 -+msgid "Seeding random number generator" -+msgstr "Startwert des Zufallszahlengenerators wird erzeugt" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:514 -+msgid "getting random seed" -+msgstr "Zufallsstartwert wird geholt" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:521 -+msgid "mapping update log" -+msgstr "Aktualisierungsprotokoll wird abgebildet" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:525 -+#, c-format -+msgid "%s: create IPROP svc (PROG=%d, VERS=%d)\n" -+msgstr "%s: IPROP-Dienst wird erstellt (PROG=%d, VERS=%d)\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:530 -+msgid "starting" -+msgstr "startet" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:532 ../../src/kdc/main.c:1061 -+#, c-format -+msgid "%s: starting...\n" -+msgstr "%s: startet …\n" -+ -+#: ../../src/kadmin/server/ovsec_kadmd.c:535 -+msgid "finished, exiting" -+msgstr "fertig, wird beendet" -+ -+#: ../../src/kadmin/server/schpw.c:282 -+#, c-format -+msgid "setpw request from %s by %.*s%s for %.*s%s: %s" -+msgstr "»setpw«-Anfrage von %s durch %.*s%s für %.*s%s: %s" -+ -+#: ../../src/kadmin/server/schpw.c:287 -+#, c-format -+msgid "chpw request from %s for %.*s%s: %s" -+msgstr "»chpw«-Anfrage von %s für %.*s%s: %s" -+ -+#: ../../src/kadmin/server/schpw.c:464 -+#, c-format -+msgid "chpw: Couldn't open admin keytab %s" -+msgstr "chpw«: Administratorschlüsseltabelle %s konnte nicht geöffnet werden" -+ -+#: ../../src/kadmin/server/server_stubs.c:293 -+#, c-format -+msgid "" -+"Unauthorized request: %s, %.*s%s, client=%.*s%s, service=%.*s%s, addr=%s" -+msgstr "" -+"Unauthorisierte Anfrage: %s, %.*s%s, Client=%.*s%s, Dienst=%.*s%s, Adresse=%s" -+ -+#: ../../src/kadmin/server/server_stubs.c:314 -+#: ../../src/kadmin/server/server_stubs.c:649 -+#: ../../src/kadmin/server/server_stubs.c:1792 -+msgid "success" -+msgstr "erfolgreich" -+ -+#: ../../src/kadmin/server/server_stubs.c:324 -+#, c-format -+msgid "Request: %s, %.*s%s, %s, client=%.*s%s, service=%.*s%s, addr=%s" -+msgstr "Anfrage: %s, %.*s%s, %s, Client=%.*s%s, Dienst=%.*s%s, Adresse=%s" -+ -+#: ../../src/kadmin/server/server_stubs.c:628 -+#, c-format -+msgid "" -+"Unauthorized request: kadm5_rename_principal, %.*s%s to %.*s%s, client=%.*s" -+"%s, service=%.*s%s, addr=%s" -+msgstr "" -+"Unauthorisierte Anfrage: kadm5_rename_principal, %.*s%s bis %.*s%s, Client=" -+"%.*s%s, Dienst=%.*s%s, Adresse=%s" -+ -+#: ../../src/kadmin/server/server_stubs.c:644 -+#, c-format -+msgid "" -+"Request: kadm5_rename_principal, %.*s%s to %.*s%s, %s, client=%.*s%s, " -+"service=%.*s%s, addr=%s" -+msgstr "" -+"Anfrage: kadm5_rename_principal, %.*s%s bis %.*s%s, %s, Client=%.*s%s, " -+"Dienst=%.*s%s, Adresse=%s" -+ -+#: ../../src/kadmin/server/server_stubs.c:1788 -+#, c-format -+msgid "" -+"Request: kadm5_init, %.*s%s, %s, client=%.*s%s, service=%.*s%s, addr=%s, " -+"vers=%d, flavor=%d" -+msgstr "" -+"Anfrage: kadm5_init, %.*s%s, %s, Client=%.*s%s, Dienst=%.*s%s, Adresse=%s, " -+"Version=%d, Variante=%d" -+ -+#: ../../src/kdc/do_as_req.c:273 -+#, c-format -+msgid "AS_REQ : handle_authdata (%d)" -+msgstr "AS_REQ: handle_authdata (%d)" -+ -+#: ../../src/kdc/do_tgs_req.c:593 -+#, c-format -+msgid "TGS_REQ : handle_authdata (%d)" -+msgstr "TGS_REQ: handle_authdata (%d)" -+ -+#: ../../src/kdc/do_tgs_req.c:655 -+msgid "not checking transit path" -+msgstr "Übergangspfad wird nicht geprüft" -+ -+#: ../../src/kdc/fast_util.c:62 -+#, c-format -+msgid "%s while handling ap-request armor" -+msgstr "%s bei der Handhabung des »ap-request«-Schutzes" -+ -+#: ../../src/kdc/fast_util.c:71 -+msgid "ap-request armor for something other than the local TGS" -+msgstr "»ap-request«-Schutz für etwas anderes als den lokalen TGS" -+ -+#: ../../src/kdc/fast_util.c:80 -+msgid "ap-request armor without subkey" -+msgstr "»ap-request«-Schutz ohne Unterschlüssel" -+ -+#: ../../src/kdc/fast_util.c:162 -+msgid "Ap-request armor not permitted with TGS" -+msgstr "»ap-request«-Schutz nicht mit TGS gestattet" -+ -+#: ../../src/kdc/fast_util.c:169 -+#, c-format -+msgid "Unknown FAST armor type %d" -+msgstr "unbekanntet FAST-Schutztyp %d" -+ -+#: ../../src/kdc/fast_util.c:183 -+msgid "No armor key but FAST armored request present" -+msgstr "Es gibt keinen Schutzschlüssel aber eine FAST-geschützte Anfrage" -+ -+#: ../../src/kdc/fast_util.c:219 -+msgid "FAST req_checksum invalid; request modified" -+msgstr "FAST-»req_checksum« ungültig; Anfrage geändert" -+ -+#: ../../src/kdc/fast_util.c:225 -+msgid "Unkeyed checksum used in fast_req" -+msgstr "in fast_req wurde eine Prüfsumme ohne Schlüssel benutzt" -+ -+#: ../../src/kdc/kdc_audit.c:110 -+#, c-format -+msgid "audit plugin %s failed to open. error=%i" -+msgstr "Öffnen der Audit-Erweiterung %s fehlgeschlagen. Fehler=%i" -+ -+#: ../../src/kdc/kdc_authdata.c:292 ../../src/kdc/kdc_authdata.c:328 -+#, c-format -+msgid "authdata %s failed to initialize: %s" -+msgstr "Initialisieren von »authdata« %s fehlgeschlagen: %s" -+ -+#: ../../src/kdc/kdc_authdata.c:779 -+#, c-format -+msgid "authdata (%s) handling failure: %s" -+msgstr "Handhabung von »authdata« %s fehlgeschlagen: %s" -+ -+#: ../../src/kdc/kdc_log.c:82 -+#, c-format -+msgid "AS_REQ (%s) %s: ISSUE: authtime %d, %s, %s for %s" -+msgstr "AS_REQ (%s) %s: PROBLEM: Authentifizierungszeit %d, %s, %s für %s" -+ -+#: ../../src/kdc/kdc_log.c:88 -+#, c-format -+msgid "AS_REQ (%s) %s: %s: %s for %s%s%s" -+msgstr "AS_REQ (%s) %s: %s: %s für %s%s%s" -+ -+#: ../../src/kdc/kdc_log.c:159 -+#, c-format -+msgid "TGS_REQ (%s) %s: %s: authtime %d, %s%s %s for %s%s%s" -+msgstr "TGS_REQ (%s) %s: %s: Authentifizierungszeit %d, %s%s %s für %s%s%s" -+ -+#: ../../src/kdc/kdc_log.c:166 -+#, c-format -+msgid "... PROTOCOL-TRANSITION s4u-client=%s" -+msgstr "… PROTOKOLLÜBERGANG s4u-client=%s" -+ -+#: ../../src/kdc/kdc_log.c:170 -+#, c-format -+msgid "... CONSTRAINED-DELEGATION s4u-client=%s" -+msgstr "… EINHESCHRÄNKTE DELEGIERUNG s4u-client=%s" -+ -+#: ../../src/kdc/kdc_log.c:174 -+#, c-format -+msgid "TGS_REQ %s: %s: authtime %d, %s for %s, 2nd tkt client %s" -+msgstr "TGS_REQ %s: %s: Authentifizierungszeit %d, %s für %s, 2. TKT-Client %s" -+ -+#: ../../src/kdc/kdc_log.c:208 -+#, c-format -+msgid "bad realm transit path from '%s' to '%s' via '%.*s%s'" -+msgstr "falscher Realm-Übergangspfad von »%s« zu »%s« über »%.*s%s«" -+ -+#: ../../src/kdc/kdc_log.c:214 -+#, c-format -+msgid "unexpected error checking transit from '%s' to '%s' via '%.*s%s': %s" -+msgstr "" -+"unerwarteter Fehler bei der Prüfung des Übergangs von »%s« zu »%s« über »%.*s" -+"%s«: %s" -+ -+#: ../../src/kdc/kdc_log.c:232 -+msgid "TGS_REQ: issuing alternate TGT" -+msgstr "TGS_REQ: alternativer TGT wird erstellt" -+ -+#: ../../src/kdc/kdc_log.c:235 -+#, c-format -+msgid "TGS_REQ: issuing TGT %s" -+msgstr "TGS_REQ: TGT %s wird erstellt" -+ -+#: ../../src/kdc/kdc_preauth.c:328 -+#, c-format -+msgid "preauth %s failed to initialize: %s" -+msgstr "Initialisieren von »preauth« %s fehlgeschlagen: %s" -+ -+#: ../../src/kdc/kdc_preauth.c:339 -+#, c-format -+msgid "preauth %s failed to setup loop: %s" -+msgstr "Einrichten der Schleife von »preauth« %s fehlgeschlagen: %s" -+ -+#: ../../src/kdc/kdc_preauth.c:760 -+#, c-format -+msgid "%spreauth required but hint list is empty" -+msgstr "%spreauth benötigt, aber Hinweisliste ist leer" -+ -+#: ../../src/kdc/kdc_preauth_ec.c:75 -+msgid "Encrypted Challenge used outside of FAST tunnel" -+msgstr "verschlüsselte Aufforderung wurde außerhalb des FAST-Tunnels verwendet" -+ -+#: ../../src/kdc/kdc_preauth_ec.c:110 -+msgid "Incorrect password in encrypted challenge" -+msgstr "falsches Passwort in verschlüsselter Aufforderung" -+ -+#: ../../src/kdc/kdc_util.c:236 -+msgid "TGS_REQ: SESSION KEY or MUTUAL" -+msgstr "TGS_REQ: SITZUNGSSCHLÜSSEL oder BEIDERSEITIG" -+ -+#: ../../src/kdc/kdc_util.c:314 -+msgid "PROCESS_TGS: failed lineage check" -+msgstr "PROCESS_TGS: Abstammungsprüfung fehlgeschlagen" -+ -+#: ../../src/kdc/kdc_util.c:468 -+#, c-format -+msgid "TGS_REQ: UNKNOWN SERVER: server='%s'" -+msgstr "TGS_REQ: UNBEKANNTER SERVER: Server=»%s«" -+ -+#: ../../src/kdc/main.c:231 -+#, c-format -+msgid "while getting context for realm %s" -+msgstr "beim Holen des Kontextes für Realm %s" -+ -+#: ../../src/kdc/main.c:329 -+#, c-format -+msgid "while setting default realm to %s" -+msgstr "beim Setzen des Standard-Realms auf %s" -+ -+#: ../../src/kdc/main.c:337 -+#, c-format -+msgid "while initializing database for realm %s" -+msgstr "beim Initialisieren der Datenbank für Realm %s" -+ -+#: ../../src/kdc/main.c:346 -+#, c-format -+msgid "while setting up master key name %s for realm %s" -+msgstr "beim Einrichten des Hauptschlüsselnamens %s für Realm %s" -+ -+#: ../../src/kdc/main.c:359 -+#, c-format -+msgid "while fetching master key %s for realm %s" -+msgstr "beim Abholen des Hauptschlüssels %s für Realm %s" -+ -+#: ../../src/kdc/main.c:367 -+#, c-format -+msgid "while fetching master keys list for realm %s" -+msgstr "beim Abholen der Hauptschlüsselliste für Realm %s" -+ -+#: ../../src/kdc/main.c:376 -+#, c-format -+msgid "while resolving kdb keytab for realm %s" -+msgstr "beim Ermitteln der KDB-Schlüsseltabelle für Realm %s" -+ -+#: ../../src/kdc/main.c:385 -+#, c-format -+msgid "while building TGS name for realm %s" -+msgstr "beim Bilden des TGS-Namens für Realm %s" -+ -+#: ../../src/kdc/main.c:503 -+#, c-format -+msgid "creating %d worker processes" -+msgstr "%d Arbeitsprozesse werden erzeugt" -+ -+#: ../../src/kdc/main.c:513 -+msgid "Unable to reinitialize main loop" -+msgstr "Hauptschleife konnte nicht neu initialisiert werden" -+ -+#: ../../src/kdc/main.c:518 -+#, c-format -+msgid "Unable to initialize signal handlers in pid %d" -+msgstr "" -+"Signalbehandlungsprogramme in PID %d konnten nicht initialisiert werden" -+ -+#: ../../src/kdc/main.c:548 -+#, c-format -+msgid "worker %ld exited with status %d" -+msgstr "Arbeitsprozess %ld endete mit Status %d" -+ -+#: ../../src/kdc/main.c:572 -+#, c-format -+msgid "signal %d received in supervisor" -+msgstr "Überwachungsprogramm empfing Signal %d" -+ -+#: ../../src/kdc/main.c:591 -+#, c-format -+msgid "" -+"usage: %s [-x db_args]* [-d dbpathname] [-r dbrealmname]\n" -+"\t\t[-R replaycachename] [-m] [-k masterenctype]\n" -+"\t\t[-M masterkeyname] [-p port] [-P pid_file]\n" -+"\t\t[-n] [-w numworkers] [/]\n" -+"\n" -+"where,\n" -+"\t[-x db_args]* - Any number of database specific arguments.\n" -+"\t\t\tLook at each database module documentation for \t\t\tsupported " -+"arguments\n" -+msgstr "" -+"Aufruf: %s [-x Datenbankargumente]* [-d Datenbankpfadname]\n" -+"\t\t[-r Datenbank-Realm-Name] [-m] [-k Hauptverschlüsselungstyp]\n" -+"\t\t[-M Hauptschlüsselname] [-p Port] [-P PID-Datei]\n" -+"\t\t[-n] [-w Arbeitsprozessanzahl] [/]\n" -+"\n" -+"dabei sind\n" -+"\t[-x Datenbankargumente]* - eine beliebige Anzahl datenbankspezifischer " -+"Argumente.\n" -+"\t\t\tWelche Argumente unterstützt werden, finden Sie in der Dokumentation " -+"der jeweiligen Datenbank.\n" -+ -+#: ../../src/kdc/main.c:653 ../../src/kdc/main.c:660 ../../src/kdc/main.c:774 -+#, c-format -+msgid " KDC cannot initialize. Not enough memory\n" -+msgstr "KDC kann nicht initialisiert werden. Speicher reicht nicht aus\n" -+ -+#: ../../src/kdc/main.c:679 ../../src/kdc/main.c:722 ../../src/kdc/main.c:733 -+#, c-format -+msgid "%s: KDC cannot initialize. Not enough memory\n" -+msgstr "%s: KDC kann nicht initialisiert werden. Speicher reicht nicht aus\n" -+ -+#: ../../src/kdc/main.c:699 ../../src/kdc/main.c:816 -+#, c-format -+msgid "%s: cannot initialize realm %s - see log file for details\n" -+msgstr "" -+"%s: Realm %s kann nicht initialisiert werden - Einzelheiten finden Sie in " -+"der Protokolldatei\n" -+ -+#: ../../src/kdc/main.c:710 -+#, c-format -+msgid "%s: cannot initialize realm %s. Not enough memory\n" -+msgstr "" -+"%s: Realm %s kann nicht initialisiert werden. Speicher reicht nicht aus\n" -+ -+#: ../../src/kdc/main.c:761 -+#, c-format -+msgid "invalid enctype %s" -+msgstr "ungültiger Verschlüsselungstyp %s" -+ -+#: ../../src/kdc/main.c:804 -+msgid "while attempting to retrieve default realm" -+msgstr "beim Versuch, den Standard-Realm abzufragen" -+ -+#: ../../src/kdc/main.c:806 -+#, c-format -+msgid "%s: %s, attempting to retrieve default realm\n" -+msgstr "%s: %s, es wird versucht, den Standard-Realm abzufragen\n" -+ -+#: ../../src/kdc/main.c:912 -+#, c-format -+msgid "%s: cannot get memory for realm list\n" -+msgstr "%s: Speicher für die Realm-Liste kann nicht erlangt werden\n" -+ -+# http://www.oreilly.de/german/freebooks/linuxdrive2ger/getcache.html -+#: ../../src/kdc/main.c:947 -+msgid "while initializing lookaside cache" -+msgstr "beim Initialisieren des Lookaside-Zwischenspeichers" -+ -+#: ../../src/kdc/main.c:955 -+msgid "while creating main loop" -+msgstr "beim Erzeugen der Hauptschleife" -+ -+# SAM=Security Accounts Manager -+#: ../../src/kdc/main.c:965 -+msgid "while initializing SAM" -+msgstr "beim Initialisieren des SAMs" -+ -+#: ../../src/kdc/main.c:1011 -+msgid "while initializing routing socket" -+msgstr "beim Initialisieren des Routing-Sockets" -+ -+#: ../../src/kdc/main.c:1017 -+msgid "while initializing signal handlers" -+msgstr "beim Initialisieren des Signalbehandlungsprogramms" -+ -+#: ../../src/kdc/main.c:1024 -+msgid "while initializing network" -+msgstr "beim Initialisieren des Netzwerks" -+ -+#: ../../src/kdc/main.c:1029 -+msgid "while detaching from tty" -+msgstr "beim Lösen vom Terminal" -+ -+#: ../../src/kdc/main.c:1036 -+msgid "while creating PID file" -+msgstr "beim Erstellen der PID-Datei" -+ -+#: ../../src/kdc/main.c:1045 -+msgid "creating worker processes" -+msgstr "Arbeitsprozesse werden erzeugt" -+ -+#: ../../src/kdc/main.c:1055 -+msgid "while loading audit plugin module(s)" -+msgstr "beim Laden des/der Auditerweiterungsmoduls/Auditerweiterungsmodule" -+ -+#: ../../src/kdc/main.c:1059 -+msgid "commencing operation" -+msgstr "Aktion wird begonnen" -+ -+#: ../../src/kdc/main.c:1067 -+msgid "shutting down" -+msgstr "wird heruntergefahren" -+ -+#: ../../src/lib/apputils/net-server.c:258 -+msgid "Got signal to request exit" -+msgstr "Signal zur Anfrage des Beendens empfangen" -+ -+#: ../../src/lib/apputils/net-server.c:272 -+msgid "Got signal to reset" -+msgstr "Signal zum Zurücksetzen empfangen" -+ -+#: ../../src/lib/apputils/net-server.c:429 -+#, c-format -+msgid "closing down fd %d" -+msgstr "Dateideskriptor %d wird geschlossen" -+ -+#: ../../src/lib/apputils/net-server.c:443 -+#, c-format -+msgid "descriptor %d closed but still in svc_fdset" -+msgstr "Deskriptor %d geschlossen, aber immer noch in »svc_fdset«" -+ -+#: ../../src/lib/apputils/net-server.c:469 -+msgid "cannot create io event" -+msgstr "E/A-Ereignis kann nicht erzeugt werden" -+ -+#: ../../src/lib/apputils/net-server.c:475 -+msgid "cannot save event" -+msgstr "Ereignis kann nicht gesichert werden" -+ -+#: ../../src/lib/apputils/net-server.c:495 -+#, c-format -+msgid "file descriptor number %d too high" -+msgstr "Dateideskriptornummer %d zu hoch" -+ -+#: ../../src/lib/apputils/net-server.c:503 -+msgid "cannot allocate storage for connection info" -+msgstr "Speicher für Verbindungsinformation kann nicht reserviert werden" -+ -+#: ../../src/lib/apputils/net-server.c:562 -+#, c-format -+msgid "Cannot create TCP server socket on %s" -+msgstr "Auf %s kann kein TCP-Server-Socket erstellt werden." -+ -+#: ../../src/lib/apputils/net-server.c:571 -+#, c-format -+msgid "TCP socket fd number %d (for %s) too high" -+msgstr "TCP-Socket-Deskriptornummer %d (für %s) zu hoch" -+ -+#: ../../src/lib/apputils/net-server.c:579 -+#, c-format -+msgid "Cannot enable SO_REUSEADDR on fd %d" -+msgstr "SO_REUSEADDR kann nicht für Dateideskriptor %d aktiviert werden" -+ -+#: ../../src/lib/apputils/net-server.c:586 -+#, c-format -+msgid "setsockopt(%d,IPV6_V6ONLY,1) failed" -+msgstr "setsockopt(%d,IPV6_V6ONLY,1) fehlgeschlagen" -+ -+#: ../../src/lib/apputils/net-server.c:588 -+#, c-format -+msgid "setsockopt(%d,IPV6_V6ONLY,1) worked" -+msgstr "setsockopt(%d,IPV6_V6ONLY,1) funktioniert" -+ -+#: ../../src/lib/apputils/net-server.c:591 -+msgid "no IPV6_V6ONLY socket option support" -+msgstr "keine Socket-Option für IPV6_V6ONLY unterstützt" -+ -+#: ../../src/lib/apputils/net-server.c:597 -+#, c-format -+msgid "Cannot bind server socket on %s" -+msgstr "Server-Socket kann nicht an %s gebunden werden" -+ -+#: ../../src/lib/apputils/net-server.c:624 -+#, c-format -+msgid "Cannot create RPC service: %s; continuing" -+msgstr "RPC-Dienst kann nicht erstellt werden: %s; es wird fortgefahren" -+ -+#: ../../src/lib/apputils/net-server.c:633 -+#, c-format -+msgid "Cannot register RPC service: %s; continuing" -+msgstr "RPC-Dienst kann nicht registriert werden: %s; es wird fortgefahren" -+ -+#: ../../src/lib/apputils/net-server.c:682 -+#, c-format -+msgid "Cannot listen on TCP server socket on %s" -+msgstr "" -+"Auf dem TCP-Server-Socket kann nicht auf eine Verbindung gewartet werden auf " -+"%s." -+ -+#: ../../src/lib/apputils/net-server.c:688 -+#, c-format -+msgid "cannot set listening tcp socket on %s non-blocking" -+msgstr "" -+"Das auf eine Verbindung wartende TCP-Socket kann nicht auf nicht-" -+"blockierendes %s gesetzt werden." -+ -+#: ../../src/lib/apputils/net-server.c:695 -+#, c-format -+msgid "disabling SO_LINGER on TCP socket on %s" -+msgstr "SO_LINGER auf dem TCP-Socket auf %s wird deaktiviert" -+ -+#: ../../src/lib/apputils/net-server.c:743 -+#: ../../src/lib/apputils/net-server.c:752 -+#, c-format -+msgid "listening on fd %d: tcp %s" -+msgstr "auf Dateideskriptor %d wird auf eine Verbindung gewartet: TCP %s" -+ -+#: ../../src/lib/apputils/net-server.c:757 -+msgid "assuming IPv6 socket accepts IPv4" -+msgstr "es wird davon ausgegangen, dass das IPv6-Socket IPv4 akzeptiert" -+ -+#: ../../src/lib/apputils/net-server.c:791 -+#: ../../src/lib/apputils/net-server.c:804 -+#, c-format -+msgid "listening on fd %d: rpc %s" -+msgstr "auf Dateideskriptor %d wird auf eine Verbindung gewartet: RPC %s" -+ -+#: ../../src/lib/apputils/net-server.c:883 -+#, c-format -+msgid "Cannot request packet info for udp socket address %s port %d" -+msgstr "" -+"Paketinformation für UDP-Socket-Adresse %s, Port %d, kann nicht abgefragt " -+"werden" -+ -+#: ../../src/lib/apputils/net-server.c:889 -+#, c-format -+msgid "listening on fd %d: udp %s%s" -+msgstr "auf Dateideskriptor %d wird auf eine Verbindung gewartet: UDP %s%s" -+ -+#: ../../src/lib/apputils/net-server.c:918 -+msgid "Failed to reconfigure network, exiting" -+msgstr "Neukonfiguration des Netzwerks fehlgeschlagen, wird beendet" -+ -+#: ../../src/lib/apputils/net-server.c:979 -+#, c-format -+msgid "" -+"unhandled routing message type %d, will reconfigure just for the fun of it" -+msgstr "" -+"nicht behandelter Routing-Meldungstyp %d, es wird es nur zum Spaß neu " -+"konfiguriert" -+ -+#: ../../src/lib/apputils/net-server.c:1013 -+#, c-format -+msgid "short read (%d/%d) from routing socket" -+msgstr "ungenügende Daten (%d/%d) vom Routing-Socket gelesen" -+ -+#: ../../src/lib/apputils/net-server.c:1023 -+#, c-format -+msgid "read %d from routing socket but msglen is %d" -+msgstr "%d vom Routing-Socket gelesen, Nachrichtenlänge ist jedoch %d" -+ -+#: ../../src/lib/apputils/net-server.c:1055 -+#, c-format -+msgid "couldn't set up routing socket: %s" -+msgstr "Routing-Socket konnte nicht eingerichtet werden: %s" -+ -+#: ../../src/lib/apputils/net-server.c:1058 -+#, c-format -+msgid "routing socket is fd %d" -+msgstr "Das Routing-Socket hat den Dateideskriptor %d." -+ -+#: ../../src/lib/apputils/net-server.c:1084 -+msgid "setting up network..." -+msgstr "Netzwerk wird eingerichtet …" -+ -+#: ../../src/lib/apputils/net-server.c:1101 -+#, c-format -+msgid "set up %d sockets" -+msgstr "%d Sockets werden eingerichtet" -+ -+#: ../../src/lib/apputils/net-server.c:1103 -+msgid "no sockets set up?" -+msgstr "keine Sockets eingerichtet?" -+ -+#: ../../src/lib/apputils/net-server.c:1351 -+#: ../../src/lib/apputils/net-server.c:1405 -+msgid "while dispatching (udp)" -+msgstr "beim Versenden (UDP)" -+ -+#: ../../src/lib/apputils/net-server.c:1380 -+#, c-format -+msgid "while sending reply to %s/%s from %s" -+msgstr "beim Senden der Antwort zu %s/%s von %s" -+ -+#: ../../src/lib/apputils/net-server.c:1385 -+#, c-format -+msgid "short reply write %d vs %d\n" -+msgstr "ungenügende Ausgabe der Antwort %d gegenüber %d\n" -+ -+#: ../../src/lib/apputils/net-server.c:1430 -+msgid "while receiving from network" -+msgstr "beim Empfangen vom Netzwerk" -+ -+#: ../../src/lib/apputils/net-server.c:1446 -+#, c-format -+msgid "pktinfo says local addr is %s" -+msgstr "Pktinfo sagt, die lokale Adresse sei %s" -+ -+#: ../../src/lib/apputils/net-server.c:1479 -+msgid "too many connections" -+msgstr "zu viele Verbindungen" -+ -+#: ../../src/lib/apputils/net-server.c:1502 -+#, c-format -+msgid "dropping %s fd %d from %s" -+msgstr "%s Dateideskriptor %d von %s wird verworfen" -+ -+#: ../../src/lib/apputils/net-server.c:1580 -+#, c-format -+msgid "allocating buffer for new TCP session from %s" -+msgstr "Puffer für neue TCP-Sitzung von %s wird reserviert" -+ -+#: ../../src/lib/apputils/net-server.c:1610 -+msgid "while dispatching (tcp)" -+msgstr "beim Versenden (TCP)" -+ -+#: ../../src/lib/apputils/net-server.c:1642 -+msgid "error allocating tcp dispatch private!" -+msgstr "Fehler beim Reservieren zum nicht öffentlichen TCP-Versand!" -+ -+#: ../../src/lib/apputils/net-server.c:1689 -+#, c-format -+msgid "TCP client %s wants %lu bytes, cap is %lu" -+msgstr "TCP-Client %s will %lu Byte, Cap ist %lu" -+ -+#: ../../src/lib/apputils/net-server.c:1697 -+#, c-format -+msgid "error constructing KRB_ERR_FIELD_TOOLONG error! %s" -+msgstr "Fehler beim Erzeugen des KRB_ERR_FIELD_TOOLONG-Fehlers! %s" -+ -+#: ../../src/lib/apputils/net-server.c:1876 -+#, c-format -+msgid "accepted RPC connection on socket %d from %s" -+msgstr "akzeptierte PRC-Verbindung auf Socket %d von %s" -+ -+# pseudo random function -+#: ../../src/lib/crypto/krb/cf2.c:114 -+#, c-format -+msgid "Enctype %d has no PRF" -+msgstr "Verschlüsselungstyp %d hat keine PRF" -+ -+#: ../../src/lib/crypto/krb/prng_fortuna.c:428 -+msgid "Random number generator could not be seeded" -+msgstr "Zufallszahlengenerator konnte kein Startwert zugewiesen werden" -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:43 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:165 -+msgid "A required input parameter could not be read" -+msgstr "Ein benötigter Eingabeparameter konnte nicht gelesen werden." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:44 -+msgid "A required input parameter could not be written" -+msgstr "Ein benötigter Eingabeparameter konnte nicht geschrieben werden." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:45 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:175 -+msgid "A parameter was malformed" -+msgstr "Ein Parameter hatte eine falsche Form" -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:48 -+msgid "calling error" -+msgstr "Aufruffehler" -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:59 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:195 -+msgid "An unsupported mechanism was requested" -+msgstr "Ein nicht unterstützter Mechanismus wurde angefordert." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:60 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:199 -+msgid "An invalid name was supplied" -+msgstr "Ein ungültiger Name wurde übergeben." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:61 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:203 -+msgid "A supplied name was of an unsupported type" -+msgstr "Ein übergebener Name hatte einen nicht unterstützten Typ." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:62 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:208 -+msgid "Incorrect channel bindings were supplied" -+msgstr "Falsche Kanalbindungen wurden übergeben." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:63 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:179 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:274 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:334 -+msgid "An invalid status code was supplied" -+msgstr "Ein ungültiger Statuscode wurde übergeben." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:64 -+msgid "A token had an invalid signature" -+msgstr "Ein Merkmal hatte eine ungültige Signatur." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:65 -+msgid "No credentials were supplied" -+msgstr "Es wurden keine Anmeldedaten übergeben." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:66 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:223 -+msgid "No context has been established" -+msgstr "Es wurde keine Kontext etabliert." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:67 -+msgid "A token was invalid" -+msgstr "Ein Merkmal war ungültig." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:68 -+msgid "A credential was invalid" -+msgstr "Eine der Anmeldedaten war ungültig." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:69 -+msgid "The referenced credentials have expired" -+msgstr "Die referenzierten Anmeldedaten sind abgelaufen." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:70 -+msgid "The context has expired" -+msgstr "Der Kontext ist abgelaufen." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:71 -+msgid "Miscellaneous failure" -+msgstr "sonstiger Fehlschlag" -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:72 -+msgid "The quality-of-protection requested could not be provided" -+msgstr "" -+"Die angeforderte Qualität des Schutzes konnte nicht bereitgestellt werden." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:73 -+msgid "The operation is forbidden by the local security policy" -+msgstr "Die Aktion wird durch die lokale Sicherheitsrichtinie verboten." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:74 -+msgid "The operation or option is not available" -+msgstr "Die Aktion oder Option ist nicht verfügbar." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:77 -+msgid "routine error" -+msgstr "Fehler in einer Routine" -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:89 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:311 -+msgid "The routine must be called again to complete its function" -+msgstr "" -+"Die Routine muss erneut aufgerufen werden, um ihre Funktion zu " -+"vervollständigen." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:90 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:316 -+msgid "The token was a duplicate of an earlier token" -+msgstr "Das Merkmal war ein Zweitexemplar eines früheren Merkmals." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:91 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:321 -+msgid "The token's validity period has expired" -+msgstr "Die Gültigkeitsperiode des Merkmals ist abgelaufen." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:92 -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:325 -+msgid "A later token has already been processed" -+msgstr "Es wurde bereits ein neueres Merkmal verarbeitet." -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:95 -+msgid "supplementary info code" -+msgstr "zusätzlicher Informationscode" -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:106 -+#: ../lib/krb5/error_tables/krb5_err.c:23 -+msgid "No error" -+msgstr "kein Fehler" -+ -+#: ../../src/lib/gssapi/generic/disp_major_status.c:107 -+#, c-format -+msgid "Unknown %s (field = %d)" -+msgstr "%s unbekannt (Feld = %d)" -+ -+#: ../../src/lib/gssapi/krb5/acquire_cred.c:165 -+#, c-format -+msgid "No key table entry found matching %s" -+msgstr "Es wurde kein zu %s passender Schlüsseltabelleneintrag gefunden." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:161 -+msgid "The routine completed successfully" -+msgstr "Die Routine wurde erfolgreich abgeschlossen" -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:170 -+msgid "A required output parameter could not be written" -+msgstr "Ein erforderlicher Ausgabeparameter konnte nicht geschrieben werden." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:212 -+msgid "A token had an invalid Message Integrity Check (MIC)" -+msgstr "" -+"Ein Merkmal hatte eine ungültige Meldungsintegritätsprüfung (Message " -+"Integrity Check/MIC)." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:217 -+msgid "" -+"No credentials were supplied, or the credentials were unavailable or " -+"inaccessible" -+msgstr "" -+"Es wurden keine Anmeldedaten übergeben oder die Anmeldedaten waren nicht " -+"verfügbar bzw. ein Zugriff darauf nicht möglich." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:227 -+msgid "Invalid token was supplied" -+msgstr "Es wurde ein ungültiges Token übergeben." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:231 -+msgid "Invalid credential was supplied" -+msgstr "ungültige Anmeldedaten wurden übergeben" -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:235 -+msgid "The referenced credential has expired" -+msgstr "Die referenzierten Anmeldedaten sind abgelaufen." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:239 -+msgid "The referenced context has expired" -+msgstr "Der referenzierte Kontext ist abgelaufen." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:243 -+msgid "Unspecified GSS failure. Minor code may provide more information" -+msgstr "" -+"nicht spezifizierter GSS-Fehlschlag. Möglicherweise stellt der " -+"untergeordnete Code weitere Informationen bereit." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:248 -+msgid "The quality-of-protection (QOP) requested could not be provided" -+msgstr "" -+"Die Qualität des Schutzes (quality-of-protection/QOP) konnte nicht " -+"bereitgestellt werden." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:253 -+msgid "The operation is forbidden by local security policy" -+msgstr "Die Aktion wird durch die lokale Sicherheitsrichtinie verboten." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:258 -+msgid "The operation or option is not available or unsupported" -+msgstr "" -+"Die Aktion oder Option ist nicht verfügbar oder wird nicht unterstützt." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:263 -+msgid "The requested credential element already exists" -+msgstr "Das angeforderte Anmeldedatenelement existiert bereits." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:268 -+msgid "The provided name was not mechanism specific (MN)" -+msgstr "Der bereitgestellte Name war nicht mechanismusspezifisch (MN)." -+ -+#: ../../src/lib/gssapi/mechglue/g_dsp_status.c:329 -+msgid "An expected per-message token was not received" -+msgstr "Ein erwartetes nachrichtenspezifisches Token wurde nicht empfangen." -+ -+#: ../../src/lib/gssapi/spnego/spnego_mech.c:1860 -+msgid "SPNEGO cannot find mechanisms to negotiate" -+msgstr "SPNEGO kann keine Mechanismen zum Aushandeln finden." -+ -+#: ../../src/lib/gssapi/spnego/spnego_mech.c:1865 -+msgid "SPNEGO failed to acquire creds" -+msgstr "SPNEGO ist beim Beschaffen von Anmeldedaten gescheitert" -+ -+#: ../../src/lib/gssapi/spnego/spnego_mech.c:1870 -+msgid "SPNEGO acceptor did not select a mechanism" -+msgstr "SPNEGO-Abnehmer hat keinen Mechanismus ausgewählt" -+ -+#: ../../src/lib/gssapi/spnego/spnego_mech.c:1875 -+msgid "SPNEGO failed to negotiate a mechanism" -+msgstr "SPNEGO ist beim Aushandeln eines Mechanismus gescheitert." -+ -+#: ../../src/lib/gssapi/spnego/spnego_mech.c:1880 -+msgid "SPNEGO acceptor did not return a valid token" -+msgstr "SPNEGO-Abnehmer hat kein gültiges Token zurückgeliefert" -+ -+#: ../../src/lib/kadm5/alt_prof.c:854 -+#, c-format -+msgid "Cannot resolve address of admin server \"%s\" for realm \"%s\"" -+msgstr "" -+"Adresse des Admin-Servers »%s« für Realm »%s« kann nicht ermittelt werden" -+ -+#: ../../src/lib/kadm5/logger.c:56 -+#, c-format -+msgid "%s: cannot parse <%s>\n" -+msgstr "%s: <%s> kann nicht ausgewertet werden\n" -+ -+#: ../../src/lib/kadm5/logger.c:57 -+#, c-format -+msgid "%s: warning - logging entry syntax error\n" -+msgstr "%s: Warnung – Syntaxfehler bei Protokolleintrag\n" -+ -+#: ../../src/lib/kadm5/logger.c:58 -+#, c-format -+msgid "%s: error writing to %s\n" -+msgstr "%s: Fehler beim Schreiben auf %s\n" -+ -+#: ../../src/lib/kadm5/logger.c:59 -+#, c-format -+msgid "%s: error writing to %s device\n" -+msgstr "%s: Fehler beim Schreiben auf Gerät %s\n" -+ -+#: ../../src/lib/kadm5/logger.c:61 -+msgid "EMERGENCY" -+msgstr "NOTFALL" -+ -+#: ../../src/lib/kadm5/logger.c:62 -+msgid "ALERT" -+msgstr "ALARM" -+ -+#: ../../src/lib/kadm5/logger.c:63 -+msgid "CRITICAL" -+msgstr "KRITISCH" -+ -+#: ../../src/lib/kadm5/logger.c:64 -+msgid "Error" -+msgstr "Fehler" -+ -+#: ../../src/lib/kadm5/logger.c:65 -+msgid "Warning" -+msgstr "Warnung" -+ -+#: ../../src/lib/kadm5/logger.c:66 -+msgid "Notice" -+msgstr "Hinweis" -+ -+#: ../../src/lib/kadm5/logger.c:67 -+msgid "info" -+msgstr "Information" -+ -+#: ../../src/lib/kadm5/logger.c:68 -+msgid "debug" -+msgstr "Fehlersuchmeldung" -+ -+#: ../../src/lib/kadm5/logger.c:967 -+#, c-format -+msgid "Couldn't open log file %s: %s\n" -+msgstr "Protokolldatei %s konnte nicht geöffnet werden: %s\n" -+ -+#: ../../src/lib/kadm5/srv/kadm5_hook.c:119 -+#, c-format -+msgid "kadm5_hook %s failed postcommit %s: %s" -+msgstr "»kadm5_hook« %s ist beim Nach-Commit %s gescheitert: %s" -+ -+#: ../../src/lib/kadm5/srv/pwqual_dict.c:106 -+msgid "No dictionary file specified, continuing without one." -+msgstr "keine Wörterbuchdatei angegeben, es wird ohne fortgefahren" -+ -+#: ../../src/lib/kadm5/srv/pwqual_dict.c:113 -+#, c-format -+msgid "WARNING! Cannot find dictionary file %s, continuing without one." -+msgstr "" -+"WARNUNG! Wörterbuchdatei %s kann nicht gefunden werden, es wird ohne " -+"fortgefahren" -+ -+#: ../../src/lib/kadm5/srv/pwqual_empty.c:42 -+msgid "Empty passwords are not allowed" -+msgstr "Leere Passwörter sind nicht erlaubt." -+ -+#: ../../src/lib/kadm5/srv/pwqual_hesiod.c:114 -+msgid "Password may not match user information." -+msgstr "Das Passwort darf keinen Anwenderdaten entsprechen." -+ -+#: ../../src/lib/kadm5/srv/pwqual_princ.c:54 -+msgid "Password may not match principal name" -+msgstr "Das Passwort darf nicht mit dem Principal-Namen übereinstimmen." -+ -+#: ../../src/lib/kadm5/srv/server_acl.c:89 -+#, c-format -+msgid "%s: line %d too long, truncated" -+msgstr "%s: Zeile %d zu lang, wurde gekürzt" -+ -+#: ../../src/lib/kadm5/srv/server_acl.c:90 -+#, c-format -+msgid "Unrecognized ACL operation '%c' in %s" -+msgstr "unbekannte ACL-Aktion »%c« in %s" -+ -+#: ../../src/lib/kadm5/srv/server_acl.c:92 -+#, c-format -+msgid "%s: syntax error at line %d <%10s...>" -+msgstr "%s: Syntaxfehler in Zeile %d <%10s …>" -+ -+#: ../../src/lib/kadm5/srv/server_acl.c:94 -+#, c-format -+msgid "%s while opening ACL file %s" -+msgstr "%s beim Öffnen der ACL-Datei %s" -+ -+#: ../../src/lib/kadm5/srv/server_acl.c:353 -+#, c-format -+msgid "%s: invalid restrictions: %s" -+msgstr "%s: ungültige Beschränkung: %s" -+ -+#: ../../src/lib/kadm5/srv/server_kdb.c:192 -+msgid "History entry contains no key data" -+msgstr "Chronikeintrag enthält keine Schlüsseldaten" -+ -+#: ../../src/lib/kadm5/srv/server_misc.c:128 -+#, c-format -+msgid "password quality module %s rejected password for %s: %s" -+msgstr "" -+"Das Modul %s für Passwortqualität hat das Passwort für %s abgelehnt: %s" -+ -+#: ../../src/lib/kadm5/str_conv.c:80 -+msgid "Not Postdateable" -+msgstr "nicht vordatierbar" -+ -+#: ../../src/lib/kadm5/str_conv.c:81 -+msgid "Not Forwardable" -+msgstr "nicht weiterleitbar" -+ -+#: ../../src/lib/kadm5/str_conv.c:82 -+msgid "No TGT-based requests" -+msgstr "keine TGT-basierten Anfragen" -+ -+#: ../../src/lib/kadm5/str_conv.c:83 -+msgid "Not renewable" -+msgstr "nicht erneuerbar" -+ -+#: ../../src/lib/kadm5/str_conv.c:84 -+msgid "Not proxiable" -+msgstr "Proxy nicht nutzbar" -+ -+#: ../../src/lib/kadm5/str_conv.c:85 -+msgid "No DUP_SKEY requests" -+msgstr "keine DUP_SKEY-Anfragen" -+ -+#: ../../src/lib/kadm5/str_conv.c:86 -+msgid "All Tickets Disallowed" -+msgstr "keine Tickets erlaubt" -+ -+#: ../../src/lib/kadm5/str_conv.c:87 -+msgid "Preauthentication required" -+msgstr "Vorauthentifizierung erforderlich" -+ -+#: ../../src/lib/kadm5/str_conv.c:88 -+msgid "HW authentication required" -+msgstr "HW-Authentifizierung erforderlich" -+ -+#: ../../src/lib/kadm5/str_conv.c:89 -+msgid "OK as Delegate" -+msgstr "OK als Vertreter" -+ -+#: ../../src/lib/kadm5/str_conv.c:90 -+msgid "Password Change required" -+msgstr "Passwortänderung erforderlich" -+ -+#: ../../src/lib/kadm5/str_conv.c:91 -+msgid "Service Disabled" -+msgstr "Dienst deaktiviert" -+ -+#: ../../src/lib/kadm5/str_conv.c:92 -+msgid "Password Changing Service" -+msgstr "Passwortänderungsdienst" -+ -+#: ../../src/lib/kadm5/str_conv.c:93 -+msgid "RSA-MD5 supported" -+msgstr "RSA-MD5 unterstützt" -+ -+#: ../../src/lib/kadm5/str_conv.c:94 -+msgid "Protocol transition with delegation allowed" -+msgstr "Protokollübergang mit Vertretung erlaubt" -+ -+#: ../../src/lib/kadm5/str_conv.c:95 -+msgid "No authorization data required" -+msgstr "keine Autorisierungsdaten erforderlich" -+ -+#: ../../src/lib/kdb/kdb5.c:219 -+msgid "No default realm set; cannot initialize KDB" -+msgstr "kein Standard-Realm gesetzt; KDB kann nicht initialisiert werden" -+ -+#: ../../src/lib/kdb/kdb5.c:324 ../../src/lib/kdb/kdb5.c:406 -+#, c-format -+msgid "Unable to find requested database type: %s" -+msgstr "angeforderter Datenbanktyp kann nicht gefunden werden. %s" -+ -+#: ../../src/lib/kdb/kdb5.c:416 -+#, c-format -+msgid "plugin symbol 'kdb_function_table' lookup failed: %s" -+msgstr "" -+"Nachschlagen des Erweiterungssymbols »kdb_function_table« fehlgeschlagen: %s" -+ -+#: ../../src/lib/kdb/kdb5.c:426 -+#, c-format -+msgid "" -+"Unable to load requested database module '%s': plugin symbol " -+"'kdb_function_table' not found" -+msgstr "" -+"angefordertes Datenbankmodul »%s« kann nicht geladen werden: " -+"Erweiterungssymbol »kdb_function_table« nicht gefunden" -+ -+#: ../../src/lib/kdb/kdb5.c:1650 -+#, c-format -+msgid "Illegal version number for KRB5_TL_MKEY_AUX %d\n" -+msgstr "Ungültige Versionsnummer für KRB5_TL_MKEY_AUX %d\n" -+ -+#: ../../src/lib/kdb/kdb5.c:1819 -+#, c-format -+msgid "Illegal version number for KRB5_TL_ACTKVNO %d\n" -+msgstr "Ungültige Versionsnummer für KRB5_TL_ACTKVNO %d\n" -+ -+#: ../../src/lib/kdb/kdb_default.c:164 -+#, c-format -+msgid "keyfile (%s) is not a regular file: %s" -+msgstr "Schlüsseldatei (%s) ist keine normale Datei: %s" -+ -+#: ../../src/lib/kdb/kdb_default.c:177 -+msgid "Could not create temp keytab file name." -+msgstr "Temporärer Schlüsseltabellendateiname konnte nicht erstellt werden." -+ -+#: ../../src/lib/kdb/kdb_default.c:202 -+#, c-format -+msgid "Temporary stash file already exists: %s." -+msgstr "Temporäre Ablagedatei existiert bereits: %s." -+ -+#: ../../src/lib/kdb/kdb_default.c:230 -+#, c-format -+msgid "rename of temporary keyfile (%s) to (%s) failed: %s" -+msgstr "" -+"Umbenennen von temporärer Schlüsseldatei (%s) in (%s) fehlgeschlagen: %s" -+ -+#: ../../src/lib/kdb/kdb_default.c:419 -+#, c-format -+msgid "Can not fetch master key (error: %s)." -+msgstr "Hauptschlüssel kann nicht abgeholt werden (Fehler: %s)" -+ -+#: ../../src/lib/kdb/kdb_default.c:482 -+msgid "Unable to decrypt latest master key with the provided master key\n" -+msgstr "" -+"Letzter Hauptschlüssel kann nicht mit dem bereitgestellten Hauptschlüssel " -+"entschlüsselt werden.\n" -+ -+#: ../../src/lib/kdb/kdb_log.c:83 -+msgid "could not sync ulog header to disk" -+msgstr "Ulog-Kopfzeilen konnten nicht auf die Platte synchronisiert werden" -+ -+#: ../../src/lib/krb5/ccache/cc_dir.c:122 -+#, c-format -+msgid "Subsidiary cache path %s has no parent directory" -+msgstr "" -+"Ergänzender Zwischenspeicherpfad %s hat kein übergeordnetes Verzeichnis." -+ -+#: ../../src/lib/krb5/ccache/cc_dir.c:128 -+#, c-format -+msgid "Subsidiary cache path %s filename does not begin with \"tkt\"" -+msgstr "" -+"Dateiname des ergänzenden Zwischenspeicherpfads %s beginnt nicht mit »tkt«" -+ -+#: ../../src/lib/krb5/ccache/cc_dir.c:169 -+#, c-format -+msgid "%s contains invalid filename" -+msgstr "%s enthält einen ungültigen Dateinamen." -+ -+#: ../../src/lib/krb5/ccache/cc_dir.c:229 -+#, c-format -+msgid "Credential cache directory %s does not exist" -+msgstr "Anmeldedatenzwischenspeicherverzeichnis %s existiert nicht." -+ -+#: ../../src/lib/krb5/ccache/cc_dir.c:235 -+#, c-format -+msgid "Credential cache directory %s exists but is not a directory" -+msgstr "" -+"Anmeldedatenzwischenspeicherverzeichnis %s existiert, ist jedoch kein " -+"Verzeichnis" -+ -+#: ../../src/lib/krb5/ccache/cc_dir.c:400 -+msgid "" -+"Can't create new subsidiary cache because default cache is not a directory " -+"collection" -+msgstr "" -+"Der neue ergänzende Zwischenspeicher kann nicht erstellt werden, da der " -+"Standardzwischenspeicher keine Ansammlung von Verzeichnissen ist." -+ -+#: ../../src/lib/krb5/ccache/cc_file.c:569 -+#, c-format -+msgid "Credentials cache file '%s' not found" -+msgstr "Anmeldedatenzwischenspeicherdatei »%s« nicht gefunden" -+ -+#: ../../src/lib/krb5/ccache/cc_file.c:1575 -+#, c-format -+msgid "Credentials cache I/O operation failed (%s)" -+msgstr "Anmeldedatenzwischenspeicher-E/A-Aktion fehlgeschlagen (%s)" -+ -+#: ../../src/lib/krb5/ccache/cc_keyring.c:1151 -+msgid "" -+"Can't create new subsidiary cache because default cache is already a " -+"subsidiary" -+msgstr "" -+"Der neue ergänzende Zwischenspeicher kann nicht erstellt werden, da der " -+"Standardzwischenspeicher bereits eine Ergänzung ist." -+ -+#: ../../src/lib/krb5/ccache/cc_keyring.c:1219 -+#, c-format -+msgid "Credentials cache keyring '%s' not found" -+msgstr "Schlüsselbund %s des Anmeldedatenzwischenspeichers nicht gefunden" -+ -+#: ../../src/lib/krb5/ccache/cccursor.c:212 -+#, c-format -+msgid "Can't find client principal %s in cache collection" -+msgstr "" -+"Client-Principal %s kann nicht in der Zwischenspeicheransammlung gefunden " -+"werden" -+ -+#: ../../src/lib/krb5/ccache/cccursor.c:253 -+msgid "No Kerberos credentials available" -+msgstr "keine Kerberos-Anmeldedaten verfügbar" -+ -+#: ../../src/lib/krb5/keytab/kt_file.c:398 -+#, c-format -+msgid "No key table entry found for %s" -+msgstr "Für %s wurde kein Schlüsseltabelleneintrag gefunden." -+ -+#: ../../src/lib/krb5/keytab/kt_file.c:815 -+#: ../../src/lib/krb5/keytab/kt_file.c:848 -+msgid "Cannot change keytab with keytab iterators active" -+msgstr "" -+"Schlüsseltabelle mit aktiven Schlüsseltabelleniteratoren kann nicht geändert " -+"werden" -+ -+#: ../../src/lib/krb5/keytab/kt_file.c:1047 -+#, c-format -+msgid "Key table file '%s' not found" -+msgstr "Schlüsseltabellendatei »%s« nicht gefunden" -+ -+#: ../../src/lib/krb5/keytab/ktfns.c:127 -+#, c-format -+msgid "Keytab %s is nonexistent or empty" -+msgstr "Schlüsseltabelle %s existiert nicht oder ist leer" -+ -+#: ../../src/lib/krb5/krb/chpw.c:251 -+msgid "Malformed request error" -+msgstr "Fehler wegen Anfrage in falscher Form" -+ -+#: ../../src/lib/krb5/krb/chpw.c:254 ../lib/krb5/error_tables/kdb5_err.c:58 -+msgid "Server error" -+msgstr "Serverfehler" -+ -+#: ../../src/lib/krb5/krb/chpw.c:257 -+msgid "Authentication error" -+msgstr "Authentifizierungsfehler" -+ -+#: ../../src/lib/krb5/krb/chpw.c:260 -+msgid "Password change rejected" -+msgstr "Passwortänderung abgelehnt" -+ -+#: ../../src/lib/krb5/krb/chpw.c:263 -+msgid "Access denied" -+msgstr "Zugriff verweigert" -+ -+#: ../../src/lib/krb5/krb/chpw.c:266 -+msgid "Wrong protocol version" -+msgstr "falsche Protokollversion" -+ -+#: ../../src/lib/krb5/krb/chpw.c:269 -+msgid "Initial password required" -+msgstr "Erstpasswort erforderlich" -+ -+#: ../../src/lib/krb5/krb/chpw.c:272 -+msgid "Success" -+msgstr "Erfolg" -+ -+#: ../../src/lib/krb5/krb/chpw.c:275 ../lib/krb5/error_tables/krb5_err.c:257 -+msgid "Password change failed" -+msgstr "Ändern des Passworts fehlgeschlagen" -+ -+#: ../../src/lib/krb5/krb/chpw.c:433 -+msgid "" -+"The password must include numbers or symbols. Don't include any part of " -+"your name in the password." -+msgstr "" -+"Das Passwort muss Zahlen oder Symbole enthalten. Fügen Sie keinen Teil Ihres " -+"Namens in das Passwort ein." -+ -+#: ../../src/lib/krb5/krb/chpw.c:439 -+#, c-format -+msgid "The password must contain at least %d character." -+msgid_plural "The password must contain at least %d characters." -+msgstr[0] "Das Passwort muss mindestens %d Zeichen enthalten." -+msgstr[1] "Das Passwort muss mindestens %d Zeichen enthalten." -+ -+#: ../../src/lib/krb5/krb/chpw.c:448 -+#, c-format -+msgid "The password must be different from the previous password." -+msgid_plural "The password must be different from the previous %d passwords." -+msgstr[0] "Das Passwort muss sich vom vorhergehenden Passwort unterscheiden." -+msgstr[1] "" -+"Das Passwort muss sich von den vorhergehenden %d Passwörtern unterscheiden." -+ -+#: ../../src/lib/krb5/krb/chpw.c:460 -+#, c-format -+msgid "The password can only be changed once a day." -+msgid_plural "The password can only be changed every %d days." -+msgstr[0] "Das Passwort kann nur einmal täglich geändert werden." -+msgstr[1] "Das Passwort kann nur alle %d Tage geändert werden." -+ -+#: ../../src/lib/krb5/krb/chpw.c:506 -+msgid "Try a more complex password, or contact your administrator." -+msgstr "" -+"Versuchen Sie es mit einem etwas komplexeren Passwort oder wenden Sie sich " -+"an Ihren Administrator." -+ -+#: ../../src/lib/krb5/krb/fast.c:217 -+#, c-format -+msgid "%s constructing AP-REQ armor" -+msgstr "%s-Konstruktion von AP-REQ-Schutz" -+ -+#: ../../src/lib/krb5/krb/fast.c:399 -+#, c-format -+msgid "%s while decrypting FAST reply" -+msgstr "%s beim Entschlüsseln der FAST-Antwort" -+ -+#: ../../src/lib/krb5/krb/fast.c:408 -+msgid "nonce modified in FAST response: KDC response modified" -+msgstr "" -+"Nummer für einmaligen Gebrauch in der FAST-Anwort geändert: KDC-Anwort " -+"geändert" -+ -+#: ../../src/lib/krb5/krb/fast.c:474 -+msgid "Expecting FX_ERROR pa-data inside FAST container" -+msgstr "Innerhalb des FAST-Containers wird »FX_ERROR pa-data« erwartet." -+ -+#: ../../src/lib/krb5/krb/fast.c:545 -+msgid "FAST response missing finish message in KDC reply" -+msgstr "Der FAST-Anwort fehlt die Beendigungsnachricht in der KDC-Anwort" -+ -+#: ../../src/lib/krb5/krb/fast.c:558 -+msgid "Ticket modified in KDC reply" -+msgstr "Ticket in der KDC-Antwort verändert" -+ -+#: ../../src/lib/krb5/krb/gc_via_tkt.c:208 -+#, c-format -+msgid "KDC returned error string: %.*s" -+msgstr "KDC gab eine Fehlermeldung zurück: %.*s" -+ -+#: ../../src/lib/krb5/krb/gc_via_tkt.c:217 -+#, c-format -+msgid "Server %s not found in Kerberos database" -+msgstr "Server %s wurde nicht in der Kerberos-Datenbank gefunden" -+ -+#: ../../src/lib/krb5/krb/get_in_tkt.c:133 -+msgid "Reply has wrong form of session key for anonymous request" -+msgstr "" -+"Antwort hat die falsche Form des Sitzungschlüssels für eine anonyme Anfrage" -+ -+#: ../../src/lib/krb5/krb/get_in_tkt.c:1628 -+#, c-format -+msgid "%s while storing credentials" -+msgstr "%s beim Speichern der Anmeldedaten" -+ -+#: ../../src/lib/krb5/krb/get_in_tkt.c:1715 -+#, c-format -+msgid "Client '%s' not found in Kerberos database" -+msgstr "Client »%s« wurde nicht in der Kerberos-Datenbank gefunden" -+ -+#: ../../src/lib/krb5/krb/gic_keytab.c:207 -+#, c-format -+msgid "Keytab contains no suitable keys for %s" -+msgstr "Schlüsseltabelle enthält keine passenden Schlüssel für %s" -+ -+#: ../../src/lib/krb5/krb/gic_pwd.c:75 -+#, c-format -+msgid "Password for %s" -+msgstr "Passwort for %s" -+ -+#: ../../src/lib/krb5/krb/gic_pwd.c:227 -+#, c-format -+msgid "Warning: Your password will expire in less than one hour on %s" -+msgstr "" -+"Warnung: Ihr Passwort auf %s wird in weniger als einer Stunde ablaufen." -+ -+# FIXME in German impossible; plural without »s« -+#: ../../src/lib/krb5/krb/gic_pwd.c:231 -+#, c-format -+msgid "Warning: Your password will expire in %d hour%s on %s" -+msgstr "Warnung: Ihr Passwort wird in %d Stunden%s auf %s ablaufen." -+ -+#: ../../src/lib/krb5/krb/gic_pwd.c:235 -+#, c-format -+msgid "Warning: Your password will expire in %d days on %s" -+msgstr "Warnung: Ihr Passwort wird in %d Tagen auf %s ablaufen." -+ -+#: ../../src/lib/krb5/krb/gic_pwd.c:409 -+msgid "Password expired. You must change it now." -+msgstr "Passwort abgelaufen. Sie müssen es nun ändern." -+ -+#: ../../src/lib/krb5/krb/gic_pwd.c:428 ../../src/lib/krb5/krb/gic_pwd.c:432 -+#, c-format -+msgid "%s. Please try again." -+msgstr "%s. Bitte versuchen Sie es erneut." -+ -+#: ../../src/lib/krb5/krb/gic_pwd.c:471 -+#, c-format -+msgid "%.*s%s%s. Please try again.\n" -+msgstr "%.*s%s%s. Bitte versuchen Sie es erneut.\n" -+ -+#: ../../src/lib/krb5/krb/parse.c:203 -+#, c-format -+msgid "Principal %s is missing required realm" -+msgstr "Principal %s fehlt erforderlicher Realm" -+ -+#: ../../src/lib/krb5/krb/parse.c:215 -+#, c-format -+msgid "Principal %s has realm present" -+msgstr "Für Principal %s ist Realm vorhanden" -+ -+#: ../../src/lib/krb5/krb/plugin.c:165 -+#, c-format -+msgid "Invalid module specifier %s" -+msgstr "ungültiger Modulbezeichner %s" -+ -+#: ../../src/lib/krb5/krb/plugin.c:402 -+#, c-format -+msgid "Could not find %s plugin module named '%s'" -+msgstr "Das Erweiterungsmodul %s namens »%s« konnte nicht gefunden werden." -+ -+#: ../../src/lib/krb5/krb/preauth2.c:1018 -+msgid "Unable to initialize preauth context" -+msgstr "Vorauthentifizierungskontext konnte nicht initialisiert werden." -+ -+#: ../../src/lib/krb5/krb/preauth2.c:1032 -+#, c-format -+msgid "Preauth module %s: %s" -+msgstr "Vorauthentifizierungsmodul %s: %s" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:510 -+msgid "Please choose from the following:\n" -+msgstr "Bitte wählen Sie aus dem Folgenden aus:\n" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:511 -+msgid "Vendor:" -+msgstr "Anbieter:" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:523 -+msgid "Enter #" -+msgstr "Geben Sie # ein" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:559 -+msgid "OTP Challenge:" -+msgstr "Anforderung des Einwegpassworts:" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:588 -+msgid "OTP Token PIN" -+msgstr "Einwegpasswort-Token-PIN" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:702 -+msgid "OTP value doesn't match any token formats" -+msgstr "Wert des Einwegpassworts entspricht keinem Token-Format" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:769 -+msgid "Enter OTP Token Value" -+msgstr "Geben Sie den Wert des Einwegpasswort-Tokens an" -+ -+#: ../../src/lib/krb5/krb/preauth_otp.c:914 -+msgid "No supported tokens" -+msgstr "keine unterstützten Token" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:49 -+msgid "Challenge for Enigma Logic mechanism" -+msgstr "Anforderung für Enigma-Logic-Mechanismus" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:53 -+msgid "Challenge for Digital Pathways mechanism" -+msgstr "Anforderung für Digital-Pathway-Mechanismus" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:57 -+msgid "Challenge for Activcard mechanism" -+msgstr "Anforderung für Activcard-Mechanismus" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:60 -+msgid "Challenge for Enhanced S/Key mechanism" -+msgstr "Anforderung für erweiterten S/Key-Mechanismus" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:63 -+msgid "Challenge for Traditional S/Key mechanism" -+msgstr "Anforderung für traditionellen S/Key-Mechanismus" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:66 -+#: ../../src/lib/krb5/krb/preauth_sam2.c:69 -+msgid "Challenge for Security Dynamics mechanism" -+msgstr "Anforderung für Security-Dynamics-Mechanismus" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:72 -+msgid "Challenge from authentication server" -+msgstr "Anforderung vom Authentifizierungsserver" -+ -+#: ../../src/lib/krb5/krb/preauth_sam2.c:166 -+msgid "SAM Authentication" -+msgstr "SAM-Authentifizierung" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:145 -+#, c-format -+msgid "Cannot find key for %s kvno %d in keytab" -+msgstr "" -+"Schlüssel für %s-KNVO %d kann nicht in der Schlüsseltabelle gefunden werden" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:150 -+#, c-format -+msgid "Cannot find key for %s kvno %d in keytab (request ticket server %s)" -+msgstr "" -+"Schlüssel für %s-KNVO %d kann nicht in der Schlüsseltabelle gefunden werden " -+"(angefragter Ticketserver %s)" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:175 -+#, c-format -+msgid "Cannot decrypt ticket for %s using keytab key for %s" -+msgstr "" -+"Ticket für %s kann nicht mittels des Schlüsseltabellenschlüssels für %s " -+"entschlüsselt werden" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:197 -+#, c-format -+msgid "Server principal %s does not match request ticket server %s" -+msgstr "Server-Principal %s passt nicht zum abgefragten Ticketserver %s" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:226 -+msgid "No keys in keytab" -+msgstr "keine Schlüssel in der Schlüsseltabelle" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:229 -+#, c-format -+msgid "Server principal %s does not match any keys in keytab" -+msgstr "" -+"Server-Principal %s hat keinen passenden Schlüssel in der Schlüsseltabelle" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:236 -+#, c-format -+msgid "" -+"Request ticket server %s found in keytab but does not match server principal " -+"%s" -+msgstr "" -+"abgefragter Ticketserver %s wurde in der Schlüsseltabelle gefunden, er passte " -+"jedoch nicht zu Server-Principal %s" -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:241 -+#, c-format -+msgid "Request ticket server %s not found in keytab (ticket kvno %d)" -+msgstr "" -+"Abgefragter Ticketserver %s wurde nicht in der Schlüsseltabelle gefunden " -+"(Ticket KVNO %d)." -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:247 -+#, c-format -+msgid "" -+"Request ticket server %s kvno %d not found in keytab; ticket is likely out " -+"of date" -+msgstr "" -+"Abgefragter Ticketserver %s KVNO %d wurde nicht in der Schlüsseltabelle " -+"gefunden; Ticket ist wahrscheinlich abgelaufen." -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:252 -+#, c-format -+msgid "" -+"Request ticket server %s kvno %d not found in keytab; keytab is likely out " -+"of date" -+msgstr "" -+"Abgefragter Ticketserver %s KVNO %d wurde nicht in der Schlüsseltabelle " -+"gefunden; Schlüsseltabelle ist wahrscheinlich nicht mehr aktuell." -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:261 -+#, c-format -+msgid "" -+"Request ticket server %s kvno %d found in keytab but not with enctype %s" -+msgstr "" -+"Abgefragter Ticketserver %s KVNO %d wurde in der Schlüsseltabelle gefunden, " -+"jedoch nicht mit Verschlüsselungstyp %s." -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:266 -+#, c-format -+msgid "" -+"Request ticket server %s kvno %d enctype %s found in keytab but cannot " -+"decrypt ticket" -+msgstr "" -+"Abgefragter Ticketserver %s KVNO %d mit Verschlüsselungstyp %s in der " -+"Schlüsseltabelle gefunden, Ticket kann jedoch nicht entschlüsselt werden." -+ -+#: ../../src/lib/krb5/krb/rd_req_dec.c:897 -+#, c-format -+msgid "Encryption type %s not permitted" -+msgstr "Verschlüsselungstyp %s nicht erlaubt" -+ -+#: ../../src/lib/krb5/os/expand_path.c:316 -+#, c-format -+msgid "Can't find username for uid %lu" -+msgstr "Zu UID %lu kann kein Benutzername gefunden werden." -+ -+#: ../../src/lib/krb5/os/expand_path.c:405 -+#: ../../src/lib/krb5/os/expand_path.c:421 -+msgid "Invalid token" -+msgstr "ungültiges Token" -+ -+#: ../../src/lib/krb5/os/expand_path.c:506 -+msgid "variable missing }" -+msgstr "Variable fehlt }" -+ -+#: ../../src/lib/krb5/os/locate_kdc.c:660 -+#, c-format -+msgid "Cannot find KDC for realm \"%.*s\"" -+msgstr "KDC für Realm »%.*s« kann nicht gefunden werden" -+ -+#: ../../src/lib/krb5/os/sendto_kdc.c:475 -+#, c-format -+msgid "Cannot contact any KDC for realm '%.*s'" -+msgstr "für Realm »%.*s« kann nicht KDC kontaktiert werden" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:106 -+#, c-format -+msgid "Cannot fstat replay cache file %s: %s" -+msgstr "»fstat« für Antwortzwischenspeicherdatei %s nicht möglich: %s" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:112 -+#, c-format -+msgid "" -+"Insecure mkstemp() file mode for replay cache file %s; try running this " -+"program with umask 077" -+msgstr "" -+"unsicherer mkstemp()-Dateimodus für Antwortzwischenspeicherdatei %s; " -+"versuchen Sie, dieses Programm mit der Umask 077 auszuführen" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:144 -+#, c-format -+msgid "Cannot %s replay cache file %s: %s" -+msgstr "%s der Wiederholungszwischenspeicherdatei %s nicht möglich: %s" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:149 -+#, c-format -+msgid "Cannot %s replay cache: %s" -+msgstr "%s des Wiederholungszwischenspeichers nicht möglich: %s" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:272 -+#, c-format -+msgid "Insecure file mode for replay cache file %s" -+msgstr "unsicherer Dateimodus für Wiederholungszwischenspeicherdatei %s" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:278 -+#, c-format -+msgid "rcache not owned by %d" -+msgstr "Rcache gehört nicht %d" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:402 ../../src/lib/krb5/rcache/rc_io.c:406 -+#: ../../src/lib/krb5/rcache/rc_io.c:411 -+#, c-format -+msgid "Can't write to replay cache: %s" -+msgstr "" -+"in Wiederholungszwischenspeicherdatei kann nicht geschrieben werden: %s" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:432 -+#, c-format -+msgid "Cannot sync replay cache file: %s" -+msgstr "" -+"Wiederholungszwischenspeicherdatei kann nicht synchronisiert werden: %s" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:451 -+#, c-format -+msgid "Can't read from replay cache: %s" -+msgstr "aus dem Wiederholungszwischenspeicher kann nicht gelesen werden: %s" -+ -+#: ../../src/lib/krb5/rcache/rc_io.c:482 ../../src/lib/krb5/rcache/rc_io.c:488 -+#: ../../src/lib/krb5/rcache/rc_io.c:493 -+#, c-format -+msgid "Can't destroy replay cache: %s" -+msgstr "Wiederholungszwischenspeicher kann nicht vernichtet werden: %s" -+ -+#: ../../src/plugins/kdb/db2/kdb_db2.c:245 -+#: ../../src/plugins/kdb/db2/kdb_db2.c:830 -+#, c-format -+msgid "Unsupported argument \"%s\" for db2" -+msgstr "nicht unterstütztes Argument »%s« für DB2" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:69 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:887 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1088 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1507 -+msgid "while reading kerberos container information" -+msgstr "beim Lesen der Kerberos-Container-Information" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:129 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:143 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:504 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:518 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:151 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:166 -+msgid "while providing time specification" -+msgstr "beim Bereitstellen der Zeitspezifikation" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:268 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:304 -+msgid "while creating policy object" -+msgstr "beim Erstellen des Richtlinienobjekts" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:279 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1515 -+msgid "while reading realm information" -+msgstr "beim Lesen der Realm-Information" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:348 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:407 -+msgid "while destroying policy object" -+msgstr "beim Zerstören des Richtlinienobjekts" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:358 -+#, c-format -+msgid "This will delete the policy object '%s', are you sure?\n" -+msgstr "Dies wird das Richtlinienobjekt »%s« löschen, sind Sie sicher?\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:473 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:663 -+msgid "while modifying policy object" -+msgstr "beim Ändern des Richtlinienobjekts" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:487 -+#, c-format -+msgid "while reading information of policy '%s'" -+msgstr "beim Lesen der Information der Richtlinie »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:692 -+msgid "while viewing policy" -+msgstr "beim Betrachten der Richtlinie" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:701 -+#, c-format -+msgid "while viewing policy '%s'" -+msgstr "beim Betrachten der Richtlinie »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_policy.c:835 -+msgid "while listing policy objects" -+msgstr "beim Auflisten der Richtlinienobjekte" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:453 -+#, c-format -+msgid "for subtree while creating realm '%s'" -+msgstr "für einen Teilbaum beim Erstellen von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:465 -+#, c-format -+msgid "for container reference while creating realm '%s'" -+msgstr "für Container-Bezug beim Erstellen von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:489 -+#, c-format -+msgid "invalid search scope while creating realm '%s'" -+msgstr "ungültiger Suchbereich beim Erstellen von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:504 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:823 -+#, c-format -+msgid "'%s' is an invalid option\n" -+msgstr "»%s« ist keine gültige Option\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:512 -+#, c-format -+msgid "Initializing database for realm '%s'\n" -+msgstr "Datenbank für Realm »%s« wird initialisiert\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:536 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:696 -+#, c-format -+msgid "while creating realm '%s'" -+msgstr "beim Erstellen von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:556 -+#, c-format -+msgid "Enter DN of Kerberos container: " -+msgstr "Geben Sie die den DN des Kerberos-Containers ein: " -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:591 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:894 -+#, c-format -+msgid "while reading information of realm '%s'" -+msgstr "beim Lesen der Information von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:733 -+msgid "while reading Kerberos container information" -+msgstr "beim Lesen der Kerberos-Container-Information" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:774 -+#, c-format -+msgid "for subtree while modifying realm '%s'" -+msgstr "für einen Teilbaum beim Ändern von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:785 -+#, c-format -+msgid "for container reference while modifying realm '%s'" -+msgstr "für Container-Bezug beim Ändern von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:812 -+#, c-format -+msgid "specified for search scope while modifying information of realm '%s'" -+msgstr "" -+"angegeben für Suchbereich, während die Information für Realm »%s« geändert " -+"wird" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:851 -+#, c-format -+msgid "while modifying information of realm '%s'" -+msgstr "beim Ändern der Information von Realm »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:940 -+msgid "Realm Name" -+msgstr "Realm-Name" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:943 -+msgid "Subtree" -+msgstr "Teilbaum" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:946 -+msgid "Principal Container Reference" -+msgstr "Principal-Container-Bezug" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:951 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:953 -+msgid "SearchScope" -+msgstr "Suchbereich" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:951 -+msgid "Invalid !" -+msgstr "ungültig!" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:958 -+msgid "KDC Services" -+msgstr "KDC-Dienste" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:973 -+msgid "Admin Services" -+msgstr "Administratordienste" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:988 -+msgid "Passwd Services" -+msgstr "Passwortdienste" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1004 -+msgid "Maximum Ticket Life" -+msgstr "maximale Ticketlebensdauer" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1009 -+msgid "Maximum Renewable Life" -+msgstr "maximale verlängerbare Lebensdauer" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1016 -+msgid "Ticket flags" -+msgstr "Ticket-Flags" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1095 -+msgid "while listing realms" -+msgstr "beim Auflisten der Realms" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1439 -+msgid "while adding entries to database" -+msgstr "beim Hinzufügen von Einträgen zur Datenbank" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1480 -+#, c-format -+msgid "Deleting KDC database of '%s', are you sure?\n" -+msgstr "" -+"Sind Sie sicher, dass die KDC-Datenbank von »%s« gelöscht werden soll?\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1491 -+#, c-format -+msgid "OK, deleting database of '%s'...\n" -+msgstr "OK, die Datenbank von »%s« wird gelöscht …\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1524 -+#, c-format -+msgid "deleting database of '%s'" -+msgstr "Die Datenbank von »%s« wird gelöscht." -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c:1529 -+#, c-format -+msgid "** Database of '%s' destroyed.\n" -+msgstr "** Datenbank von »%s« vernichtet\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:81 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:88 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:96 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:104 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:120 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:148 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:227 -+msgid "while setting service object password" -+msgstr "beim Setzen des Passworts für das Dienstobjekt" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:140 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:477 -+#, c-format -+msgid "Password for \"%s\"" -+msgstr "Passwort für »%s«" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:143 -+#, c-format -+msgid "Re-enter password for \"%s\"" -+msgstr "Geben Sie das Passwort für »%s« erneut ein." -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:154 -+#, c-format -+msgid "%s: Invalid password\n" -+msgstr "%s: ungültiges Passwort\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:170 -+msgid "Failed to convert the password to hexadecimal" -+msgstr "Das Umwandeln des Passworts in Dezimalschreibweise ist fehlgeschlagen." -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:183 -+#, c-format -+msgid "Failed to open file %s: %s" -+msgstr "Datei %s konnte nicht geöffnet werden: %s" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:205 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:247 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:256 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:283 -+msgid "Failed to write service object password to file" -+msgstr "" -+"Schreiben des Passworts für das Dienstobjekt in eine Datei fehlgeschlagen" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:211 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:268 -+msgid "Error reading service object password file" -+msgstr "Fehler beim Lesen der Passwortdatei für das Dienstobjekt" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c:236 -+#, c-format -+msgid "Error creating file %s" -+msgstr "Fehler beim Erstellen der Datei %s" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:105 -+#, c-format -+msgid "" -+"Usage: kdb5_ldap_util [-D user_dn [-w passwd]] [-H ldapuri]\n" -+"\tcmd [cmd_options]\n" -+"create [-subtrees subtree_dn_list] [-sscope search_scope] [-" -+"containerref container_reference_dn]\n" -+"\t\t[-m|-P password|-sf stashfilename] [-k mkeytype] [-kv mkeyVNO] [-s]\n" -+"\t\t[-maxtktlife max_ticket_life] [-maxrenewlife max_renewable_ticket_life]\n" -+"\t\t[ticket_flags] [-r realm]\n" -+"modify [-subtrees subtree_dn_list] [-sscope search_scope] [-" -+"containerref container_reference_dn]\n" -+"\t\t[-maxtktlife max_ticket_life] [-maxrenewlife max_renewable_ticket_life]\n" -+"\t\t[ticket_flags] [-r realm]\n" -+"view [-r realm]\n" -+"destroy [-f] [-r realm]\n" -+"list\n" -+"stashsrvpw [-f filename] service_dn\n" -+"create_policy [-r realm] [-maxtktlife max_ticket_life]\n" -+"\t\t[-maxrenewlife max_renewable_ticket_life] [ticket_flags] policy\n" -+"modify_policy [-r realm] [-maxtktlife max_ticket_life]\n" -+"\t\t[-maxrenewlife max_renewable_ticket_life] [ticket_flags] policy\n" -+"view_policy [-r realm] policy\n" -+"destroy_policy [-r realm] [-force] policy\n" -+"list_policy [-r realm]\n" -+msgstr "" -+"Aufruf: kdb5_ldap_util [-D Benutzer-DN [-w Passwort]] [-H LDAP-URI]\n" -+"\tcmd [Befehlsoptionen]\n" -+"create [-subtrees DN-Liste_Teilbäume] [-sscope Suchbereich] [-" -+"containerref Container-Bezug-DN]\n" -+"\t\t[-m|-P Passwort|-sf Ablagedateiname] [-k mkeytype] [-kv mkeyVNO] [-s]\n" -+"\t\t[-maxtktlife maximale_Ticketlebensdauer]\n" -+"\t\t[-maxrenewlife maximale_Dauer_bis_zum_Erneuern_des_Tickets]\n" -+"\t\t[Ticket_Flags] [-r Realm]\n" -+"modify [-subtrees DN-Liste_Teilbäume] [-sscope Suchbereich] [-" -+"containerref Container-Bezug-DN]\n" -+"\t\t[-maxtktlife maximale_Ticketlebensdauer]\n" -+"\t\t[-maxrenewlife maximale_Dauer_bis_zum_Erneuern_des_Tickets]\n" -+"\t\t[Ticket_Flags] [-r Realm]\n" -+"view [-r Realm]\n" -+"destroy [-f] [-r Realm]\n" -+"list\n" -+"stashsrvpw [-f Dateiname] Dienst-DN\n" -+"create_policy [-r Realm] [-maxtktlife maximale_Ticketlebensdauer]\n" -+"\t\t[-maxrenewlife maximale_Dauer_bis_zum_Erneuern_des_Tickets]\n" -+"\t\t[Ticket_Flags] Richtlinie\n" -+"modify_policy [-r Realm] [-maxtktlife maximale_Ticketlebensdauer]\n" -+"\t\t[-maxrenewlife maximale_Dauer_bis_zum_Erneuern_des_Tickets]\n" -+"\t\t[Ticket_Flags] Richtlinie\n" -+"view_policy [-r Realm] Richtlinie\n" -+"destroy_policy [-r Realm] [-force] Richtlinie\n" -+"list_policy [-r Realm]\n" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:325 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:333 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:341 -+msgid "while reading ldap parameters" -+msgstr "beim Lesen der LDAP-Parameter" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:439 -+msgid "while initializing error handling" -+msgstr "beim Initialisieren der Fehlerbehandlung" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:447 -+msgid "while initializing ldap handle" -+msgstr "beim Initialisieren des LDAP-Identifikators" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:461 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:470 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:483 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:525 -+msgid "while retrieving ldap configuration" -+msgstr "beim Abfragen der LDAP-Konfiguration" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:500 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:507 -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:516 -+msgid "while initializing server list" -+msgstr "beim Initialisieren der Serverliste" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:547 -+msgid "while setting up lib handle" -+msgstr "ein Einrichten der BibliotheksIdentifikators" -+ -+#: ../../src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c:556 -+msgid "while reading ldap configuration" -+msgstr "beim Lesen der LDAP-Konfiguration" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.c:68 -+msgid "Unable to read Kerberos container" -+msgstr "Kerberos-Container kann nicht gelesen werden" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.c:74 -+msgid "Unable to read Realm" -+msgstr "Realm kann nicht gelesen werden" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.c:215 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c:73 -+msgid "Error processing LDAP DB params:" -+msgstr "Fehler beim Verarbeiten der LDAP-Datenbankparameter:" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.c:222 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c:80 -+msgid "Error reading LDAP server params:" -+msgstr "Fehler beim Lesen der LDAP-Server-Parameters:" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap_conn.c:64 -+msgid "LDAP bind dn value missing" -+msgstr "LDAP-Bindungs-DN-Wert fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap_conn.c:69 -+msgid "LDAP bind password value missing" -+msgstr "LDAP-Bindungs-Passwortwert fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap_conn.c:77 -+msgid "Error reading password from stash: " -+msgstr "Fehler beim Lesen des Passworts aus der Ablage: " -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap_conn.c:85 -+msgid "Service password length is zero" -+msgstr "Länge des Dienstpassworts ist Null" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap_conn.c:145 -+#, c-format -+msgid "Cannot bind to LDAP server '%s' with SASL mechanism '%s': %s" -+msgstr "" -+"mit LDAP-Server »%s« kann keine Verbindung mit SASL-Mechanismus »%s« " -+"hergestellt werden: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap_conn.c:158 -+#, c-format -+msgid "Cannot bind to LDAP server '%s' as '%s': %s" -+msgstr "" -+"mit LDAP-Server »%s« kann keine Verbindung als »%s« hergestellt werden: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap_conn.c:183 -+#, c-format -+msgid "Cannot create LDAP handle for '%s': %s" -+msgstr "LDAP-Identifikator für »%s« kann nicht erstellt werden: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c:131 -+msgid "could not complete roll-back, error deleting Kerberos Container" -+msgstr "" -+"Zurücksetzen kann nicht abgeschlossen werden, Fehler beim Löschen des " -+"Kerberos-Containers" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_krbcontainer.c:56 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_krbcontainer.c:67 -+msgid "Error reading kerberos container location from krb5.conf" -+msgstr "" -+"Fehler beim Lesen des Kerberos-Container-Speicherorts aus der »krb5.conf«." -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_krbcontainer.c:75 -+msgid "Kerberos container location not specified" -+msgstr "Kerberos-Container-Speicherort nicht angegeben" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c:55 -+#, c-format -+msgid "Error reading '%s' attribute: %s" -+msgstr "Fehler beim Lesen des Attributs »%s«: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c:218 -+msgid "KDB module requires -update argument" -+msgstr "KDB-Modul benötigt Argument »-update«" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c:224 -+#, c-format -+msgid "'%s' value missing" -+msgstr "Wert »%s« fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c:282 -+#, c-format -+msgid "unknown option '%s'" -+msgstr "unbekannte Option »%s«" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c:342 -+msgid "Minimum connections required per server is 2" -+msgstr "Die benötigte Mindestanzahl von Verbindungen pro Server ist zwei" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c:159 -+msgid "Default realm not set" -+msgstr "Standard-Realm nicht gesetzt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c:262 -+msgid "DN information missing" -+msgstr "DN-Information fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:108 -+msgid "Principal does not belong to realm" -+msgstr "Principal gehört nicht zum Realm" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:278 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:287 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:295 -+#, c-format -+msgid "%s option not supported" -+msgstr "Option %s wird nicht unterstützt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:302 -+#, c-format -+msgid "unknown option: %s" -+msgstr "unbekannte Option: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:309 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:316 -+#, c-format -+msgid "%s option value missing" -+msgstr "Wert der Option %s fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:542 -+msgid "Principal does not belong to the default realm" -+msgstr "Principal gehört nicht zum Standard-Realm" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:610 -+#, c-format -+msgid "" -+"operation can not continue, more than one entry with principal name \"%s\" " -+"found" -+msgstr "" -+"Die Aktion kann nicht fortfahren, da mehr als ein Principal namens »%s« " -+"gefunden wurde." -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:673 -+#, c-format -+msgid "'%s' not found: " -+msgstr "»%s« nicht gefunden: " -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:751 -+msgid "DN is out of the realm subtree" -+msgstr "DN liegt außerhalb ders Teilbaums des Realms" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:807 -+#, c-format -+msgid "ldap object is already kerberized" -+msgstr "LDAP-Objekt ist bereits an Kerberos angepasst" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:827 -+#, c-format -+msgid "" -+"link information can not be set/updated as the kerberos principal belongs to " -+"an ldap object" -+msgstr "" -+"Verweisinformation kann nicht eingerichtet/aktualisiert werden, da der " -+"Kerberos-Principal zu einem LDAP-Objekt gehört." -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:842 -+#, c-format -+msgid "Failed getting object references" -+msgstr "Holen von Objektbezügen fehlgeschlagen" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:849 -+#, c-format -+msgid "kerberos principal is already linked to a ldap object" -+msgstr "Kerberos-Principal ist bereits mit einem LDAP-Objekt verknüpft" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:1167 -+msgid "ticket policy object value: " -+msgstr "Wert des Ticket-Richtlinienobjekts: " -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:1215 -+#, c-format -+msgid "Principal delete failed (trying to replace entry): %s" -+msgstr "" -+"Löschen des Principals fehlgeschlagen (es wird versucht, den Eintrag zu " -+"ersetzen): %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:1225 -+#, c-format -+msgid "Principal add failed: %s" -+msgstr "Hinzufügen des Principals fehlgeschlagen: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:1263 -+#, c-format -+msgid "User modification failed: %s" -+msgstr "Änderung des Benutzers fehlgeschlagen: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:1336 -+msgid "Error reading ticket policy. " -+msgstr "Fehler beim Lesen der Ticket-Richtlinie" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c:1402 -+#, c-format -+msgid "unable to decode stored principal key data (%s)" -+msgstr "" -+"Die gespeicherten Schlüsseldaten des Principals (%s) konnten nicht " -+"dekodiert werden." -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:223 -+msgid "Realm information not available" -+msgstr "Realm-Information nicht verfügbar" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:294 -+msgid "Error reading ticket policy: " -+msgstr "Fehler beim Lesen der Ticket-Richtlinie:" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:307 -+#, c-format -+msgid "Realm Delete FAILED: %s" -+msgstr "Löschen des Realms FEHLGESCHLAGEN: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:387 -+msgid "subtree value: " -+msgstr "Wert des Teilbaums: " -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:404 -+msgid "container reference value: " -+msgstr "Wert des Container-Bezugs: " -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:487 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:550 -+msgid "Kerberos Container information is missing" -+msgstr "Kerberos-Container-Information fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:499 -+msgid "Invalid Kerberos container DN" -+msgstr "ungültiger Kerberos-Container-DN" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:515 -+#, c-format -+msgid "Kerberos Container create FAILED: %s" -+msgstr "Erstellen des Kerberos-Containers FEHLGESCHLAGEN: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:558 -+#, c-format -+msgid "Kerberos Container delete FAILED: %s" -+msgstr "Löschen des Kerberos-Containers FEHLGESCHLAGEN: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c:634 -+msgid "realm object value: " -+msgstr "Wert des Realm-Objekts: " -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c:48 -+msgid "Not a hexadecimal password" -+msgstr "kein hexadezimales Passwort" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c:55 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c:66 -+msgid "Password corrupt" -+msgstr "Passwort beschädigt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c:93 -+#, c-format -+msgid "Cannot open LDAP password file '%s': %s" -+msgstr "LDAP-Passwortdatei »%s« kann nicht geöffnet werden: %s" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c:123 -+#, c-format -+msgid "Bind DN entry '%s' missing in LDAP password file '%s'" -+msgstr "Bind-DN-Eintrag »%s« fehlt in der LDAP-Passwortdatei »%s«" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:56 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:132 -+msgid "Ticket Policy Name missing" -+msgstr "Ticket-Richtlinienname fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:144 -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:221 -+msgid "ticket policy object: " -+msgstr "Ticket-Richtlinienobjekt: " -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:209 -+msgid "Ticket Policy Object information missing" -+msgstr "Ticket-Richtlinienobjekt-Information fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:300 -+msgid "Ticket Policy Object DN missing" -+msgstr "DN des Ticket-Richtlinienobjekts fehlt" -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:327 -+msgid "Delete Failed: One or more Principals associated with the Ticket Policy" -+msgstr "" -+"Löschen fehlgeschlagen: Ein oder mehrere Principals gehören zur Ticket-" -+"Richtlinie." -+ -+#: ../../src/plugins/kdb/ldap/libkdb_ldap/ldap_tkt_policy.c:435 -+msgid "Error reading container object: " -+msgstr "Fehler beim Lesen des Container-Objekts: " -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_crypto_nss.c:667 -+#: ../../src/plugins/preauth/pkinit/pkinit_crypto_openssl.c:652 -+#: ../../src/plugins/preauth/pkinit/pkinit_crypto_openssl.c:4153 -+msgid "Pass phrase for" -+msgstr "Passphrase für" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_crypto_openssl.c:1081 -+#, c-format -+msgid "Cannot create cert chain: %s" -+msgstr "Zertifikatskette kann nicht erstellt werden: %s" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_crypto_openssl.c:1408 -+msgid "Invalid pkinit packet: octet string expected" -+msgstr "ungültiges Pkinit-Paket: Achtbit-Zeichenkette erwartet" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_crypto_openssl.c:1427 -+msgid "wrong oid\n" -+msgstr "falsche OID\n" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_crypto_openssl.c:5994 -+#, c-format -+msgid "unknown code 0x%x" -+msgstr "unbekannter Code 0x%x" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_identity.c:424 -+#, c-format -+msgid "Unsupported type while processing '%s'\n" -+msgstr "nicht unterstützter Typ bei der Verarbeitung von »%s«\n" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_identity.c:465 -+msgid "Internal error parsing X509_user_identity\n" -+msgstr "interner Fehler beim Auswerten von »X509_user_identity«\n" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_identity.c:560 -+msgid "No user identity options specified" -+msgstr "keine Optionen der Nutzeridentität angegeben" -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_srv.c:414 -+msgid "Pkinit request not signed, but client not anonymous." -+msgstr "Pkinit-Anfrage nicht signiert, Client ist jedoch nicht anonym" -+ -+# DH = Diffie-Hellman -+#: ../../src/plugins/preauth/pkinit/pkinit_srv.c:447 -+msgid "Anonymous pkinit without DH public value not supported." -+msgstr "Anonymes Pkinit wird nicht ohne öffentlichen DH-Wert unterstützt." -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_srv.c:1147 -+#, c-format -+msgid "No pkinit_identity supplied for realm %s" -+msgstr "Für Realm %s wird keine »pkinit_identity« bereitgestellt." -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_srv.c:1158 -+#, c-format -+msgid "No pkinit_anchors supplied for realm %s" -+msgstr "Für Realm %s werden keine »pkinit_anchors« bereitgestellt." -+ -+#: ../../src/plugins/preauth/pkinit/pkinit_srv.c:1346 -+msgid "No realms configured correctly for pkinit support" -+msgstr "Für Pkinit-Unterstützung wurden keine Realms korrekt konfiguriert." -+ -+#: ../../src/slave/kprop.c:85 -+#, c-format -+msgid "" -+"\n" -+"Usage: %s [-r realm] [-f file] [-d] [-P port] [-s srvtab] slave_host\n" -+"\n" -+msgstr "" -+"\n" -+"Aufruf: %s [-r Realm] [-f Datei] [-d] [-P Port] [-s Dienstschlüsseltabelle] " -+"untergeordneter_Rechner\n" -+"\n" -+ -+#: ../../src/slave/kprop.c:114 -+#, c-format -+msgid "Database propagation to %s: SUCCEEDED\n" -+msgstr "Datenbankverbreitung auf %s: ERFOLGREICH\n" -+ -+#: ../../src/slave/kprop.c:187 -+msgid "while setting client principal name" -+msgstr "beim Setzen des Client-Principal-Namens" -+ -+#: ../../src/slave/kprop.c:194 ../../src/slave/kprop.c:209 -+msgid "while setting client principal realm" -+msgstr "beim Setzen des Client-Principal-Realms" -+ -+#: ../../src/slave/kprop.c:217 -+#, c-format -+msgid "while opening credential cache %s" -+msgstr "beim Öffnen des Anmeldedatenzwischenspeichers %s" -+ -+#: ../../src/slave/kprop.c:233 -+msgid "while setting server principal name" -+msgstr "beim Setzen des Server-Principal-Namens" -+ -+#: ../../src/slave/kprop.c:255 -+msgid "while resolving keytab" -+msgstr "beim Ermitteln der Schlüsseltabelle" -+ -+#: ../../src/slave/kprop.c:264 -+msgid "while getting initial credentials\n" -+msgstr "beim Holen der Anfangsanmeldedaten\n" -+ -+#: ../../src/slave/kprop.c:301 -+msgid "while creating socket" -+msgstr "beim Erstellen eines Sockets" -+ -+#: ../../src/slave/kprop.c:317 -+msgid "while converting server address" -+msgstr "beim Umwandeln der Server-Adresse" -+ -+#: ../../src/slave/kprop.c:327 -+msgid "while connecting to server" -+msgstr "beim Verbinden mit dem Server" -+ -+#: ../../src/slave/kprop.c:334 ../../src/slave/kpropd.c:1215 -+msgid "while getting local socket address" -+msgstr "beim Holen der lokalen Socket-Adresse" -+ -+#: ../../src/slave/kprop.c:339 -+msgid "while converting local address" -+msgstr "beim Umwandeln der lokalen Socket-Adresse" -+ -+#: ../../src/slave/kprop.c:362 -+msgid "in krb5_auth_con_setaddrs" -+msgstr "in »krb5_auth_con_setaddrs«" -+ -+#: ../../src/slave/kprop.c:370 -+msgid "while authenticating to server" -+msgstr "beim Authentifizieren am Server" -+ -+#: ../../src/slave/kprop.c:374 ../../src/slave/kprop.c:573 -+#: ../../src/slave/kpropd.c:1521 -+#, c-format -+msgid "Generic remote error: %s\n" -+msgstr "allgemeiner ferner Fehler: %s\n" -+ -+#: ../../src/slave/kprop.c:380 ../../src/slave/kprop.c:579 -+msgid "signalled from server" -+msgstr "signalisiert vom Server" -+ -+#: ../../src/slave/kprop.c:382 ../../src/slave/kprop.c:581 -+#, c-format -+msgid "Error text from server: %s\n" -+msgstr "Fehlermeldung vom Server: %s\n" -+ -+#: ../../src/slave/kprop.c:410 -+#, c-format -+msgid "allocating database file name '%s'" -+msgstr "Datenbankdateiname »%s« wird reserviert" -+ -+#: ../../src/slave/kprop.c:416 -+#, c-format -+msgid "while trying to open %s" -+msgstr "beim Versuch, %s zu öffnen" -+ -+#: ../../src/slave/kprop.c:423 -+msgid "database locked" -+msgstr "Datenbank gesperrt" -+ -+#: ../../src/slave/kprop.c:426 ../../src/slave/kpropd.c:525 -+#, c-format -+msgid "while trying to lock '%s'" -+msgstr "beim Versuch, »%s« zu sperren" -+ -+#: ../../src/slave/kprop.c:430 ../../src/slave/kprop.c:438 -+#, c-format -+msgid "while trying to stat %s" -+msgstr "beim Versuch, »stat« für %s auszuführen" -+ -+#: ../../src/slave/kprop.c:434 -+msgid "while trying to malloc data_ok_fn" -+msgstr "beim Versuch, Speicher für »data_ok_fn« zu reservieren" -+ -+#: ../../src/slave/kprop.c:443 -+#, c-format -+msgid "'%s' more recent than '%s'." -+msgstr "»%s« ist aktueller als »%s«." -+ -+#: ../../src/slave/kprop.c:459 -+#, c-format -+msgid "while unlocking database '%s'" -+msgstr "beim Entsperren von Datenbank »%s«" -+ -+#: ../../src/slave/kprop.c:492 ../../src/slave/kprop.c:493 -+msgid "while encoding database size" -+msgstr "beim Aufbereiten der Datenbankgröße" -+ -+#: ../../src/slave/kprop.c:501 -+msgid "while sending database size" -+msgstr "beim Senden der Datenbankgröße" -+ -+#: ../../src/slave/kprop.c:511 -+msgid "while allocating i_vector" -+msgstr "beim Reservieren von »i_vector«" -+ -+#: ../../src/slave/kprop.c:534 -+#, c-format -+msgid "while sending database block starting at %d" -+msgstr "beim Senden des Datenbankblocks, der bei %d beginnt" -+ -+#: ../../src/slave/kprop.c:544 -+msgid "Premature EOF found for database file!" -+msgstr "vorzeitiges EOF für Datenbankdatei gefunden!" -+ -+#: ../../src/slave/kprop.c:557 -+msgid "while reading response from server" -+msgstr "beim Lesen der Antwort vom Servers" -+ -+#: ../../src/slave/kprop.c:568 -+msgid "while decoding error response from server" -+msgstr "beim Aufschlüsseln der Fehlerantwort vom Server" -+ -+#: ../../src/slave/kprop.c:599 -+#, c-format -+msgid "Kpropd sent database size %d, expecting %d" -+msgstr "Kpropd sendet Datenbankgröße %d, erwartet wurde %d" -+ -+#: ../../src/slave/kprop.c:643 -+msgid "while allocating filename for update_last_prop_file" -+msgstr "beim Reservieren des Dateinamens für »update_last_prop_file«" -+ -+#: ../../src/slave/kprop.c:648 -+#, c-format -+msgid "while creating 'last_prop' file, '%s'" -+msgstr "beim Erstellen der Datei »last_prop«, »%s«" -+ -+#: ../../src/slave/kpropd.c:170 -+#, c-format -+msgid "" -+"\n" -+"Usage: %s [-r realm] [-s srvtab] [-dS] [-f slave_file]\n" -+msgstr "" -+"\n" -+"Aufruf: %s [-r Realm] [-s Dienstschlüsseltabelle] [-dS] [-f " -+"untergeordnete_Datei]\n" -+ -+#: ../../src/slave/kpropd.c:172 -+#, c-format -+msgid "\t[-F kerberos_db_file ] [-p kdb5_util_pathname]\n" -+msgstr "\t[-F Kerberos-Datenbankdatei ] [-p KDB5-Hilfswerkzeugpfadname]\n" -+ -+#: ../../src/slave/kpropd.c:173 -+#, c-format -+msgid "\t[-x db_args]* [-P port] [-a acl_file]\n" -+msgstr "\t[-x Datenbankargumente]* [-P Port] [-a ACL-Datei]\n" -+ -+#: ../../src/slave/kpropd.c:174 -+#, c-format -+msgid "\t[-A admin_server]\n" -+msgstr "\t[-A Serveradministrator]\n" -+ -+#: ../../src/slave/kpropd.c:215 -+#, c-format -+msgid "Killing fullprop child (%d)\n" -+msgstr "Beenden des Fullprop-Kindprozesses (%d) wird erzwungen\n" -+ -+#: ../../src/slave/kpropd.c:244 -+msgid "while checking if stdin is a socket" -+msgstr "beim Prüfen, ob die Standardeingabe ein Socket ist" -+ -+#: ../../src/slave/kpropd.c:262 -+#, c-format -+msgid "ready\n" -+msgstr "bereit\n" -+ -+#: ../../src/slave/kpropd.c:272 -+#, c-format -+msgid "Could not open /dev/null: %s" -+msgstr "/dev/null konnte nicht geöffnet werden: %s" -+ -+#: ../../src/slave/kpropd.c:279 -+#, c-format -+msgid "Could not dup the inetd socket: %s" -+msgstr "Das Inetd-Socket konnte nicht dupliziert werden: %s" -+ -+#: ../../src/slave/kpropd.c:314 ../../src/slave/kpropd.c:327 -+msgid "do_iprop failed.\n" -+msgstr "»do_iprop« fehlgeschlagen\n" -+ -+#: ../../src/slave/kpropd.c:366 -+#, c-format -+msgid "getaddrinfo: %s\n" -+msgstr "getaddrinfo: %s\n" -+ -+#: ../../src/slave/kpropd.c:372 -+msgid "while obtaining socket" -+msgstr "beim Erlangen des Sockets" -+ -+#: ../../src/slave/kpropd.c:378 -+msgid "while setting SO_REUSEADDR option" -+msgstr "beim Setzen der Option SO_REUSEADDR" -+ -+#: ../../src/slave/kpropd.c:386 -+msgid "while unsetting IPV6_V6ONLY option" -+msgstr "beim Entfernen der Option IPV6_V6ONLY" -+ -+#: ../../src/slave/kpropd.c:391 -+msgid "while binding listener socket" -+msgstr "beim Anbinden an das auf Verbindung wartende Socket" -+ -+#: ../../src/slave/kpropd.c:402 -+#, c-format -+msgid "waiting for a kprop connection\n" -+msgstr "warten auf Kprop-Verbindung\n" -+ -+#: ../../src/slave/kpropd.c:408 -+msgid "while accepting connection" -+msgstr "beim Akzeptieren der Verbindung" -+ -+#: ../../src/slave/kpropd.c:414 -+msgid "while forking" -+msgstr "beim Erzeugen eines Kindprozesses" -+ -+#: ../../src/slave/kpropd.c:429 -+#, c-format -+msgid "waitpid() failed to wait for doit() (%d %s)\n" -+msgstr "waitpid() schlug beim Warten auf doit() fehl (%d %s)\n" -+ -+#: ../../src/slave/kpropd.c:433 -+msgid "while waiting to receive database" -+msgstr "beim Warten auf den Erhalt der Datenbank" -+ -+#: ../../src/slave/kpropd.c:437 -+#, c-format -+msgid "Database load process for full propagation completed.\n" -+msgstr "" -+"Der Datenbankladeprozess für eine vollständige Verbreitung ist " -+"abgeschlossen.\n" -+ -+#: ../../src/slave/kpropd.c:471 -+#, c-format -+msgid "" -+"%s: Standard input does not appear to be a network socket.\n" -+"\t(Not run from inetd, and missing the -S option?)\n" -+msgstr "" -+"%s: Bei der Standardeingabe scheint es sich nicht um ein Netzwerk-Socket zu\n" -+"\thandeln (läuft nicht aus Inetd und die Option -S fehlt?).\n" -+ -+#: ../../src/slave/kpropd.c:485 -+msgid "while attempting setsockopt (SO_KEEPALIVE)" -+msgstr "beim Versuch, »setsockopt« auszuführen (SO_KEEPALIVE)" -+ -+#: ../../src/slave/kpropd.c:490 -+#, c-format -+msgid "Connection from %s" -+msgstr "Verbindung von %s" -+ -+#: ../../src/slave/kpropd.c:510 -+#, c-format -+msgid "Rejected connection from unauthorized principal %s\n" -+msgstr "Zurückgewiesene Verbindung von nicht autorisiertem Principal %s\n" -+ -+#: ../../src/slave/kpropd.c:514 -+#, c-format -+msgid "Rejected connection from unauthorized principal %s" -+msgstr "Zurückgewiesene Verbindung von nicht authorisiertem Principal %s" -+ -+#: ../../src/slave/kpropd.c:531 -+#, c-format -+msgid "while opening database file, '%s'" -+msgstr "beim Öffnen der Datenbankdatei, »%s«" -+ -+#: ../../src/slave/kpropd.c:537 -+#, c-format -+msgid "while renaming %s to %s" -+msgstr "beim Umbenennen von %s in %s" -+ -+#: ../../src/slave/kpropd.c:543 -+#, c-format -+msgid "while downgrading lock on '%s'" -+msgstr "beim Downgrade der Sperre auf »%s«" -+ -+#: ../../src/slave/kpropd.c:550 -+#, c-format -+msgid "while unlocking '%s'" -+msgstr "beim Aufheben der Sperre »%s«" -+ -+#: ../../src/slave/kpropd.c:562 -+msgid "while sending # of received bytes" -+msgstr "beim Senden n empfangener Byte" -+ -+#: ../../src/slave/kpropd.c:568 -+msgid "while trying to close database file" -+msgstr "beim Versuch, die Datenbankdatei zu schließen" -+ -+#: ../../src/slave/kpropd.c:624 -+#, c-format -+msgid "Incremental propagation enabled\n" -+msgstr "inkrementelle Verbreitung aktiviert\n" -+ -+#: ../../src/slave/kpropd.c:634 -+msgid "Unable to get default realm" -+msgstr "Standard-Realm kann nicht geholt werden" -+ -+#: ../../src/slave/kpropd.c:647 -+#, c-format -+msgid "%s: unable to get kiprop host based service name for realm %s\n" -+msgstr "" -+"%s: Kiprop-rechnerbasierter Dienstname für Realm %s kann nicht geholt " -+"werden\n" -+ -+#: ../../src/slave/kpropd.c:658 -+msgid "while trying to construct host service principal" -+msgstr "beim Versuch, den Rechnerdienst-Principal zu erstellen" -+ -+#: ../../src/slave/kpropd.c:672 -+msgid "while determining local service principal name" -+msgstr "beim Bestimmen des lokalen Dienst-Principal-Namens" -+ -+#: ../../src/slave/kpropd.c:692 -+#, c-format -+msgid "Initializing kadm5 as client %s\n" -+msgstr "Kadm5 wird als Client %s initialisiert\n" -+ -+#: ../../src/slave/kpropd.c:706 -+#, c-format -+msgid "kadm5 initialization failed!\n" -+msgstr "Initialisierung von Kadm5 fehlgeschlagen!\n" -+ -+#: ../../src/slave/kpropd.c:715 -+msgid "while attempting to connect to master KDC ... retrying" -+msgstr "" -+"beim Versuch, eine Verbindung zum Master-KDC aufzubauen … wird erneut " -+"versucht" -+ -+#: ../../src/slave/kpropd.c:719 -+#, c-format -+msgid "Sleeping %d seconds to re-initialize kadm5 (RPC ERROR)\n" -+msgstr "" -+"Um Kadm5 neu zu initialisieren, wird %d Sekunden gewartet (RPC-FEHLER).\n" -+ -+#: ../../src/slave/kpropd.c:735 -+#, c-format -+msgid "while initializing %s interface, retrying" -+msgstr "beim Initialisieren der Schnittstelle %s, wird erneut versucht" -+ -+#: ../../src/slave/kpropd.c:739 -+#, c-format -+msgid "Sleeping %d seconds to re-initialize kadm5 (krb5kdc not running?)\n" -+msgstr "" -+"Um Kadm5 neu zu initialisieren, wird %d Sekunden gewartet (läuft Krb5kdc " -+"nicht?).\n" -+ -+#: ../../src/slave/kpropd.c:749 -+#, c-format -+msgid "kadm5 initialization succeeded\n" -+msgstr "Initialisieren von Kadm5 erfolgreich\n" -+ -+#: ../../src/slave/kpropd.c:771 -+msgid "reading update log header" -+msgstr "Aktualisierungsprotokollkopfzeilen werden gelesen" -+ -+#: ../../src/slave/kpropd.c:782 -+#, c-format -+msgid "Calling iprop_get_updates_1 (sno=%u sec=%u usec=%u)\n" -+msgstr "»iprop_get_updates_1()« wird aufgerufen (sno=%u sec=%u usec=%u)\n" -+ -+#: ../../src/slave/kpropd.c:792 -+msgid "iprop_get_updates call failed" -+msgstr "Aufruf von »iprop_get_updates« fehlgeschlagen" -+ -+#: ../../src/slave/kpropd.c:798 -+#, c-format -+msgid "Reinitializing iprop because get updates failed\n" -+msgstr "" -+"Iprop wird neu initialisiert, da Aktualisierungen fehlgeschlagen sind\n" -+ -+#: ../../src/slave/kpropd.c:819 -+#, c-format -+msgid "Still waiting for full resync\n" -+msgstr "" -+"Es wird immer noch auf das vollständige erneute Synchronisieren gewartet.\n" -+ -+#: ../../src/slave/kpropd.c:824 -+#, c-format -+msgid "Full resync needed\n" -+msgstr "erneutes vollständiges Synchronisieren erforderlich\n" -+ -+#: ../../src/slave/kpropd.c:825 -+msgid "kpropd: Full resync needed." -+msgstr "Kpropd: erneutes vollständiges Synchronisieren erforderlich" -+ -+#: ../../src/slave/kpropd.c:830 -+msgid "iprop_full_resync call failed" -+msgstr "Aufruf von »iprop_full_resync« fehlgeschlagen" -+ -+#: ../../src/slave/kpropd.c:841 -+#, c-format -+msgid "Full resync request granted\n" -+msgstr "Anfrage nach vollständigem erneuten Synchronisieren genehmigt\n" -+ -+#: ../../src/slave/kpropd.c:842 -+msgid "Full resync request granted." -+msgstr "Anfrage nach vollständigem erneuten Synchronisieren genehmigt" -+ -+# FIXME s/backoff/back-off/ -+#: ../../src/slave/kpropd.c:851 -+#, c-format -+msgid "Exponential backoff\n" -+msgstr "exponentieller Wartezyklus\n" -+ -+#: ../../src/slave/kpropd.c:857 -+#, c-format -+msgid "Full resync permission denied\n" -+msgstr "vollständiges erneutes Synchronisieren nicht gestattet\n" -+ -+#: ../../src/slave/kpropd.c:858 -+msgid "Full resync, permission denied." -+msgstr "vollständiges erneutes Synchronisieren, nicht gestattet" -+ -+#: ../../src/slave/kpropd.c:863 -+#, c-format -+msgid "Full resync error from master\n" -+msgstr "Fehler beim vollständigen erneuten Synchronisieren vom Master\n" -+ -+#: ../../src/slave/kpropd.c:864 -+msgid " Full resync, error returned from master KDC." -+msgstr "" -+"vollständiges erneutes Synchronisieren, das Master-KDC gab einen Fehler " -+"zurück" -+ -+#: ../../src/slave/kpropd.c:872 -+#, c-format -+msgid "Full resync invalid result from master\n" -+msgstr "" -+"Beim vollständigen erneuten Synchronisieren gab der Master ein ungültiges " -+"Ergebnis zurück.\n" -+ -+#: ../../src/slave/kpropd.c:874 -+msgid "Full resync, invalid return from master KDC." -+msgstr "" -+"vollständiges erneutes Synchronisieren, ungültiger Rückgabewert vom Master-" -+"KDC" -+ -+#: ../../src/slave/kpropd.c:890 -+#, c-format -+msgid "Got incremental updates (sno=%u sec=%u usec=%u)\n" -+msgstr "" -+"inkrementelle Aktualisierungen erhalten (sno=%u sec=%u usec=%u)\n" -+ -+#: ../../src/slave/kpropd.c:902 -+#, c-format -+msgid "ulog_replay failed (%s), updates not registered\n" -+msgstr "" -+"»ulog_replay« fehlgeschlagen (%s), Aktualisierungen nicht registriert\n" -+ -+#: ../../src/slave/kpropd.c:905 -+#, c-format -+msgid "ulog_replay failed (%s), updates not registered." -+msgstr "»ulog_replay« fehlgeschlagen (%s), Aktualisierungen nicht registriert" -+ -+#: ../../src/slave/kpropd.c:914 -+#, c-format -+msgid "Incremental updates: %d updates / %lu us" -+msgstr "inkrementelle Aktualisierungen: %d Aktualisierungen / %lu us" -+ -+#: ../../src/slave/kpropd.c:917 -+#, c-format -+msgid "Incremental updates: %d updates / %lu us\n" -+msgstr "inkrementelle Aktualisierungen: %d Aktualisierungen / %lu us\n" -+ -+#: ../../src/slave/kpropd.c:925 -+#, c-format -+msgid "get_updates permission denied\n" -+msgstr "Zugriff bei »get_updates« verweigert\n" -+ -+#: ../../src/slave/kpropd.c:926 -+msgid "get_updates, permission denied." -+msgstr "»get_updates«, Zugriff verweigert" -+ -+#: ../../src/slave/kpropd.c:931 -+#, c-format -+msgid "get_updates error from master\n" -+msgstr "»get_updates«-Fehler vom Master\n" -+ -+#: ../../src/slave/kpropd.c:932 -+msgid "get_updates, error returned from master KDC." -+msgstr "Vom Master-KDC wurde ein »get_updates«-Fehler zurückgegeben." -+ -+# FIXME s/backoff/back-off/ -+#: ../../src/slave/kpropd.c:940 -+#, c-format -+msgid "get_updates master busy; backoff\n" -+msgstr "»get_updates«-Master ausgelastet; hält sich zurück\n" -+ -+#: ../../src/slave/kpropd.c:949 -+#, c-format -+msgid "KDC is synchronized with master.\n" -+msgstr "KDC wurde mit dem Master synchronisiert.\n" -+ -+#: ../../src/slave/kpropd.c:957 -+#, c-format -+msgid "get_updates invalid result from master\n" -+msgstr "ungültiges »get_updates«-Ergebnis vom Master\n" -+ -+#: ../../src/slave/kpropd.c:958 -+msgid "get_updates, invalid return from master KDC." -+msgstr "»get_updates«, ungültiger Rückgabewert vom Master-KDC" -+ -+# FIXME s/backoff/back-off/ -+#: ../../src/slave/kpropd.c:973 -+#, c-format -+msgid "Busy signal received from master, backoff for %d secs\n" -+msgstr "" -+"Vom Master wurde ein Signal empfangen, dass er ausgelastet ist, " -+"Zurückhaltung für %d Sekunden\n" -+ -+#: ../../src/slave/kpropd.c:980 -+#, c-format -+msgid "Waiting for %d seconds before checking for updates again\n" -+msgstr "" -+"vor der erneuten Prufung auf Aktualisierungen wird %d Sekunden gewartet\n" -+ -+#: ../../src/slave/kpropd.c:991 -+#, c-format -+msgid "ERROR returned by master, bailing\n" -+msgstr "FEHLER vom Master zurückgegeben, Ausstieg\n" -+ -+#: ../../src/slave/kpropd.c:992 -+msgid "ERROR returned by master KDC, bailing.\n" -+msgstr "FEHLER vom Master-KDC zurückgegeben, Ausstieg\n" -+ -+#: ../../src/slave/kpropd.c:1134 -+msgid "copying db args" -+msgstr "Datenbankargumente werden kopiert" -+ -+#: ../../src/slave/kpropd.c:1161 -+msgid "while trying to construct my service name" -+msgstr "beim Versuch, meinen Dienstnamen zu erstellen" -+ -+#: ../../src/slave/kpropd.c:1167 -+msgid "while constructing my service realm" -+msgstr "beim Erstellen meines Dienst-Realms" -+ -+#: ../../src/slave/kpropd.c:1175 -+msgid "while allocating filename for temp file" -+msgstr "beim Reservieren des Dateinamens für die temporäre Datei" -+ -+#: ../../src/slave/kpropd.c:1181 -+msgid "while initializing" -+msgstr "bei der Initialisierung" -+ -+#: ../../src/slave/kpropd.c:1189 -+msgid "Unable to map log!\n" -+msgstr "Protokoll kann nicht abgebildet werden!\n" -+ -+#: ../../src/slave/kpropd.c:1235 -+#, c-format -+msgid "Error in krb5_auth_con_ini: %s" -+msgstr "Fehler in »krb5_auth_con_ini«: %s" -+ -+#: ../../src/slave/kpropd.c:1243 -+#, c-format -+msgid "Error in krb5_auth_con_setflags: %s" -+msgstr "Fehler in »krb5_auth_con_setflags«: %s" -+ -+#: ../../src/slave/kpropd.c:1251 -+#, c-format -+msgid "Error in krb5_auth_con_setaddrs: %s" -+msgstr "Fehler in »krb5_auth_con_setaddrs«: %s" -+ -+#: ../../src/slave/kpropd.c:1259 -+#, c-format -+msgid "Error in krb5_kt_resolve: %s" -+msgstr "Fehler in »krb5_kt_resolve«: %s" -+ -+#: ../../src/slave/kpropd.c:1268 -+#, c-format -+msgid "Error in krb5_recvauth: %s" -+msgstr "Fehler in »krb5_recvauth«: %s" -+ -+#: ../../src/slave/kpropd.c:1275 -+#, c-format -+msgid "Error in krb5_copy_prinicpal: %s" -+msgstr "Fehler in »krb5_copy_prinicpal«: %s" -+ -+#: ../../src/slave/kpropd.c:1291 -+msgid "while unparsing ticket etype" -+msgstr "beim Rückgängigmachen der Auswertung des »etype«s des Tickets" -+ -+#: ../../src/slave/kpropd.c:1295 -+#, c-format -+msgid "authenticated client: %s (etype == %s)\n" -+msgstr "Authentifizierter Client: %s (etype == %s)\n" -+ -+#: ../../src/slave/kpropd.c:1374 -+msgid "while reading size of database from client" -+msgstr "beim Lesen der Datenbankgröße vom Client" -+ -+#: ../../src/slave/kpropd.c:1384 -+msgid "while decoding database size from client" -+msgstr "beim Dekodieren der Datenbankgröße vom Client" -+ -+#: ../../src/slave/kpropd.c:1397 -+msgid "while initializing i_vector" -+msgstr "beim Initialisieren von »i_vector«" -+ -+#: ../../src/slave/kpropd.c:1402 -+#, c-format -+msgid "Full propagation transfer started.\n" -+msgstr "vollständige Verbreitungsübertragung gestartet\n" -+ -+#: ../../src/slave/kpropd.c:1455 -+#, c-format -+msgid "Full propagation transfer finished.\n" -+msgstr "vollständige Verbreitungsübertragung beendet\n" -+ -+#: ../../src/slave/kpropd.c:1516 -+msgid "while decoding error packet from client" -+msgstr "beim Dekodieren des Fehlerpakets vom Client" -+ -+#: ../../src/slave/kpropd.c:1525 -+msgid "signaled from server" -+msgstr "signalisiert vom Server" -+ -+#: ../../src/slave/kpropd.c:1527 -+#, c-format -+msgid "Error text from client: %s\n" -+msgstr "Fehlermeldung vom Client: %s\n" -+ -+#: ../../src/slave/kpropd.c:1576 -+#, c-format -+msgid "while trying to fork %s" -+msgstr "beim Versuch, einen Kindprozess von %s zu erzeugen" -+ -+#: ../../src/slave/kpropd.c:1580 -+#, c-format -+msgid "while trying to exec %s" -+msgstr "beim Versuch, %s auszuführen" -+ -+#: ../../src/slave/kpropd.c:1587 -+#, c-format -+msgid "while waiting for %s" -+msgstr "beim Warten auf %s" -+ -+#: ../../src/slave/kpropd.c:1593 -+#, c-format -+msgid "%s load terminated" -+msgstr "Laden von %s beendet" -+ -+#: ../../src/slave/kpropd.c:1599 -+#, c-format -+msgid "%s returned a bad exit status (%d)" -+msgstr "%s gab einen falschen Exit-Status (%d) zurück" -+ -+#: ../../src/slave/kproplog.c:27 -+#, c-format -+msgid "" -+"\n" -+"Usage: %s [-h] [-v] [-v] [-e num]\n" -+"\t%s -R\n" -+"\n" -+msgstr "" -+"\n" -+"Aufruf: %s [-h] [-v] [-v] [-e Zahl]\n" -+"\t%s -R\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:129 -+#, c-format -+msgid "" -+"\n" -+"Couldn't allocate memory" -+msgstr "" -+"\n" -+"Speicher konnte nicht reserviert werden" -+ -+#: ../../src/slave/kproplog.c:223 -+#, c-format -+msgid "\t\tAttribute flags\n" -+msgstr "\t\tAttributschalter\n" -+ -+#: ../../src/slave/kproplog.c:228 -+#, c-format -+msgid "\t\tMaximum ticket life\n" -+msgstr "\t\tmaximale Ticketlebensdauer\n" -+ -+#: ../../src/slave/kproplog.c:233 -+#, c-format -+msgid "\t\tMaximum renewable life\n" -+msgstr "\t\tmaximale verlängerbare Lebensdauer\n" -+ -+#: ../../src/slave/kproplog.c:238 -+#, c-format -+msgid "\t\tPrincipal expiration\n" -+msgstr "\t\tAblauf des Principals\n" -+ -+#: ../../src/slave/kproplog.c:243 -+#, c-format -+msgid "\t\tPassword expiration\n" -+msgstr "\t\tAblauf des Passworts\n" -+ -+#: ../../src/slave/kproplog.c:248 -+#, c-format -+msgid "\t\tLast successful auth\n" -+msgstr "\t\tletzte erfolgreiche Authentifizierung\n" -+ -+#: ../../src/slave/kproplog.c:253 -+#, c-format -+msgid "\t\tLast failed auth\n" -+msgstr "\t\tletzte fehlgeschlagene Authentifizierung\n" -+ -+#: ../../src/slave/kproplog.c:258 -+#, c-format -+msgid "\t\tFailed passwd attempt\n" -+msgstr "\t\tfehlgeschlagener Passwortversuch\n" -+ -+#: ../../src/slave/kproplog.c:263 -+#, c-format -+msgid "\t\tPrincipal\n" -+msgstr "\t\tPrincipal\n" -+ -+#: ../../src/slave/kproplog.c:268 -+#, c-format -+msgid "\t\tKey data\n" -+msgstr "\t\tSchlüsseldaten\n" -+ -+#: ../../src/slave/kproplog.c:275 -+#, c-format -+msgid "\t\tTL data\n" -+msgstr "\t\tTL-Daten\n" -+ -+#: ../../src/slave/kproplog.c:282 -+#, c-format -+msgid "\t\tLength\n" -+msgstr "\t\tLänge\n" -+ -+#: ../../src/slave/kproplog.c:287 -+#, c-format -+msgid "\t\tPassword last changed\n" -+msgstr "\t\tletzte Passwortänderung\n" -+ -+#: ../../src/slave/kproplog.c:292 -+#, c-format -+msgid "\t\tModifying principal\n" -+msgstr "\t\ttPrincipal wird geändert\n" -+ -+#: ../../src/slave/kproplog.c:297 -+#, c-format -+msgid "\t\tModification time\n" -+msgstr "\t\tÄnderungszeit\n" -+ -+#: ../../src/slave/kproplog.c:302 -+#, c-format -+msgid "\t\tModified where\n" -+msgstr "\t\tGeändert wobei\n" -+ -+#: ../../src/slave/kproplog.c:307 -+#, c-format -+msgid "\t\tPassword policy\n" -+msgstr "\t\tPasswortrichtlinie\n" -+ -+#: ../../src/slave/kproplog.c:312 -+#, c-format -+msgid "\t\tPassword policy switch\n" -+msgstr "\t\tPasswortrichtlinienumschalter\n" -+ -+#: ../../src/slave/kproplog.c:317 -+#, c-format -+msgid "\t\tPassword history KVNO\n" -+msgstr "\t\tPasswortchronik KVNO\n" -+ -+#: ../../src/slave/kproplog.c:322 -+#, c-format -+msgid "\t\tPassword history\n" -+msgstr "\t\tPasswortchronik\n" -+ -+#: ../../src/slave/kproplog.c:356 -+#, c-format -+msgid "" -+"Corrupt update entry\n" -+"\n" -+msgstr "" -+"beschädigter Aktualisierungseintrag\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:364 -+#, c-format -+msgid "" -+"Entry data decode failure\n" -+"\n" -+msgstr "" -+"Dekodieren der eingetragenen Daten fehlgeschlagen\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:369 -+#, c-format -+msgid "Update Entry\n" -+msgstr "Aktualisierungseintrag\n" -+ -+#: ../../src/slave/kproplog.c:371 -+#, c-format -+msgid "\tUpdate serial # : %u\n" -+msgstr "\tAktualisierung der Seriennummer: %u\n" -+ -+#: ../../src/slave/kproplog.c:373 -+#, c-format -+msgid "\tUpdate operation : " -+msgstr "\tAktualisierungsaktion: " -+ -+#: ../../src/slave/kproplog.c:375 -+#, c-format -+msgid "Delete\n" -+msgstr "Löschen\n" -+ -+#: ../../src/slave/kproplog.c:377 -+#, c-format -+msgid "Add\n" -+msgstr "Hinzufügen\n" -+ -+#: ../../src/slave/kproplog.c:381 -+#, c-format -+msgid "" -+"Could not allocate principal name\n" -+"\n" -+msgstr "" -+"Der Principal-Name konnte nicht reserviert werden.\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:387 -+#, c-format -+msgid "\tUpdate principal : %s\n" -+msgstr "\tAktualisierung des Principals: %s\n" -+ -+#: ../../src/slave/kproplog.c:389 -+#, c-format -+msgid "\tUpdate size : %u\n" -+msgstr "\tGröße der Aktualisierung: %u\n" -+ -+#: ../../src/slave/kproplog.c:390 -+#, c-format -+msgid "\tUpdate committed : %s\n" -+msgstr "\tAktualisierung übergeben: %s\n" -+ -+#: ../../src/slave/kproplog.c:394 -+#, c-format -+msgid "\tUpdate time stamp : None\n" -+msgstr "\tZeitstempel der Aktualisierung: keiner\n" -+ -+#: ../../src/slave/kproplog.c:396 -+#, c-format -+msgid "\tUpdate time stamp : %s" -+msgstr "\tZeitstempel der Aktualisierung: %s" -+ -+#: ../../src/slave/kproplog.c:400 -+#, c-format -+msgid "\tAttributes changed : %d\n" -+msgstr "\tgeänderte Attribute: %d\n" -+ -+#: ../../src/slave/kproplog.c:465 -+#, c-format -+msgid "" -+"Unable to initialize Kerberos\n" -+"\n" -+msgstr "" -+"Kerberos kann nicht initialisiert werden\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:472 -+#, c-format -+msgid "" -+"Couldn't read database_name\n" -+"\n" -+msgstr "" -+"»database_name« kann nicht gelesen werden\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:476 -+#, c-format -+msgid "" -+"\n" -+"Kerberos update log (%s)\n" -+msgstr "" -+"\n" -+"Kerberos-Aktualisierungsprotokoll (%s)\n" -+ -+#: ../../src/slave/kproplog.c:480 ../../src/slave/kproplog.c:495 -+#, c-format -+msgid "" -+"Unable to map log file %s\n" -+"\n" -+msgstr "" -+"Protokolldatei %s kann nicht abgebildet werden\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:485 -+#, c-format -+msgid "" -+"Couldn't reinitialize ulog file %s\n" -+"\n" -+msgstr "" -+"Ulog-Datei %s konnte nicht neu initialisiert werden\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:489 -+#, c-format -+msgid "Reinitialized the ulog.\n" -+msgstr "Das Ulog wurde neu initialisiert.\n" -+ -+#: ../../src/slave/kproplog.c:501 -+#, c-format -+msgid "" -+"Corrupt header log, exiting\n" -+"\n" -+msgstr "" -+"beschädigtes Kopfzeilenprotokoll, wird beendet\n" -+"\n" -+ -+#: ../../src/slave/kproplog.c:505 -+#, c-format -+msgid "Update log dump :\n" -+msgstr "Aktualisierungsprotokollauszug :\n" -+ -+#: ../../src/slave/kproplog.c:506 -+#, c-format -+msgid "\tLog version # : %u\n" -+msgstr "\tProtokollversion #: %u\n" -+ -+#: ../../src/slave/kproplog.c:507 -+#, c-format -+msgid "\tLog state : " -+msgstr "\tProtokollstatus: " -+ -+#: ../../src/slave/kproplog.c:510 -+#, c-format -+msgid "Stable\n" -+msgstr "stabil\n" -+ -+#: ../../src/slave/kproplog.c:513 -+#, c-format -+msgid "Unstable\n" -+msgstr "instabil\n" -+ -+#: ../../src/slave/kproplog.c:516 -+#, c-format -+msgid "Corrupt\n" -+msgstr "beschädigt\n" -+ -+#: ../../src/slave/kproplog.c:519 -+#, c-format -+msgid "Unknown state: %d\n" -+msgstr "unbekannter Status: %d\n" -+ -+#: ../../src/slave/kproplog.c:522 -+#, c-format -+msgid "\tEntry block size : %u\n" -+msgstr "\tBlockgrößeneintrag: %u\n" -+ -+#: ../../src/slave/kproplog.c:523 -+#, c-format -+msgid "\tNumber of entries : %u\n" -+msgstr "\tAnzahl der Einträge: %u\n" -+ -+#: ../../src/slave/kproplog.c:526 -+#, c-format -+msgid "\tLast serial # : None\n" -+msgstr "\tletzte Seriennummer: keine\n" -+ -+#: ../../src/slave/kproplog.c:529 -+#, c-format -+msgid "\tFirst serial # : None\n" -+msgstr "\terste Seriennummer: keine\n" -+ -+#: ../../src/slave/kproplog.c:531 -+#, c-format -+msgid "\tFirst serial # : " -+msgstr "\terste Seriennummer: " -+ -+#: ../../src/slave/kproplog.c:535 -+#, c-format -+msgid "\tLast serial # : " -+msgstr "\tletzte Seriennummer: " -+ -+#: ../../src/slave/kproplog.c:540 -+#, c-format -+msgid "\tLast time stamp : None\n" -+msgstr "\tletzter Zeitstempel: keiner\n" -+ -+#: ../../src/slave/kproplog.c:543 -+#, c-format -+msgid "\tFirst time stamp : None\n" -+msgstr "\terster Zeitstempel: keiner\n" -+ -+#: ../../src/slave/kproplog.c:545 -+#, c-format -+msgid "\tFirst time stamp : %s" -+msgstr "\terster Zeitstempel: %s" -+ -+#: ../../src/slave/kproplog.c:549 -+#, c-format -+msgid "\tLast time stamp : %s\n" -+msgstr "\tletzter Zeitstempel: %s\n" -+ -+#: ../../src/util/support/errors.c:77 -+msgid "Kerberos library initialization failure" -+msgstr "Initialisieren der Kerberos-Bibliothek fehlgeschlagen" -+ -+#: ../../src/util/support/errors.c:93 -+#, c-format -+msgid "error %ld" -+msgstr "Fehler %ld" -+ -+#: ../../src/util/support/plugins.c:186 -+#, c-format -+msgid "unable to find plugin [%s]: %s" -+msgstr "Erweiterung [%s] konnte nicht gefunden werden: %s" -+ -+#: ../../src/util/support/plugins.c:274 -+msgid "unknown failure" -+msgstr "unbekannter Fehlschlag" -+ -+#: ../../src/util/support/plugins.c:277 -+#, c-format -+msgid "unable to load plugin [%s]: %s" -+msgstr "Erweiterung [%s] konnte nicht geladen werden: %s" -+ -+#: ../../src/util/support/plugins.c:300 -+#, c-format -+msgid "unable to load DLL [%s]" -+msgstr "DLL [%s] konnte nicht geladen werden" -+ -+#: ../../src/util/support/plugins.c:316 -+#, c-format -+msgid "plugin unavailable: %s" -+msgstr "Erweiterung nicht verfügbar: %s" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:23 -+msgid "No @ in SERVICE-NAME name string" -+msgstr "keine @ in der Namenszeichenkette SERVICE-NAME" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:24 -+msgid "STRING-UID-NAME contains nondigits" -+msgstr "STRING-UID-NAME enthält etwas anderes als Ziffern" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:25 -+msgid "UID does not resolve to username" -+msgstr "UID lässt sich nicht zu Benutzernamen ermitteln" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:26 -+msgid "Validation error" -+msgstr "Überprüfungsfehler" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:27 -+msgid "Couldn't allocate gss_buffer_t data" -+msgstr "»gss_buffer_t«-Daten konnten reserviert werden" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:28 -+msgid "Message context invalid" -+msgstr "Nachrichtenkontext ungültig" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:29 -+msgid "Buffer is the wrong size" -+msgstr "Puffer hat die falsche Größe" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:30 -+msgid "Credential usage type is unknown" -+msgstr "Typ des Anmeldedatenaufrufs ist unbekannt" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:31 -+msgid "Unknown quality of protection specified" -+msgstr "unbekannte Schutzqualität angegeben" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:32 -+msgid "Local host name could not be determined" -+msgstr "lokaler Rechnername konnte nicht bestimmt werden" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:33 -+msgid "Hostname in SERVICE-NAME string could not be canonicalized" -+msgstr "" -+"Rechnername in der Zeichenkette »SERVICE-NAME« konnte nicht in Normalform " -+"gebracht werden" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:34 -+msgid "Mechanism is incorrect" -+msgstr "Mechanismus ist nicht korrekt" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:35 -+msgid "Token header is malformed or corrupt" -+msgstr "Token-Kopfzeilen haben die falsche Form oder sind beschädigt" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:36 -+msgid "Packet was replayed in wrong direction" -+msgstr "Paket wurde in falscher Richtung erneut abgespielt" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:37 -+msgid "Token is missing data" -+msgstr "dem Token fehlen Daten" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:38 -+msgid "Token was reflected" -+msgstr "Token wurde zurückgeworfen" -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:39 -+msgid "Received token ID does not match expected token ID" -+msgstr "Die empfangene Token-Kennung passt nicht zur erwarteten Token-Kennung." -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:40 -+msgid "The given credential's usage does not match the requested usage" -+msgstr "" -+"Die Verwendung der angegebenen Anmeldedaten passt nicht zur angeforderten " -+"Verwendung." -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:41 -+msgid "Storing of acceptor credentials is not supported by the mechanism" -+msgstr "" -+"Das Speichern von Abnehmeranmeldedaten wird nicht durch den Mechanismus " -+"unterstützt." -+ -+#: ../lib/gssapi/generic/gssapi_err_generic.c:42 -+msgid "Storing of non-default credentials is not supported by the mechanism" -+msgstr "" -+"Das Speichern von Nichtstandardanmeldedaten wird nicht durch den Mechanismus " -+"unterstützt." -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:23 -+msgid "Principal in credential cache does not match desired name" -+msgstr "" -+"Principal im Anmeldedatenzwischenspeicher entspricht nicht dem gewünschten " -+"Namen" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:24 -+msgid "No principal in keytab matches desired name" -+msgstr "Kein Principal in der Schlüsseltabelle passt zum gewünschten Namen." -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:25 -+msgid "Credential cache has no TGT" -+msgstr "Anmeldedatenzwischenspeicher hat kein TGT" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:26 -+msgid "Authenticator has no subkey" -+msgstr "Schlüsselziffer hat keinen Unterschlüssel" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:27 -+msgid "Context is already fully established" -+msgstr "Kontext wurde bereits vollständig eingerichtet" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:28 -+msgid "Unknown signature type in token" -+msgstr "unbekannter Signaturtyp im Token" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:29 -+msgid "Invalid field length in token" -+msgstr "falsche Feldlänge im Token" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:30 -+msgid "Attempt to use incomplete security context" -+msgstr "" -+"Es wurde versucht, einen unvollständigen Sicherheitskontext zu verwenden." -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:31 -+msgid "Bad magic number for krb5_gss_ctx_id_t" -+msgstr "falsche magische Zahl für »krb5_gss_ctx_id_t«" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:32 -+msgid "Bad magic number for krb5_gss_cred_id_t" -+msgstr "falsche magische Zahl für »krb5_gss_cred_id_t«" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:33 -+msgid "Bad magic number for krb5_gss_enc_desc" -+msgstr "falsche magische Zahl für »krb5_gss_enc_desc«" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:34 -+msgid "Sequence number in token is corrupt" -+msgstr "Sequnznummer im Token ist beschädigt" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:35 -+msgid "Credential cache is empty" -+msgstr "Anmeldedatenzwischenspeicher ist leer" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:36 -+msgid "Acceptor and Initiator share no checksum types" -+msgstr "Abnehmer und Initiator haben keinen gemeinsamen Prüfsummentyp" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:37 -+msgid "Requested lucid context version not supported" -+msgstr "angeforderte »lucid«-Kontextversion nicht unterstützt" -+ -+# PRF = Pseudo Random Function -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:38 -+msgid "PRF input too long" -+msgstr "PRF-Eingabe zu lang" -+ -+#: ../lib/gssapi/krb5/gssapi_err_krb5.c:39 -+msgid "Bad magic number for iakerb_ctx_id_t" -+msgstr "falsche magische Zahl für »iakerb_ctx_id_t«" -+ -+#: ../lib/kadm5/chpass_util_strings.c:23 -+msgid "while getting policy info." -+msgstr "beim Holen der Richtlinieninformation." -+ -+#: ../lib/kadm5/chpass_util_strings.c:24 -+msgid "while getting principal info." -+msgstr "beim Holen der Principal-Information." -+ -+#: ../lib/kadm5/chpass_util_strings.c:25 -+msgid "New passwords do not match - password not changed.\n" -+msgstr "neue Passwörter stimmen nicht überein – Passwort nicht geändert\n" -+ -+#: ../lib/kadm5/chpass_util_strings.c:26 -+msgid "New password" -+msgstr "neues Passwort" -+ -+#: ../lib/kadm5/chpass_util_strings.c:27 -+msgid "New password (again)" -+msgstr "neues Passwort (erneut)" -+ -+#: ../lib/kadm5/chpass_util_strings.c:28 -+msgid "" -+"You must type a password. Passwords must be at least one character long.\n" -+msgstr "" -+"Sie müssen ein Passwort eingeben. Passwörter müssen mindestens ein Zeichen " -+"lang sein.\n" -+ -+#: ../lib/kadm5/chpass_util_strings.c:29 -+msgid "yet no policy set! Contact your system security administrator." -+msgstr "" -+"noch keine Richtlinie gesetzt! Kontaktieren Sie Ihren " -+"Systemsicherheitsadministrator" -+ -+#: ../lib/kadm5/chpass_util_strings.c:31 -+msgid "" -+"New password was found in a dictionary of possible passwords and\n" -+"therefore may be easily guessed. Please choose another password.\n" -+"See the kpasswd man page for help in choosing a good password." -+msgstr "" -+"Das neue Passwort wurde in einem Wörterbuch mit möglichen Passwörtern " -+"gefunden\n" -+"und kann daher leicht erraten werden. Bitte wählen Sie ein anderes " -+"Passwort.\n" -+"Hilfe bei der Wahl guter Passwörter finden Sie in der Handbuchseite von\n" -+"»kpasswd«." -+ -+#: ../lib/kadm5/chpass_util_strings.c:32 -+msgid "Password not changed." -+msgstr "Passwort nicht geändert" -+ -+#: ../lib/kadm5/chpass_util_strings.c:33 -+#, c-format -+msgid "" -+"New password is too short.\n" -+"Please choose a password which is at least %d characters long." -+msgstr "" -+"Das neue Passwort ist zu kurz.\n" -+"Bitte wählen Sie ein Passwort, das mindestens %d Zeichen lang ist." -+ -+#: ../lib/kadm5/chpass_util_strings.c:34 -+#, c-format -+msgid "" -+"New password does not have enough character classes.\n" -+"The character classes are:\n" -+"\t- lower-case letters,\n" -+"\t- upper-case letters,\n" -+"\t- digits,\n" -+"\t- punctuation, and\n" -+"\t- all other characters (e.g., control characters).\n" -+"Please choose a password with at least %d character classes." -+msgstr "" -+"Das neue Passwort besteht aus zu wenigen Zeichenklassen.\n" -+"Die Zeichenklassen sind:\n" -+"\t- Kleinbuchstaben,\n" -+"\t- Großbuchstaben,\n" -+"\t- Ziffern,\n" -+"\t- Satzzeichen und\n" -+"\t- alle anderen Zeichen (z.B. Steuerzeichen).\n" -+"Bitte wählen Sie ein Passwort mit mindestens %d Zeichenklassen." -+ -+#: ../lib/kadm5/chpass_util_strings.c:35 -+#, c-format -+msgid "" -+"Password cannot be changed because it was changed too recently.\n" -+"Please wait until %s before you change it.\n" -+"If you need to change your password before then, contact your system\n" -+"security administrator." -+msgstr "" -+"Das Passwort kann nicht geändert werden, da es erst vor kurzem geändert " -+"wurde.\n" -+"Bitte warten Sie bis %s, ehe Sie es ändern.\n" -+"Falls Sie es vorher ändern müssen, kontaktieren Sie Ihren\n" -+"Systemsicherheitsadministrator." -+ -+#: ../lib/kadm5/chpass_util_strings.c:36 -+msgid "New password was used previously. Please choose a different password." -+msgstr "" -+"Das neue Passwort wurde zuvor schon benutzt. Bitte wählen Sie ein anderes " -+"Passwort." -+ -+#: ../lib/kadm5/chpass_util_strings.c:37 -+msgid "while trying to change password." -+msgstr "beim Versuch, das Passwort zu ändern." -+ -+#: ../lib/kadm5/chpass_util_strings.c:38 -+msgid "while reading new password." -+msgstr "beim Lesen des neuen Passworts." -+ -+#: ../lib/kadm5/kadm_err.c:23 -+msgid "Operation failed for unspecified reason" -+msgstr "Aktion aus nicht näher beschriebenem Grund fehlgeschlagen" -+ -+#: ../lib/kadm5/kadm_err.c:24 -+msgid "Operation requires ``get'' privilege" -+msgstr "Aktion erfordert »get«-Recht" -+ -+#: ../lib/kadm5/kadm_err.c:25 -+msgid "Operation requires ``add'' privilege" -+msgstr "Aktion erfordert »add«-Recht" -+ -+#: ../lib/kadm5/kadm_err.c:26 -+msgid "Operation requires ``modify'' privilege" -+msgstr "Aktion erfordert »modify«-Recht" -+ -+#: ../lib/kadm5/kadm_err.c:27 -+msgid "Operation requires ``delete'' privilege" -+msgstr "Aktion erfordert »delete«-Recht" -+ -+#: ../lib/kadm5/kadm_err.c:28 -+msgid "Insufficient authorization for operation" -+msgstr "unzureichende Berechtigung für diese Aktion" -+ -+#: ../lib/kadm5/kadm_err.c:29 ../lib/kdb/adb_err.c:29 -+msgid "Database inconsistency detected" -+msgstr "Datenbankinkonsistenz entdeckt" -+ -+#: ../lib/kadm5/kadm_err.c:30 ../lib/kdb/adb_err.c:24 -+msgid "Principal or policy already exists" -+msgstr "Principal oder Richtlinie existiert bereits" -+ -+#: ../lib/kadm5/kadm_err.c:31 -+msgid "Communication failure with server" -+msgstr "Kommunikation mit dem Server fehlgeschlagen" -+ -+#: ../lib/kadm5/kadm_err.c:32 -+msgid "No administration server found for realm" -+msgstr "kein Administrationsserver für den Realm gefunden" -+ -+#: ../lib/kadm5/kadm_err.c:33 -+msgid "Password history principal key version mismatch" -+msgstr "Die Passwortchronikschlüssel des Principals passen nicht zusammen." -+ -+#: ../lib/kadm5/kadm_err.c:34 -+msgid "Connection to server not initialized" -+msgstr "Verbindung zum Server nicht initialisiert" -+ -+#: ../lib/kadm5/kadm_err.c:35 -+msgid "Principal does not exist" -+msgstr "Principal existiert nicht" -+ -+#: ../lib/kadm5/kadm_err.c:36 -+msgid "Policy does not exist" -+msgstr "Richtlinie existiert nicht" -+ -+#: ../lib/kadm5/kadm_err.c:37 -+msgid "Invalid field mask for operation" -+msgstr "ungültige Feldmaske für Aktion" -+ -+#: ../lib/kadm5/kadm_err.c:38 -+msgid "Invalid number of character classes" -+msgstr "ungültige Anzahl von Zeichenklassen" -+ -+#: ../lib/kadm5/kadm_err.c:39 -+msgid "Invalid password length" -+msgstr "ungültige Passwortlänge" -+ -+#: ../lib/kadm5/kadm_err.c:40 -+msgid "Illegal policy name" -+msgstr "unzulässiger Richtlinienname" -+ -+#: ../lib/kadm5/kadm_err.c:41 -+msgid "Illegal principal name" -+msgstr "unzulässiger Principal-Name" -+ -+# FIXME s/auxillary/auxilary/ -+#: ../lib/kadm5/kadm_err.c:42 -+msgid "Invalid auxillary attributes" -+msgstr "ungültige Zusatzattribute" -+ -+#: ../lib/kadm5/kadm_err.c:43 -+msgid "Invalid password history count" -+msgstr "ungültige Passwortchronikanzahl" -+ -+#: ../lib/kadm5/kadm_err.c:44 -+msgid "Password minimum life is greater than password maximum life" -+msgstr "Die minimale Lebensdauer des Passworts ist größer als die maximale." -+ -+#: ../lib/kadm5/kadm_err.c:45 -+msgid "Password is too short" -+msgstr "Das Passwort ist zu kurz." -+ -+#: ../lib/kadm5/kadm_err.c:46 -+msgid "Password does not contain enough character classes" -+msgstr "Das Passwort enthält nicht genug Zeichenklassen." -+ -+#: ../lib/kadm5/kadm_err.c:47 -+msgid "Password is in the password dictionary" -+msgstr "Das Passwort steht im Passwortwörterbuch." -+ -+#: ../lib/kadm5/kadm_err.c:48 -+msgid "Cannot reuse password" -+msgstr "Das Passwort kann nicht erneut verwendet werden." -+ -+#: ../lib/kadm5/kadm_err.c:49 -+msgid "Current password's minimum life has not expired" -+msgstr "Die aktuell minimale Lebensdauer des Passworts ist nicht abgelaufen." -+ -+#: ../lib/kadm5/kadm_err.c:50 ../lib/krb5/error_tables/kdb5_err.c:67 -+msgid "Policy is in use" -+msgstr "Richtlinie ist in Benutzung" -+ -+#: ../lib/kadm5/kadm_err.c:51 -+msgid "Connection to server already initialized" -+msgstr "Verbindung zum Server ist bereits initialisiert" -+ -+#: ../lib/kadm5/kadm_err.c:52 -+msgid "Incorrect password" -+msgstr "falsches Passwort" -+ -+#: ../lib/kadm5/kadm_err.c:53 -+msgid "Cannot change protected principal" -+msgstr "geschützter Principal kann nicht geändert werden" -+ -+#: ../lib/kadm5/kadm_err.c:54 -+msgid "Programmer error! Bad Admin server handle" -+msgstr "Fehler des Programmierers! Falscher Admin-Server-Identifikator" -+ -+#: ../lib/kadm5/kadm_err.c:55 -+msgid "Programmer error! Bad API structure version" -+msgstr "Fehler des Programmierers! Falsche API-Strukturversion" -+ -+#: ../lib/kadm5/kadm_err.c:56 -+msgid "" -+"API structure version specified by application is no longer supported (to " -+"fix, recompile application against current KADM5 API header files and " -+"libraries)" -+msgstr "" -+"Die von der Anwendung angegebene Version der API-Struktur wird nicht länger " -+"unterstützt. (Kompilieren Sie die Anwendung mit den aktuellen KADM5-API-" -+"Header-Dateien und -Bibliotheken, um dies zu beheben.)" -+ -+#: ../lib/kadm5/kadm_err.c:57 -+msgid "" -+"API structure version specified by application is unknown to libraries (to " -+"fix, obtain current KADM5 API header files and libraries and recompile " -+"application)" -+msgstr "" -+"Die von der Anwendung angegebene Version der API-Struktur ist den " -+"Bibliotheken unbekannt. (Besorgen Sie sich die aktuellen KADM5-API-Header-" -+"Dateien und -Bibliotheken und kompilieren Sie die Anwendung neu, um dies zu " -+"beheben.)" -+ -+#: ../lib/kadm5/kadm_err.c:58 -+msgid "Programmer error! Bad API version" -+msgstr "Fehler des Programmierers! Falsche API-Version" -+ -+#: ../lib/kadm5/kadm_err.c:59 -+msgid "" -+"API version specified by application is no longer supported by libraries (to " -+"fix, update application to adhere to current API version and recompile)" -+msgstr "" -+"Die von der Anwendung angegebene Version der API-Struktur wird nicht länger " -+"von den Bibliotheken unterstützt. (Aktualisieren Sie die Anwendung, dass sie " -+"zu der aktuellen API-Version passt, und kompilieren Sie sie, um dies zu " -+"beheben.)" -+ -+#: ../lib/kadm5/kadm_err.c:60 -+msgid "" -+"API version specified by application is no longer supported by server (to " -+"fix, update application to adhere to current API version and recompile)" -+msgstr "" -+"Die von der Anwendung angegebene Version der API-Struktur wird nicht länger " -+"vom Server unterstützt. (Aktualisieren Sie die Anwendung, dass sie zu der " -+"aktuellen API-Version passt, und kompilieren Sie sie, um dies zu beheben.)" -+ -+#: ../lib/kadm5/kadm_err.c:61 -+msgid "" -+"API version specified by application is unknown to libraries (to fix, obtain " -+"current KADM5 API header files and libraries and recompile application)" -+msgstr "" -+"Die von der Anwendung angegebenene API-Version ist den Bibliotheken " -+"unbekannt. (Besorgen Sie sich die aktuellen KADM5-API-Header-Dateien und -" -+"Bibliotheken und kompilieren Sie die Anwendung neu, um dies zu beheben.)" -+ -+#: ../lib/kadm5/kadm_err.c:62 -+msgid "" -+"API version specified by application is unknown to server (to fix, obtain " -+"and install newest KADM5 Admin Server)" -+msgstr "" -+"Die von der Anwendung angegebene API-Version ist dem Server unbekannt. " -+"(Besorgen und installieren Sie sich den neuesten KADM5-Admin-Server, um dies " -+"zu beheben.)" -+ -+#: ../lib/kadm5/kadm_err.c:63 -+msgid "Database error! Required KADM5 principal missing" -+msgstr "Datenbankfehler! Erforderlicher KADM5-Principal fehlt" -+ -+#: ../lib/kadm5/kadm_err.c:64 -+msgid "The salt type of the specified principal does not support renaming" -+msgstr "Der Salt-Typ des angegebenen Principals unterstützt kein Umbenennen." -+ -+#: ../lib/kadm5/kadm_err.c:65 -+msgid "Illegal configuration parameter for remote KADM5 client" -+msgstr "widerrechtlicher Konfigurationsparameter für fernen KADM5-Client" -+ -+#: ../lib/kadm5/kadm_err.c:66 -+msgid "Illegal configuration parameter for local KADM5 client" -+msgstr "widerrechtlicher Konfigurationsparameter für lokalen KADM5-Client" -+ -+#: ../lib/kadm5/kadm_err.c:67 -+msgid "Operation requires ``list'' privilege" -+msgstr "Aktion erfordert das »list«-Recht" -+ -+#: ../lib/kadm5/kadm_err.c:68 -+msgid "Operation requires ``change-password'' privilege" -+msgstr "Aktion erfordert das »change-password«-Recht" -+ -+#: ../lib/kadm5/kadm_err.c:69 -+msgid "GSS-API (or Kerberos) error" -+msgstr "GSS-API- (oder Kerberos-) Fehler" -+ -+#: ../lib/kadm5/kadm_err.c:70 -+msgid "Programmer error! Illegal tagged data list type" -+msgstr "" -+"Fehler des Programmierers! Widerrechlicher Listentyp für gekennzeichnete " -+"Daten" -+ -+#: ../lib/kadm5/kadm_err.c:71 -+msgid "Required parameters in kdc.conf missing" -+msgstr "erforderliche Parameter in »kdc.conf« fehlen" -+ -+#: ../lib/kadm5/kadm_err.c:72 -+msgid "Bad krb5 admin server hostname" -+msgstr "falscher Rechnername des KRB5-Admin-Servers" -+ -+#: ../lib/kadm5/kadm_err.c:73 -+msgid "Operation requires ``set-key'' privilege" -+msgstr "Aktion erfordert das »set-key«-Recht" -+ -+#: ../lib/kadm5/kadm_err.c:74 -+msgid "Multiple values for single or folded enctype" -+msgstr "" -+"mehrere Werte für einzelnen Verschlüsselungstyp oder Verschlüsselungstyp mit " -+"Salt" -+ -+#: ../lib/kadm5/kadm_err.c:75 -+msgid "Invalid enctype for setv4key" -+msgstr "widerrechtlicher Verschlüsselungstyp für Setv4key" -+ -+#: ../lib/kadm5/kadm_err.c:76 -+msgid "Mismatched enctypes for setkey3" -+msgstr "nicht zusammenpassende Verschlüsselungstypen für Setkey3" -+ -+#: ../lib/kadm5/kadm_err.c:77 -+msgid "Missing parameters in krb5.conf required for kadmin client" -+msgstr "für Kadmin-Client benötigte Parameter fehlen in »krb5.conf«" -+ -+#: ../lib/kadm5/kadm_err.c:78 ../lib/kdb/adb_err.c:30 -+msgid "XDR encoding error" -+msgstr "XDR-Verschlüsselungsfehler" -+ -+#: ../lib/kadm5/kadm_err.c:79 -+msgid "Cannot resolve network address for admin server in requested realm" -+msgstr "" -+"Die Netzwerkadresse für den Admin-Server im angeforderten Realm kann nicht " -+"aufgelöst werden." -+ -+#: ../lib/kadm5/kadm_err.c:80 -+msgid "Unspecified password quality failure" -+msgstr "nicht näher angegebener Passwortqualitätsfehlschlag" -+ -+#: ../lib/kadm5/kadm_err.c:81 -+msgid "Invalid key/salt tuples" -+msgstr "ungültige Schlüssel-/Salt-Tupel" -+ -+#: ../lib/kdb/adb_err.c:23 -+msgid "No Error" -+msgstr "kein Fehler" -+ -+#: ../lib/kdb/adb_err.c:25 -+msgid "Principal or policy does not exist" -+msgstr "Principal oder Richtlinie existiert nicht" -+ -+#: ../lib/kdb/adb_err.c:26 -+msgid "Database not initialized" -+msgstr "Datenbank nicht initialisiert" -+ -+#: ../lib/kdb/adb_err.c:27 -+msgid "Invalid policy name" -+msgstr "ungültiger Richtlinienname" -+ -+#: ../lib/kdb/adb_err.c:28 -+msgid "Invalid principal name" -+msgstr "ungültiger Principal-Name" -+ -+#: ../lib/kdb/adb_err.c:31 -+msgid "Failure!" -+msgstr "Fehlschlag!" -+ -+#: ../lib/kdb/adb_err.c:32 -+msgid "Bad lock mode" -+msgstr "falscher Sperrmodus" -+ -+#: ../lib/kdb/adb_err.c:33 -+msgid "Cannot lock database" -+msgstr "Datenbank kann nicht gesperrt werden" -+ -+#: ../lib/kdb/adb_err.c:34 -+msgid "Database not locked" -+msgstr "Datenbank nicht gesperrt" -+ -+#: ../lib/kdb/adb_err.c:35 -+msgid "KADM5 administration database lock file missing" -+msgstr "Sperrdatei der KADM5-Verwaltungsdatenbank fehlt" -+ -+#: ../lib/kdb/adb_err.c:36 -+msgid "Insufficient permission to lock file" -+msgstr "keine ausreichenden Rechte zum Sperren der Datei" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:23 -+msgid "Plugin does not support interface version" -+msgstr "Erweiterung unterstützt nicht die Schnittstellenversion" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:24 -+msgid "Invalid module specifier" -+msgstr "ungültige Modulangabe" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:25 -+msgid "Plugin module name not found" -+msgstr "Erweiterungsmodulname nicht gefunden" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:26 -+msgid "The KDC should discard this request" -+msgstr "Das KDC sollte diese Anfrage verwerfen" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:27 -+msgid "Can't create new subsidiary cache" -+msgstr "Der neue ergänzende Zwischenspeicher kann nicht erzeugt werden" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:28 -+msgid "Invalid keyring anchor name" -+msgstr "ungültiger Schlüsselbundverankerungsname" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:29 -+msgid "Unknown keyring collection version" -+msgstr "unbekannte Schlüsselbundsammlungsversion" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:30 -+msgid "Invalid UID in persistent keyring name" -+msgstr "ungültige UID im beständigen Schlüsselbundnamen" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:31 -+msgid "Malformed reply from KCM daemon" -+msgstr "Antwort des KCM-Daemons hat die falsche Form" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:32 -+msgid "Mach RPC error communicating with KCM daemon" -+msgstr "Mach-RPC-Fehler beim der Kommunikation mit dem KCM-Daemon" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:33 -+msgid "KCM daemon reply too big" -+msgstr "Antwort des KCM-Daemons zu groß" -+ -+#: ../lib/krb5/error_tables/k5e1_err.c:34 -+msgid "No KCM server found" -+msgstr "Kein KCM-Server gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:24 -+msgid "Client's entry in database has expired" -+msgstr "Eintrag des Clients in der Datenbank ist abgelaufen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:25 -+msgid "Server's entry in database has expired" -+msgstr "Eintrag des Servers in der Datenbank ist abgelaufen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:26 -+msgid "Requested protocol version not supported" -+msgstr "angeforderte Protokollversion nicht unterstützt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:27 -+msgid "Client's key is encrypted in an old master key" -+msgstr "" -+"Der Schlüssel des Clients wurde mit einem alten Hauptschlüssel verschlüsselt." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:28 -+msgid "Server's key is encrypted in an old master key" -+msgstr "" -+"Der Schlüssel des Servers wurde mit einem alten Hauptschlüssel verschlüsselt." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:29 -+msgid "Client not found in Kerberos database" -+msgstr "Client nicht in der Kerberos-Datenbank gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:30 -+msgid "Server not found in Kerberos database" -+msgstr "Server nicht in der Kerberos-Datenbank gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:31 -+msgid "Principal has multiple entries in Kerberos database" -+msgstr "Principal hat in der Kerberos-Datenbank mehrere Einträge" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:32 -+msgid "Client or server has a null key" -+msgstr "Client oder Server hat einen Nullschlüssel" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:33 -+msgid "Ticket is ineligible for postdating" -+msgstr "Ticket ist zum Vordatieren ungeeignet" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:34 -+msgid "Requested effective lifetime is negative or too short" -+msgstr "Die angeforderte effektive Lebensdauer ist negativ oder zu kurz." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:35 -+msgid "KDC policy rejects request" -+msgstr "KDC-Richtlinie weist die Anfrage zurück" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:36 -+msgid "KDC can't fulfill requested option" -+msgstr "KDC kann erforderliche Option nicht erfüllen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:37 -+msgid "KDC has no support for encryption type" -+msgstr "KDC unterstützt diesen Verschlüsselungstyp nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:38 -+msgid "KDC has no support for checksum type" -+msgstr "KDC unterstützt diesen Prüfsummentyp nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:39 -+msgid "KDC has no support for padata type" -+msgstr "KDC unterstützt diesen Padata-Typ nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:40 -+msgid "KDC has no support for transited type" -+msgstr "KDC unterstützt diesen Übergangstyp nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:41 -+msgid "Clients credentials have been revoked" -+msgstr "Anmeldedaten des Clients wurden widerrufen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:42 -+msgid "Credentials for server have been revoked" -+msgstr "Anmeldedaten für den Server wurden widerrufen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:43 -+msgid "TGT has been revoked" -+msgstr "TGT wurde widerrufen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:44 -+msgid "Client not yet valid - try again later" -+msgstr "Client noch nicht gültig – versuchen Sie es später noch einmal" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:45 -+msgid "Server not yet valid - try again later" -+msgstr "Server noch nicht gültig – versuchen Sie es später noch einmal" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:46 -+msgid "Password has expired" -+msgstr "Passwort ist abgelaufen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:47 -+msgid "Preauthentication failed" -+msgstr "Vorauthentifizierung fehlgeschlagen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:48 -+msgid "Additional pre-authentication required" -+msgstr "zusätzlich Vorauthentifizierung erforderlich" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:49 -+msgid "Requested server and ticket don't match" -+msgstr "abgefragter Server und Ticket passen nicht zusammen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:50 -+msgid "Server principal valid for user2user only" -+msgstr "Der Server-Principal ist nur für »user2user« gültig" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:51 -+msgid "KDC policy rejects transited path" -+msgstr "KDC-Richtlinie verwirft durchgereichten Pfad" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:52 -+msgid "A service is not available that is required to process the request" -+msgstr "" -+"Ein Dienst, der zum Verarbeiten der Abfrage erforderlich ist, ist nicht " -+"verfügbar." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:53 -+msgid "KRB5 error code 30" -+msgstr "KRB5-Fehlercode 30" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:54 -+msgid "Decrypt integrity check failed" -+msgstr "Entschlüsselungsintegritätsprüfung fehlgeschlagen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:55 -+msgid "Ticket expired" -+msgstr "Ticket abgelaufen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:56 -+msgid "Ticket not yet valid" -+msgstr "Ticket noch nicht gültig" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:57 -+msgid "Request is a replay" -+msgstr "Anfrage ist eine Wiederholung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:58 -+msgid "The ticket isn't for us" -+msgstr "Das Ticket ist nicht für uns." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:59 -+msgid "Ticket/authenticator don't match" -+msgstr "Ticket/Schlüsselziffer passen nicht zueinander" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:60 -+msgid "Clock skew too great" -+msgstr "Uhrzeitabweichung zu groß" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:61 -+msgid "Incorrect net address" -+msgstr "falsche Netzwerkadresse" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:62 -+msgid "Protocol version mismatch" -+msgstr "Protokollversion passt nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:63 -+msgid "Invalid message type" -+msgstr "ungültiger Nachrichtentyp" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:64 -+msgid "Message stream modified" -+msgstr "Nachrichtendatenstrom geändert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:65 -+msgid "Message out of order" -+msgstr "Nachricht nicht in Ordnung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:66 -+msgid "Illegal cross-realm ticket" -+msgstr "Widerrechliches Realm-übergreifendes Ticket" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:67 -+msgid "Key version is not available" -+msgstr "Schlüsselversion ist nicht verfügbar" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:68 -+msgid "Service key not available" -+msgstr "Dienstschlüssel nicht verfügbar" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:69 -+#: ../lib/krb5/error_tables/krb5_err.c:181 -+msgid "Mutual authentication failed" -+msgstr "gegenseitige Authentifizierung fehlgeschlagen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:70 -+msgid "Incorrect message direction" -+msgstr "falsche Nachrichtenrichtung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:71 -+msgid "Alternative authentication method required" -+msgstr "alternative Authentifizierungsmethode erforderlich" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:72 -+msgid "Incorrect sequence number in message" -+msgstr "falsche Sequenznummer in der Nachricht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:73 -+msgid "Inappropriate type of checksum in message" -+msgstr "ungeeigneter Prüfsummentyp in der Nachricht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:74 -+msgid "Policy rejects transited path" -+msgstr "Richtlinie verwirft durchgereichten Pfad" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:75 -+msgid "Response too big for UDP, retry with TCP" -+msgstr "Antwort für UDP zu groß, erneuter Versuch mit TCP" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:76 -+msgid "KRB5 error code 53" -+msgstr "KRB5-Fehlercode 53" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:77 -+msgid "KRB5 error code 54" -+msgstr "KRB5-Fehlercode 54" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:78 -+msgid "KRB5 error code 55" -+msgstr "KRB5-Fehlercode 55" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:79 -+msgid "KRB5 error code 56" -+msgstr "KRB5-Fehlercode 56" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:80 -+msgid "KRB5 error code 57" -+msgstr "KRB5-Fehlercode 57" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:81 -+msgid "KRB5 error code 58" -+msgstr "KRB5-Fehlercode 58" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:82 -+msgid "KRB5 error code 59" -+msgstr "KRB5-Fehlercode 59" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:83 -+msgid "Generic error (see e-text)" -+msgstr "allgemeiner Fehler (siehe E-Text)" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:84 -+msgid "Field is too long for this implementation" -+msgstr "Feld ist für diese Implementierung zu lang" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:85 -+msgid "Client not trusted" -+msgstr "Client nicht vertrauenswürdig" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:86 -+msgid "KDC not trusted" -+msgstr "KDC nicht vertrauenswürdig" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:87 -+msgid "Invalid signature" -+msgstr "ungültige Signatur" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:88 -+msgid "Key parameters not accepted" -+msgstr "Schlüsselparameter nicht akzeptiert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:89 -+msgid "Certificate mismatch" -+msgstr "Zertifikat passt nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:90 -+msgid "No ticket granting ticket" -+msgstr "kein ticketgewährendes Ticket" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:91 -+msgid "Realm not local to KDC" -+msgstr "Realm für KDC nicht lokal" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:92 -+msgid "User to user required" -+msgstr "Benutzer-zu-Benutzer erforderlich" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:93 -+msgid "Can't verify certificate" -+msgstr "Zertifikat kann nicht überprüft werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:94 -+msgid "Invalid certificate" -+msgstr "ungültiges Zertifikat" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:95 -+msgid "Revoked certificate" -+msgstr "widerrufenes Zertifikat" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:96 -+msgid "Revocation status unknown" -+msgstr "Widerrufsstatus unbekannt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:97 -+msgid "Revocation status unavailable" -+msgstr "Widerrufsstatus nicht verfügbar" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:98 -+msgid "Client name mismatch" -+msgstr "Client-Name passt nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:99 -+msgid "KDC name mismatch" -+msgstr "KDC-Name passt nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:100 -+msgid "Inconsistent key purpose" -+msgstr "inkonstistenter Schlüsselzweck" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:101 -+msgid "Digest in certificate not accepted" -+msgstr "Kurzfassung im Zertifikat nicht akzeptiert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:102 -+msgid "Checksum must be included" -+msgstr "Prüfsumme muss enthalten sein" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:103 -+msgid "Digest in signed-data not accepted" -+msgstr "Kurzfassung in signierten Daten nicht akzeptiert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:104 -+msgid "Public key encryption not supported" -+msgstr "Asymetrische Verschlüsselung nicht unterstützt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:105 -+msgid "KRB5 error code 82" -+msgstr "KRB5-Fehlercode 82" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:106 -+msgid "KRB5 error code 83" -+msgstr "KRB5-Fehlercode 83" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:107 -+msgid "KRB5 error code 84" -+msgstr "KRB5-Fehlercode 84" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:108 -+msgid "The IAKERB proxy could not find a KDC" -+msgstr "Der IAKERB-Proxy konnte kein KDC finden." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:109 -+msgid "The KDC did not respond to the IAKERB proxy" -+msgstr "Das KDC anwortete dem IAKERB-Proxy nicht." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:110 -+msgid "KRB5 error code 87" -+msgstr "KRB5-Fehlercode 87" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:111 -+msgid "KRB5 error code 88" -+msgstr "KRB5-Fehlercode 88" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:112 -+msgid "KRB5 error code 89" -+msgstr "KRB5-Fehlercode 89" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:113 -+msgid "KRB5 error code 90" -+msgstr "KRB5-Fehlercode 90" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:114 -+msgid "KRB5 error code 91" -+msgstr "KRB5-Fehlercode 91" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:115 -+msgid "KRB5 error code 92" -+msgstr "KRB5-Fehlercode 92" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:116 -+msgid "An unsupported critical FAST option was requested" -+msgstr "Es wurde eine nicht unterstützte kritische FAST-Aktion angefordert." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:117 -+msgid "KRB5 error code 94" -+msgstr "KRB5-Fehlercode 94" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:118 -+msgid "KRB5 error code 95" -+msgstr "KRB5-Fehlercode 95" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:119 -+msgid "KRB5 error code 96" -+msgstr "KRB5-Fehlercode 96" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:120 -+msgid "KRB5 error code 97" -+msgstr "KRB5-Fehlercode 97" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:121 -+msgid "KRB5 error code 98" -+msgstr "KRB5-Fehlercode 98" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:122 -+msgid "KRB5 error code 99" -+msgstr "KRB5-Fehlercode 99" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:123 -+msgid "No acceptable KDF offered" -+msgstr "kein akzeptables KDF angeboten" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:124 -+msgid "KRB5 error code 101" -+msgstr "KRB5-Fehlercode 101" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:125 -+msgid "KRB5 error code 102" -+msgstr "KRB5-Fehlercode 102" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:126 -+msgid "KRB5 error code 103" -+msgstr "KRB5-Fehlercode 103" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:127 -+msgid "KRB5 error code 104" -+msgstr "KRB5-Fehlercode 104" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:128 -+msgid "KRB5 error code 105" -+msgstr "KRB5-Fehlercode 105" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:129 -+msgid "KRB5 error code 106" -+msgstr "KRB5-Fehlercode 106" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:130 -+msgid "KRB5 error code 107" -+msgstr "KRB5-Fehlercode 107" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:131 -+msgid "KRB5 error code 108" -+msgstr "KRB5-Fehlercode 108" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:132 -+msgid "KRB5 error code 109" -+msgstr "KRB5-Fehlercode 109" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:133 -+msgid "KRB5 error code 110" -+msgstr "KRB5-Fehlercode 110" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:134 -+msgid "KRB5 error code 111" -+msgstr "KRB5-Fehlercode 111" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:135 -+msgid "KRB5 error code 112" -+msgstr "KRB5-Fehlercode 112" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:136 -+msgid "KRB5 error code 113" -+msgstr "KRB5-Fehlercode 113" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:137 -+msgid "KRB5 error code 114" -+msgstr "KRB5-Fehlercode 114" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:138 -+msgid "KRB5 error code 115" -+msgstr "KRB5-Fehlercode 115" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:139 -+msgid "KRB5 error code 116" -+msgstr "KRB5-Fehlercode 116" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:140 -+msgid "KRB5 error code 117" -+msgstr "KRB5-Fehlercode 117" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:141 -+msgid "KRB5 error code 118" -+msgstr "KRB5-Fehlercode 118" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:142 -+msgid "KRB5 error code 119" -+msgstr "KRB5-Fehlercode 119" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:143 -+msgid "KRB5 error code 120" -+msgstr "KRB5-Fehlercode 120" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:144 -+msgid "KRB5 error code 121" -+msgstr "KRB5-Fehlercode 121" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:145 -+msgid "KRB5 error code 122" -+msgstr "KRB5-Fehlercode 122" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:146 -+msgid "KRB5 error code 123" -+msgstr "KRB5-Fehlercode 123" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:147 -+msgid "KRB5 error code 124" -+msgstr "KRB5-Fehlercode 124" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:148 -+msgid "KRB5 error code 125" -+msgstr "KRB5-Fehlercode 125" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:149 -+msgid "KRB5 error code 126" -+msgstr "KRB5-Fehlercode 126" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:150 -+msgid "KRB5 error code 127" -+msgstr "KRB5-Fehlercode 127" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:151 -+#: ../lib/krb5/error_tables/kdb5_err.c:23 -+msgid "$Id$" -+msgstr "$Id$" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:152 -+msgid "Invalid flag for file lock mode" -+msgstr "ungültiger Schalter für den Datei-Sperrmodus" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:153 -+msgid "Cannot read password" -+msgstr "Passwort kann nicht gelesen werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:154 -+msgid "Password mismatch" -+msgstr "Passwort stimmt nicht überein" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:155 -+msgid "Password read interrupted" -+msgstr "Lesen des Passworts unterbrochen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:156 -+msgid "Illegal character in component name" -+msgstr "ungültiges Zeichen in Komponentenname" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:157 -+msgid "Malformed representation of principal" -+msgstr "Darstellung des Principals in falscher Form" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:158 -+msgid "Can't open/find Kerberos configuration file" -+msgstr "Kerberos-Konfigurationsdatei kann nicht geöffnet/gefunden werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:159 -+msgid "Improper format of Kerberos configuration file" -+msgstr "Format der Kerberos-Konfigurationsdatei ist ungeeignet" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:160 -+msgid "Insufficient space to return complete information" -+msgstr "Platz reicht nicht zur Rückgabe aller Informationen aus" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:161 -+msgid "Invalid message type specified for encoding" -+msgstr "der zum Kodieren angegebene Nachrichtentyp ist ungültig" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:162 -+msgid "Credential cache name malformed" -+msgstr "falsche Form des Anmeldedatenzwischenspeichernamens" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:163 -+msgid "Unknown credential cache type" -+msgstr "unbekannter Anmeldedatenzwischenspeichertyp" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:164 -+msgid "Matching credential not found" -+msgstr "keine passenden Anmeldedaten gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:165 -+msgid "End of credential cache reached" -+msgstr "Ende des Anmeldedatenzwischenspeichers erreicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:166 -+msgid "Request did not supply a ticket" -+msgstr "Anfrage lieferte kein Ticket" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:167 -+msgid "Wrong principal in request" -+msgstr "falscher Principal in der Anfrage" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:168 -+msgid "Ticket has invalid flag set" -+msgstr "Das Ticket hat einen falsch gesetzten Schalter." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:169 -+msgid "Requested principal and ticket don't match" -+msgstr "angeforderter Principal und Ticket passen nicht zusammen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:170 -+msgid "KDC reply did not match expectations" -+msgstr "KDC-Antwort entsprach nicht den Erwartungen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:171 -+msgid "Clock skew too great in KDC reply" -+msgstr "Zeitversatz in der KDC-Antwort zu groß" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:172 -+msgid "Client/server realm mismatch in initial ticket request" -+msgstr "" -+"Client-/Server-Realm passen in der anfänglichen Ticketanfrage nicht zusammen." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:173 -+msgid "Program lacks support for encryption type" -+msgstr "" -+"Dem Programm fehlt es an der Unterstützung für den Verschlüsselungstyp." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:174 -+msgid "Program lacks support for key type" -+msgstr "Dem Programm fehlt es an der Unterstützung für den Schlüsseltyp." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:175 -+msgid "Requested encryption type not used in message" -+msgstr "" -+"Der angeforderte Verschlüsselungstyp wird in der Nachricht nicht verwendet." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:176 -+msgid "Program lacks support for checksum type" -+msgstr "Dem Programm fehlt es an der Unterstützung für den Prüfsummentyp." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:177 -+msgid "Cannot find KDC for requested realm" -+msgstr "KDC für angeforderten Realm kann nicht gefunden werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:178 -+msgid "Kerberos service unknown" -+msgstr "Kerberos-Dienst unbekannt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:179 -+msgid "Cannot contact any KDC for requested realm" -+msgstr "Für den angeforderten Realm kann kein KDC kontaktiert werden." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:180 -+msgid "No local name found for principal name" -+msgstr "Für den Principal-Namen wurde kein lokaler Name gefunden." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:182 -+msgid "Replay cache type is already registered" -+msgstr "Wiederholungszwischenspeichertyp ist bereits registriert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:183 -+msgid "No more memory to allocate (in replay cache code)" -+msgstr "" -+"kein Speicher mehr zu reservieren (im Wiederholungszwischenspeichercode)" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:184 -+msgid "Replay cache type is unknown" -+msgstr "Wiederholungszwischenspeichertyp ist unbekannt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:185 -+msgid "Generic unknown RC error" -+msgstr "allgemeiner unbekannter Wiederholungszwischenspeicherfehler" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:186 -+msgid "Message is a replay" -+msgstr "Nachricht ist eine Wiederholung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:187 -+msgid "Replay cache I/O operation failed" -+msgstr "Wiederholungszwischenspeicher-E/A-Aktion fehlgeschlagen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:188 -+msgid "Replay cache type does not support non-volatile storage" -+msgstr "" -+"Wiederholungszwischenspeichertyp unterstützt keinen beständigen Speicher" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:189 -+msgid "Replay cache name parse/format error" -+msgstr "Auswerte-/Formatfehler im Wiederholungszwischenspeichernamens" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:190 -+msgid "End-of-file on replay cache I/O" -+msgstr "Dateiende bei der E/A des Wiederholungszwischenspeichers" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:191 -+msgid "No more memory to allocate (in replay cache I/O code)" -+msgstr "" -+"kein weiterer Speicher reservierbar (im Wiederholungszwischenspeicher-E/A-" -+"Code)" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:192 -+msgid "Permission denied in replay cache code" -+msgstr "Zugriff im Wiederholungszwischenspeichercode verweigert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:193 -+msgid "I/O error in replay cache i/o code" -+msgstr "E/A-Fehler im Wiederholungszwischenspeicher-E/A-Code" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:194 -+msgid "Generic unknown RC/IO error" -+msgstr "allgemeiner unbekannter Wiederholungszwischenspeicher-/E/A-Fehler" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:195 -+msgid "Insufficient system space to store replay information" -+msgstr "" -+"Platz im System reicht nicht zum Speichern der Wiederholungsinformationen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:196 -+msgid "Can't open/find realm translation file" -+msgstr "Realm-Übersetzungsdatei kann nicht geöffnet/gefunden werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:197 -+msgid "Improper format of realm translation file" -+msgstr "Format der Realm-Übersetzungsdatei ist ungeeignet" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:198 -+msgid "Can't open/find lname translation database" -+msgstr "die Lname-Übersetzungsdatenbank kann nicht geöffnet/gefunden werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:199 -+msgid "No translation available for requested principal" -+msgstr "Für den angeforderten Principal ist keine Übersetzung verfügbar." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:200 -+msgid "Improper format of translation database entry" -+msgstr "Format des Eintrags der Übersetzungsdatenbank ist ungeeignet" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:201 -+msgid "Cryptosystem internal error" -+msgstr "interner Fehler des Verschlüsselungssystems" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:202 -+msgid "Key table name malformed" -+msgstr "falsche Form des Schlüsseltabellennamens" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:203 -+msgid "Unknown Key table type" -+msgstr "unbekannter Schlüsseltabellentyp" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:204 -+msgid "Key table entry not found" -+msgstr "Schlüsseltabelleneintrag nicht gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:205 -+msgid "End of key table reached" -+msgstr "Ende der Schlüsseltabelle erreicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:206 -+msgid "Cannot write to specified key table" -+msgstr "in angegebene Schlüsseltabelle kann nicht geschrieben werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:207 -+msgid "Error writing to key table" -+msgstr "Fehler beim Schreiben in Schlüsseltabelle" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:208 -+msgid "Cannot find ticket for requested realm" -+msgstr "Ticket für angeforderten Realm kann nicht gefunden werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:209 -+msgid "DES key has bad parity" -+msgstr "DES-Schlüssel hat falsche Parität" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:210 -+msgid "DES key is a weak key" -+msgstr "DES-Schlüssel ist schwach" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:211 -+msgid "Bad encryption type" -+msgstr "falscher Verschlüsselungstyp" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:212 -+msgid "Key size is incompatible with encryption type" -+msgstr "Schlüssellänge ist nicht mit dem Verschlüsselungstyp kompatibel" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:213 -+msgid "Message size is incompatible with encryption type" -+msgstr "Nachrichtengröße ist nicht mit Verschlüsselungstyp kompatibel" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:214 -+msgid "Credentials cache type is already registered." -+msgstr "Anmeldedatenzwischenspeichertyp ist bereits registriert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:215 -+msgid "Key table type is already registered." -+msgstr "Schlüsseltabellentyp ist bereits registriert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:216 -+msgid "Credentials cache I/O operation failed XXX" -+msgstr "E/A-Aktion für Anmeldedatenzwischenspeicher fehlgeschlagen XXX" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:217 -+msgid "Credentials cache permissions incorrect" -+msgstr "Anmeldedatenzwischenspeicherrechte nicht korrekt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:218 -+msgid "No credentials cache found" -+msgstr "kein Anmeldedatenzwischenspeicher gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:219 -+msgid "Internal credentials cache error" -+msgstr "interner Anmeldedatenzwischenspeicherfehler" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:220 -+msgid "Error writing to credentials cache" -+msgstr "Fehler beim Schreiben in den Anmeldedatenzwischenspeicher" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:221 -+msgid "No more memory to allocate (in credentials cache code)" -+msgstr "" -+"kein weiterer Speicher zu reservieren (im Anmeldedatenzwischenspeichercode)" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:222 -+msgid "Bad format in credentials cache" -+msgstr "falsches Format im Anmeldedatenzwischenspeicher" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:223 -+msgid "No credentials found with supported encryption types" -+msgstr "keine Anmeldedaten mit unterstützten Verschlüsselungstypen gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:224 -+msgid "Invalid KDC option combination (library internal error)" -+msgstr "ungültige Kombination von KDC-Optionen (interner Bibliotheksfehler)" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:225 -+msgid "Request missing second ticket" -+msgstr "Der Anfrage fehlt das zweite Ticket." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:226 -+msgid "No credentials supplied to library routine" -+msgstr "der Bibliotheks-Routine wurden keine Anmeldedaten geliefert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:227 -+msgid "Bad sendauth version was sent" -+msgstr "Es wurde eine falsche Sendauth-Version verschickt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:228 -+msgid "Bad application version was sent (via sendauth)" -+msgstr "Es wurde eine falsche Anwendungsversion (über Sendauth) verschickt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:229 -+msgid "Bad response (during sendauth exchange)" -+msgstr "falsche Antwort (beim Sendauth-Austausch)" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:230 -+msgid "Server rejected authentication (during sendauth exchange)" -+msgstr "Server wies Authentifizierung (beim Sendauth-Austausch) zurück" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:231 -+msgid "Unsupported preauthentication type" -+msgstr "nicht unterstützter Vorauthentifizierungstyp" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:232 -+msgid "Required preauthentication key not supplied" -+msgstr "erforderlicher Vorauthentifizierungsschlüssel nicht bereitgestellt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:233 -+msgid "Generic preauthentication failure" -+msgstr "allgemeiner Fehlschlag der Vorauthentifizierung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:234 -+msgid "Unsupported replay cache format version number" -+msgstr "" -+"nicht unterstütztes Versionsnummernformat des Wiederholungszwischenspeichers" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:235 -+msgid "Unsupported credentials cache format version number" -+msgstr "" -+"nicht unterstütztes Versionsnummernformat des Anmeldedatenzwischenspeichers" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:236 -+msgid "Unsupported key table format version number" -+msgstr "nicht unterstütztes Versionsnummernformat der Schlüsseltabelle" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:237 -+msgid "Program lacks support for address type" -+msgstr "Dem Programm fehlt es an der Unterstützung des Adresstyps." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:238 -+msgid "Message replay detection requires rcache parameter" -+msgstr "Erkennung der Antwortnachricht erfordert den Parameter »rcache«" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:239 -+msgid "Hostname cannot be canonicalized" -+msgstr "Rechnername kann nicht in Normalform gebracht werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:240 -+msgid "Cannot determine realm for host" -+msgstr "Realm für Rechner kann nicht bestimmt werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:241 -+msgid "Conversion to service principal undefined for name type" -+msgstr "Umwandlung in Dienst-Principal für Namenstyp nicht definiert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:242 -+msgid "Initial Ticket response appears to be Version 4 error" -+msgstr "anfängliche Ticket-Antwort scheint ein Fehler der Version 4 zu sein" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:243 -+msgid "Cannot resolve network address for KDC in requested realm" -+msgstr "" -+"Netzwerkadresse für KDC im angeforderten Realm kann nicht aufgelöst werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:244 -+msgid "Requesting ticket can't get forwardable tickets" -+msgstr "anforderndes Ticket kann keine weiterleitbaren Tickets holen" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:245 -+msgid "Bad principal name while trying to forward credentials" -+msgstr "falscher Principal beim Versuch, Anmeldedaten weiterzuleiten" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:246 -+msgid "Looping detected inside krb5_get_in_tkt" -+msgstr "Schleife innerhalb von »krb5_get_in_tkt« entdeckt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:247 -+msgid "Configuration file does not specify default realm" -+msgstr "Konfigurationsdatei gibt keinen Standard-Realm an" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:248 -+msgid "Bad SAM flags in obtain_sam_padata" -+msgstr "falsche SAM-Schalter in »obtain_sam_padata«" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:249 -+msgid "Invalid encryption type in SAM challenge" -+msgstr "ungültiger Verschlüsselungstyp in der SAM-Aufforderung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:250 -+msgid "Missing checksum in SAM challenge" -+msgstr "fehlende Prüfsumme in der SAM-Aufforderung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:251 -+msgid "Bad checksum in SAM challenge" -+msgstr "falsche Prüfsumme in der SAM-Aufforderung" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:252 -+msgid "Keytab name too long" -+msgstr "Schlüsseltabellennamen zu lang" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:253 -+msgid "Key version number for principal in key table is incorrect" -+msgstr "" -+"Schlüsselversionsnummer des Principals in der Schlüsseltabelle ist nicht " -+"korrekt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:254 -+msgid "This application has expired" -+msgstr "Diese Anwendung ist abgelaufen." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:255 -+msgid "This Krb5 library has expired" -+msgstr "Diese Krb5-Bibliothek ist abgelaufen." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:256 -+msgid "New password cannot be zero length" -+msgstr "Das neue Passwort kann nicht die Länge Null haben." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:258 -+msgid "Bad format in keytab" -+msgstr "falsches Format in der Schlüsseltabelle" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:259 -+msgid "Encryption type not permitted" -+msgstr "Verschlüsselungstyp nicht erlaubt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:260 -+msgid "No supported encryption types (config file error?)" -+msgstr "" -+"keine unterstützten Verschlüsselungstypen (Fehler in der " -+"Konfigurationsdatei?)" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:261 -+msgid "Program called an obsolete, deleted function" -+msgstr "Das Programm rief eine veraltete, gelöschte Funktion auf." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:262 -+msgid "unknown getaddrinfo failure" -+msgstr "unbekannter Getaddrinfo-Fehlschlag" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:263 -+msgid "no data available for host/domain name" -+msgstr "keine Daten für Rechner/Domain-Namen verfügbar" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:264 -+msgid "host/domain name not found" -+msgstr "Rechner/Domain-Name nicht gefunden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:265 -+msgid "service name unknown" -+msgstr "Dienstname unbekannt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:266 -+msgid "Cannot determine realm for numeric host address" -+msgstr "Realm für numerische Rechneradresse kann nicht bestimmt werden" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:267 -+msgid "Invalid key generation parameters from KDC" -+msgstr "ungültige Parameter zum Erzeugen von Schlüsseln vom KDC" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:268 -+msgid "service not available" -+msgstr "Dienst nicht verfügbar" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:269 -+msgid "Ccache function not supported: read-only ccache type" -+msgstr "Ccache-Funktion nicht unterstützt: Ccache-Typ nur lesbar" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:270 -+msgid "Ccache function not supported: not implemented" -+msgstr "Ccache-Funktion nicht unterstützt: nicht implementiert" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:271 -+msgid "Invalid format of Kerberos lifetime or clock skew string" -+msgstr "" -+"ungültiges Format der Kerberos-Lebensdauer oder der Zeitversatzzeichenkette" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:272 -+msgid "Supplied data not handled by this plugin" -+msgstr "" -+"Die bereitgestellten Daten werden nicht von dieser Erweiterung behandelt." -+ -+#: ../lib/krb5/error_tables/krb5_err.c:273 -+msgid "Plugin does not support the operation" -+msgstr "Erweiterung unterstützt diese Aktion nicht" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:274 -+msgid "Invalid UTF-8 string" -+msgstr "ungültige UTF-8-Zeichenkette" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:275 -+msgid "FAST protected pre-authentication required but not supported by KDC" -+msgstr "" -+"FAST-geschützte Vorauthentifizierung erforderlich, aber nicht vom KDC " -+"unterstützt" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:276 -+msgid "Auth context must contain local address" -+msgstr "Authentifizierungskontext muss lokale Adresse enthalten" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:277 -+msgid "Auth context must contain remote address" -+msgstr "Authentifizierungskontext muss ferne Adresse enthalten" -+ -+#: ../lib/krb5/error_tables/krb5_err.c:278 -+msgid "Tracing unsupported" -+msgstr "Verfolgung nicht unterstützt" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:24 -+msgid "Entry already exists in database" -+msgstr "Eintrag existiert bereits in der Datenbank" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:25 -+msgid "Database store error" -+msgstr "Datenbank-Speicherfehler" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:26 -+msgid "Database read error" -+msgstr "Datenbank-Lesefehler" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:27 -+msgid "Insufficient access to perform requested operation" -+msgstr "Zugriffsrechte reichen nicht zur Durchführung der angeforderten Aktion" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:28 -+msgid "No such entry in the database" -+msgstr "kein derartiger Eintrag in der Datenbank" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:29 -+msgid "Illegal use of wildcard" -+msgstr "ungültige Verwendung eines Platzhalters" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:30 -+msgid "Database is locked or in use--try again later" -+msgstr "" -+"Datenbank ist gesperrt oder wird gerade benutzt – versuchen Sie es später " -+"wieder" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:31 -+msgid "Database was modified during read" -+msgstr "Datenbank wurde während des Lesens geändert" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:32 -+msgid "Database record is incomplete or corrupted" -+msgstr "Datensatz ist unvollständig oder beschädigt" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:33 -+msgid "Attempt to lock database twice" -+msgstr "Es wurde zweimal versucht, die Datenbank zu sperren." -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:34 -+msgid "Attempt to unlock database when not locked" -+msgstr "" -+"Es wurde versucht, die Datenbank zu entsperren, obwohl sie nicht gesperrt " -+"ist." -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:35 -+msgid "Invalid kdb lock mode" -+msgstr "ungültiger KDB-Sperrmodus" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:36 -+msgid "Database has not been initialized" -+msgstr "Datenbank wurde nicht initialisiert" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:37 -+msgid "Database has already been initialized" -+msgstr "Datenbank wurde bereits initialisiert" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:38 -+msgid "Bad direction for converting keys" -+msgstr "falsche Richtung zum Umwandeln von Schlüsseln" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:39 -+msgid "Cannot find master key record in database" -+msgstr "Hauptschlüsseldatensatz kann nicht in der Datenbank gefunden werden" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:40 -+msgid "Master key does not match database" -+msgstr "Hauptschlüssel passt nicht zur Datenbank" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:41 -+msgid "Key size in database is invalid" -+msgstr "Die Schlüssellänge in der Datenbank ist ungültig," -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:42 -+msgid "Cannot find/read stored master key" -+msgstr "Der gespeicherte Hauptschlüssel kann nicht gefunden/gelesen werden." -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:43 -+msgid "Stored master key is corrupted" -+msgstr "Der gespeicherte Hauptschlüssel ist beschädigt." -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:44 -+msgid "Cannot find active master key" -+msgstr "Der aktive Hauptschlüssel kann nicht gefunden werden." -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:45 -+msgid "KVNO of new master key does not match expected value" -+msgstr "KVNO des neuen Hauptschlüssels passt nicht zum erwarteten Wert" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:46 -+msgid "Stored master key is not current" -+msgstr "gespeicherter Hauptschlüssel ist nicht aktuell" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:47 -+msgid "Insufficient access to lock database" -+msgstr "keine ausreichenden Zugriffsrechte zum Sperren der Datenbank" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:48 -+msgid "Database format error" -+msgstr "fehlerhaftes Datenbankformat" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:49 -+msgid "Unsupported version in database entry" -+msgstr "nicht unterstützte Version im Datenbankeintrag" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:50 -+msgid "Unsupported salt type" -+msgstr "nicht unterstützter Salt-Typ" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:51 -+msgid "Unsupported encryption type" -+msgstr "nicht unterstützter Verschlüsselungstyp" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:52 -+msgid "Bad database creation flags" -+msgstr "falsche Schalter zum Erstellen der Datenbank" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:53 -+msgid "No matching key in entry having a permitted enctype" -+msgstr "" -+"kein passender Schlüssel in einem Eintrag mit erlaubtem Verschlüsselungstyp" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:54 -+msgid "No matching key in entry" -+msgstr "kein passender Schlüssel im Eintrag" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:55 -+msgid "Unable to find requested database type" -+msgstr "angeforderter Datenbanktyp kann nicht gefunden werden" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:56 -+msgid "Database type not supported" -+msgstr "Datenbanktyp nicht unterstützt" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:57 -+msgid "Database library failed to initialize" -+msgstr "Initialisieren der Datenbankbibliothek fehlgeschlagen" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:59 -+msgid "Unable to access Kerberos database" -+msgstr "auf die Kerberos-Datenbank kann nicht zugegriffen werden" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:60 -+msgid "Kerberos database internal error" -+msgstr "interner Kerberos-Datenbankfehler" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:61 -+msgid "Kerberos database constraints violated" -+msgstr "Kerberos-Datenbankbeschränkungen verletzt" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:62 -+msgid "Update log conversion error" -+msgstr "Fehler beim Umwandeln des Aktualisierungsprotokolls" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:63 -+msgid "Update log is unstable" -+msgstr "Aktualisierungsprotokoll ist instabil" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:64 -+msgid "Update log is corrupt" -+msgstr "Aktualisierungsprotokoll ist beschädigt" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:65 -+msgid "Generic update log error" -+msgstr "allgemeiner Aktualisierungsprotokollfehler" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:66 -+msgid "Database module does not match KDC version" -+msgstr "Datenbankmodul passt nicht zur KDC-Version" -+ -+#: ../lib/krb5/error_tables/kdb5_err.c:68 -+msgid "Too much string mapping data" -+msgstr "zu viele zeichenkettenabbildenden Daten" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:23 -+msgid "ASN.1 failed call to system time library" -+msgstr "ASN.1 beim Aufruf der Systemzeitbibliothek gescheitert" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:24 -+msgid "ASN.1 structure is missing a required field" -+msgstr "ein erforderliches Feld fehlt in der ASN.1-Struktur" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:25 -+msgid "ASN.1 unexpected field number" -+msgstr "ASN.1 unerwartete Feldnummer" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:26 -+msgid "ASN.1 type numbers are inconsistent" -+msgstr "ASN.1-Typnummern sind inkonsistent" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:27 -+msgid "ASN.1 value too large" -+msgstr "ASN.1-Wert zu groß" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:28 -+msgid "ASN.1 encoding ended unexpectedly" -+msgstr "ASN.1-Kodierung endete unerwartet" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:29 -+msgid "ASN.1 identifier doesn't match expected value" -+msgstr "ASN.1-Bezeichner passt nicht zum erwarteten Wert" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:30 -+msgid "ASN.1 length doesn't match expected value" -+msgstr "Länge von ASN.1 passt nicht zum erwarteten Wert" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:31 -+msgid "ASN.1 badly-formatted encoding" -+msgstr "fehlerhaft formatierte ASN.1-Kodierung" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:32 -+msgid "ASN.1 parse error" -+msgstr "ASN.1-Auswertungsfehler" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:33 -+msgid "ASN.1 bad return from gmtime" -+msgstr "ASN.1 falscher Rückgabewert von Gmtime" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:34 -+msgid "ASN.1 non-constructed indefinite encoding" -+msgstr "nicht konstruierte unbestimmte ASN.1-Kodierung" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:35 -+msgid "ASN.1 missing expected EOC" -+msgstr "ASN.1 fehlt erwartetes EOC" -+ -+#: ../lib/krb5/error_tables/asn1_err.c:36 -+msgid "ASN.1 object omitted in sequence" -+msgstr "ASN.1-Objekt in Sequenz ausgelassen" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:23 -+msgid "Kerberos V5 magic number table" -+msgstr "Tabelle magischer Zahlen von Kerberos V5" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:24 -+msgid "Bad magic number for krb5_principal structure" -+msgstr "falsche magische Zahl für Krb5_principal-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:25 -+msgid "Bad magic number for krb5_data structure" -+msgstr "falsche magische Zahl für Krb5_data-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:26 -+msgid "Bad magic number for krb5_keyblock structure" -+msgstr "falsche magische Zahl für Krb5_krb5_keyblock-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:27 -+msgid "Bad magic number for krb5_checksum structure" -+msgstr "falsche magische Zahl für Krb5_krb5_checksum-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:28 -+msgid "Bad magic number for krb5_encrypt_block structure" -+msgstr "falsche magische Zahl für Krb5_encrypt_bloc-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:29 -+msgid "Bad magic number for krb5_enc_data structure" -+msgstr "falsche magische Zahl für Krb5_enc_data-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:30 -+msgid "Bad magic number for krb5_cryptosystem_entry structure" -+msgstr "falsche magische Zahl für Krb5_cryptosystem_entry-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:31 -+msgid "Bad magic number for krb5_cs_table_entry structure" -+msgstr "falsche magische Zahl für Krb5_cs_table_entry-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:32 -+msgid "Bad magic number for krb5_checksum_entry structure" -+msgstr "falsche magische Zahl für Krb5_checksum_entry-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:33 -+msgid "Bad magic number for krb5_authdata structure" -+msgstr "falsche magische Zahl für Krb5_authdata-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:34 -+msgid "Bad magic number for krb5_transited structure" -+msgstr "falsche magische Zahl für Krb5_transited-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:35 -+msgid "Bad magic number for krb5_enc_tkt_part structure" -+msgstr "falsche magische Zahl für Krb5_enc_tkt_part-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:36 -+msgid "Bad magic number for krb5_ticket structure" -+msgstr "falsche magische Zahl für Krb5_ticket-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:37 -+msgid "Bad magic number for krb5_authenticator structure" -+msgstr "falsche magische Zahl für Krb5_authenticator-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:38 -+msgid "Bad magic number for krb5_tkt_authent structure" -+msgstr "falsche magische Zahl für Krb5_tkt_authent-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:39 -+msgid "Bad magic number for krb5_creds structure" -+msgstr "falsche magische Zahl für Krb5_creds-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:40 -+msgid "Bad magic number for krb5_last_req_entry structure" -+msgstr "falsche magische Zahl für Krb5_last_req_entry-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:41 -+msgid "Bad magic number for krb5_pa_data structure" -+msgstr "falsche magische Zahl für Krb5_pa_data-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:42 -+msgid "Bad magic number for krb5_kdc_req structure" -+msgstr "falsche magische Zahl für Krb5_kdc_req-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:43 -+msgid "Bad magic number for krb5_enc_kdc_rep_part structure" -+msgstr "falsche magische Zahl für Krb5_enc_kdc_rep_part-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:44 -+msgid "Bad magic number for krb5_kdc_rep structure" -+msgstr "falsche magische Zahl für Krb5_kdc_rep-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:45 -+msgid "Bad magic number for krb5_error structure" -+msgstr "falsche magische Zahl für Krb5_error-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:46 -+msgid "Bad magic number for krb5_ap_req structure" -+msgstr "falsche magische Zahl für Krb5_ap_req-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:47 -+msgid "Bad magic number for krb5_ap_rep structure" -+msgstr "falsche magische Zahl für Krb5_ap_rep-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:48 -+msgid "Bad magic number for krb5_ap_rep_enc_part structure" -+msgstr "falsche magische Zahl für Krb5_ap_rep_enc_part-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:49 -+msgid "Bad magic number for krb5_response structure" -+msgstr "falsche magische Zahl für Krb5_response-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:50 -+msgid "Bad magic number for krb5_safe structure" -+msgstr "falsche magische Zahl für Krb5_safe-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:51 -+msgid "Bad magic number for krb5_priv structure" -+msgstr "falsche magische Zahl für Krb5_priv-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:52 -+msgid "Bad magic number for krb5_priv_enc_part structure" -+msgstr "falsche magische Zahl für Krb5_priv_enc_part-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:53 -+msgid "Bad magic number for krb5_cred structure" -+msgstr "falsche magische Zahl für Krb5_cred-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:54 -+msgid "Bad magic number for krb5_cred_info structure" -+msgstr "falsche magische Zahl für Krb5_cred_info-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:55 -+msgid "Bad magic number for krb5_cred_enc_part structure" -+msgstr "falsche magische Zahl für Krb5_cred_enc_part-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:56 -+msgid "Bad magic number for krb5_pwd_data structure" -+msgstr "falsche magische Zahl für Krb5_pwd_data-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:57 -+msgid "Bad magic number for krb5_address structure" -+msgstr "falsche magische Zahl für Krb5_address-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:58 -+msgid "Bad magic number for krb5_keytab_entry structure" -+msgstr "falsche magische Zahl für Krb5_keytab_entry-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:59 -+msgid "Bad magic number for krb5_context structure" -+msgstr "falsche magische Zahl für Krb5_context-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:60 -+msgid "Bad magic number for krb5_os_context structure" -+msgstr "falsche magische Zahl für Krb5_os_context-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:61 -+msgid "Bad magic number for krb5_alt_method structure" -+msgstr "falsche magische Zahl für Krb5_alt_method-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:62 -+msgid "Bad magic number for krb5_etype_info_entry structure" -+msgstr "falsche magische Zahl für Krb5_etype_info_entry-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:63 -+msgid "Bad magic number for krb5_db_context structure" -+msgstr "falsche magische Zahl für Krb5_db_context-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:64 -+msgid "Bad magic number for krb5_auth_context structure" -+msgstr "falsche magische Zahl für Krb5_auth_context-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:65 -+msgid "Bad magic number for krb5_keytab structure" -+msgstr "falsche magische Zahl für Krb5_keytab-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:66 -+msgid "Bad magic number for krb5_rcache structure" -+msgstr "falsche magische Zahl für Krb5_rcache-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:67 -+msgid "Bad magic number for krb5_ccache structure" -+msgstr "falsche magische Zahl für Krb5_ccache-Struktur" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:68 -+msgid "Bad magic number for krb5_preauth_ops" -+msgstr "falsche magische Zahl für Krb5_preauth_ops" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:69 -+msgid "Bad magic number for krb5_sam_challenge" -+msgstr "falsche magische Zahl für Krb5_sam_challenge" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:70 -+msgid "Bad magic number for krb5_sam_challenge_2" -+msgstr "falsche magische Zahl für Krb5_sam_challenge_2" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:71 -+msgid "Bad magic number for krb5_sam_key" -+msgstr "falsche magische Zahl für Krb5_sam_key" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:72 -+#: ../lib/krb5/error_tables/kv5m_err.c:73 -+msgid "Bad magic number for krb5_enc_sam_response_enc" -+msgstr "falsche magische Zahl für Krb5_enc_sam_response_enc" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:74 -+msgid "Bad magic number for krb5_sam_response" -+msgstr "falsche magische Zahl für Krb5_sam_response" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:75 -+msgid "Bad magic number for krb5_sam_response 2" -+msgstr "falsche magische Zahl für Krb5_sam_response 2" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:76 -+msgid "Bad magic number for krb5_predicted_sam_response" -+msgstr "falsche magische Zahl für Krb5_predicted_sam_response" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:77 -+msgid "Bad magic number for passwd_phrase_element" -+msgstr "falsche magische Zahl für Passwd_phrase_element" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:78 -+msgid "Bad magic number for GSSAPI OID" -+msgstr "falsche magische Zahl für GSSAPI OID" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:79 -+msgid "Bad magic number for GSSAPI QUEUE" -+msgstr "falsche magische Zahl für GSSAPI QUEUE" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:80 -+msgid "Bad magic number for fast armored request" -+msgstr "falsche magische Zahl für per FAST geschützte Anfrage" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:81 -+msgid "Bad magic number for FAST request" -+msgstr "falsche magische Zahl für FAST-Anfrage" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:82 -+msgid "Bad magic number for FAST response" -+msgstr "falsche magische Zahl für FAST-Antwort" -+ -+#: ../lib/krb5/error_tables/kv5m_err.c:83 -+msgid "Bad magic number for krb5_authdata_context" -+msgstr "falsche magische Zahl für Krb5_authdata_context" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:23 -+msgid "Cannot convert V5 keyblock" -+msgstr "V5-Schlüsselblock kann nicht umgewandelt werden" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:24 -+msgid "Cannot convert V5 address information" -+msgstr "V5-Adressinformationen können nicht umgewandelt werden" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:25 -+msgid "Cannot convert V5 principal" -+msgstr "V5-Principal kann nicht umgewandelt werden" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:26 -+msgid "V5 realm name longer than V4 maximum" -+msgstr "V5-Realm-Name ist länger als die V4-Maximallänge" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:27 -+msgid "Kerberos V4 error" -+msgstr "Kerberos-V4-Fehler" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:28 -+msgid "Encoding too large" -+msgstr "Kodierung zu lang" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:29 -+msgid "Decoding out of data" -+msgstr "Dekodieren außerhalb der Daten" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:30 -+msgid "Service not responding" -+msgstr "Dienst antwortet nicht" -+ -+#: ../lib/krb5/error_tables/krb524_err.c:31 -+msgid "Kerberos version 4 support is disabled" -+msgstr "Kerberos 4 Unterstützung ist deaktiviert" -+ -+#~ msgid "while creating server %s principal name" -+#~ msgstr "beim Erstellen des Principal-Namens für Server %s" -+ -+# KDC = Key Distribution Center -+#~ msgid "while getting credentials from kdc" -+#~ msgstr "beim Holen der Anmeldedaten vom KDC" -+ -+# FIXME s/Retrieving/retrieving/ -+#~ msgid "while Retrieving credentials" -+#~ msgstr "beim Abfragen der Anmeldedaten" -+ -+#~ msgid "while copying principal" -+#~ msgstr "beim Kopieren des Principals" -+ -+#~ msgid "%s does not have correct permissions for %s\n" -+#~ msgstr "%s hat nicht die erforderlichen Zugriffsrechte für %s\n" -+ -+#~ msgid "no salt\n" -+#~ msgstr "kein Salt\n" -+ -+#~ msgid "%s: Couldn't grab lock\n" -+#~ msgstr "%s: Es konnte keine Sperre erlangt werden.\n" -+ -+#~ msgid "%s: Loads disallowed when iprop is enabled and a ulog is present\n" -+#~ msgstr "" -+#~ "%s: Wenn Iprop aktiviert und Ulog vorhanden ist, ist Laden nicht " -+#~ "möglich.\n" -+ -+#~ msgid "trying to lock database" -+#~ msgstr "es wird versucht, die Datenbank zu sperren" -+ -+#~ msgid "GSS-API error %s: %s\n" -+#~ msgstr "GSS-API-Fehler %s: %s\n" -+ -+#~ msgid "Couldn't create KRB5 Name NameType OID\n" -+#~ msgstr "KRB5 Name NameType OID konnte nicht erstellt werden.\n" -+ -+#~ msgid "%s: %s while initializing, aborting" -+#~ msgstr "%s: %s beim Initialisieren, wird abgebrochen" -+ -+#~ msgid "" -+#~ "%s: Missing required configuration values (%lx) while initializing, " -+#~ "aborting" -+#~ msgstr "" -+#~ "%s: Beim Initialisieren fehlen die erforderlichen Konfigurationswerte " -+#~ "(%lx), wird abgebrochen" -+ -+#~ msgid "" -+#~ "%s: Missing required configuration values (%lx) while initializing, " -+#~ "aborting\n" -+#~ msgstr "" -+#~ "%s: Beim Initialisieren fehlen die erforderlichen Konfigurationswerte " -+#~ "(%lx), wird abgebrochen\n" -+ -+#~ msgid "%s: could not initialize loop, aborting" -+#~ msgstr "%s: Schleife konnte nicht initialisiert werden, wird abgebrochen" -+ -+#~ msgid "%s: could not initialize loop, aborting\n" -+#~ msgstr "%s: Schleife konnte nicht initialisiert werden, wird abgebrochen\n" -+ -+#~ msgid "%s: %s while initializing signal handlers, aborting" -+#~ msgstr "" -+#~ "%s: %s beim Initialisieren des Signalbehandlungsprogramms, wird " -+#~ "abgebrochen" -+ -+#~ msgid "%s: %s while initializing signal handlers, aborting\n" -+#~ msgstr "" -+#~ "%s: %s beim Initialisieren des Signalbehandlungsprogramms, wird " -+#~ "abgebrochen\n" -+ -+#~ msgid "%s: %s while initializing network, aborting" -+#~ msgstr "%s: %s beim Initialisieren des Netzwerks, wird abgebrochen" -+ -+#~ msgid "%s: %s while initializing network, aborting\n" -+#~ msgstr "%s: %s beim Initialisieren des Netzwerks, wird abgebrochen\n" -+ -+#~ msgid "Cannot build GSS-API authentication names, failing." -+#~ msgstr "" -+#~ "GSS-API-Authentifizierungsnamen können nicht gebildet werden, " -+#~ "fehlgeschlagen" -+ -+#~ msgid "Can't set kdb keytab's internal context." -+#~ msgstr "" -+#~ "Der interne Kontext von KDBs Schlüsseltabelle kann nicht gesetzt werden." -+ -+#~ msgid "Can't register kdb keytab." -+#~ msgstr "Die KDB-Schlüsseltabelle kann nicht registriert werden." -+ -+#~ msgid "Can't register acceptor keytab." -+#~ msgstr "Die Empfängerschlüsseltabelle kann nicht registriert werden." -+ -+#~ msgid "" -+#~ "Cannot set GSS-API authentication names (keytab not present?), failing." -+#~ msgstr "" -+#~ "GSS-API-Authentifizierungsnamen können nicht gesetzt werden " -+#~ "(Schlüsseltabelle nicht vorhanden?), fehlgeschlagen" -+ -+#~ msgid "Cannot initialize acl file: %s" -+#~ msgstr "ACL-Datei kann nicht initialisiert werden: %s" -+ -+#~ msgid "%s: Cannot initialize acl file: %s\n" -+#~ msgstr "%s: ACL-Datei kann nicht initialisiert werden: %s\n" -+ -+#~ msgid "Cannot detach from tty: %s" -+#~ msgstr "kann nicht vom Terminal gelöst werden: %s" -+ -+#~ msgid "Cannot create PID file %s: %s" -+#~ msgstr "PID-Datei %s kann nicht erstellt werden: %s" -+ -+#~ msgid "%s: %s while mapping update log (`%s.ulog')\n" -+#~ msgstr "%s: %s beim Abbilden des Aktualisierungsprotokolls (»%s.ulog«)\n" -+ -+#~ msgid "%s while mapping update log (`%s.ulog')" -+#~ msgstr "%s beim Abbilden des Aktualisierungsprotokolls (»%s.ulog«)" -+ -+#~ msgid "%s: Cannot create IProp RPC service (PROG=%d, VERS=%d)\n" -+#~ msgstr "" -+#~ "%s: IProp-RPC-Dienst kann nicht erstellt werden (PROG=%d, VERS=%d)\n" -+ -+#~ msgid "Cannot create IProp RPC service (PROG=%d, VERS=%d), failing." -+#~ msgstr "" -+#~ "IProp-RPC-Dienst kann nicht erstellt werden (PROG=%d, VERS=%d), " -+#~ "fehlgeschlagen" -+ -+#~ msgid "%s while getting IProp svc name, failing" -+#~ msgstr "%s beim Holen des IProp-Dienstnamens, fehlgeschlagen" -+ -+#~ msgid "%s: %s while getting IProp svc name, failing\n" -+#~ msgstr "%s: %s beim Holen des IProp-Dienstnamens, fehlgeschlagen\n" -+ -+#~ msgid "Unable to set RPCSEC_GSS service name (`%s'), failing." -+#~ msgstr "" -+#~ "der RPCSEC_GSS-Dienstname (»%s«) kann nicht gesetzt werden, fehlgeschlagen" -+ -+#~ msgid "%s: Unable to set RPCSEC_GSS service name (`%s'), failing.\n" -+#~ msgstr "" -+#~ "%s: der RPCSEC_GSS-Dienstname (»%s«) kann nicht gesetzt werden, " -+#~ "fehlgeschlagen\n" -+ -+#~ msgid "GSS-API authentication error %.*s: recursive failure!" -+#~ msgstr "GSS-API-Authentifizierungsfehler %.*s: rekursiver Fehlschlag!" -+ -+#~ msgid "skipping unrecognized local address family %d" -+#~ msgstr "nicht erkannte lokale Adressfamilie %d wird übersprungen" -+ -+#~ msgid "got routing msg type %d(%s) v%d" -+#~ msgstr "Routing-Meldungstyp %d(%s) v%d erhalten" -+ -+#~ msgid "Could not create temp stash file: %s" -+#~ msgstr "Temporäre Ablagedatei konnte nicht erstellt werden: %s" -+ -+#~ msgid "ulog_sync_header: could not sync to disk" -+#~ msgstr "ulog_sync_header: kann nicht auf Platte sychronisiert werden" -+ -+#~ msgid "%s: attempt to convert non-extended krb5_get_init_creds_opt" -+#~ msgstr "" -+#~ "%s: Es wird versucht, nicht erweiterte »krb5_get_init_creds_opt« " -+#~ "umzuwandeln" -+ -+#~ msgid "krb5_sname_to_principal, while adding entries to the database" -+#~ msgstr "" -+#~ "»krb5_sname_to_principal« beim Hinzufügen von Einträgen zur Datenbank" -+ -+#~ msgid "krb5_copy_principal, while adding entries to the database" -+#~ msgstr "»krb5_copy_principal« beim Hinzufügen von Einträgen zur Datenbank" -+ -+#~ msgid "" -+#~ "Unable to check if SASL EXTERNAL mechanism is supported by LDAP server. " -+#~ "Proceeding anyway ..." -+#~ msgstr "" -+#~ "Es konnte nicht geprüft werden, ob der Mechanismus SASL EXTERNAL vom LDAP-" -+#~ "Server unterstützt wird. Es wird trotzdem fortgesetzt …" -+ -+#~ msgid "" -+#~ "SASL EXTERNAL mechanism not supported by LDAP server. Can't perform " -+#~ "certificate-based bind." -+#~ msgstr "" -+#~ "Der Mechanismus SASL EXTERNAL wird nicht vom LDAP-Server unterstützt. Es " -+#~ "kann keine zertifikatbasierte Verbindung hergestellt werden." -+ -+#~ msgid "Error reading 'ldap_servers' attribute" -+#~ msgstr "Fehler beim Lesen des Attributs »ldap_servers«" -+ -+#~ msgid "Stash file entry corrupt" -+#~ msgstr "Eintrag in der Ablagedatei beschädigt" -+ -+#~ msgid "while setting server principal realm" -+#~ msgstr "beim Setzen des Server-Principal-Realms" -+ -+#~ msgid "while getting initial ticket\n" -+#~ msgstr "beim Holen eines Anfangs-Tickets\n" -+ -+#~ msgid "while destroying ticket cache" -+#~ msgstr "beim Zerstören des Ticket-Zwischenspeichers" -+ -+#~ msgid "while closing default ccache" -+#~ msgstr "beim Schließen des Standard-Ccaches" diff --git a/Add-KDC-policy-pluggable-interface.patch b/Add-KDC-policy-pluggable-interface.patch deleted file mode 100644 index a5e029e..0000000 --- a/Add-KDC-policy-pluggable-interface.patch +++ /dev/null @@ -1,994 +0,0 @@ -From 78a1f155701f94a228c4f58f98846195a39991c4 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 27 Jun 2017 17:15:39 -0400 -Subject: [PATCH] Add KDC policy pluggable interface - -Add the header include/krb5/kdcpolicy_plugin.h, defining a pluggable -interface for modules to deny AS and TGS requests and set maximum -ticket lifetimes. This interface replaces the policy.c stub functions. - -Add check_kdcpolicy_as() and check_kdcpolicy_tgs() as entry functions. -Call them after auth indicators and ticket lifetimes have been -determined. - -Add a test module and a test script with basic kdcpolicy tests. Add -plugin interface documentation in doc/plugindev/policy.rst. - -Also authored by Matt Rogers . - -ticket: 8606 (new) -(cherry picked from commit d0969f6a8170344031ef58fd2a161190f1edfb96) -[rharwood@redhat.com: mention but do not use kadm_auth] ---- - doc/plugindev/index.rst | 1 + - doc/plugindev/kdcpolicy.rst | 24 +++ - src/Makefile.in | 1 + - src/configure.in | 1 + - src/include/Makefile.in | 1 + - src/include/k5-int.h | 4 +- - src/include/k5-trace.h | 5 + - src/include/krb5/kdcpolicy_plugin.h | 128 ++++++++++++ - src/kdc/do_as_req.c | 7 + - src/kdc/do_tgs_req.c | 6 + - src/kdc/kdc_util.c | 7 - - src/kdc/kdc_util.h | 11 - - src/kdc/main.c | 8 + - src/kdc/policy.c | 267 +++++++++++++++++++++---- - src/kdc/policy.h | 19 +- - src/kdc/tgs_policy.c | 6 - - src/lib/krb5/krb/plugin.c | 4 +- - src/plugins/kdcpolicy/test/Makefile.in | 20 ++ - src/plugins/kdcpolicy/test/deps | 0 - src/plugins/kdcpolicy/test/main.c | 111 ++++++++++ - src/plugins/kdcpolicy/test/policy_test.exports | 1 + - src/tests/Makefile.in | 1 + - src/tests/t_kdcpolicy.py | 57 ++++++ - 23 files changed, 616 insertions(+), 74 deletions(-) - create mode 100644 doc/plugindev/kdcpolicy.rst - create mode 100644 src/include/krb5/kdcpolicy_plugin.h - create mode 100644 src/plugins/kdcpolicy/test/Makefile.in - create mode 100644 src/plugins/kdcpolicy/test/deps - create mode 100644 src/plugins/kdcpolicy/test/main.c - create mode 100644 src/plugins/kdcpolicy/test/policy_test.exports - create mode 100644 src/tests/t_kdcpolicy.py - -diff --git a/doc/plugindev/index.rst b/doc/plugindev/index.rst -index 67dbc2790..0a012b82b 100644 ---- a/doc/plugindev/index.rst -+++ b/doc/plugindev/index.rst -@@ -32,5 +32,6 @@ Contents - gssapi.rst - internal.rst - certauth.rst -+ kdcpolicy.rst - - .. TODO: GSSAPI mechanism plugins -diff --git a/doc/plugindev/kdcpolicy.rst b/doc/plugindev/kdcpolicy.rst -new file mode 100644 -index 000000000..74f21f08f ---- /dev/null -+++ b/doc/plugindev/kdcpolicy.rst -@@ -0,0 +1,24 @@ -+.. _kdcpolicy_plugin: -+ -+KDC policy interface (kdcpolicy) -+================================ -+ -+The kdcpolicy interface was first introduced in release 1.16. It -+allows modules to veto otherwise valid AS and TGS requests or restrict -+the lifetime and renew time of the resulting ticket. For a detailed -+description of the kdcpolicy interface, see the header file -+````. -+ -+The optional **check_as** and **check_tgs** functions allow the module -+to perform access control. Additionally, a module can create and -+destroy module data with the **init** and **fini** methods. Module -+data objects last for the lifetime of the KDC process, and are -+provided to all other methods. The data has the type -+krb5_kdcpolicy_moddata, which should be cast to the appropriate -+internal type. -+ -+kdcpolicy modules can optionally inspect principal entries. To do -+this, the module must also include ```` to gain access to the -+principal entry structure definition. As the KDB interface is -+explicitly not as stable as other public interfaces, modules which do -+this may not retain compatibility across releases. -diff --git a/src/Makefile.in b/src/Makefile.in -index ad8565056..e47bddcb1 100644 ---- a/src/Makefile.in -+++ b/src/Makefile.in -@@ -21,6 +21,7 @@ SUBDIRS=util include lib \ - plugins/kdb/db2 \ - @ldap_plugin_dir@ \ - plugins/kdb/test \ -+ plugins/kdcpolicy/test \ - plugins/preauth/otp \ - plugins/preauth/pkinit \ - plugins/preauth/test \ -diff --git a/src/configure.in b/src/configure.in -index 4ae2c07d5..ee1983043 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -1470,6 +1470,7 @@ dnl ccapi ccapi/lib ccapi/lib/unix ccapi/server ccapi/server/unix ccapi/test - plugins/kdb/db2/libdb2/recno - plugins/kdb/db2/libdb2/test - plugins/kdb/test -+ plugins/kdcpolicy/test - plugins/preauth/otp - plugins/preauth/test - plugins/authdata/greet_client -diff --git a/src/include/Makefile.in b/src/include/Makefile.in -index 0239338a1..6a3fa8242 100644 ---- a/src/include/Makefile.in -+++ b/src/include/Makefile.in -@@ -144,6 +144,7 @@ install-headers-unix install: krb5/krb5.h profile.h - $(INSTALL_DATA) $(srcdir)/krb5/ccselect_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)ccselect_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/clpreauth_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)clpreauth_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/hostrealm_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)hostrealm_plugin.h -+ $(INSTALL_DATA) $(srcdir)/krb5/kdcpolicy_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)kdcpolicy_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/kdcpreauth_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)kdcpreauth_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/localauth_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)localauth_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/locate_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)locate_plugin.h -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index ed9c7bf75..39ffb9568 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -1157,7 +1157,9 @@ struct plugin_interface { - #define PLUGIN_INTERFACE_TLS 8 - #define PLUGIN_INTERFACE_KDCAUTHDATA 9 - #define PLUGIN_INTERFACE_CERTAUTH 10 --#define PLUGIN_NUM_INTERFACES 11 -+#define PLUGIN_INTERFACE_KADM5_AUTH 11 -+#define PLUGIN_INTERFACE_KDCPOLICY 12 -+#define PLUGIN_NUM_INTERFACES 13 - - /* Retrieve the plugin module of type interface_id and name modname, - * storing the result into module. */ -diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h -index c75e264e0..2885408a2 100644 ---- a/src/include/k5-trace.h -+++ b/src/include/k5-trace.h -@@ -454,4 +454,9 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); - #define TRACE_GET_CRED_VIA_TKT_EXT_RETURN(c, ret) \ - TRACE(c, "Got cred; {kerr}", ret) - -+#define TRACE_KDCPOLICY_VTINIT_FAIL(c, ret) \ -+ TRACE(c, "KDC policy module failed to init vtable: {kerr}", ret) -+#define TRACE_KDCPOLICY_INIT_SKIP(c, name) \ -+ TRACE(c, "kadm5_auth module {str} declined to initialize", name) -+ - #endif /* K5_TRACE_H */ -diff --git a/src/include/krb5/kdcpolicy_plugin.h b/src/include/krb5/kdcpolicy_plugin.h -new file mode 100644 -index 000000000..c7592c5db ---- /dev/null -+++ b/src/include/krb5/kdcpolicy_plugin.h -@@ -0,0 +1,128 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* include/krb5/kdcpolicy_plugin.h - KDC policy plugin interface */ -+/* -+ * Copyright (C) 2017 by Red Hat, Inc. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+/* -+ * Declarations for kdcpolicy plugin module implementors. -+ * -+ * The kdcpolicy pluggable interface currently has only one supported major -+ * version, which is 1. Major version 1 has a current minor version number of -+ * 1. -+ * -+ * kdcpolicy plugin modules should define a function named -+ * kdcpolicy__initvt, matching the signature: -+ * -+ * krb5_error_code -+ * kdcpolicy_modname_initvt(krb5_context context, int maj_ver, int min_ver, -+ * krb5_plugin_vtable vtable); -+ * -+ * The initvt function should: -+ * -+ * - Check that the supplied maj_ver number is supported by the module, or -+ * return KRB5_PLUGIN_VER_NOTSUPP if it is not. -+ * -+ * - Cast the vtable pointer as appropriate for maj_ver: -+ * maj_ver == 1: Cast to krb5_kdcpolicy_vtable -+ * -+ * - Initialize the methods of the vtable, stopping as appropriate for the -+ * supplied min_ver. Optional methods may be left uninitialized. -+ * -+ * Memory for the vtable is allocated by the caller, not by the module. -+ */ -+ -+#ifndef KRB5_POLICY_PLUGIN_H -+#define KRB5_POLICY_PLUGIN_H -+ -+#include -+ -+/* Abstract module datatype. */ -+typedef struct krb5_kdcpolicy_moddata_st *krb5_kdcpolicy_moddata; -+ -+/* A module can optionally include kdb.h to inspect principal entries when -+ * authorizing requests. */ -+struct _krb5_db_entry_new; -+ -+/* -+ * Optional: Initialize module data. Return 0 on success, -+ * KRB5_PLUGIN_NO_HANDLE if the module is inoperable (due to configuration, for -+ * example), and any other error code to abort KDC startup. Optionally set -+ * *data_out to a module data object to be passed to future calls. -+ */ -+typedef krb5_error_code -+(*krb5_kdcpolicy_init_fn)(krb5_context context, -+ krb5_kdcpolicy_moddata *data_out); -+ -+/* Optional: Clean up module data. */ -+typedef krb5_error_code -+(*krb5_kdcpolicy_fini_fn)(krb5_context context, -+ krb5_kdcpolicy_moddata moddata); -+ -+/* -+ * Optional: return an error code and set status to an appropriate string -+ * literal to deny an AS request; otherwise return 0. lifetime_out, if set, -+ * restricts the ticket lifetime. renew_lifetime_out, if set, restricts the -+ * ticket renewable lifetime. -+ */ -+typedef krb5_error_code -+(*krb5_kdcpolicy_check_as_fn)(krb5_context context, -+ krb5_kdcpolicy_moddata moddata, -+ const krb5_kdc_req *request, -+ const struct _krb5_db_entry_new *client, -+ const struct _krb5_db_entry_new *server, -+ const char *const *auth_indicators, -+ const char **status, krb5_deltat *lifetime_out, -+ krb5_deltat *renew_lifetime_out); -+ -+/* -+ * Optional: return an error code and set status to an appropriate string -+ * literal to deny a TGS request; otherwise return 0. lifetime_out, if set, -+ * restricts the ticket lifetime. renew_lifetime_out, if set, restricts the -+ * ticket renewable lifetime. -+ */ -+typedef krb5_error_code -+(*krb5_kdcpolicy_check_tgs_fn)(krb5_context context, -+ krb5_kdcpolicy_moddata moddata, -+ const krb5_kdc_req *request, -+ const struct _krb5_db_entry_new *server, -+ const krb5_ticket *ticket, -+ const char *const *auth_indicators, -+ const char **status, krb5_deltat *lifetime_out, -+ krb5_deltat *renew_lifetime_out); -+ -+typedef struct krb5_kdcpolicy_vtable_st { -+ const char *name; -+ krb5_kdcpolicy_init_fn init; -+ krb5_kdcpolicy_fini_fn fini; -+ krb5_kdcpolicy_check_as_fn check_as; -+ krb5_kdcpolicy_check_tgs_fn check_tgs; -+} *krb5_kdcpolicy_vtable; -+ -+#endif /* KRB5_POLICY_PLUGIN_H */ -diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c -index f85da6da6..f5cf8ad89 100644 ---- a/src/kdc/do_as_req.c -+++ b/src/kdc/do_as_req.c -@@ -207,6 +207,13 @@ finish_process_as_req(struct as_req_state *state, krb5_error_code errcode) - - state->ticket_reply.enc_part2 = &state->enc_tkt_reply; - -+ errcode = check_kdcpolicy_as(kdc_context, state->request, state->client, -+ state->server, state->auth_indicators, -+ state->kdc_time, &state->enc_tkt_reply.times, -+ &state->status); -+ if (errcode) -+ goto egress; -+ - /* - * Find the server key - */ -diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c -index ac5864603..0009a9319 100644 ---- a/src/kdc/do_tgs_req.c -+++ b/src/kdc/do_tgs_req.c -@@ -518,6 +518,12 @@ process_tgs_req(struct server_handle *handle, krb5_data *pkt, - kdc_get_ticket_renewtime(kdc_active_realm, request, header_enc_tkt, client, - server, &enc_tkt_reply); - -+ errcode = check_kdcpolicy_tgs(kdc_context, request, server, header_ticket, -+ auth_indicators, kdc_time, -+ &enc_tkt_reply.times, &status); -+ if (errcode) -+ goto cleanup; -+ - /* - * Set authtime to be the same as header or evidence ticket's - */ -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index b710aefe4..5455e2a67 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -642,7 +642,6 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - krb5_db_entry server, krb5_timestamp kdc_time, - const char **status, krb5_pa_data ***e_data) - { -- int errcode; - krb5_error_code ret; - - /* -@@ -750,12 +749,6 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - if (ret && ret != KRB5_PLUGIN_OP_NOTSUPP) - return errcode_to_protocol(ret); - -- /* Check against local policy. */ -- errcode = against_local_policy_as(request, client, server, -- kdc_time, status, e_data); -- if (errcode) -- return errcode; -- - return 0; - } - -diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index 672f94380..dcedfd538 100644 ---- a/src/kdc/kdc_util.h -+++ b/src/kdc/kdc_util.h -@@ -166,17 +166,6 @@ kdc_err(krb5_context call_context, errcode_t code, const char *fmt, ...) - #endif - ; - --/* policy.c */ --int --against_local_policy_as (krb5_kdc_req *, krb5_db_entry, -- krb5_db_entry, krb5_timestamp, -- const char **, krb5_pa_data ***); -- --int --against_local_policy_tgs (krb5_kdc_req *, krb5_db_entry, -- krb5_ticket *, const char **, -- krb5_pa_data ***); -- - /* kdc_preauth.c */ - krb5_boolean - enctype_requires_etype_info_2(krb5_enctype enctype); -diff --git a/src/kdc/main.c b/src/kdc/main.c -index a4dffb29a..ccac3a759 100644 ---- a/src/kdc/main.c -+++ b/src/kdc/main.c -@@ -31,6 +31,7 @@ - #include "kdc_util.h" - #include "kdc_audit.h" - #include "extern.h" -+#include "policy.h" - #include "kdc5_err.h" - #include "kdb_kt.h" - #include "net-server.h" -@@ -986,6 +987,12 @@ int main(int argc, char **argv) - - load_preauth_plugins(&shandle, kcontext, ctx); - load_authdata_plugins(kcontext); -+ retval = load_kdcpolicy_plugins(kcontext); -+ if (retval) { -+ kdc_err(kcontext, retval, _("while loading KDC policy plugin")); -+ finish_realms(); -+ return 1; -+ } - - retval = setup_sam(); - if (retval) { -@@ -1068,6 +1075,7 @@ int main(int argc, char **argv) - krb5_klog_syslog(LOG_INFO, _("shutting down")); - unload_preauth_plugins(kcontext); - unload_authdata_plugins(kcontext); -+ unload_kdcpolicy_plugins(kcontext); - unload_audit_modules(kcontext); - krb5_klog_close(kcontext); - finish_realms(); -diff --git a/src/kdc/policy.c b/src/kdc/policy.c -index 6cba4303f..e49644e06 100644 ---- a/src/kdc/policy.c -+++ b/src/kdc/policy.c -@@ -1,67 +1,246 @@ - /* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ - /* kdc/policy.c - Policy decision routines for KDC */ - /* -- * Copyright 1990 by the Massachusetts Institute of Technology. -+ * Copyright (C) 2017 by Red Hat, Inc. -+ * All rights reserved. - * -- * Export of this software from the United States of America may -- * require a specific license from the United States Government. -- * It is the responsibility of any person or organization contemplating -- * export to obtain such a license before exporting. -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: - * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of M.I.T. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. Furthermore if you modify this software you must label -- * your software as modified software and not distribute it in such a -- * fashion that it might be confused with the original M.I.T. software. -- * M.I.T. makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. - */ - - #include "k5-int.h" - #include "kdc_util.h" - #include "extern.h" -+#include "policy.h" -+#include "adm_proto.h" -+#include -+#include - --int --against_local_policy_as(register krb5_kdc_req *request, krb5_db_entry client, -- krb5_db_entry server, krb5_timestamp kdc_time, -- const char **status, krb5_pa_data ***e_data) -+typedef struct kdcpolicy_handle_st { -+ struct krb5_kdcpolicy_vtable_st vt; -+ krb5_kdcpolicy_moddata moddata; -+} *kdcpolicy_handle; -+ -+static kdcpolicy_handle *handles; -+ -+static void -+free_indicators(char **ais) - { --#if 0 -- /* An AS request must include the addresses field */ -- if (request->addresses == 0) { -- *status = "NO ADDRESS"; -- return KRB5KDC_ERR_POLICY; -- } --#endif -+ size_t i; - -- return 0; /* not against policy */ -+ if (ais == NULL) -+ return; -+ for (i = 0; ais[i] != NULL; i++) -+ free(ais[i]); -+ free(ais); -+} -+ -+/* Convert inds to a null-terminated list of C strings. */ -+static krb5_error_code -+authind_strings(krb5_data *const *inds, char ***strs_out) -+{ -+ krb5_error_code ret; -+ char **list = NULL; -+ size_t i, count; -+ -+ *strs_out = NULL; -+ -+ for (count = 0; inds != NULL && inds[count] != NULL; count++); -+ list = k5calloc(count + 1, sizeof(*list), &ret); -+ if (list == NULL) -+ goto error; -+ -+ for (i = 0; i < count; i++) { -+ list[i] = k5memdup0(inds[i]->data, inds[i]->length, &ret); -+ if (list[i] == NULL) -+ goto error; -+ } -+ -+ *strs_out = list; -+ return 0; -+ -+error: -+ free_indicators(list); -+ return ret; -+} -+ -+/* Constrain times->endtime to life and times->renew_till to rlife, relative to -+ * now. */ -+static void -+update_ticket_times(krb5_ticket_times *times, krb5_timestamp now, -+ krb5_deltat life, krb5_deltat rlife) -+{ -+ if (life) -+ times->endtime = ts_min(ts_incr(now, life), times->endtime); -+ if (rlife) -+ times->renew_till = ts_min(ts_incr(now, rlife), times->renew_till); -+} -+ -+/* Check an AS request against kdcpolicy modules, updating times with any -+ * module endtime constraints. Set an appropriate status string on error. */ -+krb5_error_code -+check_kdcpolicy_as(krb5_context context, const krb5_kdc_req *request, -+ const krb5_db_entry *client, const krb5_db_entry *server, -+ krb5_data *const *auth_indicators, krb5_timestamp kdc_time, -+ krb5_ticket_times *times, const char **status) -+{ -+ krb5_deltat life, rlife; -+ krb5_error_code ret; -+ kdcpolicy_handle *hp, h; -+ char **ais = NULL; -+ -+ *status = NULL; -+ -+ ret = authind_strings(auth_indicators, &ais); -+ if (ret) -+ goto done; -+ -+ for (hp = handles; *hp != NULL; hp++) { -+ h = *hp; -+ if (h->vt.check_as == NULL) -+ continue; -+ -+ ret = h->vt.check_as(context, h->moddata, request, client, server, -+ (const char **)ais, status, &life, &rlife); -+ if (ret) -+ goto done; -+ -+ update_ticket_times(times, kdc_time, life, rlife); -+ } -+ -+done: -+ free_indicators(ais); -+ return ret; - } - - /* -- * This is where local policy restrictions for the TGS should placed. -+ * Check the TGS request against the local TGS policy. Accepts an -+ * authentication indicator for the module policy decisions. Returns 0 and a -+ * NULL status string on success. - */ - krb5_error_code --against_local_policy_tgs(register krb5_kdc_req *request, krb5_db_entry server, -- krb5_ticket *ticket, const char **status, -- krb5_pa_data ***e_data) -+check_kdcpolicy_tgs(krb5_context context, const krb5_kdc_req *request, -+ const krb5_db_entry *server, const krb5_ticket *ticket, -+ krb5_data *const *auth_indicators, krb5_timestamp kdc_time, -+ krb5_ticket_times *times, const char **status) - { --#if 0 -- /* -- * For example, if your site wants to disallow ticket forwarding, -- * you might do something like this: -- */ -+ krb5_deltat life, rlife; -+ krb5_error_code ret; -+ kdcpolicy_handle *hp, h; -+ char **ais = NULL; - -- if (isflagset(request->kdc_options, KDC_OPT_FORWARDED)) { -- *status = "FORWARD POLICY"; -- return KRB5KDC_ERR_POLICY; -+ *status = NULL; -+ -+ ret = authind_strings(auth_indicators, &ais); -+ if (ret) -+ goto done; -+ -+ for (hp = handles; *hp != NULL; hp++) { -+ h = *hp; -+ if (h->vt.check_tgs == NULL) -+ continue; -+ -+ ret = h->vt.check_tgs(context, h->moddata, request, server, ticket, -+ (const char **)ais, status, &life, &rlife); -+ if (ret) -+ goto done; -+ -+ update_ticket_times(times, kdc_time, life, rlife); - } --#endif - -- return 0; /* not against policy */ -+done: -+ free_indicators(ais); -+ return ret; -+} -+ -+void -+unload_kdcpolicy_plugins(krb5_context context) -+{ -+ kdcpolicy_handle *hp, h; -+ -+ for (hp = handles; *hp != NULL; hp++) { -+ h = *hp; -+ if (h->vt.fini != NULL) -+ h->vt.fini(context, h->moddata); -+ free(h); -+ } -+ free(handles); -+ handles = NULL; -+} -+ -+krb5_error_code -+load_kdcpolicy_plugins(krb5_context context) -+{ -+ krb5_error_code ret; -+ krb5_plugin_initvt_fn *modules = NULL, *mod; -+ kdcpolicy_handle h; -+ size_t count; -+ -+ ret = k5_plugin_load_all(context, PLUGIN_INTERFACE_KDCPOLICY, &modules); -+ if (ret) -+ goto cleanup; -+ -+ for (count = 0; modules[count] != NULL; count++); -+ handles = k5calloc(count + 1, sizeof(*handles), &ret); -+ if (handles == NULL) -+ goto cleanup; -+ -+ count = 0; -+ for (mod = modules; *mod != NULL; mod++) { -+ h = k5calloc(1, sizeof(*h), &ret); -+ if (h == NULL) -+ goto cleanup; -+ -+ ret = (*mod)(context, 1, 1, (krb5_plugin_vtable)&h->vt); -+ if (ret) { /* Version mismatch. */ -+ TRACE_KDCPOLICY_VTINIT_FAIL(context, ret); -+ free(h); -+ continue; -+ } -+ if (h->vt.init != NULL) { -+ ret = h->vt.init(context, &h->moddata); -+ if (ret == KRB5_PLUGIN_NO_HANDLE) { -+ TRACE_KADM5_AUTH_INIT_SKIP(context, h->vt.name); -+ free(h); -+ continue; -+ } -+ if (ret) { -+ kdc_err(context, ret, _("while loading policy module %s"), -+ h->vt.name); -+ free(h); -+ goto cleanup; -+ } -+ } -+ handles[count++] = h; -+ } -+ -+ ret = 0; -+ -+cleanup: -+ if (ret) -+ unload_kdcpolicy_plugins(context); -+ k5_plugin_free_modules(context, modules); -+ return ret; - } -diff --git a/src/kdc/policy.h b/src/kdc/policy.h -index 6b000dc90..2a57b0a01 100644 ---- a/src/kdc/policy.h -+++ b/src/kdc/policy.h -@@ -26,11 +26,22 @@ - #ifndef __KRB5_KDC_POLICY__ - #define __KRB5_KDC_POLICY__ - --extern int against_postdate_policy (krb5_timestamp); -+krb5_error_code -+load_kdcpolicy_plugins(krb5_context context); - --extern int against_flag_policy_as (const krb5_kdc_req *); -+void -+unload_kdcpolicy_plugins(krb5_context context); - --extern int against_flag_policy_tgs (const krb5_kdc_req *, -- const krb5_ticket *); -+krb5_error_code -+check_kdcpolicy_as(krb5_context context, const krb5_kdc_req *request, -+ const krb5_db_entry *client, const krb5_db_entry *server, -+ krb5_data *const *auth_indicators, krb5_timestamp kdc_time, -+ krb5_ticket_times *times, const char **status); -+ -+krb5_error_code -+check_kdcpolicy_tgs(krb5_context context, const krb5_kdc_req *request, -+ const krb5_db_entry *server, const krb5_ticket *ticket, -+ krb5_data *const *auth_indicators, krb5_timestamp kdc_time, -+ krb5_ticket_times *times, const char **status); - - #endif /* __KRB5_KDC_POLICY__ */ -diff --git a/src/kdc/tgs_policy.c b/src/kdc/tgs_policy.c -index d0f25d1b7..33cfbcd81 100644 ---- a/src/kdc/tgs_policy.c -+++ b/src/kdc/tgs_policy.c -@@ -375,11 +375,5 @@ validate_tgs_request(kdc_realm_t *kdc_active_realm, - if (ret && ret != KRB5_PLUGIN_OP_NOTSUPP) - return errcode_to_protocol(ret); - -- /* Check local policy. */ -- errcode = against_local_policy_tgs(request, server, ticket, -- status, e_data); -- if (errcode) -- return errcode; -- - return 0; - } -diff --git a/src/lib/krb5/krb/plugin.c b/src/lib/krb5/krb/plugin.c -index 17dd6bd30..31aaf661d 100644 ---- a/src/lib/krb5/krb/plugin.c -+++ b/src/lib/krb5/krb/plugin.c -@@ -58,7 +58,9 @@ const char *interface_names[] = { - "audit", - "tls", - "kdcauthdata", -- "certauth" -+ "certauth", -+ "kadm5_auth", -+ "kdcpolicy", - }; - - /* Return the context's interface structure for id, or NULL if invalid. */ -diff --git a/src/plugins/kdcpolicy/test/Makefile.in b/src/plugins/kdcpolicy/test/Makefile.in -new file mode 100644 -index 000000000..b81f1a7ce ---- /dev/null -+++ b/src/plugins/kdcpolicy/test/Makefile.in -@@ -0,0 +1,20 @@ -+mydir=plugins$(S)policy$(S)test -+BUILDTOP=$(REL)..$(S)..$(S).. -+ -+LIBBASE=policy_test -+LIBMAJOR=0 -+LIBMINOR=0 -+RELDIR=../plugins/kdcpolicy/test -+SHLIB_EXPDEPS=$(KRB5_BASE_DEPLIBS) -+SHLIB_EXPLIBS=$(KRB5_BASE_LIBS) -+ -+STLIBOBJS=main.o -+ -+SRCS=$(srcdir)/main.c -+ -+all-unix: all-libs -+install-unix: -+clean-unix:: clean-libs clean-libobjs -+ -+@libnover_frag@ -+@libobj_frag@ -diff --git a/src/plugins/kdcpolicy/test/deps b/src/plugins/kdcpolicy/test/deps -new file mode 100644 -index 000000000..e69de29bb -diff --git a/src/plugins/kdcpolicy/test/main.c b/src/plugins/kdcpolicy/test/main.c -new file mode 100644 -index 000000000..eb8fde053 ---- /dev/null -+++ b/src/plugins/kdcpolicy/test/main.c -@@ -0,0 +1,111 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* include/krb5/kdcpolicy_plugin.h - KDC policy plugin interface */ -+/* -+ * Copyright (C) 2017 by Red Hat, Inc. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include "k5-int.h" -+#include "kdb.h" -+#include -+ -+static krb5_error_code -+output_from_indicator(const char *const *auth_indicators, -+ krb5_deltat *lifetime_out, -+ krb5_deltat *renew_lifetime_out, -+ const char **status) -+{ -+ if (auth_indicators[0] == NULL) { -+ *status = NULL; -+ return 0; -+ } -+ -+ if (strcmp(auth_indicators[0], "ONE_HOUR") == 0) { -+ *lifetime_out = 3600; -+ *renew_lifetime_out = *lifetime_out * 2; -+ return 0; -+ } else if (strcmp(auth_indicators[0], "SEVEN_HOURS") == 0) { -+ *lifetime_out = 7 * 3600; -+ *renew_lifetime_out = *lifetime_out * 2; -+ return 0; -+ } -+ -+ *status = "LOCAL_POLICY"; -+ return KRB5KDC_ERR_POLICY; -+} -+ -+static krb5_error_code -+test_check_as(krb5_context context, krb5_kdcpolicy_moddata moddata, -+ const krb5_kdc_req *request, const krb5_db_entry *client, -+ const krb5_db_entry *server, const char *const *auth_indicators, -+ const char **status, krb5_deltat *lifetime_out, -+ krb5_deltat *renew_lifetime_out) -+{ -+ if (request->client != NULL && request->client->length >= 1 && -+ data_eq_string(request->client->data[0], "fail")) { -+ *status = "LOCAL_POLICY"; -+ return KRB5KDC_ERR_POLICY; -+ } -+ return output_from_indicator(auth_indicators, lifetime_out, -+ renew_lifetime_out, status); -+} -+ -+static krb5_error_code -+test_check_tgs(krb5_context context, krb5_kdcpolicy_moddata moddata, -+ const krb5_kdc_req *request, const krb5_db_entry *server, -+ const krb5_ticket *ticket, const char *const *auth_indicators, -+ const char **status, krb5_deltat *lifetime_out, -+ krb5_deltat *renew_lifetime_out) -+{ -+ if (request->server != NULL && request->server->length >= 1 && -+ data_eq_string(request->server->data[0], "fail")) { -+ *status = "LOCAL_POLICY"; -+ return KRB5KDC_ERR_POLICY; -+ } -+ return output_from_indicator(auth_indicators, lifetime_out, -+ renew_lifetime_out, status); -+} -+ -+krb5_error_code -+kdcpolicy_test_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable); -+krb5_error_code -+kdcpolicy_test_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable) -+{ -+ krb5_kdcpolicy_vtable vt; -+ -+ if (maj_ver != 1) -+ return KRB5_PLUGIN_VER_NOTSUPP; -+ -+ vt = (krb5_kdcpolicy_vtable)vtable; -+ vt->name = "test"; -+ vt->check_as = test_check_as; -+ vt->check_tgs = test_check_tgs; -+ return 0; -+} -diff --git a/src/plugins/kdcpolicy/test/policy_test.exports b/src/plugins/kdcpolicy/test/policy_test.exports -new file mode 100644 -index 000000000..9682ec74f ---- /dev/null -+++ b/src/plugins/kdcpolicy/test/policy_test.exports -@@ -0,0 +1 @@ -+kdcpolicy_test_initvt -diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in -index 2b3112537..a2093108b 100644 ---- a/src/tests/Makefile.in -+++ b/src/tests/Makefile.in -@@ -169,6 +169,7 @@ check-pytests: localauth plugorder rdreq responder s2p s4u2proxy unlockiter - $(RUNPYTEST) $(srcdir)/t_tabdump.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_certauth.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_y2038.py $(PYTESTFLAGS) -+ $(RUNPYTEST) $(srcdir)/t_kdcpolicy.py $(PYTESTFLAGS) - - clean: - $(RM) adata etinfo forward gcred hist hooks hrealm icred kdbtest -diff --git a/src/tests/t_kdcpolicy.py b/src/tests/t_kdcpolicy.py -new file mode 100644 -index 000000000..6a745b959 ---- /dev/null -+++ b/src/tests/t_kdcpolicy.py -@@ -0,0 +1,57 @@ -+#!/usr/bin/python -+from k5test import * -+from datetime import datetime -+import re -+ -+testpreauth = os.path.join(buildtop, 'plugins', 'preauth', 'test', 'test.so') -+testpolicy = os.path.join(buildtop, 'plugins', 'kdcpolicy', 'test', -+ 'policy_test.so') -+krb5_conf = {'plugins': {'kdcpreauth': {'module': 'test:' + testpreauth}, -+ 'clpreauth': {'module': 'test:' + testpreauth}, -+ 'kdcpolicy': {'module': 'test:' + testpolicy}}} -+kdc_conf = {'realms': {'$realm': {'default_principal_flags': '+preauth', -+ 'max_renewable_life': '1d'}}} -+realm = K5Realm(krb5_conf=krb5_conf, kdc_conf=kdc_conf) -+ -+realm.run([kadminl, 'addprinc', '-pw', password('fail'), 'fail']) -+ -+def verify_time(out, target_time): -+ times = re.findall(r'\d\d/\d\d/\d\d \d\d:\d\d:\d\d', out) -+ times = [datetime.strptime(t, '%m/%d/%y %H:%M:%S') for t in times] -+ while len(times) > 0: -+ starttime = times.pop(0) -+ endtime = times.pop(0) -+ renewtime = times.pop(0) -+ -+ if str(endtime - starttime) != target_time: -+ fail('unexpected lifetime value') -+ if str(renewtime - endtime) != target_time: -+ fail('unexpected renewable value') -+ -+rflags = ['-r', '1d', '-l', '12h'] -+ -+# Test AS+TGS success path. -+realm.kinit(realm.user_princ, password('user'), -+ rflags + ['-X', 'indicators=SEVEN_HOURS']) -+realm.run([kvno, realm.host_princ]) -+realm.run(['./adata', realm.host_princ], expected_msg='+97: [SEVEN_HOURS]') -+out = realm.run([klist, realm.ccache, '-e']) -+verify_time(out, '7:00:00') -+ -+# Test AS+TGS success path with different values. -+realm.kinit(realm.user_princ, password('user'), -+ rflags + ['-X', 'indicators=ONE_HOUR']) -+realm.run([kvno, realm.host_princ]) -+realm.run(['./adata', realm.host_princ], expected_msg='+97: [ONE_HOUR]') -+out = realm.run([klist, realm.ccache, '-e']) -+verify_time(out, '1:00:00') -+ -+# Test TGS failure path (using previous creds). -+realm.run([kvno, 'fail@%s' % realm.realm], expected_code=1, -+ expected_msg='KDC policy rejects request') -+ -+# Test AS failure path. -+realm.kinit('fail@%s' % realm.realm, password('fail'), -+ expected_code=1, expected_msg='KDC policy rejects request') -+ -+success('kdcpolicy tests') diff --git a/Add-PKINIT-UPN-tests-to-t_pkinit.py.patch b/Add-PKINIT-UPN-tests-to-t_pkinit.py.patch deleted file mode 100644 index 94370dc..0000000 --- a/Add-PKINIT-UPN-tests-to-t_pkinit.py.patch +++ /dev/null @@ -1,101 +0,0 @@ -From 6ce3a9416ee73fee41d0190e3fd0fde0a097c774 Mon Sep 17 00:00:00 2001 -From: Matt Rogers -Date: Fri, 9 Dec 2016 11:43:27 -0500 -Subject: [PATCH] Add PKINIT UPN tests to t_pkinit.py - -[ghudson@mit.edu: simplify and explain tests; add test for -id-pkinit-san match against canonicalized client principal] - -ticket: 8528 -(cherry picked from commit d520fd3f032121b61b22681838af96ee505fe44d) ---- - src/tests/t_pkinit.py | 57 +++++++++++++++++++++++++++++++++++++++++++++++++++ - 1 file changed, 57 insertions(+) - -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index 526473b42..ac4d326b6 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -23,6 +23,9 @@ privkey_pem = os.path.join(certs, 'privkey.pem') - privkey_enc_pem = os.path.join(certs, 'privkey-enc.pem') - user_p12 = os.path.join(certs, 'user.p12') - user_enc_p12 = os.path.join(certs, 'user-enc.p12') -+user_upn_p12 = os.path.join(certs, 'user-upn.p12') -+user_upn2_p12 = os.path.join(certs, 'user-upn2.p12') -+user_upn3_p12 = os.path.join(certs, 'user-upn3.p12') - path = os.path.join(os.getcwd(), 'testdir', 'tmp-pkinit-certs') - path_enc = os.path.join(os.getcwd(), 'testdir', 'tmp-pkinit-certs-enc') - -@@ -36,6 +39,20 @@ pkinit_kdc_conf = {'realms': {'$realm': { - restrictive_kdc_conf = {'realms': {'$realm': { - 'restrict_anonymous_to_tgt': 'true' }}} - -+testprincs = {'krbtgt/KRBTEST.COM': {'keys': 'aes128-cts'}, -+ 'user': {'keys': 'aes128-cts', 'flags': '+preauth'}, -+ 'user2': {'keys': 'aes128-cts', 'flags': '+preauth'}} -+alias_kdc_conf = {'realms': {'$realm': { -+ 'default_principal_flags': '+preauth', -+ 'pkinit_eku_checking': 'none', -+ 'pkinit_allow_upn': 'true', -+ 'pkinit_identity': 'FILE:%s,%s' % (kdc_pem, privkey_pem), -+ 'database_module': 'test'}}, -+ 'dbmodules': {'test': { -+ 'db_library': 'test', -+ 'alias': {'user@krbtest.com': 'user'}, -+ 'princs': testprincs}}} -+ - file_identity = 'FILE:%s,%s' % (user_pem, privkey_pem) - file_enc_identity = 'FILE:%s,%s' % (user_pem, privkey_enc_pem) - dir_identity = 'DIR:%s' % path -@@ -45,11 +62,51 @@ dir_file_identity = 'FILE:%s,%s' % (os.path.join(path, 'user.crt'), - dir_file_enc_identity = 'FILE:%s,%s' % (os.path.join(path_enc, 'user.crt'), - os.path.join(path_enc, 'user.key')) - p12_identity = 'PKCS12:%s' % user_p12 -+p12_upn_identity = 'PKCS12:%s' % user_upn_p12 -+p12_upn2_identity = 'PKCS12:%s' % user_upn2_p12 -+p12_upn3_identity = 'PKCS12:%s' % user_upn3_p12 - p12_enc_identity = 'PKCS12:%s' % user_enc_p12 - p11_identity = 'PKCS11:soft-pkcs11.so' - p11_token_identity = ('PKCS11:module_name=soft-pkcs11.so:' - 'slotid=1:token=SoftToken (token)') - -+# Start a realm with the test kdb module for the following UPN SAN tests. -+realm = K5Realm(krb5_conf=pkinit_krb5_conf, kdc_conf=alias_kdc_conf, -+ create_kdb=False) -+realm.start_kdc() -+ -+# Compatibility check: cert contains UPN "user", which matches the -+# request principal user@KRBTEST.COM if parsed as a normal principal. -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % p12_upn2_identity]) -+ -+# Compatibility check: cert contains UPN "user@KRBTEST.COM", which matches -+# the request principal user@KRBTEST.COM if parsed as a normal principal. -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % p12_upn3_identity]) -+ -+# Cert contains UPN "user@krbtest.com" which is aliased to the request -+# principal. -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % p12_upn_identity]) -+ -+# Test an id-pkinit-san match to a post-canonical principal. -+realm.kinit('user@krbtest.com', -+ flags=['-E', '-X', 'X509_user_identity=%s' % p12_identity]) -+ -+# Test a UPN match to a post-canonical principal. (This only works -+# for the cert with the UPN containing just "user", as we don't allow -+# UPN reparsing when comparing to the canonicalized client principal.) -+realm.kinit('user@krbtest.com', -+ flags=['-E', '-X', 'X509_user_identity=%s' % p12_upn2_identity]) -+ -+# Test a mismatch. -+out = realm.run([kinit, '-X', 'X509_user_identity=%s' % p12_upn2_identity, -+ 'user2'], expected_code=1) -+if 'kinit: Client name mismatch while getting initial credentials' not in out: -+ fail('Wrong error for UPN SAN mismatch') -+realm.stop() -+ - realm = K5Realm(krb5_conf=pkinit_krb5_conf, kdc_conf=pkinit_kdc_conf, - get_creds=False) - diff --git a/Add-PKINIT-test-case-for-generic-client-cert.patch b/Add-PKINIT-test-case-for-generic-client-cert.patch deleted file mode 100644 index e77dd5f..0000000 --- a/Add-PKINIT-test-case-for-generic-client-cert.patch +++ /dev/null @@ -1,51 +0,0 @@ -From e267849bcc3813989470c03565b22d25c71af91e Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 25 Aug 2017 12:39:14 -0400 -Subject: [PATCH] Add PKINIT test case for generic client cert - -In t_pkinit.py, add a test case where a client cert with no extensions -is authorized via subject and issuer using a pkinit_cert_match string -attribute. - -ticket: 8562 -(cherry picked from commit 8c5d50888aab554239fd51306e79c5213833c898) -[rharwood@redhat.com: backport around dbmatch module] ---- - src/tests/t_pkinit.py | 10 ++++++++++ - 1 file changed, 10 insertions(+) - -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index e943f4974..fa5c5199e 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -26,6 +26,7 @@ user_enc_p12 = os.path.join(certs, 'user-enc.p12') - user_upn_p12 = os.path.join(certs, 'user-upn.p12') - user_upn2_p12 = os.path.join(certs, 'user-upn2.p12') - user_upn3_p12 = os.path.join(certs, 'user-upn3.p12') -+generic_p12 = os.path.join(certs, 'generic.p12') - path = os.path.join(os.getcwd(), 'testdir', 'tmp-pkinit-certs') - path_enc = os.path.join(os.getcwd(), 'testdir', 'tmp-pkinit-certs-enc') - -@@ -65,6 +66,7 @@ p12_identity = 'PKCS12:%s' % user_p12 - p12_upn_identity = 'PKCS12:%s' % user_upn_p12 - p12_upn2_identity = 'PKCS12:%s' % user_upn2_p12 - p12_upn3_identity = 'PKCS12:%s' % user_upn3_p12 -+p12_generic_identity = 'PKCS12:%s' % generic_p12 - p12_enc_identity = 'PKCS12:%s' % user_enc_p12 - p11_identity = 'PKCS11:soft-pkcs11.so' - p11_token_identity = ('PKCS11:module_name=soft-pkcs11.so:' -@@ -284,6 +286,14 @@ realm.run(['./responder', '-X', 'X509_user_identity=%s' % p12_enc_identity, - realm.klist(realm.user_princ) - realm.run([kvno, realm.host_princ]) - -+# Authorize a client cert with no PKINIT extensions using subject and -+# issuer. (Relies on EKU checking being turned off.) -+rule = '&&CN=user$O=MIT,' -+realm.run([kadminl, 'setstr', realm.user_princ, 'pkinit_cert_match', rule]) -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % p12_generic_identity]) -+realm.klist(realm.user_princ) -+ - if not have_soft_pkcs11: - skip_rest('PKINIT PKCS11 tests', 'soft-pkcs11.so not found') - diff --git a/Add-certauth-pluggable-interface.patch b/Add-certauth-pluggable-interface.patch deleted file mode 100644 index a9adc3e..0000000 --- a/Add-certauth-pluggable-interface.patch +++ /dev/null @@ -1,1146 +0,0 @@ -From 43418f21de72060932661242126fe611b6b17d84 Mon Sep 17 00:00:00 2001 -From: Matt Rogers -Date: Tue, 28 Feb 2017 15:55:24 -0500 -Subject: [PATCH] Add certauth pluggable interface - -Add the header include/krb5/certauth_plugin.h, defining a pluggable -interface to control authorization of PKINIT client certificates. - -Add the "pkinit_san" and "pkinit_eku" builtin certauth modules and -related PKINIT crypto X.509 helper functions. Add authorize_cert() as -the entry function for certauth plugin module checks called in -pkinit_server_verify_padata(). Modify kdcpreauth_moddata to hold the -list of certauth module handles, and load the modules when the PKINIT -kdcpreauth server plugin is initialized. Change -crypto_retrieve_X509_sans() to return ENOENT when no SAN is found. - -Add test modules in plugins/certauth/test. Create t_certauth.py with -basic certauth tests. Add plugin interface documentation in -doc/plugindev/certauth.rst and doc/admin/krb5_conf.rst. - -[ghudson@mit.edu: simplified code, edited docs] - -ticket: 8561 (new) -(cherry picked from commit b619ce84470519bea65470be3263cd85fba94f57) ---- - doc/admin/conf_files/krb5_conf.rst | 21 ++ - doc/plugindev/certauth.rst | 27 ++ - doc/plugindev/index.rst | 1 + - src/Makefile.in | 1 + - src/configure.in | 1 + - src/include/Makefile.in | 1 + - src/include/k5-int.h | 3 +- - src/include/krb5/certauth_plugin.h | 103 +++++++ - src/lib/krb5/krb/plugin.c | 3 +- - src/plugins/certauth/test/Makefile.in | 20 ++ - src/plugins/certauth/test/certauth_test.exports | 2 + - src/plugins/certauth/test/deps | 14 + - src/plugins/certauth/test/main.c | 209 +++++++++++++ - src/plugins/preauth/pkinit/pkinit_crypto.h | 4 + - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 30 ++ - src/plugins/preauth/pkinit/pkinit_srv.c | 335 ++++++++++++++++++--- - src/plugins/preauth/pkinit/pkinit_trace.h | 5 + - src/tests/Makefile.in | 1 + - src/tests/t_certauth.py | 47 +++ - 19 files changed, 786 insertions(+), 42 deletions(-) - create mode 100644 doc/plugindev/certauth.rst - create mode 100644 src/include/krb5/certauth_plugin.h - create mode 100644 src/plugins/certauth/test/Makefile.in - create mode 100644 src/plugins/certauth/test/certauth_test.exports - create mode 100644 src/plugins/certauth/test/deps - create mode 100644 src/plugins/certauth/test/main.c - create mode 100644 src/tests/t_certauth.py - -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 02a935961..1d9bc9e34 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -859,6 +859,27 @@ built-in modules exist for this interface: - This module authorizes a principal to a local account if the - principal name maps to the local account name. - -+.. _certauth: -+ -+certauth interface -+################## -+ -+The certauth section (introduced in release 1.16) controls modules for -+the certificate authorization interface, which determines whether a -+certificate is allowed to preauthenticate a user via PKINIT. The -+following built-in modules exist for this interface: -+ -+**pkinit_san** -+ This module authorizes the certificate if it contains a PKINIT -+ Subject Alternative Name for the requested client principal, or a -+ Microsoft UPN SAN matching the principal if **pkinit_allow_upn** -+ is set to true for the realm. -+ -+**pkinit_eku** -+ This module rejects the certificate if it does not contain an -+ Extended Key Usage attribute consistent with the -+ **pkinit_eku_checking** value for the realm. -+ - - PKINIT options - -------------- -diff --git a/doc/plugindev/certauth.rst b/doc/plugindev/certauth.rst -new file mode 100644 -index 000000000..8a7f7c5eb ---- /dev/null -+++ b/doc/plugindev/certauth.rst -@@ -0,0 +1,27 @@ -+.. _certauth_plugin: -+ -+PKINIT certificate authorization interface (certauth) -+===================================================== -+ -+The certauth interface was first introduced in release 1.16. It -+allows customization of the X.509 certificate attribute requirements -+placed on certificates used by PKINIT enabled clients. For a detailed -+description of the certauth interface, see the header file -+```` -+ -+A certauth module implements the **authorize** method to determine -+whether a client's certificate is authorized to authenticate a client -+principal. **authorize** receives the DER-encoded certificate, the -+requested client principal, and a pointer to the client's -+krb5_db_entry (for modules that link against libkdb5). It returns the -+authorization status and optionally outputs a list of authentication -+indicator strings to be added to the ticket. A module must use its -+own internal or library-provided ASN.1 certificate decoder. -+ -+A module can optionally create and destroy module data with the -+**init** and **fini** methods. Module data objects last for the -+lifetime of the KDC process. -+ -+If a module allocates and returns a list of authentication indicators -+from **authorize**, it must also implement the **free_ind** method -+to free the list. -diff --git a/doc/plugindev/index.rst b/doc/plugindev/index.rst -index 3fb921778..67dbc2790 100644 ---- a/doc/plugindev/index.rst -+++ b/doc/plugindev/index.rst -@@ -31,5 +31,6 @@ Contents - profile.rst - gssapi.rst - internal.rst -+ certauth.rst - - .. TODO: GSSAPI mechanism plugins -diff --git a/src/Makefile.in b/src/Makefile.in -index 2ebf2fb4d..b0249778c 100644 ---- a/src/Makefile.in -+++ b/src/Makefile.in -@@ -17,6 +17,7 @@ SUBDIRS=util include lib \ - plugins/pwqual/test \ - plugins/authdata/greet_server \ - plugins/authdata/greet_client \ -+ plugins/certauth/test \ - plugins/kdb/db2 \ - @ldap_plugin_dir@ \ - plugins/kdb/test \ -diff --git a/src/configure.in b/src/configure.in -index acf3a458b..24f653f0d 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -1451,6 +1451,7 @@ dnl ccapi ccapi/lib ccapi/lib/unix ccapi/server ccapi/server/unix ccapi/test - - kdc slave config-files build-tools man doc include - -+ plugins/certauth/test - plugins/hostrealm/test - plugins/localauth/test - plugins/kadm5_hook/test -diff --git a/src/include/Makefile.in b/src/include/Makefile.in -index f5b921833..0239338a1 100644 ---- a/src/include/Makefile.in -+++ b/src/include/Makefile.in -@@ -140,6 +140,7 @@ install-headers-unix install: krb5/krb5.h profile.h - $(INSTALL_DATA) $(srcdir)/krb5.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5.h - $(INSTALL_DATA) $(srcdir)/kdb.h $(DESTDIR)$(KRB5_INCDIR)$(S)kdb.h - $(INSTALL_DATA) krb5/krb5.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)krb5.h -+ $(INSTALL_DATA) $(srcdir)/krb5/certauth_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)certauth_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/ccselect_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)ccselect_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/clpreauth_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)clpreauth_plugin.h - $(INSTALL_DATA) $(srcdir)/krb5/hostrealm_plugin.h $(DESTDIR)$(KRB5_INCDIR)$(S)krb5$(S)hostrealm_plugin.h -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 173cb0264..cea644d0a 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -1156,7 +1156,8 @@ struct plugin_interface { - #define PLUGIN_INTERFACE_AUDIT 7 - #define PLUGIN_INTERFACE_TLS 8 - #define PLUGIN_INTERFACE_KDCAUTHDATA 9 --#define PLUGIN_NUM_INTERFACES 10 -+#define PLUGIN_INTERFACE_CERTAUTH 10 -+#define PLUGIN_NUM_INTERFACES 11 - - /* Retrieve the plugin module of type interface_id and name modname, - * storing the result into module. */ -diff --git a/src/include/krb5/certauth_plugin.h b/src/include/krb5/certauth_plugin.h -new file mode 100644 -index 000000000..f22fc1e84 ---- /dev/null -+++ b/src/include/krb5/certauth_plugin.h -@@ -0,0 +1,103 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* include/krb5/certauth_plugin.h - certauth plugin header. */ -+/* -+ * Copyright (C) 2017 by Red Hat, Inc. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+/* -+ * Certificate authorization plugin interface. The PKINIT server module uses -+ * this interface to check client certificate attributes after the certificate -+ * signature has been verified. -+ */ -+#ifndef KRB5_CERTAUTH_PLUGIN_H -+#define KRB5_CERTAUTH_PLUGIN_H -+ -+#include -+#include -+ -+/* Abstract module data type. */ -+typedef struct krb5_certauth_moddata_st *krb5_certauth_moddata; -+ -+typedef struct _krb5_db_entry_new krb5_db_entry; -+ -+/* -+ * Optional: Initialize module data. -+ */ -+typedef krb5_error_code -+(*krb5_certauth_init_fn)(krb5_context context, -+ krb5_certauth_moddata *moddata_out); -+ -+/* -+ * Optional: Clean up the module data. -+ */ -+typedef void -+(*krb5_certauth_fini_fn)(krb5_context context, krb5_certauth_moddata moddata); -+ -+/* -+ * Mandatory: -+ * Return 0 if the DER-encoded cert is authorized for PKINIT authentication by -+ * princ; otherwise return one of the following error codes: -+ * - KRB5KDC_ERR_CLIENT_NAME_MISMATCH - incorrect SAN value -+ * - KRB5KDC_ERR_INCONSISTENT_KEY_PURPOSE - incorrect EKU -+ * - KRB5KDC_ERR_CERTIFICATE_MISMATCH - other extension error -+ * - KRB5_PLUGIN_NO_HANDLE - the module has no opinion about cert -+ * -+ * - opts is used by built-in modules to receive internal data, and must be -+ * ignored by other modules. -+ * - db_entry receives the client principal database entry, and can be ignored -+ * by modules that do not link with libkdb5. -+ * - *authinds_out optionally returns a null-terminated list of authentication -+ * indicator strings upon KRB5_PLUGIN_NO_HANDLE or accepted authorization. -+ */ -+typedef krb5_error_code -+(*krb5_certauth_authorize_fn)(krb5_context context, -+ krb5_certauth_moddata moddata, -+ const uint8_t *cert, size_t cert_len, -+ krb5_const_principal princ, const void *opts, -+ const krb5_db_entry *db_entry, -+ char ***authinds_out); -+ -+/* -+ * Free indicators allocated by a module. Mandatory if authorize returns -+ * authentication indicators. -+ */ -+typedef void -+(*krb5_certauth_free_indicator_fn)(krb5_context context, -+ krb5_certauth_moddata moddata, -+ char **authinds); -+ -+typedef struct krb5_certauth_vtable_st { -+ char *name; -+ krb5_certauth_init_fn init; -+ krb5_certauth_fini_fn fini; -+ krb5_certauth_authorize_fn authorize; -+ krb5_certauth_free_indicator_fn free_ind; -+} *krb5_certauth_vtable; -+ -+#endif /* KRB5_CERTAUTH_PLUGIN_H */ -diff --git a/src/lib/krb5/krb/plugin.c b/src/lib/krb5/krb/plugin.c -index 7d64b7c7e..17dd6bd30 100644 ---- a/src/lib/krb5/krb/plugin.c -+++ b/src/lib/krb5/krb/plugin.c -@@ -57,7 +57,8 @@ const char *interface_names[] = { - "hostrealm", - "audit", - "tls", -- "kdcauthdata" -+ "kdcauthdata", -+ "certauth" - }; - - /* Return the context's interface structure for id, or NULL if invalid. */ -diff --git a/src/plugins/certauth/test/Makefile.in b/src/plugins/certauth/test/Makefile.in -new file mode 100644 -index 000000000..d3524084c ---- /dev/null -+++ b/src/plugins/certauth/test/Makefile.in -@@ -0,0 +1,20 @@ -+mydir=plugins$(S)certauth$(S)test -+BUILDTOP=$(REL)..$(S)..$(S).. -+ -+LIBBASE=certauth_test -+LIBMAJOR=0 -+LIBMINOR=0 -+RELDIR=../plugins/certauth/test -+SHLIB_EXPDEPS=$(KRB5_BASE_DEPLIBS) -+SHLIB_EXPLIBS=$(KRB5_BASE_LIBS) -+ -+STLIBOBJS=main.o -+ -+SRCS=$(srcdir)/main.c -+ -+all-unix: all-libs -+install-unix: -+clean-unix:: clean-libs clean-libobjs -+ -+@libnover_frag@ -+@libobj_frag@ -diff --git a/src/plugins/certauth/test/certauth_test.exports b/src/plugins/certauth/test/certauth_test.exports -new file mode 100644 -index 000000000..1c8cd24e2 ---- /dev/null -+++ b/src/plugins/certauth/test/certauth_test.exports -@@ -0,0 +1,2 @@ -+certauth_test1_initvt -+certauth_test2_initvt -diff --git a/src/plugins/certauth/test/deps b/src/plugins/certauth/test/deps -new file mode 100644 -index 000000000..2974b3b57 ---- /dev/null -+++ b/src/plugins/certauth/test/deps -@@ -0,0 +1,14 @@ -+# -+# Generated makefile dependencies follow. -+# -+main.so main.po $(OUTPRE)main.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -+ $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -+ $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ -+ $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -+ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -+ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -+ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -+ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -+ $(top_srcdir)/include/krb5/certauth_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -+ main.c -diff --git a/src/plugins/certauth/test/main.c b/src/plugins/certauth/test/main.c -new file mode 100644 -index 000000000..7ef7377fb ---- /dev/null -+++ b/src/plugins/certauth/test/main.c -@@ -0,0 +1,209 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* plugins/certauth/main.c - certauth plugin test modules. */ -+/* -+ * Copyright (C) 2017 by Red Hat, Inc. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include -+#include "krb5/certauth_plugin.h" -+ -+struct krb5_certauth_moddata_st { -+ int initialized; -+}; -+ -+/* Test module 1 returns OK with an indicator. */ -+static krb5_error_code -+test1_authorize(krb5_context context, krb5_certauth_moddata moddata, -+ const uint8_t *cert, size_t cert_len, -+ krb5_const_principal princ, const void *opts, -+ const krb5_db_entry *db_entry, char ***authinds_out) -+{ -+ char **ais = NULL; -+ -+ ais = calloc(2, sizeof(*ais)); -+ assert(ais != NULL); -+ ais[0] = strdup("test1"); -+ assert(ais[0] != NULL); -+ *authinds_out = ais; -+ return KRB5_PLUGIN_NO_HANDLE; -+} -+ -+static void -+test_free_ind(krb5_context context, krb5_certauth_moddata moddata, -+ char **authinds) -+{ -+ size_t i; -+ -+ if (authinds == NULL) -+ return; -+ for (i = 0; authinds[i] != NULL; i++) -+ free(authinds[i]); -+ free(authinds); -+} -+ -+/* A basic moddata test. */ -+static krb5_error_code -+test2_init(krb5_context context, krb5_certauth_moddata *moddata_out) -+{ -+ krb5_certauth_moddata mod; -+ -+ mod = calloc(1, sizeof(*mod)); -+ assert(mod != NULL); -+ mod->initialized = 1; -+ *moddata_out = mod; -+ return 0; -+} -+ -+static void -+test2_fini(krb5_context context, krb5_certauth_moddata moddata) -+{ -+ free(moddata); -+} -+ -+/* Return true if cert appears to contain the CN name, based on a search of the -+ * DER encoding. */ -+static krb5_boolean -+has_cn(krb5_context context, const uint8_t *cert, size_t cert_len, -+ const char *name) -+{ -+ krb5_boolean match = FALSE; -+ uint8_t name_len, cntag[5] = "\x06\x03\x55\x04\x03"; -+ const uint8_t *c; -+ struct k5buf buf; -+ size_t c_left; -+ -+ /* Construct a DER search string of the CN AttributeType encoding followed -+ * by a UTF8String encoding containing name as the AttributeValue. */ -+ k5_buf_init_dynamic(&buf); -+ k5_buf_add_len(&buf, cntag, sizeof(cntag)); -+ k5_buf_add(&buf, "\x0C"); -+ assert(strlen(name) < 128); -+ name_len = strlen(name); -+ k5_buf_add_len(&buf, &name_len, 1); -+ k5_buf_add_len(&buf, name, name_len); -+ assert(k5_buf_status(&buf) == 0); -+ -+ /* Check for the CN needle in the certificate haystack. */ -+ c_left = cert_len; -+ c = memchr(cert, *cntag, c_left); -+ while (c != NULL) { -+ c_left = cert_len - (c - cert); -+ if (buf.len > c_left) -+ break; -+ if (memcmp(c, buf.data, buf.len) == 0) { -+ match = TRUE; -+ break; -+ } -+ assert(c_left >= 1); -+ c = memchr(c + 1, *cntag, c_left - 1); -+ } -+ -+ k5_buf_free(&buf); -+ return match; -+} -+ -+/* -+ * Test module 2 returns OK if princ matches the CN part of the subject name, -+ * and returns indicators of the module name and princ. -+ */ -+static krb5_error_code -+test2_authorize(krb5_context context, krb5_certauth_moddata moddata, -+ const uint8_t *cert, size_t cert_len, -+ krb5_const_principal princ, const void *opts, -+ const krb5_db_entry *db_entry, char ***authinds_out) -+{ -+ krb5_error_code ret; -+ char *name = NULL, **ais = NULL; -+ -+ *authinds_out = NULL; -+ -+ assert(moddata != NULL && moddata->initialized); -+ -+ ret = krb5_unparse_name_flags(context, princ, -+ KRB5_PRINCIPAL_UNPARSE_NO_REALM, &name); -+ if (ret) -+ goto cleanup; -+ -+ if (!has_cn(context, cert, cert_len, name)) { -+ ret = KRB5KDC_ERR_CERTIFICATE_MISMATCH; -+ goto cleanup; -+ } -+ -+ /* Create an indicator list with the module name and CN. */ -+ ais = calloc(3, sizeof(*ais)); -+ assert(ais != NULL); -+ ais[0] = strdup("test2"); -+ ais[1] = strdup(name); -+ assert(ais[0] != NULL && ais[1] != NULL); -+ *authinds_out = ais; -+ -+ ais = NULL; -+ -+cleanup: -+ krb5_free_unparsed_name(context, name); -+ return ret; -+} -+ -+krb5_error_code -+certauth_test1_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable); -+krb5_error_code -+certauth_test1_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable) -+{ -+ krb5_certauth_vtable vt; -+ -+ if (maj_ver != 1) -+ return KRB5_PLUGIN_VER_NOTSUPP; -+ vt = (krb5_certauth_vtable)vtable; -+ vt->name = "test1"; -+ vt->authorize = test1_authorize; -+ vt->free_ind = test_free_ind; -+ return 0; -+} -+ -+krb5_error_code -+certauth_test2_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable); -+krb5_error_code -+certauth_test2_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable) -+{ -+ krb5_certauth_vtable vt; -+ -+ if (maj_ver != 1) -+ return KRB5_PLUGIN_VER_NOTSUPP; -+ vt = (krb5_certauth_vtable)vtable; -+ vt->name = "test2"; -+ vt->authorize = test2_authorize; -+ vt->init = test2_init; -+ vt->fini = test2_fini; -+ vt->free_ind = test_free_ind; -+ return 0; -+} -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h -index b483affed..49b96b8ee 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto.h -+++ b/src/plugins/preauth/pkinit/pkinit_crypto.h -@@ -664,4 +664,8 @@ extern const size_t krb5_pkinit_sha512_oid_len; - */ - extern krb5_data const * const supported_kdf_alg_ids[]; - -+krb5_error_code -+crypto_encode_der_cert(krb5_context context, pkinit_req_crypto_context reqctx, -+ uint8_t **der_out, size_t *der_len); -+ - #endif /* _PKINIT_CRYPTO_H */ -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 8def8c542..a5b010b26 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2137,6 +2137,7 @@ crypto_retrieve_X509_sans(krb5_context context, - - if (!(ext = X509_get_ext(cert, l)) || !(ialt = X509V3_EXT_d2i(ext))) { - pkiDebug("%s: found no subject alt name extensions\n", __FUNCTION__); -+ retval = ENOENT; - goto cleanup; - } - num_sans = sk_GENERAL_NAME_num(ialt); -@@ -6176,3 +6177,32 @@ crypto_get_deferred_ids(krb5_context context, - ret = (const pkinit_deferred_id *)deferred; - return ret; - } -+ -+/* Return the received certificate as DER-encoded data. */ -+krb5_error_code -+crypto_encode_der_cert(krb5_context context, pkinit_req_crypto_context reqctx, -+ uint8_t **der_out, size_t *der_len) -+{ -+ int len; -+ unsigned char *der, *p; -+ -+ *der_out = NULL; -+ *der_len = 0; -+ -+ if (reqctx->received_cert == NULL) -+ return EINVAL; -+ p = NULL; -+ len = i2d_X509(reqctx->received_cert, NULL); -+ if (len <= 0) -+ return EINVAL; -+ p = der = malloc(len); -+ if (p == NULL) -+ return ENOMEM; -+ if (i2d_X509(reqctx->received_cert, &p) <= 0) { -+ free(p); -+ return EINVAL; -+ } -+ *der_out = der; -+ *der_len = len; -+ return 0; -+} -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index b5638a367..731d14eb8 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -31,6 +31,25 @@ - - #include - #include "pkinit.h" -+#include "krb5/certauth_plugin.h" -+ -+/* Aliases used by the built-in certauth modules */ -+struct certauth_req_opts { -+ krb5_kdcpreauth_callbacks cb; -+ krb5_kdcpreauth_rock rock; -+ pkinit_kdc_context plgctx; -+ pkinit_kdc_req_context reqctx; -+}; -+ -+typedef struct certauth_module_handle_st { -+ struct krb5_certauth_vtable_st vt; -+ krb5_certauth_moddata moddata; -+} *certauth_handle; -+ -+struct krb5_kdcpreauth_moddata_st { -+ pkinit_kdc_context *realm_contexts; -+ certauth_handle *certauth_modules; -+}; - - static krb5_error_code - pkinit_init_kdc_req_context(krb5_context, pkinit_kdc_req_context *blob); -@@ -51,6 +70,34 @@ pkinit_find_realm_context(krb5_context context, - krb5_kdcpreauth_moddata moddata, - krb5_principal princ); - -+static void -+free_realm_contexts(krb5_context context, pkinit_kdc_context *realm_contexts) -+{ -+ int i; -+ -+ if (realm_contexts == NULL) -+ return; -+ for (i = 0; realm_contexts[i] != NULL; i++) -+ pkinit_server_plugin_fini_realm(context, realm_contexts[i]); -+ pkiDebug("%s: freeing context at %p\n", __FUNCTION__, realm_contexts); -+ free(realm_contexts); -+} -+ -+static void -+free_certauth_handles(krb5_context context, certauth_handle *list) -+{ -+ int i; -+ -+ if (list == NULL) -+ return; -+ for (i = 0; list[i] != NULL; i++) { -+ if (list[i]->vt.fini != NULL) -+ list[i]->vt.fini(context, list[i]->moddata); -+ free(list[i]); -+ } -+ free(list); -+} -+ - static krb5_error_code - pkinit_create_edata(krb5_context context, - pkinit_plg_crypto_context plg_cryptoctx, -@@ -123,7 +170,7 @@ verify_client_san(krb5_context context, - pkinit_kdc_req_context reqctx, - krb5_kdcpreauth_callbacks cb, - krb5_kdcpreauth_rock rock, -- krb5_principal client, -+ krb5_const_principal client, - int *valid_san) - { - krb5_error_code retval; -@@ -134,12 +181,15 @@ verify_client_san(krb5_context context, - char *client_string = NULL, *san_string; - #endif - -+ *valid_san = 0; - retval = crypto_retrieve_cert_sans(context, plgctx->cryptoctx, - reqctx->cryptoctx, plgctx->idctx, - &princs, - plgctx->opts->allow_upn ? &upns : NULL, - NULL); -- if (retval) { -+ if (retval == ENOENT) { -+ goto out; -+ } else if (retval) { - pkiDebug("%s: error from retrieve_certificate_sans()\n", __FUNCTION__); - retval = KRB5KDC_ERR_CLIENT_NAME_MISMATCH; - goto out; -@@ -273,6 +323,73 @@ out: - return retval; - } - -+ -+/* Run the received, verified certificate through certauth modules, to verify -+ * that it is authorized to authenticate as client. */ -+static krb5_error_code -+authorize_cert(krb5_context context, certauth_handle *certauth_modules, -+ pkinit_kdc_context plgctx, pkinit_kdc_req_context reqctx, -+ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, -+ krb5_principal client) -+{ -+ krb5_error_code ret; -+ certauth_handle h; -+ struct certauth_req_opts opts; -+ krb5_boolean accepted = FALSE; -+ uint8_t *cert; -+ size_t i, cert_len; -+ void *db_ent = NULL; -+ char **ais = NULL, **ai = NULL; -+ -+ /* Re-encode the received certificate into DER, which is extra work, but -+ * avoids creating an X.509 library dependency in the interface. */ -+ ret = crypto_encode_der_cert(context, reqctx->cryptoctx, &cert, &cert_len); -+ if (ret) -+ goto cleanup; -+ -+ /* Set options for the builtin module. */ -+ opts.plgctx = plgctx; -+ opts.reqctx = reqctx; -+ opts.cb = cb; -+ opts.rock = rock; -+ -+ db_ent = cb->client_entry(context, rock); -+ -+ /* -+ * Check the certificate against each certauth module. For the certificate -+ * to be authorized at least one module must return 0, and no module can an -+ * error code other than KRB5_PLUGIN_NO_HANDLE (pass). Add indicators from -+ * modules that return 0 or pass. -+ */ -+ ret = KRB5_PLUGIN_NO_HANDLE; -+ for (i = 0; certauth_modules != NULL && certauth_modules[i] != NULL; i++) { -+ h = certauth_modules[i]; -+ ret = h->vt.authorize(context, h->moddata, cert, cert_len, client, -+ &opts, db_ent, &ais); -+ if (ret == 0) -+ accepted = TRUE; -+ else if (ret != KRB5_PLUGIN_NO_HANDLE) -+ goto cleanup; -+ -+ if (ais != NULL) { -+ /* Assert authentication indicators from the module. */ -+ for (ai = ais; *ai != NULL; ai++) { -+ ret = cb->add_auth_indicator(context, rock, *ai); -+ if (ret) -+ goto cleanup; -+ } -+ h->vt.free_ind(context, h->moddata, ais); -+ ais = NULL; -+ } -+ } -+ -+ ret = accepted ? 0 : KRB5KDC_ERR_CLIENT_NAME_MISMATCH; -+ -+cleanup: -+ free(cert); -+ return ret; -+} -+ - static void - pkinit_server_verify_padata(krb5_context context, - krb5_data *req_pkt, -@@ -295,7 +412,6 @@ pkinit_server_verify_padata(krb5_context context, - pkinit_kdc_req_context reqctx = NULL; - krb5_checksum cksum = {0, 0, 0, NULL}; - krb5_data *der_req = NULL; -- int valid_eku = 0, valid_san = 0; - krb5_data k5data; - int is_signed = 1; - krb5_pa_data **e_data = NULL; -@@ -388,27 +504,11 @@ pkinit_server_verify_padata(krb5_context context, - goto cleanup; - } - if (is_signed) { -- -- retval = verify_client_san(context, plgctx, reqctx, cb, rock, -- request->client, &valid_san); -- if (retval) -- goto cleanup; -- if (!valid_san) { -- pkiDebug("%s: did not find an acceptable SAN in user " -- "certificate\n", __FUNCTION__); -- retval = KRB5KDC_ERR_CLIENT_NAME_MISMATCH; -- goto cleanup; -- } -- retval = verify_client_eku(context, plgctx, reqctx, &valid_eku); -+ retval = authorize_cert(context, moddata->certauth_modules, plgctx, -+ reqctx, cb, rock, request->client); - if (retval) - goto cleanup; - -- if (!valid_eku) { -- pkiDebug("%s: did not find an acceptable EKU in user " -- "certificate\n", __FUNCTION__); -- retval = KRB5KDC_ERR_INCONSISTENT_KEY_PURPOSE; -- goto cleanup; -- } - } else { /* !is_signed */ - if (!krb5_principal_compare(context, request->client, - krb5_anonymous_principal())) { -@@ -1245,11 +1345,15 @@ pkinit_find_realm_context(krb5_context context, - krb5_principal princ) - { - int i; -- pkinit_kdc_context *realm_contexts = (pkinit_kdc_context *)moddata; -+ pkinit_kdc_context *realm_contexts; - - if (moddata == NULL) - return NULL; - -+ realm_contexts = moddata->realm_contexts; -+ if (realm_contexts == NULL) -+ return NULL; -+ - for (i = 0; realm_contexts[i] != NULL; i++) { - pkinit_kdc_context p = realm_contexts[i]; - -@@ -1331,6 +1435,155 @@ errout: - return retval; - } - -+static krb5_error_code -+pkinit_san_authorize(krb5_context context, krb5_certauth_moddata moddata, -+ const uint8_t *cert, size_t cert_len, -+ krb5_const_principal princ, const void *opts, -+ const krb5_db_entry *db_entry, char ***authinds_out) -+{ -+ krb5_error_code ret; -+ int valid_san; -+ const struct certauth_req_opts *req_opts = opts; -+ -+ *authinds_out = NULL; -+ -+ ret = verify_client_san(context, req_opts->plgctx, req_opts->reqctx, -+ req_opts->cb, req_opts->rock, princ, &valid_san); -+ if (ret == ENOENT) -+ return KRB5_PLUGIN_NO_HANDLE; -+ else if (ret) -+ return ret; -+ -+ if (!valid_san) { -+ pkiDebug("%s: did not find an acceptable SAN in user certificate\n", -+ __FUNCTION__); -+ return KRB5KDC_ERR_CLIENT_NAME_MISMATCH; -+ } -+ -+ return 0; -+} -+ -+static krb5_error_code -+pkinit_eku_authorize(krb5_context context, krb5_certauth_moddata moddata, -+ const uint8_t *cert, size_t cert_len, -+ krb5_const_principal princ, const void *opts, -+ const krb5_db_entry *db_entry, char ***authinds_out) -+{ -+ krb5_error_code ret; -+ int valid_eku; -+ const struct certauth_req_opts *req_opts = opts; -+ -+ *authinds_out = NULL; -+ -+ /* Verify the client EKU. */ -+ ret = verify_client_eku(context, req_opts->plgctx, req_opts->reqctx, -+ &valid_eku); -+ if (ret) -+ return ret; -+ -+ if (!valid_eku) { -+ pkiDebug("%s: did not find an acceptable EKU in user certificate\n", -+ __FUNCTION__); -+ return KRB5KDC_ERR_INCONSISTENT_KEY_PURPOSE; -+ } -+ -+ return 0; -+} -+ -+static krb5_error_code -+certauth_pkinit_san_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable) -+{ -+ krb5_certauth_vtable vt; -+ -+ if (maj_ver != 1) -+ return KRB5_PLUGIN_VER_NOTSUPP; -+ vt = (krb5_certauth_vtable)vtable; -+ vt->name = "pkinit_san"; -+ vt->authorize = pkinit_san_authorize; -+ return 0; -+} -+ -+static krb5_error_code -+certauth_pkinit_eku_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable) -+{ -+ krb5_certauth_vtable vt; -+ -+ if (maj_ver != 1) -+ return KRB5_PLUGIN_VER_NOTSUPP; -+ vt = (krb5_certauth_vtable)vtable; -+ vt->name = "pkinit_eku"; -+ vt->authorize = pkinit_eku_authorize; -+ return 0; -+} -+ -+static krb5_error_code -+load_certauth_plugins(krb5_context context, certauth_handle **handle_out) -+{ -+ krb5_error_code ret; -+ krb5_plugin_initvt_fn *modules = NULL, *mod; -+ certauth_handle *list = NULL, h; -+ size_t count; -+ -+ /* Register the builtin modules. */ -+ ret = k5_plugin_register(context, PLUGIN_INTERFACE_CERTAUTH, -+ "pkinit_san", certauth_pkinit_san_initvt); -+ if (ret) -+ goto cleanup; -+ -+ ret = k5_plugin_register(context, PLUGIN_INTERFACE_CERTAUTH, -+ "pkinit_eku", certauth_pkinit_eku_initvt); -+ if (ret) -+ goto cleanup; -+ -+ ret = k5_plugin_load_all(context, PLUGIN_INTERFACE_CERTAUTH, &modules); -+ if (ret) -+ goto cleanup; -+ -+ /* Allocate handle list. */ -+ for (count = 0; modules[count]; count++); -+ list = k5calloc(count + 1, sizeof(*list), &ret); -+ if (list == NULL) -+ goto cleanup; -+ -+ /* Initialize each module, ignoring ones that fail. */ -+ count = 0; -+ for (mod = modules; *mod != NULL; mod++) { -+ h = k5calloc(1, sizeof(*h), &ret); -+ if (h == NULL) -+ goto cleanup; -+ -+ ret = (*mod)(context, 1, 1, (krb5_plugin_vtable)&h->vt); -+ if (ret) { -+ TRACE_CERTAUTH_VTINIT_FAIL(context, ret); -+ free(h); -+ continue; -+ } -+ h->moddata = NULL; -+ if (h->vt.init != NULL) { -+ ret = h->vt.init(context, &h->moddata); -+ if (ret) { -+ TRACE_CERTAUTH_INIT_FAIL(context, h->vt.name, ret); -+ free(h); -+ continue; -+ } -+ } -+ list[count++] = h; -+ list[count] = NULL; -+ } -+ list[count] = NULL; -+ -+ ret = 0; -+ *handle_out = list; -+ list = NULL; -+ -+cleanup: -+ k5_plugin_free_modules(context, modules); -+ free_certauth_handles(context, list); -+ return ret; -+} -+ - static int - pkinit_server_plugin_init(krb5_context context, - krb5_kdcpreauth_moddata *moddata_out, -@@ -1338,6 +1591,8 @@ pkinit_server_plugin_init(krb5_context context, - { - krb5_error_code retval = ENOMEM; - pkinit_kdc_context plgctx, *realm_contexts = NULL; -+ certauth_handle *certauth_modules = NULL; -+ krb5_kdcpreauth_moddata moddata; - size_t i, j; - size_t numrealms; - -@@ -1368,16 +1623,22 @@ pkinit_server_plugin_init(krb5_context context, - goto errout; - } - -- *moddata_out = (krb5_kdcpreauth_moddata)realm_contexts; -- retval = 0; -- pkiDebug("%s: returning context at %p\n", __FUNCTION__, realm_contexts); -+ retval = load_certauth_plugins(context, &certauth_modules); -+ if (retval) -+ goto errout; -+ -+ moddata = k5calloc(1, sizeof(*moddata), &retval); -+ if (moddata == NULL) -+ goto errout; -+ moddata->realm_contexts = realm_contexts; -+ moddata->certauth_modules = certauth_modules; -+ *moddata_out = moddata; -+ pkiDebug("%s: returning context at %p\n", __FUNCTION__, moddata); -+ return 0; - - errout: -- if (retval) { -- pkinit_server_plugin_fini(context, -- (krb5_kdcpreauth_moddata)realm_contexts); -- } -- -+ free_realm_contexts(context, realm_contexts); -+ free_certauth_handles(context, certauth_modules); - return retval; - } - -@@ -1405,17 +1666,11 @@ static void - pkinit_server_plugin_fini(krb5_context context, - krb5_kdcpreauth_moddata moddata) - { -- pkinit_kdc_context *realm_contexts = (pkinit_kdc_context *)moddata; -- int i; -- -- if (realm_contexts == NULL) -+ if (moddata == NULL) - return; -- -- for (i = 0; realm_contexts[i] != NULL; i++) { -- pkinit_server_plugin_fini_realm(context, realm_contexts[i]); -- } -- pkiDebug("%s: freeing context at %p\n", __FUNCTION__, realm_contexts); -- free(realm_contexts); -+ free_realm_contexts(context, moddata->realm_contexts); -+ free_certauth_handles(context, moddata->certauth_modules); -+ free(moddata); - } - - static krb5_error_code -diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h -index b3f5cbb20..458d0961e 100644 ---- a/src/plugins/preauth/pkinit/pkinit_trace.h -+++ b/src/plugins/preauth/pkinit/pkinit_trace.h -@@ -91,4 +91,9 @@ - #define TRACE_PKINIT_OPENSSL_ERROR(c, msg) \ - TRACE(c, "PKINIT OpenSSL error: {str}", msg) - -+#define TRACE_CERTAUTH_VTINIT_FAIL(c, ret) \ -+ TRACE(c, "certauth module failed to init vtable: {kerr}", ret) -+#define TRACE_CERTAUTH_INIT_FAIL(c, name, ret) \ -+ TRACE(c, "certauth module {str} failed to init: {kerr}", name, ret) -+ - #endif /* PKINIT_TRACE_H */ -diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in -index b55469146..0e93d6b59 100644 ---- a/src/tests/Makefile.in -+++ b/src/tests/Makefile.in -@@ -167,6 +167,7 @@ check-pytests: localauth plugorder rdreq responder s2p s4u2proxy unlockiter - $(RUNPYTEST) $(srcdir)/t_preauth.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_princflags.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_tabdump.py $(PYTESTFLAGS) -+ $(RUNPYTEST) $(srcdir)/t_certauth.py $(PYTESTFLAGS) - - clean: - $(RM) adata etinfo forward gcred hist hooks hrealm icred kdbtest -diff --git a/src/tests/t_certauth.py b/src/tests/t_certauth.py -new file mode 100644 -index 000000000..e64a57b0d ---- /dev/null -+++ b/src/tests/t_certauth.py -@@ -0,0 +1,47 @@ -+#!/usr/bin/python -+from k5test import * -+ -+# Skip this test if pkinit wasn't built. -+if not os.path.exists(os.path.join(plugins, 'preauth', 'pkinit.so')): -+ skip_rest('certauth tests', 'PKINIT module not built') -+ -+certs = os.path.join(srctop, 'tests', 'dejagnu', 'pkinit-certs') -+ca_pem = os.path.join(certs, 'ca.pem') -+kdc_pem = os.path.join(certs, 'kdc.pem') -+privkey_pem = os.path.join(certs, 'privkey.pem') -+user_pem = os.path.join(certs, 'user.pem') -+ -+modpath = os.path.join(buildtop, 'plugins', 'certauth', 'test', -+ 'certauth_test.so') -+pkinit_krb5_conf = {'realms': {'$realm': { -+ 'pkinit_anchors': 'FILE:%s' % ca_pem}}, -+ 'plugins': {'certauth': {'module': ['test1:' + modpath, -+ 'test2:' + modpath], -+ 'enable_only': ['test1', 'test2']}}} -+pkinit_kdc_conf = {'realms': {'$realm': { -+ 'default_principal_flags': '+preauth', -+ 'pkinit_eku_checking': 'none', -+ 'pkinit_identity': 'FILE:%s,%s' % (kdc_pem, privkey_pem), -+ 'pkinit_indicator': ['indpkinit1', 'indpkinit2']}}} -+ -+file_identity = 'FILE:%s,%s' % (user_pem, privkey_pem) -+ -+realm = K5Realm(krb5_conf=pkinit_krb5_conf, kdc_conf=pkinit_kdc_conf, -+ get_creds=False) -+ -+# Let the test module match user to CN=user, with indicators. -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % file_identity]) -+realm.klist(realm.user_princ) -+realm.run([kvno, realm.host_princ]) -+realm.run(['./adata', realm.host_princ], -+ expected_msg='+97: [test1, test2, user, indpkinit1, indpkinit2]') -+ -+# Let the test module mismatch with user2 to CN=user. -+realm.addprinc("user2@KRBTEST.COM") -+out = realm.kinit("user2@KRBTEST.COM", -+ flags=['-X', 'X509_user_identity=%s' % file_identity], -+ expected_code=1, -+ expected_msg='kinit: Certificate mismatch') -+ -+success("certauth tests") diff --git a/Add-hostname-based-ccselect-module.patch b/Add-hostname-based-ccselect-module.patch deleted file mode 100644 index b56b8d3..0000000 --- a/Add-hostname-based-ccselect-module.patch +++ /dev/null @@ -1,293 +0,0 @@ -From 632575ab12fc5d6c9bdc83cb8200fb8f4f422b83 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 23 Aug 2017 17:25:17 -0400 -Subject: [PATCH] Add hostname-based ccselect module - -The hostname module selects the ccache whose realm is the longest -parent domain tail of the uppercase server hostname. - -[ghudson@mit.edu: minor edits] - -ticket: 8613 (new) -(cherry picked from commit a4ddc6cf576b4155e6b994307902567f26f752b2) ---- - doc/admin/conf_files/krb5_conf.rst | 4 + - src/lib/krb5/ccache/Makefile.in | 3 + - src/lib/krb5/ccache/cc-int.h | 4 + - src/lib/krb5/ccache/ccselect.c | 5 ++ - src/lib/krb5/ccache/ccselect_hostname.c | 146 ++++++++++++++++++++++++++++++++ - src/tests/gssapi/t_ccselect.py | 9 ++ - 6 files changed, 171 insertions(+) - create mode 100644 src/lib/krb5/ccache/ccselect_hostname.c - -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 1d9bc9e34..9c1ee94a4 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -745,6 +745,10 @@ disabled with the disable tag): - Uses the service realm to guess an appropriate cache from the - collection - -+**hostname** -+ If the service principal is host-based, uses the service hostname -+ to guess an appropriate cache from the collection -+ - .. _pwqual: - - pwqual interface -diff --git a/src/lib/krb5/ccache/Makefile.in b/src/lib/krb5/ccache/Makefile.in -index 5ac870728..f84cf793e 100644 ---- a/src/lib/krb5/ccache/Makefile.in -+++ b/src/lib/krb5/ccache/Makefile.in -@@ -34,6 +34,7 @@ STLIBOBJS= \ - ccdefops.o \ - ccmarshal.o \ - ccselect.o \ -+ ccselect_hostname.o \ - ccselect_k5identity.o \ - ccselect_realm.o \ - cc_dir.o \ -@@ -52,6 +53,7 @@ OBJS= $(OUTPRE)ccbase.$(OBJEXT) \ - $(OUTPRE)ccdefops.$(OBJEXT) \ - $(OUTPRE)ccmarshal.$(OBJEXT) \ - $(OUTPRE)ccselect.$(OBJEXT) \ -+ $(OUTPRE)ccselect_hostname.$(OBJEXT) \ - $(OUTPRE)ccselect_k5identity.$(OBJEXT) \ - $(OUTPRE)ccselect_realm.$(OBJEXT) \ - $(OUTPRE)cc_dir.$(OBJEXT) \ -@@ -70,6 +72,7 @@ SRCS= $(srcdir)/ccbase.c \ - $(srcdir)/ccdefops.c \ - $(srcdir)/ccmarshal.c \ - $(srcdir)/ccselect.c \ -+ $(srcdir)/ccselect_hostname.c \ - $(srcdir)/ccselect_k5identity.c \ - $(srcdir)/ccselect_realm.c \ - $(srcdir)/cc_dir.c \ -diff --git a/src/lib/krb5/ccache/cc-int.h b/src/lib/krb5/ccache/cc-int.h -index ee9b5e0e9..d920367ce 100644 ---- a/src/lib/krb5/ccache/cc-int.h -+++ b/src/lib/krb5/ccache/cc-int.h -@@ -123,6 +123,10 @@ k5_cccol_force_unlock(void); - krb5_error_code - krb5int_fcc_new_unique(krb5_context context, char *template, krb5_ccache *id); - -+krb5_error_code -+ccselect_hostname_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable); -+ - krb5_error_code - ccselect_realm_initvt(krb5_context context, int maj_ver, int min_ver, - krb5_plugin_vtable vtable); -diff --git a/src/lib/krb5/ccache/ccselect.c b/src/lib/krb5/ccache/ccselect.c -index ee4b83a9b..393d39733 100644 ---- a/src/lib/krb5/ccache/ccselect.c -+++ b/src/lib/krb5/ccache/ccselect.c -@@ -71,6 +71,11 @@ load_modules(krb5_context context) - if (ret != 0) - goto cleanup; - -+ ret = k5_plugin_register(context, PLUGIN_INTERFACE_CCSELECT, "hostname", -+ ccselect_hostname_initvt); -+ if (ret != 0) -+ goto cleanup; -+ - ret = k5_plugin_load_all(context, PLUGIN_INTERFACE_CCSELECT, &modules); - if (ret != 0) - goto cleanup; -diff --git a/src/lib/krb5/ccache/ccselect_hostname.c b/src/lib/krb5/ccache/ccselect_hostname.c -new file mode 100644 -index 000000000..475cfabae ---- /dev/null -+++ b/src/lib/krb5/ccache/ccselect_hostname.c -@@ -0,0 +1,146 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* lib/krb5/ccache/ccselect_hostname.c - hostname ccselect module */ -+/* -+ * Copyright (C) 2017 by Red Hat, Inc. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include "k5-int.h" -+#include "cc-int.h" -+#include -+#include -+ -+/* Swap a and b, using tmp as an intermediate. */ -+#define SWAP(a, b, tmp) \ -+ tmp = a; \ -+ a = b; \ -+ b = tmp; -+ -+static krb5_error_code -+hostname_init(krb5_context context, krb5_ccselect_moddata *data_out, -+ int *priority_out) -+{ -+ *data_out = NULL; -+ *priority_out = KRB5_CCSELECT_PRIORITY_HEURISTIC; -+ return 0; -+} -+ -+static krb5_error_code -+hostname_choose(krb5_context context, krb5_ccselect_moddata data, -+ krb5_principal server, krb5_ccache *ccache_out, -+ krb5_principal *princ_out) -+{ -+ krb5_error_code ret; -+ char *p, *host = NULL; -+ size_t hostlen; -+ krb5_cccol_cursor col_cursor; -+ krb5_ccache ccache, tmp_ccache, best_ccache = NULL; -+ krb5_principal princ, tmp_princ, best_princ = NULL; -+ krb5_data domain; -+ -+ *ccache_out = NULL; -+ *princ_out = NULL; -+ -+ if (server->type != KRB5_NT_SRV_HST || server->length < 2) -+ return KRB5_PLUGIN_NO_HANDLE; -+ -+ /* Compute upper-case hostname. */ -+ hostlen = server->data[1].length; -+ host = k5memdup0(server->data[1].data, hostlen, &ret); -+ if (host == NULL) -+ return ret; -+ for (p = host; *p != '\0'; p++) { -+ if (islower(*p)) -+ *p = toupper(*p); -+ } -+ -+ /* Scan the collection for a cache with a client principal whose realm is -+ * the longest tail of the server hostname. */ -+ ret = krb5_cccol_cursor_new(context, &col_cursor); -+ if (ret) -+ goto done; -+ -+ for (ret = krb5_cccol_cursor_next(context, col_cursor, &ccache); -+ ret == 0 && ccache != NULL; -+ ret = krb5_cccol_cursor_next(context, col_cursor, &ccache)) { -+ ret = krb5_cc_get_principal(context, ccache, &princ); -+ if (ret) { -+ krb5_cc_close(context, ccache); -+ break; -+ } -+ -+ /* Check for a longer match than we have. */ -+ domain = make_data(host, hostlen); -+ while (best_princ == NULL || -+ best_princ->realm.length < domain.length) { -+ if (data_eq(princ->realm, domain)) { -+ SWAP(best_ccache, ccache, tmp_ccache); -+ SWAP(best_princ, princ, tmp_princ); -+ break; -+ } -+ -+ /* Try the next parent domain. */ -+ p = memchr(domain.data, '.', domain.length); -+ if (p == NULL) -+ break; -+ domain = make_data(p + 1, hostlen - (p + 1 - host)); -+ } -+ -+ if (ccache != NULL) -+ krb5_cc_close(context, ccache); -+ krb5_free_principal(context, princ); -+ } -+ -+ krb5_cccol_cursor_free(context, &col_cursor); -+ -+ if (best_ccache != NULL) { -+ *ccache_out = best_ccache; -+ *princ_out = best_princ; -+ } else { -+ ret = KRB5_PLUGIN_NO_HANDLE; -+ } -+ -+done: -+ free(host); -+ return ret; -+} -+ -+krb5_error_code -+ccselect_hostname_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable) -+{ -+ krb5_ccselect_vtable vt; -+ -+ if (maj_ver != 1) -+ return KRB5_PLUGIN_VER_NOTSUPP; -+ vt = (krb5_ccselect_vtable)vtable; -+ vt->name = "hostname"; -+ vt->init = hostname_init; -+ vt->choose = hostname_choose; -+ return 0; -+} -diff --git a/src/tests/gssapi/t_ccselect.py b/src/tests/gssapi/t_ccselect.py -index 668a2cc62..3503f9269 100755 ---- a/src/tests/gssapi/t_ccselect.py -+++ b/src/tests/gssapi/t_ccselect.py -@@ -33,6 +33,7 @@ host1 = 'p:' + r1.host_princ - host2 = 'p:' + r2.host_princ - foo = 'foo.krbtest.com' - foo2 = 'foo.krbtest2.com' -+foobar = "foo.bar.krbtest.com" - - # These strings specify the target as a GSS name. The resulting - # principal will have the host-based type, with the referral realm -@@ -42,6 +43,7 @@ foo2 = 'foo.krbtest2.com' - # single component. - gssserver = 'h:host@' + foo - gssserver2 = 'h:host@' + foo2 -+gssserver_bar = 'h:host@' + foobar - gsslocal = 'h:host@localhost' - - # refserver specifies the target as a principal in the referral realm. -@@ -77,10 +79,12 @@ r1.addprinc('host/localhost') - r2.addprinc('host/localhost') - r1.addprinc('host/' + foo) - r2.addprinc('host/' + foo2) -+r1.addprinc('host/' + foobar) - r1.extract_keytab('host/localhost', r1.keytab) - r2.extract_keytab('host/localhost', r2.keytab) - r1.extract_keytab('host/' + foo, r1.keytab) - r2.extract_keytab('host/' + foo2, r2.keytab) -+r1.extract_keytab('host/' + foobar, r1.keytab) - - # Get tickets for one user in each realm (zaphod will be primary). - r1.kinit(alice, password('alice')) -@@ -128,6 +132,11 @@ output = r2.run(['./t_ccselect', gsslocal]) - if output != (zaphod + '\n'): - fail('zaphod not chosen via default realm fallback') - -+# Check that realm ccselect fallback works correctly -+r1.run(['./t_ccselect', gssserver_bar], expected_msg=alice) -+r2.kinit(zaphod, password('zaphod')) -+r1.run(['./t_ccselect', gssserver_bar], expected_msg=alice) -+ - # Get a second cred in r1 (bob will be primary). - r1.kinit(bob, password('bob')) - diff --git a/Add-k5test-expected_msg-expected_trace.patch b/Add-k5test-expected_msg-expected_trace.patch deleted file mode 100644 index 16c1012..0000000 --- a/Add-k5test-expected_msg-expected_trace.patch +++ /dev/null @@ -1,96 +0,0 @@ -From 9c6f61e30e11eca5c04daa3f0dce398602ef5801 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 17 Jan 2017 11:24:41 -0500 -Subject: [PATCH] Add k5test expected_msg, expected_trace - -In k5test.py, add the optional keyword argument "expected_msg" to -methods that run commands, to make it easier to look for substrings in -the command output. Add the optional keyword "expected_trace" to run -the command with KRB5_TRACE enabled and look for an ordered series of -substrings in the trace output. - -(cherry picked from commit 8bb5fce69a4aa6c3082fa7def66a93974e10e17a) -[rharwood@redhat.com: Removed .gitignore change] ---- - src/config/post.in | 2 +- - src/util/k5test.py | 37 ++++++++++++++++++++++++++++++++++--- - 2 files changed, 35 insertions(+), 4 deletions(-) - -diff --git a/src/config/post.in b/src/config/post.in -index 7c7d86dc9..3643abad1 100644 ---- a/src/config/post.in -+++ b/src/config/post.in -@@ -156,7 +156,7 @@ clean: clean-$(WHAT) - - clean-unix:: - $(RM) $(OBJS) $(DEPTARGETS_CLEAN) $(EXTRA_FILES) -- $(RM) et-[ch]-*.et et-[ch]-*.[ch] testlog -+ $(RM) et-[ch]-*.et et-[ch]-*.[ch] testlog testtrace - -$(RM) -r testdir - - clean-windows:: -diff --git a/src/util/k5test.py b/src/util/k5test.py -index c3d026377..4d30baf40 100644 ---- a/src/util/k5test.py -+++ b/src/util/k5test.py -@@ -223,8 +223,11 @@ Scripts may use the following realm methods and attributes: - command-line debugging options. Fail if the command does not return - 0. Log the command output appropriately, and return it as a single - multi-line string. Keyword arguments can contain input='string' to -- send an input string to the command, and expected_code=N to expect a -- return code other than 0. -+ send an input string to the command, expected_code=N to expect a -+ return code other than 0, expected_msg=MSG to expect a substring in -+ the command output, and expected_trace=('a', 'b', ...) to expect an -+ ordered series of line substrings in the command's KRB5_TRACE -+ output. - - * realm.kprop_port(): Returns a port number based on realm.portbase - intended for use by kprop and kpropd. -@@ -647,10 +650,31 @@ def _stop_or_shell(stop, shell, env, ind): - subprocess.call(os.getenv('SHELL'), env=env) - - --def _run_cmd(args, env, input=None, expected_code=0): -+# Read tracefile and look for the expected strings in successive lines. -+def _check_trace(tracefile, expected): -+ output('*** Trace output for previous command:\n') -+ i = 0 -+ with open(tracefile, 'r') as f: -+ for line in f: -+ output(line) -+ if i < len(expected) and expected[i] in line: -+ i += 1 -+ if i < len(expected): -+ fail('Expected string not found in trace output: ' + expected[i]) -+ -+ -+def _run_cmd(args, env, input=None, expected_code=0, expected_msg=None, -+ expected_trace=None): - global null_input, _cmd_index, _last_cmd, _last_cmd_output, _debug - global _stop_before, _stop_after, _shell_before, _shell_after - -+ if expected_trace is not None: -+ tracefile = 'testtrace' -+ if os.path.exists(tracefile): -+ os.remove(tracefile) -+ env = env.copy() -+ env['KRB5_TRACE'] = tracefile -+ - if (_match_cmdnum(_debug, _cmd_index)): - return _debug_cmd(args, env, input) - -@@ -679,6 +703,13 @@ def _run_cmd(args, env, input=None, expected_code=0): - # Check the return code and return the output. - if code != expected_code: - fail('%s failed with code %d.' % (args[0], code)) -+ -+ if expected_msg is not None and expected_msg not in outdata: -+ fail('Expected string not found in command output: ' + expected_msg) -+ -+ if expected_trace is not None: -+ _check_trace(tracefile, expected_trace) -+ - return outdata - - diff --git a/Add-support-to-query-the-SSF-of-a-GSS-context.patch b/Add-support-to-query-the-SSF-of-a-GSS-context.patch deleted file mode 100644 index 299b0a4..0000000 --- a/Add-support-to-query-the-SSF-of-a-GSS-context.patch +++ /dev/null @@ -1,419 +0,0 @@ -From a3408731e3d73f99028f20c3f33caa5a411b430c Mon Sep 17 00:00:00 2001 -From: Simo Sorce -Date: Thu, 30 Mar 2017 11:27:09 -0400 -Subject: [PATCH] Add support to query the SSF of a GSS context - -Cyrus SASL provides a Security Strength Factor number to assess the -relative "strength" of the negotiated mechanism, and applications -sometimes make access control decisions based on it. - -Add a call that allows us to query the mechanism that established the -GSS security context to ask what is the current SSF, based on the -enctype of the session key. - -ticket: 8569 (new) -(cherry picked from commit 7feb7da54c0321b5a3eeb6c3797846a3cf7eda28) -[rharwood@redhat.com: hide GSS_KRB5_GET_CRED_IMPERSONATOR symbol] ---- - src/include/k5-int.h | 1 + - src/lib/crypto/krb/crypto_int.h | 1 + - src/lib/crypto/krb/enctype_util.c | 16 ++++++++++++++++ - src/lib/crypto/krb/etypes.c | 33 ++++++++++++++++++--------------- - src/lib/crypto/libk5crypto.exports | 1 + - src/lib/gssapi/generic/gssapi_ext.h | 11 +++++++++++ - src/lib/gssapi/generic/gssapi_generic.c | 9 +++++++++ - src/lib/gssapi/krb5/gssapiP_krb5.h | 6 ++++++ - src/lib/gssapi/krb5/gssapi_krb5.c | 4 ++++ - src/lib/gssapi/krb5/inq_context.c | 27 +++++++++++++++++++++++++++ - src/lib/gssapi/libgssapi_krb5.exports | 1 + - src/lib/gssapi32.def | 3 +++ - src/lib/krb5_32.def | 3 +++ - src/tests/gssapi/t_enctypes.c | 14 ++++++++++++++ - 14 files changed, 115 insertions(+), 15 deletions(-) - -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index cea644d0a..06ca2b66d 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -2114,6 +2114,7 @@ krb5_get_tgs_ktypes(krb5_context, krb5_const_principal, krb5_enctype **); - krb5_boolean krb5_is_permitted_enctype(krb5_context, krb5_enctype); - - krb5_boolean KRB5_CALLCONV krb5int_c_weak_enctype(krb5_enctype); -+krb5_error_code k5_enctype_to_ssf(krb5_enctype enctype, unsigned int *ssf_out); - - krb5_error_code krb5_kdc_rep_decrypt_proc(krb5_context, const krb5_keyblock *, - krb5_const_pointer, krb5_kdc_rep *); -diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h -index d75b49c69..e5099291e 100644 ---- a/src/lib/crypto/krb/crypto_int.h -+++ b/src/lib/crypto/krb/crypto_int.h -@@ -111,6 +111,7 @@ struct krb5_keytypes { - prf_func prf; - krb5_cksumtype required_ctype; - krb5_flags flags; -+ unsigned int ssf; - }; - - #define ETYPE_WEAK 1 -diff --git a/src/lib/crypto/krb/enctype_util.c b/src/lib/crypto/krb/enctype_util.c -index 0ed74bd6e..b1b40e7ec 100644 ---- a/src/lib/crypto/krb/enctype_util.c -+++ b/src/lib/crypto/krb/enctype_util.c -@@ -131,3 +131,19 @@ krb5_enctype_to_name(krb5_enctype enctype, krb5_boolean shortest, - return ENOMEM; - return 0; - } -+ -+/* The security of a mechanism cannot be summarized with a simple integer -+ * value, but we provide a per-enctype value for Cyrus SASL's SSF. */ -+krb5_error_code -+k5_enctype_to_ssf(krb5_enctype enctype, unsigned int *ssf_out) -+{ -+ const struct krb5_keytypes *ktp; -+ -+ *ssf_out = 0; -+ -+ ktp = find_enctype(enctype); -+ if (ktp == NULL) -+ return EINVAL; -+ *ssf_out = ktp->ssf; -+ return 0; -+} -diff --git a/src/lib/crypto/krb/etypes.c b/src/lib/crypto/krb/etypes.c -index 0e5e977d4..53d4a5c79 100644 ---- a/src/lib/crypto/krb/etypes.c -+++ b/src/lib/crypto/krb/etypes.c -@@ -42,7 +42,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_des_string_to_key, k5_rand2key_des, - krb5int_des_prf, - CKSUMTYPE_RSA_MD5_DES, -- ETYPE_WEAK }, -+ ETYPE_WEAK, 56 }, - { ENCTYPE_DES_CBC_MD4, - "des-cbc-md4", { 0 }, "DES cbc mode with RSA-MD4", - &krb5int_enc_des, &krb5int_hash_md4, -@@ -51,7 +51,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_des_string_to_key, k5_rand2key_des, - krb5int_des_prf, - CKSUMTYPE_RSA_MD4_DES, -- ETYPE_WEAK }, -+ ETYPE_WEAK, 56 }, - { ENCTYPE_DES_CBC_MD5, - "des-cbc-md5", { "des" }, "DES cbc mode with RSA-MD5", - &krb5int_enc_des, &krb5int_hash_md5, -@@ -60,7 +60,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_des_string_to_key, k5_rand2key_des, - krb5int_des_prf, - CKSUMTYPE_RSA_MD5_DES, -- ETYPE_WEAK }, -+ ETYPE_WEAK, 56 }, - { ENCTYPE_DES_CBC_RAW, - "des-cbc-raw", { 0 }, "DES cbc mode raw", - &krb5int_enc_des, NULL, -@@ -69,7 +69,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_des_string_to_key, k5_rand2key_des, - krb5int_des_prf, - 0, -- ETYPE_WEAK }, -+ ETYPE_WEAK, 56 }, - { ENCTYPE_DES3_CBC_RAW, - "des3-cbc-raw", { 0 }, "Triple DES cbc mode raw", - &krb5int_enc_des3, NULL, -@@ -78,7 +78,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_dk_string_to_key, k5_rand2key_des3, - NULL, /*PRF*/ - 0, -- ETYPE_WEAK }, -+ ETYPE_WEAK, 112 }, - - { ENCTYPE_DES3_CBC_SHA1, - "des3-cbc-sha1", { "des3-hmac-sha1", "des3-cbc-sha1-kd" }, -@@ -89,7 +89,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_dk_string_to_key, k5_rand2key_des3, - krb5int_dk_prf, - CKSUMTYPE_HMAC_SHA1_DES3, -- 0 /*flags*/ }, -+ 0 /*flags*/, 112 }, - - { ENCTYPE_DES_HMAC_SHA1, - "des-hmac-sha1", { 0 }, "DES with HMAC/sha1", -@@ -99,7 +99,10 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_dk_string_to_key, k5_rand2key_des, - NULL, /*PRF*/ - 0, -- ETYPE_WEAK }, -+ ETYPE_WEAK, 56 }, -+ -+ /* rc4-hmac uses a 128-bit key, but due to weaknesses in the RC4 cipher, we -+ * consider its strength degraded and assign it an SSF value of 64. */ - { ENCTYPE_ARCFOUR_HMAC, - "arcfour-hmac", { "rc4-hmac", "arcfour-hmac-md5" }, - "ArcFour with HMAC/md5", -@@ -110,7 +113,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_arcfour_decrypt, krb5int_arcfour_string_to_key, - k5_rand2key_direct, krb5int_arcfour_prf, - CKSUMTYPE_HMAC_MD5_ARCFOUR, -- 0 /*flags*/ }, -+ 0 /*flags*/, 64 }, - { ENCTYPE_ARCFOUR_HMAC_EXP, - "arcfour-hmac-exp", { "rc4-hmac-exp", "arcfour-hmac-md5-exp" }, - "Exportable ArcFour with HMAC/md5", -@@ -121,7 +124,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_arcfour_decrypt, krb5int_arcfour_string_to_key, - k5_rand2key_direct, krb5int_arcfour_prf, - CKSUMTYPE_HMAC_MD5_ARCFOUR, -- ETYPE_WEAK -+ ETYPE_WEAK, 40 - }, - - { ENCTYPE_AES128_CTS_HMAC_SHA1_96, -@@ -133,7 +136,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_aes_string_to_key, k5_rand2key_direct, - krb5int_dk_prf, - CKSUMTYPE_HMAC_SHA1_96_AES128, -- 0 /*flags*/ }, -+ 0 /*flags*/, 128 }, - { ENCTYPE_AES256_CTS_HMAC_SHA1_96, - "aes256-cts-hmac-sha1-96", { "aes256-cts", "aes256-sha1" }, - "AES-256 CTS mode with 96-bit SHA-1 HMAC", -@@ -143,7 +146,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_aes_string_to_key, k5_rand2key_direct, - krb5int_dk_prf, - CKSUMTYPE_HMAC_SHA1_96_AES256, -- 0 /*flags*/ }, -+ 0 /*flags*/, 256 }, - - { ENCTYPE_CAMELLIA128_CTS_CMAC, - "camellia128-cts-cmac", { "camellia128-cts" }, -@@ -155,7 +158,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_camellia_string_to_key, k5_rand2key_direct, - krb5int_dk_cmac_prf, - CKSUMTYPE_CMAC_CAMELLIA128, -- 0 /*flags*/ }, -+ 0 /*flags*/, 128 }, - { ENCTYPE_CAMELLIA256_CTS_CMAC, - "camellia256-cts-cmac", { "camellia256-cts" }, - "Camellia-256 CTS mode with CMAC", -@@ -166,7 +169,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_camellia_string_to_key, k5_rand2key_direct, - krb5int_dk_cmac_prf, - CKSUMTYPE_CMAC_CAMELLIA256, -- 0 /*flags */ }, -+ 0 /*flags */, 256 }, - - { ENCTYPE_AES128_CTS_HMAC_SHA256_128, - "aes128-cts-hmac-sha256-128", { "aes128-sha2" }, -@@ -177,7 +180,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_aes2_string_to_key, k5_rand2key_direct, - krb5int_aes2_prf, - CKSUMTYPE_HMAC_SHA256_128_AES128, -- 0 /*flags*/ }, -+ 0 /*flags*/, 128 }, - { ENCTYPE_AES256_CTS_HMAC_SHA384_192, - "aes256-cts-hmac-sha384-192", { "aes256-sha2" }, - "AES-256 CTS mode with 192-bit SHA-384 HMAC", -@@ -187,7 +190,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_aes2_string_to_key, k5_rand2key_direct, - krb5int_aes2_prf, - CKSUMTYPE_HMAC_SHA384_192_AES256, -- 0 /*flags*/ }, -+ 0 /*flags*/, 256 }, - }; - - const int krb5int_enctypes_length = -diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports -index 447e45644..82eb5f30c 100644 ---- a/src/lib/crypto/libk5crypto.exports -+++ b/src/lib/crypto/libk5crypto.exports -@@ -108,3 +108,4 @@ krb5int_nfold - k5_allow_weak_pbkdf2iter - krb5_c_prfplus - krb5_c_derive_prfplus -+k5_enctype_to_ssf -diff --git a/src/lib/gssapi/generic/gssapi_ext.h b/src/lib/gssapi/generic/gssapi_ext.h -index 9ad44216d..9d3a7e736 100644 ---- a/src/lib/gssapi/generic/gssapi_ext.h -+++ b/src/lib/gssapi/generic/gssapi_ext.h -@@ -575,4 +575,15 @@ gss_import_cred( - } - #endif - -+/* -+ * When used with gss_inquire_sec_context_by_oid(), return a buffer set with -+ * the first member containing an unsigned 32-bit integer in network byte -+ * order. This is the Security Strength Factor (SSF) associated with the -+ * secure channel established by the security context. NOTE: This value is -+ * made available solely as an indication for use by APIs like Cyrus SASL that -+ * classify the strength of a secure channel via this number. The strength of -+ * a channel cannot necessarily be represented by a simple number. -+ */ -+GSS_DLLIMP extern gss_OID GSS_C_SEC_CONTEXT_SASL_SSF; -+ - #endif /* GSSAPI_EXT_H_ */ -diff --git a/src/lib/gssapi/generic/gssapi_generic.c b/src/lib/gssapi/generic/gssapi_generic.c -index 5496aa335..fa144c2bf 100644 ---- a/src/lib/gssapi/generic/gssapi_generic.c -+++ b/src/lib/gssapi/generic/gssapi_generic.c -@@ -157,6 +157,13 @@ static const gss_OID_desc const_oids[] = { - {7, (void *)"\x2b\x06\x01\x05\x05\x0d\x19"}, - {7, (void *)"\x2b\x06\x01\x05\x05\x0d\x1a"}, - {7, (void *)"\x2b\x06\x01\x05\x05\x0d\x1b"}, -+ -+ /* -+ * GSS_SEC_CONTEXT_SASL_SSF_OID 1.2.840.113554.1.2.2.5.15 -+ * iso(1) member-body(2) United States(840) mit(113554) -+ * infosys(1) gssapi(2) krb5(2) krb5-gssapi-ext(5) sasl-ssf(15) -+ */ -+ {11, (void *)"\x2a\x86\x48\x86\xf7\x12\x01\x02\x02\x05\x0f"}, - }; - - /* Here are the constants which point to the static structure above. -@@ -218,6 +225,8 @@ GSS_DLLIMP gss_const_OID GSS_C_MA_PFS = oids+33; - GSS_DLLIMP gss_const_OID GSS_C_MA_COMPRESS = oids+34; - GSS_DLLIMP gss_const_OID GSS_C_MA_CTX_TRANS = oids+35; - -+GSS_DLLIMP gss_OID GSS_C_SEC_CONTEXT_SASL_SSF = oids+36; -+ - static gss_OID_set_desc gss_ma_known_attrs_desc = { 27, oids+9 }; - gss_OID_set gss_ma_known_attrs = &gss_ma_known_attrs_desc; - -diff --git a/src/lib/gssapi/krb5/gssapiP_krb5.h b/src/lib/gssapi/krb5/gssapiP_krb5.h -index d7bdef7e2..ef030707e 100644 ---- a/src/lib/gssapi/krb5/gssapiP_krb5.h -+++ b/src/lib/gssapi/krb5/gssapiP_krb5.h -@@ -1144,6 +1144,12 @@ gss_krb5int_extract_authtime_from_sec_context(OM_uint32 *, - const gss_OID, - gss_buffer_set_t *); - -+#define GET_SEC_CONTEXT_SASL_SSF_OID_LENGTH 11 -+#define GET_SEC_CONTEXT_SASL_SSF_OID "\x2a\x86\x48\x86\xf7\x12\x01\x02\x02\x05\x0f" -+OM_uint32 -+gss_krb5int_sec_context_sasl_ssf(OM_uint32 *, const gss_ctx_id_t, -+ const gss_OID, gss_buffer_set_t *); -+ - #define GSS_KRB5_IMPORT_CRED_OID_LENGTH 11 - #define GSS_KRB5_IMPORT_CRED_OID "\x2a\x86\x48\x86\xf7\x12\x01\x02\x02\x05\x0d" - -diff --git a/src/lib/gssapi/krb5/gssapi_krb5.c b/src/lib/gssapi/krb5/gssapi_krb5.c -index 99092ccab..de4131980 100644 ---- a/src/lib/gssapi/krb5/gssapi_krb5.c -+++ b/src/lib/gssapi/krb5/gssapi_krb5.c -@@ -352,6 +352,10 @@ static struct { - { - {GSS_KRB5_EXTRACT_AUTHTIME_FROM_SEC_CONTEXT_OID_LENGTH, GSS_KRB5_EXTRACT_AUTHTIME_FROM_SEC_CONTEXT_OID}, - gss_krb5int_extract_authtime_from_sec_context -+ }, -+ { -+ {GET_SEC_CONTEXT_SASL_SSF_OID_LENGTH, GET_SEC_CONTEXT_SASL_SSF_OID}, -+ gss_krb5int_sec_context_sasl_ssf - } - }; - -diff --git a/src/lib/gssapi/krb5/inq_context.c b/src/lib/gssapi/krb5/inq_context.c -index 9024b3c7e..d2e466e60 100644 ---- a/src/lib/gssapi/krb5/inq_context.c -+++ b/src/lib/gssapi/krb5/inq_context.c -@@ -310,3 +310,30 @@ gss_krb5int_extract_authtime_from_sec_context(OM_uint32 *minor_status, - - return generic_gss_add_buffer_set_member(minor_status, &rep, data_set); - } -+ -+OM_uint32 -+gss_krb5int_sec_context_sasl_ssf(OM_uint32 *minor_status, -+ const gss_ctx_id_t context_handle, -+ const gss_OID desired_object, -+ gss_buffer_set_t *data_set) -+{ -+ krb5_gss_ctx_id_rec *ctx; -+ krb5_key key; -+ krb5_error_code code; -+ gss_buffer_desc ssfbuf; -+ unsigned int ssf; -+ uint8_t buf[4]; -+ -+ ctx = (krb5_gss_ctx_id_rec *)context_handle; -+ key = ctx->have_acceptor_subkey ? ctx->acceptor_subkey : ctx->subkey; -+ -+ code = k5_enctype_to_ssf(key->keyblock.enctype, &ssf); -+ if (code) -+ return GSS_S_FAILURE; -+ -+ store_32_be(ssf, buf); -+ ssfbuf.value = buf; -+ ssfbuf.length = sizeof(buf); -+ -+ return generic_gss_add_buffer_set_member(minor_status, &ssfbuf, data_set); -+} -diff --git a/src/lib/gssapi/libgssapi_krb5.exports b/src/lib/gssapi/libgssapi_krb5.exports -index 9facb3f42..936540e41 100644 ---- a/src/lib/gssapi/libgssapi_krb5.exports -+++ b/src/lib/gssapi/libgssapi_krb5.exports -@@ -37,6 +37,7 @@ GSS_C_MA_CBINDINGS - GSS_C_MA_PFS - GSS_C_MA_COMPRESS - GSS_C_MA_CTX_TRANS -+GSS_C_SEC_CONTEXT_SASL_SSF - gss_accept_sec_context - gss_acquire_cred - gss_acquire_cred_with_password -diff --git a/src/lib/gssapi32.def b/src/lib/gssapi32.def -index 362b9bce8..dff057754 100644 ---- a/src/lib/gssapi32.def -+++ b/src/lib/gssapi32.def -@@ -182,3 +182,6 @@ EXPORTS - gss_verify_mic_iov @146 - ; Added in 1.14 - GSS_KRB5_CRED_NO_CI_FLAGS_X @147 DATA -+; Added in 1.16 -+; GSS_KRB5_GET_CRED_IMPERSONATOR @148 DATA -+ GSS_C_SEC_CONTEXT_SASL_SSF @149 DATA -diff --git a/src/lib/krb5_32.def b/src/lib/krb5_32.def -index e5b560dfc..f7b428e16 100644 ---- a/src/lib/krb5_32.def -+++ b/src/lib/krb5_32.def -@@ -470,3 +470,6 @@ EXPORTS - krb5_get_init_creds_opt_set_pac_request @435 - krb5int_trace @436 ; PRIVATE GSSAPI - krb5_expand_hostname @437 -+ -+; new in 1.16 -+ k5_enctype_to_ssf @438 ; PRIVATE GSSAPI -diff --git a/src/tests/gssapi/t_enctypes.c b/src/tests/gssapi/t_enctypes.c -index a2ad18f47..3fd31e2f8 100644 ---- a/src/tests/gssapi/t_enctypes.c -+++ b/src/tests/gssapi/t_enctypes.c -@@ -32,6 +32,7 @@ - - #include "k5-int.h" - #include "common.h" -+#include "gssapi_ext.h" - - /* - * This test program establishes contexts with the krb5 mech, the default -@@ -86,6 +87,9 @@ main(int argc, char *argv[]) - gss_krb5_lucid_context_v1_t *ilucid, *alucid; - gss_krb5_rfc1964_keydata_t *i1964, *a1964; - gss_krb5_cfx_keydata_t *icfx, *acfx; -+ gss_buffer_set_t bufset = GSS_C_NO_BUFFER_SET; -+ gss_OID ssf_oid = GSS_C_SEC_CONTEXT_SASL_SSF; -+ unsigned int ssf; - size_t count; - void *lptr; - int c; -@@ -139,6 +143,16 @@ main(int argc, char *argv[]) - establish_contexts(&mech_krb5, icred, acred, tname, flags, &ictx, &actx, - NULL, NULL, NULL); - -+ /* Query the SSF value and range-check the result. */ -+ major = gss_inquire_sec_context_by_oid(&minor, ictx, ssf_oid, &bufset); -+ check_gsserr("gss_inquire_sec_context_by_oid(ssf)", major, minor); -+ if (bufset->elements[0].length != 4) -+ errout("SSF buffer has unexpected length"); -+ ssf = load_32_be(bufset->elements[0].value); -+ if (ssf < 56 || ssf > 256) -+ errout("SSF value not within acceptable range (56-256)"); -+ (void)gss_release_buffer_set(&minor, &bufset); -+ - /* Export to lucid contexts. */ - major = gss_krb5_export_lucid_sec_context(&minor, &ictx, 1, &lptr); - check_gsserr("gss_export_lucid_sec_context(initiator)", major, minor); diff --git a/Add-test-case-for-PKINIT-DH-renegotiation.patch b/Add-test-case-for-PKINIT-DH-renegotiation.patch deleted file mode 100644 index 89d695d..0000000 --- a/Add-test-case-for-PKINIT-DH-renegotiation.patch +++ /dev/null @@ -1,45 +0,0 @@ -From 5faadd66bb278bcc1c618e199444e3012eeec215 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 11 Jan 2017 10:49:30 -0500 -Subject: [PATCH] Add test case for PKINIT DH renegotiation - -In t_pkinit.py, add a PKINIT test case where the KDC sends -KDC_ERR_DH_KEY_PARAMETERS_NOT_ACCEPTED and the client retries with the -KDC's TD_DH_PARAMETERS value, using the clpreauth tryagain method. -Use the trace log to verify that the renegotiation actually takes -place. - -(cherry picked from commit 7ad7eb7fd591e6c789ea24b94eccbf74ee4d79f8) ---- - src/tests/t_pkinit.py | 18 ++++++++++++++++++ - 1 file changed, 18 insertions(+) - -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index ac4d326b6..183977750 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -174,6 +174,24 @@ realm.kinit(realm.user_princ, - '-X', 'flag_RSA_PROTOCOL=yes']) - realm.klist(realm.user_princ) - -+# Test a DH parameter renegotiation by temporarily setting a 4096-bit -+# minimum on the KDC. -+tracefile = os.path.join(realm.testdir, 'trace') -+minbits_kdc_conf = {'realms': {'$realm': {'pkinit_dh_min_bits': '4096'}}} -+minbits_env = realm.special_env('restrict', True, kdc_conf=minbits_kdc_conf) -+realm.stop_kdc() -+realm.start_kdc(env=minbits_env) -+realm.run(['env', 'KRB5_TRACE=' + tracefile, kinit, '-X', -+ 'X509_user_identity=' + file_identity, realm.user_princ]) -+with open(tracefile, 'r') as f: -+ trace = f.read() -+if ('Key parameters not accepted' not in trace or -+ 'Preauth tryagain input types' not in trace or -+ 'trying again with KDC-provided parameters' not in trace): -+ fail('DH renegotiation steps not found in kinit trace log') -+realm.stop_kdc() -+realm.start_kdc() -+ - # Run the basic test - PKINIT with FILE: identity, with a password on the key, - # supplied by the prompter. - # Expect failure if the responder does nothing, and we have no prompter. diff --git a/Add-test-cert-generation-to-make-certs.sh.patch b/Add-test-cert-generation-to-make-certs.sh.patch deleted file mode 100644 index eb7df73..0000000 --- a/Add-test-cert-generation-to-make-certs.sh.patch +++ /dev/null @@ -1,968 +0,0 @@ -From 5e3885e9d7c7cd2a19a291cdb1e54312ca7f7e1f Mon Sep 17 00:00:00 2001 -From: Matt Rogers -Date: Mon, 5 Dec 2016 12:22:45 -0500 -Subject: [PATCH] Add test cert generation to make-certs.sh - -Add additional test certificates for UPN matching. Run make-certs.sh -to regenerate certs. - -ticket: 8528 -(cherry picked from commit 5a1d0388ba2e4ec510ed715ce5fbc7f748941425) ---- - src/tests/dejagnu/pkinit-certs/ca.pem | 54 ++++++++++++------------ - src/tests/dejagnu/pkinit-certs/kdc.pem | 50 ++++++++++++---------- - src/tests/dejagnu/pkinit-certs/make-certs.sh | 53 ++++++++++++++++++++++- - src/tests/dejagnu/pkinit-certs/privkey-enc.pem | 52 +++++++++++------------ - src/tests/dejagnu/pkinit-certs/privkey.pem | 50 +++++++++++----------- - src/tests/dejagnu/pkinit-certs/user-enc.p12 | Bin 3029 -> 2837 bytes - src/tests/dejagnu/pkinit-certs/user-upn.p12 | Bin 0 -> 2829 bytes - src/tests/dejagnu/pkinit-certs/user-upn.pem | 28 +++++++++++++ - src/tests/dejagnu/pkinit-certs/user-upn2.p12 | Bin 0 -> 2813 bytes - src/tests/dejagnu/pkinit-certs/user-upn2.pem | 28 +++++++++++++ - src/tests/dejagnu/pkinit-certs/user-upn3.csr | 16 +++++++ - src/tests/dejagnu/pkinit-certs/user-upn3.p12 | Bin 0 -> 2829 bytes - src/tests/dejagnu/pkinit-certs/user-upn3.pem | 28 +++++++++++++ - src/tests/dejagnu/pkinit-certs/user.p12 | Bin 3104 -> 2837 bytes - src/tests/dejagnu/pkinit-certs/user.pem | 56 ++++++++++++------------- - 15 files changed, 283 insertions(+), 132 deletions(-) - create mode 100644 src/tests/dejagnu/pkinit-certs/user-upn.p12 - create mode 100644 src/tests/dejagnu/pkinit-certs/user-upn.pem - create mode 100644 src/tests/dejagnu/pkinit-certs/user-upn2.p12 - create mode 100644 src/tests/dejagnu/pkinit-certs/user-upn2.pem - create mode 100644 src/tests/dejagnu/pkinit-certs/user-upn3.csr - create mode 100644 src/tests/dejagnu/pkinit-certs/user-upn3.p12 - create mode 100644 src/tests/dejagnu/pkinit-certs/user-upn3.pem - -diff --git a/src/tests/dejagnu/pkinit-certs/ca.pem b/src/tests/dejagnu/pkinit-certs/ca.pem -index 55fe02c92..44c917687 100644 ---- a/src/tests/dejagnu/pkinit-certs/ca.pem -+++ b/src/tests/dejagnu/pkinit-certs/ca.pem -@@ -1,29 +1,29 @@ - -----BEGIN CERTIFICATE----- --MIIE5TCCA82gAwIBAgIJANsFDWp1HgAaMA0GCSqGSIb3DQEBBQUAMIGnMQswCQYD --VQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAGA1UEBxMJQ2FtYnJp --ZGdlMQwwCgYDVQQKEwNNSVQxKTAnBgNVBAsTIEluc2VjdXJlIFBraW5pdCBLZXJi --ZXJvcyB0ZXN0IENBMTMwMQYDVQQDFCpwa2luaXQgdGVzdCBzdWl0ZSBDQTsgZG8g --bm90IHVzZSBvdGhlcndpc2UwHhcNMTAwMTA2MTQ1MTI3WhcNMjMwOTE1MTQ1MTI3 --WjCBpzELMAkGA1UEBhMCVVMxFjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNV --BAcTCUNhbWJyaWRnZTEMMAoGA1UEChMDTUlUMSkwJwYDVQQLEyBJbnNlY3VyZSBQ --a2luaXQgS2VyYmVyb3MgdGVzdCBDQTEzMDEGA1UEAxQqcGtpbml0IHRlc3Qgc3Vp --dGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlMIIBIjANBgkqhkiG9w0BAQEFAAOC --AQ8AMIIBCgKCAQEAnYLMe58ny00MgskJP7tZ3PIQRpQkXGLJZKI0HfntCRbIuvmn --ZejPSKdNMyejzRIyjdw1FDJUAnpXYcic3TD5817G5H63UrllAGuy+lhQWNzE6c6K --ueerevR3pMaqHXonaflVasUu5e2AAWVnFbz4x04uLlQejqPwm5sR1xTeLUnVfSY7 --5NbXGIE488iDV0wW8nqGoVWn/TsRd+7KuQUIkJpt8+V6Jk6hPIcPqe6h7mXNGsgc --5dBSqBwVcjU9DbeT4xxxEmgQdLt7qdNwV1ZPLQnTQpogNrT5uf3oSbOTsyM02GOW --riIRmsqq81sfMrpviTRRDwoqTUEhoCSor0UmcwIDAQABo4IBEDCCAQwwHQYDVR0O --BBYEFFn82RUKgTvkFn0cgwyCQpNeWCxYMIHcBgNVHSMEgdQwgdGAFFn82RUKgTvk --Fn0cgwyCQpNeWCxYoYGtpIGqMIGnMQswCQYDVQQGEwJVUzEWMBQGA1UECBMNTWFz --c2FjaHVzZXR0czESMBAGA1UEBxMJQ2FtYnJpZGdlMQwwCgYDVQQKEwNNSVQxKTAn --BgNVBAsTIEluc2VjdXJlIFBraW5pdCBLZXJiZXJvcyB0ZXN0IENBMTMwMQYDVQQD --FCpwa2luaXQgdGVzdCBzdWl0ZSBDQTsgZG8gbm90IHVzZSBvdGhlcndpc2WCCQDb --BQ1qdR4AGjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQBVL2Q6Xubs --gm881cAy6esku17/BSTZur7hCLHTGof1ZKNcCXALjmwNYNC3tl6owqpX8CSdBdsD --Bw/Vs9p3mqnaVEoZc8uW8zS6LoAQbcqiYdQHdEXMh3ec8uvAfmdlQsIsm5Ux8q8L --NM6bKnUOqOFOHme+RC4FGOLb8JqnnuQdwyIZaUyQP6hXbw4zyDphfgo1ZlZn20xh --I555kPfAZKEi/d3WY0oN4k+sfCs9tWRNjmqZfKkH1OqRpjCFGG0b0vY77MFRMuPz --YtN2iD3plgla7KkUMljp9th/Z8Ok79uA1TNLYKzoBjlAX0vToxfa8rrSNo1dHFKT --e5Tj7+29DE4I -+MIIE5TCCA82gAwIBAgIBATANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx -+FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG -+A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz -+dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug -+b3RoZXJ3aXNlMB4XDTE2MTIxMjE0NDYzOVoXDTI3MTEyNTE0NDYzOVowgacxCzAJ -+BgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNldHRzMRIwEAYDVQQHDAlDYW1i -+cmlkZ2UxDDAKBgNVBAoMA01JVDEpMCcGA1UECwwgSW5zZWN1cmUgUEtJTklUIEtl -+cmJlcm9zIHRlc3QgQ0ExMzAxBgNVBAMMKnBraW5pdCB0ZXN0IHN1aXRlIENBOyBk -+byBub3QgdXNlIG90aGVyd2lzZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC -+ggEBANOWvXDyubZ/Kf8QYdPSRk/rsogzqS0rycNEJp/6rPpTS40UxGae5MyLHfmN -+l2mSevRoHSqhb7cfT6n9kR2kb3HB0qhhhecHey4sGwd+m7WMhBQgVtYaiWkuEQDC -+7/SWkRYzmYX8J41vrQulXU2/2pOQCmG4NKPsNo+vcKoT2SHl6qr3lflUaIG0wDu4 -+bFrWszkxcuSkU7SSXDf2xTTTJ8QftO6WQY3g0+dAhbjZFKxRO5uipxURez5EemVs -+Re86vXEILka85tiVS4maCn3l3FWMqcBHRFNa+/osTb0J/OmvvdQ3bzvscG7KDRtM -+bRUnpWClr5R+AbGVvKocj5I1+G0CAwEAAaOCARgwggEUMB0GA1UdDgQWBBRrwMkO -+fMoN3ofjotSWjK0c27fYYjCB1AYDVR0jBIHMMIHJgBRrwMkOfMoN3ofjotSWjK0c -+27fYYqGBraSBqjCBpzELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0 -+dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoGA1UECgwDTUlUMSkwJwYDVQQLDCBJ -+bnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVzdCBDQTEzMDEGA1UEAwwqcGtpbml0 -+IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlggEBMAsGA1UdDwQE -+AwIB/jAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAN82zurZwM -+TugUG6b1symxXxOdDqwinwIlQjzXJ8mTRv31q+YwNdYvdWn1aex8v44qjFDjEP80 -+83y18CjjBHznwxsHll80QmFHjpy6xtRrUC/Ak7jfKnDiTKQYBdgmF4/UiVQu354e -+QI6jPMQlrWZXThlRuBjM55hs4tgRYeTgbd4VSZzVQXdm2ViZkg8SGqw0R2ZRnG91 -+dfXkhu/tTruguPAT3MQ2pTK/CoHHA4W2piQbBDqIl83fphRhYxyW/cCF2mvZZUhE -+AfWhgYDeTDxHKG3Jfmm+ujMo5HscgeUpJ7XjZdobNhkQjD1piyuGzFkUfo2XzA6m -+kMz4Jq4cnvpz - -----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/pkinit-certs/kdc.pem b/src/tests/dejagnu/pkinit-certs/kdc.pem -index 5575ab579..8820ad447 100644 ---- a/src/tests/dejagnu/pkinit-certs/kdc.pem -+++ b/src/tests/dejagnu/pkinit-certs/kdc.pem -@@ -1,25 +1,29 @@ - -----BEGIN CERTIFICATE----- --MIIEMjCCAxqgAwIBAgIBAjANBgkqhkiG9w0BAQUFADCBpzELMAkGA1UEBhMCVVMx --FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcTCUNhbWJyaWRnZTEMMAoG --A1UEChMDTUlUMSkwJwYDVQQLEyBJbnNlY3VyZSBQa2luaXQgS2VyYmVyb3MgdGVz --dCBDQTEzMDEGA1UEAxQqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug --b3RoZXJ3aXNlMB4XDTEwMDEwNjE0NTgwOFoXDTIzMDkxNTE0NTgwOFowSjELMAkG --A1UEBhMCVVMxFjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxFTATBgNVBAoTDEtSQlRF --U1QuQ09NIDEMMAoGA1UECxMDS0RDMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB --CgKCAQEAnYLMe58ny00MgskJP7tZ3PIQRpQkXGLJZKI0HfntCRbIuvmnZejPSKdN --MyejzRIyjdw1FDJUAnpXYcic3TD5817G5H63UrllAGuy+lhQWNzE6c6KueerevR3 --pMaqHXonaflVasUu5e2AAWVnFbz4x04uLlQejqPwm5sR1xTeLUnVfSY75NbXGIE4 --88iDV0wW8nqGoVWn/TsRd+7KuQUIkJpt8+V6Jk6hPIcPqe6h7mXNGsgc5dBSqBwV --cjU9DbeT4xxxEmgQdLt7qdNwV1ZPLQnTQpogNrT5uf3oSbOTsyM02GOWriIRmsqq --81sfMrpviTRRDwoqTUEhoCSor0UmcwIDAQABo4HEMIHBMAkGA1UdEwQCMAAwCwYD --VR0PBAQDAgPoMBIGA1UdJQQLMAkGBysGAQUCAwUwHQYDVR0OBBYEFFn82RUKgTvk --Fn0cgwyCQpNeWCxYMB8GA1UdIwQYMBaAFFn82RUKgTvkFn0cgwyCQpNeWCxYMAkG --A1UdEgQCMAAwSAYDVR0RBEEwP6A9BgYrBgEFAgKgMzAxoA0bC0tSQlRFU1QuQ09N --oSAwHqADAgEBoRcwFRsGa3JidGd0GwtLUkJURVNULkNPTTANBgkqhkiG9w0BAQUF --AAOCAQEAP0byILHLWPyGlv/1HN34DfIpLdVkgGar2yceMtZ2v/7UjeA5PlZc8DFM --20bTq/vIN0eWDTPLI57e+MzQTMxs2UHsic4su0m5DG0cvQTsBXRK51CW/qUF+4n0 --qSEORULiDF6LNoo8akoLukNBhzBh+aqYt4aB46hhsmDmNZTDP1CXsNGHQI9/L52l --oqpUGx8tBpKIFos95PSajXrQn2u66rSMMi4aawitM2igurHPDMbC+XvEYMtXpOS5 --3PEzXEYiSV3TWLTzIE9ytswHeZyHCbp7XHx0LVZFxzqtIe4qmwJJOGhlbH21Izr4 --feF5h5e2ZrOVREY4cKkJmJhEwsqBVA== -+MIIE4TCCA8mgAwIBAgIBAjANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx -+FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG -+A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz -+dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug -+b3RoZXJ3aXNlMB4XDTE2MTIxMjE0NDYzOVoXDTI3MTEyNTE0NDYzOVowSTELMAkG -+A1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxFDASBgNVBAoMC0tSQlRF -+U1QuQ09NMQwwCgYDVQQDDANLREMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK -+AoIBAQDTlr1w8rm2fyn/EGHT0kZP67KIM6ktK8nDRCaf+qz6U0uNFMRmnuTMix35 -+jZdpknr0aB0qoW+3H0+p/ZEdpG9xwdKoYYXnB3suLBsHfpu1jIQUIFbWGolpLhEA -+wu/0lpEWM5mF/CeNb60LpV1Nv9qTkAphuDSj7DaPr3CqE9kh5eqq95X5VGiBtMA7 -+uGxa1rM5MXLkpFO0klw39sU00yfEH7TulkGN4NPnQIW42RSsUTuboqcVEXs+RHpl -+bEXvOr1xCC5GvObYlUuJmgp95dxVjKnAR0RTWvv6LE29Cfzpr73UN2877HBuyg0b -+TG0VJ6Vgpa+UfgGxlbyqHI+SNfhtAgMBAAGjggFzMIIBbzAdBgNVHQ4EFgQUa8DJ -+DnzKDd6H46LUloytHNu32GIwgdQGA1UdIwSBzDCByYAUa8DJDnzKDd6H46LUloyt -+HNu32GKhga2kgaowgacxCzAJBgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNl -+dHRzMRIwEAYDVQQHDAlDYW1icmlkZ2UxDDAKBgNVBAoMA01JVDEpMCcGA1UECwwg -+SW5zZWN1cmUgUEtJTklUIEtlcmJlcm9zIHRlc3QgQ0ExMzAxBgNVBAMMKnBraW5p -+dCB0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZYIBATALBgNVHQ8E -+BAMCA+gwDAYDVR0TAQH/BAIwADBIBgNVHREEQTA/oD0GBisGAQUCAqAzMDGgDRsL -+S1JCVEVTVC5DT02hIDAeoAMCAQGhFzAVGwZrcmJ0Z3QbC0tSQlRFU1QuQ09NMBIG -+A1UdJQQLMAkGBysGAQUCAwUwDQYJKoZIhvcNAQELBQADggEBABJpKRfoFxyOUp9i -+Z/fWql5anJuZElgBSbEC5sL2mMcmL/1vqkiYF3uF6/Z9g4X1LX4QDuvaXCJSdQ+b -+JpmhklSyFN+E/agxZtSim+AjTgYJ0y+jwNvX6kZQ8fW3VLNJZ+zbb4n4txfgSROn -+7ub+02mo4DYajyD9TE/qLzmVaiKLEKW0osjxX3fB1RN/d7zm//NDPsezzUzmKkgz -+u0ML7HGYUNY3+/SC4ShF/But1IoY3/I46lB6BMrIn9X6fsVKlipqrRFniUk0qDlJ -+fbKVB+MvGEFoqFNlMoGiufmDjnJl4PQZCVEmXO8wAVGeK8NpTBCjltAAsoVJVnjq -+AC5jSAM= - -----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/pkinit-certs/make-certs.sh b/src/tests/dejagnu/pkinit-certs/make-certs.sh -index b82ef6f83..0f07709b0 100755 ---- a/src/tests/dejagnu/pkinit-certs/make-certs.sh -+++ b/src/tests/dejagnu/pkinit-certs/make-certs.sh -@@ -4,7 +4,9 @@ NAMETYPE=1 - KEYSIZE=2048 - DAYS=4000 - REALM=KRBTEST.COM -+LOWREALM=krbtest.com - KRB5_PRINCIPAL_SAN=1.3.6.1.5.2.2 -+KRB5_UPN_SAN=1.3.6.1.4.1.311.20.2.3 - PKINIT_KDC_EKU=1.3.6.1.5.2.3.5 - PKINIT_CLIENT_EKU=1.3.6.1.5.2.3.4 - TLS_SERVER_EKU=1.3.6.1.5.5.7.3.1 -@@ -85,6 +87,30 @@ keyUsage = nonRepudiation,digitalSignature,keyEncipherment,keyAgreement - basicConstraints = critical,CA:FALSE - subjectAltName = otherName:$KRB5_PRINCIPAL_SAN;SEQUENCE:krb5princ_client - extendedKeyUsage = $CLIENT_EKU_LIST -+ -+[exts_upn_client] -+subjectKeyIdentifier = hash -+authorityKeyIdentifier = keyid:always,issuer:always -+keyUsage = nonRepudiation,digitalSignature,keyEncipherment,keyAgreement -+basicConstraints = critical,CA:FALSE -+subjectAltName = otherName:$KRB5_UPN_SAN;UTF8:user@$LOWREALM -+extendedKeyUsage = $CLIENT_EKU_LIST -+ -+[exts_upn2_client] -+subjectKeyIdentifier = hash -+authorityKeyIdentifier = keyid:always,issuer:always -+keyUsage = nonRepudiation,digitalSignature,keyEncipherment,keyAgreement -+basicConstraints = critical,CA:FALSE -+subjectAltName = otherName:$KRB5_UPN_SAN;UTF8:user -+extendedKeyUsage = $CLIENT_EKU_LIST -+ -+[exts_upn3_client] -+subjectKeyIdentifier = hash -+authorityKeyIdentifier = keyid:always,issuer:always -+keyUsage = nonRepudiation,digitalSignature,keyEncipherment,keyAgreement -+basicConstraints = critical,CA:FALSE -+subjectAltName = otherName:$KRB5_UPN_SAN;UTF8:user@$REALM -+extendedKeyUsage = $CLIENT_EKU_LIST - EOF - - # Generate a private key. -@@ -113,5 +139,30 @@ openssl pkcs12 -export -in user.pem -inkey privkey.pem -out user.p12 \ - openssl pkcs12 -export -in user.pem -inkey privkey.pem -out user-enc.p12 \ - -passout pass:encrypted - -+# Generate a client certificate and PKCS#12 bundles with a UPN SAN. -+SUBJECT=user openssl req -config openssl.cnf -new -subj /CN=user \ -+ -key privkey.pem -out user-upn.csr -+SUBJECT=user openssl x509 -extfile openssl.cnf -extensions exts_upn_client \ -+ -set_serial 4 -days $DAYS -req -CA ca.pem -CAkey privkey.pem \ -+ -out user-upn.pem -in user-upn.csr -+openssl pkcs12 -export -in user-upn.pem -inkey privkey.pem -out user-upn.p12 \ -+ -passout pass: -+ -+SUBJECT=user openssl req -config openssl.cnf -new -subj /CN=user \ -+ -key privkey.pem -out user-upn2.csr -+SUBJECT=user openssl x509 -extfile openssl.cnf -extensions exts_upn2_client \ -+ -set_serial 5 -days $DAYS -req -CA ca.pem -CAkey privkey.pem \ -+ -out user-upn2.pem -in user-upn2.csr -+openssl pkcs12 -export -in user-upn2.pem -inkey privkey.pem \ -+ -out user-upn2.p12 -passout pass: -+ -+SUBJECT=user openssl req -config openssl.cnf -new -subj /CN=user \ -+ -key privkey.pem -out user-upn3.csr -+SUBJECT=user openssl x509 -extfile openssl.cnf -extensions exts_upn3_client \ -+ -set_serial 6 -days $DAYS -req -CA ca.pem -CAkey privkey.pem \ -+ -out user-upn3.pem -in user-upn3.csr -+openssl pkcs12 -export -in user-upn3.pem -inkey privkey.pem \ -+ -out user-upn3.p12 -passout pass: -+ - # Clean up. --rm -f openssl.cnf kdc.csr user.csr -+rm -f openssl.cnf kdc.csr user.csr user-upn.csr user-upn2.csr user-upn3.csr -diff --git a/src/tests/dejagnu/pkinit-certs/privkey-enc.pem b/src/tests/dejagnu/pkinit-certs/privkey-enc.pem -index 9f7816f17..837fd0b01 100644 ---- a/src/tests/dejagnu/pkinit-certs/privkey-enc.pem -+++ b/src/tests/dejagnu/pkinit-certs/privkey-enc.pem -@@ -1,30 +1,30 @@ - -----BEGIN RSA PRIVATE KEY----- - Proc-Type: 4,ENCRYPTED --DEK-Info: DES-EDE3-CBC,91CA660D6286E453 -+DEK-Info: DES-EDE3-CBC,19FEC334A4D4391D - --DpJ5bo/AN37NcxTNv0Z4d5YomWqyryqYhuA43FlzWWKubld4Gp+owAv5BUd4VLx7 --Efq23ODfuiuh5zna/ZXnY+9m8RHS5AxDd2Kr1s/fVsn+m2Lw9qS69DLjxTjEuDLU --AwmVADqQUbvocZEt0Byn9oY4ku2lGOY/ax7tZ1WegLInnoCqT2xGC6TLw7Gwr3mX --z6xFB2Yv4PbvVU8y4V+ka0p5manxptYkrbAkC+vrC4LPUACdbonmpeXUxAfVV9hL --EMzY74IqY2QS1xFMhbLh2HunfjjC3HZ1wXMf1/LtLl1nnodiOk5o+MTLEHO+npaO --rJn2z3V/eQsr93M8/K5ONQcPAKZGOCmNpNQUj1UHnUHEubhpI+nqRYe3vqem5GaH --8gn+uc1/N6c/Bs037iSLWvkgk8mvHgH/26JobZ8qg9yYgVUl3AIVkkGwLGhE5+Kn --593/p4E5Mb6ttv3ZJ4f3Mz/1b84guhTENY67zxnQEGnpEjfRKoEN1vmHi6mIuWld --rrUCJ/x1Yvy2tN9eyuTNsGCcfvPeY22RrKgl7Wi0EIvBlLPKBQxqXOA7Mi9Acapd --+n5pW2Ka2FABSifZ36owa7SJEJ0GLMtdHmZPirolgIjOZVOMbSj2UuR/kXVZjZUM --LcRcVI1z8NgKF3RKs653HqkphcyRQMMQrL/A38t+v0zFA2P3HPoNWcD+BfKg0H37 --bHPjXdlvAD5yiFXKb1XN99utW5G/qCq5CdzAirm7drxR0bs4ZIV4SwTulvWLW644 --RYes8x7WKg3WUxtair++c1eTwTPhMLz/SxERYXxSUqpxJiRgYTQhwwbE22P6FCWT --H9pso5IMi6AJp35CGaYHi78NPLWVmrxgkkv2uBoDFd/iIQTac60aG/F86aozQD7V --DmHINEcsN3lVUmHinoNTcIfc5EZVEbLQIBhy3XI0UDxWuLnchVlU3ad1OKqknbbi --Ik3lmeLz07JFbpCcMk+xDlQsZYbxcRzyRh0NsWvHXuG77Hbcrnk3ndxT8wADsfOn --foXf1/R/gf7PDmte3nFlpEcJCHyeY1haIqgk4WsnUUKP56O75cGF1ylkaBrDPlLw --WaN2Li537ALo6TyB0jspdCzPqIRt8Gr4muoX0tqFjSfKaWmRb3Y7i6jbVrh8d6KV --xqLse0Vkaip4Lgf/VUWOTvlfHz9nLD0xR6OUPeQ3jxGdhLxmcYec1oRj1aVMlp6f --PyC6TN+NlPEtv6KWWB9OMc420DGOWllvS5+zsm7Ff7/5TkXlWmlhfhrkyQVy8NOe --/3ygPbpSfCFjJMwdbEX+ic/Qjk04f3CluP3FYiIG/Pd6ny6rclrhPHg08X6+sciU --Rj7QtoFpVsDvde2QO0depdoysAG1j1a+sas2lYNPG8hdzbPe20xIJCmF0fWfdxOy --BxxtKzpq46S8xKLfxAMvKrZNuZy5xhs3JMUjpxTIam7ZiQXd752LdzGx2s4CII6d --mkeQ/d32TDACAxyEK8es4Mcm3IoCAq/NjIU/ICwGDeOmfDUpsV2TMrg+aKMKcwUE --UK4bMXercw7Cs0C3o6mdCTFrTtsihHNTrbb7yyN83XK76niSc+LREbuJ8T0vp1Yh -+S6pSicLj30Jlnu2OnYM0eXCvwAHR3xMhhl2N0gheWUGkjicqTdW6ft1qCmGBre9b -+/aTSF1ajvFC+YQ/iABznWNmRNZKCzTK1dQ6P73p83uNqWt/cfe+pVYdeHw3u8NKA -+fscciBtxnHNaAs16GX5/j1XXRPb+zmUe18A+VFMRgctbaurk+KbxO8qVUkzt9NNa -+v5zHkXnaJf6ixL6zR3cOCJWPGy4GmGeFIytQos5Jgn23Pjn8BHAXf39GMs2n6g5V -+eE5RAGDeXqPv/tO1kN0/RSKDeIPvKW6REklXraRUle0PNN5g5l3umSkg4fkplusp -+nTsQCRWkqyVcMpxcf0wy7F2ZPOYIWDt1/pzAHC7y/fl0uCQPz0Qd1smwt0ABKcZv -+m9zaMq6lkKYnBOxPiYIlWVlQi3RLDiQyAWQz/nF0SKsE88SUlB83quySJsZsLKzk -+MR/C+ccSiHqMiDKVj5Ts1go+gbj8Vhlto8jH6ynQj6lrOIczyMmgUa0v0dFH3i3/ -+WL/8ydJ0otY67A8w5yH3hMzRChXQZlpTmH2dDhAv6EzKBi8eIiB0Em+laz5lDv6C -+SfNxZa1/+bSAvXr7LwllUu+Gzbu7MNLwfB2ieTqdFQGA659DjnMqyBGLFzni4Ir0 -+Hi6Uh6yQubTm07oqyUHAsChGFE4Efh4O0rCbKKPZuSVfimUZcE6JM9IjRC/0DIwr -+LZSYqsFgn44byrc62qV2JAE2ua+/4aHHI28hIZ3MDLwyYpCQL/FAUZtqZvni+zgw -+yoHLRDbdrqPps6P71T6Pw6OQzAYC7AL/FsZnLJK78nI+Yai0dpyv/QWiFSXoDEVN -+6vQoDv/VZbNIctr31OE4XyjIMiTpn3FPa3VSbKM4/h7SthjwEV2ONNfR8XQF+siz -+3NhOjEFrZ6UGHvT06wo/hp4CM7u580fNu5HvyCyIwkx9CZRLHvG6Vu0emlzDfQhE -+qxQs6L7IM8A46/LPSTtmEA8Rrn51YY9NChMdY6j3rLe4NLxxOCE6JYaGWVWBBawK -+k3y9z6L9gWRwxEfCgWIutDrYtmA2aj6y/vRS6LrotCNeN5qBx+TdRnh6uCqbi1T8 -+4rF20TVhNZ/l+pkH/ehY9OJ/zpwdbTq4FlE0wWQZB/vwbYP5CZKF+rU6IXnCZEjt -+Ak6Bka9mFm9Z/TvnKIRYiXELq32zOJAuEOQ576tkDX2rAuIQAfE9biX2qo0gbsJo -+1RIfXekRurD/HX54blv5mNqUV34gl+ngPpV5nNDy7RuTAdP77Mu7/ynaPfnM7nqu -+rECbZVv1HZSgTi+7G9SUjn4Bg36p4NiF0/dZ2W70byYIQvNPNqU1kyeSrZk/43te -+NwFgpoAKVbMD1rZ+0xM2YCFFKQZZMN1a5tn8/1TWPlPU28Tu3ZliGeWMdeKd4/MP -+vfH1pE58qVcyOngjLqGkk0L5A7WOAgu+vibKrxGxywwVLx/GfDFqnNr6H0buwXrk -+vuKBTo0r3pcbaZt3kaYBm0d3zznQI1O/pX+eGiNr/rI86j4KC+jUSoKi4BdUeuDN -+p1x6qyEK37kgVXiUyiEXO7e1arLBZMfFRTNKVsN5ewL441eCIgs5gA== - -----END RSA PRIVATE KEY----- -diff --git a/src/tests/dejagnu/pkinit-certs/privkey.pem b/src/tests/dejagnu/pkinit-certs/privkey.pem -index 1825dec4e..7e9beb09a 100644 ---- a/src/tests/dejagnu/pkinit-certs/privkey.pem -+++ b/src/tests/dejagnu/pkinit-certs/privkey.pem -@@ -1,27 +1,27 @@ - -----BEGIN RSA PRIVATE KEY----- --MIIEpQIBAAKCAQEAnYLMe58ny00MgskJP7tZ3PIQRpQkXGLJZKI0HfntCRbIuvmn --ZejPSKdNMyejzRIyjdw1FDJUAnpXYcic3TD5817G5H63UrllAGuy+lhQWNzE6c6K --ueerevR3pMaqHXonaflVasUu5e2AAWVnFbz4x04uLlQejqPwm5sR1xTeLUnVfSY7 --5NbXGIE488iDV0wW8nqGoVWn/TsRd+7KuQUIkJpt8+V6Jk6hPIcPqe6h7mXNGsgc --5dBSqBwVcjU9DbeT4xxxEmgQdLt7qdNwV1ZPLQnTQpogNrT5uf3oSbOTsyM02GOW --riIRmsqq81sfMrpviTRRDwoqTUEhoCSor0UmcwIDAQABAoIBAQCSMh5Tu9S2yUwM --dEZmZiGxhuf+anAZZAOjqT4QeLI/Fmu3yBNM7rq+p7JrAabyp6pOq46EsXXyWtWS --SB742wWUk2quGMNVQAj0TAJyhNgGstr+XJu8k8BBPnlycobhF0lP/oH+uQifl0KR --iSoWLjEG5JTOoXs/UAD6nQMBDDhv9TweEwSyIY9jq1J5Q3wVXm/Nr/FJ/8O53guJ --/TQeo6dtdx6x2+oxKkeWinfxmy2nSoEZd0eb3WUNPZswijO7QgSJolOo83VNqFcn --lj8hYT41zUM4chple8kGnuSV4ql4a1w/52dSTLKJbgukIqvxeDtKNost344eQqkS --Lwcc+NO5AoGBAM0bR8TmFlbP4RJAEOOilXTYgP6Ttd1r1mRXGi3DRPyv4EWGT7WW --MmBHsqU6Mqz+fcoD/AIy1BBdenhaYrrwyCSvitJpoHPjqzOJDX33wUcrnYeincQ3 --PVzpF41O45vTmm692DSJ8t/uR8DhGpCzf/kxuA9ixvdKgMPgBHYeb5zlAoGBAMSY --KZvgwbtlRR25CGaUgOCHtW76puaPcyxEeCbJEKkJO1vZDAf8vi1zXOM4e/gorKHm --349ZrBQfFCrvtZG//KvI12MpjBs0Z/ijSCwS4EkYJaSH+Hm+1ygLdArwWEFkNncL --qQ+Wme1OUoDiAAxRiBKUxUF/pAQqn7X+0MGa2th3AoGBAJ8kRaFu7XJaRUZF01Ts --d4571kqxDXFKFMUyGCvd0Q9G33rSZdJ9QYUW3HP7HgrAQ5WVVdnW2lgAT+BGMUjf --PkvIsKvmLQr+YX3RH1jX/W1dWBM/h64RNll6uj14Mn5bxv2Z68GIL5y0Y5QylMwl --mmwdubSmbb6+Xf6dOJj1sKBJAoGBAJwP0tAMHp6daL2Mmk+cSaZz9KJx1bYnYB1f --CSZ47IHTc0yZQ0S/7VR1ROKXf0njOA+aEBRi8ghTF5ZyDefyySixWdI9NByQgIzP --Sca7AVLlGVTAH4694VzHosngO59FZzsfhYh7XBwW1cW8Ip+kxWlCskgphFFOaNR3 --wM5AGMRHAoGAJELs9VYPRJd7h4dPUa2RqfVPlYkcMwvoLYykY0wE5mjoNaJkQbUr --W5aKhidh4h48fImt2rpB6OYSofYC4yu3VDEr/Kl2nSb8UPE5qEd1pvmdkHSxMNkh --M2diIqot6s2v20lE/6UCqLXonlquRK1MAlyfPw9yZHP9meCvlBsYZXc= -+MIIEowIBAAKCAQEA05a9cPK5tn8p/xBh09JGT+uyiDOpLSvJw0Qmn/qs+lNLjRTE -+Zp7kzIsd+Y2XaZJ69GgdKqFvtx9Pqf2RHaRvccHSqGGF5wd7LiwbB36btYyEFCBW -+1hqJaS4RAMLv9JaRFjOZhfwnjW+tC6VdTb/ak5AKYbg0o+w2j69wqhPZIeXqqveV -++VRogbTAO7hsWtazOTFy5KRTtJJcN/bFNNMnxB+07pZBjeDT50CFuNkUrFE7m6Kn -+FRF7PkR6ZWxF7zq9cQguRrzm2JVLiZoKfeXcVYypwEdEU1r7+ixNvQn86a+91Ddv -+O+xwbsoNG0xtFSelYKWvlH4BsZW8qhyPkjX4bQIDAQABAoIBAH28SS0ygFvLq4gw -+EwJOJYxeswQvNuxp5gcMm6tbyqkjEHVxDtkwuSQ304M1ufF5o2lT6Wko7/sxNyT8 -+Utz7l2JRXL7E3U6R6ohgm1tTyHIVY3OWWCP5Nwjy4BXEwdVmGCfKWAP/+P0ajQmr -+pguK4/fmk9TIIzf6Kd4u0lOvYcu7AYfaBj9OSSF08IoE1EA9gY3Mh9k8C3d3JDhG -+hoJKwMAIX0PRyx6cvmpuAJyPf+19K0/SmzpbdNOHfIXZKtfYw3HxmebhhyCxqNsY -+opI2fpn8joasvfcXICBFRHreSu4nKc8ky6FkMIc5KZRiSP//N3oFM7ZLxciMjfgl -+bCYqST0CgYEA7xfrB4atDYApsmLk92uHnC2bOmJhncfAuLHh8M35fk09Jt6CMYPx -+Ydp4cKYzMemO5zzHxdMnlmISIWWtNbm/gR74KZwOmhFFEP2LE09hpAXRBfQvN5af -+RZwMZ9uyJU5ByecXbIt0cuNerl8sKJfG1S+/maD3dZvr78K4Jd6StTcCgYEA4ozu -+okBTEZ9h7lxdBBbZcO8i/eikPeKnCEBaSryf3K3Pr/k8Ssaa7MYOT9yD+iRwU/uV -+n13BA1I9PvdcWl6ewZdOYX4jCVCIsLs7ed4wfwLxGQMZIVHPZ59lRmVsZFO08g0D -+27U/rUZBpMHl+ppq/FfBjyyUSqayKjcBoFXx0XsCgYAOzQM+pwaldE6gfWDBNEXj -+1Crs1VRHqSr0BAcBmi6cs/laI6IZoJpbvWOBTbiTmWrAQ9H2HBkyRQXsTVgIoGQL -+gThJkyCQRwtoftmSK3LW7Yk//hrCLS/U5lEaSM5hYtPNxOF9VbCywAKHdtrL9IFZ -+hygsQXuwKyPS5tHxfjLExwKBgQC1D+Hg9vvtB67jLBqDHCfopJcYywgJFc5dP+Fp -+/dreKmPkxpMzSAul1Jy3owwvrVPBKz9nwSxzlRSx8Ex1RU4odt8D+CXUWfMFHH7q -+ZXPo7tb2II3DHXlf3fq5CnJYtLXXBiPhQriDqbTpErbVVPjQeOqPnRdfml6mcpPw -+KwA7ZQKBgFzqLmWqy7ZnZdbBo4CUUt6B12eaPCW6YNpOd53zHOphaiZLq4rEhpiZ -+S6JYQTEQYugr0yd6vxsVL2An58niRg1sM6gca9QqBlGMzaQoXaPx6OrLW2WoS5+I -+MmVTeh7yvdop+6gvR8Eoh4cI0HoiJw8oQOOneiXVnh7Izk+WjKXb - -----END RSA PRIVATE KEY----- -diff --git a/src/tests/dejagnu/pkinit-certs/user-enc.p12 b/src/tests/dejagnu/pkinit-certs/user-enc.p12 -index 107480c6d2564a2e60655f29a9984f3009c35a11..049602939def4be1fa9164649b39a801f417e74e 100644 -GIT binary patch -delta 2772 -zcmV;_3M=*17nK%3FoFva0s#Xsf(q9L2`Yw2hW8Bt2LYgh3djV43dAsi3cxUe1$PDs -zDuzgg_YDCD2B3lkXfT2WWC8&IFoFeLkw6`P>Pk7sT{fZm0s;sCfPw`u+L;oVmwM*l -z^A^(IMG+~hWX?aEZU^((3=^fBlyN^uJ1HdaB~86Bo9}9N+iX!V%5OEvtt$|1s1*AD -zSi4_@qyJcutzz!=uO|*1J0QdyMXJ9F0W$DQND|#_%aKA}$m?*9_9e@K*B!h=TVo7= -zMU9jzfb7^C(2Aqpo+PWbs`#J#x*BuH0)VGjB2ly(^0MI0lF7=F#Hzw2C+INlA^N4t -zQGyERj6sz8uZ>M&)xR&um+swj;`PYIw7WY^-c-*m>8DZZQKge>x$dqy#H-~)PY_BM$dd~(Onw}(9&Z?axg}0Z9>TNk$HM5;@0zFIm*-gU`117jbMl3DK%BxZTfFoaazy+Y;K&KQb%|%j4SGGNq>fa9~oCG -zwgvwvlgWm}c<(Owow5C6%<-HJ+#%w}d^yDVJj@KHm7O$cj$%wmqlApelQKGFkb>xi -z&5HN+ZW~fbxGRW%c2vkasI|;g8|kowoTpi`2d$&gAo5M+Cd@-p1~P_!Ft-zz7TTx- -zY=&;!yAmC`w_4KM$YX)1Rw*cdk0678Q7lj?36`+_J(4VyW}Tq4w1Njv41vgs&>dhV -zSy#O>l4{FWV8Oa^*jM@TB-&IwhQ^?iss8sqxRaAy73MP_getDL=XHMi>x{`9P;^eT -zX;^D`Rv!PAqmjC4%L#g1dGlx5N06S76*wky6q4>VTfaR`SZQ6zOcRNJ98dY`dEmKb -z8P}CmkW^L=n%B9Q9|IB&cjOfV8D0G*n}j#+Ae+CPG+aZe8MXo -z`F_a6PkRdLk^jg~O|0#pR0Kh4XB=|!R$IMS=fhN%1ASSURF+C{e}%w%@G#U5K0jS@ -zdqcB9wUuTBoobzl&7kLhWRVF4i_>Aob7rR*b{%KZvHim+x9m@8H0mf6Z^St4G8&LB -zHpTy;XI)>%!4A7DU(WgFp<~_!rjA?yBX>`Ll2{j!#;LZ@Ra|%q6ljZ~oCLM58DO2B -z@@qKlVxyM%_wk^S+2B<;eEl8dI;C75!305v&lHVB%?{%@{fN_lh0Fz3+WhU-rc;Co -zt{pd|08cdwp(y#Ey%DO75wgIM9oZx%m;M@)w+q%#yhOTzM{|0epFFl2%V2B*^zdb# -zLtg+*Pk!JU6r=SE96Y=uWXqmonUaq_U~mhe|Nhs11z$eYsq5r6GvdUIkxPbSa^!JucJ6lunrI!~CYCBHpo`Zlp7W6T -z0R}mN*!=ieFoIWHCQy@x2^a~s%8cQE!@vue=@_6@v&v+9@(+s>=GA{t>n(JibIAkC -zc_Cl8#TZq+<+)Jkbg%{Bk2vlkN)*Sm?_sK9U|~dPYRfTytvvra%6Swxv_}$>R4{GC -z9dlx?of)+8u)G1`(17)Ar}|)emc*7pvv9xmdyDM`V^qSXB8PVe5W(w!XdCZ@{~c9? -z{EuW@x+Vd(`s-b0^6A;0gJC-K(fJr!jN58A+Ayo=k&&lfG4=NM^i(BMI}xs%5TYP@ -z=E+!co_#J#@ZGJ~+ZKh%5>wJ?OBEbcqJ!fd06JoCD0sTevnh -zeYb}GmToDBVSi|c4c)}Znmx{Cob!CF^iezCh?0>3o=y9wlV)5pdPtsk3Dd6eJ&_}N -z40Iz(KJ#BVeo_0Mf!({!#P6toUoXX?w!oM7*9BVb~ -zIG--Gt9ix_oY;+?D3Yc*H_^D|!+$CDRYbeE*wlZk3z1mJyVvza8MJTbTVp{-MR$_Vb -z85o1|GO+9}*jSN6x`o$u_GevO|A1oH2-B5JUOqY2dO1Y3xg@ket~W;HF3_p3ch;8H -zA@hF(dD6pT!-L$M?9BB<@nkRrBfLfUa>Ey?Cx^`yKl#cDagwcp@|}$uh#okmH=tsN4bb+PHefW|Pj%3Vy}fha7a_E$bOa?P -z8FJ-bADHzv$dO)+ZeJzqb&rWk^O*C_S+sv1mnye;2bKg{7eI^pmn(XQKdP_lspwTr -zX3jc1V2jk!Qr(x}g`1t1=n8G+uvgT$sxT}{=y0^ob%Mg>npS<}){)aAx0%V$_o=B_ -z=~`SOSZjK3Bu&8!eRoGV7E#C8aL^u2%VNxK3R0dVoI`UXs6b26vcD9$2c%&DT-1N@ -zOi+2^=KXfZ0E|fDhH@NjFZ=~oJ&x0Gl83}Xbq*W-14JW -z5Npb?m|k`Fk1*3yniB}lEEU`;O%s240Z(1|b?~}E?*rj9DBGvik&Ix=3%@9Wr{Jf? -zK$@qQgGUoLG|`FO53OK&_7?s^fNVpBgzWs{{x=M{I0$#)RqH^t? -z%~@S*78!xW^UhVCcK6>Y=Dv}9xW+urfVcc -zu>g#>iAxh_@0-L1`M|BMF|<{62P8z2r?f5+qTVJtpE~#aF(oh~1_>&LNQU0g$6*WuPSm -z)&=BgN#*52!DdM7rK>Tl7p9;qj%3GuXDxAAtu*4h -zC~9=k?MXWaO9t8Iz|oL*2?Un2l9AE|a$=h6Ph7myik>RjLzPAKR~3exF~gXi7EvqW -zE~9J)1$c|Nk0{8hA?+9+)H9)`@X_yoFgT(r4IA^^MTMj{Qg_G_Ecp5%>Z9~6aEq$I -zqZ#8v{eFLJh^yhFyaXX+Wj){=eEmUmy`7~T2J1-8fxBIne8Km2YT>L%0ByK93;aq*c}2&1oN%Xv@sK}hC3l=wcLZg~cO)e4BA -z9A-09@Eafd$`l!^yiLb`C@H8+r5iaEM;12amg^s3a2XC}sPdDEl<$~&v&Pt^O1_1E -zQLtxqpx7ZB63jv2o#cE0mya%atND;ON*P9$5}aRRDv>sZ{ey&Aj(@1u1CJ9R>^DKP -z^ixMkvsI@5PQIVZ3yi;x99d6)uZU8`4H|tVT|k0A07DTdxKdUroElL%G2hIaX>&z- -zGBw+$uCgJ}c49uynU1`N7tso{NI`B)cx`w%*LIVJ;lKpsWLl6f9RZbB1vefXcRoxN -zf`j3p2&6|(LpTdfF`pzIs5HmQw0{t!f-w%I3Vn3;v*=k3Q$aN;z%(z;Q~Gd!!I0h)kqAw}+m -z)+NTjby%K`)VatpY0W8Hew#n^$E=RUK7nr1>4 -z>iwtm%PM>6uO=PfP>m?)-Gb0cP_7gNctp${p3IyR4R=HRqM7Ltg{E|SIaOHhlurhABd(0~x?Wl|2L82IQ(SU$e^JtfBDf7?-BFe^(x+A2}Ar^U?gLKFd_=+-4d3FF@XI)g-zh -z-YtUJqo^N$Ly5y6L8u>qux4^IlnY>!6%dVBhAqwN2zEP8eon_hpqFqKTTU&#sK5}O -zR_G2^6daRk?y%axch8{tVp@I}&7l#{P0Os;!v}UV1h?=i&-X=pfo-qbS+T++W?ZX%Us-H|5<*D)EJXiAg3Bf>mv`pr~(2A00e>r$U;JEGF6`VoCJzVa0|EX -z?r-cm#ze}S%!%psUL4|O7o)w?aL6CUL2C;@kcy;3mXmu9k5552^YysVU|y}Dt4Tre -zPV>~Ox;FGPu3FhmY0ynI1FpBTH20$$M^SakV6_70&$J`Hks;hNehz)Le^GJSJ=_GN -zH*39XikMG#7>%AiDZORRkOLt30;%lzH4I}kR@``X%@4PRBKiA11Q+_vN>vOuEud{H -z&<_ysqjijW)wp?Ok%G6mho{!?zW9O6j+^7LBvOZo|k^lr?BV+&1Np*EvfVARsB<$IWpEwLanuBXis{e8Dk%c%<_`_Vrl+ -zeqkeQsAX_5vbkPxufliV&E|2DwZd -zb0a{R1$ot?e^yQpL#pUx?VWYRLnMsW%7--ugt4*a$I(}Hbu=0C{2_Z-8}s81q&aI9 -zJV$jFX1!0#)!Qr);z4f0ALns&37-$Ja!$6RBT&!xakOnxj9v0?HEOIy+(jna|HALOL6>+lrjgECvKHr!Gf67D>%p^v_`gSa$$4e+m*4;}Ckz#l?vNJZm2-dM=-bp!>L=k|AGKa`?vcIahAIZmTnuxhxl{YICp3 -zbH$qBcKtQZ8KAYVKc9+^HbatsPu{fE0zFaZHYW(`rDO+*{EDYApMIT5Q32n4CqAZ* -z3o$&+QaVdGHLs9Cc0+|GA=Q3D8!`&+u~`8Oe;^^E@Vz;0#P`PM6$qBdZ)?J)lMoT) -zz)rs=&q(e@F^-GlakAu9)f*&p!LhhDMXuDwQi)vur?~mo6w(T -M3X5P3IRXL*0PAOtl>h($ - -diff --git a/src/tests/dejagnu/pkinit-certs/user-upn.p12 b/src/tests/dejagnu/pkinit-certs/user-upn.p12 -new file mode 100644 -index 0000000000000000000000000000000000000000..7a184f651e50d1443e5fe907b5a11455d69bc0d1 -GIT binary patch -literal 2829 -zcmV+o3-a_Zf(r=(0Ru3C3eN@!Duzgg_YDCD0ic2kzyyK{yfA_axG;hRZw3h}hDe6@ -z4FLxRpn?TpFoFeK0s#Opf(2Cu2`Yw2hW8Bt2LUh~1_~;MNQUKrWafC+r24#=H7D;`er=H*b_6X_JS?p@<Xs@2^$asn4KAS;Hr!s53%;M>!4_lI!jE@siDP@6({Y?SkW5h+LdIH$!` -z_-XqxelFC+82Tg$(YW7cLdVydSw%i;-Dj91iRUVJgL03EKjM>L^g{mUmKBVKsyAB4h;T<*EUp~k -z5rfW}jFu*r0k8Y^g;u6zO^A+%O_lMV@d%&03_Kg*X^^o_Uz{`U5MX67$xAr!e22Ui -zNAXN+;wkb+d}b~b&i1*3(p;Exz@ODQOofrIDJ4q$8bvI|QlJ^WxvF6?PHha;kGKy*Lw>`x5`pX#xOpU&t`! -z7)slT|4hs;jt~|+@{`;8_Mdj$GgX1D7bOQ^)Q}w75-Y#V2+pavIB(a*V$3IEP -zg?T;;_;l~R>6v}Ls7>PH|CSU4@((!&99d`8mJ4VP6tfU( -z4xw}bWH@+eq;9;I?L2T^2F%;7KMe9jrkMY5;~yqZdv|HCk0HHe6ELR7-?nEn3P5tpF1(5hLL=IZuz7bA2y^CwDO;azer* -z!C$qO=WhrA@3Sv;JL{~5A4{ohyNZWeqOYnSDSb7#hu$$uU(aKsIIcB?CZ9J;Z5$lu -z=Cjt}MYS&q`XV#P))k%qT34!b_#XJr>cQ`>q`i7hA!{`l0Mcf&{z`~2DbjCAeFaIZ -zsk<_2+ZB>2+Y`;uY#zb8doC4=Dl8MrvwAKUL`Q@5E -znq+%df~WK#qUD~jzbgmfQeAq_dvu$o@tNNmYJPp4oVJ2u0qBUy8Jxcoc2$6Hz}-~z -zxOwJtoxJUF&6R0oar=qp*4XgOz)zgalsD+2B(!V3Q|`x>a-lDmn?dh^U5F1;y2S0+ -zPRYG~!nEeag~ngC@l&LNQUM2ml0v1jyDvT%JrGqHcV|9L||!v`3Xn^r^f=@jKTTw|8IP`5&TRwiQNz -zuxF)@AE&AXjT8}6AiSS|MLo#|aBOswU;hdcU7DWCd`J>wJYfn542DWQmL+e#>?*H8 -zdH;kV9Zz*4#xxQrPTyNZM>hg4EpEgx#nP4#fobQPcfv18grG+nAHI;bL{ylamN8W@ -zKljh2Bb-jW^J?a^CKm+huNYxBjL<&hBZIF2SK -zVu{~Wpo9P=Pg;QoJ|*nw7DjGB4y_W^t4=uyCXy=!hMY3cGj*tx`I>011gj_pl(O=FX4%Pv8{?*qOk9 -ziMJ9kiDb%Rq~);boeQ_o6Gz>K3&BxCt+`@~nJAh%g!EqIPY9B0ewTqT;whOBDJtl59yda9Br}TXCfgC9#E~QjpuTlPa3D;Kuf{=3 -zeP!#*-6{&>E_LrM8`cuctXs|W@67%V=)pB@oy&Yus -z@2ph_mT_Bq{2J2QMk74-EEJMTAE*X9x#e!==1 -zfh0RBMQN77*2GhWj_q=-;Wz;n_ig?}US0W`OuQS?@DtZzW1f~nnyoPy(0Hx*GdchzpbQ0S0ir-J -zuHsr4irnU(ilPifZg3UpkOD}qmij*p0LDWB`u7D|00oR5NcER_L2r?C?;0s76-g9| -zoP$#^&~mk2OIS|=F_sMsnX8)@2#;-@M`*t=Bh1+Frmnm8t#fylmKL=Kk92~}LueGYkFoKdBM+&*L7DFr$HNMR#9xE?N?M^FnQZJ^OT}z~im)IwW1caxhYM;+?)l -z6FfS#9Zi+;8|~jLBE|RqTDAHS-Es(u*=ip2^4OkHCUs}hqma-3PAVfv2kYkUh7$_j -z2|o2WEq=(;OC)Sg0{2i&3wkEy+s&cco^Hy?ow{G9!#<1CX=U-w;l%M;QxsMc1X{6^ -z@6*5A?zKfo@cDpT+L%OfWgny?;`z+SIpl0Bg=fDrrRB=EaGDD+ODlERhx_l4t_MSA -zZ`6*wF0gJrmlz&9>PSWsZRGWzM9)1?B%hhQDZaPZz)@56+a=hTJ^Gd+X{KWGzD#mq -z-)pP0)q9px96kY?$-{@ArN#H3W~b5SQpD^r{( -zR2Aa>s|ul_3wCEtZPXyZ-^r|UbeSu}@3Tf;uCGgUPxvsJ_f8btP9L)4Gg}HiY);_2 -z+mOZkK=xZm%YI+y7HzaRSCY`jya)D=X|9p -z4i<_VEkh~=A|CY!+4#xR43GCR3n_n$#mB!Q*Caq98D{#S -zG2G6Qx>5L(CX1A+juY-*fdn6FiaFyDIVxdbcL^V(xEaKTCEGE?Eg-?Ir|*F}s^5!F -z?uPI=y0M>KgdCNtoMqO7WN&7|%urZN+YeMK2xf3r~lQ+GSa7%(FHQyBM;pW9P% -zaYm6(pg&99#xo>+!=(tb&Z%7-db}vcu*5eLkNkGZo -zzF*Fi3O>s*3bhY!SM}Vz^#%)mEr-e%Q@4;7yibf%Z7JO1P^k=rogOwEP53EasxnaeY|& -z@#_1`qn`I>sO}W|rUxMujvfdt)Pw>>jdIQ$6rBk!R?Dt3>HE(ioW+$zbs`si)M<^v -zD!WD8%JztN8Hd@%EZTZYNj~AzLgM)N-?t%C&ch~aytdUXOx4wsy9c5Nt&-Emq#f4- -zHl=P`cgVJINMbU#Kdm%;UPucqJ=;5x2HOrGV*FpO|#t8^HM1;b*9+* -z?Zrj8WYTa5?5X87{AmuhQ~{eUOrUJ)e#{c2RMvjrL*+(0axNW{6}k4rWO^+1h+8G`-UW2$QEGKUu2I^6J46a;(RUNp$Kxxh+7_@dXK -zD3E6J{uf}Muo{~}jVZQ{9-6OTAubq-@rVmDa-`b|`7@B!AeO10305~@Dr%6}iV8CQ -zX=X6;)T_SAFS7M$LiE@D+*=b7TUtKh#SiDT!#~CG=`dm~xS(|WMh2cwC -z9xApaX8)-#y$}a)r)<27$PL=Btmpkt47*NBvk8ah#FF41>VQUrT~(jsda)wttvb!- -zM+f8nK~3)SE8Uzv>G&lV4)_-4`%LMHreSl%ftOL3EVsbU&-o^)j+>LMjzQhwIHkzs -zj3_$2&5jM8($vnfB%~s(`|}Z1C!?xTVII!4JlFJ1^Re_w@F9G4mN$!!_KgcobwEi=6Y(|7ZRIDRJGT*_~94IW0yH%-kFs9feQJ1yJn96nt$lA -zzrxgdtPW^+9dj6s89v$x=KzGEryP`-O_BZ+GS2{l%GJ -z;Wg}AbQUBB4M?CzGy8Ssk9A|Hpi;6b7mn2$y?*zP>|QNHc|A(7fn(<1Cf>^n=D2i4 -zKzgEcD}!8bkWoA}X|O@i)yfYB<*)NprS!O-sZn>>{Fs%#IjfvVXcK`c!w>TZC_`)L -z+iDpL1H%ga{1M#fkH5W(UbJ6AdC5@ -zU_?h2EWjXR{7@lx`=c0sVEQ~^7P$v3nigDDUJKG8QvK%lSC^!oJ2OHT0o?DE{uPC?#3C(OA -zki6%DF9nBN!6h`eVtXs4W(A%(^dA#v!!&+b>kELYWpRq53rJne*K(ZpG~HB_^VCt? -zf}PYa%M7*9wP4L>v+TwLKvTK5;tbtW_0s`(G_#F47O@y)BStu}uBOf)QBy-Z*`=tIAm?i4u#!!!3KB7)I -z&S&h+XZ9MjAMs0e`O9!!0W;w!w{oKJ5c?VTVfMz1gdptZe|4k=ORxc1k(BTT-5~lg -z`SxY-DooVB&XB_ZCIRDzQB#oLrY9riA}0Z|8jeaL!SN1ZPMJZ5zHE}mPLR8nKq_{_ -NjEEGCzWl$H{1*d>HH`oO - -literal 0 -HcmV?d00001 - -diff --git a/src/tests/dejagnu/pkinit-certs/user-upn2.pem b/src/tests/dejagnu/pkinit-certs/user-upn2.pem -new file mode 100644 -index 000000000..3a5094c84 ---- /dev/null -+++ b/src/tests/dejagnu/pkinit-certs/user-upn2.pem -@@ -0,0 +1,28 @@ -+-----BEGIN CERTIFICATE----- -+MIIEuTCCA6GgAwIBAgIBBTANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx -+FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG -+A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz -+dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug -+b3RoZXJ3aXNlMB4XDTE2MTIxMjE0NDYzOVoXDTI3MTEyNTE0NDYzOVowSjELMAkG -+A1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxFDASBgNVBAoMC0tSQlRF -+U1QuQ09NMQ0wCwYDVQQDDAR1c2VyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB -+CgKCAQEA05a9cPK5tn8p/xBh09JGT+uyiDOpLSvJw0Qmn/qs+lNLjRTEZp7kzIsd -++Y2XaZJ69GgdKqFvtx9Pqf2RHaRvccHSqGGF5wd7LiwbB36btYyEFCBW1hqJaS4R -+AMLv9JaRFjOZhfwnjW+tC6VdTb/ak5AKYbg0o+w2j69wqhPZIeXqqveV+VRogbTA -+O7hsWtazOTFy5KRTtJJcN/bFNNMnxB+07pZBjeDT50CFuNkUrFE7m6KnFRF7PkR6 -+ZWxF7zq9cQguRrzm2JVLiZoKfeXcVYypwEdEU1r7+ixNvQn86a+91DdvO+xwbsoN -+G0xtFSelYKWvlH4BsZW8qhyPkjX4bQIDAQABo4IBSjCCAUYwHQYDVR0OBBYEFGvA -+yQ58yg3eh+Oi1JaMrRzbt9hiMIHUBgNVHSMEgcwwgcmAFGvAyQ58yg3eh+Oi1JaM -+rRzbt9hioYGtpIGqMIGnMQswCQYDVQQGEwJVUzEWMBQGA1UECAwNTWFzc2FjaHVz -+ZXR0czESMBAGA1UEBwwJQ2FtYnJpZGdlMQwwCgYDVQQKDANNSVQxKTAnBgNVBAsM -+IEluc2VjdXJlIFBLSU5JVCBLZXJiZXJvcyB0ZXN0IENBMTMwMQYDVQQDDCpwa2lu -+aXQgdGVzdCBzdWl0ZSBDQTsgZG8gbm90IHVzZSBvdGhlcndpc2WCAQEwCwYDVR0P -+BAQDAgPoMAwGA1UdEwEB/wQCMAAwHwYDVR0RBBgwFqAUBgorBgEEAYI3FAIDoAYM -+BHVzZXIwEgYDVR0lBAswCQYHKwYBBQIDBDANBgkqhkiG9w0BAQsFAAOCAQEAElYM -+786mUr91z82s6QC0TwP380ze8yJQiaWifHYXiqIPay19M+QG91PvSm7LLZw+ersC -+gEl/mPKrC89XlAFp8b+hJnGq6t6YmeC7OI+FapEMxpxX/X8eqAOQLrGnoq7Pm9/8 -+QtWaKgo09i7rmyykKl3xSU1VktBsmlhNPPNh3x+N4bxea9OIbZonPdDtr5/Yt87/ -+6kBPsGgvUUoIxLw03OmLu8AmKAwJja0FWyu93uCUP4UZWLEGpUhSYC1uUCpAZDNy -+2AtPnxfGUDtvI9eMmyeXVGYXTfkfGZyvB3m9lyIj3VVmhbvr7qLAGQn00dbOHz16 -+r6w2aye0Me0GcU0grg== -+-----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/pkinit-certs/user-upn3.csr b/src/tests/dejagnu/pkinit-certs/user-upn3.csr -new file mode 100644 -index 000000000..958c1e043 ---- /dev/null -+++ b/src/tests/dejagnu/pkinit-certs/user-upn3.csr -@@ -0,0 +1,16 @@ -+-----BEGIN CERTIFICATE REQUEST----- -+MIICjzCCAXcCAQAwSjELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0 -+dHMxFDASBgNVBAoMC0tSQlRFU1QuQ09NMQ0wCwYDVQQDDAR1c2VyMIIBIjANBgkq -+hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA05a9cPK5tn8p/xBh09JGT+uyiDOpLSvJ -+w0Qmn/qs+lNLjRTEZp7kzIsd+Y2XaZJ69GgdKqFvtx9Pqf2RHaRvccHSqGGF5wd7 -+LiwbB36btYyEFCBW1hqJaS4RAMLv9JaRFjOZhfwnjW+tC6VdTb/ak5AKYbg0o+w2 -+j69wqhPZIeXqqveV+VRogbTAO7hsWtazOTFy5KRTtJJcN/bFNNMnxB+07pZBjeDT -+50CFuNkUrFE7m6KnFRF7PkR6ZWxF7zq9cQguRrzm2JVLiZoKfeXcVYypwEdEU1r7 -++ixNvQn86a+91DdvO+xwbsoNG0xtFSelYKWvlH4BsZW8qhyPkjX4bQIDAQABoAAw -+DQYJKoZIhvcNAQELBQADggEBAEMxNp5md+jV5dFC1iSKh2CYl3P4g3UMQ9NjLcyq -+upjJmFiEGkEg/LpH4CoXI03BaD885S7akKPA1J/sG2YIrbl3TpjUJKZoJ8BjNT0L -+tYc+JIODZJEONR34Fh6/1uRU7UkRcJ8Crc83+ML+71O2SRZRJDEOS3tVbdzjEOTj -+HIed6Ia3cu0XeAvhoqRSjh8J0ufoIv3CRRCtRU8ChkmMD64p3kOTlORxWspAF8sm -+Xa53bWIpyuyz/vWwpWfr+fL+Q+BQ1TU39xvy+46AYuQIIKzK9vKZdCElQwFXZs26 -+f53OyZpFjcsT9jJAM54XUxLv5rE3fqZQiBhatPZa2ThHt08= -+-----END CERTIFICATE REQUEST----- -diff --git a/src/tests/dejagnu/pkinit-certs/user-upn3.p12 b/src/tests/dejagnu/pkinit-certs/user-upn3.p12 -new file mode 100644 -index 0000000000000000000000000000000000000000..a9d4780c47d33cd4d409d6ee657a7911381fe753 -GIT binary patch -literal 2829 -zcmV+o3-a_Zf(r=(0Ru3C3eN@!Duzgg_YDCD0ic2kzyyK{yfA_axG;hRZw3h}hDe6@ -z4FLxRpn?TpFoFeK0s#Opf(2Cu2`Yw2hW8Bt2LUh~1_~;MNQU4cR+h_S!1xwTJB>WLrfC_;4Q{WSMU*o- -zn@1qFp2kU-SDex#I*!6h8=!K8qv9pObzLDLmnzWdibwhCfJuy%lF%>17?*+`lBBJM -zmXpRI{I$vJ#9ra!;LI(a-Y;XQ;Lg(@=%$W%N@M`uG=dT?Us_5#Ydy@oR}Jqosz*ey -zVPGvYS6-Lg5~d9q+Kq_7hwvb*@x0}_hvi{GII8!JaJ+M3rIu;J>8y>3=gG`dH0^iR -z|2dL^4OS11LK|#C4SCTCdZoH|NY!h^jRkR_ZBdMalelZlJG~EQsb631B6Pems-P<2 -zy=ikP`PqC(+TZsM6awppC_f0Xl3g4K3t|VAQ*|@tqWP;7pCfxOI}DZ9(iJy)rS*nL -z8a}#DV!e3{QR4jj(Ty7a7d86H_%`o3)tY*5-w|QkembO|Ujs3}!86C73mgV0q^5iP -zuZU!CsXRr9j$1G307B=@uSo~fVS&hEIJ+>AH&cjQ2XBCfI;BM))U5*2LLkNN(0?0u`ndx|WU+*&cfWKL8;~Qf+dr$yMp*|3(UJ$X~0n_~&n<|bR -zOiCnb3@;b`fsYZW;zy3u!xk;pHehyodmHBK(b4`FY+RdV=I@k+phXazTua8A-KghY -zbHI;PA;HtNCqk1?WmxDfVMr;cPF-ev6fv2Fqj2|J6VMXUHxmH&PN -z7i%{(&ibQjorX+L&72F>74o;aDdTY|SfNampj*cW`)4?RC{QhRV~@au<4#(Y1RTbE -z+4)2+UV+lnFK&q(3AJu`R~b$_-o!)-dXZdz3uyEXkjR$GQ+@~Nrzj3Op78qsDTByr -z87^>(n=t}k--9Y2&($W_V$rpuB>QO?+3-dA-pr3g54LFhpSdbUZ|IdewW&nX@Id-7N;;8dTYiF$bj&+Vz -zp+$O4o`v}qtLqJumEjK!5TYC+&IxPxnPJ?qPwid3z%qigSZUd*O)r-j4oE29GsC=< -zw0myiDI9d*4E>t?xOcwEA~EKL0)VbEj&Uc^xro!On)Pjn$+w5R6#oT#|93jg*@V}Z -zk%j`((IQj&TOx`1Bp_153n75Eqw3)xRNoBq49xGry~PpA>RD@*p=h}-LFRPD=V~%O -zL!t(9?TCJvy{&-ipV)bfua3YR-|1T`d;?f_6b0}I+QRRVRCX;HVm@R2;PE+7K -z3Q|#cnBp2{Ho#|+7-NPyucnCX#eD8mEc6JWn6yVrPT1jqs)!%NzfUi>O@f`DTz7r- -zs6~@+cMQii)Zyfm5|I-1^j4{K7>B7|irNe8d;&TQyncnqec(ERvcvZ=HhwevKN)GU -zzDKIn4gl?ZdnRwvb(WT2#ZBk3!kjVDJEGu3Mj^N{FoFd^1_>&LNQU?&x>nfj%n^6>^V7CUp+ -zETM}jN%cj-MzspiSpQ6CYmqrq{b{-|Kj>-Fd1TKY;L3MOk&IO)fs00$bk5ZHGFaBf -zsRg6kCS^21bh?tWf1jQLIaT&uM>-1!L@?~)eWqce&iDF0qMSy`TNzT_)VB-&hdVeW -zjEeXb0i{%KpZeK!$PY01Wa=BLfB6xzk$J9wnQ+$8Q?cOhQWJ^oEshJdhCpbB9?+gW -z%#d0mHXCu4Kr$r>M+VFC+yRsa^lQ^YyqVejN5NolmXwl=j;AXtkvzSNzYdLcLS1M3v(LEqdCXAG^SL1Jy92cADy`hRveJZ&>9tO3Rq_n_U2brOPWo6XM -zre^&}huWluk$ -z+B?xm6(8=jJ-w!B_8@+OFo>mq_>DV#ryewM9%Z)!#3=XxhO#WL%G$~t4CS!5WVoB@ -z9IwU{Qb#y?ADZ8(K#I6quZz_TTCR&i8M?`ng1<++_9q(O>U=r;A$ep&O5PL~0ADX*&QcF)J*1tw=!Jp;oWW92 -zx_WL`bX!>KW=&X!8je^w5L8BljVzqd+B6(1iYw*+a2t*Og-{}@ahG~CSZjlKgN)_F -z_gX^4sG -z?|whq1p%Fu)%2@m@;098MdnS5un)e;6`RgFr)yc~xn2wcd|aAZWeZIH?b=2rqMuuF -zhM;R=1L3DiNIjP$4H_N4*lqU$eq7|>Ys3|ew5^EImFF1cx!T2jaX -zfyvmtstS0orV!Q7PL#g{*$ChxfS!0s;sCZ%;ud - -literal 0 -HcmV?d00001 - -diff --git a/src/tests/dejagnu/pkinit-certs/user-upn3.pem b/src/tests/dejagnu/pkinit-certs/user-upn3.pem -new file mode 100644 -index 000000000..ffedb0d1a ---- /dev/null -+++ b/src/tests/dejagnu/pkinit-certs/user-upn3.pem -@@ -0,0 +1,28 @@ -+-----BEGIN CERTIFICATE----- -+MIIExTCCA62gAwIBAgIBBjANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx -+FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG -+A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz -+dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug -+b3RoZXJ3aXNlMB4XDTE2MTIxMjE0NDYzOVoXDTI3MTEyNTE0NDYzOVowSjELMAkG -+A1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxFDASBgNVBAoMC0tSQlRF -+U1QuQ09NMQ0wCwYDVQQDDAR1c2VyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB -+CgKCAQEA05a9cPK5tn8p/xBh09JGT+uyiDOpLSvJw0Qmn/qs+lNLjRTEZp7kzIsd -++Y2XaZJ69GgdKqFvtx9Pqf2RHaRvccHSqGGF5wd7LiwbB36btYyEFCBW1hqJaS4R -+AMLv9JaRFjOZhfwnjW+tC6VdTb/ak5AKYbg0o+w2j69wqhPZIeXqqveV+VRogbTA -+O7hsWtazOTFy5KRTtJJcN/bFNNMnxB+07pZBjeDT50CFuNkUrFE7m6KnFRF7PkR6 -+ZWxF7zq9cQguRrzm2JVLiZoKfeXcVYypwEdEU1r7+ixNvQn86a+91DdvO+xwbsoN -+G0xtFSelYKWvlH4BsZW8qhyPkjX4bQIDAQABo4IBVjCCAVIwHQYDVR0OBBYEFGvA -+yQ58yg3eh+Oi1JaMrRzbt9hiMIHUBgNVHSMEgcwwgcmAFGvAyQ58yg3eh+Oi1JaM -+rRzbt9hioYGtpIGqMIGnMQswCQYDVQQGEwJVUzEWMBQGA1UECAwNTWFzc2FjaHVz -+ZXR0czESMBAGA1UEBwwJQ2FtYnJpZGdlMQwwCgYDVQQKDANNSVQxKTAnBgNVBAsM -+IEluc2VjdXJlIFBLSU5JVCBLZXJiZXJvcyB0ZXN0IENBMTMwMQYDVQQDDCpwa2lu -+aXQgdGVzdCBzdWl0ZSBDQTsgZG8gbm90IHVzZSBvdGhlcndpc2WCAQEwCwYDVR0P -+BAQDAgPoMAwGA1UdEwEB/wQCMAAwKwYDVR0RBCQwIqAgBgorBgEEAYI3FAIDoBIM -+EHVzZXJAS1JCVEVTVC5DT00wEgYDVR0lBAswCQYHKwYBBQIDBDANBgkqhkiG9w0B -+AQsFAAOCAQEARVeLPouequn86P3LgOZQ9LpP6IHpY2ZQwvNviiA8Zk0hsqFXnmwx -+wr3JtESim3EPuwQtJ3jXp0rxQB02r5r8sg21OjCeAB+vOz3IoF/y6WEYlz67LjMB -+XCB6Fuq80IHhVXWRi7w8dVI8xcADwIOh6fgzwbbk8qV2Lgn2Giivstp+76PnRtEn -+tavWlWW7bQlXkiROYh6u3Y8IvYYoIdlDsXQBFSRE80Rc2jR2XGKAz5CDEZNC7RAH -+Z7ON9HH6IRBOX1ijmXhBl/39QQ5t+ZYgKk8OJpL1RAZlJZtGMBwJtA1aGiAFvqTr -+aCREHZfn9NAFE/szItH7hxWJv9RISUXYmA== -+-----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/pkinit-certs/user.p12 b/src/tests/dejagnu/pkinit-certs/user.p12 -index a7c2baddf67f5a8c6ad97b661f6ff285ecd5bf37..67c3fa2eb01c9fdd543af9172dc63a3955987ed6 100644 -GIT binary patch -delta 2825 -zcmV+k3-L2N;;rqK -zSyqcBB#a`vq%RJm?UQRey5syNN;I{A1gyVwKE~n@jbWz;r@|AM -zlt-Dw4#5`C3%OE;suP^fKAkmd<0stTrax4cKBYi#wmDyWkH@HTEzF9Vzb4z(Px-u%2--OA4DL`@vMDzJ%k+he$KUV+etb#R@X1p^xjIQ -zHHCI2jR$-F?jK09io?qm@M_cn8*o;ql~XNl6dFi83)IqmcEQ`VgCdb<6p=l&wDNBh -zCsi)gZ^pn!adN6tfqjU59L{WP9ZTwex*A&&TJq-rK^pl7CaosnYypN4z4}f_$-a57 -zM>j1uIhmSFRBBso?WIxHcvNXh7@BuA#OSnOJLPr!CPo6T$^vk}CF!iZW?)pB$=3O@ -zrfxe$v8EVwa|3H6ER9y+OaA^AN?sy_V(?K!suZGEvWScYsU%j8Tm223XbjYUAviV< -zjRVqXMw@vdf|o5^9wFcIr=5rw4>$56__Xd6#^Qsv`g(v1=Q8> -ziP0(7aSZ@G=xc!){8#vY(P0#=2i#b!H0mS*tnBJn+%XiU^}ohqA;4n6-qyM>pihFy -z4Eln#fQ^@qtxx1ua<5>n{y3?85=BH@b`Rk06z{b>dCNW6Oo&}cxMKGgz!y(Zd1EKXWX|R6D%;V -zO%}A{2XK=U6Q9)>4CCpjR7Bmj5tGi0`fNAAiyy6Buzq`yQ7=G@(jo4kz~uX3a|leQ -znPbFK-QrsSWjW`ZE0l0RbzoN$EaUA3xKZT3H)vpww4;H4Y~@Fxa(N5MMgT3L3esA& -z#khOUkdtQeZ?ujc@i|b{Az$o6ji1SvfQ2P4Fl9xj(j2fRfXM91NY?TZi@9G~Q>8u> -znUEbT327qTp=2E;8j!deS!wcJtNPg6~u?|e$Cn#?wg>Gy;!h%T#ZZm!|+sp>F-1wjT0Duzgg_YDCD0ic2fG6aGJ -zE--=xDlmctCI$;ChDe6@4FL=a0Ro_c1nw|`1nMx8x&{${n%1@_Wccvq0s;sC1cC&} -z(RN}-FcTn?seem_$6vscHBDugxnx8L|3Ew+b;;a<>LT@K6&!=f&;v{-fr9J4)RI5E -zj@&%tk43H}?45`sk;yf*U$h5Rp|)9F6Mbkixr+=hea8YdyXbvVtQsqNcpBZ -z#n8MiO94WErRUY&{G8aC13PpOJ~sOK8;S<+Ie>LKd{9|1T9WiB_c>(}FfnAf;L;jb -zfNB;hfdYtGs0rLO^TE8t4y7e>6bF8CPHU5uP4jz$Yy -zbL9m*YvAtA8!^vfrnnrj&CCGA^^&svs%|+8*DEE?lL`tj- -zf`rq7l(SqSOVc@gT!bIJH%*ulo^Rrq8vp}!YD=*9th0b|XC4K5kKCIJ#G)UbZN)Ww -zSw`3^C#o(f`hsxT+he6hh$}M~2Q87|(edYIB5yDLZ(%;MTpajfq_bj!59ytas5{aU -zjlC6r#g*`SaxR%zzqQ6BW|Q6?cyz1Bvuy6fjt!Bo`$oo^9;J^!3#!XmSiw9*5%*N^ -zQ`2(jBGPjpt%+*4Ds-K8@v?N$LVXpWSJgCCtdxP8Ct2+e*4j(IdxkRy@~{XUZ}X+DyjPW+V9xWn;~GLbJO}s4^x6; -z6$reQw$IdY>X?kq_FmyYA+B|x6euPPHyfqnqwIO~_)n2=R;F+z4p%BJLy`c@dS(2- -zx1Ora8m!D>l^j=a<4^I_s^luw>R2~vsr^$6814D=So0R^I>^3!lj4S1`0<`!x&sk^ -zT)bs;3pPzQTN^KA4O2TRv6Lezb#;s2(3`&1@Is%>(bImh$?j2Wv3z`eh8z^5Kqwnx -zB9UF+NI^$^U>1@@y>$c-eUN_iXYM_d)Cc@f!jXT6&#y70UI?FBobSP=?)}8^=fZC{ -zH4+W5iQxFbHcNUHQfmMqnc71wJlHjVLAuoFS6%YV)&L9jzQ8?M-MXaXY8IG+q)TT3^jVwS*gQ@y;alU9 -zYt%DyI=C1o@+PH7AHTADb^xm{o(C~q=^;j5^A1;iPuz%5H<;GtbhX9NhsDtNX{U+Rl2#B;cyXCk!hT~J7*4P9Lt -z?sqAVi^dY}SlRgxYg^JcHm7@k-95OD4H6){G!Nrf%MW&7s(zR_*{b+Ys$MBCm0-*&fN2d -zLo!o!O^GGE95nVk4@7S03xTA;N(*fPCX`P8`Xm>azWsS23xZYFbkS9REW0}sxCq_W -zZA!1X2X1Q9)%6x;w#V%=r3cQCtdG~JmCf2ML+=s$*YLOY&xjJu6R*W@*bAA>)DitD -zLn3);mi?f8-j`_w`MPBdP9y){Ok{43vm0hfd|)sc>x+EAS}`RsBL)d7hDe6@4FL%i -zF%|?Aa~UTT2sI*=Z7gOy+Pr~M|3OA6;4m>TAutIB1uG5%0vZJX1Qf564%Dx{fH@}( -by5{;I{o2EAUPuH8o2f}+U#knW0s;sCTvk7E - -delta 3072 -zcmV+b4FB_$7N8hFFoFym0s#Xsf(zmX2`Yw2hW8Bt2LYgh3)2LG3(qiu3(GKq244mV -zDuzgg_YDCD2B3llP%wf9OacJ_FoFg}kw6`P!$C#iY;oVd0s;sCfPw}X{k^@yX8+%9 -zwBJ}5flvw?@^UAz@E_15;f|7 -z%=`IEmu8Fm{;M@9J1*`p_pIcRPLK(+FMWn?4Ww%T0x^GtUpOaX{(}d=6zfxU*O_P_ -z;{8-Vz=+PJ*fq5Q5}1P|h8#+LByXQ+P>3e*vahmych~z9*bcGZU>fX`OHPSi?VqiC -zB=Rqvb+r)J90J&GI+Fao+TB6@Z9^%48aMh$*5ZZ;bg}FUG;4;3aF(v8Mc%?$$0qwd -zc3^N%>ETq(6vTI$`2w_1OaX?h#=Tof#*z5MeSw0*v$CMQcQ$S>moyee?d|Ygd -zOSrQGiK>X-ozcDa;*JHQLCC}?$LH>?!Yi#hRsnX1OX -z*EB3%Xa}bdITw;zI$pm5MeS#lApv12PFz^)>i>;Kq;rwfsX%C~f|;W&4uX`4^{hYr=Sv0%nHrgoVxp@+Oa2pz6_!d%FIr;pRDqUYfO{2<~UWQ(O#?)HAW1rbVG%r -zq9bBAoA9db8X#}@U%8%J7?%N|4`BO{Kf`A)Bo>s1w3U?&wtbya#nq(}in*aOqVWwL -z54v^FBkaQkJ{{9QU=Swu92Ip%GvLLOIDd7VZmIBi##hu?f(v78%UHjEu7or)#XQ(K -z6nwxUcCasL?i8)8F(v3tkFjU0@B||ae%?*I6IKzV$B;Xlklq^f`Sg6cXaqJHeeaB= -zR|Kl&E3F1db<1&_nuDc1V^iiCJ{=(AE^+aqY5NBcI$5;qni~17mHn5(Ds))Qj>(fB -z!cAhp`uQ=F+SOD%%+Ha38w{~j -zo9@HR2C2O8b?-H5VC5*x&5I%i_u7WWj~_7^J#l4mNU^ZX$|TykZ>kn^P>m*4do=8) -z-lvs7RD7|XX;o@sWC$=qUP|t9tI!D(6aWp9r+d%S@i=hsUzZGj4`0ajob3mf39g=O -z%sLUXQul@047pG(XAo^Bzg#aTGeIP9XG%lsySCBt^BD;L!P?o>8|72>-F%bY1Wq+- -zQ&co>uVf4#KdH09JZl->qdH!j&5obWpC252k*~RRm`++aA -zb)ix=M5o -zkDSS^SpDZ46j6?8FSSEt!hzU2{_KAgGG#C6JOuiZ$dBlrIHJI>a!|_ci}n~u6wfBn -z1&}v(3R~EJEM#g)ZxZO$;#Uy*l%8e6KIeQxo6!Ev!p)g^jmB_%6GXqkLS>=3J;!BiP~zMs^7_ZV@z2e~h;XLQo=1(w3< -zKSrEW)`6L0#?Y=Y^OVjAPol3~Y2-UA_>BjuU<55l@tHF|>M7Zh5YYg$$Med8J1xt2 -zLP*MiFoFeS1_>&LNQUQ6J*E3t0>aCid|=?nFOo@xF7nMEwFSqGFL=q6+5@%_ -zt-z3k=H;LP>M5^($OYSZJ{(r}tFwIj -zvW>%k6&+&B`~)0-Gg;CuKJ}d10CU^>UaG3Eag)cBnkgpw6c$vz5a->`qeYY{qOzjV -z$lM&d7YnfSl+TL;$Z%XYD8P&u6+OPseP8BbQ`Co+4qNH^w^HP@t~i7h`yya}!u<oz#o;ZUj=Hp -z(TV68ifC2(4C2=wv3r~1104(jA4cs9gd=F=kJAOeb?#j`oJ0bKe65FiHPEx{!4^2M -zz^<`>c3WJhEzhxX)l8^flHtnoU_1>9oCV*rdmGdTgN`7ewco2nZuA--|EL=EaG4Nn -zpF~eT3tG2-f{+uROTHXdk{V0)X{9@F4mpkfDP7mjH8Tej5p$_wAOlRUsVV8eC0hd` -zl4Cv#L%OnpO;^-jK=n`BoqWJ#I2zzYA;sz+Y;icw<{th3N}p#_Xrp8*rEd6NEX=4@Qp-i%c1jGY-l^{T#gMCnLtFM}iUj!H}kK_5;CTggujzqx``SqC!?Fq@kO^ab0Yk*7|TX+l3@A8Z-brb&{t -zZX^wVHoyg=NeF)1EnnZ8*NrQU!QHwFx6a1u4+j8i75XaX{V` -zTejP79{ii}hnRQ)sO)7qj>Pd@U}lVl&(b}Ag$oc4za4|Y2`)pu(3@Q{oocgpL9XPg -z&ARc&g{ZqR#9lsFPr=r@2fK*A|lb4n3k%R8?I#c2D -z;=TTZZ*j*ygj57wLl>LICIh&x-2VrAPjpHqNvA6BWcuW0J`V>k -zX2DR;M<%0M5rj)YL!vo}Lr8*yNjn|jEon4LP>F3;n-~NKB>zj8a%?p*fZm_SEdJB6 -zP-Yt1+4};5@fwomsJaS~^N?NR6BXot?2jw}Jgj_7AnKjnZoO5nIY`wuDf(}pQfmod -zE}t2${x!MEq*UT6S13ie-bH%m!2V*Ai?V#!PB*W9mXC+U>&7FB$YbjRT!@-#?o3x& -ziB>ytwV(g|m}&0NES6Y|(~D_kcv$pTt6{{O5=Tjd*U#!Tli@}SuFK6QcZ9`%x3jAa -z9wib(pG>woZhqj$pub -Date: Fri, 25 Aug 2017 12:33:33 -0400 -Subject: [PATCH] Add test cert with no extensions - -Add commands to make-certs.sh to generate a test client certificate -with no certificate extensions. Re-run make-certs.sh. - -ticket: 8562 -(cherry picked from commit 0d23835660ab131d244d395e4568969b5c0dc678) ---- - src/tests/dejagnu/pkinit-certs/ca.pem | 32 +++++++-------- - src/tests/dejagnu/pkinit-certs/generic.p12 | Bin 0 -> 2477 bytes - src/tests/dejagnu/pkinit-certs/generic.pem | 21 ++++++++++ - src/tests/dejagnu/pkinit-certs/kdc.pem | 32 +++++++-------- - src/tests/dejagnu/pkinit-certs/make-certs.sh | 9 +++++ - src/tests/dejagnu/pkinit-certs/privkey-enc.pem | 52 ++++++++++++------------- - src/tests/dejagnu/pkinit-certs/privkey.pem | 50 ++++++++++++------------ - src/tests/dejagnu/pkinit-certs/user-enc.p12 | Bin 2837 -> 2837 bytes - src/tests/dejagnu/pkinit-certs/user-upn.p12 | Bin 2829 -> 2829 bytes - src/tests/dejagnu/pkinit-certs/user-upn.pem | 30 +++++++------- - src/tests/dejagnu/pkinit-certs/user-upn2.p12 | Bin 2813 -> 2813 bytes - src/tests/dejagnu/pkinit-certs/user-upn2.pem | 32 +++++++-------- - src/tests/dejagnu/pkinit-certs/user-upn3.csr | 16 -------- - src/tests/dejagnu/pkinit-certs/user-upn3.p12 | Bin 2829 -> 2829 bytes - src/tests/dejagnu/pkinit-certs/user-upn3.pem | 30 +++++++------- - src/tests/dejagnu/pkinit-certs/user.p12 | Bin 2837 -> 2837 bytes - src/tests/dejagnu/pkinit-certs/user.pem | 30 +++++++------- - 17 files changed, 174 insertions(+), 160 deletions(-) - create mode 100644 src/tests/dejagnu/pkinit-certs/generic.p12 - create mode 100644 src/tests/dejagnu/pkinit-certs/generic.pem - delete mode 100644 src/tests/dejagnu/pkinit-certs/user-upn3.csr - -diff --git a/src/tests/dejagnu/pkinit-certs/ca.pem b/src/tests/dejagnu/pkinit-certs/ca.pem -index 44c917687..f7421ba02 100644 ---- a/src/tests/dejagnu/pkinit-certs/ca.pem -+++ b/src/tests/dejagnu/pkinit-certs/ca.pem -@@ -3,27 +3,27 @@ MIIE5TCCA82gAwIBAgIBATANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx - FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG - A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz - dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug --b3RoZXJ3aXNlMB4XDTE2MTIxMjE0NDYzOVoXDTI3MTEyNTE0NDYzOVowgacxCzAJ -+b3RoZXJ3aXNlMB4XDTE3MDgyNTE4MzIxMFoXDTI4MDgwNzE4MzIxMFowgacxCzAJ - BgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNldHRzMRIwEAYDVQQHDAlDYW1i - cmlkZ2UxDDAKBgNVBAoMA01JVDEpMCcGA1UECwwgSW5zZWN1cmUgUEtJTklUIEtl - cmJlcm9zIHRlc3QgQ0ExMzAxBgNVBAMMKnBraW5pdCB0ZXN0IHN1aXRlIENBOyBk - byBub3QgdXNlIG90aGVyd2lzZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC --ggEBANOWvXDyubZ/Kf8QYdPSRk/rsogzqS0rycNEJp/6rPpTS40UxGae5MyLHfmN --l2mSevRoHSqhb7cfT6n9kR2kb3HB0qhhhecHey4sGwd+m7WMhBQgVtYaiWkuEQDC --7/SWkRYzmYX8J41vrQulXU2/2pOQCmG4NKPsNo+vcKoT2SHl6qr3lflUaIG0wDu4 --bFrWszkxcuSkU7SSXDf2xTTTJ8QftO6WQY3g0+dAhbjZFKxRO5uipxURez5EemVs --Re86vXEILka85tiVS4maCn3l3FWMqcBHRFNa+/osTb0J/OmvvdQ3bzvscG7KDRtM --bRUnpWClr5R+AbGVvKocj5I1+G0CAwEAAaOCARgwggEUMB0GA1UdDgQWBBRrwMkO --fMoN3ofjotSWjK0c27fYYjCB1AYDVR0jBIHMMIHJgBRrwMkOfMoN3ofjotSWjK0c --27fYYqGBraSBqjCBpzELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0 -+ggEBAL8HFT/+Uia/TcSFIJJd7Z7ZFvMOYLhEkCyqRhW1ggDp0xrIAoh/fyxq4qId -+S8f7Aurf39kzyS9NtDD2snKwfoLaZpunIXNLCujrlrqdhKsZdtl8aYLmjIhTLu4r -+rN5WZIRQULbkLiuqc6ZFOjOZxkR0NkC/CyfQTJO5a2TaMrweLswmY0k5KlAoevps -+h+LPXsLC66sqgYuWDD8c1Z9GlI8dW2abRPt+WUKskEgHqYJrCkjvPIZgS7UDAzpU -+OCXopDDr/qQ9dnAYzt98r/pCx621/2R4JttZbdsXQDbQaHhV69iJqACqZB0lLyKO -+Ka4Y2U5zy3++t6pd3oGlWCr96D0CAwEAAaOCARgwggEUMB0GA1UdDgQWBBSvEuBX -+VNKtIomCkLcxpsKp9Ag9qzCB1AYDVR0jBIHMMIHJgBSvEuBXVNKtIomCkLcxpsKp -+9Ag9q6GBraSBqjCBpzELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0 - dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoGA1UECgwDTUlUMSkwJwYDVQQLDCBJ - bnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVzdCBDQTEzMDEGA1UEAwwqcGtpbml0 - IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlggEBMAsGA1UdDwQE --AwIB/jAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAN82zurZwM --TugUG6b1symxXxOdDqwinwIlQjzXJ8mTRv31q+YwNdYvdWn1aex8v44qjFDjEP80 --83y18CjjBHznwxsHll80QmFHjpy6xtRrUC/Ak7jfKnDiTKQYBdgmF4/UiVQu354e --QI6jPMQlrWZXThlRuBjM55hs4tgRYeTgbd4VSZzVQXdm2ViZkg8SGqw0R2ZRnG91 --dfXkhu/tTruguPAT3MQ2pTK/CoHHA4W2piQbBDqIl83fphRhYxyW/cCF2mvZZUhE --AfWhgYDeTDxHKG3Jfmm+ujMo5HscgeUpJ7XjZdobNhkQjD1piyuGzFkUfo2XzA6m --kMz4Jq4cnvpz -+AwIB/jAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQArUoCjqxsY -+/m3nx/5BQSkBAL4T5RgWIX+L4y4GXloYYlafpw+SxRq0QffFm5fpCJBnMd21MbPl -+k/YA+oq0/76cKyQmJ6h/Wl4KHCKKMmvGuhCEXzmrevk/EJ8lJXNdPfbBueAuLeyU -+7X9tO8i9fJ59AZ9YWD9d//puOF+8xeHPxJIxHcR2jHpUOJPtm4yVu1LreHiJJTu4 -+Xotp9yMpJu/uJM3aBKVS5N/5JreraLj9N6N8nZ/7nEw9Dj1zzGHcHCcqtcxz1oOH -+Zbg5Jo8HhVhIHxKdKLvwEk60P+lkGFIE+IUmhWfcbbprTGs7VhxREwxaWyCapCOk -+qlhbJdEcjHr2 - -----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/pkinit-certs/generic.p12 b/src/tests/dejagnu/pkinit-certs/generic.p12 -new file mode 100644 -index 0000000000000000000000000000000000000000..238baa56bc7b4ec4a4cd66861d9a54888ae6baf8 -GIT binary patch -literal 2477 -zcmV;e2~zejf(fYt0Ru3C32z1oDuzgg_YDCD0ic2jU<85*Trh$OSTKSF4+aS;hDe6@ -z4FLxRpn?PdFoFa80s#Opf&=vi2`Yw2hW8Bt2LUh~1_~;MNQU6Cwj5&?-ITdyp+x|XE-*3B|L8H?6tR9A4HUV -zXKXC4=L{;GYOU0TZ%YIlTM6d!F~cR^uf!*<@U_-l*QqJ>xt(al?+>_BvzoP^gL1N$ -z`F-->tkpYWJQUWTg*!blr__$E(F`vAa6$tp#&2s#wO{Z+x9Qj#E{tn`2{H -zg{vzUo0|{iV-+Q+#HBbV5=@9HX*$|bj>(CQqEHI)oQ(#V>5%ee;p0M7*Ncmla{Oaw`~Lk01PKR0)2+7#ypOR -zE<@*23b5&ny_nUSu&QRYf<9ZS$K+zIxKS{-TDjaw -zil6-nf!Sd?4znmK)|t(Kh;^hMN(xELd?H&?xwpdgxQuGz&lqkC*bt7YYcgZyhS`(_ -zV#Eei3)wjY67{AC<7Jdb$1DrskBFGeZl1_X_JSlij;_AeG&Ze&pK!02Uol4a -zAU3nTn}n!jf3MeflZTds*L87yad1DS(dZEx?R=EV`~wYbzuJ+gyipE3%clL}xH|uh -z*0lFO@p4PYUlRKizgu%`-6@}1$(>d}Hi|tilS_mz$63&pG)DTS?u#a3%DdCMr6nS= -zuqM$zP9u98I!aB)2ukr=BA^QLRczSH^0a)!b6RMWsc6m2lXG@=*;qxzKpg}Q;PWP$ -zSPdG{kzh|I5&?lP;`r@Y6C5-O-aNIi>snK{0uoVguzqbh?|wC|;ZdY*FoFd^1_>&L -zNQUi7=~UOR -zVu`0Rq`j%-S6Ff=&?TzqMFSM&gz}ICHc9bAOg}ADuoHHkw?kNR=9F1w*lYN{EG@Q( -z^&Z!5aJ#r-f4w{9{l_?xms3iieP1I%l~D*(t;Nk1aGOf}qn#GuBv85jI+6|9D>yt8 -z=`CiI1xSM|6#z}e8mUO30BVUlR!<3__7-RBW%t*-clA6mka`9Ep#J89G6;43;kLxp -z*-|yA&X1<^zP0+5jK3^7X7_8Ji!05N16zPQD?*Vmuu}Oqin+2p?#8~7bHAc6s#bFC -zBNktoPt|Xx$KKi92&|HGRDq~8=dk}B3c`50V14okG{eS4V-1zL#^Hl>} -zDnU~+pT_`PO~9}`Jv`1wS!fR(ZMPa4i`@TU5bt()(#ACb9{Y+&=*3 -z?16YQJcXXtc1SY}^F0^kPKKB2!~3O%n-3mC^{G$p0l|354kxz5D%&q&VtpxbBv{)* -zpMNnNpUwwe>D5nKequv57A`7WDkH{;SWnT$m6mFQM_4sCy6`Q6+R>fF3xV>`&)a%y -zB1l^2YMSpWB_)PDnwNbAr1q&CK9%#FU7a%regezQN#m#I@aB>MWA)qZGWrv>>pVj~&d(I8p??>w1k}$4P^X -zAWnN%6sS3RRKSDNfisfVQl0_dGxCM!+1Yl>tFQeHvTap~MEH7XV84MrcTfkph~OhN -z{o=b|+k%aoLEyQSSSCuJgEO`uIb&{+Z)uzyj^e7-ow^S5`Lr4TK3IX)>y>`8oiIWy -zH0hllKCxMqW=7K+*+}M2uMG#-iv4KGvA+{{p>ck6qZXw*_yoH?4r-2LxGhvU$-SJ& -z%}Cbjx7lK8OxbcYY6+T8eDcs^;Xvdw>6;}lnp8q -zOI2Bf

+yF}Y41&9t?C1#$YRn~NWY8C%6yHl*AOeW|@!q&2^AvuxK!KnnF`7+J)np -zj6bGtii!U}#abz=^y{$*-&7lSX?~Xs2w?6rihtbpW0dcnT=iZgshJw14vAdMlwyD6 -z|23bFWaw<;jHGdx+WL{QTwvP`6=BXmumW|@H&izw=M#i7|4o2kT^B@DwWN<09-mt* -zH_scbs?(Qg+gx};zbY90=8VD210!z1E&|~fxwzSLg-MMc62*ZwTWl5YDkMj->^Hv+ -zEh;f3Fe3&DDuzgg_YDCF6)_eB6ofmTa$1pK4AutIB1uG5% -r0vZJX1QbFHUUX|Bgz^@{lOae~ZgSk8C3^%24n#rsPDd1M0s;sCf8Be; - -literal 0 -HcmV?d00001 - -diff --git a/src/tests/dejagnu/pkinit-certs/generic.pem b/src/tests/dejagnu/pkinit-certs/generic.pem -new file mode 100644 -index 000000000..706c2f341 ---- /dev/null -+++ b/src/tests/dejagnu/pkinit-certs/generic.pem -@@ -0,0 +1,21 @@ -+-----BEGIN CERTIFICATE----- -+MIIDZjCCAk4CAQcwDQYJKoZIhvcNAQELBQAwgacxCzAJBgNVBAYTAlVTMRYwFAYD -+VQQIDA1NYXNzYWNodXNldHRzMRIwEAYDVQQHDAlDYW1icmlkZ2UxDDAKBgNVBAoM -+A01JVDEpMCcGA1UECwwgSW5zZWN1cmUgUEtJTklUIEtlcmJlcm9zIHRlc3QgQ0Ex -+MzAxBgNVBAMMKnBraW5pdCB0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVy -+d2lzZTAeFw0xNzA4MjUxODMyMTFaFw0yODA4MDcxODMyMTFaMEoxCzAJBgNVBAYT -+AlVTMRYwFAYDVQQIDA1NYXNzYWNodXNldHRzMRQwEgYDVQQKDAtLUkJURVNULkNP -+TTENMAsGA1UEAwwEdXNlcjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB -+AL8HFT/+Uia/TcSFIJJd7Z7ZFvMOYLhEkCyqRhW1ggDp0xrIAoh/fyxq4qIdS8f7 -+Aurf39kzyS9NtDD2snKwfoLaZpunIXNLCujrlrqdhKsZdtl8aYLmjIhTLu4rrN5W -+ZIRQULbkLiuqc6ZFOjOZxkR0NkC/CyfQTJO5a2TaMrweLswmY0k5KlAoevpsh+LP -+XsLC66sqgYuWDD8c1Z9GlI8dW2abRPt+WUKskEgHqYJrCkjvPIZgS7UDAzpUOCXo -+pDDr/qQ9dnAYzt98r/pCx621/2R4JttZbdsXQDbQaHhV69iJqACqZB0lLyKOKa4Y -+2U5zy3++t6pd3oGlWCr96D0CAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAAniIG+xJ -+6rXbrH2kt40GE58fFzrIlzhG4VzncNnpFitvPEMzN0kMa5LBX5/zSYiMawQBQ7C0 -+FpCjz+n82VVW8iabCNoqUUNwOP7ZYmsoraHT9klSak/mLfAXOyOG3DUV9jntivnl -+HUIiDO7Pf6GnVVROio9psQEVOX1+W1uq9Vs79+F5GI/s0QR9dG0qXvdJ0h5UdVee -+8LVXQOi3cQKyBOwECwt0HA0pJwwcD6w9e8Y2NYTeOTamWGQVEV3NlcvtdSVuDJ8y -+lTke2YbEKyHdcsQ1vrDHtdyfEmJcgO5c9EL5ptYJB7Yv1QiwWJOhLdT13IBYvOtO -+ebOF6zAD73Bpkw== -+-----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/pkinit-certs/kdc.pem b/src/tests/dejagnu/pkinit-certs/kdc.pem -index 8820ad447..4eb811deb 100644 ---- a/src/tests/dejagnu/pkinit-certs/kdc.pem -+++ b/src/tests/dejagnu/pkinit-certs/kdc.pem -@@ -3,27 +3,27 @@ MIIE4TCCA8mgAwIBAgIBAjANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx - FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG - A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz - dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug --b3RoZXJ3aXNlMB4XDTE2MTIxMjE0NDYzOVoXDTI3MTEyNTE0NDYzOVowSTELMAkG -+b3RoZXJ3aXNlMB4XDTE3MDgyNTE4MzIxMFoXDTI4MDgwNzE4MzIxMFowSTELMAkG - A1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxFDASBgNVBAoMC0tSQlRF - U1QuQ09NMQwwCgYDVQQDDANLREMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK --AoIBAQDTlr1w8rm2fyn/EGHT0kZP67KIM6ktK8nDRCaf+qz6U0uNFMRmnuTMix35 --jZdpknr0aB0qoW+3H0+p/ZEdpG9xwdKoYYXnB3suLBsHfpu1jIQUIFbWGolpLhEA --wu/0lpEWM5mF/CeNb60LpV1Nv9qTkAphuDSj7DaPr3CqE9kh5eqq95X5VGiBtMA7 --uGxa1rM5MXLkpFO0klw39sU00yfEH7TulkGN4NPnQIW42RSsUTuboqcVEXs+RHpl --bEXvOr1xCC5GvObYlUuJmgp95dxVjKnAR0RTWvv6LE29Cfzpr73UN2877HBuyg0b --TG0VJ6Vgpa+UfgGxlbyqHI+SNfhtAgMBAAGjggFzMIIBbzAdBgNVHQ4EFgQUa8DJ --DnzKDd6H46LUloytHNu32GIwgdQGA1UdIwSBzDCByYAUa8DJDnzKDd6H46LUloyt --HNu32GKhga2kgaowgacxCzAJBgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNl -+AoIBAQC/BxU//lImv03EhSCSXe2e2RbzDmC4RJAsqkYVtYIA6dMayAKIf38sauKi -+HUvH+wLq39/ZM8kvTbQw9rJysH6C2mabpyFzSwro65a6nYSrGXbZfGmC5oyIUy7u -+K6zeVmSEUFC25C4rqnOmRTozmcZEdDZAvwsn0EyTuWtk2jK8Hi7MJmNJOSpQKHr6 -+bIfiz17CwuurKoGLlgw/HNWfRpSPHVtmm0T7fllCrJBIB6mCawpI7zyGYEu1AwM6 -+VDgl6KQw6/6kPXZwGM7ffK/6Qsettf9keCbbWW3bF0A20Gh4VevYiagAqmQdJS8i -+jimuGNlOc8t/vreqXd6BpVgq/eg9AgMBAAGjggFzMIIBbzAdBgNVHQ4EFgQUrxLg -+V1TSrSKJgpC3MabCqfQIPaswgdQGA1UdIwSBzDCByYAUrxLgV1TSrSKJgpC3MabC -+qfQIPauhga2kgaowgacxCzAJBgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNl - dHRzMRIwEAYDVQQHDAlDYW1icmlkZ2UxDDAKBgNVBAoMA01JVDEpMCcGA1UECwwg - SW5zZWN1cmUgUEtJTklUIEtlcmJlcm9zIHRlc3QgQ0ExMzAxBgNVBAMMKnBraW5p - dCB0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZYIBATALBgNVHQ8E - BAMCA+gwDAYDVR0TAQH/BAIwADBIBgNVHREEQTA/oD0GBisGAQUCAqAzMDGgDRsL - S1JCVEVTVC5DT02hIDAeoAMCAQGhFzAVGwZrcmJ0Z3QbC0tSQlRFU1QuQ09NMBIG --A1UdJQQLMAkGBysGAQUCAwUwDQYJKoZIhvcNAQELBQADggEBABJpKRfoFxyOUp9i --Z/fWql5anJuZElgBSbEC5sL2mMcmL/1vqkiYF3uF6/Z9g4X1LX4QDuvaXCJSdQ+b --JpmhklSyFN+E/agxZtSim+AjTgYJ0y+jwNvX6kZQ8fW3VLNJZ+zbb4n4txfgSROn --7ub+02mo4DYajyD9TE/qLzmVaiKLEKW0osjxX3fB1RN/d7zm//NDPsezzUzmKkgz --u0ML7HGYUNY3+/SC4ShF/But1IoY3/I46lB6BMrIn9X6fsVKlipqrRFniUk0qDlJ --fbKVB+MvGEFoqFNlMoGiufmDjnJl4PQZCVEmXO8wAVGeK8NpTBCjltAAsoVJVnjq --AC5jSAM= -+A1UdJQQLMAkGBysGAQUCAwUwDQYJKoZIhvcNAQELBQADggEBAFMX7ZTpNPdzFwkE -+hrab7fSDeoG+mN0yorY8e5Evx6sE7pXOtHgHIjQY2Ys0lk2mhbsIKptL/R6jTxWR -+rbmU6jFNFeJgn5ba3NWdhlUiZ8WKe2knp6uc9ZDIK007XaKA4rRoHlJ3vHXoF+ga -+JFOYwRzCtAlmsOCQ0UetoC3Ju6Y6NhCXIE8f81dsh6RMADoQT0n/fcLY/JtbbLXK -+ANTIWHm0oSX9wvOU/yZkYGuwcPd91cc6Mea8f3J8D/OiatMZXc3719extmeR6Cv6 -+aba31kv9wtbxVuxkR7HhjlJhzhqfzfIp3tNREaIxPb/qKGWBOjwxGRqSUkdEqMvD -+GjaSlyc= - -----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/pkinit-certs/make-certs.sh b/src/tests/dejagnu/pkinit-certs/make-certs.sh -index 0f07709b0..f77ac5813 100755 ---- a/src/tests/dejagnu/pkinit-certs/make-certs.sh -+++ b/src/tests/dejagnu/pkinit-certs/make-certs.sh -@@ -164,5 +164,14 @@ SUBJECT=user openssl x509 -extfile openssl.cnf -extensions exts_upn3_client \ - openssl pkcs12 -export -in user-upn3.pem -inkey privkey.pem \ - -out user-upn3.p12 -passout pass: - -+# Generate a client certificate and PKCS#12 bundle with no PKINIT extensions. -+SUBJECT=user openssl req -config openssl.cnf -new -subj /CN=user \ -+ -key privkey.pem -out generic.csr -+SUBJECT=user openssl x509 -set_serial 7 -days $DAYS -req -CA ca.pem \ -+ -CAkey privkey.pem -out generic.pem -in generic.csr -+openssl pkcs12 -export -in generic.pem -inkey privkey.pem -out generic.p12 \ -+ -passout pass: -+ - # Clean up. - rm -f openssl.cnf kdc.csr user.csr user-upn.csr user-upn2.csr user-upn3.csr -+rm -f generic.csr -diff --git a/src/tests/dejagnu/pkinit-certs/privkey-enc.pem b/src/tests/dejagnu/pkinit-certs/privkey-enc.pem -index 837fd0b01..ee35e5cdc 100644 ---- a/src/tests/dejagnu/pkinit-certs/privkey-enc.pem -+++ b/src/tests/dejagnu/pkinit-certs/privkey-enc.pem -@@ -1,30 +1,30 @@ - -----BEGIN RSA PRIVATE KEY----- - Proc-Type: 4,ENCRYPTED --DEK-Info: DES-EDE3-CBC,19FEC334A4D4391D -+DEK-Info: DES-EDE3-CBC,7DF54DB740F92845 - --S6pSicLj30Jlnu2OnYM0eXCvwAHR3xMhhl2N0gheWUGkjicqTdW6ft1qCmGBre9b --/aTSF1ajvFC+YQ/iABznWNmRNZKCzTK1dQ6P73p83uNqWt/cfe+pVYdeHw3u8NKA --fscciBtxnHNaAs16GX5/j1XXRPb+zmUe18A+VFMRgctbaurk+KbxO8qVUkzt9NNa --v5zHkXnaJf6ixL6zR3cOCJWPGy4GmGeFIytQos5Jgn23Pjn8BHAXf39GMs2n6g5V --eE5RAGDeXqPv/tO1kN0/RSKDeIPvKW6REklXraRUle0PNN5g5l3umSkg4fkplusp --nTsQCRWkqyVcMpxcf0wy7F2ZPOYIWDt1/pzAHC7y/fl0uCQPz0Qd1smwt0ABKcZv --m9zaMq6lkKYnBOxPiYIlWVlQi3RLDiQyAWQz/nF0SKsE88SUlB83quySJsZsLKzk --MR/C+ccSiHqMiDKVj5Ts1go+gbj8Vhlto8jH6ynQj6lrOIczyMmgUa0v0dFH3i3/ --WL/8ydJ0otY67A8w5yH3hMzRChXQZlpTmH2dDhAv6EzKBi8eIiB0Em+laz5lDv6C --SfNxZa1/+bSAvXr7LwllUu+Gzbu7MNLwfB2ieTqdFQGA659DjnMqyBGLFzni4Ir0 --Hi6Uh6yQubTm07oqyUHAsChGFE4Efh4O0rCbKKPZuSVfimUZcE6JM9IjRC/0DIwr --LZSYqsFgn44byrc62qV2JAE2ua+/4aHHI28hIZ3MDLwyYpCQL/FAUZtqZvni+zgw --yoHLRDbdrqPps6P71T6Pw6OQzAYC7AL/FsZnLJK78nI+Yai0dpyv/QWiFSXoDEVN --6vQoDv/VZbNIctr31OE4XyjIMiTpn3FPa3VSbKM4/h7SthjwEV2ONNfR8XQF+siz --3NhOjEFrZ6UGHvT06wo/hp4CM7u580fNu5HvyCyIwkx9CZRLHvG6Vu0emlzDfQhE --qxQs6L7IM8A46/LPSTtmEA8Rrn51YY9NChMdY6j3rLe4NLxxOCE6JYaGWVWBBawK --k3y9z6L9gWRwxEfCgWIutDrYtmA2aj6y/vRS6LrotCNeN5qBx+TdRnh6uCqbi1T8 --4rF20TVhNZ/l+pkH/ehY9OJ/zpwdbTq4FlE0wWQZB/vwbYP5CZKF+rU6IXnCZEjt --Ak6Bka9mFm9Z/TvnKIRYiXELq32zOJAuEOQ576tkDX2rAuIQAfE9biX2qo0gbsJo --1RIfXekRurD/HX54blv5mNqUV34gl+ngPpV5nNDy7RuTAdP77Mu7/ynaPfnM7nqu --rECbZVv1HZSgTi+7G9SUjn4Bg36p4NiF0/dZ2W70byYIQvNPNqU1kyeSrZk/43te --NwFgpoAKVbMD1rZ+0xM2YCFFKQZZMN1a5tn8/1TWPlPU28Tu3ZliGeWMdeKd4/MP --vfH1pE58qVcyOngjLqGkk0L5A7WOAgu+vibKrxGxywwVLx/GfDFqnNr6H0buwXrk --vuKBTo0r3pcbaZt3kaYBm0d3zznQI1O/pX+eGiNr/rI86j4KC+jUSoKi4BdUeuDN --p1x6qyEK37kgVXiUyiEXO7e1arLBZMfFRTNKVsN5ewL441eCIgs5gA== -+3I3F5dJkYmjX49YRQub+AzWPOJock699vQZV3oxcAabcZWtLVbQ75QBXXBPEtm3j -+LAqb3gRxfETHNHsSIEwGtN3rYre1UdKs3Bu9ROQNTvlbCwRdss3JA1kGhJu2o5bu -+hf5sjpfR+ivf2prJ4whfhb4+efCHE0Ll669V33D2kbPKX0VCokkRmxsIoVtHd2qu -+d1HM/EkjxrOy/GHZ+93mkSeWC4hz56VL5ApGOV4wHuphdvKy121mU0mjtQRKF2El -+N7DtM9/AIAkLPx5wxrTJXuELd+BBDPbRMwmvgqCX1m8sJLJT2fBzVKRKWexowp7T -+d3j9hT+kMiWCTgd4vJ+i/KPkK460Cy9PzFrzCtWut4jh6rZ+F9Tdp1g4Np0ygWAg -+q9tV4RC7ylW0DeseRTXTLuohngfu0h7mXuhutr1Xmq+SoRuhBllZyexV4jJMc1kZ -+2nv9RJ+h7mCAQbLSVvWCZpngfK2IcZhi4hfNiiQ/wqc6rE3eaBIR9E60kaCeBpWB -+rxZm4VHOrwJw0GsaCRLQez1F65Ulk4TA+7TYJWnW/MGrvBptuBamwxk28Ts6eOee -+RVwb/AdY4QBVJKKT+/e3Lfy409evmdTAA2N+tbYzALC1cH4ex4sO0BifaLmKo3t1 -+fC2FLna4P9F17bbjcS1lSWVJKodofUEt4H03X7LaMhwe+sLRuKBIoTH2nLPHLIYg -+B8NO1yFiJPFL0a8fi9kG8JJlCPkASQC5vcYg6BE40b7h7T4qw0HmkuH3i6TX6bsG -+nQlryJ2BfQM+IT3MTEh/T1iHPZcTwFLPF9HMnZ/ydL/nM2kElF6YfMClFvuDGULQ -+zmsvG4D/ndSisapJQeoevAwtCHybh8/3cy8CoAjBE9C1JlHOvP2+64rzvFVUAKfa -+z5aZQQJKcdXcKcM8u8PgEyCN5x5tBqWQjSHR904k25KRkePAh8SoiSDuNQPwtzbB -+RHesvkaSXuUaN7q1+oJzeQvzO8i79ud0Diu5y2KePrlB4HBSWCuWmvz9U+WvGBiw -+KpEUAp/YpkqB1as4IUBDNjV1Y77cyUZ+/8EkPgAvB9wltCCAyQ5xi1h70cDJdabj -+swabRD5JV1JLalFMDrOeOPZh1heaTNHXV8f7m8rMVeYVzVTM1JoQLlvKxcc3LVfN -+9RLn/vTN7Ox//+385UiozC/PAo/Cep6Z1Wz+cwsd62HH0LVimVt2mrmHRKY983cw -+U6cZyhvcTB5UOdJdhwbHfnxQipWRu//XRYY/yVdB6W2J4Gzh//adJfKOmHd8+cB+ -+y8Q1yZP3diTGkhyY9pkXS7Gv2Q9mcXlMJtoyb7rqBIL/osVTKdsZn7Cj6ZYB6ftF -++hKQKNs/bKXYs3PF09UOInfUf57pENSr1AQBQceAisAsr8znRYsFlpqZ5L8G6um7 -+XBneZ1RBj41wheB8g3kL6hj2UrXrE2rxDAw175a3BaxP/Wc2JgGcBWyJTVcZ35Ab -+f24UNlrfcJdgEFETEiy12WY2VaqJCSY3J6YSimHDbffX+ku8QgU1shZf9z8K1l1A -+OJQzbjlxPZT/k4cfw/Xi0rHdgWGcmL7tKLkTcrG/AixdEoI9KCSlQGSksI8CfFmj - -----END RSA PRIVATE KEY----- -diff --git a/src/tests/dejagnu/pkinit-certs/privkey.pem b/src/tests/dejagnu/pkinit-certs/privkey.pem -index 7e9beb09a..548e5a8d5 100644 ---- a/src/tests/dejagnu/pkinit-certs/privkey.pem -+++ b/src/tests/dejagnu/pkinit-certs/privkey.pem -@@ -1,27 +1,27 @@ - -----BEGIN RSA PRIVATE KEY----- --MIIEowIBAAKCAQEA05a9cPK5tn8p/xBh09JGT+uyiDOpLSvJw0Qmn/qs+lNLjRTE --Zp7kzIsd+Y2XaZJ69GgdKqFvtx9Pqf2RHaRvccHSqGGF5wd7LiwbB36btYyEFCBW --1hqJaS4RAMLv9JaRFjOZhfwnjW+tC6VdTb/ak5AKYbg0o+w2j69wqhPZIeXqqveV --+VRogbTAO7hsWtazOTFy5KRTtJJcN/bFNNMnxB+07pZBjeDT50CFuNkUrFE7m6Kn --FRF7PkR6ZWxF7zq9cQguRrzm2JVLiZoKfeXcVYypwEdEU1r7+ixNvQn86a+91Ddv --O+xwbsoNG0xtFSelYKWvlH4BsZW8qhyPkjX4bQIDAQABAoIBAH28SS0ygFvLq4gw --EwJOJYxeswQvNuxp5gcMm6tbyqkjEHVxDtkwuSQ304M1ufF5o2lT6Wko7/sxNyT8 --Utz7l2JRXL7E3U6R6ohgm1tTyHIVY3OWWCP5Nwjy4BXEwdVmGCfKWAP/+P0ajQmr --pguK4/fmk9TIIzf6Kd4u0lOvYcu7AYfaBj9OSSF08IoE1EA9gY3Mh9k8C3d3JDhG --hoJKwMAIX0PRyx6cvmpuAJyPf+19K0/SmzpbdNOHfIXZKtfYw3HxmebhhyCxqNsY --opI2fpn8joasvfcXICBFRHreSu4nKc8ky6FkMIc5KZRiSP//N3oFM7ZLxciMjfgl --bCYqST0CgYEA7xfrB4atDYApsmLk92uHnC2bOmJhncfAuLHh8M35fk09Jt6CMYPx --Ydp4cKYzMemO5zzHxdMnlmISIWWtNbm/gR74KZwOmhFFEP2LE09hpAXRBfQvN5af --RZwMZ9uyJU5ByecXbIt0cuNerl8sKJfG1S+/maD3dZvr78K4Jd6StTcCgYEA4ozu --okBTEZ9h7lxdBBbZcO8i/eikPeKnCEBaSryf3K3Pr/k8Ssaa7MYOT9yD+iRwU/uV --n13BA1I9PvdcWl6ewZdOYX4jCVCIsLs7ed4wfwLxGQMZIVHPZ59lRmVsZFO08g0D --27U/rUZBpMHl+ppq/FfBjyyUSqayKjcBoFXx0XsCgYAOzQM+pwaldE6gfWDBNEXj --1Crs1VRHqSr0BAcBmi6cs/laI6IZoJpbvWOBTbiTmWrAQ9H2HBkyRQXsTVgIoGQL --gThJkyCQRwtoftmSK3LW7Yk//hrCLS/U5lEaSM5hYtPNxOF9VbCywAKHdtrL9IFZ --hygsQXuwKyPS5tHxfjLExwKBgQC1D+Hg9vvtB67jLBqDHCfopJcYywgJFc5dP+Fp --/dreKmPkxpMzSAul1Jy3owwvrVPBKz9nwSxzlRSx8Ex1RU4odt8D+CXUWfMFHH7q --ZXPo7tb2II3DHXlf3fq5CnJYtLXXBiPhQriDqbTpErbVVPjQeOqPnRdfml6mcpPw --KwA7ZQKBgFzqLmWqy7ZnZdbBo4CUUt6B12eaPCW6YNpOd53zHOphaiZLq4rEhpiZ --S6JYQTEQYugr0yd6vxsVL2An58niRg1sM6gca9QqBlGMzaQoXaPx6OrLW2WoS5+I --MmVTeh7yvdop+6gvR8Eoh4cI0HoiJw8oQOOneiXVnh7Izk+WjKXb -+MIIEpAIBAAKCAQEAvwcVP/5SJr9NxIUgkl3tntkW8w5guESQLKpGFbWCAOnTGsgC -+iH9/LGrioh1Lx/sC6t/f2TPJL020MPaycrB+gtpmm6chc0sK6OuWup2Eqxl22Xxp -+guaMiFMu7ius3lZkhFBQtuQuK6pzpkU6M5nGRHQ2QL8LJ9BMk7lrZNoyvB4uzCZj -+STkqUCh6+myH4s9ewsLrqyqBi5YMPxzVn0aUjx1bZptE+35ZQqyQSAepgmsKSO88 -+hmBLtQMDOlQ4JeikMOv+pD12cBjO33yv+kLHrbX/ZHgm21lt2xdANtBoeFXr2Imo -+AKpkHSUvIo4prhjZTnPLf763ql3egaVYKv3oPQIDAQABAoIBAEe7ACa8d9qm4SvX -+FYkAjjakq/JuxrDKxhyPf6utMXjoVGXtDs50matzI1DekVMxlUHe+O5VfMkvc2cj -+a5SXY5n9KqRuGKhzWFBoDnxao7Of5zn5dqE5szGJksjKS6pdZHcutXBHtHKfGbgo -+rJctuf6AaNLdKfI0TFz4NjRznrN2NyFQGhXzPpq34Qm3Rg91hVlU3A8FYjE7ez6b -+vlJBsbKqnvzxEQMWTk0z0bWC79zE1ElH3Hpwfwb2cG7H4EXf0j6N5k2zODg7C45I -+xWtlES+OpZqdDH6mKFBQojU375j6rb2plZGkTA+qxX9GvG7GsF5aOM6Wkge7SUeT -+NUY2lB0CgYEA83u0TtxCMye1p+ykZwQdcEKR+l4aSjNsM2V2s8Zy4eZseR7f5fgZ -+71ggIpzK9pjT55OiYJOwsEkZAPB0gBgiEcqJgow52w3Hg8sUU5LBEahUpx3Qm64W -+64WNIOL9oVXYQu1S/yJ3iWPMQcH1xIlDtPPC1LH+yHyEOnGe4szIeccCgYEAyNkN -+K2JEbbfK7Wsh3/MOtx5KCkzJzFClTSQZ55IxRUf+myauljKt+kI99jYV6eoicAJv -+SMHQeYurLtSkhuyptAHUqo5xgH0HZ7cE7LV1nfam2p588Yg21nIId9XLDPK4AvCx -+Phz1oznaiGMu4jB7esozuW4FKxB1kRmUikM8bdsCgYEA23jMRLFhsr6+jclPP9SD -+vKck8mtUg0Hq7EEvSEk/UMTlTiA4bhC/P/FNtiVjBfkoOXvoR+mYwK6DLUeRm80l -+GKhaXySLGhtHllK91b9Y7NOwypqjaVD5M/9EATraqEy7DUjjITsuSNd+TF/LawbX -+0wpOum5fXNRwVEYKlCFHLA0CgYApr3LeSDzvkK/batrTAj1RoEW5sYpIj4xfYFjI -+CT2UpYagaPzfS5F0WX9GtJ8Dt4aCPN8f+KnuMCDNTXEAV+o45BBhfcLs6gY5bnDl -+OBw7NtAWm8JO1viatXwwcvz7qPysD4yZ2aTZxc4ndH5sj6dxKrpliAIml/nuraJ4 -+t8+49QKBgQCxJ7ZDlM9J0quVivSui5aoZ7iLEiu6GSZ5yF1HSNXY69OnqQK3UxMl -+aERCn/cKqtquJQK3v1IE6k6uAaoM7PXDVKqKSH0Z1Jpqciqjg+J/i7Vym6oCdjer -+6zt6P7Q13f9X9uUlZBnNrT9jk5WjR9pSpxAc0vU78VKa0lZMZ3bROg== - -----END RSA PRIVATE KEY----- -diff --git a/src/tests/dejagnu/pkinit-certs/user-enc.p12 b/src/tests/dejagnu/pkinit-certs/user-enc.p12 -index 049602939def4be1fa9164649b39a801f417e74e..b2648ceaa04be6a560966a414a7bbc8ac022c20e 100644 -GIT binary patch -delta 2706 -zcmV;D3T^e37L^u|U4IAu_0R=Q$07m(2mpYB1u!tho?ixcuO0j=`>lGTs)`UgGm<_) -zpKPe)yNdVeYJWc`4 -zF|P^R?oh5stR*_(MT+TZR4{&W9qoqi)f&pBxOiQbYZZ1lmQ#Pc4q?TD!0ns{qlu}U -zz(Odv2K+dfougnpE_VouJ0!M7bt6;%w@&*9{%SfiDrvUdRZW6CSckeD^E--2MzmZD -zliS3w_y8kT@PFwptW_3@*xAKJ7u%{U_HfDf9jg*K{X<$ZK~Z=^`bq{K)M1SMGVQ^? -zv#j3vs0HG{g~oN&R6FPVPVchC^z{P@wq`t};KFoH0iPJC$e?G@1S`jv>DCV8RB0 -zmIsXlD|}<)cCDUm$lZ#mt_Z{Bv{YU=x+YDXTvPmRZqmcS#sZMLcxp_X>UsXy*q9%5!2Sahq`0+O!z?}T -zi$jc*@c*4b82s)hz9gxO-sN=XmM&gwlz*+BOwds}(8bcfnOwG9>c4M41I>BdyIE6( -zXbn>T;bsx#*{293>WqA>Y^T8DHfefzJaoF~ZIQJHExS&`Tva3s7=r%MBNe?|IHadr -z3;)tG~fkk%kK$~?KlYIw23fnj%9teHJ@ZW*2W?&0_g?~!F -zv4KH{ocV+%s=kSCbfuiTU@S3?HSk;9`=V>fXAVPQ5yJ-A3VGtMn$hyJjBL>)Xat*f -zk>LDwCgwH<7MZbk%enw@_RMCIr@ki6QHeb;WK_J`RwaC8Mfd`O!Ox)RKq~fUu_iU>d?3o -z{a5i;hDvlYB>6O@o?_&bd+Lyi(>Q~@du=M6Hgdv6`ogLgF)jrfhJv2PHS&O?EAOq?#SMnKNcb&pBwlq5g^OegV?n;MEw^ee; -zNAm2zd3N1vCWnEDkE2q@f3WB!pgs=2pUxlBhb1$h(bH{Eh$P!rF3CGZuuACYydDn`l00e>r$h%Gmj<@&l(&Xw}Eidkz -zz@_D66&yL_Rt&B;1I)=kuf6ANgrS(5a+rcm&O0Um(1W@-qtpcTe1y@SR`1y2+!Bjk -zQw=o(lgh9Kq4o>zszLR*B2s9LY?-=8`IIV7);U#dMhstBw7oiDXdQhCe+i9pk0cnV -zMlgF0u95BdPI`jmlfO~!!}altl{kMJXBOyAE&JL=v<&Va3rMzRzEl_6c~VY?np>Zo -zc?iAu&Mt}Dt}KDnI_!(wF&W;btDeR~!+4GFOI$qsL2rSj&Nf1Z`%l4{qYJ4Qo$_}# -zJwxm6gK(!^XH`H3GDvYMf6ZXiHexfG^(D-Fhn88u;X368WggB2*>Np*Ni+Go9sUe9 -z{=o5{uwK>`NVcYMf4tOHNIsnqr!Hx^gA~eWZks4J^1j{2p{HG?g@>qFF8lS7+k^J`&{T!%j#_zl8OmX0^a|L_Hb^Bf&;C%^ -zDRf4UJIncVpMKi6e_ptRh8&L~a0c+OZyUh4xk_H*ZiVT9oPj~^=?cH{ -zvVq3YVa|#w$>d?3-K=B$mSiz|5L=0aU%z0r5=NXvy%;*bv}`8zSe%or`$-|90;plD -zBMc35ZSO>Cs2V+WJaJ0#L+Y2{w9jWYmI~V$Xh0U}91I|Pf1})&1-$>cf4IK3avbmhiO_QH -zUzb|*rY0bBQH(2Dz0^m5V`6s!4}lu+2Z4sL!Z;_w`zlgnxe2p>);eKXeRgPbE8hM) -zh`oOs<_8p$e;6ws?`vcLw-*IKpOB*Ser86?AiRqkbxtkcVjVI7;D@#G#Zz{htm%|t -z{IL@z9azcPs?vP_JN_heR0Dg%Z|rV#jIu&Cz<+D|zX&(+Uz{)Hp2UasosM?7e~B}} -z@Uc>9Lbj7eqH5pI{>XB6W3)`4gbWgDP6bb^t$0U;e~hQjWsuc=W%5osyn#COy+0Wn -zfXyb`UV#nIfFOyKcTxpXT4y|ytF%_1G!x9h^LdFL>`qCd-xJuFe=Cka?oHZzMvv?F -z4Tv$#KpEY*>=SF~eJrHN-&}^_T`nbeQ#*zvBRah$g$#AJtiay_Dr(%Vf`f5yT3Wx4 -zPw9EGe{U+zCREP#EnqfSUY`b6mlSFbnd$rpIUC2?Bx* -z&*ahaHlnLZq_)8PFZU&7S##TPwtTI){S}rL@XarlH4%tMe*>vZ$pfl61)r>6REt#6 -zA1Tmhn;*&xXn8IimR;1v;fwKcbLt}hCu@0Ke_$`LZOuZ5IpYkzdoDeo7LH_jdX(6n -zI8<+LlcXr9=#AM@2Sx-NbWd|hrC&4HEsn(_cD0F-dOu17hU<54gBG6YK=4`U_l4`A -zqM(8cTN||R5H++bkzne?q5MIh^^GwlFe3&DDuzgg_YDCF6)_eB6ccK}Vdj_r1JjB8 -zJcW?bd-abN6XY;4Fd;Ar1_dh)0|FWa00b00NU*E?J0(4Y+o=|f0;Fia+%K{O2)&NJ -M-JAb8(*gnr07yzcC;$Ke - -delta 2706 -zcmV;D3T^e37L^u|U4QCIImcZ#q51*>2mpYB1u)u~5}22I=HT-d(%(f9DXV18Kbvj` -z^Vtj&rJIy-KS(<%B=99oy)c{aYIfUfQ83DHHOZ|j5N)Uw`u|wFUxcIoSdpz_?)9%H -z4jelm#2iJczX|~|@JmP%-E7N|LSD%0aE|sR%YoM&yhB@K41Yz9lq-Pj*c;G_qu!n* -ztG256pZmHRbI1aKr&uCUv>WoW;LeiC%96yY!X+o@FzzAxrOHu)3g?VLl=`oYO=8u* -zFUXhf-E-pg$i=j~J5AnH&n@YvQR-2plWV!|u18vsOGavYQq$5K0c{Y)cD=>F@sB1~ -z#Ce~xs1%rGd4G(-!z|O%#O_xY2j{voND30(DGP7NkMXu3u$QVLc=J6%CHpuQKR%i~VGy#97gZKGgC -zQ)7)_hvF$URord*Z(4C$&;M+0oSafecrT1A>TOAXhJPO!S1Yy!|0t8mhQxU9F8H0X -z{bS7WoDJL|;>UbB#Q8kT45pQxG--}vOh}`IjL4HRI%JT7=!MOS_w{ZYQc1Wgh<|oe -z$UCUD%v2lcu!NkaS+WPMqtPJpP30!cLsAAZhJP@(6PFg+r~_<zPu>L)gER|-RptQ7t2T%-w$coS%U?y2ty)u$&%U58*x^dW7 -z`SK*%R6K^ppp&Wo_dd9jlUx<%Ga!U2uD9oPe){W-$sAC0PPA!QYj{>3|COVWx@pS^ -zdR%$)XWB=Qo{$wdCUX>$?lfD!Jxy3?UC2xmiGLhV`RaM#xn>#Hl~j;aRu7ujxtJdV -z5)OCd6$2Sv{U)1)H|`*tznwIA_Lu0xM(g7cYqXUD@0)zWD;@cM$iz>33hI&n$WKkI -z?VwZyL273la`IMNy;tYMRF(sMS(#LpN^yUMz!Pw$N2vcnTC~i=mtZwXPXpou2Y*IPGGimihPbppn_& -zRXBY89ppNtTpqy$L5I&2jYQ23<2e0@(|?7`1y3bhH4C9A`JcTJ -zs*Mq{z>yus8k4sR)=<1ex`9V?dYzvH0P5C26D4493!(r1*M9|H -zKGdn}RlVi8Q0R29 -z1>lc3?jlMQ$F%QZs$yVaL}+TuF@LQ*|2oQf6gad;5|UIfZNwdOVy>MTwDGXK0pZYq -z^=+s6V0xCsmO-;{zxI2J?FM61!lojJcLxx`>wst*?}YyyRfPPHWL&x?0k-< -z*`9-8I`q-`7+Q?mYB$<2tLTxDr(QAj_V@HuB~m*PuA2~|AbRG>SaP0yE=us-t=HQY -zg~<|Cdt7j{a8>OwxZuklbr=dfAs{AYygi_jsgM*00e>r$Ow~3k+rOeO>(s`grF?$ -zJG{bdqli57x@xMkpB3?9W>*jR4I((MPl$BvNhVhbw?_vgtkh{C4|j=)L!maakLdv;I? -zQAlp`ykIYDUK>4ac3hrzJuJgy{liWNPtKgmw!Von2J@L_?kwdzL -z*LC)1U0nZwV%P}Nl}uhfIo5hPM76mjv_P&mM&vHgsjqj|mewKje*}5b!(zjO+??#p -z^+fSxFa#sKMfh^V7pW(Q%@sfS$_a6jt%35LjT(p^IHot23x3e7QBt|q8Bx!}hMy)p -zjHIkywUCO1=vwR+a-j{-_L(+dG~7>h(22dhbKe&sw5W6hB_qBi~5%rNy$JlVt9!<+)%x(%&o+O+@b0ergOVP5w6uAeaVE|mzfALIEdE(~%cEj*Nx1l?I)xNe5I~CB-XG7RdT=};;vL@W}qgN1X%CMMTb@z`j(^Hxg -z2+k}O+$v2Ie|Z5?WpteEE^-jk3x*2kq -z{l#-|^i)J+)WGL>*FSJ+u}4ad5!NiRTj*bBOEz4N1ylP -z>^0wkW58HZsCHK&O*4YkvSMBQ2tO%OVIE`(y0uWHS!>4~{B#t&21e9&djORBw&Q`g -z2)Kc2)NTqH_|x#q1O6HWS5W|}5BOBUZ%Vo9Qw5NOKV&)yHS`wX9$DV8 -zZ6V?M9adFv7f3LmPCzozft%9ptIIDEtwklxf0b0u(0L&L4qp#ge@p=B*bmxjw(;PV -z;Cshn-XXPKyoA+FG;h}OQpsj+-)bhjhBs`0k|`c7DQ>1~Bt@|RjJJtP6KC(6#0L4m -zt*tS%Rdoj>M3SepE)k;MCOV%w_xv#>Fe3&DDuzgg_YDCF6)_eB6muCT6bLmUm2E6$ -zJled0QvX3lDc~?MFd;Ar1_dh)0|FWa00b0Mw6Ml6`rPp>w1kFoo;UO4PXV|D2xTCM -Meh!`itO5cE0QPz^F#rGn - -diff --git a/src/tests/dejagnu/pkinit-certs/user-upn.p12 b/src/tests/dejagnu/pkinit-certs/user-upn.p12 -index 7a184f651e50d1443e5fe907b5a11455d69bc0d1..6daa5b378b83e9d4134ae48f8d1ebef715bf6cf5 100644 -GIT binary patch -delta 2698 -zcmV;53U&337L68=U4J7*Cd0h`aFqfA2mpYB1t^AZ29wx*eOgc}d`r>Q7K3iXfn7bI -z-h75b<#ho7#K*k@hvV0DY72cD-+GQbBx+_M+%n71zn -z#X29cB(NtFLejt8_}`1}u<)0Fa|N#PFrop1;9l4e3fW%nAm0812NzC2PWtG5Q-Le3SkbJQ8%$`CRQF5lvDMt^VA%Nf7 -z%gqA3e;};~*2a*2L2#V&7p#=9h0m8OkwZeltqP35E+5dzCHJJcdi2I@dxk4_kjEOT -zj0U8U0++mnH-9@Zh;5`5me2`GT}33BIrtwbrAtxQU_u1LtK|{6gpV~{xkE5ejT2ih -zN^~x-hZKe}PsA-74%;xY -z%1B^HDt0=soP3^{EKJ)&_b-pfV8cwL_(1dml;Sji;(r9YP~QfvMIR=;$|FM4HE^b6 -zOll6EI_7z*5>D_vgiic>K%ddTL?+VkF!(XYy-glao-W+_2?bN*!b-%g+(*LW1WU#4Df_kOw0G_-qaOq{v+SRpmK1m*tb3kPzLIGjVa^ -z2hUFOzaEpi%o&g2^lIMNwb&tG?#XFJz%l4U56fY`oz^klt?AK -zuXwGHf}vN7zq;z1mdw(fafua(ZnorQ`;=s@1b^+)-r`oP1|(c=7dWrTM*Y3X!S+-s -z6yvzsNy6{reSb#uzqXA*j?J{*SW(elo9x=4Tgvmk7340ZG;`lvBR3tL))izIU+caHn$AdqnrQly -ze+yjHVauRy-|J4u6<7{TTLNDLr4%Jx7=JHGUoO1>1Jcfv{I7f>&cx$XLd+C6{T;$@ -z!JSbO;_3Sm(&oAtwAZTwA;V25RbO9psZt* -zln}2yx+-4*YnuuI!9EkI82olCom|r^m3LOkVwF_AlZNQc;2PpCjjVZX)YexUPnw2 -z_$_(XXS$6%xZjS13_#*rgWL;?J<7vhZ&suuk^}1zTKrxKS~8Q14u?oGg}H -zlv+EHsJHLYhdzk>*1*x?GypZ%k$)pPwmu21v!s;VGk^k+YzPtgAL>R8DmBl>#+JNk -z9u*4ll2JG9`v}C4*CP{?T!#_a+ScwglwY1hLX}2-)3S}nNh}9HZ+}fv%zwfwr^~k! -z=rp+UoO0)meUalXvhV<156HPdXB0C2j3K;I>+=s(Buy-477MAi_(gcw~VJ;|J3AUk`);%Zg&6=cfM%r$Q?RW!0hdBllOO0 -zTK$e}^K!@?la&QVe>VvCGU(Vo?g9b`00e>r$fO@bT)QV0_0B1+RtRaRQU!+^G+F8ByUATuiqPku)}3=nLROGQxsSbkkY- -zasCODE@NO&{NkW~>X(G9%rXzSV@mm{^~LPTEK*0Wm{&=#e~+kA6Ku&p0j~W>F>f{_ -zePAde#=SNS#X0&z^HzqJYAyDwxNt&TfKJc%3yAgfrUZA4_&$b8o8XaNZw=|8qY -zljvN6gHeh`L6q!)aIAW3M| -zku8zILVI$GTwtMdU?^96# -zg~=M+e>pl9)d2Z?X8#?o-z0==7jEP#m#A>bdA2062BlD8Lkw*A-P*PsR8T~|$qx;D -zg^_hvYQOo650pOQ9dBiuA#&WAk;Ae&G*Kp;Mz#)6aM7P|YSDn6RK -z2FMmd^WV`rg9qo0*gPnx{M#w}w_jIXLt?Htq?997K%)maV%KC#Lbt!#l8-tKoQ$GB -zXiH8|epkkQXRPYNxML#!2-7pL2YG28Kjpo|2b}kK?f)J1gPw({=3$W^com8c3Ye7dJ}RHz -z*vvJzwpsR6M44c_{jk~~Myb{^rc(sqe>x=O*QBRH4UGQB?z&_Bm@zH!#+>l)4pTGr -z&x}!IZ*t34iEdy8K1?hC686S+fvw2MM4b6|ovWo{VfySc*qk^hH|y;Ox->fB-fZW3 -z9P`l12ah8*RP-+LVYybf -z<$s@pM^MUhoQy-XmtfWe_GYFerm2qLg%H>?7HBLGv~=PBmQW8Ay#|QIkK#;jO;$81 -z;Ec&>RSgW` -zXj?}J-UUPY8f7(HIC6UZGfOfO72c@ABwq8tiZ0?s3(7$ -zxM}RzJuAa0`@+dpgSHC=ye;ze6=fI5jLQm5(4O@ywKR%B(SKp;94zpF34Epw$elea -z9!~P+oiqK>Q_>yAd4Fbui&Gbz+?SuIr3+{gn2}D)4zKA -zw6q+|xyzFg{C~CJXs@2^$asn4KAS;Hr!s53%;M>!4_lI!j -zE@siDP@6({Y?SkW5h+LdIH$!`_-XqxelFC+82Tg$EY9PMt$UIeu5 -zj=iT7iUSA-e*52|0Dc!;kRC(OF6vpH^HL(#b3Wr8xr5SNtP6{wfsN>aHEory -zZz-!@F_mMHzsyrd5SFu-?*f)-4@0fWC;9#&dw*SQ32o63t5Zm+f1C1bL*s$N7grel -z=O+Y!#o8f?VAUB9+;Hl3)PR91eu?p_GHL`ZzV(YKX%{M`k(!63Bb|Ob1gX^X;@_0swMf$S~y?O52J5Ow2Ei5EeZ0liT|CpLX3dRe|Y?h-)%* -z1Ahy_Q}w75-Y#V2+pavIB(a*V$3IEPg?T;;_;l~R>6v}Ls7>PH|CSU4@((!&99d`8mJ4VP6tfU(4xw}bWH@+eq;9;I?L2T^2F%;7KMe9jrkMY5 -z;~yqZdv|HCk0HHe6ELR7-?n0PnLebvx^Hl$-REUwC2Ty#$UDZRB}HY213#mttD}( -zBu{Oz+8I6(k)MzWxr$ksqyo=hI1ZhXWX&Y5JiN0mzSsk}t- -zJJ%SucVFN6AEIBj6-I!tXQhuHr>X^w6cJM(yq|zYJ;?@eY;==f{|XXanx4vhND^Z_ -zVG0NghDtq_C2zj$Dz8C#|AZkOPjw>3G!iII-&;gSHv%p#e{RGu#nP4#fobQPcfv18 -zgrG+nAHI;bL{ylamN8W@lZ^DQ(sR -zT%P@xq9c;o5?_9TBIsOs|hcX>KKPL9C6IfhyjT9og;C -zTTYklra)`+#hT@j5b!vTCMRNv-&CN403}aafd@V%?CBOpZa@yL63{b_VYz#)84%BP -zfYP3we-mmC228v;c=3=b_ySr8pLt+9&oCknyR!6tdU*&t03h4#MVDePO!=PdJKgTE -zaHJvVh#iv(yLboW+T3TYbSszMmU_pnlTuRonrN;Bt0)GPvhsgs*~x?(edh&W?F?mzlkD$J3Hfwl`moP6Hg%s+6VJf4+~1Rx+6eBhwZUl;!=3s8jgC!;aQf -zD9Z@?L2PX$Ghgizq~7d-QhTd>iMJ9kiDb%Rq~);boeQ_o6Gz>K3&BxCt+`@~nJAh% -zg!EqIPY9B0ewTqT;i1r~)!+l+G9oP%4++@@;Yo|$z -zMwTf3)yGj9S(sW_1-Kzi6+3#SgOCRWU*>*BPfO6cBnql?REk}m2!l~16V`K&3x=#~ -z05!gcR0QYhTv!?>tIt7C*)hIDp`l^Ge?{+>tH@RY7FrUffN~A>;tlE(3sD|7LUANB -zis>fX5un78BnY6sbwqF=OpLF_K}&sQ>&x9L3ga$y?=2hF63nby&Kn+_8fYj=Q%qs9^LzWtFszxdqjsR&mys<{B|EGHk9GANU8t_m0Fe?x$v -zpy|a!(Wp`ffAoA3^XaeEa(HpQ9c1?JtW^k>aa()*8q(TFBZbOowXt_)DRU3xiT^R= -z=F~RNdSDu1@)T$jO}aMmZ0Z-E9f!w814*M^g*;BUCL)C0s^{0*#IGyLz;78!^?dxg -zVlRVeg08jZ18}h9;65v{AH^?-f8aiTOIbeJluz**@tGI6G+BB)7Q~kN!AQ{g!qteM -zhqd!L(uO>k74-EEJMTAE*X9x#e!==1fh0RBMQN77*2GhWj_q=-;Wz;n_ig?}US0W` -zOuQS?@DtZzW1f~nnyoPEU4QEdRHRCfek}q52mpYB1sD{K_#Ii+3SG3sHqthXJUvY<=YDAc -z9#;0PWo-O>j);dWavz`vlnJdRTmaQEo(0cc+s7lXMT_ckx;wyC2|pOcNMhk2NQEoc -z(*6LSNK&b;J(RKHcLgS$UbyOpsCkh&(Z&4JM6@2PAel3A~|!xb3Th5gvs -z+2ZyxIT3B%aetn&kjA>&caGx0pjK-&f8Q_X>G1awp^&srIY7Je-gw)mNU&6nAKeV@ -zDUyEhZo?kDw^KqVPWeWk-%0aRE+Wjuc3X9h@7jFk@Bt8^KtvL9oxdA)#3I|;*|BOo -z->lHL_8Whhtz?3eZXiK#wkl>sh(V2h>Rg}a(k;J|xPRt2O2Tj<96swuA_=jT#@8zR -zTsY*e-_N+_<&h_dPb%s`G69d~tdf<}E{REDc=M2s^y7fW{0hfw^3IhGV>@v#&Kq3} -zhwf5UAn^i(2RW!~epxan!iiQi1q9E*i^;IyPET${O0wgRN(&2aaM8OE5y7A05(S7? -zsYqm-b$@CJke2fvwgCDwtGEZSH5p4N)(<4?9_pX)FmKp#;CJk)fx47Q!Ji=>(`gLt -zB9@RMXeL6z=WsaVZGDZy -zS;DhvL?nwM{iQ)K1<=B|aQg-X&IDSl$A~zKkYo -zhV&KKYp^vG$Xo#98^t%_%B6ouEDxE%5^=ljeyV}hvfWi+B(755(_^ -zyBq^D^D)}0ODnN{tCc;IJ~a0+z_Z4F{>vTLxtG7v-n?O6^jolP-ZweAlZ6FFe`>0B -zfhbF<9s&Xg00e>r$je4%i&omIruPaAML(chuA&9Npn@rycZovGBZ#}MmPoP7HFyS+ -z5YP1fO@E2>32IZ)3U7So39tUWihv|bt@|JD=G>W@vLbuh$`t2r-H%|(HA#7Z7W-_6 -zMx(NU&So_YHnXHr{(L?L$F@_~eG6X?q6S`WCfKOSVZ2DhB(;a-fB!!0 -zx12RrgaWp -zY5qyxizI4x;ougu@A$3NK6q`unhku}7(r*IjuEbk_W?J+^#5)TU`GEu5)6)&$OQdF -z;-goaN}BKgkRb>#!sPGo0~l6y6J_wWv)T|RQ;IHAJzqBid4iXawd)P0rV6^HMLnb$ -z)*C7%K6%-JP9aAHs48ype~zwJly9JZ$}NYKx-Mp9`1s6RNNL#vLto*^@?m;nGW+I= -zWrFX-+Ya8`rQ6nHMD*!7*jvVb6y)NbtGwi4TGa~%?hH{~D+F~WCg$qzYa5~Jg_L|t -zRR4#x%vZ6tegWzpK5qbxOZlsQw9ed@cuy1?5hFwQI5x`5k*FI1f3=Bo6N?70(6E=! -z)=e3F8h{}lF=#L0^Xd)rP>R2*=*YJFpRmnBBqPdF6~Em{>vK>4KYMxGKc(f49lQR* -zpC5e;d4$#Ea4PR55SyjScaGF=qC5ad8W_NCb&1?YgbKORkd^;He$u%fp+PlI)X|mz -zVstj3!6b2+*r!Dke}#limlzF>9>fdN{BmbrZ}WBUCLIQZ!JJo(?`OTRR|!iY(4U7e -z$^v2Fxgs0I5*}XGJhGl7%`WX>-$vfL?F|tI;2fAi`BD5;7Bd#Vy+Sw;PxmH*ra_J0uID$f8R;tP|Zy-aDWv?@#W%h -zgadvFj)f%M9Vnn?eUJrGfhc=2RDa9V -z>FxIlgkKyC(TX_6Co);|LM8Y_i725KU9m*^TC$^0OB)4Q@!qg|><#|?M~Ctb+P+hI -zkbMqX>Z6#Xe>34_&bOc2;_=J{oyk_Ny}nc=NryDiE!$)Q7+PK!i92EIEojc$?P96m -zc?iK(OD1K6|1g4R+r<@Y5|Jg!GwO8#LjQ})>Ni^dMDAw0p*0`d{zeV3zaLZ3oYpEw -zH%D+{4}P!wbSfTH=8xk$*K9Gx2wGly)4dY^K_bE!e@dLK94%Iux!tn5oCu>-ve@+_7Qen#! -zCcQI#e_G{j=hkznNe7#RtdAbEF26Pu?E0(v%|h1m<)!3M1d@Njft3yg;C}h;Dso!= -zfAFsv_<1EcnjXbW)|JR|FCL)ej`wM6w&%hWM}7Gk&X#(57o~9AdT@&Zbv}$YQU*8&0v05$6?i~s-t - -delta 2682 -zcmV-=3WfFk75x>EU4Nojn7^Afzuf`?2mpYB1sEA6cU;`CoS+7>CyWFQ$f+`W0i)xX -z1IMo8fFTH+Sz>3S>Uht|Eny;NP)?BG$3gXhG8NY)?NxVg6aGis7v1YDigSP`x?im@ -z`?Db1bRoQBgcP>Q+5v3SBB~AyAzr+=xrsL^J*kw{1hZ5%a+ -zHc2Xg8*)=q>SP@L@CC{#w>L^Z+J&6pnI}#Mq2P6X*Nyqox5QLoU(Jpxpoq&?#cuXc -zXJAXQt}I!EzNSb2ejUPkjluI$|4N3SNcUzZvV&GsmZuciaq~wn*p_S%?j(No_hj!&e-e>lt2Pg<@@fsC`72#frhb+0TlAJiVEMe+^V -zdV&&N)e5!qVh}cr=ge)HA7V6&5DHAbYHMo2Cwb?2_HFi@NgTia_2J9}>VmG;PF11h -zuX{^wYCwv%P3F#g(FX%|k23^bb3@-HU&VT%}IkJ8+A94z3vJox8pxZTm -zh96kU7&>62DbVf_jg>pF8CWC|H9xpweRbyo-+3m`BB;l^m|n5?F~-UAw2Eo|Upr51 -zfzm`i1<%YQFY4E;7^kKDXL(Z>fhax#kUom*Hj0_R>A-22fRZK89x=g|&JSE{W{2vI -z^w^gDgMa^gOhBw$Ca*O&b-vw=S;5yL^$nwu8i^;~ -zmVO3ig006aRom{J8v_Oh6k7nJM^oOvgO$e?LIcUe@rCtq|s3&RB^ -zp*ri|HnLH%?bY0wu{FJ?nTgs5ZEh;!_`)$2#t+ZJDuWwlGEIQ!^sZWqrL^=L`giqm -z34aFCQ+hfGDFnHl9}q8BCSMbhWO{0LhibaOL`8zaZw)#kDfpVL!WS$Bf|Wp#SGs8z -zuMxe^2$FU%zGSVpNVe46cBmbY6hqiGm#PP&EQ$kq_W{$pm06H0I%gFf)9CYmtx{e` -zCJomci2D?Z;c$t;*dS$k%-x!+$E95H>*!vWXOLFkcWfP(8vvqEm^ -zD7?NEyE=lGE=5{3&E1qK?Pq*of+X=YNRd~ny(2zVQ$<$apcRzL@uGb_@^{?HAb*II -z$&EQT=ZqVQpB3Q~c_g!iYNSeNLJIbf9LS;cn*N*`225y4pWcO>;8=j3zmG!aoO6zN -zSv~SZC)THX1T9jO_hUY0^=Dn#Xf}@Po+cTbq?@TM`@ji}ttmn2n;Sr4S<{d4l2a2) -zPS}ZZea)SIItKpy^!VN -z+N>iElo8@Mr$PrK`e)v)F{}y9KcSe}c^NmRCcg8to5T>| -z))WBs=1!|VB#mFx`T^_p+=Pn>y_{Zw#nr0X{?<`094{ph7>-~kbq@olS=kAbC8n;u -zqo--UqoV^)&Jq=A_HU}Cbbqn(f6FcUJe4TRe&a}TeVj?vOMT*nA50LwT!xaLWC~?z -zuR;Q1O*uQ+^mH=6@E2eV!vRW8xN1V^ -z7CvAHrt*6lqf)z5mkVEybFjWWrp|)?J*)@-OENCPO5D86?t`Ru9vD!^e;eouy|I2+ -z)$WnuN?<+4|2P~77T6MX&E~%*V{m1X=w~b<4D1y6!fa8v^q-RT@mT(ydAbR9tx)Mg -za`UP#n<^-&N3T@x%5`|IYt`Dh8FG&3*k>3@-f8ZRSjJBYOX+8{Vp2tFEQl+0M92wn~XpZ4n$&REI$O|!A -z|C&upTLIlp;Cd-QTpjF8zK+*zVNtRL8TaU#8gXF2dW4AnLSjby@N|0|VUWjIwuzP7 -z2xQObW)|z43v)#`5QOv~WpJ>Wxk#=te<$e*%Nh%31rZ;eP4F -zCW8>)15kbf%VdCj6aFwL?c2SQo#n52WiFgQTPjU)KxSQV{S``6ngGtn -z|Lk(B1|^3OZUXEj6IkMTS+tQbc2JMX@jaF0-Y)3F&iIGWY3c-<&L!MH-FQs?2>rCo -zW)YfJ#J06pbph*0FRV?dVRUI9mZe(rkQ(0v9mAEpe?l>lDrmYvy^Rh&^F$bAg9aFx -zb;PX}B%WHxJK8;Gcqh-`?*P;qO4xaQT}m-W6F`5&om0=1){V^dwH-A)3GtCm7iP)scf7`!^ -zpcfWDpn~znhuv+jW45rkqMPDQT}e67FE|w_ESX(LKd}_=1_wtRDk{{ei?VevL^v4)*gHc4wiT(y#HLe -z4qSa#+Lf4khNXr}4Pq3ujwKQ%=*c1>#@tMjIH6+JG=JUgo3n9hbV2@&`^09UzLsXx -z1Q0;yi%cyg>96()dg6wn_&qzl`iL-O?IPE57!Zi%GjLm9XfP6c3OXaDg?zmXl_m|- -zD#I>Xh}5fP8${o7N)c1RcdbKF?oNOY6SjNF1NxBu?Xn2B5^2_>uDznS=+!Ntgao5u -zB_17l5`Tuv-3}{<8W0>JB~ZN>!|UwyTJ;p$j>5;?5;Y$w%BzS>?M_-N=&9H^M5*5VIABRGi2Gd*F0<%A61E4i|HUz -zX!OLlQeM2}Z={{ENfa0g*iW|uy6#x-f>|U_zzmuM>X>mvJm2MZn#=zwdTlT-NTv)n -z$gq@JThWUCy5?f5nUaHNcqc>Wi{@iB-%8J0m(YS!7p$&;U$Mx~#YgsS#hfS;=L)-0 -z4}bqab$|EYJ#yJjn${s(M^^4b`Y9ZM%%!e@ka;J&=%N+5kQpuV&Y*NQ6%bqqrp?0c -zvkASQ^E5U0TOV~zI*%0#ts88^z*()E+lgg{*<{;CjX2|_kR5t`3b)2*_|u7AS)zCI -zddqMp*eroBDYq6%$yo$Y{G=>O3TL-|_kTW!!P_2$POnW{>xFSfio_MXs0ww-mo~hi -z=(rSEzL&BlLd#CsC*oqs6C~Fo+9Hg8?ck})d&Mf}w3xopmhhLVP`QjiQyjND61#m- -z@Ti!l54-Aa1EIxMwvv%1+o8lC5XZ?$KpMOoo;_Rth{0DdmNF=oifNM6@T>e -z7}*!D{OdLG!LDBZFZ#;gcf%2Gl4oOl6Fn~r8DNFFQ~AA?eY^)C|5Ly1pjk;wx&r6# -zDrVnH0^2DH(;P{I=T})*lyeFUa6%tU6RtX@SZ<2mTs?v7BL{(|rzuaK5kMkSf)x!P -zMII;x>mr$R@xPVtr{^r7my}%1}E!A}WmbofvFM -zcS!kljv8Z%(&&Qf>ru913`}dK`R}b6!=OYQ|L5CpY15F!mbW2qYdr|JUF9YL8WSuf -ze*bNr&bN?B+Q@E1=uUeEjhQSIS?`-Af4;LXKn5N-XLq6xc|f%_#M%w-*Pn9 -z0f3p>$dACQCD|ZcE0T;i&hLLDWC+>2e_q0`-xh{n0FH%33ag~TcZ@rg112tzut(cYLAtgLWrFG9P}7g>GqSjUx=*%5=Ei(wi;B#qD!D0DdHB=5ne3p -zz7X)28kw|s=IQ-C@X=`XBrP#XfrYOchw)SmxSL>Lf2fV;6VyWK+tGI0@;#9o`ML}b -z=Efu{JvtPd@rn|9u&5^X|3=^8Ur|_(J(G1WEIKJ0`^x9%VSj#?Nk6WwjXxRnu-6m( -zjd)VmBbBWvY@1~+Vw#!O<(3tv)oh)ricul3Rfwl%X8C3a+<33*fD-2-GI5{qDV75o -z>LqpWe?G2-@V5x^ez4WY)5DkL6ZxDB*vBE9%u;E|A>H(s6n}9bH&KQb#zdIBW7MnaIzRarxL@n!O)O -zK=8REHm-D)+!QbFDD>eFGqQGle!kP6e|@)JpgdCP;~7UeyK0@F3NK#SJ0IUT4CA() -zo39%1U#tTOc@;VYuXNuOe?N1eS){UjB$ovmaX=}kj~2dJIL}s}NbDPCos#k!q0k~& -z6(yK2z2-dNY(yJA%`mY1gCo4XY$|Rb{VRvx>}p2VB)BS18|crUeYiOaX8I5uf9e;5 -z!Sp~;hom{dK*GcnV={{eZlquY3=K$u%N;dC3YcZ7Jwid9q$w720~h8_o0`rJ#+e>}#fXz~jOgIgpH5GUFmGfeNWtu%Y@mn$$D4=DMM -z<8V+G_ROuV$#I&3s%U2e{*tn{;XFo~vnDzTiDiOa;XL2_2q1G2#|Ib<`7((J_Ta?x -z6ma$u_FJom0HA=6G# -zp;0g~Fd;Ar1_dh)0|FWa00a~tK>i(z<@;kWV;*m?sLnLjiHbx72-=Fo1r5yv^#TG2 -E0EqGn4gdfE - -delta 2698 -zcmV;53U&337L68=U4OgPIH0Ma|Ih*g2mpYB1t^cgTby1_i4bV`ET($=&EQs+%VWU! -z7EL>iJi4Z78OaT9ubV}bGdi0`Ahw>yNtjoh(jz*K!b%&Ua)hJeCBb!FAt9G4(CLat -z`Rag4jFpnmFT)s@f*z8jt%jD9#v%N*$?L>k;p5=UEuP*lV}GdN&eI?0rjB?@WB}eY -zf)XxYT1q=>J -zymMlumTAK2tc{81$;?wU?RVDyIg)}6Ru7Is8*D-idC>`arMh=W)oa9!1#zHlQH+C= -zxNFQiy$@%pUw>ciB6Pems-P<2y=ikP`PqC(+TZsM6awppC_f0Xl3g4K3t|VAQ*|@t -zqWP;7pCfxOI}DZ9(iJy)rS*nL8a}#DV!e3{QR4jj(Ty7a7d86H_%`o3)tY*5-w|Qk -zembO|Ujs3}!86C73mgV0q^5iPuZU!CsXRr9j$1G30DnT~&96xZ(_w+gVmP}nkT+9^ -zTnBG}hdQN2AJnve+R?%pEbv=8E5(bzWG-#u#DzEycabv3EOTQ^KP}Xh8CNH%dMrC| -zl_ZZqKVqcBMJt^u$Fh!)FjVOw&dWSYUg?omm_rDHAOgriM49P$d0+1``GCJ!ZsQwc -zIeSn5N`Ij~5U5@dvEBjG{TiDpjvP!%Bx(#V7yW^c5vbxvj?}{zE!H+*c6xgo=IhbX -z{ugXqn`P$jl!c&05S&~~#+%)!=U#Kbk5wVT)3ql;lTT$>=q+JLDX30eW_%PenT4Zp -z_goXztU1Ch8>MHCoD|K5H4(V-ja(n=t}k--9Y2&($W_V$rpuB>QO?+3-dA -z-pr3g54LFhpSdbUZ -z|IdewW&nX@Id-7N;;8dTYiF$bj&+Vzp?^hsO`e7M7OU$Gla=8Q4G^LnBF+hG_nBeb -zu}|$?y}&Ypv{-4`sZB4J84gG&-!sF!m9%?q;wc<-;0*nm{J3|%$s#f4g#v)CGLCU4 -z(Yc7zteW+0h{?ByycGWhd;fPj&Dn(4myw17)6pVR`dcE2`6M7x!wVsRwxjCdAb(Wf -z4D$@k@4>yr5z6XWYn7pBxh_HGbj9atGCo7126F9)ewn?kfa;&vg>e{5+wgb3)|=NA -z`o8_Sx*VNIakI&`^qCUyxWkzJM}b~6qYN&iv+v+c(UQ5=%{ok(ekXq$lZ@xKgBHx0Tl@87a+hB943i -zFD%RA(jSI%C|Xca<$+=*lWL`yEop8}Q{X%bQc-xA;u>Z)z-N*eV}?4frikpteC|{% -z^a!Dtv`0%$*x`Vxh#$niPcOGkf}NjScYXD!MU!uL497Oq;pCJOkrMUvRzj(C7>B7| -zirNe8d;&TQyncnqec(ERvcvZ=HhwevKN)GUzDKIn4gl?ZdnRwvb(WT2#ZBk3!kjVD -zJEGu3Mj^N{la&QVe+@0G1;Pz3&jJDn00e>r$OX00Alr(atOG})P|bur1*6+0Wi&x_x{|YhpPm9aRrXy+e>w{XL@?~)eWqce&iDF0 -zqMSy`TNzT_)VB-&hdVeWjEeXb0i{%KpZeK!$PY01Wa=BLfB6xzk$J9wnQ+$8Q?cOh -zQWJ^oEshJdhCpbB9?+gW%#d0mHXCu4Kr$r>M+VFC+yRsa^lQ^YyqVejN5NolmXwl= -zj;AXtkvzSNf4>f%vSi6=NX>a2^%IT&;v29li&z4uXN8vz(uEM&T*Qo=&F?5rk#RQz -zC336+`bfFPsilPKn2a5|Np2S1s2;)B2v;glXVE<%O(u+#u~*}7ksKGB=)IwePkk!6 -zKOP3PmZY@6SqGV+fn{aX%cf@iNQisE!MeAT`8h7je{pcQ%DlZS83P&0<4$9^B?j!n -z0^s^wwN->E=~xLdD_)eKs$i$WQ?$&-S=N4)kY -z8sF-Ce>waid23??s6b(A4ogu;h++fH;y`eEvd@BSm#`s!Ry -z+6L`T@d*j+#(xh*)fPw%XJxi5_WgWEv1C&^jNYt_5ZCvbDlQ07M;HV(J|PE-03cDz -zI%m{>hShEl-wN=n~{2XZ{L*9dR&>p&O5P -zL~0ADX*&QcF)J*1tw=!e<$;FCS~Q>H`vQ6<^=_{tlE=R-j`1+-CyIrhMa^l@GsOkoi*b5gc{|O)u6y -z*Eybgfl##owFc|2DqiQ%>C%TLxKNZ2)Y8q^GKz)qUCCb^Y!~Ouk~utFj^%qDAD7$7 -z4|(O*(4Us`f{<2cXiaTtd7QygQM!6=e^+!{SnFm@Sce*pSUC_>Mud$loY2}d94m?| -z<^OOSjsAsDBC2thdNWvSgLi|B<-_+{K_gsBydMbNjR&C)NZ%Y(>Bs|d@Ni&G^NWGp&(#5%4Z5twBV>={4~8{UuyO)#6}%;xPIHyY{h_i55`b4<${ihODv=^X_GvM2$(ip)-{scMp=K6z4NT0 -zh9qH{M2vDnA%B4RMJV4L3g&uG{}^y>U@_^&s079+Uw;8UwQZawTn!vsnczNryXER< -z^4t|;quLw`bl;E|eEKmn>RrwfXq1zSpT$o-918IoaQn0K1Qcv~32@A!!Yk9d$5)cI -zy{aB^id7jlNY5I{?KJ6dEI`cwQ;~`h@bsE-*#wn1qLARY;aK^Be3VEOF^3YZC -z@z)+dYJm7<$cmm$-`oMA4%n3L(y&2%bYK#IC-~*C61&8wgQwA^>q1bHC}EtDjtVc1 -zELlaHTmHT=Yj$uxFYs(>usRFRqQvn&Y=h-QA_vyh{d+oN#SEVcRq3G;MW*B4{9l6v -zq4IfK2!A=Q^+R+st9#jqW4=?osK-Q)K4Hq5%bbPzj&C#dO##MJ7oXFI1vcvc70Jw{ -zEv_S72+LnOnU;)4y)s1`vlaV>-0o^K1+!777`l65f<`flFo5nDa<3{ccfhQZ2?{|o -z7c|F5o2|#B%7Rj;vzYt{Mut5sSc(Fb-e#e^-GBAX_{?R+=$MOl)HiG~U+;&08^mvP -zHNfv;+m0CZZAMc)NCYtA@^kdgq@Aok`CYuV8^FZ~W1mpM$Y|0UcYycv$Rw~Uk-pz- -z!Dy26%)YpIB<5W?r3BX^eu*^fEgSl~ReH*mqG<*`wedGDz+{; -zx4kLMqty}CrlV-aA&gVt>cAAtAE|kT{Gl>@GBfH-*I9Ut$$mL}Z;Gm~5u@3~UH3u; -zu*RcYkh532p}cjA>7*oslZ7OgH8tToL4TJC&l=yANqs|aNom00jp9FBDbRbjK3>*1 -z%t%A$fhz|l3Z2Gti}j5NxrXYzf=4jVC`TMPTZvUT-H%YSuYeGCOl)KMa1~`sWdLxxWOlH7Hp((U}SX!YNhgfJ)IPf=;Gx -zCA}LPUS!(0kh@$b!MG*{z^TG9-c9BlhSqSqv`*cklbr=df9nY*n}fvB!vX>b00e>r$RI81nSv?+Yi!SD63Wi? -zTpz5uAf~z86j38B#-LJmrSIOk*?dx5rdvPi*JcISr -z;GrMw4kJI_;L|8E8I7#QK@8J%06j|~QeRT5YPYz2e~m|0eC*+N -z;tTbW&k|>^&OYIQAQZ)=e!ZR$EefvbbEa%e@aTI~@iZEV&h?kl_iWbBu8gqL22EWO -z9%e@s!Ln9mn5gIkKyZEbno(BO|N92gh4zi>;+t!DB# -zUD*#wq%14Ws-EP3hBY-&Ihk~ywGtQqB8-6CEv895gq+Y?Ref!PVQoN$e}ep~l&{da -zqe>QuPg-wYhtPeEN!5YpIa21fnSW1kwM|Wu{MOd})a|@aJwy*geIt_-o -zf@_GTcauuKT26Cov}Jb>o;A$hT-*SD}c|OaKX(rQfx^MRmECJ-R!H{CDx2O -ztfI!lXTISDio|vGOxL+yF(#V^*FP|1>(VxK)_HV+LW+m+hM>6nHJtbPD8$YNAI`V} -zJxt8tv;~TeJ|us*$IFJ&gYiOXa5$hQD(6={4wTTv<(s?me|tUC1}n4%7sLR#^%2Z1 -z>wB$BQPVbOEZr-HbQu^qQZZDV0B=qKLSTk0OH6ViZg6t{x4jDwj>Q2g#8kQ3r>Eji -zoCHAsSfZI^gjaN%upLrFe;LL-L(-_It&su|RC&en#x}vk5N84OPL*8oFVPE6rr}-0qN*#i8!ZNM -z-lMCaJq9;t`UH;WVM3PeWlDBk&GJ8MW!kVJPop~_JfAJz8Tv~1W~R=A -zf#mg1W3o+d#@#T-2&}3LjtVGn(SoOHnQi>T=yg_;f6ZBqH!1J@yw>z^@>NitY+5GG -z$_K1gfo*y_T~t97XgHe91xGJb>0;+13X;T-03Pf6IfLg53{}XapD=~I*1UWMmfQ!D -z7Ze1;SJ|?3B4jg+a%x7qjgRh1J9NxeFNvzi*YlS;ci9S -z#DRe^Za5%?_JurFHR(9)uJQ)yN&4iz?H -zSw@t!Q))44>uN8OaX|V82359~wEHn7Fe3&DDuzgg_YDCF6)_eB6ccK}Vdj_r1JjB8 -zJcW?bd-abN6XY;4Fd;Ar1_dh)0|FWa00a~TEWhWcHtRjAj4t&h2$Cd#3qV%{2$+b8 -MPj+1S(*gnr0E_P~i~s-t - -delta 2706 -zcmV;D3T^e37L^u|U4L0@OZ+^lY6AiS2mpYB1u&$H6w%_X?Uh+pizOtCBDzx2lCMDmI_;E4nZypk7SId1QiiG% -zoX$R-HEZK1+~1}@RF*!aKybD>UweVLW#TM}CG=Kw((`3EMgCgE%Wh7i5_PDshVd9Oz|EjKxtnoLw`TW#&7 -zQPy}=X-XKHcQwT5v|u~sb^Inq0NJ4Lak7<6+3Ya}d< -zR^Uti{uWAJB7|b_QADZ~qF1trj0LGAR*qZ!4V-8U)PEs3HV=&h(r8ATc_D(AEnMV1 -zwuVIjs`^7H=|3CS`*aB@;CnPV&TlP!Yu&aLuDOS7Sg0Cqu0xGBQP5;o#gwP}e8{0B -z7jV-rq(ifyxm<=mq)wx^ScfIWLZ7^FtdIF5!b_#_SU{v)$6P6;3c{)K{n+@;OiiQ- -z)v(k`B7Y~QMMOz0exF+cpQ;~*F-}k8OW2c^cHxE_)brp6_t{vy8?fdPQ-ctCS#H(j -z$jQY05`;BJt5Y1_E&P`i?y7~+)+fF@I~p95YmggrA_kkXkLdVu+sQe~jV^LlG=Fp{ -zGMUwQ8FM7Kg20u!G&B)cCNQ!KA|~SY(%9(~dw)NYD5>AwQTYoOym#9ju3MlAj~yL! -z+9RAIsl?+#`6IQ~$`6sGmR#$qABV!__lx-g(mg2@c}g0+B+myWGZ@B1H-hdORvFBr11a5D -zD5mD8X#7lUgZJ09DQa34oE2MSOlRl*Pk;Loc@3DRHQ-tjjjDOpdmBQ1xk?t__INBb -zA2{y5_WewW14^G6WH^SY0hmJ8^Ng^zx=ZpuY7#VI+rLN#wJ0?Q;k^@dZ=X;S&RshD -zWP{?O$!sjtgM5;`y4Wj6`G$m`1OsXIXK)R(Jwf5Zy`3r9HV=gsO7Qi4jzaFFm49h7 -zfsyLIa}fYP4lU}*uw@gGo4t5v27iR`O@MAwyFq8%w;vNMFt1G(wBrYGlM@r4)ff!p -z>8Mmh-L?^v&W!qOH^7S@tzEEwdy!EuK#bBM?x4Wr`(bkkOsAP+#8TbjTL5J_=bS5) -za6olnR}(Db?FG0|ejvnzj -zP}Lz{>_d&8$(MkIB`z>!MW@mnuqJ@W?8->i@)3)j#DPAOs8q=yg6rJ-m=-Lk7xDaXe*1RV@>aTN~)U7 -zHjL@_ge{0Jt7~qq;qj^Jlbr=df11{|CuI2Wr$kBFUM=%p0lc|48g~wmO -zlQm6cm$_s_2>(DlA9cyxg6bmmW)&QR$peuE=vJIf2HTu-u#@{ -znFBj?5I#2g`5TG`?>T^VI($%BFj|uIDfc;L5->4jxZu(nSAc33NNkgSR!9J}GSx4y -z_4M@|c;BpN-D}R->!q&&aVy|TU2Cb!tnn_pGykac3R{dXLJEv0NPZVx+TTgAeJQji@`)5{g< -zcJZ=w(L#L{pjXv2RjibOnkQN957ydC_9_$?NmM?Po^Q&34Z7W?1h2;S>~cDOEpIB3e3RmaS@`juU%CSke_Xs}bPG03Hd`AnWDQe0 -zDzTI!DRp&=;Lw}C)$l@}&C%0-vB~aHYq5NMeTEzqqd+JdVj_`U-$+46eP9-nM7?zc -z5Pgt-^k?oplhg%4^}fJ8S>3v%<7ynPniiv_Z|t!~Z%up1%zf`A$#gTl -z|Itn@fJi}H(elXg%0X;2+!%;)-lR)s0rXj$+}J!$F5z3_l55m6b2_*fC-NqxNFTql -zdv*Y;FP;Z6UFji4Uh@uDeNWtoP&b(ZdpU59uCOvye<+Qgi5uA#^8lnW?w_X5a(Zcq -zqur4>A_O|0nJ|NBvfV)Jmkk!X>5(vIem$?G-`>87E-&XqHpVEiV;~i$OoPodAQ$zu -zHfA}RyWpW+OJ@WK!YX*SO<(GZEW~rTpl2eq>|IbuqzzqN8t!)~kBi0rn7;jaAq#?4)^yQTe=NH@6SxT7)@@3!xd(1))7AABX12%e -zGo=U4kgSi_sg=#zEko}S``7Td_RokC%@eQ1Z`cc&&D0V7DMKQ8X_oz -Date: Tue, 4 Apr 2017 16:54:56 -0400 -Subject: [PATCH] Add the client_name() kdcpreauth callback - -Add a kdcpreauth callback to returns the canonicalized client principal. - -ticket: 8570 (new) -(cherry picked from commit a84f39ec30f3deeda7836da6e8b3d8dcf7a045b1) ---- - src/include/krb5/kdcpreauth_plugin.h | 6 ++++++ - src/kdc/kdc_preauth.c | 9 ++++++++- - 2 files changed, 14 insertions(+), 1 deletion(-) - -diff --git a/src/include/krb5/kdcpreauth_plugin.h b/src/include/krb5/kdcpreauth_plugin.h -index 92aa5a5a5..fa4436b83 100644 ---- a/src/include/krb5/kdcpreauth_plugin.h -+++ b/src/include/krb5/kdcpreauth_plugin.h -@@ -232,6 +232,12 @@ typedef struct krb5_kdcpreauth_callbacks_st { - krb5_kdcpreauth_rock rock, - krb5_principal princ); - -+ /* -+ * Get an alias to the client DB entry principal (possibly canonicalized). -+ */ -+ krb5_principal (*client_name)(krb5_context context, -+ krb5_kdcpreauth_rock rock); -+ - /* End of version 4 kdcpreauth callbacks. */ - - } *krb5_kdcpreauth_callbacks; -diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c -index 0ce79c667..81d0b8cff 100644 ---- a/src/kdc/kdc_preauth.c -+++ b/src/kdc/kdc_preauth.c -@@ -591,6 +591,12 @@ match_client(krb5_context context, krb5_kdcpreauth_rock rock, - return match; - } - -+static krb5_principal -+client_name(krb5_context context, krb5_kdcpreauth_rock rock) -+{ -+ return rock->client->princ; -+} -+ - static struct krb5_kdcpreauth_callbacks_st callbacks = { - 4, - max_time_skew, -@@ -607,7 +613,8 @@ static struct krb5_kdcpreauth_callbacks_st callbacks = { - add_auth_indicator, - get_cookie, - set_cookie, -- match_client -+ match_client, -+ client_name - }; - - static krb5_error_code diff --git a/Add-timestamp-helper-functions.patch b/Add-timestamp-helper-functions.patch deleted file mode 100644 index 54e7f59..0000000 --- a/Add-timestamp-helper-functions.patch +++ /dev/null @@ -1,80 +0,0 @@ -From 9b50a75e97cbe9cc8c0a4e37158b56b58e966f25 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 22 Apr 2017 09:49:12 -0400 -Subject: [PATCH] Add timestamp helper functions - -Add k5-int.h helper functions to manipulate krb5_timestamp values, -avoiding undefined behavior and treating negative timestamp values as -times between 2038 and 2106. Add a doxygen comment for krb5_timestamp -indicating how third-party code should use it safely. - -ticket: 8352 -(cherry picked from commit 58e9155060cd93b1a7557e37fbc9b077b76465c2) ---- - src/include/k5-int.h | 31 +++++++++++++++++++++++++++++++ - src/include/krb5/krb5.hin | 9 +++++++++ - 2 files changed, 40 insertions(+) - -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 06ca2b66d..82ee20760 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -2353,6 +2353,37 @@ k5memdup0(const void *in, size_t len, krb5_error_code *code) - return ptr; - } - -+/* Convert a krb5_timestamp to a time_t value, treating the negative range of -+ * krb5_timestamp as times between 2038 and 2106 (if time_t is 64-bit). */ -+static inline time_t -+ts2tt(krb5_timestamp timestamp) -+{ -+ return (time_t)(uint32_t)timestamp; -+} -+ -+/* Return the delta between two timestamps (a - b) as a signed 32-bit value, -+ * without relying on undefined behavior. */ -+static inline krb5_deltat -+ts_delta(krb5_timestamp a, krb5_timestamp b) -+{ -+ return (krb5_deltat)((uint32_t)a - (uint32_t)b); -+} -+ -+/* Increment a timestamp by a signed 32-bit interval, without relying on -+ * undefined behavior. */ -+static inline krb5_timestamp -+ts_incr(krb5_timestamp ts, krb5_deltat delta) -+{ -+ return (krb5_timestamp)((uint32_t)ts + (uint32_t)delta); -+} -+ -+/* Return true if a comes after b. */ -+static inline krb5_boolean -+ts_after(krb5_timestamp a, krb5_timestamp b) -+{ -+ return (uint32_t)a > (uint32_t)b; -+} -+ - krb5_error_code KRB5_CALLCONV - krb5_get_credentials_for_user(krb5_context context, krb5_flags options, - krb5_ccache ccache, -diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index cf60d6c41..53ad85384 100644 ---- a/src/include/krb5/krb5.hin -+++ b/src/include/krb5/krb5.hin -@@ -187,7 +187,16 @@ typedef krb5_int32 krb5_cryptotype; - - typedef krb5_int32 krb5_preauthtype; /* This may change, later on */ - typedef krb5_int32 krb5_flags; -+ -+/** -+ * Represents a timestamp in seconds since the POSIX epoch. This legacy type -+ * is used frequently in the ABI, but cannot represent timestamps after 2038 as -+ * a positive number. Code which uses this type should cast values of it to -+ * uint32_t so that negative values are treated as timestamps between 2038 and -+ * 2106 on platforms with 64-bit time_t. -+ */ - typedef krb5_int32 krb5_timestamp; -+ - typedef krb5_int32 krb5_deltat; - - /** diff --git a/Add-timestamp-tests.patch b/Add-timestamp-tests.patch deleted file mode 100644 index ac64115..0000000 --- a/Add-timestamp-tests.patch +++ /dev/null @@ -1,599 +0,0 @@ -From 3a06f6a3cfad62da6dd8878d3446003f8293c3ae Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 29 Apr 2017 17:30:36 -0400 -Subject: [PATCH] Add timestamp tests - -Add a test program for krb5int_validate_times() covering cases before -and across the y2038 boundary. Add a GSSAPI test program to exercise -lifetime queries, and tests using it in t_gssapi.py for ticket end -times after y2038. Add a new test script t_y2038.py which only runs -on platforms with 64-bit time_t to exercise end-user operations across -and after y2038. Add an LDAP test case to test storage of post-y2038 -timestamps. - -ticket: 8352 -(cherry picked from commit 8ca62e54e89e2fbd6a089e8ab20b4e374a486003) -[rharwood@redhat.com: prune gitignore] ---- - src/Makefile.in | 1 + - src/config/pre.in | 2 + - src/configure.in | 3 + - src/lib/krb5/krb/Makefile.in | 14 ++-- - src/lib/krb5/krb/t_valid_times.c | 109 ++++++++++++++++++++++++++++++ - src/tests/Makefile.in | 1 + - src/tests/gssapi/Makefile.in | 27 ++++---- - src/tests/gssapi/t_gssapi.py | 32 +++++++++ - src/tests/gssapi/t_lifetime.c | 140 +++++++++++++++++++++++++++++++++++++++ - src/tests/t_kdb.py | 7 ++ - src/tests/t_y2038.py | 75 +++++++++++++++++++++ - 11 files changed, 395 insertions(+), 16 deletions(-) - create mode 100644 src/lib/krb5/krb/t_valid_times.c - create mode 100644 src/tests/gssapi/t_lifetime.c - create mode 100644 src/tests/t_y2038.py - -diff --git a/src/Makefile.in b/src/Makefile.in -index b0249778c..ad8565056 100644 ---- a/src/Makefile.in -+++ b/src/Makefile.in -@@ -521,6 +521,7 @@ pyrunenv.vals: Makefile - done > $@ - echo "tls_impl = '$(TLS_IMPL)'" >> $@ - echo "have_sasl = '$(HAVE_SASL)'" >> $@ -+ echo "sizeof_time_t = $(SIZEOF_TIME_T)" >> $@ - - runenv.py: pyrunenv.vals - echo 'env = {}' > $@ -diff --git a/src/config/pre.in b/src/config/pre.in -index d961b5621..f23c07d9d 100644 ---- a/src/config/pre.in -+++ b/src/config/pre.in -@@ -452,6 +452,8 @@ HAVE_SASL = @HAVE_SASL@ - # Whether we have libresolv 1.1.5 for URI discovery tests - HAVE_RESOLV_WRAPPER = @HAVE_RESOLV_WRAPPER@ - -+SIZEOF_TIME_T = @SIZEOF_TIME_T@ -+ - # error table rules - # - ### /* these are invoked as $(...) foo.et, which works, but could be better */ -diff --git a/src/configure.in b/src/configure.in -index 24f653f0d..4ae2c07d5 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -744,6 +744,9 @@ fi - - AC_HEADER_TIME - AC_CHECK_TYPE(time_t, long) -+AC_CHECK_SIZEOF(time_t) -+SIZEOF_TIME_T=$ac_cv_sizeof_time_t -+AC_SUBST(SIZEOF_TIME_T) - - # Determine where to put the replay cache. - -diff --git a/src/lib/krb5/krb/Makefile.in b/src/lib/krb5/krb/Makefile.in -index 0fe02a95d..55f82b147 100644 ---- a/src/lib/krb5/krb/Makefile.in -+++ b/src/lib/krb5/krb/Makefile.in -@@ -364,6 +364,7 @@ SRCS= $(srcdir)/addr_comp.c \ - $(srcdir)/t_in_ccache.c \ - $(srcdir)/t_response_items.c \ - $(srcdir)/t_sname_match.c \ -+ $(srcdir)/t_valid_times.c \ - $(srcdir)/t_vfy_increds.c - - # Someday, when we have a "maintainer mode", do this right: -@@ -457,9 +458,12 @@ t_response_items: t_response_items.o response_items.o $(KRB5_BASE_DEPLIBS) - t_sname_match: t_sname_match.o sname_match.o $(KRB5_BASE_DEPLIBS) - $(CC_LINK) -o $@ t_sname_match.o sname_match.o $(KRB5_BASE_LIBS) - -+t_valid_times: t_valid_times.o valid_times.o $(KRB5_BASE_DEPLIBS) -+ $(CC_LINK) -o $@ t_valid_times.o valid_times.o $(KRB5_BASE_LIBS) -+ - TEST_PROGS= t_walk_rtree t_kerb t_ser t_deltat t_expand t_authdata t_pac \ -- t_in_ccache t_cc_config t_copy_context \ -- t_princ t_etypes t_vfy_increds t_response_items t_sname_match -+ t_in_ccache t_cc_config t_copy_context t_princ t_etypes t_vfy_increds \ -+ t_response_items t_sname_match t_valid_times - - check-unix: $(TEST_PROGS) - $(RUN_TEST_LOCAL_CONF) ./t_kerb \ -@@ -496,6 +500,7 @@ check-unix: $(TEST_PROGS) - $(RUN_TEST) ./t_response_items - $(RUN_TEST) ./t_copy_context - $(RUN_TEST) ./t_sname_match -+ $(RUN_TEST) ./t_valid_times - - check-pytests: t_expire_warn t_vfy_increds - $(RUNPYTEST) $(srcdir)/t_expire_warn.py $(PYTESTFLAGS) -@@ -522,8 +527,9 @@ clean: - $(OUTPRE)t_ad_fx_armor$(EXEEXT) $(OUTPRE)t_ad_fx_armor.$(OBJEXT) \ - $(OUTPRE)t_vfy_increds$(EXEEXT) $(OUTPRE)t_vfy_increds.$(OBJEXT) \ - $(OUTPRE)t_response_items$(EXEEXT) \ -- $(OUTPRE)t_response_items.$(OBJEXT) $(OUTPRE)t_sname_match$(EXEEXT) \ -- $(OUTPRE)t_sname_match.$(OBJEXT) \ -+ $(OUTPRE)t_response_items.$(OBJEXT) \ -+ $(OUTPRE)t_sname_match$(EXEEXT) $(OUTPRE)t_sname_match.$(OBJEXT) \ -+ $(OUTPRE)t_valid_times$(EXEEXT) $(OUTPRE)t_valid_times.$(OBJECT) \ - $(OUTPRE)t_parse_host_string$(EXEEXT) \ - $(OUTPRE)t_parse_host_string.$(OBJEXT) - -diff --git a/src/lib/krb5/krb/t_valid_times.c b/src/lib/krb5/krb/t_valid_times.c -new file mode 100644 -index 000000000..1b469ffc2 ---- /dev/null -+++ b/src/lib/krb5/krb/t_valid_times.c -@@ -0,0 +1,109 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* lib/krb5/krb/t_valid_times.c - test program for krb5int_validate_times() */ -+/* -+ * Copyright (C) 2017 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include "k5-int.h" -+#include "int-proto.h" -+ -+#define BOUNDARY (uint32_t)INT32_MIN -+ -+int -+main() -+{ -+ krb5_error_code ret; -+ krb5_context context; -+ krb5_ticket_times times = { 0, 0, 0, 0 }; -+ -+ ret = krb5_init_context(&context); -+ assert(!ret); -+ -+ /* Current time is within authtime and end time. */ -+ ret = krb5_set_debugging_time(context, 1000, 0); -+ times.authtime = 500; -+ times.endtime = 1500; -+ ret = krb5int_validate_times(context, ×); -+ assert(!ret); -+ -+ /* Current time is before starttime, but within clock skew. */ -+ times.starttime = 1100; -+ ret = krb5int_validate_times(context, ×); -+ assert(!ret); -+ -+ /* Current time is before starttime by more than clock skew. */ -+ times.starttime = 1400; -+ ret = krb5int_validate_times(context, ×); -+ assert(ret == KRB5KRB_AP_ERR_TKT_NYV); -+ -+ /* Current time is after end time, but within clock skew. */ -+ times.starttime = 500; -+ times.endtime = 800; -+ ret = krb5int_validate_times(context, ×); -+ assert(!ret); -+ -+ /* Current time is after end time by more than clock skew. */ -+ times.endtime = 600; -+ ret = krb5int_validate_times(context, ×); -+ assert(ret == KRB5KRB_AP_ERR_TKT_EXPIRED); -+ -+ /* Current time is within starttime and endtime; current time and -+ * endtime are across y2038 boundary. */ -+ ret = krb5_set_debugging_time(context, BOUNDARY - 100, 0); -+ assert(!ret); -+ times.starttime = BOUNDARY - 200; -+ times.endtime = BOUNDARY + 500; -+ ret = krb5int_validate_times(context, ×); -+ assert(!ret); -+ -+ /* Current time is before starttime, but by less than clock skew. */ -+ times.starttime = BOUNDARY + 100; -+ ret = krb5int_validate_times(context, ×); -+ assert(!ret); -+ -+ /* Current time is before starttime by more than clock skew. */ -+ times.starttime = BOUNDARY + 250; -+ ret = krb5int_validate_times(context, ×); -+ assert(ret == KRB5KRB_AP_ERR_TKT_NYV); -+ -+ /* Current time is after endtime, but by less than clock skew. */ -+ ret = krb5_set_debugging_time(context, BOUNDARY + 100, 0); -+ assert(!ret); -+ times.starttime = BOUNDARY - 1000; -+ times.endtime = BOUNDARY - 100; -+ ret = krb5int_validate_times(context, ×); -+ assert(!ret); -+ -+ /* Current time is after endtime by more than clock skew. */ -+ times.endtime = BOUNDARY - 300; -+ ret = krb5int_validate_times(context, ×); -+ assert(ret == KRB5KRB_AP_ERR_TKT_EXPIRED); -+ -+ return 0; -+} -diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in -index 0e93d6b59..2b3112537 100644 ---- a/src/tests/Makefile.in -+++ b/src/tests/Makefile.in -@@ -168,6 +168,7 @@ check-pytests: localauth plugorder rdreq responder s2p s4u2proxy unlockiter - $(RUNPYTEST) $(srcdir)/t_princflags.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_tabdump.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_certauth.py $(PYTESTFLAGS) -+ $(RUNPYTEST) $(srcdir)/t_y2038.py $(PYTESTFLAGS) - - clean: - $(RM) adata etinfo forward gcred hist hooks hrealm icred kdbtest -diff --git a/src/tests/gssapi/Makefile.in b/src/tests/gssapi/Makefile.in -index 6c1464297..604f926de 100644 ---- a/src/tests/gssapi/Makefile.in -+++ b/src/tests/gssapi/Makefile.in -@@ -15,15 +15,16 @@ SRCS= $(srcdir)/ccinit.c $(srcdir)/ccrefresh.c $(srcdir)/common.c \ - $(srcdir)/t_gssexts.c $(srcdir)/t_imp_cred.c $(srcdir)/t_imp_name.c \ - $(srcdir)/t_invalid.c $(srcdir)/t_inq_cred.c $(srcdir)/t_inq_ctx.c \ - $(srcdir)/t_inq_mechs_name.c $(srcdir)/t_iov.c \ -- $(srcdir)/t_namingexts.c $(srcdir)/t_oid.c $(srcdir)/t_pcontok.c \ -- $(srcdir)/t_prf.c $(srcdir)/t_s4u.c $(srcdir)/t_s4u2proxy_krb5.c \ -- $(srcdir)/t_saslname.c $(srcdir)/t_spnego.c $(srcdir)/t_srcattrs.c -+ $(srcdir)/t_lifetime.c $(srcdir)/t_namingexts.c $(srcdir)/t_oid.c \ -+ $(srcdir)/t_pcontok.c $(srcdir)/t_prf.c $(srcdir)/t_s4u.c \ -+ $(srcdir)/t_s4u2proxy_krb5.c $(srcdir)/t_saslname.c \ -+ $(srcdir)/t_spnego.c $(srcdir)/t_srcattrs.c - - OBJS= ccinit.o ccrefresh.o common.o t_accname.o t_ccselect.o t_ciflags.o \ - t_credstore.o t_enctypes.o t_err.o t_export_cred.o t_export_name.o \ - t_gssexts.o t_imp_cred.o t_imp_name.o t_invalid.o t_inq_cred.o \ -- t_inq_ctx.o t_inq_mechs_name.o t_iov.o t_namingexts.o t_oid.o \ -- t_pcontok.o t_prf.o t_s4u.o t_s4u2proxy_krb5.o t_saslname.o \ -+ t_inq_ctx.o t_inq_mechs_name.o t_iov.o t_lifetime.o t_namingexts.o \ -+ t_oid.o t_pcontok.o t_prf.o t_s4u.o t_s4u2proxy_krb5.o t_saslname.o \ - t_spnego.o t_srcattrs.o - - COMMON_DEPS= common.o $(GSS_DEPLIBS) $(KRB5_BASE_DEPLIBS) -@@ -31,9 +32,9 @@ COMMON_LIBS= common.o $(GSS_LIBS) $(KRB5_BASE_LIBS) - - all: ccinit ccrefresh t_accname t_ccselect t_ciflags t_credstore t_enctypes \ - t_err t_export_cred t_export_name t_gssexts t_imp_cred t_imp_name \ -- t_invalid t_inq_cred t_inq_ctx t_inq_mechs_name t_iov t_namingexts \ -- t_oid t_pcontok t_prf t_s4u t_s4u2proxy_krb5 t_saslname t_spnego \ -- t_srcattrs -+ t_invalid t_inq_cred t_inq_ctx t_inq_mechs_name t_iov t_lifetime \ -+ t_namingexts t_oid t_pcontok t_prf t_s4u t_s4u2proxy_krb5 t_saslname \ -+ t_spnego t_srcattrs - - check-unix: t_oid - $(RUN_TEST) ./t_invalid -@@ -42,8 +43,8 @@ check-unix: t_oid - - check-pytests: ccinit ccrefresh t_accname t_ccselect t_ciflags t_credstore \ - t_enctypes t_err t_export_cred t_export_name t_imp_cred t_inq_cred \ -- t_inq_ctx t_inq_mechs_name t_iov t_pcontok t_s4u t_s4u2proxy_krb5 \ -- t_spnego t_srcattrs -+ t_inq_ctx t_inq_mechs_name t_iov t_lifetime t_pcontok t_s4u \ -+ t_s4u2proxy_krb5 t_spnego t_srcattrs - $(RUNPYTEST) $(srcdir)/t_gssapi.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_ccselect.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_client_keytab.py $(PYTESTFLAGS) -@@ -88,6 +89,8 @@ t_inq_mechs_name: t_inq_mechs_name.o $(COMMON_DEPS) - $(CC_LINK) -o $@ t_inq_mechs_name.o $(COMMON_LIBS) - t_iov: t_iov.o $(COMMON_DEPS) - $(CC_LINK) -o $@ t_iov.o $(COMMON_LIBS) -+t_lifetime: t_lifetime.o $(COMMON_DEPS) -+ $(CC_LINK) -o $@ t_lifetime.o $(COMMON_LIBS) - t_namingexts: t_namingexts.o $(COMMON_DEPS) - $(CC_LINK) -o $@ t_namingexts.o $(COMMON_LIBS) - t_pcontok: t_pcontok.o $(COMMON_DEPS) -@@ -111,5 +114,5 @@ clean: - $(RM) ccinit ccrefresh t_accname t_ccselect t_ciflags t_credstore - $(RM) t_enctypes t_err t_export_cred t_export_name t_gssexts t_imp_cred - $(RM) t_imp_name t_invalid t_inq_cred t_inq_ctx t_inq_mechs_name t_iov -- $(RM) t_namingexts t_oid t_pcontok t_prf t_s4u t_s4u2proxy_krb5 -- $(RM) t_saslname t_spnego t_srcattrs -+ $(RM) t_lifetime t_namingexts t_oid t_pcontok t_prf t_s4u -+ $(RM) t_s4u2proxy_krb5 t_saslname t_spnego t_srcattrs -diff --git a/src/tests/gssapi/t_gssapi.py b/src/tests/gssapi/t_gssapi.py -index 397e58962..98c8df25c 100755 ---- a/src/tests/gssapi/t_gssapi.py -+++ b/src/tests/gssapi/t_gssapi.py -@@ -185,4 +185,36 @@ realm.run(['./t_ciflags', 'p:' + realm.host_princ]) - # contexts. - realm.run(['./t_inq_ctx', 'user', password('user'), 'p:%s' % realm.host_princ]) - -+# Test lifetime results, using a realm with a large maximum lifetime -+# so that we can test ticket end dates after y2038. There are no -+# time_t conversions involved, so we can run these tests on platforms -+# with 32-bit time_t. -+realm.stop() -+conf = {'realms': {'$realm': {'max_life': '9000d'}}} -+realm = K5Realm(kdc_conf=conf, get_creds=False) -+ -+# Check a lifetime string result against an expected number value (or None). -+# Allow some variance due to time elapsed during the tests. -+def check_lifetime(msg, val, expected): -+ if expected is None and val != 'indefinite': -+ fail('%s: expected indefinite, got %s' % (msg, val)) -+ if expected is not None and val == 'indefinite': -+ fail('%s: expected %d, got indefinite' % (msg, expected)) -+ if expected is not None and abs(int(val) - expected) > 100: -+ fail('%s: expected %d, got %s' % (msg, expected, val)) -+ -+realm.kinit(realm.user_princ, password('user'), flags=['-l', '8500d']) -+out = realm.run(['./t_lifetime', 'p:' + realm.host_princ, str(8000 * 86400)]) -+ln = out.split('\n') -+check_lifetime('icred gss_acquire_cred', ln[0], 8500 * 86400) -+check_lifetime('icred gss_inquire_cred', ln[1], 8500 * 86400) -+check_lifetime('acred gss_acquire_cred', ln[2], None) -+check_lifetime('acred gss_inquire_cred', ln[3], None) -+check_lifetime('ictx gss_init_sec_context', ln[4], 8000 * 86400) -+check_lifetime('ictx gss_inquire_context', ln[5], 8000 * 86400) -+check_lifetime('ictx gss_context_time', ln[6], 8000 * 86400) -+check_lifetime('actx gss_accept_sec_context', ln[7], 8000 * 86400 + 300) -+check_lifetime('actx gss_inquire_context', ln[8], 8000 * 86400 + 300) -+check_lifetime('actx gss_context_time', ln[9], 8000 * 86400 + 300) -+ - success('GSSAPI tests') -diff --git a/src/tests/gssapi/t_lifetime.c b/src/tests/gssapi/t_lifetime.c -new file mode 100644 -index 000000000..8dcf18621 ---- /dev/null -+++ b/src/tests/gssapi/t_lifetime.c -@@ -0,0 +1,140 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* tests/gssapi/t_lifetime.c - display cred and context lifetimes */ -+/* -+ * Copyright (C) 2017 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include -+#include -+#include -+#include "common.h" -+ -+/* -+ * Using the default credential, exercise the GSS functions which accept or -+ * produce lifetimes. Display the following results, one per line, as ASCII -+ * integers or the string "indefinite": -+ * -+ * initiator cred lifetime according to gss_acquire_cred() -+ * initiator cred lifetime according to gss_inquire_cred() -+ * acceptor cred lifetime according to gss_acquire_cred() -+ * acceptor cred lifetime according to gss_inquire_cred() -+ * initiator context lifetime according to gss_init_sec_context() -+ * initiator context lifetime according to gss_inquire_context() -+ * initiator context lifetime according to gss_context_time() -+ * acceptor context lifetime according to gss_init_sec_context() -+ * acceptor context lifetime according to gss_inquire_context() -+ * acceptor context lifetime according to gss_context_time() -+ */ -+ -+static void -+display_time(OM_uint32 tval) -+{ -+ if (tval == GSS_C_INDEFINITE) -+ puts("indefinite"); -+ else -+ printf("%u\n", (unsigned int)tval); -+} -+ -+int -+main(int argc, char *argv[]) -+{ -+ OM_uint32 minor, major; -+ gss_cred_id_t icred, acred; -+ gss_name_t tname; -+ gss_ctx_id_t ictx = GSS_C_NO_CONTEXT, actx = GSS_C_NO_CONTEXT; -+ gss_buffer_desc itok = GSS_C_EMPTY_BUFFER, atok = GSS_C_EMPTY_BUFFER; -+ OM_uint32 time_req = GSS_C_INDEFINITE, time_rec; -+ -+ if (argc < 2 || argc > 3) { -+ fprintf(stderr, "Usage: %s targetname [time_req]\n", argv[0]); -+ return 1; -+ } -+ tname = import_name(argv[1]); -+ if (argc >= 3) -+ time_req = atoll(argv[2]); -+ -+ /* Get initiator cred and display its lifetime according to -+ * gss_acquire_cred and gss_inquire_cred. */ -+ major = gss_acquire_cred(&minor, GSS_C_NO_NAME, time_req, &mechset_krb5, -+ GSS_C_INITIATE, &icred, NULL, &time_rec); -+ check_gsserr("gss_acquire_cred(initiate)", major, minor); -+ display_time(time_rec); -+ major = gss_inquire_cred(&minor, icred, NULL, &time_rec, NULL, NULL); -+ check_gsserr("gss_inquire_cred(initiate)", major, minor); -+ display_time(time_rec); -+ -+ /* Get acceptor cred and display its lifetime according to gss_acquire_cred -+ * and gss_inquire_cred. */ -+ major = gss_acquire_cred(&minor, GSS_C_NO_NAME, time_req, &mechset_krb5, -+ GSS_C_ACCEPT, &acred, NULL, &time_rec); -+ check_gsserr("gss_acquire_cred(accept)", major, minor); -+ display_time(time_rec); -+ major = gss_inquire_cred(&minor, acred, NULL, &time_rec, NULL, NULL); -+ check_gsserr("gss_inquire_cred(accept)", major, minor); -+ display_time(time_rec); -+ -+ /* Make an initiator context and display its lifetime according to -+ * gss_init_sec_context, gss_inquire_context, and gss_context_time. */ -+ major = gss_init_sec_context(&minor, icred, &ictx, tname, &mech_krb5, 0, -+ time_req, GSS_C_NO_CHANNEL_BINDINGS, &atok, -+ NULL, &itok, NULL, &time_rec); -+ check_gsserr("gss_init_sec_context", major, minor); -+ assert(major == GSS_S_COMPLETE); -+ display_time(time_rec); -+ major = gss_inquire_context(&minor, ictx, NULL, NULL, &time_rec, NULL, -+ NULL, NULL, NULL); -+ check_gsserr("gss_inquire_context(initiate)", major, minor); -+ display_time(time_rec); -+ major = gss_context_time(&minor, ictx, &time_rec); -+ check_gsserr("gss_context_time(initiate)", major, minor); -+ display_time(time_rec); -+ -+ major = gss_accept_sec_context(&minor, &actx, acred, &itok, -+ GSS_C_NO_CHANNEL_BINDINGS, NULL, -+ NULL, &atok, NULL, &time_rec, NULL); -+ check_gsserr("gss_accept_sec_context", major, minor); -+ assert(major == GSS_S_COMPLETE); -+ display_time(time_rec); -+ major = gss_inquire_context(&minor, actx, NULL, NULL, &time_rec, NULL, -+ NULL, NULL, NULL); -+ check_gsserr("gss_inquire_context(accept)", major, minor); -+ display_time(time_rec); -+ major = gss_context_time(&minor, actx, &time_rec); -+ check_gsserr("gss_context_time(accept)", major, minor); -+ display_time(time_rec); -+ -+ (void)gss_release_buffer(&minor, &itok); -+ (void)gss_release_buffer(&minor, &atok); -+ (void)gss_release_name(&minor, &tname); -+ (void)gss_release_cred(&minor, &icred); -+ (void)gss_release_cred(&minor, &acred); -+ (void)gss_delete_sec_context(&minor, &ictx, NULL); -+ (void)gss_delete_sec_context(&minor, &actx, NULL); -+ return 0; -+} -diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py -index 44635b089..ffc043709 100755 ---- a/src/tests/t_kdb.py -+++ b/src/tests/t_kdb.py -@@ -414,6 +414,13 @@ realm.run([kadminl, 'addprinc', '-policy', 'keepoldpasspol', '-pw', 'aaaa', - for p in ('bbbb', 'cccc', 'aaaa'): - realm.run([kadminl, 'cpw', '-keepold', '-pw', p, 'keepoldpassprinc']) - -+if runenv.sizeof_time_t <= 4: -+ skipped('y2038 LDAP test', 'platform has 32-bit time_t') -+else: -+ # Test storage of timestamps after y2038. -+ realm.run([kadminl, 'modprinc', '-pwexpire', '2040-02-03', 'user']) -+ realm.run([kadminl, 'getprinc', 'user'], expected_msg=' 2040\n') -+ - realm.stop() - - # Briefly test dump and load. -diff --git a/src/tests/t_y2038.py b/src/tests/t_y2038.py -new file mode 100644 -index 000000000..02e946df4 ---- /dev/null -+++ b/src/tests/t_y2038.py -@@ -0,0 +1,75 @@ -+#!/usr/bin/python -+from k5test import * -+ -+# These tests will become much less important after the y2038 boundary -+# has elapsed, and may start exhibiting problems around the year 2075. -+ -+if runenv.sizeof_time_t <= 4: -+ skip_rest('y2038 timestamp tests', 'platform has 32-bit time_t') -+ -+# Start a KDC running roughly 21 years in the future, after the y2038 -+# boundary. Set long maximum lifetimes for later tests. -+conf = {'realms': {'$realm': {'max_life': '9000d', -+ 'max_renewable_life': '9000d'}}} -+realm = K5Realm(start_kdc=False, kdc_conf=conf) -+realm.start_kdc(['-T', '662256000']) -+ -+# kinit without preauth should succeed with clock skew correction, but -+# will result in an expired ticket, because we sent an absolute end -+# time and didn't get a chance to correct it.. -+realm.kinit(realm.user_princ, password('user')) -+realm.run([kvno, realm.host_princ], expected_code=1, -+ expected_msg='Ticket expired') -+ -+# kinit with preauth should succeed and result in a valid ticket, as -+# we get a chance to correct the end time based on the KDC time. Try -+# with encrypted timestamp and encrypted challenge. -+realm.run([kadminl, 'modprinc', '+requires_preauth', 'user']) -+realm.kinit(realm.user_princ, password('user')) -+realm.run([kvno, realm.host_princ]) -+realm.kinit(realm.user_princ, password('user'), flags=['-T', realm.ccache]) -+realm.run([kvno, realm.host_princ]) -+ -+# Test that expiration warning works after y2038, by setting a -+# password expiration time ten minutes after the KDC time. -+realm.run([kadminl, 'modprinc', '-pwexpire', '662256600 seconds', 'user']) -+out = realm.kinit(realm.user_princ, password('user')) -+if 'will expire in less than one hour' not in out: -+ fail('password expiration message') -+year = int(out.split()[-1]) -+if year < 2038 or year > 9999: -+ fail('password expiration year') -+ -+realm.stop_kdc() -+realm.start_kdc() -+realm.start_kadmind() -+realm.prep_kadmin() -+ -+# Test getdate parsing of absolute timestamps after 2038 and -+# marshalling over the kadmin protocol. The local time zone will -+# affect the display time by a little bit, so just look for the year. -+realm.run_kadmin(['modprinc', '-pwexpire', '2040-02-03', realm.host_princ]) -+realm.run_kadmin(['getprinc', realm.host_princ], expected_msg=' 2040\n') -+ -+# Get a ticket whose lifetime crosses the y2038 boundary and -+# range-check the expiration year as reported by klist. -+realm.kinit(realm.user_princ, password('user'), -+ flags=['-l', '8000d', '-r', '8500d']) -+realm.run([kvno, realm.host_princ]) -+out = realm.run([klist]) -+if int(out.split('\n')[4].split()[2].split('/')[2]) < 39: -+ fail('unexpected tgt expiration year') -+if int(out.split('\n')[5].split()[2].split('/')[2]) < 40: -+ fail('unexpected tgt rtill year') -+if int(out.split('\n')[6].split()[2].split('/')[2]) < 39: -+ fail('unexpected service ticket expiration year') -+if int(out.split('\n')[7].split()[2].split('/')[2]) < 40: -+ fail('unexpected service ticket rtill year') -+realm.kinit(realm.user_princ, None, ['-R']) -+out = realm.run([klist]) -+if int(out.split('\n')[4].split()[2].split('/')[2]) < 39: -+ fail('unexpected renewed tgt expiration year') -+if int(out.split('\n')[5].split()[2].split('/')[2]) < 40: -+ fail('unexpected renewed tgt rtill year') -+ -+success('y2038 tests') diff --git a/Add-y2038-documentation.patch b/Add-y2038-documentation.patch deleted file mode 100644 index 693a1fb..0000000 --- a/Add-y2038-documentation.patch +++ /dev/null @@ -1,59 +0,0 @@ -From 69ca5ff168f24792924b3cab0a9f27ada3eb4c4b Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 4 May 2017 17:03:35 -0400 -Subject: [PATCH] Add y2038 documentation - -ticket: 8352 -(cherry picked from commit 85d64c43dbf7a7faa56a1999494cdfa49e8bd2c9) ---- - doc/appdev/index.rst | 1 + - doc/appdev/y2038.rst | 28 ++++++++++++++++++++++++++++ - 2 files changed, 29 insertions(+) - create mode 100644 doc/appdev/y2038.rst - -diff --git a/doc/appdev/index.rst b/doc/appdev/index.rst -index 3d62045ca..961bb1e9e 100644 ---- a/doc/appdev/index.rst -+++ b/doc/appdev/index.rst -@@ -5,6 +5,7 @@ For application developers - :maxdepth: 1 - - gssapi.rst -+ y2038.rst - h5l_mit_apidiff.rst - init_creds.rst - princ_handle.rst -diff --git a/doc/appdev/y2038.rst b/doc/appdev/y2038.rst -new file mode 100644 -index 000000000..bc4122dad ---- /dev/null -+++ b/doc/appdev/y2038.rst -@@ -0,0 +1,28 @@ -+Year 2038 considerations for uses of krb5_timestamp -+=================================================== -+ -+POSIX time values, which measure the number of seconds since January 1 -+1970, will exceed the maximum value representable in a signed 32-bit -+integer in January 2038. This documentation describes considerations -+for consumers of the MIT krb5 libraries. -+ -+Applications or libraries which use libkrb5 and consume the timestamps -+included in credentials or other structures make use of the -+:c:type:`krb5_timestamp` type. For historical reasons, krb5_timestamp -+is a signed 32-bit integer, even on platforms where a larger type is -+natively used to represent time values. To behave properly for time -+values after January 2038, calling code should cast krb5_timestamp -+values to uint32_t, and then to time_t:: -+ -+ (time_t)(uint32_t)timestamp -+ -+Used in this way, krb5_timestamp values can represent time values up -+until February 2106, provided that the platform uses a 64-bit or -+larger time_t type. This usage will also remain safe if a later -+version of MIT krb5 changes krb5_timestamp to an unsigned 32-bit -+integer. -+ -+The GSSAPI only uses representations of time intervals, not absolute -+times. Callers of the GSSAPI should require no changes to behave -+correctly after January 2038, provided that they use MIT krb5 release -+1.16 or later. diff --git a/Build-with-Werror-implicit-int-where-supported.patch b/Build-with-Werror-implicit-int-where-supported.patch deleted file mode 100644 index 30e3ba8..0000000 --- a/Build-with-Werror-implicit-int-where-supported.patch +++ /dev/null @@ -1,23 +0,0 @@ -From 5f2ea38f7ecd60184e510558bdb551d0153432e0 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 10 Nov 2016 13:20:49 -0500 -Subject: [PATCH] Build with -Werror-implicit-int where supported - -(cherry picked from commit 873d864230c9c64c65ff12a24199bac3adf3bc2f) ---- - src/aclocal.m4 | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 2bfb99496..da1d6d8b4 100644 ---- a/src/aclocal.m4 -+++ b/src/aclocal.m4 -@@ -529,7 +529,7 @@ if test "$GCC" = yes ; then - TRY_WARN_CC_FLAG(-Wno-format-zero-length) - # Other flags here may not be supported on some versions of - # gcc that people want to use. -- for flag in overflow strict-overflow missing-format-attribute missing-prototypes return-type missing-braces parentheses switch unused-function unused-label unused-variable unused-value unknown-pragmas sign-compare newline-eof error=uninitialized error=pointer-arith error=int-conversion error=incompatible-pointer-types error=discarded-qualifiers ; do -+ for flag in overflow strict-overflow missing-format-attribute missing-prototypes return-type missing-braces parentheses switch unused-function unused-label unused-variable unused-value unknown-pragmas sign-compare newline-eof error=uninitialized error=pointer-arith error=int-conversion error=incompatible-pointer-types error=discarded-qualifiers error=implicit-int ; do - TRY_WARN_CC_FLAG(-W$flag) - done - # old-style-definition? generates many, many warnings diff --git a/Convert-some-pkiDebug-messages-to-TRACE-macros.patch b/Convert-some-pkiDebug-messages-to-TRACE-macros.patch deleted file mode 100644 index e9e27df..0000000 --- a/Convert-some-pkiDebug-messages-to-TRACE-macros.patch +++ /dev/null @@ -1,422 +0,0 @@ -From 686fa6476eb759532d566794fa8d430774d44cf7 Mon Sep 17 00:00:00 2001 -From: Matt Rogers -Date: Wed, 29 Mar 2017 10:35:13 -0400 -Subject: [PATCH] Convert some pkiDebug messages to TRACE macros - -ticket: 8568 (new) -(cherry picked from commit 9852862a83952a94300adfafa3e333f43396ec33) ---- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 46 ++++++--------- - src/plugins/preauth/pkinit/pkinit_identity.c | 3 - - src/plugins/preauth/pkinit/pkinit_matching.c | 1 + - src/plugins/preauth/pkinit/pkinit_srv.c | 24 ++++---- - src/plugins/preauth/pkinit/pkinit_trace.h | 68 +++++++++++++++++++++- - 5 files changed, 97 insertions(+), 45 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 90c30dbf5..70e230ec2 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2320,7 +2320,6 @@ crypto_check_cert_eku(krb5_context context, - - X509_NAME_oneline(X509_get_subject_name(reqctx->received_cert), - buf, sizeof(buf)); -- pkiDebug("%s: looking for EKUs in cert = %s\n", __FUNCTION__, buf); - - if ((i = X509_get_ext_by_NID(reqctx->received_cert, - NID_ext_key_usage, -1)) >= 0) { -@@ -2354,7 +2353,6 @@ crypto_check_cert_eku(krb5_context context, - - if (found_eku) { - ASN1_BIT_STRING *usage = NULL; -- pkiDebug("%s: found acceptable EKU, checking for digitalSignature\n", __FUNCTION__); - - /* check that digitalSignature KeyUsage is present */ - X509_check_ca(reqctx->received_cert); -@@ -2363,12 +2361,10 @@ crypto_check_cert_eku(krb5_context context, - - if (!ku_reject(reqctx->received_cert, - X509v3_KU_DIGITAL_SIGNATURE)) { -- pkiDebug("%s: found digitalSignature KU\n", -- __FUNCTION__); -+ TRACE_PKINIT_EKU(context); - *valid_eku = 1; - } else -- pkiDebug("%s: didn't find digitalSignature KU\n", -- __FUNCTION__); -+ TRACE_PKINIT_EKU_NO_KU(context); - } - ASN1_BIT_STRING_free(usage); - } -@@ -4317,8 +4313,7 @@ pkinit_get_certs_pkcs12(krb5_context context, - - fp = fopen(idopts->cert_filename, "rb"); - if (fp == NULL) { -- pkiDebug("Failed to open PKCS12 file '%s', error %d\n", -- idopts->cert_filename, errno); -+ TRACE_PKINIT_PKCS_OPEN_FAIL(context, idopts->cert_filename, errno); - goto cleanup; - } - set_cloexec_file(fp); -@@ -4326,8 +4321,7 @@ pkinit_get_certs_pkcs12(krb5_context context, - p12 = d2i_PKCS12_fp(fp, NULL); - fclose(fp); - if (p12 == NULL) { -- pkiDebug("Failed to decode PKCS12 file '%s' contents\n", -- idopts->cert_filename); -+ TRACE_PKINIT_PKCS_DECODE_FAIL(context, idopts->cert_filename); - goto cleanup; - } - /* -@@ -4345,7 +4339,7 @@ pkinit_get_certs_pkcs12(krb5_context context, - char *p12name = reassemble_pkcs12_name(idopts->cert_filename); - const char *tmp; - -- pkiDebug("Initial PKCS12_parse with no password failed\n"); -+ TRACE_PKINIT_PKCS_PARSE_FAIL_FIRST(context); - - if (id_cryptoctx->defer_id_prompt) { - /* Supply the identity name to be passed to the responder. */ -@@ -4386,14 +4380,14 @@ pkinit_get_certs_pkcs12(krb5_context context, - NULL, NULL, 1, &kprompt); - k5int_set_prompt_types(context, 0); - if (r) { -- pkiDebug("Failed to prompt for PKCS12 password"); -+ TRACE_PKINIT_PKCS_PROMPT_FAIL(context); - goto cleanup; - } - } - - ret = PKCS12_parse(p12, rdat.data, &y, &x, NULL); - if (ret == 0) { -- pkiDebug("Second PKCS12_parse with password failed\n"); -+ TRACE_PKINIT_PKCS_PARSE_FAIL_SECOND(context); - goto cleanup; - } - } -@@ -4516,8 +4510,7 @@ pkinit_get_certs_fs(krb5_context context, - } - - if (idopts->key_filename == NULL) { -- pkiDebug("%s: failed to get user's private key location\n", -- __FUNCTION__); -+ TRACE_PKINIT_NO_PRIVKEY(context); - goto cleanup; - } - -@@ -4545,8 +4538,7 @@ pkinit_get_certs_dir(krb5_context context, - char *dirname, *suf; - - if (idopts->cert_filename == NULL) { -- pkiDebug("%s: failed to get user's certificate directory location\n", -- __FUNCTION__); -+ TRACE_PKINIT_NO_CERT(context); - return ENOENT; - } - -@@ -4590,8 +4582,7 @@ pkinit_get_certs_dir(krb5_context context, - retval = pkinit_load_fs_cert_and_key(context, id_cryptoctx, - certname, keyname, i); - if (retval == 0) { -- pkiDebug("%s: Successfully loaded cert (and key) for %s\n", -- __FUNCTION__, dentry->d_name); -+ TRACE_PKINIT_LOADED_CERT(context, dentry->d_name); - i++; - } - else -@@ -4599,8 +4590,7 @@ pkinit_get_certs_dir(krb5_context context, - } - - if (!id_cryptoctx->defer_id_prompt && i == 0) { -- pkiDebug("%s: No cert/key pairs found in directory '%s'\n", -- __FUNCTION__, idopts->cert_filename); -+ TRACE_PKINIT_NO_CERT_AND_KEY(context, idopts->cert_filename); - retval = ENOENT; - goto cleanup; - } -@@ -5370,9 +5360,7 @@ crypto_cert_select_default(krb5_context context, - goto errout; - } - if (cert_count != 1) { -- pkiDebug("%s: ERROR: There are %d certs to choose from, " -- "but there must be exactly one.\n", -- __FUNCTION__, cert_count); -+ TRACE_PKINIT_NO_DEFAULT_CERT(context, cert_count); - retval = EINVAL; - goto errout; - } -@@ -5520,7 +5508,7 @@ load_cas_and_crls(krb5_context context, - switch(catype) { - case CATYPE_ANCHORS: - if (sk_X509_num(ca_certs) == 0) { -- pkiDebug("no anchors in file, %s\n", filename); -+ TRACE_PKINIT_NO_CA_ANCHOR(context, filename); - if (id_cryptoctx->trustedCAs == NULL) - sk_X509_free(ca_certs); - } else { -@@ -5530,7 +5518,7 @@ load_cas_and_crls(krb5_context context, - break; - case CATYPE_INTERMEDIATES: - if (sk_X509_num(ca_certs) == 0) { -- pkiDebug("no intermediates in file, %s\n", filename); -+ TRACE_PKINIT_NO_CA_INTERMEDIATE(context, filename); - if (id_cryptoctx->intermediateCAs == NULL) - sk_X509_free(ca_certs); - } else { -@@ -5540,7 +5528,7 @@ load_cas_and_crls(krb5_context context, - break; - case CATYPE_CRLS: - if (sk_X509_CRL_num(ca_crls) == 0) { -- pkiDebug("no crls in file, %s\n", filename); -+ TRACE_PKINIT_NO_CRL(context, filename); - if (id_cryptoctx->revoked == NULL) - sk_X509_CRL_free(ca_crls); - } else { -@@ -5626,14 +5614,14 @@ crypto_load_cas_and_crls(krb5_context context, - int catype, - char *id) - { -- pkiDebug("%s: called with idtype %s and catype %s\n", -- __FUNCTION__, idtype2string(idtype), catype2string(catype)); - switch (idtype) { - case IDTYPE_FILE: -+ TRACE_PKINIT_LOAD_FROM_FILE(context); - return load_cas_and_crls(context, plg_cryptoctx, req_cryptoctx, - id_cryptoctx, catype, id); - break; - case IDTYPE_DIR: -+ TRACE_PKINIT_LOAD_FROM_DIR(context); - return load_cas_and_crls_dir(context, plg_cryptoctx, req_cryptoctx, - id_cryptoctx, catype, id); - break; -diff --git a/src/plugins/preauth/pkinit/pkinit_identity.c b/src/plugins/preauth/pkinit/pkinit_identity.c -index a897efa25..737552e85 100644 ---- a/src/plugins/preauth/pkinit/pkinit_identity.c -+++ b/src/plugins/preauth/pkinit/pkinit_identity.c -@@ -608,7 +608,6 @@ pkinit_identity_prompt(krb5_context context, - retval = pkinit_cert_matching(context, plg_cryptoctx, - req_cryptoctx, id_cryptoctx, princ); - if (retval) { -- pkiDebug("%s: No matching certificate found\n", __FUNCTION__); - crypto_free_cert_info(context, plg_cryptoctx, req_cryptoctx, - id_cryptoctx); - goto errout; -@@ -621,8 +620,6 @@ pkinit_identity_prompt(krb5_context context, - retval = crypto_cert_select_default(context, plg_cryptoctx, - req_cryptoctx, id_cryptoctx); - if (retval) { -- pkiDebug("%s: Failed while selecting default certificate\n", -- __FUNCTION__); - crypto_free_cert_info(context, plg_cryptoctx, req_cryptoctx, - id_cryptoctx); - goto errout; -diff --git a/src/plugins/preauth/pkinit/pkinit_matching.c b/src/plugins/preauth/pkinit/pkinit_matching.c -index a50c50c8d..cad4c2b9a 100644 ---- a/src/plugins/preauth/pkinit/pkinit_matching.c -+++ b/src/plugins/preauth/pkinit/pkinit_matching.c -@@ -812,6 +812,7 @@ pkinit_cert_matching(krb5_context context, - goto cleanup; - } - } else { -+ TRACE_PKINIT_NO_MATCHING_CERT(context); - retval = ENOENT; /* XXX */ - goto cleanup; - } -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index 32ca122f2..9c6e96c9e 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -188,6 +188,7 @@ verify_client_san(krb5_context context, - plgctx->opts->allow_upn ? &upns : NULL, - NULL); - if (retval == ENOENT) { -+ TRACE_PKINIT_SERVER_NO_SAN(context); - goto out; - } else if (retval) { - pkiDebug("%s: error from retrieve_certificate_sans()\n", __FUNCTION__); -@@ -224,7 +225,7 @@ verify_client_san(krb5_context context, - krb5_free_unparsed_name(context, san_string); - #endif - if (cb->match_client(context, rock, princs[i])) { -- pkiDebug("%s: pkinit san match found\n", __FUNCTION__); -+ TRACE_PKINIT_SERVER_MATCHING_SAN_FOUND(context); - *valid_san = 1; - retval = 0; - goto out; -@@ -252,7 +253,7 @@ verify_client_san(krb5_context context, - krb5_free_unparsed_name(context, san_string); - #endif - if (cb->match_client(context, rock, upns[i])) { -- pkiDebug("%s: upn san match found\n", __FUNCTION__); -+ TRACE_PKINIT_SERVER_MATCHING_UPN_FOUND(context); - *valid_san = 1; - retval = 0; - goto out; -@@ -300,7 +301,7 @@ verify_client_eku(krb5_context context, - *eku_accepted = 0; - - if (plgctx->opts->require_eku == 0) { -- pkiDebug("%s: configuration requests no EKU checking\n", __FUNCTION__); -+ TRACE_PKINIT_SERVER_EKU_SKIP(context); - *eku_accepted = 1; - retval = 0; - goto out; -@@ -364,6 +365,7 @@ authorize_cert(krb5_context context, certauth_handle *certauth_modules, - ret = KRB5_PLUGIN_NO_HANDLE; - for (i = 0; certauth_modules != NULL && certauth_modules[i] != NULL; i++) { - h = certauth_modules[i]; -+ TRACE_PKINIT_SERVER_CERT_AUTH(context, h->vt.name); - ret = h->vt.authorize(context, h->moddata, cert, cert_len, client, - &opts, db_ent, &ais); - if (ret == 0) -@@ -449,7 +451,7 @@ pkinit_server_verify_padata(krb5_context context, - - switch ((int)data->pa_type) { - case KRB5_PADATA_PK_AS_REQ: -- pkiDebug("processing KRB5_PADATA_PK_AS_REQ\n"); -+ TRACE_PKINIT_SERVER_PADATA_VERIFY(context); - retval = k5int_decode_krb5_pa_pk_as_req(&k5data, &reqp); - if (retval) { - pkiDebug("decode_krb5_pa_pk_as_req failed\n"); -@@ -472,7 +474,7 @@ pkinit_server_verify_padata(krb5_context context, - break; - case KRB5_PADATA_PK_AS_REP_OLD: - case KRB5_PADATA_PK_AS_REQ_OLD: -- pkiDebug("processing KRB5_PADATA_PK_AS_REQ_OLD\n"); -+ TRACE_PKINIT_SERVER_PADATA_VERIFY_OLD(context); - retval = k5int_decode_krb5_pa_pk_as_req_draft9(&k5data, &reqp9); - if (retval) { - pkiDebug("decode_krb5_pa_pk_as_req_draft9 failed\n"); -@@ -500,7 +502,7 @@ pkinit_server_verify_padata(krb5_context context, - goto cleanup; - } - if (retval) { -- pkiDebug("pkcs7_signeddata_verify failed\n"); -+ TRACE_PKINIT_SERVER_PADATA_VERIFY_FAIL(context); - goto cleanup; - } - if (is_signed) { -@@ -830,7 +832,7 @@ pkinit_server_return_padata(krb5_context context, - return ENOENT; - } - -- pkiDebug("pkinit_return_padata: entered!\n"); -+ TRACE_PKINIT_SERVER_RETURN_PADATA(context); - reqctx = (pkinit_kdc_req_context)modreq; - - if (encrypting_key->contents) { -@@ -1463,8 +1465,7 @@ pkinit_san_authorize(krb5_context context, krb5_certauth_moddata moddata, - return ret; - - if (!valid_san) { -- pkiDebug("%s: did not find an acceptable SAN in user certificate\n", -- __FUNCTION__); -+ TRACE_PKINIT_SERVER_SAN_REJECT(context); - return KRB5KDC_ERR_CLIENT_NAME_MISMATCH; - } - -@@ -1490,8 +1491,7 @@ pkinit_eku_authorize(krb5_context context, krb5_certauth_moddata moddata, - return ret; - - if (!valid_eku) { -- pkiDebug("%s: did not find an acceptable EKU in user certificate\n", -- __FUNCTION__); -+ TRACE_PKINIT_SERVER_EKU_REJECT(context); - return KRB5KDC_ERR_INCONSISTENT_KEY_PURPOSE; - } - -@@ -1617,7 +1617,7 @@ pkinit_server_plugin_init(krb5_context context, - return ENOMEM; - - for (i = 0, j = 0; i < numrealms; i++) { -- pkiDebug("%s: processing realm '%s'\n", __FUNCTION__, realmnames[i]); -+ TRACE_PKINIT_SERVER_INIT_REALM(context, realmnames[i]); - retval = pkinit_server_plugin_init_realm(context, realmnames[i], &plgctx); - if (retval == 0 && plgctx != NULL) - realm_contexts[j++] = plgctx; -diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h -index 458d0961e..6abe28c0c 100644 ---- a/src/plugins/preauth/pkinit/pkinit_trace.h -+++ b/src/plugins/preauth/pkinit/pkinit_trace.h -@@ -52,7 +52,7 @@ - #define TRACE_PKINIT_CLIENT_REP_CHECKSUM_FAIL(c, expected, received) \ - TRACE(c, "PKINIT client checksum mismatch: expected {cksum}, " \ - "received {cksum}", expected, received) --#define TRACE_PKINIT_CLIENT_REP_DH(c) \ -+#define TRACE_PKINIT_CLIENT_REP_DH(c) \ - TRACE(c, "PKINIT client verified DH reply") - #define TRACE_PKINIT_CLIENT_REP_DH_FAIL(c) \ - TRACE(c, "PKINIT client could not verify DH reply") -@@ -91,6 +91,72 @@ - #define TRACE_PKINIT_OPENSSL_ERROR(c, msg) \ - TRACE(c, "PKINIT OpenSSL error: {str}", msg) - -+#define TRACE_PKINIT_SERVER_CERT_AUTH(c, modname) \ -+ TRACE(c, "PKINIT server authorizing cert with module {str}", \ -+ modname) -+#define TRACE_PKINIT_SERVER_EKU_REJECT(c) \ -+ TRACE(c, "PKINIT server found no acceptable EKU in client cert") -+#define TRACE_PKINIT_SERVER_EKU_SKIP(c) \ -+ TRACE(c, "PKINIT server skipping EKU check due to configuration") -+#define TRACE_PKINIT_SERVER_INIT_REALM(c, realm) \ -+ TRACE(c, "PKINIT server initializing realm {str}", realm) -+#define TRACE_PKINIT_SERVER_MATCHING_UPN_FOUND(c) \ -+ TRACE(c, "PKINIT server found a matching UPN SAN in client cert") -+#define TRACE_PKINIT_SERVER_MATCHING_SAN_FOUND(c) \ -+ TRACE(c, "PKINIT server found a matching SAN in client cert") -+#define TRACE_PKINIT_SERVER_NO_SAN(c) \ -+ TRACE(c, "PKINIT server found no SAN in client cert") -+#define TRACE_PKINIT_SERVER_PADATA_VERIFY(c) \ -+ TRACE(c, "PKINIT server verifying KRB5_PADATA_PK_AS_REQ") -+#define TRACE_PKINIT_SERVER_PADATA_VERIFY_OLD(c) \ -+ TRACE(c, "PKINIT server verifying KRB5_PADATA_PK_AS_REQ_OLD") -+#define TRACE_PKINIT_SERVER_PADATA_VERIFY_FAIL(c) \ -+ TRACE(c, "PKINIT server failed to verify PA data") -+#define TRACE_PKINIT_SERVER_RETURN_PADATA(c) \ -+ TRACE(c, "PKINIT server returning PA data") -+#define TRACE_PKINIT_SERVER_SAN_REJECT(c) \ -+ TRACE(c, "PKINIT server found no acceptable SAN in client cert") -+ -+#define TRACE_PKINIT_EKU(c) \ -+ TRACE(c, "PKINIT found acceptable EKU and digitalSignature KU") -+#define TRACE_PKINIT_EKU_NO_KU(c) \ -+ TRACE(c, "PKINIT found acceptable EKU but no digitalSignature KU") -+#define TRACE_PKINIT_LOADED_CERT(c, name) \ -+ TRACE(c, "PKINIT loaded cert and key for {str}", name) -+#define TRACE_PKINIT_LOAD_FROM_FILE(c) \ -+ TRACE(c, "PKINIT loading CA certs and CRLs from FILE") -+#define TRACE_PKINIT_LOAD_FROM_DIR(c) \ -+ TRACE(c, "PKINIT loading CA certs and CRLs from DIR") -+#define TRACE_PKINIT_NO_CA_ANCHOR(c, file) \ -+ TRACE(c, "PKINIT no anchor CA in file {str}", file) -+#define TRACE_PKINIT_NO_CA_INTERMEDIATE(c, file) \ -+ TRACE(c, "PKINIT no intermediate CA in file {str}", file) -+#define TRACE_PKINIT_NO_CERT(c) \ -+ TRACE(c, "PKINIT no certificate provided") -+#define TRACE_PKINIT_NO_CERT_AND_KEY(c, dirname) \ -+ TRACE(c, "PKINIT no cert and key pair found in directory {str}", \ -+ dirname) -+#define TRACE_PKINIT_NO_CRL(c, file) \ -+ TRACE(c, "PKINIT no CRL in file {str}", file) -+#define TRACE_PKINIT_NO_DEFAULT_CERT(c, count) \ -+ TRACE(c, "PKINIT error: There are {int} certs, but there must " \ -+ "be exactly one.", count) -+#define TRACE_PKINIT_NO_MATCHING_CERT(c) \ -+ TRACE(c, "PKINIT no matching certificate found") -+#define TRACE_PKINIT_NO_PRIVKEY(c) \ -+ TRACE(c, "PKINIT no private key provided") -+#define TRACE_PKINIT_PKCS_DECODE_FAIL(c, name) \ -+ TRACE(c, "PKINIT failed to decode PKCS12 file {str} contents", name) -+#define TRACE_PKINIT_PKCS_OPEN_FAIL(c, name, err) \ -+ TRACE(c, "PKINIT failed to open PKCS12 file {str}: err {errno}", \ -+ name, err) -+#define TRACE_PKINIT_PKCS_PARSE_FAIL_FIRST(c) \ -+ TRACE(c, "PKINIT initial PKCS12_parse with no password failed") -+#define TRACE_PKINIT_PKCS_PARSE_FAIL_SECOND(c) \ -+ TRACE(c, "PKINIT second PKCS12_parse with password failed") -+#define TRACE_PKINIT_PKCS_PROMPT_FAIL(c) \ -+ TRACE(c, "PKINIT failed to prompt for PKCS12 password") -+ - #define TRACE_CERTAUTH_VTINIT_FAIL(c, ret) \ - TRACE(c, "certauth module failed to init vtable: {kerr}", ret) - #define TRACE_CERTAUTH_INIT_FAIL(c, name, ret) \ diff --git a/Correct-error-handling-bug-in-prior-commit.patch b/Correct-error-handling-bug-in-prior-commit.patch deleted file mode 100644 index 6878e8c..0000000 --- a/Correct-error-handling-bug-in-prior-commit.patch +++ /dev/null @@ -1,32 +0,0 @@ -From 08d995aaf48e75c174525ae0b47e12c3170b3f5f Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 23 Mar 2017 13:42:55 -0400 -Subject: [PATCH] Correct error handling bug in prior commit - -In crypto_encode_der_cert(), if the second i2d_X509() invocation -fails, make sure to free the allocated pointer and not the -possibly-modified alias. - -ticket: 8561 -(cherry picked from commit 7fdaef7c3280c86b5df25ae061fb04cc56d8620c) ---- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index a5b010b26..90c30dbf5 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -6196,10 +6196,10 @@ crypto_encode_der_cert(krb5_context context, pkinit_req_crypto_context reqctx, - if (len <= 0) - return EINVAL; - p = der = malloc(len); -- if (p == NULL) -+ if (der == NULL) - return ENOMEM; - if (i2d_X509(reqctx->received_cert, &p) <= 0) { -- free(p); -+ free(der); - return EINVAL; - } - *der_out = der; diff --git a/Deindent-crypto_retrieve_X509_sans.patch b/Deindent-crypto_retrieve_X509_sans.patch deleted file mode 100644 index 9262e7d..0000000 --- a/Deindent-crypto_retrieve_X509_sans.patch +++ /dev/null @@ -1,263 +0,0 @@ -From d5462c96c9918ffa7d3f05de310c5aed34181941 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 4 Jan 2017 11:33:57 -0500 -Subject: [PATCH] Deindent crypto_retrieve_X509_sans() - -Fix some long lines in crypto_retrieve_X509_sans() by returning early -if X509_get_ext_by_NID() returns a negative result. Also ensure that -return parameters are always initialized. - -(cherry picked from commit c6b772523db9d7791ee1c56eb512c4626556a4e7) ---- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 224 +++++++++++---------- - 1 file changed, 114 insertions(+), 110 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index bc6e7662e..8def8c542 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2101,11 +2101,21 @@ crypto_retrieve_X509_sans(krb5_context context, - { - krb5_error_code retval = EINVAL; - char buf[DN_BUF_LEN]; -- int p = 0, u = 0, d = 0, l; -+ int p = 0, u = 0, d = 0, ret = 0, l; - krb5_principal *princs = NULL; - krb5_principal *upns = NULL; - unsigned char **dnss = NULL; -- unsigned int i, num_found = 0; -+ unsigned int i, num_found = 0, num_sans = 0; -+ X509_EXTENSION *ext = NULL; -+ GENERAL_NAMES *ialt = NULL; -+ GENERAL_NAME *gen = NULL; -+ -+ if (princs_ret != NULL) -+ *princs_ret = NULL; -+ if (upn_ret != NULL) -+ *upn_ret = NULL; -+ if (dns_ret != NULL) -+ *dns_ret = NULL; - - if (princs_ret == NULL && upn_ret == NULL && dns_ret == NULL) { - pkiDebug("%s: nowhere to return any values!\n", __FUNCTION__); -@@ -2121,118 +2131,112 @@ crypto_retrieve_X509_sans(krb5_context context, - buf, sizeof(buf)); - pkiDebug("%s: looking for SANs in cert = %s\n", __FUNCTION__, buf); - -- if ((l = X509_get_ext_by_NID(cert, NID_subject_alt_name, -1)) >= 0) { -- X509_EXTENSION *ext = NULL; -- GENERAL_NAMES *ialt = NULL; -- GENERAL_NAME *gen = NULL; -- int ret = 0; -- unsigned int num_sans = 0; -+ l = X509_get_ext_by_NID(cert, NID_subject_alt_name, -1); -+ if (l < 0) -+ return 0; - -- if (!(ext = X509_get_ext(cert, l)) || !(ialt = X509V3_EXT_d2i(ext))) { -- pkiDebug("%s: found no subject alt name extensions\n", -- __FUNCTION__); -+ if (!(ext = X509_get_ext(cert, l)) || !(ialt = X509V3_EXT_d2i(ext))) { -+ pkiDebug("%s: found no subject alt name extensions\n", __FUNCTION__); -+ goto cleanup; -+ } -+ num_sans = sk_GENERAL_NAME_num(ialt); -+ -+ pkiDebug("%s: found %d subject alt name extension(s)\n", __FUNCTION__, -+ num_sans); -+ -+ /* OK, we're likely returning something. Allocate return values */ -+ if (princs_ret != NULL) { -+ princs = calloc(num_sans + 1, sizeof(krb5_principal)); -+ if (princs == NULL) { -+ retval = ENOMEM; - goto cleanup; - } -- num_sans = sk_GENERAL_NAME_num(ialt); -- -- pkiDebug("%s: found %d subject alt name extension(s)\n", -- __FUNCTION__, num_sans); -- -- /* OK, we're likely returning something. Allocate return values */ -- if (princs_ret != NULL) { -- princs = calloc(num_sans + 1, sizeof(krb5_principal)); -- if (princs == NULL) { -- retval = ENOMEM; -- goto cleanup; -- } -- } -- if (upn_ret != NULL) { -- upns = calloc(num_sans + 1, sizeof(krb5_principal)); -- if (upns == NULL) { -- retval = ENOMEM; -- goto cleanup; -- } -- } -- if (dns_ret != NULL) { -- dnss = calloc(num_sans + 1, sizeof(*dnss)); -- if (dnss == NULL) { -- retval = ENOMEM; -- goto cleanup; -- } -- } -- -- for (i = 0; i < num_sans; i++) { -- krb5_data name = { 0, 0, NULL }; -- -- gen = sk_GENERAL_NAME_value(ialt, i); -- switch (gen->type) { -- case GEN_OTHERNAME: -- name.length = gen->d.otherName->value->value.sequence->length; -- name.data = (char *)gen->d.otherName->value->value.sequence->data; -- if (princs != NULL -- && OBJ_cmp(plgctx->id_pkinit_san, -- gen->d.otherName->type_id) == 0) { --#ifdef DEBUG_ASN1 -- print_buffer_bin((unsigned char *)name.data, name.length, -- "/tmp/pkinit_san"); --#endif -- ret = k5int_decode_krb5_principal_name(&name, &princs[p]); -- if (ret) { -- pkiDebug("%s: failed decoding pkinit san value\n", -- __FUNCTION__); -- } else { -- p++; -- num_found++; -- } -- } else if (upns != NULL -- && OBJ_cmp(plgctx->id_ms_san_upn, -- gen->d.otherName->type_id) == 0) { -- /* Prevent abuse of embedded null characters. */ -- if (memchr(name.data, '\0', name.length)) -- break; -- ret = krb5_parse_name_flags(context, name.data, -- KRB5_PRINCIPAL_PARSE_ENTERPRISE, -- &upns[u]); -- if (ret) { -- pkiDebug("%s: failed parsing ms-upn san value\n", -- __FUNCTION__); -- } else { -- u++; -- num_found++; -- } -- } else { -- pkiDebug("%s: unrecognized othername oid in SAN\n", -- __FUNCTION__); -- continue; -- } -- -- break; -- case GEN_DNS: -- if (dnss != NULL) { -- /* Prevent abuse of embedded null characters. */ -- if (memchr(gen->d.dNSName->data, '\0', -- gen->d.dNSName->length)) -- break; -- pkiDebug("%s: found dns name = %s\n", -- __FUNCTION__, gen->d.dNSName->data); -- dnss[d] = (unsigned char *) -- strdup((char *)gen->d.dNSName->data); -- if (dnss[d] == NULL) { -- pkiDebug("%s: failed to duplicate dns name\n", -- __FUNCTION__); -- } else { -- d++; -- num_found++; -- } -- } -- break; -- default: -- pkiDebug("%s: SAN type = %d expecting %d\n", -- __FUNCTION__, gen->type, GEN_OTHERNAME); -- } -- } -- sk_GENERAL_NAME_pop_free(ialt, GENERAL_NAME_free); - } -+ if (upn_ret != NULL) { -+ upns = calloc(num_sans + 1, sizeof(krb5_principal)); -+ if (upns == NULL) { -+ retval = ENOMEM; -+ goto cleanup; -+ } -+ } -+ if (dns_ret != NULL) { -+ dnss = calloc(num_sans + 1, sizeof(*dnss)); -+ if (dnss == NULL) { -+ retval = ENOMEM; -+ goto cleanup; -+ } -+ } -+ -+ for (i = 0; i < num_sans; i++) { -+ krb5_data name = { 0, 0, NULL }; -+ -+ gen = sk_GENERAL_NAME_value(ialt, i); -+ switch (gen->type) { -+ case GEN_OTHERNAME: -+ name.length = gen->d.otherName->value->value.sequence->length; -+ name.data = (char *)gen->d.otherName->value->value.sequence->data; -+ if (princs != NULL && -+ OBJ_cmp(plgctx->id_pkinit_san, -+ gen->d.otherName->type_id) == 0) { -+#ifdef DEBUG_ASN1 -+ print_buffer_bin((unsigned char *)name.data, name.length, -+ "/tmp/pkinit_san"); -+#endif -+ ret = k5int_decode_krb5_principal_name(&name, &princs[p]); -+ if (ret) { -+ pkiDebug("%s: failed decoding pkinit san value\n", -+ __FUNCTION__); -+ } else { -+ p++; -+ num_found++; -+ } -+ } else if (upns != NULL && -+ OBJ_cmp(plgctx->id_ms_san_upn, -+ gen->d.otherName->type_id) == 0) { -+ /* Prevent abuse of embedded null characters. */ -+ if (memchr(name.data, '\0', name.length)) -+ break; -+ ret = krb5_parse_name_flags(context, name.data, -+ KRB5_PRINCIPAL_PARSE_ENTERPRISE, -+ &upns[u]); -+ if (ret) { -+ pkiDebug("%s: failed parsing ms-upn san value\n", -+ __FUNCTION__); -+ } else { -+ u++; -+ num_found++; -+ } -+ } else { -+ pkiDebug("%s: unrecognized othername oid in SAN\n", -+ __FUNCTION__); -+ continue; -+ } -+ -+ break; -+ case GEN_DNS: -+ if (dnss != NULL) { -+ /* Prevent abuse of embedded null characters. */ -+ if (memchr(gen->d.dNSName->data, '\0', gen->d.dNSName->length)) -+ break; -+ pkiDebug("%s: found dns name = %s\n", __FUNCTION__, -+ gen->d.dNSName->data); -+ dnss[d] = (unsigned char *) -+ strdup((char *)gen->d.dNSName->data); -+ if (dnss[d] == NULL) { -+ pkiDebug("%s: failed to duplicate dns name\n", -+ __FUNCTION__); -+ } else { -+ d++; -+ num_found++; -+ } -+ } -+ break; -+ default: -+ pkiDebug("%s: SAN type = %d expecting %d\n", __FUNCTION__, -+ gen->type, GEN_OTHERNAME); -+ } -+ } -+ sk_GENERAL_NAME_pop_free(ialt, GENERAL_NAME_free); - - retval = 0; - if (princs) diff --git a/Fix-bugs-in-kdcpolicy-commit.patch b/Fix-bugs-in-kdcpolicy-commit.patch deleted file mode 100644 index c4c50a1..0000000 --- a/Fix-bugs-in-kdcpolicy-commit.patch +++ /dev/null @@ -1,130 +0,0 @@ -From c8c704cdaaa15a0908024f0917344048c0df5940 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 19 Aug 2017 19:09:24 -0400 -Subject: [PATCH] Fix bugs in kdcpolicy commit - -Commit d0969f6a8170344031ef58fd2a161190f1edfb96 added tests using -"klist ccachname -e", which does not work with a POSIX-conformant -getopt() implementation such as the one in Solaris. Fix -t_kdcpolicy.py to use "klist -e ccachename" instead. - -The tests could fail if the clock second rolled over between kinit and -kvno. Divide service ticket maximum lifetimes by 2 in the test module -to correctly exercise TGS policy restrictions and ensure that service -tickets are not constrained by the TGT end time. - -Also use the correct trace macro when a kdcpolicy module declines to -initialize (my mistake when revising the commit, noted by rharwood). - -ticket: 8606 -(cherry picked from commit 09acbd91efc6df54e1572285ffc94c6acb3a9113) ---- - src/kdc/policy.c | 2 +- - src/plugins/kdcpolicy/test/main.c | 10 +++++----- - src/tests/t_kdcpolicy.py | 13 +++++++++---- - 3 files changed, 15 insertions(+), 10 deletions(-) - -diff --git a/src/kdc/policy.c b/src/kdc/policy.c -index e49644e06..26c16f97c 100644 ---- a/src/kdc/policy.c -+++ b/src/kdc/policy.c -@@ -222,7 +222,7 @@ load_kdcpolicy_plugins(krb5_context context) - if (h->vt.init != NULL) { - ret = h->vt.init(context, &h->moddata); - if (ret == KRB5_PLUGIN_NO_HANDLE) { -- TRACE_KADM5_AUTH_INIT_SKIP(context, h->vt.name); -+ TRACE_KDCPOLICY_INIT_SKIP(context, h->vt.name); - free(h); - continue; - } -diff --git a/src/plugins/kdcpolicy/test/main.c b/src/plugins/kdcpolicy/test/main.c -index eb8fde053..86c808958 100644 ---- a/src/plugins/kdcpolicy/test/main.c -+++ b/src/plugins/kdcpolicy/test/main.c -@@ -35,7 +35,7 @@ - #include - - static krb5_error_code --output_from_indicator(const char *const *auth_indicators, -+output_from_indicator(const char *const *auth_indicators, int divisor, - krb5_deltat *lifetime_out, - krb5_deltat *renew_lifetime_out, - const char **status) -@@ -46,11 +46,11 @@ output_from_indicator(const char *const *auth_indicators, - } - - if (strcmp(auth_indicators[0], "ONE_HOUR") == 0) { -- *lifetime_out = 3600; -+ *lifetime_out = 3600 / divisor; - *renew_lifetime_out = *lifetime_out * 2; - return 0; - } else if (strcmp(auth_indicators[0], "SEVEN_HOURS") == 0) { -- *lifetime_out = 7 * 3600; -+ *lifetime_out = 7 * 3600 / divisor; - *renew_lifetime_out = *lifetime_out * 2; - return 0; - } -@@ -71,7 +71,7 @@ test_check_as(krb5_context context, krb5_kdcpolicy_moddata moddata, - *status = "LOCAL_POLICY"; - return KRB5KDC_ERR_POLICY; - } -- return output_from_indicator(auth_indicators, lifetime_out, -+ return output_from_indicator(auth_indicators, 1, lifetime_out, - renew_lifetime_out, status); - } - -@@ -87,7 +87,7 @@ test_check_tgs(krb5_context context, krb5_kdcpolicy_moddata moddata, - *status = "LOCAL_POLICY"; - return KRB5KDC_ERR_POLICY; - } -- return output_from_indicator(auth_indicators, lifetime_out, -+ return output_from_indicator(auth_indicators, 2, lifetime_out, - renew_lifetime_out, status); - } - -diff --git a/src/tests/t_kdcpolicy.py b/src/tests/t_kdcpolicy.py -index 6a745b959..b5d308461 100644 ---- a/src/tests/t_kdcpolicy.py -+++ b/src/tests/t_kdcpolicy.py -@@ -18,16 +18,21 @@ realm.run([kadminl, 'addprinc', '-pw', password('fail'), 'fail']) - def verify_time(out, target_time): - times = re.findall(r'\d\d/\d\d/\d\d \d\d:\d\d:\d\d', out) - times = [datetime.strptime(t, '%m/%d/%y %H:%M:%S') for t in times] -+ divisor = 1 - while len(times) > 0: - starttime = times.pop(0) - endtime = times.pop(0) - renewtime = times.pop(0) - -- if str(endtime - starttime) != target_time: -+ if str((endtime - starttime) * divisor) != target_time: - fail('unexpected lifetime value') -- if str(renewtime - endtime) != target_time: -+ if str((renewtime - endtime) * divisor) != target_time: - fail('unexpected renewable value') - -+ # Service tickets should have half the lifetime of initial -+ # tickets. -+ divisor = 2 -+ - rflags = ['-r', '1d', '-l', '12h'] - - # Test AS+TGS success path. -@@ -35,7 +40,7 @@ realm.kinit(realm.user_princ, password('user'), - rflags + ['-X', 'indicators=SEVEN_HOURS']) - realm.run([kvno, realm.host_princ]) - realm.run(['./adata', realm.host_princ], expected_msg='+97: [SEVEN_HOURS]') --out = realm.run([klist, realm.ccache, '-e']) -+out = realm.run([klist, '-e', realm.ccache]) - verify_time(out, '7:00:00') - - # Test AS+TGS success path with different values. -@@ -43,7 +48,7 @@ realm.kinit(realm.user_princ, password('user'), - rflags + ['-X', 'indicators=ONE_HOUR']) - realm.run([kvno, realm.host_princ]) - realm.run(['./adata', realm.host_princ], expected_msg='+97: [ONE_HOUR]') --out = realm.run([klist, realm.ccache, '-e']) -+out = realm.run([klist, '-e', realm.ccache]) - verify_time(out, '1:00:00') - - # Test TGS failure path (using previous creds). diff --git a/Fix-certauth-built-in-module-returns.patch b/Fix-certauth-built-in-module-returns.patch deleted file mode 100644 index 1c927d5..0000000 --- a/Fix-certauth-built-in-module-returns.patch +++ /dev/null @@ -1,124 +0,0 @@ -From 0d93e336e2cb8319bfd3e0fa096e5ee8ea3bbbbf Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 24 Aug 2017 11:11:46 -0400 -Subject: [PATCH] Fix certauth built-in module returns - -The PKINIT certauth eku module should never authoritatively authorize -a certificate, because an extended key usage does not establish a -relationship between the certificate and any specific user; it only -establishes that the certificate was created for PKINIT client -authentication. Therefore, pkinit_eku_authorize() should return -KRB5_PLUGIN_NO_HANDLE on success, not 0. - -The certauth san module should pass if it does not find any SANs of -the types it can match against; the presence of other types of SANs -should not cause it to explicitly deny a certificate. Check for an -empty result from crypto_retrieve_cert_sans() in verify_client_san(), -instead of returning ENOENT from crypto_retrieve_cert_sans() when -there are no SANs at all. - -ticket: 8561 -(cherry picked from commit 07243f85a760fb37f0622d7ff0177db3f19ab025) ---- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 39 ++++++++++------------ - src/plugins/preauth/pkinit/pkinit_srv.c | 14 +++++--- - 2 files changed, 27 insertions(+), 26 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 70e230ec2..7fa2efd21 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2137,7 +2137,6 @@ crypto_retrieve_X509_sans(krb5_context context, - - if (!(ext = X509_get_ext(cert, l)) || !(ialt = X509V3_EXT_d2i(ext))) { - pkiDebug("%s: found no subject alt name extensions\n", __FUNCTION__); -- retval = ENOENT; - goto cleanup; - } - num_sans = sk_GENERAL_NAME_num(ialt); -@@ -2240,31 +2239,29 @@ crypto_retrieve_X509_sans(krb5_context context, - sk_GENERAL_NAME_pop_free(ialt, GENERAL_NAME_free); - - retval = 0; -- if (princs) -+ if (princs != NULL && *princs != NULL) { - *princs_ret = princs; -- if (upns) -+ princs = NULL; -+ } -+ if (upns != NULL && *upns != NULL) { - *upn_ret = upns; -- if (dnss) -+ upns = NULL; -+ } -+ if (dnss != NULL && *dnss != NULL) { - *dns_ret = dnss; -+ dnss = NULL; -+ } - - cleanup: -- if (retval) { -- if (princs != NULL) { -- for (i = 0; princs[i] != NULL; i++) -- krb5_free_principal(context, princs[i]); -- free(princs); -- } -- if (upns != NULL) { -- for (i = 0; upns[i] != NULL; i++) -- krb5_free_principal(context, upns[i]); -- free(upns); -- } -- if (dnss != NULL) { -- for (i = 0; dnss[i] != NULL; i++) -- free(dnss[i]); -- free(dnss); -- } -- } -+ for (i = 0; princs != NULL && princs[i] != NULL; i++) -+ krb5_free_principal(context, princs[i]); -+ free(princs); -+ for (i = 0; upns != NULL && upns[i] != NULL; i++) -+ krb5_free_principal(context, upns[i]); -+ free(upns); -+ for (i = 0; dnss != NULL && dnss[i] != NULL; i++) -+ free(dnss[i]); -+ free(dnss); - return retval; - } - -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index 9c6e96c9e..8e77606f8 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -187,14 +187,18 @@ verify_client_san(krb5_context context, - &princs, - plgctx->opts->allow_upn ? &upns : NULL, - NULL); -- if (retval == ENOENT) { -- TRACE_PKINIT_SERVER_NO_SAN(context); -- goto out; -- } else if (retval) { -+ if (retval) { - pkiDebug("%s: error from retrieve_certificate_sans()\n", __FUNCTION__); - retval = KRB5KDC_ERR_CLIENT_NAME_MISMATCH; - goto out; - } -+ -+ if (princs == NULL && upns == NULL) { -+ TRACE_PKINIT_SERVER_NO_SAN(context); -+ retval = ENOENT; -+ goto out; -+ } -+ - /* XXX Verify this is consistent with client side XXX */ - #if 0 - retval = call_san_checking_plugins(context, plgctx, reqctx, princs, -@@ -1495,7 +1499,7 @@ pkinit_eku_authorize(krb5_context context, krb5_certauth_moddata moddata, - return KRB5KDC_ERR_INCONSISTENT_KEY_PURPOSE; - } - -- return 0; -+ return KRB5_PLUGIN_NO_HANDLE; - } - - static krb5_error_code diff --git a/Fix-in_clock_skew-and-use-it-in-AS-client-code.patch b/Fix-in_clock_skew-and-use-it-in-AS-client-code.patch deleted file mode 100644 index a8a53cf..0000000 --- a/Fix-in_clock_skew-and-use-it-in-AS-client-code.patch +++ /dev/null @@ -1,58 +0,0 @@ -From e2d34698687c00504b83e1c0deb56dc6232bef42 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 24 Apr 2017 02:02:36 -0400 -Subject: [PATCH] Fix in_clock_skew() and use it in AS client code - -Add a context parameter to the in_clock_skew() macro so that it isn't -implicitly relying on a local variable. Use it in -get_in_tkt.c:verify_as_reply(). - -(cherry picked from commit 28a07a6461bb443b7fa75cc5cb859ad0db4cbb5a) ---- - src/lib/krb5/krb/gc_via_tkt.c | 2 +- - src/lib/krb5/krb/get_in_tkt.c | 4 ++-- - src/lib/krb5/krb/int-proto.h | 3 ++- - 3 files changed, 5 insertions(+), 4 deletions(-) - -diff --git a/src/lib/krb5/krb/gc_via_tkt.c b/src/lib/krb5/krb/gc_via_tkt.c -index 4c0a1a461..c85d8b8d8 100644 ---- a/src/lib/krb5/krb/gc_via_tkt.c -+++ b/src/lib/krb5/krb/gc_via_tkt.c -@@ -305,7 +305,7 @@ krb5int_process_tgs_reply(krb5_context context, - goto cleanup; - - if (!in_cred->times.starttime && -- !in_clock_skew(dec_rep->enc_part2->times.starttime, -+ !in_clock_skew(context, dec_rep->enc_part2->times.starttime, - timestamp)) { - retval = KRB5_KDCREP_SKEW; - goto cleanup; -diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c -index 54badbbc3..a058f5bd7 100644 ---- a/src/lib/krb5/krb/get_in_tkt.c -+++ b/src/lib/krb5/krb/get_in_tkt.c -@@ -287,8 +287,8 @@ verify_as_reply(krb5_context context, - return retval; - } else { - if ((request->from == 0) && -- (labs(as_reply->enc_part2->times.starttime - time_now) -- > context->clockskew)) -+ !in_clock_skew(context, as_reply->enc_part2->times.starttime, -+ time_now)) - return (KRB5_KDCREP_SKEW); - } - return 0; -diff --git a/src/lib/krb5/krb/int-proto.h b/src/lib/krb5/krb/int-proto.h -index 6da74858e..44eca359f 100644 ---- a/src/lib/krb5/krb/int-proto.h -+++ b/src/lib/krb5/krb/int-proto.h -@@ -83,7 +83,8 @@ krb5int_construct_matching_creds(krb5_context context, krb5_flags options, - krb5_creds *in_creds, krb5_creds *mcreds, - krb5_flags *fields); - --#define in_clock_skew(date, now) (labs((date)-(now)) < context->clockskew) -+#define in_clock_skew(context, date, now) \ -+ (labs((date) - (now)) < (context)->clockskew) - - #define IS_TGS_PRINC(p) ((p)->length == 2 && \ - data_eq_string((p)->data[0], KRB5_TGS_NAME)) diff --git a/Fix-more-time-manipulations-for-y2038.patch b/Fix-more-time-manipulations-for-y2038.patch deleted file mode 100644 index a57a64c..0000000 --- a/Fix-more-time-manipulations-for-y2038.patch +++ /dev/null @@ -1,83 +0,0 @@ -From 7b28a408650c58d0ea98fddab5034642af32fdaf Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 17 May 2017 14:52:09 -0400 -Subject: [PATCH] Fix more time manipulations for y2038 - -Use timestamp helper functions to ensure that more operations are safe -after y2038, and display the current timestamp as unsigned in -krb5int_trace(). - -ticket: 8352 -(cherry picked from commit a60db180211a383bd382afe729e9309acb8dcf53) ---- - src/kadmin/server/misc.c | 2 +- - src/kdc/dispatch.c | 2 +- - src/lib/krb5/os/c_ustime.c | 8 ++++---- - src/lib/krb5/os/trace.c | 2 +- - 4 files changed, 7 insertions(+), 7 deletions(-) - -diff --git a/src/kadmin/server/misc.c b/src/kadmin/server/misc.c -index 27a6376af..a75b65a26 100644 ---- a/src/kadmin/server/misc.c -+++ b/src/kadmin/server/misc.c -@@ -184,7 +184,7 @@ check_min_life(void *server_handle, krb5_principal principal, - (void) kadm5_free_principal_ent(handle->lhandle, &princ); - return (ret == KADM5_UNK_POLICY) ? 0 : ret; - } -- if((now - princ.last_pwd_change) < pol.pw_min_life && -+ if(ts_delta(now, princ.last_pwd_change) < pol.pw_min_life && - !(princ.attributes & KRB5_KDB_REQUIRES_PWCHANGE)) { - if (msg_ret != NULL) { - time_t until; -diff --git a/src/kdc/dispatch.c b/src/kdc/dispatch.c -index 3a169ebc7..16a35d2be 100644 ---- a/src/kdc/dispatch.c -+++ b/src/kdc/dispatch.c -@@ -104,7 +104,7 @@ reseed_random(krb5_context kdc_err_context) - if (last_os_random == 0) - last_os_random = now; - /* Grab random data from OS every hour*/ -- if (now-last_os_random >= 60 * 60) { -+ if (ts_delta(now, last_os_random) >= 60 * 60) { - krb5_c_random_os_entropy(kdc_err_context, 0, NULL); - last_os_random = now; - } -diff --git a/src/lib/krb5/os/c_ustime.c b/src/lib/krb5/os/c_ustime.c -index 871d72183..68fb381f4 100644 ---- a/src/lib/krb5/os/c_ustime.c -+++ b/src/lib/krb5/os/c_ustime.c -@@ -102,17 +102,17 @@ krb5_crypto_us_timeofday(krb5_int32 *seconds, krb5_int32 *microseconds) - putting now.sec in the past. But don't just use '<' because we - need to properly handle the case where the administrator intentionally - adjusted time backwards. */ -- if ((now.sec == last_time.sec-1) || -- ((now.sec == last_time.sec) && (now.usec <= last_time.usec))) { -+ if (now.sec == ts_incr(last_time.sec, -1) || -+ (now.sec == last_time.sec && !ts_after(last_time.usec, now.usec))) { - /* Correct 'now' to be exactly one microsecond later than 'last_time'. - Note that _because_ we perform this hack, 'now' may be _earlier_ - than 'last_time', even though the system time is monotonically - increasing. */ - - now.sec = last_time.sec; -- now.usec = ++last_time.usec; -+ now.usec = ts_incr(last_time.usec, 1); - if (now.usec >= 1000000) { -- ++now.sec; -+ now.sec = ts_incr(now.sec, 1); - now.usec = 0; - } - } -diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c -index a19246128..74c315c90 100644 ---- a/src/lib/krb5/os/trace.c -+++ b/src/lib/krb5/os/trace.c -@@ -350,7 +350,7 @@ krb5int_trace(krb5_context context, const char *fmt, ...) - goto cleanup; - if (krb5_crypto_us_timeofday(&sec, &usec) != 0) - goto cleanup; -- if (asprintf(&msg, "[%d] %d.%d: %s\n", (int) getpid(), (int) sec, -+ if (asprintf(&msg, "[%d] %u.%d: %s\n", (int) getpid(), (unsigned int) sec, - (int) usec, str) < 0) - goto cleanup; - info.message = msg; diff --git a/Improve-PKINIT-UPN-SAN-matching.patch b/Improve-PKINIT-UPN-SAN-matching.patch deleted file mode 100644 index 26b27f1..0000000 --- a/Improve-PKINIT-UPN-SAN-matching.patch +++ /dev/null @@ -1,151 +0,0 @@ -From 03265620488b84238c31170356b5f41c80f0e9d9 Mon Sep 17 00:00:00 2001 -From: Matt Rogers -Date: Mon, 5 Dec 2016 12:17:59 -0500 -Subject: [PATCH] Improve PKINIT UPN SAN matching - -Add the match_client() kdcpreauth callback and use it in -verify_client_san(). match_client() preserves the direct UPN to -request principal comparison and adds a direct comparison to the -client principal, falling back to an alias DB search and comparison -against the client principal. Change crypto_retreive_X509_sans() to -parse UPN values as enterprise principals. - -[ghudson@mit.edu: use match_client for both kinds of SANs] - -ticket: 8528 (new) -(cherry picked from commit 46ff765e1fb8cbec2bb602b43311269e695dbedc) ---- - src/include/krb5/kdcpreauth_plugin.h | 13 ++++++++++ - src/kdc/kdc_preauth.c | 28 ++++++++++++++++++++-- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 4 +++- - src/plugins/preauth/pkinit/pkinit_srv.c | 10 ++++---- - 4 files changed, 48 insertions(+), 7 deletions(-) - -diff --git a/src/include/krb5/kdcpreauth_plugin.h b/src/include/krb5/kdcpreauth_plugin.h -index f455effae..92aa5a5a5 100644 ---- a/src/include/krb5/kdcpreauth_plugin.h -+++ b/src/include/krb5/kdcpreauth_plugin.h -@@ -221,6 +221,19 @@ typedef struct krb5_kdcpreauth_callbacks_st { - - /* End of version 3 kdcpreauth callbacks. */ - -+ /* -+ * Return true if princ matches the principal named in the request or the -+ * client principal (possibly canonicalized). If princ does not match, -+ * attempt a database lookup of princ with aliases allowed and compare the -+ * result to the client principal, returning true if it matches. -+ * Otherwise, return false. -+ */ -+ krb5_boolean (*match_client)(krb5_context context, -+ krb5_kdcpreauth_rock rock, -+ krb5_principal princ); -+ -+ /* End of version 4 kdcpreauth callbacks. */ -+ - } *krb5_kdcpreauth_callbacks; - - /* Optional: preauth plugin initialization function. */ -diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c -index 605fcb7ad..0ce79c667 100644 ---- a/src/kdc/kdc_preauth.c -+++ b/src/kdc/kdc_preauth.c -@@ -568,8 +568,31 @@ set_cookie(krb5_context context, krb5_kdcpreauth_rock rock, - return kdc_fast_set_cookie(rock->rstate, pa_type, data); - } - -+static krb5_boolean -+match_client(krb5_context context, krb5_kdcpreauth_rock rock, -+ krb5_principal princ) -+{ -+ krb5_db_entry *ent; -+ krb5_boolean match = FALSE; -+ krb5_principal req_client = rock->request->client; -+ krb5_principal client = rock->client->princ; -+ -+ /* Check for a direct match against the request principal or -+ * the post-canon client principal. */ -+ if (krb5_principal_compare_flags(context, princ, req_client, -+ KRB5_PRINCIPAL_COMPARE_ENTERPRISE) || -+ krb5_principal_compare(context, princ, client)) -+ return TRUE; -+ -+ if (krb5_db_get_principal(context, princ, KRB5_KDB_FLAG_ALIAS_OK, &ent)) -+ return FALSE; -+ match = krb5_principal_compare(context, ent->princ, client); -+ krb5_db_free_principal(context, ent); -+ return match; -+} -+ - static struct krb5_kdcpreauth_callbacks_st callbacks = { -- 3, -+ 4, - max_time_skew, - client_keys, - free_keys, -@@ -583,7 +606,8 @@ static struct krb5_kdcpreauth_callbacks_st callbacks = { - client_keyblock, - add_auth_indicator, - get_cookie, -- set_cookie -+ set_cookie, -+ match_client - }; - - static krb5_error_code -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 74fffbf32..bc6e7662e 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2190,7 +2190,9 @@ crypto_retrieve_X509_sans(krb5_context context, - /* Prevent abuse of embedded null characters. */ - if (memchr(name.data, '\0', name.length)) - break; -- ret = krb5_parse_name(context, name.data, &upns[u]); -+ ret = krb5_parse_name_flags(context, name.data, -+ KRB5_PRINCIPAL_PARSE_ENTERPRISE, -+ &upns[u]); - if (ret) { - pkiDebug("%s: failed parsing ms-upn san value\n", - __FUNCTION__); -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index 295be25e1..b5638a367 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -121,6 +121,8 @@ static krb5_error_code - verify_client_san(krb5_context context, - pkinit_kdc_context plgctx, - pkinit_kdc_req_context reqctx, -+ krb5_kdcpreauth_callbacks cb, -+ krb5_kdcpreauth_rock rock, - krb5_principal client, - int *valid_san) - { -@@ -171,7 +173,7 @@ verify_client_san(krb5_context context, - __FUNCTION__, client_string, san_string); - krb5_free_unparsed_name(context, san_string); - #endif -- if (krb5_principal_compare(context, princs[i], client)) { -+ if (cb->match_client(context, rock, princs[i])) { - pkiDebug("%s: pkinit san match found\n", __FUNCTION__); - *valid_san = 1; - retval = 0; -@@ -199,7 +201,7 @@ verify_client_san(krb5_context context, - __FUNCTION__, client_string, san_string); - krb5_free_unparsed_name(context, san_string); - #endif -- if (krb5_principal_compare(context, upns[i], client)) { -+ if (cb->match_client(context, rock, upns[i])) { - pkiDebug("%s: upn san match found\n", __FUNCTION__); - *valid_san = 1; - retval = 0; -@@ -387,8 +389,8 @@ pkinit_server_verify_padata(krb5_context context, - } - if (is_signed) { - -- retval = verify_client_san(context, plgctx, reqctx, request->client, -- &valid_san); -+ retval = verify_client_san(context, plgctx, reqctx, cb, rock, -+ request->client, &valid_san); - if (retval) - goto cleanup; - if (!valid_san) { diff --git a/Make-timestamp-manipulations-y2038-safe.patch b/Make-timestamp-manipulations-y2038-safe.patch deleted file mode 100644 index 26bff26..0000000 --- a/Make-timestamp-manipulations-y2038-safe.patch +++ /dev/null @@ -1,1844 +0,0 @@ -From ac30f4753f157dafe93df2941a216fde591fcb69 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 22 Apr 2017 12:52:17 -0400 -Subject: [PATCH] Make timestamp manipulations y2038-safe - -Wherever we manipulate krb5_timestamp values using arithmetic, -comparison operations, or conversion to time_t, use the new helper -functions in k5-int.h to ensure that the operations work after y2038 -and do not exhibit undefined behavior. (Relying on -implementation-defined conversion to signed values is okay as we test -that in configure.in.) - -In printf format strings, use %u instead of signed types. When -exporting creds with k5_json_array_fmt(), use a long long so that -timestamps after y2038 aren't marshalled as negative numbers. When -parsing timestamps in test programs, use atoll() instead of atol() so -that positive timestamps after y2038 can be used as input. - -In ksu and klist, make printtime() take a krb5_timestamp parameter to -avoid an unnecessary conversion to time_t and back. - -As Leash does not use k5-int.h, use time_t values internally and -safely convert from libkrb5 timestamp values. - -ticket: 8352 -(cherry picked from commit a9cbbf0899f270fbb14f63ffbed1b6d542333641) ---- - src/clients/kinit/kinit.c | 2 +- - src/clients/klist/klist.c | 20 ++++------- - src/clients/ksu/ccache.c | 20 +++-------- - src/clients/ksu/ksu.h | 2 +- - src/kadmin/cli/getdate.y | 2 +- - src/kadmin/cli/kadmin.c | 5 ++- - src/kadmin/dbutil/dump.c | 27 ++++++++------- - src/kadmin/dbutil/kdb5_mkey.c | 6 ++-- - src/kadmin/dbutil/tabdump.c | 2 +- - src/kadmin/testing/util/tcl_kadm5.c | 12 +++---- - src/kdc/do_as_req.c | 2 +- - src/kdc/do_tgs_req.c | 6 ++-- - src/kdc/extern.c | 4 ++- - src/kdc/fast_util.c | 4 +-- - src/kdc/kdc_log.c | 14 ++++---- - src/kdc/kdc_util.c | 20 +++++------ - src/kdc/kdc_util.h | 2 ++ - src/kdc/replay.c | 2 +- - src/kdc/tgs_policy.c | 7 ++-- - src/lib/gssapi/krb5/accept_sec_context.c | 8 +++-- - src/lib/gssapi/krb5/acquire_cred.c | 13 ++++--- - src/lib/gssapi/krb5/context_time.c | 2 +- - src/lib/gssapi/krb5/export_cred.c | 5 +-- - src/lib/gssapi/krb5/iakerb.c | 4 +-- - src/lib/gssapi/krb5/init_sec_context.c | 9 ++--- - src/lib/gssapi/krb5/inq_context.c | 2 +- - src/lib/gssapi/krb5/inq_cred.c | 5 +-- - src/lib/gssapi/krb5/s4u_gss_glue.c | 2 +- - src/lib/kadm5/chpass_util.c | 8 ++--- - src/lib/kadm5/srv/server_acl.c | 5 +-- - src/lib/kadm5/srv/svr_principal.c | 12 +++---- - src/lib/kdb/kdb5.c | 2 +- - src/lib/krb5/asn.1/asn1_k_encode.c | 3 +- - src/lib/krb5/ccache/cc_keyring.c | 14 ++++---- - src/lib/krb5/ccache/cc_memory.c | 4 +-- - src/lib/krb5/ccache/cc_retr.c | 4 +-- - src/lib/krb5/ccache/ccapi/stdcc_util.c | 40 +++++++++++----------- - src/lib/krb5/ccache/cccursor.c | 2 +- - src/lib/krb5/keytab/kt_file.c | 6 ++-- - src/lib/krb5/krb/gc_via_tkt.c | 7 ++-- - src/lib/krb5/krb/get_creds.c | 2 +- - src/lib/krb5/krb/get_in_tkt.c | 38 ++++++-------------- - src/lib/krb5/krb/gic_pwd.c | 4 +-- - src/lib/krb5/krb/int-proto.h | 2 +- - src/lib/krb5/krb/pac.c | 2 +- - src/lib/krb5/krb/str_conv.c | 4 +-- - src/lib/krb5/krb/t_kerb.c | 12 ++----- - src/lib/krb5/krb/valid_times.c | 4 +-- - src/lib/krb5/krb/vfy_increds.c | 2 +- - src/lib/krb5/os/timeofday.c | 2 +- - src/lib/krb5/os/toffset.c | 2 +- - src/lib/krb5/os/ustime.c | 6 ++-- - src/lib/krb5/rcache/rc_dfl.c | 3 +- - src/lib/krb5/rcache/t_replay.c | 8 ++--- - src/plugins/kdb/db2/lockout.c | 8 ++--- - src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c | 2 +- - src/plugins/kdb/ldap/libkdb_ldap/lockout.c | 8 ++--- - src/windows/cns/tktlist.c | 10 +++--- - src/windows/include/leashwin.h | 12 +++---- - src/windows/leash/KrbListTickets.cpp | 12 +++---- - src/windows/leash/LeashView.cpp | 22 ++++++------ - src/windows/leashdll/lshfunc.c | 2 +- - src/windows/ms2mit/ms2mit.c | 2 +- - 63 files changed, 230 insertions(+), 255 deletions(-) - -diff --git a/src/clients/kinit/kinit.c b/src/clients/kinit/kinit.c -index f1cd1b73d..50065e32e 100644 ---- a/src/clients/kinit/kinit.c -+++ b/src/clients/kinit/kinit.c -@@ -318,7 +318,7 @@ parse_options(argc, argv, opts) - fprintf(stderr, _("Bad start time value %s\n"), optarg); - errflg++; - } else { -- opts->starttime = abs_starttime - time(0); -+ opts->starttime = ts_delta(abs_starttime, time(NULL)); - } - } - break; -diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c -index ba19788a2..ffeecc394 100644 ---- a/src/clients/klist/klist.c -+++ b/src/clients/klist/klist.c -@@ -72,7 +72,7 @@ void do_ccache_name (char *); - int show_ccache (krb5_ccache); - int check_ccache (krb5_ccache); - void do_keytab (char *); --void printtime (time_t); -+void printtime (krb5_timestamp); - void one_addr (krb5_address *); - void fillit (FILE *, unsigned int, int); - -@@ -538,10 +538,10 @@ check_ccache(krb5_ccache cache) - while (!(ret = krb5_cc_next_cred(kcontext, cache, &cur, &creds))) { - if (is_local_tgt(creds.server, &princ->realm)) { - found_tgt = TRUE; -- if (creds.times.endtime > now) -+ if (ts_after(creds.times.endtime, now)) - found_current_tgt = TRUE; - } else if (!krb5_is_config_principal(kcontext, creds.server) && -- creds.times.endtime > now) { -+ ts_after(creds.times.endtime, now)) { - found_current_cred = TRUE; - } - krb5_free_cred_contents(kcontext, &creds); -@@ -623,19 +623,13 @@ flags_string(cred) - } - - void --printtime(tv) -- time_t tv; -+printtime(krb5_timestamp ts) - { -- char timestring[BUFSIZ]; -- char fill; -+ char timestring[BUFSIZ], fill = ' '; - -- fill = ' '; -- if (!krb5_timestamp_to_sfstring((krb5_timestamp) tv, -- timestring, -- timestamp_width+1, -- &fill)) { -+ if (!krb5_timestamp_to_sfstring(ts, timestring, timestamp_width + 1, -+ &fill)) - printf("%s", timestring); -- } - } - - static void -diff --git a/src/clients/ksu/ccache.c b/src/clients/ksu/ccache.c -index a0736f2da..236313b7b 100644 ---- a/src/clients/ksu/ccache.c -+++ b/src/clients/ksu/ccache.c -@@ -278,11 +278,11 @@ krb5_error_code krb5_check_exp(context, tkt_time) - context->clockskew); - - fprintf(stderr,"krb5_check_exp: currenttime - endtime %d \n", -- (currenttime - tkt_time.endtime )); -+ ts_delta(currenttime, tkt_time.endtime)); - - } - -- if (currenttime - tkt_time.endtime > context->clockskew){ -+ if (ts_delta(currenttime, tkt_time.endtime) > context->clockskew) { - retval = KRB5KRB_AP_ERR_TKT_EXPIRED ; - return retval; - } -@@ -323,21 +323,11 @@ char *flags_string(cred) - return(buf); - } - --void printtime(tv) -- time_t tv; -+void printtime(krb5_timestamp ts) - { -- char fmtbuf[18]; -- char fill; -- krb5_timestamp tstamp; -+ char fmtbuf[18], fill = ' '; - -- /* XXXX ASSUMES sizeof(krb5_timestamp) >= sizeof(time_t) */ -- (void) localtime((time_t *)&tv); -- tstamp = tv; -- fill = ' '; -- if (!krb5_timestamp_to_sfstring(tstamp, -- fmtbuf, -- sizeof(fmtbuf), -- &fill)) -+ if (!krb5_timestamp_to_sfstring(ts, fmtbuf, sizeof(fmtbuf), &fill)) - printf("%s", fmtbuf); - } - -diff --git a/src/clients/ksu/ksu.h b/src/clients/ksu/ksu.h -index ee8e9d6a0..3bf0bd438 100644 ---- a/src/clients/ksu/ksu.h -+++ b/src/clients/ksu/ksu.h -@@ -150,7 +150,7 @@ extern krb5_boolean krb5_find_princ_in_cred_list - extern krb5_error_code krb5_find_princ_in_cache - (krb5_context, krb5_ccache, krb5_principal, krb5_boolean *); - --extern void printtime (time_t); -+extern void printtime (krb5_timestamp); - - /* authorization.c */ - extern krb5_boolean fowner (FILE *, uid_t); -diff --git a/src/kadmin/cli/getdate.y b/src/kadmin/cli/getdate.y -index 4f0c56f7e..0a19c5648 100644 ---- a/src/kadmin/cli/getdate.y -+++ b/src/kadmin/cli/getdate.y -@@ -118,7 +118,7 @@ static int getdate_yyerror (char *); - - - #define EPOCH 1970 --#define EPOCH_END 2038 /* assumes 32 bits */ -+#define EPOCH_END 2106 /* assumes unsigned 32-bit range */ - #define HOUR(x) ((time_t)(x) * 60) - #define SECSPERDAY (24L * 60L * 60L) - -diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c -index c53c677a8..aee5c83b9 100644 ---- a/src/kadmin/cli/kadmin.c -+++ b/src/kadmin/cli/kadmin.c -@@ -31,8 +31,7 @@ - * library */ - - /* for "_" macro */ --#include "k5-platform.h" --#include -+#include "k5-int.h" - #include - #include - #include -@@ -144,8 +143,8 @@ strdate(krb5_timestamp when) - { - struct tm *tm; - static char out[40]; -+ time_t lcltim = ts2tt(when); - -- time_t lcltim = when; - tm = localtime(&lcltim); - strftime(out, sizeof(out), "%a %b %d %H:%M:%S %Z %Y", tm); - return out; -diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c -index cad53cfbf..a6fc4ea77 100644 ---- a/src/kadmin/dbutil/dump.c -+++ b/src/kadmin/dbutil/dump.c -@@ -379,11 +379,12 @@ k5beta7_common(krb5_context context, krb5_db_entry *entry, - fprintf(fp, "princ\t%d\t%lu\t%d\t%d\t%d\t%s\t", (int)entry->len, - (unsigned long)strlen(name), counter, (int)entry->n_key_data, - (int)entry->e_length, name); -- fprintf(fp, "%d\t%d\t%d\t%d\t%d\t%d\t%d\t%d", entry->attributes, -- entry->max_life, entry->max_renewable_life, entry->expiration, -- entry->pw_expiration, -- omit_nra ? 0 : entry->last_success, -- omit_nra ? 0 : entry->last_failed, -+ fprintf(fp, "%d\t%d\t%d\t%u\t%u\t%u\t%u\t%d", entry->attributes, -+ entry->max_life, entry->max_renewable_life, -+ (unsigned int)entry->expiration, -+ (unsigned int)entry->pw_expiration, -+ (unsigned int)(omit_nra ? 0 : entry->last_success), -+ (unsigned int)(omit_nra ? 0 : entry->last_failed), - omit_nra ? 0 : entry->fail_auth_count); - - /* Write out tagged data. */ -@@ -717,7 +718,7 @@ process_k5beta7_princ(krb5_context context, const char *fname, FILE *filep, - { - int retval, nread, i, j; - krb5_db_entry *dbentry; -- int t1, t2, t3, t4, t5, t6, t7; -+ int t1, t2, t3, t4; - unsigned int u1, u2, u3, u4, u5; - char *name = NULL; - krb5_key_data *kp = NULL, *kd; -@@ -773,8 +774,8 @@ process_k5beta7_princ(krb5_context context, const char *fname, FILE *filep, - } - - /* Get the fixed principal attributes */ -- nread = fscanf(filep, "%d\t%d\t%d\t%d\t%d\t%d\t%d\t%d\t", -- &t1, &t2, &t3, &t4, &t5, &t6, &t7, &u1); -+ nread = fscanf(filep, "%d\t%d\t%d\t%u\t%u\t%d\t%d\t%d\t", -+ &t1, &t2, &t3, &u1, &u2, &u3, &u4, &u5); - if (nread != 8) { - load_err(fname, *linenop, _("cannot read principal attributes")); - goto fail; -@@ -782,11 +783,11 @@ process_k5beta7_princ(krb5_context context, const char *fname, FILE *filep, - dbentry->attributes = t1; - dbentry->max_life = t2; - dbentry->max_renewable_life = t3; -- dbentry->expiration = t4; -- dbentry->pw_expiration = t5; -- dbentry->last_success = t6; -- dbentry->last_failed = t7; -- dbentry->fail_auth_count = u1; -+ dbentry->expiration = u1; -+ dbentry->pw_expiration = u2; -+ dbentry->last_success = u3; -+ dbentry->last_failed = u4; -+ dbentry->fail_auth_count = u5; - dbentry->mask = KADM5_LOAD | KADM5_PRINCIPAL | KADM5_ATTRIBUTES | - KADM5_MAX_LIFE | KADM5_MAX_RLIFE | - KADM5_PRINC_EXPIRE_TIME | KADM5_LAST_SUCCESS | -diff --git a/src/kadmin/dbutil/kdb5_mkey.c b/src/kadmin/dbutil/kdb5_mkey.c -index 7df8cbc83..2efe3176e 100644 ---- a/src/kadmin/dbutil/kdb5_mkey.c -+++ b/src/kadmin/dbutil/kdb5_mkey.c -@@ -44,8 +44,8 @@ static char *strdate(krb5_timestamp when) - { - struct tm *tm; - static char out[40]; -+ time_t lcltim = ts2tt(when); - -- time_t lcltim = when; - tm = localtime(&lcltim); - strftime(out, sizeof(out), "%a %b %d %H:%M:%S %Z %Y", tm); - return out; -@@ -481,7 +481,7 @@ kdb5_use_mkey(int argc, char *argv[]) - cur_actkvno != NULL; - prev_actkvno = cur_actkvno, cur_actkvno = cur_actkvno->next) { - -- if (new_actkvno->act_time < cur_actkvno->act_time) { -+ if (ts_after(cur_actkvno->act_time, new_actkvno->act_time)) { - if (prev_actkvno) { - prev_actkvno->next = new_actkvno; - new_actkvno->next = cur_actkvno; -@@ -499,7 +499,7 @@ kdb5_use_mkey(int argc, char *argv[]) - } - } - -- if (actkvno_list->act_time > now) { -+ if (ts_after(actkvno_list->act_time, now)) { - com_err(progname, EINVAL, - _("there must be one master key currently active")); - exit_status++; -diff --git a/src/kadmin/dbutil/tabdump.c b/src/kadmin/dbutil/tabdump.c -index 69a3482ec..fb36b060a 100644 ---- a/src/kadmin/dbutil/tabdump.c -+++ b/src/kadmin/dbutil/tabdump.c -@@ -148,7 +148,7 @@ write_date_iso(struct rec_args *args, krb5_timestamp when) - struct tm *tm = NULL; - struct rechandle *h = args->rh; - -- t = when; -+ t = ts2tt(when); - tm = gmtime(&t); - if (tm == NULL) { - errno = EINVAL; -diff --git a/src/kadmin/testing/util/tcl_kadm5.c b/src/kadmin/testing/util/tcl_kadm5.c -index a4997c60c..9dde579ef 100644 ---- a/src/kadmin/testing/util/tcl_kadm5.c -+++ b/src/kadmin/testing/util/tcl_kadm5.c -@@ -697,13 +697,13 @@ static Tcl_DString *unparse_principal_ent(kadm5_principal_ent_t princ, - } else - Tcl_DStringAppendElement(str, "null"); - -- sprintf(buf, "%d", princ->princ_expire_time); -+ sprintf(buf, "%u", (unsigned int)princ->princ_expire_time); - Tcl_DStringAppendElement(str, buf); - -- sprintf(buf, "%d", princ->last_pwd_change); -+ sprintf(buf, "%u", (unsigned int)princ->last_pwd_change); - Tcl_DStringAppendElement(str, buf); - -- sprintf(buf, "%d", princ->pw_expiration); -+ sprintf(buf, "%u", (unsigned int)princ->pw_expiration); - Tcl_DStringAppendElement(str, buf); - - sprintf(buf, "%d", princ->max_life); -@@ -722,7 +722,7 @@ static Tcl_DString *unparse_principal_ent(kadm5_principal_ent_t princ, - } else - Tcl_DStringAppendElement(str, "null"); - -- sprintf(buf, "%d", princ->mod_date); -+ sprintf(buf, "%u", (unsigned int)princ->mod_date); - Tcl_DStringAppendElement(str, buf); - - if (mask & KADM5_ATTRIBUTES) { -@@ -758,10 +758,10 @@ static Tcl_DString *unparse_principal_ent(kadm5_principal_ent_t princ, - sprintf(buf, "%d", princ->max_renewable_life); - Tcl_DStringAppendElement(str, buf); - -- sprintf(buf, "%d", princ->last_success); -+ sprintf(buf, "%u", (unsigned int)princ->last_success); - Tcl_DStringAppendElement(str, buf); - -- sprintf(buf, "%d", princ->last_failed); -+ sprintf(buf, "%u", (unsigned int)princ->last_failed); - Tcl_DStringAppendElement(str, buf); - - sprintf(buf, "%d", princ->fail_auth_count); -diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c -index a4bf91b1b..f85da6da6 100644 ---- a/src/kdc/do_as_req.c -+++ b/src/kdc/do_as_req.c -@@ -87,7 +87,7 @@ get_key_exp(krb5_db_entry *entry) - return entry->pw_expiration; - if (entry->pw_expiration == 0) - return entry->expiration; -- return min(entry->expiration, entry->pw_expiration); -+ return ts_min(entry->expiration, entry->pw_expiration); - } - - /* -diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c -index 339259fd1..ac5864603 100644 ---- a/src/kdc/do_tgs_req.c -+++ b/src/kdc/do_tgs_req.c -@@ -500,12 +500,12 @@ process_tgs_req(struct server_handle *handle, krb5_data *pkt, - - old_starttime = enc_tkt_reply.times.starttime ? - enc_tkt_reply.times.starttime : enc_tkt_reply.times.authtime; -- old_life = enc_tkt_reply.times.endtime - old_starttime; -+ old_life = ts_delta(enc_tkt_reply.times.endtime, old_starttime); - - enc_tkt_reply.times.starttime = kdc_time; - enc_tkt_reply.times.endtime = -- min(header_ticket->enc_part2->times.renew_till, -- kdc_time + old_life); -+ ts_min(header_ticket->enc_part2->times.renew_till, -+ ts_incr(kdc_time, old_life)); - } else { - /* not a renew request */ - enc_tkt_reply.times.starttime = kdc_time; -diff --git a/src/kdc/extern.c b/src/kdc/extern.c -index fe627494b..84b5c6ad5 100644 ---- a/src/kdc/extern.c -+++ b/src/kdc/extern.c -@@ -37,6 +37,8 @@ - kdc_realm_t **kdc_realmlist = (kdc_realm_t **) NULL; - int kdc_numrealms = 0; - krb5_data empty_string = {0, 0, ""}; --krb5_timestamp kdc_infinity = KRB5_INT32_MAX; /* XXX */ - krb5_keyblock psr_key; - krb5_int32 max_dgram_reply_size = MAX_DGRAM_SIZE; -+ -+/* With ts_after(), this is the largest timestamp value. */ -+krb5_timestamp kdc_infinity = -1; -diff --git a/src/kdc/fast_util.c b/src/kdc/fast_util.c -index 9df940219..e05107ef3 100644 ---- a/src/kdc/fast_util.c -+++ b/src/kdc/fast_util.c -@@ -607,7 +607,7 @@ kdc_fast_read_cookie(krb5_context context, struct kdc_request_state *state, - ret = krb5_timeofday(context, &now); - if (ret) - goto cleanup; -- if (now - COOKIE_LIFETIME > cookie->time) { -+ if (ts2tt(now) > cookie->time + COOKIE_LIFETIME) { - /* Don't accept the cookie contents. Only return an error if the - * cookie is relevant to the request. */ - if (is_relevant(cookie->data, req->padata)) -@@ -700,7 +700,7 @@ kdc_fast_make_cookie(krb5_context context, struct kdc_request_state *state, - ret = krb5_timeofday(context, &now); - if (ret) - goto cleanup; -- cookie.time = now; -+ cookie.time = ts2tt(now); - cookie.data = contents; - ret = encode_krb5_secure_cookie(&cookie, &der_cookie); - if (ret) -diff --git a/src/kdc/kdc_log.c b/src/kdc/kdc_log.c -index 94a2a1c87..c044a3553 100644 ---- a/src/kdc/kdc_log.c -+++ b/src/kdc/kdc_log.c -@@ -79,9 +79,9 @@ log_as_req(krb5_context context, const krb5_fulladdr *from, - /* success */ - char rep_etypestr[128]; - rep_etypes2str(rep_etypestr, sizeof(rep_etypestr), reply); -- krb5_klog_syslog(LOG_INFO, _("AS_REQ (%s) %s: ISSUE: authtime %d, %s, " -+ krb5_klog_syslog(LOG_INFO, _("AS_REQ (%s) %s: ISSUE: authtime %u, %s, " - "%s for %s"), -- ktypestr, fromstring, authtime, -+ ktypestr, fromstring, (unsigned int)authtime, - rep_etypestr, cname2, sname2); - } else { - /* fail */ -@@ -156,10 +156,10 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from, - name (useful), and doesn't log ktypestr (probably not - important). */ - if (errcode != KRB5KDC_ERR_SERVER_NOMATCH) { -- krb5_klog_syslog(LOG_INFO, _("TGS_REQ (%s) %s: %s: authtime %d, %s%s " -+ krb5_klog_syslog(LOG_INFO, _("TGS_REQ (%s) %s: %s: authtime %u, %s%s " - "%s for %s%s%s"), -- ktypestr, fromstring, status, authtime, rep_etypestr, -- !errcode ? "," : "", logcname, logsname, -+ ktypestr, fromstring, status, (unsigned int)authtime, -+ rep_etypestr, !errcode ? "," : "", logcname, logsname, - errcode ? ", " : "", errcode ? emsg : ""); - if (isflagset(c_flags, KRB5_KDB_FLAG_PROTOCOL_TRANSITION)) - krb5_klog_syslog(LOG_INFO, -@@ -171,9 +171,9 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from, - logaltcname); - - } else -- krb5_klog_syslog(LOG_INFO, _("TGS_REQ %s: %s: authtime %d, %s for %s, " -+ krb5_klog_syslog(LOG_INFO, _("TGS_REQ %s: %s: authtime %u, %s for %s, " - "2nd tkt client %s"), -- fromstring, status, authtime, -+ fromstring, status, (unsigned int)authtime, - logcname, logsname, logaltcname); - - /* OpenSolaris: audit_krb5kdc_tgs_req(...) or -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index 30c501c67..b710aefe4 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -654,7 +654,7 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - } - - /* The client must not be expired */ -- if (client.expiration && client.expiration < kdc_time) { -+ if (client.expiration && ts_after(kdc_time, client.expiration)) { - *status = "CLIENT EXPIRED"; - if (vague_errors) - return(KRB_ERR_GENERIC); -@@ -664,7 +664,7 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - - /* The client's password must not be expired, unless the server is - a KRB5_KDC_PWCHANGE_SERVICE. */ -- if (client.pw_expiration && client.pw_expiration < kdc_time && -+ if (client.pw_expiration && ts_after(kdc_time, client.pw_expiration) && - !isflagset(server.attributes, KRB5_KDB_PWCHANGE_SERVICE)) { - *status = "CLIENT KEY EXPIRED"; - if (vague_errors) -@@ -674,7 +674,7 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - } - - /* The server must not be expired */ -- if (server.expiration && server.expiration < kdc_time) { -+ if (server.expiration && ts_after(kdc_time, server.expiration)) { - *status = "SERVICE EXPIRED"; - return(KDC_ERR_SERVICE_EXP); - } -@@ -1771,9 +1771,9 @@ kdc_get_ticket_endtime(kdc_realm_t *kdc_active_realm, - if (till == 0) - till = kdc_infinity; - -- until = min(till, endtime); -+ until = ts_min(till, endtime); - -- life = until - starttime; -+ life = ts_delta(until, starttime); - - if (client != NULL && client->max_life != 0) - life = min(life, client->max_life); -@@ -1782,7 +1782,7 @@ kdc_get_ticket_endtime(kdc_realm_t *kdc_active_realm, - if (kdc_active_realm->realm_maxlife != 0) - life = min(life, kdc_active_realm->realm_maxlife); - -- *out_endtime = starttime + life; -+ *out_endtime = ts_incr(starttime, life); - } - - /* -@@ -1812,22 +1812,22 @@ kdc_get_ticket_renewtime(kdc_realm_t *realm, krb5_kdc_req *request, - if (isflagset(request->kdc_options, KDC_OPT_RENEWABLE)) - rtime = request->rtime ? request->rtime : kdc_infinity; - else if (isflagset(request->kdc_options, KDC_OPT_RENEWABLE_OK) && -- tkt->times.endtime < request->till) -+ ts_after(request->till, tkt->times.endtime)) - rtime = request->till; - else - return; - - /* Truncate it to the allowable renewable time. */ - if (tgt != NULL) -- rtime = min(rtime, tgt->times.renew_till); -+ rtime = ts_min(rtime, tgt->times.renew_till); - max_rlife = min(server->max_renewable_life, realm->realm_maxrlife); - if (client != NULL) - max_rlife = min(max_rlife, client->max_renewable_life); -- rtime = min(rtime, tkt->times.starttime + max_rlife); -+ rtime = ts_min(rtime, ts_incr(tkt->times.starttime, max_rlife)); - - /* Make the ticket renewable if the truncated requested time is larger than - * the ticket end time. */ -- if (rtime > tkt->times.endtime) { -+ if (ts_after(rtime, tkt->times.endtime)) { - setflag(tkt->flags, TKT_FLG_RENEWABLE); - tkt->times.renew_till = rtime; - } -diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index bcf05fc27..672f94380 100644 ---- a/src/kdc/kdc_util.h -+++ b/src/kdc/kdc_util.h -@@ -452,6 +452,8 @@ struct krb5_kdcpreauth_rock_st { - #define max(a, b) ((a) > (b) ? (a) : (b)) - #endif - -+#define ts_min(a, b) (ts_after(a, b) ? (b) : (a)) -+ - #define ADDRTYPE2FAMILY(X) \ - ((X) == ADDRTYPE_INET6 ? AF_INET6 : (X) == ADDRTYPE_INET ? AF_INET : -1) - -diff --git a/src/kdc/replay.c b/src/kdc/replay.c -index 8da7ac19a..fab39cf88 100644 ---- a/src/kdc/replay.c -+++ b/src/kdc/replay.c -@@ -61,7 +61,7 @@ static size_t total_size = 0; - static krb5_ui_4 seed; - - #define STALE_TIME (2*60) /* two minutes */ --#define STALE(ptr, now) (abs((ptr)->timein - (now)) >= STALE_TIME) -+#define STALE(ptr, now) (labs(ts_delta((ptr)->timein, now)) >= STALE_TIME) - - /* Return x rotated to the left by r bits. */ - static inline krb5_ui_4 -diff --git a/src/kdc/tgs_policy.c b/src/kdc/tgs_policy.c -index a30cacc66..d0f25d1b7 100644 ---- a/src/kdc/tgs_policy.c -+++ b/src/kdc/tgs_policy.c -@@ -186,7 +186,7 @@ static int - check_tgs_svc_time(krb5_kdc_req *req, krb5_db_entry server, krb5_ticket *tkt, - krb5_timestamp kdc_time, const char **status) - { -- if (server.expiration && server.expiration < kdc_time) { -+ if (server.expiration && ts_after(kdc_time, server.expiration)) { - *status = "SERVICE EXPIRED"; - return KDC_ERR_SERVICE_EXP; - } -@@ -222,7 +222,7 @@ check_tgs_times(krb5_kdc_req *req, krb5_ticket_times *times, - KDC time. */ - if (req->kdc_options & KDC_OPT_VALIDATE) { - starttime = times->starttime ? times->starttime : times->authtime; -- if (starttime > kdc_time) { -+ if (ts_after(starttime, kdc_time)) { - *status = "NOT_YET_VALID"; - return KRB_AP_ERR_TKT_NYV; - } -@@ -231,7 +231,8 @@ check_tgs_times(krb5_kdc_req *req, krb5_ticket_times *times, - * Check the renew_till time. The endtime was already - * been checked in the initial authentication check. - */ -- if ((req->kdc_options & KDC_OPT_RENEW) && times->renew_till < kdc_time) { -+ if ((req->kdc_options & KDC_OPT_RENEW) && -+ ts_after(kdc_time, times->renew_till)) { - *status = "TKT_EXPIRED"; - return KRB_AP_ERR_TKT_EXPIRED; - } -diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index 580d08cbf..06967aa27 100644 ---- a/src/lib/gssapi/krb5/accept_sec_context.c -+++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -351,8 +351,10 @@ kg_accept_dce(minor_status, context_handle, verifier_cred_handle, - if (mech_type) - *mech_type = ctx->mech_used; - -- if (time_rec) -- *time_rec = ctx->krb_times.endtime + ctx->k5_context->clockskew - now; -+ if (time_rec) { -+ *time_rec = ts_delta(ctx->krb_times.endtime, now) + -+ ctx->k5_context->clockskew; -+ } - - /* Never return GSS_C_DELEG_FLAG since we don't support DCE credential - * delegation yet. */ -@@ -1146,7 +1148,7 @@ kg_accept_krb5(minor_status, context_handle, - /* Add the maximum allowable clock skew as a grace period for context - * expiration, just as we do for the ticket. */ - if (time_rec) -- *time_rec = ctx->krb_times.endtime + context->clockskew - now; -+ *time_rec = ts_delta(ctx->krb_times.endtime, now) + context->clockskew; - - if (ret_flags) - *ret_flags = ctx->gss_flags; -diff --git a/src/lib/gssapi/krb5/acquire_cred.c b/src/lib/gssapi/krb5/acquire_cred.c -index 03ee25ec1..362ba9d86 100644 ---- a/src/lib/gssapi/krb5/acquire_cred.c -+++ b/src/lib/gssapi/krb5/acquire_cred.c -@@ -550,7 +550,7 @@ set_refresh_time(krb5_context context, krb5_ccache ccache, - char buf[128]; - krb5_data d; - -- snprintf(buf, sizeof(buf), "%ld", (long)refresh_time); -+ snprintf(buf, sizeof(buf), "%u", (unsigned int)ts2tt(refresh_time)); - d = string2data(buf); - (void)krb5_cc_set_config(context, ccache, NULL, KRB5_CC_CONF_REFRESH_TIME, - &d); -@@ -566,8 +566,9 @@ kg_cred_time_to_refresh(krb5_context context, krb5_gss_cred_id_rec *cred) - - if (krb5_timeofday(context, &now)) - return FALSE; -- if (cred->refresh_time != 0 && now >= cred->refresh_time) { -- set_refresh_time(context, cred->ccache, cred->refresh_time + 30); -+ if (cred->refresh_time != 0 && !ts_after(cred->refresh_time, now)) { -+ set_refresh_time(context, cred->ccache, -+ ts_incr(cred->refresh_time, 30)); - return TRUE; - } - return FALSE; -@@ -586,7 +587,8 @@ kg_cred_set_initial_refresh(krb5_context context, krb5_gss_cred_id_rec *cred, - return; - - /* Make a note to refresh these when they are halfway to expired. */ -- refresh = times->starttime + (times->endtime - times->starttime) / 2; -+ refresh = ts_incr(times->starttime, -+ ts_delta(times->endtime, times->starttime) / 2); - set_refresh_time(context, cred->ccache, refresh); - } - -@@ -848,7 +850,8 @@ acquire_cred_context(krb5_context context, OM_uint32 *minor_status, - GSS_C_NO_NAME); - if (GSS_ERROR(ret)) - goto error_out; -- *time_rec = (cred->expire > now) ? (cred->expire - now) : 0; -+ *time_rec = ts_after(cred->expire, now) ? -+ ts_delta(cred->expire, now) : 0; - k5_mutex_unlock(&cred->lock); - } - } -diff --git a/src/lib/gssapi/krb5/context_time.c b/src/lib/gssapi/krb5/context_time.c -index 450593288..1fdb5a16f 100644 ---- a/src/lib/gssapi/krb5/context_time.c -+++ b/src/lib/gssapi/krb5/context_time.c -@@ -51,7 +51,7 @@ krb5_gss_context_time(minor_status, context_handle, time_rec) - return(GSS_S_FAILURE); - } - -- lifetime = ctx->krb_times.endtime - now; -+ lifetime = ts_delta(ctx->krb_times.endtime, now); - if (!ctx->initiate) - lifetime += ctx->k5_context->clockskew; - if (lifetime <= 0) { -diff --git a/src/lib/gssapi/krb5/export_cred.c b/src/lib/gssapi/krb5/export_cred.c -index 652b2604b..8054e4a77 100644 ---- a/src/lib/gssapi/krb5/export_cred.c -+++ b/src/lib/gssapi/krb5/export_cred.c -@@ -410,10 +410,11 @@ json_kgcred(krb5_context context, krb5_gss_cred_id_t cred, - if (ret) - goto cleanup; - -- ret = k5_json_array_fmt(&array, "ivvbbvvvvbiivs", cred->usage, name, imp, -+ ret = k5_json_array_fmt(&array, "ivvbbvvvvbLLvs", cred->usage, name, imp, - cred->default_identity, cred->iakerb_mech, keytab, - rcache, ccache, ckeytab, cred->have_tgt, -- cred->expire, cred->refresh_time, etypes, -+ (long long)ts2tt(cred->expire), -+ (long long)ts2tt(cred->refresh_time), etypes, - cred->password); - if (ret) - goto cleanup; -diff --git a/src/lib/gssapi/krb5/iakerb.c b/src/lib/gssapi/krb5/iakerb.c -index 2dc4d0c1a..bb1072fe4 100644 ---- a/src/lib/gssapi/krb5/iakerb.c -+++ b/src/lib/gssapi/krb5/iakerb.c -@@ -494,7 +494,7 @@ iakerb_tkt_creds_ctx(iakerb_ctx_id_t ctx, - if (code != 0) - goto cleanup; - -- creds.times.endtime = now + time_req; -+ creds.times.endtime = ts_incr(now, time_req); - } - - if (cred->name->ad_context != NULL) { -@@ -669,7 +669,7 @@ iakerb_get_initial_state(iakerb_ctx_id_t ctx, - if (code != 0) - goto cleanup; - -- in_creds.times.endtime = now + time_req; -+ in_creds.times.endtime = ts_incr(now, time_req); - } - - /* Make an AS request if we have no creds or it's time to refresh them. */ -diff --git a/src/lib/gssapi/krb5/init_sec_context.c b/src/lib/gssapi/krb5/init_sec_context.c -index 2a7467f54..1be1b5878 100644 ---- a/src/lib/gssapi/krb5/init_sec_context.c -+++ b/src/lib/gssapi/krb5/init_sec_context.c -@@ -214,7 +214,8 @@ static krb5_error_code get_credentials(context, cred, server, now, - * boundaries) because accept_sec_context code is also similarly - * non-forgiving. - */ -- if (!krb5_gss_dbg_client_expcreds && result_creds->times.endtime < now) { -+ if (!krb5_gss_dbg_client_expcreds && -+ ts_after(now, result_creds->times.endtime)) { - code = KRB5KRB_AP_ERR_TKT_EXPIRED; - goto cleanup; - } -@@ -573,7 +574,7 @@ kg_new_connection( - if (time_req == 0 || time_req == GSS_C_INDEFINITE) { - ctx->krb_times.endtime = 0; - } else { -- ctx->krb_times.endtime = now + time_req; -+ ctx->krb_times.endtime = ts_incr(now, time_req); - } - - if ((code = kg_duplicate_name(context, cred->name, &ctx->here))) -@@ -657,7 +658,7 @@ kg_new_connection( - if (time_rec) { - if ((code = krb5_timeofday(context, &now))) - goto cleanup; -- *time_rec = ctx->krb_times.endtime - now; -+ *time_rec = ts_delta(ctx->krb_times.endtime, now); - } - - /* set the other returns */ -@@ -871,7 +872,7 @@ mutual_auth( - if (time_rec) { - if ((code = krb5_timeofday(context, &now))) - goto fail; -- *time_rec = ctx->krb_times.endtime - now; -+ *time_rec = ts_delta(ctx->krb_times.endtime, now); - } - - if (ret_flags) -diff --git a/src/lib/gssapi/krb5/inq_context.c b/src/lib/gssapi/krb5/inq_context.c -index d2e466e60..cac024da1 100644 ---- a/src/lib/gssapi/krb5/inq_context.c -+++ b/src/lib/gssapi/krb5/inq_context.c -@@ -120,7 +120,7 @@ krb5_gss_inquire_context(minor_status, context_handle, initiator_name, - - /* Add the maximum allowable clock skew as a grace period for context - * expiration, just as we do for the ticket during authentication. */ -- lifetime = ctx->krb_times.endtime - now; -+ lifetime = ts_delta(ctx->krb_times.endtime, now); - if (!ctx->initiate) - lifetime += context->clockskew; - if (lifetime < 0) -diff --git a/src/lib/gssapi/krb5/inq_cred.c b/src/lib/gssapi/krb5/inq_cred.c -index 4e35a0563..e662ae53a 100644 ---- a/src/lib/gssapi/krb5/inq_cred.c -+++ b/src/lib/gssapi/krb5/inq_cred.c -@@ -130,8 +130,9 @@ krb5_gss_inquire_cred(minor_status, cred_handle, name, lifetime_ret, - goto fail; - } - -- if (cred->expire > 0) { -- if ((lifetime = cred->expire - now) < 0) -+ if (cred->expire != 0) { -+ lifetime = ts_delta(cred->expire, now); -+ if (lifetime < 0) - lifetime = 0; - } - else -diff --git a/src/lib/gssapi/krb5/s4u_gss_glue.c b/src/lib/gssapi/krb5/s4u_gss_glue.c -index ff1c310bc..10848c1df 100644 ---- a/src/lib/gssapi/krb5/s4u_gss_glue.c -+++ b/src/lib/gssapi/krb5/s4u_gss_glue.c -@@ -284,7 +284,7 @@ kg_compose_deleg_cred(OM_uint32 *minor_status, - if (code != 0) - goto cleanup; - -- *time_rec = cred->expire - now; -+ *time_rec = ts_delta(cred->expire, now); - } - - major_status = GSS_S_COMPLETE; -diff --git a/src/lib/kadm5/chpass_util.c b/src/lib/kadm5/chpass_util.c -index 408b0eb31..1680a5504 100644 ---- a/src/lib/kadm5/chpass_util.c -+++ b/src/lib/kadm5/chpass_util.c -@@ -4,15 +4,11 @@ - */ - - --#include "autoconf.h" --#include --#include --#include -+#include "k5-int.h" - - #include - #include "admin_internal.h" - --#include - - #define string_text error_message - -@@ -218,7 +214,7 @@ kadm5_ret_t _kadm5_chpass_principal_util(void *server_handle, - time_t until; - char *time_string, *ptr; - -- until = princ_ent.last_pwd_change + policy_ent.pw_min_life; -+ until = ts_incr(princ_ent.last_pwd_change, policy_ent.pw_min_life); - - time_string = ctime(&until); - if (*(ptr = &time_string[strlen(time_string)-1]) == '\n') -diff --git a/src/lib/kadm5/srv/server_acl.c b/src/lib/kadm5/srv/server_acl.c -index 3c2844d14..c4bb16dc7 100644 ---- a/src/lib/kadm5/srv/server_acl.c -+++ b/src/lib/kadm5/srv/server_acl.c -@@ -408,13 +408,14 @@ kadm5int_acl_impose_restrictions(kcontext, recp, maskp, rp) - } - if (rp->mask & KADM5_PRINC_EXPIRE_TIME) { - if (!(*maskp & KADM5_PRINC_EXPIRE_TIME) -- || (recp->princ_expire_time > (now + rp->princ_lifetime))) -+ || ts_after(recp->princ_expire_time, -+ ts_incr(now, rp->princ_lifetime))) - recp->princ_expire_time = now + rp->princ_lifetime; - *maskp |= KADM5_PRINC_EXPIRE_TIME; - } - if (rp->mask & KADM5_PW_EXPIRATION) { - if (!(*maskp & KADM5_PW_EXPIRATION) -- || (recp->pw_expiration > (now + rp->pw_lifetime))) -+ || ts_after(recp->pw_expiration, ts_incr(now, rp->pw_lifetime))) - recp->pw_expiration = now + rp->pw_lifetime; - *maskp |= KADM5_PW_EXPIRATION; - } -diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c -index 8f4da0e52..137e1fb64 100644 ---- a/src/lib/kadm5/srv/svr_principal.c -+++ b/src/lib/kadm5/srv/svr_principal.c -@@ -400,7 +400,7 @@ kadm5_create_principal_3(void *server_handle, - kdb->pw_expiration = 0; - if (have_polent) { - if(polent.pw_max_life) -- kdb->pw_expiration = now + polent.pw_max_life; -+ kdb->pw_expiration = ts_incr(now, polent.pw_max_life); - else - kdb->pw_expiration = 0; - } -@@ -612,7 +612,7 @@ kadm5_modify_principal(void *server_handle, - &(kdb->pw_expiration)); - if (ret) - goto done; -- kdb->pw_expiration += pol.pw_max_life; -+ kdb->pw_expiration = ts_incr(kdb->pw_expiration, pol.pw_max_life); - } else { - kdb->pw_expiration = 0; - } -@@ -1445,7 +1445,7 @@ kadm5_chpass_principal_3(void *server_handle, - } - - if (pol.pw_max_life) -- kdb->pw_expiration = now + pol.pw_max_life; -+ kdb->pw_expiration = ts_incr(now, pol.pw_max_life); - else - kdb->pw_expiration = 0; - } else { -@@ -1624,7 +1624,7 @@ kadm5_randkey_principal_3(void *server_handle, - #endif - - if (pol.pw_max_life) -- kdb->pw_expiration = now + pol.pw_max_life; -+ kdb->pw_expiration = ts_incr(now, pol.pw_max_life); - else - kdb->pw_expiration = 0; - } else { -@@ -1774,7 +1774,7 @@ kadm5_setv4key_principal(void *server_handle, - #endif - - if (pol.pw_max_life) -- kdb->pw_expiration = now + pol.pw_max_life; -+ kdb->pw_expiration = ts_incr(now, pol.pw_max_life); - else - kdb->pw_expiration = 0; - } else { -@@ -2027,7 +2027,7 @@ kadm5_setkey_principal_4(void *server_handle, krb5_principal principal, - } - if (have_pol) { - if (pol.pw_max_life) -- kdb->pw_expiration = now + pol.pw_max_life; -+ kdb->pw_expiration = ts_incr(now, pol.pw_max_life); - else - kdb->pw_expiration = 0; - } else { -diff --git a/src/lib/kdb/kdb5.c b/src/lib/kdb/kdb5.c -index 690725765..07392572e 100644 ---- a/src/lib/kdb/kdb5.c -+++ b/src/lib/kdb/kdb5.c -@@ -1297,7 +1297,7 @@ find_actkvno(krb5_actkvno_node *list, krb5_timestamp now) - * are in the future, we will return the first node; if all are in the - * past, we will return the last node. - */ -- while (list->next != NULL && list->next->act_time <= now) -+ while (list->next != NULL && !ts_after(list->next->act_time, now)) - list = list->next; - return list->act_kvno; - } -diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c -index a827ca608..889460989 100644 ---- a/src/lib/krb5/asn.1/asn1_k_encode.c -+++ b/src/lib/krb5/asn.1/asn1_k_encode.c -@@ -158,8 +158,7 @@ static asn1_error_code - encode_kerberos_time(asn1buf *buf, const void *p, taginfo *rettag, - size_t *len_out) - { -- /* Range checking for time_t vs krb5_timestamp? */ -- time_t val = *(krb5_timestamp *)p; -+ time_t val = ts2tt(*(krb5_timestamp *)p); - rettag->asn1class = UNIVERSAL; - rettag->construction = PRIMITIVE; - rettag->tagnum = ASN1_GENERALTIME; -diff --git a/src/lib/krb5/ccache/cc_keyring.c b/src/lib/krb5/ccache/cc_keyring.c -index 4fe3f0d6f..fba710b1b 100644 ---- a/src/lib/krb5/ccache/cc_keyring.c -+++ b/src/lib/krb5/ccache/cc_keyring.c -@@ -751,7 +751,7 @@ update_keyring_expiration(krb5_context context, krb5_ccache id) - for (;;) { - if (krcc_next_cred(context, id, &cursor, &creds) != 0) - break; -- if (creds.times.endtime > endtime) -+ if (ts_after(creds.times.endtime, endtime)) - endtime = creds.times.endtime; - krb5_free_cred_contents(context, &creds); - } -@@ -765,7 +765,7 @@ update_keyring_expiration(krb5_context context, krb5_ccache id) - - /* Setting the timeout to zero would reset the timeout, so we set it to one - * second instead if creds are already expired. */ -- timeout = (endtime > now) ? endtime - now : 1; -+ timeout = ts_after(endtime, now) ? ts_delta(endtime, now) : 1; - (void)keyctl_set_timeout(data->cache_id, timeout); - } - -@@ -1316,8 +1316,10 @@ krcc_store(krb5_context context, krb5_ccache id, krb5_creds *creds) - if (ret) - goto errout; - -- if (creds->times.endtime > now) -- (void)keyctl_set_timeout(cred_key, creds->times.endtime - now); -+ if (ts_after(creds->times.endtime, now)) { -+ (void)keyctl_set_timeout(cred_key, -+ ts_delta(creds->times.endtime, now)); -+ } - - update_keyring_expiration(context, id); - -@@ -1680,8 +1682,8 @@ static void - krcc_update_change_time(krcc_data *data) - { - krb5_timestamp now_time = time(NULL); -- data->changetime = (data->changetime >= now_time) ? -- data->changetime + 1 : now_time; -+ data->changetime = ts_after(now_time, data->changetime) ? -+ now_time : ts_incr(data->changetime, 1); - } - - /* -diff --git a/src/lib/krb5/ccache/cc_memory.c b/src/lib/krb5/ccache/cc_memory.c -index 0354575c5..c5425eb3a 100644 ---- a/src/lib/krb5/ccache/cc_memory.c -+++ b/src/lib/krb5/ccache/cc_memory.c -@@ -720,8 +720,8 @@ static void - update_mcc_change_time(krb5_mcc_data *d) - { - krb5_timestamp now_time = time(NULL); -- d->changetime = (d->changetime >= now_time) ? -- d->changetime + 1 : now_time; -+ d->changetime = ts_after(now_time, d->changetime) ? -+ now_time : ts_incr(d->changetime, 1); - } - - static krb5_error_code KRB5_CALLCONV -diff --git a/src/lib/krb5/ccache/cc_retr.c b/src/lib/krb5/ccache/cc_retr.c -index 1314d24bd..1a32e00c8 100644 ---- a/src/lib/krb5/ccache/cc_retr.c -+++ b/src/lib/krb5/ccache/cc_retr.c -@@ -46,11 +46,11 @@ static krb5_boolean - times_match(const krb5_ticket_times *t1, const krb5_ticket_times *t2) - { - if (t1->renew_till) { -- if (t1->renew_till > t2->renew_till) -+ if (ts_after(t1->renew_till, t2->renew_till)) - return FALSE; /* this one expires too late */ - } - if (t1->endtime) { -- if (t1->endtime > t2->endtime) -+ if (ts_after(t1->endtime, t2->endtime)) - return FALSE; /* this one expires too late */ - } - /* only care about expiration on a times_match */ -diff --git a/src/lib/krb5/ccache/ccapi/stdcc_util.c b/src/lib/krb5/ccache/ccapi/stdcc_util.c -index 9f44af3d0..6092ee432 100644 ---- a/src/lib/krb5/ccache/ccapi/stdcc_util.c -+++ b/src/lib/krb5/ccache/ccapi/stdcc_util.c -@@ -16,8 +16,8 @@ - #include - #endif - -+#include "k5-int.h" - #include "stdcc_util.h" --#include "krb5.h" - #ifdef _WIN32 /* it's part of krb5.h everywhere else */ - #include "kv5m_err.h" - #endif -@@ -321,10 +321,10 @@ copy_cc_cred_union_to_krb5_creds (krb5_context in_context, - keyblock_contents = NULL; - - /* copy times */ -- out_creds->times.authtime = cv5->authtime + offset_seconds; -- out_creds->times.starttime = cv5->starttime + offset_seconds; -- out_creds->times.endtime = cv5->endtime + offset_seconds; -- out_creds->times.renew_till = cv5->renew_till + offset_seconds; -+ out_creds->times.authtime = ts_incr(cv5->authtime, offset_seconds); -+ out_creds->times.starttime = ts_incr(cv5->starttime, offset_seconds); -+ out_creds->times.endtime = ts_incr(cv5->endtime, offset_seconds); -+ out_creds->times.renew_till = ts_incr(cv5->renew_till, offset_seconds); - out_creds->is_skey = cv5->is_skey; - out_creds->ticket_flags = cv5->ticket_flags; - -@@ -451,11 +451,11 @@ copy_krb5_creds_to_cc_cred_union (krb5_context in_context, - cv5->keyblock.data = keyblock_data; - keyblock_data = NULL; - -- cv5->authtime = in_creds->times.authtime - offset_seconds; -- cv5->starttime = in_creds->times.starttime - offset_seconds; -- cv5->endtime = in_creds->times.endtime - offset_seconds; -- cv5->renew_till = in_creds->times.renew_till - offset_seconds; -- cv5->is_skey = in_creds->is_skey; -+ cv5->authtime = ts_incr(in_creds->times.authtime, -offset_seconds); -+ cv5->starttime = ts_incr(in_creds->times.starttime, -offset_seconds); -+ cv5->endtime = ts_incr(in_creds->times.endtime, -offset_seconds); -+ cv5->renew_till = ts_incr(in_creds->times.renew_till, -offset_seconds); -+ cv5->is_skey = in_creds->is_skey; - cv5->ticket_flags = in_creds->ticket_flags; - - if (in_creds->ticket.data) { -@@ -732,10 +732,10 @@ void dupCCtoK5(krb5_context context, cc_creds *src, krb5_creds *dest) - err = krb5_get_time_offsets(context, &offset_seconds, &offset_microseconds); - if (err) return; - #endif -- dest->times.authtime = src->authtime + offset_seconds; -- dest->times.starttime = src->starttime + offset_seconds; -- dest->times.endtime = src->endtime + offset_seconds; -- dest->times.renew_till = src->renew_till + offset_seconds; -+ dest->times.authtime = ts_incr(src->authtime, offset_seconds); -+ dest->times.starttime = ts_incr(src->starttime, offset_seconds); -+ dest->times.endtime = ts_incr(src->endtime, offset_seconds); -+ dest->times.renew_till = ts_incr(src->renew_till, offset_seconds); - dest->is_skey = src->is_skey; - dest->ticket_flags = src->ticket_flags; - -@@ -804,10 +804,10 @@ void dupK5toCC(krb5_context context, krb5_creds *creds, cred_union **cu) - err = krb5_get_time_offsets(context, &offset_seconds, &offset_microseconds); - if (err) return; - #endif -- c->authtime = creds->times.authtime - offset_seconds; -- c->starttime = creds->times.starttime - offset_seconds; -- c->endtime = creds->times.endtime - offset_seconds; -- c->renew_till = creds->times.renew_till - offset_seconds; -+ c->authtime = ts_incr(creds->times.authtime, -offset_seconds); -+ c->starttime = ts_incr(creds->times.starttime, -offset_seconds); -+ c->endtime = ts_incr(creds->times.endtime, -offset_seconds); -+ c->renew_till = ts_incr(creds->times.renew_till, -offset_seconds); - c->is_skey = creds->is_skey; - c->ticket_flags = creds->ticket_flags; - -@@ -925,11 +925,11 @@ times_match(t1, t2) - register const krb5_ticket_times *t2; - { - if (t1->renew_till) { -- if (t1->renew_till > t2->renew_till) -+ if (ts_after(t1->renew_till, t2->renew_till)) - return FALSE; /* this one expires too late */ - } - if (t1->endtime) { -- if (t1->endtime > t2->endtime) -+ if (ts_after(t1->endtime, t2->endtime)) - return FALSE; /* this one expires too late */ - } - /* only care about expiration on a times_match */ -diff --git a/src/lib/krb5/ccache/cccursor.c b/src/lib/krb5/ccache/cccursor.c -index c31a3f5f0..e631f2051 100644 ---- a/src/lib/krb5/ccache/cccursor.c -+++ b/src/lib/krb5/ccache/cccursor.c -@@ -159,7 +159,7 @@ krb5_cccol_last_change_time(krb5_context context, - ret = krb5_cccol_cursor_next(context, c, &ccache); - if (ccache) { - ret = krb5_cc_last_change_time(context, ccache, &last_time); -- if (!ret && last_time > max_change_time) { -+ if (!ret && ts_after(last_time, max_change_time)) { - max_change_time = last_time; - } - ret = 0; -diff --git a/src/lib/krb5/keytab/kt_file.c b/src/lib/krb5/keytab/kt_file.c -index 674d88bab..76efb71c6 100644 ---- a/src/lib/krb5/keytab/kt_file.c -+++ b/src/lib/krb5/keytab/kt_file.c -@@ -264,9 +264,11 @@ more_recent(const krb5_keytab_entry *k1, const krb5_keytab_entry *k2) - * limitations (8-bit kvno storage), pre-1.14 kadmin protocol limitations - * (8-bit kvno marshalling), or KDB limitations (16-bit kvno storage). - */ -- if (k1->timestamp >= k2->timestamp && k1->vno < 128 && k2->vno > 240) -+ if (!ts_after(k2->timestamp, k1->timestamp) && -+ k1->vno < 128 && k2->vno > 240) - return TRUE; -- if (k1->timestamp <= k2->timestamp && k1->vno > 240 && k2->vno < 128) -+ if (!ts_after(k1->timestamp, k2->timestamp) && -+ k1->vno > 240 && k2->vno < 128) - return FALSE; - - /* Otherwise do a simple version comparison. */ -diff --git a/src/lib/krb5/krb/gc_via_tkt.c b/src/lib/krb5/krb/gc_via_tkt.c -index c85d8b8d8..cf1ea361f 100644 ---- a/src/lib/krb5/krb/gc_via_tkt.c -+++ b/src/lib/krb5/krb/gc_via_tkt.c -@@ -287,18 +287,19 @@ krb5int_process_tgs_reply(krb5_context context, - retval = KRB5_KDCREP_MODIFIED; - - if ((in_cred->times.endtime != 0) && -- (dec_rep->enc_part2->times.endtime > in_cred->times.endtime)) -+ ts_after(dec_rep->enc_part2->times.endtime, in_cred->times.endtime)) - retval = KRB5_KDCREP_MODIFIED; - - if ((kdcoptions & KDC_OPT_RENEWABLE) && - (in_cred->times.renew_till != 0) && -- (dec_rep->enc_part2->times.renew_till > in_cred->times.renew_till)) -+ ts_after(dec_rep->enc_part2->times.renew_till, -+ in_cred->times.renew_till)) - retval = KRB5_KDCREP_MODIFIED; - - if ((kdcoptions & KDC_OPT_RENEWABLE_OK) && - (dec_rep->enc_part2->flags & KDC_OPT_RENEWABLE) && - (in_cred->times.endtime != 0) && -- (dec_rep->enc_part2->times.renew_till > in_cred->times.endtime)) -+ ts_after(dec_rep->enc_part2->times.renew_till, in_cred->times.endtime)) - retval = KRB5_KDCREP_MODIFIED; - - if (retval != 0) -diff --git a/src/lib/krb5/krb/get_creds.c b/src/lib/krb5/krb/get_creds.c -index 110abeb2b..be5b2d18c 100644 ---- a/src/lib/krb5/krb/get_creds.c -+++ b/src/lib/krb5/krb/get_creds.c -@@ -816,7 +816,7 @@ get_cached_local_tgt(krb5_context context, krb5_tkt_creds_context ctx, - return code; - - /* Check if the TGT is expired before bothering the KDC with it. */ -- if (now > tgt->times.endtime) { -+ if (ts_after(now, tgt->times.endtime)) { - krb5_free_creds(context, tgt); - return KRB5KRB_AP_ERR_TKT_EXPIRED; - } -diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c -index a058f5bd7..40aba1905 100644 ---- a/src/lib/krb5/krb/get_in_tkt.c -+++ b/src/lib/krb5/krb/get_in_tkt.c -@@ -39,24 +39,6 @@ static krb5_error_code sort_krb5_padata_sequence(krb5_context context, - krb5_data *realm, - krb5_pa_data **padata); - --/* -- * This function performs 32 bit bounded addition so we can generate -- * lifetimes without overflowing krb5_int32 -- */ --static krb5_int32 --krb5int_addint32 (krb5_int32 x, krb5_int32 y) --{ -- if ((x > 0) && (y > (KRB5_INT32_MAX - x))) { -- /* sum will be be greater than KRB5_INT32_MAX */ -- return KRB5_INT32_MAX; -- } else if ((x < 0) && (y < (KRB5_INT32_MIN - x))) { -- /* sum will be less than KRB5_INT32_MIN */ -- return KRB5_INT32_MIN; -- } -- -- return x + y; --} -- - /* - * Decrypt the AS reply in ctx, populating ctx->reply->enc_part2. If - * strengthen_key is not null, combine it with the reply key as specified in -@@ -267,21 +249,21 @@ verify_as_reply(krb5_context context, - (request->from != 0) && - (request->from != as_reply->enc_part2->times.starttime)) - || ((request->till != 0) && -- (as_reply->enc_part2->times.endtime > request->till)) -+ ts_after(as_reply->enc_part2->times.endtime, request->till)) - || ((request->kdc_options & KDC_OPT_RENEWABLE) && - (request->rtime != 0) && -- (as_reply->enc_part2->times.renew_till > request->rtime)) -+ ts_after(as_reply->enc_part2->times.renew_till, request->rtime)) - || ((request->kdc_options & KDC_OPT_RENEWABLE_OK) && - !(request->kdc_options & KDC_OPT_RENEWABLE) && - (as_reply->enc_part2->flags & KDC_OPT_RENEWABLE) && - (request->till != 0) && -- (as_reply->enc_part2->times.renew_till > request->till)) -+ ts_after(as_reply->enc_part2->times.renew_till, request->till)) - ) { - return KRB5_KDCREP_MODIFIED; - } - - if (context->library_options & KRB5_LIBOPT_SYNC_KDCTIME) { -- time_offset = as_reply->enc_part2->times.authtime - time_now; -+ time_offset = ts_delta(as_reply->enc_part2->times.authtime, time_now); - retval = krb5_set_time_offsets(context, time_offset, 0); - if (retval) - return retval; -@@ -790,15 +772,15 @@ set_request_times(krb5_context context, krb5_init_creds_context ctx) - return code; - - /* Omit request start time unless the caller explicitly asked for one. */ -- from = krb5int_addint32(now, ctx->start_time); -+ from = ts_incr(now, ctx->start_time); - if (ctx->start_time != 0) - ctx->request->from = from; - -- ctx->request->till = krb5int_addint32(from, ctx->tkt_life); -+ ctx->request->till = ts_incr(from, ctx->tkt_life); - - if (ctx->renew_life > 0) { - /* Don't ask for a smaller renewable time than the lifetime. */ -- ctx->request->rtime = krb5int_addint32(from, ctx->renew_life); -+ ctx->request->rtime = ts_incr(from, ctx->renew_life); - if (ctx->request->rtime < ctx->request->till) - ctx->request->rtime = ctx->request->till; - ctx->request->kdc_options &= ~KDC_OPT_RENEWABLE_OK; -@@ -1438,7 +1420,7 @@ note_req_timestamp(krb5_context context, krb5_init_creds_context ctx, - - if (k5_time_with_offset(0, 0, &now, &usec) != 0) - return; -- ctx->pa_offset = kdc_time - now; -+ ctx->pa_offset = ts_delta(kdc_time, now); - ctx->pa_offset_usec = kdc_usec - usec; - ctx->pa_offset_state = (ctx->fast_state->armor_key != NULL) ? - AUTH_OFFSET : UNAUTH_OFFSET; -@@ -1807,6 +1789,7 @@ k5_populate_gic_opt(krb5_context context, krb5_get_init_creds_opt **out, - { - int i; - krb5_int32 starttime; -+ krb5_deltat lifetime; - krb5_get_init_creds_opt *opt; - krb5_error_code retval; - -@@ -1838,7 +1821,8 @@ k5_populate_gic_opt(krb5_context context, krb5_get_init_creds_opt **out, - if (retval) - goto cleanup; - if (creds->times.starttime) starttime = creds->times.starttime; -- krb5_get_init_creds_opt_set_tkt_life(opt, creds->times.endtime - starttime); -+ lifetime = ts_delta(creds->times.endtime, starttime); -+ krb5_get_init_creds_opt_set_tkt_life(opt, lifetime); - } - *out = opt; - return 0; -diff --git a/src/lib/krb5/krb/gic_pwd.c b/src/lib/krb5/krb/gic_pwd.c -index 6f3a29f2c..3565a7c4c 100644 ---- a/src/lib/krb5/krb/gic_pwd.c -+++ b/src/lib/krb5/krb/gic_pwd.c -@@ -211,7 +211,7 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, - if (ret != 0) - return; - if (!is_last_req && -- (pw_exp < now || (pw_exp - now) > 7 * 24 * 60 * 60)) -+ (ts_after(now, pw_exp) || ts_delta(pw_exp, now) > 7 * 24 * 60 * 60)) - return; - - if (!prompter) -@@ -221,7 +221,7 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, - if (ret != 0) - return; - -- delta = pw_exp - now; -+ delta = ts_delta(pw_exp, now); - if (delta < 3600) { - snprintf(banner, sizeof(banner), - _("Warning: Your password will expire in less than one hour " -diff --git a/src/lib/krb5/krb/int-proto.h b/src/lib/krb5/krb/int-proto.h -index 44eca359f..48bd9f8f7 100644 ---- a/src/lib/krb5/krb/int-proto.h -+++ b/src/lib/krb5/krb/int-proto.h -@@ -84,7 +84,7 @@ krb5int_construct_matching_creds(krb5_context context, krb5_flags options, - krb5_flags *fields); - - #define in_clock_skew(context, date, now) \ -- (labs((date) - (now)) < (context)->clockskew) -+ (labs(ts_delta(date, now)) < (context)->clockskew) - - #define IS_TGS_PRINC(p) ((p)->length == 2 && \ - data_eq_string((p)->data[0], KRB5_TGS_NAME)) -diff --git a/src/lib/krb5/krb/pac.c b/src/lib/krb5/krb/pac.c -index 9098927b5..c70585a9e 100644 ---- a/src/lib/krb5/krb/pac.c -+++ b/src/lib/krb5/krb/pac.c -@@ -378,7 +378,7 @@ k5_time_to_seconds_since_1970(int64_t ntTime, krb5_timestamp *elapsedSeconds) - - abstime = ntTime > 0 ? ntTime - NT_TIME_EPOCH : -ntTime; - -- if (abstime > KRB5_INT32_MAX) -+ if (abstime > UINT32_MAX) - return ERANGE; - - *elapsedSeconds = abstime; -diff --git a/src/lib/krb5/krb/str_conv.c b/src/lib/krb5/krb/str_conv.c -index 3ab7eacac..f0a2ae20b 100644 ---- a/src/lib/krb5/krb/str_conv.c -+++ b/src/lib/krb5/krb/str_conv.c -@@ -207,7 +207,7 @@ krb5_error_code KRB5_CALLCONV - krb5_timestamp_to_string(krb5_timestamp timestamp, char *buffer, size_t buflen) - { - size_t ret; -- time_t timestamp2 = timestamp; -+ time_t timestamp2 = ts2tt(timestamp); - struct tm tmbuf; - const char *fmt = "%c"; /* This is to get around gcc -Wall warning that - the year returned might be two digits */ -@@ -229,7 +229,7 @@ krb5_timestamp_to_sfstring(krb5_timestamp timestamp, char *buffer, size_t buflen - struct tm *tmp; - size_t i; - size_t ndone; -- time_t timestamp2 = timestamp; -+ time_t timestamp2 = ts2tt(timestamp); - struct tm tmbuf; - - static const char * const sftime_format_table[] = { -diff --git a/src/lib/krb5/krb/t_kerb.c b/src/lib/krb5/krb/t_kerb.c -index 60cfb5b15..74ac14d9a 100644 ---- a/src/lib/krb5/krb/t_kerb.c -+++ b/src/lib/krb5/krb/t_kerb.c -@@ -5,16 +5,8 @@ - */ - - #include "autoconf.h" --#include "krb5.h" --#include --#include --#include --#include -+#include "k5-int.h" - #include --#include --#include --#include --#include - - #include "com_err.h" - -@@ -37,7 +29,7 @@ test_string_to_timestamp(krb5_context ctx, char *ktime) - com_err("krb5_string_to_timestamp", retval, 0); - return; - } -- t = (time_t) timestamp; -+ t = ts2tt(timestamp); - printf("Parsed time was %s", ctime(&t)); - } - -diff --git a/src/lib/krb5/krb/valid_times.c b/src/lib/krb5/krb/valid_times.c -index d63122183..9e509b2dd 100644 ---- a/src/lib/krb5/krb/valid_times.c -+++ b/src/lib/krb5/krb/valid_times.c -@@ -47,10 +47,10 @@ krb5int_validate_times(krb5_context context, krb5_ticket_times *times) - else - starttime = times->authtime; - -- if (starttime - currenttime > context->clockskew) -+ if (ts_delta(starttime, currenttime) > context->clockskew) - return KRB5KRB_AP_ERR_TKT_NYV; /* ticket not yet valid */ - -- if ((currenttime - times->endtime) > context->clockskew) -+ if (ts_delta(currenttime, times->endtime) > context->clockskew) - return KRB5KRB_AP_ERR_TKT_EXPIRED; /* ticket expired */ - - return 0; -diff --git a/src/lib/krb5/krb/vfy_increds.c b/src/lib/krb5/krb/vfy_increds.c -index 9786d63b5..b4878ba38 100644 ---- a/src/lib/krb5/krb/vfy_increds.c -+++ b/src/lib/krb5/krb/vfy_increds.c -@@ -120,7 +120,7 @@ get_vfy_cred(krb5_context context, krb5_creds *creds, krb5_principal server, - ret = krb5_timeofday(context, &in_creds.times.endtime); - if (ret) - goto cleanup; -- in_creds.times.endtime += 5*60; -+ in_creds.times.endtime = ts_incr(in_creds.times.endtime, 5 * 60); - ret = krb5_get_credentials(context, 0, ccache, &in_creds, &out_creds); - if (ret) - goto cleanup; -diff --git a/src/lib/krb5/os/timeofday.c b/src/lib/krb5/os/timeofday.c -index fddb12142..887f24c22 100644 ---- a/src/lib/krb5/os/timeofday.c -+++ b/src/lib/krb5/os/timeofday.c -@@ -60,7 +60,7 @@ krb5_check_clockskew(krb5_context context, krb5_timestamp date) - retval = krb5_timeofday(context, ¤ttime); - if (retval) - return retval; -- if (!(labs((date)-currenttime) < context->clockskew)) -+ if (labs(ts_delta(date, currenttime)) >= context->clockskew) - return KRB5KRB_AP_ERR_SKEW; - - return 0; -diff --git a/src/lib/krb5/os/toffset.c b/src/lib/krb5/os/toffset.c -index 456193a41..37bc69f49 100644 ---- a/src/lib/krb5/os/toffset.c -+++ b/src/lib/krb5/os/toffset.c -@@ -47,7 +47,7 @@ krb5_set_real_time(krb5_context context, krb5_timestamp seconds, krb5_int32 micr - if (retval) - return retval; - -- os_ctx->time_offset = seconds - sec; -+ os_ctx->time_offset = ts_delta(seconds, sec); - os_ctx->usec_offset = (microseconds > -1) ? microseconds - usec : 0; - - os_ctx->os_flags = ((os_ctx->os_flags & ~KRB5_OS_TOFFSET_TIME) | -diff --git a/src/lib/krb5/os/ustime.c b/src/lib/krb5/os/ustime.c -index 056357683..1c1b571eb 100644 ---- a/src/lib/krb5/os/ustime.c -+++ b/src/lib/krb5/os/ustime.c -@@ -49,13 +49,13 @@ k5_time_with_offset(krb5_timestamp offset, krb5_int32 offset_usec, - usec += offset_usec; - if (usec > 1000000) { - usec -= 1000000; -- sec++; -+ sec = ts_incr(sec, 1); - } - if (usec < 0) { - usec += 1000000; -- sec--; -+ sec = ts_incr(sec, -1); - } -- sec += offset; -+ sec = ts_incr(sec, offset); - - *time_out = sec; - *usec_out = usec; -diff --git a/src/lib/krb5/rcache/rc_dfl.c b/src/lib/krb5/rcache/rc_dfl.c -index c0f12ed9d..6b043844d 100644 ---- a/src/lib/krb5/rcache/rc_dfl.c -+++ b/src/lib/krb5/rcache/rc_dfl.c -@@ -97,8 +97,7 @@ alive(krb5_int32 mytime, krb5_donot_replay *new1, krb5_deltat t) - { - if (mytime == 0) - return CMP_HOHUM; /* who cares? */ -- /* I hope we don't have to worry about overflow */ -- if (new1->ctime + t < mytime) -+ if (ts_after(mytime, ts_incr(new1->ctime, t))) - return CMP_EXPIRED; - return CMP_HOHUM; - } -diff --git a/src/lib/krb5/rcache/t_replay.c b/src/lib/krb5/rcache/t_replay.c -index db273ec2f..b99cdf1ab 100644 ---- a/src/lib/krb5/rcache/t_replay.c -+++ b/src/lib/krb5/rcache/t_replay.c -@@ -110,7 +110,7 @@ store(krb5_context ctx, char *rcspec, char *client, char *server, char *msg, - krb5_donot_replay rep; - krb5_data d; - -- if (now_timestamp > 0) -+ if (now_timestamp != 0) - krb5_set_debugging_time(ctx, now_timestamp, now_usec); - if ((retval = krb5_rc_resolve_full(ctx, &rc, rcspec))) - goto cleanup; -@@ -221,13 +221,13 @@ main(int argc, char **argv) - msg = (**argv) ? *argv : NULL; - argc--; argv++; - if (!argc) usage(progname); -- timestamp = (krb5_timestamp) atol(*argv); -+ timestamp = (krb5_timestamp) atoll(*argv); - argc--; argv++; - if (!argc) usage(progname); - usec = (krb5_int32) atol(*argv); - argc--; argv++; - if (!argc) usage(progname); -- now_timestamp = (krb5_timestamp) atol(*argv); -+ now_timestamp = (krb5_timestamp) atoll(*argv); - argc--; argv++; - if (!argc) usage(progname); - now_usec = (krb5_int32) atol(*argv); -@@ -249,7 +249,7 @@ main(int argc, char **argv) - rcspec = *argv; - argc--; argv++; - if (!argc) usage(progname); -- now_timestamp = (krb5_timestamp) atol(*argv); -+ now_timestamp = (krb5_timestamp) atoll(*argv); - argc--; argv++; - if (!argc) usage(progname); - now_usec = (krb5_int32) atol(*argv); -diff --git a/src/plugins/kdb/db2/lockout.c b/src/plugins/kdb/db2/lockout.c -index 7d151b55b..3a4f41821 100644 ---- a/src/plugins/kdb/db2/lockout.c -+++ b/src/plugins/kdb/db2/lockout.c -@@ -100,7 +100,7 @@ locked_check_p(krb5_context context, - - /* If the entry was unlocked since the last failure, it's not locked. */ - if (krb5_dbe_lookup_last_admin_unlock(context, entry, &unlock_time) == 0 && -- entry->last_failed <= unlock_time) -+ !ts_after(entry->last_failed, unlock_time)) - return FALSE; - - if (max_fail == 0 || entry->fail_auth_count < max_fail) -@@ -109,7 +109,7 @@ locked_check_p(krb5_context context, - if (lockout_duration == 0) - return TRUE; /* principal permanently locked */ - -- return (stamp < entry->last_failed + lockout_duration); -+ return ts_after(ts_incr(entry->last_failed, lockout_duration), stamp); - } - - krb5_error_code -@@ -200,13 +200,13 @@ krb5_db2_lockout_audit(krb5_context context, - status == KRB5KRB_AP_ERR_BAD_INTEGRITY)) { - if (krb5_dbe_lookup_last_admin_unlock(context, entry, - &unlock_time) == 0 && -- entry->last_failed <= unlock_time) { -+ !ts_after(entry->last_failed, unlock_time)) { - /* Reset fail_auth_count after administrative unlock. */ - entry->fail_auth_count = 0; - } - - if (failcnt_interval != 0 && -- stamp > entry->last_failed + failcnt_interval) { -+ ts_after(stamp, ts_incr(entry->last_failed, failcnt_interval))) { - /* Reset fail_auth_count after failcnt_interval. */ - entry->fail_auth_count = 0; - } -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -index 7ba53f959..88a170495 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -@@ -1734,7 +1734,7 @@ getstringtime(krb5_timestamp epochtime) - { - struct tm tme; - char *strtime=NULL; -- time_t posixtime = epochtime; -+ time_t posixtime = ts2tt(epochtime); - - strtime = calloc (50, 1); - if (strtime == NULL) -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/lockout.c b/src/plugins/kdb/ldap/libkdb_ldap/lockout.c -index 0fc56c2fe..1088ecc5a 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/lockout.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/lockout.c -@@ -93,7 +93,7 @@ locked_check_p(krb5_context context, - - /* If the entry was unlocked since the last failure, it's not locked. */ - if (krb5_dbe_lookup_last_admin_unlock(context, entry, &unlock_time) == 0 && -- entry->last_failed <= unlock_time) -+ !ts_after(entry->last_failed, unlock_time)) - return FALSE; - - if (max_fail == 0 || entry->fail_auth_count < max_fail) -@@ -102,7 +102,7 @@ locked_check_p(krb5_context context, - if (lockout_duration == 0) - return TRUE; /* principal permanently locked */ - -- return (stamp < entry->last_failed + lockout_duration); -+ return ts_after(ts_incr(entry->last_failed, lockout_duration), stamp); - } - - krb5_error_code -@@ -196,14 +196,14 @@ krb5_ldap_lockout_audit(krb5_context context, - status == KRB5KRB_AP_ERR_BAD_INTEGRITY)) { - if (krb5_dbe_lookup_last_admin_unlock(context, entry, - &unlock_time) == 0 && -- entry->last_failed <= unlock_time) { -+ !ts_after(entry->last_failed, unlock_time)) { - /* Reset fail_auth_count after administrative unlock. */ - entry->fail_auth_count = 0; - entry->mask |= KADM5_FAIL_AUTH_COUNT; - } - - if (failcnt_interval != 0 && -- stamp > entry->last_failed + failcnt_interval) { -+ ts_after(stamp, ts_incr(entry->last_failed, failcnt_interval))) { - /* Reset fail_auth_count after failcnt_interval */ - entry->fail_auth_count = 0; - entry->mask |= KADM5_FAIL_AUTH_COUNT; -diff --git a/src/windows/cns/tktlist.c b/src/windows/cns/tktlist.c -index f2805f5cd..26e699fae 100644 ---- a/src/windows/cns/tktlist.c -+++ b/src/windows/cns/tktlist.c -@@ -35,6 +35,8 @@ - #include "cns.h" - #include "tktlist.h" - -+#define ts2tt(t) (time_t)(uint32_t)(t) -+ - /* - * Ticket information for a list line - */ -@@ -167,10 +169,10 @@ ticket_init_list (HWND hwnd) - - ncred++; - strcpy (buf, " "); -- strncat(buf, short_date (c.times.starttime - kwin_get_epoch()), -+ strncat(buf, short_date(ts2tt(c.times.starttime) - kwin_get_epoch()), - sizeof(buf) - 1 - strlen(buf)); - strncat(buf, " ", sizeof(buf) - 1 - strlen(buf)); -- strncat(buf, short_date (c.times.endtime - kwin_get_epoch()), -+ strncat(buf, short_date(ts2tt(c.times.endtime) - kwin_get_epoch()), - sizeof(buf) - 1 - strlen(buf)); - strncat(buf, " ", sizeof(buf) - 1 - strlen(buf)); - -@@ -192,8 +194,8 @@ ticket_init_list (HWND hwnd) - return -1; - - lpinfo->ticket = TRUE; -- lpinfo->issue_time = c.times.starttime - kwin_get_epoch(); -- lpinfo->lifetime = c.times.endtime - c.times.starttime; -+ lpinfo->issue_time = ts2tt(c.times.starttime) - kwin_get_epoch(); -+ lpinfo->lifetime = ts2tt(c.times.endtime) - c.times.starttime; - strcpy(lpinfo->buf, buf); - - rc = ListBox_AddItemData(hwnd, lpinfo); -diff --git a/src/windows/include/leashwin.h b/src/windows/include/leashwin.h -index 9577365a7..325dce2e9 100644 ---- a/src/windows/include/leashwin.h -+++ b/src/windows/include/leashwin.h -@@ -111,9 +111,9 @@ struct TicketList { - TicketList *next; - char *service; - char *encTypes; -- krb5_timestamp issued; -- krb5_timestamp valid_until; -- krb5_timestamp renew_until; -+ time_t issued; -+ time_t valid_until; -+ time_t renew_until; - unsigned long flags; - }; - -@@ -124,9 +124,9 @@ struct TICKETINFO { - char *ccache_name; - TicketList *ticket_list; - int btickets; /* Do we have tickets? */ -- long issued; /* The issue time */ -- long valid_until; /* */ -- long renew_until; /* The Renew time (k5 only) */ -+ time_t issued; /* The issue time */ -+ time_t valid_until; /* */ -+ time_t renew_until; /* The Renew time (k5 only) */ - unsigned long flags; - }; - -diff --git a/src/windows/leash/KrbListTickets.cpp b/src/windows/leash/KrbListTickets.cpp -index beab0ea11..5dd37b05a 100644 ---- a/src/windows/leash/KrbListTickets.cpp -+++ b/src/windows/leash/KrbListTickets.cpp -@@ -92,10 +92,10 @@ etype_string(krb5_enctype enctype) - static void - CredToTicketInfo(krb5_creds KRBv5Credentials, TICKETINFO *ticketinfo) - { -- ticketinfo->issued = KRBv5Credentials.times.starttime; -- ticketinfo->valid_until = KRBv5Credentials.times.endtime; -+ ticketinfo->issued = (DWORD)KRBv5Credentials.times.starttime; -+ ticketinfo->valid_until = (DWORD)KRBv5Credentials.times.endtime; - ticketinfo->renew_until = KRBv5Credentials.ticket_flags & TKT_FLG_RENEWABLE ? -- KRBv5Credentials.times.renew_till : 0; -+ (DWORD)KRBv5Credentials.times.renew_till : (DWORD)0; - _tzset(); - if ( ticketinfo->valid_until - time(0) <= 0L ) - ticketinfo->btickets = EXPD_TICKETS; -@@ -137,10 +137,10 @@ CredToTicketList(krb5_context ctx, krb5_creds KRBv5Credentials, - functionName = "calloc()"; - goto cleanup; - } -- list->issued = KRBv5Credentials.times.starttime; -- list->valid_until = KRBv5Credentials.times.endtime; -+ list->issued = (DWORD)KRBv5Credentials.times.starttime; -+ list->valid_until = (DWORD)KRBv5Credentials.times.endtime; - if (KRBv5Credentials.ticket_flags & TKT_FLG_RENEWABLE) -- list->renew_until = KRBv5Credentials.times.renew_till; -+ list->renew_until = (DWORD)KRBv5Credentials.times.renew_till; - else - list->renew_until = 0; - -diff --git a/src/windows/leash/LeashView.cpp b/src/windows/leash/LeashView.cpp -index ef2a5a3e0..253ae3f06 100644 ---- a/src/windows/leash/LeashView.cpp -+++ b/src/windows/leash/LeashView.cpp -@@ -229,22 +229,22 @@ static HFONT CreateBoldItalicFont(HFONT font) - - bool change_icon_size = true; - --void krb5TimestampToFileTime(krb5_timestamp t, LPFILETIME pft) -+void TimestampToFileTime(time_t t, LPFILETIME pft) - { - // Note that LONGLONG is a 64-bit value -- LONGLONG ll; -+ ULONGLONG ll; - -- ll = Int32x32To64(t, 10000000) + 116444736000000000; -+ ll = UInt32x32To64((DWORD)t, 10000000) + 116444736000000000; - pft->dwLowDateTime = (DWORD)ll; - pft->dwHighDateTime = ll >> 32; - } - - // allocate outstr --void krb5TimestampToLocalizedString(krb5_timestamp t, LPTSTR *outStr) -+void TimestampToLocalizedString(time_t t, LPTSTR *outStr) - { - FILETIME ft, lft; - SYSTEMTIME st; -- krb5TimestampToFileTime(t, &ft); -+ TimestampToFileTime(t, &ft); - FileTimeToLocalFileTime(&ft, &lft); - FileTimeToSystemTime(&lft, &st); - TCHAR timeFormat[80]; // 80 is max required for LOCALE_STIMEFORMAT -@@ -1125,9 +1125,9 @@ void CLeashView::AddDisplayItem(CListCtrl &list, - CCacheDisplayData *elem, - int iItem, - char *principal, -- long issued, -- long valid_until, -- long renew_until, -+ time_t issued, -+ time_t valid_until, -+ time_t renew_until, - char *encTypes, - unsigned long flags, - char *ccache_name) -@@ -1145,7 +1145,7 @@ void CLeashView::AddDisplayItem(CListCtrl &list, - if (issued == 0) { - list.SetItemText(iItem, iSubItem++, "Unknown"); - } else { -- krb5TimestampToLocalizedString(issued, &localTimeStr); -+ TimestampToLocalizedString(issued, &localTimeStr); - list.SetItemText(iItem, iSubItem++, localTimeStr); - } - } -@@ -1155,7 +1155,7 @@ void CLeashView::AddDisplayItem(CListCtrl &list, - } else if (valid_until < now) { - list.SetItemText(iItem, iSubItem++, "Expired"); - } else if (renew_until) { -- krb5TimestampToLocalizedString(renew_until, &localTimeStr); -+ TimestampToLocalizedString(renew_until, &localTimeStr); - DurationToString(renew_until - now, &durationStr); - if (localTimeStr && durationStr) { - _snprintf(tempStr, MAX_DURATION_STR, "%s %s", localTimeStr, durationStr); -@@ -1172,7 +1172,7 @@ void CLeashView::AddDisplayItem(CListCtrl &list, - } else if (valid_until < now) { - list.SetItemText(iItem, iSubItem++, "Expired"); - } else { -- krb5TimestampToLocalizedString(valid_until, &localTimeStr); -+ TimestampToLocalizedString(valid_until, &localTimeStr); - DurationToString(valid_until - now, &durationStr); - if (localTimeStr && durationStr) { - _snprintf(tempStr, MAX_DURATION_STR, "%s %s", localTimeStr, durationStr); -diff --git a/src/windows/leashdll/lshfunc.c b/src/windows/leashdll/lshfunc.c -index 0f76cc334..8dafb7bed 100644 ---- a/src/windows/leashdll/lshfunc.c -+++ b/src/windows/leashdll/lshfunc.c -@@ -2898,7 +2898,7 @@ static BOOL cc_have_tickets(krb5_context ctx, krb5_ccache cache) - _tzset(); - while (!(code = pkrb5_cc_next_cred(ctx, cache, &cur, &creds))) { - if ((!pkrb5_is_config_principal(ctx, creds.server)) && -- (creds.times.endtime - time(0) > 0)) -+ ((time_t)(DWORD)creds.times.endtime - time(0) > 0)) - have_tickets = TRUE; - - pkrb5_free_cred_contents(ctx, &creds); -diff --git a/src/windows/ms2mit/ms2mit.c b/src/windows/ms2mit/ms2mit.c -index c3325034a..2b4373cc1 100644 ---- a/src/windows/ms2mit/ms2mit.c -+++ b/src/windows/ms2mit/ms2mit.c -@@ -74,7 +74,7 @@ cc_has_tickets(krb5_context kcontext, krb5_ccache ccache, int *has_tickets) - break; - - if (!krb5_is_config_principal(kcontext, creds.server) && -- creds.times.endtime > now) -+ ts_after(creds.times.endtime, now)) - *has_tickets = 1; - - krb5_free_cred_contents(kcontext, &creds); diff --git a/Remove-incomplete-PKINIT-OCSP-support.patch b/Remove-incomplete-PKINIT-OCSP-support.patch deleted file mode 100644 index 2f40965..0000000 --- a/Remove-incomplete-PKINIT-OCSP-support.patch +++ /dev/null @@ -1,134 +0,0 @@ -From 466d09c9b2c456d663672cb6d5f661ef86e8536e Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 31 Jul 2017 16:03:41 -0400 -Subject: [PATCH] Remove incomplete PKINIT OCSP support - -pkinit_kdc_ocsp is non-functional in the PKINIT OpenSSL crypto -implementation, so remove most traces of it, including its man page -entry. If it is present in kdc.conf, error out of PKINIT -initialization instead of silently ignoring the realm entirely. - -ticket: 8603 (new) -(cherry picked from commit 3ff426b9048a8024e5c175256c63cd0ad0572320) ---- - doc/admin/conf_files/kdc_conf.rst | 3 --- - src/man/kdc.conf.man | 3 --- - src/plugins/preauth/pkinit/pkinit.h | 2 +- - src/plugins/preauth/pkinit/pkinit_identity.c | 11 ----------- - src/plugins/preauth/pkinit/pkinit_srv.c | 12 ++++++++++-- - 5 files changed, 11 insertions(+), 20 deletions(-) - -diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst -index 4e54f7e1d..d00e7926c 100644 ---- a/doc/admin/conf_files/kdc_conf.rst -+++ b/doc/admin/conf_files/kdc_conf.rst -@@ -765,9 +765,6 @@ For information about the syntax of some of these options, see - pkinit is used to authenticate. This option may be specified - multiple times. (New in release 1.14.) - --**pkinit_kdc_ocsp** -- Specifies the location of the KDC's OCSP. -- - **pkinit_pool** - Specifies the location of intermediate certificates which may be - used by the KDC to complete the trust chain between a client's -diff --git a/src/man/kdc.conf.man b/src/man/kdc.conf.man -index d207ebd7f..c47da0117 100644 ---- a/src/man/kdc.conf.man -+++ b/src/man/kdc.conf.man -@@ -886,9 +886,6 @@ Specifies an authentication indicator to include in the ticket if - pkinit is used to authenticate. This option may be specified - multiple times. (New in release 1.14.) - .TP --.B \fBpkinit_kdc_ocsp\fP --Specifies the location of the KDC\(aqs OCSP. --.TP - .B \fBpkinit_pool\fP - Specifies the location of intermediate certificates which may be - used by the KDC to complete the trust chain between a client\(aqs -diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h -index 876db94c3..a49f3078e 100644 ---- a/src/plugins/preauth/pkinit/pkinit.h -+++ b/src/plugins/preauth/pkinit/pkinit.h -@@ -73,6 +73,7 @@ - #define KRB5_CONF_PKINIT_IDENTITIES "pkinit_identities" - #define KRB5_CONF_PKINIT_IDENTITY "pkinit_identity" - #define KRB5_CONF_PKINIT_KDC_HOSTNAME "pkinit_kdc_hostname" -+/* pkinit_kdc_ocsp has been removed */ - #define KRB5_CONF_PKINIT_KDC_OCSP "pkinit_kdc_ocsp" - #define KRB5_CONF_PKINIT_POOL "pkinit_pool" - #define KRB5_CONF_PKINIT_REQUIRE_CRL_CHECKING "pkinit_require_crl_checking" -@@ -173,7 +174,6 @@ typedef struct _pkinit_identity_opts { - char **anchors; - char **intermediates; - char **crls; -- char *ocsp; - int idtype; - char *cert_filename; - char *key_filename; -diff --git a/src/plugins/preauth/pkinit/pkinit_identity.c b/src/plugins/preauth/pkinit/pkinit_identity.c -index 177a2cad8..a897efa25 100644 ---- a/src/plugins/preauth/pkinit/pkinit_identity.c -+++ b/src/plugins/preauth/pkinit/pkinit_identity.c -@@ -125,7 +125,6 @@ pkinit_init_identity_opts(pkinit_identity_opts **idopts) - opts->anchors = NULL; - opts->intermediates = NULL; - opts->crls = NULL; -- opts->ocsp = NULL; - - opts->cert_filename = NULL; - opts->key_filename = NULL; -@@ -174,12 +173,6 @@ pkinit_dup_identity_opts(pkinit_identity_opts *src_opts, - if (retval) - goto cleanup; - -- if (src_opts->ocsp != NULL) { -- newopts->ocsp = strdup(src_opts->ocsp); -- if (newopts->ocsp == NULL) -- goto cleanup; -- } -- - if (src_opts->cert_filename != NULL) { - newopts->cert_filename = strdup(src_opts->cert_filename); - if (newopts->cert_filename == NULL) -@@ -674,10 +667,6 @@ pkinit_identity_prompt(krb5_context context, - if (retval) - goto errout; - } -- if (idopts->ocsp != NULL) { -- retval = ENOTSUP; -- goto errout; -- } - - errout: - return retval; -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index 731d14eb8..32ca122f2 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -1252,7 +1252,7 @@ static krb5_error_code - pkinit_init_kdc_profile(krb5_context context, pkinit_kdc_context plgctx) - { - krb5_error_code retval; -- char *eku_string = NULL; -+ char *eku_string = NULL, *ocsp_check = NULL; - - pkiDebug("%s: entered for realm %s\n", __FUNCTION__, plgctx->realmname); - retval = pkinit_kdcdefault_string(context, plgctx->realmname, -@@ -1287,7 +1287,15 @@ pkinit_init_kdc_profile(krb5_context context, pkinit_kdc_context plgctx) - - pkinit_kdcdefault_string(context, plgctx->realmname, - KRB5_CONF_PKINIT_KDC_OCSP, -- &plgctx->idopts->ocsp); -+ &ocsp_check); -+ if (ocsp_check != NULL) { -+ free(ocsp_check); -+ retval = ENOTSUP; -+ krb5_set_error_message(context, retval, -+ _("OCSP is not supported: (realm: %s)"), -+ plgctx->realmname); -+ goto errout; -+ } - - pkinit_kdcdefault_integer(context, plgctx->realmname, - KRB5_CONF_PKINIT_DH_MIN_BITS, diff --git a/Use-GSSAPI-fallback-skiptest.patch b/Use-GSSAPI-fallback-skiptest.patch index 118df5a..14beb76 100644 --- a/Use-GSSAPI-fallback-skiptest.patch +++ b/Use-GSSAPI-fallback-skiptest.patch @@ -1,4 +1,4 @@ -From 6d0b40b26e7fea1cd394618c1ab6d5e366bbc069 Mon Sep 17 00:00:00 2001 +From 697f19c5bfd4470c167d35c7af43c82a32660b82 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 1 Mar 2017 17:46:22 -0500 Subject: [PATCH] Use GSSAPI fallback skiptest diff --git a/Use-expected_msg-in-test-scripts.patch b/Use-expected_msg-in-test-scripts.patch deleted file mode 100644 index d4dc83e..0000000 --- a/Use-expected_msg-in-test-scripts.patch +++ /dev/null @@ -1,2584 +0,0 @@ -From 24ac588502b1731a7fd2629804f8d9ed1668297e Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 18 Jan 2017 11:22:58 -0500 -Subject: [PATCH] Use expected_msg in test scripts - -(cherry picked from commit d406afa363554097ac48646a29249c04f498c88e) ---- - src/appl/gss-sample/t_gss_sample.py | 18 ++- - src/appl/user_user/t_user2user.py | 6 +- - src/kdc/t_emptytgt.py | 5 +- - src/lib/krb5/krb/t_expire_warn.py | 13 +- - src/tests/gssapi/t_authind.py | 5 +- - src/tests/gssapi/t_ccselect.py | 10 +- - src/tests/gssapi/t_client_keytab.py | 60 +++------ - src/tests/gssapi/t_enctypes.py | 4 +- - src/tests/gssapi/t_export_cred.py | 4 +- - src/tests/gssapi/t_gssapi.py | 97 +++++--------- - src/tests/gssapi/t_s4u.py | 21 ++- - src/tests/t_audit.py | 11 +- - src/tests/t_authdata.py | 58 +++----- - src/tests/t_ccache.py | 38 ++---- - src/tests/t_crossrealm.py | 14 +- - src/tests/t_dump.py | 31 ++--- - src/tests/t_general.py | 12 +- - src/tests/t_hostrealm.py | 5 +- - src/tests/t_iprop.py | 103 ++++++--------- - src/tests/t_kadm5_hook.py | 10 +- - src/tests/t_kadmin_acl.py | 254 ++++++++++++++---------------------- - src/tests/t_kadmin_parsing.py | 30 ++--- - src/tests/t_kdb.py | 127 +++++++----------- - src/tests/t_kdb_locking.py | 5 +- - src/tests/t_keydata.py | 16 +-- - src/tests/t_keyrollover.py | 16 +-- - src/tests/t_keytab.py | 50 +++---- - src/tests/t_kprop.py | 13 +- - src/tests/t_localauth.py | 5 +- - src/tests/t_mkey.py | 45 +++---- - src/tests/t_otp.py | 10 +- - src/tests/t_pkinit.py | 27 ++-- - src/tests/t_policy.py | 101 +++++--------- - src/tests/t_preauth.py | 14 +- - src/tests/t_pwqual.py | 25 ++-- - src/tests/t_referral.py | 10 +- - src/tests/t_renew.py | 5 +- - src/tests/t_salt.py | 12 +- - src/tests/t_skew.py | 22 ++-- - src/tests/t_stringattr.py | 4 +- - 40 files changed, 475 insertions(+), 841 deletions(-) - -diff --git a/src/appl/gss-sample/t_gss_sample.py b/src/appl/gss-sample/t_gss_sample.py -index 8a6b0304f..0299e4590 100755 ---- a/src/appl/gss-sample/t_gss_sample.py -+++ b/src/appl/gss-sample/t_gss_sample.py -@@ -31,22 +31,20 @@ gss_server = os.path.join(appdir, 'gss-server') - # Run a gss-server process and a gss-client process, with additional - # gss-client flags given by options and additional gss-server flags - # given by server_options. Return the output of gss-client. --def run_client_server(realm, options, server_options, expected_code=0): -+def run_client_server(realm, options, server_options, **kwargs): - portstr = str(realm.server_port()) - server_args = [gss_server, '-export', '-port', portstr] - server_args += server_options + ['host'] - server = realm.start_server(server_args, 'starting...') -- out = realm.run([gss_client, '-port', portstr] + options + -- [hostname, 'host', 'testmsg'], expected_code=expected_code) -+ realm.run([gss_client, '-port', portstr] + options + -+ [hostname, 'host', 'testmsg'], **kwargs) - stop_daemon(server) -- return out - - # Run a gss-server and gss-client process, and verify that gss-client - # displayed the expected output for a successful negotiation. - def server_client_test(realm, options, server_options): -- out = run_client_server(realm, options, server_options) -- if 'Signature verified.' not in out: -- fail('Expected message not seen in gss-client output') -+ run_client_server(realm, options, server_options, -+ expected_msg='Signature verified.') - - # Make up a filename to hold user's initial credentials. - def ccache_savefile(realm): -@@ -81,10 +79,10 @@ def pw_test(realm, options, server_options=[]): - # IAKERB, gss_aqcuire_cred_with_password() otherwise). - def wrong_pw_test(realm, options, server_options=[], iakerb=False): - options = options + ['-user', realm.user_princ, '-pass', 'wrongpw'] -- out = run_client_server(realm, options, server_options, expected_code=1) - failed_op = 'initializing context' if iakerb else 'acquiring creds' -- if 'GSS-API error ' + failed_op not in out: -- fail('Expected error not seen in gss-client output') -+ msg = 'GSS-API error ' + failed_op -+ run_client_server(realm, options, server_options, expected_code=1, -+ expected_msg=msg) - - # Perform a test of the server and client with initial credentials - # obtained with the client keytab -diff --git a/src/appl/user_user/t_user2user.py b/src/appl/user_user/t_user2user.py -index 8bdef8e07..2a7d03f8d 100755 ---- a/src/appl/user_user/t_user2user.py -+++ b/src/appl/user_user/t_user2user.py -@@ -10,9 +10,9 @@ for realm in multipass_realms(): - else: - srv_output = realm.start_server(['./uuserver', '9999'], 'Server started') - -- output = realm.run(['./uuclient', hostname, 'testing message', '9999']) -- if 'uu-client: server says \"Hello, other end of connection.\"' not in output: -- fail('Message not echoed back.') -+ msg = 'uu-client: server says "Hello, other end of connection."' -+ realm.run(['./uuclient', hostname, 'testing message', '9999'], -+ expected_msg=msg) - - - success('User-2-user test programs') -diff --git a/src/kdc/t_emptytgt.py b/src/kdc/t_emptytgt.py -index 8f7717a01..2d0432e33 100755 ---- a/src/kdc/t_emptytgt.py -+++ b/src/kdc/t_emptytgt.py -@@ -2,7 +2,6 @@ - from k5test import * - - realm = K5Realm(create_host=False) --output = realm.run([kvno, 'krbtgt/'], expected_code=1) --if 'not found in Kerberos database' not in output: -- fail('TGT lookup for empty realm failed in unexpected way') -+realm.run([kvno, 'krbtgt/'], expected_code=1, -+ expected_msg='not found in Kerberos database') - success('Empty tgt lookup.') -diff --git a/src/lib/krb5/krb/t_expire_warn.py b/src/lib/krb5/krb/t_expire_warn.py -index e021379ab..aed39e399 100755 ---- a/src/lib/krb5/krb/t_expire_warn.py -+++ b/src/lib/krb5/krb/t_expire_warn.py -@@ -39,15 +39,10 @@ realm.run([kadminl, 'addprinc', '-pw', 'pass', '-pwexpire', '3 days', 'days']) - output = realm.run(['./t_expire_warn', 'noexpire', 'pass', '0']) - if output: - fail('Unexpected output for noexpire') --output = realm.run(['./t_expire_warn', 'minutes', 'pass', '0']) --if ' less than one hour on ' not in output: -- fail('Expected warning not seen for minutes') --output = realm.run(['./t_expire_warn', 'hours', 'pass', '0']) --if ' hours on ' not in output: -- fail('Expected warning not seen for hours') --output = realm.run(['./t_expire_warn', 'days', 'pass', '0']) --if ' days on ' not in output: -- fail('Expected warning not seen for days') -+realm.run(['./t_expire_warn', 'minutes', 'pass', '0'], -+ expected_msg=' less than one hour on ') -+realm.run(['./t_expire_warn', 'hours', 'pass', '0'], expected_msg=' hours on ') -+realm.run(['./t_expire_warn', 'days', 'pass', '0'], expected_msg=' days on ') - - # Check for expected expire callback behavior. These tests are - # carefully agnostic about whether the KDC supports last_req fields, -diff --git a/src/tests/gssapi/t_authind.py b/src/tests/gssapi/t_authind.py -index 316bc4093..dfd0a9a04 100644 ---- a/src/tests/gssapi/t_authind.py -+++ b/src/tests/gssapi/t_authind.py -@@ -24,9 +24,8 @@ if ('Attribute auth-indicators Authenticated Complete') not in out: - if '73757065727374726f6e67' not in out: - fail('Expected auth indicator not seen in name attributes') - --out = realm.run(['./t_srcattrs', 'p:service/2'], expected_code=1) --if 'gss_init_sec_context: KDC policy rejects request' not in out: -- fail('Expected error message not seen for indicator mismatch') -+msg = 'gss_init_sec_context: KDC policy rejects request' -+realm.run(['./t_srcattrs', 'p:service/2'], expected_code=1, expected_msg=msg) - - realm.kinit(realm.user_princ, password('user'), ['-X', 'indicators=one two']) - out = realm.run(['./t_srcattrs', 'p:service/2']) -diff --git a/src/tests/gssapi/t_ccselect.py b/src/tests/gssapi/t_ccselect.py -index 6be6b4ec0..1ea614d30 100755 ---- a/src/tests/gssapi/t_ccselect.py -+++ b/src/tests/gssapi/t_ccselect.py -@@ -45,9 +45,8 @@ refserver = 'p:host/' + hostname + '@' - - # Verify that we can't get initiator creds with no credentials in the - # collection. --output = r1.run(['./t_ccselect', host1, '-'], expected_code=1) --if 'No Kerberos credentials available' not in output: -- fail('Expected error not seen in output when no credentials available') -+r1.run(['./t_ccselect', host1, '-'], expected_code=1, -+ expected_msg='No Kerberos credentials available') - - # Make a directory collection and use it for client commands in both realms. - ccdir = os.path.join(r1.testdir, 'cc') -@@ -117,8 +116,7 @@ if output != (zaphod + '\n'): - output = r1.run(['./t_ccselect', refserver]) - if output != (bob + '\n'): - fail('bob not chosen via primary cache when no .k5identity line matches.') --output = r1.run(['./t_ccselect', 'h:bogus@' + hostname], expected_code=1) --if 'Can\'t find client principal noprinc' not in output: -- fail('Expected error not seen when k5identity selects bad principal.') -+r1.run(['./t_ccselect', 'h:bogus@' + hostname], expected_code=1, -+ expected_msg="Can't find client principal noprinc") - - success('GSSAPI credential selection tests') -diff --git a/src/tests/gssapi/t_client_keytab.py b/src/tests/gssapi/t_client_keytab.py -index 4c8747a50..2da87f45b 100755 ---- a/src/tests/gssapi/t_client_keytab.py -+++ b/src/tests/gssapi/t_client_keytab.py -@@ -15,9 +15,7 @@ realm.extract_keytab(realm.user_princ, realm.client_keytab) - realm.extract_keytab(bob, realm.client_keytab) - - # Test 1: no name/cache specified, pick first principal from client keytab --out = realm.run(['./t_ccselect', phost]) --if realm.user_princ not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', phost], expected_msg=realm.user_princ) - realm.run([kdestroy]) - - # Test 2: no name/cache specified, pick principal from k5identity -@@ -25,36 +23,27 @@ k5idname = os.path.join(realm.testdir, '.k5identity') - k5id = open(k5idname, 'w') - k5id.write('%s service=host host=%s\n' % (bob, hostname)) - k5id.close() --out = realm.run(['./t_ccselect', gssserver]) --if bob not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', gssserver], expected_msg=bob) - os.remove(k5idname) - realm.run([kdestroy]) - - # Test 3: no name/cache specified, default ccache has name but no creds - realm.run(['./ccinit', realm.ccache, bob]) --out = realm.run(['./t_ccselect', phost]) --if bob not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', phost], expected_msg=bob) - # Leave tickets for next test. - - # Test 4: name specified, non-collectable default cache doesn't match --out = realm.run(['./t_ccselect', phost, puser], expected_code=1) --if 'Principal in credential cache does not match desired name' not in out: -- fail('Expected error not seen') -+msg = 'Principal in credential cache does not match desired name' -+realm.run(['./t_ccselect', phost, puser], expected_code=1, expected_msg=msg) - realm.run([kdestroy]) - - # Test 5: name specified, nonexistent default cache --out = realm.run(['./t_ccselect', phost, pbob]) --if bob not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', phost, pbob], expected_msg=bob) - # Leave tickets for next test. - - # Test 6: name specified, matches default cache, time to refresh - realm.run(['./ccrefresh', realm.ccache, '1']) --out = realm.run(['./t_ccselect', phost, pbob]) --if bob not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', phost, pbob], expected_msg=bob) - out = realm.run(['./ccrefresh', realm.ccache]) - if int(out) < 1000: - fail('Credentials apparently not refreshed') -@@ -67,9 +56,8 @@ realm.run([kdestroy]) - - # Test 8: ccache specified with name but no creds; name not in client keytab - realm.run(['./ccinit', realm.ccache, realm.host_princ]) --out = realm.run(['./t_imp_cred', phost], expected_code=1) --if 'Credential cache is empty' not in out: -- fail('Expected error not seen') -+realm.run(['./t_imp_cred', phost], expected_code=1, -+ expected_msg='Credential cache is empty') - realm.run([kdestroy]) - - # Test 9: ccache specified with name but no creds; name in client keytab -@@ -104,16 +92,12 @@ realm.env['KRB5CCNAME'] = ccname - # Test 12: name specified, matching cache in collection with no creds - bobcache = os.path.join(ccdir, 'tktbob') - realm.run(['./ccinit', bobcache, bob]) --out = realm.run(['./t_ccselect', phost, pbob]) --if bob not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', phost, pbob], expected_msg=bob) - # Leave tickets for next test. - - # Test 13: name specified, matching cache in collection, time to refresh - realm.run(['./ccrefresh', bobcache, '1']) --out = realm.run(['./t_ccselect', phost, pbob]) --if bob not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', phost, pbob], expected_msg=bob) - out = realm.run(['./ccrefresh', bobcache]) - if int(out) < 1000: - fail('Credentials apparently not refreshed') -@@ -121,22 +105,15 @@ realm.run([kdestroy, '-A']) - - # Test 14: name specified, collection has default for different principal - realm.kinit(realm.user_princ, password('user')) --out = realm.run(['./t_ccselect', phost, pbob]) --if bob not in out: -- fail('Authenticated as wrong principal') --out = realm.run([klist]) --if 'Default principal: %s\n' % realm.user_princ not in out: -- fail('Default cache overwritten by acquire_cred') -+realm.run(['./t_ccselect', phost, pbob], expected_msg=bob) -+msg = 'Default principal: %s\n' % realm.user_princ -+realm.run([klist], expected_msg=msg) - realm.run([kdestroy, '-A']) - - # Test 15: name specified, collection has no default cache --out = realm.run(['./t_ccselect', phost, pbob]) --if bob not in out: -- fail('Authenticated as wrong principal') -+realm.run(['./t_ccselect', phost, pbob], expected_msg=bob) - # Make sure the tickets we acquired didn't become the default --out = realm.run([klist], expected_code=1) --if 'No credentials cache found' not in out: -- fail('Expected error not seen') -+realm.run([klist], expected_code=1, expected_msg='No credentials cache found') - realm.run([kdestroy, '-A']) - - # Test 16: default client keytab cannot be resolved, but valid -@@ -145,8 +122,7 @@ conf = {'libdefaults': {'default_client_keytab_name': '%{'}} - bad_cktname = realm.special_env('bad_cktname', False, krb5_conf=conf) - del bad_cktname['KRB5_CLIENT_KTNAME'] - realm.kinit(realm.user_princ, password('user')) --out = realm.run(['./t_ccselect', phost], env=bad_cktname) --if realm.user_princ not in out: -- fail('Expected principal not seen for bad client keytab name') -+realm.run(['./t_ccselect', phost], env=bad_cktname, -+ expected_msg=realm.user_princ) - - success('Client keytab tests') -diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py -index 862f22989..f513db2b5 100755 ---- a/src/tests/gssapi/t_enctypes.py -+++ b/src/tests/gssapi/t_enctypes.py -@@ -58,9 +58,7 @@ def test(msg, ienc, aenc, tktenc='', tktsession='', proto='', isubkey='', - # and check that it fails with the expected error message. - def test_err(msg, ienc, aenc, expected_err): - shutil.copyfile(os.path.join(realm.testdir, 'save'), realm.ccache) -- out = realm.run(cmdline(ienc, aenc), expected_code=1) -- if expected_err not in out: -- fail(msg) -+ realm.run(cmdline(ienc, aenc), expected_code=1, expected_msg=expected_err) - - - # By default, all of the key enctypes should be aes256. -diff --git a/src/tests/gssapi/t_export_cred.py b/src/tests/gssapi/t_export_cred.py -index 698835928..b98962788 100755 ---- a/src/tests/gssapi/t_export_cred.py -+++ b/src/tests/gssapi/t_export_cred.py -@@ -23,9 +23,7 @@ def ccache_restore(realm): - def check(realm, args): - ccache_restore(realm) - realm.run(['./t_export_cred'] + args) -- output = realm.run([klist, '-f']) -- if 'Flags: Ff' not in output: -- fail('Forwarded tickets not found in ccache after t_export_cred') -+ realm.run([klist, '-f'], expected_msg='Flags: Ff') - - # Check a given set of arguments with no specified mech and with krb5 - # and SPNEGO as the specified mech. -diff --git a/src/tests/gssapi/t_gssapi.py b/src/tests/gssapi/t_gssapi.py -index e23c936d7..397e58962 100755 ---- a/src/tests/gssapi/t_gssapi.py -+++ b/src/tests/gssapi/t_gssapi.py -@@ -28,57 +28,40 @@ realm.run([kadminl, 'renprinc', 'service1/abraham', 'service1/andrew']) - - # Test with no acceptor name, including client/keytab principal - # mismatch (non-fatal) and missing keytab entry (fatal). --output = realm.run(['./t_accname', 'p:service1/andrew']) --if 'service1/abraham' not in output: -- fail('Expected service1/abraham in t_accname output') --output = realm.run(['./t_accname', 'p:service1/barack']) --if 'service1/barack' not in output: -- fail('Expected service1/barack in t_accname output') --output = realm.run(['./t_accname', 'p:service2/calvin']) --if 'service2/calvin' not in output: -- fail('Expected service1/barack in t_accname output') --output = realm.run(['./t_accname', 'p:service2/dwight'], expected_code=1) --if ' not found in keytab' not in output: -- fail('Expected error message not seen in t_accname output') -+realm.run(['./t_accname', 'p:service1/andrew'], -+ expected_msg='service1/abraham') -+realm.run(['./t_accname', 'p:service1/barack'], expected_msg='service1/barack') -+realm.run(['./t_accname', 'p:service2/calvin'], expected_msg='service2/calvin') -+realm.run(['./t_accname', 'p:service2/dwight'], expected_code=1, -+ expected_msg=' not found in keytab') - - # Test with acceptor name containing service only, including - # client/keytab hostname mismatch (non-fatal) and service name - # mismatch (fatal). --output = realm.run(['./t_accname', 'p:service1/andrew', 'h:service1']) --if 'service1/abraham' not in output: -- fail('Expected service1/abraham in t_accname output') --output = realm.run(['./t_accname', 'p:service1/andrew', 'h:service2'], -- expected_code=1) --if ' not found in keytab' not in output: -- fail('Expected error message not seen in t_accname output') --output = realm.run(['./t_accname', 'p:service2/calvin', 'h:service2']) --if 'service2/calvin' not in output: -- fail('Expected service2/calvin in t_accname output') --output = realm.run(['./t_accname', 'p:service2/calvin', 'h:service1'], -- expected_code=1) --if ' found in keytab but does not match server principal' not in output: -- fail('Expected error message not seen in t_accname output') -+realm.run(['./t_accname', 'p:service1/andrew', 'h:service1'], -+ expected_msg='service1/abraham') -+realm.run(['./t_accname', 'p:service1/andrew', 'h:service2'], expected_code=1, -+ expected_msg=' not found in keytab') -+realm.run(['./t_accname', 'p:service2/calvin', 'h:service2'], -+ expected_msg='service2/calvin') -+realm.run(['./t_accname', 'p:service2/calvin', 'h:service1'], expected_code=1, -+ expected_msg=' found in keytab but does not match server principal') - - # Test with acceptor name containing service and host. Use the - # client's un-canonicalized hostname as acceptor input to mirror what - # many servers do. --output = realm.run(['./t_accname', 'p:' + realm.host_princ, -- 'h:host@%s' % socket.gethostname()]) --if realm.host_princ not in output: -- fail('Expected %s in t_accname output' % realm.host_princ) --output = realm.run(['./t_accname', 'p:host/-nomatch-', -- 'h:host@%s' % socket.gethostname()], -- expected_code=1) --if ' not found in keytab' not in output: -- fail('Expected error message not seen in t_accname output') -+realm.run(['./t_accname', 'p:' + realm.host_princ, -+ 'h:host@%s' % socket.gethostname()], expected_msg=realm.host_princ) -+realm.run(['./t_accname', 'p:host/-nomatch-', -+ 'h:host@%s' % socket.gethostname()], expected_code=1, -+ expected_msg=' not found in keytab') - - # Test krb5_gss_import_cred. - realm.run(['./t_imp_cred', 'p:service1/barack']) - realm.run(['./t_imp_cred', 'p:service1/barack', 'service1/barack']) - realm.run(['./t_imp_cred', 'p:service1/andrew', 'service1/abraham']) --output = realm.run(['./t_imp_cred', 'p:service2/dwight'], expected_code=1) --if ' not found in keytab' not in output: -- fail('Expected error message not seen in t_imp_cred output') -+realm.run(['./t_imp_cred', 'p:service2/dwight'], expected_code=1, -+ expected_msg=' not found in keytab') - - # Test credential store extension. - tmpccname = 'FILE:' + os.path.join(realm.testdir, 'def_cache') -@@ -116,10 +99,8 @@ ignore_conf = {'libdefaults': {'ignore_acceptor_hostname': 'true'}} - realm = K5Realm(krb5_conf=ignore_conf) - realm.run([kadminl, 'addprinc', '-randkey', 'host/-nomatch-']) - realm.run([kadminl, 'xst', 'host/-nomatch-']) --output = realm.run(['./t_accname', 'p:host/-nomatch-', -- 'h:host@%s' % socket.gethostname()]) --if 'host/-nomatch-' not in output: -- fail('Expected host/-nomatch- in t_accname output') -+realm.run(['./t_accname', 'p:host/-nomatch-', -+ 'h:host@%s' % socket.gethostname()], expected_msg='host/-nomatch-') - - realm.stop() - -@@ -141,41 +122,25 @@ r3.stop() - realm = K5Realm() - - # Test deferred resolution of the default ccache for initiator creds. --output = realm.run(['./t_inq_cred']) --if realm.user_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.user_princ) --output = realm.run(['./t_inq_cred', '-k']) --if realm.user_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.user_princ) --output = realm.run(['./t_inq_cred', '-s']) --if realm.user_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.user_princ) -+realm.run(['./t_inq_cred'], expected_msg=realm.user_princ) -+realm.run(['./t_inq_cred', '-k'], expected_msg=realm.user_princ) -+realm.run(['./t_inq_cred', '-s'], expected_msg=realm.user_princ) - - # Test picking a name from the keytab for acceptor creds. --output = realm.run(['./t_inq_cred', '-a']) --if realm.host_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.host_princ) --output = realm.run(['./t_inq_cred', '-k', '-a']) --if realm.host_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.host_princ) --output = realm.run(['./t_inq_cred', '-s', '-a']) --if realm.host_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.host_princ) -+realm.run(['./t_inq_cred', '-a'], expected_msg=realm.host_princ) -+realm.run(['./t_inq_cred', '-k', '-a'], expected_msg=realm.host_princ) -+realm.run(['./t_inq_cred', '-s', '-a'], expected_msg=realm.host_princ) - - # Test client keytab initiation (non-deferred) with a specified name. - realm.extract_keytab(realm.user_princ, realm.client_keytab) - os.remove(realm.ccache) --output = realm.run(['./t_inq_cred', '-k']) --if realm.user_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.user_princ) -+realm.run(['./t_inq_cred', '-k'], expected_msg=realm.user_princ) - - # Test deferred client keytab initiation and GSS_C_BOTH cred usage. - os.remove(realm.client_keytab) - os.remove(realm.ccache) - shutil.copyfile(realm.keytab, realm.client_keytab) --output = realm.run(['./t_inq_cred', '-k', '-b']) --if realm.host_princ not in output: -- fail('Expected %s in t_inq_cred output' % realm.host_princ) -+realm.run(['./t_inq_cred', '-k', '-b'], expected_msg=realm.host_princ) - - # Test gss_export_name behavior. - out = realm.run(['./t_export_name', 'u:x']) -diff --git a/src/tests/gssapi/t_s4u.py b/src/tests/gssapi/t_s4u.py -index 7366e3915..e4cd68469 100755 ---- a/src/tests/gssapi/t_s4u.py -+++ b/src/tests/gssapi/t_s4u.py -@@ -42,10 +42,8 @@ if ('auth1: ' + realm.user_princ not in output or - # result in no delegated credential being created by - # accept_sec_context. - realm.kinit(realm.user_princ, password('user'), ['-c', usercache]) --output = realm.run(['./t_s4u2proxy_krb5', usercache, storagecache, pservice1, -- pservice1, pservice2]) --if 'no credential delegated' not in output: -- fail('krb5 -> no delegated cred') -+realm.run(['./t_s4u2proxy_krb5', usercache, storagecache, pservice1, -+ pservice1, pservice2], expected_msg='no credential delegated') - - # Try S4U2Self. Ask for an S4U2Proxy step; this won't happen because - # service/1 isn't allowed to get a forwardable S4U2Self ticket. -@@ -61,17 +59,15 @@ if ('Warning: no delegated cred handle' not in output or - # Correct that problem and try again. As above, the S4U2Proxy step - # won't actually succeed since we don't support that in DB2. - realm.run([kadminl, 'modprinc', '+ok_to_auth_as_delegate', service1]) --output = realm.run(['./t_s4u', puser, pservice2], expected_code=1) --if 'NOT_ALLOWED_TO_DELEGATE' not in output: -- fail('s4u2self') -+realm.run(['./t_s4u', puser, pservice2], expected_code=1, -+ expected_msg='NOT_ALLOWED_TO_DELEGATE') - - # Again with SPNEGO. This uses SPNEGO for the initial authentication, - # but still uses krb5 for S4U2Proxy--the delegated cred is returned as - # a krb5 cred, not a SPNEGO cred, and t_s4u uses the delegated cred - # directly rather than saving and reacquiring it. --output = realm.run(['./t_s4u', '--spnego', puser, pservice2], expected_code=1) --if 'NOT_ALLOWED_TO_DELEGATE' not in output: -- fail('s4u2self') -+realm.run(['./t_s4u', '--spnego', puser, pservice2], expected_code=1, -+ expected_msg='NOT_ALLOWED_TO_DELEGATE') - - realm.stop() - -@@ -148,9 +144,8 @@ realm.stop() - # fail, but we can check that the right server principal was used. - r1, r2 = cross_realms(2, create_user=False) - r1.run([kinit, '-k', r1.host_princ]) --out = r1.run(['./t_s4u', 'p:' + r2.host_princ], expected_code=1) --if 'Server not found in Kerberos database' not in out: -- fail('cross-realm s4u2self (t_s4u output)') -+r1.run(['./t_s4u', 'p:' + r2.host_princ], expected_code=1, -+ expected_msg='Server not found in Kerberos database') - r1.stop() - r2.stop() - with open(os.path.join(r2.testdir, 'kdc.log')) as f: -diff --git a/src/tests/t_audit.py b/src/tests/t_audit.py -index 69c9251e0..00e96bfea 100755 ---- a/src/tests/t_audit.py -+++ b/src/tests/t_audit.py -@@ -14,18 +14,15 @@ realm.run([kvno, 'target']) - - # Make S4U2Self and S4U2Proxy requests so they will be audited. The - # S4U2Proxy request is expected to fail. --out = realm.run([kvno, '-k', realm.keytab, '-U', 'user', '-P', 'target'], -- expected_code=1) --if 'NOT_ALLOWED_TO_DELEGATE' not in out: -- fail('Unexpected error for S4U2Proxy') -+realm.run([kvno, '-k', realm.keytab, '-U', 'user', '-P', 'target'], -+ expected_code=1, expected_msg='NOT_ALLOWED_TO_DELEGATE') - - # Make a U2U request so it will be audited. - uuserver = os.path.join(buildtop, 'appl', 'user_user', 'uuserver') - uuclient = os.path.join(buildtop, 'appl', 'user_user', 'uuclient') - port_arg = str(realm.server_port()) - realm.start_server([uuserver, port_arg], 'Server started') --output = realm.run([uuclient, hostname, 'testing message', port_arg]) --if 'Hello' not in output: -- fail('U2U request failed unexpectedly') -+realm.run([uuclient, hostname, 'testing message', port_arg], -+ expected_msg='Hello') - - success('Audit tests') -diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py -index 33525022b..dd92b338f 100644 ---- a/src/tests/t_authdata.py -+++ b/src/tests/t_authdata.py -@@ -24,10 +24,8 @@ if ' -5: test1' not in out or '?-6: test2' not in out: - if 'fake' in out: - fail('KDC-only authdata not filtered for request with authdata') - --out = realm.run(['./adata', realm.host_princ, '!-1', 'mandatoryforkdc'], -- expected_code=1) --if 'KDC policy rejects request' not in out: -- fail('Wrong error seen for mandatory-for-kdc failure') -+realm.run(['./adata', realm.host_princ, '!-1', 'mandatoryforkdc'], -+ expected_code=1, expected_msg='KDC policy rejects request') - - # The no_auth_data_required server flag should suppress SIGNTICKET, - # but not module or request authdata. -@@ -98,45 +96,32 @@ realm2.extract_keytab('krbtgt/LOCAL', realm.keytab) - # AS request to local-realm service - realm.kinit(realm.user_princ, password('user'), - ['-X', 'indicators=indcl', '-r', '2d', '-S', realm.host_princ]) --out = realm.run(['./adata', realm.host_princ]) --if '+97: [indcl]' not in out: -- fail('auth-indicator not seen for AS req to service') -+realm.run(['./adata', realm.host_princ], expected_msg='+97: [indcl]') - - # Ticket modification request - realm.kinit(realm.user_princ, None, ['-R', '-S', realm.host_princ]) --out = realm.run(['./adata', realm.host_princ]) --if '+97: [indcl]' not in out: -- fail('auth-indicator not seen for ticket modification request') -+realm.run(['./adata', realm.host_princ], expected_msg='+97: [indcl]') - - # AS request to cross TGT - realm.kinit(realm.user_princ, password('user'), - ['-X', 'indicators=indcl', '-S', 'krbtgt/FOREIGN']) --out = realm.run(['./adata', 'krbtgt/FOREIGN']) --if '+97: [indcl]' not in out: -- fail('auth-indicator not seen for AS req to cross-realm TGT') -+realm.run(['./adata', 'krbtgt/FOREIGN'], expected_msg='+97: [indcl]') - - # Multiple indicators - realm.kinit(realm.user_princ, password('user'), - ['-X', 'indicators=indcl indcl2 indcl3']) --out = realm.run(['./adata', realm.krbtgt_princ]) --if '+97: [indcl, indcl2, indcl3]' not in out: -- fail('multiple auth-indicators not seen for normal AS req') -+realm.run(['./adata', realm.krbtgt_princ], -+ expected_msg='+97: [indcl, indcl2, indcl3]') - - # AS request to local TGT (resulting creds are used for TGS tests) - realm.kinit(realm.user_princ, password('user'), ['-X', 'indicators=indcl']) --out = realm.run(['./adata', realm.krbtgt_princ]) --if '+97: [indcl]' not in out: -- fail('auth-indicator not seen for normal AS req') -+realm.run(['./adata', realm.krbtgt_princ], expected_msg='+97: [indcl]') - - # Local TGS request for local realm service --out = realm.run(['./adata', realm.host_princ]) --if '+97: [indcl]' not in out: -- fail('auth-indicator not seen for local TGS req') -+realm.run(['./adata', realm.host_princ], expected_msg='+97: [indcl]') - - # Local TGS request for cross TGT service --out = realm.run(['./adata', 'krbtgt/FOREIGN']) --if '+97: [indcl]' not in out: -- fail('auth-indicator not seen for TGS req to cross-realm TGT') -+realm.run(['./adata', 'krbtgt/FOREIGN'], expected_msg='+97: [indcl]') - - # We don't yet have support for passing auth indicators across realms, - # so just verify that indicators don't survive cross-realm requests. -@@ -152,16 +137,13 @@ if '97:' in out: - - # Test that the CAMMAC signature still works during a krbtgt rollover. - realm.run([kadminl, 'cpw', '-randkey', '-keepold', realm.krbtgt_princ]) --out = realm.run(['./adata', realm.host_princ]) --if '+97: [indcl]' not in out: -- fail('auth-indicator not seen for local TGS req after krbtgt rotation') -+realm.run(['./adata', realm.host_princ], expected_msg='+97: [indcl]') - - # Test indicator enforcement. - realm.addprinc('restricted') - realm.run([kadminl, 'setstr', 'restricted', 'require_auth', 'superstrong']) --out = realm.run([kvno, 'restricted'], expected_code=1) --if 'KDC policy rejects request' not in out: -- fail('expected error not seen for auth indicator enforcement') -+realm.run([kvno, 'restricted'], expected_code=1, -+ expected_msg='KDC policy rejects request') - realm.run([kadminl, 'setstr', 'restricted', 'require_auth', 'indcl']) - realm.run([kvno, 'restricted']) - realm.kinit(realm.user_princ, password('user'), ['-X', 'indicators=ind1 ind2']) -@@ -222,13 +204,11 @@ if '+97: [indcl]' not in out or '[inds1]' in out: - # Test that KDB module authdata is included in an AS request, by - # default or with an explicit PAC request. - realm.kinit(realm.user_princ, None, ['-k']) --out = realm.run(['./adata', realm.krbtgt_princ]) --if '-456: db-authdata-test' not in out: -- fail('DB authdata not seen in default AS request') -+realm.run(['./adata', realm.krbtgt_princ], -+ expected_msg='-456: db-authdata-test') - realm.kinit(realm.user_princ, None, ['-k', '--request-pac']) --out = realm.run(['./adata', realm.krbtgt_princ]) --if '-456: db-authdata-test' not in out: -- fail('DB authdata not seen with --request-pac') -+realm.run(['./adata', realm.krbtgt_princ], -+ expected_msg='-456: db-authdata-test') - - # Test that KDB module authdata is suppressed in an AS request by a - # negative PAC request. -@@ -238,9 +218,7 @@ if '-456: db-authdata-test' in out: - fail('DB authdata not suppressed by --no-request-pac') - - # Test that KDB authdata is included in a TGS request by default. --out = realm.run(['./adata', 'service/1']) --if '-456: db-authdata-test' not in out: -- fail('DB authdata not seen in TGS request') -+realm.run(['./adata', 'service/1'], expected_msg='-456: db-authdata-test') - - # Test that KDB authdata is suppressed in a TGS request by the - # +no_auth_data_required flag. -diff --git a/src/tests/t_ccache.py b/src/tests/t_ccache.py -index 47d963130..2dcd19102 100755 ---- a/src/tests/t_ccache.py -+++ b/src/tests/t_ccache.py -@@ -35,15 +35,11 @@ if not test_keyring: - - # Test kdestroy and klist of a non-existent ccache. - realm.run([kdestroy]) --output = realm.run([klist], expected_code=1) --if 'No credentials cache found' not in output: -- fail('Expected error message not seen in klist output') -+realm.run([klist], expected_code=1, expected_msg='No credentials cache found') - - # Test kinit with an inaccessible ccache. --out = realm.run([kinit, '-c', 'testdir/xx/yy', realm.user_princ], -- input=(password('user') + '\n'), expected_code=1) --if 'Failed to store credentials' not in out: -- fail('Expected error message not seen in kinit output') -+realm.kinit(realm.user_princ, password('user'), flags=['-c', 'testdir/xx/yy'], -+ expected_code=1, expected_msg='Failed to store credentials') - - # Test klist -s with a single ccache. - realm.run([klist, '-s'], expected_code=1) -@@ -65,9 +61,7 @@ def collection_test(realm, ccname): - - realm.run([klist, '-A', '-s'], expected_code=1) - realm.kinit('alice', password('alice')) -- output = realm.run([klist]) -- if 'Default principal: alice@' not in output: -- fail('Initial kinit failed to get credentials for alice.') -+ realm.run([klist], expected_msg='Default principal: alice@') - realm.run([klist, '-A', '-s']) - realm.run([kdestroy]) - output = realm.run([klist], expected_code=1) -@@ -130,25 +124,20 @@ if test_keyring: - realm.env['KRB5CCNAME'] = 'KEYRING:' + cname - realm.run([kdestroy, '-A']) - realm.kinit(realm.user_princ, password('user')) -- out = realm.run([klist, '-l']) -- if 'KEYRING:legacy:' + cname + ':' + cname not in out: -- fail('Wrong initial primary name in keyring legacy collection') -+ msg = 'KEYRING:legacy:' + cname + ':' + cname -+ realm.run([klist, '-l'], expected_msg=msg) - # Make sure this cache is linked to the session keyring. - id = realm.run([keyctl, 'search', '@s', 'keyring', cname]) -- out = realm.run([keyctl, 'list', id.strip()]) -- if 'user: __krb5_princ__' not in out: -- fail('Legacy cache not linked into session keyring') -+ realm.run([keyctl, 'list', id.strip()], -+ expected_msg='user: __krb5_princ__') - # Remove the collection keyring. When the collection is - # reinitialized, the legacy cache should reappear inside it - # automatically as the primary cache. - cleanup_keyring('@s', col_ringname) -- out = realm.run([klist]) -- if realm.user_princ not in out: -- fail('Cannot see legacy cache after removing collection') -+ realm.run([klist], expected_msg=realm.user_princ) - coll_id = realm.run([keyctl, 'search', '@s', 'keyring', '_krb_' + cname]) -- out = realm.run([keyctl, 'list', coll_id.strip()]) -- if (id.strip() + ':') not in out: -- fail('Legacy cache did not reappear in collection after klist') -+ msg = id.strip() + ':' -+ realm.run([keyctl, 'list', coll_id.strip()], expected_msg=msg) - # Destroy the cache and check that it is unlinked from the session keyring. - realm.run([kdestroy]) - realm.run([keyctl, 'search', '@s', 'keyring', cname], expected_code=1) -@@ -160,8 +149,7 @@ conf = {'libdefaults': {'default_ccache_name': 'testdir/%{null}abc%{uid}'}} - realm = K5Realm(krb5_conf=conf, create_kdb=False) - del realm.env['KRB5CCNAME'] - uidstr = str(os.getuid()) --out = realm.run([klist], expected_code=1) --if 'testdir/abc%s' % uidstr not in out: -- fail('Wrong ccache in klist') -+msg = 'testdir/abc%s' % uidstr -+realm.run([klist], expected_code=1, expected_msg=msg) - - success('Credential cache tests') -diff --git a/src/tests/t_crossrealm.py b/src/tests/t_crossrealm.py -index 0d967b8a5..1fa48793a 100755 ---- a/src/tests/t_crossrealm.py -+++ b/src/tests/t_crossrealm.py -@@ -25,9 +25,7 @@ - from k5test import * - - def test_kvno(r, princ, test, env=None): -- output = r.run([kvno, princ], env=env) -- if princ not in output: -- fail('%s: principal %s not in kvno output' % (test, princ)) -+ r.run([kvno, princ], env=env, expected_msg=princ) - - - def stop(*realms): -@@ -85,9 +83,8 @@ capaths = {'capaths': {'A': {'C': 'B'}}} - r1, r2, r3 = cross_realms(3, xtgts=((0,1), (1,2)), - args=({'realm': 'A', 'krb5_conf': capaths}, - {'realm': 'B'}, {'realm': 'C'})) --output = r1.run([kvno, r3.host_princ], expected_code=1) --if 'KDC policy rejects request' not in output: -- fail('transited 1: Expected error message not in output') -+r1.run([kvno, r3.host_princ], expected_code=1, -+ expected_msg='KDC policy rejects request') - stop(r1, r2, r3) - - # Test a different kind of transited error. The KDC for D does not -@@ -99,9 +96,8 @@ r1, r2, r3, r4 = cross_realms(4, xtgts=((0,1), (1,2), (2,3)), - {'realm': 'B', 'krb5_conf': capaths}, - {'realm': 'C', 'krb5_conf': capaths}, - {'realm': 'D'})) --output = r1.run([kvno, r4.host_princ], expected_code=1) --if 'Illegal cross-realm ticket' not in output: -- fail('transited 2: Expected error message not in output') -+r1.run([kvno, r4.host_princ], expected_code=1, -+ expected_msg='Illegal cross-realm ticket') - stop(r1, r2, r3, r4) - - success('Cross-realm tests') -diff --git a/src/tests/t_dump.py b/src/tests/t_dump.py -index 5d3a43762..8a9462bd8 100755 ---- a/src/tests/t_dump.py -+++ b/src/tests/t_dump.py -@@ -36,12 +36,10 @@ if 'Expiration date: [never]' not in out or 'MKey: vno 1' not in out: - out = realm.run([kadminl, 'getpols']) - if 'fred\n' not in out or 'barney\n' not in out: - fail('Missing policy after load') --out = realm.run([kadminl, 'getpol', 'compat']) --if 'Number of old keys kept: 5' not in out: -- fail('Policy (1.8 format) has wrong value after load') --out = realm.run([kadminl, 'getpol', 'barney']) --if 'Number of old keys kept: 1' not in out: -- fail('Policy has wrong value after load') -+realm.run([kadminl, 'getpol', 'compat'], -+ expected_msg='Number of old keys kept: 5') -+realm.run([kadminl, 'getpol', 'barney'], -+ expected_msg='Number of old keys kept: 1') - - # Dump/load again, and make sure everything is still there. - realm.run([kdb5_util, 'dump', dumpfile]) -@@ -81,15 +79,10 @@ dump_compare(realm, ['-ov'], srcdump_ov) - def load_dump_check_compare(realm, opt, srcfile): - realm.run([kdb5_util, 'destroy', '-f']) - realm.run([kdb5_util, 'load'] + opt + [srcfile]) -- out = realm.run([kadminl, 'getprincs']) -- if 'user@' not in out: -- fail('Loaded dumpfile missing user principal') -- out = realm.run([kadminl, 'getprinc', 'nokeys']) -- if 'Number of keys: 0' not in out: -- fail('Loading dumpfile did not process zero-key principal') -- out = realm.run([kadminl, 'getpols']) -- if 'testpol' not in out: -- fail('Loaded dumpfile missing test policy') -+ realm.run([kadminl, 'getprincs'], expected_msg='user@') -+ realm.run([kadminl, 'getprinc', 'nokeys'], -+ expected_msg='Number of keys: 0') -+ realm.run([kadminl, 'getpols'], expected_msg='testpol') - dump_compare(realm, opt, srcfile) - - # Load each format of dump, check it, re-dump it, and compare. -@@ -99,12 +92,8 @@ load_dump_check_compare(realm, ['-b7'], srcdump_b7) - - # Loading the last (-b7 format) dump won't have loaded the - # per-principal kadm data. Load that incrementally with -ov. --out = realm.run([kadminl, 'getprinc', 'user']) --if 'Policy: [none]' not in out: -- fail('Loaded b7 dump unexpectedly contains user policy reference') -+realm.run([kadminl, 'getprinc', 'user'], expected_msg='Policy: [none]') - realm.run([kdb5_util, 'load', '-update', '-ov', srcdump_ov]) --out = realm.run([kadminl, 'getprinc', 'user']) --if 'Policy: testpol' not in out: -- fail('Loading ov dump did not add user policy reference') -+realm.run([kadminl, 'getprinc', 'user'], expected_msg='Policy: testpol') - - success('Dump/load tests') -diff --git a/src/tests/t_general.py b/src/tests/t_general.py -index 16bf6c5e3..6621b7230 100755 ---- a/src/tests/t_general.py -+++ b/src/tests/t_general.py -@@ -3,10 +3,9 @@ from k5test import * - - for realm in multipass_realms(create_host=False): - # Check that kinit fails appropriately with the wrong password. -- output = realm.run([kinit, realm.user_princ], input='wrong\n', -- expected_code=1) -- if 'Password incorrect while getting initial credentials' not in output: -- fail('Expected error message not seen in kinit output') -+ msg = 'Password incorrect while getting initial credentials' -+ realm.run([kinit, realm.user_princ], input='wrong\n', expected_code=1, -+ expected_msg=msg) - - # Check that we can kinit as a different principal. - realm.kinit(realm.admin_princ, password('admin')) -@@ -42,9 +41,8 @@ realm.run(['./responder', '-r', 'password=%s' % password('user'), - # Test that WRONG_REALM responses aren't treated as referrals unless - # they contain a crealm field pointing to a different realm. - # (Regression test for #8060.) --out = realm.run([kinit, '-C', 'notfoundprinc'], expected_code=1) --if 'not found in Kerberos database' not in out: -- fail('Expected error message not seen in kinit -C output') -+realm.run([kinit, '-C', 'notfoundprinc'], expected_code=1, -+ expected_msg='not found in Kerberos database') - - # Spot-check KRB5_TRACE output - expected_trace = ('Sending initial UDP request', -diff --git a/src/tests/t_hostrealm.py b/src/tests/t_hostrealm.py -index 76b282d2a..224c067ef 100755 ---- a/src/tests/t_hostrealm.py -+++ b/src/tests/t_hostrealm.py -@@ -20,9 +20,8 @@ def test(realm, args, expected_realms, msg, env=None): - fail(msg) - - def test_error(realm, args, expected_error, msg, env=None): -- out = realm.run(['./hrealm'] + args, env=env, expected_code=1) -- if expected_error not in out: -- fail(msg) -+ realm.run(['./hrealm'] + args, env=env, expected_code=1, -+ expected_msg=expected_error) - - def testh(realm, host, expected_realms, msg, env=None): - test(realm, ['-h', host], expected_realms, msg, env=env) -diff --git a/src/tests/t_iprop.py b/src/tests/t_iprop.py -index e64fdd279..8e23cd5de 100755 ---- a/src/tests/t_iprop.py -+++ b/src/tests/t_iprop.py -@@ -214,9 +214,8 @@ check_ulog(7, 1, 7, [None, pr1, pr3, pr2, pr2, pr2, pr2]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, False, 6, 7) - check_ulog(2, 6, 7, [None, pr2], slave1) --out = realm.run([kadminl, 'getprinc', pr2], env=slave1) --if 'Attributes: DISALLOW_ALL_TIX' not in out: -- fail('slave1 does not have modification from master') -+realm.run([kadminl, 'getprinc', pr2], env=slave1, -+ expected_msg='Attributes: DISALLOW_ALL_TIX') - - # Start kadmind -proponly for slave1. (Use the slave1m environment - # which defines iprop_port to $port8.) -@@ -245,15 +244,13 @@ check_ulog(8, 1, 8, [None, pr1, pr3, pr2, pr2, pr2, pr2, pr1]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, False, 7, 8) - check_ulog(3, 6, 8, [None, pr2, pr1], slave1) --out = realm.run([kadminl, 'getprinc', pr1], env=slave1) --if 'Maximum ticket life: 0 days 00:20:00' not in out: -- fail('slave1 does not have modification from master') -+realm.run([kadminl, 'getprinc', pr1], env=slave1, -+ expected_msg='Maximum ticket life: 0 days 00:20:00') - kpropd3.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd3, False, 7, 8) - check_ulog(2, 7, 8, [None, pr1], slave3) --out = realm.run([kadminl, '-r', realm.realm, 'getprinc', pr1], env=slave3) --if 'Maximum ticket life: 0 days 00:20:00' not in out: -- fail('slave3 does not have modification from slave1') -+realm.run([kadminl, '-r', realm.realm, 'getprinc', pr1], env=slave3, -+ expected_msg='Maximum ticket life: 0 days 00:20:00') - stop_daemon(kpropd3) - - # Test dissimilar default_realm and domain_realm map settings (no -r realm). -@@ -287,15 +284,13 @@ check_ulog(9, 1, 9, [None, pr1, pr3, pr2, pr2, pr2, pr2, pr1, pr1]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, False, 8, 9) - check_ulog(4, 6, 9, [None, pr2, pr1, pr1], slave1) --out = realm.run([kadminl, 'getprinc', pr1], env=slave1) --if 'Maximum renewable life: 0 days 22:00:00\n' not in out: -- fail('slave1 does not have modification from master') -+realm.run([kadminl, 'getprinc', pr1], env=slave1, -+ expected_msg='Maximum renewable life: 0 days 22:00:00\n') - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, False, 8, 9) - check_ulog(3, 7, 9, [None, pr1, pr1], slave2) --out = realm.run([kadminl, 'getprinc', pr1], env=slave2) --if 'Maximum renewable life: 0 days 22:00:00\n' not in out: -- fail('slave2 does not have modification from slave1') -+realm.run([kadminl, 'getprinc', pr1], env=slave2, -+ expected_msg='Maximum renewable life: 0 days 22:00:00\n') - - # Reset the ulog on slave1 to force a full resync from master. The - # resync will use the old dump file and then propagate changes. -@@ -317,15 +312,11 @@ check_ulog(10, 1, 10, [None, pr1, pr3, pr2, pr2, pr2, pr2, pr1, pr1, pr2]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, False, 9, 10) - check_ulog(5, 6, 10, [None, pr2, pr1, pr1, pr2], slave1) --out = realm.run([kadminl, 'getprinc', pr2], env=slave1) --if 'Attributes:\n' not in out: -- fail('slave1 does not have modification from master') -+realm.run([kadminl, 'getprinc', pr2], env=slave1, expected_msg='Attributes:\n') - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, False, 9, 10) - check_ulog(4, 7, 10, [None, pr1, pr1, pr2], slave2) --out = realm.run([kadminl, 'getprinc', pr2], env=slave2) --if 'Attributes:\n' not in out: -- fail('slave2 does not have modification from slave1') -+realm.run([kadminl, 'getprinc', pr2], env=slave2, expected_msg='Attributes:\n') - - # Create a policy and check that it propagates via full resync. - realm.run([kadminl, 'addpol', '-minclasses', '2', 'testpol']) -@@ -333,15 +324,13 @@ check_ulog(1, 1, 1, [None]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, True, 10, 1) - check_ulog(1, 1, 1, [None], slave1) --out = realm.run([kadminl, 'getpol', 'testpol'], env=slave1) --if 'Minimum number of password character classes: 2' not in out: -- fail('slave1 does not have policy from master') -+realm.run([kadminl, 'getpol', 'testpol'], env=slave1, -+ expected_msg='Minimum number of password character classes: 2') - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, True, 10, 1) - check_ulog(1, 1, 1, [None], slave2) --out = realm.run([kadminl, 'getpol', 'testpol'], env=slave2) --if 'Minimum number of password character classes: 2' not in out: -- fail('slave2 does not have policy from slave1') -+realm.run([kadminl, 'getpol', 'testpol'], env=slave2, -+ expected_msg='Minimum number of password character classes: 2') - - # Modify the policy and test that it also propagates via full resync. - realm.run([kadminl, 'modpol', '-minlength', '17', 'testpol']) -@@ -349,15 +338,13 @@ check_ulog(1, 1, 1, [None]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, True, 1, 1) - check_ulog(1, 1, 1, [None], slave1) --out = realm.run([kadminl, 'getpol', 'testpol'], env=slave1) --if 'Minimum password length: 17' not in out: -- fail('slave1 does not have policy change from master') -+realm.run([kadminl, 'getpol', 'testpol'], env=slave1, -+ expected_msg='Minimum password length: 17') - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, True, 1, 1) - check_ulog(1, 1, 1, [None], slave2) --out = realm.run([kadminl, 'getpol', 'testpol'], env=slave2) --if 'Minimum password length: 17' not in out: -- fail('slave2 does not have policy change from slave1') -+realm.run([kadminl, 'getpol', 'testpol'], env=slave2, -+ expected_msg='Minimum password length: 17') - - # Delete the policy and test that it propagates via full resync. - realm.run([kadminl, 'delpol', 'testpol']) -@@ -365,15 +352,13 @@ check_ulog(1, 1, 1, [None]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, True, 1, 1) - check_ulog(1, 1, 1, [None], slave1) --out = realm.run([kadminl, 'getpol', 'testpol'], env=slave1, expected_code=1) --if 'Policy does not exist' not in out: -- fail('slave1 did not get policy deletion from master') -+realm.run([kadminl, 'getpol', 'testpol'], env=slave1, expected_code=1, -+ expected_msg='Policy does not exist') - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, True, 1, 1) - check_ulog(1, 1, 1, [None], slave2) --out = realm.run([kadminl, 'getpol', 'testpol'], env=slave2, expected_code=1) --if 'Policy does not exist' not in out: -- fail('slave2 did not get policy deletion from slave1') -+realm.run([kadminl, 'getpol', 'testpol'], env=slave2, expected_code=1, -+ expected_msg='Policy does not exist') - - # Modify a principal on the master and test that it propagates incrementally. - realm.run([kadminl, 'modprinc', '-maxlife', '10 minutes', pr1]) -@@ -381,15 +366,13 @@ check_ulog(2, 1, 2, [None, pr1]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, False, 1, 2) - check_ulog(2, 1, 2, [None, pr1], slave1) --out = realm.run([kadminl, 'getprinc', pr1], env=slave1) --if 'Maximum ticket life: 0 days 00:10:00' not in out: -- fail('slave1 does not have modification from master') -+realm.run([kadminl, 'getprinc', pr1], env=slave1, -+ expected_msg='Maximum ticket life: 0 days 00:10:00') - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, False, 1, 2) - check_ulog(2, 1, 2, [None, pr1], slave2) --out = realm.run([kadminl, 'getprinc', pr1], env=slave2) --if 'Maximum ticket life: 0 days 00:10:00' not in out: -- fail('slave2 does not have modification from slave1') -+realm.run([kadminl, 'getprinc', pr1], env=slave2, -+ expected_msg='Maximum ticket life: 0 days 00:10:00') - - # Delete a principal and test that it propagates incrementally. - realm.run([kadminl, 'delprinc', pr3]) -@@ -397,15 +380,13 @@ check_ulog(3, 1, 3, [None, pr1, pr3]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, False, 2, 3) - check_ulog(3, 1, 3, [None, pr1, pr3], slave1) --out = realm.run([kadminl, 'getprinc', pr3], env=slave1, expected_code=1) --if 'Principal does not exist' not in out: -- fail('slave1 does not have principal deletion from master') -+realm.run([kadminl, 'getprinc', pr3], env=slave1, expected_code=1, -+ expected_msg='Principal does not exist') - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, False, 2, 3) - check_ulog(3, 1, 3, [None, pr1, pr3], slave2) --out = realm.run([kadminl, 'getprinc', pr3], env=slave2, expected_code=1) --if 'Principal does not exist' not in out: -- fail('slave2 does not have principal deletion from slave1') -+realm.run([kadminl, 'getprinc', pr3], env=slave2, expected_code=1, -+ expected_msg='Principal does not exist') - - # Rename a principal and test that it propagates incrementally. - renpr = "quacked@" + realm.realm -@@ -414,16 +395,14 @@ check_ulog(6, 1, 6, [None, pr1, pr3, renpr, pr1, renpr]) - kpropd1.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd1, False, 3, 6) - check_ulog(6, 1, 6, [None, pr1, pr3, renpr, pr1, renpr], slave1) --out = realm.run([kadminl, 'getprinc', pr1], env=slave1, expected_code=1) --if 'Principal does not exist' not in out: -- fail('slave1 does not have principal deletion from master') -+realm.run([kadminl, 'getprinc', pr1], env=slave1, expected_code=1, -+ expected_msg='Principal does not exist') - realm.run([kadminl, 'getprinc', renpr], env=slave1) - kpropd2.send_signal(signal.SIGUSR1) - wait_for_prop(kpropd2, False, 3, 6) - check_ulog(6, 1, 6, [None, pr1, pr3, renpr, pr1, renpr], slave2) --out = realm.run([kadminl, 'getprinc', pr1], env=slave2, expected_code=1) --if 'Principal does not exist' not in out: -- fail('slave2 does not have principal deletion from master') -+realm.run([kadminl, 'getprinc', pr1], env=slave2, expected_code=1, -+ expected_msg='Principal does not exist') - realm.run([kadminl, 'getprinc', renpr], env=slave2) - - pr1 = renpr -@@ -455,9 +434,8 @@ out = realm.run_kpropd_once(slave1, ['-d']) - if 'Got incremental updates (sno=2 ' not in out: - fail('Expected full dump and synchronized from kpropd -t') - check_ulog(2, 1, 2, [None, pr1], slave1) --out = realm.run([kadminl, 'getprinc', pr1], env=slave1) --if 'Maximum ticket life: 0 days 00:05:00' not in out: -- fail('slave1 does not have modification from master after kpropd -t') -+realm.run([kadminl, 'getprinc', pr1], env=slave1, -+ expected_msg='Maximum ticket life: 0 days 00:05:00') - - # Propagate a policy change via full resync. - realm.run([kadminl, 'addpol', '-minclasses', '3', 'testpol']) -@@ -467,8 +445,7 @@ if ('Full propagation transfer finished' not in out or - 'KDC is synchronized' not in out): - fail('Expected full dump and synchronized from kpropd -t') - check_ulog(1, 1, 1, [None], slave1) --out = realm.run([kadminl, 'getpol', 'testpol'], env=slave1) --if 'Minimum number of password character classes: 3' not in out: -- fail('slave1 does not have policy from master after kpropd -t') -+realm.run([kadminl, 'getpol', 'testpol'], env=slave1, -+ expected_msg='Minimum number of password character classes: 3') - - success('iprop tests') -diff --git a/src/tests/t_kadm5_hook.py b/src/tests/t_kadm5_hook.py -index 708e328b0..c1c8c9419 100755 ---- a/src/tests/t_kadm5_hook.py -+++ b/src/tests/t_kadm5_hook.py -@@ -7,12 +7,10 @@ plugin = os.path.join(buildtop, "plugins", "kadm5_hook", "test", - hook_krb5_conf = {'plugins': {'kadm5_hook': { 'module': 'test:' + plugin}}} - - realm = K5Realm(krb5_conf=hook_krb5_conf, create_user=False, create_host=False) --output = realm.run([kadminl, 'addprinc', '-randkey', 'test']) --if "create: stage precommit" not in output: -- fail('kadm5_hook test output not found') -+realm.run([kadminl, 'addprinc', '-randkey', 'test'], -+ expected_msg='create: stage precommit') - --output = realm.run([kadminl, 'renprinc', 'test', 'test2']) --if "rename: stage precommit" not in output: -- fail('kadm5_hook test output not found') -+realm.run([kadminl, 'renprinc', 'test', 'test2'], -+ expected_msg='rename: stage precommit') - - success('kadm5_hook') -diff --git a/src/tests/t_kadmin_acl.py b/src/tests/t_kadmin_acl.py -index 188929a76..bbbbae99e 100755 ---- a/src/tests/t_kadmin_acl.py -+++ b/src/tests/t_kadmin_acl.py -@@ -87,27 +87,24 @@ for pw in (['-pw', 'newpw'], ['-randkey']): - args = pw + ks - kadmin_as(all_changepw, ['cpw'] + args + ['unselected']) - kadmin_as(some_changepw, ['cpw'] + args + ['selected']) -- out = kadmin_as(none, ['cpw'] + args + ['selected'], expected_code=1) -- if 'Operation requires ``change-password\'\' privilege' not in out: -- fail('cpw failure (no perms)') -- out = kadmin_as(some_changepw, ['cpw'] + args + ['unselected'], -- expected_code=1) -- if 'Operation requires ``change-password\'\' privilege' not in out: -- fail('cpw failure (target)') -- out = kadmin_as(none, ['cpw'] + args + ['none']) -+ msg = "Operation requires ``change-password'' privilege" -+ kadmin_as(none, ['cpw'] + args + ['selected'], expected_code=1, -+ expected_msg=msg) -+ kadmin_as(some_changepw, ['cpw'] + args + ['unselected'], -+ expected_code=1, expected_msg=msg) -+ kadmin_as(none, ['cpw'] + args + ['none']) - realm.run([kadminl, 'modprinc', '-policy', 'minlife', 'none']) -- out = kadmin_as(none, ['cpw'] + args + ['none'], expected_code=1) -- if 'Current password\'s minimum life has not expired' not in out: -- fail('cpw failure (minimum life)') -+ msg = "Current password's minimum life has not expired" -+ kadmin_as(none, ['cpw'] + args + ['none'], expected_code=1, -+ expected_msg=msg) - realm.run([kadminl, 'modprinc', '-clearpolicy', 'none']) - realm.run([kadminl, 'delprinc', 'selected']) - realm.run([kadminl, 'delprinc', 'unselected']) - - kadmin_as(all_add, ['addpol', 'policy']) - realm.run([kadminl, 'delpol', 'policy']) --out = kadmin_as(none, ['addpol', 'policy'], expected_code=1) --if 'Operation requires ``add\'\' privilege' not in out: -- fail('addpol failure (no perms)') -+kadmin_as(none, ['addpol', 'policy'], expected_code=1, -+ expected_msg="Operation requires ``add'' privilege") - - # addprinc can generate two different RPC calls depending on options. - for ks in ([], ['-e', 'aes256-cts']): -@@ -117,89 +114,62 @@ for ks in ([], ['-e', 'aes256-cts']): - kadmin_as(some_add, ['addprinc'] + args + ['selected']) - realm.run([kadminl, 'delprinc', 'selected']) - kadmin_as(restricted_add, ['addprinc'] + args + ['unselected']) -- out = realm.run([kadminl, 'getprinc', 'unselected']) -- if 'REQUIRES_PRE_AUTH' not in out: -- fail('addprinc success (restrictions) -- restriction check') -+ realm.run([kadminl, 'getprinc', 'unselected'], -+ expected_msg='REQUIRES_PRE_AUTH') - realm.run([kadminl, 'delprinc', 'unselected']) -- out = kadmin_as(none, ['addprinc'] + args + ['selected'], expected_code=1) -- if 'Operation requires ``add\'\' privilege' not in out: -- fail('addprinc failure (no perms)') -- out = kadmin_as(some_add, ['addprinc'] + args + ['unselected'], -- expected_code=1) -- if 'Operation requires ``add\'\' privilege' not in out: -- fail('addprinc failure (target)') -+ kadmin_as(none, ['addprinc'] + args + ['selected'], expected_code=1, -+ expected_msg="Operation requires ``add'' privilege") -+ kadmin_as(some_add, ['addprinc'] + args + ['unselected'], expected_code=1, -+ expected_msg="Operation requires ``add'' privilege") - - realm.addprinc('unselected', 'pw') - kadmin_as(all_delete, ['delprinc', 'unselected']) - realm.addprinc('selected', 'pw') - kadmin_as(some_delete, ['delprinc', 'selected']) - realm.addprinc('unselected', 'pw') --out = kadmin_as(none, ['delprinc', 'unselected'], expected_code=1) --if 'Operation requires ``delete\'\' privilege' not in out: -- fail('delprinc failure (no perms)') --out = kadmin_as(some_delete, ['delprinc', 'unselected'], expected_code=1) --if 'Operation requires ``delete\'\' privilege' not in out: -- fail('delprinc failure (no target)') -+kadmin_as(none, ['delprinc', 'unselected'], expected_code=1, -+ expected_msg="Operation requires ``delete'' privilege") -+kadmin_as(some_delete, ['delprinc', 'unselected'], expected_code=1, -+ expected_msg="Operation requires ``delete'' privilege") - realm.run([kadminl, 'delprinc', 'unselected']) - --out = kadmin_as(all_inquire, ['getpol', 'minlife']) --if 'Policy: minlife' not in out: -- fail('getpol success (acl)') --out = kadmin_as(none, ['getpol', 'minlife'], expected_code=1) --if 'Operation requires ``get\'\' privilege' not in out: -- fail('getpol failure (no perms)') -+kadmin_as(all_inquire, ['getpol', 'minlife'], expected_msg='Policy: minlife') -+kadmin_as(none, ['getpol', 'minlife'], expected_code=1, -+ expected_msg="Operation requires ``get'' privilege") - realm.run([kadminl, 'modprinc', '-policy', 'minlife', 'none']) --out = kadmin_as(none, ['getpol', 'minlife']) --if 'Policy: minlife' not in out: -- fail('getpol success (self policy exemption)') -+kadmin_as(none, ['getpol', 'minlife'], expected_msg='Policy: minlife') - realm.run([kadminl, 'modprinc', '-clearpolicy', 'none']) - - realm.addprinc('selected', 'pw') - realm.addprinc('unselected', 'pw') --out = kadmin_as(all_inquire, ['getprinc', 'unselected']) --if 'Principal: unselected@KRBTEST.COM' not in out: -- fail('getprinc success (acl)') --out = kadmin_as(some_inquire, ['getprinc', 'selected']) --if 'Principal: selected@KRBTEST.COM' not in out: -- fail('getprinc success (target)') --out = kadmin_as(none, ['getprinc', 'selected'], expected_code=1) --if 'Operation requires ``get\'\' privilege' not in out: -- fail('getprinc failure (no perms)') --out = kadmin_as(some_inquire, ['getprinc', 'unselected'], expected_code=1) --if 'Operation requires ``get\'\' privilege' not in out: -- fail('getprinc failure (target)') --out = kadmin_as(none, ['getprinc', 'none']) --if 'Principal: none@KRBTEST.COM' not in out: -- fail('getprinc success (self exemption)') -+kadmin_as(all_inquire, ['getprinc', 'unselected'], -+ expected_msg='Principal: unselected@KRBTEST.COM') -+kadmin_as(some_inquire, ['getprinc', 'selected'], -+ expected_msg='Principal: selected@KRBTEST.COM') -+kadmin_as(none, ['getprinc', 'selected'], expected_code=1, -+ expected_msg="Operation requires ``get'' privilege") -+kadmin_as(some_inquire, ['getprinc', 'unselected'], expected_code=1, -+ expected_msg="Operation requires ``get'' privilege") -+kadmin_as(none, ['getprinc', 'none'], -+ expected_msg='Principal: none@KRBTEST.COM') - realm.run([kadminl, 'delprinc', 'selected']) - realm.run([kadminl, 'delprinc', 'unselected']) - --out = kadmin_as(all_list, ['listprincs']) --if 'K/M@KRBTEST.COM' not in out: -- fail('listprincs success (acl)') --out = kadmin_as(none, ['listprincs'], expected_code=1) --if 'Operation requires ``list\'\' privilege' not in out: -- fail('listprincs failure (no perms)') -+kadmin_as(all_list, ['listprincs'], expected_msg='K/M@KRBTEST.COM') -+kadmin_as(none, ['listprincs'], expected_code=1, -+ expected_msg="Operation requires ``list'' privilege") - - realm.addprinc('selected', 'pw') - realm.addprinc('unselected', 'pw') - realm.run([kadminl, 'setstr', 'selected', 'key', 'value']) - realm.run([kadminl, 'setstr', 'unselected', 'key', 'value']) --out = kadmin_as(all_inquire, ['getstrs', 'unselected']) --if 'key: value' not in out: -- fail('getstrs success (acl)') --out = kadmin_as(some_inquire, ['getstrs', 'selected']) --if 'key: value' not in out: -- fail('getstrs success (target)') --out = kadmin_as(none, ['getstrs', 'selected'], expected_code=1) --if 'Operation requires ``get\'\' privilege' not in out: -- fail('getstrs failure (no perms)') --out = kadmin_as(some_inquire, ['getstrs', 'unselected'], expected_code=1) --if 'Operation requires ``get\'\' privilege' not in out: -- fail('getstrs failure (target)') --out = kadmin_as(none, ['getstrs', 'none']) --if '(No string attributes.)' not in out: -- fail('getstrs success (self exemption)') -+kadmin_as(all_inquire, ['getstrs', 'unselected'], expected_msg='key: value') -+kadmin_as(some_inquire, ['getstrs', 'selected'], expected_msg='key: value') -+kadmin_as(none, ['getstrs', 'selected'], expected_code=1, -+ expected_msg="Operation requires ``get'' privilege") -+kadmin_as(some_inquire, ['getstrs', 'unselected'], expected_code=1, -+ expected_msg="Operation requires ``get'' privilege") -+kadmin_as(none, ['getstrs', 'none'], expected_msg='(No string attributes.)') - realm.run([kadminl, 'delprinc', 'selected']) - realm.run([kadminl, 'delprinc', 'unselected']) - -@@ -207,27 +177,21 @@ out = kadmin_as(all_modify, ['modpol', '-maxlife', '1 hour', 'policy'], - expected_code=1) - if 'Operation requires' in out: - fail('modpol success (acl)') --out = kadmin_as(none, ['modpol', '-maxlife', '1 hour', 'policy'], -- expected_code=1) --if 'Operation requires ``modify\'\' privilege' not in out: -- fail('modpol failure (no perms)') -+kadmin_as(none, ['modpol', '-maxlife', '1 hour', 'policy'], expected_code=1, -+ expected_msg="Operation requires ``modify'' privilege") - - realm.addprinc('selected', 'pw') - realm.addprinc('unselected', 'pw') - kadmin_as(all_modify, ['modprinc', '-maxlife', '1 hour', 'unselected']) - kadmin_as(some_modify, ['modprinc', '-maxlife', '1 hour', 'selected']) - kadmin_as(restricted_modify, ['modprinc', '-maxlife', '1 hour', 'unselected']) --out = realm.run([kadminl, 'getprinc', 'unselected']) --if 'REQUIRES_PRE_AUTH' not in out: -- fail('addprinc success (restrictions) -- restriction check') --out = kadmin_as(all_inquire, ['modprinc', '-maxlife', '1 hour', 'selected'], -- expected_code=1) --if 'Operation requires ``modify\'\' privilege' not in out: -- fail('addprinc failure (no perms)') --out = kadmin_as(some_modify, ['modprinc', '-maxlife', '1 hour', 'unselected'], -- expected_code=1) --if 'Operation requires' not in out: -- fail('modprinc failure (target)') -+realm.run([kadminl, 'getprinc', 'unselected'], -+ expected_msg='REQUIRES_PRE_AUTH') -+kadmin_as(all_inquire, ['modprinc', '-maxlife', '1 hour', 'selected'], -+ expected_code=1, -+ expected_msg="Operation requires ``modify'' privilege") -+kadmin_as(some_modify, ['modprinc', '-maxlife', '1 hour', 'unselected'], -+ expected_code=1, expected_msg='Operation requires') - realm.run([kadminl, 'delprinc', 'selected']) - realm.run([kadminl, 'delprinc', 'unselected']) - -@@ -235,12 +199,10 @@ realm.addprinc('selected', 'pw') - realm.addprinc('unselected', 'pw') - kadmin_as(all_modify, ['purgekeys', 'unselected']) - kadmin_as(some_modify, ['purgekeys', 'selected']) --out = kadmin_as(none, ['purgekeys', 'selected'], expected_code=1) --if 'Operation requires ``modify\'\' privilege' not in out: -- fail('purgekeys failure (no perms)') --out = kadmin_as(some_modify, ['purgekeys', 'unselected'], expected_code=1) --if 'Operation requires ``modify\'\' privilege' not in out: -- fail('purgekeys failure (target)') -+kadmin_as(none, ['purgekeys', 'selected'], expected_code=1, -+ expected_msg="Operation requires ``modify'' privilege") -+kadmin_as(some_modify, ['purgekeys', 'unselected'], expected_code=1, -+ expected_msg="Operation requires ``modify'' privilege") - kadmin_as(none, ['purgekeys', 'none']) - realm.run([kadminl, 'delprinc', 'selected']) - realm.run([kadminl, 'delprinc', 'unselected']) -@@ -250,36 +212,27 @@ kadmin_as(all_rename, ['renprinc', 'from', 'to']) - realm.run([kadminl, 'renprinc', 'to', 'from']) - kadmin_as(some_rename, ['renprinc', 'from', 'to']) - realm.run([kadminl, 'renprinc', 'to', 'from']) --out = kadmin_as(all_add, ['renprinc', 'from', 'to'], expected_code=1) --if 'Operation requires ``delete\'\' privilege' not in out: -- fail('renprinc failure (no delete perms)') --out = kadmin_as(all_delete, ['renprinc', 'from', 'to'], expected_code=1) --if 'Operation requires ``add\'\' privilege' not in out: -- fail('renprinc failure (no add perms)') --out = kadmin_as(some_rename, ['renprinc', 'from', 'notto'], expected_code=1) --if 'Operation requires ``add\'\' privilege' not in out: -- fail('renprinc failure (new target)') -+kadmin_as(all_add, ['renprinc', 'from', 'to'], expected_code=1, -+ expected_msg="Operation requires ``delete'' privilege") -+kadmin_as(all_delete, ['renprinc', 'from', 'to'], expected_code=1, -+ expected_msg="Operation requires ``add'' privilege") -+kadmin_as(some_rename, ['renprinc', 'from', 'notto'], expected_code=1, -+ expected_msg="Operation requires ``add'' privilege") - realm.run([kadminl, 'renprinc', 'from', 'notfrom']) --out = kadmin_as(some_rename, ['renprinc', 'notfrom', 'to'], expected_code=1) --if 'Operation requires ``delete\'\' privilege' not in out: -- fail('renprinc failure (old target)') --out = kadmin_as(restricted_rename, ['renprinc', 'notfrom', 'to'], -- expected_code=1) --if 'Operation requires ``add\'\' privilege' not in out: -- fail('renprinc failure (restrictions)') -+kadmin_as(some_rename, ['renprinc', 'notfrom', 'to'], expected_code=1, -+ expected_msg="Operation requires ``delete'' privilege") -+kadmin_as(restricted_rename, ['renprinc', 'notfrom', 'to'], expected_code=1, -+ expected_msg="Operation requires ``add'' privilege") - realm.run([kadminl, 'delprinc', 'notfrom']) - - realm.addprinc('selected', 'pw') - realm.addprinc('unselected', 'pw') - kadmin_as(all_modify, ['setstr', 'unselected', 'key', 'value']) - kadmin_as(some_modify, ['setstr', 'selected', 'key', 'value']) --out = kadmin_as(none, ['setstr', 'selected', 'key', 'value'], expected_code=1) --if 'Operation requires ``modify\'\' privilege' not in out: -- fail('addprinc failure (no perms)') --out = kadmin_as(some_modify, ['setstr', 'unselected', 'key', 'value'], -- expected_code=1) --if 'Operation requires' not in out: -- fail('modprinc failure (target)') -+kadmin_as(none, ['setstr', 'selected', 'key', 'value'], expected_code=1, -+ expected_msg="Operation requires ``modify'' privilege") -+kadmin_as(some_modify, ['setstr', 'unselected', 'key', 'value'], -+ expected_code=1, expected_msg='Operation requires') - realm.run([kadminl, 'delprinc', 'selected']) - realm.run([kadminl, 'delprinc', 'unselected']) - -@@ -287,28 +240,21 @@ kadmin_as(admin, ['addprinc', '-pw', 'pw', 'anytarget']) - realm.run([kadminl, 'delprinc', 'anytarget']) - kadmin_as(wctarget, ['addprinc', '-pw', 'pw', 'wild/card']) - realm.run([kadminl, 'delprinc', 'wild/card']) --out = kadmin_as(wctarget, ['addprinc', '-pw', 'pw', 'wild/card/extra'], -- expected_code=1) --if 'Operation requires' not in out: -- fail('addprinc failure (target wildcard extra component)') -+kadmin_as(wctarget, ['addprinc', '-pw', 'pw', 'wild/card/extra'], -+ expected_code=1, expected_msg='Operation requires') - realm.addprinc('admin/user', 'pw') - kadmin_as(admin, ['delprinc', 'admin/user']) --out = kadmin_as(admin, ['delprinc', 'none'], expected_code=1) --if 'Operation requires' not in out: -- fail('delprinc failure (wildcard backreferences not matched)') -+kadmin_as(admin, ['delprinc', 'none'], expected_code=1, -+ expected_msg='Operation requires') - realm.addprinc('four/one/three', 'pw') - kadmin_as(onetwothreefour, ['delprinc', 'four/one/three']) - - kadmin_as(restrictions, ['addprinc', '-pw', 'pw', 'type1']) --out = realm.run([kadminl, 'getprinc', 'type1']) --if 'Policy: minlife' not in out: -- fail('restriction (policy)') -+realm.run([kadminl, 'getprinc', 'type1'], expected_msg='Policy: minlife') - realm.run([kadminl, 'delprinc', 'type1']) - kadmin_as(restrictions, ['addprinc', '-pw', 'pw', '-policy', 'minlife', - 'type2']) --out = realm.run([kadminl, 'getprinc', 'type2']) --if 'Policy: [none]' not in out: -- fail('restriction (clearpolicy)') -+realm.run([kadminl, 'getprinc', 'type2'], expected_msg='Policy: [none]') - realm.run([kadminl, 'delprinc', 'type2']) - kadmin_as(restrictions, ['addprinc', '-pw', 'pw', '-maxlife', '1 minute', - 'type3']) -@@ -319,40 +265,32 @@ if ('Maximum ticket life: 0 days 00:01:00' not in out or - realm.run([kadminl, 'delprinc', 'type3']) - kadmin_as(restrictions, ['addprinc', '-pw', 'pw', '-maxrenewlife', '1 day', - 'type3']) --out = realm.run([kadminl, 'getprinc', 'type3']) --if 'Maximum renewable life: 0 days 02:00:00' not in out: -- fail('restriction (maxrenewlife high)') -+realm.run([kadminl, 'getprinc', 'type3'], -+ expected_msg='Maximum renewable life: 0 days 02:00:00') - - realm.run([kadminl, 'addprinc', '-pw', 'pw', 'extractkeys']) --out = kadmin_as(all_wildcard, ['ktadd', '-norandkey', 'extractkeys'], -- expected_code=1) --if 'Operation requires ``extract-keys\'\' privilege' not in out: -- fail('extractkeys failure (all_wildcard)') -+kadmin_as(all_wildcard, ['ktadd', '-norandkey', 'extractkeys'], -+ expected_code=1, -+ expected_msg="Operation requires ``extract-keys'' privilege") - kadmin_as(all_extract, ['ktadd', '-norandkey', 'extractkeys']) - realm.kinit('extractkeys', flags=['-k']) - os.remove(realm.keytab) - - kadmin_as(all_modify, ['modprinc', '+lockdown_keys', 'extractkeys']) --out = kadmin_as(all_changepw, ['cpw', '-pw', 'newpw', 'extractkeys'], -- expected_code=1) --if 'Operation requires ``change-password\'\' privilege' not in out: -- fail('extractkeys failure (all_changepw)') -+kadmin_as(all_changepw, ['cpw', '-pw', 'newpw', 'extractkeys'], -+ expected_code=1, -+ expected_msg="Operation requires ``change-password'' privilege") - kadmin_as(all_changepw, ['cpw', '-randkey', 'extractkeys']) --out = kadmin_as(all_extract, ['ktadd', '-norandkey', 'extractkeys'], -- expected_code=1) --if 'Operation requires ``extract-keys\'\' privilege' not in out: -- fail('extractkeys failure (all_extract)') --out = kadmin_as(all_delete, ['delprinc', 'extractkeys'], expected_code=1) --if 'Operation requires ``delete\'\' privilege' not in out: -- fail('extractkeys failure (all_delete)') --out = kadmin_as(all_rename, ['renprinc', 'extractkeys', 'renamedprinc'], -- expected_code=1) --if 'Operation requires ``delete\'\' privilege' not in out: -- fail('extractkeys failure (all_rename)') --out = kadmin_as(all_modify, ['modprinc', '-lockdown_keys', 'extractkeys'], -- expected_code=1) --if 'Operation requires ``modify\'\' privilege' not in out: -- fail('extractkeys failure (all_modify)') -+kadmin_as(all_extract, ['ktadd', '-norandkey', 'extractkeys'], expected_code=1, -+ expected_msg="Operation requires ``extract-keys'' privilege") -+kadmin_as(all_delete, ['delprinc', 'extractkeys'], expected_code=1, -+ expected_msg="Operation requires ``delete'' privilege") -+kadmin_as(all_rename, ['renprinc', 'extractkeys', 'renamedprinc'], -+ expected_code=1, -+ expected_msg="Operation requires ``delete'' privilege") -+kadmin_as(all_modify, ['modprinc', '-lockdown_keys', 'extractkeys'], -+ expected_code=1, -+ expected_msg="Operation requires ``modify'' privilege") - realm.run([kadminl, 'modprinc', '-lockdown_keys', 'extractkeys']) - kadmin_as(all_extract, ['ktadd', '-norandkey', 'extractkeys']) - realm.kinit('extractkeys', flags=['-k']) -diff --git a/src/tests/t_kadmin_parsing.py b/src/tests/t_kadmin_parsing.py -index 92d72d2b0..8de387c64 100644 ---- a/src/tests/t_kadmin_parsing.py -+++ b/src/tests/t_kadmin_parsing.py -@@ -57,33 +57,27 @@ realm = K5Realm(create_host=False, get_creds=False) - realm.run([kadminl, 'addpol', 'pol']) - for instr, outstr in intervals: - realm.run([kadminl, 'modprinc', '-maxlife', instr, realm.user_princ]) -- out = realm.run([kadminl, 'getprinc', realm.user_princ]) -- if 'Maximum ticket life: ' + outstr + '\n' not in out: -- fail('princ maxlife: ' + instr) -+ msg = 'Maximum ticket life: ' + outstr + '\n' -+ realm.run([kadminl, 'getprinc', realm.user_princ], expected_msg=msg) - - realm.run([kadminl, 'modprinc', '-maxrenewlife', instr, realm.user_princ]) -- out = realm.run([kadminl, 'getprinc', realm.user_princ]) -- if 'Maximum renewable life: ' + outstr + '\n' not in out: -- fail('princ maxrenewlife: ' + instr) -+ msg = 'Maximum renewable life: ' + outstr + '\n' -+ realm.run([kadminl, 'getprinc', realm.user_princ], expected_msg=msg) - - realm.run([kadminl, 'modpol', '-maxlife', instr, 'pol']) -- out = realm.run([kadminl, 'getpol', 'pol']) -- if 'Maximum password life: ' + outstr + '\n' not in out: -- fail('pol maxlife: ' + instr) -+ msg = 'Maximum password life: ' + outstr + '\n' -+ realm.run([kadminl, 'getpol', 'pol'], expected_msg=msg) - - realm.run([kadminl, 'modpol', '-minlife', instr, 'pol']) -- out = realm.run([kadminl, 'getpol', 'pol']) -- if 'Minimum password life: ' + outstr + '\n' not in out: -- fail('pol maxlife: ' + instr) -+ msg = 'Minimum password life: ' + outstr + '\n' -+ realm.run([kadminl, 'getpol', 'pol'], expected_msg=msg) - - realm.run([kadminl, 'modpol', '-failurecountinterval', instr, 'pol']) -- out = realm.run([kadminl, 'getpol', 'pol']) -- if 'Password failure count reset interval: ' + outstr + '\n' not in out: -- fail('pol maxlife: ' + instr) -+ msg = 'Password failure count reset interval: ' + outstr + '\n' -+ realm.run([kadminl, 'getpol', 'pol'], expected_msg=msg) - - realm.run([kadminl, 'modpol', '-lockoutduration', instr, 'pol']) -- out = realm.run([kadminl, 'getpol', 'pol']) -- if 'Password lockout duration: ' + outstr + '\n' not in out: -- fail('pol maxlife: ' + instr) -+ msg = 'Password lockout duration: ' + outstr + '\n' -+ realm.run([kadminl, 'getpol', 'pol'], expected_msg=msg) - - success('kadmin command parsing tests') -diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py -index 185225afa..44635b089 100755 ---- a/src/tests/t_kdb.py -+++ b/src/tests/t_kdb.py -@@ -167,47 +167,31 @@ if out != 'KRBTEST.COM\n': - # because we're sticking a krbPrincipalAux objectclass onto a subtree - # krbContainer, but it works and it avoids having to load core.schema - # in the test LDAP server. --out = realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=krb5', 'princ1'], -- expected_code=1) --if 'DN is out of the realm subtree' not in out: -- fail('Unexpected kadmin.local output for out-of-realm dn') -+realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=krb5', 'princ1'], -+ expected_code=1, expected_msg='DN is out of the realm subtree') - realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=t2,cn=krb5', 'princ1']) --out = realm.run([kadminl, 'getprinc', 'princ1']) --if 'Principal: princ1' not in out: -- fail('Unexpected kadmin.local output after creating princ1') --out = realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=t2,cn=krb5', -- 'again'], expected_code=1) --if 'ldap object is already kerberized' not in out: -- fail('Unexpected kadmin.local output trying to re-kerberize DN') -+realm.run([kadminl, 'getprinc', 'princ1'], expected_msg='Principal: princ1') -+realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=t2,cn=krb5', 'again'], -+ expected_code=1, expected_msg='ldap object is already kerberized') - # Check that we can't set linkdn on a non-standalone object. --out = realm.run([kadminl, 'modprinc', '-x', 'linkdn=cn=t1,cn=krb5', 'princ1'], -- expected_code=1) --if 'link information can not be set' not in out: -- fail('Unexpected kadmin.local output trying to set linkdn on princ1') -+realm.run([kadminl, 'modprinc', '-x', 'linkdn=cn=t1,cn=krb5', 'princ1'], -+ expected_code=1, expected_msg='link information can not be set') - - # Create a principal with a specified linkdn. --out = realm.run([kadminl, 'ank', '-randkey', '-x', 'linkdn=cn=krb5', 'princ2'], -- expected_code=1) --if 'DN is out of the realm subtree' not in out: -- fail('Unexpected kadmin.local output for out-of-realm linkdn') -+realm.run([kadminl, 'ank', '-randkey', '-x', 'linkdn=cn=krb5', 'princ2'], -+ expected_code=1, expected_msg='DN is out of the realm subtree') - realm.run([kadminl, 'ank', '-randkey', '-x', 'linkdn=cn=t1,cn=krb5', 'princ2']) - # Check that we can't reset linkdn. --out = realm.run([kadminl, 'modprinc', '-x', 'linkdn=cn=t2,cn=krb5', 'princ2'], -- expected_code=1) --if 'kerberos principal is already linked' not in out: -- fail('Unexpected kadmin.local output for re-specified linkdn') -+realm.run([kadminl, 'modprinc', '-x', 'linkdn=cn=t2,cn=krb5', 'princ2'], -+ expected_code=1, expected_msg='kerberos principal is already linked') - - # Create a principal with a specified containerdn. --out = realm.run([kadminl, 'ank', '-randkey', '-x', 'containerdn=cn=krb5', -- 'princ3'], expected_code=1) --if 'DN is out of the realm subtree' not in out: -- fail('Unexpected kadmin.local output for out-of-realm containerdn') -+realm.run([kadminl, 'ank', '-randkey', '-x', 'containerdn=cn=krb5', 'princ3'], -+ expected_code=1, expected_msg='DN is out of the realm subtree') - realm.run([kadminl, 'ank', '-randkey', '-x', 'containerdn=cn=t1,cn=krb5', - 'princ3']) --out = realm.run([kadminl, 'modprinc', '-x', 'containerdn=cn=t2,cn=krb5', -- 'princ3'], expected_code=1) --if 'containerdn option not supported' not in out: -- fail('Unexpected kadmin.local output trying to reset containerdn') -+realm.run([kadminl, 'modprinc', '-x', 'containerdn=cn=t2,cn=krb5', 'princ3'], -+ expected_code=1, expected_msg='containerdn option not supported') - - # Create and modify a ticket policy. - kldaputil(['create_policy', '-maxtktlife', '3hour', '-maxrenewlife', '6hour', -@@ -255,9 +239,8 @@ if out: - kldaputil(['create_policy', 'tktpol2']) - - # Try to create a password policy conflicting with a ticket policy. --out = realm.run([kadminl, 'addpol', 'tktpol2'], expected_code=1) --if 'Already exists while creating policy "tktpol2"' not in out: -- fail('Expected error not seen in kadmin.local output') -+realm.run([kadminl, 'addpol', 'tktpol2'], expected_code=1, -+ expected_msg='Already exists while creating policy "tktpol2"') - - # Try to create a ticket policy conflicting with a password policy. - realm.run([kadminl, 'addpol', 'pwpol']) -@@ -266,16 +249,13 @@ if 'Already exists while creating policy object' not in out: - fail('Expected error not seen in kdb5_ldap_util output') - - # Try to use a password policy as a ticket policy. --out = realm.run([kadminl, 'modprinc', '-x', 'tktpolicy=pwpol', 'princ4'], -- expected_code=1) --if 'Object class violation' not in out: -- fail('Expected error not seem in kadmin.local output') -+realm.run([kadminl, 'modprinc', '-x', 'tktpolicy=pwpol', 'princ4'], -+ expected_code=1, expected_msg='Object class violation') - - # Use a ticket policy as a password policy (CVE-2014-5353). This - # works with a warning; use kadmin.local -q so the warning is shown. --out = realm.run([kadminl, '-q', 'modprinc -policy tktpol2 princ4']) --if 'WARNING: policy "tktpol2" does not exist' not in out: -- fail('Expected error not seen in kadmin.local output') -+realm.run([kadminl, '-q', 'modprinc -policy tktpol2 princ4'], -+ expected_msg='WARNING: policy "tktpol2" does not exist') - - # Do some basic tests with a KDC against the LDAP module, exercising the - # db_args processing code. -@@ -298,9 +278,8 @@ if 'krbPrincipalAuthInd: otp' not in out: - if 'krbPrincipalAuthInd: radius' not in out: - fail('Expected krbPrincipalAuthInd value not in output') - --out = realm.run([kadminl, 'getstrs', 'authind']) --if 'require_auth: otp radius' not in out: -- fail('Expected auth indicators value not in output') -+realm.run([kadminl, 'getstrs', 'authind'], -+ expected_msg='require_auth: otp radius') - - # Test service principal aliases. - realm.addprinc('canon', password('canon')) -@@ -311,12 +290,10 @@ ldap_modify('dn: krbPrincipalName=canon@KRBTEST.COM,cn=t1,cn=krb5\n' - '-\n' - 'add: krbCanonicalName\n' - 'krbCanonicalName: canon@KRBTEST.COM\n') --out = realm.run([kadminl, 'getprinc', 'alias']) --if 'Principal: canon@KRBTEST.COM\n' not in out: -- fail('Could not fetch canon through alias') --out = realm.run([kadminl, 'getprinc', 'canon']) --if 'Principal: canon@KRBTEST.COM\n' not in out: -- fail('Could not fetch canon through canon') -+realm.run([kadminl, 'getprinc', 'alias'], -+ expected_msg='Principal: canon@KRBTEST.COM\n') -+realm.run([kadminl, 'getprinc', 'canon'], -+ expected_msg='Principal: canon@KRBTEST.COM\n') - realm.run([kvno, 'alias']) - realm.run([kvno, 'canon']) - out = realm.run([klist]) -@@ -334,9 +311,8 @@ ldap_modify('dn: krbPrincipalName=krbtgt/KRBTEST.COM@KRBTEST.COM,' - '-\n' - 'add: krbCanonicalName\n' - 'krbCanonicalName: krbtgt/KRBTEST.COM@KRBTEST.COM\n') --out = realm.run([kadminl, 'getprinc', 'tgtalias']) --if 'Principal: krbtgt/KRBTEST.COM@KRBTEST.COM' not in out: -- fail('Could not fetch krbtgt through tgtalias') -+realm.run([kadminl, 'getprinc', 'tgtalias'], -+ expected_msg='Principal: krbtgt/KRBTEST.COM@KRBTEST.COM') - realm.kinit(realm.user_princ, password('user')) - realm.run([kvno, 'tgtalias']) - realm.klist(realm.user_princ, 'tgtalias@KRBTEST.COM') -@@ -352,9 +328,8 @@ realm.klist(realm.user_princ, 'alias@KRBTEST.COM') - - # Test client principal aliases, with and without preauth. - realm.kinit('canon', password('canon')) --out = realm.kinit('alias', password('canon'), expected_code=1) --if 'not found in Kerberos database' not in out: -- fail('Wrong error message for kinit to alias without -C flag') -+realm.kinit('alias', password('canon'), expected_code=1, -+ expected_msg='not found in Kerberos database') - realm.kinit('alias', password('canon'), ['-C']) - realm.run([kvno, 'alias']) - realm.klist('canon@KRBTEST.COM', 'alias@KRBTEST.COM') -@@ -413,31 +388,24 @@ realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts,aes128-cts', - 'kvnoprinc']) - realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', - 'aes256-cts,aes128-cts', 'kvnoprinc']) --out = realm.run([kadminl, 'getprinc', 'kvnoprinc']) --if 'Number of keys: 4' not in out: -- fail('After cpw -keepold, wrong number of keys') -+realm.run([kadminl, 'getprinc', 'kvnoprinc'], expected_msg='Number of keys: 4') - realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', - 'aes256-cts,aes128-cts', 'kvnoprinc']) --out = realm.run([kadminl, 'getprinc', 'kvnoprinc']) --if 'Number of keys: 6' not in out: -- fail('After cpw -keepold, wrong number of keys') -+realm.run([kadminl, 'getprinc', 'kvnoprinc'], expected_msg='Number of keys: 6') - - # Regression test for #8041 (NULL dereference on keyless principals). - realm.run([kadminl, 'addprinc', '-nokey', 'keylessprinc']) --out = realm.run([kadminl, 'getprinc', 'keylessprinc']) --if 'Number of keys: 0' not in out: -- fail('Failed to create a principal with no keys') -+realm.run([kadminl, 'getprinc', 'keylessprinc'], -+ expected_msg='Number of keys: 0') - realm.run([kadminl, 'cpw', '-randkey', '-e', 'aes256-cts,aes128-cts', - 'keylessprinc']) - realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', - 'aes256-cts,aes128-cts', 'keylessprinc']) --out = realm.run([kadminl, 'getprinc', 'keylessprinc']) --if 'Number of keys: 4' not in out: -- fail('Failed to add keys to keylessprinc') -+realm.run([kadminl, 'getprinc', 'keylessprinc'], -+ expected_msg='Number of keys: 4') - realm.run([kadminl, 'purgekeys', '-all', 'keylessprinc']) --out = realm.run([kadminl, 'getprinc', 'keylessprinc']) --if 'Number of keys: 0' not in out: -- fail('After purgekeys -all, keys remain') -+realm.run([kadminl, 'getprinc', 'keylessprinc'], -+ expected_msg='Number of keys: 0') - - # Test for 8354 (old password history entries when -keepold is used) - realm.run([kadminl, 'addpol', '-history', '2', 'keepoldpasspol']) -@@ -451,9 +419,8 @@ realm.stop() - # Briefly test dump and load. - dumpfile = os.path.join(realm.testdir, 'dump') - realm.run([kdb5_util, 'dump', dumpfile]) --out = realm.run([kdb5_util, 'load', dumpfile], expected_code=1) --if 'KDB module requires -update argument' not in out: -- fail('Unexpected error from kdb5_util load without -update') -+realm.run([kdb5_util, 'load', dumpfile], expected_code=1, -+ expected_msg='KDB module requires -update argument') - realm.run([kdb5_util, 'load', '-update', dumpfile]) - - # Destroy the realm. -@@ -501,14 +468,10 @@ realm.addprinc(realm.user_princ, password('user')) - realm.kinit(realm.user_princ, password('user')) - realm.stop() - # Exercise DB options, which should cause binding to fail. --out = realm.run([kadminl, '-x', 'sasl_authcid=ab', 'getprinc', 'user'], -- expected_code=1) --if 'Cannot bind to LDAP server' not in out: -- fail('Expected error not seen in kadmin.local output') --out = realm.run([kadminl, '-x', 'bindpwd=wrong', 'getprinc', 'user'], -- expected_code=1) --if 'Cannot bind to LDAP server' not in out: -- fail('Expected error not seen in kadmin.local output') -+realm.run([kadminl, '-x', 'sasl_authcid=ab', 'getprinc', 'user'], -+ expected_code=1, expected_msg='Cannot bind to LDAP server') -+realm.run([kadminl, '-x', 'bindpwd=wrong', 'getprinc', 'user'], -+ expected_code=1, expected_msg='Cannot bind to LDAP server') - realm.run([kdb5_ldap_util, 'destroy', '-f']) - - # We could still use tests to exercise: -diff --git a/src/tests/t_kdb_locking.py b/src/tests/t_kdb_locking.py -index e8d86e09b..aac0a220f 100755 ---- a/src/tests/t_kdb_locking.py -+++ b/src/tests/t_kdb_locking.py -@@ -21,9 +21,8 @@ if not os.path.exists(kadm5_lock): - fail('kadm5 lock file not created: ' + kadm5_lock) - os.unlink(kadm5_lock) - --output = realm.kinit(p, p, [], expected_code=1) --if 'A service is not available' not in output: -- fail('krb5kdc should have returned service not available error') -+realm.kinit(p, p, [], expected_code=1, -+ expected_msg='A service is not available') - - f = open(kadm5_lock, 'w') - f.close() -diff --git a/src/tests/t_keydata.py b/src/tests/t_keydata.py -index 686e543bd..5c04a8523 100755 ---- a/src/tests/t_keydata.py -+++ b/src/tests/t_keydata.py -@@ -5,27 +5,19 @@ realm = K5Realm(create_user=False, create_host=False) - - # Create a principal with no keys. - realm.run([kadminl, 'addprinc', '-nokey', 'user']) --out = realm.run([kadminl, 'getprinc', 'user']) --if 'Number of keys: 0' not in out: -- fail('getprinc (addprinc -nokey)') -+realm.run([kadminl, 'getprinc', 'user'], expected_msg='Number of keys: 0') - - # Change its password and check the resulting kvno. - realm.run([kadminl, 'cpw', '-pw', 'password', 'user']) --out = realm.run([kadminl, 'getprinc', 'user']) --if 'vno 1' not in out: -- fail('getprinc (cpw -pw)') -+realm.run([kadminl, 'getprinc', 'user'], expected_msg='vno 1') - - # Delete all of its keys. - realm.run([kadminl, 'purgekeys', '-all', 'user']) --out = realm.run([kadminl, 'getprinc', 'user']) --if 'Number of keys: 0' not in out: -- fail('getprinc (purgekeys)') -+realm.run([kadminl, 'getprinc', 'user'], expected_msg='Number of keys: 0') - - # Randomize its keys and check the resulting kvno. - realm.run([kadminl, 'cpw', '-randkey', 'user']) --out = realm.run([kadminl, 'getprinc', 'user']) --if 'vno 1' not in out: -- fail('getprinc (cpw -randkey)') -+realm.run([kadminl, 'getprinc', 'user'], expected_msg='vno 1') - - # Return true if patype appears to have been received in a hint list - # from a KDC error message, based on the trace file fname. -diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py -index 35d0b61b8..bfd38914b 100755 ---- a/src/tests/t_keyrollover.py -+++ b/src/tests/t_keyrollover.py -@@ -23,25 +23,17 @@ realm.run([kvno, princ1]) - realm.run([kadminl, 'purgekeys', realm.krbtgt_princ]) - # Make sure an old TGT fails after purging old TGS key. - realm.run([kvno, princ2], expected_code=1) --output = realm.run([klist, '-e']) -- --expected = 'krbtgt/%s@%s\n\tEtype (skey, tkt): des-cbc-crc, des-cbc-crc' % \ -+msg = 'krbtgt/%s@%s\n\tEtype (skey, tkt): des-cbc-crc, des-cbc-crc' % \ - (realm.realm, realm.realm) -- --if expected not in output: -- fail('keyrollover: expected TGS enctype not found') -+realm.run([klist, '-e'], expected_msg=msg) - - # Check that new key actually works. - realm.kinit(realm.user_princ, password('user')) - realm.run([kvno, realm.host_princ]) --output = realm.run([klist, '-e']) -- --expected = 'krbtgt/%s@%s\n\tEtype (skey, tkt): ' \ -+msg = 'krbtgt/%s@%s\n\tEtype (skey, tkt): ' \ - 'aes256-cts-hmac-sha1-96, aes256-cts-hmac-sha1-96' % \ - (realm.realm, realm.realm) -- --if expected not in output: -- fail('keyrollover: expected TGS enctype not found after change') -+realm.run([klist, '-e'], expected_msg=msg) - - # Test that the KDC only accepts the first enctype for a kvno, for a - # local-realm TGS request. To set this up, we abuse an edge-case -diff --git a/src/tests/t_keytab.py b/src/tests/t_keytab.py -index a06e6c296..a48740ba5 100755 ---- a/src/tests/t_keytab.py -+++ b/src/tests/t_keytab.py -@@ -14,9 +14,8 @@ realm.run([ktutil], input=('rkt %s\ndelent 1\nwkt %s\n' % - realm.kinit(realm.host_princ, flags=['-k', '-t', pkeytab]) - - # Test kinit with no keys for client in keytab. --output = realm.kinit(realm.user_princ, flags=['-k'], expected_code=1) --if 'no suitable keys' not in output: -- fail('Expected error not seen in kinit output') -+realm.kinit(realm.user_princ, flags=['-k'], expected_code=1, -+ expected_msg='no suitable keys') - - # Test kinit and klist with client keytab defaults. - realm.extract_keytab(realm.user_princ, realm.client_keytab); -@@ -31,14 +30,12 @@ if realm.client_keytab not in out or realm.user_princ not in out: - - # Test implicit request for keytab (-i or -t without -k) - realm.run([kdestroy]) --output = realm.kinit(realm.host_princ, flags=['-t', realm.keytab]) --if 'keytab specified, forcing -k' not in output: -- fail('Expected output not seen from kinit -t keytab') -+realm.kinit(realm.host_princ, flags=['-t', realm.keytab], -+ expected_msg='keytab specified, forcing -k') - realm.klist(realm.host_princ) - realm.run([kdestroy]) --output = realm.kinit(realm.user_princ, flags=['-i']) --if 'keytab specified, forcing -k' not in output: -- fail('Expected output not seen from kinit -i') -+realm.kinit(realm.user_princ, flags=['-i'], -+ expected_msg='keytab specified, forcing -k') - realm.klist(realm.user_princ) - - # Test extracting keys with multiple key versions present. -@@ -70,12 +67,10 @@ def test_key_rotate(realm, princ, expected_kvno): - realm.run_kadmin(['ktadd', '-k', realm.keytab, princ]) - realm.run([kadminl, 'ktrem', princ, 'old']) - realm.kinit(princ, flags=['-k']) -- out = realm.run([klist, '-k']) -- if ('%d %s' % (expected_kvno, princ)) not in out: -- fail('kvno %d not listed in keytab' % expected_kvno) -- out = realm.run_kadmin(['getprinc', princ]) -- if ('Key: vno %d,' % expected_kvno) not in out: -- fail('vno %d not seen in getprinc output' % expected_kvno) -+ msg = '%d %s' % (expected_kvno, princ) -+ out = realm.run([klist, '-k'], expected_msg=msg) -+ msg = 'Key: vno %d,' % expected_kvno -+ out = realm.run_kadmin(['getprinc', princ], expected_msg=msg) - - princ = 'foo/bar@%s' % realm.realm - realm.addprinc(princ) -@@ -109,9 +104,8 @@ f = open(realm.keytab, 'w') - f.write('\x05\x02\x00\x00\x00' + chr(len(record))) - f.write(record) - f.close() --out = realm.run([klist, '-k']) --if (' 2 %s' % realm.user_princ) not in out: -- fail('Expected entry not seen in klist -k output') -+msg = ' 2 %s' % realm.user_princ -+out = realm.run([klist, '-k'], expected_msg=msg) - - # Make sure zero-fill isn't treated as a 32-bit kvno. - f = open(realm.keytab, 'w') -@@ -119,9 +113,8 @@ f.write('\x05\x02\x00\x00\x00' + chr(len(record) + 4)) - f.write(record) - f.write('\x00\x00\x00\x00') - f.close() --out = realm.run([klist, '-k']) --if (' 2 %s' % realm.user_princ) not in out: -- fail('Expected entry not seen in klist -k output') -+msg = ' 2 %s' % realm.user_princ -+out = realm.run([klist, '-k'], expected_msg=msg) - - # Make sure a hand-crafted 32-bit kvno is recognized. - f = open(realm.keytab, 'w') -@@ -129,9 +122,8 @@ f.write('\x05\x02\x00\x00\x00' + chr(len(record) + 4)) - f.write(record) - f.write('\x00\x00\x00\x03') - f.close() --out = realm.run([klist, '-k']) --if (' 3 %s' % realm.user_princ) not in out: -- fail('Expected entry not seen in klist -k output') -+msg = ' 3 %s' % realm.user_princ -+out = realm.run([klist, '-k'], expected_msg=msg) - - # Test parameter expansion in profile variables - realm.stop() -@@ -142,11 +134,9 @@ realm = K5Realm(krb5_conf=conf, create_kdb=False) - del realm.env['KRB5_KTNAME'] - del realm.env['KRB5_CLIENT_KTNAME'] - uidstr = str(os.getuid()) --out = realm.run([klist, '-k'], expected_code=1) --if 'FILE:testdir/abc%s' % uidstr not in out: -- fail('Wrong keytab in klist -k output') --out = realm.run([klist, '-ki'], expected_code=1) --if 'FILE:testdir/xyz%s' % uidstr not in out: -- fail('Wrong keytab in klist -ki output') -+msg = 'FILE:testdir/abc%s' % uidstr -+out = realm.run([klist, '-k'], expected_code=1, expected_msg=msg) -+msg = 'FILE:testdir/xyz%s' % uidstr -+out = realm.run([klist, '-ki'], expected_code=1, expected_msg=msg) - - success('Keytab-related tests') -diff --git a/src/tests/t_kprop.py b/src/tests/t_kprop.py -index 02cdfeec2..39169675d 100755 ---- a/src/tests/t_kprop.py -+++ b/src/tests/t_kprop.py -@@ -43,9 +43,7 @@ for realm in multipass_realms(create_user=False): - realm.run([kprop, '-f', dumpfile, '-P', str(realm.kprop_port()), hostname]) - check_output(kpropd) - -- out = realm.run([kadminl, 'listprincs'], slave) -- if 'wakawaka' not in out: -- fail('Slave does not have all principals from master') -+ realm.run([kadminl, 'listprincs'], slave, expected_msg='wakawaka') - - # default_realm tests follow. - # default_realm and domain_realm different than realm.realm (test -r argument). -@@ -79,9 +77,8 @@ realm.run([kdb5_util, 'dump', dumpfile]) - realm.run([kprop, '-r', realm.realm, '-f', dumpfile, '-P', - str(realm.kprop_port()), hostname]) - check_output(kpropd) --out = realm.run([kadminl, '-r', realm.realm, 'listprincs'], slave2) --if 'wakawaka' not in out: -- fail('Slave does not have all principals from master') -+realm.run([kadminl, '-r', realm.realm, 'listprincs'], slave2, -+ expected_msg='wakawaka') - - stop_daemon(kpropd) - -@@ -90,8 +87,6 @@ kpropd = realm.start_kpropd(slave3, ['-d']) - realm.run([kdb5_util, 'dump', dumpfile]) - realm.run([kprop, '-f', dumpfile, '-P', str(realm.kprop_port()), hostname]) - check_output(kpropd) --out = realm.run([kadminl, 'listprincs'], slave3) --if 'wakawaka' not in out: -- fail('Slave does not have all principals from master') -+realm.run([kadminl, 'listprincs'], slave3, expected_msg='wakawaka') - - success('kprop tests') -diff --git a/src/tests/t_localauth.py b/src/tests/t_localauth.py -index 4590485ac..aa625d038 100755 ---- a/src/tests/t_localauth.py -+++ b/src/tests/t_localauth.py -@@ -14,9 +14,8 @@ def test_an2ln(env, aname, result, msg): - fail(msg) - - def test_an2ln_err(env, aname, err, msg): -- out = realm.run(['./localauth', aname], env=env, expected_code=1) -- if err not in out: -- fail(msg) -+ realm.run(['./localauth', aname], env=env, expected_code=1, -+ expected_msg=err) - - def test_userok(env, aname, lname, ok, msg): - out = realm.run(['./localauth', aname, lname], env=env) -diff --git a/src/tests/t_mkey.py b/src/tests/t_mkey.py -index c53b71b45..615cd91ca 100755 ---- a/src/tests/t_mkey.py -+++ b/src/tests/t_mkey.py -@@ -92,9 +92,8 @@ def check_stash(*expected): - - # Verify that the user principal has the expected mkvno. - def check_mkvno(princ, expected_mkvno): -- out = realm.run([kadminl, 'getprinc', princ]) -- if ('MKey: vno %d\n' % expected_mkvno) not in out: -- fail('Unexpected mkvno in user DB entry') -+ msg = 'MKey: vno %d\n' % expected_mkvno -+ realm.run([kadminl, 'getprinc', princ], expected_msg=msg) - - - # Change the password using either kadmin.local or kadmin, then check -@@ -160,9 +159,8 @@ check_mkvno(realm.user_princ, 1) - collisionfile = os.path.join(realm.testdir, 'stash_tmp') - f = open(collisionfile, 'w') - f.close() --output = realm.run([kdb5_util, 'stash'], expected_code=1) --if 'Temporary stash file already exists' not in output: -- fail('Did not detect temp stash file collision') -+realm.run([kdb5_util, 'stash'], expected_code=1, -+ expected_msg='Temporary stash file already exists') - os.unlink(collisionfile) - - # Add a new master key with no options. Verify that: -@@ -179,9 +177,8 @@ change_password_check_mkvno(True, realm.user_princ, 'abcd', 1) - change_password_check_mkvno(False, realm.user_princ, 'user', 1) - - # Verify that use_mkey won't make all master keys inactive. --out = realm.run([kdb5_util, 'use_mkey', '1', 'now+1day'], expected_code=1) --if 'there must be one master key currently active' not in out: -- fail('Unexpected error from use_mkey making all mkeys inactive') -+realm.run([kdb5_util, 'use_mkey', '1', 'now+1day'], expected_code=1, -+ expected_msg='there must be one master key currently active') - check_mkey_list((2, defetype, False, False), (1, defetype, True, True)) - - # Make the new master key active. Verify that: -@@ -194,9 +191,8 @@ change_password_check_mkvno(True, realm.user_princ, 'abcd', 2) - change_password_check_mkvno(False, realm.user_princ, 'user', 2) - - # Check purge_mkeys behavior with both master keys still in use. --out = realm.run([kdb5_util, 'purge_mkeys', '-f', '-v']) --if 'All keys in use, nothing purged.' not in out: -- fail('Unexpected output from purge_mkeys with both mkeys in use') -+realm.run([kdb5_util, 'purge_mkeys', '-f', '-v'], -+ expected_msg='All keys in use, nothing purged.') - - # Do an update_princ_encryption dry run and for real. Verify that: - # 1. The target master key is 2 (the active mkvno). -@@ -226,9 +222,8 @@ update_princ_encryption(False, 2, nprincs - 1, 0) - check_mkvno(realm.user_princ, 2) - - # Test the safety check for purging with an outdated stash file. --out = realm.run([kdb5_util, 'purge_mkeys', '-f'], expected_code=1) --if 'stash file needs updating' not in out: -- fail('Unexpected error from purge_mkeys safety check') -+realm.run([kdb5_util, 'purge_mkeys', '-f'], expected_code=1, -+ expected_msg='stash file needs updating') - - # Update the master stash file and check it. Save a copy of the old - # one for a later test. -@@ -253,18 +248,15 @@ check_mkey_list((2, defetype, True, True)) - check_master_dbent(2, (2, defetype)) - os.rename(stash_file, stash_file + '.save') - os.rename(stash_file + '.old', stash_file) --out = realm.run([kadminl, 'getprinc', 'user'], expected_code=1) --if 'Unable to decrypt latest master key' not in out: -- fail('Unexpected error from kadmin.local with old stash file') -+realm.run([kadminl, 'getprinc', 'user'], expected_code=1, -+ expected_msg='Unable to decrypt latest master key') - os.rename(stash_file + '.save', stash_file) - realm.run([kdb5_util, 'stash']) - check_stash((2, defetype)) --out = realm.run([kdb5_util, 'use_mkey', '1'], expected_code=1) --if '1 is an invalid KVNO value' not in out: -- fail('Unexpected error from use_mkey with invalid kvno') --out = realm.run([kdb5_util, 'purge_mkeys', '-f', '-v']) --if 'There is only one master key which can not be purged.' not in out: -- fail('Unexpected output from purge_mkeys with one mkey') -+realm.run([kdb5_util, 'use_mkey', '1'], expected_code=1, -+ expected_msg='1 is an invalid KVNO value') -+realm.run([kdb5_util, 'purge_mkeys', '-f', '-v'], -+ expected_msg='There is only one master key which can not be purged.') - - # Add a third master key with a specified enctype. Verify that: - # 1. The new master key receives the correct number. -@@ -331,8 +323,7 @@ check_mkey_list((2, defetype, True, True), (1, des3, True, False)) - # Regression test for #8395. Purge the master key and verify that a - # master key fetch does not segfault. - realm.run([kadminl, 'purgekeys', '-all', 'K/M']) --out = realm.run([kadminl, 'getprinc', realm.user_princ], expected_code=1) --if 'Cannot find master key record in database' not in out: -- fail('Unexpected output from failed master key fetch') -+realm.run([kadminl, 'getprinc', realm.user_princ], expected_code=1, -+ expected_msg='Cannot find master key record in database') - - success('Master key rollover tests') -diff --git a/src/tests/t_otp.py b/src/tests/t_otp.py -index f098374f9..9b18ff94b 100755 ---- a/src/tests/t_otp.py -+++ b/src/tests/t_otp.py -@@ -199,9 +199,8 @@ realm.run([kadminl, 'setstr', realm.user_princ, 'otp', otpconfig('udp')]) - realm.kinit(realm.user_princ, 'accept', flags=flags) - verify(daemon, queue, True, realm.user_princ.split('@')[0], 'accept') - realm.extract_keytab(realm.krbtgt_princ, realm.keytab) --out = realm.run(['./adata', realm.krbtgt_princ]) --if '+97: [indotp1, indotp2]' not in out: -- fail('auth indicators not seen in OTP ticket') -+realm.run(['./adata', realm.krbtgt_princ], -+ expected_msg='+97: [indotp1, indotp2]') - - # Repeat with an indicators override in the string attribute. - daemon = UDPRadiusDaemon(args=(server_addr, secret_file, 'accept', queue)) -@@ -212,9 +211,8 @@ realm.run([kadminl, 'setstr', realm.user_princ, 'otp', oconf]) - realm.kinit(realm.user_princ, 'accept', flags=flags) - verify(daemon, queue, True, realm.user_princ.split('@')[0], 'accept') - realm.extract_keytab(realm.krbtgt_princ, realm.keytab) --out = realm.run(['./adata', realm.krbtgt_princ]) --if '+97: [indtok1, indtok2]' not in out: -- fail('auth indicators not seen in OTP ticket') -+realm.run(['./adata', realm.krbtgt_princ], -+ expected_msg='+97: [indtok1, indtok2]') - - # Detect upstream pyrad bug - # https://github.com/wichert/pyrad/pull/18 -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index f56141564..e943f4974 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -101,10 +101,9 @@ realm.kinit('user@krbtest.com', - flags=['-E', '-X', 'X509_user_identity=%s' % p12_upn2_identity]) - - # Test a mismatch. --out = realm.run([kinit, '-X', 'X509_user_identity=%s' % p12_upn2_identity, -- 'user2'], expected_code=1) --if 'kinit: Client name mismatch while getting initial credentials' not in out: -- fail('Wrong error for UPN SAN mismatch') -+msg = 'kinit: Client name mismatch while getting initial credentials' -+realm.run([kinit, '-X', 'X509_user_identity=%s' % p12_upn2_identity, 'user2'], -+ expected_code=1, expected_msg=msg) - realm.stop() - - realm = K5Realm(krb5_conf=pkinit_krb5_conf, kdc_conf=pkinit_kdc_conf, -@@ -118,9 +117,8 @@ realm.klist(realm.user_princ) - realm.run([kvno, realm.host_princ]) - - # Test anonymous PKINIT. --out = realm.kinit('@%s' % realm.realm, flags=['-n'], expected_code=1) --if 'not found in Kerberos database' not in out: -- fail('Wrong error for anonymous PKINIT without anonymous enabled') -+realm.kinit('@%s' % realm.realm, flags=['-n'], expected_code=1, -+ expected_msg='not found in Kerberos database') - realm.addprinc('WELLKNOWN/ANONYMOUS') - realm.kinit('@%s' % realm.realm, flags=['-n']) - realm.klist('WELLKNOWN/ANONYMOUS@WELLKNOWN:ANONYMOUS') -@@ -135,9 +133,8 @@ f.write('WELLKNOWN/ANONYMOUS@WELLKNOWN:ANONYMOUS a *') - f.close() - realm.start_kadmind() - realm.run([kadmin, '-n', 'addprinc', '-pw', 'test', 'testadd']) --out = realm.run([kadmin, '-n', 'getprinc', 'testadd'], expected_code=1) --if "Operation requires ``get'' privilege" not in out: -- fail('Anonymous kadmin has too much privilege') -+realm.run([kadmin, '-n', 'getprinc', 'testadd'], expected_code=1, -+ expected_msg="Operation requires ``get'' privilege") - realm.stop_kadmind() - - # Test with anonymous restricted; FAST should work but kvno should fail. -@@ -146,9 +143,8 @@ realm.stop_kdc() - realm.start_kdc(env=r_env) - realm.kinit('@%s' % realm.realm, flags=['-n']) - realm.kinit('@%s' % realm.realm, flags=['-n', '-T', realm.ccache]) --out = realm.run([kvno, realm.host_princ], expected_code=1) --if 'KDC policy rejects request' not in out: -- fail('Wrong error for restricted anonymous PKINIT') -+realm.run([kvno, realm.host_princ], expected_code=1, -+ expected_msg='KDC policy rejects request') - - # Regression test for #8458: S4U2Self requests crash the KDC if - # anonymous is restricted. -@@ -200,9 +196,8 @@ realm.kinit(realm.user_princ, - password='encrypted') - realm.klist(realm.user_princ) - realm.run([kvno, realm.host_princ]) --out = realm.run(['./adata', realm.host_princ]) --if '+97: [indpkinit1, indpkinit2]' not in out: -- fail('auth indicators not seen in PKINIT ticket') -+realm.run(['./adata', realm.host_princ], -+ expected_msg='+97: [indpkinit1, indpkinit2]') - - # Run the basic test - PKINIT with FILE: identity, with a password on the key, - # supplied by the responder. -diff --git a/src/tests/t_policy.py b/src/tests/t_policy.py -index bfec96a93..26c4e466e 100755 ---- a/src/tests/t_policy.py -+++ b/src/tests/t_policy.py -@@ -7,35 +7,27 @@ realm = K5Realm(create_host=False, start_kadmind=True) - # Test password quality enforcement. - realm.run([kadminl, 'addpol', '-minlength', '6', '-minclasses', '2', 'pwpol']) - realm.run([kadminl, 'addprinc', '-randkey', '-policy', 'pwpol', 'pwuser']) --out = realm.run([kadminl, 'cpw', '-pw', 'sh0rt', 'pwuser'], expected_code=1) --if 'Password is too short' not in out: -- fail('short password') --out = realm.run([kadminl, 'cpw', '-pw', 'longenough', 'pwuser'], -- expected_code=1) --if 'Password does not contain enough character classes' not in out: -- fail('insufficient character classes') -+realm.run([kadminl, 'cpw', '-pw', 'sh0rt', 'pwuser'], expected_code=1, -+ expected_msg='Password is too short') -+realm.run([kadminl, 'cpw', '-pw', 'longenough', 'pwuser'], expected_code=1, -+ expected_msg='Password does not contain enough character classes') - realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser']) - - # Test some password history enforcement. Even with no history value, - # the current password should be denied. --out = realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser'], -- expected_code=1) --if 'Cannot reuse password' not in out: -- fail('reuse of current password') -+realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser'], expected_code=1, -+ expected_msg='Cannot reuse password') - realm.run([kadminl, 'modpol', '-history', '2', 'pwpol']) - realm.run([kadminl, 'cpw', '-pw', 'an0therpw', 'pwuser']) --out = realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser'], -- expected_code=1) --if 'Cannot reuse password' not in out: -- fail('reuse of old password') -+realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser'], expected_code=1, -+ expected_msg='Cannot reuse password') - realm.run([kadminl, 'cpw', '-pw', '3rdpassword', 'pwuser']) - realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser']) - - # Test references to nonexistent policies. - realm.run([kadminl, 'addprinc', '-randkey', '-policy', 'newpol', 'newuser']) --out = realm.run([kadminl, 'getprinc', 'newuser']) --if 'Policy: newpol [does not exist]\n' not in out: -- fail('getprinc output for principal referencing nonexistent policy') -+realm.run([kadminl, 'getprinc', 'newuser'], -+ expected_msg='Policy: newpol [does not exist]\n') - realm.run([kadminl, 'modprinc', '-policy', 'newpol', 'pwuser']) - # pwuser should allow reuse of the current password since newpol doesn't exist. - realm.run([kadminl, 'cpw', '-pw', '3rdpassword', 'pwuser']) -@@ -45,29 +37,20 @@ realm.run([kadmin, '-p', 'pwuser', '-w', '3rdpassword', 'cpw', '-pw', - - # Create newpol and verify that it is enforced. - realm.run([kadminl, 'addpol', '-minlength', '3', 'newpol']) --out = realm.run([kadminl, 'getprinc', 'pwuser']) --if 'Policy: newpol\n' not in out: -- fail('getprinc after creating policy (pwuser)') --out = realm.run([kadminl, 'cpw', '-pw', 'aa', 'pwuser'], expected_code=1) --if 'Password is too short' not in out: -- fail('short password after creating policy (pwuser)') --out = realm.run([kadminl, 'cpw', '-pw', '3rdpassword', 'pwuser'], -- expected_code=1) --if 'Cannot reuse password' not in out: -- fail('reuse of current password after creating policy') -+realm.run([kadminl, 'getprinc', 'pwuser'], expected_msg='Policy: newpol\n') -+realm.run([kadminl, 'cpw', '-pw', 'aa', 'pwuser'], expected_code=1, -+ expected_msg='Password is too short') -+realm.run([kadminl, 'cpw', '-pw', '3rdpassword', 'pwuser'], expected_code=1, -+ expected_msg='Cannot reuse password') - --out = realm.run([kadminl, 'getprinc', 'newuser']) --if 'Policy: newpol\n' not in out: -- fail('getprinc after creating policy (newuser)') --out = realm.run([kadminl, 'cpw', '-pw', 'aa', 'newuser'], expected_code=1) --if 'Password is too short' not in out: -- fail('short password after creating policy (newuser)') -+realm.run([kadminl, 'getprinc', 'newuser'], expected_msg='Policy: newpol\n') -+realm.run([kadminl, 'cpw', '-pw', 'aa', 'newuser'], expected_code=1, -+ expected_msg='Password is too short') - - # Delete the policy and verify that it is no longer enforced. - realm.run([kadminl, 'delpol', 'newpol']) --out = realm.run([kadminl, 'getpol', 'newpol'], expected_code=1) --if 'Policy does not exist' not in out: -- fail('deletion of referenced policy') -+realm.run([kadminl, 'getpol', 'newpol'], expected_code=1, -+ expected_msg='Policy does not exist') - realm.run([kadminl, 'cpw', '-pw', 'aa', 'pwuser']) - - # Test basic password lockout support. -@@ -78,18 +61,14 @@ realm.run([kadminl, 'modprinc', '+requires_preauth', '-policy', 'lockout', - 'user']) - - # kinit twice with the wrong password. --output = realm.run([kinit, realm.user_princ], input='wrong\n', expected_code=1) --if 'Password incorrect while getting initial credentials' not in output: -- fail('Expected error message not seen in kinit output') --output = realm.run([kinit, realm.user_princ], input='wrong\n', expected_code=1) --if 'Password incorrect while getting initial credentials' not in output: -- fail('Expected error message not seen in kinit output') -+realm.run([kinit, realm.user_princ], input='wrong\n', expected_code=1, -+ expected_msg='Password incorrect while getting initial credentials') -+realm.run([kinit, realm.user_princ], input='wrong\n', expected_code=1, -+ expected_msg='Password incorrect while getting initial credentials') - - # Now the account should be locked out. --output = realm.run([kinit, realm.user_princ], expected_code=1) --if 'Client\'s credentials have been revoked while getting initial credentials' \ -- not in output: -- fail('Expected lockout error message not seen in kinit output') -+m = 'Client\'s credentials have been revoked while getting initial credentials' -+realm.run([kinit, realm.user_princ], expected_code=1, expected_msg=m) - - # Check that modprinc -unlock allows a further attempt. - realm.run([kadminl, 'modprinc', '-unlock', 'user']) -@@ -113,10 +92,8 @@ realm.run([kadminl, 'cpw', '-pw', 'pw2', 'user']) - # Swap the keys, simulating older kadmin having chosen the second entry. - realm.run(['./hist', 'swap']) - # Make sure we can read the history entry. --out = realm.run([kadminl, 'cpw', '-pw', password('user'), 'user'], -- expected_code=1) --if 'Cannot reuse password' not in out: -- fail('Expected error not seen in output') -+realm.run([kadminl, 'cpw', '-pw', password('user'), 'user'], expected_code=1, -+ expected_msg='Cannot reuse password') - - # Test key/salt constraints. - -@@ -142,9 +119,8 @@ realm.run([kadminl, 'cpw', '-randkey', '-e', 'aes256-cts', 'server']) - - # Test modpol. - realm.run([kadminl, 'modpol', '-allowedkeysalts', 'aes256-cts,rc4-hmac', 'ak']) --out = realm.run([kadminl, 'getpol', 'ak']) --if not 'Allowed key/salt types: aes256-cts,rc4-hmac' in out: -- fail('getpol does not implement allowedkeysalts?') -+realm.run([kadminl, 'getpol', 'ak'], -+ expected_msg='Allowed key/salt types: aes256-cts,rc4-hmac') - - # Test subsets and full set. - realm.run([kadminl, 'cpw', '-randkey', '-e', 'rc4-hmac', 'server']) -@@ -153,19 +129,14 @@ realm.run([kadminl, 'cpw', '-randkey', '-e', 'aes256-cts,rc4-hmac', 'server']) - realm.run([kadminl, 'cpw', '-randkey', '-e', 'rc4-hmac,aes256-cts', 'server']) - - # Check that the order we got is the one from the policy. --out = realm.run([kadminl, 'getprinc', '-terse', 'server']) --if not '2\t1\t6\t18\t0\t1\t6\t23\t0' in out: -- fail('allowed_keysalts policy did not preserve order') -+realm.run([kadminl, 'getprinc', '-terse', 'server'], -+ expected_msg='2\t1\t6\t18\t0\t1\t6\t23\t0') - - # Test partially intersecting sets. --out = realm.run([kadminl, 'cpw', '-randkey', '-e', 'rc4-hmac,aes128-cts', -- 'server'], expected_code=1) --if not 'Invalid key/salt tuples' in out: -- fail('allowed_keysalts policy not applied properly') --out = realm.run([kadminl, 'cpw', '-randkey', '-e', -- 'rc4-hmac,aes256-cts,aes128-cts', 'server'], expected_code=1) --if not 'Invalid key/salt tuples' in out: -- fail('allowed_keysalts policy not applied properly') -+realm.run([kadminl, 'cpw', '-randkey', '-e', 'rc4-hmac,aes128-cts', 'server'], -+ expected_code=1, expected_msg='Invalid key/salt tuples') -+realm.run([kadminl, 'cpw', '-randkey', '-e', 'rc4-hmac,aes256-cts,aes128-cts', -+ 'server'], expected_code=1, expected_msg='Invalid key/salt tuples') - - # Test reset of allowedkeysalts. - realm.run([kadminl, 'modpol', '-allowedkeysalts', '-', 'ak']) -diff --git a/src/tests/t_preauth.py b/src/tests/t_preauth.py -index 0ef8bbca4..1823a797d 100644 ---- a/src/tests/t_preauth.py -+++ b/src/tests/t_preauth.py -@@ -10,18 +10,12 @@ realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) - realm.run([kadminl, 'modprinc', '+requires_preauth', realm.user_princ]) - realm.run([kadminl, 'setstr', realm.user_princ, 'teststring', 'testval']) - realm.run([kadminl, 'addprinc', '-nokey', '+requires_preauth', 'nokeyuser']) --out = realm.run([kinit, realm.user_princ], input=password('user')+'\n') --if 'testval' not in out: -- fail('Decrypted string attribute not in kinit output') --out = realm.run([kinit, 'nokeyuser'], input=password('user')+'\n', -- expected_code=1) --if 'no key' not in out: -- fail('Expected "no key" message not in kinit output') -+realm.kinit(realm.user_princ, password('user'), expected_msg='testval') -+realm.kinit('nokeyuser', password('user'), expected_code=1, -+ expected_msg='no key') - - # Exercise KDC_ERR_MORE_PREAUTH_DATA_REQUIRED and secure cookies. - realm.run([kadminl, 'setstr', realm.user_princ, '2rt', 'secondtrip']) --out = realm.run([kinit, realm.user_princ], input=password('user')+'\n') --if '2rt: secondtrip' not in out: -- fail('multi round-trip cookie test') -+realm.kinit(realm.user_princ, password('user'), expected_msg='2rt: secondtrip') - - success('Pre-authentication framework tests') -diff --git a/src/tests/t_pwqual.py b/src/tests/t_pwqual.py -index 0d1d387d8..011110bd1 100755 ---- a/src/tests/t_pwqual.py -+++ b/src/tests/t_pwqual.py -@@ -18,29 +18,24 @@ f.close() - realm.run([kadminl, 'addpol', 'pol']) - - # The built-in "empty" module rejects empty passwords even without a policy. --out = realm.run([kadminl, 'addprinc', '-pw', '', 'p1'], expected_code=1) --if 'Empty passwords are not allowed' not in out: -- fail('Expected error not seen for empty password') -+realm.run([kadminl, 'addprinc', '-pw', '', 'p1'], expected_code=1, -+ expected_msg='Empty passwords are not allowed') - - # The built-in "dict" module rejects dictionary words, but only with a policy. - realm.run([kadminl, 'addprinc', '-pw', 'birds', 'p2']) --out = realm.run([kadminl, 'addprinc', '-pw', 'birds', '-policy', 'pol', 'p3'], -- expected_code=1) --if 'Password is in the password dictionary' not in out: -- fail('Expected error not seen from dictionary password') -+realm.run([kadminl, 'addprinc', '-pw', 'birds', '-policy', 'pol', 'p3'], -+ expected_code=1, -+ expected_msg='Password is in the password dictionary') - - # The built-in "princ" module rejects principal components, only with a policy. - realm.run([kadminl, 'addprinc', '-pw', 'p4', 'p4']) --out = realm.run([kadminl, 'addprinc', '-pw', 'p5', '-policy', 'pol', 'p5'], -- expected_code=1) --if 'Password may not match principal name' not in out: -- fail('Expected error not seen from principal component') -+realm.run([kadminl, 'addprinc', '-pw', 'p5', '-policy', 'pol', 'p5'], -+ expected_code=1, -+ expected_msg='Password may not match principal name') - - # The dynamic "combo" module rejects pairs of dictionary words. --out = realm.run([kadminl, 'addprinc', '-pw', 'birdsoranges', 'p6'], -- expected_code=1) --if 'Password may not be a pair of dictionary words' not in out: -- fail('Expected error not seen from combo module') -+realm.run([kadminl, 'addprinc', '-pw', 'birdsoranges', 'p6'], expected_code=1, -+ expected_msg='Password may not be a pair of dictionary words') - - # These plugin ordering tests aren't specifically related to the - # password quality interface, but are convenient to put here. -diff --git a/src/tests/t_referral.py b/src/tests/t_referral.py -index 559fbd5f7..9765116aa 100755 ---- a/src/tests/t_referral.py -+++ b/src/tests/t_referral.py -@@ -23,9 +23,8 @@ def testref(realm, nametype): - # Get credentials and check that we get an error, not a referral. - def testfail(realm, nametype): - shutil.copyfile(savefile, realm.ccache) -- out = realm.run(['./gcred', nametype, 'a/x.d'], expected_code=1) -- if 'not found in Kerberos database' not in out: -- fail('unexpected error') -+ realm.run(['./gcred', nametype, 'a/x.d'], expected_code=1, -+ expected_msg='not found in Kerberos database') - - # Create a modified KDC environment and restart the KDC. - def restart_kdc(realm, kdc_conf): -@@ -116,9 +115,8 @@ r1, r2 = cross_realms(2, xtgts=(), - create_host=False) - r2.addprinc('abc\@XYZ', 'pw') - r1.start_kdc() --out = r1.kinit('user', expected_code=1) --if 'not found in Kerberos database' not in out: -- fail('Expected error not seen for referral without canonicalize flag') -+r1.kinit('user', expected_code=1, -+ expected_msg='not found in Kerberos database') - r1.kinit('user', password('user'), ['-C']) - r1.klist('user@KRBTEST2.COM', 'krbtgt/KRBTEST2.COM') - r1.kinit('abc@XYZ', 'pw', ['-E']) -diff --git a/src/tests/t_renew.py b/src/tests/t_renew.py -index a5f0d4bc1..106c8ecd3 100755 ---- a/src/tests/t_renew.py -+++ b/src/tests/t_renew.py -@@ -32,9 +32,8 @@ realm.run([kvno, realm.user_princ]) - - # Make sure we can't renew non-renewable tickets. - test('non-renewable', '1h', '1h', False) --out = realm.kinit(realm.user_princ, flags=['-R'], expected_code=1) --if "KDC can't fulfill requested option" not in out: -- fail('expected error not seen renewing non-renewable ticket') -+realm.kinit(realm.user_princ, flags=['-R'], expected_code=1, -+ expected_msg="KDC can't fulfill requested option") - - # Test that -allow_renewable on the client principal works. - realm.run([kadminl, 'modprinc', '-allow_renewable', 'user']) -diff --git a/src/tests/t_salt.py b/src/tests/t_salt.py -index e923c92d1..ddb1905ed 100755 ---- a/src/tests/t_salt.py -+++ b/src/tests/t_salt.py -@@ -62,13 +62,11 @@ for ks in dup_kstypes: - # fails. - def test_reject_afs3(realm, etype): - query = 'ank -e ' + etype + ':afs3 -pw password princ1' -- out = realm.run([kadminl, 'ank', '-e', etype + ':afs3', '-pw', 'password', -- 'princ1'], expected_code=1) -- if 'Invalid key generation parameters from KDC' not in out: -- fail('Allowed afs3 salt for ' + etype) -- out = realm.run([kadminl, 'getprinc', 'princ1'], expected_code=1) -- if 'Principal does not exist' not in out: -- fail('Created principal with afs3 salt and enctype ' + etype) -+ realm.run([kadminl, 'ank', '-e', etype + ':afs3', '-pw', 'password', -+ 'princ1'], expected_code=1, -+ expected_msg='Invalid key generation parameters from KDC') -+ realm.run([kadminl, 'getprinc', 'princ1'], expected_code=1, -+ expected_msg='Principal does not exist') - - # Verify that the afs3 salt is rejected for arcfour and pbkdf2 enctypes. - # We do not currently do any verification on the key-generation parameters -diff --git a/src/tests/t_skew.py b/src/tests/t_skew.py -index b72971070..f2ae06695 100755 ---- a/src/tests/t_skew.py -+++ b/src/tests/t_skew.py -@@ -37,22 +37,16 @@ realm.kinit(realm.user_princ, password('user'), - - # kinit should detect too much skew in the KDC response. kinit with - # FAST should fail from the KDC since the armor AP-REQ won't be valid. --out = realm.kinit(realm.user_princ, password('user'), expected_code=1) --if 'Clock skew too great in KDC reply' not in out: -- fail('Expected error message not seen in kinit skew case') --out = realm.kinit(realm.user_princ, None, flags=['-T', fast_cache], -- expected_code=1) --if 'Clock skew too great while' not in out: -- fail('Expected error message not seen in kinit FAST skew case') -+realm.kinit(realm.user_princ, password('user'), expected_code=1, -+ expected_msg='Clock skew too great in KDC reply') -+realm.kinit(realm.user_princ, None, flags=['-T', fast_cache], expected_code=1, -+ expected_msg='Clock skew too great while') - - # kinit (with preauth) should fail from the KDC, with or without FAST. - realm.run([kadminl, 'modprinc', '+requires_preauth', 'user']) --out = realm.kinit(realm.user_princ, password('user'), expected_code=1) --if 'Clock skew too great while' not in out: -- fail('Expected error message not seen in kinit skew case (preauth)') --out = realm.kinit(realm.user_princ, None, flags=['-T', fast_cache], -- expected_code=1) --if 'Clock skew too great while' not in out: -- fail('Expected error message not seen in kinit FAST skew case (preauth)') -+realm.kinit(realm.user_princ, password('user'), expected_code=1, -+ expected_msg='Clock skew too great while') -+realm.kinit(realm.user_princ, None, flags=['-T', fast_cache], expected_code=1, -+ expected_msg='Clock skew too great while') - - success('Clock skew tests') -diff --git a/src/tests/t_stringattr.py b/src/tests/t_stringattr.py -index 281c8726f..5672a0f20 100755 ---- a/src/tests/t_stringattr.py -+++ b/src/tests/t_stringattr.py -@@ -28,9 +28,7 @@ realm = K5Realm(start_kadmind=True, create_host=False, get_creds=False) - - realm.prep_kadmin() - --out = realm.run_kadmin(['getstrs', 'user']) --if '(No string attributes.)' not in out: -- fail('Empty attribute query') -+realm.run_kadmin(['getstrs', 'user'], expected_msg='(No string attributes.)') - - realm.run_kadmin(['setstr', 'user', 'attr1', 'value1']) - realm.run_kadmin(['setstr', 'user', 'attr2', 'value2']) diff --git a/Use-expected_trace-in-test-scripts.patch b/Use-expected_trace-in-test-scripts.patch deleted file mode 100644 index 74516ea..0000000 --- a/Use-expected_trace-in-test-scripts.patch +++ /dev/null @@ -1,75 +0,0 @@ -From 35a00879008457d21ccc6e623835976a21f5000b Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 17 Jan 2017 11:25:22 -0500 -Subject: [PATCH] Use expected_trace in test scripts - -(cherry picked from commit 7b7e5d964e5d020fdda3fb9843d9b8cf8b29a6f8) ---- - src/tests/t_general.py | 24 ++++++++---------------- - src/tests/t_pkinit.py | 15 ++++++--------- - 2 files changed, 14 insertions(+), 25 deletions(-) - -diff --git a/src/tests/t_general.py b/src/tests/t_general.py -index 6d523fe45..16bf6c5e3 100755 ---- a/src/tests/t_general.py -+++ b/src/tests/t_general.py -@@ -47,21 +47,13 @@ if 'not found in Kerberos database' not in out: - fail('Expected error message not seen in kinit -C output') - - # Spot-check KRB5_TRACE output --tracefile = os.path.join(realm.testdir, 'trace') --realm.run(['env', 'KRB5_TRACE=' + tracefile, kinit, realm.user_princ], -- input=(password('user') + "\n")) --f = open(tracefile, 'r') --trace = f.read() --f.close() --expected = ('Sending initial UDP request', -- 'Received answer', -- 'Selected etype info', -- 'AS key obtained', -- 'Decrypted AS reply', -- 'FAST negotiation: available', -- 'Storing user@KRBTEST.COM') --for e in expected: -- if e not in trace: -- fail('Expected output not in kinit trace log') -+expected_trace = ('Sending initial UDP request', -+ 'Received answer', -+ 'Selected etype info', -+ 'AS key obtained', -+ 'Decrypted AS reply', -+ 'FAST negotiation: available', -+ 'Storing user@KRBTEST.COM') -+realm.kinit(realm.user_princ, password('user'), expected_trace=expected_trace) - - success('FAST kinit, trace logging') -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index 183977750..f56141564 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -176,19 +176,16 @@ realm.klist(realm.user_princ) - - # Test a DH parameter renegotiation by temporarily setting a 4096-bit - # minimum on the KDC. --tracefile = os.path.join(realm.testdir, 'trace') - minbits_kdc_conf = {'realms': {'$realm': {'pkinit_dh_min_bits': '4096'}}} - minbits_env = realm.special_env('restrict', True, kdc_conf=minbits_kdc_conf) - realm.stop_kdc() - realm.start_kdc(env=minbits_env) --realm.run(['env', 'KRB5_TRACE=' + tracefile, kinit, '-X', -- 'X509_user_identity=' + file_identity, realm.user_princ]) --with open(tracefile, 'r') as f: -- trace = f.read() --if ('Key parameters not accepted' not in trace or -- 'Preauth tryagain input types' not in trace or -- 'trying again with KDC-provided parameters' not in trace): -- fail('DH renegotiation steps not found in kinit trace log') -+expected_trace = ('Key parameters not accepted', -+ 'Preauth tryagain input types', -+ 'trying again with KDC-provided parameters') -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % file_identity], -+ expected_trace=expected_trace) - realm.stop_kdc() - realm.start_kdc() - diff --git a/Use-fallback-realm-for-GSSAPI-ccache-selection.patch b/Use-fallback-realm-for-GSSAPI-ccache-selection.patch deleted file mode 100644 index bc0591a..0000000 --- a/Use-fallback-realm-for-GSSAPI-ccache-selection.patch +++ /dev/null @@ -1,185 +0,0 @@ -From feee4c633a7db348ef99f1f0c99a5c2e6cb70f92 Mon Sep 17 00:00:00 2001 -From: Matt Rogers -Date: Fri, 10 Feb 2017 12:53:42 -0500 -Subject: [PATCH] Use fallback realm for GSSAPI ccache selection - -In krb5_cc_select(), if the server principal has an empty realm, use -krb5_get_fallback_host_realm() and set the server realm to the first -fallback found. This helps with the selection of a non-default ccache -when there is no [domain_realms] configuration for the server domain. -Modify t_ccselect.py tests to account for fallback behavior. - -ticket: 8549 (new) -(cherry picked from commit 234b64bd6139d5b75dadd5abbd5bef5a162e298a) ---- - src/lib/krb5/ccache/ccselect.c | 37 ++++++++++++++++++++++++++----- - src/tests/gssapi/t_ccselect.py | 50 +++++++++++++++++++++++++++++++++--------- - 2 files changed, 72 insertions(+), 15 deletions(-) - -diff --git a/src/lib/krb5/ccache/ccselect.c b/src/lib/krb5/ccache/ccselect.c -index 2f3071a27..ee4b83a9b 100644 ---- a/src/lib/krb5/ccache/ccselect.c -+++ b/src/lib/krb5/ccache/ccselect.c -@@ -132,6 +132,8 @@ krb5_cc_select(krb5_context context, krb5_principal server, - struct ccselect_module_handle **hp, *h; - krb5_ccache cache; - krb5_principal princ; -+ krb5_principal srvcp = NULL; -+ char **fbrealms = NULL; - - *cache_out = NULL; - *princ_out = NULL; -@@ -139,7 +141,27 @@ krb5_cc_select(krb5_context context, krb5_principal server, - if (context->ccselect_handles == NULL) { - ret = load_modules(context); - if (ret) -- return ret; -+ goto cleanup; -+ } -+ -+ /* Try to use the fallback host realm for the server if there is no -+ * authoritative realm. */ -+ if (krb5_is_referral_realm(&server->realm) && -+ server->type == KRB5_NT_SRV_HST && server->length == 2) { -+ ret = krb5_get_fallback_host_realm(context, &server->data[1], -+ &fbrealms); -+ if (ret) -+ goto cleanup; -+ -+ /* Make a copy with the first fallback realm. */ -+ ret = krb5_copy_principal(context, server, &srvcp); -+ if (ret) -+ goto cleanup; -+ ret = krb5_set_principal_realm(context, srvcp, fbrealms[0]); -+ if (ret) -+ goto cleanup; -+ -+ server = srvcp; - } - - /* Consult authoritative modules first, then heuristic ones. */ -@@ -155,20 +177,25 @@ krb5_cc_select(krb5_context context, krb5_principal server, - princ); - *cache_out = cache; - *princ_out = princ; -- return 0; -+ goto cleanup; - } else if (ret == KRB5_CC_NOTFOUND) { - TRACE_CCSELECT_MODNOTFOUND(context, h->vt.name, server, princ); - *princ_out = princ; -- return ret; -+ goto cleanup; - } else if (ret != KRB5_PLUGIN_NO_HANDLE) { - TRACE_CCSELECT_MODFAIL(context, h->vt.name, ret, server); -- return ret; -+ goto cleanup; - } - } - } - - TRACE_CCSELECT_NOTFOUND(context, server); -- return KRB5_CC_NOTFOUND; -+ ret = KRB5_CC_NOTFOUND; -+ -+cleanup: -+ krb5_free_principal(context, srvcp); -+ krb5_free_host_realm(context, fbrealms); -+ return ret; - } - - void -diff --git a/src/tests/gssapi/t_ccselect.py b/src/tests/gssapi/t_ccselect.py -index 1ea614d30..668a2cc62 100755 ---- a/src/tests/gssapi/t_ccselect.py -+++ b/src/tests/gssapi/t_ccselect.py -@@ -31,12 +31,18 @@ r2 = K5Realm(create_user=False, realm='KRBTEST2.COM', portbase=62000, - - host1 = 'p:' + r1.host_princ - host2 = 'p:' + r2.host_princ -+foo = 'foo.krbtest.com' -+foo2 = 'foo.krbtest2.com' - --# gsserver specifies the target as a GSS name. The resulting --# principal will have the host-based type, but the realm won't be --# known before the client cache is selected (since k5test realms have --# no domain-realm mapping by default). --gssserver = 'h:host@' + hostname -+# These strings specify the target as a GSS name. The resulting -+# principal will have the host-based type, with the referral realm -+# (since k5test realms have no domain-realm mapping by default). -+# krb5_cc_select() will use the fallback realm, which is either the -+# uppercased parent domain, or the default realm if the hostname is a -+# single component. -+gssserver = 'h:host@' + foo -+gssserver2 = 'h:host@' + foo2 -+gsslocal = 'h:host@localhost' - - # refserver specifies the target as a principal in the referral realm. - # The principal won't be treated as a host principal by the -@@ -66,6 +72,16 @@ r1.addprinc(alice, password('alice')) - r1.addprinc(bob, password('bob')) - r2.addprinc(zaphod, password('zaphod')) - -+# Create host principals and keytabs for fallback realm tests. -+r1.addprinc('host/localhost') -+r2.addprinc('host/localhost') -+r1.addprinc('host/' + foo) -+r2.addprinc('host/' + foo2) -+r1.extract_keytab('host/localhost', r1.keytab) -+r2.extract_keytab('host/localhost', r2.keytab) -+r1.extract_keytab('host/' + foo, r1.keytab) -+r2.extract_keytab('host/' + foo2, r2.keytab) -+ - # Get tickets for one user in each realm (zaphod will be primary). - r1.kinit(alice, password('alice')) - r2.kinit(zaphod, password('zaphod')) -@@ -93,10 +109,24 @@ if output != (zaphod + '\n'): - fail('zaphod not chosen as default initiator name for server in r1') - - # Check that primary cache is used if server realm is unknown. --output = r2.run(['./t_ccselect', gssserver]) -+output = r2.run(['./t_ccselect', refserver]) - if output != (zaphod + '\n'): - fail('zaphod not chosen via primary cache for unknown server realm') --r1.run(['./t_ccselect', gssserver], expected_code=1) -+r1.run(['./t_ccselect', gssserver2], expected_code=1) -+# Check ccache selection using a fallback realm. -+output = r1.run(['./t_ccselect', gssserver]) -+if output != (alice + '\n'): -+ fail('alice not chosen via parent domain fallback') -+output = r2.run(['./t_ccselect', gssserver2]) -+if output != (zaphod + '\n'): -+ fail('zaphod not chosen via parent domain fallback') -+# Check ccache selection using a fallback realm (default realm). -+output = r1.run(['./t_ccselect', gsslocal]) -+if output != (alice + '\n'): -+ fail('alice not chosen via default realm fallback') -+output = r2.run(['./t_ccselect', gsslocal]) -+if output != (zaphod + '\n'): -+ fail('zaphod not chosen via default realm fallback') - - # Get a second cred in r1 (bob will be primary). - r1.kinit(bob, password('bob')) -@@ -104,19 +134,19 @@ r1.kinit(bob, password('bob')) - # Try some cache selections using .k5identity. - k5id = open(os.path.join(r1.testdir, '.k5identity'), 'w') - k5id.write('%s realm=%s\n' % (alice, r1.realm)) --k5id.write('%s service=ho*t host=%s\n' % (zaphod, hostname)) -+k5id.write('%s service=ho*t host=localhost\n' % zaphod) - k5id.write('noprinc service=bogus') - k5id.close() - output = r1.run(['./t_ccselect', host1]) - if output != (alice + '\n'): - fail('alice not chosen via .k5identity realm line.') --output = r2.run(['./t_ccselect', gssserver]) -+output = r2.run(['./t_ccselect', gsslocal]) - if output != (zaphod + '\n'): - fail('zaphod not chosen via .k5identity service/host line.') - output = r1.run(['./t_ccselect', refserver]) - if output != (bob + '\n'): - fail('bob not chosen via primary cache when no .k5identity line matches.') --r1.run(['./t_ccselect', 'h:bogus@' + hostname], expected_code=1, -+r1.run(['./t_ccselect', 'h:bogus@' + foo2], expected_code=1, - expected_msg="Can't find client principal noprinc") - - success('GSSAPI credential selection tests') diff --git a/Use-krb5_timestamp-where-appropriate.patch b/Use-krb5_timestamp-where-appropriate.patch deleted file mode 100644 index c5b4c25..0000000 --- a/Use-krb5_timestamp-where-appropriate.patch +++ /dev/null @@ -1,327 +0,0 @@ -From 0ae9141d53a8d9fe048542f89d17760990bd5bc4 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 17 May 2017 15:14:15 -0400 -Subject: [PATCH] Use krb5_timestamp where appropriate - -Where krb5_int32 is used to hold the number of seconds since the -epoch, use krb5_timestamp instead. - -(cherry picked from commit ae25f6ec5558140a546db34fea389412d81c0631) ---- - src/clients/klist/klist.c | 2 +- - src/include/k5-int.h | 2 +- - src/kadmin/server/misc.c | 2 +- - src/kdc/dispatch.c | 4 ++-- - src/lib/kadm5/srv/server_acl.c | 2 +- - src/lib/kadm5/srv/server_kdb.c | 2 +- - src/lib/kadm5/srv/svr_principal.c | 10 +++++----- - src/lib/krb5/krb/gen_save_subkey.c | 3 ++- - src/lib/krb5/krb/get_in_tkt.c | 2 +- - src/lib/krb5/krb/init_ctx.c | 3 ++- - src/lib/krb5/os/c_ustime.c | 7 +++++-- - src/lib/krb5/os/toffset.c | 3 ++- - src/lib/krb5/os/trace.c | 3 ++- - src/lib/krb5/os/ustime.c | 3 ++- - src/lib/krb5/rcache/rc_dfl.c | 10 +++++----- - src/tests/create/kdb5_mkdums.c | 2 +- - 16 files changed, 34 insertions(+), 26 deletions(-) - -diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c -index ffeecc394..4334415be 100644 ---- a/src/clients/klist/klist.c -+++ b/src/clients/klist/klist.c -@@ -56,7 +56,7 @@ int show_adtype = 0, show_all = 0, list_all = 0, use_client_keytab = 0; - int show_config = 0; - char *defname; - char *progname; --krb5_int32 now; -+krb5_timestamp now; - unsigned int timestamp_width; - - krb5_context kcontext; -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 82ee20760..ed9c7bf75 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -721,7 +721,7 @@ krb5_error_code krb5int_c_copy_keyblock_contents(krb5_context context, - const krb5_keyblock *from, - krb5_keyblock *to); - --krb5_error_code krb5_crypto_us_timeofday(krb5_int32 *, krb5_int32 *); -+krb5_error_code krb5_crypto_us_timeofday(krb5_timestamp *, krb5_int32 *); - - /* - * End "los-proto.h" -diff --git a/src/kadmin/server/misc.c b/src/kadmin/server/misc.c -index a75b65a26..ba672d714 100644 ---- a/src/kadmin/server/misc.c -+++ b/src/kadmin/server/misc.c -@@ -159,7 +159,7 @@ kadm5_ret_t - check_min_life(void *server_handle, krb5_principal principal, - char *msg_ret, unsigned int msg_len) - { -- krb5_int32 now; -+ krb5_timestamp now; - kadm5_ret_t ret; - kadm5_policy_ent_rec pol; - kadm5_principal_ent_rec princ; -diff --git a/src/kdc/dispatch.c b/src/kdc/dispatch.c -index 16a35d2be..4ecc23481 100644 ---- a/src/kdc/dispatch.c -+++ b/src/kdc/dispatch.c -@@ -94,8 +94,8 @@ static void - reseed_random(krb5_context kdc_err_context) - { - krb5_error_code retval; -- krb5_int32 now, now_usec; -- krb5_int32 usec_difference; -+ krb5_timestamp now; -+ krb5_int32 now_usec, usec_difference; - krb5_data data; - - retval = krb5_crypto_us_timeofday(&now, &now_usec); -diff --git a/src/lib/kadm5/srv/server_acl.c b/src/lib/kadm5/srv/server_acl.c -index c4bb16dc7..679fc7c41 100644 ---- a/src/lib/kadm5/srv/server_acl.c -+++ b/src/lib/kadm5/srv/server_acl.c -@@ -375,7 +375,7 @@ kadm5int_acl_impose_restrictions(kcontext, recp, maskp, rp) - restriction_t *rp; - { - krb5_error_code code; -- krb5_int32 now; -+ krb5_timestamp now; - - DPRINT(DEBUG_CALLS, acl_debug_level, - ("* kadm5int_acl_impose_restrictions(..., *maskp=0x%08x, rp=0x%08x)\n", -diff --git a/src/lib/kadm5/srv/server_kdb.c b/src/lib/kadm5/srv/server_kdb.c -index 612553ba3..f4b8aef2b 100644 ---- a/src/lib/kadm5/srv/server_kdb.c -+++ b/src/lib/kadm5/srv/server_kdb.c -@@ -365,7 +365,7 @@ kdb_put_entry(kadm5_server_handle_t handle, - krb5_db_entry *kdb, osa_princ_ent_rec *adb) - { - krb5_error_code ret; -- krb5_int32 now; -+ krb5_timestamp now; - XDR xdrs; - krb5_tl_data tl_data; - -diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c -index 137e1fb64..89f34482b 100644 ---- a/src/lib/kadm5/srv/svr_principal.c -+++ b/src/lib/kadm5/srv/svr_principal.c -@@ -296,7 +296,7 @@ kadm5_create_principal_3(void *server_handle, - osa_princ_ent_rec adb; - kadm5_policy_ent_rec polent; - krb5_boolean have_polent = FALSE; -- krb5_int32 now; -+ krb5_timestamp now; - krb5_tl_data *tl_data_tail; - unsigned int ret; - kadm5_server_handle_t handle = server_handle; -@@ -1322,7 +1322,7 @@ kadm5_chpass_principal_3(void *server_handle, - int n_ks_tuple, krb5_key_salt_tuple *ks_tuple, - char *password) - { -- krb5_int32 now; -+ krb5_timestamp now; - kadm5_policy_ent_rec pol; - osa_princ_ent_rec adb; - krb5_db_entry *kdb; -@@ -1544,7 +1544,7 @@ kadm5_randkey_principal_3(void *server_handle, - { - krb5_db_entry *kdb; - osa_princ_ent_rec adb; -- krb5_int32 now; -+ krb5_timestamp now; - kadm5_policy_ent_rec pol; - int ret, last_pwd, n_new_keys; - krb5_boolean have_pol = FALSE; -@@ -1686,7 +1686,7 @@ kadm5_setv4key_principal(void *server_handle, - { - krb5_db_entry *kdb; - osa_princ_ent_rec adb; -- krb5_int32 now; -+ krb5_timestamp now; - kadm5_policy_ent_rec pol; - krb5_keysalt keysalt; - int i, kvno, ret; -@@ -1891,7 +1891,7 @@ kadm5_setkey_principal_4(void *server_handle, krb5_principal principal, - { - krb5_db_entry *kdb; - osa_princ_ent_rec adb; -- krb5_int32 now; -+ krb5_timestamp now; - kadm5_policy_ent_rec pol; - krb5_key_data *new_key_data = NULL; - int i, j, ret, n_new_key_data = 0; -diff --git a/src/lib/krb5/krb/gen_save_subkey.c b/src/lib/krb5/krb/gen_save_subkey.c -index 61f36aa36..bc2c46d30 100644 ---- a/src/lib/krb5/krb/gen_save_subkey.c -+++ b/src/lib/krb5/krb/gen_save_subkey.c -@@ -38,7 +38,8 @@ k5_generate_and_save_subkey(krb5_context context, - to guarantee randomness, but to make it less likely that multiple - sessions could pick the same subkey. */ - struct { -- krb5_int32 sec, usec; -+ krb5_timestamp sec; -+ krb5_int32 usec; - } rnd_data; - krb5_data d; - krb5_error_code retval; -diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c -index 40aba1905..7178bd87b 100644 ---- a/src/lib/krb5/krb/get_in_tkt.c -+++ b/src/lib/krb5/krb/get_in_tkt.c -@@ -1788,7 +1788,7 @@ k5_populate_gic_opt(krb5_context context, krb5_get_init_creds_opt **out, - krb5_creds *creds) - { - int i; -- krb5_int32 starttime; -+ krb5_timestamp starttime; - krb5_deltat lifetime; - krb5_get_init_creds_opt *opt; - krb5_error_code retval; -diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index cf226fdba..4246c5dd2 100644 ---- a/src/lib/krb5/krb/init_ctx.c -+++ b/src/lib/krb5/krb/init_ctx.c -@@ -139,7 +139,8 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, - krb5_context ctx = 0; - krb5_error_code retval; - struct { -- krb5_int32 now, now_usec; -+ krb5_timestamp now; -+ krb5_int32 now_usec; - long pid; - } seed_data; - krb5_data seed; -diff --git a/src/lib/krb5/os/c_ustime.c b/src/lib/krb5/os/c_ustime.c -index 68fb381f4..f69f2ea4c 100644 ---- a/src/lib/krb5/os/c_ustime.c -+++ b/src/lib/krb5/os/c_ustime.c -@@ -29,7 +29,10 @@ - - k5_mutex_t krb5int_us_time_mutex = K5_MUTEX_PARTIAL_INITIALIZER; - --struct time_now { krb5_int32 sec, usec; }; -+struct time_now { -+ krb5_timestamp sec; -+ krb5_int32 usec; -+}; - - #if defined(_WIN32) - -@@ -73,7 +76,7 @@ get_time_now(struct time_now *n) - static struct time_now last_time; - - krb5_error_code --krb5_crypto_us_timeofday(krb5_int32 *seconds, krb5_int32 *microseconds) -+krb5_crypto_us_timeofday(krb5_timestamp *seconds, krb5_int32 *microseconds) - { - struct time_now now; - krb5_error_code err; -diff --git a/src/lib/krb5/os/toffset.c b/src/lib/krb5/os/toffset.c -index 37bc69f49..4bbcdde52 100644 ---- a/src/lib/krb5/os/toffset.c -+++ b/src/lib/krb5/os/toffset.c -@@ -40,7 +40,8 @@ krb5_error_code KRB5_CALLCONV - krb5_set_real_time(krb5_context context, krb5_timestamp seconds, krb5_int32 microseconds) - { - krb5_os_context os_ctx = &context->os_context; -- krb5_int32 sec, usec; -+ krb5_timestamp sec; -+ krb5_int32 usec; - krb5_error_code retval; - - retval = krb5_crypto_us_timeofday(&sec, &usec); -diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c -index 74c315c90..8750b7650 100644 ---- a/src/lib/krb5/os/trace.c -+++ b/src/lib/krb5/os/trace.c -@@ -340,7 +340,8 @@ krb5int_trace(krb5_context context, const char *fmt, ...) - va_list ap; - krb5_trace_info info; - char *str = NULL, *msg = NULL; -- krb5_int32 sec, usec; -+ krb5_timestamp sec; -+ krb5_int32 usec; - - if (context == NULL || context->trace_callback == NULL) - return; -diff --git a/src/lib/krb5/os/ustime.c b/src/lib/krb5/os/ustime.c -index 1c1b571eb..a80fdf68c 100644 ---- a/src/lib/krb5/os/ustime.c -+++ b/src/lib/krb5/os/ustime.c -@@ -40,7 +40,8 @@ krb5_error_code - k5_time_with_offset(krb5_timestamp offset, krb5_int32 offset_usec, - krb5_timestamp *time_out, krb5_int32 *usec_out) - { -- krb5_int32 sec, usec; -+ krb5_timestamp sec; -+ krb5_int32 usec; - krb5_error_code retval; - - retval = krb5_crypto_us_timeofday(&sec, &usec); -diff --git a/src/lib/krb5/rcache/rc_dfl.c b/src/lib/krb5/rcache/rc_dfl.c -index 6b043844d..41ebf94da 100644 ---- a/src/lib/krb5/rcache/rc_dfl.c -+++ b/src/lib/krb5/rcache/rc_dfl.c -@@ -93,7 +93,7 @@ cmp(krb5_donot_replay *old, krb5_donot_replay *new1, krb5_deltat t) - } - - static int --alive(krb5_int32 mytime, krb5_donot_replay *new1, krb5_deltat t) -+alive(krb5_timestamp mytime, krb5_donot_replay *new1, krb5_deltat t) - { - if (mytime == 0) - return CMP_HOHUM; /* who cares? */ -@@ -129,7 +129,7 @@ struct authlist - - static int - rc_store(krb5_context context, krb5_rcache id, krb5_donot_replay *rep, -- krb5_int32 now, krb5_boolean fromfile) -+ krb5_timestamp now, krb5_boolean fromfile) - { - struct dfl_data *t = (struct dfl_data *)id->data; - unsigned int rephash; -@@ -536,7 +536,7 @@ krb5_rc_dfl_recover_locked(krb5_context context, krb5_rcache id) - krb5_error_code retval; - long max_size; - int expired_entries = 0; -- krb5_int32 now; -+ krb5_timestamp now; - - if ((retval = krb5_rc_io_open(context, &t->d, t->name))) { - return retval; -@@ -706,7 +706,7 @@ krb5_rc_dfl_store(krb5_context context, krb5_rcache id, krb5_donot_replay *rep) - { - krb5_error_code ret; - struct dfl_data *t; -- krb5_int32 now; -+ krb5_timestamp now; - - ret = krb5_timeofday(context, &now); - if (ret) -@@ -762,7 +762,7 @@ krb5_rc_dfl_expunge_locked(krb5_context context, krb5_rcache id) - struct authlist **qt; - struct authlist *r; - struct authlist *rt; -- krb5_int32 now; -+ krb5_timestamp now; - - if (krb5_timestamp(context, &now)) - now = 0; -diff --git a/src/tests/create/kdb5_mkdums.c b/src/tests/create/kdb5_mkdums.c -index 622f549f9..7c0666601 100644 ---- a/src/tests/create/kdb5_mkdums.c -+++ b/src/tests/create/kdb5_mkdums.c -@@ -247,7 +247,7 @@ add_princ(context, str_newprinc) - - { - /* Add mod princ to db entry */ -- krb5_int32 now; -+ krb5_timestamp now; - - retval = krb5_timeofday(context, &now); - if (retval) { diff --git a/Use-the-canonical-client-principal-name-for-OTP.patch b/Use-the-canonical-client-principal-name-for-OTP.patch deleted file mode 100644 index c96aeb5..0000000 --- a/Use-the-canonical-client-principal-name-for-OTP.patch +++ /dev/null @@ -1,28 +0,0 @@ -From 7998de0b9ccd0c8813159cc3f1d49fe107e3e0ba Mon Sep 17 00:00:00 2001 -From: Matt Rogers -Date: Wed, 5 Apr 2017 16:48:55 -0400 -Subject: [PATCH] Use the canonical client principal name for OTP - -In the OTP module, when constructing the RADIUS request, use the -canonicalized client principal (using the new client_name kdcpreauth -callback) instead of the request client principal. - -ticket: 8571 (new) ---- - src/plugins/preauth/otp/main.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/src/plugins/preauth/otp/main.c b/src/plugins/preauth/otp/main.c -index 2649e9a90..a1b681682 100644 ---- a/src/plugins/preauth/otp/main.c -+++ b/src/plugins/preauth/otp/main.c -@@ -331,7 +331,8 @@ otp_verify(krb5_context context, krb5_data *req_pkt, krb5_kdc_req *request, - - /* Send the request. */ - otp_state_verify((otp_state *)moddata, cb->event_context(context, rock), -- request->client, config, req, on_response, rs); -+ cb->client_name(context, rock), config, req, on_response, -+ rs); - cb->free_string(context, rock, config); - - k5_free_pa_otp_req(context, req); diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch index e68fb05..92f3dab 100644 --- a/krb5-1.11-kpasswdtest.patch +++ b/krb5-1.11-kpasswdtest.patch @@ -1,4 +1,4 @@ -From fb8f32ebdf3293d8a6bdb9478fe1f902a399ba7a Mon Sep 17 00:00:00 2001 +From 3e94cf1accf2b33bd0c8cf54eb58b4777f411cc6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:52:01 -0400 Subject: [PATCH] krb5-1.11-kpasswdtest.patch diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch index ad93b8a..9c4cf0e 100644 --- a/krb5-1.11-run_user_0.patch +++ b/krb5-1.11-run_user_0.patch @@ -1,4 +1,4 @@ -From 9c45f66fbc6afb472589dbeb5166f46ad266d319 Mon Sep 17 00:00:00 2001 +From 9e7e92ae1dcd242044f2dfe3b89926ddddb6a221 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:57 -0400 Subject: [PATCH] krb5-1.11-run_user_0.patch diff --git a/krb5-1.12-api.patch b/krb5-1.12-api.patch index c5bc2e5..0b8ec6f 100644 --- a/krb5-1.12-api.patch +++ b/krb5-1.12-api.patch @@ -1,4 +1,4 @@ -From 107a2b8728f1b76feb16df9201919444482e3981 Mon Sep 17 00:00:00 2001 +From 9a6cfaaecd1a37e74dba285decd03bb4a3382f9a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:00 -0400 Subject: [PATCH] krb5-1.12-api.patch diff --git a/krb5-1.12-ksu-path.patch b/krb5-1.12-ksu-path.patch index 7f92b1d..43178b9 100644 --- a/krb5-1.12-ksu-path.patch +++ b/krb5-1.12-ksu-path.patch @@ -1,4 +1,4 @@ -From 93b86d94b871aed49b14d7fc1a2a9f23c16cbe0f Mon Sep 17 00:00:00 2001 +From 7b3bdbc0ca882325291caad391c4d328f174a614 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:32:09 -0400 Subject: [PATCH] krb5-1.12-ksu-path.patch diff --git a/krb5-1.12-ktany.patch b/krb5-1.12-ktany.patch index a941082..24135fd 100644 --- a/krb5-1.12-ktany.patch +++ b/krb5-1.12-ktany.patch @@ -1,4 +1,4 @@ -From efee9f8598ba84f2be0983fc1d07a9a72d0ff1b7 Mon Sep 17 00:00:00 2001 +From 1ede8564105568182e3cf6f273ab820453e2f025 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:33:53 -0400 Subject: [PATCH] krb5-1.12-ktany.patch diff --git a/krb5-1.12.1-pam.patch b/krb5-1.12.1-pam.patch index 5372fb4..c56606f 100644 --- a/krb5-1.12.1-pam.patch +++ b/krb5-1.12.1-pam.patch @@ -1,4 +1,4 @@ -From e0924e10dd431a898c9c95faa04b51edbe59c5ef Mon Sep 17 00:00:00 2001 +From 385194db1a08c1b923f9eb75e9602b56720fd50e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] krb5-1.12.1-pam.patch @@ -28,10 +28,10 @@ changes we're proposing for how it handles cache collections. create mode 100644 src/clients/ksu/pam.h diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 9c46da4b5..508e5fe90 100644 +index d6d1279c3..5c9c13e5f 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -1675,3 +1675,70 @@ AC_DEFUN(KRB5_AC_PERSISTENT_KEYRING,[ +@@ -1696,3 +1696,70 @@ AC_DEFUN(KRB5_AC_PERSISTENT_KEYRING,[ ])) ])dnl dnl @@ -141,7 +141,7 @@ index b2fcbf240..5755bb58a 100644 clean: $(RM) ksu diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c -index 28342c2d7..cab0c1806 100644 +index 7ff676ca7..c6321c01b 100644 --- a/src/clients/ksu/main.c +++ b/src/clients/ksu/main.c @@ -26,6 +26,7 @@ @@ -756,10 +756,10 @@ index 000000000..0ab76569c +void appl_pam_cleanup(void); +#endif diff --git a/src/configure.in b/src/configure.in -index 037c9f316..daabd12c8 100644 +index 10f45eb12..7288a71ec 100644 --- a/src/configure.in +++ b/src/configure.in -@@ -1336,6 +1336,8 @@ AC_SUBST([VERTO_VERSION]) +@@ -1306,6 +1306,8 @@ AC_SUBST([VERTO_VERSION]) AC_PATH_PROG(GROFF, groff) diff --git a/krb5-1.13-dirsrv-accountlock.patch b/krb5-1.13-dirsrv-accountlock.patch index 9b0178c..47716dc 100644 --- a/krb5-1.13-dirsrv-accountlock.patch +++ b/krb5-1.13-dirsrv-accountlock.patch @@ -1,4 +1,4 @@ -From f2df0b75dfbc9796bf8e1477f4661dfb7cdcf8d4 Mon Sep 17 00:00:00 2001 +From 850689009f9aeddc0b63051a3e2883d02b05387e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:44 -0400 Subject: [PATCH] krb5-1.13-dirsrv-accountlock.patch @@ -12,10 +12,10 @@ original version filed as RT#5891. 3 files changed, 29 insertions(+) diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index f5667c35f..2bfb99496 100644 +index 5eeaa2d8a..1fd243094 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -1656,6 +1656,15 @@ if test "$with_ldap" = yes; then +@@ -1677,6 +1677,15 @@ if test "$with_ldap" = yes; then AC_MSG_NOTICE(enabling OpenLDAP database backend module support) OPENLDAP_PLUGIN=yes fi @@ -32,10 +32,10 @@ index f5667c35f..2bfb99496 100644 dnl dnl If libkeyutils exists (on Linux) include it and use keyring ccache diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c -index 32efc4f54..af8b2db7b 100644 +index 5b9d1e9fa..4e7270065 100644 --- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c +++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c -@@ -1674,6 +1674,23 @@ populate_krb5_db_entry(krb5_context context, krb5_ldap_context *ldap_context, +@@ -1652,6 +1652,23 @@ populate_krb5_db_entry(krb5_context context, krb5_ldap_context *ldap_context, ret = krb5_dbe_update_tl_data(context, entry, &userinfo_tl_data); if (ret) goto cleanup; diff --git a/krb5-1.15-beta1-buildconf.patch b/krb5-1.15-beta1-buildconf.patch index 276c254..b0024ec 100644 --- a/krb5-1.15-beta1-buildconf.patch +++ b/krb5-1.15-beta1-buildconf.patch @@ -1,4 +1,4 @@ -From ae5bb11c0f06fdf92f51d237e94c1d410c59aa04 Mon Sep 17 00:00:00 2001 +From 285eaffa69e9c2ff7f0adf017d192b5e7afb7002 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] krb5-1.15-beta1-buildconf.patch @@ -33,7 +33,7 @@ index c17cb5eb5..1891dea99 100755 lib_flags="$lib_flags -lkdb5 $KDB5_DB_LIB" library=krb5 diff --git a/src/config/pre.in b/src/config/pre.in -index fcea229bd..d961b5621 100644 +index d4714d29a..03f5c8890 100644 --- a/src/config/pre.in +++ b/src/config/pre.in @@ -185,7 +185,7 @@ INSTALL_PROGRAM=@INSTALL_PROGRAM@ $(INSTALL_STRIP) diff --git a/krb5-1.15.1-selinux-label.patch b/krb5-1.15.1-selinux-label.patch index 2590f8e..475f74d 100644 --- a/krb5-1.15.1-selinux-label.patch +++ b/krb5-1.15.1-selinux-label.patch @@ -1,4 +1,4 @@ -From aaf74b66a51cbda90ba40f73eb8def9b192ab262 Mon Sep 17 00:00:00 2001 +From d38588a165302d915eb6b4da0c2755601547bcd1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] krb5-1.15.1-selinux-label.patch @@ -66,7 +66,7 @@ which we used earlier, is some improvement. create mode 100644 src/util/support/selinux.c diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 508e5fe90..607859f17 100644 +index 5c9c13e5f..6257dba40 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 @@ -89,6 +89,7 @@ AC_SUBST_FILE(libnodeps_frag) @@ -77,7 +77,7 @@ index 508e5fe90..607859f17 100644 KRB5_LIB_PARAMS KRB5_AC_INITFINI KRB5_AC_ENABLE_THREADS -@@ -1742,3 +1743,51 @@ AC_SUBST(PAM_LIBS) +@@ -1763,3 +1764,51 @@ AC_SUBST(PAM_LIBS) AC_SUBST(PAM_MAN) AC_SUBST(NON_PAM_MAN) ])dnl @@ -151,7 +151,7 @@ index f6184da3f..c17cb5eb5 100755 echo $lib_flags diff --git a/src/config/pre.in b/src/config/pre.in -index e0626320c..fcea229bd 100644 +index 3f267eb1f..d4714d29a 100644 --- a/src/config/pre.in +++ b/src/config/pre.in @@ -177,6 +177,7 @@ LD = $(PURE) @LD@ @@ -170,12 +170,12 @@ index e0626320c..fcea229bd 100644 +KRB5_BASE_LIBS = $(KRB5_LIB) $(K5CRYPTO_LIB) $(COM_ERR_LIB) $(SUPPORT_LIB) $(GEN_LIB) $(LIBS) $(SELINUX_LIBS) $(DL_LIB) KDB5_LIBS = $(KDB5_LIB) $(GSSRPC_LIBS) GSS_LIBS = $(GSS_KRB5_LIB) - # needs fixing if ever used on Mac OS X! + # needs fixing if ever used on macOS! diff --git a/src/configure.in b/src/configure.in -index daabd12c8..acf3a458b 100644 +index 7288a71ec..2b6d5baa7 100644 --- a/src/configure.in +++ b/src/configure.in -@@ -1338,6 +1338,8 @@ AC_PATH_PROG(GROFF, groff) +@@ -1308,6 +1308,8 @@ AC_PATH_PROG(GROFF, groff) KRB5_WITH_PAM @@ -185,7 +185,7 @@ index daabd12c8..acf3a458b 100644 if test "${localedir+set}" != set; then localedir='$(datadir)/locale' diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 64991738a..173cb0264 100644 +index e1b1cb040..9378ae047 100644 --- a/src/include/k5-int.h +++ b/src/include/k5-int.h @@ -128,6 +128,7 @@ typedef unsigned char u_char; @@ -235,7 +235,7 @@ index 000000000..dfaaa847c +#endif +#endif diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index ac22f4c55..cf60d6c41 100644 +index c86e78274..e81bb0a6d 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin @@ -87,6 +87,12 @@ @@ -252,7 +252,7 @@ index ac22f4c55..cf60d6c41 100644 #include diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c -index f7889bd23..cad53cfbf 100644 +index aca136f0b..22e926ae4 100644 --- a/src/kadmin/dbutil/dump.c +++ b/src/kadmin/dbutil/dump.c @@ -148,12 +148,21 @@ create_ofile(char *ofile, char **tmpname) @@ -287,10 +287,10 @@ index f7889bd23..cad53cfbf 100644 com_err(progname, errno, _("while creating 'ok' file, '%s'"), file_ok); exit_status++; diff --git a/src/kdc/main.c b/src/kdc/main.c -index ebc852bba..a4dffb29a 100644 +index f2226da25..ccac3a759 100644 --- a/src/kdc/main.c +++ b/src/kdc/main.c -@@ -872,7 +872,7 @@ write_pid_file(const char *path) +@@ -873,7 +873,7 @@ write_pid_file(const char *path) FILE *file; unsigned long pid; @@ -385,10 +385,10 @@ index bba64e516..73f0fe62d 100644 _("Credential cache directory %s does not exist"), dirname); diff --git a/src/lib/krb5/keytab/kt_file.c b/src/lib/krb5/keytab/kt_file.c -index 6a42f267d..674d88bab 100644 +index 091f2c43f..ecc97ee2f 100644 --- a/src/lib/krb5/keytab/kt_file.c +++ b/src/lib/krb5/keytab/kt_file.c -@@ -1022,14 +1022,14 @@ krb5_ktfileint_open(krb5_context context, krb5_keytab id, int mode) +@@ -1024,14 +1024,14 @@ krb5_ktfileint_open(krb5_context context, krb5_keytab id, int mode) KTCHECKLOCK(id); errno = 0; @@ -406,10 +406,10 @@ index 6a42f267d..674d88bab 100644 goto report_errno; writevno = 1; diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c -index 83c8d4db8..a19246128 100644 +index e97ce5fe5..779f184cb 100644 --- a/src/lib/krb5/os/trace.c +++ b/src/lib/krb5/os/trace.c -@@ -397,7 +397,7 @@ krb5_set_trace_filename(krb5_context context, const char *filename) +@@ -398,7 +398,7 @@ krb5_set_trace_filename(krb5_context context, const char *filename) fd = malloc(sizeof(*fd)); if (fd == NULL) return ENOMEM; @@ -419,10 +419,10 @@ index 83c8d4db8..a19246128 100644 free(fd); return errno; diff --git a/src/lib/krb5/rcache/rc_dfl.c b/src/lib/krb5/rcache/rc_dfl.c -index c4d2c744d..c0f12ed9d 100644 +index 1e0cb22c9..f5e93b1ab 100644 --- a/src/lib/krb5/rcache/rc_dfl.c +++ b/src/lib/krb5/rcache/rc_dfl.c -@@ -794,6 +794,9 @@ krb5_rc_dfl_expunge_locked(krb5_context context, krb5_rcache id) +@@ -793,6 +793,9 @@ krb5_rc_dfl_expunge_locked(krb5_context context, krb5_rcache id) krb5_error_code retval = 0; krb5_rcache tmp; krb5_deltat lifespan = t->lifespan; /* save original lifespan */ @@ -432,7 +432,7 @@ index c4d2c744d..c0f12ed9d 100644 if (! t->recovering) { name = t->name; -@@ -815,7 +818,17 @@ krb5_rc_dfl_expunge_locked(krb5_context context, krb5_rcache id) +@@ -814,7 +817,17 @@ krb5_rc_dfl_expunge_locked(krb5_context context, krb5_rcache id) retval = krb5_rc_resolve(context, tmp, 0); if (retval) goto cleanup; @@ -464,7 +464,7 @@ index 7db30a33b..2b9d01921 100644 * maybe someone took away write permission so we could only * get shared locks? diff --git a/src/plugins/kdb/db2/kdb_db2.c b/src/plugins/kdb/db2/kdb_db2.c -index 4c4036eb4..d90bdeaba 100644 +index d23587a59..e2825650b 100644 --- a/src/plugins/kdb/db2/kdb_db2.c +++ b/src/plugins/kdb/db2/kdb_db2.c @@ -694,8 +694,8 @@ ctx_create_db(krb5_context context, krb5_db2_context *dbc) @@ -500,7 +500,7 @@ index 2977b17f3..d5809a5a9 100644 } else { diff --git a/src/plugins/kdb/db2/libdb2/hash/hash.c b/src/plugins/kdb/db2/libdb2/hash/hash.c -index 76f5d4709..1fa8b8389 100644 +index 862dbb164..686a960c9 100644 --- a/src/plugins/kdb/db2/libdb2/hash/hash.c +++ b/src/plugins/kdb/db2/libdb2/hash/hash.c @@ -51,6 +51,7 @@ static char sccsid[] = "@(#)hash.c 8.12 (Berkeley) 11/7/95"; @@ -511,7 +511,7 @@ index 76f5d4709..1fa8b8389 100644 #include "db-int.h" #include "hash.h" #include "page.h" -@@ -140,7 +141,7 @@ __kdb2_hash_open(file, flags, mode, info, dflags) +@@ -129,7 +130,7 @@ __kdb2_hash_open(file, flags, mode, info, dflags) new_table = 1; } if (file) { @@ -580,10 +580,10 @@ index 022156a5e..3d6994c67 100644 if (newfile == NULL) { com_err(me, errno, _("Error creating file %s"), tmp_file); diff --git a/src/slave/kpropd.c b/src/slave/kpropd.c -index 056c31a42..b78c3d9e5 100644 +index d621f108f..99676cc97 100644 --- a/src/slave/kpropd.c +++ b/src/slave/kpropd.c -@@ -464,6 +464,9 @@ doit(int fd) +@@ -488,6 +488,9 @@ doit(int fd) krb5_enctype etype; int database_fd; char host[INET6_ADDRSTRLEN + 1]; @@ -593,7 +593,7 @@ index 056c31a42..b78c3d9e5 100644 signal_wrapper(SIGALRM, alarm_handler); alarm(params.iprop_resync_timeout); -@@ -520,9 +523,15 @@ doit(int fd) +@@ -543,9 +546,15 @@ doit(int fd) free(name); exit(1); } @@ -631,7 +631,7 @@ index 907c119bb..0f5462aea 100644 retval = errno; if (retval == 0) diff --git a/src/util/support/Makefile.in b/src/util/support/Makefile.in -index 6239e4176..17bcd2a67 100644 +index 0bf0b7a87..58ac2e333 100644 --- a/src/util/support/Makefile.in +++ b/src/util/support/Makefile.in @@ -69,6 +69,7 @@ IPC_SYMS= \ @@ -642,7 +642,7 @@ index 6239e4176..17bcd2a67 100644 init-addrinfo.o \ plugins.o \ errors.o \ -@@ -148,7 +149,7 @@ SRCS=\ +@@ -149,7 +150,7 @@ SRCS=\ SHLIB_EXPDEPS = # Add -lm if dumping thread stats, for sqrt. diff --git a/krb5-1.3.1-dns.patch b/krb5-1.3.1-dns.patch index 766226f..c50f1df 100644 --- a/krb5-1.3.1-dns.patch +++ b/krb5-1.3.1-dns.patch @@ -1,4 +1,4 @@ -From 1b95f8a488d1e70bf7698c8b49412306a1b8aba0 Mon Sep 17 00:00:00 2001 +From 4bc124bfff119d436eeb1af7b9d5726e17284d67 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] krb5-1.3.1-dns.patch @@ -9,10 +9,10 @@ We want to be able to use --with-netlib and --enable-dns at the same time. 1 file changed, 1 insertion(+) diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 607859f17..f5667c35f 100644 +index 6257dba40..5eeaa2d8a 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -703,6 +703,7 @@ AC_HELP_STRING([--with-netlib=LIBS], use user defined resolver library), +@@ -726,6 +726,7 @@ AC_HELP_STRING([--with-netlib=LIBS], use user defined resolver library), LIBS="$LIBS $withval" AC_MSG_RESULT("netlib will use \'$withval\'") fi diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index d3d0080..57a8b32 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -1,4 +1,4 @@ -From e1d7fcf9713fe322ad5740045650dac86427e6ae Mon Sep 17 00:00:00 2001 +From 82f8b63ae3955423456adf15790c10eb1145ec52 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] krb5-1.9-debuginfo.patch diff --git a/krb5.spec b/krb5.spec index df62457..53c3d25 100644 --- a/krb5.spec +++ b/krb5.spec @@ -9,21 +9,21 @@ %global configured_default_ccache_name KEYRING:persistent:%%{uid} # leave empty or set to e.g., -beta2 -%global prerelease %{nil} +%global prerelease -beta1 # Should be in form 5.0, 6.1, etc. %global kdbversion 6.1 Summary: The Kerberos network authentication system Name: krb5 -Version: 1.15.2 -# for prerelease, should be e.g., 0.3.beta2% { ?dist } (without spaces) -Release: 2%{?dist} +Version: 1.16 +# for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) +Release: 0.beta1.1%{?dist} # lookaside-cached sources; two downloads and a build artifact -Source0: https://web.mit.edu/kerberos/dist/krb5/1.15/krb5-%{version}%{prerelease}.tar.gz +Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz # rharwood has trust path to signing key and verifies on check-in -Source1: https://web.mit.edu/kerberos/dist/krb5/1.15/krb5-%{version}%{prerelease}.tar.gz.asc +Source1: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz.asc # This source is generated during the build because it is documentation. # To override this behavior (e.g., new upstream version), do: # tar cfT krb5-1.15.2-pdfs.tar /dev/null @@ -60,38 +60,7 @@ Patch33: krb5-1.13-dirsrv-accountlock.patch Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch -Patch37: Build-with-Werror-implicit-int-where-supported.patch -Patch38: Add-PKINIT-UPN-tests-to-t_pkinit.py.patch -Patch39: Add-test-case-for-PKINIT-DH-renegotiation.patch -Patch40: Use-expected_trace-in-test-scripts.patch -Patch41: Use-expected_msg-in-test-scripts.patch -Patch42: Use-fallback-realm-for-GSSAPI-ccache-selection.patch Patch43: Use-GSSAPI-fallback-skiptest.patch -Patch44: Improve-PKINIT-UPN-SAN-matching.patch -Patch45: Add-test-cert-generation-to-make-certs.sh.patch -Patch46: Deindent-crypto_retrieve_X509_sans.patch -Patch47: Add-the-client_name-kdcpreauth-callback.patch -Patch48: Use-the-canonical-client-principal-name-for-OTP.patch -Patch49: Add-certauth-pluggable-interface.patch -Patch50: Correct-error-handling-bug-in-prior-commit.patch -Patch51: Add-k5test-expected_msg-expected_trace.patch -Patch53: Add-support-to-query-the-SSF-of-a-GSS-context.patch -Patch55: Remove-incomplete-PKINIT-OCSP-support.patch -Patch57: Fix-in_clock_skew-and-use-it-in-AS-client-code.patch -Patch58: Add-timestamp-helper-functions.patch -Patch59: Make-timestamp-manipulations-y2038-safe.patch -Patch60: Add-timestamp-tests.patch -Patch61: Add-y2038-documentation.patch -Patch62: Fix-more-time-manipulations-for-y2038.patch -Patch63: Use-krb5_timestamp-where-appropriate.patch -Patch64: Add-KDC-policy-pluggable-interface.patch -Patch65: Fix-bugs-in-kdcpolicy-commit.patch -Patch66: Convert-some-pkiDebug-messages-to-TRACE-macros.patch -Patch67: Fix-certauth-built-in-module-returns.patch -Patch68: Add-test-cert-with-no-extensions.patch -Patch69: Add-PKINIT-test-case-for-generic-client-cert.patch -Patch70: Add-hostname-based-ccselect-module.patch -Patch71: Add-German-translation.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -381,7 +350,7 @@ for pdf in admin appdev basic build plugindev user ; do test -s build-pdf/$pdf.pdf || make -C build-pdf done # new krb5-%{version}-pdf -tar -cf "krb5-%{version}-pdfs.tar.new" build-pdf/*.pdf +tar -cf "krb5-%{version}%{prerelease}-pdfs.tar.new" build-pdf/*.pdf # We need to cut off any access to locally-running nameservers, too. %{__cc} -fPIC -shared -o noport.so -Wall -Wextra $RPM_SOURCE_DIR/noport.c @@ -745,6 +714,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Oct 05 2017 Robbie Harwood - 1.16-0.beta1.1 +- New upstream prerelease (1.16-beta1) + * Thu Sep 28 2017 Robbie Harwood - 1.15.2-2 - Add German translation diff --git a/sources b/sources index a72430d..d5f6442 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (krb5-1.15.2-pdfs.tar) = 5875efde7ed88dcccd6f624a5252c5c70844fe94015ce4acfdf7f6ccabf52c86965c5a661b161c73e37b46e51aa5e9ea19602ab32e8b50682ecb0a450f0553b6 -SHA512 (krb5-1.15.2.tar.gz) = e5814bb66384b13637c37918df694c6b9933c29c2d952da0ed0dcd2e623b269060b4c16b6c02162039dadebdab99ff1085e37e7621ae4748dafb036424e612c2 -SHA512 (krb5-1.15.2.tar.gz.asc) = 37cee442de29229fa821539c3f1724eb4d37fa9ce5eee644869a7311c8fe10218dac36da3a5297d45168d8fb1ad64dbd614f10d3384d54e4070e56e7fe8a1e63 +SHA512 (krb5-1.16-beta1-pdfs.tar) = 79329b7978101723a5c9f55773ac69bd1986c716e6d8b4cd42cbf17a8e85cd49f13b376e0b4b0ccca485b5a5a79d6bce8ace0c22df79b6f0a47a74c387f83ffd +SHA512 (krb5-1.16-beta1.tar.gz) = 68dba5212d2dd28ed0bc4961931af8d291bcdf2805baa4e930b0218f7749dc1e4dfe696aacca0529787f274b99fe5a8297f3e13877f724ee983483b399daf2c9 +SHA512 (krb5-1.16-beta1.tar.gz.asc) = 342272496897b4a4452d73186b7d19bbc3155e38fe39e0e852e03ce4757a3284baefbb1c49653e53d36e96ab587a7acb718e14c8281ccca85cb0de4c7d0b730e From e02d5c1dacd83eb53537641f3ad0e267c9ca48bb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 9 Oct 2017 15:24:04 +0000 Subject: [PATCH 002/304] Actually bump kdbversion like I was supposed to --- krb5.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/krb5.spec b/krb5.spec index 53c3d25..5edaaa0 100644 --- a/krb5.spec +++ b/krb5.spec @@ -12,13 +12,13 @@ %global prerelease -beta1 # Should be in form 5.0, 6.1, etc. -%global kdbversion 6.1 +%global kdbversion 7.0 Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 0.beta1.1%{?dist} +Release: 0.beta1.2%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -714,6 +714,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Oct 09 2017 Robbie Harwood - 1.16-0.beta1.2 +- Actually bump kdbversion like I was supposed to + * Thu Oct 05 2017 Robbie Harwood - 1.16-0.beta1.1 - New upstream prerelease (1.16-beta1) From 6e83fb6a5e95320177a4d3a0e4fae6b3546bd19f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 23 Oct 2017 16:28:53 +0000 Subject: [PATCH 003/304] Drop dependency on python2-pyrad (dead upstream, broken with new python) --- krb5.spec | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/krb5.spec b/krb5.spec index 5edaaa0..c390007 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 0.beta1.2%{?dist} +Release: 0.beta1.3%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -110,7 +110,6 @@ BuildRequires: perl-interpreter, dejagnu, tcl-devel BuildRequires: net-tools, rpcbind BuildRequires: hostname BuildRequires: iproute -BuildRequires: python2-pyrad BuildRequires: libverto-devel BuildRequires: openldap-devel BuildRequires: openssl-devel >= 0.9.8 @@ -714,6 +713,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Oct 23 2017 Robbie Harwood - 1.16-0.beta1.3 +- Drop dependency on python2-pyrad (dead upstream, broken with new python) + * Mon Oct 09 2017 Robbie Harwood - 1.16-0.beta1.2 - Actually bump kdbversion like I was supposed to From 91465b2b091557c11d9824b34c1ae8a8b7d345b3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 23 Oct 2017 16:28:53 +0000 Subject: [PATCH 004/304] Drop dependency on python2-pyrad (dead upstream, broken with new python) --- krb5.spec | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/krb5.spec b/krb5.spec index df62457..5257456 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.15.2 # for prerelease, should be e.g., 0.3.beta2% { ?dist } (without spaces) -Release: 2%{?dist} +Release: 3%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.15/krb5-%{version}%{prerelease}.tar.gz @@ -141,7 +141,6 @@ BuildRequires: perl-interpreter, dejagnu, tcl-devel BuildRequires: net-tools, rpcbind BuildRequires: hostname BuildRequires: iproute -BuildRequires: python2-pyrad BuildRequires: libverto-devel BuildRequires: openldap-devel BuildRequires: openssl-devel >= 0.9.8 @@ -745,6 +744,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Oct 23 2017 Robbie Harwood - 1.15.2-3 +- Drop dependency on python2-pyrad (dead upstream, broken with new python) + * Thu Sep 28 2017 Robbie Harwood - 1.15.2-2 - Add German translation From 1884c63c38f83b45af237ccb58a17b786a441f09 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 24 Oct 2017 15:59:37 -0400 Subject: [PATCH 005/304] Fix CVE-2017-15088 (Buffer overflow in get_matching_data()) --- ...INIT-cert-matching-data-construction.patch | 105 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 110 insertions(+), 1 deletion(-) create mode 100644 Fix-PKINIT-cert-matching-data-construction.patch diff --git a/Fix-PKINIT-cert-matching-data-construction.patch b/Fix-PKINIT-cert-matching-data-construction.patch new file mode 100644 index 0000000..99b3db7 --- /dev/null +++ b/Fix-PKINIT-cert-matching-data-construction.patch @@ -0,0 +1,105 @@ +From 3fe07aaa6d8b6115aa19e2c04087352a5c87a568 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 24 Oct 2017 15:33:37 -0400 +Subject: [PATCH] Fix PKINIT cert matching data construction + +Rewrite X509_NAME_oneline_ex() and its call sites to use dynamic +allocation and to perform proper error checking. + +(cherry picked from commit 1d8fb334a6256b9ddd3d4377a92c2441407d8a12) +--- + src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 63 ++++++++-------------- + 1 file changed, 21 insertions(+), 42 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 7fa2efd21..336102656 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -5139,33 +5139,23 @@ out: + return retval; + } + +-/* +- * Return a string format of an X509_NAME in buf where +- * size is an in/out parameter. On input it is the size +- * of the buffer, and on output it is the actual length +- * of the name. +- * If buf is NULL, returns the length req'd to hold name +- */ +-static char * +-X509_NAME_oneline_ex(X509_NAME * a, +- char *buf, +- unsigned int *size, +- unsigned long flag) ++static krb5_error_code ++rfc2253_name(X509_NAME *name, char **str_out) + { +- BIO *out = NULL; ++ BIO *b = NULL; ++ char *str; + +- out = BIO_new(BIO_s_mem ()); +- if (X509_NAME_print_ex(out, a, 0, flag) > 0) { +- if (buf != NULL && (*size) > (unsigned int) BIO_number_written(out)) { +- memset(buf, 0, *size); +- BIO_read(out, buf, (int) BIO_number_written(out)); +- } +- else { +- *size = BIO_number_written(out); +- } +- } +- BIO_free(out); +- return (buf); ++ *str_out = NULL; ++ b = BIO_new(BIO_s_mem()); ++ if (X509_NAME_print_ex(b, name, 0, XN_FLAG_SEP_COMMA_PLUS) < 0) ++ return ENOMEM; ++ str = calloc(BIO_number_written(b) + 1, 1); ++ if (str == NULL) ++ return ENOMEM; ++ BIO_read(b, str, BIO_number_written(b)); ++ BIO_free(b); ++ *str_out = str; ++ return 0; + } + + /* +@@ -5181,8 +5171,6 @@ crypto_cert_get_matching_data(krb5_context context, + krb5_principal *pkinit_sans =NULL, *upn_sans = NULL; + struct _pkinit_cert_data *cd = (struct _pkinit_cert_data *)ch; + unsigned int i, j; +- char buf[DN_BUF_LEN]; +- unsigned int bufsize = sizeof(buf); + + if (cd == NULL || cd->magic != CERT_MAGIC) + return EINVAL; +@@ -5195,23 +5183,14 @@ crypto_cert_get_matching_data(krb5_context context, + + md->ch = ch; + +- /* get the subject name (in rfc2253 format) */ +- X509_NAME_oneline_ex(X509_get_subject_name(cd->cred->cert), +- buf, &bufsize, XN_FLAG_SEP_COMMA_PLUS); +- md->subject_dn = strdup(buf); +- if (md->subject_dn == NULL) { +- retval = ENOMEM; ++ retval = rfc2253_name(X509_get_subject_name(cd->cred->cert), ++ &md->subject_dn); ++ if (retval) + goto cleanup; +- } +- +- /* get the issuer name (in rfc2253 format) */ +- X509_NAME_oneline_ex(X509_get_issuer_name(cd->cred->cert), +- buf, &bufsize, XN_FLAG_SEP_COMMA_PLUS); +- md->issuer_dn = strdup(buf); +- if (md->issuer_dn == NULL) { +- retval = ENOMEM; ++ retval = rfc2253_name(X509_get_issuer_name(cd->cred->cert), ++ &md->issuer_dn); ++ if (retval) + goto cleanup; +- } + + /* get the san data */ + retval = crypto_retrieve_X509_sans(context, cd->plgctx, cd->reqctx, diff --git a/krb5.spec b/krb5.spec index 5257456..e790908 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.15.2 # for prerelease, should be e.g., 0.3.beta2% { ?dist } (without spaces) -Release: 3%{?dist} +Release: 4%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.15/krb5-%{version}%{prerelease}.tar.gz @@ -92,6 +92,7 @@ Patch68: Add-test-cert-with-no-extensions.patch Patch69: Add-PKINIT-test-case-for-generic-client-cert.patch Patch70: Add-hostname-based-ccselect-module.patch Patch71: Add-German-translation.patch +Patch72: Fix-PKINIT-cert-matching-data-construction.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -744,6 +745,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Oct 24 2017 Robbie Harwood - 1.15.2-4 +- Fix CVE-2017-15088 (Buffer overflow in get_matching_data()) + * Mon Oct 23 2017 Robbie Harwood - 1.15.2-3 - Drop dependency on python2-pyrad (dead upstream, broken with new python) From 23141c22b16d8a7248bc50c6c56dc1836de8d086 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 24 Oct 2017 15:18:59 -0400 Subject: [PATCH 006/304] Fix CVE-2017-15088 (Buffer overflow in get_matching_data()) --- ...INIT-cert-matching-data-construction.patch | 103 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 108 insertions(+), 1 deletion(-) create mode 100644 Fix-PKINIT-cert-matching-data-construction.patch diff --git a/Fix-PKINIT-cert-matching-data-construction.patch b/Fix-PKINIT-cert-matching-data-construction.patch new file mode 100644 index 0000000..577db58 --- /dev/null +++ b/Fix-PKINIT-cert-matching-data-construction.patch @@ -0,0 +1,103 @@ +From 82854302309e2a513908cf85ed9321113ef26a08 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 24 Oct 2017 15:09:57 -0400 +Subject: [PATCH] Fix PKINIT cert matching data construction + +Rewrite X509_NAME_oneline_ex() and its call sites to use dynamic +allocation and to perform proper error checking. + +(cherry picked from commit 5a2faf2802480548ff6a7261552ee17efaed7be1) +--- + src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 61 +++++++--------------- + 1 file changed, 19 insertions(+), 42 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index f7640baf1..9fa20a8b2 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -5002,33 +5002,23 @@ out: + return retval; + } + +-/* +- * Return a string format of an X509_NAME in buf where +- * size is an in/out parameter. On input it is the size +- * of the buffer, and on output it is the actual length +- * of the name. +- * If buf is NULL, returns the length req'd to hold name +- */ +-static char * +-X509_NAME_oneline_ex(X509_NAME * a, +- char *buf, +- unsigned int *size, +- unsigned long flag) ++static krb5_error_code ++rfc2253_name(X509_NAME *name, char **str_out) + { +- BIO *out = NULL; ++ BIO *b = NULL; ++ char *str; + +- out = BIO_new(BIO_s_mem ()); +- if (X509_NAME_print_ex(out, a, 0, flag) > 0) { +- if (buf != NULL && (*size) > (unsigned int) BIO_number_written(out)) { +- memset(buf, 0, *size); +- BIO_read(out, buf, (int) BIO_number_written(out)); +- } +- else { +- *size = BIO_number_written(out); +- } +- } +- BIO_free(out); +- return (buf); ++ *str_out = NULL; ++ b = BIO_new(BIO_s_mem()); ++ if (X509_NAME_print_ex(b, name, 0, XN_FLAG_SEP_COMMA_PLUS) < 0) ++ return ENOMEM; ++ str = calloc(BIO_number_written(b) + 1, 1); ++ if (str == NULL) ++ return ENOMEM; ++ BIO_read(b, str, BIO_number_written(b)); ++ BIO_free(b); ++ *str_out = str; ++ return 0; + } + + /* +@@ -5094,8 +5084,6 @@ get_matching_data(krb5_context context, + pkinit_cert_matching_data *md = NULL; + krb5_principal *pkinit_sans = NULL, *upn_sans = NULL; + size_t i, j; +- char buf[DN_BUF_LEN]; +- unsigned int bufsize = sizeof(buf); + + *md_out = NULL; + +@@ -5103,23 +5091,12 @@ get_matching_data(krb5_context context, + if (md == NULL) + goto cleanup; + +- /* Get the subject name (in rfc2253 format). */ +- X509_NAME_oneline_ex(X509_get_subject_name(cert), buf, &bufsize, +- XN_FLAG_SEP_COMMA_PLUS); +- md->subject_dn = strdup(buf); +- if (md->subject_dn == NULL) { +- ret = ENOMEM; ++ ret = rfc2253_name(X509_get_subject_name(cert), &md->subject_dn); ++ if (ret) + goto cleanup; +- } +- +- /* Get the issuer name (in rfc2253 format). */ +- X509_NAME_oneline_ex(X509_get_issuer_name(cert), buf, &bufsize, +- XN_FLAG_SEP_COMMA_PLUS); +- md->issuer_dn = strdup(buf); +- if (md->issuer_dn == NULL) { +- ret = ENOMEM; ++ ret = rfc2253_name(X509_get_issuer_name(cert), &md->issuer_dn); ++ if (ret) + goto cleanup; +- } + + /* Get the SAN data. */ + ret = crypto_retrieve_X509_sans(context, plg_cryptoctx, req_cryptoctx, diff --git a/krb5.spec b/krb5.spec index c390007..cf24c0a 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 0.beta1.3%{?dist} +Release: 0.beta1.4%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -61,6 +61,7 @@ Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch Patch43: Use-GSSAPI-fallback-skiptest.patch +Patch44: Fix-PKINIT-cert-matching-data-construction.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -713,6 +714,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Oct 24 2017 Robbie Harwood - 1.16-0.beta1.4 +- Fix CVE-2017-15088 (Buffer overflow in get_matching_data()) + * Mon Oct 23 2017 Robbie Harwood - 1.16-0.beta1.3 - Drop dependency on python2-pyrad (dead upstream, broken with new python) From 17620d4f26c22e00463df7b0de5efbafc381d07c Mon Sep 17 00:00:00 2001 From: Yevhenii Shapovalov Date: Mon, 27 Nov 2017 14:42:49 +0200 Subject: [PATCH 007/304] add tests with standard tests interface --- tests/inplace-upgrade-sanity-test/Makefile | 64 ++++ tests/inplace-upgrade-sanity-test/PURPOSE | 3 + tests/inplace-upgrade-sanity-test/kdc.conf | 19 ++ tests/inplace-upgrade-sanity-test/krb5.conf | 36 +++ tests/inplace-upgrade-sanity-test/runtest.sh | 306 +++++++++++++++++++ tests/tests.yml | 16 + 6 files changed, 444 insertions(+) create mode 100644 tests/inplace-upgrade-sanity-test/Makefile create mode 100644 tests/inplace-upgrade-sanity-test/PURPOSE create mode 100644 tests/inplace-upgrade-sanity-test/kdc.conf create mode 100644 tests/inplace-upgrade-sanity-test/krb5.conf create mode 100755 tests/inplace-upgrade-sanity-test/runtest.sh create mode 100644 tests/tests.yml diff --git a/tests/inplace-upgrade-sanity-test/Makefile b/tests/inplace-upgrade-sanity-test/Makefile new file mode 100644 index 0000000..ccd8818 --- /dev/null +++ b/tests/inplace-upgrade-sanity-test/Makefile @@ -0,0 +1,64 @@ +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +# +# Makefile of /CoreOS/krb5/Sanity/inplace-upgrade-sanity-test +# Description: Verifies basic scenarios which should work after inplace upgrade. +# Author: Patrik Kis +# +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +# +# Copyright (c) 2014 Red Hat, Inc. +# +# This copyrighted material is made available to anyone wishing +# to use, modify, copy, or redistribute it subject to the terms +# and conditions of the GNU General Public License version 2. +# +# This program is distributed in the hope that it will be +# useful, but WITHOUT ANY WARRANTY; without even the implied +# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR +# PURPOSE. See the GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public +# License along with this program; if not, write to the Free +# Software Foundation, Inc., 51 Franklin Street, Fifth Floor, +# Boston, MA 02110-1301, USA. +# +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +export TEST=/CoreOS/krb5/Sanity/inplace-upgrade-sanity-test +export TESTVERSION=1.0 + +BUILT_FILES= + +FILES=$(METADATA) runtest.sh Makefile PURPOSE + +.PHONY: all install download clean + +run: $(FILES) build + ./runtest.sh + +build: $(BUILT_FILES) + test -x runtest.sh || chmod a+x runtest.sh + +clean: + rm -f *~ $(BUILT_FILES) + + +include /usr/share/rhts/lib/rhts-make.include + +$(METADATA): Makefile + @echo "Owner: Patrik Kis " > $(METADATA) + @echo "Name: $(TEST)" >> $(METADATA) + @echo "TestVersion: $(TESTVERSION)" >> $(METADATA) + @echo "Path: $(TEST_DIR)" >> $(METADATA) + @echo "Description: Verifies basic scenarios which should work after inplace upgrade." >> $(METADATA) + @echo "Type: Sanity" >> $(METADATA) + @echo "TestTime: 20m" >> $(METADATA) + @echo "RunFor: krb5" >> $(METADATA) + @echo "Requires: expect krb5-server krb5-workstation openssh-clients openssh-server rng-tools" >> $(METADATA) + @echo "Priority: Normal" >> $(METADATA) + @echo "License: GPLv2" >> $(METADATA) + @echo "Confidential: no" >> $(METADATA) + @echo "Destructive: no" >> $(METADATA) + @echo "Releases: -RHEL4 -RHELClient5 -RHELServer5" >> $(METADATA) + + rhts-lint $(METADATA) diff --git a/tests/inplace-upgrade-sanity-test/PURPOSE b/tests/inplace-upgrade-sanity-test/PURPOSE new file mode 100644 index 0000000..763d5a1 --- /dev/null +++ b/tests/inplace-upgrade-sanity-test/PURPOSE @@ -0,0 +1,3 @@ +PURPOSE of /CoreOS/krb5/Sanity/inplace-upgrade-sanity-test +Description: Verifies basic scenarios which should work after inplace upgrade. +Author: Patrik Kis diff --git a/tests/inplace-upgrade-sanity-test/kdc.conf b/tests/inplace-upgrade-sanity-test/kdc.conf new file mode 100644 index 0000000..d2212d0 --- /dev/null +++ b/tests/inplace-upgrade-sanity-test/kdc.conf @@ -0,0 +1,19 @@ +[kdcdefaults] + kdc_ports = 88 + kdc_tcp_ports = 88 + +[realms] + ${krb5REALM1} = { + #master_key_type = aes256-cts + acl_file = /var/kerberos/krb5kdc/kadm5.acl + dict_file = /usr/share/dict/words + admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab + supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal + } + ${krb5REALM2} = { + #master_key_type = aes256-cts + acl_file = /var/kerberos/krb5kdc/kadm5.acl + dict_file = /usr/share/dict/words + admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab + supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal + } diff --git a/tests/inplace-upgrade-sanity-test/krb5.conf b/tests/inplace-upgrade-sanity-test/krb5.conf new file mode 100644 index 0000000..18b40b6 --- /dev/null +++ b/tests/inplace-upgrade-sanity-test/krb5.conf @@ -0,0 +1,36 @@ +# To opt out of the system crypto-policies configuration of krb5, remove the +# symlink at /etc/krb5.conf.d/crypto-policies which will not be recreated. +includedir /etc/krb5.conf.d/ + +[logging] + default = FILE:/var/log/krb5libs.log + kdc = FILE:/var/log/krb5kdc.log + admin_server = FILE:/var/log/kadmind.log + +[libdefaults] + default_realm = ${krb5REALM1} + dns_lookup_realm = false + ticket_lifetime = 24h + renew_lifetime = 7d + forwardable = true + rdns = false + default_ccache_name = KEYRING:persistent:%{uid} + +[realms] + ${krb5REALM1} = { + kdc = localhost.localdomain + admin_server = localhost.localdomain + } + ${krb5REALM2} = { + kdc = localhost.localdomain + admin_server = localhost.localdomain + } + +[domain_realm] + ${krb5HostName} = ${krb5REALM1} + ${krb5HostName} = ${krb5REALM2} + +[capaths] + ${krb5REALM1} = { + ${krb5REALM2} = . + } diff --git a/tests/inplace-upgrade-sanity-test/runtest.sh b/tests/inplace-upgrade-sanity-test/runtest.sh new file mode 100755 index 0000000..db06748 --- /dev/null +++ b/tests/inplace-upgrade-sanity-test/runtest.sh @@ -0,0 +1,306 @@ +#!/bin/bash +# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +# +# runtest.sh of /CoreOS/krb5/Sanity/inplace-upgrade-sanity-test +# Description: Verifies basic scenarios which should work after inplace upgrade. +# Author: Patrik Kis +# +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +# +# Copyright (c) 2014 Red Hat, Inc. +# +# This copyrighted material is made available to anyone wishing +# to use, modify, copy, or redistribute it subject to the terms +# and conditions of the GNU General Public License version 2. +# +# This program is distributed in the hope that it will be +# useful, but WITHOUT ANY WARRANTY; without even the implied +# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR +# PURPOSE. See the GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public +# License along with this program; if not, write to the Free +# Software Foundation, Inc., 51 Franklin Street, Fifth Floor, +# Boston, MA 02110-1301, USA. +# +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +# Include Beaker environment +. /usr/bin/rhts-environment.sh +. /usr/share/beakerlib/beakerlib.sh || exit 1 + +PACKAGE="krb5" +PACKAGES="krb5-libs krb5-server krb5-workstation openssh" + +TEST_ENTROPY_SOURCE=${TEST_ENTROPY_SOURCE:-no} +echo TEST_ENTROPY_SOURCE=$TEST_ENTROPY_SOURCE + +hostnamectl set-hostname test.fedora.com +echo "`hostname -I` test.fedora.com" >>/etc/hosts + +krb5REALM1='ZMRAZ.COM' +krb5REALM2='PKIS.NET' +krb5HostName=`hostname` +krb5DomainName=`hostname -d` +krb5User='alice' +krb5UserPass='alice' +krb5UserKrbPass='aaa' +krb5User2='bob' +krb5User3='carl' +krb5KDCPass='qwe' +krb5RootPass='rrr' + +krb5conf="/etc/krb5.conf" +krb5confdir="/etc/krb5.conf.d" +krb5kdcconf="/var/kerberos/krb5kdc/kdc.conf" +krb5kadmacl="/var/kerberos/krb5kdc/kadm5.acl" + +rlJournalStart + rlPhaseStartSetup + for pkg in $PACKAGES; do + rlAssertRpm $pkg + done + rlRun "TmpDir=\$(mktemp -d)" + rlRun "pushd $TmpDir" + rlPhaseEnd + + # Run this part on OLD and in "normal" mode + if [[ -z $IN_PLACE_UPGRADE || $IN_PLACE_UPGRADE == old ]]; then + rlPhaseStartSetup "KDC and kadmind setup" + # Stop and backup + rlRun "rlServiceStop kadmin krb5kdc" + rlRun "rm -f /var/kerberos/krb5kdc/principal* /var/kerberos/krb5kdc/.k5*" + rlFileBackup $krb5conf /var/kerberos/krb5kdc /etc/sysconfig/{kadmin,krb5kdc} + [ -e /etc/krb5.keytab ] && rlFileBackup /etc/krb5.keytab + [ -e $krb5confdir ] && rlFileBackup $krb5confdir + # Basic setup of KDC and krb5.conf + if rlIsRHEL 6; then + rlRun "sed -i \"s/EXAMPLE.COM/$krb5REALM1/\" $krb5conf" + rlRun "sed -i \"s/kerberos.example.com/$krb5HostName/\" $krb5conf" + rlRun "sed -i \"s/example.com/$krb5DomainName/\" $krb5conf" + else + rlRun "sed -i \"s/\[libdefaults\]/[libdefaults]\n default_realm = $krb5REALM1/\" $krb5conf" + rlRun "sed -i \"s/\[realms\]/[realms]\n $krb5REALM1 = {\n kdc = $krb5HostName\n admin_server = $krb5HostName\n }/\" $krb5conf" + rlRun "sed -i \"s/\[domain_realm\]/[domain_realm]\n .$krb5DomainName = $krb5REALM1\n $krb5DomainName = $krb5REALM1/\" $krb5conf" + fi + rlRun "sed -i s/EXAMPLE.COM/$krb5REALM1/ $krb5kdcconf" + # Configure the kadmin ACL + rlRun "echo \"*/master@$krb5REALM1 *\" > $krb5kadmacl" + # Configure the 2nd realmd + cat >>$krb5kdcconf <<_EOF + + $krb5REALM2 = { + #master_key_type = aes256-cts + database_name = /var/kerberos/krb5kdc/principal.$krb5REALM1 + acl_file = /var/kerberos/krb5kdc/kadm5.acl + dict_file = /usr/share/dict/words + admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab + supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal + } +_EOF + rlIsRHEL 6 || rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal/\" /var/kerberos/krb5kdc/kdc.conf" + rlRun "sed -i \"s/\[realms\]/[realms]\n $krb5REALM2 = {\n kdc = $krb5HostName\n admin_server = $krb5HostName\n }/\" $krb5conf" + cat >> $krb5conf << _EOF + +[capaths] + $krb5REALM1 = { + $krb5REALM2 = . + } +_EOF + # Test the entropy source (not relevant for RHEL6) + if ! rlIsRHEL 6 && [[ $TEST_ENTROPY_SOURCE == 'yes' ]]; then + rlLog "The source of entropy will be tested as well" + START_DATE=`date +%H:%M:%S` + echo START_DATE=$START_DATE + sleep 1 + rlRun "auditctl -w /dev/random -p rwxa -k RAND" + auditctl -l + sleep 1 + rlRun "ausearch -i -k RAND -ts $START_DATE" + fi + # Create the realm databases + rlRun "rngd -r /dev/urandom" + rlRun "kdb5_util create -s -r $krb5REALM1 -P $krb5KDCPass" + rlRun "kdb5_util create -s -r $krb5REALM2 -P $krb5KDCPass" + # Configure KDC to handle 2 realms + if rlIsRHEL 6; then + rlRun "echo \"KRB5REALM=$krb5REALM1\" > /etc/sysconfig/krb5kdc" + rlRun "echo KRB5KDC_ARGS=\\\"-r $krb5REALM2\\\" >> /etc/sysconfig/krb5kdc" + else + rlRun "echo KRB5KDC_ARGS=\\\"-r $krb5REALM1 -r $krb5REALM2 \\\" >/etc/sysconfig/krb5kdc" + fi + rlRun "rlServiceStart kadmin krb5kdc" + # Add krb5 principals for the 2nd realm + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -pw $krb5RootPass root/master\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -pw $krb5UserKrbPass $krb5User\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -randkey host/$krb5HostName\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"ktadd host/$krb5HostName\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -pw $krb5KDCPass krbtgt/$krb5REALM1@$krb5REALM2\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -pw $krb5KDCPass krbtgt/$krb5REALM2@$krb5REALM1\"" + # Add krb5 principals for the 2nd realm + rlRun "kadmin.local -r $krb5REALM2 -q \"addprinc -pw $krb5UserKrbPass $krb5User2\"" + rlRun "kadmin.local -r $krb5REALM2 -q \"addprinc -randkey host/$krb5HostName\"" + rlRun "kadmin.local -r $krb5REALM2 -q \"addprinc -pw $krb5KDCPass krbtgt/$krb5REALM1@$krb5REALM2\"" + rlRun "kadmin.local -r $krb5REALM2 -q \"addprinc -pw $krb5KDCPass krbtgt/$krb5REALM2@$krb5REALM1\"" + # Create test system user + [ $krb5User != "root" ] && rlRun "useradd $krb5User" + rlRun "echo $krb5UserPass | passwd --stdin $krb5User" + rlPhaseEnd + fi + + rlPhaseStartTest "Daemon start and log file test" + # Make sure there is enough entropy and start recording of the logs + rlRun "rngd -r /dev/urandom" + if grep -q krb5kdc /var/log/krb5kdc.log; then + tail -n0 -f /var/log/krb5kdc.log &> krb5kdc.log.record & + KRB5KDC_LOG_PID=$! + echo "log_record_start: PID = $KRB5KDC_LOG_PID" + sleep 1 + elif journalctl |grep -q krb5kdc; then + journalctl -f &> krb5kdc.log.record & + KRB5KDC_LOG_PID=$! + echo "log_record_start: PID = $KRB5KDC_LOG_PID" + sleep 1 + else + rlFail "Could not find krb5kdc logs" + echo "journalctl:" + journalctl -n 100 + ls -la /var/log/krb5kdc* + echo "/var/log/krb5kdc.log:" + tail -n 100 /var/log/krb5kdc.log + fi + if grep -q kadmind /var/log/kadmind.log; then + tail -n0 -f /var/log/kadmind.log &> kadmind.log.record & + KADMIND_LOG_PID=$! + echo "log_record_start: PID = $KADMIND_LOG_PID" + sleep 1 + elif journalctl |grep -q kadmind; then + journalctl -f &> kadmind.log.record & + KADMIND_LOG_PID=$! + echo "log_record_start: PID = $KADMIND_LOG_PID" + sleep 1 + else + rlFail "Could not find kadmind logs" + echo "journalctl:" + journalctl -n 100 + ls -la /var/log/kadmind* + echo "/var/log/kadmind.log:" + tail -n 100 /var/log/kadmind.log + fi + # Restart daemon auto start + if rlIsRHEL 6; then + rlRun "service krb5kdc restart" + rlRun "service kadmin restart" + rlRun "service krb5kdc status" + rlRun "service kadmin status" + else + rlRun "systemctl restart krb5kdc.service" + rlRun "systemctl restart kadmin.service" + rlRun "systemctl --no-pager status krb5kdc.service" + rlRun "systemctl --no-pager status kadmin.service" + fi + rlRun "echo $krb5UserKrbPass |kinit $krb5User && klist" + rlRun "kdestroy" + rlRun "kadmin -p root/master -w rrr -q ''" + rlAssertGrep "AS_REQ.*$krb5User@$krb5REALM1.*krbtgt/$krb5REALM1@$krb5REALM1" krb5kdc.log.record + cat krb5kdc.log.record + rlAssertGrep "Request: kadm5_init.*root/master@$krb5REALM1.*service=kadmin/`hostname`@$krb5REALM1" kadmind.log.record + cat kadmind.log.record + # Stop log recording + kill $KADMIND_LOG_PID + kill $KRB5KDC_LOG_PID + rlPhaseEnd + + rlPhaseStartTest "SSH test" + cat > sshtest.exp <<'_EOF' +#!/usr/bin/expect -f +set USER [lindex $argv 0] +set HOST [lindex $argv 1] +set timeout 10 +spawn ssh $USER@$HOST pwd +expect { + -re ".*(yes/no).*" { send -- "yes\r"; exp_continue } + -re ".*password:.*" { exit 1 } + "/home/$USER" { exit 0 } + timeout { exit 2 } + eof { exit 3 } +} +exit 4 +_EOF + chmod 744 sshtest.exp + rlAssertExists sshtest.exp + rlRun "echo $krb5UserKrbPass |kinit $krb5User && klist" + rlRun "./sshtest.exp $krb5User $krb5HostName"; echo + rlRun "klist &>klist.log" + cat klist.log + rlAssertGrep "host/`hostname`@$krb5REALM1" klist.log + rlRun "kdestroy" + rlPhaseEnd + + rlPhaseStartTest "Basic kadmin and kpasswd test" + rlRun "kadmin.local -q \"listprincs\" |grep -v Authenticating >lplocal" + rlRun "kadmin -p root/master -w $krb5RootPass -q \"listprincs\" |grep -v Authenticating >lpremote" + rlAssertNotDiffer lplocal lpremote || diff -u lplocal lpremote + diff lplocal lpremote + rlRun "kadmin -p root/master -w $krb5RootPass -q \"addprinc -pw $krb5User2 $krb5User2@$krb5REALM1\"" + rlRun "kadmin -p root/master -w $krb5RootPass -q \"listprincs\" | grep \"$krb5User2@$krb5REALM1\"" + + rlRun "echo $krb5User2 | kinit $krb5User2" + rlRun "echo -e \"$krb5User2\nqwerty\nqwerty\" | kpasswd &>kpasswd.log" + cat kpasswd.log + rlAssertGrep "Password changed." kpasswd.log + rlRun "echo qwerty | kinit $krb5User2" + rlRun "kdestroy" + rlRun "kadmin -p root/master -w $krb5RootPass -q \"delprinc -force $krb5User2@$krb5REALM1\"" + rlPhaseEnd + + rlPhaseStartTest "Basic ksu test" + [[ -f /root/.k5login ]] && rlRun "mv /root/.k5login ." + rlRun "echo $krb5User@$krb5REALM1 > /root/.k5login" + rlRun "su - $krb5User -c \"echo $krb5UserKrbPass | kinit $krb5User\"" + rlRun "su - $krb5User -c \"ksu -e /usr/bin/id\" &> ksu.log" + cat ksu.log + rlAssertGrep "^uid=0(root) gid=0(root)" ksu.log + rlRun "su - $krb5User -c kdestroy" + [[ -f .k5login ]] && rlRun "mv .k5login /root/.k5login" + rlPhaseEnd + + rlPhaseStartTest "Cross realm test" + rlRun "echo $krb5UserKrbPass |kinit $krb5User && klist" + rlRun "kvno host/`hostname`@$krb5REALM2" + rlRun "klist &>klist.log" + cat klist.log + rlAssertGrep "krbtgt/$krb5REALM1@$krb5REALM1" klist.log + rlAssertGrep "krbtgt/$krb5REALM2@$krb5REALM1" klist.log + rlAssertGrep "host/`hostname`@$krb5REALM2" klist.log + rlRun "kdestroy" + rlPhaseEnd + + # Test the entropy source (not relevant for RHEL6) + if ! rlIsRHEL 6 && [[ $TEST_ENTROPY_SOURCE == 'yes' ]]; then + rlPhaseStartTest "Enable faster getrandom-based entropy system" + echo START_DATE=$START_DATE + auditctl -l + rlRun "ausearch -i -k RAND -ts $START_DATE" + rlRun "ausearch -i -k RAND -ts $START_DATE |grep comm= |grep -v 'comm=rngd'" 1 + rlRun "auditctl -D" + rlPhaseEnd + fi + + # Run this part on "normal" mode; in inplace upgrade no cleanup is needed + if [[ -z $IN_PLACE_UPGRADE ]]; then + rlPhaseStartCleanup "KDC and kadmind cleanup" + rlRun "rm -rf /var/kerberos/krb5kdc/* /var/kerberos/krb5kdc/.k5* /etc/krb5* /etc/sysconfig/{kadmin,krb5kdc}" + rlFileRestore + rlRun "rlServiceRestore krb5kdc kadmin" + [ $krb5User != "root" ] && rlRun "userdel -r -f $krb5User" + rlPhaseEnd + fi + + rlPhaseStartCleanup + rlRun "popd" + rlRun "rm -r $TmpDir" + rlPhaseEnd +rlJournalPrintText +rlJournalEnd diff --git a/tests/tests.yml b/tests/tests.yml new file mode 100644 index 0000000..6ebc417 --- /dev/null +++ b/tests/tests.yml @@ -0,0 +1,16 @@ +--- +# This first play always runs on the local staging system +- hosts: localhost + roles: + - role: standard-test-beakerlib + tags: + - classic + tests: + - inplace-upgrade-sanity-test + required_packages: + - expect # Required for inplace-upgrade-sanity-test + - krb5-server # Required for inplace-upgrade-sanity-test + - krb5-workstation # Required for inplace-upgrade-sanity-test + - openssh-clients # Required for inplace-upgrade-sanity-test + - openssh-server # Required for inplace-upgrade-sanity-test + - rng-tools # Required for inplace-upgrade-sanity-test From 6f4f842e5fe20a8bb4bd58323e3fee5a97a4c2a1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 27 Nov 2017 22:15:25 +0000 Subject: [PATCH 008/304] New upstream prerelease (1.16-beta2) --- .gitignore | 3 + ...INIT-cert-matching-data-construction.patch | 103 ------------------ Use-GSSAPI-fallback-skiptest.patch | 35 ------ krb5-1.11-kpasswdtest.patch | 3 +- krb5-1.11-run_user_0.patch | 4 +- krb5-1.12-api.patch | 4 +- krb5-1.12-ksu-path.patch | 4 +- krb5-1.12-ktany.patch | 4 +- krb5-1.12.1-pam.patch | 4 +- krb5-1.13-dirsrv-accountlock.patch | 4 +- krb5-1.15-beta1-buildconf.patch | 4 +- krb5-1.15.1-selinux-label.patch | 4 +- krb5-1.3.1-dns.patch | 4 +- krb5-1.9-debuginfo.patch | 4 +- krb5.spec | 9 +- sources | 6 +- 16 files changed, 43 insertions(+), 156 deletions(-) delete mode 100644 Fix-PKINIT-cert-matching-data-construction.patch delete mode 100644 Use-GSSAPI-fallback-skiptest.patch diff --git a/.gitignore b/.gitignore index df05a67..3cbaf2f 100644 --- a/.gitignore +++ b/.gitignore @@ -157,3 +157,6 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.16-beta1-pdfs.tar /krb5-1.16-beta1.tar.gz /krb5-1.16-beta1.tar.gz.asc +/krb5-1.16-beta2.tar.gz +/krb5-1.16-beta2.tar.gz.asc +/krb5-1.16-beta2-pdfs.tar diff --git a/Fix-PKINIT-cert-matching-data-construction.patch b/Fix-PKINIT-cert-matching-data-construction.patch deleted file mode 100644 index 577db58..0000000 --- a/Fix-PKINIT-cert-matching-data-construction.patch +++ /dev/null @@ -1,103 +0,0 @@ -From 82854302309e2a513908cf85ed9321113ef26a08 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 24 Oct 2017 15:09:57 -0400 -Subject: [PATCH] Fix PKINIT cert matching data construction - -Rewrite X509_NAME_oneline_ex() and its call sites to use dynamic -allocation and to perform proper error checking. - -(cherry picked from commit 5a2faf2802480548ff6a7261552ee17efaed7be1) ---- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 61 +++++++--------------- - 1 file changed, 19 insertions(+), 42 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index f7640baf1..9fa20a8b2 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -5002,33 +5002,23 @@ out: - return retval; - } - --/* -- * Return a string format of an X509_NAME in buf where -- * size is an in/out parameter. On input it is the size -- * of the buffer, and on output it is the actual length -- * of the name. -- * If buf is NULL, returns the length req'd to hold name -- */ --static char * --X509_NAME_oneline_ex(X509_NAME * a, -- char *buf, -- unsigned int *size, -- unsigned long flag) -+static krb5_error_code -+rfc2253_name(X509_NAME *name, char **str_out) - { -- BIO *out = NULL; -+ BIO *b = NULL; -+ char *str; - -- out = BIO_new(BIO_s_mem ()); -- if (X509_NAME_print_ex(out, a, 0, flag) > 0) { -- if (buf != NULL && (*size) > (unsigned int) BIO_number_written(out)) { -- memset(buf, 0, *size); -- BIO_read(out, buf, (int) BIO_number_written(out)); -- } -- else { -- *size = BIO_number_written(out); -- } -- } -- BIO_free(out); -- return (buf); -+ *str_out = NULL; -+ b = BIO_new(BIO_s_mem()); -+ if (X509_NAME_print_ex(b, name, 0, XN_FLAG_SEP_COMMA_PLUS) < 0) -+ return ENOMEM; -+ str = calloc(BIO_number_written(b) + 1, 1); -+ if (str == NULL) -+ return ENOMEM; -+ BIO_read(b, str, BIO_number_written(b)); -+ BIO_free(b); -+ *str_out = str; -+ return 0; - } - - /* -@@ -5094,8 +5084,6 @@ get_matching_data(krb5_context context, - pkinit_cert_matching_data *md = NULL; - krb5_principal *pkinit_sans = NULL, *upn_sans = NULL; - size_t i, j; -- char buf[DN_BUF_LEN]; -- unsigned int bufsize = sizeof(buf); - - *md_out = NULL; - -@@ -5103,23 +5091,12 @@ get_matching_data(krb5_context context, - if (md == NULL) - goto cleanup; - -- /* Get the subject name (in rfc2253 format). */ -- X509_NAME_oneline_ex(X509_get_subject_name(cert), buf, &bufsize, -- XN_FLAG_SEP_COMMA_PLUS); -- md->subject_dn = strdup(buf); -- if (md->subject_dn == NULL) { -- ret = ENOMEM; -+ ret = rfc2253_name(X509_get_subject_name(cert), &md->subject_dn); -+ if (ret) - goto cleanup; -- } -- -- /* Get the issuer name (in rfc2253 format). */ -- X509_NAME_oneline_ex(X509_get_issuer_name(cert), buf, &bufsize, -- XN_FLAG_SEP_COMMA_PLUS); -- md->issuer_dn = strdup(buf); -- if (md->issuer_dn == NULL) { -- ret = ENOMEM; -+ ret = rfc2253_name(X509_get_issuer_name(cert), &md->issuer_dn); -+ if (ret) - goto cleanup; -- } - - /* Get the SAN data. */ - ret = crypto_retrieve_X509_sans(context, plg_cryptoctx, req_cryptoctx, diff --git a/Use-GSSAPI-fallback-skiptest.patch b/Use-GSSAPI-fallback-skiptest.patch deleted file mode 100644 index 14beb76..0000000 --- a/Use-GSSAPI-fallback-skiptest.patch +++ /dev/null @@ -1,35 +0,0 @@ -From 697f19c5bfd4470c167d35c7af43c82a32660b82 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 1 Mar 2017 17:46:22 -0500 -Subject: [PATCH] Use GSSAPI fallback skiptest - -Also-authored-by: Matt Rogers -[rharwood@redhat.com: Adjusted patch to apply] ---- - src/appl/gss-sample/Makefile.in | 6 +++++- - 1 file changed, 5 insertions(+), 1 deletion(-) - -diff --git a/src/appl/gss-sample/Makefile.in b/src/appl/gss-sample/Makefile.in -index 28e59f90f..9806fd327 100644 ---- a/src/appl/gss-sample/Makefile.in -+++ b/src/appl/gss-sample/Makefile.in -@@ -6,6 +6,8 @@ SRCS= $(srcdir)/gss-client.c $(srcdir)/gss-misc.c $(srcdir)/gss-server.c - - OBJS= gss-client.o gss-misc.o gss-server.o - -+LBITS = $(shell /usr/bin/getconf LONG_BIT) -+ - all-unix: gss-server gss-client - - ##WIN32##VERSIONRC = $(BUILDTOP)\windows\version.rc -@@ -43,7 +45,9 @@ clean-unix:: - $(RM) gss-server gss-client - - check-pytests: -- $(RUNPYTEST) $(srcdir)/t_gss_sample.py $(PYTESTFLAGS) -+ if ! [ $(LBITS) -eq 32 ]; then \ -+ $(RUNPYTEST) $(srcdir)/t_gss_sample.py $(PYTESTFLAGS); \ -+ fi - - install-unix: - $(INSTALL_PROGRAM) gss-client $(DESTDIR)$(CLIENT_BINDIR)/gss-client diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch index 92f3dab..3932d5f 100644 --- a/krb5-1.11-kpasswdtest.patch +++ b/krb5-1.11-kpasswdtest.patch @@ -1,8 +1,9 @@ -From 3e94cf1accf2b33bd0c8cf54eb58b4777f411cc6 Mon Sep 17 00:00:00 2001 +From f92f616e67909fe76f7628fa0fd1e28320c7e4c3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:52:01 -0400 Subject: [PATCH] krb5-1.11-kpasswdtest.patch +Signed-off-by: Robbie Harwood --- src/kadmin/testing/proto/krb5.conf.proto | 1 + 1 file changed, 1 insertion(+) diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch index 9c4cf0e..83e5f9c 100644 --- a/krb5-1.11-run_user_0.patch +++ b/krb5-1.11-run_user_0.patch @@ -1,4 +1,4 @@ -From 9e7e92ae1dcd242044f2dfe3b89926ddddb6a221 Mon Sep 17 00:00:00 2001 +From 1940160be747f4c62ff00b95bc7d34301cf313d2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:57 -0400 Subject: [PATCH] krb5-1.11-run_user_0.patch @@ -6,6 +6,8 @@ Subject: [PATCH] krb5-1.11-run_user_0.patch A hack: if we're looking at creating a ccache directory directly below the /run/user/0 directory, and /run/user/0 doesn't exist, try to create it, too. + +Signed-off-by: Robbie Harwood --- src/lib/krb5/ccache/cc_dir.c | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/krb5-1.12-api.patch b/krb5-1.12-api.patch index 0b8ec6f..6c588df 100644 --- a/krb5-1.12-api.patch +++ b/krb5-1.12-api.patch @@ -1,4 +1,4 @@ -From 9a6cfaaecd1a37e74dba285decd03bb4a3382f9a Mon Sep 17 00:00:00 2001 +From f872d1b9d44ae48846641dab97b546665fbc1c33 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:00 -0400 Subject: [PATCH] krb5-1.12-api.patch @@ -6,6 +6,8 @@ Subject: [PATCH] krb5-1.12-api.patch Reference docs don't define what happens if you call krb5_realm_compare() with malformed krb5_principal structures. Define a behavior which keeps it from crashing if applications don't check ahead of time. + +Signed-off-by: Robbie Harwood --- src/lib/krb5/krb/princ_comp.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/krb5-1.12-ksu-path.patch b/krb5-1.12-ksu-path.patch index 43178b9..8a46429 100644 --- a/krb5-1.12-ksu-path.patch +++ b/krb5-1.12-ksu-path.patch @@ -1,9 +1,11 @@ -From 7b3bdbc0ca882325291caad391c4d328f174a614 Mon Sep 17 00:00:00 2001 +From 5bcd5fc7c793f1345d8e052c9242a93e17562ad6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:32:09 -0400 Subject: [PATCH] krb5-1.12-ksu-path.patch Set the default PATH to the one set by login. + +Signed-off-by: Robbie Harwood --- src/clients/ksu/Makefile.in | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/krb5-1.12-ktany.patch b/krb5-1.12-ktany.patch index 24135fd..3fe3310 100644 --- a/krb5-1.12-ktany.patch +++ b/krb5-1.12-ktany.patch @@ -1,4 +1,4 @@ -From 1ede8564105568182e3cf6f273ab820453e2f025 Mon Sep 17 00:00:00 2001 +From 690b710e3cdf40cb9b9184ed6883f26c0d5d0d39 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:33:53 -0400 Subject: [PATCH] krb5-1.12-ktany.patch @@ -6,6 +6,8 @@ Subject: [PATCH] krb5-1.12-ktany.patch Adds an "ANY" keytab type which is a list of other keytab locations to search when searching for a specific entry. When iterated through, it only presents the contents of the first keytab. + +Signed-off-by: Robbie Harwood --- src/lib/krb5/keytab/Makefile.in | 3 + src/lib/krb5/keytab/kt_any.c | 292 ++++++++++++++++++++++++++++++++++++++++ diff --git a/krb5-1.12.1-pam.patch b/krb5-1.12.1-pam.patch index c56606f..9ae19e0 100644 --- a/krb5-1.12.1-pam.patch +++ b/krb5-1.12.1-pam.patch @@ -1,4 +1,4 @@ -From 385194db1a08c1b923f9eb75e9602b56720fd50e Mon Sep 17 00:00:00 2001 +From 42f20ac00a2f71dcef166b0cbf2db58d02f117c8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] krb5-1.12.1-pam.patch @@ -16,6 +16,8 @@ When enabled, ksu gains a dependency on libpam. Originally RT#5939, though it's changed since then to perform the account and session management before dropping privileges, and to apply on top of changes we're proposing for how it handles cache collections. + +Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 67 ++++++++ src/clients/ksu/Makefile.in | 8 +- diff --git a/krb5-1.13-dirsrv-accountlock.patch b/krb5-1.13-dirsrv-accountlock.patch index 47716dc..cd40cbf 100644 --- a/krb5-1.13-dirsrv-accountlock.patch +++ b/krb5-1.13-dirsrv-accountlock.patch @@ -1,10 +1,12 @@ -From 850689009f9aeddc0b63051a3e2883d02b05387e Mon Sep 17 00:00:00 2001 +From fd3013f4dec1dfdfa40a8161cfdfea87aaac8e35 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:44 -0400 Subject: [PATCH] krb5-1.13-dirsrv-accountlock.patch Treat 'nsAccountLock: true' the same as 'loginDisabled: true'. Updated from original version filed as RT#5891. + +Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 9 +++++++++ src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c | 17 +++++++++++++++++ diff --git a/krb5-1.15-beta1-buildconf.patch b/krb5-1.15-beta1-buildconf.patch index b0024ec..493c3fa 100644 --- a/krb5-1.15-beta1-buildconf.patch +++ b/krb5-1.15-beta1-buildconf.patch @@ -1,4 +1,4 @@ -From 285eaffa69e9c2ff7f0adf017d192b5e7afb7002 Mon Sep 17 00:00:00 2001 +From e4103ccd0ad37297c64440ce9153e3dd355e1d5a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] krb5-1.15-beta1-buildconf.patch @@ -8,6 +8,8 @@ and install shared libraries with the execute bit set on them. Prune out the -L/usr/lib* and PIE flags where they might leak out and affect apps which just want to link with the libraries. FIXME: needs to check and not just assume that the compiler supports using these flags. + +Signed-off-by: Robbie Harwood --- src/build-tools/krb5-config.in | 7 +++++++ src/config/pre.in | 2 +- diff --git a/krb5-1.15.1-selinux-label.patch b/krb5-1.15.1-selinux-label.patch index 475f74d..35b98e6 100644 --- a/krb5-1.15.1-selinux-label.patch +++ b/krb5-1.15.1-selinux-label.patch @@ -1,4 +1,4 @@ -From d38588a165302d915eb6b4da0c2755601547bcd1 Mon Sep 17 00:00:00 2001 +From 36874eb7b52ccc606f705029d6a5c83f77cea2c4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] krb5-1.15.1-selinux-label.patch @@ -35,6 +35,8 @@ stomp all over us. The selabel APIs for looking up the context should be thread-safe (per Red Hat #273081), so switching to using them instead of matchpathcon(), which we used earlier, is some improvement. + +Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 49 +++ src/build-tools/krb5-config.in | 3 +- diff --git a/krb5-1.3.1-dns.patch b/krb5-1.3.1-dns.patch index c50f1df..193fe8a 100644 --- a/krb5-1.3.1-dns.patch +++ b/krb5-1.3.1-dns.patch @@ -1,9 +1,11 @@ -From 4bc124bfff119d436eeb1af7b9d5726e17284d67 Mon Sep 17 00:00:00 2001 +From 5f9dccda2e9f4637732aa4071d37e76a3526fd6c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] krb5-1.3.1-dns.patch We want to be able to use --with-netlib and --enable-dns at the same time. + +Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 1 + 1 file changed, 1 insertion(+) diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index 57a8b32..a5e4590 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -1,4 +1,4 @@ -From 82f8b63ae3955423456adf15790c10eb1145ec52 Mon Sep 17 00:00:00 2001 +From 1eeb1b3e0ceb5500e5c1102d2144203352f0d00f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] krb5-1.9-debuginfo.patch @@ -6,6 +6,8 @@ Subject: [PATCH] krb5-1.9-debuginfo.patch We want to keep these y.tab.c files around because the debuginfo points to them. It would be more elegant at the end to use symbolic links, but that could mess up people working in the tree on other things. + +Signed-off-by: Robbie Harwood --- src/kadmin/cli/Makefile.in | 5 +++++ src/plugins/kdb/ldap/ldap_util/Makefile.in | 2 +- diff --git a/krb5.spec b/krb5.spec index cf24c0a..fb6da8c 100644 --- a/krb5.spec +++ b/krb5.spec @@ -9,7 +9,7 @@ %global configured_default_ccache_name KEYRING:persistent:%%{uid} # leave empty or set to e.g., -beta2 -%global prerelease -beta1 +%global prerelease -beta2 # Should be in form 5.0, 6.1, etc. %global kdbversion 7.0 @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 0.beta1.4%{?dist} +Release: 0.beta2.1%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -60,8 +60,6 @@ Patch33: krb5-1.13-dirsrv-accountlock.patch Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch -Patch43: Use-GSSAPI-fallback-skiptest.patch -Patch44: Fix-PKINIT-cert-matching-data-construction.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -714,6 +712,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Nov 27 2017 Robbie Harwood - 1.16-0.beta2.1 +- New upstream prerelease (1.16-beta2) + * Tue Oct 24 2017 Robbie Harwood - 1.16-0.beta1.4 - Fix CVE-2017-15088 (Buffer overflow in get_matching_data()) diff --git a/sources b/sources index d5f6442..1def434 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (krb5-1.16-beta1-pdfs.tar) = 79329b7978101723a5c9f55773ac69bd1986c716e6d8b4cd42cbf17a8e85cd49f13b376e0b4b0ccca485b5a5a79d6bce8ace0c22df79b6f0a47a74c387f83ffd -SHA512 (krb5-1.16-beta1.tar.gz) = 68dba5212d2dd28ed0bc4961931af8d291bcdf2805baa4e930b0218f7749dc1e4dfe696aacca0529787f274b99fe5a8297f3e13877f724ee983483b399daf2c9 -SHA512 (krb5-1.16-beta1.tar.gz.asc) = 342272496897b4a4452d73186b7d19bbc3155e38fe39e0e852e03ce4757a3284baefbb1c49653e53d36e96ab587a7acb718e14c8281ccca85cb0de4c7d0b730e +SHA512 (krb5-1.16-beta2.tar.gz) = 12dfbac5357e1bfa6acce4ea8ee690015136c0297c08405ed8a77ba219ed1490cbf35eaa3d7ab3cd517cdfcd697dfa6c64efd6270f5419d7e2914ed562338ea7 +SHA512 (krb5-1.16-beta2.tar.gz.asc) = c653f7babc9baf58528fde523169e971aada520a606ade2afdb22d7aa9c513a7fec2662f6ba4b344bde0ad8ebc1ebd4e7fc90960c50b3ff44867a9c547749613 +SHA512 (krb5-1.16-beta2-pdfs.tar) = f3791cbe3b6cedbc07af70b2e6c87aabe921a637e419096fa37faff40538e0575237c006ee0df56e5c728988b0677faef41f26e61501e5ab8851591ea12faa3a From 9869daa1e863f575973d304efe5ff805d99e4725 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 6 Dec 2017 12:48:55 -0500 Subject: [PATCH 009/304] New upstream release (1.16) - No changes from beta2 - Add spec file support for COPR --- .gitignore | 3 +++ krb5-1.11-kpasswdtest.patch | 3 +-- krb5-1.11-run_user_0.patch | 4 +--- krb5-1.12-api.patch | 4 +--- krb5-1.12-ksu-path.patch | 4 +--- krb5-1.12-ktany.patch | 4 +--- krb5-1.12.1-pam.patch | 4 +--- krb5-1.13-dirsrv-accountlock.patch | 4 +--- krb5-1.15-beta1-buildconf.patch | 4 +--- krb5-1.15.1-selinux-label.patch | 4 +--- krb5-1.3.1-dns.patch | 4 +--- krb5-1.9-debuginfo.patch | 4 +--- krb5.spec | 21 ++++++++++++++++----- sources | 6 +++--- 14 files changed, 33 insertions(+), 40 deletions(-) diff --git a/.gitignore b/.gitignore index 3cbaf2f..fcf514a 100644 --- a/.gitignore +++ b/.gitignore @@ -160,3 +160,6 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.16-beta2.tar.gz /krb5-1.16-beta2.tar.gz.asc /krb5-1.16-beta2-pdfs.tar +/krb5-1.16-pdfs.tar +/krb5-1.16.tar.gz +/krb5-1.16.tar.gz.asc diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch index 3932d5f..134ce84 100644 --- a/krb5-1.11-kpasswdtest.patch +++ b/krb5-1.11-kpasswdtest.patch @@ -1,9 +1,8 @@ -From f92f616e67909fe76f7628fa0fd1e28320c7e4c3 Mon Sep 17 00:00:00 2001 +From 5d7ff3b42a2f1a4f5f15ac7f2b8fff743c3f33fc Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:52:01 -0400 Subject: [PATCH] krb5-1.11-kpasswdtest.patch -Signed-off-by: Robbie Harwood --- src/kadmin/testing/proto/krb5.conf.proto | 1 + 1 file changed, 1 insertion(+) diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch index 83e5f9c..8a767c9 100644 --- a/krb5-1.11-run_user_0.patch +++ b/krb5-1.11-run_user_0.patch @@ -1,4 +1,4 @@ -From 1940160be747f4c62ff00b95bc7d34301cf313d2 Mon Sep 17 00:00:00 2001 +From d29ad5a58999cb952cdb8ae876fe8b195a11a3e1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:57 -0400 Subject: [PATCH] krb5-1.11-run_user_0.patch @@ -6,8 +6,6 @@ Subject: [PATCH] krb5-1.11-run_user_0.patch A hack: if we're looking at creating a ccache directory directly below the /run/user/0 directory, and /run/user/0 doesn't exist, try to create it, too. - -Signed-off-by: Robbie Harwood --- src/lib/krb5/ccache/cc_dir.c | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/krb5-1.12-api.patch b/krb5-1.12-api.patch index 6c588df..64e9875 100644 --- a/krb5-1.12-api.patch +++ b/krb5-1.12-api.patch @@ -1,4 +1,4 @@ -From f872d1b9d44ae48846641dab97b546665fbc1c33 Mon Sep 17 00:00:00 2001 +From d2297aa0ca6006dae654f0f2a24ac8f7ead737f6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:00 -0400 Subject: [PATCH] krb5-1.12-api.patch @@ -6,8 +6,6 @@ Subject: [PATCH] krb5-1.12-api.patch Reference docs don't define what happens if you call krb5_realm_compare() with malformed krb5_principal structures. Define a behavior which keeps it from crashing if applications don't check ahead of time. - -Signed-off-by: Robbie Harwood --- src/lib/krb5/krb/princ_comp.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/krb5-1.12-ksu-path.patch b/krb5-1.12-ksu-path.patch index 8a46429..7b03aeb 100644 --- a/krb5-1.12-ksu-path.patch +++ b/krb5-1.12-ksu-path.patch @@ -1,11 +1,9 @@ -From 5bcd5fc7c793f1345d8e052c9242a93e17562ad6 Mon Sep 17 00:00:00 2001 +From bd1a0d1d4dba9f72bf8150d9aa8fdf70f738c4d7 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:32:09 -0400 Subject: [PATCH] krb5-1.12-ksu-path.patch Set the default PATH to the one set by login. - -Signed-off-by: Robbie Harwood --- src/clients/ksu/Makefile.in | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/krb5-1.12-ktany.patch b/krb5-1.12-ktany.patch index 3fe3310..f48ba8d 100644 --- a/krb5-1.12-ktany.patch +++ b/krb5-1.12-ktany.patch @@ -1,4 +1,4 @@ -From 690b710e3cdf40cb9b9184ed6883f26c0d5d0d39 Mon Sep 17 00:00:00 2001 +From 812be10fc5f9f2d771fc38e6ba84f7d89a32f726 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:33:53 -0400 Subject: [PATCH] krb5-1.12-ktany.patch @@ -6,8 +6,6 @@ Subject: [PATCH] krb5-1.12-ktany.patch Adds an "ANY" keytab type which is a list of other keytab locations to search when searching for a specific entry. When iterated through, it only presents the contents of the first keytab. - -Signed-off-by: Robbie Harwood --- src/lib/krb5/keytab/Makefile.in | 3 + src/lib/krb5/keytab/kt_any.c | 292 ++++++++++++++++++++++++++++++++++++++++ diff --git a/krb5-1.12.1-pam.patch b/krb5-1.12.1-pam.patch index 9ae19e0..9a6a092 100644 --- a/krb5-1.12.1-pam.patch +++ b/krb5-1.12.1-pam.patch @@ -1,4 +1,4 @@ -From 42f20ac00a2f71dcef166b0cbf2db58d02f117c8 Mon Sep 17 00:00:00 2001 +From f4bb886c93625c39d4ee788250385c55230a8442 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] krb5-1.12.1-pam.patch @@ -16,8 +16,6 @@ When enabled, ksu gains a dependency on libpam. Originally RT#5939, though it's changed since then to perform the account and session management before dropping privileges, and to apply on top of changes we're proposing for how it handles cache collections. - -Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 67 ++++++++ src/clients/ksu/Makefile.in | 8 +- diff --git a/krb5-1.13-dirsrv-accountlock.patch b/krb5-1.13-dirsrv-accountlock.patch index cd40cbf..db7ca29 100644 --- a/krb5-1.13-dirsrv-accountlock.patch +++ b/krb5-1.13-dirsrv-accountlock.patch @@ -1,12 +1,10 @@ -From fd3013f4dec1dfdfa40a8161cfdfea87aaac8e35 Mon Sep 17 00:00:00 2001 +From 43fe2e2c880cc8281cb9c0ffbaff374eb4a075aa Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:44 -0400 Subject: [PATCH] krb5-1.13-dirsrv-accountlock.patch Treat 'nsAccountLock: true' the same as 'loginDisabled: true'. Updated from original version filed as RT#5891. - -Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 9 +++++++++ src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c | 17 +++++++++++++++++ diff --git a/krb5-1.15-beta1-buildconf.patch b/krb5-1.15-beta1-buildconf.patch index 493c3fa..d44d79f 100644 --- a/krb5-1.15-beta1-buildconf.patch +++ b/krb5-1.15-beta1-buildconf.patch @@ -1,4 +1,4 @@ -From e4103ccd0ad37297c64440ce9153e3dd355e1d5a Mon Sep 17 00:00:00 2001 +From c1c44857896ab37ed59c6cab841f5f9a0ceba5d0 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] krb5-1.15-beta1-buildconf.patch @@ -8,8 +8,6 @@ and install shared libraries with the execute bit set on them. Prune out the -L/usr/lib* and PIE flags where they might leak out and affect apps which just want to link with the libraries. FIXME: needs to check and not just assume that the compiler supports using these flags. - -Signed-off-by: Robbie Harwood --- src/build-tools/krb5-config.in | 7 +++++++ src/config/pre.in | 2 +- diff --git a/krb5-1.15.1-selinux-label.patch b/krb5-1.15.1-selinux-label.patch index 35b98e6..8d4d1db 100644 --- a/krb5-1.15.1-selinux-label.patch +++ b/krb5-1.15.1-selinux-label.patch @@ -1,4 +1,4 @@ -From 36874eb7b52ccc606f705029d6a5c83f77cea2c4 Mon Sep 17 00:00:00 2001 +From 2857105eb2e301164a1486d31907699d0073dc5f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] krb5-1.15.1-selinux-label.patch @@ -35,8 +35,6 @@ stomp all over us. The selabel APIs for looking up the context should be thread-safe (per Red Hat #273081), so switching to using them instead of matchpathcon(), which we used earlier, is some improvement. - -Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 49 +++ src/build-tools/krb5-config.in | 3 +- diff --git a/krb5-1.3.1-dns.patch b/krb5-1.3.1-dns.patch index 193fe8a..36abd62 100644 --- a/krb5-1.3.1-dns.patch +++ b/krb5-1.3.1-dns.patch @@ -1,11 +1,9 @@ -From 5f9dccda2e9f4637732aa4071d37e76a3526fd6c Mon Sep 17 00:00:00 2001 +From bf0db245d46aa0a43479a38bf0b4ec964ae642b7 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] krb5-1.3.1-dns.patch We want to be able to use --with-netlib and --enable-dns at the same time. - -Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 1 + 1 file changed, 1 insertion(+) diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index a5e4590..3a8ba3d 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -1,4 +1,4 @@ -From 1eeb1b3e0ceb5500e5c1102d2144203352f0d00f Mon Sep 17 00:00:00 2001 +From 6df2f0876e95a39d88f602abe992f26907e0136a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] krb5-1.9-debuginfo.patch @@ -6,8 +6,6 @@ Subject: [PATCH] krb5-1.9-debuginfo.patch We want to keep these y.tab.c files around because the debuginfo points to them. It would be more elegant at the end to use symbolic links, but that could mess up people working in the tree on other things. - -Signed-off-by: Robbie Harwood --- src/kadmin/cli/Makefile.in | 5 +++++ src/plugins/kdb/ldap/ldap_util/Makefile.in | 2 +- diff --git a/krb5.spec b/krb5.spec index fb6da8c..f1fbfa8 100644 --- a/krb5.spec +++ b/krb5.spec @@ -9,7 +9,7 @@ %global configured_default_ccache_name KEYRING:persistent:%%{uid} # leave empty or set to e.g., -beta2 -%global prerelease -beta2 +%global prerelease %{nil} # Should be in form 5.0, 6.1, etc. %global kdbversion 7.0 @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 0.beta2.1%{?dist} +Release: 1 # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -364,16 +364,23 @@ export NOPORT='53,111' export SOCKET_WRAPPER_DIR="$PWD/sockets" ; mkdir -p $SOCKET_WRAPPER_DIR export LD_PRELOAD="$PWD/noport.so:libnss_wrapper.so:libsocket_wrapper.so" +# ugh. COPR doesn't expose the keyring, so try to cope. +%if 0%{copr_username}%{copr_projectname} +%global keyctl : +%else +%global keyctl keyctl +%endif + # Run the test suite. We can't actually run the whole thing in the build # system, but we can at least run more than we used to. The build system may # give us a revoked session keyring, so run affected tests with a new one. make -C src runenv.py : make -C src check TMPDIR=%{_tmppath} -keyctl session - make -C src/lib check TMPDIR=%{_tmppath} OFFLINE=yes +%{keyctl} session - make -C src/lib check TMPDIR=%{_tmppath} OFFLINE=yes make -C src/kdc check TMPDIR=%{_tmppath} -keyctl session - make -C src/appl check TMPDIR=%{_tmppath} +%{keyctl} session - make -C src/appl check TMPDIR=%{_tmppath} make -C src/clients check TMPDIR=%{_tmppath} -keyctl session - make -C src/util check TMPDIR=%{_tmppath} +%{keyctl} session - make -C src/util check TMPDIR=%{_tmppath} %install [ "$RPM_BUILD_ROOT" != '/' ] && rm -rf -- "$RPM_BUILD_ROOT" @@ -712,6 +719,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Dec 06 2017 Robbie Harwood - 1.16-1 +- New upstream release (1.16) +- No changes from beta2 + * Mon Nov 27 2017 Robbie Harwood - 1.16-0.beta2.1 - New upstream prerelease (1.16-beta2) diff --git a/sources b/sources index 1def434..29f4aa7 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (krb5-1.16-beta2.tar.gz) = 12dfbac5357e1bfa6acce4ea8ee690015136c0297c08405ed8a77ba219ed1490cbf35eaa3d7ab3cd517cdfcd697dfa6c64efd6270f5419d7e2914ed562338ea7 -SHA512 (krb5-1.16-beta2.tar.gz.asc) = c653f7babc9baf58528fde523169e971aada520a606ade2afdb22d7aa9c513a7fec2662f6ba4b344bde0ad8ebc1ebd4e7fc90960c50b3ff44867a9c547749613 -SHA512 (krb5-1.16-beta2-pdfs.tar) = f3791cbe3b6cedbc07af70b2e6c87aabe921a637e419096fa37faff40538e0575237c006ee0df56e5c728988b0677faef41f26e61501e5ab8851591ea12faa3a +SHA512 (krb5-1.16-pdfs.tar) = d245aad2be70d7786c45331671ed04ebaa7e5a30f7fcf5da9baf74441723e8841a7bd4dbbd977a27c925d487591a98f03430c90c72aa17f859daa9bf6cd91410 +SHA512 (krb5-1.16.tar.gz) = 7e162467b95dad2b6aaa11686d08a00f1cc4eb08247fca8f0e5a8bcaa5f9f7b42cdf00db69c5c6111bdf9eb8063d53cef3bb207ce5d6a287615ca10b710153f9 +SHA512 (krb5-1.16.tar.gz.asc) = a4b28b0877b7e1df28016cec7cd50569aa3bd539c366e7ef304e4824560f7c4cbf92ab0cd7d14328a0b578e982ff585c619a49378e59648b4259a33a799e6b2a From e714c5792747e59b1eaf49f93b9acf3ac3b145e6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 6 Dec 2017 18:10:36 +0000 Subject: [PATCH 010/304] Fix copr rule sop that the spec file builds --- krb5.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index f1fbfa8..253453d 100644 --- a/krb5.spec +++ b/krb5.spec @@ -365,7 +365,7 @@ export SOCKET_WRAPPER_DIR="$PWD/sockets" ; mkdir -p $SOCKET_WRAPPER_DIR export LD_PRELOAD="$PWD/noport.so:libnss_wrapper.so:libsocket_wrapper.so" # ugh. COPR doesn't expose the keyring, so try to cope. -%if 0%{copr_username}%{copr_projectname} +%if 0%{?copr_username:1} %global keyctl : %else %global keyctl keyctl From 30d56290b3fdcd665dd401349ef4a621005bedf6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 12 Dec 2017 21:45:17 +0000 Subject: [PATCH 011/304] Fix network service dependencies Resolves: #1525230 --- kadmin.service | 3 ++- kprop.service | 3 ++- krb5.spec | 6 +++++- krb5kdc.service | 3 ++- 4 files changed, 11 insertions(+), 4 deletions(-) diff --git a/kadmin.service b/kadmin.service index 49657f6..f1677c6 100644 --- a/kadmin.service +++ b/kadmin.service @@ -1,6 +1,7 @@ [Unit] Description=Kerberos 5 Password-changing and Administration -After=syslog.target network.target +Wants=network-online.target +After=syslog.target network.target network-online.target AssertPathExists=!/var/kerberos/krb5kdc/kpropd.acl [Service] diff --git a/kprop.service b/kprop.service index 4bbf8eb..7b5d4b9 100644 --- a/kprop.service +++ b/kprop.service @@ -1,6 +1,7 @@ [Unit] Description=Kerberos 5 Propagation -After=syslog.target network.target +Wants=network-online.target +After=syslog.target network.target network-online.target AssertPathExists=/var/kerberos/krb5kdc/kpropd.acl [Service] diff --git a/krb5.spec b/krb5.spec index 253453d..b189d73 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1 +Release: 2 # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -719,6 +719,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Dec 12 2017 Robbie Harwood - 1.16-2 +- Fix network service dependencies +- Resolves: #1525230 + * Wed Dec 06 2017 Robbie Harwood - 1.16-1 - New upstream release (1.16) - No changes from beta2 diff --git a/krb5kdc.service b/krb5kdc.service index bc49204..806b062 100644 --- a/krb5kdc.service +++ b/krb5kdc.service @@ -1,6 +1,7 @@ [Unit] Description=Kerberos 5 KDC -After=syslog.target network.target +Wants=network-online.target +After=syslog.target network.target network-online.target [Service] Type=forking From 85d9f736b5d0a546c876becde790ea0fbff77759 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 29 Jan 2018 17:48:17 +0100 Subject: [PATCH 012/304] Process included directories in alphabetical order --- ...ed-directories-in-alphabetical-order.patch | 74 +++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 79 insertions(+), 1 deletion(-) create mode 100644 Process-included-directories-in-alphabetical-order.patch diff --git a/Process-included-directories-in-alphabetical-order.patch b/Process-included-directories-in-alphabetical-order.patch new file mode 100644 index 0000000..df80196 --- /dev/null +++ b/Process-included-directories-in-alphabetical-order.patch @@ -0,0 +1,74 @@ +From 5d5a6a48e9529fccac9e4c3487577276f8da69ef Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 29 Jan 2018 12:10:53 +0100 +Subject: [PATCH] Process included directories in alphabetical order + +readdir() and FindFirstFile()/FindNextFile() do not define any +ordering on the entries they return. Use sorted scandir() instead on +Unix-likes. + +(cherry picked from commit c2734538945d284a21bc8ad17404fca1eecdcf86) +--- + src/util/profile/prof_parse.c | 26 ++++++++++++++++---------- + 1 file changed, 16 insertions(+), 10 deletions(-) + +diff --git a/src/util/profile/prof_parse.c b/src/util/profile/prof_parse.c +index 1baceea9e..6c77f3a0c 100644 +--- a/src/util/profile/prof_parse.c ++++ b/src/util/profile/prof_parse.c +@@ -241,12 +241,18 @@ static int valid_name(const char *filename) + } + return 1; + } ++#ifndef _WIN32 ++static int valid_name_scandir(const struct dirent *d) ++{ ++ return valid_name(d->d_name); ++} ++#endif + + /* + * Include files within dirname. Only files with names ending in ".conf", or + * consisting entirely of alphanumeric characters, dashes, and underscores are + * included. This restriction avoids including editor backup files, .rpmsave +- * files, and the like. ++ * files, and the like. Files are processed in alphanumeric order. + */ + static errcode_t parse_include_dir(const char *dirname, + struct profile_node *root_section) +@@ -287,18 +293,17 @@ cleanup: + + #else /* not _WIN32 */ + +- DIR *dir; + char *pathname; + errcode_t retval = 0; +- struct dirent *ent; ++ struct dirent **namelist; ++ int num_ents, i; + +- dir = opendir(dirname); +- if (dir == NULL) ++ num_ents = scandir(dirname, &namelist, &valid_name_scandir, &alphasort); ++ if (num_ents == -1) + return PROF_FAIL_INCLUDE_DIR; +- while ((ent = readdir(dir)) != NULL) { +- if (!valid_name(ent->d_name)) +- continue; +- if (asprintf(&pathname, "%s/%s", dirname, ent->d_name) < 0) { ++ ++ for (i = 0; i < num_ents; i++) { ++ if (asprintf(&pathname, "%s/%s", dirname, namelist[i]->d_name) < 0) { + retval = ENOMEM; + break; + } +@@ -307,7 +312,8 @@ cleanup: + if (retval) + break; + } +- closedir(dir); ++ ++ free(namelist); + return retval; + #endif /* not _WIN32 */ + } diff --git a/krb5.spec b/krb5.spec index b189d73..ac23f76 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 2 +Release: 3 # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -60,6 +60,7 @@ Patch33: krb5-1.13-dirsrv-accountlock.patch Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch +Patch37: Process-included-directories-in-alphabetical-order.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -719,6 +720,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jan 29 2018 Robbie Harwood - 1.16-3 +- Process included directories in alphabetical order + * Tue Dec 12 2017 Robbie Harwood - 1.16-2 - Fix network service dependencies - Resolves: #1525230 From ee2993187ab2780f313a0e9125ceb5fe275f660e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 29 Jan 2018 16:52:05 +0000 Subject: [PATCH 013/304] Process include directories in alphabetical order --- ...ed-directories-in-alphabetical-order.patch | 74 +++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 79 insertions(+), 1 deletion(-) create mode 100644 Process-included-directories-in-alphabetical-order.patch diff --git a/Process-included-directories-in-alphabetical-order.patch b/Process-included-directories-in-alphabetical-order.patch new file mode 100644 index 0000000..df80196 --- /dev/null +++ b/Process-included-directories-in-alphabetical-order.patch @@ -0,0 +1,74 @@ +From 5d5a6a48e9529fccac9e4c3487577276f8da69ef Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 29 Jan 2018 12:10:53 +0100 +Subject: [PATCH] Process included directories in alphabetical order + +readdir() and FindFirstFile()/FindNextFile() do not define any +ordering on the entries they return. Use sorted scandir() instead on +Unix-likes. + +(cherry picked from commit c2734538945d284a21bc8ad17404fca1eecdcf86) +--- + src/util/profile/prof_parse.c | 26 ++++++++++++++++---------- + 1 file changed, 16 insertions(+), 10 deletions(-) + +diff --git a/src/util/profile/prof_parse.c b/src/util/profile/prof_parse.c +index 1baceea9e..6c77f3a0c 100644 +--- a/src/util/profile/prof_parse.c ++++ b/src/util/profile/prof_parse.c +@@ -241,12 +241,18 @@ static int valid_name(const char *filename) + } + return 1; + } ++#ifndef _WIN32 ++static int valid_name_scandir(const struct dirent *d) ++{ ++ return valid_name(d->d_name); ++} ++#endif + + /* + * Include files within dirname. Only files with names ending in ".conf", or + * consisting entirely of alphanumeric characters, dashes, and underscores are + * included. This restriction avoids including editor backup files, .rpmsave +- * files, and the like. ++ * files, and the like. Files are processed in alphanumeric order. + */ + static errcode_t parse_include_dir(const char *dirname, + struct profile_node *root_section) +@@ -287,18 +293,17 @@ cleanup: + + #else /* not _WIN32 */ + +- DIR *dir; + char *pathname; + errcode_t retval = 0; +- struct dirent *ent; ++ struct dirent **namelist; ++ int num_ents, i; + +- dir = opendir(dirname); +- if (dir == NULL) ++ num_ents = scandir(dirname, &namelist, &valid_name_scandir, &alphasort); ++ if (num_ents == -1) + return PROF_FAIL_INCLUDE_DIR; +- while ((ent = readdir(dir)) != NULL) { +- if (!valid_name(ent->d_name)) +- continue; +- if (asprintf(&pathname, "%s/%s", dirname, ent->d_name) < 0) { ++ ++ for (i = 0; i < num_ents; i++) { ++ if (asprintf(&pathname, "%s/%s", dirname, namelist[i]->d_name) < 0) { + retval = ENOMEM; + break; + } +@@ -307,7 +312,8 @@ cleanup: + if (retval) + break; + } +- closedir(dir); ++ ++ free(namelist); + return retval; + #endif /* not _WIN32 */ + } diff --git a/krb5.spec b/krb5.spec index e790908..9f43f76 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.15.2 # for prerelease, should be e.g., 0.3.beta2% { ?dist } (without spaces) -Release: 4%{?dist} +Release: 5%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.15/krb5-%{version}%{prerelease}.tar.gz @@ -93,6 +93,7 @@ Patch69: Add-PKINIT-test-case-for-generic-client-cert.patch Patch70: Add-hostname-based-ccselect-module.patch Patch71: Add-German-translation.patch Patch72: Fix-PKINIT-cert-matching-data-construction.patch +Patch73: Process-included-directories-in-alphabetical-order.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -745,6 +746,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jan 29 2018 Robbie Harwood - 1.15.2-5 +- Process include directories in alphabetical order + * Tue Oct 24 2017 Robbie Harwood - 1.15.2-4 - Fix CVE-2017-15088 (Buffer overflow in get_matching_data()) From caf02999e014c3fe8752d27c80717bfc1c5139b5 Mon Sep 17 00:00:00 2001 From: Igor Gnatenko Date: Sat, 3 Feb 2018 17:31:01 +0100 Subject: [PATCH 014/304] Switch to %ldconfig_scriptlets Signed-off-by: Igor Gnatenko --- krb5.spec | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/krb5.spec b/krb5.spec index ac23f76..2168621 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 3 +Release: 4 # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -507,7 +507,7 @@ rm -- "$RPM_BUILD_ROOT/%{_libdir}/krb5/plugins/preauth/test.so" %clean [ "$RPM_BUILD_ROOT" != '/' ] && rm -rf -- "$RPM_BUILD_ROOT" -%post libs -p /sbin/ldconfig +%ldconfig_scriptlets libs %triggerun libs -- krb5-libs < 1.15.1-5 if ! grep -q 'includedir /etc/krb5.conf.d' /etc/krb5.conf ; then @@ -515,11 +515,7 @@ if ! grep -q 'includedir /etc/krb5.conf.d' /etc/krb5.conf ; then fi exit 0 -%postun libs -p /sbin/ldconfig - -%post server-ldap -p /sbin/ldconfig - -%postun server-ldap -p /sbin/ldconfig +%ldconfig_scriptlets server-ldap %post server %systemd_post krb5kdc.service kadmin.service kprop.service @@ -535,9 +531,7 @@ exit 0 %systemd_postun_with_restart krb5kdc.service kadmin.service kprop.service exit 0 -%post -n libkadm5 -p /sbin/ldconfig - -%postun -n libkadm5 -p /sbin/ldconfig +%ldconfig_scriptlets -n libkadm5 %files workstation %defattr(-,root,root,-) @@ -720,6 +714,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Sat Feb 03 2018 Igor Gnatenko - 1.16-4 +- Switch to %%ldconfig_scriptlets + * Mon Jan 29 2018 Robbie Harwood - 1.16-3 - Process included directories in alphabetical order From bfe3c598b5436f7c9960e0f757d1e836e32b2fb6 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Wed, 7 Feb 2018 20:27:38 +0000 Subject: [PATCH 015/304] - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 2168621..2769c6d 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 4 +Release: 5 # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -714,6 +714,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Feb 07 2018 Fedora Release Engineering - 1.16-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild + * Sat Feb 03 2018 Igor Gnatenko - 1.16-4 - Switch to %%ldconfig_scriptlets From c4848e33323104d0d1dad7054526cecb2a9d9e9b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 12 Feb 2018 12:35:25 -0500 Subject: [PATCH 016/304] Fix a leak in the previous commit Also, restore dist macro that was accidentally removed Resolves: #1540939 --- ...ed-directories-in-alphabetical-order.patch | 20 +++++++++++-------- krb5.spec | 7 ++++++- 2 files changed, 18 insertions(+), 9 deletions(-) diff --git a/Process-included-directories-in-alphabetical-order.patch b/Process-included-directories-in-alphabetical-order.patch index df80196..aeeae75 100644 --- a/Process-included-directories-in-alphabetical-order.patch +++ b/Process-included-directories-in-alphabetical-order.patch @@ -1,4 +1,4 @@ -From 5d5a6a48e9529fccac9e4c3487577276f8da69ef Mon Sep 17 00:00:00 2001 +From c7c44bbd80beabe7fb21f5fb6cfb9b57faa320f4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 29 Jan 2018 12:10:53 +0100 Subject: [PATCH] Process included directories in alphabetical order @@ -7,13 +7,13 @@ readdir() and FindFirstFile()/FindNextFile() do not define any ordering on the entries they return. Use sorted scandir() instead on Unix-likes. -(cherry picked from commit c2734538945d284a21bc8ad17404fca1eecdcf86) +(cherry picked from commit 4e8518baeedf376ae3e4ce302c9a138263d648df) --- - src/util/profile/prof_parse.c | 26 ++++++++++++++++---------- - 1 file changed, 16 insertions(+), 10 deletions(-) + src/util/profile/prof_parse.c | 30 ++++++++++++++++++++---------- + 1 file changed, 20 insertions(+), 10 deletions(-) diff --git a/src/util/profile/prof_parse.c b/src/util/profile/prof_parse.c -index 1baceea9e..6c77f3a0c 100644 +index 1baceea9e..309c27d07 100644 --- a/src/util/profile/prof_parse.c +++ b/src/util/profile/prof_parse.c @@ -241,12 +241,18 @@ static int valid_name(const char *filename) @@ -36,7 +36,7 @@ index 1baceea9e..6c77f3a0c 100644 */ static errcode_t parse_include_dir(const char *dirname, struct profile_node *root_section) -@@ -287,18 +293,17 @@ cleanup: +@@ -287,18 +293,19 @@ cleanup: #else /* not _WIN32 */ @@ -58,15 +58,19 @@ index 1baceea9e..6c77f3a0c 100644 - if (asprintf(&pathname, "%s/%s", dirname, ent->d_name) < 0) { + + for (i = 0; i < num_ents; i++) { -+ if (asprintf(&pathname, "%s/%s", dirname, namelist[i]->d_name) < 0) { ++ retval = asprintf(&pathname, "%s/%s", dirname, namelist[i]->d_name); ++ free(namelist[i]); ++ if (retval < 0) { retval = ENOMEM; break; } -@@ -307,7 +312,8 @@ cleanup: +@@ -307,7 +314,10 @@ cleanup: if (retval) break; } - closedir(dir); ++ for (i++; i < num_ents; i++) ++ free(namelist[i]); + + free(namelist); return retval; diff --git a/krb5.spec b/krb5.spec index 2769c6d..e1dde28 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 5 +Release: 6%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -714,6 +714,11 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Feb 12 2018 Robbie Harwood - 1.16-6 +- Fix a leak in the previous commit +- Restore dist macro that was accidentally removed +- Resolves: #1540939 + * Wed Feb 07 2018 Fedora Release Engineering - 1.16-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild From 702b0a90b5aaf5001227d93c6f65e1372c9af91c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 12 Feb 2018 17:43:01 +0000 Subject: [PATCH 017/304] Fix leak in previous commit Resolves: #1540939 --- ...ed-directories-in-alphabetical-order.patch | 20 +++++++++++-------- krb5.spec | 6 +++++- 2 files changed, 17 insertions(+), 9 deletions(-) diff --git a/Process-included-directories-in-alphabetical-order.patch b/Process-included-directories-in-alphabetical-order.patch index df80196..aeeae75 100644 --- a/Process-included-directories-in-alphabetical-order.patch +++ b/Process-included-directories-in-alphabetical-order.patch @@ -1,4 +1,4 @@ -From 5d5a6a48e9529fccac9e4c3487577276f8da69ef Mon Sep 17 00:00:00 2001 +From c7c44bbd80beabe7fb21f5fb6cfb9b57faa320f4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 29 Jan 2018 12:10:53 +0100 Subject: [PATCH] Process included directories in alphabetical order @@ -7,13 +7,13 @@ readdir() and FindFirstFile()/FindNextFile() do not define any ordering on the entries they return. Use sorted scandir() instead on Unix-likes. -(cherry picked from commit c2734538945d284a21bc8ad17404fca1eecdcf86) +(cherry picked from commit 4e8518baeedf376ae3e4ce302c9a138263d648df) --- - src/util/profile/prof_parse.c | 26 ++++++++++++++++---------- - 1 file changed, 16 insertions(+), 10 deletions(-) + src/util/profile/prof_parse.c | 30 ++++++++++++++++++++---------- + 1 file changed, 20 insertions(+), 10 deletions(-) diff --git a/src/util/profile/prof_parse.c b/src/util/profile/prof_parse.c -index 1baceea9e..6c77f3a0c 100644 +index 1baceea9e..309c27d07 100644 --- a/src/util/profile/prof_parse.c +++ b/src/util/profile/prof_parse.c @@ -241,12 +241,18 @@ static int valid_name(const char *filename) @@ -36,7 +36,7 @@ index 1baceea9e..6c77f3a0c 100644 */ static errcode_t parse_include_dir(const char *dirname, struct profile_node *root_section) -@@ -287,18 +293,17 @@ cleanup: +@@ -287,18 +293,19 @@ cleanup: #else /* not _WIN32 */ @@ -58,15 +58,19 @@ index 1baceea9e..6c77f3a0c 100644 - if (asprintf(&pathname, "%s/%s", dirname, ent->d_name) < 0) { + + for (i = 0; i < num_ents; i++) { -+ if (asprintf(&pathname, "%s/%s", dirname, namelist[i]->d_name) < 0) { ++ retval = asprintf(&pathname, "%s/%s", dirname, namelist[i]->d_name); ++ free(namelist[i]); ++ if (retval < 0) { retval = ENOMEM; break; } -@@ -307,7 +312,8 @@ cleanup: +@@ -307,7 +314,10 @@ cleanup: if (retval) break; } - closedir(dir); ++ for (i++; i < num_ents; i++) ++ free(namelist[i]); + + free(namelist); return retval; diff --git a/krb5.spec b/krb5.spec index 9f43f76..6fa2647 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.15.2 # for prerelease, should be e.g., 0.3.beta2% { ?dist } (without spaces) -Release: 5%{?dist} +Release: 6%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.15/krb5-%{version}%{prerelease}.tar.gz @@ -746,6 +746,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Feb 12 2018 Robbie Harwood - 1.15.2-6 +- Fix leak in previous commit +- Resolves: #1540939 + * Mon Jan 29 2018 Robbie Harwood - 1.15.2-5 - Process include directories in alphabetical order From 392309c493a7499c2ed6d8de9b89b8fd2f13e4eb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 13 Feb 2018 11:09:41 -0500 Subject: [PATCH 018/304] Fix flaws in LDAP DN checking CVE-2018-5729, CVE-2018-5730 --- Fix-flaws-in-LDAP-DN-checking.patch | 346 ++++++++++++++++++++++++++++ krb5.spec | 7 +- 2 files changed, 352 insertions(+), 1 deletion(-) create mode 100644 Fix-flaws-in-LDAP-DN-checking.patch diff --git a/Fix-flaws-in-LDAP-DN-checking.patch b/Fix-flaws-in-LDAP-DN-checking.patch new file mode 100644 index 0000000..4a775bb --- /dev/null +++ b/Fix-flaws-in-LDAP-DN-checking.patch @@ -0,0 +1,346 @@ +From 27581397cd0d2f213c91bdf20ea9a6736f3e60dc Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 12 Jan 2018 11:43:01 -0500 +Subject: [PATCH] Fix flaws in LDAP DN checking + +KDB_TL_USER_INFO tl-data is intended to be internal to the LDAP KDB +module, and not used in disk or wire principal entries. Prevent +kadmin clients from sending KDB_TL_USER_INFO tl-data by giving it a +type number less than 256 and filtering out type numbers less than 256 +in kadm5_create_principal_3(). (We already filter out low type +numbers in kadm5_modify_principal()). + +In the LDAP KDB module, if containerdn and linkdn are both specified +in a put_principal operation, check both linkdn and the computed +standalone_principal_dn for container membership. To that end, factor +out the checks into helper functions and call them on all applicable +client-influenced DNs. + +CVE-2018-5729: + +In MIT krb5 1.6 or later, an authenticated kadmin user with permission +to add principals to an LDAP Kerberos database can cause a null +dereference in kadmind, or circumvent a DN container check, by +supplying tagged data intended to be internal to the database module. +Thanks to Sharwan Ram and Pooja Anil for discovering the potential +null dereference. + +CVE-2018-5730: + +In MIT krb5 1.6 or later, an authenticated kadmin user with permission +to add principals to an LDAP Kerberos database can circumvent a DN +containership check by supplying both a "linkdn" and "containerdn" +database argument, or by supplying a DN string which is a left +extension of a container DN string but is not hierarchically within +the container DN. + +ticket: 8643 (new) +tags: pullup +target_version: 1.16-next +target_version: 1.15-next + +(cherry picked from commit e1caf6fb74981da62039846931ebdffed71309d1) +--- + src/lib/kadm5/srv/svr_principal.c | 7 + + src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h | 2 +- + src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c | 200 +++++++++++---------- + src/tests/t_kdb.py | 11 ++ + 4 files changed, 125 insertions(+), 95 deletions(-) + +diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c +index 2420f2c2b..a59a65e8f 100644 +--- a/src/lib/kadm5/srv/svr_principal.c ++++ b/src/lib/kadm5/srv/svr_principal.c +@@ -330,6 +330,13 @@ kadm5_create_principal_3(void *server_handle, + return KADM5_BAD_MASK; + if((mask & ~ALL_PRINC_MASK)) + return KADM5_BAD_MASK; ++ if (mask & KADM5_TL_DATA) { ++ for (tl_data_tail = entry->tl_data; tl_data_tail != NULL; ++ tl_data_tail = tl_data_tail->tl_data_next) { ++ if (tl_data_tail->tl_data_type < 256) ++ return KADM5_BAD_TL_TYPE; ++ } ++ } + + /* + * Check to see if the principal exists +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h b/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h +index 535a1f309..8b8420faa 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h ++++ b/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h +@@ -141,7 +141,7 @@ extern int set_ldap_error (krb5_context ctx, int st, int op); + #define UNSTORE16_INT(ptr, val) (val = load_16_be(ptr)) + #define UNSTORE32_INT(ptr, val) (val = load_32_be(ptr)) + +-#define KDB_TL_USER_INFO 0x7ffe ++#define KDB_TL_USER_INFO 0xff + + #define KDB_TL_PRINCTYPE 0x01 + #define KDB_TL_PRINCCOUNT 0x02 +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c +index 88a170495..b7c9212cb 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c ++++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c +@@ -651,6 +651,107 @@ cleanup: + return ret; + } + ++static krb5_error_code ++check_dn_in_container(krb5_context context, const char *dn, ++ char *const *subtrees, unsigned int ntrees) ++{ ++ unsigned int i; ++ size_t dnlen = strlen(dn), stlen; ++ ++ for (i = 0; i < ntrees; i++) { ++ if (subtrees[i] == NULL || *subtrees[i] == '\0') ++ return 0; ++ stlen = strlen(subtrees[i]); ++ if (dnlen >= stlen && ++ strcasecmp(dn + dnlen - stlen, subtrees[i]) == 0 && ++ (dnlen == stlen || dn[dnlen - stlen - 1] == ',')) ++ return 0; ++ } ++ ++ k5_setmsg(context, EINVAL, _("DN is out of the realm subtree")); ++ return EINVAL; ++} ++ ++static krb5_error_code ++check_dn_exists(krb5_context context, ++ krb5_ldap_server_handle *ldap_server_handle, ++ const char *dn, krb5_boolean nonkrb_only) ++{ ++ krb5_error_code st = 0, tempst; ++ krb5_ldap_context *ldap_context = context->dal_handle->db_context; ++ LDAP *ld = ldap_server_handle->ldap_handle; ++ LDAPMessage *result = NULL, *ent; ++ char *attrs[] = { "krbticketpolicyreference", "krbprincipalname", NULL }; ++ char **values; ++ ++ LDAP_SEARCH_1(dn, LDAP_SCOPE_BASE, 0, attrs, IGNORE_STATUS); ++ if (st != LDAP_SUCCESS) ++ return set_ldap_error(context, st, OP_SEARCH); ++ ++ ent = ldap_first_entry(ld, result); ++ CHECK_NULL(ent); ++ ++ values = ldap_get_values(ld, ent, "krbticketpolicyreference"); ++ if (values != NULL) ++ ldap_value_free(values); ++ ++ values = ldap_get_values(ld, ent, "krbprincipalname"); ++ if (values != NULL) { ++ ldap_value_free(values); ++ if (nonkrb_only) { ++ st = EINVAL; ++ k5_setmsg(context, st, _("ldap object is already kerberized")); ++ goto cleanup; ++ } ++ } ++ ++cleanup: ++ ldap_msgfree(result); ++ return st; ++} ++ ++static krb5_error_code ++validate_xargs(krb5_context context, ++ krb5_ldap_server_handle *ldap_server_handle, ++ const xargs_t *xargs, const char *standalone_dn, ++ char *const *subtrees, unsigned int ntrees) ++{ ++ krb5_error_code st; ++ ++ if (xargs->dn != NULL) { ++ /* The supplied dn must be within a realm container. */ ++ st = check_dn_in_container(context, xargs->dn, subtrees, ntrees); ++ if (st) ++ return st; ++ /* The supplied dn must exist without Kerberos attributes. */ ++ st = check_dn_exists(context, ldap_server_handle, xargs->dn, TRUE); ++ if (st) ++ return st; ++ } ++ ++ if (xargs->linkdn != NULL) { ++ /* The supplied linkdn must be within a realm container. */ ++ st = check_dn_in_container(context, xargs->linkdn, subtrees, ntrees); ++ if (st) ++ return st; ++ /* The supplied linkdn must exist. */ ++ st = check_dn_exists(context, ldap_server_handle, xargs->linkdn, ++ FALSE); ++ if (st) ++ return st; ++ } ++ ++ if (xargs->containerdn != NULL && standalone_dn != NULL) { ++ /* standalone_dn (likely composed using containerdn) must be within a ++ * container. */ ++ st = check_dn_in_container(context, standalone_dn, subtrees, ntrees); ++ if (st) ++ return st; ++ } ++ ++ return 0; ++} ++ + krb5_error_code + krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, + char **db_args) +@@ -662,12 +763,12 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, + LDAPMessage *result=NULL, *ent=NULL; + char **subtreelist = NULL; + char *user=NULL, *subtree=NULL, *principal_dn=NULL; +- char **values=NULL, *strval[10]={NULL}, errbuf[1024]; ++ char *strval[10]={NULL}, errbuf[1024]; + char *filtuser=NULL; + struct berval **bersecretkey=NULL; + LDAPMod **mods=NULL; + krb5_boolean create_standalone=FALSE; +- krb5_boolean krb_identity_exists=FALSE, establish_links=FALSE; ++ krb5_boolean establish_links=FALSE; + char *standalone_principal_dn=NULL; + krb5_tl_data *tl_data=NULL; + krb5_key_data **keys=NULL; +@@ -860,24 +961,6 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, + * any of the subtrees + */ + if (xargs.dn_from_kbd == TRUE) { +- /* make sure the DN falls in the subtree */ +- int dnlen=0, subtreelen=0; +- char *dn=NULL; +- krb5_boolean outofsubtree=TRUE; +- +- if (xargs.dn != NULL) { +- dn = xargs.dn; +- } else if (xargs.linkdn != NULL) { +- dn = xargs.linkdn; +- } else if (standalone_principal_dn != NULL) { +- /* +- * Even though the standalone_principal_dn is constructed +- * within this function, there is the containerdn input +- * from the user that can become part of the it. +- */ +- dn = standalone_principal_dn; +- } +- + /* Get the current subtree list if we haven't already done so. */ + if (subtreelist == NULL) { + st = krb5_get_subtree_info(ldap_context, &subtreelist, &ntrees); +@@ -885,81 +968,10 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, + goto cleanup; + } + +- for (tre=0; tre= subtreelen) && (strcasecmp((dn + dnlen - subtreelen), subtreelist[tre]) == 0)) { +- outofsubtree = FALSE; +- break; +- } +- } +- } +- +- if (outofsubtree == TRUE) { +- st = EINVAL; +- k5_setmsg(context, st, _("DN is out of the realm subtree")); ++ st = validate_xargs(context, ldap_server_handle, &xargs, ++ standalone_principal_dn, subtreelist, ntrees); ++ if (st) + goto cleanup; +- } +- +- /* +- * dn value will be set either by dn, linkdn or the standalone_principal_dn +- * In the first 2 cases, the dn should be existing and in the last case we +- * are supposed to create the ldap object. so the below should not be +- * executed for the last case. +- */ +- +- if (standalone_principal_dn == NULL) { +- /* +- * If the ldap object is missing, this results in an error. +- */ +- +- /* +- * Search for krbprincipalname attribute here. +- * This is to find if a kerberos identity is already present +- * on the ldap object, in which case adding a kerberos identity +- * on the ldap object should result in an error. +- */ +- char *attributes[]={"krbticketpolicyreference", "krbprincipalname", NULL}; +- +- ldap_msgfree(result); +- result = NULL; +- LDAP_SEARCH_1(dn, LDAP_SCOPE_BASE, 0, attributes, IGNORE_STATUS); +- if (st == LDAP_SUCCESS) { +- ent = ldap_first_entry(ld, result); +- if (ent != NULL) { +- if ((values=ldap_get_values(ld, ent, "krbticketpolicyreference")) != NULL) { +- ldap_value_free(values); +- } +- +- if ((values=ldap_get_values(ld, ent, "krbprincipalname")) != NULL) { +- krb_identity_exists = TRUE; +- ldap_value_free(values); +- } +- } +- } else { +- st = set_ldap_error(context, st, OP_SEARCH); +- goto cleanup; +- } +- } +- } +- +- /* +- * If xargs.dn is set then the request is to add a +- * kerberos principal on a ldap object, but if +- * there is one already on the ldap object this +- * should result in an error. +- */ +- +- if (xargs.dn != NULL && krb_identity_exists == TRUE) { +- st = EINVAL; +- snprintf(errbuf, sizeof(errbuf), +- _("ldap object is already kerberized")); +- k5_setmsg(context, st, "%s", errbuf); +- goto cleanup; + } + + if (xargs.linkdn != NULL) { +diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py +index 217f2cdc3..6e563b103 100755 +--- a/src/tests/t_kdb.py ++++ b/src/tests/t_kdb.py +@@ -203,6 +203,12 @@ if out != 'KRBTEST.COM\n': + # in the test LDAP server. + realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=krb5', 'princ1'], + expected_code=1, expected_msg='DN is out of the realm subtree') ++# Check that the DN container check is a hierarchy test, not a simple ++# suffix match (CVE-2018-5730). We expect this operation to fail ++# either way (because "xcn" isn't a valid DN tag) but the container ++# check should happen before the DN is parsed. ++realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=xcn=t1,cn=krb5', 'princ1'], ++ expected_code=1, expected_msg='DN is out of the realm subtree') + realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=t2,cn=krb5', 'princ1']) + realm.run([kadminl, 'getprinc', 'princ1'], expected_msg='Principal: princ1') + realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=t2,cn=krb5', 'again'], +@@ -226,6 +232,11 @@ realm.run([kadminl, 'ank', '-randkey', '-x', 'containerdn=cn=t1,cn=krb5', + 'princ3']) + realm.run([kadminl, 'modprinc', '-x', 'containerdn=cn=t2,cn=krb5', 'princ3'], + expected_code=1, expected_msg='containerdn option not supported') ++# Verify that containerdn is checked when linkdn is also supplied ++# (CVE-2018-5730). ++realm.run([kadminl, 'ank', '-randkey', '-x', 'containerdn=cn=krb5', ++ '-x', 'linkdn=cn=t2,cn=krb5', 'princ4'], expected_code=1, ++ expected_msg='DN is out of the realm subtree') + + # Create and modify a ticket policy. + kldaputil(['create_policy', '-maxtktlife', '3hour', '-maxrenewlife', '6hour', diff --git a/krb5.spec b/krb5.spec index e1dde28..23895a8 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 6%{?dist} +Release: 7%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -61,6 +61,7 @@ Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch Patch37: Process-included-directories-in-alphabetical-order.patch +Patch38: Fix-flaws-in-LDAP-DN-checking.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -714,6 +715,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Feb 13 2018 Robbie Harwood - 1.16-7 +- Fix flaws in LDAP DN checking +- CVE-2018-5729, CVE-2018-5730 + * Mon Feb 12 2018 Robbie Harwood - 1.16-6 - Fix a leak in the previous commit - Restore dist macro that was accidentally removed From 466fd80d0edc5ad7a67157a247f9210f7e659047 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 13 Feb 2018 16:11:51 +0000 Subject: [PATCH 019/304] Fix flaws in LDAP DN checking CVE-2018-5729, CVE-2018-5730 --- Fix-flaws-in-LDAP-DN-checking.patch | 346 ++++++++++++++++++++++++++++ krb5.spec | 7 +- 2 files changed, 352 insertions(+), 1 deletion(-) create mode 100644 Fix-flaws-in-LDAP-DN-checking.patch diff --git a/Fix-flaws-in-LDAP-DN-checking.patch b/Fix-flaws-in-LDAP-DN-checking.patch new file mode 100644 index 0000000..4a775bb --- /dev/null +++ b/Fix-flaws-in-LDAP-DN-checking.patch @@ -0,0 +1,346 @@ +From 27581397cd0d2f213c91bdf20ea9a6736f3e60dc Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 12 Jan 2018 11:43:01 -0500 +Subject: [PATCH] Fix flaws in LDAP DN checking + +KDB_TL_USER_INFO tl-data is intended to be internal to the LDAP KDB +module, and not used in disk or wire principal entries. Prevent +kadmin clients from sending KDB_TL_USER_INFO tl-data by giving it a +type number less than 256 and filtering out type numbers less than 256 +in kadm5_create_principal_3(). (We already filter out low type +numbers in kadm5_modify_principal()). + +In the LDAP KDB module, if containerdn and linkdn are both specified +in a put_principal operation, check both linkdn and the computed +standalone_principal_dn for container membership. To that end, factor +out the checks into helper functions and call them on all applicable +client-influenced DNs. + +CVE-2018-5729: + +In MIT krb5 1.6 or later, an authenticated kadmin user with permission +to add principals to an LDAP Kerberos database can cause a null +dereference in kadmind, or circumvent a DN container check, by +supplying tagged data intended to be internal to the database module. +Thanks to Sharwan Ram and Pooja Anil for discovering the potential +null dereference. + +CVE-2018-5730: + +In MIT krb5 1.6 or later, an authenticated kadmin user with permission +to add principals to an LDAP Kerberos database can circumvent a DN +containership check by supplying both a "linkdn" and "containerdn" +database argument, or by supplying a DN string which is a left +extension of a container DN string but is not hierarchically within +the container DN. + +ticket: 8643 (new) +tags: pullup +target_version: 1.16-next +target_version: 1.15-next + +(cherry picked from commit e1caf6fb74981da62039846931ebdffed71309d1) +--- + src/lib/kadm5/srv/svr_principal.c | 7 + + src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h | 2 +- + src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c | 200 +++++++++++---------- + src/tests/t_kdb.py | 11 ++ + 4 files changed, 125 insertions(+), 95 deletions(-) + +diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c +index 2420f2c2b..a59a65e8f 100644 +--- a/src/lib/kadm5/srv/svr_principal.c ++++ b/src/lib/kadm5/srv/svr_principal.c +@@ -330,6 +330,13 @@ kadm5_create_principal_3(void *server_handle, + return KADM5_BAD_MASK; + if((mask & ~ALL_PRINC_MASK)) + return KADM5_BAD_MASK; ++ if (mask & KADM5_TL_DATA) { ++ for (tl_data_tail = entry->tl_data; tl_data_tail != NULL; ++ tl_data_tail = tl_data_tail->tl_data_next) { ++ if (tl_data_tail->tl_data_type < 256) ++ return KADM5_BAD_TL_TYPE; ++ } ++ } + + /* + * Check to see if the principal exists +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h b/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h +index 535a1f309..8b8420faa 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h ++++ b/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h +@@ -141,7 +141,7 @@ extern int set_ldap_error (krb5_context ctx, int st, int op); + #define UNSTORE16_INT(ptr, val) (val = load_16_be(ptr)) + #define UNSTORE32_INT(ptr, val) (val = load_32_be(ptr)) + +-#define KDB_TL_USER_INFO 0x7ffe ++#define KDB_TL_USER_INFO 0xff + + #define KDB_TL_PRINCTYPE 0x01 + #define KDB_TL_PRINCCOUNT 0x02 +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c +index 88a170495..b7c9212cb 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c ++++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c +@@ -651,6 +651,107 @@ cleanup: + return ret; + } + ++static krb5_error_code ++check_dn_in_container(krb5_context context, const char *dn, ++ char *const *subtrees, unsigned int ntrees) ++{ ++ unsigned int i; ++ size_t dnlen = strlen(dn), stlen; ++ ++ for (i = 0; i < ntrees; i++) { ++ if (subtrees[i] == NULL || *subtrees[i] == '\0') ++ return 0; ++ stlen = strlen(subtrees[i]); ++ if (dnlen >= stlen && ++ strcasecmp(dn + dnlen - stlen, subtrees[i]) == 0 && ++ (dnlen == stlen || dn[dnlen - stlen - 1] == ',')) ++ return 0; ++ } ++ ++ k5_setmsg(context, EINVAL, _("DN is out of the realm subtree")); ++ return EINVAL; ++} ++ ++static krb5_error_code ++check_dn_exists(krb5_context context, ++ krb5_ldap_server_handle *ldap_server_handle, ++ const char *dn, krb5_boolean nonkrb_only) ++{ ++ krb5_error_code st = 0, tempst; ++ krb5_ldap_context *ldap_context = context->dal_handle->db_context; ++ LDAP *ld = ldap_server_handle->ldap_handle; ++ LDAPMessage *result = NULL, *ent; ++ char *attrs[] = { "krbticketpolicyreference", "krbprincipalname", NULL }; ++ char **values; ++ ++ LDAP_SEARCH_1(dn, LDAP_SCOPE_BASE, 0, attrs, IGNORE_STATUS); ++ if (st != LDAP_SUCCESS) ++ return set_ldap_error(context, st, OP_SEARCH); ++ ++ ent = ldap_first_entry(ld, result); ++ CHECK_NULL(ent); ++ ++ values = ldap_get_values(ld, ent, "krbticketpolicyreference"); ++ if (values != NULL) ++ ldap_value_free(values); ++ ++ values = ldap_get_values(ld, ent, "krbprincipalname"); ++ if (values != NULL) { ++ ldap_value_free(values); ++ if (nonkrb_only) { ++ st = EINVAL; ++ k5_setmsg(context, st, _("ldap object is already kerberized")); ++ goto cleanup; ++ } ++ } ++ ++cleanup: ++ ldap_msgfree(result); ++ return st; ++} ++ ++static krb5_error_code ++validate_xargs(krb5_context context, ++ krb5_ldap_server_handle *ldap_server_handle, ++ const xargs_t *xargs, const char *standalone_dn, ++ char *const *subtrees, unsigned int ntrees) ++{ ++ krb5_error_code st; ++ ++ if (xargs->dn != NULL) { ++ /* The supplied dn must be within a realm container. */ ++ st = check_dn_in_container(context, xargs->dn, subtrees, ntrees); ++ if (st) ++ return st; ++ /* The supplied dn must exist without Kerberos attributes. */ ++ st = check_dn_exists(context, ldap_server_handle, xargs->dn, TRUE); ++ if (st) ++ return st; ++ } ++ ++ if (xargs->linkdn != NULL) { ++ /* The supplied linkdn must be within a realm container. */ ++ st = check_dn_in_container(context, xargs->linkdn, subtrees, ntrees); ++ if (st) ++ return st; ++ /* The supplied linkdn must exist. */ ++ st = check_dn_exists(context, ldap_server_handle, xargs->linkdn, ++ FALSE); ++ if (st) ++ return st; ++ } ++ ++ if (xargs->containerdn != NULL && standalone_dn != NULL) { ++ /* standalone_dn (likely composed using containerdn) must be within a ++ * container. */ ++ st = check_dn_in_container(context, standalone_dn, subtrees, ntrees); ++ if (st) ++ return st; ++ } ++ ++ return 0; ++} ++ + krb5_error_code + krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, + char **db_args) +@@ -662,12 +763,12 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, + LDAPMessage *result=NULL, *ent=NULL; + char **subtreelist = NULL; + char *user=NULL, *subtree=NULL, *principal_dn=NULL; +- char **values=NULL, *strval[10]={NULL}, errbuf[1024]; ++ char *strval[10]={NULL}, errbuf[1024]; + char *filtuser=NULL; + struct berval **bersecretkey=NULL; + LDAPMod **mods=NULL; + krb5_boolean create_standalone=FALSE; +- krb5_boolean krb_identity_exists=FALSE, establish_links=FALSE; ++ krb5_boolean establish_links=FALSE; + char *standalone_principal_dn=NULL; + krb5_tl_data *tl_data=NULL; + krb5_key_data **keys=NULL; +@@ -860,24 +961,6 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, + * any of the subtrees + */ + if (xargs.dn_from_kbd == TRUE) { +- /* make sure the DN falls in the subtree */ +- int dnlen=0, subtreelen=0; +- char *dn=NULL; +- krb5_boolean outofsubtree=TRUE; +- +- if (xargs.dn != NULL) { +- dn = xargs.dn; +- } else if (xargs.linkdn != NULL) { +- dn = xargs.linkdn; +- } else if (standalone_principal_dn != NULL) { +- /* +- * Even though the standalone_principal_dn is constructed +- * within this function, there is the containerdn input +- * from the user that can become part of the it. +- */ +- dn = standalone_principal_dn; +- } +- + /* Get the current subtree list if we haven't already done so. */ + if (subtreelist == NULL) { + st = krb5_get_subtree_info(ldap_context, &subtreelist, &ntrees); +@@ -885,81 +968,10 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, + goto cleanup; + } + +- for (tre=0; tre= subtreelen) && (strcasecmp((dn + dnlen - subtreelen), subtreelist[tre]) == 0)) { +- outofsubtree = FALSE; +- break; +- } +- } +- } +- +- if (outofsubtree == TRUE) { +- st = EINVAL; +- k5_setmsg(context, st, _("DN is out of the realm subtree")); ++ st = validate_xargs(context, ldap_server_handle, &xargs, ++ standalone_principal_dn, subtreelist, ntrees); ++ if (st) + goto cleanup; +- } +- +- /* +- * dn value will be set either by dn, linkdn or the standalone_principal_dn +- * In the first 2 cases, the dn should be existing and in the last case we +- * are supposed to create the ldap object. so the below should not be +- * executed for the last case. +- */ +- +- if (standalone_principal_dn == NULL) { +- /* +- * If the ldap object is missing, this results in an error. +- */ +- +- /* +- * Search for krbprincipalname attribute here. +- * This is to find if a kerberos identity is already present +- * on the ldap object, in which case adding a kerberos identity +- * on the ldap object should result in an error. +- */ +- char *attributes[]={"krbticketpolicyreference", "krbprincipalname", NULL}; +- +- ldap_msgfree(result); +- result = NULL; +- LDAP_SEARCH_1(dn, LDAP_SCOPE_BASE, 0, attributes, IGNORE_STATUS); +- if (st == LDAP_SUCCESS) { +- ent = ldap_first_entry(ld, result); +- if (ent != NULL) { +- if ((values=ldap_get_values(ld, ent, "krbticketpolicyreference")) != NULL) { +- ldap_value_free(values); +- } +- +- if ((values=ldap_get_values(ld, ent, "krbprincipalname")) != NULL) { +- krb_identity_exists = TRUE; +- ldap_value_free(values); +- } +- } +- } else { +- st = set_ldap_error(context, st, OP_SEARCH); +- goto cleanup; +- } +- } +- } +- +- /* +- * If xargs.dn is set then the request is to add a +- * kerberos principal on a ldap object, but if +- * there is one already on the ldap object this +- * should result in an error. +- */ +- +- if (xargs.dn != NULL && krb_identity_exists == TRUE) { +- st = EINVAL; +- snprintf(errbuf, sizeof(errbuf), +- _("ldap object is already kerberized")); +- k5_setmsg(context, st, "%s", errbuf); +- goto cleanup; + } + + if (xargs.linkdn != NULL) { +diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py +index 217f2cdc3..6e563b103 100755 +--- a/src/tests/t_kdb.py ++++ b/src/tests/t_kdb.py +@@ -203,6 +203,12 @@ if out != 'KRBTEST.COM\n': + # in the test LDAP server. + realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=krb5', 'princ1'], + expected_code=1, expected_msg='DN is out of the realm subtree') ++# Check that the DN container check is a hierarchy test, not a simple ++# suffix match (CVE-2018-5730). We expect this operation to fail ++# either way (because "xcn" isn't a valid DN tag) but the container ++# check should happen before the DN is parsed. ++realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=xcn=t1,cn=krb5', 'princ1'], ++ expected_code=1, expected_msg='DN is out of the realm subtree') + realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=t2,cn=krb5', 'princ1']) + realm.run([kadminl, 'getprinc', 'princ1'], expected_msg='Principal: princ1') + realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=t2,cn=krb5', 'again'], +@@ -226,6 +232,11 @@ realm.run([kadminl, 'ank', '-randkey', '-x', 'containerdn=cn=t1,cn=krb5', + 'princ3']) + realm.run([kadminl, 'modprinc', '-x', 'containerdn=cn=t2,cn=krb5', 'princ3'], + expected_code=1, expected_msg='containerdn option not supported') ++# Verify that containerdn is checked when linkdn is also supplied ++# (CVE-2018-5730). ++realm.run([kadminl, 'ank', '-randkey', '-x', 'containerdn=cn=krb5', ++ '-x', 'linkdn=cn=t2,cn=krb5', 'princ4'], expected_code=1, ++ expected_msg='DN is out of the realm subtree') + + # Create and modify a ticket policy. + kldaputil(['create_policy', '-maxtktlife', '3hour', '-maxrenewlife', '6hour', diff --git a/krb5.spec b/krb5.spec index 6fa2647..749a64d 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.15.2 # for prerelease, should be e.g., 0.3.beta2% { ?dist } (without spaces) -Release: 6%{?dist} +Release: 7%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.15/krb5-%{version}%{prerelease}.tar.gz @@ -94,6 +94,7 @@ Patch70: Add-hostname-based-ccselect-module.patch Patch71: Add-German-translation.patch Patch72: Fix-PKINIT-cert-matching-data-construction.patch Patch73: Process-included-directories-in-alphabetical-order.patch +Patch74: Fix-flaws-in-LDAP-DN-checking.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -746,6 +747,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Feb 13 2018 Robbie Harwood - 1.15.2-7 +- Fix flaws in LDAP DN checking +- CVE-2018-5729, CVE-2018-5730 + * Mon Feb 12 2018 Robbie Harwood - 1.15.2-6 - Fix leak in previous commit - Resolves: #1540939 From 307e1c3fabf0150c163992f9e57e3cd782e4b0e0 Mon Sep 17 00:00:00 2001 From: Igor Gnatenko Date: Tue, 13 Feb 2018 23:36:56 +0100 Subject: [PATCH 020/304] Remove BuildRoot definition None of currently supported distributions need that. It was needed last for EL5 which is EOL now Signed-off-by: Igor Gnatenko --- krb5.spec | 1 - 1 file changed, 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 23895a8..cf5ae46 100644 --- a/krb5.spec +++ b/krb5.spec @@ -66,7 +66,6 @@ Patch38: Fix-flaws-in-LDAP-DN-checking.patch License: MIT URL: http://web.mit.edu/kerberos/www/ Group: System Environment/Libraries -BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) BuildRequires: autoconf, bison, cmake, flex, gawk, gettext, pkgconfig, sed BuildRequires: libcom_err-devel, libedit-devel, libss-devel BuildRequires: gzip, ncurses-devel From 03afcfa42c4b5b9a2ac43ba6f5704f28f19f02fc Mon Sep 17 00:00:00 2001 From: Igor Gnatenko Date: Wed, 14 Feb 2018 09:55:56 +0100 Subject: [PATCH 021/304] Remove %clean section None of currently supported distributions need that. Last one was EL5 which is EOL for a while. Signed-off-by: Igor Gnatenko --- krb5.spec | 3 --- 1 file changed, 3 deletions(-) diff --git a/krb5.spec b/krb5.spec index cf5ae46..42b9194 100644 --- a/krb5.spec +++ b/krb5.spec @@ -504,9 +504,6 @@ rm -- "$RPM_BUILD_ROOT/%{_libdir}/krb5/plugins/preauth/test.so" %find_lang %{gettext_domain} -%clean -[ "$RPM_BUILD_ROOT" != '/' ] && rm -rf -- "$RPM_BUILD_ROOT" - %ldconfig_scriptlets libs %triggerun libs -- krb5-libs < 1.15.1-5 From 4b5cd8c1f84341f3fcb49e2cd36c39f5df4dd498 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 7 Mar 2018 12:40:49 -0500 Subject: [PATCH 022/304] Fix capaths "." values on client Resolves: 1551099 --- Fix-capaths-.-values-on-client.patch | 60 ++++++++++++++++++++++++++++ krb5.spec | 7 +++- 2 files changed, 66 insertions(+), 1 deletion(-) create mode 100644 Fix-capaths-.-values-on-client.patch diff --git a/Fix-capaths-.-values-on-client.patch b/Fix-capaths-.-values-on-client.patch new file mode 100644 index 0000000..49016f2 --- /dev/null +++ b/Fix-capaths-.-values-on-client.patch @@ -0,0 +1,60 @@ +From 5cdef749204eccf05ae5d7bad455d34899eb33da Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sat, 3 Mar 2018 13:44:00 -0500 +Subject: [PATCH] Fix capaths "." values on client + +Commit b72aef2c1cbcc76f7fba14ddc54a4e66e7a4e66c (ticket 6966) +introduced k5_client_realm_path() for use on the client in place of +krb5_walk_realm_tree(), but failed to handle the special case of a +capaths "." value as is done in the latter function. Correct that +omission and add a test case. + +ticket: 8646 (new) +tags: pullup +target_version: 1.16-next +target_version: 1.15-next + +(cherry picked from commit f8d0877f848563d07152a0ee191fe82846fdb8f1) +--- + src/lib/krb5/krb/walk_rtree.c | 6 ++++++ + src/tests/t_crossrealm.py | 10 ++++++++++ + 2 files changed, 16 insertions(+) + +diff --git a/src/lib/krb5/krb/walk_rtree.c b/src/lib/krb5/krb/walk_rtree.c +index 0566a55f1..f4e8e35f5 100644 +--- a/src/lib/krb5/krb/walk_rtree.c ++++ b/src/lib/krb5/krb/walk_rtree.c +@@ -133,6 +133,12 @@ k5_client_realm_path(krb5_context context, const krb5_data *client, + if (retval) + return retval; + ++ /* A capaths value of "." means no intermediates. */ ++ if (capvals != NULL && capvals[0] != NULL && *capvals[0] == '.') { ++ profile_free_list(capvals); ++ capvals = NULL; ++ } ++ + /* Count capaths (if any) and allocate space. Leave room for the client + * realm, server realm, and terminator. */ + for (i = 0; capvals != NULL && capvals[i] != NULL; i++); +diff --git a/src/tests/t_crossrealm.py b/src/tests/t_crossrealm.py +index e7ddb0525..4d595dca6 100755 +--- a/src/tests/t_crossrealm.py ++++ b/src/tests/t_crossrealm.py +@@ -109,6 +109,16 @@ test_kvno(r1, r4.host_princ, 'KDC capaths') + check_klist(r1, (tgt(r1, r1), tgt(r4, r3), r4.host_princ)) + stop(r1, r2, r3, r4) + ++# A capaths value of '.' should enforce direct cross-realm, with no ++# intermediate. ++capaths = {'capaths': {'A.X': {'B.X': '.'}}} ++r1, r2, r3 = cross_realms(3, xtgts=((0,1), (1,2)), ++ args=({'realm': 'A.X', 'krb5_conf': capaths}, ++ {'realm': 'X'}, {'realm': 'B.X'})) ++r1.run([kvno, r3.host_princ], expected_code=1, ++ expected_msg='Server krbtgt/B.X@A.X not found in Kerberos database') ++stop(r1, r2, r3) ++ + # Test transited error. The KDC for C does not recognize B as an + # intermediate realm for A->C, so it refuses to issue a service + # ticket. diff --git a/krb5.spec b/krb5.spec index 42b9194..293caff 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 7%{?dist} +Release: 8%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -62,6 +62,7 @@ Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch Patch37: Process-included-directories-in-alphabetical-order.patch Patch38: Fix-flaws-in-LDAP-DN-checking.patch +Patch39: Fix-capaths-.-values-on-client.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -711,6 +712,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Mar 07 2018 Robbie Harwood - 1.16-8 +- Fix capaths "." values on client +- Resolves: 1551099 + * Tue Feb 13 2018 Robbie Harwood - 1.16-7 - Fix flaws in LDAP DN checking - CVE-2018-5729, CVE-2018-5730 From 5f3f6ef19b7cb50195d94432faaeffcd5f6aa62e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 13 Mar 2018 17:45:47 -0400 Subject: [PATCH 023/304] Fix hex conversion of PKINIT certid strings --- ...-conversion-of-PKINIT-certid-strings.patch | 92 +++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 97 insertions(+), 1 deletion(-) create mode 100644 Fix-hex-conversion-of-PKINIT-certid-strings.patch diff --git a/Fix-hex-conversion-of-PKINIT-certid-strings.patch b/Fix-hex-conversion-of-PKINIT-certid-strings.patch new file mode 100644 index 0000000..6acb007 --- /dev/null +++ b/Fix-hex-conversion-of-PKINIT-certid-strings.patch @@ -0,0 +1,92 @@ +From 46fada3b8a7ad21adf6831cf86c38a822a38748e Mon Sep 17 00:00:00 2001 +From: Sumit Bose +Date: Fri, 26 Jan 2018 11:47:50 -0500 +Subject: [PATCH] Fix hex conversion of PKINIT certid strings + +When parsing a PKCS11 token specification, correctly convert from hex +to binary instead of using OpenSSL bignum functions (which would strip +leading zeros). + +[ghudson@mit.edu: made hex_string_to_bin() a bit less verbose; wrote +commit message] + +ticket: 8636 +(cherry picked from commit 63e8b8142fd7b3931a7bf2d6448978ca536bafc0) +--- + src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 55 +++++++++++++++++----- + 1 file changed, 44 insertions(+), 11 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index ac107c2c1..4f21f90d2 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -4623,6 +4623,43 @@ reassemble_pkcs11_name(pkinit_identity_opts *idopts) + return ret; + } + ++static int ++hex_string_to_bin(const char *str, int *bin_len_out, CK_BYTE **bin_out) ++{ ++ size_t str_len, i; ++ CK_BYTE *bin; ++ char *endptr, tmp[3] = { '\0', '\0', '\0' }; ++ long val; ++ ++ *bin_len_out = 0; ++ *bin_out = NULL; ++ ++ str_len = strlen(str); ++ if (str_len % 2 != 0) ++ return EINVAL; ++ bin = malloc(str_len / 2); ++ if (bin == NULL) ++ return ENOMEM; ++ ++ errno = 0; ++ for (i = 0; i < str_len / 2; i++) { ++ tmp[0] = str[i * 2]; ++ tmp[1] = str[i * 2 + 1]; ++ ++ val = strtol(tmp, &endptr, 16); ++ if (val < 0 || val > 255 || errno != 0 || endptr != &tmp[2]) { ++ free(bin); ++ return EINVAL; ++ } ++ ++ bin[i] = (CK_BYTE)val; ++ } ++ ++ *bin_len_out = str_len / 2; ++ *bin_out = bin; ++ return 0; ++} ++ + static krb5_error_code + pkinit_get_certs_pkcs11(krb5_context context, + pkinit_plg_crypto_context plg_cryptoctx, +@@ -4665,18 +4702,14 @@ pkinit_get_certs_pkcs11(krb5_context context, + } + /* Convert the ascii cert_id string into a binary blob */ + if (idopts->cert_id_string != NULL) { +- BIGNUM *bn = NULL; +- BN_hex2bn(&bn, idopts->cert_id_string); +- if (bn == NULL) +- return ENOMEM; +- id_cryptoctx->cert_id_len = BN_num_bytes(bn); +- id_cryptoctx->cert_id = malloc((size_t) id_cryptoctx->cert_id_len); +- if (id_cryptoctx->cert_id == NULL) { +- BN_free(bn); +- return ENOMEM; ++ r = hex_string_to_bin(idopts->cert_id_string, ++ &id_cryptoctx->cert_id_len, ++ &id_cryptoctx->cert_id); ++ if (r != 0) { ++ pkiDebug("Failed to convert certid string [%s]\n", ++ idopts->cert_id_string); ++ return r; + } +- BN_bn2bin(bn, id_cryptoctx->cert_id); +- BN_free(bn); + } + id_cryptoctx->slotid = idopts->slotid; + id_cryptoctx->pkcs11_method = 1; diff --git a/krb5.spec b/krb5.spec index 293caff..ea4bbfc 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 8%{?dist} +Release: 9%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -63,6 +63,7 @@ Patch36: krb5-1.11-kpasswdtest.patch Patch37: Process-included-directories-in-alphabetical-order.patch Patch38: Fix-flaws-in-LDAP-DN-checking.patch Patch39: Fix-capaths-.-values-on-client.patch +Patch40: Fix-hex-conversion-of-PKINIT-certid-strings.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -712,6 +713,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Mar 13 2018 Robbie Harwood - 1.16-9 +- Fix hex conversion of PKINIT certid strings + * Wed Mar 07 2018 Robbie Harwood - 1.16-8 - Fix capaths "." values on client - Resolves: 1551099 From ed142b51b15c1fc2736a3cda06a13522f18b78f6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 14 Mar 2018 14:44:04 -0400 Subject: [PATCH 024/304] Exit with status 0 from kadmind --- Exit-with-status-0-from-kadmind.patch | 31 +++++++++++++++++++++++++++ krb5.spec | 6 +++++- 2 files changed, 36 insertions(+), 1 deletion(-) create mode 100644 Exit-with-status-0-from-kadmind.patch diff --git a/Exit-with-status-0-from-kadmind.patch b/Exit-with-status-0-from-kadmind.patch new file mode 100644 index 0000000..30b7201 --- /dev/null +++ b/Exit-with-status-0-from-kadmind.patch @@ -0,0 +1,31 @@ +From a4576a5946d84e1a74093c4fc171a7fcb1f7ef59 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 14 Mar 2018 14:31:22 -0400 +Subject: [PATCH] Exit with status 0 from kadmind + +Typically, 0 denotes successful exit. In particular, init systems +will complain if another different value is returned. This presents a +problem for automated installation jobs which want to restart kadmind. + +`service kadmin stop` typically sends SIGTERM, which is caught by +verto and passed to our handler. Besides cleanup, we then call +verto_break(), which causes the verto_run() event loop to return. The +weird return code has been present since the addition of the kadmin +code, which used a similar event model for signals. + +(cherry picked from commit f970ad412aca36f8a7d3addb1cd4026ed22e5592) +--- + src/kadmin/server/ovsec_kadmd.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/kadmin/server/ovsec_kadmd.c b/src/kadmin/server/ovsec_kadmd.c +index 6c875901a..936955b89 100644 +--- a/src/kadmin/server/ovsec_kadmd.c ++++ b/src/kadmin/server/ovsec_kadmd.c +@@ -560,5 +560,5 @@ main(int argc, char *argv[]) + + krb5_klog_close(context); + krb5_free_context(context); +- exit(2); ++ exit(0); + } diff --git a/krb5.spec b/krb5.spec index ea4bbfc..5ba26b7 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 9%{?dist} +Release: 10%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -64,6 +64,7 @@ Patch37: Process-included-directories-in-alphabetical-order.patch Patch38: Fix-flaws-in-LDAP-DN-checking.patch Patch39: Fix-capaths-.-values-on-client.patch Patch40: Fix-hex-conversion-of-PKINIT-certid-strings.patch +Patch41: Exit-with-status-0-from-kadmind.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -713,6 +714,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Mar 14 2018 Robbie Harwood - 1.16-10 +- Exit with status 0 from kadmind + * Tue Mar 13 2018 Robbie Harwood - 1.16-9 - Fix hex conversion of PKINIT certid strings From a387becbf58d2c3f2cc9db34eb2884e556c441ea Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 19 Mar 2018 18:15:48 -0400 Subject: [PATCH 025/304] Add PKINIT KDC support for freshness token Also, fix securid_sam2 preauth for non-default salt --- ...INIT-KDC-support-for-freshness-token.patch | 631 +++++++++++++++ ...T-client-support-for-freshness-token.patch | 336 ++++++++ ...id_sam2-preauth-for-non-default-salt.patch | 43 + ...e-info-in-for-hardware-preauth-hints.patch | 38 + ...r-KDC-krb5_pa_data-utility-functions.patch | 393 ++++++++++ Simplify-kdc_preauth.c-systems-table.patch | 738 ++++++++++++++++++ krb5.spec | 11 +- 7 files changed, 2189 insertions(+), 1 deletion(-) create mode 100644 Add-PKINIT-KDC-support-for-freshness-token.patch create mode 100644 Add-PKINIT-client-support-for-freshness-token.patch create mode 100644 Fix-securid_sam2-preauth-for-non-default-salt.patch create mode 100644 Include-etype-info-in-for-hardware-preauth-hints.patch create mode 100644 Refactor-KDC-krb5_pa_data-utility-functions.patch create mode 100644 Simplify-kdc_preauth.c-systems-table.patch diff --git a/Add-PKINIT-KDC-support-for-freshness-token.patch b/Add-PKINIT-KDC-support-for-freshness-token.patch new file mode 100644 index 0000000..a2630db --- /dev/null +++ b/Add-PKINIT-KDC-support-for-freshness-token.patch @@ -0,0 +1,631 @@ +From 4ddfba7c9c12056f9f5819648f20f68e5625dced Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 12 Mar 2018 11:31:46 -0400 +Subject: [PATCH] Add PKINIT KDC support for freshness token + +Send a freshness token in the preauth hint list if PKINIT is +configured and the request padata indicates support. Verify the +freshness token if the client includes one in a PKINIT request, and +log whether one was received. If pkinit_require_freshness is set to +true in the realm config, reject non-anonymous requests which don't +contain a freshness token. + +Add freshness token tests to t_pkinit.py with some related changes. +Remove client long-term keys after testing password preauth so we get +better error reporting when pkinit_require_freshness is set and a +token is not sent. Remove ./responder invocations for test cases +which don't ask PKINIT responder questions, or else the responder +would fail now that it isn't being asked for the password. Leave +anonymous PKINIT enabled after the anonymous tests so that we can use +it again when testing enforcement of pkinit_require_freshness. Add +expected trace messages for the basic test, including one for +receiving a freshness token. Add minimal expected trace messages for +the RSA test. + +ticket: 8648 +(cherry picked from commit 4a9050df0bc34bfb08ba24462d6e2514640f4b8e) +--- + doc/admin/conf_files/kdc_conf.rst | 4 + + doc/admin/pkinit.rst | 25 ++++++ + doc/appdev/refs/macros/index.rst | 2 + + doc/formats/freshness_token.rst | 19 +++++ + doc/formats/index.rst | 1 + + src/include/krb5/kdcpreauth_plugin.h | 17 +++++ + src/include/krb5/krb5.hin | 3 + + src/kdc/do_as_req.c | 2 + + src/kdc/kdc_preauth.c | 130 +++++++++++++++++++++++++++++++- + src/kdc/kdc_util.h | 2 + + src/plugins/preauth/pkinit/pkinit.h | 2 + + src/plugins/preauth/pkinit/pkinit_srv.c | 51 ++++++++++++- + src/tests/t_pkinit.py | 50 ++++++++---- + 13 files changed, 292 insertions(+), 16 deletions(-) + create mode 100644 doc/formats/freshness_token.rst + +diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst +index 3af1c3796..1ac1a37c2 100644 +--- a/doc/admin/conf_files/kdc_conf.rst ++++ b/doc/admin/conf_files/kdc_conf.rst +@@ -798,6 +798,10 @@ For information about the syntax of some of these options, see + **pkinit_require_crl_checking** should be set to true if the + policy is such that up-to-date CRLs must be present for every CA. + ++**pkinit_require_freshness** ++ Specifies whether to require clients to include a freshness token ++ in PKINIT requests. The default value is false. (New in release ++ 1.17.) + + .. _Encryption_types: + +diff --git a/doc/admin/pkinit.rst b/doc/admin/pkinit.rst +index c601c5c9e..bec4fc800 100644 +--- a/doc/admin/pkinit.rst ++++ b/doc/admin/pkinit.rst +@@ -327,3 +327,28 @@ appropriate :ref:`kdc_realms` subsection of the KDC's + To obtain anonymous credentials on a client, run ``kinit -n``, or + ``kinit -n @REALMNAME`` to specify a realm. The resulting tickets + will have the client name ``WELLKNOWN/ANONYMOUS@WELLKNOWN:ANONYMOUS``. ++ ++ ++Freshness tokens ++---------------- ++ ++Freshness tokens can ensure that the client has recently had access to ++its certificate private key. If freshness tokens are not required by ++the KDC, a client program with temporary possession of the private key ++can compose requests for future timestamps and use them later. ++ ++In release 1.17 and later, freshness tokens are supported by the ++client and are sent by the KDC when the client indicates support for ++them. Because not all clients support freshness tokens yet, they are ++not required by default. To check if freshness tokens are supported ++by a realm's clients, look in the KDC logs for the lines:: ++ ++ PKINIT: freshness token received from ++ PKINIT: no freshness token received from ++ ++To require freshness tokens for all clients in a realm (except for ++clients authenticating anonymously), set the ++**pkinit_require_freshness** variable to ``true`` in the appropriate ++:ref:`kdc_realms` subsection of the KDC's :ref:`kdc.conf(5)` file. To ++test that this option is in effect, run ``kinit -X disable_freshness`` ++and verify that authentication is unsuccessful. +diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst +index e76747102..dba818b26 100644 +--- a/doc/appdev/refs/macros/index.rst ++++ b/doc/appdev/refs/macros/index.rst +@@ -181,6 +181,7 @@ Public + KRB5_KEYUSAGE_KRB_ERROR_CKSUM.rst + KRB5_KEYUSAGE_KRB_PRIV_ENCPART.rst + KRB5_KEYUSAGE_KRB_SAFE_CKSUM.rst ++ KRB5_KEYUSAGE_PA_AS_FRESHNESS.rst + KRB5_KEYUSAGE_PA_FX_COOKIE.rst + KRB5_KEYUSAGE_PA_OTP_REQUEST.rst + KRB5_KEYUSAGE_PA_PKINIT_KX.rst +@@ -241,6 +242,7 @@ Public + KRB5_PADATA_AFS3_SALT.rst + KRB5_PADATA_AP_REQ.rst + KRB5_PADATA_AS_CHECKSUM.rst ++ KRB5_PADATA_AS_FRESHNESS.rst + KRB5_PADATA_ENCRYPTED_CHALLENGE.rst + KRB5_PADATA_ENC_SANDIA_SECURID.rst + KRB5_PADATA_ENC_TIMESTAMP.rst +diff --git a/doc/formats/freshness_token.rst b/doc/formats/freshness_token.rst +new file mode 100644 +index 000000000..3127621a9 +--- /dev/null ++++ b/doc/formats/freshness_token.rst +@@ -0,0 +1,19 @@ ++PKINIT freshness tokens ++======================= ++ ++:rfc:`8070` specifies a pa-data type PA_AS_FRESHNESS, which clients ++should reflect within signed PKINIT data to prove recent access to the ++client certificate private key. The contents of a freshness token are ++left to the KDC implementation. The MIT krb5 KDC uses the following ++format for freshness tokens (starting in release 1.17): ++ ++* a four-byte big-endian POSIX timestamp ++* a four-byte big-endian key version number ++* an :rfc:`3961` checksum, with no ASN.1 wrapper ++ ++The checksum is computed using the first key in the local krbtgt ++principal entry for the realm (e.g. ``krbtgt/KRBTEST.COM@KRBTEST.COM`` ++if the request is to the ``KRBTEST.COM`` realm) of the indicated key ++version. The checksum type must be the mandatory checksum type for ++the encryption type of the krbtgt key. The key usage value for the ++checksum is 514. +diff --git a/doc/formats/index.rst b/doc/formats/index.rst +index 8b30626d4..4ad534424 100644 +--- a/doc/formats/index.rst ++++ b/doc/formats/index.rst +@@ -7,3 +7,4 @@ Protocols and file formats + ccache_file_format + keytab_file_format + cookie ++ freshness_token +diff --git a/src/include/krb5/kdcpreauth_plugin.h b/src/include/krb5/kdcpreauth_plugin.h +index f38820099..3a4754234 100644 +--- a/src/include/krb5/kdcpreauth_plugin.h ++++ b/src/include/krb5/kdcpreauth_plugin.h +@@ -240,6 +240,23 @@ typedef struct krb5_kdcpreauth_callbacks_st { + + /* End of version 4 kdcpreauth callbacks. */ + ++ /* ++ * Instruct the KDC to send a freshness token in the method data ++ * accompanying a PREAUTH_REQUIRED or PREAUTH_FAILED error, if the client ++ * indicated support for freshness tokens. This callback should only be ++ * invoked from the edata method. ++ */ ++ void (*send_freshness_token)(krb5_context context, ++ krb5_kdcpreauth_rock rock); ++ ++ /* Validate a freshness token sent by the client. Return 0 on success, ++ * KRB5KDC_ERR_PREAUTH_EXPIRED on error. */ ++ krb5_error_code (*check_freshness_token)(krb5_context context, ++ krb5_kdcpreauth_rock rock, ++ const krb5_data *token); ++ ++ /* End of version 5 kdcpreauth callbacks. */ ++ + } *krb5_kdcpreauth_callbacks; + + /* Optional: preauth plugin initialization function. */ +diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin +index 833e72335..a650ecece 100644 +--- a/src/include/krb5/krb5.hin ++++ b/src/include/krb5/krb5.hin +@@ -1035,7 +1035,10 @@ krb5_c_keyed_checksum_types(krb5_context context, krb5_enctype enctype, + #define KRB5_KEYUSAGE_AS_REQ 56 + #define KRB5_KEYUSAGE_CAMMAC 64 + ++/* Key usage values 512-1023 are reserved for uses internal to a Kerberos ++ * implementation. */ + #define KRB5_KEYUSAGE_PA_FX_COOKIE 513 /**< Used for encrypted FAST cookies */ ++#define KRB5_KEYUSAGE_PA_AS_FRESHNESS 514 /**< Used for freshness tokens */ + /** @} */ /* end of KRB5_KEYUSAGE group */ + + /** +diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c +index 7c8da63e1..588c1375a 100644 +--- a/src/kdc/do_as_req.c ++++ b/src/kdc/do_as_req.c +@@ -563,6 +563,7 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, + state->rock.rstate = state->rstate; + state->rock.vctx = vctx; + state->rock.auth_indicators = &state->auth_indicators; ++ state->rock.send_freshness_token = FALSE; + if (!state->request->client) { + state->status = "NULL_CLIENT"; + errcode = KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN; +@@ -659,6 +660,7 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, + state->status = "GET_LOCAL_TGT"; + goto errout; + } ++ state->rock.local_tgt = state->local_tgt; + + au_state->stage = VALIDATE_POL; + +diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c +index 6f34dc289..80b130222 100644 +--- a/src/kdc/kdc_preauth.c ++++ b/src/kdc/kdc_preauth.c +@@ -87,6 +87,9 @@ + #include + #include + ++/* Let freshness tokens be valid for ten minutes. */ ++#define FRESHNESS_LIFETIME 600 ++ + typedef struct preauth_system_st { + const char *name; + int type; +@@ -497,8 +500,68 @@ client_name(krb5_context context, krb5_kdcpreauth_rock rock) + return rock->client->princ; + } + ++static void ++send_freshness_token(krb5_context context, krb5_kdcpreauth_rock rock) ++{ ++ rock->send_freshness_token = TRUE; ++} ++ ++static krb5_error_code ++check_freshness_token(krb5_context context, krb5_kdcpreauth_rock rock, ++ const krb5_data *token) ++{ ++ krb5_timestamp token_ts, now; ++ krb5_key_data *kd; ++ krb5_keyblock kb; ++ krb5_kvno token_kvno; ++ krb5_checksum cksum; ++ krb5_data d; ++ uint8_t *token_cksum; ++ size_t token_cksum_len; ++ krb5_boolean valid = FALSE; ++ char ckbuf[4]; ++ ++ memset(&kb, 0, sizeof(kb)); ++ ++ if (krb5_timeofday(context, &now) != 0) ++ goto cleanup; ++ ++ if (token->length <= 8) ++ goto cleanup; ++ token_ts = load_32_be(token->data); ++ token_kvno = load_32_be(token->data + 4); ++ token_cksum = (uint8_t *)token->data + 8; ++ token_cksum_len = token->length - 8; ++ ++ /* Check if the token timestamp is too old. */ ++ if (ts_after(now, ts_incr(token_ts, FRESHNESS_LIFETIME))) ++ goto cleanup; ++ ++ /* Fetch and decrypt the local krbtgt key of the token's kvno. */ ++ if (krb5_dbe_find_enctype(context, rock->local_tgt, -1, -1, token_kvno, ++ &kd) != 0) ++ goto cleanup; ++ if (krb5_dbe_decrypt_key_data(context, NULL, kd, &kb, NULL) != 0) ++ goto cleanup; ++ ++ /* Verify the token checksum against the current KDC time. The checksum ++ * must use the mandatory checksum type of the krbtgt key's enctype. */ ++ store_32_be(token_ts, ckbuf); ++ d = make_data(ckbuf, sizeof(ckbuf)); ++ cksum.magic = KV5M_CHECKSUM; ++ cksum.checksum_type = 0; ++ cksum.length = token_cksum_len; ++ cksum.contents = token_cksum; ++ (void)krb5_c_verify_checksum(context, &kb, KRB5_KEYUSAGE_PA_AS_FRESHNESS, ++ &d, &cksum, &valid); ++ ++cleanup: ++ krb5_free_keyblock_contents(context, &kb); ++ return valid ? 0 : KRB5KDC_ERR_PREAUTH_EXPIRED; ++} ++ + static struct krb5_kdcpreauth_callbacks_st callbacks = { +- 4, ++ 5, + max_time_skew, + client_keys, + free_keys, +@@ -514,7 +577,9 @@ static struct krb5_kdcpreauth_callbacks_st callbacks = { + get_cookie, + set_cookie, + match_client, +- client_name ++ client_name, ++ send_freshness_token, ++ check_freshness_token + }; + + static krb5_error_code +@@ -770,6 +835,62 @@ cleanup: + return ret; + } + ++static krb5_error_code ++add_freshness_token(krb5_context context, krb5_kdcpreauth_rock rock, ++ krb5_pa_data ***pa_list) ++{ ++ krb5_error_code ret; ++ krb5_timestamp now; ++ krb5_key_data *kd; ++ krb5_keyblock kb; ++ krb5_checksum cksum; ++ krb5_data d; ++ krb5_pa_data *pa; ++ char ckbuf[4]; ++ ++ memset(&cksum, 0, sizeof(cksum)); ++ memset(&kb, 0, sizeof(kb)); ++ ++ if (!rock->send_freshness_token) ++ return 0; ++ if (krb5int_find_pa_data(context, rock->request->padata, ++ KRB5_PADATA_AS_FRESHNESS) == NULL) ++ return 0; ++ ++ /* Fetch and decrypt the current local krbtgt key. */ ++ ret = krb5_dbe_find_enctype(context, rock->local_tgt, -1, -1, 0, &kd); ++ if (ret) ++ goto cleanup; ++ ret = krb5_dbe_decrypt_key_data(context, NULL, kd, &kb, NULL); ++ if (ret) ++ goto cleanup; ++ ++ /* Compute a checksum over the current KDC time. */ ++ ret = krb5_timeofday(context, &now); ++ if (ret) ++ goto cleanup; ++ store_32_be(now, ckbuf); ++ d = make_data(ckbuf, sizeof(ckbuf)); ++ ret = krb5_c_make_checksum(context, 0, &kb, KRB5_KEYUSAGE_PA_AS_FRESHNESS, ++ &d, &cksum); ++ ++ /* Compose a freshness token from the time, krbtgt kvno, and checksum. */ ++ ret = alloc_pa_data(KRB5_PADATA_AS_FRESHNESS, 8 + cksum.length, &pa); ++ if (ret) ++ goto cleanup; ++ store_32_be(now, pa->contents); ++ store_32_be(kd->key_data_kvno, pa->contents + 4); ++ memcpy(pa->contents + 8, cksum.contents, cksum.length); ++ ++ /* add_pa_data_element() claims pa on success or failure. */ ++ ret = add_pa_data_element(pa_list, pa); ++ ++cleanup: ++ krb5_free_keyblock_contents(context, &kb); ++ krb5_free_checksum_contents(context, &cksum); ++ return ret; ++} ++ + struct hint_state { + kdc_hint_respond_fn respond; + void *arg; +@@ -792,6 +913,11 @@ hint_list_finish(struct hint_state *state, krb5_error_code code) + void *oldarg = state->arg; + kdc_realm_t *kdc_active_realm = state->realm; + ++ /* Add a freshness token if a preauth module requested it and the client ++ * request indicates support for it. */ ++ if (!code) ++ code = add_freshness_token(kdc_context, state->rock, &state->pa_data); ++ + if (!code) { + if (state->pa_data == NULL) { + krb5_klog_syslog(LOG_INFO, +diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h +index 18649b8ad..a63af2503 100644 +--- a/src/kdc/kdc_util.h ++++ b/src/kdc/kdc_util.h +@@ -427,11 +427,13 @@ struct krb5_kdcpreauth_rock_st { + krb5_kdc_req *request; + krb5_data *inner_body; + krb5_db_entry *client; ++ krb5_db_entry *local_tgt; + krb5_key_data *client_key; + krb5_keyblock *client_keyblock; + struct kdc_request_state *rstate; + verto_ctx *vctx; + krb5_data ***auth_indicators; ++ krb5_boolean send_freshness_token; + }; + + #define isflagset(flagfield, flag) (flagfield & (flag)) +diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h +index 8489a3e23..fe2ec0d31 100644 +--- a/src/plugins/preauth/pkinit/pkinit.h ++++ b/src/plugins/preauth/pkinit/pkinit.h +@@ -77,6 +77,7 @@ + #define KRB5_CONF_PKINIT_KDC_OCSP "pkinit_kdc_ocsp" + #define KRB5_CONF_PKINIT_POOL "pkinit_pool" + #define KRB5_CONF_PKINIT_REQUIRE_CRL_CHECKING "pkinit_require_crl_checking" ++#define KRB5_CONF_PKINIT_REQUIRE_FRESHNESS "pkinit_require_freshness" + #define KRB5_CONF_PKINIT_REVOKE "pkinit_revoke" + + /* Make pkiDebug(fmt,...) print, or not. */ +@@ -148,6 +149,7 @@ typedef struct _pkinit_plg_opts { + int allow_upn; /* allow UPN-SAN instead of pkinit-SAN */ + int dh_or_rsa; /* selects DH or RSA based pkinit */ + int require_crl_checking; /* require CRL for a CA (default is false) */ ++ int require_freshness; /* require freshness token (default is false) */ + int disable_freshness; /* disable freshness token on client for testing */ + int dh_min_bits; /* minimum DH modulus size allowed */ + } pkinit_plg_opts; +diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c +index 4e9685885..bbfde34b2 100644 +--- a/src/plugins/preauth/pkinit/pkinit_srv.c ++++ b/src/plugins/preauth/pkinit/pkinit_srv.c +@@ -161,6 +161,10 @@ pkinit_server_get_edata(krb5_context context, + if (plgctx == NULL) + retval = EINVAL; + ++ /* Send a freshness token if the client requested one. */ ++ if (!retval) ++ cb->send_freshness_token(context, rock); ++ + (*respond)(arg, retval, NULL); + } + +@@ -396,6 +400,31 @@ cleanup: + return ret; + } + ++/* Return an error if freshness tokens are required and one was not received. ++ * Log an appropriate message indicating whether a valid token was received. */ ++static krb5_error_code ++check_log_freshness(krb5_context context, pkinit_kdc_context plgctx, ++ krb5_kdc_req *request, krb5_boolean valid_freshness_token) ++{ ++ krb5_error_code ret; ++ char *name = NULL; ++ ++ ret = krb5_unparse_name(context, request->client, &name); ++ if (ret) ++ return ret; ++ if (plgctx->opts->require_freshness && !valid_freshness_token) { ++ com_err("", 0, _("PKINIT: no freshness token, rejecting auth from %s"), ++ name); ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ } else if (valid_freshness_token) { ++ com_err("", 0, _("PKINIT: freshness token received from %s"), name); ++ } else { ++ com_err("", 0, _("PKINIT: no freshness token received from %s"), name); ++ } ++ krb5_free_unparsed_name(context, name); ++ return ret; ++} ++ + static void + pkinit_server_verify_padata(krb5_context context, + krb5_data *req_pkt, +@@ -418,10 +447,11 @@ pkinit_server_verify_padata(krb5_context context, + pkinit_kdc_req_context reqctx = NULL; + krb5_checksum cksum = {0, 0, 0, NULL}; + krb5_data *der_req = NULL; +- krb5_data k5data; ++ krb5_data k5data, *ftoken; + int is_signed = 1; + krb5_pa_data **e_data = NULL; + krb5_kdcpreauth_modreq modreq = NULL; ++ krb5_boolean valid_freshness_token = FALSE; + char **sp; + + pkiDebug("pkinit_verify_padata: entered!\n"); +@@ -592,6 +622,14 @@ pkinit_server_verify_padata(krb5_context context, + goto cleanup; + } + ++ ftoken = auth_pack->pkAuthenticator.freshnessToken; ++ if (ftoken != NULL) { ++ retval = cb->check_freshness_token(context, rock, ftoken); ++ if (retval) ++ goto cleanup; ++ valid_freshness_token = TRUE; ++ } ++ + /* check if kdcPkId present and match KDC's subjectIdentifier */ + if (reqp->kdcPkId.data != NULL) { + int valid_kdcPkId = 0; +@@ -634,6 +672,13 @@ pkinit_server_verify_padata(krb5_context context, + break; + } + ++ if (is_signed) { ++ retval = check_log_freshness(context, plgctx, request, ++ valid_freshness_token); ++ if (retval) ++ goto cleanup; ++ } ++ + if (is_signed && plgctx->auth_indicators != NULL) { + /* Assert configured authentication indicators. */ + for (sp = plgctx->auth_indicators; *sp != NULL; sp++) { +@@ -1323,6 +1368,10 @@ pkinit_init_kdc_profile(krb5_context context, pkinit_kdc_context plgctx) + KRB5_CONF_PKINIT_REQUIRE_CRL_CHECKING, + 0, &plgctx->opts->require_crl_checking); + ++ pkinit_kdcdefault_boolean(context, plgctx->realmname, ++ KRB5_CONF_PKINIT_REQUIRE_FRESHNESS, ++ 0, &plgctx->opts->require_freshness); ++ + pkinit_kdcdefault_string(context, plgctx->realmname, + KRB5_CONF_PKINIT_EKU_CHECKING, + &eku_string); +diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py +index b790a7cda..3030322e1 100755 +--- a/src/tests/t_pkinit.py ++++ b/src/tests/t_pkinit.py +@@ -39,6 +39,8 @@ pkinit_kdc_conf = {'realms': {'$realm': { + 'pkinit_indicator': ['indpkinit1', 'indpkinit2']}}} + restrictive_kdc_conf = {'realms': {'$realm': { + 'restrict_anonymous_to_tgt': 'true' }}} ++freshness_kdc_conf = {'realms': {'$realm': { ++ 'pkinit_require_freshness': 'true'}}} + + testprincs = {'krbtgt/KRBTEST.COM': {'keys': 'aes128-cts'}, + 'user': {'keys': 'aes128-cts', 'flags': '+preauth'}, +@@ -118,6 +120,10 @@ realm.kinit(realm.user_princ, password=password('user')) + realm.klist(realm.user_princ) + realm.run([kvno, realm.host_princ]) + ++# Having tested password preauth, remove the keys for better error ++# reporting. ++realm.run([kadminl, 'purgekeys', '-all', realm.user_princ]) ++ + # Test anonymous PKINIT. + realm.kinit('@%s' % realm.realm, flags=['-n'], expected_code=1, + expected_msg='not found in Kerberos database') +@@ -153,23 +159,32 @@ realm.run([kvno, realm.host_princ], expected_code=1, + realm.kinit(realm.host_princ, flags=['-k']) + realm.run([kvno, '-U', 'user', realm.host_princ]) + +-# Go back to a normal KDC and disable anonymous PKINIT. ++# Go back to the normal KDC environment. + realm.stop_kdc() + realm.start_kdc() +-realm.run([kadminl, 'delprinc', 'WELLKNOWN/ANONYMOUS']) + + # Run the basic test - PKINIT with FILE: identity, with no password on the key. +-realm.run(['./responder', '-x', 'pkinit=', +- '-X', 'X509_user_identity=%s' % file_identity, realm.user_princ]) + realm.kinit(realm.user_princ, +- flags=['-X', 'X509_user_identity=%s' % file_identity]) ++ flags=['-X', 'X509_user_identity=%s' % file_identity], ++ expected_trace=('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Preauthenticating using KDC method data', ++ 'PKINIT client received freshness token from KDC', ++ 'PKINIT loading CA certs and CRLs from FILE', ++ 'PKINIT client making DH request', ++ 'Produced preauth for next request: 133, 16', ++ 'PKINIT client verified DH reply', ++ 'PKINIT client found id-pkinit-san in KDC cert', ++ 'PKINIT client matched KDC principal krbtgt/')) + realm.klist(realm.user_princ) + realm.run([kvno, realm.host_princ]) + + # Try again using RSA instead of DH. + realm.kinit(realm.user_princ, + flags=['-X', 'X509_user_identity=%s' % file_identity, +- '-X', 'flag_RSA_PROTOCOL=yes']) ++ '-X', 'flag_RSA_PROTOCOL=yes'], ++ expected_trace=('PKINIT client making RSA request', ++ 'PKINIT client verified RSA reply')) + realm.klist(realm.user_princ) + + # Test a DH parameter renegotiation by temporarily setting a 4096-bit +@@ -192,8 +207,23 @@ expected_trace = ('Sending unauthenticated request', + realm.kinit(realm.user_princ, + flags=['-X', 'X509_user_identity=%s' % file_identity], + expected_trace=expected_trace) ++ ++# Test enforcement of required freshness tokens. (We can leave ++# freshness tokens required after this test.) ++realm.kinit(realm.user_princ, ++ flags=['-X', 'X509_user_identity=%s' % file_identity, ++ '-X', 'disable_freshness=yes']) ++f_env = realm.special_env('freshness', True, kdc_conf=freshness_kdc_conf) + realm.stop_kdc() +-realm.start_kdc() ++realm.start_kdc(env=f_env) ++realm.kinit(realm.user_princ, ++ flags=['-X', 'X509_user_identity=%s' % file_identity]) ++realm.kinit(realm.user_princ, ++ flags=['-X', 'X509_user_identity=%s' % file_identity, ++ '-X', 'disable_freshness=yes'], ++ expected_code=1, expected_msg='Preauthentication failed') ++# Anonymous should never require a freshness token. ++realm.kinit('@%s' % realm.realm, flags=['-n', '-X', 'disable_freshness=yes']) + + # Run the basic test - PKINIT with FILE: identity, with a password on the key, + # supplied by the prompter. +@@ -229,8 +259,6 @@ shutil.copy(privkey_pem, os.path.join(path, 'user.key')) + shutil.copy(privkey_enc_pem, os.path.join(path_enc, 'user.key')) + shutil.copy(user_pem, os.path.join(path, 'user.crt')) + shutil.copy(user_pem, os.path.join(path_enc, 'user.crt')) +-realm.run(['./responder', '-x', 'pkinit=', '-X', +- 'X509_user_identity=%s' % dir_identity, realm.user_princ]) + realm.kinit(realm.user_princ, + flags=['-X', 'X509_user_identity=%s' % dir_identity]) + realm.klist(realm.user_princ) +@@ -262,8 +290,6 @@ realm.klist(realm.user_princ) + realm.run([kvno, realm.host_princ]) + + # PKINIT with PKCS12: identity, with no password on the bundle. +-realm.run(['./responder', '-x', 'pkinit=', +- '-X', 'X509_user_identity=%s' % p12_identity, realm.user_princ]) + realm.kinit(realm.user_princ, + flags=['-X', 'X509_user_identity=%s' % p12_identity]) + realm.klist(realm.user_princ) +@@ -350,8 +376,6 @@ conf = open(softpkcs11rc, 'w') + conf.write("%s\t%s\t%s\t%s\n" % ('user', 'user token', user_pem, privkey_pem)) + conf.close() + # Expect to succeed without having to supply any more information. +-realm.run(['./responder', '-x', 'pkinit=', +- '-X', 'X509_user_identity=%s' % p11_identity, realm.user_princ]) + realm.kinit(realm.user_princ, + flags=['-X', 'X509_user_identity=%s' % p11_identity]) + realm.klist(realm.user_princ) diff --git a/Add-PKINIT-client-support-for-freshness-token.patch b/Add-PKINIT-client-support-for-freshness-token.patch new file mode 100644 index 0000000..478229b --- /dev/null +++ b/Add-PKINIT-client-support-for-freshness-token.patch @@ -0,0 +1,336 @@ +From 7eb2df66aef8e2b58ec7dfa13e9ee19f5e3b5b34 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 31 Jan 2017 17:02:34 -0500 +Subject: [PATCH] Add PKINIT client support for freshness token + +Send an empty PA_AS_FRESHNESS padata item in unauthenticated AS +requests to indicate support for RFC 8070. If the KDC includes a +PA_AS_FRESHNESS value in its method data, echo it back in the new +freshnessToken field of pkAuthenticator + +ticket: 8648 +(cherry picked from commit 085785362e01467cb25c79a90dcebfba9ea019d8) +--- + doc/user/user_commands/kinit.rst | 3 +++ + src/include/k5-int-pkinit.h | 1 + + src/include/krb5/krb5.hin | 1 + + src/lib/krb5/asn.1/asn1_k_encode.c | 5 ++++- + src/lib/krb5/krb/get_in_tkt.c | 12 ++++++++---- + src/lib/krb5/krb/init_creds_ctx.h | 2 +- + src/plugins/preauth/pkinit/pkinit.h | 3 +++ + src/plugins/preauth/pkinit/pkinit_clnt.c | 19 ++++++++++++++++++- + src/plugins/preauth/pkinit/pkinit_lib.c | 3 +++ + src/plugins/preauth/pkinit/pkinit_trace.h | 2 ++ + src/tests/asn.1/ktest.c | 4 ++++ + src/tests/asn.1/pkinit_encode.out | 2 +- + src/tests/asn.1/pkinit_trval.out | 1 + + 13 files changed, 50 insertions(+), 8 deletions(-) + +diff --git a/doc/user/user_commands/kinit.rst b/doc/user/user_commands/kinit.rst +index 3f9d5340f..1f696920f 100644 +--- a/doc/user/user_commands/kinit.rst ++++ b/doc/user/user_commands/kinit.rst +@@ -197,6 +197,9 @@ OPTIONS + specify use of RSA, rather than the default Diffie-Hellman + protocol + ++ **disable_freshness**\ [**=yes**] ++ disable sending freshness tokens (for testing purposes only) ++ + + ENVIRONMENT + ----------- +diff --git a/src/include/k5-int-pkinit.h b/src/include/k5-int-pkinit.h +index 7b2f595cb..4622a629e 100644 +--- a/src/include/k5-int-pkinit.h ++++ b/src/include/k5-int-pkinit.h +@@ -42,6 +42,7 @@ typedef struct _krb5_pk_authenticator { + krb5_timestamp ctime; + krb5_int32 nonce; /* (0..4294967295) */ + krb5_checksum paChecksum; ++ krb5_data *freshnessToken; + } krb5_pk_authenticator; + + /* PKAuthenticator draft9 */ +diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin +index e81bb0a6d..833e72335 100644 +--- a/src/include/krb5/krb5.hin ++++ b/src/include/krb5/krb5.hin +@@ -1879,6 +1879,7 @@ krb5_verify_checksum(krb5_context context, krb5_cksumtype ctype, + #define KRB5_PADATA_OTP_PIN_CHANGE 144 /**< RFC 6560 section 4.3 */ + #define KRB5_PADATA_PKINIT_KX 147 /**< RFC 6112 */ + #define KRB5_ENCPADATA_REQ_ENC_PA_REP 149 /**< RFC 6806 */ ++#define KRB5_PADATA_AS_FRESHNESS 150 /**< RFC 8070 */ + + #define KRB5_SAM_USE_SAD_AS_KEY 0x80000000 + #define KRB5_SAM_SEND_ENCRYPTED_SAD 0x40000000 +diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c +index 889460989..3b23fe34a 100644 +--- a/src/lib/krb5/asn.1/asn1_k_encode.c ++++ b/src/lib/krb5/asn.1/asn1_k_encode.c +@@ -1442,9 +1442,12 @@ DEFFIELD(pk_authenticator_1, krb5_pk_authenticator, ctime, 1, kerberos_time); + DEFFIELD(pk_authenticator_2, krb5_pk_authenticator, nonce, 2, int32); + DEFFIELD(pk_authenticator_3, krb5_pk_authenticator, paChecksum, 3, + ostring_checksum); ++DEFFIELD(pk_authenticator_4, krb5_pk_authenticator, freshnessToken, 4, ++ opt_ostring_data_ptr); + static const struct atype_info *pk_authenticator_fields[] = { + &k5_atype_pk_authenticator_0, &k5_atype_pk_authenticator_1, +- &k5_atype_pk_authenticator_2, &k5_atype_pk_authenticator_3 ++ &k5_atype_pk_authenticator_2, &k5_atype_pk_authenticator_3, ++ &k5_atype_pk_authenticator_4 + }; + DEFSEQTYPE(pk_authenticator, krb5_pk_authenticator, pk_authenticator_fields); + +diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c +index 47a00bf2c..1d96ff163 100644 +--- a/src/lib/krb5/krb/get_in_tkt.c ++++ b/src/lib/krb5/krb/get_in_tkt.c +@@ -895,7 +895,7 @@ krb5_init_creds_init(krb5_context context, + ctx->request = k5alloc(sizeof(krb5_kdc_req), &code); + if (code != 0) + goto cleanup; +- ctx->enc_pa_rep_permitted = TRUE; ++ ctx->info_pa_permitted = TRUE; + code = krb5_copy_principal(context, client, &ctx->request->client); + if (code != 0) + goto cleanup; +@@ -1389,7 +1389,11 @@ init_creds_step_request(krb5_context context, + krb5_free_data(context, ctx->encoded_previous_request); + ctx->encoded_previous_request = NULL; + } +- if (ctx->enc_pa_rep_permitted) { ++ if (ctx->info_pa_permitted) { ++ code = add_padata(&ctx->request->padata, KRB5_PADATA_AS_FRESHNESS, ++ NULL, 0); ++ if (code) ++ goto cleanup; + code = add_padata(&ctx->request->padata, KRB5_ENCPADATA_REQ_ENC_PA_REP, + NULL, 0); + } +@@ -1530,7 +1534,7 @@ init_creds_step_reply(krb5_context context, + ctx->selected_preauth_type == KRB5_PADATA_NONE) { + /* The KDC didn't like our informational padata (probably a pre-1.7 + * MIT krb5 KDC). Retry without it. */ +- ctx->enc_pa_rep_permitted = FALSE; ++ ctx->info_pa_permitted = FALSE; + ctx->restarted = TRUE; + code = restart_init_creds_loop(context, ctx, FALSE); + } else if (reply_code == KDC_ERR_PREAUTH_EXPIRED) { +@@ -1574,7 +1578,7 @@ init_creds_step_reply(krb5_context context, + goto cleanup; + /* Reset per-realm negotiation state. */ + ctx->restarted = FALSE; +- ctx->enc_pa_rep_permitted = TRUE; ++ ctx->info_pa_permitted = TRUE; + code = restart_init_creds_loop(context, ctx, FALSE); + } else { + if (retry && ctx->selected_preauth_type != KRB5_PADATA_NONE) { +diff --git a/src/lib/krb5/krb/init_creds_ctx.h b/src/lib/krb5/krb/init_creds_ctx.h +index fe769685b..b19410a13 100644 +--- a/src/lib/krb5/krb/init_creds_ctx.h ++++ b/src/lib/krb5/krb/init_creds_ctx.h +@@ -58,7 +58,7 @@ struct _krb5_init_creds_context { + krb5_data s2kparams; + krb5_keyblock as_key; + krb5_enctype etype; +- krb5_boolean enc_pa_rep_permitted; ++ krb5_boolean info_pa_permitted; + krb5_boolean restarted; + struct krb5_responder_context_st rctx; + krb5_preauthtype selected_preauth_type; +diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h +index f3de9ad7a..8489a3e23 100644 +--- a/src/plugins/preauth/pkinit/pkinit.h ++++ b/src/plugins/preauth/pkinit/pkinit.h +@@ -148,6 +148,7 @@ typedef struct _pkinit_plg_opts { + int allow_upn; /* allow UPN-SAN instead of pkinit-SAN */ + int dh_or_rsa; /* selects DH or RSA based pkinit */ + int require_crl_checking; /* require CRL for a CA (default is false) */ ++ int disable_freshness; /* disable freshness token on client for testing */ + int dh_min_bits; /* minimum DH modulus size allowed */ + } pkinit_plg_opts; + +@@ -162,6 +163,7 @@ typedef struct _pkinit_req_opts { + int require_crl_checking; + int dh_size; /* initial request DH modulus size (default=1024) */ + int require_hostname_match; ++ int disable_freshness; + } pkinit_req_opts; + + /* +@@ -214,6 +216,7 @@ struct _pkinit_req_context { + int identity_initialized; + int identity_prompted; + krb5_error_code identity_prompt_retval; ++ krb5_data *freshness_token; + }; + typedef struct _pkinit_req_context *pkinit_req_context; + +diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c +index f1bc6b21d..9483d69e5 100644 +--- a/src/plugins/preauth/pkinit/pkinit_clnt.c ++++ b/src/plugins/preauth/pkinit/pkinit_clnt.c +@@ -231,6 +231,8 @@ pkinit_as_req_create(krb5_context context, + auth_pack.pkAuthenticator.cusec = cusec; + auth_pack.pkAuthenticator.nonce = nonce; + auth_pack.pkAuthenticator.paChecksum = *cksum; ++ if (!reqctx->opts->disable_freshness) ++ auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token; + auth_pack.clientDHNonce.length = 0; + auth_pack.clientPublicValue = &info; + auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; +@@ -1162,6 +1164,7 @@ pkinit_client_process(krb5_context context, krb5_clpreauth_moddata moddata, + pkinit_context plgctx = (pkinit_context)moddata; + pkinit_req_context reqctx = (pkinit_req_context)modreq; + krb5_keyblock as_key; ++ krb5_data d; + + pkiDebug("pkinit_client_process %p %p %p %p\n", + context, plgctx, reqctx, request); +@@ -1174,6 +1177,12 @@ pkinit_client_process(krb5_context context, krb5_clpreauth_moddata moddata, + case KRB5_PADATA_PKINIT_KX: + reqctx->rfc6112_kdc = 1; + return 0; ++ case KRB5_PADATA_AS_FRESHNESS: ++ TRACE_PKINIT_CLIENT_FRESHNESS_TOKEN(context); ++ krb5_free_data(context, reqctx->freshness_token); ++ reqctx->freshness_token = NULL; ++ d = make_data(in_padata->contents, in_padata->length); ++ return krb5_copy_data(context, &d, &reqctx->freshness_token); + case KRB5_PADATA_PK_AS_REQ: + reqctx->rfc4556_kdc = 1; + pkiDebug("processing KRB5_PADATA_PK_AS_REQ\n"); +@@ -1359,7 +1368,7 @@ cleanup: + static int + pkinit_client_get_flags(krb5_context kcontext, krb5_preauthtype patype) + { +- if (patype == KRB5_PADATA_PKINIT_KX) ++ if (patype == KRB5_PADATA_PKINIT_KX || patype == KRB5_PADATA_AS_FRESHNESS) + return PA_INFO; + return PA_REAL; + } +@@ -1376,6 +1385,7 @@ static krb5_preauthtype supported_client_pa_types[] = { + KRB5_PADATA_PK_AS_REP_OLD, + KRB5_PADATA_PK_AS_REQ_OLD, + KRB5_PADATA_PKINIT_KX, ++ KRB5_PADATA_AS_FRESHNESS, + 0 + }; + +@@ -1400,6 +1410,7 @@ pkinit_client_req_init(krb5_context context, + reqctx->opts = NULL; + reqctx->idctx = NULL; + reqctx->idopts = NULL; ++ reqctx->freshness_token = NULL; + + retval = pkinit_init_req_opts(&reqctx->opts); + if (retval) +@@ -1410,6 +1421,7 @@ pkinit_client_req_init(krb5_context context, + reqctx->opts->dh_or_rsa = plgctx->opts->dh_or_rsa; + reqctx->opts->allow_upn = plgctx->opts->allow_upn; + reqctx->opts->require_crl_checking = plgctx->opts->require_crl_checking; ++ reqctx->opts->disable_freshness = plgctx->opts->disable_freshness; + + retval = pkinit_init_req_crypto(&reqctx->cryptoctx); + if (retval) +@@ -1468,6 +1480,8 @@ pkinit_client_req_fini(krb5_context context, krb5_clpreauth_moddata moddata, + if (reqctx->idopts != NULL) + pkinit_fini_identity_opts(reqctx->idopts); + ++ krb5_free_data(context, reqctx->freshness_token); ++ + free(reqctx); + return; + } +@@ -1580,6 +1594,9 @@ handle_gic_opt(krb5_context context, + pkiDebug("Setting flag to use RSA_PROTOCOL\n"); + plgctx->opts->dh_or_rsa = RSA_PROTOCOL; + } ++ } else if (strcmp(attr, "disable_freshness") == 0) { ++ if (strcmp(value, "yes") == 0) ++ plgctx->opts->disable_freshness = 1; + } + return 0; + } +diff --git a/src/plugins/preauth/pkinit/pkinit_lib.c b/src/plugins/preauth/pkinit/pkinit_lib.c +index 2f88545da..d5858c424 100644 +--- a/src/plugins/preauth/pkinit/pkinit_lib.c ++++ b/src/plugins/preauth/pkinit/pkinit_lib.c +@@ -82,6 +82,8 @@ pkinit_init_plg_opts(pkinit_plg_opts **plgopts) + opts->dh_or_rsa = DH_PROTOCOL; + opts->allow_upn = 0; + opts->require_crl_checking = 0; ++ opts->require_freshness = 0; ++ opts->disable_freshness = 0; + + opts->dh_min_bits = PKINIT_DEFAULT_DH_MIN_BITS; + +@@ -145,6 +147,7 @@ free_krb5_auth_pack(krb5_auth_pack **in) + free((*in)->clientPublicValue); + } + free((*in)->pkAuthenticator.paChecksum.contents); ++ krb5_free_data(NULL, (*in)->pkAuthenticator.freshnessToken); + if ((*in)->supportedCMSTypes != NULL) + free_krb5_algorithm_identifiers(&((*in)->supportedCMSTypes)); + if ((*in)->supportedKDFs) { +diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h +index d4eb39d88..67e0caeb4 100644 +--- a/src/plugins/preauth/pkinit/pkinit_trace.h ++++ b/src/plugins/preauth/pkinit/pkinit_trace.h +@@ -41,6 +41,8 @@ + TRACE(c, "PKINIT client found no acceptable EKU in KDC cert") + #define TRACE_PKINIT_CLIENT_EKU_SKIP(c) \ + TRACE(c, "PKINIT client skipping EKU check due to configuration") ++#define TRACE_PKINIT_CLIENT_FRESHNESS_TOKEN(c) \ ++ TRACE(c, "PKINIT client received freshness token from KDC") + #define TRACE_PKINIT_CLIENT_KDF_ALG(c, kdf, keyblock) \ + TRACE(c, "PKINIT client used KDF {hexdata} to compute reply key " \ + "{keyblock}", kdf, keyblock) +diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c +index 43084cbbd..cf63f3f66 100644 +--- a/src/tests/asn.1/ktest.c ++++ b/src/tests/asn.1/ktest.c +@@ -725,6 +725,8 @@ ktest_make_sample_pk_authenticator(krb5_pk_authenticator *p) + ktest_make_sample_checksum(&p->paChecksum); + /* We don't encode the checksum type, only the contents. */ + p->paChecksum.checksum_type = 0; ++ p->freshnessToken = ealloc(sizeof(krb5_data)); ++ ktest_make_sample_data(p->freshnessToken); + } + + static void +@@ -1651,6 +1653,8 @@ ktest_empty_pk_authenticator(krb5_pk_authenticator *p) + { + ktest_empty_checksum(&p->paChecksum); + p->paChecksum.contents = NULL; ++ krb5_free_data(NULL, p->freshnessToken); ++ p->freshnessToken = NULL; + } + + static void +diff --git a/src/tests/asn.1/pkinit_encode.out b/src/tests/asn.1/pkinit_encode.out +index 463128de0..3b0f7190a 100644 +--- a/src/tests/asn.1/pkinit_encode.out ++++ b/src/tests/asn.1/pkinit_encode.out +@@ -4,7 +4,7 @@ encode_krb5_pa_pk_as_rep(dhInfo): A0 28 30 26 80 08 6B 72 62 35 64 61 74 61 A1 0 + encode_krb5_pa_pk_as_rep(encKeyPack): 81 08 6B 72 62 35 64 61 74 61 + encode_krb5_pa_pk_as_rep_draft9(dhSignedData): 80 08 6B 72 62 35 64 61 74 61 + encode_krb5_pa_pk_as_rep_draft9(encKeyPack): 81 08 6B 72 62 35 64 61 74 61 +-encode_krb5_auth_pack: 30 81 93 A0 29 30 27 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61 ++encode_krb5_auth_pack: 30 81 9F A0 35 30 33 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61 + encode_krb5_auth_pack_draft9: 30 75 A0 4F 30 4D A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A2 05 02 03 01 E2 40 A3 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A4 03 02 01 2A A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61 + encode_krb5_kdc_dh_key_info: 30 25 A0 0B 03 09 00 6B 72 62 35 64 61 74 61 A1 03 02 01 2A A2 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A + encode_krb5_reply_key_pack: 30 26 A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34 +diff --git a/src/tests/asn.1/pkinit_trval.out b/src/tests/asn.1/pkinit_trval.out +index 58d870631..f9edbe154 100644 +--- a/src/tests/asn.1/pkinit_trval.out ++++ b/src/tests/asn.1/pkinit_trval.out +@@ -57,6 +57,7 @@ encode_krb5_auth_pack: + . . [1] [Generalized Time] "19940610060317Z" + . . [2] [Integer] 42 + . . [3] [Octet String] "1234" ++. . [4] [Octet String] "krb5data" + . [1] [Sequence/Sequence Of] + . . [Sequence/Sequence Of] + . . . [Object Identifier] <9> diff --git a/Fix-securid_sam2-preauth-for-non-default-salt.patch b/Fix-securid_sam2-preauth-for-non-default-salt.patch new file mode 100644 index 0000000..4d6365e --- /dev/null +++ b/Fix-securid_sam2-preauth-for-non-default-salt.patch @@ -0,0 +1,43 @@ +From afe1c26d08f0aead0d4ac49ad06715b1e8be7b6d Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 3 Jan 2018 12:06:08 -0500 +Subject: [PATCH] Fix securid_sam2 preauth for non-default salt + +When looking up the client long-term key, look for any salt type, not +just the default salt type. + +ticket: 8629 +(cherry picked from commit a2339099ad13c84de0843fd04d0ba612fc194a1e) +--- + src/plugins/preauth/securid_sam2/grail.c | 3 +-- + src/plugins/preauth/securid_sam2/securid2.c | 3 +-- + 2 files changed, 2 insertions(+), 4 deletions(-) + +diff --git a/src/plugins/preauth/securid_sam2/grail.c b/src/plugins/preauth/securid_sam2/grail.c +index 18d48f924..48b61b0d1 100644 +--- a/src/plugins/preauth/securid_sam2/grail.c ++++ b/src/plugins/preauth/securid_sam2/grail.c +@@ -213,8 +213,7 @@ verify_grail_data(krb5_context context, krb5_db_entry *client, + return KRB5KDC_ERR_PREAUTH_FAILED; + + ret = krb5_dbe_find_enctype(context, client, +- sr2->sam_enc_nonce_or_sad.enctype, +- KRB5_KDB_SALTTYPE_NORMAL, ++ sr2->sam_enc_nonce_or_sad.enctype, -1, + sr2->sam_enc_nonce_or_sad.kvno, + &client_key_data); + if (ret) +diff --git a/src/plugins/preauth/securid_sam2/securid2.c b/src/plugins/preauth/securid_sam2/securid2.c +index ca99ce3ef..363e17a10 100644 +--- a/src/plugins/preauth/securid_sam2/securid2.c ++++ b/src/plugins/preauth/securid_sam2/securid2.c +@@ -313,8 +313,7 @@ verify_securid_data_2(krb5_context context, krb5_db_entry *client, + } + + retval = krb5_dbe_find_enctype(context, client, +- sr2->sam_enc_nonce_or_sad.enctype, +- KRB5_KDB_SALTTYPE_NORMAL, ++ sr2->sam_enc_nonce_or_sad.enctype, -1, + sr2->sam_enc_nonce_or_sad.kvno, + &client_key_data); + if (retval) { diff --git a/Include-etype-info-in-for-hardware-preauth-hints.patch b/Include-etype-info-in-for-hardware-preauth-hints.patch new file mode 100644 index 0000000..21eef78 --- /dev/null +++ b/Include-etype-info-in-for-hardware-preauth-hints.patch @@ -0,0 +1,38 @@ +From be4a469216fb87408484b90be9a1da772ba923df Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 3 Jan 2018 11:59:14 -0500 +Subject: [PATCH] Include etype-info in for hardware preauth hints + +If a principal has the requires_hwauth bit set, include PA-ETYPE-INFO +or PA-ETYPE-INFO2 padata in the PREAUTH_REQUIRED error, as preauth +mechs involving hardware tokens may also use the principal's Kerberos +password. + +ticket: 8629 +(cherry picked from commit ba92da05accc524b8037453b63ced1a6c65fd2a1) +--- + src/kdc/kdc_preauth.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c +index 81d0b8cff..739c5e776 100644 +--- a/src/kdc/kdc_preauth.c ++++ b/src/kdc/kdc_preauth.c +@@ -144,7 +144,7 @@ static preauth_system static_preauth_systems[] = { + { + "etype-info", + KRB5_PADATA_ETYPE_INFO, +- 0, ++ PA_HARDWARE, + NULL, + NULL, + NULL, +@@ -155,7 +155,7 @@ static preauth_system static_preauth_systems[] = { + { + "etype-info2", + KRB5_PADATA_ETYPE_INFO2, +- 0, ++ PA_HARDWARE, + NULL, + NULL, + NULL, diff --git a/Refactor-KDC-krb5_pa_data-utility-functions.patch b/Refactor-KDC-krb5_pa_data-utility-functions.patch new file mode 100644 index 0000000..664e99b --- /dev/null +++ b/Refactor-KDC-krb5_pa_data-utility-functions.patch @@ -0,0 +1,393 @@ +From 61e3f0142b09cb230be3a2a110f5224e773f1281 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 21 Dec 2017 11:28:52 -0500 +Subject: [PATCH] Refactor KDC krb5_pa_data utility functions + +Move alloc_padata from fast_util.c to kdc_util.c and make it +non-static so it can be used by other files. Rename it to +alloc_pa_data for consistency with add_pa_data_element. Make it +correctly handle zero length using a null contents pointer. + +Make add_pa_data_element claim both the container and contents memory +from the caller, now that callers can use alloc_pa_data to simplify +allocation and copying. Remove the copy parameter and the unused +context parameter, and put the list parameter first. Adjust all +callers accordingly, making small simplifications to memory handling +where applicable. + +(cherry picked from commit 4af478c18b02e1d2444a328bb79e6976ef3d312b) +--- + src/kdc/fast_util.c | 28 +------- + src/kdc/kdc_preauth.c | 14 ++-- + src/kdc/kdc_util.c | 187 +++++++++++++++++++++++++------------------------- + src/kdc/kdc_util.h | 8 +-- + 4 files changed, 109 insertions(+), 128 deletions(-) + +diff --git a/src/kdc/fast_util.c b/src/kdc/fast_util.c +index e05107ef3..6a3fc11b9 100644 +--- a/src/kdc/fast_util.c ++++ b/src/kdc/fast_util.c +@@ -451,36 +451,12 @@ kdc_fast_hide_client(struct kdc_request_state *state) + return (state->fast_options & KRB5_FAST_OPTION_HIDE_CLIENT_NAMES) != 0; + } + +-/* Allocate a pa-data entry with an uninitialized buffer of size len. */ +-static krb5_error_code +-alloc_padata(krb5_preauthtype pa_type, size_t len, krb5_pa_data **out) +-{ +- krb5_pa_data *pa; +- uint8_t *buf; +- +- *out = NULL; +- buf = malloc(len); +- if (buf == NULL) +- return ENOMEM; +- pa = malloc(sizeof(*pa)); +- if (pa == NULL) { +- free(buf); +- return ENOMEM; +- } +- pa->magic = KV5M_PA_DATA; +- pa->pa_type = pa_type; +- pa->length = len; +- pa->contents = buf; +- *out = pa; +- return 0; +-} +- + /* Create a pa-data entry with the specified type and contents. */ + static krb5_error_code + make_padata(krb5_preauthtype pa_type, const void *contents, size_t len, + krb5_pa_data **out) + { +- if (alloc_padata(pa_type, len, out) != 0) ++ if (alloc_pa_data(pa_type, len, out) != 0) + return ENOMEM; + memcpy((*out)->contents, contents, len); + return 0; +@@ -720,7 +696,7 @@ kdc_fast_make_cookie(krb5_context context, struct kdc_request_state *state, + goto cleanup; + + /* Construct the cookie pa-data entry. */ +- ret = alloc_padata(KRB5_PADATA_FX_COOKIE, 8 + enc.ciphertext.length, &pa); ++ ret = alloc_pa_data(KRB5_PADATA_FX_COOKIE, 8 + enc.ciphertext.length, &pa); + memcpy(pa->contents, "MIT1", 4); + store_32_be(kvno, pa->contents + 4); + memcpy(pa->contents + 8, enc.ciphertext.data, enc.ciphertext.length); +diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c +index 739c5e776..edc30bd83 100644 +--- a/src/kdc/kdc_preauth.c ++++ b/src/kdc/kdc_preauth.c +@@ -1617,18 +1617,20 @@ return_referral_enc_padata( krb5_context context, + { + krb5_error_code code; + krb5_tl_data tl_data; +- krb5_pa_data pa_data; ++ krb5_pa_data *pa; + + tl_data.tl_data_type = KRB5_TL_SVR_REFERRAL_DATA; + code = krb5_dbe_lookup_tl_data(context, server, &tl_data); + if (code || tl_data.tl_data_length == 0) + return 0; + +- pa_data.magic = KV5M_PA_DATA; +- pa_data.pa_type = KRB5_PADATA_SVR_REFERRAL_INFO; +- pa_data.length = tl_data.tl_data_length; +- pa_data.contents = tl_data.tl_data_contents; +- return add_pa_data_element(context, &pa_data, &reply->enc_padata, TRUE); ++ code = alloc_pa_data(KRB5_PADATA_SVR_REFERRAL_INFO, tl_data.tl_data_length, ++ &pa); ++ if (code) ++ return code; ++ memcpy(pa->contents, tl_data.tl_data_contents, tl_data.tl_data_length); ++ /* add_pa_data_element() claims pa on success or failure. */ ++ return add_pa_data_element(&reply->enc_padata, pa); + } + + krb5_error_code +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index 754570c01..13111215d 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1353,9 +1353,9 @@ kdc_make_s4u2self_rep(krb5_context context, + krb5_enc_kdc_rep_part *reply_encpart) + { + krb5_error_code code; +- krb5_data *data = NULL; ++ krb5_data *der_user_id = NULL, *der_s4u_x509_user = NULL; + krb5_pa_s4u_x509_user rep_s4u_user; +- krb5_pa_data padata; ++ krb5_pa_data *pa; + krb5_enctype enctype; + krb5_keyusage usage; + +@@ -1366,7 +1366,7 @@ kdc_make_s4u2self_rep(krb5_context context, + rep_s4u_user.user_id.options = + req_s4u_user->user_id.options & KRB5_S4U_OPTS_USE_REPLY_KEY_USAGE; + +- code = encode_krb5_s4u_userid(&rep_s4u_user.user_id, &data); ++ code = encode_krb5_s4u_userid(&rep_s4u_user.user_id, &der_user_id); + if (code != 0) + goto cleanup; + +@@ -1377,29 +1377,25 @@ kdc_make_s4u2self_rep(krb5_context context, + + code = krb5_c_make_checksum(context, req_s4u_user->cksum.checksum_type, + tgs_subkey != NULL ? tgs_subkey : tgs_session, +- usage, data, +- &rep_s4u_user.cksum); ++ usage, der_user_id, &rep_s4u_user.cksum); + if (code != 0) + goto cleanup; + +- krb5_free_data(context, data); +- data = NULL; +- +- code = encode_krb5_pa_s4u_x509_user(&rep_s4u_user, &data); ++ code = encode_krb5_pa_s4u_x509_user(&rep_s4u_user, &der_s4u_x509_user); + if (code != 0) + goto cleanup; + +- padata.magic = KV5M_PA_DATA; +- padata.pa_type = KRB5_PADATA_S4U_X509_USER; +- padata.length = data->length; +- padata.contents = (krb5_octet *)data->data; +- +- code = add_pa_data_element(context, &padata, &reply->padata, FALSE); ++ /* Add a padata element, stealing memory from der_s4u_x509_user. */ ++ code = alloc_pa_data(KRB5_PADATA_S4U_X509_USER, 0, &pa); ++ if (code != 0) ++ goto cleanup; ++ pa->length = der_s4u_x509_user->length; ++ pa->contents = (uint8_t *)der_s4u_x509_user->data; ++ der_s4u_x509_user->data = NULL; ++ /* add_pa_data_element() claims pa on success or failure. */ ++ code = add_pa_data_element(&reply->padata, pa); + if (code != 0) + goto cleanup; +- +- free(data); +- data = NULL; + + if (tgs_subkey != NULL) + enctype = tgs_subkey->enctype; +@@ -1413,33 +1409,27 @@ kdc_make_s4u2self_rep(krb5_context context, + */ + if ((req_s4u_user->user_id.options & KRB5_S4U_OPTS_USE_REPLY_KEY_USAGE) && + enctype_requires_etype_info_2(enctype) == FALSE) { +- padata.length = req_s4u_user->cksum.length + +- rep_s4u_user.cksum.length; +- padata.contents = malloc(padata.length); +- if (padata.contents == NULL) { +- code = ENOMEM; ++ code = alloc_pa_data(KRB5_PADATA_S4U_X509_USER, ++ req_s4u_user->cksum.length + ++ rep_s4u_user.cksum.length, &pa); ++ if (code != 0) + goto cleanup; +- } ++ memcpy(pa->contents, ++ req_s4u_user->cksum.contents, req_s4u_user->cksum.length); ++ memcpy(&pa->contents[req_s4u_user->cksum.length], ++ rep_s4u_user.cksum.contents, rep_s4u_user.cksum.length); + +- memcpy(padata.contents, +- req_s4u_user->cksum.contents, +- req_s4u_user->cksum.length); +- memcpy(&padata.contents[req_s4u_user->cksum.length], +- rep_s4u_user.cksum.contents, +- rep_s4u_user.cksum.length); +- +- code = add_pa_data_element(context,&padata, +- &reply_encpart->enc_padata, FALSE); +- if (code != 0) { +- free(padata.contents); ++ /* add_pa_data_element() claims pa on success or failure. */ ++ code = add_pa_data_element(&reply_encpart->enc_padata, pa); ++ if (code != 0) + goto cleanup; +- } + } + + cleanup: + if (rep_s4u_user.cksum.contents != NULL) + krb5_free_checksum_contents(context, &rep_s4u_user.cksum); +- krb5_free_data(context, data); ++ krb5_free_data(context, der_user_id); ++ krb5_free_data(context, der_s4u_x509_user); + + return code; + } +@@ -1707,46 +1697,50 @@ enctype_requires_etype_info_2(krb5_enctype enctype) + } + } + +-/* XXX where are the generic helper routines for this? */ ++/* Allocate a pa-data entry with an uninitialized buffer of size len. */ + krb5_error_code +-add_pa_data_element(krb5_context context, +- krb5_pa_data *padata, +- krb5_pa_data ***inout_padata, +- krb5_boolean copy) ++alloc_pa_data(krb5_preauthtype pa_type, size_t len, krb5_pa_data **out) + { +- int i; +- krb5_pa_data **p; ++ krb5_pa_data *pa; ++ uint8_t *buf = NULL; + +- if (*inout_padata != NULL) { +- for (i = 0; (*inout_padata)[i] != NULL; i++) +- ; +- } else +- i = 0; +- +- p = realloc(*inout_padata, (i + 2) * sizeof(krb5_pa_data *)); +- if (p == NULL) +- return ENOMEM; +- +- *inout_padata = p; +- +- p[i] = (krb5_pa_data *)malloc(sizeof(krb5_pa_data)); +- if (p[i] == NULL) +- return ENOMEM; +- *(p[i]) = *padata; +- +- p[i + 1] = NULL; +- +- if (copy) { +- p[i]->contents = (krb5_octet *)malloc(padata->length); +- if (p[i]->contents == NULL) { +- free(p[i]); +- p[i] = NULL; ++ *out = NULL; ++ if (len > 0) { ++ buf = malloc(len); ++ if (buf == NULL) + return ENOMEM; +- } +- +- memcpy(p[i]->contents, padata->contents, padata->length); + } ++ pa = malloc(sizeof(*pa)); ++ if (pa == NULL) { ++ free(buf); ++ return ENOMEM; ++ } ++ pa->magic = KV5M_PA_DATA; ++ pa->pa_type = pa_type; ++ pa->length = len; ++ pa->contents = buf; ++ *out = pa; ++ return 0; ++} + ++/* Add pa to list, claiming its memory. Free pa on failure. */ ++krb5_error_code ++add_pa_data_element(krb5_pa_data ***list, krb5_pa_data *pa) ++{ ++ size_t count; ++ krb5_pa_data **newlist; ++ ++ for (count = 0; *list != NULL && (*list)[count] != NULL; count++); ++ ++ newlist = realloc(*list, (count + 2) * sizeof(*newlist)); ++ if (newlist == NULL) { ++ free(pa->contents); ++ free(pa); ++ return ENOMEM; ++ } ++ newlist[count] = pa; ++ newlist[count + 1] = NULL; ++ *list = newlist; + return 0; + } + +@@ -1850,38 +1844,47 @@ kdc_handle_protected_negotiation(krb5_context context, + { + krb5_error_code retval = 0; + krb5_checksum checksum; +- krb5_data *out = NULL; +- krb5_pa_data pa, *pa_in; ++ krb5_data *der_cksum = NULL; ++ krb5_pa_data *pa, *pa_in; ++ ++ memset(&checksum, 0, sizeof(checksum)); ++ + pa_in = krb5int_find_pa_data(context, request->padata, + KRB5_ENCPADATA_REQ_ENC_PA_REP); + if (pa_in == NULL) + return 0; +- pa.magic = KV5M_PA_DATA; +- pa.pa_type = KRB5_ENCPADATA_REQ_ENC_PA_REP; +- memset(&checksum, 0, sizeof(checksum)); +- retval = krb5_c_make_checksum(context,0, reply_key, +- KRB5_KEYUSAGE_AS_REQ, req_pkt, &checksum); ++ ++ /* Compute and encode a checksum over the AS-REQ. */ ++ retval = krb5_c_make_checksum(context, 0, reply_key, KRB5_KEYUSAGE_AS_REQ, ++ req_pkt, &checksum); + if (retval != 0) + goto cleanup; +- retval = encode_krb5_checksum(&checksum, &out); ++ retval = encode_krb5_checksum(&checksum, &der_cksum); + if (retval != 0) + goto cleanup; +- pa.contents = (krb5_octet *) out->data; +- pa.length = out->length; +- retval = add_pa_data_element(context, &pa, out_enc_padata, FALSE); ++ ++ /* Add a pa-data element to the list, stealing memory from der_cksum. */ ++ retval = alloc_pa_data(KRB5_ENCPADATA_REQ_ENC_PA_REP, 0, &pa); + if (retval) + goto cleanup; +- out->data = NULL; +- pa.magic = KV5M_PA_DATA; +- pa.pa_type = KRB5_PADATA_FX_FAST; +- pa.length = 0; +- pa.contents = NULL; +- retval = add_pa_data_element(context, &pa, out_enc_padata, FALSE); ++ pa->length = der_cksum->length; ++ pa->contents = (uint8_t *)der_cksum->data; ++ der_cksum->data = NULL; ++ /* add_pa_data_element() claims pa on success or failure. */ ++ retval = add_pa_data_element(out_enc_padata, pa); ++ if (retval) ++ goto cleanup; ++ ++ /* Add a zero-length PA-FX-FAST element to the list. */ ++ retval = alloc_pa_data(KRB5_PADATA_FX_FAST, 0, &pa); ++ if (retval) ++ goto cleanup; ++ /* add_pa_data_element() claims pa on success or failure. */ ++ retval = add_pa_data_element(out_enc_padata, pa); ++ + cleanup: +- if (checksum.contents) +- krb5_free_checksum_contents(context, &checksum); +- if (out != NULL) +- krb5_free_data(context, out); ++ krb5_free_checksum_contents(context, &checksum); ++ krb5_free_data(context, der_cksum); + return retval; + } + +diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h +index f99efcf50..18649b8ad 100644 +--- a/src/kdc/kdc_util.h ++++ b/src/kdc/kdc_util.h +@@ -203,10 +203,10 @@ void + free_padata_context(krb5_context context, void *padata_context); + + krb5_error_code +-add_pa_data_element (krb5_context context, +- krb5_pa_data *padata, +- krb5_pa_data ***out_padata, +- krb5_boolean copy); ++alloc_pa_data(krb5_preauthtype pa_type, size_t len, krb5_pa_data **out); ++ ++krb5_error_code ++add_pa_data_element(krb5_pa_data ***list, krb5_pa_data *pa); + + /* kdc_preauth_ec.c */ + krb5_error_code diff --git a/Simplify-kdc_preauth.c-systems-table.patch b/Simplify-kdc_preauth.c-systems-table.patch new file mode 100644 index 0000000..fad6fc4 --- /dev/null +++ b/Simplify-kdc_preauth.c-systems-table.patch @@ -0,0 +1,738 @@ +From 0afb9c336dd8573faa025915fcb97e643cc3e748 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sun, 11 Feb 2018 15:23:35 -0500 +Subject: [PATCH] Simplify kdc_preauth.c systems table + +Get rid of static_preauth_systems, and replace it with explicit calls +to helper functions in get_preauth_hint_list() and return_padata(). +Stop preallocating pa-data lists, instead reallocating on each +addition using add_pa_data_element(). Also simplify +maybe_add_etype_info2() using add_pa_data_element(). + +The KRB5_PADATA_PAC_REQUEST table entry did nothing, and was probably +originally added back when the KDC would error out on unrecognized +padata types. The KRB5_PADATA_SERVER_REFERRAL entry has been disabled +since it was first added. + +(cherry picked from commit fea1a488924faa3938ef723feaa1ff12d22a91ff) +--- + src/kdc/kdc_preauth.c | 526 ++++++++++++++++++-------------------------------- + 1 file changed, 184 insertions(+), 342 deletions(-) + +diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c +index edc30bd83..6f34dc289 100644 +--- a/src/kdc/kdc_preauth.c ++++ b/src/kdc/kdc_preauth.c +@@ -101,108 +101,14 @@ typedef struct preauth_system_st { + krb5_kdcpreauth_loop_fn loop; + } preauth_system; + ++static preauth_system *preauth_systems; ++static size_t n_preauth_systems; ++ + static krb5_error_code + make_etype_info(krb5_context context, krb5_preauthtype pa_type, + krb5_principal client, krb5_key_data *client_key, + krb5_enctype enctype, krb5_pa_data **pa_out); + +-static void +-get_etype_info(krb5_context context, krb5_kdc_req *request, +- krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, +- krb5_kdcpreauth_moddata moddata, krb5_preauthtype pa_type, +- krb5_kdcpreauth_edata_respond_fn respond, void *arg); +- +-static krb5_error_code +-return_etype_info(krb5_context, krb5_pa_data *padata, +- krb5_data *req_pkt, krb5_kdc_req *request, +- krb5_kdc_rep *reply, krb5_keyblock *encrypting_key, +- krb5_pa_data **send_pa, krb5_kdcpreauth_callbacks cb, +- krb5_kdcpreauth_rock rock, krb5_kdcpreauth_moddata moddata, +- krb5_kdcpreauth_modreq modreq); +- +-static krb5_error_code +-return_pw_salt(krb5_context, krb5_pa_data *padata, +- krb5_data *req_pkt, krb5_kdc_req *request, krb5_kdc_rep *reply, +- krb5_keyblock *encrypting_key, krb5_pa_data **send_pa, +- krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, +- krb5_kdcpreauth_moddata moddata, krb5_kdcpreauth_modreq modreq); +- +- +- +-static preauth_system static_preauth_systems[] = { +- { +- "FAST", +- KRB5_PADATA_FX_FAST, +- PA_HARDWARE, +- NULL, +- NULL, +- NULL, +- NULL, +- NULL, +- 0 +- }, +- { +- "etype-info", +- KRB5_PADATA_ETYPE_INFO, +- PA_HARDWARE, +- NULL, +- NULL, +- NULL, +- get_etype_info, +- 0, +- return_etype_info +- }, +- { +- "etype-info2", +- KRB5_PADATA_ETYPE_INFO2, +- PA_HARDWARE, +- NULL, +- NULL, +- NULL, +- get_etype_info, +- 0, +- return_etype_info +- }, +- { +- "pw-salt", +- KRB5_PADATA_PW_SALT, +- PA_PSEUDO, /* Don't include this in the error list */ +- NULL, +- NULL, +- NULL, +- 0, +- 0, +- return_pw_salt +- }, +- { +- "pac-request", +- KRB5_PADATA_PAC_REQUEST, +- PA_PSEUDO, +- NULL, +- NULL, +- NULL, +- NULL, +- NULL, +- NULL +- }, +-#if 0 +- { +- "server-referral", +- KRB5_PADATA_SERVER_REFERRAL, +- PA_PSEUDO, +- 0, +- 0, +- return_server_referral +- }, +-#endif +-}; +- +-#define NUM_STATIC_PREAUTH_SYSTEMS (sizeof(static_preauth_systems) / \ +- sizeof(*static_preauth_systems)) +- +-static preauth_system *preauth_systems; +-static size_t n_preauth_systems; +- + /* Get all available kdcpreauth vtables and a count of preauth types they + * support. Return an empty list on failure. */ + static void +@@ -284,7 +190,6 @@ load_preauth_plugins(struct server_handle *handle, krb5_context context, + get_plugin_vtables(context, &vtables, &n_tables, &n_systems); + + /* Allocate the list of static and plugin preauth systems. */ +- n_systems += NUM_STATIC_PREAUTH_SYSTEMS; + preauth_systems = calloc(n_systems + 1, sizeof(preauth_system)); + if (preauth_systems == NULL) + goto cleanup; +@@ -292,13 +197,8 @@ load_preauth_plugins(struct server_handle *handle, krb5_context context, + if (get_realm_names(handle, &realm_names)) + goto cleanup; + +- /* Add the static system to the list first. No static systems require +- * initialization, so just make a direct copy. */ +- memcpy(preauth_systems, static_preauth_systems, +- sizeof(static_preauth_systems)); +- + /* Add the dynamically-loaded mechanisms to the list. */ +- n_systems = NUM_STATIC_PREAUTH_SYSTEMS; ++ n_systems = 0; + for (i = 0; i < n_tables; i++) { + /* Try to initialize this module. */ + vt = &vtables[i]; +@@ -622,7 +522,9 @@ find_pa_system(int type, preauth_system **preauth) + { + preauth_system *ap; + +- ap = preauth_systems ? preauth_systems : static_preauth_systems; ++ if (preauth_systems == NULL) ++ return KRB5_PREAUTH_BAD_TYPE; ++ ap = preauth_systems; + while ((ap->type != -1) && (ap->type != type)) + ap++; + if (ap->type == -1) +@@ -776,6 +678,98 @@ const char *missing_required_preauth(krb5_db_entry *client, + return 0; + } + ++/* Return true if request's enctypes indicate support for etype-info2. */ ++static krb5_boolean ++requires_info2(const krb5_kdc_req *request) ++{ ++ int i; ++ ++ for (i = 0; i < request->nktypes; i++) { ++ if (enctype_requires_etype_info_2(request->ktype[i])) ++ return TRUE; ++ } ++ return FALSE; ++} ++ ++/* Add PA-ETYPE-INFO2 and possibly PA-ETYPE-INFO entries to pa_list as ++ * appropriate for the request and client principal. */ ++static krb5_error_code ++add_etype_info(krb5_context context, krb5_kdcpreauth_rock rock, ++ krb5_pa_data ***pa_list) ++{ ++ krb5_error_code ret; ++ krb5_pa_data *pa; ++ ++ if (rock->client_key == NULL) ++ return 0; ++ ++ if (!requires_info2(rock->request)) { ++ /* Include PA-ETYPE-INFO only for old clients. */ ++ ret = make_etype_info(context, KRB5_PADATA_ETYPE_INFO, ++ rock->client->princ, rock->client_key, ++ rock->client_keyblock->enctype, &pa); ++ if (ret) ++ return ret; ++ /* add_pa_data_element() claims pa on success or failure. */ ++ ret = add_pa_data_element(pa_list, pa); ++ if (ret) ++ return ret; ++ } ++ ++ /* Always include PA-ETYPE-INFO2. */ ++ ret = make_etype_info(context, KRB5_PADATA_ETYPE_INFO2, ++ rock->client->princ, rock->client_key, ++ rock->client_keyblock->enctype, &pa); ++ if (ret) ++ return ret; ++ /* add_pa_data_element() claims pa on success or failure. */ ++ return add_pa_data_element(pa_list, pa); ++} ++ ++/* Add PW-SALT or AFS3-SALT entries to pa_list as appropriate for the request ++ * and client principal. */ ++static krb5_error_code ++add_pw_salt(krb5_context context, krb5_kdcpreauth_rock rock, ++ krb5_pa_data ***pa_list) ++{ ++ krb5_error_code ret; ++ krb5_pa_data *pa; ++ krb5_data *salt = NULL; ++ krb5_int16 salttype; ++ ++ /* Only include this pa-data for old clients. */ ++ if (rock->client_key == NULL || requires_info2(rock->request)) ++ return 0; ++ ++ ret = krb5_dbe_compute_salt(context, rock->client_key, ++ rock->request->client, &salttype, &salt); ++ if (ret) ++ return 0; ++ ++ if (salttype == KRB5_KDB_SALTTYPE_AFS3) { ++ ret = alloc_pa_data(KRB5_PADATA_AFS3_SALT, salt->length + 1, &pa); ++ if (ret) ++ goto cleanup; ++ memcpy(pa->contents, salt->data, salt->length); ++ pa->contents[salt->length] = '\0'; ++ } else { ++ /* Steal memory from salt to make the pa-data entry. */ ++ ret = alloc_pa_data(KRB5_PADATA_PW_SALT, 0, &pa); ++ if (ret) ++ goto cleanup; ++ pa->length = salt->length; ++ pa->contents = (uint8_t *)salt->data; ++ salt->data = NULL; ++ } ++ ++ /* add_pa_data_element() claims pa on success or failure. */ ++ ret = add_pa_data_element(pa_list, pa); ++ ++cleanup: ++ krb5_free_data(context, salt); ++ return ret; ++} ++ + struct hint_state { + kdc_hint_respond_fn respond; + void *arg; +@@ -787,7 +781,7 @@ struct hint_state { + + int hw_only; + preauth_system *ap; +- krb5_pa_data **pa_data, **pa_cur; ++ krb5_pa_data **pa_data; + krb5_preauthtype pa_type; + }; + +@@ -799,7 +793,7 @@ hint_list_finish(struct hint_state *state, krb5_error_code code) + kdc_realm_t *kdc_active_realm = state->realm; + + if (!code) { +- if (state->pa_data[0] == 0) { ++ if (state->pa_data == NULL) { + krb5_klog_syslog(LOG_INFO, + _("%spreauth required but hint list is empty"), + state->hw_only ? "hw" : ""); +@@ -820,20 +814,27 @@ hint_list_next(struct hint_state *arg); + static void + finish_get_edata(void *arg, krb5_error_code code, krb5_pa_data *pa) + { ++ krb5_error_code ret; + struct hint_state *state = arg; + + if (code == 0) { + if (pa == NULL) { +- /* Include an empty value of the current type. */ +- pa = calloc(1, sizeof(*pa)); +- pa->magic = KV5M_PA_DATA; +- pa->pa_type = state->pa_type; ++ ret = alloc_pa_data(state->pa_type, 0, &pa); ++ if (ret) ++ goto error; + } +- *state->pa_cur++ = pa; ++ /* add_pa_data_element() claims pa on success or failure. */ ++ ret = add_pa_data_element(&state->pa_data, pa); ++ if (ret) ++ goto error; + } + + state->ap++; + hint_list_next(state); ++ return; ++ ++error: ++ hint_list_finish(state, ret); + } + + static void +@@ -870,16 +871,16 @@ get_preauth_hint_list(krb5_kdc_req *request, krb5_kdcpreauth_rock rock, + krb5_pa_data ***e_data_out, kdc_hint_respond_fn respond, + void *arg) + { ++ kdc_realm_t *kdc_active_realm = rock->rstate->realm_data; + struct hint_state *state; ++ krb5_pa_data *pa; + + *e_data_out = NULL; + + /* Allocate our state. */ + state = calloc(1, sizeof(*state)); +- if (state == NULL) { +- (*respond)(arg); +- return; +- } ++ if (state == NULL) ++ goto error; + state->hw_only = isflagset(rock->client->attributes, + KRB5_KDB_REQUIRES_HW_AUTH); + state->respond = respond; +@@ -888,17 +889,27 @@ get_preauth_hint_list(krb5_kdc_req *request, krb5_kdcpreauth_rock rock, + state->rock = rock; + state->realm = rock->rstate->realm_data; + state->e_data_out = e_data_out; +- +- state->pa_data = calloc(n_preauth_systems + 1, sizeof(krb5_pa_data *)); +- if (!state->pa_data) { +- free(state); +- (*respond)(arg); +- return; +- } +- +- state->pa_cur = state->pa_data; ++ state->pa_data = NULL; + state->ap = preauth_systems; ++ ++ /* Add an empty PA-FX-FAST element to advertise FAST support. */ ++ if (alloc_pa_data(KRB5_PADATA_FX_FAST, 0, &pa) != 0) ++ goto error; ++ /* add_pa_data_element() claims pa on success or failure. */ ++ if (add_pa_data_element(&state->pa_data, pa) != 0) ++ goto error; ++ ++ if (add_etype_info(kdc_context, rock, &state->pa_data) != 0) ++ goto error; ++ + hint_list_next(state); ++ return; ++ ++error: ++ if (state != NULL) ++ krb5_free_pa_data(kdc_context, state->pa_data); ++ free(state); ++ (*respond)(arg); + } + + /* +@@ -1029,10 +1040,10 @@ filter_preauth_error(krb5_error_code code) + static krb5_error_code + maybe_add_etype_info2(struct padata_state *state, krb5_error_code code) + { ++ krb5_error_code ret; + krb5_context context = state->context; + krb5_kdcpreauth_rock rock = state->rock; +- krb5_pa_data **list = state->pa_e_data; +- size_t count; ++ krb5_pa_data *pa; + + /* Only add key information when requesting another preauth round trip. */ + if (code != KRB5KDC_ERR_MORE_PREAUTH_DATA_REQUIRED) +@@ -1048,18 +1059,14 @@ maybe_add_etype_info2(struct padata_state *state, krb5_error_code code) + KRB5_PADATA_FX_COOKIE) != NULL) + return 0; + +- /* Reallocate state->pa_e_data to make room for the etype-info2 element. */ +- for (count = 0; list != NULL && list[count] != NULL; count++); +- list = realloc(list, (count + 2) * sizeof(*list)); +- if (list == NULL) +- return ENOMEM; +- list[count] = list[count + 1] = NULL; +- state->pa_e_data = list; ++ ret = make_etype_info(context, KRB5_PADATA_ETYPE_INFO2, ++ rock->client->princ, rock->client_key, ++ rock->client_keyblock->enctype, &pa); ++ if (ret) ++ return ret; + +- /* Generate an etype-info2 element in the new slot. */ +- return make_etype_info(context, KRB5_PADATA_ETYPE_INFO2, +- rock->client->princ, rock->client_key, +- rock->client_keyblock->enctype, &list[count]); ++ /* add_pa_data_element() claims pa on success or failure. */ ++ return add_pa_data_element(&state->pa_e_data, pa); + } + + /* Release state and respond to the AS-REQ processing code with the result of +@@ -1279,17 +1286,20 @@ return_padata(krb5_context context, krb5_kdcpreauth_rock rock, + { + krb5_error_code retval; + krb5_pa_data ** padata; +- krb5_pa_data ** send_pa_list; +- krb5_pa_data ** send_pa; ++ krb5_pa_data ** send_pa_list = NULL; ++ krb5_pa_data * send_pa; + krb5_pa_data * pa = 0; + krb5_pa_data null_item; + preauth_system * ap; +- int * pa_order; ++ int * pa_order = NULL; + int * pa_type; + int size = 0; + krb5_kdcpreauth_modreq *modreq_ptr; + krb5_boolean key_modified; + krb5_keyblock original_key; ++ ++ memset(&original_key, 0, sizeof(original_key)); ++ + if ((!*padata_context) && + (make_padata_context(context, padata_context) != 0)) { + return KRB5KRB_ERR_GENERIC; +@@ -1300,26 +1310,18 @@ return_padata(krb5_context context, krb5_kdcpreauth_rock rock, + size++; + } + +- if ((send_pa_list = malloc((size+1) * sizeof(krb5_pa_data *))) == NULL) +- return ENOMEM; +- if ((pa_order = malloc((size+1) * sizeof(int))) == NULL) { +- free(send_pa_list); +- return ENOMEM; +- } ++ pa_order = k5calloc(size + 1, sizeof(int), &retval); ++ if (pa_order == NULL) ++ goto cleanup; + sort_pa_order(context, request, pa_order); + + retval = krb5_copy_keyblock_contents(context, encrypting_key, + &original_key); +- if (retval) { +- free(send_pa_list); +- free(pa_order); +- return retval; +- } ++ if (retval) ++ goto cleanup; + key_modified = FALSE; + null_item.contents = NULL; + null_item.length = 0; +- send_pa = send_pa_list; +- *send_pa = 0; + + for (pa_type = pa_order; *pa_type != -1; pa_type++) { + ap = &preauth_systems[*pa_type]; +@@ -1349,20 +1351,30 @@ return_padata(krb5_context context, krb5_kdcpreauth_rock rock, + } + } + } ++ send_pa = NULL; + retval = ap->return_padata(context, pa, req_pkt, request, reply, +- encrypting_key, send_pa, &callbacks, rock, ++ encrypting_key, &send_pa, &callbacks, rock, + ap->moddata, *modreq_ptr); + if (retval) + goto cleanup; + +- if (*send_pa) +- send_pa++; +- *send_pa = 0; ++ if (send_pa != NULL) { ++ /* add_pa_data_element() claims send_pa on success or failure. */ ++ retval = add_pa_data_element(&send_pa_list, send_pa); ++ if (retval) ++ goto cleanup; ++ } + } + +- retval = 0; ++ /* Add etype-info and pw-salt pa-data as needed. */ ++ retval = add_etype_info(context, rock, &send_pa_list); ++ if (retval) ++ goto cleanup; ++ retval = add_pw_salt(context, rock, &send_pa_list); ++ if (retval) ++ goto cleanup; + +- if (send_pa_list[0]) { ++ if (send_pa_list != NULL) { + reply->padata = send_pa_list; + send_pa_list = 0; + } +@@ -1370,8 +1382,7 @@ return_padata(krb5_context context, krb5_kdcpreauth_rock rock, + cleanup: + krb5_free_keyblock_contents(context, &original_key); + free(pa_order); +- if (send_pa_list) +- krb5_free_pa_data(context, send_pa_list); ++ krb5_free_pa_data(context, send_pa_list); + + return (retval); + } +@@ -1438,9 +1449,8 @@ make_etype_info(krb5_context context, krb5_preauthtype pa_type, + krb5_enctype enctype, krb5_pa_data **pa_out) + { + krb5_error_code retval; +- krb5_pa_data *pa = NULL; + krb5_etype_info_entry **entry = NULL; +- krb5_data *scratch = NULL; ++ krb5_data *der_etype_info = NULL; + int etype_info2 = (pa_type == KRB5_PADATA_ETYPE_INFO2); + + *pa_out = NULL; +@@ -1454,125 +1464,23 @@ make_etype_info(krb5_context context, krb5_preauthtype pa_type, + goto cleanup; + + if (etype_info2) +- retval = encode_krb5_etype_info2(entry, &scratch); ++ retval = encode_krb5_etype_info2(entry, &der_etype_info); + else +- retval = encode_krb5_etype_info(entry, &scratch); ++ retval = encode_krb5_etype_info(entry, &der_etype_info); + if (retval) + goto cleanup; +- pa = k5alloc(sizeof(*pa), &retval); +- if (pa == NULL) ++ ++ /* Steal the data from der_etype_info to create a pa-data element. */ ++ retval = alloc_pa_data(pa_type, 0, pa_out); ++ if (retval) + goto cleanup; +- pa->magic = KV5M_PA_DATA; +- pa->pa_type = pa_type; +- pa->contents = (unsigned char *)scratch->data; +- pa->length = scratch->length; +- scratch->data = NULL; +- *pa_out = pa; ++ (*pa_out)->contents = (uint8_t *)der_etype_info->data; ++ (*pa_out)->length = der_etype_info->length; ++ der_etype_info->data = NULL; + + cleanup: + krb5_free_etype_info(context, entry); +- krb5_free_data(context, scratch); +- return retval; +-} +- +-/* Return true if request's enctypes indicate support for etype-info2. */ +-static krb5_boolean +-requires_info2(const krb5_kdc_req *request) +-{ +- int i; +- +- for (i = 0; i < request->nktypes; i++) { +- if (enctype_requires_etype_info_2(request->ktype[i])) +- return TRUE; +- } +- return FALSE; +-} +- +-/* Generate hint list padata for PA-ETYPE-INFO or PA-ETYPE-INFO2. */ +-static void +-get_etype_info(krb5_context context, krb5_kdc_req *request, +- krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, +- krb5_kdcpreauth_moddata moddata, krb5_preauthtype pa_type, +- krb5_kdcpreauth_edata_respond_fn respond, void *arg) +-{ +- krb5_error_code ret; +- krb5_pa_data *pa = NULL; +- +- if (rock->client_key == NULL) { +- ret = KRB5KDC_ERR_PADATA_TYPE_NOSUPP; +- } else if (pa_type == KRB5_PADATA_ETYPE_INFO && requires_info2(request)) { +- ret = KRB5KDC_ERR_PADATA_TYPE_NOSUPP; +- } else { +- ret = make_etype_info(context, pa_type, rock->client->princ, +- rock->client_key, rock->client_keyblock->enctype, +- &pa); +- } +- (*respond)(arg, ret, pa); +-} +- +-/* Generate AS-REP padata for PA-ETYPE-INFO or PA-ETYPE-INFO2. */ +-static krb5_error_code +-return_etype_info(krb5_context context, krb5_pa_data *padata, +- krb5_data *req_pkt, krb5_kdc_req *request, +- krb5_kdc_rep *reply, krb5_keyblock *encrypting_key, +- krb5_pa_data **send_pa, krb5_kdcpreauth_callbacks cb, +- krb5_kdcpreauth_rock rock, krb5_kdcpreauth_moddata moddata, +- krb5_kdcpreauth_modreq modreq) +-{ +- *send_pa = NULL; +- if (rock->client_key == NULL) +- return 0; +- if (padata->pa_type == KRB5_PADATA_ETYPE_INFO && requires_info2(request)) +- return 0; +- return make_etype_info(context, padata->pa_type, rock->client->princ, +- rock->client_key, encrypting_key->enctype, send_pa); +-} +- +-static krb5_error_code +-return_pw_salt(krb5_context context, krb5_pa_data *in_padata, +- krb5_data *req_pkt, krb5_kdc_req *request, krb5_kdc_rep *reply, +- krb5_keyblock *encrypting_key, krb5_pa_data **send_pa, +- krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, +- krb5_kdcpreauth_moddata moddata, krb5_kdcpreauth_modreq modreq) +-{ +- krb5_error_code retval; +- krb5_pa_data * padata; +- krb5_data * salt = NULL; +- krb5_int16 salttype; +- krb5_key_data * client_key = rock->client_key; +- +- if (client_key == NULL || requires_info2(request)) +- return 0; +- +- retval = krb5_dbe_compute_salt(context, client_key, request->client, +- &salttype, &salt); +- if (retval) +- return 0; +- +- padata = k5alloc(sizeof(*padata), &retval); +- if (padata == NULL) +- goto cleanup; +- padata->magic = KV5M_PA_DATA; +- +- if (salttype == KRB5_KDB_SALTTYPE_AFS3) { +- padata->contents = k5memdup0(salt->data, salt->length, &retval); +- if (padata->contents == NULL) +- goto cleanup; +- padata->pa_type = KRB5_PADATA_AFS3_SALT; +- padata->length = salt->length + 1; +- } else { +- padata->pa_type = KRB5_PADATA_PW_SALT; +- padata->length = salt->length; +- padata->contents = (krb5_octet *)salt->data; +- salt->data = NULL; +- } +- +- *send_pa = padata; +- padata = NULL; +- +-cleanup: +- free(padata); +- krb5_free_data(context, salt); ++ krb5_free_data(context, der_etype_info); + return retval; + } + +@@ -1656,69 +1564,3 @@ return_enc_padata(krb5_context context, krb5_data *req_pkt, + cleanup: + return code; + } +- +- +-#if 0 +-static krb5_error_code return_server_referral(krb5_context context, +- krb5_pa_data * padata, +- krb5_db_entry *client, +- krb5_db_entry *server, +- krb5_kdc_req *request, +- krb5_kdc_rep *reply, +- krb5_key_data *client_key, +- krb5_keyblock *encrypting_key, +- krb5_pa_data **send_pa) +-{ +- krb5_error_code code; +- krb5_tl_data tl_data; +- krb5_pa_data *pa_data; +- krb5_enc_data enc_data; +- krb5_data plain; +- krb5_data *enc_pa_data; +- +- *send_pa = NULL; +- +- tl_data.tl_data_type = KRB5_TL_SERVER_REFERRAL; +- +- code = krb5_dbe_lookup_tl_data(context, server, &tl_data); +- if (code || tl_data.tl_data_length == 0) +- return 0; /* no server referrals to return */ +- +- plain.length = tl_data.tl_data_length; +- plain.data = tl_data.tl_data_contents; +- +- /* Encrypt ServerReferralData */ +- code = krb5_encrypt_helper(context, encrypting_key, +- KRB5_KEYUSAGE_PA_SERVER_REFERRAL_DATA, +- &plain, &enc_data); +- if (code) +- return code; +- +- /* Encode ServerReferralData into PA-SERVER-REFERRAL-DATA */ +- code = encode_krb5_enc_data(&enc_data, &enc_pa_data); +- if (code) { +- krb5_free_data_contents(context, &enc_data.ciphertext); +- return code; +- } +- +- krb5_free_data_contents(context, &enc_data.ciphertext); +- +- /* Return PA-SERVER-REFERRAL-DATA */ +- pa_data = (krb5_pa_data *)malloc(sizeof(*pa_data)); +- if (pa_data == NULL) { +- krb5_free_data(context, enc_pa_data); +- return ENOMEM; +- } +- +- pa_data->magic = KV5M_PA_DATA; +- pa_data->pa_type = KRB5_PADATA_SVR_REFERRAL_INFO; +- pa_data->length = enc_pa_data->length; +- pa_data->contents = enc_pa_data->data; +- +- free(enc_pa_data); /* don't free contents */ +- +- *send_pa = pa_data; +- +- return 0; +-} +-#endif diff --git a/krb5.spec b/krb5.spec index 5ba26b7..105326d 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 10%{?dist} +Release: 11%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -65,6 +65,12 @@ Patch38: Fix-flaws-in-LDAP-DN-checking.patch Patch39: Fix-capaths-.-values-on-client.patch Patch40: Fix-hex-conversion-of-PKINIT-certid-strings.patch Patch41: Exit-with-status-0-from-kadmind.patch +Patch42: Include-etype-info-in-for-hardware-preauth-hints.patch +Patch43: Fix-securid_sam2-preauth-for-non-default-salt.patch +Patch44: Refactor-KDC-krb5_pa_data-utility-functions.patch +Patch45: Simplify-kdc_preauth.c-systems-table.patch +Patch46: Add-PKINIT-client-support-for-freshness-token.patch +Patch47: Add-PKINIT-KDC-support-for-freshness-token.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -714,6 +720,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Mar 19 2018 Robbie Harwood - 1.16-11 +- Add PKINIT KDC support for freshness token + * Wed Mar 14 2018 Robbie Harwood - 1.16-10 - Exit with status 0 from kadmind From 2eafc4d8aa9711086e763e77d6569162e7a725fd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 20 Mar 2018 11:20:09 -0400 Subject: [PATCH 026/304] Include preauth names in trace output where possible Also fix misc bugs --- ...dation-of-PACs-with-enterprise-names.patch | 49 ++ Fix-read-overflow-in-KDC-sort_pa_data.patch | 48 ++ ...uth-name-in-trace-output-if-possible.patch | 514 ++++++++++++++++++ Report-extended-errors-in-kinit-k-t-KDB.patch | 27 + krb5.spec | 10 +- 5 files changed, 647 insertions(+), 1 deletion(-) create mode 100644 Allow-validation-of-PACs-with-enterprise-names.patch create mode 100644 Fix-read-overflow-in-KDC-sort_pa_data.patch create mode 100644 Include-preauth-name-in-trace-output-if-possible.patch create mode 100644 Report-extended-errors-in-kinit-k-t-KDB.patch diff --git a/Allow-validation-of-PACs-with-enterprise-names.patch b/Allow-validation-of-PACs-with-enterprise-names.patch new file mode 100644 index 0000000..b8492f5 --- /dev/null +++ b/Allow-validation-of-PACs-with-enterprise-names.patch @@ -0,0 +1,49 @@ +From 8a2ceda87107973ec10fec532c095cf347ec050c Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Wed, 14 Mar 2018 01:19:17 +0200 +Subject: [PATCH] Allow validation of PACs with enterprise names + +In k5_pac_validate_client(), if we are verifying against an enterprise +principal, parse the PAC_CLIENT_INFO field as an enterprise principal. +This scenario may arise in the response to an S4U2Self request for an +enterprise principal, as the KDC does not appear to canonicalize the +client principal requested in PA-FOR-USER. + +[ghudson@mit.edu: rewrote commit message; adjusted style] + +ticket: 8649 (new) +tags: pullup +target_version: 1.16-next + +(cherry picked from commit f876aab80a69f9b934cd7f4e2339e3815aa8c4bf) +--- + src/lib/krb5/krb/pac.c | 9 +++++++-- + 1 file changed, 7 insertions(+), 2 deletions(-) + +diff --git a/src/lib/krb5/krb/pac.c b/src/lib/krb5/krb/pac.c +index 0eb19e6bb..c9b5de30a 100644 +--- a/src/lib/krb5/krb/pac.c ++++ b/src/lib/krb5/krb/pac.c +@@ -413,6 +413,7 @@ k5_pac_validate_client(krb5_context context, + krb5_ui_2 pac_princname_length; + int64_t pac_nt_authtime; + krb5_principal pac_principal; ++ int flags; + + ret = k5_pac_locate_buffer(context, pac, KRB5_PAC_CLIENT_INFO, + &client_info); +@@ -440,8 +441,12 @@ k5_pac_validate_client(krb5_context context, + if (ret != 0) + return ret; + +- ret = krb5_parse_name_flags(context, pac_princname, +- KRB5_PRINCIPAL_PARSE_NO_REALM, &pac_principal); ++ /* Parse the UTF-8 name as an enterprise principal if we are matching ++ * against one; otherwise parse it as a regular principal with no realm. */ ++ flags = KRB5_PRINCIPAL_PARSE_NO_REALM; ++ if (principal->type == KRB5_NT_ENTERPRISE_PRINCIPAL) ++ flags |= KRB5_PRINCIPAL_PARSE_ENTERPRISE; ++ ret = krb5_parse_name_flags(context, pac_princname, flags, &pac_principal); + if (ret != 0) { + free(pac_princname); + return ret; diff --git a/Fix-read-overflow-in-KDC-sort_pa_data.patch b/Fix-read-overflow-in-KDC-sort_pa_data.patch new file mode 100644 index 0000000..709eac9 --- /dev/null +++ b/Fix-read-overflow-in-KDC-sort_pa_data.patch @@ -0,0 +1,48 @@ +From 87cc924b8c127afb617cd110b1fbee57f809cd49 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 15 Mar 2018 20:27:30 -0400 +Subject: [PATCH] Fix read overflow in KDC sort_pa_data() + +sort_pa_data() could read past the end of pa_order if all preauth +systems in the table have the PA_REPLACES_KEY flag, causing a +dereference of preauth_systems[-1]. This situation became possible +after commit fea1a488924faa3938ef723feaa1ff12d22a91ff with the +elimination of static_preauth_systems; before that there were always +table entries which did not have PA_REPLACES_KEY set. + +Fix this bug by removing the loop to count n_key_replacers, and +instead get the count from the prior loop by stopping once we move all +of the key-replacing modules to the front. + +(cherry picked from commit b38e318cea18fd65647189eed64aef83bf1cb772) +--- + src/kdc/kdc_preauth.c | 9 +++++---- + 1 file changed, 5 insertions(+), 4 deletions(-) + +diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c +index 80b130222..62ff9a8a7 100644 +--- a/src/kdc/kdc_preauth.c ++++ b/src/kdc/kdc_preauth.c +@@ -663,17 +663,18 @@ sort_pa_order(krb5_context context, krb5_kdc_req *request, int *pa_order) + break; + } + } ++ /* If we didn't find one, we have moved all of the key-replacing ++ * modules, and i is the count of those modules. */ ++ if (j == n_repliers) ++ break; + } ++ n_key_replacers = i; + + if (request->padata != NULL) { + /* Now reorder the subset of modules which replace the key, + * bubbling those which handle pa_data types provided by the + * client ahead of the others. + */ +- for (i = 0; preauth_systems[pa_order[i]].flags & PA_REPLACES_KEY; i++) { +- continue; +- } +- n_key_replacers = i; + for (i = 0; i < n_key_replacers; i++) { + if (pa_list_includes(request->padata, + preauth_systems[pa_order[i]].type)) diff --git a/Include-preauth-name-in-trace-output-if-possible.patch b/Include-preauth-name-in-trace-output-if-possible.patch new file mode 100644 index 0000000..ca12e6f --- /dev/null +++ b/Include-preauth-name-in-trace-output-if-possible.patch @@ -0,0 +1,514 @@ +From 44fe6e4df092e3bc7673449ccd7c70b6f0a4ccbf Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 15 Mar 2018 14:37:28 -0400 +Subject: [PATCH] Include preauth name in trace output if possible + +Add a {patype} trace format specifier for a single pa-type value. Add +a krb5_preauthtype to string conversion function to trace machinery +and use it when formatting {patype} or {patypes}. + +[ghudson@mit.edu: wrote conversion function; edited commit message] + +ticket: 8653 (new) +(cherry picked from commit 9c68fe39b018666eabe033b639c1f35d03ba51c7) +--- + src/include/k5-trace.h | 17 ++-- + src/lib/krb5/os/t_trace.ref | 2 +- + src/lib/krb5/os/trace.c | 61 ++++++++++++- + src/tests/t_pkinit.py | 43 ++++----- + src/tests/t_preauth.py | 216 ++++++++++++++++++++++---------------------- + 5 files changed, 200 insertions(+), 139 deletions(-) + +diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h +index 390a8b7d6..5f7eb9517 100644 +--- a/src/include/k5-trace.h ++++ b/src/include/k5-trace.h +@@ -75,6 +75,7 @@ + * {cksum} const krb5_checksum *, display cksumtype and hex checksum + * {princ} krb5_principal, unparse and display + * {ptype} krb5_int32, krb5_principal type, display name ++ * {patype} krb5_preauthtype, a single padata type number + * {patypes} krb5_pa_data **, display list of padata type numbers + * {etype} krb5_enctype, display shortest name of enctype + * {etypes} krb5_enctype *, display list of enctypes +@@ -232,14 +233,14 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); + #define TRACE_INIT_CREDS_PREAUTH_DECRYPT_FAIL(c, code) \ + TRACE(c, "Decrypt with preauth AS key failed: {kerr}", code) + #define TRACE_INIT_CREDS_PREAUTH_MORE(c, patype) \ +- TRACE(c, "Continuing preauth mech {int}", (int)patype) ++ TRACE(c, "Continuing preauth mech {patype}", patype) + #define TRACE_INIT_CREDS_PREAUTH_NONE(c) \ + TRACE(c, "Sending unauthenticated request") + #define TRACE_INIT_CREDS_PREAUTH_OPTIMISTIC(c) \ + TRACE(c, "Attempting optimistic preauth") + #define TRACE_INIT_CREDS_PREAUTH_TRYAGAIN(c, patype, code) \ +- TRACE(c, "Recovering from KDC error {int} using preauth mech {int}", \ +- (int)patype, (int)code) ++ TRACE(c, "Recovering from KDC error {int} using preauth mech {patype}", \ ++ patype, (int)code) + #define TRACE_INIT_CREDS_RESTART_FAST(c) \ + TRACE(c, "Restarting to upgrade to FAST") + #define TRACE_INIT_CREDS_RESTART_PREAUTH_FAILED(c) \ +@@ -290,7 +291,7 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); + + #define TRACE_PREAUTH_CONFLICT(c, name1, name2, patype) \ + TRACE(c, "Preauth module {str} conflicts with module {str} for pa " \ +- "type {int}", name1, name2, (int) patype) ++ "type {patype}", name1, name2, patype) + #define TRACE_PREAUTH_COOKIE(c, len, data) \ + TRACE(c, "Received cookie: {lenstr}", (size_t) len, data) + #define TRACE_PREAUTH_ENC_TS_KEY_GAK(c, keyblock) \ +@@ -302,8 +303,8 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); + TRACE(c, "Selected etype info: etype {etype}, salt \"{data}\", " \ + "params \"{data}\"", etype, salt, s2kparams) + #define TRACE_PREAUTH_INFO_FAIL(c, patype, code) \ +- TRACE(c, "Preauth builtin info function failure, type={int}: {kerr}", \ +- (int) patype, code) ++ TRACE(c, "Preauth builtin info function failure, type={patype}: {kerr}", \ ++ patype, code) + #define TRACE_PREAUTH_INPUT(c, padata) \ + TRACE(c, "Processing preauth types: {patypes}", padata) + #define TRACE_PREAUTH_OUTPUT(c, padata) \ +@@ -314,8 +315,8 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); + #define TRACE_PREAUTH_SAM_KEY_GAK(c, keyblock) \ + TRACE(c, "AS key obtained for SAM: {keyblock}", keyblock) + #define TRACE_PREAUTH_SALT(c, salt, patype) \ +- TRACE(c, "Received salt \"{data}\" via padata type {int}", salt, \ +- (int) patype) ++ TRACE(c, "Received salt \"{data}\" via padata type {patype}", salt, \ ++ patype) + #define TRACE_PREAUTH_SKIP(c, name, patype) \ + TRACE(c, "Skipping previously used preauth module {str} ({int})", \ + name, (int) patype) +diff --git a/src/lib/krb5/os/t_trace.ref b/src/lib/krb5/os/t_trace.ref +index ca5818a1e..bd5d9b6b6 100644 +--- a/src/lib/krb5/os/t_trace.ref ++++ b/src/lib/krb5/os/t_trace.ref +@@ -38,7 +38,7 @@ int, krb5_principal type: Windows 2000 UPN and SID + int, krb5_principal type: NT 4 style name + int, krb5_principal type: NT 4 style name and SID + int, krb5_principal type: ? +-krb5_pa_data **, display list of padata type numbers: 3, 0 ++krb5_pa_data **, display list of padata type numbers: PA-PW-SALT (3), 0 + krb5_pa_data **, display list of padata type numbers: (empty) + krb5_enctype, display shortest name of enctype: des-cbc-crc + krb5_enctype *, display list of enctypes: 5, rc4-hmac-exp, 511 +diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c +index 779f184cb..10b4f0c14 100644 +--- a/src/lib/krb5/os/trace.c ++++ b/src/lib/krb5/os/trace.c +@@ -123,6 +123,50 @@ principal_type_string(krb5_int32 type) + } + } + ++static char * ++padata_type_string(krb5_preauthtype type) ++{ ++ switch (type) { ++ case KRB5_PADATA_TGS_REQ: return "PA-TGS-REQ"; ++ case KRB5_PADATA_ENC_TIMESTAMP: return "PA-ENC-TIMESTAMP"; ++ case KRB5_PADATA_PW_SALT: return "PA-PW-SALT"; ++ case KRB5_PADATA_ENC_UNIX_TIME: return "PA-ENC-UNIX-TIME"; ++ case KRB5_PADATA_ENC_SANDIA_SECURID: return "PA-SANDIA-SECUREID"; ++ case KRB5_PADATA_SESAME: return "PA-SESAME"; ++ case KRB5_PADATA_OSF_DCE: return "PA-OSF-DCE"; ++ case KRB5_CYBERSAFE_SECUREID: return "PA-CYBERSAFE-SECUREID"; ++ case KRB5_PADATA_AFS3_SALT: return "PA-AFS3-SALT"; ++ case KRB5_PADATA_ETYPE_INFO: return "PA-ETYPE-INFO"; ++ case KRB5_PADATA_SAM_CHALLENGE: return "PA-SAM-CHALLENGE"; ++ case KRB5_PADATA_SAM_RESPONSE: return "PA-SAM-RESPONSE"; ++ case KRB5_PADATA_PK_AS_REQ_OLD: return "PA-PK-AS-REQ_OLD"; ++ case KRB5_PADATA_PK_AS_REP_OLD: return "PA-PK-AS-REP_OLD"; ++ case KRB5_PADATA_PK_AS_REQ: return "PA-PK-AS-REQ"; ++ case KRB5_PADATA_PK_AS_REP: return "PA-PK-AS-REP"; ++ case KRB5_PADATA_ETYPE_INFO2: return "PA-ETYPE-INFO2"; ++ case KRB5_PADATA_SVR_REFERRAL_INFO: return "PA-SVR-REFERRAL-INFO"; ++ case KRB5_PADATA_SAM_REDIRECT: return "PA-SAM-REDIRECT"; ++ case KRB5_PADATA_GET_FROM_TYPED_DATA: return "PA-GET-FROM-TYPED-DATA"; ++ case KRB5_PADATA_SAM_CHALLENGE_2: return "PA-SAM-CHALLENGE2"; ++ case KRB5_PADATA_SAM_RESPONSE_2: return "PA-SAM-RESPONSE2"; ++ case KRB5_PADATA_PAC_REQUEST: return "PA-PAC-REQUEST"; ++ case KRB5_PADATA_FOR_USER: return "PA-FOR_USER"; ++ case KRB5_PADATA_S4U_X509_USER: return "PA-FOR-X509-USER"; ++ case KRB5_PADATA_AS_CHECKSUM: return "PA-AS-CHECKSUM"; ++ case KRB5_PADATA_FX_COOKIE: return "PA-FX-COOKIE"; ++ case KRB5_PADATA_FX_FAST: return "PA-FX-FAST"; ++ case KRB5_PADATA_FX_ERROR: return "PA-FX-ERROR"; ++ case KRB5_PADATA_ENCRYPTED_CHALLENGE: return "PA-ENCRYPTED-CHALLENGE"; ++ case KRB5_PADATA_OTP_CHALLENGE: return "PA-OTP-CHALLENGE"; ++ case KRB5_PADATA_OTP_REQUEST: return "PA-OTP-REQUEST"; ++ case KRB5_PADATA_OTP_PIN_CHANGE: return "PA-OTP-PIN-CHANGE"; ++ case KRB5_PADATA_PKINIT_KX: return "PA-PKINIT-KX"; ++ case KRB5_ENCPADATA_REQ_ENC_PA_REP: return "PA-REQ-ENC-PA-REP"; ++ case KRB5_PADATA_AS_FRESHNESS: return "PA_AS_FRESHNESS"; ++ default: return NULL; ++ } ++} ++ + static char * + trace_format(krb5_context context, const char *fmt, va_list ap) + { +@@ -140,6 +184,8 @@ trace_format(krb5_context context, const char *fmt, va_list ap) + krb5_key key; + const krb5_checksum *cksum; + krb5_pa_data **padata; ++ krb5_preauthtype pa_type; ++ const char *name; + krb5_ccache ccache; + krb5_keytab keytab; + krb5_creds *creds; +@@ -271,10 +317,23 @@ trace_format(krb5_context context, const char *fmt, va_list ap) + if (padata == NULL || *padata == NULL) + k5_buf_add(&buf, "(empty)"); + for (; padata != NULL && *padata != NULL; padata++) { +- k5_buf_add_fmt(&buf, "%d", (int)(*padata)->pa_type); ++ pa_type = (*padata)->pa_type; ++ name = padata_type_string(pa_type); ++ if (name != NULL) ++ k5_buf_add_fmt(&buf, "%s (%d)", name, (int)pa_type); ++ else ++ k5_buf_add_fmt(&buf, "%d", (int)pa_type); ++ + if (*(padata + 1) != NULL) + k5_buf_add(&buf, ", "); + } ++ } else if (strcmp(tmpbuf, "patype") == 0) { ++ pa_type = va_arg(ap, krb5_preauthtype); ++ name = padata_type_string(pa_type); ++ if (name != NULL) ++ k5_buf_add_fmt(&buf, "%s (%d)", name, (int)pa_type); ++ else ++ k5_buf_add_fmt(&buf, "%d", (int)pa_type); + } else if (strcmp(tmpbuf, "etype") == 0) { + etype = va_arg(ap, krb5_enctype); + if (krb5_enctype_to_name(etype, TRUE, tmpbuf, sizeof(tmpbuf)) == 0) +diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py +index 3030322e1..1ba3536da 100755 +--- a/src/tests/t_pkinit.py ++++ b/src/tests/t_pkinit.py +@@ -164,18 +164,19 @@ realm.stop_kdc() + realm.start_kdc() + + # Run the basic test - PKINIT with FILE: identity, with no password on the key. ++msgs = ('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Preauthenticating using KDC method data', ++ 'PKINIT client received freshness token from KDC', ++ 'PKINIT loading CA certs and CRLs from FILE', ++ 'PKINIT client making DH request', ++ ' preauth for next request: PA-FX-COOKIE (133), PA-PK-AS-REQ (16)', ++ 'PKINIT client verified DH reply', ++ 'PKINIT client found id-pkinit-san in KDC cert', ++ 'PKINIT client matched KDC principal krbtgt/') + realm.kinit(realm.user_princ, + flags=['-X', 'X509_user_identity=%s' % file_identity], +- expected_trace=('Sending unauthenticated request', +- '/Additional pre-authentication required', +- 'Preauthenticating using KDC method data', +- 'PKINIT client received freshness token from KDC', +- 'PKINIT loading CA certs and CRLs from FILE', +- 'PKINIT client making DH request', +- 'Produced preauth for next request: 133, 16', +- 'PKINIT client verified DH reply', +- 'PKINIT client found id-pkinit-san in KDC cert', +- 'PKINIT client matched KDC principal krbtgt/')) ++ expected_trace=msgs) + realm.klist(realm.user_princ) + realm.run([kvno, realm.host_princ]) + +@@ -194,19 +195,19 @@ minbits_kdc_conf = {'realms': {'$realm': {'pkinit_dh_min_bits': '4096'}}} + minbits_env = realm.special_env('restrict', True, kdc_conf=minbits_kdc_conf) + realm.stop_kdc() + realm.start_kdc(env=minbits_env) +-expected_trace = ('Sending unauthenticated request', +- '/Additional pre-authentication required', +- 'Preauthenticating using KDC method data', +- 'Preauth module pkinit (16) (real) returned: 0/Success', +- 'Produced preauth for next request: 133, 16', +- '/Key parameters not accepted', +- 'Preauth tryagain input types (16): 109, 133', +- 'trying again with KDC-provided parameters', +- 'Preauth module pkinit (16) tryagain returned: 0/Success', +- 'Followup preauth for next request: 16, 133') ++msgs = ('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Preauthenticating using KDC method data', ++ 'Preauth module pkinit (16) (real) returned: 0/Success', ++ ' preauth for next request: PA-FX-COOKIE (133), PA-PK-AS-REQ (16)', ++ '/Key parameters not accepted', ++ 'Preauth tryagain input types (16): 109, PA-FX-COOKIE (133)', ++ 'trying again with KDC-provided parameters', ++ 'Preauth module pkinit (16) tryagain returned: 0/Success', ++ ' preauth for next request: PA-PK-AS-REQ (16), PA-FX-COOKIE (133)') + realm.kinit(realm.user_princ, + flags=['-X', 'X509_user_identity=%s' % file_identity], +- expected_trace=expected_trace) ++ expected_trace=msgs) + + # Test enforcement of required freshness tokens. (We can leave + # freshness tokens required after this test.) +diff --git a/src/tests/t_preauth.py b/src/tests/t_preauth.py +index fec0bf619..efb3ea20d 100644 +--- a/src/tests/t_preauth.py ++++ b/src/tests/t_preauth.py +@@ -18,15 +18,15 @@ realm.kinit('nokeyuser', password('user'), expected_code=1, + # PA-FX-COOKIE; 2 is encrypted timestamp. + + # Test normal preauth flow. +-expected_trace = ('Sending unauthenticated request', +- '/Additional pre-authentication required', +- 'Preauthenticating using KDC method data', +- 'Processing preauth types:', +- 'Preauth module test (-123) (real) returned: 0/Success', +- 'Produced preauth for next request: 133, -123', +- 'Decrypted AS reply') ++msgs = ('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Preauthenticating using KDC method data', ++ 'Processing preauth types:', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ 'Decrypted AS reply') + realm.run(['./icred', realm.user_princ, password('user')], +- expected_msg='testval', expected_trace=expected_trace) ++ expected_msg='testval', expected_trace=msgs) + + # Test successful optimistic preauth. + expected_trace = ('Attempting optimistic preauth', +@@ -39,136 +39,136 @@ realm.run(['./icred', '-o', '-123', realm.user_princ, password('user')], + + # Test optimistic preauth failing on client, followed by successful + # preauth using the same module. +-expected_trace = ('Attempting optimistic preauth', +- 'Processing preauth types: -123', +- '/induced optimistic fail', +- 'Sending unauthenticated request', +- '/Additional pre-authentication required', +- 'Preauthenticating using KDC method data', +- 'Processing preauth types:', +- 'Preauth module test (-123) (real) returned: 0/Success', +- 'Produced preauth for next request: 133, -123', +- 'Decrypted AS reply') ++msgs = ('Attempting optimistic preauth', ++ 'Processing preauth types: -123', ++ '/induced optimistic fail', ++ 'Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Preauthenticating using KDC method data', ++ 'Processing preauth types:', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ 'Decrypted AS reply') + realm.run(['./icred', '-o', '-123', '-X', 'fail_optimistic', realm.user_princ, + password('user')], expected_msg='testval', +- expected_trace=expected_trace) ++ expected_trace=msgs) + + # Test optimistic preauth failing on KDC, followed by successful preauth + # using the same module. + realm.run([kadminl, 'setstr', realm.user_princ, 'failopt', 'yes']) +-expected_trace = ('Attempting optimistic preauth', +- 'Processing preauth types: -123', +- 'Preauth module test (-123) (real) returned: 0/Success', +- 'Produced preauth for next request: -123', +- '/Preauthentication failed', +- 'Preauthenticating using KDC method data', +- 'Processing preauth types:', +- 'Preauth module test (-123) (real) returned: 0/Success', +- 'Produced preauth for next request: 133, -123', +- 'Decrypted AS reply') ++msgs = ('Attempting optimistic preauth', ++ 'Processing preauth types: -123', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: -123', ++ '/Preauthentication failed', ++ 'Preauthenticating using KDC method data', ++ 'Processing preauth types:', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ 'Decrypted AS reply') + realm.run(['./icred', '-o', '-123', realm.user_princ, password('user')], +- expected_msg='testval', expected_trace=expected_trace) ++ expected_msg='testval', expected_trace=msgs) + realm.run([kadminl, 'delstr', realm.user_princ, 'failopt']) + + # Test KDC_ERR_MORE_PREAUTH_DATA_REQUIRED and secure cookies. + realm.run([kadminl, 'setstr', realm.user_princ, '2rt', 'secondtrip']) +-expected_trace = ('Sending unauthenticated request', +- '/Additional pre-authentication required', +- 'Preauthenticating using KDC method data', +- 'Processing preauth types:', +- 'Preauth module test (-123) (real) returned: 0/Success', +- 'Produced preauth for next request: 133, -123', +- '/More preauthentication data is required', +- 'Continuing preauth mech -123', +- 'Processing preauth types: -123, 133', +- 'Produced preauth for next request: 133, -123', +- 'Decrypted AS reply') ++msgs = ('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Preauthenticating using KDC method data', ++ 'Processing preauth types:', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ '/More preauthentication data is required', ++ 'Continuing preauth mech -123', ++ 'Processing preauth types: -123, PA-FX-COOKIE (133)', ++ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ 'Decrypted AS reply') + realm.run(['./icred', realm.user_princ, password('user')], +- expected_msg='2rt: secondtrip', expected_trace=expected_trace) ++ expected_msg='2rt: secondtrip', expected_trace=msgs) + + # Test client-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED, + # falling back to encrypted timestamp. +-expected_trace = ('Sending unauthenticated request', +- '/Additional pre-authentication required', +- 'Preauthenticating using KDC method data', +- 'Processing preauth types:', +- 'Preauth module test (-123) (real) returned: 0/Success', +- 'Produced preauth for next request: 133, -123', +- '/More preauthentication data is required', +- 'Continuing preauth mech -123', +- 'Processing preauth types: -123, 133', +- '/induced 2rt fail', +- 'Preauthenticating using KDC method data', +- 'Processing preauth types:', +- 'Encrypted timestamp (for ', +- 'module encrypted_timestamp (2) (real) returned: 0/Success', +- 'Produced preauth for next request: 133, 2', +- 'Decrypted AS reply') ++msgs = ('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Preauthenticating using KDC method data', ++ 'Processing preauth types:', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ '/More preauthentication data is required', ++ 'Continuing preauth mech -123', ++ 'Processing preauth types: -123, PA-FX-COOKIE (133)', ++ '/induced 2rt fail', ++ 'Preauthenticating using KDC method data', ++ 'Processing preauth types:', ++ 'Encrypted timestamp (for ', ++ 'module encrypted_timestamp (2) (real) returned: 0/Success', ++ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', ++ 'Decrypted AS reply') + realm.run(['./icred', '-X', 'fail_2rt', realm.user_princ, password('user')], +- expected_msg='2rt: secondtrip', expected_trace=expected_trace) ++ expected_msg='2rt: secondtrip', expected_trace=msgs) + + # Test KDC-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED, + # falling back to encrypted timestamp. + realm.run([kadminl, 'setstr', realm.user_princ, 'fail2rt', 'yes']) +-expected_trace = ('Sending unauthenticated request', +- '/Additional pre-authentication required', +- 'Preauthenticating using KDC method data', +- 'Processing preauth types:', +- 'Preauth module test (-123) (real) returned: 0/Success', +- 'Produced preauth for next request: 133, -123', +- '/More preauthentication data is required', +- 'Continuing preauth mech -123', +- 'Processing preauth types: -123, 133', +- 'Preauth module test (-123) (real) returned: 0/Success', +- 'Produced preauth for next request: 133, -123', +- '/Preauthentication failed', +- 'Preauthenticating using KDC method data', +- 'Processing preauth types:', +- 'Encrypted timestamp (for ', +- 'module encrypted_timestamp (2) (real) returned: 0/Success', +- 'Produced preauth for next request: 133, 2', +- 'Decrypted AS reply') ++msgs = ('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Preauthenticating using KDC method data', ++ 'Processing preauth types:', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ '/More preauthentication data is required', ++ 'Continuing preauth mech -123', ++ 'Processing preauth types: -123, PA-FX-COOKIE (133)', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ '/Preauthentication failed', ++ 'Preauthenticating using KDC method data', ++ 'Processing preauth types:', ++ 'Encrypted timestamp (for ', ++ 'module encrypted_timestamp (2) (real) returned: 0/Success', ++ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', ++ 'Decrypted AS reply') + realm.run(['./icred', realm.user_princ, password('user')], +- expected_msg='2rt: secondtrip', expected_trace=expected_trace) ++ expected_msg='2rt: secondtrip', expected_trace=msgs) + realm.run([kadminl, 'delstr', realm.user_princ, 'fail2rt']) + + # Test tryagain flow by inducing a KDC_ERR_ENCTYPE_NOSUPP error on the KDC. + realm.run([kadminl, 'setstr', realm.user_princ, 'err', 'testagain']) +-expected_trace = ('Sending unauthenticated request', +- '/Additional pre-authentication required', +- 'Preauthenticating using KDC method data', +- 'Processing preauth types:', +- 'Preauth module test (-123) (real) returned: 0/Success', +- 'Produced preauth for next request: 133, -123', +- '/KDC has no support for encryption type', +- 'Recovering from KDC error 14 using preauth mech -123', +- 'Preauth tryagain input types (-123): -123, 133', +- 'Preauth module test (-123) tryagain returned: 0/Success', +- 'Followup preauth for next request: -123, 133', +- 'Decrypted AS reply') ++msgs = ('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Preauthenticating using KDC method data', ++ 'Processing preauth types:', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ '/KDC has no support for encryption type', ++ 'Recovering from KDC error 14 using preauth mech -123', ++ 'Preauth tryagain input types (-123): -123, PA-FX-COOKIE (133)', ++ 'Preauth module test (-123) tryagain returned: 0/Success', ++ 'Followup preauth for next request: -123, PA-FX-COOKIE (133)', ++ 'Decrypted AS reply') + realm.run(['./icred', realm.user_princ, password('user')], +- expected_msg='tryagain: testagain', expected_trace=expected_trace) ++ expected_msg='tryagain: testagain', expected_trace=msgs) + + # Test a client-side tryagain failure, falling back to encrypted + # timestamp. +-expected_trace = ('Sending unauthenticated request', +- '/Additional pre-authentication required', +- 'Preauthenticating using KDC method data', +- 'Processing preauth types:', +- 'Preauth module test (-123) (real) returned: 0/Success', +- 'Produced preauth for next request: 133, -123', +- '/KDC has no support for encryption type', +- 'Recovering from KDC error 14 using preauth mech -123', +- 'Preauth tryagain input types (-123): -123, 133', +- '/induced tryagain fail', +- 'Preauthenticating using KDC method data', +- 'Processing preauth types:', +- 'Encrypted timestamp (for ', +- 'module encrypted_timestamp (2) (real) returned: 0/Success', +- 'Produced preauth for next request: 133, 2', +- 'Decrypted AS reply') ++msgs = ('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Preauthenticating using KDC method data', ++ 'Processing preauth types:', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ '/KDC has no support for encryption type', ++ 'Recovering from KDC error 14 using preauth mech -123', ++ 'Preauth tryagain input types (-123): -123, PA-FX-COOKIE (133)', ++ '/induced tryagain fail', ++ 'Preauthenticating using KDC method data', ++ 'Processing preauth types:', ++ 'Encrypted timestamp (for ', ++ 'module encrypted_timestamp (2) (real) returned: 0/Success', ++ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', ++ 'Decrypted AS reply') + realm.run(['./icred', '-X', 'fail_tryagain', realm.user_princ, +- password('user')], expected_trace=expected_trace) ++ password('user')], expected_trace=msgs) + + # Test that multiple stepwise initial creds operations can be + # performed with the same krb5_context, with proper tracking of diff --git a/Report-extended-errors-in-kinit-k-t-KDB.patch b/Report-extended-errors-in-kinit-k-t-KDB.patch new file mode 100644 index 0000000..feb49b7 --- /dev/null +++ b/Report-extended-errors-in-kinit-k-t-KDB.patch @@ -0,0 +1,27 @@ +From b3b5cf3d57ac2889aeab82a79a6ea967c1412eb6 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sat, 17 Mar 2018 22:47:34 -0400 +Subject: [PATCH] Report extended errors in kinit -k -t KDB: + +In kinit, if we recreate the context using kinit_kdb_init(), also +reset the global errctx so that we use the new context to retrieve +extended error messages. + +ticket: 8652 (new) +(cherry picked from commit d4d902d317a2acc46ee71094a33a9203b6135275) +--- + src/clients/kinit/kinit.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/src/clients/kinit/kinit.c b/src/clients/kinit/kinit.c +index a518284ea..3fdae2878 100644 +--- a/src/clients/kinit/kinit.c ++++ b/src/clients/kinit/kinit.c +@@ -718,6 +718,7 @@ k5_kinit(struct k_opts *opts, struct k5_data *k5) + #ifndef _WIN32 + if (strncmp(opts->keytab_name, "KDB:", 4) == 0) { + ret = kinit_kdb_init(&k5->ctx, k5->me->realm.data); ++ errctx = k5->ctx; + if (ret) { + com_err(progname, ret, + _("while setting up KDB keytab for realm %s"), diff --git a/krb5.spec b/krb5.spec index 105326d..4cbdcf1 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 11%{?dist} +Release: 12%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -71,6 +71,10 @@ Patch44: Refactor-KDC-krb5_pa_data-utility-functions.patch Patch45: Simplify-kdc_preauth.c-systems-table.patch Patch46: Add-PKINIT-client-support-for-freshness-token.patch Patch47: Add-PKINIT-KDC-support-for-freshness-token.patch +Patch48: Allow-validation-of-PACs-with-enterprise-names.patch +Patch49: Fix-read-overflow-in-KDC-sort_pa_data.patch +Patch50: Include-preauth-name-in-trace-output-if-possible.patch +Patch51: Report-extended-errors-in-kinit-k-t-KDB.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -720,6 +724,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Mar 20 2018 Robbie Harwood - 1.16-12 +- Log preauth names in trace output +- Misc bugfixes from upstream + * Mon Mar 19 2018 Robbie Harwood - 1.16-11 - Add PKINIT KDC support for freshness token From 6b1b652d4d3bd7580f3dfde8dee080167c34cf7b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 20 Mar 2018 17:53:36 +0000 Subject: [PATCH 027/304] Add pkinit_anchors default value to krb5.conf Reindent krb5.conf to not be terrible --- krb5.conf | 23 ++++++++++++----------- krb5.spec | 6 +++++- 2 files changed, 17 insertions(+), 12 deletions(-) diff --git a/krb5.conf b/krb5.conf index cf23f53..0ba01ea 100644 --- a/krb5.conf +++ b/krb5.conf @@ -3,22 +3,23 @@ includedir /etc/krb5.conf.d/ [logging] - default = FILE:/var/log/krb5libs.log - kdc = FILE:/var/log/krb5kdc.log - admin_server = FILE:/var/log/kadmind.log + default = FILE:/var/log/krb5libs.log + kdc = FILE:/var/log/krb5kdc.log + admin_server = FILE:/var/log/kadmind.log [libdefaults] - dns_lookup_realm = false - ticket_lifetime = 24h - renew_lifetime = 7d - forwardable = true - rdns = false -# default_realm = EXAMPLE.COM + dns_lookup_realm = false + ticket_lifetime = 24h + renew_lifetime = 7d + forwardable = true + rdns = false + pkinit_anchors = /etc/pki/tls/certs/ca-bundle.crt +# default_realm = EXAMPLE.COM [realms] # EXAMPLE.COM = { -# kdc = kerberos.example.com -# admin_server = kerberos.example.com +# kdc = kerberos.example.com +# admin_server = kerberos.example.com # } [domain_realm] diff --git a/krb5.spec b/krb5.spec index 4cbdcf1..2ebbf66 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 12%{?dist} +Release: 13%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -724,6 +724,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Mar 20 2018 Robbie Harwood - 1.16-13 +- Add pkinit_anchors default value to krb5.conf +- Reindent krb5.conf to not be terrible + * Tue Mar 20 2018 Robbie Harwood - 1.16-12 - Log preauth names in trace output - Misc bugfixes from upstream From 8b49b0644c7e1ec0b61610e20ebb864db32ce741 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 20 Mar 2018 18:20:01 +0000 Subject: [PATCH 028/304] Fix problem with ccache_name logic in previous build --- krb5.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/krb5.spec b/krb5.spec index 2ebbf66..d243d85 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 13%{?dist} +Release: 14%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -428,7 +428,7 @@ mkdir -m 755 -p $RPM_BUILD_ROOT/etc/gss/mech.d %if 0%{?configure_default_ccache_name} export DEFCCNAME="%{configured_default_ccache_name}" awk '{print} - /^# default_realm/{print " default_ccache_name =", ENVIRON["DEFCCNAME"]}' \ + /^# default_realm/{print " default_ccache_name =", ENVIRON["DEFCCNAME"]}' \ %{SOURCE6} > $RPM_BUILD_ROOT/etc/krb5.conf touch -r %{SOURCE6} $RPM_BUILD_ROOT/etc/krb5.conf grep default_ccache_name $RPM_BUILD_ROOT/etc/krb5.conf @@ -724,6 +724,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Mar 20 2018 Robbie Harwood - 1.16-13 +- Fix problem with ccache_name logic in previous build + * Tue Mar 20 2018 Robbie Harwood - 1.16-13 - Add pkinit_anchors default value to krb5.conf - Reindent krb5.conf to not be terrible From 2c340efca2219c5c003b6f2c87c7d314d7a70d05 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 27 Mar 2018 11:02:50 -0400 Subject: [PATCH 029/304] Add SPAKE support - Improve protections on internal sensitive buffers - Improve internal hex encoding/decoding --- ...ncoders-and-decoders-for-SPAKE-types.patch | 866 + Add-SPAKE-preauth-support.patch | 14349 ++++++++++++++++ ...oc-index-entries-for-SPAKE-constants.patch | 31 + Add-k5_buf_add_vfmt-to-k5buf-interface.patch | 119 + ...bkrb5support-hex-functions-and-tests.patch | 496 + Add-vector-support-to-k5_sha256.patch | 106 + Implement-k5_buf_init_dynamic_zap.patch | 149 + Move-zap-definition-to-k5-platform.h.patch | 151 + ...f_init_dynamic_zap-where-appropriate.patch | 62 + ...port-hex-functions-where-appropriate.patch | 869 + kdc.conf | 19 +- krb5.conf | 1 + krb5.spec | 19 +- 13 files changed, 17226 insertions(+), 11 deletions(-) create mode 100644 Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch create mode 100644 Add-SPAKE-preauth-support.patch create mode 100644 Add-doc-index-entries-for-SPAKE-constants.patch create mode 100644 Add-k5_buf_add_vfmt-to-k5buf-interface.patch create mode 100644 Add-libkrb5support-hex-functions-and-tests.patch create mode 100644 Add-vector-support-to-k5_sha256.patch create mode 100644 Implement-k5_buf_init_dynamic_zap.patch create mode 100644 Move-zap-definition-to-k5-platform.h.patch create mode 100644 Use-k5_buf_init_dynamic_zap-where-appropriate.patch create mode 100644 Use-libkrb5support-hex-functions-where-appropriate.patch diff --git a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch new file mode 100644 index 0000000..96377e8 --- /dev/null +++ b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch @@ -0,0 +1,866 @@ +From 09304f3859f2dd637b7cc27ba1cb3fb3603a3576 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sat, 13 Jun 2015 16:04:53 -0400 +Subject: [PATCH] Add ASN.1 encoders and decoders for SPAKE types + +Add a new internal header k5-spake.h. Add ASN.1 encoder and decoder +functions and an internal free function for SPAKE types. Add ASN.1 +tests and asn1c test vectors the new types. + +The additions to to make-vectors.c use C99 designated initializers in +order to initialize unions. This is okay since make-vectors.c is only +compiled as part of "make test-vectors" and not as part of the regular +build. + +(cherry picked from commit 78a09d95dff6915da4079bc611f4bb95f6a95f70) +--- + src/include/k5-spake.h | 107 +++++++++++++++++++++++++++++++++++ + src/lib/krb5/asn.1/asn1_k_encode.c | 52 ++++++++++++++++- + src/lib/krb5/krb/kfree.c | 40 +++++++++++++ + src/lib/krb5/libkrb5.exports | 6 ++ + src/tests/asn.1/Makefile.in | 2 +- + src/tests/asn.1/krb5_decode_test.c | 37 ++++++++++++ + src/tests/asn.1/krb5_encode_test.c | 29 ++++++++++ + src/tests/asn.1/ktest.c | 97 +++++++++++++++++++++++++++++++ + src/tests/asn.1/ktest.h | 9 +++ + src/tests/asn.1/ktest_equal.c | 49 ++++++++++++++++ + src/tests/asn.1/ktest_equal.h | 6 ++ + src/tests/asn.1/make-vectors.c | 56 ++++++++++++++++++ + src/tests/asn.1/reference_encode.out | 6 ++ + src/tests/asn.1/spake.asn1 | 44 ++++++++++++++ + src/tests/asn.1/trval_reference.out | 50 ++++++++++++++++ + 15 files changed, 588 insertions(+), 2 deletions(-) + create mode 100644 src/include/k5-spake.h + create mode 100644 src/tests/asn.1/spake.asn1 + +diff --git a/src/include/k5-spake.h b/src/include/k5-spake.h +new file mode 100644 +index 000000000..ddb5d810d +--- /dev/null ++++ b/src/include/k5-spake.h +@@ -0,0 +1,107 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* include/k5-spake.h - SPAKE preauth mech declarations */ ++/* ++ * Copyright (C) 2015 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++/* ++ * The SPAKE preauth mechanism allows long-term client keys to be used for ++ * preauthentication without exposing them to offline dictionary attacks. The ++ * negotiated key can also be used for second-factor authentication. This ++ * header file declares structures and encoder/decoder functions for the ++ * mechanism's padata messages. ++ */ ++ ++#ifndef K5_SPAKE_H ++#define K5_SPAKE_H ++ ++#include "k5-int.h" ++ ++/* SPAKESecondFactor is contained within a SPAKEChallenge, SPAKEResponse, or ++ * EncryptedData message and contains a second-factor challenge or response. */ ++typedef struct krb5_spake_factor_st { ++ int32_t type; ++ krb5_data *data; ++} krb5_spake_factor; ++ ++/* SPAKESupport is sent from the client to the KDC to indicate which group the ++ * client supports. */ ++typedef struct krb5_spake_support_st { ++ int32_t ngroups; ++ int32_t *groups; ++} krb5_spake_support; ++ ++/* SPAKEChallenge is sent from the KDC to the client to communicate its group ++ * selection, public value, and second-factor challenge options. */ ++typedef struct krb5_spake_challenge_st { ++ int32_t group; ++ krb5_data pubkey; ++ krb5_spake_factor **factors; ++} krb5_spake_challenge; ++ ++/* SPAKEResponse is sent from the client to the KDC to communicate its public ++ * value and encrypted second-factor response. */ ++typedef struct krb5_spake_response_st { ++ krb5_data pubkey; ++ krb5_enc_data factor; ++} krb5_spake_response; ++ ++enum krb5_spake_msgtype { ++ SPAKE_MSGTYPE_UNKNOWN = -1, ++ SPAKE_MSGTYPE_SUPPORT = 0, ++ SPAKE_MSGTYPE_CHALLENGE = 1, ++ SPAKE_MSGTYPE_RESPONSE = 2, ++ SPAKE_MSGTYPE_ENCDATA = 3 ++}; ++ ++/* PA-SPAKE is a choice among the message types which can appear in a PA-SPAKE ++ * padata element. */ ++typedef struct krb5_pa_spake_st { ++ enum krb5_spake_msgtype choice; ++ union krb5_spake_message_choices { ++ krb5_spake_support support; ++ krb5_spake_challenge challenge; ++ krb5_spake_response response; ++ krb5_enc_data encdata; ++ } u; ++} krb5_pa_spake; ++ ++krb5_error_code encode_krb5_spake_factor(const krb5_spake_factor *val, ++ krb5_data **code_out); ++krb5_error_code decode_krb5_spake_factor(const krb5_data *code, ++ krb5_spake_factor **val_out); ++void k5_free_spake_factor(krb5_context context, krb5_spake_factor *val); ++ ++krb5_error_code encode_krb5_pa_spake(const krb5_pa_spake *val, ++ krb5_data **code_out); ++krb5_error_code decode_krb5_pa_spake(const krb5_data *code, ++ krb5_pa_spake **val_out); ++void k5_free_pa_spake(krb5_context context, krb5_pa_spake *val); ++ ++#endif /* K5_SPAKE_H */ +diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c +index 3b23fe34a..29f6b903d 100644 +--- a/src/lib/krb5/asn.1/asn1_k_encode.c ++++ b/src/lib/krb5/asn.1/asn1_k_encode.c +@@ -25,7 +25,7 @@ + */ + + #include "asn1_encode.h" +-#include ++#include "k5-spake.h" + + DEFINT_IMMEDIATE(krb5_version, KVNO, KRB5KDC_ERR_BAD_PVNO); + +@@ -1817,3 +1817,53 @@ static const struct atype_info *secure_cookie_fields[] = { + DEFSEQTYPE(secure_cookie, krb5_secure_cookie, secure_cookie_fields); + MAKE_ENCODER(encode_krb5_secure_cookie, secure_cookie); + MAKE_DECODER(decode_krb5_secure_cookie, secure_cookie); ++ ++DEFFIELD(spake_factor_0, krb5_spake_factor, type, 0, int32); ++DEFFIELD(spake_factor_1, krb5_spake_factor, data, 1, opt_ostring_data_ptr); ++static const struct atype_info *spake_factor_fields[] = { ++ &k5_atype_spake_factor_0, &k5_atype_spake_factor_1 ++}; ++DEFSEQTYPE(spake_factor, krb5_spake_factor, spake_factor_fields); ++DEFPTRTYPE(spake_factor_ptr, spake_factor); ++DEFNULLTERMSEQOFTYPE(seqof_spake_factor, spake_factor_ptr); ++DEFPTRTYPE(ptr_seqof_spake_factor, seqof_spake_factor); ++MAKE_ENCODER(encode_krb5_spake_factor, spake_factor); ++MAKE_DECODER(decode_krb5_spake_factor, spake_factor); ++ ++DEFCNFIELD(spake_support_0, krb5_spake_support, groups, ngroups, 0, ++ cseqof_int32); ++static const struct atype_info *spake_support_fields[] = { ++ &k5_atype_spake_support_0 ++}; ++DEFSEQTYPE(spake_support, krb5_spake_support, spake_support_fields); ++ ++DEFFIELD(spake_challenge_0, krb5_spake_challenge, group, 0, int32); ++DEFFIELD(spake_challenge_1, krb5_spake_challenge, pubkey, 1, ostring_data); ++DEFFIELD(spake_challenge_2, krb5_spake_challenge, factors, 2, ++ ptr_seqof_spake_factor); ++static const struct atype_info *spake_challenge_fields[] = { ++ &k5_atype_spake_challenge_0, &k5_atype_spake_challenge_1, ++ &k5_atype_spake_challenge_2 ++}; ++DEFSEQTYPE(spake_challenge, krb5_spake_challenge, spake_challenge_fields); ++ ++DEFFIELD(spake_response_0, krb5_spake_response, pubkey, 0, ostring_data); ++DEFFIELD(spake_response_1, krb5_spake_response, factor, 1, encrypted_data); ++static const struct atype_info *spake_response_fields[] = { ++ &k5_atype_spake_response_0, &k5_atype_spake_response_1, ++}; ++DEFSEQTYPE(spake_response, krb5_spake_response, spake_response_fields); ++ ++DEFCTAGGEDTYPE(pa_spake_0, 0, spake_support); ++DEFCTAGGEDTYPE(pa_spake_1, 1, spake_challenge); ++DEFCTAGGEDTYPE(pa_spake_2, 2, spake_response); ++DEFCTAGGEDTYPE(pa_spake_3, 3, encrypted_data); ++static const struct atype_info *pa_spake_alternatives[] = { ++ &k5_atype_pa_spake_0, &k5_atype_pa_spake_1, &k5_atype_pa_spake_2, ++ &k5_atype_pa_spake_3 ++}; ++DEFCHOICETYPE(pa_spake_choice, union krb5_spake_message_choices, ++ enum krb5_spake_msgtype, pa_spake_alternatives); ++DEFCOUNTEDTYPE_SIGNED(pa_spake, krb5_pa_spake, u, choice, pa_spake_choice); ++MAKE_ENCODER(encode_krb5_pa_spake, pa_spake); ++MAKE_DECODER(decode_krb5_pa_spake, pa_spake); +diff --git a/src/lib/krb5/krb/kfree.c b/src/lib/krb5/krb/kfree.c +index a631807d3..e1ea1494a 100644 +--- a/src/lib/krb5/krb/kfree.c ++++ b/src/lib/krb5/krb/kfree.c +@@ -51,6 +51,7 @@ + */ + + #include "k5-int.h" ++#include "k5-spake.h" + #include + + void KRB5_CALLCONV +@@ -890,3 +891,42 @@ k5_free_secure_cookie(krb5_context context, krb5_secure_cookie *val) + k5_zapfree_pa_data(val->data); + free(val); + } ++ ++void ++k5_free_spake_factor(krb5_context context, krb5_spake_factor *val) ++{ ++ if (val == NULL) ++ return; ++ krb5_free_data(context, val->data); ++ free(val); ++} ++ ++void ++k5_free_pa_spake(krb5_context context, krb5_pa_spake *val) ++{ ++ krb5_spake_factor **f; ++ ++ if (val == NULL) ++ return; ++ switch (val->choice) { ++ case SPAKE_MSGTYPE_SUPPORT: ++ free(val->u.support.groups); ++ break; ++ case SPAKE_MSGTYPE_CHALLENGE: ++ krb5_free_data_contents(context, &val->u.challenge.pubkey); ++ for (f = val->u.challenge.factors; f != NULL && *f != NULL; f++) ++ k5_free_spake_factor(context, *f); ++ free(val->u.challenge.factors); ++ break; ++ case SPAKE_MSGTYPE_RESPONSE: ++ krb5_free_data_contents(context, &val->u.response.pubkey); ++ krb5_free_data_contents(context, &val->u.response.factor.ciphertext); ++ break; ++ case SPAKE_MSGTYPE_ENCDATA: ++ krb5_free_data_contents(context, &val->u.encdata.ciphertext); ++ break; ++ default: ++ break; ++ } ++ free(val); ++} +diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports +index ed6cad6ad..622bc3673 100644 +--- a/src/lib/krb5/libkrb5.exports ++++ b/src/lib/krb5/libkrb5.exports +@@ -36,6 +36,7 @@ decode_krb5_pa_otp_req + decode_krb5_pa_otp_enc_req + decode_krb5_pa_pac_req + decode_krb5_pa_s4u_x509_user ++decode_krb5_pa_spake + decode_krb5_padata_sequence + decode_krb5_priv + decode_krb5_safe +@@ -44,6 +45,7 @@ decode_krb5_sam_challenge_2_body + decode_krb5_sam_response_2 + decode_krb5_secure_cookie + decode_krb5_setpw_req ++decode_krb5_spake_factor + decode_krb5_tgs_rep + decode_krb5_tgs_req + decode_krb5_ticket +@@ -85,6 +87,7 @@ encode_krb5_pa_otp_challenge + encode_krb5_pa_otp_req + encode_krb5_pa_otp_enc_req + encode_krb5_pa_s4u_x509_user ++encode_krb5_pa_spake + encode_krb5_padata_sequence + encode_krb5_pkinit_supp_pub_info + encode_krb5_priv +@@ -95,6 +98,7 @@ encode_krb5_sam_challenge_2_body + encode_krb5_sam_response_2 + encode_krb5_secure_cookie + encode_krb5_sp80056a_other_info ++encode_krb5_spake_factor + encode_krb5_tgs_rep + encode_krb5_tgs_req + encode_krb5_ticket +@@ -128,7 +132,9 @@ k5_free_kkdcp_message + k5_free_pa_otp_challenge + k5_free_pa_otp_req + k5_free_secure_cookie ++k5_free_pa_spake + k5_free_serverlist ++k5_free_spake_factor + k5_hostrealm_free_context + k5_init_trace + k5_is_string_numeric +diff --git a/src/tests/asn.1/Makefile.in b/src/tests/asn.1/Makefile.in +index fec4e109e..ec9c67495 100644 +--- a/src/tests/asn.1/Makefile.in ++++ b/src/tests/asn.1/Makefile.in +@@ -9,7 +9,7 @@ SRCS= $(srcdir)/krb5_encode_test.c $(srcdir)/krb5_decode_test.c \ + + ASN1SRCS= $(srcdir)/krb5.asn1 $(srcdir)/pkix.asn1 $(srcdir)/otp.asn1 \ + $(srcdir)/pkinit.asn1 $(srcdir)/pkinit-agility.asn1 \ +- $(srcdir)/cammac.asn1 ++ $(srcdir)/cammac.asn1 $(srcdir)/spake.asn1 + + all: krb5_encode_test krb5_decode_test krb5_decode_leak t_trval + +diff --git a/src/tests/asn.1/krb5_decode_test.c b/src/tests/asn.1/krb5_decode_test.c +index f17f9b1f1..ee70fa4b9 100644 +--- a/src/tests/asn.1/krb5_decode_test.c ++++ b/src/tests/asn.1/krb5_decode_test.c +@@ -25,6 +25,7 @@ + */ + + #include "k5-int.h" ++#include "k5-spake.h" + #include "ktest.h" + #include "com_err.h" + #include "utility.h" +@@ -1107,6 +1108,42 @@ int main(argc, argv) + ktest_empty_secure_cookie(&ref); + } + ++ /****************************************************************/ ++ /* decode_krb5_spake_factor */ ++ { ++ setup(krb5_spake_factor,ktest_make_minimal_spake_factor); ++ decode_run("spake_factor","(optionals NULL)","30 05 A0 03 02 01 01",decode_krb5_spake_factor,ktest_equal_spake_factor,k5_free_spake_factor); ++ ktest_empty_spake_factor(&ref); ++ } ++ { ++ setup(krb5_spake_factor,ktest_make_maximal_spake_factor); ++ decode_run("spake_factor","","30 0E A0 03 02 01 02 A1 07 04 05 66 64 61 74 61",decode_krb5_spake_factor,ktest_equal_spake_factor,k5_free_spake_factor); ++ ktest_empty_spake_factor(&ref); ++ } ++ ++ /****************************************************************/ ++ /* decode_krb5_pa_spake */ ++ { ++ setup(krb5_pa_spake,ktest_make_support_pa_spake); ++ decode_run("pa_spake","(support)","A0 0C 30 0A A0 08 30 06 02 01 01 02 01 02",decode_krb5_pa_spake,ktest_equal_pa_spake,k5_free_pa_spake); ++ ktest_empty_pa_spake(&ref); ++ } ++ { ++ setup(krb5_pa_spake,ktest_make_challenge_pa_spake); ++ decode_run("pa_spake","(challenge)","A1 2D 30 2B A0 03 02 01 01 A1 09 04 07 54 20 76 61 6C 75 65 A2 19 30 17 30 05 A0 03 02 01 01 30 0E A0 03 02 01 02 A1 07 04 05 66 64 61 74 61",decode_krb5_pa_spake,ktest_equal_pa_spake,k5_free_pa_spake); ++ ktest_empty_pa_spake(&ref); ++ } ++ { ++ setup(krb5_pa_spake,ktest_make_response_pa_spake); ++ decode_run("pa_spake","(response)","A2 34 30 32 A0 09 04 07 53 20 76 61 6C 75 65 A1 25 30 23 A0 03 02 01 00 A1 03 02 01 05 A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65",decode_krb5_pa_spake,ktest_equal_pa_spake,k5_free_pa_spake); ++ ktest_empty_pa_spake(&ref); ++ } ++ { ++ setup(krb5_pa_spake,ktest_make_encdata_pa_spake); ++ decode_run("pa_spake","(encdata)","A3 25 30 23 A0 03 02 01 00 A1 03 02 01 05 A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65",decode_krb5_pa_spake,ktest_equal_pa_spake,k5_free_pa_spake); ++ ktest_empty_pa_spake(&ref); ++ } ++ + #ifndef DISABLE_PKINIT + + /****************************************************************/ +diff --git a/src/tests/asn.1/krb5_encode_test.c b/src/tests/asn.1/krb5_encode_test.c +index f5710b68c..3efbfb4c0 100644 +--- a/src/tests/asn.1/krb5_encode_test.c ++++ b/src/tests/asn.1/krb5_encode_test.c +@@ -759,6 +759,35 @@ main(argc, argv) + encode_run(cookie, "secure_cookie", "", encode_krb5_secure_cookie); + ktest_empty_secure_cookie(&cookie); + } ++ /****************************************************************/ ++ /* encode_krb5_spake_factor */ ++ { ++ krb5_spake_factor factor; ++ ktest_make_minimal_spake_factor(&factor); ++ encode_run(factor, "spake_factor", "(optionals NULL)", ++ encode_krb5_spake_factor); ++ ktest_empty_spake_factor(&factor); ++ ktest_make_maximal_spake_factor(&factor); ++ encode_run(factor, "spake_factor", "", encode_krb5_spake_factor); ++ ktest_empty_spake_factor(&factor); ++ } ++ /****************************************************************/ ++ /* encode_krb5_pa_spake */ ++ { ++ krb5_pa_spake pa_spake; ++ ktest_make_support_pa_spake(&pa_spake); ++ encode_run(pa_spake, "pa_spake", "(support)", encode_krb5_pa_spake); ++ ktest_empty_pa_spake(&pa_spake); ++ ktest_make_challenge_pa_spake(&pa_spake); ++ encode_run(pa_spake, "pa_spake", "(challenge)", encode_krb5_pa_spake); ++ ktest_empty_pa_spake(&pa_spake); ++ ktest_make_response_pa_spake(&pa_spake); ++ encode_run(pa_spake, "pa_spake", "(response)", encode_krb5_pa_spake); ++ ktest_empty_pa_spake(&pa_spake); ++ ktest_make_encdata_pa_spake(&pa_spake); ++ encode_run(pa_spake, "pa_spake", "(encdata)", encode_krb5_pa_spake); ++ ktest_empty_pa_spake(&pa_spake); ++ } + #ifndef DISABLE_PKINIT + /****************************************************************/ + /* encode_krb5_pa_pk_as_req */ +diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c +index cf63f3f66..5bfdc5be2 100644 +--- a/src/tests/asn.1/ktest.c ++++ b/src/tests/asn.1/ktest.c +@@ -1018,6 +1018,66 @@ ktest_make_sample_secure_cookie(krb5_secure_cookie *p) + p->time = SAMPLE_TIME; + } + ++void ++ktest_make_minimal_spake_factor(krb5_spake_factor *p) ++{ ++ p->type = 1; ++ p->data = NULL; ++} ++ ++void ++ktest_make_maximal_spake_factor(krb5_spake_factor *p) ++{ ++ p->type = 2; ++ p->data = ealloc(sizeof(*p->data)); ++ krb5_data_parse(p->data, "fdata"); ++} ++ ++void ++ktest_make_support_pa_spake(krb5_pa_spake *p) ++{ ++ krb5_spake_support *s = &p->u.support; ++ ++ s->ngroups = 2; ++ s->groups = ealloc(s->ngroups * sizeof(*s->groups)); ++ s->groups[0] = 1; ++ s->groups[1] = 2; ++ p->choice = SPAKE_MSGTYPE_SUPPORT; ++} ++ ++void ++ktest_make_challenge_pa_spake(krb5_pa_spake *p) ++{ ++ krb5_spake_challenge *c = &p->u.challenge; ++ ++ c->group = 1; ++ krb5_data_parse(&c->pubkey, "T value"); ++ c->factors = ealloc(3 * sizeof(*c->factors)); ++ c->factors[0] = ealloc(sizeof(*c->factors[0])); ++ ktest_make_minimal_spake_factor(c->factors[0]); ++ c->factors[1] = ealloc(sizeof(*c->factors[1])); ++ ktest_make_maximal_spake_factor(c->factors[1]); ++ c->factors[2] = NULL; ++ p->choice = SPAKE_MSGTYPE_CHALLENGE; ++} ++ ++void ++ktest_make_response_pa_spake(krb5_pa_spake *p) ++{ ++ krb5_spake_response *r = &p->u.response; ++ ++ krb5_data_parse(&r->pubkey, "S value"); ++ ktest_make_sample_enc_data(&r->factor); ++ p->choice = SPAKE_MSGTYPE_RESPONSE; ++} ++ ++void ++ktest_make_encdata_pa_spake(krb5_pa_spake *p) ++{ ++ ktest_make_sample_enc_data(&p->u.encdata); ++ p->choice = SPAKE_MSGTYPE_ENCDATA; ++} ++ + /****************************************************************/ + /* destructors */ + +@@ -1858,3 +1918,40 @@ ktest_empty_secure_cookie(krb5_secure_cookie *p) + { + ktest_empty_pa_data_array(p->data); + } ++ ++void ++ktest_empty_spake_factor(krb5_spake_factor *p) ++{ ++ krb5_free_data(NULL, p->data); ++ p->data = NULL; ++} ++ ++void ++ktest_empty_pa_spake(krb5_pa_spake *p) ++{ ++ krb5_spake_factor **f; ++ ++ switch (p->choice) { ++ case SPAKE_MSGTYPE_SUPPORT: ++ free(p->u.support.groups); ++ break; ++ case SPAKE_MSGTYPE_CHALLENGE: ++ ktest_empty_data(&p->u.challenge.pubkey); ++ for (f = p->u.challenge.factors; *f != NULL; f++) { ++ ktest_empty_spake_factor(*f); ++ free(*f); ++ } ++ free(p->u.challenge.factors); ++ break; ++ case SPAKE_MSGTYPE_RESPONSE: ++ ktest_empty_data(&p->u.response.pubkey); ++ ktest_destroy_enc_data(&p->u.response.factor); ++ break; ++ case SPAKE_MSGTYPE_ENCDATA: ++ ktest_destroy_enc_data(&p->u.encdata); ++ break; ++ default: ++ break; ++ } ++ p->choice = SPAKE_MSGTYPE_UNKNOWN; ++} +diff --git a/src/tests/asn.1/ktest.h b/src/tests/asn.1/ktest.h +index 493303cc8..1413cfae1 100644 +--- a/src/tests/asn.1/ktest.h ++++ b/src/tests/asn.1/ktest.h +@@ -28,6 +28,7 @@ + #define __KTEST_H__ + + #include "k5-int.h" ++#include "k5-spake.h" + #include "kdb.h" + + #define SAMPLE_USEC 123456 +@@ -124,6 +125,12 @@ void ktest_make_sample_kkdcp_message(krb5_kkdcp_message *p); + void ktest_make_minimal_cammac(krb5_cammac *p); + void ktest_make_maximal_cammac(krb5_cammac *p); + void ktest_make_sample_secure_cookie(krb5_secure_cookie *p); ++void ktest_make_minimal_spake_factor(krb5_spake_factor *p); ++void ktest_make_maximal_spake_factor(krb5_spake_factor *p); ++void ktest_make_support_pa_spake(krb5_pa_spake *p); ++void ktest_make_challenge_pa_spake(krb5_pa_spake *p); ++void ktest_make_response_pa_spake(krb5_pa_spake *p); ++void ktest_make_encdata_pa_spake(krb5_pa_spake *p); + + /*----------------------------------------------------------------------*/ + +@@ -209,6 +216,8 @@ void ktest_empty_ldap_seqof_key_data(krb5_context, ldap_seqof_key_data *p); + void ktest_empty_kkdcp_message(krb5_kkdcp_message *p); + void ktest_empty_cammac(krb5_cammac *p); + void ktest_empty_secure_cookie(krb5_secure_cookie *p); ++void ktest_empty_spake_factor(krb5_spake_factor *p); ++void ktest_empty_pa_spake(krb5_pa_spake *p); + + extern krb5_context test_context; + extern char *sample_principal_name; +diff --git a/src/tests/asn.1/ktest_equal.c b/src/tests/asn.1/ktest_equal.c +index e8bb88944..714cc4398 100644 +--- a/src/tests/asn.1/ktest_equal.c ++++ b/src/tests/asn.1/ktest_equal.c +@@ -853,6 +853,13 @@ ktest_equal_sequence_of_otp_tokeninfo(krb5_otp_tokeninfo **ref, + array_compare(ktest_equal_otp_tokeninfo); + } + ++int ++ktest_equal_sequence_of_spake_factor(krb5_spake_factor **ref, ++ krb5_spake_factor **var) ++{ ++ array_compare(ktest_equal_spake_factor); ++} ++ + #ifndef DISABLE_PKINIT + + static int +@@ -1094,3 +1101,45 @@ ktest_equal_secure_cookie(krb5_secure_cookie *ref, krb5_secure_cookie *var) + p = p && ref->time == ref->time; + return p; + } ++ ++int ++ktest_equal_spake_factor(krb5_spake_factor *ref, krb5_spake_factor *var) ++{ ++ int p = TRUE; ++ if (ref == var) return TRUE; ++ else if (ref == NULL || var == NULL) return FALSE; ++ p = p && scalar_equal(type); ++ p = p && ptr_equal(data,ktest_equal_data); ++ return p; ++} ++ ++int ++ktest_equal_pa_spake(krb5_pa_spake *ref, krb5_pa_spake *var) ++{ ++ int p = TRUE; ++ if (ref == var) return TRUE; ++ else if (ref == NULL || var == NULL) return FALSE; ++ else if (ref->choice != var->choice) return FALSE; ++ switch (ref->choice) { ++ case SPAKE_MSGTYPE_SUPPORT: ++ p = p && scalar_equal(u.support.ngroups); ++ p = p && (memcmp(ref->u.support.groups,var->u.support.groups, ++ ref->u.support.ngroups * sizeof(int32_t)) == 0); ++ break; ++ case SPAKE_MSGTYPE_CHALLENGE: ++ p = p && struct_equal(u.challenge.pubkey,ktest_equal_data); ++ p = p && ptr_equal(u.challenge.factors, ++ ktest_equal_sequence_of_spake_factor); ++ break; ++ case SPAKE_MSGTYPE_RESPONSE: ++ p = p && struct_equal(u.response.pubkey,ktest_equal_data); ++ p = p && struct_equal(u.response.factor,ktest_equal_enc_data); ++ break; ++ case SPAKE_MSGTYPE_ENCDATA: ++ p = p && struct_equal(u.encdata,ktest_equal_enc_data); ++ break; ++ default: ++ break; ++ } ++ return p; ++} +diff --git a/src/tests/asn.1/ktest_equal.h b/src/tests/asn.1/ktest_equal.h +index c7b5d7467..cfa82ac6e 100644 +--- a/src/tests/asn.1/ktest_equal.h ++++ b/src/tests/asn.1/ktest_equal.h +@@ -28,6 +28,7 @@ + #define __KTEST_EQUAL_H__ + + #include "k5-int.h" ++#include "k5-spake.h" + #include "kdb.h" + + /* int ktest_equal_structure(krb5_structure *ref, *var) */ +@@ -97,6 +98,8 @@ ktest_equal_sequence_of_algorithm_identifier(krb5_algorithm_identifier **ref, + krb5_algorithm_identifier **var); + int ktest_equal_sequence_of_otp_tokeninfo(krb5_otp_tokeninfo **ref, + krb5_otp_tokeninfo **var); ++int ktest_equal_sequence_of_spake_factor(krb5_spake_factor **ref, ++ krb5_spake_factor **var); + + len_array(ktest_equal_array_of_enctype,krb5_enctype); + len_array(ktest_equal_array_of_data,krb5_data); +@@ -152,4 +155,7 @@ int ktest_equal_cammac(krb5_cammac *ref, krb5_cammac *var); + int ktest_equal_secure_cookie(krb5_secure_cookie *ref, + krb5_secure_cookie *var); + ++generic(ktest_equal_spake_factor, krb5_spake_factor); ++generic(ktest_equal_pa_spake, krb5_pa_spake); ++ + #endif +diff --git a/src/tests/asn.1/make-vectors.c b/src/tests/asn.1/make-vectors.c +index 3cb8a45ba..2fc85466b 100644 +--- a/src/tests/asn.1/make-vectors.c ++++ b/src/tests/asn.1/make-vectors.c +@@ -40,6 +40,8 @@ + #include + #include + #include ++#include ++#include + + static unsigned char buf[8192]; + static size_t buf_pos; +@@ -168,6 +170,36 @@ static struct other_verifiers overfs = { { verifiers, 2, 2 } }; + static AD_CAMMAC_t cammac_2 = { { { (void *)adlist_2, 2, 2 } }, + &vmac_1, &vmac_2, &overfs }; + ++/* SPAKESecondFactor */ ++static SPAKESecondFactor_t factor_1 = { 1, NULL }; ++static OCTET_STRING_t factor_data = { "fdata", 5 }; ++static SPAKESecondFactor_t factor_2 = { 2, &factor_data }; ++ ++/* PA-SPAKE (support) */ ++static Int32_t group_1 = 1, group_2 = 2, *groups[] = { &group_1, &group_2 }; ++static PA_SPAKE_t pa_spake_1 = { PA_SPAKE_PR_support, ++ { .support = { { groups, 2, 2 } } } }; ++ ++/* PA-SPAKE (challenge) */ ++static SPAKESecondFactor_t *factors[2] = { &factor_1, &factor_2 }; ++static PA_SPAKE_t pa_spake_2 = { PA_SPAKE_PR_challenge, ++ { .challenge = { 1, { "T value", 7 }, ++ { factors, 2, 2 } } } }; ++ ++/* PA-SPAKE (response) */ ++UInt32_t enctype_5 = 5; ++static PA_SPAKE_t pa_spake_3 = { PA_SPAKE_PR_response, ++ { .response = { { "S value", 7 }, ++ { 0, &enctype_5, ++ { "krbASN.1 test message", ++ 21 } } } } }; ++ ++/* PA-SPAKE (encdata) */ ++static PA_SPAKE_t pa_spake_4 = { PA_SPAKE_PR_encdata, ++ { .encdata = { 0, &enctype_5, ++ { "krbASN.1 test message", ++ 21 } } } }; ++ + static int + consume(const void *data, size_t size, void *dummy) + { +@@ -272,6 +304,30 @@ main() + der_encode(&asn_DEF_AD_CAMMAC, &cammac_2, consume, NULL); + printbuf(); + ++ printf("\nMinimal SPAKESecondFactor:\n"); ++ der_encode(&asn_DEF_SPAKESecondFactor, &factor_1, consume, NULL); ++ printbuf(); ++ ++ printf("\nMaximal SPAKESecondFactor:\n"); ++ der_encode(&asn_DEF_SPAKESecondFactor, &factor_2, consume, NULL); ++ printbuf(); ++ ++ printf("\nPA-SPAKE (support):\n"); ++ der_encode(&asn_DEF_PA_SPAKE, &pa_spake_1, consume, NULL); ++ printbuf(); ++ ++ printf("\nPA-SPAKE (challenge):\n"); ++ der_encode(&asn_DEF_PA_SPAKE, &pa_spake_2, consume, NULL); ++ printbuf(); ++ ++ printf("\nPA-SPAKE (response):\n"); ++ der_encode(&asn_DEF_PA_SPAKE, &pa_spake_3, consume, NULL); ++ printbuf(); ++ ++ printf("\nPA-SPAKE (encdata):\n"); ++ der_encode(&asn_DEF_PA_SPAKE, &pa_spake_4, consume, NULL); ++ printbuf(); ++ + printf("\n"); + return 0; + } +diff --git a/src/tests/asn.1/reference_encode.out b/src/tests/asn.1/reference_encode.out +index 824e0798b..a76deead2 100644 +--- a/src/tests/asn.1/reference_encode.out ++++ b/src/tests/asn.1/reference_encode.out +@@ -72,3 +72,9 @@ encode_krb5_kkdcp_message: 30 82 01 FC A0 82 01 EC 04 82 01 E8 6A 82 01 E4 30 82 + encode_krb5_cammac(optionals NULL): 30 12 A0 10 30 0E 30 0C A0 03 02 01 01 A1 05 04 03 61 64 31 + encode_krb5_cammac: 30 81 F2 A0 1E 30 1C 30 0C A0 03 02 01 01 A1 05 04 03 61 64 31 30 0C A0 03 02 01 02 A1 05 04 03 61 64 32 A1 3D 30 3B A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 03 02 01 05 A2 03 02 01 10 A3 13 30 11 A0 03 02 01 01 A1 0A 04 08 63 6B 73 75 6D 6B 64 63 A2 3D 30 3B A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 03 02 01 05 A2 03 02 01 10 A3 13 30 11 A0 03 02 01 01 A1 0A 04 08 63 6B 73 75 6D 73 76 63 A3 52 30 50 30 13 A3 11 30 0F A0 03 02 01 01 A1 08 04 06 63 6B 73 75 6D 31 30 39 A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 03 02 01 05 A2 03 02 01 10 A3 11 30 0F A0 03 02 01 01 A1 08 04 06 63 6B 73 75 6D 32 + encode_krb5_secure_cookie: 30 2C 02 04 2D F8 02 25 30 24 30 10 A1 03 02 01 0D A2 09 04 07 70 61 2D 64 61 74 61 30 10 A1 03 02 01 0D A2 09 04 07 70 61 2D 64 61 74 61 ++encode_krb5_spake_factor(optionals NULL): 30 05 A0 03 02 01 01 ++encode_krb5_spake_factor: 30 0E A0 03 02 01 02 A1 07 04 05 66 64 61 74 61 ++encode_krb5_pa_spake(support): A0 0C 30 0A A0 08 30 06 02 01 01 02 01 02 ++encode_krb5_pa_spake(challenge): A1 2D 30 2B A0 03 02 01 01 A1 09 04 07 54 20 76 61 6C 75 65 A2 19 30 17 30 05 A0 03 02 01 01 30 0E A0 03 02 01 02 A1 07 04 05 66 64 61 74 61 ++encode_krb5_pa_spake(response): A2 34 30 32 A0 09 04 07 53 20 76 61 6C 75 65 A1 25 30 23 A0 03 02 01 00 A1 03 02 01 05 A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65 ++encode_krb5_pa_spake(encdata): A3 25 30 23 A0 03 02 01 00 A1 03 02 01 05 A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65 +diff --git a/src/tests/asn.1/spake.asn1 b/src/tests/asn.1/spake.asn1 +new file mode 100644 +index 000000000..50718d8ad +--- /dev/null ++++ b/src/tests/asn.1/spake.asn1 +@@ -0,0 +1,44 @@ ++KerberosV5SPAKE { ++ iso(1) identified-organization(3) dod(6) internet(1) ++ security(5) kerberosV5(2) modules(4) spake(8) ++} DEFINITIONS EXPLICIT TAGS ::= BEGIN ++ ++IMPORTS ++ EncryptedData, Int32 ++ FROM KerberosV5Spec2 { iso(1) identified-organization(3) ++ dod(6) internet(1) security(5) kerberosV5(2) modules(4) ++ krb5spec2(2) }; ++ -- as defined in RFC 4120. ++ ++SPAKESupport ::= SEQUENCE { ++ groups [0] SEQUENCE (SIZE(1..MAX)) OF Int32, ++ ... ++} ++ ++SPAKEChallenge ::= SEQUENCE { ++ group [0] Int32, ++ pubkey [1] OCTET STRING, ++ factors [2] SEQUENCE (SIZE(1..MAX)) OF SPAKESecondFactor, ++ ... ++} ++ ++SPAKESecondFactor ::= SEQUENCE { ++ type [0] Int32, ++ data [1] OCTET STRING OPTIONAL ++} ++ ++SPAKEResponse ::= SEQUENCE { ++ pubkey [0] OCTET STRING, ++ factor [1] EncryptedData, -- SPAKESecondFactor ++ ... ++} ++ ++PA-SPAKE ::= CHOICE { ++ support [0] SPAKESupport, ++ challenge [1] SPAKEChallenge, ++ response [2] SPAKEResponse, ++ encdata [3] EncryptedData, ++ ... ++} ++ ++END +diff --git a/src/tests/asn.1/trval_reference.out b/src/tests/asn.1/trval_reference.out +index c27a0425b..e5c715924 100644 +--- a/src/tests/asn.1/trval_reference.out ++++ b/src/tests/asn.1/trval_reference.out +@@ -1584,3 +1584,53 @@ encode_krb5_secure_cookie: + . . [Sequence/Sequence Of] + . . . [1] [Integer] 13 + . . . [2] [Octet String] "pa-data" ++ ++encode_krb5_spake_factor(optionals NULL): ++ ++[Sequence/Sequence Of] ++. [0] [Integer] 1 ++ ++encode_krb5_spake_factor: ++ ++[Sequence/Sequence Of] ++. [0] [Integer] 2 ++. [1] [Octet String] "fdata" ++ ++encode_krb5_pa_spake(support): ++ ++[CONT 0] ++. [Sequence/Sequence Of] ++. . [0] [Sequence/Sequence Of] ++. . . [Integer] 1 ++. . . [Integer] 2 ++ ++encode_krb5_pa_spake(challenge): ++ ++[CONT 1] ++. [Sequence/Sequence Of] ++. . [0] [Integer] 1 ++. . [1] [Octet String] "T value" ++. . [2] [Sequence/Sequence Of] ++. . . [Sequence/Sequence Of] ++. . . . [0] [Integer] 1 ++. . . [Sequence/Sequence Of] ++. . . . [0] [Integer] 2 ++. . . . [1] [Octet String] "fdata" ++ ++encode_krb5_pa_spake(response): ++ ++[CONT 2] ++. [Sequence/Sequence Of] ++. . [0] [Octet String] "S value" ++. . [1] [Sequence/Sequence Of] ++. . . [0] [Integer] 0 ++. . . [1] [Integer] 5 ++. . . [2] [Octet String] "krbASN.1 test message" ++ ++encode_krb5_pa_spake(encdata): ++ ++[CONT 3] ++. [Sequence/Sequence Of] ++. . [0] [Integer] 0 ++. . [1] [Integer] 5 ++. . [2] [Octet String] "krbASN.1 test message" diff --git a/Add-SPAKE-preauth-support.patch b/Add-SPAKE-preauth-support.patch new file mode 100644 index 0000000..e23d35c --- /dev/null +++ b/Add-SPAKE-preauth-support.patch @@ -0,0 +1,14349 @@ +From 0284b6503c003af90b9c317620d38b488dadcf86 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 25 Sep 2015 17:47:35 -0400 +Subject: [PATCH] Add SPAKE preauth support + +This is an implementation of draft-ietf-kitten-krb-spake-preauth-05. +SPAKE preauth authenticates using the client principal long-term key, +but protects against offline dictionary attacks. + +SPAKE preauth negotiates a group for use by the SPAKE2 algorithm. The +edwards25519 group is implemented using code adapted from BoringSSL. +The P-256, P-384, and P-521 groups are implemented against OpenSSL. +edwards25519 is enabled by default on the client; no groups are +enabled by default on the KDC. + +SPAKE preauth can also include a second factor. Second factor support +isn't included in this implementation; comments have been left to +indicate what should change when it is added in. + +Integration tests (tests/t_spake.py) are included with good coverage +of the negotiation scenarios. + +Test vectors from the draft are checked against the group's "result" +operation. The "keygen" operation is inherently random and is +therefore not tested against the vectors, but is effectively exercised +by the integration tests. + +KDC optimistic challenge is implemented. In the future we should +implement client optimistic SPAKE as well; this will require changes +to the generic client preauth framework. + +In the future we should add per-realm configuration to deny encrypted +timestamp and encrypted challenge on a per-realm basis. This +configuration should stick across client realm referrals. + +In the future we should avoid attempting encrypting timestamp or +encrypted challenge if the KDC replies to a single-factor +SPAKEResponse message with PREAUTH_FAILED. This will require a change +to the generic client preauth framework. + +In the future we should make SPAKE support apply to the Windows build, +either by adding support for building plugin DLLs or by moving the +edwards25519 and client code to libkrb5. + +[npmccallum@redhat.com: split up internal headers; split out group +registry contents; implemented P-384 and P-521] + +ticket: 8647 (new) +(cherry picked from commit 7447259401569c92b1fb2e31cb02edbbffd67d35) +--- + NOTICE | 51 + + doc/admin/conf_files/kdc_conf.rst | 22 +- + doc/admin/conf_files/krb5_conf.rst | 15 + + doc/admin/index.rst | 1 + + doc/admin/spake.rst | 46 + + doc/formats/cookie.rst | 37 + + doc/notice.rst | 47 + + src/Makefile.in | 2 + + src/config/pre.in | 6 + + src/configure.in | 20 + + src/include/k5-int.h | 3 + + src/include/krb5/krb5.hin | 2 + + src/kdc/kdc_preauth.c | 2 + + src/lib/krb5/krb/preauth2.c | 2 + + src/lib/krb5/os/trace.c | 1 + + src/plugins/preauth/spake/AUTHORS | 16 + + src/plugins/preauth/spake/Makefile.in | 39 + + src/plugins/preauth/spake/deps | 73 + + src/plugins/preauth/spake/edwards25519.c | 2651 ++++++++ + src/plugins/preauth/spake/edwards25519_tables.h | 7881 +++++++++++++++++++++++ + src/plugins/preauth/spake/groups.c | 442 ++ + src/plugins/preauth/spake/groups.h | 148 + + src/plugins/preauth/spake/iana.c | 108 + + src/plugins/preauth/spake/iana.h | 65 + + src/plugins/preauth/spake/openssl.c | 315 + + src/plugins/preauth/spake/spake.exports | 2 + + src/plugins/preauth/spake/spake_client.c | 363 ++ + src/plugins/preauth/spake/spake_kdc.c | 590 ++ + src/plugins/preauth/spake/t_krb5.conf | 2 + + src/plugins/preauth/spake/t_vectors.c | 476 ++ + src/plugins/preauth/spake/trace.h | 74 + + src/plugins/preauth/spake/util.c | 211 + + src/plugins/preauth/spake/util.h | 56 + + src/tests/Makefile.in | 1 + + src/tests/t_spake.py | 151 + + 35 files changed, 13917 insertions(+), 4 deletions(-) + create mode 100644 doc/admin/spake.rst + create mode 100644 src/plugins/preauth/spake/AUTHORS + create mode 100644 src/plugins/preauth/spake/Makefile.in + create mode 100644 src/plugins/preauth/spake/deps + create mode 100644 src/plugins/preauth/spake/edwards25519.c + create mode 100644 src/plugins/preauth/spake/edwards25519_tables.h + create mode 100644 src/plugins/preauth/spake/groups.c + create mode 100644 src/plugins/preauth/spake/groups.h + create mode 100644 src/plugins/preauth/spake/iana.c + create mode 100644 src/plugins/preauth/spake/iana.h + create mode 100644 src/plugins/preauth/spake/openssl.c + create mode 100644 src/plugins/preauth/spake/spake.exports + create mode 100644 src/plugins/preauth/spake/spake_client.c + create mode 100644 src/plugins/preauth/spake/spake_kdc.c + create mode 100644 src/plugins/preauth/spake/t_krb5.conf + create mode 100644 src/plugins/preauth/spake/t_vectors.c + create mode 100644 src/plugins/preauth/spake/trace.h + create mode 100644 src/plugins/preauth/spake/util.c + create mode 100644 src/plugins/preauth/spake/util.h + create mode 100644 src/tests/t_spake.py + +diff --git a/NOTICE b/NOTICE +index 1db2420a7..9dc1148b1 100644 +--- a/NOTICE ++++ b/NOTICE +@@ -1316,3 +1316,54 @@ The following notice applies to + STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED + OF THE POSSIBILITY OF SUCH DAMAGE. ++ ++====================================================================== ++ ++The following notice applies to portions of ++"src/plugins/preauth/spake/edwards25519.c" and ++"src/plugins/preauth/spake/edwards25519_tables.h": ++ ++The MIT License (MIT) ++ ++Copyright (c) 2015-2016 the fiat-crypto authors (see the AUTHORS ++file). ++ ++Permission is hereby granted, free of charge, to any person obtaining ++a copy of this software and associated documentation files (the ++"Software"), to deal in the Software without restriction, including ++without limitation the rights to use, copy, modify, merge, publish, ++distribute, sublicense, and/or sell copies of the Software, and to ++permit persons to whom the Software is furnished to do so, subject to ++the following conditions: ++ ++The above copyright notice and this permission notice shall be ++included in all copies or substantial portions of the Software. ++ ++THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, ++EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF ++MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. ++IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY ++CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, ++TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE ++SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. ++ ++====================================================================== ++ ++The following notice applies to portions of ++"src/plugins/preauth/spake/edwards25519.c": ++ ++Copyright (c) 2015-2016, Google Inc. ++ ++Permission to use, copy, modify, and/or distribute this software for ++any purpose with or without fee is hereby granted, provided that the ++above copyright notice and this permission notice appear in all ++copies. ++ ++THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL ++WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED ++WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE ++AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL ++DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR ++PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER ++TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR ++PERFORMANCE OF THIS SOFTWARE. +diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst +index 1ac1a37c2..f8cf1be7c 100644 +--- a/doc/admin/conf_files/kdc_conf.rst ++++ b/doc/admin/conf_files/kdc_conf.rst +@@ -43,10 +43,10 @@ The kdc.conf file may contain the following sections: + [kdcdefaults] + ~~~~~~~~~~~~~ + +-With two exceptions, relations in the [kdcdefaults] section specify +-default values for realm variables, to be used if the [realms] +-subsection does not contain a relation for the tag. See the +-:ref:`kdc_realms` section for the definitions of these relations. ++Some relations in the [kdcdefaults] section specify default values for ++realm variables, to be used if the [realms] subsection does not ++contain a relation for the tag. See the :ref:`kdc_realms` section for ++the definitions of these relations. + + * **host_based_services** + * **kdc_listen** +@@ -56,6 +56,8 @@ subsection does not contain a relation for the tag. See the + * **no_host_referral** + * **restrict_anonymous_to_tgt** + ++The following [kdcdefaults] variables have no per-realm equivalent: ++ + **kdc_max_dgram_reply_size** + Specifies the maximum packet size that can be sent over UDP. The + default value is 4096 bytes. +@@ -65,6 +67,12 @@ subsection does not contain a relation for the tag. See the + daemon. The value may be limited by OS settings. The default + value is 5. + ++**spake_preauth_kdc_challenge** ++ (String.) Specifies the group for a SPAKE optimistic challenge. ++ See the **spake_preauth_groups** variable in :ref:`libdefaults` ++ for possible values. The default is not to issue an optimistic ++ challenge. (New in release 1.17.) ++ + + .. _kdc_realms: + +@@ -403,6 +411,12 @@ The following tags may be specified in a [realms] subsection: + without allowing anonymous authentication to services. The + default value is false. New in release 1.9. + ++**spake_preauth_indicator** ++ (String.) Specifies an authentication indicator value that the ++ KDC asserts into tickets obtained using SPAKE pre-authentication. ++ The default is not to add any indicators. This option may be ++ specified multiple times. New in release 1.17. ++ + **supported_enctypes** + (List of *key*:*salt* strings.) Specifies the default key/salt + combinations of principals for this realm. Any principals created +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index 4ed9832c7..8cfe5f458 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -365,6 +365,21 @@ The libdefaults section may contain any of the following relations: + with the session key type. See the **kdc_req_checksum_type** + configuration option for the possible values and their meanings. + ++**spake_preauth_groups** ++ A whitespace or comma-separated list of words which specifies the ++ groups allowed for SPAKE preauthentication. The possible values ++ are: ++ ++ ============ ================================ ++ edwards25519 Edwards25519 curve (:rfc:`7748`) ++ P-256 NIST P-256 curve (:rfc:`5480`) ++ P-384 NIST P-384 curve (:rfc:`5480`) ++ P-521 NIST P-521 curve (:rfc:`5480`) ++ ============ ================================ ++ ++ The default value for the client is ``edwards25519``. The default ++ value for the KDC is empty. New in release 1.17. ++ + **ticket_lifetime** + (:ref:`duration` string.) Sets the default lifetime for initial + ticket requests. The default value is 1 day. +diff --git a/doc/admin/index.rst b/doc/admin/index.rst +index b702f4021..292a64104 100644 +--- a/doc/admin/index.rst ++++ b/doc/admin/index.rst +@@ -15,6 +15,7 @@ For administrators + backup_host.rst + pkinit.rst + otp.rst ++ spake.rst + princ_dns.rst + enctypes.rst + https.rst +diff --git a/doc/admin/spake.rst b/doc/admin/spake.rst +new file mode 100644 +index 000000000..b65c694aa +--- /dev/null ++++ b/doc/admin/spake.rst +@@ -0,0 +1,46 @@ ++SPAKE Preauthentication ++======================= ++ ++SPAKE preauthentication (added in release 1.17) uses public key ++cryptography techniques to protect against password dictionary ++attacks. Unlike :ref:`PKINIT `, it does not require any ++additional infrastructure such as certificates; it simply needs to be ++turned on. Using SPAKE preauthentication may modestly increase the ++CPU and network load on the KDC. ++ ++SPAKE preauthentication can use one of four elliptic curve groups for ++its password-authenticated key exchange. The recommended group is ++``edwards25519``; three NIST curves (``P-256``, ``P-384``, and ++``P-521``) are also supported. ++ ++By default, SPAKE with the ``edwards25519`` group is enabled on ++clients, but the KDC does not offer SPAKE by default. To turn it on, ++set the **spake_preauth_groups** variable in :ref:`libdefaults` to a ++list of allowed groups. This variable affects both the client and the ++KDC. Simply setting it to ``edwards25519`` is recommended:: ++ ++ [libdefaults] ++ spake_preauth_groups = edwards25519 ++ ++Set the **+requires_preauth** and **-allow_svr** flags on client ++principal entries, as you would for any preauthentication mechanism:: ++ ++ kadmin: modprinc +requires_preauth -allow_srv PRINCNAME ++ ++Clients which do not implement SPAKE preauthentication will fall back ++to encrypted timestamp. ++ ++By default, SPAKE preauthentication requires an extra network round ++trip to the KDC during initial authentication. If most of the clients ++in a realm support SPAKE, this extra round trip can be eliminated ++using an optimistic challenge, by setting the ++**spake_preauth_kdc_challenge** variable in :ref:`kdcdefaults` to a ++single group name:: ++ ++ [kdcdefaults] ++ spake_preauth_kdc_challenge = edwards25519 ++ ++Using optimistic challenge will cause the KDC to do extra work for ++initial authentication requests that do not result in SPAKE ++preauthentication, but will save work when SPAKE preauthentication is ++used. +diff --git a/doc/formats/cookie.rst b/doc/formats/cookie.rst +index 640955c90..e32365daa 100644 +--- a/doc/formats/cookie.rst ++++ b/doc/formats/cookie.rst +@@ -58,3 +58,40 @@ mechanisms which have separate request and reply types, the request + type is used; this allows the KDC to determine whether a cookie is + relevant to a request by comparing the request pa-data types to the + cookie data types. ++ ++SPAKE cookie format (version 1) ++------------------------------- ++ ++Inside the SecureCookie wrapper, a data value of type 151 contains ++state for SPAKE pre-authentication. This data is the concatenation of ++the following: ++ ++* a two-byte big-endian version number with the value 1 ++* a two-byte big-endian stage number ++* a four-byte big-endian group number ++* a four-byte big-endian length and data for the SPAKE value ++* a four-byte big-endian length and data for the transcript hash ++* zero or more second factor records, each consisting of: ++ - a four-byte big-endian second-factor type ++ - a four-byte big-endian length and data ++ ++The stage value is 0 if the cookie was sent with a challenge message. ++Otherwise it is 1 for the first encdata message sent by the KDC during ++an exchange, 2 for the second, etc.. ++ ++The group value indicates the group number used in the SPAKE challenge. ++ ++For a stage-0 cookie, the SPAKE value is the KDC private key, ++represented in the scalar marshalling form of the group. For other ++cookies, the SPAKE value is the SPAKE result K, represented in the ++group element marshalling form. ++ ++For a stage-0 cookie, the transcript hash is the intermediate hash ++after updating with the client support message (if one was sent) and ++challenge. For other cookies it is the final hash. ++ ++For a stage-0 cookie, there may be any number of second-factor ++records, including none; a second-factor type need not create a state ++field if it does not need one, and no record is created for SF-NONE. ++For other cookies, there must be exactly one second-factor record ++corresponding to the factor type chosen by the client. +diff --git a/doc/notice.rst b/doc/notice.rst +index 26011550b..cacfd659a 100644 +--- a/doc/notice.rst ++++ b/doc/notice.rst +@@ -1237,3 +1237,50 @@ The following notice applies to + STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED + OF THE POSSIBILITY OF SUCH DAMAGE. ++ ++------------------- ++ ++The following notice applies to portions of ++``src/plugins/preauth/spake/edwards25519.c`` and ++``src/plugins/preauth/spake/edwards25519_tables.h``: ++ ++The MIT License (MIT) ++ ++Copyright (c) 2015-2016 the fiat-crypto authors (see the AUTHORS file). ++ ++Permission is hereby granted, free of charge, to any person obtaining a copy ++of this software and associated documentation files (the "Software"), to ++deal in the Software without restriction, including without limitation the ++rights to use, copy, modify, merge, publish, distribute, sublicense, and/or ++sell copies of the Software, and to permit persons to whom the Software is ++furnished to do so, subject to the following conditions: ++ ++The above copyright notice and this permission notice shall be included in ++all copies or substantial portions of the Software. ++ ++THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR ++IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, ++FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE ++AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER ++LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING ++FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS ++IN THE SOFTWARE. ++ ++------------------- ++ ++The following notice applies to portions of ++``src/plugins/preauth/spake/edwards25519.c``: ++ ++Copyright (c) 2015-2016, Google Inc. ++ ++Permission to use, copy, modify, and/or distribute this software for any ++purpose with or without fee is hereby granted, provided that the above ++copyright notice and this permission notice appear in all copies. ++ ++THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES ++WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF ++MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY ++SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES ++WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION ++OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN ++CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. +diff --git a/src/Makefile.in b/src/Makefile.in +index ac9a2a060..77beff8bc 100644 +--- a/src/Makefile.in ++++ b/src/Makefile.in +@@ -25,6 +25,7 @@ SUBDIRS=util include lib \ + plugins/kdcpolicy/test \ + plugins/preauth/otp \ + plugins/preauth/pkinit \ ++ plugins/preauth/spake \ + plugins/preauth/test \ + plugins/tls/k5tls \ + kdc kadmin slave clients appl tests \ +@@ -523,6 +524,7 @@ pyrunenv.vals: Makefile + done > $@ + echo "tls_impl = '$(TLS_IMPL)'" >> $@ + echo "have_sasl = '$(HAVE_SASL)'" >> $@ ++ echo "have_spake_openssl = '$(HAVE_SPAKE_OPENSSL)'" >> $@ + echo "sizeof_time_t = $(SIZEOF_TIME_T)" >> $@ + + runenv.py: pyrunenv.vals +diff --git a/src/config/pre.in b/src/config/pre.in +index 03f5c8890..6317d3564 100644 +--- a/src/config/pre.in ++++ b/src/config/pre.in +@@ -441,9 +441,15 @@ TLS_IMPL = @TLS_IMPL@ + TLS_IMPL_CFLAGS = @TLS_IMPL_CFLAGS@ + TLS_IMPL_LIBS = @TLS_IMPL_LIBS@ + ++# SPAKE preauth back-end libraries ++SPAKE_OPENSSL_LIBS = @SPAKE_OPENSSL_LIBS@ ++ + # Whether we have the SASL header file for the LDAP KDB module + HAVE_SASL = @HAVE_SASL@ + ++# Whether we are building support for NIST SPAKE groups using OpenSSL ++HAVE_SPAKE_OPENSSL = @HAVE_SPAKE_OPENSSL@ ++ + # Whether we have libresolv 1.1.5 for URI discovery tests + HAVE_RESOLV_WRAPPER = @HAVE_RESOLV_WRAPPER@ + +diff --git a/src/configure.in b/src/configure.in +index 2b6d5baa7..08c63beca 100644 +--- a/src/configure.in ++++ b/src/configure.in +@@ -321,6 +321,25 @@ AC_SUBST(TLS_IMPL) + AC_SUBST(TLS_IMPL_CFLAGS) + AC_SUBST(TLS_IMPL_LIBS) + ++# The SPAKE preauth plugin currently supports edwards25519 natively, ++# and can support three NIST groups using OpenSSL. ++HAVE_SPAKE_OPENSSL=no ++AC_ARG_WITH([spake-openssl], ++AC_HELP_STRING([--with-spake-openssl], ++ [use OpenSSL for SPAKE preauth @<:@auto@:>@]),,[withval=auto]) ++if test "$withval" = auto -o "$withval" = yes; then ++ AC_CHECK_LIB([crypto],[EC_POINT_new],[have_crypto=true],[have_crypto=false]) ++ if test "$have_crypto" = true; then ++ AC_DEFINE(SPAKE_OPENSSL,1,[Define to use OpenSSL for SPAKE preauth]) ++ SPAKE_OPENSSL_LIBS=-lcrypto ++ HAVE_SPAKE_OPENSSL=yes ++ elif test "$withval" = yes; then ++ AC_MSG_ERROR([OpenSSL libcrypto not found]) ++ fi ++fi ++AC_SUBST(HAVE_SPAKE_OPENSSL) ++AC_SUBST(SPAKE_OPENSSL_LIBS) ++ + AC_ARG_ENABLE([aesni], + AC_HELP_STRING([--disable-aesni],[Do not build with AES-NI support]), , + enable_aesni=check) +@@ -1440,6 +1459,7 @@ dnl ccapi ccapi/lib ccapi/lib/unix ccapi/server ccapi/server/unix ccapi/test + plugins/kdb/test + plugins/kdcpolicy/test + plugins/preauth/otp ++ plugins/preauth/spake + plugins/preauth/test + plugins/authdata/greet_client + plugins/authdata/greet_server +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 69b81a7f7..86b53c76b 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -286,6 +286,9 @@ typedef unsigned char u_char; + #define KRB5_CONF_RESTRICT_ANONYMOUS_TO_TGT "restrict_anonymous_to_tgt" + #define KRB5_CONF_SAFE_CHECKSUM_TYPE "safe_checksum_type" + #define KRB5_CONF_SUPPORTED_ENCTYPES "supported_enctypes" ++#define KRB5_CONF_SPAKE_PREAUTH_INDICATOR "spake_preauth_indicator" ++#define KRB5_CONF_SPAKE_PREAUTH_KDC_CHALLENGE "spake_preauth_kdc_challenge" ++#define KRB5_CONF_SPAKE_PREAUTH_GROUPS "spake_preauth_groups" + #define KRB5_CONF_TICKET_LIFETIME "ticket_lifetime" + #define KRB5_CONF_UDP_PREFERENCE_LIMIT "udp_preference_limit" + #define KRB5_CONF_UNLOCKITER "unlockiter" +diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin +index a650ecece..cea22dcac 100644 +--- a/src/include/krb5/krb5.hin ++++ b/src/include/krb5/krb5.hin +@@ -1034,6 +1034,7 @@ krb5_c_keyed_checksum_types(krb5_context context, krb5_enctype enctype, + #define KRB5_KEYUSAGE_ENC_CHALLENGE_KDC 55 + #define KRB5_KEYUSAGE_AS_REQ 56 + #define KRB5_KEYUSAGE_CAMMAC 64 ++#define KRB5_KEYUSAGE_SPAKE 65 + + /* Key usage values 512-1023 are reserved for uses internal to a Kerberos + * implementation. */ +@@ -1883,6 +1884,7 @@ krb5_verify_checksum(krb5_context context, krb5_cksumtype ctype, + #define KRB5_PADATA_PKINIT_KX 147 /**< RFC 6112 */ + #define KRB5_ENCPADATA_REQ_ENC_PA_REP 149 /**< RFC 6806 */ + #define KRB5_PADATA_AS_FRESHNESS 150 /**< RFC 8070 */ ++#define KRB5_PADATA_SPAKE 151 + + #define KRB5_SAM_USE_SAD_AS_KEY 0x80000000 + #define KRB5_SAM_SEND_ENCRYPTED_SAD 0x40000000 +diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c +index 62ff9a8a7..86b9e2991 100644 +--- a/src/kdc/kdc_preauth.c ++++ b/src/kdc/kdc_preauth.c +@@ -131,6 +131,8 @@ get_plugin_vtables(krb5_context context, + "preauth"); + k5_plugin_register_dyn(context, PLUGIN_INTERFACE_KDCPREAUTH, "otp", + "preauth"); ++ k5_plugin_register_dyn(context, PLUGIN_INTERFACE_KDCPREAUTH, "spake", ++ "preauth"); + k5_plugin_register(context, PLUGIN_INTERFACE_KDCPREAUTH, + "encrypted_challenge", + kdcpreauth_encrypted_challenge_initvt); +diff --git a/src/lib/krb5/krb/preauth2.c b/src/lib/krb5/krb/preauth2.c +index 6b96fa135..451e0b7a8 100644 +--- a/src/lib/krb5/krb/preauth2.c ++++ b/src/lib/krb5/krb/preauth2.c +@@ -132,6 +132,8 @@ k5_init_preauth_context(krb5_context context) + /* Auto-register built-in modules. */ + k5_plugin_register_dyn(context, PLUGIN_INTERFACE_CLPREAUTH, "pkinit", + "preauth"); ++ k5_plugin_register_dyn(context, PLUGIN_INTERFACE_CLPREAUTH, "spake", ++ "preauth"); + k5_plugin_register(context, PLUGIN_INTERFACE_CLPREAUTH, + "encrypted_challenge", + clpreauth_encrypted_challenge_initvt); +diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c +index 10b4f0c14..40a9e7b10 100644 +--- a/src/lib/krb5/os/trace.c ++++ b/src/lib/krb5/os/trace.c +@@ -163,6 +163,7 @@ padata_type_string(krb5_preauthtype type) + case KRB5_PADATA_PKINIT_KX: return "PA-PKINIT-KX"; + case KRB5_ENCPADATA_REQ_ENC_PA_REP: return "PA-REQ-ENC-PA-REP"; + case KRB5_PADATA_AS_FRESHNESS: return "PA_AS_FRESHNESS"; ++ case KRB5_PADATA_SPAKE: return "PA-SPAKE"; + default: return NULL; + } + } +diff --git a/src/plugins/preauth/spake/AUTHORS b/src/plugins/preauth/spake/AUTHORS +new file mode 100644 +index 000000000..31d71c211 +--- /dev/null ++++ b/src/plugins/preauth/spake/AUTHORS +@@ -0,0 +1,16 @@ ++# This is the official list of fiat-crypto authors for copyright purposes. ++# This file is distinct from the CONTRIBUTORS files. ++# See the latter for an explanation. ++ ++# Names should be added to this file as one of ++# Organization's name ++# Individual's name ++# Individual's name ++# See CONTRIBUTORS for the meaning of multiple email addresses. ++ ++# Please keep the list sorted. ++ ++Andres Erbsen ++Google Inc. ++Jade Philipoom ++Massachusetts Institute of Technology +diff --git a/src/plugins/preauth/spake/Makefile.in b/src/plugins/preauth/spake/Makefile.in +new file mode 100644 +index 000000000..dd1b90730 +--- /dev/null ++++ b/src/plugins/preauth/spake/Makefile.in +@@ -0,0 +1,39 @@ ++mydir=plugins$(S)preauth$(S)spake ++BUILDTOP=$(REL)..$(S)..$(S).. ++MODULE_INSTALL_DIR = $(KRB5_PA_MODULE_DIR) ++ ++# Like RUN_TEST, but use t_krb5.conf from this directory. ++RUN_TEST_LOCAL_CONF=$(RUN_SETUP) KRB5_CONFIG=$(srcdir)/t_krb5.conf LC_ALL=C \ ++ $(VALGRIND) ++ ++LIBBASE=spake ++LIBMAJOR=0 ++LIBMINOR=0 ++RELDIR=../plugins/preauth/spake ++SHLIB_EXPDEPS=$(KRB5_BASE_DEPLIBS) ++SHLIB_EXPLIBS=$(KRB5_BASE_LIBS) $(SPAKE_OPENSSL_LIBS) ++ ++STLIBOBJS=util.o iana.o groups.o openssl.o edwards25519.o \ ++ spake_client.o spake_kdc.o ++ ++SRCS= \ ++ $(srcdir)/util.c \ ++ $(srcdir)/iana.c \ ++ $(srcdir)/groups.c \ ++ $(srcdir)/openssl.c \ ++ $(srcdir)/edwards25519.c \ ++ $(srcdir)/spake_client.c \ ++ $(srcdir)/spake_kdc.c ++ ++t_vectors: t_vectors.o $(STLIBOBJS) $(SHLIB_EXPDEPS) ++ $(CC_LINK) -o $@ t_vectors.o $(STLIBOBJS) $(SHLIB_EXPLIBS) ++ ++all-unix: all-liblinks ++install-unix: install-libs ++clean-unix:: clean-liblinks clean-libs clean-libobjs ++ ++check-unix: t_vectors ++ $(RUN_TEST_LOCAL_CONF) ./t_vectors ++ ++@libnover_frag@ ++@libobj_frag@ +diff --git a/src/plugins/preauth/spake/deps b/src/plugins/preauth/spake/deps +new file mode 100644 +index 000000000..ce636af66 +--- /dev/null ++++ b/src/plugins/preauth/spake/deps +@@ -0,0 +1,73 @@ ++# ++# Generated makefile dependencies follow. ++# ++util.so util.po $(OUTPRE)util.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ ++ $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ ++ $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ ++ $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ ++ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ ++ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ ++ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ ++ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ ++ $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ ++ $(top_srcdir)/include/socket-utils.h groups.h iana.h \ ++ trace.h util.c util.h ++iana.so iana.po $(OUTPRE)iana.$(OBJEXT): iana.c iana.h ++groups.so groups.po $(OUTPRE)groups.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ ++ $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ ++ $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ ++ $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ ++ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ ++ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ ++ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ ++ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ ++ $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ ++ $(top_srcdir)/include/socket-utils.h groups.c groups.h \ ++ iana.h trace.h ++openssl.so openssl.po $(OUTPRE)openssl.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ ++ $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ ++ $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ ++ $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ ++ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ ++ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ ++ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ ++ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ ++ $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ ++ $(top_srcdir)/include/socket-utils.h groups.h iana.h \ ++ openssl.c ++edwards25519.so edwards25519.po $(OUTPRE)edwards25519.$(OBJEXT): \ ++ $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ ++ $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ ++ $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ ++ $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ ++ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ ++ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ ++ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ ++ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ ++ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ ++ edwards25519.c edwards25519_tables.h groups.h iana.h ++spake_client.so spake_client.po $(OUTPRE)spake_client.$(OBJEXT): \ ++ $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ ++ $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ ++ $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ ++ $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ ++ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ ++ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-spake.h \ ++ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ ++ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ ++ $(top_srcdir)/include/krb5/clpreauth_plugin.h $(top_srcdir)/include/krb5/plugin.h \ ++ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ ++ groups.h iana.h spake_client.c trace.h util.h ++spake_kdc.so spake_kdc.po $(OUTPRE)spake_kdc.$(OBJEXT): \ ++ $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ ++ $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ ++ $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ ++ $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-input.h \ ++ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ ++ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ ++ $(top_srcdir)/include/k5-spake.h $(top_srcdir)/include/k5-thread.h \ ++ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ ++ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/kdcpreauth_plugin.h \ ++ $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ ++ $(top_srcdir)/include/socket-utils.h groups.h iana.h \ ++ spake_kdc.c trace.h util.h +diff --git a/src/plugins/preauth/spake/edwards25519.c b/src/plugins/preauth/spake/edwards25519.c +new file mode 100644 +index 000000000..fd228d9d4 +--- /dev/null ++++ b/src/plugins/preauth/spake/edwards25519.c +@@ -0,0 +1,2651 @@ ++/* -*- mode: c; c-basic-offset: 2; indent-tabs-mode: nil -*- */ ++/* This file is adapted from the SPAKE edwards25519 code in BoringSSL. */ ++/* ++ * The MIT License (MIT) ++ * ++ * Copyright (c) 2015-2016 the fiat-crypto authors (see the AUTHORS file). ++ * ++ * Permission is hereby granted, free of charge, to any person obtaining a copy ++ * of this software and associated documentation files (the "Software"), to ++ * deal in the Software without restriction, including without limitation the ++ * rights to use, copy, modify, merge, publish, distribute, sublicense, and/or ++ * sell copies of the Software, and to permit persons to whom the Software is ++ * furnished to do so, subject to the following conditions: ++ * ++ * The above copyright notice and this permission notice shall be included in ++ * all copies or substantial portions of the Software. ++ * ++ * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR ++ * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, ++ * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE ++ * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER ++ * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING ++ * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS ++ * IN THE SOFTWARE. ++ */ ++/* ++ * Copyright (c) 2015-2016, Google Inc. ++ * ++ * Permission to use, copy, modify, and/or distribute this software for any ++ * purpose with or without fee is hereby granted, provided that the above ++ * copyright notice and this permission notice appear in all copies. ++ * ++ * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES ++ * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF ++ * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY ++ * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES ++ * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION ++ * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN ++ * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. ++ */ ++ ++/* ++ * This code is adapted from the BoringSSL edwards25519 SPAKE2 implementation ++ * from third_party/fiat and crypto/spake25519.c, with the following ++ * adaptations: ++ * ++ * - The M and N points are the ones from draft-irtf-cfrg-spake2-05. The ++ * BoringSSL M and N points were determined similarly, but were not ++ * restricted to members of the generator subgroup, so they use only one hash ++ * iteration for both points. The intent in BoringSSL had been to multiply w ++ * by the cofactor so that wM and wN would be in the subgroup, but as that ++ * step was accidentally omitted, a hack had to be introduced after the fact ++ * to add multiples of the prime order to the scalar. That hack is not ++ * present in this code, and the SPAKE preauth spec does not multiply w by ++ * the cofactor as it is unnecessary if M and N are chosen from the subgroup. ++ * ++ * - The SPAKE code is modified to fit the groups.h interface and the SPAKE ++ * preauth spec. ++ * ++ * - The required declarations and code are all here in one file (except for ++ * the generator point table, which is still in a separate header), so all of ++ * the functions are declared static. ++ * ++ * - BORINGSSL_CURVE25519_64BIT is defined here using preprocessor conditionals ++ * derived from the BoringSSL headers. ++ * ++ * - The field element bounds assertion checks are disabled by default, as they ++ * slow the code down by roughly a factor of two. The ++ * OPENSSL_COMPILE_ASSERT() in fe_copy_lt() is changed to a regular assert ++ * and is also conditionalized. Do a build and "make check" with ++ * EDWARDS25519_ASSERTS defined when updating this code. ++ * ++ * - The copyright comments at the top are formatted the way we do so in other ++ * source files, for ease of extraction. ++ * ++ * - Declarations in for loops conflict with our compiler configuration in ++ * older versions of gcc, so they are moved outside of the for loop. ++ * ++ * - The preprocessor symbol OPENSSL_SMALL is changed to CONFIG_SMALL. ++ * ++ * - OPENSSL_memset and OPENSSL_memmove are changed to memset and memmove, in ++ * each case verifying that they are used with nonzero length arguments. ++ * ++ * - CRYPTO_memcmp is changed to k5_bcmp. ++ * ++ * - Functions used only by X25519 or Ed25519 interfaces but not SPAKE are ++ * removed, taking care to check for unused functions in both the 64-bit and ++ * 32-bit preprocessor branches. ge_p3_dbl() is unused here if CONFIG_SMALL ++ * is defined, so it is placed inside #ifndef CONFIG_SMALL. ++ */ ++ ++// Some of this code is taken from the ref10 version of Ed25519 in SUPERCOP ++// 20141124 (http://bench.cr.yp.to/supercop.html). That code is released as ++// public domain but parts have been replaced with code generated by Fiat ++// (https://github.com/mit-plv/fiat-crypto), which is MIT licensed. ++ ++#include "groups.h" ++#include "iana.h" ++ ++#ifdef __GNUC__ ++#pragma GCC diagnostic ignored "-Wdeclaration-after-statement" ++#endif ++ ++/* ++ * These preprocessor conditionals are derived the BoringSSL ++ * include/openssl/base.h (OPENSSL_64_BIT) and crypto/internal.h ++ * (BORINGSSL_HAS_UINT128). ++ */ ++#if defined(__x86_64) || defined(_M_AMD64) || defined(_M_X64) || defined(__aarch64__) || ((defined(__PPC64__) || defined(__powerpc64__)) && defined(_LITTLE_ENDIAN)) || defined(__mips__) && defined(__LP64__) ++#if !defined(_MSC_VER) || defined(__clang__) ++#define BORINGSSL_CURVE25519_64BIT ++typedef __int128_t int128_t; ++typedef __uint128_t uint128_t; ++#endif ++#endif ++ ++#ifndef EDWARDS25519_ASSERTS ++#define assert_fe(f) ++#define assert_fe_loose(f) ++#define assert_fe_frozen(f) ++#endif ++ ++/* From BoringSSL third-party/fiat/internal.h */ ++ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++// fe means field element. Here the field is \Z/(2^255-19). An element t, ++// entries t[0]...t[4], represents the integer t[0]+2^51 t[1]+2^102 t[2]+2^153 ++// t[3]+2^204 t[4]. ++// fe limbs are bounded by 1.125*2^51. ++// Multiplication and carrying produce fe from fe_loose. ++typedef struct fe { uint64_t v[5]; } fe; ++ ++// fe_loose limbs are bounded by 3.375*2^51. ++// Addition and subtraction produce fe_loose from (fe, fe). ++typedef struct fe_loose { uint64_t v[5]; } fe_loose; ++#else ++// fe means field element. Here the field is \Z/(2^255-19). An element t, ++// entries t[0]...t[9], represents the integer t[0]+2^26 t[1]+2^51 t[2]+2^77 ++// t[3]+2^102 t[4]+...+2^230 t[9]. ++// fe limbs are bounded by 1.125*2^26,1.125*2^25,1.125*2^26,1.125*2^25,etc. ++// Multiplication and carrying produce fe from fe_loose. ++typedef struct fe { uint32_t v[10]; } fe; ++ ++// fe_loose limbs are bounded by 3.375*2^26,3.375*2^25,3.375*2^26,3.375*2^25,etc. ++// Addition and subtraction produce fe_loose from (fe, fe). ++typedef struct fe_loose { uint32_t v[10]; } fe_loose; ++#endif ++ ++// ge means group element. ++// ++// Here the group is the set of pairs (x,y) of field elements (see fe.h) ++// satisfying -x^2 + y^2 = 1 + d x^2y^2 ++// where d = -121665/121666. ++// ++// Representations: ++// ge_p2 (projective): (X:Y:Z) satisfying x=X/Z, y=Y/Z ++// ge_p3 (extended): (X:Y:Z:T) satisfying x=X/Z, y=Y/Z, XY=ZT ++// ge_p1p1 (completed): ((X:Z),(Y:T)) satisfying x=X/Z, y=Y/T ++// ge_precomp (Duif): (y+x,y-x,2dxy) ++ ++typedef struct { ++ fe X; ++ fe Y; ++ fe Z; ++} ge_p2; ++ ++typedef struct { ++ fe X; ++ fe Y; ++ fe Z; ++ fe T; ++} ge_p3; ++ ++typedef struct { ++ fe_loose X; ++ fe_loose Y; ++ fe_loose Z; ++ fe_loose T; ++} ge_p1p1; ++ ++typedef struct { ++ fe_loose yplusx; ++ fe_loose yminusx; ++ fe_loose xy2d; ++} ge_precomp; ++ ++typedef struct { ++ fe_loose YplusX; ++ fe_loose YminusX; ++ fe_loose Z; ++ fe_loose T2d; ++} ge_cached; ++ ++#include "edwards25519_tables.h" ++ ++/* From BoringSSL third-party/fiat/curve25519.c */ ++ ++static uint64_t load_3(const uint8_t *in) { ++ uint64_t result; ++ result = (uint64_t)in[0]; ++ result |= ((uint64_t)in[1]) << 8; ++ result |= ((uint64_t)in[2]) << 16; ++ return result; ++} ++ ++static uint64_t load_4(const uint8_t *in) { ++ uint64_t result; ++ result = (uint64_t)in[0]; ++ result |= ((uint64_t)in[1]) << 8; ++ result |= ((uint64_t)in[2]) << 16; ++ result |= ((uint64_t)in[3]) << 24; ++ return result; ++} ++ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++static uint64_t load_8(const uint8_t *in) { ++ uint64_t result; ++ result = (uint64_t)in[0]; ++ result |= ((uint64_t)in[1]) << 8; ++ result |= ((uint64_t)in[2]) << 16; ++ result |= ((uint64_t)in[3]) << 24; ++ result |= ((uint64_t)in[4]) << 32; ++ result |= ((uint64_t)in[5]) << 40; ++ result |= ((uint64_t)in[6]) << 48; ++ result |= ((uint64_t)in[7]) << 56; ++ return result; ++} ++ ++static uint8_t /*bool*/ addcarryx_u51(uint8_t /*bool*/ c, uint64_t a, ++ uint64_t b, uint64_t *low) { ++ // This function extracts 51 bits of result and 1 bit of carry (52 total), so ++ // a 64-bit intermediate is sufficient. ++ uint64_t x = a + b + c; ++ *low = x & ((UINT64_C(1) << 51) - 1); ++ return (x >> 51) & 1; ++} ++ ++static uint8_t /*bool*/ subborrow_u51(uint8_t /*bool*/ c, uint64_t a, ++ uint64_t b, uint64_t *low) { ++ // This function extracts 51 bits of result and 1 bit of borrow (52 total), so ++ // a 64-bit intermediate is sufficient. ++ uint64_t x = a - b - c; ++ *low = x & ((UINT64_C(1) << 51) - 1); ++ return x >> 63; ++} ++ ++static uint64_t cmovznz64(uint64_t t, uint64_t z, uint64_t nz) { ++ t = -!!t; // all set if nonzero, 0 if 0 ++ return (t&nz) | ((~t)&z); ++} ++ ++#else ++ ++static uint8_t /*bool*/ addcarryx_u25(uint8_t /*bool*/ c, uint32_t a, ++ uint32_t b, uint32_t *low) { ++ // This function extracts 25 bits of result and 1 bit of carry (26 total), so ++ // a 32-bit intermediate is sufficient. ++ uint32_t x = a + b + c; ++ *low = x & ((1 << 25) - 1); ++ return (x >> 25) & 1; ++} ++ ++static uint8_t /*bool*/ addcarryx_u26(uint8_t /*bool*/ c, uint32_t a, ++ uint32_t b, uint32_t *low) { ++ // This function extracts 26 bits of result and 1 bit of carry (27 total), so ++ // a 32-bit intermediate is sufficient. ++ uint32_t x = a + b + c; ++ *low = x & ((1 << 26) - 1); ++ return (x >> 26) & 1; ++} ++ ++static uint8_t /*bool*/ subborrow_u25(uint8_t /*bool*/ c, uint32_t a, ++ uint32_t b, uint32_t *low) { ++ // This function extracts 25 bits of result and 1 bit of borrow (26 total), so ++ // a 32-bit intermediate is sufficient. ++ uint32_t x = a - b - c; ++ *low = x & ((1 << 25) - 1); ++ return x >> 31; ++} ++ ++static uint8_t /*bool*/ subborrow_u26(uint8_t /*bool*/ c, uint32_t a, ++ uint32_t b, uint32_t *low) { ++ // This function extracts 26 bits of result and 1 bit of borrow (27 total), so ++ // a 32-bit intermediate is sufficient. ++ uint32_t x = a - b - c; ++ *low = x & ((1 << 26) - 1); ++ return x >> 31; ++} ++ ++static uint32_t cmovznz32(uint32_t t, uint32_t z, uint32_t nz) { ++ t = -!!t; // all set if nonzero, 0 if 0 ++ return (t&nz) | ((~t)&z); ++} ++ ++#endif ++ ++ ++// Field operations. ++ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ ++#ifdef EDWARDS25519_ASSERTS ++#define assert_fe(f) do { \ ++ unsigned _assert_fe_i; \ ++ for (_assert_fe_i = 0; _assert_fe_i< 5; _assert_fe_i++) { \ ++ assert(f[_assert_fe_i] < 1.125*(UINT64_C(1)<<51)); \ ++ } \ ++} while (0) ++ ++#define assert_fe_loose(f) do { \ ++ unsigned _assert_fe_i; \ ++ for (_assert_fe_i = 0; _assert_fe_i< 5; _assert_fe_i++) { \ ++ assert(f[_assert_fe_i] < 3.375*(UINT64_C(1)<<51)); \ ++ } \ ++} while (0) ++ ++#define assert_fe_frozen(f) do { \ ++ unsigned _assert_fe_i; \ ++ for (_assert_fe_i = 0; _assert_fe_i< 5; _assert_fe_i++) { \ ++ assert(f[_assert_fe_i] < (UINT64_C(1)<<51)); \ ++ } \ ++} while (0) ++#endif /* EDWARDS25519_ASSERTS */ ++ ++static void fe_frombytes_impl(uint64_t h[5], const uint8_t *s) { ++ // Ignores top bit of s. ++ uint64_t a0 = load_8(s); ++ uint64_t a1 = load_8(s+8); ++ uint64_t a2 = load_8(s+16); ++ uint64_t a3 = load_8(s+24); ++ // Use 51 bits, 64-51 = 13 left. ++ h[0] = a0 & ((UINT64_C(1) << 51) - 1); ++ // (64-51) + 38 = 13 + 38 = 51 ++ h[1] = (a0 >> 51) | ((a1 & ((UINT64_C(1) << 38) - 1)) << 13); ++ // (64-38) + 25 = 26 + 25 = 51 ++ h[2] = (a1 >> 38) | ((a2 & ((UINT64_C(1) << 25) - 1)) << 26); ++ // (64-25) + 12 = 39 + 12 = 51 ++ h[3] = (a2 >> 25) | ((a3 & ((UINT64_C(1) << 12) - 1)) << 39); ++ // (64-12) = 52, ignore top bit ++ h[4] = (a3 >> 12) & ((UINT64_C(1) << 51) - 1); ++ assert_fe(h); ++} ++ ++static void fe_frombytes(fe *h, const uint8_t *s) { ++ fe_frombytes_impl(h->v, s); ++} ++ ++static void fe_freeze(uint64_t out[5], const uint64_t in1[5]) { ++ { const uint64_t x7 = in1[4]; ++ { const uint64_t x8 = in1[3]; ++ { const uint64_t x6 = in1[2]; ++ { const uint64_t x4 = in1[1]; ++ { const uint64_t x2 = in1[0]; ++ { uint64_t x10; uint8_t/*bool*/ x11 = subborrow_u51(0x0, x2, 0x7ffffffffffed, &x10); ++ { uint64_t x13; uint8_t/*bool*/ x14 = subborrow_u51(x11, x4, 0x7ffffffffffff, &x13); ++ { uint64_t x16; uint8_t/*bool*/ x17 = subborrow_u51(x14, x6, 0x7ffffffffffff, &x16); ++ { uint64_t x19; uint8_t/*bool*/ x20 = subborrow_u51(x17, x8, 0x7ffffffffffff, &x19); ++ { uint64_t x22; uint8_t/*bool*/ x23 = subborrow_u51(x20, x7, 0x7ffffffffffff, &x22); ++ { uint64_t x24 = cmovznz64(x23, 0x0, 0xffffffffffffffffL); ++ { uint64_t x25 = (x24 & 0x7ffffffffffed); ++ { uint64_t x27; uint8_t/*bool*/ x28 = addcarryx_u51(0x0, x10, x25, &x27); ++ { uint64_t x29 = (x24 & 0x7ffffffffffff); ++ { uint64_t x31; uint8_t/*bool*/ x32 = addcarryx_u51(x28, x13, x29, &x31); ++ { uint64_t x33 = (x24 & 0x7ffffffffffff); ++ { uint64_t x35; uint8_t/*bool*/ x36 = addcarryx_u51(x32, x16, x33, &x35); ++ { uint64_t x37 = (x24 & 0x7ffffffffffff); ++ { uint64_t x39; uint8_t/*bool*/ x40 = addcarryx_u51(x36, x19, x37, &x39); ++ { uint64_t x41 = (x24 & 0x7ffffffffffff); ++ { uint64_t x43; addcarryx_u51(x40, x22, x41, &x43); ++ out[0] = x27; ++ out[1] = x31; ++ out[2] = x35; ++ out[3] = x39; ++ out[4] = x43; ++ }}}}}}}}}}}}}}}}}}}}} ++} ++ ++static void fe_tobytes(uint8_t s[32], const fe *f) { ++ assert_fe(f->v); ++ uint64_t h[5]; ++ fe_freeze(h, f->v); ++ assert_fe_frozen(h); ++ ++ s[0] = h[0] >> 0; ++ s[1] = h[0] >> 8; ++ s[2] = h[0] >> 16; ++ s[3] = h[0] >> 24; ++ s[4] = h[0] >> 32; ++ s[5] = h[0] >> 40; ++ s[6] = (h[0] >> 48) | (h[1] << 3); ++ s[7] = h[1] >> 5; ++ s[8] = h[1] >> 13; ++ s[9] = h[1] >> 21; ++ s[10] = h[1] >> 29; ++ s[11] = h[1] >> 37; ++ s[12] = (h[1] >> 45) | (h[2] << 6); ++ s[13] = h[2] >> 2; ++ s[14] = h[2] >> 10; ++ s[15] = h[2] >> 18; ++ s[16] = h[2] >> 26; ++ s[17] = h[2] >> 34; ++ s[18] = h[2] >> 42; ++ s[19] = (h[2] >> 50) | (h[3] << 1); ++ s[20] = h[3] >> 7; ++ s[21] = h[3] >> 15; ++ s[22] = h[3] >> 23; ++ s[23] = h[3] >> 31; ++ s[24] = h[3] >> 39; ++ s[25] = (h[3] >> 47) | (h[4] << 4); ++ s[26] = h[4] >> 4; ++ s[27] = h[4] >> 12; ++ s[28] = h[4] >> 20; ++ s[29] = h[4] >> 28; ++ s[30] = h[4] >> 36; ++ s[31] = h[4] >> 44; ++} ++ ++// h = 0 ++static void fe_0(fe *h) { ++ memset(h, 0, sizeof(fe)); ++} ++ ++static void fe_loose_0(fe_loose *h) { ++ memset(h, 0, sizeof(fe_loose)); ++} ++ ++// h = 1 ++static void fe_1(fe *h) { ++ memset(h, 0, sizeof(fe)); ++ h->v[0] = 1; ++} ++ ++static void fe_loose_1(fe_loose *h) { ++ memset(h, 0, sizeof(fe_loose)); ++ h->v[0] = 1; ++} ++ ++static void fe_add_impl(uint64_t out[5], const uint64_t in1[5], const uint64_t in2[5]) { ++ { const uint64_t x10 = in1[4]; ++ { const uint64_t x11 = in1[3]; ++ { const uint64_t x9 = in1[2]; ++ { const uint64_t x7 = in1[1]; ++ { const uint64_t x5 = in1[0]; ++ { const uint64_t x18 = in2[4]; ++ { const uint64_t x19 = in2[3]; ++ { const uint64_t x17 = in2[2]; ++ { const uint64_t x15 = in2[1]; ++ { const uint64_t x13 = in2[0]; ++ out[0] = (x5 + x13); ++ out[1] = (x7 + x15); ++ out[2] = (x9 + x17); ++ out[3] = (x11 + x19); ++ out[4] = (x10 + x18); ++ }}}}}}}}}} ++} ++ ++// h = f + g ++// Can overlap h with f or g. ++static void fe_add(fe_loose *h, const fe *f, const fe *g) { ++ assert_fe(f->v); ++ assert_fe(g->v); ++ fe_add_impl(h->v, f->v, g->v); ++ assert_fe_loose(h->v); ++} ++ ++static void fe_sub_impl(uint64_t out[5], const uint64_t in1[5], const uint64_t in2[5]) { ++ { const uint64_t x10 = in1[4]; ++ { const uint64_t x11 = in1[3]; ++ { const uint64_t x9 = in1[2]; ++ { const uint64_t x7 = in1[1]; ++ { const uint64_t x5 = in1[0]; ++ { const uint64_t x18 = in2[4]; ++ { const uint64_t x19 = in2[3]; ++ { const uint64_t x17 = in2[2]; ++ { const uint64_t x15 = in2[1]; ++ { const uint64_t x13 = in2[0]; ++ out[0] = ((0xfffffffffffda + x5) - x13); ++ out[1] = ((0xffffffffffffe + x7) - x15); ++ out[2] = ((0xffffffffffffe + x9) - x17); ++ out[3] = ((0xffffffffffffe + x11) - x19); ++ out[4] = ((0xffffffffffffe + x10) - x18); ++ }}}}}}}}}} ++} ++ ++// h = f - g ++// Can overlap h with f or g. ++static void fe_sub(fe_loose *h, const fe *f, const fe *g) { ++ assert_fe(f->v); ++ assert_fe(g->v); ++ fe_sub_impl(h->v, f->v, g->v); ++ assert_fe_loose(h->v); ++} ++ ++static void fe_carry_impl(uint64_t out[5], const uint64_t in1[5]) { ++ { const uint64_t x7 = in1[4]; ++ { const uint64_t x8 = in1[3]; ++ { const uint64_t x6 = in1[2]; ++ { const uint64_t x4 = in1[1]; ++ { const uint64_t x2 = in1[0]; ++ { uint64_t x9 = (x2 >> 0x33); ++ { uint64_t x10 = (x2 & 0x7ffffffffffff); ++ { uint64_t x11 = (x9 + x4); ++ { uint64_t x12 = (x11 >> 0x33); ++ { uint64_t x13 = (x11 & 0x7ffffffffffff); ++ { uint64_t x14 = (x12 + x6); ++ { uint64_t x15 = (x14 >> 0x33); ++ { uint64_t x16 = (x14 & 0x7ffffffffffff); ++ { uint64_t x17 = (x15 + x8); ++ { uint64_t x18 = (x17 >> 0x33); ++ { uint64_t x19 = (x17 & 0x7ffffffffffff); ++ { uint64_t x20 = (x18 + x7); ++ { uint64_t x21 = (x20 >> 0x33); ++ { uint64_t x22 = (x20 & 0x7ffffffffffff); ++ { uint64_t x23 = (x10 + (0x13 * x21)); ++ { uint64_t x24 = (x23 >> 0x33); ++ { uint64_t x25 = (x23 & 0x7ffffffffffff); ++ { uint64_t x26 = (x24 + x13); ++ { uint64_t x27 = (x26 >> 0x33); ++ { uint64_t x28 = (x26 & 0x7ffffffffffff); ++ out[0] = x25; ++ out[1] = x28; ++ out[2] = (x27 + x16); ++ out[3] = x19; ++ out[4] = x22; ++ }}}}}}}}}}}}}}}}}}}}}}}}} ++} ++ ++static void fe_carry(fe *h, const fe_loose* f) { ++ assert_fe_loose(f->v); ++ fe_carry_impl(h->v, f->v); ++ assert_fe(h->v); ++} ++ ++static void fe_mul_impl(uint64_t out[5], const uint64_t in1[5], const uint64_t in2[5]) { ++ assert_fe_loose(in1); ++ assert_fe_loose(in2); ++ { const uint64_t x10 = in1[4]; ++ { const uint64_t x11 = in1[3]; ++ { const uint64_t x9 = in1[2]; ++ { const uint64_t x7 = in1[1]; ++ { const uint64_t x5 = in1[0]; ++ { const uint64_t x18 = in2[4]; ++ { const uint64_t x19 = in2[3]; ++ { const uint64_t x17 = in2[2]; ++ { const uint64_t x15 = in2[1]; ++ { const uint64_t x13 = in2[0]; ++ { uint128_t x20 = ((uint128_t)x5 * x13); ++ { uint128_t x21 = (((uint128_t)x5 * x15) + ((uint128_t)x7 * x13)); ++ { uint128_t x22 = ((((uint128_t)x5 * x17) + ((uint128_t)x9 * x13)) + ((uint128_t)x7 * x15)); ++ { uint128_t x23 = (((((uint128_t)x5 * x19) + ((uint128_t)x11 * x13)) + ((uint128_t)x7 * x17)) + ((uint128_t)x9 * x15)); ++ { uint128_t x24 = ((((((uint128_t)x5 * x18) + ((uint128_t)x10 * x13)) + ((uint128_t)x11 * x15)) + ((uint128_t)x7 * x19)) + ((uint128_t)x9 * x17)); ++ { uint64_t x25 = (x10 * 0x13); ++ { uint64_t x26 = (x7 * 0x13); ++ { uint64_t x27 = (x9 * 0x13); ++ { uint64_t x28 = (x11 * 0x13); ++ { uint128_t x29 = ((((x20 + ((uint128_t)x25 * x15)) + ((uint128_t)x26 * x18)) + ((uint128_t)x27 * x19)) + ((uint128_t)x28 * x17)); ++ { uint128_t x30 = (((x21 + ((uint128_t)x25 * x17)) + ((uint128_t)x27 * x18)) + ((uint128_t)x28 * x19)); ++ { uint128_t x31 = ((x22 + ((uint128_t)x25 * x19)) + ((uint128_t)x28 * x18)); ++ { uint128_t x32 = (x23 + ((uint128_t)x25 * x18)); ++ { uint64_t x33 = (uint64_t) (x29 >> 0x33); ++ { uint64_t x34 = ((uint64_t)x29 & 0x7ffffffffffff); ++ { uint128_t x35 = (x33 + x30); ++ { uint64_t x36 = (uint64_t) (x35 >> 0x33); ++ { uint64_t x37 = ((uint64_t)x35 & 0x7ffffffffffff); ++ { uint128_t x38 = (x36 + x31); ++ { uint64_t x39 = (uint64_t) (x38 >> 0x33); ++ { uint64_t x40 = ((uint64_t)x38 & 0x7ffffffffffff); ++ { uint128_t x41 = (x39 + x32); ++ { uint64_t x42 = (uint64_t) (x41 >> 0x33); ++ { uint64_t x43 = ((uint64_t)x41 & 0x7ffffffffffff); ++ { uint128_t x44 = (x42 + x24); ++ { uint64_t x45 = (uint64_t) (x44 >> 0x33); ++ { uint64_t x46 = ((uint64_t)x44 & 0x7ffffffffffff); ++ { uint64_t x47 = (x34 + (0x13 * x45)); ++ { uint64_t x48 = (x47 >> 0x33); ++ { uint64_t x49 = (x47 & 0x7ffffffffffff); ++ { uint64_t x50 = (x48 + x37); ++ { uint64_t x51 = (x50 >> 0x33); ++ { uint64_t x52 = (x50 & 0x7ffffffffffff); ++ out[0] = x49; ++ out[1] = x52; ++ out[2] = (x51 + x40); ++ out[3] = x43; ++ out[4] = x46; ++ }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}} ++ assert_fe(out); ++} ++ ++static void fe_mul_ltt(fe_loose *h, const fe *f, const fe *g) { ++ fe_mul_impl(h->v, f->v, g->v); ++} ++ ++static void fe_mul_llt(fe_loose *h, const fe_loose *f, const fe *g) { ++ fe_mul_impl(h->v, f->v, g->v); ++} ++ ++static void fe_mul_ttt(fe *h, const fe *f, const fe *g) { ++ fe_mul_impl(h->v, f->v, g->v); ++} ++ ++static void fe_mul_tlt(fe *h, const fe_loose *f, const fe *g) { ++ fe_mul_impl(h->v, f->v, g->v); ++} ++ ++static void fe_mul_ttl(fe *h, const fe *f, const fe_loose *g) { ++ fe_mul_impl(h->v, f->v, g->v); ++} ++ ++static void fe_mul_tll(fe *h, const fe_loose *f, const fe_loose *g) { ++ fe_mul_impl(h->v, f->v, g->v); ++} ++ ++static void fe_sqr_impl(uint64_t out[5], const uint64_t in1[5]) { ++ assert_fe_loose(in1); ++ { const uint64_t x7 = in1[4]; ++ { const uint64_t x8 = in1[3]; ++ { const uint64_t x6 = in1[2]; ++ { const uint64_t x4 = in1[1]; ++ { const uint64_t x2 = in1[0]; ++ { uint64_t x9 = (x2 * 0x2); ++ { uint64_t x10 = (x4 * 0x2); ++ { uint64_t x11 = ((x6 * 0x2) * 0x13); ++ { uint64_t x12 = (x7 * 0x13); ++ { uint64_t x13 = (x12 * 0x2); ++ { uint128_t x14 = ((((uint128_t)x2 * x2) + ((uint128_t)x13 * x4)) + ((uint128_t)x11 * x8)); ++ { uint128_t x15 = ((((uint128_t)x9 * x4) + ((uint128_t)x13 * x6)) + ((uint128_t)x8 * (x8 * 0x13))); ++ { uint128_t x16 = ((((uint128_t)x9 * x6) + ((uint128_t)x4 * x4)) + ((uint128_t)x13 * x8)); ++ { uint128_t x17 = ((((uint128_t)x9 * x8) + ((uint128_t)x10 * x6)) + ((uint128_t)x7 * x12)); ++ { uint128_t x18 = ((((uint128_t)x9 * x7) + ((uint128_t)x10 * x8)) + ((uint128_t)x6 * x6)); ++ { uint64_t x19 = (uint64_t) (x14 >> 0x33); ++ { uint64_t x20 = ((uint64_t)x14 & 0x7ffffffffffff); ++ { uint128_t x21 = (x19 + x15); ++ { uint64_t x22 = (uint64_t) (x21 >> 0x33); ++ { uint64_t x23 = ((uint64_t)x21 & 0x7ffffffffffff); ++ { uint128_t x24 = (x22 + x16); ++ { uint64_t x25 = (uint64_t) (x24 >> 0x33); ++ { uint64_t x26 = ((uint64_t)x24 & 0x7ffffffffffff); ++ { uint128_t x27 = (x25 + x17); ++ { uint64_t x28 = (uint64_t) (x27 >> 0x33); ++ { uint64_t x29 = ((uint64_t)x27 & 0x7ffffffffffff); ++ { uint128_t x30 = (x28 + x18); ++ { uint64_t x31 = (uint64_t) (x30 >> 0x33); ++ { uint64_t x32 = ((uint64_t)x30 & 0x7ffffffffffff); ++ { uint64_t x33 = (x20 + (0x13 * x31)); ++ { uint64_t x34 = (x33 >> 0x33); ++ { uint64_t x35 = (x33 & 0x7ffffffffffff); ++ { uint64_t x36 = (x34 + x23); ++ { uint64_t x37 = (x36 >> 0x33); ++ { uint64_t x38 = (x36 & 0x7ffffffffffff); ++ out[0] = x35; ++ out[1] = x38; ++ out[2] = (x37 + x26); ++ out[3] = x29; ++ out[4] = x32; ++ }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}} ++ assert_fe(out); ++} ++ ++static void fe_sq_tl(fe *h, const fe_loose *f) { ++ fe_sqr_impl(h->v, f->v); ++} ++ ++static void fe_sq_tt(fe *h, const fe *f) { ++ fe_sqr_impl(h->v, f->v); ++} ++ ++// Adapted from Fiat-synthesized |fe_sub_impl| with |out| = 0. ++static void fe_neg_impl(uint64_t out[5], const uint64_t in2[5]) { ++ { const uint64_t x10 = 0; ++ { const uint64_t x11 = 0; ++ { const uint64_t x9 = 0; ++ { const uint64_t x7 = 0; ++ { const uint64_t x5 = 0; ++ { const uint64_t x18 = in2[4]; ++ { const uint64_t x19 = in2[3]; ++ { const uint64_t x17 = in2[2]; ++ { const uint64_t x15 = in2[1]; ++ { const uint64_t x13 = in2[0]; ++ out[0] = ((0xfffffffffffda + x5) - x13); ++ out[1] = ((0xffffffffffffe + x7) - x15); ++ out[2] = ((0xffffffffffffe + x9) - x17); ++ out[3] = ((0xffffffffffffe + x11) - x19); ++ out[4] = ((0xffffffffffffe + x10) - x18); ++ }}}}}}}}}} ++} ++ ++// h = -f ++static void fe_neg(fe_loose *h, const fe *f) { ++ assert_fe(f->v); ++ fe_neg_impl(h->v, f->v); ++ assert_fe_loose(h->v); ++} ++ ++// Replace (f,g) with (g,g) if b == 1; ++// replace (f,g) with (f,g) if b == 0. ++// ++// Preconditions: b in {0,1}. ++static void fe_cmov(fe_loose *f, const fe_loose *g, uint64_t b) { ++ unsigned i; ++ b = 0-b; ++ for (i = 0; i < 5; i++) { ++ uint64_t x = f->v[i] ^ g->v[i]; ++ x &= b; ++ f->v[i] ^= x; ++ } ++} ++ ++#else ++ ++#ifdef EDWARDS25519_ASSERTS ++#define assert_fe(f) do { \ ++ unsigned _assert_fe_i; \ ++ for (_assert_fe_i = 0; _assert_fe_i< 10; _assert_fe_i++) { \ ++ assert(f[_assert_fe_i] < 1.125*(1<<(26-(_assert_fe_i&1)))); \ ++ } \ ++} while (0) ++ ++#define assert_fe_loose(f) do { \ ++ unsigned _assert_fe_i; \ ++ for (_assert_fe_i = 0; _assert_fe_i< 10; _assert_fe_i++) { \ ++ assert(f[_assert_fe_i] < 3.375*(1<<(26-(_assert_fe_i&1)))); \ ++ } \ ++} while (0) ++ ++#define assert_fe_frozen(f) do { \ ++ unsigned _assert_fe_i; \ ++ for (_assert_fe_i = 0; _assert_fe_i< 10; _assert_fe_i++) { \ ++ assert(f[_assert_fe_i] < (1u<<(26-(_assert_fe_i&1)))); \ ++ } \ ++} while (0) ++#endif /* EDWARDS25519_ASSERTS */ ++ ++static void fe_frombytes_impl(uint32_t h[10], const uint8_t *s) { ++ // Ignores top bit of s. ++ uint32_t a0 = load_4(s); ++ uint32_t a1 = load_4(s+4); ++ uint32_t a2 = load_4(s+8); ++ uint32_t a3 = load_4(s+12); ++ uint32_t a4 = load_4(s+16); ++ uint32_t a5 = load_4(s+20); ++ uint32_t a6 = load_4(s+24); ++ uint32_t a7 = load_4(s+28); ++ h[0] = a0&((1<<26)-1); // 26 used, 32-26 left. 26 ++ h[1] = (a0>>26) | ((a1&((1<<19)-1))<< 6); // (32-26) + 19 = 6+19 = 25 ++ h[2] = (a1>>19) | ((a2&((1<<13)-1))<<13); // (32-19) + 13 = 13+13 = 26 ++ h[3] = (a2>>13) | ((a3&((1<< 6)-1))<<19); // (32-13) + 6 = 19+ 6 = 25 ++ h[4] = (a3>> 6); // (32- 6) = 26 ++ h[5] = a4&((1<<25)-1); // 25 ++ h[6] = (a4>>25) | ((a5&((1<<19)-1))<< 7); // (32-25) + 19 = 7+19 = 26 ++ h[7] = (a5>>19) | ((a6&((1<<12)-1))<<13); // (32-19) + 12 = 13+12 = 25 ++ h[8] = (a6>>12) | ((a7&((1<< 6)-1))<<20); // (32-12) + 6 = 20+ 6 = 26 ++ h[9] = (a7>> 6)&((1<<25)-1); // 25 ++ assert_fe(h); ++} ++ ++static void fe_frombytes(fe *h, const uint8_t *s) { ++ fe_frombytes_impl(h->v, s); ++} ++ ++static void fe_freeze(uint32_t out[10], const uint32_t in1[10]) { ++ { const uint32_t x17 = in1[9]; ++ { const uint32_t x18 = in1[8]; ++ { const uint32_t x16 = in1[7]; ++ { const uint32_t x14 = in1[6]; ++ { const uint32_t x12 = in1[5]; ++ { const uint32_t x10 = in1[4]; ++ { const uint32_t x8 = in1[3]; ++ { const uint32_t x6 = in1[2]; ++ { const uint32_t x4 = in1[1]; ++ { const uint32_t x2 = in1[0]; ++ { uint32_t x20; uint8_t/*bool*/ x21 = subborrow_u26(0x0, x2, 0x3ffffed, &x20); ++ { uint32_t x23; uint8_t/*bool*/ x24 = subborrow_u25(x21, x4, 0x1ffffff, &x23); ++ { uint32_t x26; uint8_t/*bool*/ x27 = subborrow_u26(x24, x6, 0x3ffffff, &x26); ++ { uint32_t x29; uint8_t/*bool*/ x30 = subborrow_u25(x27, x8, 0x1ffffff, &x29); ++ { uint32_t x32; uint8_t/*bool*/ x33 = subborrow_u26(x30, x10, 0x3ffffff, &x32); ++ { uint32_t x35; uint8_t/*bool*/ x36 = subborrow_u25(x33, x12, 0x1ffffff, &x35); ++ { uint32_t x38; uint8_t/*bool*/ x39 = subborrow_u26(x36, x14, 0x3ffffff, &x38); ++ { uint32_t x41; uint8_t/*bool*/ x42 = subborrow_u25(x39, x16, 0x1ffffff, &x41); ++ { uint32_t x44; uint8_t/*bool*/ x45 = subborrow_u26(x42, x18, 0x3ffffff, &x44); ++ { uint32_t x47; uint8_t/*bool*/ x48 = subborrow_u25(x45, x17, 0x1ffffff, &x47); ++ { uint32_t x49 = cmovznz32(x48, 0x0, 0xffffffff); ++ { uint32_t x50 = (x49 & 0x3ffffed); ++ { uint32_t x52; uint8_t/*bool*/ x53 = addcarryx_u26(0x0, x20, x50, &x52); ++ { uint32_t x54 = (x49 & 0x1ffffff); ++ { uint32_t x56; uint8_t/*bool*/ x57 = addcarryx_u25(x53, x23, x54, &x56); ++ { uint32_t x58 = (x49 & 0x3ffffff); ++ { uint32_t x60; uint8_t/*bool*/ x61 = addcarryx_u26(x57, x26, x58, &x60); ++ { uint32_t x62 = (x49 & 0x1ffffff); ++ { uint32_t x64; uint8_t/*bool*/ x65 = addcarryx_u25(x61, x29, x62, &x64); ++ { uint32_t x66 = (x49 & 0x3ffffff); ++ { uint32_t x68; uint8_t/*bool*/ x69 = addcarryx_u26(x65, x32, x66, &x68); ++ { uint32_t x70 = (x49 & 0x1ffffff); ++ { uint32_t x72; uint8_t/*bool*/ x73 = addcarryx_u25(x69, x35, x70, &x72); ++ { uint32_t x74 = (x49 & 0x3ffffff); ++ { uint32_t x76; uint8_t/*bool*/ x77 = addcarryx_u26(x73, x38, x74, &x76); ++ { uint32_t x78 = (x49 & 0x1ffffff); ++ { uint32_t x80; uint8_t/*bool*/ x81 = addcarryx_u25(x77, x41, x78, &x80); ++ { uint32_t x82 = (x49 & 0x3ffffff); ++ { uint32_t x84; uint8_t/*bool*/ x85 = addcarryx_u26(x81, x44, x82, &x84); ++ { uint32_t x86 = (x49 & 0x1ffffff); ++ { uint32_t x88; addcarryx_u25(x85, x47, x86, &x88); ++ out[0] = x52; ++ out[1] = x56; ++ out[2] = x60; ++ out[3] = x64; ++ out[4] = x68; ++ out[5] = x72; ++ out[6] = x76; ++ out[7] = x80; ++ out[8] = x84; ++ out[9] = x88; ++ }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}} ++} ++ ++static void fe_tobytes(uint8_t s[32], const fe *f) { ++ assert_fe(f->v); ++ uint32_t h[10]; ++ fe_freeze(h, f->v); ++ assert_fe_frozen(h); ++ ++ s[0] = h[0] >> 0; ++ s[1] = h[0] >> 8; ++ s[2] = h[0] >> 16; ++ s[3] = (h[0] >> 24) | (h[1] << 2); ++ s[4] = h[1] >> 6; ++ s[5] = h[1] >> 14; ++ s[6] = (h[1] >> 22) | (h[2] << 3); ++ s[7] = h[2] >> 5; ++ s[8] = h[2] >> 13; ++ s[9] = (h[2] >> 21) | (h[3] << 5); ++ s[10] = h[3] >> 3; ++ s[11] = h[3] >> 11; ++ s[12] = (h[3] >> 19) | (h[4] << 6); ++ s[13] = h[4] >> 2; ++ s[14] = h[4] >> 10; ++ s[15] = h[4] >> 18; ++ s[16] = h[5] >> 0; ++ s[17] = h[5] >> 8; ++ s[18] = h[5] >> 16; ++ s[19] = (h[5] >> 24) | (h[6] << 1); ++ s[20] = h[6] >> 7; ++ s[21] = h[6] >> 15; ++ s[22] = (h[6] >> 23) | (h[7] << 3); ++ s[23] = h[7] >> 5; ++ s[24] = h[7] >> 13; ++ s[25] = (h[7] >> 21) | (h[8] << 4); ++ s[26] = h[8] >> 4; ++ s[27] = h[8] >> 12; ++ s[28] = (h[8] >> 20) | (h[9] << 6); ++ s[29] = h[9] >> 2; ++ s[30] = h[9] >> 10; ++ s[31] = h[9] >> 18; ++} ++ ++// h = 0 ++static void fe_0(fe *h) { ++ memset(h, 0, sizeof(fe)); ++} ++ ++static void fe_loose_0(fe_loose *h) { ++ memset(h, 0, sizeof(fe_loose)); ++} ++ ++// h = 1 ++static void fe_1(fe *h) { ++ memset(h, 0, sizeof(fe)); ++ h->v[0] = 1; ++} ++ ++static void fe_loose_1(fe_loose *h) { ++ memset(h, 0, sizeof(fe_loose)); ++ h->v[0] = 1; ++} ++ ++static void fe_add_impl(uint32_t out[10], const uint32_t in1[10], const uint32_t in2[10]) { ++ { const uint32_t x20 = in1[9]; ++ { const uint32_t x21 = in1[8]; ++ { const uint32_t x19 = in1[7]; ++ { const uint32_t x17 = in1[6]; ++ { const uint32_t x15 = in1[5]; ++ { const uint32_t x13 = in1[4]; ++ { const uint32_t x11 = in1[3]; ++ { const uint32_t x9 = in1[2]; ++ { const uint32_t x7 = in1[1]; ++ { const uint32_t x5 = in1[0]; ++ { const uint32_t x38 = in2[9]; ++ { const uint32_t x39 = in2[8]; ++ { const uint32_t x37 = in2[7]; ++ { const uint32_t x35 = in2[6]; ++ { const uint32_t x33 = in2[5]; ++ { const uint32_t x31 = in2[4]; ++ { const uint32_t x29 = in2[3]; ++ { const uint32_t x27 = in2[2]; ++ { const uint32_t x25 = in2[1]; ++ { const uint32_t x23 = in2[0]; ++ out[0] = (x5 + x23); ++ out[1] = (x7 + x25); ++ out[2] = (x9 + x27); ++ out[3] = (x11 + x29); ++ out[4] = (x13 + x31); ++ out[5] = (x15 + x33); ++ out[6] = (x17 + x35); ++ out[7] = (x19 + x37); ++ out[8] = (x21 + x39); ++ out[9] = (x20 + x38); ++ }}}}}}}}}}}}}}}}}}}} ++} ++ ++// h = f + g ++// Can overlap h with f or g. ++static void fe_add(fe_loose *h, const fe *f, const fe *g) { ++ assert_fe(f->v); ++ assert_fe(g->v); ++ fe_add_impl(h->v, f->v, g->v); ++ assert_fe_loose(h->v); ++} ++ ++static void fe_sub_impl(uint32_t out[10], const uint32_t in1[10], const uint32_t in2[10]) { ++ { const uint32_t x20 = in1[9]; ++ { const uint32_t x21 = in1[8]; ++ { const uint32_t x19 = in1[7]; ++ { const uint32_t x17 = in1[6]; ++ { const uint32_t x15 = in1[5]; ++ { const uint32_t x13 = in1[4]; ++ { const uint32_t x11 = in1[3]; ++ { const uint32_t x9 = in1[2]; ++ { const uint32_t x7 = in1[1]; ++ { const uint32_t x5 = in1[0]; ++ { const uint32_t x38 = in2[9]; ++ { const uint32_t x39 = in2[8]; ++ { const uint32_t x37 = in2[7]; ++ { const uint32_t x35 = in2[6]; ++ { const uint32_t x33 = in2[5]; ++ { const uint32_t x31 = in2[4]; ++ { const uint32_t x29 = in2[3]; ++ { const uint32_t x27 = in2[2]; ++ { const uint32_t x25 = in2[1]; ++ { const uint32_t x23 = in2[0]; ++ out[0] = ((0x7ffffda + x5) - x23); ++ out[1] = ((0x3fffffe + x7) - x25); ++ out[2] = ((0x7fffffe + x9) - x27); ++ out[3] = ((0x3fffffe + x11) - x29); ++ out[4] = ((0x7fffffe + x13) - x31); ++ out[5] = ((0x3fffffe + x15) - x33); ++ out[6] = ((0x7fffffe + x17) - x35); ++ out[7] = ((0x3fffffe + x19) - x37); ++ out[8] = ((0x7fffffe + x21) - x39); ++ out[9] = ((0x3fffffe + x20) - x38); ++ }}}}}}}}}}}}}}}}}}}} ++} ++ ++// h = f - g ++// Can overlap h with f or g. ++static void fe_sub(fe_loose *h, const fe *f, const fe *g) { ++ assert_fe(f->v); ++ assert_fe(g->v); ++ fe_sub_impl(h->v, f->v, g->v); ++ assert_fe_loose(h->v); ++} ++ ++static void fe_carry_impl(uint32_t out[10], const uint32_t in1[10]) { ++ { const uint32_t x17 = in1[9]; ++ { const uint32_t x18 = in1[8]; ++ { const uint32_t x16 = in1[7]; ++ { const uint32_t x14 = in1[6]; ++ { const uint32_t x12 = in1[5]; ++ { const uint32_t x10 = in1[4]; ++ { const uint32_t x8 = in1[3]; ++ { const uint32_t x6 = in1[2]; ++ { const uint32_t x4 = in1[1]; ++ { const uint32_t x2 = in1[0]; ++ { uint32_t x19 = (x2 >> 0x1a); ++ { uint32_t x20 = (x2 & 0x3ffffff); ++ { uint32_t x21 = (x19 + x4); ++ { uint32_t x22 = (x21 >> 0x19); ++ { uint32_t x23 = (x21 & 0x1ffffff); ++ { uint32_t x24 = (x22 + x6); ++ { uint32_t x25 = (x24 >> 0x1a); ++ { uint32_t x26 = (x24 & 0x3ffffff); ++ { uint32_t x27 = (x25 + x8); ++ { uint32_t x28 = (x27 >> 0x19); ++ { uint32_t x29 = (x27 & 0x1ffffff); ++ { uint32_t x30 = (x28 + x10); ++ { uint32_t x31 = (x30 >> 0x1a); ++ { uint32_t x32 = (x30 & 0x3ffffff); ++ { uint32_t x33 = (x31 + x12); ++ { uint32_t x34 = (x33 >> 0x19); ++ { uint32_t x35 = (x33 & 0x1ffffff); ++ { uint32_t x36 = (x34 + x14); ++ { uint32_t x37 = (x36 >> 0x1a); ++ { uint32_t x38 = (x36 & 0x3ffffff); ++ { uint32_t x39 = (x37 + x16); ++ { uint32_t x40 = (x39 >> 0x19); ++ { uint32_t x41 = (x39 & 0x1ffffff); ++ { uint32_t x42 = (x40 + x18); ++ { uint32_t x43 = (x42 >> 0x1a); ++ { uint32_t x44 = (x42 & 0x3ffffff); ++ { uint32_t x45 = (x43 + x17); ++ { uint32_t x46 = (x45 >> 0x19); ++ { uint32_t x47 = (x45 & 0x1ffffff); ++ { uint32_t x48 = (x20 + (0x13 * x46)); ++ { uint32_t x49 = (x48 >> 0x1a); ++ { uint32_t x50 = (x48 & 0x3ffffff); ++ { uint32_t x51 = (x49 + x23); ++ { uint32_t x52 = (x51 >> 0x19); ++ { uint32_t x53 = (x51 & 0x1ffffff); ++ out[0] = x50; ++ out[1] = x53; ++ out[2] = (x52 + x26); ++ out[3] = x29; ++ out[4] = x32; ++ out[5] = x35; ++ out[6] = x38; ++ out[7] = x41; ++ out[8] = x44; ++ out[9] = x47; ++ }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}} ++} ++ ++static void fe_carry(fe *h, const fe_loose* f) { ++ assert_fe_loose(f->v); ++ fe_carry_impl(h->v, f->v); ++ assert_fe(h->v); ++} ++ ++static void fe_mul_impl(uint32_t out[10], const uint32_t in1[10], const uint32_t in2[10]) { ++ assert_fe_loose(in1); ++ assert_fe_loose(in2); ++ { const uint32_t x20 = in1[9]; ++ { const uint32_t x21 = in1[8]; ++ { const uint32_t x19 = in1[7]; ++ { const uint32_t x17 = in1[6]; ++ { const uint32_t x15 = in1[5]; ++ { const uint32_t x13 = in1[4]; ++ { const uint32_t x11 = in1[3]; ++ { const uint32_t x9 = in1[2]; ++ { const uint32_t x7 = in1[1]; ++ { const uint32_t x5 = in1[0]; ++ { const uint32_t x38 = in2[9]; ++ { const uint32_t x39 = in2[8]; ++ { const uint32_t x37 = in2[7]; ++ { const uint32_t x35 = in2[6]; ++ { const uint32_t x33 = in2[5]; ++ { const uint32_t x31 = in2[4]; ++ { const uint32_t x29 = in2[3]; ++ { const uint32_t x27 = in2[2]; ++ { const uint32_t x25 = in2[1]; ++ { const uint32_t x23 = in2[0]; ++ { uint64_t x40 = ((uint64_t)x23 * x5); ++ { uint64_t x41 = (((uint64_t)x23 * x7) + ((uint64_t)x25 * x5)); ++ { uint64_t x42 = ((((uint64_t)(0x2 * x25) * x7) + ((uint64_t)x23 * x9)) + ((uint64_t)x27 * x5)); ++ { uint64_t x43 = (((((uint64_t)x25 * x9) + ((uint64_t)x27 * x7)) + ((uint64_t)x23 * x11)) + ((uint64_t)x29 * x5)); ++ { uint64_t x44 = (((((uint64_t)x27 * x9) + (0x2 * (((uint64_t)x25 * x11) + ((uint64_t)x29 * x7)))) + ((uint64_t)x23 * x13)) + ((uint64_t)x31 * x5)); ++ { uint64_t x45 = (((((((uint64_t)x27 * x11) + ((uint64_t)x29 * x9)) + ((uint64_t)x25 * x13)) + ((uint64_t)x31 * x7)) + ((uint64_t)x23 * x15)) + ((uint64_t)x33 * x5)); ++ { uint64_t x46 = (((((0x2 * ((((uint64_t)x29 * x11) + ((uint64_t)x25 * x15)) + ((uint64_t)x33 * x7))) + ((uint64_t)x27 * x13)) + ((uint64_t)x31 * x9)) + ((uint64_t)x23 * x17)) + ((uint64_t)x35 * x5)); ++ { uint64_t x47 = (((((((((uint64_t)x29 * x13) + ((uint64_t)x31 * x11)) + ((uint64_t)x27 * x15)) + ((uint64_t)x33 * x9)) + ((uint64_t)x25 * x17)) + ((uint64_t)x35 * x7)) + ((uint64_t)x23 * x19)) + ((uint64_t)x37 * x5)); ++ { uint64_t x48 = (((((((uint64_t)x31 * x13) + (0x2 * (((((uint64_t)x29 * x15) + ((uint64_t)x33 * x11)) + ((uint64_t)x25 * x19)) + ((uint64_t)x37 * x7)))) + ((uint64_t)x27 * x17)) + ((uint64_t)x35 * x9)) + ((uint64_t)x23 * x21)) + ((uint64_t)x39 * x5)); ++ { uint64_t x49 = (((((((((((uint64_t)x31 * x15) + ((uint64_t)x33 * x13)) + ((uint64_t)x29 * x17)) + ((uint64_t)x35 * x11)) + ((uint64_t)x27 * x19)) + ((uint64_t)x37 * x9)) + ((uint64_t)x25 * x21)) + ((uint64_t)x39 * x7)) + ((uint64_t)x23 * x20)) + ((uint64_t)x38 * x5)); ++ { uint64_t x50 = (((((0x2 * ((((((uint64_t)x33 * x15) + ((uint64_t)x29 * x19)) + ((uint64_t)x37 * x11)) + ((uint64_t)x25 * x20)) + ((uint64_t)x38 * x7))) + ((uint64_t)x31 * x17)) + ((uint64_t)x35 * x13)) + ((uint64_t)x27 * x21)) + ((uint64_t)x39 * x9)); ++ { uint64_t x51 = (((((((((uint64_t)x33 * x17) + ((uint64_t)x35 * x15)) + ((uint64_t)x31 * x19)) + ((uint64_t)x37 * x13)) + ((uint64_t)x29 * x21)) + ((uint64_t)x39 * x11)) + ((uint64_t)x27 * x20)) + ((uint64_t)x38 * x9)); ++ { uint64_t x52 = (((((uint64_t)x35 * x17) + (0x2 * (((((uint64_t)x33 * x19) + ((uint64_t)x37 * x15)) + ((uint64_t)x29 * x20)) + ((uint64_t)x38 * x11)))) + ((uint64_t)x31 * x21)) + ((uint64_t)x39 * x13)); ++ { uint64_t x53 = (((((((uint64_t)x35 * x19) + ((uint64_t)x37 * x17)) + ((uint64_t)x33 * x21)) + ((uint64_t)x39 * x15)) + ((uint64_t)x31 * x20)) + ((uint64_t)x38 * x13)); ++ { uint64_t x54 = (((0x2 * ((((uint64_t)x37 * x19) + ((uint64_t)x33 * x20)) + ((uint64_t)x38 * x15))) + ((uint64_t)x35 * x21)) + ((uint64_t)x39 * x17)); ++ { uint64_t x55 = (((((uint64_t)x37 * x21) + ((uint64_t)x39 * x19)) + ((uint64_t)x35 * x20)) + ((uint64_t)x38 * x17)); ++ { uint64_t x56 = (((uint64_t)x39 * x21) + (0x2 * (((uint64_t)x37 * x20) + ((uint64_t)x38 * x19)))); ++ { uint64_t x57 = (((uint64_t)x39 * x20) + ((uint64_t)x38 * x21)); ++ { uint64_t x58 = ((uint64_t)(0x2 * x38) * x20); ++ { uint64_t x59 = (x48 + (x58 << 0x4)); ++ { uint64_t x60 = (x59 + (x58 << 0x1)); ++ { uint64_t x61 = (x60 + x58); ++ { uint64_t x62 = (x47 + (x57 << 0x4)); ++ { uint64_t x63 = (x62 + (x57 << 0x1)); ++ { uint64_t x64 = (x63 + x57); ++ { uint64_t x65 = (x46 + (x56 << 0x4)); ++ { uint64_t x66 = (x65 + (x56 << 0x1)); ++ { uint64_t x67 = (x66 + x56); ++ { uint64_t x68 = (x45 + (x55 << 0x4)); ++ { uint64_t x69 = (x68 + (x55 << 0x1)); ++ { uint64_t x70 = (x69 + x55); ++ { uint64_t x71 = (x44 + (x54 << 0x4)); ++ { uint64_t x72 = (x71 + (x54 << 0x1)); ++ { uint64_t x73 = (x72 + x54); ++ { uint64_t x74 = (x43 + (x53 << 0x4)); ++ { uint64_t x75 = (x74 + (x53 << 0x1)); ++ { uint64_t x76 = (x75 + x53); ++ { uint64_t x77 = (x42 + (x52 << 0x4)); ++ { uint64_t x78 = (x77 + (x52 << 0x1)); ++ { uint64_t x79 = (x78 + x52); ++ { uint64_t x80 = (x41 + (x51 << 0x4)); ++ { uint64_t x81 = (x80 + (x51 << 0x1)); ++ { uint64_t x82 = (x81 + x51); ++ { uint64_t x83 = (x40 + (x50 << 0x4)); ++ { uint64_t x84 = (x83 + (x50 << 0x1)); ++ { uint64_t x85 = (x84 + x50); ++ { uint64_t x86 = (x85 >> 0x1a); ++ { uint32_t x87 = ((uint32_t)x85 & 0x3ffffff); ++ { uint64_t x88 = (x86 + x82); ++ { uint64_t x89 = (x88 >> 0x19); ++ { uint32_t x90 = ((uint32_t)x88 & 0x1ffffff); ++ { uint64_t x91 = (x89 + x79); ++ { uint64_t x92 = (x91 >> 0x1a); ++ { uint32_t x93 = ((uint32_t)x91 & 0x3ffffff); ++ { uint64_t x94 = (x92 + x76); ++ { uint64_t x95 = (x94 >> 0x19); ++ { uint32_t x96 = ((uint32_t)x94 & 0x1ffffff); ++ { uint64_t x97 = (x95 + x73); ++ { uint64_t x98 = (x97 >> 0x1a); ++ { uint32_t x99 = ((uint32_t)x97 & 0x3ffffff); ++ { uint64_t x100 = (x98 + x70); ++ { uint64_t x101 = (x100 >> 0x19); ++ { uint32_t x102 = ((uint32_t)x100 & 0x1ffffff); ++ { uint64_t x103 = (x101 + x67); ++ { uint64_t x104 = (x103 >> 0x1a); ++ { uint32_t x105 = ((uint32_t)x103 & 0x3ffffff); ++ { uint64_t x106 = (x104 + x64); ++ { uint64_t x107 = (x106 >> 0x19); ++ { uint32_t x108 = ((uint32_t)x106 & 0x1ffffff); ++ { uint64_t x109 = (x107 + x61); ++ { uint64_t x110 = (x109 >> 0x1a); ++ { uint32_t x111 = ((uint32_t)x109 & 0x3ffffff); ++ { uint64_t x112 = (x110 + x49); ++ { uint64_t x113 = (x112 >> 0x19); ++ { uint32_t x114 = ((uint32_t)x112 & 0x1ffffff); ++ { uint64_t x115 = (x87 + (0x13 * x113)); ++ { uint32_t x116 = (uint32_t) (x115 >> 0x1a); ++ { uint32_t x117 = ((uint32_t)x115 & 0x3ffffff); ++ { uint32_t x118 = (x116 + x90); ++ { uint32_t x119 = (x118 >> 0x19); ++ { uint32_t x120 = (x118 & 0x1ffffff); ++ out[0] = x117; ++ out[1] = x120; ++ out[2] = (x119 + x93); ++ out[3] = x96; ++ out[4] = x99; ++ out[5] = x102; ++ out[6] = x105; ++ out[7] = x108; ++ out[8] = x111; ++ out[9] = x114; ++ }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}} ++ assert_fe(out); ++} ++ ++static void fe_mul_ltt(fe_loose *h, const fe *f, const fe *g) { ++ fe_mul_impl(h->v, f->v, g->v); ++} ++ ++static void fe_mul_llt(fe_loose *h, const fe_loose *f, const fe *g) { ++ fe_mul_impl(h->v, f->v, g->v); ++} ++ ++static void fe_mul_ttt(fe *h, const fe *f, const fe *g) { ++ fe_mul_impl(h->v, f->v, g->v); ++} ++ ++static void fe_mul_tlt(fe *h, const fe_loose *f, const fe *g) { ++ fe_mul_impl(h->v, f->v, g->v); ++} ++ ++static void fe_mul_ttl(fe *h, const fe *f, const fe_loose *g) { ++ fe_mul_impl(h->v, f->v, g->v); ++} ++ ++static void fe_mul_tll(fe *h, const fe_loose *f, const fe_loose *g) { ++ fe_mul_impl(h->v, f->v, g->v); ++} ++ ++static void fe_sqr_impl(uint32_t out[10], const uint32_t in1[10]) { ++ assert_fe_loose(in1); ++ { const uint32_t x17 = in1[9]; ++ { const uint32_t x18 = in1[8]; ++ { const uint32_t x16 = in1[7]; ++ { const uint32_t x14 = in1[6]; ++ { const uint32_t x12 = in1[5]; ++ { const uint32_t x10 = in1[4]; ++ { const uint32_t x8 = in1[3]; ++ { const uint32_t x6 = in1[2]; ++ { const uint32_t x4 = in1[1]; ++ { const uint32_t x2 = in1[0]; ++ { uint64_t x19 = ((uint64_t)x2 * x2); ++ { uint64_t x20 = ((uint64_t)(0x2 * x2) * x4); ++ { uint64_t x21 = (0x2 * (((uint64_t)x4 * x4) + ((uint64_t)x2 * x6))); ++ { uint64_t x22 = (0x2 * (((uint64_t)x4 * x6) + ((uint64_t)x2 * x8))); ++ { uint64_t x23 = ((((uint64_t)x6 * x6) + ((uint64_t)(0x4 * x4) * x8)) + ((uint64_t)(0x2 * x2) * x10)); ++ { uint64_t x24 = (0x2 * ((((uint64_t)x6 * x8) + ((uint64_t)x4 * x10)) + ((uint64_t)x2 * x12))); ++ { uint64_t x25 = (0x2 * (((((uint64_t)x8 * x8) + ((uint64_t)x6 * x10)) + ((uint64_t)x2 * x14)) + ((uint64_t)(0x2 * x4) * x12))); ++ { uint64_t x26 = (0x2 * (((((uint64_t)x8 * x10) + ((uint64_t)x6 * x12)) + ((uint64_t)x4 * x14)) + ((uint64_t)x2 * x16))); ++ { uint64_t x27 = (((uint64_t)x10 * x10) + (0x2 * ((((uint64_t)x6 * x14) + ((uint64_t)x2 * x18)) + (0x2 * (((uint64_t)x4 * x16) + ((uint64_t)x8 * x12)))))); ++ { uint64_t x28 = (0x2 * ((((((uint64_t)x10 * x12) + ((uint64_t)x8 * x14)) + ((uint64_t)x6 * x16)) + ((uint64_t)x4 * x18)) + ((uint64_t)x2 * x17))); ++ { uint64_t x29 = (0x2 * (((((uint64_t)x12 * x12) + ((uint64_t)x10 * x14)) + ((uint64_t)x6 * x18)) + (0x2 * (((uint64_t)x8 * x16) + ((uint64_t)x4 * x17))))); ++ { uint64_t x30 = (0x2 * (((((uint64_t)x12 * x14) + ((uint64_t)x10 * x16)) + ((uint64_t)x8 * x18)) + ((uint64_t)x6 * x17))); ++ { uint64_t x31 = (((uint64_t)x14 * x14) + (0x2 * (((uint64_t)x10 * x18) + (0x2 * (((uint64_t)x12 * x16) + ((uint64_t)x8 * x17)))))); ++ { uint64_t x32 = (0x2 * ((((uint64_t)x14 * x16) + ((uint64_t)x12 * x18)) + ((uint64_t)x10 * x17))); ++ { uint64_t x33 = (0x2 * ((((uint64_t)x16 * x16) + ((uint64_t)x14 * x18)) + ((uint64_t)(0x2 * x12) * x17))); ++ { uint64_t x34 = (0x2 * (((uint64_t)x16 * x18) + ((uint64_t)x14 * x17))); ++ { uint64_t x35 = (((uint64_t)x18 * x18) + ((uint64_t)(0x4 * x16) * x17)); ++ { uint64_t x36 = ((uint64_t)(0x2 * x18) * x17); ++ { uint64_t x37 = ((uint64_t)(0x2 * x17) * x17); ++ { uint64_t x38 = (x27 + (x37 << 0x4)); ++ { uint64_t x39 = (x38 + (x37 << 0x1)); ++ { uint64_t x40 = (x39 + x37); ++ { uint64_t x41 = (x26 + (x36 << 0x4)); ++ { uint64_t x42 = (x41 + (x36 << 0x1)); ++ { uint64_t x43 = (x42 + x36); ++ { uint64_t x44 = (x25 + (x35 << 0x4)); ++ { uint64_t x45 = (x44 + (x35 << 0x1)); ++ { uint64_t x46 = (x45 + x35); ++ { uint64_t x47 = (x24 + (x34 << 0x4)); ++ { uint64_t x48 = (x47 + (x34 << 0x1)); ++ { uint64_t x49 = (x48 + x34); ++ { uint64_t x50 = (x23 + (x33 << 0x4)); ++ { uint64_t x51 = (x50 + (x33 << 0x1)); ++ { uint64_t x52 = (x51 + x33); ++ { uint64_t x53 = (x22 + (x32 << 0x4)); ++ { uint64_t x54 = (x53 + (x32 << 0x1)); ++ { uint64_t x55 = (x54 + x32); ++ { uint64_t x56 = (x21 + (x31 << 0x4)); ++ { uint64_t x57 = (x56 + (x31 << 0x1)); ++ { uint64_t x58 = (x57 + x31); ++ { uint64_t x59 = (x20 + (x30 << 0x4)); ++ { uint64_t x60 = (x59 + (x30 << 0x1)); ++ { uint64_t x61 = (x60 + x30); ++ { uint64_t x62 = (x19 + (x29 << 0x4)); ++ { uint64_t x63 = (x62 + (x29 << 0x1)); ++ { uint64_t x64 = (x63 + x29); ++ { uint64_t x65 = (x64 >> 0x1a); ++ { uint32_t x66 = ((uint32_t)x64 & 0x3ffffff); ++ { uint64_t x67 = (x65 + x61); ++ { uint64_t x68 = (x67 >> 0x19); ++ { uint32_t x69 = ((uint32_t)x67 & 0x1ffffff); ++ { uint64_t x70 = (x68 + x58); ++ { uint64_t x71 = (x70 >> 0x1a); ++ { uint32_t x72 = ((uint32_t)x70 & 0x3ffffff); ++ { uint64_t x73 = (x71 + x55); ++ { uint64_t x74 = (x73 >> 0x19); ++ { uint32_t x75 = ((uint32_t)x73 & 0x1ffffff); ++ { uint64_t x76 = (x74 + x52); ++ { uint64_t x77 = (x76 >> 0x1a); ++ { uint32_t x78 = ((uint32_t)x76 & 0x3ffffff); ++ { uint64_t x79 = (x77 + x49); ++ { uint64_t x80 = (x79 >> 0x19); ++ { uint32_t x81 = ((uint32_t)x79 & 0x1ffffff); ++ { uint64_t x82 = (x80 + x46); ++ { uint64_t x83 = (x82 >> 0x1a); ++ { uint32_t x84 = ((uint32_t)x82 & 0x3ffffff); ++ { uint64_t x85 = (x83 + x43); ++ { uint64_t x86 = (x85 >> 0x19); ++ { uint32_t x87 = ((uint32_t)x85 & 0x1ffffff); ++ { uint64_t x88 = (x86 + x40); ++ { uint64_t x89 = (x88 >> 0x1a); ++ { uint32_t x90 = ((uint32_t)x88 & 0x3ffffff); ++ { uint64_t x91 = (x89 + x28); ++ { uint64_t x92 = (x91 >> 0x19); ++ { uint32_t x93 = ((uint32_t)x91 & 0x1ffffff); ++ { uint64_t x94 = (x66 + (0x13 * x92)); ++ { uint32_t x95 = (uint32_t) (x94 >> 0x1a); ++ { uint32_t x96 = ((uint32_t)x94 & 0x3ffffff); ++ { uint32_t x97 = (x95 + x69); ++ { uint32_t x98 = (x97 >> 0x19); ++ { uint32_t x99 = (x97 & 0x1ffffff); ++ out[0] = x96; ++ out[1] = x99; ++ out[2] = (x98 + x72); ++ out[3] = x75; ++ out[4] = x78; ++ out[5] = x81; ++ out[6] = x84; ++ out[7] = x87; ++ out[8] = x90; ++ out[9] = x93; ++ }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}} ++ assert_fe(out); ++} ++ ++static void fe_sq_tl(fe *h, const fe_loose *f) { ++ fe_sqr_impl(h->v, f->v); ++} ++ ++static void fe_sq_tt(fe *h, const fe *f) { ++ fe_sqr_impl(h->v, f->v); ++} ++ ++// Adapted from Fiat-synthesized |fe_sub_impl| with |out| = 0. ++static void fe_neg_impl(uint32_t out[10], const uint32_t in2[10]) { ++ { const uint32_t x20 = 0; ++ { const uint32_t x21 = 0; ++ { const uint32_t x19 = 0; ++ { const uint32_t x17 = 0; ++ { const uint32_t x15 = 0; ++ { const uint32_t x13 = 0; ++ { const uint32_t x11 = 0; ++ { const uint32_t x9 = 0; ++ { const uint32_t x7 = 0; ++ { const uint32_t x5 = 0; ++ { const uint32_t x38 = in2[9]; ++ { const uint32_t x39 = in2[8]; ++ { const uint32_t x37 = in2[7]; ++ { const uint32_t x35 = in2[6]; ++ { const uint32_t x33 = in2[5]; ++ { const uint32_t x31 = in2[4]; ++ { const uint32_t x29 = in2[3]; ++ { const uint32_t x27 = in2[2]; ++ { const uint32_t x25 = in2[1]; ++ { const uint32_t x23 = in2[0]; ++ out[0] = ((0x7ffffda + x5) - x23); ++ out[1] = ((0x3fffffe + x7) - x25); ++ out[2] = ((0x7fffffe + x9) - x27); ++ out[3] = ((0x3fffffe + x11) - x29); ++ out[4] = ((0x7fffffe + x13) - x31); ++ out[5] = ((0x3fffffe + x15) - x33); ++ out[6] = ((0x7fffffe + x17) - x35); ++ out[7] = ((0x3fffffe + x19) - x37); ++ out[8] = ((0x7fffffe + x21) - x39); ++ out[9] = ((0x3fffffe + x20) - x38); ++ }}}}}}}}}}}}}}}}}}}} ++} ++ ++// h = -f ++static void fe_neg(fe_loose *h, const fe *f) { ++ assert_fe(f->v); ++ fe_neg_impl(h->v, f->v); ++ assert_fe_loose(h->v); ++} ++ ++// Replace (f,g) with (g,g) if b == 1; ++// replace (f,g) with (f,g) if b == 0. ++// ++// Preconditions: b in {0,1}. ++static void fe_cmov(fe_loose *f, const fe_loose *g, unsigned b) { ++ b = 0-b; ++ unsigned i; ++ for (i = 0; i < 10; i++) { ++ uint32_t x = f->v[i] ^ g->v[i]; ++ x &= b; ++ f->v[i] ^= x; ++ } ++} ++ ++#endif // BORINGSSL_CURVE25519_64BIT ++ ++// h = f ++static void fe_copy(fe *h, const fe *f) { ++ memmove(h, f, sizeof(fe)); ++} ++ ++static void fe_copy_lt(fe_loose *h, const fe *f) { ++#ifdef EDWARDS25519_ASSERTS ++ assert(sizeof(fe_loose) == sizeof(fe)); ++#endif ++ memmove(h, f, sizeof(fe)); ++} ++#if !defined(CONFIG_SMALL) ++static void fe_copy_ll(fe_loose *h, const fe_loose *f) { ++ memmove(h, f, sizeof(fe_loose)); ++} ++#endif // !defined(CONFIG_SMALL) ++ ++static void fe_loose_invert(fe *out, const fe_loose *z) { ++ fe t0; ++ fe t1; ++ fe t2; ++ fe t3; ++ int i; ++ ++ fe_sq_tl(&t0, z); ++ fe_sq_tt(&t1, &t0); ++ for (i = 1; i < 2; ++i) { ++ fe_sq_tt(&t1, &t1); ++ } ++ fe_mul_tlt(&t1, z, &t1); ++ fe_mul_ttt(&t0, &t0, &t1); ++ fe_sq_tt(&t2, &t0); ++ fe_mul_ttt(&t1, &t1, &t2); ++ fe_sq_tt(&t2, &t1); ++ for (i = 1; i < 5; ++i) { ++ fe_sq_tt(&t2, &t2); ++ } ++ fe_mul_ttt(&t1, &t2, &t1); ++ fe_sq_tt(&t2, &t1); ++ for (i = 1; i < 10; ++i) { ++ fe_sq_tt(&t2, &t2); ++ } ++ fe_mul_ttt(&t2, &t2, &t1); ++ fe_sq_tt(&t3, &t2); ++ for (i = 1; i < 20; ++i) { ++ fe_sq_tt(&t3, &t3); ++ } ++ fe_mul_ttt(&t2, &t3, &t2); ++ fe_sq_tt(&t2, &t2); ++ for (i = 1; i < 10; ++i) { ++ fe_sq_tt(&t2, &t2); ++ } ++ fe_mul_ttt(&t1, &t2, &t1); ++ fe_sq_tt(&t2, &t1); ++ for (i = 1; i < 50; ++i) { ++ fe_sq_tt(&t2, &t2); ++ } ++ fe_mul_ttt(&t2, &t2, &t1); ++ fe_sq_tt(&t3, &t2); ++ for (i = 1; i < 100; ++i) { ++ fe_sq_tt(&t3, &t3); ++ } ++ fe_mul_ttt(&t2, &t3, &t2); ++ fe_sq_tt(&t2, &t2); ++ for (i = 1; i < 50; ++i) { ++ fe_sq_tt(&t2, &t2); ++ } ++ fe_mul_ttt(&t1, &t2, &t1); ++ fe_sq_tt(&t1, &t1); ++ for (i = 1; i < 5; ++i) { ++ fe_sq_tt(&t1, &t1); ++ } ++ fe_mul_ttt(out, &t1, &t0); ++} ++ ++static void fe_invert(fe *out, const fe *z) { ++ fe_loose l; ++ fe_copy_lt(&l, z); ++ fe_loose_invert(out, &l); ++} ++ ++// return 0 if f == 0 ++// return 1 if f != 0 ++static int fe_isnonzero(const fe_loose *f) { ++ fe tight; ++ fe_carry(&tight, f); ++ uint8_t s[32]; ++ fe_tobytes(s, &tight); ++ ++ static const uint8_t zero[32] = {0}; ++ return k5_bcmp(s, zero, sizeof(zero)) != 0; ++} ++ ++// return 1 if f is in {1,3,5,...,q-2} ++// return 0 if f is in {0,2,4,...,q-1} ++static int fe_isnegative(const fe *f) { ++ uint8_t s[32]; ++ fe_tobytes(s, f); ++ return s[0] & 1; ++} ++ ++static void fe_sq2_tt(fe *h, const fe *f) { ++ // h = f^2 ++ fe_sq_tt(h, f); ++ ++ // h = h + h ++ fe_loose tmp; ++ fe_add(&tmp, h, h); ++ fe_carry(h, &tmp); ++} ++ ++static void fe_pow22523(fe *out, const fe *z) { ++ fe t0; ++ fe t1; ++ fe t2; ++ int i; ++ ++ fe_sq_tt(&t0, z); ++ fe_sq_tt(&t1, &t0); ++ for (i = 1; i < 2; ++i) { ++ fe_sq_tt(&t1, &t1); ++ } ++ fe_mul_ttt(&t1, z, &t1); ++ fe_mul_ttt(&t0, &t0, &t1); ++ fe_sq_tt(&t0, &t0); ++ fe_mul_ttt(&t0, &t1, &t0); ++ fe_sq_tt(&t1, &t0); ++ for (i = 1; i < 5; ++i) { ++ fe_sq_tt(&t1, &t1); ++ } ++ fe_mul_ttt(&t0, &t1, &t0); ++ fe_sq_tt(&t1, &t0); ++ for (i = 1; i < 10; ++i) { ++ fe_sq_tt(&t1, &t1); ++ } ++ fe_mul_ttt(&t1, &t1, &t0); ++ fe_sq_tt(&t2, &t1); ++ for (i = 1; i < 20; ++i) { ++ fe_sq_tt(&t2, &t2); ++ } ++ fe_mul_ttt(&t1, &t2, &t1); ++ fe_sq_tt(&t1, &t1); ++ for (i = 1; i < 10; ++i) { ++ fe_sq_tt(&t1, &t1); ++ } ++ fe_mul_ttt(&t0, &t1, &t0); ++ fe_sq_tt(&t1, &t0); ++ for (i = 1; i < 50; ++i) { ++ fe_sq_tt(&t1, &t1); ++ } ++ fe_mul_ttt(&t1, &t1, &t0); ++ fe_sq_tt(&t2, &t1); ++ for (i = 1; i < 100; ++i) { ++ fe_sq_tt(&t2, &t2); ++ } ++ fe_mul_ttt(&t1, &t2, &t1); ++ fe_sq_tt(&t1, &t1); ++ for (i = 1; i < 50; ++i) { ++ fe_sq_tt(&t1, &t1); ++ } ++ fe_mul_ttt(&t0, &t1, &t0); ++ fe_sq_tt(&t0, &t0); ++ for (i = 1; i < 2; ++i) { ++ fe_sq_tt(&t0, &t0); ++ } ++ fe_mul_ttt(out, &t0, z); ++} ++ ++ ++// Group operations. ++ ++static void x25519_ge_tobytes(uint8_t s[32], const ge_p2 *h) { ++ fe recip; ++ fe x; ++ fe y; ++ ++ fe_invert(&recip, &h->Z); ++ fe_mul_ttt(&x, &h->X, &recip); ++ fe_mul_ttt(&y, &h->Y, &recip); ++ fe_tobytes(s, &y); ++ s[31] ^= fe_isnegative(&x) << 7; ++} ++ ++static int x25519_ge_frombytes_vartime(ge_p3 *h, const uint8_t *s) { ++ fe u; ++ fe_loose v; ++ fe v3; ++ fe vxx; ++ fe_loose check; ++ ++ fe_frombytes(&h->Y, s); ++ fe_1(&h->Z); ++ fe_sq_tt(&v3, &h->Y); ++ fe_mul_ttt(&vxx, &v3, &d); ++ fe_sub(&v, &v3, &h->Z); // u = y^2-1 ++ fe_carry(&u, &v); ++ fe_add(&v, &vxx, &h->Z); // v = dy^2+1 ++ ++ fe_sq_tl(&v3, &v); ++ fe_mul_ttl(&v3, &v3, &v); // v3 = v^3 ++ fe_sq_tt(&h->X, &v3); ++ fe_mul_ttl(&h->X, &h->X, &v); ++ fe_mul_ttt(&h->X, &h->X, &u); // x = uv^7 ++ ++ fe_pow22523(&h->X, &h->X); // x = (uv^7)^((q-5)/8) ++ fe_mul_ttt(&h->X, &h->X, &v3); ++ fe_mul_ttt(&h->X, &h->X, &u); // x = uv^3(uv^7)^((q-5)/8) ++ ++ fe_sq_tt(&vxx, &h->X); ++ fe_mul_ttl(&vxx, &vxx, &v); ++ fe_sub(&check, &vxx, &u); ++ if (fe_isnonzero(&check)) { ++ fe_add(&check, &vxx, &u); ++ if (fe_isnonzero(&check)) { ++ return -1; ++ } ++ fe_mul_ttt(&h->X, &h->X, &sqrtm1); ++ } ++ ++ if (fe_isnegative(&h->X) != (s[31] >> 7)) { ++ fe_loose t; ++ fe_neg(&t, &h->X); ++ fe_carry(&h->X, &t); ++ } ++ ++ fe_mul_ttt(&h->T, &h->X, &h->Y); ++ return 0; ++} ++ ++static void ge_p2_0(ge_p2 *h) { ++ fe_0(&h->X); ++ fe_1(&h->Y); ++ fe_1(&h->Z); ++} ++ ++static void ge_p3_0(ge_p3 *h) { ++ fe_0(&h->X); ++ fe_1(&h->Y); ++ fe_1(&h->Z); ++ fe_0(&h->T); ++} ++ ++static void ge_cached_0(ge_cached *h) { ++ fe_loose_1(&h->YplusX); ++ fe_loose_1(&h->YminusX); ++ fe_loose_1(&h->Z); ++ fe_loose_0(&h->T2d); ++} ++ ++static void ge_precomp_0(ge_precomp *h) { ++ fe_loose_1(&h->yplusx); ++ fe_loose_1(&h->yminusx); ++ fe_loose_0(&h->xy2d); ++} ++ ++// r = p ++static void ge_p3_to_p2(ge_p2 *r, const ge_p3 *p) { ++ fe_copy(&r->X, &p->X); ++ fe_copy(&r->Y, &p->Y); ++ fe_copy(&r->Z, &p->Z); ++} ++ ++// r = p ++static void x25519_ge_p3_to_cached(ge_cached *r, const ge_p3 *p) { ++ fe_add(&r->YplusX, &p->Y, &p->X); ++ fe_sub(&r->YminusX, &p->Y, &p->X); ++ fe_copy_lt(&r->Z, &p->Z); ++ fe_mul_ltt(&r->T2d, &p->T, &d2); ++} ++ ++// r = p ++static void x25519_ge_p1p1_to_p2(ge_p2 *r, const ge_p1p1 *p) { ++ fe_mul_tll(&r->X, &p->X, &p->T); ++ fe_mul_tll(&r->Y, &p->Y, &p->Z); ++ fe_mul_tll(&r->Z, &p->Z, &p->T); ++} ++ ++// r = p ++static void x25519_ge_p1p1_to_p3(ge_p3 *r, const ge_p1p1 *p) { ++ fe_mul_tll(&r->X, &p->X, &p->T); ++ fe_mul_tll(&r->Y, &p->Y, &p->Z); ++ fe_mul_tll(&r->Z, &p->Z, &p->T); ++ fe_mul_tll(&r->T, &p->X, &p->Y); ++} ++ ++// r = p ++static void ge_p1p1_to_cached(ge_cached *r, const ge_p1p1 *p) { ++ ge_p3 t; ++ x25519_ge_p1p1_to_p3(&t, p); ++ x25519_ge_p3_to_cached(r, &t); ++} ++ ++// r = 2 * p ++static void ge_p2_dbl(ge_p1p1 *r, const ge_p2 *p) { ++ fe trX, trZ, trT; ++ fe t0; ++ ++ fe_sq_tt(&trX, &p->X); ++ fe_sq_tt(&trZ, &p->Y); ++ fe_sq2_tt(&trT, &p->Z); ++ fe_add(&r->Y, &p->X, &p->Y); ++ fe_sq_tl(&t0, &r->Y); ++ ++ fe_add(&r->Y, &trZ, &trX); ++ fe_sub(&r->Z, &trZ, &trX); ++ fe_carry(&trZ, &r->Y); ++ fe_sub(&r->X, &t0, &trZ); ++ fe_carry(&trZ, &r->Z); ++ fe_sub(&r->T, &trT, &trZ); ++} ++ ++#ifndef CONFIG_SMALL ++// r = 2 * p ++static void ge_p3_dbl(ge_p1p1 *r, const ge_p3 *p) { ++ ge_p2 q; ++ ge_p3_to_p2(&q, p); ++ ge_p2_dbl(r, &q); ++} ++#endif ++ ++// r = p + q ++static void ge_madd(ge_p1p1 *r, const ge_p3 *p, const ge_precomp *q) { ++ fe trY, trZ, trT; ++ ++ fe_add(&r->X, &p->Y, &p->X); ++ fe_sub(&r->Y, &p->Y, &p->X); ++ fe_mul_tll(&trZ, &r->X, &q->yplusx); ++ fe_mul_tll(&trY, &r->Y, &q->yminusx); ++ fe_mul_tlt(&trT, &q->xy2d, &p->T); ++ fe_add(&r->T, &p->Z, &p->Z); ++ fe_sub(&r->X, &trZ, &trY); ++ fe_add(&r->Y, &trZ, &trY); ++ fe_carry(&trZ, &r->T); ++ fe_add(&r->Z, &trZ, &trT); ++ fe_sub(&r->T, &trZ, &trT); ++} ++ ++// r = p + q ++static void x25519_ge_add(ge_p1p1 *r, const ge_p3 *p, const ge_cached *q) { ++ fe trX, trY, trZ, trT; ++ ++ fe_add(&r->X, &p->Y, &p->X); ++ fe_sub(&r->Y, &p->Y, &p->X); ++ fe_mul_tll(&trZ, &r->X, &q->YplusX); ++ fe_mul_tll(&trY, &r->Y, &q->YminusX); ++ fe_mul_tlt(&trT, &q->T2d, &p->T); ++ fe_mul_ttl(&trX, &p->Z, &q->Z); ++ fe_add(&r->T, &trX, &trX); ++ fe_sub(&r->X, &trZ, &trY); ++ fe_add(&r->Y, &trZ, &trY); ++ fe_carry(&trZ, &r->T); ++ fe_add(&r->Z, &trZ, &trT); ++ fe_sub(&r->T, &trZ, &trT); ++} ++ ++// r = p - q ++static void x25519_ge_sub(ge_p1p1 *r, const ge_p3 *p, const ge_cached *q) { ++ fe trX, trY, trZ, trT; ++ ++ fe_add(&r->X, &p->Y, &p->X); ++ fe_sub(&r->Y, &p->Y, &p->X); ++ fe_mul_tll(&trZ, &r->X, &q->YminusX); ++ fe_mul_tll(&trY, &r->Y, &q->YplusX); ++ fe_mul_tlt(&trT, &q->T2d, &p->T); ++ fe_mul_ttl(&trX, &p->Z, &q->Z); ++ fe_add(&r->T, &trX, &trX); ++ fe_sub(&r->X, &trZ, &trY); ++ fe_add(&r->Y, &trZ, &trY); ++ fe_carry(&trZ, &r->T); ++ fe_sub(&r->Z, &trZ, &trT); ++ fe_add(&r->T, &trZ, &trT); ++} ++ ++static uint8_t equal(signed char b, signed char c) { ++ uint8_t ub = b; ++ uint8_t uc = c; ++ uint8_t x = ub ^ uc; // 0: yes; 1..255: no ++ uint32_t y = x; // 0: yes; 1..255: no ++ y -= 1; // 4294967295: yes; 0..254: no ++ y >>= 31; // 1: yes; 0: no ++ return y; ++} ++ ++static void cmov(ge_precomp *t, const ge_precomp *u, uint8_t b) { ++ fe_cmov(&t->yplusx, &u->yplusx, b); ++ fe_cmov(&t->yminusx, &u->yminusx, b); ++ fe_cmov(&t->xy2d, &u->xy2d, b); ++} ++ ++static void x25519_ge_scalarmult_small_precomp( ++ ge_p3 *h, const uint8_t a[32], const uint8_t precomp_table[15 * 2 * 32]) { ++ // precomp_table is first expanded into matching |ge_precomp| ++ // elements. ++ ge_precomp multiples[15]; ++ ++ unsigned i; ++ for (i = 0; i < 15; i++) { ++ const uint8_t *bytes = &precomp_table[i*(2 * 32)]; ++ fe x, y; ++ fe_frombytes(&x, bytes); ++ fe_frombytes(&y, bytes + 32); ++ ++ ge_precomp *out = &multiples[i]; ++ fe_add(&out->yplusx, &y, &x); ++ fe_sub(&out->yminusx, &y, &x); ++ fe_mul_ltt(&out->xy2d, &x, &y); ++ fe_mul_llt(&out->xy2d, &out->xy2d, &d2); ++ } ++ ++ // See the comment above |k25519SmallPrecomp| about the structure of the ++ // precomputed elements. This loop does 64 additions and 64 doublings to ++ // calculate the result. ++ ge_p3_0(h); ++ ++ for (i = 63; i < 64; i--) { ++ unsigned j; ++ signed char index = 0; ++ ++ for (j = 0; j < 4; j++) { ++ const uint8_t bit = 1 & (a[(8 * j) + (i / 8)] >> (i & 7)); ++ index |= (bit << j); ++ } ++ ++ ge_precomp e; ++ ge_precomp_0(&e); ++ ++ for (j = 1; j < 16; j++) { ++ cmov(&e, &multiples[j-1], equal(index, j)); ++ } ++ ++ ge_cached cached; ++ ge_p1p1 r; ++ x25519_ge_p3_to_cached(&cached, h); ++ x25519_ge_add(&r, h, &cached); ++ x25519_ge_p1p1_to_p3(h, &r); ++ ++ ge_madd(&r, h, &e); ++ x25519_ge_p1p1_to_p3(h, &r); ++ } ++} ++ ++#if defined(CONFIG_SMALL) ++ ++static void x25519_ge_scalarmult_base(ge_p3 *h, const uint8_t a[32]) { ++ x25519_ge_scalarmult_small_precomp(h, a, k25519SmallPrecomp); ++} ++ ++#else ++ ++static uint8_t negative(signed char b) { ++ uint32_t x = b; ++ x >>= 31; // 1: yes; 0: no ++ return x; ++} ++ ++static void table_select(ge_precomp *t, int pos, signed char b) { ++ ge_precomp minust; ++ uint8_t bnegative = negative(b); ++ uint8_t babs = b - ((uint8_t)((-bnegative) & b) << 1); ++ ++ ge_precomp_0(t); ++ cmov(t, &k25519Precomp[pos][0], equal(babs, 1)); ++ cmov(t, &k25519Precomp[pos][1], equal(babs, 2)); ++ cmov(t, &k25519Precomp[pos][2], equal(babs, 3)); ++ cmov(t, &k25519Precomp[pos][3], equal(babs, 4)); ++ cmov(t, &k25519Precomp[pos][4], equal(babs, 5)); ++ cmov(t, &k25519Precomp[pos][5], equal(babs, 6)); ++ cmov(t, &k25519Precomp[pos][6], equal(babs, 7)); ++ cmov(t, &k25519Precomp[pos][7], equal(babs, 8)); ++ fe_copy_ll(&minust.yplusx, &t->yminusx); ++ fe_copy_ll(&minust.yminusx, &t->yplusx); ++ ++ // NOTE: the input table is canonical, but types don't encode it ++ fe tmp; ++ fe_carry(&tmp, &t->xy2d); ++ fe_neg(&minust.xy2d, &tmp); ++ ++ cmov(t, &minust, bnegative); ++} ++ ++// h = a * B ++// where a = a[0]+256*a[1]+...+256^31 a[31] ++// B is the Ed25519 base point (x,4/5) with x positive. ++// ++// Preconditions: ++// a[31] <= 127 ++static void x25519_ge_scalarmult_base(ge_p3 *h, const uint8_t *a) { ++ signed char e[64]; ++ signed char carry; ++ ge_p1p1 r; ++ ge_p2 s; ++ ge_precomp t; ++ int i; ++ ++ for (i = 0; i < 32; ++i) { ++ e[2 * i + 0] = (a[i] >> 0) & 15; ++ e[2 * i + 1] = (a[i] >> 4) & 15; ++ } ++ // each e[i] is between 0 and 15 ++ // e[63] is between 0 and 7 ++ ++ carry = 0; ++ for (i = 0; i < 63; ++i) { ++ e[i] += carry; ++ carry = e[i] + 8; ++ carry >>= 4; ++ e[i] -= carry << 4; ++ } ++ e[63] += carry; ++ // each e[i] is between -8 and 8 ++ ++ ge_p3_0(h); ++ for (i = 1; i < 64; i += 2) { ++ table_select(&t, i / 2, e[i]); ++ ge_madd(&r, h, &t); ++ x25519_ge_p1p1_to_p3(h, &r); ++ } ++ ++ ge_p3_dbl(&r, h); ++ x25519_ge_p1p1_to_p2(&s, &r); ++ ge_p2_dbl(&r, &s); ++ x25519_ge_p1p1_to_p2(&s, &r); ++ ge_p2_dbl(&r, &s); ++ x25519_ge_p1p1_to_p2(&s, &r); ++ ge_p2_dbl(&r, &s); ++ x25519_ge_p1p1_to_p3(h, &r); ++ ++ for (i = 0; i < 64; i += 2) { ++ table_select(&t, i / 2, e[i]); ++ ge_madd(&r, h, &t); ++ x25519_ge_p1p1_to_p3(h, &r); ++ } ++} ++ ++#endif ++ ++static void cmov_cached(ge_cached *t, ge_cached *u, uint8_t b) { ++ fe_cmov(&t->YplusX, &u->YplusX, b); ++ fe_cmov(&t->YminusX, &u->YminusX, b); ++ fe_cmov(&t->Z, &u->Z, b); ++ fe_cmov(&t->T2d, &u->T2d, b); ++} ++ ++// r = scalar * A. ++// where a = a[0]+256*a[1]+...+256^31 a[31]. ++static void x25519_ge_scalarmult(ge_p2 *r, const uint8_t *scalar, ++ const ge_p3 *A) { ++ ge_p2 Ai_p2[8]; ++ ge_cached Ai[16]; ++ ge_p1p1 t; ++ ++ ge_cached_0(&Ai[0]); ++ x25519_ge_p3_to_cached(&Ai[1], A); ++ ge_p3_to_p2(&Ai_p2[1], A); ++ ++ unsigned i; ++ for (i = 2; i < 16; i += 2) { ++ ge_p2_dbl(&t, &Ai_p2[i / 2]); ++ ge_p1p1_to_cached(&Ai[i], &t); ++ if (i < 8) { ++ x25519_ge_p1p1_to_p2(&Ai_p2[i], &t); ++ } ++ x25519_ge_add(&t, A, &Ai[i]); ++ ge_p1p1_to_cached(&Ai[i + 1], &t); ++ if (i < 7) { ++ x25519_ge_p1p1_to_p2(&Ai_p2[i + 1], &t); ++ } ++ } ++ ++ ge_p2_0(r); ++ ge_p3 u; ++ ++ for (i = 0; i < 256; i += 4) { ++ ge_p2_dbl(&t, r); ++ x25519_ge_p1p1_to_p2(r, &t); ++ ge_p2_dbl(&t, r); ++ x25519_ge_p1p1_to_p2(r, &t); ++ ge_p2_dbl(&t, r); ++ x25519_ge_p1p1_to_p2(r, &t); ++ ge_p2_dbl(&t, r); ++ x25519_ge_p1p1_to_p3(&u, &t); ++ ++ uint8_t index = scalar[31 - i/8]; ++ index >>= 4 - (i & 4); ++ index &= 0xf; ++ ++ unsigned j; ++ ge_cached selected; ++ ge_cached_0(&selected); ++ for (j = 0; j < 16; j++) { ++ cmov_cached(&selected, &Ai[j], equal(j, index)); ++ } ++ ++ x25519_ge_add(&t, &u, &selected); ++ x25519_ge_p1p1_to_p2(r, &t); ++ } ++} ++ ++// The set of scalars is \Z/l ++// where l = 2^252 + 27742317777372353535851937790883648493. ++ ++// Input: ++// s[0]+256*s[1]+...+256^63*s[63] = s ++// ++// Output: ++// s[0]+256*s[1]+...+256^31*s[31] = s mod l ++// where l = 2^252 + 27742317777372353535851937790883648493. ++// Overwrites s in place. ++static void x25519_sc_reduce(uint8_t s[64]) { ++ int64_t s0 = 2097151 & load_3(s); ++ int64_t s1 = 2097151 & (load_4(s + 2) >> 5); ++ int64_t s2 = 2097151 & (load_3(s + 5) >> 2); ++ int64_t s3 = 2097151 & (load_4(s + 7) >> 7); ++ int64_t s4 = 2097151 & (load_4(s + 10) >> 4); ++ int64_t s5 = 2097151 & (load_3(s + 13) >> 1); ++ int64_t s6 = 2097151 & (load_4(s + 15) >> 6); ++ int64_t s7 = 2097151 & (load_3(s + 18) >> 3); ++ int64_t s8 = 2097151 & load_3(s + 21); ++ int64_t s9 = 2097151 & (load_4(s + 23) >> 5); ++ int64_t s10 = 2097151 & (load_3(s + 26) >> 2); ++ int64_t s11 = 2097151 & (load_4(s + 28) >> 7); ++ int64_t s12 = 2097151 & (load_4(s + 31) >> 4); ++ int64_t s13 = 2097151 & (load_3(s + 34) >> 1); ++ int64_t s14 = 2097151 & (load_4(s + 36) >> 6); ++ int64_t s15 = 2097151 & (load_3(s + 39) >> 3); ++ int64_t s16 = 2097151 & load_3(s + 42); ++ int64_t s17 = 2097151 & (load_4(s + 44) >> 5); ++ int64_t s18 = 2097151 & (load_3(s + 47) >> 2); ++ int64_t s19 = 2097151 & (load_4(s + 49) >> 7); ++ int64_t s20 = 2097151 & (load_4(s + 52) >> 4); ++ int64_t s21 = 2097151 & (load_3(s + 55) >> 1); ++ int64_t s22 = 2097151 & (load_4(s + 57) >> 6); ++ int64_t s23 = (load_4(s + 60) >> 3); ++ int64_t carry0; ++ int64_t carry1; ++ int64_t carry2; ++ int64_t carry3; ++ int64_t carry4; ++ int64_t carry5; ++ int64_t carry6; ++ int64_t carry7; ++ int64_t carry8; ++ int64_t carry9; ++ int64_t carry10; ++ int64_t carry11; ++ int64_t carry12; ++ int64_t carry13; ++ int64_t carry14; ++ int64_t carry15; ++ int64_t carry16; ++ ++ s11 += s23 * 666643; ++ s12 += s23 * 470296; ++ s13 += s23 * 654183; ++ s14 -= s23 * 997805; ++ s15 += s23 * 136657; ++ s16 -= s23 * 683901; ++ s23 = 0; ++ ++ s10 += s22 * 666643; ++ s11 += s22 * 470296; ++ s12 += s22 * 654183; ++ s13 -= s22 * 997805; ++ s14 += s22 * 136657; ++ s15 -= s22 * 683901; ++ s22 = 0; ++ ++ s9 += s21 * 666643; ++ s10 += s21 * 470296; ++ s11 += s21 * 654183; ++ s12 -= s21 * 997805; ++ s13 += s21 * 136657; ++ s14 -= s21 * 683901; ++ s21 = 0; ++ ++ s8 += s20 * 666643; ++ s9 += s20 * 470296; ++ s10 += s20 * 654183; ++ s11 -= s20 * 997805; ++ s12 += s20 * 136657; ++ s13 -= s20 * 683901; ++ s20 = 0; ++ ++ s7 += s19 * 666643; ++ s8 += s19 * 470296; ++ s9 += s19 * 654183; ++ s10 -= s19 * 997805; ++ s11 += s19 * 136657; ++ s12 -= s19 * 683901; ++ s19 = 0; ++ ++ s6 += s18 * 666643; ++ s7 += s18 * 470296; ++ s8 += s18 * 654183; ++ s9 -= s18 * 997805; ++ s10 += s18 * 136657; ++ s11 -= s18 * 683901; ++ s18 = 0; ++ ++ carry6 = (s6 + (1 << 20)) >> 21; ++ s7 += carry6; ++ s6 -= carry6 << 21; ++ carry8 = (s8 + (1 << 20)) >> 21; ++ s9 += carry8; ++ s8 -= carry8 << 21; ++ carry10 = (s10 + (1 << 20)) >> 21; ++ s11 += carry10; ++ s10 -= carry10 << 21; ++ carry12 = (s12 + (1 << 20)) >> 21; ++ s13 += carry12; ++ s12 -= carry12 << 21; ++ carry14 = (s14 + (1 << 20)) >> 21; ++ s15 += carry14; ++ s14 -= carry14 << 21; ++ carry16 = (s16 + (1 << 20)) >> 21; ++ s17 += carry16; ++ s16 -= carry16 << 21; ++ ++ carry7 = (s7 + (1 << 20)) >> 21; ++ s8 += carry7; ++ s7 -= carry7 << 21; ++ carry9 = (s9 + (1 << 20)) >> 21; ++ s10 += carry9; ++ s9 -= carry9 << 21; ++ carry11 = (s11 + (1 << 20)) >> 21; ++ s12 += carry11; ++ s11 -= carry11 << 21; ++ carry13 = (s13 + (1 << 20)) >> 21; ++ s14 += carry13; ++ s13 -= carry13 << 21; ++ carry15 = (s15 + (1 << 20)) >> 21; ++ s16 += carry15; ++ s15 -= carry15 << 21; ++ ++ s5 += s17 * 666643; ++ s6 += s17 * 470296; ++ s7 += s17 * 654183; ++ s8 -= s17 * 997805; ++ s9 += s17 * 136657; ++ s10 -= s17 * 683901; ++ s17 = 0; ++ ++ s4 += s16 * 666643; ++ s5 += s16 * 470296; ++ s6 += s16 * 654183; ++ s7 -= s16 * 997805; ++ s8 += s16 * 136657; ++ s9 -= s16 * 683901; ++ s16 = 0; ++ ++ s3 += s15 * 666643; ++ s4 += s15 * 470296; ++ s5 += s15 * 654183; ++ s6 -= s15 * 997805; ++ s7 += s15 * 136657; ++ s8 -= s15 * 683901; ++ s15 = 0; ++ ++ s2 += s14 * 666643; ++ s3 += s14 * 470296; ++ s4 += s14 * 654183; ++ s5 -= s14 * 997805; ++ s6 += s14 * 136657; ++ s7 -= s14 * 683901; ++ s14 = 0; ++ ++ s1 += s13 * 666643; ++ s2 += s13 * 470296; ++ s3 += s13 * 654183; ++ s4 -= s13 * 997805; ++ s5 += s13 * 136657; ++ s6 -= s13 * 683901; ++ s13 = 0; ++ ++ s0 += s12 * 666643; ++ s1 += s12 * 470296; ++ s2 += s12 * 654183; ++ s3 -= s12 * 997805; ++ s4 += s12 * 136657; ++ s5 -= s12 * 683901; ++ s12 = 0; ++ ++ carry0 = (s0 + (1 << 20)) >> 21; ++ s1 += carry0; ++ s0 -= carry0 << 21; ++ carry2 = (s2 + (1 << 20)) >> 21; ++ s3 += carry2; ++ s2 -= carry2 << 21; ++ carry4 = (s4 + (1 << 20)) >> 21; ++ s5 += carry4; ++ s4 -= carry4 << 21; ++ carry6 = (s6 + (1 << 20)) >> 21; ++ s7 += carry6; ++ s6 -= carry6 << 21; ++ carry8 = (s8 + (1 << 20)) >> 21; ++ s9 += carry8; ++ s8 -= carry8 << 21; ++ carry10 = (s10 + (1 << 20)) >> 21; ++ s11 += carry10; ++ s10 -= carry10 << 21; ++ ++ carry1 = (s1 + (1 << 20)) >> 21; ++ s2 += carry1; ++ s1 -= carry1 << 21; ++ carry3 = (s3 + (1 << 20)) >> 21; ++ s4 += carry3; ++ s3 -= carry3 << 21; ++ carry5 = (s5 + (1 << 20)) >> 21; ++ s6 += carry5; ++ s5 -= carry5 << 21; ++ carry7 = (s7 + (1 << 20)) >> 21; ++ s8 += carry7; ++ s7 -= carry7 << 21; ++ carry9 = (s9 + (1 << 20)) >> 21; ++ s10 += carry9; ++ s9 -= carry9 << 21; ++ carry11 = (s11 + (1 << 20)) >> 21; ++ s12 += carry11; ++ s11 -= carry11 << 21; ++ ++ s0 += s12 * 666643; ++ s1 += s12 * 470296; ++ s2 += s12 * 654183; ++ s3 -= s12 * 997805; ++ s4 += s12 * 136657; ++ s5 -= s12 * 683901; ++ s12 = 0; ++ ++ carry0 = s0 >> 21; ++ s1 += carry0; ++ s0 -= carry0 << 21; ++ carry1 = s1 >> 21; ++ s2 += carry1; ++ s1 -= carry1 << 21; ++ carry2 = s2 >> 21; ++ s3 += carry2; ++ s2 -= carry2 << 21; ++ carry3 = s3 >> 21; ++ s4 += carry3; ++ s3 -= carry3 << 21; ++ carry4 = s4 >> 21; ++ s5 += carry4; ++ s4 -= carry4 << 21; ++ carry5 = s5 >> 21; ++ s6 += carry5; ++ s5 -= carry5 << 21; ++ carry6 = s6 >> 21; ++ s7 += carry6; ++ s6 -= carry6 << 21; ++ carry7 = s7 >> 21; ++ s8 += carry7; ++ s7 -= carry7 << 21; ++ carry8 = s8 >> 21; ++ s9 += carry8; ++ s8 -= carry8 << 21; ++ carry9 = s9 >> 21; ++ s10 += carry9; ++ s9 -= carry9 << 21; ++ carry10 = s10 >> 21; ++ s11 += carry10; ++ s10 -= carry10 << 21; ++ carry11 = s11 >> 21; ++ s12 += carry11; ++ s11 -= carry11 << 21; ++ ++ s0 += s12 * 666643; ++ s1 += s12 * 470296; ++ s2 += s12 * 654183; ++ s3 -= s12 * 997805; ++ s4 += s12 * 136657; ++ s5 -= s12 * 683901; ++ s12 = 0; ++ ++ carry0 = s0 >> 21; ++ s1 += carry0; ++ s0 -= carry0 << 21; ++ carry1 = s1 >> 21; ++ s2 += carry1; ++ s1 -= carry1 << 21; ++ carry2 = s2 >> 21; ++ s3 += carry2; ++ s2 -= carry2 << 21; ++ carry3 = s3 >> 21; ++ s4 += carry3; ++ s3 -= carry3 << 21; ++ carry4 = s4 >> 21; ++ s5 += carry4; ++ s4 -= carry4 << 21; ++ carry5 = s5 >> 21; ++ s6 += carry5; ++ s5 -= carry5 << 21; ++ carry6 = s6 >> 21; ++ s7 += carry6; ++ s6 -= carry6 << 21; ++ carry7 = s7 >> 21; ++ s8 += carry7; ++ s7 -= carry7 << 21; ++ carry8 = s8 >> 21; ++ s9 += carry8; ++ s8 -= carry8 << 21; ++ carry9 = s9 >> 21; ++ s10 += carry9; ++ s9 -= carry9 << 21; ++ carry10 = s10 >> 21; ++ s11 += carry10; ++ s10 -= carry10 << 21; ++ ++ s[0] = s0 >> 0; ++ s[1] = s0 >> 8; ++ s[2] = (s0 >> 16) | (s1 << 5); ++ s[3] = s1 >> 3; ++ s[4] = s1 >> 11; ++ s[5] = (s1 >> 19) | (s2 << 2); ++ s[6] = s2 >> 6; ++ s[7] = (s2 >> 14) | (s3 << 7); ++ s[8] = s3 >> 1; ++ s[9] = s3 >> 9; ++ s[10] = (s3 >> 17) | (s4 << 4); ++ s[11] = s4 >> 4; ++ s[12] = s4 >> 12; ++ s[13] = (s4 >> 20) | (s5 << 1); ++ s[14] = s5 >> 7; ++ s[15] = (s5 >> 15) | (s6 << 6); ++ s[16] = s6 >> 2; ++ s[17] = s6 >> 10; ++ s[18] = (s6 >> 18) | (s7 << 3); ++ s[19] = s7 >> 5; ++ s[20] = s7 >> 13; ++ s[21] = s8 >> 0; ++ s[22] = s8 >> 8; ++ s[23] = (s8 >> 16) | (s9 << 5); ++ s[24] = s9 >> 3; ++ s[25] = s9 >> 11; ++ s[26] = (s9 >> 19) | (s10 << 2); ++ s[27] = s10 >> 6; ++ s[28] = (s10 >> 14) | (s11 << 7); ++ s[29] = s11 >> 1; ++ s[30] = s11 >> 9; ++ s[31] = s11 >> 17; ++} ++ ++/* Loosely from BoringSSL crypto/curve25519/spake25519.c */ ++ ++/* ++ * Here BoringSSL uses different points, not restricted to the generator ++ * subgroup, while we use the draft-irtf-cfrg-spake2-05 points. The Python ++ * code is modified to add the subgroup restriction. ++ */ ++ ++// The following precomputation tables are for the following ++// points: ++// ++// N (found in 7 iterations): ++// x: 10742253510813957597047979962966927467575235974254765187031601461055699024931 ++// y: 19796686047937480651099107989427797822652529149428697746066532921705571401683 ++// encoded: d3bfb518f44f3430f29d0c92af503865a1ed3281dc69b35dd868ba85f886c4ab ++// ++// M (found in 21 iterations): ++// x: 8158688967149231307266666683326742915289288280191350817196911733632187385319 ++// y: 21622333750659878624441478467798461427617029906629724657331223068277098105040 ++// encoded: d048032c6ea0b6d697ddc2e86bda85a33adac920f1bf18e1b0c6d166a5cecdaf ++// ++// These points and their precomputation tables are generated with the ++// following Python code. ++ ++/* ++import hashlib ++import ed25519 as E # http://ed25519.cr.yp.to/python/ed25519.py ++ ++SEED_N = 'edwards25519 point generation seed (N)' ++SEED_M = 'edwards25519 point generation seed (M)' ++ ++def genpoint(seed): ++ v = hashlib.sha256(seed).digest() ++ it = 1 ++ while True: ++ try: ++ x,y = E.decodepoint(v) ++ if E.scalarmult((x,y), E.l) != [0, 1]: ++ raise Exception('point has wrong order') ++ except Exception, e: ++ print e ++ it += 1 ++ v = hashlib.sha256(v).digest() ++ continue ++ print "Found in %d iterations:" % it ++ print " x = %d" % x ++ print " y = %d" % y ++ print " Encoded (hex)" ++ print E.encodepoint((x,y)).encode('hex') ++ return (x,y) ++ ++def gentable(P): ++ t = [] ++ for i in range(1,16): ++ k = (i >> 3 & 1) * (1 << 192) + \ ++ (i >> 2 & 1) * (1 << 128) + \ ++ (i >> 1 & 1) * (1 << 64) + \ ++ (i & 1) ++ t.append(E.scalarmult(P, k)) ++ return ''.join(E.encodeint(x) + E.encodeint(y) for (x,y) in t) ++ ++def printtable(table, name): ++ print "static const uint8_t %s[15 * 2 * 32] = {" % name, ++ for i in range(15 * 2 * 32): ++ if i % 12 == 0: ++ print "\n ", ++ print " 0x%02x," % ord(table[i]), ++ print "\n};" ++ ++if __name__ == "__main__": ++ print "Searching for N" ++ N = genpoint(SEED_N) ++ print "Generating precomputation table for N" ++ Ntable = gentable(N) ++ printtable(Ntable, "kSpakeNSmallPrecomp") ++ ++ print "Searching for M" ++ M = genpoint(SEED_M) ++ print "Generating precomputation table for M" ++ Mtable = gentable(M) ++ printtable(Mtable, "kSpakeMSmallPrecomp") ++*/ ++ ++static const uint8_t kSpakeNSmallPrecomp[15 * 2 * 32] = { ++ 0x23, 0xfc, 0x27, 0x6c, 0x55, 0xaf, 0xb3, 0x9c, 0xd8, 0x99, 0x3a, 0x0d, ++ 0x7f, 0x08, 0xc9, 0xeb, 0x4d, 0x6e, 0x90, 0x99, 0x2f, 0x3c, 0x15, 0x2b, ++ 0x89, 0x5a, 0x0f, 0xf2, 0x67, 0xe6, 0xbf, 0x17, 0xd3, 0xbf, 0xb5, 0x18, ++ 0xf4, 0x4f, 0x34, 0x30, 0xf2, 0x9d, 0x0c, 0x92, 0xaf, 0x50, 0x38, 0x65, ++ 0xa1, 0xed, 0x32, 0x81, 0xdc, 0x69, 0xb3, 0x5d, 0xd8, 0x68, 0xba, 0x85, ++ 0xf8, 0x86, 0xc4, 0x2b, 0x53, 0x93, 0xb1, 0x99, 0x90, 0x30, 0xca, 0xb0, ++ 0xbd, 0xea, 0x14, 0x4c, 0x6f, 0x2b, 0x81, 0x1e, 0x23, 0x45, 0xb2, 0x32, ++ 0x2e, 0x2d, 0xe6, 0xb8, 0x5d, 0xc5, 0x15, 0x91, 0x63, 0x39, 0x18, 0x5b, ++ 0x62, 0x63, 0x9b, 0xf4, 0x8b, 0xe0, 0x34, 0xa2, 0x95, 0x11, 0x92, 0x68, ++ 0x54, 0xb7, 0xf3, 0x91, 0xca, 0x22, 0xad, 0x08, 0xd8, 0x9c, 0xa2, 0xf0, ++ 0xdc, 0x9c, 0x2c, 0x84, 0x32, 0x26, 0xe0, 0x17, 0x89, 0x53, 0x6b, 0xfd, ++ 0x76, 0x97, 0x25, 0xea, 0x99, 0x94, 0xf8, 0x29, 0x7c, 0xc4, 0x53, 0xc0, ++ 0x98, 0x9a, 0x20, 0xdc, 0x70, 0x01, 0x50, 0xaa, 0x05, 0xa3, 0x40, 0x50, ++ 0x66, 0x87, 0x30, 0x19, 0x12, 0xc3, 0xb8, 0x2d, 0x28, 0x8b, 0x7b, 0x48, ++ 0xf7, 0x7b, 0xab, 0x45, 0x70, 0x2e, 0xbb, 0x85, 0xc1, 0x6c, 0xdd, 0x35, ++ 0x00, 0x83, 0x20, 0x13, 0x82, 0x08, 0xaa, 0xa3, 0x03, 0x0f, 0xca, 0x27, ++ 0x3e, 0x8b, 0x52, 0xc2, 0xd7, 0xb1, 0x8c, 0x22, 0xfe, 0x04, 0x4a, 0xf2, ++ 0xe8, 0xac, 0xee, 0x2e, 0xd7, 0x77, 0x34, 0x49, 0xf2, 0xe9, 0xeb, 0x8c, ++ 0xa6, 0xc8, 0xc6, 0xcd, 0x8a, 0x8f, 0x7c, 0x5d, 0x51, 0xc8, 0xfa, 0x6f, ++ 0xb3, 0x93, 0xdb, 0x71, 0xef, 0x3e, 0x6e, 0xa7, 0x85, 0xc7, 0xd4, 0x3e, ++ 0xa2, 0xe2, 0xc0, 0xaa, 0x17, 0xb3, 0xa4, 0x7c, 0xc2, 0x3f, 0x7c, 0x7a, ++ 0xdd, 0x26, 0xde, 0x3e, 0xf1, 0x99, 0x06, 0xf7, 0x69, 0x1b, 0xc9, 0x20, ++ 0x55, 0x4f, 0x86, 0x7a, 0x93, 0x89, 0x68, 0xe9, 0x2b, 0x2d, 0xbc, 0x08, ++ 0x15, 0x5d, 0x2d, 0x0b, 0x4f, 0x1a, 0xb3, 0xd4, 0x8e, 0x77, 0x79, 0x2a, ++ 0x25, 0xf9, 0xb6, 0x46, 0xfb, 0x87, 0x02, 0xa6, 0xe0, 0xd3, 0xba, 0x84, ++ 0xea, 0x3e, 0x58, 0xa5, 0x7f, 0x8f, 0x8c, 0x39, 0x79, 0x28, 0xb5, 0xcf, ++ 0xe4, 0xca, 0x63, 0xdc, 0xac, 0xed, 0x4b, 0x74, 0x1e, 0x94, 0x85, 0x8c, ++ 0xe5, 0xf4, 0x76, 0x6f, 0x20, 0x67, 0x8b, 0xd8, 0xd6, 0x4b, 0xe7, 0x2d, ++ 0xa0, 0xbd, 0xcc, 0x1f, 0xdf, 0x46, 0x9c, 0xa2, 0x49, 0x64, 0xdf, 0x24, ++ 0x00, 0x11, 0x11, 0x45, 0x62, 0x5c, 0xd7, 0x8a, 0x00, 0x02, 0xf5, 0x9b, ++ 0x4f, 0x53, 0x42, 0xc5, 0xd5, 0x55, 0x80, 0x73, 0x9a, 0x5b, 0x31, 0x5a, ++ 0xbd, 0x3a, 0x43, 0xe9, 0x33, 0xe5, 0xaf, 0x1d, 0x92, 0x5e, 0x59, 0x37, ++ 0xae, 0x57, 0xfa, 0x3b, 0xd2, 0x31, 0xae, 0xa6, 0xf9, 0xc9, 0xc1, 0x82, ++ 0xa6, 0xa5, 0xed, 0x24, 0x53, 0x4b, 0x38, 0x22, 0xf2, 0x85, 0x8d, 0x13, ++ 0xa6, 0x5e, 0xd6, 0x57, 0x17, 0xd3, 0x33, 0x38, 0x8d, 0x65, 0xd3, 0xcb, ++ 0x1a, 0xa2, 0x3a, 0x2b, 0xbb, 0x61, 0x53, 0xd7, 0xff, 0xcd, 0x20, 0xb6, ++ 0xbb, 0x8c, 0xab, 0x63, 0xef, 0xb8, 0x26, 0x7e, 0x81, 0x65, 0xaf, 0x90, ++ 0xfc, 0xd2, 0xb6, 0x72, 0xdb, 0xe9, 0x23, 0x78, 0x12, 0x04, 0xc0, 0x03, ++ 0x82, 0xa8, 0x7a, 0x0f, 0x48, 0x6f, 0x82, 0x7f, 0x81, 0xcd, 0xa7, 0x89, ++ 0xdd, 0x86, 0xea, 0x5e, 0xa1, 0x50, 0x14, 0x34, 0x17, 0x64, 0x82, 0x0f, ++ 0xc4, 0x40, 0x20, 0x1d, 0x8f, 0xfe, 0xfa, 0x99, 0xaf, 0x5b, 0xc1, 0x5d, ++ 0xc8, 0x47, 0x07, 0x54, 0x4a, 0x22, 0x56, 0x57, 0xf1, 0x2c, 0x3b, 0x62, ++ 0x7f, 0x12, 0x62, 0xaf, 0xfd, 0xf8, 0x04, 0x11, 0xa8, 0x51, 0xf0, 0x46, ++ 0x5d, 0x79, 0x66, 0xff, 0x8a, 0x06, 0xef, 0x54, 0x64, 0x1b, 0x84, 0x3e, ++ 0x41, 0xf3, 0xfe, 0x19, 0x51, 0xf7, 0x44, 0x9c, 0x16, 0xd3, 0x7a, 0x09, ++ 0x59, 0xf5, 0x47, 0x45, 0xd0, 0x31, 0xef, 0x96, 0x2c, 0xc5, 0xc0, 0xd0, ++ 0x56, 0xef, 0x3f, 0x07, 0x2b, 0xb7, 0x28, 0x49, 0xf5, 0xb1, 0x42, 0x18, ++ 0xcf, 0x77, 0xd8, 0x2b, 0x71, 0x74, 0x80, 0xba, 0x34, 0x52, 0xce, 0x11, ++ 0xfe, 0xc4, 0xb9, 0xeb, 0xf9, 0xc4, 0x5e, 0x1f, 0xd3, 0xde, 0x4b, 0x14, ++ 0xe3, 0x6e, 0xe7, 0xd7, 0x83, 0x59, 0x98, 0xe8, 0x3d, 0x8e, 0xd6, 0x7d, ++ 0xc0, 0x9a, 0x79, 0xb9, 0x83, 0xf1, 0xc1, 0x00, 0x5d, 0x16, 0x1b, 0x44, ++ 0xe9, 0x02, 0xce, 0x99, 0x1e, 0x77, 0xef, 0xca, 0xbc, 0xf0, 0x6a, 0xb9, ++ 0x65, 0x3f, 0x3c, 0xd9, 0xe1, 0x63, 0x0b, 0xbf, 0xaa, 0xa7, 0xe6, 0x6d, ++ 0x6d, 0x3f, 0x44, 0x29, 0xa3, 0x8b, 0x6d, 0xc4, 0x81, 0xa9, 0xc3, 0x5a, ++ 0x90, 0x55, 0x72, 0x61, 0x17, 0x22, 0x7f, 0x3e, 0x5f, 0xfc, 0xba, 0xb3, ++ 0x7a, 0x99, 0x76, 0xe9, 0x20, 0xe5, 0xc5, 0xe8, 0x55, 0x56, 0x0f, 0x7a, ++ 0x48, 0xe7, 0xbc, 0xe1, 0x13, 0xf4, 0x90, 0xef, 0x97, 0x6c, 0x02, 0x89, ++ 0x4d, 0x22, 0x48, 0xda, 0xd3, 0x52, 0x45, 0x31, 0x26, 0xcc, 0xe8, 0x9e, ++ 0x5d, 0xdd, 0x75, 0xe4, 0x1d, 0xbc, 0xb1, 0x08, 0x55, 0xaf, 0x54, 0x70, ++ 0x0d, 0x0c, 0xf3, 0x50, 0xbc, 0x40, 0x83, 0xee, 0xdc, 0x6d, 0x8b, 0x40, ++ 0x79, 0x62, 0x18, 0x37, 0xc4, 0x78, 0x02, 0x58, 0x7c, 0x78, 0xd3, 0x54, ++ 0xed, 0x31, 0xbd, 0x7d, 0x48, 0xcf, 0xb6, 0x11, 0x27, 0x37, 0x9c, 0x86, ++ 0xf7, 0x2e, 0x00, 0x7a, 0x48, 0x1b, 0xa6, 0x72, 0x70, 0x7b, 0x44, 0x45, ++ 0xeb, 0x49, 0xbf, 0xbe, 0x09, 0x78, 0x66, 0x71, 0x12, 0x7f, 0x3d, 0x78, ++ 0x51, 0x24, 0x82, 0xa2, 0xf0, 0x1e, 0x83, 0x81, 0x81, 0x45, 0x53, 0xfd, ++ 0x5e, 0xf3, 0x03, 0x74, 0xbd, 0x23, 0x35, 0xf6, 0x10, 0xdd, 0x7c, 0x73, ++ 0x46, 0x32, 0x09, 0x54, 0x99, 0x95, 0x91, 0x25, 0xb8, 0x32, 0x09, 0xd8, ++ 0x2f, 0x97, 0x50, 0xa3, 0xf5, 0xd6, 0xb1, 0xed, 0x97, 0x51, 0x06, 0x42, ++ 0x12, 0x0c, 0x69, 0x38, 0x09, 0xa0, 0xd8, 0x19, 0x70, 0xf7, 0x8f, 0x61, ++ 0x0d, 0x56, 0x43, 0x66, 0x22, 0x8b, 0x0e, 0x0e, 0xf9, 0x81, 0x9f, 0xac, ++ 0x6f, 0xbf, 0x7d, 0x04, 0x13, 0xf2, 0xe4, 0xeb, 0xfd, 0xbe, 0x4e, 0x56, ++ 0xda, 0xe0, 0x22, 0x6d, 0x1b, 0x25, 0xc8, 0xa5, 0x9c, 0x05, 0x45, 0x52, ++ 0x3c, 0x3a, 0xde, 0x6b, 0xac, 0x9b, 0xf8, 0x81, 0x97, 0x21, 0x46, 0xac, ++ 0x7e, 0x89, 0xf8, 0x49, 0x58, 0xbb, 0x45, 0xac, 0xa2, 0xc4, 0x90, 0x1f, ++ 0xb2, 0xb4, 0xf8, 0xe0, 0xcd, 0xa1, 0x9d, 0x1c, 0xf2, 0xf1, 0xdf, 0xfb, ++ 0x88, 0x4e, 0xe5, 0x41, 0xd8, 0x6e, 0xac, 0x07, 0x87, 0x95, 0x35, 0xa6, ++ 0x12, 0x08, 0x5d, 0x57, 0x5e, 0xaf, 0x71, 0x0f, 0x07, 0x4e, 0x81, 0x77, ++ 0xf1, 0xef, 0xb5, 0x35, 0x5c, 0xfa, 0xf4, 0x4e, 0x42, 0xdc, 0x19, 0xfe, ++ 0xe4, 0xd2, 0xb4, 0x27, 0xfb, 0x34, 0x1f, 0xb2, 0x6f, 0xf2, 0x95, 0xcc, ++ 0xd4, 0x47, 0x63, 0xdc, 0x7e, 0x4f, 0x97, 0x2b, 0x7a, 0xe0, 0x80, 0x31, ++}; ++ ++static const uint8_t kSpakeMSmallPrecomp[15 * 2 * 32] = { ++ 0xe7, 0x45, 0x7e, 0x47, 0x49, 0x69, 0xbd, 0x1b, 0x35, 0x1c, 0x2c, 0x98, ++ 0x03, 0xf3, 0xb3, 0x37, 0xde, 0x39, 0xa5, 0xda, 0xc0, 0x2e, 0xa4, 0xac, ++ 0x7d, 0x08, 0x26, 0xfc, 0x80, 0xa7, 0x09, 0x12, 0xd0, 0x48, 0x03, 0x2c, ++ 0x6e, 0xa0, 0xb6, 0xd6, 0x97, 0xdd, 0xc2, 0xe8, 0x6b, 0xda, 0x85, 0xa3, ++ 0x3a, 0xda, 0xc9, 0x20, 0xf1, 0xbf, 0x18, 0xe1, 0xb0, 0xc6, 0xd1, 0x66, ++ 0xa5, 0xce, 0xcd, 0x2f, 0x80, 0xa8, 0x4e, 0xc3, 0x81, 0xae, 0x68, 0x3b, ++ 0x0d, 0xdb, 0x56, 0x32, 0x2f, 0xa8, 0x97, 0xa0, 0x5c, 0x15, 0xc1, 0xcb, ++ 0x6f, 0x7a, 0x5f, 0xc5, 0x32, 0xfb, 0x49, 0x17, 0x18, 0xfa, 0x85, 0x08, ++ 0x85, 0xf1, 0xe3, 0x11, 0x8e, 0x3d, 0x70, 0x20, 0x38, 0x4e, 0x0c, 0x17, ++ 0xa1, 0xa8, 0x20, 0xd2, 0xb1, 0x1d, 0x05, 0x8d, 0x0f, 0xc9, 0x96, 0x18, ++ 0x9d, 0x8c, 0x89, 0x8f, 0x46, 0x6a, 0x6c, 0x6e, 0x72, 0x03, 0xb2, 0x75, ++ 0x87, 0xd8, 0xa9, 0x60, 0x93, 0x2b, 0x8b, 0x66, 0xee, 0xaf, 0xce, 0x98, ++ 0xcd, 0x6b, 0x7c, 0x6a, 0xbe, 0x19, 0xda, 0x66, 0x7c, 0xda, 0x53, 0xa0, ++ 0xe3, 0x9a, 0x0e, 0x53, 0x3a, 0x7c, 0x73, 0x4a, 0x37, 0xa6, 0x53, 0x23, ++ 0x67, 0x31, 0xce, 0x8a, 0xab, 0xee, 0x72, 0x76, 0xc2, 0xb5, 0x54, 0x42, ++ 0xcf, 0x4b, 0xc7, 0x53, 0x24, 0x59, 0xaf, 0x76, 0x53, 0x10, 0x7e, 0x25, ++ 0x94, 0x5c, 0x23, 0xa6, 0x5e, 0x05, 0xea, 0x14, 0xad, 0x2b, 0xce, 0x50, ++ 0x77, 0xb3, 0x7a, 0x88, 0x4c, 0xf7, 0x74, 0x04, 0x35, 0xa4, 0x0c, 0x9e, ++ 0xee, 0x6a, 0x4c, 0x3c, 0xc1, 0x6a, 0x35, 0x4d, 0x6d, 0x8f, 0x94, 0x95, ++ 0xe4, 0x10, 0xca, 0x46, 0x4e, 0xfa, 0x38, 0x40, 0xeb, 0x1a, 0x1b, 0x5a, ++ 0xff, 0x73, 0x4d, 0xe9, 0xf2, 0xbe, 0x89, 0xf5, 0xd1, 0x72, 0xd0, 0x1a, ++ 0x7b, 0x82, 0x08, 0x19, 0xda, 0x54, 0x44, 0xa5, 0x3d, 0xd8, 0x10, 0x1c, ++ 0xcf, 0x3b, 0xc7, 0x54, 0xd5, 0x11, 0xd7, 0x2a, 0x69, 0x3f, 0xa6, 0x58, ++ 0x74, 0xfd, 0x90, 0xb2, 0xf4, 0xc2, 0x0e, 0xf3, 0x19, 0x8f, 0x51, 0x7c, ++ 0x31, 0x12, 0x79, 0x61, 0x16, 0xb4, 0x2f, 0x2f, 0xd0, 0x88, 0x97, 0xf2, ++ 0xc3, 0x8c, 0xa6, 0xa3, 0x29, 0xff, 0x7e, 0x12, 0x46, 0x2a, 0x9c, 0x09, ++ 0x7c, 0x5f, 0x87, 0x07, 0x6b, 0xa1, 0x9a, 0x57, 0x55, 0x8e, 0xb0, 0x56, ++ 0x5d, 0xc9, 0x4c, 0x5b, 0xae, 0xd3, 0xd0, 0x8e, 0xb8, 0xac, 0xba, 0xe8, ++ 0x54, 0x45, 0x30, 0x14, 0xf6, 0x59, 0x20, 0xc4, 0x03, 0xb7, 0x7a, 0x5d, ++ 0x6b, 0x5a, 0xcb, 0x28, 0x60, 0xf8, 0xef, 0x61, 0x60, 0x78, 0x6b, 0xf5, ++ 0x21, 0x4b, 0x75, 0xc2, 0x77, 0xba, 0x0e, 0x38, 0x98, 0xe0, 0xfb, 0xb7, ++ 0x5f, 0x75, 0x87, 0x04, 0x0c, 0xb4, 0x5c, 0x09, 0x04, 0x00, 0x38, 0x4e, ++ 0x4f, 0x7b, 0x73, 0xe5, 0xdb, 0xdb, 0xf1, 0xf4, 0x5c, 0x64, 0x68, 0xfd, ++ 0xb1, 0x86, 0xe8, 0x89, 0xbe, 0x9c, 0xd4, 0x96, 0x1d, 0xcb, 0xdc, 0x5c, ++ 0xef, 0xd4, 0x33, 0x28, 0xb9, 0xb6, 0xaf, 0x3b, 0xcf, 0x8d, 0x30, 0xba, ++ 0xe8, 0x08, 0xcf, 0x84, 0xba, 0x61, 0x10, 0x9b, 0x62, 0xf6, 0x18, 0x79, ++ 0x66, 0x87, 0x82, 0x7c, 0xaa, 0x71, 0xac, 0xd0, 0xd0, 0x32, 0xb0, 0x54, ++ 0x03, 0xa4, 0xad, 0x3f, 0x72, 0xca, 0x22, 0xff, 0x01, 0x87, 0x08, 0x36, ++ 0x61, 0x22, 0xaa, 0x18, 0xab, 0x3a, 0xbc, 0xf2, 0x78, 0x05, 0xe1, 0x99, ++ 0xa3, 0x59, 0x98, 0xcc, 0x21, 0xc6, 0x2b, 0x51, 0x6d, 0x43, 0x0a, 0x46, ++ 0x50, 0xae, 0x11, 0x7e, 0xd5, 0x23, 0x56, 0xef, 0x83, 0xc8, 0xbf, 0x42, ++ 0xf0, 0x45, 0x52, 0x1f, 0x34, 0xbc, 0x2f, 0xb0, 0xf0, 0xce, 0xf0, 0xec, ++ 0xd0, 0x99, 0x59, 0x2e, 0x1f, 0xab, 0xa8, 0x1e, 0x4b, 0xce, 0x1b, 0x9a, ++ 0x75, 0xc6, 0xc4, 0x71, 0x86, 0xf0, 0x8d, 0xec, 0xb0, 0x30, 0xb9, 0x62, ++ 0xb3, 0xb7, 0xdd, 0x96, 0x29, 0xc8, 0xbf, 0xe9, 0xb0, 0x74, 0x78, 0x7b, ++ 0xf7, 0xea, 0xa3, 0x14, 0x12, 0x56, 0xe0, 0xf3, 0x35, 0x7a, 0x26, 0x4a, ++ 0x4c, 0xe6, 0xdf, 0x13, 0xb5, 0x52, 0xb0, 0x2a, 0x5f, 0x2e, 0xac, 0x34, ++ 0xab, 0x5f, 0x1a, 0x01, 0xe4, 0x15, 0x1a, 0xd1, 0xbf, 0xc9, 0x95, 0x0a, ++ 0xac, 0x1d, 0xe7, 0x53, 0x59, 0x8d, 0xc3, 0x21, 0x78, 0x5e, 0x12, 0x97, ++ 0x8f, 0x4e, 0x1d, 0xf9, 0xe5, 0xe2, 0xc2, 0xc4, 0xba, 0xfb, 0x50, 0x96, ++ 0x5b, 0x43, 0xe8, 0xf7, 0x0d, 0x1b, 0x64, 0x58, 0xbe, 0xd3, 0x95, 0x7f, ++ 0x8e, 0xf1, 0x85, 0x35, 0xba, 0x25, 0x55, 0x2e, 0x02, 0x46, 0x5c, 0xad, ++ 0x1f, 0xc5, 0x03, 0xcc, 0xd0, 0x43, 0x4c, 0xf2, 0x5e, 0x64, 0x0a, 0x89, ++ 0xd9, 0xfd, 0x23, 0x7d, 0x4f, 0xbe, 0x2f, 0x0f, 0x1e, 0x12, 0x4a, 0xd9, ++ 0xf8, 0x82, 0xde, 0x8f, 0x4f, 0x98, 0xb9, 0x90, 0xf6, 0xfa, 0xd1, 0x11, ++ 0xa6, 0xdc, 0x7e, 0x32, 0x48, 0x6a, 0x8a, 0x14, 0x5e, 0x73, 0xb9, 0x6c, ++ 0x0e, 0xc2, 0xf9, 0xcc, 0xf0, 0x32, 0xc8, 0xb5, 0x56, 0xaa, 0x5d, 0xd2, ++ 0x07, 0xf1, 0x6f, 0x33, 0x6f, 0x05, 0x70, 0x49, 0x60, 0x49, 0x23, 0x23, ++ 0x14, 0x0e, 0x4c, 0x58, 0x92, 0xad, 0xa9, 0x50, 0xb1, 0x59, 0x43, 0x96, ++ 0x7b, 0xc1, 0x51, 0x45, 0xef, 0x0d, 0xef, 0xd1, 0xe4, 0xd0, 0xce, 0xdf, ++ 0x6a, 0xbc, 0x1b, 0xbf, 0x7a, 0x87, 0x4e, 0x47, 0x17, 0x9c, 0x34, 0x38, ++ 0xb0, 0x3c, 0xa1, 0x04, 0xfb, 0xe2, 0x66, 0xce, 0xb6, 0x82, 0xbb, 0xad, ++ 0xc3, 0x8e, 0x12, 0x35, 0xbc, 0x17, 0xce, 0x01, 0x2d, 0xa3, 0xa6, 0xb9, ++ 0xfa, 0x84, 0xc2, 0x2f, 0x5a, 0x4a, 0x8c, 0x4c, 0x11, 0x4e, 0xa8, 0x14, ++ 0xcb, 0xb8, 0x99, 0xaa, 0x2e, 0x8c, 0xa0, 0xc9, 0x5f, 0x62, 0x2a, 0x84, ++ 0x66, 0x60, 0x0a, 0x7e, 0xdc, 0x93, 0x17, 0x45, 0x19, 0xb3, 0x93, 0x4c, ++ 0xdc, 0xd0, 0xd5, 0x5c, 0x25, 0xd2, 0xcd, 0x4e, 0x84, 0x4c, 0x73, 0xb3, ++ 0x90, 0xa4, 0x22, 0x05, 0x2c, 0x7c, 0x39, 0x2b, 0x70, 0xd9, 0x61, 0x76, ++ 0xb2, 0x03, 0x71, 0xe9, 0x0e, 0xf8, 0x57, 0x85, 0xad, 0xb1, 0x2f, 0x34, ++ 0xa5, 0x66, 0xb0, 0x0f, 0x75, 0x94, 0x6e, 0x26, 0x79, 0x99, 0xb4, 0xe2, ++ 0xe2, 0xa3, 0x58, 0xdd, 0xb4, 0xfb, 0x74, 0xf4, 0xa1, 0xca, 0xc3, 0x30, ++ 0xe7, 0x86, 0xb2, 0xa2, 0x2c, 0x11, 0xc9, 0x58, 0xe3, 0xc1, 0xa6, 0x5f, ++ 0x86, 0x6a, 0xe7, 0x75, 0xd5, 0xd8, 0x63, 0x95, 0x64, 0x59, 0xbc, 0xb8, ++ 0xb7, 0xf5, 0x12, 0xe3, 0x03, 0xc6, 0x17, 0xea, 0x4e, 0xcb, 0xee, 0x4c, ++ 0xae, 0x03, 0xd1, 0x33, 0xd0, 0x39, 0x36, 0x00, 0x0f, 0xf4, 0x9c, 0xbd, ++ 0x35, 0x96, 0xfd, 0x0d, 0x26, 0xb7, 0x9e, 0xf4, 0x4b, 0x6f, 0x4b, 0xf1, ++ 0xec, 0x11, 0x00, 0x16, 0x21, 0x1e, 0xd4, 0x43, 0x23, 0x8c, 0x4a, 0xfa, ++ 0x9e, 0xd4, 0x2b, 0x36, 0x9a, 0x43, 0x1e, 0x58, 0x31, 0xe8, 0x1f, 0x83, ++ 0x15, 0x20, 0x31, 0x68, 0xfe, 0x27, 0xd3, 0xd8, 0x9b, 0x43, 0x81, 0x8f, ++ 0x57, 0x32, 0x14, 0xe6, 0x9e, 0xbf, 0xd1, 0xfb, 0xdf, 0xad, 0x7a, 0x52, ++}; ++ ++/* left_shift_3 sets |n| to |n|*8, where |n| is represented in little-endian ++ * order. */ ++static void left_shift_3(uint8_t n[32]) { ++ uint8_t carry = 0; ++ unsigned i; ++ ++ for (i = 0; i < 32; i++) { ++ const uint8_t next_carry = n[i] >> 5; ++ n[i] = (n[i] << 3) | carry; ++ carry = next_carry; ++ } ++} ++ ++static krb5_error_code ++builtin_edwards25519_keygen(krb5_context context, groupdata *gdata, ++ const uint8_t *wbytes, krb5_boolean use_m, ++ uint8_t *priv_out, uint8_t *pub_out) ++{ ++ uint8_t private[64]; ++ krb5_data data = make_data(private, 32); ++ krb5_error_code ret; ++ ++ /* Pick x or y uniformly from [0, p*h) divisible by h. */ ++ ret = krb5_c_random_make_octets(context, &data); ++ if (ret) ++ return ret; ++ memset(private + 32, 0, 32); ++ x25519_sc_reduce(private); ++ left_shift_3(private); ++ ++ /* Compute X=x*G or Y=y*G. */ ++ ge_p3 P; ++ x25519_ge_scalarmult_base(&P, private); ++ ++ /* Compute w mod p. */ ++ uint8_t wreduced[64]; ++ memcpy(wreduced, wbytes, 32); ++ memset(wreduced + 32, 0, 32); ++ x25519_sc_reduce(wreduced); ++ ++ /* Compute the mask, w*M or w*N. */ ++ ge_p3 mask; ++ x25519_ge_scalarmult_small_precomp(&mask, wreduced, ++ use_m ? kSpakeMSmallPrecomp : ++ kSpakeNSmallPrecomp); ++ ++ /* Compute the masked point T=w*M+X or S=w*N+Y. */ ++ ge_cached mask_cached; ++ x25519_ge_p3_to_cached(&mask_cached, &mask); ++ ge_p1p1 Pmasked; ++ x25519_ge_add(&Pmasked, &P, &mask_cached); ++ ++ /* Encode T or S into pub_out. */ ++ ge_p2 Pmasked_proj; ++ x25519_ge_p1p1_to_p2(&Pmasked_proj, &Pmasked); ++ x25519_ge_tobytes(pub_out, &Pmasked_proj); ++ ++ /* Remember the private key in priv_out. */ ++ memcpy(priv_out, private, 32); ++ return 0; ++} ++ ++static krb5_error_code ++builtin_edwards25519_result(krb5_context context, groupdata *gdata, ++ const uint8_t *wbytes, const uint8_t *ourpriv, ++ const uint8_t *theirpub, krb5_boolean use_m, ++ uint8_t *elem_out) ++{ ++ /* ++ * Check if the point received from peer is on the curve. This does not ++ * verify that it is in the generator subgroup, but since our private key is ++ * a multiple of the cofactor, the shared point will be in the generator ++ * subgroup even if a rogue peer sends a point which is not. ++ */ ++ ge_p3 Qmasked; ++ if (x25519_ge_frombytes_vartime(&Qmasked, theirpub) != 0) ++ return EINVAL; ++ ++ /* Compute w mod p. */ ++ uint8_t wreduced[64]; ++ memcpy(wreduced, wbytes, 32); ++ memset(wreduced + 32, 0, 32); ++ x25519_sc_reduce(wreduced); ++ ++ /* Compute the peer's mask, w*M or w*N. */ ++ ge_p3 peers_mask; ++ x25519_ge_scalarmult_small_precomp(&peers_mask, wreduced, ++ use_m ? kSpakeMSmallPrecomp : ++ kSpakeNSmallPrecomp); ++ ++ ge_cached peers_mask_cached; ++ x25519_ge_p3_to_cached(&peers_mask_cached, &peers_mask); ++ ++ /* Compute the peer's unmasked point, T-w*M or S-w*N. */ ++ ge_p1p1 Qcompl; ++ ge_p3 Qunmasked; ++ x25519_ge_sub(&Qcompl, &Qmasked, &peers_mask_cached); ++ x25519_ge_p1p1_to_p3(&Qunmasked, &Qcompl); ++ ++ /* Multiply by our private value to compute K=x*(S-w*N) or K=y*(T-w*M). */ ++ ge_p2 K; ++ x25519_ge_scalarmult(&K, ourpriv, &Qunmasked); ++ ++ /* Encode K into elem_out. */ ++ x25519_ge_tobytes(elem_out, &K); ++ return 0; ++} ++ ++static krb5_error_code ++builtin_sha256(krb5_context context, groupdata *gdata, const krb5_data *dlist, ++ size_t ndata, uint8_t *result_out) ++{ ++ return k5_sha256(dlist, ndata, result_out); ++} ++ ++groupdef builtin_edwards25519 = { ++ .reg = &spake_iana_edwards25519, ++ .keygen = builtin_edwards25519_keygen, ++ .result = builtin_edwards25519_result, ++ .hash = builtin_sha256 ++}; +diff --git a/src/plugins/preauth/spake/edwards25519_tables.h b/src/plugins/preauth/spake/edwards25519_tables.h +new file mode 100644 +index 000000000..c6c501373 +--- /dev/null ++++ b/src/plugins/preauth/spake/edwards25519_tables.h +@@ -0,0 +1,7881 @@ ++/* -*- mode: c; c-basic-offset: 2; indent-tabs-mode: nil -*- */ ++/* ++ * The MIT License (MIT) ++ * ++ * Copyright (c) 2015-2016 the fiat-crypto authors (see the AUTHORS file). ++ * ++ * Permission is hereby granted, free of charge, to any person obtaining a copy ++ * of this software and associated documentation files (the "Software"), to deal ++ * in the Software without restriction, including without limitation the rights ++ * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell ++ * copies of the Software, and to permit persons to whom the Software is ++ * furnished to do so, subject to the following conditions: ++ * ++ * The above copyright notice and this permission notice shall be included in ++ * all copies or substantial portions of the Software. ++ * ++ * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR ++ * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, ++ * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE ++ * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER ++ * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, ++ * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE ++ * SOFTWARE. ++ */ ++ ++/* From BoringSSL third-party/fiat/curve25519_tables.h */ ++ ++static const fe d = {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 929955233495203, 466365720129213, 1662059464998953, 2033849074728123, ++ 1442794654840575 ++#else ++ 56195235, 13857412, 51736253, 6949390, 114729, 24766616, 60832955, 30306712, ++ 48412415, 21499315 ++#endif ++}}; ++ ++static const fe sqrtm1 = {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1718705420411056, 234908883556509, 2233514472574048, 2117202627021982, ++ 765476049583133 ++#else ++ 34513072, 25610706, 9377949, 3500415, 12389472, 33281959, 41962654, ++ 31548777, 326685, 11406482 ++#endif ++}}; ++ ++static const fe d2 = {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1859910466990425, 932731440258426, 1072319116312658, 1815898335770999, ++ 633789495995903 ++#else ++ 45281625, 27714825, 36363642, 13898781, 229458, 15978800, 54557047, ++ 27058993, 29715967, 9444199 ++#endif ++}}; ++ ++#if defined(CONFIG_SMALL) ++ ++// This block of code replaces the standard base-point table with a much smaller ++// one. The standard table is 30,720 bytes while this one is just 960. ++// ++// This table contains 15 pairs of group elements, (x, y), where each field ++// element is serialised with |fe_tobytes|. If |i| is the index of the group ++// element then consider i+1 as a four-bit number: (i₀, i₁, i₂, i₃) (where i₀ ++// is the most significant bit). The value of the group element is then: ++// (i₀×2^192 + i₁×2^128 + i₂×2^64 + i₃)G, where G is the generator. ++static const uint8_t k25519SmallPrecomp[15 * 2 * 32] = { ++ 0x1a, 0xd5, 0x25, 0x8f, 0x60, 0x2d, 0x56, 0xc9, 0xb2, 0xa7, 0x25, 0x95, ++ 0x60, 0xc7, 0x2c, 0x69, 0x5c, 0xdc, 0xd6, 0xfd, 0x31, 0xe2, 0xa4, 0xc0, ++ 0xfe, 0x53, 0x6e, 0xcd, 0xd3, 0x36, 0x69, 0x21, 0x58, 0x66, 0x66, 0x66, ++ 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, ++ 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, ++ 0x66, 0x66, 0x66, 0x66, 0x02, 0xa2, 0xed, 0xf4, 0x8f, 0x6b, 0x0b, 0x3e, ++ 0xeb, 0x35, 0x1a, 0xd5, 0x7e, 0xdb, 0x78, 0x00, 0x96, 0x8a, 0xa0, 0xb4, ++ 0xcf, 0x60, 0x4b, 0xd4, 0xd5, 0xf9, 0x2d, 0xbf, 0x88, 0xbd, 0x22, 0x62, ++ 0x13, 0x53, 0xe4, 0x82, 0x57, 0xfa, 0x1e, 0x8f, 0x06, 0x2b, 0x90, 0xba, ++ 0x08, 0xb6, 0x10, 0x54, 0x4f, 0x7c, 0x1b, 0x26, 0xed, 0xda, 0x6b, 0xdd, ++ 0x25, 0xd0, 0x4e, 0xea, 0x42, 0xbb, 0x25, 0x03, 0xa2, 0xfb, 0xcc, 0x61, ++ 0x67, 0x06, 0x70, 0x1a, 0xc4, 0x78, 0x3a, 0xff, 0x32, 0x62, 0xdd, 0x2c, ++ 0xab, 0x50, 0x19, 0x3b, 0xf2, 0x9b, 0x7d, 0xb8, 0xfd, 0x4f, 0x29, 0x9c, ++ 0xa7, 0x91, 0xba, 0x0e, 0x46, 0x5e, 0x51, 0xfe, 0x1d, 0xbf, 0xe5, 0xe5, ++ 0x9b, 0x95, 0x0d, 0x67, 0xf8, 0xd1, 0xb5, 0x5a, 0xa1, 0x93, 0x2c, 0xc3, ++ 0xde, 0x0e, 0x97, 0x85, 0x2d, 0x7f, 0xea, 0xab, 0x3e, 0x47, 0x30, 0x18, ++ 0x24, 0xe8, 0xb7, 0x60, 0xae, 0x47, 0x80, 0xfc, 0xe5, 0x23, 0xe7, 0xc2, ++ 0xc9, 0x85, 0xe6, 0x98, 0xa0, 0x29, 0x4e, 0xe1, 0x84, 0x39, 0x2d, 0x95, ++ 0x2c, 0xf3, 0x45, 0x3c, 0xff, 0xaf, 0x27, 0x4c, 0x6b, 0xa6, 0xf5, 0x4b, ++ 0x11, 0xbd, 0xba, 0x5b, 0x9e, 0xc4, 0xa4, 0x51, 0x1e, 0xbe, 0xd0, 0x90, ++ 0x3a, 0x9c, 0xc2, 0x26, 0xb6, 0x1e, 0xf1, 0x95, 0x7d, 0xc8, 0x6d, 0x52, ++ 0xe6, 0x99, 0x2c, 0x5f, 0x9a, 0x96, 0x0c, 0x68, 0x29, 0xfd, 0xe2, 0xfb, ++ 0xe6, 0xbc, 0xec, 0x31, 0x08, 0xec, 0xe6, 0xb0, 0x53, 0x60, 0xc3, 0x8c, ++ 0xbe, 0xc1, 0xb3, 0x8a, 0x8f, 0xe4, 0x88, 0x2b, 0x55, 0xe5, 0x64, 0x6e, ++ 0x9b, 0xd0, 0xaf, 0x7b, 0x64, 0x2a, 0x35, 0x25, 0x10, 0x52, 0xc5, 0x9e, ++ 0x58, 0x11, 0x39, 0x36, 0x45, 0x51, 0xb8, 0x39, 0x93, 0xfc, 0x9d, 0x6a, ++ 0xbe, 0x58, 0xcb, 0xa4, 0x0f, 0x51, 0x3c, 0x38, 0x05, 0xca, 0xab, 0x43, ++ 0x63, 0x0e, 0xf3, 0x8b, 0x41, 0xa6, 0xf8, 0x9b, 0x53, 0x70, 0x80, 0x53, ++ 0x86, 0x5e, 0x8f, 0xe3, 0xc3, 0x0d, 0x18, 0xc8, 0x4b, 0x34, 0x1f, 0xd8, ++ 0x1d, 0xbc, 0xf2, 0x6d, 0x34, 0x3a, 0xbe, 0xdf, 0xd9, 0xf6, 0xf3, 0x89, ++ 0xa1, 0xe1, 0x94, 0x9f, 0x5d, 0x4c, 0x5d, 0xe9, 0xa1, 0x49, 0x92, 0xef, ++ 0x0e, 0x53, 0x81, 0x89, 0x58, 0x87, 0xa6, 0x37, 0xf1, 0xdd, 0x62, 0x60, ++ 0x63, 0x5a, 0x9d, 0x1b, 0x8c, 0xc6, 0x7d, 0x52, 0xea, 0x70, 0x09, 0x6a, ++ 0xe1, 0x32, 0xf3, 0x73, 0x21, 0x1f, 0x07, 0x7b, 0x7c, 0x9b, 0x49, 0xd8, ++ 0xc0, 0xf3, 0x25, 0x72, 0x6f, 0x9d, 0xed, 0x31, 0x67, 0x36, 0x36, 0x54, ++ 0x40, 0x92, 0x71, 0xe6, 0x11, 0x28, 0x11, 0xad, 0x93, 0x32, 0x85, 0x7b, ++ 0x3e, 0xb7, 0x3b, 0x49, 0x13, 0x1c, 0x07, 0xb0, 0x2e, 0x93, 0xaa, 0xfd, ++ 0xfd, 0x28, 0x47, 0x3d, 0x8d, 0xd2, 0xda, 0xc7, 0x44, 0xd6, 0x7a, 0xdb, ++ 0x26, 0x7d, 0x1d, 0xb8, 0xe1, 0xde, 0x9d, 0x7a, 0x7d, 0x17, 0x7e, 0x1c, ++ 0x37, 0x04, 0x8d, 0x2d, 0x7c, 0x5e, 0x18, 0x38, 0x1e, 0xaf, 0xc7, 0x1b, ++ 0x33, 0x48, 0x31, 0x00, 0x59, 0xf6, 0xf2, 0xca, 0x0f, 0x27, 0x1b, 0x63, ++ 0x12, 0x7e, 0x02, 0x1d, 0x49, 0xc0, 0x5d, 0x79, 0x87, 0xef, 0x5e, 0x7a, ++ 0x2f, 0x1f, 0x66, 0x55, 0xd8, 0x09, 0xd9, 0x61, 0x38, 0x68, 0xb0, 0x07, ++ 0xa3, 0xfc, 0xcc, 0x85, 0x10, 0x7f, 0x4c, 0x65, 0x65, 0xb3, 0xfa, 0xfa, ++ 0xa5, 0x53, 0x6f, 0xdb, 0x74, 0x4c, 0x56, 0x46, 0x03, 0xe2, 0xd5, 0x7a, ++ 0x29, 0x1c, 0xc6, 0x02, 0xbc, 0x59, 0xf2, 0x04, 0x75, 0x63, 0xc0, 0x84, ++ 0x2f, 0x60, 0x1c, 0x67, 0x76, 0xfd, 0x63, 0x86, 0xf3, 0xfa, 0xbf, 0xdc, ++ 0xd2, 0x2d, 0x90, 0x91, 0xbd, 0x33, 0xa9, 0xe5, 0x66, 0x0c, 0xda, 0x42, ++ 0x27, 0xca, 0xf4, 0x66, 0xc2, 0xec, 0x92, 0x14, 0x57, 0x06, 0x63, 0xd0, ++ 0x4d, 0x15, 0x06, 0xeb, 0x69, 0x58, 0x4f, 0x77, 0xc5, 0x8b, 0xc7, 0xf0, ++ 0x8e, 0xed, 0x64, 0xa0, 0xb3, 0x3c, 0x66, 0x71, 0xc6, 0x2d, 0xda, 0x0a, ++ 0x0d, 0xfe, 0x70, 0x27, 0x64, 0xf8, 0x27, 0xfa, 0xf6, 0x5f, 0x30, 0xa5, ++ 0x0d, 0x6c, 0xda, 0xf2, 0x62, 0x5e, 0x78, 0x47, 0xd3, 0x66, 0x00, 0x1c, ++ 0xfd, 0x56, 0x1f, 0x5d, 0x3f, 0x6f, 0xf4, 0x4c, 0xd8, 0xfd, 0x0e, 0x27, ++ 0xc9, 0x5c, 0x2b, 0xbc, 0xc0, 0xa4, 0xe7, 0x23, 0x29, 0x02, 0x9f, 0x31, ++ 0xd6, 0xe9, 0xd7, 0x96, 0xf4, 0xe0, 0x5e, 0x0b, 0x0e, 0x13, 0xee, 0x3c, ++ 0x09, 0xed, 0xf2, 0x3d, 0x76, 0x91, 0xc3, 0xa4, 0x97, 0xae, 0xd4, 0x87, ++ 0xd0, 0x5d, 0xf6, 0x18, 0x47, 0x1f, 0x1d, 0x67, 0xf2, 0xcf, 0x63, 0xa0, ++ 0x91, 0x27, 0xf8, 0x93, 0x45, 0x75, 0x23, 0x3f, 0xd1, 0xf1, 0xad, 0x23, ++ 0xdd, 0x64, 0x93, 0x96, 0x41, 0x70, 0x7f, 0xf7, 0xf5, 0xa9, 0x89, 0xa2, ++ 0x34, 0xb0, 0x8d, 0x1b, 0xae, 0x19, 0x15, 0x49, 0x58, 0x23, 0x6d, 0x87, ++ 0x15, 0x4f, 0x81, 0x76, 0xfb, 0x23, 0xb5, 0xea, 0xcf, 0xac, 0x54, 0x8d, ++ 0x4e, 0x42, 0x2f, 0xeb, 0x0f, 0x63, 0xdb, 0x68, 0x37, 0xa8, 0xcf, 0x8b, ++ 0xab, 0xf5, 0xa4, 0x6e, 0x96, 0x2a, 0xb2, 0xd6, 0xbe, 0x9e, 0xbd, 0x0d, ++ 0xb4, 0x42, 0xa9, 0xcf, 0x01, 0x83, 0x8a, 0x17, 0x47, 0x76, 0xc4, 0xc6, ++ 0x83, 0x04, 0x95, 0x0b, 0xfc, 0x11, 0xc9, 0x62, 0xb8, 0x0c, 0x76, 0x84, ++ 0xd9, 0xb9, 0x37, 0xfa, 0xfc, 0x7c, 0xc2, 0x6d, 0x58, 0x3e, 0xb3, 0x04, ++ 0xbb, 0x8c, 0x8f, 0x48, 0xbc, 0x91, 0x27, 0xcc, 0xf9, 0xb7, 0x22, 0x19, ++ 0x83, 0x2e, 0x09, 0xb5, 0x72, 0xd9, 0x54, 0x1c, 0x4d, 0xa1, 0xea, 0x0b, ++ 0xf1, 0xc6, 0x08, 0x72, 0x46, 0x87, 0x7a, 0x6e, 0x80, 0x56, 0x0a, 0x8a, ++ 0xc0, 0xdd, 0x11, 0x6b, 0xd6, 0xdd, 0x47, 0xdf, 0x10, 0xd9, 0xd8, 0xea, ++ 0x7c, 0xb0, 0x8f, 0x03, 0x00, 0x2e, 0xc1, 0x8f, 0x44, 0xa8, 0xd3, 0x30, ++ 0x06, 0x89, 0xa2, 0xf9, 0x34, 0xad, 0xdc, 0x03, 0x85, 0xed, 0x51, 0xa7, ++ 0x82, 0x9c, 0xe7, 0x5d, 0x52, 0x93, 0x0c, 0x32, 0x9a, 0x5b, 0xe1, 0xaa, ++ 0xca, 0xb8, 0x02, 0x6d, 0x3a, 0xd4, 0xb1, 0x3a, 0xf0, 0x5f, 0xbe, 0xb5, ++ 0x0d, 0x10, 0x6b, 0x38, 0x32, 0xac, 0x76, 0x80, 0xbd, 0xca, 0x94, 0x71, ++ 0x7a, 0xf2, 0xc9, 0x35, 0x2a, 0xde, 0x9f, 0x42, 0x49, 0x18, 0x01, 0xab, ++ 0xbc, 0xef, 0x7c, 0x64, 0x3f, 0x58, 0x3d, 0x92, 0x59, 0xdb, 0x13, 0xdb, ++ 0x58, 0x6e, 0x0a, 0xe0, 0xb7, 0x91, 0x4a, 0x08, 0x20, 0xd6, 0x2e, 0x3c, ++ 0x45, 0xc9, 0x8b, 0x17, 0x79, 0xe7, 0xc7, 0x90, 0x99, 0x3a, 0x18, 0x25, ++}; ++ ++#else ++ ++// k25519Precomp[i][j] = (j+1)*256^i*B ++static const ge_precomp k25519Precomp[32][8] = { ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1288382639258501, 245678601348599, 269427782077623, ++ 1462984067271730, 137412439391563 ++#else ++ 25967493, 19198397, 29566455, 3660896, 54414519, 4014786, ++ 27544626, 21800161, 61029707, 2047604 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 62697248952638, 204681361388450, 631292143396476, ++ 338455783676468, 1213667448819585 ++#else ++ 54563134, 934261, 64385954, 3049989, 66381436, 9406985, ++ 12720692, 5043384, 19500929, 18085054 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 301289933810280, 1259582250014073, 1422107436869536, ++ 796239922652654, 1953934009299142 ++#else ++ 58370664, 4489569, 9688441, 18769238, 10184608, 21191052, ++ 29287918, 11864899, 42594502, 29115885 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1380971894829527, 790832306631236, 2067202295274102, ++ 1995808275510000, 1566530869037010 ++#else ++ 54292951, 20578084, 45527620, 11784319, 41753206, 30803714, ++ 55390960, 29739860, 66750418, 23343128 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 463307831301544, 432984605774163, 1610641361907204, ++ 750899048855000, 1894842303421586 ++#else ++ 45405608, 6903824, 27185491, 6451973, 37531140, 24000426, ++ 51492312, 11189267, 40279186, 28235350 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 748439484463711, 1033211726465151, 1396005112841647, ++ 1611506220286469, 1972177495910992 ++#else ++ 26966623, 11152617, 32442495, 15396054, 14353839, 20802097, ++ 63980037, 24013313, 51636816, 29387734 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1601611775252272, 1720807796594148, 1132070835939856, ++ 1260455018889551, 2147779492816911 ++#else ++ 15636272, 23865875, 24204772, 25642034, 616976, 16869170, ++ 27787599, 18782243, 28944399, 32004408 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 316559037616741, 2177824224946892, 1459442586438991, ++ 1461528397712656, 751590696113597 ++#else ++ 16568933, 4717097, 55552716, 32452109, 15682895, 21747389, ++ 16354576, 21778470, 7689661, 11199574 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1850748884277385, 1200145853858453, 1068094770532492, ++ 672251375690438, 1586055907191707 ++#else ++ 30464137, 27578307, 55329429, 17883566, 23220364, 15915852, ++ 7512774, 10017326, 49359771, 23634074 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 934282339813791, 1846903124198670, 1172395437954843, ++ 1007037127761661, 1830588347719256 ++#else ++ 50071967, 13921891, 10945806, 27521001, 27105051, 17470053, ++ 38182653, 15006022, 3284568, 27277892 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1694390458783935, 1735906047636159, 705069562067493, ++ 648033061693059, 696214010414170 ++#else ++ 23599295, 25248385, 55915199, 25867015, 13236773, 10506355, ++ 7464579, 9656445, 13059162, 10374397 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1121406372216585, 192876649532226, 190294192191717, ++ 1994165897297032, 2245000007398739 ++#else ++ 7798537, 16710257, 3033922, 2874086, 28997861, 2835604, ++ 32406664, 29715387, 66467155, 33453106 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 769950342298419, 132954430919746, 844085933195555, ++ 974092374476333, 726076285546016 ++#else ++ 10861363, 11473154, 27284546, 1981175, 37044515, 12577860, ++ 32867885, 14515107, 51670560, 10819379 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 425251763115706, 608463272472562, 442562545713235, ++ 837766094556764, 374555092627893 ++#else ++ 4708026, 6336745, 20377586, 9066809, 55836755, 6594695, ++ 41455196, 12483687, 54440373, 5581305 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1086255230780037, 274979815921559, 1960002765731872, ++ 929474102396301, 1190409889297339 ++#else ++ 19563141, 16186464, 37722007, 4097518, 10237984, 29206317, ++ 28542349, 13850243, 43430843, 17738489 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1388594989461809, 316767091099457, 394298842192982, ++ 1230079486801005, 1440737038838979 ++#else ++ 51736881, 20691677, 32573249, 4720197, 40672342, 5875510, ++ 47920237, 18329612, 57289923, 21468654 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 7380825640100, 146210432690483, 304903576448906, ++ 1198869323871120, 997689833219095 ++#else ++ 58559652, 109982, 15149363, 2178705, 22900618, 4543417, 3044240, ++ 17864545, 1762327, 14866737 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1181317918772081, 114573476638901, 262805072233344, ++ 265712217171332, 294181933805782 ++#else ++ 48909169, 17603008, 56635573, 1707277, 49922944, 3916100, ++ 38872452, 3959420, 27914454, 4383652 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 665000864555967, 2065379846933859, 370231110385876, ++ 350988370788628, 1233371373142985 ++#else ++ 5153727, 9909285, 1723747, 30776558, 30523604, 5516873, ++ 19480852, 5230134, 43156425, 18378665 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2019367628972465, 676711900706637, 110710997811333, ++ 1108646842542025, 517791959672113 ++#else ++ 36839857, 30090922, 7665485, 10083793, 28475525, 1649722, ++ 20654025, 16520125, 30598449, 7715701 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 965130719900578, 247011430587952, 526356006571389, ++ 91986625355052, 2157223321444601 ++#else ++ 28881826, 14381568, 9657904, 3680757, 46927229, 7843315, ++ 35708204, 1370707, 29794553, 32145132 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2068619540119183, 1966274918058806, 957728544705549, ++ 729906502578991, 159834893065166 ++#else ++ 14499471, 30824833, 33917750, 29299779, 28494861, 14271267, ++ 30290735, 10876454, 33954766, 2381725 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2073601412052185, 31021124762708, 264500969797082, ++ 248034690651703, 1030252227928288 ++#else ++ 59913433, 30899068, 52378708, 462250, 39384538, 3941371, ++ 60872247, 3696004, 34808032, 15351954 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 551790716293402, 1989538725166328, 801169423371717, ++ 2052451893578887, 678432056995012 ++#else ++ 27431194, 8222322, 16448760, 29646437, 48401861, 11938354, ++ 34147463, 30583916, 29551812, 10109425 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1368953770187805, 790347636712921, 437508475667162, ++ 2142576377050580, 1932081720066286 ++#else ++ 53451805, 20399000, 35825113, 11777097, 21447386, 6519384, ++ 64730580, 31926875, 10092782, 28790261 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 953638594433374, 1092333936795051, 1419774766716690, ++ 805677984380077, 859228993502513 ++#else ++ 27939166, 14210322, 4677035, 16277044, 44144402, 21156292, ++ 34600109, 12005537, 49298737, 12803509 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1200766035879111, 20142053207432, 1465634435977050, ++ 1645256912097844, 295121984874596 ++#else ++ 17228999, 17892808, 65875336, 300139, 65883994, 21839654, ++ 30364212, 24516238, 18016356, 4397660 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1735718747031557, 1248237894295956, 1204753118328107, ++ 976066523550493, 65943769534592 ++#else ++ 56150021, 25864224, 4776340, 18600194, 27850027, 17952220, ++ 40489757, 14544524, 49631360, 982638 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1060098822528990, 1586825862073490, 212301317240126, ++ 1975302711403555, 666724059764335 ++#else ++ 29253598, 15796703, 64244882, 23645547, 10057022, 3163536, ++ 7332899, 29434304, 46061167, 9934962 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1091990273418756, 1572899409348578, 80968014455247, ++ 306009358661350, 1520450739132526 ++#else ++ 5793284, 16271923, 42977250, 23438027, 29188559, 1206517, ++ 52360934, 4559894, 36984942, 22656481 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1480517209436112, 1511153322193952, 1244343858991172, ++ 304788150493241, 369136856496443 ++#else ++ 39464912, 22061425, 16282656, 22517939, 28414020, 18542168, ++ 24191033, 4541697, 53770555, 5500567 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2151330273626164, 762045184746182, 1688074332551515, ++ 823046109005759, 907602769079491 ++#else ++ 12650548, 32057319, 9052870, 11355358, 49428827, 25154267, ++ 49678271, 12264342, 10874051, 13524335 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2047386910586836, 168470092900250, 1552838872594810, ++ 340951180073789, 360819374702533 ++#else ++ 25556948, 30508442, 714650, 2510400, 23394682, 23139102, ++ 33119037, 5080568, 44580805, 5376627 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1982622644432056, 2014393600336956, 128909208804214, ++ 1617792623929191, 105294281913815 ++#else ++ 41020600, 29543379, 50095164, 30016803, 60382070, 1920896, ++ 44787559, 24106988, 4535767, 1569007 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 980234343912898, 1712256739246056, 588935272190264, ++ 204298813091998, 841798321043288 ++#else ++ 64853442, 14606629, 45416424, 25514613, 28430648, 8775819, ++ 36614302, 3044289, 31848280, 12543772 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 197561292938973, 454817274782871, 1963754960082318, ++ 2113372252160468, 971377527342673 ++#else ++ 45080285, 2943892, 35251351, 6777305, 13784462, 29262229, ++ 39731668, 31491700, 7718481, 14474653 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 164699448829328, 3127451757672, 1199504971548753, ++ 1766155447043652, 1899238924683527 ++#else ++ 2385296, 2454213, 44477544, 46602, 62670929, 17874016, 656964, ++ 26317767, 24316167, 28300865 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 732262946680281, 1674412764227063, 2182456405662809, ++ 1350894754474250, 558458873295247 ++#else ++ 13741529, 10911568, 33875447, 24950694, 46931033, 32521134, ++ 33040650, 20129900, 46379407, 8321685 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2103305098582922, 1960809151316468, 715134605001343, ++ 1454892949167181, 40827143824949 ++#else ++ 21060490, 31341688, 15712756, 29218333, 1639039, 10656336, ++ 23845965, 21679594, 57124405, 608371 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1239289043050212, 1744654158124578, 758702410031698, ++ 1796762995074688, 1603056663766 ++#else ++ 53436132, 18466845, 56219170, 25997372, 61071954, 11305546, ++ 1123968, 26773855, 27229398, 23887 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2232056027107988, 987343914584615, 2115594492994461, ++ 1819598072792159, 1119305654014850 ++#else ++ 43864724, 33260226, 55364135, 14712570, 37643165, 31524814, ++ 12797023, 27114124, 65475458, 16678953 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 320153677847348, 939613871605645, 641883205761567, ++ 1930009789398224, 329165806634126 ++#else ++ 37608244, 4770661, 51054477, 14001337, 7830047, 9564805, ++ 65600720, 28759386, 49939598, 4904952 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 980930490474130, 1242488692177893, 1251446316964684, ++ 1086618677993530, 1961430968465772 ++#else ++ 24059538, 14617003, 19037157, 18514524, 19766092, 18648003, ++ 5169210, 16191880, 2128236, 29227599 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 276821765317453, 1536835591188030, 1305212741412361, ++ 61473904210175, 2051377036983058 ++#else ++ 50127693, 4124965, 58568254, 22900634, 30336521, 19449185, ++ 37302527, 916032, 60226322, 30567899 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 833449923882501, 1750270368490475, 1123347002068295, ++ 185477424765687, 278090826653186 ++#else ++ 44477957, 12419371, 59974635, 26081060, 50629959, 16739174, ++ 285431, 2763829, 15736322, 4143876 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 794524995833413, 1849907304548286, 53348672473145, ++ 1272368559505217, 1147304168324779 ++#else ++ 2379333, 11839345, 62998462, 27565766, 11274297, 794957, 212801, ++ 18959769, 23527083, 17096164 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1504846112759364, 1203096289004681, 562139421471418, ++ 274333017451844, 1284344053775441 ++#else ++ 33431108, 22423954, 49269897, 17927531, 8909498, 8376530, ++ 34483524, 4087880, 51919953, 19138217 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 483048732424432, 2116063063343382, 30120189902313, ++ 292451576741007, 1156379271702225 ++#else ++ 1767664, 7197987, 53903638, 31531796, 54017513, 448825, 5799055, ++ 4357868, 62334673, 17231393 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 928372153029038, 2147692869914564, 1455665844462196, ++ 1986737809425946, 185207050258089 ++#else ++ 6721966, 13833823, 43585476, 32003117, 26354292, 21691111, ++ 23365146, 29604700, 7390889, 2759800 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 137732961814206, 706670923917341, 1387038086865771, ++ 1965643813686352, 1384777115696347 ++#else ++ 4409022, 2052381, 23373853, 10530217, 7676779, 20668478, ++ 21302352, 29290375, 1244379, 20634787 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 481144981981577, 2053319313589856, 2065402289827512, ++ 617954271490316, 1106602634668125 ++#else ++ 62687625, 7169618, 4982368, 30596842, 30256824, 30776892, ++ 14086412, 9208236, 15886429, 16489664 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 696298019648792, 893299659040895, 1148636718636009, ++ 26734077349617, 2203955659340681 ++#else ++ 1996056, 10375649, 14346367, 13311202, 60234729, 17116020, ++ 53415665, 398368, 36502409, 32841498 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 657390353372855, 998499966885562, 991893336905797, ++ 810470207106761, 343139804608786 ++#else ++ 41801399, 9795879, 64331450, 14878808, 33577029, 14780362, ++ 13348553, 12076947, 36272402, 5113181 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 791736669492960, 934767652997115, 824656780392914, ++ 1759463253018643, 361530362383518 ++#else ++ 49338080, 11797795, 31950843, 13929123, 41220562, 12288343, ++ 36767763, 26218045, 13847710, 5387222 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2022541353055597, 2094700262587466, 1551008075025686, ++ 242785517418164, 695985404963562 ++#else ++ 48526701, 30138214, 17824842, 31213466, 22744342, 23111821, ++ 8763060, 3617786, 47508202, 10370990 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1287487199965223, 2215311941380308, 1552928390931986, ++ 1664859529680196, 1125004975265243 ++#else ++ 20246567, 19185054, 22358228, 33010720, 18507282, 23140436, ++ 14554436, 24808340, 32232923, 16763880 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 677434665154918, 989582503122485, 1817429540898386, ++ 1052904935475344, 1143826298169798 ++#else ++ 9648486, 10094563, 26416693, 14745928, 36734546, 27081810, ++ 11094160, 15689506, 3140038, 17044340 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 367266328308408, 318431188922404, 695629353755355, ++ 634085657580832, 24581612564426 ++#else ++ 50948792, 5472694, 31895588, 4744994, 8823515, 10365685, ++ 39884064, 9448612, 38334410, 366294 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 773360688841258, 1815381330538070, 363773437667376, ++ 539629987070205, 783280434248437 ++#else ++ 19153450, 11523972, 56012374, 27051289, 42461232, 5420646, ++ 28344573, 8041113, 719605, 11671788 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 180820816194166, 168937968377394, 748416242794470, ++ 1227281252254508, 1567587861004268 ++#else ++ 8678006, 2694440, 60300850, 2517371, 4964326, 11152271, ++ 51675948, 18287915, 27000812, 23358879 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 478775558583645, 2062896624554807, 699391259285399, ++ 358099408427873, 1277310261461761 ++#else ++ 51950941, 7134311, 8639287, 30739555, 59873175, 10421741, ++ 564065, 5336097, 6750977, 19033406 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1984740906540026, 1079164179400229, 1056021349262661, ++ 1659958556483663, 1088529069025527 ++#else ++ 11836410, 29574944, 26297893, 16080799, 23455045, 15735944, ++ 1695823, 24735310, 8169719, 16220347 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 580736401511151, 1842931091388998, 1177201471228238, ++ 2075460256527244, 1301133425678027 ++#else ++ 48993007, 8653646, 17578566, 27461813, 59083086, 17541668, ++ 55964556, 30926767, 61118155, 19388398 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1515728832059182, 1575261009617579, 1510246567196186, ++ 191078022609704, 116661716289141 ++#else ++ 43800366, 22586119, 15213227, 23473218, 36255258, 22504427, ++ 27884328, 2847284, 2655861, 1738395 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1295295738269652, 1714742313707026, 545583042462581, ++ 2034411676262552, 1513248090013606 ++#else ++ 39571412, 19301410, 41772562, 25551651, 57738101, 8129820, ++ 21651608, 30315096, 48021414, 22549153 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 230710545179830, 30821514358353, 760704303452229, ++ 390668103790604, 573437871383156 ++#else ++ 1533110, 3437855, 23735889, 459276, 29970501, 11335377, ++ 26030092, 5821408, 10478196, 8544890 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1169380107545646, 263167233745614, 2022901299054448, ++ 819900753251120, 2023898464874585 ++#else ++ 32173102, 17425121, 24896206, 3921497, 22579056, 30143578, ++ 19270448, 12217473, 17789017, 30158437 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2102254323485823, 1570832666216754, 34696906544624, ++ 1993213739807337, 70638552271463 ++#else ++ 36555903, 31326030, 51530034, 23407230, 13243888, 517024, ++ 15479401, 29701199, 30460519, 1052596 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 894132856735058, 548675863558441, 845349339503395, ++ 1942269668326667, 1615682209874691 ++#else ++ 55493970, 13323617, 32618793, 8175907, 51878691, 12596686, ++ 27491595, 28942073, 3179267, 24075541 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1287670217537834, 1222355136884920, 1846481788678694, ++ 1150426571265110, 1613523400722047 ++#else ++ 31947050, 19187781, 62468280, 18214510, 51982886, 27514722, ++ 52352086, 17142691, 19072639, 24043372 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 793388516527298, 1315457083650035, 1972286999342417, ++ 1901825953052455, 338269477222410 ++#else ++ 11685058, 11822410, 3158003, 19601838, 33402193, 29389366, ++ 5977895, 28339415, 473098, 5040608 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 550201530671806, 778605267108140, 2063911101902983, ++ 115500557286349, 2041641272971022 ++#else ++ 46817982, 8198641, 39698732, 11602122, 1290375, 30754672, ++ 28326861, 1721092, 47550222, 30422825 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 717255318455100, 519313764361315, 2080406977303708, ++ 541981206705521, 774328150311600 ++#else ++ 7881532, 10687937, 7578723, 7738378, 48157852, 31000479, ++ 21820785, 8076149, 39240368, 11538388 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 261715221532238, 1795354330069993, 1496878026850283, ++ 499739720521052, 389031152673770 ++#else ++ 47173198, 3899860, 18283497, 26752864, 51380203, 22305220, ++ 8754524, 7446702, 61432810, 5797015 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1997217696294013, 1717306351628065, 1684313917746180, ++ 1644426076011410, 1857378133465451 ++#else ++ 55813245, 29760862, 51326753, 25589858, 12708868, 25098233, ++ 2014098, 24503858, 64739691, 27677090 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1475434724792648, 76931896285979, 1116729029771667, ++ 2002544139318042, 725547833803938 ++#else ++ 44636488, 21985690, 39426843, 1146374, 18956691, 16640559, ++ 1192730, 29840233, 15123618, 10811505 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2022306639183567, 726296063571875, 315345054448644, ++ 1058733329149221, 1448201136060677 ++#else ++ 14352079, 30134717, 48166819, 10822654, 32750596, 4699007, ++ 67038501, 15776355, 38222085, 21579878 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1710065158525665, 1895094923036397, 123988286168546, ++ 1145519900776355, 1607510767693874 ++#else ++ 38867681, 25481956, 62129901, 28239114, 29416930, 1847569, ++ 46454691, 17069576, 4714546, 23953777 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 561605375422540, 1071733543815037, 131496498800990, ++ 1946868434569999, 828138133964203 ++#else ++ 15200332, 8368572, 19679101, 15970074, 35236190, 1959450, ++ 24611599, 29010600, 55362987, 12340219 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1548495173745801, 442310529226540, 998072547000384, ++ 553054358385281, 644824326376171 ++#else ++ 12876937, 23074376, 33134380, 6590940, 60801088, 14872439, ++ 9613953, 8241152, 15370987, 9608631 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1445526537029440, 2225519789662536, 914628859347385, ++ 1064754194555068, 1660295614401091 ++#else ++ 62965568, 21540023, 8446280, 33162829, 4407737, 13629032, ++ 59383996, 15866073, 38898243, 24740332 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1199690223111956, 24028135822341, 66638289244341, ++ 57626156285975, 565093967979607 ++#else ++ 26660628, 17876777, 8393733, 358047, 59707573, 992987, 43204631, ++ 858696, 20571223, 8420556 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 876926774220824, 554618976488214, 1012056309841565, ++ 839961821554611, 1414499340307677 ++#else ++ 14620696, 13067227, 51661590, 8264466, 14106269, 15080814, ++ 33531827, 12516406, 45534429, 21077682 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 703047626104145, 1266841406201770, 165556500219173, ++ 486991595001879, 1011325891650656 ++#else ++ 236881, 10476226, 57258, 18877408, 6472997, 2466984, 17258519, ++ 7256740, 8791136, 15069930 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1622861044480487, 1156394801573634, 1869132565415504, ++ 327103985777730, 2095342781472284 ++#else ++ 1276391, 24182514, 22949634, 17231625, 43615824, 27852245, ++ 14711874, 4874229, 36445724, 31223040 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 334886927423922, 489511099221528, 129160865966726, ++ 1720809113143481, 619700195649254 ++#else ++ 5855666, 4990204, 53397016, 7294283, 59304582, 1924646, ++ 65685689, 25642053, 34039526, 9234252 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1646545795166119, 1758370782583567, 714746174550637, ++ 1472693650165135, 898994790308209 ++#else ++ 20590503, 24535444, 31529743, 26201766, 64402029, 10650547, ++ 31559055, 21944845, 18979185, 13396066 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 333403773039279, 295772542452938, 1693106465353610, ++ 912330357530760, 471235657950362 ++#else ++ 24474287, 4968103, 22267082, 4407354, 24063882, 25229252, ++ 48291976, 13594781, 33514650, 7021958 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1811196219982022, 1068969825533602, 289602974833439, ++ 1988956043611592, 863562343398367 ++#else ++ 55541958, 26988926, 45743778, 15928891, 40950559, 4315420, ++ 41160136, 29637754, 45628383, 12868081 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 906282429780072, 2108672665779781, 432396390473936, ++ 150625823801893, 1708930497638539 ++#else ++ 38473832, 13504660, 19988037, 31421671, 21078224, 6443208, ++ 45662757, 2244499, 54653067, 25465048 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 925664675702328, 21416848568684, 1831436641861340, ++ 601157008940113, 371818055044496 ++#else ++ 36513336, 13793478, 61256044, 319135, 41385692, 27290532, ++ 33086545, 8957937, 51875216, 5540520 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1479786007267725, 1738881859066675, 68646196476567, ++ 2146507056100328, 1247662817535471 ++#else ++ 55478669, 22050529, 58989363, 25911358, 2620055, 1022908, ++ 43398120, 31985447, 50980335, 18591624 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 52035296774456, 939969390708103, 312023458773250, ++ 59873523517659, 1231345905848899 ++#else ++ 23152952, 775386, 27395463, 14006635, 57407746, 4649511, ++ 1689819, 892185, 55595587, 18348483 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 643355106415761, 290186807495774, 2013561737429023, ++ 319648069511546, 393736678496162 ++#else ++ 9770129, 9586738, 26496094, 4324120, 1556511, 30004408, ++ 27453818, 4763127, 47929250, 5867133 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 129358342392716, 1932811617704777, 1176749390799681, ++ 398040349861790, 1170779668090425 ++#else ++ 34343820, 1927589, 31726409, 28801137, 23962433, 17534932, ++ 27846558, 5931263, 37359161, 17445976 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2051980782668029, 121859921510665, 2048329875753063, ++ 1235229850149665, 519062146124755 ++#else ++ 27461885, 30576896, 22380809, 1815854, 44075111, 30522493, ++ 7283489, 18406359, 47582163, 7734628 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1608170971973096, 415809060360428, 1350468408164766, ++ 2038620059057678, 1026904485989112 ++#else ++ 59098600, 23963614, 55988460, 6196037, 29344158, 20123547, ++ 7585294, 30377806, 18549496, 15302069 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1837656083115103, 1510134048812070, 906263674192061, ++ 1821064197805734, 565375124676301 ++#else ++ 34450527, 27383209, 59436070, 22502750, 6258877, 13504381, ++ 10458790, 27135971, 58236621, 8424745 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 578027192365650, 2034800251375322, 2128954087207123, ++ 478816193810521, 2196171989962750 ++#else ++ 24687186, 8613276, 36441818, 30320886, 1863891, 31723888, ++ 19206233, 7134917, 55824382, 32725512 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1633188840273139, 852787172373708, 1548762607215796, ++ 1266275218902681, 1107218203325133 ++#else ++ 11334899, 24336410, 8025292, 12707519, 17523892, 23078361, ++ 10243737, 18868971, 62042829, 16498836 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 462189358480054, 1784816734159228, 1611334301651368, ++ 1303938263943540, 707589560319424 ++#else ++ 8911542, 6887158, 57524604, 26595841, 11145640, 24010752, ++ 17303924, 19430194, 6536640, 10543906 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1038829280972848, 38176604650029, 753193246598573, ++ 1136076426528122, 595709990562434 ++#else ++ 38162480, 15479762, 49642029, 568875, 65611181, 11223453, ++ 64439674, 16928857, 39873154, 8876770 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1408451820859834, 2194984964010833, 2198361797561729, ++ 1061962440055713, 1645147963442934 ++#else ++ 41365946, 20987567, 51458897, 32707824, 34082177, 32758143, ++ 33627041, 15824473, 66504438, 24514614 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 4701053362120, 1647641066302348, 1047553002242085, ++ 1923635013395977, 206970314902065 ++#else ++ 10330056, 70051, 7957388, 24551765, 9764901, 15609756, 27698697, ++ 28664395, 1657393, 3084098 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1750479161778571, 1362553355169293, 1891721260220598, ++ 966109370862782, 1024913988299801 ++#else ++ 10477963, 26084172, 12119565, 20303627, 29016246, 28188843, ++ 31280318, 14396151, 36875289, 15272408 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 212699049131723, 1117950018299775, 1873945661751056, ++ 1403802921984058, 130896082652698 ++#else ++ 54820555, 3169462, 28813183, 16658753, 25116432, 27923966, ++ 41934906, 20918293, 42094106, 1950503 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 636808533673210, 1262201711667560, 390951380330599, ++ 1663420692697294, 561951321757406 ++#else ++ 40928506, 9489186, 11053416, 18808271, 36055143, 5825629, ++ 58724558, 24786899, 15341278, 8373727 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 520731594438141, 1446301499955692, 273753264629267, ++ 1565101517999256, 1019411827004672 ++#else ++ 28685821, 7759505, 52730348, 21551571, 35137043, 4079241, ++ 298136, 23321830, 64230656, 15190419 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 926527492029409, 1191853477411379, 734233225181171, ++ 184038887541270, 1790426146325343 ++#else ++ 34175969, 13806335, 52771379, 17760000, 43104243, 10940927, ++ 8669718, 2742393, 41075551, 26679428 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1464651961852572, 1483737295721717, 1519450561335517, ++ 1161429831763785, 405914998179977 ++#else ++ 65528476, 21825014, 41129205, 22109408, 49696989, 22641577, ++ 9291593, 17306653, 54954121, 6048604 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 996126634382301, 796204125879525, 127517800546509, ++ 344155944689303, 615279846169038 ++#else ++ 36803549, 14843443, 1539301, 11864366, 20201677, 1900163, ++ 13934231, 5128323, 11213262, 9168384 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 738724080975276, 2188666632415296, 1961313708559162, ++ 1506545807547587, 1151301638969740 ++#else ++ 40828332, 11007846, 19408960, 32613674, 48515898, 29225851, ++ 62020803, 22449281, 20470156, 17155731 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 622917337413835, 1218989177089035, 1284857712846592, ++ 970502061709359, 351025208117090 ++#else ++ 43972811, 9282191, 14855179, 18164354, 59746048, 19145871, ++ 44324911, 14461607, 14042978, 5230683 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2067814584765580, 1677855129927492, 2086109782475197, ++ 235286517313238, 1416314046739645 ++#else ++ 29969548, 30812838, 50396996, 25001989, 9175485, 31085458, ++ 21556950, 3506042, 61174973, 21104723 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 586844262630358, 307444381952195, 458399356043426, ++ 602068024507062, 1028548203415243 ++#else ++ 63964118, 8744660, 19704003, 4581278, 46678178, 6830682, ++ 45824694, 8971512, 38569675, 15326562 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 678489922928203, 2016657584724032, 90977383049628, ++ 1026831907234582, 615271492942522 ++#else ++ 47644235, 10110287, 49846336, 30050539, 43608476, 1355668, ++ 51585814, 15300987, 46594746, 9168259 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 301225714012278, 1094837270268560, 1202288391010439, ++ 644352775178361, 1647055902137983 ++#else ++ 61755510, 4488612, 43305616, 16314346, 7780487, 17915493, ++ 38160505, 9601604, 33087103, 24543045 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1210746697896478, 1416608304244708, 686487477217856, ++ 1245131191434135, 1051238336855737 ++#else ++ 47665694, 18041531, 46311396, 21109108, 37284416, 10229460, ++ 39664535, 18553900, 61111993, 15664671 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1135604073198207, 1683322080485474, 769147804376683, ++ 2086688130589414, 900445683120379 ++#else ++ 23294591, 16921819, 44458082, 25083453, 27844203, 11461195, ++ 13099750, 31094076, 18151675, 13417686 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1971518477615628, 401909519527336, 448627091057375, ++ 1409486868273821, 1214789035034363 ++#else ++ 42385932, 29377914, 35958184, 5988918, 40250079, 6685064, ++ 1661597, 21002991, 15271675, 18101767 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1364039144731711, 1897497433586190, 2203097701135459, ++ 145461396811251, 1349844460790699 ++#else ++ 11433023, 20325767, 8239630, 28274915, 65123427, 32828713, ++ 48410099, 2167543, 60187563, 20114249 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1045230323257973, 818206601145807, 630513189076103, ++ 1672046528998132, 807204017562437 ++#else ++ 35672693, 15575145, 30436815, 12192228, 44645511, 9395378, ++ 57191156, 24915434, 12215109, 12028277 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 439961968385997, 386362664488986, 1382706320807688, ++ 309894000125359, 2207801346498567 ++#else ++ 14098381, 6555944, 23007258, 5757252, 51681032, 20603929, ++ 30123439, 4617780, 50208775, 32898803 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1229004686397588, 920643968530863, 123975893911178, ++ 681423993215777, 1400559197080973 ++#else ++ 63082644, 18313596, 11893167, 13718664, 52299402, 1847384, ++ 51288865, 10154008, 23973261, 20869958 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2003766096898049, 170074059235165, 1141124258967971, ++ 1485419893480973, 1573762821028725 ++#else ++ 40577025, 29858441, 65199965, 2534300, 35238307, 17004076, ++ 18341389, 22134481, 32013173, 23450893 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 729905708611432, 1270323270673202, 123353058984288, ++ 426460209632942, 2195574535456672 ++#else ++ 41629544, 10876442, 55337778, 18929291, 54739296, 1838103, ++ 21911214, 6354752, 4425632, 32716610 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1271140255321235, 2044363183174497, 52125387634689, ++ 1445120246694705, 942541986339084 ++#else ++ 56675475, 18941465, 22229857, 30463385, 53917697, 776728, ++ 49693489, 21533969, 4725004, 14044970 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1761608437466135, 583360847526804, 1586706389685493, ++ 2157056599579261, 1170692369685772 ++#else ++ 19268631, 26250011, 1555348, 8692754, 45634805, 23643767, ++ 6347389, 32142648, 47586572, 17444675 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 871476219910823, 1878769545097794, 2241832391238412, ++ 548957640601001, 690047440233174 ++#else ++ 42244775, 12986007, 56209986, 27995847, 55796492, 33405905, ++ 19541417, 8180106, 9282262, 10282508 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 297194732135507, 1366347803776820, 1301185512245601, ++ 561849853336294, 1533554921345731 ++#else ++ 40903763, 4428546, 58447668, 20360168, 4098401, 19389175, ++ 15522534, 8372215, 5542595, 22851749 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 999628998628371, 1132836708493400, 2084741674517453, ++ 469343353015612, 678782988708035 ++#else ++ 56546323, 14895632, 26814552, 16880582, 49628109, 31065071, ++ 64326972, 6993760, 49014979, 10114654 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2189427607417022, 699801937082607, 412764402319267, ++ 1478091893643349, 2244675696854460 ++#else ++ 47001790, 32625013, 31422703, 10427861, 59998115, 6150668, ++ 38017109, 22025285, 25953724, 33448274 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1712292055966563, 204413590624874, 1405738637332841, ++ 408981300829763, 861082219276721 ++#else ++ 62874467, 25515139, 57989738, 3045999, 2101609, 20947138, ++ 19390019, 6094296, 63793585, 12831124 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 508561155940631, 966928475686665, 2236717801150132, ++ 424543858577297, 2089272956986143 ++#else ++ 51110167, 7578151, 5310217, 14408357, 33560244, 33329692, ++ 31575953, 6326196, 7381791, 31132593 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 221245220129925, 1156020201681217, 491145634799213, ++ 542422431960839, 828100817819207 ++#else ++ 46206085, 3296810, 24736065, 17226043, 18374253, 7318640, ++ 6295303, 8082724, 51746375, 12339663 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 153756971240384, 1299874139923977, 393099165260502, ++ 1058234455773022, 996989038681183 ++#else ++ 27724736, 2291157, 6088201, 19369634, 1792726, 5857634, ++ 13848414, 15768922, 25091167, 14856294 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 559086812798481, 573177704212711, 1629737083816402, ++ 1399819713462595, 1646954378266038 ++#else ++ 48242193, 8331042, 24373479, 8541013, 66406866, 24284974, ++ 12927299, 20858939, 44926390, 24541532 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1887963056288059, 228507035730124, 1468368348640282, ++ 930557653420194, 613513962454686 ++#else ++ 55685435, 28132841, 11632844, 3405020, 30536730, 21880393, ++ 39848098, 13866389, 30146206, 9142070 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1224529808187553, 1577022856702685, 2206946542980843, ++ 625883007765001, 279930793512158 ++#else ++ 3924129, 18246916, 53291741, 23499471, 12291819, 32886066, ++ 39406089, 9326383, 58871006, 4171293 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1076287717051609, 1114455570543035, 187297059715481, ++ 250446884292121, 1885187512550540 ++#else ++ 51186905, 16037936, 6713787, 16606682, 45496729, 2790943, ++ 26396185, 3731949, 345228, 28091483 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 902497362940219, 76749815795675, 1657927525633846, ++ 1420238379745202, 1340321636548352 ++#else ++ 45781307, 13448258, 25284571, 1143661, 20614966, 24705045, ++ 2031538, 21163201, 50855680, 19972348 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1129576631190784, 1281994010027327, 996844254743018, ++ 257876363489249, 1150850742055018 ++#else ++ 31016192, 16832003, 26371391, 19103199, 62081514, 14854136, ++ 17477601, 3842657, 28012650, 17149012 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 628740660038789, 1943038498527841, 467786347793886, ++ 1093341428303375, 235413859513003 ++#else ++ 62033029, 9368965, 58546785, 28953529, 51858910, 6970559, ++ 57918991, 16292056, 58241707, 3507939 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 237425418909360, 469614029179605, 1512389769174935, ++ 1241726368345357, 441602891065214 ++#else ++ 29439664, 3537914, 23333589, 6997794, 49553303, 22536363, ++ 51899661, 18503164, 57943934, 6580395 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1736417953058555, 726531315520508, 1833335034432527, ++ 1629442561574747, 624418919286085 ++#else ++ 54923003, 25874643, 16438268, 10826160, 58412047, 27318820, ++ 17860443, 24280586, 65013061, 9304566 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1960754663920689, 497040957888962, 1909832851283095, ++ 1271432136996826, 2219780368020940 ++#else ++ 20714545, 29217521, 29088194, 7406487, 11426967, 28458727, ++ 14792666, 18945815, 5289420, 33077305 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1537037379417136, 1358865369268262, 2130838645654099, ++ 828733687040705, 1999987652890901 ++#else ++ 50443312, 22903641, 60948518, 20248671, 9192019, 31751970, ++ 17271489, 12349094, 26939669, 29802138 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 629042105241814, 1098854999137608, 887281544569320, ++ 1423102019874777, 7911258951561 ++#else ++ 54218966, 9373457, 31595848, 16374215, 21471720, 13221525, ++ 39825369, 21205872, 63410057, 117886 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1811562332665373, 1501882019007673, 2213763501088999, ++ 359573079719636, 36370565049116 ++#else ++ 22263325, 26994382, 3984569, 22379786, 51994855, 32987646, ++ 28311252, 5358056, 43789084, 541963 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 218907117361280, 1209298913016966, 1944312619096112, ++ 1130690631451061, 1342327389191701 ++#else ++ 16259200, 3261970, 2309254, 18019958, 50223152, 28972515, ++ 24134069, 16848603, 53771797, 20002236 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1369976867854704, 1396479602419169, 1765656654398856, ++ 2203659200586299, 998327836117241 ++#else ++ 9378160, 20414246, 44262881, 20809167, 28198280, 26310334, ++ 64709179, 32837080, 690425, 14876244 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2230701885562825, 1348173180338974, 2172856128624598, ++ 1426538746123771, 444193481326151 ++#else ++ 24977353, 33240048, 58884894, 20089345, 28432342, 32378079, ++ 54040059, 21257083, 44727879, 6618998 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 784210426627951, 918204562375674, 1284546780452985, ++ 1324534636134684, 1872449409642708 ++#else ++ 65570671, 11685645, 12944378, 13682314, 42719353, 19141238, ++ 8044828, 19737104, 32239828, 27901670 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 319638829540294, 596282656808406, 2037902696412608, ++ 1557219121643918, 341938082688094 ++#else ++ 48505798, 4762989, 66182614, 8885303, 38696384, 30367116, ++ 9781646, 23204373, 32779358, 5095274 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1901860206695915, 2004489122065736, 1625847061568236, ++ 973529743399879, 2075287685312905 ++#else ++ 34100715, 28339925, 34843976, 29869215, 9460460, 24227009, ++ 42507207, 14506723, 21639561, 30924196 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1371853944110545, 1042332820512553, 1949855697918254, ++ 1791195775521505, 37487364849293 ++#else ++ 50707921, 20442216, 25239337, 15531969, 3987758, 29055114, ++ 65819361, 26690896, 17874573, 558605 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 687200189577855, 1082536651125675, 644224940871546, ++ 340923196057951, 343581346747396 ++#else ++ 53508735, 10240080, 9171883, 16131053, 46239610, 9599699, ++ 33499487, 5080151, 2085892, 5119761 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2082717129583892, 27829425539422, 145655066671970, ++ 1690527209845512, 1865260509673478 ++#else ++ 44903700, 31034903, 50727262, 414690, 42089314, 2170429, ++ 30634760, 25190818, 35108870, 27794547 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1059729620568824, 2163709103470266, 1440302280256872, ++ 1769143160546397, 869830310425069 ++#else ++ 60263160, 15791201, 8550074, 32241778, 29928808, 21462176, ++ 27534429, 26362287, 44757485, 12961481 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1609516219779025, 777277757338817, 2101121130363987, ++ 550762194946473, 1905542338659364 ++#else ++ 42616785, 23983660, 10368193, 11582341, 43711571, 31309144, ++ 16533929, 8206996, 36914212, 28394793 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2024821921041576, 426948675450149, 595133284085473, ++ 471860860885970, 600321679413000 ++#else ++ 55987368, 30172197, 2307365, 6362031, 66973409, 8868176, ++ 50273234, 7031274, 7589640, 8945490 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 598474602406721, 1468128276358244, 1191923149557635, ++ 1501376424093216, 1281662691293476 ++#else ++ 34956097, 8917966, 6661220, 21876816, 65916803, 17761038, ++ 7251488, 22372252, 24099108, 19098262 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1721138489890707, 1264336102277790, 433064545421287, ++ 1359988423149466, 1561871293409447 ++#else ++ 5019539, 25646962, 4244126, 18840076, 40175591, 6453164, ++ 47990682, 20265406, 60876967, 23273695 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 719520245587143, 393380711632345, 132350400863381, ++ 1543271270810729, 1819543295798660 ++#else ++ 10853575, 10721687, 26480089, 5861829, 44113045, 1972174, ++ 65242217, 22996533, 63745412, 27113307 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 396397949784152, 1811354474471839, 1362679985304303, ++ 2117033964846756, 498041172552279 ++#else ++ 50106456, 5906789, 221599, 26991285, 7828207, 20305514, ++ 24362660, 31546264, 53242455, 7421391 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1812471844975748, 1856491995543149, 126579494584102, ++ 1036244859282620, 1975108050082550 ++#else ++ 8139908, 27007935, 32257645, 27663886, 30375718, 1886181, ++ 45933756, 15441251, 28826358, 29431403 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 650623932407995, 1137551288410575, 2125223403615539, ++ 1725658013221271, 2134892965117796 ++#else ++ 6267067, 9695052, 7709135, 16950835, 34239795, 31668296, ++ 14795159, 25714308, 13746020, 31812384 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 522584000310195, 1241762481390450, 1743702789495384, ++ 2227404127826575, 1686746002148897 ++#else ++ 28584883, 7787108, 60375922, 18503702, 22846040, 25983196, ++ 63926927, 33190907, 4771361, 25134474 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 427904865186312, 1703211129693455, 1585368107547509, ++ 1436984488744336, 761188534613978 ++#else ++ 24949256, 6376279, 39642383, 25379823, 48462709, 23623825, ++ 33543568, 21412737, 3569626, 11342593 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 318101947455002, 248138407995851, 1481904195303927, ++ 309278454311197, 1258516760217879 ++#else ++ 26514970, 4740088, 27912651, 3697550, 19331575, 22082093, ++ 6809885, 4608608, 7325975, 18753361 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1275068538599310, 513726919533379, 349926553492294, ++ 688428871968420, 1702400196000666 ++#else ++ 55490446, 19000001, 42787651, 7655127, 65739590, 5214311, ++ 39708324, 10258389, 49462170, 25367739 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1061864036265233, 961611260325381, 321859632700838, ++ 1045600629959517, 1985130202504038 ++#else ++ 11431185, 15823007, 26570245, 14329124, 18029990, 4796082, ++ 35662685, 15580663, 9280358, 29580745 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1558816436882417, 1962896332636523, 1337709822062152, ++ 1501413830776938, 294436165831932 ++#else ++ 66948081, 23228174, 44253547, 29249434, 46247496, 19933429, ++ 34297962, 22372809, 51563772, 4387440 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 818359826554971, 1862173000996177, 626821592884859, ++ 573655738872376, 1749691246745455 ++#else ++ 46309467, 12194511, 3937617, 27748540, 39954043, 9340369, ++ 42594872, 8548136, 20617071, 26072431 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1988022651432119, 1082111498586040, 1834020786104821, ++ 1454826876423687, 692929915223122 ++#else ++ 66170039, 29623845, 58394552, 16124717, 24603125, 27329039, ++ 53333511, 21678609, 24345682, 10325460 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2146513703733331, 584788900394667, 464965657279958, ++ 2183973639356127, 238371159456790 ++#else ++ 47253587, 31985546, 44906155, 8714033, 14007766, 6928528, ++ 16318175, 32543743, 4766742, 3552007 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1129007025494441, 2197883144413266, 265142755578169, ++ 971864464758890, 1983715884903702 ++#else ++ 45357481, 16823515, 1351762, 32751011, 63099193, 3950934, ++ 3217514, 14481909, 10988822, 29559670 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1291366624493075, 381456718189114, 1711482489312444, ++ 1815233647702022, 892279782992467 ++#else ++ 15564307, 19242862, 3101242, 5684148, 30446780, 25503076, ++ 12677126, 27049089, 58813011, 13296004 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 444548969917454, 1452286453853356, 2113731441506810, ++ 645188273895859, 810317625309512 ++#else ++ 57666574, 6624295, 36809900, 21640754, 62437882, 31497052, ++ 31521203, 9614054, 37108040, 12074673 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2242724082797924, 1373354730327868, 1006520110883049, ++ 2147330369940688, 1151816104883620 ++#else ++ 4771172, 33419193, 14290748, 20464580, 27992297, 14998318, ++ 65694928, 31997715, 29832612, 17163397 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1745720200383796, 1911723143175317, 2056329390702074, ++ 355227174309849, 879232794371100 ++#else ++ 7064884, 26013258, 47946901, 28486894, 48217594, 30641695, ++ 25825241, 5293297, 39986204, 13101589 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 163723479936298, 115424889803150, 1156016391581227, ++ 1894942220753364, 1970549419986329 ++#else ++ 64810282, 2439669, 59642254, 1719964, 39841323, 17225986, ++ 32512468, 28236839, 36752793, 29363474 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 681981452362484, 267208874112496, 1374683991933094, ++ 638600984916117, 646178654558546 ++#else ++ 37102324, 10162315, 33928688, 3981722, 50626726, 20484387, ++ 14413973, 9515896, 19568978, 9628812 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 13378654854251, 106237307029567, 1944412051589651, ++ 1841976767925457, 230702819835573 ++#else ++ 33053803, 199357, 15894591, 1583059, 27380243, 28973997, ++ 49269969, 27447592, 60817077, 3437739 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 260683893467075, 854060306077237, 913639551980112, ++ 4704576840123, 280254810808712 ++#else ++ 48129987, 3884492, 19469877, 12726490, 15913552, 13614290, ++ 44147131, 70103, 7463304, 4176122 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 715374893080287, 1173334812210491, 1806524662079626, ++ 1894596008000979, 398905715033393 ++#else ++ 39984863, 10659916, 11482427, 17484051, 12771466, 26919315, ++ 34389459, 28231680, 24216881, 5944158 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 500026409727661, 1596431288195371, 1420380351989370, ++ 985211561521489, 392444930785633 ++#else ++ 8894125, 7450974, 64444715, 23788679, 39028346, 21165316, ++ 19345745, 14680796, 11632993, 5847885 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2096421546958141, 1922523000950363, 789831022876840, ++ 427295144688779, 320923973161730 ++#else ++ 26942781, 31239115, 9129563, 28647825, 26024104, 11769399, ++ 55590027, 6367193, 57381634, 4782139 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1927770723575450, 1485792977512719, 1850996108474547, ++ 551696031508956, 2126047405475647 ++#else ++ 19916442, 28726022, 44198159, 22140040, 25606323, 27581991, ++ 33253852, 8220911, 6358847, 31680575 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2112099158080148, 742570803909715, 6484558077432, ++ 1951119898618916, 93090382703416 ++#else ++ 801428, 31472730, 16569427, 11065167, 29875704, 96627, 7908388, ++ 29073952, 53570360, 1387154 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 383905201636970, 859946997631870, 855623867637644, ++ 1017125780577795, 794250831877809 ++#else ++ 19646058, 5720633, 55692158, 12814208, 11607948, 12749789, ++ 14147075, 15156355, 45242033, 11835259 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 77571826285752, 999304298101753, 487841111777762, ++ 1038031143212339, 339066367948762 ++#else ++ 19299512, 1155910, 28703737, 14890794, 2925026, 7269399, ++ 26121523, 15467869, 40548314, 5052482 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 674994775520533, 266035846330789, 826951213393478, ++ 1405007746162285, 1781791018620876 ++#else ++ 64091413, 10058205, 1980837, 3964243, 22160966, 12322533, ++ 60677741, 20936246, 12228556, 26550755 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1001412661522686, 348196197067298, 1666614366723946, ++ 888424995032760, 580747687801357 ++#else ++ 32944382, 14922211, 44263970, 5188527, 21913450, 24834489, ++ 4001464, 13238564, 60994061, 8653814 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1939560076207777, 1409892634407635, 552574736069277, ++ 383854338280405, 190706709864139 ++#else ++ 22865569, 28901697, 27603667, 21009037, 14348957, 8234005, ++ 24808405, 5719875, 28483275, 2841751 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2177087163428741, 1439255351721944, 1208070840382793, ++ 2230616362004769, 1396886392021913 ++#else ++ 50687877, 32441126, 66781144, 21446575, 21886281, 18001658, ++ 65220897, 33238773, 19932057, 20815229 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 676962063230039, 1880275537148808, 2046721011602706, ++ 888463247083003, 1318301552024067 ++#else ++ 55452759, 10087520, 58243976, 28018288, 47830290, 30498519, ++ 3999227, 13239134, 62331395, 19644223 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1466980508178206, 617045217998949, 652303580573628, ++ 757303753529064, 207583137376902 ++#else ++ 1382174, 21859713, 17266789, 9194690, 53784508, 9720080, ++ 20403944, 11284705, 53095046, 3093229 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1511056752906902, 105403126891277, 493434892772846, ++ 1091943425335976, 1802717338077427 ++#else ++ 16650902, 22516500, 66044685, 1570628, 58779118, 7352752, ++ 66806440, 16271224, 43059443, 26862581 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1853982405405128, 1878664056251147, 1528011020803992, ++ 1019626468153565, 1128438412189035 ++#else ++ 45197768, 27626490, 62497547, 27994275, 35364760, 22769138, ++ 24123613, 15193618, 45456747, 16815042 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1963939888391106, 293456433791664, 697897559513649, ++ 985882796904380, 796244541237972 ++#else ++ 57172930, 29264984, 41829040, 4372841, 2087473, 10399484, ++ 31870908, 14690798, 17361620, 11864968 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 416770998629779, 389655552427054, 1314476859406756, ++ 1749382513022778, 1161905598739491 ++#else ++ 55801235, 6210371, 13206574, 5806320, 38091172, 19587231, ++ 54777658, 26067830, 41530403, 17313742 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1428358296490651, 1027115282420478, 304840698058337, ++ 441410174026628, 1819358356278573 ++#else ++ 14668443, 21284197, 26039038, 15305210, 25515617, 4542480, ++ 10453892, 6577524, 9145645, 27110552 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 204943430200135, 1554861433819175, 216426658514651, ++ 264149070665950, 2047097371738319 ++#else ++ 5974855, 3053895, 57675815, 23169240, 35243739, 3225008, ++ 59136222, 3936127, 61456591, 30504127 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1934415182909034, 1393285083565062, 516409331772960, ++ 1157690734993892, 121039666594268 ++#else ++ 30625386, 28825032, 41552902, 20761565, 46624288, 7695098, ++ 17097188, 17250936, 39109084, 1803631 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 662035583584445, 286736105093098, 1131773000510616, ++ 818494214211439, 472943792054479 ++#else ++ 63555773, 9865098, 61880298, 4272700, 61435032, 16864731, ++ 14911343, 12196514, 45703375, 7047411 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 665784778135882, 1893179629898606, 808313193813106, ++ 276797254706413, 1563426179676396 ++#else ++ 20093258, 9920966, 55970670, 28210574, 13161586, 12044805, ++ 34252013, 4124600, 34765036, 23296865 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 945205108984232, 526277562959295, 1324180513733566, ++ 1666970227868664, 153547609289173 ++#else ++ 46320040, 14084653, 53577151, 7842146, 19119038, 19731827, ++ 4752376, 24839792, 45429205, 2288037 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2031433403516252, 203996615228162, 170487168837083, ++ 981513604791390, 843573964916831 ++#else ++ 40289628, 30270716, 29965058, 3039786, 52635099, 2540456, ++ 29457502, 14625692, 42289247, 12570231 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1476570093962618, 838514669399805, 1857930577281364, ++ 2017007352225784, 317085545220047 ++#else ++ 66045306, 22002608, 16920317, 12494842, 1278292, 27685323, ++ 45948920, 30055751, 55134159, 4724942 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1461557121912842, 1600674043318359, 2157134900399597, ++ 1670641601940616, 127765583803283 ++#else ++ 17960970, 21778898, 62967895, 23851901, 58232301, 32143814, ++ 54201480, 24894499, 37532563, 1903855 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1293543509393474, 2143624609202546, 1058361566797508, ++ 214097127393994, 946888515472729 ++#else ++ 23134274, 19275300, 56426866, 31942495, 20684484, 15770816, ++ 54119114, 3190295, 26955097, 14109738 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 357067959932916, 1290876214345711, 521245575443703, ++ 1494975468601005, 800942377643885 ++#else ++ 15308788, 5320727, 36995055, 19235554, 22902007, 7767164, ++ 29425325, 22276870, 31960941, 11934971 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 566116659100033, 820247422481740, 994464017954148, ++ 327157611686365, 92591318111744 ++#else ++ 39713153, 8435795, 4109644, 12222639, 42480996, 14818668, ++ 20638173, 4875028, 10491392, 1379718 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 617256647603209, 1652107761099439, 1857213046645471, ++ 1085597175214970, 817432759830522 ++#else ++ 53949449, 9197840, 3875503, 24618324, 65725151, 27674630, ++ 33518458, 16176658, 21432314, 12180697 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 771808161440705, 1323510426395069, 680497615846440, ++ 851580615547985, 1320806384849017 ++#else ++ 55321537, 11500837, 13787581, 19721842, 44678184, 10140204, ++ 1465425, 12689540, 56807545, 19681548 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1219260086131915, 647169006596815, 79601124759706, ++ 2161724213426748, 404861897060198 ++#else ++ 5414091, 18168391, 46101199, 9643569, 12834970, 1186149, ++ 64485948, 32212200, 26128230, 6032912 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1327968293887866, 1335500852943256, 1401587164534264, ++ 558137311952440, 1551360549268902 ++#else ++ 40771450, 19788269, 32496024, 19900513, 17847800, 20885276, ++ 3604024, 8316894, 41233830, 23117073 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 417621685193956, 1429953819744454, 396157358457099, ++ 1940470778873255, 214000046234152 ++#else ++ 3296484, 6223048, 24680646, 21307972, 44056843, 5903204, ++ 58246567, 28915267, 12376616, 3188849 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1268047918491973, 2172375426948536, 1533916099229249, ++ 1761293575457130, 1590622667026765 ++#else ++ 29190469, 18895386, 27549112, 32370916, 3520065, 22857131, ++ 32049514, 26245319, 50999629, 23702124 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1627072914981959, 2211603081280073, 1912369601616504, ++ 1191770436221309, 2187309757525860 ++#else ++ 52364359, 24245275, 735817, 32955454, 46701176, 28496527, ++ 25246077, 17758763, 18640740, 32593455 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1149147819689533, 378692712667677, 828475842424202, ++ 2218619146419342, 70688125792186 ++#else ++ 60180029, 17123636, 10361373, 5642961, 4910474, 12345252, ++ 35470478, 33060001, 10530746, 1053335 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1299739417079761, 1438616663452759, 1536729078504412, ++ 2053896748919838, 1008421032591246 ++#else ++ 37842897, 19367626, 53570647, 21437058, 47651804, 22899047, ++ 35646494, 30605446, 24018830, 15026644 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2040723824657366, 399555637875075, 632543375452995, ++ 872649937008051, 1235394727030233 ++#else ++ 44516310, 30409154, 64819587, 5953842, 53668675, 9425630, ++ 25310643, 13003497, 64794073, 18408815 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2211311599327900, 2139787259888175, 938706616835350, ++ 12609661139114, 2081897930719789 ++#else ++ 39688860, 32951110, 59064879, 31885314, 41016598, 13987818, ++ 39811242, 187898, 43942445, 31022696 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1324994503390450, 336982330582631, 1183998925654177, ++ 1091654665913274, 48727673971319 ++#else ++ 45364466, 19743956, 1844839, 5021428, 56674465, 17642958, ++ 9716666, 16266922, 62038647, 726098 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1845522914617879, 1222198248335542, 150841072760134, ++ 1927029069940982, 1189913404498011 ++#else ++ 29370903, 27500434, 7334070, 18212173, 9385286, 2247707, ++ 53446902, 28714970, 30007387, 17731091 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1079559557592645, 2215338383666441, 1903569501302605, ++ 49033973033940, 305703433934152 ++#else ++ 66172485, 16086690, 23751945, 33011114, 65941325, 28365395, ++ 9137108, 730663, 9835848, 4555336 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 94653405416909, 1386121349852999, 1062130477891762, ++ 36553947479274, 833669648948846 ++#else ++ 43732429, 1410445, 44855111, 20654817, 30867634, 15826977, ++ 17693930, 544696, 55123566, 12422645 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1432015813136298, 440364795295369, 1395647062821501, ++ 1976874522764578, 934452372723352 ++#else ++ 31117226, 21338698, 53606025, 6561946, 57231997, 20796761, ++ 61990178, 29457725, 29120152, 13924425 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1296625309219774, 2068273464883862, 1858621048097805, ++ 1492281814208508, 2235868981918946 ++#else ++ 49707966, 19321222, 19675798, 30819676, 56101901, 27695611, ++ 57724924, 22236731, 7240930, 33317044 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1490330266465570, 1858795661361448, 1436241134969763, ++ 294573218899647, 1208140011028933 ++#else ++ 35747106, 22207651, 52101416, 27698213, 44655523, 21401660, ++ 1222335, 4389483, 3293637, 18002689 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1282462923712748, 741885683986255, 2027754642827561, ++ 518989529541027, 1826610009555945 ++#else ++ 50424044, 19110186, 11038543, 11054958, 53307689, 30215898, ++ 42789283, 7733546, 12796905, 27218610 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1525827120027511, 723686461809551, 1597702369236987, ++ 244802101764964, 1502833890372311 ++#else ++ 58349431, 22736595, 41689999, 10783768, 36493307, 23807620, ++ 38855524, 3647835, 3222231, 22393970 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 113622036244513, 1233740067745854, 674109952278496, ++ 2114345180342965, 166764512856263 ++#else ++ 18606113, 1693100, 41660478, 18384159, 4112352, 10045021, ++ 23603893, 31506198, 59558087, 2484984 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2041668749310338, 2184405322203901, 1633400637611036, ++ 2110682505536899, 2048144390084644 ++#else ++ 9255298, 30423235, 54952701, 32550175, 13098012, 24339566, ++ 16377219, 31451620, 47306788, 30519729 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 503058759232932, 760293024620937, 2027152777219493, ++ 666858468148475, 1539184379870952 ++#else ++ 44379556, 7496159, 61366665, 11329248, 19991973, 30206930, ++ 35390715, 9936965, 37011176, 22935634 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1916168475367211, 915626432541343, 883217071712575, ++ 363427871374304, 1976029821251593 ++#else ++ 21878571, 28553135, 4338335, 13643897, 64071999, 13160959, ++ 19708896, 5415497, 59748361, 29445138 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 678039535434506, 570587290189340, 1605302676614120, ++ 2147762562875701, 1706063797091704 ++#else ++ 27736842, 10103576, 12500508, 8502413, 63695848, 23920873, ++ 10436917, 32004156, 43449720, 25422331 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1439489648586438, 2194580753290951, 832380563557396, ++ 561521973970522, 584497280718389 ++#else ++ 19492550, 21450067, 37426887, 32701801, 63900692, 12403436, ++ 30066266, 8367329, 13243957, 8709688 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 187989455492609, 681223515948275, 1933493571072456, ++ 1872921007304880, 488162364135671 ++#else ++ 12015105, 2801261, 28198131, 10151021, 24818120, 28811299, ++ 55914672, 27908697, 5150967, 7274186 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1413466089534451, 410844090765630, 1397263346404072, ++ 408227143123410, 1594561803147811 ++#else ++ 2831347, 21062286, 1478974, 6122054, 23825128, 20820846, ++ 31097298, 6083058, 31021603, 23760822 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2102170800973153, 719462588665004, 1479649438510153, ++ 1097529543970028, 1302363283777685 ++#else ++ 64578913, 31324785, 445612, 10720828, 53259337, 22048494, ++ 43601132, 16354464, 15067285, 19406725 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 942065717847195, 1069313679352961, 2007341951411051, ++ 70973416446291, 1419433790163706 ++#else ++ 7840923, 14037873, 33744001, 15934015, 66380651, 29911725, ++ 21403987, 1057586, 47729402, 21151211 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1146565545556377, 1661971299445212, 406681704748893, ++ 564452436406089, 1109109865829139 ++#else ++ 915865, 17085158, 15608284, 24765302, 42751837, 6060029, ++ 49737545, 8410996, 59888403, 16527024 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2214421081775077, 1165671861210569, 1890453018796184, ++ 3556249878661, 442116172656317 ++#else ++ 32922597, 32997445, 20336073, 17369864, 10903704, 28169945, ++ 16957573, 52992, 23834301, 6588044 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 753830546620811, 1666955059895019, 1530775289309243, ++ 1119987029104146, 2164156153857580 ++#else ++ 32752011, 11232950, 3381995, 24839566, 22652987, 22810329, ++ 17159698, 16689107, 46794284, 32248439 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 615171919212796, 1523849404854568, 854560460547503, ++ 2067097370290715, 1765325848586042 ++#else ++ 62419196, 9166775, 41398568, 22707125, 11576751, 12733943, ++ 7924251, 30802151, 1976122, 26305405 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1094538949313667, 1796592198908825, 870221004284388, ++ 2025558921863561, 1699010892802384 ++#else ++ 21251203, 16309901, 64125849, 26771309, 30810596, 12967303, ++ 156041, 30183180, 12331344, 25317235 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1951351290725195, 1916457206844795, 198025184438026, ++ 1909076887557595, 1938542290318919 ++#else ++ 8651595, 29077400, 51023227, 28557437, 13002506, 2950805, ++ 29054427, 28447462, 10008135, 28886531 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1014323197538413, 869150639940606, 1756009942696599, ++ 1334952557375672, 1544945379082874 ++#else ++ 31486061, 15114593, 52847614, 12951353, 14369431, 26166587, ++ 16347320, 19892343, 8684154, 23021480 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 764055910920305, 1603590757375439, 146805246592357, ++ 1843313433854297, 954279890114939 ++#else ++ 19443825, 11385320, 24468943, 23895364, 43189605, 2187568, ++ 40845657, 27467510, 31316347, 14219878 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 80113526615750, 764536758732259, 1055139345100233, ++ 469252651759390, 617897512431515 ++#else ++ 38514374, 1193784, 32245219, 11392485, 31092169, 15722801, ++ 27146014, 6992409, 29126555, 9207390 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 74497112547268, 740094153192149, 1745254631717581, ++ 727713886503130, 1283034364416928 ++#else ++ 32382916, 1110093, 18477781, 11028262, 39697101, 26006320, ++ 62128346, 10843781, 59151264, 19118701 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 525892105991110, 1723776830270342, 1476444848991936, ++ 573789489857760, 133864092632978 ++#else ++ 2814918, 7836403, 27519878, 25686276, 46214848, 22000742, ++ 45614304, 8550129, 28346258, 1994730 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 542611720192581, 1986812262899321, 1162535242465837, ++ 481498966143464, 544600533583622 ++#else ++ 47530565, 8085544, 53108345, 29605809, 2785837, 17323125, ++ 47591912, 7174893, 22628102, 8115180 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 64123227344372, 1239927720647794, 1360722983445904, ++ 222610813654661, 62429487187991 ++#else ++ 36703732, 955510, 55975026, 18476362, 34661776, 20276352, ++ 41457285, 3317159, 57165847, 930271 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1793193323953132, 91096687857833, 70945970938921, ++ 2158587638946380, 1537042406482111 ++#else ++ 51805164, 26720662, 28856489, 1357446, 23421993, 1057177, ++ 24091212, 32165462, 44343487, 22903716 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1895854577604609, 1394895708949416, 1728548428495944, ++ 1140864900240149, 563645333603061 ++#else ++ 44357633, 28250434, 54201256, 20785565, 51297352, 25757378, ++ 52269845, 17000211, 65241845, 8398969 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 141358280486863, 91435889572504, 1087208572552643, ++ 1829599652522921, 1193307020643647 ++#else ++ 35139535, 2106402, 62372504, 1362500, 12813763, 16200670, ++ 22981545, 27263159, 18009407, 17781660 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1611230858525381, 950720175540785, 499589887488610, ++ 2001656988495019, 88977313255908 ++#else ++ 49887941, 24009210, 39324209, 14166834, 29815394, 7444469, ++ 29551787, 29827013, 19288548, 1325865 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1189080501479658, 2184348804772597, 1040818725742319, ++ 2018318290311834, 1712060030915354 ++#else ++ 15100138, 17718680, 43184885, 32549333, 40658671, 15509407, ++ 12376730, 30075286, 33166106, 25511682 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 873966876953756, 1090638350350440, 1708559325189137, ++ 672344594801910, 1320437969700239 ++#else ++ 20909212, 13023121, 57899112, 16251777, 61330449, 25459517, ++ 12412150, 10018715, 2213263, 19676059 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1508590048271766, 1131769479776094, 101550868699323, ++ 428297785557897, 561791648661744 ++#else ++ 32529814, 22479743, 30361438, 16864679, 57972923, 1513225, ++ 22922121, 6382134, 61341936, 8371347 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 756417570499462, 237882279232602, 2136263418594016, ++ 1701968045454886, 703713185137472 ++#else ++ 9923462, 11271500, 12616794, 3544722, 37110496, 31832805, ++ 12891686, 25361300, 40665920, 10486143 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1781187809325462, 1697624151492346, 1381393690939988, ++ 175194132284669, 1483054666415238 ++#else ++ 44511638, 26541766, 8587002, 25296571, 4084308, 20584370, ++ 361725, 2610596, 43187334, 22099236 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2175517777364616, 708781536456029, 955668231122942, ++ 1967557500069555, 2021208005604118 ++#else ++ 5408392, 32417741, 62139741, 10561667, 24145918, 14240566, ++ 31319731, 29318891, 19985174, 30118346 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1115135966606887, 224217372950782, 915967306279222, ++ 593866251291540, 561747094208006 ++#else ++ 53114407, 16616820, 14549246, 3341099, 32155958, 13648976, ++ 49531796, 8849296, 65030, 8370684 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1443163092879439, 391875531646162, 2180847134654632, ++ 464538543018753, 1594098196837178 ++#else ++ 58787919, 21504805, 31204562, 5839400, 46481576, 32497154, ++ 47665921, 6922163, 12743482, 23753914 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 850858855888869, 319436476624586, 327807784938441, ++ 740785849558761, 17128415486016 ++#else ++ 64747493, 12678784, 28815050, 4759974, 43215817, 4884716, ++ 23783145, 11038569, 18800704, 255233 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2132756334090067, 536247820155645, 48907151276867, ++ 608473197600695, 1261689545022784 ++#else ++ 61839187, 31780545, 13957885, 7990715, 23132995, 728773, ++ 13393847, 9066957, 19258688, 18800639 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1525176236978354, 974205476721062, 293436255662638, ++ 148269621098039, 137961998433963 ++#else ++ 64172210, 22726896, 56676774, 14516792, 63468078, 4372540, ++ 35173943, 2209389, 65584811, 2055793 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1121075518299410, 2071745529082111, 1265567917414828, ++ 1648196578317805, 496232102750820 ++#else ++ 580882, 16705327, 5468415, 30871414, 36182444, 18858431, ++ 59905517, 24560042, 37087844, 7394434 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 122321229299801, 1022922077493685, 2001275453369484, ++ 2017441881607947, 993205880778002 ++#else ++ 23838809, 1822728, 51370421, 15242726, 8318092, 29821328, ++ 45436683, 30062226, 62287122, 14799920 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 654925550560074, 1168810995576858, 575655959430926, ++ 905758704861388, 496774564663534 ++#else ++ 13345610, 9759151, 3371034, 17416641, 16353038, 8577942, ++ 31129804, 13496856, 58052846, 7402517 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1954109525779738, 2117022646152485, 338102630417180, ++ 1194140505732026, 107881734943492 ++#else ++ 2286874, 29118501, 47066405, 31546095, 53412636, 5038121, ++ 11006906, 17794080, 8205060, 1607563 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1714785840001267, 2036500018681589, 1876380234251966, ++ 2056717182974196, 1645855254384642 ++#else ++ 14414067, 25552300, 3331829, 30346215, 22249150, 27960244, ++ 18364660, 30647474, 30019586, 24525154 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 106431476499341, 62482972120563, 1513446655109411, ++ 807258751769522, 538491469114 ++#else ++ 39420813, 1585952, 56333811, 931068, 37988643, 22552112, ++ 52698034, 12029092, 9944378, 8024 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2002850762893643, 1243624520538135, 1486040410574605, ++ 2184752338181213, 378495998083531 ++#else ++ 4368715, 29844802, 29874199, 18531449, 46878477, 22143727, ++ 50994269, 32555346, 58966475, 5640029 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 922510868424903, 1089502620807680, 402544072617374, ++ 1131446598479839, 1290278588136533 ++#else ++ 10299591, 13746483, 11661824, 16234854, 7630238, 5998374, ++ 9809887, 16859868, 15219797, 19226649 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1867998812076769, 715425053580701, 39968586461416, ++ 2173068014586163, 653822651801304 ++#else ++ 27425505, 27835351, 3055005, 10660664, 23458024, 595578, ++ 51710259, 32381236, 48766680, 9742716 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 162892278589453, 182585796682149, 75093073137630, ++ 497037941226502, 133871727117371 ++#else ++ 6744077, 2427284, 26042789, 2720740, 66260958, 1118973, ++ 32324614, 7406442, 12420155, 1994844 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1914596576579670, 1608999621851578, 1987629837704609, ++ 1519655314857977, 1819193753409464 ++#else ++ 14012502, 28529712, 48724410, 23975962, 40623521, 29617992, ++ 54075385, 22644628, 24319928, 27108099 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1949315551096831, 1069003344994464, 1939165033499916, ++ 1548227205730856, 1933767655861407 ++#else ++ 16412671, 29047065, 10772640, 15929391, 50040076, 28895810, ++ 10555944, 23070383, 37006495, 28815383 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1730519386931635, 1393284965610134, 1597143735726030, ++ 416032382447158, 1429665248828629 ++#else ++ 22397363, 25786748, 57815702, 20761563, 17166286, 23799296, ++ 39775798, 6199365, 21880021, 21303672 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 360275475604565, 547835731063078, 215360904187529, ++ 596646739879007, 332709650425085 ++#else ++ 62825557, 5368522, 35991846, 8163388, 36785801, 3209127, ++ 16557151, 8890729, 8840445, 4957760 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 47602113726801, 1522314509708010, 437706261372925, ++ 814035330438027, 335930650933545 ++#else ++ 51661137, 709326, 60189418, 22684253, 37330941, 6522331, ++ 45388683, 12130071, 52312361, 5005756 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1291597595523886, 1058020588994081, 402837842324045, ++ 1363323695882781, 2105763393033193 ++#else ++ 64994094, 19246303, 23019041, 15765735, 41839181, 6002751, ++ 10183197, 20315106, 50713577, 31378319 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 109521982566564, 1715257748585139, 1112231216891516, ++ 2046641005101484, 134249157157013 ++#else ++ 48083108, 1632004, 13466291, 25559332, 43468412, 16573536, ++ 35094956, 30497327, 22208661, 2000468 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2156991030936798, 2227544497153325, 1869050094431622, ++ 754875860479115, 1754242344267058 ++#else ++ 3065054, 32141671, 41510189, 33192999, 49425798, 27851016, ++ 58944651, 11248526, 63417650, 26140247 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1846089562873800, 98894784984326, 1412430299204844, ++ 171351226625762, 1100604760929008 ++#else ++ 10379208, 27508878, 8877318, 1473647, 37817580, 21046851, ++ 16690914, 2553332, 63976176, 16400288 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 84172382130492, 499710970700046, 425749630620778, ++ 1762872794206857, 612842602127960 ++#else ++ 15716668, 1254266, 48636174, 7446273, 58659946, 6344163, ++ 45011593, 26268851, 26894936, 9132066 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 868309334532756, 1703010512741873, 1952690008738057, ++ 4325269926064, 2071083554962116 ++#else ++ 24158868, 12938817, 11085297, 25376834, 39045385, 29097348, ++ 36532400, 64451, 60291780, 30861549 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 523094549451158, 401938899487815, 1407690589076010, ++ 2022387426254453, 158660516411257 ++#else ++ 13488534, 7794716, 22236231, 5989356, 25426474, 20976224, ++ 2350709, 30135921, 62420857, 2364225 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 612867287630009, 448212612103814, 571629077419196, ++ 1466796750919376, 1728478129663858 ++#else ++ 16335033, 9132434, 25640582, 6678888, 1725628, 8517937, ++ 55301840, 21856974, 15445874, 25756331 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1723848973783452, 2208822520534681, 1718748322776940, ++ 1974268454121942, 1194212502258141 ++#else ++ 29004188, 25687351, 28661401, 32914020, 54314860, 25611345, ++ 31863254, 29418892, 66830813, 17795152 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1254114807944608, 977770684047110, 2010756238954993, ++ 1783628927194099, 1525962994408256 ++#else ++ 60986784, 18687766, 38493958, 14569918, 56250865, 29962602, ++ 10343411, 26578142, 37280576, 22738620 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 232464058235826, 1948628555342434, 1835348780427694, ++ 1031609499437291, 64472106918373 ++#else ++ 27081650, 3463984, 14099042, 29036828, 1616302, 27348828, ++ 29542635, 15372179, 17293797, 960709 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 767338676040683, 754089548318405, 1523192045639075, ++ 435746025122062, 512692508440385 ++#else ++ 20263915, 11434237, 61343429, 11236809, 13505955, 22697330, ++ 50997518, 6493121, 47724353, 7639713 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1255955808701983, 1700487367990941, 1166401238800299, ++ 1175121994891534, 1190934801395380 ++#else ++ 64278047, 18715199, 25403037, 25339236, 58791851, 17380732, ++ 18006286, 17510682, 29994676, 17746311 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 349144008168292, 1337012557669162, 1475912332999108, ++ 1321618454900458, 47611291904320 ++#else ++ 9769828, 5202651, 42951466, 19923039, 39057860, 21992807, ++ 42495722, 19693649, 35924288, 709463 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 877519947135419, 2172838026132651, 272304391224129, ++ 1655143327559984, 886229406429814 ++#else ++ 12286395, 13076066, 45333675, 32377809, 42105665, 4057651, ++ 35090736, 24663557, 16102006, 13205847 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 375806028254706, 214463229793940, 572906353144089, ++ 572168269875638, 697556386112979 ++#else ++ 13733362, 5599946, 10557076, 3195751, 61550873, 8536969, ++ 41568694, 8525971, 10151379, 10394400 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1168827102357844, 823864273033637, 2071538752104697, ++ 788062026895924, 599578340743362 ++#else ++ 4024660, 17416881, 22436261, 12276534, 58009849, 30868332, ++ 19698228, 11743039, 33806530, 8934413 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1948116082078088, 2054898304487796, 2204939184983900, ++ 210526805152138, 786593586607626 ++#else ++ 51229064, 29029191, 58528116, 30620370, 14634844, 32856154, ++ 57659786, 3137093, 55571978, 11721157 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1915320147894736, 156481169009469, 655050471180417, ++ 592917090415421, 2165897438660879 ++#else ++ 17555920, 28540494, 8268605, 2331751, 44370049, 9761012, ++ 9319229, 8835153, 57903375, 32274386 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1726336468579724, 1119932070398949, 1929199510967666, ++ 33918788322959, 1836837863503150 ++#else ++ 66647436, 25724417, 20614117, 16688288, 59594098, 28747312, ++ 22300303, 505429, 6108462, 27371017 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 829996854845988, 217061778005138, 1686565909803640, ++ 1346948817219846, 1723823550730181 ++#else ++ 62038564, 12367916, 36445330, 3234472, 32617080, 25131790, ++ 29880582, 20071101, 40210373, 25686972 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 384301494966394, 687038900403062, 2211195391021739, ++ 254684538421383, 1245698430589680 ++#else ++ 35133562, 5726538, 26934134, 10237677, 63935147, 32949378, ++ 24199303, 3795095, 7592688, 18562353 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1247567493562688, 1978182094455847, 183871474792955, ++ 806570235643435, 288461518067916 ++#else ++ 21594432, 18590204, 17466407, 29477210, 32537083, 2739898, ++ 6407723, 12018833, 38852812, 4298411 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1449077384734201, 38285445457996, 2136537659177832, ++ 2146493000841573, 725161151123125 ++#else ++ 46458361, 21592935, 39872588, 570497, 3767144, 31836892, ++ 13891941, 31985238, 13717173, 10805743 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1201928866368855, 800415690605445, 1703146756828343, ++ 997278587541744, 1858284414104014 ++#else ++ 52432215, 17910135, 15287173, 11927123, 24177847, 25378864, ++ 66312432, 14860608, 40169934, 27690595 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 356468809648877, 782373916933152, 1718002439402870, ++ 1392222252219254, 663171266061951 ++#else ++ 12962541, 5311799, 57048096, 11658279, 18855286, 25600231, ++ 13286262, 20745728, 62727807, 9882021 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 759628738230460, 1012693474275852, 353780233086498, ++ 246080061387552, 2030378857679162 ++#else ++ 18512060, 11319350, 46985740, 15090308, 18818594, 5271736, ++ 44380960, 3666878, 43141434, 30255002 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2040672435071076, 888593182036908, 1298443657189359, ++ 1804780278521327, 354070726137060 ++#else ++ 60319844, 30408388, 16192428, 13241070, 15898607, 19348318, ++ 57023983, 26893321, 64705764, 5276064 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1894938527423184, 1463213041477277, 474410505497651, ++ 247294963033299, 877975941029128 ++#else ++ 30169808, 28236784, 26306205, 21803573, 27814963, 7069267, ++ 7152851, 3684982, 1449224, 13082861 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 207937160991127, 12966911039119, 820997788283092, ++ 1010440472205286, 1701372890140810 ++#else ++ 10342807, 3098505, 2119311, 193222, 25702612, 12233820, ++ 23697382, 15056736, 46092426, 25352431 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 218882774543183, 533427444716285, 1233243976733245, ++ 435054256891319, 1509568989549904 ++#else ++ 33958735, 3261607, 22745853, 7948688, 19370557, 18376767, ++ 40936887, 6482813, 56808784, 22494330 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1888838535711826, 1052177758340622, 1213553803324135, ++ 169182009127332, 463374268115872 ++#else ++ 32869458, 28145887, 25609742, 15678670, 56421095, 18083360, ++ 26112420, 2521008, 44444576, 6904814 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 299137589460312, 1594371588983567, 868058494039073, ++ 257771590636681, 1805012993142921 ++#else ++ 29506904, 4457497, 3377935, 23757988, 36598817, 12935079, ++ 1561737, 3841096, 38105225, 26896789 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1806842755664364, 2098896946025095, 1356630998422878, ++ 1458279806348064, 347755825962072 ++#else ++ 10340844, 26924055, 48452231, 31276001, 12621150, 20215377, ++ 30878496, 21730062, 41524312, 5181965 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1402334161391744, 1560083671046299, 1008585416617747, ++ 1147797150908892, 1420416683642459 ++#else ++ 25940096, 20896407, 17324187, 23247058, 58437395, 15029093, ++ 24396252, 17103510, 64786011, 21165857 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 665506704253369, 273770475169863, 799236974202630, ++ 848328990077558, 1811448782807931 ++#else ++ 45343161, 9916822, 65808455, 4079497, 66080518, 11909558, ++ 1782390, 12641087, 20603771, 26992690 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1468412523962641, 771866649897997, 1931766110147832, ++ 799561180078482, 524837559150077 ++#else ++ 48226577, 21881051, 24849421, 11501709, 13161720, 28785558, ++ 1925522, 11914390, 4662781, 7820689 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2223212657821850, 630416247363666, 2144451165500328, ++ 816911130947791, 1024351058410032 ++#else ++ 12241050, 33128450, 8132690, 9393934, 32846760, 31954812, ++ 29749455, 12172924, 16136752, 15264020 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1266603897524861, 156378408858100, 1275649024228779, ++ 447738405888420, 253186462063095 ++#else ++ 56758909, 18873868, 58896884, 2330219, 49446315, 19008651, ++ 10658212, 6671822, 19012087, 3772772 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2022215964509735, 136144366993649, 1800716593296582, ++ 1193970603800203, 871675847064218 ++#else ++ 3753511, 30133366, 10617073, 2028709, 14841030, 26832768, ++ 28718731, 17791548, 20527770, 12988982 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1862751661970328, 851596246739884, 1519315554814041, ++ 1542798466547449, 1417975335901520 ++#else ++ 52286360, 27757162, 63400876, 12689772, 66209881, 22639565, ++ 42925817, 22989488, 3299664, 21129479 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1228168094547481, 334133883362894, 587567568420081, ++ 433612590281181, 603390400373205 ++#else ++ 50331161, 18301130, 57466446, 4978982, 3308785, 8755439, ++ 6943197, 6461331, 41525717, 8991217 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 121893973206505, 1843345804916664, 1703118377384911, ++ 497810164760654, 101150811654673 ++#else ++ 49882601, 1816361, 65435576, 27467992, 31783887, 25378441, ++ 34160718, 7417949, 36866577, 1507264 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 458346255946468, 290909935619344, 1452768413850679, ++ 550922875254215, 1537286854336538 ++#else ++ 29692644, 6829891, 56610064, 4334895, 20945975, 21647936, ++ 38221255, 8209390, 14606362, 22907359 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 584322311184395, 380661238802118, 114839394528060, ++ 655082270500073, 2111856026034852 ++#else ++ 63627275, 8707080, 32188102, 5672294, 22096700, 1711240, ++ 34088169, 9761486, 4170404, 31469107 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 996965581008991, 2148998626477022, 1012273164934654, ++ 1073876063914522, 1688031788934939 ++#else ++ 55521375, 14855944, 62981086, 32022574, 40459774, 15084045, ++ 22186522, 16002000, 52832027, 25153633 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 923487018849600, 2085106799623355, 528082801620136, ++ 1606206360876188, 735907091712524 ++#else ++ 62297408, 13761028, 35404987, 31070512, 63796392, 7869046, ++ 59995292, 23934339, 13240844, 10965870 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1697697887804317, 1335343703828273, 831288615207040, ++ 949416685250051, 288760277392022 ++#else ++ 59366301, 25297669, 52340529, 19898171, 43876480, 12387165, ++ 4498947, 14147411, 29514390, 4302863 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1419122478109648, 1325574567803701, 602393874111094, ++ 2107893372601700, 1314159682671307 ++#else ++ 53695440, 21146572, 20757301, 19752600, 14785142, 8976368, ++ 62047588, 31410058, 17846987, 19582505 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2201150872731804, 2180241023425241, 97663456423163, ++ 1633405770247824, 848945042443986 ++#else ++ 64864412, 32799703, 62511833, 32488122, 60861691, 1455298, ++ 45461136, 24339642, 61886162, 12650266 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1173339555550611, 818605084277583, 47521504364289, ++ 924108720564965, 735423405754506 ++#else ++ 57202067, 17484121, 21134159, 12198166, 40044289, 708125, ++ 387813, 13770293, 47974538, 10958662 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 830104860549448, 1886653193241086, 1600929509383773, ++ 1475051275443631, 286679780900937 ++#else ++ 22470984, 12369526, 23446014, 28113323, 45588061, 23855708, ++ 55336367, 21979976, 42025033, 4271861 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1577111294832995, 1030899169768747, 144900916293530, ++ 1964672592979567, 568390100955250 ++#else ++ 41939299, 23500789, 47199531, 15361594, 61124506, 2159191, ++ 75375, 29275903, 34582642, 8469672 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 278388655910247, 487143369099838, 927762205508727, ++ 181017540174210, 1616886700741287 ++#else ++ 15854951, 4148314, 58214974, 7259001, 11666551, 13824734, ++ 36577666, 2697371, 24154791, 24093489 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1191033906638969, 940823957346562, 1606870843663445, ++ 861684761499847, 658674867251089 ++#else ++ 15446137, 17747788, 29759746, 14019369, 30811221, 23944241, ++ 35526855, 12840103, 24913809, 9815020 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1875032594195546, 1427106132796197, 724736390962158, ++ 901860512044740, 635268497268760 ++#else ++ 62399578, 27940162, 35267365, 21265538, 52665326, 10799413, ++ 58005188, 13438768, 18735128, 9466238 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 622869792298357, 1903919278950367, 1922588621661629, ++ 1520574711600434, 1087100760174640 ++#else ++ 11933045, 9281483, 5081055, 28370608, 64480701, 28648802, ++ 59381042, 22658328, 44380208, 16199063 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 25465949416618, 1693639527318811, 1526153382657203, ++ 125943137857169, 145276964043999 ++#else ++ 14576810, 379472, 40322331, 25237195, 37682355, 22741457, ++ 67006097, 1876698, 30801119, 2164795 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 214739857969358, 920212862967915, 1939901550972269, ++ 1211862791775221, 85097515720120 ++#else ++ 15995086, 3199873, 13672555, 13712240, 47730029, 28906785, ++ 54027253, 18058162, 53616056, 1268051 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2006245852772938, 734762734836159, 254642929763427, ++ 1406213292755966, 239303749517686 ++#else ++ 56818250, 29895392, 63822271, 10948817, 23037027, 3794475, ++ 63638526, 20954210, 50053494, 3565903 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1619678837192149, 1919424032779215, 1357391272956794, ++ 1525634040073113, 1310226789796241 ++#else ++ 29210069, 24135095, 61189071, 28601646, 10834810, 20226706, ++ 50596761, 22733718, 39946641, 19523900 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1040763709762123, 1704449869235352, 605263070456329, ++ 1998838089036355, 1312142911487502 ++#else ++ 53946955, 15508587, 16663704, 25398282, 38758921, 9019122, ++ 37925443, 29785008, 2244110, 19552453 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1996723311435669, 1844342766567060, 985455700466044, ++ 1165924681400960, 311508689870129 ++#else ++ 61955989, 29753495, 57802388, 27482848, 16243068, 14684434, ++ 41435776, 17373631, 13491505, 4641841 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 43173156290518, 2202883069785309, 1137787467085917, ++ 1733636061944606, 1394992037553852 ++#else ++ 10813398, 643330, 47920349, 32825515, 30292061, 16954354, ++ 27548446, 25833190, 14476988, 20787001 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 670078326344559, 555655025059356, 471959386282438, ++ 2141455487356409, 849015953823125 ++#else ++ 10292079, 9984945, 6481436, 8279905, 59857350, 7032742, ++ 27282937, 31910173, 39196053, 12651323 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2197214573372804, 794254097241315, 1030190060513737, ++ 267632515541902, 2040478049202624 ++#else ++ 35923332, 32741048, 22271203, 11835308, 10201545, 15351028, ++ 17099662, 3988035, 21721536, 30405492 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1812516004670529, 1609256702920783, 1706897079364493, ++ 258549904773295, 996051247540686 ++#else ++ 10202177, 27008593, 35735631, 23979793, 34958221, 25434748, ++ 54202543, 3852693, 13216206, 14842320 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1540374301420584, 1764656898914615, 1810104162020396, ++ 923808779163088, 664390074196579 ++#else ++ 51293224, 22953365, 60569911, 26295436, 60124204, 26972653, ++ 35608016, 13765823, 39674467, 9900183 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1323460699404750, 1262690757880991, 871777133477900, ++ 1060078894988977, 1712236889662886 ++#else ++ 14465486, 19721101, 34974879, 18815558, 39665676, 12990491, ++ 33046193, 15796406, 60056998, 25514317 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1696163952057966, 1391710137550823, 608793846867416, ++ 1034391509472039, 1780770894075012 ++#else ++ 30924398, 25274812, 6359015, 20738097, 16508376, 9071735, ++ 41620263, 15413634, 9524356, 26535554 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1367603834210841, 2131988646583224, 890353773628144, ++ 1908908219165595, 270836895252891 ++#else ++ 12274201, 20378885, 32627640, 31769106, 6736624, 13267305, ++ 5237659, 28444949, 15663515, 4035784 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 597536315471731, 40375058742586, 1942256403956049, ++ 1185484645495932, 312666282024145 ++#else ++ 64157555, 8903984, 17349946, 601635, 50676049, 28941875, ++ 53376124, 17665097, 44850385, 4659090 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1919411405316294, 1234508526402192, 1066863051997083, ++ 1008444703737597, 1348810787701552 ++#else ++ 50192582, 28601458, 36715152, 18395610, 20774811, 15897498, ++ 5736189, 15026997, 64930608, 20098846 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2102881477513865, 1570274565945361, 1573617900503708, ++ 18662635732583, 2232324307922098 ++#else ++ 58249865, 31335375, 28571665, 23398914, 66634396, 23448733, ++ 63307367, 278094, 23440562, 33264224 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1853931367696942, 8107973870707, 350214504129299, ++ 775206934582587, 1752317649166792 ++#else ++ 10226222, 27625730, 15139955, 120818, 52241171, 5218602, ++ 32937275, 11551483, 50536904, 26111567 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1417148368003523, 721357181628282, 505725498207811, ++ 373232277872983, 261634707184480 ++#else ++ 17932739, 21117156, 43069306, 10749059, 11316803, 7535897, ++ 22503767, 5561594, 63462240, 3898660 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2186733281493267, 2250694917008620, 1014829812957440, ++ 479998161452389, 83566193876474 ++#else ++ 7749907, 32584865, 50769132, 33537967, 42090752, 15122142, ++ 65535333, 7152529, 21831162, 1245233 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1268116367301224, 560157088142809, 802626839600444, ++ 2210189936605713, 1129993785579988 ++#else ++ 26958440, 18896406, 4314585, 8346991, 61431100, 11960071, ++ 34519569, 32934396, 36706772, 16838219 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 615183387352312, 917611676109240, 878893615973325, ++ 978940963313282, 938686890583575 ++#else ++ 54942968, 9166946, 33491384, 13673479, 29787085, 13096535, ++ 6280834, 14587357, 44770839, 13987524 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 522024729211672, 1045059315315808, 1892245413707790, ++ 1907891107684253, 2059998109500714 ++#else ++ 42758936, 7778774, 21116000, 15572597, 62275598, 28196653, ++ 62807965, 28429792, 59639082, 30696363 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1799679152208884, 912132775900387, 25967768040979, ++ 432130448590461, 274568990261996 ++#else ++ 9681908, 26817309, 35157219, 13591837, 60225043, 386949, ++ 31622781, 6439245, 52527852, 4091396 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 98698809797682, 2144627600856209, 1907959298569602, ++ 811491302610148, 1262481774981493 ++#else ++ 58682418, 1470726, 38999185, 31957441, 3978626, 28430809, ++ 47486180, 12092162, 29077877, 18812444 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1791451399743152, 1713538728337276, 118349997257490, ++ 1882306388849954, 158235232210248 ++#else ++ 5269168, 26694706, 53878652, 25533716, 25932562, 1763552, ++ 61502754, 28048550, 47091016, 2357888 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1217809823321928, 2173947284933160, 1986927836272325, ++ 1388114931125539, 12686131160169 ++#else ++ 32264008, 18146780, 61721128, 32394338, 65017541, 29607531, ++ 23104803, 20684524, 5727337, 189038 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1650875518872272, 1136263858253897, 1732115601395988, ++ 734312880662190, 1252904681142109 ++#else ++ 14609104, 24599962, 61108297, 16931650, 52531476, 25810533, ++ 40363694, 10942114, 41219933, 18669734 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 372986456113865, 525430915458171, 2116279931702135, ++ 501422713587815, 1907002872974925 ++#else ++ 20513481, 5557931, 51504251, 7829530, 26413943, 31535028, ++ 45729895, 7471780, 13913677, 28416557 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 803147181835288, 868941437997146, 316299302989663, ++ 943495589630550, 571224287904572 ++#else ++ 41534488, 11967825, 29233242, 12948236, 60354399, 4713226, ++ 58167894, 14059179, 12878652, 8511905 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 227742695588364, 1776969298667369, 628602552821802, ++ 457210915378118, 2041906378111140 ++#else ++ 41452044, 3393630, 64153449, 26478905, 64858154, 9366907, ++ 36885446, 6812973, 5568676, 30426776 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 815000523470260, 913085688728307, 1052060118271173, ++ 1345536665214223, 541623413135555 ++#else ++ 11630004, 12144454, 2116339, 13606037, 27378885, 15676917, ++ 49700111, 20050058, 52713667, 8070817 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1580216071604333, 1877997504342444, 857147161260913, ++ 703522726778478, 2182763974211603 ++#else ++ 27117677, 23547054, 35826092, 27984343, 1127281, 12772488, ++ 37262958, 10483305, 55556115, 32525717 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1870080310923419, 71988220958492, 1783225432016732, ++ 615915287105016, 1035570475990230 ++#else ++ 10637467, 27866368, 5674780, 1072708, 40765276, 26572129, ++ 65424888, 9177852, 39615702, 15431202 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 730987750830150, 857613889540280, 1083813157271766, ++ 1002817255970169, 1719228484436074 ++#else ++ 20525126, 10892566, 54366392, 12779442, 37615830, 16150074, ++ 38868345, 14943141, 52052074, 25618500 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 377616581647602, 1581980403078513, 804044118130621, ++ 2034382823044191, 643844048472185 ++#else ++ 37084402, 5626925, 66557297, 23573344, 753597, 11981191, ++ 25244767, 30314666, 63752313, 9594023 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 176957326463017, 1573744060478586, 528642225008045, ++ 1816109618372371, 1515140189765006 ++#else ++ 43356201, 2636869, 61944954, 23450613, 585133, 7877383, ++ 11345683, 27062142, 13352334, 22577348 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1888911448245718, 1387110895611080, 1924503794066429, ++ 1731539523700949, 2230378382645454 ++#else ++ 65177046, 28146973, 3304648, 20669563, 17015805, 28677341, ++ 37325013, 25801949, 53893326, 33235227 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 443392177002051, 233793396845137, 2199506622312416, ++ 1011858706515937, 974676837063129 ++#else ++ 20239939, 6607058, 6203985, 3483793, 48721888, 32775202, ++ 46385121, 15077869, 44358105, 14523816 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1846351103143623, 1949984838808427, 671247021915253, ++ 1946756846184401, 1929296930380217 ++#else ++ 27406023, 27512775, 27423595, 29057038, 4996213, 10002360, ++ 38266833, 29008937, 36936121, 28748764 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 849646212452002, 1410198775302919, 73767886183695, ++ 1641663456615812, 762256272452411 ++#else ++ 11374242, 12660715, 17861383, 21013599, 10935567, 1099227, ++ 53222788, 24462691, 39381819, 11358503 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 692017667358279, 723305578826727, 1638042139863265, ++ 748219305990306, 334589200523901 ++#else ++ 54378055, 10311866, 1510375, 10778093, 64989409, 24408729, ++ 32676002, 11149336, 40985213, 4985767 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 22893968530686, 2235758574399251, 1661465835630252, ++ 925707319443452, 1203475116966621 ++#else ++ 48012542, 341146, 60911379, 33315398, 15756972, 24757770, ++ 66125820, 13794113, 47694557, 17933176 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 801299035785166, 1733292596726131, 1664508947088596, ++ 467749120991922, 1647498584535623 ++#else ++ 6490062, 11940286, 25495923, 25828072, 8668372, 24803116, ++ 3367602, 6970005, 65417799, 24549641 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 903105258014366, 427141894933047, 561187017169777, ++ 1884330244401954, 1914145708422219 ++#else ++ 1656478, 13457317, 15370807, 6364910, 13605745, 8362338, ++ 47934242, 28078708, 50312267, 28522993 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1344191060517578, 1960935031767890, 1518838929955259, ++ 1781502350597190, 1564784025565682 ++#else ++ 44835530, 20030007, 67044178, 29220208, 48503227, 22632463, ++ 46537798, 26546453, 67009010, 23317098 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 673723351748086, 1979969272514923, 1175287312495508, ++ 1187589090978666, 1881897672213940 ++#else ++ 17747446, 10039260, 19368299, 29503841, 46478228, 17513145, ++ 31992682, 17696456, 37848500, 28042460 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1917185587363432, 1098342571752737, 5935801044414, ++ 2000527662351839, 1538640296181569 ++#else ++ 31932008, 28568291, 47496481, 16366579, 22023614, 88450, ++ 11371999, 29810185, 4882241, 22927527 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2495540013192, 678856913479236, 224998292422872, ++ 219635787698590, 1972465269000940 ++#else ++ 29796488, 37186, 19818052, 10115756, 55279832, 3352735, ++ 18551198, 3272828, 61917932, 29392022 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 271413961212179, 1353052061471651, 344711291283483, ++ 2014925838520662, 2006221033113941 ++#else ++ 12501267, 4044383, 58495907, 20162046, 34678811, 5136598, ++ 47878486, 30024734, 330069, 29895023 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 194583029968109, 514316781467765, 829677956235672, ++ 1676415686873082, 810104584395840 ++#else ++ 6384877, 2899513, 17807477, 7663917, 64749976, 12363164, ++ 25366522, 24980540, 66837568, 12071498 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1980510813313589, 1948645276483975, 152063780665900, ++ 129968026417582, 256984195613935 ++#else ++ 58743349, 29511910, 25133447, 29037077, 60897836, 2265926, ++ 34339246, 1936674, 61949167, 3829362 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1860190562533102, 1936576191345085, 461100292705964, ++ 1811043097042830, 957486749306835 ++#else ++ 28425966, 27718999, 66531773, 28857233, 52891308, 6870929, ++ 7921550, 26986645, 26333139, 14267664 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 796664815624365, 1543160838872951, 1500897791837765, ++ 1667315977988401, 599303877030711 ++#else ++ 56041645, 11871230, 27385719, 22994888, 62522949, 22365119, ++ 10004785, 24844944, 45347639, 8930323 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1151480509533204, 2136010406720455, 738796060240027, ++ 319298003765044, 1150614464349587 ++#else ++ 45911060, 17158396, 25654215, 31829035, 12282011, 11008919, ++ 1541940, 4757911, 40617363, 17145491 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1731069268103150, 735642447616087, 1364750481334268, ++ 417232839982871, 927108269127661 ++#else ++ 13537262, 25794942, 46504023, 10961926, 61186044, 20336366, ++ 53952279, 6217253, 51165165, 13814989 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1017222050227968, 1987716148359, 2234319589635701, ++ 621282683093392, 2132553131763026 ++#else ++ 49686272, 15157789, 18705543, 29619, 24409717, 33293956, ++ 27361680, 9257833, 65152338, 31777517 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1567828528453324, 1017807205202360, 565295260895298, ++ 829541698429100, 307243822276582 ++#else ++ 42063564, 23362465, 15366584, 15166509, 54003778, 8423555, ++ 37937324, 12361134, 48422886, 4578289 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 249079270936248, 1501514259790706, 947909724204848, ++ 944551802437487, 552658763982480 ++#else ++ 24579768, 3711570, 1342322, 22374306, 40103728, 14124955, ++ 44564335, 14074918, 21964432, 8235257 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2089966982947227, 1854140343916181, 2151980759220007, ++ 2139781292261749, 158070445864917 ++#else ++ 60580251, 31142934, 9442965, 27628844, 12025639, 32067012, ++ 64127349, 31885225, 13006805, 2355433 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1338766321464554, 1906702607371284, 1519569445519894, ++ 115384726262267, 1393058953390992 ++#else ++ 50803946, 19949172, 60476436, 28412082, 16974358, 22643349, ++ 27202043, 1719366, 1141648, 20758196 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1364621558265400, 1512388234908357, 1926731583198686, ++ 2041482526432505, 920401122333774 ++#else ++ 54244920, 20334445, 58790597, 22536340, 60298718, 28710537, ++ 13475065, 30420460, 32674894, 13715045 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1884844597333588, 601480070269079, 620203503079537, ++ 1079527400117915, 1202076693132015 ++#else ++ 11423316, 28086373, 32344215, 8962751, 24989809, 9241752, ++ 53843611, 16086211, 38367983, 17912338 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 840922919763324, 727955812569642, 1303406629750194, ++ 522898432152867, 294161410441865 ++#else ++ 65699196, 12530727, 60740138, 10847386, 19531186, 19422272, ++ 55399715, 7791793, 39862921, 4383346 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 353760790835310, 1598361541848743, 1122905698202299, ++ 1922533590158905, 419107700666580 ++#else ++ 38137966, 5271446, 65842855, 23817442, 54653627, 16732598, ++ 62246457, 28647982, 27193556, 6245191 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 359856369838236, 180914355488683, 861726472646627, ++ 218807937262986, 575626773232501 ++#else ++ 51914908, 5362277, 65324971, 2695833, 4960227, 12840725, ++ 23061898, 3260492, 22510453, 8577507 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 755467689082474, 909202735047934, 730078068932500, ++ 936309075711518, 2007798262842972 ++#else ++ 54476394, 11257345, 34415870, 13548176, 66387860, 10879010, ++ 31168030, 13952092, 37537372, 29918525 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1609384177904073, 362745185608627, 1335318541768201, ++ 800965770436248, 547877979267412 ++#else ++ 3877321, 23981693, 32416691, 5405324, 56104457, 19897796, ++ 3759768, 11935320, 5611860, 8164018 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 984339177776787, 815727786505884, 1645154585713747, ++ 1659074964378553, 1686601651984156 ++#else ++ 50833043, 14667796, 15906460, 12155291, 44997715, 24514713, ++ 32003001, 24722143, 5773084, 25132323 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1697863093781930, 599794399429786, 1104556219769607, ++ 830560774794755, 12812858601017 ++#else ++ 43320746, 25300131, 1950874, 8937633, 18686727, 16459170, ++ 66203139, 12376319, 31632953, 190926 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1168737550514982, 897832437380552, 463140296333799, ++ 302564600022547, 2008360505135501 ++#else ++ 42515238, 17415546, 58684872, 13378745, 14162407, 6901328, ++ 58820115, 4508563, 41767309, 29926903 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1856930662813910, 678090852002597, 1920179140755167, ++ 1259527833759868, 55540971895511 ++#else ++ 8884438, 27670423, 6023973, 10104341, 60227295, 28612898, ++ 18722940, 18768427, 65436375, 827624 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1158643631044921, 476554103621892, 178447851439725, ++ 1305025542653569, 103433927680625 ++#else ++ 34388281, 17265135, 34605316, 7101209, 13354605, 2659080, ++ 65308289, 19446395, 42230385, 1541285 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2176793111709008, 1576725716350391, 2009350167273523, ++ 2012390194631546, 2125297410909580 ++#else ++ 2901328, 32436745, 3880375, 23495044, 49487923, 29941650, ++ 45306746, 29986950, 20456844, 31669399 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 825403285195098, 2144208587560784, 1925552004644643, ++ 1915177840006985, 1015952128947864 ++#else ++ 27019610, 12299467, 53450576, 31951197, 54247203, 28692960, ++ 47568713, 28538373, 29439640, 15138866 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1807108316634472, 1534392066433717, 347342975407218, ++ 1153820745616376, 7375003497471 ++#else ++ 21536104, 26928012, 34661045, 22864223, 44700786, 5175813, ++ 61688824, 17193268, 7779327, 109896 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 983061001799725, 431211889901241, 2201903782961093, ++ 817393911064341, 2214616493042167 ++#else ++ 30279725, 14648750, 59063993, 6425557, 13639621, 32810923, ++ 28698389, 12180118, 23177719, 33000357 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 228567918409756, 865093958780220, 358083886450556, ++ 159617889659320, 1360637926292598 ++#else ++ 26572828, 3405927, 35407164, 12890904, 47843196, 5335865, ++ 60615096, 2378491, 4439158, 20275085 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 234147501399755, 2229469128637390, 2175289352258889, ++ 1397401514549353, 1885288963089922 ++#else ++ 44392139, 3489069, 57883598, 33221678, 18875721, 32414337, ++ 14819433, 20822905, 49391106, 28092994 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1111762412951562, 252849572507389, 1048714233823341, ++ 146111095601446, 1237505378776770 ++#else ++ 62052362, 16566550, 15953661, 3767752, 56672365, 15627059, ++ 66287910, 2177224, 8550082, 18440267 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1113790697840279, 1051167139966244, 1045930658550944, ++ 2011366241542643, 1686166824620755 ++#else ++ 48635543, 16596774, 66727204, 15663610, 22860960, 15585581, ++ 39264755, 29971692, 43848403, 25125843 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1054097349305049, 1872495070333352, 182121071220717, ++ 1064378906787311, 100273572924182 ++#else ++ 34628313, 15707274, 58902952, 27902350, 29464557, 2713815, ++ 44383727, 15860481, 45206294, 1494192 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1306410853171605, 1627717417672447, 50983221088417, ++ 1109249951172250, 870201789081392 ++#else ++ 47546773, 19467038, 41524991, 24254879, 13127841, 759709, ++ 21923482, 16529112, 8742704, 12967017 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 104233794644221, 1548919791188248, 2224541913267306, ++ 2054909377116478, 1043803389015153 ++#else ++ 38643965, 1553204, 32536856, 23080703, 42417258, 33148257, ++ 58194238, 30620535, 37205105, 15553882 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 216762189468802, 707284285441622, 190678557969733, ++ 973969342604308, 1403009538434867 ++#else ++ 21877890, 3230008, 9881174, 10539357, 62311749, 2841331, ++ 11543572, 14513274, 19375923, 20906471 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1279024291038477, 344776835218310, 273722096017199, ++ 1834200436811442, 634517197663804 ++#else ++ 8832269, 19058947, 13253510, 5137575, 5037871, 4078777, ++ 24880818, 27331716, 2862652, 9455043 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 343805853118335, 1302216857414201, 566872543223541, ++ 2051138939539004, 321428858384280 ++#else ++ 29306751, 5123106, 20245049, 19404543, 9592565, 8447059, ++ 65031740, 30564351, 15511448, 4789663 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 470067171324852, 1618629234173951, 2000092177515639, ++ 7307679772789, 1117521120249968 ++#else ++ 46429108, 7004546, 8824831, 24119455, 63063159, 29803695, ++ 61354101, 108892, 23513200, 16652362 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 278151578291475, 1810282338562947, 1771599529530998, ++ 1383659409671631, 685373414471841 ++#else ++ 33852691, 4144781, 62632835, 26975308, 10770038, 26398890, ++ 60458447, 20618131, 48789665, 10212859 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 577009397403102, 1791440261786291, 2177643735971638, ++ 174546149911960, 1412505077782326 ++#else ++ 2756062, 8598110, 7383731, 26694540, 22312758, 32449420, ++ 21179800, 2600940, 57120566, 21047965 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 893719721537457, 1201282458018197, 1522349501711173, ++ 58011597740583, 1130406465887139 ++#else ++ 42463153, 13317461, 36659605, 17900503, 21365573, 22684775, ++ 11344423, 864440, 64609187, 16844368 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 412607348255453, 1280455764199780, 2233277987330768, ++ 14180080401665, 331584698417165 ++#else ++ 40676061, 6148328, 49924452, 19080277, 18782928, 33278435, ++ 44547329, 211299, 2719757, 4940997 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 262483770854550, 990511055108216, 526885552771698, ++ 571664396646158, 354086190278723 ++#else ++ 65784982, 3911312, 60160120, 14759764, 37081714, 7851206, ++ 21690126, 8518463, 26699843, 5276295 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1820352417585487, 24495617171480, 1547899057533253, ++ 10041836186225, 480457105094042 ++#else ++ 53958991, 27125364, 9396248, 365013, 24703301, 23065493, ++ 1321585, 149635, 51656090, 7159368 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2023310314989233, 637905337525881, 2106474638900687, ++ 557820711084072, 1687858215057826 ++#else ++ 9987761, 30149673, 17507961, 9505530, 9731535, 31388918, ++ 22356008, 8312176, 22477218, 25151047 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1144168702609745, 604444390410187, 1544541121756138, ++ 1925315550126027, 626401428894002 ++#else ++ 18155857, 17049442, 19744715, 9006923, 15154154, 23015456, ++ 24256459, 28689437, 44560690, 9334108 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1922168257351784, 2018674099908659, 1776454117494445, ++ 956539191509034, 36031129147635 ++#else ++ 2986088, 28642539, 10776627, 30080588, 10620589, 26471229, ++ 45695018, 14253544, 44521715, 536905 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 544644538748041, 1039872944430374, 876750409130610, ++ 710657711326551, 1216952687484972 ++#else ++ 4377737, 8115836, 24567078, 15495314, 11625074, 13064599, ++ 7390551, 10589625, 10838060, 18134008 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 58242421545916, 2035812695641843, 2118491866122923, ++ 1191684463816273, 46921517454099 ++#else ++ 47766460, 867879, 9277171, 30335973, 52677291, 31567988, ++ 19295825, 17757482, 6378259, 699185 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 272268252444639, 1374166457774292, 2230115177009552, ++ 1053149803909880, 1354288411641016 ++#else ++ 7895007, 4057113, 60027092, 20476675, 49222032, 33231305, ++ 66392824, 15693154, 62063800, 20180469 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1857910905368338, 1754729879288912, 885945464109877, ++ 1516096106802166, 1602902393369811 ++#else ++ 59371282, 27685029, 52542544, 26147512, 11385653, 13201616, ++ 31730678, 22591592, 63190227, 23885106 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1193437069800958, 901107149704790, 999672920611411, ++ 477584824802207, 364239578697845 ++#else ++ 10188286, 17783598, 59772502, 13427542, 22223443, 14896287, ++ 30743455, 7116568, 45322357, 5427592 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 886299989548838, 1538292895758047, 1590564179491896, ++ 1944527126709657, 837344427345298 ++#else ++ 696102, 13206899, 27047647, 22922350, 15285304, 23701253, ++ 10798489, 28975712, 19236242, 12477404 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 754558365378305, 1712186480903618, 1703656826337531, ++ 750310918489786, 518996040250900 ++#else ++ 55879425, 11243795, 50054594, 25513566, 66320635, 25386464, ++ 63211194, 11180503, 43939348, 7733643 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1309847803895382, 1462151862813074, 211370866671570, ++ 1544595152703681, 1027691798954090 ++#else ++ 17800790, 19518253, 40108434, 21787760, 23887826, 3149671, ++ 23466177, 23016261, 10322026, 15313801 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 803217563745370, 1884799722343599, 1357706345069218, ++ 2244955901722095, 730869460037413 ++#else ++ 26246234, 11968874, 32263343, 28085704, 6830754, 20231401, ++ 51314159, 33452449, 42659621, 10890803 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 689299471295966, 1831210565161071, 1375187341585438, ++ 1106284977546171, 1893781834054269 ++#else ++ 35743198, 10271362, 54448239, 27287163, 16690206, 20491888, ++ 52126651, 16484930, 25180797, 28219548 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 696351368613042, 1494385251239250, 738037133616932, ++ 636385507851544, 927483222611406 ++#else ++ 66522290, 10376443, 34522450, 22268075, 19801892, 10997610, ++ 2276632, 9482883, 316878, 13820577 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1949114198209333, 1104419699537997, 783495707664463, ++ 1747473107602770, 2002634765788641 ++#else ++ 57226037, 29044064, 64993357, 16457135, 56008783, 11674995, ++ 30756178, 26039378, 30696929, 29841583 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1607325776830197, 530883941415333, 1451089452727895, ++ 1581691157083423, 496100432831154 ++#else ++ 32988917, 23951020, 12499365, 7910787, 56491607, 21622917, ++ 59766047, 23569034, 34759346, 7392472 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1068900648804224, 2006891997072550, 1134049269345549, ++ 1638760646180091, 2055396084625778 ++#else ++ 58253184, 15927860, 9866406, 29905021, 64711949, 16898650, ++ 36699387, 24419436, 25112946, 30627788 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2222475519314561, 1870703901472013, 1884051508440561, ++ 1344072275216753, 1318025677799069 ++#else ++ 64604801, 33117465, 25621773, 27875660, 15085041, 28074555, ++ 42223985, 20028237, 5537437, 19640113 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 155711679280656, 681100400509288, 389811735211209, ++ 2135723811340709, 408733211204125 ++#else ++ 55883280, 2320284, 57524584, 10149186, 33664201, 5808647, ++ 52232613, 31824764, 31234589, 6090599 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 7813206966729, 194444201427550, 2071405409526507, ++ 1065605076176312, 1645486789731291 ++#else ++ 57475529, 116425, 26083934, 2897444, 60744427, 30866345, 609720, ++ 15878753, 60138459, 24519663 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 16625790644959, 1647648827778410, 1579910185572704, ++ 436452271048548, 121070048451050 ++#else ++ 39351007, 247743, 51914090, 24551880, 23288160, 23542496, ++ 43239268, 6503645, 20650474, 1804084 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1037263028552531, 568385780377829, 297953104144430, ++ 1558584511931211, 2238221839292471 ++#else ++ 39519059, 15456423, 8972517, 8469608, 15640622, 4439847, ++ 3121995, 23224719, 27842615, 33352104 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 190565267697443, 672855706028058, 338796554369226, ++ 337687268493904, 853246848691734 ++#else ++ 51801891, 2839643, 22530074, 10026331, 4602058, 5048462, ++ 28248656, 5031932, 55733782, 12714368 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1763863028400139, 766498079432444, 1321118624818005, ++ 69494294452268, 858786744165651 ++#else ++ 20807691, 26283607, 29286140, 11421711, 39232341, 19686201, ++ 45881388, 1035545, 47375635, 12796919 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1292056768563024, 1456632109855638, 1100631247050184, ++ 1386133165675321, 1232898350193752 ++#else ++ 12076880, 19253146, 58323862, 21705509, 42096072, 16400683, ++ 49517369, 20654993, 3480664, 18371617 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 366253102478259, 525676242508811, 1449610995265438, ++ 1183300845322183, 185960306491545 ++#else ++ 34747315, 5457596, 28548107, 7833186, 7303070, 21600887, ++ 42745799, 17632556, 33734809, 2771024 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 28315355815982, 460422265558930, 1799675876678724, ++ 1969256312504498, 1051823843138725 ++#else ++ 45719598, 421931, 26597266, 6860826, 22486084, 26817260, ++ 49971378, 29344205, 42556581, 15673396 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 156914999361983, 1606148405719949, 1665208410108430, ++ 317643278692271, 1383783705665320 ++#else ++ 46924223, 2338215, 19788685, 23933476, 63107598, 24813538, ++ 46837679, 4733253, 3727144, 20619984 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 54684536365732, 2210010038536222, 1194984798155308, ++ 535239027773705, 1516355079301361 ++#else ++ 6120100, 814863, 55314462, 32931715, 6812204, 17806661, 2019593, ++ 7975683, 31123697, 22595451 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1484387703771650, 198537510937949, 2186282186359116, ++ 617687444857508, 647477376402122 ++#else ++ 30069250, 22119100, 30434653, 2958439, 18399564, 32578143, ++ 12296868, 9204260, 50676426, 9648164 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2147715541830533, 500032538445817, 646380016884826, ++ 352227855331122, 1488268620408052 ++#else ++ 32705413, 32003455, 30705657, 7451065, 55303258, 9631812, ++ 3305266, 5248604, 41100532, 22176930 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 159386186465542, 1877626593362941, 618737197060512, ++ 1026674284330807, 1158121760792685 ++#else ++ 17219846, 2375039, 35537917, 27978816, 47649184, 9219902, ++ 294711, 15298639, 2662509, 17257359 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1744544377739822, 1964054180355661, 1685781755873170, ++ 2169740670377448, 1286112621104591 ++#else ++ 65935918, 25995736, 62742093, 29266687, 45762450, 25120105, ++ 32087528, 32331655, 32247247, 19164571 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 81977249784993, 1667943117713086, 1668983819634866, ++ 1605016835177615, 1353960708075544 ++#else ++ 14312609, 1221556, 17395390, 24854289, 62163122, 24869796, ++ 38911119, 23916614, 51081240, 20175586 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1602253788689063, 439542044889886, 2220348297664483, ++ 657877410752869, 157451572512238 ++#else ++ 65680039, 23875441, 57873182, 6549686, 59725795, 33085767, ++ 23046501, 9803137, 17597934, 2346211 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1029287186166717, 65860128430192, 525298368814832, ++ 1491902500801986, 1461064796385400 ++#else ++ 18510781, 15337574, 26171504, 981392, 44867312, 7827555, ++ 43617730, 22231079, 3059832, 21771562 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 408216988729246, 2121095722306989, 913562102267595, ++ 1879708920318308, 241061448436731 ++#else ++ 10141598, 6082907, 17829293, 31606789, 9830091, 13613136, ++ 41552228, 28009845, 33606651, 3592095 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1185483484383269, 1356339572588553, 584932367316448, ++ 102132779946470, 1792922621116791 ++#else ++ 33114149, 17665080, 40583177, 20211034, 33076704, 8716171, ++ 1151462, 1521897, 66126199, 26716628 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1966196870701923, 2230044620318636, 1425982460745905, ++ 261167817826569, 46517743394330 ++#else ++ 34169699, 29298616, 23947180, 33230254, 34035889, 21248794, ++ 50471177, 3891703, 26353178, 693168 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 107077591595359, 884959942172345, 27306869797400, ++ 2224911448949390, 964352058245223 ++#else ++ 30374239, 1595580, 50224825, 13186930, 4600344, 406904, 9585294, ++ 33153764, 31375463, 14369965 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1730194207717538, 431790042319772, 1831515233279467, ++ 1372080552768581, 1074513929381760 ++#else ++ 52738210, 25781902, 1510300, 6434173, 48324075, 27291703, ++ 32732229, 20445593, 17901440, 16011505 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1450880638731607, 1019861580989005, 1229729455116861, ++ 1174945729836143, 826083146840706 ++#else ++ 18171223, 21619806, 54608461, 15197121, 56070717, 18324396, ++ 47936623, 17508055, 8764034, 12309598 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1899935429242705, 1602068751520477, 940583196550370, ++ 82431069053859, 1540863155745696 ++#else ++ 5975889, 28311244, 47649501, 23872684, 55567586, 14015781, ++ 43443107, 1228318, 17544096, 22960650 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2136688454840028, 2099509000964294, 1690800495246475, ++ 1217643678575476, 828720645084218 ++#else ++ 5811932, 31839139, 3442886, 31285122, 48741515, 25194890, ++ 49064820, 18144304, 61543482, 12348899 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 765548025667841, 462473984016099, 998061409979798, ++ 546353034089527, 2212508972466858 ++#else ++ 35709185, 11407554, 25755363, 6891399, 63851926, 14872273, ++ 42259511, 8141294, 56476330, 32968952 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 46575283771160, 892570971573071, 1281983193144090, ++ 1491520128287375, 75847005908304 ++#else ++ 54433560, 694025, 62032719, 13300343, 14015258, 19103038, ++ 57410191, 22225381, 30944592, 1130208 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1801436127943107, 1734436817907890, 1268728090345068, ++ 167003097070711, 2233597765834956 ++#else ++ 8247747, 26843490, 40546482, 25845122, 52706924, 18905521, ++ 4652151, 2488540, 23550156, 33283200 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1997562060465113, 1048700225534011, 7615603985628, ++ 1855310849546841, 2242557647635213 ++#else ++ 17294297, 29765994, 7026747, 15626851, 22990044, 113481, ++ 2267737, 27646286, 66700045, 33416712 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1161017320376250, 492624580169043, 2169815802355237, ++ 976496781732542, 1770879511019629 ++#else ++ 16091066, 17300506, 18599251, 7340678, 2137637, 32332775, ++ 63744702, 14550935, 3260525, 26388161 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1357044908364776, 729130645262438, 1762469072918979, ++ 1365633616878458, 181282906404941 ++#else ++ 62198760, 20221544, 18550886, 10864893, 50649539, 26262835, ++ 44079994, 20349526, 54360141, 2701325 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1080413443139865, 1155205815510486, 1848782073549786, ++ 622566975152580, 124965574467971 ++#else ++ 58534169, 16099414, 4629974, 17213908, 46322650, 27548999, ++ 57090500, 9276970, 11329923, 1862132 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1184526762066993, 247622751762817, 692129017206356, ++ 820018689412496, 2188697339828085 ++#else ++ 14763057, 17650824, 36190593, 3689866, 3511892, 10313526, ++ 45157776, 12219230, 58070901, 32614131 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2020536369003019, 202261491735136, 1053169669150884, ++ 2056531979272544, 778165514694311 ++#else ++ 8894987, 30108338, 6150752, 3013931, 301220, 15693451, 35127648, ++ 30644714, 51670695, 11595569 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 237404399610207, 1308324858405118, 1229680749538400, ++ 720131409105291, 1958958863624906 ++#else ++ 15214943, 3537601, 40870142, 19495559, 4418656, 18323671, ++ 13947275, 10730794, 53619402, 29190761 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 515583508038846, 17656978857189, 1717918437373989, ++ 1568052070792483, 46975803123923 ++#else ++ 64570558, 7682792, 32759013, 263109, 37124133, 25598979, ++ 44776739, 23365796, 977107, 699994 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 281527309158085, 36970532401524, 866906920877543, ++ 2222282602952734, 1289598729589882 ++#else ++ 54642373, 4195083, 57897332, 550903, 51543527, 12917919, ++ 19118110, 33114591, 36574330, 19216518 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1278207464902042, 494742455008756, 1262082121427081, ++ 1577236621659884, 1888786707293291 ++#else ++ 31788442, 19046775, 4799988, 7372237, 8808585, 18806489, ++ 9408236, 23502657, 12493931, 28145115 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 353042527954210, 1830056151907359, 1111731275799225, ++ 174960955838824, 404312815582675 ++#else ++ 41428258, 5260743, 47873055, 27269961, 63412921, 16566086, ++ 27218280, 2607121, 29375955, 6024730 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2064251142068628, 1666421603389706, 1419271365315441, ++ 468767774902855, 191535130366583 ++#else ++ 842132, 30759739, 62345482, 24831616, 26332017, 21148791, ++ 11831879, 6985184, 57168503, 2854095 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1716987058588002, 1859366439773457, 1767194234188234, ++ 64476199777924, 1117233614485261 ++#else ++ 62261602, 25585100, 2516241, 27706719, 9695690, 26333246, ++ 16512644, 960770, 12121869, 16648078 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 984292135520292, 135138246951259, 2220652137473167, ++ 1722843421165029, 190482558012909 ++#else ++ 51890212, 14667095, 53772635, 2013716, 30598287, 33090295, ++ 35603941, 25672367, 20237805, 2838411 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 298845952651262, 1166086588952562, 1179896526238434, ++ 1347812759398693, 1412945390096208 ++#else ++ 47820798, 4453151, 15298546, 17376044, 22115042, 17581828, ++ 12544293, 20083975, 1068880, 21054527 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1143239552672925, 906436640714209, 2177000572812152, ++ 2075299936108548, 325186347798433 ++#else ++ 57549981, 17035596, 33238497, 13506958, 30505848, 32439836, ++ 58621956, 30924378, 12521377, 4845654 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 721024854374772, 684487861263316, 1373438744094159, ++ 2193186935276995, 1387043709851261 ++#else ++ 38910324, 10744107, 64150484, 10199663, 7759311, 20465832, ++ 3409347, 32681032, 60626557, 20668561 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 418098668140962, 715065997721283, 1471916138376055, ++ 2168570337288357, 937812682637044 ++#else ++ 43547042, 6230155, 46726851, 10655313, 43068279, 21933259, ++ 10477733, 32314216, 63995636, 13974497 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1043584187226485, 2143395746619356, 2209558562919611, ++ 482427979307092, 847556718384018 ++#else ++ 12966261, 15550616, 35069916, 31939085, 21025979, 32924988, ++ 5642324, 7188737, 18895762, 12629579 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1248731221520759, 1465200936117687, 540803492710140, ++ 52978634680892, 261434490176109 ++#else ++ 14741879, 18607545, 22177207, 21833195, 1279740, 8058600, ++ 11758140, 789443, 32195181, 3895677 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1057329623869501, 620334067429122, 461700859268034, ++ 2012481616501857, 297268569108938 ++#else ++ 10758205, 15755439, 62598914, 9243697, 62229442, 6879878, ++ 64904289, 29988312, 58126794, 4429646 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1055352180870759, 1553151421852298, 1510903185371259, ++ 1470458349428097, 1226259419062731 ++#else ++ 64654951, 15725972, 46672522, 23143759, 61304955, 22514211, ++ 59972993, 21911536, 18047435, 18272689 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1492988790301668, 790326625573331, 1190107028409745, ++ 1389394752159193, 1620408196604194 ++#else ++ 41935844, 22247266, 29759955, 11776784, 44846481, 17733976, ++ 10993113, 20703595, 49488162, 24145963 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 47000654413729, 1004754424173864, 1868044813557703, ++ 173236934059409, 588771199737015 ++#else ++ 21987233, 700364, 42603816, 14972007, 59334599, 27836036, ++ 32155025, 2581431, 37149879, 8773374 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 30498470091663, 1082245510489825, 576771653181956, ++ 806509986132686, 1317634017056939 ++#else ++ 41540495, 454462, 53896929, 16126714, 25240068, 8594567, ++ 20656846, 12017935, 59234475, 19634276 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 420308055751555, 1493354863316002, 165206721528088, ++ 1884845694919786, 2065456951573059 ++#else ++ 6028163, 6263078, 36097058, 22252721, 66289944, 2461771, ++ 35267690, 28086389, 65387075, 30777706 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1115636332012334, 1854340990964155, 83792697369514, ++ 1972177451994021, 457455116057587 ++#else ++ 54829870, 16624276, 987579, 27631834, 32908202, 1248608, ++ 7719845, 29387734, 28408819, 6816612 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1698968457310898, 1435137169051090, 1083661677032510, ++ 938363267483709, 340103887207182 ++#else ++ 56750770, 25316602, 19549650, 21385210, 22082622, 16147817, ++ 20613181, 13982702, 56769294, 5067942 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1995325341336574, 911500251774648, 164010755403692, ++ 855378419194762, 1573601397528842 ++#else ++ 36602878, 29732664, 12074680, 13582412, 47230892, 2443950, ++ 47389578, 12746131, 5331210, 23448488 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 241719380661528, 310028521317150, 1215881323380194, ++ 1408214976493624, 2141142156467363 ++#else ++ 30528792, 3601899, 65151774, 4619784, 39747042, 18118043, ++ 24180792, 20984038, 27679907, 31905504 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1315157046163473, 727368447885818, 1363466668108618, ++ 1668921439990361, 1398483384337907 ++#else ++ 9402385, 19597367, 32834042, 10838634, 40528714, 20317236, ++ 26653273, 24868867, 22611443, 20839026 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 75029678299646, 1015388206460473, 1849729037055212, ++ 1939814616452984, 444404230394954 ++#else ++ 22190590, 1118029, 22736441, 15130463, 36648172, 27563110, ++ 19189624, 28905490, 4854858, 6622139 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2053597130993710, 2024431685856332, 2233550957004860, ++ 2012407275509545, 872546993104440 ++#else ++ 58798126, 30600981, 58846284, 30166382, 56707132, 33282502, ++ 13424425, 29987205, 26404408, 13001963 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1217269667678610, 599909351968693, 1390077048548598, ++ 1471879360694802, 739586172317596 ++#else ++ 35867026, 18138731, 64114613, 8939345, 11562230, 20713762, ++ 41044498, 21932711, 51703708, 11020692 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1718318639380794, 1560510726633958, 904462881159922, ++ 1418028351780052, 94404349451937 ++#else ++ 1866042, 25604943, 59210214, 23253421, 12483314, 13477547, ++ 3175636, 21130269, 28761761, 1406734 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2132502667405250, 214379346175414, 1502748313768060, ++ 1960071701057800, 1353971822643138 ++#else ++ 66660290, 31776765, 13018550, 3194501, 57528444, 22392694, ++ 24760584, 29207344, 25577410, 20175752 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 319394212043702, 2127459436033571, 717646691535162, ++ 663366796076914, 318459064945314 ++#else ++ 42818486, 4759344, 66418211, 31701615, 2066746, 10693769, ++ 37513074, 9884935, 57739938, 4745409 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 405989424923593, 1960452633787083, 667349034401665, ++ 1492674260767112, 1451061489880787 ++#else ++ 57967561, 6049713, 47577803, 29213020, 35848065, 9944275, ++ 51646856, 22242579, 10931923, 21622501 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 947085906234007, 323284730494107, 1485778563977200, ++ 728576821512394, 901584347702286 ++#else ++ 50547351, 14112679, 59096219, 4817317, 59068400, 22139825, ++ 44255434, 10856640, 46638094, 13434653 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1575783124125742, 2126210792434375, 1569430791264065, ++ 1402582372904727, 1891780248341114 ++#else ++ 22759470, 23480998, 50342599, 31683009, 13637441, 23386341, ++ 1765143, 20900106, 28445306, 28189722 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 838432205560695, 1997703511451664, 1018791879907867, ++ 1662001808174331, 78328132957753 ++#else ++ 29875063, 12493613, 2795536, 29768102, 1710619, 15181182, ++ 56913147, 24765756, 9074233, 1167180 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 739152638255629, 2074935399403557, 505483666745895, ++ 1611883356514088, 628654635394878 ++#else ++ 40903181, 11014232, 57266213, 30918946, 40200743, 7532293, ++ 48391976, 24018933, 3843902, 9367684 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1822054032121349, 643057948186973, 7306757352712, ++ 577249257962099, 284735863382083 ++#else ++ 56139269, 27150720, 9591133, 9582310, 11349256, 108879, ++ 16235123, 8601684, 66969667, 4242894 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1366558556363930, 1448606567552086, 1478881020944768, ++ 165803179355898, 1115718458123498 ++#else ++ 22092954, 20363309, 65066070, 21585919, 32186752, 22037044, ++ 60534522, 2470659, 39691498, 16625500 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 204146226972102, 1630511199034723, 2215235214174763, ++ 174665910283542, 956127674017216 ++#else ++ 56051142, 3042015, 13770083, 24296510, 584235, 33009577, ++ 59338006, 2602724, 39757248, 14247412 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1562934578796716, 1070893489712745, 11324610642270, ++ 958989751581897, 2172552325473805 ++#else ++ 6314156, 23289540, 34336361, 15957556, 56951134, 168749, ++ 58490057, 14290060, 27108877, 32373552 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1770564423056027, 735523631664565, 1326060113795289, ++ 1509650369341127, 65892421582684 ++#else ++ 58522267, 26383465, 13241781, 10960156, 34117849, 19759835, ++ 33547975, 22495543, 39960412, 981873 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 623682558650637, 1337866509471512, 990313350206649, ++ 1314236615762469, 1164772974270275 ++#else ++ 22833421, 9293594, 34459416, 19935764, 57971897, 14756818, ++ 44180005, 19583651, 56629059, 17356469 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 223256821462517, 723690150104139, 1000261663630601, ++ 933280913953265, 254872671543046 ++#else ++ 59340277, 3326785, 38997067, 10783823, 19178761, 14905060, ++ 22680049, 13906969, 51175174, 3797898 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1969087237026041, 624795725447124, 1335555107635969, ++ 2069986355593023, 1712100149341902 ++#else ++ 21721337, 29341686, 54902740, 9310181, 63226625, 19901321, ++ 23740223, 30845200, 20491982, 25512280 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1236103475266979, 1837885883267218, 1026072585230455, ++ 1025865513954973, 1801964901432134 ++#else ++ 9209251, 18419377, 53852306, 27386633, 66377847, 15289672, ++ 25947805, 15286587, 30997318, 26851369 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1115241013365517, 1712251818829143, 2148864332502771, ++ 2096001471438138, 2235017246626125 ++#else ++ 7392013, 16618386, 23946583, 25514540, 53843699, 32020573, ++ 52911418, 31232855, 17649997, 33304352 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1299268198601632, 2047148477845621, 2165648650132450, ++ 1612539282026145, 514197911628890 ++#else ++ 57807776, 19360604, 30609525, 30504889, 41933794, 32270679, ++ 51867297, 24028707, 64875610, 7662145 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 118352772338543, 1067608711804704, 1434796676193498, ++ 1683240170548391, 230866769907437 ++#else ++ 49550191, 1763593, 33994528, 15908609, 37067994, 21380136, ++ 7335079, 25082233, 63934189, 3440182 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1850689576796636, 1601590730430274, 1139674615958142, ++ 1954384401440257, 76039205311 ++#else ++ 47219164, 27577423, 42997570, 23865561, 10799742, 16982475, ++ 40449, 29122597, 4862399, 1133 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1723387471374172, 997301467038410, 533927635123657, ++ 20928644693965, 1756575222802513 ++#else ++ 34252636, 25680474, 61686474, 14860949, 50789833, 7956141, ++ 7258061, 311861, 36513873, 26175010 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2146711623855116, 503278928021499, 625853062251406, ++ 1109121378393107, 1033853809911861 ++#else ++ 63335436, 31988495, 28985339, 7499440, 24445838, 9325937, ++ 29727763, 16527196, 18278453, 15405622 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 571005965509422, 2005213373292546, 1016697270349626, ++ 56607856974274, 914438579435146 ++#else ++ 62726958, 8508651, 47210498, 29880007, 61124410, 15149969, ++ 53795266, 843522, 45233802, 13626196 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1346698876211176, 2076651707527589, 1084761571110205, ++ 265334478828406, 1068954492309671 ++#else ++ 2281448, 20067377, 56193445, 30944521, 1879357, 16164207, ++ 56324982, 3953791, 13340839, 15928663 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1769967932677654, 1695893319756416, 1151863389675920, ++ 1781042784397689, 400287774418285 ++#else ++ 31727126, 26374577, 48671360, 25270779, 2875792, 17164102, ++ 41838969, 26539605, 43656557, 5964752 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1851867764003121, 403841933237558, 820549523771987, ++ 761292590207581, 1743735048551143 ++#else ++ 4100401, 27594980, 49929526, 6017713, 48403027, 12227140, ++ 40424029, 11344143, 2538215, 25983677 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 410915148140008, 2107072311871739, 1004367461876503, ++ 99684895396761, 1180818713503224 ++#else ++ 57675240, 6123112, 11159803, 31397824, 30016279, 14966241, ++ 46633881, 1485420, 66479608, 17595569 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 285945406881439, 648174397347453, 1098403762631981, ++ 1366547441102991, 1505876883139217 ++#else ++ 40304287, 4260918, 11851389, 9658551, 35091757, 16367491, ++ 46903439, 20363143, 11659921, 22439314 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 672095903120153, 1675918957959872, 636236529315028, ++ 1569297300327696, 2164144194785875 ++#else ++ 26180377, 10015009, 36264640, 24973138, 5418196, 9480663, ++ 2231568, 23384352, 33100371, 32248261 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1902708175321798, 1035343530915438, 1178560808893263, ++ 301095684058146, 1280977479761118 ++#else ++ 15121094, 28352561, 56718958, 15427820, 39598927, 17561924, ++ 21670946, 4486675, 61177054, 19088051 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1615357281742403, 404257611616381, 2160201349780978, ++ 1160947379188955, 1578038619549541 ++#else ++ 16166467, 24070699, 56004733, 6023907, 35182066, 32189508, ++ 2340059, 17299464, 56373093, 23514607 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2013087639791217, 822734930507457, 1785668418619014, ++ 1668650702946164, 389450875221715 ++#else ++ 28042865, 29997343, 54982337, 12259705, 63391366, 26608532, ++ 6766452, 24864833, 18036435, 5803270 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 453918449698368, 106406819929001, 2072540975937135, ++ 308588860670238, 1304394580755385 ++#else ++ 66291264, 6763911, 11803561, 1585585, 10958447, 30883267, ++ 23855390, 4598332, 60949433, 19436993 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1295082798350326, 2091844511495996, 1851348972587817, ++ 3375039684596, 789440738712837 ++#else ++ 36077558, 19298237, 17332028, 31170912, 31312681, 27587249, ++ 696308, 50292, 47013125, 11763583 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2083069137186154, 848523102004566, 993982213589257, ++ 1405313299916317, 1532824818698468 ++#else ++ 66514282, 31040148, 34874710, 12643979, 12650761, 14811489, ++ 665117, 20940800, 47335652, 22840869 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1495961298852430, 1397203457344779, 1774950217066942, ++ 139302743555696, 66603584342787 ++#else ++ 30464590, 22291560, 62981387, 20819953, 19835326, 26448819, ++ 42712688, 2075772, 50088707, 992470 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1782411379088302, 1096724939964781, 27593390721418, ++ 542241850291353, 1540337798439873 ++#else ++ 18357166, 26559999, 7766381, 16342475, 37783946, 411173, ++ 14578841, 8080033, 55534529, 22952821 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 693543956581437, 171507720360750, 1557908942697227, ++ 1074697073443438, 1104093109037196 ++#else ++ 19598397, 10334610, 12555054, 2555664, 18821899, 23214652, ++ 21873262, 16014234, 26224780, 16452269 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 345288228393419, 1099643569747172, 134881908403743, ++ 1740551994106740, 248212179299770 ++#else ++ 36884939, 5145195, 5944548, 16385966, 3976735, 2009897, ++ 55731060, 25936245, 46575034, 3698649 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 231429562203065, 1526290236421172, 2021375064026423, ++ 1520954495658041, 806337791525116 ++#else ++ 14187449, 3448569, 56472628, 22743496, 44444983, 30120835, ++ 7268409, 22663988, 27394300, 12015369 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1079623667189886, 872403650198613, 766894200588288, ++ 2163700860774109, 2023464507911816 ++#else ++ 19695742, 16087646, 28032085, 12999827, 6817792, 11427614, ++ 20244189, 32241655, 53849736, 30151970 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 854645372543796, 1936406001954827, 151460662541253, ++ 825325739271555, 1554306377287556 ++#else ++ 30860084, 12735208, 65220619, 28854697, 50133957, 2256939, ++ 58942851, 12298311, 58558340, 23160969 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1497138821904622, 1044820250515590, 1742593886423484, ++ 1237204112746837, 849047450816987 ++#else ++ 61389038, 22309106, 65198214, 15569034, 26642876, 25966672, ++ 61319509, 18435777, 62132699, 12651792 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 667962773375330, 1897271816877105, 1399712621683474, ++ 1143302161683099, 2081798441209593 ++#else ++ 64260450, 9953420, 11531313, 28271553, 26895122, 20857343, ++ 53990043, 17036529, 9768697, 31021214 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 127147851567005, 1936114012888110, 1704424366552046, ++ 856674880716312, 716603621335359 ++#else ++ 42389405, 1894650, 66821166, 28850346, 15348718, 25397902, ++ 32767512, 12765450, 4940095, 10678226 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1072409664800960, 2146937497077528, 1508780108920651, ++ 935767602384853, 1112800433544068 ++#else ++ 18860224, 15980149, 48121624, 31991861, 40875851, 22482575, ++ 59264981, 13944023, 42736516, 16582018 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 333549023751292, 280219272863308, 2104176666454852, ++ 1036466864875785, 536135186520207 ++#else ++ 51604604, 4970267, 37215820, 4175592, 46115652, 31354675, ++ 55404809, 15444559, 56105103, 7989036 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 373666279883137, 146457241530109, 304116267127857, ++ 416088749147715, 1258577131183391 ++#else ++ 31490433, 5568061, 64696061, 2182382, 34772017, 4531685, ++ 35030595, 6200205, 47422751, 18754260 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1186115062588401, 2251609796968486, 1098944457878953, ++ 1153112761201374, 1791625503417267 ++#else ++ 49800177, 17674491, 35586086, 33551600, 34221481, 16375548, ++ 8680158, 17182719, 28550067, 26697300 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1870078460219737, 2129630962183380, 852283639691142, ++ 292865602592851, 401904317342226 ++#else ++ 38981977, 27866340, 16837844, 31733974, 60258182, 12700015, ++ 37068883, 4364037, 1155602, 5988841 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1361070124828035, 815664541425524, 1026798897364671, ++ 1951790935390647, 555874891834790 ++#else ++ 21890435, 20281525, 54484852, 12154348, 59276991, 15300495, ++ 23148983, 29083951, 24618406, 8283181 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1546301003424277, 459094500062839, 1097668518375311, ++ 1780297770129643, 720763293687608 ++#else ++ 33972757, 23041680, 9975415, 6841041, 35549071, 16356535, ++ 3070187, 26528504, 1466168, 10740210 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1212405311403990, 1536693382542438, 61028431067459, ++ 1863929423417129, 1223219538638038 ++#else ++ 65599446, 18066246, 53605478, 22898515, 32799043, 909394, ++ 53169961, 27774712, 34944214, 18227391 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1294303766540260, 1183557465955093, 882271357233093, ++ 63854569425375, 2213283684565087 ++#else ++ 3960804, 19286629, 39082773, 17636380, 47704005, 13146867, ++ 15567327, 951507, 63848543, 32980496 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 339050984211414, 601386726509773, 413735232134068, ++ 966191255137228, 1839475899458159 ++#else ++ 24740822, 5052253, 37014733, 8961360, 25877428, 6165135, ++ 42740684, 14397371, 59728495, 27410326 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 235605972169408, 2174055643032978, 1538335001838863, ++ 1281866796917192, 1815940222628465 ++#else ++ 38220480, 3510802, 39005586, 32395953, 55870735, 22922977, ++ 51667400, 19101303, 65483377, 27059617 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1632352921721536, 1833328609514701, 2092779091951987, ++ 1923956201873226, 2210068022482919 ++#else ++ 793280, 24323954, 8836301, 27318725, 39747955, 31184838, ++ 33152842, 28669181, 57202663, 32932579 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 35271216625062, 1712350667021807, 983664255668860, ++ 98571260373038, 1232645608559836 ++#else ++ 5666214, 525582, 20782575, 25516013, 42570364, 14657739, ++ 16099374, 1468826, 60937436, 18367850 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1998172393429622, 1798947921427073, 784387737563581, ++ 1589352214827263, 1589861734168180 ++#else ++ 62249590, 29775088, 64191105, 26806412, 7778749, 11688288, ++ 36704511, 23683193, 65549940, 23690785 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1733739258725305, 31715717059538, 201969945218860, ++ 992093044556990, 1194308773174556 ++#else ++ 10896313, 25834728, 824274, 472601, 47648556, 3009586, 25248958, ++ 14783338, 36527388, 17796587 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 846415389605137, 746163495539180, 829658752826080, ++ 592067705956946, 957242537821393 ++#else ++ 10566929, 12612572, 35164652, 11118702, 54475488, 12362878, ++ 21752402, 8822496, 24003793, 14264025 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1758148849754419, 619249044817679, 168089007997045, ++ 1371497636330523, 1867101418880350 ++#else ++ 27713843, 26198459, 56100623, 9227529, 27050101, 2504721, ++ 23886875, 20436907, 13958494, 27821979 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 326633984209635, 261759506071016, 1700682323676193, ++ 1577907266349064, 1217647663383016 ++#else ++ 43627235, 4867225, 39861736, 3900520, 29838369, 25342141, ++ 35219464, 23512650, 7340520, 18144364 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1714182387328607, 1477856482074168, 574895689942184, ++ 2159118410227270, 1555532449716575 ++#else ++ 4646495, 25543308, 44342840, 22021777, 23184552, 8566613, ++ 31366726, 32173371, 52042079, 23179239 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 853828206885131, 998498946036955, 1835887550391235, ++ 207627336608048, 258363815956050 ++#else ++ 49838347, 12723031, 50115803, 14878793, 21619651, 27356856, ++ 27584816, 3093888, 58265170, 3849920 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 141141474651677, 1236728744905256, 643101419899887, ++ 1646615130509173, 1208239602291765 ++#else ++ 58043933, 2103171, 25561640, 18428694, 61869039, 9582957, ++ 32477045, 24536477, 5002293, 18004173 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1501663228068911, 1354879465566912, 1444432675498247, ++ 897812463852601, 855062598754348 ++#else ++ 55051311, 22376525, 21115584, 20189277, 8808711, 21523724, ++ 16489529, 13378448, 41263148, 12741425 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 714380763546606, 1032824444965790, 1774073483745338, ++ 1063840874947367, 1738680636537158 ++#else ++ 61162478, 10645102, 36197278, 15390283, 63821882, 26435754, ++ 24306471, 15852464, 28834118, 25908360 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1640635546696252, 633168953192112, 2212651044092396, ++ 30590958583852, 368515260889378 ++#else ++ 49773116, 24447374, 42577584, 9434952, 58636780, 32971069, ++ 54018092, 455840, 20461858, 5491305 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1171650314802029, 1567085444565577, 1453660792008405, ++ 757914533009261, 1619511342778196 ++#else ++ 13669229, 17458950, 54626889, 23351392, 52539093, 21661233, ++ 42112877, 11293806, 38520660, 24132599 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 420958967093237, 971103481109486, 2169549185607107, ++ 1301191633558497, 1661514101014240 ++#else ++ 28497909, 6272777, 34085870, 14470569, 8906179, 32328802, ++ 18504673, 19389266, 29867744, 24758489 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 907123651818302, 1332556122804146, 1824055253424487, ++ 1367614217442959, 1982558335973172 ++#else ++ 50901822, 13517195, 39309234, 19856633, 24009063, 27180541, ++ 60741263, 20379039, 22853428, 29542421 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1121533090144639, 1021251337022187, 110469995947421, ++ 1511059774758394, 2110035908131662 ++#else ++ 24191359, 16712145, 53177067, 15217830, 14542237, 1646131, ++ 18603514, 22516545, 12876622, 31441985 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 303213233384524, 2061932261128138, 352862124777736, ++ 40828818670255, 249879468482660 ++#else ++ 17902668, 4518229, 66697162, 30725184, 26878216, 5258055, ++ 54248111, 608396, 16031844, 3723494 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 856559257852200, 508517664949010, 1378193767894916, ++ 1723459126947129, 1962275756614521 ++#else ++ 38476072, 12763727, 46662418, 7577503, 33001348, 20536687, ++ 17558841, 25681542, 23896953, 29240187 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1445691340537320, 40614383122127, 402104303144865, ++ 485134269878232, 1659439323587426 ++#else ++ 47103464, 21542479, 31520463, 605201, 2543521, 5991821, ++ 64163800, 7229063, 57189218, 24727572 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 20057458979482, 1183363722525800, 2140003847237215, ++ 2053873950687614, 2112017736174909 ++#else ++ 28816026, 298879, 38943848, 17633493, 19000927, 31888542, ++ 54428030, 30605106, 49057085, 31471516 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2228654250927986, 1483591363415267, 1368661293910956, ++ 1076511285177291, 526650682059608 ++#else ++ 16000882, 33209536, 3493091, 22107234, 37604268, 20394642, ++ 12577739, 16041268, 47393624, 7847706 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 709481497028540, 531682216165724, 316963769431931, ++ 1814315888453765, 258560242424104 ++#else ++ 10151868, 10572098, 27312476, 7922682, 14825339, 4723128, ++ 34252933, 27035413, 57088296, 3852847 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1053447823660455, 1955135194248683, 1010900954918985, ++ 1182614026976701, 1240051576966610 ++#else ++ 55678375, 15697595, 45987307, 29133784, 5386313, 15063598, ++ 16514493, 17622322, 29330898, 18478208 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1957943897155497, 1788667368028035, 137692910029106, ++ 1039519607062, 826404763313028 ++#else ++ 41609129, 29175637, 51885955, 26653220, 16615730, 2051784, ++ 3303702, 15490, 39560068, 12314390 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1848942433095597, 1582009882530495, 1849292741020143, ++ 1068498323302788, 2001402229799484 ++#else ++ 15683501, 27551389, 18109119, 23573784, 15337967, 27556609, ++ 50391428, 15921865, 16103996, 29823217 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1528282417624269, 2142492439828191, 2179662545816034, ++ 362568973150328, 1591374675250271 ++#else ++ 43939021, 22773182, 13588191, 31925625, 63310306, 32479502, ++ 47835256, 5402698, 37293151, 23713330 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 160026679434388, 232341189218716, 2149181472355545, ++ 598041771119831, 183859001910173 ++#else ++ 23190676, 2384583, 34394524, 3462153, 37205209, 32025299, ++ 55842007, 8911516, 41903005, 2739712 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2013278155187349, 662660471354454, 793981225706267, ++ 411706605985744, 804490933124791 ++#else ++ 21374101, 30000182, 33584214, 9874410, 15377179, 11831242, ++ 33578960, 6134906, 4931255, 11987849 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2051892037280204, 488391251096321, 2230187337030708, ++ 930221970662692, 679002758255210 ++#else ++ 67101132, 30575573, 50885377, 7277596, 105524, 33232381, ++ 35628324, 13861387, 37032554, 10117929 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1530723630438670, 875873929577927, 341560134269988, ++ 449903119530753, 1055551308214179 ++#else ++ 37607694, 22809559, 40945095, 13051538, 41483300, 5089642, ++ 60783361, 6704078, 12890019, 15728940 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1461835919309432, 1955256480136428, 180866187813063, ++ 1551979252664528, 557743861963950 ++#else ++ 45136504, 21783052, 66157804, 29135591, 14704839, 2695116, ++ 903376, 23126293, 12885166, 8311031 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 359179641731115, 1324915145732949, 902828372691474, ++ 294254275669987, 1887036027752957 ++#else ++ 49592363, 5352193, 10384213, 19742774, 7506450, 13453191, ++ 26423267, 4384730, 1888765, 28119028 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2043271609454323, 2038225437857464, 1317528426475850, ++ 1398989128982787, 2027639881006861 ++#else ++ 41291507, 30447119, 53614264, 30371925, 30896458, 19632703, ++ 34857219, 20846562, 47644429, 30214188 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2072902725256516, 312132452743412, 309930885642209, ++ 996244312618453, 1590501300352303 ++#else ++ 43500868, 30888657, 66582772, 4651135, 5765089, 4618330, ++ 6092245, 14845197, 17151279, 23700316 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1397254305160710, 695734355138021, 2233992044438756, ++ 1776180593969996, 1085588199351115 ++#else ++ 42278406, 20820711, 51942885, 10367249, 37577956, 33289075, ++ 22825804, 26467153, 50242379, 16176524 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 440567051331029, 254894786356681, 493869224930222, ++ 1556322069683366, 1567456540319218 ++#else ++ 43525589, 6564960, 20063689, 3798228, 62368686, 7359224, ++ 2006182, 23191006, 38362610, 23356922 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1950722461391320, 1907845598854797, 1822757481635527, ++ 2121567704750244, 73811931471221 ++#else ++ 56482264, 29068029, 53788301, 28429114, 3432135, 27161203, ++ 23632036, 31613822, 32808309, 1099883 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 387139307395758, 2058036430315676, 1220915649965325, ++ 1794832055328951, 1230009312169328 ++#else ++ 15030958, 5768825, 39657628, 30667132, 60681485, 18193060, ++ 51830967, 26745081, 2051440, 18328567 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1765973779329517, 659344059446977, 19821901606666, ++ 1301928341311214, 1116266004075885 ++#else ++ 63746541, 26315059, 7517889, 9824992, 23555850, 295369, 5148398, ++ 19400244, 44422509, 16633659 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1127572801181483, 1224743760571696, 1276219889847274, ++ 1529738721702581, 1589819666871853 ++#else ++ 4577067, 16802144, 13249840, 18250104, 19958762, 19017158, ++ 18559669, 22794883, 8402477, 23690159 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2181229378964934, 2190885205260020, 1511536077659137, ++ 1246504208580490, 668883326494241 ++#else ++ 38702534, 32502850, 40318708, 32646733, 49896449, 22523642, ++ 9453450, 18574360, 17983009, 9967138 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 437866655573314, 669026411194768, 81896997980338, ++ 523874406393178, 245052060935236 ++#else ++ 41346370, 6524721, 26585488, 9969270, 24709298, 1220360, ++ 65430874, 7806336, 17507396, 3651560 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1975438052228868, 1071801519999806, 594652299224319, ++ 1877697652668809, 1489635366987285 ++#else ++ 56688388, 29436320, 14584638, 15971087, 51340543, 8861009, ++ 26556809, 27979875, 48555541, 22197296 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 958592545673770, 233048016518599, 851568750216589, ++ 567703851596087, 1740300006094761 ++#else ++ 2839082, 14284142, 4029895, 3472686, 14402957, 12689363, ++ 40466743, 8459446, 61503401, 25932490 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2014540178270324, 192672779514432, 213877182641530, ++ 2194819933853411, 1716422829364835 ++#else ++ 62269556, 30018987, 9744960, 2871048, 25113978, 3187018, ++ 41998051, 32705365, 17258083, 25576693 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1540769606609725, 2148289943846077, 1597804156127445, ++ 1230603716683868, 815423458809453 ++#else ++ 18164541, 22959256, 49953981, 32012014, 19237077, 23809137, ++ 23357532, 18337424, 26908269, 12150756 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1738560251245018, 1779576754536888, 1783765347671392, ++ 1880170990446751, 1088225159617541 ++#else ++ 36843994, 25906566, 5112248, 26517760, 65609056, 26580174, ++ 43167, 28016731, 34806789, 16215818 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 659303913929492, 1956447718227573, 1830568515922666, ++ 841069049744408, 1669607124206368 ++#else ++ 60209940, 9824393, 54804085, 29153342, 35711722, 27277596, ++ 32574488, 12532905, 59605792, 24879084 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1143465490433355, 1532194726196059, 1093276745494697, ++ 481041706116088, 2121405433561163 ++#else ++ 39765323, 17038963, 39957339, 22831480, 946345, 16291093, ++ 254968, 7168080, 21676107, 31611404 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1686424298744462, 1451806974487153, 266296068846582, ++ 1834686947542675, 1720762336132256 ++#else ++ 21260942, 25129680, 50276977, 21633609, 43430902, 3968120, ++ 63456915, 27338965, 63552672, 25641356 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 889217026388959, 1043290623284660, 856125087551909, ++ 1669272323124636, 1603340330827879 ++#else ++ 16544735, 13250366, 50304436, 15546241, 62525861, 12757257, ++ 64646556, 24874095, 48201831, 23891632 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1206396181488998, 333158148435054, 1402633492821422, ++ 1120091191722026, 1945474114550509 ++#else ++ 64693606, 17976703, 18312302, 4964443, 51836334, 20900867, ++ 26820650, 16690659, 25459437, 28989823 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 766720088232571, 1512222781191002, 1189719893490790, ++ 2091302129467914, 2141418006894941 ++#else ++ 41964155, 11425019, 28423002, 22533875, 60963942, 17728207, ++ 9142794, 31162830, 60676445, 31909614 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 419663647306612, 1998875112167987, 1426599870253707, ++ 1154928355379510, 486538532138187 ++#else ++ 44004212, 6253475, 16964147, 29785560, 41994891, 21257994, ++ 39651638, 17209773, 6335691, 7249989 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 938160078005954, 1421776319053174, 1941643234741774, ++ 180002183320818, 1414380336750546 ++#else ++ 36775618, 13979674, 7503222, 21186118, 55152142, 28932738, ++ 36836594, 2682241, 25993170, 21075909 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 398001940109652, 1577721237663248, 1012748649830402, ++ 1540516006905144, 1011684812884559 ++#else ++ 4364628, 5930691, 32304656, 23509878, 59054082, 15091130, ++ 22857016, 22955477, 31820367, 15075278 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1653276489969630, 6081825167624, 1921777941170836, ++ 1604139841794531, 861211053640641 ++#else ++ 31879134, 24635739, 17258760, 90626, 59067028, 28636722, ++ 24162787, 23903546, 49138625, 12833044 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 996661541407379, 1455877387952927, 744312806857277, ++ 139213896196746, 1000282908547789 ++#else ++ 19073683, 14851414, 42705695, 21694263, 7625277, 11091125, ++ 47489674, 2074448, 57694925, 14905376 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1450817495603008, 1476865707053229, 1030490562252053, ++ 620966950353376, 1744760161539058 ++#else ++ 24483648, 21618865, 64589997, 22007013, 65555733, 15355505, ++ 41826784, 9253128, 27628530, 25998952 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 559728410002599, 37056661641185, 2038622963352006, ++ 1637244893271723, 1026565352238948 ++#else ++ 17597607, 8340603, 19355617, 552187, 26198470, 30377849, ++ 4593323, 24396850, 52997988, 15297015 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 962165956135846, 1116599660248791, 182090178006815, ++ 1455605467021751, 196053588803284 ++#else ++ 510886, 14337390, 35323607, 16638631, 6328095, 2713355, ++ 46891447, 21690211, 8683220, 2921426 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 796863823080135, 1897365583584155, 420466939481601, ++ 2165972651724672, 932177357788289 ++#else ++ 18606791, 11874196, 27155355, 28272950, 43077121, 6265445, ++ 41930624, 32275507, 4674689, 13890525 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 877047233620632, 1375632631944375, 643773611882121, ++ 660022738847877, 19353932331831 ++#else ++ 13609624, 13069022, 39736503, 20498523, 24360585, 9592974, ++ 14977157, 9835105, 4389687, 288396 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2216943882299338, 394841323190322, 2222656898319671, ++ 558186553950529, 1077236877025190 ++#else ++ 9922506, 33035038, 13613106, 5883594, 48350519, 33120168, ++ 54804801, 8317627, 23388070, 16052080 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 801118384953213, 1914330175515892, 574541023311511, ++ 1471123787903705, 1526158900256288 ++#else ++ 12719997, 11937594, 35138804, 28525742, 26900119, 8561328, ++ 46953177, 21921452, 52354592, 22741539 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 949617889087234, 2207116611267331, 912920039141287, ++ 501158539198789, 62362560771472 ++#else ++ 15961858, 14150409, 26716931, 32888600, 44314535, 13603568, ++ 11829573, 7467844, 38286736, 929274 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1474518386765335, 1760793622169197, 1157399790472736, ++ 1622864308058898, 165428294422792 ++#else ++ 11038231, 21972036, 39798381, 26237869, 56610336, 17246600, ++ 43629330, 24182562, 45715720, 2465073 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1961673048027128, 102619413083113, 1051982726768458, ++ 1603657989805485, 1941613251499678 ++#else ++ 20017144, 29231206, 27915241, 1529148, 12396362, 15675764, ++ 13817261, 23896366, 2463390, 28932292 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1401939116319266, 335306339903072, 72046196085786, ++ 862423201496006, 850518754531384 ++#else ++ 50749986, 20890520, 55043680, 4996453, 65852442, 1073571, ++ 9583558, 12851107, 4003896, 12673717 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1234706593321979, 1083343891215917, 898273974314935, ++ 1640859118399498, 157578398571149 ++#else ++ 65377275, 18398561, 63845933, 16143081, 19294135, 13385325, ++ 14741514, 24450706, 7903885, 2348101 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1143483057726416, 1992614991758919, 674268662140796, ++ 1773370048077526, 674318359920189 ++#else ++ 24536016, 17039225, 12715591, 29692277, 1511292, 10047386, ++ 63266518, 26425272, 38731325, 10048126 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1835401379538542, 173900035308392, 818247630716732, ++ 1762100412152786, 1021506399448291 ++#else ++ 54486638, 27349611, 30718824, 2591312, 56491836, 12192839, ++ 18873298, 26257342, 34811107, 15221631 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1506632088156630, 2127481795522179, 513812919490255, ++ 140643715928370, 442476620300318 ++#else ++ 40630742, 22450567, 11546243, 31701949, 9180879, 7656409, ++ 45764914, 2095754, 29769758, 6593415 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2056683376856736, 219094741662735, 2193541883188309, ++ 1841182310235800, 556477468664293 ++#else ++ 35114656, 30646970, 4176911, 3264766, 12538965, 32686321, ++ 26312344, 27435754, 30958053, 8292160 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1315019427910827, 1049075855992603, 2066573052986543, ++ 266904467185534, 2040482348591520 ++#else ++ 31429803, 19595316, 29173531, 15632448, 12174511, 30794338, ++ 32808830, 3977186, 26143136, 30405556 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 94096246544434, 922482381166992, 24517828745563, ++ 2139430508542503, 2097139044231004 ++#else ++ 22648882, 1402143, 44308880, 13746058, 7936347, 365344, ++ 58440231, 31879998, 63350620, 31249806 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 537697207950515, 1399352016347350, 1563663552106345, ++ 2148749520888918, 549922092988516 ++#else ++ 51616947, 8012312, 64594134, 20851969, 43143017, 23300402, ++ 65496150, 32018862, 50444388, 8194477 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1747985413252434, 680511052635695, 1809559829982725, ++ 594274250930054, 201673170745982 ++#else ++ 27338066, 26047012, 59694639, 10140404, 48082437, 26964542, ++ 27277190, 8855376, 28572286, 3005164 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 323583936109569, 1973572998577657, 1192219029966558, ++ 79354804385273, 1374043025560347 ++#else ++ 26287105, 4821776, 25476601, 29408529, 63344350, 17765447, ++ 49100281, 1182478, 41014043, 20474836 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 213277331329947, 416202017849623, 1950535221091783, ++ 1313441578103244, 2171386783823658 ++#else ++ 59937691, 3178079, 23970071, 6201893, 49913287, 29065239, ++ 45232588, 19571804, 32208682, 32356184 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 189088804229831, 993969372859110, 895870121536987, ++ 1547301535298256, 1477373024911350 ++#else ++ 50451143, 2817642, 56822502, 14811297, 6024667, 13349505, ++ 39793360, 23056589, 39436278, 22014573 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1620578418245010, 541035331188469, 2235785724453865, ++ 2154865809088198, 1974627268751826 ++#else ++ 15941010, 24148500, 45741813, 8062054, 31876073, 33315803, ++ 51830470, 32110002, 15397330, 29424239 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1346805451740245, 1350981335690626, 942744349501813, ++ 2155094562545502, 1012483751693409 ++#else ++ 8934485, 20068965, 43822466, 20131190, 34662773, 14047985, ++ 31170398, 32113411, 39603297, 15087183 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2107080134091762, 1132567062788208, 1824935377687210, ++ 769194804343737, 1857941799971888 ++#else ++ 48751602, 31397940, 24524912, 16876564, 15520426, 27193656, ++ 51606457, 11461895, 16788528, 27685490 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1074666112436467, 249279386739593, 1174337926625354, ++ 1559013532006480, 1472287775519121 ++#else ++ 65161459, 16013772, 21750665, 3714552, 49707082, 17498998, ++ 63338576, 23231111, 31322513, 21938797 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1872620123779532, 1892932666768992, 1921559078394978, ++ 1270573311796160, 1438913646755037 ++#else ++ 21426636, 27904214, 53460576, 28206894, 38296674, 28633461, ++ 48833472, 18933017, 13040861, 21441484 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 837390187648199, 1012253300223599, 989780015893987, ++ 1351393287739814, 328627746545550 ++#else ++ 11293895, 12478086, 39972463, 15083749, 37801443, 14748871, ++ 14555558, 20137329, 1613710, 4896935 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1028328827183114, 1711043289969857, 1350832470374933, ++ 1923164689604327, 1495656368846911 ++#else ++ 41213962, 15323293, 58619073, 25496531, 25967125, 20128972, ++ 2825959, 28657387, 43137087, 22287016 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1900828492104143, 430212361082163, 687437570852799, ++ 832514536673512, 1685641495940794 ++#else ++ 51184079, 28324551, 49665331, 6410663, 3622847, 10243618, ++ 20615400, 12405433, 43355834, 25118015 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 842632847936398, 605670026766216, 290836444839585, ++ 163210774892356, 2213815011799645 ++#else ++ 60017550, 12556207, 46917512, 9025186, 50036385, 4333800, ++ 4378436, 2432030, 23097949, 32988414 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1176336383453996, 1725477294339771, 12700622672454, ++ 678015708818208, 162724078519879 ++#else ++ 4565804, 17528778, 20084411, 25711615, 1724998, 189254, ++ 24767264, 10103221, 48596551, 2424777 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1448049969043497, 1789411762943521, 385587766217753, ++ 90201620913498, 832999441066823 ++#else ++ 366633, 21577626, 8173089, 26664313, 30788633, 5745705, ++ 59940186, 1344108, 63466311, 12412658 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 516086333293313, 2240508292484616, 1351669528166508, ++ 1223255565316488, 750235824427138 ++#else ++ 43107073, 7690285, 14929416, 33386175, 34898028, 20141445, ++ 24162696, 18227928, 63967362, 11179384 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1263624896582495, 1102602401673328, 526302183714372, ++ 2152015839128799, 1483839308490010 ++#else ++ 18289503, 18829478, 8056944, 16430056, 45379140, 7842513, ++ 61107423, 32067534, 48424218, 22110928 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 442991718646863, 1599275157036458, 1925389027579192, ++ 899514691371390, 350263251085160 ++#else ++ 476239, 6601091, 60956074, 23831056, 17503544, 28690532, ++ 27672958, 13403813, 11052904, 5219329 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1689713572022143, 593854559254373, 978095044791970, ++ 1985127338729499, 1676069120347625 ++#else ++ 20678527, 25178694, 34436965, 8849122, 62099106, 14574751, ++ 31186971, 29580702, 9014761, 24975376 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1557207018622683, 340631692799603, 1477725909476187, ++ 614735951619419, 2033237123746766 ++#else ++ 53464795, 23204192, 51146355, 5075807, 65594203, 22019831, ++ 34006363, 9160279, 8473550, 30297594 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 968764929340557, 1225534776710944, 662967304013036, ++ 1155521416178595, 791142883466590 ++#else ++ 24900749, 14435722, 17209120, 18261891, 44516588, 9878982, ++ 59419555, 17218610, 42540382, 11788947 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1487081286167458, 993039441814934, 1792378982844640, ++ 698652444999874, 2153908693179754 ++#else ++ 63990690, 22159237, 53306774, 14797440, 9652448, 26708528, ++ 47071426, 10410732, 42540394, 32095740 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1123181311102823, 685575944875442, 507605465509927, ++ 1412590462117473, 568017325228626 ++#else ++ 51449703, 16736705, 44641714, 10215877, 58011687, 7563910, ++ 11871841, 21049238, 48595538, 8464117 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 560258797465417, 2193971151466401, 1824086900849026, ++ 579056363542056, 1690063960036441 ++#else ++ 43708233, 8348506, 52522913, 32692717, 63158658, 27181012, ++ 14325288, 8628612, 33313881, 25183915 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1918407319222416, 353767553059963, 1930426334528099, ++ 1564816146005724, 1861342381708096 ++#else ++ 46921872, 28586496, 22367355, 5271547, 66011747, 28765593, ++ 42303196, 23317577, 58168128, 27736162 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2131325168777276, 1176636658428908, 1756922641512981, ++ 1390243617176012, 1966325177038383 ++#else ++ 60160060, 31759219, 34483180, 17533252, 32635413, 26180187, ++ 15989196, 20716244, 28358191, 29300528 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2063958120364491, 2140267332393533, 699896251574968, ++ 273268351312140, 375580724713232 ++#else ++ 43547083, 30755372, 34757181, 31892468, 57961144, 10429266, ++ 50471180, 4072015, 61757200, 5596588 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2024297515263178, 416959329722687, 1079014235017302, ++ 171612225573183, 1031677520051053 ++#else ++ 38872266, 30164383, 12312895, 6213178, 3117142, 16078565, ++ 29266239, 2557221, 1768301, 15373193 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2033900009388450, 1744902869870788, 2190580087917640, ++ 1949474984254121, 231049754293748 ++#else ++ 59865506, 30307471, 62515396, 26001078, 66980936, 32642186, ++ 66017961, 29049440, 42448372, 3442909 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 343868674606581, 550155864008088, 1450580864229630, ++ 481603765195050, 896972360018042 ++#else ++ 36898293, 5124042, 14181784, 8197961, 18964734, 21615339, ++ 22597930, 7176455, 48523386, 13365929 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2151139328380127, 314745882084928, 59756825775204, ++ 1676664391494651, 2048348075599360 ++#else ++ 59231455, 32054473, 8324672, 4690079, 6261860, 890446, 24538107, ++ 24984246, 57419264, 30522764 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1528930066340597, 1605003907059576, 1055061081337675, ++ 1458319101947665, 1234195845213142 ++#else ++ 25008885, 22782833, 62803832, 23916421, 16265035, 15721635, ++ 683793, 21730648, 15723478, 18390951 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 830430507734812, 1780282976102377, 1425386760709037, ++ 362399353095425, 2168861579799910 ++#else ++ 57448220, 12374378, 40101865, 26528283, 59384749, 21239917, ++ 11879681, 5400171, 519526, 32318556 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1155762232730333, 980662895504006, 2053766700883521, ++ 490966214077606, 510405877041357 ++#else ++ 22258397, 17222199, 59239046, 14613015, 44588609, 30603508, ++ 46754982, 7315966, 16648397, 7605640 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1683750316716132, 652278688286128, 1221798761193539, ++ 1897360681476669, 319658166027343 ++#else ++ 59027556, 25089834, 58885552, 9719709, 19259459, 18206220, ++ 23994941, 28272877, 57640015, 4763277 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 618808732869972, 72755186759744, 2060379135624181, ++ 1730731526741822, 48862757828238 ++#else ++ 45409620, 9220968, 51378240, 1084136, 41632757, 30702041, ++ 31088446, 25789909, 55752334, 728111 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1463171970593505, 1143040711767452, 614590986558883, ++ 1409210575145591, 1882816996436803 ++#else ++ 26047201, 21802961, 60208540, 17032633, 24092067, 9158119, ++ 62835319, 20998873, 37743427, 28056159 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2230133264691131, 563950955091024, 2042915975426398, ++ 827314356293472, 672028980152815 ++#else ++ 17510331, 33231575, 5854288, 8403524, 17133918, 30441820, ++ 38997856, 12327944, 10750447, 10014012 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 264204366029760, 1654686424479449, 2185050199932931, ++ 2207056159091748, 506015669043634 ++#else ++ 56796096, 3936951, 9156313, 24656749, 16498691, 32559785, ++ 39627812, 32887699, 3424690, 7540221 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1784446333136569, 1973746527984364, 334856327359575, ++ 1156769775884610, 1023950124675478 ++#else ++ 30322361, 26590322, 11361004, 29411115, 7433303, 4989748, ++ 60037442, 17237212, 57864598, 15258045 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2065270940578383, 31477096270353, 306421879113491, ++ 181958643936686, 1907105536686083 ++#else ++ 13054543, 30774935, 19155473, 469045, 54626067, 4566041, ++ 5631406, 2711395, 1062915, 28418087 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1496516440779464, 1748485652986458, 872778352227340, ++ 818358834654919, 97932669284220 ++#else ++ 47868616, 22299832, 37599834, 26054466, 61273100, 13005410, ++ 61042375, 12194496, 32960380, 1459310 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 471636015770351, 672455402793577, 1804995246884103, ++ 1842309243470804, 1501862504981682 ++#else ++ 19852015, 7027924, 23669353, 10020366, 8586503, 26896525, ++ 394196, 27452547, 18638002, 22379495 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1013216974933691, 538921919682598, 1915776722521558, ++ 1742822441583877, 1886550687916656 ++#else ++ 31395515, 15098109, 26581030, 8030562, 50580950, 28547297, ++ 9012485, 25970078, 60465776, 28111795 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2094270000643336, 303971879192276, 40801275554748, ++ 649448917027930, 1818544418535447 ++#else ++ 57916680, 31207054, 65111764, 4529533, 25766844, 607986, ++ 67095642, 9677542, 34813975, 27098423 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2241737709499165, 549397817447461, 838180519319392, ++ 1725686958520781, 1705639080897747 ++#else ++ 64664349, 33404494, 29348901, 8186665, 1873760, 12489863, ++ 36174285, 25714739, 59256019, 25416002 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1216074541925116, 50120933933509, 1565829004133810, ++ 721728156134580, 349206064666188 ++#else ++ 51872508, 18120922, 7766469, 746860, 26346930, 23332670, ++ 39775412, 10754587, 57677388, 5203575 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 948617110470858, 346222547451945, 1126511960599975, ++ 1759386906004538, 493053284802266 ++#else ++ 31834314, 14135496, 66338857, 5159117, 20917671, 16786336, ++ 59640890, 26216907, 31809242, 7347066 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1454933046815146, 874696014266362, 1467170975468588, ++ 1432316382418897, 2111710746366763 ++#else ++ 57502122, 21680191, 20414458, 13033986, 13716524, 21862551, ++ 19797969, 21343177, 15192875, 31466942 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2105387117364450, 1996463405126433, 1303008614294500, ++ 851908115948209, 1353742049788635 ++#else ++ 54445282, 31372712, 1168161, 29749623, 26747876, 19416341, ++ 10609329, 12694420, 33473243, 20172328 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 750300956351719, 1487736556065813, 15158817002104, ++ 1511998221598392, 971739901354129 ++#else ++ 33184999, 11180355, 15832085, 22169002, 65475192, 225883, ++ 15089336, 22530529, 60973201, 14480052 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1874648163531693, 2124487685930551, 1810030029384882, ++ 918400043048335, 586348627300650 ++#else ++ 31308717, 27934434, 31030839, 31657333, 15674546, 26971549, ++ 5496207, 13685227, 27595050, 8737275 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1235084464747900, 1166111146432082, 1745394857881591, ++ 1405516473883040, 4463504151617 ++#else ++ 46790012, 18404192, 10933842, 17376410, 8335351, 26008410, ++ 36100512, 20943827, 26498113, 66511 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1663810156463827, 327797390285791, 1341846161759410, ++ 1964121122800605, 1747470312055380 ++#else ++ 22644435, 24792703, 50437087, 4884561, 64003250, 19995065, ++ 30540765, 29267685, 53781076, 26039336 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 660005247548233, 2071860029952887, 1358748199950107, ++ 911703252219107, 1014379923023831 ++#else ++ 39091017, 9834844, 18617207, 30873120, 63706907, 20246925, ++ 8205539, 13585437, 49981399, 15115438 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2206641276178231, 1690587809721504, 1600173622825126, ++ 2156096097634421, 1106822408548216 ++#else ++ 23711543, 32881517, 31206560, 25191721, 6164646, 23844445, ++ 33572981, 32128335, 8236920, 16492939 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1344788193552206, 1949552134239140, 1735915881729557, ++ 675891104100469, 1834220014427292 ++#else ++ 43198286, 20038905, 40809380, 29050590, 25005589, 25867162, ++ 19574901, 10071562, 6708380, 27332008 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1920949492387964, 158885288387530, 70308263664033, ++ 626038464897817, 1468081726101009 ++#else ++ 2101372, 28624378, 19702730, 2367575, 51681697, 1047674, ++ 5301017, 9328700, 29955601, 21876122 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 622221042073383, 1210146474039168, 1742246422343683, ++ 1403839361379025, 417189490895736 ++#else ++ 3096359, 9271816, 45488000, 18032587, 52260867, 25961494, ++ 41216721, 20918836, 57191288, 6216607 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 22727256592983, 168471543384997, 1324340989803650, ++ 1839310709638189, 504999476432775 ++#else ++ 34493015, 338662, 41913253, 2510421, 37895298, 19734218, ++ 24822829, 27407865, 40341383, 7525078 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1313240518756327, 1721896294296942, 52263574587266, ++ 2065069734239232, 804910473424630 ++#else ++ 44042215, 19568808, 16133486, 25658254, 63719298, 778787, ++ 66198528, 30771936, 47722230, 11994100 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1337466662091884, 1287645354669772, 2018019646776184, ++ 652181229374245, 898011753211715 ++#else ++ 21691500, 19929806, 66467532, 19187410, 3285880, 30070836, ++ 42044197, 9718257, 59631427, 13381417 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1969792547910734, 779969968247557, 2011350094423418, ++ 1823964252907487, 1058949448296945 ++#else ++ 18445390, 29352196, 14979845, 11622458, 65381754, 29971451, ++ 23111647, 27179185, 28535281, 15779576 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 207343737062002, 1118176942430253, 758894594548164, ++ 806764629546266, 1157700123092949 ++#else ++ 30098034, 3089662, 57874477, 16662134, 45801924, 11308410, ++ 53040410, 12021729, 9955285, 17251076 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1273565321399022, 1638509681964574, 759235866488935, ++ 666015124346707, 897983460943405 ++#else ++ 9734894, 18977602, 59635230, 24415696, 2060391, 11313496, ++ 48682835, 9924398, 20194861, 13380996 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1717263794012298, 1059601762860786, 1837819172257618, ++ 1054130665797229, 680893204263559 ++#else ++ 40730762, 25589224, 44941042, 15789296, 49053522, 27385639, ++ 65123949, 15707770, 26342023, 10146099 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2237039662793603, 2249022333361206, 2058613546633703, ++ 149454094845279, 2215176649164582 ++#else ++ 41091971, 33334488, 21339190, 33513044, 19745255, 30675732, ++ 37471583, 2227039, 21612326, 33008704 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 79472182719605, 1851130257050174, 1825744808933107, ++ 821667333481068, 781795293511946 ++#else ++ 54031477, 1184227, 23562814, 27583990, 46757619, 27205717, ++ 25764460, 12243797, 46252298, 11649657 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 755822026485370, 152464789723500, 1178207602290608, ++ 410307889503239, 156581253571278 ++#else ++ 57077370, 11262625, 27384172, 2271902, 26947504, 17556661, ++ 39943, 6114064, 33514190, 2333242 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1418185496130297, 484520167728613, 1646737281442950, ++ 1401487684670265, 1349185550126961 ++#else ++ 45675257, 21132610, 8119781, 7219913, 45278342, 24538297, ++ 60429113, 20883793, 24350577, 20104431 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1495380034400429, 325049476417173, 46346894893933, ++ 1553408840354856, 828980101835683 ++#else ++ 62992557, 22282898, 43222677, 4843614, 37020525, 690622, ++ 35572776, 23147595, 8317859, 12352766 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1280337889310282, 2070832742866672, 1640940617225222, ++ 2098284908289951, 450929509534434 ++#else ++ 18200138, 19078521, 34021104, 30857812, 43406342, 24451920, ++ 43556767, 31266881, 20712162, 6719373 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 407703353998781, 126572141483652, 286039827513621, ++ 1999255076709338, 2030511179441770 ++#else ++ 26656189, 6075253, 59250308, 1886071, 38764821, 4262325, ++ 11117530, 29791222, 26224234, 30256974 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1254958221100483, 1153235960999843, 942907704968834, ++ 637105404087392, 1149293270147267 ++#else ++ 49939907, 18700334, 63713187, 17184554, 47154818, 14050419, ++ 21728352, 9493610, 18620611, 17125804 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 894249020470196, 400291701616810, 406878712230981, ++ 1599128793487393, 1145868722604026 ++#else ++ 53785524, 13325348, 11432106, 5964811, 18609221, 6062965, ++ 61839393, 23828875, 36407290, 17074774 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1497955250203334, 110116344653260, 1128535642171976, ++ 1900106496009660, 129792717460909 ++#else ++ 43248326, 22321272, 26961356, 1640861, 34695752, 16816491, ++ 12248508, 28313793, 13735341, 1934062 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 452487513298665, 1352120549024569, 1173495883910956, ++ 1999111705922009, 367328130454226 ++#else ++ 25089769, 6742589, 17081145, 20148166, 21909292, 17486451, ++ 51972569, 29789085, 45830866, 5473615 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1717539401269642, 1475188995688487, 891921989653942, ++ 836824441505699, 1885988485608364 ++#else ++ 31883658, 25593331, 1083431, 21982029, 22828470, 13290673, ++ 59983779, 12469655, 29111212, 28103418 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1241784121422547, 187337051947583, 1118481812236193, ++ 428747751936362, 30358898927325 ++#else ++ 24244947, 18504025, 40845887, 2791539, 52111265, 16666677, ++ 24367466, 6388839, 56813277, 452382 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2022432361201842, 1088816090685051, 1977843398539868, ++ 1854834215890724, 564238862029357 ++#else ++ 41468082, 30136590, 5217915, 16224624, 19987036, 29472163, ++ 42872612, 27639183, 15766061, 8407814 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 938868489100585, 1100285072929025, 1017806255688848, ++ 1957262154788833, 152787950560442 ++#else ++ 46701865, 13990230, 15495425, 16395525, 5377168, 15166495, ++ 58191841, 29165478, 59040954, 2276717 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 867319417678923, 620471962942542, 226032203305716, ++ 342001443957629, 1761675818237336 ++#else ++ 30157899, 12924066, 49396814, 9245752, 19895028, 3368142, ++ 43281277, 5096218, 22740376, 26251015 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1295072362439987, 931227904689414, 1355731432641687, ++ 922235735834035, 892227229410209 ++#else ++ 2041139, 19298082, 7783686, 13876377, 41161879, 20201972, ++ 24051123, 13742383, 51471265, 13295221 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1680989767906154, 535362787031440, 2136691276706570, ++ 1942228485381244, 1267350086882274 ++#else ++ 33338218, 25048699, 12532112, 7977527, 9106186, 31839181, ++ 49388668, 28941459, 62657506, 18884987 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 366018233770527, 432660629755596, 126409707644535, ++ 1973842949591662, 645627343442376 ++#else ++ 47063583, 5454096, 52762316, 6447145, 28862071, 1883651, ++ 64639598, 29412551, 7770568, 9620597 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 535509430575217, 546885533737322, 1524675609547799, ++ 2138095752851703, 1260738089896827 ++#else ++ 23208049, 7979712, 33071466, 8149229, 1758231, 22719437, ++ 30945527, 31860109, 33606523, 18786461 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1159906385590467, 2198530004321610, 714559485023225, ++ 81880727882151, 1484020820037082 ++#else ++ 1439939, 17283952, 66028874, 32760649, 4625401, 10647766, ++ 62065063, 1220117, 30494170, 22113633 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1377485731340769, 2046328105512000, 1802058637158797, ++ 62146136768173, 1356993908853901 ++#else ++ 62071265, 20526136, 64138304, 30492664, 15640973, 26852766, ++ 40369837, 926049, 65424525, 20220784 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2013612215646735, 1830770575920375, 536135310219832, ++ 609272325580394, 270684344495013 ++#else ++ 13908495, 30005160, 30919927, 27280607, 45587000, 7989038, ++ 9021034, 9078865, 3353509, 4033511 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1237542585982777, 2228682050256790, 1385281931622824, ++ 593183794882890, 493654978552689 ++#else ++ 37445433, 18440821, 32259990, 33209950, 24295848, 20642309, ++ 23161162, 8839127, 27485041, 7356032 ++#endif ++ }}, ++ }, ++ }, ++ { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 47341488007760, 1891414891220257, 983894663308928, ++ 176161768286818, 1126261115179708 ++#else ++ 9661008, 705443, 11980065, 28184278, 65480320, 14661172, ++ 60762722, 2625014, 28431036, 16782598 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1694030170963455, 502038567066200, 1691160065225467, ++ 949628319562187, 275110186693066 ++#else ++ 43269631, 25243016, 41163352, 7480957, 49427195, 25200248, ++ 44562891, 14150564, 15970762, 4099461 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1124515748676336, 1661673816593408, 1499640319059718, ++ 1584929449166988, 558148594103306 ++#else ++ 29262576, 16756590, 26350592, 24760869, 8529670, 22346382, ++ 13617292, 23617289, 11465738, 8317062 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1784525599998356, 1619698033617383, 2097300287550715, ++ 258265458103756, 1905684794832758 ++#else ++ 41615764, 26591503, 32500199, 24135381, 44070139, 31252209, ++ 14898636, 3848455, 20969334, 28396916 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1288941072872766, 931787902039402, 190731008859042, ++ 2006859954667190, 1005931482221702 ++#else ++ 46724414, 19206718, 48772458, 13884721, 34069410, 2842113, ++ 45498038, 29904543, 11177094, 14989547 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1465551264822703, 152905080555927, 680334307368453, ++ 173227184634745, 666407097159852 ++#else ++ 42612143, 21838415, 16959895, 2278463, 12066309, 10137771, ++ 13515641, 2581286, 38621356, 9930239 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2111017076203943, 1378760485794347, 1248583954016456, ++ 1352289194864422, 1895180776543896 ++#else ++ 49357223, 31456605, 16544299, 20545132, 51194056, 18605350, ++ 18345766, 20150679, 16291480, 28240394 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 171348223915638, 662766099800389, 462338943760497, ++ 466917763340314, 656911292869115 ++#else ++ 33879670, 2553287, 32678213, 9875984, 8534129, 6889387, ++ 57432090, 6957616, 4368891, 9788741 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 488623681976577, 866497561541722, 1708105560937768, ++ 1673781214218839, 1506146329818807 ++#else ++ 16660737, 7281060, 56278106, 12911819, 20108584, 25452756, ++ 45386327, 24941283, 16250551, 22443329 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 160425464456957, 950394373239689, 430497123340934, ++ 711676555398832, 320964687779005 ++#else ++ 47343357, 2390525, 50557833, 14161979, 1905286, 6414907, ++ 4689584, 10604807, 36918461, 4782746 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 988979367990485, 1359729327576302, 1301834257246029, ++ 294141160829308, 29348272277475 ++#else ++ 65754325, 14736940, 59741422, 20261545, 7710541, 19398842, ++ 57127292, 4383044, 22546403, 437323 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1434382743317910, 100082049942065, 221102347892623, ++ 186982837860588, 1305765053501834 ++#else ++ 31665558, 21373968, 50922033, 1491338, 48740239, 3294681, ++ 27343084, 2786261, 36475274, 19457415 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2205916462268190, 499863829790820, 961960554686616, ++ 158062762756985, 1841471168298305 ++#else ++ 52641566, 32870716, 33734756, 7448551, 19294360, 14334329, ++ 47418233, 2355318, 47824193, 27440058 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1191737341426592, 1847042034978363, 1382213545049056, ++ 1039952395710448, 788812858896859 ++#else ++ 15121312, 17758270, 6377019, 27523071, 56310752, 20596586, ++ 18952176, 15496498, 37728731, 11754227 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1346965964571152, 1291881610839830, 2142916164336056, ++ 786821641205979, 1571709146321039 ++#else ++ 64471568, 20071356, 8488726, 19250536, 12728760, 31931939, ++ 7141595, 11724556, 22761615, 23420291 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 787164375951248, 202869205373189, 1356590421032140, ++ 1431233331032510, 786341368775957 ++#else ++ 16918416, 11729663, 49025285, 3022986, 36093132, 20214772, ++ 38367678, 21327038, 32851221, 11717399 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 492448143532951, 304105152670757, 1761767168301056, ++ 233782684697790, 1981295323106089 ++#else ++ 11166615, 7338049, 60386341, 4531519, 37640192, 26252376, ++ 31474878, 3483633, 65915689, 29523600 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 665807507761866, 1343384868355425, 895831046139653, ++ 439338948736892, 1986828765695105 ++#else ++ 66923210, 9921304, 31456609, 20017994, 55095045, 13348922, ++ 33142652, 6546660, 47123585, 29606055 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 756096210874553, 1721699973539149, 258765301727885, ++ 1390588532210645, 1212530909934781 ++#else ++ 34648249, 11266711, 55911757, 25655328, 31703693, 3855903, ++ 58571733, 20721383, 36336829, 18068118 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 852891097972275, 1816988871354562, 1543772755726524, ++ 1174710635522444, 202129090724628 ++#else ++ 49102387, 12709067, 3991746, 27075244, 45617340, 23004006, ++ 35973516, 17504552, 10928916, 3011958 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1205281565824323, 22430498399418, 992947814485516, ++ 1392458699738672, 688441466734558 ++#else ++ 60151107, 17960094, 31696058, 334240, 29576716, 14796075, ++ 36277808, 20749251, 18008030, 10258577 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1050627428414972, 1955849529137135, 2171162376368357, ++ 91745868298214, 447733118757826 ++#else ++ 44660220, 15655568, 7018479, 29144429, 36794597, 32352840, ++ 65255398, 1367119, 25127874, 6671743 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1287181461435438, 622722465530711, 880952150571872, ++ 741035693459198, 311565274989772 ++#else ++ 29701166, 19180498, 56230743, 9279287, 67091296, 13127209, ++ 21382910, 11042292, 25838796, 4642684 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1003649078149734, 545233927396469, 1849786171789880, ++ 1318943684880434, 280345687170552 ++#else ++ 46678630, 14955536, 42982517, 8124618, 61739576, 27563961, ++ 30468146, 19653792, 18423288, 4177476 ++#endif ++ }}, ++ }, ++ }, ++}; ++ ++#endif // CONFIG_SMALL ++ ++// Bi[i] = (2*i+1)*B ++static const ge_precomp Bi[8] = { ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1288382639258501, 245678601348599, 269427782077623, ++ 1462984067271730, 137412439391563 ++#else ++ 25967493, 19198397, 29566455, 3660896, 54414519, 4014786, 27544626, ++ 21800161, 61029707, 2047604 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 62697248952638, 204681361388450, 631292143396476, 338455783676468, ++ 1213667448819585 ++#else ++ 54563134, 934261, 64385954, 3049989, 66381436, 9406985, 12720692, ++ 5043384, 19500929, 18085054 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 301289933810280, 1259582250014073, 1422107436869536, ++ 796239922652654, 1953934009299142 ++#else ++ 58370664, 4489569, 9688441, 18769238, 10184608, 21191052, 29287918, ++ 11864899, 42594502, 29115885 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1601611775252272, 1720807796594148, 1132070835939856, ++ 1260455018889551, 2147779492816911 ++#else ++ 15636272, 23865875, 24204772, 25642034, 616976, 16869170, 27787599, ++ 18782243, 28944399, 32004408 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 316559037616741, 2177824224946892, 1459442586438991, ++ 1461528397712656, 751590696113597 ++#else ++ 16568933, 4717097, 55552716, 32452109, 15682895, 21747389, 16354576, ++ 21778470, 7689661, 11199574 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1850748884277385, 1200145853858453, 1068094770532492, ++ 672251375690438, 1586055907191707 ++#else ++ 30464137, 27578307, 55329429, 17883566, 23220364, 15915852, 7512774, ++ 10017326, 49359771, 23634074 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 769950342298419, 132954430919746, 844085933195555, 974092374476333, ++ 726076285546016 ++#else ++ 10861363, 11473154, 27284546, 1981175, 37044515, 12577860, 32867885, ++ 14515107, 51670560, 10819379 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 425251763115706, 608463272472562, 442562545713235, 837766094556764, ++ 374555092627893 ++#else ++ 4708026, 6336745, 20377586, 9066809, 55836755, 6594695, 41455196, ++ 12483687, 54440373, 5581305 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1086255230780037, 274979815921559, 1960002765731872, ++ 929474102396301, 1190409889297339 ++#else ++ 19563141, 16186464, 37722007, 4097518, 10237984, 29206317, 28542349, ++ 13850243, 43430843, 17738489 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 665000864555967, 2065379846933859, 370231110385876, 350988370788628, ++ 1233371373142985 ++#else ++ 5153727, 9909285, 1723747, 30776558, 30523604, 5516873, 19480852, ++ 5230134, 43156425, 18378665 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2019367628972465, 676711900706637, 110710997811333, ++ 1108646842542025, 517791959672113 ++#else ++ 36839857, 30090922, 7665485, 10083793, 28475525, 1649722, 20654025, ++ 16520125, 30598449, 7715701 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 965130719900578, 247011430587952, 526356006571389, 91986625355052, ++ 2157223321444601 ++#else ++ 28881826, 14381568, 9657904, 3680757, 46927229, 7843315, 35708204, ++ 1370707, 29794553, 32145132 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1802695059465007, 1664899123557221, 593559490740857, ++ 2160434469266659, 927570450755031 ++#else ++ 44589871, 26862249, 14201701, 24808930, 43598457, 8844725, 18474211, ++ 32192982, 54046167, 13821876 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1725674970513508, 1933645953859181, 1542344539275782, ++ 1767788773573747, 1297447965928905 ++#else ++ 60653668, 25714560, 3374701, 28813570, 40010246, 22982724, 31655027, ++ 26342105, 18853321, 19333481 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1381809363726107, 1430341051343062, 2061843536018959, ++ 1551778050872521, 2036394857967624 ++#else ++ 4566811, 20590564, 38133974, 21313742, 59506191, 30723862, 58594505, ++ 23123294, 2207752, 30344648 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1970894096313054, 528066325833207, 1619374932191227, ++ 2207306624415883, 1169170329061080 ++#else ++ 41954014, 29368610, 29681143, 7868801, 60254203, 24130566, 54671499, ++ 32891431, 35997400, 17421995 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 2070390218572616, 1458919061857835, 624171843017421, ++ 1055332792707765, 433987520732508 ++#else ++ 25576264, 30851218, 7349803, 21739588, 16472781, 9300885, 3844789, ++ 15725684, 171356, 6466918 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 893653801273833, 1168026499324677, 1242553501121234, ++ 1306366254304474, 1086752658510815 ++#else ++ 23103977, 13316479, 9739013, 17404951, 817874, 18515490, 8965338, ++ 19466374, 36393951, 16193876 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 213454002618221, 939771523987438, 1159882208056014, 317388369627517, ++ 621213314200687 ++#else ++ 33587053, 3180712, 64714734, 14003686, 50205390, 17283591, 17238397, ++ 4729455, 49034351, 9256799 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1971678598905747, 338026507889165, 762398079972271, 655096486107477, ++ 42299032696322 ++#else ++ 41926547, 29380300, 32336397, 5036987, 45872047, 11360616, 22616405, ++ 9761698, 47281666, 630304 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 177130678690680, 1754759263300204, 1864311296286618, ++ 1180675631479880, 1292726903152791 ++#else ++ 53388152, 2639452, 42871404, 26147950, 9494426, 27780403, 60554312, ++ 17593437, 64659607, 19263131 ++#endif ++ }}, ++ }, ++ { ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1913163449625248, 460779200291993, 2193883288642314, ++ 1008900146920800, 1721983679009502 ++#else ++ 63957664, 28508356, 9282713, 6866145, 35201802, 32691408, 48168288, ++ 15033783, 25105118, 25659556 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 1070401523076875, 1272492007800961, 1910153608563310, ++ 2075579521696771, 1191169788841221 ++#else ++ 42782475, 15950225, 35307649, 18961608, 55446126, 28463506, 1573891, ++ 30928545, 2198789, 17749813 ++#endif ++ }}, ++ {{ ++#if defined(BORINGSSL_CURVE25519_64BIT) ++ 692896803108118, 500174642072499, 2068223309439677, ++ 1162190621851337, 1426986007309901 ++#else ++ 64009494, 10324966, 64867251, 7453182, 61661885, 30818928, 53296841, ++ 17317989, 34647629, 21263748 ++#endif ++ }}, ++ }, ++}; +diff --git a/src/plugins/preauth/spake/groups.c b/src/plugins/preauth/spake/groups.c +new file mode 100644 +index 000000000..a195cc195 +--- /dev/null ++++ b/src/plugins/preauth/spake/groups.c +@@ -0,0 +1,442 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* plugins/preauth/spake/groups.c - SPAKE group interfaces */ ++/* ++ * Copyright (C) 2015 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++/* ++ * The SPAKE2 algorithm works as follows: ++ * ++ * 1. The parties agree on a group, a base element G, and constant elements M ++ * and N. In this mechanism, these parameters are determined by the ++ * registered group number. ++ * 2. Both parties derive a scalar value w from the initial key. ++ * 3. The first party (the KDC, in this mechanism) chooses a random secret ++ * scalar x and sends T=xG+wM. ++ * 4. The second party (the client, in this mechanism) chooses a random ++ * secret scalar y and sends S=yG+wN. ++ * 5. The first party computes K=x(S-wN). ++ * 6. The second party computes the same value as K=y(T-wM). ++ * 7. Both parties derive a key from a random oracle whose input incorporates ++ * the party identities, w, T, S, and K. ++ * ++ * We implement the algorithm using a vtable for each group, where the primary ++ * vtable methods are "keygen" (corresponding to step 3 or 4) and "result" ++ * (corresponding to step 5 or 6). We use the term "private scalar" to refer ++ * to x or y, and "public element" to refer to S or T. ++ */ ++ ++#include "iana.h" ++#include "trace.h" ++#include "groups.h" ++ ++#define DEFAULT_GROUPS_CLIENT "edwards25519" ++#define DEFAULT_GROUPS_KDC "" ++ ++typedef struct groupent_st { ++ const groupdef *gdef; ++ groupdata *gdata; ++} groupent; ++ ++struct groupstate_st { ++ krb5_boolean is_kdc; ++ ++ /* Permitted and groups, from configuration */ ++ int32_t *permitted; ++ size_t npermitted; ++ ++ /* Optimistic challenge group, from configuration */ ++ int32_t challenge_group; ++ ++ /* Lazily-initialized list of gdata objects. */ ++ groupent *data; ++ size_t ndata; ++}; ++ ++extern groupdef builtin_edwards25519; ++#ifdef SPAKE_OPENSSL ++extern groupdef ossl_P256; ++extern groupdef ossl_P384; ++extern groupdef ossl_P521; ++#endif ++ ++static const groupdef *groupdefs[] = { ++ &builtin_edwards25519, ++#ifdef SPAKE_OPENSSL ++ &ossl_P256, ++ &ossl_P384, ++ &ossl_P521, ++#endif ++ NULL ++}; ++ ++/* Find a groupdef structure by group number. Return NULL on failure. */ ++static const groupdef * ++find_gdef(int32_t group) ++{ ++ size_t i; ++ ++ for (i = 0; groupdefs[i] != NULL; i++) { ++ if (groupdefs[i]->reg->id == group) ++ return groupdefs[i]; ++ } ++ ++ return NULL; ++} ++ ++/* Find a group number by name. Return 0 on failure. */ ++static int32_t ++find_gnum(const char *name) ++{ ++ size_t i; ++ ++ for (i = 0; groupdefs[i] != NULL; i++) { ++ if (strcasecmp(name, groupdefs[i]->reg->name) == 0) ++ return groupdefs[i]->reg->id; ++ } ++ return 0; ++} ++ ++static krb5_boolean ++in_grouplist(const int32_t *list, size_t count, int32_t group) ++{ ++ size_t i; ++ ++ for (i = 0; i < count; i++) { ++ if (list[i] == group) ++ return TRUE; ++ } ++ ++ return FALSE; ++} ++ ++/* Retrieve a group data object for group within gstate, lazily initializing it ++ * if necessary. */ ++static krb5_error_code ++get_gdata(krb5_context context, groupstate *gstate, const groupdef *gdef, ++ groupdata **gdata_out) ++{ ++ krb5_error_code ret; ++ groupent *ent, *newptr; ++ ++ *gdata_out = NULL; ++ ++ /* Look for an existing entry. */ ++ for (ent = gstate->data; ent < gstate->data + gstate->ndata; ent++) { ++ if (ent->gdef == gdef) { ++ *gdata_out = ent->gdata; ++ return 0; ++ } ++ } ++ ++ /* Make a new entry. */ ++ newptr = realloc(gstate->data, (gstate->ndata + 1) * sizeof(groupent)); ++ if (newptr == NULL) ++ return ENOMEM; ++ gstate->data = newptr; ++ ent = &gstate->data[gstate->ndata]; ++ ent->gdef = gdef; ++ ent->gdata = NULL; ++ if (gdef->init != NULL) { ++ ret = gdef->init(context, gdef, &ent->gdata); ++ if (ret) ++ return ret; ++ } ++ gstate->ndata++; ++ *gdata_out = ent->gdata; ++ return 0; ++} ++ ++/* Destructively parse str into a list of group numbers. */ ++static krb5_error_code ++parse_groups(krb5_context context, char *str, int32_t **list_out, ++ size_t *count_out) ++{ ++ const char *const delim = " \t\r\n,"; ++ char *token, *save = NULL; ++ int32_t group, *newptr, *list = NULL; ++ size_t count = 0; ++ ++ *list_out = NULL; ++ *count_out = 0; ++ ++ /* Walk through the words in profstr. */ ++ for (token = strtok_r(str, delim, &save); token != NULL; ++ token = strtok_r(NULL, delim, &save)) { ++ group = find_gnum(token); ++ if (!group) { ++ TRACE_SPAKE_UNKNOWN_GROUP(context, token); ++ continue; ++ } ++ if (in_grouplist(list, count, group)) ++ continue; ++ newptr = realloc(list, (count + 1) * sizeof(*list)); ++ if (newptr == NULL) { ++ free(list); ++ return ENOMEM; ++ } ++ list = newptr; ++ list[count++] = group; ++ } ++ ++ *list_out = list; ++ *count_out = count; ++ return 0; ++} ++ ++krb5_error_code ++group_init_state(krb5_context context, krb5_boolean is_kdc, ++ groupstate **gstate_out) ++{ ++ krb5_error_code ret; ++ groupstate *gstate; ++ const char *defgroups; ++ char *profstr1 = NULL, *profstr2 = NULL; ++ int32_t *permitted = NULL, challenge_group = 0; ++ size_t npermitted; ++ ++ *gstate_out = NULL; ++ ++ defgroups = is_kdc ? DEFAULT_GROUPS_KDC : DEFAULT_GROUPS_CLIENT; ++ ret = profile_get_string(context->profile, KRB5_CONF_LIBDEFAULTS, ++ KRB5_CONF_SPAKE_PREAUTH_GROUPS, NULL, defgroups, ++ &profstr1); ++ if (ret) ++ goto cleanup; ++ ret = parse_groups(context, profstr1, &permitted, &npermitted); ++ if (ret) ++ goto cleanup; ++ if (npermitted == 0) { ++ ret = KRB5_PLUGIN_OP_NOTSUPP; ++ k5_setmsg(context, ret, _("No SPAKE preauth groups configured")); ++ goto cleanup; ++ } ++ ++ if (is_kdc) { ++ /* ++ * Check for a configured optimistic challenge group. If one is set, ++ * the KDC will send a challenge in the PREAUTH_REQUIRED method data, ++ * before receiving the list of supported groups. ++ */ ++ ret = profile_get_string(context->profile, KRB5_CONF_KDCDEFAULTS, ++ KRB5_CONF_SPAKE_PREAUTH_KDC_CHALLENGE, NULL, ++ NULL, &profstr2); ++ if (ret) ++ goto cleanup; ++ if (profstr2 != NULL) { ++ challenge_group = find_gnum(profstr2); ++ if (!in_grouplist(permitted, npermitted, challenge_group)) { ++ ret = KRB5_PLUGIN_OP_NOTSUPP; ++ k5_setmsg(context, ret, ++ _("SPAKE challenge group not a permitted group: %s"), ++ profstr2); ++ goto cleanup; ++ } ++ } ++ } ++ ++ gstate = k5alloc(sizeof(*gstate), &ret); ++ if (gstate == NULL) ++ goto cleanup; ++ gstate->is_kdc = is_kdc; ++ gstate->permitted = permitted; ++ gstate->npermitted = npermitted; ++ gstate->challenge_group = challenge_group; ++ permitted = NULL; ++ gstate->data = NULL; ++ gstate->ndata = 0; ++ *gstate_out = gstate; ++ ++cleanup: ++ profile_release_string(profstr1); ++ profile_release_string(profstr2); ++ free(permitted); ++ return ret; ++} ++ ++ ++void ++group_free_state(groupstate *gstate) ++{ ++ groupent *ent; ++ ++ for (ent = gstate->data; ent < gstate->data + gstate->ndata; ent++) { ++ if (ent->gdata != NULL && ent->gdef->fini != NULL) ++ ent->gdef->fini(ent->gdata); ++ } ++ ++ free(gstate->permitted); ++ free(gstate->data); ++ free(gstate); ++} ++ ++krb5_boolean ++group_is_permitted(groupstate *gstate, int32_t group) ++{ ++ return in_grouplist(gstate->permitted, gstate->npermitted, group); ++} ++ ++void ++group_get_permitted(groupstate *gstate, int32_t **list_out, int32_t *count_out) ++{ ++ *list_out = gstate->permitted; ++ *count_out = gstate->npermitted; ++} ++ ++krb5_int32 ++group_optimistic_challenge(groupstate *gstate) ++{ ++ assert(gstate->is_kdc); ++ return gstate->challenge_group; ++} ++ ++krb5_error_code ++group_mult_len(int32_t group, size_t *len_out) ++{ ++ const groupdef *gdef; ++ ++ *len_out = 0; ++ gdef = find_gdef(group); ++ if (gdef == NULL) ++ return EINVAL; ++ *len_out = gdef->reg->mult_len; ++ return 0; ++} ++ ++krb5_error_code ++group_keygen(krb5_context context, groupstate *gstate, int32_t group, ++ const krb5_data *wbytes, krb5_data *priv_out, krb5_data *pub_out) ++{ ++ krb5_error_code ret; ++ const groupdef *gdef; ++ groupdata *gdata; ++ uint8_t *priv = NULL, *pub = NULL; ++ ++ *priv_out = empty_data(); ++ *pub_out = empty_data(); ++ gdef = find_gdef(group); ++ if (gdef == NULL || wbytes->length != gdef->reg->mult_len) ++ return EINVAL; ++ ret = get_gdata(context, gstate, gdef, &gdata); ++ if (ret) ++ return ret; ++ ++ priv = k5alloc(gdef->reg->mult_len, &ret); ++ if (priv == NULL) ++ goto cleanup; ++ pub = k5alloc(gdef->reg->elem_len, &ret); ++ if (pub == NULL) ++ goto cleanup; ++ ++ ret = gdef->keygen(context, gdata, (uint8_t *)wbytes->data, gstate->is_kdc, ++ priv, pub); ++ if (ret) ++ goto cleanup; ++ ++ *priv_out = make_data(priv, gdef->reg->mult_len); ++ *pub_out = make_data(pub, gdef->reg->elem_len); ++ priv = pub = NULL; ++ TRACE_SPAKE_KEYGEN(context, pub_out); ++ ++cleanup: ++ zapfree(priv, gdef->reg->mult_len); ++ free(pub); ++ return ret; ++} ++ ++krb5_error_code ++group_result(krb5_context context, groupstate *gstate, int32_t group, ++ const krb5_data *wbytes, const krb5_data *ourpriv, ++ const krb5_data *theirpub, krb5_data *spakeresult_out) ++{ ++ krb5_error_code ret; ++ const groupdef *gdef; ++ groupdata *gdata; ++ uint8_t *spakeresult = NULL; ++ ++ *spakeresult_out = empty_data(); ++ gdef = find_gdef(group); ++ if (gdef == NULL || wbytes->length != gdef->reg->mult_len) ++ return EINVAL; ++ if (ourpriv->length != gdef->reg->mult_len || ++ theirpub->length != gdef->reg->elem_len) ++ return EINVAL; ++ ret = get_gdata(context, gstate, gdef, &gdata); ++ if (ret) ++ return ret; ++ ++ spakeresult = k5alloc(gdef->reg->elem_len, &ret); ++ if (spakeresult == NULL) ++ goto cleanup; ++ ++ /* Invert is_kdc here to use the other party's constant. */ ++ ret = gdef->result(context, gdata, (uint8_t *)wbytes->data, ++ (uint8_t *)ourpriv->data, (uint8_t *)theirpub->data, ++ !gstate->is_kdc, spakeresult); ++ if (ret) ++ goto cleanup; ++ ++ *spakeresult_out = make_data(spakeresult, gdef->reg->elem_len); ++ spakeresult = NULL; ++ TRACE_SPAKE_RESULT(context, spakeresult_out); ++ ++cleanup: ++ zapfree(spakeresult, gdef->reg->elem_len); ++ return ret; ++} ++ ++krb5_error_code ++group_hash_len(int32_t group, size_t *len_out) ++{ ++ const groupdef *gdef; ++ ++ *len_out = 0; ++ gdef = find_gdef(group); ++ if (gdef == NULL) ++ return EINVAL; ++ *len_out = gdef->reg->hash_len; ++ return 0; ++} ++ ++krb5_error_code ++group_hash(krb5_context context, groupstate *gstate, int32_t group, ++ const krb5_data *dlist, size_t ndata, uint8_t *result_out) ++{ ++ krb5_error_code ret; ++ const groupdef *gdef; ++ groupdata *gdata; ++ ++ gdef = find_gdef(group); ++ if (gdef == NULL) ++ return EINVAL; ++ ret = get_gdata(context, gstate, gdef, &gdata); ++ if (ret) ++ return ret; ++ return gdef->hash(context, gdata, dlist, ndata, result_out); ++} +diff --git a/src/plugins/preauth/spake/groups.h b/src/plugins/preauth/spake/groups.h +new file mode 100644 +index 000000000..3add69494 +--- /dev/null ++++ b/src/plugins/preauth/spake/groups.h +@@ -0,0 +1,148 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* plugins/preauth/spake/groups.h - SPAKE group interfaces */ ++/* ++ * Copyright (C) 2015 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#ifndef GROUPS_H ++#define GROUPS_H ++ ++#include "k5-int.h" ++#include "iana.h" ++ ++typedef struct groupstate_st groupstate; ++typedef struct groupdata_st groupdata; ++typedef struct groupdef_st groupdef; ++ ++struct groupdef_st { ++ const spake_iana *reg; ++ ++ /* ++ * Optional: create a per-group data object to allow more efficient keygen ++ * and result computations. Saving a reference to gdef is okay; its ++ * lifetime will always be longer than the resulting object. ++ */ ++ krb5_error_code (*init)(krb5_context context, const groupdef *gdef, ++ groupdata **gdata_out); ++ ++ /* Optional: release a group data object. */ ++ void (*fini)(groupdata *gdata); ++ ++ /* ++ * Mandatory: generate a random private scalar (x or y) and a public ++ * element (T or S), using wbytes for the w value. If use_m is true, use ++ * the M element (generating T); otherwise use the N element (generating ++ * S). wbytes and priv_out have length reg->mult_len; pub_out has length ++ * reg->elem_len. priv_out and pub_out are caller-allocated. ++ */ ++ krb5_error_code (*keygen)(krb5_context context, groupdata *gdata, ++ const uint8_t *wbytes, krb5_boolean use_m, ++ uint8_t *priv_out, uint8_t *pub_out); ++ ++ /* ++ * Mandatory: compute K given a private scalar (x or y) and the other ++ * party's public element (S or T), using wbytes for the w value. If use_m ++ * is true, use the M element (computing K from y and T); otherwise use the ++ * N element (computing K from x and S). wbytes and ourpriv have length ++ * reg->mult_len; theirpub and elem_out have length reg->elem_len. ++ * elem_out is caller-allocated. ++ */ ++ krb5_error_code (*result)(krb5_context context, groupdata *gdata, ++ const uint8_t *wbytes, const uint8_t *ourpriv, ++ const uint8_t *theirpub, krb5_boolean use_m, ++ uint8_t *elem_out); ++ ++ /* ++ * Mandatory: compute the group's specified hash function over datas (with ++ * ndata elements), placing the result in result_out. result_out is ++ * caller-allocated with length reg->hash_len. ++ */ ++ krb5_error_code (*hash)(krb5_context context, groupdata *gdata, ++ const krb5_data *datas, size_t ndata, ++ uint8_t *result_out); ++}; ++ ++/* Initialize an object which holds group configuration and pre-computation ++ * state for each group. is_kdc is true for KDCs, false for clients. */ ++krb5_error_code group_init_state(krb5_context context, krb5_boolean is_kdc, ++ groupstate **out); ++ ++/* Release resources held by gstate. */ ++void group_free_state(groupstate *gstate); ++ ++/* Return true if group is permitted by configuration. */ ++krb5_boolean group_is_permitted(groupstate *gstate, int32_t group); ++ ++/* Set *list_out and *count_out to the list of groups permitted by ++ * configuration. */ ++void group_get_permitted(groupstate *gstate, int32_t **list_out, ++ int32_t *count_out); ++ ++/* Return the KDC optimistic challenge group if one is configured. Valid for ++ * KDC groupstate objects only. */ ++krb5_int32 group_optimistic_challenge(groupstate *gstate); ++ ++/* Set *len_out to the multiplier length for group. */ ++krb5_error_code group_mult_len(int32_t group, size_t *len_out); ++ ++/* ++ * Generate a SPAKE private scalar (x or y) and public element (T or S), given ++ * an input multiplier wbytes. Use constant M if gstate is a KDC groupstate ++ * object, N if it is a client object. Allocate storage and place the results ++ * in *priv_out and *pub_out. ++ */ ++krb5_error_code group_keygen(krb5_context context, groupstate *gstate, ++ int32_t group, const krb5_data *wbytes, ++ krb5_data *priv_out, krb5_data *pub_out); ++ ++/* ++ * Compute the SPAKE result K from our private scalar (x or y) and their public ++ * key (S or T), deriving the input scalar w from ikey. Use the other party's ++ * constant, N if gstate is a KDC groupstate object or M if it is a client ++ * object. Allocate storage and place the result in *spakeresult_out. ++ */ ++krb5_error_code group_result(krb5_context context, groupstate *gstate, ++ int32_t group, const krb5_data *wbytes, ++ const krb5_data *ourpriv, ++ const krb5_data *theirpub, ++ krb5_data *spakeresult_out); ++ ++/* Set *result_out to the hash output length for group. */ ++krb5_error_code group_hash_len(int32_t group, size_t *result_out); ++ ++/* ++ * Compute the group's specified hash function over dlist (with ndata ++ * elements). result_out is caller-allocated with enough bytes for the hash ++ * output as given by group_hash_len(). ++ */ ++krb5_error_code group_hash(krb5_context context, groupstate *gstate, ++ int32_t group, const krb5_data *dlist, size_t ndata, ++ uint8_t *result_out); ++ ++#endif /* GROUPS_H */ +diff --git a/src/plugins/preauth/spake/iana.c b/src/plugins/preauth/spake/iana.c +new file mode 100644 +index 000000000..e7901dedf +--- /dev/null ++++ b/src/plugins/preauth/spake/iana.c +@@ -0,0 +1,108 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* plugins/preauth/spake/iana.c - SPAKE IANA registry contents */ ++/* ++ * Copyright (C) 2015 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#include "iana.h" ++ ++static uint8_t edwards25519_M[] = { ++ 0xD0, 0x48, 0x03, 0x2C, 0x6E, 0xA0, 0xB6, 0xD6, 0x97, 0xDD, 0xC2, 0xE8, ++ 0x6B, 0xDA, 0x85, 0xA3, 0x3A, 0xDA, 0xC9, 0x20, 0xF1, 0xBF, 0x18, 0xE1, ++ 0xB0, 0xC6, 0xD1, 0x66, 0xA5, 0xCE, 0xCD, 0xAF ++}; ++ ++static uint8_t edwards25519_N[] = { ++ 0xD3, 0xBF, 0xB5, 0x18, 0xF4, 0x4F, 0x34, 0x30, 0xF2, 0x9D, 0x0C, 0x92, ++ 0xAF, 0x50, 0x38, 0x65, 0xA1, 0xED, 0x32, 0x81, 0xDC, 0x69, 0xB3, 0x5D, ++ 0xD8, 0x68, 0xBA, 0x85, 0xF8, 0x86, 0xC4, 0xAB ++}; ++ ++static uint8_t P256_M[] = { ++ 0x02, 0x88, 0x6E, 0x2F, 0x97, 0xAC, 0xE4, 0x6E, 0x55, 0xBA, 0x9D, 0xD7, ++ 0x24, 0x25, 0x79, 0xF2, 0x99, 0x3B, 0x64, 0xE1, 0x6E, 0xF3, 0xDC, 0xAB, ++ 0x95, 0xAF, 0xD4, 0x97, 0x33, 0x3D, 0x8F, 0xA1, 0x2F ++}; ++ ++static uint8_t P256_N[] = { ++ 0x03, 0xD8, 0xBB, 0xD6, 0xC6, 0x39, 0xC6, 0x29, 0x37, 0xB0, 0x4D, 0x99, ++ 0x7F, 0x38, 0xC3, 0x77, 0x07, 0x19, 0xC6, 0x29, 0xD7, 0x01, 0x4D, 0x49, ++ 0xA2, 0x4B, 0x4F, 0x98, 0xBA, 0xA1, 0x29, 0x2B, 0x49 ++}; ++ ++static uint8_t P384_M[] = { ++ 0x03, 0x0F, 0xF0, 0x89, 0x5A, 0xE5, 0xEB, 0xF6, 0x18, 0x70, 0x80, 0xA8, ++ 0x2D, 0x82, 0xB4, 0x2E, 0x27, 0x65, 0xE3, 0xB2, 0xF8, 0x74, 0x9C, 0x7E, ++ 0x05, 0xEB, 0xA3, 0x66, 0x43, 0x4B, 0x36, 0x3D, 0x3D, 0xC3, 0x6F, 0x15, ++ 0x31, 0x47, 0x39, 0x07, 0x4D, 0x2E, 0xB8, 0x61, 0x3F, 0xCE, 0xEC, 0x28, ++ 0x53 ++}; ++ ++static uint8_t P384_N[] = { ++ 0x02, 0xC7, 0x2C, 0xF2, 0xE3, 0x90, 0x85, 0x3A, 0x1C, 0x1C, 0x4A, 0xD8, ++ 0x16, 0xA6, 0x2F, 0xD1, 0x58, 0x24, 0xF5, 0x60, 0x78, 0x91, 0x8F, 0x43, ++ 0xF9, 0x22, 0xCA, 0x21, 0x51, 0x8F, 0x9C, 0x54, 0x3B, 0xB2, 0x52, 0xC5, ++ 0x49, 0x02, 0x14, 0xCF, 0x9A, 0xA3, 0xF0, 0xBA, 0xAB, 0x4B, 0x66, 0x5C, ++ 0x10 ++}; ++ ++static uint8_t P521_M[] = { ++ 0x02, 0x00, 0x3F, 0x06, 0xF3, 0x81, 0x31, 0xB2, 0xBA, 0x26, 0x00, 0x79, ++ 0x1E, 0x82, 0x48, 0x8E, 0x8D, 0x20, 0xAB, 0x88, 0x9A, 0xF7, 0x53, 0xA4, ++ 0x18, 0x06, 0xC5, 0xDB, 0x18, 0xD3, 0x7D, 0x85, 0x60, 0x8C, 0xFA, 0xE0, ++ 0x6B, 0x82, 0xE4, 0xA7, 0x2C, 0xD7, 0x44, 0xC7, 0x19, 0x19, 0x35, 0x62, ++ 0xA6, 0x53, 0xEA, 0x1F, 0x11, 0x9E, 0xEF, 0x93, 0x56, 0x90, 0x7E, 0xDC, ++ 0x9B, 0x56, 0x97, 0x99, 0x62, 0xD7, 0xAA ++}; ++ ++static uint8_t P521_N[] = { ++ 0x02, 0x00, 0xC7, 0x92, 0x4B, 0x9E, 0xC0, 0x17, 0xF3, 0x09, 0x45, 0x62, ++ 0x89, 0x43, 0x36, 0xA5, 0x3C, 0x50, 0x16, 0x7B, 0xA8, 0xC5, 0x96, 0x38, ++ 0x76, 0x88, 0x05, 0x42, 0xBC, 0x66, 0x9E, 0x49, 0x4B, 0x25, 0x32, 0xD7, ++ 0x6C, 0x5B, 0x53, 0xDF, 0xB3, 0x49, 0xFD, 0xF6, 0x91, 0x54, 0xB9, 0xE0, ++ 0x04, 0x8C, 0x58, 0xA4, 0x2E, 0x8E, 0xD0, 0x4C, 0xEF, 0x05, 0x2A, 0x3B, ++ 0xC3, 0x49, 0xD9, 0x55, 0x75, 0xCD, 0x25 ++}; ++ ++const spake_iana spake_iana_edwards25519 = { ++ SPAKE_GROUP_EDWARDS25519, "edwards25519", 32, 32, ++ edwards25519_M, edwards25519_N, 32 ++}; ++ ++const spake_iana spake_iana_p256 = { ++ SPAKE_GROUP_P256, "P-256", 32, 33, P256_M, P256_N, 32 ++}; ++ ++const spake_iana spake_iana_p384 = { ++ SPAKE_GROUP_P384, "P-384", 48, 49, P384_M, P384_N, 48 ++}; ++ ++const spake_iana spake_iana_p521 = { ++ SPAKE_GROUP_P521, "P-521", 66, 67, P521_M, P521_N, 64 ++}; +diff --git a/src/plugins/preauth/spake/iana.h b/src/plugins/preauth/spake/iana.h +new file mode 100644 +index 000000000..1d99c4dd6 +--- /dev/null ++++ b/src/plugins/preauth/spake/iana.h +@@ -0,0 +1,65 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* plugins/preauth/spake/iana.h - SPAKE IANA registry contents */ ++/* ++ * Copyright (C) 2015 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#ifndef IANA_H ++#define IANA_H ++ ++#include ++#include ++ ++typedef enum { ++ SPAKE_SF_NONE = 1, ++} spake_sf_type; ++ ++typedef enum { ++ SPAKE_GROUP_EDWARDS25519 = 1, ++ SPAKE_GROUP_P256 = 2, ++ SPAKE_GROUP_P384 = 3, ++ SPAKE_GROUP_P521 = 4, ++} spake_group; ++ ++typedef struct { ++ int32_t id; ++ const char *name; ++ size_t mult_len; ++ size_t elem_len; ++ const uint8_t *m; ++ const uint8_t *n; ++ size_t hash_len; ++} spake_iana; ++ ++extern const spake_iana spake_iana_edwards25519; ++extern const spake_iana spake_iana_p256; ++extern const spake_iana spake_iana_p384; ++extern const spake_iana spake_iana_p521; ++ ++#endif /* IANA_H */ +diff --git a/src/plugins/preauth/spake/openssl.c b/src/plugins/preauth/spake/openssl.c +new file mode 100644 +index 000000000..b821a9158 +--- /dev/null ++++ b/src/plugins/preauth/spake/openssl.c +@@ -0,0 +1,315 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* plugins/preauth/spake/openssl.c - SPAKE implementations using OpenSSL */ ++/* ++ * Copyright (C) 2015 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#include "k5-int.h" ++ ++#include "groups.h" ++#include "iana.h" ++ ++#ifdef SPAKE_OPENSSL ++#include ++#include ++#include ++#include ++ ++/* OpenSSL 1.1 standardizes constructor and destructor names, renaming ++ * EVP_MD_CTX_create and EVP_MD_CTX_destroy. */ ++#if OPENSSL_VERSION_NUMBER < 0x10100000L ++#define EVP_MD_CTX_new EVP_MD_CTX_create ++#define EVP_MD_CTX_free EVP_MD_CTX_destroy ++#endif ++ ++struct groupdata_st { ++ const groupdef *gdef; ++ EC_GROUP *group; ++ BIGNUM *order; ++ BN_CTX *ctx; ++ EC_POINT *M; ++ EC_POINT *N; ++ const EVP_MD *md; ++}; ++ ++static void ++ossl_fini(groupdata *gd) ++{ ++ if (gd == NULL) ++ return; ++ ++ EC_GROUP_free(gd->group); ++ EC_POINT_free(gd->M); ++ EC_POINT_free(gd->N); ++ BN_CTX_free(gd->ctx); ++ BN_free(gd->order); ++} ++ ++static krb5_error_code ++ossl_init(krb5_context context, const groupdef *gdef, groupdata **gdata_out) ++{ ++ const spake_iana *reg = gdef->reg; ++ const EVP_MD *md; ++ groupdata *gd; ++ int nid; ++ ++ switch (reg->id) { ++ case SPAKE_GROUP_P256: ++ nid = NID_X9_62_prime256v1; ++ md = EVP_sha256(); ++ break; ++ case SPAKE_GROUP_P384: ++ nid = NID_secp384r1; ++ md = EVP_sha384(); ++ break; ++ case SPAKE_GROUP_P521: ++ nid = NID_secp521r1; ++ md = EVP_sha512(); ++ break; ++ default: ++ return EINVAL; ++ }; ++ ++ gd = calloc(1, sizeof(*gd)); ++ if (gd == NULL) ++ return ENOMEM; ++ gd->gdef = gdef; ++ ++ gd->group = EC_GROUP_new_by_curve_name(nid); ++ if (gd->group == NULL) ++ goto error; ++ ++ gd->ctx = BN_CTX_new(); ++ if (gd->ctx == NULL) ++ goto error; ++ ++ gd->order = BN_new(); ++ if (gd->order == NULL) ++ goto error; ++ if (!EC_GROUP_get_order(gd->group, gd->order, gd->ctx)) ++ goto error; ++ ++ gd->M = EC_POINT_new(gd->group); ++ if (gd->M == NULL) ++ goto error; ++ if (!EC_POINT_oct2point(gd->group, gd->M, reg->m, reg->elem_len, gd->ctx)) ++ goto error; ++ ++ gd->N = EC_POINT_new(gd->group); ++ if (gd->N == NULL) ++ goto error; ++ if (!EC_POINT_oct2point(gd->group, gd->N, reg->n, reg->elem_len, gd->ctx)) ++ goto error; ++ ++ gd->md = md; ++ ++ *gdata_out = gd; ++ return 0; ++ ++error: ++ ossl_fini(gd); ++ return ENOMEM; ++} ++ ++/* Convert pseudo-random bytes into a scalar value in constant time. ++ * Return NULL on failure. */ ++static BIGNUM * ++unmarshal_w(const groupdata *gdata, const uint8_t *wbytes) ++{ ++ const spake_iana *reg = gdata->gdef->reg; ++ BIGNUM *w = NULL; ++ ++ w = BN_new(); ++ if (w == NULL) ++ return NULL; ++ ++ BN_set_flags(w, BN_FLG_CONSTTIME); ++ ++ if (BN_bin2bn(wbytes, reg->mult_len, w) && ++ BN_div(NULL, w, w, gdata->order, gdata->ctx)) ++ return w; ++ ++ BN_free(w); ++ return NULL; ++} ++ ++static krb5_error_code ++ossl_keygen(krb5_context context, groupdata *gdata, const uint8_t *wbytes, ++ krb5_boolean use_m, uint8_t *priv_out, uint8_t *pub_out) ++{ ++ const spake_iana *reg = gdata->gdef->reg; ++ const EC_POINT *constant = use_m ? gdata->M : gdata->N; ++ krb5_boolean success = FALSE; ++ EC_POINT *pub = NULL; ++ BIGNUM *priv = NULL, *w = NULL; ++ size_t len; ++ ++ w = unmarshal_w(gdata, wbytes); ++ if (w == NULL) ++ goto cleanup; ++ ++ pub = EC_POINT_new(gdata->group); ++ if (pub == NULL) ++ goto cleanup; ++ ++ priv = BN_new(); ++ if (priv == NULL) ++ goto cleanup; ++ ++ if (!BN_rand_range(priv, gdata->order)) ++ goto cleanup; ++ ++ /* Compute priv*G + w*constant; EC_POINT_mul() does this in one call. */ ++ if (!EC_POINT_mul(gdata->group, pub, priv, constant, w, gdata->ctx)) ++ goto cleanup; ++ ++ /* Marshal priv into priv_out. */ ++ memset(priv_out, 0, reg->mult_len); ++ BN_bn2bin(priv, &priv_out[reg->mult_len - BN_num_bytes(priv)]); ++ ++ /* Marshal pub into pub_out. */ ++ len = EC_POINT_point2oct(gdata->group, pub, POINT_CONVERSION_COMPRESSED, ++ pub_out, reg->elem_len, gdata->ctx); ++ if (len != reg->elem_len) ++ goto cleanup; ++ ++ success = TRUE; ++ ++cleanup: ++ EC_POINT_free(pub); ++ BN_clear_free(priv); ++ BN_clear_free(w); ++ return success ? 0 : ENOMEM; ++} ++ ++static krb5_error_code ++ossl_result(krb5_context context, groupdata *gdata, const uint8_t *wbytes, ++ const uint8_t *ourpriv, const uint8_t *theirpub, ++ krb5_boolean use_m, uint8_t *elem_out) ++{ ++ const spake_iana *reg = gdata->gdef->reg; ++ const EC_POINT *constant = use_m ? gdata->M : gdata->N; ++ krb5_boolean success = FALSE, invalid = FALSE; ++ EC_POINT *result = NULL, *pub = NULL; ++ BIGNUM *priv = NULL, *w = NULL; ++ size_t len; ++ ++ w = unmarshal_w(gdata, wbytes); ++ if (w == NULL) ++ goto cleanup; ++ ++ priv = BN_bin2bn(ourpriv, reg->mult_len, NULL); ++ if (priv == NULL) ++ goto cleanup; ++ ++ pub = EC_POINT_new(gdata->group); ++ if (pub == NULL) ++ goto cleanup; ++ if (!EC_POINT_oct2point(gdata->group, pub, theirpub, reg->elem_len, ++ gdata->ctx)) { ++ invalid = TRUE; ++ goto cleanup; ++ } ++ ++ /* Compute result = priv*(pub - w*constant), using result to hold the ++ * intermediate steps. */ ++ result = EC_POINT_new(gdata->group); ++ if (result == NULL) ++ goto cleanup; ++ if (!EC_POINT_mul(gdata->group, result, NULL, constant, w, gdata->ctx)) ++ goto cleanup; ++ if (!EC_POINT_invert(gdata->group, result, gdata->ctx)) ++ goto cleanup; ++ if (!EC_POINT_add(gdata->group, result, pub, result, gdata->ctx)) ++ goto cleanup; ++ if (!EC_POINT_mul(gdata->group, result, NULL, result, priv, gdata->ctx)) ++ goto cleanup; ++ ++ /* Marshal result into elem_out. */ ++ len = EC_POINT_point2oct(gdata->group, result, POINT_CONVERSION_COMPRESSED, ++ elem_out, reg->elem_len, gdata->ctx); ++ if (len != reg->elem_len) ++ goto cleanup; ++ ++ success = TRUE; ++ ++cleanup: ++ BN_clear_free(priv); ++ BN_clear_free(w); ++ EC_POINT_free(pub); ++ EC_POINT_clear_free(result); ++ return invalid ? EINVAL : (success ? 0 : ENOMEM); ++} ++ ++static krb5_error_code ++ossl_hash(krb5_context context, groupdata *gdata, const krb5_data *dlist, ++ size_t ndata, uint8_t *result_out) ++{ ++ EVP_MD_CTX *ctx; ++ size_t i; ++ int ok; ++ ++ ctx = EVP_MD_CTX_new(); ++ if (ctx == NULL) ++ return ENOMEM; ++ ok = EVP_DigestInit_ex(ctx, gdata->md, NULL); ++ for (i = 0; i < ndata; i++) ++ ok = ok && EVP_DigestUpdate(ctx, dlist[i].data, dlist[i].length); ++ ok = ok && EVP_DigestFinal_ex(ctx, result_out, NULL); ++ EVP_MD_CTX_free(ctx); ++ return ok ? 0 : ENOMEM; ++} ++ ++groupdef ossl_P256 = { ++ .reg = &spake_iana_p256, ++ .init = ossl_init, ++ .fini = ossl_fini, ++ .keygen = ossl_keygen, ++ .result = ossl_result, ++ .hash = ossl_hash, ++}; ++ ++groupdef ossl_P384 = { ++ .reg = &spake_iana_p384, ++ .init = ossl_init, ++ .fini = ossl_fini, ++ .keygen = ossl_keygen, ++ .result = ossl_result, ++ .hash = ossl_hash, ++}; ++ ++groupdef ossl_P521 = { ++ .reg = &spake_iana_p521, ++ .init = ossl_init, ++ .fini = ossl_fini, ++ .keygen = ossl_keygen, ++ .result = ossl_result, ++ .hash = ossl_hash, ++}; ++#endif /* SPAKE_OPENSSL */ +diff --git a/src/plugins/preauth/spake/spake.exports b/src/plugins/preauth/spake/spake.exports +new file mode 100644 +index 000000000..81d100228 +--- /dev/null ++++ b/src/plugins/preauth/spake/spake.exports +@@ -0,0 +1,2 @@ ++clpreauth_spake_initvt ++kdcpreauth_spake_initvt +diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c +new file mode 100644 +index 000000000..d72bd64aa +--- /dev/null ++++ b/src/plugins/preauth/spake/spake_client.c +@@ -0,0 +1,363 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* plugins/preauth/spake/spake_client.c - SPAKE clpreauth module */ ++/* ++ * Copyright (C) 2015 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#include "k5-int.h" ++#include "k5-spake.h" ++#include "trace.h" ++#include "util.h" ++#include "iana.h" ++#include "groups.h" ++#include ++ ++typedef struct reqstate_st { ++ krb5_keyblock *initial_key; ++ krb5_data *support; ++ krb5_data thash; ++ krb5_data spakeresult; ++} reqstate; ++ ++static krb5_error_code ++spake_init(krb5_context context, krb5_clpreauth_moddata *moddata_out) ++{ ++ krb5_error_code ret; ++ groupstate *gstate; ++ ++ ret = group_init_state(context, FALSE, &gstate); ++ if (ret) ++ return ret; ++ *moddata_out = (krb5_clpreauth_moddata)gstate; ++ return 0; ++} ++ ++static void ++spake_fini(krb5_context context, krb5_clpreauth_moddata moddata) ++{ ++ group_free_state((groupstate *)moddata); ++} ++ ++static void ++spake_request_init(krb5_context context, krb5_clpreauth_moddata moddata, ++ krb5_clpreauth_modreq *modreq_out) ++{ ++ *modreq_out = calloc(1, sizeof(reqstate)); ++} ++ ++static void ++spake_request_fini(krb5_context context, krb5_clpreauth_moddata moddata, ++ krb5_clpreauth_modreq modreq) ++{ ++ reqstate *st = (reqstate *)modreq; ++ ++ krb5_free_keyblock(context, st->initial_key); ++ krb5_free_data(context, st->support); ++ krb5_free_data_contents(context, &st->thash); ++ zapfree(st->spakeresult.data, st->spakeresult.length); ++ free(st); ++} ++ ++static krb5_error_code ++spake_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata, ++ krb5_clpreauth_modreq modreq, ++ krb5_get_init_creds_opt *opt, krb5_clpreauth_callbacks cb, ++ krb5_clpreauth_rock rock, krb5_kdc_req *req, ++ krb5_data *enc_req, krb5_data *enc_prev_req, ++ krb5_pa_data *pa_data) ++{ ++ reqstate *st = (reqstate *)modreq; ++ ++ if (st == NULL) ++ return ENOMEM; ++ if (st->initial_key == NULL && pa_data->length > 0) ++ cb->need_as_key(context, rock); ++ ++ /* When second-factor is implemented, we should ask questions based on the ++ * factors in the challenge. */ ++ ++ return 0; ++} ++ ++/* ++ * Output a PA-SPAKE support message indicating which groups we support. This ++ * may be done for optimistic preauth, in response to an empty message, or in ++ * response to a challenge using a group we do not support. Save the support ++ * message in st->support. ++ */ ++static krb5_error_code ++send_support(krb5_context context, groupstate *gstate, reqstate *st, ++ krb5_pa_data ***pa_out) ++{ ++ krb5_error_code ret; ++ krb5_data *support; ++ krb5_pa_spake msg; ++ ++ msg.choice = SPAKE_MSGTYPE_SUPPORT; ++ group_get_permitted(gstate, &msg.u.support.groups, &msg.u.support.ngroups); ++ ret = encode_krb5_pa_spake(&msg, &support); ++ if (ret) ++ return ret; ++ ++ /* Save the support message for later use in the transcript hash. */ ++ ret = krb5_copy_data(context, support, &st->support); ++ if (ret) { ++ krb5_free_data(context, support); ++ return ret; ++ } ++ ++ TRACE_SPAKE_SEND_SUPPORT(context); ++ return convert_to_padata(support, pa_out); ++} ++ ++/* Return true if SF-NONE is present in factors. */ ++static krb5_boolean ++contains_sf_none(krb5_spake_factor **factors) ++{ ++ int i; ++ ++ for (i = 0; factors != NULL && factors[i] != NULL; i++) { ++ if (factors[i]->type == SPAKE_SF_NONE) ++ return TRUE; ++ } ++ return FALSE; ++} ++ ++static krb5_error_code ++process_challenge(krb5_context context, groupstate *gstate, reqstate *st, ++ krb5_spake_challenge *ch, const krb5_data *der_msg, ++ krb5_clpreauth_callbacks cb, krb5_clpreauth_rock rock, ++ krb5_prompter_fct prompter, void *prompter_data, ++ const krb5_data *der_req, krb5_pa_data ***pa_out) ++{ ++ krb5_error_code ret; ++ krb5_keyblock *k0 = NULL, *k1 = NULL; ++ krb5_spake_factor factor; ++ krb5_pa_spake msg; ++ krb5_data *der_factor = NULL, *response; ++ krb5_data clpriv = empty_data(), clpub = empty_data(); ++ krb5_data wbytes = empty_data(); ++ krb5_enc_data enc_factor; ++ ++ enc_factor.ciphertext = empty_data(); ++ ++ /* Not expected if we already computed the SPAKE result. */ ++ if (st->spakeresult.length != 0) ++ return KRB5KDC_ERR_PREAUTH_FAILED; ++ ++ if (!group_is_permitted(gstate, ch->group)) { ++ TRACE_SPAKE_REJECT_CHALLENGE(context, ch->group); ++ /* No point in sending a second support message. */ ++ if (st->support != NULL) ++ return KRB5KDC_ERR_PREAUTH_FAILED; ++ return send_support(context, gstate, st, pa_out); ++ } ++ ++ /* Initialize and update the transcript with the concatenation of the ++ * support message (if we sent one) and the received challenge. */ ++ ret = update_thash(context, gstate, ch->group, &st->thash, st->support, ++ der_msg); ++ if (ret) ++ return ret; ++ ++ TRACE_SPAKE_RECEIVE_CHALLENGE(context, ch->group, &ch->pubkey); ++ ++ /* When second factor support is implemented, we should check for a ++ * supported factor type instead of just checking for SF-NONE. */ ++ if (!contains_sf_none(ch->factors)) ++ return KRB5KDC_ERR_PREAUTH_FAILED; ++ ++ ret = derive_wbytes(context, ch->group, st->initial_key, &wbytes); ++ if (ret) ++ goto cleanup; ++ ret = group_keygen(context, gstate, ch->group, &wbytes, &clpriv, &clpub); ++ if (ret) ++ goto cleanup; ++ ret = group_result(context, gstate, ch->group, &wbytes, &clpriv, ++ &ch->pubkey, &st->spakeresult); ++ if (ret) ++ goto cleanup; ++ ++ ret = update_thash(context, gstate, ch->group, &st->thash, &clpub, NULL); ++ if (ret) ++ goto cleanup; ++ TRACE_SPAKE_CLIENT_THASH(context, &st->thash); ++ ++ /* Replace the reply key with K'[0]. */ ++ ret = derive_key(context, gstate, ch->group, st->initial_key, &wbytes, ++ &st->spakeresult, &st->thash, der_req, 0, &k0); ++ if (ret) ++ goto cleanup; ++ ret = cb->set_as_key(context, rock, k0); ++ if (ret) ++ goto cleanup; ++ ++ /* Encrypt a SPAKESecondFactor message with K'[1]. */ ++ ret = derive_key(context, gstate, ch->group, st->initial_key, &wbytes, ++ &st->spakeresult, &st->thash, der_req, 1, &k1); ++ if (ret) ++ goto cleanup; ++ /* When second factor support is implemented, we should construct an ++ * appropriate factor here instead of hardcoding SF-NONE. */ ++ factor.type = SPAKE_SF_NONE; ++ factor.data = NULL; ++ ret = encode_krb5_spake_factor(&factor, &der_factor); ++ if (ret) ++ goto cleanup; ++ ret = krb5_encrypt_helper(context, k1, KRB5_KEYUSAGE_SPAKE, der_factor, ++ &enc_factor); ++ if (ret) ++ goto cleanup; ++ ++ /* Encode and output a response message. */ ++ msg.choice = SPAKE_MSGTYPE_RESPONSE; ++ msg.u.response.pubkey = clpub; ++ msg.u.response.factor = enc_factor; ++ ret = encode_krb5_pa_spake(&msg, &response); ++ if (ret) ++ goto cleanup; ++ TRACE_SPAKE_SEND_RESPONSE(context); ++ ret = convert_to_padata(response, pa_out); ++ ++cleanup: ++ krb5_free_keyblock(context, k0); ++ krb5_free_keyblock(context, k1); ++ krb5_free_data_contents(context, &enc_factor.ciphertext); ++ krb5_free_data_contents(context, &clpub); ++ zapfree(clpriv.data, clpriv.length); ++ zapfree(wbytes.data, wbytes.length); ++ if (der_factor != NULL) { ++ zapfree(der_factor->data, der_factor->length); ++ free(der_factor); ++ } ++ return ret; ++} ++ ++static krb5_error_code ++process_encdata(krb5_context context, reqstate *st, krb5_enc_data *enc, ++ krb5_clpreauth_callbacks cb, krb5_clpreauth_rock rock, ++ krb5_prompter_fct prompter, void *prompter_data, ++ const krb5_data *der_prev_req, const krb5_data *der_req, ++ krb5_pa_data ***pa_out) ++{ ++ /* Not expected if we haven't sent a response yet. */ ++ if (st->spakeresult.length == 0) ++ return KRB5KDC_ERR_PREAUTH_FAILED; ++ ++ /* ++ * When second factor support is implemented, we should process encdata ++ * messages according to the factor type. We should make sure to re-derive ++ * K'[0] and replace the reply key again, in case the request has changed. ++ * We should use der_prev_req to derive K'[n] to decrypt factor from the ++ * KDC. We should use der_req to derive K'[n+1] for the next message to ++ * send to the KDC. ++ */ ++ return KRB5_PLUGIN_OP_NOTSUPP; ++} ++ ++static krb5_error_code ++spake_process(krb5_context context, krb5_clpreauth_moddata moddata, ++ krb5_clpreauth_modreq modreq, krb5_get_init_creds_opt *opt, ++ krb5_clpreauth_callbacks cb, krb5_clpreauth_rock rock, ++ krb5_kdc_req *req, krb5_data *der_req, krb5_data *der_prev_req, ++ krb5_pa_data *pa_in, krb5_prompter_fct prompter, ++ void *prompter_data, krb5_pa_data ***pa_out) ++{ ++ krb5_error_code ret; ++ groupstate *gstate = (groupstate *)moddata; ++ reqstate *st = (reqstate *)modreq; ++ krb5_pa_spake *msg; ++ krb5_data in_data; ++ krb5_keyblock *as_key; ++ ++ if (st == NULL) ++ return ENOMEM; ++ ++ if (pa_in->length == 0) { ++ /* Not expected if we already sent a support message. */ ++ if (st->support != NULL) ++ return KRB5KDC_ERR_PREAUTH_FAILED; ++ return send_support(context, gstate, st, pa_out); ++ } ++ ++ /* We need the initial reply key to process any non-trivial message. */ ++ if (st->initial_key == NULL) { ++ ret = cb->get_as_key(context, rock, &as_key); ++ if (ret) ++ return ret; ++ ret = krb5_copy_keyblock(context, as_key, &st->initial_key); ++ if (ret) ++ return ret; ++ } ++ ++ in_data = make_data(pa_in->contents, pa_in->length); ++ ret = decode_krb5_pa_spake(&in_data, &msg); ++ if (ret) ++ return ret; ++ ++ if (msg->choice == SPAKE_MSGTYPE_CHALLENGE) { ++ ret = process_challenge(context, gstate, st, &msg->u.challenge, ++ &in_data, cb, rock, prompter, prompter_data, ++ der_req, pa_out); ++ } else if (msg->choice == SPAKE_MSGTYPE_ENCDATA) { ++ ret = process_encdata(context, st, &msg->u.encdata, cb, rock, prompter, ++ prompter_data, der_prev_req, der_req, pa_out); ++ } else { ++ /* Unexpected message type */ ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ } ++ ++ k5_free_pa_spake(context, msg); ++ return ret; ++} ++ ++krb5_error_code ++clpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, ++ krb5_plugin_vtable vtable); ++ ++krb5_error_code ++clpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, ++ krb5_plugin_vtable vtable) ++{ ++ krb5_clpreauth_vtable vt; ++ static krb5_preauthtype pa_types[] = { KRB5_PADATA_SPAKE, 0 }; ++ ++ if (maj_ver != 1) ++ return KRB5_PLUGIN_VER_NOTSUPP; ++ vt = (krb5_clpreauth_vtable)vtable; ++ vt->name = "spake"; ++ vt->pa_type_list = pa_types; ++ vt->init = spake_init; ++ vt->fini = spake_fini; ++ vt->request_init = spake_request_init; ++ vt->request_fini = spake_request_fini; ++ vt->process = spake_process; ++ vt->prep_questions = spake_prep_questions; ++ return 0; ++} +diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c +new file mode 100644 +index 000000000..c1723ebaf +--- /dev/null ++++ b/src/plugins/preauth/spake/spake_kdc.c +@@ -0,0 +1,590 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* plugins/preauth/spake/spake_kdc.c - SPAKE kdcpreauth module */ ++/* ++ * Copyright (C) 2015 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#include "k5-int.h" ++#include "k5-input.h" ++#include "k5-spake.h" ++ ++#include "groups.h" ++#include "trace.h" ++#include "iana.h" ++#include "util.h" ++ ++#include ++ ++/* ++ * The SPAKE kdcpreauth module uses a secure cookie containing the following ++ * concatenated fields (all integer fields are big-endian): ++ * ++ * version (16-bit unsigned integer) ++ * stage (16-bit unsigned integer) ++ * group (32-bit signed integer) ++ * SPAKE value (32-bit unsigned length, followed by data) ++ * Transcript hash (32-bit unsigned length, followed by data) ++ * Zero or more instances of: ++ * second-factor number (32-bit signed integer) ++ * second-factor data (32-bit unsigned length, followed by data) ++ * ++ * The only currently supported version is 1. stage is 0 if the cookie was ++ * sent with a challenge message. stage is n>0 if the cookie was sent with an ++ * encdata message encrypted in K'[2n]. group indicates the group number used ++ * in the SPAKE challenge. The SPAKE value is the KDC private key for a ++ * stage-0 cookie, represented in the scalar marshalling form of the group; for ++ * other cookies, the SPAKE value is the SPAKE result K, represented in the ++ * group element marshalling form. The transcript hash is the intermediate ++ * hash after updating with the support and challenge messages for a stage-0 ++ * cookie, or the final hash for other cookies. For a stage 0 cookie, there ++ * may be any number of second-factor records, including none (no record is ++ * generated for SF-NONE); for other cookies, there must be exactly one ++ * second-factor record corresponding to the factor type chosen by the client. ++ */ ++ ++/* From a k5input structure representing the remainder of a secure cookie ++ * plaintext, parse a four-byte length and data. */ ++static void ++parse_data(struct k5input *in, krb5_data *out) ++{ ++ out->length = k5_input_get_uint32_be(in); ++ out->data = (char *)k5_input_get_bytes(in, out->length); ++} ++ ++/* Parse a received cookie into its components. The pointers stored in the ++ * krb5_data outputs are aliases into cookie and should not be freed. */ ++static krb5_error_code ++parse_cookie(const krb5_data *cookie, int *stage_out, int32_t *group_out, ++ krb5_data *spake_out, krb5_data *thash_out, ++ krb5_data *factors_out) ++{ ++ struct k5input in; ++ int version, stage; ++ int32_t group; ++ krb5_data thash, spake, factors; ++ ++ *spake_out = *thash_out = *factors_out = empty_data(); ++ k5_input_init(&in, cookie->data, cookie->length); ++ ++ /* Parse and check the version, and read the other integer fields. */ ++ version = k5_input_get_uint16_be(&in); ++ if (version != 1) ++ return KRB5KDC_ERR_PREAUTH_FAILED; ++ stage = k5_input_get_uint16_be(&in); ++ group = k5_input_get_uint32_be(&in); ++ ++ /* Parse the data fields. The factor data is anything remaining after the ++ * transcript hash. */ ++ parse_data(&in, &spake); ++ parse_data(&in, &thash); ++ if (in.status) ++ return in.status; ++ factors = make_data((char *)in.ptr, in.len); ++ ++ *stage_out = stage; ++ *group_out = group; ++ *spake_out = spake; ++ *thash_out = thash; ++ *factors_out = factors; ++ return 0; ++} ++ ++/* Marshal data into buf as a four-byte length followed by the contents. */ ++static void ++marshal_data(struct k5buf *buf, const krb5_data *data) ++{ ++ uint8_t lenbuf[4]; ++ ++ store_32_be(data->length, lenbuf); ++ k5_buf_add_len(buf, lenbuf, 4); ++ k5_buf_add_len(buf, data->data, data->length); ++} ++ ++/* Marshal components into a cookie. */ ++static krb5_error_code ++make_cookie(int stage, int32_t group, const krb5_data *spake, ++ const krb5_data *thash, krb5_data *cookie_out) ++{ ++ struct k5buf buf; ++ uint8_t intbuf[4]; ++ ++ *cookie_out = empty_data(); ++ k5_buf_init_dynamic_zap(&buf); ++ ++ /* Marshal the version, stage, and group. */ ++ store_16_be(1, intbuf); ++ k5_buf_add_len(&buf, intbuf, 2); ++ store_16_be(stage, intbuf); ++ k5_buf_add_len(&buf, intbuf, 2); ++ store_32_be(group, intbuf); ++ k5_buf_add_len(&buf, intbuf, 4); ++ ++ /* Marshal the data fields. */ ++ marshal_data(&buf, spake); ++ marshal_data(&buf, thash); ++ ++ /* When second factor support is implemented, we should add factor data ++ * here. */ ++ ++ if (buf.data == NULL) ++ return ENOMEM; ++ *cookie_out = make_data(buf.data, buf.len); ++ return 0; ++} ++ ++/* Add authentication indicators if any are configured for SPAKE. */ ++static krb5_error_code ++add_indicators(krb5_context context, const krb5_data *realm, ++ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock) ++{ ++ krb5_error_code ret; ++ const char *keys[4]; ++ char *realmstr, **indicators, **ind; ++ ++ realmstr = k5memdup0(realm->data, realm->length, &ret); ++ if (realmstr == NULL) ++ return ret; ++ keys[0] = KRB5_CONF_REALMS; ++ keys[1] = realmstr; ++ keys[2] = KRB5_CONF_SPAKE_PREAUTH_INDICATOR; ++ keys[3] = NULL; ++ ret = profile_get_values(context->profile, keys, &indicators); ++ free(realmstr); ++ if (ret == PROF_NO_RELATION) ++ return 0; ++ if (ret) ++ return ret; ++ ++ for (ind = indicators; *ind != NULL && !ret; ind++) ++ ret = cb->add_auth_indicator(context, rock, *ind); ++ ++ profile_free_list(indicators); ++ return ret; ++} ++ ++/* Initialize a SPAKE module data object. */ ++static krb5_error_code ++spake_init(krb5_context context, krb5_kdcpreauth_moddata *moddata_out, ++ const char **realmnames) ++{ ++ krb5_error_code ret; ++ groupstate *gstate; ++ ++ ret = group_init_state(context, TRUE, &gstate); ++ if (ret) ++ return ret; ++ *moddata_out = (krb5_kdcpreauth_moddata)gstate; ++ return 0; ++} ++ ++/* Release a SPAKE module data object. */ ++static void ++spake_fini(krb5_context context, krb5_kdcpreauth_moddata moddata) ++{ ++ group_free_state((groupstate *)moddata); ++} ++ ++/* ++ * Generate a SPAKE challenge message for the specified group. Use cb and rock ++ * to retrieve the initial reply key and to set a stage-0 cookie. Invoke ++ * either erespond or vrespond with the result. ++ */ ++static void ++send_challenge(krb5_context context, groupstate *gstate, int32_t group, ++ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, ++ const krb5_data *support, ++ krb5_kdcpreauth_edata_respond_fn erespond, ++ krb5_kdcpreauth_verify_respond_fn vrespond, void *arg) ++{ ++ krb5_error_code ret; ++ const krb5_keyblock *ikey; ++ krb5_pa_data **padata = NULL, *pa; ++ krb5_data kdcpriv = empty_data(), kdcpub = empty_data(), *der_msg = NULL; ++ krb5_data thash = empty_data(), cookie = empty_data(); ++ krb5_data wbytes = empty_data(); ++ krb5_spake_factor f, *flist[2]; ++ krb5_pa_spake msg; ++ ++ ikey = cb->client_keyblock(context, rock); ++ if (ikey == NULL) { ++ ret = KRB5KDC_ERR_ETYPE_NOSUPP; ++ goto cleanup; ++ } ++ ++ ret = derive_wbytes(context, group, ikey, &wbytes); ++ if (ret) ++ goto cleanup; ++ ret = group_keygen(context, gstate, group, &wbytes, &kdcpriv, &kdcpub); ++ if (ret) ++ goto cleanup; ++ ++ /* Encode the challenge. When second factor support is implemented, we ++ * should construct a factor list instead of hardcoding SF-NONE. */ ++ f.type = SPAKE_SF_NONE; ++ f.data = NULL; ++ flist[0] = &f; ++ flist[1] = NULL; ++ msg.choice = SPAKE_MSGTYPE_CHALLENGE; ++ msg.u.challenge.group = group; ++ msg.u.challenge.pubkey = kdcpub; ++ msg.u.challenge.factors = flist; ++ ret = encode_krb5_pa_spake(&msg, &der_msg); ++ if (ret) ++ goto cleanup; ++ ++ /* Initialize and update the transcript hash with the support message (if ++ * we received one) and challenge message. */ ++ ret = update_thash(context, gstate, group, &thash, support, der_msg); ++ if (ret) ++ goto cleanup; ++ ++ /* Save the group, transcript hash, and private key in a stage-0 cookie. ++ * When second factor support is implemented, also save factor state. */ ++ ret = make_cookie(0, group, &kdcpriv, &thash, &cookie); ++ if (ret) ++ goto cleanup; ++ ret = cb->set_cookie(context, rock, KRB5_PADATA_SPAKE, &cookie); ++ if (ret) ++ goto cleanup; ++ ++ ret = convert_to_padata(der_msg, &padata); ++ der_msg = NULL; ++ TRACE_SPAKE_SEND_CHALLENGE(context, group); ++ ++cleanup: ++ zapfree(wbytes.data, wbytes.length); ++ zapfree(kdcpriv.data, kdcpriv.length); ++ zapfree(cookie.data, cookie.length); ++ krb5_free_data_contents(context, &kdcpub); ++ krb5_free_data_contents(context, &thash); ++ krb5_free_data(context, der_msg); ++ ++ if (erespond != NULL) { ++ assert(vrespond == NULL); ++ /* Grab the first pa-data element from the list, if we made one. */ ++ pa = (padata == NULL) ? NULL : padata[0]; ++ free(padata); ++ (*erespond)(arg, ret, pa); ++ } else { ++ assert(vrespond != NULL); ++ if (!ret) ++ ret = KRB5KDC_ERR_MORE_PREAUTH_DATA_REQUIRED; ++ (*vrespond)(arg, ret, NULL, padata, NULL); ++ } ++} ++ ++/* Generate the METHOD-DATA entry indicating support for SPAKE. Include an ++ * optimistic challenge if configured to do so. */ ++static void ++spake_edata(krb5_context context, krb5_kdc_req *req, ++ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, ++ krb5_kdcpreauth_moddata moddata, krb5_preauthtype pa_type, ++ krb5_kdcpreauth_edata_respond_fn respond, void *arg) ++{ ++ const krb5_keyblock *ikey; ++ groupstate *gstate = (groupstate *)moddata; ++ krb5_data empty = empty_data(); ++ int32_t group; ++ ++ /* SPAKE requires a client key, which cannot be a single-DES key. */ ++ ikey = cb->client_keyblock(context, rock); ++ if (ikey == NULL) { ++ (*respond)(arg, KRB5KDC_ERR_ETYPE_NOSUPP, NULL); ++ return; ++ } ++ ++ group = group_optimistic_challenge(gstate); ++ if (group) { ++ send_challenge(context, gstate, group, cb, rock, &empty, respond, NULL, ++ arg); ++ } else { ++ /* No optimistic challenge configured; send an empty pa-data value. */ ++ (*respond)(arg, 0, NULL); ++ } ++} ++ ++/* Choose a group from the client's support message and generate a ++ * challenge. */ ++static void ++verify_support(krb5_context context, groupstate *gstate, ++ krb5_spake_support *support, const krb5_data *der_msg, ++ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, ++ krb5_kdcpreauth_verify_respond_fn respond, void *arg) ++{ ++ krb5_error_code ret; ++ int32_t i, group; ++ ++ for (i = 0; i < support->ngroups; i++) { ++ if (group_is_permitted(gstate, support->groups[i])) ++ break; ++ } ++ if (i == support->ngroups) { ++ TRACE_SPAKE_REJECT_SUPPORT(context); ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto error; ++ } ++ group = support->groups[i]; ++ TRACE_SPAKE_RECEIVE_SUPPORT(context, group); ++ ++ send_challenge(context, gstate, group, cb, rock, der_msg, NULL, respond, ++ arg); ++ return; ++ ++error: ++ (*respond)(arg, ret, NULL, NULL, NULL); ++} ++ ++/* ++ * From the client's response message, compute the SPAKE result and decrypt the ++ * factor reply. On success, either mark the reply as pre-authenticated and ++ * set a reply key in the pre-request module data, or generate an additional ++ * factor challenge and ask for another round of pre-authentication. ++ */ ++static void ++verify_response(krb5_context context, groupstate *gstate, ++ krb5_spake_response *resp, const krb5_data *realm, ++ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, ++ krb5_enc_tkt_part *enc_tkt_reply, ++ krb5_kdcpreauth_verify_respond_fn respond, void *arg) ++{ ++ krb5_error_code ret; ++ const krb5_keyblock *ikey; ++ krb5_keyblock *k1 = NULL, *reply_key = NULL; ++ krb5_data cookie, thash_in, kdcpriv, factors, *der_req; ++ krb5_data thash = empty_data(), der_factor = empty_data(); ++ krb5_data wbytes = empty_data(), spakeresult = empty_data(); ++ krb5_spake_factor *factor = NULL; ++ int stage; ++ int32_t group; ++ ++ ikey = cb->client_keyblock(context, rock); ++ if (ikey == NULL) { ++ ret = KRB5KDC_ERR_ETYPE_NOSUPP; ++ goto cleanup; ++ } ++ ++ /* Fetch the stage-0 cookie and parse it. (All of the krb5_data results ++ * are aliases into memory owned by rock). */ ++ if (!cb->get_cookie(context, rock, KRB5_PADATA_SPAKE, &cookie)) { ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; ++ } ++ ret = parse_cookie(&cookie, &stage, &group, &kdcpriv, &thash_in, &factors); ++ if (ret) ++ goto cleanup; ++ if (stage != 0) { ++ /* The received cookie wasn't sent with a challenge. */ ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; ++ } ++ TRACE_SPAKE_RECEIVE_RESPONSE(context, &resp->pubkey); ++ ++ /* Update the transcript hash with the client public key. */ ++ ret = krb5int_copy_data_contents(context, &thash_in, &thash); ++ if (ret) ++ goto cleanup; ++ ret = update_thash(context, gstate, group, &thash, &resp->pubkey, NULL); ++ if (ret) ++ goto cleanup; ++ TRACE_SPAKE_KDC_THASH(context, &thash); ++ ++ ret = derive_wbytes(context, group, ikey, &wbytes); ++ if (ret) ++ goto cleanup; ++ ret = group_result(context, gstate, group, &wbytes, &kdcpriv, ++ &resp->pubkey, &spakeresult); ++ if (ret) ++ goto cleanup; ++ ++ /* Decrypt the response factor field using K'[1]. If the decryption ++ * integrity check fails, the client probably used the wrong password. */ ++ der_req = cb->request_body(context, rock); ++ ret = derive_key(context, gstate, group, ikey, &wbytes, &spakeresult, ++ &thash, der_req, 1, &k1); ++ if (ret) ++ goto cleanup; ++ ret = alloc_data(&der_factor, resp->factor.ciphertext.length); ++ if (ret) ++ goto cleanup; ++ ret = krb5_c_decrypt(context, k1, KRB5_KEYUSAGE_SPAKE, NULL, &resp->factor, ++ &der_factor); ++ if (ret == KRB5KRB_AP_ERR_BAD_INTEGRITY) ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ if (ret) ++ goto cleanup; ++ ret = decode_krb5_spake_factor(&der_factor, &factor); ++ if (ret) ++ goto cleanup; ++ ++ /* ++ * When second factor support is implemented, we should verify the factor ++ * data here, and possibly generate an encdata message for another hop. ++ * This function may need to be split at this point to allow for ++ * asynchronous verification of the second-factor value. We might also ++ * need to collect authentication indicators from the second-factor module; ++ * alternatively the module could have access to cb and rock so that it can ++ * add indicators itself. ++ */ ++ if (factor->type != SPAKE_SF_NONE) { ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; ++ } ++ ++ ret = add_indicators(context, realm, cb, rock); ++ if (ret) ++ goto cleanup; ++ ++ enc_tkt_reply->flags |= TKT_FLG_PRE_AUTH; ++ ++ ret = derive_key(context, gstate, group, ikey, &wbytes, &spakeresult, ++ &thash, der_req, 0, &reply_key); ++ ++cleanup: ++ zapfree(wbytes.data, wbytes.length); ++ zapfree(der_factor.data, der_factor.length); ++ zapfree(spakeresult.data, spakeresult.length); ++ krb5_free_data_contents(context, &thash); ++ krb5_free_keyblock(context, k1); ++ k5_free_spake_factor(context, factor); ++ (*respond)(arg, ret, (krb5_kdcpreauth_modreq)reply_key, NULL, NULL); ++} ++ ++/* ++ * Decrypt and validate an additional second-factor reply. On success, either ++ * mark the reply as pre-authenticated and set a reply key in the pre-request ++ * module data, or generate an additional factor challenge and ask for another ++ * round of pre-authentication. ++ */ ++static void ++verify_encdata(krb5_context context, krb5_enc_data *enc, ++ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, ++ krb5_enc_tkt_part *enc_tkt_reply, ++ krb5_kdcpreauth_verify_respond_fn respond, void *arg) ++{ ++ /* ++ * When second factor support is implemented, we should process encdata ++ * message according to the factor type recorded in the cookie. If the ++ * second factor exchange finishes successfully, we should set ++ * TKT_FLG_PRE_AUTH, set the reply key to K'[0], and add any auth ++ * indicators from configuration (with a call to add_indicators()) or the ++ * second factor module (unless the module has access to cb and rock and ++ * can add indicators itself). ++ */ ++ (*respond)(arg, KRB5KDC_ERR_PREAUTH_FAILED, NULL, NULL, NULL); ++} ++ ++/* ++ * Respond to a client padata message, either by generating a SPAKE challenge, ++ * generating an additional second-factor challenge, or marking the reply as ++ * pre-authenticated and setting an additional reply key in the pre-request ++ * module data. ++ */ ++static void ++spake_verify(krb5_context context, krb5_data *req_pkt, krb5_kdc_req *request, ++ krb5_enc_tkt_part *enc_tkt_reply, krb5_pa_data *data, ++ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, ++ krb5_kdcpreauth_moddata moddata, ++ krb5_kdcpreauth_verify_respond_fn respond, void *arg) ++{ ++ krb5_error_code ret; ++ krb5_pa_spake *pa_spake = NULL; ++ krb5_data in_data = make_data(data->contents, data->length); ++ groupstate *gstate = (groupstate *)moddata; ++ ++ ret = decode_krb5_pa_spake(&in_data, &pa_spake); ++ if (ret) { ++ (*respond)(arg, ret, NULL, NULL, NULL); ++ } else if (pa_spake->choice == SPAKE_MSGTYPE_SUPPORT) { ++ verify_support(context, gstate, &pa_spake->u.support, &in_data, cb, ++ rock, respond, arg); ++ } else if (pa_spake->choice == SPAKE_MSGTYPE_RESPONSE) { ++ verify_response(context, gstate, &pa_spake->u.response, ++ &request->server->realm, cb, rock, enc_tkt_reply, ++ respond, arg); ++ } else if (pa_spake->choice == SPAKE_MSGTYPE_ENCDATA) { ++ verify_encdata(context, &pa_spake->u.encdata, cb, rock, enc_tkt_reply, ++ respond, arg); ++ } else { ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ k5_setmsg(context, ret, _("Unknown SPAKE request type")); ++ (*respond)(arg, ret, NULL, NULL, NULL); ++ } ++ ++ k5_free_pa_spake(context, pa_spake); ++} ++ ++/* If a key was set in the per-request module data, replace the reply key. Do ++ * not generate any pa-data to include with the KDC reply. */ ++static krb5_error_code ++spake_return(krb5_context context, krb5_pa_data *padata, krb5_data *req_pkt, ++ krb5_kdc_req *request, krb5_kdc_rep *reply, ++ krb5_keyblock *encrypting_key, krb5_pa_data **send_pa_out, ++ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, ++ krb5_kdcpreauth_moddata moddata, krb5_kdcpreauth_modreq modreq) ++{ ++ krb5_keyblock *reply_key = (krb5_keyblock *)modreq; ++ ++ if (reply_key == NULL) ++ return 0; ++ krb5_free_keyblock_contents(context, encrypting_key); ++ return krb5_copy_keyblock_contents(context, reply_key, encrypting_key); ++} ++ ++/* Release a per-request module data object. */ ++static void ++spake_free_modreq(krb5_context context, krb5_kdcpreauth_moddata moddata, ++ krb5_kdcpreauth_modreq modreq) ++{ ++ krb5_free_keyblock(context, (krb5_keyblock *)modreq); ++} ++ ++krb5_error_code ++kdcpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, ++ krb5_plugin_vtable vtable); ++ ++krb5_error_code ++kdcpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, ++ krb5_plugin_vtable vtable) ++{ ++ krb5_kdcpreauth_vtable vt; ++ static krb5_preauthtype pa_types[] = { KRB5_PADATA_SPAKE, 0 }; ++ ++ if (maj_ver != 1) ++ return KRB5_PLUGIN_VER_NOTSUPP; ++ vt = (krb5_kdcpreauth_vtable)vtable; ++ vt->name = "spake"; ++ vt->pa_type_list = pa_types; ++ vt->init = spake_init; ++ vt->fini = spake_fini; ++ vt->edata = spake_edata; ++ vt->verify = spake_verify; ++ vt->return_padata = spake_return; ++ vt->free_modreq = spake_free_modreq; ++ return 0; ++} +diff --git a/src/plugins/preauth/spake/t_krb5.conf b/src/plugins/preauth/spake/t_krb5.conf +new file mode 100644 +index 000000000..65fdaec63 +--- /dev/null ++++ b/src/plugins/preauth/spake/t_krb5.conf +@@ -0,0 +1,2 @@ ++[libdefaults] ++ spake_preauth_groups = edwards25519 +diff --git a/src/plugins/preauth/spake/t_vectors.c b/src/plugins/preauth/spake/t_vectors.c +new file mode 100644 +index 000000000..2279202d3 +--- /dev/null ++++ b/src/plugins/preauth/spake/t_vectors.c +@@ -0,0 +1,476 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* plugins/preauth/spake/t_vectors.c - SPAKE test vector verification */ ++/* ++ * Copyright (C) 2015 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#include "k5-int.h" ++#include "k5-hex.h" ++#include "groups.h" ++#include "iana.h" ++#include "util.h" ++#include ++ ++struct test { ++ krb5_enctype enctype; ++ int32_t group; ++ const char *ikey; ++ const char *w; ++ const char *x; ++ const char *y; ++ const char *T; ++ const char *S; ++ const char *K; ++ const char *support; ++ const char *challenge; ++ const char *thash; ++ const char *body; ++ const char *K0; ++ const char *K1; ++ const char *K2; ++ const char *K3; ++} tests[] = { ++ { ENCTYPE_DES3_CBC_SHA1, SPAKE_GROUP_EDWARDS25519, ++ /* initial key, w, x, y, T, S, K */ ++ "850BB51358548CD05E86768C313E3BFEF7511937DCF72C3E", ++ "686D84730CB8679AE95416C6567C6A63F2C9CEF124F7A3371AE81E11CAD42A37", ++ "201012D07BFD48DDFA33C4AAC4FB1E229FB0D043CFE65EBFB14399091C71A723", ++ "500B294797B8B042ACA1BEDC0F5931A4F52C537B3608B2D05CC8A2372F439F25", ++ "18F511E750C97B592ACD30DB7D9E5FCA660389102E6BF610C1BFBED4616C8362", ++ "5D10705E0D1E43D5DBF30240CCFBDE4A0230C70D4C79147AB0B317EDAD2F8AE7", ++ "25BDE0D875F0FEB5755F45BA5E857889D916ECF7476F116AA31DC3E037EC4292", ++ /* support, challenge, thash, body */ ++ "A0093007A0053003020101", ++ "A1363034A003020101A122042018F511E750C97B592ACD30DB7D9E5FCA660389" ++ "102E6BF610C1BFBED4616C8362A20930073005A003020101", ++ "EAAA08807D0616026FF51C849EFBF35BA0CE3C5300E7D486DA46351B13D4605B", ++ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" ++ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" ++ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" ++ "303130313030303030305AA703020100A8053003020110", ++ /* K'[0], K'[1], K'[2], K'[3] */ ++ "BAF12FAE7CD958CBF1A29BFBC71F89CE49E03E295D89DAFD", ++ "64F73DD9C41908206BCEC1F719026B574F9D13463D7A2520", ++ "0454520B086B152C455829E6BAEFF78A61DFE9E3D04A895D", ++ "4A92260B25E3EF94C125D5C24C3E5BCED5B37976E67F25C4", ++ }, ++ ++ { ENCTYPE_ARCFOUR_HMAC, SPAKE_GROUP_EDWARDS25519, ++ /* initial key, w, x, y, T, S, K */ ++ "8846F7EAEE8FB117AD06BDD830B7586C", ++ "7C86659D29CF2B2EA93BFE79C3CEFB8850E82215B3EA6FCD896561D48048F49C", ++ "C8A62E7B626F44CAD807B2D695450697E020D230A738C5CD5691CC781DCE8754", ++ "18FE7C1512708C7FD06DB270361F04593775BC634CEAF45347E5C11C38AAE017", ++ "7DB465F1C08C64983A19F560BCE966FE5306C4B447F70A5BCA14612A92DA1D63", ++ "38F8D4568090148EBC9FD17C241B4CC2769505A7CA6F3F7104417B72B5B5CF54", ++ "03E75EDD2CD7E7677642DD68736E91700953AC55DC650E3C2A1B3B4ACDB800F8", ++ /* support, challenge, thash, body */ ++ "A0093007A0053003020101", ++ "A1363034A003020101A12204207DB465F1C08C64983A19F560BCE966FE5306C4" ++ "B447F70A5BCA14612A92DA1D63A20930073005A003020101", ++ "F4B208458017DE6EF7F6A307D47D87DB6C2AF1D291B726860F68BC08BFEF440A", ++ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" ++ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" ++ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" ++ "303130313030303030305AA703020100A8053003020117", ++ /* K'[0], K'[1], K'[2], K'[3] */ ++ "770B720C82384CBB693E85411EEDECBA", ++ "621DEEC88E2865837C4D3462BB50A1D5", ++ "1CC8F6333B9FA3B42662FD9914FBD5BB", ++ "EDB4032B7FC3806D5211A534DCBC390C", ++ }, ++ ++ { ENCTYPE_AES128_CTS_HMAC_SHA1_96, SPAKE_GROUP_EDWARDS25519, ++ /* initial key, w, x, y, T, S, K */ ++ "FCA822951813FB252154C883F5EE1CF4", ++ "0D591B197B667E083C2F5F98AC891D3C9F99E710E464E62F1FB7C9B67936F3EB", ++ "50BE049A5A570FA1459FB9F666E6FD80602E4E87790A0E567F12438A2C96C138", ++ "B877AFE8612B406D96BE85BD9F19D423E95BE96C0E1E0B5824127195C3ED5917", ++ "9E9311D985C1355E022D7C3C694AD8D6F7AD6D647B68A90B0FE46992818002DA", ++ "FBE08F7F96CD5D4139E7C9ECCB95E79B8ACE41E270A60198C007DF18525B628E", ++ "C2F7F99997C585E6B686CEB62DB42F17CC70932DEF3BB4CF009E36F22EA5473D", ++ /* support, challenge, thash, body */ ++ "A0093007A0053003020101", ++ "A1363034A003020101A12204209E9311D985C1355E022D7C3C694AD8D6F7AD6D" ++ "647B68A90B0FE46992818002DAA20930073005A003020101", ++ "951285F107C87F0169B9C918A1F51F60CB1A75B9F8BB799A99F53D03ADD94B5F", ++ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" ++ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" ++ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" ++ "303130313030303030305AA703020100A8053003020111", ++ /* K'[0], K'[1], K'[2], K'[3] */ ++ "548022D58A7C47EAE8C49DCCF6BAA407", ++ "B2C9BA0E13FC8AB3A9D96B51B601CF4A", ++ "69F0EE5FDB6C237E7FCD38D9F87DF1BD", ++ "78F91E2240B5EE528A5CC8D7CBEBFBA5", ++ }, ++ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, SPAKE_GROUP_EDWARDS25519, ++ /* initial key, w, x, y, T, S, K */ ++ "01B897121D933AB44B47EB5494DB15E50EB74530DBDAE9B634D65020FF5D88C1", ++ "E902341590A1B4BB4D606A1C643CCCB3F2108F1B6AA97B381012B9400C9E3F4E", ++ "88C6C0A4F0241EF217C9788F02C32D00B72E4310748CD8FB5F94717607E6417D", ++ "88B859DF58EF5C69BACDFE681C582754EAAB09A74DC29CFF50B328613C232F55", ++ "6F301AACAE1220E91BE42868C163C5009AEEA1E9D9E28AFCFC339CDA5E7105B5", ++ "9E2CC32908FC46273279EC75354B4AEAFA70C3D99A4D507175ED70D80B255DDA", ++ "CF57F58F6E60169D2ECC8F20BB923A8E4C16E5BC95B9E64B5DC870DA7026321B", ++ /* support, challenge, thash, body */ ++ "A0093007A0053003020101", ++ "A1363034A003020101A12204206F301AACAE1220E91BE42868C163C5009AEEA1" ++ "E9D9E28AFCFC339CDA5E7105B5A20930073005A003020101", ++ "1C605649D4658B58CBE79A5FAF227ACC16C355C58B7DADE022F90C158FE5ED8E", ++ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" ++ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" ++ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" ++ "303130313030303030305AA703020100A8053003020112", ++ /* K'[0], K'[1], K'[2], K'[3] */ ++ "A9BFA71C95C575756F922871524B65288B3F695573CCC0633E87449568210C23", ++ "1865A9EE1EF0640EC28AC007391CAC624C42639C714767A974E99AA10003015F", ++ "E57781513FEFDB978E374E156B0DA0C1A08148F5EB26B8E157AC3C077E28BF49", ++ "008E6487293C3CC9FABBBCDD8B392D6DCB88222317FD7FE52D12FBC44FA047F1", ++ }, ++ ++#ifdef SPAKE_OPENSSL ++ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, SPAKE_GROUP_P256, ++ /* initial key, w, x, y, T, S, K */ ++ "01B897121D933AB44B47EB5494DB15E50EB74530DBDAE9B634D65020FF5D88C1", ++ "EB2984AF18703F94DD5288B8596CD36988D0D4E83BFB2B44DE14D0E95E2090BD", ++ "935DDD725129FB7C6288E1A5CC45782198A6416D1775336D71EACD0549A3E80E", ++ "E07405EB215663ABC1F254B8ADC0DA7A16FEBAA011AF923D79FDEF7C42930B33", ++ "024F62078CEB53840D02612195494D0D0D88DE21FEEB81187C71CBF3D01E71788D", ++ "021D07DC31266FC7CFD904CE2632111A169B7EC730E5F74A7E79700F86638E13C8", ++ "0268489D7A9983F2FDE69C6E6A1307E9D252259264F5F2DFC32F58CCA19671E79B", ++ /* support, challenge, thash, body */ ++ "A0093007A0053003020102", ++ "A1373035A003020102A1230421024F62078CEB53840D02612195494D0D0D88DE" ++ "21FEEB81187C71CBF3D01E71788DA20930073005A003020101", ++ "20AD3C1A9A90FC037D1963A1C4BFB15AB4484D7B6CF07B12D24984F14652DE60", ++ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" ++ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" ++ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" ++ "303130313030303030305AA703020100A8053003020112", ++ /* K'[0], K'[1], K'[2], K'[3] */ ++ "7D3B906F7BE49932DB22CD3463F032D06C9C078BE4B1D076D201FC6E61EF531E", ++ "17D74E36F8993841FBB7FEB12FA4F011243D3AE4D2ACE55B39379294BBC4DB2C", ++ "D192C9044081A2AA6A97A6C69E2724E8E5671C2C9CE073DD439CDBAF96D7DAB0", ++ "41E5BAD6B67F12C53CE0E2720DD6A9887F877BF9463C2D5209C74C36F8D776B7", ++ }, ++ ++ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, SPAKE_GROUP_P384, ++ /* initial key, w, x, y, T, S, K */ ++ "01B897121D933AB44B47EB5494DB15E50EB74530DBDAE9B634D65020FF5D88C1", ++ "0304CFC55151C6BBE889653DB96DBFE0BA4ACAFC024C1E8840CB3A486F6D80C1" ++ "6E1B8974016AA4B7FA43042A9B3825B1", ++ "F323CA74D344749096FD35D0ADF20806E521460637176E84D977E9933C49D76F" ++ "CFC6E62585940927468FF53D864A7A50", ++ "5B7C709ACB175A5AFB82860DEABCA8D0B341FACDFF0AC0F1A425799AA905D750" ++ "7E1EA9C573581A81467437419466E472", ++ "02A1524603EF14F184696F854229D3397507A66C63F841BA748451056BE07879" ++ "AC298912387B1C5CDFF6381C264701BE57", ++ "020D5ADFDB92BC377041CF5837412574C5D13E0F4739208A4F0C859A0A302BC6" ++ "A533440A245B9D97A0D34AF5016A20053D", ++ "0264AA8C61DA9600DFB0BEB5E46550D63740E4EF29E73F1A30D543EB43C25499" ++ "037AD16538586552761B093CF0E37C703A", ++ /* support, challenge, thash, body */ ++ "A0093007A0053003020103", ++ "A1473045A003020103A133043102A1524603EF14F184696F854229D3397507A6" ++ "6C63F841BA748451056BE07879AC298912387B1C5CDFF6381C264701BE57A209" ++ "30073005A003020101", ++ "5AC0D99EF9E5A73998797FE64F074673E3952DEC4C7D1AACCE8B75F64D2B0276" ++ "A901CB8539B4E8ED69E4DB0CE805B47B", ++ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" ++ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" ++ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" ++ "303130313030303030305AA703020100A8053003020112", ++ /* K'[0], K'[1], K'[2], K'[3] */ ++ "B917D37C16DD1D8567FBE379F64E1EE36CA3FD127AA4E60F97E4AFA3D9E56D91", ++ "93D40079DAB229B9C79366829F4E7E7282E6A4B943AC7BAC69922D516673F49A", ++ "BFC4F16F12F683E71589F9A888E232875EF293AC9793DB6C919567CD7B94BCD4", ++ "3630E2B5B99938E7506733141E8EC344166F6407E5FC2EF107C156E764D1BC20", ++ }, ++ ++ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, SPAKE_GROUP_P521, ++ /* initial key, w, x, y, T, S, K */ ++ "01B897121D933AB44B47EB5494DB15E50EB74530DBDAE9B634D65020FF5D88C1", ++ "DE3A095A2B2386EFF3EB15B735398DA1CAF95BC8425665D82370AFF58B0471F3" ++ "4A57BCCDDF1EBF0A2965B58A93EE5B45E85D1A5435D1C8C83662999722D54283" ++ "1F9A", ++ "017C38701A14B490B6081DFC83524562BE7FBB42E0B20426465E3E37952D30BC" ++ "AB0ED857010255D44936A1515607964A870C7C879B741D878F9F9CDF5A865306" ++ "F3F5", ++ "003E2E2950656FA231E959ACDD984D125E7FA59CEC98126CBC8F3888447911EB" ++ "CD49428A1C22D5FDB76A19FBEB1D9EDFA3DA6CF55B158B53031D05D51433ADE9" ++ "B2B4", ++ "02017D3DE19A3EC53D0174905665EF37947D142535102CD9809C0DFBD0DFE007" ++ "353D54CF406CE2A59950F2BB540DF6FBE75F8BBBEF811C9BA06CC275ADBD9675" ++ "6696EC", ++ "02004D142D87477841F6BA053C8F651F3395AD264B7405CA5911FB9A55ABD454" ++ "FEF658A5F9ED97D1EFAC68764E9092FA15B9E0050880D78E95FD03ABF5931791" ++ "6822B5", ++ "03007C303F62F09282CC849490805BD4457A6793A832CBEB55DF427DB6A31E99" ++ "B055D5DC99756D24D47B70AD8B6015B0FB8742A718462ED423B90FA3FE631AC1" ++ "3FA916", ++ /* support, challenge, thash, body */ ++ "A0093007A0053003020104", ++ "A1593057A003020104A145044302017D3DE19A3EC53D0174905665EF37947D14" ++ "2535102CD9809C0DFBD0DFE007353D54CF406CE2A59950F2BB540DF6FBE75F8B" ++ "BBEF811C9BA06CC275ADBD96756696ECA20930073005A003020101", ++ "8D6A89AE4D80CC4E47B6F4E48EA3E57919CC69598D0D3DC7C8BD49B6F1DB1409" ++ "CA0312944CD964E213ABA98537041102237CFF5B331E5347A0673869B412302E", ++ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" ++ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" ++ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" ++ "303130313030303030305AA703020100A8053003020112", ++ /* K'[0], K'[1], K'[2], K'[3] */ ++ "1EB3D10BEE8FAB483ADCD3EB38F3EBF1F4FEB8DB96ECC035F563CF2E1115D276", ++ "482B92781CE57F49176E4C94153CC622FE247A7DBE931D1478315F856F085890", ++ "A2C215126DD3DF280AAB5A27E1E0FB7E594192CBFF8D6D8E1B6F1818D9BB8FAC", ++ "CC06603DE984324013A01F888DE6D43B410A4DA2DEA53509F30E433C352FB668", ++ }, ++#endif /* SPAKE_OPENSSL */ ++ ++ /* Successful optimistic challenge (no support message in transcript) */ ++ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, SPAKE_GROUP_EDWARDS25519, ++ /* initial key, w, x, y, T, S, K */ ++ "01B897121D933AB44B47EB5494DB15E50EB74530DBDAE9B634D65020FF5D88C1", ++ "E902341590A1B4BB4D606A1C643CCCB3F2108F1B6AA97B381012B9400C9E3F4E", ++ "70937207344CAFBC53C8A55070E399C584CBAFCE00B836980DD4E7E74FAD2A64", ++ "785D6801A2490DF028903AC6449B105F2FF0DB895B252953CDC2076649526103", ++ "83523B35F1565006CBFC4F159885467C2FB9BC6FE23D36CB1DA43D199F1A3118", ++ "2A8F70F46CEE9030700037B77F22CEC7970DCC238E3E066D9D726BAF183992C6", ++ "D3C5E4266AA6D1B2873A97CE8AF91C7E4D7A7AC456ACCED7908D34C561AD8FA6", ++ /* support, challenge, thash, body */ ++ NULL, ++ "A1363034A003020101A122042083523B35F1565006CBFC4F159885467C2FB9BC" ++ "6FE23D36CB1DA43D199F1A3118A20930073005A003020101", ++ "26F07F9F8965307434D11EA855461D41E0CBABCC0A1BAB48ECEE0C6C1A4292B7", ++ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" ++ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" ++ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" ++ "303130313030303030305AA703020100A8053003020112", ++ /* K'[0], K'[1], K'[2], K'[3] */ ++ "4569EC08B5DE5C3CC19D941725913ACE8D74524B521A341DC746ACD5C3784D92", ++ "0D96CE1A4AC0F2E280A0CFC31742B06461D83D04AE45433DB2D80478DD882A4C", ++ "58018C19315A1BA5D5BB9813B58029F0AEC18A6F9CA59E0847DE1C60BC25945C", ++ "ED7E9BFFD68C54D86FB19CD3C03F317F88A71AD9A5E94C28581D93FC4EC72B6A", ++ }, ++ ++#ifdef SPAKE_OPENSSL ++ /* Rejected optimistic challenge (no support message in transcript), ++ * falling back from edwards25519 to P-521 */ ++ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, SPAKE_GROUP_P521, ++ /* initial key, w, x, y, T, S, K */ ++ "01B897121D933AB44B47EB5494DB15E50EB74530DBDAE9B634D65020FF5D88C1", ++ "DE3A095A2B2386EFF3EB15B735398DA1CAF95BC8425665D82370AFF58B0471F3" ++ "4A57BCCDDF1EBF0A2965B58A93EE5B45E85D1A5435D1C8C83662999722D54283" ++ "1F9A", ++ "01687B59051BF40048D7C31D5A973D792FA12284B7A447E7F5938B5885CA0BB2" ++ "C3F0BD30291A55FEA08E143E2E04BDD7D19B753C7C99032F06CAB0D9C2AA8F83" ++ "7EF7", ++ "01DED675EBF74FE30C9A53710F577E9CF84F09F6048FE245A4600004884CC167" ++ "733F9A9E43108FB83BABE8754CD37CBD7025E28BC9FF870F084C7244F536285E" ++ "25B4", ++ "02014CB2E5B592ECE5990F0EF30D308C061DE1598BC4272B4A6599BED466FD15" ++ "21693642ABCF4DBE36CE1A2D13967DE45F6C4F8D0FA8E14428BF03FB96EF5F1E" ++ "D3E645", ++ "02016C64995E804416F748FD5FA3AA678CBC7CBB596A4F523132DC8AF7CE84E5" ++ "41F484A2C74808C6B21DCF7775BAEFA6753398425BECC7B838B210AC5DAA0CB0" ++ "B710E2", ++ "0200997F4848AE2E7A98C23D14AC662030743AB37FCCC2A45F1C721114F40BCC" ++ "80FE6EC6ABA49868F8AEA1AA994D50E81B86D3E4D3C1130C8695B68907C673D9" ++ "E5886A", ++ /* support, challenge, thash, body */ ++ "A0093007A0053003020104", ++ "A1593057A003020104A145044302014CB2E5B592ECE5990F0EF30D308C061DE1" ++ "598BC4272B4A6599BED466FD1521693642ABCF4DBE36CE1A2D13967DE45F6C4F" ++ "8D0FA8E14428BF03FB96EF5F1ED3E645A20930073005A003020101", ++ "D0EFED5E3E2C39C26034756D92A66FEC3082AD793D0197F3F89AD36026F146A3" ++ "996E548AA3FC49E2E82F8CAC5D132C505AA475B39E7BE79CDED22C26C41AA777", ++ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" ++ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" ++ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" ++ "303130313030303030305AA703020100A8053003020112", ++ /* K'[0], K'[1], K'[2], K'[3] */ ++ "631FCC8596E7F40E59045950D72AA0B7BAC2810A07B767050E983841CF3A2D4C", ++ "881464920117074DBC67155A8F3341D1121EF65F78EA0380BFA81A134C1C47B1", ++ "377B72AC3AF2CAAD582D73AE4682FD56B531EE56706200DD6C38C42B8219837A", ++ "35AD8E4D580ED3F0D15AD928329773C081BD19F9A56363F3A5F77C7E66108C26", ++ }, ++#endif /* SPAKE_OPENSSL */ ++}; ++ ++static krb5_context ctx; ++ ++static void ++check(krb5_error_code code) ++{ ++ const char *errmsg; ++ ++ if (code) { ++ errmsg = krb5_get_error_message(ctx, code); ++ assert(errmsg != NULL); ++ abort(); ++ } ++} ++ ++static void ++check_key_equal(const krb5_keyblock *kb1, const krb5_keyblock *kb2) ++{ ++ assert(kb1->enctype == kb2->enctype); ++ assert(kb1->length == kb2->length); ++ assert(memcmp(kb1->contents, kb2->contents, kb1->length) == 0); ++} ++ ++static krb5_data * ++decode_data(const char *s) ++{ ++ uint8_t *bytes; ++ size_t len; ++ krb5_data *d; ++ ++ if (k5_hex_decode(s, &bytes, &len) != 0) ++ abort(); ++ d = malloc(sizeof(*d)); ++ assert(d != NULL); ++ *d = make_data(bytes, len); ++ return d; ++} ++ ++static krb5_keyblock * ++decode_keyblock(krb5_enctype enctype, const char *s) ++{ ++ uint8_t *bytes; ++ size_t len; ++ krb5_keyblock *kb; ++ ++ if (k5_hex_decode(s, &bytes, &len) != 0) ++ abort(); ++ kb = malloc(sizeof(*kb)); ++ kb->magic = KV5M_KEYBLOCK; ++ kb->enctype = enctype; ++ kb->length = len; ++ kb->contents = bytes; ++ return kb; ++} ++ ++static void ++run_test(const struct test *t) ++{ ++ groupstate *gstate; ++ krb5_keyblock *ikey, *K0, *K1, *K2, *K3, *kb; ++ krb5_data *w, *x, *y, *T, *S, *K, *support, *challenge, *thash; ++ krb5_data *body, wbytes, result, hash, empty = empty_data(); ++ ++ /* Decode hex strings into keyblocks and byte strings. */ ++ ikey = decode_keyblock(t->enctype, t->ikey); ++ w = decode_data(t->w); ++ x = decode_data(t->x); ++ y = decode_data(t->y); ++ T = decode_data(t->T); ++ S = decode_data(t->S); ++ K = decode_data(t->K); ++ support = (t->support != NULL) ? decode_data(t->support) : NULL; ++ challenge = decode_data(t->challenge); ++ thash = decode_data(t->thash); ++ body = decode_data(t->body); ++ K0 = decode_keyblock(t->enctype, t->K0); ++ K1 = decode_keyblock(t->enctype, t->K1); ++ K2 = decode_keyblock(t->enctype, t->K2); ++ K3 = decode_keyblock(t->enctype, t->K3); ++ ++ check(derive_wbytes(ctx, t->group, ikey, &wbytes)); ++ assert(data_eq(*w, wbytes)); ++ ++ /* Verify KDC-side result computation. */ ++ check(group_init_state(ctx, TRUE, &gstate)); ++ check(group_result(ctx, gstate, t->group, &wbytes, x, S, &result)); ++ assert(data_eq(*K, result)); ++ krb5_free_data_contents(ctx, &result); ++ group_free_state(gstate); ++ ++ /* Verify client-side result computation. */ ++ check(group_init_state(ctx, FALSE, &gstate)); ++ check(group_result(ctx, gstate, t->group, &wbytes, y, T, &result)); ++ assert(data_eq(*K, result)); ++ krb5_free_data_contents(ctx, &result); ++ ++ /* Verify transcript hash. */ ++ hash = empty_data(); ++ check(update_thash(ctx, gstate, t->group, &hash, support, challenge)); ++ check(update_thash(ctx, gstate, t->group, &hash, S, &empty)); ++ assert(data_eq(*thash, hash)); ++ krb5_free_data_contents(ctx, &hash); ++ ++ /* Verify derived keys. */ ++ check(derive_key(ctx, gstate, t->group, ikey, &wbytes, K, thash, body, 0, ++ &kb)); ++ check_key_equal(K0, kb); ++ krb5_free_keyblock(ctx, kb); ++ check(derive_key(ctx, gstate, t->group, ikey, &wbytes, K, thash, body, 1, ++ &kb)); ++ check_key_equal(K1, kb); ++ krb5_free_keyblock(ctx, kb); ++ check(derive_key(ctx, gstate, t->group, ikey, &wbytes, K, thash, body, 2, ++ &kb)); ++ check_key_equal(K2, kb); ++ krb5_free_keyblock(ctx, kb); ++ check(derive_key(ctx, gstate, t->group, ikey, &wbytes, K, thash, body, 3, ++ &kb)); ++ check_key_equal(K3, kb); ++ krb5_free_keyblock(ctx, kb); ++ ++ group_free_state(gstate); ++ krb5_free_data_contents(ctx, &wbytes); ++ krb5_free_keyblock(ctx, ikey); ++ krb5_free_data(ctx, w); ++ krb5_free_data(ctx, x); ++ krb5_free_data(ctx, y); ++ krb5_free_data(ctx, T); ++ krb5_free_data(ctx, S); ++ krb5_free_data(ctx, K); ++ krb5_free_data(ctx, support); ++ krb5_free_data(ctx, challenge); ++ krb5_free_data(ctx, thash); ++ krb5_free_data(ctx, body); ++ krb5_free_keyblock(ctx, K0); ++ krb5_free_keyblock(ctx, K1); ++ krb5_free_keyblock(ctx, K2); ++ krb5_free_keyblock(ctx, K3); ++} ++ ++int ++main() ++{ ++ size_t i; ++ ++ check(krb5_init_context(&ctx)); ++ for (i = 0; i < sizeof(tests) / sizeof(*tests); i++) ++ run_test(&tests[i]); ++ krb5_free_context(ctx); ++ return 0; ++} +diff --git a/src/plugins/preauth/spake/trace.h b/src/plugins/preauth/spake/trace.h +new file mode 100644 +index 000000000..9dd964260 +--- /dev/null ++++ b/src/plugins/preauth/spake/trace.h +@@ -0,0 +1,74 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* plugins/preauth/spake/internal.h - SPAKE internal function declarations */ ++/* ++ * Copyright (C) 2015 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#ifndef TRACE_H ++#define TRACE_H ++ ++#include "k5-int.h" ++ ++/* ++ * Possible improvements at the cost of more code: ++ * - Groups could be displayed by name instead of number ++ * - We could display the group list when tracing support messages ++ */ ++ ++#define TRACE_SPAKE_CLIENT_THASH(c, thash) \ ++ TRACE(c, "SPAKE final transcript hash: {hexdata}", thash) ++#define TRACE_SPAKE_DERIVE_KEY(c, n, kb) \ ++ TRACE(c, "SPAKE derived K'[{int}] = {keyblock}", n, kb) ++#define TRACE_SPAKE_KDC_THASH(c, thash) \ ++ TRACE(c, "SPAKE final transcript hash: {hexdata}", thash) ++#define TRACE_SPAKE_KEYGEN(c, pubkey) \ ++ TRACE(c, "SPAKE key generated with pubkey {hexdata}", pubkey) ++#define TRACE_SPAKE_RECEIVE_CHALLENGE(c, group, pubkey) \ ++ TRACE(c, "SPAKE challenge received with group {int}, pubkey {hexdata}", \ ++ group, pubkey) ++#define TRACE_SPAKE_RECEIVE_RESPONSE(c, pubkey) \ ++ TRACE(c, "SPAKE response received with pubkey {hexdata}", pubkey) ++#define TRACE_SPAKE_RECEIVE_SUPPORT(c, group) \ ++ TRACE(c, "SPAKE support message received, selected group {int}", group) ++#define TRACE_SPAKE_REJECT_CHALLENGE(c, group) \ ++ TRACE(c, "SPAKE challenge with group {int} rejected", (int)group) ++#define TRACE_SPAKE_REJECT_SUPPORT(c) \ ++ TRACE(c, "SPAKE support message rejected") ++#define TRACE_SPAKE_RESULT(c, result) \ ++ TRACE(c, "SPAKE algorithm result: {hexdata}", result) ++#define TRACE_SPAKE_SEND_CHALLENGE(c, group) \ ++ TRACE(c, "Sending SPAKE challenge with group {int}", group) ++#define TRACE_SPAKE_SEND_RESPONSE(c) \ ++ TRACE(c, "Sending SPAKE response") ++#define TRACE_SPAKE_SEND_SUPPORT(c) \ ++ TRACE(c, "Sending SPAKE support message") ++#define TRACE_SPAKE_UNKNOWN_GROUP(c, name) \ ++ TRACE(c, "Unrecognized SPAKE group name: {string}", name) ++ ++#endif /* TRACE_H */ +diff --git a/src/plugins/preauth/spake/util.c b/src/plugins/preauth/spake/util.c +new file mode 100644 +index 000000000..cbdbbd7ac +--- /dev/null ++++ b/src/plugins/preauth/spake/util.c +@@ -0,0 +1,211 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* plugins/preauth/spake/util.c - Utility functions for SPAKE preauth module */ ++/* ++ * Copyright (C) 2015 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#include "k5-int.h" ++#include "trace.h" ++#include "util.h" ++#include "groups.h" ++ ++/* Use data to construct a single-element pa-data list of type ++ * KRB5_PADATA_SPAKE. Claim data's memory on success or failure. */ ++krb5_error_code ++convert_to_padata(krb5_data *data, krb5_pa_data ***pa_out) ++{ ++ krb5_pa_data *pa = NULL, **list = NULL; ++ ++ list = calloc(2, sizeof(*list)); ++ if (list == NULL) ++ goto fail; ++ pa = calloc(1, sizeof(*pa)); ++ if (pa == NULL) ++ goto fail; ++ pa->magic = KV5M_PA_DATA; ++ pa->pa_type = KRB5_PADATA_SPAKE; ++ pa->length = data->length; ++ pa->contents = (uint8_t *)data->data; ++ list[0] = pa; ++ list[1] = NULL; ++ *pa_out = list; ++ free(data); ++ return 0; ++ ++fail: ++ free(list); ++ free(pa); ++ free(data->data); ++ free(data); ++ return ENOMEM; ++} ++ ++/* ++ * Update the transcript hash thash with its current value and the ++ * concatenation of data1 and data2, using the hash function for group. Either ++ * data1 or data2 may be NULL to omit it. Allocate thash if it is empty. ++ */ ++krb5_error_code ++update_thash(krb5_context context, groupstate *gstate, int32_t group, ++ krb5_data *thash, const krb5_data *data1, const krb5_data *data2) ++{ ++ krb5_error_code ret; ++ size_t hashlen; ++ krb5_data dlist[3]; ++ ++ if (thash->length == 0) { ++ /* Initialize the transcript hash to all zeros. */ ++ ret = group_hash_len(group, &hashlen); ++ if (ret) ++ return ret; ++ ret = alloc_data(thash, hashlen); ++ if (ret) ++ return ret; ++ } ++ ++ /* Set up the data array and hash it with the group's hash function. */ ++ dlist[0] = *thash; ++ dlist[1] = (data1 != NULL) ? *data1 : empty_data(); ++ dlist[2] = (data2 != NULL) ? *data2 : empty_data(); ++ return group_hash(context, gstate, group, dlist, 3, ++ (uint8_t *)thash->data); ++} ++ ++/* Derive a byte vector for the SPAKE w multiplier input from ikey. Place ++ * result in allocated storage in *wbytes_out. */ ++krb5_error_code ++derive_wbytes(krb5_context context, int32_t group, const krb5_keyblock *ikey, ++ krb5_data *wbytes_out) ++{ ++ krb5_error_code ret; ++ const char prefix[] = "SPAKEsecret"; ++ size_t mult_len, prefix_len = sizeof(prefix) - 1; ++ krb5_data prf_input = empty_data(), wbytes = empty_data(); ++ ++ *wbytes_out = empty_data(); ++ ++ /* Allocate space for a multiplier. */ ++ ret = group_mult_len(group, &mult_len); ++ if (ret) ++ goto cleanup; ++ ret = alloc_data(&wbytes, mult_len); ++ if (ret) ++ goto cleanup; ++ ++ /* Compose the PRF input string. */ ++ ret = alloc_data(&prf_input, prefix_len + 4); ++ if (ret) ++ goto cleanup; ++ memcpy(prf_input.data, prefix, prefix_len); ++ store_32_be(group, prf_input.data + prefix_len); ++ ++ /* Derive the SPAKE input from the initial reply key with PRF+. */ ++ ret = krb5_c_prfplus(context, ikey, &prf_input, &wbytes); ++ if (ret) ++ goto cleanup; ++ ++ *wbytes_out = wbytes; ++ wbytes = empty_data(); ++ ++cleanup: ++ free(prf_input.data); ++ zapfree(wbytes.data, wbytes.length); ++ return ret; ++} ++ ++/* ++ * Derive K'[n] from the group number, the initial key enctype, the initial ++ * multiplier, the SPAKE result, the transcript hash, and the encoded ++ * KDC-REQ-BODY. Place the result in allocated storage in *out. ++ */ ++krb5_error_code ++derive_key(krb5_context context, groupstate *gstate, int32_t group, ++ const krb5_keyblock *ikey, const krb5_data *wbytes, ++ const krb5_data *spakeresult, const krb5_data *thash, ++ const krb5_data *der_req, uint32_t n, krb5_keyblock **out) ++{ ++ krb5_error_code ret; ++ krb5_data dlist[9], seed = empty_data(), d; ++ uint8_t groupnbuf[4], etypenbuf[4], nbuf[4], bcount; ++ size_t hashlen, seedlen, keylen, nblocks, i; ++ size_t ndata = sizeof(dlist) / sizeof(*dlist); ++ krb5_keyblock *hkey = NULL; ++ ++ *out = NULL; ++ ++ store_32_be(group, groupnbuf); ++ store_32_be(n, nbuf); ++ store_32_be(ikey->enctype, etypenbuf); ++ dlist[0] = string2data("SPAKEkey"); ++ dlist[1] = make_data(groupnbuf, sizeof(groupnbuf)); ++ dlist[2] = make_data(etypenbuf, sizeof(etypenbuf)); ++ dlist[3] = *wbytes; ++ dlist[4] = *spakeresult; ++ dlist[5] = *thash; ++ dlist[6] = *der_req; ++ dlist[7] = make_data(nbuf, sizeof(nbuf)); ++ dlist[8] = make_data(&bcount, 1); ++ ++ /* Count the number of hash blocks required (should be 1 for all current ++ * scenarios) and allocate space. */ ++ ret = group_hash_len(group, &hashlen); ++ if (ret) ++ goto cleanup; ++ ret = krb5_c_keylengths(context, ikey->enctype, &seedlen, &keylen); ++ if (ret) ++ goto cleanup; ++ nblocks = (seedlen + hashlen - 1) / hashlen; ++ ret = alloc_data(&seed, nblocks * hashlen); ++ if (ret) ++ goto cleanup; ++ ++ /* Compute and concatenate hash blocks to fill the seed buffer. */ ++ for (i = 0; i < nblocks; i++) { ++ bcount = i + 1; ++ ret = group_hash(context, gstate, group, dlist, ndata, ++ (uint8_t *)seed.data + i * hashlen); ++ if (ret) ++ goto cleanup; ++ } ++ ++ ret = krb5_init_keyblock(context, ikey->enctype, keylen, &hkey); ++ if (ret) ++ goto cleanup; ++ d = make_data(seed.data, seedlen); ++ ret = krb5_c_random_to_key(context, ikey->enctype, &d, hkey); ++ if (ret) ++ goto cleanup; ++ ++ ret = krb5_c_fx_cf2_simple(context, ikey, "SPAKE", hkey, "keyderiv", out); ++ ++cleanup: ++ zapfree(seed.data, seed.length); ++ krb5_free_keyblock(context, hkey); ++ return ret; ++} +diff --git a/src/plugins/preauth/spake/util.h b/src/plugins/preauth/spake/util.h +new file mode 100644 +index 000000000..3ab2bead1 +--- /dev/null ++++ b/src/plugins/preauth/spake/util.h +@@ -0,0 +1,56 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* plugins/preauth/spake/internal.h - SPAKE internal function declarations */ ++/* ++ * Copyright (C) 2015 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#ifndef UTIL_H ++#define UTIL_H ++ ++#include "k5-int.h" ++#include "groups.h" ++ ++krb5_error_code convert_to_padata(krb5_data *data, krb5_pa_data ***pa_out); ++ ++krb5_error_code update_thash(krb5_context context, groupstate *gstate, ++ int32_t group, krb5_data *thash, ++ const krb5_data *data1, const krb5_data *data2); ++ ++krb5_error_code derive_wbytes(krb5_context context, int32_t group, ++ const krb5_keyblock *ikey, ++ krb5_data *wbytes_out); ++ ++krb5_error_code derive_key(krb5_context context, groupstate *gstate, ++ int32_t group, const krb5_keyblock *ikey, ++ const krb5_data *wbytes, ++ const krb5_data *spakeresult, ++ const krb5_data *thash, const krb5_data *der_req, ++ uint32_t n, krb5_keyblock **out); ++ ++#endif /* UTIL_H */ +diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in +index 67d3e8200..aed23e570 100644 +--- a/src/tests/Makefile.in ++++ b/src/tests/Makefile.in +@@ -130,6 +130,7 @@ check-pytests: unlockiter + $(RUNPYTEST) $(srcdir)/t_changepw.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_pkinit.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_otp.py $(PYTESTFLAGS) ++ $(RUNPYTEST) $(srcdir)/t_spake.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_localauth.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_kadm5_hook.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_kadm5_auth.py $(PYTESTFLAGS) +diff --git a/src/tests/t_spake.py b/src/tests/t_spake.py +new file mode 100644 +index 000000000..a81a238b4 +--- /dev/null ++++ b/src/tests/t_spake.py +@@ -0,0 +1,151 @@ ++#!/usr/bin/python ++from k5test import * ++ ++# The name and number of each supported SPAKE group. ++builtin_groups = ((1, 'edwards25519'),) ++openssl_groups = ((2, 'P-256'), (3, 'P-384'), (4, 'P-521')) ++if runenv.have_spake_openssl == 'yes': ++ groups = builtin_groups + openssl_groups ++else: ++ groups = builtin_groups ++ ++for gnum, gname in groups: ++ output('*** Testing group %s\n' % gname) ++ conf = {'libdefaults': {'spake_preauth_groups': gname}} ++ for realm in multipass_realms(create_user=False, create_host=False, ++ krb5_conf=conf): ++ realm.run([kadminl, 'addprinc', '+preauth', '-pw', 'pw', 'user']) ++ ++ # Test a basic SPAKE preauth scenario with no optimizations. ++ msgs = ('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Selected etype info:', ++ 'Sending SPAKE support message', ++ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', ++ '/More preauthentication data is required', ++ 'Continuing preauth mech PA-SPAKE (151)', ++ 'SPAKE challenge received with group ' + str(gnum), ++ 'Sending SPAKE response', ++ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', ++ 'AS key determined by preauth:', ++ 'Decrypted AS reply') ++ realm.kinit('user', 'pw', expected_trace=msgs) ++ ++ # Test an unsuccessful authentication. (The client will try ++ # again with encrypted timestamp, which isn't really desired, ++ # but check for that as long as it is expected.) ++ msgs = ('/Additional pre-authentication required', ++ 'Selected etype info:', ++ 'Sending SPAKE support message', ++ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', ++ '/More preauthentication data is required', ++ 'Continuing preauth mech PA-SPAKE (151)', ++ 'SPAKE challenge received with group ' + str(gnum), ++ 'Sending SPAKE response', ++ '/Preauthentication failed', ++ 'Encrypted timestamp ', ++ 'for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', ++ '/Preauthentication failed') ++ realm.kinit('user', 'wrongpw', expected_code=1, expected_trace=msgs) ++ ++conf = {'libdefaults': {'spake_preauth_groups': 'edwards25519'}} ++kdcconf = {'realms': {'$realm': {'spake_preauth_indicator': 'indspake'}}} ++realm = K5Realm(create_user=False, krb5_conf=conf, kdc_conf=kdcconf) ++realm.run([kadminl, 'addprinc', '+preauth', '-pw', 'pw', 'user']) ++ ++# Test with FAST. ++msgs = ('Using FAST due to armor ccache negotiation', ++ 'FAST armor key:', ++ 'Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Decoding FAST response', ++ 'Selected etype info:', ++ 'Sending SPAKE support message', ++ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', ++ '/More preauthentication data is required', ++ 'Continuing preauth mech PA-SPAKE (151)', ++ 'SPAKE challenge received with group 1', ++ 'Sending SPAKE response', ++ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', ++ 'AS key determined by preauth:', ++ 'FAST reply key:') ++realm.kinit(realm.host_princ, flags=['-k']) ++realm.kinit('user', 'pw', flags=['-T', realm.ccache], expected_trace=msgs) ++ ++# Test optimistic client preauth (151 is PA-SPAKE). ++msgs = ('Attempting optimistic preauth', ++ 'Processing preauth types: PA-SPAKE (151)', ++ 'Sending SPAKE support message', ++ 'for next request: PA-SPAKE (151)', ++ '/More preauthentication data is required', ++ 'Selected etype info:', ++ 'SPAKE challenge received with group 1', ++ 'Sending SPAKE response', ++ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', ++ 'AS key determined by preauth:', ++ 'Decrypted AS reply') ++realm.run(['./icred', '-o', '151', 'user', 'pw'], expected_trace=msgs) ++ ++# Test KDC optimistic challenge (accepted by client). ++oconf = {'kdcdefaults': {'spake_preauth_kdc_challenge': 'edwards25519'}} ++oenv = realm.special_env('ochal', True, krb5_conf=oconf) ++realm.stop_kdc() ++realm.start_kdc(env=oenv) ++msgs = ('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Selected etype info:', ++ 'SPAKE challenge received with group 1', ++ 'Sending SPAKE response', ++ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', ++ 'AS key determined by preauth:', ++ 'Decrypted AS reply') ++realm.kinit('user', 'pw', expected_trace=msgs) ++ ++if runenv.have_spake_openssl != 'yes': ++ skip_rest('SPAKE fallback tests', 'SPAKE not built using OpenSSL') ++ ++# Test optimistic client preauth falling back to encrypted timestamp ++# because the KDC doesn't support any of the client groups. ++p256conf={'libdefaults': {'spake_preauth_groups': 'P-256'}} ++p256env = realm.special_env('p256', False, krb5_conf=p256conf) ++msgs = ('Attempting optimistic preauth', ++ 'Processing preauth types: PA-SPAKE (151)', ++ 'Sending SPAKE support message', ++ 'for next request: PA-SPAKE (151)', ++ '/Preauthentication failed', ++ 'Selected etype info:', ++ 'SPAKE challenge with group 1 rejected', ++ 'spake (151) (real) returned: -1765328360/Preauthentication failed', ++ 'Encrypted timestamp ', ++ 'for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', ++ 'AS key determined by preauth:', ++ 'Decrypted AS reply') ++realm.run(['./icred', '-o', '151', 'user', 'pw'], env=p256env, ++ expected_trace=msgs) ++ ++# Test KDC optimistic challenge (rejected by client). ++rconf = {'libdefaults': {'spake_preauth_groups': 'P-384,edwards25519'}, ++ 'kdcdefaults': {'spake_preauth_kdc_challenge': 'P-384'}} ++renv = realm.special_env('ochal', True, krb5_conf=rconf) ++realm.stop_kdc() ++realm.start_kdc(env=renv) ++msgs = ('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Selected etype info:', ++ 'SPAKE challenge with group 3 rejected', ++ 'Sending SPAKE support message', ++ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', ++ '/More preauthentication data is required', ++ 'Continuing preauth mech PA-SPAKE (151)', ++ 'SPAKE challenge received with group 1', ++ 'Sending SPAKE response', ++ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', ++ 'AS key determined by preauth:', ++ 'Decrypted AS reply') ++realm.kinit('user', 'pw', expected_trace=msgs) ++ ++# Check that the auth indicator for SPAKE is properly included by the KDC. ++realm.run([kvno, realm.host_princ]) ++realm.run(['./adata', realm.host_princ], expected_msg='+97: [indspake]') ++ ++success('SPAKE pre-authentication tests') diff --git a/Add-doc-index-entries-for-SPAKE-constants.patch b/Add-doc-index-entries-for-SPAKE-constants.patch new file mode 100644 index 0000000..3bf7e4e --- /dev/null +++ b/Add-doc-index-entries-for-SPAKE-constants.patch @@ -0,0 +1,31 @@ +From c4c9ca6edde2157cd42839d227e5f3defd4011a1 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 27 Mar 2018 00:49:43 -0400 +Subject: [PATCH] Add doc index entries for SPAKE constants + +ticket: 8647 +(cherry picked from commit c010c9031753f356bb380e8a1324cc34721f8221) +--- + doc/appdev/refs/macros/index.rst | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst +index dba818b26..47c6d4413 100644 +--- a/doc/appdev/refs/macros/index.rst ++++ b/doc/appdev/refs/macros/index.rst +@@ -190,6 +190,7 @@ Public + KRB5_KEYUSAGE_PA_SAM_CHALLENGE_CKSUM.rst + KRB5_KEYUSAGE_PA_SAM_CHALLENGE_TRACKID.rst + KRB5_KEYUSAGE_PA_SAM_RESPONSE.rst ++ KRB5_KEYUSAGE_SPAKE.rst + KRB5_KEYUSAGE_TGS_REP_ENCPART_SESSKEY.rst + KRB5_KEYUSAGE_TGS_REP_ENCPART_SUBKEY.rst + KRB5_KEYUSAGE_TGS_REQ_AD_SESSKEY.rst +@@ -274,6 +275,7 @@ Public + KRB5_PADATA_SAM_RESPONSE.rst + KRB5_PADATA_SAM_RESPONSE_2.rst + KRB5_PADATA_SESAME.rst ++ KRB5_PADATA_SPAKE.rst + KRB5_PADATA_SVR_REFERRAL_INFO.rst + KRB5_PADATA_TGS_REQ.rst + KRB5_PADATA_USE_SPECIFIED_KVNO.rst diff --git a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch new file mode 100644 index 0000000..0510e92 --- /dev/null +++ b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch @@ -0,0 +1,119 @@ +From 4705fc3c9df924b0c1de015e63f95f98eb563dd3 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 4 Jan 2018 14:35:12 -0500 +Subject: [PATCH] Add k5_buf_add_vfmt to k5buf interface + +(cherry picked from commit f05766469efc2a055085c0bcf9d40c4cdf47fe36) +--- + src/include/k5-buf.h | 8 ++++++++ + src/util/support/k5buf.c | 26 +++++++++++++++----------- + src/util/support/libkrb5support-fixed.exports | 1 + + 3 files changed, 24 insertions(+), 11 deletions(-) + +diff --git a/src/include/k5-buf.h b/src/include/k5-buf.h +index f3207bd09..1223916a6 100644 +--- a/src/include/k5-buf.h ++++ b/src/include/k5-buf.h +@@ -76,6 +76,14 @@ void k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) + #endif + ; + ++/* Add sprintf-style formatted data to BUF, with a va_list. The value of ap is ++ * undefined after the call. */ ++void k5_buf_add_vfmt(struct k5buf *buf, const char *fmt, va_list ap) ++#if !defined(__cplusplus) && (__GNUC__ > 2) ++ __attribute__((__format__(__printf__, 2, 0))) ++#endif ++ ; ++ + /* Extend the length of buf by len and return a pointer to the reserved space, + * to be filled in by the caller. Return NULL on error. */ + void *k5_buf_get_space(struct k5buf *buf, size_t len); +diff --git a/src/util/support/k5buf.c b/src/util/support/k5buf.c +index f619f6a48..35978f238 100644 +--- a/src/util/support/k5buf.c ++++ b/src/util/support/k5buf.c +@@ -141,9 +141,9 @@ k5_buf_add_len(struct k5buf *buf, const void *data, size_t len) + } + + void +-k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) ++k5_buf_add_vfmt(struct k5buf *buf, const char *fmt, va_list ap) + { +- va_list ap; ++ va_list apcopy; + int r; + size_t remaining; + char *tmp; +@@ -154,9 +154,7 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) + + if (buf->buftype == K5BUF_FIXED) { + /* Format the data directly into the fixed buffer. */ +- va_start(ap, fmt); + r = vsnprintf(endptr(buf), remaining, fmt, ap); +- va_end(ap); + if (SNPRINTF_OVERFLOW(r, remaining)) + set_error(buf); + else +@@ -166,9 +164,9 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) + + /* Optimistically format the data directly into the dynamic buffer. */ + assert(buf->buftype == K5BUF_DYNAMIC); +- va_start(ap, fmt); +- r = vsnprintf(endptr(buf), remaining, fmt, ap); +- va_end(ap); ++ va_copy(apcopy, ap); ++ r = vsnprintf(endptr(buf), remaining, fmt, apcopy); ++ va_end(apcopy); + if (!SNPRINTF_OVERFLOW(r, remaining)) { + buf->len += (unsigned int) r; + return; +@@ -179,9 +177,7 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) + if (!ensure_space(buf, r)) + return; + remaining = buf->space - buf->len; +- va_start(ap, fmt); + r = vsnprintf(endptr(buf), remaining, fmt, ap); +- va_end(ap); + if (SNPRINTF_OVERFLOW(r, remaining)) /* Shouldn't ever happen. */ + k5_buf_free(buf); + else +@@ -191,9 +187,7 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) + + /* It's a pre-C99 snprintf implementation, or something else went wrong. + * Fall back to asprintf. */ +- va_start(ap, fmt); + r = vasprintf(&tmp, fmt, ap); +- va_end(ap); + if (r < 0) { + k5_buf_free(buf); + return; +@@ -206,6 +200,16 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) + free(tmp); + } + ++void ++k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) ++{ ++ va_list ap; ++ ++ va_start(ap, fmt); ++ k5_buf_add_vfmt(buf, fmt, ap); ++ va_end(ap); ++} ++ + void * + k5_buf_get_space(struct k5buf *buf, size_t len) + { +diff --git a/src/util/support/libkrb5support-fixed.exports b/src/util/support/libkrb5support-fixed.exports +index 30c946e7e..cb9bf0826 100644 +--- a/src/util/support/libkrb5support-fixed.exports ++++ b/src/util/support/libkrb5support-fixed.exports +@@ -6,6 +6,7 @@ k5_buf_init_dynamic + k5_buf_add + k5_buf_add_len + k5_buf_add_fmt ++k5_buf_add_vfmt + k5_buf_get_space + k5_buf_truncate + k5_buf_status diff --git a/Add-libkrb5support-hex-functions-and-tests.patch b/Add-libkrb5support-hex-functions-and-tests.patch new file mode 100644 index 0000000..b09b708 --- /dev/null +++ b/Add-libkrb5support-hex-functions-and-tests.patch @@ -0,0 +1,496 @@ +From 9fa4d4095164c09b70061fce5c31ccbd97bc7553 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 19 Feb 2018 00:51:44 -0500 +Subject: [PATCH] Add libkrb5support hex functions and tests + +(cherry picked from commit 720dea558da0062d3cea4385327161e62cf09a5e) +--- + .gitignore | 1 + + src/include/k5-hex.h | 53 ++++++++ + src/util/support/Makefile.in | 15 ++- + src/util/support/deps | 6 + + src/util/support/hex.c | 116 ++++++++++++++++++ + src/util/support/libkrb5support-fixed.exports | 2 + + src/util/support/t_hex.c | 169 ++++++++++++++++++++++++++ + 7 files changed, 359 insertions(+), 3 deletions(-) + create mode 100644 src/include/k5-hex.h + create mode 100644 src/util/support/hex.c + create mode 100644 src/util/support/t_hex.c + +diff --git a/.gitignore b/.gitignore +index c13b5e356..91c8b942e 100644 +--- a/.gitignore ++++ b/.gitignore +@@ -517,6 +517,7 @@ local.properties + + /src/util/support/libkrb5support.exports + /src/util/support/t_base64 ++/src/util/support/t_hex + /src/util/support/t_json + /src/util/support/t_k5buf + /src/util/support/t_path +diff --git a/src/include/k5-hex.h b/src/include/k5-hex.h +new file mode 100644 +index 000000000..75bd2cb19 +--- /dev/null ++++ b/src/include/k5-hex.h +@@ -0,0 +1,53 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* include/k5-hex.h - libkrb5support hex encoding/decoding declarations */ ++/* ++ * Copyright (C) 2018 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#ifndef K5_HEX_H ++#define K5_HEX_H ++ ++#include "k5-platform.h" ++ ++/* ++ * Encode len bytes in hex, placing the result in allocated storage in ++ * *hex_out. Use uppercase hex digits if uppercase is non-zero. Return 0 on ++ * success, ENOMEM on error. ++ */ ++int k5_hex_encode(const void *bytes, size_t len, int uppercase, ++ char **hex_out); ++ ++/* ++ * Decode hex bytes, placing the result in allocated storage in *bytes_out and ++ * *len_out. Null-terminate the result (primarily for decoding passwords in ++ * libkdb_ldap). Return 0 on success, ENOMEM or EINVAL on error. ++ */ ++int k5_hex_decode(const char *hex, uint8_t **bytes_out, size_t *len_out); ++ ++#endif /* K5_HEX_H */ +diff --git a/src/util/support/Makefile.in b/src/util/support/Makefile.in +index 58ac2e333..caaf15822 100644 +--- a/src/util/support/Makefile.in ++++ b/src/util/support/Makefile.in +@@ -82,6 +82,7 @@ STLIBOBJS= \ + path.o \ + base64.o \ + json.o \ ++ hex.o \ + bcmp.o \ + strerror_r.o \ + $(GETTIMEOFDAY_ST_OBJ) \ +@@ -107,6 +108,7 @@ LIBOBJS= \ + $(OUTPRE)path.$(OBJEXT) \ + $(OUTPRE)base64.$(OBJEXT) \ + $(OUTPRE)json.$(OBJEXT) \ ++ $(OUTPRE)hex.$(OBJEXT) \ + $(OUTPRE)bcmp.$(OBJEXT) \ + $(OUTPRE)strerror_r.$(OBJEXT) \ + $(GETTIMEOFDAY_OBJ) \ +@@ -137,10 +139,12 @@ SRCS=\ + $(srcdir)/t_unal.c \ + $(srcdir)/t_path.c \ + $(srcdir)/t_json.c \ ++ $(srcdir)/t_hex.c \ + $(srcdir)/zap.c \ + $(srcdir)/path.c \ + $(srcdir)/base64.c \ + $(srcdir)/json.c \ ++ $(srcdir)/hex.c \ + $(srcdir)/bcmp.c \ + $(srcdir)/strerror_r.c \ + $(srcdir)/t_utf8.c \ +@@ -216,6 +220,9 @@ T_JSON_OBJS= t_json.o json.o base64.o k5buf.o $(PRINTF_ST_OBJ) + t_json: $(T_JSON_OBJS) + $(CC_LINK) -o $@ $(T_JSON_OBJS) + ++t_hex: t_hex.o hex.o ++ $(CC_LINK) -o $@ t_hex.o hex.o ++ + t_unal: t_unal.o + $(CC_LINK) -o t_unal t_unal.o + +@@ -227,7 +234,8 @@ T_UTF16_OBJS= t_utf16.o utf8_conv.o utf8.o k5buf.o $(PRINTF_ST_OBJ) + t_utf16: $(T_UTF16_OBJS) + $(CC_LINK) -o $@ $(T_UTF16_OBJS) + +-TEST_PROGS= t_k5buf t_path t_path_win t_base64 t_json t_unal t_utf8 t_utf16 ++TEST_PROGS= t_k5buf t_path t_path_win t_base64 t_json t_hex t_unal t_utf8 \ ++ t_utf16 + + check-unix: $(TEST_PROGS) + ./t_k5buf +@@ -235,6 +243,7 @@ check-unix: $(TEST_PROGS) + ./t_path_win + ./t_base64 + ./t_json ++ ./t_hex + ./t_unal + ./t_utf8 + ./t_utf16 +@@ -242,8 +251,8 @@ check-unix: $(TEST_PROGS) + clean: + $(RM) t_k5buf.o t_k5buf t_unal.o t_unal path_win.o path_win + $(RM) t_path_win.o t_path_win t_path.o t_path t_base64.o t_base64 +- $(RM) t_json.o t_json libkrb5support.exports t_utf8.o t_utf8 +- $(RM) t_utf16.o t_utf16 ++ $(RM) t_json.o t_json t_hex.o t_hex libkrb5support.exports ++ $(RM) t_utf8.o t_utf8 t_utf16.o t_utf16 + + @lib_frag@ + @libobj_frag@ +diff --git a/src/util/support/deps b/src/util/support/deps +index 34d8a884b..80e9a1c58 100644 +--- a/src/util/support/deps ++++ b/src/util/support/deps +@@ -63,6 +63,9 @@ t_path.so t_path.po $(OUTPRE)t_path.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + t_path.c + t_json.so t_json.po $(OUTPRE)t_json.$(OBJEXT): $(top_srcdir)/include/k5-json.h \ + t_json.c ++t_hex.so t_hex.po $(OUTPRE)t_hex.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ ++ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-platform.h \ ++ $(top_srcdir)/include/k5-thread.h t_hex.c + zap.so zap.po $(OUTPRE)zap.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-thread.h \ + zap.c +@@ -76,6 +79,9 @@ json.so json.po $(OUTPRE)json.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(top_srcdir)/include/k5-base64.h $(top_srcdir)/include/k5-buf.h \ + $(top_srcdir)/include/k5-json.h $(top_srcdir)/include/k5-platform.h \ + $(top_srcdir)/include/k5-thread.h json.c ++hex.so hex.po $(OUTPRE)hex.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ ++ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-platform.h \ ++ $(top_srcdir)/include/k5-thread.h hex.c + bcmp.so bcmp.po $(OUTPRE)bcmp.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-thread.h \ + bcmp.c +diff --git a/src/util/support/hex.c b/src/util/support/hex.c +new file mode 100644 +index 000000000..4407ff9ff +--- /dev/null ++++ b/src/util/support/hex.c +@@ -0,0 +1,116 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* util/support/hex.c - hex encoding/decoding implementation */ ++/* ++ * Copyright (C) 2018 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#include ++#include ++#include ++ ++static inline char ++hex_digit(uint8_t bval, int uppercase) ++{ ++ assert(bval >= 0 && bval <= 0xF); ++ if (bval < 10) ++ return '0' + bval; ++ else if (uppercase) ++ return 'A' + (bval - 10); ++ else ++ return 'a' + (bval - 10); ++} ++ ++int ++k5_hex_encode(const void *bytes, size_t len, int uppercase, char **hex_out) ++{ ++ size_t i; ++ const uint8_t *p = bytes; ++ char *hex; ++ ++ *hex_out = NULL; ++ ++ hex = malloc(len * 2 + 1); ++ if (hex == NULL) ++ return ENOMEM; ++ ++ for (i = 0; i < len; i++) { ++ hex[i * 2] = hex_digit(p[i] >> 4, uppercase); ++ hex[i * 2 + 1] = hex_digit(p[i] & 0xF, uppercase); ++ } ++ hex[len * 2] = '\0'; ++ ++ *hex_out = hex; ++ return 0; ++} ++ ++/* Decode a hex digit. Return 0-15 on success, -1 on invalid input. */ ++static inline int ++decode_hexchar(unsigned char c) ++{ ++ if (isdigit(c)) ++ return c - '0'; ++ if (c >= 'A' && c <= 'F') ++ return c - 'A' + 10; ++ if (c >= 'a' && c <= 'f') ++ return c - 'a' + 10; ++ return -1; ++} ++ ++int ++k5_hex_decode(const char *hex, uint8_t **bytes_out, size_t *len_out) ++{ ++ size_t hexlen, i; ++ int h1, h2; ++ uint8_t *bytes; ++ ++ *bytes_out = NULL; ++ *len_out = 0; ++ ++ hexlen = strlen(hex); ++ if (hexlen % 2 != 0) ++ return EINVAL; ++ bytes = malloc(hexlen / 2 + 1); ++ if (bytes == NULL) ++ return ENOMEM; ++ ++ for (i = 0; i < hexlen / 2; i++) { ++ h1 = decode_hexchar(hex[i * 2]); ++ h2 = decode_hexchar(hex[i * 2 + 1]); ++ if (h1 == -1 || h2 == -1) { ++ free(bytes); ++ return EINVAL; ++ } ++ bytes[i] = h1 * 16 + h2; ++ } ++ bytes[i] = 0; ++ ++ *bytes_out = bytes; ++ *len_out = hexlen / 2; ++ return 0; ++} +diff --git a/src/util/support/libkrb5support-fixed.exports b/src/util/support/libkrb5support-fixed.exports +index fd74a1897..30c946e7e 100644 +--- a/src/util/support/libkrb5support-fixed.exports ++++ b/src/util/support/libkrb5support-fixed.exports +@@ -16,6 +16,8 @@ k5_get_error + k5_free_error + k5_clear_error + k5_set_error_info_callout_fn ++k5_hex_decode ++k5_hex_encode + k5_json_array_add + k5_json_array_create + k5_json_array_fmt +diff --git a/src/util/support/t_hex.c b/src/util/support/t_hex.c +new file mode 100644 +index 000000000..a586a1bc8 +--- /dev/null ++++ b/src/util/support/t_hex.c +@@ -0,0 +1,169 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* util/support/t_hex.c - Test hex encoding and decoding */ ++/* ++ * Copyright (C) 2018 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#include ++#include ++ ++struct { ++ const char *hex; ++ const char *binary; ++ size_t binary_len; ++ int uppercase; ++} tests[] = { ++ /* Invalid hex strings */ ++ { "1" }, ++ { "123" }, ++ { "0/" }, ++ { "/0" }, ++ { "0:" }, ++ { ":0" }, ++ { "0@" }, ++ { "@0" }, ++ { "0G" }, ++ { "G0" }, ++ { "0`" }, ++ { "`0" }, ++ { "0g" }, ++ { "g0" }, ++ { " 00 " }, ++ { "0\x01" }, ++ ++ { "", "", 0 }, ++ { "00", "\x00", 1 }, ++ { "01", "\x01", 1 }, ++ { "10", "\x10", 1 }, ++ { "01ff", "\x01\xFF", 2 }, ++ { "A0B0C0", "\xA0\xB0\xC0", 3, 1 }, ++ { "1a2b3c4d5e6f", "\x1A\x2B\x3C\x4D\x5E\x6F", 6 }, ++ { "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff", ++ "\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF" ++ "\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF", 32 }, ++ ++ /* All byte values, lowercase */ ++ { "0001020304050607", "\x00\x01\x02\x03\x04\x05\x06\x07", 8 }, ++ { "08090a0b0c0d0e0f", "\x08\x09\x0A\x0B\x0C\x0D\x0E\x0F", 8 }, ++ { "1011121314151617", "\x10\x11\x12\x13\x14\x15\x16\x17", 8 }, ++ { "18191a1b1c1d1e1f", "\x18\x19\x1A\x1B\x1C\x1D\x1E\x1F", 8 }, ++ { "2021222324252627", "\x20\x21\x22\x23\x24\x25\x26\x27", 8 }, ++ { "28292a2b2c2d2e2f", "\x28\x29\x2A\x2B\x2C\x2D\x2E\x2F", 8 }, ++ { "3031323334353637", "\x30\x31\x32\x33\x34\x35\x36\x37", 8 }, ++ { "38393a3b3c3d3e3f", "\x38\x39\x3A\x3B\x3C\x3D\x3E\x3F", 8 }, ++ { "4041424344454647", "\x40\x41\x42\x43\x44\x45\x46\x47", 8 }, ++ { "48494a4b4c4d4e4f", "\x48\x49\x4A\x4B\x4C\x4D\x4E\x4F", 8 }, ++ { "5051525354555657", "\x50\x51\x52\x53\x54\x55\x56\x57", 8 }, ++ { "58595a5b5c5d5e5f", "\x58\x59\x5A\x5B\x5C\x5D\x5E\x5F", 8 }, ++ { "6061626364656667", "\x60\x61\x62\x63\x64\x65\x66\x67", 8 }, ++ { "68696a6b6c6d6e6f", "\x68\x69\x6A\x6B\x6C\x6D\x6E\x6F", 8 }, ++ { "7071727374757677", "\x70\x71\x72\x73\x74\x75\x76\x77", 8 }, ++ { "78797a7b7c7d7e7f", "\x78\x79\x7A\x7B\x7C\x7D\x7E\x7F", 8 }, ++ { "8081828384858687", "\x80\x81\x82\x83\x84\x85\x86\x87", 8 }, ++ { "88898a8b8c8d8e8f", "\x88\x89\x8A\x8B\x8C\x8D\x8E\x8F", 8 }, ++ { "9091929394959697", "\x90\x91\x92\x93\x94\x95\x96\x97", 8 }, ++ { "98999a9b9c9d9e9f", "\x98\x99\x9A\x9B\x9C\x9D\x9E\x9F", 8 }, ++ { "a0a1a2a3a4a5a6a7", "\xA0\xA1\xA2\xA3\xA4\xA5\xA6\xA7", 8 }, ++ { "a8a9aaabacadaeaf", "\xA8\xA9\xAA\xAB\xAC\xAD\xAE\xAF", 8 }, ++ { "b0b1b2b3b4b5b6b7", "\xB0\xB1\xB2\xB3\xB4\xB5\xB6\xB7", 8 }, ++ { "b8b9babbbcbdbebf", "\xB8\xB9\xBA\xBB\xBC\xBD\xBE\xBF", 8 }, ++ { "c0c1c2c3c4c5c6c7", "\xC0\xC1\xC2\xC3\xC4\xC5\xC6\xC7", 8 }, ++ { "c8c9cacbcccdcecf", "\xC8\xC9\xCA\xCB\xCC\xCD\xCE\xCF", 8 }, ++ { "d0d1d2d3d4d5d6d7", "\xD0\xD1\xD2\xD3\xD4\xD5\xD6\xD7", 8 }, ++ { "d8d9dadbdcdddedf", "\xD8\xD9\xDA\xDB\xDC\xDD\xDE\xDF", 8 }, ++ { "e0e1e2e3e4e5e6e7", "\xE0\xE1\xE2\xE3\xE4\xE5\xE6\xE7", 8 }, ++ { "e8e9eaebecedeeef", "\xE8\xE9\xEA\xEB\xEC\xED\xEE\xEF", 8 }, ++ { "f0f1f2f3f4f5f6f7", "\xF0\xF1\xF2\xF3\xF4\xF5\xF6\xF7", 8 }, ++ { "f8f9fafbfcfdfeff", "\xF8\xF9\xFA\xFB\xFC\xFD\xFE\xFF", 8 }, ++ ++ /* All byte values, uppercase */ ++ { "0001020304050607", "\x00\x01\x02\x03\x04\x05\x06\x07", 8, 1 }, ++ { "08090A0B0C0D0E0F", "\x08\x09\x0A\x0B\x0C\x0D\x0E\x0F", 8, 1 }, ++ { "1011121314151617", "\x10\x11\x12\x13\x14\x15\x16\x17", 8, 1 }, ++ { "18191A1B1C1D1E1F", "\x18\x19\x1A\x1B\x1C\x1D\x1E\x1F", 8, 1 }, ++ { "2021222324252627", "\x20\x21\x22\x23\x24\x25\x26\x27", 8, 1 }, ++ { "28292A2B2C2D2E2F", "\x28\x29\x2A\x2B\x2C\x2D\x2E\x2F", 8, 1 }, ++ { "3031323334353637", "\x30\x31\x32\x33\x34\x35\x36\x37", 8, 1 }, ++ { "38393A3B3C3D3E3F", "\x38\x39\x3A\x3B\x3C\x3D\x3E\x3F", 8, 1 }, ++ { "4041424344454647", "\x40\x41\x42\x43\x44\x45\x46\x47", 8, 1 }, ++ { "48494A4B4C4D4E4F", "\x48\x49\x4A\x4B\x4C\x4D\x4E\x4F", 8, 1 }, ++ { "5051525354555657", "\x50\x51\x52\x53\x54\x55\x56\x57", 8, 1 }, ++ { "58595A5B5C5D5E5F", "\x58\x59\x5A\x5B\x5C\x5D\x5E\x5F", 8, 1 }, ++ { "6061626364656667", "\x60\x61\x62\x63\x64\x65\x66\x67", 8, 1 }, ++ { "68696A6B6C6D6E6F", "\x68\x69\x6A\x6B\x6C\x6D\x6E\x6F", 8, 1 }, ++ { "7071727374757677", "\x70\x71\x72\x73\x74\x75\x76\x77", 8, 1 }, ++ { "78797A7B7C7D7E7F", "\x78\x79\x7A\x7B\x7C\x7D\x7E\x7F", 8, 1 }, ++ { "8081828384858687", "\x80\x81\x82\x83\x84\x85\x86\x87", 8, 1 }, ++ { "88898A8B8C8D8E8F", "\x88\x89\x8A\x8B\x8C\x8D\x8E\x8F", 8, 1 }, ++ { "9091929394959697", "\x90\x91\x92\x93\x94\x95\x96\x97", 8, 1 }, ++ { "98999A9B9C9D9E9F", "\x98\x99\x9A\x9B\x9C\x9D\x9E\x9F", 8, 1 }, ++ { "A0A1A2A3A4A5A6A7", "\xA0\xA1\xA2\xA3\xA4\xA5\xA6\xA7", 8, 1 }, ++ { "A8A9AAABACADAEAF", "\xA8\xA9\xAA\xAB\xAC\xAD\xAE\xAF", 8, 1 }, ++ { "B0B1B2B3B4B5B6B7", "\xB0\xB1\xB2\xB3\xB4\xB5\xB6\xB7", 8, 1 }, ++ { "B8B9BABBBCBDBEBF", "\xB8\xB9\xBA\xBB\xBC\xBD\xBE\xBF", 8, 1 }, ++ { "C0C1C2C3C4C5C6C7", "\xC0\xC1\xC2\xC3\xC4\xC5\xC6\xC7", 8, 1 }, ++ { "C8C9CACBCCCDCECF", "\xC8\xC9\xCA\xCB\xCC\xCD\xCE\xCF", 8, 1 }, ++ { "D0D1D2D3D4D5D6D7", "\xD0\xD1\xD2\xD3\xD4\xD5\xD6\xD7", 8, 1 }, ++ { "D8D9DADBDCDDDEDF", "\xD8\xD9\xDA\xDB\xDC\xDD\xDE\xDF", 8, 1 }, ++ { "E0E1E2E3E4E5E6E7", "\xE0\xE1\xE2\xE3\xE4\xE5\xE6\xE7", 8, 1 }, ++ { "E8E9EAEBECEDEEEF", "\xE8\xE9\xEA\xEB\xEC\xED\xEE\xEF", 8, 1 }, ++ { "F0F1F2F3F4F5F6F7", "\xF0\xF1\xF2\xF3\xF4\xF5\xF6\xF7", 8, 1 }, ++ { "F8F9FAFBFCFDFEFF", "\xF8\xF9\xFA\xFB\xFC\xFD\xFE\xFF", 8, 1 }, ++}; ++ ++int main() ++{ ++ size_t i; ++ char *hex; ++ int ret; ++ uint8_t *bytes; ++ size_t len; ++ ++ for (i = 0; i < sizeof(tests) / sizeof(*tests); i++) { ++ if (tests[i].binary == NULL) { ++ ret = k5_hex_decode(tests[i].hex, &bytes, &len); ++ assert(ret == EINVAL && bytes == NULL && len == 0); ++ continue; ++ } ++ ++ ret = k5_hex_decode(tests[i].hex, &bytes, &len); ++ assert(ret == 0); ++ assert(len == tests[i].binary_len); ++ assert(memcmp(bytes, tests[i].binary, len) == 0); ++ assert(bytes[len] == 0); ++ free(bytes); ++ ++ ret = k5_hex_encode((uint8_t *)tests[i].binary, tests[i].binary_len, ++ tests[i].uppercase, &hex); ++ assert(ret == 0); ++ assert(strcmp(tests[i].hex, hex) == 0); ++ free(hex); ++ } ++ return 0; ++} diff --git a/Add-vector-support-to-k5_sha256.patch b/Add-vector-support-to-k5_sha256.patch new file mode 100644 index 0000000..1a04ac4 --- /dev/null +++ b/Add-vector-support-to-k5_sha256.patch @@ -0,0 +1,106 @@ +From 73fe8ea67105a4e056c82a0593dad8e6820f05d4 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sat, 3 Feb 2018 20:53:42 -0500 +Subject: [PATCH] Add vector support to k5_sha256() + +Add a length argument so that multiple krb5_data values can be passed +to k5_sha256(), for efficient computation of SHA-256 hashes over +concatenations of data values. + +(cherry picked from commit 4f3373e8c55b3e9bdfb5b065e07214c5816c85fa) +--- + src/include/k5-int.h | 4 ++-- + src/lib/crypto/builtin/sha2/sha256.c | 6 ++++-- + src/lib/crypto/crypto_tests/t_sha2.c | 2 +- + src/lib/crypto/openssl/sha256.c | 6 ++++-- + src/lib/krb5/rcache/rc_conv.c | 2 +- + 5 files changed, 12 insertions(+), 8 deletions(-) + +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 9378ae047..1c1d9783b 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -635,9 +635,9 @@ krb5int_arcfour_gsscrypt(const krb5_keyblock *keyblock, krb5_keyusage usage, + + #define K5_SHA256_HASHLEN (256 / 8) + +-/* Write the SHA-256 hash of in to out. */ ++/* Write the SHA-256 hash of in (containing n elements) to out. */ + krb5_error_code +-k5_sha256(const krb5_data *in, uint8_t out[K5_SHA256_HASHLEN]); ++k5_sha256(const krb5_data *in, size_t n, uint8_t out[K5_SHA256_HASHLEN]); + + /* + * Attempt to zero memory in a way that compilers won't optimize out. +diff --git a/src/lib/crypto/builtin/sha2/sha256.c b/src/lib/crypto/builtin/sha2/sha256.c +index 2b5cbe480..9a940b3f8 100644 +--- a/src/lib/crypto/builtin/sha2/sha256.c ++++ b/src/lib/crypto/builtin/sha2/sha256.c +@@ -257,12 +257,14 @@ k5_sha256_final(void *res, SHA256_CTX *m) + } + + krb5_error_code +-k5_sha256(const krb5_data *in, uint8_t out[K5_SHA256_HASHLEN]) ++k5_sha256(const krb5_data *in, size_t n, uint8_t out[K5_SHA256_HASHLEN]) + { + SHA256_CTX ctx; ++ size_t i; + + k5_sha256_init(&ctx); +- k5_sha256_update(&ctx, in->data, in->length); ++ for (i = 0; i < n; i++) ++ k5_sha256_update(&ctx, in[i].data, in[i].length); + k5_sha256_final(out, &ctx); + return 0; + } +diff --git a/src/lib/crypto/crypto_tests/t_sha2.c b/src/lib/crypto/crypto_tests/t_sha2.c +index 12f32869b..e6fa58498 100644 +--- a/src/lib/crypto/crypto_tests/t_sha2.c ++++ b/src/lib/crypto/crypto_tests/t_sha2.c +@@ -125,7 +125,7 @@ hash_test(const struct krb5_hash_provider *hash, struct test *tests) + + if (hash == &krb5int_hash_sha256) { + /* Try again using k5_sha256(). */ +- if (k5_sha256(&iov.data, (uint8_t *)hval.data) != 0) ++ if (k5_sha256(&iov.data, 1, (uint8_t *)hval.data) != 0) + abort(); + if (memcmp(hval.data, t->hash, hval.length) != 0) + abort(); +diff --git a/src/lib/crypto/openssl/sha256.c b/src/lib/crypto/openssl/sha256.c +index fa095d472..0edd8b7ba 100644 +--- a/src/lib/crypto/openssl/sha256.c ++++ b/src/lib/crypto/openssl/sha256.c +@@ -34,16 +34,18 @@ + #include + + krb5_error_code +-k5_sha256(const krb5_data *in, uint8_t out[K5_SHA256_HASHLEN]) ++k5_sha256(const krb5_data *in, size_t n, uint8_t out[K5_SHA256_HASHLEN]) + { + EVP_MD_CTX *ctx; ++ size_t i; + int ok; + + ctx = EVP_MD_CTX_new(); + if (ctx == NULL) + return ENOMEM; + ok = EVP_DigestInit_ex(ctx, EVP_sha256(), NULL); +- ok = ok && EVP_DigestUpdate(ctx, in->data, in->length); ++ for (i = 0; i < n; i++) ++ ok = ok && EVP_DigestUpdate(ctx, in[i].data, in[i].length); + ok = ok && EVP_DigestFinal_ex(ctx, out, NULL); + EVP_MD_CTX_free(ctx); + return ok ? 0 : ENOMEM; +diff --git a/src/lib/krb5/rcache/rc_conv.c b/src/lib/krb5/rcache/rc_conv.c +index 0e021f5d8..f2fe528ac 100644 +--- a/src/lib/krb5/rcache/rc_conv.c ++++ b/src/lib/krb5/rcache/rc_conv.c +@@ -58,7 +58,7 @@ krb5_rc_hash_message(krb5_context context, const krb5_data *message, + *out = NULL; + + /* Calculate the binary checksum. */ +- retval = k5_sha256(message, cksum); ++ retval = k5_sha256(message, 1, cksum); + if (retval) + return retval; + diff --git a/Implement-k5_buf_init_dynamic_zap.patch b/Implement-k5_buf_init_dynamic_zap.patch new file mode 100644 index 0000000..4f78d34 --- /dev/null +++ b/Implement-k5_buf_init_dynamic_zap.patch @@ -0,0 +1,149 @@ +From 7a578d56d42d12973ec17be4cffd983c57aa38c9 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 26 Mar 2018 11:12:39 -0400 +Subject: [PATCH] Implement k5_buf_init_dynamic_zap + +Add a variant of dynamic k5buf objects which zeroes memory when +reallocating or freeing the buffer. + +(cherry picked from commit 8ee8246c14702dc03b02e31b9fb5b7c2bb674bfb) +--- + src/include/k5-buf.h | 6 +++- + src/util/support/k5buf.c | 41 +++++++++++++++++++++------ + src/util/support/libkrb5support-fixed.exports | 1 + + 3 files changed, 39 insertions(+), 9 deletions(-) + +diff --git a/src/include/k5-buf.h b/src/include/k5-buf.h +index 1223916a6..48e2a7d53 100644 +--- a/src/include/k5-buf.h ++++ b/src/include/k5-buf.h +@@ -45,7 +45,7 @@ + */ + + /* Buffer type values */ +-enum k5buftype { K5BUF_ERROR, K5BUF_FIXED, K5BUF_DYNAMIC }; ++enum k5buftype { K5BUF_ERROR, K5BUF_FIXED, K5BUF_DYNAMIC, K5BUF_DYNAMIC_ZAP }; + + struct k5buf { + enum k5buftype buftype; +@@ -63,6 +63,10 @@ void k5_buf_init_fixed(struct k5buf *buf, char *data, size_t space); + /* Initialize a k5buf using an internally allocated dynamic buffer. */ + void k5_buf_init_dynamic(struct k5buf *buf); + ++/* Initialize a k5buf using an internally allocated dynamic buffer, zeroing ++ * memory when reallocating or freeing. */ ++void k5_buf_init_dynamic_zap(struct k5buf *buf); ++ + /* Add a C string to BUF. */ + void k5_buf_add(struct k5buf *buf, const char *data); + +diff --git a/src/util/support/k5buf.c b/src/util/support/k5buf.c +index 35978f238..b2b5e5b67 100644 +--- a/src/util/support/k5buf.c ++++ b/src/util/support/k5buf.c +@@ -37,7 +37,7 @@ + /* + * Structure invariants: + * +- * buftype is K5BUF_FIXED, K5BUF_DYNAMIC, or K5BUF_ERROR ++ * buftype is K5BUF_FIXED, K5BUF_DYNAMIC, K5BUF_DYNAMIC_ZAP, or K5BUF_ERROR + * if buftype is K5BUF_ERROR, the other fields are NULL or 0 + * if buftype is not K5BUF_ERROR: + * space > 0 +@@ -77,22 +77,35 @@ ensure_space(struct k5buf *buf, size_t len) + return 1; + if (buf->buftype == K5BUF_FIXED) /* Can't resize a fixed buffer. */ + goto error_exit; +- assert(buf->buftype == K5BUF_DYNAMIC); ++ assert(buf->buftype == K5BUF_DYNAMIC || buf->buftype == K5BUF_DYNAMIC_ZAP); + new_space = buf->space * 2; + while (new_space - buf->len - 1 < len) { + if (new_space > SIZE_MAX / 2) + goto error_exit; + new_space *= 2; + } +- new_data = realloc(buf->data, new_space); +- if (new_data == NULL) +- goto error_exit; ++ if (buf->buftype == K5BUF_DYNAMIC_ZAP) { ++ /* realloc() could leave behind a partial copy of sensitive data. */ ++ new_data = malloc(new_space); ++ if (new_data == NULL) ++ goto error_exit; ++ memcpy(new_data, buf->data, buf->len); ++ new_data[buf->len] = '\0'; ++ zap(buf->data, buf->len); ++ free(buf->data); ++ } else { ++ new_data = realloc(buf->data, new_space); ++ if (new_data == NULL) ++ goto error_exit; ++ } + buf->data = new_data; + buf->space = new_space; + return 1; + + error_exit: +- if (buf->buftype == K5BUF_DYNAMIC) ++ if (buf->buftype == K5BUF_DYNAMIC_ZAP) ++ zap(buf->data, buf->len); ++ if (buf->buftype == K5BUF_DYNAMIC_ZAP || buf->buftype == K5BUF_DYNAMIC) + free(buf->data); + set_error(buf); + return 0; +@@ -123,6 +136,14 @@ k5_buf_init_dynamic(struct k5buf *buf) + *endptr(buf) = '\0'; + } + ++void ++k5_buf_init_dynamic_zap(struct k5buf *buf) ++{ ++ k5_buf_init_dynamic(buf); ++ if (buf->buftype == K5BUF_DYNAMIC) ++ buf->buftype = K5BUF_DYNAMIC_ZAP; ++} ++ + void + k5_buf_add(struct k5buf *buf, const char *data) + { +@@ -163,7 +184,7 @@ k5_buf_add_vfmt(struct k5buf *buf, const char *fmt, va_list ap) + } + + /* Optimistically format the data directly into the dynamic buffer. */ +- assert(buf->buftype == K5BUF_DYNAMIC); ++ assert(buf->buftype == K5BUF_DYNAMIC || buf->buftype == K5BUF_DYNAMIC_ZAP); + va_copy(apcopy, ap); + r = vsnprintf(endptr(buf), remaining, fmt, apcopy); + va_end(apcopy); +@@ -197,6 +218,8 @@ k5_buf_add_vfmt(struct k5buf *buf, const char *fmt, va_list ap) + memcpy(endptr(buf), tmp, r + 1); + buf->len += r; + } ++ if (buf->buftype == K5BUF_DYNAMIC_ZAP) ++ zap(tmp, strlen(tmp)); + free(tmp); + } + +@@ -241,7 +264,9 @@ k5_buf_free(struct k5buf *buf) + { + if (buf->buftype == K5BUF_ERROR) + return; +- assert(buf->buftype == K5BUF_DYNAMIC); ++ assert(buf->buftype == K5BUF_DYNAMIC || buf->buftype == K5BUF_DYNAMIC_ZAP); ++ if (buf->buftype == K5BUF_DYNAMIC_ZAP) ++ zap(buf->data, buf->len); + free(buf->data); + set_error(buf); + } +diff --git a/src/util/support/libkrb5support-fixed.exports b/src/util/support/libkrb5support-fixed.exports +index cb9bf0826..a5e2ade04 100644 +--- a/src/util/support/libkrb5support-fixed.exports ++++ b/src/util/support/libkrb5support-fixed.exports +@@ -3,6 +3,7 @@ k5_base64_encode + k5_bcmp + k5_buf_init_fixed + k5_buf_init_dynamic ++k5_buf_init_dynamic_zap + k5_buf_add + k5_buf_add_len + k5_buf_add_fmt diff --git a/Move-zap-definition-to-k5-platform.h.patch b/Move-zap-definition-to-k5-platform.h.patch new file mode 100644 index 0000000..83e7e94 --- /dev/null +++ b/Move-zap-definition-to-k5-platform.h.patch @@ -0,0 +1,151 @@ +From 5824de8b471d132ed58eece98c614c56c7b0d48d Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 26 Mar 2018 10:54:29 -0400 +Subject: [PATCH] Move zap() definition to k5-platform.h + +Make it possible to use zap() in parts of the code which should not +include k5-int.h by moving its definition to k5-platform.h. + +(cherry picked from commit df6bef6f9ea6a5f6f3956a2988cd658c78aae817) +--- + src/include/k5-int.h | 45 --------------------------------------------- + src/include/k5-platform.h | 47 ++++++++++++++++++++++++++++++++++++++++++++++- + src/util/support/zap.c | 4 ++-- + 3 files changed, 48 insertions(+), 48 deletions(-) + +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 1c1d9783b..69b81a7f7 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -639,51 +639,6 @@ krb5int_arcfour_gsscrypt(const krb5_keyblock *keyblock, krb5_keyusage usage, + krb5_error_code + k5_sha256(const krb5_data *in, size_t n, uint8_t out[K5_SHA256_HASHLEN]); + +-/* +- * Attempt to zero memory in a way that compilers won't optimize out. +- * +- * This mechanism should work even for heap storage about to be freed, +- * or automatic storage right before we return from a function. +- * +- * Then, even if we leak uninitialized memory someplace, or UNIX +- * "core" files get created with world-read access, some of the most +- * sensitive data in the process memory will already be safely wiped. +- * +- * We're not going so far -- yet -- as to try to protect key data that +- * may have been written into swap space.... +- */ +-#ifdef _WIN32 +-# define zap(ptr, len) SecureZeroMemory(ptr, len) +-#elif defined(__STDC_LIB_EXT1__) +-/* +- * Use memset_s() which cannot be optimized out. Avoid memset_s(NULL, 0, 0, 0) +- * which would cause a runtime constraint violation. +- */ +-static inline void zap(void *ptr, size_t len) +-{ +- if (len > 0) +- memset_s(ptr, len, 0, len); +-} +-#elif defined(__GNUC__) || defined(__clang__) +-/* +- * Use an asm statement which declares a memory clobber to force the memset to +- * be carried out. Avoid memset(NULL, 0, 0) which has undefined behavior. +- */ +-static inline void zap(void *ptr, size_t len) +-{ +- if (len > 0) +- memset(ptr, 0, len); +- __asm__ __volatile__("" : : "r" (ptr) : "memory"); +-} +-#else +-/* +- * Use a function from libkrb5support to defeat inlining unless link-time +- * optimization is used. The function uses a volatile pointer, which prevents +- * current compilers from optimizing out the memset. +- */ +-# define zap(ptr, len) krb5int_zap(ptr, len) +-#endif +- + /* Convenience function: zap and free ptr if it is non-NULL. */ + static inline void + zapfree(void *ptr, size_t len) +diff --git a/src/include/k5-platform.h b/src/include/k5-platform.h +index 548c0486d..07ef6a4ca 100644 +--- a/src/include/k5-platform.h ++++ b/src/include/k5-platform.h +@@ -40,7 +40,7 @@ + * + [v]asprintf + * + strerror_r + * + mkstemp +- * + zap (support function; macro is in k5-int.h) ++ * + zap (support function and macro) + * + constant time memory comparison + * + path manipulation + * + _, N_, dgettext, bindtextdomain (for localization) +@@ -1022,6 +1022,51 @@ extern int krb5int_gettimeofday(struct timeval *tp, void *ignore); + #define gettimeofday krb5int_gettimeofday + #endif + ++/* ++ * Attempt to zero memory in a way that compilers won't optimize out. ++ * ++ * This mechanism should work even for heap storage about to be freed, ++ * or automatic storage right before we return from a function. ++ * ++ * Then, even if we leak uninitialized memory someplace, or UNIX ++ * "core" files get created with world-read access, some of the most ++ * sensitive data in the process memory will already be safely wiped. ++ * ++ * We're not going so far -- yet -- as to try to protect key data that ++ * may have been written into swap space.... ++ */ ++#ifdef _WIN32 ++# define zap(ptr, len) SecureZeroMemory(ptr, len) ++#elif defined(__STDC_LIB_EXT1__) ++/* ++ * Use memset_s() which cannot be optimized out. Avoid memset_s(NULL, 0, 0, 0) ++ * which would cause a runtime constraint violation. ++ */ ++static inline void zap(void *ptr, size_t len) ++{ ++ if (len > 0) ++ memset_s(ptr, len, 0, len); ++} ++#elif defined(__GNUC__) || defined(__clang__) ++/* ++ * Use an asm statement which declares a memory clobber to force the memset to ++ * be carried out. Avoid memset(NULL, 0, 0) which has undefined behavior. ++ */ ++static inline void zap(void *ptr, size_t len) ++{ ++ if (len > 0) ++ memset(ptr, 0, len); ++ __asm__ __volatile__("" : : "r" (ptr) : "memory"); ++} ++#else ++/* ++ * Use a function from libkrb5support to defeat inlining unless link-time ++ * optimization is used. The function uses a volatile pointer, which prevents ++ * current compilers from optimizing out the memset. ++ */ ++# define zap(ptr, len) krb5int_zap(ptr, len) ++#endif ++ + extern void krb5int_zap(void *ptr, size_t len); + + /* +diff --git a/src/util/support/zap.c b/src/util/support/zap.c +index ed31630db..2f6cdd70e 100644 +--- a/src/util/support/zap.c ++++ b/src/util/support/zap.c +@@ -25,8 +25,8 @@ + */ + + /* +- * krb5int_zap() is used by zap() (a static inline function defined in +- * k5-int.h) on non-Windows, non-gcc compilers, in order to prevent the ++ * krb5int_zap() is used by zap() (a macro or static inline function defined in ++ * k5-platform.h) on non-Windows, non-gcc compilers, in order to prevent the + * compiler from inlining and optimizing out the memset() call. + */ + diff --git a/Use-k5_buf_init_dynamic_zap-where-appropriate.patch b/Use-k5_buf_init_dynamic_zap-where-appropriate.patch new file mode 100644 index 0000000..a0ecfd4 --- /dev/null +++ b/Use-k5_buf_init_dynamic_zap-where-appropriate.patch @@ -0,0 +1,62 @@ +From 9168f0c02a066543a8d03c60e4f05d5f4073f373 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 26 Mar 2018 11:24:49 -0400 +Subject: [PATCH] Use k5_buf_init_dynamic_zap where appropriate + +(cherry picked from commit 9172599008f3a6790d4a9a67acff58049742dcb6) +--- + src/lib/krb5/ccache/cc_file.c | 4 ++-- + src/lib/krb5/ccache/cc_keyring.c | 2 +- + src/util/support/utf8_conv.c | 4 +++- + 3 files changed, 6 insertions(+), 4 deletions(-) + +diff --git a/src/lib/krb5/ccache/cc_file.c b/src/lib/krb5/ccache/cc_file.c +index 6789c09e1..9263a0054 100644 +--- a/src/lib/krb5/ccache/cc_file.c ++++ b/src/lib/krb5/ccache/cc_file.c +@@ -758,7 +758,7 @@ fcc_next_cred(krb5_context context, krb5_ccache id, krb5_cc_cursor *cursor, + + memset(creds, 0, sizeof(*creds)); + k5_cc_mutex_lock(context, &data->lock); +- k5_buf_init_dynamic(&buf); ++ k5_buf_init_dynamic_zap(&buf); + + ret = krb5_lock_file(context, fileno(fcursor->fp), KRB5_LOCKMODE_SHARED); + if (ret) +@@ -982,7 +982,7 @@ fcc_store(krb5_context context, krb5_ccache id, krb5_creds *creds) + goto cleanup; + + /* Marshal the cred and write it to the file with a single append write. */ +- k5_buf_init_dynamic(&buf); ++ k5_buf_init_dynamic_zap(&buf); + k5_marshal_cred(&buf, version, creds); + ret = k5_buf_status(&buf); + if (ret) +diff --git a/src/lib/krb5/ccache/cc_keyring.c b/src/lib/krb5/ccache/cc_keyring.c +index fba710b1b..8419f6ebf 100644 +--- a/src/lib/krb5/ccache/cc_keyring.c ++++ b/src/lib/krb5/ccache/cc_keyring.c +@@ -1295,7 +1295,7 @@ krcc_store(krb5_context context, krb5_ccache id, krb5_creds *creds) + goto errout; + + /* Serialize credential using the file ccache version 4 format. */ +- k5_buf_init_dynamic(&buf); ++ k5_buf_init_dynamic_zap(&buf); + k5_marshal_cred(&buf, 4, creds); + ret = k5_buf_status(&buf); + if (ret) +diff --git a/src/util/support/utf8_conv.c b/src/util/support/utf8_conv.c +index 5cfc2c512..08cef4168 100644 +--- a/src/util/support/utf8_conv.c ++++ b/src/util/support/utf8_conv.c +@@ -99,7 +99,9 @@ k5_utf8_to_utf16le(const char *utf8, uint8_t **utf16_out, size_t *nbytes_out) + *utf16_out = NULL; + *nbytes_out = 0; + +- k5_buf_init_dynamic(&buf); ++ /* UTF-16 conversion is used for RC4 string-to-key, so treat this data as ++ * sensitive. */ ++ k5_buf_init_dynamic_zap(&buf); + + /* Examine next UTF-8 character. */ + while (*utf8 != '\0') { diff --git a/Use-libkrb5support-hex-functions-where-appropriate.patch b/Use-libkrb5support-hex-functions-where-appropriate.patch new file mode 100644 index 0000000..7af1f64 --- /dev/null +++ b/Use-libkrb5support-hex-functions-where-appropriate.patch @@ -0,0 +1,869 @@ +From a77bccb3fd953ae5800768efc0fb4a13753cb785 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 19 Feb 2018 00:52:35 -0500 +Subject: [PATCH] Use libkrb5support hex functions where appropriate + +(cherry picked from commit b0c700608be7455041a8afc0e4502e8783ee7f30) +--- + src/kadmin/dbutil/deps | 16 +++--- + src/kadmin/dbutil/tabdump.c | 19 +++---- + src/kadmin/ktutil/deps | 13 +++-- + src/kadmin/ktutil/ktutil_funcs.c | 30 ++++------ + src/lib/crypto/crypto_tests/deps | 39 +++++++------ + src/lib/crypto/crypto_tests/t_cksum.c | 35 +++--------- + src/lib/crypto/crypto_tests/t_crc.c | 28 ++-------- + src/lib/crypto/crypto_tests/t_hmac.c | 34 +++++------ + src/plugins/kdb/ldap/ldap_util/deps | 18 +++--- + .../kdb/ldap/ldap_util/kdb5_ldap_services.c | 32 ++++------- + .../kdb/ldap/ldap_util/kdb5_ldap_services.h | 2 - + src/plugins/kdb/ldap/libkdb_ldap/deps | 19 ++++--- + .../kdb/ldap/libkdb_ldap/ldap_service_stash.c | 65 +++------------------- + .../kdb/ldap/libkdb_ldap/ldap_service_stash.h | 3 - + .../kdb/ldap/libkdb_ldap/libkdb_ldap.exports | 1 - + src/slave/deps | 15 ++--- + src/slave/kproplog.c | 11 ++-- + src/tests/gssapi/deps | 14 ++--- + src/tests/gssapi/t_prf.c | 13 +++-- + 19 files changed, 152 insertions(+), 255 deletions(-) + +diff --git a/src/kadmin/dbutil/deps b/src/kadmin/dbutil/deps +index 4dcc33628..8b0965aac 100644 +--- a/src/kadmin/dbutil/deps ++++ b/src/kadmin/dbutil/deps +@@ -185,14 +185,14 @@ $(OUTPRE)tabdump.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/iprop.h \ + $(top_srcdir)/include/iprop_hdr.h $(top_srcdir)/include/k5-buf.h \ + $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/kdb.h $(top_srcdir)/include/kdb_log.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h kdb5_util.h tabdump.c \ +- tdumputil.h ++ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ ++ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ ++ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ ++ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/kdb.h \ ++ $(top_srcdir)/include/kdb_log.h $(top_srcdir)/include/krb5.h \ ++ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ ++ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ ++ kdb5_util.h tabdump.c tdumputil.h + $(OUTPRE)tdumputil.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ +diff --git a/src/kadmin/dbutil/tabdump.c b/src/kadmin/dbutil/tabdump.c +index fb36b060a..2f313dbb0 100644 +--- a/src/kadmin/dbutil/tabdump.c ++++ b/src/kadmin/dbutil/tabdump.c +@@ -32,6 +32,7 @@ + + #include + #include "k5-platform.h" /* for asprintf */ ++#include "k5-hex.h" + + #include + #include +@@ -230,9 +231,7 @@ static int + write_data(struct rec_args *args, krb5_data *data) + { + int ret; +- char *p; +- size_t i; +- struct k5buf buf; ++ char *hex; + struct rechandle *h = args->rh; + struct tdopts *opts = args->opts; + +@@ -241,17 +240,15 @@ write_data(struct rec_args *args, krb5_data *data) + return -1; + return 0; + } +- k5_buf_init_dynamic(&buf); +- p = data->data; +- for (i = 0; i < data->length; i++) +- k5_buf_add_fmt(&buf, "%02x", (unsigned char)p[i]); + +- if (buf.data == NULL) { +- errno = ENOMEM; ++ ret = k5_hex_encode(data->data, data->length, FALSE, &hex); ++ if (ret) { ++ errno = ret; + return -1; + } +- ret = writefield(h, "%s", (char *)buf.data); +- k5_buf_free(&buf); ++ ++ ret = writefield(h, "%s", hex); ++ free(hex); + return ret; + } + +diff --git a/src/kadmin/ktutil/deps b/src/kadmin/ktutil/deps +index 4df399924..5863e63c7 100644 +--- a/src/kadmin/ktutil/deps ++++ b/src/kadmin/ktutil/deps +@@ -18,9 +18,10 @@ $(OUTPRE)ktutil_funcs.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ + $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h ktutil.h ktutil_funcs.c ++ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ ++ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ ++ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ ++ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ ++ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ ++ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ ++ ktutil.h ktutil_funcs.c +diff --git a/src/kadmin/ktutil/ktutil_funcs.c b/src/kadmin/ktutil/ktutil_funcs.c +index 7a3aa0dca..5843e24b7 100644 +--- a/src/kadmin/ktutil/ktutil_funcs.c ++++ b/src/kadmin/ktutil/ktutil_funcs.c +@@ -29,6 +29,7 @@ + */ + + #include "k5-int.h" ++#include "k5-hex.h" + #include "ktutil.h" + #include + #include +@@ -106,9 +107,8 @@ krb5_error_code ktutil_add(context, list, princ_str, kvno, + krb5_keyblock key; + char buf[BUFSIZ]; + char promptstr[1024]; +- +- char *cp; +- int i, tmp; ++ uint8_t *keybytes; ++ size_t keylen; + unsigned int pwsize = BUFSIZ; + + retval = krb5_parse_name(context, princ_str, &princ); +@@ -199,24 +199,18 @@ krb5_error_code ktutil_add(context, list, princ_str, kvno, + goto cleanup; + } + +- lp->entry->key.enctype = enctype; +- lp->entry->key.contents = (krb5_octet *) malloc((strlen(buf) + 1) / 2); +- if (!lp->entry->key.contents) { +- retval = ENOMEM; ++ retval = k5_hex_decode(buf, &keybytes, &keylen); ++ if (retval) { ++ if (retval == EINVAL) { ++ fprintf(stderr, _("addent: Illegal character in key.\n")); ++ retval = 0; ++ } + goto cleanup; + } + +- i = 0; +- for (cp = buf; *cp; cp += 2) { +- if (!isxdigit((int) cp[0]) || !isxdigit((int) cp[1])) { +- fprintf(stderr, _("addent: Illegal character in key.\n")); +- retval = 0; +- goto cleanup; +- } +- sscanf(cp, "%02x", &tmp); +- lp->entry->key.contents[i++] = (krb5_octet) tmp; +- } +- lp->entry->key.length = i; ++ lp->entry->key.enctype = enctype; ++ lp->entry->key.contents = keybytes; ++ lp->entry->key.length = keylen; + } + lp->entry->principal = princ; + lp->entry->vno = kvno; +diff --git a/src/lib/crypto/crypto_tests/deps b/src/lib/crypto/crypto_tests/deps +index bc5422a06..5d94a593d 100644 +--- a/src/lib/crypto/crypto_tests/deps ++++ b/src/lib/crypto/crypto_tests/deps +@@ -73,12 +73,13 @@ $(OUTPRE)t_hmac.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(srcdir)/../builtin/crypto_mod.h $(srcdir)/../builtin/sha2/sha2.h \ + $(srcdir)/../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ + $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h t_hmac.c ++ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ ++ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ ++ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ ++ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ ++ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ ++ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ ++ t_hmac.c + $(OUTPRE)t_pkcs5.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ +@@ -143,12 +144,13 @@ $(OUTPRE)t_cksum.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ + $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h t_cksum.c ++ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ ++ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ ++ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ ++ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ ++ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ ++ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ ++ t_cksum.c + $(OUTPRE)t_cksums.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ +@@ -165,12 +167,13 @@ $(OUTPRE)t_crc.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(srcdir)/../builtin/crypto_mod.h $(srcdir)/../builtin/sha2/sha2.h \ + $(srcdir)/../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ + $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h t_crc.c ++ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ ++ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ ++ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ ++ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ ++ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ ++ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ ++ t_crc.c + $(OUTPRE)t_mddriver.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \ +diff --git a/src/lib/crypto/crypto_tests/t_cksum.c b/src/lib/crypto/crypto_tests/t_cksum.c +index 2200fe76e..0edaeb850 100644 +--- a/src/lib/crypto/crypto_tests/t_cksum.c ++++ b/src/lib/crypto/crypto_tests/t_cksum.c +@@ -27,6 +27,7 @@ + /* Test checksum and checksum compatability for rsa-md[4,5]-des. */ + + #include "k5-int.h" ++#include "k5-hex.h" + + #define MD5_K5BETA_COMPAT + #define MD4_K5BETA_COMPAT +@@ -50,29 +51,6 @@ print_checksum(char *text, int number, char *message, krb5_checksum *checksum) + printf("\n"); + } + +-static void +-parse_hexstring(const char *s, krb5_checksum *cksum) +-{ +- size_t i, len; +- unsigned int byte; +- unsigned char *cp; +- +- len = strlen(s); +- cp = malloc(len / 2); +- cksum->contents = cp; +- if (cp == NULL) { +- cksum->length = 0; +- return; +- } +- cksum->length = len / 2; +- for (i = 0; i + 1 < len; i += 2) { +- sscanf(&s[i], "%2x", &byte); +- *cp++ = byte; +- } +- cksum->checksum_type = CKTYPE; +- cksum->magic = KV5M_CHECKSUM; +-} +- + /* + * Test the checksum verification of Old Style (tm) and correct RSA-MD[4,5]-DES + * checksums. +@@ -86,6 +64,7 @@ main(argc, argv) + char **argv; + { + int msgindex; ++ size_t len; + krb5_boolean valid; + krb5_keyblock keyblock; + krb5_key key; +@@ -150,12 +129,14 @@ main(argc, argv) + free(checksum.contents); + + /* Verify a known-good checksum for this plaintext. */ +- parse_hexstring(argv[msgindex+1], &knowncksum); +- if (knowncksum.contents == NULL) { +- printf("parse_hexstring failed\n"); +- kret = 1; ++ kret = k5_hex_decode(argv[msgindex + 1], &knowncksum.contents, &len); ++ if (kret) { ++ printf("k5_hex_decode failed\n"); + break; + } ++ knowncksum.length = len; ++ knowncksum.checksum_type = CKTYPE; ++ knowncksum.magic = KV5M_CHECKSUM; + kret = krb5_k_verify_checksum(NULL, key, 0, &plaintext, &knowncksum, + &valid); + if (kret != 0) { +diff --git a/src/lib/crypto/crypto_tests/t_crc.c b/src/lib/crypto/crypto_tests/t_crc.c +index 190773252..1a35cfba5 100644 +--- a/src/lib/crypto/crypto_tests/t_crc.c ++++ b/src/lib/crypto/crypto_tests/t_crc.c +@@ -32,6 +32,7 @@ + #include + #include + #include ++#include + #include "crypto_int.h" + + #define HEX 1 +@@ -139,31 +140,12 @@ timetest(unsigned int nblk, unsigned int blksiz) + } + #endif + +-static void gethexstr(char *data, size_t *outlen, unsigned char *outbuf, +- size_t buflen) +-{ +- size_t inlen; +- char *cp, buf[3]; +- long n; +- +- inlen = strlen(data); +- *outlen = 0; +- for (cp = data; (size_t) (cp - data) < inlen; cp += 2) { +- strncpy(buf, cp, 2); +- buf[2] = '\0'; +- n = strtol(buf, NULL, 16); +- outbuf[(*outlen)++] = n; +- if (*outlen > buflen) +- break; +- } +-} +- + static void + verify(void) + { + unsigned int i; + struct crc_trial trial; +- unsigned char buf[4]; ++ uint8_t *bytes; + size_t len; + unsigned long cksum; + char *typestr; +@@ -179,9 +161,11 @@ verify(void) + break; + case HEX: + typestr = "HEX"; +- gethexstr(trial.data, &len, buf, 4); ++ if (k5_hex_decode(trial.data, &bytes, &len) != 0) ++ abort(); + cksum = 0; +- mit_crc32(buf, len, &cksum); ++ mit_crc32(bytes, len, &cksum); ++ free(bytes); + break; + default: + typestr = "BOGUS"; +diff --git a/src/lib/crypto/crypto_tests/t_hmac.c b/src/lib/crypto/crypto_tests/t_hmac.c +index 8961380ea..93d54828f 100644 +--- a/src/lib/crypto/crypto_tests/t_hmac.c ++++ b/src/lib/crypto/crypto_tests/t_hmac.c +@@ -34,6 +34,7 @@ + #include + #include + ++#include + #include "crypto_int.h" + + #define ASIZE(ARRAY) (sizeof(ARRAY)/sizeof(ARRAY[0])) +@@ -136,12 +137,10 @@ static void test_hmac() + { + krb5_keyblock key; + krb5_data in, out; +- char outbuf[20]; +- char stroutbuf[80]; ++ char outbuf[20], *hexdigest; + krb5_error_code err; +- unsigned int i, j; ++ unsigned int i; + int lose = 0; +- struct k5buf buf; + + /* RFC 2202 test vector. */ + static const struct hmac_test md5tests[] = { +@@ -151,13 +150,13 @@ static void test_hmac() + 0xb, 0xb, 0xb, 0xb, 0xb, 0xb, 0xb, 0xb, + }, + 8, "Hi There", +- "0x9294727a3638bb1c13f48ef8158bfc9d" ++ "9294727a3638bb1c13f48ef8158bfc9d" + }, + + { + 4, "Jefe", + 28, "what do ya want for nothing?", +- "0x750c783e6ab0b503eaa86e310a5db738" ++ "750c783e6ab0b503eaa86e310a5db738" + }, + + { +@@ -172,7 +171,7 @@ static void test_hmac() + 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, + 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, + }, +- "0x56be34521d144c88dbb8c733f0e8b3f6" ++ "56be34521d144c88dbb8c733f0e8b3f6" + }, + + { +@@ -188,7 +187,7 @@ static void test_hmac() + 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, + 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, + }, +- "0x697eaf0aca3a3aea3a75164746ffaa79" ++ "697eaf0aca3a3aea3a75164746ffaa79" + }, + + { +@@ -197,7 +196,7 @@ static void test_hmac() + 0x0c, 0x0c, 0x0c, 0x0c, 0x0c, 0x0c, 0x0c, 0x0c + }, + 20, "Test With Truncation", +- "0x56461ef2342edc00f9bab995690efd4c" ++ "56461ef2342edc00f9bab995690efd4c" + }, + + { +@@ -212,7 +211,7 @@ static void test_hmac() + 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, + }, + 54, "Test Using Larger Than Block-Size Key - Hash Key First", +- "0x6b1ab7fe4bd7bf8f0b62e6ce61b9d0cd" ++ "6b1ab7fe4bd7bf8f0b62e6ce61b9d0cd" + }, + + { +@@ -228,7 +227,7 @@ static void test_hmac() + }, + 73, + "Test Using Larger Than Block-Size Key and Larger Than One Block-Size Data", +- "0x6f630fad67cda0ee1fb1f562db3aa53e" ++ "6f630fad67cda0ee1fb1f562db3aa53e" + }, + }; + +@@ -246,19 +245,16 @@ static void test_hmac() + exit(1); + } + +- k5_buf_init_fixed(&buf, stroutbuf, sizeof(stroutbuf)); +- k5_buf_add(&buf, "0x"); +- for (j = 0; j < out.length; j++) +- k5_buf_add_fmt(&buf, "%02x", 0xff & outbuf[j]); +- if (k5_buf_status(&buf) != 0) ++ if (k5_hex_encode(out.data, out.length, FALSE, &hexdigest) != 0) + abort(); +- if (strcmp(stroutbuf, md5tests[i].hexdigest)) { ++ if (strcmp(hexdigest, md5tests[i].hexdigest)) { + printf("*** CHECK FAILED!\n" +- "\tReturned: %s.\n" +- "\tExpected: %s.\n", stroutbuf, md5tests[i].hexdigest); ++ "\tReturned: 0x%s.\n" ++ "\tExpected: 0x%s.\n", hexdigest, md5tests[i].hexdigest); + lose++; + } else + printf("Matches expected result.\n"); ++ free(hexdigest); + } + + /* Do again with SHA-1 tests.... */ +diff --git a/src/plugins/kdb/ldap/ldap_util/deps b/src/plugins/kdb/ldap/ldap_util/deps +index 75d4dd0cf..be0194c00 100644 +--- a/src/plugins/kdb/ldap/ldap_util/deps ++++ b/src/plugins/kdb/ldap/ldap_util/deps +@@ -89,15 +89,15 @@ $(OUTPRE)kdb5_ldap_services.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(srcdir)/../libkdb_ldap/ldap_krbcontainer.h $(srcdir)/../libkdb_ldap/ldap_misc.h \ + $(srcdir)/../libkdb_ldap/ldap_realm.h $(top_srcdir)/include/k5-buf.h \ + $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/kdb.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- $(top_srcdir)/lib/kdb/kdb5.h kdb5_ldap_list.h kdb5_ldap_policy.h \ +- kdb5_ldap_realm.h kdb5_ldap_services.c kdb5_ldap_services.h \ +- kdb5_ldap_util.h ++ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ ++ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ ++ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ ++ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/kdb.h \ ++ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ ++ $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ ++ $(top_srcdir)/include/socket-utils.h $(top_srcdir)/lib/kdb/kdb5.h \ ++ kdb5_ldap_list.h kdb5_ldap_policy.h kdb5_ldap_realm.h \ ++ kdb5_ldap_services.c kdb5_ldap_services.h kdb5_ldap_util.h + $(OUTPRE)getdate.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h \ + getdate.c +diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c +index 3d6994c67..ce038fc3d 100644 +--- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c ++++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c +@@ -37,6 +37,7 @@ + */ + + #include ++#include + #include "kdb5_ldap_util.h" + #include "kdb5_ldap_list.h" + +@@ -96,11 +97,10 @@ kdb5_ldap_stash_service_password(int argc, char **argv) + char *service_object = NULL; + char *file_name = NULL, *tmp_file = NULL; + char passwd[MAX_SERVICE_PASSWD_LEN]; +- char *str = NULL; ++ char *str = NULL, *hexpasswd = NULL; + char line[MAX_LEN]; + FILE *pfile = NULL; + krb5_boolean print_usage = FALSE; +- krb5_data hexpasswd = {0, 0, NULL}; + mode_t old_mode = 0; + + /* +@@ -183,21 +183,12 @@ kdb5_ldap_stash_service_password(int argc, char **argv) + } + + /* Convert the password to hexadecimal */ +- { +- krb5_data pwd; +- +- pwd.length = passwd_len; +- pwd.data = passwd; +- +- ret = tohex(pwd, &hexpasswd); +- if (ret != 0) { +- com_err(me, ret, +- _("Failed to convert the password to hexadecimal")); +- memset(passwd, 0, passwd_len); +- goto cleanup; +- } ++ ret = k5_hex_encode(passwd, passwd_len, FALSE, &hexpasswd); ++ zap(passwd, passwd_len); ++ if (ret != 0) { ++ com_err(me, ret, _("Failed to convert the password to hexadecimal")); ++ goto cleanup; + } +- memset(passwd, 0, passwd_len); + + /* TODO: file lock for the service password file */ + +@@ -225,7 +216,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv) + if (str == NULL) { + if (feof(pfile)) { + /* If the service object dn is not present in the service password file */ +- if (fprintf(pfile, "%s#{HEX}%s\n", service_object, hexpasswd.data) < 0) { ++ if (fprintf(pfile, "%s#{HEX}%s\n", service_object, hexpasswd) < 0) { + com_err(me, errno, + _("Failed to write service object password to file")); + fclose(pfile); +@@ -277,7 +268,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv) + while (fgets(line, MAX_LEN, pfile) != NULL) { + if (((str = strstr(line, service_object)) != NULL) && + (line[strlen(service_object)] == '#')) { +- if (fprintf(newfile, "%s#{HEX}%s\n", service_object, hexpasswd.data) < 0) { ++ if (fprintf(newfile, "%s#{HEX}%s\n", service_object, hexpasswd) < 0) { + com_err(me, errno, _("Failed to write service object " + "password to file")); + fclose(newfile); +@@ -322,10 +313,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv) + + cleanup: + +- if (hexpasswd.length != 0) { +- memset(hexpasswd.data, 0, hexpasswd.length); +- free(hexpasswd.data); +- } ++ zapfreestr(hexpasswd); + + if (service_object) + free(service_object); +diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.h b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.h +index cf652c578..08af62e17 100644 +--- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.h ++++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.h +@@ -32,6 +32,4 @@ + #define MAX_LEN 1024 + #define MAX_SERVICE_PASSWD_LEN 256 + +-extern int tohex(krb5_data, krb5_data *); +- + extern void kdb5_ldap_stash_service_password(int argc, char **argv); +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/deps b/src/plugins/kdb/ldap/libkdb_ldap/deps +index 1ff28553f..afca604dc 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/deps ++++ b/src/plugins/kdb/ldap/libkdb_ldap/deps +@@ -220,15 +220,16 @@ ldap_service_stash.so ldap_service_stash.po $(OUTPRE)ldap_service_stash.$(OBJEXT + $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ + $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ + $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/kdb.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h $(top_srcdir)/lib/kdb/kdb5.h \ +- kdb_ldap.h ldap_handle.h ldap_krbcontainer.h ldap_main.h \ +- ldap_misc.h ldap_realm.h ldap_service_stash.c ldap_service_stash.h ++ $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-hex.h \ ++ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ ++ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ ++ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ ++ $(top_srcdir)/include/kdb.h $(top_srcdir)/include/krb5.h \ ++ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ ++ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ ++ $(top_srcdir)/lib/kdb/kdb5.h kdb_ldap.h ldap_handle.h \ ++ ldap_krbcontainer.h ldap_main.h ldap_misc.h ldap_realm.h \ ++ ldap_service_stash.c ldap_service_stash.h + kdb_xdr.so kdb_xdr.po $(OUTPRE)kdb_xdr.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c +index 87a2118ff..cb30f4a7f 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c ++++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c +@@ -31,16 +31,16 @@ + #include "ldap_main.h" + #include "kdb_ldap.h" + #include "ldap_service_stash.h" ++#include + #include + + /* Decode a password of the form {HEX}. */ + static krb5_error_code + dec_password(krb5_context context, const char *str, char **password_out) + { ++ krb5_error_code ret; ++ uint8_t *bytes; + size_t len; +- const unsigned char *p; +- unsigned char *password, *q; +- unsigned int k; + + *password_out = NULL; + +@@ -48,30 +48,15 @@ dec_password(krb5_context context, const char *str, char **password_out) + k5_setmsg(context, EINVAL, _("Not a hexadecimal password")); + return EINVAL; + } +- str += 5; + +- len = strlen(str); +- if (len % 2 != 0) { +- k5_setmsg(context, EINVAL, _("Password corrupt")); +- return EINVAL; ++ ret = k5_hex_decode(str + 5, &bytes, &len); ++ if (ret) { ++ if (ret == EINVAL) ++ k5_setmsg(context, ret, _("Password corrupt")); ++ return ret; + } + +- q = password = malloc(len / 2 + 1); +- if (password == NULL) +- return ENOMEM; +- +- for (p = (unsigned char *)str; *p != '\0'; p += 2) { +- if (!isxdigit(*p) || !isxdigit(p[1])) { +- free(password); +- k5_setmsg(context, EINVAL, _("Password corrupt")); +- return EINVAL; +- } +- sscanf((char *)p, "%2x", &k); +- *q++ = k; +- } +- *q = '\0'; +- +- *password_out = (char *)password; ++ *password_out = (char *)bytes; + return 0; + } + +@@ -128,35 +113,3 @@ krb5_ldap_readpassword(krb5_context context, const char *filename, + /* Extract the plain password information. */ + return dec_password(context, val, password_out); + } +- +-/* Encodes a sequence of bytes in hexadecimal */ +- +-int +-tohex(krb5_data in, krb5_data *ret) +-{ +- unsigned int i=0; +- int err = 0; +- +- ret->length = 0; +- ret->data = NULL; +- +- ret->data = malloc((unsigned int)in.length * 2 + 1 /*Null termination */); +- if (ret->data == NULL) { +- err = ENOMEM; +- goto cleanup; +- } +- ret->length = in.length * 2; +- ret->data[ret->length] = 0; +- +- for (i = 0; i < in.length; i++) +- snprintf(ret->data + 2 * i, 3, "%02x", in.data[i] & 0xff); +- +-cleanup: +- +- if (ret->length == 0) { +- free(ret->data); +- ret->data = NULL; +- } +- +- return err; +-} +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.h b/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.h +index dbf62443a..03cf9a1f7 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.h ++++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.h +@@ -37,7 +37,4 @@ krb5_error_code + krb5_ldap_readpassword(krb5_context context, const char *filename, + const char *name, char **password_out); + +-int +-tohex(krb5_data, krb5_data *); +- + #endif +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/libkdb_ldap.exports b/src/plugins/kdb/ldap/libkdb_ldap/libkdb_ldap.exports +index 2342f1db8..5376d3453 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/libkdb_ldap.exports ++++ b/src/plugins/kdb/ldap/libkdb_ldap/libkdb_ldap.exports +@@ -1,4 +1,3 @@ +-tohex + krb5_ldap_open + krb5_ldap_close + krb5_ldap_db_init +diff --git a/src/slave/deps b/src/slave/deps +index c3677a5e1..c0f558ecd 100644 +--- a/src/slave/deps ++++ b/src/slave/deps +@@ -64,10 +64,11 @@ $(OUTPRE)kproplog.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/iprop.h \ + $(top_srcdir)/include/iprop_hdr.h $(top_srcdir)/include/k5-buf.h \ + $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/kdb.h $(top_srcdir)/include/kdb_log.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h kproplog.c ++ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ ++ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ ++ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ ++ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/kdb.h \ ++ $(top_srcdir)/include/kdb_log.h $(top_srcdir)/include/krb5.h \ ++ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ ++ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ ++ kproplog.c +diff --git a/src/slave/kproplog.c b/src/slave/kproplog.c +index 4f19eeb8c..d4aed7ba6 100644 +--- a/src/slave/kproplog.c ++++ b/src/slave/kproplog.c +@@ -9,6 +9,7 @@ + */ + + #include "k5-int.h" ++#include "k5-hex.h" + #include + #include + #include +@@ -106,15 +107,15 @@ print_deltat(uint32_t *deltat) + static void + print_hex(const char *tag, utf8str_t *str) + { +- unsigned int i; + unsigned int len; ++ char *hex; + + len = str->utf8str_t_len; + +- printf("\t\t\t%s(%d): 0x", tag, len); +- for (i = 0; i < len; i++) +- printf("%02x", (krb5_octet)str->utf8str_t_val[i]); +- printf("\n"); ++ if (k5_hex_encode(str->utf8str_t_val, len, FALSE, &hex) != 0) ++ abort(); ++ printf("\t\t\t%s(%d): 0x%s\n", tag, len, hex); ++ free(hex); + } + + /* Display string primitive. */ +diff --git a/src/tests/gssapi/deps b/src/tests/gssapi/deps +index b784deb63..0b50d9ed3 100644 +--- a/src/tests/gssapi/deps ++++ b/src/tests/gssapi/deps +@@ -149,13 +149,13 @@ $(OUTPRE)t_prf.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(srcdir)/../../lib/gssapi/krb5/gssapiP_krb5.h $(srcdir)/../../lib/gssapi/krb5/gssapi_krb5.h \ + $(srcdir)/../../lib/gssapi/mechglue/mechglue.h $(srcdir)/../../lib/gssapi/mechglue/mglueP.h \ + $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- common.h t_prf.c ++ $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-hex.h \ ++ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ ++ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ ++ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ ++ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ ++ $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ ++ $(top_srcdir)/include/socket-utils.h common.h t_prf.c + $(OUTPRE)t_s4u.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ + $(BUILDTOP)/include/gssapi/gssapi_ext.h $(BUILDTOP)/include/gssapi/gssapi_krb5.h \ + $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h \ +diff --git a/src/tests/gssapi/t_prf.c b/src/tests/gssapi/t_prf.c +index 2c8c85188..6a698ce0f 100644 +--- a/src/tests/gssapi/t_prf.c ++++ b/src/tests/gssapi/t_prf.c +@@ -24,6 +24,7 @@ + */ + + #include "k5-int.h" ++#include "k5-hex.h" + #include "common.h" + #include "mglueP.h" + #include "gssapiP_krb5.h" +@@ -109,12 +110,14 @@ static struct { + static size_t + fromhex(const char *hexstr, unsigned char *out) + { +- const char *p; +- size_t count; ++ uint8_t *bytes; ++ size_t len; + +- for (p = hexstr, count = 0; *p != '\0'; p += 2, count++) +- sscanf(p, "%2hhx", &out[count]); +- return count; ++ if (k5_hex_decode(hexstr, &bytes, &len) != 0) ++ abort(); ++ memcpy(out, bytes, len); ++ free(bytes); ++ return len; + } + + int diff --git a/kdc.conf b/kdc.conf index e99219a..b2e5e9b 100644 --- a/kdc.conf +++ b/kdc.conf @@ -1,12 +1,13 @@ [kdcdefaults] - kdc_ports = 88 - kdc_tcp_ports = 88 + kdc_ports = 88 + kdc_tcp_ports = 88 + spake_preauth_kdc_challenge = edwards25519 [realms] - EXAMPLE.COM = { - #master_key_type = aes256-cts - acl_file = /var/kerberos/krb5kdc/kadm5.acl - dict_file = /usr/share/dict/words - admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab - supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal - } +EXAMPLE.COM = { + #master_key_type = aes256-cts + acl_file = /var/kerberos/krb5kdc/kadm5.acl + dict_file = /usr/share/dict/words + admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab + supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal +} diff --git a/krb5.conf b/krb5.conf index 0ba01ea..99b8859 100644 --- a/krb5.conf +++ b/krb5.conf @@ -14,6 +14,7 @@ includedir /etc/krb5.conf.d/ forwardable = true rdns = false pkinit_anchors = /etc/pki/tls/certs/ca-bundle.crt + spake_preauth_groups = edwards25519 # default_realm = EXAMPLE.COM [realms] diff --git a/krb5.spec b/krb5.spec index d243d85..a98b750 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 14%{?dist} +Release: 15%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -75,6 +75,16 @@ Patch48: Allow-validation-of-PACs-with-enterprise-names.patch Patch49: Fix-read-overflow-in-KDC-sort_pa_data.patch Patch50: Include-preauth-name-in-trace-output-if-possible.patch Patch51: Report-extended-errors-in-kinit-k-t-KDB.patch +Patch52: Add-libkrb5support-hex-functions-and-tests.patch +Patch53: Use-libkrb5support-hex-functions-where-appropriate.patch +Patch54: Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch +Patch55: Add-k5_buf_add_vfmt-to-k5buf-interface.patch +Patch56: Add-vector-support-to-k5_sha256.patch +Patch57: Move-zap-definition-to-k5-platform.h.patch +Patch58: Implement-k5_buf_init_dynamic_zap.patch +Patch59: Use-k5_buf_init_dynamic_zap-where-appropriate.patch +Patch60: Add-SPAKE-preauth-support.patch +Patch61: Add-doc-index-entries-for-SPAKE-constants.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -724,7 +734,12 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog -* Tue Mar 20 2018 Robbie Harwood - 1.16-13 +* Tue Mar 27 2018 Robbie Harwood - 1.16-15 +- Add SPAKE support +- Improve protections on internal sensitive buffers +- Improve internal hex encoding/decoding + +* Tue Mar 20 2018 Robbie Harwood - 1.16-14 - Fix problem with ccache_name logic in previous build * Tue Mar 20 2018 Robbie Harwood - 1.16-13 From 99cea2e511eab05aa402daf9832cb4b4268c39dd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 27 Mar 2018 11:13:24 -0400 Subject: [PATCH 030/304] Fix gitignore problem with previous patchset --- ...encoders-and-decoders-for-SPAKE-types.patch | 2 +- Add-SPAKE-preauth-support.patch | 2 +- ...doc-index-entries-for-SPAKE-constants.patch | 2 +- Add-k5_buf_add_vfmt-to-k5buf-interface.patch | 2 +- ...ibkrb5support-hex-functions-and-tests.patch | 18 +++--------------- Add-vector-support-to-k5_sha256.patch | 2 +- Implement-k5_buf_init_dynamic_zap.patch | 2 +- Move-zap-definition-to-k5-platform.h.patch | 2 +- ...uf_init_dynamic_zap-where-appropriate.patch | 2 +- ...pport-hex-functions-where-appropriate.patch | 2 +- krb5.spec | 5 ++++- 11 files changed, 16 insertions(+), 25 deletions(-) diff --git a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch index 96377e8..b2ef69d 100644 --- a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch +++ b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch @@ -1,4 +1,4 @@ -From 09304f3859f2dd637b7cc27ba1cb3fb3603a3576 Mon Sep 17 00:00:00 2001 +From a675384ef4cc4b6d28cce20cbcef0d033206139a Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 13 Jun 2015 16:04:53 -0400 Subject: [PATCH] Add ASN.1 encoders and decoders for SPAKE types diff --git a/Add-SPAKE-preauth-support.patch b/Add-SPAKE-preauth-support.patch index e23d35c..0afb0dc 100644 --- a/Add-SPAKE-preauth-support.patch +++ b/Add-SPAKE-preauth-support.patch @@ -1,4 +1,4 @@ -From 0284b6503c003af90b9c317620d38b488dadcf86 Mon Sep 17 00:00:00 2001 +From bcc764eca6c92210716d1d6db59bfe112522a95d Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 25 Sep 2015 17:47:35 -0400 Subject: [PATCH] Add SPAKE preauth support diff --git a/Add-doc-index-entries-for-SPAKE-constants.patch b/Add-doc-index-entries-for-SPAKE-constants.patch index 3bf7e4e..e5de247 100644 --- a/Add-doc-index-entries-for-SPAKE-constants.patch +++ b/Add-doc-index-entries-for-SPAKE-constants.patch @@ -1,4 +1,4 @@ -From c4c9ca6edde2157cd42839d227e5f3defd4011a1 Mon Sep 17 00:00:00 2001 +From 6410daacd3b14ca1b96889f3db5ea9c94bf58734 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 27 Mar 2018 00:49:43 -0400 Subject: [PATCH] Add doc index entries for SPAKE constants diff --git a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch index 0510e92..e6dae99 100644 --- a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch +++ b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch @@ -1,4 +1,4 @@ -From 4705fc3c9df924b0c1de015e63f95f98eb563dd3 Mon Sep 17 00:00:00 2001 +From 87e99d886fe8ea74521e73f8f0a8445353162526 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 4 Jan 2018 14:35:12 -0500 Subject: [PATCH] Add k5_buf_add_vfmt to k5buf interface diff --git a/Add-libkrb5support-hex-functions-and-tests.patch b/Add-libkrb5support-hex-functions-and-tests.patch index b09b708..88a1be7 100644 --- a/Add-libkrb5support-hex-functions-and-tests.patch +++ b/Add-libkrb5support-hex-functions-and-tests.patch @@ -1,34 +1,22 @@ -From 9fa4d4095164c09b70061fce5c31ccbd97bc7553 Mon Sep 17 00:00:00 2001 +From 443151a0690d3f11b38db54f650b320cb733535f Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 19 Feb 2018 00:51:44 -0500 Subject: [PATCH] Add libkrb5support hex functions and tests (cherry picked from commit 720dea558da0062d3cea4385327161e62cf09a5e) +[rharwood@redhat.com Remove .gitignore] --- - .gitignore | 1 + src/include/k5-hex.h | 53 ++++++++ src/util/support/Makefile.in | 15 ++- src/util/support/deps | 6 + src/util/support/hex.c | 116 ++++++++++++++++++ src/util/support/libkrb5support-fixed.exports | 2 + src/util/support/t_hex.c | 169 ++++++++++++++++++++++++++ - 7 files changed, 359 insertions(+), 3 deletions(-) + 6 files changed, 358 insertions(+), 3 deletions(-) create mode 100644 src/include/k5-hex.h create mode 100644 src/util/support/hex.c create mode 100644 src/util/support/t_hex.c -diff --git a/.gitignore b/.gitignore -index c13b5e356..91c8b942e 100644 ---- a/.gitignore -+++ b/.gitignore -@@ -517,6 +517,7 @@ local.properties - - /src/util/support/libkrb5support.exports - /src/util/support/t_base64 -+/src/util/support/t_hex - /src/util/support/t_json - /src/util/support/t_k5buf - /src/util/support/t_path diff --git a/src/include/k5-hex.h b/src/include/k5-hex.h new file mode 100644 index 000000000..75bd2cb19 diff --git a/Add-vector-support-to-k5_sha256.patch b/Add-vector-support-to-k5_sha256.patch index 1a04ac4..7d8ff80 100644 --- a/Add-vector-support-to-k5_sha256.patch +++ b/Add-vector-support-to-k5_sha256.patch @@ -1,4 +1,4 @@ -From 73fe8ea67105a4e056c82a0593dad8e6820f05d4 Mon Sep 17 00:00:00 2001 +From 181d3a9e2d274b49a2830895a59ce1b22be4000a Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 3 Feb 2018 20:53:42 -0500 Subject: [PATCH] Add vector support to k5_sha256() diff --git a/Implement-k5_buf_init_dynamic_zap.patch b/Implement-k5_buf_init_dynamic_zap.patch index 4f78d34..2b5656c 100644 --- a/Implement-k5_buf_init_dynamic_zap.patch +++ b/Implement-k5_buf_init_dynamic_zap.patch @@ -1,4 +1,4 @@ -From 7a578d56d42d12973ec17be4cffd983c57aa38c9 Mon Sep 17 00:00:00 2001 +From 4656f809f0f50c3a0a82192f9436e3292a5fe82a Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 26 Mar 2018 11:12:39 -0400 Subject: [PATCH] Implement k5_buf_init_dynamic_zap diff --git a/Move-zap-definition-to-k5-platform.h.patch b/Move-zap-definition-to-k5-platform.h.patch index 83e7e94..dc4e696 100644 --- a/Move-zap-definition-to-k5-platform.h.patch +++ b/Move-zap-definition-to-k5-platform.h.patch @@ -1,4 +1,4 @@ -From 5824de8b471d132ed58eece98c614c56c7b0d48d Mon Sep 17 00:00:00 2001 +From b0fb55f284f543e1e3752512df1f581e77d486ca Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 26 Mar 2018 10:54:29 -0400 Subject: [PATCH] Move zap() definition to k5-platform.h diff --git a/Use-k5_buf_init_dynamic_zap-where-appropriate.patch b/Use-k5_buf_init_dynamic_zap-where-appropriate.patch index a0ecfd4..2dd6ead 100644 --- a/Use-k5_buf_init_dynamic_zap-where-appropriate.patch +++ b/Use-k5_buf_init_dynamic_zap-where-appropriate.patch @@ -1,4 +1,4 @@ -From 9168f0c02a066543a8d03c60e4f05d5f4073f373 Mon Sep 17 00:00:00 2001 +From 678c67ef21578fb269f2efc56ff46bbd0e6b482b Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 26 Mar 2018 11:24:49 -0400 Subject: [PATCH] Use k5_buf_init_dynamic_zap where appropriate diff --git a/Use-libkrb5support-hex-functions-where-appropriate.patch b/Use-libkrb5support-hex-functions-where-appropriate.patch index 7af1f64..e706d8e 100644 --- a/Use-libkrb5support-hex-functions-where-appropriate.patch +++ b/Use-libkrb5support-hex-functions-where-appropriate.patch @@ -1,4 +1,4 @@ -From a77bccb3fd953ae5800768efc0fb4a13753cb785 Mon Sep 17 00:00:00 2001 +From 4a33689d89144f9e473e8192241dcd2473c78bd7 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 19 Feb 2018 00:52:35 -0500 Subject: [PATCH] Use libkrb5support hex functions where appropriate diff --git a/krb5.spec b/krb5.spec index a98b750..9ba2b88 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 15%{?dist} +Release: 16%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -734,6 +734,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Mar 27 2018 Robbie Harwood - 1.16-16 +- Fix gitignore problem with previous patchset + * Tue Mar 27 2018 Robbie Harwood - 1.16-15 - Add SPAKE support - Improve protections on internal sensitive buffers From 27ca1f267898c031020ab0f419c12cb3c307a1f8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 27 Mar 2018 13:55:07 -0400 Subject: [PATCH 031/304] Fix SPAKE memory leak Also fix build problem --- Fix-SPAKE-memory-leak.patch | 41 +++++++++++++++++++++++++++++++++++++ krb5.spec | 7 ++++++- 2 files changed, 47 insertions(+), 1 deletion(-) create mode 100644 Fix-SPAKE-memory-leak.patch diff --git a/Fix-SPAKE-memory-leak.patch b/Fix-SPAKE-memory-leak.patch new file mode 100644 index 0000000..c631a97 --- /dev/null +++ b/Fix-SPAKE-memory-leak.patch @@ -0,0 +1,41 @@ +From 9bfd14df2d6458dfef8d1a17af5247af21183e3d Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 27 Mar 2018 10:36:05 -0400 +Subject: [PATCH] Fix SPAKE memory leak + +In the NIST group implementations, ossl_fini() needs to free the +groupdata container as well as its fields. Also in +spake_kdc.c:parse_data(), initialize the magic field of the resulting +data object to avoid a harmless uninitialized memory copy. + +ticket: 8647 +(cherry picked from commit 70b88b8018658e052d6eabf06f8fdad17fbe993c) +--- + src/plugins/preauth/spake/openssl.c | 1 + + src/plugins/preauth/spake/spake_kdc.c | 1 + + 2 files changed, 2 insertions(+) + +diff --git a/src/plugins/preauth/spake/openssl.c b/src/plugins/preauth/spake/openssl.c +index b821a9158..f2e4b53ec 100644 +--- a/src/plugins/preauth/spake/openssl.c ++++ b/src/plugins/preauth/spake/openssl.c +@@ -69,6 +69,7 @@ ossl_fini(groupdata *gd) + EC_POINT_free(gd->N); + BN_CTX_free(gd->ctx); + BN_free(gd->order); ++ free(gd); + } + + static krb5_error_code +diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c +index c1723ebaf..59e88409e 100644 +--- a/src/plugins/preauth/spake/spake_kdc.c ++++ b/src/plugins/preauth/spake/spake_kdc.c +@@ -75,6 +75,7 @@ parse_data(struct k5input *in, krb5_data *out) + { + out->length = k5_input_get_uint32_be(in); + out->data = (char *)k5_input_get_bytes(in, out->length); ++ out->magic = KV5M_DATA; + } + + /* Parse a received cookie into its components. The pointers stored in the diff --git a/krb5.spec b/krb5.spec index 9ba2b88..0f79518 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 16%{?dist} +Release: 17%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -85,6 +85,7 @@ Patch58: Implement-k5_buf_init_dynamic_zap.patch Patch59: Use-k5_buf_init_dynamic_zap-where-appropriate.patch Patch60: Add-SPAKE-preauth-support.patch Patch61: Add-doc-index-entries-for-SPAKE-constants.patch +Patch62: Fix-SPAKE-memory-leak.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -685,6 +686,7 @@ exit 0 %dir %{_libdir}/krb5/plugins %dir %{_libdir}/krb5/plugins/* %{_libdir}/krb5/plugins/tls/k5tls.so +%{_libdir}/krb5/plugins/preauth/spake.so %dir %{_var}/kerberos %dir %{_var}/kerberos/krb5 %dir %{_var}/kerberos/krb5/user @@ -734,6 +736,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Mar 27 2018 Robbie Harwood - 1.16-17 +- Fix SPAKE memory leak + * Tue Mar 27 2018 Robbie Harwood - 1.16-16 - Fix gitignore problem with previous patchset From 09f9308fd8aba5c2e9bc1144487d3d0e18bee37a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 29 Mar 2018 10:43:22 -0400 Subject: [PATCH 032/304] Continue after KRB5_CC_END in KCM cache iteration --- ...r-KRB5_CC_END-in-KCM-cache-iteration.patch | 42 +++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 47 insertions(+), 1 deletion(-) create mode 100644 Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch diff --git a/Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch b/Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch new file mode 100644 index 0000000..999a5ba --- /dev/null +++ b/Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch @@ -0,0 +1,42 @@ +From 3001200ba4598aeb14511353a72dc746034280b1 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Fabiano=20Fid=C3=AAncio?= +Date: Wed, 28 Mar 2018 18:27:06 +0200 +Subject: [PATCH] Continue after KRB5_CC_END in KCM cache iteration + +The KCM server returns KRB5_CC_END in response to a GET_CACHE_BY_UUID +request to indicate that the specified ccache uuid no longer exists. +In krb5_ptcursor_next(), ignore this error and continue the iteration, +as the Heimdal KCM client code does. + +In addition to addressing the case where a third party deletes a cache +between the GET_CACHE_UUID_LIST request and when we reach that uuid in +the iteration, this change also fixes a bug in kdestroy -A where the +caller deletes the primary cache and we later request it by uuid when +iterating over the list. + +[ghudson@mit.edu: rewrote commit message; edited comment] + +ticket: 8658 (new) +tags: pullup +target_version: 1.16-next +target_version: 1.15-next + +(cherry picked from commit 49087f5e6309f298f8898c35af6f4ade418ced60) +--- + src/lib/krb5/ccache/cc_kcm.c | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c +index b621ed33b..0d38b1839 100644 +--- a/src/lib/krb5/ccache/cc_kcm.c ++++ b/src/lib/krb5/ccache/cc_kcm.c +@@ -966,6 +966,9 @@ kcm_ptcursor_next(krb5_context context, krb5_cc_ptcursor cursor, + kcmreq_init(&req, KCM_OP_GET_CACHE_BY_UUID, NULL); + k5_buf_add_len(&req.reqbuf, id, KCM_UUID_LEN); + ret = kcmio_call(context, data->io, &req); ++ /* Continue if the cache has been deleted. */ ++ if (ret == KRB5_CC_END) ++ continue; + if (ret) + goto cleanup; + ret = kcmreq_get_name(&req, &name); diff --git a/krb5.spec b/krb5.spec index 0f79518..bd92e64 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 17%{?dist} +Release: 18%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -86,6 +86,7 @@ Patch59: Use-k5_buf_init_dynamic_zap-where-appropriate.patch Patch60: Add-SPAKE-preauth-support.patch Patch61: Add-doc-index-entries-for-SPAKE-constants.patch Patch62: Fix-SPAKE-memory-leak.patch +Patch63: Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -736,6 +737,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Mar 29 2018 Robbie Harwood - 1.16-18 +- Continue after KRB5_CC_END in KCM cache iteration + * Tue Mar 27 2018 Robbie Harwood - 1.16-17 - Fix SPAKE memory leak From 6208c030172b1d329044ab49c4205aee04140b9c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 29 Mar 2018 10:50:19 -0400 Subject: [PATCH 033/304] Continue after KRB5_CC_END in KCM cache iteration --- ...r-KRB5_CC_END-in-KCM-cache-iteration.patch | 43 +++ Fix-flaws-in-LDAP-DN-checking.patch | 346 ------------------ ...ed-directories-in-alphabetical-order.patch | 78 ---- krb5.spec | 8 +- 4 files changed, 48 insertions(+), 427 deletions(-) create mode 100644 Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch delete mode 100644 Fix-flaws-in-LDAP-DN-checking.patch delete mode 100644 Process-included-directories-in-alphabetical-order.patch diff --git a/Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch b/Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch new file mode 100644 index 0000000..01073e1 --- /dev/null +++ b/Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch @@ -0,0 +1,43 @@ +From bc42112fbc232c2afba602672affc3e92ae1491e Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Fabiano=20Fid=C3=AAncio?= +Date: Wed, 28 Mar 2018 18:27:06 +0200 +Subject: [PATCH] Continue after KRB5_CC_END in KCM cache iteration + +The KCM server returns KRB5_CC_END in response to a GET_CACHE_BY_UUID +request to indicate that the specified ccache uuid no longer exists. +In krb5_ptcursor_next(), ignore this error and continue the iteration, +as the Heimdal KCM client code does. + +In addition to addressing the case where a third party deletes a cache +between the GET_CACHE_UUID_LIST request and when we reach that uuid in +the iteration, this change also fixes a bug in kdestroy -A where the +caller deletes the primary cache and we later request it by uuid when +iterating over the list. + +[ghudson@mit.edu: rewrote commit message; edited comment] + +ticket: 8658 (new) +tags: pullup +target_version: 1.16-next +target_version: 1.15-next + +(cherry picked from commit 49087f5e6309f298f8898c35af6f4ade418ced60) +(cherry picked from commit 3001200ba4598aeb14511353a72dc746034280b1) +--- + src/lib/krb5/ccache/cc_kcm.c | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c +index a889e67b4..a3afd7056 100644 +--- a/src/lib/krb5/ccache/cc_kcm.c ++++ b/src/lib/krb5/ccache/cc_kcm.c +@@ -966,6 +966,9 @@ kcm_ptcursor_next(krb5_context context, krb5_cc_ptcursor cursor, + kcmreq_init(&req, KCM_OP_GET_CACHE_BY_UUID, NULL); + k5_buf_add_len(&req.reqbuf, id, KCM_UUID_LEN); + ret = kcmio_call(context, data->io, &req); ++ /* Continue if the cache has been deleted. */ ++ if (ret == KRB5_CC_END) ++ continue; + if (ret) + goto cleanup; + ret = kcmreq_get_name(&req, &name); diff --git a/Fix-flaws-in-LDAP-DN-checking.patch b/Fix-flaws-in-LDAP-DN-checking.patch deleted file mode 100644 index 4a775bb..0000000 --- a/Fix-flaws-in-LDAP-DN-checking.patch +++ /dev/null @@ -1,346 +0,0 @@ -From 27581397cd0d2f213c91bdf20ea9a6736f3e60dc Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 12 Jan 2018 11:43:01 -0500 -Subject: [PATCH] Fix flaws in LDAP DN checking - -KDB_TL_USER_INFO tl-data is intended to be internal to the LDAP KDB -module, and not used in disk or wire principal entries. Prevent -kadmin clients from sending KDB_TL_USER_INFO tl-data by giving it a -type number less than 256 and filtering out type numbers less than 256 -in kadm5_create_principal_3(). (We already filter out low type -numbers in kadm5_modify_principal()). - -In the LDAP KDB module, if containerdn and linkdn are both specified -in a put_principal operation, check both linkdn and the computed -standalone_principal_dn for container membership. To that end, factor -out the checks into helper functions and call them on all applicable -client-influenced DNs. - -CVE-2018-5729: - -In MIT krb5 1.6 or later, an authenticated kadmin user with permission -to add principals to an LDAP Kerberos database can cause a null -dereference in kadmind, or circumvent a DN container check, by -supplying tagged data intended to be internal to the database module. -Thanks to Sharwan Ram and Pooja Anil for discovering the potential -null dereference. - -CVE-2018-5730: - -In MIT krb5 1.6 or later, an authenticated kadmin user with permission -to add principals to an LDAP Kerberos database can circumvent a DN -containership check by supplying both a "linkdn" and "containerdn" -database argument, or by supplying a DN string which is a left -extension of a container DN string but is not hierarchically within -the container DN. - -ticket: 8643 (new) -tags: pullup -target_version: 1.16-next -target_version: 1.15-next - -(cherry picked from commit e1caf6fb74981da62039846931ebdffed71309d1) ---- - src/lib/kadm5/srv/svr_principal.c | 7 + - src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h | 2 +- - src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c | 200 +++++++++++---------- - src/tests/t_kdb.py | 11 ++ - 4 files changed, 125 insertions(+), 95 deletions(-) - -diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c -index 2420f2c2b..a59a65e8f 100644 ---- a/src/lib/kadm5/srv/svr_principal.c -+++ b/src/lib/kadm5/srv/svr_principal.c -@@ -330,6 +330,13 @@ kadm5_create_principal_3(void *server_handle, - return KADM5_BAD_MASK; - if((mask & ~ALL_PRINC_MASK)) - return KADM5_BAD_MASK; -+ if (mask & KADM5_TL_DATA) { -+ for (tl_data_tail = entry->tl_data; tl_data_tail != NULL; -+ tl_data_tail = tl_data_tail->tl_data_next) { -+ if (tl_data_tail->tl_data_type < 256) -+ return KADM5_BAD_TL_TYPE; -+ } -+ } - - /* - * Check to see if the principal exists -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h b/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h -index 535a1f309..8b8420faa 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h -+++ b/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h -@@ -141,7 +141,7 @@ extern int set_ldap_error (krb5_context ctx, int st, int op); - #define UNSTORE16_INT(ptr, val) (val = load_16_be(ptr)) - #define UNSTORE32_INT(ptr, val) (val = load_32_be(ptr)) - --#define KDB_TL_USER_INFO 0x7ffe -+#define KDB_TL_USER_INFO 0xff - - #define KDB_TL_PRINCTYPE 0x01 - #define KDB_TL_PRINCCOUNT 0x02 -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -index 88a170495..b7c9212cb 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -@@ -651,6 +651,107 @@ cleanup: - return ret; - } - -+static krb5_error_code -+check_dn_in_container(krb5_context context, const char *dn, -+ char *const *subtrees, unsigned int ntrees) -+{ -+ unsigned int i; -+ size_t dnlen = strlen(dn), stlen; -+ -+ for (i = 0; i < ntrees; i++) { -+ if (subtrees[i] == NULL || *subtrees[i] == '\0') -+ return 0; -+ stlen = strlen(subtrees[i]); -+ if (dnlen >= stlen && -+ strcasecmp(dn + dnlen - stlen, subtrees[i]) == 0 && -+ (dnlen == stlen || dn[dnlen - stlen - 1] == ',')) -+ return 0; -+ } -+ -+ k5_setmsg(context, EINVAL, _("DN is out of the realm subtree")); -+ return EINVAL; -+} -+ -+static krb5_error_code -+check_dn_exists(krb5_context context, -+ krb5_ldap_server_handle *ldap_server_handle, -+ const char *dn, krb5_boolean nonkrb_only) -+{ -+ krb5_error_code st = 0, tempst; -+ krb5_ldap_context *ldap_context = context->dal_handle->db_context; -+ LDAP *ld = ldap_server_handle->ldap_handle; -+ LDAPMessage *result = NULL, *ent; -+ char *attrs[] = { "krbticketpolicyreference", "krbprincipalname", NULL }; -+ char **values; -+ -+ LDAP_SEARCH_1(dn, LDAP_SCOPE_BASE, 0, attrs, IGNORE_STATUS); -+ if (st != LDAP_SUCCESS) -+ return set_ldap_error(context, st, OP_SEARCH); -+ -+ ent = ldap_first_entry(ld, result); -+ CHECK_NULL(ent); -+ -+ values = ldap_get_values(ld, ent, "krbticketpolicyreference"); -+ if (values != NULL) -+ ldap_value_free(values); -+ -+ values = ldap_get_values(ld, ent, "krbprincipalname"); -+ if (values != NULL) { -+ ldap_value_free(values); -+ if (nonkrb_only) { -+ st = EINVAL; -+ k5_setmsg(context, st, _("ldap object is already kerberized")); -+ goto cleanup; -+ } -+ } -+ -+cleanup: -+ ldap_msgfree(result); -+ return st; -+} -+ -+static krb5_error_code -+validate_xargs(krb5_context context, -+ krb5_ldap_server_handle *ldap_server_handle, -+ const xargs_t *xargs, const char *standalone_dn, -+ char *const *subtrees, unsigned int ntrees) -+{ -+ krb5_error_code st; -+ -+ if (xargs->dn != NULL) { -+ /* The supplied dn must be within a realm container. */ -+ st = check_dn_in_container(context, xargs->dn, subtrees, ntrees); -+ if (st) -+ return st; -+ /* The supplied dn must exist without Kerberos attributes. */ -+ st = check_dn_exists(context, ldap_server_handle, xargs->dn, TRUE); -+ if (st) -+ return st; -+ } -+ -+ if (xargs->linkdn != NULL) { -+ /* The supplied linkdn must be within a realm container. */ -+ st = check_dn_in_container(context, xargs->linkdn, subtrees, ntrees); -+ if (st) -+ return st; -+ /* The supplied linkdn must exist. */ -+ st = check_dn_exists(context, ldap_server_handle, xargs->linkdn, -+ FALSE); -+ if (st) -+ return st; -+ } -+ -+ if (xargs->containerdn != NULL && standalone_dn != NULL) { -+ /* standalone_dn (likely composed using containerdn) must be within a -+ * container. */ -+ st = check_dn_in_container(context, standalone_dn, subtrees, ntrees); -+ if (st) -+ return st; -+ } -+ -+ return 0; -+} -+ - krb5_error_code - krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, - char **db_args) -@@ -662,12 +763,12 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, - LDAPMessage *result=NULL, *ent=NULL; - char **subtreelist = NULL; - char *user=NULL, *subtree=NULL, *principal_dn=NULL; -- char **values=NULL, *strval[10]={NULL}, errbuf[1024]; -+ char *strval[10]={NULL}, errbuf[1024]; - char *filtuser=NULL; - struct berval **bersecretkey=NULL; - LDAPMod **mods=NULL; - krb5_boolean create_standalone=FALSE; -- krb5_boolean krb_identity_exists=FALSE, establish_links=FALSE; -+ krb5_boolean establish_links=FALSE; - char *standalone_principal_dn=NULL; - krb5_tl_data *tl_data=NULL; - krb5_key_data **keys=NULL; -@@ -860,24 +961,6 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, - * any of the subtrees - */ - if (xargs.dn_from_kbd == TRUE) { -- /* make sure the DN falls in the subtree */ -- int dnlen=0, subtreelen=0; -- char *dn=NULL; -- krb5_boolean outofsubtree=TRUE; -- -- if (xargs.dn != NULL) { -- dn = xargs.dn; -- } else if (xargs.linkdn != NULL) { -- dn = xargs.linkdn; -- } else if (standalone_principal_dn != NULL) { -- /* -- * Even though the standalone_principal_dn is constructed -- * within this function, there is the containerdn input -- * from the user that can become part of the it. -- */ -- dn = standalone_principal_dn; -- } -- - /* Get the current subtree list if we haven't already done so. */ - if (subtreelist == NULL) { - st = krb5_get_subtree_info(ldap_context, &subtreelist, &ntrees); -@@ -885,81 +968,10 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, - goto cleanup; - } - -- for (tre=0; tre= subtreelen) && (strcasecmp((dn + dnlen - subtreelen), subtreelist[tre]) == 0)) { -- outofsubtree = FALSE; -- break; -- } -- } -- } -- -- if (outofsubtree == TRUE) { -- st = EINVAL; -- k5_setmsg(context, st, _("DN is out of the realm subtree")); -+ st = validate_xargs(context, ldap_server_handle, &xargs, -+ standalone_principal_dn, subtreelist, ntrees); -+ if (st) - goto cleanup; -- } -- -- /* -- * dn value will be set either by dn, linkdn or the standalone_principal_dn -- * In the first 2 cases, the dn should be existing and in the last case we -- * are supposed to create the ldap object. so the below should not be -- * executed for the last case. -- */ -- -- if (standalone_principal_dn == NULL) { -- /* -- * If the ldap object is missing, this results in an error. -- */ -- -- /* -- * Search for krbprincipalname attribute here. -- * This is to find if a kerberos identity is already present -- * on the ldap object, in which case adding a kerberos identity -- * on the ldap object should result in an error. -- */ -- char *attributes[]={"krbticketpolicyreference", "krbprincipalname", NULL}; -- -- ldap_msgfree(result); -- result = NULL; -- LDAP_SEARCH_1(dn, LDAP_SCOPE_BASE, 0, attributes, IGNORE_STATUS); -- if (st == LDAP_SUCCESS) { -- ent = ldap_first_entry(ld, result); -- if (ent != NULL) { -- if ((values=ldap_get_values(ld, ent, "krbticketpolicyreference")) != NULL) { -- ldap_value_free(values); -- } -- -- if ((values=ldap_get_values(ld, ent, "krbprincipalname")) != NULL) { -- krb_identity_exists = TRUE; -- ldap_value_free(values); -- } -- } -- } else { -- st = set_ldap_error(context, st, OP_SEARCH); -- goto cleanup; -- } -- } -- } -- -- /* -- * If xargs.dn is set then the request is to add a -- * kerberos principal on a ldap object, but if -- * there is one already on the ldap object this -- * should result in an error. -- */ -- -- if (xargs.dn != NULL && krb_identity_exists == TRUE) { -- st = EINVAL; -- snprintf(errbuf, sizeof(errbuf), -- _("ldap object is already kerberized")); -- k5_setmsg(context, st, "%s", errbuf); -- goto cleanup; - } - - if (xargs.linkdn != NULL) { -diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py -index 217f2cdc3..6e563b103 100755 ---- a/src/tests/t_kdb.py -+++ b/src/tests/t_kdb.py -@@ -203,6 +203,12 @@ if out != 'KRBTEST.COM\n': - # in the test LDAP server. - realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=krb5', 'princ1'], - expected_code=1, expected_msg='DN is out of the realm subtree') -+# Check that the DN container check is a hierarchy test, not a simple -+# suffix match (CVE-2018-5730). We expect this operation to fail -+# either way (because "xcn" isn't a valid DN tag) but the container -+# check should happen before the DN is parsed. -+realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=xcn=t1,cn=krb5', 'princ1'], -+ expected_code=1, expected_msg='DN is out of the realm subtree') - realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=t2,cn=krb5', 'princ1']) - realm.run([kadminl, 'getprinc', 'princ1'], expected_msg='Principal: princ1') - realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=t2,cn=krb5', 'again'], -@@ -226,6 +232,11 @@ realm.run([kadminl, 'ank', '-randkey', '-x', 'containerdn=cn=t1,cn=krb5', - 'princ3']) - realm.run([kadminl, 'modprinc', '-x', 'containerdn=cn=t2,cn=krb5', 'princ3'], - expected_code=1, expected_msg='containerdn option not supported') -+# Verify that containerdn is checked when linkdn is also supplied -+# (CVE-2018-5730). -+realm.run([kadminl, 'ank', '-randkey', '-x', 'containerdn=cn=krb5', -+ '-x', 'linkdn=cn=t2,cn=krb5', 'princ4'], expected_code=1, -+ expected_msg='DN is out of the realm subtree') - - # Create and modify a ticket policy. - kldaputil(['create_policy', '-maxtktlife', '3hour', '-maxrenewlife', '6hour', diff --git a/Process-included-directories-in-alphabetical-order.patch b/Process-included-directories-in-alphabetical-order.patch deleted file mode 100644 index aeeae75..0000000 --- a/Process-included-directories-in-alphabetical-order.patch +++ /dev/null @@ -1,78 +0,0 @@ -From c7c44bbd80beabe7fb21f5fb6cfb9b57faa320f4 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 29 Jan 2018 12:10:53 +0100 -Subject: [PATCH] Process included directories in alphabetical order - -readdir() and FindFirstFile()/FindNextFile() do not define any -ordering on the entries they return. Use sorted scandir() instead on -Unix-likes. - -(cherry picked from commit 4e8518baeedf376ae3e4ce302c9a138263d648df) ---- - src/util/profile/prof_parse.c | 30 ++++++++++++++++++++---------- - 1 file changed, 20 insertions(+), 10 deletions(-) - -diff --git a/src/util/profile/prof_parse.c b/src/util/profile/prof_parse.c -index 1baceea9e..309c27d07 100644 ---- a/src/util/profile/prof_parse.c -+++ b/src/util/profile/prof_parse.c -@@ -241,12 +241,18 @@ static int valid_name(const char *filename) - } - return 1; - } -+#ifndef _WIN32 -+static int valid_name_scandir(const struct dirent *d) -+{ -+ return valid_name(d->d_name); -+} -+#endif - - /* - * Include files within dirname. Only files with names ending in ".conf", or - * consisting entirely of alphanumeric characters, dashes, and underscores are - * included. This restriction avoids including editor backup files, .rpmsave -- * files, and the like. -+ * files, and the like. Files are processed in alphanumeric order. - */ - static errcode_t parse_include_dir(const char *dirname, - struct profile_node *root_section) -@@ -287,18 +293,19 @@ cleanup: - - #else /* not _WIN32 */ - -- DIR *dir; - char *pathname; - errcode_t retval = 0; -- struct dirent *ent; -+ struct dirent **namelist; -+ int num_ents, i; - -- dir = opendir(dirname); -- if (dir == NULL) -+ num_ents = scandir(dirname, &namelist, &valid_name_scandir, &alphasort); -+ if (num_ents == -1) - return PROF_FAIL_INCLUDE_DIR; -- while ((ent = readdir(dir)) != NULL) { -- if (!valid_name(ent->d_name)) -- continue; -- if (asprintf(&pathname, "%s/%s", dirname, ent->d_name) < 0) { -+ -+ for (i = 0; i < num_ents; i++) { -+ retval = asprintf(&pathname, "%s/%s", dirname, namelist[i]->d_name); -+ free(namelist[i]); -+ if (retval < 0) { - retval = ENOMEM; - break; - } -@@ -307,7 +314,10 @@ cleanup: - if (retval) - break; - } -- closedir(dir); -+ for (i++; i < num_ents; i++) -+ free(namelist[i]); -+ -+ free(namelist); - return retval; - #endif /* not _WIN32 */ - } diff --git a/krb5.spec b/krb5.spec index 749a64d..925be0b 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.15.2 # for prerelease, should be e.g., 0.3.beta2% { ?dist } (without spaces) -Release: 7%{?dist} +Release: 8%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.15/krb5-%{version}%{prerelease}.tar.gz @@ -93,8 +93,7 @@ Patch69: Add-PKINIT-test-case-for-generic-client-cert.patch Patch70: Add-hostname-based-ccselect-module.patch Patch71: Add-German-translation.patch Patch72: Fix-PKINIT-cert-matching-data-construction.patch -Patch73: Process-included-directories-in-alphabetical-order.patch -Patch74: Fix-flaws-in-LDAP-DN-checking.patch +Patch73: Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -747,6 +746,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Mar 29 2018 Robbie Harwood - 1.15.2-8 +- Continue after KRB5_CC_END in KCM cache iteration + * Tue Feb 13 2018 Robbie Harwood - 1.15.2-7 - Fix flaws in LDAP DN checking - CVE-2018-5729, CVE-2018-5730 From 091dcbf7942abf94b8423482bd268e3661f8880d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 2 Apr 2018 12:37:37 -0400 Subject: [PATCH 034/304] Zap data when freeing krb5_spake_factor --- Zap-data-when-freeing-krb5_spake_factor.patch | 29 +++++++++++++++++++ krb5.spec | 6 +++- 2 files changed, 34 insertions(+), 1 deletion(-) create mode 100644 Zap-data-when-freeing-krb5_spake_factor.patch diff --git a/Zap-data-when-freeing-krb5_spake_factor.patch b/Zap-data-when-freeing-krb5_spake_factor.patch new file mode 100644 index 0000000..18192c9 --- /dev/null +++ b/Zap-data-when-freeing-krb5_spake_factor.patch @@ -0,0 +1,29 @@ +From 19ed715d39bdf8415f69156d6cef19225cf6355a Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 27 Mar 2018 15:42:28 -0400 +Subject: [PATCH] Zap data when freeing krb5_spake_factor + +krb5_spake_factor structures will sometimes hold sensitive data when +second-factor SPAKE is implemented, so should be zapped when freed. + +ticket: 8647 +(cherry picked from commit 9cc94a3f1ce06a4430f684300a747ec079102403) +--- + src/lib/krb5/krb/kfree.c | 4 +++- + 1 file changed, 3 insertions(+), 1 deletion(-) + +diff --git a/src/lib/krb5/krb/kfree.c b/src/lib/krb5/krb/kfree.c +index e1ea1494a..71e7fcad0 100644 +--- a/src/lib/krb5/krb/kfree.c ++++ b/src/lib/krb5/krb/kfree.c +@@ -897,7 +897,9 @@ k5_free_spake_factor(krb5_context context, krb5_spake_factor *val) + { + if (val == NULL) + return; +- krb5_free_data(context, val->data); ++ if (val->data != NULL) ++ zapfree(val->data->data, val->data->length); ++ free(val->data); + free(val); + } + diff --git a/krb5.spec b/krb5.spec index bd92e64..f0df09b 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 18%{?dist} +Release: 19%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -87,6 +87,7 @@ Patch60: Add-SPAKE-preauth-support.patch Patch61: Add-doc-index-entries-for-SPAKE-constants.patch Patch62: Fix-SPAKE-memory-leak.patch Patch63: Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch +Patch64: Zap-data-when-freeing-krb5_spake_factor.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -737,6 +738,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Apr 02 2018 Robbie Harwood - 1.16-19 +- Zap data when freeing krb5_spake_factor + * Thu Mar 29 2018 Robbie Harwood - 1.16-18 - Continue after KRB5_CC_END in KCM cache iteration From 9f52d3d29f20f64744d7f10ffc025898b8e2ce1e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 3 Apr 2018 15:05:13 -0400 Subject: [PATCH 035/304] Be more careful asking for AS key in SPAKE client --- ...ul-asking-for-AS-key-in-SPAKE-client.patch | 229 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 234 insertions(+), 1 deletion(-) create mode 100644 Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch diff --git a/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch b/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch new file mode 100644 index 0000000..ac80178 --- /dev/null +++ b/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch @@ -0,0 +1,229 @@ +From 864f90dcc860997189679b980f52de41ef10a238 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sat, 31 Mar 2018 10:43:49 -0400 +Subject: [PATCH] Be more careful asking for AS key in SPAKE client + +Asking for the AS key too early can result in password prompts in +situations where SPAKE won't proceed, such as when the KDC offers only +second factor types not supported by the client. + +In spake_prep_questions(), decode the received message and make sure +it's a challenge with a supported group and second factor type +(SF-NONE at the moment). Save the decoded message and use it in +spake_process(). Do not retrieve the AS key at the beginning of +spake_process(); instead do so in process_challenge() after checking +the challenge group and factor types. + +Move contains_sf_none() earlier in the file so that it can be used by +spake_prep_questions() without a prototype. + +ticket: 8659 +(cherry picked from commit f240f1b0d324312be8aa59ead7cfbe0c329ed064) +--- + src/plugins/preauth/spake/spake_client.c | 111 ++++++++++++++++++------------- + 1 file changed, 66 insertions(+), 45 deletions(-) + +diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c +index d72bd64aa..47a6ba26c 100644 +--- a/src/plugins/preauth/spake/spake_client.c ++++ b/src/plugins/preauth/spake/spake_client.c +@@ -39,12 +39,26 @@ + #include + + typedef struct reqstate_st { ++ krb5_pa_spake *msg; /* set in prep_questions, used in process */ + krb5_keyblock *initial_key; + krb5_data *support; + krb5_data thash; + krb5_data spakeresult; + } reqstate; + ++/* Return true if SF-NONE is present in factors. */ ++static krb5_boolean ++contains_sf_none(krb5_spake_factor **factors) ++{ ++ int i; ++ ++ for (i = 0; factors != NULL && factors[i] != NULL; i++) { ++ if (factors[i]->type == SPAKE_SF_NONE) ++ return TRUE; ++ } ++ return FALSE; ++} ++ + static krb5_error_code + spake_init(krb5_context context, krb5_clpreauth_moddata *moddata_out) + { +@@ -77,6 +91,7 @@ spake_request_fini(krb5_context context, krb5_clpreauth_moddata moddata, + { + reqstate *st = (reqstate *)modreq; + ++ k5_free_pa_spake(context, st->msg); + krb5_free_keyblock(context, st->initial_key); + krb5_free_data(context, st->support); + krb5_free_data_contents(context, &st->thash); +@@ -92,16 +107,42 @@ spake_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata, + krb5_data *enc_req, krb5_data *enc_prev_req, + krb5_pa_data *pa_data) + { ++ krb5_error_code ret; ++ groupstate *gstate = (groupstate *)moddata; + reqstate *st = (reqstate *)modreq; ++ krb5_data in_data; ++ krb5_spake_challenge *ch; + + if (st == NULL) + return ENOMEM; +- if (st->initial_key == NULL && pa_data->length > 0) ++ ++ /* We don't need to ask any questions to send a support message. */ ++ if (pa_data->length == 0) ++ return 0; ++ ++ /* Decode the incoming message, replacing any previous one in the request ++ * state. If we can't decode it, we have no questions to ask. */ ++ k5_free_pa_spake(context, st->msg); ++ st->msg = NULL; ++ in_data = make_data(pa_data->contents, pa_data->length); ++ ret = decode_krb5_pa_spake(&in_data, &st->msg); ++ if (ret) ++ return (ret == ENOMEM) ? ENOMEM : 0; ++ ++ if (st->msg->choice == SPAKE_MSGTYPE_CHALLENGE) { ++ ch = &st->msg->u.challenge; ++ if (!group_is_permitted(gstate, ch->group)) ++ return 0; ++ /* When second factor support is implemented, we should ask questions ++ * based on the factors in the challenge. */ ++ if (!contains_sf_none(ch->factors)) ++ return 0; ++ /* We will need the AS key to respond to the challenge. */ + cb->need_as_key(context, rock); +- +- /* When second-factor is implemented, we should ask questions based on the +- * factors in the challenge. */ +- ++ } else if (st->msg->choice == SPAKE_MSGTYPE_ENCDATA) { ++ /* When second factor support is implemented, we should decrypt the ++ * encdata message and ask questions based on the factor data. */ ++ } + return 0; + } + +@@ -136,19 +177,6 @@ send_support(krb5_context context, groupstate *gstate, reqstate *st, + return convert_to_padata(support, pa_out); + } + +-/* Return true if SF-NONE is present in factors. */ +-static krb5_boolean +-contains_sf_none(krb5_spake_factor **factors) +-{ +- int i; +- +- for (i = 0; factors != NULL && factors[i] != NULL; i++) { +- if (factors[i]->type == SPAKE_SF_NONE) +- return TRUE; +- } +- return FALSE; +-} +- + static krb5_error_code + process_challenge(krb5_context context, groupstate *gstate, reqstate *st, + krb5_spake_challenge *ch, const krb5_data *der_msg, +@@ -157,7 +185,7 @@ process_challenge(krb5_context context, groupstate *gstate, reqstate *st, + const krb5_data *der_req, krb5_pa_data ***pa_out) + { + krb5_error_code ret; +- krb5_keyblock *k0 = NULL, *k1 = NULL; ++ krb5_keyblock *k0 = NULL, *k1 = NULL, *as_key; + krb5_spake_factor factor; + krb5_pa_spake msg; + krb5_data *der_factor = NULL, *response; +@@ -167,8 +195,8 @@ process_challenge(krb5_context context, groupstate *gstate, reqstate *st, + + enc_factor.ciphertext = empty_data(); + +- /* Not expected if we already computed the SPAKE result. */ +- if (st->spakeresult.length != 0) ++ /* Not expected if we processed a challenge and didn't reject it. */ ++ if (st->initial_key != NULL) + return KRB5KDC_ERR_PREAUTH_FAILED; + + if (!group_is_permitted(gstate, ch->group)) { +@@ -193,6 +221,12 @@ process_challenge(krb5_context context, groupstate *gstate, reqstate *st, + if (!contains_sf_none(ch->factors)) + return KRB5KDC_ERR_PREAUTH_FAILED; + ++ ret = cb->get_as_key(context, rock, &as_key); ++ if (ret) ++ goto cleanup; ++ ret = krb5_copy_keyblock(context, as_key, &st->initial_key); ++ if (ret) ++ goto cleanup; + ret = derive_wbytes(context, ch->group, st->initial_key, &wbytes); + if (ret) + goto cleanup; +@@ -267,7 +301,7 @@ process_encdata(krb5_context context, reqstate *st, krb5_enc_data *enc, + krb5_pa_data ***pa_out) + { + /* Not expected if we haven't sent a response yet. */ +- if (st->spakeresult.length == 0) ++ if (st->initial_key == NULL || st->spakeresult.length == 0) + return KRB5KDC_ERR_PREAUTH_FAILED; + + /* +@@ -292,9 +326,7 @@ spake_process(krb5_context context, krb5_clpreauth_moddata moddata, + krb5_error_code ret; + groupstate *gstate = (groupstate *)moddata; + reqstate *st = (reqstate *)modreq; +- krb5_pa_spake *msg; + krb5_data in_data; +- krb5_keyblock *as_key; + + if (st == NULL) + return ENOMEM; +@@ -306,34 +338,23 @@ spake_process(krb5_context context, krb5_clpreauth_moddata moddata, + return send_support(context, gstate, st, pa_out); + } + +- /* We need the initial reply key to process any non-trivial message. */ +- if (st->initial_key == NULL) { +- ret = cb->get_as_key(context, rock, &as_key); +- if (ret) +- return ret; +- ret = krb5_copy_keyblock(context, as_key, &st->initial_key); +- if (ret) +- return ret; +- } +- +- in_data = make_data(pa_in->contents, pa_in->length); +- ret = decode_krb5_pa_spake(&in_data, &msg); +- if (ret) +- return ret; +- +- if (msg->choice == SPAKE_MSGTYPE_CHALLENGE) { +- ret = process_challenge(context, gstate, st, &msg->u.challenge, ++ if (st->msg == NULL) { ++ /* The message failed to decode in spake_prep_questions(). */ ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ } else if (st->msg->choice == SPAKE_MSGTYPE_CHALLENGE) { ++ in_data = make_data(pa_in->contents, pa_in->length); ++ ret = process_challenge(context, gstate, st, &st->msg->u.challenge, + &in_data, cb, rock, prompter, prompter_data, + der_req, pa_out); +- } else if (msg->choice == SPAKE_MSGTYPE_ENCDATA) { +- ret = process_encdata(context, st, &msg->u.encdata, cb, rock, prompter, +- prompter_data, der_prev_req, der_req, pa_out); ++ } else if (st->msg->choice == SPAKE_MSGTYPE_ENCDATA) { ++ ret = process_encdata(context, st, &st->msg->u.encdata, cb, rock, ++ prompter, prompter_data, der_prev_req, der_req, ++ pa_out); + } else { + /* Unexpected message type */ + ret = KRB5KDC_ERR_PREAUTH_FAILED; + } + +- k5_free_pa_spake(context, msg); + return ret; + } + diff --git a/krb5.spec b/krb5.spec index f0df09b..8b22173 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 19%{?dist} +Release: 20%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -88,6 +88,7 @@ Patch61: Add-doc-index-entries-for-SPAKE-constants.patch Patch62: Fix-SPAKE-memory-leak.patch Patch63: Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch Patch64: Zap-data-when-freeing-krb5_spake_factor.patch +Patch65: Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -738,6 +739,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Apr 03 2018 Robbie Harwood - 1.16-20 +- Be more careful asking for AS key in SPAKE client + * Mon Apr 02 2018 Robbie Harwood - 1.16-19 - Zap data when freeing krb5_spake_factor From 8ed07abedfe4ae7d853bbd2440007af1bca86fd5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 9 Apr 2018 12:12:08 -0400 Subject: [PATCH 036/304] Restrict pre-authentication fallback cases --- ...ct-pre-authentication-fallback-cases.patch | 491 ++++++++++++++++++ Return-UPN-SANs-as-strings.patch | 204 ++++++++ ...ately-and-unparse-them-with-NO_REALM.patch | 148 ++++++ krb5.spec | 8 +- 4 files changed, 850 insertions(+), 1 deletion(-) create mode 100644 Restrict-pre-authentication-fallback-cases.patch create mode 100644 Return-UPN-SANs-as-strings.patch create mode 100644 Save-SANs-separately-and-unparse-them-with-NO_REALM.patch diff --git a/Restrict-pre-authentication-fallback-cases.patch b/Restrict-pre-authentication-fallback-cases.patch new file mode 100644 index 0000000..0d42ba8 --- /dev/null +++ b/Restrict-pre-authentication-fallback-cases.patch @@ -0,0 +1,491 @@ +From 4a13b97ffba771de4b45b1ed309934cc840569d1 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 5 Apr 2018 16:23:34 -0400 +Subject: [PATCH] Restrict pre-authentication fallback cases + +Add a new callback disable_fallback() and call it from each clpreauth +module when it generates a client message using credentials to +authenticate. (For SPAKE, this is the message responding to a +challenge; for all other current mechanisms, it is the first and only +client message.) If disable_fallback() is called, do not try another +mechanism after a KDC error. + +Remove k5_reset_preauth_types_tried() and its call sites, so that +preauth mechanisms which are tried optimistically will no longer be +retried after a failure. + +ticket: 8654 +(cherry picked from commit 7a24a088c16d326127dd2b29084d4ca085c70d10) +--- + src/include/krb5/clpreauth_plugin.h | 14 +++++ + src/lib/krb5/krb/get_in_tkt.c | 21 +++----- + src/lib/krb5/krb/init_creds_ctx.h | 1 + + src/lib/krb5/krb/int-proto.h | 3 -- + src/lib/krb5/krb/preauth2.c | 23 ++++----- + src/lib/krb5/krb/preauth_ec.c | 1 + + src/lib/krb5/krb/preauth_encts.c | 2 + + src/lib/krb5/krb/preauth_otp.c | 4 ++ + src/lib/krb5/krb/preauth_sam2.c | 1 + + src/plugins/preauth/pkinit/pkinit_clnt.c | 1 + + src/plugins/preauth/spake/spake_client.c | 4 ++ + src/plugins/preauth/test/cltest.c | 11 ++++ + src/tests/t_preauth.py | 88 ++++++++++++++++++++++++++++---- + src/tests/t_spake.py | 9 +--- + 14 files changed, 134 insertions(+), 49 deletions(-) + +diff --git a/src/include/krb5/clpreauth_plugin.h b/src/include/krb5/clpreauth_plugin.h +index 0106734ad..5317669b7 100644 +--- a/src/include/krb5/clpreauth_plugin.h ++++ b/src/include/krb5/clpreauth_plugin.h +@@ -160,7 +160,21 @@ typedef struct krb5_clpreauth_callbacks_st { + krb5_error_code (*set_cc_config)(krb5_context context, + krb5_clpreauth_rock rock, + const char *key, const char *data); ++ + /* End of version 2 clpreauth callbacks (added in 1.11). */ ++ ++ /* ++ * Prevent further fallbacks to other preauth mechanisms if the KDC replies ++ * with an error. (The module itself can still respond to errors with its ++ * tryagain method, or continue after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED ++ * errors with its process method.) A module should invoke this callback ++ * from the process method when it generates an authenticated request using ++ * credentials; often this will be the first or only client message ++ * generated by the mechanism. ++ */ ++ void (*disable_fallback)(krb5_context context, krb5_clpreauth_rock rock); ++ ++ /* End of version 3 clpreauth callbacks (added in 1.17). */ + } *krb5_clpreauth_callbacks; + + /* +diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c +index 1d96ff163..c026bbc6d 100644 +--- a/src/lib/krb5/krb/get_in_tkt.c ++++ b/src/lib/krb5/krb/get_in_tkt.c +@@ -1331,9 +1331,7 @@ init_creds_step_request(krb5_context context, + krb5_free_pa_data(context, ctx->optimistic_padata); + ctx->optimistic_padata = NULL; + if (code) { +- /* Make an unauthenticated request, and possibly try again using +- * the same mechanisms as we tried optimistically. */ +- k5_reset_preauth_types_tried(ctx); ++ /* Make an unauthenticated request. */ + krb5_clear_error_message(context); + code = 0; + } +@@ -1361,6 +1359,9 @@ init_creds_step_request(krb5_context context, + /* Don't continue after a keyboard interrupt. */ + if (code == KRB5_LIBOS_PWDINTR) + goto cleanup; ++ /* Don't continue if fallback is disabled. */ ++ if (code && ctx->fallback_disabled) ++ goto cleanup; + if (code) { + /* See if we can try a different preauth mech before giving up. */ + k5_save_ctx_error(context, code, &save); +@@ -1549,16 +1550,10 @@ init_creds_step_reply(krb5_context context, + } else if (reply_code == KDC_ERR_PREAUTH_FAILED && retry) { + note_req_timestamp(context, ctx, ctx->err_reply->stime, + ctx->err_reply->susec); +- if (ctx->method_padata == NULL) { +- /* Optimistic preauth failed on the KDC. Allow all mechanisms +- * to be tried again using method data. */ +- k5_reset_preauth_types_tried(ctx); +- } else { +- /* Don't try again with the mechanism that failed. */ +- code = k5_preauth_note_failed(ctx, ctx->selected_preauth_type); +- if (code) +- goto cleanup; +- } ++ /* Don't try again with the mechanism that failed. */ ++ code = k5_preauth_note_failed(ctx, ctx->selected_preauth_type); ++ if (code) ++ goto cleanup; + ctx->selected_preauth_type = KRB5_PADATA_NONE; + /* Accept or update method data if the KDC sent it. */ + if (ctx->err_padata != NULL) +diff --git a/src/lib/krb5/krb/init_creds_ctx.h b/src/lib/krb5/krb/init_creds_ctx.h +index b19410a13..7ba61e17c 100644 +--- a/src/lib/krb5/krb/init_creds_ctx.h ++++ b/src/lib/krb5/krb/init_creds_ctx.h +@@ -60,6 +60,7 @@ struct _krb5_init_creds_context { + krb5_enctype etype; + krb5_boolean info_pa_permitted; + krb5_boolean restarted; ++ krb5_boolean fallback_disabled; + struct krb5_responder_context_st rctx; + krb5_preauthtype selected_preauth_type; + krb5_preauthtype allowed_preauth_type; +diff --git a/src/lib/krb5/krb/int-proto.h b/src/lib/krb5/krb/int-proto.h +index cda9010e3..d20133885 100644 +--- a/src/lib/krb5/krb/int-proto.h ++++ b/src/lib/krb5/krb/int-proto.h +@@ -197,9 +197,6 @@ k5_init_preauth_context(krb5_context context); + void + k5_free_preauth_context(krb5_context context); + +-void +-k5_reset_preauth_types_tried(krb5_init_creds_context ctx); +- + krb5_error_code + k5_preauth_note_failed(krb5_init_creds_context ctx, krb5_preauthtype pa_type); + +diff --git a/src/lib/krb5/krb/preauth2.c b/src/lib/krb5/krb/preauth2.c +index 451e0b7a8..1f17ec2b0 100644 +--- a/src/lib/krb5/krb/preauth2.c ++++ b/src/lib/krb5/krb/preauth2.c +@@ -203,18 +203,6 @@ cleanup: + free_handles(context, list); + } + +-/* Reset the memory of which preauth types we have already tried. */ +-void +-k5_reset_preauth_types_tried(krb5_init_creds_context ctx) +-{ +- krb5_preauth_req_context reqctx = ctx->preauth_reqctx; +- +- if (reqctx == NULL) +- return; +- free(reqctx->failed); +- reqctx->failed = NULL; +-} +- + /* Add pa_type to the list of types which has previously failed. */ + krb5_error_code + k5_preauth_note_failed(krb5_init_creds_context ctx, krb5_preauthtype pa_type) +@@ -553,8 +541,14 @@ set_cc_config(krb5_context context, krb5_clpreauth_rock rock, + return ret; + } + ++static void ++disable_fallback(krb5_context context, krb5_clpreauth_rock rock) ++{ ++ ((krb5_init_creds_context)rock)->fallback_disabled = TRUE; ++} ++ + static struct krb5_clpreauth_callbacks_st callbacks = { +- 2, ++ 3, + get_etype, + fast_armor, + get_as_key, +@@ -564,7 +558,8 @@ static struct krb5_clpreauth_callbacks_st callbacks = { + responder_get_answer, + need_as_key, + get_cc_config, +- set_cc_config ++ set_cc_config, ++ disable_fallback + }; + + /* Tweak the request body, for now adding any enctypes which the module claims +diff --git a/src/lib/krb5/krb/preauth_ec.c b/src/lib/krb5/krb/preauth_ec.c +index c1aa9090f..75aab770e 100644 +--- a/src/lib/krb5/krb/preauth_ec.c ++++ b/src/lib/krb5/krb/preauth_ec.c +@@ -138,6 +138,7 @@ ec_process(krb5_context context, krb5_clpreauth_moddata moddata, + encoded_ts->data = NULL; + *out_padata = pa; + pa = NULL; ++ cb->disable_fallback(context, rock); + } + free(pa); + krb5_free_data(context, encoded_ts); +diff --git a/src/lib/krb5/krb/preauth_encts.c b/src/lib/krb5/krb/preauth_encts.c +index cec384227..45bf9da92 100644 +--- a/src/lib/krb5/krb/preauth_encts.c ++++ b/src/lib/krb5/krb/preauth_encts.c +@@ -109,6 +109,8 @@ encts_process(krb5_context context, krb5_clpreauth_moddata moddata, + *out_padata = pa; + pa = NULL; + ++ cb->disable_fallback(context, rock); ++ + cleanup: + krb5_free_data(context, ts); + krb5_free_data(context, enc_ts); +diff --git a/src/lib/krb5/krb/preauth_otp.c b/src/lib/krb5/krb/preauth_otp.c +index 48fcbb5d5..13e584657 100644 +--- a/src/lib/krb5/krb/preauth_otp.c ++++ b/src/lib/krb5/krb/preauth_otp.c +@@ -1123,6 +1123,10 @@ otp_client_process(krb5_context context, krb5_clpreauth_moddata moddata, + + /* Encode the request into the pa_data output. */ + retval = set_pa_data(req, pa_data_out); ++ if (retval != 0) ++ goto error; ++ cb->disable_fallback(context, rock); ++ + error: + krb5_free_data_contents(context, &value); + krb5_free_data_contents(context, &pin); +diff --git a/src/lib/krb5/krb/preauth_sam2.c b/src/lib/krb5/krb/preauth_sam2.c +index c8a330655..4c70021a9 100644 +--- a/src/lib/krb5/krb/preauth_sam2.c ++++ b/src/lib/krb5/krb/preauth_sam2.c +@@ -410,6 +410,7 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata, + sam_padata[1] = NULL; + + *out_padata = sam_padata; ++ cb->disable_fallback(context, rock); + + return(0); + } +diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c +index 9483d69e5..77e9e5308 100644 +--- a/src/plugins/preauth/pkinit/pkinit_clnt.c ++++ b/src/plugins/preauth/pkinit/pkinit_clnt.c +@@ -179,6 +179,7 @@ pa_pkinit_gen_req(krb5_context context, + + *out_padata = return_pa_data; + return_pa_data = NULL; ++ cb->disable_fallback(context, rock); + + cleanup: + krb5_free_data(context, der_req); +diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c +index 47a6ba26c..00734a13b 100644 +--- a/src/plugins/preauth/spake/spake_client.c ++++ b/src/plugins/preauth/spake/spake_client.c +@@ -278,6 +278,10 @@ process_challenge(krb5_context context, groupstate *gstate, reqstate *st, + goto cleanup; + TRACE_SPAKE_SEND_RESPONSE(context); + ret = convert_to_padata(response, pa_out); ++ if (ret) ++ goto cleanup; ++ ++ cb->disable_fallback(context, rock); + + cleanup: + krb5_free_keyblock(context, k0); +diff --git a/src/plugins/preauth/test/cltest.c b/src/plugins/preauth/test/cltest.c +index f5f7c5aba..51b848481 100644 +--- a/src/plugins/preauth/test/cltest.c ++++ b/src/plugins/preauth/test/cltest.c +@@ -53,6 +53,9 @@ + * - If the "fail_optimistic", "fail_2rt", or "fail_tryagain" gic options are + * set, it fails with a recognizable error string at the requested point in + * processing. ++ * ++ * - If the "disable_fallback" gic option is set, fallback is disabled when a ++ * client message is generated. + */ + + #include "k5-int.h" +@@ -66,6 +69,7 @@ struct client_state { + krb5_boolean fail_optimistic; + krb5_boolean fail_2rt; + krb5_boolean fail_tryagain; ++ krb5_boolean disable_fallback; + }; + + struct client_request_state { +@@ -81,6 +85,7 @@ test_init(krb5_context context, krb5_clpreauth_moddata *moddata_out) + assert(st != NULL); + st->indicators = NULL; + st->fail_optimistic = st->fail_2rt = st->fail_tryagain = FALSE; ++ st->disable_fallback = FALSE; + *moddata_out = (krb5_clpreauth_moddata)st; + return 0; + } +@@ -138,6 +143,8 @@ test_process(krb5_context context, krb5_clpreauth_moddata moddata, + return KRB5_PREAUTH_FAILED; + } + *out_pa_data = make_pa_list("optimistic", 10); ++ if (st->disable_fallback) ++ cb->disable_fallback(context, rock); + return 0; + } else if (reqst->second_round_trip) { + printf("2rt: %.*s\n", pa_data->length, pa_data->contents); +@@ -166,6 +173,8 @@ test_process(krb5_context context, krb5_clpreauth_moddata moddata, + + indstr = (st->indicators != NULL) ? st->indicators : ""; + *out_pa_data = make_pa_list(indstr, strlen(indstr)); ++ if (st->disable_fallback) ++ cb->disable_fallback(context, rock); + return 0; + } + +@@ -212,6 +221,8 @@ test_gic_opt(krb5_context kcontext, krb5_clpreauth_moddata moddata, + st->fail_2rt = TRUE; + } else if (strcmp(attr, "fail_tryagain") == 0) { + st->fail_tryagain = TRUE; ++ } else if (strcmp(attr, "disable_fallback") == 0) { ++ st->disable_fallback = TRUE; + } + return 0; + } +diff --git a/src/tests/t_preauth.py b/src/tests/t_preauth.py +index efb3ea20d..32e35b08b 100644 +--- a/src/tests/t_preauth.py ++++ b/src/tests/t_preauth.py +@@ -37,8 +37,8 @@ expected_trace = ('Attempting optimistic preauth', + realm.run(['./icred', '-o', '-123', realm.user_princ, password('user')], + expected_trace=expected_trace) + +-# Test optimistic preauth failing on client, followed by successful +-# preauth using the same module. ++# Test optimistic preauth failing on client, falling back to encrypted ++# timestamp. + msgs = ('Attempting optimistic preauth', + 'Processing preauth types: -123', + '/induced optimistic fail', +@@ -46,15 +46,15 @@ msgs = ('Attempting optimistic preauth', + '/Additional pre-authentication required', + 'Preauthenticating using KDC method data', + 'Processing preauth types:', +- 'Preauth module test (-123) (real) returned: 0/Success', +- 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ 'Encrypted timestamp (for ', ++ 'module encrypted_timestamp (2) (real) returned: 0/Success', ++ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', + 'Decrypted AS reply') + realm.run(['./icred', '-o', '-123', '-X', 'fail_optimistic', realm.user_princ, +- password('user')], expected_msg='testval', +- expected_trace=msgs) ++ password('user')], expected_trace=msgs) + +-# Test optimistic preauth failing on KDC, followed by successful preauth +-# using the same module. ++# Test optimistic preauth failing on KDC, falling back to encrypted ++# timestamp. + realm.run([kadminl, 'setstr', realm.user_princ, 'failopt', 'yes']) + msgs = ('Attempting optimistic preauth', + 'Processing preauth types: -123', +@@ -63,11 +63,24 @@ msgs = ('Attempting optimistic preauth', + '/Preauthentication failed', + 'Preauthenticating using KDC method data', + 'Processing preauth types:', +- 'Preauth module test (-123) (real) returned: 0/Success', +- 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ 'Encrypted timestamp (for ', ++ 'module encrypted_timestamp (2) (real) returned: 0/Success', ++ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', + 'Decrypted AS reply') + realm.run(['./icred', '-o', '-123', realm.user_princ, password('user')], +- expected_msg='testval', expected_trace=msgs) ++ expected_trace=msgs) ++# Leave failopt set for the next test. ++ ++# Test optimistic preauth failing on KDC, stopping because the test ++# module disabled fallback. ++msgs = ('Attempting optimistic preauth', ++ 'Processing preauth types: -123', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: -123', ++ '/Preauthentication failed') ++realm.run(['./icred', '-X', 'disable_fallback', '-o', '-123', realm.user_princ, ++ password('user')], expected_code=1, ++ expected_msg='Preauthentication failed', expected_trace=msgs) + realm.run([kadminl, 'delstr', realm.user_princ, 'failopt']) + + # Test KDC_ERR_MORE_PREAUTH_DATA_REQUIRED and secure cookies. +@@ -107,6 +120,23 @@ msgs = ('Sending unauthenticated request', + realm.run(['./icred', '-X', 'fail_2rt', realm.user_princ, password('user')], + expected_msg='2rt: secondtrip', expected_trace=msgs) + ++# Test client-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED, ++# stopping because the test module disabled fallback. ++msgs = ('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Preauthenticating using KDC method data', ++ 'Processing preauth types:', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ '/More preauthentication data is required', ++ 'Continuing preauth mech -123', ++ 'Processing preauth types: -123, PA-FX-COOKIE (133)', ++ '/induced 2rt fail') ++realm.run(['./icred', '-X', 'fail_2rt', '-X', 'disable_fallback', ++ realm.user_princ, password('user')], expected_code=1, ++ expected_msg='Pre-authentication failed: induced 2rt fail', ++ expected_trace=msgs) ++ + # Test KDC-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED, + # falling back to encrypted timestamp. + realm.run([kadminl, 'setstr', realm.user_princ, 'fail2rt', 'yes']) +@@ -130,6 +160,25 @@ msgs = ('Sending unauthenticated request', + 'Decrypted AS reply') + realm.run(['./icred', realm.user_princ, password('user')], + expected_msg='2rt: secondtrip', expected_trace=msgs) ++# Leave fail2rt set for the next test. ++ ++# Test KDC-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED, ++# stopping because the test module disabled fallback. ++msgs = ('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Preauthenticating using KDC method data', ++ 'Processing preauth types:', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ '/More preauthentication data is required', ++ 'Continuing preauth mech -123', ++ 'Processing preauth types: -123, PA-FX-COOKIE (133)', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ '/Preauthentication failed') ++realm.run(['./icred', '-X', 'disable_fallback', ++ realm.user_princ, password('user')], expected_code=1, ++ expected_msg='Preauthentication failed', expected_trace=msgs) + realm.run([kadminl, 'delstr', realm.user_princ, 'fail2rt']) + + # Test tryagain flow by inducing a KDC_ERR_ENCTYPE_NOSUPP error on the KDC. +@@ -170,6 +219,23 @@ msgs = ('Sending unauthenticated request', + realm.run(['./icred', '-X', 'fail_tryagain', realm.user_princ, + password('user')], expected_trace=msgs) + ++# Test a client-side tryagain failure, stopping because the test ++# module disabled fallback. ++msgs = ('Sending unauthenticated request', ++ '/Additional pre-authentication required', ++ 'Preauthenticating using KDC method data', ++ 'Processing preauth types:', ++ 'Preauth module test (-123) (real) returned: 0/Success', ++ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', ++ '/KDC has no support for encryption type', ++ 'Recovering from KDC error 14 using preauth mech -123', ++ 'Preauth tryagain input types (-123): -123, PA-FX-COOKIE (133)', ++ '/induced tryagain fail') ++realm.run(['./icred', '-X', 'fail_tryagain', '-X', 'disable_fallback', ++ realm.user_princ, password('user')], expected_code=1, ++ expected_msg='KDC has no support for encryption type', ++ expected_trace=msgs) ++ + # Test that multiple stepwise initial creds operations can be + # performed with the same krb5_context, with proper tracking of + # clpreauth module request handles. +diff --git a/src/tests/t_spake.py b/src/tests/t_spake.py +index a81a238b4..5b47e62d3 100644 +--- a/src/tests/t_spake.py ++++ b/src/tests/t_spake.py +@@ -31,9 +31,7 @@ for gnum, gname in groups: + 'Decrypted AS reply') + realm.kinit('user', 'pw', expected_trace=msgs) + +- # Test an unsuccessful authentication. (The client will try +- # again with encrypted timestamp, which isn't really desired, +- # but check for that as long as it is expected.) ++ # Test an unsuccessful authentication. + msgs = ('/Additional pre-authentication required', + 'Selected etype info:', + 'Sending SPAKE support message', +@@ -42,9 +40,6 @@ for gnum, gname in groups: + 'Continuing preauth mech PA-SPAKE (151)', + 'SPAKE challenge received with group ' + str(gnum), + 'Sending SPAKE response', +- '/Preauthentication failed', +- 'Encrypted timestamp ', +- 'for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', + '/Preauthentication failed') + realm.kinit('user', 'wrongpw', expected_code=1, expected_trace=msgs) + +@@ -114,8 +109,6 @@ msgs = ('Attempting optimistic preauth', + 'for next request: PA-SPAKE (151)', + '/Preauthentication failed', + 'Selected etype info:', +- 'SPAKE challenge with group 1 rejected', +- 'spake (151) (real) returned: -1765328360/Preauthentication failed', + 'Encrypted timestamp ', + 'for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', + 'AS key determined by preauth:', diff --git a/Return-UPN-SANs-as-strings.patch b/Return-UPN-SANs-as-strings.patch new file mode 100644 index 0000000..d8aab07 --- /dev/null +++ b/Return-UPN-SANs-as-strings.patch @@ -0,0 +1,204 @@ +From 06d48c8d04a5efb098b026a1ec1c1609a5491ab0 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 22 Mar 2018 20:07:17 -0400 +Subject: [PATCH] Return UPN SANs as strings + +(cherry picked from commit fd3c824e3be56a1fa77d140fd7e93934bfd6e565) +--- + src/plugins/preauth/pkinit/pkinit_crypto.h | 4 ++-- + src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 28 ++++++++-------------- + src/plugins/preauth/pkinit/pkinit_matching.c | 16 +++---------- + src/plugins/preauth/pkinit/pkinit_srv.c | 21 ++++++++++------ + 4 files changed, 29 insertions(+), 40 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index c7ff29fb2..4e4752ff7 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -98,7 +98,7 @@ typedef struct _pkinit_cert_matching_data { + unsigned int ku_bits; /* key usage information */ + unsigned int eku_bits; /* extended key usage information */ + krb5_principal *sans; /* Null-terminated array of PKINIT SANs */ +- krb5_principal *upns; /* Null-terimnated array of UPN SANs */ ++ char **upns; /* Null-terimnated array of UPN SANs */ + } pkinit_cert_matching_data; + + /* +@@ -250,7 +250,7 @@ krb5_error_code crypto_retrieve_cert_sans + if non-NULL, a null-terminated array of + id-pkinit-san values found in the certificate + are returned */ +- krb5_principal **upn_sans, /* OUT ++ char ***upn_sans, /* OUT + if non-NULL, a null-terminated array of + id-ms-upn-san values found in the certificate + are returned */ +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index bc6de7ae8..b5a549c2c 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -29,6 +29,7 @@ + * SUCH DAMAGES. + */ + ++#include "k5-int.h" + #include "pkinit_crypto_openssl.h" + #include "k5-buf.h" + #include +@@ -2083,15 +2084,14 @@ crypto_retrieve_X509_sans(krb5_context context, + pkinit_plg_crypto_context plgctx, + pkinit_req_crypto_context reqctx, + X509 *cert, +- krb5_principal **princs_ret, +- krb5_principal **upn_ret, ++ krb5_principal **princs_ret, char ***upn_ret, + unsigned char ***dns_ret) + { + krb5_error_code retval = EINVAL; + char buf[DN_BUF_LEN]; + int p = 0, u = 0, d = 0, ret = 0, l; + krb5_principal *princs = NULL; +- krb5_principal *upns = NULL; ++ char **upns = NULL; + unsigned char **dnss = NULL; + unsigned int i, num_found = 0, num_sans = 0; + X509_EXTENSION *ext = NULL; +@@ -2141,7 +2141,7 @@ crypto_retrieve_X509_sans(krb5_context context, + } + } + if (upn_ret != NULL) { +- upns = calloc(num_sans + 1, sizeof(krb5_principal)); ++ upns = calloc(num_sans + 1, sizeof(*upns)); + if (upns == NULL) { + retval = ENOMEM; + goto cleanup; +@@ -2184,16 +2184,9 @@ crypto_retrieve_X509_sans(krb5_context context, + /* Prevent abuse of embedded null characters. */ + if (memchr(name.data, '\0', name.length)) + break; +- ret = krb5_parse_name_flags(context, name.data, +- KRB5_PRINCIPAL_PARSE_ENTERPRISE, +- &upns[u]); +- if (ret) { +- pkiDebug("%s: failed parsing ms-upn san value\n", +- __FUNCTION__); +- } else { +- u++; +- num_found++; +- } ++ upns[u] = k5memdup0(name.data, name.length, &ret); ++ if (upns[u] == NULL) ++ goto cleanup; + } else { + pkiDebug("%s: unrecognized othername oid in SAN\n", + __FUNCTION__); +@@ -2245,7 +2238,7 @@ cleanup: + krb5_free_principal(context, princs[i]); + free(princs); + for (i = 0; upns != NULL && upns[i] != NULL; i++) +- krb5_free_principal(context, upns[i]); ++ free(upns[i]); + free(upns); + for (i = 0; dnss != NULL && dnss[i] != NULL; i++) + free(dnss[i]); +@@ -2269,8 +2262,7 @@ crypto_retrieve_cert_sans(krb5_context context, + pkinit_plg_crypto_context plgctx, + pkinit_req_crypto_context reqctx, + pkinit_identity_crypto_context idctx, +- krb5_principal **princs_ret, +- krb5_principal **upn_ret, ++ krb5_principal **princs_ret, char ***upn_ret, + unsigned char ***dns_ret) + { + krb5_error_code retval = EINVAL; +@@ -5094,7 +5086,7 @@ crypto_cert_free_matching_data(krb5_context context, + krb5_free_principal(context, md->sans[i]); + free(md->sans); + for (i = 0; md->upns != NULL && md->upns[i] != NULL; i++) +- krb5_free_principal(context, md->upns[i]); ++ free(md->upns[i]); + free(md->upns); + free(md); + } +diff --git a/src/plugins/preauth/pkinit/pkinit_matching.c b/src/plugins/preauth/pkinit/pkinit_matching.c +index 37bd0251a..c2a4c084d 100644 +--- a/src/plugins/preauth/pkinit/pkinit_matching.c ++++ b/src/plugins/preauth/pkinit/pkinit_matching.c +@@ -490,11 +490,7 @@ component_match(krb5_context context, + break; + } + for (i = 0; md->upns != NULL && md->upns[i] != NULL; i++) { +- krb5_unparse_name_flags(context, md->upns[i], +- KRB5_PRINCIPAL_UNPARSE_NO_REALM, +- &princ_string); +- match = regexp_match(context, rc, princ_string); +- krb5_free_unparsed_name(context, princ_string); ++ match = regexp_match(context, rc, md->upns[i]); + if (match) + break; + } +@@ -584,14 +580,8 @@ check_all_certs(krb5_context context, + pkiDebug("%s: PKINIT san: '%s'\n", __FUNCTION__, san_string); + krb5_free_unparsed_name(context, san_string); + } +- for (j = 0; md->upns != NULL && md->upns[j] != NULL; j++) { +- char *san_string; +- krb5_unparse_name_flags(context, md->upns[j], +- KRB5_PRINCIPAL_UNPARSE_NO_REALM, +- &san_string); +- pkiDebug("%s: UPN san: '%s'\n", __FUNCTION__, san_string); +- krb5_free_unparsed_name(context, san_string); +- } ++ for (j = 0; md->upns != NULL && md->upns[j] != NULL; j++) ++ pkiDebug("%s: UPN san: '%s'\n", __FUNCTION__, md->upns[j]); + #endif + certs_checked++; + for (rc = rs->crs; rc != NULL; rc = rc->next) { +diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c +index bbfde34b2..3cc573813 100644 +--- a/src/plugins/preauth/pkinit/pkinit_srv.c ++++ b/src/plugins/preauth/pkinit/pkinit_srv.c +@@ -178,8 +178,9 @@ verify_client_san(krb5_context context, + int *valid_san) + { + krb5_error_code retval; +- krb5_principal *princs = NULL; +- krb5_principal *upns = NULL; ++ krb5_principal *princs = NULL, upn; ++ krb5_boolean match; ++ char **upns = NULL; + int i; + #ifdef DEBUG_SAN_INFO + char *client_string = NULL, *san_string; +@@ -255,12 +256,18 @@ verify_client_san(krb5_context context, + pkiDebug("%s: Checking upn sans\n", __FUNCTION__); + for (i = 0; upns[i] != NULL; i++) { + #ifdef DEBUG_SAN_INFO +- krb5_unparse_name(context, upns[i], &san_string); + pkiDebug("%s: Comparing client '%s' to upn san value '%s'\n", +- __FUNCTION__, client_string, san_string); +- krb5_free_unparsed_name(context, san_string); ++ __FUNCTION__, client_string, upns[i]); + #endif +- if (cb->match_client(context, rock, upns[i])) { ++ retval = krb5_parse_name_flags(context, upns[i], ++ KRB5_PRINCIPAL_PARSE_ENTERPRISE, &upn); ++ if (retval) { ++ /* XXX trace */ ++ continue; ++ } ++ match = cb->match_client(context, rock, upn); ++ krb5_free_principal(context, upn); ++ if (match) { + TRACE_PKINIT_SERVER_MATCHING_UPN_FOUND(context); + *valid_san = 1; + retval = 0; +@@ -286,7 +293,7 @@ out: + } + if (upns != NULL) { + for (i = 0; upns[i] != NULL; i++) +- krb5_free_principal(context, upns[i]); ++ free(upns[i]); + free(upns); + } + #ifdef DEBUG_SAN_INFO diff --git a/Save-SANs-separately-and-unparse-them-with-NO_REALM.patch b/Save-SANs-separately-and-unparse-them-with-NO_REALM.patch new file mode 100644 index 0000000..689ed40 --- /dev/null +++ b/Save-SANs-separately-and-unparse-them-with-NO_REALM.patch @@ -0,0 +1,148 @@ +From 8924d4bbbf82a29f1d6bf524a416d6e44b694734 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 22 Mar 2018 19:46:22 -0400 +Subject: [PATCH] Save SANs separately and unparse them with NO_REALM + +(cherry picked from commit 23ea8d6a9617d17ae5a529c23174d77adac39055) +--- + src/plugins/preauth/pkinit/pkinit_crypto.h | 4 +-- + src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 37 +++------------------- + src/plugins/preauth/pkinit/pkinit_matching.c | 30 +++++++++++++----- + 3 files changed, 28 insertions(+), 43 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index 2d3733bbc..c7ff29fb2 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -97,8 +97,8 @@ typedef struct _pkinit_cert_matching_data { + char *issuer_dn; /* rfc2253-style issuer name string */ + unsigned int ku_bits; /* key usage information */ + unsigned int eku_bits; /* extended key usage information */ +- krb5_principal *sans; /* Null-terminated array of subject alternative +- name info (pkinit and ms-upn) */ ++ krb5_principal *sans; /* Null-terminated array of PKINIT SANs */ ++ krb5_principal *upns; /* Null-terimnated array of UPN SANs */ + } pkinit_cert_matching_data; + + /* +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 4f21f90d2..bc6de7ae8 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -5093,6 +5093,9 @@ crypto_cert_free_matching_data(krb5_context context, + for (i = 0; md->sans != NULL && md->sans[i] != NULL; i++) + krb5_free_principal(context, md->sans[i]); + free(md->sans); ++ for (i = 0; md->upns != NULL && md->upns[i] != NULL; i++) ++ krb5_free_principal(context, md->upns[i]); ++ free(md->upns); + free(md); + } + +@@ -5121,8 +5124,6 @@ get_matching_data(krb5_context context, + { + krb5_error_code ret = ENOMEM; + pkinit_cert_matching_data *md = NULL; +- krb5_principal *pkinit_sans = NULL, *upn_sans = NULL; +- size_t i, j; + + *md_out = NULL; + +@@ -5139,40 +5140,10 @@ get_matching_data(krb5_context context, + + /* Get the SAN data. */ + ret = crypto_retrieve_X509_sans(context, plg_cryptoctx, req_cryptoctx, +- cert, &pkinit_sans, &upn_sans, NULL); ++ cert, &md->sans, &md->upns, NULL); + if (ret) + goto cleanup; + +- j = 0; +- if (pkinit_sans != NULL) { +- for (i = 0; pkinit_sans[i] != NULL; i++) +- j++; +- } +- if (upn_sans != NULL) { +- for (i = 0; upn_sans[i] != NULL; i++) +- j++; +- } +- if (j != 0) { +- md->sans = calloc((size_t)j+1, sizeof(*md->sans)); +- if (md->sans == NULL) { +- ret = ENOMEM; +- goto cleanup; +- } +- j = 0; +- if (pkinit_sans != NULL) { +- for (i = 0; pkinit_sans[i] != NULL; i++) +- md->sans[j++] = pkinit_sans[i]; +- free(pkinit_sans); +- } +- if (upn_sans != NULL) { +- for (i = 0; upn_sans[i] != NULL; i++) +- md->sans[j++] = upn_sans[i]; +- free(upn_sans); +- } +- md->sans[j] = NULL; +- } else +- md->sans = NULL; +- + /* Get the KU and EKU data. */ + ret = crypto_retrieve_X509_key_usage(context, plg_cryptoctx, + req_cryptoctx, cert, &md->ku_bits, +diff --git a/src/plugins/preauth/pkinit/pkinit_matching.c b/src/plugins/preauth/pkinit/pkinit_matching.c +index c1ce84b82..37bd0251a 100644 +--- a/src/plugins/preauth/pkinit/pkinit_matching.c ++++ b/src/plugins/preauth/pkinit/pkinit_matching.c +@@ -470,7 +470,6 @@ component_match(krb5_context context, + { + int match = 0; + int i; +- krb5_principal p; + char *princ_string; + + switch (rc->kwval_type) { +@@ -483,10 +482,17 @@ component_match(krb5_context context, + match = regexp_match(context, rc, md->issuer_dn); + break; + case kw_san: +- if (md->sans == NULL) +- break; +- for (i = 0, p = md->sans[i]; p != NULL; p = md->sans[++i]) { +- krb5_unparse_name(context, p, &princ_string); ++ for (i = 0; md->sans != NULL && md->sans[i] != NULL; i++) { ++ krb5_unparse_name(context, md->sans[i], &princ_string); ++ match = regexp_match(context, rc, princ_string); ++ krb5_free_unparsed_name(context, princ_string); ++ if (match) ++ break; ++ } ++ for (i = 0; md->upns != NULL && md->upns[i] != NULL; i++) { ++ krb5_unparse_name_flags(context, md->upns[i], ++ KRB5_PRINCIPAL_UNPARSE_NO_REALM, ++ &princ_string); + match = regexp_match(context, rc, princ_string); + krb5_free_unparsed_name(context, princ_string); + if (match) +@@ -572,10 +578,18 @@ check_all_certs(krb5_context context, + pkiDebug("%s: subject: '%s'\n", __FUNCTION__, md->subject_dn); + #if 0 + pkiDebug("%s: issuer: '%s'\n", __FUNCTION__, md->subject_dn); +- for (j = 0, p = md->sans[j]; p != NULL; p = md->sans[++j]) { ++ for (j = 0; md->sans != NULL && md->sans[j] != NULL; j++) { + char *san_string; +- krb5_unparse_name(context, p, &san_string); +- pkiDebug("%s: san: '%s'\n", __FUNCTION__, san_string); ++ krb5_unparse_name(context, md->sans[j], &san_string); ++ pkiDebug("%s: PKINIT san: '%s'\n", __FUNCTION__, san_string); ++ krb5_free_unparsed_name(context, san_string); ++ } ++ for (j = 0; md->upns != NULL && md->upns[j] != NULL; j++) { ++ char *san_string; ++ krb5_unparse_name_flags(context, md->upns[j], ++ KRB5_PRINCIPAL_UNPARSE_NO_REALM, ++ &san_string); ++ pkiDebug("%s: UPN san: '%s'\n", __FUNCTION__, san_string); + krb5_free_unparsed_name(context, san_string); + } + #endif diff --git a/krb5.spec b/krb5.spec index 8b22173..abe7092 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 20%{?dist} +Release: 21%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -89,6 +89,9 @@ Patch62: Fix-SPAKE-memory-leak.patch Patch63: Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch Patch64: Zap-data-when-freeing-krb5_spake_factor.patch Patch65: Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch +Patch66: Save-SANs-separately-and-unparse-them-with-NO_REALM.patch +Patch67: Return-UPN-SANs-as-strings.patch +Patch68: Restrict-pre-authentication-fallback-cases.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -739,6 +742,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Apr 09 2018 Robbie Harwood - 1.16-21 +- Restrict pre-authentication fallback cases + * Tue Apr 03 2018 Robbie Harwood - 1.16-20 - Be more careful asking for AS key in SPAKE client From 492b9109aa4d2f80b683b1eee50747e897d69a0f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 17 Apr 2018 17:27:54 +0000 Subject: [PATCH 037/304] Formatting changes (no code changes) New git behavior, ugh. --- ...ncoders-and-decoders-for-SPAKE-types.patch | 20 +++--- ...INIT-KDC-support-for-freshness-token.patch | 12 ++-- Add-SPAKE-preauth-support.patch | 70 +++++++++---------- Add-k5_buf_add_vfmt-to-k5buf-interface.patch | 4 +- ...bkrb5support-hex-functions-and-tests.patch | 8 +-- ...ul-asking-for-AS-key-in-SPAKE-client.patch | 2 +- Fix-flaws-in-LDAP-DN-checking.patch | 8 +-- ...-conversion-of-PKINIT-certid-strings.patch | 2 +- Implement-k5_buf_init_dynamic_zap.patch | 4 +- ...uth-name-in-trace-output-if-possible.patch | 8 +-- Move-zap-definition-to-k5-platform.h.patch | 4 +- ...r-KDC-krb5_pa_data-utility-functions.patch | 6 +- ...ct-pre-authentication-fallback-cases.patch | 14 ++-- Return-UPN-SANs-as-strings.patch | 8 +-- ...ately-and-unparse-them-with-NO_REALM.patch | 6 +- Simplify-kdc_preauth.c-systems-table.patch | 2 +- ...port-hex-functions-where-appropriate.patch | 38 +++++----- krb5-1.12-ktany.patch | 2 +- krb5-1.12.1-pam.patch | 8 +-- krb5-1.13-dirsrv-accountlock.patch | 6 +- krb5-1.15.1-selinux-label.patch | 50 ++++++------- 21 files changed, 141 insertions(+), 141 deletions(-) diff --git a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch index b2ef69d..52cd463 100644 --- a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch +++ b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch @@ -14,21 +14,21 @@ build. (cherry picked from commit 78a09d95dff6915da4079bc611f4bb95f6a95f70) --- - src/include/k5-spake.h | 107 +++++++++++++++++++++++++++++++++++ - src/lib/krb5/asn.1/asn1_k_encode.c | 52 ++++++++++++++++- - src/lib/krb5/krb/kfree.c | 40 +++++++++++++ + src/include/k5-spake.h | 107 +++++++++++++++++++++++++++ + src/lib/krb5/asn.1/asn1_k_encode.c | 52 ++++++++++++- + src/lib/krb5/krb/kfree.c | 40 ++++++++++ src/lib/krb5/libkrb5.exports | 6 ++ src/tests/asn.1/Makefile.in | 2 +- - src/tests/asn.1/krb5_decode_test.c | 37 ++++++++++++ - src/tests/asn.1/krb5_encode_test.c | 29 ++++++++++ - src/tests/asn.1/ktest.c | 97 +++++++++++++++++++++++++++++++ + src/tests/asn.1/krb5_decode_test.c | 37 +++++++++ + src/tests/asn.1/krb5_encode_test.c | 29 ++++++++ + src/tests/asn.1/ktest.c | 97 ++++++++++++++++++++++++ src/tests/asn.1/ktest.h | 9 +++ - src/tests/asn.1/ktest_equal.c | 49 ++++++++++++++++ + src/tests/asn.1/ktest_equal.c | 49 ++++++++++++ src/tests/asn.1/ktest_equal.h | 6 ++ - src/tests/asn.1/make-vectors.c | 56 ++++++++++++++++++ + src/tests/asn.1/make-vectors.c | 56 ++++++++++++++ src/tests/asn.1/reference_encode.out | 6 ++ - src/tests/asn.1/spake.asn1 | 44 ++++++++++++++ - src/tests/asn.1/trval_reference.out | 50 ++++++++++++++++ + src/tests/asn.1/spake.asn1 | 44 +++++++++++ + src/tests/asn.1/trval_reference.out | 50 +++++++++++++ 15 files changed, 588 insertions(+), 2 deletions(-) create mode 100644 src/include/k5-spake.h create mode 100644 src/tests/asn.1/spake.asn1 diff --git a/Add-PKINIT-KDC-support-for-freshness-token.patch b/Add-PKINIT-KDC-support-for-freshness-token.patch index a2630db..94830f4 100644 --- a/Add-PKINIT-KDC-support-for-freshness-token.patch +++ b/Add-PKINIT-KDC-support-for-freshness-token.patch @@ -26,18 +26,18 @@ ticket: 8648 (cherry picked from commit 4a9050df0bc34bfb08ba24462d6e2514640f4b8e) --- doc/admin/conf_files/kdc_conf.rst | 4 + - doc/admin/pkinit.rst | 25 ++++++ + doc/admin/pkinit.rst | 25 +++++ doc/appdev/refs/macros/index.rst | 2 + - doc/formats/freshness_token.rst | 19 +++++ + doc/formats/freshness_token.rst | 19 ++++ doc/formats/index.rst | 1 + - src/include/krb5/kdcpreauth_plugin.h | 17 +++++ + src/include/krb5/kdcpreauth_plugin.h | 17 ++++ src/include/krb5/krb5.hin | 3 + src/kdc/do_as_req.c | 2 + - src/kdc/kdc_preauth.c | 130 +++++++++++++++++++++++++++++++- + src/kdc/kdc_preauth.c | 130 +++++++++++++++++++++++- src/kdc/kdc_util.h | 2 + src/plugins/preauth/pkinit/pkinit.h | 2 + - src/plugins/preauth/pkinit/pkinit_srv.c | 51 ++++++++++++- - src/tests/t_pkinit.py | 50 ++++++++---- + src/plugins/preauth/pkinit/pkinit_srv.c | 51 +++++++++- + src/tests/t_pkinit.py | 50 ++++++--- 13 files changed, 292 insertions(+), 16 deletions(-) create mode 100644 doc/formats/freshness_token.rst diff --git a/Add-SPAKE-preauth-support.patch b/Add-SPAKE-preauth-support.patch index 0afb0dc..8f67729 100644 --- a/Add-SPAKE-preauth-support.patch +++ b/Add-SPAKE-preauth-support.patch @@ -48,41 +48,41 @@ registry contents; implemented P-384 and P-521] ticket: 8647 (new) (cherry picked from commit 7447259401569c92b1fb2e31cb02edbbffd67d35) --- - NOTICE | 51 + - doc/admin/conf_files/kdc_conf.rst | 22 +- - doc/admin/conf_files/krb5_conf.rst | 15 + - doc/admin/index.rst | 1 + - doc/admin/spake.rst | 46 + - doc/formats/cookie.rst | 37 + - doc/notice.rst | 47 + - src/Makefile.in | 2 + - src/config/pre.in | 6 + - src/configure.in | 20 + - src/include/k5-int.h | 3 + - src/include/krb5/krb5.hin | 2 + - src/kdc/kdc_preauth.c | 2 + - src/lib/krb5/krb/preauth2.c | 2 + - src/lib/krb5/os/trace.c | 1 + - src/plugins/preauth/spake/AUTHORS | 16 + - src/plugins/preauth/spake/Makefile.in | 39 + - src/plugins/preauth/spake/deps | 73 + - src/plugins/preauth/spake/edwards25519.c | 2651 ++++++++ - src/plugins/preauth/spake/edwards25519_tables.h | 7881 +++++++++++++++++++++++ - src/plugins/preauth/spake/groups.c | 442 ++ - src/plugins/preauth/spake/groups.h | 148 + - src/plugins/preauth/spake/iana.c | 108 + - src/plugins/preauth/spake/iana.h | 65 + - src/plugins/preauth/spake/openssl.c | 315 + - src/plugins/preauth/spake/spake.exports | 2 + - src/plugins/preauth/spake/spake_client.c | 363 ++ - src/plugins/preauth/spake/spake_kdc.c | 590 ++ - src/plugins/preauth/spake/t_krb5.conf | 2 + - src/plugins/preauth/spake/t_vectors.c | 476 ++ - src/plugins/preauth/spake/trace.h | 74 + - src/plugins/preauth/spake/util.c | 211 + - src/plugins/preauth/spake/util.h | 56 + - src/tests/Makefile.in | 1 + - src/tests/t_spake.py | 151 + + NOTICE | 51 + + doc/admin/conf_files/kdc_conf.rst | 22 +- + doc/admin/conf_files/krb5_conf.rst | 15 + + doc/admin/index.rst | 1 + + doc/admin/spake.rst | 46 + + doc/formats/cookie.rst | 37 + + doc/notice.rst | 47 + + src/Makefile.in | 2 + + src/config/pre.in | 6 + + src/configure.in | 20 + + src/include/k5-int.h | 3 + + src/include/krb5/krb5.hin | 2 + + src/kdc/kdc_preauth.c | 2 + + src/lib/krb5/krb/preauth2.c | 2 + + src/lib/krb5/os/trace.c | 1 + + src/plugins/preauth/spake/AUTHORS | 16 + + src/plugins/preauth/spake/Makefile.in | 39 + + src/plugins/preauth/spake/deps | 73 + + src/plugins/preauth/spake/edwards25519.c | 2651 ++++++ + .../preauth/spake/edwards25519_tables.h | 7881 +++++++++++++++++ + src/plugins/preauth/spake/groups.c | 442 + + src/plugins/preauth/spake/groups.h | 148 + + src/plugins/preauth/spake/iana.c | 108 + + src/plugins/preauth/spake/iana.h | 65 + + src/plugins/preauth/spake/openssl.c | 315 + + src/plugins/preauth/spake/spake.exports | 2 + + src/plugins/preauth/spake/spake_client.c | 363 + + src/plugins/preauth/spake/spake_kdc.c | 590 ++ + src/plugins/preauth/spake/t_krb5.conf | 2 + + src/plugins/preauth/spake/t_vectors.c | 476 + + src/plugins/preauth/spake/trace.h | 74 + + src/plugins/preauth/spake/util.c | 211 + + src/plugins/preauth/spake/util.h | 56 + + src/tests/Makefile.in | 1 + + src/tests/t_spake.py | 151 + 35 files changed, 13917 insertions(+), 4 deletions(-) create mode 100644 doc/admin/spake.rst create mode 100644 src/plugins/preauth/spake/AUTHORS diff --git a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch index e6dae99..d9b8d94 100644 --- a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch +++ b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch @@ -5,8 +5,8 @@ Subject: [PATCH] Add k5_buf_add_vfmt to k5buf interface (cherry picked from commit f05766469efc2a055085c0bcf9d40c4cdf47fe36) --- - src/include/k5-buf.h | 8 ++++++++ - src/util/support/k5buf.c | 26 +++++++++++++++----------- + src/include/k5-buf.h | 8 ++++++ + src/util/support/k5buf.c | 26 +++++++++++-------- src/util/support/libkrb5support-fixed.exports | 1 + 3 files changed, 24 insertions(+), 11 deletions(-) diff --git a/Add-libkrb5support-hex-functions-and-tests.patch b/Add-libkrb5support-hex-functions-and-tests.patch index 88a1be7..7b769ab 100644 --- a/Add-libkrb5support-hex-functions-and-tests.patch +++ b/Add-libkrb5support-hex-functions-and-tests.patch @@ -6,12 +6,12 @@ Subject: [PATCH] Add libkrb5support hex functions and tests (cherry picked from commit 720dea558da0062d3cea4385327161e62cf09a5e) [rharwood@redhat.com Remove .gitignore] --- - src/include/k5-hex.h | 53 ++++++++ - src/util/support/Makefile.in | 15 ++- + src/include/k5-hex.h | 53 ++++++ + src/util/support/Makefile.in | 15 +- src/util/support/deps | 6 + - src/util/support/hex.c | 116 ++++++++++++++++++ + src/util/support/hex.c | 116 ++++++++++++ src/util/support/libkrb5support-fixed.exports | 2 + - src/util/support/t_hex.c | 169 ++++++++++++++++++++++++++ + src/util/support/t_hex.c | 169 ++++++++++++++++++ 6 files changed, 358 insertions(+), 3 deletions(-) create mode 100644 src/include/k5-hex.h create mode 100644 src/util/support/hex.c diff --git a/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch b/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch index ac80178..287b3f9 100644 --- a/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch +++ b/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch @@ -20,7 +20,7 @@ spake_prep_questions() without a prototype. ticket: 8659 (cherry picked from commit f240f1b0d324312be8aa59ead7cfbe0c329ed064) --- - src/plugins/preauth/spake/spake_client.c | 111 ++++++++++++++++++------------- + src/plugins/preauth/spake/spake_client.c | 111 ++++++++++++++--------- 1 file changed, 66 insertions(+), 45 deletions(-) diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c diff --git a/Fix-flaws-in-LDAP-DN-checking.patch b/Fix-flaws-in-LDAP-DN-checking.patch index 4a775bb..fc3f23c 100644 --- a/Fix-flaws-in-LDAP-DN-checking.patch +++ b/Fix-flaws-in-LDAP-DN-checking.patch @@ -41,10 +41,10 @@ target_version: 1.15-next (cherry picked from commit e1caf6fb74981da62039846931ebdffed71309d1) --- - src/lib/kadm5/srv/svr_principal.c | 7 + - src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h | 2 +- - src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c | 200 +++++++++++---------- - src/tests/t_kdb.py | 11 ++ + src/lib/kadm5/srv/svr_principal.c | 7 + + src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h | 2 +- + .../kdb/ldap/libkdb_ldap/ldap_principal2.c | 200 ++++++++++-------- + src/tests/t_kdb.py | 11 + 4 files changed, 125 insertions(+), 95 deletions(-) diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c diff --git a/Fix-hex-conversion-of-PKINIT-certid-strings.patch b/Fix-hex-conversion-of-PKINIT-certid-strings.patch index 6acb007..bc21999 100644 --- a/Fix-hex-conversion-of-PKINIT-certid-strings.patch +++ b/Fix-hex-conversion-of-PKINIT-certid-strings.patch @@ -13,7 +13,7 @@ commit message] ticket: 8636 (cherry picked from commit 63e8b8142fd7b3931a7bf2d6448978ca536bafc0) --- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 55 +++++++++++++++++----- + .../preauth/pkinit/pkinit_crypto_openssl.c | 55 +++++++++++++++---- 1 file changed, 44 insertions(+), 11 deletions(-) diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c diff --git a/Implement-k5_buf_init_dynamic_zap.patch b/Implement-k5_buf_init_dynamic_zap.patch index 2b5656c..94ba25f 100644 --- a/Implement-k5_buf_init_dynamic_zap.patch +++ b/Implement-k5_buf_init_dynamic_zap.patch @@ -8,8 +8,8 @@ reallocating or freeing the buffer. (cherry picked from commit 8ee8246c14702dc03b02e31b9fb5b7c2bb674bfb) --- - src/include/k5-buf.h | 6 +++- - src/util/support/k5buf.c | 41 +++++++++++++++++++++------ + src/include/k5-buf.h | 6 ++- + src/util/support/k5buf.c | 41 +++++++++++++++---- src/util/support/libkrb5support-fixed.exports | 1 + 3 files changed, 39 insertions(+), 9 deletions(-) diff --git a/Include-preauth-name-in-trace-output-if-possible.patch b/Include-preauth-name-in-trace-output-if-possible.patch index ca12e6f..e5c024a 100644 --- a/Include-preauth-name-in-trace-output-if-possible.patch +++ b/Include-preauth-name-in-trace-output-if-possible.patch @@ -12,11 +12,11 @@ and use it when formatting {patype} or {patypes}. ticket: 8653 (new) (cherry picked from commit 9c68fe39b018666eabe033b639c1f35d03ba51c7) --- - src/include/k5-trace.h | 17 ++-- + src/include/k5-trace.h | 17 +-- src/lib/krb5/os/t_trace.ref | 2 +- - src/lib/krb5/os/trace.c | 61 ++++++++++++- - src/tests/t_pkinit.py | 43 ++++----- - src/tests/t_preauth.py | 216 ++++++++++++++++++++++---------------------- + src/lib/krb5/os/trace.c | 61 +++++++++- + src/tests/t_pkinit.py | 43 +++---- + src/tests/t_preauth.py | 216 ++++++++++++++++++------------------ 5 files changed, 200 insertions(+), 139 deletions(-) diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h diff --git a/Move-zap-definition-to-k5-platform.h.patch b/Move-zap-definition-to-k5-platform.h.patch index dc4e696..9d08931 100644 --- a/Move-zap-definition-to-k5-platform.h.patch +++ b/Move-zap-definition-to-k5-platform.h.patch @@ -8,8 +8,8 @@ include k5-int.h by moving its definition to k5-platform.h. (cherry picked from commit df6bef6f9ea6a5f6f3956a2988cd658c78aae817) --- - src/include/k5-int.h | 45 --------------------------------------------- - src/include/k5-platform.h | 47 ++++++++++++++++++++++++++++++++++++++++++++++- + src/include/k5-int.h | 45 ------------------------------------- + src/include/k5-platform.h | 47 ++++++++++++++++++++++++++++++++++++++- src/util/support/zap.c | 4 ++-- 3 files changed, 48 insertions(+), 48 deletions(-) diff --git a/Refactor-KDC-krb5_pa_data-utility-functions.patch b/Refactor-KDC-krb5_pa_data-utility-functions.patch index 664e99b..0dedd1f 100644 --- a/Refactor-KDC-krb5_pa_data-utility-functions.patch +++ b/Refactor-KDC-krb5_pa_data-utility-functions.patch @@ -17,10 +17,10 @@ where applicable. (cherry picked from commit 4af478c18b02e1d2444a328bb79e6976ef3d312b) --- - src/kdc/fast_util.c | 28 +------- + src/kdc/fast_util.c | 28 +------ src/kdc/kdc_preauth.c | 14 ++-- - src/kdc/kdc_util.c | 187 +++++++++++++++++++++++++------------------------- - src/kdc/kdc_util.h | 8 +-- + src/kdc/kdc_util.c | 187 +++++++++++++++++++++--------------------- + src/kdc/kdc_util.h | 8 +- 4 files changed, 109 insertions(+), 128 deletions(-) diff --git a/src/kdc/fast_util.c b/src/kdc/fast_util.c diff --git a/Restrict-pre-authentication-fallback-cases.patch b/Restrict-pre-authentication-fallback-cases.patch index 0d42ba8..f5cf87e 100644 --- a/Restrict-pre-authentication-fallback-cases.patch +++ b/Restrict-pre-authentication-fallback-cases.patch @@ -17,20 +17,20 @@ retried after a failure. ticket: 8654 (cherry picked from commit 7a24a088c16d326127dd2b29084d4ca085c70d10) --- - src/include/krb5/clpreauth_plugin.h | 14 +++++ - src/lib/krb5/krb/get_in_tkt.c | 21 +++----- + src/include/krb5/clpreauth_plugin.h | 14 ++++ + src/lib/krb5/krb/get_in_tkt.c | 21 +++--- src/lib/krb5/krb/init_creds_ctx.h | 1 + - src/lib/krb5/krb/int-proto.h | 3 -- - src/lib/krb5/krb/preauth2.c | 23 ++++----- + src/lib/krb5/krb/int-proto.h | 3 - + src/lib/krb5/krb/preauth2.c | 23 +++---- src/lib/krb5/krb/preauth_ec.c | 1 + src/lib/krb5/krb/preauth_encts.c | 2 + src/lib/krb5/krb/preauth_otp.c | 4 ++ src/lib/krb5/krb/preauth_sam2.c | 1 + src/plugins/preauth/pkinit/pkinit_clnt.c | 1 + src/plugins/preauth/spake/spake_client.c | 4 ++ - src/plugins/preauth/test/cltest.c | 11 ++++ - src/tests/t_preauth.py | 88 ++++++++++++++++++++++++++++---- - src/tests/t_spake.py | 9 +--- + src/plugins/preauth/test/cltest.c | 11 +++ + src/tests/t_preauth.py | 88 +++++++++++++++++++++--- + src/tests/t_spake.py | 9 +-- 14 files changed, 134 insertions(+), 49 deletions(-) diff --git a/src/include/krb5/clpreauth_plugin.h b/src/include/krb5/clpreauth_plugin.h diff --git a/Return-UPN-SANs-as-strings.patch b/Return-UPN-SANs-as-strings.patch index d8aab07..78a458e 100644 --- a/Return-UPN-SANs-as-strings.patch +++ b/Return-UPN-SANs-as-strings.patch @@ -5,10 +5,10 @@ Subject: [PATCH] Return UPN SANs as strings (cherry picked from commit fd3c824e3be56a1fa77d140fd7e93934bfd6e565) --- - src/plugins/preauth/pkinit/pkinit_crypto.h | 4 ++-- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 28 ++++++++-------------- - src/plugins/preauth/pkinit/pkinit_matching.c | 16 +++---------- - src/plugins/preauth/pkinit/pkinit_srv.c | 21 ++++++++++------ + src/plugins/preauth/pkinit/pkinit_crypto.h | 4 +-- + .../preauth/pkinit/pkinit_crypto_openssl.c | 28 +++++++------------ + src/plugins/preauth/pkinit/pkinit_matching.c | 16 ++--------- + src/plugins/preauth/pkinit/pkinit_srv.c | 21 +++++++++----- 4 files changed, 29 insertions(+), 40 deletions(-) diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h diff --git a/Save-SANs-separately-and-unparse-them-with-NO_REALM.patch b/Save-SANs-separately-and-unparse-them-with-NO_REALM.patch index 689ed40..9375e07 100644 --- a/Save-SANs-separately-and-unparse-them-with-NO_REALM.patch +++ b/Save-SANs-separately-and-unparse-them-with-NO_REALM.patch @@ -5,9 +5,9 @@ Subject: [PATCH] Save SANs separately and unparse them with NO_REALM (cherry picked from commit 23ea8d6a9617d17ae5a529c23174d77adac39055) --- - src/plugins/preauth/pkinit/pkinit_crypto.h | 4 +-- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 37 +++------------------- - src/plugins/preauth/pkinit/pkinit_matching.c | 30 +++++++++++++----- + src/plugins/preauth/pkinit/pkinit_crypto.h | 4 +- + .../preauth/pkinit/pkinit_crypto_openssl.c | 37 ++----------------- + src/plugins/preauth/pkinit/pkinit_matching.c | 30 +++++++++++---- 3 files changed, 28 insertions(+), 43 deletions(-) diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h diff --git a/Simplify-kdc_preauth.c-systems-table.patch b/Simplify-kdc_preauth.c-systems-table.patch index fad6fc4..a8d1ded 100644 --- a/Simplify-kdc_preauth.c-systems-table.patch +++ b/Simplify-kdc_preauth.c-systems-table.patch @@ -16,7 +16,7 @@ since it was first added. (cherry picked from commit fea1a488924faa3938ef723feaa1ff12d22a91ff) --- - src/kdc/kdc_preauth.c | 526 ++++++++++++++++++-------------------------------- + src/kdc/kdc_preauth.c | 526 +++++++++++++++--------------------------- 1 file changed, 184 insertions(+), 342 deletions(-) diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c diff --git a/Use-libkrb5support-hex-functions-where-appropriate.patch b/Use-libkrb5support-hex-functions-where-appropriate.patch index e706d8e..0e3e26b 100644 --- a/Use-libkrb5support-hex-functions-where-appropriate.patch +++ b/Use-libkrb5support-hex-functions-where-appropriate.patch @@ -5,25 +5,25 @@ Subject: [PATCH] Use libkrb5support hex functions where appropriate (cherry picked from commit b0c700608be7455041a8afc0e4502e8783ee7f30) --- - src/kadmin/dbutil/deps | 16 +++--- - src/kadmin/dbutil/tabdump.c | 19 +++---- - src/kadmin/ktutil/deps | 13 +++-- - src/kadmin/ktutil/ktutil_funcs.c | 30 ++++------ - src/lib/crypto/crypto_tests/deps | 39 +++++++------ - src/lib/crypto/crypto_tests/t_cksum.c | 35 +++--------- - src/lib/crypto/crypto_tests/t_crc.c | 28 ++-------- - src/lib/crypto/crypto_tests/t_hmac.c | 34 +++++------ - src/plugins/kdb/ldap/ldap_util/deps | 18 +++--- - .../kdb/ldap/ldap_util/kdb5_ldap_services.c | 32 ++++------- - .../kdb/ldap/ldap_util/kdb5_ldap_services.h | 2 - - src/plugins/kdb/ldap/libkdb_ldap/deps | 19 ++++--- - .../kdb/ldap/libkdb_ldap/ldap_service_stash.c | 65 +++------------------- - .../kdb/ldap/libkdb_ldap/ldap_service_stash.h | 3 - - .../kdb/ldap/libkdb_ldap/libkdb_ldap.exports | 1 - - src/slave/deps | 15 ++--- - src/slave/kproplog.c | 11 ++-- - src/tests/gssapi/deps | 14 ++--- - src/tests/gssapi/t_prf.c | 13 +++-- + src/kadmin/dbutil/deps | 16 ++--- + src/kadmin/dbutil/tabdump.c | 19 +++--- + src/kadmin/ktutil/deps | 13 ++-- + src/kadmin/ktutil/ktutil_funcs.c | 30 ++++----- + src/lib/crypto/crypto_tests/deps | 39 ++++++----- + src/lib/crypto/crypto_tests/t_cksum.c | 35 +++------- + src/lib/crypto/crypto_tests/t_crc.c | 28 ++------ + src/lib/crypto/crypto_tests/t_hmac.c | 34 +++++----- + src/plugins/kdb/ldap/ldap_util/deps | 18 ++--- + .../kdb/ldap/ldap_util/kdb5_ldap_services.c | 32 +++------ + .../kdb/ldap/ldap_util/kdb5_ldap_services.h | 2 - + src/plugins/kdb/ldap/libkdb_ldap/deps | 19 +++--- + .../kdb/ldap/libkdb_ldap/ldap_service_stash.c | 65 +++---------------- + .../kdb/ldap/libkdb_ldap/ldap_service_stash.h | 3 - + .../kdb/ldap/libkdb_ldap/libkdb_ldap.exports | 1 - + src/slave/deps | 15 +++-- + src/slave/kproplog.c | 11 ++-- + src/tests/gssapi/deps | 14 ++-- + src/tests/gssapi/t_prf.c | 13 ++-- 19 files changed, 152 insertions(+), 255 deletions(-) diff --git a/src/kadmin/dbutil/deps b/src/kadmin/dbutil/deps diff --git a/krb5-1.12-ktany.patch b/krb5-1.12-ktany.patch index f48ba8d..b7e5ef1 100644 --- a/krb5-1.12-ktany.patch +++ b/krb5-1.12-ktany.patch @@ -8,7 +8,7 @@ when searching for a specific entry. When iterated through, it only presents the contents of the first keytab. --- src/lib/krb5/keytab/Makefile.in | 3 + - src/lib/krb5/keytab/kt_any.c | 292 ++++++++++++++++++++++++++++++++++++++++ + src/lib/krb5/keytab/kt_any.c | 292 ++++++++++++++++++++++++++++++++ src/lib/krb5/keytab/ktbase.c | 7 +- 3 files changed, 301 insertions(+), 1 deletion(-) create mode 100644 src/lib/krb5/keytab/kt_any.c diff --git a/krb5-1.12.1-pam.patch b/krb5-1.12.1-pam.patch index 9a6a092..ba4382a 100644 --- a/krb5-1.12.1-pam.patch +++ b/krb5-1.12.1-pam.patch @@ -17,11 +17,11 @@ Originally RT#5939, though it's changed since then to perform the account and session management before dropping privileges, and to apply on top of changes we're proposing for how it handles cache collections. --- - src/aclocal.m4 | 67 ++++++++ + src/aclocal.m4 | 67 +++++++ src/clients/ksu/Makefile.in | 8 +- - src/clients/ksu/main.c | 88 +++++++++- - src/clients/ksu/pam.c | 389 ++++++++++++++++++++++++++++++++++++++++++++ - src/clients/ksu/pam.h | 57 +++++++ + src/clients/ksu/main.c | 88 +++++++- + src/clients/ksu/pam.c | 389 ++++++++++++++++++++++++++++++++++++ + src/clients/ksu/pam.h | 57 ++++++ src/configure.in | 2 + 6 files changed, 608 insertions(+), 3 deletions(-) create mode 100644 src/clients/ksu/pam.c diff --git a/krb5-1.13-dirsrv-accountlock.patch b/krb5-1.13-dirsrv-accountlock.patch index db7ca29..e898d9d 100644 --- a/krb5-1.13-dirsrv-accountlock.patch +++ b/krb5-1.13-dirsrv-accountlock.patch @@ -6,9 +6,9 @@ Subject: [PATCH] krb5-1.13-dirsrv-accountlock.patch Treat 'nsAccountLock: true' the same as 'loginDisabled: true'. Updated from original version filed as RT#5891. --- - src/aclocal.m4 | 9 +++++++++ - src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c | 17 +++++++++++++++++ - src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c | 3 +++ + src/aclocal.m4 | 9 +++++++++ + src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c | 17 +++++++++++++++++ + .../kdb/ldap/libkdb_ldap/ldap_principal.c | 3 +++ 3 files changed, 29 insertions(+) diff --git a/src/aclocal.m4 b/src/aclocal.m4 diff --git a/krb5-1.15.1-selinux-label.patch b/krb5-1.15.1-selinux-label.patch index 8d4d1db..8c9a252 100644 --- a/krb5-1.15.1-selinux-label.patch +++ b/krb5-1.15.1-selinux-label.patch @@ -36,31 +36,31 @@ The selabel APIs for looking up the context should be thread-safe (per Red Hat #273081), so switching to using them instead of matchpathcon(), which we used earlier, is some improvement. --- - src/aclocal.m4 | 49 +++ - src/build-tools/krb5-config.in | 3 +- - src/config/pre.in | 3 +- - src/configure.in | 2 + - src/include/k5-int.h | 1 + - src/include/k5-label.h | 32 ++ - src/include/krb5/krb5.hin | 6 + - src/kadmin/dbutil/dump.c | 11 +- - src/kdc/main.c | 2 +- - src/lib/kadm5/logger.c | 4 +- - src/lib/kdb/kdb_log.c | 2 +- - src/lib/krb5/ccache/cc_dir.c | 26 +- - src/lib/krb5/keytab/kt_file.c | 4 +- - src/lib/krb5/os/trace.c | 2 +- - src/lib/krb5/rcache/rc_dfl.c | 13 + - src/plugins/kdb/db2/adb_openclose.c | 2 +- - src/plugins/kdb/db2/kdb_db2.c | 4 +- - src/plugins/kdb/db2/libdb2/btree/bt_open.c | 3 +- - src/plugins/kdb/db2/libdb2/hash/hash.c | 3 +- - src/plugins/kdb/db2/libdb2/recno/rec_open.c | 4 +- - .../kdb/ldap/ldap_util/kdb5_ldap_services.c | 11 +- - src/slave/kpropd.c | 9 + - src/util/profile/prof_file.c | 3 +- - src/util/support/Makefile.in | 3 +- - src/util/support/selinux.c | 406 +++++++++++++++++++++ + src/aclocal.m4 | 49 +++ + src/build-tools/krb5-config.in | 3 +- + src/config/pre.in | 3 +- + src/configure.in | 2 + + src/include/k5-int.h | 1 + + src/include/k5-label.h | 32 ++ + src/include/krb5/krb5.hin | 6 + + src/kadmin/dbutil/dump.c | 11 +- + src/kdc/main.c | 2 +- + src/lib/kadm5/logger.c | 4 +- + src/lib/kdb/kdb_log.c | 2 +- + src/lib/krb5/ccache/cc_dir.c | 26 +- + src/lib/krb5/keytab/kt_file.c | 4 +- + src/lib/krb5/os/trace.c | 2 +- + src/lib/krb5/rcache/rc_dfl.c | 13 + + src/plugins/kdb/db2/adb_openclose.c | 2 +- + src/plugins/kdb/db2/kdb_db2.c | 4 +- + src/plugins/kdb/db2/libdb2/btree/bt_open.c | 3 +- + src/plugins/kdb/db2/libdb2/hash/hash.c | 3 +- + src/plugins/kdb/db2/libdb2/recno/rec_open.c | 4 +- + .../kdb/ldap/ldap_util/kdb5_ldap_services.c | 11 +- + src/slave/kpropd.c | 9 + + src/util/profile/prof_file.c | 3 +- + src/util/support/Makefile.in | 3 +- + src/util/support/selinux.c | 406 ++++++++++++++++++ 25 files changed, 587 insertions(+), 21 deletions(-) create mode 100644 src/include/k5-label.h create mode 100644 src/util/support/selinux.c From a48c97c32b059ef357fc8b937eb8f96f8b1ec33e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 17 Apr 2018 13:28:40 -0400 Subject: [PATCH 038/304] Merge duplicate subsections in profile library --- ...icate-subsections-in-profile-library.patch | 122 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 127 insertions(+), 1 deletion(-) create mode 100644 Merge-duplicate-subsections-in-profile-library.patch diff --git a/Merge-duplicate-subsections-in-profile-library.patch b/Merge-duplicate-subsections-in-profile-library.patch new file mode 100644 index 0000000..3507c9e --- /dev/null +++ b/Merge-duplicate-subsections-in-profile-library.patch @@ -0,0 +1,122 @@ +From 77ece30d3df5b119a74f7fe9e2c0a4c693194917 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 10 Apr 2018 15:55:41 -0400 +Subject: [PATCH] Merge duplicate subsections in profile library + +Modify profile_add_node() to return the existing node, rather than +making a new one, when adding subsection configuration. + +This fixes an issue where the first instance of a subsection will hide +the second instance entirely. In particular, it was previously +impossible to split realm-specific configuration across multiple +config files. + +[ghudson@mit.edu: adjusted style, added test case] + +ticket: 7863 +tags: pullup +target_version: 1.16-next +target_version: 1.15-next + +(cherry picked from commit efab9fa5a6d23c486467264e20b58bf5a9c60f0c) +--- + src/util/profile/prof_test1 | 22 ++++++++++++++++++++++ + src/util/profile/prof_tree.c | 15 +++++++++++---- + src/util/profile/test.ini | 6 ++++++ + 3 files changed, 39 insertions(+), 4 deletions(-) + +diff --git a/src/util/profile/prof_test1 b/src/util/profile/prof_test1 +index 7e30fc12f..7d13c9389 100644 +--- a/src/util/profile/prof_test1 ++++ b/src/util/profile/prof_test1 +@@ -341,6 +341,27 @@ proc test9 {} { + puts "OK: test9: profile_flush_to_file with no changes" + } + ++proc test10 {} { ++ global wd verbose ++ ++ # Regression test for #7863: multiply-specified subsections should ++ # be merged. ++ set p [profile_init_path $wd/test2.ini] ++ set x [profile_get_values $p {{test section 2} child_section2 child}] ++ if $verbose { puts "Read $x from profile" } ++ if ![string equal $x "slick harry {john\tb } ron"] { ++ puts stderr "Error: test10: Did not get expected merged children." ++ exit 1 ++ } ++ ++ set x [profile_get_string $p {test section 2} child_section2 chores] ++ if $verbose { puts "Read $x from profile" } ++ if ![string equal $x "cleaning"] { ++ puts stderr "Error: test10: Did not find expected chores." ++ exit 1 ++ } ++} ++ + test1 + test2 + test3 +@@ -350,5 +371,6 @@ test6 + test7 + test8 + test9 ++test10 + + exit 0 +diff --git a/src/util/profile/prof_tree.c b/src/util/profile/prof_tree.c +index 081f688e4..38aadc4e5 100644 +--- a/src/util/profile/prof_tree.c ++++ b/src/util/profile/prof_tree.c +@@ -9,7 +9,7 @@ + * + * Each node may represent either a relation or a section header. + * +- * A section header must have its value field set to 0, and may a one ++ * A section header must have its value field be null, and may have one + * or more child nodes, pointed to by first_child. + * + * A relation has as its value a pointer to allocated memory +@@ -159,15 +159,22 @@ errcode_t profile_add_node(struct profile_node *section, const char *name, + return PROF_ADD_NOT_SECTION; + + /* +- * Find the place to insert the new node. We look for the +- * place *after* the last match of the node name, since ++ * Find the place to insert the new node. If we are adding a subsection ++ * and already have a subsection with that name, merge them. Otherwise, ++ * we look for the place *after* the last match of the node name, since + * order matters. + */ + for (p=section->first_child, last = 0; p; last = p, p = p->next) { + int cmp; + cmp = strcmp(p->name, name); +- if (cmp > 0) ++ if (cmp > 0) { + break; ++ } else if (value == NULL && cmp == 0 && ++ p->value == NULL && p->deleted != 1) { ++ /* Found duplicate subsection, so don't make a new one. */ ++ *ret_node = p; ++ return 0; ++ } + } + retval = profile_create_node(name, value, &new); + if (retval) +diff --git a/src/util/profile/test.ini b/src/util/profile/test.ini +index 23ca89677..6622df108 100644 +--- a/src/util/profile/test.ini ++++ b/src/util/profile/test.ini +@@ -10,6 +10,12 @@ this is a comment. Everything up to the first square brace is ignored. + } + child_section2 = foo + ++[test section 2] ++ child_section2 = { ++ child = ron ++ chores = cleaning ++ } ++ + [realms] + ATHENA.MIT.EDU = { + server = KERBEROS.MIT.EDU:88 diff --git a/krb5.spec b/krb5.spec index abe7092..8fbe91f 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 21%{?dist} +Release: 22%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -92,6 +92,7 @@ Patch65: Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch Patch66: Save-SANs-separately-and-unparse-them-with-NO_REALM.patch Patch67: Return-UPN-SANs-as-strings.patch Patch68: Restrict-pre-authentication-fallback-cases.patch +Patch69: Merge-duplicate-subsections-in-profile-library.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -742,6 +743,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Apr 17 2018 Robbie Harwood - 1.16-22 +- Merge duplicate subsections in profile library + * Mon Apr 09 2018 Robbie Harwood - 1.16-21 - Restrict pre-authentication fallback cases From 58b0bd97d4c53e4cf5998f7b0df7028ef17f9195 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 23 Apr 2018 17:11:51 +0000 Subject: [PATCH 039/304] Explicitly use openssl rather than builtin crypto Resolves: #1570910 --- krb5.spec | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 8fbe91f..4eab979 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 22%{?dist} +Release: 23%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -350,6 +350,7 @@ CPPFLAGS="`echo $DEFINES $INCLUDES`" --with-dirsrv-account-locking \ %endif --enable-pkinit \ + --with-crypto-impl=openssl \ --with-pkinit-crypto-impl=openssl \ --with-tls-impl=openssl \ --with-system-verto \ @@ -743,6 +744,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Apr 23 2018 Robbie Harwood - 1.16-23 +- Explicitly use openssl rather than builtin crypto +- Resolves: #1570910 + * Tue Apr 17 2018 Robbie Harwood - 1.16-22 - Merge duplicate subsections in profile library From 95cc3ea977d430346f544796426d4e7c1ef36b63 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 23 Apr 2018 17:14:27 +0000 Subject: [PATCH 040/304] Explicitly use openssl rather than builtin crypto Resolves: #1570910 --- krb5.spec | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 925be0b..1031c0d 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.15.2 # for prerelease, should be e.g., 0.3.beta2% { ?dist } (without spaces) -Release: 8%{?dist} +Release: 9%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.15/krb5-%{version}%{prerelease}.tar.gz @@ -352,6 +352,7 @@ CPPFLAGS="`echo $DEFINES $INCLUDES`" --with-dirsrv-account-locking \ %endif --enable-pkinit \ + --with-crypto-impl=openssl \ --with-pkinit-crypto-impl=openssl \ --with-tls-impl=openssl \ --with-system-verto \ @@ -746,6 +747,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Apr 23 2018 Robbie Harwood - 1.15.2-9 +- Explicitly use openssl rather than builtin crypto +- Resolves: #1570910 + * Thu Mar 29 2018 Robbie Harwood - 1.15.2-8 - Continue after KRB5_CC_END in KCM cache iteration From 1dc2c64cf30f9a216a17b4c11ffc7a908e472df5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 24 Apr 2018 11:19:31 -0400 Subject: [PATCH 041/304] Fix KDC null dereference on large TGS replies --- ...ull-dereference-on-large-TGS-replies.patch | 224 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 229 insertions(+), 1 deletion(-) create mode 100644 Fix-KDC-null-dereference-on-large-TGS-replies.patch diff --git a/Fix-KDC-null-dereference-on-large-TGS-replies.patch b/Fix-KDC-null-dereference-on-large-TGS-replies.patch new file mode 100644 index 0000000..d0fc333 --- /dev/null +++ b/Fix-KDC-null-dereference-on-large-TGS-replies.patch @@ -0,0 +1,224 @@ +From d3697aa9a653bc9aaf11f3c9e985ba544c23a9c3 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 20 Apr 2018 16:16:02 -0400 +Subject: [PATCH] Fix KDC null dereference on large TGS replies + +For TGS requests, dispatch() doesn't set state->active_realm, which +leads to a NULL dereference in finish_dispatch() if the reply is too +big for UDP. Prior to commit 0a2f14f752c32a24200363cc6b6ae64a92f81379 +the active realm was a global and was set when process_tgs_req() +called setup_server_realm(). + +Move TGS decoding out of process_tgs_req() so that we can set +state->active_realm before any errors requiring response. Add a test +case. + +[ghudson@mit.edu: edited commit message; added test case; reduced code +duplication; removed server handle from process_tgs_req() parameters] + +ticket: 8666 +tags: pullup +target_version: 1.16-next +target_version: 1.15-next + +(cherry picked from commit 6afa8b4abf8f7c5774d03e6b15ee7288ad68d725) +--- + src/kdc/Makefile.in | 1 + + src/kdc/dispatch.c | 50 ++++++++++++++++++++++++------------------- + src/kdc/do_tgs_req.c | 24 ++++++--------------- + src/kdc/kdc_util.h | 5 ++--- + src/kdc/t_bigreply.py | 19 ++++++++++++++++ + 5 files changed, 56 insertions(+), 43 deletions(-) + create mode 100644 src/kdc/t_bigreply.py + +diff --git a/src/kdc/Makefile.in b/src/kdc/Makefile.in +index 61a3dbc6f..117a8f561 100644 +--- a/src/kdc/Makefile.in ++++ b/src/kdc/Makefile.in +@@ -85,6 +85,7 @@ check-cmocka: t_replay + check-pytests: + $(RUNPYTEST) $(srcdir)/t_workers.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_emptytgt.py $(PYTESTFLAGS) ++ $(RUNPYTEST) $(srcdir)/t_bigreply.py $(PYTESTFLAGS) + + install: + $(INSTALL_PROGRAM) krb5kdc ${DESTDIR}$(SERVER_BINDIR)/krb5kdc +diff --git a/src/kdc/dispatch.c b/src/kdc/dispatch.c +index 3867ff952..3ed5176a8 100644 +--- a/src/kdc/dispatch.c ++++ b/src/kdc/dispatch.c +@@ -124,7 +124,7 @@ dispatch(void *cb, const krb5_fulladdr *local_addr, + verto_ctx *vctx, loop_respond_fn respond, void *arg) + { + krb5_error_code retval; +- krb5_kdc_req *as_req; ++ krb5_kdc_req *req = NULL; + krb5_data *response = NULL; + struct dispatch_state *state; + struct server_handle *handle = cb; +@@ -176,29 +176,35 @@ dispatch(void *cb, const krb5_fulladdr *local_addr, + + /* try TGS_REQ first; they are more common! */ + +- if (krb5_is_tgs_req(pkt)) { +- retval = process_tgs_req(handle, pkt, remote_addr, &response); +- } else if (krb5_is_as_req(pkt)) { +- if (!(retval = decode_krb5_as_req(pkt, &as_req))) { +- /* +- * setup_server_realm() sets up the global realm-specific data +- * pointer. +- * process_as_req frees the request if it is called +- */ +- state->active_realm = setup_server_realm(handle, as_req->server); +- if (state->active_realm != NULL) { +- process_as_req(as_req, pkt, local_addr, remote_addr, +- state->active_realm, vctx, +- finish_dispatch_cache, state); +- return; +- } else { +- retval = KRB5KDC_ERR_WRONG_REALM; +- krb5_free_kdc_req(kdc_err_context, as_req); +- } +- } +- } else ++ if (krb5_is_tgs_req(pkt)) ++ retval = decode_krb5_tgs_req(pkt, &req); ++ else if (krb5_is_as_req(pkt)) ++ retval = decode_krb5_as_req(pkt, &req); ++ else + retval = KRB5KRB_AP_ERR_MSG_TYPE; ++ if (retval) ++ goto done; + ++ state->active_realm = setup_server_realm(handle, req->server); ++ if (state->active_realm == NULL) { ++ retval = KRB5KDC_ERR_WRONG_REALM; ++ goto done; ++ } ++ ++ if (krb5_is_tgs_req(pkt)) { ++ /* process_tgs_req frees the request */ ++ retval = process_tgs_req(req, pkt, remote_addr, state->active_realm, ++ &response); ++ req = NULL; ++ } else if (krb5_is_as_req(pkt)) { ++ /* process_as_req frees the request and calls finish_dispatch_cache. */ ++ process_as_req(req, pkt, local_addr, remote_addr, state->active_realm, ++ vctx, finish_dispatch_cache, state); ++ return; ++ } ++ ++done: ++ krb5_free_kdc_req(kdc_err_context, req); + finish_dispatch_cache(state, retval, response); + } + +diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c +index cc5a69236..61051bafa 100644 +--- a/src/kdc/do_tgs_req.c ++++ b/src/kdc/do_tgs_req.c +@@ -98,12 +98,12 @@ search_sprinc(kdc_realm_t *, krb5_kdc_req *, krb5_flags, + + /*ARGSUSED*/ + krb5_error_code +-process_tgs_req(struct server_handle *handle, krb5_data *pkt, +- const krb5_fulladdr *from, krb5_data **response) ++process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, ++ const krb5_fulladdr *from, kdc_realm_t *kdc_active_realm, ++ krb5_data **response) + { + krb5_keyblock * subkey = 0; + krb5_keyblock *header_key = NULL; +- krb5_kdc_req *request = 0; + krb5_db_entry *server = NULL; + krb5_db_entry *stkt_server = NULL; + krb5_kdc_rep reply; +@@ -136,7 +136,6 @@ process_tgs_req(struct server_handle *handle, krb5_data *pkt, + krb5_pa_data *pa_tgs_req; /*points into request*/ + krb5_data scratch; + krb5_pa_data **e_data = NULL; +- kdc_realm_t *kdc_active_realm = NULL; + krb5_audit_state *au_state = NULL; + krb5_data **auth_indicators = NULL; + +@@ -146,36 +145,25 @@ process_tgs_req(struct server_handle *handle, krb5_data *pkt, + memset(&enc_tkt_reply, 0, sizeof(enc_tkt_reply)); + session_key.contents = NULL; + +- retval = decode_krb5_tgs_req(pkt, &request); +- if (retval) +- return retval; + /* Save pointer to client-requested service principal, in case of + * errors before a successful call to search_sprinc(). */ + sprinc = request->server; + + if (request->msg_type != KRB5_TGS_REQ) { +- krb5_free_kdc_req(handle->kdc_err_context, request); ++ krb5_free_kdc_req(kdc_context, request); + return KRB5_BADMSGTYPE; + } + +- /* +- * setup_server_realm() sets up the global realm-specific data pointer. +- */ +- kdc_active_realm = setup_server_realm(handle, request->server); +- if (kdc_active_realm == NULL) { +- krb5_free_kdc_req(handle->kdc_err_context, request); +- return KRB5KDC_ERR_WRONG_REALM; +- } + errcode = kdc_make_rstate(kdc_active_realm, &state); + if (errcode !=0) { +- krb5_free_kdc_req(handle->kdc_err_context, request); ++ krb5_free_kdc_req(kdc_context, request); + return errcode; + } + + /* Initialize audit state. */ + errcode = kau_init_kdc_req(kdc_context, request, from, &au_state); + if (errcode) { +- krb5_free_kdc_req(handle->kdc_err_context, request); ++ krb5_free_kdc_req(kdc_context, request); + return errcode; + } + /* Seed the audit trail with the request ID and basic information. */ +diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h +index a63af2503..1885c9f80 100644 +--- a/src/kdc/kdc_util.h ++++ b/src/kdc/kdc_util.h +@@ -145,9 +145,8 @@ process_as_req (krb5_kdc_req *, krb5_data *, + + /* do_tgs_req.c */ + krb5_error_code +-process_tgs_req (struct server_handle *, krb5_data *, +- const krb5_fulladdr *, +- krb5_data ** ); ++process_tgs_req (krb5_kdc_req *, krb5_data *, const krb5_fulladdr *, ++ kdc_realm_t *, krb5_data ** ); + /* dispatch.c */ + void + dispatch (void *, +diff --git a/src/kdc/t_bigreply.py b/src/kdc/t_bigreply.py +new file mode 100644 +index 000000000..6bc9a8fe0 +--- /dev/null ++++ b/src/kdc/t_bigreply.py +@@ -0,0 +1,19 @@ ++#!/usr/bin/python ++from k5test import * ++ ++# Set the maximum UDP reply size very low, so that all replies go ++# through the RESPONSE_TOO_BIG path. ++kdc_conf = {'kdcdefaults': {'kdc_max_dgram_reply_size': '10'}} ++realm = K5Realm(kdc_conf=kdc_conf, get_creds=False) ++ ++msgs = ('Sending initial UDP request', ++ 'Received answer', ++ 'Request or response is too big for UDP; retrying with TCP', ++ ' to KRBTEST.COM (tcp only)', ++ 'Initiating TCP connection', ++ 'Sending TCP request', ++ 'Terminating TCP connection') ++realm.kinit(realm.user_princ, password('user'), expected_trace=msgs) ++realm.run([kvno, realm.host_princ], expected_trace=msgs) ++ ++success('Large KDC replies') diff --git a/krb5.spec b/krb5.spec index 4eab979..b567e42 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 23%{?dist} +Release: 24%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -93,6 +93,7 @@ Patch66: Save-SANs-separately-and-unparse-them-with-NO_REALM.patch Patch67: Return-UPN-SANs-as-strings.patch Patch68: Restrict-pre-authentication-fallback-cases.patch Patch69: Merge-duplicate-subsections-in-profile-library.patch +Patch70: Fix-KDC-null-dereference-on-large-TGS-replies.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -744,6 +745,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Apr 24 2018 Robbie Harwood - 1.16-24 +- Fix KDC null dereference on large TGS replies + * Mon Apr 23 2018 Robbie Harwood - 1.16-23 - Explicitly use openssl rather than builtin crypto - Resolves: #1570910 From c150a97555c426856c262e83b3aaa578e383c2b6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 30 Apr 2018 12:08:15 -0400 Subject: [PATCH 042/304] Set error message on KCM get_princ failure --- Check-for-zero-argc-in-ksu.patch | 29 +++++++++++++ Move-zero-argc-check-earlier-in-ksu.patch | 39 +++++++++++++++++ ...ror-message-on-KCM-get_princ-failure.patch | 42 +++++++++++++++++++ krb5.spec | 8 +++- 4 files changed, 117 insertions(+), 1 deletion(-) create mode 100644 Check-for-zero-argc-in-ksu.patch create mode 100644 Move-zero-argc-check-earlier-in-ksu.patch create mode 100644 Set-error-message-on-KCM-get_princ-failure.patch diff --git a/Check-for-zero-argc-in-ksu.patch b/Check-for-zero-argc-in-ksu.patch new file mode 100644 index 0000000..32b0ae4 --- /dev/null +++ b/Check-for-zero-argc-in-ksu.patch @@ -0,0 +1,29 @@ +From 2c88cf9966d2dad7902df3eeef1834b55000b246 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 24 Apr 2018 14:31:35 -0400 +Subject: [PATCH] Check for zero argc in ksu + +Most programs in the tree will perform a null dereference when argc is +zero, but as a setuid program ksu should be extra careful about memory +errors, even if this one is harmless. Check and exit with status 1 +immediately. + +ticket: 8661 +(cherry picked from commit c5b0a998d6349f8c90821a347db5666aed0e50eb) +--- + src/clients/ksu/main.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c +index c6321c01b..6cb91e24f 100644 +--- a/src/clients/ksu/main.c ++++ b/src/clients/ksu/main.c +@@ -144,6 +144,8 @@ main (argc, argv) + exit(1); + } + ++ if (argc == 0) ++ exit(1); + if (strrchr(argv[0], '/')) + argv[0] = strrchr(argv[0], '/')+1; + prog_name = argv[0]; diff --git a/Move-zero-argc-check-earlier-in-ksu.patch b/Move-zero-argc-check-earlier-in-ksu.patch new file mode 100644 index 0000000..ba14d3e --- /dev/null +++ b/Move-zero-argc-check-earlier-in-ksu.patch @@ -0,0 +1,39 @@ +From 292843b6a1d774198845d8e9511d1fa2ca5859e4 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 24 Apr 2018 19:35:38 -0400 +Subject: [PATCH] Move zero argc check earlier in ksu + +For improved auditability, check for a zero argc value earlier in +main() so that the first two calls to com_err() can't pass a NULL +whoami value--which would be harmless, but that may not be obvious to +a reader. + +ticket: 8661 +(cherry picked from commit e1b5b824f5d7388a67d0854b56d3906c4fbdd778) +--- + src/clients/ksu/main.c | 5 +++-- + 1 file changed, 3 insertions(+), 2 deletions(-) + +diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c +index 6cb91e24f..b9a997fc2 100644 +--- a/src/clients/ksu/main.c ++++ b/src/clients/ksu/main.c +@@ -127,6 +127,9 @@ main (argc, argv) + krb5_boolean restrict_creds; + krb5_deltat lifetime, rlife; + ++ if (argc == 0) ++ exit(1); ++ + params = (char **) xcalloc (2, sizeof (char *)); + params[1] = NULL; + +@@ -144,8 +147,6 @@ main (argc, argv) + exit(1); + } + +- if (argc == 0) +- exit(1); + if (strrchr(argv[0], '/')) + argv[0] = strrchr(argv[0], '/')+1; + prog_name = argv[0]; diff --git a/Set-error-message-on-KCM-get_princ-failure.patch b/Set-error-message-on-KCM-get_princ-failure.patch new file mode 100644 index 0000000..bb2e3cb --- /dev/null +++ b/Set-error-message-on-KCM-get_princ-failure.patch @@ -0,0 +1,42 @@ +From fb73fe5af9c82c20630cbf72c08e3e89f57deeaf Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 27 Apr 2018 13:51:39 -0400 +Subject: [PATCH] Set error message on KCM get_princ failure + +This matches the expected behavior from other ccache types. Most +notably, the KEYRING equivalent was added in +c25fc42e8eac7350209df61e4a7b9960d17755ca + +ticket: 8675 (new) +tags: pullup +target_version: 1.16-next +target_version: 1.15-next + +(cherry picked from commit 58f60f3df7a625ccdcce23dfadd52dc335fd8da7) +--- + src/lib/krb5/ccache/cc_kcm.c | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c +index 0d38b1839..a777f2710 100644 +--- a/src/lib/krb5/ccache/cc_kcm.c ++++ b/src/lib/krb5/ccache/cc_kcm.c +@@ -721,12 +721,18 @@ kcm_get_princ(krb5_context context, krb5_ccache cache, + { + krb5_error_code ret; + struct kcmreq req; ++ struct kcm_cache_data *data = cache->data; + + kcmreq_init(&req, KCM_OP_GET_PRINCIPAL, cache); + ret = cache_call(context, cache, &req, FALSE); + /* Heimdal KCM can respond with code 0 and no principal. */ + if (!ret && req.reply.len == 0) + ret = KRB5_FCC_NOFILE; ++ if (ret == KRB5_FCC_NOFILE) { ++ k5_setmsg(context, ret, _("Credentials cache 'KCM:%s' not found"), ++ data->residual); ++ } ++ + if (!ret) + ret = k5_unmarshal_princ(req.reply.ptr, req.reply.len, 4, princ_out); + kcmreq_free(&req); diff --git a/krb5.spec b/krb5.spec index b567e42..6abe00c 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 24%{?dist} +Release: 25%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -94,6 +94,9 @@ Patch67: Return-UPN-SANs-as-strings.patch Patch68: Restrict-pre-authentication-fallback-cases.patch Patch69: Merge-duplicate-subsections-in-profile-library.patch Patch70: Fix-KDC-null-dereference-on-large-TGS-replies.patch +Patch71: Check-for-zero-argc-in-ksu.patch +Patch72: Move-zero-argc-check-earlier-in-ksu.patch +Patch73: Set-error-message-on-KCM-get_princ-failure.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -745,6 +748,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Apr 30 2018 Robbie Harwood - 1.16-25 +- Set error message on KCM get_princ failure + * Tue Apr 24 2018 Robbie Harwood - 1.16-24 - Fix KDC null dereference on large TGS replies From ace60f77734bfc30643927b307b8134272bfd68b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 30 Apr 2018 12:08:36 -0400 Subject: [PATCH 043/304] Set error message on KCM get_princ failure --- Check-for-zero-argc-in-ksu.patch | 29 -------------- Move-zero-argc-check-earlier-in-ksu.patch | 39 ------------------- ...ror-message-on-KCM-get_princ-failure.patch | 2 +- krb5.spec | 7 ++-- 4 files changed, 5 insertions(+), 72 deletions(-) delete mode 100644 Check-for-zero-argc-in-ksu.patch delete mode 100644 Move-zero-argc-check-earlier-in-ksu.patch diff --git a/Check-for-zero-argc-in-ksu.patch b/Check-for-zero-argc-in-ksu.patch deleted file mode 100644 index 32b0ae4..0000000 --- a/Check-for-zero-argc-in-ksu.patch +++ /dev/null @@ -1,29 +0,0 @@ -From 2c88cf9966d2dad7902df3eeef1834b55000b246 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 24 Apr 2018 14:31:35 -0400 -Subject: [PATCH] Check for zero argc in ksu - -Most programs in the tree will perform a null dereference when argc is -zero, but as a setuid program ksu should be extra careful about memory -errors, even if this one is harmless. Check and exit with status 1 -immediately. - -ticket: 8661 -(cherry picked from commit c5b0a998d6349f8c90821a347db5666aed0e50eb) ---- - src/clients/ksu/main.c | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c -index c6321c01b..6cb91e24f 100644 ---- a/src/clients/ksu/main.c -+++ b/src/clients/ksu/main.c -@@ -144,6 +144,8 @@ main (argc, argv) - exit(1); - } - -+ if (argc == 0) -+ exit(1); - if (strrchr(argv[0], '/')) - argv[0] = strrchr(argv[0], '/')+1; - prog_name = argv[0]; diff --git a/Move-zero-argc-check-earlier-in-ksu.patch b/Move-zero-argc-check-earlier-in-ksu.patch deleted file mode 100644 index ba14d3e..0000000 --- a/Move-zero-argc-check-earlier-in-ksu.patch +++ /dev/null @@ -1,39 +0,0 @@ -From 292843b6a1d774198845d8e9511d1fa2ca5859e4 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 24 Apr 2018 19:35:38 -0400 -Subject: [PATCH] Move zero argc check earlier in ksu - -For improved auditability, check for a zero argc value earlier in -main() so that the first two calls to com_err() can't pass a NULL -whoami value--which would be harmless, but that may not be obvious to -a reader. - -ticket: 8661 -(cherry picked from commit e1b5b824f5d7388a67d0854b56d3906c4fbdd778) ---- - src/clients/ksu/main.c | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - -diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c -index 6cb91e24f..b9a997fc2 100644 ---- a/src/clients/ksu/main.c -+++ b/src/clients/ksu/main.c -@@ -127,6 +127,9 @@ main (argc, argv) - krb5_boolean restrict_creds; - krb5_deltat lifetime, rlife; - -+ if (argc == 0) -+ exit(1); -+ - params = (char **) xcalloc (2, sizeof (char *)); - params[1] = NULL; - -@@ -144,8 +147,6 @@ main (argc, argv) - exit(1); - } - -- if (argc == 0) -- exit(1); - if (strrchr(argv[0], '/')) - argv[0] = strrchr(argv[0], '/')+1; - prog_name = argv[0]; diff --git a/Set-error-message-on-KCM-get_princ-failure.patch b/Set-error-message-on-KCM-get_princ-failure.patch index bb2e3cb..20cc5ba 100644 --- a/Set-error-message-on-KCM-get_princ-failure.patch +++ b/Set-error-message-on-KCM-get_princ-failure.patch @@ -1,4 +1,4 @@ -From fb73fe5af9c82c20630cbf72c08e3e89f57deeaf Mon Sep 17 00:00:00 2001 +From f9c9d683852eb4881e099b3042d4c6e5e1444efc Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 27 Apr 2018 13:51:39 -0400 Subject: [PATCH] Set error message on KCM get_princ failure diff --git a/krb5.spec b/krb5.spec index 6abe00c..8062dad 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 25%{?dist} +Release: 26%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -94,8 +94,6 @@ Patch67: Return-UPN-SANs-as-strings.patch Patch68: Restrict-pre-authentication-fallback-cases.patch Patch69: Merge-duplicate-subsections-in-profile-library.patch Patch70: Fix-KDC-null-dereference-on-large-TGS-replies.patch -Patch71: Check-for-zero-argc-in-ksu.patch -Patch72: Move-zero-argc-check-earlier-in-ksu.patch Patch73: Set-error-message-on-KCM-get_princ-failure.patch License: MIT @@ -748,6 +746,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Apr 30 2018 Robbie Harwood - 1.16-26 +- Set error message on KCM get_princ failure + * Mon Apr 30 2018 Robbie Harwood - 1.16-25 - Set error message on KCM get_princ failure From ab1e0477e9b5c9a0f92dd65f006441b7547483bb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 3 May 2018 13:01:11 -0400 Subject: [PATCH 044/304] Fix indentation in krb5.conf of default_ccache_name --- krb5.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/krb5.spec b/krb5.spec index 8062dad..cd472d1 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 26%{?dist} +Release: 27%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -449,7 +449,7 @@ mkdir -m 755 -p $RPM_BUILD_ROOT/etc/gss/mech.d %if 0%{?configure_default_ccache_name} export DEFCCNAME="%{configured_default_ccache_name}" awk '{print} - /^# default_realm/{print " default_ccache_name =", ENVIRON["DEFCCNAME"]}' \ + /^# default_realm/{print " default_ccache_name =", ENVIRON["DEFCCNAME"]}' \ %{SOURCE6} > $RPM_BUILD_ROOT/etc/krb5.conf touch -r %{SOURCE6} $RPM_BUILD_ROOT/etc/krb5.conf grep default_ccache_name $RPM_BUILD_ROOT/etc/krb5.conf @@ -746,6 +746,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu May 03 2018 Robbie Harwood - 1.16-27 +- Fix configuration of default ccache name to match file indentation + * Mon Apr 30 2018 Robbie Harwood - 1.16-26 - Set error message on KCM get_princ failure From 88ba66fe53de88d97d67086c713b85787d48e0c5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 4 May 2018 10:46:27 -0400 Subject: [PATCH 045/304] New upstream release - 1.16.1 --- .gitignore | 3 + ...ncoders-and-decoders-for-SPAKE-types.patch | 2 +- ...INIT-KDC-support-for-freshness-token.patch | 22 +- ...T-client-support-for-freshness-token.patch | 4 +- Add-SPAKE-preauth-support.patch | 10 +- ...oc-index-entries-for-SPAKE-constants.patch | 2 +- Add-k5_buf_add_vfmt-to-k5buf-interface.patch | 2 +- ...bkrb5support-hex-functions-and-tests.patch | 2 +- Add-vector-support-to-k5_sha256.patch | 2 +- ...dation-of-PACs-with-enterprise-names.patch | 49 --- ...ul-asking-for-AS-key-in-SPAKE-client.patch | 2 +- ...r-KRB5_CC_END-in-KCM-cache-iteration.patch | 42 --- Exit-with-status-0-from-kadmind.patch | 6 +- ...ull-dereference-on-large-TGS-replies.patch | 224 ------------ Fix-SPAKE-memory-leak.patch | 2 +- Fix-capaths-.-values-on-client.patch | 60 --- Fix-flaws-in-LDAP-DN-checking.patch | 346 ------------------ ...-conversion-of-PKINIT-certid-strings.patch | 8 +- Fix-read-overflow-in-KDC-sort_pa_data.patch | 2 +- ...id_sam2-preauth-for-non-default-salt.patch | 2 +- Implement-k5_buf_init_dynamic_zap.patch | 2 +- ...e-info-in-for-hardware-preauth-hints.patch | 2 +- ...uth-name-in-trace-output-if-possible.patch | 4 +- ...icate-subsections-in-profile-library.patch | 122 ------ Move-zap-definition-to-k5-platform.h.patch | 2 +- ...ed-directories-in-alphabetical-order.patch | 2 +- ...r-KDC-krb5_pa_data-utility-functions.patch | 6 +- Report-extended-errors-in-kinit-k-t-KDB.patch | 2 +- ...ct-pre-authentication-fallback-cases.patch | 2 +- Return-UPN-SANs-as-strings.patch | 204 ----------- ...ately-and-unparse-them-with-NO_REALM.patch | 148 -------- ...ror-message-on-KCM-get_princ-failure.patch | 42 --- Simplify-kdc_preauth.c-systems-table.patch | 2 +- ...f_init_dynamic_zap-where-appropriate.patch | 2 +- ...port-hex-functions-where-appropriate.patch | 2 +- Zap-data-when-freeing-krb5_spake_factor.patch | 2 +- krb5-1.11-kpasswdtest.patch | 2 +- krb5-1.11-run_user_0.patch | 2 +- krb5-1.12-api.patch | 2 +- krb5-1.12-ksu-path.patch | 2 +- krb5-1.12-ktany.patch | 2 +- krb5-1.12.1-pam.patch | 2 +- krb5-1.13-dirsrv-accountlock.patch | 2 +- krb5-1.15-beta1-buildconf.patch | 2 +- krb5-1.15.1-selinux-label.patch | 2 +- krb5-1.3.1-dns.patch | 2 +- krb5-1.9-debuginfo.patch | 2 +- krb5.spec | 16 +- sources | 6 +- 49 files changed, 71 insertions(+), 1311 deletions(-) delete mode 100644 Allow-validation-of-PACs-with-enterprise-names.patch delete mode 100644 Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch delete mode 100644 Fix-KDC-null-dereference-on-large-TGS-replies.patch delete mode 100644 Fix-capaths-.-values-on-client.patch delete mode 100644 Fix-flaws-in-LDAP-DN-checking.patch delete mode 100644 Merge-duplicate-subsections-in-profile-library.patch delete mode 100644 Return-UPN-SANs-as-strings.patch delete mode 100644 Save-SANs-separately-and-unparse-them-with-NO_REALM.patch delete mode 100644 Set-error-message-on-KCM-get_princ-failure.patch diff --git a/.gitignore b/.gitignore index fcf514a..c8fdb57 100644 --- a/.gitignore +++ b/.gitignore @@ -163,3 +163,6 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.16-pdfs.tar /krb5-1.16.tar.gz /krb5-1.16.tar.gz.asc +/krb5-1.16.1-pdfs.tar +/krb5-1.16.1.tar.gz +/krb5-1.16.1.tar.gz.asc diff --git a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch index 52cd463..6a00f5d 100644 --- a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch +++ b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch @@ -1,4 +1,4 @@ -From a675384ef4cc4b6d28cce20cbcef0d033206139a Mon Sep 17 00:00:00 2001 +From dd66546bde0bc868a9af2ac702c7466e7494b33b Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 13 Jun 2015 16:04:53 -0400 Subject: [PATCH] Add ASN.1 encoders and decoders for SPAKE types diff --git a/Add-PKINIT-KDC-support-for-freshness-token.patch b/Add-PKINIT-KDC-support-for-freshness-token.patch index 94830f4..7a5d9eb 100644 --- a/Add-PKINIT-KDC-support-for-freshness-token.patch +++ b/Add-PKINIT-KDC-support-for-freshness-token.patch @@ -1,4 +1,4 @@ -From 4ddfba7c9c12056f9f5819648f20f68e5625dced Mon Sep 17 00:00:00 2001 +From 9f69b78a93de5ae396eb96d2957f36f8b9dc7458 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 12 Mar 2018 11:31:46 -0400 Subject: [PATCH] Add PKINIT KDC support for freshness token @@ -377,10 +377,10 @@ index 6f34dc289..80b130222 100644 if (state->pa_data == NULL) { krb5_klog_syslog(LOG_INFO, diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index 18649b8ad..a63af2503 100644 +index 198eab9c4..1885c9f80 100644 --- a/src/kdc/kdc_util.h +++ b/src/kdc/kdc_util.h -@@ -427,11 +427,13 @@ struct krb5_kdcpreauth_rock_st { +@@ -426,11 +426,13 @@ struct krb5_kdcpreauth_rock_st { krb5_kdc_req *request; krb5_data *inner_body; krb5_db_entry *client; @@ -415,7 +415,7 @@ index 8489a3e23..fe2ec0d31 100644 int dh_min_bits; /* minimum DH modulus size allowed */ } pkinit_plg_opts; diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index 4e9685885..bbfde34b2 100644 +index 8aa4d8b49..76ad5bf19 100644 --- a/src/plugins/preauth/pkinit/pkinit_srv.c +++ b/src/plugins/preauth/pkinit/pkinit_srv.c @@ -161,6 +161,10 @@ pkinit_server_get_edata(krb5_context context, @@ -429,7 +429,7 @@ index 4e9685885..bbfde34b2 100644 (*respond)(arg, retval, NULL); } -@@ -396,6 +400,31 @@ cleanup: +@@ -403,6 +407,31 @@ cleanup: return ret; } @@ -461,7 +461,7 @@ index 4e9685885..bbfde34b2 100644 static void pkinit_server_verify_padata(krb5_context context, krb5_data *req_pkt, -@@ -418,10 +447,11 @@ pkinit_server_verify_padata(krb5_context context, +@@ -425,10 +454,11 @@ pkinit_server_verify_padata(krb5_context context, pkinit_kdc_req_context reqctx = NULL; krb5_checksum cksum = {0, 0, 0, NULL}; krb5_data *der_req = NULL; @@ -474,7 +474,7 @@ index 4e9685885..bbfde34b2 100644 char **sp; pkiDebug("pkinit_verify_padata: entered!\n"); -@@ -592,6 +622,14 @@ pkinit_server_verify_padata(krb5_context context, +@@ -599,6 +629,14 @@ pkinit_server_verify_padata(krb5_context context, goto cleanup; } @@ -489,7 +489,7 @@ index 4e9685885..bbfde34b2 100644 /* check if kdcPkId present and match KDC's subjectIdentifier */ if (reqp->kdcPkId.data != NULL) { int valid_kdcPkId = 0; -@@ -634,6 +672,13 @@ pkinit_server_verify_padata(krb5_context context, +@@ -641,6 +679,13 @@ pkinit_server_verify_padata(krb5_context context, break; } @@ -503,7 +503,7 @@ index 4e9685885..bbfde34b2 100644 if (is_signed && plgctx->auth_indicators != NULL) { /* Assert configured authentication indicators. */ for (sp = plgctx->auth_indicators; *sp != NULL; sp++) { -@@ -1323,6 +1368,10 @@ pkinit_init_kdc_profile(krb5_context context, pkinit_kdc_context plgctx) +@@ -1330,6 +1375,10 @@ pkinit_init_kdc_profile(krb5_context context, pkinit_kdc_context plgctx) KRB5_CONF_PKINIT_REQUIRE_CRL_CHECKING, 0, &plgctx->opts->require_crl_checking); @@ -515,7 +515,7 @@ index 4e9685885..bbfde34b2 100644 KRB5_CONF_PKINIT_EKU_CHECKING, &eku_string); diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index b790a7cda..3030322e1 100755 +index 86fe661a0..5bc60cb1e 100755 --- a/src/tests/t_pkinit.py +++ b/src/tests/t_pkinit.py @@ -39,6 +39,8 @@ pkinit_kdc_conf = {'realms': {'$realm': { @@ -620,7 +620,7 @@ index b790a7cda..3030322e1 100755 realm.kinit(realm.user_princ, flags=['-X', 'X509_user_identity=%s' % p12_identity]) realm.klist(realm.user_princ) -@@ -350,8 +376,6 @@ conf = open(softpkcs11rc, 'w') +@@ -357,8 +383,6 @@ conf = open(softpkcs11rc, 'w') conf.write("%s\t%s\t%s\t%s\n" % ('user', 'user token', user_pem, privkey_pem)) conf.close() # Expect to succeed without having to supply any more information. diff --git a/Add-PKINIT-client-support-for-freshness-token.patch b/Add-PKINIT-client-support-for-freshness-token.patch index 478229b..9aade4d 100644 --- a/Add-PKINIT-client-support-for-freshness-token.patch +++ b/Add-PKINIT-client-support-for-freshness-token.patch @@ -1,4 +1,4 @@ -From 7eb2df66aef8e2b58ec7dfa13e9ee19f5e3b5b34 Mon Sep 17 00:00:00 2001 +From 0bc035db40c5badae3cc00f452560785a0cb0a44 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 31 Jan 2017 17:02:34 -0500 Subject: [PATCH] Add PKINIT client support for freshness token @@ -275,7 +275,7 @@ index 2f88545da..d5858c424 100644 free_krb5_algorithm_identifiers(&((*in)->supportedCMSTypes)); if ((*in)->supportedKDFs) { diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h -index d4eb39d88..67e0caeb4 100644 +index 2d95da94a..7f95206c0 100644 --- a/src/plugins/preauth/pkinit/pkinit_trace.h +++ b/src/plugins/preauth/pkinit/pkinit_trace.h @@ -41,6 +41,8 @@ diff --git a/Add-SPAKE-preauth-support.patch b/Add-SPAKE-preauth-support.patch index 8f67729..52ae328 100644 --- a/Add-SPAKE-preauth-support.patch +++ b/Add-SPAKE-preauth-support.patch @@ -1,4 +1,4 @@ -From bcc764eca6c92210716d1d6db59bfe112522a95d Mon Sep 17 00:00:00 2001 +From b054d1d29e676600abd6fdd7a67a283c3c011f95 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 25 Sep 2015 17:47:35 -0400 Subject: [PATCH] Add SPAKE preauth support @@ -106,7 +106,7 @@ ticket: 8647 (new) create mode 100644 src/tests/t_spake.py diff --git a/NOTICE b/NOTICE -index 1db2420a7..9dc1148b1 100644 +index 1f2ce6493..cb6ab462b 100644 --- a/NOTICE +++ b/NOTICE @@ -1316,3 +1316,54 @@ The following notice applies to @@ -219,10 +219,10 @@ index 1ac1a37c2..f8cf1be7c 100644 (List of *key*:*salt* strings.) Specifies the default key/salt combinations of principals for this realm. Any principals created diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 4ed9832c7..8cfe5f458 100644 +index 3d33dba40..2574e5c26 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst -@@ -365,6 +365,21 @@ The libdefaults section may contain any of the following relations: +@@ -367,6 +367,21 @@ The libdefaults section may contain any of the following relations: with the session key type. See the **kdc_req_checksum_type** configuration option for the possible values and their meanings. @@ -354,7 +354,7 @@ index 640955c90..e32365daa 100644 +For other cookies, there must be exactly one second-factor record +corresponding to the factor type chosen by the client. diff --git a/doc/notice.rst b/doc/notice.rst -index 26011550b..cacfd659a 100644 +index a32e55529..8f6b68638 100644 --- a/doc/notice.rst +++ b/doc/notice.rst @@ -1237,3 +1237,50 @@ The following notice applies to diff --git a/Add-doc-index-entries-for-SPAKE-constants.patch b/Add-doc-index-entries-for-SPAKE-constants.patch index e5de247..fa8e7ab 100644 --- a/Add-doc-index-entries-for-SPAKE-constants.patch +++ b/Add-doc-index-entries-for-SPAKE-constants.patch @@ -1,4 +1,4 @@ -From 6410daacd3b14ca1b96889f3db5ea9c94bf58734 Mon Sep 17 00:00:00 2001 +From 0ff94a373749e83fb9c2c5c6fa6d5788b2b63460 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 27 Mar 2018 00:49:43 -0400 Subject: [PATCH] Add doc index entries for SPAKE constants diff --git a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch index d9b8d94..e1e5b35 100644 --- a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch +++ b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch @@ -1,4 +1,4 @@ -From 87e99d886fe8ea74521e73f8f0a8445353162526 Mon Sep 17 00:00:00 2001 +From f2402ea18c8587dab261cd724ef62fd7f6bcc8ec Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 4 Jan 2018 14:35:12 -0500 Subject: [PATCH] Add k5_buf_add_vfmt to k5buf interface diff --git a/Add-libkrb5support-hex-functions-and-tests.patch b/Add-libkrb5support-hex-functions-and-tests.patch index 7b769ab..097c2af 100644 --- a/Add-libkrb5support-hex-functions-and-tests.patch +++ b/Add-libkrb5support-hex-functions-and-tests.patch @@ -1,4 +1,4 @@ -From 443151a0690d3f11b38db54f650b320cb733535f Mon Sep 17 00:00:00 2001 +From c8992ad9dc0c7fc4d8bec3b9ecb129fe587d615e Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 19 Feb 2018 00:51:44 -0500 Subject: [PATCH] Add libkrb5support hex functions and tests diff --git a/Add-vector-support-to-k5_sha256.patch b/Add-vector-support-to-k5_sha256.patch index 7d8ff80..9d9c792 100644 --- a/Add-vector-support-to-k5_sha256.patch +++ b/Add-vector-support-to-k5_sha256.patch @@ -1,4 +1,4 @@ -From 181d3a9e2d274b49a2830895a59ce1b22be4000a Mon Sep 17 00:00:00 2001 +From 5ed0331bd6bfd39b9c5ca40ec38d536221118998 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 3 Feb 2018 20:53:42 -0500 Subject: [PATCH] Add vector support to k5_sha256() diff --git a/Allow-validation-of-PACs-with-enterprise-names.patch b/Allow-validation-of-PACs-with-enterprise-names.patch deleted file mode 100644 index b8492f5..0000000 --- a/Allow-validation-of-PACs-with-enterprise-names.patch +++ /dev/null @@ -1,49 +0,0 @@ -From 8a2ceda87107973ec10fec532c095cf347ec050c Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Wed, 14 Mar 2018 01:19:17 +0200 -Subject: [PATCH] Allow validation of PACs with enterprise names - -In k5_pac_validate_client(), if we are verifying against an enterprise -principal, parse the PAC_CLIENT_INFO field as an enterprise principal. -This scenario may arise in the response to an S4U2Self request for an -enterprise principal, as the KDC does not appear to canonicalize the -client principal requested in PA-FOR-USER. - -[ghudson@mit.edu: rewrote commit message; adjusted style] - -ticket: 8649 (new) -tags: pullup -target_version: 1.16-next - -(cherry picked from commit f876aab80a69f9b934cd7f4e2339e3815aa8c4bf) ---- - src/lib/krb5/krb/pac.c | 9 +++++++-- - 1 file changed, 7 insertions(+), 2 deletions(-) - -diff --git a/src/lib/krb5/krb/pac.c b/src/lib/krb5/krb/pac.c -index 0eb19e6bb..c9b5de30a 100644 ---- a/src/lib/krb5/krb/pac.c -+++ b/src/lib/krb5/krb/pac.c -@@ -413,6 +413,7 @@ k5_pac_validate_client(krb5_context context, - krb5_ui_2 pac_princname_length; - int64_t pac_nt_authtime; - krb5_principal pac_principal; -+ int flags; - - ret = k5_pac_locate_buffer(context, pac, KRB5_PAC_CLIENT_INFO, - &client_info); -@@ -440,8 +441,12 @@ k5_pac_validate_client(krb5_context context, - if (ret != 0) - return ret; - -- ret = krb5_parse_name_flags(context, pac_princname, -- KRB5_PRINCIPAL_PARSE_NO_REALM, &pac_principal); -+ /* Parse the UTF-8 name as an enterprise principal if we are matching -+ * against one; otherwise parse it as a regular principal with no realm. */ -+ flags = KRB5_PRINCIPAL_PARSE_NO_REALM; -+ if (principal->type == KRB5_NT_ENTERPRISE_PRINCIPAL) -+ flags |= KRB5_PRINCIPAL_PARSE_ENTERPRISE; -+ ret = krb5_parse_name_flags(context, pac_princname, flags, &pac_principal); - if (ret != 0) { - free(pac_princname); - return ret; diff --git a/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch b/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch index 287b3f9..05106ad 100644 --- a/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch +++ b/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch @@ -1,4 +1,4 @@ -From 864f90dcc860997189679b980f52de41ef10a238 Mon Sep 17 00:00:00 2001 +From c98a6fc929b80dd8d221314e31903a9d5ee56295 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 31 Mar 2018 10:43:49 -0400 Subject: [PATCH] Be more careful asking for AS key in SPAKE client diff --git a/Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch b/Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch deleted file mode 100644 index 999a5ba..0000000 --- a/Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch +++ /dev/null @@ -1,42 +0,0 @@ -From 3001200ba4598aeb14511353a72dc746034280b1 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Fabiano=20Fid=C3=AAncio?= -Date: Wed, 28 Mar 2018 18:27:06 +0200 -Subject: [PATCH] Continue after KRB5_CC_END in KCM cache iteration - -The KCM server returns KRB5_CC_END in response to a GET_CACHE_BY_UUID -request to indicate that the specified ccache uuid no longer exists. -In krb5_ptcursor_next(), ignore this error and continue the iteration, -as the Heimdal KCM client code does. - -In addition to addressing the case where a third party deletes a cache -between the GET_CACHE_UUID_LIST request and when we reach that uuid in -the iteration, this change also fixes a bug in kdestroy -A where the -caller deletes the primary cache and we later request it by uuid when -iterating over the list. - -[ghudson@mit.edu: rewrote commit message; edited comment] - -ticket: 8658 (new) -tags: pullup -target_version: 1.16-next -target_version: 1.15-next - -(cherry picked from commit 49087f5e6309f298f8898c35af6f4ade418ced60) ---- - src/lib/krb5/ccache/cc_kcm.c | 3 +++ - 1 file changed, 3 insertions(+) - -diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c -index b621ed33b..0d38b1839 100644 ---- a/src/lib/krb5/ccache/cc_kcm.c -+++ b/src/lib/krb5/ccache/cc_kcm.c -@@ -966,6 +966,9 @@ kcm_ptcursor_next(krb5_context context, krb5_cc_ptcursor cursor, - kcmreq_init(&req, KCM_OP_GET_CACHE_BY_UUID, NULL); - k5_buf_add_len(&req.reqbuf, id, KCM_UUID_LEN); - ret = kcmio_call(context, data->io, &req); -+ /* Continue if the cache has been deleted. */ -+ if (ret == KRB5_CC_END) -+ continue; - if (ret) - goto cleanup; - ret = kcmreq_get_name(&req, &name); diff --git a/Exit-with-status-0-from-kadmind.patch b/Exit-with-status-0-from-kadmind.patch index 30b7201..93a1a18 100644 --- a/Exit-with-status-0-from-kadmind.patch +++ b/Exit-with-status-0-from-kadmind.patch @@ -1,4 +1,4 @@ -From a4576a5946d84e1a74093c4fc171a7fcb1f7ef59 Mon Sep 17 00:00:00 2001 +From cb8f31e6bbf72e207b428d52c2fd9ed719bbec4f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 14 Mar 2018 14:31:22 -0400 Subject: [PATCH] Exit with status 0 from kadmind @@ -19,10 +19,10 @@ code, which used a similar event model for signals. 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/kadmin/server/ovsec_kadmd.c b/src/kadmin/server/ovsec_kadmd.c -index 6c875901a..936955b89 100644 +index aac4d4ffd..0a28b2384 100644 --- a/src/kadmin/server/ovsec_kadmd.c +++ b/src/kadmin/server/ovsec_kadmd.c -@@ -560,5 +560,5 @@ main(int argc, char *argv[]) +@@ -559,5 +559,5 @@ main(int argc, char *argv[]) krb5_klog_close(context); krb5_free_context(context); diff --git a/Fix-KDC-null-dereference-on-large-TGS-replies.patch b/Fix-KDC-null-dereference-on-large-TGS-replies.patch deleted file mode 100644 index d0fc333..0000000 --- a/Fix-KDC-null-dereference-on-large-TGS-replies.patch +++ /dev/null @@ -1,224 +0,0 @@ -From d3697aa9a653bc9aaf11f3c9e985ba544c23a9c3 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 20 Apr 2018 16:16:02 -0400 -Subject: [PATCH] Fix KDC null dereference on large TGS replies - -For TGS requests, dispatch() doesn't set state->active_realm, which -leads to a NULL dereference in finish_dispatch() if the reply is too -big for UDP. Prior to commit 0a2f14f752c32a24200363cc6b6ae64a92f81379 -the active realm was a global and was set when process_tgs_req() -called setup_server_realm(). - -Move TGS decoding out of process_tgs_req() so that we can set -state->active_realm before any errors requiring response. Add a test -case. - -[ghudson@mit.edu: edited commit message; added test case; reduced code -duplication; removed server handle from process_tgs_req() parameters] - -ticket: 8666 -tags: pullup -target_version: 1.16-next -target_version: 1.15-next - -(cherry picked from commit 6afa8b4abf8f7c5774d03e6b15ee7288ad68d725) ---- - src/kdc/Makefile.in | 1 + - src/kdc/dispatch.c | 50 ++++++++++++++++++++++++------------------- - src/kdc/do_tgs_req.c | 24 ++++++--------------- - src/kdc/kdc_util.h | 5 ++--- - src/kdc/t_bigreply.py | 19 ++++++++++++++++ - 5 files changed, 56 insertions(+), 43 deletions(-) - create mode 100644 src/kdc/t_bigreply.py - -diff --git a/src/kdc/Makefile.in b/src/kdc/Makefile.in -index 61a3dbc6f..117a8f561 100644 ---- a/src/kdc/Makefile.in -+++ b/src/kdc/Makefile.in -@@ -85,6 +85,7 @@ check-cmocka: t_replay - check-pytests: - $(RUNPYTEST) $(srcdir)/t_workers.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_emptytgt.py $(PYTESTFLAGS) -+ $(RUNPYTEST) $(srcdir)/t_bigreply.py $(PYTESTFLAGS) - - install: - $(INSTALL_PROGRAM) krb5kdc ${DESTDIR}$(SERVER_BINDIR)/krb5kdc -diff --git a/src/kdc/dispatch.c b/src/kdc/dispatch.c -index 3867ff952..3ed5176a8 100644 ---- a/src/kdc/dispatch.c -+++ b/src/kdc/dispatch.c -@@ -124,7 +124,7 @@ dispatch(void *cb, const krb5_fulladdr *local_addr, - verto_ctx *vctx, loop_respond_fn respond, void *arg) - { - krb5_error_code retval; -- krb5_kdc_req *as_req; -+ krb5_kdc_req *req = NULL; - krb5_data *response = NULL; - struct dispatch_state *state; - struct server_handle *handle = cb; -@@ -176,29 +176,35 @@ dispatch(void *cb, const krb5_fulladdr *local_addr, - - /* try TGS_REQ first; they are more common! */ - -- if (krb5_is_tgs_req(pkt)) { -- retval = process_tgs_req(handle, pkt, remote_addr, &response); -- } else if (krb5_is_as_req(pkt)) { -- if (!(retval = decode_krb5_as_req(pkt, &as_req))) { -- /* -- * setup_server_realm() sets up the global realm-specific data -- * pointer. -- * process_as_req frees the request if it is called -- */ -- state->active_realm = setup_server_realm(handle, as_req->server); -- if (state->active_realm != NULL) { -- process_as_req(as_req, pkt, local_addr, remote_addr, -- state->active_realm, vctx, -- finish_dispatch_cache, state); -- return; -- } else { -- retval = KRB5KDC_ERR_WRONG_REALM; -- krb5_free_kdc_req(kdc_err_context, as_req); -- } -- } -- } else -+ if (krb5_is_tgs_req(pkt)) -+ retval = decode_krb5_tgs_req(pkt, &req); -+ else if (krb5_is_as_req(pkt)) -+ retval = decode_krb5_as_req(pkt, &req); -+ else - retval = KRB5KRB_AP_ERR_MSG_TYPE; -+ if (retval) -+ goto done; - -+ state->active_realm = setup_server_realm(handle, req->server); -+ if (state->active_realm == NULL) { -+ retval = KRB5KDC_ERR_WRONG_REALM; -+ goto done; -+ } -+ -+ if (krb5_is_tgs_req(pkt)) { -+ /* process_tgs_req frees the request */ -+ retval = process_tgs_req(req, pkt, remote_addr, state->active_realm, -+ &response); -+ req = NULL; -+ } else if (krb5_is_as_req(pkt)) { -+ /* process_as_req frees the request and calls finish_dispatch_cache. */ -+ process_as_req(req, pkt, local_addr, remote_addr, state->active_realm, -+ vctx, finish_dispatch_cache, state); -+ return; -+ } -+ -+done: -+ krb5_free_kdc_req(kdc_err_context, req); - finish_dispatch_cache(state, retval, response); - } - -diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c -index cc5a69236..61051bafa 100644 ---- a/src/kdc/do_tgs_req.c -+++ b/src/kdc/do_tgs_req.c -@@ -98,12 +98,12 @@ search_sprinc(kdc_realm_t *, krb5_kdc_req *, krb5_flags, - - /*ARGSUSED*/ - krb5_error_code --process_tgs_req(struct server_handle *handle, krb5_data *pkt, -- const krb5_fulladdr *from, krb5_data **response) -+process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, -+ const krb5_fulladdr *from, kdc_realm_t *kdc_active_realm, -+ krb5_data **response) - { - krb5_keyblock * subkey = 0; - krb5_keyblock *header_key = NULL; -- krb5_kdc_req *request = 0; - krb5_db_entry *server = NULL; - krb5_db_entry *stkt_server = NULL; - krb5_kdc_rep reply; -@@ -136,7 +136,6 @@ process_tgs_req(struct server_handle *handle, krb5_data *pkt, - krb5_pa_data *pa_tgs_req; /*points into request*/ - krb5_data scratch; - krb5_pa_data **e_data = NULL; -- kdc_realm_t *kdc_active_realm = NULL; - krb5_audit_state *au_state = NULL; - krb5_data **auth_indicators = NULL; - -@@ -146,36 +145,25 @@ process_tgs_req(struct server_handle *handle, krb5_data *pkt, - memset(&enc_tkt_reply, 0, sizeof(enc_tkt_reply)); - session_key.contents = NULL; - -- retval = decode_krb5_tgs_req(pkt, &request); -- if (retval) -- return retval; - /* Save pointer to client-requested service principal, in case of - * errors before a successful call to search_sprinc(). */ - sprinc = request->server; - - if (request->msg_type != KRB5_TGS_REQ) { -- krb5_free_kdc_req(handle->kdc_err_context, request); -+ krb5_free_kdc_req(kdc_context, request); - return KRB5_BADMSGTYPE; - } - -- /* -- * setup_server_realm() sets up the global realm-specific data pointer. -- */ -- kdc_active_realm = setup_server_realm(handle, request->server); -- if (kdc_active_realm == NULL) { -- krb5_free_kdc_req(handle->kdc_err_context, request); -- return KRB5KDC_ERR_WRONG_REALM; -- } - errcode = kdc_make_rstate(kdc_active_realm, &state); - if (errcode !=0) { -- krb5_free_kdc_req(handle->kdc_err_context, request); -+ krb5_free_kdc_req(kdc_context, request); - return errcode; - } - - /* Initialize audit state. */ - errcode = kau_init_kdc_req(kdc_context, request, from, &au_state); - if (errcode) { -- krb5_free_kdc_req(handle->kdc_err_context, request); -+ krb5_free_kdc_req(kdc_context, request); - return errcode; - } - /* Seed the audit trail with the request ID and basic information. */ -diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index a63af2503..1885c9f80 100644 ---- a/src/kdc/kdc_util.h -+++ b/src/kdc/kdc_util.h -@@ -145,9 +145,8 @@ process_as_req (krb5_kdc_req *, krb5_data *, - - /* do_tgs_req.c */ - krb5_error_code --process_tgs_req (struct server_handle *, krb5_data *, -- const krb5_fulladdr *, -- krb5_data ** ); -+process_tgs_req (krb5_kdc_req *, krb5_data *, const krb5_fulladdr *, -+ kdc_realm_t *, krb5_data ** ); - /* dispatch.c */ - void - dispatch (void *, -diff --git a/src/kdc/t_bigreply.py b/src/kdc/t_bigreply.py -new file mode 100644 -index 000000000..6bc9a8fe0 ---- /dev/null -+++ b/src/kdc/t_bigreply.py -@@ -0,0 +1,19 @@ -+#!/usr/bin/python -+from k5test import * -+ -+# Set the maximum UDP reply size very low, so that all replies go -+# through the RESPONSE_TOO_BIG path. -+kdc_conf = {'kdcdefaults': {'kdc_max_dgram_reply_size': '10'}} -+realm = K5Realm(kdc_conf=kdc_conf, get_creds=False) -+ -+msgs = ('Sending initial UDP request', -+ 'Received answer', -+ 'Request or response is too big for UDP; retrying with TCP', -+ ' to KRBTEST.COM (tcp only)', -+ 'Initiating TCP connection', -+ 'Sending TCP request', -+ 'Terminating TCP connection') -+realm.kinit(realm.user_princ, password('user'), expected_trace=msgs) -+realm.run([kvno, realm.host_princ], expected_trace=msgs) -+ -+success('Large KDC replies') diff --git a/Fix-SPAKE-memory-leak.patch b/Fix-SPAKE-memory-leak.patch index c631a97..9d4011d 100644 --- a/Fix-SPAKE-memory-leak.patch +++ b/Fix-SPAKE-memory-leak.patch @@ -1,4 +1,4 @@ -From 9bfd14df2d6458dfef8d1a17af5247af21183e3d Mon Sep 17 00:00:00 2001 +From 3ea258c813de4c55a8979f019b716422b998e231 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 27 Mar 2018 10:36:05 -0400 Subject: [PATCH] Fix SPAKE memory leak diff --git a/Fix-capaths-.-values-on-client.patch b/Fix-capaths-.-values-on-client.patch deleted file mode 100644 index 49016f2..0000000 --- a/Fix-capaths-.-values-on-client.patch +++ /dev/null @@ -1,60 +0,0 @@ -From 5cdef749204eccf05ae5d7bad455d34899eb33da Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 3 Mar 2018 13:44:00 -0500 -Subject: [PATCH] Fix capaths "." values on client - -Commit b72aef2c1cbcc76f7fba14ddc54a4e66e7a4e66c (ticket 6966) -introduced k5_client_realm_path() for use on the client in place of -krb5_walk_realm_tree(), but failed to handle the special case of a -capaths "." value as is done in the latter function. Correct that -omission and add a test case. - -ticket: 8646 (new) -tags: pullup -target_version: 1.16-next -target_version: 1.15-next - -(cherry picked from commit f8d0877f848563d07152a0ee191fe82846fdb8f1) ---- - src/lib/krb5/krb/walk_rtree.c | 6 ++++++ - src/tests/t_crossrealm.py | 10 ++++++++++ - 2 files changed, 16 insertions(+) - -diff --git a/src/lib/krb5/krb/walk_rtree.c b/src/lib/krb5/krb/walk_rtree.c -index 0566a55f1..f4e8e35f5 100644 ---- a/src/lib/krb5/krb/walk_rtree.c -+++ b/src/lib/krb5/krb/walk_rtree.c -@@ -133,6 +133,12 @@ k5_client_realm_path(krb5_context context, const krb5_data *client, - if (retval) - return retval; - -+ /* A capaths value of "." means no intermediates. */ -+ if (capvals != NULL && capvals[0] != NULL && *capvals[0] == '.') { -+ profile_free_list(capvals); -+ capvals = NULL; -+ } -+ - /* Count capaths (if any) and allocate space. Leave room for the client - * realm, server realm, and terminator. */ - for (i = 0; capvals != NULL && capvals[i] != NULL; i++); -diff --git a/src/tests/t_crossrealm.py b/src/tests/t_crossrealm.py -index e7ddb0525..4d595dca6 100755 ---- a/src/tests/t_crossrealm.py -+++ b/src/tests/t_crossrealm.py -@@ -109,6 +109,16 @@ test_kvno(r1, r4.host_princ, 'KDC capaths') - check_klist(r1, (tgt(r1, r1), tgt(r4, r3), r4.host_princ)) - stop(r1, r2, r3, r4) - -+# A capaths value of '.' should enforce direct cross-realm, with no -+# intermediate. -+capaths = {'capaths': {'A.X': {'B.X': '.'}}} -+r1, r2, r3 = cross_realms(3, xtgts=((0,1), (1,2)), -+ args=({'realm': 'A.X', 'krb5_conf': capaths}, -+ {'realm': 'X'}, {'realm': 'B.X'})) -+r1.run([kvno, r3.host_princ], expected_code=1, -+ expected_msg='Server krbtgt/B.X@A.X not found in Kerberos database') -+stop(r1, r2, r3) -+ - # Test transited error. The KDC for C does not recognize B as an - # intermediate realm for A->C, so it refuses to issue a service - # ticket. diff --git a/Fix-flaws-in-LDAP-DN-checking.patch b/Fix-flaws-in-LDAP-DN-checking.patch deleted file mode 100644 index fc3f23c..0000000 --- a/Fix-flaws-in-LDAP-DN-checking.patch +++ /dev/null @@ -1,346 +0,0 @@ -From 27581397cd0d2f213c91bdf20ea9a6736f3e60dc Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 12 Jan 2018 11:43:01 -0500 -Subject: [PATCH] Fix flaws in LDAP DN checking - -KDB_TL_USER_INFO tl-data is intended to be internal to the LDAP KDB -module, and not used in disk or wire principal entries. Prevent -kadmin clients from sending KDB_TL_USER_INFO tl-data by giving it a -type number less than 256 and filtering out type numbers less than 256 -in kadm5_create_principal_3(). (We already filter out low type -numbers in kadm5_modify_principal()). - -In the LDAP KDB module, if containerdn and linkdn are both specified -in a put_principal operation, check both linkdn and the computed -standalone_principal_dn for container membership. To that end, factor -out the checks into helper functions and call them on all applicable -client-influenced DNs. - -CVE-2018-5729: - -In MIT krb5 1.6 or later, an authenticated kadmin user with permission -to add principals to an LDAP Kerberos database can cause a null -dereference in kadmind, or circumvent a DN container check, by -supplying tagged data intended to be internal to the database module. -Thanks to Sharwan Ram and Pooja Anil for discovering the potential -null dereference. - -CVE-2018-5730: - -In MIT krb5 1.6 or later, an authenticated kadmin user with permission -to add principals to an LDAP Kerberos database can circumvent a DN -containership check by supplying both a "linkdn" and "containerdn" -database argument, or by supplying a DN string which is a left -extension of a container DN string but is not hierarchically within -the container DN. - -ticket: 8643 (new) -tags: pullup -target_version: 1.16-next -target_version: 1.15-next - -(cherry picked from commit e1caf6fb74981da62039846931ebdffed71309d1) ---- - src/lib/kadm5/srv/svr_principal.c | 7 + - src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h | 2 +- - .../kdb/ldap/libkdb_ldap/ldap_principal2.c | 200 ++++++++++-------- - src/tests/t_kdb.py | 11 + - 4 files changed, 125 insertions(+), 95 deletions(-) - -diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c -index 2420f2c2b..a59a65e8f 100644 ---- a/src/lib/kadm5/srv/svr_principal.c -+++ b/src/lib/kadm5/srv/svr_principal.c -@@ -330,6 +330,13 @@ kadm5_create_principal_3(void *server_handle, - return KADM5_BAD_MASK; - if((mask & ~ALL_PRINC_MASK)) - return KADM5_BAD_MASK; -+ if (mask & KADM5_TL_DATA) { -+ for (tl_data_tail = entry->tl_data; tl_data_tail != NULL; -+ tl_data_tail = tl_data_tail->tl_data_next) { -+ if (tl_data_tail->tl_data_type < 256) -+ return KADM5_BAD_TL_TYPE; -+ } -+ } - - /* - * Check to see if the principal exists -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h b/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h -index 535a1f309..8b8420faa 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h -+++ b/src/plugins/kdb/ldap/libkdb_ldap/kdb_ldap.h -@@ -141,7 +141,7 @@ extern int set_ldap_error (krb5_context ctx, int st, int op); - #define UNSTORE16_INT(ptr, val) (val = load_16_be(ptr)) - #define UNSTORE32_INT(ptr, val) (val = load_32_be(ptr)) - --#define KDB_TL_USER_INFO 0x7ffe -+#define KDB_TL_USER_INFO 0xff - - #define KDB_TL_PRINCTYPE 0x01 - #define KDB_TL_PRINCCOUNT 0x02 -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -index 88a170495..b7c9212cb 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -@@ -651,6 +651,107 @@ cleanup: - return ret; - } - -+static krb5_error_code -+check_dn_in_container(krb5_context context, const char *dn, -+ char *const *subtrees, unsigned int ntrees) -+{ -+ unsigned int i; -+ size_t dnlen = strlen(dn), stlen; -+ -+ for (i = 0; i < ntrees; i++) { -+ if (subtrees[i] == NULL || *subtrees[i] == '\0') -+ return 0; -+ stlen = strlen(subtrees[i]); -+ if (dnlen >= stlen && -+ strcasecmp(dn + dnlen - stlen, subtrees[i]) == 0 && -+ (dnlen == stlen || dn[dnlen - stlen - 1] == ',')) -+ return 0; -+ } -+ -+ k5_setmsg(context, EINVAL, _("DN is out of the realm subtree")); -+ return EINVAL; -+} -+ -+static krb5_error_code -+check_dn_exists(krb5_context context, -+ krb5_ldap_server_handle *ldap_server_handle, -+ const char *dn, krb5_boolean nonkrb_only) -+{ -+ krb5_error_code st = 0, tempst; -+ krb5_ldap_context *ldap_context = context->dal_handle->db_context; -+ LDAP *ld = ldap_server_handle->ldap_handle; -+ LDAPMessage *result = NULL, *ent; -+ char *attrs[] = { "krbticketpolicyreference", "krbprincipalname", NULL }; -+ char **values; -+ -+ LDAP_SEARCH_1(dn, LDAP_SCOPE_BASE, 0, attrs, IGNORE_STATUS); -+ if (st != LDAP_SUCCESS) -+ return set_ldap_error(context, st, OP_SEARCH); -+ -+ ent = ldap_first_entry(ld, result); -+ CHECK_NULL(ent); -+ -+ values = ldap_get_values(ld, ent, "krbticketpolicyreference"); -+ if (values != NULL) -+ ldap_value_free(values); -+ -+ values = ldap_get_values(ld, ent, "krbprincipalname"); -+ if (values != NULL) { -+ ldap_value_free(values); -+ if (nonkrb_only) { -+ st = EINVAL; -+ k5_setmsg(context, st, _("ldap object is already kerberized")); -+ goto cleanup; -+ } -+ } -+ -+cleanup: -+ ldap_msgfree(result); -+ return st; -+} -+ -+static krb5_error_code -+validate_xargs(krb5_context context, -+ krb5_ldap_server_handle *ldap_server_handle, -+ const xargs_t *xargs, const char *standalone_dn, -+ char *const *subtrees, unsigned int ntrees) -+{ -+ krb5_error_code st; -+ -+ if (xargs->dn != NULL) { -+ /* The supplied dn must be within a realm container. */ -+ st = check_dn_in_container(context, xargs->dn, subtrees, ntrees); -+ if (st) -+ return st; -+ /* The supplied dn must exist without Kerberos attributes. */ -+ st = check_dn_exists(context, ldap_server_handle, xargs->dn, TRUE); -+ if (st) -+ return st; -+ } -+ -+ if (xargs->linkdn != NULL) { -+ /* The supplied linkdn must be within a realm container. */ -+ st = check_dn_in_container(context, xargs->linkdn, subtrees, ntrees); -+ if (st) -+ return st; -+ /* The supplied linkdn must exist. */ -+ st = check_dn_exists(context, ldap_server_handle, xargs->linkdn, -+ FALSE); -+ if (st) -+ return st; -+ } -+ -+ if (xargs->containerdn != NULL && standalone_dn != NULL) { -+ /* standalone_dn (likely composed using containerdn) must be within a -+ * container. */ -+ st = check_dn_in_container(context, standalone_dn, subtrees, ntrees); -+ if (st) -+ return st; -+ } -+ -+ return 0; -+} -+ - krb5_error_code - krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, - char **db_args) -@@ -662,12 +763,12 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, - LDAPMessage *result=NULL, *ent=NULL; - char **subtreelist = NULL; - char *user=NULL, *subtree=NULL, *principal_dn=NULL; -- char **values=NULL, *strval[10]={NULL}, errbuf[1024]; -+ char *strval[10]={NULL}, errbuf[1024]; - char *filtuser=NULL; - struct berval **bersecretkey=NULL; - LDAPMod **mods=NULL; - krb5_boolean create_standalone=FALSE; -- krb5_boolean krb_identity_exists=FALSE, establish_links=FALSE; -+ krb5_boolean establish_links=FALSE; - char *standalone_principal_dn=NULL; - krb5_tl_data *tl_data=NULL; - krb5_key_data **keys=NULL; -@@ -860,24 +961,6 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, - * any of the subtrees - */ - if (xargs.dn_from_kbd == TRUE) { -- /* make sure the DN falls in the subtree */ -- int dnlen=0, subtreelen=0; -- char *dn=NULL; -- krb5_boolean outofsubtree=TRUE; -- -- if (xargs.dn != NULL) { -- dn = xargs.dn; -- } else if (xargs.linkdn != NULL) { -- dn = xargs.linkdn; -- } else if (standalone_principal_dn != NULL) { -- /* -- * Even though the standalone_principal_dn is constructed -- * within this function, there is the containerdn input -- * from the user that can become part of the it. -- */ -- dn = standalone_principal_dn; -- } -- - /* Get the current subtree list if we haven't already done so. */ - if (subtreelist == NULL) { - st = krb5_get_subtree_info(ldap_context, &subtreelist, &ntrees); -@@ -885,81 +968,10 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, - goto cleanup; - } - -- for (tre=0; tre= subtreelen) && (strcasecmp((dn + dnlen - subtreelen), subtreelist[tre]) == 0)) { -- outofsubtree = FALSE; -- break; -- } -- } -- } -- -- if (outofsubtree == TRUE) { -- st = EINVAL; -- k5_setmsg(context, st, _("DN is out of the realm subtree")); -+ st = validate_xargs(context, ldap_server_handle, &xargs, -+ standalone_principal_dn, subtreelist, ntrees); -+ if (st) - goto cleanup; -- } -- -- /* -- * dn value will be set either by dn, linkdn or the standalone_principal_dn -- * In the first 2 cases, the dn should be existing and in the last case we -- * are supposed to create the ldap object. so the below should not be -- * executed for the last case. -- */ -- -- if (standalone_principal_dn == NULL) { -- /* -- * If the ldap object is missing, this results in an error. -- */ -- -- /* -- * Search for krbprincipalname attribute here. -- * This is to find if a kerberos identity is already present -- * on the ldap object, in which case adding a kerberos identity -- * on the ldap object should result in an error. -- */ -- char *attributes[]={"krbticketpolicyreference", "krbprincipalname", NULL}; -- -- ldap_msgfree(result); -- result = NULL; -- LDAP_SEARCH_1(dn, LDAP_SCOPE_BASE, 0, attributes, IGNORE_STATUS); -- if (st == LDAP_SUCCESS) { -- ent = ldap_first_entry(ld, result); -- if (ent != NULL) { -- if ((values=ldap_get_values(ld, ent, "krbticketpolicyreference")) != NULL) { -- ldap_value_free(values); -- } -- -- if ((values=ldap_get_values(ld, ent, "krbprincipalname")) != NULL) { -- krb_identity_exists = TRUE; -- ldap_value_free(values); -- } -- } -- } else { -- st = set_ldap_error(context, st, OP_SEARCH); -- goto cleanup; -- } -- } -- } -- -- /* -- * If xargs.dn is set then the request is to add a -- * kerberos principal on a ldap object, but if -- * there is one already on the ldap object this -- * should result in an error. -- */ -- -- if (xargs.dn != NULL && krb_identity_exists == TRUE) { -- st = EINVAL; -- snprintf(errbuf, sizeof(errbuf), -- _("ldap object is already kerberized")); -- k5_setmsg(context, st, "%s", errbuf); -- goto cleanup; - } - - if (xargs.linkdn != NULL) { -diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py -index 217f2cdc3..6e563b103 100755 ---- a/src/tests/t_kdb.py -+++ b/src/tests/t_kdb.py -@@ -203,6 +203,12 @@ if out != 'KRBTEST.COM\n': - # in the test LDAP server. - realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=krb5', 'princ1'], - expected_code=1, expected_msg='DN is out of the realm subtree') -+# Check that the DN container check is a hierarchy test, not a simple -+# suffix match (CVE-2018-5730). We expect this operation to fail -+# either way (because "xcn" isn't a valid DN tag) but the container -+# check should happen before the DN is parsed. -+realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=xcn=t1,cn=krb5', 'princ1'], -+ expected_code=1, expected_msg='DN is out of the realm subtree') - realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=t2,cn=krb5', 'princ1']) - realm.run([kadminl, 'getprinc', 'princ1'], expected_msg='Principal: princ1') - realm.run([kadminl, 'ank', '-randkey', '-x', 'dn=cn=t2,cn=krb5', 'again'], -@@ -226,6 +232,11 @@ realm.run([kadminl, 'ank', '-randkey', '-x', 'containerdn=cn=t1,cn=krb5', - 'princ3']) - realm.run([kadminl, 'modprinc', '-x', 'containerdn=cn=t2,cn=krb5', 'princ3'], - expected_code=1, expected_msg='containerdn option not supported') -+# Verify that containerdn is checked when linkdn is also supplied -+# (CVE-2018-5730). -+realm.run([kadminl, 'ank', '-randkey', '-x', 'containerdn=cn=krb5', -+ '-x', 'linkdn=cn=t2,cn=krb5', 'princ4'], expected_code=1, -+ expected_msg='DN is out of the realm subtree') - - # Create and modify a ticket policy. - kldaputil(['create_policy', '-maxtktlife', '3hour', '-maxrenewlife', '6hour', diff --git a/Fix-hex-conversion-of-PKINIT-certid-strings.patch b/Fix-hex-conversion-of-PKINIT-certid-strings.patch index bc21999..cc9ff38 100644 --- a/Fix-hex-conversion-of-PKINIT-certid-strings.patch +++ b/Fix-hex-conversion-of-PKINIT-certid-strings.patch @@ -1,4 +1,4 @@ -From 46fada3b8a7ad21adf6831cf86c38a822a38748e Mon Sep 17 00:00:00 2001 +From 6b8f7371e49c3aa636871bb4e2ea2d2e86c743de Mon Sep 17 00:00:00 2001 From: Sumit Bose Date: Fri, 26 Jan 2018 11:47:50 -0500 Subject: [PATCH] Fix hex conversion of PKINIT certid strings @@ -17,10 +17,10 @@ ticket: 8636 1 file changed, 44 insertions(+), 11 deletions(-) diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index ac107c2c1..4f21f90d2 100644 +index 2064eb7bd..eb2953fe1 100644 --- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -4623,6 +4623,43 @@ reassemble_pkcs11_name(pkinit_identity_opts *idopts) +@@ -4616,6 +4616,43 @@ reassemble_pkcs11_name(pkinit_identity_opts *idopts) return ret; } @@ -64,7 +64,7 @@ index ac107c2c1..4f21f90d2 100644 static krb5_error_code pkinit_get_certs_pkcs11(krb5_context context, pkinit_plg_crypto_context plg_cryptoctx, -@@ -4665,18 +4702,14 @@ pkinit_get_certs_pkcs11(krb5_context context, +@@ -4658,18 +4695,14 @@ pkinit_get_certs_pkcs11(krb5_context context, } /* Convert the ascii cert_id string into a binary blob */ if (idopts->cert_id_string != NULL) { diff --git a/Fix-read-overflow-in-KDC-sort_pa_data.patch b/Fix-read-overflow-in-KDC-sort_pa_data.patch index 709eac9..50a3923 100644 --- a/Fix-read-overflow-in-KDC-sort_pa_data.patch +++ b/Fix-read-overflow-in-KDC-sort_pa_data.patch @@ -1,4 +1,4 @@ -From 87cc924b8c127afb617cd110b1fbee57f809cd49 Mon Sep 17 00:00:00 2001 +From 20c25d4a2f78d8ab33d4879e1cf843e1fdb8a20b Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 15 Mar 2018 20:27:30 -0400 Subject: [PATCH] Fix read overflow in KDC sort_pa_data() diff --git a/Fix-securid_sam2-preauth-for-non-default-salt.patch b/Fix-securid_sam2-preauth-for-non-default-salt.patch index 4d6365e..ea4f220 100644 --- a/Fix-securid_sam2-preauth-for-non-default-salt.patch +++ b/Fix-securid_sam2-preauth-for-non-default-salt.patch @@ -1,4 +1,4 @@ -From afe1c26d08f0aead0d4ac49ad06715b1e8be7b6d Mon Sep 17 00:00:00 2001 +From 9c9ff189c16b16f848f2e85c1d262f12c6d5e922 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 3 Jan 2018 12:06:08 -0500 Subject: [PATCH] Fix securid_sam2 preauth for non-default salt diff --git a/Implement-k5_buf_init_dynamic_zap.patch b/Implement-k5_buf_init_dynamic_zap.patch index 94ba25f..530416d 100644 --- a/Implement-k5_buf_init_dynamic_zap.patch +++ b/Implement-k5_buf_init_dynamic_zap.patch @@ -1,4 +1,4 @@ -From 4656f809f0f50c3a0a82192f9436e3292a5fe82a Mon Sep 17 00:00:00 2001 +From e6945eee571b0ff776270dea52fb051b62aedabd Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 26 Mar 2018 11:12:39 -0400 Subject: [PATCH] Implement k5_buf_init_dynamic_zap diff --git a/Include-etype-info-in-for-hardware-preauth-hints.patch b/Include-etype-info-in-for-hardware-preauth-hints.patch index 21eef78..841a9c1 100644 --- a/Include-etype-info-in-for-hardware-preauth-hints.patch +++ b/Include-etype-info-in-for-hardware-preauth-hints.patch @@ -1,4 +1,4 @@ -From be4a469216fb87408484b90be9a1da772ba923df Mon Sep 17 00:00:00 2001 +From 6f883193ddb63da0f29977e3b95a663321404546 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 3 Jan 2018 11:59:14 -0500 Subject: [PATCH] Include etype-info in for hardware preauth hints diff --git a/Include-preauth-name-in-trace-output-if-possible.patch b/Include-preauth-name-in-trace-output-if-possible.patch index e5c024a..7ab27a7 100644 --- a/Include-preauth-name-in-trace-output-if-possible.patch +++ b/Include-preauth-name-in-trace-output-if-possible.patch @@ -1,4 +1,4 @@ -From 44fe6e4df092e3bc7673449ccd7c70b6f0a4ccbf Mon Sep 17 00:00:00 2001 +From 265d00ef6bb5469b2464d7813af8c37581338385 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 15 Mar 2018 14:37:28 -0400 Subject: [PATCH] Include preauth name in trace output if possible @@ -183,7 +183,7 @@ index 779f184cb..10b4f0c14 100644 etype = va_arg(ap, krb5_enctype); if (krb5_enctype_to_name(etype, TRUE, tmpbuf, sizeof(tmpbuf)) == 0) diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index 3030322e1..1ba3536da 100755 +index 5bc60cb1e..0e964c689 100755 --- a/src/tests/t_pkinit.py +++ b/src/tests/t_pkinit.py @@ -164,18 +164,19 @@ realm.stop_kdc() diff --git a/Merge-duplicate-subsections-in-profile-library.patch b/Merge-duplicate-subsections-in-profile-library.patch deleted file mode 100644 index 3507c9e..0000000 --- a/Merge-duplicate-subsections-in-profile-library.patch +++ /dev/null @@ -1,122 +0,0 @@ -From 77ece30d3df5b119a74f7fe9e2c0a4c693194917 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 10 Apr 2018 15:55:41 -0400 -Subject: [PATCH] Merge duplicate subsections in profile library - -Modify profile_add_node() to return the existing node, rather than -making a new one, when adding subsection configuration. - -This fixes an issue where the first instance of a subsection will hide -the second instance entirely. In particular, it was previously -impossible to split realm-specific configuration across multiple -config files. - -[ghudson@mit.edu: adjusted style, added test case] - -ticket: 7863 -tags: pullup -target_version: 1.16-next -target_version: 1.15-next - -(cherry picked from commit efab9fa5a6d23c486467264e20b58bf5a9c60f0c) ---- - src/util/profile/prof_test1 | 22 ++++++++++++++++++++++ - src/util/profile/prof_tree.c | 15 +++++++++++---- - src/util/profile/test.ini | 6 ++++++ - 3 files changed, 39 insertions(+), 4 deletions(-) - -diff --git a/src/util/profile/prof_test1 b/src/util/profile/prof_test1 -index 7e30fc12f..7d13c9389 100644 ---- a/src/util/profile/prof_test1 -+++ b/src/util/profile/prof_test1 -@@ -341,6 +341,27 @@ proc test9 {} { - puts "OK: test9: profile_flush_to_file with no changes" - } - -+proc test10 {} { -+ global wd verbose -+ -+ # Regression test for #7863: multiply-specified subsections should -+ # be merged. -+ set p [profile_init_path $wd/test2.ini] -+ set x [profile_get_values $p {{test section 2} child_section2 child}] -+ if $verbose { puts "Read $x from profile" } -+ if ![string equal $x "slick harry {john\tb } ron"] { -+ puts stderr "Error: test10: Did not get expected merged children." -+ exit 1 -+ } -+ -+ set x [profile_get_string $p {test section 2} child_section2 chores] -+ if $verbose { puts "Read $x from profile" } -+ if ![string equal $x "cleaning"] { -+ puts stderr "Error: test10: Did not find expected chores." -+ exit 1 -+ } -+} -+ - test1 - test2 - test3 -@@ -350,5 +371,6 @@ test6 - test7 - test8 - test9 -+test10 - - exit 0 -diff --git a/src/util/profile/prof_tree.c b/src/util/profile/prof_tree.c -index 081f688e4..38aadc4e5 100644 ---- a/src/util/profile/prof_tree.c -+++ b/src/util/profile/prof_tree.c -@@ -9,7 +9,7 @@ - * - * Each node may represent either a relation or a section header. - * -- * A section header must have its value field set to 0, and may a one -+ * A section header must have its value field be null, and may have one - * or more child nodes, pointed to by first_child. - * - * A relation has as its value a pointer to allocated memory -@@ -159,15 +159,22 @@ errcode_t profile_add_node(struct profile_node *section, const char *name, - return PROF_ADD_NOT_SECTION; - - /* -- * Find the place to insert the new node. We look for the -- * place *after* the last match of the node name, since -+ * Find the place to insert the new node. If we are adding a subsection -+ * and already have a subsection with that name, merge them. Otherwise, -+ * we look for the place *after* the last match of the node name, since - * order matters. - */ - for (p=section->first_child, last = 0; p; last = p, p = p->next) { - int cmp; - cmp = strcmp(p->name, name); -- if (cmp > 0) -+ if (cmp > 0) { - break; -+ } else if (value == NULL && cmp == 0 && -+ p->value == NULL && p->deleted != 1) { -+ /* Found duplicate subsection, so don't make a new one. */ -+ *ret_node = p; -+ return 0; -+ } - } - retval = profile_create_node(name, value, &new); - if (retval) -diff --git a/src/util/profile/test.ini b/src/util/profile/test.ini -index 23ca89677..6622df108 100644 ---- a/src/util/profile/test.ini -+++ b/src/util/profile/test.ini -@@ -10,6 +10,12 @@ this is a comment. Everything up to the first square brace is ignored. - } - child_section2 = foo - -+[test section 2] -+ child_section2 = { -+ child = ron -+ chores = cleaning -+ } -+ - [realms] - ATHENA.MIT.EDU = { - server = KERBEROS.MIT.EDU:88 diff --git a/Move-zap-definition-to-k5-platform.h.patch b/Move-zap-definition-to-k5-platform.h.patch index 9d08931..c499685 100644 --- a/Move-zap-definition-to-k5-platform.h.patch +++ b/Move-zap-definition-to-k5-platform.h.patch @@ -1,4 +1,4 @@ -From b0fb55f284f543e1e3752512df1f581e77d486ca Mon Sep 17 00:00:00 2001 +From 56521276ff20bc05a61c6f070cb4dcab730ff6d6 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 26 Mar 2018 10:54:29 -0400 Subject: [PATCH] Move zap() definition to k5-platform.h diff --git a/Process-included-directories-in-alphabetical-order.patch b/Process-included-directories-in-alphabetical-order.patch index aeeae75..29d3e90 100644 --- a/Process-included-directories-in-alphabetical-order.patch +++ b/Process-included-directories-in-alphabetical-order.patch @@ -1,4 +1,4 @@ -From c7c44bbd80beabe7fb21f5fb6cfb9b57faa320f4 Mon Sep 17 00:00:00 2001 +From 88abb837d8a9ff12b71a848efbeaa9b9a009cc1f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 29 Jan 2018 12:10:53 +0100 Subject: [PATCH] Process included directories in alphabetical order diff --git a/Refactor-KDC-krb5_pa_data-utility-functions.patch b/Refactor-KDC-krb5_pa_data-utility-functions.patch index 0dedd1f..957bf71 100644 --- a/Refactor-KDC-krb5_pa_data-utility-functions.patch +++ b/Refactor-KDC-krb5_pa_data-utility-functions.patch @@ -1,4 +1,4 @@ -From 61e3f0142b09cb230be3a2a110f5224e773f1281 Mon Sep 17 00:00:00 2001 +From 276ecd7ba513ce0bfe5e51d6368e00476041a5b4 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 21 Dec 2017 11:28:52 -0500 Subject: [PATCH] Refactor KDC krb5_pa_data utility functions @@ -373,10 +373,10 @@ index 754570c01..13111215d 100644 } diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index f99efcf50..18649b8ad 100644 +index c57d48f73..198eab9c4 100644 --- a/src/kdc/kdc_util.h +++ b/src/kdc/kdc_util.h -@@ -203,10 +203,10 @@ void +@@ -202,10 +202,10 @@ void free_padata_context(krb5_context context, void *padata_context); krb5_error_code diff --git a/Report-extended-errors-in-kinit-k-t-KDB.patch b/Report-extended-errors-in-kinit-k-t-KDB.patch index feb49b7..c41334e 100644 --- a/Report-extended-errors-in-kinit-k-t-KDB.patch +++ b/Report-extended-errors-in-kinit-k-t-KDB.patch @@ -1,4 +1,4 @@ -From b3b5cf3d57ac2889aeab82a79a6ea967c1412eb6 Mon Sep 17 00:00:00 2001 +From 177cb167cfc151a1f58fb3e771cd29d0598f462f Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 17 Mar 2018 22:47:34 -0400 Subject: [PATCH] Report extended errors in kinit -k -t KDB: diff --git a/Restrict-pre-authentication-fallback-cases.patch b/Restrict-pre-authentication-fallback-cases.patch index f5cf87e..8830d1e 100644 --- a/Restrict-pre-authentication-fallback-cases.patch +++ b/Restrict-pre-authentication-fallback-cases.patch @@ -1,4 +1,4 @@ -From 4a13b97ffba771de4b45b1ed309934cc840569d1 Mon Sep 17 00:00:00 2001 +From 1e423ec03dbd65845a4aeb8999d130d3d6a0cdd7 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 5 Apr 2018 16:23:34 -0400 Subject: [PATCH] Restrict pre-authentication fallback cases diff --git a/Return-UPN-SANs-as-strings.patch b/Return-UPN-SANs-as-strings.patch deleted file mode 100644 index 78a458e..0000000 --- a/Return-UPN-SANs-as-strings.patch +++ /dev/null @@ -1,204 +0,0 @@ -From 06d48c8d04a5efb098b026a1ec1c1609a5491ab0 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 22 Mar 2018 20:07:17 -0400 -Subject: [PATCH] Return UPN SANs as strings - -(cherry picked from commit fd3c824e3be56a1fa77d140fd7e93934bfd6e565) ---- - src/plugins/preauth/pkinit/pkinit_crypto.h | 4 +-- - .../preauth/pkinit/pkinit_crypto_openssl.c | 28 +++++++------------ - src/plugins/preauth/pkinit/pkinit_matching.c | 16 ++--------- - src/plugins/preauth/pkinit/pkinit_srv.c | 21 +++++++++----- - 4 files changed, 29 insertions(+), 40 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h -index c7ff29fb2..4e4752ff7 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto.h -+++ b/src/plugins/preauth/pkinit/pkinit_crypto.h -@@ -98,7 +98,7 @@ typedef struct _pkinit_cert_matching_data { - unsigned int ku_bits; /* key usage information */ - unsigned int eku_bits; /* extended key usage information */ - krb5_principal *sans; /* Null-terminated array of PKINIT SANs */ -- krb5_principal *upns; /* Null-terimnated array of UPN SANs */ -+ char **upns; /* Null-terimnated array of UPN SANs */ - } pkinit_cert_matching_data; - - /* -@@ -250,7 +250,7 @@ krb5_error_code crypto_retrieve_cert_sans - if non-NULL, a null-terminated array of - id-pkinit-san values found in the certificate - are returned */ -- krb5_principal **upn_sans, /* OUT -+ char ***upn_sans, /* OUT - if non-NULL, a null-terminated array of - id-ms-upn-san values found in the certificate - are returned */ -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index bc6de7ae8..b5a549c2c 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -29,6 +29,7 @@ - * SUCH DAMAGES. - */ - -+#include "k5-int.h" - #include "pkinit_crypto_openssl.h" - #include "k5-buf.h" - #include -@@ -2083,15 +2084,14 @@ crypto_retrieve_X509_sans(krb5_context context, - pkinit_plg_crypto_context plgctx, - pkinit_req_crypto_context reqctx, - X509 *cert, -- krb5_principal **princs_ret, -- krb5_principal **upn_ret, -+ krb5_principal **princs_ret, char ***upn_ret, - unsigned char ***dns_ret) - { - krb5_error_code retval = EINVAL; - char buf[DN_BUF_LEN]; - int p = 0, u = 0, d = 0, ret = 0, l; - krb5_principal *princs = NULL; -- krb5_principal *upns = NULL; -+ char **upns = NULL; - unsigned char **dnss = NULL; - unsigned int i, num_found = 0, num_sans = 0; - X509_EXTENSION *ext = NULL; -@@ -2141,7 +2141,7 @@ crypto_retrieve_X509_sans(krb5_context context, - } - } - if (upn_ret != NULL) { -- upns = calloc(num_sans + 1, sizeof(krb5_principal)); -+ upns = calloc(num_sans + 1, sizeof(*upns)); - if (upns == NULL) { - retval = ENOMEM; - goto cleanup; -@@ -2184,16 +2184,9 @@ crypto_retrieve_X509_sans(krb5_context context, - /* Prevent abuse of embedded null characters. */ - if (memchr(name.data, '\0', name.length)) - break; -- ret = krb5_parse_name_flags(context, name.data, -- KRB5_PRINCIPAL_PARSE_ENTERPRISE, -- &upns[u]); -- if (ret) { -- pkiDebug("%s: failed parsing ms-upn san value\n", -- __FUNCTION__); -- } else { -- u++; -- num_found++; -- } -+ upns[u] = k5memdup0(name.data, name.length, &ret); -+ if (upns[u] == NULL) -+ goto cleanup; - } else { - pkiDebug("%s: unrecognized othername oid in SAN\n", - __FUNCTION__); -@@ -2245,7 +2238,7 @@ cleanup: - krb5_free_principal(context, princs[i]); - free(princs); - for (i = 0; upns != NULL && upns[i] != NULL; i++) -- krb5_free_principal(context, upns[i]); -+ free(upns[i]); - free(upns); - for (i = 0; dnss != NULL && dnss[i] != NULL; i++) - free(dnss[i]); -@@ -2269,8 +2262,7 @@ crypto_retrieve_cert_sans(krb5_context context, - pkinit_plg_crypto_context plgctx, - pkinit_req_crypto_context reqctx, - pkinit_identity_crypto_context idctx, -- krb5_principal **princs_ret, -- krb5_principal **upn_ret, -+ krb5_principal **princs_ret, char ***upn_ret, - unsigned char ***dns_ret) - { - krb5_error_code retval = EINVAL; -@@ -5094,7 +5086,7 @@ crypto_cert_free_matching_data(krb5_context context, - krb5_free_principal(context, md->sans[i]); - free(md->sans); - for (i = 0; md->upns != NULL && md->upns[i] != NULL; i++) -- krb5_free_principal(context, md->upns[i]); -+ free(md->upns[i]); - free(md->upns); - free(md); - } -diff --git a/src/plugins/preauth/pkinit/pkinit_matching.c b/src/plugins/preauth/pkinit/pkinit_matching.c -index 37bd0251a..c2a4c084d 100644 ---- a/src/plugins/preauth/pkinit/pkinit_matching.c -+++ b/src/plugins/preauth/pkinit/pkinit_matching.c -@@ -490,11 +490,7 @@ component_match(krb5_context context, - break; - } - for (i = 0; md->upns != NULL && md->upns[i] != NULL; i++) { -- krb5_unparse_name_flags(context, md->upns[i], -- KRB5_PRINCIPAL_UNPARSE_NO_REALM, -- &princ_string); -- match = regexp_match(context, rc, princ_string); -- krb5_free_unparsed_name(context, princ_string); -+ match = regexp_match(context, rc, md->upns[i]); - if (match) - break; - } -@@ -584,14 +580,8 @@ check_all_certs(krb5_context context, - pkiDebug("%s: PKINIT san: '%s'\n", __FUNCTION__, san_string); - krb5_free_unparsed_name(context, san_string); - } -- for (j = 0; md->upns != NULL && md->upns[j] != NULL; j++) { -- char *san_string; -- krb5_unparse_name_flags(context, md->upns[j], -- KRB5_PRINCIPAL_UNPARSE_NO_REALM, -- &san_string); -- pkiDebug("%s: UPN san: '%s'\n", __FUNCTION__, san_string); -- krb5_free_unparsed_name(context, san_string); -- } -+ for (j = 0; md->upns != NULL && md->upns[j] != NULL; j++) -+ pkiDebug("%s: UPN san: '%s'\n", __FUNCTION__, md->upns[j]); - #endif - certs_checked++; - for (rc = rs->crs; rc != NULL; rc = rc->next) { -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index bbfde34b2..3cc573813 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -178,8 +178,9 @@ verify_client_san(krb5_context context, - int *valid_san) - { - krb5_error_code retval; -- krb5_principal *princs = NULL; -- krb5_principal *upns = NULL; -+ krb5_principal *princs = NULL, upn; -+ krb5_boolean match; -+ char **upns = NULL; - int i; - #ifdef DEBUG_SAN_INFO - char *client_string = NULL, *san_string; -@@ -255,12 +256,18 @@ verify_client_san(krb5_context context, - pkiDebug("%s: Checking upn sans\n", __FUNCTION__); - for (i = 0; upns[i] != NULL; i++) { - #ifdef DEBUG_SAN_INFO -- krb5_unparse_name(context, upns[i], &san_string); - pkiDebug("%s: Comparing client '%s' to upn san value '%s'\n", -- __FUNCTION__, client_string, san_string); -- krb5_free_unparsed_name(context, san_string); -+ __FUNCTION__, client_string, upns[i]); - #endif -- if (cb->match_client(context, rock, upns[i])) { -+ retval = krb5_parse_name_flags(context, upns[i], -+ KRB5_PRINCIPAL_PARSE_ENTERPRISE, &upn); -+ if (retval) { -+ /* XXX trace */ -+ continue; -+ } -+ match = cb->match_client(context, rock, upn); -+ krb5_free_principal(context, upn); -+ if (match) { - TRACE_PKINIT_SERVER_MATCHING_UPN_FOUND(context); - *valid_san = 1; - retval = 0; -@@ -286,7 +293,7 @@ out: - } - if (upns != NULL) { - for (i = 0; upns[i] != NULL; i++) -- krb5_free_principal(context, upns[i]); -+ free(upns[i]); - free(upns); - } - #ifdef DEBUG_SAN_INFO diff --git a/Save-SANs-separately-and-unparse-them-with-NO_REALM.patch b/Save-SANs-separately-and-unparse-them-with-NO_REALM.patch deleted file mode 100644 index 9375e07..0000000 --- a/Save-SANs-separately-and-unparse-them-with-NO_REALM.patch +++ /dev/null @@ -1,148 +0,0 @@ -From 8924d4bbbf82a29f1d6bf524a416d6e44b694734 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 22 Mar 2018 19:46:22 -0400 -Subject: [PATCH] Save SANs separately and unparse them with NO_REALM - -(cherry picked from commit 23ea8d6a9617d17ae5a529c23174d77adac39055) ---- - src/plugins/preauth/pkinit/pkinit_crypto.h | 4 +- - .../preauth/pkinit/pkinit_crypto_openssl.c | 37 ++----------------- - src/plugins/preauth/pkinit/pkinit_matching.c | 30 +++++++++++---- - 3 files changed, 28 insertions(+), 43 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h -index 2d3733bbc..c7ff29fb2 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto.h -+++ b/src/plugins/preauth/pkinit/pkinit_crypto.h -@@ -97,8 +97,8 @@ typedef struct _pkinit_cert_matching_data { - char *issuer_dn; /* rfc2253-style issuer name string */ - unsigned int ku_bits; /* key usage information */ - unsigned int eku_bits; /* extended key usage information */ -- krb5_principal *sans; /* Null-terminated array of subject alternative -- name info (pkinit and ms-upn) */ -+ krb5_principal *sans; /* Null-terminated array of PKINIT SANs */ -+ krb5_principal *upns; /* Null-terimnated array of UPN SANs */ - } pkinit_cert_matching_data; - - /* -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 4f21f90d2..bc6de7ae8 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -5093,6 +5093,9 @@ crypto_cert_free_matching_data(krb5_context context, - for (i = 0; md->sans != NULL && md->sans[i] != NULL; i++) - krb5_free_principal(context, md->sans[i]); - free(md->sans); -+ for (i = 0; md->upns != NULL && md->upns[i] != NULL; i++) -+ krb5_free_principal(context, md->upns[i]); -+ free(md->upns); - free(md); - } - -@@ -5121,8 +5124,6 @@ get_matching_data(krb5_context context, - { - krb5_error_code ret = ENOMEM; - pkinit_cert_matching_data *md = NULL; -- krb5_principal *pkinit_sans = NULL, *upn_sans = NULL; -- size_t i, j; - - *md_out = NULL; - -@@ -5139,40 +5140,10 @@ get_matching_data(krb5_context context, - - /* Get the SAN data. */ - ret = crypto_retrieve_X509_sans(context, plg_cryptoctx, req_cryptoctx, -- cert, &pkinit_sans, &upn_sans, NULL); -+ cert, &md->sans, &md->upns, NULL); - if (ret) - goto cleanup; - -- j = 0; -- if (pkinit_sans != NULL) { -- for (i = 0; pkinit_sans[i] != NULL; i++) -- j++; -- } -- if (upn_sans != NULL) { -- for (i = 0; upn_sans[i] != NULL; i++) -- j++; -- } -- if (j != 0) { -- md->sans = calloc((size_t)j+1, sizeof(*md->sans)); -- if (md->sans == NULL) { -- ret = ENOMEM; -- goto cleanup; -- } -- j = 0; -- if (pkinit_sans != NULL) { -- for (i = 0; pkinit_sans[i] != NULL; i++) -- md->sans[j++] = pkinit_sans[i]; -- free(pkinit_sans); -- } -- if (upn_sans != NULL) { -- for (i = 0; upn_sans[i] != NULL; i++) -- md->sans[j++] = upn_sans[i]; -- free(upn_sans); -- } -- md->sans[j] = NULL; -- } else -- md->sans = NULL; -- - /* Get the KU and EKU data. */ - ret = crypto_retrieve_X509_key_usage(context, plg_cryptoctx, - req_cryptoctx, cert, &md->ku_bits, -diff --git a/src/plugins/preauth/pkinit/pkinit_matching.c b/src/plugins/preauth/pkinit/pkinit_matching.c -index c1ce84b82..37bd0251a 100644 ---- a/src/plugins/preauth/pkinit/pkinit_matching.c -+++ b/src/plugins/preauth/pkinit/pkinit_matching.c -@@ -470,7 +470,6 @@ component_match(krb5_context context, - { - int match = 0; - int i; -- krb5_principal p; - char *princ_string; - - switch (rc->kwval_type) { -@@ -483,10 +482,17 @@ component_match(krb5_context context, - match = regexp_match(context, rc, md->issuer_dn); - break; - case kw_san: -- if (md->sans == NULL) -- break; -- for (i = 0, p = md->sans[i]; p != NULL; p = md->sans[++i]) { -- krb5_unparse_name(context, p, &princ_string); -+ for (i = 0; md->sans != NULL && md->sans[i] != NULL; i++) { -+ krb5_unparse_name(context, md->sans[i], &princ_string); -+ match = regexp_match(context, rc, princ_string); -+ krb5_free_unparsed_name(context, princ_string); -+ if (match) -+ break; -+ } -+ for (i = 0; md->upns != NULL && md->upns[i] != NULL; i++) { -+ krb5_unparse_name_flags(context, md->upns[i], -+ KRB5_PRINCIPAL_UNPARSE_NO_REALM, -+ &princ_string); - match = regexp_match(context, rc, princ_string); - krb5_free_unparsed_name(context, princ_string); - if (match) -@@ -572,10 +578,18 @@ check_all_certs(krb5_context context, - pkiDebug("%s: subject: '%s'\n", __FUNCTION__, md->subject_dn); - #if 0 - pkiDebug("%s: issuer: '%s'\n", __FUNCTION__, md->subject_dn); -- for (j = 0, p = md->sans[j]; p != NULL; p = md->sans[++j]) { -+ for (j = 0; md->sans != NULL && md->sans[j] != NULL; j++) { - char *san_string; -- krb5_unparse_name(context, p, &san_string); -- pkiDebug("%s: san: '%s'\n", __FUNCTION__, san_string); -+ krb5_unparse_name(context, md->sans[j], &san_string); -+ pkiDebug("%s: PKINIT san: '%s'\n", __FUNCTION__, san_string); -+ krb5_free_unparsed_name(context, san_string); -+ } -+ for (j = 0; md->upns != NULL && md->upns[j] != NULL; j++) { -+ char *san_string; -+ krb5_unparse_name_flags(context, md->upns[j], -+ KRB5_PRINCIPAL_UNPARSE_NO_REALM, -+ &san_string); -+ pkiDebug("%s: UPN san: '%s'\n", __FUNCTION__, san_string); - krb5_free_unparsed_name(context, san_string); - } - #endif diff --git a/Set-error-message-on-KCM-get_princ-failure.patch b/Set-error-message-on-KCM-get_princ-failure.patch deleted file mode 100644 index 20cc5ba..0000000 --- a/Set-error-message-on-KCM-get_princ-failure.patch +++ /dev/null @@ -1,42 +0,0 @@ -From f9c9d683852eb4881e099b3042d4c6e5e1444efc Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 27 Apr 2018 13:51:39 -0400 -Subject: [PATCH] Set error message on KCM get_princ failure - -This matches the expected behavior from other ccache types. Most -notably, the KEYRING equivalent was added in -c25fc42e8eac7350209df61e4a7b9960d17755ca - -ticket: 8675 (new) -tags: pullup -target_version: 1.16-next -target_version: 1.15-next - -(cherry picked from commit 58f60f3df7a625ccdcce23dfadd52dc335fd8da7) ---- - src/lib/krb5/ccache/cc_kcm.c | 6 ++++++ - 1 file changed, 6 insertions(+) - -diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c -index 0d38b1839..a777f2710 100644 ---- a/src/lib/krb5/ccache/cc_kcm.c -+++ b/src/lib/krb5/ccache/cc_kcm.c -@@ -721,12 +721,18 @@ kcm_get_princ(krb5_context context, krb5_ccache cache, - { - krb5_error_code ret; - struct kcmreq req; -+ struct kcm_cache_data *data = cache->data; - - kcmreq_init(&req, KCM_OP_GET_PRINCIPAL, cache); - ret = cache_call(context, cache, &req, FALSE); - /* Heimdal KCM can respond with code 0 and no principal. */ - if (!ret && req.reply.len == 0) - ret = KRB5_FCC_NOFILE; -+ if (ret == KRB5_FCC_NOFILE) { -+ k5_setmsg(context, ret, _("Credentials cache 'KCM:%s' not found"), -+ data->residual); -+ } -+ - if (!ret) - ret = k5_unmarshal_princ(req.reply.ptr, req.reply.len, 4, princ_out); - kcmreq_free(&req); diff --git a/Simplify-kdc_preauth.c-systems-table.patch b/Simplify-kdc_preauth.c-systems-table.patch index a8d1ded..6716ca3 100644 --- a/Simplify-kdc_preauth.c-systems-table.patch +++ b/Simplify-kdc_preauth.c-systems-table.patch @@ -1,4 +1,4 @@ -From 0afb9c336dd8573faa025915fcb97e643cc3e748 Mon Sep 17 00:00:00 2001 +From bd2f01d99b623be070c8bc8d660ca92c337147ae Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 11 Feb 2018 15:23:35 -0500 Subject: [PATCH] Simplify kdc_preauth.c systems table diff --git a/Use-k5_buf_init_dynamic_zap-where-appropriate.patch b/Use-k5_buf_init_dynamic_zap-where-appropriate.patch index 2dd6ead..e2baf07 100644 --- a/Use-k5_buf_init_dynamic_zap-where-appropriate.patch +++ b/Use-k5_buf_init_dynamic_zap-where-appropriate.patch @@ -1,4 +1,4 @@ -From 678c67ef21578fb269f2efc56ff46bbd0e6b482b Mon Sep 17 00:00:00 2001 +From 0c2324e3f88f5ba3dbe7c9053017549f13e1f995 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 26 Mar 2018 11:24:49 -0400 Subject: [PATCH] Use k5_buf_init_dynamic_zap where appropriate diff --git a/Use-libkrb5support-hex-functions-where-appropriate.patch b/Use-libkrb5support-hex-functions-where-appropriate.patch index 0e3e26b..f22d05b 100644 --- a/Use-libkrb5support-hex-functions-where-appropriate.patch +++ b/Use-libkrb5support-hex-functions-where-appropriate.patch @@ -1,4 +1,4 @@ -From 4a33689d89144f9e473e8192241dcd2473c78bd7 Mon Sep 17 00:00:00 2001 +From c7677e91fb406c7ec55cb115155ed0d4c5943b72 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 19 Feb 2018 00:52:35 -0500 Subject: [PATCH] Use libkrb5support hex functions where appropriate diff --git a/Zap-data-when-freeing-krb5_spake_factor.patch b/Zap-data-when-freeing-krb5_spake_factor.patch index 18192c9..31795b9 100644 --- a/Zap-data-when-freeing-krb5_spake_factor.patch +++ b/Zap-data-when-freeing-krb5_spake_factor.patch @@ -1,4 +1,4 @@ -From 19ed715d39bdf8415f69156d6cef19225cf6355a Mon Sep 17 00:00:00 2001 +From 6f02200464dd484641639f2cb38b775d34af4bcd Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 27 Mar 2018 15:42:28 -0400 Subject: [PATCH] Zap data when freeing krb5_spake_factor diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch index 134ce84..ddd3ec2 100644 --- a/krb5-1.11-kpasswdtest.patch +++ b/krb5-1.11-kpasswdtest.patch @@ -1,4 +1,4 @@ -From 5d7ff3b42a2f1a4f5f15ac7f2b8fff743c3f33fc Mon Sep 17 00:00:00 2001 +From fc2953ce9ce06ff896b1687e1c0cc9b8a4357d09 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:52:01 -0400 Subject: [PATCH] krb5-1.11-kpasswdtest.patch diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch index 8a767c9..febb3b3 100644 --- a/krb5-1.11-run_user_0.patch +++ b/krb5-1.11-run_user_0.patch @@ -1,4 +1,4 @@ -From d29ad5a58999cb952cdb8ae876fe8b195a11a3e1 Mon Sep 17 00:00:00 2001 +From b0adf9a65d5c22a77cf957ceb1c298baff01555d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:57 -0400 Subject: [PATCH] krb5-1.11-run_user_0.patch diff --git a/krb5-1.12-api.patch b/krb5-1.12-api.patch index 64e9875..9eba2ff 100644 --- a/krb5-1.12-api.patch +++ b/krb5-1.12-api.patch @@ -1,4 +1,4 @@ -From d2297aa0ca6006dae654f0f2a24ac8f7ead737f6 Mon Sep 17 00:00:00 2001 +From abb19d2d2eac5f9f6e4a1bf26f59f3a62143dab9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:00 -0400 Subject: [PATCH] krb5-1.12-api.patch diff --git a/krb5-1.12-ksu-path.patch b/krb5-1.12-ksu-path.patch index 7b03aeb..19b9e73 100644 --- a/krb5-1.12-ksu-path.patch +++ b/krb5-1.12-ksu-path.patch @@ -1,4 +1,4 @@ -From bd1a0d1d4dba9f72bf8150d9aa8fdf70f738c4d7 Mon Sep 17 00:00:00 2001 +From 7f076496c7441cd108929aa05dbe009f34054bf5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:32:09 -0400 Subject: [PATCH] krb5-1.12-ksu-path.patch diff --git a/krb5-1.12-ktany.patch b/krb5-1.12-ktany.patch index b7e5ef1..de59827 100644 --- a/krb5-1.12-ktany.patch +++ b/krb5-1.12-ktany.patch @@ -1,4 +1,4 @@ -From 812be10fc5f9f2d771fc38e6ba84f7d89a32f726 Mon Sep 17 00:00:00 2001 +From 01acbf3cbd60bd460e6ec6702589451d19c89933 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:33:53 -0400 Subject: [PATCH] krb5-1.12-ktany.patch diff --git a/krb5-1.12.1-pam.patch b/krb5-1.12.1-pam.patch index ba4382a..97c1e8f 100644 --- a/krb5-1.12.1-pam.patch +++ b/krb5-1.12.1-pam.patch @@ -1,4 +1,4 @@ -From f4bb886c93625c39d4ee788250385c55230a8442 Mon Sep 17 00:00:00 2001 +From 4cbb4325a86d1d71fa45d254221ec460c41b434d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] krb5-1.12.1-pam.patch diff --git a/krb5-1.13-dirsrv-accountlock.patch b/krb5-1.13-dirsrv-accountlock.patch index e898d9d..ff5f73e 100644 --- a/krb5-1.13-dirsrv-accountlock.patch +++ b/krb5-1.13-dirsrv-accountlock.patch @@ -1,4 +1,4 @@ -From 43fe2e2c880cc8281cb9c0ffbaff374eb4a075aa Mon Sep 17 00:00:00 2001 +From bd9a3cc0c53f6dc47a124eb6e8f698c7f1d3cd36 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:44 -0400 Subject: [PATCH] krb5-1.13-dirsrv-accountlock.patch diff --git a/krb5-1.15-beta1-buildconf.patch b/krb5-1.15-beta1-buildconf.patch index d44d79f..a949727 100644 --- a/krb5-1.15-beta1-buildconf.patch +++ b/krb5-1.15-beta1-buildconf.patch @@ -1,4 +1,4 @@ -From c1c44857896ab37ed59c6cab841f5f9a0ceba5d0 Mon Sep 17 00:00:00 2001 +From 162ba7fbce23d82719956de1b126e48fe676e9d1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] krb5-1.15-beta1-buildconf.patch diff --git a/krb5-1.15.1-selinux-label.patch b/krb5-1.15.1-selinux-label.patch index 8c9a252..728c72e 100644 --- a/krb5-1.15.1-selinux-label.patch +++ b/krb5-1.15.1-selinux-label.patch @@ -1,4 +1,4 @@ -From 2857105eb2e301164a1486d31907699d0073dc5f Mon Sep 17 00:00:00 2001 +From c79d3881fefb6108306eb56cff62de03897d4bbc Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] krb5-1.15.1-selinux-label.patch diff --git a/krb5-1.3.1-dns.patch b/krb5-1.3.1-dns.patch index 36abd62..1af7c12 100644 --- a/krb5-1.3.1-dns.patch +++ b/krb5-1.3.1-dns.patch @@ -1,4 +1,4 @@ -From bf0db245d46aa0a43479a38bf0b4ec964ae642b7 Mon Sep 17 00:00:00 2001 +From 2338e73d8dced4f85d6b4f5a0f7df21033ac78c1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] krb5-1.3.1-dns.patch diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index 3a8ba3d..5b0f5bc 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -1,4 +1,4 @@ -From 6df2f0876e95a39d88f602abe992f26907e0136a Mon Sep 17 00:00:00 2001 +From 20bc1c9b1d37138d1a8538f9cef22108c8fabf4f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] krb5-1.9-debuginfo.patch diff --git a/krb5.spec b/krb5.spec index cd472d1..d874304 100644 --- a/krb5.spec +++ b/krb5.spec @@ -16,9 +16,9 @@ Summary: The Kerberos network authentication system Name: krb5 -Version: 1.16 +Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 27%{?dist} +Release: 1%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -61,8 +61,6 @@ Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch Patch37: Process-included-directories-in-alphabetical-order.patch -Patch38: Fix-flaws-in-LDAP-DN-checking.patch -Patch39: Fix-capaths-.-values-on-client.patch Patch40: Fix-hex-conversion-of-PKINIT-certid-strings.patch Patch41: Exit-with-status-0-from-kadmind.patch Patch42: Include-etype-info-in-for-hardware-preauth-hints.patch @@ -71,7 +69,6 @@ Patch44: Refactor-KDC-krb5_pa_data-utility-functions.patch Patch45: Simplify-kdc_preauth.c-systems-table.patch Patch46: Add-PKINIT-client-support-for-freshness-token.patch Patch47: Add-PKINIT-KDC-support-for-freshness-token.patch -Patch48: Allow-validation-of-PACs-with-enterprise-names.patch Patch49: Fix-read-overflow-in-KDC-sort_pa_data.patch Patch50: Include-preauth-name-in-trace-output-if-possible.patch Patch51: Report-extended-errors-in-kinit-k-t-KDB.patch @@ -86,15 +83,9 @@ Patch59: Use-k5_buf_init_dynamic_zap-where-appropriate.patch Patch60: Add-SPAKE-preauth-support.patch Patch61: Add-doc-index-entries-for-SPAKE-constants.patch Patch62: Fix-SPAKE-memory-leak.patch -Patch63: Continue-after-KRB5_CC_END-in-KCM-cache-iteration.patch Patch64: Zap-data-when-freeing-krb5_spake_factor.patch Patch65: Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch -Patch66: Save-SANs-separately-and-unparse-them-with-NO_REALM.patch -Patch67: Return-UPN-SANs-as-strings.patch Patch68: Restrict-pre-authentication-fallback-cases.patch -Patch69: Merge-duplicate-subsections-in-profile-library.patch -Patch70: Fix-KDC-null-dereference-on-large-TGS-replies.patch -Patch73: Set-error-message-on-KCM-get_princ-failure.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -746,6 +737,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri May 04 2018 Robbie Harwood - 1.16.1-1 +- New upstream release - 1.16.1 + * Thu May 03 2018 Robbie Harwood - 1.16-27 - Fix configuration of default ccache name to match file indentation diff --git a/sources b/sources index 29f4aa7..771c76f 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (krb5-1.16-pdfs.tar) = d245aad2be70d7786c45331671ed04ebaa7e5a30f7fcf5da9baf74441723e8841a7bd4dbbd977a27c925d487591a98f03430c90c72aa17f859daa9bf6cd91410 -SHA512 (krb5-1.16.tar.gz) = 7e162467b95dad2b6aaa11686d08a00f1cc4eb08247fca8f0e5a8bcaa5f9f7b42cdf00db69c5c6111bdf9eb8063d53cef3bb207ce5d6a287615ca10b710153f9 -SHA512 (krb5-1.16.tar.gz.asc) = a4b28b0877b7e1df28016cec7cd50569aa3bd539c366e7ef304e4824560f7c4cbf92ab0cd7d14328a0b578e982ff585c619a49378e59648b4259a33a799e6b2a +SHA512 (krb5-1.16.1-pdfs.tar) = 89a5a709720ee9028e9bfbcbc808eec436c4b9c6e105888b37660e97cff48e190bc77affa9809353de9cf2f39e517e8a6ab22792263978b403a4a6317ac24a46 +SHA512 (krb5-1.16.1.tar.gz) = fa4ec14a4ffe690861e2dd7ea39d7698af2058ce181bb733ea891f80279f4dde4bb891adec5ccb0eaddf737306e6ceb1fe3744a2946e6189a7d7d2dd3bc5ba84 +SHA512 (krb5-1.16.1.tar.gz.asc) = 2d24fec31ca71ee93a1339ff4fa50a9397693deff2cc7097927617e04c2509fe7e671b58b982360cbdf80c0df066e03f289a2ecacdb270dc65d7abad1e6812de From 9467290bc70322b47164e4c34f716cfb81724854 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 4 May 2018 10:59:52 -0400 Subject: [PATCH 046/304] Remove "-nodes" option from make-certs scripts --- ...nodes-option-from-make-certs-scripts.patch | 45 +++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 50 insertions(+), 1 deletion(-) create mode 100644 Remove-nodes-option-from-make-certs-scripts.patch diff --git a/Remove-nodes-option-from-make-certs-scripts.patch b/Remove-nodes-option-from-make-certs-scripts.patch new file mode 100644 index 0000000..79dcc27 --- /dev/null +++ b/Remove-nodes-option-from-make-certs-scripts.patch @@ -0,0 +1,45 @@ +From bf6ffd35be7325db3447fec9bf95b626f43b6734 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 3 May 2018 14:40:45 -0400 +Subject: [PATCH] Remove "-nodes" option from make-certs scripts + +The openssl command does not recognize options after positional +arguments, so in "openssl genrsa $KEYSIZE -nodes", the "-nodes" was +ignored as a excess positional argument prior to OpenSSL 1.1.0h, and +now causes an error. "-nodes" is an option to the openssl req and +pkcs12 subcommands, but genrsa creates unencrypted keys by default. + +[ghudson@mit.edu: edited commit message] + +(cherry picked from commit 928a36aae326d496c9a73f2cd41b4da45eef577c) +--- + src/tests/dejagnu/pkinit-certs/make-certs.sh | 2 +- + src/tests/dejagnu/proxy-certs/make-certs.sh | 2 +- + 2 files changed, 2 insertions(+), 2 deletions(-) + +diff --git a/src/tests/dejagnu/pkinit-certs/make-certs.sh b/src/tests/dejagnu/pkinit-certs/make-certs.sh +index 63f0c6f75..387311aed 100755 +--- a/src/tests/dejagnu/pkinit-certs/make-certs.sh ++++ b/src/tests/dejagnu/pkinit-certs/make-certs.sh +@@ -114,7 +114,7 @@ extendedKeyUsage = $CLIENT_EKU_LIST + EOF + + # Generate a private key. +-openssl genrsa $KEYSIZE -nodes > privkey.pem ++openssl genrsa $KEYSIZE > privkey.pem + openssl rsa -in privkey.pem -out privkey-enc.pem -des3 -passout pass:encrypted + + # Generate a "CA" certificate. +diff --git a/src/tests/dejagnu/proxy-certs/make-certs.sh b/src/tests/dejagnu/proxy-certs/make-certs.sh +index 1191bf05e..24ef91bde 100755 +--- a/src/tests/dejagnu/proxy-certs/make-certs.sh ++++ b/src/tests/dejagnu/proxy-certs/make-certs.sh +@@ -79,7 +79,7 @@ extendedKeyUsage = $PROXY_EKU_LIST + EOF + + # Generate a private key. +-openssl genrsa $KEYSIZE -nodes > privkey.pem ++openssl genrsa $KEYSIZE > privkey.pem + + # Generate a "CA" certificate. + SUBJECT=signer openssl req -config openssl.cnf -new -x509 -extensions exts_ca \ diff --git a/krb5.spec b/krb5.spec index d874304..7cbd450 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1%{?dist} +Release: 2%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -86,6 +86,7 @@ Patch62: Fix-SPAKE-memory-leak.patch Patch64: Zap-data-when-freeing-krb5_spake_factor.patch Patch65: Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch Patch68: Restrict-pre-authentication-fallback-cases.patch +Patch69: Remove-nodes-option-from-make-certs-scripts.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -737,6 +738,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri May 04 2018 Robbie Harwood - 1.16.1-2 +- Remove "-nodes" option from make-certs scripts + * Fri May 04 2018 Robbie Harwood - 1.16.1-1 - New upstream release - 1.16.1 From 6e3058a9c5ca723480629656e7d60b8a32b9156b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 1 Jun 2018 14:04:16 -0400 Subject: [PATCH 047/304] Log when non-root ksu authorization fails Resolves: #1575771 --- Fix-segfault-in-finish_dispatch.patch | 133 ++++++++++++++++++ ...hen-non-root-ksu-authorization-fails.patch | 35 +++++ krb5.spec | 8 +- 3 files changed, 175 insertions(+), 1 deletion(-) create mode 100644 Fix-segfault-in-finish_dispatch.patch create mode 100644 Log-when-non-root-ksu-authorization-fails.patch diff --git a/Fix-segfault-in-finish_dispatch.patch b/Fix-segfault-in-finish_dispatch.patch new file mode 100644 index 0000000..fe9e63c --- /dev/null +++ b/Fix-segfault-in-finish_dispatch.patch @@ -0,0 +1,133 @@ +From d134cd489a6841f510b3efdf4ddcb283493655f0 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 18 Apr 2018 14:13:28 -0400 +Subject: [PATCH] Fix segfault in finish_dispatch() + +dispatch() doesn't necessarily initialize state->active_realm which +led to an explicit NULL dereference in finish_dispatch(). + +Additionally, fix make_too_big_error() so that it won't subsequently +dereference state->active_realm. + +tags: pullup +target_version: 1.16-next +target_version: 1.15-next +--- + src/kdc/dispatch.c | 79 ++++++++++++++++++++++++---------------------- + 1 file changed, 42 insertions(+), 37 deletions(-) + +diff --git a/src/kdc/dispatch.c b/src/kdc/dispatch.c +index 3ed5176a8..fb3686c98 100644 +--- a/src/kdc/dispatch.c ++++ b/src/kdc/dispatch.c +@@ -35,9 +35,6 @@ + + static krb5_int32 last_usec = 0, last_os_random = 0; + +-static krb5_error_code make_too_big_error(kdc_realm_t *kdc_active_realm, +- krb5_data **out); +- + struct dispatch_state { + loop_respond_fn respond; + void *arg; +@@ -47,6 +44,41 @@ struct dispatch_state { + krb5_context kdc_err_context; + }; + ++ ++static krb5_error_code ++make_too_big_error(krb5_context context, krb5_principal tgsprinc, ++ krb5_data **out) ++{ ++ krb5_error errpkt; ++ krb5_error_code retval; ++ krb5_data *scratch; ++ ++ *out = NULL; ++ memset(&errpkt, 0, sizeof(errpkt)); ++ ++ retval = krb5_us_timeofday(context, &errpkt.stime, &errpkt.susec); ++ if (retval) ++ return retval; ++ errpkt.error = KRB_ERR_RESPONSE_TOO_BIG; ++ errpkt.server = tgsprinc; ++ errpkt.client = NULL; ++ errpkt.text.length = 0; ++ errpkt.text.data = 0; ++ errpkt.e_data.length = 0; ++ errpkt.e_data.data = 0; ++ scratch = malloc(sizeof(*scratch)); ++ if (scratch == NULL) ++ return ENOMEM; ++ retval = krb5_mk_error(context, &errpkt, scratch); ++ if (retval) { ++ free(scratch); ++ return retval; ++ } ++ ++ *out = scratch; ++ return 0; ++} ++ + static void + finish_dispatch(struct dispatch_state *state, krb5_error_code code, + krb5_data *response) +@@ -54,12 +86,17 @@ finish_dispatch(struct dispatch_state *state, krb5_error_code code, + loop_respond_fn oldrespond = state->respond; + void *oldarg = state->arg; + kdc_realm_t *kdc_active_realm = state->active_realm; ++ krb5_principal tgsprinc = NULL; ++ ++ if (kdc_active_realm != NULL) ++ tgsprinc = kdc_active_realm->realm_tgsprinc; + + if (state->is_tcp == 0 && response && + response->length > (unsigned int)max_dgram_reply_size) { +- krb5_free_data(kdc_context, response); ++ krb5_free_data(state->kdc_err_context, response); + response = NULL; +- code = make_too_big_error(kdc_active_realm, &response); ++ code = make_too_big_error(state->kdc_err_context, tgsprinc, ++ &response); + if (code) + krb5_klog_syslog(LOG_ERR, "error constructing " + "KRB_ERR_RESPONSE_TOO_BIG error: %s", +@@ -208,38 +245,6 @@ done: + finish_dispatch_cache(state, retval, response); + } + +-static krb5_error_code +-make_too_big_error(kdc_realm_t *kdc_active_realm, krb5_data **out) +-{ +- krb5_error errpkt; +- krb5_error_code retval; +- krb5_data *scratch; +- +- *out = NULL; +- memset(&errpkt, 0, sizeof(errpkt)); +- +- retval = krb5_us_timeofday(kdc_context, &errpkt.stime, &errpkt.susec); +- if (retval) +- return retval; +- errpkt.error = KRB_ERR_RESPONSE_TOO_BIG; +- errpkt.server = tgs_server; +- errpkt.client = NULL; +- errpkt.text.length = 0; +- errpkt.text.data = 0; +- errpkt.e_data.length = 0; +- errpkt.e_data.data = 0; +- scratch = malloc(sizeof(*scratch)); +- if (scratch == NULL) +- return ENOMEM; +- retval = krb5_mk_error(kdc_context, &errpkt, scratch); +- if (retval) { +- free(scratch); +- return retval; +- } +- +- *out = scratch; +- return 0; +-} + + krb5_context get_context(void *handle) + { diff --git a/Log-when-non-root-ksu-authorization-fails.patch b/Log-when-non-root-ksu-authorization-fails.patch new file mode 100644 index 0000000..6136e85 --- /dev/null +++ b/Log-when-non-root-ksu-authorization-fails.patch @@ -0,0 +1,35 @@ +From 6b85df6c6f4bb0e61ba0913722317f4e2c3c23fc Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 7 May 2018 16:42:59 -0400 +Subject: [PATCH] Log when non-root ksu authorization fails + +If non-root user attempts to ksu but is denied by policy, log to +syslog at LOG_WARNING in keeping with other failure messages. + +ticket: 8270 +(cherry picked from commit 6cfa5c113e981f14f70ccafa20abfa5c46b665ba) +--- + src/clients/ksu/main.c | 10 ++++++++++ + 1 file changed, 10 insertions(+) + +diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c +index c6321c01b..35ff8978f 100644 +--- a/src/clients/ksu/main.c ++++ b/src/clients/ksu/main.c +@@ -417,6 +417,16 @@ main (argc, argv) + if (hp){ + if (gb_err) fprintf(stderr, "%s", gb_err); + fprintf(stderr, _("account %s: authorization failed\n"), target_user); ++ ++ if (cmd != NULL) { ++ syslog(LOG_WARNING, ++ "Account %s: authorization for %s for execution of %s failed", ++ target_user, source_user, cmd); ++ } else { ++ syslog(LOG_WARNING, "Account %s: authorization of %s failed", ++ target_user, source_user); ++ } ++ + exit(1); + } + diff --git a/krb5.spec b/krb5.spec index 7cbd450..73fdb1c 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 2%{?dist} +Release: 3%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -87,6 +87,8 @@ Patch64: Zap-data-when-freeing-krb5_spake_factor.patch Patch65: Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch Patch68: Restrict-pre-authentication-fallback-cases.patch Patch69: Remove-nodes-option-from-make-certs-scripts.patch +Patch70: Fix-segfault-in-finish_dispatch.patch +Patch71: Log-when-non-root-ksu-authorization-fails.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -738,6 +740,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Jun 01 2018 Robbie Harwood - 1.16.1-3 +- Log when non-root ksu authorization fails +- Resolves: #1575771 + * Fri May 04 2018 Robbie Harwood - 1.16.1-2 - Remove "-nodes" option from make-certs scripts From 6dd406494de102216207b46cb7436436f829b0b1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 7 Jun 2018 12:37:24 -0400 Subject: [PATCH 048/304] Update includedir processing to match upstream --- ...ncoders-and-decoders-for-SPAKE-types.patch | 2 +- ...INIT-KDC-support-for-freshness-token.patch | 2 +- ...T-client-support-for-freshness-token.patch | 2 +- Add-SPAKE-preauth-support.patch | 2 +- ...oc-index-entries-for-SPAKE-constants.patch | 2 +- Add-k5_buf_add_vfmt-to-k5buf-interface.patch | 2 +- Add-k5_dir_filenames-to-libkrb5support.patch | 222 ++++++++++++++++++ ...bkrb5support-hex-functions-and-tests.patch | 2 +- Add-vector-support-to-k5_sha256.patch | 2 +- ...ul-asking-for-AS-key-in-SPAKE-client.patch | 2 +- Exit-with-status-0-from-kadmind.patch | 2 +- Fix-SPAKE-memory-leak.patch | 2 +- ...-conversion-of-PKINIT-certid-strings.patch | 2 +- Fix-read-overflow-in-KDC-sort_pa_data.patch | 2 +- ...id_sam2-preauth-for-non-default-salt.patch | 2 +- Fix-segfault-in-finish_dispatch.patch | 2 +- Implement-k5_buf_init_dynamic_zap.patch | 2 +- ...e-info-in-for-hardware-preauth-hints.patch | 2 +- ...uth-name-in-trace-output-if-possible.patch | 2 +- ...hen-non-root-ksu-authorization-fails.patch | 2 +- Move-zap-definition-to-k5-platform.h.patch | 2 +- ...ed-directories-in-alphabetical-order.patch | 78 ------ ...s-profile-includedir-in-sorted-order.patch | 114 +++++++++ ...r-KDC-krb5_pa_data-utility-functions.patch | 2 +- ...nodes-option-from-make-certs-scripts.patch | 2 +- Report-extended-errors-in-kinit-k-t-KDB.patch | 2 +- ...ct-pre-authentication-fallback-cases.patch | 2 +- Simplify-kdc_preauth.c-systems-table.patch | 2 +- ...f_init_dynamic_zap-where-appropriate.patch | 2 +- ...port-hex-functions-where-appropriate.patch | 2 +- Zap-data-when-freeing-krb5_spake_factor.patch | 2 +- krb5.spec | 8 +- 32 files changed, 370 insertions(+), 108 deletions(-) create mode 100644 Add-k5_dir_filenames-to-libkrb5support.patch delete mode 100644 Process-included-directories-in-alphabetical-order.patch create mode 100644 Process-profile-includedir-in-sorted-order.patch diff --git a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch index 6a00f5d..6e78dcc 100644 --- a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch +++ b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch @@ -1,4 +1,4 @@ -From dd66546bde0bc868a9af2ac702c7466e7494b33b Mon Sep 17 00:00:00 2001 +From dff5177801444307d19071fc4fac7de864fda92a Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 13 Jun 2015 16:04:53 -0400 Subject: [PATCH] Add ASN.1 encoders and decoders for SPAKE types diff --git a/Add-PKINIT-KDC-support-for-freshness-token.patch b/Add-PKINIT-KDC-support-for-freshness-token.patch index 7a5d9eb..70782fb 100644 --- a/Add-PKINIT-KDC-support-for-freshness-token.patch +++ b/Add-PKINIT-KDC-support-for-freshness-token.patch @@ -1,4 +1,4 @@ -From 9f69b78a93de5ae396eb96d2957f36f8b9dc7458 Mon Sep 17 00:00:00 2001 +From c93112a19f73b9a984cabd320129ee8f70cb4823 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 12 Mar 2018 11:31:46 -0400 Subject: [PATCH] Add PKINIT KDC support for freshness token diff --git a/Add-PKINIT-client-support-for-freshness-token.patch b/Add-PKINIT-client-support-for-freshness-token.patch index 9aade4d..1a00819 100644 --- a/Add-PKINIT-client-support-for-freshness-token.patch +++ b/Add-PKINIT-client-support-for-freshness-token.patch @@ -1,4 +1,4 @@ -From 0bc035db40c5badae3cc00f452560785a0cb0a44 Mon Sep 17 00:00:00 2001 +From 5edc6de93196b4f07da6695a4b271a067000c84d Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 31 Jan 2017 17:02:34 -0500 Subject: [PATCH] Add PKINIT client support for freshness token diff --git a/Add-SPAKE-preauth-support.patch b/Add-SPAKE-preauth-support.patch index 52ae328..ab04539 100644 --- a/Add-SPAKE-preauth-support.patch +++ b/Add-SPAKE-preauth-support.patch @@ -1,4 +1,4 @@ -From b054d1d29e676600abd6fdd7a67a283c3c011f95 Mon Sep 17 00:00:00 2001 +From f8f2cff0aba6ea7dd9b5fef89549aaff36ce4fee Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 25 Sep 2015 17:47:35 -0400 Subject: [PATCH] Add SPAKE preauth support diff --git a/Add-doc-index-entries-for-SPAKE-constants.patch b/Add-doc-index-entries-for-SPAKE-constants.patch index fa8e7ab..7ac2afe 100644 --- a/Add-doc-index-entries-for-SPAKE-constants.patch +++ b/Add-doc-index-entries-for-SPAKE-constants.patch @@ -1,4 +1,4 @@ -From 0ff94a373749e83fb9c2c5c6fa6d5788b2b63460 Mon Sep 17 00:00:00 2001 +From c891e4bc54c8083a1af8d28aa9b12ab1177ebb9a Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 27 Mar 2018 00:49:43 -0400 Subject: [PATCH] Add doc index entries for SPAKE constants diff --git a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch index e1e5b35..1a333a7 100644 --- a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch +++ b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch @@ -1,4 +1,4 @@ -From f2402ea18c8587dab261cd724ef62fd7f6bcc8ec Mon Sep 17 00:00:00 2001 +From 74e1079df0cc6e8932e487455177a69f782b863a Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 4 Jan 2018 14:35:12 -0500 Subject: [PATCH] Add k5_buf_add_vfmt to k5buf interface diff --git a/Add-k5_dir_filenames-to-libkrb5support.patch b/Add-k5_dir_filenames-to-libkrb5support.patch new file mode 100644 index 0000000..d420f15 --- /dev/null +++ b/Add-k5_dir_filenames-to-libkrb5support.patch @@ -0,0 +1,222 @@ +From 9010a0dbf59771cb0a9c1e6fd5a18a92a1200ca7 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 5 Jun 2018 14:01:05 -0400 +Subject: [PATCH] Add k5_dir_filenames() to libkrb5support + +Add a support function to get a list of filenames from a directory in +sorted order. + +(cherry picked from commit 27534121eb39089ff4335d8b465027e9ba783682) +--- + src/include/k5-platform.h | 7 + + src/util/support/Makefile.in | 3 + + src/util/support/dir_filenames.c | 135 ++++++++++++++++++ + src/util/support/libkrb5support-fixed.exports | 2 + + 4 files changed, 147 insertions(+) + create mode 100644 src/util/support/dir_filenames.c + +diff --git a/src/include/k5-platform.h b/src/include/k5-platform.h +index 07ef6a4ca..763408a09 100644 +--- a/src/include/k5-platform.h ++++ b/src/include/k5-platform.h +@@ -44,6 +44,8 @@ + * + constant time memory comparison + * + path manipulation + * + _, N_, dgettext, bindtextdomain (for localization) ++ * + getopt_long ++ * + fetching filenames from a directory + */ + + #ifndef K5_PLATFORM_H +@@ -1148,4 +1150,9 @@ extern int k5_getopt_long(int nargc, char **nargv, char *options, + #define getopt_long k5_getopt_long + #endif /* HAVE_GETOPT_LONG */ + ++/* Set *fnames_out to a null-terminated list of filenames within dirname, ++ * sorted according to strcmp(). Return 0 on success, or ENOENT/ENOMEM. */ ++int k5_dir_filenames(const char *dirname, char ***fnames_out); ++void k5_free_filenames(char **fnames); ++ + #endif /* K5_PLATFORM_H */ +diff --git a/src/util/support/Makefile.in b/src/util/support/Makefile.in +index caaf15822..4715e0391 100644 +--- a/src/util/support/Makefile.in ++++ b/src/util/support/Makefile.in +@@ -85,6 +85,7 @@ STLIBOBJS= \ + hex.o \ + bcmp.o \ + strerror_r.o \ ++ dir_filenames.o \ + $(GETTIMEOFDAY_ST_OBJ) \ + $(IPC_ST_OBJ) \ + $(STRLCPY_ST_OBJ) \ +@@ -111,6 +112,7 @@ LIBOBJS= \ + $(OUTPRE)hex.$(OBJEXT) \ + $(OUTPRE)bcmp.$(OBJEXT) \ + $(OUTPRE)strerror_r.$(OBJEXT) \ ++ $(OUTPRE)dir_filenames.$(OBJEXT) \ + $(GETTIMEOFDAY_OBJ) \ + $(IPC_OBJ) \ + $(STRLCPY_OBJ) \ +@@ -147,6 +149,7 @@ SRCS=\ + $(srcdir)/hex.c \ + $(srcdir)/bcmp.c \ + $(srcdir)/strerror_r.c \ ++ $(srcdir)/dir_filenames.c \ + $(srcdir)/t_utf8.c \ + $(srcdir)/t_utf16.c \ + $(srcdir)/getopt.c \ +diff --git a/src/util/support/dir_filenames.c b/src/util/support/dir_filenames.c +new file mode 100644 +index 000000000..9312b0238 +--- /dev/null ++++ b/src/util/support/dir_filenames.c +@@ -0,0 +1,135 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* util/support/dir_filenames.c - fetch filenames in a directory */ ++/* ++ * Copyright (C) 2018 by the Massachusetts Institute of Technology. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#include "k5-platform.h" ++ ++void ++k5_free_filenames(char **fnames) ++{ ++ char **fn; ++ ++ for (fn = fnames; fn != NULL && *fn != NULL; fn++) ++ free(*fn); ++ free(fnames); ++} ++ ++/* Resize the filename list and add a name. */ ++static int ++add_filename(char ***fnames, int *n_fnames, const char *name) ++{ ++ char **newlist; ++ ++ newlist = realloc(*fnames, (*n_fnames + 2) * sizeof(*newlist)); ++ if (newlist == NULL) ++ return ENOMEM; ++ *fnames = newlist; ++ newlist[*n_fnames] = strdup(name); ++ if (newlist[*n_fnames] == NULL) ++ return ENOMEM; ++ (*n_fnames)++; ++ newlist[*n_fnames] = NULL; ++ return 0; ++} ++ ++static int ++compare_with_strcmp(const void *a, const void *b) ++{ ++ return strcmp(*(char **)a, *(char **)b); ++} ++ ++#ifdef _WIN32 ++ ++int ++k5_dir_filenames(const char *dirname, char ***fnames_out) ++{ ++ char *wildcard; ++ WIN32_FIND_DATA ffd; ++ HANDLE handle; ++ char **fnames = NULL; ++ int n_fnames = 0; ++ ++ *fnames_out = NULL; ++ ++ if (asprintf(&wildcard, "%s\\*", dirname) < 0) ++ return ENOMEM; ++ handle = FindFirstFile(wildcard, &ffd); ++ free(wildcard); ++ if (handle == INVALID_HANDLE_VALUE) ++ return ENOENT; ++ ++ do { ++ if (add_filename(&fnames, &n_fnames, &ffd.cFileName) != 0) { ++ k5_free_filenames(fnames); ++ FindClose(handle); ++ return ENOMEM; ++ } ++ } while (FindNextFile(handle, &ffd) != 0); ++ ++ FindClose(handle); ++ qsort(fnames, n_fnames, sizeof(*fnames), compare_with_strcmp); ++ *fnames_out = fnames; ++ return 0; ++} ++ ++#else /* _WIN32 */ ++ ++#include ++ ++int ++k5_dir_filenames(const char *dirname, char ***fnames_out) ++{ ++ DIR *dir; ++ struct dirent *ent; ++ char **fnames = NULL; ++ int n_fnames = 0; ++ ++ *fnames_out = NULL; ++ ++ dir = opendir(dirname); ++ if (dir == NULL) ++ return ENOENT; ++ ++ while ((ent = readdir(dir)) != NULL) { ++ if (add_filename(&fnames, &n_fnames, ent->d_name) != 0) { ++ k5_free_filenames(fnames); ++ closedir(dir); ++ return ENOMEM; ++ } ++ } ++ ++ closedir(dir); ++ qsort(fnames, n_fnames, sizeof(*fnames), compare_with_strcmp); ++ *fnames_out = fnames; ++ return 0; ++} ++ ++#endif /* not _WIN32 */ +diff --git a/src/util/support/libkrb5support-fixed.exports b/src/util/support/libkrb5support-fixed.exports +index a5e2ade04..16ed5a6c1 100644 +--- a/src/util/support/libkrb5support-fixed.exports ++++ b/src/util/support/libkrb5support-fixed.exports +@@ -58,6 +58,8 @@ k5_path_split + k5_strerror_r + k5_utf8_to_utf16le + k5_utf16le_to_utf8 ++k5_dir_filenames ++k5_free_filenames + krb5int_key_register + krb5int_key_delete + krb5int_getspecific diff --git a/Add-libkrb5support-hex-functions-and-tests.patch b/Add-libkrb5support-hex-functions-and-tests.patch index 097c2af..d7caab2 100644 --- a/Add-libkrb5support-hex-functions-and-tests.patch +++ b/Add-libkrb5support-hex-functions-and-tests.patch @@ -1,4 +1,4 @@ -From c8992ad9dc0c7fc4d8bec3b9ecb129fe587d615e Mon Sep 17 00:00:00 2001 +From 507b1aff60fdadc91ca7c56d39711049aeeb1e58 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 19 Feb 2018 00:51:44 -0500 Subject: [PATCH] Add libkrb5support hex functions and tests diff --git a/Add-vector-support-to-k5_sha256.patch b/Add-vector-support-to-k5_sha256.patch index 9d9c792..f9a3233 100644 --- a/Add-vector-support-to-k5_sha256.patch +++ b/Add-vector-support-to-k5_sha256.patch @@ -1,4 +1,4 @@ -From 5ed0331bd6bfd39b9c5ca40ec38d536221118998 Mon Sep 17 00:00:00 2001 +From f8b14b92cc4c82578f8fc56dd1fddebe88120769 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 3 Feb 2018 20:53:42 -0500 Subject: [PATCH] Add vector support to k5_sha256() diff --git a/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch b/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch index 05106ad..692f4ad 100644 --- a/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch +++ b/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch @@ -1,4 +1,4 @@ -From c98a6fc929b80dd8d221314e31903a9d5ee56295 Mon Sep 17 00:00:00 2001 +From 2b9e79d58b28196dba5f7d3ff2f32ca577444ddc Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 31 Mar 2018 10:43:49 -0400 Subject: [PATCH] Be more careful asking for AS key in SPAKE client diff --git a/Exit-with-status-0-from-kadmind.patch b/Exit-with-status-0-from-kadmind.patch index 93a1a18..5fbdff8 100644 --- a/Exit-with-status-0-from-kadmind.patch +++ b/Exit-with-status-0-from-kadmind.patch @@ -1,4 +1,4 @@ -From cb8f31e6bbf72e207b428d52c2fd9ed719bbec4f Mon Sep 17 00:00:00 2001 +From 3bfe632c7011c335362d78356232507d9ee26f73 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 14 Mar 2018 14:31:22 -0400 Subject: [PATCH] Exit with status 0 from kadmind diff --git a/Fix-SPAKE-memory-leak.patch b/Fix-SPAKE-memory-leak.patch index 9d4011d..e1cacca 100644 --- a/Fix-SPAKE-memory-leak.patch +++ b/Fix-SPAKE-memory-leak.patch @@ -1,4 +1,4 @@ -From 3ea258c813de4c55a8979f019b716422b998e231 Mon Sep 17 00:00:00 2001 +From 390c515e13dffc8c00b44623cba47e27c2f20cf7 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 27 Mar 2018 10:36:05 -0400 Subject: [PATCH] Fix SPAKE memory leak diff --git a/Fix-hex-conversion-of-PKINIT-certid-strings.patch b/Fix-hex-conversion-of-PKINIT-certid-strings.patch index cc9ff38..57d561b 100644 --- a/Fix-hex-conversion-of-PKINIT-certid-strings.patch +++ b/Fix-hex-conversion-of-PKINIT-certid-strings.patch @@ -1,4 +1,4 @@ -From 6b8f7371e49c3aa636871bb4e2ea2d2e86c743de Mon Sep 17 00:00:00 2001 +From 8b898badbe8051270c6da96f5c15f3bc8b6d974e Mon Sep 17 00:00:00 2001 From: Sumit Bose Date: Fri, 26 Jan 2018 11:47:50 -0500 Subject: [PATCH] Fix hex conversion of PKINIT certid strings diff --git a/Fix-read-overflow-in-KDC-sort_pa_data.patch b/Fix-read-overflow-in-KDC-sort_pa_data.patch index 50a3923..4f46827 100644 --- a/Fix-read-overflow-in-KDC-sort_pa_data.patch +++ b/Fix-read-overflow-in-KDC-sort_pa_data.patch @@ -1,4 +1,4 @@ -From 20c25d4a2f78d8ab33d4879e1cf843e1fdb8a20b Mon Sep 17 00:00:00 2001 +From 59a28991e15496e6f9cf867c32dc18e7e1062f59 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 15 Mar 2018 20:27:30 -0400 Subject: [PATCH] Fix read overflow in KDC sort_pa_data() diff --git a/Fix-securid_sam2-preauth-for-non-default-salt.patch b/Fix-securid_sam2-preauth-for-non-default-salt.patch index ea4f220..610bf4e 100644 --- a/Fix-securid_sam2-preauth-for-non-default-salt.patch +++ b/Fix-securid_sam2-preauth-for-non-default-salt.patch @@ -1,4 +1,4 @@ -From 9c9ff189c16b16f848f2e85c1d262f12c6d5e922 Mon Sep 17 00:00:00 2001 +From e405f42b532e377e7e3d654313a07f8c11f48f9a Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 3 Jan 2018 12:06:08 -0500 Subject: [PATCH] Fix securid_sam2 preauth for non-default salt diff --git a/Fix-segfault-in-finish_dispatch.patch b/Fix-segfault-in-finish_dispatch.patch index fe9e63c..ff28848 100644 --- a/Fix-segfault-in-finish_dispatch.patch +++ b/Fix-segfault-in-finish_dispatch.patch @@ -1,4 +1,4 @@ -From d134cd489a6841f510b3efdf4ddcb283493655f0 Mon Sep 17 00:00:00 2001 +From 617d153bb32d0bd7db33ccec21043d1113651f3a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 18 Apr 2018 14:13:28 -0400 Subject: [PATCH] Fix segfault in finish_dispatch() diff --git a/Implement-k5_buf_init_dynamic_zap.patch b/Implement-k5_buf_init_dynamic_zap.patch index 530416d..28fd16b 100644 --- a/Implement-k5_buf_init_dynamic_zap.patch +++ b/Implement-k5_buf_init_dynamic_zap.patch @@ -1,4 +1,4 @@ -From e6945eee571b0ff776270dea52fb051b62aedabd Mon Sep 17 00:00:00 2001 +From 3d651a6e234bed4c4d4865a56c5fa47dab89a5a6 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 26 Mar 2018 11:12:39 -0400 Subject: [PATCH] Implement k5_buf_init_dynamic_zap diff --git a/Include-etype-info-in-for-hardware-preauth-hints.patch b/Include-etype-info-in-for-hardware-preauth-hints.patch index 841a9c1..82aba62 100644 --- a/Include-etype-info-in-for-hardware-preauth-hints.patch +++ b/Include-etype-info-in-for-hardware-preauth-hints.patch @@ -1,4 +1,4 @@ -From 6f883193ddb63da0f29977e3b95a663321404546 Mon Sep 17 00:00:00 2001 +From bbc68d1657306a61a7646dd7b9690f67705e24be Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 3 Jan 2018 11:59:14 -0500 Subject: [PATCH] Include etype-info in for hardware preauth hints diff --git a/Include-preauth-name-in-trace-output-if-possible.patch b/Include-preauth-name-in-trace-output-if-possible.patch index 7ab27a7..fe88920 100644 --- a/Include-preauth-name-in-trace-output-if-possible.patch +++ b/Include-preauth-name-in-trace-output-if-possible.patch @@ -1,4 +1,4 @@ -From 265d00ef6bb5469b2464d7813af8c37581338385 Mon Sep 17 00:00:00 2001 +From b623881ec039bffc758f53906f7e4f9b884f1cf4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 15 Mar 2018 14:37:28 -0400 Subject: [PATCH] Include preauth name in trace output if possible diff --git a/Log-when-non-root-ksu-authorization-fails.patch b/Log-when-non-root-ksu-authorization-fails.patch index 6136e85..704b5a9 100644 --- a/Log-when-non-root-ksu-authorization-fails.patch +++ b/Log-when-non-root-ksu-authorization-fails.patch @@ -1,4 +1,4 @@ -From 6b85df6c6f4bb0e61ba0913722317f4e2c3c23fc Mon Sep 17 00:00:00 2001 +From 9dd3a84f324979c29e8ab4b472e98dfa73e6b290 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 7 May 2018 16:42:59 -0400 Subject: [PATCH] Log when non-root ksu authorization fails diff --git a/Move-zap-definition-to-k5-platform.h.patch b/Move-zap-definition-to-k5-platform.h.patch index c499685..f181701 100644 --- a/Move-zap-definition-to-k5-platform.h.patch +++ b/Move-zap-definition-to-k5-platform.h.patch @@ -1,4 +1,4 @@ -From 56521276ff20bc05a61c6f070cb4dcab730ff6d6 Mon Sep 17 00:00:00 2001 +From ee941a490268bb045ec7e153bdf229adcd6d2f73 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 26 Mar 2018 10:54:29 -0400 Subject: [PATCH] Move zap() definition to k5-platform.h diff --git a/Process-included-directories-in-alphabetical-order.patch b/Process-included-directories-in-alphabetical-order.patch deleted file mode 100644 index 29d3e90..0000000 --- a/Process-included-directories-in-alphabetical-order.patch +++ /dev/null @@ -1,78 +0,0 @@ -From 88abb837d8a9ff12b71a848efbeaa9b9a009cc1f Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 29 Jan 2018 12:10:53 +0100 -Subject: [PATCH] Process included directories in alphabetical order - -readdir() and FindFirstFile()/FindNextFile() do not define any -ordering on the entries they return. Use sorted scandir() instead on -Unix-likes. - -(cherry picked from commit 4e8518baeedf376ae3e4ce302c9a138263d648df) ---- - src/util/profile/prof_parse.c | 30 ++++++++++++++++++++---------- - 1 file changed, 20 insertions(+), 10 deletions(-) - -diff --git a/src/util/profile/prof_parse.c b/src/util/profile/prof_parse.c -index 1baceea9e..309c27d07 100644 ---- a/src/util/profile/prof_parse.c -+++ b/src/util/profile/prof_parse.c -@@ -241,12 +241,18 @@ static int valid_name(const char *filename) - } - return 1; - } -+#ifndef _WIN32 -+static int valid_name_scandir(const struct dirent *d) -+{ -+ return valid_name(d->d_name); -+} -+#endif - - /* - * Include files within dirname. Only files with names ending in ".conf", or - * consisting entirely of alphanumeric characters, dashes, and underscores are - * included. This restriction avoids including editor backup files, .rpmsave -- * files, and the like. -+ * files, and the like. Files are processed in alphanumeric order. - */ - static errcode_t parse_include_dir(const char *dirname, - struct profile_node *root_section) -@@ -287,18 +293,19 @@ cleanup: - - #else /* not _WIN32 */ - -- DIR *dir; - char *pathname; - errcode_t retval = 0; -- struct dirent *ent; -+ struct dirent **namelist; -+ int num_ents, i; - -- dir = opendir(dirname); -- if (dir == NULL) -+ num_ents = scandir(dirname, &namelist, &valid_name_scandir, &alphasort); -+ if (num_ents == -1) - return PROF_FAIL_INCLUDE_DIR; -- while ((ent = readdir(dir)) != NULL) { -- if (!valid_name(ent->d_name)) -- continue; -- if (asprintf(&pathname, "%s/%s", dirname, ent->d_name) < 0) { -+ -+ for (i = 0; i < num_ents; i++) { -+ retval = asprintf(&pathname, "%s/%s", dirname, namelist[i]->d_name); -+ free(namelist[i]); -+ if (retval < 0) { - retval = ENOMEM; - break; - } -@@ -307,7 +314,10 @@ cleanup: - if (retval) - break; - } -- closedir(dir); -+ for (i++; i < num_ents; i++) -+ free(namelist[i]); -+ -+ free(namelist); - return retval; - #endif /* not _WIN32 */ - } diff --git a/Process-profile-includedir-in-sorted-order.patch b/Process-profile-includedir-in-sorted-order.patch new file mode 100644 index 0000000..92efffc --- /dev/null +++ b/Process-profile-includedir-in-sorted-order.patch @@ -0,0 +1,114 @@ +From 5d868264bca1771aa16abbc8cc0aefb0e1750a73 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 6 Jun 2018 17:58:41 -0400 +Subject: [PATCH] Process profile includedir in sorted order + +In the profile library, use k5_dir_filenames() so that files within an +included directory are read in a predictable order (alphanumeric +within the C locale). + +ticket: 8686 +(cherry picked from commit f574eda48740ad192f51e9a382a205e2ea0e60ad) +--- + doc/admin/conf_files/krb5_conf.rst | 4 ++- + src/util/profile/prof_parse.c | 56 +++++------------------------- + 2 files changed, 12 insertions(+), 48 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index 2574e5c26..ce545492d 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -60,7 +60,9 @@ alphanumeric characters, dashes, or underscores. Starting in release + 1.15, files with names ending in ".conf" are also included, unless the + name begins with ".". Included profile files are syntactically + independent of their parents, so each included file must begin with a +-section header. ++section header. Starting in release 1.17, files are read in ++alphanumeric order; in previous releases, they may be read in any ++order. + + The krb5.conf file can specify that configuration should be obtained + from a loadable module, rather than the file itself, using the +diff --git a/src/util/profile/prof_parse.c b/src/util/profile/prof_parse.c +index 1baceea9e..531e4a099 100644 +--- a/src/util/profile/prof_parse.c ++++ b/src/util/profile/prof_parse.c +@@ -246,59 +246,22 @@ static int valid_name(const char *filename) + * Include files within dirname. Only files with names ending in ".conf", or + * consisting entirely of alphanumeric characters, dashes, and underscores are + * included. This restriction avoids including editor backup files, .rpmsave +- * files, and the like. ++ * files, and the like. Files are processed in alphanumeric order. + */ + static errcode_t parse_include_dir(const char *dirname, + struct profile_node *root_section) + { +-#ifdef _WIN32 +- char *wildcard = NULL, *pathname; +- WIN32_FIND_DATA ffd; +- HANDLE handle; + errcode_t retval = 0; ++ char **fnames, *pathname; ++ int i; + +- if (asprintf(&wildcard, "%s\\*", dirname) < 0) +- return ENOMEM; +- +- handle = FindFirstFile(wildcard, &ffd); +- if (handle == INVALID_HANDLE_VALUE) { +- retval = PROF_FAIL_INCLUDE_DIR; +- goto cleanup; +- } +- +- do { +- if (!valid_name(ffd.cFileName)) +- continue; +- if (asprintf(&pathname, "%s\\%s", dirname, ffd.cFileName) < 0) { +- retval = ENOMEM; +- break; +- } +- retval = parse_include_file(pathname, root_section); +- free(pathname); +- if (retval) +- break; +- } while (FindNextFile(handle, &ffd) != 0); +- +- FindClose(handle); +- +-cleanup: +- free(wildcard); +- return retval; +- +-#else /* not _WIN32 */ +- +- DIR *dir; +- char *pathname; +- errcode_t retval = 0; +- struct dirent *ent; +- +- dir = opendir(dirname); +- if (dir == NULL) ++ if (k5_dir_filenames(dirname, &fnames) != 0) + return PROF_FAIL_INCLUDE_DIR; +- while ((ent = readdir(dir)) != NULL) { +- if (!valid_name(ent->d_name)) ++ ++ for (i = 0; fnames != NULL && fnames[i] != NULL; i++) { ++ if (!valid_name(fnames[i])) + continue; +- if (asprintf(&pathname, "%s/%s", dirname, ent->d_name) < 0) { ++ if (asprintf(&pathname, "%s/%s", dirname, fnames[i]) < 0) { + retval = ENOMEM; + break; + } +@@ -307,9 +270,8 @@ cleanup: + if (retval) + break; + } +- closedir(dir); ++ k5_free_filenames(fnames); + return retval; +-#endif /* not _WIN32 */ + } + + static errcode_t parse_line(char *line, struct parse_state *state, diff --git a/Refactor-KDC-krb5_pa_data-utility-functions.patch b/Refactor-KDC-krb5_pa_data-utility-functions.patch index 957bf71..41e7cbe 100644 --- a/Refactor-KDC-krb5_pa_data-utility-functions.patch +++ b/Refactor-KDC-krb5_pa_data-utility-functions.patch @@ -1,4 +1,4 @@ -From 276ecd7ba513ce0bfe5e51d6368e00476041a5b4 Mon Sep 17 00:00:00 2001 +From 7c59b7ee063489a4259c34b725728fee7e411c46 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 21 Dec 2017 11:28:52 -0500 Subject: [PATCH] Refactor KDC krb5_pa_data utility functions diff --git a/Remove-nodes-option-from-make-certs-scripts.patch b/Remove-nodes-option-from-make-certs-scripts.patch index 79dcc27..402f5fb 100644 --- a/Remove-nodes-option-from-make-certs-scripts.patch +++ b/Remove-nodes-option-from-make-certs-scripts.patch @@ -1,4 +1,4 @@ -From bf6ffd35be7325db3447fec9bf95b626f43b6734 Mon Sep 17 00:00:00 2001 +From 83da5675551dba13fee837adc26ce885a061dbc1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 3 May 2018 14:40:45 -0400 Subject: [PATCH] Remove "-nodes" option from make-certs scripts diff --git a/Report-extended-errors-in-kinit-k-t-KDB.patch b/Report-extended-errors-in-kinit-k-t-KDB.patch index c41334e..6859b55 100644 --- a/Report-extended-errors-in-kinit-k-t-KDB.patch +++ b/Report-extended-errors-in-kinit-k-t-KDB.patch @@ -1,4 +1,4 @@ -From 177cb167cfc151a1f58fb3e771cd29d0598f462f Mon Sep 17 00:00:00 2001 +From 3b3e31316ae247e18ea22293dffbc8f604338fa7 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 17 Mar 2018 22:47:34 -0400 Subject: [PATCH] Report extended errors in kinit -k -t KDB: diff --git a/Restrict-pre-authentication-fallback-cases.patch b/Restrict-pre-authentication-fallback-cases.patch index 8830d1e..f519557 100644 --- a/Restrict-pre-authentication-fallback-cases.patch +++ b/Restrict-pre-authentication-fallback-cases.patch @@ -1,4 +1,4 @@ -From 1e423ec03dbd65845a4aeb8999d130d3d6a0cdd7 Mon Sep 17 00:00:00 2001 +From 70f41a8dafaadfb43aba4918564c22460f812dca Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 5 Apr 2018 16:23:34 -0400 Subject: [PATCH] Restrict pre-authentication fallback cases diff --git a/Simplify-kdc_preauth.c-systems-table.patch b/Simplify-kdc_preauth.c-systems-table.patch index 6716ca3..08853d4 100644 --- a/Simplify-kdc_preauth.c-systems-table.patch +++ b/Simplify-kdc_preauth.c-systems-table.patch @@ -1,4 +1,4 @@ -From bd2f01d99b623be070c8bc8d660ca92c337147ae Mon Sep 17 00:00:00 2001 +From 65f078dfc68f5680e87e686a59970291b64ebd95 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 11 Feb 2018 15:23:35 -0500 Subject: [PATCH] Simplify kdc_preauth.c systems table diff --git a/Use-k5_buf_init_dynamic_zap-where-appropriate.patch b/Use-k5_buf_init_dynamic_zap-where-appropriate.patch index e2baf07..3d3bcd8 100644 --- a/Use-k5_buf_init_dynamic_zap-where-appropriate.patch +++ b/Use-k5_buf_init_dynamic_zap-where-appropriate.patch @@ -1,4 +1,4 @@ -From 0c2324e3f88f5ba3dbe7c9053017549f13e1f995 Mon Sep 17 00:00:00 2001 +From c5df16a88027d7f9b6eb53b1c3fa949d6538616b Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 26 Mar 2018 11:24:49 -0400 Subject: [PATCH] Use k5_buf_init_dynamic_zap where appropriate diff --git a/Use-libkrb5support-hex-functions-where-appropriate.patch b/Use-libkrb5support-hex-functions-where-appropriate.patch index f22d05b..eab05bc 100644 --- a/Use-libkrb5support-hex-functions-where-appropriate.patch +++ b/Use-libkrb5support-hex-functions-where-appropriate.patch @@ -1,4 +1,4 @@ -From c7677e91fb406c7ec55cb115155ed0d4c5943b72 Mon Sep 17 00:00:00 2001 +From 19109505ad04efdfd70df3ee922e22bcf5a294f3 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 19 Feb 2018 00:52:35 -0500 Subject: [PATCH] Use libkrb5support hex functions where appropriate diff --git a/Zap-data-when-freeing-krb5_spake_factor.patch b/Zap-data-when-freeing-krb5_spake_factor.patch index 31795b9..9ce2462 100644 --- a/Zap-data-when-freeing-krb5_spake_factor.patch +++ b/Zap-data-when-freeing-krb5_spake_factor.patch @@ -1,4 +1,4 @@ -From 6f02200464dd484641639f2cb38b775d34af4bcd Mon Sep 17 00:00:00 2001 +From 5d970e16e768a134e65ee7cf367b8f34a80e0980 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 27 Mar 2018 15:42:28 -0400 Subject: [PATCH] Zap data when freeing krb5_spake_factor diff --git a/krb5.spec b/krb5.spec index 73fdb1c..a408bf7 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 3%{?dist} +Release: 4%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -60,7 +60,6 @@ Patch33: krb5-1.13-dirsrv-accountlock.patch Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch -Patch37: Process-included-directories-in-alphabetical-order.patch Patch40: Fix-hex-conversion-of-PKINIT-certid-strings.patch Patch41: Exit-with-status-0-from-kadmind.patch Patch42: Include-etype-info-in-for-hardware-preauth-hints.patch @@ -89,6 +88,8 @@ Patch68: Restrict-pre-authentication-fallback-cases.patch Patch69: Remove-nodes-option-from-make-certs-scripts.patch Patch70: Fix-segfault-in-finish_dispatch.patch Patch71: Log-when-non-root-ksu-authorization-fails.patch +Patch72: Add-k5_dir_filenames-to-libkrb5support.patch +Patch73: Process-profile-includedir-in-sorted-order.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -740,6 +741,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jun 07 2018 Robbie Harwood - 1.16.1-4 +- Update includedir processing to match upstream + * Fri Jun 01 2018 Robbie Harwood - 1.16.1-3 - Log when non-root ksu authorization fails - Resolves: #1575771 From 367b100b3bf1f84b632fd3c24be0807bf914ac2c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Jun 2018 10:49:23 -0400 Subject: [PATCH 049/304] Make docs build python3-compatible Resolves: #1590928 --- Make-docs-build-python3-compatible.patch | 36 ++++++++++++++++++++++++ krb5.spec | 7 ++++- 2 files changed, 42 insertions(+), 1 deletion(-) create mode 100644 Make-docs-build-python3-compatible.patch diff --git a/Make-docs-build-python3-compatible.patch b/Make-docs-build-python3-compatible.patch new file mode 100644 index 0000000..58a3e86 --- /dev/null +++ b/Make-docs-build-python3-compatible.patch @@ -0,0 +1,36 @@ +From 16c745b7e9e239535a8c71dc7022b477a5165e01 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 13 Jun 2018 15:07:48 -0400 +Subject: [PATCH] Make docs build python3-compatible + +python3 removed execfile(), which we use for loading version data and +paths information in docs. Call exec() directly instead. + +ticket: 8692 (new) +(cherry picked from commit a7c6d98480f1e33454173f88381921472d72f80a) +--- + doc/conf.py | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/doc/conf.py b/doc/conf.py +index 25ba214a8..0555808e6 100644 +--- a/doc/conf.py ++++ b/doc/conf.py +@@ -50,7 +50,7 @@ copyright = u'1985-2018, MIT' + # The version info for the project you're documenting, acts as replacement for + # |version| and |release|, also used in various other places throughout the + # built documents. +-execfile("version.py") ++exec(open("version.py").read()) + # The short X.Y version. + r_list = [r_major, r_minor] + if r_patch: +@@ -238,7 +238,7 @@ if 'mansubs' in tags: + ckeytab = '``@CKTNAME@``' + elif 'pathsubs' in tags: + # Read configured paths from a file produced by the build system. +- execfile('paths.py') ++ exec(open("paths.py").read()) + else: + bindir = ':ref:`BINDIR `' + sbindir = ':ref:`SBINDIR `' diff --git a/krb5.spec b/krb5.spec index a408bf7..305ffcc 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 4%{?dist} +Release: 5%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -90,6 +90,7 @@ Patch70: Fix-segfault-in-finish_dispatch.patch Patch71: Log-when-non-root-ksu-authorization-fails.patch Patch72: Add-k5_dir_filenames-to-libkrb5support.patch Patch73: Process-profile-includedir-in-sorted-order.patch +Patch74: Make-docs-build-python3-compatible.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -741,6 +742,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jun 14 2018 Robbie Harwood - 1.16.1-5 +- Make docs build python3-compatible +- Resolves: #1590928 + * Thu Jun 07 2018 Robbie Harwood - 1.16.1-4 - Update includedir processing to match upstream From d6ae33b85a8c6a2ff641258abf452c65ea94ff94 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Jun 2018 16:56:44 +0000 Subject: [PATCH 050/304] Switch to python3-sphinx for docs Resolves: #1590928 --- krb5.spec | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/krb5.spec b/krb5.spec index 305ffcc..7dbcdaf 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 5%{?dist} +Release: 6%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -98,7 +98,7 @@ Group: System Environment/Libraries BuildRequires: autoconf, bison, cmake, flex, gawk, gettext, pkgconfig, sed BuildRequires: libcom_err-devel, libedit-devel, libss-devel BuildRequires: gzip, ncurses-devel -BuildRequires: python2-sphinx, texlive-pdftex, latexmk +BuildRequires: python3-sphinx, texlive-pdftex, latexmk # For autosetup BuildRequires: git @@ -742,6 +742,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jun 14 2018 Robbie Harwood - 1.16.1-6 +- Switch to python3-sphinx for docs +- Resolves: #1590928 + * Thu Jun 14 2018 Robbie Harwood - 1.16.1-5 - Make docs build python3-compatible - Resolves: #1590928 From ff388043f1a790a897f21e9d3aac2474d040415b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Jun 2018 17:45:09 -0400 Subject: [PATCH 051/304] Add flag to disable encrypted timestamp on client --- ...isable-encrypted-timestamp-on-client.patch | 204 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 209 insertions(+), 1 deletion(-) create mode 100644 Add-flag-to-disable-encrypted-timestamp-on-client.patch diff --git a/Add-flag-to-disable-encrypted-timestamp-on-client.patch b/Add-flag-to-disable-encrypted-timestamp-on-client.patch new file mode 100644 index 0000000..adc4f41 --- /dev/null +++ b/Add-flag-to-disable-encrypted-timestamp-on-client.patch @@ -0,0 +1,204 @@ +From f44ef4893050e673f495444c27a19525813f75a8 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 11 Jun 2018 13:53:27 -0400 +Subject: [PATCH] Add flag to disable encrypted timestamp on client + +ticket: 8655 +(cherry picked from commit 4ad376134b8d456392edbac7a7d351e6c7a7f0e7) +--- + doc/admin/conf_files/krb5_conf.rst | 10 ++++++++++ + doc/admin/spake.rst | 8 ++++++++ + src/include/k5-int.h | 1 + + src/include/k5-trace.h | 2 ++ + src/lib/krb5/krb/get_in_tkt.c | 23 +++++++++++++++++++++++ + src/lib/krb5/krb/init_creds_ctx.h | 1 + + src/lib/krb5/krb/preauth_encts.c | 14 +++++++++++++- + src/tests/t_referral.py | 13 +++++++++++++ + 8 files changed, 71 insertions(+), 1 deletion(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index ce545492d..eb5c29e5d 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -475,6 +475,16 @@ following tags may be specified in the realm's subsection: + (for example, when converting ``rcmd.hostname`` to + ``host/hostname.domain``). + ++**disable_encrypted_timestamp** ++ If this flag is true, the client will not perform encrypted ++ timestamp preauthentication if requested by the KDC. Setting this ++ flag can help to prevent dictionary attacks by active attackers, ++ if the realm's KDCs support SPAKE preauthentication or if initial ++ authentication always uses another mechanism or always uses FAST. ++ This flag persists across client referrals during initial ++ authentication. This flag does not prevent the KDC from offering ++ encrypted timestamp. New in release 1.17. ++ + **http_anchors** + When KDCs and kpasswd servers are accessed through HTTPS proxies, this tag + can be used to specify the location of the CA certificate which should be +diff --git a/doc/admin/spake.rst b/doc/admin/spake.rst +index b65c694aa..4f6eeaf53 100644 +--- a/doc/admin/spake.rst ++++ b/doc/admin/spake.rst +@@ -30,6 +30,14 @@ principal entries, as you would for any preauthentication mechanism:: + Clients which do not implement SPAKE preauthentication will fall back + to encrypted timestamp. + ++An active attacker can force a fallback to encrypted timestamp by ++modifying the initial KDC response, defeating the protection against ++dictionary attacks. To prevent this fallback on clients which do ++implement SPAKE preauthentication, set the ++**disable_encrypted_timestamp** variable to ``true`` in the ++:ref:`realms` subsection for realms whose KDCs offer SPAKE ++preauthentication. ++ + By default, SPAKE preauthentication requires an extra network round + trip to the KDC during initial authentication. If most of the clients + in a realm support SPAKE, this extra round trip can be eliminated +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 86b53c76b..e4a9a1412 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -204,6 +204,7 @@ typedef unsigned char u_char; + #define KRB5_CONF_DES_CRC_SESSION_SUPPORTED "des_crc_session_supported" + #define KRB5_CONF_DICT_FILE "dict_file" + #define KRB5_CONF_DISABLE "disable" ++#define KRB5_CONF_DISABLE_ENCRYPTED_TIMESTAMP "disable_encrypted_timestamp" + #define KRB5_CONF_DISABLE_LAST_SUCCESS "disable_last_success" + #define KRB5_CONF_DISABLE_LOCKOUT "disable_lockout" + #define KRB5_CONF_DNS_CANONICALIZE_HOSTNAME "dns_canonicalize_hostname" +diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h +index 5f7eb9517..0854974dc 100644 +--- a/src/include/k5-trace.h ++++ b/src/include/k5-trace.h +@@ -299,6 +299,8 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); + #define TRACE_PREAUTH_ENC_TS(c, sec, usec, plain, enc) \ + TRACE(c, "Encrypted timestamp (for {long}.{int}): plain {hexdata}, " \ + "encrypted {hexdata}", (long) sec, (int) usec, plain, enc) ++#define TRACE_PREAUTH_ENC_TS_DISABLED(c) \ ++ TRACE(c, "Ignoring encrypted timestamp because it is disabled") + #define TRACE_PREAUTH_ETYPE_INFO(c, etype, salt, s2kparams) \ + TRACE(c, "Selected etype info: etype {etype}, salt \"{data}\", " \ + "params \"{data}\"", etype, salt, s2kparams) +diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c +index c026bbc6d..79dede2c6 100644 +--- a/src/lib/krb5/krb/get_in_tkt.c ++++ b/src/lib/krb5/krb/get_in_tkt.c +@@ -801,6 +801,24 @@ read_allowed_preauth_type(krb5_context context, krb5_init_creds_context ctx) + free(tmp); + } + ++/* Return true if encrypted timestamp is disabled for realm. */ ++static krb5_boolean ++encts_disabled(profile_t profile, const krb5_data *realm) ++{ ++ krb5_error_code ret; ++ char *realmstr; ++ int bval; ++ ++ realmstr = k5memdup0(realm->data, realm->length, &ret); ++ if (realmstr == NULL) ++ return FALSE; ++ ret = profile_get_boolean(profile, KRB5_CONF_REALMS, realmstr, ++ KRB5_CONF_DISABLE_ENCRYPTED_TIMESTAMP, FALSE, ++ &bval); ++ free(realmstr); ++ return (ret == 0) ? bval : FALSE; ++} ++ + /** + * Throw away any pre-authentication realm state and begin with a + * unauthenticated or optimistically authenticated request. If fast_upgrade is +@@ -842,6 +860,11 @@ restart_init_creds_loop(krb5_context context, krb5_init_creds_context ctx, + goto cleanup; + } + ++ /* Never set encts_disabled back to false, so it can't be circumvented with ++ * client realm referrals. */ ++ if (encts_disabled(context->profile, &ctx->request->client->realm)) ++ ctx->encts_disabled = TRUE; ++ + krb5_free_principal(context, ctx->request->server); + ctx->request->server = NULL; + +diff --git a/src/lib/krb5/krb/init_creds_ctx.h b/src/lib/krb5/krb/init_creds_ctx.h +index 7ba61e17c..7a6219b1c 100644 +--- a/src/lib/krb5/krb/init_creds_ctx.h ++++ b/src/lib/krb5/krb/init_creds_ctx.h +@@ -61,6 +61,7 @@ struct _krb5_init_creds_context { + krb5_boolean info_pa_permitted; + krb5_boolean restarted; + krb5_boolean fallback_disabled; ++ krb5_boolean encts_disabled; + struct krb5_responder_context_st rctx; + krb5_preauthtype selected_preauth_type; + krb5_preauthtype allowed_preauth_type; +diff --git a/src/lib/krb5/krb/preauth_encts.c b/src/lib/krb5/krb/preauth_encts.c +index 45bf9da92..345701984 100644 +--- a/src/lib/krb5/krb/preauth_encts.c ++++ b/src/lib/krb5/krb/preauth_encts.c +@@ -28,6 +28,7 @@ + #include + #include + #include "int-proto.h" ++#include "init_creds_ctx.h" + + static krb5_error_code + encts_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata, +@@ -38,7 +39,10 @@ encts_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata, + krb5_data *encoded_previous_request, + krb5_pa_data *pa_data) + { +- cb->need_as_key(context, rock); ++ krb5_init_creds_context ctx = (krb5_init_creds_context)rock; ++ ++ if (!ctx->encts_disabled) ++ cb->need_as_key(context, rock); + return 0; + } + +@@ -51,6 +55,7 @@ encts_process(krb5_context context, krb5_clpreauth_moddata moddata, + krb5_prompter_fct prompter, void *prompter_data, + krb5_pa_data ***out_padata) + { ++ krb5_init_creds_context ctx = (krb5_init_creds_context)rock; + krb5_error_code ret; + krb5_pa_enc_ts pa_enc; + krb5_data *ts = NULL, *enc_ts = NULL; +@@ -60,6 +65,13 @@ encts_process(krb5_context context, krb5_clpreauth_moddata moddata, + + enc_data.ciphertext = empty_data(); + ++ if (ctx->encts_disabled) { ++ TRACE_PREAUTH_ENC_TS_DISABLED(context); ++ k5_setmsg(context, KRB5_PREAUTH_FAILED, ++ _("Encrypted timestamp is disabled")); ++ return KRB5_PREAUTH_FAILED; ++ } ++ + ret = cb->get_as_key(context, rock, &as_key); + if (ret) + goto cleanup; +diff --git a/src/tests/t_referral.py b/src/tests/t_referral.py +index 98fdf2925..e12fdc2e9 100755 +--- a/src/tests/t_referral.py ++++ b/src/tests/t_referral.py +@@ -126,4 +126,17 @@ r1.klist('user@KRBTEST2.COM', 'krbtgt/KRBTEST2.COM') + r1.kinit('abc@XYZ', 'pw', ['-E']) + r1.klist('abc\@XYZ@KRBTEST2.COM', 'krbtgt/KRBTEST2.COM') + ++# Test that disable_encrypted_timestamp persists across client ++# referrals. (This test relies on SPAKE not being enabled by default ++# on the KDC.) ++r2.run([kadminl, 'modprinc', '+preauth', 'user']) ++msgs = ('Encrypted timestamp (for ') ++r1.kinit('user', password('user'), ['-C'], expected_trace=msgs) ++dconf = {'realms': {'$realm': {'disable_encrypted_timestamp': 'true'}}} ++denv = r1.special_env('disable_encts', False, krb5_conf=dconf) ++msgs = ('Ignoring encrypted timestamp because it is disabled', ++ '/Encrypted timestamp is disabled') ++r1.kinit('user', None, ['-C'], env=denv, expected_code=1, expected_trace=msgs, ++ expected_msg='Encrypted timestamp is disabled') ++ + success('KDC host referral tests') diff --git a/krb5.spec b/krb5.spec index 7dbcdaf..e1681e2 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 6%{?dist} +Release: 7%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -91,6 +91,7 @@ Patch71: Log-when-non-root-ksu-authorization-fails.patch Patch72: Add-k5_dir_filenames-to-libkrb5support.patch Patch73: Process-profile-includedir-in-sorted-order.patch Patch74: Make-docs-build-python3-compatible.patch +Patch75: Add-flag-to-disable-encrypted-timestamp-on-client.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -742,6 +743,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jun 14 2018 Robbie Harwood - 1.16.1-7 +- Add flag to disable encrypted timestamp on client + * Thu Jun 14 2018 Robbie Harwood - 1.16.1-6 - Switch to python3-sphinx for docs - Resolves: #1590928 From 32e71bc9e74dbdb188bc985e37b6f0196e11bfef Mon Sep 17 00:00:00 2001 From: Bruno Goncalves Date: Fri, 15 Jun 2018 14:24:33 +0200 Subject: [PATCH 052/304] Updated tests for Fedora pipeline changes Workaround new hostname behavior. Also bump timeout to 15 for consistency. [rharwood@redhat.com: rewrote commit message] Merges: #3 --- tests/inplace-upgrade-sanity-test/runtest.sh | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/tests/inplace-upgrade-sanity-test/runtest.sh b/tests/inplace-upgrade-sanity-test/runtest.sh index db06748..cdd4744 100755 --- a/tests/inplace-upgrade-sanity-test/runtest.sh +++ b/tests/inplace-upgrade-sanity-test/runtest.sh @@ -37,12 +37,14 @@ TEST_ENTROPY_SOURCE=${TEST_ENTROPY_SOURCE:-no} echo TEST_ENTROPY_SOURCE=$TEST_ENTROPY_SOURCE hostnamectl set-hostname test.fedora.com -echo "`hostname -I` test.fedora.com" >>/etc/hosts + +host_ip=`hostname -I | awk '{print$1}'` +echo "$host_ip test.fedora.com" >> /etc/hosts krb5REALM1='ZMRAZ.COM' krb5REALM2='PKIS.NET' krb5HostName=`hostname` -krb5DomainName=`hostname -d` +krb5DomainName='fedora.com' krb5User='alice' krb5UserPass='alice' krb5UserKrbPass='aaa' @@ -143,12 +145,12 @@ _EOF rlRun "kadmin.local -r $krb5REALM2 -q \"addprinc -randkey host/$krb5HostName\"" rlRun "kadmin.local -r $krb5REALM2 -q \"addprinc -pw $krb5KDCPass krbtgt/$krb5REALM1@$krb5REALM2\"" rlRun "kadmin.local -r $krb5REALM2 -q \"addprinc -pw $krb5KDCPass krbtgt/$krb5REALM2@$krb5REALM1\"" - # Create test system user + # Create test system user [ $krb5User != "root" ] && rlRun "useradd $krb5User" rlRun "echo $krb5UserPass | passwd --stdin $krb5User" rlPhaseEnd fi - + rlPhaseStartTest "Daemon start and log file test" # Make sure there is enough entropy and start recording of the logs rlRun "rngd -r /dev/urandom" @@ -217,7 +219,7 @@ _EOF #!/usr/bin/expect -f set USER [lindex $argv 0] set HOST [lindex $argv 1] -set timeout 10 +set timeout 15 spawn ssh $USER@$HOST pwd expect { -re ".*(yes/no).*" { send -- "yes\r"; exp_continue } @@ -297,7 +299,7 @@ _EOF [ $krb5User != "root" ] && rlRun "userdel -r -f $krb5User" rlPhaseEnd fi - + rlPhaseStartCleanup rlRun "popd" rlRun "rm -r $TmpDir" From 97d3fa66d008489d627a743c25e719942ae7cc52 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 6 Jul 2018 10:59:48 -0400 Subject: [PATCH 053/304] Explicitly look for python2 in configure.in --- ...tly-look-for-python2-in-configure.in.patch | 816 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 821 insertions(+), 1 deletion(-) create mode 100644 Explicitly-look-for-python2-in-configure.in.patch diff --git a/Explicitly-look-for-python2-in-configure.in.patch b/Explicitly-look-for-python2-in-configure.in.patch new file mode 100644 index 0000000..cb6620f --- /dev/null +++ b/Explicitly-look-for-python2-in-configure.in.patch @@ -0,0 +1,816 @@ +From 1d0c0db7755076834519fd02c271a78bbf26bb19 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 3 Jul 2018 01:20:50 -0400 +Subject: [PATCH] Explicitly look for python2 in configure.in + +The executable "python" has traditionally been Python 2, but is +becoming more ambiguous as operating systems transition towards Python +3. Look for "python2" in the path in preference to "python", and +check that what we found isn't Python 3. + +Remove the "#!/usr/bin/python" headers at the start of Python test +scripts since we run them explicitly under python, not as executables. +Execute paste-kdcproxy.py via sys.executable in t_proxy.py so that it +doesn't need a #!/usr/bin/python header. + +ticket: 8709 (new) +(cherry picked from commit 2bd410ecdb366083fe9b4e5f6ac4b741b624230b) +--- + src/appl/gss-sample/t_gss_sample.py | 2 -- + src/appl/user_user/t_user2user.py | 1 - + src/configure.in | 9 ++++++--- + src/kadmin/dbutil/t_tdumputil.py | 2 -- + src/kdc/t_bigreply.py | 1 - + src/kdc/t_emptytgt.py | 1 - + src/kdc/t_workers.py | 1 - + src/lib/kdb/t_stringattr.py | 1 - + src/lib/krad/t_daemon.py | 2 -- + src/lib/krb5/ccache/t_cccol.py | 1 - + src/lib/krb5/krb/t_expire_warn.py | 2 -- + src/lib/krb5/krb/t_in_ccache_patypes.py | 2 -- + src/lib/krb5/krb/t_vfy_increds.py | 2 -- + src/lib/krb5/os/t_discover_uri.py | 1 - + src/tests/gssapi/t_authind.py | 1 - + src/tests/gssapi/t_ccselect.py | 2 -- + src/tests/gssapi/t_client_keytab.py | 1 - + src/tests/gssapi/t_enctypes.py | 1 - + src/tests/gssapi/t_export_cred.py | 1 - + src/tests/gssapi/t_gssapi.py | 1 - + src/tests/gssapi/t_s4u.py | 1 - + src/tests/jsonwalker.py | 2 -- + src/tests/t_audit.py | 1 - + src/tests/t_authdata.py | 1 - + src/tests/t_bogus_kdc_req.py | 2 -- + src/tests/t_ccache.py | 2 -- + src/tests/t_certauth.py | 1 - + src/tests/t_changepw.py | 1 - + src/tests/t_crossrealm.py | 2 -- + src/tests/t_cve-2012-1014.py | 2 -- + src/tests/t_cve-2012-1015.py | 2 -- + src/tests/t_cve-2013-1416.py | 2 -- + src/tests/t_cve-2013-1417.py | 2 -- + src/tests/t_dump.py | 1 - + src/tests/t_errmsg.py | 1 - + src/tests/t_etype_info.py | 1 - + src/tests/t_general.py | 1 - + src/tests/t_hooks.py | 1 - + src/tests/t_hostrealm.py | 1 - + src/tests/t_iprop.py | 2 -- + src/tests/t_kadm5_auth.py | 1 - + src/tests/t_kadm5_hook.py | 1 - + src/tests/t_kadmin_acl.py | 1 - + src/tests/t_kadmin_parsing.py | 1 - + src/tests/t_kdb.py | 1 - + src/tests/t_kdb_locking.py | 2 -- + src/tests/t_kdc_log.py | 2 -- + src/tests/t_kdcpolicy.py | 1 - + src/tests/t_keydata.py | 1 - + src/tests/t_keyrollover.py | 1 - + src/tests/t_keytab.py | 1 - + src/tests/t_kprop.py | 1 - + src/tests/t_localauth.py | 1 - + src/tests/t_mkey.py | 1 - + src/tests/t_otp.py | 2 -- + src/tests/t_pkinit.py | 1 - + src/tests/t_policy.py | 1 - + src/tests/t_preauth.py | 1 - + src/tests/t_princflags.py | 1 - + src/tests/t_proxy.py | 4 ++-- + src/tests/t_pwqual.py | 1 - + src/tests/t_rdreq.py | 1 - + src/tests/t_referral.py | 1 - + src/tests/t_renew.py | 1 - + src/tests/t_renprinc.py | 2 -- + src/tests/t_salt.py | 1 - + src/tests/t_sesskeynego.py | 1 - + src/tests/t_skew.py | 1 - + src/tests/t_sn2princ.py | 1 - + src/tests/t_spake.py | 1 - + src/tests/t_stringattr.py | 2 -- + src/tests/t_tabdump.py | 1 - + src/tests/t_unlockiter.py | 1 - + src/tests/t_y2038.py | 1 - + src/util/paste-kdcproxy.py | 1 - + 75 files changed, 8 insertions(+), 99 deletions(-) + +diff --git a/src/appl/gss-sample/t_gss_sample.py b/src/appl/gss-sample/t_gss_sample.py +index 0299e4590..2f537823a 100755 +--- a/src/appl/gss-sample/t_gss_sample.py ++++ b/src/appl/gss-sample/t_gss_sample.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + # Copyright (C) 2010 by the Massachusetts Institute of Technology. + # All rights reserved. + # +diff --git a/src/appl/user_user/t_user2user.py b/src/appl/user_user/t_user2user.py +index 2a7d03f8d..2c054f181 100755 +--- a/src/appl/user_user/t_user2user.py ++++ b/src/appl/user_user/t_user2user.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # If uuserver is not compiled under -DDEBUG, then set to 0 +diff --git a/src/configure.in b/src/configure.in +index 08c63beca..3f45784b5 100644 +--- a/src/configure.in ++++ b/src/configure.in +@@ -1098,13 +1098,16 @@ fi + AC_SUBST(HAVE_RUNTEST) + + # For Python tests. +-AC_CHECK_PROG(PYTHON,python,python) ++AC_CHECK_PROG(PYTHON,python2,python2) ++if text x"$PYTHON" = x; then ++ AC_CHECK_PROG(PYTHON,python,python) ++fi + HAVE_PYTHON=no + if test x"$PYTHON" != x; then + # k5test.py requires python 2.4 (for the subprocess module). + # Some code needs python 2.5 (for syntax like conditional expressions). +- vercheck="import sys;sys.exit((sys.hexversion < 0x2050000) and 1 or 0)" +- if python -c "$vercheck"; then ++ wantver="(sys.hexversion >= 0x2050000 and sys.hexversion < 0x3000000)" ++ if "$PYTHON" -c "import sys; sys.exit(not $wantver and 1 or 0)"; then + HAVE_PYTHON=yes + fi + fi +diff --git a/src/kadmin/dbutil/t_tdumputil.py b/src/kadmin/dbutil/t_tdumputil.py +index 5d7ac38d2..52e356533 100755 +--- a/src/kadmin/dbutil/t_tdumputil.py ++++ b/src/kadmin/dbutil/t_tdumputil.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + from k5test import * + from subprocess import * + +diff --git a/src/kdc/t_bigreply.py b/src/kdc/t_bigreply.py +index 6bc9a8fe0..b6300154f 100644 +--- a/src/kdc/t_bigreply.py ++++ b/src/kdc/t_bigreply.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Set the maximum UDP reply size very low, so that all replies go +diff --git a/src/kdc/t_emptytgt.py b/src/kdc/t_emptytgt.py +index 2d0432e33..c601c010c 100755 +--- a/src/kdc/t_emptytgt.py ++++ b/src/kdc/t_emptytgt.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + realm = K5Realm(create_host=False) +diff --git a/src/kdc/t_workers.py b/src/kdc/t_workers.py +index 6dd4f6805..8de3f34d9 100755 +--- a/src/kdc/t_workers.py ++++ b/src/kdc/t_workers.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + realm = K5Realm(start_kdc=False, create_host=False) +diff --git a/src/lib/kdb/t_stringattr.py b/src/lib/kdb/t_stringattr.py +index 085e179e4..93e2b0c01 100755 +--- a/src/lib/kdb/t_stringattr.py ++++ b/src/lib/kdb/t_stringattr.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + realm = K5Realm(create_kdb=False) +diff --git a/src/lib/krad/t_daemon.py b/src/lib/krad/t_daemon.py +index dcda0050b..7d7a5d0c8 100755 +--- a/src/lib/krad/t_daemon.py ++++ b/src/lib/krad/t_daemon.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +-# + # Copyright 2013 Red Hat, Inc. All rights reserved. + # + # Redistribution and use in source and binary forms, with or without +diff --git a/src/lib/krb5/ccache/t_cccol.py b/src/lib/krb5/ccache/t_cccol.py +index f7f178564..1467512e2 100755 +--- a/src/lib/krb5/ccache/t_cccol.py ++++ b/src/lib/krb5/ccache/t_cccol.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + realm = K5Realm(create_kdb=False) +diff --git a/src/lib/krb5/krb/t_expire_warn.py b/src/lib/krb5/krb/t_expire_warn.py +index aed39e399..781f2728a 100755 +--- a/src/lib/krb5/krb/t_expire_warn.py ++++ b/src/lib/krb5/krb/t_expire_warn.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + # Copyright (C) 2010 by the Massachusetts Institute of Technology. + # All rights reserved. + # +diff --git a/src/lib/krb5/krb/t_in_ccache_patypes.py b/src/lib/krb5/krb/t_in_ccache_patypes.py +index c04234064..b2812688c 100755 +--- a/src/lib/krb5/krb/t_in_ccache_patypes.py ++++ b/src/lib/krb5/krb/t_in_ccache_patypes.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + # Copyright (C) 2010,2012 by the Massachusetts Institute of Technology. + # All rights reserved. + # +diff --git a/src/lib/krb5/krb/t_vfy_increds.py b/src/lib/krb5/krb/t_vfy_increds.py +index c820cc690..b899308a8 100755 +--- a/src/lib/krb5/krb/t_vfy_increds.py ++++ b/src/lib/krb5/krb/t_vfy_increds.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + # Copyright (C) 2011 by the Massachusetts Institute of Technology. + # All rights reserved. + # +diff --git a/src/lib/krb5/os/t_discover_uri.py b/src/lib/krb5/os/t_discover_uri.py +index 278f98371..87bac1792 100644 +--- a/src/lib/krb5/os/t_discover_uri.py ++++ b/src/lib/krb5/os/t_discover_uri.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + entries = ('URI _kerberos.TEST krb5srv::kkdcp:https://kdc1 1 1\n', +diff --git a/src/tests/gssapi/t_authind.py b/src/tests/gssapi/t_authind.py +index 84793beb6..af1741a23 100644 +--- a/src/tests/gssapi/t_authind.py ++++ b/src/tests/gssapi/t_authind.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Test authentication indicators. Load the test preauth module so we +diff --git a/src/tests/gssapi/t_ccselect.py b/src/tests/gssapi/t_ccselect.py +index 3503f9269..cd62da231 100755 +--- a/src/tests/gssapi/t_ccselect.py ++++ b/src/tests/gssapi/t_ccselect.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + # Copyright (C) 2011 by the Massachusetts Institute of Technology. + # All rights reserved. + +diff --git a/src/tests/gssapi/t_client_keytab.py b/src/tests/gssapi/t_client_keytab.py +index 2da87f45b..e474a27c7 100755 +--- a/src/tests/gssapi/t_client_keytab.py ++++ b/src/tests/gssapi/t_client_keytab.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Set up a basic realm and a client keytab containing two user principals. +diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py +index f513db2b5..ee43ff028 100755 +--- a/src/tests/gssapi/t_enctypes.py ++++ b/src/tests/gssapi/t_enctypes.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Define some convenience abbreviations for enctypes we will see in +diff --git a/src/tests/gssapi/t_export_cred.py b/src/tests/gssapi/t_export_cred.py +index b98962788..89167bcc5 100755 +--- a/src/tests/gssapi/t_export_cred.py ++++ b/src/tests/gssapi/t_export_cred.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Test gss_export_cred and gss_import_cred for initiator creds, +diff --git a/src/tests/gssapi/t_gssapi.py b/src/tests/gssapi/t_gssapi.py +index 6da5fceff..a7dda20fb 100755 +--- a/src/tests/gssapi/t_gssapi.py ++++ b/src/tests/gssapi/t_gssapi.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Test krb5 negotiation under SPNEGO for all enctype configurations. Also +diff --git a/src/tests/gssapi/t_s4u.py b/src/tests/gssapi/t_s4u.py +index e4cd68469..fc9d9e8a4 100755 +--- a/src/tests/gssapi/t_s4u.py ++++ b/src/tests/gssapi/t_s4u.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + realm = K5Realm(create_host=False, get_creds=False) +diff --git a/src/tests/jsonwalker.py b/src/tests/jsonwalker.py +index 265c69c70..942ca2db7 100644 +--- a/src/tests/jsonwalker.py ++++ b/src/tests/jsonwalker.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + import sys + try: + import cjson +diff --git a/src/tests/t_audit.py b/src/tests/t_audit.py +index 00e96bfea..0f880edb2 100755 +--- a/src/tests/t_audit.py ++++ b/src/tests/t_audit.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + conf = {'plugins': {'audit': { +diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py +index 8a577b4b1..5cff80348 100644 +--- a/src/tests/t_authdata.py ++++ b/src/tests/t_authdata.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Load the sample KDC authdata module. +diff --git a/src/tests/t_bogus_kdc_req.py b/src/tests/t_bogus_kdc_req.py +index b6208ca68..a101c0e10 100755 +--- a/src/tests/t_bogus_kdc_req.py ++++ b/src/tests/t_bogus_kdc_req.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + import base64 + import socket + from k5test import * +diff --git a/src/tests/t_ccache.py b/src/tests/t_ccache.py +index 61d549b7b..a913eb025 100755 +--- a/src/tests/t_ccache.py ++++ b/src/tests/t_ccache.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + # Copyright (C) 2011 by the Massachusetts Institute of Technology. + # All rights reserved. + +diff --git a/src/tests/t_certauth.py b/src/tests/t_certauth.py +index e64a57b0d..9c7094525 100644 +--- a/src/tests/t_certauth.py ++++ b/src/tests/t_certauth.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Skip this test if pkinit wasn't built. +diff --git a/src/tests/t_changepw.py b/src/tests/t_changepw.py +index 37fe4fce1..211cda6c3 100755 +--- a/src/tests/t_changepw.py ++++ b/src/tests/t_changepw.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # This file is intended to cover any password-changing mechanism. For +diff --git a/src/tests/t_crossrealm.py b/src/tests/t_crossrealm.py +index 4d595dca6..09028bfa7 100755 +--- a/src/tests/t_crossrealm.py ++++ b/src/tests/t_crossrealm.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + # Copyright (C) 2011 by the Massachusetts Institute of Technology. + # All rights reserved. + # +diff --git a/src/tests/t_cve-2012-1014.py b/src/tests/t_cve-2012-1014.py +index e02162d6c..dcff95f6e 100755 +--- a/src/tests/t_cve-2012-1014.py ++++ b/src/tests/t_cve-2012-1014.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + import base64 + import socket + from k5test import * +diff --git a/src/tests/t_cve-2012-1015.py b/src/tests/t_cve-2012-1015.py +index e00c4dc90..28b1e619b 100755 +--- a/src/tests/t_cve-2012-1015.py ++++ b/src/tests/t_cve-2012-1015.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + import base64 + import socket + from k5test import * +diff --git a/src/tests/t_cve-2013-1416.py b/src/tests/t_cve-2013-1416.py +index 94fb6d5ef..8c4391a86 100755 +--- a/src/tests/t_cve-2013-1416.py ++++ b/src/tests/t_cve-2013-1416.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + from k5test import * + + realm = K5Realm() +diff --git a/src/tests/t_cve-2013-1417.py b/src/tests/t_cve-2013-1417.py +index c26930a30..ce47d21ca 100755 +--- a/src/tests/t_cve-2013-1417.py ++++ b/src/tests/t_cve-2013-1417.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + from k5test import * + + realm = K5Realm(realm='TEST') +diff --git a/src/tests/t_dump.py b/src/tests/t_dump.py +index 8a9462bd8..2cfeada6c 100755 +--- a/src/tests/t_dump.py ++++ b/src/tests/t_dump.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + from filecmp import cmp + +diff --git a/src/tests/t_errmsg.py b/src/tests/t_errmsg.py +index c9ae6637f..4aacf4e0a 100755 +--- a/src/tests/t_errmsg.py ++++ b/src/tests/t_errmsg.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + realm = K5Realm(create_kdb=False) +diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py +index b2eb0f7af..b12fb53c8 100644 +--- a/src/tests/t_etype_info.py ++++ b/src/tests/t_etype_info.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac des-cbc-crc:afs3' +diff --git a/src/tests/t_general.py b/src/tests/t_general.py +index 91ad0cb8a..96ba8a4b0 100755 +--- a/src/tests/t_general.py ++++ b/src/tests/t_general.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + for realm in multipass_realms(create_host=False): +diff --git a/src/tests/t_hooks.py b/src/tests/t_hooks.py +index 58dff3ae7..4fd3822e8 100755 +--- a/src/tests/t_hooks.py ++++ b/src/tests/t_hooks.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Test that KDC send and recv hooks work correctly. +diff --git a/src/tests/t_hostrealm.py b/src/tests/t_hostrealm.py +index 224c067ef..256ba2a38 100755 +--- a/src/tests/t_hostrealm.py ++++ b/src/tests/t_hostrealm.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + plugin = os.path.join(buildtop, "plugins", "hostrealm", "test", +diff --git a/src/tests/t_iprop.py b/src/tests/t_iprop.py +index 8e23cd5de..9cbeb3e68 100755 +--- a/src/tests/t_iprop.py ++++ b/src/tests/t_iprop.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + import os + import re + +diff --git a/src/tests/t_kadm5_auth.py b/src/tests/t_kadm5_auth.py +index ba4ab8ef1..6e0f42b08 100644 +--- a/src/tests/t_kadm5_auth.py ++++ b/src/tests/t_kadm5_auth.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Create a realm with the welcomer and bouncer kadm5_auth test modules +diff --git a/src/tests/t_kadm5_hook.py b/src/tests/t_kadm5_hook.py +index c1c8c9419..32fab781d 100755 +--- a/src/tests/t_kadm5_hook.py ++++ b/src/tests/t_kadm5_hook.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + plugin = os.path.join(buildtop, "plugins", "kadm5_hook", "test", +diff --git a/src/tests/t_kadmin_acl.py b/src/tests/t_kadmin_acl.py +index 42bdf423c..01a3eda29 100755 +--- a/src/tests/t_kadmin_acl.py ++++ b/src/tests/t_kadmin_acl.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + import os + +diff --git a/src/tests/t_kadmin_parsing.py b/src/tests/t_kadmin_parsing.py +index 8de387c64..bebb01488 100644 +--- a/src/tests/t_kadmin_parsing.py ++++ b/src/tests/t_kadmin_parsing.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # This file contains tests for kadmin command parsing. Principal +diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py +index 6e563b103..983cd93c8 100755 +--- a/src/tests/t_kdb.py ++++ b/src/tests/t_kdb.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + import time + from itertools import imap +diff --git a/src/tests/t_kdb_locking.py b/src/tests/t_kdb_locking.py +index aac0a220f..b5afd6d23 100755 +--- a/src/tests/t_kdb_locking.py ++++ b/src/tests/t_kdb_locking.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + # This is a regression test for + # https://bugzilla.redhat.com/show_bug.cgi?id=586032 . + # +diff --git a/src/tests/t_kdc_log.py b/src/tests/t_kdc_log.py +index 8ddb7691b..1b14828de 100755 +--- a/src/tests/t_kdc_log.py ++++ b/src/tests/t_kdc_log.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + from k5test import * + + # Make a TGS request with an expired ticket. +diff --git a/src/tests/t_kdcpolicy.py b/src/tests/t_kdcpolicy.py +index 5b198bb43..a44adfdb5 100644 +--- a/src/tests/t_kdcpolicy.py ++++ b/src/tests/t_kdcpolicy.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + from datetime import datetime + import re +diff --git a/src/tests/t_keydata.py b/src/tests/t_keydata.py +index 5c04a8523..b37233b21 100755 +--- a/src/tests/t_keydata.py ++++ b/src/tests/t_keydata.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + realm = K5Realm(create_user=False, create_host=False) +diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py +index bfd38914b..7c8d828f0 100755 +--- a/src/tests/t_keyrollover.py ++++ b/src/tests/t_keyrollover.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + rollover_krb5_conf = {'libdefaults': {'allow_weak_crypto': 'true'}} +diff --git a/src/tests/t_keytab.py b/src/tests/t_keytab.py +index a48740ba5..228c36334 100755 +--- a/src/tests/t_keytab.py ++++ b/src/tests/t_keytab.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + for realm in multipass_realms(create_user=False): +diff --git a/src/tests/t_kprop.py b/src/tests/t_kprop.py +index 39169675d..f352ec8d7 100755 +--- a/src/tests/t_kprop.py ++++ b/src/tests/t_kprop.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + conf_slave = {'dbmodules': {'db': {'database_name': '$testdir/db.slave'}}} +diff --git a/src/tests/t_localauth.py b/src/tests/t_localauth.py +index aa625d038..ebc9cdfde 100755 +--- a/src/tests/t_localauth.py ++++ b/src/tests/t_localauth.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Unfortunately, we can't reliably test the k5login module. We can control +diff --git a/src/tests/t_mkey.py b/src/tests/t_mkey.py +index 615cd91ca..48a533059 100755 +--- a/src/tests/t_mkey.py ++++ b/src/tests/t_mkey.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + import random + import re +diff --git a/src/tests/t_otp.py b/src/tests/t_otp.py +index 9b18ff94b..0fd35d576 100755 +--- a/src/tests/t_otp.py ++++ b/src/tests/t_otp.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +-# + # Author: Nathaniel McCallum + # + # Copyright (c) 2013 Red Hat, Inc. +diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py +index 0e964c689..850db4fdd 100755 +--- a/src/tests/t_pkinit.py ++++ b/src/tests/t_pkinit.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Skip this test if pkinit wasn't built. +diff --git a/src/tests/t_policy.py b/src/tests/t_policy.py +index 26c4e466e..eb3865d7c 100755 +--- a/src/tests/t_policy.py ++++ b/src/tests/t_policy.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + import re + +diff --git a/src/tests/t_preauth.py b/src/tests/t_preauth.py +index 32e35b08b..f597c3d08 100644 +--- a/src/tests/t_preauth.py ++++ b/src/tests/t_preauth.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Test that the kdcpreauth client_keyblock() callback matches the key +diff --git a/src/tests/t_princflags.py b/src/tests/t_princflags.py +index 6378ef94f..aa3660217 100755 +--- a/src/tests/t_princflags.py ++++ b/src/tests/t_princflags.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + from princflags import * + import re +diff --git a/src/tests/t_proxy.py b/src/tests/t_proxy.py +index 4e86fce8f..ff1929bef 100755 +--- a/src/tests/t_proxy.py ++++ b/src/tests/t_proxy.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Skip this test if we're missing proxy functionality or parts of the proxy. +@@ -62,7 +61,8 @@ def start_proxy(realm, keycertpem): + conf.write('kpasswd = kpasswd://localhost:%d\n' % (realm.portbase + 2)) + conf.close() + realm.env['KDCPROXY_CONFIG'] = proxy_conf_path +- cmd = [proxy_exec_path, str(realm.server_port()), keycertpem] ++ cmd = [sys.executable, proxy_exec_path, str(realm.server_port()), ++ keycertpem] + return realm.start_server(cmd, sentinel='proxy server ready') + + # Fail: untrusted issuer and hostname doesn't match. +diff --git a/src/tests/t_pwqual.py b/src/tests/t_pwqual.py +index 011110bd1..171805697 100755 +--- a/src/tests/t_pwqual.py ++++ b/src/tests/t_pwqual.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + plugin = os.path.join(buildtop, "plugins", "pwqual", "test", "pwqual_test.so") +diff --git a/src/tests/t_rdreq.py b/src/tests/t_rdreq.py +index f67c34866..00cd5cbb4 100755 +--- a/src/tests/t_rdreq.py ++++ b/src/tests/t_rdreq.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + conf = {'realms': {'$realm': {'supported_enctypes': 'aes256-cts aes128-cts'}}} +diff --git a/src/tests/t_referral.py b/src/tests/t_referral.py +index e12fdc2e9..2f29d5712 100755 +--- a/src/tests/t_referral.py ++++ b/src/tests/t_referral.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Create a pair of realms, where KRBTEST1.COM can authenticate to +diff --git a/src/tests/t_renew.py b/src/tests/t_renew.py +index 034190c80..67b4182fd 100755 +--- a/src/tests/t_renew.py ++++ b/src/tests/t_renew.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + from datetime import datetime + import re +diff --git a/src/tests/t_renprinc.py b/src/tests/t_renprinc.py +index cc780839a..46cbed441 100755 +--- a/src/tests/t_renprinc.py ++++ b/src/tests/t_renprinc.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + # Copyright (C) 2011 by the Massachusetts Institute of Technology. + # All rights reserved. + +diff --git a/src/tests/t_salt.py b/src/tests/t_salt.py +index ddb1905ed..278911a22 100755 +--- a/src/tests/t_salt.py ++++ b/src/tests/t_salt.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + import re + +diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py +index 732c306ea..448092387 100755 +--- a/src/tests/t_sesskeynego.py ++++ b/src/tests/t_sesskeynego.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + import re + +diff --git a/src/tests/t_skew.py b/src/tests/t_skew.py +index f2ae06695..36d5a95c5 100755 +--- a/src/tests/t_skew.py ++++ b/src/tests/t_skew.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Create a realm with the KDC one hour in the past. +diff --git a/src/tests/t_sn2princ.py b/src/tests/t_sn2princ.py +index 19a0d2fa7..e2c85e665 100755 +--- a/src/tests/t_sn2princ.py ++++ b/src/tests/t_sn2princ.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + offline = (len(args) > 0 and args[0] != "no") +diff --git a/src/tests/t_spake.py b/src/tests/t_spake.py +index 5b47e62d3..65af46d18 100644 +--- a/src/tests/t_spake.py ++++ b/src/tests/t_spake.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # The name and number of each supported SPAKE group. +diff --git a/src/tests/t_stringattr.py b/src/tests/t_stringattr.py +index 5672a0f20..c2dc348e9 100755 +--- a/src/tests/t_stringattr.py ++++ b/src/tests/t_stringattr.py +@@ -1,5 +1,3 @@ +-#!/usr/bin/python +- + # Copyright (C) 2011 by the Massachusetts Institute of Technology. + # All rights reserved. + +diff --git a/src/tests/t_tabdump.py b/src/tests/t_tabdump.py +index 066e48418..2a86136dd 100755 +--- a/src/tests/t_tabdump.py ++++ b/src/tests/t_tabdump.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + import csv +diff --git a/src/tests/t_unlockiter.py b/src/tests/t_unlockiter.py +index 2a438e99a..603cf721d 100755 +--- a/src/tests/t_unlockiter.py ++++ b/src/tests/t_unlockiter.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # Default KDB iteration is locked. Expect write lock failure unless +diff --git a/src/tests/t_y2038.py b/src/tests/t_y2038.py +index 02e946df4..42a4ff7ed 100644 +--- a/src/tests/t_y2038.py ++++ b/src/tests/t_y2038.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + from k5test import * + + # These tests will become much less important after the y2038 boundary +diff --git a/src/util/paste-kdcproxy.py b/src/util/paste-kdcproxy.py +index 1e56b8954..30467fd74 100755 +--- a/src/util/paste-kdcproxy.py ++++ b/src/util/paste-kdcproxy.py +@@ -1,4 +1,3 @@ +-#!/usr/bin/python + import kdcproxy + from paste import httpserver + import os diff --git a/krb5.spec b/krb5.spec index e1681e2..a67c921 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 7%{?dist} +Release: 8%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -92,6 +92,7 @@ Patch72: Add-k5_dir_filenames-to-libkrb5support.patch Patch73: Process-profile-includedir-in-sorted-order.patch Patch74: Make-docs-build-python3-compatible.patch Patch75: Add-flag-to-disable-encrypted-timestamp-on-client.patch +Patch76: Explicitly-look-for-python2-in-configure.in.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -743,6 +744,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Jul 06 2018 Robbie Harwood - 1.16.1-8 +- Explicitly look for python2 in configure.in + * Thu Jun 14 2018 Robbie Harwood - 1.16.1-7 - Add flag to disable encrypted timestamp on client From 2fc18e91429bfa82a8a58117317dd0a77dc9d2ad Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 6 Jul 2018 15:27:21 +0000 Subject: [PATCH 054/304] Add BuildRequires on python2 so we can run tests at build-time --- krb5.spec | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index a67c921..35068e1 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 8%{?dist} +Release: 9%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -152,6 +152,9 @@ BuildRequires: yasm BuildRequires: nss_wrapper BuildRequires: socket_wrapper +# To run TESTS, we need python2 +BuildRequires: python2 + %description Kerberos V5 is a trusted-third-party network authentication system, which can improve your network's security by eliminating the insecure @@ -744,6 +747,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Jul 06 2018 Robbie Harwood - 1.16.1-9 +- Add BuildRequires on python2 so we can run tests at build-time + * Fri Jul 06 2018 Robbie Harwood - 1.16.1-8 - Explicitly look for python2 in configure.in From 816afcf8e2f3acc8b831320e7fd9de1cad937d0e Mon Sep 17 00:00:00 2001 From: Jason Tibbitts Date: Tue, 10 Jul 2018 01:32:54 -0500 Subject: [PATCH 055/304] Remove needless use of %defattr --- krb5.spec | 7 ------- 1 file changed, 7 deletions(-) diff --git a/krb5.spec b/krb5.spec index 35068e1..b022c73 100644 --- a/krb5.spec +++ b/krb5.spec @@ -566,7 +566,6 @@ exit 0 %ldconfig_scriptlets -n libkadm5 %files workstation -%defattr(-,root,root,-) %doc src/config-files/services.append %doc src/config-files/krb5.conf %doc build-html/* @@ -601,7 +600,6 @@ exit 0 %config(noreplace) /etc/pam.d/ksu %files server -%defattr(-,root,root,-) %docdir %{_mandir} %doc build-pdf/admin.pdf build-pdf/build.pdf %doc src/config-files/kdc.conf @@ -655,7 +653,6 @@ exit 0 %{_mandir}/man8/sserver.8* %files server-ldap -%defattr(-,root,root,-) %docdir %{_mandir} %doc src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif %doc src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema @@ -670,7 +667,6 @@ exit 0 %{_sbindir}/kdb5_ldap_util %files libs -f %{gettext_domain}.lang -%defattr(-,root,root,-) %doc README NOTICE %{!?_licensedir:%global license %%doc} %license LICENSE @@ -703,14 +699,12 @@ exit 0 %dir %{_var}/kerberos/krb5/user %files pkinit -%defattr(-,root,root,-) %dir %{_libdir}/krb5 %dir %{_libdir}/krb5/plugins %dir %{_libdir}/krb5/plugins/preauth %{_libdir}/krb5/plugins/preauth/pkinit.so %files devel -%defattr(-,root,root,-) %docdir %{_mandir} %doc build-pdf/appdev.pdf build-pdf/plugindev.pdf @@ -738,7 +732,6 @@ exit 0 %{_sbindir}/uuserver %files -n libkadm5 -%defattr(-,root,root,-) %{_libdir}/libkadm5clnt.so %{_libdir}/libkadm5clnt_mit.so %{_libdir}/libkadm5srv.so From 40a05d03472a1bcc7aa57f32273357732b2fe895 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 10 Jul 2018 17:34:02 -0400 Subject: [PATCH 056/304] Use SHA-256 instead of MD5 for audit ticket IDs --- ...-instead-of-MD5-for-audit-ticket-IDs.patch | 53 +++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 58 insertions(+), 1 deletion(-) create mode 100644 Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch diff --git a/Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch b/Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch new file mode 100644 index 0000000..26df25a --- /dev/null +++ b/Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch @@ -0,0 +1,53 @@ +From a9bc03fe03ef4b00bcdad13c99bb4c376a8b9964 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 10 Jul 2018 16:17:15 -0400 +Subject: [PATCH] Use SHA-256 instead of MD5 for audit ticket IDs + +ticket: 8711 (new) +(cherry picked from commit c1e1bfa26bd2f045e88e6013c500fca9428c98f3) +--- + src/kdc/kdc_audit.c | 21 ++++++++++----------- + 1 file changed, 10 insertions(+), 11 deletions(-) + +diff --git a/src/kdc/kdc_audit.c b/src/kdc/kdc_audit.c +index c9a7f9f9d..f40913dc8 100644 +--- a/src/kdc/kdc_audit.c ++++ b/src/kdc/kdc_audit.c +@@ -146,7 +146,7 @@ kau_make_tkt_id(krb5_context context, + { + krb5_error_code ret = 0; + char *hash = NULL, *ptr; +- krb5_checksum cksum; ++ uint8_t hashbytes[K5_SHA256_HASHLEN]; + unsigned int i; + + *out = NULL; +@@ -154,19 +154,18 @@ kau_make_tkt_id(krb5_context context, + if (ticket == NULL) + return EINVAL; + +- ret = krb5_c_make_checksum(context, CKSUMTYPE_RSA_MD5, NULL, 0, +- &ticket->enc_part.ciphertext, &cksum); ++ ret = k5_sha256(&ticket->enc_part.ciphertext, 1, hashbytes); + if (ret) + return ret; + +- hash = k5alloc(cksum.length * 2 + 1, &ret); +- if (hash != NULL) { +- for (i = 0, ptr = hash; i < cksum.length; i++, ptr += 2) +- snprintf(ptr, 3, "%02X", cksum.contents[i]); +- *ptr = '\0'; +- *out = hash; +- } +- krb5_free_checksum_contents(context, &cksum); ++ hash = k5alloc(sizeof(hashbytes) * 2 + 1, &ret); ++ if (hash == NULL) ++ return ret; ++ ++ for (i = 0, ptr = hash; i < sizeof(hashbytes); i++, ptr += 2) ++ snprintf(ptr, 3, "%02X", hashbytes[i]); ++ *ptr = '\0'; ++ *out = hash; + + return 0; + } diff --git a/krb5.spec b/krb5.spec index b022c73..0a258c1 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 9%{?dist} +Release: 10%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -93,6 +93,7 @@ Patch73: Process-profile-includedir-in-sorted-order.patch Patch74: Make-docs-build-python3-compatible.patch Patch75: Add-flag-to-disable-encrypted-timestamp-on-client.patch Patch76: Explicitly-look-for-python2-in-configure.in.patch +Patch77: Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -740,6 +741,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Jul 10 2018 Robbie Harwood - 1.16.1-10 +- Use SHA-256 instead of MD5 for audit ticket IDs + * Fri Jul 06 2018 Robbie Harwood - 1.16.1-9 - Add BuildRequires on python2 so we can run tests at build-time From 50f81aad57475cfdcdb01efc857abf00b6769a04 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 11 Jul 2018 16:49:24 +0000 Subject: [PATCH 057/304] Add build dependency on gcc --- krb5.spec | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/krb5.spec b/krb5.spec index 0a258c1..8229c33 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 10%{?dist} +Release: 11%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -360,7 +360,8 @@ CPPFLAGS="`echo $DEFINES $INCLUDES`" --with-system-verto \ --with-pam \ --with-selinux \ - --with-prng-alg=os + --with-prng-alg=os \ + || (cat config.log; exit 1) # Now build it. make popd @@ -741,6 +742,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Jul 11 2018 Robbie Harwood - 1.16.1-11 +- Add build dependency on gcc + * Tue Jul 10 2018 Robbie Harwood - 1.16.1-10 - Use SHA-256 instead of MD5 for audit ticket IDs From 18245c6b0fddecbbd19b29c66cb4ab97b3d15516 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 11 Jul 2018 12:56:14 -0400 Subject: [PATCH 058/304] Actually add the dependency this time --- krb5.spec | 1 + 1 file changed, 1 insertion(+) diff --git a/krb5.spec b/krb5.spec index 8229c33..a4fac33 100644 --- a/krb5.spec +++ b/krb5.spec @@ -99,6 +99,7 @@ License: MIT URL: http://web.mit.edu/kerberos/www/ Group: System Environment/Libraries BuildRequires: autoconf, bison, cmake, flex, gawk, gettext, pkgconfig, sed +BuildRequires: gcc BuildRequires: libcom_err-devel, libedit-devel, libss-devel BuildRequires: gzip, ncurses-devel BuildRequires: python3-sphinx, texlive-pdftex, latexmk From 6bb371b55524445ee942bafebf6fda48325e6c15 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 12 Jul 2018 13:08:20 -0400 Subject: [PATCH 059/304] Convert Python tests to Python 3 --- Add-k5test-mark-function.patch | 60 +++ Convert-Python-tests-to-Python-3.patch | 536 +++++++++++++++++++++++++ krb5.spec | 12 +- 3 files changed, 603 insertions(+), 5 deletions(-) create mode 100644 Add-k5test-mark-function.patch create mode 100644 Convert-Python-tests-to-Python-3.patch diff --git a/Add-k5test-mark-function.patch b/Add-k5test-mark-function.patch new file mode 100644 index 0000000..0b2b9fa --- /dev/null +++ b/Add-k5test-mark-function.patch @@ -0,0 +1,60 @@ +From 68b61c6d6402c0ad57509705137c92ae814ace27 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 18 Apr 2018 19:21:40 -0400 +Subject: [PATCH] Add k5test mark() function + +Make it easier to locate a failing command in long Python test scripts +by allowing the script to output marks, and displaying the most recent +mark with command failures. + +(cherry picked from commit 4e813204ac3dace93297f47d64dfc0aaecc370f8) +--- + src/util/k5test.py | 14 ++++++++++++++ + 1 file changed, 14 insertions(+) + +diff --git a/src/util/k5test.py b/src/util/k5test.py +index 4d30baf40..bc32877a7 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -141,6 +141,11 @@ Scripts may use the following functions and variables: + added newline) in testlog, and write it to stdout if running + verbosely. + ++* mark(message): Place a divider message in the test output, to make ++ it easier to determine what part of the test script a command ++ invocation belongs to. The last mark message will also be displayed ++ if a command invocation fails. Do not include a newline in message. ++ + * which(progname): Return the location of progname in the executable + path, or None if it is not found. + +@@ -376,6 +381,8 @@ def fail(msg): + """Print a message and exit with failure.""" + global _current_pass + print "*** Failure:", msg ++ if _last_mark: ++ print "*** Last mark: %s" % _last_mark + if _last_cmd: + print "*** Last command (#%d): %s" % (_cmd_index - 1, _last_cmd) + if _last_cmd_output: +@@ -392,6 +399,12 @@ def success(msg): + _success = True + + ++def mark(msg): ++ global _last_mark ++ output('\n====== %s ======\n' % msg) ++ _last_mark = msg ++ ++ + def skipped(whatmsg, whymsg): + output('*** Skipping: %s: %s\n' % (whatmsg, whymsg), force_verbose=True) + f = open(os.path.join(buildtop, 'skiptests'), 'a') +@@ -1275,6 +1288,7 @@ atexit.register(_onexit) + signal.signal(signal.SIGINT, _onsigint) + _outfile = open('testlog', 'w') + _cmd_index = 1 ++_last_mark = None + _last_cmd = None + _last_cmd_output = None + buildtop = _find_buildtop() diff --git a/Convert-Python-tests-to-Python-3.patch b/Convert-Python-tests-to-Python-3.patch new file mode 100644 index 0000000..5f5dc23 --- /dev/null +++ b/Convert-Python-tests-to-Python-3.patch @@ -0,0 +1,536 @@ +From 2bc365f12282cdd83a191478b97f4ea0d9aa60dd Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 19 Feb 2018 21:10:09 -0500 +Subject: [PATCH] Convert Python tests to Python 3 + +Look for python3 in configure.in and verify that we got it. Convert +test code to conform to Python 3. + +ticket: 8710 (new) +(cherry picked from commit e23d24beacb73581bbf4351250f3955e6fd44361) +[rharwood@redhat.com: Context skew due to not having LMDB in tests] +--- + src/Makefile.in | 1 + + src/configure.in | 6 ++-- + src/kadmin/dbutil/t_tdumputil.py | 4 +-- + src/tests/jsonwalker.py | 16 +++++------ + src/tests/t_cve-2012-1014.py | 2 +- + src/tests/t_cve-2012-1015.py | 2 +- + src/tests/t_hostrealm.py | 4 ++- + src/tests/t_kdb.py | 11 ++++--- + src/tests/t_keytab.py | 34 +++++++++++----------- + src/tests/t_mkey.py | 6 ++-- + src/tests/t_otp.py | 7 +++-- + src/tests/t_tabdump.py | 4 +-- + src/util/Makefile.in | 1 + + src/util/k5test.py | 49 +++++++++++++++++--------------- + src/util/princflags.py | 25 ++++++++-------- + 15 files changed, 88 insertions(+), 84 deletions(-) + +diff --git a/src/Makefile.in b/src/Makefile.in +index 77beff8bc..79b8d5f98 100644 +--- a/src/Makefile.in ++++ b/src/Makefile.in +@@ -533,6 +533,7 @@ runenv.py: pyrunenv.vals + + clean-unix:: + $(RM) runenv.py runenv.pyc pyrunenv.vals ++ $(RM) -r __pycache__ + + COV_BUILD= cov-build + COV_ANALYZE= cov-analyze +diff --git a/src/configure.in b/src/configure.in +index 3f45784b5..00cb297b8 100644 +--- a/src/configure.in ++++ b/src/configure.in +@@ -1098,15 +1098,13 @@ fi + AC_SUBST(HAVE_RUNTEST) + + # For Python tests. +-AC_CHECK_PROG(PYTHON,python2,python2) ++AC_CHECK_PROG(PYTHON,python3,python3) + if text x"$PYTHON" = x; then + AC_CHECK_PROG(PYTHON,python,python) + fi + HAVE_PYTHON=no + if test x"$PYTHON" != x; then +- # k5test.py requires python 2.4 (for the subprocess module). +- # Some code needs python 2.5 (for syntax like conditional expressions). +- wantver="(sys.hexversion >= 0x2050000 and sys.hexversion < 0x3000000)" ++ wantver="(sys.hexversion >= 0x3000000)" + if "$PYTHON" -c "import sys; sys.exit(not $wantver and 1 or 0)"; then + HAVE_PYTHON=yes + fi +diff --git a/src/kadmin/dbutil/t_tdumputil.py b/src/kadmin/dbutil/t_tdumputil.py +index 52e356533..47b2aa7a3 100755 +--- a/src/kadmin/dbutil/t_tdumputil.py ++++ b/src/kadmin/dbutil/t_tdumputil.py +@@ -6,8 +6,8 @@ realm = K5Realm(create_kdb=False) + def compare(s, expected, msg): + if s == expected: + return +- print 'expected:', repr(expected) +- print 'got:', repr(s) ++ print('expected:', repr(expected)) ++ print('got:', repr(s)) + fail(msg) + + out = realm.run(['./t_tdumputil', '2', 'field1', 'field2', +diff --git a/src/tests/jsonwalker.py b/src/tests/jsonwalker.py +index 942ca2db7..7a0675e08 100644 +--- a/src/tests/jsonwalker.py ++++ b/src/tests/jsonwalker.py +@@ -2,8 +2,8 @@ import sys + try: + import cjson + except ImportError: +- print "Warning: skipping audit log verification because the cjson module" \ +- " is unavailable" ++ print("Warning: skipping audit log verification because the cjson module" \ ++ " is unavailable") + sys.exit(0) + from collections import defaultdict + from optparse import OptionParser +@@ -22,10 +22,10 @@ class Parser(object): + result = self.parse(logs) + if len(result) != len(self.defaults): + diff = set(self.defaults.keys()).difference(result.keys()) +- print 'Test failed.' +- print 'The following attributes were not set:' ++ print('Test failed.') ++ print('The following attributes were not set:') + for it in diff: +- print it ++ print(it) + sys.exit(1) + + def flatten(self, defaults): +@@ -42,7 +42,7 @@ class Parser(object): + result = dict() + for path,value in self._walk(defaults): + if path in result: +- print 'Warning: attribute path %s already exists' % path ++ print('Warning: attribute path %s already exists' % path) + result[path] = value + + return result +@@ -60,7 +60,7 @@ class Parser(object): + if v is not None: + dv = self.DEFAULTS[type(v)] + else: +- print 'Warning: attribute %s is set to None' % a ++ print('Warning: attribute %s is set to None' % a) + continue + # by now we have default value + if v != dv: +@@ -96,7 +96,7 @@ if __name__ == '__main__': + content.append(cjson.decode(l.rstrip())) + f.close() + else: +- print 'Input file in jason format is required' ++ print('Input file in jason format is required') + exit() + + defaults = None +diff --git a/src/tests/t_cve-2012-1014.py b/src/tests/t_cve-2012-1014.py +index dcff95f6e..8447e0ee7 100755 +--- a/src/tests/t_cve-2012-1014.py ++++ b/src/tests/t_cve-2012-1014.py +@@ -20,7 +20,7 @@ x2 = base64.b16decode('A44F304DA007030500FEDCBA90A10E30' + + '01') + + for x in range(11, 128): +- s.sendto(''.join([x1, chr(x), x2]), a) ++ s.sendto(x1 + bytes([x]) + x2, a) + + # Make sure kinit still works. + +diff --git a/src/tests/t_cve-2012-1015.py b/src/tests/t_cve-2012-1015.py +index 28b1e619b..ae5678cac 100755 +--- a/src/tests/t_cve-2012-1015.py ++++ b/src/tests/t_cve-2012-1015.py +@@ -27,7 +27,7 @@ x1 = base64.b16decode('6A81A030819DA103020105A20302010A' + + x2 = base64.b16decode('A8083006020106020112') + + for x in range(0, 128): +- s.sendto(''.join([x1, chr(x), x2]), a) ++ s.sendto(x1 + bytes([x]) + x2, a) + + # Make sure kinit still works. + +diff --git a/src/tests/t_hostrealm.py b/src/tests/t_hostrealm.py +index 256ba2a38..beea6f3bc 100755 +--- a/src/tests/t_hostrealm.py ++++ b/src/tests/t_hostrealm.py +@@ -119,7 +119,9 @@ testd(realm, 'KRBTEST.COM', 'default_realm profile', env=notest2) + # see the first. Remove the profile default_realm setting to expose + # this behavior. + remove_default = {'libdefaults': {'default_realm': None}} +-nodefault_conf = dict(disable_conf.items() + remove_default.items()) ++# Python 3.5+: nodefault_conf = {**disable_conf, **remove_default} ++nodefault_conf = dict(list(disable_conf.items()) + ++ list(remove_default.items())) + nodefault = realm.special_env('nodefault', False, krb5_conf=nodefault_conf) + testd(realm, 'one', 'default_realm test1', env=nodefault) + +diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py +index 983cd93c8..42237f7a1 100755 +--- a/src/tests/t_kdb.py ++++ b/src/tests/t_kdb.py +@@ -1,6 +1,5 @@ + from k5test import * + import time +-from itertools import imap + + # Run kdbtest against the BDB module. + realm = K5Realm(create_kdb=False) +@@ -51,7 +50,7 @@ else: + def slap_add(ldif): + proc = subprocess.Popen([slapadd, '-b', 'cn=config', '-F', slapd_conf], + stdin=subprocess.PIPE, stdout=subprocess.PIPE, +- stderr=subprocess.STDOUT) ++ stderr=subprocess.STDOUT, universal_newlines=True) + (out, dummy) = proc.communicate(ldif) + output(out) + return proc.wait() +@@ -98,7 +97,7 @@ if slap_add('include: file://%s\n' % schema) != 0: + ldap_homes = ['/etc/ldap', '/etc/openldap', '/usr/local/etc/openldap', + '/usr/local/etc/ldap'] + local_schema_path = '/schema/core.ldif' +-core_schema = next((i for i in imap(lambda x:x+local_schema_path, ldap_homes) ++core_schema = next((i for i in map(lambda x:x+local_schema_path, ldap_homes) + if os.path.isfile(i)), None) + if core_schema: + if slap_add('include: file://%s\n' % core_schema) != 0: +@@ -114,7 +113,7 @@ atexit.register(kill_slapd) + + out = open(slapd_out, 'w') + subprocess.call([slapd, '-h', ldap_uri, '-F', slapd_conf], stdout=out, +- stderr=out) ++ stderr=out, universal_newlines=True) + out.close() + pidf = open(slapd_pidfile, 'r') + slapd_pid = int(pidf.read()) +@@ -158,7 +157,7 @@ def ldap_search(args): + proc = subprocess.Popen([ldapsearch, '-H', ldap_uri, '-b', top_dn, + '-D', admin_dn, '-w', admin_pw, args], + stdin=subprocess.PIPE, stdout=subprocess.PIPE, +- stderr=subprocess.STDOUT) ++ stderr=subprocess.STDOUT, universal_newlines=True) + (out, dummy) = proc.communicate() + return out + +@@ -166,7 +165,7 @@ def ldap_modify(ldif, args=[]): + proc = subprocess.Popen([ldapmodify, '-H', ldap_uri, '-D', admin_dn, + '-x', '-w', admin_pw] + args, + stdin=subprocess.PIPE, stdout=subprocess.PIPE, +- stderr=subprocess.STDOUT) ++ stderr=subprocess.STDOUT, universal_newlines=True) + (out, dummy) = proc.communicate(ldif) + output(out) + +diff --git a/src/tests/t_keytab.py b/src/tests/t_keytab.py +index 228c36334..8a17ae2eb 100755 +--- a/src/tests/t_keytab.py ++++ b/src/tests/t_keytab.py +@@ -90,36 +90,36 @@ test_key_rotate(realm, princ, 2) + + # Test that klist -k can read a keytab entry without a 32-bit kvno and + # reports the 8-bit key version. +-record = '\x00\x01' # principal component count +-record += '\x00\x0bKRBTEST.COM' # realm +-record += '\x00\x04user' # principal component +-record += '\x00\x00\x00\x01' # name type (NT-PRINCIPAL) +-record += '\x54\xf7\x4d\x35' # timestamp +-record += '\x02' # key version +-record += '\x00\x12' # enctype +-record += '\x00\x20' # key length +-record += '\x00' * 32 # key bytes +-f = open(realm.keytab, 'w') +-f.write('\x05\x02\x00\x00\x00' + chr(len(record))) ++record = b'\x00\x01' # principal component count ++record += b'\x00\x0bKRBTEST.COM' # realm ++record += b'\x00\x04user' # principal component ++record += b'\x00\x00\x00\x01' # name type (NT-PRINCIPAL) ++record += b'\x54\xf7\x4d\x35' # timestamp ++record += b'\x02' # key version ++record += b'\x00\x12' # enctype ++record += b'\x00\x20' # key length ++record += b'\x00' * 32 # key bytes ++f = open(realm.keytab, 'wb') ++f.write(b'\x05\x02\x00\x00\x00' + bytes([len(record)])) + f.write(record) + f.close() + msg = ' 2 %s' % realm.user_princ + out = realm.run([klist, '-k'], expected_msg=msg) + + # Make sure zero-fill isn't treated as a 32-bit kvno. +-f = open(realm.keytab, 'w') +-f.write('\x05\x02\x00\x00\x00' + chr(len(record) + 4)) ++f = open(realm.keytab, 'wb') ++f.write(b'\x05\x02\x00\x00\x00' + bytes([len(record) + 4])) + f.write(record) +-f.write('\x00\x00\x00\x00') ++f.write(b'\x00\x00\x00\x00') + f.close() + msg = ' 2 %s' % realm.user_princ + out = realm.run([klist, '-k'], expected_msg=msg) + + # Make sure a hand-crafted 32-bit kvno is recognized. +-f = open(realm.keytab, 'w') +-f.write('\x05\x02\x00\x00\x00' + chr(len(record) + 4)) ++f = open(realm.keytab, 'wb') ++f.write(b'\x05\x02\x00\x00\x00' + bytes([len(record) + 4])) + f.write(record) +-f.write('\x00\x00\x00\x03') ++f.write(b'\x00\x00\x00\x03') + f.close() + msg = ' 3 %s' % realm.user_princ + out = realm.run([klist, '-k'], expected_msg=msg) +diff --git a/src/tests/t_mkey.py b/src/tests/t_mkey.py +index 48a533059..cbc830235 100755 +--- a/src/tests/t_mkey.py ++++ b/src/tests/t_mkey.py +@@ -296,10 +296,10 @@ realm.stop() + # 2. list_mkeys displays the same list as for a post-1.7 KDB. + dumpfile = os.path.join(srctop, 'tests', 'dumpfiles', 'dump.16') + os.remove(stash_file) +-f = open(stash_file, 'w') ++f = open(stash_file, 'wb') + f.write(struct.pack('=HL24s', 16, 24, +- '\xF8\x3E\xFB\xBA\x6D\x80\xD9\x54\xE5\x5D\xF2\xE0' +- '\x94\xAD\x6D\x86\xB5\x16\x37\xEC\x7C\x8A\xBC\x86')) ++ b'\xF8\x3E\xFB\xBA\x6D\x80\xD9\x54\xE5\x5D\xF2\xE0' ++ b'\x94\xAD\x6D\x86\xB5\x16\x37\xEC\x7C\x8A\xBC\x86')) + f.close() + realm.run([kdb5_util, 'load', dumpfile]) + nprincs = len(realm.run([kadminl, 'listprincs']).splitlines()) +diff --git a/src/tests/t_otp.py b/src/tests/t_otp.py +index 0fd35d576..617a8ecf5 100755 +--- a/src/tests/t_otp.py ++++ b/src/tests/t_otp.py +@@ -29,8 +29,8 @@ + # + + from k5test import * +-from Queue import Empty +-import StringIO ++from queue import Empty ++from io import StringIO + import struct + + try: +@@ -120,7 +120,8 @@ class UnixRadiusDaemon(RadiusDaemon): + sock.listen(1) + return (sock, addr) + +- def recvRequest(self, (sock, addr)): ++ def recvRequest(self, sock_and_addr): ++ sock, addr = sock_and_addr + conn = sock.accept()[0] + sock.close() + os.remove(addr) +diff --git a/src/tests/t_tabdump.py b/src/tests/t_tabdump.py +index 2a86136dd..49531bf49 100755 +--- a/src/tests/t_tabdump.py ++++ b/src/tests/t_tabdump.py +@@ -1,10 +1,10 @@ + from k5test import * + + import csv +-import StringIO ++from io import StringIO + + def tab_csv(s): +- io = StringIO.StringIO(s) ++ io = StringIO(s) + return list(csv.DictReader(io, dialect=csv.excel_tab)) + + +diff --git a/src/util/Makefile.in b/src/util/Makefile.in +index 2611581c1..19a6bd312 100644 +--- a/src/util/Makefile.in ++++ b/src/util/Makefile.in +@@ -26,3 +26,4 @@ install: + + clean-unix:: + $(RM) *.pyc ++ $(RM) -r __pycache__ +diff --git a/src/util/k5test.py b/src/util/k5test.py +index bc32877a7..81fac3063 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -380,16 +380,16 @@ import imp + def fail(msg): + """Print a message and exit with failure.""" + global _current_pass +- print "*** Failure:", msg ++ print("*** Failure:", msg) + if _last_mark: +- print "*** Last mark: %s" % _last_mark ++ print("*** Last mark: %s" % _last_mark) + if _last_cmd: +- print "*** Last command (#%d): %s" % (_cmd_index - 1, _last_cmd) ++ print("*** Last command (#%d): %s" % (_cmd_index - 1, _last_cmd)) + if _last_cmd_output: +- print "*** Output of last command:" ++ print("*** Output of last command:") + sys.stdout.write(_last_cmd_output) + if _current_pass: +- print "*** Failed in test pass:", _current_pass ++ print("*** Failed in test pass:", _current_pass) + sys.exit(1) + + +@@ -465,15 +465,16 @@ def _onexit(): + if not verbose: + testlogfile = os.path.join(os.getcwd(), 'testlog') + utildir = os.path.join(srctop, 'util') +- print 'For details, see: %s' % testlogfile +- print 'Or re-run this test script with the -v flag:' +- print ' cd %s' % os.getcwd() +- print ' PYTHONPATH=%s %s %s -v' % \ +- (utildir, sys.executable, sys.argv[0]) +- print +- print 'Use --debug=NUM to run a command under a debugger. Use' +- print '--stop-after=NUM to stop after a daemon is started in order to' +- print 'attach to it with a debugger. Use --help to see other options.' ++ print('For details, see: %s' % testlogfile) ++ print('Or re-run this test script with the -v flag:') ++ print(' cd %s' % os.getcwd()) ++ print(' PYTHONPATH=%s %s %s -v' % ++ (utildir, sys.executable, sys.argv[0])) ++ print() ++ print('Use --debug=NUM to run a command under a debugger. Use') ++ print('--stop-after=NUM to stop after a daemon is started in order to') ++ print('attach to it with a debugger. Use --help to see other') ++ print('options.') + + + def _onsigint(signum, frame): +@@ -523,8 +524,8 @@ def _get_hostname(): + hostname = socket.gethostname() + try: + ai = socket.getaddrinfo(hostname, None, 0, 0, 0, socket.AI_CANONNAME) +- except socket.gaierror, (error, errstr): +- fail('Local hostname "%s" does not resolve: %s.' % (hostname, errstr)) ++ except socket.gaierror as e: ++ fail('Local hostname "%s" does not resolve: %s.' % (hostname, e[1])) + (family, socktype, proto, canonname, sockaddr) = ai[0] + try: + name = socket.getnameinfo(sockaddr, socket.NI_NAMEREQD) +@@ -594,7 +595,7 @@ def _match_cmdnum(cmdnum, ind): + def _build_env(): + global buildtop, runenv + env = os.environ.copy() +- for (k, v) in runenv.env.iteritems(): ++ for (k, v) in runenv.env.items(): + if v.find('./') == 0: + env[k] = os.path.join(buildtop, v) + else: +@@ -704,7 +705,8 @@ def _run_cmd(args, env, input=None, expected_code=0, expected_msg=None, + + # Run the command and log the result, folding stderr into stdout. + proc = subprocess.Popen(args, stdin=infile, stdout=subprocess.PIPE, +- stderr=subprocess.STDOUT, env=env) ++ stderr=subprocess.STDOUT, env=env, ++ universal_newlines=True) + (outdata, dummy_errdata) = proc.communicate(input) + _last_cmd_output = outdata + code = proc.returncode +@@ -734,10 +736,10 @@ def _debug_cmd(args, env, input): + (_cmd_index, _shell_equiv(args)), True) + if input: + print +- print '*** Enter the following input when appropriate:' +- print +- print input +- print ++ print('*** Enter the following input when appropriate:') ++ print() ++ print(input) ++ print() + code = subprocess.call(args, env=env) + output('*** [%d] Completed in debugger with return code %d\n' % + (_cmd_index, code)) +@@ -765,7 +767,8 @@ def _start_daemon(args, env, sentinel): + + # Start the daemon and look for the sentinel in stdout or stderr. + proc = subprocess.Popen(args, stdin=null_input, stdout=subprocess.PIPE, +- stderr=subprocess.STDOUT, env=env) ++ stderr=subprocess.STDOUT, env=env, ++ universal_newlines=True) + _last_cmd_output = '' + while True: + line = proc.stdout.readline() +diff --git a/src/util/princflags.py b/src/util/princflags.py +index f568dd2f1..f645e86e4 100644 +--- a/src/util/princflags.py ++++ b/src/util/princflags.py +@@ -1,5 +1,4 @@ + import re +-import string + + # Module for translating KDB principal flags between string and + # integer forms. +@@ -81,7 +80,7 @@ _prefixlen = len(_prefix) + _flagnames = {} + + # Translation table to map hyphens to underscores +-_squash = string.maketrans('-', '_') ++_squash = str.maketrans('-', '_') + + # Combined input-to-flag lookup table, to be filled in by + # _setup_tables() +@@ -176,7 +175,7 @@ def flagnum2str(n): + # Return a list of flag names from a flag word. + def flags2namelist(flags): + a = [] +- for n in xrange(32): ++ for n in range(32): + if flags & (1 << n): + a.append(flagnum2str(n)) + return a +@@ -225,21 +224,21 @@ def speclist2mask(s): + + # Print C table of input flag specifiers for lib/kadm5/str_conv.c. + def _print_ftbl(): +- print 'static const struct flag_table_row ftbl[] = {' +- a = sorted(pflags.items(), key=lambda (k, v): (v.flag, -v.invert, k)) ++ print('static const struct flag_table_row ftbl[] = {') ++ a = sorted(pflags.items(), key=lambda k, v: (v.flag, -v.invert, k)) + for k, v in a: + s1 = ' {"%s",' % k + s2 = '%-31s KRB5_KDB_%s,' % (s1, v.flagname()) +- print '%-63s %d},' % (s2, 1 if v.invert else 0) ++ print('%-63s %d},' % (s2, 1 if v.invert else 0)) + +- print '};' +- print '#define NFTBL (sizeof(ftbl) / sizeof(ftbl[0]))' ++ print('};') ++ print('#define NFTBL (sizeof(ftbl) / sizeof(ftbl[0]))') + + + # Print C table of output flag names for lib/kadm5/str_conv.c. + def _print_outflags(): +- print 'static const char *outflags[] = {' +- for i in xrange(32): ++ print('static const char *outflags[] = {') ++ for i in range(32): + flag = 1 << i + if flag > max(_flagnames.keys()): + break +@@ -247,10 +246,10 @@ def _print_outflags(): + s = ' "%s",' % _flagnames[flag] + except KeyError: + s = ' NULL,' +- print '%-32s/* 0x%08x */' % (s, flag) ++ print('%-32s/* 0x%08x */' % (s, flag)) + +- print '};' +- print '#define NOUTFLAGS (sizeof(outflags) / sizeof(outflags[0]))' ++ print('};') ++ print('#define NOUTFLAGS (sizeof(outflags) / sizeof(outflags[0]))') + + + # Print out C tables to insert into lib/kadm5/str_conv.c. diff --git a/krb5.spec b/krb5.spec index a4fac33..39e03ae 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 11%{?dist} +Release: 12%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -94,6 +94,8 @@ Patch74: Make-docs-build-python3-compatible.patch Patch75: Add-flag-to-disable-encrypted-timestamp-on-client.patch Patch76: Explicitly-look-for-python2-in-configure.in.patch Patch77: Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch +Patch78: Add-k5test-mark-function.patch +Patch79: Convert-Python-tests-to-Python-3.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -139,7 +141,7 @@ BuildRequires: pam-devel BuildRequires: systemd-units # For the test framework. -BuildRequires: perl-interpreter, dejagnu, tcl-devel +BuildRequires: perl-interpreter, dejagnu, tcl-devel, python3 BuildRequires: net-tools, rpcbind BuildRequires: hostname BuildRequires: iproute @@ -154,9 +156,6 @@ BuildRequires: yasm BuildRequires: nss_wrapper BuildRequires: socket_wrapper -# To run TESTS, we need python2 -BuildRequires: python2 - %description Kerberos V5 is a trusted-third-party network authentication system, which can improve your network's security by eliminating the insecure @@ -743,6 +742,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jul 12 2018 Robbie Harwood - 1.16.1-12 +- Convert Python tests to Python 3 + * Wed Jul 11 2018 Robbie Harwood - 1.16.1-11 - Add build dependency on gcc From c0f34c36f86e49b241dce85135819017ae6cf4c0 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 16 Jul 2018 10:38:52 -0400 Subject: [PATCH 060/304] Zap copy of secret in RC4 string-to-key --- Zap-copy-of-secret-in-RC4-string-to-key.patch | 30 +++++++++++++++++++ krb5.spec | 6 +++- 2 files changed, 35 insertions(+), 1 deletion(-) create mode 100644 Zap-copy-of-secret-in-RC4-string-to-key.patch diff --git a/Zap-copy-of-secret-in-RC4-string-to-key.patch b/Zap-copy-of-secret-in-RC4-string-to-key.patch new file mode 100644 index 0000000..7502c25 --- /dev/null +++ b/Zap-copy-of-secret-in-RC4-string-to-key.patch @@ -0,0 +1,30 @@ +From 55a8161c3f5238df522447499a38bf2e9497b074 Mon Sep 17 00:00:00 2001 +From: Dylan Gray <35609490+Dylan-MSFT@users.noreply.github.com> +Date: Fri, 13 Jul 2018 15:09:01 -0700 +Subject: [PATCH] Zap copy of secret in RC4 string-to-key + +Commit b8814745049b5f401e3ae39a81dc1e14598ae48c (ticket 8576) added a +zero-terminated copy of the input string in +krb5int_arcfour_string_to_key(). This copy should be zeroed when +freed as the input string typically contains a password. + +[ghudson@mit.edu: rewrote commit message] + +ticket: 8713 (new) +--- + src/lib/crypto/krb/s2k_rc4.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/lib/crypto/krb/s2k_rc4.c b/src/lib/crypto/krb/s2k_rc4.c +index 081a91217..f7e699d60 100644 +--- a/src/lib/crypto/krb/s2k_rc4.c ++++ b/src/lib/crypto/krb/s2k_rc4.c +@@ -25,7 +25,7 @@ krb5int_arcfour_string_to_key(const struct krb5_keytypes *ktp, + if (utf8 == NULL) + return err; + err = k5_utf8_to_utf16le(utf8, ©str, ©strlen); +- free(utf8); ++ zapfree(utf8, string->length); + if (err) + return err; + diff --git a/krb5.spec b/krb5.spec index 39e03ae..646254f 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 12%{?dist} +Release: 13%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -96,6 +96,7 @@ Patch76: Explicitly-look-for-python2-in-configure.in.patch Patch77: Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch Patch78: Add-k5test-mark-function.patch Patch79: Convert-Python-tests-to-Python-3.patch +Patch80: Zap-copy-of-secret-in-RC4-string-to-key.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -742,6 +743,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jul 16 2018 Robbie Harwood - 1.16.1-13 +- Zap copy of secret in RC4 string-to-key + * Thu Jul 12 2018 Robbie Harwood - 1.16.1-12 - Convert Python tests to Python 3 From b5615f9f2c07035740ff0b489a893a29bdb7b15a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 18 Jul 2018 17:25:00 -0400 Subject: [PATCH 061/304] Fix some broken tests for Python 3 --- Fix-some-broken-tests-for-Python-3.patch | 81 ++++++++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 86 insertions(+), 1 deletion(-) create mode 100644 Fix-some-broken-tests-for-Python-3.patch diff --git a/Fix-some-broken-tests-for-Python-3.patch b/Fix-some-broken-tests-for-Python-3.patch new file mode 100644 index 0000000..42825b0 --- /dev/null +++ b/Fix-some-broken-tests-for-Python-3.patch @@ -0,0 +1,81 @@ +From eb60404564852a262d4082c3e38086742afb1bd9 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 16 Jul 2018 16:44:01 -0400 +Subject: [PATCH] Fix some broken tests for Python 3 + +Remove python2 dependencies in .travis.yml and add python3-paste. +Convert t_daemon.py and jsonwalker.py to python3. csjon has no +python3 version, so replace it with python's built-in JSON module. + +python3-pyrad isn't available for Trusty, so krad and OTP tests are +currently not exercised by Travis. + +[ghudson@mit.edu: squashed commits; edited commit message] + +ticket: 8710 +(cherry picked from commit d1fb3551c0dff5c3e6555b31fcbf04ff04d577fe) +[rharwood@redhat.com: .travis.yml] +--- + src/lib/krad/t_daemon.py | 2 +- + src/tests/jsonwalker.py | 16 +++++----------- + 2 files changed, 6 insertions(+), 12 deletions(-) + +diff --git a/src/lib/krad/t_daemon.py b/src/lib/krad/t_daemon.py +index 7d7a5d0c8..7668cd7f8 100755 +--- a/src/lib/krad/t_daemon.py ++++ b/src/lib/krad/t_daemon.py +@@ -23,7 +23,7 @@ + # NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS + # SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +-import StringIO ++from io import StringIO + import os + import sys + import signal +diff --git a/src/tests/jsonwalker.py b/src/tests/jsonwalker.py +index 7a0675e08..1880363d2 100644 +--- a/src/tests/jsonwalker.py ++++ b/src/tests/jsonwalker.py +@@ -1,10 +1,5 @@ + import sys +-try: +- import cjson +-except ImportError: +- print("Warning: skipping audit log verification because the cjson module" \ +- " is unavailable") +- sys.exit(0) ++import json + from collections import defaultdict + from optparse import OptionParser + +@@ -72,7 +67,7 @@ class Parser(object): + """ + Generator that works through dictionary. + """ +- for a,v in adict.iteritems(): ++ for a,v in adict.items(): + if isinstance(v,dict): + for (attrpath,u) in self._walk(v): + yield (a+'.'+attrpath,u) +@@ -93,17 +88,16 @@ if __name__ == '__main__': + with open(options.filename, 'r') as f: + content = list() + for l in f: +- content.append(cjson.decode(l.rstrip())) ++ content.append(json.loads(l.rstrip())) + f.close() + else: +- print('Input file in jason format is required') ++ print('Input file in JSON format is required') + exit() + + defaults = None + if options.defaults is not None: + with open(options.defaults, 'r') as f: +- defaults = cjson.decode(f.read()) +- f.close() ++ defaults = json.load(f) + + # run test + p = Parser(defaults) diff --git a/krb5.spec b/krb5.spec index 646254f..4fa6c6c 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 13%{?dist} +Release: 14%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -97,6 +97,7 @@ Patch77: Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch Patch78: Add-k5test-mark-function.patch Patch79: Convert-Python-tests-to-Python-3.patch Patch80: Zap-copy-of-secret-in-RC4-string-to-key.patch +Patch81: Fix-some-broken-tests-for-Python-3.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -743,6 +744,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Jul 18 2018 Robbie Harwood - 1.16.1-14 +- Fix some broken tests for Python 3 + * Mon Jul 16 2018 Robbie Harwood - 1.16.1-13 - Zap copy of secret in RC4 string-to-key From e3ab2c3591c98c044847d156928d35cca225ed4e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 19 Jul 2018 16:43:06 -0400 Subject: [PATCH 062/304] Eliminate preprocessor-disabled dead code --- ...nate-preprocessor-disabled-dead-code.patch | 2950 +++++++++++++++++ krb5.spec | 6 +- 2 files changed, 2955 insertions(+), 1 deletion(-) create mode 100644 Eliminate-preprocessor-disabled-dead-code.patch diff --git a/Eliminate-preprocessor-disabled-dead-code.patch b/Eliminate-preprocessor-disabled-dead-code.patch new file mode 100644 index 0000000..9c55c67 --- /dev/null +++ b/Eliminate-preprocessor-disabled-dead-code.patch @@ -0,0 +1,2950 @@ +From 904a5789da342857a50de5874fe6aae1f96cbc5c Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 16 Jul 2018 15:35:15 -0400 +Subject: [PATCH] Eliminate preprocessor-disabled dead code + +It's been policy for a while now not to create "dead hunks" like +these. A great deal of this code simply doesn't work because it +hasn't been kept up-to-date, and may never have worked. Eliminate +these dead hunks along with the complexity to support them. + +(cherry picked from commit 2bc951d3c88b460a16249115cbd51d69c3c57e22) +[rharwood@redhat.com: context skew] +--- + src/ccapi/common/win/OldCC/ccutils.c | 6 -- + src/ccapi/common/win/OldCC/ccutils.h | 3 - + src/ccapi/common/win/OldCC/opts.cxx | 39 ---------- + src/ccapi/common/win/OldCC/secure.hxx | 6 -- + src/ccapi/common/win/OldCC/util.h | 3 - + src/ccapi/lib/win/OldCC/client.cxx | 39 ---------- + src/ccapi/lib/win/ccapi_os_ipc.cxx | 15 ---- + src/ccapi/lib/win/ccs_reply_proc.c | 8 +- + src/ccapi/lib/win/dllmain.cxx | 12 +-- + src/ccapi/server/win/ccs_os_server.cpp | 23 +----- + src/ccapi/server/win/ccs_request_proc.c | 12 +-- + src/ccapi/server/win/ccs_win_pipe.c | 4 +- + src/ccapi/test/pingtest.c | 6 -- + src/clients/ksu/authorization.c | 17 ----- + src/config/win-post.in | 8 -- + src/include/gssrpc/auth.h | 15 ---- + src/include/gssrpc/rename.h | 26 +------ + src/include/gssrpc/rpc.h | 25 ------- + src/include/gssrpc/types.hin | 7 -- + src/include/k5-platform.h | 28 +------ + src/kadmin/dbutil/kdb5_util.c | 38 ---------- + src/kadmin/server/ipropd_svc.c | 29 ------- + src/kdc/kdc_log.c | 8 -- + src/kdc/kdc_preauth.c | 13 ---- + src/lib/apputils/net-server.c | 27 ------- + src/lib/crypto/builtin/des/destest.c | 4 - + src/lib/crypto/builtin/des/t_verify.c | 24 ------ + src/lib/crypto/builtin/pbkdf2.c | 38 +--------- + src/lib/crypto/builtin/sha1/t_shs.c | 15 ---- + src/lib/crypto/crypto_tests/t_cksums.c | 4 - + src/lib/crypto/crypto_tests/t_crc.c | 45 +---------- + src/lib/crypto/crypto_tests/t_cts.c | 27 ------- + src/lib/crypto/crypto_tests/t_decrypt.c | 4 - + src/lib/crypto/crypto_tests/t_derive.c | 4 - + src/lib/crypto/crypto_tests/t_hmac.c | 11 --- + src/lib/crypto/crypto_tests/t_str2key.c | 4 - + src/lib/crypto/crypto_tests/vectors.c | 5 -- + src/lib/crypto/krb/nfold.c | 10 --- + src/lib/gssapi/generic/util_set.c | 15 ---- + src/lib/gssapi/krb5/accept_sec_context.c | 11 --- + src/lib/gssapi/krb5/gssapi_krb5.c | 28 ------- + src/lib/gssapi/krb5/naming_exts.c | 10 --- + src/lib/gssapi/mechglue/g_initialize.c | 25 ------- + src/lib/gssapi/mechglue/g_inq_cred.c | 5 -- + src/lib/gssapi/mechglue/mglueP.h | 5 -- + src/lib/kadm5/clnt/client_init.c | 48 +----------- + src/lib/kadm5/srv/server_init.c | 11 --- + src/lib/kadm5/unit-test/setkey-test.c | 9 --- + src/lib/krb5/asn.1/ldap_key_seq.c | 3 - + src/lib/krb5/ccache/ccapi/stdcc.c | 58 -------------- + src/lib/krb5/ccache/ccapi/winccld.h | 36 --------- + src/lib/krb5/keytab/t_keytab.c | 13 ---- + src/lib/krb5/krb/gc_via_tkt.c | 11 --- + src/lib/krb5/krb/init_ctx.c | 7 -- + src/lib/krb5/krb/rd_req_dec.c | 31 +------- + src/lib/krb5/krb/t_ser.c | 75 +------------------ + src/lib/krb5/krb/unparse.c | 7 -- + src/lib/krb5/os/localaddr.c | 22 ------ + src/lib/krb5/rcache/rc_io.c | 4 - + src/lib/rpc/auth_gssapi.c | 8 -- + src/lib/rpc/svc_auth.c | 3 - + src/lib/rpc/svc_auth_gssapi.c | 4 - + src/lib/win_glue.c | 9 --- + src/plugins/kdb/db2/lockout.c | 4 - + src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c | 3 - + src/plugins/preauth/pkinit/pkinit_clnt.c | 18 ----- + src/plugins/preauth/pkinit/pkinit_matching.c | 11 --- + src/plugins/preauth/pkinit/pkinit_srv.c | 18 ----- + src/tests/asn.1/krb5_decode_leak.c | 12 --- + src/tests/dejagnu/config/default.exp | 20 ----- + src/tests/shlib/t_loader.c | 12 --- + src/tests/threads/t_rcache.c | 6 -- + src/util/profile/prof_file.c | 43 ----------- + src/util/support/fake-addrinfo.c | 6 -- + src/util/support/utf8.c | 22 ------ + src/windows/include/loadfuncs-krb5.h | 23 ------ + src/windows/kfwlogon/kfwlogon.c | 11 --- + src/windows/leash/Leash.cpp | 4 - + src/windows/leash/Makefile.in | 3 - + src/windows/leash/VSroutines.c | 64 ---------------- + src/windows/leashdll/lsh_pwd.c | 11 --- + src/windows/leashdll/lshfunc.c | 32 +------- + src/windows/leashdll/lshutil.cpp | 11 --- + src/windows/lib/cacheapi.h | 15 ---- + 84 files changed, 23 insertions(+), 1396 deletions(-) + delete mode 100644 src/windows/leash/VSroutines.c + +diff --git a/src/ccapi/common/win/OldCC/ccutils.c b/src/ccapi/common/win/OldCC/ccutils.c +index 13f72cbe0..403c67ebe 100644 +--- a/src/ccapi/common/win/OldCC/ccutils.c ++++ b/src/ccapi/common/win/OldCC/ccutils.c +@@ -101,9 +101,6 @@ HANDLE createThreadEvent(char* uuid, char* suffix) { + event_name = allocEventName(uuid, suffix); + if (!event_name) status = cci_check_error(ccErrNoMem); + } +-#if 0 +- cci_debug_printf("%s event_name:%s", __FUNCTION__, event_name); +-#endif + if (!status) { + hEvent = CreateEvent(psa, FALSE, FALSE, event_name); + if (!hEvent) status = cci_check_error(GetLastError()); +@@ -125,9 +122,6 @@ HANDLE openThreadEvent(char* uuid, char* suffix) { + + event_name = allocEventName(uuid, suffix); + if (!event_name) status = cci_check_error(ccErrNoMem); +-#if 0 +- cci_debug_printf("%s event_name:%s", __FUNCTION__, event_name); +-#endif + if (!status) { + hEvent = OpenEvent(EVENT_MODIFY_STATE, FALSE, event_name); + if (!hEvent) status = cci_check_error(GetLastError()); +diff --git a/src/ccapi/common/win/OldCC/ccutils.h b/src/ccapi/common/win/OldCC/ccutils.h +index f91c77702..9da3d87fd 100644 +--- a/src/ccapi/common/win/OldCC/ccutils.h ++++ b/src/ccapi/common/win/OldCC/ccutils.h +@@ -29,9 +29,6 @@ + #ifdef __cplusplus + extern "C" { + #endif +-#if 0 +-} +-#endif + + #define REPLY_SUFFIX (char*)"reply" + #define LISTEN_SUFFIX (char*)"listen" +diff --git a/src/ccapi/common/win/OldCC/opts.cxx b/src/ccapi/common/win/OldCC/opts.cxx +index bd5f503ea..c9776638b 100644 +--- a/src/ccapi/common/win/OldCC/opts.cxx ++++ b/src/ccapi/common/win/OldCC/opts.cxx +@@ -29,45 +29,6 @@ + #include + #include + +-#if 0 +-const struct Opts* +-GetOpts( +- ) +-{ +- bool done = false; +- struct Opts* o; +- if (!(o = new Opts)) +- goto cleanup; +- if (!(o->pszString = new char[lstrlenA(opts.pszString) + 1])) +- goto cleanup; +- if (!(o->pszEndpoint = new char[lstrlenA(opts.pszEndpoint) + 1])) +- goto cleanup; +- strcpy(o->pszString, opts.pszString); +- strcpy(o->pszEndpoint, opts.pszEndpoint); +- done = true; +- cleanup: +- if (!done) { +- FreeOpts(o); +- o = 0; +- } +- return o; +-} +- +-void +-FreeOpts( +- struct Opts* o +- ) +-{ +- if (o) { +- if (o->pszString) +- delete [] o->pszString; +- if (o->pszEndpoint) +- delete [] o->pszEndpoint; +- delete o; +- } +-} +-#endif +- + bool + ParseOpts::IsValidOpt( + char ch +diff --git a/src/ccapi/common/win/OldCC/secure.hxx b/src/ccapi/common/win/OldCC/secure.hxx +index 3714c6f84..1b2e7532d 100644 +--- a/src/ccapi/common/win/OldCC/secure.hxx ++++ b/src/ccapi/common/win/OldCC/secure.hxx +@@ -38,12 +38,6 @@ public: + static void Start(SecureClient*& s); + static void Stop(SecureClient*& s); + +-#if 0 +- static DWORD CheckImpersonation(); +- static bool IsImp(); +- static DWORD DuplicateImpAsPrimary(HANDLE& hPrimary); +-#endif +- + SecureClient(); + ~SecureClient(); + DWORD Error(); +diff --git a/src/ccapi/common/win/OldCC/util.h b/src/ccapi/common/win/OldCC/util.h +index 082f6080b..45e069a71 100644 +--- a/src/ccapi/common/win/OldCC/util.h ++++ b/src/ccapi/common/win/OldCC/util.h +@@ -29,9 +29,6 @@ + #ifdef __cplusplus + extern "C" { + #endif +-#if 0 +-} +-#endif + + BOOL isNT(); + +diff --git a/src/ccapi/lib/win/OldCC/client.cxx b/src/ccapi/lib/win/OldCC/client.cxx +index 4b2d718cc..0f95dfceb 100644 +--- a/src/ccapi/lib/win/OldCC/client.cxx ++++ b/src/ccapi/lib/win/OldCC/client.cxx +@@ -118,9 +118,6 @@ DWORD find_server(Init::InitInfo& info, LPSTR endpoint) { + char* szDir = 0; + BOOL bRes = FALSE; + char* cmdline = NULL; +-#if 0 +- HANDLE hToken = 0; +-#endif + + psa = isNT() ? &sa : 0; + +@@ -156,38 +153,6 @@ DWORD find_server(Init::InitInfo& info, LPSTR endpoint) { + } + + if (!status) { +- +-#if 0 +- if (SecureClient::IsImp()) { +- cci_debug_printf(STARTUP "Token is impersonation token")); +- SecureClient::DuplicateImpAsPrimary(hToken); +- } +- else { +- cci_debug_printf(STARTUP "Token is NOT impersonation token")); +- } +-#endif +- +-#if 0 +- if (hToken) +- bRes = CreateProcessAsUser(hToken, +- szExe, // app name +- NULL, // cmd line +- psa, // SA +- psa, // SA +- FALSE, +- CREATE_NEW_PROCESS_GROUP | +- //CREATE_NEW_CONSOLE | +- NORMAL_PRIORITY_CLASS | +- // CREATE_NO_WINDOW | +- DETACHED_PROCESS | +- 0 +- , +- NULL, // environment +- szDir, // current dir +- &si, +- &pi); +- else +-#endif + alloc_cmdline_2_args(szExe, endpoint, "-D", &cmdline); + bRes = CreateProcess( szExe, // app name + NULL, //cmdline, // cmd line is +@@ -223,10 +188,6 @@ DWORD find_server(Init::InitInfo& info, LPSTR endpoint) { + cci_debug_printf(" unexpected error while looking for server: 0D%d / 0U%u / 0X%X", status, status, status); + } + +-#if 0 +- if (hToken) +- CloseHandle(hToken); +-#endif + if (szDir) free_alloc_p(&szDir); + if (szExe) free_alloc_p(&szExe); + if (hEvent) CloseHandle(hEvent); +diff --git a/src/ccapi/lib/win/ccapi_os_ipc.cxx b/src/ccapi/lib/win/ccapi_os_ipc.cxx +index 35589a54f..1b1f874e9 100644 +--- a/src/ccapi/lib/win/ccapi_os_ipc.cxx ++++ b/src/ccapi/lib/win/ccapi_os_ipc.cxx +@@ -132,9 +132,6 @@ extern "C" cc_int32 cci_os_ipc_thread_init (void) { + cci_check_error(err); + } + +-#if 0 +- cci_debug_printf("%s UUID:<%s>", __FUNCTION__, tspdata_getUUID(ptspdata)); +-#endif + // Initialize old CCAPI if necessary: + if (!err) if (!Init:: Initialized()) err = Init:: Initialize( ); + if (!err) if (!Client::Initialized()) err = Client::Initialize(0); +@@ -243,10 +240,6 @@ extern "C" cc_int32 cci_os_ipc_msg( cc_int32 in_launch_server, + if (!GetTspData(GetTlsIndex(), &ptspdata)) {return ccErrBadParam;} + uuid = tspdata_getUUID(ptspdata); + lenUUID = 1 + strlen(uuid); /* 1+ includes terminating \0. */ +-#if 0 +- cci_debug_printf("%s calling remote ccs_rpc_request tsp*:0x%X", __FUNCTION__, ptspdata); +- cci_debug_printf(" rpcmsg:%d; UUID[%d]:<%s> SST:%ld", in_msg, lenUUID, uuid, sst); +-#endif + /* copy ptr into handle; ptr may be 4 or 8 bytes, depending on platform; handle is always 8 */ + memcpy(tspdata_handle, &ptspdata, sizeof(ptspdata)); + ccs_rpc_request( /* make call with user message: */ +@@ -282,11 +275,6 @@ extern "C" cc_int32 cci_os_ipc_msg( cc_int32 in_launch_server, + if (!err && server_died) { + err = cci_check_error (ccErrServerUnavailable); + } +-#if 0 +- if (err == BOOTSTRAP_UNKNOWN_SERVICE && !in_launch_server) { +- err = ccNoError; /* If the server is not running just return an empty stream. */ +- } +-#endif + + if (!err) { + *out_reply_stream = tspdata_getStream(ptspdata); +@@ -365,9 +353,6 @@ cc_int32 ccapi_connect(const struct tspdata* tsp) { + ReleaseMutex(hCCAPIv2Mutex); + + if (!status) { +-#if 0 +- cci_debug_printf("%s Waiting for replyEvent.", __FUNCTION__); +-#endif + status = WaitForSingleObject(replyEvent, INFINITE);//(SECONDS_TO_WAIT)*1000); + status = cci_check_error(RpcMgmtIsServerListening(CLIENT_REQUEST_RPC_HANDLE)); + cci_debug_printf(" Server %sFOUND!", (status) ? "NOT " : ""); +diff --git a/src/ccapi/lib/win/ccs_reply_proc.c b/src/ccapi/lib/win/ccs_reply_proc.c +index bf8c7f4f4..b4dbc0d19 100644 +--- a/src/ccapi/lib/win/ccs_reply_proc.c ++++ b/src/ccapi/lib/win/ccs_reply_proc.c +@@ -47,9 +47,7 @@ void ccs_rpc_request_reply( + struct tspdata* tsp; + k5_ipc_stream stream; + long status = 0; +-#if 0 +- cci_debug_printf("%s! msg#:%d SST:%ld uuid:%s", __FUNCTION__, rpcmsg, srvStartTime, uuid); +-#endif ++ + memcpy(&tsp, tspHandle, sizeof(tsp)); + if (!status) { + status = krb5int_ipc_stream_new (&stream); /* Create a stream for the request data */ +@@ -77,9 +75,7 @@ void ccs_rpc_connect_reply( + + HANDLE hEvent = openThreadEvent(uuid, REPLY_SUFFIX); + DWORD* p = (DWORD*)(tspHandle); +-#if 0 +- cci_debug_printf("%s! msg#:%d SST:%ld uuid:%s", __FUNCTION__, rpcmsg, srvStartTime, uuid); +-#endif ++ + SetEvent(hEvent); + CloseHandle(hEvent); + } +diff --git a/src/ccapi/lib/win/dllmain.cxx b/src/ccapi/lib/win/dllmain.cxx +index 82cacad9c..aa5d00a65 100644 +--- a/src/ccapi/lib/win/dllmain.cxx ++++ b/src/ccapi/lib/win/dllmain.cxx +@@ -163,17 +163,7 @@ BOOL WINAPI DllMain(HINSTANCE hinstDLL, // DLL module handle + // using multiple DLLs that use this DLL. + // + WaitForSingleObject( hCCAPIv2Mutex, INFINITE ); +-#if 0 +- bool process_teardown_workaround = false; +- if (lpvReserved) { +- Init::InitInfo info; +- status = Init::Info(info); +- if (status) break; +- if (!info.isNT) process_teardown_workaround = true; +- } +- if (process_teardown_workaround) +- break; +-#endif ++ + // return value is ignored, so we set status for debugging purposes + status = Client::Cleanup(); + status = Init::Cleanup(); +diff --git a/src/ccapi/server/win/ccs_os_server.cpp b/src/ccapi/server/win/ccs_os_server.cpp +index f84239491..7c5012039 100644 +--- a/src/ccapi/server/win/ccs_os_server.cpp ++++ b/src/ccapi/server/win/ccs_os_server.cpp +@@ -245,10 +245,7 @@ cc_int32 ccs_os_server_listen_loop (int argc, const char *argv[]) { + + if (worklist_remove(&rpcmsg, &pipe, &buf, &serverStartTime)) { + uuid = ccs_win_pipe_getUuid(pipe); +-#if 0 +- cci_debug_printf("%s: processing WorkItem msg:%ld pipeUUID:<%s> pipeHandle:0x%X SST:%ld", +- __FUNCTION__, rpcmsg, uuid, ccs_win_pipe_getHandle(pipe), serverStartTime); +-#endif ++ + if (serverStartTime <= getMySST()) { + switch (rpcmsg) { + case CCMSG_CONNECT: { +@@ -472,13 +469,6 @@ void receiveLoop(void* rpcargs) { + } // End receiveLoop + + +-#if 0 +- +- return status; +-} +-#endif +- +- + + /* ------------------------------------------------------------------------ */ + /* The connection listener thread waits forever for a call to the CCAPI_CLIENT_ +@@ -647,17 +637,6 @@ RPC_STATUS send_connection_reply(ccs_pipe_t in_pipe) { + return (status); + } + +-#if 0 +-DWORD alloc_name(LPSTR* pname, LPSTR postfix) { +- DWORD len = strlen(sessID) + 1 + strlen(postfix) + 1; +- +- *pname = (LPSTR)malloc(len); +- if (!*pname) return GetLastError(); +- _snprintf(*pname, len, "%s.%s", sessID, postfix); +- return 0; +- } +-#endif +- + RPC_STATUS GetPeerName( RPC_BINDING_HANDLE hClient, + LPTSTR pszClientName, + int iMaxLen) { +diff --git a/src/ccapi/server/win/ccs_request_proc.c b/src/ccapi/server/win/ccs_request_proc.c +index 461c441ed..c0328ea7e 100644 +--- a/src/ccapi/server/win/ccs_request_proc.c ++++ b/src/ccapi/server/win/ccs_request_proc.c +@@ -45,9 +45,7 @@ void ccs_rpc_request( + k5_ipc_stream stream; + UINT64* p = (UINT64*)(tspHandle); + WIN_PIPE* pipe = NULL; +-#if 0 +- cci_debug_printf("%s rpcmsg:%d; UUID:<%s> SST:<%s>", __FUNCTION__, rpcmsg, pszUUID, serverStartTime); +-#endif ++ + status = (rpcmsg != CCMSG_REQUEST) && (rpcmsg != CCMSG_PING); + + if (!status) { +@@ -72,9 +70,7 @@ void ccs_rpc_connect( + + UINT64* p = (UINT64*)(tspHandle); + WIN_PIPE* pipe = ccs_win_pipe_new(pszUUID, *p); +-#if 0 +- cci_debug_printf("%s; rpcmsg:%d; UUID: <%s>", __FUNCTION__, rpcmsg, pszUUID); +-#endif ++ + worklist_add( rpcmsg, + pipe, + NULL, /* No payload with connect request */ +@@ -89,9 +85,7 @@ CC_UINT32 ccs_authenticate(const CC_CHAR* name) { + PDWORD pvalue = 0; + CC_UINT32 result = 0; + DWORD status = 0; +-#if 0 +- cci_debug_printf("%s ( %s )", __FUNCTION__, name); +-#endif ++ + hMap = OpenFileMapping(FILE_MAP_ALL_ACCESS, FALSE, (LPSTR)name); + status = !hMap; + +diff --git a/src/ccapi/server/win/ccs_win_pipe.c b/src/ccapi/server/win/ccs_win_pipe.c +index d23e4448e..99c667017 100644 +--- a/src/ccapi/server/win/ccs_win_pipe.c ++++ b/src/ccapi/server/win/ccs_win_pipe.c +@@ -61,9 +61,7 @@ struct ccs_win_pipe_t* ccs_win_pipe_new (const char* uuid, const UINT64 h) { + out_pipe->uuid = uuidCopy; + out_pipe->clientHandle = h; + } +-#if 0 +- cci_debug_printf("0x%X = %s(%s, 0x%X)", out_pipe, __FUNCTION__, uuid, h); +-#endif ++ + return out_pipe; + } + +diff --git a/src/ccapi/test/pingtest.c b/src/ccapi/test/pingtest.c +index d44839f71..0ffc15e7a 100644 +--- a/src/ccapi/test/pingtest.c ++++ b/src/ccapi/test/pingtest.c +@@ -74,12 +74,6 @@ int main( int argc, char *argv[]) { + + if ((dwTlsIndex = TlsAlloc()) == TLS_OUT_OF_INDEXES) return FALSE; + +-// send_test("krbcc.229026.0.ep"); +- +-#if 0 +- err = cc_initialize(&context, ccapi_version_7, NULL, NULL); +-#endif +- + if (!err) { + err = cci_os_ipc_thread_init(); + } +diff --git a/src/clients/ksu/authorization.c b/src/clients/ksu/authorization.c +index 90aafbd75..891921870 100644 +--- a/src/clients/ksu/authorization.c ++++ b/src/clients/ksu/authorization.c +@@ -123,23 +123,6 @@ krb5_error_code krb5_authorization(context, principal, luser, + "In krb5_authorization: if auth files exist -> can access\n"); + } + +-#if 0 +- if (cmd){ +- if(k5users_flag){ +- return 0; /* if kusers does not exist -> done */ +- }else{ +- if(retval = k5users_lookup(users_fp,princname, +- cmd,&retbool,out_fcmd)){ +- auth_cleanup(users_fp, login_fp, princname); +- return retval; +- }else{ +- *ok =retbool; +- return retval; +- } +- } +- } +-#endif +- + /* if either file exists, + first see if the principal is in the login in file, + if it's not there check the k5users file */ +diff --git a/src/config/win-post.in b/src/config/win-post.in +index 6535c1ba5..3f43bda77 100644 +--- a/src/config/win-post.in ++++ b/src/config/win-post.in +@@ -121,14 +121,6 @@ clean-windows-files: + !else + @if exist $(OUTPRE3)$(DIRNUL) deltree /y $(OUTPRE3) + !endif +-!if 0 +- $(RM) .\$(OUTPRE)*.obj .\$(OUTPRE)*.res +- $(RM) .\$(OUTPRE)*.exe .\$(OUTPRE)*.dll +- $(RM) .\$(OUTPRE)*.lib .\$(OUTPRE)*.pdb +- $(RM) .\$(OUTPRE)*.exp .\$(OUTPRE)*.map +- $(RM) .\$(OUTPRE)*.idb .\$(OUTPRE)*.ilk +- $(RM) .\$(OUTPRE)*.manifest +-!endif + + # Dependencies + !if exist($(srcdir)/deps) +diff --git a/src/include/gssrpc/auth.h b/src/include/gssrpc/auth.h +index 0f653fcc7..8576c5142 100644 +--- a/src/include/gssrpc/auth.h ++++ b/src/include/gssrpc/auth.h +@@ -75,12 +75,6 @@ enum auth_stat { + }; + + union des_block { +-#if 0 /* XXX nothing uses this, anyway */ +- struct { +- uint32_t high; +- uint32_t low; +- } key; +-#endif + char c[8]; + }; + typedef union des_block des_block; +@@ -207,15 +201,6 @@ extern bool_t xdr_opaque_auth(XDR *, struct opaque_auth *); + #define AUTH_GSSAPI 300001 /* GSS-API style */ + #define RPCSEC_GSS 6 /* RPCSEC_GSS */ + +-#if 0 +-/* +- * BACKWARDS COMPATIBILIY! OpenV*Secure 1.0 had AUTH_GSSAPI == 4. We +- * need to accept this value until 1.0 is dead. +- */ +-/* This conflicts with AUTH_KERB (Solaris). */ +-#define AUTH_GSSAPI_COMPAT 4 +-#endif +- + GSSRPC__END_DECLS + + #endif /* !defined(GSSRPC_AUTH_H) */ +diff --git a/src/include/gssrpc/rename.h b/src/include/gssrpc/rename.h +index 669a0580c..df37e95b7 100644 +--- a/src/include/gssrpc/rename.h ++++ b/src/include/gssrpc/rename.h +@@ -50,10 +50,7 @@ + * External names in the RPC API not beginning with "_" get renamed + * with the prefix "gssrpc_" via #define, e.g., "foo" -> "gssrpc_foo". + * External names in the RPC API beginning with "_" get textually +- * rewritten, with "#if 0"-disabled #defines mapping them back to +- * their original forms, e.g., "_foo" is rewrittten to "gssrpc__foo" +- * in the original files, with an unused "#define gssrpc__foo _foo" +- * here. ++ * rewritten. + */ + + #ifndef GSSRPC_RENAME_H +@@ -72,10 +69,6 @@ + #define authdes_create gssrpc_authdes_create + #define xdr_opaque_auth gssrpc_xdr_opaque_auth + +-#if 0 +-#define gssrpc__null_auth _null_auth +-#endif +- + /* auth_gss.c */ + + #define auth_debug_gss gssrpc_auth_debug_gss +@@ -181,10 +174,6 @@ + #define callrpc gssrpc_callrpc + #define getrpcport gssrpc_getrpcport + +-#if 0 +-#define gssrpc__rpc_getdtablesize _rpc_getdtablesize +-#endif +- + /* rpc_msg.h */ + + #define xdr_callmsg gssrpc_xdr_callmsg +@@ -193,10 +182,6 @@ + #define xdr_accepted_reply gssrpc_xdr_accepted_reply + #define xdr_rejected_reply gssrpc_xdr_rejected_reply + +-#if 0 +-#define gssrpc__seterr_reply _seterr_reply +-#endif +- + /* svc.h */ + + #define svc_register gssrpc_svc_register +@@ -244,15 +229,6 @@ + #define svcauth_gss_set_svc_name gssrpc_svcauth_gss_set_svc_name + #define svcauth_gss_get_principal gssrpc_svcauth_gss_get_principal + +-#if 0 +-#define gssrpc__authenticate _authenticate +-#define gssrpc__svcauth_none _svcauth_none +-#define gssrpc__svcauth_unix _svcauth_unix +-#define gssrpc__svcauth_short _svcauth_short +-#define gssrpc__svcauth_gssapi _svcauth_gssapi +-#define gssrpc__svcauth_gss _svcauth_gss +-#endif +- + /* svc_auth_gss.c */ + + #define svc_debug_gss gssrpc_svc_debug_gss +diff --git a/src/include/gssrpc/rpc.h b/src/include/gssrpc/rpc.h +index 2d94a7fe9..78727c49d 100644 +--- a/src/include/gssrpc/rpc.h ++++ b/src/include/gssrpc/rpc.h +@@ -55,36 +55,11 @@ + #include /* protocol for rpc messages */ + #include /* protocol for unix style cred */ + #include /* RPCSEC_GSS */ +-/* +- * Uncomment-out the next line if you are building the rpc library with +- * DES Authentication (see the README file in the secure_rpc/ directory). +- */ +-#if 0 +-#include protocol for des style cred +-#endif + + /* Server side only remote procedure callee */ + #include /* service side authenticator */ + #include /* service manager and multiplexer */ + +-/* +- * Punt the rpc/netdb.h everywhere because it just makes things much more +- * difficult. We don't use the *rpcent functions anyway. +- */ +-#if 0 +-/* +- * COMMENT OUT THE NEXT INCLUDE IF RUNNING ON SUN OS OR ON A VERSION +- * OF UNIX BASED ON NFSSRC. These systems will already have the structures +- * defined by included in . +- */ +-/* routines for parsing /etc/rpc */ +-#if 0 /* netdb.h already included in rpc/types.h */ +-#include +-#endif +- +-#include /* structures and routines to parse /etc/rpc */ +-#endif +- + /* + * get the local host's IP address without consulting + * name service library functions +diff --git a/src/include/gssrpc/types.hin b/src/include/gssrpc/types.hin +index 022ab4fa9..4c4120c6f 100644 +--- a/src/include/gssrpc/types.hin ++++ b/src/include/gssrpc/types.hin +@@ -116,13 +116,6 @@ typedef int32_t rpc_inline_t; + #define mem_alloc(bsize) malloc(bsize) + #define mem_free(ptr, bsize) free(ptr) + +-#if 0 +-#include /* XXX This should not have to be here. +- * I got sick of seeing the warnings for MAXHOSTNAMELEN +- * and the two values were different. -- shanzer +- */ +-#endif +- + #ifndef INADDR_LOOPBACK + #define INADDR_LOOPBACK (uint32_t)0x7F000001 + #endif +diff --git a/src/include/k5-platform.h b/src/include/k5-platform.h +index 763408a09..3368c7193 100644 +--- a/src/include/k5-platform.h ++++ b/src/include/k5-platform.h +@@ -526,15 +526,11 @@ typedef struct { int error; unsigned char did_run; } k5_init_t; + # endif + #elif TARGET_OS_MAC + # include +-# if 0 /* This causes compiler warnings. */ +-# define SWAP16 OSSwapInt16 +-# else +-# define SWAP16 k5_swap16 ++# define SWAP16 k5_swap16 + static inline unsigned int k5_swap16 (unsigned int x) { + x &= 0xffff; + return (x >> 8) | ((x & 0xff) << 8); + } +-# endif + # define SWAP32 OSSwapInt32 + # define SWAP64 OSSwapInt64 + #elif defined(HAVE_SYS_BSWAP_H) +@@ -848,25 +844,6 @@ k5_ntohll (uint64_t val) + business. Probably most callers won't check the return status + anyways. */ + +-#if 0 +-static inline void +-set_cloexec_fd(int fd) +-{ +-#if defined(F_SETFD) +-# ifdef FD_CLOEXEC +- (void)fcntl(fd, F_SETFD, FD_CLOEXEC); +-# else +- (void)fcntl(fd, F_SETFD, 1); +-# endif +-#endif +-} +- +-static inline void +-set_cloexec_file(FILE *f) +-{ +- return set_cloexec_fd(fileno(f)); +-} +-#else + /* Macros make the Sun compiler happier, and all variants of this do a + single evaluation of the argument, and fcntl and fileno should + produce reasonable error messages on type mismatches, on any system +@@ -881,9 +858,6 @@ set_cloexec_file(FILE *f) + # define set_cloexec_fd(FD) ((void)(FD)) + #endif + #define set_cloexec_file(F) set_cloexec_fd(fileno(F)) +-#endif +- +- + + /* Since the original ANSI C spec left it undefined whether or + how you could copy around a va_list, C 99 added va_copy. +diff --git a/src/kadmin/dbutil/kdb5_util.c b/src/kadmin/dbutil/kdb5_util.c +index 000b5595c..4ff1cdf38 100644 +--- a/src/kadmin/dbutil/kdb5_util.c ++++ b/src/kadmin/dbutil/kdb5_util.c +@@ -358,44 +358,6 @@ int main(argc, argv) + return exit_status; + } + +-#if 0 +-/* +- * This function is no longer used in kdb5_util (and it would no +- * longer work, anyway). +- */ +-void set_dbname(argc, argv) +- int argc; +- char *argv[]; +-{ +- krb5_error_code retval; +- +- if (argc < 3) { +- com_err(argv[0], 0, _("Too few arguments")); +- com_err(progname, 0, _("Usage: %s dbpathname realmname"), argv[0]); +- exit_status++; +- return; +- } +- if (dbactive) { +- if ((retval = krb5_db_fini(util_context)) && retval!= KRB5_KDB_DBNOTINITED) { +- com_err(progname, retval, _("while closing previous database")); +- exit_status++; +- return; +- } +- if (valid_master_key) { +- krb5_free_keyblock_contents(util_context, &master_keyblock); +- master_keyblock.contents = NULL; +- valid_master_key = 0; +- } +- krb5_free_principal(util_context, master_princ); +- free(mkey_fullname); +- dbactive = FALSE; +- } +- +- (void) set_dbname_help(progname, argv[1]); +- return; +-} +-#endif +- + /* + * open_db_and_mkey: Opens the KDC and policy database, and sets the + * global master_* variables. Sets dbactive to TRUE if the databases +diff --git a/src/kadmin/server/ipropd_svc.c b/src/kadmin/server/ipropd_svc.c +index e6e190136..3228687c7 100644 +--- a/src/kadmin/server/ipropd_svc.c ++++ b/src/kadmin/server/ipropd_svc.c +@@ -621,32 +621,3 @@ krb5_iprop_prog_1(struct svc_req *rqstp, + } + + } +- +-#if 0 +-/* +- * Get the host base service name for the kiprop principal. Returns +- * KADM5_OK on success. Caller must free the storage allocated for +- * host_service_name. +- */ +-kadm5_ret_t +-kiprop_get_adm_host_srv_name(krb5_context context, +- const char *realm, +- char **host_service_name) +-{ +- kadm5_ret_t ret; +- char *name; +- char *host; +- +- if (ret = kadm5_get_master(context, realm, &host)) +- return (ret); +- +- if (asprintf(&name, "%s@%s", KIPROP_SVC_NAME, host) < 0) { +- free(host); +- return (ENOMEM); +- } +- free(host); +- *host_service_name = name; +- +- return (KADM5_OK); +-} +-#endif +diff --git a/src/kdc/kdc_log.c b/src/kdc/kdc_log.c +index 7e8733980..4eec50373 100644 +--- a/src/kdc/kdc_log.c ++++ b/src/kdc/kdc_log.c +@@ -94,14 +94,6 @@ log_as_req(krb5_context context, + krb5_db_audit_as_req(context, request, + local_addr->address, remote_addr->address, + client, server, authtime, errcode); +-#if 0 +- /* Sun (OpenSolaris) version would probably something like this. +- The client and server names passed can be null, unlike in the +- logging routines used above. Note that a struct in_addr is +- used, but the real address could be an IPv6 address. */ +- audit_krb5kdc_as_req(some in_addr *, (in_port_t)remote_addr->port, 0, +- cname, sname, errcode); +-#endif + } + + /* +diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c +index 86b9e2991..811c16368 100644 +--- a/src/kdc/kdc_preauth.c ++++ b/src/kdc/kdc_preauth.c +@@ -712,19 +712,6 @@ const char *missing_required_preauth(krb5_db_entry *client, + krb5_db_entry *server, + krb5_enc_tkt_part *enc_tkt_reply) + { +-#if 0 +- /* +- * If this is the pwchange service, and the pre-auth bit is set, +- * allow it even if the HW preauth would normally be required. +- * +- * Sandia national labs wanted this for some strange reason... we +- * leave it disabled normally. +- */ +- if (isflagset(server->attributes, KRB5_KDB_PWCHANGE_SERVICE) && +- isflagset(enc_tkt_reply->flags, TKT_FLG_PRE_AUTH)) +- return 0; +-#endif +- + #ifdef DEBUG + krb5_klog_syslog ( + LOG_DEBUG, +diff --git a/src/lib/apputils/net-server.c b/src/lib/apputils/net-server.c +index a40da927e..54ee4c5c5 100644 +--- a/src/lib/apputils/net-server.c ++++ b/src/lib/apputils/net-server.c +@@ -1060,17 +1060,6 @@ process_packet(verto_ctx *ctx, verto_ev *ev) + return; + } + +-#if 0 +- if (state->daddr_len > 0) { +- char addrbuf[100]; +- if (getnameinfo(ss2sa(&state->daddr), state->daddr_len, +- addrbuf, sizeof(addrbuf), +- 0, 0, NI_NUMERICHOST)) +- strlcpy(addrbuf, "?", sizeof(addrbuf)); +- com_err(conn->prog, 0, _("pktinfo says local addr is %s"), addrbuf); +- } +-#endif +- + if (state->daddr_len == 0 && conn->type == CONN_UDP) { + /* + * An address couldn't be obtained, so the PKTINFO option probably +@@ -1116,11 +1105,6 @@ kill_lru_tcp_or_rpc_connection(void *handle, verto_ev *newev) + continue; + if (c->type != CONN_TCP && c->type != CONN_RPC) + continue; +-#if 0 +- krb5_klog_syslog(LOG_INFO, "fd %d started at %ld", +- verto_get_fd(oldest_ev), +- c->start_time); +-#endif + if (oldest_c == NULL + || oldest_c->start_time > c->start_time) { + oldest_ev = ev; +@@ -1186,10 +1170,6 @@ accept_tcp_connection(verto_ctx *ctx, verto_ev *ev) + strlcpy(p, tmpbuf, end - p); + } + } +-#if 0 +- krb5_klog_syslog(LOG_INFO, "accepted TCP connection on socket %d from %s", +- s, newconn->addrbuf); +-#endif + + newconn->addr_s = addr_s; + newconn->addrlen = addrlen; +@@ -1481,9 +1461,6 @@ accept_rpc_connection(verto_ctx *ctx, verto_ev *ev) + newconn = verto_get_private(newev); + + set_cloexec_fd(s); +-#if 0 +- setnbio(s), setnolinger(s), setkeepalive(s); +-#endif + + if (getpeername(s, addr, &addrlen) || + getnameinfo(addr, addrlen, +@@ -1503,10 +1480,6 @@ accept_rpc_connection(verto_ctx *ctx, verto_ev *ev) + strlcpy(p, tmpbuf, end - p); + } + } +-#if 0 +- krb5_klog_syslog(LOG_INFO, _("accepted RPC connection on socket %d " +- "from %s"), s, newconn->addrbuf); +-#endif + + newconn->addr_s = addr_s; + newconn->addrlen = addrlen; +diff --git a/src/lib/crypto/builtin/des/destest.c b/src/lib/crypto/builtin/des/destest.c +index dd2f68ec4..0d92b365b 100644 +--- a/src/lib/crypto/builtin/des/destest.c ++++ b/src/lib/crypto/builtin/des/destest.c +@@ -67,9 +67,6 @@ main(argc, argv) + char *argv[]; + { + char block1[17], block2[17], block3[17]; +-#if 0 +- mit_des_cblock key, input, output, output2; +-#else + /* Force tests of unaligned accesses. */ + union { unsigned char c[8*4+3]; long l; } u; + unsigned char *ioblocks = u.c; +@@ -77,7 +74,6 @@ main(argc, argv) + unsigned char *output = ioblocks+10; + unsigned char *output2 = ioblocks+19; + unsigned char *key = ioblocks+27; +-#endif + mit_des_key_schedule sched; + int num = 0; + int retval; +diff --git a/src/lib/crypto/builtin/des/t_verify.c b/src/lib/crypto/builtin/des/t_verify.c +index 1f3239fed..f4332f5c0 100644 +--- a/src/lib/crypto/builtin/des/t_verify.c ++++ b/src/lib/crypto/builtin/des/t_verify.c +@@ -334,30 +334,6 @@ main(argc,argv) + exit(0); + } + +-#if 0 +-void +-flip(array) +- char *array; +-{ +- register int old,new,i,j; +- /* flips the bit order within each byte from 0 lsb to 0 msb */ +- for (i = 0; i<=7; i++) { +- old = *array; +- new = 0; +- for (j = 0; j<=7; j++) { +- if (old & 01) +- new = new | 01; +- if (j < 7) { +- old = old >> 1; +- new = new << 1; +- } +- } +- *array = new; +- array++; +- } +-} +-#endif +- + static void + do_encrypt(in,out) + unsigned char *in; +diff --git a/src/lib/crypto/builtin/pbkdf2.c b/src/lib/crypto/builtin/pbkdf2.c +index d36b32e7e..8905f2671 100644 +--- a/src/lib/crypto/builtin/pbkdf2.c ++++ b/src/lib/crypto/builtin/pbkdf2.c +@@ -102,11 +102,6 @@ F(char *output, char *u_tmp1, char *u_tmp2, + krb5_data out; + krb5_error_code err; + +-#if 0 +- printf("F(i=%d, count=%lu, pass=%d:%s)\n", i, count, +- pass->length, pass->data); +-#endif +- + /* Compute U_1. */ + store_32_be(i, ibytes); + +@@ -114,45 +109,25 @@ F(char *output, char *u_tmp1, char *u_tmp2, + memcpy(u_tmp2 + salt->length, ibytes, 4); + sdata = make_data(u_tmp2, salt->length + 4); + +-#if 0 +- printd("initial salt", &sdata); +-#endif +- + out = make_data(u_tmp1, hlen); + +-#if 0 +- printf("F: computing hmac #1 (U_1) with %s\n", pdata.contents); +-#endif + err = hmac(hash, pass, &sdata, &out); + if (err) + return err; +-#if 0 +- printd("F: prf return value", &out); +-#endif ++ + memcpy(output, u_tmp1, hlen); + + /* Compute U_2, .. U_c. */ + sdata.length = hlen; + for (j = 2; j <= count; j++) { +-#if 0 +- printf("F: computing hmac #%d (U_%d)\n", j, j); +-#endif + memcpy(u_tmp2, u_tmp1, hlen); + err = hmac(hash, pass, &sdata, &out); + if (err) + return err; +-#if 0 +- printd("F: prf return value", &out); +-#endif ++ + /* And xor them together. */ + for (k = 0; k < hlen; k++) + output[k] ^= u_tmp1[k]; +-#if 0 +- printf("F: xor result:\n"); +- for (k = 0; k < hlen; k++) +- printf(" %02x", 0xff & output[k]); +- printf("\n"); +-#endif + } + return 0; + } +@@ -185,9 +160,6 @@ pbkdf2(const struct krb5_hash_provider *hash, krb5_keyblock *pass, + + /* Step 3. */ + for (i = 1; i <= l; i++) { +-#if 0 +- int j; +-#endif + krb5_error_code err; + char *out; + +@@ -205,12 +177,6 @@ pbkdf2(const struct krb5_hash_provider *hash, krb5_keyblock *pass, + memcpy(output->data + (i-1) * hlen, utmp3, + output->length - (i-1) * hlen); + +-#if 0 +- printf("after F(%d), @%p:\n", i, output->data); +- for (j = (i-1) * hlen; j < i * hlen; j++) +- printf(" %02x", 0xff & output->data[j]); +- printf ("\n"); +-#endif + } + free(utmp1); + free(utmp2); +diff --git a/src/lib/crypto/builtin/sha1/t_shs.c b/src/lib/crypto/builtin/sha1/t_shs.c +index 08157b662..c1d18f557 100644 +--- a/src/lib/crypto/builtin/sha1/t_shs.c ++++ b/src/lib/crypto/builtin/sha1/t_shs.c +@@ -59,10 +59,6 @@ main() + { + SHS_INFO shsInfo; + unsigned int i; +-#if 0 +- time_t secondCount; +- SHS_BYTE data[ 200 ]; +-#endif + + /* Make sure we've got the endianness set right. If the machine is + big-endian (up to 64 bits) the following value will be signed, +@@ -120,17 +116,6 @@ main() + puts( "passed, result= 3232AFFA48628A26653B5AAA44541FD90D690603" ); + #endif /* NEW_SHS */ + +-#if 0 +- printf( "\nTesting speed for 100MB data... " ); +- shsInit( &shsInfo ); +- secondCount = time( NULL ); +- for( i = 0; i < 500000U; i++ ) +- shsUpdate( &shsInfo, data, 200 ); +- secondCount = time( NULL ) - secondCount; +- printf( "done. Time = %ld seconds, %ld kbytes/second.\n", \ +- secondCount, 100500L / secondCount ); +-#endif +- + puts( "\nAll SHS tests passed" ); + exit( 0 ); + } +diff --git a/src/lib/crypto/crypto_tests/t_cksums.c b/src/lib/crypto/crypto_tests/t_cksums.c +index 4b5406e67..5afc90ed8 100644 +--- a/src/lib/crypto/crypto_tests/t_cksums.c ++++ b/src/lib/crypto/crypto_tests/t_cksums.c +@@ -175,15 +175,11 @@ printhex(const char *head, void *data, size_t len) + + printf("%s", head); + for (i = 0; i < len; i++) { +-#if 0 /* For convenience when updating test cases. */ +- printf("\\x%02X", ((unsigned char*)data)[i]); +-#else + printf("%02X", ((unsigned char*)data)[i]); + if (i % 16 == 15 && i + 1 < len) + printf("\n%*s", (int)strlen(head), ""); + else if (i + 1 < len) + printf(" "); +-#endif + } + printf("\n"); + } +diff --git a/src/lib/crypto/crypto_tests/t_crc.c b/src/lib/crypto/crypto_tests/t_crc.c +index 1a35cfba5..8cd1d36cb 100644 +--- a/src/lib/crypto/crypto_tests/t_crc.c ++++ b/src/lib/crypto/crypto_tests/t_crc.c +@@ -107,41 +107,9 @@ struct crc_trial trials[] = { + + #define NTRIALS (sizeof(trials) / sizeof(trials[0])) + +-#if 0 +-static void +-timetest(unsigned int nblk, unsigned int blksiz) +-{ +- char *block; +- unsigned int i; +- struct tms before, after; +- unsigned long cksum; + +- block = malloc(blksiz * nblk); +- if (block == NULL) +- exit(1); +- for (i = 0; i < blksiz * nblk; i++) +- block[i] = i % 256; +- times(&before); +- for (i = 0; i < nblk; i++) { +- cksum = 0; +- mit_crc32(block + i * blksiz, blksiz, &cksum); +- } +- +- times(&after); +- printf("shift-8 implementation, %d blocks of %d bytes:\n", +- nblk, blksiz); +- printf("\tu=%ld s=%ld cu=%ld cs=%ld\n", +- (long)(after.tms_utime - before.tms_utime), +- (long)(after.tms_stime - before.tms_stime), +- (long)(after.tms_cutime - before.tms_cutime), +- (long)(after.tms_cstime - before.tms_cstime)); +- +- free(block); +-} +-#endif +- +-static void +-verify(void) ++int ++main(void) + { + unsigned int i; + struct crc_trial trial; +@@ -176,14 +144,5 @@ verify(void) + (trial.sum == cksum) ? "OK" : "***BAD***", + typestr, trial.data, cksum); + } +-} +- +-int +-main(void) +-{ +-#if 0 +- timetest(64*1024, 1024); +-#endif +- verify(); + exit(0); + } +diff --git a/src/lib/crypto/crypto_tests/t_cts.c b/src/lib/crypto/crypto_tests/t_cts.c +index 2b022b4ac..fe505169f 100644 +--- a/src/lib/crypto/crypto_tests/t_cts.c ++++ b/src/lib/crypto/crypto_tests/t_cts.c +@@ -44,37 +44,10 @@ + + const char *whoami; + +-#if 0 +-static void printhex (size_t len, const char *p) +-{ +- while (len--) +- printf ("%02x", 0xff & *p++); +-} +- +-static void printstringhex (const char *p) { printhex (strlen (p), p); } +- +-static void printdata (krb5_data *d) { printhex (d->length, d->data); } +- +-static void printkey (krb5_keyblock *k) { printhex (k->length, k->contents); } +-#endif +- +- + #define JURISIC "Juri\305\241i\304\207" /* hi Miro */ + #define ESZETT "\303\237" + #define GCLEF "\360\235\204\236" /* outside BMP, woo hoo! */ + +-#if 0 +-static void +-check_error (int r, int line) { +- if (r != 0) { +- fprintf (stderr, "%s:%d: %s\n", __FILE__, line, +- error_message (r)); +- exit (1); +- } +-} +-#define CHECK check_error(r, __LINE__) +-#endif +- + static void printd (const char *descr, krb5_data *d) { + unsigned int i, j; + const int r = 16; +diff --git a/src/lib/crypto/crypto_tests/t_decrypt.c b/src/lib/crypto/crypto_tests/t_decrypt.c +index 1dbc4dd1b..4ae0256cc 100644 +--- a/src/lib/crypto/crypto_tests/t_decrypt.c ++++ b/src/lib/crypto/crypto_tests/t_decrypt.c +@@ -658,15 +658,11 @@ printhex(const char *head, void *data, size_t len) + + printf("%s", head); + for (i = 0; i < len; i++) { +-#if 0 /* For convenience when updating test cases. */ +- printf("\\x%02X", ((unsigned char*)data)[i]); +-#else + printf("%02X", ((unsigned char*)data)[i]); + if (i % 16 == 15 && i + 1 < len) + printf("\n%*s", (int)strlen(head), ""); + else if (i + 1 < len) + printf(" "); +-#endif + } + printf("\n"); + } +diff --git a/src/lib/crypto/crypto_tests/t_derive.c b/src/lib/crypto/crypto_tests/t_derive.c +index 381ae4393..afbf7477f 100644 +--- a/src/lib/crypto/crypto_tests/t_derive.c ++++ b/src/lib/crypto/crypto_tests/t_derive.c +@@ -273,15 +273,11 @@ printhex(const char *head, void *data, size_t len) + + printf("%s", head); + for (i = 0; i < len; i++) { +-#if 0 /* For convenience when updating test cases. */ +- printf("\\x%02X", ((unsigned char*)data)[i]); +-#else + printf("%02X", ((unsigned char*)data)[i]); + if (i % 16 == 15 && i + 1 < len) + printf("\n%*s", (int)strlen(head), ""); + else if (i + 1 < len) + printf(" "); +-#endif + } + printf("\n"); + } +diff --git a/src/lib/crypto/crypto_tests/t_hmac.c b/src/lib/crypto/crypto_tests/t_hmac.c +index 93d54828f..da359cb49 100644 +--- a/src/lib/crypto/crypto_tests/t_hmac.c ++++ b/src/lib/crypto/crypto_tests/t_hmac.c +@@ -46,17 +46,6 @@ static void keyToData (krb5_keyblock *k, krb5_data *d) { + d->data = (char *) k->contents; + } + +-#if 0 +-static void check_error (int r, int line) { +- if (r != 0) { +- fprintf (stderr, "%s:%d: %s\n", __FILE__, line, +- error_message (r)); +- exit (1); +- } +-} +-#define CHECK check_error(r, __LINE__) +-#endif +- + static void printd (const char *descr, krb5_data *d) { + unsigned int i, j; + const int r = 16; +diff --git a/src/lib/crypto/crypto_tests/t_str2key.c b/src/lib/crypto/crypto_tests/t_str2key.c +index 7a7813874..27896e61e 100644 +--- a/src/lib/crypto/crypto_tests/t_str2key.c ++++ b/src/lib/crypto/crypto_tests/t_str2key.c +@@ -719,15 +719,11 @@ printhex(const char *head, void *data, size_t len) + + printf("%s", head); + for (i = 0; i < len; i++) { +-#if 0 /* For convenience when updating test cases. */ +- printf("\\x%02X", ((unsigned char*)data)[i]); +-#else + printf("%02X", ((unsigned char*)data)[i]); + if (i % 16 == 15 && i + 1 < len) + printf("\n%*s", (int)strlen(head), ""); + else if (i + 1 < len) + printf(" "); +-#endif + } + printf("\n"); + } +diff --git a/src/lib/crypto/crypto_tests/vectors.c b/src/lib/crypto/crypto_tests/vectors.c +index 482d2de20..c1a765732 100644 +--- a/src/lib/crypto/crypto_tests/vectors.c ++++ b/src/lib/crypto/crypto_tests/vectors.c +@@ -448,11 +448,6 @@ int main (int argc, char **argv) + { + whoami = argv[0]; + test_nfold (); +-#if 0 +- test_mit_des_s2k (); +- test_des3_s2k (); +- test_dr_dk (); +-#endif + test_pbkdf2(); + return 0; + } +diff --git a/src/lib/crypto/krb/nfold.c b/src/lib/crypto/krb/nfold.c +index ea02fddcf..75bceaecd 100644 +--- a/src/lib/crypto/krb/nfold.c ++++ b/src/lib/crypto/krb/nfold.c +@@ -98,19 +98,9 @@ krb5int_nfold(unsigned int inbits, const unsigned char *in, unsigned int outbits + byte += out[i%outbits]; + out[i%outbits] = byte&0xff; + +-#if 0 +- printf("msbit[%d] = %d\tbyte = %02x\tsum = %03x\n", i, msbit, +- (((in[((inbits-1)-(msbit>>3))%inbits]<<8)| +- (in[((inbits)-(msbit>>3))%inbits])) +- >>((msbit&7)+1))&0xff, byte); +-#endif +- + /* keep around the carry bit, if any */ + byte >>= 8; + +-#if 0 +- printf("carry=%d\n", byte); +-#endif + } + + /* if there's a carry bit left over, add it back in */ +diff --git a/src/lib/gssapi/generic/util_set.c b/src/lib/gssapi/generic/util_set.c +index 8866f525f..432a9ee0d 100644 +--- a/src/lib/gssapi/generic/util_set.c ++++ b/src/lib/gssapi/generic/util_set.c +@@ -40,21 +40,6 @@ int g_set_init(g_set_elt *s) + return(0); + } + +-#if 0 +-int g_set_destroy(g_set_elt *s) +-{ +- g_set next; +- +- while (*s) { +- next = (*s)->next; +- free(*s); +- *s = next; +- } +- +- return(0); +-} +-#endif +- + int g_set_entry_add(g_set_elt *s, void *key, void *value) + { + g_set_elt first; +diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c +index 06967aa27..5baa6cecf 100644 +--- a/src/lib/gssapi/krb5/accept_sec_context.c ++++ b/src/lib/gssapi/krb5/accept_sec_context.c +@@ -654,17 +654,6 @@ kg_accept_krb5(minor_status, context_handle, + + krb5_auth_con_getauthenticator(context, auth_context, &authdat); + +-#if 0 +- /* make sure the necessary parts of the authdat are present */ +- +- if ((authdat->authenticator->subkey == NULL) || +- (authdat->ticket->enc_part2 == NULL)) { +- code = KG_NO_SUBKEY; +- major_status = GSS_S_FAILURE; +- goto fail; +- } +-#endif +- + if (authdat->checksum == NULL) { + /* + * Some SMB client implementations use handcrafted GSSAPI code that +diff --git a/src/lib/gssapi/krb5/gssapi_krb5.c b/src/lib/gssapi/krb5/gssapi_krb5.c +index 43930dd61..1eaf2bffb 100644 +--- a/src/lib/gssapi/krb5/gssapi_krb5.c ++++ b/src/lib/gssapi/krb5/gssapi_krb5.c +@@ -465,28 +465,12 @@ krb5_gss_inquire_cred_by_oid(OM_uint32 *minor_status, + return GSS_S_UNAVAILABLE; + } + +-/* +- * gss_set_sec_context_option() methods +- * (Disabled until we have something to populate the array.) +- */ +-#if 0 +-static struct { +- gss_OID_desc oid; +- OM_uint32 (*func)(OM_uint32 *, gss_ctx_id_t *, const gss_OID, const gss_buffer_t); +-} krb5_gss_set_sec_context_option_ops[] = { +-}; +-#endif +- + OM_uint32 KRB5_CALLCONV + krb5_gss_set_sec_context_option (OM_uint32 *minor_status, + gss_ctx_id_t *context_handle, + const gss_OID desired_object, + const gss_buffer_t value) + { +-#if 0 +- size_t i; +-#endif +- + if (minor_status == NULL) + return GSS_S_CALL_INACCESSIBLE_WRITE; + +@@ -498,18 +482,6 @@ krb5_gss_set_sec_context_option (OM_uint32 *minor_status, + if (desired_object == GSS_C_NO_OID) + return GSS_S_CALL_INACCESSIBLE_READ; + +-#if 0 +- for (i = 0; i < sizeof(krb5_gss_set_sec_context_option_ops)/ +- sizeof(krb5_gss_set_sec_context_option_ops[0]); i++) { +- if (g_OID_prefix_equal(desired_object, &krb5_gss_set_sec_context_option_ops[i].oid)) { +- return (*krb5_gss_set_sec_context_option_ops[i].func)(minor_status, +- context_handle, +- desired_object, +- value); +- } +- } +-#endif +- + *minor_status = EINVAL; + + return GSS_S_UNAVAILABLE; +diff --git a/src/lib/gssapi/krb5/naming_exts.c b/src/lib/gssapi/krb5/naming_exts.c +index 5f00efe34..41752d90b 100644 +--- a/src/lib/gssapi/krb5/naming_exts.c ++++ b/src/lib/gssapi/krb5/naming_exts.c +@@ -664,13 +664,3 @@ cleanup: + + return kg_map_name_error(minor_status, code); + } +- +-#if 0 +-OM_uint32 +-krb5_gss_display_name_ext(OM_uint32 *minor_status, +- gss_name_t name, +- gss_OID display_as_name_type, +- gss_buffer_t display_name) +-{ +-} +-#endif +diff --git a/src/lib/gssapi/mechglue/g_initialize.c b/src/lib/gssapi/mechglue/g_initialize.c +index 9197666e1..0ad11c0b0 100644 +--- a/src/lib/gssapi/mechglue/g_initialize.c ++++ b/src/lib/gssapi/mechglue/g_initialize.c +@@ -391,9 +391,6 @@ build_mechSet(void) + g_mechSet.count = count; + } + +-#if 0 +- g_mechSetTime = fileInfo.st_mtime; +-#endif + k5_mutex_unlock(&g_mechSetLock); + k5_mutex_unlock(&g_mechListLock); + +@@ -916,10 +913,6 @@ loadInterMech(gss_mech_info minfo) + + if (krb5int_open_plugin(minfo->uLibName, &dl, &errinfo) != 0 || + errinfo.code != 0) { +-#if 0 +- (void) syslog(LOG_INFO, "libgss dlopen(%s): %s\n", +- aMech->uLibName, dlerror()); +-#endif + return; + } + +@@ -959,12 +952,6 @@ loadInterMech(gss_mech_info minfo) + dl = NULL; + + cleanup: +-#if 0 +- if (aMech->mech == NULL) { +- (void) syslog(LOG_INFO, "unable to initialize mechanism" +- " library [%s]\n", aMech->uLibName); +- } +-#endif + if (dl != NULL) + krb5int_close_plugin(dl); + k5_clear_error(&errinfo); +@@ -1161,10 +1148,6 @@ gssint_get_mechanism(gss_const_OID oid) + + if (krb5int_open_plugin(aMech->uLibName, &dl, &errinfo) != 0 || + errinfo.code != 0) { +-#if 0 +- (void) syslog(LOG_INFO, "libgss dlopen(%s): %s\n", +- aMech->uLibName, dlerror()); +-#endif + k5_mutex_unlock(&g_mechListLock); + return ((gss_mechanism)NULL); + } +@@ -1180,10 +1163,6 @@ gssint_get_mechanism(gss_const_OID oid) + } + if (aMech->mech == NULL) { + (void) krb5int_close_plugin(dl); +-#if 0 +- (void) syslog(LOG_INFO, "unable to initialize mechanism" +- " library [%s]\n", aMech->uLibName); +-#endif + k5_mutex_unlock(&g_mechListLock); + return ((gss_mechanism)NULL); + } +@@ -1503,10 +1482,6 @@ addConfigEntry(const char *oidStr, const char *oid, const char *sharedLib, + oidBuf.length = strlen(oid); + if (generic_gss_str_to_oid(&minor, &oidBuf, &mechOid) + != GSS_S_COMPLETE) { +-#if 0 +- (void) syslog(LOG_INFO, "invalid mechanism oid" +- " [%s] in configuration file", oid); +-#endif + return; + } + +diff --git a/src/lib/gssapi/mechglue/g_inq_cred.c b/src/lib/gssapi/mechglue/g_inq_cred.c +index 911196264..cbe045ab9 100644 +--- a/src/lib/gssapi/mechglue/g_inq_cred.c ++++ b/src/lib/gssapi/mechglue/g_inq_cred.c +@@ -198,11 +198,6 @@ gss_inquire_cred_by_mech(minor_status, cred_handle, mech_type, name, + union_cred = (gss_union_cred_t) cred_handle; + mech_cred = gssint_get_mechanism_cred(union_cred, selected_mech); + +-#if 0 +- if (mech_cred == NULL) +- return (GSS_S_DEFECTIVE_CREDENTIAL); +-#endif +- + public_mech = gssint_get_public_oid(selected_mech); + status = mech->gss_inquire_cred_by_mech(minor_status, + mech_cred, public_mech, +diff --git a/src/lib/gssapi/mechglue/mglueP.h b/src/lib/gssapi/mechglue/mglueP.h +index 2b5145e07..2b00987e6 100644 +--- a/src/lib/gssapi/mechglue/mglueP.h ++++ b/src/lib/gssapi/mechglue/mglueP.h +@@ -730,11 +730,6 @@ typedef struct gss_mech_config { + /********************************************************/ + /* Internal mechglue routines */ + +-#if 0 +-int gssint_mechglue_init(void); +-void gssint_mechglue_fini(void); +-#endif +- + OM_uint32 gssint_select_mech_type(OM_uint32 *minor, gss_const_OID in_oid, + gss_OID *selected_oid); + gss_OID gssint_get_public_oid(gss_const_OID internal_oid); +diff --git a/src/lib/kadm5/clnt/client_init.c b/src/lib/kadm5/clnt/client_init.c +index 4350a9eb0..6f10db018 100644 +--- a/src/lib/kadm5/clnt/client_init.c ++++ b/src/lib/kadm5/clnt/client_init.c +@@ -161,7 +161,6 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, + generic_ret r = { 0, 0 }; + + initialize_ovk_error_table(); +-/* initialize_adb_error_table(); */ + initialize_ovku_error_table(); + + if (! server_handle) { +@@ -612,53 +611,8 @@ setup_gss(kadm5_server_handle_t handle, kadm5_config_params *params_in, + gssstat = gss_acquire_cred(&minor_stat, gss_client, 0, + GSS_C_NULL_OID_SET, GSS_C_INITIATE, + &handle->cred, NULL, NULL); +- if (gssstat != GSS_S_COMPLETE) { +-#if 0 /* for debugging only */ +- { +- OM_uint32 maj_status, min_status, message_context = 0; +- gss_buffer_desc status_string; +- do { +- maj_status = gss_display_status(&min_status, +- gssstat, +- GSS_C_GSS_CODE, +- GSS_C_NO_OID, +- &message_context, +- &status_string); +- if (maj_status == GSS_S_COMPLETE) { +- fprintf(stderr, "MAJ: %.*s\n", +- (int) status_string.length, +- (char *)status_string.value); +- gss_release_buffer(&min_status, &status_string); +- } else { +- fprintf(stderr, +- "MAJ? gss_display_status returns 0x%lx?!\n", +- (unsigned long) maj_status); +- message_context = 0; +- } +- } while (message_context != 0); +- do { +- maj_status = gss_display_status(&min_status, +- minor_stat, +- GSS_C_MECH_CODE, +- GSS_C_NO_OID, +- &message_context, +- &status_string); +- if (maj_status == GSS_S_COMPLETE) { +- fprintf(stderr, "MIN: %.*s\n", +- (int) status_string.length, +- (char *)status_string.value); +- gss_release_buffer(&min_status, &status_string); +- } else { +- fprintf(stderr, +- "MIN? gss_display_status returns 0x%lx?!\n", +- (unsigned long) maj_status); +- message_context = 0; +- } +- } while (message_context != 0); +- } +-#endif ++ if (gssstat != GSS_S_COMPLETE) + goto error; +- } + + /* + * Do actual creation of RPC auth handle. Implements auth flavor +diff --git a/src/lib/kadm5/srv/server_init.c b/src/lib/kadm5/srv/server_init.c +index b3ae4ff5c..87a732292 100644 +--- a/src/lib/kadm5/srv/server_init.c ++++ b/src/lib/kadm5/srv/server_init.c +@@ -186,7 +186,6 @@ kadm5_ret_t kadm5_init(krb5_context context, char *client_name, char *pass, + handle->context = context; + + initialize_ovk_error_table(); +-/* initialize_adb_error_table(); */ + initialize_ovku_error_table(); + + handle->magic_number = KADM5_SERVER_HANDLE_MAGIC; +@@ -207,16 +206,6 @@ kadm5_ret_t kadm5_init(krb5_context context, char *client_name, char *pass, + */ + memset(¶ms_local, 0, sizeof(params_local)); + +-#if 0 /* Now that we look at krb5.conf as well as kdc.conf, we can +- expect to see admin_server being set sometimes. */ +-#define ILLEGAL_PARAMS (KADM5_CONFIG_ADMIN_SERVER) +- if (params_in && (params_in->mask & ILLEGAL_PARAMS)) { +- free_db_args(handle); +- free(handle); +- return KADM5_BAD_SERVER_PARAMS; +- } +-#endif +- + ret = kadm5_get_config_params(handle->context, 1, params_in, + &handle->params); + if (ret) { +diff --git a/src/lib/kadm5/unit-test/setkey-test.c b/src/lib/kadm5/unit-test/setkey-test.c +index 0431653bf..fa2392f81 100644 +--- a/src/lib/kadm5/unit-test/setkey-test.c ++++ b/src/lib/kadm5/unit-test/setkey-test.c +@@ -35,15 +35,6 @@ krb5_keyblock *tests[] = { + test1, test2, test3, NULL + }; + +-#if 0 +-int keyblocks_equal(krb5_keyblock *kb1, krb5_keyblock *kb2) +-{ +- return (kb1->enctype == kb2->enctype && +- kb1->length == kb2->length && +- memcmp(kb1->contents, kb2->contents, kb1->length) == 0); +-} +-#endif +- + krb5_data tgtname = { + 0, + KRB5_TGS_NAME_SIZE, +diff --git a/src/lib/krb5/asn.1/ldap_key_seq.c b/src/lib/krb5/asn.1/ldap_key_seq.c +index 74569d9e2..f0be2d6d9 100644 +--- a/src/lib/krb5/asn.1/ldap_key_seq.c ++++ b/src/lib/krb5/asn.1/ldap_key_seq.c +@@ -96,9 +96,6 @@ no_salt(void *p) + DEFOPTIONALTYPE(key_data_salt_if_present, is_salt_present, no_salt, krbsalt); + DEFCTAGGEDTYPE(key_data_0, 0, key_data_salt_if_present); + DEFCTAGGEDTYPE(key_data_1, 1, encryptionkey); +-#if 0 /* We don't support this field currently. */ +-DEFCTAGGEDTYPE(key_data_2, 2, s2kparams), +-#endif + static const struct atype_info *key_data_fields[] = { + &k5_atype_key_data_0, &k5_atype_key_data_1 + }; +diff --git a/src/lib/krb5/ccache/ccapi/stdcc.c b/src/lib/krb5/ccache/ccapi/stdcc.c +index 0256a0a5d..db69eebb4 100644 +--- a/src/lib/krb5/ccache/ccapi/stdcc.c ++++ b/src/lib/krb5/ccache/ccapi/stdcc.c +@@ -1300,14 +1300,6 @@ krb5_error_code KRB5_CALLCONV krb5_stdcc_initialize + return cc_err_xlate(err); + } + +-#if 0 +- /* +- * Some implementations don't set the principal name +- * correctly, so we force set it to the correct value. +- */ +- err = cc_set_principal(gCntrlBlock, ccapi_data->NamedCache, +- CC_CRED_V5, cName); +-#endif + krb5_free_unparsed_name(context, cName); + cache_changed(); + +@@ -1432,54 +1424,6 @@ krb5_error_code KRB5_CALLCONV krb5_stdcc_next_cred + * + * - try to find a matching credential in the cache + */ +-#if 0 +-krb5_error_code KRB5_CALLCONV krb5_stdcc_retrieve +-(krb5_context context, +- krb5_ccache id, +- krb5_flags whichfields, +- krb5_creds *mcreds, +- krb5_creds *creds ) +-{ +- krb5_error_code retval; +- krb5_cc_cursor curs = NULL; +- krb5_creds *fetchcreds; +- +- if ((retval = stdcc_setup(context, NULL))) +- return retval; +- +- fetchcreds = (krb5_creds *)malloc(sizeof(krb5_creds)); +- if (fetchcreds == NULL) return KRB5_CC_NOMEM; +- +- /* we're going to use the iterators */ +- krb5_stdcc_start_seq_get(context, id, &curs); +- +- while (!krb5_stdcc_next_cred(context, id, &curs, fetchcreds)) { +- /* +- * look at each credential for a match +- * use this match routine since it takes the +- * whichfields and the API doesn't +- */ +- if (stdccCredsMatch(context, fetchcreds, +- mcreds, whichfields)) { +- /* we found it, copy and exit */ +- *creds = *fetchcreds; +- krb5_stdcc_end_seq_get(context, id, &curs); +- return 0; +- } +- /* free copy allocated by next_cred */ +- krb5_free_cred_contents(context, fetchcreds); +- } +- +- /* no luck, end get and exit */ +- krb5_stdcc_end_seq_get(context, id, &curs); +- +- /* we're not using this anymore so we should get rid of it! */ +- free(fetchcreds); +- +- return KRB5_CC_NOTFOUND; +-} +-#else +- + krb5_error_code KRB5_CALLCONV + krb5_stdcc_retrieve(context, id, whichfields, mcreds, creds) + krb5_context context; +@@ -1492,8 +1436,6 @@ krb5_stdcc_retrieve(context, id, whichfields, mcreds, creds) + creds); + } + +-#endif +- + /* + * end seq + * +diff --git a/src/lib/krb5/ccache/ccapi/winccld.h b/src/lib/krb5/ccache/ccapi/winccld.h +index 85017abbd..df34e3346 100644 +--- a/src/lib/krb5/ccache/ccapi/winccld.h ++++ b/src/lib/krb5/ccache/ccapi/winccld.h +@@ -85,24 +85,10 @@ DECL_FUNC_PTR(cc_create); + DECL_FUNC_PTR(cc_open); + DECL_FUNC_PTR(cc_close); + DECL_FUNC_PTR(cc_destroy); +-#if 0 /* Not used */ +-#ifdef CC_API_VER2 +-DECL_FUNC_PTR(cc_seq_fetch_NCs_begin); +-DECL_FUNC_PTR(cc_seq_fetch_NCs_next); +-DECL_FUNC_PTR(cc_seq_fetch_NCs_end); +-#else +-DECL_FUNC_PTR(cc_seq_fetch_NCs); +-#endif +-DECL_FUNC_PTR(cc_get_NC_info); +-DECL_FUNC_PTR(cc_free_NC_info); +-#endif + DECL_FUNC_PTR(cc_get_name); + DECL_FUNC_PTR(cc_set_principal); + DECL_FUNC_PTR(cc_get_principal); + DECL_FUNC_PTR(cc_get_cred_version); +-#if 0 /* Not used */ +-DECL_FUNC_PTR(cc_lock_request); +-#endif + DECL_FUNC_PTR(cc_store); + DECL_FUNC_PTR(cc_remove_cred); + #ifdef CC_API_VER2 +@@ -127,18 +113,10 @@ FUNC_INFO krbcc_fi[] = { + MAKE_FUNC_INFO(cc_open), + MAKE_FUNC_INFO(cc_close), + MAKE_FUNC_INFO(cc_destroy), +-#if 0 /* Not used */ +- MAKE_FUNC_INFO(cc_seq_fetch_NCs), +- MAKE_FUNC_INFO(cc_get_NC_info), +- MAKE_FUNC_INFO(cc_free_NC_info), +-#endif + MAKE_FUNC_INFO(cc_get_name), + MAKE_FUNC_INFO(cc_set_principal), + MAKE_FUNC_INFO(cc_get_principal), + MAKE_FUNC_INFO(cc_get_cred_version), +-#if 0 /* Not used */ +- MAKE_FUNC_INFO(cc_lock_request), +-#endif + MAKE_FUNC_INFO(cc_store), + MAKE_FUNC_INFO(cc_remove_cred), + #ifdef CC_API_VER2 +@@ -166,24 +144,10 @@ FUNC_INFO krbcc_fi[] = { + #define cc_open pcc_open + #define cc_close pcc_close + #define cc_destroy pcc_destroy +-#if 0 /* Not used */ +-#ifdef CC_API_VER2 +-#define cc_seq_fetch_NCs_begin pcc_seq_fetch_NCs_begin +-#define cc_seq_fetch_NCs_next pcc_seq_fetch_NCs_next +-#define cc_seq_fetch_NCs_end pcc_seq_fetch_NCs_end +-#else +-#define cc_seq_fetch_NCs pcc_seq_fetch_NCs +-#endif +-#define cc_get_NC_info pcc_get_NC_info +-#define cc_free_NC_info pcc_free_NC_info +-#endif /* End of Not used */ + #define cc_get_name pcc_get_name + #define cc_set_principal pcc_set_principal + #define cc_get_principal pcc_get_principal + #define cc_get_cred_version pcc_get_cred_version +-#if 0 /* Not used */ +-#define cc_lock_request pcc_lock_request +-#endif + #define cc_store pcc_store + #define cc_remove_cred pcc_remove_cred + #ifdef CC_API_VER2 +diff --git a/src/lib/krb5/keytab/t_keytab.c b/src/lib/krb5/keytab/t_keytab.c +index 80a94eafe..c845596d6 100644 +--- a/src/lib/krb5/keytab/t_keytab.c ++++ b/src/lib/krb5/keytab/t_keytab.c +@@ -441,16 +441,3 @@ main(void) + return 0; + + } +- +- +-#if 0 +-/* remove and add are functions, so that they can return NOWRITE +- if not a writable keytab */ +-krb5_error_code KRB5_CALLCONV krb5_kt_remove_entry +-(krb5_context, +- krb5_keytab, +- krb5_keytab_entry * ); +- +- +- +-#endif +diff --git a/src/lib/krb5/krb/gc_via_tkt.c b/src/lib/krb5/krb/gc_via_tkt.c +index 5b9bb9573..e7a3b01f8 100644 +--- a/src/lib/krb5/krb/gc_via_tkt.c ++++ b/src/lib/krb5/krb/gc_via_tkt.c +@@ -131,17 +131,6 @@ check_reply_server(krb5_context context, krb5_flags kdcoptions, + /* Canonicalization not requested, and not a TGS referral. */ + return KRB5_KDCREP_MODIFIED; + } +-#if 0 +- /* +- * Is this check needed? find_nxt_kdc() in gc_frm_kdc.c already +- * effectively checks this. +- */ +- if (krb5_realm_compare(context, in_cred->client, in_cred->server) && +- data_eq(*in_cred->server->data[1], *in_cred->client->realm)) { +- /* Attempted to rewrite local TGS. */ +- return KRB5_KDCREP_MODIFIED; +- } +-#endif + return 0; + } + +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index 4246c5dd2..c90b2af87 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -232,13 +232,6 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + get_integer(ctx, KRB5_CONF_CLOCKSKEW, DEFAULT_CLOCKSKEW, &tmp); + ctx->clockskew = tmp; + +-#if 0 +- /* Default ticket lifetime is currently not supported */ +- profile_get_integer(ctx->profile, KRB5_CONF_LIBDEFAULTS, "tkt_lifetime", +- 0, 10 * 60 * 60, &tmp); +- ctx->tkt_lifetime = tmp; +-#endif +- + /* DCE 1.1 and below only support CKSUMTYPE_RSA_MD4 (2) */ + /* DCE add kdc_req_checksum_type = 2 to krb5.conf */ + get_integer(ctx, KRB5_CONF_KDC_REQ_CHECKSUM_TYPE, CKSUMTYPE_RSA_MD5, +diff --git a/src/lib/krb5/krb/rd_req_dec.c b/src/lib/krb5/krb/rd_req_dec.c +index 6defbdbf0..4cd429a11 100644 +--- a/src/lib/krb5/krb/rd_req_dec.c ++++ b/src/lib/krb5/krb/rd_req_dec.c +@@ -441,30 +441,6 @@ decrypt_ticket(krb5_context context, const krb5_ap_req *req, + #endif /* LEAN_CLIENT */ + } + +-#if 0 +-#include +-static void +-debug_log_authz_data(const char *which, krb5_authdata **a) +-{ +- if (a) { +- syslog(LOG_ERR|LOG_DAEMON, "%s authz data:", which); +- while (*a) { +- syslog(LOG_ERR|LOG_DAEMON, " ad_type:%d length:%d '%.*s'", +- (*a)->ad_type, (*a)->length, (*a)->length, +- (char *) (*a)->contents); +- a++; +- } +- syslog(LOG_ERR|LOG_DAEMON, " [end]"); +- } else +- syslog(LOG_ERR|LOG_DAEMON, "no %s authz data", which); +-} +-#else +-static void +-debug_log_authz_data(const char *which, krb5_authdata **a) +-{ +-} +-#endif +- + static krb5_error_code + rd_req_decoded_opt(krb5_context context, krb5_auth_context *auth_context, + const krb5_ap_req *req, krb5_const_principal server, +@@ -759,8 +735,6 @@ rd_req_decoded_opt(krb5_context context, krb5_auth_context *auth_context, + &((*auth_context)->key)))) + goto cleanup; + +- debug_log_authz_data("ticket", req->ticket->enc_part2->authorization_data); +- + /* + * If not AP_OPTS_MUTUAL_REQUIRED then and sequence numbers are used + * then the default sequence number is the one's complement of the +@@ -855,10 +829,9 @@ decrypt_authenticator(krb5_context context, const krb5_ap_req *request, + free(scratch.data);} + + /* now decode the decrypted stuff */ +- if (!(retval = decode_krb5_authenticator(&scratch, &local_auth))) { ++ if (!(retval = decode_krb5_authenticator(&scratch, &local_auth))) + *authpp = local_auth; +- debug_log_authz_data("authenticator", local_auth->authorization_data); +- } ++ + clean_scratch(); + return retval; + } +diff --git a/src/lib/krb5/krb/t_ser.c b/src/lib/krb5/krb/t_ser.c +index 9cdf5e641..1d6cceaa2 100644 +--- a/src/lib/krb5/krb/t_ser.c ++++ b/src/lib/krb5/krb/t_ser.c +@@ -151,10 +151,6 @@ ser_data(int verbose, char *msg, krb5_pointer ctx, krb5_magic dtype) + krb5_encrypt_block *eblock; + + eblock = (krb5_encrypt_block *) nctx; +-#if 0 +- if (eblock->priv && eblock->priv_size) +- free(eblock->priv); +-#endif + if (eblock->key) + krb5_free_keyblock(ser_ctx, eblock->key); + free(eblock); +@@ -450,60 +446,6 @@ ser_rcache_test(krb5_context kcontext, int verbose) + return(kret); + } + +-#if 0 +-/* +- * Serialize krb5_encrypt_block. +- */ +-static krb5_error_code +-ser_eblock_test(kcontext, verbose) +- krb5_context kcontext; +- int verbose; +-{ +- krb5_error_code kret; +- krb5_encrypt_block eblock; +- krb5_keyblock ukeyblock; +- krb5_octet keydata[8]; +- +- memset(&eblock, 0, sizeof(krb5_encrypt_block)); +- eblock.magic = KV5M_ENCRYPT_BLOCK; +- krb5_use_enctype(kcontext, &eblock, DEFAULT_KDC_ENCTYPE); +- if (!(kret = ser_data(verbose, "> NULL eblock", +- (krb5_pointer) &eblock, KV5M_ENCRYPT_BLOCK))) { +-#if 0 +- eblock.priv = (krb5_pointer) stuff; +- eblock.priv_size = 8; +-#endif +- if (!(kret = ser_data(verbose, "> eblock with private data", +- (krb5_pointer) &eblock, +- KV5M_ENCRYPT_BLOCK))) { +- memset(&ukeyblock, 0, sizeof(ukeyblock)); +- memset(keydata, 0, sizeof(keydata)); +- ukeyblock.enctype = ENCTYPE_DES_CBC_MD5; +- ukeyblock.length = sizeof(keydata); +- ukeyblock.contents = keydata; +- keydata[0] = 0xde; +- keydata[1] = 0xad; +- keydata[2] = 0xbe; +- keydata[3] = 0xef; +- keydata[4] = 0xfe; +- keydata[5] = 0xed; +- keydata[6] = 0xf0; +- keydata[7] = 0xd; +- eblock.key = &ukeyblock; +- if (!(kret = ser_data(verbose, "> eblock with private key", +- (krb5_pointer) &eblock, +- KV5M_ENCRYPT_BLOCK))) { +- if (verbose) +- printf("* eblock test succeeded\n"); +- } +- } +- } +- if (kret) +- printf("* eblock test failed\n"); +- return(kret); +-} +-#endif +- + /* + * Serialize krb5_principal + */ +@@ -584,7 +526,7 @@ main(int argc, char **argv) + do_ptest = 1; + do_rtest = 1; + do_stest = 1; +- while ((option = getopt(argc, argv, "acekprsxvACEKPRSX")) != -1) { ++ while ((option = getopt(argc, argv, "acekprsxvACKPRSX")) != -1) { + switch (option) { + case 'a': + do_atest = 0; +@@ -619,11 +561,6 @@ main(int argc, char **argv) + case 'C': + do_ctest = 1; + break; +-#if 0 +- case 'E': +- do_etest = 1; +- break; +-#endif + case 'K': + do_ktest = 1; + break; +@@ -641,7 +578,7 @@ main(int argc, char **argv) + break; + default: + fprintf(stderr, +- "%s: usage is %s [-acekprsxvACEKPRSX]\n", ++ "%s: usage is %s [-acekprsxvACKPRSX]\n", + argv[0], argv[0]); + exit(1); + break; +@@ -682,14 +619,6 @@ main(int argc, char **argv) + if (kret) + goto fail; + } +-#if 0 /* code to be tested is currently disabled */ +- if (do_etest) { +- ch_err = 'e'; +- kret = ser_eblock_test(kcontext, verbose); +- if (kret) +- goto fail; +- } +-#endif + if (do_ptest) { + ch_err = 'p'; + kret = ser_princ_test(kcontext, verbose); +diff --git a/src/lib/krb5/krb/unparse.c b/src/lib/krb5/krb/unparse.c +index 5bb64d00a..d94aa3cfa 100644 +--- a/src/lib/krb5/krb/unparse.c ++++ b/src/lib/krb5/krb/unparse.c +@@ -122,13 +122,6 @@ copy_component_quoting(char *dest, const krb5_data *src, int flags) + *q++ = '\\'; + *q++ = 'b'; + break; +-#if 0 +- /* Heimdal escapes spaces in principal names upon unparsing */ +- case ' ': +- *q++ = '\\'; +- *q++ = ' '; +- break; +-#endif + case '\0': + *q++ = '\\'; + *q++ = '0'; +diff --git a/src/lib/krb5/os/localaddr.c b/src/lib/krb5/os/localaddr.c +index 58443f6e3..92d765f4b 100644 +--- a/src/lib/krb5/os/localaddr.c ++++ b/src/lib/krb5/os/localaddr.c +@@ -392,20 +392,6 @@ get_linux_ipv6_addrs () + a6.s6_addr[i] = addrbyte[i]; + if (scope != 0) + continue; +-#if 0 /* These symbol names are as used by ifconfig, but none of the +- system header files export them. Dig up the kernel versions +- someday and see if they're exported. */ +- switch (scope) { +- case 0: +- default: +- break; +- case IPV6_ADDR_LINKLOCAL: +- case IPV6_ADDR_SITELOCAL: +- case IPV6_ADDR_COMPATv4: +- case IPV6_ADDR_LOOPBACK: +- continue; +- } +-#endif + nw = calloc (1, sizeof (struct linux_ipv6_addr_list)); + if (nw == 0) + continue; +@@ -1331,14 +1317,6 @@ krb5_os_localaddr(krb5_context context, krb5_address ***addr) + return get_localaddrs(context, addr, 1); + } + +-#if 0 /* not actually used anywhere currently */ +-krb5_error_code +-krb5int_local_addresses(krb5_context context, krb5_address ***addr) +-{ +- return get_localaddrs(context, addr, 0); +-} +-#endif +- + static krb5_error_code + get_localaddrs (krb5_context context, krb5_address ***addr, int use_profile) + { +diff --git a/src/lib/krb5/rcache/rc_io.c b/src/lib/krb5/rcache/rc_io.c +index b9859fe9f..35fa14a1f 100644 +--- a/src/lib/krb5/rcache/rc_io.c ++++ b/src/lib/krb5/rcache/rc_io.c +@@ -117,10 +117,6 @@ krb5_rc_io_mkstemp(krb5_context context, krb5_rc_iostuff *d, char *dir) + return 0; + } + +-#if 0 +-static krb5_error_code rc_map_errno (int) __attribute__((cold)); +-#endif +- + static krb5_error_code + rc_map_errno (krb5_context context, int e, const char *fn, + const char *operation) +diff --git a/src/lib/rpc/auth_gssapi.c b/src/lib/rpc/auth_gssapi.c +index ace0be925..568ec6d87 100644 +--- a/src/lib/rpc/auth_gssapi.c ++++ b/src/lib/rpc/auth_gssapi.c +@@ -744,14 +744,6 @@ skip_call: + } + + free(AUTH_PRIVATE(auth)->client_handle.value); +- +-#if 0 +- PRINTF(("gssapi_destroy: calling GSSAPI_EXIT\n")); +- AUTH_PRIVATE(auth)->established = FALSE; +- callstat = clnt_call(AUTH_PRIVATE(auth)->clnt, AUTH_GSSAPI_EXIT, +- xdr_void, NULL, xdr_void, NULL, timeout); +-#endif +- + free(auth->ah_private); + free(auth); + PRINTF(("gssapi_destroy: done\n")); +diff --git a/src/lib/rpc/svc_auth.c b/src/lib/rpc/svc_auth.c +index 5fedef7d7..e0f80af0b 100644 +--- a/src/lib/rpc/svc_auth.c ++++ b/src/lib/rpc/svc_auth.c +@@ -59,9 +59,6 @@ static struct svcauthsw_type { + } svcauthsw[] = { + {AUTH_GSSAPI, gssrpc__svcauth_gssapi}, /* AUTH_GSSAPI */ + {AUTH_NONE, gssrpc__svcauth_none}, /* AUTH_NONE */ +-#if 0 +- {AUTH_GSSAPI_COMPAT, gssrpc__svcauth_gssapi}, /* AUTH_GSSAPI_COMPAT */ +-#endif + {AUTH_UNIX, gssrpc__svcauth_unix}, /* AUTH_UNIX */ + {AUTH_SHORT, gssrpc__svcauth_short}, /* AUTH_SHORT */ + {RPCSEC_GSS, gssrpc__svcauth_gss} /* RPCSEC_GSS */ +diff --git a/src/lib/rpc/svc_auth_gssapi.c b/src/lib/rpc/svc_auth_gssapi.c +index f3b3e35b8..384bdc336 100644 +--- a/src/lib/rpc/svc_auth_gssapi.c ++++ b/src/lib/rpc/svc_auth_gssapi.c +@@ -869,10 +869,6 @@ done: + L_PRINTF(2, ("destroy_client: client %d destroyed\n", client_data->key)); + + free(client_data); +- +-#if 0 /*ifdef PURIFY*/ +- purify_watch_n(client_data, sizeof(*client_data), "rw"); +-#endif + } + + static void dump_db(char *msg) +diff --git a/src/lib/win_glue.c b/src/lib/win_glue.c +index 3d6dd7206..e149a1226 100644 +--- a/src/lib/win_glue.c ++++ b/src/lib/win_glue.c +@@ -111,10 +111,6 @@ void GetCallingAppVerInfo( char *AppTitle, char *AppVer, char *AppIni, + * hey , I bet we don't have a version resource, let's + * punt + */ +-#if 0 +- /* let's see what we have? (1813 means no resource) */ +- size = GetLastError(); /* WIN32 only */ +-#endif + *VSflag = FALSE; + return; + } +@@ -291,11 +287,6 @@ krb5_error_code krb5_vercheck() + return retval; + #endif + #ifdef VERSERV +-#if 0 +- /* Check library ? */ +- if (CallVersionServer(APP_TITLE, APP_VER, APP_INI, NULL)) +- return KRB5_LIB_EXPIRED; +-#endif + { + #ifdef APP_TITLE + if (CallVersionServer(APP_TITLE, APP_VER, APP_INI, NULL)) +diff --git a/src/plugins/kdb/db2/lockout.c b/src/plugins/kdb/db2/lockout.c +index 3a4f41821..30fb554db 100644 +--- a/src/plugins/kdb/db2/lockout.c ++++ b/src/plugins/kdb/db2/lockout.c +@@ -157,10 +157,6 @@ krb5_db2_lockout_audit(krb5_context context, + case KRB5KDC_ERR_PREAUTH_FAILED: + case KRB5KRB_AP_ERR_BAD_INTEGRITY: + break; +-#if 0 +- case KRB5KDC_ERR_CLIENT_REVOKED: +- break; +-#endif + default: + return 0; + } +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c +index 28dffe0c2..f6d00be9f 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c ++++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c +@@ -777,9 +777,6 @@ krb5_ldap_read_realm_params(krb5_context context, char *lrealm, + ent = ldap_first_entry (ld, result); + if (ent == NULL) { + ldap_get_option (ld, LDAP_OPT_ERROR_NUMBER, (void *) &st); +-#if 0 +- st = translate_ldap_error(st, OP_SEARCH); +-#endif + goto cleanup; + } + +diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c +index 77e9e5308..238101762 100644 +--- a/src/plugins/preauth/pkinit/pkinit_clnt.c ++++ b/src/plugins/preauth/pkinit/pkinit_clnt.c +@@ -507,24 +507,6 @@ verify_kdc_san(krb5_context context, + for (hostptr = certhosts; *hostptr != NULL; hostptr++) + TRACE_PKINIT_CLIENT_SAN_KDCCERT_DNSNAME(context, *hostptr); + } +-#if 0 +- retval = call_san_checking_plugins(context, plgctx, reqctx, idctx, +- princs, hosts, &plugin_decision, +- need_eku_checking); +- pkiDebug("%s: call_san_checking_plugins() returned retval %d\n", +- __FUNCTION__); +- if (retval) { +- retval = KRB5KDC_ERR_KDC_NAME_MISMATCH; +- goto out; +- } +- pkiDebug("%s: call_san_checking_plugins() returned decision %d and " +- "need_eku_checking %d\n", +- __FUNCTION__, plugin_decision, *need_eku_checking); +- if (plugin_decision != NO_DECISION) { +- retval = plugin_decision; +- goto out; +- } +-#endif + + pkiDebug("%s: Checking pkinit sans\n", __FUNCTION__); + for (i = 0; princs != NULL && princs[i] != NULL; i++) { +diff --git a/src/plugins/preauth/pkinit/pkinit_matching.c b/src/plugins/preauth/pkinit/pkinit_matching.c +index c2a4c084d..afcce3f8b 100644 +--- a/src/plugins/preauth/pkinit/pkinit_matching.c ++++ b/src/plugins/preauth/pkinit/pkinit_matching.c +@@ -572,17 +572,6 @@ check_all_certs(krb5_context context, + */ + for (i = 0, md = matchdata[i]; md != NULL; md = matchdata[++i]) { + pkiDebug("%s: subject: '%s'\n", __FUNCTION__, md->subject_dn); +-#if 0 +- pkiDebug("%s: issuer: '%s'\n", __FUNCTION__, md->subject_dn); +- for (j = 0; md->sans != NULL && md->sans[j] != NULL; j++) { +- char *san_string; +- krb5_unparse_name(context, md->sans[j], &san_string); +- pkiDebug("%s: PKINIT san: '%s'\n", __FUNCTION__, san_string); +- krb5_free_unparsed_name(context, san_string); +- } +- for (j = 0; md->upns != NULL && md->upns[j] != NULL; j++) +- pkiDebug("%s: UPN san: '%s'\n", __FUNCTION__, md->upns[j]); +-#endif + certs_checked++; + for (rc = rs->crs; rc != NULL; rc = rc->next) { + comp_match = component_match(context, rc, md); +diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c +index 76ad5bf19..27e6ef4d2 100644 +--- a/src/plugins/preauth/pkinit/pkinit_srv.c ++++ b/src/plugins/preauth/pkinit/pkinit_srv.c +@@ -204,24 +204,6 @@ verify_client_san(krb5_context context, + goto out; + } + +- /* XXX Verify this is consistent with client side XXX */ +-#if 0 +- retval = call_san_checking_plugins(context, plgctx, reqctx, princs, +- upns, NULL, &plugin_decision, &ignore); +- pkiDebug("%s: call_san_checking_plugins() returned retval %d\n", +- __FUNCTION__); +- if (retval) { +- retval = KRB5KDC_ERR_CLIENT_NAME_MISMATCH; +- goto cleanup; +- } +- pkiDebug("%s: call_san_checking_plugins() returned decision %d\n", +- __FUNCTION__, plugin_decision); +- if (plugin_decision != NO_DECISION) { +- retval = plugin_decision; +- goto out; +- } +-#endif +- + #ifdef DEBUG_SAN_INFO + krb5_unparse_name(context, client, &client_string); + #endif +diff --git a/src/tests/asn.1/krb5_decode_leak.c b/src/tests/asn.1/krb5_decode_leak.c +index 22601c7bf..77fd3ee40 100644 +--- a/src/tests/asn.1/krb5_decode_leak.c ++++ b/src/tests/asn.1/krb5_decode_leak.c +@@ -633,18 +633,6 @@ main(int argc, char **argv) + krb5_free_ad_kdcissued); + ktest_empty_ad_kdcissued(&kdci); + } +-#if 0 +- /****************************************************************/ +- /* encode_krb5_ad_signedpath_data */ +- { +- krb5_ad_signedpath_data spd, *tmp; +- ktest_make_sample_ad_signedpath_data(&spd); +- leak_test(spd, encode_krb5_ad_signedpath_data, +- decode_krb5_ad_signedpath_data, +- NULL); +- ktest_empty_ad_signedpath_data(&spd); +- } +-#endif + /****************************************************************/ + /* encode_krb5_ad_signedpath */ + { +diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp +index 2d1686c56..daf3c7d3b 100644 +--- a/src/tests/dejagnu/config/default.exp ++++ b/src/tests/dejagnu/config/default.exp +@@ -32,26 +32,6 @@ set tgt_support_desmd5 0 + # request a des-cbc-md4 session key. Since only des-cbc-crc is in the + # KDC's permitted_enctypes list, the TGT will be unusable. + +-# KLUDGE for tracking down leaking ptys +-if 0 { +- rename spawn oldspawn +- rename wait oldwait +- proc spawn { args } { +- upvar 1 spawn_id spawn_id +- verbose "spawn: args=$args" +- set pid [eval oldspawn $args] +- verbose "spawn: pid=$pid spawn_id=$spawn_id" +- return $pid +- } +- proc wait { args } { +- upvar 1 spawn_id spawn_id +- verbose "wait: args=$args" +- set ret [eval oldwait $args] +- verbose "wait: $ret" +- return $ret +- } +-} +- + if { [string length $VALGRIND] } { + rename spawn valgrind_aux_spawn + proc spawn { args } { +diff --git a/src/tests/shlib/t_loader.c b/src/tests/shlib/t_loader.c +index 869be800a..29481a7be 100644 +--- a/src/tests/shlib/t_loader.c ++++ b/src/tests/shlib/t_loader.c +@@ -186,18 +186,6 @@ int main() + + (void) setvbuf(stdout, 0, _IONBF, 0); + +-#if 0 +- /* Simplest test: Load, then unload out of order. */ +- celib = do_open("com_err", "3.0", 0); +- k5lib = do_open("krb5", "3.2", 0); +- gsslib = do_open("gssapi_krb5", "2.2", 0); +- celib2 = do_open("com_err", "3.0", 0); +- do_close(celib); +- do_close(k5lib); +- do_close(celib2); +- do_close(gsslib); +-#endif +- + celib = do_open("com_err", "3.0", 0); + k5lib = do_open("krb5", "3.2", 0); + gsslib = do_open("gssapi_krb5", "2.2", 0); +diff --git a/src/tests/threads/t_rcache.c b/src/tests/threads/t_rcache.c +index d6187f061..9d9b1acd3 100644 +--- a/src/tests/threads/t_rcache.c ++++ b/src/tests/threads/t_rcache.c +@@ -106,7 +106,6 @@ static void try_one (struct tinfo *t) + static void *run_a_loop (void *x) + { + struct tinfo t = { 0 }; +-/* int chr = "ABCDEFGHIJKLMNOPQRSTUVWXYZ_"[(*(int*)x) % 27]; */ + + t.now = time(0); + t.idx = *(int *)x; +@@ -117,12 +116,7 @@ static void *run_a_loop (void *x) + t.now = time(0); + try_one(&t); + t.total++; +-#if 0 +- printf("%c", chr); +- fflush(stdout); +-#endif + } +-/* printf("thread %u total %u\n", (unsigned) ((int *)x-ip), t.total);*/ + *(int*)x = t.total; + return 0; + } +diff --git a/src/util/profile/prof_file.c b/src/util/profile/prof_file.c +index 0f5462aea..64b32dbf1 100644 +--- a/src/util/profile/prof_file.c ++++ b/src/util/profile/prof_file.c +@@ -79,39 +79,6 @@ void profile_library_finalizer(void) + + static void profile_free_file_data(prf_data_t); + +-#if 0 +- +-#define scan_shared_trees_locked() \ +- { \ +- prf_data_t d; \ +- k5_mutex_assert_locked(&g_shared_trees_mutex); \ +- for (d = g_shared_trees; d; d = d->next) { \ +- assert(d->magic == PROF_MAGIC_FILE_DATA); \ +- assert((d->flags & PROFILE_FILE_SHARED) != 0); \ +- assert(d->filespec[0] != 0); \ +- assert(d->fslen <= 1000); /* XXX */ \ +- assert(d->filespec[d->fslen] == 0); \ +- assert(d->fslen = strlen(d->filespec)); \ +- assert(d->root != NULL); \ +- } \ +- } +- +-#define scan_shared_trees_unlocked() \ +- { \ +- int r; \ +- r = k5_mutex_lock(&g_shared_trees_mutex); \ +- assert (r == 0); \ +- scan_shared_trees_locked(); \ +- k5_mutex_unlock(&g_shared_trees_mutex); \ +- } +- +-#else +- +-#define scan_shared_trees_locked() { ; } +-#define scan_shared_trees_unlocked() { ; } +- +-#endif +- + static int rw_access(const_profile_filespec_t filespec) + { + #ifdef HAVE_ACCESS +@@ -209,8 +176,6 @@ errcode_t profile_open_file(const_profile_filespec_t filespec, + if (retval) + return retval; + +- scan_shared_trees_unlocked(); +- + prf = malloc(sizeof(struct _prf_file_t)); + if (!prf) + return ENOMEM; +@@ -244,7 +209,6 @@ errcode_t profile_open_file(const_profile_filespec_t filespec, + } + + k5_mutex_lock(&g_shared_trees_mutex); +- scan_shared_trees_locked(); + for (data = g_shared_trees; data; data = data->next) { + if (!strcmp(data->filespec, expanded_filename) + /* Check that current uid has read access. */ +@@ -264,7 +228,6 @@ errcode_t profile_open_file(const_profile_filespec_t filespec, + } + prf->data = data; + *ret_prof = prf; +- scan_shared_trees_unlocked(); + return 0; + } + k5_mutex_unlock(&g_shared_trees_mutex); +@@ -291,11 +254,9 @@ errcode_t profile_open_file(const_profile_filespec_t filespec, + } + + k5_mutex_lock(&g_shared_trees_mutex); +- scan_shared_trees_locked(); + data->flags |= PROFILE_FILE_SHARED; + data->next = g_shared_trees; + g_shared_trees = data; +- scan_shared_trees_locked(); + k5_mutex_unlock(&g_shared_trees_mutex); + + *ret_prof = prf; +@@ -537,11 +498,9 @@ void profile_dereference_data(prf_data_t data) + } + void profile_dereference_data_locked(prf_data_t data) + { +- scan_shared_trees_locked(); + data->refcount--; + if (data->refcount == 0) + profile_free_file_data(data); +- scan_shared_trees_locked(); + } + + void profile_lock_global() +@@ -562,7 +521,6 @@ void profile_free_file(prf_file_t prf) + /* Call with mutex locked! */ + static void profile_free_file_data(prf_data_t data) + { +- scan_shared_trees_locked(); + if (data->flags & PROFILE_FILE_SHARED) { + /* Remove from linked list. */ + if (g_shared_trees == data) +@@ -586,7 +544,6 @@ static void profile_free_file_data(prf_data_t data) + data->magic = 0; + k5_mutex_destroy(&data->lock); + free(data); +- scan_shared_trees_locked(); + } + + errcode_t profile_close_file(prf_file_t prf) +diff --git a/src/util/support/fake-addrinfo.c b/src/util/support/fake-addrinfo.c +index 3ee162e0d..0fb35cf15 100644 +--- a/src/util/support/fake-addrinfo.c ++++ b/src/util/support/fake-addrinfo.c +@@ -888,16 +888,10 @@ fake_getaddrinfo (const char *name, const char *serv, + If it's not set, don't accept such names. */ + if (flags & AI_NUMERICHOST) { + struct in_addr addr4; +-#if 0 +- ret = inet_aton (name, &addr4); +- if (ret) +- return EAI_NONAME; +-#else + addr4.s_addr = inet_addr (name); + if (addr4.s_addr == 0xffffffff || addr4.s_addr == -1) + /* 255.255.255.255 or parse error, both bad */ + return EAI_NONAME; +-#endif + ret = fai_add_entry (&res, &addr4, port, &template); + } else { + ret = fai_add_hosts_by_name (name, &template, port, flags, +diff --git a/src/util/support/utf8.c b/src/util/support/utf8.c +index 34e2b6adb..ea8818116 100644 +--- a/src/util/support/utf8.c ++++ b/src/util/support/utf8.c +@@ -404,28 +404,6 @@ int krb5int_utf8_isalnum(const char * p) + + return KRB5_ALNUM(c); + } +- +-#if 0 +-int krb5int_utf8_islower(const char * p) +-{ +- unsigned c = * (const unsigned char *) p; +- +- if (!KRB5_ASCII(c)) +- return 0; +- +- return KRB5_LOWER(c); +-} +- +-int krb5int_utf8_isupper(const char * p) +-{ +- unsigned c = * (const unsigned char *) p; +- +- if (!KRB5_ASCII(c)) +- return 0; +- +- return KRB5_UPPER(c); +-} +-#endif + #endif + + +diff --git a/src/windows/include/loadfuncs-krb5.h b/src/windows/include/loadfuncs-krb5.h +index a90678878..39a3504f6 100644 +--- a/src/windows/include/loadfuncs-krb5.h ++++ b/src/windows/include/loadfuncs-krb5.h +@@ -106,29 +106,6 @@ TYPEDEF_FUNC( + krb5_free_ap_rep, + (krb5_context, krb5_ap_rep * ) + ); +- +-/* Removed around the time of krb5_rc_* change... */ +-#if 0 +-TYPEDEF_FUNC( +- void, +- KRB5_CALLCONV, +- krb5_free_safe, +- (krb5_context, krb5_safe * ) +- ); +-TYPEDEF_FUNC( +- void, +- KRB5_CALLCONV, +- krb5_free_priv, +- (krb5_context, krb5_priv * ) +- ); +-TYPEDEF_FUNC( +- void, +- KRB5_CALLCONV, +- krb5_free_priv_enc_part, +- (krb5_context, krb5_priv_enc_part * ) +- ); +-#endif +- + TYPEDEF_FUNC( + void, + KRB5_CALLCONV, +diff --git a/src/windows/kfwlogon/kfwlogon.c b/src/windows/kfwlogon/kfwlogon.c +index d851c4685..c388fffcd 100644 +--- a/src/windows/kfwlogon/kfwlogon.c ++++ b/src/windows/kfwlogon/kfwlogon.c +@@ -434,9 +434,6 @@ static BOOL + GetSecurityLogonSessionData(HANDLE hToken, PSECURITY_LOGON_SESSION_DATA * ppSessionData) + { + NTSTATUS Status = 0; +-#if 0 +- HANDLE TokenHandle; +-#endif + TOKEN_STATISTICS Stats; + DWORD ReqLen; + BOOL Success; +@@ -445,16 +442,8 @@ GetSecurityLogonSessionData(HANDLE hToken, PSECURITY_LOGON_SESSION_DATA * ppSess + return FALSE; + *ppSessionData = NULL; + +-#if 0 +- Success = OpenProcessToken( HANDLE GetCurrentProcess(), TOKEN_QUERY, &TokenHandle ); +- if ( !Success ) +- return FALSE; +-#endif + + Success = GetTokenInformation( hToken, TokenStatistics, &Stats, sizeof(TOKEN_STATISTICS), &ReqLen ); +-#if 0 +- CloseHandle( TokenHandle ); +-#endif + if ( !Success ) + return FALSE; + +diff --git a/src/windows/leash/Leash.cpp b/src/windows/leash/Leash.cpp +index f4e749350..cafcda7ce 100644 +--- a/src/windows/leash/Leash.cpp ++++ b/src/windows/leash/Leash.cpp +@@ -46,8 +46,6 @@ + static char THIS_FILE[] = __FILE__; + #endif + +-extern "C" int VScheckVersion(HWND hWnd, HANDLE hThisInstance); +- + TicketInfoWrapper ticketinfo; + + HWND CLeashApp::m_hProgram = 0; +@@ -479,8 +477,6 @@ BOOL CLeashApp::InitInstance() + } + } + +- VScheckVersion(m_pMainWnd->m_hWnd, AfxGetInstanceHandle()); +- + // The one and only window has been initialized, so show and update it. + m_pMainWnd->SetWindowText("MIT Kerberos"); + m_pMainWnd->UpdateWindow(); +diff --git a/src/windows/leash/Makefile.in b/src/windows/leash/Makefile.in +index 1b124e90f..57f93a418 100644 +--- a/src/windows/leash/Makefile.in ++++ b/src/windows/leash/Makefile.in +@@ -61,9 +61,6 @@ OBJS= \ + $(OUTPRE)MainFrm.obj \ + $(OUTPRE)out2con.obj \ + $(OUTPRE)StdAfx.obj \ +- $(OUTPRE)AfsProperties.obj \ +- $(OUTPRE)VSroutines.obj \ +- $(OUTPRE)KrbMiscConfigOpt.obj \ + $(OUTPRE)KrbListTickets.obj + + RESFILE = $(OUTPRE)Leash.res +diff --git a/src/windows/leash/VSroutines.c b/src/windows/leash/VSroutines.c +deleted file mode 100644 +index 63f0b4ae1..000000000 +--- a/src/windows/leash/VSroutines.c ++++ /dev/null +@@ -1,64 +0,0 @@ +-#include +-#include +- +-#if 0 +-//#ifdef USE_VS +-#include +- +-#define ININAME "leash.ini" +- +-int VScheckVersion(HWND hWnd, HANDLE hThisInstance) +-{ +- VS_Request vrequest; +- VS_Status status; +- BOOL ok_to_continue; +- HCURSOR hcursor; +- char szFilename[255]; +- char szVerQ[90]; +- char *cp; +- LPSTR lpAppVersion; +- LPSTR lpAppName; +- LONG FAR *lpLangInfo; +- DWORD hVersionInfoID; +- DWORD size; +- GLOBALHANDLE hVersionInfo; +- LPSTR lpVersionInfo; +- int dumint; +- int retval; +- +- GetModuleFileName(hThisInstance, (LPSTR)szFilename, 255); +- size = GetFileVersionInfoSize((LPSTR) szFilename, &hVersionInfoID); +- hVersionInfo = GlobalAlloc(GHND, size); +- lpVersionInfo = GlobalLock(hVersionInfo); +- retval = GetFileVersionInfo(szFilename, hVersionInfoID, size, +- lpVersionInfo); +- retval = VerQueryValue(lpVersionInfo, "\\VarFileInfo\\Translation", +- (LPSTR FAR *)&lpLangInfo, &dumint); +- wsprintf(szVerQ, "\\StringFileInfo\\%04x%04x\\", +- LOWORD(*lpLangInfo), HIWORD(*lpLangInfo)); +- cp = szVerQ + lstrlen(szVerQ); +- lstrcpy(cp, "ProductName"); +- retval = VerQueryValue(lpVersionInfo, szVerQ, &lpAppName, &dumint); +- lstrcpy(cp, "ProductVersion"); +- +- retval = VerQueryValue(lpVersionInfo, szVerQ, &lpAppVersion, &dumint); +- hcursor = SetCursor(LoadCursor((HINSTANCE)NULL, IDC_WAIT)); +- vrequest = VSFormRequest(lpAppName, lpAppVersion, ININAME, NULL, hWnd, +- V_CHECK_AND_LOG); +- if ((ok_to_continue = (ReqStatus(vrequest) != V_E_CANCEL)) +- && v_complain((status = VSProcessRequest(vrequest)), ININAME)) +- WinVSReportRequest(vrequest, hWnd, "Version Server Status Report"); +- if (ok_to_continue && status == V_REQUIRED) +- ok_to_continue = FALSE; +- VSDestroyRequest(vrequest); +- SetCursor(hcursor); +- GlobalUnlock(hVersionInfo); +- GlobalFree(hVersionInfo); +- return(ok_to_continue); +-} +-#else +-int VScheckVersion(HWND hWnd, HANDLE hThisInstance) +-{ +- return(1); +-} +-#endif +diff --git a/src/windows/leashdll/lsh_pwd.c b/src/windows/leashdll/lsh_pwd.c +index ac85625a0..7cbe3d7e4 100644 +--- a/src/windows/leashdll/lsh_pwd.c ++++ b/src/windows/leashdll/lsh_pwd.c +@@ -1426,11 +1426,6 @@ AuthenticateProc( + CSetDlgItemText(hDialog, IDC_EDIT_PRINCIPAL, principal); + CSetDlgItemText(hDialog, IDC_EDIT_PASSWORD, ""); + +-#if 0 /* 20030619 - mjv wishes to return to the default character */ +- /* echo spaces */ +- CSendDlgItemMessage(hDialog, IDC_EDIT_PASSWORD, EM_SETPASSWORDCHAR, 32, 0); +-#endif +- + /* Set Lifetime Slider + * min value = 5 + * max value = 1440 +@@ -1817,12 +1812,6 @@ NewPasswordProc( + if (hEditCtrl) + pAutoComplete = Leash_pec_create(hEditCtrl); + +-#if 0 /* 20030619 - mjv wishes to return to the default character */ +- /* echo spaces */ +- CSendDlgItemMessage(hDialog, IDC_EDIT_PASSWORD, EM_SETPASSWORDCHAR, 32, 0); +- CSendDlgItemMessage(hDialog, IDC_EDIT_PASSWORD2, EM_SETPASSWORDCHAR, 32, 0); +- CSendDlgItemMessage(hDialog, IDC_EDIT_PASSWORD3, EM_SETPASSWORDCHAR, 32, 0); +-#endif + /* setup text of stuff. */ + + if (Position.x > 0 && Position.y > 0 && +diff --git a/src/windows/leashdll/lshfunc.c b/src/windows/leashdll/lshfunc.c +index 8dafb7bed..47337de5d 100644 +--- a/src/windows/leashdll/lshfunc.c ++++ b/src/windows/leashdll/lshfunc.c +@@ -279,19 +279,11 @@ Leash_changepwd_v5( + if ( !pkrb5_init_context ) + goto cleanup; + +- if (rc = pkrb5_init_context(&context)) { +-#if 0 +- com_err(argv[0], ret, "initializing kerberos library"); +-#endif ++ if (rc = pkrb5_init_context(&context)) + goto cleanup; +- } + +- if (rc = pkrb5_parse_name(context, principal, &princ)) { +-#if 0 +- com_err(argv[0], ret, "parsing client name"); +-#endif ++ if (rc = pkrb5_parse_name(context, principal, &princ)) + goto cleanup; +- } + + pkrb5_get_init_creds_opt_init(&opts); + pkrb5_get_init_creds_opt_set_tkt_life(&opts, 5*60); +@@ -305,29 +297,13 @@ Leash_changepwd_v5( + + + if (rc = pkrb5_get_init_creds_password(context, &creds, princ, password, +- 0, 0, 0, "kadmin/changepw", &opts)) { +- if (rc == KRB5KRB_AP_ERR_BAD_INTEGRITY) { +-#if 0 +- com_err(argv[0], 0, +- "Password incorrect while getting initial ticket"); +-#endif +- } +- else { +-#if 0 +- com_err(argv[0], ret, "getting initial ticket"); +-#endif +- } ++ 0, 0, 0, "kadmin/changepw", &opts)) + goto cleanup; +- } + + if (rc = pkrb5_change_password(context, &creds, newpassword, + &result_code, &result_code_string, +- &result_string)) { +-#if 0 +- com_err(argv[0], ret, "changing password"); +-#endif ++ &result_string)) + goto cleanup; +- } + + if (result_code) { + int len = result_code_string.length + +diff --git a/src/windows/leashdll/lshutil.cpp b/src/windows/leashdll/lshutil.cpp +index 37c0723f3..a90e7e92e 100644 +--- a/src/windows/leashdll/lshutil.cpp ++++ b/src/windows/leashdll/lshutil.cpp +@@ -531,17 +531,6 @@ protected: + IAutoCompleteDropDown* pacdd = NULL; + hRes = pac->QueryInterface(IID_IAutoCompleteDropDown, (LPVOID*)&pacdd); + pac->Release(); +- +- // @TODO: auto-suggest; other advanced options? +-#if 0 +- IAutoComplete2 *pac2; +- +- if (SUCCEEDED(pac->QueryInterface(IID_IAutoComplete2, +- (LPVOID*)&pac2))) { +- pac2->SetOptions(ACO_AUTOSUGGEST); +- pac2->Release(); +- } +-#endif + m_acdd = pacdd; + } + } +diff --git a/src/windows/lib/cacheapi.h b/src/windows/lib/cacheapi.h +index c485080c1..b30857810 100644 +--- a/src/windows/lib/cacheapi.h ++++ b/src/windows/lib/cacheapi.h +@@ -102,21 +102,6 @@ typedef struct opaque_dll_control_block_type* apiCB; + typedef struct opaque_ccache_pointer_type* ccache_p; + typedef struct opaque_credential_iterator_type* ccache_cit; + +-#if 0 +-enum _cc_data_type { +- type_ticket = 0, /* 0 for ticket, second_ticket */ +- /* Ted's draft spec says these are to be +- "as defined in the Kerberos V5 protocol" +- all I can find are typdefs, +- can't find an enumerated type or #define +- */ +- type_address, /* = <"as defined in the Kerberos V5 protocol"> */ +- type_authdata, /* = <"as defined in the Kerberos V5 protocol"> */ +- type_encryption, /* = <"as defined in the Kerberos V5 protocol"> */ +- cc_data_type_max /* for validation */ +-}; +-#endif +- + typedef struct _cc_data + { + cc_uint32 type; // should be one of _cc_data_type diff --git a/krb5.spec b/krb5.spec index 4fa6c6c..25804a9 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 14%{?dist} +Release: 15%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -98,6 +98,7 @@ Patch78: Add-k5test-mark-function.patch Patch79: Convert-Python-tests-to-Python-3.patch Patch80: Zap-copy-of-secret-in-RC4-string-to-key.patch Patch81: Fix-some-broken-tests-for-Python-3.patch +Patch82: Eliminate-preprocessor-disabled-dead-code.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -744,6 +745,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jul 19 2018 Robbie Harwood - 1.16.1-15 +- Eliminate preprocessor-disabled dead code + * Wed Jul 18 2018 Robbie Harwood - 1.16.1-14 - Fix some broken tests for Python 3 From e506fad693fe66555116a07d3fc54487acd78c74 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 19 Jul 2018 16:43:21 -0400 Subject: [PATCH 063/304] Make krb5kdc -p affect TCP ports --- Make-krb5kdc-p-affect-TCP-ports.patch | 67 +++++++++++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 72 insertions(+), 1 deletion(-) create mode 100644 Make-krb5kdc-p-affect-TCP-ports.patch diff --git a/Make-krb5kdc-p-affect-TCP-ports.patch b/Make-krb5kdc-p-affect-TCP-ports.patch new file mode 100644 index 0000000..ac5bc30 --- /dev/null +++ b/Make-krb5kdc-p-affect-TCP-ports.patch @@ -0,0 +1,67 @@ +From 5587c1de938324faa1871e08ccfc835415acb443 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 17 Jul 2018 11:29:19 -0400 +Subject: [PATCH] Make krb5kdc -p affect TCP ports + +Now that the KDC listens for TCP connections by default (ticket 6731), +the "-p" option should affect both UDP and TCP default listening +ports. + +ticket: 8715 (new) +(cherry picked from commit eb514587acc5c357bf0f554199bf0489b5515f8b) +--- + doc/admin/admin_commands/krb5kdc.rst | 12 ++++++------ + src/kdc/main.c | 12 ++++-------- + 2 files changed, 10 insertions(+), 14 deletions(-) + +diff --git a/doc/admin/admin_commands/krb5kdc.rst b/doc/admin/admin_commands/krb5kdc.rst +index 7ec4ee4d3..bda2c015c 100644 +--- a/doc/admin/admin_commands/krb5kdc.rst ++++ b/doc/admin/admin_commands/krb5kdc.rst +@@ -57,12 +57,12 @@ The **-P** *pid_file* option tells the KDC to write its PID into + the KDC is still running and to allow init scripts to stop the correct + process. + +-The **-p** *portnum* option specifies the default UDP port numbers +-which the KDC should listen on for Kerberos version 5 requests, as a +-comma-separated list. This value overrides the UDP port numbers +-specified in the :ref:`kdcdefaults` section of :ref:`kdc.conf(5)`, but +-may be overridden by realm-specific values. If no value is given from +-any source, the default port is 88. ++The **-p** *portnum* option specifies the default UDP and TCP port ++numbers which the KDC should listen on for Kerberos version 5 ++requests, as a comma-separated list. This value overrides the port ++numbers specified in the :ref:`kdcdefaults` section of ++:ref:`kdc.conf(5)`, but may be overridden by realm-specific values. ++If no value is given from any source, the default port is 88. + + The **-w** *numworkers* option tells the KDC to fork *numworkers* + processes to listen to the KDC ports and process requests in parallel. +diff --git a/src/kdc/main.c b/src/kdc/main.c +index ccac3a759..89dac23ae 100644 +--- a/src/kdc/main.c ++++ b/src/kdc/main.c +@@ -793,19 +793,15 @@ initialize_realms(krb5_context kcontext, int argc, char **argv, + pid_file = optarg; + break; + case 'p': +- if (def_udp_listen) +- free(def_udp_listen); ++ free(def_udp_listen); ++ free(def_tcp_listen); + def_udp_listen = strdup(optarg); +- if (!def_udp_listen) { ++ def_tcp_listen = strdup(optarg); ++ if (def_udp_listen == NULL || def_tcp_listen == NULL) { + fprintf(stderr, _(" KDC cannot initialize. Not enough " + "memory\n")); + exit(1); + } +-#if 0 /* not yet */ +- if (default_tcp_ports) +- free(default_tcp_ports); +- default_tcp_ports = strdup(optarg); +-#endif + break; + case 'T': + time_offset = atoi(optarg); diff --git a/krb5.spec b/krb5.spec index 25804a9..eb3cf66 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 15%{?dist} +Release: 16%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -99,6 +99,7 @@ Patch79: Convert-Python-tests-to-Python-3.patch Patch80: Zap-copy-of-secret-in-RC4-string-to-key.patch Patch81: Fix-some-broken-tests-for-Python-3.patch Patch82: Eliminate-preprocessor-disabled-dead-code.patch +Patch83: Make-krb5kdc-p-affect-TCP-ports.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -745,6 +746,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jul 19 2018 Robbie Harwood - 1.16.1-16 +- Make krb5kdc -p affect TCP ports + * Thu Jul 19 2018 Robbie Harwood - 1.16.1-15 - Eliminate preprocessor-disabled dead code From 29b7ff3bb1a446080250e30a890a2cc38be5a43a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 19 Jul 2018 16:43:33 -0400 Subject: [PATCH 064/304] Remove outdated note in krb5kdc man page --- ...ve-outdated-note-in-krb5kdc-man-page.patch | 37 +++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 42 insertions(+), 1 deletion(-) create mode 100644 Remove-outdated-note-in-krb5kdc-man-page.patch diff --git a/Remove-outdated-note-in-krb5kdc-man-page.patch b/Remove-outdated-note-in-krb5kdc-man-page.patch new file mode 100644 index 0000000..6845b89 --- /dev/null +++ b/Remove-outdated-note-in-krb5kdc-man-page.patch @@ -0,0 +1,37 @@ +From 65130d13c59c13b7e5e07cfe69421ce1a08c0b7f Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 17 Jul 2018 11:33:03 -0400 +Subject: [PATCH] Remove outdated note in krb5kdc man page + +Commit af5b77c887bfff24603715f8296c00d5eb839b0c (ticket 8348) removed +the interface-scanning workaround for platforms without pktinfo +support, so there is no longer an interaction between the krb5kdc -w +option and this workaround. + +ticket: 8716 (new) +tags: pullup +target_version: 1.16-next + +(cherry picked from commit 728b66ab867e31c4c338c6a6309d629d39a4ec3f) +--- + doc/admin/admin_commands/krb5kdc.rst | 7 ------- + 1 file changed, 7 deletions(-) + +diff --git a/doc/admin/admin_commands/krb5kdc.rst b/doc/admin/admin_commands/krb5kdc.rst +index bda2c015c..b605b563d 100644 +--- a/doc/admin/admin_commands/krb5kdc.rst ++++ b/doc/admin/admin_commands/krb5kdc.rst +@@ -72,13 +72,6 @@ will relay SIGHUP signals to the worker subprocesses, and will + terminate the worker subprocess if the it is itself terminated or if + any other worker process exits. + +-.. note:: +- +- On operating systems which do not have *pktinfo* support, +- using worker processes will prevent the KDC from listening +- for UDP packets on network interfaces created after the KDC +- starts. +- + The **-x** *db_args* option specifies database-specific arguments. + See :ref:`Database Options ` in :ref:`kadmin(1)` for + supported arguments. diff --git a/krb5.spec b/krb5.spec index eb3cf66..f55d227 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 16%{?dist} +Release: 17%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -100,6 +100,7 @@ Patch80: Zap-copy-of-secret-in-RC4-string-to-key.patch Patch81: Fix-some-broken-tests-for-Python-3.patch Patch82: Eliminate-preprocessor-disabled-dead-code.patch Patch83: Make-krb5kdc-p-affect-TCP-ports.patch +Patch84: Remove-outdated-note-in-krb5kdc-man-page.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -746,6 +747,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jul 19 2018 Robbie Harwood - 1.16.1-17 +- Remove outdated note in krb5kdc man page + * Thu Jul 19 2018 Robbie Harwood - 1.16.1-16 - Make krb5kdc -p affect TCP ports From d21edd514c178d07b6f3bd8e7701f81510427a33 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 26 Jul 2018 14:23:13 -0400 Subject: [PATCH 065/304] Fix k5test prompts for Python 3 --- ...ncoders-and-decoders-for-SPAKE-types.patch | 1 + ...INIT-KDC-support-for-freshness-token.patch | 1 + ...T-client-support-for-freshness-token.patch | 1 + Add-SPAKE-preauth-support.patch | 1 + ...oc-index-entries-for-SPAKE-constants.patch | 1 + ...isable-encrypted-timestamp-on-client.patch | 1 + Add-k5_buf_add_vfmt-to-k5buf-interface.patch | 1 + Add-k5_dir_filenames-to-libkrb5support.patch | 1 + Add-k5test-mark-function.patch | 1 + ...bkrb5support-hex-functions-and-tests.patch | 1 + Add-vector-support-to-k5_sha256.patch | 1 + ...ul-asking-for-AS-key-in-SPAKE-client.patch | 1 + Convert-Python-tests-to-Python-3.patch | 1 + ...nate-preprocessor-disabled-dead-code.patch | 1 + Exit-with-status-0-from-kadmind.patch | 1 + ...tly-look-for-python2-in-configure.in.patch | 1 + Fix-SPAKE-memory-leak.patch | 1 + ...-conversion-of-PKINIT-certid-strings.patch | 1 + Fix-k5test-prompts-for-Python-3.patch | 36 +++++++++++++++++++ Fix-read-overflow-in-KDC-sort_pa_data.patch | 1 + ...id_sam2-preauth-for-non-default-salt.patch | 1 + Fix-segfault-in-finish_dispatch.patch | 2 ++ Fix-some-broken-tests-for-Python-3.patch | 1 + Implement-k5_buf_init_dynamic_zap.patch | 1 + ...e-info-in-for-hardware-preauth-hints.patch | 1 + ...uth-name-in-trace-output-if-possible.patch | 1 + ...hen-non-root-ksu-authorization-fails.patch | 1 + Make-docs-build-python3-compatible.patch | 1 + Make-krb5kdc-p-affect-TCP-ports.patch | 1 + Move-zap-definition-to-k5-platform.h.patch | 1 + ...s-profile-includedir-in-sorted-order.patch | 1 + ...r-KDC-krb5_pa_data-utility-functions.patch | 1 + ...nodes-option-from-make-certs-scripts.patch | 1 + ...ve-outdated-note-in-krb5kdc-man-page.patch | 1 + Report-extended-errors-in-kinit-k-t-KDB.patch | 1 + ...ct-pre-authentication-fallback-cases.patch | 1 + Simplify-kdc_preauth.c-systems-table.patch | 1 + ...-instead-of-MD5-for-audit-ticket-IDs.patch | 1 + ...f_init_dynamic_zap-where-appropriate.patch | 1 + ...port-hex-functions-where-appropriate.patch | 1 + Zap-copy-of-secret-in-RC4-string-to-key.patch | 1 + Zap-data-when-freeing-krb5_spake_factor.patch | 1 + krb5-1.11-kpasswdtest.patch | 1 + krb5-1.11-run_user_0.patch | 2 ++ krb5-1.12-api.patch | 2 ++ krb5-1.12-ksu-path.patch | 2 ++ krb5-1.12-ktany.patch | 2 ++ krb5-1.12.1-pam.patch | 2 ++ krb5-1.13-dirsrv-accountlock.patch | 2 ++ krb5-1.15-beta1-buildconf.patch | 2 ++ krb5-1.15.1-selinux-label.patch | 2 ++ krb5-1.3.1-dns.patch | 2 ++ krb5-1.9-debuginfo.patch | 2 ++ krb5.spec | 6 +++- 54 files changed, 104 insertions(+), 1 deletion(-) create mode 100644 Fix-k5test-prompts-for-Python-3.patch diff --git a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch index 6e78dcc..7b61fce 100644 --- a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch +++ b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch @@ -13,6 +13,7 @@ compiled as part of "make test-vectors" and not as part of the regular build. (cherry picked from commit 78a09d95dff6915da4079bc611f4bb95f6a95f70) +Signed-off-by: Robbie Harwood --- src/include/k5-spake.h | 107 +++++++++++++++++++++++++++ src/lib/krb5/asn.1/asn1_k_encode.c | 52 ++++++++++++- diff --git a/Add-PKINIT-KDC-support-for-freshness-token.patch b/Add-PKINIT-KDC-support-for-freshness-token.patch index 70782fb..23af740 100644 --- a/Add-PKINIT-KDC-support-for-freshness-token.patch +++ b/Add-PKINIT-KDC-support-for-freshness-token.patch @@ -24,6 +24,7 @@ the RSA test. ticket: 8648 (cherry picked from commit 4a9050df0bc34bfb08ba24462d6e2514640f4b8e) +Signed-off-by: Robbie Harwood --- doc/admin/conf_files/kdc_conf.rst | 4 + doc/admin/pkinit.rst | 25 +++++ diff --git a/Add-PKINIT-client-support-for-freshness-token.patch b/Add-PKINIT-client-support-for-freshness-token.patch index 1a00819..3e34b68 100644 --- a/Add-PKINIT-client-support-for-freshness-token.patch +++ b/Add-PKINIT-client-support-for-freshness-token.patch @@ -10,6 +10,7 @@ freshnessToken field of pkAuthenticator ticket: 8648 (cherry picked from commit 085785362e01467cb25c79a90dcebfba9ea019d8) +Signed-off-by: Robbie Harwood --- doc/user/user_commands/kinit.rst | 3 +++ src/include/k5-int-pkinit.h | 1 + diff --git a/Add-SPAKE-preauth-support.patch b/Add-SPAKE-preauth-support.patch index ab04539..e9f4bc3 100644 --- a/Add-SPAKE-preauth-support.patch +++ b/Add-SPAKE-preauth-support.patch @@ -47,6 +47,7 @@ registry contents; implemented P-384 and P-521] ticket: 8647 (new) (cherry picked from commit 7447259401569c92b1fb2e31cb02edbbffd67d35) +Signed-off-by: Robbie Harwood --- NOTICE | 51 + doc/admin/conf_files/kdc_conf.rst | 22 +- diff --git a/Add-doc-index-entries-for-SPAKE-constants.patch b/Add-doc-index-entries-for-SPAKE-constants.patch index 7ac2afe..c60e9ba 100644 --- a/Add-doc-index-entries-for-SPAKE-constants.patch +++ b/Add-doc-index-entries-for-SPAKE-constants.patch @@ -5,6 +5,7 @@ Subject: [PATCH] Add doc index entries for SPAKE constants ticket: 8647 (cherry picked from commit c010c9031753f356bb380e8a1324cc34721f8221) +Signed-off-by: Robbie Harwood --- doc/appdev/refs/macros/index.rst | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Add-flag-to-disable-encrypted-timestamp-on-client.patch b/Add-flag-to-disable-encrypted-timestamp-on-client.patch index adc4f41..2c8768c 100644 --- a/Add-flag-to-disable-encrypted-timestamp-on-client.patch +++ b/Add-flag-to-disable-encrypted-timestamp-on-client.patch @@ -5,6 +5,7 @@ Subject: [PATCH] Add flag to disable encrypted timestamp on client ticket: 8655 (cherry picked from commit 4ad376134b8d456392edbac7a7d351e6c7a7f0e7) +Signed-off-by: Robbie Harwood --- doc/admin/conf_files/krb5_conf.rst | 10 ++++++++++ doc/admin/spake.rst | 8 ++++++++ diff --git a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch index 1a333a7..31c81c1 100644 --- a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch +++ b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch @@ -4,6 +4,7 @@ Date: Thu, 4 Jan 2018 14:35:12 -0500 Subject: [PATCH] Add k5_buf_add_vfmt to k5buf interface (cherry picked from commit f05766469efc2a055085c0bcf9d40c4cdf47fe36) +Signed-off-by: Robbie Harwood --- src/include/k5-buf.h | 8 ++++++ src/util/support/k5buf.c | 26 +++++++++++-------- diff --git a/Add-k5_dir_filenames-to-libkrb5support.patch b/Add-k5_dir_filenames-to-libkrb5support.patch index d420f15..953cab1 100644 --- a/Add-k5_dir_filenames-to-libkrb5support.patch +++ b/Add-k5_dir_filenames-to-libkrb5support.patch @@ -7,6 +7,7 @@ Add a support function to get a list of filenames from a directory in sorted order. (cherry picked from commit 27534121eb39089ff4335d8b465027e9ba783682) +Signed-off-by: Robbie Harwood --- src/include/k5-platform.h | 7 + src/util/support/Makefile.in | 3 + diff --git a/Add-k5test-mark-function.patch b/Add-k5test-mark-function.patch index 0b2b9fa..21f5a5f 100644 --- a/Add-k5test-mark-function.patch +++ b/Add-k5test-mark-function.patch @@ -8,6 +8,7 @@ by allowing the script to output marks, and displaying the most recent mark with command failures. (cherry picked from commit 4e813204ac3dace93297f47d64dfc0aaecc370f8) +Signed-off-by: Robbie Harwood --- src/util/k5test.py | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/Add-libkrb5support-hex-functions-and-tests.patch b/Add-libkrb5support-hex-functions-and-tests.patch index d7caab2..6ddba45 100644 --- a/Add-libkrb5support-hex-functions-and-tests.patch +++ b/Add-libkrb5support-hex-functions-and-tests.patch @@ -5,6 +5,7 @@ Subject: [PATCH] Add libkrb5support hex functions and tests (cherry picked from commit 720dea558da0062d3cea4385327161e62cf09a5e) [rharwood@redhat.com Remove .gitignore] +Signed-off-by: Robbie Harwood --- src/include/k5-hex.h | 53 ++++++ src/util/support/Makefile.in | 15 +- diff --git a/Add-vector-support-to-k5_sha256.patch b/Add-vector-support-to-k5_sha256.patch index f9a3233..a77f6a2 100644 --- a/Add-vector-support-to-k5_sha256.patch +++ b/Add-vector-support-to-k5_sha256.patch @@ -8,6 +8,7 @@ to k5_sha256(), for efficient computation of SHA-256 hashes over concatenations of data values. (cherry picked from commit 4f3373e8c55b3e9bdfb5b065e07214c5816c85fa) +Signed-off-by: Robbie Harwood --- src/include/k5-int.h | 4 ++-- src/lib/crypto/builtin/sha2/sha256.c | 6 ++++-- diff --git a/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch b/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch index 692f4ad..668b640 100644 --- a/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch +++ b/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch @@ -19,6 +19,7 @@ spake_prep_questions() without a prototype. ticket: 8659 (cherry picked from commit f240f1b0d324312be8aa59ead7cfbe0c329ed064) +Signed-off-by: Robbie Harwood --- src/plugins/preauth/spake/spake_client.c | 111 ++++++++++++++--------- 1 file changed, 66 insertions(+), 45 deletions(-) diff --git a/Convert-Python-tests-to-Python-3.patch b/Convert-Python-tests-to-Python-3.patch index 5f5dc23..ebf0f4c 100644 --- a/Convert-Python-tests-to-Python-3.patch +++ b/Convert-Python-tests-to-Python-3.patch @@ -9,6 +9,7 @@ test code to conform to Python 3. ticket: 8710 (new) (cherry picked from commit e23d24beacb73581bbf4351250f3955e6fd44361) [rharwood@redhat.com: Context skew due to not having LMDB in tests] +Signed-off-by: Robbie Harwood --- src/Makefile.in | 1 + src/configure.in | 6 ++-- diff --git a/Eliminate-preprocessor-disabled-dead-code.patch b/Eliminate-preprocessor-disabled-dead-code.patch index 9c55c67..83cd935 100644 --- a/Eliminate-preprocessor-disabled-dead-code.patch +++ b/Eliminate-preprocessor-disabled-dead-code.patch @@ -10,6 +10,7 @@ these dead hunks along with the complexity to support them. (cherry picked from commit 2bc951d3c88b460a16249115cbd51d69c3c57e22) [rharwood@redhat.com: context skew] +Signed-off-by: Robbie Harwood --- src/ccapi/common/win/OldCC/ccutils.c | 6 -- src/ccapi/common/win/OldCC/ccutils.h | 3 - diff --git a/Exit-with-status-0-from-kadmind.patch b/Exit-with-status-0-from-kadmind.patch index 5fbdff8..afc8b69 100644 --- a/Exit-with-status-0-from-kadmind.patch +++ b/Exit-with-status-0-from-kadmind.patch @@ -14,6 +14,7 @@ weird return code has been present since the addition of the kadmin code, which used a similar event model for signals. (cherry picked from commit f970ad412aca36f8a7d3addb1cd4026ed22e5592) +Signed-off-by: Robbie Harwood --- src/kadmin/server/ovsec_kadmd.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Explicitly-look-for-python2-in-configure.in.patch b/Explicitly-look-for-python2-in-configure.in.patch index cb6620f..19c8d1f 100644 --- a/Explicitly-look-for-python2-in-configure.in.patch +++ b/Explicitly-look-for-python2-in-configure.in.patch @@ -15,6 +15,7 @@ doesn't need a #!/usr/bin/python header. ticket: 8709 (new) (cherry picked from commit 2bd410ecdb366083fe9b4e5f6ac4b741b624230b) +Signed-off-by: Robbie Harwood --- src/appl/gss-sample/t_gss_sample.py | 2 -- src/appl/user_user/t_user2user.py | 1 - diff --git a/Fix-SPAKE-memory-leak.patch b/Fix-SPAKE-memory-leak.patch index e1cacca..de172f6 100644 --- a/Fix-SPAKE-memory-leak.patch +++ b/Fix-SPAKE-memory-leak.patch @@ -10,6 +10,7 @@ data object to avoid a harmless uninitialized memory copy. ticket: 8647 (cherry picked from commit 70b88b8018658e052d6eabf06f8fdad17fbe993c) +Signed-off-by: Robbie Harwood --- src/plugins/preauth/spake/openssl.c | 1 + src/plugins/preauth/spake/spake_kdc.c | 1 + diff --git a/Fix-hex-conversion-of-PKINIT-certid-strings.patch b/Fix-hex-conversion-of-PKINIT-certid-strings.patch index 57d561b..0cf098a 100644 --- a/Fix-hex-conversion-of-PKINIT-certid-strings.patch +++ b/Fix-hex-conversion-of-PKINIT-certid-strings.patch @@ -12,6 +12,7 @@ commit message] ticket: 8636 (cherry picked from commit 63e8b8142fd7b3931a7bf2d6448978ca536bafc0) +Signed-off-by: Robbie Harwood --- .../preauth/pkinit/pkinit_crypto_openssl.c | 55 +++++++++++++++---- 1 file changed, 44 insertions(+), 11 deletions(-) diff --git a/Fix-k5test-prompts-for-Python-3.patch b/Fix-k5test-prompts-for-Python-3.patch new file mode 100644 index 0000000..fe16746 --- /dev/null +++ b/Fix-k5test-prompts-for-Python-3.patch @@ -0,0 +1,36 @@ +From 43cf653d21d931b792b36c7e6e4cfab3a6236bef Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 25 Jul 2018 11:50:02 -0400 +Subject: [PATCH] Fix k5test prompts for Python 3 + +With Python 3, sys.stdout.write() of a partial line followed by +sys.stdin.readline() does not display the partial line. Add explicit +flushes to make prompts visible in k5test.py. + +ticket: 8710 +(cherry picked from commit 297535b72177dcced036b78107e9d0e37781c7a3) +Signed-off-by: Robbie Harwood +--- + src/util/k5test.py | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/src/util/k5test.py b/src/util/k5test.py +index 81fac3063..e4f99b211 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -457,6 +457,7 @@ def _onexit(): + if _debug or _stop_before or _stop_after or _shell_before or _shell_after: + # Wait before killing daemons in case one is being debugged. + sys.stdout.write('*** Press return to kill daemons and exit script: ') ++ sys.stdout.flush() + sys.stdin.readline() + for proc in _daemons: + os.kill(proc.pid, signal.SIGTERM) +@@ -658,6 +659,7 @@ def _valgrind(args): + def _stop_or_shell(stop, shell, env, ind): + if (_match_cmdnum(stop, ind)): + sys.stdout.write('*** [%d] Waiting for return: ' % ind) ++ sys.stdout.flush() + sys.stdin.readline() + if (_match_cmdnum(shell, ind)): + output('*** [%d] Spawning shell\n' % ind, True) diff --git a/Fix-read-overflow-in-KDC-sort_pa_data.patch b/Fix-read-overflow-in-KDC-sort_pa_data.patch index 4f46827..d8737c2 100644 --- a/Fix-read-overflow-in-KDC-sort_pa_data.patch +++ b/Fix-read-overflow-in-KDC-sort_pa_data.patch @@ -15,6 +15,7 @@ instead get the count from the prior loop by stopping once we move all of the key-replacing modules to the front. (cherry picked from commit b38e318cea18fd65647189eed64aef83bf1cb772) +Signed-off-by: Robbie Harwood --- src/kdc/kdc_preauth.c | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/Fix-securid_sam2-preauth-for-non-default-salt.patch b/Fix-securid_sam2-preauth-for-non-default-salt.patch index 610bf4e..5f0a1b4 100644 --- a/Fix-securid_sam2-preauth-for-non-default-salt.patch +++ b/Fix-securid_sam2-preauth-for-non-default-salt.patch @@ -8,6 +8,7 @@ just the default salt type. ticket: 8629 (cherry picked from commit a2339099ad13c84de0843fd04d0ba612fc194a1e) +Signed-off-by: Robbie Harwood --- src/plugins/preauth/securid_sam2/grail.c | 3 +-- src/plugins/preauth/securid_sam2/securid2.c | 3 +-- diff --git a/Fix-segfault-in-finish_dispatch.patch b/Fix-segfault-in-finish_dispatch.patch index ff28848..0225ab3 100644 --- a/Fix-segfault-in-finish_dispatch.patch +++ b/Fix-segfault-in-finish_dispatch.patch @@ -12,6 +12,8 @@ dereference state->active_realm. tags: pullup target_version: 1.16-next target_version: 1.15-next + +Signed-off-by: Robbie Harwood --- src/kdc/dispatch.c | 79 ++++++++++++++++++++++++---------------------- 1 file changed, 42 insertions(+), 37 deletions(-) diff --git a/Fix-some-broken-tests-for-Python-3.patch b/Fix-some-broken-tests-for-Python-3.patch index 42825b0..4f17284 100644 --- a/Fix-some-broken-tests-for-Python-3.patch +++ b/Fix-some-broken-tests-for-Python-3.patch @@ -15,6 +15,7 @@ currently not exercised by Travis. ticket: 8710 (cherry picked from commit d1fb3551c0dff5c3e6555b31fcbf04ff04d577fe) [rharwood@redhat.com: .travis.yml] +Signed-off-by: Robbie Harwood --- src/lib/krad/t_daemon.py | 2 +- src/tests/jsonwalker.py | 16 +++++----------- diff --git a/Implement-k5_buf_init_dynamic_zap.patch b/Implement-k5_buf_init_dynamic_zap.patch index 28fd16b..ceadd64 100644 --- a/Implement-k5_buf_init_dynamic_zap.patch +++ b/Implement-k5_buf_init_dynamic_zap.patch @@ -7,6 +7,7 @@ Add a variant of dynamic k5buf objects which zeroes memory when reallocating or freeing the buffer. (cherry picked from commit 8ee8246c14702dc03b02e31b9fb5b7c2bb674bfb) +Signed-off-by: Robbie Harwood --- src/include/k5-buf.h | 6 ++- src/util/support/k5buf.c | 41 +++++++++++++++---- diff --git a/Include-etype-info-in-for-hardware-preauth-hints.patch b/Include-etype-info-in-for-hardware-preauth-hints.patch index 82aba62..788a88a 100644 --- a/Include-etype-info-in-for-hardware-preauth-hints.patch +++ b/Include-etype-info-in-for-hardware-preauth-hints.patch @@ -10,6 +10,7 @@ password. ticket: 8629 (cherry picked from commit ba92da05accc524b8037453b63ced1a6c65fd2a1) +Signed-off-by: Robbie Harwood --- src/kdc/kdc_preauth.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Include-preauth-name-in-trace-output-if-possible.patch b/Include-preauth-name-in-trace-output-if-possible.patch index fe88920..59dfc21 100644 --- a/Include-preauth-name-in-trace-output-if-possible.patch +++ b/Include-preauth-name-in-trace-output-if-possible.patch @@ -11,6 +11,7 @@ and use it when formatting {patype} or {patypes}. ticket: 8653 (new) (cherry picked from commit 9c68fe39b018666eabe033b639c1f35d03ba51c7) +Signed-off-by: Robbie Harwood --- src/include/k5-trace.h | 17 +-- src/lib/krb5/os/t_trace.ref | 2 +- diff --git a/Log-when-non-root-ksu-authorization-fails.patch b/Log-when-non-root-ksu-authorization-fails.patch index 704b5a9..b4a6c2e 100644 --- a/Log-when-non-root-ksu-authorization-fails.patch +++ b/Log-when-non-root-ksu-authorization-fails.patch @@ -8,6 +8,7 @@ syslog at LOG_WARNING in keeping with other failure messages. ticket: 8270 (cherry picked from commit 6cfa5c113e981f14f70ccafa20abfa5c46b665ba) +Signed-off-by: Robbie Harwood --- src/clients/ksu/main.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/Make-docs-build-python3-compatible.patch b/Make-docs-build-python3-compatible.patch index 58a3e86..f6e5fa1 100644 --- a/Make-docs-build-python3-compatible.patch +++ b/Make-docs-build-python3-compatible.patch @@ -8,6 +8,7 @@ paths information in docs. Call exec() directly instead. ticket: 8692 (new) (cherry picked from commit a7c6d98480f1e33454173f88381921472d72f80a) +Signed-off-by: Robbie Harwood --- doc/conf.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Make-krb5kdc-p-affect-TCP-ports.patch b/Make-krb5kdc-p-affect-TCP-ports.patch index ac5bc30..1b4ae04 100644 --- a/Make-krb5kdc-p-affect-TCP-ports.patch +++ b/Make-krb5kdc-p-affect-TCP-ports.patch @@ -9,6 +9,7 @@ ports. ticket: 8715 (new) (cherry picked from commit eb514587acc5c357bf0f554199bf0489b5515f8b) +Signed-off-by: Robbie Harwood --- doc/admin/admin_commands/krb5kdc.rst | 12 ++++++------ src/kdc/main.c | 12 ++++-------- diff --git a/Move-zap-definition-to-k5-platform.h.patch b/Move-zap-definition-to-k5-platform.h.patch index f181701..4e93056 100644 --- a/Move-zap-definition-to-k5-platform.h.patch +++ b/Move-zap-definition-to-k5-platform.h.patch @@ -7,6 +7,7 @@ Make it possible to use zap() in parts of the code which should not include k5-int.h by moving its definition to k5-platform.h. (cherry picked from commit df6bef6f9ea6a5f6f3956a2988cd658c78aae817) +Signed-off-by: Robbie Harwood --- src/include/k5-int.h | 45 ------------------------------------- src/include/k5-platform.h | 47 ++++++++++++++++++++++++++++++++++++++- diff --git a/Process-profile-includedir-in-sorted-order.patch b/Process-profile-includedir-in-sorted-order.patch index 92efffc..044c046 100644 --- a/Process-profile-includedir-in-sorted-order.patch +++ b/Process-profile-includedir-in-sorted-order.patch @@ -9,6 +9,7 @@ within the C locale). ticket: 8686 (cherry picked from commit f574eda48740ad192f51e9a382a205e2ea0e60ad) +Signed-off-by: Robbie Harwood --- doc/admin/conf_files/krb5_conf.rst | 4 ++- src/util/profile/prof_parse.c | 56 +++++------------------------- diff --git a/Refactor-KDC-krb5_pa_data-utility-functions.patch b/Refactor-KDC-krb5_pa_data-utility-functions.patch index 41e7cbe..b7acc49 100644 --- a/Refactor-KDC-krb5_pa_data-utility-functions.patch +++ b/Refactor-KDC-krb5_pa_data-utility-functions.patch @@ -16,6 +16,7 @@ callers accordingly, making small simplifications to memory handling where applicable. (cherry picked from commit 4af478c18b02e1d2444a328bb79e6976ef3d312b) +Signed-off-by: Robbie Harwood --- src/kdc/fast_util.c | 28 +------ src/kdc/kdc_preauth.c | 14 ++-- diff --git a/Remove-nodes-option-from-make-certs-scripts.patch b/Remove-nodes-option-from-make-certs-scripts.patch index 402f5fb..f45b1b0 100644 --- a/Remove-nodes-option-from-make-certs-scripts.patch +++ b/Remove-nodes-option-from-make-certs-scripts.patch @@ -12,6 +12,7 @@ pkcs12 subcommands, but genrsa creates unencrypted keys by default. [ghudson@mit.edu: edited commit message] (cherry picked from commit 928a36aae326d496c9a73f2cd41b4da45eef577c) +Signed-off-by: Robbie Harwood --- src/tests/dejagnu/pkinit-certs/make-certs.sh | 2 +- src/tests/dejagnu/proxy-certs/make-certs.sh | 2 +- diff --git a/Remove-outdated-note-in-krb5kdc-man-page.patch b/Remove-outdated-note-in-krb5kdc-man-page.patch index 6845b89..b2e8c13 100644 --- a/Remove-outdated-note-in-krb5kdc-man-page.patch +++ b/Remove-outdated-note-in-krb5kdc-man-page.patch @@ -13,6 +13,7 @@ tags: pullup target_version: 1.16-next (cherry picked from commit 728b66ab867e31c4c338c6a6309d629d39a4ec3f) +Signed-off-by: Robbie Harwood --- doc/admin/admin_commands/krb5kdc.rst | 7 ------- 1 file changed, 7 deletions(-) diff --git a/Report-extended-errors-in-kinit-k-t-KDB.patch b/Report-extended-errors-in-kinit-k-t-KDB.patch index 6859b55..bc6728d 100644 --- a/Report-extended-errors-in-kinit-k-t-KDB.patch +++ b/Report-extended-errors-in-kinit-k-t-KDB.patch @@ -9,6 +9,7 @@ extended error messages. ticket: 8652 (new) (cherry picked from commit d4d902d317a2acc46ee71094a33a9203b6135275) +Signed-off-by: Robbie Harwood --- src/clients/kinit/kinit.c | 1 + 1 file changed, 1 insertion(+) diff --git a/Restrict-pre-authentication-fallback-cases.patch b/Restrict-pre-authentication-fallback-cases.patch index f519557..d5c9d86 100644 --- a/Restrict-pre-authentication-fallback-cases.patch +++ b/Restrict-pre-authentication-fallback-cases.patch @@ -16,6 +16,7 @@ retried after a failure. ticket: 8654 (cherry picked from commit 7a24a088c16d326127dd2b29084d4ca085c70d10) +Signed-off-by: Robbie Harwood --- src/include/krb5/clpreauth_plugin.h | 14 ++++ src/lib/krb5/krb/get_in_tkt.c | 21 +++--- diff --git a/Simplify-kdc_preauth.c-systems-table.patch b/Simplify-kdc_preauth.c-systems-table.patch index 08853d4..c7ff103 100644 --- a/Simplify-kdc_preauth.c-systems-table.patch +++ b/Simplify-kdc_preauth.c-systems-table.patch @@ -15,6 +15,7 @@ padata types. The KRB5_PADATA_SERVER_REFERRAL entry has been disabled since it was first added. (cherry picked from commit fea1a488924faa3938ef723feaa1ff12d22a91ff) +Signed-off-by: Robbie Harwood --- src/kdc/kdc_preauth.c | 526 +++++++++++++++--------------------------- 1 file changed, 184 insertions(+), 342 deletions(-) diff --git a/Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch b/Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch index 26df25a..061a7fc 100644 --- a/Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch +++ b/Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch @@ -5,6 +5,7 @@ Subject: [PATCH] Use SHA-256 instead of MD5 for audit ticket IDs ticket: 8711 (new) (cherry picked from commit c1e1bfa26bd2f045e88e6013c500fca9428c98f3) +Signed-off-by: Robbie Harwood --- src/kdc/kdc_audit.c | 21 ++++++++++----------- 1 file changed, 10 insertions(+), 11 deletions(-) diff --git a/Use-k5_buf_init_dynamic_zap-where-appropriate.patch b/Use-k5_buf_init_dynamic_zap-where-appropriate.patch index 3d3bcd8..8d8e774 100644 --- a/Use-k5_buf_init_dynamic_zap-where-appropriate.patch +++ b/Use-k5_buf_init_dynamic_zap-where-appropriate.patch @@ -4,6 +4,7 @@ Date: Mon, 26 Mar 2018 11:24:49 -0400 Subject: [PATCH] Use k5_buf_init_dynamic_zap where appropriate (cherry picked from commit 9172599008f3a6790d4a9a67acff58049742dcb6) +Signed-off-by: Robbie Harwood --- src/lib/krb5/ccache/cc_file.c | 4 ++-- src/lib/krb5/ccache/cc_keyring.c | 2 +- diff --git a/Use-libkrb5support-hex-functions-where-appropriate.patch b/Use-libkrb5support-hex-functions-where-appropriate.patch index eab05bc..81c8164 100644 --- a/Use-libkrb5support-hex-functions-where-appropriate.patch +++ b/Use-libkrb5support-hex-functions-where-appropriate.patch @@ -4,6 +4,7 @@ Date: Mon, 19 Feb 2018 00:52:35 -0500 Subject: [PATCH] Use libkrb5support hex functions where appropriate (cherry picked from commit b0c700608be7455041a8afc0e4502e8783ee7f30) +Signed-off-by: Robbie Harwood --- src/kadmin/dbutil/deps | 16 ++--- src/kadmin/dbutil/tabdump.c | 19 +++--- diff --git a/Zap-copy-of-secret-in-RC4-string-to-key.patch b/Zap-copy-of-secret-in-RC4-string-to-key.patch index 7502c25..7f3bbf4 100644 --- a/Zap-copy-of-secret-in-RC4-string-to-key.patch +++ b/Zap-copy-of-secret-in-RC4-string-to-key.patch @@ -11,6 +11,7 @@ freed as the input string typically contains a password. [ghudson@mit.edu: rewrote commit message] ticket: 8713 (new) +Signed-off-by: Robbie Harwood --- src/lib/crypto/krb/s2k_rc4.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Zap-data-when-freeing-krb5_spake_factor.patch b/Zap-data-when-freeing-krb5_spake_factor.patch index 9ce2462..04652af 100644 --- a/Zap-data-when-freeing-krb5_spake_factor.patch +++ b/Zap-data-when-freeing-krb5_spake_factor.patch @@ -8,6 +8,7 @@ second-factor SPAKE is implemented, so should be zapped when freed. ticket: 8647 (cherry picked from commit 9cc94a3f1ce06a4430f684300a747ec079102403) +Signed-off-by: Robbie Harwood --- src/lib/krb5/krb/kfree.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch index ddd3ec2..144e3bf 100644 --- a/krb5-1.11-kpasswdtest.patch +++ b/krb5-1.11-kpasswdtest.patch @@ -3,6 +3,7 @@ From: Robbie Harwood Date: Tue, 23 Aug 2016 16:52:01 -0400 Subject: [PATCH] krb5-1.11-kpasswdtest.patch +Signed-off-by: Robbie Harwood --- src/kadmin/testing/proto/krb5.conf.proto | 1 + 1 file changed, 1 insertion(+) diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch index febb3b3..06f2e6e 100644 --- a/krb5-1.11-run_user_0.patch +++ b/krb5-1.11-run_user_0.patch @@ -6,6 +6,8 @@ Subject: [PATCH] krb5-1.11-run_user_0.patch A hack: if we're looking at creating a ccache directory directly below the /run/user/0 directory, and /run/user/0 doesn't exist, try to create it, too. + +Signed-off-by: Robbie Harwood --- src/lib/krb5/ccache/cc_dir.c | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/krb5-1.12-api.patch b/krb5-1.12-api.patch index 9eba2ff..dbf6183 100644 --- a/krb5-1.12-api.patch +++ b/krb5-1.12-api.patch @@ -6,6 +6,8 @@ Subject: [PATCH] krb5-1.12-api.patch Reference docs don't define what happens if you call krb5_realm_compare() with malformed krb5_principal structures. Define a behavior which keeps it from crashing if applications don't check ahead of time. + +Signed-off-by: Robbie Harwood --- src/lib/krb5/krb/princ_comp.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/krb5-1.12-ksu-path.patch b/krb5-1.12-ksu-path.patch index 19b9e73..b7b1c7e 100644 --- a/krb5-1.12-ksu-path.patch +++ b/krb5-1.12-ksu-path.patch @@ -4,6 +4,8 @@ Date: Tue, 23 Aug 2016 16:32:09 -0400 Subject: [PATCH] krb5-1.12-ksu-path.patch Set the default PATH to the one set by login. + +Signed-off-by: Robbie Harwood --- src/clients/ksu/Makefile.in | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/krb5-1.12-ktany.patch b/krb5-1.12-ktany.patch index de59827..59bb3d6 100644 --- a/krb5-1.12-ktany.patch +++ b/krb5-1.12-ktany.patch @@ -6,6 +6,8 @@ Subject: [PATCH] krb5-1.12-ktany.patch Adds an "ANY" keytab type which is a list of other keytab locations to search when searching for a specific entry. When iterated through, it only presents the contents of the first keytab. + +Signed-off-by: Robbie Harwood --- src/lib/krb5/keytab/Makefile.in | 3 + src/lib/krb5/keytab/kt_any.c | 292 ++++++++++++++++++++++++++++++++ diff --git a/krb5-1.12.1-pam.patch b/krb5-1.12.1-pam.patch index 97c1e8f..6060ce9 100644 --- a/krb5-1.12.1-pam.patch +++ b/krb5-1.12.1-pam.patch @@ -16,6 +16,8 @@ When enabled, ksu gains a dependency on libpam. Originally RT#5939, though it's changed since then to perform the account and session management before dropping privileges, and to apply on top of changes we're proposing for how it handles cache collections. + +Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 67 +++++++ src/clients/ksu/Makefile.in | 8 +- diff --git a/krb5-1.13-dirsrv-accountlock.patch b/krb5-1.13-dirsrv-accountlock.patch index ff5f73e..7e22280 100644 --- a/krb5-1.13-dirsrv-accountlock.patch +++ b/krb5-1.13-dirsrv-accountlock.patch @@ -5,6 +5,8 @@ Subject: [PATCH] krb5-1.13-dirsrv-accountlock.patch Treat 'nsAccountLock: true' the same as 'loginDisabled: true'. Updated from original version filed as RT#5891. + +Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 9 +++++++++ src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c | 17 +++++++++++++++++ diff --git a/krb5-1.15-beta1-buildconf.patch b/krb5-1.15-beta1-buildconf.patch index a949727..3e301c8 100644 --- a/krb5-1.15-beta1-buildconf.patch +++ b/krb5-1.15-beta1-buildconf.patch @@ -8,6 +8,8 @@ and install shared libraries with the execute bit set on them. Prune out the -L/usr/lib* and PIE flags where they might leak out and affect apps which just want to link with the libraries. FIXME: needs to check and not just assume that the compiler supports using these flags. + +Signed-off-by: Robbie Harwood --- src/build-tools/krb5-config.in | 7 +++++++ src/config/pre.in | 2 +- diff --git a/krb5-1.15.1-selinux-label.patch b/krb5-1.15.1-selinux-label.patch index 728c72e..b2f6cb0 100644 --- a/krb5-1.15.1-selinux-label.patch +++ b/krb5-1.15.1-selinux-label.patch @@ -35,6 +35,8 @@ stomp all over us. The selabel APIs for looking up the context should be thread-safe (per Red Hat #273081), so switching to using them instead of matchpathcon(), which we used earlier, is some improvement. + +Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 49 +++ src/build-tools/krb5-config.in | 3 +- diff --git a/krb5-1.3.1-dns.patch b/krb5-1.3.1-dns.patch index 1af7c12..9fb9df8 100644 --- a/krb5-1.3.1-dns.patch +++ b/krb5-1.3.1-dns.patch @@ -4,6 +4,8 @@ Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] krb5-1.3.1-dns.patch We want to be able to use --with-netlib and --enable-dns at the same time. + +Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 1 + 1 file changed, 1 insertion(+) diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index 5b0f5bc..4378ff7 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -6,6 +6,8 @@ Subject: [PATCH] krb5-1.9-debuginfo.patch We want to keep these y.tab.c files around because the debuginfo points to them. It would be more elegant at the end to use symbolic links, but that could mess up people working in the tree on other things. + +Signed-off-by: Robbie Harwood --- src/kadmin/cli/Makefile.in | 5 +++++ src/plugins/kdb/ldap/ldap_util/Makefile.in | 2 +- diff --git a/krb5.spec b/krb5.spec index f55d227..db9f9b0 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 17%{?dist} +Release: 18%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -101,6 +101,7 @@ Patch81: Fix-some-broken-tests-for-Python-3.patch Patch82: Eliminate-preprocessor-disabled-dead-code.patch Patch83: Make-krb5kdc-p-affect-TCP-ports.patch Patch84: Remove-outdated-note-in-krb5kdc-man-page.patch +Patch85: Fix-k5test-prompts-for-Python-3.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -747,6 +748,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jul 26 2018 Robbie Harwood - 1.16.1-18 +- Fix k5test prompts for Python 3 + * Thu Jul 19 2018 Robbie Harwood - 1.16.1-17 - Remove outdated note in krb5kdc man page From ef8eae7c7b8b1f6fa0844763ce672168d3a0950a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 1 Aug 2018 15:11:35 -0400 Subject: [PATCH 066/304] In FIPS mode, add plaintext fallback for RC4 usages and taint --- ...ncoders-and-decoders-for-SPAKE-types.patch | 1 - ...INIT-KDC-support-for-freshness-token.patch | 1 - ...T-client-support-for-freshness-token.patch | 1 - Add-SPAKE-preauth-support.patch | 1 - ...oc-index-entries-for-SPAKE-constants.patch | 1 - ...isable-encrypted-timestamp-on-client.patch | 1 - Add-k5_buf_add_vfmt-to-k5buf-interface.patch | 1 - Add-k5_dir_filenames-to-libkrb5support.patch | 1 - Add-k5test-mark-function.patch | 1 - ...bkrb5support-hex-functions-and-tests.patch | 1 - Add-vector-support-to-k5_sha256.patch | 1 - ...ul-asking-for-AS-key-in-SPAKE-client.patch | 1 - Convert-Python-tests-to-Python-3.patch | 1 - ...nate-preprocessor-disabled-dead-code.patch | 1 - Exit-with-status-0-from-kadmind.patch | 1 - ...tly-look-for-python2-in-configure.in.patch | 1 - Fix-SPAKE-memory-leak.patch | 1 - ...-conversion-of-PKINIT-certid-strings.patch | 1 - Fix-k5test-prompts-for-Python-3.patch | 1 - Fix-read-overflow-in-KDC-sort_pa_data.patch | 1 - ...id_sam2-preauth-for-non-default-salt.patch | 1 - Fix-segfault-in-finish_dispatch.patch | 2 - Fix-some-broken-tests-for-Python-3.patch | 1 - Implement-k5_buf_init_dynamic_zap.patch | 1 - ...-plaintext-fallback-for-RC4-usages-a.patch | 327 ++++++++++++++++++ ...e-info-in-for-hardware-preauth-hints.patch | 1 - ...uth-name-in-trace-output-if-possible.patch | 1 - ...hen-non-root-ksu-authorization-fails.patch | 1 - Make-docs-build-python3-compatible.patch | 1 - Make-krb5kdc-p-affect-TCP-ports.patch | 1 - Move-zap-definition-to-k5-platform.h.patch | 1 - ...s-profile-includedir-in-sorted-order.patch | 1 - ...r-KDC-krb5_pa_data-utility-functions.patch | 1 - ...nodes-option-from-make-certs-scripts.patch | 1 - ...ve-outdated-note-in-krb5kdc-man-page.patch | 1 - Report-extended-errors-in-kinit-k-t-KDB.patch | 1 - ...ct-pre-authentication-fallback-cases.patch | 1 - Simplify-kdc_preauth.c-systems-table.patch | 1 - ...-instead-of-MD5-for-audit-ticket-IDs.patch | 1 - ...f_init_dynamic_zap-where-appropriate.patch | 1 - ...port-hex-functions-where-appropriate.patch | 1 - Zap-copy-of-secret-in-RC4-string-to-key.patch | 1 - Zap-data-when-freeing-krb5_spake_factor.patch | 1 - krb5-1.11-kpasswdtest.patch | 1 - krb5-1.11-run_user_0.patch | 2 - krb5-1.12-api.patch | 2 - krb5-1.12-ksu-path.patch | 2 - krb5-1.12-ktany.patch | 2 - krb5-1.12.1-pam.patch | 2 - krb5-1.13-dirsrv-accountlock.patch | 2 - krb5-1.15-beta1-buildconf.patch | 2 - krb5-1.15.1-selinux-label.patch | 2 - krb5-1.3.1-dns.patch | 2 - krb5-1.9-debuginfo.patch | 2 - krb5.spec | 6 +- 55 files changed, 332 insertions(+), 65 deletions(-) create mode 100644 In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch diff --git a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch index 7b61fce..6e78dcc 100644 --- a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch +++ b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch @@ -13,7 +13,6 @@ compiled as part of "make test-vectors" and not as part of the regular build. (cherry picked from commit 78a09d95dff6915da4079bc611f4bb95f6a95f70) -Signed-off-by: Robbie Harwood --- src/include/k5-spake.h | 107 +++++++++++++++++++++++++++ src/lib/krb5/asn.1/asn1_k_encode.c | 52 ++++++++++++- diff --git a/Add-PKINIT-KDC-support-for-freshness-token.patch b/Add-PKINIT-KDC-support-for-freshness-token.patch index 23af740..70782fb 100644 --- a/Add-PKINIT-KDC-support-for-freshness-token.patch +++ b/Add-PKINIT-KDC-support-for-freshness-token.patch @@ -24,7 +24,6 @@ the RSA test. ticket: 8648 (cherry picked from commit 4a9050df0bc34bfb08ba24462d6e2514640f4b8e) -Signed-off-by: Robbie Harwood --- doc/admin/conf_files/kdc_conf.rst | 4 + doc/admin/pkinit.rst | 25 +++++ diff --git a/Add-PKINIT-client-support-for-freshness-token.patch b/Add-PKINIT-client-support-for-freshness-token.patch index 3e34b68..1a00819 100644 --- a/Add-PKINIT-client-support-for-freshness-token.patch +++ b/Add-PKINIT-client-support-for-freshness-token.patch @@ -10,7 +10,6 @@ freshnessToken field of pkAuthenticator ticket: 8648 (cherry picked from commit 085785362e01467cb25c79a90dcebfba9ea019d8) -Signed-off-by: Robbie Harwood --- doc/user/user_commands/kinit.rst | 3 +++ src/include/k5-int-pkinit.h | 1 + diff --git a/Add-SPAKE-preauth-support.patch b/Add-SPAKE-preauth-support.patch index e9f4bc3..ab04539 100644 --- a/Add-SPAKE-preauth-support.patch +++ b/Add-SPAKE-preauth-support.patch @@ -47,7 +47,6 @@ registry contents; implemented P-384 and P-521] ticket: 8647 (new) (cherry picked from commit 7447259401569c92b1fb2e31cb02edbbffd67d35) -Signed-off-by: Robbie Harwood --- NOTICE | 51 + doc/admin/conf_files/kdc_conf.rst | 22 +- diff --git a/Add-doc-index-entries-for-SPAKE-constants.patch b/Add-doc-index-entries-for-SPAKE-constants.patch index c60e9ba..7ac2afe 100644 --- a/Add-doc-index-entries-for-SPAKE-constants.patch +++ b/Add-doc-index-entries-for-SPAKE-constants.patch @@ -5,7 +5,6 @@ Subject: [PATCH] Add doc index entries for SPAKE constants ticket: 8647 (cherry picked from commit c010c9031753f356bb380e8a1324cc34721f8221) -Signed-off-by: Robbie Harwood --- doc/appdev/refs/macros/index.rst | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Add-flag-to-disable-encrypted-timestamp-on-client.patch b/Add-flag-to-disable-encrypted-timestamp-on-client.patch index 2c8768c..adc4f41 100644 --- a/Add-flag-to-disable-encrypted-timestamp-on-client.patch +++ b/Add-flag-to-disable-encrypted-timestamp-on-client.patch @@ -5,7 +5,6 @@ Subject: [PATCH] Add flag to disable encrypted timestamp on client ticket: 8655 (cherry picked from commit 4ad376134b8d456392edbac7a7d351e6c7a7f0e7) -Signed-off-by: Robbie Harwood --- doc/admin/conf_files/krb5_conf.rst | 10 ++++++++++ doc/admin/spake.rst | 8 ++++++++ diff --git a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch index 31c81c1..1a333a7 100644 --- a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch +++ b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch @@ -4,7 +4,6 @@ Date: Thu, 4 Jan 2018 14:35:12 -0500 Subject: [PATCH] Add k5_buf_add_vfmt to k5buf interface (cherry picked from commit f05766469efc2a055085c0bcf9d40c4cdf47fe36) -Signed-off-by: Robbie Harwood --- src/include/k5-buf.h | 8 ++++++ src/util/support/k5buf.c | 26 +++++++++++-------- diff --git a/Add-k5_dir_filenames-to-libkrb5support.patch b/Add-k5_dir_filenames-to-libkrb5support.patch index 953cab1..d420f15 100644 --- a/Add-k5_dir_filenames-to-libkrb5support.patch +++ b/Add-k5_dir_filenames-to-libkrb5support.patch @@ -7,7 +7,6 @@ Add a support function to get a list of filenames from a directory in sorted order. (cherry picked from commit 27534121eb39089ff4335d8b465027e9ba783682) -Signed-off-by: Robbie Harwood --- src/include/k5-platform.h | 7 + src/util/support/Makefile.in | 3 + diff --git a/Add-k5test-mark-function.patch b/Add-k5test-mark-function.patch index 21f5a5f..0b2b9fa 100644 --- a/Add-k5test-mark-function.patch +++ b/Add-k5test-mark-function.patch @@ -8,7 +8,6 @@ by allowing the script to output marks, and displaying the most recent mark with command failures. (cherry picked from commit 4e813204ac3dace93297f47d64dfc0aaecc370f8) -Signed-off-by: Robbie Harwood --- src/util/k5test.py | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/Add-libkrb5support-hex-functions-and-tests.patch b/Add-libkrb5support-hex-functions-and-tests.patch index 6ddba45..d7caab2 100644 --- a/Add-libkrb5support-hex-functions-and-tests.patch +++ b/Add-libkrb5support-hex-functions-and-tests.patch @@ -5,7 +5,6 @@ Subject: [PATCH] Add libkrb5support hex functions and tests (cherry picked from commit 720dea558da0062d3cea4385327161e62cf09a5e) [rharwood@redhat.com Remove .gitignore] -Signed-off-by: Robbie Harwood --- src/include/k5-hex.h | 53 ++++++ src/util/support/Makefile.in | 15 +- diff --git a/Add-vector-support-to-k5_sha256.patch b/Add-vector-support-to-k5_sha256.patch index a77f6a2..f9a3233 100644 --- a/Add-vector-support-to-k5_sha256.patch +++ b/Add-vector-support-to-k5_sha256.patch @@ -8,7 +8,6 @@ to k5_sha256(), for efficient computation of SHA-256 hashes over concatenations of data values. (cherry picked from commit 4f3373e8c55b3e9bdfb5b065e07214c5816c85fa) -Signed-off-by: Robbie Harwood --- src/include/k5-int.h | 4 ++-- src/lib/crypto/builtin/sha2/sha256.c | 6 ++++-- diff --git a/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch b/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch index 668b640..692f4ad 100644 --- a/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch +++ b/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch @@ -19,7 +19,6 @@ spake_prep_questions() without a prototype. ticket: 8659 (cherry picked from commit f240f1b0d324312be8aa59ead7cfbe0c329ed064) -Signed-off-by: Robbie Harwood --- src/plugins/preauth/spake/spake_client.c | 111 ++++++++++++++--------- 1 file changed, 66 insertions(+), 45 deletions(-) diff --git a/Convert-Python-tests-to-Python-3.patch b/Convert-Python-tests-to-Python-3.patch index ebf0f4c..5f5dc23 100644 --- a/Convert-Python-tests-to-Python-3.patch +++ b/Convert-Python-tests-to-Python-3.patch @@ -9,7 +9,6 @@ test code to conform to Python 3. ticket: 8710 (new) (cherry picked from commit e23d24beacb73581bbf4351250f3955e6fd44361) [rharwood@redhat.com: Context skew due to not having LMDB in tests] -Signed-off-by: Robbie Harwood --- src/Makefile.in | 1 + src/configure.in | 6 ++-- diff --git a/Eliminate-preprocessor-disabled-dead-code.patch b/Eliminate-preprocessor-disabled-dead-code.patch index 83cd935..9c55c67 100644 --- a/Eliminate-preprocessor-disabled-dead-code.patch +++ b/Eliminate-preprocessor-disabled-dead-code.patch @@ -10,7 +10,6 @@ these dead hunks along with the complexity to support them. (cherry picked from commit 2bc951d3c88b460a16249115cbd51d69c3c57e22) [rharwood@redhat.com: context skew] -Signed-off-by: Robbie Harwood --- src/ccapi/common/win/OldCC/ccutils.c | 6 -- src/ccapi/common/win/OldCC/ccutils.h | 3 - diff --git a/Exit-with-status-0-from-kadmind.patch b/Exit-with-status-0-from-kadmind.patch index afc8b69..5fbdff8 100644 --- a/Exit-with-status-0-from-kadmind.patch +++ b/Exit-with-status-0-from-kadmind.patch @@ -14,7 +14,6 @@ weird return code has been present since the addition of the kadmin code, which used a similar event model for signals. (cherry picked from commit f970ad412aca36f8a7d3addb1cd4026ed22e5592) -Signed-off-by: Robbie Harwood --- src/kadmin/server/ovsec_kadmd.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Explicitly-look-for-python2-in-configure.in.patch b/Explicitly-look-for-python2-in-configure.in.patch index 19c8d1f..cb6620f 100644 --- a/Explicitly-look-for-python2-in-configure.in.patch +++ b/Explicitly-look-for-python2-in-configure.in.patch @@ -15,7 +15,6 @@ doesn't need a #!/usr/bin/python header. ticket: 8709 (new) (cherry picked from commit 2bd410ecdb366083fe9b4e5f6ac4b741b624230b) -Signed-off-by: Robbie Harwood --- src/appl/gss-sample/t_gss_sample.py | 2 -- src/appl/user_user/t_user2user.py | 1 - diff --git a/Fix-SPAKE-memory-leak.patch b/Fix-SPAKE-memory-leak.patch index de172f6..e1cacca 100644 --- a/Fix-SPAKE-memory-leak.patch +++ b/Fix-SPAKE-memory-leak.patch @@ -10,7 +10,6 @@ data object to avoid a harmless uninitialized memory copy. ticket: 8647 (cherry picked from commit 70b88b8018658e052d6eabf06f8fdad17fbe993c) -Signed-off-by: Robbie Harwood --- src/plugins/preauth/spake/openssl.c | 1 + src/plugins/preauth/spake/spake_kdc.c | 1 + diff --git a/Fix-hex-conversion-of-PKINIT-certid-strings.patch b/Fix-hex-conversion-of-PKINIT-certid-strings.patch index 0cf098a..57d561b 100644 --- a/Fix-hex-conversion-of-PKINIT-certid-strings.patch +++ b/Fix-hex-conversion-of-PKINIT-certid-strings.patch @@ -12,7 +12,6 @@ commit message] ticket: 8636 (cherry picked from commit 63e8b8142fd7b3931a7bf2d6448978ca536bafc0) -Signed-off-by: Robbie Harwood --- .../preauth/pkinit/pkinit_crypto_openssl.c | 55 +++++++++++++++---- 1 file changed, 44 insertions(+), 11 deletions(-) diff --git a/Fix-k5test-prompts-for-Python-3.patch b/Fix-k5test-prompts-for-Python-3.patch index fe16746..4adb451 100644 --- a/Fix-k5test-prompts-for-Python-3.patch +++ b/Fix-k5test-prompts-for-Python-3.patch @@ -9,7 +9,6 @@ flushes to make prompts visible in k5test.py. ticket: 8710 (cherry picked from commit 297535b72177dcced036b78107e9d0e37781c7a3) -Signed-off-by: Robbie Harwood --- src/util/k5test.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Fix-read-overflow-in-KDC-sort_pa_data.patch b/Fix-read-overflow-in-KDC-sort_pa_data.patch index d8737c2..4f46827 100644 --- a/Fix-read-overflow-in-KDC-sort_pa_data.patch +++ b/Fix-read-overflow-in-KDC-sort_pa_data.patch @@ -15,7 +15,6 @@ instead get the count from the prior loop by stopping once we move all of the key-replacing modules to the front. (cherry picked from commit b38e318cea18fd65647189eed64aef83bf1cb772) -Signed-off-by: Robbie Harwood --- src/kdc/kdc_preauth.c | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/Fix-securid_sam2-preauth-for-non-default-salt.patch b/Fix-securid_sam2-preauth-for-non-default-salt.patch index 5f0a1b4..610bf4e 100644 --- a/Fix-securid_sam2-preauth-for-non-default-salt.patch +++ b/Fix-securid_sam2-preauth-for-non-default-salt.patch @@ -8,7 +8,6 @@ just the default salt type. ticket: 8629 (cherry picked from commit a2339099ad13c84de0843fd04d0ba612fc194a1e) -Signed-off-by: Robbie Harwood --- src/plugins/preauth/securid_sam2/grail.c | 3 +-- src/plugins/preauth/securid_sam2/securid2.c | 3 +-- diff --git a/Fix-segfault-in-finish_dispatch.patch b/Fix-segfault-in-finish_dispatch.patch index 0225ab3..ff28848 100644 --- a/Fix-segfault-in-finish_dispatch.patch +++ b/Fix-segfault-in-finish_dispatch.patch @@ -12,8 +12,6 @@ dereference state->active_realm. tags: pullup target_version: 1.16-next target_version: 1.15-next - -Signed-off-by: Robbie Harwood --- src/kdc/dispatch.c | 79 ++++++++++++++++++++++++---------------------- 1 file changed, 42 insertions(+), 37 deletions(-) diff --git a/Fix-some-broken-tests-for-Python-3.patch b/Fix-some-broken-tests-for-Python-3.patch index 4f17284..42825b0 100644 --- a/Fix-some-broken-tests-for-Python-3.patch +++ b/Fix-some-broken-tests-for-Python-3.patch @@ -15,7 +15,6 @@ currently not exercised by Travis. ticket: 8710 (cherry picked from commit d1fb3551c0dff5c3e6555b31fcbf04ff04d577fe) [rharwood@redhat.com: .travis.yml] -Signed-off-by: Robbie Harwood --- src/lib/krad/t_daemon.py | 2 +- src/tests/jsonwalker.py | 16 +++++----------- diff --git a/Implement-k5_buf_init_dynamic_zap.patch b/Implement-k5_buf_init_dynamic_zap.patch index ceadd64..28fd16b 100644 --- a/Implement-k5_buf_init_dynamic_zap.patch +++ b/Implement-k5_buf_init_dynamic_zap.patch @@ -7,7 +7,6 @@ Add a variant of dynamic k5buf objects which zeroes memory when reallocating or freeing the buffer. (cherry picked from commit 8ee8246c14702dc03b02e31b9fb5b7c2bb674bfb) -Signed-off-by: Robbie Harwood --- src/include/k5-buf.h | 6 ++- src/util/support/k5buf.c | 41 +++++++++++++++---- diff --git a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch b/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch new file mode 100644 index 0000000..73ac10d --- /dev/null +++ b/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch @@ -0,0 +1,327 @@ +From a9f547544ae43c2a71f21cab4fa61388c2f67553 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 31 Jul 2018 13:47:26 -0400 +Subject: [PATCH] In FIPS mode, add plaintext fallback for RC4 usages and taint + +--- + src/lib/krad/attr.c | 38 ++++++++++++++++++++++++++++---------- + src/lib/krad/attrset.c | 5 +++-- + src/lib/krad/internal.h | 13 +++++++++++-- + src/lib/krad/packet.c | 18 +++++++++--------- + src/lib/krad/remote.c | 10 ++++++++-- + src/lib/krad/t_attr.c | 3 ++- + src/lib/krad/t_attrset.c | 4 +++- + 7 files changed, 64 insertions(+), 27 deletions(-) + +diff --git a/src/lib/krad/attr.c b/src/lib/krad/attr.c +index 9c13d9d75..3a2d0243b 100644 +--- a/src/lib/krad/attr.c ++++ b/src/lib/krad/attr.c +@@ -38,7 +38,8 @@ + typedef krb5_error_code + (*attribute_transform_fn)(krb5_context ctx, const char *secret, + const unsigned char *auth, const krb5_data *in, +- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen); ++ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen, ++ krb5_boolean *is_fips); + + typedef struct { + const char *name; +@@ -51,12 +52,14 @@ typedef struct { + static krb5_error_code + user_password_encode(krb5_context ctx, const char *secret, + const unsigned char *auth, const krb5_data *in, +- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen); ++ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen, ++ krb5_boolean *is_fips); + + static krb5_error_code + user_password_decode(krb5_context ctx, const char *secret, + const unsigned char *auth, const krb5_data *in, +- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen); ++ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen, ++ krb5_boolean *ignored); + + static const attribute_record attributes[UCHAR_MAX] = { + {"User-Name", 1, MAX_ATTRSIZE, NULL, NULL}, +@@ -128,7 +131,8 @@ static const attribute_record attributes[UCHAR_MAX] = { + static krb5_error_code + user_password_encode(krb5_context ctx, const char *secret, + const unsigned char *auth, const krb5_data *in, +- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen) ++ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen, ++ krb5_boolean *is_fips) + { + const unsigned char *indx; + krb5_error_code retval; +@@ -156,7 +160,12 @@ user_password_encode(krb5_context ctx, const char *secret, + + retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &tmp, + &sum); +- if (retval != 0) { ++ if (retval == ENOMEM) { ++ /* I'm Linux, so we know this is a FIPS failure. Taint so we ++ * don't send it later. */ ++ *is_fips = TRUE; ++ sum.contents = calloc(1, BLOCKSIZE); ++ } else if (retval != 0) { + zap(tmp.data, tmp.length); + zap(outbuf, len); + krb5_free_data_contents(ctx, &tmp); +@@ -180,7 +189,8 @@ user_password_encode(krb5_context ctx, const char *secret, + static krb5_error_code + user_password_decode(krb5_context ctx, const char *secret, + const unsigned char *auth, const krb5_data *in, +- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen) ++ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen, ++ krb5_boolean *is_fips) + { + const unsigned char *indx; + krb5_error_code retval; +@@ -206,7 +216,12 @@ user_password_decode(krb5_context ctx, const char *secret, + + retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, + &tmp, &sum); +- if (retval != 0) { ++ if (retval == ENOMEM) { ++ /* I'm Linux, so we know this is a FIPS failure. Assume the ++ * other side is running locally and move on. */ ++ *is_fips = TRUE; ++ sum.contents = calloc(1, BLOCKSIZE); ++ } else if (retval != 0) { + zap(tmp.data, tmp.length); + zap(outbuf, in->length); + krb5_free_data_contents(ctx, &tmp); +@@ -248,7 +263,7 @@ krb5_error_code + kr_attr_encode(krb5_context ctx, const char *secret, + const unsigned char *auth, krad_attr type, + const krb5_data *in, unsigned char outbuf[MAX_ATTRSIZE], +- size_t *outlen) ++ size_t *outlen, krb5_boolean *is_fips) + { + krb5_error_code retval; + +@@ -265,7 +280,8 @@ kr_attr_encode(krb5_context ctx, const char *secret, + return 0; + } + +- return attributes[type - 1].encode(ctx, secret, auth, in, outbuf, outlen); ++ return attributes[type - 1].encode(ctx, secret, auth, in, outbuf, outlen, ++ is_fips); + } + + krb5_error_code +@@ -274,6 +290,7 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, + unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen) + { + krb5_error_code retval; ++ krb5_boolean ignored; + + retval = kr_attr_valid(type, in); + if (retval != 0) +@@ -288,7 +305,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, + return 0; + } + +- return attributes[type - 1].decode(ctx, secret, auth, in, outbuf, outlen); ++ return attributes[type - 1].decode(ctx, secret, auth, in, outbuf, outlen, ++ &ignored); + } + + krad_attr +diff --git a/src/lib/krad/attrset.c b/src/lib/krad/attrset.c +index 03c613716..d89982a13 100644 +--- a/src/lib/krad/attrset.c ++++ b/src/lib/krad/attrset.c +@@ -167,7 +167,8 @@ krad_attrset_copy(const krad_attrset *set, krad_attrset **copy) + krb5_error_code + kr_attrset_encode(const krad_attrset *set, const char *secret, + const unsigned char *auth, +- unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen) ++ unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen, ++ krb5_boolean *is_fips) + { + unsigned char buffer[MAX_ATTRSIZE]; + krb5_error_code retval; +@@ -181,7 +182,7 @@ kr_attrset_encode(const krad_attrset *set, const char *secret, + + K5_TAILQ_FOREACH(a, &set->list, list) { + retval = kr_attr_encode(set->ctx, secret, auth, a->type, &a->attr, +- buffer, &attrlen); ++ buffer, &attrlen, is_fips); + if (retval != 0) + return retval; + +diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h +index 996a89372..a53ce31ce 100644 +--- a/src/lib/krad/internal.h ++++ b/src/lib/krad/internal.h +@@ -49,6 +49,13 @@ + + typedef struct krad_remote_st krad_remote; + ++struct krad_packet_st { ++ char buffer[KRAD_PACKET_SIZE_MAX]; ++ krad_attrset *attrset; ++ krb5_data pkt; ++ krb5_boolean is_fips; ++}; ++ + /* Validate constraints of an attribute. */ + krb5_error_code + kr_attr_valid(krad_attr type, const krb5_data *data); +@@ -57,7 +64,8 @@ kr_attr_valid(krad_attr type, const krb5_data *data); + krb5_error_code + kr_attr_encode(krb5_context ctx, const char *secret, const unsigned char *auth, + krad_attr type, const krb5_data *in, +- unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen); ++ unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen, ++ krb5_boolean *is_fips); + + /* Decode an attribute. */ + krb5_error_code +@@ -69,7 +77,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, + krb5_error_code + kr_attrset_encode(const krad_attrset *set, const char *secret, + const unsigned char *auth, +- unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen); ++ unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen, ++ krb5_boolean *is_fips); + + /* Decode attributes from a buffer. */ + krb5_error_code +diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c +index c597174b6..2fbf0ee1e 100644 +--- a/src/lib/krad/packet.c ++++ b/src/lib/krad/packet.c +@@ -53,12 +53,6 @@ typedef unsigned char uchar; + #define pkt_auth(p) ((uchar *)offset(&(p)->pkt, OFFSET_AUTH)) + #define pkt_attr(p) ((unsigned char *)offset(&(p)->pkt, OFFSET_ATTR)) + +-struct krad_packet_st { +- char buffer[KRAD_PACKET_SIZE_MAX]; +- krad_attrset *attrset; +- krb5_data pkt; +-}; +- + typedef struct { + uchar x[(UCHAR_MAX + 1) / 8]; + } idmap; +@@ -190,7 +184,11 @@ auth_generate_response(krb5_context ctx, const char *secret, + retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &data, + &hash); + free(data.data); +- if (retval != 0) ++ if (retval == ENOMEM) { ++ /* We're on Linux, so this is a FIPS failure, and this checksum ++ * does very little security-wise anyway, so don't taint. */ ++ hash.contents = calloc(1, AUTH_FIELD_SIZE); ++ } else if (retval != 0) + return retval; + + memcpy(rauth, hash.contents, AUTH_FIELD_SIZE); +@@ -276,7 +274,7 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code, + + /* Encode the attributes. */ + retval = kr_attrset_encode(set, secret, pkt_auth(pkt), pkt_attr(pkt), +- &attrset_len); ++ &attrset_len, &pkt->is_fips); + if (retval != 0) + goto error; + +@@ -314,7 +312,7 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code, + + /* Encode the attributes. */ + retval = kr_attrset_encode(set, secret, pkt_auth(request), pkt_attr(pkt), +- &attrset_len); ++ &attrset_len, &pkt->is_fips); + if (retval != 0) + goto error; + +@@ -451,6 +449,8 @@ krad_packet_decode_response(krb5_context ctx, const char *secret, + const krb5_data * + krad_packet_encode(const krad_packet *pkt) + { ++ if (pkt->is_fips) ++ return NULL; + return &pkt->pkt; + } + +diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c +index 437f7e91a..0f90443ce 100644 +--- a/src/lib/krad/remote.c ++++ b/src/lib/krad/remote.c +@@ -263,7 +263,7 @@ on_io_write(krad_remote *rr) + request *r; + + K5_TAILQ_FOREACH(r, &rr->list, list) { +- tmp = krad_packet_encode(r->request); ++ tmp = &r->request->pkt; + + /* If the packet has already been sent, do nothing. */ + if (r->sent == tmp->length) +@@ -359,7 +359,7 @@ on_io_read(krad_remote *rr) + if (req != NULL) { + K5_TAILQ_FOREACH(r, &rr->list, list) { + if (r->request == req && +- r->sent == krad_packet_encode(req)->length) { ++ r->sent == req->pkt.length) { + request_finish(r, 0, rsp); + break; + } +@@ -455,6 +455,12 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs, + (krad_packet_iter_cb)iterator, &r, &tmp); + if (retval != 0) + goto error; ++ else if (tmp->is_fips && rr->info->ai_family != AF_LOCAL && ++ rr->info->ai_family != AF_UNIX) { ++ /* This would expose cleartext passwords, so abort. */ ++ retval = ESOCKTNOSUPPORT; ++ goto error; ++ } + + K5_TAILQ_FOREACH(r, &rr->list, list) { + if (r->request == tmp) { +diff --git a/src/lib/krad/t_attr.c b/src/lib/krad/t_attr.c +index eb2a780c8..4d285ad9d 100644 +--- a/src/lib/krad/t_attr.c ++++ b/src/lib/krad/t_attr.c +@@ -50,6 +50,7 @@ main() + const char *tmp; + krb5_data in; + size_t len; ++ krb5_boolean is_fips = FALSE; + + noerror(krb5_init_context(&ctx)); + +@@ -73,7 +74,7 @@ main() + in = string2data((char *)decoded); + retval = kr_attr_encode(ctx, secret, auth, + krad_attr_name2num("User-Password"), +- &in, outbuf, &len); ++ &in, outbuf, &len, &is_fips); + insist(retval == 0); + insist(len == sizeof(encoded)); + insist(memcmp(outbuf, encoded, len) == 0); +diff --git a/src/lib/krad/t_attrset.c b/src/lib/krad/t_attrset.c +index 7928335ca..0f9576253 100644 +--- a/src/lib/krad/t_attrset.c ++++ b/src/lib/krad/t_attrset.c +@@ -49,6 +49,7 @@ main() + krb5_context ctx; + size_t len = 0, encode_len; + krb5_data tmp; ++ krb5_boolean is_fips = FALSE; + + noerror(krb5_init_context(&ctx)); + noerror(krad_attrset_new(ctx, &set)); +@@ -62,7 +63,8 @@ main() + noerror(krad_attrset_add(set, krad_attr_name2num("User-Password"), &tmp)); + + /* Encode attrset. */ +- noerror(kr_attrset_encode(set, "foo", auth, buffer, &encode_len)); ++ noerror(kr_attrset_encode(set, "foo", auth, buffer, &encode_len, ++ &is_fips)); + krad_attrset_free(set); + + /* Manually encode User-Name. */ diff --git a/Include-etype-info-in-for-hardware-preauth-hints.patch b/Include-etype-info-in-for-hardware-preauth-hints.patch index 788a88a..82aba62 100644 --- a/Include-etype-info-in-for-hardware-preauth-hints.patch +++ b/Include-etype-info-in-for-hardware-preauth-hints.patch @@ -10,7 +10,6 @@ password. ticket: 8629 (cherry picked from commit ba92da05accc524b8037453b63ced1a6c65fd2a1) -Signed-off-by: Robbie Harwood --- src/kdc/kdc_preauth.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Include-preauth-name-in-trace-output-if-possible.patch b/Include-preauth-name-in-trace-output-if-possible.patch index 59dfc21..fe88920 100644 --- a/Include-preauth-name-in-trace-output-if-possible.patch +++ b/Include-preauth-name-in-trace-output-if-possible.patch @@ -11,7 +11,6 @@ and use it when formatting {patype} or {patypes}. ticket: 8653 (new) (cherry picked from commit 9c68fe39b018666eabe033b639c1f35d03ba51c7) -Signed-off-by: Robbie Harwood --- src/include/k5-trace.h | 17 +-- src/lib/krb5/os/t_trace.ref | 2 +- diff --git a/Log-when-non-root-ksu-authorization-fails.patch b/Log-when-non-root-ksu-authorization-fails.patch index b4a6c2e..704b5a9 100644 --- a/Log-when-non-root-ksu-authorization-fails.patch +++ b/Log-when-non-root-ksu-authorization-fails.patch @@ -8,7 +8,6 @@ syslog at LOG_WARNING in keeping with other failure messages. ticket: 8270 (cherry picked from commit 6cfa5c113e981f14f70ccafa20abfa5c46b665ba) -Signed-off-by: Robbie Harwood --- src/clients/ksu/main.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/Make-docs-build-python3-compatible.patch b/Make-docs-build-python3-compatible.patch index f6e5fa1..58a3e86 100644 --- a/Make-docs-build-python3-compatible.patch +++ b/Make-docs-build-python3-compatible.patch @@ -8,7 +8,6 @@ paths information in docs. Call exec() directly instead. ticket: 8692 (new) (cherry picked from commit a7c6d98480f1e33454173f88381921472d72f80a) -Signed-off-by: Robbie Harwood --- doc/conf.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Make-krb5kdc-p-affect-TCP-ports.patch b/Make-krb5kdc-p-affect-TCP-ports.patch index 1b4ae04..ac5bc30 100644 --- a/Make-krb5kdc-p-affect-TCP-ports.patch +++ b/Make-krb5kdc-p-affect-TCP-ports.patch @@ -9,7 +9,6 @@ ports. ticket: 8715 (new) (cherry picked from commit eb514587acc5c357bf0f554199bf0489b5515f8b) -Signed-off-by: Robbie Harwood --- doc/admin/admin_commands/krb5kdc.rst | 12 ++++++------ src/kdc/main.c | 12 ++++-------- diff --git a/Move-zap-definition-to-k5-platform.h.patch b/Move-zap-definition-to-k5-platform.h.patch index 4e93056..f181701 100644 --- a/Move-zap-definition-to-k5-platform.h.patch +++ b/Move-zap-definition-to-k5-platform.h.patch @@ -7,7 +7,6 @@ Make it possible to use zap() in parts of the code which should not include k5-int.h by moving its definition to k5-platform.h. (cherry picked from commit df6bef6f9ea6a5f6f3956a2988cd658c78aae817) -Signed-off-by: Robbie Harwood --- src/include/k5-int.h | 45 ------------------------------------- src/include/k5-platform.h | 47 ++++++++++++++++++++++++++++++++++++++- diff --git a/Process-profile-includedir-in-sorted-order.patch b/Process-profile-includedir-in-sorted-order.patch index 044c046..92efffc 100644 --- a/Process-profile-includedir-in-sorted-order.patch +++ b/Process-profile-includedir-in-sorted-order.patch @@ -9,7 +9,6 @@ within the C locale). ticket: 8686 (cherry picked from commit f574eda48740ad192f51e9a382a205e2ea0e60ad) -Signed-off-by: Robbie Harwood --- doc/admin/conf_files/krb5_conf.rst | 4 ++- src/util/profile/prof_parse.c | 56 +++++------------------------- diff --git a/Refactor-KDC-krb5_pa_data-utility-functions.patch b/Refactor-KDC-krb5_pa_data-utility-functions.patch index b7acc49..41e7cbe 100644 --- a/Refactor-KDC-krb5_pa_data-utility-functions.patch +++ b/Refactor-KDC-krb5_pa_data-utility-functions.patch @@ -16,7 +16,6 @@ callers accordingly, making small simplifications to memory handling where applicable. (cherry picked from commit 4af478c18b02e1d2444a328bb79e6976ef3d312b) -Signed-off-by: Robbie Harwood --- src/kdc/fast_util.c | 28 +------ src/kdc/kdc_preauth.c | 14 ++-- diff --git a/Remove-nodes-option-from-make-certs-scripts.patch b/Remove-nodes-option-from-make-certs-scripts.patch index f45b1b0..402f5fb 100644 --- a/Remove-nodes-option-from-make-certs-scripts.patch +++ b/Remove-nodes-option-from-make-certs-scripts.patch @@ -12,7 +12,6 @@ pkcs12 subcommands, but genrsa creates unencrypted keys by default. [ghudson@mit.edu: edited commit message] (cherry picked from commit 928a36aae326d496c9a73f2cd41b4da45eef577c) -Signed-off-by: Robbie Harwood --- src/tests/dejagnu/pkinit-certs/make-certs.sh | 2 +- src/tests/dejagnu/proxy-certs/make-certs.sh | 2 +- diff --git a/Remove-outdated-note-in-krb5kdc-man-page.patch b/Remove-outdated-note-in-krb5kdc-man-page.patch index b2e8c13..6845b89 100644 --- a/Remove-outdated-note-in-krb5kdc-man-page.patch +++ b/Remove-outdated-note-in-krb5kdc-man-page.patch @@ -13,7 +13,6 @@ tags: pullup target_version: 1.16-next (cherry picked from commit 728b66ab867e31c4c338c6a6309d629d39a4ec3f) -Signed-off-by: Robbie Harwood --- doc/admin/admin_commands/krb5kdc.rst | 7 ------- 1 file changed, 7 deletions(-) diff --git a/Report-extended-errors-in-kinit-k-t-KDB.patch b/Report-extended-errors-in-kinit-k-t-KDB.patch index bc6728d..6859b55 100644 --- a/Report-extended-errors-in-kinit-k-t-KDB.patch +++ b/Report-extended-errors-in-kinit-k-t-KDB.patch @@ -9,7 +9,6 @@ extended error messages. ticket: 8652 (new) (cherry picked from commit d4d902d317a2acc46ee71094a33a9203b6135275) -Signed-off-by: Robbie Harwood --- src/clients/kinit/kinit.c | 1 + 1 file changed, 1 insertion(+) diff --git a/Restrict-pre-authentication-fallback-cases.patch b/Restrict-pre-authentication-fallback-cases.patch index d5c9d86..f519557 100644 --- a/Restrict-pre-authentication-fallback-cases.patch +++ b/Restrict-pre-authentication-fallback-cases.patch @@ -16,7 +16,6 @@ retried after a failure. ticket: 8654 (cherry picked from commit 7a24a088c16d326127dd2b29084d4ca085c70d10) -Signed-off-by: Robbie Harwood --- src/include/krb5/clpreauth_plugin.h | 14 ++++ src/lib/krb5/krb/get_in_tkt.c | 21 +++--- diff --git a/Simplify-kdc_preauth.c-systems-table.patch b/Simplify-kdc_preauth.c-systems-table.patch index c7ff103..08853d4 100644 --- a/Simplify-kdc_preauth.c-systems-table.patch +++ b/Simplify-kdc_preauth.c-systems-table.patch @@ -15,7 +15,6 @@ padata types. The KRB5_PADATA_SERVER_REFERRAL entry has been disabled since it was first added. (cherry picked from commit fea1a488924faa3938ef723feaa1ff12d22a91ff) -Signed-off-by: Robbie Harwood --- src/kdc/kdc_preauth.c | 526 +++++++++++++++--------------------------- 1 file changed, 184 insertions(+), 342 deletions(-) diff --git a/Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch b/Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch index 061a7fc..26df25a 100644 --- a/Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch +++ b/Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch @@ -5,7 +5,6 @@ Subject: [PATCH] Use SHA-256 instead of MD5 for audit ticket IDs ticket: 8711 (new) (cherry picked from commit c1e1bfa26bd2f045e88e6013c500fca9428c98f3) -Signed-off-by: Robbie Harwood --- src/kdc/kdc_audit.c | 21 ++++++++++----------- 1 file changed, 10 insertions(+), 11 deletions(-) diff --git a/Use-k5_buf_init_dynamic_zap-where-appropriate.patch b/Use-k5_buf_init_dynamic_zap-where-appropriate.patch index 8d8e774..3d3bcd8 100644 --- a/Use-k5_buf_init_dynamic_zap-where-appropriate.patch +++ b/Use-k5_buf_init_dynamic_zap-where-appropriate.patch @@ -4,7 +4,6 @@ Date: Mon, 26 Mar 2018 11:24:49 -0400 Subject: [PATCH] Use k5_buf_init_dynamic_zap where appropriate (cherry picked from commit 9172599008f3a6790d4a9a67acff58049742dcb6) -Signed-off-by: Robbie Harwood --- src/lib/krb5/ccache/cc_file.c | 4 ++-- src/lib/krb5/ccache/cc_keyring.c | 2 +- diff --git a/Use-libkrb5support-hex-functions-where-appropriate.patch b/Use-libkrb5support-hex-functions-where-appropriate.patch index 81c8164..eab05bc 100644 --- a/Use-libkrb5support-hex-functions-where-appropriate.patch +++ b/Use-libkrb5support-hex-functions-where-appropriate.patch @@ -4,7 +4,6 @@ Date: Mon, 19 Feb 2018 00:52:35 -0500 Subject: [PATCH] Use libkrb5support hex functions where appropriate (cherry picked from commit b0c700608be7455041a8afc0e4502e8783ee7f30) -Signed-off-by: Robbie Harwood --- src/kadmin/dbutil/deps | 16 ++--- src/kadmin/dbutil/tabdump.c | 19 +++--- diff --git a/Zap-copy-of-secret-in-RC4-string-to-key.patch b/Zap-copy-of-secret-in-RC4-string-to-key.patch index 7f3bbf4..7502c25 100644 --- a/Zap-copy-of-secret-in-RC4-string-to-key.patch +++ b/Zap-copy-of-secret-in-RC4-string-to-key.patch @@ -11,7 +11,6 @@ freed as the input string typically contains a password. [ghudson@mit.edu: rewrote commit message] ticket: 8713 (new) -Signed-off-by: Robbie Harwood --- src/lib/crypto/krb/s2k_rc4.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Zap-data-when-freeing-krb5_spake_factor.patch b/Zap-data-when-freeing-krb5_spake_factor.patch index 04652af..9ce2462 100644 --- a/Zap-data-when-freeing-krb5_spake_factor.patch +++ b/Zap-data-when-freeing-krb5_spake_factor.patch @@ -8,7 +8,6 @@ second-factor SPAKE is implemented, so should be zapped when freed. ticket: 8647 (cherry picked from commit 9cc94a3f1ce06a4430f684300a747ec079102403) -Signed-off-by: Robbie Harwood --- src/lib/krb5/krb/kfree.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch index 144e3bf..ddd3ec2 100644 --- a/krb5-1.11-kpasswdtest.patch +++ b/krb5-1.11-kpasswdtest.patch @@ -3,7 +3,6 @@ From: Robbie Harwood Date: Tue, 23 Aug 2016 16:52:01 -0400 Subject: [PATCH] krb5-1.11-kpasswdtest.patch -Signed-off-by: Robbie Harwood --- src/kadmin/testing/proto/krb5.conf.proto | 1 + 1 file changed, 1 insertion(+) diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch index 06f2e6e..febb3b3 100644 --- a/krb5-1.11-run_user_0.patch +++ b/krb5-1.11-run_user_0.patch @@ -6,8 +6,6 @@ Subject: [PATCH] krb5-1.11-run_user_0.patch A hack: if we're looking at creating a ccache directory directly below the /run/user/0 directory, and /run/user/0 doesn't exist, try to create it, too. - -Signed-off-by: Robbie Harwood --- src/lib/krb5/ccache/cc_dir.c | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/krb5-1.12-api.patch b/krb5-1.12-api.patch index dbf6183..9eba2ff 100644 --- a/krb5-1.12-api.patch +++ b/krb5-1.12-api.patch @@ -6,8 +6,6 @@ Subject: [PATCH] krb5-1.12-api.patch Reference docs don't define what happens if you call krb5_realm_compare() with malformed krb5_principal structures. Define a behavior which keeps it from crashing if applications don't check ahead of time. - -Signed-off-by: Robbie Harwood --- src/lib/krb5/krb/princ_comp.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/krb5-1.12-ksu-path.patch b/krb5-1.12-ksu-path.patch index b7b1c7e..19b9e73 100644 --- a/krb5-1.12-ksu-path.patch +++ b/krb5-1.12-ksu-path.patch @@ -4,8 +4,6 @@ Date: Tue, 23 Aug 2016 16:32:09 -0400 Subject: [PATCH] krb5-1.12-ksu-path.patch Set the default PATH to the one set by login. - -Signed-off-by: Robbie Harwood --- src/clients/ksu/Makefile.in | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/krb5-1.12-ktany.patch b/krb5-1.12-ktany.patch index 59bb3d6..de59827 100644 --- a/krb5-1.12-ktany.patch +++ b/krb5-1.12-ktany.patch @@ -6,8 +6,6 @@ Subject: [PATCH] krb5-1.12-ktany.patch Adds an "ANY" keytab type which is a list of other keytab locations to search when searching for a specific entry. When iterated through, it only presents the contents of the first keytab. - -Signed-off-by: Robbie Harwood --- src/lib/krb5/keytab/Makefile.in | 3 + src/lib/krb5/keytab/kt_any.c | 292 ++++++++++++++++++++++++++++++++ diff --git a/krb5-1.12.1-pam.patch b/krb5-1.12.1-pam.patch index 6060ce9..97c1e8f 100644 --- a/krb5-1.12.1-pam.patch +++ b/krb5-1.12.1-pam.patch @@ -16,8 +16,6 @@ When enabled, ksu gains a dependency on libpam. Originally RT#5939, though it's changed since then to perform the account and session management before dropping privileges, and to apply on top of changes we're proposing for how it handles cache collections. - -Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 67 +++++++ src/clients/ksu/Makefile.in | 8 +- diff --git a/krb5-1.13-dirsrv-accountlock.patch b/krb5-1.13-dirsrv-accountlock.patch index 7e22280..ff5f73e 100644 --- a/krb5-1.13-dirsrv-accountlock.patch +++ b/krb5-1.13-dirsrv-accountlock.patch @@ -5,8 +5,6 @@ Subject: [PATCH] krb5-1.13-dirsrv-accountlock.patch Treat 'nsAccountLock: true' the same as 'loginDisabled: true'. Updated from original version filed as RT#5891. - -Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 9 +++++++++ src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c | 17 +++++++++++++++++ diff --git a/krb5-1.15-beta1-buildconf.patch b/krb5-1.15-beta1-buildconf.patch index 3e301c8..a949727 100644 --- a/krb5-1.15-beta1-buildconf.patch +++ b/krb5-1.15-beta1-buildconf.patch @@ -8,8 +8,6 @@ and install shared libraries with the execute bit set on them. Prune out the -L/usr/lib* and PIE flags where they might leak out and affect apps which just want to link with the libraries. FIXME: needs to check and not just assume that the compiler supports using these flags. - -Signed-off-by: Robbie Harwood --- src/build-tools/krb5-config.in | 7 +++++++ src/config/pre.in | 2 +- diff --git a/krb5-1.15.1-selinux-label.patch b/krb5-1.15.1-selinux-label.patch index b2f6cb0..728c72e 100644 --- a/krb5-1.15.1-selinux-label.patch +++ b/krb5-1.15.1-selinux-label.patch @@ -35,8 +35,6 @@ stomp all over us. The selabel APIs for looking up the context should be thread-safe (per Red Hat #273081), so switching to using them instead of matchpathcon(), which we used earlier, is some improvement. - -Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 49 +++ src/build-tools/krb5-config.in | 3 +- diff --git a/krb5-1.3.1-dns.patch b/krb5-1.3.1-dns.patch index 9fb9df8..1af7c12 100644 --- a/krb5-1.3.1-dns.patch +++ b/krb5-1.3.1-dns.patch @@ -4,8 +4,6 @@ Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] krb5-1.3.1-dns.patch We want to be able to use --with-netlib and --enable-dns at the same time. - -Signed-off-by: Robbie Harwood --- src/aclocal.m4 | 1 + 1 file changed, 1 insertion(+) diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index 4378ff7..5b0f5bc 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -6,8 +6,6 @@ Subject: [PATCH] krb5-1.9-debuginfo.patch We want to keep these y.tab.c files around because the debuginfo points to them. It would be more elegant at the end to use symbolic links, but that could mess up people working in the tree on other things. - -Signed-off-by: Robbie Harwood --- src/kadmin/cli/Makefile.in | 5 +++++ src/plugins/kdb/ldap/ldap_util/Makefile.in | 2 +- diff --git a/krb5.spec b/krb5.spec index db9f9b0..ae797b0 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 18%{?dist} +Release: 19%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -102,6 +102,7 @@ Patch82: Eliminate-preprocessor-disabled-dead-code.patch Patch83: Make-krb5kdc-p-affect-TCP-ports.patch Patch84: Remove-outdated-note-in-krb5kdc-man-page.patch Patch85: Fix-k5test-prompts-for-Python-3.patch +Patch86: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -748,6 +749,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Aug 01 2018 Robbie Harwood - 1.16.1-19 +- In FIPS mode, add plaintext fallback for RC4 usages and taint + * Thu Jul 26 2018 Robbie Harwood - 1.16.1-18 - Fix k5test prompts for Python 3 From af8b6635d681ab0b7acf611ef49935742299e422 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Oct 2018 13:36:43 -0400 Subject: [PATCH 067/304] Fix bugs with concurrent use of MEMORY ccaches --- ...ith-concurrent-use-of-MEMORY-ccaches.patch | 396 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 401 insertions(+), 1 deletion(-) create mode 100644 Fix-bugs-with-concurrent-use-of-MEMORY-ccaches.patch diff --git a/Fix-bugs-with-concurrent-use-of-MEMORY-ccaches.patch b/Fix-bugs-with-concurrent-use-of-MEMORY-ccaches.patch new file mode 100644 index 0000000..085030a --- /dev/null +++ b/Fix-bugs-with-concurrent-use-of-MEMORY-ccaches.patch @@ -0,0 +1,396 @@ +From f61875dc7da3d5dadb935ebcce25fe66564f7d0f Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sun, 1 Jul 2018 00:12:25 -0400 +Subject: [PATCH] Fix bugs with concurrent use of MEMORY ccaches + +A memory ccache iterator stores an alias into the cache object's +linked list of credentials. If the cache is reinitialized while the +iterator is active, the alias becomes invalid. Also, multiple handles +referencing the same memory ccache all use aliases to the same data +object; if one of the handles is destroyed, the other contains a +dangling pointer. + +Fix the first issue by adding a generation counter to the cache and to +cursors, incremented each time the cache is initialized or destroyed. +Check the generation on each cursor step and end the iteration if the +list was invalidated. Fix the second issue by adding a reference +count to the cache object, counting one reference for the table slot +and one for each open handle. Empty the cache object on each destroy +operation, but only release the object when the last handle to it is +destroyed or closed. + +Add regression tests for the two issues to t_cc.c. + +The first issue was reported by Sorin Manolache. + +ticket: 8202 +tags: pullup +target_version: 1.16-next +target_version: 1.15-next + +(cherry picked from commit 146dadec8fe7ccc4149eb2e3f577cc320aee6efb) +--- + src/lib/krb5/ccache/cc_memory.c | 164 ++++++++++++++++++++------------ + src/lib/krb5/ccache/t_cc.c | 51 ++++++++++ + 2 files changed, 154 insertions(+), 61 deletions(-) + +diff --git a/src/lib/krb5/ccache/cc_memory.c b/src/lib/krb5/ccache/cc_memory.c +index c5425eb3a..8cdaff7fb 100644 +--- a/src/lib/krb5/ccache/cc_memory.c ++++ b/src/lib/krb5/ccache/cc_memory.c +@@ -102,18 +102,20 @@ extern krb5_error_code krb5_change_cache (void); + typedef struct _krb5_mcc_link { + struct _krb5_mcc_link *next; + krb5_creds *creds; +-} krb5_mcc_link, *krb5_mcc_cursor; ++} krb5_mcc_link; + + /* Per-cache data header. */ + typedef struct _krb5_mcc_data { + char *name; + k5_cc_mutex lock; + krb5_principal prin; +- krb5_mcc_cursor link; ++ krb5_mcc_link *link; + krb5_timestamp changetime; + /* Time offsets for clock-skewed clients. */ + krb5_int32 time_offset; + krb5_int32 usec_offset; ++ int refcount; /* One for the table slot, one per handle */ ++ int generation; /* Incremented at each initialize */ + } krb5_mcc_data; + + /* List of memory caches. */ +@@ -122,6 +124,12 @@ typedef struct krb5_mcc_list_node { + krb5_mcc_data *cache; + } krb5_mcc_list_node; + ++/* Iterator over credentials in a memory cache. */ ++struct mcc_cursor { ++ int generation; ++ krb5_mcc_link *next_link; ++}; ++ + /* Iterator over memory caches. */ + struct krb5_mcc_ptcursor_data { + struct krb5_mcc_list_node *cur; +@@ -132,7 +140,23 @@ static krb5_mcc_list_node *mcc_head = 0; + + static void update_mcc_change_time(krb5_mcc_data *); + +-static void krb5_mcc_free (krb5_context context, krb5_ccache id); ++/* Remove creds from d, invalidate any existing cursors, and unset the client ++ * principal. The caller is responsible for locking. */ ++static void ++empty_mcc_cache(krb5_context context, krb5_mcc_data *d) ++{ ++ krb5_mcc_link *curr, *next; ++ ++ for (curr = d->link; curr != NULL; curr = next) { ++ next = curr->next; ++ krb5_free_creds(context, curr->creds); ++ free(curr); ++ } ++ d->link = NULL; ++ d->generation++; ++ krb5_free_principal(context, d->prin); ++ d->prin = NULL; ++} + + /* + * Modifies: +@@ -150,16 +174,12 @@ krb5_mcc_initialize(krb5_context context, krb5_ccache id, krb5_principal princ) + { + krb5_os_context os_ctx = &context->os_context; + krb5_error_code ret; +- krb5_mcc_data *d; ++ krb5_mcc_data *d = id->data; + +- d = (krb5_mcc_data *)id->data; + k5_cc_mutex_lock(context, &d->lock); ++ empty_mcc_cache(context, d); + +- krb5_mcc_free(context, id); +- +- d = (krb5_mcc_data *)id->data; +- ret = krb5_copy_principal(context, princ, +- &d->prin); ++ ret = krb5_copy_principal(context, princ, &d->prin); + update_mcc_change_time(d); + + if (os_ctx->os_flags & KRB5_OS_TOFFSET_VALID) { +@@ -185,61 +205,59 @@ krb5_mcc_initialize(krb5_context context, krb5_ccache id, krb5_principal princ) + krb5_error_code KRB5_CALLCONV + krb5_mcc_close(krb5_context context, krb5_ccache id) + { ++ krb5_mcc_data *d = id->data; ++ int count; ++ + free(id); +- return KRB5_OK; +-} +- +-static void +-krb5_mcc_free(krb5_context context, krb5_ccache id) +-{ +- krb5_mcc_cursor curr,next; +- krb5_mcc_data *d; +- +- d = (krb5_mcc_data *) id->data; +- for (curr = d->link; curr;) { +- krb5_free_creds(context, curr->creds); +- next = curr->next; +- free(curr); +- curr = next; ++ k5_cc_mutex_lock(context, &d->lock); ++ count = --d->refcount; ++ k5_cc_mutex_unlock(context, &d->lock); ++ if (count == 0) { ++ /* This is the last active handle referencing d and d has been removed ++ * from the table, so we can release it. */ ++ empty_mcc_cache(context, d); ++ free(d->name); ++ k5_cc_mutex_destroy(&d->lock); ++ free(d); + } +- d->link = NULL; +- krb5_free_principal(context, d->prin); ++ return KRB5_OK; + } + + /* + * Effects: + * Destroys the contents of id. id is invalid after call. +- * +- * Errors: +- * system errors (locks related) + */ + krb5_error_code KRB5_CALLCONV + krb5_mcc_destroy(krb5_context context, krb5_ccache id) + { + krb5_mcc_list_node **curr, *node; +- krb5_mcc_data *d; ++ krb5_mcc_data *d = id->data; ++ krb5_boolean removed_from_table = FALSE; + + k5_cc_mutex_lock(context, &krb5int_mcc_mutex); + +- d = (krb5_mcc_data *)id->data; + for (curr = &mcc_head; *curr; curr = &(*curr)->next) { + if ((*curr)->cache == d) { + node = *curr; + *curr = node->next; + free(node); ++ removed_from_table = TRUE; + break; + } + } + k5_cc_mutex_unlock(context, &krb5int_mcc_mutex); + ++ /* Empty the cache and remove the reference for the table slot. There will ++ * always be at least one reference left for the handle being destroyed. */ + k5_cc_mutex_lock(context, &d->lock); +- +- krb5_mcc_free(context, id); +- free(d->name); ++ empty_mcc_cache(context, d); ++ if (removed_from_table) ++ d->refcount--; + k5_cc_mutex_unlock(context, &d->lock); +- k5_cc_mutex_destroy(&d->lock); +- free(d); +- free(id); ++ ++ /* Invalidate the handle, possibly removing the last reference to d and ++ * freeing it. */ ++ krb5_mcc_close(context, id); + + krb5_change_cache (); + return KRB5_OK; +@@ -279,9 +297,12 @@ krb5_mcc_resolve (krb5_context context, krb5_ccache *id, const char *residual) + for (ptr = mcc_head; ptr; ptr=ptr->next) + if (!strcmp(ptr->cache->name, residual)) + break; +- if (ptr) ++ if (ptr != NULL) { + d = ptr->cache; +- else { ++ k5_cc_mutex_lock(context, &d->lock); ++ d->refcount++; ++ k5_cc_mutex_unlock(context, &d->lock); ++ } else { + err = new_mcc_data(residual, &d); + if (err) { + k5_cc_mutex_unlock(context, &krb5int_mcc_mutex); +@@ -326,14 +347,18 @@ krb5_error_code KRB5_CALLCONV + krb5_mcc_start_seq_get(krb5_context context, krb5_ccache id, + krb5_cc_cursor *cursor) + { +- krb5_mcc_cursor mcursor; ++ struct mcc_cursor *mcursor; + krb5_mcc_data *d; + ++ mcursor = malloc(sizeof(*mcursor)); ++ if (mcursor == NULL) ++ return KRB5_CC_NOMEM; + d = id->data; + k5_cc_mutex_lock(context, &d->lock); +- mcursor = d->link; ++ mcursor->generation = d->generation; ++ mcursor->next_link = d->link; + k5_cc_mutex_unlock(context, &d->lock); +- *cursor = (krb5_cc_cursor) mcursor; ++ *cursor = mcursor; + return KRB5_OK; + } + +@@ -361,23 +386,34 @@ krb5_error_code KRB5_CALLCONV + krb5_mcc_next_cred(krb5_context context, krb5_ccache id, + krb5_cc_cursor *cursor, krb5_creds *creds) + { +- krb5_mcc_cursor mcursor; ++ struct mcc_cursor *mcursor; + krb5_error_code retval; ++ krb5_mcc_data *d = id->data; + +- /* Once the node in the linked list is created, it's never +- modified, so we don't need to worry about locking here. (Note +- that we don't support _remove_cred.) */ +- mcursor = (krb5_mcc_cursor) *cursor; +- if (mcursor == NULL) +- return KRB5_CC_END; + memset(creds, 0, sizeof(krb5_creds)); +- if (mcursor->creds) { +- retval = k5_copy_creds_contents(context, mcursor->creds, creds); +- if (retval) +- return retval; ++ mcursor = *cursor; ++ if (mcursor->next_link == NULL) ++ return KRB5_CC_END; ++ ++ /* ++ * Check the cursor generation against the cache generation in case the ++ * cache has been reinitialized or destroyed, freeing the pointer in the ++ * cursor. Keep the cache locked while we copy the creds and advance the ++ * pointer, in case another thread reinitializes the cache after we check ++ * the generation. ++ */ ++ k5_cc_mutex_lock(context, &d->lock); ++ if (mcursor->generation != d->generation) { ++ k5_cc_mutex_unlock(context, &d->lock); ++ return KRB5_CC_END; + } +- *cursor = (krb5_cc_cursor)mcursor->next; +- return KRB5_OK; ++ ++ retval = k5_copy_creds_contents(context, mcursor->next_link->creds, creds); ++ if (retval == 0) ++ mcursor->next_link = mcursor->next_link->next; ++ ++ k5_cc_mutex_unlock(context, &d->lock); ++ return retval; + } + + /* +@@ -396,14 +432,18 @@ krb5_mcc_next_cred(krb5_context context, krb5_ccache id, + krb5_error_code KRB5_CALLCONV + krb5_mcc_end_seq_get(krb5_context context, krb5_ccache id, krb5_cc_cursor *cursor) + { +- *cursor = 0L; ++ free(*cursor); ++ *cursor = NULL; + return KRB5_OK; + } + +-/* Utility routine: Creates the back-end data for a memory cache, and +- threads it into the global linked list. +- +- Call with the global list lock held. */ ++/* ++ * Utility routine: Creates the back-end data for a memory cache, and threads ++ * it into the global linked list. Give the new object two references, one for ++ * the table slot and one for the caller's handle. ++ * ++ * Call with the global list lock held. ++ */ + static krb5_error_code + new_mcc_data (const char *name, krb5_mcc_data **dataptr) + { +@@ -432,6 +472,8 @@ new_mcc_data (const char *name, krb5_mcc_data **dataptr) + d->changetime = 0; + d->time_offset = 0; + d->usec_offset = 0; ++ d->refcount = 2; ++ d->generation = 0; + update_mcc_change_time(d); + + n = malloc(sizeof(krb5_mcc_list_node)); +diff --git a/src/lib/krb5/ccache/t_cc.c b/src/lib/krb5/ccache/t_cc.c +index 6069cabd3..cd4569c4c 100644 +--- a/src/lib/krb5/ccache/t_cc.c ++++ b/src/lib/krb5/ccache/t_cc.c +@@ -386,6 +386,55 @@ test_misc(krb5_context context) + krb5_cc_dfl_ops = ops_save; + + } ++ ++/* ++ * Regression tests for #8202. Because memory ccaches share objects between ++ * different handles to the same cache and between iterators and caches, ++ * historically there have been some bugs when those objects are released. ++ */ ++static void ++test_memory_concurrent(krb5_context context) ++{ ++ krb5_error_code kret; ++ krb5_ccache id1, id2; ++ krb5_cc_cursor cursor; ++ krb5_creds creds; ++ ++ /* Create two handles to the same memory ccache and destroy them. */ ++ kret = krb5_cc_resolve(context, "MEMORY:x", &id1); ++ CHECK(kret, "resolve 1"); ++ kret = krb5_cc_resolve(context, "MEMORY:x", &id2); ++ CHECK(kret, "resolve 2"); ++ kret = krb5_cc_destroy(context, id1); ++ CHECK(kret, "destroy 1"); ++ kret = krb5_cc_destroy(context, id2); ++ CHECK(kret, "destroy 2"); ++ ++ kret = init_test_cred(context); ++ CHECK(kret, "init_creds"); ++ ++ /* Reinitialize the cache after creating an iterator for it, and verify ++ * that the iterator ends gracefully. */ ++ kret = krb5_cc_resolve(context, "MEMORY:x", &id1); ++ CHECK(kret, "resolve"); ++ kret = krb5_cc_initialize(context, id1, test_creds.client); ++ CHECK(kret, "initialize"); ++ kret = krb5_cc_store_cred(context, id1, &test_creds); ++ CHECK(kret, "store"); ++ kret = krb5_cc_start_seq_get(context, id1, &cursor); ++ CHECK(kret, "start_seq_get"); ++ kret = krb5_cc_initialize(context, id1, test_creds.client); ++ CHECK(kret, "initialize again"); ++ kret = krb5_cc_next_cred(context, id1, &cursor, &creds); ++ CHECK_BOOL(kret != KRB5_CC_END, "iterator should end", "next_cred"); ++ kret = krb5_cc_end_seq_get(context, id1, &cursor); ++ CHECK(kret, "end_seq_get"); ++ kret = krb5_cc_destroy(context, id1); ++ CHECK(kret, "destroy"); ++ ++ free_test_cred(context); ++} ++ + extern const krb5_cc_ops krb5_mcc_ops; + extern const krb5_cc_ops krb5_fcc_ops; + +@@ -434,6 +483,8 @@ main(void) + do_test(context, "MEMORY:"); + do_test(context, "FILE:"); + ++ test_memory_concurrent(context); ++ + krb5_free_context(context); + return 0; + } diff --git a/krb5.spec b/krb5.spec index ae797b0..12f7d60 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 19%{?dist} +Release: 20%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -103,6 +103,7 @@ Patch83: Make-krb5kdc-p-affect-TCP-ports.patch Patch84: Remove-outdated-note-in-krb5kdc-man-page.patch Patch85: Fix-k5test-prompts-for-Python-3.patch Patch86: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch +Patch87: Fix-bugs-with-concurrent-use-of-MEMORY-ccaches.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -749,6 +750,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Oct 02 2018 Robbie Harwood - 1.16.1-20 +- Fix bugs with concurrent use of MEMORY ccaches + * Wed Aug 01 2018 Robbie Harwood - 1.16.1-19 - In FIPS mode, add plaintext fallback for RC4 usages and taint From 4a2dfb104c2f2bd84634e45b7713453488aa2da0 Mon Sep 17 00:00:00 2001 From: Adam Williamson Date: Tue, 9 Oct 2018 13:57:21 -0700 Subject: [PATCH 068/304] Revert the patch from -20 as it seems to make FreeIPA worse --- krb5.spec | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/krb5.spec b/krb5.spec index 12f7d60..9d0e2e7 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 20%{?dist} +Release: 21%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -103,7 +103,10 @@ Patch83: Make-krb5kdc-p-affect-TCP-ports.patch Patch84: Remove-outdated-note-in-krb5kdc-man-page.patch Patch85: Fix-k5test-prompts-for-Python-3.patch Patch86: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch -Patch87: Fix-bugs-with-concurrent-use-of-MEMORY-ccaches.patch +# Disabled for now as it seems to make things worse for FreeIPA +# (consistent crashes during server deployment, not just a crash +# in a later test): https://bugzilla.redhat.com/show_bug.cgi?id=1633089#c26 +#Patch87: Fix-bugs-with-concurrent-use-of-MEMORY-ccaches.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -750,6 +753,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Oct 09 2018 Adam Williamson - 1.16.1-21 +- Revert the patch from -20 for now as it seems to make FreeIPA worse + * Tue Oct 02 2018 Robbie Harwood - 1.16.1-20 - Fix bugs with concurrent use of MEMORY ccaches From 0eeac3abafaa9b064b5c05dc137ffbee7c485ec8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 15 Oct 2018 13:26:07 -0400 Subject: [PATCH 069/304] Prefer TCP to UDP for password changes Resolves: #1637611 --- ...ith-concurrent-use-of-MEMORY-ccaches.patch | 396 ------------------ Prefer-TCP-to-UDP-for-password-changes.patch | 168 ++++++++ krb5.spec | 11 +- 3 files changed, 174 insertions(+), 401 deletions(-) delete mode 100644 Fix-bugs-with-concurrent-use-of-MEMORY-ccaches.patch create mode 100644 Prefer-TCP-to-UDP-for-password-changes.patch diff --git a/Fix-bugs-with-concurrent-use-of-MEMORY-ccaches.patch b/Fix-bugs-with-concurrent-use-of-MEMORY-ccaches.patch deleted file mode 100644 index 085030a..0000000 --- a/Fix-bugs-with-concurrent-use-of-MEMORY-ccaches.patch +++ /dev/null @@ -1,396 +0,0 @@ -From f61875dc7da3d5dadb935ebcce25fe66564f7d0f Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sun, 1 Jul 2018 00:12:25 -0400 -Subject: [PATCH] Fix bugs with concurrent use of MEMORY ccaches - -A memory ccache iterator stores an alias into the cache object's -linked list of credentials. If the cache is reinitialized while the -iterator is active, the alias becomes invalid. Also, multiple handles -referencing the same memory ccache all use aliases to the same data -object; if one of the handles is destroyed, the other contains a -dangling pointer. - -Fix the first issue by adding a generation counter to the cache and to -cursors, incremented each time the cache is initialized or destroyed. -Check the generation on each cursor step and end the iteration if the -list was invalidated. Fix the second issue by adding a reference -count to the cache object, counting one reference for the table slot -and one for each open handle. Empty the cache object on each destroy -operation, but only release the object when the last handle to it is -destroyed or closed. - -Add regression tests for the two issues to t_cc.c. - -The first issue was reported by Sorin Manolache. - -ticket: 8202 -tags: pullup -target_version: 1.16-next -target_version: 1.15-next - -(cherry picked from commit 146dadec8fe7ccc4149eb2e3f577cc320aee6efb) ---- - src/lib/krb5/ccache/cc_memory.c | 164 ++++++++++++++++++++------------ - src/lib/krb5/ccache/t_cc.c | 51 ++++++++++ - 2 files changed, 154 insertions(+), 61 deletions(-) - -diff --git a/src/lib/krb5/ccache/cc_memory.c b/src/lib/krb5/ccache/cc_memory.c -index c5425eb3a..8cdaff7fb 100644 ---- a/src/lib/krb5/ccache/cc_memory.c -+++ b/src/lib/krb5/ccache/cc_memory.c -@@ -102,18 +102,20 @@ extern krb5_error_code krb5_change_cache (void); - typedef struct _krb5_mcc_link { - struct _krb5_mcc_link *next; - krb5_creds *creds; --} krb5_mcc_link, *krb5_mcc_cursor; -+} krb5_mcc_link; - - /* Per-cache data header. */ - typedef struct _krb5_mcc_data { - char *name; - k5_cc_mutex lock; - krb5_principal prin; -- krb5_mcc_cursor link; -+ krb5_mcc_link *link; - krb5_timestamp changetime; - /* Time offsets for clock-skewed clients. */ - krb5_int32 time_offset; - krb5_int32 usec_offset; -+ int refcount; /* One for the table slot, one per handle */ -+ int generation; /* Incremented at each initialize */ - } krb5_mcc_data; - - /* List of memory caches. */ -@@ -122,6 +124,12 @@ typedef struct krb5_mcc_list_node { - krb5_mcc_data *cache; - } krb5_mcc_list_node; - -+/* Iterator over credentials in a memory cache. */ -+struct mcc_cursor { -+ int generation; -+ krb5_mcc_link *next_link; -+}; -+ - /* Iterator over memory caches. */ - struct krb5_mcc_ptcursor_data { - struct krb5_mcc_list_node *cur; -@@ -132,7 +140,23 @@ static krb5_mcc_list_node *mcc_head = 0; - - static void update_mcc_change_time(krb5_mcc_data *); - --static void krb5_mcc_free (krb5_context context, krb5_ccache id); -+/* Remove creds from d, invalidate any existing cursors, and unset the client -+ * principal. The caller is responsible for locking. */ -+static void -+empty_mcc_cache(krb5_context context, krb5_mcc_data *d) -+{ -+ krb5_mcc_link *curr, *next; -+ -+ for (curr = d->link; curr != NULL; curr = next) { -+ next = curr->next; -+ krb5_free_creds(context, curr->creds); -+ free(curr); -+ } -+ d->link = NULL; -+ d->generation++; -+ krb5_free_principal(context, d->prin); -+ d->prin = NULL; -+} - - /* - * Modifies: -@@ -150,16 +174,12 @@ krb5_mcc_initialize(krb5_context context, krb5_ccache id, krb5_principal princ) - { - krb5_os_context os_ctx = &context->os_context; - krb5_error_code ret; -- krb5_mcc_data *d; -+ krb5_mcc_data *d = id->data; - -- d = (krb5_mcc_data *)id->data; - k5_cc_mutex_lock(context, &d->lock); -+ empty_mcc_cache(context, d); - -- krb5_mcc_free(context, id); -- -- d = (krb5_mcc_data *)id->data; -- ret = krb5_copy_principal(context, princ, -- &d->prin); -+ ret = krb5_copy_principal(context, princ, &d->prin); - update_mcc_change_time(d); - - if (os_ctx->os_flags & KRB5_OS_TOFFSET_VALID) { -@@ -185,61 +205,59 @@ krb5_mcc_initialize(krb5_context context, krb5_ccache id, krb5_principal princ) - krb5_error_code KRB5_CALLCONV - krb5_mcc_close(krb5_context context, krb5_ccache id) - { -+ krb5_mcc_data *d = id->data; -+ int count; -+ - free(id); -- return KRB5_OK; --} -- --static void --krb5_mcc_free(krb5_context context, krb5_ccache id) --{ -- krb5_mcc_cursor curr,next; -- krb5_mcc_data *d; -- -- d = (krb5_mcc_data *) id->data; -- for (curr = d->link; curr;) { -- krb5_free_creds(context, curr->creds); -- next = curr->next; -- free(curr); -- curr = next; -+ k5_cc_mutex_lock(context, &d->lock); -+ count = --d->refcount; -+ k5_cc_mutex_unlock(context, &d->lock); -+ if (count == 0) { -+ /* This is the last active handle referencing d and d has been removed -+ * from the table, so we can release it. */ -+ empty_mcc_cache(context, d); -+ free(d->name); -+ k5_cc_mutex_destroy(&d->lock); -+ free(d); - } -- d->link = NULL; -- krb5_free_principal(context, d->prin); -+ return KRB5_OK; - } - - /* - * Effects: - * Destroys the contents of id. id is invalid after call. -- * -- * Errors: -- * system errors (locks related) - */ - krb5_error_code KRB5_CALLCONV - krb5_mcc_destroy(krb5_context context, krb5_ccache id) - { - krb5_mcc_list_node **curr, *node; -- krb5_mcc_data *d; -+ krb5_mcc_data *d = id->data; -+ krb5_boolean removed_from_table = FALSE; - - k5_cc_mutex_lock(context, &krb5int_mcc_mutex); - -- d = (krb5_mcc_data *)id->data; - for (curr = &mcc_head; *curr; curr = &(*curr)->next) { - if ((*curr)->cache == d) { - node = *curr; - *curr = node->next; - free(node); -+ removed_from_table = TRUE; - break; - } - } - k5_cc_mutex_unlock(context, &krb5int_mcc_mutex); - -+ /* Empty the cache and remove the reference for the table slot. There will -+ * always be at least one reference left for the handle being destroyed. */ - k5_cc_mutex_lock(context, &d->lock); -- -- krb5_mcc_free(context, id); -- free(d->name); -+ empty_mcc_cache(context, d); -+ if (removed_from_table) -+ d->refcount--; - k5_cc_mutex_unlock(context, &d->lock); -- k5_cc_mutex_destroy(&d->lock); -- free(d); -- free(id); -+ -+ /* Invalidate the handle, possibly removing the last reference to d and -+ * freeing it. */ -+ krb5_mcc_close(context, id); - - krb5_change_cache (); - return KRB5_OK; -@@ -279,9 +297,12 @@ krb5_mcc_resolve (krb5_context context, krb5_ccache *id, const char *residual) - for (ptr = mcc_head; ptr; ptr=ptr->next) - if (!strcmp(ptr->cache->name, residual)) - break; -- if (ptr) -+ if (ptr != NULL) { - d = ptr->cache; -- else { -+ k5_cc_mutex_lock(context, &d->lock); -+ d->refcount++; -+ k5_cc_mutex_unlock(context, &d->lock); -+ } else { - err = new_mcc_data(residual, &d); - if (err) { - k5_cc_mutex_unlock(context, &krb5int_mcc_mutex); -@@ -326,14 +347,18 @@ krb5_error_code KRB5_CALLCONV - krb5_mcc_start_seq_get(krb5_context context, krb5_ccache id, - krb5_cc_cursor *cursor) - { -- krb5_mcc_cursor mcursor; -+ struct mcc_cursor *mcursor; - krb5_mcc_data *d; - -+ mcursor = malloc(sizeof(*mcursor)); -+ if (mcursor == NULL) -+ return KRB5_CC_NOMEM; - d = id->data; - k5_cc_mutex_lock(context, &d->lock); -- mcursor = d->link; -+ mcursor->generation = d->generation; -+ mcursor->next_link = d->link; - k5_cc_mutex_unlock(context, &d->lock); -- *cursor = (krb5_cc_cursor) mcursor; -+ *cursor = mcursor; - return KRB5_OK; - } - -@@ -361,23 +386,34 @@ krb5_error_code KRB5_CALLCONV - krb5_mcc_next_cred(krb5_context context, krb5_ccache id, - krb5_cc_cursor *cursor, krb5_creds *creds) - { -- krb5_mcc_cursor mcursor; -+ struct mcc_cursor *mcursor; - krb5_error_code retval; -+ krb5_mcc_data *d = id->data; - -- /* Once the node in the linked list is created, it's never -- modified, so we don't need to worry about locking here. (Note -- that we don't support _remove_cred.) */ -- mcursor = (krb5_mcc_cursor) *cursor; -- if (mcursor == NULL) -- return KRB5_CC_END; - memset(creds, 0, sizeof(krb5_creds)); -- if (mcursor->creds) { -- retval = k5_copy_creds_contents(context, mcursor->creds, creds); -- if (retval) -- return retval; -+ mcursor = *cursor; -+ if (mcursor->next_link == NULL) -+ return KRB5_CC_END; -+ -+ /* -+ * Check the cursor generation against the cache generation in case the -+ * cache has been reinitialized or destroyed, freeing the pointer in the -+ * cursor. Keep the cache locked while we copy the creds and advance the -+ * pointer, in case another thread reinitializes the cache after we check -+ * the generation. -+ */ -+ k5_cc_mutex_lock(context, &d->lock); -+ if (mcursor->generation != d->generation) { -+ k5_cc_mutex_unlock(context, &d->lock); -+ return KRB5_CC_END; - } -- *cursor = (krb5_cc_cursor)mcursor->next; -- return KRB5_OK; -+ -+ retval = k5_copy_creds_contents(context, mcursor->next_link->creds, creds); -+ if (retval == 0) -+ mcursor->next_link = mcursor->next_link->next; -+ -+ k5_cc_mutex_unlock(context, &d->lock); -+ return retval; - } - - /* -@@ -396,14 +432,18 @@ krb5_mcc_next_cred(krb5_context context, krb5_ccache id, - krb5_error_code KRB5_CALLCONV - krb5_mcc_end_seq_get(krb5_context context, krb5_ccache id, krb5_cc_cursor *cursor) - { -- *cursor = 0L; -+ free(*cursor); -+ *cursor = NULL; - return KRB5_OK; - } - --/* Utility routine: Creates the back-end data for a memory cache, and -- threads it into the global linked list. -- -- Call with the global list lock held. */ -+/* -+ * Utility routine: Creates the back-end data for a memory cache, and threads -+ * it into the global linked list. Give the new object two references, one for -+ * the table slot and one for the caller's handle. -+ * -+ * Call with the global list lock held. -+ */ - static krb5_error_code - new_mcc_data (const char *name, krb5_mcc_data **dataptr) - { -@@ -432,6 +472,8 @@ new_mcc_data (const char *name, krb5_mcc_data **dataptr) - d->changetime = 0; - d->time_offset = 0; - d->usec_offset = 0; -+ d->refcount = 2; -+ d->generation = 0; - update_mcc_change_time(d); - - n = malloc(sizeof(krb5_mcc_list_node)); -diff --git a/src/lib/krb5/ccache/t_cc.c b/src/lib/krb5/ccache/t_cc.c -index 6069cabd3..cd4569c4c 100644 ---- a/src/lib/krb5/ccache/t_cc.c -+++ b/src/lib/krb5/ccache/t_cc.c -@@ -386,6 +386,55 @@ test_misc(krb5_context context) - krb5_cc_dfl_ops = ops_save; - - } -+ -+/* -+ * Regression tests for #8202. Because memory ccaches share objects between -+ * different handles to the same cache and between iterators and caches, -+ * historically there have been some bugs when those objects are released. -+ */ -+static void -+test_memory_concurrent(krb5_context context) -+{ -+ krb5_error_code kret; -+ krb5_ccache id1, id2; -+ krb5_cc_cursor cursor; -+ krb5_creds creds; -+ -+ /* Create two handles to the same memory ccache and destroy them. */ -+ kret = krb5_cc_resolve(context, "MEMORY:x", &id1); -+ CHECK(kret, "resolve 1"); -+ kret = krb5_cc_resolve(context, "MEMORY:x", &id2); -+ CHECK(kret, "resolve 2"); -+ kret = krb5_cc_destroy(context, id1); -+ CHECK(kret, "destroy 1"); -+ kret = krb5_cc_destroy(context, id2); -+ CHECK(kret, "destroy 2"); -+ -+ kret = init_test_cred(context); -+ CHECK(kret, "init_creds"); -+ -+ /* Reinitialize the cache after creating an iterator for it, and verify -+ * that the iterator ends gracefully. */ -+ kret = krb5_cc_resolve(context, "MEMORY:x", &id1); -+ CHECK(kret, "resolve"); -+ kret = krb5_cc_initialize(context, id1, test_creds.client); -+ CHECK(kret, "initialize"); -+ kret = krb5_cc_store_cred(context, id1, &test_creds); -+ CHECK(kret, "store"); -+ kret = krb5_cc_start_seq_get(context, id1, &cursor); -+ CHECK(kret, "start_seq_get"); -+ kret = krb5_cc_initialize(context, id1, test_creds.client); -+ CHECK(kret, "initialize again"); -+ kret = krb5_cc_next_cred(context, id1, &cursor, &creds); -+ CHECK_BOOL(kret != KRB5_CC_END, "iterator should end", "next_cred"); -+ kret = krb5_cc_end_seq_get(context, id1, &cursor); -+ CHECK(kret, "end_seq_get"); -+ kret = krb5_cc_destroy(context, id1); -+ CHECK(kret, "destroy"); -+ -+ free_test_cred(context); -+} -+ - extern const krb5_cc_ops krb5_mcc_ops; - extern const krb5_cc_ops krb5_fcc_ops; - -@@ -434,6 +483,8 @@ main(void) - do_test(context, "MEMORY:"); - do_test(context, "FILE:"); - -+ test_memory_concurrent(context); -+ - krb5_free_context(context); - return 0; - } diff --git a/Prefer-TCP-to-UDP-for-password-changes.patch b/Prefer-TCP-to-UDP-for-password-changes.patch new file mode 100644 index 0000000..6df2bc1 --- /dev/null +++ b/Prefer-TCP-to-UDP-for-password-changes.patch @@ -0,0 +1,168 @@ +From dd40cfaf0eef43157afed58795e78de0bb7142eb Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 8 Oct 2018 16:02:12 -0400 +Subject: [PATCH] Prefer TCP to UDP for password changes + +When password changes are performed over UDP, spotty networks may +cause the client to retransmit. This leads to replay errors if the +kpasswd server receives both requests, which hide the actual request +status and make it appear that the password has not been changed, when +it may in fact have been. Use TCP instead with UDP fallback to avoid +this issue. + +ticket: 7905 +(cherry picked from commit d7b3018d338fc9c989c3fa17505870f23c3759a8) +--- + src/lib/krb5/os/changepw.c | 110 ++++++++++++++----------------------- + 1 file changed, 42 insertions(+), 68 deletions(-) + +diff --git a/src/lib/krb5/os/changepw.c b/src/lib/krb5/os/changepw.c +index e4db57084..9f968da7f 100644 +--- a/src/lib/krb5/os/changepw.c ++++ b/src/lib/krb5/os/changepw.c +@@ -59,13 +59,12 @@ struct sendto_callback_context { + + static krb5_error_code + locate_kpasswd(krb5_context context, const krb5_data *realm, +- struct serverlist *serverlist, krb5_boolean no_udp) ++ struct serverlist *serverlist) + { + krb5_error_code code; + + code = k5_locate_server(context, realm, serverlist, locate_service_kpasswd, +- no_udp); +- ++ FALSE); + if (code == KRB5_REALM_CANT_RESOLVE || code == KRB5_REALM_UNKNOWN) { + code = k5_locate_server(context, realm, serverlist, + locate_service_kadmin, TRUE); +@@ -76,7 +75,7 @@ locate_kpasswd(krb5_context context, const krb5_data *realm, + for (i = 0; i < serverlist->nservers; i++) { + struct server_entry *s = &serverlist->servers[i]; + +- if (!no_udp && s->transport == TCP) ++ if (s->transport == TCP) + s->transport = TCP_OR_UDP; + if (s->hostname != NULL) + s->port = DEFAULT_KPASSWD_PORT; +@@ -214,7 +213,6 @@ change_set_password(krb5_context context, + krb5_data *result_string) + { + krb5_data chpw_rep; +- krb5_boolean no_udp = FALSE; + GETSOCKNAME_ARG3_TYPE addrlen; + krb5_error_code code = 0; + char *code_string; +@@ -246,73 +244,49 @@ change_set_password(krb5_context context, + callback_ctx.remote_seq_num = callback_ctx.auth_context->remote_seq_number; + callback_ctx.local_seq_num = callback_ctx.auth_context->local_seq_number; + +- do { +- k5_transport_strategy strategy = no_udp ? NO_UDP : UDP_FIRST; ++ code = locate_kpasswd(callback_ctx.context, &creds->server->realm, &sl); ++ if (code) ++ goto cleanup; + +- code = locate_kpasswd(callback_ctx.context, &creds->server->realm, &sl, +- no_udp); ++ addrlen = sizeof(remote_addr); ++ ++ callback_info.data = &callback_ctx; ++ callback_info.pfn_callback = kpasswd_sendto_msg_callback; ++ callback_info.pfn_cleanup = kpasswd_sendto_msg_cleanup; ++ krb5_free_data_contents(callback_ctx.context, &chpw_rep); ++ ++ code = k5_sendto(callback_ctx.context, NULL, &creds->server->realm, ++ &sl, UDP_LAST, &callback_info, &chpw_rep, ++ ss2sa(&remote_addr), &addrlen, NULL, NULL, NULL); ++ if (code) ++ goto cleanup; ++ ++ code = krb5int_rd_chpw_rep(callback_ctx.context, ++ callback_ctx.auth_context, ++ &chpw_rep, &local_result_code, ++ result_string); ++ ++ if (code) ++ goto cleanup; ++ ++ if (result_code) ++ *result_code = local_result_code; ++ ++ if (result_code_string) { ++ code = krb5_chpw_result_code_string(callback_ctx.context, ++ local_result_code, ++ &code_string); + if (code) +- break; ++ goto cleanup; + +- addrlen = sizeof(remote_addr); +- +- callback_info.data = &callback_ctx; +- callback_info.pfn_callback = kpasswd_sendto_msg_callback; +- callback_info.pfn_cleanup = kpasswd_sendto_msg_cleanup; +- krb5_free_data_contents(callback_ctx.context, &chpw_rep); +- +- code = k5_sendto(callback_ctx.context, NULL, &creds->server->realm, +- &sl, strategy, &callback_info, &chpw_rep, +- ss2sa(&remote_addr), &addrlen, NULL, NULL, NULL); +- if (code) { +- /* +- * Here we may want to switch to TCP on some errors. +- * right? +- */ +- break; ++ result_code_string->length = strlen(code_string); ++ result_code_string->data = malloc(result_code_string->length); ++ if (result_code_string->data == NULL) { ++ code = ENOMEM; ++ goto cleanup; + } +- +- code = krb5int_rd_chpw_rep(callback_ctx.context, +- callback_ctx.auth_context, +- &chpw_rep, &local_result_code, +- result_string); +- +- if (code) { +- if (code == KRB5KRB_ERR_RESPONSE_TOO_BIG && !no_udp) { +- k5_free_serverlist(&sl); +- no_udp = 1; +- continue; +- } +- +- break; +- } +- +- if (result_code) +- *result_code = local_result_code; +- +- if (result_code_string) { +- code = krb5_chpw_result_code_string(callback_ctx.context, +- local_result_code, +- &code_string); +- if (code) +- goto cleanup; +- +- result_code_string->length = strlen(code_string); +- result_code_string->data = malloc(result_code_string->length); +- if (result_code_string->data == NULL) { +- code = ENOMEM; +- goto cleanup; +- } +- strncpy(result_code_string->data, code_string, result_code_string->length); +- } +- +- if (code == KRB5KRB_ERR_RESPONSE_TOO_BIG && !no_udp) { +- k5_free_serverlist(&sl); +- no_udp = 1; +- } else { +- break; +- } +- } while (TRUE); ++ strncpy(result_code_string->data, code_string, result_code_string->length); ++ } + + cleanup: + if (callback_ctx.auth_context != NULL) diff --git a/krb5.spec b/krb5.spec index 9d0e2e7..0de5b73 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 21%{?dist} +Release: 22%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -103,10 +103,7 @@ Patch83: Make-krb5kdc-p-affect-TCP-ports.patch Patch84: Remove-outdated-note-in-krb5kdc-man-page.patch Patch85: Fix-k5test-prompts-for-Python-3.patch Patch86: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch -# Disabled for now as it seems to make things worse for FreeIPA -# (consistent crashes during server deployment, not just a crash -# in a later test): https://bugzilla.redhat.com/show_bug.cgi?id=1633089#c26 -#Patch87: Fix-bugs-with-concurrent-use-of-MEMORY-ccaches.patch +Patch87: Prefer-TCP-to-UDP-for-password-changes.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -753,6 +750,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Oct 15 2018 Robbie Harwood - 1.16.1-22 +- Prefer TCP to UDP for password changes +- Resolves: #1637611 + * Tue Oct 09 2018 Adam Williamson - 1.16.1-21 - Revert the patch from -20 for now as it seems to make FreeIPA worse From c0ac611ad390c1bc20f30a80ea1fef7abbf8478e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 17 Oct 2018 13:49:20 -0400 Subject: [PATCH 070/304] Correct kpasswd_server description in krb5.conf(5) Resolves: #1640272 --- ...wd_server-description-in-krb5.conf-5.patch | 28 +++++++++++++++++++ krb5.spec | 7 ++++- 2 files changed, 34 insertions(+), 1 deletion(-) create mode 100644 Correct-kpasswd_server-description-in-krb5.conf-5.patch diff --git a/Correct-kpasswd_server-description-in-krb5.conf-5.patch b/Correct-kpasswd_server-description-in-krb5.conf-5.patch new file mode 100644 index 0000000..07e10d1 --- /dev/null +++ b/Correct-kpasswd_server-description-in-krb5.conf-5.patch @@ -0,0 +1,28 @@ +From c5d97d45431509fe972ce24fed2429027221b0ec Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 16 Oct 2018 17:32:29 -0400 +Subject: [PATCH] Correct kpasswd_server description in krb5.conf(5) + +ticket: 8754 (new) +tags: pullup +target_version: 1.16-next + +(cherry picked from commit 762d804701f78fc76f728ec05a205eea6a2b2dd7) +--- + doc/admin/conf_files/krb5_conf.rst | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index eb5c29e5d..f5139244b 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -523,7 +523,8 @@ following tags may be specified in the realm's subsection: + + **kpasswd_server** + Points to the server where all the password changes are performed. +- If there is no such entry, the port 464 on the **admin_server** ++ If there is no such entry, DNS will be queried (unless forbidden ++ by **dns_lookup_kdc**). Finally, port 464 on the **admin_server** + host will be tried. + + **master_kdc** diff --git a/krb5.spec b/krb5.spec index 0de5b73..4aea62d 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 22%{?dist} +Release: 23%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -104,6 +104,7 @@ Patch84: Remove-outdated-note-in-krb5kdc-man-page.patch Patch85: Fix-k5test-prompts-for-Python-3.patch Patch86: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch Patch87: Prefer-TCP-to-UDP-for-password-changes.patch +Patch88: Correct-kpasswd_server-description-in-krb5.conf-5.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -750,6 +751,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Oct 17 2018 Robbie Harwood - 1.16.1-23 +- Correct kpasswd_server description in krb5.conf(5) +- Resolves: #1640272 + * Mon Oct 15 2018 Robbie Harwood - 1.16.1-22 - Prefer TCP to UDP for password changes - Resolves: #1637611 From d760ebeab2fa146bd3a6ea581efc0834a1920a50 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 17 Oct 2018 15:27:45 -0400 Subject: [PATCH 071/304] Use port-sockets.h macros in cc_kcm, sendto_kdc Resolves: #1631998 --- ...IPE-from-socket-writes-on-UNIX-likes.patch | 86 +++++++++++ ...ockets.h-macros-in-cc_kcm-sendto_kdc.patch | 138 ++++++++++++++++++ krb5.spec | 8 +- 3 files changed, 231 insertions(+), 1 deletion(-) create mode 100644 Prevent-SIGPIPE-from-socket-writes-on-UNIX-likes.patch create mode 100644 Use-port-sockets.h-macros-in-cc_kcm-sendto_kdc.patch diff --git a/Prevent-SIGPIPE-from-socket-writes-on-UNIX-likes.patch b/Prevent-SIGPIPE-from-socket-writes-on-UNIX-likes.patch new file mode 100644 index 0000000..d8238ba --- /dev/null +++ b/Prevent-SIGPIPE-from-socket-writes-on-UNIX-likes.patch @@ -0,0 +1,86 @@ +From 23e01e9a966ee0aa08668a75f5753a55e1ea4547 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 12 Oct 2018 16:57:05 -0400 +Subject: [PATCH] Prevent SIGPIPE from socket writes on UNIX-likes + +When writing to a disconnected socket, try to only get EPIPE rather +than taking down the process with SIGPIPE. + +On recent Linux and other systems which have it, switch from writev to +sendmsg and pass MSG_NOSIGNAL. + +On BSD-likes, set SO_NOSIGPIPE at connect time. + +ticket: 8753 (new) +(cherry picked from commit 98bf22027bd6e746f456a671ca5e257ca4bd371e) +--- + src/include/port-sockets.h | 43 +++++++++++++++++++++++++++++++++++--- + 1 file changed, 40 insertions(+), 3 deletions(-) + +diff --git a/src/include/port-sockets.h b/src/include/port-sockets.h +index b3ab9c906..3b05e022d 100644 +--- a/src/include/port-sockets.h ++++ b/src/include/port-sockets.h +@@ -158,6 +158,7 @@ typedef int socklen_t; + #include /* For struct sockaddr_in and in_addr */ + #include /* For inet_ntoa */ + #include ++#include /* For memset */ + + #ifndef HAVE_NETDB_H_H_ERRNO + extern int h_errno; /* In case it's missing, e.g., HP-UX 10.20. */ +@@ -218,15 +219,51 @@ typedef struct iovec sg_buf; + #define SOCKET_NFDS(f) ((f)+1) /* select() arg for a single fd */ + #define SOCKET_READ read + #define SOCKET_WRITE write +-#define SOCKET_CONNECT connect ++static inline int ++socket_connect(int fd, const struct sockaddr *addr, socklen_t addrlen) ++{ ++ int st; ++#ifdef SO_NOSIGPIPE ++ int set = 1; ++#endif ++ ++ st = connect(fd, addr, addrlen); ++ if (st == -1) ++ return st; ++ ++#ifdef SO_NOSIGPIPE ++ st = setsockopt(fd, SOL_SOCKET, SO_NOSIGPIPE, &set, sizeof(set)); ++ if (st != 0) ++ st = -1; ++#endif ++ ++ return st; ++} ++#define SOCKET_CONNECT socket_connect + #define SOCKET_GETSOCKNAME getsockname + #define SOCKET_CLOSE close + #define SOCKET_EINTR EINTR + #define SOCKET_WRITEV_TEMP int ++static inline ssize_t ++socket_sendmsg(SOCKET fd, sg_buf *iov, int iovcnt) ++{ ++ struct msghdr msg; ++ int flags = 0; ++ ++#ifdef MSG_NOSIGNAL ++ flags |= MSG_NOSIGNAL; ++#endif ++ ++ memset(&msg, 0, sizeof(msg)); ++ msg.msg_iov = iov; ++ msg.msg_iovlen = iovcnt; ++ ++ return sendmsg(fd, &msg, flags); ++} + /* Use TMP to avoid compiler warnings and keep things consistent with + * Windows version. */ +-#define SOCKET_WRITEV(FD, SG, LEN, TMP) \ +- ((TMP) = writev((FD), (SG), (LEN)), (TMP)) ++#define SOCKET_WRITEV(FD, SG, LEN, TMP) \ ++ ((TMP) = socket_sendmsg((FD), (SG), (LEN)), (TMP)) + + #define SHUTDOWN_READ 0 + #define SHUTDOWN_WRITE 1 diff --git a/Use-port-sockets.h-macros-in-cc_kcm-sendto_kdc.patch b/Use-port-sockets.h-macros-in-cc_kcm-sendto_kdc.patch new file mode 100644 index 0000000..56b83c3 --- /dev/null +++ b/Use-port-sockets.h-macros-in-cc_kcm-sendto_kdc.patch @@ -0,0 +1,138 @@ +From 76fc514d3d00b8ac9f7844ade35c08eaa7c8a1fc Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 15 Oct 2018 19:12:45 -0400 +Subject: [PATCH] Use port-sockets.h macros in cc_kcm, sendto_kdc + +Use SOCKET_CONNECT in cc_kcm.c and sendto_kdc.c to prevent SIGPIPE on +BSD-like systems. Use other port-sockets.h macros in cc_kcm.c in case +it is ever used on Windows. + +ticket: 8753 +(cherry picked from commit 2aaf0e74805e295358627ac1e5d589d625d8e6b0) +--- + src/lib/krb5/ccache/cc_kcm.c | 34 ++++++++++++++++++---------------- + src/lib/krb5/os/sendto_kdc.c | 3 ++- + 2 files changed, 20 insertions(+), 17 deletions(-) + +diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c +index a777f2710..b260cd81b 100644 +--- a/src/lib/krb5/ccache/cc_kcm.c ++++ b/src/lib/krb5/ccache/cc_kcm.c +@@ -42,6 +42,7 @@ + #include "k5-input.h" + #include "cc-int.h" + #include "kcm.h" ++#include "../os/os-proto.h" + #include + #include + #ifdef __APPLE__ +@@ -61,7 +62,7 @@ struct uuid_list { + }; + + struct kcmio { +- int fd; ++ SOCKET fd; + #ifdef __APPLE__ + mach_port_t mport; + #endif +@@ -252,7 +253,7 @@ static krb5_error_code + kcmio_unix_socket_connect(krb5_context context, struct kcmio *io) + { + krb5_error_code ret; +- int fd = -1; ++ SOCKET fd = INVALID_SOCKET; + struct sockaddr_un addr; + char *path = NULL; + +@@ -267,25 +268,25 @@ kcmio_unix_socket_connect(krb5_context context, struct kcmio *io) + } + + fd = socket(AF_UNIX, SOCK_STREAM, 0); +- if (fd == -1) { +- ret = errno; ++ if (fd == INVALID_SOCKET) { ++ ret = SOCKET_ERRNO; + goto cleanup; + } + + memset(&addr, 0, sizeof(addr)); + addr.sun_family = AF_UNIX; + strlcpy(addr.sun_path, path, sizeof(addr.sun_path)); +- if (connect(fd, (struct sockaddr *)&addr, sizeof(addr)) != 0) { +- ret = (errno == ENOENT) ? KRB5_KCM_NO_SERVER : errno; ++ if (SOCKET_CONNECT(fd, (struct sockaddr *)&addr, sizeof(addr)) != 0) { ++ ret = (SOCKET_ERRNO == ENOENT) ? KRB5_KCM_NO_SERVER : SOCKET_ERRNO; + goto cleanup; + } + + io->fd = fd; +- fd = -1; ++ fd = INVALID_SOCKET; + + cleanup: +- if (fd != -1) +- close(fd); ++ if (fd != INVALID_SOCKET) ++ closesocket(fd); + profile_release_string(path); + return ret; + } +@@ -297,11 +298,12 @@ kcmio_unix_socket_write(krb5_context context, struct kcmio *io, void *request, + size_t len) + { + char lenbytes[4]; ++ sg_buf sg[2]; + ++ SG_SET(&sg[0], lenbytes, sizeof(lenbytes)); ++ SG_SET(&sg[1], request, len); + store_32_be(len, lenbytes); +- if (krb5_net_write(context, io->fd, lenbytes, 4) < 0) +- return errno; +- if (krb5_net_write(context, io->fd, request, len) < 0) ++ if (krb5int_net_writev(context, io->fd, sg, 2) < 0) + return errno; + return 0; + } +@@ -358,7 +360,7 @@ kcmio_connect(krb5_context context, struct kcmio **io_out) + io = calloc(1, sizeof(*io)); + if (io == NULL) + return ENOMEM; +- io->fd = -1; ++ io->fd = INVALID_SOCKET; + + /* Try Mach RPC (macOS only), then fall back to Unix domain sockets */ + ret = kcmio_mach_connect(context, io); +@@ -384,7 +386,7 @@ kcmio_call(krb5_context context, struct kcmio *io, struct kcmreq *req) + if (k5_buf_status(&req->reqbuf) != 0) + return ENOMEM; + +- if (io->fd != -1) { ++ if (io->fd != INVALID_SOCKET) { + ret = kcmio_unix_socket_write(context, io, req->reqbuf.data, + req->reqbuf.len); + if (ret) +@@ -411,8 +413,8 @@ kcmio_close(struct kcmio *io) + { + if (io != NULL) { + kcmio_mach_close(io); +- if (io->fd != -1) +- close(io->fd); ++ if (io->fd != INVALID_SOCKET) ++ closesocket(io->fd); + free(io); + } + } +diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c +index e8bc0ad6e..0ed6b1d70 100644 +--- a/src/lib/krb5/os/sendto_kdc.c ++++ b/src/lib/krb5/os/sendto_kdc.c +@@ -880,7 +880,8 @@ start_connection(krb5_context context, struct conn_state *state, + } + + /* Start connecting to KDC. */ +- e = connect(fd, (struct sockaddr *)&state->addr.saddr, state->addr.len); ++ e = SOCKET_CONNECT(fd, (struct sockaddr *)&state->addr.saddr, ++ state->addr.len); + if (e != 0) { + /* + * This is the path that should be followed for non-blocking diff --git a/krb5.spec b/krb5.spec index 4aea62d..abfc7fd 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 23%{?dist} +Release: 24%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -105,6 +105,8 @@ Patch85: Fix-k5test-prompts-for-Python-3.patch Patch86: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch Patch87: Prefer-TCP-to-UDP-for-password-changes.patch Patch88: Correct-kpasswd_server-description-in-krb5.conf-5.patch +Patch89: Prevent-SIGPIPE-from-socket-writes-on-UNIX-likes.patch +Patch90: Use-port-sockets.h-macros-in-cc_kcm-sendto_kdc.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -751,6 +753,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Oct 17 2018 Robbie Harwood - 1.16.1-24 +- Use port-sockets.h macros in cc_kcm, sendto_kdc +- Resolves: #1631998 + * Wed Oct 17 2018 Robbie Harwood - 1.16.1-23 - Correct kpasswd_server description in krb5.conf(5) - Resolves: #1640272 From 3ce8c381c3ff4ade017facaa4f935ef62c8a6021 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 24 Oct 2018 15:07:14 -0400 Subject: [PATCH 072/304] Update man pages to reference kerberos(7) Resolves: #1143767 --- Bring-back-general-kerberos-man-page.patch | 468 +++++++++++++++++ Modernize-kerberos-7.patch | 429 ++++++++++++++++ ...te-man-pages-to-reference-kerberos-7.patch | 476 ++++++++++++++++++ krb5.spec | 9 +- 4 files changed, 1381 insertions(+), 1 deletion(-) create mode 100644 Bring-back-general-kerberos-man-page.patch create mode 100644 Modernize-kerberos-7.patch create mode 100644 Update-man-pages-to-reference-kerberos-7.patch diff --git a/Bring-back-general-kerberos-man-page.patch b/Bring-back-general-kerberos-man-page.patch new file mode 100644 index 0000000..65a9966 --- /dev/null +++ b/Bring-back-general-kerberos-man-page.patch @@ -0,0 +1,468 @@ +From 67653084e8770fe4af4e06848452e83dc37b7ade Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 9 Oct 2018 17:05:10 -0400 +Subject: [PATCH] Bring back general kerberos man page + +Restore the content of kerberos(1) as it stood in +0f81e372a2830c9170f6e08dfa956841d0ebdfb1. Convert to ReST to match +the other man pages, and install it as the more appropriate +kerberos(7). + +Build kerberos(7) and check it in to avoid breaking the build. + +ticket: 8755 (new) +tags: pullup +target_version: 1.16-next + +(cherry picked from commit c38197ee9808503f86ccffd4a2bd94389e17df0b) +--- + doc/conf.py | 1 + + doc/user/user_config/index.rst | 1 + + doc/user/user_config/kerberos.rst | 148 ++++++++++++++++++++++++ + src/Makefile.in | 4 +- + src/config/pre.in | 2 + + src/man/Makefile.in | 14 ++- + src/man/kerberos.man | 180 ++++++++++++++++++++++++++++++ + 7 files changed, 345 insertions(+), 5 deletions(-) + create mode 100644 doc/user/user_config/kerberos.rst + create mode 100644 src/man/kerberos.man + +diff --git a/doc/conf.py b/doc/conf.py +index 0555808e6..f8bf588b6 100644 +--- a/doc/conf.py ++++ b/doc/conf.py +@@ -292,6 +292,7 @@ man_pages = [ + ('user/user_commands/krb5-config', 'krb5-config', u'tool for linking against MIT Kerberos libraries', [u'MIT'], 1), + ('user/user_config/k5login', 'k5login', u'Kerberos V5 acl file for host access', [u'MIT'], 5), + ('user/user_config/k5identity', 'k5identity', u'Kerberos V5 client principal selection rules', [u'MIT'], 5), ++ ('user/user_config/kerberos', 'kerberos', u'Overview of using Kerberos', [u'MIT'], 7), + ('admin/admin_commands/krb5kdc', 'krb5kdc', u'Kerberos V5 KDC', [u'MIT'], 8), + ('admin/admin_commands/kadmin_local', 'kadmin', u'Kerberos V5 database administration program', [u'MIT'], 1), + ('admin/admin_commands/kprop', 'kprop', u'propagate a Kerberos V5 principal database to a slave server', [u'MIT'], 8), +diff --git a/doc/user/user_config/index.rst b/doc/user/user_config/index.rst +index 6b3d4393b..ad0dc1a72 100644 +--- a/doc/user/user_config/index.rst ++++ b/doc/user/user_config/index.rst +@@ -8,5 +8,6 @@ been disabled by your host's configuration): + .. toctree:: + :maxdepth: 1 + ++ kerberos.rst + k5login.rst + k5identity.rst +diff --git a/doc/user/user_config/kerberos.rst b/doc/user/user_config/kerberos.rst +new file mode 100644 +index 000000000..6c4453b3b +--- /dev/null ++++ b/doc/user/user_config/kerberos.rst +@@ -0,0 +1,148 @@ ++.. _kerberos(7): ++ ++kerberos ++======== ++ ++DESCRIPTION ++----------- ++ ++The Kerberos system authenticates individual users in a network ++environment. After authenticating yourself to Kerberos, you can use ++Kerberos-enabled programs without having to present passwords. ++ ++If you enter your username and :ref:`kinit(1)` responds with this ++message: ++ ++kinit(v5): Client not found in Kerberos database while getting initial ++credentials ++ ++you haven't been registered as a Kerberos user. See your system ++administrator. ++ ++A Kerberos name usually contains three parts. The first is the ++**primary**, which is usually a user's or service's name. The second ++is the **instance**, which in the case of a user is usually null. ++Some users may have privileged instances, however, such as ``root`` or ++``admin``. In the case of a service, the instance is the fully ++qualified name of the machine on which it runs; i.e. there can be an ++rlogin service running on the machine ABC, which is different from the ++rlogin service running on the machine XYZ. The third part of a ++Kerberos name is the **realm**. The realm corresponds to the Kerberos ++service providing authentication for the principal. ++ ++When writing a Kerberos name, the principal name is separated from the ++instance (if not null) by a slash, and the realm (if not the local ++realm) follows, preceded by an "@" sign. The following are examples ++of valid Kerberos names:: ++ ++ david ++ jennifer/admin ++ joeuser@BLEEP.COM ++ cbrown/root@FUBAR.ORG ++ ++When you authenticate yourself with Kerberos you get an initial ++Kerberos **ticket**. (A Kerberos ticket is an encrypted protocol ++message that provides authentication.) Kerberos uses this ticket for ++network utilities such as rlogin and rcp. The ticket transactions are ++done transparently, so you don't have to worry about their management. ++ ++Note, however, that tickets expire. Privileged tickets, such as those ++with the instance ``root``, expire in a few minutes, while tickets ++that carry more ordinary privileges may be good for several hours or a ++day, depending on the installation's policy. If your login session ++extends beyond the time limit, you will have to re-authenticate ++yourself to Kerberos to get new tickets. Use the :ref:`kinit(1)` ++command to re-authenticate yourself. ++ ++If you use the kinit command to get your tickets, make sure you use ++the kdestroy command to destroy your tickets before you end your login ++session. You should put the kdestroy command in your ``.logout`` file ++so that your tickets will be destroyed automatically when you logout. ++For more information about the kinit and kdestroy commands, see the ++:ref:`kinit(1)` and :ref:`kdestroy(1)` manual pages. ++ ++Kerberos tickets can be forwarded. In order to forward tickets, you ++must request **forwardable** tickets when you kinit. Once you have ++forwardable tickets, most Kerberos programs have a command line option ++to forward them to the remote host. ++ ++ENVIRONMENT VARIABLES ++--------------------- ++ ++Several environment variables affect the operation of Kerberos-enabled ++programs. These inclide: ++ ++**KRB5CCNAME** ++ Specifies the location of the credential cache, in the form ++ *TYPE*:*residual*. If no *type* prefix is present, the **FILE** ++ type is assumed and *residual* is the pathname of the cache file. ++ A collection of multiple caches may be used by specifying the ++ **dir** type and the pathname of a private directory (which must ++ already exist). The default cache file is /tmp/krb5cc_*uid*, ++ where *uid* is the decimal user ID of the user. ++ ++**KRB5_KTNAME** ++ Specifies the location of the keytab file, in the form ++ *TYPE*:*residual*. If no *type* is present, the **FILE** type is ++ assumed and *residual* is the pathname of the keytab file. The ++ default keytab file is ``/etc/krb5.keytab``. ++ ++**KRB5_CONFIG** ++ Specifies the location of the Kerberos configuration file. The ++ default is ``/etc/krb5.conf``. ++ ++**KRB5_KDC_PROFILE** ++ Specifies the location of the KDC configuration file, which ++ contains additional configuration directives for the Key ++ Distribution Center daemon and associated programs. The default ++ is ``/usr/local/var/krb5kdc/kdc.conf``. ++ ++**KRB5RCACHETYPE** ++ Specifies the default type of replay cache to use for servers. ++ Valid types include **dfl** for the normal file type and **none** ++ for no replay cache. ++ ++**KRB5RCACHEDIR** ++ Specifies the default directory for replay caches used by servers. ++ The default is the value of the **TMPDIR** environment variable, ++ or ``/var/tmp`` if **TMPDIR** is not set. ++ ++**KRB5_TRACE** ++ Specifies a filename to write trace log output to. Trace logs can ++ help illuminate decisions made internally by the Kerberos ++ libraries. The default is not to write trace log output anywhere. ++ ++Most environment variables are disabled for certain programs, such as ++login system programs and setuid programs, which are designed to be ++secure when run within an untrusted process environment. ++ ++SEE ALSO ++-------- ++ ++:ref:`kdestroy(1)`, :ref:`kinit(1)`, :ref:`klist(1)`, ++:ref:`kswitch(1)`, :ref:`kpasswd(1)`, :ref:`ksu(1)`, ++:ref:`krb5.conf(5)`, :ref:`kdc.conf(5)`, :ref:`kadmin(1)`, ++:ref:`kadmind(8)`, :ref:`kdb5_util(8)`, :ref:`krb5kdc(8)` ++ ++BUGS ++---- ++ ++AUTHORS ++------- ++ ++| Steve Miller, MIT Project Athena/Digital Equipment Corporation ++| Clifford Neuman, MIT Project Athena ++| Greg Hudson, MIT Kerberos Consortium ++ ++HISTORY ++------- ++ ++The MIT Kerberos 5 implementation was developed at MIT, with ++contributions from many outside parties. It is currently maintained ++by the MIT Kerberos Consortium. ++ ++RESTRICTIONS ++------------ ++ ++Copyright 1985, 1986, 1989-1996, 2002, 2011 Masachusetts Institute of ++Technology +diff --git a/src/Makefile.in b/src/Makefile.in +index 79b8d5f98..745cbc497 100644 +--- a/src/Makefile.in ++++ b/src/Makefile.in +@@ -62,9 +62,9 @@ world: + INSTALLMKDIRS = $(KRB5ROOT) $(KRB5MANROOT) $(KRB5OTHERMKDIRS) \ + $(ADMIN_BINDIR) $(SERVER_BINDIR) $(CLIENT_BINDIR) \ + $(ADMIN_MANDIR) $(SERVER_MANDIR) $(CLIENT_MANDIR) \ +- $(FILE_MANDIR) \ ++ $(FILE_MANDIR) $(OVERVIEW_MANDIR) \ + $(ADMIN_CATDIR) $(SERVER_CATDIR) $(CLIENT_CATDIR) \ +- $(FILE_CATDIR) \ ++ $(FILE_CATDIR) $(OVERVIEW_CATDIR) \ + $(KRB5_LIBDIR) $(KRB5_INCDIR) \ + $(KRB5_DB_MODULE_DIR) $(KRB5_PA_MODULE_DIR) \ + $(KRB5_AD_MODULE_DIR) \ +diff --git a/src/config/pre.in b/src/config/pre.in +index 6317d3564..42bccf14c 100644 +--- a/src/config/pre.in ++++ b/src/config/pre.in +@@ -210,6 +210,8 @@ ADMIN_CATDIR = $(KRB5MANROOT)/cat8 + SERVER_CATDIR = $(KRB5MANROOT)/cat8 + CLIENT_CATDIR = $(KRB5MANROOT)/cat1 + FILE_CATDIR = $(KRB5MANROOT)/cat5 ++OVERVIEW_MANDIR = $(KRB5MANROOT)/man7 ++OVERVIEW_CATDIR = $(KRB5MANROOT)/cat7 + KRB5_LIBDIR = @libdir@ + KRB5_INCDIR = @includedir@ + MODULE_DIR = @libdir@/krb5/plugins +diff --git a/src/man/Makefile.in b/src/man/Makefile.in +index 4bc670bad..e3722b1cd 100644 +--- a/src/man/Makefile.in ++++ b/src/man/Makefile.in +@@ -15,7 +15,7 @@ MANSUBS=k5identity.sub k5login.sub k5srvutil.sub kadm5.acl.sub kadmin.sub \ + kadmind.sub kdb5_ldap_util.sub kdb5_util.sub kdc.conf.sub \ + kdestroy.sub kinit.sub klist.sub kpasswd.sub kprop.sub kpropd.sub \ + kproplog.sub krb5.conf.sub krb5-config.sub krb5kdc.sub ksu.sub \ +- kswitch.sub ktutil.sub kvno.sub sclient.sub sserver.sub ++ kswitch.sub ktutil.sub kvno.sub sclient.sub sserver.sub kerberos.sub + + docsrc=$(top_srcdir)/../doc + +@@ -56,9 +56,11 @@ all: $(MANSUBS) + clean: + rm -rf $(MANSUBS) rst_man + +-install: install-clientman install-fileman install-adminman install-serverman ++install: install-clientman install-fileman install-adminman \ ++ install-overviewman install-serverman + +-install-catman: install-clientcat install-filecat install-admincat install-servercat ++install-catman: install-clientcat install-filecat install-admincat \ ++ install-overviewcat install-servercat + + install-clientman: + $(INSTALL_DATA) k5srvutil.sub $(DESTDIR)$(CLIENT_MANDIR)/k5srvutil.1 +@@ -85,6 +87,9 @@ install-fileman: + $(INSTALL_DATA) kdc.conf.sub $(DESTDIR)$(FILE_MANDIR)/kdc.conf.5 + $(INSTALL_DATA) krb5.conf.sub $(DESTDIR)$(FILE_MANDIR)/krb5.conf.5 + ++install-overviewman: ++ $(INSTALL_DATA) kerberos.sub $(DESTDIR)$(OVERVIEW_MANDIR)/kerberos.7 ++ + install-adminman: + $(INSTALL_DATA) $(srcdir)/kadmin.local.8 \ + $(DESTDIR)$(ADMIN_MANDIR)/kadmin.local.8 +@@ -127,6 +132,9 @@ install-filecat: + $(GROFF_MAN) kdc.conf.sub > $(DESTDIR)$(FILE_CATDIR)/kdc.conf.5 + $(GROFF_MAN) krb5.conf.sub > $(DESTDIR)$(FILE_CATDIR)/krb5.conf.5 + ++install-overviewcat: ++ $(GROFF_MAN) kerberos.sub > $(DESTDIR)$(OVERVIEW_CATDIR)/kerberos.7 ++ + install-admincat: + ($(RM) $(DESTDIR)$(ADMIN_CATDIR)/kadmin.local.8; \ + $(LN_S) $(CLIENT_CATDIR)/kadmin.1 \ +diff --git a/src/man/kerberos.man b/src/man/kerberos.man +new file mode 100644 +index 000000000..7b2b5d932 +--- /dev/null ++++ b/src/man/kerberos.man +@@ -0,0 +1,180 @@ ++.\" Man page generated from reStructuredText. ++. ++.TH "KERBEROS" "7" " " "1.17" "MIT Kerberos" ++.SH NAME ++kerberos \- Overview of using Kerberos ++. ++.nr rst2man-indent-level 0 ++. ++.de1 rstReportMargin ++\\$1 \\n[an-margin] ++level \\n[rst2man-indent-level] ++level margin: \\n[rst2man-indent\\n[rst2man-indent-level]] ++- ++\\n[rst2man-indent0] ++\\n[rst2man-indent1] ++\\n[rst2man-indent2] ++.. ++.de1 INDENT ++.\" .rstReportMargin pre: ++. RS \\$1 ++. nr rst2man-indent\\n[rst2man-indent-level] \\n[an-margin] ++. nr rst2man-indent-level +1 ++.\" .rstReportMargin post: ++.. ++.de UNINDENT ++. RE ++.\" indent \\n[an-margin] ++.\" old: \\n[rst2man-indent\\n[rst2man-indent-level]] ++.nr rst2man-indent-level -1 ++.\" new: \\n[rst2man-indent\\n[rst2man-indent-level]] ++.in \\n[rst2man-indent\\n[rst2man-indent-level]]u ++.. ++.SH DESCRIPTION ++.sp ++The Kerberos system authenticates individual users in a network ++environment. After authenticating yourself to Kerberos, you can use ++Kerberos\-enabled programs without having to present passwords. ++.sp ++If you enter your username and kinit(1) responds with this ++message: ++.sp ++kinit(v5): Client not found in Kerberos database while getting initial ++credentials ++.sp ++you haven\(aqt been registered as a Kerberos user. See your system ++administrator. ++.sp ++A Kerberos name usually contains three parts. The first is the ++\fBprimary\fP, which is usually a user\(aqs or service\(aqs name. The second ++is the \fBinstance\fP, which in the case of a user is usually null. ++Some users may have privileged instances, however, such as \fBroot\fP or ++\fBadmin\fP\&. In the case of a service, the instance is the fully ++qualified name of the machine on which it runs; i.e. there can be an ++rlogin service running on the machine ABC, which is different from the ++rlogin service running on the machine XYZ. The third part of a ++Kerberos name is the \fBrealm\fP\&. The realm corresponds to the Kerberos ++service providing authentication for the principal. ++.sp ++When writing a Kerberos name, the principal name is separated from the ++instance (if not null) by a slash, and the realm (if not the local ++realm) follows, preceded by an "@" sign. The following are examples ++of valid Kerberos names: ++.INDENT 0.0 ++.INDENT 3.5 ++.sp ++.nf ++.ft C ++david ++jennifer/admin ++joeuser@BLEEP.COM ++cbrown/root@FUBAR.ORG ++.ft P ++.fi ++.UNINDENT ++.UNINDENT ++.sp ++When you authenticate yourself with Kerberos you get an initial ++Kerberos \fBticket\fP\&. (A Kerberos ticket is an encrypted protocol ++message that provides authentication.) Kerberos uses this ticket for ++network utilities such as rlogin and rcp. The ticket transactions are ++done transparently, so you don\(aqt have to worry about their management. ++.sp ++Note, however, that tickets expire. Privileged tickets, such as those ++with the instance \fBroot\fP, expire in a few minutes, while tickets ++that carry more ordinary privileges may be good for several hours or a ++day, depending on the installation\(aqs policy. If your login session ++extends beyond the time limit, you will have to re\-authenticate ++yourself to Kerberos to get new tickets. Use the kinit(1) ++command to re\-authenticate yourself. ++.sp ++If you use the kinit command to get your tickets, make sure you use ++the kdestroy command to destroy your tickets before you end your login ++session. You should put the kdestroy command in your \fB\&.logout\fP file ++so that your tickets will be destroyed automatically when you logout. ++For more information about the kinit and kdestroy commands, see the ++kinit(1) and kdestroy(1) manual pages. ++.sp ++Kerberos tickets can be forwarded. In order to forward tickets, you ++must request \fBforwardable\fP tickets when you kinit. Once you have ++forwardable tickets, most Kerberos programs have a command line option ++to forward them to the remote host. ++.SH ENVIRONMENT VARIABLES ++.sp ++Several environment variables affect the operation of Kerberos\-enabled ++programs. These inclide: ++.INDENT 0.0 ++.TP ++\fBKRB5CCNAME\fP ++Specifies the location of the credential cache, in the form ++\fITYPE\fP:\fIresidual\fP\&. If no \fItype\fP prefix is present, the \fBFILE\fP ++type is assumed and \fIresidual\fP is the pathname of the cache file. ++A collection of multiple caches may be used by specifying the ++\fBdir\fP type and the pathname of a private directory (which must ++already exist). The default cache file is /tmp/krb5cc_*uid*, ++where \fIuid\fP is the decimal user ID of the user. ++.TP ++\fBKRB5_KTNAME\fP ++Specifies the location of the keytab file, in the form ++\fITYPE\fP:\fIresidual\fP\&. If no \fItype\fP is present, the \fBFILE\fP type is ++assumed and \fIresidual\fP is the pathname of the keytab file. The ++default keytab file is \fB/etc/krb5.keytab\fP\&. ++.TP ++\fBKRB5_CONFIG\fP ++Specifies the location of the Kerberos configuration file. The ++default is \fB/etc/krb5.conf\fP\&. ++.TP ++\fBKRB5_KDC_PROFILE\fP ++Specifies the location of the KDC configuration file, which ++contains additional configuration directives for the Key ++Distribution Center daemon and associated programs. The default ++is \fB/usr/local/var/krb5kdc/kdc.conf\fP\&. ++.TP ++\fBKRB5RCACHETYPE\fP ++Specifies the default type of replay cache to use for servers. ++Valid types include \fBdfl\fP for the normal file type and \fBnone\fP ++for no replay cache. ++.TP ++\fBKRB5RCACHEDIR\fP ++Specifies the default directory for replay caches used by servers. ++The default is the value of the \fBTMPDIR\fP environment variable, ++or \fB/var/tmp\fP if \fBTMPDIR\fP is not set. ++.TP ++\fBKRB5_TRACE\fP ++Specifies a filename to write trace log output to. Trace logs can ++help illuminate decisions made internally by the Kerberos ++libraries. The default is not to write trace log output anywhere. ++.UNINDENT ++.sp ++Most environment variables are disabled for certain programs, such as ++login system programs and setuid programs, which are designed to be ++secure when run within an untrusted process environment. ++.SH SEE ALSO ++.sp ++kdestroy(1), kinit(1), klist(1), ++kswitch(1), kpasswd(1), ksu(1), ++krb5.conf(5), kdc.conf(5), kadmin(1), ++kadmind(8), kdb5_util(8), krb5kdc(8) ++.SH BUGS ++.SH AUTHORS ++.nf ++Steve Miller, MIT Project Athena/Digital Equipment Corporation ++Clifford Neuman, MIT Project Athena ++Greg Hudson, MIT Kerberos Consortium ++.fi ++.sp ++.SH HISTORY ++.sp ++The MIT Kerberos 5 implementation was developed at MIT, with ++contributions from many outside parties. It is currently maintained ++by the MIT Kerberos Consortium. ++.SH RESTRICTIONS ++.sp ++Copyright 1985, 1986, 1989\-1996, 2002, 2011 Masachusetts Institute of ++Technology ++.SH AUTHOR ++MIT ++.SH COPYRIGHT ++1985-2018, MIT ++.\" Generated by docutils manpage writer. ++. diff --git a/Modernize-kerberos-7.patch b/Modernize-kerberos-7.patch new file mode 100644 index 0000000..f82b878 --- /dev/null +++ b/Modernize-kerberos-7.patch @@ -0,0 +1,429 @@ +From a6baae6bfddb5a56c64e19e5bff9f0455dc89e53 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 15 Oct 2018 13:20:30 -0400 +Subject: [PATCH] Modernize kerberos(7) + +Update environment variable descriptions, using env_variables.rst as a +guide. Replace the content in env_variables.rst with a pointer to +documentation at kerberos(7) so that we don't break external links and +don't duplicate content. + +Replace references to rlogin. Clarify and modernize other language. + +ticket: 8755 +(cherry picked from commit cdccdefa2d74d3abf5a8ae126e423af9d467d34f) +--- + doc/admin/env_variables.rst | 44 +------------ + doc/user/user_config/kerberos.rst | 106 ++++++++++++++++++------------ + src/man/kerberos.man | 104 +++++++++++++++++------------ + 3 files changed, 128 insertions(+), 126 deletions(-) + +diff --git a/doc/admin/env_variables.rst b/doc/admin/env_variables.rst +index 0c146d3e3..a2d15bea8 100644 +--- a/doc/admin/env_variables.rst ++++ b/doc/admin/env_variables.rst +@@ -1,46 +1,4 @@ + Environment variables + ===================== + +-The following environment variables can be used during runtime: +- +-**KRB5_CONFIG** +- Main Kerberos configuration file. Multiple filenames can be +- specified, separated by a colon; all files which are present will +- be read. (See :ref:`mitK5defaults` for the default path.) +- +-**KRB5_KDC_PROFILE** +- KDC configuration file. (See :ref:`mitK5defaults` for the default +- name.) +- +-**KRB5_KTNAME** +- Default keytab file name. (See :ref:`mitK5defaults` for the +- default name.) +- +-**KRB5_CLIENT_KTNAME** +- Default client keytab file name. (See :ref:`mitK5defaults` for +- the default name.) +- +-**KRB5CCNAME** +- Default name for the credentials cache file, in the form *type*\:\ +- *residual*. The type of the default cache may determine the +- availability of a cache collection. For instance, a default cache +- of type ``DIR`` causes caches within the directory to be present +- in the global cache collection. +- +-**KRB5RCACHETYPE** +- Default replay cache type. Defaults to ``dfl``. A value of +- ``none`` disables the replay cache. +- +-**KRB5RCACHEDIR** +- Default replay cache directory. (See :ref:`mitK5defaults` for the +- default location.) +- +-**KPROP_PORT** +- :ref:`kprop(8)` port to use. Defaults to 754. +- +-**KRB5_TRACE** +- Filename for trace-logging output (introduced in release 1.9). +- For example, ``env KRB5_TRACE=/dev/stdout kinit`` would send +- tracing information for kinit to ``/dev/stdout``. Some programs +- may ignore this variable (particularly setuid or login system +- programs). ++This content has moved to :ref:`kerberos(7)`. +diff --git a/doc/user/user_config/kerberos.rst b/doc/user/user_config/kerberos.rst +index 6c4453b3b..56412f099 100644 +--- a/doc/user/user_config/kerberos.rst ++++ b/doc/user/user_config/kerberos.rst +@@ -8,12 +8,12 @@ DESCRIPTION + + The Kerberos system authenticates individual users in a network + environment. After authenticating yourself to Kerberos, you can use +-Kerberos-enabled programs without having to present passwords. ++Kerberos-enabled programs without having to present passwords or ++certificates to those programs. + +-If you enter your username and :ref:`kinit(1)` responds with this +-message: ++If you receive the following response from :ref:`kinit(1)`: + +-kinit(v5): Client not found in Kerberos database while getting initial ++kinit: Client not found in Kerberos database while getting initial + credentials + + you haven't been registered as a Kerberos user. See your system +@@ -25,10 +25,13 @@ is the **instance**, which in the case of a user is usually null. + Some users may have privileged instances, however, such as ``root`` or + ``admin``. In the case of a service, the instance is the fully + qualified name of the machine on which it runs; i.e. there can be an +-rlogin service running on the machine ABC, which is different from the +-rlogin service running on the machine XYZ. The third part of a +-Kerberos name is the **realm**. The realm corresponds to the Kerberos +-service providing authentication for the principal. ++ssh service running on the machine ABC (ssh/ABC@REALM), which is ++different from the ssh service running on the machine XYZ ++(ssh/XYZ@REALM). The third part of a Kerberos name is the **realm**. ++The realm corresponds to the Kerberos service providing authentication ++for the principal. Realms are conventionally all-uppercase, and often ++match the end of hostnames in the realm (for instance, host01.example.com ++might be in realm EXAMPLE.COM). + + When writing a Kerberos name, the principal name is separated from the + instance (if not null) by a slash, and the realm (if not the local +@@ -43,64 +46,72 @@ of valid Kerberos names:: + When you authenticate yourself with Kerberos you get an initial + Kerberos **ticket**. (A Kerberos ticket is an encrypted protocol + message that provides authentication.) Kerberos uses this ticket for +-network utilities such as rlogin and rcp. The ticket transactions are +-done transparently, so you don't have to worry about their management. ++network utilities such as ssh. The ticket transactions are done ++transparently, so you don't have to worry about their management. + +-Note, however, that tickets expire. Privileged tickets, such as those +-with the instance ``root``, expire in a few minutes, while tickets +-that carry more ordinary privileges may be good for several hours or a +-day, depending on the installation's policy. If your login session +-extends beyond the time limit, you will have to re-authenticate +-yourself to Kerberos to get new tickets. Use the :ref:`kinit(1)` +-command to re-authenticate yourself. ++Note, however, that tickets expire. Administrators may configure more ++privileged tickets, such as those with service or instance of ``root`` ++or ``admin``, to expire in a few minutes, while tickets that carry ++more ordinary privileges may be good for several hours or a day. If ++your login session extends beyond the time limit, you will have to ++re-authenticate yourself to Kerberos to get new tickets using the ++:ref:`kinit(1)` command. + +-If you use the kinit command to get your tickets, make sure you use +-the kdestroy command to destroy your tickets before you end your login +-session. You should put the kdestroy command in your ``.logout`` file +-so that your tickets will be destroyed automatically when you logout. +-For more information about the kinit and kdestroy commands, see the +-:ref:`kinit(1)` and :ref:`kdestroy(1)` manual pages. ++Some tickets are **renewable** beyond their initial lifetime. This ++means that ``kinit -R`` can extend their lifetime without requiring ++you to re-authenticate. ++ ++If you wish to delete your local tickets, use the :ref:`kdestroy(1)` ++command. + + Kerberos tickets can be forwarded. In order to forward tickets, you + must request **forwardable** tickets when you kinit. Once you have + forwardable tickets, most Kerberos programs have a command line option +-to forward them to the remote host. ++to forward them to the remote host. This can be useful for, e.g., ++running kinit on your local machine and then sshing into another to do ++work. Note that this should not be done on untrusted machines since ++they will then have your tickets. + + ENVIRONMENT VARIABLES + --------------------- + + Several environment variables affect the operation of Kerberos-enabled +-programs. These inclide: ++programs. These include: + + **KRB5CCNAME** +- Specifies the location of the credential cache, in the form +- *TYPE*:*residual*. If no *type* prefix is present, the **FILE** +- type is assumed and *residual* is the pathname of the cache file. +- A collection of multiple caches may be used by specifying the +- **dir** type and the pathname of a private directory (which must +- already exist). The default cache file is /tmp/krb5cc_*uid*, +- where *uid* is the decimal user ID of the user. ++ Default name for the credentials cache file, in the form ++ *TYPE*:*residual*. The type of the default cache may determine ++ the availability of a cache collection. ``FILE`` is not a ++ collection type; ``KEYRING``, ``DIR``, and ``KCM`` are. ++ ++ If not set, the value of **default_ccache_name** from ++ configuration files (see **KRB5_CONFIG**) will be used. If that ++ is also not set, the default *type* is ``FILE``, and the ++ *residual* is the path /tmp/krb5cc_*uid*, where *uid* is the ++ decimal user ID of the user. + + **KRB5_KTNAME** +- Specifies the location of the keytab file, in the form ++ Specifies the location of the default keytab file, in the form + *TYPE*:*residual*. If no *type* is present, the **FILE** type is +- assumed and *residual* is the pathname of the keytab file. The +- default keytab file is ``/etc/krb5.keytab``. ++ assumed and *residual* is the pathname of the keytab file. If ++ unset, |keytab| will be used. + + **KRB5_CONFIG** + Specifies the location of the Kerberos configuration file. The +- default is ``/etc/krb5.conf``. ++ default is |sysconfdir|\ ``/krb5.conf``. Multiple filenames can ++ be specified, separated by a colon; all files which are present ++ will be read. + + **KRB5_KDC_PROFILE** + Specifies the location of the KDC configuration file, which + contains additional configuration directives for the Key + Distribution Center daemon and associated programs. The default +- is ``/usr/local/var/krb5kdc/kdc.conf``. ++ is |kdcdir|\ ``/kdc.conf``. + + **KRB5RCACHETYPE** + Specifies the default type of replay cache to use for servers. +- Valid types include **dfl** for the normal file type and **none** +- for no replay cache. ++ Valid types include ``dfl`` for the normal file type and ``none`` ++ for no replay cache. The default is ``dfl``. + + **KRB5RCACHEDIR** + Specifies the default directory for replay caches used by servers. +@@ -110,7 +121,17 @@ programs. These inclide: + **KRB5_TRACE** + Specifies a filename to write trace log output to. Trace logs can + help illuminate decisions made internally by the Kerberos +- libraries. The default is not to write trace log output anywhere. ++ libraries. For example, ``env KRB5_TRACE=/dev/stderr kinit`` ++ would send tracing information for :ref:`kinit(1)` to ++ ``/dev/stderr``. The default is not to write trace log output ++ anywhere. ++ ++**KRB5_CLIENT_KTNAME** ++ Default client keytab file name. If unset, |ckeytab| will be ++ used). ++ ++**KPROP_PORT** ++ :ref:`kprop(8)` port to use. Defaults to 754. + + Most environment variables are disabled for certain programs, such as + login system programs and setuid programs, which are designed to be +@@ -133,6 +154,7 @@ AUTHORS + | Steve Miller, MIT Project Athena/Digital Equipment Corporation + | Clifford Neuman, MIT Project Athena + | Greg Hudson, MIT Kerberos Consortium ++| Robbie Harwood, Red Hat, Inc. + + HISTORY + ------- +@@ -144,5 +166,5 @@ by the MIT Kerberos Consortium. + RESTRICTIONS + ------------ + +-Copyright 1985, 1986, 1989-1996, 2002, 2011 Masachusetts Institute of +-Technology ++Copyright 1985, 1986, 1989-1996, 2002, 2011, 2018 Masachusetts ++Institute of Technology +diff --git a/src/man/kerberos.man b/src/man/kerberos.man +index 7b2b5d932..026f4604a 100644 +--- a/src/man/kerberos.man ++++ b/src/man/kerberos.man +@@ -34,12 +34,12 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]] + .sp + The Kerberos system authenticates individual users in a network + environment. After authenticating yourself to Kerberos, you can use +-Kerberos\-enabled programs without having to present passwords. ++Kerberos\-enabled programs without having to present passwords or ++certificates to those programs. + .sp +-If you enter your username and kinit(1) responds with this +-message: ++If you receive the following response from kinit(1): + .sp +-kinit(v5): Client not found in Kerberos database while getting initial ++kinit: Client not found in Kerberos database while getting initial + credentials + .sp + you haven\(aqt been registered as a Kerberos user. See your system +@@ -51,10 +51,13 @@ is the \fBinstance\fP, which in the case of a user is usually null. + Some users may have privileged instances, however, such as \fBroot\fP or + \fBadmin\fP\&. In the case of a service, the instance is the fully + qualified name of the machine on which it runs; i.e. there can be an +-rlogin service running on the machine ABC, which is different from the +-rlogin service running on the machine XYZ. The third part of a +-Kerberos name is the \fBrealm\fP\&. The realm corresponds to the Kerberos +-service providing authentication for the principal. ++ssh service running on the machine ABC (\fI\%ssh/ABC@REALM\fP), which is ++different from the ssh service running on the machine XYZ ++(\fI\%ssh/XYZ@REALM\fP). The third part of a Kerberos name is the \fBrealm\fP\&. ++The realm corresponds to the Kerberos service providing authentication ++for the principal. Realms are conventionally all\-uppercase, and often ++match the end of hostnames in the realm (for instance, host01.example.com ++might be in realm EXAMPLE.COM). + .sp + When writing a Kerberos name, the principal name is separated from the + instance (if not null) by a slash, and the realm (if not the local +@@ -77,63 +80,71 @@ cbrown/root@FUBAR.ORG + When you authenticate yourself with Kerberos you get an initial + Kerberos \fBticket\fP\&. (A Kerberos ticket is an encrypted protocol + message that provides authentication.) Kerberos uses this ticket for +-network utilities such as rlogin and rcp. The ticket transactions are +-done transparently, so you don\(aqt have to worry about their management. ++network utilities such as ssh. The ticket transactions are done ++transparently, so you don\(aqt have to worry about their management. + .sp +-Note, however, that tickets expire. Privileged tickets, such as those +-with the instance \fBroot\fP, expire in a few minutes, while tickets +-that carry more ordinary privileges may be good for several hours or a +-day, depending on the installation\(aqs policy. If your login session +-extends beyond the time limit, you will have to re\-authenticate +-yourself to Kerberos to get new tickets. Use the kinit(1) +-command to re\-authenticate yourself. ++Note, however, that tickets expire. Administrators may configure more ++privileged tickets, such as those with service or instance of \fBroot\fP ++or \fBadmin\fP, to expire in a few minutes, while tickets that carry ++more ordinary privileges may be good for several hours or a day. If ++your login session extends beyond the time limit, you will have to ++re\-authenticate yourself to Kerberos to get new tickets using the ++kinit(1) command. + .sp +-If you use the kinit command to get your tickets, make sure you use +-the kdestroy command to destroy your tickets before you end your login +-session. You should put the kdestroy command in your \fB\&.logout\fP file +-so that your tickets will be destroyed automatically when you logout. +-For more information about the kinit and kdestroy commands, see the +-kinit(1) and kdestroy(1) manual pages. ++Some tickets are \fBrenewable\fP beyond their initial lifetime. This ++means that \fBkinit \-R\fP can extend their lifetime without requiring ++you to re\-authenticate. ++.sp ++If you wish to delete your local tickets, use the kdestroy(1) ++command. + .sp + Kerberos tickets can be forwarded. In order to forward tickets, you + must request \fBforwardable\fP tickets when you kinit. Once you have + forwardable tickets, most Kerberos programs have a command line option +-to forward them to the remote host. ++to forward them to the remote host. This can be useful for, e.g., ++running kinit on your local machine and then sshing into another to do ++work. Note that this should not be done on untrusted machines since ++they will then have your tickets. + .SH ENVIRONMENT VARIABLES + .sp + Several environment variables affect the operation of Kerberos\-enabled +-programs. These inclide: ++programs. These include: + .INDENT 0.0 + .TP + \fBKRB5CCNAME\fP +-Specifies the location of the credential cache, in the form +-\fITYPE\fP:\fIresidual\fP\&. If no \fItype\fP prefix is present, the \fBFILE\fP +-type is assumed and \fIresidual\fP is the pathname of the cache file. +-A collection of multiple caches may be used by specifying the +-\fBdir\fP type and the pathname of a private directory (which must +-already exist). The default cache file is /tmp/krb5cc_*uid*, +-where \fIuid\fP is the decimal user ID of the user. ++Default name for the credentials cache file, in the form ++\fITYPE\fP:\fIresidual\fP\&. The type of the default cache may determine ++the availability of a cache collection. \fBFILE\fP is not a ++collection type; \fBKEYRING\fP, \fBDIR\fP, and \fBKCM\fP are. ++.sp ++If not set, the value of \fBdefault_ccache_name\fP from ++configuration files (see \fBKRB5_CONFIG\fP) will be used. If that ++is also not set, the default \fItype\fP is \fBFILE\fP, and the ++\fIresidual\fP is the path /tmp/krb5cc_*uid*, where \fIuid\fP is the ++decimal user ID of the user. + .TP + \fBKRB5_KTNAME\fP +-Specifies the location of the keytab file, in the form ++Specifies the location of the default keytab file, in the form + \fITYPE\fP:\fIresidual\fP\&. If no \fItype\fP is present, the \fBFILE\fP type is +-assumed and \fIresidual\fP is the pathname of the keytab file. The +-default keytab file is \fB/etc/krb5.keytab\fP\&. ++assumed and \fIresidual\fP is the pathname of the keytab file. If ++unset, \fB@KTNAME@\fP will be used. + .TP + \fBKRB5_CONFIG\fP + Specifies the location of the Kerberos configuration file. The +-default is \fB/etc/krb5.conf\fP\&. ++default is \fB@SYSCONFDIR@\fP\fB/krb5.conf\fP\&. Multiple filenames can ++be specified, separated by a colon; all files which are present ++will be read. + .TP + \fBKRB5_KDC_PROFILE\fP + Specifies the location of the KDC configuration file, which + contains additional configuration directives for the Key + Distribution Center daemon and associated programs. The default +-is \fB/usr/local/var/krb5kdc/kdc.conf\fP\&. ++is \fB@LOCALSTATEDIR@\fP\fB/krb5kdc\fP\fB/kdc.conf\fP\&. + .TP + \fBKRB5RCACHETYPE\fP + Specifies the default type of replay cache to use for servers. + Valid types include \fBdfl\fP for the normal file type and \fBnone\fP +-for no replay cache. ++for no replay cache. The default is \fBdfl\fP\&. + .TP + \fBKRB5RCACHEDIR\fP + Specifies the default directory for replay caches used by servers. +@@ -143,7 +154,17 @@ or \fB/var/tmp\fP if \fBTMPDIR\fP is not set. + \fBKRB5_TRACE\fP + Specifies a filename to write trace log output to. Trace logs can + help illuminate decisions made internally by the Kerberos +-libraries. The default is not to write trace log output anywhere. ++libraries. For example, \fBenv KRB5_TRACE=/dev/stderr kinit\fP ++would send tracing information for kinit(1) to ++\fB/dev/stderr\fP\&. The default is not to write trace log output ++anywhere. ++.TP ++\fBKRB5_CLIENT_KTNAME\fP ++Default client keytab file name. If unset, \fB@CKTNAME@\fP will be ++used). ++.TP ++\fBKPROP_PORT\fP ++kprop(8) port to use. Defaults to 754. + .UNINDENT + .sp + Most environment variables are disabled for certain programs, such as +@@ -161,6 +182,7 @@ kadmind(8), kdb5_util(8), krb5kdc(8) + Steve Miller, MIT Project Athena/Digital Equipment Corporation + Clifford Neuman, MIT Project Athena + Greg Hudson, MIT Kerberos Consortium ++Robbie Harwood, Red Hat, Inc. + .fi + .sp + .SH HISTORY +@@ -170,8 +192,8 @@ contributions from many outside parties. It is currently maintained + by the MIT Kerberos Consortium. + .SH RESTRICTIONS + .sp +-Copyright 1985, 1986, 1989\-1996, 2002, 2011 Masachusetts Institute of +-Technology ++Copyright 1985, 1986, 1989\-1996, 2002, 2011, 2018 Masachusetts ++Institute of Technology + .SH AUTHOR + MIT + .SH COPYRIGHT diff --git a/Update-man-pages-to-reference-kerberos-7.patch b/Update-man-pages-to-reference-kerberos-7.patch new file mode 100644 index 0000000..50dcf83 --- /dev/null +++ b/Update-man-pages-to-reference-kerberos-7.patch @@ -0,0 +1,476 @@ +From 92984a6d7208ceab384d5a21d03de08b4cb4c8d8 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 15 Oct 2018 15:19:12 -0400 +Subject: [PATCH] Update man pages to reference kerberos(7) + +Remove broken references to old kerberos(1). Reference kerberos(7) +from all man pages, and create/update their environment section so +that it references kerberos(7). + +ticket: 8755 +(cherry picked from commit 52cbe198d0d6f0085d4653b2f6a1ecc84d139118) +[rharwood@redhat.com: conflicts: kvno doesn't have u2u yet, git derped +on kswitch] +--- + doc/admin/admin_commands/k5srvutil.rst | 9 ++++++++- + doc/admin/admin_commands/kadmin_local.rst | 9 ++++++++- + doc/admin/admin_commands/kadmind.rst | 9 ++++++++- + doc/admin/admin_commands/kdb5_ldap_util.rst | 9 ++++++++- + doc/admin/admin_commands/kdb5_util.rst | 9 ++++++++- + doc/admin/admin_commands/kprop.rst | 8 ++++---- + doc/admin/admin_commands/kpropd.rst | 10 +++++++++- + doc/admin/admin_commands/kproplog.rst | 7 +++---- + doc/admin/admin_commands/krb5kdc.rst | 8 +++----- + doc/admin/admin_commands/ktutil.rst | 9 ++++++++- + doc/admin/admin_commands/sserver.rst | 9 ++++++++- + doc/user/user_commands/kdestroy.rst | 13 +++---------- + doc/user/user_commands/kinit.rst | 14 +++----------- + doc/user/user_commands/klist.rst | 13 +++---------- + doc/user/user_commands/kpasswd.rst | 9 ++++++++- + doc/user/user_commands/krb5-config.rst | 2 +- + doc/user/user_commands/ksu.rst | 13 +++++++++++++ + doc/user/user_commands/kswitch.rst | 14 ++++---------- + doc/user/user_commands/kvno.rst | 9 +++------ + doc/user/user_commands/sclient.rst | 8 +++++++- + 20 files changed, 120 insertions(+), 71 deletions(-) + +diff --git a/doc/admin/admin_commands/k5srvutil.rst b/doc/admin/admin_commands/k5srvutil.rst +index b873d9077..79502cf9e 100644 +--- a/doc/admin/admin_commands/k5srvutil.rst ++++ b/doc/admin/admin_commands/k5srvutil.rst +@@ -56,7 +56,14 @@ k5srvutil uses the :ref:`kadmin(1)` program to edit the keytab in + place. + + ++ENVIRONMENT ++----------- ++ ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. ++ ++ + SEE ALSO + -------- + +-:ref:`kadmin(1)`, :ref:`ktutil(1)` ++:ref:`kadmin(1)`, :ref:`ktutil(1)`, :ref:`kerberos(7)` +diff --git a/doc/admin/admin_commands/kadmin_local.rst b/doc/admin/admin_commands/kadmin_local.rst +index 9b5ccf4e9..cefe6054b 100644 +--- a/doc/admin/admin_commands/kadmin_local.rst ++++ b/doc/admin/admin_commands/kadmin_local.rst +@@ -996,7 +996,14 @@ The kadmin program was originally written by Tom Yu at MIT, as an + interface to the OpenVision Kerberos administration program. + + ++ENVIRONMENT ++----------- ++ ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. ++ ++ + SEE ALSO + -------- + +-:ref:`kpasswd(1)`, :ref:`kadmind(8)` ++:ref:`kpasswd(1)`, :ref:`kadmind(8)`, :ref:`kerberos(7)` +diff --git a/doc/admin/admin_commands/kadmind.rst b/doc/admin/admin_commands/kadmind.rst +index f5b7733ea..8bfb48a32 100644 +--- a/doc/admin/admin_commands/kadmind.rst ++++ b/doc/admin/admin_commands/kadmind.rst +@@ -116,8 +116,15 @@ OPTIONS + ` in :ref:`kadmin(1)` for supported arguments. + + ++ENVIRONMENT ++----------- ++ ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. ++ ++ + SEE ALSO + -------- + + :ref:`kpasswd(1)`, :ref:`kadmin(1)`, :ref:`kdb5_util(8)`, +-:ref:`kdb5_ldap_util(8)`, :ref:`kadm5.acl(5)` ++:ref:`kdb5_ldap_util(8)`, :ref:`kadm5.acl(5)`, :ref:`kerberos(7)` +diff --git a/doc/admin/admin_commands/kdb5_ldap_util.rst b/doc/admin/admin_commands/kdb5_ldap_util.rst +index cbf313f55..343df4dd9 100644 +--- a/doc/admin/admin_commands/kdb5_ldap_util.rst ++++ b/doc/admin/admin_commands/kdb5_ldap_util.rst +@@ -456,7 +456,14 @@ Example:: + .. _kdb5_ldap_util_list_policy_end: + + ++ENVIRONMENT ++----------- ++ ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. ++ ++ + SEE ALSO + -------- + +-:ref:`kadmin(1)` ++:ref:`kadmin(1)`, :ref:`kerberos(7)` +diff --git a/doc/admin/admin_commands/kdb5_util.rst b/doc/admin/admin_commands/kdb5_util.rst +index 258498f0d..18a3fb627 100644 +--- a/doc/admin/admin_commands/kdb5_util.rst ++++ b/doc/admin/admin_commands/kdb5_util.rst +@@ -491,7 +491,14 @@ Examples:: + bar@EXAMPLE.COM 1 1 des-cbc-crc normal -1 + + ++ENVIRONMENT ++----------- ++ ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. ++ ++ + SEE ALSO + -------- + +-:ref:`kadmin(1)` ++:ref:`kadmin(1)`, :ref:`kerberos(7)` +diff --git a/doc/admin/admin_commands/kprop.rst b/doc/admin/admin_commands/kprop.rst +index 726c8cc2f..0bc353239 100644 +--- a/doc/admin/admin_commands/kprop.rst ++++ b/doc/admin/admin_commands/kprop.rst +@@ -49,12 +49,12 @@ OPTIONS + ENVIRONMENT + ----------- + +-*kprop* uses the following environment variable: +- +-* **KRB5_CONFIG** ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. + + + SEE ALSO + -------- + +-:ref:`kpropd(8)`, :ref:`kdb5_util(8)`, :ref:`krb5kdc(8)` ++:ref:`kpropd(8)`, :ref:`kdb5_util(8)`, :ref:`krb5kdc(8)`, ++:ref:`kerberos(7)` +diff --git a/doc/admin/admin_commands/kpropd.rst b/doc/admin/admin_commands/kpropd.rst +index 5468b0675..03aa8ce90 100644 +--- a/doc/admin/admin_commands/kpropd.rst ++++ b/doc/admin/admin_commands/kpropd.rst +@@ -129,7 +129,15 @@ kpropd.acl + will allow Kerberos database propagation via :ref:`kprop(8)`. + + ++ENVIRONMENT ++----------- ++ ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. ++ ++ + SEE ALSO + -------- + +-:ref:`kprop(8)`, :ref:`kdb5_util(8)`, :ref:`krb5kdc(8)`, inetd(8) ++:ref:`kprop(8)`, :ref:`kdb5_util(8)`, :ref:`krb5kdc(8)`, ++:ref:`kerberos(7)`, inetd(8) +diff --git a/doc/admin/admin_commands/kproplog.rst b/doc/admin/admin_commands/kproplog.rst +index ed906398d..b98e1b29b 100644 +--- a/doc/admin/admin_commands/kproplog.rst ++++ b/doc/admin/admin_commands/kproplog.rst +@@ -74,12 +74,11 @@ OPTIONS + ENVIRONMENT + ----------- + +-kproplog uses the following environment variables: +- +-* **KRB5_KDC_PROFILE** ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. + + + SEE ALSO + -------- + +-:ref:`kpropd(8)` ++:ref:`kpropd(8)`, :ref:`kerberos(7)` +diff --git a/doc/admin/admin_commands/krb5kdc.rst b/doc/admin/admin_commands/krb5kdc.rst +index b605b563d..0342d0d18 100644 +--- a/doc/admin/admin_commands/krb5kdc.rst ++++ b/doc/admin/admin_commands/krb5kdc.rst +@@ -103,14 +103,12 @@ description for further details. + ENVIRONMENT + ----------- + +-krb5kdc uses the following environment variables: +- +-* **KRB5_CONFIG** +-* **KRB5_KDC_PROFILE** ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. + + + SEE ALSO + -------- + + :ref:`kdb5_util(8)`, :ref:`kdc.conf(5)`, :ref:`krb5.conf(5)`, +-:ref:`kdb5_ldap_util(8)` ++:ref:`kdb5_ldap_util(8)`, :ref:`kerberos(7)` +diff --git a/doc/admin/admin_commands/ktutil.rst b/doc/admin/admin_commands/ktutil.rst +index 2eb19ded2..7d8ab4913 100644 +--- a/doc/admin/admin_commands/ktutil.rst ++++ b/doc/admin/admin_commands/ktutil.rst +@@ -127,7 +127,14 @@ EXAMPLE + ktutil: + + ++ENVIRONMENT ++----------- ++ ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. ++ ++ + SEE ALSO + -------- + +-:ref:`kadmin(1)`, :ref:`kdb5_util(8)` ++:ref:`kadmin(1)`, :ref:`kdb5_util(8)`, :ref:`kerberos(7)` +diff --git a/doc/admin/admin_commands/sserver.rst b/doc/admin/admin_commands/sserver.rst +index b4e464466..a8dcf5d5b 100644 +--- a/doc/admin/admin_commands/sserver.rst ++++ b/doc/admin/admin_commands/sserver.rst +@@ -99,7 +99,14 @@ COMMON ERROR MESSAGES + probably not installed in the proper directory. + + ++ENVIRONMENT ++----------- ++ ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. ++ ++ + SEE ALSO + -------- + +-:ref:`sclient(1)`, services(5), inetd(8) ++:ref:`sclient(1)`, :ref:`kerberos(7)`, services(5), inetd(8) +diff --git a/doc/user/user_commands/kdestroy.rst b/doc/user/user_commands/kdestroy.rst +index b8c67aba4..c69d65667 100644 +--- a/doc/user/user_commands/kdestroy.rst ++++ b/doc/user/user_commands/kdestroy.rst +@@ -53,15 +53,8 @@ when you log out. + ENVIRONMENT + ----------- + +-kdestroy uses the following environment variable: +- +-**KRB5CCNAME** +- Location of the default Kerberos 5 credentials (ticket) cache, in +- the form *type*:*residual*. If no *type* prefix is present, the +- **FILE** type is assumed. The type of the default cache may +- determine the availability of a cache collection; for instance, a +- default cache of type **DIR** causes caches within the directory +- to be present in the collection. ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. + + + FILES +@@ -74,4 +67,4 @@ FILES + SEE ALSO + -------- + +-:ref:`kinit(1)`, :ref:`klist(1)` ++:ref:`kinit(1)`, :ref:`klist(1)`, :ref:`kerberos(7)` +diff --git a/doc/user/user_commands/kinit.rst b/doc/user/user_commands/kinit.rst +index 1f696920f..d692e2791 100644 +--- a/doc/user/user_commands/kinit.rst ++++ b/doc/user/user_commands/kinit.rst +@@ -200,19 +200,11 @@ OPTIONS + **disable_freshness**\ [**=yes**] + disable sending freshness tokens (for testing purposes only) + +- + ENVIRONMENT + ----------- + +-kinit uses the following environment variables: +- +-**KRB5CCNAME** +- Location of the default Kerberos 5 credentials cache, in the form +- *type*:*residual*. If no *type* prefix is present, the **FILE** +- type is assumed. The type of the default cache may determine the +- availability of a cache collection; for instance, a default cache +- of type **DIR** causes caches within the directory to be present +- in the collection. ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. + + + FILES +@@ -228,4 +220,4 @@ FILES + SEE ALSO + -------- + +-:ref:`klist(1)`, :ref:`kdestroy(1)`, kerberos(1) ++:ref:`klist(1)`, :ref:`kdestroy(1)`, :ref:`kerberos(7)` +diff --git a/doc/user/user_commands/klist.rst b/doc/user/user_commands/klist.rst +index c24c74132..88e457846 100644 +--- a/doc/user/user_commands/klist.rst ++++ b/doc/user/user_commands/klist.rst +@@ -105,15 +105,8 @@ value is used to locate the default ticket cache. + ENVIRONMENT + ----------- + +-klist uses the following environment variable: +- +-**KRB5CCNAME** +- Location of the default Kerberos 5 credentials (ticket) cache, in +- the form *type*:*residual*. If no *type* prefix is present, the +- **FILE** type is assumed. The type of the default cache may +- determine the availability of a cache collection; for instance, a +- default cache of type **DIR** causes caches within the directory +- to be present in the collection. ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. + + + FILES +@@ -129,4 +122,4 @@ FILES + SEE ALSO + -------- + +-:ref:`kinit(1)`, :ref:`kdestroy(1)` ++:ref:`kinit(1)`, :ref:`kdestroy(1)`, :ref:`kerberos(7)` +diff --git a/doc/user/user_commands/kpasswd.rst b/doc/user/user_commands/kpasswd.rst +index 1b6463265..0583bbd05 100644 +--- a/doc/user/user_commands/kpasswd.rst ++++ b/doc/user/user_commands/kpasswd.rst +@@ -33,7 +33,14 @@ OPTIONS + identity of the user invoking the kpasswd command. + + ++ENVIRONMENT ++----------- ++ ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. ++ ++ + SEE ALSO + -------- + +-:ref:`kadmin(1)`, :ref:`kadmind(8)` ++:ref:`kadmin(1)`, :ref:`kadmind(8)`, :ref:`kerberos(7)` +diff --git a/doc/user/user_commands/krb5-config.rst b/doc/user/user_commands/krb5-config.rst +index ee0fceaa3..2c09141a1 100644 +--- a/doc/user/user_commands/krb5-config.rst ++++ b/doc/user/user_commands/krb5-config.rst +@@ -80,4 +80,4 @@ the following output:: + SEE ALSO + -------- + +-kerberos(1), cc(1) ++:ref:`kerberos(7)`, cc(1) +diff --git a/doc/user/user_commands/ksu.rst b/doc/user/user_commands/ksu.rst +index b2f9121f0..29487a838 100644 +--- a/doc/user/user_commands/ksu.rst ++++ b/doc/user/user_commands/ksu.rst +@@ -385,3 +385,16 @@ AUTHOR OF KSU + ------------- + + GENNADY (ARI) MEDVINSKY ++ ++ ++ENVIRONMENT ++----------- ++ ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. ++ ++ ++SEE ALSO ++-------- ++ ++:ref:`kerberos(7)`, :ref:`kinit(1)` +diff --git a/doc/user/user_commands/kswitch.rst b/doc/user/user_commands/kswitch.rst +index 56e5915ac..010332e6a 100644 +--- a/doc/user/user_commands/kswitch.rst ++++ b/doc/user/user_commands/kswitch.rst +@@ -32,15 +32,8 @@ OPTIONS + ENVIRONMENT + ----------- + +-kswitch uses the following environment variables: +- +-**KRB5CCNAME** +- Location of the default Kerberos 5 credentials (ticket) cache, in +- the form *type*:*residual*. If no *type* prefix is present, the +- **FILE** type is assumed. The type of the default cache may +- determine the availability of a cache collection; for instance, a +- default cache of type **DIR** causes caches within the directory +- to be present in the collection. ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. + + + FILES +@@ -53,4 +46,5 @@ FILES + SEE ALSO + -------- + +-:ref:`kinit(1)`, :ref:`kdestroy(1)`, :ref:`klist(1)`), kerberos(1) ++:ref:`kinit(1)`, :ref:`kdestroy(1)`, :ref:`klist(1)`, ++:ref:`kerberos(7)` +diff --git a/doc/user/user_commands/kvno.rst b/doc/user/user_commands/kvno.rst +index 31ca24460..f269fb3f9 100644 +--- a/doc/user/user_commands/kvno.rst ++++ b/doc/user/user_commands/kvno.rst +@@ -63,14 +63,11 @@ OPTIONS + delegation is not requested, the service name must match the + credentials cache client principal. + +- + ENVIRONMENT + ----------- + +-kvno uses the following environment variable: +- +-**KRB5CCNAME** +- Location of the credentials (ticket) cache. ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. + + + FILES +@@ -83,4 +80,4 @@ FILES + SEE ALSO + -------- + +-:ref:`kinit(1)`, :ref:`kdestroy(1)` ++:ref:`kinit(1)`, :ref:`kdestroy(1)`, :ref:`kerberos(7)` +diff --git a/doc/user/user_commands/sclient.rst b/doc/user/user_commands/sclient.rst +index ebf797253..1e3d38f82 100644 +--- a/doc/user/user_commands/sclient.rst ++++ b/doc/user/user_commands/sclient.rst +@@ -17,8 +17,14 @@ purposes. It contacts a sample server :ref:`sserver(8)` and + authenticates to it using Kerberos version 5 tickets, then displays + the server's response. + ++ENVIRONMENT ++----------- ++ ++See :ref:`kerberos(7)` for a description of Kerberos environment ++variables. ++ + + SEE ALSO + -------- + +-:ref:`kinit(1)`, :ref:`sserver(8)` ++:ref:`kinit(1)`, :ref:`sserver(8)`, :ref:`kerberos(7)` diff --git a/krb5.spec b/krb5.spec index abfc7fd..01e7a01 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.16.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 24%{?dist} +Release: 25%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -107,6 +107,9 @@ Patch87: Prefer-TCP-to-UDP-for-password-changes.patch Patch88: Correct-kpasswd_server-description-in-krb5.conf-5.patch Patch89: Prevent-SIGPIPE-from-socket-writes-on-UNIX-likes.patch Patch90: Use-port-sockets.h-macros-in-cc_kcm-sendto_kdc.patch +Patch91: Bring-back-general-kerberos-man-page.patch +Patch92: Modernize-kerberos-7.patch +Patch93: Update-man-pages-to-reference-kerberos-7.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -753,6 +756,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Oct 24 2018 Robbie Harwood - 1.16.1-25 +- Update man pages to reference kerberos(7) +- Resolves: #1143767 + * Wed Oct 17 2018 Robbie Harwood - 1.16.1-24 - Use port-sockets.h macros in cc_kcm, sendto_kdc - Resolves: #1631998 From 5f59f8911127511fcef36aaf9f2dbd9b823d5332 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 24 Oct 2018 15:36:36 -0400 Subject: [PATCH 073/304] Package kerberos(7) --- krb5.spec | 1 + 1 file changed, 1 insertion(+) diff --git a/krb5.spec b/krb5.spec index 01e7a01..6eca6f7 100644 --- a/krb5.spec +++ b/krb5.spec @@ -698,6 +698,7 @@ exit 0 /%{_mandir}/man5/k5identity.5* /%{_mandir}/man5/k5login.5* /%{_mandir}/man5/krb5.conf.5* +/%{_mandir}/man7/kerberos.7* %{_libdir}/libgssapi_krb5.so.* %{_libdir}/libgssrpc.so.* %{_libdir}/libk5crypto.so.* From f745542b78b20b9e54aaf77e372e730c1fb361ad Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 1 Nov 2018 15:55:31 -0400 Subject: [PATCH 074/304] New upstream beta release (1.17-beta1) --- .gitignore | 3 + ...ncoders-and-decoders-for-SPAKE-types.patch | 866 - ...INIT-KDC-support-for-freshness-token.patch | 631 - ...T-client-support-for-freshness-token.patch | 336 - Add-SPAKE-preauth-support.patch | 14349 ---------------- ...oc-index-entries-for-SPAKE-constants.patch | 31 - ...isable-encrypted-timestamp-on-client.patch | 204 - Add-k5_buf_add_vfmt-to-k5buf-interface.patch | 119 - Add-k5_dir_filenames-to-libkrb5support.patch | 222 - Add-k5test-mark-function.patch | 60 - ...bkrb5support-hex-functions-and-tests.patch | 484 - Add-vector-support-to-k5_sha256.patch | 106 - ...ul-asking-for-AS-key-in-SPAKE-client.patch | 229 - Bring-back-general-kerberos-man-page.patch | 468 - Convert-Python-tests-to-Python-3.patch | 536 - ...wd_server-description-in-krb5.conf-5.patch | 28 - ...nate-preprocessor-disabled-dead-code.patch | 2950 ---- Exit-with-status-0-from-kadmind.patch | 31 - ...tly-look-for-python2-in-configure.in.patch | 816 - Fix-SPAKE-memory-leak.patch | 41 - ...-conversion-of-PKINIT-certid-strings.patch | 92 - Fix-k5test-prompts-for-Python-3.patch | 35 - Fix-read-overflow-in-KDC-sort_pa_data.patch | 48 - ...id_sam2-preauth-for-non-default-salt.patch | 43 - Fix-segfault-in-finish_dispatch.patch | 133 - Fix-some-broken-tests-for-Python-3.patch | 81 - Implement-k5_buf_init_dynamic_zap.patch | 149 - ...-plaintext-fallback-for-RC4-usages-a.patch | 2 +- ...e-info-in-for-hardware-preauth-hints.patch | 38 - ...uth-name-in-trace-output-if-possible.patch | 514 - ...hen-non-root-ksu-authorization-fails.patch | 35 - Make-docs-build-python3-compatible.patch | 36 - Make-krb5kdc-p-affect-TCP-ports.patch | 67 - Modernize-kerberos-7.patch | 429 - Move-zap-definition-to-k5-platform.h.patch | 151 - Prefer-TCP-to-UDP-for-password-changes.patch | 168 - ...IPE-from-socket-writes-on-UNIX-likes.patch | 86 - ...s-profile-includedir-in-sorted-order.patch | 114 - ...r-KDC-krb5_pa_data-utility-functions.patch | 393 - ...nodes-option-from-make-certs-scripts.patch | 45 - ...ve-outdated-note-in-krb5kdc-man-page.patch | 37 - Report-extended-errors-in-kinit-k-t-KDB.patch | 27 - ...ct-pre-authentication-fallback-cases.patch | 491 - Simplify-kdc_preauth.c-systems-table.patch | 738 - ...te-man-pages-to-reference-kerberos-7.patch | 476 - ...-instead-of-MD5-for-audit-ticket-IDs.patch | 53 - ...f_init_dynamic_zap-where-appropriate.patch | 62 - ...port-hex-functions-where-appropriate.patch | 869 - ...ockets.h-macros-in-cc_kcm-sendto_kdc.patch | 138 - Zap-copy-of-secret-in-RC4-string-to-key.patch | 30 - Zap-data-when-freeing-krb5_spake_factor.patch | 29 - krb5-1.11-kpasswdtest.patch | 2 +- krb5-1.11-run_user_0.patch | 2 +- krb5-1.12-api.patch | 2 +- krb5-1.12-ksu-path.patch | 2 +- krb5-1.12-ktany.patch | 2 +- krb5-1.12.1-pam.patch | 22 +- krb5-1.13-dirsrv-accountlock.patch | 6 +- krb5-1.15-beta1-buildconf.patch | 4 +- ...tch => krb5-1.17-beta1-selinux-label.patch | 146 +- krb5-1.3.1-dns.patch | 4 +- krb5-1.9-debuginfo.patch | 2 +- krb5.spec | 60 +- sources | 6 +- 64 files changed, 111 insertions(+), 28268 deletions(-) delete mode 100644 Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch delete mode 100644 Add-PKINIT-KDC-support-for-freshness-token.patch delete mode 100644 Add-PKINIT-client-support-for-freshness-token.patch delete mode 100644 Add-SPAKE-preauth-support.patch delete mode 100644 Add-doc-index-entries-for-SPAKE-constants.patch delete mode 100644 Add-flag-to-disable-encrypted-timestamp-on-client.patch delete mode 100644 Add-k5_buf_add_vfmt-to-k5buf-interface.patch delete mode 100644 Add-k5_dir_filenames-to-libkrb5support.patch delete mode 100644 Add-k5test-mark-function.patch delete mode 100644 Add-libkrb5support-hex-functions-and-tests.patch delete mode 100644 Add-vector-support-to-k5_sha256.patch delete mode 100644 Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch delete mode 100644 Bring-back-general-kerberos-man-page.patch delete mode 100644 Convert-Python-tests-to-Python-3.patch delete mode 100644 Correct-kpasswd_server-description-in-krb5.conf-5.patch delete mode 100644 Eliminate-preprocessor-disabled-dead-code.patch delete mode 100644 Exit-with-status-0-from-kadmind.patch delete mode 100644 Explicitly-look-for-python2-in-configure.in.patch delete mode 100644 Fix-SPAKE-memory-leak.patch delete mode 100644 Fix-hex-conversion-of-PKINIT-certid-strings.patch delete mode 100644 Fix-k5test-prompts-for-Python-3.patch delete mode 100644 Fix-read-overflow-in-KDC-sort_pa_data.patch delete mode 100644 Fix-securid_sam2-preauth-for-non-default-salt.patch delete mode 100644 Fix-segfault-in-finish_dispatch.patch delete mode 100644 Fix-some-broken-tests-for-Python-3.patch delete mode 100644 Implement-k5_buf_init_dynamic_zap.patch delete mode 100644 Include-etype-info-in-for-hardware-preauth-hints.patch delete mode 100644 Include-preauth-name-in-trace-output-if-possible.patch delete mode 100644 Log-when-non-root-ksu-authorization-fails.patch delete mode 100644 Make-docs-build-python3-compatible.patch delete mode 100644 Make-krb5kdc-p-affect-TCP-ports.patch delete mode 100644 Modernize-kerberos-7.patch delete mode 100644 Move-zap-definition-to-k5-platform.h.patch delete mode 100644 Prefer-TCP-to-UDP-for-password-changes.patch delete mode 100644 Prevent-SIGPIPE-from-socket-writes-on-UNIX-likes.patch delete mode 100644 Process-profile-includedir-in-sorted-order.patch delete mode 100644 Refactor-KDC-krb5_pa_data-utility-functions.patch delete mode 100644 Remove-nodes-option-from-make-certs-scripts.patch delete mode 100644 Remove-outdated-note-in-krb5kdc-man-page.patch delete mode 100644 Report-extended-errors-in-kinit-k-t-KDB.patch delete mode 100644 Restrict-pre-authentication-fallback-cases.patch delete mode 100644 Simplify-kdc_preauth.c-systems-table.patch delete mode 100644 Update-man-pages-to-reference-kerberos-7.patch delete mode 100644 Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch delete mode 100644 Use-k5_buf_init_dynamic_zap-where-appropriate.patch delete mode 100644 Use-libkrb5support-hex-functions-where-appropriate.patch delete mode 100644 Use-port-sockets.h-macros-in-cc_kcm-sendto_kdc.patch delete mode 100644 Zap-copy-of-secret-in-RC4-string-to-key.patch delete mode 100644 Zap-data-when-freeing-krb5_spake_factor.patch rename krb5-1.15.1-selinux-label.patch => krb5-1.17-beta1-selinux-label.patch (93%) diff --git a/.gitignore b/.gitignore index c8fdb57..1eed1cf 100644 --- a/.gitignore +++ b/.gitignore @@ -166,3 +166,6 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.16.1-pdfs.tar /krb5-1.16.1.tar.gz /krb5-1.16.1.tar.gz.asc +/krb5-1.17-beta1.tar.gz +/krb5-1.17-beta1.tar.gz.asc +/krb5-1.17-beta1-pdfs.tar diff --git a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch b/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch deleted file mode 100644 index 6e78dcc..0000000 --- a/Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch +++ /dev/null @@ -1,866 +0,0 @@ -From dff5177801444307d19071fc4fac7de864fda92a Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 13 Jun 2015 16:04:53 -0400 -Subject: [PATCH] Add ASN.1 encoders and decoders for SPAKE types - -Add a new internal header k5-spake.h. Add ASN.1 encoder and decoder -functions and an internal free function for SPAKE types. Add ASN.1 -tests and asn1c test vectors the new types. - -The additions to to make-vectors.c use C99 designated initializers in -order to initialize unions. This is okay since make-vectors.c is only -compiled as part of "make test-vectors" and not as part of the regular -build. - -(cherry picked from commit 78a09d95dff6915da4079bc611f4bb95f6a95f70) ---- - src/include/k5-spake.h | 107 +++++++++++++++++++++++++++ - src/lib/krb5/asn.1/asn1_k_encode.c | 52 ++++++++++++- - src/lib/krb5/krb/kfree.c | 40 ++++++++++ - src/lib/krb5/libkrb5.exports | 6 ++ - src/tests/asn.1/Makefile.in | 2 +- - src/tests/asn.1/krb5_decode_test.c | 37 +++++++++ - src/tests/asn.1/krb5_encode_test.c | 29 ++++++++ - src/tests/asn.1/ktest.c | 97 ++++++++++++++++++++++++ - src/tests/asn.1/ktest.h | 9 +++ - src/tests/asn.1/ktest_equal.c | 49 ++++++++++++ - src/tests/asn.1/ktest_equal.h | 6 ++ - src/tests/asn.1/make-vectors.c | 56 ++++++++++++++ - src/tests/asn.1/reference_encode.out | 6 ++ - src/tests/asn.1/spake.asn1 | 44 +++++++++++ - src/tests/asn.1/trval_reference.out | 50 +++++++++++++ - 15 files changed, 588 insertions(+), 2 deletions(-) - create mode 100644 src/include/k5-spake.h - create mode 100644 src/tests/asn.1/spake.asn1 - -diff --git a/src/include/k5-spake.h b/src/include/k5-spake.h -new file mode 100644 -index 000000000..ddb5d810d ---- /dev/null -+++ b/src/include/k5-spake.h -@@ -0,0 +1,107 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* include/k5-spake.h - SPAKE preauth mech declarations */ -+/* -+ * Copyright (C) 2015 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+/* -+ * The SPAKE preauth mechanism allows long-term client keys to be used for -+ * preauthentication without exposing them to offline dictionary attacks. The -+ * negotiated key can also be used for second-factor authentication. This -+ * header file declares structures and encoder/decoder functions for the -+ * mechanism's padata messages. -+ */ -+ -+#ifndef K5_SPAKE_H -+#define K5_SPAKE_H -+ -+#include "k5-int.h" -+ -+/* SPAKESecondFactor is contained within a SPAKEChallenge, SPAKEResponse, or -+ * EncryptedData message and contains a second-factor challenge or response. */ -+typedef struct krb5_spake_factor_st { -+ int32_t type; -+ krb5_data *data; -+} krb5_spake_factor; -+ -+/* SPAKESupport is sent from the client to the KDC to indicate which group the -+ * client supports. */ -+typedef struct krb5_spake_support_st { -+ int32_t ngroups; -+ int32_t *groups; -+} krb5_spake_support; -+ -+/* SPAKEChallenge is sent from the KDC to the client to communicate its group -+ * selection, public value, and second-factor challenge options. */ -+typedef struct krb5_spake_challenge_st { -+ int32_t group; -+ krb5_data pubkey; -+ krb5_spake_factor **factors; -+} krb5_spake_challenge; -+ -+/* SPAKEResponse is sent from the client to the KDC to communicate its public -+ * value and encrypted second-factor response. */ -+typedef struct krb5_spake_response_st { -+ krb5_data pubkey; -+ krb5_enc_data factor; -+} krb5_spake_response; -+ -+enum krb5_spake_msgtype { -+ SPAKE_MSGTYPE_UNKNOWN = -1, -+ SPAKE_MSGTYPE_SUPPORT = 0, -+ SPAKE_MSGTYPE_CHALLENGE = 1, -+ SPAKE_MSGTYPE_RESPONSE = 2, -+ SPAKE_MSGTYPE_ENCDATA = 3 -+}; -+ -+/* PA-SPAKE is a choice among the message types which can appear in a PA-SPAKE -+ * padata element. */ -+typedef struct krb5_pa_spake_st { -+ enum krb5_spake_msgtype choice; -+ union krb5_spake_message_choices { -+ krb5_spake_support support; -+ krb5_spake_challenge challenge; -+ krb5_spake_response response; -+ krb5_enc_data encdata; -+ } u; -+} krb5_pa_spake; -+ -+krb5_error_code encode_krb5_spake_factor(const krb5_spake_factor *val, -+ krb5_data **code_out); -+krb5_error_code decode_krb5_spake_factor(const krb5_data *code, -+ krb5_spake_factor **val_out); -+void k5_free_spake_factor(krb5_context context, krb5_spake_factor *val); -+ -+krb5_error_code encode_krb5_pa_spake(const krb5_pa_spake *val, -+ krb5_data **code_out); -+krb5_error_code decode_krb5_pa_spake(const krb5_data *code, -+ krb5_pa_spake **val_out); -+void k5_free_pa_spake(krb5_context context, krb5_pa_spake *val); -+ -+#endif /* K5_SPAKE_H */ -diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c -index 3b23fe34a..29f6b903d 100644 ---- a/src/lib/krb5/asn.1/asn1_k_encode.c -+++ b/src/lib/krb5/asn.1/asn1_k_encode.c -@@ -25,7 +25,7 @@ - */ - - #include "asn1_encode.h" --#include -+#include "k5-spake.h" - - DEFINT_IMMEDIATE(krb5_version, KVNO, KRB5KDC_ERR_BAD_PVNO); - -@@ -1817,3 +1817,53 @@ static const struct atype_info *secure_cookie_fields[] = { - DEFSEQTYPE(secure_cookie, krb5_secure_cookie, secure_cookie_fields); - MAKE_ENCODER(encode_krb5_secure_cookie, secure_cookie); - MAKE_DECODER(decode_krb5_secure_cookie, secure_cookie); -+ -+DEFFIELD(spake_factor_0, krb5_spake_factor, type, 0, int32); -+DEFFIELD(spake_factor_1, krb5_spake_factor, data, 1, opt_ostring_data_ptr); -+static const struct atype_info *spake_factor_fields[] = { -+ &k5_atype_spake_factor_0, &k5_atype_spake_factor_1 -+}; -+DEFSEQTYPE(spake_factor, krb5_spake_factor, spake_factor_fields); -+DEFPTRTYPE(spake_factor_ptr, spake_factor); -+DEFNULLTERMSEQOFTYPE(seqof_spake_factor, spake_factor_ptr); -+DEFPTRTYPE(ptr_seqof_spake_factor, seqof_spake_factor); -+MAKE_ENCODER(encode_krb5_spake_factor, spake_factor); -+MAKE_DECODER(decode_krb5_spake_factor, spake_factor); -+ -+DEFCNFIELD(spake_support_0, krb5_spake_support, groups, ngroups, 0, -+ cseqof_int32); -+static const struct atype_info *spake_support_fields[] = { -+ &k5_atype_spake_support_0 -+}; -+DEFSEQTYPE(spake_support, krb5_spake_support, spake_support_fields); -+ -+DEFFIELD(spake_challenge_0, krb5_spake_challenge, group, 0, int32); -+DEFFIELD(spake_challenge_1, krb5_spake_challenge, pubkey, 1, ostring_data); -+DEFFIELD(spake_challenge_2, krb5_spake_challenge, factors, 2, -+ ptr_seqof_spake_factor); -+static const struct atype_info *spake_challenge_fields[] = { -+ &k5_atype_spake_challenge_0, &k5_atype_spake_challenge_1, -+ &k5_atype_spake_challenge_2 -+}; -+DEFSEQTYPE(spake_challenge, krb5_spake_challenge, spake_challenge_fields); -+ -+DEFFIELD(spake_response_0, krb5_spake_response, pubkey, 0, ostring_data); -+DEFFIELD(spake_response_1, krb5_spake_response, factor, 1, encrypted_data); -+static const struct atype_info *spake_response_fields[] = { -+ &k5_atype_spake_response_0, &k5_atype_spake_response_1, -+}; -+DEFSEQTYPE(spake_response, krb5_spake_response, spake_response_fields); -+ -+DEFCTAGGEDTYPE(pa_spake_0, 0, spake_support); -+DEFCTAGGEDTYPE(pa_spake_1, 1, spake_challenge); -+DEFCTAGGEDTYPE(pa_spake_2, 2, spake_response); -+DEFCTAGGEDTYPE(pa_spake_3, 3, encrypted_data); -+static const struct atype_info *pa_spake_alternatives[] = { -+ &k5_atype_pa_spake_0, &k5_atype_pa_spake_1, &k5_atype_pa_spake_2, -+ &k5_atype_pa_spake_3 -+}; -+DEFCHOICETYPE(pa_spake_choice, union krb5_spake_message_choices, -+ enum krb5_spake_msgtype, pa_spake_alternatives); -+DEFCOUNTEDTYPE_SIGNED(pa_spake, krb5_pa_spake, u, choice, pa_spake_choice); -+MAKE_ENCODER(encode_krb5_pa_spake, pa_spake); -+MAKE_DECODER(decode_krb5_pa_spake, pa_spake); -diff --git a/src/lib/krb5/krb/kfree.c b/src/lib/krb5/krb/kfree.c -index a631807d3..e1ea1494a 100644 ---- a/src/lib/krb5/krb/kfree.c -+++ b/src/lib/krb5/krb/kfree.c -@@ -51,6 +51,7 @@ - */ - - #include "k5-int.h" -+#include "k5-spake.h" - #include - - void KRB5_CALLCONV -@@ -890,3 +891,42 @@ k5_free_secure_cookie(krb5_context context, krb5_secure_cookie *val) - k5_zapfree_pa_data(val->data); - free(val); - } -+ -+void -+k5_free_spake_factor(krb5_context context, krb5_spake_factor *val) -+{ -+ if (val == NULL) -+ return; -+ krb5_free_data(context, val->data); -+ free(val); -+} -+ -+void -+k5_free_pa_spake(krb5_context context, krb5_pa_spake *val) -+{ -+ krb5_spake_factor **f; -+ -+ if (val == NULL) -+ return; -+ switch (val->choice) { -+ case SPAKE_MSGTYPE_SUPPORT: -+ free(val->u.support.groups); -+ break; -+ case SPAKE_MSGTYPE_CHALLENGE: -+ krb5_free_data_contents(context, &val->u.challenge.pubkey); -+ for (f = val->u.challenge.factors; f != NULL && *f != NULL; f++) -+ k5_free_spake_factor(context, *f); -+ free(val->u.challenge.factors); -+ break; -+ case SPAKE_MSGTYPE_RESPONSE: -+ krb5_free_data_contents(context, &val->u.response.pubkey); -+ krb5_free_data_contents(context, &val->u.response.factor.ciphertext); -+ break; -+ case SPAKE_MSGTYPE_ENCDATA: -+ krb5_free_data_contents(context, &val->u.encdata.ciphertext); -+ break; -+ default: -+ break; -+ } -+ free(val); -+} -diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports -index ed6cad6ad..622bc3673 100644 ---- a/src/lib/krb5/libkrb5.exports -+++ b/src/lib/krb5/libkrb5.exports -@@ -36,6 +36,7 @@ decode_krb5_pa_otp_req - decode_krb5_pa_otp_enc_req - decode_krb5_pa_pac_req - decode_krb5_pa_s4u_x509_user -+decode_krb5_pa_spake - decode_krb5_padata_sequence - decode_krb5_priv - decode_krb5_safe -@@ -44,6 +45,7 @@ decode_krb5_sam_challenge_2_body - decode_krb5_sam_response_2 - decode_krb5_secure_cookie - decode_krb5_setpw_req -+decode_krb5_spake_factor - decode_krb5_tgs_rep - decode_krb5_tgs_req - decode_krb5_ticket -@@ -85,6 +87,7 @@ encode_krb5_pa_otp_challenge - encode_krb5_pa_otp_req - encode_krb5_pa_otp_enc_req - encode_krb5_pa_s4u_x509_user -+encode_krb5_pa_spake - encode_krb5_padata_sequence - encode_krb5_pkinit_supp_pub_info - encode_krb5_priv -@@ -95,6 +98,7 @@ encode_krb5_sam_challenge_2_body - encode_krb5_sam_response_2 - encode_krb5_secure_cookie - encode_krb5_sp80056a_other_info -+encode_krb5_spake_factor - encode_krb5_tgs_rep - encode_krb5_tgs_req - encode_krb5_ticket -@@ -128,7 +132,9 @@ k5_free_kkdcp_message - k5_free_pa_otp_challenge - k5_free_pa_otp_req - k5_free_secure_cookie -+k5_free_pa_spake - k5_free_serverlist -+k5_free_spake_factor - k5_hostrealm_free_context - k5_init_trace - k5_is_string_numeric -diff --git a/src/tests/asn.1/Makefile.in b/src/tests/asn.1/Makefile.in -index fec4e109e..ec9c67495 100644 ---- a/src/tests/asn.1/Makefile.in -+++ b/src/tests/asn.1/Makefile.in -@@ -9,7 +9,7 @@ SRCS= $(srcdir)/krb5_encode_test.c $(srcdir)/krb5_decode_test.c \ - - ASN1SRCS= $(srcdir)/krb5.asn1 $(srcdir)/pkix.asn1 $(srcdir)/otp.asn1 \ - $(srcdir)/pkinit.asn1 $(srcdir)/pkinit-agility.asn1 \ -- $(srcdir)/cammac.asn1 -+ $(srcdir)/cammac.asn1 $(srcdir)/spake.asn1 - - all: krb5_encode_test krb5_decode_test krb5_decode_leak t_trval - -diff --git a/src/tests/asn.1/krb5_decode_test.c b/src/tests/asn.1/krb5_decode_test.c -index f17f9b1f1..ee70fa4b9 100644 ---- a/src/tests/asn.1/krb5_decode_test.c -+++ b/src/tests/asn.1/krb5_decode_test.c -@@ -25,6 +25,7 @@ - */ - - #include "k5-int.h" -+#include "k5-spake.h" - #include "ktest.h" - #include "com_err.h" - #include "utility.h" -@@ -1107,6 +1108,42 @@ int main(argc, argv) - ktest_empty_secure_cookie(&ref); - } - -+ /****************************************************************/ -+ /* decode_krb5_spake_factor */ -+ { -+ setup(krb5_spake_factor,ktest_make_minimal_spake_factor); -+ decode_run("spake_factor","(optionals NULL)","30 05 A0 03 02 01 01",decode_krb5_spake_factor,ktest_equal_spake_factor,k5_free_spake_factor); -+ ktest_empty_spake_factor(&ref); -+ } -+ { -+ setup(krb5_spake_factor,ktest_make_maximal_spake_factor); -+ decode_run("spake_factor","","30 0E A0 03 02 01 02 A1 07 04 05 66 64 61 74 61",decode_krb5_spake_factor,ktest_equal_spake_factor,k5_free_spake_factor); -+ ktest_empty_spake_factor(&ref); -+ } -+ -+ /****************************************************************/ -+ /* decode_krb5_pa_spake */ -+ { -+ setup(krb5_pa_spake,ktest_make_support_pa_spake); -+ decode_run("pa_spake","(support)","A0 0C 30 0A A0 08 30 06 02 01 01 02 01 02",decode_krb5_pa_spake,ktest_equal_pa_spake,k5_free_pa_spake); -+ ktest_empty_pa_spake(&ref); -+ } -+ { -+ setup(krb5_pa_spake,ktest_make_challenge_pa_spake); -+ decode_run("pa_spake","(challenge)","A1 2D 30 2B A0 03 02 01 01 A1 09 04 07 54 20 76 61 6C 75 65 A2 19 30 17 30 05 A0 03 02 01 01 30 0E A0 03 02 01 02 A1 07 04 05 66 64 61 74 61",decode_krb5_pa_spake,ktest_equal_pa_spake,k5_free_pa_spake); -+ ktest_empty_pa_spake(&ref); -+ } -+ { -+ setup(krb5_pa_spake,ktest_make_response_pa_spake); -+ decode_run("pa_spake","(response)","A2 34 30 32 A0 09 04 07 53 20 76 61 6C 75 65 A1 25 30 23 A0 03 02 01 00 A1 03 02 01 05 A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65",decode_krb5_pa_spake,ktest_equal_pa_spake,k5_free_pa_spake); -+ ktest_empty_pa_spake(&ref); -+ } -+ { -+ setup(krb5_pa_spake,ktest_make_encdata_pa_spake); -+ decode_run("pa_spake","(encdata)","A3 25 30 23 A0 03 02 01 00 A1 03 02 01 05 A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65",decode_krb5_pa_spake,ktest_equal_pa_spake,k5_free_pa_spake); -+ ktest_empty_pa_spake(&ref); -+ } -+ - #ifndef DISABLE_PKINIT - - /****************************************************************/ -diff --git a/src/tests/asn.1/krb5_encode_test.c b/src/tests/asn.1/krb5_encode_test.c -index f5710b68c..3efbfb4c0 100644 ---- a/src/tests/asn.1/krb5_encode_test.c -+++ b/src/tests/asn.1/krb5_encode_test.c -@@ -759,6 +759,35 @@ main(argc, argv) - encode_run(cookie, "secure_cookie", "", encode_krb5_secure_cookie); - ktest_empty_secure_cookie(&cookie); - } -+ /****************************************************************/ -+ /* encode_krb5_spake_factor */ -+ { -+ krb5_spake_factor factor; -+ ktest_make_minimal_spake_factor(&factor); -+ encode_run(factor, "spake_factor", "(optionals NULL)", -+ encode_krb5_spake_factor); -+ ktest_empty_spake_factor(&factor); -+ ktest_make_maximal_spake_factor(&factor); -+ encode_run(factor, "spake_factor", "", encode_krb5_spake_factor); -+ ktest_empty_spake_factor(&factor); -+ } -+ /****************************************************************/ -+ /* encode_krb5_pa_spake */ -+ { -+ krb5_pa_spake pa_spake; -+ ktest_make_support_pa_spake(&pa_spake); -+ encode_run(pa_spake, "pa_spake", "(support)", encode_krb5_pa_spake); -+ ktest_empty_pa_spake(&pa_spake); -+ ktest_make_challenge_pa_spake(&pa_spake); -+ encode_run(pa_spake, "pa_spake", "(challenge)", encode_krb5_pa_spake); -+ ktest_empty_pa_spake(&pa_spake); -+ ktest_make_response_pa_spake(&pa_spake); -+ encode_run(pa_spake, "pa_spake", "(response)", encode_krb5_pa_spake); -+ ktest_empty_pa_spake(&pa_spake); -+ ktest_make_encdata_pa_spake(&pa_spake); -+ encode_run(pa_spake, "pa_spake", "(encdata)", encode_krb5_pa_spake); -+ ktest_empty_pa_spake(&pa_spake); -+ } - #ifndef DISABLE_PKINIT - /****************************************************************/ - /* encode_krb5_pa_pk_as_req */ -diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c -index cf63f3f66..5bfdc5be2 100644 ---- a/src/tests/asn.1/ktest.c -+++ b/src/tests/asn.1/ktest.c -@@ -1018,6 +1018,66 @@ ktest_make_sample_secure_cookie(krb5_secure_cookie *p) - p->time = SAMPLE_TIME; - } - -+void -+ktest_make_minimal_spake_factor(krb5_spake_factor *p) -+{ -+ p->type = 1; -+ p->data = NULL; -+} -+ -+void -+ktest_make_maximal_spake_factor(krb5_spake_factor *p) -+{ -+ p->type = 2; -+ p->data = ealloc(sizeof(*p->data)); -+ krb5_data_parse(p->data, "fdata"); -+} -+ -+void -+ktest_make_support_pa_spake(krb5_pa_spake *p) -+{ -+ krb5_spake_support *s = &p->u.support; -+ -+ s->ngroups = 2; -+ s->groups = ealloc(s->ngroups * sizeof(*s->groups)); -+ s->groups[0] = 1; -+ s->groups[1] = 2; -+ p->choice = SPAKE_MSGTYPE_SUPPORT; -+} -+ -+void -+ktest_make_challenge_pa_spake(krb5_pa_spake *p) -+{ -+ krb5_spake_challenge *c = &p->u.challenge; -+ -+ c->group = 1; -+ krb5_data_parse(&c->pubkey, "T value"); -+ c->factors = ealloc(3 * sizeof(*c->factors)); -+ c->factors[0] = ealloc(sizeof(*c->factors[0])); -+ ktest_make_minimal_spake_factor(c->factors[0]); -+ c->factors[1] = ealloc(sizeof(*c->factors[1])); -+ ktest_make_maximal_spake_factor(c->factors[1]); -+ c->factors[2] = NULL; -+ p->choice = SPAKE_MSGTYPE_CHALLENGE; -+} -+ -+void -+ktest_make_response_pa_spake(krb5_pa_spake *p) -+{ -+ krb5_spake_response *r = &p->u.response; -+ -+ krb5_data_parse(&r->pubkey, "S value"); -+ ktest_make_sample_enc_data(&r->factor); -+ p->choice = SPAKE_MSGTYPE_RESPONSE; -+} -+ -+void -+ktest_make_encdata_pa_spake(krb5_pa_spake *p) -+{ -+ ktest_make_sample_enc_data(&p->u.encdata); -+ p->choice = SPAKE_MSGTYPE_ENCDATA; -+} -+ - /****************************************************************/ - /* destructors */ - -@@ -1858,3 +1918,40 @@ ktest_empty_secure_cookie(krb5_secure_cookie *p) - { - ktest_empty_pa_data_array(p->data); - } -+ -+void -+ktest_empty_spake_factor(krb5_spake_factor *p) -+{ -+ krb5_free_data(NULL, p->data); -+ p->data = NULL; -+} -+ -+void -+ktest_empty_pa_spake(krb5_pa_spake *p) -+{ -+ krb5_spake_factor **f; -+ -+ switch (p->choice) { -+ case SPAKE_MSGTYPE_SUPPORT: -+ free(p->u.support.groups); -+ break; -+ case SPAKE_MSGTYPE_CHALLENGE: -+ ktest_empty_data(&p->u.challenge.pubkey); -+ for (f = p->u.challenge.factors; *f != NULL; f++) { -+ ktest_empty_spake_factor(*f); -+ free(*f); -+ } -+ free(p->u.challenge.factors); -+ break; -+ case SPAKE_MSGTYPE_RESPONSE: -+ ktest_empty_data(&p->u.response.pubkey); -+ ktest_destroy_enc_data(&p->u.response.factor); -+ break; -+ case SPAKE_MSGTYPE_ENCDATA: -+ ktest_destroy_enc_data(&p->u.encdata); -+ break; -+ default: -+ break; -+ } -+ p->choice = SPAKE_MSGTYPE_UNKNOWN; -+} -diff --git a/src/tests/asn.1/ktest.h b/src/tests/asn.1/ktest.h -index 493303cc8..1413cfae1 100644 ---- a/src/tests/asn.1/ktest.h -+++ b/src/tests/asn.1/ktest.h -@@ -28,6 +28,7 @@ - #define __KTEST_H__ - - #include "k5-int.h" -+#include "k5-spake.h" - #include "kdb.h" - - #define SAMPLE_USEC 123456 -@@ -124,6 +125,12 @@ void ktest_make_sample_kkdcp_message(krb5_kkdcp_message *p); - void ktest_make_minimal_cammac(krb5_cammac *p); - void ktest_make_maximal_cammac(krb5_cammac *p); - void ktest_make_sample_secure_cookie(krb5_secure_cookie *p); -+void ktest_make_minimal_spake_factor(krb5_spake_factor *p); -+void ktest_make_maximal_spake_factor(krb5_spake_factor *p); -+void ktest_make_support_pa_spake(krb5_pa_spake *p); -+void ktest_make_challenge_pa_spake(krb5_pa_spake *p); -+void ktest_make_response_pa_spake(krb5_pa_spake *p); -+void ktest_make_encdata_pa_spake(krb5_pa_spake *p); - - /*----------------------------------------------------------------------*/ - -@@ -209,6 +216,8 @@ void ktest_empty_ldap_seqof_key_data(krb5_context, ldap_seqof_key_data *p); - void ktest_empty_kkdcp_message(krb5_kkdcp_message *p); - void ktest_empty_cammac(krb5_cammac *p); - void ktest_empty_secure_cookie(krb5_secure_cookie *p); -+void ktest_empty_spake_factor(krb5_spake_factor *p); -+void ktest_empty_pa_spake(krb5_pa_spake *p); - - extern krb5_context test_context; - extern char *sample_principal_name; -diff --git a/src/tests/asn.1/ktest_equal.c b/src/tests/asn.1/ktest_equal.c -index e8bb88944..714cc4398 100644 ---- a/src/tests/asn.1/ktest_equal.c -+++ b/src/tests/asn.1/ktest_equal.c -@@ -853,6 +853,13 @@ ktest_equal_sequence_of_otp_tokeninfo(krb5_otp_tokeninfo **ref, - array_compare(ktest_equal_otp_tokeninfo); - } - -+int -+ktest_equal_sequence_of_spake_factor(krb5_spake_factor **ref, -+ krb5_spake_factor **var) -+{ -+ array_compare(ktest_equal_spake_factor); -+} -+ - #ifndef DISABLE_PKINIT - - static int -@@ -1094,3 +1101,45 @@ ktest_equal_secure_cookie(krb5_secure_cookie *ref, krb5_secure_cookie *var) - p = p && ref->time == ref->time; - return p; - } -+ -+int -+ktest_equal_spake_factor(krb5_spake_factor *ref, krb5_spake_factor *var) -+{ -+ int p = TRUE; -+ if (ref == var) return TRUE; -+ else if (ref == NULL || var == NULL) return FALSE; -+ p = p && scalar_equal(type); -+ p = p && ptr_equal(data,ktest_equal_data); -+ return p; -+} -+ -+int -+ktest_equal_pa_spake(krb5_pa_spake *ref, krb5_pa_spake *var) -+{ -+ int p = TRUE; -+ if (ref == var) return TRUE; -+ else if (ref == NULL || var == NULL) return FALSE; -+ else if (ref->choice != var->choice) return FALSE; -+ switch (ref->choice) { -+ case SPAKE_MSGTYPE_SUPPORT: -+ p = p && scalar_equal(u.support.ngroups); -+ p = p && (memcmp(ref->u.support.groups,var->u.support.groups, -+ ref->u.support.ngroups * sizeof(int32_t)) == 0); -+ break; -+ case SPAKE_MSGTYPE_CHALLENGE: -+ p = p && struct_equal(u.challenge.pubkey,ktest_equal_data); -+ p = p && ptr_equal(u.challenge.factors, -+ ktest_equal_sequence_of_spake_factor); -+ break; -+ case SPAKE_MSGTYPE_RESPONSE: -+ p = p && struct_equal(u.response.pubkey,ktest_equal_data); -+ p = p && struct_equal(u.response.factor,ktest_equal_enc_data); -+ break; -+ case SPAKE_MSGTYPE_ENCDATA: -+ p = p && struct_equal(u.encdata,ktest_equal_enc_data); -+ break; -+ default: -+ break; -+ } -+ return p; -+} -diff --git a/src/tests/asn.1/ktest_equal.h b/src/tests/asn.1/ktest_equal.h -index c7b5d7467..cfa82ac6e 100644 ---- a/src/tests/asn.1/ktest_equal.h -+++ b/src/tests/asn.1/ktest_equal.h -@@ -28,6 +28,7 @@ - #define __KTEST_EQUAL_H__ - - #include "k5-int.h" -+#include "k5-spake.h" - #include "kdb.h" - - /* int ktest_equal_structure(krb5_structure *ref, *var) */ -@@ -97,6 +98,8 @@ ktest_equal_sequence_of_algorithm_identifier(krb5_algorithm_identifier **ref, - krb5_algorithm_identifier **var); - int ktest_equal_sequence_of_otp_tokeninfo(krb5_otp_tokeninfo **ref, - krb5_otp_tokeninfo **var); -+int ktest_equal_sequence_of_spake_factor(krb5_spake_factor **ref, -+ krb5_spake_factor **var); - - len_array(ktest_equal_array_of_enctype,krb5_enctype); - len_array(ktest_equal_array_of_data,krb5_data); -@@ -152,4 +155,7 @@ int ktest_equal_cammac(krb5_cammac *ref, krb5_cammac *var); - int ktest_equal_secure_cookie(krb5_secure_cookie *ref, - krb5_secure_cookie *var); - -+generic(ktest_equal_spake_factor, krb5_spake_factor); -+generic(ktest_equal_pa_spake, krb5_pa_spake); -+ - #endif -diff --git a/src/tests/asn.1/make-vectors.c b/src/tests/asn.1/make-vectors.c -index 3cb8a45ba..2fc85466b 100644 ---- a/src/tests/asn.1/make-vectors.c -+++ b/src/tests/asn.1/make-vectors.c -@@ -40,6 +40,8 @@ - #include - #include - #include -+#include -+#include - - static unsigned char buf[8192]; - static size_t buf_pos; -@@ -168,6 +170,36 @@ static struct other_verifiers overfs = { { verifiers, 2, 2 } }; - static AD_CAMMAC_t cammac_2 = { { { (void *)adlist_2, 2, 2 } }, - &vmac_1, &vmac_2, &overfs }; - -+/* SPAKESecondFactor */ -+static SPAKESecondFactor_t factor_1 = { 1, NULL }; -+static OCTET_STRING_t factor_data = { "fdata", 5 }; -+static SPAKESecondFactor_t factor_2 = { 2, &factor_data }; -+ -+/* PA-SPAKE (support) */ -+static Int32_t group_1 = 1, group_2 = 2, *groups[] = { &group_1, &group_2 }; -+static PA_SPAKE_t pa_spake_1 = { PA_SPAKE_PR_support, -+ { .support = { { groups, 2, 2 } } } }; -+ -+/* PA-SPAKE (challenge) */ -+static SPAKESecondFactor_t *factors[2] = { &factor_1, &factor_2 }; -+static PA_SPAKE_t pa_spake_2 = { PA_SPAKE_PR_challenge, -+ { .challenge = { 1, { "T value", 7 }, -+ { factors, 2, 2 } } } }; -+ -+/* PA-SPAKE (response) */ -+UInt32_t enctype_5 = 5; -+static PA_SPAKE_t pa_spake_3 = { PA_SPAKE_PR_response, -+ { .response = { { "S value", 7 }, -+ { 0, &enctype_5, -+ { "krbASN.1 test message", -+ 21 } } } } }; -+ -+/* PA-SPAKE (encdata) */ -+static PA_SPAKE_t pa_spake_4 = { PA_SPAKE_PR_encdata, -+ { .encdata = { 0, &enctype_5, -+ { "krbASN.1 test message", -+ 21 } } } }; -+ - static int - consume(const void *data, size_t size, void *dummy) - { -@@ -272,6 +304,30 @@ main() - der_encode(&asn_DEF_AD_CAMMAC, &cammac_2, consume, NULL); - printbuf(); - -+ printf("\nMinimal SPAKESecondFactor:\n"); -+ der_encode(&asn_DEF_SPAKESecondFactor, &factor_1, consume, NULL); -+ printbuf(); -+ -+ printf("\nMaximal SPAKESecondFactor:\n"); -+ der_encode(&asn_DEF_SPAKESecondFactor, &factor_2, consume, NULL); -+ printbuf(); -+ -+ printf("\nPA-SPAKE (support):\n"); -+ der_encode(&asn_DEF_PA_SPAKE, &pa_spake_1, consume, NULL); -+ printbuf(); -+ -+ printf("\nPA-SPAKE (challenge):\n"); -+ der_encode(&asn_DEF_PA_SPAKE, &pa_spake_2, consume, NULL); -+ printbuf(); -+ -+ printf("\nPA-SPAKE (response):\n"); -+ der_encode(&asn_DEF_PA_SPAKE, &pa_spake_3, consume, NULL); -+ printbuf(); -+ -+ printf("\nPA-SPAKE (encdata):\n"); -+ der_encode(&asn_DEF_PA_SPAKE, &pa_spake_4, consume, NULL); -+ printbuf(); -+ - printf("\n"); - return 0; - } -diff --git a/src/tests/asn.1/reference_encode.out b/src/tests/asn.1/reference_encode.out -index 824e0798b..a76deead2 100644 ---- a/src/tests/asn.1/reference_encode.out -+++ b/src/tests/asn.1/reference_encode.out -@@ -72,3 +72,9 @@ encode_krb5_kkdcp_message: 30 82 01 FC A0 82 01 EC 04 82 01 E8 6A 82 01 E4 30 82 - encode_krb5_cammac(optionals NULL): 30 12 A0 10 30 0E 30 0C A0 03 02 01 01 A1 05 04 03 61 64 31 - encode_krb5_cammac: 30 81 F2 A0 1E 30 1C 30 0C A0 03 02 01 01 A1 05 04 03 61 64 31 30 0C A0 03 02 01 02 A1 05 04 03 61 64 32 A1 3D 30 3B A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 03 02 01 05 A2 03 02 01 10 A3 13 30 11 A0 03 02 01 01 A1 0A 04 08 63 6B 73 75 6D 6B 64 63 A2 3D 30 3B A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 03 02 01 05 A2 03 02 01 10 A3 13 30 11 A0 03 02 01 01 A1 0A 04 08 63 6B 73 75 6D 73 76 63 A3 52 30 50 30 13 A3 11 30 0F A0 03 02 01 01 A1 08 04 06 63 6B 73 75 6D 31 30 39 A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 03 02 01 05 A2 03 02 01 10 A3 11 30 0F A0 03 02 01 01 A1 08 04 06 63 6B 73 75 6D 32 - encode_krb5_secure_cookie: 30 2C 02 04 2D F8 02 25 30 24 30 10 A1 03 02 01 0D A2 09 04 07 70 61 2D 64 61 74 61 30 10 A1 03 02 01 0D A2 09 04 07 70 61 2D 64 61 74 61 -+encode_krb5_spake_factor(optionals NULL): 30 05 A0 03 02 01 01 -+encode_krb5_spake_factor: 30 0E A0 03 02 01 02 A1 07 04 05 66 64 61 74 61 -+encode_krb5_pa_spake(support): A0 0C 30 0A A0 08 30 06 02 01 01 02 01 02 -+encode_krb5_pa_spake(challenge): A1 2D 30 2B A0 03 02 01 01 A1 09 04 07 54 20 76 61 6C 75 65 A2 19 30 17 30 05 A0 03 02 01 01 30 0E A0 03 02 01 02 A1 07 04 05 66 64 61 74 61 -+encode_krb5_pa_spake(response): A2 34 30 32 A0 09 04 07 53 20 76 61 6C 75 65 A1 25 30 23 A0 03 02 01 00 A1 03 02 01 05 A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65 -+encode_krb5_pa_spake(encdata): A3 25 30 23 A0 03 02 01 00 A1 03 02 01 05 A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65 -diff --git a/src/tests/asn.1/spake.asn1 b/src/tests/asn.1/spake.asn1 -new file mode 100644 -index 000000000..50718d8ad ---- /dev/null -+++ b/src/tests/asn.1/spake.asn1 -@@ -0,0 +1,44 @@ -+KerberosV5SPAKE { -+ iso(1) identified-organization(3) dod(6) internet(1) -+ security(5) kerberosV5(2) modules(4) spake(8) -+} DEFINITIONS EXPLICIT TAGS ::= BEGIN -+ -+IMPORTS -+ EncryptedData, Int32 -+ FROM KerberosV5Spec2 { iso(1) identified-organization(3) -+ dod(6) internet(1) security(5) kerberosV5(2) modules(4) -+ krb5spec2(2) }; -+ -- as defined in RFC 4120. -+ -+SPAKESupport ::= SEQUENCE { -+ groups [0] SEQUENCE (SIZE(1..MAX)) OF Int32, -+ ... -+} -+ -+SPAKEChallenge ::= SEQUENCE { -+ group [0] Int32, -+ pubkey [1] OCTET STRING, -+ factors [2] SEQUENCE (SIZE(1..MAX)) OF SPAKESecondFactor, -+ ... -+} -+ -+SPAKESecondFactor ::= SEQUENCE { -+ type [0] Int32, -+ data [1] OCTET STRING OPTIONAL -+} -+ -+SPAKEResponse ::= SEQUENCE { -+ pubkey [0] OCTET STRING, -+ factor [1] EncryptedData, -- SPAKESecondFactor -+ ... -+} -+ -+PA-SPAKE ::= CHOICE { -+ support [0] SPAKESupport, -+ challenge [1] SPAKEChallenge, -+ response [2] SPAKEResponse, -+ encdata [3] EncryptedData, -+ ... -+} -+ -+END -diff --git a/src/tests/asn.1/trval_reference.out b/src/tests/asn.1/trval_reference.out -index c27a0425b..e5c715924 100644 ---- a/src/tests/asn.1/trval_reference.out -+++ b/src/tests/asn.1/trval_reference.out -@@ -1584,3 +1584,53 @@ encode_krb5_secure_cookie: - . . [Sequence/Sequence Of] - . . . [1] [Integer] 13 - . . . [2] [Octet String] "pa-data" -+ -+encode_krb5_spake_factor(optionals NULL): -+ -+[Sequence/Sequence Of] -+. [0] [Integer] 1 -+ -+encode_krb5_spake_factor: -+ -+[Sequence/Sequence Of] -+. [0] [Integer] 2 -+. [1] [Octet String] "fdata" -+ -+encode_krb5_pa_spake(support): -+ -+[CONT 0] -+. [Sequence/Sequence Of] -+. . [0] [Sequence/Sequence Of] -+. . . [Integer] 1 -+. . . [Integer] 2 -+ -+encode_krb5_pa_spake(challenge): -+ -+[CONT 1] -+. [Sequence/Sequence Of] -+. . [0] [Integer] 1 -+. . [1] [Octet String] "T value" -+. . [2] [Sequence/Sequence Of] -+. . . [Sequence/Sequence Of] -+. . . . [0] [Integer] 1 -+. . . [Sequence/Sequence Of] -+. . . . [0] [Integer] 2 -+. . . . [1] [Octet String] "fdata" -+ -+encode_krb5_pa_spake(response): -+ -+[CONT 2] -+. [Sequence/Sequence Of] -+. . [0] [Octet String] "S value" -+. . [1] [Sequence/Sequence Of] -+. . . [0] [Integer] 0 -+. . . [1] [Integer] 5 -+. . . [2] [Octet String] "krbASN.1 test message" -+ -+encode_krb5_pa_spake(encdata): -+ -+[CONT 3] -+. [Sequence/Sequence Of] -+. . [0] [Integer] 0 -+. . [1] [Integer] 5 -+. . [2] [Octet String] "krbASN.1 test message" diff --git a/Add-PKINIT-KDC-support-for-freshness-token.patch b/Add-PKINIT-KDC-support-for-freshness-token.patch deleted file mode 100644 index 70782fb..0000000 --- a/Add-PKINIT-KDC-support-for-freshness-token.patch +++ /dev/null @@ -1,631 +0,0 @@ -From c93112a19f73b9a984cabd320129ee8f70cb4823 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 12 Mar 2018 11:31:46 -0400 -Subject: [PATCH] Add PKINIT KDC support for freshness token - -Send a freshness token in the preauth hint list if PKINIT is -configured and the request padata indicates support. Verify the -freshness token if the client includes one in a PKINIT request, and -log whether one was received. If pkinit_require_freshness is set to -true in the realm config, reject non-anonymous requests which don't -contain a freshness token. - -Add freshness token tests to t_pkinit.py with some related changes. -Remove client long-term keys after testing password preauth so we get -better error reporting when pkinit_require_freshness is set and a -token is not sent. Remove ./responder invocations for test cases -which don't ask PKINIT responder questions, or else the responder -would fail now that it isn't being asked for the password. Leave -anonymous PKINIT enabled after the anonymous tests so that we can use -it again when testing enforcement of pkinit_require_freshness. Add -expected trace messages for the basic test, including one for -receiving a freshness token. Add minimal expected trace messages for -the RSA test. - -ticket: 8648 -(cherry picked from commit 4a9050df0bc34bfb08ba24462d6e2514640f4b8e) ---- - doc/admin/conf_files/kdc_conf.rst | 4 + - doc/admin/pkinit.rst | 25 +++++ - doc/appdev/refs/macros/index.rst | 2 + - doc/formats/freshness_token.rst | 19 ++++ - doc/formats/index.rst | 1 + - src/include/krb5/kdcpreauth_plugin.h | 17 ++++ - src/include/krb5/krb5.hin | 3 + - src/kdc/do_as_req.c | 2 + - src/kdc/kdc_preauth.c | 130 +++++++++++++++++++++++- - src/kdc/kdc_util.h | 2 + - src/plugins/preauth/pkinit/pkinit.h | 2 + - src/plugins/preauth/pkinit/pkinit_srv.c | 51 +++++++++- - src/tests/t_pkinit.py | 50 ++++++--- - 13 files changed, 292 insertions(+), 16 deletions(-) - create mode 100644 doc/formats/freshness_token.rst - -diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst -index 3af1c3796..1ac1a37c2 100644 ---- a/doc/admin/conf_files/kdc_conf.rst -+++ b/doc/admin/conf_files/kdc_conf.rst -@@ -798,6 +798,10 @@ For information about the syntax of some of these options, see - **pkinit_require_crl_checking** should be set to true if the - policy is such that up-to-date CRLs must be present for every CA. - -+**pkinit_require_freshness** -+ Specifies whether to require clients to include a freshness token -+ in PKINIT requests. The default value is false. (New in release -+ 1.17.) - - .. _Encryption_types: - -diff --git a/doc/admin/pkinit.rst b/doc/admin/pkinit.rst -index c601c5c9e..bec4fc800 100644 ---- a/doc/admin/pkinit.rst -+++ b/doc/admin/pkinit.rst -@@ -327,3 +327,28 @@ appropriate :ref:`kdc_realms` subsection of the KDC's - To obtain anonymous credentials on a client, run ``kinit -n``, or - ``kinit -n @REALMNAME`` to specify a realm. The resulting tickets - will have the client name ``WELLKNOWN/ANONYMOUS@WELLKNOWN:ANONYMOUS``. -+ -+ -+Freshness tokens -+---------------- -+ -+Freshness tokens can ensure that the client has recently had access to -+its certificate private key. If freshness tokens are not required by -+the KDC, a client program with temporary possession of the private key -+can compose requests for future timestamps and use them later. -+ -+In release 1.17 and later, freshness tokens are supported by the -+client and are sent by the KDC when the client indicates support for -+them. Because not all clients support freshness tokens yet, they are -+not required by default. To check if freshness tokens are supported -+by a realm's clients, look in the KDC logs for the lines:: -+ -+ PKINIT: freshness token received from -+ PKINIT: no freshness token received from -+ -+To require freshness tokens for all clients in a realm (except for -+clients authenticating anonymously), set the -+**pkinit_require_freshness** variable to ``true`` in the appropriate -+:ref:`kdc_realms` subsection of the KDC's :ref:`kdc.conf(5)` file. To -+test that this option is in effect, run ``kinit -X disable_freshness`` -+and verify that authentication is unsuccessful. -diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst -index e76747102..dba818b26 100644 ---- a/doc/appdev/refs/macros/index.rst -+++ b/doc/appdev/refs/macros/index.rst -@@ -181,6 +181,7 @@ Public - KRB5_KEYUSAGE_KRB_ERROR_CKSUM.rst - KRB5_KEYUSAGE_KRB_PRIV_ENCPART.rst - KRB5_KEYUSAGE_KRB_SAFE_CKSUM.rst -+ KRB5_KEYUSAGE_PA_AS_FRESHNESS.rst - KRB5_KEYUSAGE_PA_FX_COOKIE.rst - KRB5_KEYUSAGE_PA_OTP_REQUEST.rst - KRB5_KEYUSAGE_PA_PKINIT_KX.rst -@@ -241,6 +242,7 @@ Public - KRB5_PADATA_AFS3_SALT.rst - KRB5_PADATA_AP_REQ.rst - KRB5_PADATA_AS_CHECKSUM.rst -+ KRB5_PADATA_AS_FRESHNESS.rst - KRB5_PADATA_ENCRYPTED_CHALLENGE.rst - KRB5_PADATA_ENC_SANDIA_SECURID.rst - KRB5_PADATA_ENC_TIMESTAMP.rst -diff --git a/doc/formats/freshness_token.rst b/doc/formats/freshness_token.rst -new file mode 100644 -index 000000000..3127621a9 ---- /dev/null -+++ b/doc/formats/freshness_token.rst -@@ -0,0 +1,19 @@ -+PKINIT freshness tokens -+======================= -+ -+:rfc:`8070` specifies a pa-data type PA_AS_FRESHNESS, which clients -+should reflect within signed PKINIT data to prove recent access to the -+client certificate private key. The contents of a freshness token are -+left to the KDC implementation. The MIT krb5 KDC uses the following -+format for freshness tokens (starting in release 1.17): -+ -+* a four-byte big-endian POSIX timestamp -+* a four-byte big-endian key version number -+* an :rfc:`3961` checksum, with no ASN.1 wrapper -+ -+The checksum is computed using the first key in the local krbtgt -+principal entry for the realm (e.g. ``krbtgt/KRBTEST.COM@KRBTEST.COM`` -+if the request is to the ``KRBTEST.COM`` realm) of the indicated key -+version. The checksum type must be the mandatory checksum type for -+the encryption type of the krbtgt key. The key usage value for the -+checksum is 514. -diff --git a/doc/formats/index.rst b/doc/formats/index.rst -index 8b30626d4..4ad534424 100644 ---- a/doc/formats/index.rst -+++ b/doc/formats/index.rst -@@ -7,3 +7,4 @@ Protocols and file formats - ccache_file_format - keytab_file_format - cookie -+ freshness_token -diff --git a/src/include/krb5/kdcpreauth_plugin.h b/src/include/krb5/kdcpreauth_plugin.h -index f38820099..3a4754234 100644 ---- a/src/include/krb5/kdcpreauth_plugin.h -+++ b/src/include/krb5/kdcpreauth_plugin.h -@@ -240,6 +240,23 @@ typedef struct krb5_kdcpreauth_callbacks_st { - - /* End of version 4 kdcpreauth callbacks. */ - -+ /* -+ * Instruct the KDC to send a freshness token in the method data -+ * accompanying a PREAUTH_REQUIRED or PREAUTH_FAILED error, if the client -+ * indicated support for freshness tokens. This callback should only be -+ * invoked from the edata method. -+ */ -+ void (*send_freshness_token)(krb5_context context, -+ krb5_kdcpreauth_rock rock); -+ -+ /* Validate a freshness token sent by the client. Return 0 on success, -+ * KRB5KDC_ERR_PREAUTH_EXPIRED on error. */ -+ krb5_error_code (*check_freshness_token)(krb5_context context, -+ krb5_kdcpreauth_rock rock, -+ const krb5_data *token); -+ -+ /* End of version 5 kdcpreauth callbacks. */ -+ - } *krb5_kdcpreauth_callbacks; - - /* Optional: preauth plugin initialization function. */ -diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 833e72335..a650ecece 100644 ---- a/src/include/krb5/krb5.hin -+++ b/src/include/krb5/krb5.hin -@@ -1035,7 +1035,10 @@ krb5_c_keyed_checksum_types(krb5_context context, krb5_enctype enctype, - #define KRB5_KEYUSAGE_AS_REQ 56 - #define KRB5_KEYUSAGE_CAMMAC 64 - -+/* Key usage values 512-1023 are reserved for uses internal to a Kerberos -+ * implementation. */ - #define KRB5_KEYUSAGE_PA_FX_COOKIE 513 /**< Used for encrypted FAST cookies */ -+#define KRB5_KEYUSAGE_PA_AS_FRESHNESS 514 /**< Used for freshness tokens */ - /** @} */ /* end of KRB5_KEYUSAGE group */ - - /** -diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c -index 7c8da63e1..588c1375a 100644 ---- a/src/kdc/do_as_req.c -+++ b/src/kdc/do_as_req.c -@@ -563,6 +563,7 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, - state->rock.rstate = state->rstate; - state->rock.vctx = vctx; - state->rock.auth_indicators = &state->auth_indicators; -+ state->rock.send_freshness_token = FALSE; - if (!state->request->client) { - state->status = "NULL_CLIENT"; - errcode = KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN; -@@ -659,6 +660,7 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, - state->status = "GET_LOCAL_TGT"; - goto errout; - } -+ state->rock.local_tgt = state->local_tgt; - - au_state->stage = VALIDATE_POL; - -diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c -index 6f34dc289..80b130222 100644 ---- a/src/kdc/kdc_preauth.c -+++ b/src/kdc/kdc_preauth.c -@@ -87,6 +87,9 @@ - #include - #include - -+/* Let freshness tokens be valid for ten minutes. */ -+#define FRESHNESS_LIFETIME 600 -+ - typedef struct preauth_system_st { - const char *name; - int type; -@@ -497,8 +500,68 @@ client_name(krb5_context context, krb5_kdcpreauth_rock rock) - return rock->client->princ; - } - -+static void -+send_freshness_token(krb5_context context, krb5_kdcpreauth_rock rock) -+{ -+ rock->send_freshness_token = TRUE; -+} -+ -+static krb5_error_code -+check_freshness_token(krb5_context context, krb5_kdcpreauth_rock rock, -+ const krb5_data *token) -+{ -+ krb5_timestamp token_ts, now; -+ krb5_key_data *kd; -+ krb5_keyblock kb; -+ krb5_kvno token_kvno; -+ krb5_checksum cksum; -+ krb5_data d; -+ uint8_t *token_cksum; -+ size_t token_cksum_len; -+ krb5_boolean valid = FALSE; -+ char ckbuf[4]; -+ -+ memset(&kb, 0, sizeof(kb)); -+ -+ if (krb5_timeofday(context, &now) != 0) -+ goto cleanup; -+ -+ if (token->length <= 8) -+ goto cleanup; -+ token_ts = load_32_be(token->data); -+ token_kvno = load_32_be(token->data + 4); -+ token_cksum = (uint8_t *)token->data + 8; -+ token_cksum_len = token->length - 8; -+ -+ /* Check if the token timestamp is too old. */ -+ if (ts_after(now, ts_incr(token_ts, FRESHNESS_LIFETIME))) -+ goto cleanup; -+ -+ /* Fetch and decrypt the local krbtgt key of the token's kvno. */ -+ if (krb5_dbe_find_enctype(context, rock->local_tgt, -1, -1, token_kvno, -+ &kd) != 0) -+ goto cleanup; -+ if (krb5_dbe_decrypt_key_data(context, NULL, kd, &kb, NULL) != 0) -+ goto cleanup; -+ -+ /* Verify the token checksum against the current KDC time. The checksum -+ * must use the mandatory checksum type of the krbtgt key's enctype. */ -+ store_32_be(token_ts, ckbuf); -+ d = make_data(ckbuf, sizeof(ckbuf)); -+ cksum.magic = KV5M_CHECKSUM; -+ cksum.checksum_type = 0; -+ cksum.length = token_cksum_len; -+ cksum.contents = token_cksum; -+ (void)krb5_c_verify_checksum(context, &kb, KRB5_KEYUSAGE_PA_AS_FRESHNESS, -+ &d, &cksum, &valid); -+ -+cleanup: -+ krb5_free_keyblock_contents(context, &kb); -+ return valid ? 0 : KRB5KDC_ERR_PREAUTH_EXPIRED; -+} -+ - static struct krb5_kdcpreauth_callbacks_st callbacks = { -- 4, -+ 5, - max_time_skew, - client_keys, - free_keys, -@@ -514,7 +577,9 @@ static struct krb5_kdcpreauth_callbacks_st callbacks = { - get_cookie, - set_cookie, - match_client, -- client_name -+ client_name, -+ send_freshness_token, -+ check_freshness_token - }; - - static krb5_error_code -@@ -770,6 +835,62 @@ cleanup: - return ret; - } - -+static krb5_error_code -+add_freshness_token(krb5_context context, krb5_kdcpreauth_rock rock, -+ krb5_pa_data ***pa_list) -+{ -+ krb5_error_code ret; -+ krb5_timestamp now; -+ krb5_key_data *kd; -+ krb5_keyblock kb; -+ krb5_checksum cksum; -+ krb5_data d; -+ krb5_pa_data *pa; -+ char ckbuf[4]; -+ -+ memset(&cksum, 0, sizeof(cksum)); -+ memset(&kb, 0, sizeof(kb)); -+ -+ if (!rock->send_freshness_token) -+ return 0; -+ if (krb5int_find_pa_data(context, rock->request->padata, -+ KRB5_PADATA_AS_FRESHNESS) == NULL) -+ return 0; -+ -+ /* Fetch and decrypt the current local krbtgt key. */ -+ ret = krb5_dbe_find_enctype(context, rock->local_tgt, -1, -1, 0, &kd); -+ if (ret) -+ goto cleanup; -+ ret = krb5_dbe_decrypt_key_data(context, NULL, kd, &kb, NULL); -+ if (ret) -+ goto cleanup; -+ -+ /* Compute a checksum over the current KDC time. */ -+ ret = krb5_timeofday(context, &now); -+ if (ret) -+ goto cleanup; -+ store_32_be(now, ckbuf); -+ d = make_data(ckbuf, sizeof(ckbuf)); -+ ret = krb5_c_make_checksum(context, 0, &kb, KRB5_KEYUSAGE_PA_AS_FRESHNESS, -+ &d, &cksum); -+ -+ /* Compose a freshness token from the time, krbtgt kvno, and checksum. */ -+ ret = alloc_pa_data(KRB5_PADATA_AS_FRESHNESS, 8 + cksum.length, &pa); -+ if (ret) -+ goto cleanup; -+ store_32_be(now, pa->contents); -+ store_32_be(kd->key_data_kvno, pa->contents + 4); -+ memcpy(pa->contents + 8, cksum.contents, cksum.length); -+ -+ /* add_pa_data_element() claims pa on success or failure. */ -+ ret = add_pa_data_element(pa_list, pa); -+ -+cleanup: -+ krb5_free_keyblock_contents(context, &kb); -+ krb5_free_checksum_contents(context, &cksum); -+ return ret; -+} -+ - struct hint_state { - kdc_hint_respond_fn respond; - void *arg; -@@ -792,6 +913,11 @@ hint_list_finish(struct hint_state *state, krb5_error_code code) - void *oldarg = state->arg; - kdc_realm_t *kdc_active_realm = state->realm; - -+ /* Add a freshness token if a preauth module requested it and the client -+ * request indicates support for it. */ -+ if (!code) -+ code = add_freshness_token(kdc_context, state->rock, &state->pa_data); -+ - if (!code) { - if (state->pa_data == NULL) { - krb5_klog_syslog(LOG_INFO, -diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index 198eab9c4..1885c9f80 100644 ---- a/src/kdc/kdc_util.h -+++ b/src/kdc/kdc_util.h -@@ -426,11 +426,13 @@ struct krb5_kdcpreauth_rock_st { - krb5_kdc_req *request; - krb5_data *inner_body; - krb5_db_entry *client; -+ krb5_db_entry *local_tgt; - krb5_key_data *client_key; - krb5_keyblock *client_keyblock; - struct kdc_request_state *rstate; - verto_ctx *vctx; - krb5_data ***auth_indicators; -+ krb5_boolean send_freshness_token; - }; - - #define isflagset(flagfield, flag) (flagfield & (flag)) -diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h -index 8489a3e23..fe2ec0d31 100644 ---- a/src/plugins/preauth/pkinit/pkinit.h -+++ b/src/plugins/preauth/pkinit/pkinit.h -@@ -77,6 +77,7 @@ - #define KRB5_CONF_PKINIT_KDC_OCSP "pkinit_kdc_ocsp" - #define KRB5_CONF_PKINIT_POOL "pkinit_pool" - #define KRB5_CONF_PKINIT_REQUIRE_CRL_CHECKING "pkinit_require_crl_checking" -+#define KRB5_CONF_PKINIT_REQUIRE_FRESHNESS "pkinit_require_freshness" - #define KRB5_CONF_PKINIT_REVOKE "pkinit_revoke" - - /* Make pkiDebug(fmt,...) print, or not. */ -@@ -148,6 +149,7 @@ typedef struct _pkinit_plg_opts { - int allow_upn; /* allow UPN-SAN instead of pkinit-SAN */ - int dh_or_rsa; /* selects DH or RSA based pkinit */ - int require_crl_checking; /* require CRL for a CA (default is false) */ -+ int require_freshness; /* require freshness token (default is false) */ - int disable_freshness; /* disable freshness token on client for testing */ - int dh_min_bits; /* minimum DH modulus size allowed */ - } pkinit_plg_opts; -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index 8aa4d8b49..76ad5bf19 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -161,6 +161,10 @@ pkinit_server_get_edata(krb5_context context, - if (plgctx == NULL) - retval = EINVAL; - -+ /* Send a freshness token if the client requested one. */ -+ if (!retval) -+ cb->send_freshness_token(context, rock); -+ - (*respond)(arg, retval, NULL); - } - -@@ -403,6 +407,31 @@ cleanup: - return ret; - } - -+/* Return an error if freshness tokens are required and one was not received. -+ * Log an appropriate message indicating whether a valid token was received. */ -+static krb5_error_code -+check_log_freshness(krb5_context context, pkinit_kdc_context plgctx, -+ krb5_kdc_req *request, krb5_boolean valid_freshness_token) -+{ -+ krb5_error_code ret; -+ char *name = NULL; -+ -+ ret = krb5_unparse_name(context, request->client, &name); -+ if (ret) -+ return ret; -+ if (plgctx->opts->require_freshness && !valid_freshness_token) { -+ com_err("", 0, _("PKINIT: no freshness token, rejecting auth from %s"), -+ name); -+ ret = KRB5KDC_ERR_PREAUTH_FAILED; -+ } else if (valid_freshness_token) { -+ com_err("", 0, _("PKINIT: freshness token received from %s"), name); -+ } else { -+ com_err("", 0, _("PKINIT: no freshness token received from %s"), name); -+ } -+ krb5_free_unparsed_name(context, name); -+ return ret; -+} -+ - static void - pkinit_server_verify_padata(krb5_context context, - krb5_data *req_pkt, -@@ -425,10 +454,11 @@ pkinit_server_verify_padata(krb5_context context, - pkinit_kdc_req_context reqctx = NULL; - krb5_checksum cksum = {0, 0, 0, NULL}; - krb5_data *der_req = NULL; -- krb5_data k5data; -+ krb5_data k5data, *ftoken; - int is_signed = 1; - krb5_pa_data **e_data = NULL; - krb5_kdcpreauth_modreq modreq = NULL; -+ krb5_boolean valid_freshness_token = FALSE; - char **sp; - - pkiDebug("pkinit_verify_padata: entered!\n"); -@@ -599,6 +629,14 @@ pkinit_server_verify_padata(krb5_context context, - goto cleanup; - } - -+ ftoken = auth_pack->pkAuthenticator.freshnessToken; -+ if (ftoken != NULL) { -+ retval = cb->check_freshness_token(context, rock, ftoken); -+ if (retval) -+ goto cleanup; -+ valid_freshness_token = TRUE; -+ } -+ - /* check if kdcPkId present and match KDC's subjectIdentifier */ - if (reqp->kdcPkId.data != NULL) { - int valid_kdcPkId = 0; -@@ -641,6 +679,13 @@ pkinit_server_verify_padata(krb5_context context, - break; - } - -+ if (is_signed) { -+ retval = check_log_freshness(context, plgctx, request, -+ valid_freshness_token); -+ if (retval) -+ goto cleanup; -+ } -+ - if (is_signed && plgctx->auth_indicators != NULL) { - /* Assert configured authentication indicators. */ - for (sp = plgctx->auth_indicators; *sp != NULL; sp++) { -@@ -1330,6 +1375,10 @@ pkinit_init_kdc_profile(krb5_context context, pkinit_kdc_context plgctx) - KRB5_CONF_PKINIT_REQUIRE_CRL_CHECKING, - 0, &plgctx->opts->require_crl_checking); - -+ pkinit_kdcdefault_boolean(context, plgctx->realmname, -+ KRB5_CONF_PKINIT_REQUIRE_FRESHNESS, -+ 0, &plgctx->opts->require_freshness); -+ - pkinit_kdcdefault_string(context, plgctx->realmname, - KRB5_CONF_PKINIT_EKU_CHECKING, - &eku_string); -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index 86fe661a0..5bc60cb1e 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -39,6 +39,8 @@ pkinit_kdc_conf = {'realms': {'$realm': { - 'pkinit_indicator': ['indpkinit1', 'indpkinit2']}}} - restrictive_kdc_conf = {'realms': {'$realm': { - 'restrict_anonymous_to_tgt': 'true' }}} -+freshness_kdc_conf = {'realms': {'$realm': { -+ 'pkinit_require_freshness': 'true'}}} - - testprincs = {'krbtgt/KRBTEST.COM': {'keys': 'aes128-cts'}, - 'user': {'keys': 'aes128-cts', 'flags': '+preauth'}, -@@ -118,6 +120,10 @@ realm.kinit(realm.user_princ, password=password('user')) - realm.klist(realm.user_princ) - realm.run([kvno, realm.host_princ]) - -+# Having tested password preauth, remove the keys for better error -+# reporting. -+realm.run([kadminl, 'purgekeys', '-all', realm.user_princ]) -+ - # Test anonymous PKINIT. - realm.kinit('@%s' % realm.realm, flags=['-n'], expected_code=1, - expected_msg='not found in Kerberos database') -@@ -153,23 +159,32 @@ realm.run([kvno, realm.host_princ], expected_code=1, - realm.kinit(realm.host_princ, flags=['-k']) - realm.run([kvno, '-U', 'user', realm.host_princ]) - --# Go back to a normal KDC and disable anonymous PKINIT. -+# Go back to the normal KDC environment. - realm.stop_kdc() - realm.start_kdc() --realm.run([kadminl, 'delprinc', 'WELLKNOWN/ANONYMOUS']) - - # Run the basic test - PKINIT with FILE: identity, with no password on the key. --realm.run(['./responder', '-x', 'pkinit=', -- '-X', 'X509_user_identity=%s' % file_identity, realm.user_princ]) - realm.kinit(realm.user_princ, -- flags=['-X', 'X509_user_identity=%s' % file_identity]) -+ flags=['-X', 'X509_user_identity=%s' % file_identity], -+ expected_trace=('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Preauthenticating using KDC method data', -+ 'PKINIT client received freshness token from KDC', -+ 'PKINIT loading CA certs and CRLs from FILE', -+ 'PKINIT client making DH request', -+ 'Produced preauth for next request: 133, 16', -+ 'PKINIT client verified DH reply', -+ 'PKINIT client found id-pkinit-san in KDC cert', -+ 'PKINIT client matched KDC principal krbtgt/')) - realm.klist(realm.user_princ) - realm.run([kvno, realm.host_princ]) - - # Try again using RSA instead of DH. - realm.kinit(realm.user_princ, - flags=['-X', 'X509_user_identity=%s' % file_identity, -- '-X', 'flag_RSA_PROTOCOL=yes']) -+ '-X', 'flag_RSA_PROTOCOL=yes'], -+ expected_trace=('PKINIT client making RSA request', -+ 'PKINIT client verified RSA reply')) - realm.klist(realm.user_princ) - - # Test a DH parameter renegotiation by temporarily setting a 4096-bit -@@ -192,8 +207,23 @@ expected_trace = ('Sending unauthenticated request', - realm.kinit(realm.user_princ, - flags=['-X', 'X509_user_identity=%s' % file_identity], - expected_trace=expected_trace) -+ -+# Test enforcement of required freshness tokens. (We can leave -+# freshness tokens required after this test.) -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % file_identity, -+ '-X', 'disable_freshness=yes']) -+f_env = realm.special_env('freshness', True, kdc_conf=freshness_kdc_conf) - realm.stop_kdc() --realm.start_kdc() -+realm.start_kdc(env=f_env) -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % file_identity]) -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % file_identity, -+ '-X', 'disable_freshness=yes'], -+ expected_code=1, expected_msg='Preauthentication failed') -+# Anonymous should never require a freshness token. -+realm.kinit('@%s' % realm.realm, flags=['-n', '-X', 'disable_freshness=yes']) - - # Run the basic test - PKINIT with FILE: identity, with a password on the key, - # supplied by the prompter. -@@ -229,8 +259,6 @@ shutil.copy(privkey_pem, os.path.join(path, 'user.key')) - shutil.copy(privkey_enc_pem, os.path.join(path_enc, 'user.key')) - shutil.copy(user_pem, os.path.join(path, 'user.crt')) - shutil.copy(user_pem, os.path.join(path_enc, 'user.crt')) --realm.run(['./responder', '-x', 'pkinit=', '-X', -- 'X509_user_identity=%s' % dir_identity, realm.user_princ]) - realm.kinit(realm.user_princ, - flags=['-X', 'X509_user_identity=%s' % dir_identity]) - realm.klist(realm.user_princ) -@@ -262,8 +290,6 @@ realm.klist(realm.user_princ) - realm.run([kvno, realm.host_princ]) - - # PKINIT with PKCS12: identity, with no password on the bundle. --realm.run(['./responder', '-x', 'pkinit=', -- '-X', 'X509_user_identity=%s' % p12_identity, realm.user_princ]) - realm.kinit(realm.user_princ, - flags=['-X', 'X509_user_identity=%s' % p12_identity]) - realm.klist(realm.user_princ) -@@ -357,8 +383,6 @@ conf = open(softpkcs11rc, 'w') - conf.write("%s\t%s\t%s\t%s\n" % ('user', 'user token', user_pem, privkey_pem)) - conf.close() - # Expect to succeed without having to supply any more information. --realm.run(['./responder', '-x', 'pkinit=', -- '-X', 'X509_user_identity=%s' % p11_identity, realm.user_princ]) - realm.kinit(realm.user_princ, - flags=['-X', 'X509_user_identity=%s' % p11_identity]) - realm.klist(realm.user_princ) diff --git a/Add-PKINIT-client-support-for-freshness-token.patch b/Add-PKINIT-client-support-for-freshness-token.patch deleted file mode 100644 index 1a00819..0000000 --- a/Add-PKINIT-client-support-for-freshness-token.patch +++ /dev/null @@ -1,336 +0,0 @@ -From 5edc6de93196b4f07da6695a4b271a067000c84d Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 31 Jan 2017 17:02:34 -0500 -Subject: [PATCH] Add PKINIT client support for freshness token - -Send an empty PA_AS_FRESHNESS padata item in unauthenticated AS -requests to indicate support for RFC 8070. If the KDC includes a -PA_AS_FRESHNESS value in its method data, echo it back in the new -freshnessToken field of pkAuthenticator - -ticket: 8648 -(cherry picked from commit 085785362e01467cb25c79a90dcebfba9ea019d8) ---- - doc/user/user_commands/kinit.rst | 3 +++ - src/include/k5-int-pkinit.h | 1 + - src/include/krb5/krb5.hin | 1 + - src/lib/krb5/asn.1/asn1_k_encode.c | 5 ++++- - src/lib/krb5/krb/get_in_tkt.c | 12 ++++++++---- - src/lib/krb5/krb/init_creds_ctx.h | 2 +- - src/plugins/preauth/pkinit/pkinit.h | 3 +++ - src/plugins/preauth/pkinit/pkinit_clnt.c | 19 ++++++++++++++++++- - src/plugins/preauth/pkinit/pkinit_lib.c | 3 +++ - src/plugins/preauth/pkinit/pkinit_trace.h | 2 ++ - src/tests/asn.1/ktest.c | 4 ++++ - src/tests/asn.1/pkinit_encode.out | 2 +- - src/tests/asn.1/pkinit_trval.out | 1 + - 13 files changed, 50 insertions(+), 8 deletions(-) - -diff --git a/doc/user/user_commands/kinit.rst b/doc/user/user_commands/kinit.rst -index 3f9d5340f..1f696920f 100644 ---- a/doc/user/user_commands/kinit.rst -+++ b/doc/user/user_commands/kinit.rst -@@ -197,6 +197,9 @@ OPTIONS - specify use of RSA, rather than the default Diffie-Hellman - protocol - -+ **disable_freshness**\ [**=yes**] -+ disable sending freshness tokens (for testing purposes only) -+ - - ENVIRONMENT - ----------- -diff --git a/src/include/k5-int-pkinit.h b/src/include/k5-int-pkinit.h -index 7b2f595cb..4622a629e 100644 ---- a/src/include/k5-int-pkinit.h -+++ b/src/include/k5-int-pkinit.h -@@ -42,6 +42,7 @@ typedef struct _krb5_pk_authenticator { - krb5_timestamp ctime; - krb5_int32 nonce; /* (0..4294967295) */ - krb5_checksum paChecksum; -+ krb5_data *freshnessToken; - } krb5_pk_authenticator; - - /* PKAuthenticator draft9 */ -diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index e81bb0a6d..833e72335 100644 ---- a/src/include/krb5/krb5.hin -+++ b/src/include/krb5/krb5.hin -@@ -1879,6 +1879,7 @@ krb5_verify_checksum(krb5_context context, krb5_cksumtype ctype, - #define KRB5_PADATA_OTP_PIN_CHANGE 144 /**< RFC 6560 section 4.3 */ - #define KRB5_PADATA_PKINIT_KX 147 /**< RFC 6112 */ - #define KRB5_ENCPADATA_REQ_ENC_PA_REP 149 /**< RFC 6806 */ -+#define KRB5_PADATA_AS_FRESHNESS 150 /**< RFC 8070 */ - - #define KRB5_SAM_USE_SAD_AS_KEY 0x80000000 - #define KRB5_SAM_SEND_ENCRYPTED_SAD 0x40000000 -diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c -index 889460989..3b23fe34a 100644 ---- a/src/lib/krb5/asn.1/asn1_k_encode.c -+++ b/src/lib/krb5/asn.1/asn1_k_encode.c -@@ -1442,9 +1442,12 @@ DEFFIELD(pk_authenticator_1, krb5_pk_authenticator, ctime, 1, kerberos_time); - DEFFIELD(pk_authenticator_2, krb5_pk_authenticator, nonce, 2, int32); - DEFFIELD(pk_authenticator_3, krb5_pk_authenticator, paChecksum, 3, - ostring_checksum); -+DEFFIELD(pk_authenticator_4, krb5_pk_authenticator, freshnessToken, 4, -+ opt_ostring_data_ptr); - static const struct atype_info *pk_authenticator_fields[] = { - &k5_atype_pk_authenticator_0, &k5_atype_pk_authenticator_1, -- &k5_atype_pk_authenticator_2, &k5_atype_pk_authenticator_3 -+ &k5_atype_pk_authenticator_2, &k5_atype_pk_authenticator_3, -+ &k5_atype_pk_authenticator_4 - }; - DEFSEQTYPE(pk_authenticator, krb5_pk_authenticator, pk_authenticator_fields); - -diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c -index 47a00bf2c..1d96ff163 100644 ---- a/src/lib/krb5/krb/get_in_tkt.c -+++ b/src/lib/krb5/krb/get_in_tkt.c -@@ -895,7 +895,7 @@ krb5_init_creds_init(krb5_context context, - ctx->request = k5alloc(sizeof(krb5_kdc_req), &code); - if (code != 0) - goto cleanup; -- ctx->enc_pa_rep_permitted = TRUE; -+ ctx->info_pa_permitted = TRUE; - code = krb5_copy_principal(context, client, &ctx->request->client); - if (code != 0) - goto cleanup; -@@ -1389,7 +1389,11 @@ init_creds_step_request(krb5_context context, - krb5_free_data(context, ctx->encoded_previous_request); - ctx->encoded_previous_request = NULL; - } -- if (ctx->enc_pa_rep_permitted) { -+ if (ctx->info_pa_permitted) { -+ code = add_padata(&ctx->request->padata, KRB5_PADATA_AS_FRESHNESS, -+ NULL, 0); -+ if (code) -+ goto cleanup; - code = add_padata(&ctx->request->padata, KRB5_ENCPADATA_REQ_ENC_PA_REP, - NULL, 0); - } -@@ -1530,7 +1534,7 @@ init_creds_step_reply(krb5_context context, - ctx->selected_preauth_type == KRB5_PADATA_NONE) { - /* The KDC didn't like our informational padata (probably a pre-1.7 - * MIT krb5 KDC). Retry without it. */ -- ctx->enc_pa_rep_permitted = FALSE; -+ ctx->info_pa_permitted = FALSE; - ctx->restarted = TRUE; - code = restart_init_creds_loop(context, ctx, FALSE); - } else if (reply_code == KDC_ERR_PREAUTH_EXPIRED) { -@@ -1574,7 +1578,7 @@ init_creds_step_reply(krb5_context context, - goto cleanup; - /* Reset per-realm negotiation state. */ - ctx->restarted = FALSE; -- ctx->enc_pa_rep_permitted = TRUE; -+ ctx->info_pa_permitted = TRUE; - code = restart_init_creds_loop(context, ctx, FALSE); - } else { - if (retry && ctx->selected_preauth_type != KRB5_PADATA_NONE) { -diff --git a/src/lib/krb5/krb/init_creds_ctx.h b/src/lib/krb5/krb/init_creds_ctx.h -index fe769685b..b19410a13 100644 ---- a/src/lib/krb5/krb/init_creds_ctx.h -+++ b/src/lib/krb5/krb/init_creds_ctx.h -@@ -58,7 +58,7 @@ struct _krb5_init_creds_context { - krb5_data s2kparams; - krb5_keyblock as_key; - krb5_enctype etype; -- krb5_boolean enc_pa_rep_permitted; -+ krb5_boolean info_pa_permitted; - krb5_boolean restarted; - struct krb5_responder_context_st rctx; - krb5_preauthtype selected_preauth_type; -diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h -index f3de9ad7a..8489a3e23 100644 ---- a/src/plugins/preauth/pkinit/pkinit.h -+++ b/src/plugins/preauth/pkinit/pkinit.h -@@ -148,6 +148,7 @@ typedef struct _pkinit_plg_opts { - int allow_upn; /* allow UPN-SAN instead of pkinit-SAN */ - int dh_or_rsa; /* selects DH or RSA based pkinit */ - int require_crl_checking; /* require CRL for a CA (default is false) */ -+ int disable_freshness; /* disable freshness token on client for testing */ - int dh_min_bits; /* minimum DH modulus size allowed */ - } pkinit_plg_opts; - -@@ -162,6 +163,7 @@ typedef struct _pkinit_req_opts { - int require_crl_checking; - int dh_size; /* initial request DH modulus size (default=1024) */ - int require_hostname_match; -+ int disable_freshness; - } pkinit_req_opts; - - /* -@@ -214,6 +216,7 @@ struct _pkinit_req_context { - int identity_initialized; - int identity_prompted; - krb5_error_code identity_prompt_retval; -+ krb5_data *freshness_token; - }; - typedef struct _pkinit_req_context *pkinit_req_context; - -diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c -index f1bc6b21d..9483d69e5 100644 ---- a/src/plugins/preauth/pkinit/pkinit_clnt.c -+++ b/src/plugins/preauth/pkinit/pkinit_clnt.c -@@ -231,6 +231,8 @@ pkinit_as_req_create(krb5_context context, - auth_pack.pkAuthenticator.cusec = cusec; - auth_pack.pkAuthenticator.nonce = nonce; - auth_pack.pkAuthenticator.paChecksum = *cksum; -+ if (!reqctx->opts->disable_freshness) -+ auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token; - auth_pack.clientDHNonce.length = 0; - auth_pack.clientPublicValue = &info; - auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; -@@ -1162,6 +1164,7 @@ pkinit_client_process(krb5_context context, krb5_clpreauth_moddata moddata, - pkinit_context plgctx = (pkinit_context)moddata; - pkinit_req_context reqctx = (pkinit_req_context)modreq; - krb5_keyblock as_key; -+ krb5_data d; - - pkiDebug("pkinit_client_process %p %p %p %p\n", - context, plgctx, reqctx, request); -@@ -1174,6 +1177,12 @@ pkinit_client_process(krb5_context context, krb5_clpreauth_moddata moddata, - case KRB5_PADATA_PKINIT_KX: - reqctx->rfc6112_kdc = 1; - return 0; -+ case KRB5_PADATA_AS_FRESHNESS: -+ TRACE_PKINIT_CLIENT_FRESHNESS_TOKEN(context); -+ krb5_free_data(context, reqctx->freshness_token); -+ reqctx->freshness_token = NULL; -+ d = make_data(in_padata->contents, in_padata->length); -+ return krb5_copy_data(context, &d, &reqctx->freshness_token); - case KRB5_PADATA_PK_AS_REQ: - reqctx->rfc4556_kdc = 1; - pkiDebug("processing KRB5_PADATA_PK_AS_REQ\n"); -@@ -1359,7 +1368,7 @@ cleanup: - static int - pkinit_client_get_flags(krb5_context kcontext, krb5_preauthtype patype) - { -- if (patype == KRB5_PADATA_PKINIT_KX) -+ if (patype == KRB5_PADATA_PKINIT_KX || patype == KRB5_PADATA_AS_FRESHNESS) - return PA_INFO; - return PA_REAL; - } -@@ -1376,6 +1385,7 @@ static krb5_preauthtype supported_client_pa_types[] = { - KRB5_PADATA_PK_AS_REP_OLD, - KRB5_PADATA_PK_AS_REQ_OLD, - KRB5_PADATA_PKINIT_KX, -+ KRB5_PADATA_AS_FRESHNESS, - 0 - }; - -@@ -1400,6 +1410,7 @@ pkinit_client_req_init(krb5_context context, - reqctx->opts = NULL; - reqctx->idctx = NULL; - reqctx->idopts = NULL; -+ reqctx->freshness_token = NULL; - - retval = pkinit_init_req_opts(&reqctx->opts); - if (retval) -@@ -1410,6 +1421,7 @@ pkinit_client_req_init(krb5_context context, - reqctx->opts->dh_or_rsa = plgctx->opts->dh_or_rsa; - reqctx->opts->allow_upn = plgctx->opts->allow_upn; - reqctx->opts->require_crl_checking = plgctx->opts->require_crl_checking; -+ reqctx->opts->disable_freshness = plgctx->opts->disable_freshness; - - retval = pkinit_init_req_crypto(&reqctx->cryptoctx); - if (retval) -@@ -1468,6 +1480,8 @@ pkinit_client_req_fini(krb5_context context, krb5_clpreauth_moddata moddata, - if (reqctx->idopts != NULL) - pkinit_fini_identity_opts(reqctx->idopts); - -+ krb5_free_data(context, reqctx->freshness_token); -+ - free(reqctx); - return; - } -@@ -1580,6 +1594,9 @@ handle_gic_opt(krb5_context context, - pkiDebug("Setting flag to use RSA_PROTOCOL\n"); - plgctx->opts->dh_or_rsa = RSA_PROTOCOL; - } -+ } else if (strcmp(attr, "disable_freshness") == 0) { -+ if (strcmp(value, "yes") == 0) -+ plgctx->opts->disable_freshness = 1; - } - return 0; - } -diff --git a/src/plugins/preauth/pkinit/pkinit_lib.c b/src/plugins/preauth/pkinit/pkinit_lib.c -index 2f88545da..d5858c424 100644 ---- a/src/plugins/preauth/pkinit/pkinit_lib.c -+++ b/src/plugins/preauth/pkinit/pkinit_lib.c -@@ -82,6 +82,8 @@ pkinit_init_plg_opts(pkinit_plg_opts **plgopts) - opts->dh_or_rsa = DH_PROTOCOL; - opts->allow_upn = 0; - opts->require_crl_checking = 0; -+ opts->require_freshness = 0; -+ opts->disable_freshness = 0; - - opts->dh_min_bits = PKINIT_DEFAULT_DH_MIN_BITS; - -@@ -145,6 +147,7 @@ free_krb5_auth_pack(krb5_auth_pack **in) - free((*in)->clientPublicValue); - } - free((*in)->pkAuthenticator.paChecksum.contents); -+ krb5_free_data(NULL, (*in)->pkAuthenticator.freshnessToken); - if ((*in)->supportedCMSTypes != NULL) - free_krb5_algorithm_identifiers(&((*in)->supportedCMSTypes)); - if ((*in)->supportedKDFs) { -diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h -index 2d95da94a..7f95206c0 100644 ---- a/src/plugins/preauth/pkinit/pkinit_trace.h -+++ b/src/plugins/preauth/pkinit/pkinit_trace.h -@@ -41,6 +41,8 @@ - TRACE(c, "PKINIT client found no acceptable EKU in KDC cert") - #define TRACE_PKINIT_CLIENT_EKU_SKIP(c) \ - TRACE(c, "PKINIT client skipping EKU check due to configuration") -+#define TRACE_PKINIT_CLIENT_FRESHNESS_TOKEN(c) \ -+ TRACE(c, "PKINIT client received freshness token from KDC") - #define TRACE_PKINIT_CLIENT_KDF_ALG(c, kdf, keyblock) \ - TRACE(c, "PKINIT client used KDF {hexdata} to compute reply key " \ - "{keyblock}", kdf, keyblock) -diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c -index 43084cbbd..cf63f3f66 100644 ---- a/src/tests/asn.1/ktest.c -+++ b/src/tests/asn.1/ktest.c -@@ -725,6 +725,8 @@ ktest_make_sample_pk_authenticator(krb5_pk_authenticator *p) - ktest_make_sample_checksum(&p->paChecksum); - /* We don't encode the checksum type, only the contents. */ - p->paChecksum.checksum_type = 0; -+ p->freshnessToken = ealloc(sizeof(krb5_data)); -+ ktest_make_sample_data(p->freshnessToken); - } - - static void -@@ -1651,6 +1653,8 @@ ktest_empty_pk_authenticator(krb5_pk_authenticator *p) - { - ktest_empty_checksum(&p->paChecksum); - p->paChecksum.contents = NULL; -+ krb5_free_data(NULL, p->freshnessToken); -+ p->freshnessToken = NULL; - } - - static void -diff --git a/src/tests/asn.1/pkinit_encode.out b/src/tests/asn.1/pkinit_encode.out -index 463128de0..3b0f7190a 100644 ---- a/src/tests/asn.1/pkinit_encode.out -+++ b/src/tests/asn.1/pkinit_encode.out -@@ -4,7 +4,7 @@ encode_krb5_pa_pk_as_rep(dhInfo): A0 28 30 26 80 08 6B 72 62 35 64 61 74 61 A1 0 - encode_krb5_pa_pk_as_rep(encKeyPack): 81 08 6B 72 62 35 64 61 74 61 - encode_krb5_pa_pk_as_rep_draft9(dhSignedData): 80 08 6B 72 62 35 64 61 74 61 - encode_krb5_pa_pk_as_rep_draft9(encKeyPack): 81 08 6B 72 62 35 64 61 74 61 --encode_krb5_auth_pack: 30 81 93 A0 29 30 27 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61 -+encode_krb5_auth_pack: 30 81 9F A0 35 30 33 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61 - encode_krb5_auth_pack_draft9: 30 75 A0 4F 30 4D A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A2 05 02 03 01 E2 40 A3 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A4 03 02 01 2A A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61 - encode_krb5_kdc_dh_key_info: 30 25 A0 0B 03 09 00 6B 72 62 35 64 61 74 61 A1 03 02 01 2A A2 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A - encode_krb5_reply_key_pack: 30 26 A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34 -diff --git a/src/tests/asn.1/pkinit_trval.out b/src/tests/asn.1/pkinit_trval.out -index 58d870631..f9edbe154 100644 ---- a/src/tests/asn.1/pkinit_trval.out -+++ b/src/tests/asn.1/pkinit_trval.out -@@ -57,6 +57,7 @@ encode_krb5_auth_pack: - . . [1] [Generalized Time] "19940610060317Z" - . . [2] [Integer] 42 - . . [3] [Octet String] "1234" -+. . [4] [Octet String] "krb5data" - . [1] [Sequence/Sequence Of] - . . [Sequence/Sequence Of] - . . . [Object Identifier] <9> diff --git a/Add-SPAKE-preauth-support.patch b/Add-SPAKE-preauth-support.patch deleted file mode 100644 index ab04539..0000000 --- a/Add-SPAKE-preauth-support.patch +++ /dev/null @@ -1,14349 +0,0 @@ -From f8f2cff0aba6ea7dd9b5fef89549aaff36ce4fee Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 25 Sep 2015 17:47:35 -0400 -Subject: [PATCH] Add SPAKE preauth support - -This is an implementation of draft-ietf-kitten-krb-spake-preauth-05. -SPAKE preauth authenticates using the client principal long-term key, -but protects against offline dictionary attacks. - -SPAKE preauth negotiates a group for use by the SPAKE2 algorithm. The -edwards25519 group is implemented using code adapted from BoringSSL. -The P-256, P-384, and P-521 groups are implemented against OpenSSL. -edwards25519 is enabled by default on the client; no groups are -enabled by default on the KDC. - -SPAKE preauth can also include a second factor. Second factor support -isn't included in this implementation; comments have been left to -indicate what should change when it is added in. - -Integration tests (tests/t_spake.py) are included with good coverage -of the negotiation scenarios. - -Test vectors from the draft are checked against the group's "result" -operation. The "keygen" operation is inherently random and is -therefore not tested against the vectors, but is effectively exercised -by the integration tests. - -KDC optimistic challenge is implemented. In the future we should -implement client optimistic SPAKE as well; this will require changes -to the generic client preauth framework. - -In the future we should add per-realm configuration to deny encrypted -timestamp and encrypted challenge on a per-realm basis. This -configuration should stick across client realm referrals. - -In the future we should avoid attempting encrypting timestamp or -encrypted challenge if the KDC replies to a single-factor -SPAKEResponse message with PREAUTH_FAILED. This will require a change -to the generic client preauth framework. - -In the future we should make SPAKE support apply to the Windows build, -either by adding support for building plugin DLLs or by moving the -edwards25519 and client code to libkrb5. - -[npmccallum@redhat.com: split up internal headers; split out group -registry contents; implemented P-384 and P-521] - -ticket: 8647 (new) -(cherry picked from commit 7447259401569c92b1fb2e31cb02edbbffd67d35) ---- - NOTICE | 51 + - doc/admin/conf_files/kdc_conf.rst | 22 +- - doc/admin/conf_files/krb5_conf.rst | 15 + - doc/admin/index.rst | 1 + - doc/admin/spake.rst | 46 + - doc/formats/cookie.rst | 37 + - doc/notice.rst | 47 + - src/Makefile.in | 2 + - src/config/pre.in | 6 + - src/configure.in | 20 + - src/include/k5-int.h | 3 + - src/include/krb5/krb5.hin | 2 + - src/kdc/kdc_preauth.c | 2 + - src/lib/krb5/krb/preauth2.c | 2 + - src/lib/krb5/os/trace.c | 1 + - src/plugins/preauth/spake/AUTHORS | 16 + - src/plugins/preauth/spake/Makefile.in | 39 + - src/plugins/preauth/spake/deps | 73 + - src/plugins/preauth/spake/edwards25519.c | 2651 ++++++ - .../preauth/spake/edwards25519_tables.h | 7881 +++++++++++++++++ - src/plugins/preauth/spake/groups.c | 442 + - src/plugins/preauth/spake/groups.h | 148 + - src/plugins/preauth/spake/iana.c | 108 + - src/plugins/preauth/spake/iana.h | 65 + - src/plugins/preauth/spake/openssl.c | 315 + - src/plugins/preauth/spake/spake.exports | 2 + - src/plugins/preauth/spake/spake_client.c | 363 + - src/plugins/preauth/spake/spake_kdc.c | 590 ++ - src/plugins/preauth/spake/t_krb5.conf | 2 + - src/plugins/preauth/spake/t_vectors.c | 476 + - src/plugins/preauth/spake/trace.h | 74 + - src/plugins/preauth/spake/util.c | 211 + - src/plugins/preauth/spake/util.h | 56 + - src/tests/Makefile.in | 1 + - src/tests/t_spake.py | 151 + - 35 files changed, 13917 insertions(+), 4 deletions(-) - create mode 100644 doc/admin/spake.rst - create mode 100644 src/plugins/preauth/spake/AUTHORS - create mode 100644 src/plugins/preauth/spake/Makefile.in - create mode 100644 src/plugins/preauth/spake/deps - create mode 100644 src/plugins/preauth/spake/edwards25519.c - create mode 100644 src/plugins/preauth/spake/edwards25519_tables.h - create mode 100644 src/plugins/preauth/spake/groups.c - create mode 100644 src/plugins/preauth/spake/groups.h - create mode 100644 src/plugins/preauth/spake/iana.c - create mode 100644 src/plugins/preauth/spake/iana.h - create mode 100644 src/plugins/preauth/spake/openssl.c - create mode 100644 src/plugins/preauth/spake/spake.exports - create mode 100644 src/plugins/preauth/spake/spake_client.c - create mode 100644 src/plugins/preauth/spake/spake_kdc.c - create mode 100644 src/plugins/preauth/spake/t_krb5.conf - create mode 100644 src/plugins/preauth/spake/t_vectors.c - create mode 100644 src/plugins/preauth/spake/trace.h - create mode 100644 src/plugins/preauth/spake/util.c - create mode 100644 src/plugins/preauth/spake/util.h - create mode 100644 src/tests/t_spake.py - -diff --git a/NOTICE b/NOTICE -index 1f2ce6493..cb6ab462b 100644 ---- a/NOTICE -+++ b/NOTICE -@@ -1316,3 +1316,54 @@ The following notice applies to - STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) - ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED - OF THE POSSIBILITY OF SUCH DAMAGE. -+ -+====================================================================== -+ -+The following notice applies to portions of -+"src/plugins/preauth/spake/edwards25519.c" and -+"src/plugins/preauth/spake/edwards25519_tables.h": -+ -+The MIT License (MIT) -+ -+Copyright (c) 2015-2016 the fiat-crypto authors (see the AUTHORS -+file). -+ -+Permission is hereby granted, free of charge, to any person obtaining -+a copy of this software and associated documentation files (the -+"Software"), to deal in the Software without restriction, including -+without limitation the rights to use, copy, modify, merge, publish, -+distribute, sublicense, and/or sell copies of the Software, and to -+permit persons to whom the Software is furnished to do so, subject to -+the following conditions: -+ -+The above copyright notice and this permission notice shall be -+included in all copies or substantial portions of the Software. -+ -+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, -+EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF -+MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. -+IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY -+CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, -+TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE -+SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. -+ -+====================================================================== -+ -+The following notice applies to portions of -+"src/plugins/preauth/spake/edwards25519.c": -+ -+Copyright (c) 2015-2016, Google Inc. -+ -+Permission to use, copy, modify, and/or distribute this software for -+any purpose with or without fee is hereby granted, provided that the -+above copyright notice and this permission notice appear in all -+copies. -+ -+THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL -+WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED -+WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE -+AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL -+DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR -+PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER -+TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR -+PERFORMANCE OF THIS SOFTWARE. -diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst -index 1ac1a37c2..f8cf1be7c 100644 ---- a/doc/admin/conf_files/kdc_conf.rst -+++ b/doc/admin/conf_files/kdc_conf.rst -@@ -43,10 +43,10 @@ The kdc.conf file may contain the following sections: - [kdcdefaults] - ~~~~~~~~~~~~~ - --With two exceptions, relations in the [kdcdefaults] section specify --default values for realm variables, to be used if the [realms] --subsection does not contain a relation for the tag. See the --:ref:`kdc_realms` section for the definitions of these relations. -+Some relations in the [kdcdefaults] section specify default values for -+realm variables, to be used if the [realms] subsection does not -+contain a relation for the tag. See the :ref:`kdc_realms` section for -+the definitions of these relations. - - * **host_based_services** - * **kdc_listen** -@@ -56,6 +56,8 @@ subsection does not contain a relation for the tag. See the - * **no_host_referral** - * **restrict_anonymous_to_tgt** - -+The following [kdcdefaults] variables have no per-realm equivalent: -+ - **kdc_max_dgram_reply_size** - Specifies the maximum packet size that can be sent over UDP. The - default value is 4096 bytes. -@@ -65,6 +67,12 @@ subsection does not contain a relation for the tag. See the - daemon. The value may be limited by OS settings. The default - value is 5. - -+**spake_preauth_kdc_challenge** -+ (String.) Specifies the group for a SPAKE optimistic challenge. -+ See the **spake_preauth_groups** variable in :ref:`libdefaults` -+ for possible values. The default is not to issue an optimistic -+ challenge. (New in release 1.17.) -+ - - .. _kdc_realms: - -@@ -403,6 +411,12 @@ The following tags may be specified in a [realms] subsection: - without allowing anonymous authentication to services. The - default value is false. New in release 1.9. - -+**spake_preauth_indicator** -+ (String.) Specifies an authentication indicator value that the -+ KDC asserts into tickets obtained using SPAKE pre-authentication. -+ The default is not to add any indicators. This option may be -+ specified multiple times. New in release 1.17. -+ - **supported_enctypes** - (List of *key*:*salt* strings.) Specifies the default key/salt - combinations of principals for this realm. Any principals created -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 3d33dba40..2574e5c26 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -367,6 +367,21 @@ The libdefaults section may contain any of the following relations: - with the session key type. See the **kdc_req_checksum_type** - configuration option for the possible values and their meanings. - -+**spake_preauth_groups** -+ A whitespace or comma-separated list of words which specifies the -+ groups allowed for SPAKE preauthentication. The possible values -+ are: -+ -+ ============ ================================ -+ edwards25519 Edwards25519 curve (:rfc:`7748`) -+ P-256 NIST P-256 curve (:rfc:`5480`) -+ P-384 NIST P-384 curve (:rfc:`5480`) -+ P-521 NIST P-521 curve (:rfc:`5480`) -+ ============ ================================ -+ -+ The default value for the client is ``edwards25519``. The default -+ value for the KDC is empty. New in release 1.17. -+ - **ticket_lifetime** - (:ref:`duration` string.) Sets the default lifetime for initial - ticket requests. The default value is 1 day. -diff --git a/doc/admin/index.rst b/doc/admin/index.rst -index b702f4021..292a64104 100644 ---- a/doc/admin/index.rst -+++ b/doc/admin/index.rst -@@ -15,6 +15,7 @@ For administrators - backup_host.rst - pkinit.rst - otp.rst -+ spake.rst - princ_dns.rst - enctypes.rst - https.rst -diff --git a/doc/admin/spake.rst b/doc/admin/spake.rst -new file mode 100644 -index 000000000..b65c694aa ---- /dev/null -+++ b/doc/admin/spake.rst -@@ -0,0 +1,46 @@ -+SPAKE Preauthentication -+======================= -+ -+SPAKE preauthentication (added in release 1.17) uses public key -+cryptography techniques to protect against password dictionary -+attacks. Unlike :ref:`PKINIT `, it does not require any -+additional infrastructure such as certificates; it simply needs to be -+turned on. Using SPAKE preauthentication may modestly increase the -+CPU and network load on the KDC. -+ -+SPAKE preauthentication can use one of four elliptic curve groups for -+its password-authenticated key exchange. The recommended group is -+``edwards25519``; three NIST curves (``P-256``, ``P-384``, and -+``P-521``) are also supported. -+ -+By default, SPAKE with the ``edwards25519`` group is enabled on -+clients, but the KDC does not offer SPAKE by default. To turn it on, -+set the **spake_preauth_groups** variable in :ref:`libdefaults` to a -+list of allowed groups. This variable affects both the client and the -+KDC. Simply setting it to ``edwards25519`` is recommended:: -+ -+ [libdefaults] -+ spake_preauth_groups = edwards25519 -+ -+Set the **+requires_preauth** and **-allow_svr** flags on client -+principal entries, as you would for any preauthentication mechanism:: -+ -+ kadmin: modprinc +requires_preauth -allow_srv PRINCNAME -+ -+Clients which do not implement SPAKE preauthentication will fall back -+to encrypted timestamp. -+ -+By default, SPAKE preauthentication requires an extra network round -+trip to the KDC during initial authentication. If most of the clients -+in a realm support SPAKE, this extra round trip can be eliminated -+using an optimistic challenge, by setting the -+**spake_preauth_kdc_challenge** variable in :ref:`kdcdefaults` to a -+single group name:: -+ -+ [kdcdefaults] -+ spake_preauth_kdc_challenge = edwards25519 -+ -+Using optimistic challenge will cause the KDC to do extra work for -+initial authentication requests that do not result in SPAKE -+preauthentication, but will save work when SPAKE preauthentication is -+used. -diff --git a/doc/formats/cookie.rst b/doc/formats/cookie.rst -index 640955c90..e32365daa 100644 ---- a/doc/formats/cookie.rst -+++ b/doc/formats/cookie.rst -@@ -58,3 +58,40 @@ mechanisms which have separate request and reply types, the request - type is used; this allows the KDC to determine whether a cookie is - relevant to a request by comparing the request pa-data types to the - cookie data types. -+ -+SPAKE cookie format (version 1) -+------------------------------- -+ -+Inside the SecureCookie wrapper, a data value of type 151 contains -+state for SPAKE pre-authentication. This data is the concatenation of -+the following: -+ -+* a two-byte big-endian version number with the value 1 -+* a two-byte big-endian stage number -+* a four-byte big-endian group number -+* a four-byte big-endian length and data for the SPAKE value -+* a four-byte big-endian length and data for the transcript hash -+* zero or more second factor records, each consisting of: -+ - a four-byte big-endian second-factor type -+ - a four-byte big-endian length and data -+ -+The stage value is 0 if the cookie was sent with a challenge message. -+Otherwise it is 1 for the first encdata message sent by the KDC during -+an exchange, 2 for the second, etc.. -+ -+The group value indicates the group number used in the SPAKE challenge. -+ -+For a stage-0 cookie, the SPAKE value is the KDC private key, -+represented in the scalar marshalling form of the group. For other -+cookies, the SPAKE value is the SPAKE result K, represented in the -+group element marshalling form. -+ -+For a stage-0 cookie, the transcript hash is the intermediate hash -+after updating with the client support message (if one was sent) and -+challenge. For other cookies it is the final hash. -+ -+For a stage-0 cookie, there may be any number of second-factor -+records, including none; a second-factor type need not create a state -+field if it does not need one, and no record is created for SF-NONE. -+For other cookies, there must be exactly one second-factor record -+corresponding to the factor type chosen by the client. -diff --git a/doc/notice.rst b/doc/notice.rst -index a32e55529..8f6b68638 100644 ---- a/doc/notice.rst -+++ b/doc/notice.rst -@@ -1237,3 +1237,50 @@ The following notice applies to - STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) - ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED - OF THE POSSIBILITY OF SUCH DAMAGE. -+ -+------------------- -+ -+The following notice applies to portions of -+``src/plugins/preauth/spake/edwards25519.c`` and -+``src/plugins/preauth/spake/edwards25519_tables.h``: -+ -+The MIT License (MIT) -+ -+Copyright (c) 2015-2016 the fiat-crypto authors (see the AUTHORS file). -+ -+Permission is hereby granted, free of charge, to any person obtaining a copy -+of this software and associated documentation files (the "Software"), to -+deal in the Software without restriction, including without limitation the -+rights to use, copy, modify, merge, publish, distribute, sublicense, and/or -+sell copies of the Software, and to permit persons to whom the Software is -+furnished to do so, subject to the following conditions: -+ -+The above copyright notice and this permission notice shall be included in -+all copies or substantial portions of the Software. -+ -+THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR -+IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, -+FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE -+AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER -+LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING -+FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS -+IN THE SOFTWARE. -+ -+------------------- -+ -+The following notice applies to portions of -+``src/plugins/preauth/spake/edwards25519.c``: -+ -+Copyright (c) 2015-2016, Google Inc. -+ -+Permission to use, copy, modify, and/or distribute this software for any -+purpose with or without fee is hereby granted, provided that the above -+copyright notice and this permission notice appear in all copies. -+ -+THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES -+WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF -+MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY -+SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES -+WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION -+OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -+CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. -diff --git a/src/Makefile.in b/src/Makefile.in -index ac9a2a060..77beff8bc 100644 ---- a/src/Makefile.in -+++ b/src/Makefile.in -@@ -25,6 +25,7 @@ SUBDIRS=util include lib \ - plugins/kdcpolicy/test \ - plugins/preauth/otp \ - plugins/preauth/pkinit \ -+ plugins/preauth/spake \ - plugins/preauth/test \ - plugins/tls/k5tls \ - kdc kadmin slave clients appl tests \ -@@ -523,6 +524,7 @@ pyrunenv.vals: Makefile - done > $@ - echo "tls_impl = '$(TLS_IMPL)'" >> $@ - echo "have_sasl = '$(HAVE_SASL)'" >> $@ -+ echo "have_spake_openssl = '$(HAVE_SPAKE_OPENSSL)'" >> $@ - echo "sizeof_time_t = $(SIZEOF_TIME_T)" >> $@ - - runenv.py: pyrunenv.vals -diff --git a/src/config/pre.in b/src/config/pre.in -index 03f5c8890..6317d3564 100644 ---- a/src/config/pre.in -+++ b/src/config/pre.in -@@ -441,9 +441,15 @@ TLS_IMPL = @TLS_IMPL@ - TLS_IMPL_CFLAGS = @TLS_IMPL_CFLAGS@ - TLS_IMPL_LIBS = @TLS_IMPL_LIBS@ - -+# SPAKE preauth back-end libraries -+SPAKE_OPENSSL_LIBS = @SPAKE_OPENSSL_LIBS@ -+ - # Whether we have the SASL header file for the LDAP KDB module - HAVE_SASL = @HAVE_SASL@ - -+# Whether we are building support for NIST SPAKE groups using OpenSSL -+HAVE_SPAKE_OPENSSL = @HAVE_SPAKE_OPENSSL@ -+ - # Whether we have libresolv 1.1.5 for URI discovery tests - HAVE_RESOLV_WRAPPER = @HAVE_RESOLV_WRAPPER@ - -diff --git a/src/configure.in b/src/configure.in -index 2b6d5baa7..08c63beca 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -321,6 +321,25 @@ AC_SUBST(TLS_IMPL) - AC_SUBST(TLS_IMPL_CFLAGS) - AC_SUBST(TLS_IMPL_LIBS) - -+# The SPAKE preauth plugin currently supports edwards25519 natively, -+# and can support three NIST groups using OpenSSL. -+HAVE_SPAKE_OPENSSL=no -+AC_ARG_WITH([spake-openssl], -+AC_HELP_STRING([--with-spake-openssl], -+ [use OpenSSL for SPAKE preauth @<:@auto@:>@]),,[withval=auto]) -+if test "$withval" = auto -o "$withval" = yes; then -+ AC_CHECK_LIB([crypto],[EC_POINT_new],[have_crypto=true],[have_crypto=false]) -+ if test "$have_crypto" = true; then -+ AC_DEFINE(SPAKE_OPENSSL,1,[Define to use OpenSSL for SPAKE preauth]) -+ SPAKE_OPENSSL_LIBS=-lcrypto -+ HAVE_SPAKE_OPENSSL=yes -+ elif test "$withval" = yes; then -+ AC_MSG_ERROR([OpenSSL libcrypto not found]) -+ fi -+fi -+AC_SUBST(HAVE_SPAKE_OPENSSL) -+AC_SUBST(SPAKE_OPENSSL_LIBS) -+ - AC_ARG_ENABLE([aesni], - AC_HELP_STRING([--disable-aesni],[Do not build with AES-NI support]), , - enable_aesni=check) -@@ -1440,6 +1459,7 @@ dnl ccapi ccapi/lib ccapi/lib/unix ccapi/server ccapi/server/unix ccapi/test - plugins/kdb/test - plugins/kdcpolicy/test - plugins/preauth/otp -+ plugins/preauth/spake - plugins/preauth/test - plugins/authdata/greet_client - plugins/authdata/greet_server -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 69b81a7f7..86b53c76b 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -286,6 +286,9 @@ typedef unsigned char u_char; - #define KRB5_CONF_RESTRICT_ANONYMOUS_TO_TGT "restrict_anonymous_to_tgt" - #define KRB5_CONF_SAFE_CHECKSUM_TYPE "safe_checksum_type" - #define KRB5_CONF_SUPPORTED_ENCTYPES "supported_enctypes" -+#define KRB5_CONF_SPAKE_PREAUTH_INDICATOR "spake_preauth_indicator" -+#define KRB5_CONF_SPAKE_PREAUTH_KDC_CHALLENGE "spake_preauth_kdc_challenge" -+#define KRB5_CONF_SPAKE_PREAUTH_GROUPS "spake_preauth_groups" - #define KRB5_CONF_TICKET_LIFETIME "ticket_lifetime" - #define KRB5_CONF_UDP_PREFERENCE_LIMIT "udp_preference_limit" - #define KRB5_CONF_UNLOCKITER "unlockiter" -diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index a650ecece..cea22dcac 100644 ---- a/src/include/krb5/krb5.hin -+++ b/src/include/krb5/krb5.hin -@@ -1034,6 +1034,7 @@ krb5_c_keyed_checksum_types(krb5_context context, krb5_enctype enctype, - #define KRB5_KEYUSAGE_ENC_CHALLENGE_KDC 55 - #define KRB5_KEYUSAGE_AS_REQ 56 - #define KRB5_KEYUSAGE_CAMMAC 64 -+#define KRB5_KEYUSAGE_SPAKE 65 - - /* Key usage values 512-1023 are reserved for uses internal to a Kerberos - * implementation. */ -@@ -1883,6 +1884,7 @@ krb5_verify_checksum(krb5_context context, krb5_cksumtype ctype, - #define KRB5_PADATA_PKINIT_KX 147 /**< RFC 6112 */ - #define KRB5_ENCPADATA_REQ_ENC_PA_REP 149 /**< RFC 6806 */ - #define KRB5_PADATA_AS_FRESHNESS 150 /**< RFC 8070 */ -+#define KRB5_PADATA_SPAKE 151 - - #define KRB5_SAM_USE_SAD_AS_KEY 0x80000000 - #define KRB5_SAM_SEND_ENCRYPTED_SAD 0x40000000 -diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c -index 62ff9a8a7..86b9e2991 100644 ---- a/src/kdc/kdc_preauth.c -+++ b/src/kdc/kdc_preauth.c -@@ -131,6 +131,8 @@ get_plugin_vtables(krb5_context context, - "preauth"); - k5_plugin_register_dyn(context, PLUGIN_INTERFACE_KDCPREAUTH, "otp", - "preauth"); -+ k5_plugin_register_dyn(context, PLUGIN_INTERFACE_KDCPREAUTH, "spake", -+ "preauth"); - k5_plugin_register(context, PLUGIN_INTERFACE_KDCPREAUTH, - "encrypted_challenge", - kdcpreauth_encrypted_challenge_initvt); -diff --git a/src/lib/krb5/krb/preauth2.c b/src/lib/krb5/krb/preauth2.c -index 6b96fa135..451e0b7a8 100644 ---- a/src/lib/krb5/krb/preauth2.c -+++ b/src/lib/krb5/krb/preauth2.c -@@ -132,6 +132,8 @@ k5_init_preauth_context(krb5_context context) - /* Auto-register built-in modules. */ - k5_plugin_register_dyn(context, PLUGIN_INTERFACE_CLPREAUTH, "pkinit", - "preauth"); -+ k5_plugin_register_dyn(context, PLUGIN_INTERFACE_CLPREAUTH, "spake", -+ "preauth"); - k5_plugin_register(context, PLUGIN_INTERFACE_CLPREAUTH, - "encrypted_challenge", - clpreauth_encrypted_challenge_initvt); -diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c -index 10b4f0c14..40a9e7b10 100644 ---- a/src/lib/krb5/os/trace.c -+++ b/src/lib/krb5/os/trace.c -@@ -163,6 +163,7 @@ padata_type_string(krb5_preauthtype type) - case KRB5_PADATA_PKINIT_KX: return "PA-PKINIT-KX"; - case KRB5_ENCPADATA_REQ_ENC_PA_REP: return "PA-REQ-ENC-PA-REP"; - case KRB5_PADATA_AS_FRESHNESS: return "PA_AS_FRESHNESS"; -+ case KRB5_PADATA_SPAKE: return "PA-SPAKE"; - default: return NULL; - } - } -diff --git a/src/plugins/preauth/spake/AUTHORS b/src/plugins/preauth/spake/AUTHORS -new file mode 100644 -index 000000000..31d71c211 ---- /dev/null -+++ b/src/plugins/preauth/spake/AUTHORS -@@ -0,0 +1,16 @@ -+# This is the official list of fiat-crypto authors for copyright purposes. -+# This file is distinct from the CONTRIBUTORS files. -+# See the latter for an explanation. -+ -+# Names should be added to this file as one of -+# Organization's name -+# Individual's name -+# Individual's name -+# See CONTRIBUTORS for the meaning of multiple email addresses. -+ -+# Please keep the list sorted. -+ -+Andres Erbsen -+Google Inc. -+Jade Philipoom -+Massachusetts Institute of Technology -diff --git a/src/plugins/preauth/spake/Makefile.in b/src/plugins/preauth/spake/Makefile.in -new file mode 100644 -index 000000000..dd1b90730 ---- /dev/null -+++ b/src/plugins/preauth/spake/Makefile.in -@@ -0,0 +1,39 @@ -+mydir=plugins$(S)preauth$(S)spake -+BUILDTOP=$(REL)..$(S)..$(S).. -+MODULE_INSTALL_DIR = $(KRB5_PA_MODULE_DIR) -+ -+# Like RUN_TEST, but use t_krb5.conf from this directory. -+RUN_TEST_LOCAL_CONF=$(RUN_SETUP) KRB5_CONFIG=$(srcdir)/t_krb5.conf LC_ALL=C \ -+ $(VALGRIND) -+ -+LIBBASE=spake -+LIBMAJOR=0 -+LIBMINOR=0 -+RELDIR=../plugins/preauth/spake -+SHLIB_EXPDEPS=$(KRB5_BASE_DEPLIBS) -+SHLIB_EXPLIBS=$(KRB5_BASE_LIBS) $(SPAKE_OPENSSL_LIBS) -+ -+STLIBOBJS=util.o iana.o groups.o openssl.o edwards25519.o \ -+ spake_client.o spake_kdc.o -+ -+SRCS= \ -+ $(srcdir)/util.c \ -+ $(srcdir)/iana.c \ -+ $(srcdir)/groups.c \ -+ $(srcdir)/openssl.c \ -+ $(srcdir)/edwards25519.c \ -+ $(srcdir)/spake_client.c \ -+ $(srcdir)/spake_kdc.c -+ -+t_vectors: t_vectors.o $(STLIBOBJS) $(SHLIB_EXPDEPS) -+ $(CC_LINK) -o $@ t_vectors.o $(STLIBOBJS) $(SHLIB_EXPLIBS) -+ -+all-unix: all-liblinks -+install-unix: install-libs -+clean-unix:: clean-liblinks clean-libs clean-libobjs -+ -+check-unix: t_vectors -+ $(RUN_TEST_LOCAL_CONF) ./t_vectors -+ -+@libnover_frag@ -+@libobj_frag@ -diff --git a/src/plugins/preauth/spake/deps b/src/plugins/preauth/spake/deps -new file mode 100644 -index 000000000..ce636af66 ---- /dev/null -+++ b/src/plugins/preauth/spake/deps -@@ -0,0 +1,73 @@ -+# -+# Generated makefile dependencies follow. -+# -+util.so util.po $(OUTPRE)util.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -+ $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -+ $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ -+ $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -+ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -+ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -+ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -+ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -+ $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -+ $(top_srcdir)/include/socket-utils.h groups.h iana.h \ -+ trace.h util.c util.h -+iana.so iana.po $(OUTPRE)iana.$(OBJEXT): iana.c iana.h -+groups.so groups.po $(OUTPRE)groups.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -+ $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -+ $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ -+ $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -+ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -+ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -+ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -+ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -+ $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -+ $(top_srcdir)/include/socket-utils.h groups.c groups.h \ -+ iana.h trace.h -+openssl.so openssl.po $(OUTPRE)openssl.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -+ $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -+ $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ -+ $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -+ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -+ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -+ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -+ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -+ $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -+ $(top_srcdir)/include/socket-utils.h groups.h iana.h \ -+ openssl.c -+edwards25519.so edwards25519.po $(OUTPRE)edwards25519.$(OBJEXT): \ -+ $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ -+ $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -+ $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -+ $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -+ edwards25519.c edwards25519_tables.h groups.h iana.h -+spake_client.so spake_client.po $(OUTPRE)spake_client.$(OBJEXT): \ -+ $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ -+ $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -+ $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -+ $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-spake.h \ -+ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -+ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -+ $(top_srcdir)/include/krb5/clpreauth_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -+ groups.h iana.h spake_client.c trace.h util.h -+spake_kdc.so spake_kdc.po $(OUTPRE)spake_kdc.$(OBJEXT): \ -+ $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ -+ $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -+ $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -+ $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-input.h \ -+ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -+ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -+ $(top_srcdir)/include/k5-spake.h $(top_srcdir)/include/k5-thread.h \ -+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/kdcpreauth_plugin.h \ -+ $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -+ $(top_srcdir)/include/socket-utils.h groups.h iana.h \ -+ spake_kdc.c trace.h util.h -diff --git a/src/plugins/preauth/spake/edwards25519.c b/src/plugins/preauth/spake/edwards25519.c -new file mode 100644 -index 000000000..fd228d9d4 ---- /dev/null -+++ b/src/plugins/preauth/spake/edwards25519.c -@@ -0,0 +1,2651 @@ -+/* -*- mode: c; c-basic-offset: 2; indent-tabs-mode: nil -*- */ -+/* This file is adapted from the SPAKE edwards25519 code in BoringSSL. */ -+/* -+ * The MIT License (MIT) -+ * -+ * Copyright (c) 2015-2016 the fiat-crypto authors (see the AUTHORS file). -+ * -+ * Permission is hereby granted, free of charge, to any person obtaining a copy -+ * of this software and associated documentation files (the "Software"), to -+ * deal in the Software without restriction, including without limitation the -+ * rights to use, copy, modify, merge, publish, distribute, sublicense, and/or -+ * sell copies of the Software, and to permit persons to whom the Software is -+ * furnished to do so, subject to the following conditions: -+ * -+ * The above copyright notice and this permission notice shall be included in -+ * all copies or substantial portions of the Software. -+ * -+ * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR -+ * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, -+ * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE -+ * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER -+ * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING -+ * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS -+ * IN THE SOFTWARE. -+ */ -+/* -+ * Copyright (c) 2015-2016, Google Inc. -+ * -+ * Permission to use, copy, modify, and/or distribute this software for any -+ * purpose with or without fee is hereby granted, provided that the above -+ * copyright notice and this permission notice appear in all copies. -+ * -+ * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES -+ * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF -+ * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY -+ * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES -+ * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION -+ * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN -+ * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. -+ */ -+ -+/* -+ * This code is adapted from the BoringSSL edwards25519 SPAKE2 implementation -+ * from third_party/fiat and crypto/spake25519.c, with the following -+ * adaptations: -+ * -+ * - The M and N points are the ones from draft-irtf-cfrg-spake2-05. The -+ * BoringSSL M and N points were determined similarly, but were not -+ * restricted to members of the generator subgroup, so they use only one hash -+ * iteration for both points. The intent in BoringSSL had been to multiply w -+ * by the cofactor so that wM and wN would be in the subgroup, but as that -+ * step was accidentally omitted, a hack had to be introduced after the fact -+ * to add multiples of the prime order to the scalar. That hack is not -+ * present in this code, and the SPAKE preauth spec does not multiply w by -+ * the cofactor as it is unnecessary if M and N are chosen from the subgroup. -+ * -+ * - The SPAKE code is modified to fit the groups.h interface and the SPAKE -+ * preauth spec. -+ * -+ * - The required declarations and code are all here in one file (except for -+ * the generator point table, which is still in a separate header), so all of -+ * the functions are declared static. -+ * -+ * - BORINGSSL_CURVE25519_64BIT is defined here using preprocessor conditionals -+ * derived from the BoringSSL headers. -+ * -+ * - The field element bounds assertion checks are disabled by default, as they -+ * slow the code down by roughly a factor of two. The -+ * OPENSSL_COMPILE_ASSERT() in fe_copy_lt() is changed to a regular assert -+ * and is also conditionalized. Do a build and "make check" with -+ * EDWARDS25519_ASSERTS defined when updating this code. -+ * -+ * - The copyright comments at the top are formatted the way we do so in other -+ * source files, for ease of extraction. -+ * -+ * - Declarations in for loops conflict with our compiler configuration in -+ * older versions of gcc, so they are moved outside of the for loop. -+ * -+ * - The preprocessor symbol OPENSSL_SMALL is changed to CONFIG_SMALL. -+ * -+ * - OPENSSL_memset and OPENSSL_memmove are changed to memset and memmove, in -+ * each case verifying that they are used with nonzero length arguments. -+ * -+ * - CRYPTO_memcmp is changed to k5_bcmp. -+ * -+ * - Functions used only by X25519 or Ed25519 interfaces but not SPAKE are -+ * removed, taking care to check for unused functions in both the 64-bit and -+ * 32-bit preprocessor branches. ge_p3_dbl() is unused here if CONFIG_SMALL -+ * is defined, so it is placed inside #ifndef CONFIG_SMALL. -+ */ -+ -+// Some of this code is taken from the ref10 version of Ed25519 in SUPERCOP -+// 20141124 (http://bench.cr.yp.to/supercop.html). That code is released as -+// public domain but parts have been replaced with code generated by Fiat -+// (https://github.com/mit-plv/fiat-crypto), which is MIT licensed. -+ -+#include "groups.h" -+#include "iana.h" -+ -+#ifdef __GNUC__ -+#pragma GCC diagnostic ignored "-Wdeclaration-after-statement" -+#endif -+ -+/* -+ * These preprocessor conditionals are derived the BoringSSL -+ * include/openssl/base.h (OPENSSL_64_BIT) and crypto/internal.h -+ * (BORINGSSL_HAS_UINT128). -+ */ -+#if defined(__x86_64) || defined(_M_AMD64) || defined(_M_X64) || defined(__aarch64__) || ((defined(__PPC64__) || defined(__powerpc64__)) && defined(_LITTLE_ENDIAN)) || defined(__mips__) && defined(__LP64__) -+#if !defined(_MSC_VER) || defined(__clang__) -+#define BORINGSSL_CURVE25519_64BIT -+typedef __int128_t int128_t; -+typedef __uint128_t uint128_t; -+#endif -+#endif -+ -+#ifndef EDWARDS25519_ASSERTS -+#define assert_fe(f) -+#define assert_fe_loose(f) -+#define assert_fe_frozen(f) -+#endif -+ -+/* From BoringSSL third-party/fiat/internal.h */ -+ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+// fe means field element. Here the field is \Z/(2^255-19). An element t, -+// entries t[0]...t[4], represents the integer t[0]+2^51 t[1]+2^102 t[2]+2^153 -+// t[3]+2^204 t[4]. -+// fe limbs are bounded by 1.125*2^51. -+// Multiplication and carrying produce fe from fe_loose. -+typedef struct fe { uint64_t v[5]; } fe; -+ -+// fe_loose limbs are bounded by 3.375*2^51. -+// Addition and subtraction produce fe_loose from (fe, fe). -+typedef struct fe_loose { uint64_t v[5]; } fe_loose; -+#else -+// fe means field element. Here the field is \Z/(2^255-19). An element t, -+// entries t[0]...t[9], represents the integer t[0]+2^26 t[1]+2^51 t[2]+2^77 -+// t[3]+2^102 t[4]+...+2^230 t[9]. -+// fe limbs are bounded by 1.125*2^26,1.125*2^25,1.125*2^26,1.125*2^25,etc. -+// Multiplication and carrying produce fe from fe_loose. -+typedef struct fe { uint32_t v[10]; } fe; -+ -+// fe_loose limbs are bounded by 3.375*2^26,3.375*2^25,3.375*2^26,3.375*2^25,etc. -+// Addition and subtraction produce fe_loose from (fe, fe). -+typedef struct fe_loose { uint32_t v[10]; } fe_loose; -+#endif -+ -+// ge means group element. -+// -+// Here the group is the set of pairs (x,y) of field elements (see fe.h) -+// satisfying -x^2 + y^2 = 1 + d x^2y^2 -+// where d = -121665/121666. -+// -+// Representations: -+// ge_p2 (projective): (X:Y:Z) satisfying x=X/Z, y=Y/Z -+// ge_p3 (extended): (X:Y:Z:T) satisfying x=X/Z, y=Y/Z, XY=ZT -+// ge_p1p1 (completed): ((X:Z),(Y:T)) satisfying x=X/Z, y=Y/T -+// ge_precomp (Duif): (y+x,y-x,2dxy) -+ -+typedef struct { -+ fe X; -+ fe Y; -+ fe Z; -+} ge_p2; -+ -+typedef struct { -+ fe X; -+ fe Y; -+ fe Z; -+ fe T; -+} ge_p3; -+ -+typedef struct { -+ fe_loose X; -+ fe_loose Y; -+ fe_loose Z; -+ fe_loose T; -+} ge_p1p1; -+ -+typedef struct { -+ fe_loose yplusx; -+ fe_loose yminusx; -+ fe_loose xy2d; -+} ge_precomp; -+ -+typedef struct { -+ fe_loose YplusX; -+ fe_loose YminusX; -+ fe_loose Z; -+ fe_loose T2d; -+} ge_cached; -+ -+#include "edwards25519_tables.h" -+ -+/* From BoringSSL third-party/fiat/curve25519.c */ -+ -+static uint64_t load_3(const uint8_t *in) { -+ uint64_t result; -+ result = (uint64_t)in[0]; -+ result |= ((uint64_t)in[1]) << 8; -+ result |= ((uint64_t)in[2]) << 16; -+ return result; -+} -+ -+static uint64_t load_4(const uint8_t *in) { -+ uint64_t result; -+ result = (uint64_t)in[0]; -+ result |= ((uint64_t)in[1]) << 8; -+ result |= ((uint64_t)in[2]) << 16; -+ result |= ((uint64_t)in[3]) << 24; -+ return result; -+} -+ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+static uint64_t load_8(const uint8_t *in) { -+ uint64_t result; -+ result = (uint64_t)in[0]; -+ result |= ((uint64_t)in[1]) << 8; -+ result |= ((uint64_t)in[2]) << 16; -+ result |= ((uint64_t)in[3]) << 24; -+ result |= ((uint64_t)in[4]) << 32; -+ result |= ((uint64_t)in[5]) << 40; -+ result |= ((uint64_t)in[6]) << 48; -+ result |= ((uint64_t)in[7]) << 56; -+ return result; -+} -+ -+static uint8_t /*bool*/ addcarryx_u51(uint8_t /*bool*/ c, uint64_t a, -+ uint64_t b, uint64_t *low) { -+ // This function extracts 51 bits of result and 1 bit of carry (52 total), so -+ // a 64-bit intermediate is sufficient. -+ uint64_t x = a + b + c; -+ *low = x & ((UINT64_C(1) << 51) - 1); -+ return (x >> 51) & 1; -+} -+ -+static uint8_t /*bool*/ subborrow_u51(uint8_t /*bool*/ c, uint64_t a, -+ uint64_t b, uint64_t *low) { -+ // This function extracts 51 bits of result and 1 bit of borrow (52 total), so -+ // a 64-bit intermediate is sufficient. -+ uint64_t x = a - b - c; -+ *low = x & ((UINT64_C(1) << 51) - 1); -+ return x >> 63; -+} -+ -+static uint64_t cmovznz64(uint64_t t, uint64_t z, uint64_t nz) { -+ t = -!!t; // all set if nonzero, 0 if 0 -+ return (t&nz) | ((~t)&z); -+} -+ -+#else -+ -+static uint8_t /*bool*/ addcarryx_u25(uint8_t /*bool*/ c, uint32_t a, -+ uint32_t b, uint32_t *low) { -+ // This function extracts 25 bits of result and 1 bit of carry (26 total), so -+ // a 32-bit intermediate is sufficient. -+ uint32_t x = a + b + c; -+ *low = x & ((1 << 25) - 1); -+ return (x >> 25) & 1; -+} -+ -+static uint8_t /*bool*/ addcarryx_u26(uint8_t /*bool*/ c, uint32_t a, -+ uint32_t b, uint32_t *low) { -+ // This function extracts 26 bits of result and 1 bit of carry (27 total), so -+ // a 32-bit intermediate is sufficient. -+ uint32_t x = a + b + c; -+ *low = x & ((1 << 26) - 1); -+ return (x >> 26) & 1; -+} -+ -+static uint8_t /*bool*/ subborrow_u25(uint8_t /*bool*/ c, uint32_t a, -+ uint32_t b, uint32_t *low) { -+ // This function extracts 25 bits of result and 1 bit of borrow (26 total), so -+ // a 32-bit intermediate is sufficient. -+ uint32_t x = a - b - c; -+ *low = x & ((1 << 25) - 1); -+ return x >> 31; -+} -+ -+static uint8_t /*bool*/ subborrow_u26(uint8_t /*bool*/ c, uint32_t a, -+ uint32_t b, uint32_t *low) { -+ // This function extracts 26 bits of result and 1 bit of borrow (27 total), so -+ // a 32-bit intermediate is sufficient. -+ uint32_t x = a - b - c; -+ *low = x & ((1 << 26) - 1); -+ return x >> 31; -+} -+ -+static uint32_t cmovznz32(uint32_t t, uint32_t z, uint32_t nz) { -+ t = -!!t; // all set if nonzero, 0 if 0 -+ return (t&nz) | ((~t)&z); -+} -+ -+#endif -+ -+ -+// Field operations. -+ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ -+#ifdef EDWARDS25519_ASSERTS -+#define assert_fe(f) do { \ -+ unsigned _assert_fe_i; \ -+ for (_assert_fe_i = 0; _assert_fe_i< 5; _assert_fe_i++) { \ -+ assert(f[_assert_fe_i] < 1.125*(UINT64_C(1)<<51)); \ -+ } \ -+} while (0) -+ -+#define assert_fe_loose(f) do { \ -+ unsigned _assert_fe_i; \ -+ for (_assert_fe_i = 0; _assert_fe_i< 5; _assert_fe_i++) { \ -+ assert(f[_assert_fe_i] < 3.375*(UINT64_C(1)<<51)); \ -+ } \ -+} while (0) -+ -+#define assert_fe_frozen(f) do { \ -+ unsigned _assert_fe_i; \ -+ for (_assert_fe_i = 0; _assert_fe_i< 5; _assert_fe_i++) { \ -+ assert(f[_assert_fe_i] < (UINT64_C(1)<<51)); \ -+ } \ -+} while (0) -+#endif /* EDWARDS25519_ASSERTS */ -+ -+static void fe_frombytes_impl(uint64_t h[5], const uint8_t *s) { -+ // Ignores top bit of s. -+ uint64_t a0 = load_8(s); -+ uint64_t a1 = load_8(s+8); -+ uint64_t a2 = load_8(s+16); -+ uint64_t a3 = load_8(s+24); -+ // Use 51 bits, 64-51 = 13 left. -+ h[0] = a0 & ((UINT64_C(1) << 51) - 1); -+ // (64-51) + 38 = 13 + 38 = 51 -+ h[1] = (a0 >> 51) | ((a1 & ((UINT64_C(1) << 38) - 1)) << 13); -+ // (64-38) + 25 = 26 + 25 = 51 -+ h[2] = (a1 >> 38) | ((a2 & ((UINT64_C(1) << 25) - 1)) << 26); -+ // (64-25) + 12 = 39 + 12 = 51 -+ h[3] = (a2 >> 25) | ((a3 & ((UINT64_C(1) << 12) - 1)) << 39); -+ // (64-12) = 52, ignore top bit -+ h[4] = (a3 >> 12) & ((UINT64_C(1) << 51) - 1); -+ assert_fe(h); -+} -+ -+static void fe_frombytes(fe *h, const uint8_t *s) { -+ fe_frombytes_impl(h->v, s); -+} -+ -+static void fe_freeze(uint64_t out[5], const uint64_t in1[5]) { -+ { const uint64_t x7 = in1[4]; -+ { const uint64_t x8 = in1[3]; -+ { const uint64_t x6 = in1[2]; -+ { const uint64_t x4 = in1[1]; -+ { const uint64_t x2 = in1[0]; -+ { uint64_t x10; uint8_t/*bool*/ x11 = subborrow_u51(0x0, x2, 0x7ffffffffffed, &x10); -+ { uint64_t x13; uint8_t/*bool*/ x14 = subborrow_u51(x11, x4, 0x7ffffffffffff, &x13); -+ { uint64_t x16; uint8_t/*bool*/ x17 = subborrow_u51(x14, x6, 0x7ffffffffffff, &x16); -+ { uint64_t x19; uint8_t/*bool*/ x20 = subborrow_u51(x17, x8, 0x7ffffffffffff, &x19); -+ { uint64_t x22; uint8_t/*bool*/ x23 = subborrow_u51(x20, x7, 0x7ffffffffffff, &x22); -+ { uint64_t x24 = cmovznz64(x23, 0x0, 0xffffffffffffffffL); -+ { uint64_t x25 = (x24 & 0x7ffffffffffed); -+ { uint64_t x27; uint8_t/*bool*/ x28 = addcarryx_u51(0x0, x10, x25, &x27); -+ { uint64_t x29 = (x24 & 0x7ffffffffffff); -+ { uint64_t x31; uint8_t/*bool*/ x32 = addcarryx_u51(x28, x13, x29, &x31); -+ { uint64_t x33 = (x24 & 0x7ffffffffffff); -+ { uint64_t x35; uint8_t/*bool*/ x36 = addcarryx_u51(x32, x16, x33, &x35); -+ { uint64_t x37 = (x24 & 0x7ffffffffffff); -+ { uint64_t x39; uint8_t/*bool*/ x40 = addcarryx_u51(x36, x19, x37, &x39); -+ { uint64_t x41 = (x24 & 0x7ffffffffffff); -+ { uint64_t x43; addcarryx_u51(x40, x22, x41, &x43); -+ out[0] = x27; -+ out[1] = x31; -+ out[2] = x35; -+ out[3] = x39; -+ out[4] = x43; -+ }}}}}}}}}}}}}}}}}}}}} -+} -+ -+static void fe_tobytes(uint8_t s[32], const fe *f) { -+ assert_fe(f->v); -+ uint64_t h[5]; -+ fe_freeze(h, f->v); -+ assert_fe_frozen(h); -+ -+ s[0] = h[0] >> 0; -+ s[1] = h[0] >> 8; -+ s[2] = h[0] >> 16; -+ s[3] = h[0] >> 24; -+ s[4] = h[0] >> 32; -+ s[5] = h[0] >> 40; -+ s[6] = (h[0] >> 48) | (h[1] << 3); -+ s[7] = h[1] >> 5; -+ s[8] = h[1] >> 13; -+ s[9] = h[1] >> 21; -+ s[10] = h[1] >> 29; -+ s[11] = h[1] >> 37; -+ s[12] = (h[1] >> 45) | (h[2] << 6); -+ s[13] = h[2] >> 2; -+ s[14] = h[2] >> 10; -+ s[15] = h[2] >> 18; -+ s[16] = h[2] >> 26; -+ s[17] = h[2] >> 34; -+ s[18] = h[2] >> 42; -+ s[19] = (h[2] >> 50) | (h[3] << 1); -+ s[20] = h[3] >> 7; -+ s[21] = h[3] >> 15; -+ s[22] = h[3] >> 23; -+ s[23] = h[3] >> 31; -+ s[24] = h[3] >> 39; -+ s[25] = (h[3] >> 47) | (h[4] << 4); -+ s[26] = h[4] >> 4; -+ s[27] = h[4] >> 12; -+ s[28] = h[4] >> 20; -+ s[29] = h[4] >> 28; -+ s[30] = h[4] >> 36; -+ s[31] = h[4] >> 44; -+} -+ -+// h = 0 -+static void fe_0(fe *h) { -+ memset(h, 0, sizeof(fe)); -+} -+ -+static void fe_loose_0(fe_loose *h) { -+ memset(h, 0, sizeof(fe_loose)); -+} -+ -+// h = 1 -+static void fe_1(fe *h) { -+ memset(h, 0, sizeof(fe)); -+ h->v[0] = 1; -+} -+ -+static void fe_loose_1(fe_loose *h) { -+ memset(h, 0, sizeof(fe_loose)); -+ h->v[0] = 1; -+} -+ -+static void fe_add_impl(uint64_t out[5], const uint64_t in1[5], const uint64_t in2[5]) { -+ { const uint64_t x10 = in1[4]; -+ { const uint64_t x11 = in1[3]; -+ { const uint64_t x9 = in1[2]; -+ { const uint64_t x7 = in1[1]; -+ { const uint64_t x5 = in1[0]; -+ { const uint64_t x18 = in2[4]; -+ { const uint64_t x19 = in2[3]; -+ { const uint64_t x17 = in2[2]; -+ { const uint64_t x15 = in2[1]; -+ { const uint64_t x13 = in2[0]; -+ out[0] = (x5 + x13); -+ out[1] = (x7 + x15); -+ out[2] = (x9 + x17); -+ out[3] = (x11 + x19); -+ out[4] = (x10 + x18); -+ }}}}}}}}}} -+} -+ -+// h = f + g -+// Can overlap h with f or g. -+static void fe_add(fe_loose *h, const fe *f, const fe *g) { -+ assert_fe(f->v); -+ assert_fe(g->v); -+ fe_add_impl(h->v, f->v, g->v); -+ assert_fe_loose(h->v); -+} -+ -+static void fe_sub_impl(uint64_t out[5], const uint64_t in1[5], const uint64_t in2[5]) { -+ { const uint64_t x10 = in1[4]; -+ { const uint64_t x11 = in1[3]; -+ { const uint64_t x9 = in1[2]; -+ { const uint64_t x7 = in1[1]; -+ { const uint64_t x5 = in1[0]; -+ { const uint64_t x18 = in2[4]; -+ { const uint64_t x19 = in2[3]; -+ { const uint64_t x17 = in2[2]; -+ { const uint64_t x15 = in2[1]; -+ { const uint64_t x13 = in2[0]; -+ out[0] = ((0xfffffffffffda + x5) - x13); -+ out[1] = ((0xffffffffffffe + x7) - x15); -+ out[2] = ((0xffffffffffffe + x9) - x17); -+ out[3] = ((0xffffffffffffe + x11) - x19); -+ out[4] = ((0xffffffffffffe + x10) - x18); -+ }}}}}}}}}} -+} -+ -+// h = f - g -+// Can overlap h with f or g. -+static void fe_sub(fe_loose *h, const fe *f, const fe *g) { -+ assert_fe(f->v); -+ assert_fe(g->v); -+ fe_sub_impl(h->v, f->v, g->v); -+ assert_fe_loose(h->v); -+} -+ -+static void fe_carry_impl(uint64_t out[5], const uint64_t in1[5]) { -+ { const uint64_t x7 = in1[4]; -+ { const uint64_t x8 = in1[3]; -+ { const uint64_t x6 = in1[2]; -+ { const uint64_t x4 = in1[1]; -+ { const uint64_t x2 = in1[0]; -+ { uint64_t x9 = (x2 >> 0x33); -+ { uint64_t x10 = (x2 & 0x7ffffffffffff); -+ { uint64_t x11 = (x9 + x4); -+ { uint64_t x12 = (x11 >> 0x33); -+ { uint64_t x13 = (x11 & 0x7ffffffffffff); -+ { uint64_t x14 = (x12 + x6); -+ { uint64_t x15 = (x14 >> 0x33); -+ { uint64_t x16 = (x14 & 0x7ffffffffffff); -+ { uint64_t x17 = (x15 + x8); -+ { uint64_t x18 = (x17 >> 0x33); -+ { uint64_t x19 = (x17 & 0x7ffffffffffff); -+ { uint64_t x20 = (x18 + x7); -+ { uint64_t x21 = (x20 >> 0x33); -+ { uint64_t x22 = (x20 & 0x7ffffffffffff); -+ { uint64_t x23 = (x10 + (0x13 * x21)); -+ { uint64_t x24 = (x23 >> 0x33); -+ { uint64_t x25 = (x23 & 0x7ffffffffffff); -+ { uint64_t x26 = (x24 + x13); -+ { uint64_t x27 = (x26 >> 0x33); -+ { uint64_t x28 = (x26 & 0x7ffffffffffff); -+ out[0] = x25; -+ out[1] = x28; -+ out[2] = (x27 + x16); -+ out[3] = x19; -+ out[4] = x22; -+ }}}}}}}}}}}}}}}}}}}}}}}}} -+} -+ -+static void fe_carry(fe *h, const fe_loose* f) { -+ assert_fe_loose(f->v); -+ fe_carry_impl(h->v, f->v); -+ assert_fe(h->v); -+} -+ -+static void fe_mul_impl(uint64_t out[5], const uint64_t in1[5], const uint64_t in2[5]) { -+ assert_fe_loose(in1); -+ assert_fe_loose(in2); -+ { const uint64_t x10 = in1[4]; -+ { const uint64_t x11 = in1[3]; -+ { const uint64_t x9 = in1[2]; -+ { const uint64_t x7 = in1[1]; -+ { const uint64_t x5 = in1[0]; -+ { const uint64_t x18 = in2[4]; -+ { const uint64_t x19 = in2[3]; -+ { const uint64_t x17 = in2[2]; -+ { const uint64_t x15 = in2[1]; -+ { const uint64_t x13 = in2[0]; -+ { uint128_t x20 = ((uint128_t)x5 * x13); -+ { uint128_t x21 = (((uint128_t)x5 * x15) + ((uint128_t)x7 * x13)); -+ { uint128_t x22 = ((((uint128_t)x5 * x17) + ((uint128_t)x9 * x13)) + ((uint128_t)x7 * x15)); -+ { uint128_t x23 = (((((uint128_t)x5 * x19) + ((uint128_t)x11 * x13)) + ((uint128_t)x7 * x17)) + ((uint128_t)x9 * x15)); -+ { uint128_t x24 = ((((((uint128_t)x5 * x18) + ((uint128_t)x10 * x13)) + ((uint128_t)x11 * x15)) + ((uint128_t)x7 * x19)) + ((uint128_t)x9 * x17)); -+ { uint64_t x25 = (x10 * 0x13); -+ { uint64_t x26 = (x7 * 0x13); -+ { uint64_t x27 = (x9 * 0x13); -+ { uint64_t x28 = (x11 * 0x13); -+ { uint128_t x29 = ((((x20 + ((uint128_t)x25 * x15)) + ((uint128_t)x26 * x18)) + ((uint128_t)x27 * x19)) + ((uint128_t)x28 * x17)); -+ { uint128_t x30 = (((x21 + ((uint128_t)x25 * x17)) + ((uint128_t)x27 * x18)) + ((uint128_t)x28 * x19)); -+ { uint128_t x31 = ((x22 + ((uint128_t)x25 * x19)) + ((uint128_t)x28 * x18)); -+ { uint128_t x32 = (x23 + ((uint128_t)x25 * x18)); -+ { uint64_t x33 = (uint64_t) (x29 >> 0x33); -+ { uint64_t x34 = ((uint64_t)x29 & 0x7ffffffffffff); -+ { uint128_t x35 = (x33 + x30); -+ { uint64_t x36 = (uint64_t) (x35 >> 0x33); -+ { uint64_t x37 = ((uint64_t)x35 & 0x7ffffffffffff); -+ { uint128_t x38 = (x36 + x31); -+ { uint64_t x39 = (uint64_t) (x38 >> 0x33); -+ { uint64_t x40 = ((uint64_t)x38 & 0x7ffffffffffff); -+ { uint128_t x41 = (x39 + x32); -+ { uint64_t x42 = (uint64_t) (x41 >> 0x33); -+ { uint64_t x43 = ((uint64_t)x41 & 0x7ffffffffffff); -+ { uint128_t x44 = (x42 + x24); -+ { uint64_t x45 = (uint64_t) (x44 >> 0x33); -+ { uint64_t x46 = ((uint64_t)x44 & 0x7ffffffffffff); -+ { uint64_t x47 = (x34 + (0x13 * x45)); -+ { uint64_t x48 = (x47 >> 0x33); -+ { uint64_t x49 = (x47 & 0x7ffffffffffff); -+ { uint64_t x50 = (x48 + x37); -+ { uint64_t x51 = (x50 >> 0x33); -+ { uint64_t x52 = (x50 & 0x7ffffffffffff); -+ out[0] = x49; -+ out[1] = x52; -+ out[2] = (x51 + x40); -+ out[3] = x43; -+ out[4] = x46; -+ }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}} -+ assert_fe(out); -+} -+ -+static void fe_mul_ltt(fe_loose *h, const fe *f, const fe *g) { -+ fe_mul_impl(h->v, f->v, g->v); -+} -+ -+static void fe_mul_llt(fe_loose *h, const fe_loose *f, const fe *g) { -+ fe_mul_impl(h->v, f->v, g->v); -+} -+ -+static void fe_mul_ttt(fe *h, const fe *f, const fe *g) { -+ fe_mul_impl(h->v, f->v, g->v); -+} -+ -+static void fe_mul_tlt(fe *h, const fe_loose *f, const fe *g) { -+ fe_mul_impl(h->v, f->v, g->v); -+} -+ -+static void fe_mul_ttl(fe *h, const fe *f, const fe_loose *g) { -+ fe_mul_impl(h->v, f->v, g->v); -+} -+ -+static void fe_mul_tll(fe *h, const fe_loose *f, const fe_loose *g) { -+ fe_mul_impl(h->v, f->v, g->v); -+} -+ -+static void fe_sqr_impl(uint64_t out[5], const uint64_t in1[5]) { -+ assert_fe_loose(in1); -+ { const uint64_t x7 = in1[4]; -+ { const uint64_t x8 = in1[3]; -+ { const uint64_t x6 = in1[2]; -+ { const uint64_t x4 = in1[1]; -+ { const uint64_t x2 = in1[0]; -+ { uint64_t x9 = (x2 * 0x2); -+ { uint64_t x10 = (x4 * 0x2); -+ { uint64_t x11 = ((x6 * 0x2) * 0x13); -+ { uint64_t x12 = (x7 * 0x13); -+ { uint64_t x13 = (x12 * 0x2); -+ { uint128_t x14 = ((((uint128_t)x2 * x2) + ((uint128_t)x13 * x4)) + ((uint128_t)x11 * x8)); -+ { uint128_t x15 = ((((uint128_t)x9 * x4) + ((uint128_t)x13 * x6)) + ((uint128_t)x8 * (x8 * 0x13))); -+ { uint128_t x16 = ((((uint128_t)x9 * x6) + ((uint128_t)x4 * x4)) + ((uint128_t)x13 * x8)); -+ { uint128_t x17 = ((((uint128_t)x9 * x8) + ((uint128_t)x10 * x6)) + ((uint128_t)x7 * x12)); -+ { uint128_t x18 = ((((uint128_t)x9 * x7) + ((uint128_t)x10 * x8)) + ((uint128_t)x6 * x6)); -+ { uint64_t x19 = (uint64_t) (x14 >> 0x33); -+ { uint64_t x20 = ((uint64_t)x14 & 0x7ffffffffffff); -+ { uint128_t x21 = (x19 + x15); -+ { uint64_t x22 = (uint64_t) (x21 >> 0x33); -+ { uint64_t x23 = ((uint64_t)x21 & 0x7ffffffffffff); -+ { uint128_t x24 = (x22 + x16); -+ { uint64_t x25 = (uint64_t) (x24 >> 0x33); -+ { uint64_t x26 = ((uint64_t)x24 & 0x7ffffffffffff); -+ { uint128_t x27 = (x25 + x17); -+ { uint64_t x28 = (uint64_t) (x27 >> 0x33); -+ { uint64_t x29 = ((uint64_t)x27 & 0x7ffffffffffff); -+ { uint128_t x30 = (x28 + x18); -+ { uint64_t x31 = (uint64_t) (x30 >> 0x33); -+ { uint64_t x32 = ((uint64_t)x30 & 0x7ffffffffffff); -+ { uint64_t x33 = (x20 + (0x13 * x31)); -+ { uint64_t x34 = (x33 >> 0x33); -+ { uint64_t x35 = (x33 & 0x7ffffffffffff); -+ { uint64_t x36 = (x34 + x23); -+ { uint64_t x37 = (x36 >> 0x33); -+ { uint64_t x38 = (x36 & 0x7ffffffffffff); -+ out[0] = x35; -+ out[1] = x38; -+ out[2] = (x37 + x26); -+ out[3] = x29; -+ out[4] = x32; -+ }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}} -+ assert_fe(out); -+} -+ -+static void fe_sq_tl(fe *h, const fe_loose *f) { -+ fe_sqr_impl(h->v, f->v); -+} -+ -+static void fe_sq_tt(fe *h, const fe *f) { -+ fe_sqr_impl(h->v, f->v); -+} -+ -+// Adapted from Fiat-synthesized |fe_sub_impl| with |out| = 0. -+static void fe_neg_impl(uint64_t out[5], const uint64_t in2[5]) { -+ { const uint64_t x10 = 0; -+ { const uint64_t x11 = 0; -+ { const uint64_t x9 = 0; -+ { const uint64_t x7 = 0; -+ { const uint64_t x5 = 0; -+ { const uint64_t x18 = in2[4]; -+ { const uint64_t x19 = in2[3]; -+ { const uint64_t x17 = in2[2]; -+ { const uint64_t x15 = in2[1]; -+ { const uint64_t x13 = in2[0]; -+ out[0] = ((0xfffffffffffda + x5) - x13); -+ out[1] = ((0xffffffffffffe + x7) - x15); -+ out[2] = ((0xffffffffffffe + x9) - x17); -+ out[3] = ((0xffffffffffffe + x11) - x19); -+ out[4] = ((0xffffffffffffe + x10) - x18); -+ }}}}}}}}}} -+} -+ -+// h = -f -+static void fe_neg(fe_loose *h, const fe *f) { -+ assert_fe(f->v); -+ fe_neg_impl(h->v, f->v); -+ assert_fe_loose(h->v); -+} -+ -+// Replace (f,g) with (g,g) if b == 1; -+// replace (f,g) with (f,g) if b == 0. -+// -+// Preconditions: b in {0,1}. -+static void fe_cmov(fe_loose *f, const fe_loose *g, uint64_t b) { -+ unsigned i; -+ b = 0-b; -+ for (i = 0; i < 5; i++) { -+ uint64_t x = f->v[i] ^ g->v[i]; -+ x &= b; -+ f->v[i] ^= x; -+ } -+} -+ -+#else -+ -+#ifdef EDWARDS25519_ASSERTS -+#define assert_fe(f) do { \ -+ unsigned _assert_fe_i; \ -+ for (_assert_fe_i = 0; _assert_fe_i< 10; _assert_fe_i++) { \ -+ assert(f[_assert_fe_i] < 1.125*(1<<(26-(_assert_fe_i&1)))); \ -+ } \ -+} while (0) -+ -+#define assert_fe_loose(f) do { \ -+ unsigned _assert_fe_i; \ -+ for (_assert_fe_i = 0; _assert_fe_i< 10; _assert_fe_i++) { \ -+ assert(f[_assert_fe_i] < 3.375*(1<<(26-(_assert_fe_i&1)))); \ -+ } \ -+} while (0) -+ -+#define assert_fe_frozen(f) do { \ -+ unsigned _assert_fe_i; \ -+ for (_assert_fe_i = 0; _assert_fe_i< 10; _assert_fe_i++) { \ -+ assert(f[_assert_fe_i] < (1u<<(26-(_assert_fe_i&1)))); \ -+ } \ -+} while (0) -+#endif /* EDWARDS25519_ASSERTS */ -+ -+static void fe_frombytes_impl(uint32_t h[10], const uint8_t *s) { -+ // Ignores top bit of s. -+ uint32_t a0 = load_4(s); -+ uint32_t a1 = load_4(s+4); -+ uint32_t a2 = load_4(s+8); -+ uint32_t a3 = load_4(s+12); -+ uint32_t a4 = load_4(s+16); -+ uint32_t a5 = load_4(s+20); -+ uint32_t a6 = load_4(s+24); -+ uint32_t a7 = load_4(s+28); -+ h[0] = a0&((1<<26)-1); // 26 used, 32-26 left. 26 -+ h[1] = (a0>>26) | ((a1&((1<<19)-1))<< 6); // (32-26) + 19 = 6+19 = 25 -+ h[2] = (a1>>19) | ((a2&((1<<13)-1))<<13); // (32-19) + 13 = 13+13 = 26 -+ h[3] = (a2>>13) | ((a3&((1<< 6)-1))<<19); // (32-13) + 6 = 19+ 6 = 25 -+ h[4] = (a3>> 6); // (32- 6) = 26 -+ h[5] = a4&((1<<25)-1); // 25 -+ h[6] = (a4>>25) | ((a5&((1<<19)-1))<< 7); // (32-25) + 19 = 7+19 = 26 -+ h[7] = (a5>>19) | ((a6&((1<<12)-1))<<13); // (32-19) + 12 = 13+12 = 25 -+ h[8] = (a6>>12) | ((a7&((1<< 6)-1))<<20); // (32-12) + 6 = 20+ 6 = 26 -+ h[9] = (a7>> 6)&((1<<25)-1); // 25 -+ assert_fe(h); -+} -+ -+static void fe_frombytes(fe *h, const uint8_t *s) { -+ fe_frombytes_impl(h->v, s); -+} -+ -+static void fe_freeze(uint32_t out[10], const uint32_t in1[10]) { -+ { const uint32_t x17 = in1[9]; -+ { const uint32_t x18 = in1[8]; -+ { const uint32_t x16 = in1[7]; -+ { const uint32_t x14 = in1[6]; -+ { const uint32_t x12 = in1[5]; -+ { const uint32_t x10 = in1[4]; -+ { const uint32_t x8 = in1[3]; -+ { const uint32_t x6 = in1[2]; -+ { const uint32_t x4 = in1[1]; -+ { const uint32_t x2 = in1[0]; -+ { uint32_t x20; uint8_t/*bool*/ x21 = subborrow_u26(0x0, x2, 0x3ffffed, &x20); -+ { uint32_t x23; uint8_t/*bool*/ x24 = subborrow_u25(x21, x4, 0x1ffffff, &x23); -+ { uint32_t x26; uint8_t/*bool*/ x27 = subborrow_u26(x24, x6, 0x3ffffff, &x26); -+ { uint32_t x29; uint8_t/*bool*/ x30 = subborrow_u25(x27, x8, 0x1ffffff, &x29); -+ { uint32_t x32; uint8_t/*bool*/ x33 = subborrow_u26(x30, x10, 0x3ffffff, &x32); -+ { uint32_t x35; uint8_t/*bool*/ x36 = subborrow_u25(x33, x12, 0x1ffffff, &x35); -+ { uint32_t x38; uint8_t/*bool*/ x39 = subborrow_u26(x36, x14, 0x3ffffff, &x38); -+ { uint32_t x41; uint8_t/*bool*/ x42 = subborrow_u25(x39, x16, 0x1ffffff, &x41); -+ { uint32_t x44; uint8_t/*bool*/ x45 = subborrow_u26(x42, x18, 0x3ffffff, &x44); -+ { uint32_t x47; uint8_t/*bool*/ x48 = subborrow_u25(x45, x17, 0x1ffffff, &x47); -+ { uint32_t x49 = cmovznz32(x48, 0x0, 0xffffffff); -+ { uint32_t x50 = (x49 & 0x3ffffed); -+ { uint32_t x52; uint8_t/*bool*/ x53 = addcarryx_u26(0x0, x20, x50, &x52); -+ { uint32_t x54 = (x49 & 0x1ffffff); -+ { uint32_t x56; uint8_t/*bool*/ x57 = addcarryx_u25(x53, x23, x54, &x56); -+ { uint32_t x58 = (x49 & 0x3ffffff); -+ { uint32_t x60; uint8_t/*bool*/ x61 = addcarryx_u26(x57, x26, x58, &x60); -+ { uint32_t x62 = (x49 & 0x1ffffff); -+ { uint32_t x64; uint8_t/*bool*/ x65 = addcarryx_u25(x61, x29, x62, &x64); -+ { uint32_t x66 = (x49 & 0x3ffffff); -+ { uint32_t x68; uint8_t/*bool*/ x69 = addcarryx_u26(x65, x32, x66, &x68); -+ { uint32_t x70 = (x49 & 0x1ffffff); -+ { uint32_t x72; uint8_t/*bool*/ x73 = addcarryx_u25(x69, x35, x70, &x72); -+ { uint32_t x74 = (x49 & 0x3ffffff); -+ { uint32_t x76; uint8_t/*bool*/ x77 = addcarryx_u26(x73, x38, x74, &x76); -+ { uint32_t x78 = (x49 & 0x1ffffff); -+ { uint32_t x80; uint8_t/*bool*/ x81 = addcarryx_u25(x77, x41, x78, &x80); -+ { uint32_t x82 = (x49 & 0x3ffffff); -+ { uint32_t x84; uint8_t/*bool*/ x85 = addcarryx_u26(x81, x44, x82, &x84); -+ { uint32_t x86 = (x49 & 0x1ffffff); -+ { uint32_t x88; addcarryx_u25(x85, x47, x86, &x88); -+ out[0] = x52; -+ out[1] = x56; -+ out[2] = x60; -+ out[3] = x64; -+ out[4] = x68; -+ out[5] = x72; -+ out[6] = x76; -+ out[7] = x80; -+ out[8] = x84; -+ out[9] = x88; -+ }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}} -+} -+ -+static void fe_tobytes(uint8_t s[32], const fe *f) { -+ assert_fe(f->v); -+ uint32_t h[10]; -+ fe_freeze(h, f->v); -+ assert_fe_frozen(h); -+ -+ s[0] = h[0] >> 0; -+ s[1] = h[0] >> 8; -+ s[2] = h[0] >> 16; -+ s[3] = (h[0] >> 24) | (h[1] << 2); -+ s[4] = h[1] >> 6; -+ s[5] = h[1] >> 14; -+ s[6] = (h[1] >> 22) | (h[2] << 3); -+ s[7] = h[2] >> 5; -+ s[8] = h[2] >> 13; -+ s[9] = (h[2] >> 21) | (h[3] << 5); -+ s[10] = h[3] >> 3; -+ s[11] = h[3] >> 11; -+ s[12] = (h[3] >> 19) | (h[4] << 6); -+ s[13] = h[4] >> 2; -+ s[14] = h[4] >> 10; -+ s[15] = h[4] >> 18; -+ s[16] = h[5] >> 0; -+ s[17] = h[5] >> 8; -+ s[18] = h[5] >> 16; -+ s[19] = (h[5] >> 24) | (h[6] << 1); -+ s[20] = h[6] >> 7; -+ s[21] = h[6] >> 15; -+ s[22] = (h[6] >> 23) | (h[7] << 3); -+ s[23] = h[7] >> 5; -+ s[24] = h[7] >> 13; -+ s[25] = (h[7] >> 21) | (h[8] << 4); -+ s[26] = h[8] >> 4; -+ s[27] = h[8] >> 12; -+ s[28] = (h[8] >> 20) | (h[9] << 6); -+ s[29] = h[9] >> 2; -+ s[30] = h[9] >> 10; -+ s[31] = h[9] >> 18; -+} -+ -+// h = 0 -+static void fe_0(fe *h) { -+ memset(h, 0, sizeof(fe)); -+} -+ -+static void fe_loose_0(fe_loose *h) { -+ memset(h, 0, sizeof(fe_loose)); -+} -+ -+// h = 1 -+static void fe_1(fe *h) { -+ memset(h, 0, sizeof(fe)); -+ h->v[0] = 1; -+} -+ -+static void fe_loose_1(fe_loose *h) { -+ memset(h, 0, sizeof(fe_loose)); -+ h->v[0] = 1; -+} -+ -+static void fe_add_impl(uint32_t out[10], const uint32_t in1[10], const uint32_t in2[10]) { -+ { const uint32_t x20 = in1[9]; -+ { const uint32_t x21 = in1[8]; -+ { const uint32_t x19 = in1[7]; -+ { const uint32_t x17 = in1[6]; -+ { const uint32_t x15 = in1[5]; -+ { const uint32_t x13 = in1[4]; -+ { const uint32_t x11 = in1[3]; -+ { const uint32_t x9 = in1[2]; -+ { const uint32_t x7 = in1[1]; -+ { const uint32_t x5 = in1[0]; -+ { const uint32_t x38 = in2[9]; -+ { const uint32_t x39 = in2[8]; -+ { const uint32_t x37 = in2[7]; -+ { const uint32_t x35 = in2[6]; -+ { const uint32_t x33 = in2[5]; -+ { const uint32_t x31 = in2[4]; -+ { const uint32_t x29 = in2[3]; -+ { const uint32_t x27 = in2[2]; -+ { const uint32_t x25 = in2[1]; -+ { const uint32_t x23 = in2[0]; -+ out[0] = (x5 + x23); -+ out[1] = (x7 + x25); -+ out[2] = (x9 + x27); -+ out[3] = (x11 + x29); -+ out[4] = (x13 + x31); -+ out[5] = (x15 + x33); -+ out[6] = (x17 + x35); -+ out[7] = (x19 + x37); -+ out[8] = (x21 + x39); -+ out[9] = (x20 + x38); -+ }}}}}}}}}}}}}}}}}}}} -+} -+ -+// h = f + g -+// Can overlap h with f or g. -+static void fe_add(fe_loose *h, const fe *f, const fe *g) { -+ assert_fe(f->v); -+ assert_fe(g->v); -+ fe_add_impl(h->v, f->v, g->v); -+ assert_fe_loose(h->v); -+} -+ -+static void fe_sub_impl(uint32_t out[10], const uint32_t in1[10], const uint32_t in2[10]) { -+ { const uint32_t x20 = in1[9]; -+ { const uint32_t x21 = in1[8]; -+ { const uint32_t x19 = in1[7]; -+ { const uint32_t x17 = in1[6]; -+ { const uint32_t x15 = in1[5]; -+ { const uint32_t x13 = in1[4]; -+ { const uint32_t x11 = in1[3]; -+ { const uint32_t x9 = in1[2]; -+ { const uint32_t x7 = in1[1]; -+ { const uint32_t x5 = in1[0]; -+ { const uint32_t x38 = in2[9]; -+ { const uint32_t x39 = in2[8]; -+ { const uint32_t x37 = in2[7]; -+ { const uint32_t x35 = in2[6]; -+ { const uint32_t x33 = in2[5]; -+ { const uint32_t x31 = in2[4]; -+ { const uint32_t x29 = in2[3]; -+ { const uint32_t x27 = in2[2]; -+ { const uint32_t x25 = in2[1]; -+ { const uint32_t x23 = in2[0]; -+ out[0] = ((0x7ffffda + x5) - x23); -+ out[1] = ((0x3fffffe + x7) - x25); -+ out[2] = ((0x7fffffe + x9) - x27); -+ out[3] = ((0x3fffffe + x11) - x29); -+ out[4] = ((0x7fffffe + x13) - x31); -+ out[5] = ((0x3fffffe + x15) - x33); -+ out[6] = ((0x7fffffe + x17) - x35); -+ out[7] = ((0x3fffffe + x19) - x37); -+ out[8] = ((0x7fffffe + x21) - x39); -+ out[9] = ((0x3fffffe + x20) - x38); -+ }}}}}}}}}}}}}}}}}}}} -+} -+ -+// h = f - g -+// Can overlap h with f or g. -+static void fe_sub(fe_loose *h, const fe *f, const fe *g) { -+ assert_fe(f->v); -+ assert_fe(g->v); -+ fe_sub_impl(h->v, f->v, g->v); -+ assert_fe_loose(h->v); -+} -+ -+static void fe_carry_impl(uint32_t out[10], const uint32_t in1[10]) { -+ { const uint32_t x17 = in1[9]; -+ { const uint32_t x18 = in1[8]; -+ { const uint32_t x16 = in1[7]; -+ { const uint32_t x14 = in1[6]; -+ { const uint32_t x12 = in1[5]; -+ { const uint32_t x10 = in1[4]; -+ { const uint32_t x8 = in1[3]; -+ { const uint32_t x6 = in1[2]; -+ { const uint32_t x4 = in1[1]; -+ { const uint32_t x2 = in1[0]; -+ { uint32_t x19 = (x2 >> 0x1a); -+ { uint32_t x20 = (x2 & 0x3ffffff); -+ { uint32_t x21 = (x19 + x4); -+ { uint32_t x22 = (x21 >> 0x19); -+ { uint32_t x23 = (x21 & 0x1ffffff); -+ { uint32_t x24 = (x22 + x6); -+ { uint32_t x25 = (x24 >> 0x1a); -+ { uint32_t x26 = (x24 & 0x3ffffff); -+ { uint32_t x27 = (x25 + x8); -+ { uint32_t x28 = (x27 >> 0x19); -+ { uint32_t x29 = (x27 & 0x1ffffff); -+ { uint32_t x30 = (x28 + x10); -+ { uint32_t x31 = (x30 >> 0x1a); -+ { uint32_t x32 = (x30 & 0x3ffffff); -+ { uint32_t x33 = (x31 + x12); -+ { uint32_t x34 = (x33 >> 0x19); -+ { uint32_t x35 = (x33 & 0x1ffffff); -+ { uint32_t x36 = (x34 + x14); -+ { uint32_t x37 = (x36 >> 0x1a); -+ { uint32_t x38 = (x36 & 0x3ffffff); -+ { uint32_t x39 = (x37 + x16); -+ { uint32_t x40 = (x39 >> 0x19); -+ { uint32_t x41 = (x39 & 0x1ffffff); -+ { uint32_t x42 = (x40 + x18); -+ { uint32_t x43 = (x42 >> 0x1a); -+ { uint32_t x44 = (x42 & 0x3ffffff); -+ { uint32_t x45 = (x43 + x17); -+ { uint32_t x46 = (x45 >> 0x19); -+ { uint32_t x47 = (x45 & 0x1ffffff); -+ { uint32_t x48 = (x20 + (0x13 * x46)); -+ { uint32_t x49 = (x48 >> 0x1a); -+ { uint32_t x50 = (x48 & 0x3ffffff); -+ { uint32_t x51 = (x49 + x23); -+ { uint32_t x52 = (x51 >> 0x19); -+ { uint32_t x53 = (x51 & 0x1ffffff); -+ out[0] = x50; -+ out[1] = x53; -+ out[2] = (x52 + x26); -+ out[3] = x29; -+ out[4] = x32; -+ out[5] = x35; -+ out[6] = x38; -+ out[7] = x41; -+ out[8] = x44; -+ out[9] = x47; -+ }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}} -+} -+ -+static void fe_carry(fe *h, const fe_loose* f) { -+ assert_fe_loose(f->v); -+ fe_carry_impl(h->v, f->v); -+ assert_fe(h->v); -+} -+ -+static void fe_mul_impl(uint32_t out[10], const uint32_t in1[10], const uint32_t in2[10]) { -+ assert_fe_loose(in1); -+ assert_fe_loose(in2); -+ { const uint32_t x20 = in1[9]; -+ { const uint32_t x21 = in1[8]; -+ { const uint32_t x19 = in1[7]; -+ { const uint32_t x17 = in1[6]; -+ { const uint32_t x15 = in1[5]; -+ { const uint32_t x13 = in1[4]; -+ { const uint32_t x11 = in1[3]; -+ { const uint32_t x9 = in1[2]; -+ { const uint32_t x7 = in1[1]; -+ { const uint32_t x5 = in1[0]; -+ { const uint32_t x38 = in2[9]; -+ { const uint32_t x39 = in2[8]; -+ { const uint32_t x37 = in2[7]; -+ { const uint32_t x35 = in2[6]; -+ { const uint32_t x33 = in2[5]; -+ { const uint32_t x31 = in2[4]; -+ { const uint32_t x29 = in2[3]; -+ { const uint32_t x27 = in2[2]; -+ { const uint32_t x25 = in2[1]; -+ { const uint32_t x23 = in2[0]; -+ { uint64_t x40 = ((uint64_t)x23 * x5); -+ { uint64_t x41 = (((uint64_t)x23 * x7) + ((uint64_t)x25 * x5)); -+ { uint64_t x42 = ((((uint64_t)(0x2 * x25) * x7) + ((uint64_t)x23 * x9)) + ((uint64_t)x27 * x5)); -+ { uint64_t x43 = (((((uint64_t)x25 * x9) + ((uint64_t)x27 * x7)) + ((uint64_t)x23 * x11)) + ((uint64_t)x29 * x5)); -+ { uint64_t x44 = (((((uint64_t)x27 * x9) + (0x2 * (((uint64_t)x25 * x11) + ((uint64_t)x29 * x7)))) + ((uint64_t)x23 * x13)) + ((uint64_t)x31 * x5)); -+ { uint64_t x45 = (((((((uint64_t)x27 * x11) + ((uint64_t)x29 * x9)) + ((uint64_t)x25 * x13)) + ((uint64_t)x31 * x7)) + ((uint64_t)x23 * x15)) + ((uint64_t)x33 * x5)); -+ { uint64_t x46 = (((((0x2 * ((((uint64_t)x29 * x11) + ((uint64_t)x25 * x15)) + ((uint64_t)x33 * x7))) + ((uint64_t)x27 * x13)) + ((uint64_t)x31 * x9)) + ((uint64_t)x23 * x17)) + ((uint64_t)x35 * x5)); -+ { uint64_t x47 = (((((((((uint64_t)x29 * x13) + ((uint64_t)x31 * x11)) + ((uint64_t)x27 * x15)) + ((uint64_t)x33 * x9)) + ((uint64_t)x25 * x17)) + ((uint64_t)x35 * x7)) + ((uint64_t)x23 * x19)) + ((uint64_t)x37 * x5)); -+ { uint64_t x48 = (((((((uint64_t)x31 * x13) + (0x2 * (((((uint64_t)x29 * x15) + ((uint64_t)x33 * x11)) + ((uint64_t)x25 * x19)) + ((uint64_t)x37 * x7)))) + ((uint64_t)x27 * x17)) + ((uint64_t)x35 * x9)) + ((uint64_t)x23 * x21)) + ((uint64_t)x39 * x5)); -+ { uint64_t x49 = (((((((((((uint64_t)x31 * x15) + ((uint64_t)x33 * x13)) + ((uint64_t)x29 * x17)) + ((uint64_t)x35 * x11)) + ((uint64_t)x27 * x19)) + ((uint64_t)x37 * x9)) + ((uint64_t)x25 * x21)) + ((uint64_t)x39 * x7)) + ((uint64_t)x23 * x20)) + ((uint64_t)x38 * x5)); -+ { uint64_t x50 = (((((0x2 * ((((((uint64_t)x33 * x15) + ((uint64_t)x29 * x19)) + ((uint64_t)x37 * x11)) + ((uint64_t)x25 * x20)) + ((uint64_t)x38 * x7))) + ((uint64_t)x31 * x17)) + ((uint64_t)x35 * x13)) + ((uint64_t)x27 * x21)) + ((uint64_t)x39 * x9)); -+ { uint64_t x51 = (((((((((uint64_t)x33 * x17) + ((uint64_t)x35 * x15)) + ((uint64_t)x31 * x19)) + ((uint64_t)x37 * x13)) + ((uint64_t)x29 * x21)) + ((uint64_t)x39 * x11)) + ((uint64_t)x27 * x20)) + ((uint64_t)x38 * x9)); -+ { uint64_t x52 = (((((uint64_t)x35 * x17) + (0x2 * (((((uint64_t)x33 * x19) + ((uint64_t)x37 * x15)) + ((uint64_t)x29 * x20)) + ((uint64_t)x38 * x11)))) + ((uint64_t)x31 * x21)) + ((uint64_t)x39 * x13)); -+ { uint64_t x53 = (((((((uint64_t)x35 * x19) + ((uint64_t)x37 * x17)) + ((uint64_t)x33 * x21)) + ((uint64_t)x39 * x15)) + ((uint64_t)x31 * x20)) + ((uint64_t)x38 * x13)); -+ { uint64_t x54 = (((0x2 * ((((uint64_t)x37 * x19) + ((uint64_t)x33 * x20)) + ((uint64_t)x38 * x15))) + ((uint64_t)x35 * x21)) + ((uint64_t)x39 * x17)); -+ { uint64_t x55 = (((((uint64_t)x37 * x21) + ((uint64_t)x39 * x19)) + ((uint64_t)x35 * x20)) + ((uint64_t)x38 * x17)); -+ { uint64_t x56 = (((uint64_t)x39 * x21) + (0x2 * (((uint64_t)x37 * x20) + ((uint64_t)x38 * x19)))); -+ { uint64_t x57 = (((uint64_t)x39 * x20) + ((uint64_t)x38 * x21)); -+ { uint64_t x58 = ((uint64_t)(0x2 * x38) * x20); -+ { uint64_t x59 = (x48 + (x58 << 0x4)); -+ { uint64_t x60 = (x59 + (x58 << 0x1)); -+ { uint64_t x61 = (x60 + x58); -+ { uint64_t x62 = (x47 + (x57 << 0x4)); -+ { uint64_t x63 = (x62 + (x57 << 0x1)); -+ { uint64_t x64 = (x63 + x57); -+ { uint64_t x65 = (x46 + (x56 << 0x4)); -+ { uint64_t x66 = (x65 + (x56 << 0x1)); -+ { uint64_t x67 = (x66 + x56); -+ { uint64_t x68 = (x45 + (x55 << 0x4)); -+ { uint64_t x69 = (x68 + (x55 << 0x1)); -+ { uint64_t x70 = (x69 + x55); -+ { uint64_t x71 = (x44 + (x54 << 0x4)); -+ { uint64_t x72 = (x71 + (x54 << 0x1)); -+ { uint64_t x73 = (x72 + x54); -+ { uint64_t x74 = (x43 + (x53 << 0x4)); -+ { uint64_t x75 = (x74 + (x53 << 0x1)); -+ { uint64_t x76 = (x75 + x53); -+ { uint64_t x77 = (x42 + (x52 << 0x4)); -+ { uint64_t x78 = (x77 + (x52 << 0x1)); -+ { uint64_t x79 = (x78 + x52); -+ { uint64_t x80 = (x41 + (x51 << 0x4)); -+ { uint64_t x81 = (x80 + (x51 << 0x1)); -+ { uint64_t x82 = (x81 + x51); -+ { uint64_t x83 = (x40 + (x50 << 0x4)); -+ { uint64_t x84 = (x83 + (x50 << 0x1)); -+ { uint64_t x85 = (x84 + x50); -+ { uint64_t x86 = (x85 >> 0x1a); -+ { uint32_t x87 = ((uint32_t)x85 & 0x3ffffff); -+ { uint64_t x88 = (x86 + x82); -+ { uint64_t x89 = (x88 >> 0x19); -+ { uint32_t x90 = ((uint32_t)x88 & 0x1ffffff); -+ { uint64_t x91 = (x89 + x79); -+ { uint64_t x92 = (x91 >> 0x1a); -+ { uint32_t x93 = ((uint32_t)x91 & 0x3ffffff); -+ { uint64_t x94 = (x92 + x76); -+ { uint64_t x95 = (x94 >> 0x19); -+ { uint32_t x96 = ((uint32_t)x94 & 0x1ffffff); -+ { uint64_t x97 = (x95 + x73); -+ { uint64_t x98 = (x97 >> 0x1a); -+ { uint32_t x99 = ((uint32_t)x97 & 0x3ffffff); -+ { uint64_t x100 = (x98 + x70); -+ { uint64_t x101 = (x100 >> 0x19); -+ { uint32_t x102 = ((uint32_t)x100 & 0x1ffffff); -+ { uint64_t x103 = (x101 + x67); -+ { uint64_t x104 = (x103 >> 0x1a); -+ { uint32_t x105 = ((uint32_t)x103 & 0x3ffffff); -+ { uint64_t x106 = (x104 + x64); -+ { uint64_t x107 = (x106 >> 0x19); -+ { uint32_t x108 = ((uint32_t)x106 & 0x1ffffff); -+ { uint64_t x109 = (x107 + x61); -+ { uint64_t x110 = (x109 >> 0x1a); -+ { uint32_t x111 = ((uint32_t)x109 & 0x3ffffff); -+ { uint64_t x112 = (x110 + x49); -+ { uint64_t x113 = (x112 >> 0x19); -+ { uint32_t x114 = ((uint32_t)x112 & 0x1ffffff); -+ { uint64_t x115 = (x87 + (0x13 * x113)); -+ { uint32_t x116 = (uint32_t) (x115 >> 0x1a); -+ { uint32_t x117 = ((uint32_t)x115 & 0x3ffffff); -+ { uint32_t x118 = (x116 + x90); -+ { uint32_t x119 = (x118 >> 0x19); -+ { uint32_t x120 = (x118 & 0x1ffffff); -+ out[0] = x117; -+ out[1] = x120; -+ out[2] = (x119 + x93); -+ out[3] = x96; -+ out[4] = x99; -+ out[5] = x102; -+ out[6] = x105; -+ out[7] = x108; -+ out[8] = x111; -+ out[9] = x114; -+ }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}} -+ assert_fe(out); -+} -+ -+static void fe_mul_ltt(fe_loose *h, const fe *f, const fe *g) { -+ fe_mul_impl(h->v, f->v, g->v); -+} -+ -+static void fe_mul_llt(fe_loose *h, const fe_loose *f, const fe *g) { -+ fe_mul_impl(h->v, f->v, g->v); -+} -+ -+static void fe_mul_ttt(fe *h, const fe *f, const fe *g) { -+ fe_mul_impl(h->v, f->v, g->v); -+} -+ -+static void fe_mul_tlt(fe *h, const fe_loose *f, const fe *g) { -+ fe_mul_impl(h->v, f->v, g->v); -+} -+ -+static void fe_mul_ttl(fe *h, const fe *f, const fe_loose *g) { -+ fe_mul_impl(h->v, f->v, g->v); -+} -+ -+static void fe_mul_tll(fe *h, const fe_loose *f, const fe_loose *g) { -+ fe_mul_impl(h->v, f->v, g->v); -+} -+ -+static void fe_sqr_impl(uint32_t out[10], const uint32_t in1[10]) { -+ assert_fe_loose(in1); -+ { const uint32_t x17 = in1[9]; -+ { const uint32_t x18 = in1[8]; -+ { const uint32_t x16 = in1[7]; -+ { const uint32_t x14 = in1[6]; -+ { const uint32_t x12 = in1[5]; -+ { const uint32_t x10 = in1[4]; -+ { const uint32_t x8 = in1[3]; -+ { const uint32_t x6 = in1[2]; -+ { const uint32_t x4 = in1[1]; -+ { const uint32_t x2 = in1[0]; -+ { uint64_t x19 = ((uint64_t)x2 * x2); -+ { uint64_t x20 = ((uint64_t)(0x2 * x2) * x4); -+ { uint64_t x21 = (0x2 * (((uint64_t)x4 * x4) + ((uint64_t)x2 * x6))); -+ { uint64_t x22 = (0x2 * (((uint64_t)x4 * x6) + ((uint64_t)x2 * x8))); -+ { uint64_t x23 = ((((uint64_t)x6 * x6) + ((uint64_t)(0x4 * x4) * x8)) + ((uint64_t)(0x2 * x2) * x10)); -+ { uint64_t x24 = (0x2 * ((((uint64_t)x6 * x8) + ((uint64_t)x4 * x10)) + ((uint64_t)x2 * x12))); -+ { uint64_t x25 = (0x2 * (((((uint64_t)x8 * x8) + ((uint64_t)x6 * x10)) + ((uint64_t)x2 * x14)) + ((uint64_t)(0x2 * x4) * x12))); -+ { uint64_t x26 = (0x2 * (((((uint64_t)x8 * x10) + ((uint64_t)x6 * x12)) + ((uint64_t)x4 * x14)) + ((uint64_t)x2 * x16))); -+ { uint64_t x27 = (((uint64_t)x10 * x10) + (0x2 * ((((uint64_t)x6 * x14) + ((uint64_t)x2 * x18)) + (0x2 * (((uint64_t)x4 * x16) + ((uint64_t)x8 * x12)))))); -+ { uint64_t x28 = (0x2 * ((((((uint64_t)x10 * x12) + ((uint64_t)x8 * x14)) + ((uint64_t)x6 * x16)) + ((uint64_t)x4 * x18)) + ((uint64_t)x2 * x17))); -+ { uint64_t x29 = (0x2 * (((((uint64_t)x12 * x12) + ((uint64_t)x10 * x14)) + ((uint64_t)x6 * x18)) + (0x2 * (((uint64_t)x8 * x16) + ((uint64_t)x4 * x17))))); -+ { uint64_t x30 = (0x2 * (((((uint64_t)x12 * x14) + ((uint64_t)x10 * x16)) + ((uint64_t)x8 * x18)) + ((uint64_t)x6 * x17))); -+ { uint64_t x31 = (((uint64_t)x14 * x14) + (0x2 * (((uint64_t)x10 * x18) + (0x2 * (((uint64_t)x12 * x16) + ((uint64_t)x8 * x17)))))); -+ { uint64_t x32 = (0x2 * ((((uint64_t)x14 * x16) + ((uint64_t)x12 * x18)) + ((uint64_t)x10 * x17))); -+ { uint64_t x33 = (0x2 * ((((uint64_t)x16 * x16) + ((uint64_t)x14 * x18)) + ((uint64_t)(0x2 * x12) * x17))); -+ { uint64_t x34 = (0x2 * (((uint64_t)x16 * x18) + ((uint64_t)x14 * x17))); -+ { uint64_t x35 = (((uint64_t)x18 * x18) + ((uint64_t)(0x4 * x16) * x17)); -+ { uint64_t x36 = ((uint64_t)(0x2 * x18) * x17); -+ { uint64_t x37 = ((uint64_t)(0x2 * x17) * x17); -+ { uint64_t x38 = (x27 + (x37 << 0x4)); -+ { uint64_t x39 = (x38 + (x37 << 0x1)); -+ { uint64_t x40 = (x39 + x37); -+ { uint64_t x41 = (x26 + (x36 << 0x4)); -+ { uint64_t x42 = (x41 + (x36 << 0x1)); -+ { uint64_t x43 = (x42 + x36); -+ { uint64_t x44 = (x25 + (x35 << 0x4)); -+ { uint64_t x45 = (x44 + (x35 << 0x1)); -+ { uint64_t x46 = (x45 + x35); -+ { uint64_t x47 = (x24 + (x34 << 0x4)); -+ { uint64_t x48 = (x47 + (x34 << 0x1)); -+ { uint64_t x49 = (x48 + x34); -+ { uint64_t x50 = (x23 + (x33 << 0x4)); -+ { uint64_t x51 = (x50 + (x33 << 0x1)); -+ { uint64_t x52 = (x51 + x33); -+ { uint64_t x53 = (x22 + (x32 << 0x4)); -+ { uint64_t x54 = (x53 + (x32 << 0x1)); -+ { uint64_t x55 = (x54 + x32); -+ { uint64_t x56 = (x21 + (x31 << 0x4)); -+ { uint64_t x57 = (x56 + (x31 << 0x1)); -+ { uint64_t x58 = (x57 + x31); -+ { uint64_t x59 = (x20 + (x30 << 0x4)); -+ { uint64_t x60 = (x59 + (x30 << 0x1)); -+ { uint64_t x61 = (x60 + x30); -+ { uint64_t x62 = (x19 + (x29 << 0x4)); -+ { uint64_t x63 = (x62 + (x29 << 0x1)); -+ { uint64_t x64 = (x63 + x29); -+ { uint64_t x65 = (x64 >> 0x1a); -+ { uint32_t x66 = ((uint32_t)x64 & 0x3ffffff); -+ { uint64_t x67 = (x65 + x61); -+ { uint64_t x68 = (x67 >> 0x19); -+ { uint32_t x69 = ((uint32_t)x67 & 0x1ffffff); -+ { uint64_t x70 = (x68 + x58); -+ { uint64_t x71 = (x70 >> 0x1a); -+ { uint32_t x72 = ((uint32_t)x70 & 0x3ffffff); -+ { uint64_t x73 = (x71 + x55); -+ { uint64_t x74 = (x73 >> 0x19); -+ { uint32_t x75 = ((uint32_t)x73 & 0x1ffffff); -+ { uint64_t x76 = (x74 + x52); -+ { uint64_t x77 = (x76 >> 0x1a); -+ { uint32_t x78 = ((uint32_t)x76 & 0x3ffffff); -+ { uint64_t x79 = (x77 + x49); -+ { uint64_t x80 = (x79 >> 0x19); -+ { uint32_t x81 = ((uint32_t)x79 & 0x1ffffff); -+ { uint64_t x82 = (x80 + x46); -+ { uint64_t x83 = (x82 >> 0x1a); -+ { uint32_t x84 = ((uint32_t)x82 & 0x3ffffff); -+ { uint64_t x85 = (x83 + x43); -+ { uint64_t x86 = (x85 >> 0x19); -+ { uint32_t x87 = ((uint32_t)x85 & 0x1ffffff); -+ { uint64_t x88 = (x86 + x40); -+ { uint64_t x89 = (x88 >> 0x1a); -+ { uint32_t x90 = ((uint32_t)x88 & 0x3ffffff); -+ { uint64_t x91 = (x89 + x28); -+ { uint64_t x92 = (x91 >> 0x19); -+ { uint32_t x93 = ((uint32_t)x91 & 0x1ffffff); -+ { uint64_t x94 = (x66 + (0x13 * x92)); -+ { uint32_t x95 = (uint32_t) (x94 >> 0x1a); -+ { uint32_t x96 = ((uint32_t)x94 & 0x3ffffff); -+ { uint32_t x97 = (x95 + x69); -+ { uint32_t x98 = (x97 >> 0x19); -+ { uint32_t x99 = (x97 & 0x1ffffff); -+ out[0] = x96; -+ out[1] = x99; -+ out[2] = (x98 + x72); -+ out[3] = x75; -+ out[4] = x78; -+ out[5] = x81; -+ out[6] = x84; -+ out[7] = x87; -+ out[8] = x90; -+ out[9] = x93; -+ }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}} -+ assert_fe(out); -+} -+ -+static void fe_sq_tl(fe *h, const fe_loose *f) { -+ fe_sqr_impl(h->v, f->v); -+} -+ -+static void fe_sq_tt(fe *h, const fe *f) { -+ fe_sqr_impl(h->v, f->v); -+} -+ -+// Adapted from Fiat-synthesized |fe_sub_impl| with |out| = 0. -+static void fe_neg_impl(uint32_t out[10], const uint32_t in2[10]) { -+ { const uint32_t x20 = 0; -+ { const uint32_t x21 = 0; -+ { const uint32_t x19 = 0; -+ { const uint32_t x17 = 0; -+ { const uint32_t x15 = 0; -+ { const uint32_t x13 = 0; -+ { const uint32_t x11 = 0; -+ { const uint32_t x9 = 0; -+ { const uint32_t x7 = 0; -+ { const uint32_t x5 = 0; -+ { const uint32_t x38 = in2[9]; -+ { const uint32_t x39 = in2[8]; -+ { const uint32_t x37 = in2[7]; -+ { const uint32_t x35 = in2[6]; -+ { const uint32_t x33 = in2[5]; -+ { const uint32_t x31 = in2[4]; -+ { const uint32_t x29 = in2[3]; -+ { const uint32_t x27 = in2[2]; -+ { const uint32_t x25 = in2[1]; -+ { const uint32_t x23 = in2[0]; -+ out[0] = ((0x7ffffda + x5) - x23); -+ out[1] = ((0x3fffffe + x7) - x25); -+ out[2] = ((0x7fffffe + x9) - x27); -+ out[3] = ((0x3fffffe + x11) - x29); -+ out[4] = ((0x7fffffe + x13) - x31); -+ out[5] = ((0x3fffffe + x15) - x33); -+ out[6] = ((0x7fffffe + x17) - x35); -+ out[7] = ((0x3fffffe + x19) - x37); -+ out[8] = ((0x7fffffe + x21) - x39); -+ out[9] = ((0x3fffffe + x20) - x38); -+ }}}}}}}}}}}}}}}}}}}} -+} -+ -+// h = -f -+static void fe_neg(fe_loose *h, const fe *f) { -+ assert_fe(f->v); -+ fe_neg_impl(h->v, f->v); -+ assert_fe_loose(h->v); -+} -+ -+// Replace (f,g) with (g,g) if b == 1; -+// replace (f,g) with (f,g) if b == 0. -+// -+// Preconditions: b in {0,1}. -+static void fe_cmov(fe_loose *f, const fe_loose *g, unsigned b) { -+ b = 0-b; -+ unsigned i; -+ for (i = 0; i < 10; i++) { -+ uint32_t x = f->v[i] ^ g->v[i]; -+ x &= b; -+ f->v[i] ^= x; -+ } -+} -+ -+#endif // BORINGSSL_CURVE25519_64BIT -+ -+// h = f -+static void fe_copy(fe *h, const fe *f) { -+ memmove(h, f, sizeof(fe)); -+} -+ -+static void fe_copy_lt(fe_loose *h, const fe *f) { -+#ifdef EDWARDS25519_ASSERTS -+ assert(sizeof(fe_loose) == sizeof(fe)); -+#endif -+ memmove(h, f, sizeof(fe)); -+} -+#if !defined(CONFIG_SMALL) -+static void fe_copy_ll(fe_loose *h, const fe_loose *f) { -+ memmove(h, f, sizeof(fe_loose)); -+} -+#endif // !defined(CONFIG_SMALL) -+ -+static void fe_loose_invert(fe *out, const fe_loose *z) { -+ fe t0; -+ fe t1; -+ fe t2; -+ fe t3; -+ int i; -+ -+ fe_sq_tl(&t0, z); -+ fe_sq_tt(&t1, &t0); -+ for (i = 1; i < 2; ++i) { -+ fe_sq_tt(&t1, &t1); -+ } -+ fe_mul_tlt(&t1, z, &t1); -+ fe_mul_ttt(&t0, &t0, &t1); -+ fe_sq_tt(&t2, &t0); -+ fe_mul_ttt(&t1, &t1, &t2); -+ fe_sq_tt(&t2, &t1); -+ for (i = 1; i < 5; ++i) { -+ fe_sq_tt(&t2, &t2); -+ } -+ fe_mul_ttt(&t1, &t2, &t1); -+ fe_sq_tt(&t2, &t1); -+ for (i = 1; i < 10; ++i) { -+ fe_sq_tt(&t2, &t2); -+ } -+ fe_mul_ttt(&t2, &t2, &t1); -+ fe_sq_tt(&t3, &t2); -+ for (i = 1; i < 20; ++i) { -+ fe_sq_tt(&t3, &t3); -+ } -+ fe_mul_ttt(&t2, &t3, &t2); -+ fe_sq_tt(&t2, &t2); -+ for (i = 1; i < 10; ++i) { -+ fe_sq_tt(&t2, &t2); -+ } -+ fe_mul_ttt(&t1, &t2, &t1); -+ fe_sq_tt(&t2, &t1); -+ for (i = 1; i < 50; ++i) { -+ fe_sq_tt(&t2, &t2); -+ } -+ fe_mul_ttt(&t2, &t2, &t1); -+ fe_sq_tt(&t3, &t2); -+ for (i = 1; i < 100; ++i) { -+ fe_sq_tt(&t3, &t3); -+ } -+ fe_mul_ttt(&t2, &t3, &t2); -+ fe_sq_tt(&t2, &t2); -+ for (i = 1; i < 50; ++i) { -+ fe_sq_tt(&t2, &t2); -+ } -+ fe_mul_ttt(&t1, &t2, &t1); -+ fe_sq_tt(&t1, &t1); -+ for (i = 1; i < 5; ++i) { -+ fe_sq_tt(&t1, &t1); -+ } -+ fe_mul_ttt(out, &t1, &t0); -+} -+ -+static void fe_invert(fe *out, const fe *z) { -+ fe_loose l; -+ fe_copy_lt(&l, z); -+ fe_loose_invert(out, &l); -+} -+ -+// return 0 if f == 0 -+// return 1 if f != 0 -+static int fe_isnonzero(const fe_loose *f) { -+ fe tight; -+ fe_carry(&tight, f); -+ uint8_t s[32]; -+ fe_tobytes(s, &tight); -+ -+ static const uint8_t zero[32] = {0}; -+ return k5_bcmp(s, zero, sizeof(zero)) != 0; -+} -+ -+// return 1 if f is in {1,3,5,...,q-2} -+// return 0 if f is in {0,2,4,...,q-1} -+static int fe_isnegative(const fe *f) { -+ uint8_t s[32]; -+ fe_tobytes(s, f); -+ return s[0] & 1; -+} -+ -+static void fe_sq2_tt(fe *h, const fe *f) { -+ // h = f^2 -+ fe_sq_tt(h, f); -+ -+ // h = h + h -+ fe_loose tmp; -+ fe_add(&tmp, h, h); -+ fe_carry(h, &tmp); -+} -+ -+static void fe_pow22523(fe *out, const fe *z) { -+ fe t0; -+ fe t1; -+ fe t2; -+ int i; -+ -+ fe_sq_tt(&t0, z); -+ fe_sq_tt(&t1, &t0); -+ for (i = 1; i < 2; ++i) { -+ fe_sq_tt(&t1, &t1); -+ } -+ fe_mul_ttt(&t1, z, &t1); -+ fe_mul_ttt(&t0, &t0, &t1); -+ fe_sq_tt(&t0, &t0); -+ fe_mul_ttt(&t0, &t1, &t0); -+ fe_sq_tt(&t1, &t0); -+ for (i = 1; i < 5; ++i) { -+ fe_sq_tt(&t1, &t1); -+ } -+ fe_mul_ttt(&t0, &t1, &t0); -+ fe_sq_tt(&t1, &t0); -+ for (i = 1; i < 10; ++i) { -+ fe_sq_tt(&t1, &t1); -+ } -+ fe_mul_ttt(&t1, &t1, &t0); -+ fe_sq_tt(&t2, &t1); -+ for (i = 1; i < 20; ++i) { -+ fe_sq_tt(&t2, &t2); -+ } -+ fe_mul_ttt(&t1, &t2, &t1); -+ fe_sq_tt(&t1, &t1); -+ for (i = 1; i < 10; ++i) { -+ fe_sq_tt(&t1, &t1); -+ } -+ fe_mul_ttt(&t0, &t1, &t0); -+ fe_sq_tt(&t1, &t0); -+ for (i = 1; i < 50; ++i) { -+ fe_sq_tt(&t1, &t1); -+ } -+ fe_mul_ttt(&t1, &t1, &t0); -+ fe_sq_tt(&t2, &t1); -+ for (i = 1; i < 100; ++i) { -+ fe_sq_tt(&t2, &t2); -+ } -+ fe_mul_ttt(&t1, &t2, &t1); -+ fe_sq_tt(&t1, &t1); -+ for (i = 1; i < 50; ++i) { -+ fe_sq_tt(&t1, &t1); -+ } -+ fe_mul_ttt(&t0, &t1, &t0); -+ fe_sq_tt(&t0, &t0); -+ for (i = 1; i < 2; ++i) { -+ fe_sq_tt(&t0, &t0); -+ } -+ fe_mul_ttt(out, &t0, z); -+} -+ -+ -+// Group operations. -+ -+static void x25519_ge_tobytes(uint8_t s[32], const ge_p2 *h) { -+ fe recip; -+ fe x; -+ fe y; -+ -+ fe_invert(&recip, &h->Z); -+ fe_mul_ttt(&x, &h->X, &recip); -+ fe_mul_ttt(&y, &h->Y, &recip); -+ fe_tobytes(s, &y); -+ s[31] ^= fe_isnegative(&x) << 7; -+} -+ -+static int x25519_ge_frombytes_vartime(ge_p3 *h, const uint8_t *s) { -+ fe u; -+ fe_loose v; -+ fe v3; -+ fe vxx; -+ fe_loose check; -+ -+ fe_frombytes(&h->Y, s); -+ fe_1(&h->Z); -+ fe_sq_tt(&v3, &h->Y); -+ fe_mul_ttt(&vxx, &v3, &d); -+ fe_sub(&v, &v3, &h->Z); // u = y^2-1 -+ fe_carry(&u, &v); -+ fe_add(&v, &vxx, &h->Z); // v = dy^2+1 -+ -+ fe_sq_tl(&v3, &v); -+ fe_mul_ttl(&v3, &v3, &v); // v3 = v^3 -+ fe_sq_tt(&h->X, &v3); -+ fe_mul_ttl(&h->X, &h->X, &v); -+ fe_mul_ttt(&h->X, &h->X, &u); // x = uv^7 -+ -+ fe_pow22523(&h->X, &h->X); // x = (uv^7)^((q-5)/8) -+ fe_mul_ttt(&h->X, &h->X, &v3); -+ fe_mul_ttt(&h->X, &h->X, &u); // x = uv^3(uv^7)^((q-5)/8) -+ -+ fe_sq_tt(&vxx, &h->X); -+ fe_mul_ttl(&vxx, &vxx, &v); -+ fe_sub(&check, &vxx, &u); -+ if (fe_isnonzero(&check)) { -+ fe_add(&check, &vxx, &u); -+ if (fe_isnonzero(&check)) { -+ return -1; -+ } -+ fe_mul_ttt(&h->X, &h->X, &sqrtm1); -+ } -+ -+ if (fe_isnegative(&h->X) != (s[31] >> 7)) { -+ fe_loose t; -+ fe_neg(&t, &h->X); -+ fe_carry(&h->X, &t); -+ } -+ -+ fe_mul_ttt(&h->T, &h->X, &h->Y); -+ return 0; -+} -+ -+static void ge_p2_0(ge_p2 *h) { -+ fe_0(&h->X); -+ fe_1(&h->Y); -+ fe_1(&h->Z); -+} -+ -+static void ge_p3_0(ge_p3 *h) { -+ fe_0(&h->X); -+ fe_1(&h->Y); -+ fe_1(&h->Z); -+ fe_0(&h->T); -+} -+ -+static void ge_cached_0(ge_cached *h) { -+ fe_loose_1(&h->YplusX); -+ fe_loose_1(&h->YminusX); -+ fe_loose_1(&h->Z); -+ fe_loose_0(&h->T2d); -+} -+ -+static void ge_precomp_0(ge_precomp *h) { -+ fe_loose_1(&h->yplusx); -+ fe_loose_1(&h->yminusx); -+ fe_loose_0(&h->xy2d); -+} -+ -+// r = p -+static void ge_p3_to_p2(ge_p2 *r, const ge_p3 *p) { -+ fe_copy(&r->X, &p->X); -+ fe_copy(&r->Y, &p->Y); -+ fe_copy(&r->Z, &p->Z); -+} -+ -+// r = p -+static void x25519_ge_p3_to_cached(ge_cached *r, const ge_p3 *p) { -+ fe_add(&r->YplusX, &p->Y, &p->X); -+ fe_sub(&r->YminusX, &p->Y, &p->X); -+ fe_copy_lt(&r->Z, &p->Z); -+ fe_mul_ltt(&r->T2d, &p->T, &d2); -+} -+ -+// r = p -+static void x25519_ge_p1p1_to_p2(ge_p2 *r, const ge_p1p1 *p) { -+ fe_mul_tll(&r->X, &p->X, &p->T); -+ fe_mul_tll(&r->Y, &p->Y, &p->Z); -+ fe_mul_tll(&r->Z, &p->Z, &p->T); -+} -+ -+// r = p -+static void x25519_ge_p1p1_to_p3(ge_p3 *r, const ge_p1p1 *p) { -+ fe_mul_tll(&r->X, &p->X, &p->T); -+ fe_mul_tll(&r->Y, &p->Y, &p->Z); -+ fe_mul_tll(&r->Z, &p->Z, &p->T); -+ fe_mul_tll(&r->T, &p->X, &p->Y); -+} -+ -+// r = p -+static void ge_p1p1_to_cached(ge_cached *r, const ge_p1p1 *p) { -+ ge_p3 t; -+ x25519_ge_p1p1_to_p3(&t, p); -+ x25519_ge_p3_to_cached(r, &t); -+} -+ -+// r = 2 * p -+static void ge_p2_dbl(ge_p1p1 *r, const ge_p2 *p) { -+ fe trX, trZ, trT; -+ fe t0; -+ -+ fe_sq_tt(&trX, &p->X); -+ fe_sq_tt(&trZ, &p->Y); -+ fe_sq2_tt(&trT, &p->Z); -+ fe_add(&r->Y, &p->X, &p->Y); -+ fe_sq_tl(&t0, &r->Y); -+ -+ fe_add(&r->Y, &trZ, &trX); -+ fe_sub(&r->Z, &trZ, &trX); -+ fe_carry(&trZ, &r->Y); -+ fe_sub(&r->X, &t0, &trZ); -+ fe_carry(&trZ, &r->Z); -+ fe_sub(&r->T, &trT, &trZ); -+} -+ -+#ifndef CONFIG_SMALL -+// r = 2 * p -+static void ge_p3_dbl(ge_p1p1 *r, const ge_p3 *p) { -+ ge_p2 q; -+ ge_p3_to_p2(&q, p); -+ ge_p2_dbl(r, &q); -+} -+#endif -+ -+// r = p + q -+static void ge_madd(ge_p1p1 *r, const ge_p3 *p, const ge_precomp *q) { -+ fe trY, trZ, trT; -+ -+ fe_add(&r->X, &p->Y, &p->X); -+ fe_sub(&r->Y, &p->Y, &p->X); -+ fe_mul_tll(&trZ, &r->X, &q->yplusx); -+ fe_mul_tll(&trY, &r->Y, &q->yminusx); -+ fe_mul_tlt(&trT, &q->xy2d, &p->T); -+ fe_add(&r->T, &p->Z, &p->Z); -+ fe_sub(&r->X, &trZ, &trY); -+ fe_add(&r->Y, &trZ, &trY); -+ fe_carry(&trZ, &r->T); -+ fe_add(&r->Z, &trZ, &trT); -+ fe_sub(&r->T, &trZ, &trT); -+} -+ -+// r = p + q -+static void x25519_ge_add(ge_p1p1 *r, const ge_p3 *p, const ge_cached *q) { -+ fe trX, trY, trZ, trT; -+ -+ fe_add(&r->X, &p->Y, &p->X); -+ fe_sub(&r->Y, &p->Y, &p->X); -+ fe_mul_tll(&trZ, &r->X, &q->YplusX); -+ fe_mul_tll(&trY, &r->Y, &q->YminusX); -+ fe_mul_tlt(&trT, &q->T2d, &p->T); -+ fe_mul_ttl(&trX, &p->Z, &q->Z); -+ fe_add(&r->T, &trX, &trX); -+ fe_sub(&r->X, &trZ, &trY); -+ fe_add(&r->Y, &trZ, &trY); -+ fe_carry(&trZ, &r->T); -+ fe_add(&r->Z, &trZ, &trT); -+ fe_sub(&r->T, &trZ, &trT); -+} -+ -+// r = p - q -+static void x25519_ge_sub(ge_p1p1 *r, const ge_p3 *p, const ge_cached *q) { -+ fe trX, trY, trZ, trT; -+ -+ fe_add(&r->X, &p->Y, &p->X); -+ fe_sub(&r->Y, &p->Y, &p->X); -+ fe_mul_tll(&trZ, &r->X, &q->YminusX); -+ fe_mul_tll(&trY, &r->Y, &q->YplusX); -+ fe_mul_tlt(&trT, &q->T2d, &p->T); -+ fe_mul_ttl(&trX, &p->Z, &q->Z); -+ fe_add(&r->T, &trX, &trX); -+ fe_sub(&r->X, &trZ, &trY); -+ fe_add(&r->Y, &trZ, &trY); -+ fe_carry(&trZ, &r->T); -+ fe_sub(&r->Z, &trZ, &trT); -+ fe_add(&r->T, &trZ, &trT); -+} -+ -+static uint8_t equal(signed char b, signed char c) { -+ uint8_t ub = b; -+ uint8_t uc = c; -+ uint8_t x = ub ^ uc; // 0: yes; 1..255: no -+ uint32_t y = x; // 0: yes; 1..255: no -+ y -= 1; // 4294967295: yes; 0..254: no -+ y >>= 31; // 1: yes; 0: no -+ return y; -+} -+ -+static void cmov(ge_precomp *t, const ge_precomp *u, uint8_t b) { -+ fe_cmov(&t->yplusx, &u->yplusx, b); -+ fe_cmov(&t->yminusx, &u->yminusx, b); -+ fe_cmov(&t->xy2d, &u->xy2d, b); -+} -+ -+static void x25519_ge_scalarmult_small_precomp( -+ ge_p3 *h, const uint8_t a[32], const uint8_t precomp_table[15 * 2 * 32]) { -+ // precomp_table is first expanded into matching |ge_precomp| -+ // elements. -+ ge_precomp multiples[15]; -+ -+ unsigned i; -+ for (i = 0; i < 15; i++) { -+ const uint8_t *bytes = &precomp_table[i*(2 * 32)]; -+ fe x, y; -+ fe_frombytes(&x, bytes); -+ fe_frombytes(&y, bytes + 32); -+ -+ ge_precomp *out = &multiples[i]; -+ fe_add(&out->yplusx, &y, &x); -+ fe_sub(&out->yminusx, &y, &x); -+ fe_mul_ltt(&out->xy2d, &x, &y); -+ fe_mul_llt(&out->xy2d, &out->xy2d, &d2); -+ } -+ -+ // See the comment above |k25519SmallPrecomp| about the structure of the -+ // precomputed elements. This loop does 64 additions and 64 doublings to -+ // calculate the result. -+ ge_p3_0(h); -+ -+ for (i = 63; i < 64; i--) { -+ unsigned j; -+ signed char index = 0; -+ -+ for (j = 0; j < 4; j++) { -+ const uint8_t bit = 1 & (a[(8 * j) + (i / 8)] >> (i & 7)); -+ index |= (bit << j); -+ } -+ -+ ge_precomp e; -+ ge_precomp_0(&e); -+ -+ for (j = 1; j < 16; j++) { -+ cmov(&e, &multiples[j-1], equal(index, j)); -+ } -+ -+ ge_cached cached; -+ ge_p1p1 r; -+ x25519_ge_p3_to_cached(&cached, h); -+ x25519_ge_add(&r, h, &cached); -+ x25519_ge_p1p1_to_p3(h, &r); -+ -+ ge_madd(&r, h, &e); -+ x25519_ge_p1p1_to_p3(h, &r); -+ } -+} -+ -+#if defined(CONFIG_SMALL) -+ -+static void x25519_ge_scalarmult_base(ge_p3 *h, const uint8_t a[32]) { -+ x25519_ge_scalarmult_small_precomp(h, a, k25519SmallPrecomp); -+} -+ -+#else -+ -+static uint8_t negative(signed char b) { -+ uint32_t x = b; -+ x >>= 31; // 1: yes; 0: no -+ return x; -+} -+ -+static void table_select(ge_precomp *t, int pos, signed char b) { -+ ge_precomp minust; -+ uint8_t bnegative = negative(b); -+ uint8_t babs = b - ((uint8_t)((-bnegative) & b) << 1); -+ -+ ge_precomp_0(t); -+ cmov(t, &k25519Precomp[pos][0], equal(babs, 1)); -+ cmov(t, &k25519Precomp[pos][1], equal(babs, 2)); -+ cmov(t, &k25519Precomp[pos][2], equal(babs, 3)); -+ cmov(t, &k25519Precomp[pos][3], equal(babs, 4)); -+ cmov(t, &k25519Precomp[pos][4], equal(babs, 5)); -+ cmov(t, &k25519Precomp[pos][5], equal(babs, 6)); -+ cmov(t, &k25519Precomp[pos][6], equal(babs, 7)); -+ cmov(t, &k25519Precomp[pos][7], equal(babs, 8)); -+ fe_copy_ll(&minust.yplusx, &t->yminusx); -+ fe_copy_ll(&minust.yminusx, &t->yplusx); -+ -+ // NOTE: the input table is canonical, but types don't encode it -+ fe tmp; -+ fe_carry(&tmp, &t->xy2d); -+ fe_neg(&minust.xy2d, &tmp); -+ -+ cmov(t, &minust, bnegative); -+} -+ -+// h = a * B -+// where a = a[0]+256*a[1]+...+256^31 a[31] -+// B is the Ed25519 base point (x,4/5) with x positive. -+// -+// Preconditions: -+// a[31] <= 127 -+static void x25519_ge_scalarmult_base(ge_p3 *h, const uint8_t *a) { -+ signed char e[64]; -+ signed char carry; -+ ge_p1p1 r; -+ ge_p2 s; -+ ge_precomp t; -+ int i; -+ -+ for (i = 0; i < 32; ++i) { -+ e[2 * i + 0] = (a[i] >> 0) & 15; -+ e[2 * i + 1] = (a[i] >> 4) & 15; -+ } -+ // each e[i] is between 0 and 15 -+ // e[63] is between 0 and 7 -+ -+ carry = 0; -+ for (i = 0; i < 63; ++i) { -+ e[i] += carry; -+ carry = e[i] + 8; -+ carry >>= 4; -+ e[i] -= carry << 4; -+ } -+ e[63] += carry; -+ // each e[i] is between -8 and 8 -+ -+ ge_p3_0(h); -+ for (i = 1; i < 64; i += 2) { -+ table_select(&t, i / 2, e[i]); -+ ge_madd(&r, h, &t); -+ x25519_ge_p1p1_to_p3(h, &r); -+ } -+ -+ ge_p3_dbl(&r, h); -+ x25519_ge_p1p1_to_p2(&s, &r); -+ ge_p2_dbl(&r, &s); -+ x25519_ge_p1p1_to_p2(&s, &r); -+ ge_p2_dbl(&r, &s); -+ x25519_ge_p1p1_to_p2(&s, &r); -+ ge_p2_dbl(&r, &s); -+ x25519_ge_p1p1_to_p3(h, &r); -+ -+ for (i = 0; i < 64; i += 2) { -+ table_select(&t, i / 2, e[i]); -+ ge_madd(&r, h, &t); -+ x25519_ge_p1p1_to_p3(h, &r); -+ } -+} -+ -+#endif -+ -+static void cmov_cached(ge_cached *t, ge_cached *u, uint8_t b) { -+ fe_cmov(&t->YplusX, &u->YplusX, b); -+ fe_cmov(&t->YminusX, &u->YminusX, b); -+ fe_cmov(&t->Z, &u->Z, b); -+ fe_cmov(&t->T2d, &u->T2d, b); -+} -+ -+// r = scalar * A. -+// where a = a[0]+256*a[1]+...+256^31 a[31]. -+static void x25519_ge_scalarmult(ge_p2 *r, const uint8_t *scalar, -+ const ge_p3 *A) { -+ ge_p2 Ai_p2[8]; -+ ge_cached Ai[16]; -+ ge_p1p1 t; -+ -+ ge_cached_0(&Ai[0]); -+ x25519_ge_p3_to_cached(&Ai[1], A); -+ ge_p3_to_p2(&Ai_p2[1], A); -+ -+ unsigned i; -+ for (i = 2; i < 16; i += 2) { -+ ge_p2_dbl(&t, &Ai_p2[i / 2]); -+ ge_p1p1_to_cached(&Ai[i], &t); -+ if (i < 8) { -+ x25519_ge_p1p1_to_p2(&Ai_p2[i], &t); -+ } -+ x25519_ge_add(&t, A, &Ai[i]); -+ ge_p1p1_to_cached(&Ai[i + 1], &t); -+ if (i < 7) { -+ x25519_ge_p1p1_to_p2(&Ai_p2[i + 1], &t); -+ } -+ } -+ -+ ge_p2_0(r); -+ ge_p3 u; -+ -+ for (i = 0; i < 256; i += 4) { -+ ge_p2_dbl(&t, r); -+ x25519_ge_p1p1_to_p2(r, &t); -+ ge_p2_dbl(&t, r); -+ x25519_ge_p1p1_to_p2(r, &t); -+ ge_p2_dbl(&t, r); -+ x25519_ge_p1p1_to_p2(r, &t); -+ ge_p2_dbl(&t, r); -+ x25519_ge_p1p1_to_p3(&u, &t); -+ -+ uint8_t index = scalar[31 - i/8]; -+ index >>= 4 - (i & 4); -+ index &= 0xf; -+ -+ unsigned j; -+ ge_cached selected; -+ ge_cached_0(&selected); -+ for (j = 0; j < 16; j++) { -+ cmov_cached(&selected, &Ai[j], equal(j, index)); -+ } -+ -+ x25519_ge_add(&t, &u, &selected); -+ x25519_ge_p1p1_to_p2(r, &t); -+ } -+} -+ -+// The set of scalars is \Z/l -+// where l = 2^252 + 27742317777372353535851937790883648493. -+ -+// Input: -+// s[0]+256*s[1]+...+256^63*s[63] = s -+// -+// Output: -+// s[0]+256*s[1]+...+256^31*s[31] = s mod l -+// where l = 2^252 + 27742317777372353535851937790883648493. -+// Overwrites s in place. -+static void x25519_sc_reduce(uint8_t s[64]) { -+ int64_t s0 = 2097151 & load_3(s); -+ int64_t s1 = 2097151 & (load_4(s + 2) >> 5); -+ int64_t s2 = 2097151 & (load_3(s + 5) >> 2); -+ int64_t s3 = 2097151 & (load_4(s + 7) >> 7); -+ int64_t s4 = 2097151 & (load_4(s + 10) >> 4); -+ int64_t s5 = 2097151 & (load_3(s + 13) >> 1); -+ int64_t s6 = 2097151 & (load_4(s + 15) >> 6); -+ int64_t s7 = 2097151 & (load_3(s + 18) >> 3); -+ int64_t s8 = 2097151 & load_3(s + 21); -+ int64_t s9 = 2097151 & (load_4(s + 23) >> 5); -+ int64_t s10 = 2097151 & (load_3(s + 26) >> 2); -+ int64_t s11 = 2097151 & (load_4(s + 28) >> 7); -+ int64_t s12 = 2097151 & (load_4(s + 31) >> 4); -+ int64_t s13 = 2097151 & (load_3(s + 34) >> 1); -+ int64_t s14 = 2097151 & (load_4(s + 36) >> 6); -+ int64_t s15 = 2097151 & (load_3(s + 39) >> 3); -+ int64_t s16 = 2097151 & load_3(s + 42); -+ int64_t s17 = 2097151 & (load_4(s + 44) >> 5); -+ int64_t s18 = 2097151 & (load_3(s + 47) >> 2); -+ int64_t s19 = 2097151 & (load_4(s + 49) >> 7); -+ int64_t s20 = 2097151 & (load_4(s + 52) >> 4); -+ int64_t s21 = 2097151 & (load_3(s + 55) >> 1); -+ int64_t s22 = 2097151 & (load_4(s + 57) >> 6); -+ int64_t s23 = (load_4(s + 60) >> 3); -+ int64_t carry0; -+ int64_t carry1; -+ int64_t carry2; -+ int64_t carry3; -+ int64_t carry4; -+ int64_t carry5; -+ int64_t carry6; -+ int64_t carry7; -+ int64_t carry8; -+ int64_t carry9; -+ int64_t carry10; -+ int64_t carry11; -+ int64_t carry12; -+ int64_t carry13; -+ int64_t carry14; -+ int64_t carry15; -+ int64_t carry16; -+ -+ s11 += s23 * 666643; -+ s12 += s23 * 470296; -+ s13 += s23 * 654183; -+ s14 -= s23 * 997805; -+ s15 += s23 * 136657; -+ s16 -= s23 * 683901; -+ s23 = 0; -+ -+ s10 += s22 * 666643; -+ s11 += s22 * 470296; -+ s12 += s22 * 654183; -+ s13 -= s22 * 997805; -+ s14 += s22 * 136657; -+ s15 -= s22 * 683901; -+ s22 = 0; -+ -+ s9 += s21 * 666643; -+ s10 += s21 * 470296; -+ s11 += s21 * 654183; -+ s12 -= s21 * 997805; -+ s13 += s21 * 136657; -+ s14 -= s21 * 683901; -+ s21 = 0; -+ -+ s8 += s20 * 666643; -+ s9 += s20 * 470296; -+ s10 += s20 * 654183; -+ s11 -= s20 * 997805; -+ s12 += s20 * 136657; -+ s13 -= s20 * 683901; -+ s20 = 0; -+ -+ s7 += s19 * 666643; -+ s8 += s19 * 470296; -+ s9 += s19 * 654183; -+ s10 -= s19 * 997805; -+ s11 += s19 * 136657; -+ s12 -= s19 * 683901; -+ s19 = 0; -+ -+ s6 += s18 * 666643; -+ s7 += s18 * 470296; -+ s8 += s18 * 654183; -+ s9 -= s18 * 997805; -+ s10 += s18 * 136657; -+ s11 -= s18 * 683901; -+ s18 = 0; -+ -+ carry6 = (s6 + (1 << 20)) >> 21; -+ s7 += carry6; -+ s6 -= carry6 << 21; -+ carry8 = (s8 + (1 << 20)) >> 21; -+ s9 += carry8; -+ s8 -= carry8 << 21; -+ carry10 = (s10 + (1 << 20)) >> 21; -+ s11 += carry10; -+ s10 -= carry10 << 21; -+ carry12 = (s12 + (1 << 20)) >> 21; -+ s13 += carry12; -+ s12 -= carry12 << 21; -+ carry14 = (s14 + (1 << 20)) >> 21; -+ s15 += carry14; -+ s14 -= carry14 << 21; -+ carry16 = (s16 + (1 << 20)) >> 21; -+ s17 += carry16; -+ s16 -= carry16 << 21; -+ -+ carry7 = (s7 + (1 << 20)) >> 21; -+ s8 += carry7; -+ s7 -= carry7 << 21; -+ carry9 = (s9 + (1 << 20)) >> 21; -+ s10 += carry9; -+ s9 -= carry9 << 21; -+ carry11 = (s11 + (1 << 20)) >> 21; -+ s12 += carry11; -+ s11 -= carry11 << 21; -+ carry13 = (s13 + (1 << 20)) >> 21; -+ s14 += carry13; -+ s13 -= carry13 << 21; -+ carry15 = (s15 + (1 << 20)) >> 21; -+ s16 += carry15; -+ s15 -= carry15 << 21; -+ -+ s5 += s17 * 666643; -+ s6 += s17 * 470296; -+ s7 += s17 * 654183; -+ s8 -= s17 * 997805; -+ s9 += s17 * 136657; -+ s10 -= s17 * 683901; -+ s17 = 0; -+ -+ s4 += s16 * 666643; -+ s5 += s16 * 470296; -+ s6 += s16 * 654183; -+ s7 -= s16 * 997805; -+ s8 += s16 * 136657; -+ s9 -= s16 * 683901; -+ s16 = 0; -+ -+ s3 += s15 * 666643; -+ s4 += s15 * 470296; -+ s5 += s15 * 654183; -+ s6 -= s15 * 997805; -+ s7 += s15 * 136657; -+ s8 -= s15 * 683901; -+ s15 = 0; -+ -+ s2 += s14 * 666643; -+ s3 += s14 * 470296; -+ s4 += s14 * 654183; -+ s5 -= s14 * 997805; -+ s6 += s14 * 136657; -+ s7 -= s14 * 683901; -+ s14 = 0; -+ -+ s1 += s13 * 666643; -+ s2 += s13 * 470296; -+ s3 += s13 * 654183; -+ s4 -= s13 * 997805; -+ s5 += s13 * 136657; -+ s6 -= s13 * 683901; -+ s13 = 0; -+ -+ s0 += s12 * 666643; -+ s1 += s12 * 470296; -+ s2 += s12 * 654183; -+ s3 -= s12 * 997805; -+ s4 += s12 * 136657; -+ s5 -= s12 * 683901; -+ s12 = 0; -+ -+ carry0 = (s0 + (1 << 20)) >> 21; -+ s1 += carry0; -+ s0 -= carry0 << 21; -+ carry2 = (s2 + (1 << 20)) >> 21; -+ s3 += carry2; -+ s2 -= carry2 << 21; -+ carry4 = (s4 + (1 << 20)) >> 21; -+ s5 += carry4; -+ s4 -= carry4 << 21; -+ carry6 = (s6 + (1 << 20)) >> 21; -+ s7 += carry6; -+ s6 -= carry6 << 21; -+ carry8 = (s8 + (1 << 20)) >> 21; -+ s9 += carry8; -+ s8 -= carry8 << 21; -+ carry10 = (s10 + (1 << 20)) >> 21; -+ s11 += carry10; -+ s10 -= carry10 << 21; -+ -+ carry1 = (s1 + (1 << 20)) >> 21; -+ s2 += carry1; -+ s1 -= carry1 << 21; -+ carry3 = (s3 + (1 << 20)) >> 21; -+ s4 += carry3; -+ s3 -= carry3 << 21; -+ carry5 = (s5 + (1 << 20)) >> 21; -+ s6 += carry5; -+ s5 -= carry5 << 21; -+ carry7 = (s7 + (1 << 20)) >> 21; -+ s8 += carry7; -+ s7 -= carry7 << 21; -+ carry9 = (s9 + (1 << 20)) >> 21; -+ s10 += carry9; -+ s9 -= carry9 << 21; -+ carry11 = (s11 + (1 << 20)) >> 21; -+ s12 += carry11; -+ s11 -= carry11 << 21; -+ -+ s0 += s12 * 666643; -+ s1 += s12 * 470296; -+ s2 += s12 * 654183; -+ s3 -= s12 * 997805; -+ s4 += s12 * 136657; -+ s5 -= s12 * 683901; -+ s12 = 0; -+ -+ carry0 = s0 >> 21; -+ s1 += carry0; -+ s0 -= carry0 << 21; -+ carry1 = s1 >> 21; -+ s2 += carry1; -+ s1 -= carry1 << 21; -+ carry2 = s2 >> 21; -+ s3 += carry2; -+ s2 -= carry2 << 21; -+ carry3 = s3 >> 21; -+ s4 += carry3; -+ s3 -= carry3 << 21; -+ carry4 = s4 >> 21; -+ s5 += carry4; -+ s4 -= carry4 << 21; -+ carry5 = s5 >> 21; -+ s6 += carry5; -+ s5 -= carry5 << 21; -+ carry6 = s6 >> 21; -+ s7 += carry6; -+ s6 -= carry6 << 21; -+ carry7 = s7 >> 21; -+ s8 += carry7; -+ s7 -= carry7 << 21; -+ carry8 = s8 >> 21; -+ s9 += carry8; -+ s8 -= carry8 << 21; -+ carry9 = s9 >> 21; -+ s10 += carry9; -+ s9 -= carry9 << 21; -+ carry10 = s10 >> 21; -+ s11 += carry10; -+ s10 -= carry10 << 21; -+ carry11 = s11 >> 21; -+ s12 += carry11; -+ s11 -= carry11 << 21; -+ -+ s0 += s12 * 666643; -+ s1 += s12 * 470296; -+ s2 += s12 * 654183; -+ s3 -= s12 * 997805; -+ s4 += s12 * 136657; -+ s5 -= s12 * 683901; -+ s12 = 0; -+ -+ carry0 = s0 >> 21; -+ s1 += carry0; -+ s0 -= carry0 << 21; -+ carry1 = s1 >> 21; -+ s2 += carry1; -+ s1 -= carry1 << 21; -+ carry2 = s2 >> 21; -+ s3 += carry2; -+ s2 -= carry2 << 21; -+ carry3 = s3 >> 21; -+ s4 += carry3; -+ s3 -= carry3 << 21; -+ carry4 = s4 >> 21; -+ s5 += carry4; -+ s4 -= carry4 << 21; -+ carry5 = s5 >> 21; -+ s6 += carry5; -+ s5 -= carry5 << 21; -+ carry6 = s6 >> 21; -+ s7 += carry6; -+ s6 -= carry6 << 21; -+ carry7 = s7 >> 21; -+ s8 += carry7; -+ s7 -= carry7 << 21; -+ carry8 = s8 >> 21; -+ s9 += carry8; -+ s8 -= carry8 << 21; -+ carry9 = s9 >> 21; -+ s10 += carry9; -+ s9 -= carry9 << 21; -+ carry10 = s10 >> 21; -+ s11 += carry10; -+ s10 -= carry10 << 21; -+ -+ s[0] = s0 >> 0; -+ s[1] = s0 >> 8; -+ s[2] = (s0 >> 16) | (s1 << 5); -+ s[3] = s1 >> 3; -+ s[4] = s1 >> 11; -+ s[5] = (s1 >> 19) | (s2 << 2); -+ s[6] = s2 >> 6; -+ s[7] = (s2 >> 14) | (s3 << 7); -+ s[8] = s3 >> 1; -+ s[9] = s3 >> 9; -+ s[10] = (s3 >> 17) | (s4 << 4); -+ s[11] = s4 >> 4; -+ s[12] = s4 >> 12; -+ s[13] = (s4 >> 20) | (s5 << 1); -+ s[14] = s5 >> 7; -+ s[15] = (s5 >> 15) | (s6 << 6); -+ s[16] = s6 >> 2; -+ s[17] = s6 >> 10; -+ s[18] = (s6 >> 18) | (s7 << 3); -+ s[19] = s7 >> 5; -+ s[20] = s7 >> 13; -+ s[21] = s8 >> 0; -+ s[22] = s8 >> 8; -+ s[23] = (s8 >> 16) | (s9 << 5); -+ s[24] = s9 >> 3; -+ s[25] = s9 >> 11; -+ s[26] = (s9 >> 19) | (s10 << 2); -+ s[27] = s10 >> 6; -+ s[28] = (s10 >> 14) | (s11 << 7); -+ s[29] = s11 >> 1; -+ s[30] = s11 >> 9; -+ s[31] = s11 >> 17; -+} -+ -+/* Loosely from BoringSSL crypto/curve25519/spake25519.c */ -+ -+/* -+ * Here BoringSSL uses different points, not restricted to the generator -+ * subgroup, while we use the draft-irtf-cfrg-spake2-05 points. The Python -+ * code is modified to add the subgroup restriction. -+ */ -+ -+// The following precomputation tables are for the following -+// points: -+// -+// N (found in 7 iterations): -+// x: 10742253510813957597047979962966927467575235974254765187031601461055699024931 -+// y: 19796686047937480651099107989427797822652529149428697746066532921705571401683 -+// encoded: d3bfb518f44f3430f29d0c92af503865a1ed3281dc69b35dd868ba85f886c4ab -+// -+// M (found in 21 iterations): -+// x: 8158688967149231307266666683326742915289288280191350817196911733632187385319 -+// y: 21622333750659878624441478467798461427617029906629724657331223068277098105040 -+// encoded: d048032c6ea0b6d697ddc2e86bda85a33adac920f1bf18e1b0c6d166a5cecdaf -+// -+// These points and their precomputation tables are generated with the -+// following Python code. -+ -+/* -+import hashlib -+import ed25519 as E # http://ed25519.cr.yp.to/python/ed25519.py -+ -+SEED_N = 'edwards25519 point generation seed (N)' -+SEED_M = 'edwards25519 point generation seed (M)' -+ -+def genpoint(seed): -+ v = hashlib.sha256(seed).digest() -+ it = 1 -+ while True: -+ try: -+ x,y = E.decodepoint(v) -+ if E.scalarmult((x,y), E.l) != [0, 1]: -+ raise Exception('point has wrong order') -+ except Exception, e: -+ print e -+ it += 1 -+ v = hashlib.sha256(v).digest() -+ continue -+ print "Found in %d iterations:" % it -+ print " x = %d" % x -+ print " y = %d" % y -+ print " Encoded (hex)" -+ print E.encodepoint((x,y)).encode('hex') -+ return (x,y) -+ -+def gentable(P): -+ t = [] -+ for i in range(1,16): -+ k = (i >> 3 & 1) * (1 << 192) + \ -+ (i >> 2 & 1) * (1 << 128) + \ -+ (i >> 1 & 1) * (1 << 64) + \ -+ (i & 1) -+ t.append(E.scalarmult(P, k)) -+ return ''.join(E.encodeint(x) + E.encodeint(y) for (x,y) in t) -+ -+def printtable(table, name): -+ print "static const uint8_t %s[15 * 2 * 32] = {" % name, -+ for i in range(15 * 2 * 32): -+ if i % 12 == 0: -+ print "\n ", -+ print " 0x%02x," % ord(table[i]), -+ print "\n};" -+ -+if __name__ == "__main__": -+ print "Searching for N" -+ N = genpoint(SEED_N) -+ print "Generating precomputation table for N" -+ Ntable = gentable(N) -+ printtable(Ntable, "kSpakeNSmallPrecomp") -+ -+ print "Searching for M" -+ M = genpoint(SEED_M) -+ print "Generating precomputation table for M" -+ Mtable = gentable(M) -+ printtable(Mtable, "kSpakeMSmallPrecomp") -+*/ -+ -+static const uint8_t kSpakeNSmallPrecomp[15 * 2 * 32] = { -+ 0x23, 0xfc, 0x27, 0x6c, 0x55, 0xaf, 0xb3, 0x9c, 0xd8, 0x99, 0x3a, 0x0d, -+ 0x7f, 0x08, 0xc9, 0xeb, 0x4d, 0x6e, 0x90, 0x99, 0x2f, 0x3c, 0x15, 0x2b, -+ 0x89, 0x5a, 0x0f, 0xf2, 0x67, 0xe6, 0xbf, 0x17, 0xd3, 0xbf, 0xb5, 0x18, -+ 0xf4, 0x4f, 0x34, 0x30, 0xf2, 0x9d, 0x0c, 0x92, 0xaf, 0x50, 0x38, 0x65, -+ 0xa1, 0xed, 0x32, 0x81, 0xdc, 0x69, 0xb3, 0x5d, 0xd8, 0x68, 0xba, 0x85, -+ 0xf8, 0x86, 0xc4, 0x2b, 0x53, 0x93, 0xb1, 0x99, 0x90, 0x30, 0xca, 0xb0, -+ 0xbd, 0xea, 0x14, 0x4c, 0x6f, 0x2b, 0x81, 0x1e, 0x23, 0x45, 0xb2, 0x32, -+ 0x2e, 0x2d, 0xe6, 0xb8, 0x5d, 0xc5, 0x15, 0x91, 0x63, 0x39, 0x18, 0x5b, -+ 0x62, 0x63, 0x9b, 0xf4, 0x8b, 0xe0, 0x34, 0xa2, 0x95, 0x11, 0x92, 0x68, -+ 0x54, 0xb7, 0xf3, 0x91, 0xca, 0x22, 0xad, 0x08, 0xd8, 0x9c, 0xa2, 0xf0, -+ 0xdc, 0x9c, 0x2c, 0x84, 0x32, 0x26, 0xe0, 0x17, 0x89, 0x53, 0x6b, 0xfd, -+ 0x76, 0x97, 0x25, 0xea, 0x99, 0x94, 0xf8, 0x29, 0x7c, 0xc4, 0x53, 0xc0, -+ 0x98, 0x9a, 0x20, 0xdc, 0x70, 0x01, 0x50, 0xaa, 0x05, 0xa3, 0x40, 0x50, -+ 0x66, 0x87, 0x30, 0x19, 0x12, 0xc3, 0xb8, 0x2d, 0x28, 0x8b, 0x7b, 0x48, -+ 0xf7, 0x7b, 0xab, 0x45, 0x70, 0x2e, 0xbb, 0x85, 0xc1, 0x6c, 0xdd, 0x35, -+ 0x00, 0x83, 0x20, 0x13, 0x82, 0x08, 0xaa, 0xa3, 0x03, 0x0f, 0xca, 0x27, -+ 0x3e, 0x8b, 0x52, 0xc2, 0xd7, 0xb1, 0x8c, 0x22, 0xfe, 0x04, 0x4a, 0xf2, -+ 0xe8, 0xac, 0xee, 0x2e, 0xd7, 0x77, 0x34, 0x49, 0xf2, 0xe9, 0xeb, 0x8c, -+ 0xa6, 0xc8, 0xc6, 0xcd, 0x8a, 0x8f, 0x7c, 0x5d, 0x51, 0xc8, 0xfa, 0x6f, -+ 0xb3, 0x93, 0xdb, 0x71, 0xef, 0x3e, 0x6e, 0xa7, 0x85, 0xc7, 0xd4, 0x3e, -+ 0xa2, 0xe2, 0xc0, 0xaa, 0x17, 0xb3, 0xa4, 0x7c, 0xc2, 0x3f, 0x7c, 0x7a, -+ 0xdd, 0x26, 0xde, 0x3e, 0xf1, 0x99, 0x06, 0xf7, 0x69, 0x1b, 0xc9, 0x20, -+ 0x55, 0x4f, 0x86, 0x7a, 0x93, 0x89, 0x68, 0xe9, 0x2b, 0x2d, 0xbc, 0x08, -+ 0x15, 0x5d, 0x2d, 0x0b, 0x4f, 0x1a, 0xb3, 0xd4, 0x8e, 0x77, 0x79, 0x2a, -+ 0x25, 0xf9, 0xb6, 0x46, 0xfb, 0x87, 0x02, 0xa6, 0xe0, 0xd3, 0xba, 0x84, -+ 0xea, 0x3e, 0x58, 0xa5, 0x7f, 0x8f, 0x8c, 0x39, 0x79, 0x28, 0xb5, 0xcf, -+ 0xe4, 0xca, 0x63, 0xdc, 0xac, 0xed, 0x4b, 0x74, 0x1e, 0x94, 0x85, 0x8c, -+ 0xe5, 0xf4, 0x76, 0x6f, 0x20, 0x67, 0x8b, 0xd8, 0xd6, 0x4b, 0xe7, 0x2d, -+ 0xa0, 0xbd, 0xcc, 0x1f, 0xdf, 0x46, 0x9c, 0xa2, 0x49, 0x64, 0xdf, 0x24, -+ 0x00, 0x11, 0x11, 0x45, 0x62, 0x5c, 0xd7, 0x8a, 0x00, 0x02, 0xf5, 0x9b, -+ 0x4f, 0x53, 0x42, 0xc5, 0xd5, 0x55, 0x80, 0x73, 0x9a, 0x5b, 0x31, 0x5a, -+ 0xbd, 0x3a, 0x43, 0xe9, 0x33, 0xe5, 0xaf, 0x1d, 0x92, 0x5e, 0x59, 0x37, -+ 0xae, 0x57, 0xfa, 0x3b, 0xd2, 0x31, 0xae, 0xa6, 0xf9, 0xc9, 0xc1, 0x82, -+ 0xa6, 0xa5, 0xed, 0x24, 0x53, 0x4b, 0x38, 0x22, 0xf2, 0x85, 0x8d, 0x13, -+ 0xa6, 0x5e, 0xd6, 0x57, 0x17, 0xd3, 0x33, 0x38, 0x8d, 0x65, 0xd3, 0xcb, -+ 0x1a, 0xa2, 0x3a, 0x2b, 0xbb, 0x61, 0x53, 0xd7, 0xff, 0xcd, 0x20, 0xb6, -+ 0xbb, 0x8c, 0xab, 0x63, 0xef, 0xb8, 0x26, 0x7e, 0x81, 0x65, 0xaf, 0x90, -+ 0xfc, 0xd2, 0xb6, 0x72, 0xdb, 0xe9, 0x23, 0x78, 0x12, 0x04, 0xc0, 0x03, -+ 0x82, 0xa8, 0x7a, 0x0f, 0x48, 0x6f, 0x82, 0x7f, 0x81, 0xcd, 0xa7, 0x89, -+ 0xdd, 0x86, 0xea, 0x5e, 0xa1, 0x50, 0x14, 0x34, 0x17, 0x64, 0x82, 0x0f, -+ 0xc4, 0x40, 0x20, 0x1d, 0x8f, 0xfe, 0xfa, 0x99, 0xaf, 0x5b, 0xc1, 0x5d, -+ 0xc8, 0x47, 0x07, 0x54, 0x4a, 0x22, 0x56, 0x57, 0xf1, 0x2c, 0x3b, 0x62, -+ 0x7f, 0x12, 0x62, 0xaf, 0xfd, 0xf8, 0x04, 0x11, 0xa8, 0x51, 0xf0, 0x46, -+ 0x5d, 0x79, 0x66, 0xff, 0x8a, 0x06, 0xef, 0x54, 0x64, 0x1b, 0x84, 0x3e, -+ 0x41, 0xf3, 0xfe, 0x19, 0x51, 0xf7, 0x44, 0x9c, 0x16, 0xd3, 0x7a, 0x09, -+ 0x59, 0xf5, 0x47, 0x45, 0xd0, 0x31, 0xef, 0x96, 0x2c, 0xc5, 0xc0, 0xd0, -+ 0x56, 0xef, 0x3f, 0x07, 0x2b, 0xb7, 0x28, 0x49, 0xf5, 0xb1, 0x42, 0x18, -+ 0xcf, 0x77, 0xd8, 0x2b, 0x71, 0x74, 0x80, 0xba, 0x34, 0x52, 0xce, 0x11, -+ 0xfe, 0xc4, 0xb9, 0xeb, 0xf9, 0xc4, 0x5e, 0x1f, 0xd3, 0xde, 0x4b, 0x14, -+ 0xe3, 0x6e, 0xe7, 0xd7, 0x83, 0x59, 0x98, 0xe8, 0x3d, 0x8e, 0xd6, 0x7d, -+ 0xc0, 0x9a, 0x79, 0xb9, 0x83, 0xf1, 0xc1, 0x00, 0x5d, 0x16, 0x1b, 0x44, -+ 0xe9, 0x02, 0xce, 0x99, 0x1e, 0x77, 0xef, 0xca, 0xbc, 0xf0, 0x6a, 0xb9, -+ 0x65, 0x3f, 0x3c, 0xd9, 0xe1, 0x63, 0x0b, 0xbf, 0xaa, 0xa7, 0xe6, 0x6d, -+ 0x6d, 0x3f, 0x44, 0x29, 0xa3, 0x8b, 0x6d, 0xc4, 0x81, 0xa9, 0xc3, 0x5a, -+ 0x90, 0x55, 0x72, 0x61, 0x17, 0x22, 0x7f, 0x3e, 0x5f, 0xfc, 0xba, 0xb3, -+ 0x7a, 0x99, 0x76, 0xe9, 0x20, 0xe5, 0xc5, 0xe8, 0x55, 0x56, 0x0f, 0x7a, -+ 0x48, 0xe7, 0xbc, 0xe1, 0x13, 0xf4, 0x90, 0xef, 0x97, 0x6c, 0x02, 0x89, -+ 0x4d, 0x22, 0x48, 0xda, 0xd3, 0x52, 0x45, 0x31, 0x26, 0xcc, 0xe8, 0x9e, -+ 0x5d, 0xdd, 0x75, 0xe4, 0x1d, 0xbc, 0xb1, 0x08, 0x55, 0xaf, 0x54, 0x70, -+ 0x0d, 0x0c, 0xf3, 0x50, 0xbc, 0x40, 0x83, 0xee, 0xdc, 0x6d, 0x8b, 0x40, -+ 0x79, 0x62, 0x18, 0x37, 0xc4, 0x78, 0x02, 0x58, 0x7c, 0x78, 0xd3, 0x54, -+ 0xed, 0x31, 0xbd, 0x7d, 0x48, 0xcf, 0xb6, 0x11, 0x27, 0x37, 0x9c, 0x86, -+ 0xf7, 0x2e, 0x00, 0x7a, 0x48, 0x1b, 0xa6, 0x72, 0x70, 0x7b, 0x44, 0x45, -+ 0xeb, 0x49, 0xbf, 0xbe, 0x09, 0x78, 0x66, 0x71, 0x12, 0x7f, 0x3d, 0x78, -+ 0x51, 0x24, 0x82, 0xa2, 0xf0, 0x1e, 0x83, 0x81, 0x81, 0x45, 0x53, 0xfd, -+ 0x5e, 0xf3, 0x03, 0x74, 0xbd, 0x23, 0x35, 0xf6, 0x10, 0xdd, 0x7c, 0x73, -+ 0x46, 0x32, 0x09, 0x54, 0x99, 0x95, 0x91, 0x25, 0xb8, 0x32, 0x09, 0xd8, -+ 0x2f, 0x97, 0x50, 0xa3, 0xf5, 0xd6, 0xb1, 0xed, 0x97, 0x51, 0x06, 0x42, -+ 0x12, 0x0c, 0x69, 0x38, 0x09, 0xa0, 0xd8, 0x19, 0x70, 0xf7, 0x8f, 0x61, -+ 0x0d, 0x56, 0x43, 0x66, 0x22, 0x8b, 0x0e, 0x0e, 0xf9, 0x81, 0x9f, 0xac, -+ 0x6f, 0xbf, 0x7d, 0x04, 0x13, 0xf2, 0xe4, 0xeb, 0xfd, 0xbe, 0x4e, 0x56, -+ 0xda, 0xe0, 0x22, 0x6d, 0x1b, 0x25, 0xc8, 0xa5, 0x9c, 0x05, 0x45, 0x52, -+ 0x3c, 0x3a, 0xde, 0x6b, 0xac, 0x9b, 0xf8, 0x81, 0x97, 0x21, 0x46, 0xac, -+ 0x7e, 0x89, 0xf8, 0x49, 0x58, 0xbb, 0x45, 0xac, 0xa2, 0xc4, 0x90, 0x1f, -+ 0xb2, 0xb4, 0xf8, 0xe0, 0xcd, 0xa1, 0x9d, 0x1c, 0xf2, 0xf1, 0xdf, 0xfb, -+ 0x88, 0x4e, 0xe5, 0x41, 0xd8, 0x6e, 0xac, 0x07, 0x87, 0x95, 0x35, 0xa6, -+ 0x12, 0x08, 0x5d, 0x57, 0x5e, 0xaf, 0x71, 0x0f, 0x07, 0x4e, 0x81, 0x77, -+ 0xf1, 0xef, 0xb5, 0x35, 0x5c, 0xfa, 0xf4, 0x4e, 0x42, 0xdc, 0x19, 0xfe, -+ 0xe4, 0xd2, 0xb4, 0x27, 0xfb, 0x34, 0x1f, 0xb2, 0x6f, 0xf2, 0x95, 0xcc, -+ 0xd4, 0x47, 0x63, 0xdc, 0x7e, 0x4f, 0x97, 0x2b, 0x7a, 0xe0, 0x80, 0x31, -+}; -+ -+static const uint8_t kSpakeMSmallPrecomp[15 * 2 * 32] = { -+ 0xe7, 0x45, 0x7e, 0x47, 0x49, 0x69, 0xbd, 0x1b, 0x35, 0x1c, 0x2c, 0x98, -+ 0x03, 0xf3, 0xb3, 0x37, 0xde, 0x39, 0xa5, 0xda, 0xc0, 0x2e, 0xa4, 0xac, -+ 0x7d, 0x08, 0x26, 0xfc, 0x80, 0xa7, 0x09, 0x12, 0xd0, 0x48, 0x03, 0x2c, -+ 0x6e, 0xa0, 0xb6, 0xd6, 0x97, 0xdd, 0xc2, 0xe8, 0x6b, 0xda, 0x85, 0xa3, -+ 0x3a, 0xda, 0xc9, 0x20, 0xf1, 0xbf, 0x18, 0xe1, 0xb0, 0xc6, 0xd1, 0x66, -+ 0xa5, 0xce, 0xcd, 0x2f, 0x80, 0xa8, 0x4e, 0xc3, 0x81, 0xae, 0x68, 0x3b, -+ 0x0d, 0xdb, 0x56, 0x32, 0x2f, 0xa8, 0x97, 0xa0, 0x5c, 0x15, 0xc1, 0xcb, -+ 0x6f, 0x7a, 0x5f, 0xc5, 0x32, 0xfb, 0x49, 0x17, 0x18, 0xfa, 0x85, 0x08, -+ 0x85, 0xf1, 0xe3, 0x11, 0x8e, 0x3d, 0x70, 0x20, 0x38, 0x4e, 0x0c, 0x17, -+ 0xa1, 0xa8, 0x20, 0xd2, 0xb1, 0x1d, 0x05, 0x8d, 0x0f, 0xc9, 0x96, 0x18, -+ 0x9d, 0x8c, 0x89, 0x8f, 0x46, 0x6a, 0x6c, 0x6e, 0x72, 0x03, 0xb2, 0x75, -+ 0x87, 0xd8, 0xa9, 0x60, 0x93, 0x2b, 0x8b, 0x66, 0xee, 0xaf, 0xce, 0x98, -+ 0xcd, 0x6b, 0x7c, 0x6a, 0xbe, 0x19, 0xda, 0x66, 0x7c, 0xda, 0x53, 0xa0, -+ 0xe3, 0x9a, 0x0e, 0x53, 0x3a, 0x7c, 0x73, 0x4a, 0x37, 0xa6, 0x53, 0x23, -+ 0x67, 0x31, 0xce, 0x8a, 0xab, 0xee, 0x72, 0x76, 0xc2, 0xb5, 0x54, 0x42, -+ 0xcf, 0x4b, 0xc7, 0x53, 0x24, 0x59, 0xaf, 0x76, 0x53, 0x10, 0x7e, 0x25, -+ 0x94, 0x5c, 0x23, 0xa6, 0x5e, 0x05, 0xea, 0x14, 0xad, 0x2b, 0xce, 0x50, -+ 0x77, 0xb3, 0x7a, 0x88, 0x4c, 0xf7, 0x74, 0x04, 0x35, 0xa4, 0x0c, 0x9e, -+ 0xee, 0x6a, 0x4c, 0x3c, 0xc1, 0x6a, 0x35, 0x4d, 0x6d, 0x8f, 0x94, 0x95, -+ 0xe4, 0x10, 0xca, 0x46, 0x4e, 0xfa, 0x38, 0x40, 0xeb, 0x1a, 0x1b, 0x5a, -+ 0xff, 0x73, 0x4d, 0xe9, 0xf2, 0xbe, 0x89, 0xf5, 0xd1, 0x72, 0xd0, 0x1a, -+ 0x7b, 0x82, 0x08, 0x19, 0xda, 0x54, 0x44, 0xa5, 0x3d, 0xd8, 0x10, 0x1c, -+ 0xcf, 0x3b, 0xc7, 0x54, 0xd5, 0x11, 0xd7, 0x2a, 0x69, 0x3f, 0xa6, 0x58, -+ 0x74, 0xfd, 0x90, 0xb2, 0xf4, 0xc2, 0x0e, 0xf3, 0x19, 0x8f, 0x51, 0x7c, -+ 0x31, 0x12, 0x79, 0x61, 0x16, 0xb4, 0x2f, 0x2f, 0xd0, 0x88, 0x97, 0xf2, -+ 0xc3, 0x8c, 0xa6, 0xa3, 0x29, 0xff, 0x7e, 0x12, 0x46, 0x2a, 0x9c, 0x09, -+ 0x7c, 0x5f, 0x87, 0x07, 0x6b, 0xa1, 0x9a, 0x57, 0x55, 0x8e, 0xb0, 0x56, -+ 0x5d, 0xc9, 0x4c, 0x5b, 0xae, 0xd3, 0xd0, 0x8e, 0xb8, 0xac, 0xba, 0xe8, -+ 0x54, 0x45, 0x30, 0x14, 0xf6, 0x59, 0x20, 0xc4, 0x03, 0xb7, 0x7a, 0x5d, -+ 0x6b, 0x5a, 0xcb, 0x28, 0x60, 0xf8, 0xef, 0x61, 0x60, 0x78, 0x6b, 0xf5, -+ 0x21, 0x4b, 0x75, 0xc2, 0x77, 0xba, 0x0e, 0x38, 0x98, 0xe0, 0xfb, 0xb7, -+ 0x5f, 0x75, 0x87, 0x04, 0x0c, 0xb4, 0x5c, 0x09, 0x04, 0x00, 0x38, 0x4e, -+ 0x4f, 0x7b, 0x73, 0xe5, 0xdb, 0xdb, 0xf1, 0xf4, 0x5c, 0x64, 0x68, 0xfd, -+ 0xb1, 0x86, 0xe8, 0x89, 0xbe, 0x9c, 0xd4, 0x96, 0x1d, 0xcb, 0xdc, 0x5c, -+ 0xef, 0xd4, 0x33, 0x28, 0xb9, 0xb6, 0xaf, 0x3b, 0xcf, 0x8d, 0x30, 0xba, -+ 0xe8, 0x08, 0xcf, 0x84, 0xba, 0x61, 0x10, 0x9b, 0x62, 0xf6, 0x18, 0x79, -+ 0x66, 0x87, 0x82, 0x7c, 0xaa, 0x71, 0xac, 0xd0, 0xd0, 0x32, 0xb0, 0x54, -+ 0x03, 0xa4, 0xad, 0x3f, 0x72, 0xca, 0x22, 0xff, 0x01, 0x87, 0x08, 0x36, -+ 0x61, 0x22, 0xaa, 0x18, 0xab, 0x3a, 0xbc, 0xf2, 0x78, 0x05, 0xe1, 0x99, -+ 0xa3, 0x59, 0x98, 0xcc, 0x21, 0xc6, 0x2b, 0x51, 0x6d, 0x43, 0x0a, 0x46, -+ 0x50, 0xae, 0x11, 0x7e, 0xd5, 0x23, 0x56, 0xef, 0x83, 0xc8, 0xbf, 0x42, -+ 0xf0, 0x45, 0x52, 0x1f, 0x34, 0xbc, 0x2f, 0xb0, 0xf0, 0xce, 0xf0, 0xec, -+ 0xd0, 0x99, 0x59, 0x2e, 0x1f, 0xab, 0xa8, 0x1e, 0x4b, 0xce, 0x1b, 0x9a, -+ 0x75, 0xc6, 0xc4, 0x71, 0x86, 0xf0, 0x8d, 0xec, 0xb0, 0x30, 0xb9, 0x62, -+ 0xb3, 0xb7, 0xdd, 0x96, 0x29, 0xc8, 0xbf, 0xe9, 0xb0, 0x74, 0x78, 0x7b, -+ 0xf7, 0xea, 0xa3, 0x14, 0x12, 0x56, 0xe0, 0xf3, 0x35, 0x7a, 0x26, 0x4a, -+ 0x4c, 0xe6, 0xdf, 0x13, 0xb5, 0x52, 0xb0, 0x2a, 0x5f, 0x2e, 0xac, 0x34, -+ 0xab, 0x5f, 0x1a, 0x01, 0xe4, 0x15, 0x1a, 0xd1, 0xbf, 0xc9, 0x95, 0x0a, -+ 0xac, 0x1d, 0xe7, 0x53, 0x59, 0x8d, 0xc3, 0x21, 0x78, 0x5e, 0x12, 0x97, -+ 0x8f, 0x4e, 0x1d, 0xf9, 0xe5, 0xe2, 0xc2, 0xc4, 0xba, 0xfb, 0x50, 0x96, -+ 0x5b, 0x43, 0xe8, 0xf7, 0x0d, 0x1b, 0x64, 0x58, 0xbe, 0xd3, 0x95, 0x7f, -+ 0x8e, 0xf1, 0x85, 0x35, 0xba, 0x25, 0x55, 0x2e, 0x02, 0x46, 0x5c, 0xad, -+ 0x1f, 0xc5, 0x03, 0xcc, 0xd0, 0x43, 0x4c, 0xf2, 0x5e, 0x64, 0x0a, 0x89, -+ 0xd9, 0xfd, 0x23, 0x7d, 0x4f, 0xbe, 0x2f, 0x0f, 0x1e, 0x12, 0x4a, 0xd9, -+ 0xf8, 0x82, 0xde, 0x8f, 0x4f, 0x98, 0xb9, 0x90, 0xf6, 0xfa, 0xd1, 0x11, -+ 0xa6, 0xdc, 0x7e, 0x32, 0x48, 0x6a, 0x8a, 0x14, 0x5e, 0x73, 0xb9, 0x6c, -+ 0x0e, 0xc2, 0xf9, 0xcc, 0xf0, 0x32, 0xc8, 0xb5, 0x56, 0xaa, 0x5d, 0xd2, -+ 0x07, 0xf1, 0x6f, 0x33, 0x6f, 0x05, 0x70, 0x49, 0x60, 0x49, 0x23, 0x23, -+ 0x14, 0x0e, 0x4c, 0x58, 0x92, 0xad, 0xa9, 0x50, 0xb1, 0x59, 0x43, 0x96, -+ 0x7b, 0xc1, 0x51, 0x45, 0xef, 0x0d, 0xef, 0xd1, 0xe4, 0xd0, 0xce, 0xdf, -+ 0x6a, 0xbc, 0x1b, 0xbf, 0x7a, 0x87, 0x4e, 0x47, 0x17, 0x9c, 0x34, 0x38, -+ 0xb0, 0x3c, 0xa1, 0x04, 0xfb, 0xe2, 0x66, 0xce, 0xb6, 0x82, 0xbb, 0xad, -+ 0xc3, 0x8e, 0x12, 0x35, 0xbc, 0x17, 0xce, 0x01, 0x2d, 0xa3, 0xa6, 0xb9, -+ 0xfa, 0x84, 0xc2, 0x2f, 0x5a, 0x4a, 0x8c, 0x4c, 0x11, 0x4e, 0xa8, 0x14, -+ 0xcb, 0xb8, 0x99, 0xaa, 0x2e, 0x8c, 0xa0, 0xc9, 0x5f, 0x62, 0x2a, 0x84, -+ 0x66, 0x60, 0x0a, 0x7e, 0xdc, 0x93, 0x17, 0x45, 0x19, 0xb3, 0x93, 0x4c, -+ 0xdc, 0xd0, 0xd5, 0x5c, 0x25, 0xd2, 0xcd, 0x4e, 0x84, 0x4c, 0x73, 0xb3, -+ 0x90, 0xa4, 0x22, 0x05, 0x2c, 0x7c, 0x39, 0x2b, 0x70, 0xd9, 0x61, 0x76, -+ 0xb2, 0x03, 0x71, 0xe9, 0x0e, 0xf8, 0x57, 0x85, 0xad, 0xb1, 0x2f, 0x34, -+ 0xa5, 0x66, 0xb0, 0x0f, 0x75, 0x94, 0x6e, 0x26, 0x79, 0x99, 0xb4, 0xe2, -+ 0xe2, 0xa3, 0x58, 0xdd, 0xb4, 0xfb, 0x74, 0xf4, 0xa1, 0xca, 0xc3, 0x30, -+ 0xe7, 0x86, 0xb2, 0xa2, 0x2c, 0x11, 0xc9, 0x58, 0xe3, 0xc1, 0xa6, 0x5f, -+ 0x86, 0x6a, 0xe7, 0x75, 0xd5, 0xd8, 0x63, 0x95, 0x64, 0x59, 0xbc, 0xb8, -+ 0xb7, 0xf5, 0x12, 0xe3, 0x03, 0xc6, 0x17, 0xea, 0x4e, 0xcb, 0xee, 0x4c, -+ 0xae, 0x03, 0xd1, 0x33, 0xd0, 0x39, 0x36, 0x00, 0x0f, 0xf4, 0x9c, 0xbd, -+ 0x35, 0x96, 0xfd, 0x0d, 0x26, 0xb7, 0x9e, 0xf4, 0x4b, 0x6f, 0x4b, 0xf1, -+ 0xec, 0x11, 0x00, 0x16, 0x21, 0x1e, 0xd4, 0x43, 0x23, 0x8c, 0x4a, 0xfa, -+ 0x9e, 0xd4, 0x2b, 0x36, 0x9a, 0x43, 0x1e, 0x58, 0x31, 0xe8, 0x1f, 0x83, -+ 0x15, 0x20, 0x31, 0x68, 0xfe, 0x27, 0xd3, 0xd8, 0x9b, 0x43, 0x81, 0x8f, -+ 0x57, 0x32, 0x14, 0xe6, 0x9e, 0xbf, 0xd1, 0xfb, 0xdf, 0xad, 0x7a, 0x52, -+}; -+ -+/* left_shift_3 sets |n| to |n|*8, where |n| is represented in little-endian -+ * order. */ -+static void left_shift_3(uint8_t n[32]) { -+ uint8_t carry = 0; -+ unsigned i; -+ -+ for (i = 0; i < 32; i++) { -+ const uint8_t next_carry = n[i] >> 5; -+ n[i] = (n[i] << 3) | carry; -+ carry = next_carry; -+ } -+} -+ -+static krb5_error_code -+builtin_edwards25519_keygen(krb5_context context, groupdata *gdata, -+ const uint8_t *wbytes, krb5_boolean use_m, -+ uint8_t *priv_out, uint8_t *pub_out) -+{ -+ uint8_t private[64]; -+ krb5_data data = make_data(private, 32); -+ krb5_error_code ret; -+ -+ /* Pick x or y uniformly from [0, p*h) divisible by h. */ -+ ret = krb5_c_random_make_octets(context, &data); -+ if (ret) -+ return ret; -+ memset(private + 32, 0, 32); -+ x25519_sc_reduce(private); -+ left_shift_3(private); -+ -+ /* Compute X=x*G or Y=y*G. */ -+ ge_p3 P; -+ x25519_ge_scalarmult_base(&P, private); -+ -+ /* Compute w mod p. */ -+ uint8_t wreduced[64]; -+ memcpy(wreduced, wbytes, 32); -+ memset(wreduced + 32, 0, 32); -+ x25519_sc_reduce(wreduced); -+ -+ /* Compute the mask, w*M or w*N. */ -+ ge_p3 mask; -+ x25519_ge_scalarmult_small_precomp(&mask, wreduced, -+ use_m ? kSpakeMSmallPrecomp : -+ kSpakeNSmallPrecomp); -+ -+ /* Compute the masked point T=w*M+X or S=w*N+Y. */ -+ ge_cached mask_cached; -+ x25519_ge_p3_to_cached(&mask_cached, &mask); -+ ge_p1p1 Pmasked; -+ x25519_ge_add(&Pmasked, &P, &mask_cached); -+ -+ /* Encode T or S into pub_out. */ -+ ge_p2 Pmasked_proj; -+ x25519_ge_p1p1_to_p2(&Pmasked_proj, &Pmasked); -+ x25519_ge_tobytes(pub_out, &Pmasked_proj); -+ -+ /* Remember the private key in priv_out. */ -+ memcpy(priv_out, private, 32); -+ return 0; -+} -+ -+static krb5_error_code -+builtin_edwards25519_result(krb5_context context, groupdata *gdata, -+ const uint8_t *wbytes, const uint8_t *ourpriv, -+ const uint8_t *theirpub, krb5_boolean use_m, -+ uint8_t *elem_out) -+{ -+ /* -+ * Check if the point received from peer is on the curve. This does not -+ * verify that it is in the generator subgroup, but since our private key is -+ * a multiple of the cofactor, the shared point will be in the generator -+ * subgroup even if a rogue peer sends a point which is not. -+ */ -+ ge_p3 Qmasked; -+ if (x25519_ge_frombytes_vartime(&Qmasked, theirpub) != 0) -+ return EINVAL; -+ -+ /* Compute w mod p. */ -+ uint8_t wreduced[64]; -+ memcpy(wreduced, wbytes, 32); -+ memset(wreduced + 32, 0, 32); -+ x25519_sc_reduce(wreduced); -+ -+ /* Compute the peer's mask, w*M or w*N. */ -+ ge_p3 peers_mask; -+ x25519_ge_scalarmult_small_precomp(&peers_mask, wreduced, -+ use_m ? kSpakeMSmallPrecomp : -+ kSpakeNSmallPrecomp); -+ -+ ge_cached peers_mask_cached; -+ x25519_ge_p3_to_cached(&peers_mask_cached, &peers_mask); -+ -+ /* Compute the peer's unmasked point, T-w*M or S-w*N. */ -+ ge_p1p1 Qcompl; -+ ge_p3 Qunmasked; -+ x25519_ge_sub(&Qcompl, &Qmasked, &peers_mask_cached); -+ x25519_ge_p1p1_to_p3(&Qunmasked, &Qcompl); -+ -+ /* Multiply by our private value to compute K=x*(S-w*N) or K=y*(T-w*M). */ -+ ge_p2 K; -+ x25519_ge_scalarmult(&K, ourpriv, &Qunmasked); -+ -+ /* Encode K into elem_out. */ -+ x25519_ge_tobytes(elem_out, &K); -+ return 0; -+} -+ -+static krb5_error_code -+builtin_sha256(krb5_context context, groupdata *gdata, const krb5_data *dlist, -+ size_t ndata, uint8_t *result_out) -+{ -+ return k5_sha256(dlist, ndata, result_out); -+} -+ -+groupdef builtin_edwards25519 = { -+ .reg = &spake_iana_edwards25519, -+ .keygen = builtin_edwards25519_keygen, -+ .result = builtin_edwards25519_result, -+ .hash = builtin_sha256 -+}; -diff --git a/src/plugins/preauth/spake/edwards25519_tables.h b/src/plugins/preauth/spake/edwards25519_tables.h -new file mode 100644 -index 000000000..c6c501373 ---- /dev/null -+++ b/src/plugins/preauth/spake/edwards25519_tables.h -@@ -0,0 +1,7881 @@ -+/* -*- mode: c; c-basic-offset: 2; indent-tabs-mode: nil -*- */ -+/* -+ * The MIT License (MIT) -+ * -+ * Copyright (c) 2015-2016 the fiat-crypto authors (see the AUTHORS file). -+ * -+ * Permission is hereby granted, free of charge, to any person obtaining a copy -+ * of this software and associated documentation files (the "Software"), to deal -+ * in the Software without restriction, including without limitation the rights -+ * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell -+ * copies of the Software, and to permit persons to whom the Software is -+ * furnished to do so, subject to the following conditions: -+ * -+ * The above copyright notice and this permission notice shall be included in -+ * all copies or substantial portions of the Software. -+ * -+ * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR -+ * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, -+ * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE -+ * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER -+ * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, -+ * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE -+ * SOFTWARE. -+ */ -+ -+/* From BoringSSL third-party/fiat/curve25519_tables.h */ -+ -+static const fe d = {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 929955233495203, 466365720129213, 1662059464998953, 2033849074728123, -+ 1442794654840575 -+#else -+ 56195235, 13857412, 51736253, 6949390, 114729, 24766616, 60832955, 30306712, -+ 48412415, 21499315 -+#endif -+}}; -+ -+static const fe sqrtm1 = {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1718705420411056, 234908883556509, 2233514472574048, 2117202627021982, -+ 765476049583133 -+#else -+ 34513072, 25610706, 9377949, 3500415, 12389472, 33281959, 41962654, -+ 31548777, 326685, 11406482 -+#endif -+}}; -+ -+static const fe d2 = {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1859910466990425, 932731440258426, 1072319116312658, 1815898335770999, -+ 633789495995903 -+#else -+ 45281625, 27714825, 36363642, 13898781, 229458, 15978800, 54557047, -+ 27058993, 29715967, 9444199 -+#endif -+}}; -+ -+#if defined(CONFIG_SMALL) -+ -+// This block of code replaces the standard base-point table with a much smaller -+// one. The standard table is 30,720 bytes while this one is just 960. -+// -+// This table contains 15 pairs of group elements, (x, y), where each field -+// element is serialised with |fe_tobytes|. If |i| is the index of the group -+// element then consider i+1 as a four-bit number: (i₀, i₁, i₂, i₃) (where i₀ -+// is the most significant bit). The value of the group element is then: -+// (i₀×2^192 + i₁×2^128 + i₂×2^64 + i₃)G, where G is the generator. -+static const uint8_t k25519SmallPrecomp[15 * 2 * 32] = { -+ 0x1a, 0xd5, 0x25, 0x8f, 0x60, 0x2d, 0x56, 0xc9, 0xb2, 0xa7, 0x25, 0x95, -+ 0x60, 0xc7, 0x2c, 0x69, 0x5c, 0xdc, 0xd6, 0xfd, 0x31, 0xe2, 0xa4, 0xc0, -+ 0xfe, 0x53, 0x6e, 0xcd, 0xd3, 0x36, 0x69, 0x21, 0x58, 0x66, 0x66, 0x66, -+ 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, -+ 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, -+ 0x66, 0x66, 0x66, 0x66, 0x02, 0xa2, 0xed, 0xf4, 0x8f, 0x6b, 0x0b, 0x3e, -+ 0xeb, 0x35, 0x1a, 0xd5, 0x7e, 0xdb, 0x78, 0x00, 0x96, 0x8a, 0xa0, 0xb4, -+ 0xcf, 0x60, 0x4b, 0xd4, 0xd5, 0xf9, 0x2d, 0xbf, 0x88, 0xbd, 0x22, 0x62, -+ 0x13, 0x53, 0xe4, 0x82, 0x57, 0xfa, 0x1e, 0x8f, 0x06, 0x2b, 0x90, 0xba, -+ 0x08, 0xb6, 0x10, 0x54, 0x4f, 0x7c, 0x1b, 0x26, 0xed, 0xda, 0x6b, 0xdd, -+ 0x25, 0xd0, 0x4e, 0xea, 0x42, 0xbb, 0x25, 0x03, 0xa2, 0xfb, 0xcc, 0x61, -+ 0x67, 0x06, 0x70, 0x1a, 0xc4, 0x78, 0x3a, 0xff, 0x32, 0x62, 0xdd, 0x2c, -+ 0xab, 0x50, 0x19, 0x3b, 0xf2, 0x9b, 0x7d, 0xb8, 0xfd, 0x4f, 0x29, 0x9c, -+ 0xa7, 0x91, 0xba, 0x0e, 0x46, 0x5e, 0x51, 0xfe, 0x1d, 0xbf, 0xe5, 0xe5, -+ 0x9b, 0x95, 0x0d, 0x67, 0xf8, 0xd1, 0xb5, 0x5a, 0xa1, 0x93, 0x2c, 0xc3, -+ 0xde, 0x0e, 0x97, 0x85, 0x2d, 0x7f, 0xea, 0xab, 0x3e, 0x47, 0x30, 0x18, -+ 0x24, 0xe8, 0xb7, 0x60, 0xae, 0x47, 0x80, 0xfc, 0xe5, 0x23, 0xe7, 0xc2, -+ 0xc9, 0x85, 0xe6, 0x98, 0xa0, 0x29, 0x4e, 0xe1, 0x84, 0x39, 0x2d, 0x95, -+ 0x2c, 0xf3, 0x45, 0x3c, 0xff, 0xaf, 0x27, 0x4c, 0x6b, 0xa6, 0xf5, 0x4b, -+ 0x11, 0xbd, 0xba, 0x5b, 0x9e, 0xc4, 0xa4, 0x51, 0x1e, 0xbe, 0xd0, 0x90, -+ 0x3a, 0x9c, 0xc2, 0x26, 0xb6, 0x1e, 0xf1, 0x95, 0x7d, 0xc8, 0x6d, 0x52, -+ 0xe6, 0x99, 0x2c, 0x5f, 0x9a, 0x96, 0x0c, 0x68, 0x29, 0xfd, 0xe2, 0xfb, -+ 0xe6, 0xbc, 0xec, 0x31, 0x08, 0xec, 0xe6, 0xb0, 0x53, 0x60, 0xc3, 0x8c, -+ 0xbe, 0xc1, 0xb3, 0x8a, 0x8f, 0xe4, 0x88, 0x2b, 0x55, 0xe5, 0x64, 0x6e, -+ 0x9b, 0xd0, 0xaf, 0x7b, 0x64, 0x2a, 0x35, 0x25, 0x10, 0x52, 0xc5, 0x9e, -+ 0x58, 0x11, 0x39, 0x36, 0x45, 0x51, 0xb8, 0x39, 0x93, 0xfc, 0x9d, 0x6a, -+ 0xbe, 0x58, 0xcb, 0xa4, 0x0f, 0x51, 0x3c, 0x38, 0x05, 0xca, 0xab, 0x43, -+ 0x63, 0x0e, 0xf3, 0x8b, 0x41, 0xa6, 0xf8, 0x9b, 0x53, 0x70, 0x80, 0x53, -+ 0x86, 0x5e, 0x8f, 0xe3, 0xc3, 0x0d, 0x18, 0xc8, 0x4b, 0x34, 0x1f, 0xd8, -+ 0x1d, 0xbc, 0xf2, 0x6d, 0x34, 0x3a, 0xbe, 0xdf, 0xd9, 0xf6, 0xf3, 0x89, -+ 0xa1, 0xe1, 0x94, 0x9f, 0x5d, 0x4c, 0x5d, 0xe9, 0xa1, 0x49, 0x92, 0xef, -+ 0x0e, 0x53, 0x81, 0x89, 0x58, 0x87, 0xa6, 0x37, 0xf1, 0xdd, 0x62, 0x60, -+ 0x63, 0x5a, 0x9d, 0x1b, 0x8c, 0xc6, 0x7d, 0x52, 0xea, 0x70, 0x09, 0x6a, -+ 0xe1, 0x32, 0xf3, 0x73, 0x21, 0x1f, 0x07, 0x7b, 0x7c, 0x9b, 0x49, 0xd8, -+ 0xc0, 0xf3, 0x25, 0x72, 0x6f, 0x9d, 0xed, 0x31, 0x67, 0x36, 0x36, 0x54, -+ 0x40, 0x92, 0x71, 0xe6, 0x11, 0x28, 0x11, 0xad, 0x93, 0x32, 0x85, 0x7b, -+ 0x3e, 0xb7, 0x3b, 0x49, 0x13, 0x1c, 0x07, 0xb0, 0x2e, 0x93, 0xaa, 0xfd, -+ 0xfd, 0x28, 0x47, 0x3d, 0x8d, 0xd2, 0xda, 0xc7, 0x44, 0xd6, 0x7a, 0xdb, -+ 0x26, 0x7d, 0x1d, 0xb8, 0xe1, 0xde, 0x9d, 0x7a, 0x7d, 0x17, 0x7e, 0x1c, -+ 0x37, 0x04, 0x8d, 0x2d, 0x7c, 0x5e, 0x18, 0x38, 0x1e, 0xaf, 0xc7, 0x1b, -+ 0x33, 0x48, 0x31, 0x00, 0x59, 0xf6, 0xf2, 0xca, 0x0f, 0x27, 0x1b, 0x63, -+ 0x12, 0x7e, 0x02, 0x1d, 0x49, 0xc0, 0x5d, 0x79, 0x87, 0xef, 0x5e, 0x7a, -+ 0x2f, 0x1f, 0x66, 0x55, 0xd8, 0x09, 0xd9, 0x61, 0x38, 0x68, 0xb0, 0x07, -+ 0xa3, 0xfc, 0xcc, 0x85, 0x10, 0x7f, 0x4c, 0x65, 0x65, 0xb3, 0xfa, 0xfa, -+ 0xa5, 0x53, 0x6f, 0xdb, 0x74, 0x4c, 0x56, 0x46, 0x03, 0xe2, 0xd5, 0x7a, -+ 0x29, 0x1c, 0xc6, 0x02, 0xbc, 0x59, 0xf2, 0x04, 0x75, 0x63, 0xc0, 0x84, -+ 0x2f, 0x60, 0x1c, 0x67, 0x76, 0xfd, 0x63, 0x86, 0xf3, 0xfa, 0xbf, 0xdc, -+ 0xd2, 0x2d, 0x90, 0x91, 0xbd, 0x33, 0xa9, 0xe5, 0x66, 0x0c, 0xda, 0x42, -+ 0x27, 0xca, 0xf4, 0x66, 0xc2, 0xec, 0x92, 0x14, 0x57, 0x06, 0x63, 0xd0, -+ 0x4d, 0x15, 0x06, 0xeb, 0x69, 0x58, 0x4f, 0x77, 0xc5, 0x8b, 0xc7, 0xf0, -+ 0x8e, 0xed, 0x64, 0xa0, 0xb3, 0x3c, 0x66, 0x71, 0xc6, 0x2d, 0xda, 0x0a, -+ 0x0d, 0xfe, 0x70, 0x27, 0x64, 0xf8, 0x27, 0xfa, 0xf6, 0x5f, 0x30, 0xa5, -+ 0x0d, 0x6c, 0xda, 0xf2, 0x62, 0x5e, 0x78, 0x47, 0xd3, 0x66, 0x00, 0x1c, -+ 0xfd, 0x56, 0x1f, 0x5d, 0x3f, 0x6f, 0xf4, 0x4c, 0xd8, 0xfd, 0x0e, 0x27, -+ 0xc9, 0x5c, 0x2b, 0xbc, 0xc0, 0xa4, 0xe7, 0x23, 0x29, 0x02, 0x9f, 0x31, -+ 0xd6, 0xe9, 0xd7, 0x96, 0xf4, 0xe0, 0x5e, 0x0b, 0x0e, 0x13, 0xee, 0x3c, -+ 0x09, 0xed, 0xf2, 0x3d, 0x76, 0x91, 0xc3, 0xa4, 0x97, 0xae, 0xd4, 0x87, -+ 0xd0, 0x5d, 0xf6, 0x18, 0x47, 0x1f, 0x1d, 0x67, 0xf2, 0xcf, 0x63, 0xa0, -+ 0x91, 0x27, 0xf8, 0x93, 0x45, 0x75, 0x23, 0x3f, 0xd1, 0xf1, 0xad, 0x23, -+ 0xdd, 0x64, 0x93, 0x96, 0x41, 0x70, 0x7f, 0xf7, 0xf5, 0xa9, 0x89, 0xa2, -+ 0x34, 0xb0, 0x8d, 0x1b, 0xae, 0x19, 0x15, 0x49, 0x58, 0x23, 0x6d, 0x87, -+ 0x15, 0x4f, 0x81, 0x76, 0xfb, 0x23, 0xb5, 0xea, 0xcf, 0xac, 0x54, 0x8d, -+ 0x4e, 0x42, 0x2f, 0xeb, 0x0f, 0x63, 0xdb, 0x68, 0x37, 0xa8, 0xcf, 0x8b, -+ 0xab, 0xf5, 0xa4, 0x6e, 0x96, 0x2a, 0xb2, 0xd6, 0xbe, 0x9e, 0xbd, 0x0d, -+ 0xb4, 0x42, 0xa9, 0xcf, 0x01, 0x83, 0x8a, 0x17, 0x47, 0x76, 0xc4, 0xc6, -+ 0x83, 0x04, 0x95, 0x0b, 0xfc, 0x11, 0xc9, 0x62, 0xb8, 0x0c, 0x76, 0x84, -+ 0xd9, 0xb9, 0x37, 0xfa, 0xfc, 0x7c, 0xc2, 0x6d, 0x58, 0x3e, 0xb3, 0x04, -+ 0xbb, 0x8c, 0x8f, 0x48, 0xbc, 0x91, 0x27, 0xcc, 0xf9, 0xb7, 0x22, 0x19, -+ 0x83, 0x2e, 0x09, 0xb5, 0x72, 0xd9, 0x54, 0x1c, 0x4d, 0xa1, 0xea, 0x0b, -+ 0xf1, 0xc6, 0x08, 0x72, 0x46, 0x87, 0x7a, 0x6e, 0x80, 0x56, 0x0a, 0x8a, -+ 0xc0, 0xdd, 0x11, 0x6b, 0xd6, 0xdd, 0x47, 0xdf, 0x10, 0xd9, 0xd8, 0xea, -+ 0x7c, 0xb0, 0x8f, 0x03, 0x00, 0x2e, 0xc1, 0x8f, 0x44, 0xa8, 0xd3, 0x30, -+ 0x06, 0x89, 0xa2, 0xf9, 0x34, 0xad, 0xdc, 0x03, 0x85, 0xed, 0x51, 0xa7, -+ 0x82, 0x9c, 0xe7, 0x5d, 0x52, 0x93, 0x0c, 0x32, 0x9a, 0x5b, 0xe1, 0xaa, -+ 0xca, 0xb8, 0x02, 0x6d, 0x3a, 0xd4, 0xb1, 0x3a, 0xf0, 0x5f, 0xbe, 0xb5, -+ 0x0d, 0x10, 0x6b, 0x38, 0x32, 0xac, 0x76, 0x80, 0xbd, 0xca, 0x94, 0x71, -+ 0x7a, 0xf2, 0xc9, 0x35, 0x2a, 0xde, 0x9f, 0x42, 0x49, 0x18, 0x01, 0xab, -+ 0xbc, 0xef, 0x7c, 0x64, 0x3f, 0x58, 0x3d, 0x92, 0x59, 0xdb, 0x13, 0xdb, -+ 0x58, 0x6e, 0x0a, 0xe0, 0xb7, 0x91, 0x4a, 0x08, 0x20, 0xd6, 0x2e, 0x3c, -+ 0x45, 0xc9, 0x8b, 0x17, 0x79, 0xe7, 0xc7, 0x90, 0x99, 0x3a, 0x18, 0x25, -+}; -+ -+#else -+ -+// k25519Precomp[i][j] = (j+1)*256^i*B -+static const ge_precomp k25519Precomp[32][8] = { -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1288382639258501, 245678601348599, 269427782077623, -+ 1462984067271730, 137412439391563 -+#else -+ 25967493, 19198397, 29566455, 3660896, 54414519, 4014786, -+ 27544626, 21800161, 61029707, 2047604 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 62697248952638, 204681361388450, 631292143396476, -+ 338455783676468, 1213667448819585 -+#else -+ 54563134, 934261, 64385954, 3049989, 66381436, 9406985, -+ 12720692, 5043384, 19500929, 18085054 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 301289933810280, 1259582250014073, 1422107436869536, -+ 796239922652654, 1953934009299142 -+#else -+ 58370664, 4489569, 9688441, 18769238, 10184608, 21191052, -+ 29287918, 11864899, 42594502, 29115885 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1380971894829527, 790832306631236, 2067202295274102, -+ 1995808275510000, 1566530869037010 -+#else -+ 54292951, 20578084, 45527620, 11784319, 41753206, 30803714, -+ 55390960, 29739860, 66750418, 23343128 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 463307831301544, 432984605774163, 1610641361907204, -+ 750899048855000, 1894842303421586 -+#else -+ 45405608, 6903824, 27185491, 6451973, 37531140, 24000426, -+ 51492312, 11189267, 40279186, 28235350 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 748439484463711, 1033211726465151, 1396005112841647, -+ 1611506220286469, 1972177495910992 -+#else -+ 26966623, 11152617, 32442495, 15396054, 14353839, 20802097, -+ 63980037, 24013313, 51636816, 29387734 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1601611775252272, 1720807796594148, 1132070835939856, -+ 1260455018889551, 2147779492816911 -+#else -+ 15636272, 23865875, 24204772, 25642034, 616976, 16869170, -+ 27787599, 18782243, 28944399, 32004408 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 316559037616741, 2177824224946892, 1459442586438991, -+ 1461528397712656, 751590696113597 -+#else -+ 16568933, 4717097, 55552716, 32452109, 15682895, 21747389, -+ 16354576, 21778470, 7689661, 11199574 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1850748884277385, 1200145853858453, 1068094770532492, -+ 672251375690438, 1586055907191707 -+#else -+ 30464137, 27578307, 55329429, 17883566, 23220364, 15915852, -+ 7512774, 10017326, 49359771, 23634074 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 934282339813791, 1846903124198670, 1172395437954843, -+ 1007037127761661, 1830588347719256 -+#else -+ 50071967, 13921891, 10945806, 27521001, 27105051, 17470053, -+ 38182653, 15006022, 3284568, 27277892 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1694390458783935, 1735906047636159, 705069562067493, -+ 648033061693059, 696214010414170 -+#else -+ 23599295, 25248385, 55915199, 25867015, 13236773, 10506355, -+ 7464579, 9656445, 13059162, 10374397 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1121406372216585, 192876649532226, 190294192191717, -+ 1994165897297032, 2245000007398739 -+#else -+ 7798537, 16710257, 3033922, 2874086, 28997861, 2835604, -+ 32406664, 29715387, 66467155, 33453106 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 769950342298419, 132954430919746, 844085933195555, -+ 974092374476333, 726076285546016 -+#else -+ 10861363, 11473154, 27284546, 1981175, 37044515, 12577860, -+ 32867885, 14515107, 51670560, 10819379 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 425251763115706, 608463272472562, 442562545713235, -+ 837766094556764, 374555092627893 -+#else -+ 4708026, 6336745, 20377586, 9066809, 55836755, 6594695, -+ 41455196, 12483687, 54440373, 5581305 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1086255230780037, 274979815921559, 1960002765731872, -+ 929474102396301, 1190409889297339 -+#else -+ 19563141, 16186464, 37722007, 4097518, 10237984, 29206317, -+ 28542349, 13850243, 43430843, 17738489 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1388594989461809, 316767091099457, 394298842192982, -+ 1230079486801005, 1440737038838979 -+#else -+ 51736881, 20691677, 32573249, 4720197, 40672342, 5875510, -+ 47920237, 18329612, 57289923, 21468654 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 7380825640100, 146210432690483, 304903576448906, -+ 1198869323871120, 997689833219095 -+#else -+ 58559652, 109982, 15149363, 2178705, 22900618, 4543417, 3044240, -+ 17864545, 1762327, 14866737 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1181317918772081, 114573476638901, 262805072233344, -+ 265712217171332, 294181933805782 -+#else -+ 48909169, 17603008, 56635573, 1707277, 49922944, 3916100, -+ 38872452, 3959420, 27914454, 4383652 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 665000864555967, 2065379846933859, 370231110385876, -+ 350988370788628, 1233371373142985 -+#else -+ 5153727, 9909285, 1723747, 30776558, 30523604, 5516873, -+ 19480852, 5230134, 43156425, 18378665 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2019367628972465, 676711900706637, 110710997811333, -+ 1108646842542025, 517791959672113 -+#else -+ 36839857, 30090922, 7665485, 10083793, 28475525, 1649722, -+ 20654025, 16520125, 30598449, 7715701 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 965130719900578, 247011430587952, 526356006571389, -+ 91986625355052, 2157223321444601 -+#else -+ 28881826, 14381568, 9657904, 3680757, 46927229, 7843315, -+ 35708204, 1370707, 29794553, 32145132 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2068619540119183, 1966274918058806, 957728544705549, -+ 729906502578991, 159834893065166 -+#else -+ 14499471, 30824833, 33917750, 29299779, 28494861, 14271267, -+ 30290735, 10876454, 33954766, 2381725 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2073601412052185, 31021124762708, 264500969797082, -+ 248034690651703, 1030252227928288 -+#else -+ 59913433, 30899068, 52378708, 462250, 39384538, 3941371, -+ 60872247, 3696004, 34808032, 15351954 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 551790716293402, 1989538725166328, 801169423371717, -+ 2052451893578887, 678432056995012 -+#else -+ 27431194, 8222322, 16448760, 29646437, 48401861, 11938354, -+ 34147463, 30583916, 29551812, 10109425 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1368953770187805, 790347636712921, 437508475667162, -+ 2142576377050580, 1932081720066286 -+#else -+ 53451805, 20399000, 35825113, 11777097, 21447386, 6519384, -+ 64730580, 31926875, 10092782, 28790261 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 953638594433374, 1092333936795051, 1419774766716690, -+ 805677984380077, 859228993502513 -+#else -+ 27939166, 14210322, 4677035, 16277044, 44144402, 21156292, -+ 34600109, 12005537, 49298737, 12803509 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1200766035879111, 20142053207432, 1465634435977050, -+ 1645256912097844, 295121984874596 -+#else -+ 17228999, 17892808, 65875336, 300139, 65883994, 21839654, -+ 30364212, 24516238, 18016356, 4397660 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1735718747031557, 1248237894295956, 1204753118328107, -+ 976066523550493, 65943769534592 -+#else -+ 56150021, 25864224, 4776340, 18600194, 27850027, 17952220, -+ 40489757, 14544524, 49631360, 982638 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1060098822528990, 1586825862073490, 212301317240126, -+ 1975302711403555, 666724059764335 -+#else -+ 29253598, 15796703, 64244882, 23645547, 10057022, 3163536, -+ 7332899, 29434304, 46061167, 9934962 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1091990273418756, 1572899409348578, 80968014455247, -+ 306009358661350, 1520450739132526 -+#else -+ 5793284, 16271923, 42977250, 23438027, 29188559, 1206517, -+ 52360934, 4559894, 36984942, 22656481 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1480517209436112, 1511153322193952, 1244343858991172, -+ 304788150493241, 369136856496443 -+#else -+ 39464912, 22061425, 16282656, 22517939, 28414020, 18542168, -+ 24191033, 4541697, 53770555, 5500567 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2151330273626164, 762045184746182, 1688074332551515, -+ 823046109005759, 907602769079491 -+#else -+ 12650548, 32057319, 9052870, 11355358, 49428827, 25154267, -+ 49678271, 12264342, 10874051, 13524335 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2047386910586836, 168470092900250, 1552838872594810, -+ 340951180073789, 360819374702533 -+#else -+ 25556948, 30508442, 714650, 2510400, 23394682, 23139102, -+ 33119037, 5080568, 44580805, 5376627 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1982622644432056, 2014393600336956, 128909208804214, -+ 1617792623929191, 105294281913815 -+#else -+ 41020600, 29543379, 50095164, 30016803, 60382070, 1920896, -+ 44787559, 24106988, 4535767, 1569007 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 980234343912898, 1712256739246056, 588935272190264, -+ 204298813091998, 841798321043288 -+#else -+ 64853442, 14606629, 45416424, 25514613, 28430648, 8775819, -+ 36614302, 3044289, 31848280, 12543772 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 197561292938973, 454817274782871, 1963754960082318, -+ 2113372252160468, 971377527342673 -+#else -+ 45080285, 2943892, 35251351, 6777305, 13784462, 29262229, -+ 39731668, 31491700, 7718481, 14474653 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 164699448829328, 3127451757672, 1199504971548753, -+ 1766155447043652, 1899238924683527 -+#else -+ 2385296, 2454213, 44477544, 46602, 62670929, 17874016, 656964, -+ 26317767, 24316167, 28300865 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 732262946680281, 1674412764227063, 2182456405662809, -+ 1350894754474250, 558458873295247 -+#else -+ 13741529, 10911568, 33875447, 24950694, 46931033, 32521134, -+ 33040650, 20129900, 46379407, 8321685 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2103305098582922, 1960809151316468, 715134605001343, -+ 1454892949167181, 40827143824949 -+#else -+ 21060490, 31341688, 15712756, 29218333, 1639039, 10656336, -+ 23845965, 21679594, 57124405, 608371 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1239289043050212, 1744654158124578, 758702410031698, -+ 1796762995074688, 1603056663766 -+#else -+ 53436132, 18466845, 56219170, 25997372, 61071954, 11305546, -+ 1123968, 26773855, 27229398, 23887 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2232056027107988, 987343914584615, 2115594492994461, -+ 1819598072792159, 1119305654014850 -+#else -+ 43864724, 33260226, 55364135, 14712570, 37643165, 31524814, -+ 12797023, 27114124, 65475458, 16678953 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 320153677847348, 939613871605645, 641883205761567, -+ 1930009789398224, 329165806634126 -+#else -+ 37608244, 4770661, 51054477, 14001337, 7830047, 9564805, -+ 65600720, 28759386, 49939598, 4904952 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 980930490474130, 1242488692177893, 1251446316964684, -+ 1086618677993530, 1961430968465772 -+#else -+ 24059538, 14617003, 19037157, 18514524, 19766092, 18648003, -+ 5169210, 16191880, 2128236, 29227599 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 276821765317453, 1536835591188030, 1305212741412361, -+ 61473904210175, 2051377036983058 -+#else -+ 50127693, 4124965, 58568254, 22900634, 30336521, 19449185, -+ 37302527, 916032, 60226322, 30567899 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 833449923882501, 1750270368490475, 1123347002068295, -+ 185477424765687, 278090826653186 -+#else -+ 44477957, 12419371, 59974635, 26081060, 50629959, 16739174, -+ 285431, 2763829, 15736322, 4143876 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 794524995833413, 1849907304548286, 53348672473145, -+ 1272368559505217, 1147304168324779 -+#else -+ 2379333, 11839345, 62998462, 27565766, 11274297, 794957, 212801, -+ 18959769, 23527083, 17096164 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1504846112759364, 1203096289004681, 562139421471418, -+ 274333017451844, 1284344053775441 -+#else -+ 33431108, 22423954, 49269897, 17927531, 8909498, 8376530, -+ 34483524, 4087880, 51919953, 19138217 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 483048732424432, 2116063063343382, 30120189902313, -+ 292451576741007, 1156379271702225 -+#else -+ 1767664, 7197987, 53903638, 31531796, 54017513, 448825, 5799055, -+ 4357868, 62334673, 17231393 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 928372153029038, 2147692869914564, 1455665844462196, -+ 1986737809425946, 185207050258089 -+#else -+ 6721966, 13833823, 43585476, 32003117, 26354292, 21691111, -+ 23365146, 29604700, 7390889, 2759800 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 137732961814206, 706670923917341, 1387038086865771, -+ 1965643813686352, 1384777115696347 -+#else -+ 4409022, 2052381, 23373853, 10530217, 7676779, 20668478, -+ 21302352, 29290375, 1244379, 20634787 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 481144981981577, 2053319313589856, 2065402289827512, -+ 617954271490316, 1106602634668125 -+#else -+ 62687625, 7169618, 4982368, 30596842, 30256824, 30776892, -+ 14086412, 9208236, 15886429, 16489664 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 696298019648792, 893299659040895, 1148636718636009, -+ 26734077349617, 2203955659340681 -+#else -+ 1996056, 10375649, 14346367, 13311202, 60234729, 17116020, -+ 53415665, 398368, 36502409, 32841498 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 657390353372855, 998499966885562, 991893336905797, -+ 810470207106761, 343139804608786 -+#else -+ 41801399, 9795879, 64331450, 14878808, 33577029, 14780362, -+ 13348553, 12076947, 36272402, 5113181 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 791736669492960, 934767652997115, 824656780392914, -+ 1759463253018643, 361530362383518 -+#else -+ 49338080, 11797795, 31950843, 13929123, 41220562, 12288343, -+ 36767763, 26218045, 13847710, 5387222 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2022541353055597, 2094700262587466, 1551008075025686, -+ 242785517418164, 695985404963562 -+#else -+ 48526701, 30138214, 17824842, 31213466, 22744342, 23111821, -+ 8763060, 3617786, 47508202, 10370990 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1287487199965223, 2215311941380308, 1552928390931986, -+ 1664859529680196, 1125004975265243 -+#else -+ 20246567, 19185054, 22358228, 33010720, 18507282, 23140436, -+ 14554436, 24808340, 32232923, 16763880 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 677434665154918, 989582503122485, 1817429540898386, -+ 1052904935475344, 1143826298169798 -+#else -+ 9648486, 10094563, 26416693, 14745928, 36734546, 27081810, -+ 11094160, 15689506, 3140038, 17044340 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 367266328308408, 318431188922404, 695629353755355, -+ 634085657580832, 24581612564426 -+#else -+ 50948792, 5472694, 31895588, 4744994, 8823515, 10365685, -+ 39884064, 9448612, 38334410, 366294 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 773360688841258, 1815381330538070, 363773437667376, -+ 539629987070205, 783280434248437 -+#else -+ 19153450, 11523972, 56012374, 27051289, 42461232, 5420646, -+ 28344573, 8041113, 719605, 11671788 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 180820816194166, 168937968377394, 748416242794470, -+ 1227281252254508, 1567587861004268 -+#else -+ 8678006, 2694440, 60300850, 2517371, 4964326, 11152271, -+ 51675948, 18287915, 27000812, 23358879 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 478775558583645, 2062896624554807, 699391259285399, -+ 358099408427873, 1277310261461761 -+#else -+ 51950941, 7134311, 8639287, 30739555, 59873175, 10421741, -+ 564065, 5336097, 6750977, 19033406 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1984740906540026, 1079164179400229, 1056021349262661, -+ 1659958556483663, 1088529069025527 -+#else -+ 11836410, 29574944, 26297893, 16080799, 23455045, 15735944, -+ 1695823, 24735310, 8169719, 16220347 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 580736401511151, 1842931091388998, 1177201471228238, -+ 2075460256527244, 1301133425678027 -+#else -+ 48993007, 8653646, 17578566, 27461813, 59083086, 17541668, -+ 55964556, 30926767, 61118155, 19388398 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1515728832059182, 1575261009617579, 1510246567196186, -+ 191078022609704, 116661716289141 -+#else -+ 43800366, 22586119, 15213227, 23473218, 36255258, 22504427, -+ 27884328, 2847284, 2655861, 1738395 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1295295738269652, 1714742313707026, 545583042462581, -+ 2034411676262552, 1513248090013606 -+#else -+ 39571412, 19301410, 41772562, 25551651, 57738101, 8129820, -+ 21651608, 30315096, 48021414, 22549153 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 230710545179830, 30821514358353, 760704303452229, -+ 390668103790604, 573437871383156 -+#else -+ 1533110, 3437855, 23735889, 459276, 29970501, 11335377, -+ 26030092, 5821408, 10478196, 8544890 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1169380107545646, 263167233745614, 2022901299054448, -+ 819900753251120, 2023898464874585 -+#else -+ 32173102, 17425121, 24896206, 3921497, 22579056, 30143578, -+ 19270448, 12217473, 17789017, 30158437 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2102254323485823, 1570832666216754, 34696906544624, -+ 1993213739807337, 70638552271463 -+#else -+ 36555903, 31326030, 51530034, 23407230, 13243888, 517024, -+ 15479401, 29701199, 30460519, 1052596 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 894132856735058, 548675863558441, 845349339503395, -+ 1942269668326667, 1615682209874691 -+#else -+ 55493970, 13323617, 32618793, 8175907, 51878691, 12596686, -+ 27491595, 28942073, 3179267, 24075541 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1287670217537834, 1222355136884920, 1846481788678694, -+ 1150426571265110, 1613523400722047 -+#else -+ 31947050, 19187781, 62468280, 18214510, 51982886, 27514722, -+ 52352086, 17142691, 19072639, 24043372 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 793388516527298, 1315457083650035, 1972286999342417, -+ 1901825953052455, 338269477222410 -+#else -+ 11685058, 11822410, 3158003, 19601838, 33402193, 29389366, -+ 5977895, 28339415, 473098, 5040608 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 550201530671806, 778605267108140, 2063911101902983, -+ 115500557286349, 2041641272971022 -+#else -+ 46817982, 8198641, 39698732, 11602122, 1290375, 30754672, -+ 28326861, 1721092, 47550222, 30422825 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 717255318455100, 519313764361315, 2080406977303708, -+ 541981206705521, 774328150311600 -+#else -+ 7881532, 10687937, 7578723, 7738378, 48157852, 31000479, -+ 21820785, 8076149, 39240368, 11538388 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 261715221532238, 1795354330069993, 1496878026850283, -+ 499739720521052, 389031152673770 -+#else -+ 47173198, 3899860, 18283497, 26752864, 51380203, 22305220, -+ 8754524, 7446702, 61432810, 5797015 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1997217696294013, 1717306351628065, 1684313917746180, -+ 1644426076011410, 1857378133465451 -+#else -+ 55813245, 29760862, 51326753, 25589858, 12708868, 25098233, -+ 2014098, 24503858, 64739691, 27677090 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1475434724792648, 76931896285979, 1116729029771667, -+ 2002544139318042, 725547833803938 -+#else -+ 44636488, 21985690, 39426843, 1146374, 18956691, 16640559, -+ 1192730, 29840233, 15123618, 10811505 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2022306639183567, 726296063571875, 315345054448644, -+ 1058733329149221, 1448201136060677 -+#else -+ 14352079, 30134717, 48166819, 10822654, 32750596, 4699007, -+ 67038501, 15776355, 38222085, 21579878 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1710065158525665, 1895094923036397, 123988286168546, -+ 1145519900776355, 1607510767693874 -+#else -+ 38867681, 25481956, 62129901, 28239114, 29416930, 1847569, -+ 46454691, 17069576, 4714546, 23953777 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 561605375422540, 1071733543815037, 131496498800990, -+ 1946868434569999, 828138133964203 -+#else -+ 15200332, 8368572, 19679101, 15970074, 35236190, 1959450, -+ 24611599, 29010600, 55362987, 12340219 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1548495173745801, 442310529226540, 998072547000384, -+ 553054358385281, 644824326376171 -+#else -+ 12876937, 23074376, 33134380, 6590940, 60801088, 14872439, -+ 9613953, 8241152, 15370987, 9608631 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1445526537029440, 2225519789662536, 914628859347385, -+ 1064754194555068, 1660295614401091 -+#else -+ 62965568, 21540023, 8446280, 33162829, 4407737, 13629032, -+ 59383996, 15866073, 38898243, 24740332 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1199690223111956, 24028135822341, 66638289244341, -+ 57626156285975, 565093967979607 -+#else -+ 26660628, 17876777, 8393733, 358047, 59707573, 992987, 43204631, -+ 858696, 20571223, 8420556 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 876926774220824, 554618976488214, 1012056309841565, -+ 839961821554611, 1414499340307677 -+#else -+ 14620696, 13067227, 51661590, 8264466, 14106269, 15080814, -+ 33531827, 12516406, 45534429, 21077682 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 703047626104145, 1266841406201770, 165556500219173, -+ 486991595001879, 1011325891650656 -+#else -+ 236881, 10476226, 57258, 18877408, 6472997, 2466984, 17258519, -+ 7256740, 8791136, 15069930 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1622861044480487, 1156394801573634, 1869132565415504, -+ 327103985777730, 2095342781472284 -+#else -+ 1276391, 24182514, 22949634, 17231625, 43615824, 27852245, -+ 14711874, 4874229, 36445724, 31223040 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 334886927423922, 489511099221528, 129160865966726, -+ 1720809113143481, 619700195649254 -+#else -+ 5855666, 4990204, 53397016, 7294283, 59304582, 1924646, -+ 65685689, 25642053, 34039526, 9234252 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1646545795166119, 1758370782583567, 714746174550637, -+ 1472693650165135, 898994790308209 -+#else -+ 20590503, 24535444, 31529743, 26201766, 64402029, 10650547, -+ 31559055, 21944845, 18979185, 13396066 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 333403773039279, 295772542452938, 1693106465353610, -+ 912330357530760, 471235657950362 -+#else -+ 24474287, 4968103, 22267082, 4407354, 24063882, 25229252, -+ 48291976, 13594781, 33514650, 7021958 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1811196219982022, 1068969825533602, 289602974833439, -+ 1988956043611592, 863562343398367 -+#else -+ 55541958, 26988926, 45743778, 15928891, 40950559, 4315420, -+ 41160136, 29637754, 45628383, 12868081 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 906282429780072, 2108672665779781, 432396390473936, -+ 150625823801893, 1708930497638539 -+#else -+ 38473832, 13504660, 19988037, 31421671, 21078224, 6443208, -+ 45662757, 2244499, 54653067, 25465048 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 925664675702328, 21416848568684, 1831436641861340, -+ 601157008940113, 371818055044496 -+#else -+ 36513336, 13793478, 61256044, 319135, 41385692, 27290532, -+ 33086545, 8957937, 51875216, 5540520 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1479786007267725, 1738881859066675, 68646196476567, -+ 2146507056100328, 1247662817535471 -+#else -+ 55478669, 22050529, 58989363, 25911358, 2620055, 1022908, -+ 43398120, 31985447, 50980335, 18591624 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 52035296774456, 939969390708103, 312023458773250, -+ 59873523517659, 1231345905848899 -+#else -+ 23152952, 775386, 27395463, 14006635, 57407746, 4649511, -+ 1689819, 892185, 55595587, 18348483 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 643355106415761, 290186807495774, 2013561737429023, -+ 319648069511546, 393736678496162 -+#else -+ 9770129, 9586738, 26496094, 4324120, 1556511, 30004408, -+ 27453818, 4763127, 47929250, 5867133 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 129358342392716, 1932811617704777, 1176749390799681, -+ 398040349861790, 1170779668090425 -+#else -+ 34343820, 1927589, 31726409, 28801137, 23962433, 17534932, -+ 27846558, 5931263, 37359161, 17445976 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2051980782668029, 121859921510665, 2048329875753063, -+ 1235229850149665, 519062146124755 -+#else -+ 27461885, 30576896, 22380809, 1815854, 44075111, 30522493, -+ 7283489, 18406359, 47582163, 7734628 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1608170971973096, 415809060360428, 1350468408164766, -+ 2038620059057678, 1026904485989112 -+#else -+ 59098600, 23963614, 55988460, 6196037, 29344158, 20123547, -+ 7585294, 30377806, 18549496, 15302069 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1837656083115103, 1510134048812070, 906263674192061, -+ 1821064197805734, 565375124676301 -+#else -+ 34450527, 27383209, 59436070, 22502750, 6258877, 13504381, -+ 10458790, 27135971, 58236621, 8424745 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 578027192365650, 2034800251375322, 2128954087207123, -+ 478816193810521, 2196171989962750 -+#else -+ 24687186, 8613276, 36441818, 30320886, 1863891, 31723888, -+ 19206233, 7134917, 55824382, 32725512 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1633188840273139, 852787172373708, 1548762607215796, -+ 1266275218902681, 1107218203325133 -+#else -+ 11334899, 24336410, 8025292, 12707519, 17523892, 23078361, -+ 10243737, 18868971, 62042829, 16498836 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 462189358480054, 1784816734159228, 1611334301651368, -+ 1303938263943540, 707589560319424 -+#else -+ 8911542, 6887158, 57524604, 26595841, 11145640, 24010752, -+ 17303924, 19430194, 6536640, 10543906 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1038829280972848, 38176604650029, 753193246598573, -+ 1136076426528122, 595709990562434 -+#else -+ 38162480, 15479762, 49642029, 568875, 65611181, 11223453, -+ 64439674, 16928857, 39873154, 8876770 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1408451820859834, 2194984964010833, 2198361797561729, -+ 1061962440055713, 1645147963442934 -+#else -+ 41365946, 20987567, 51458897, 32707824, 34082177, 32758143, -+ 33627041, 15824473, 66504438, 24514614 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 4701053362120, 1647641066302348, 1047553002242085, -+ 1923635013395977, 206970314902065 -+#else -+ 10330056, 70051, 7957388, 24551765, 9764901, 15609756, 27698697, -+ 28664395, 1657393, 3084098 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1750479161778571, 1362553355169293, 1891721260220598, -+ 966109370862782, 1024913988299801 -+#else -+ 10477963, 26084172, 12119565, 20303627, 29016246, 28188843, -+ 31280318, 14396151, 36875289, 15272408 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 212699049131723, 1117950018299775, 1873945661751056, -+ 1403802921984058, 130896082652698 -+#else -+ 54820555, 3169462, 28813183, 16658753, 25116432, 27923966, -+ 41934906, 20918293, 42094106, 1950503 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 636808533673210, 1262201711667560, 390951380330599, -+ 1663420692697294, 561951321757406 -+#else -+ 40928506, 9489186, 11053416, 18808271, 36055143, 5825629, -+ 58724558, 24786899, 15341278, 8373727 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 520731594438141, 1446301499955692, 273753264629267, -+ 1565101517999256, 1019411827004672 -+#else -+ 28685821, 7759505, 52730348, 21551571, 35137043, 4079241, -+ 298136, 23321830, 64230656, 15190419 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 926527492029409, 1191853477411379, 734233225181171, -+ 184038887541270, 1790426146325343 -+#else -+ 34175969, 13806335, 52771379, 17760000, 43104243, 10940927, -+ 8669718, 2742393, 41075551, 26679428 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1464651961852572, 1483737295721717, 1519450561335517, -+ 1161429831763785, 405914998179977 -+#else -+ 65528476, 21825014, 41129205, 22109408, 49696989, 22641577, -+ 9291593, 17306653, 54954121, 6048604 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 996126634382301, 796204125879525, 127517800546509, -+ 344155944689303, 615279846169038 -+#else -+ 36803549, 14843443, 1539301, 11864366, 20201677, 1900163, -+ 13934231, 5128323, 11213262, 9168384 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 738724080975276, 2188666632415296, 1961313708559162, -+ 1506545807547587, 1151301638969740 -+#else -+ 40828332, 11007846, 19408960, 32613674, 48515898, 29225851, -+ 62020803, 22449281, 20470156, 17155731 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 622917337413835, 1218989177089035, 1284857712846592, -+ 970502061709359, 351025208117090 -+#else -+ 43972811, 9282191, 14855179, 18164354, 59746048, 19145871, -+ 44324911, 14461607, 14042978, 5230683 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2067814584765580, 1677855129927492, 2086109782475197, -+ 235286517313238, 1416314046739645 -+#else -+ 29969548, 30812838, 50396996, 25001989, 9175485, 31085458, -+ 21556950, 3506042, 61174973, 21104723 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 586844262630358, 307444381952195, 458399356043426, -+ 602068024507062, 1028548203415243 -+#else -+ 63964118, 8744660, 19704003, 4581278, 46678178, 6830682, -+ 45824694, 8971512, 38569675, 15326562 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 678489922928203, 2016657584724032, 90977383049628, -+ 1026831907234582, 615271492942522 -+#else -+ 47644235, 10110287, 49846336, 30050539, 43608476, 1355668, -+ 51585814, 15300987, 46594746, 9168259 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 301225714012278, 1094837270268560, 1202288391010439, -+ 644352775178361, 1647055902137983 -+#else -+ 61755510, 4488612, 43305616, 16314346, 7780487, 17915493, -+ 38160505, 9601604, 33087103, 24543045 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1210746697896478, 1416608304244708, 686487477217856, -+ 1245131191434135, 1051238336855737 -+#else -+ 47665694, 18041531, 46311396, 21109108, 37284416, 10229460, -+ 39664535, 18553900, 61111993, 15664671 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1135604073198207, 1683322080485474, 769147804376683, -+ 2086688130589414, 900445683120379 -+#else -+ 23294591, 16921819, 44458082, 25083453, 27844203, 11461195, -+ 13099750, 31094076, 18151675, 13417686 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1971518477615628, 401909519527336, 448627091057375, -+ 1409486868273821, 1214789035034363 -+#else -+ 42385932, 29377914, 35958184, 5988918, 40250079, 6685064, -+ 1661597, 21002991, 15271675, 18101767 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1364039144731711, 1897497433586190, 2203097701135459, -+ 145461396811251, 1349844460790699 -+#else -+ 11433023, 20325767, 8239630, 28274915, 65123427, 32828713, -+ 48410099, 2167543, 60187563, 20114249 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1045230323257973, 818206601145807, 630513189076103, -+ 1672046528998132, 807204017562437 -+#else -+ 35672693, 15575145, 30436815, 12192228, 44645511, 9395378, -+ 57191156, 24915434, 12215109, 12028277 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 439961968385997, 386362664488986, 1382706320807688, -+ 309894000125359, 2207801346498567 -+#else -+ 14098381, 6555944, 23007258, 5757252, 51681032, 20603929, -+ 30123439, 4617780, 50208775, 32898803 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1229004686397588, 920643968530863, 123975893911178, -+ 681423993215777, 1400559197080973 -+#else -+ 63082644, 18313596, 11893167, 13718664, 52299402, 1847384, -+ 51288865, 10154008, 23973261, 20869958 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2003766096898049, 170074059235165, 1141124258967971, -+ 1485419893480973, 1573762821028725 -+#else -+ 40577025, 29858441, 65199965, 2534300, 35238307, 17004076, -+ 18341389, 22134481, 32013173, 23450893 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 729905708611432, 1270323270673202, 123353058984288, -+ 426460209632942, 2195574535456672 -+#else -+ 41629544, 10876442, 55337778, 18929291, 54739296, 1838103, -+ 21911214, 6354752, 4425632, 32716610 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1271140255321235, 2044363183174497, 52125387634689, -+ 1445120246694705, 942541986339084 -+#else -+ 56675475, 18941465, 22229857, 30463385, 53917697, 776728, -+ 49693489, 21533969, 4725004, 14044970 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1761608437466135, 583360847526804, 1586706389685493, -+ 2157056599579261, 1170692369685772 -+#else -+ 19268631, 26250011, 1555348, 8692754, 45634805, 23643767, -+ 6347389, 32142648, 47586572, 17444675 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 871476219910823, 1878769545097794, 2241832391238412, -+ 548957640601001, 690047440233174 -+#else -+ 42244775, 12986007, 56209986, 27995847, 55796492, 33405905, -+ 19541417, 8180106, 9282262, 10282508 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 297194732135507, 1366347803776820, 1301185512245601, -+ 561849853336294, 1533554921345731 -+#else -+ 40903763, 4428546, 58447668, 20360168, 4098401, 19389175, -+ 15522534, 8372215, 5542595, 22851749 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 999628998628371, 1132836708493400, 2084741674517453, -+ 469343353015612, 678782988708035 -+#else -+ 56546323, 14895632, 26814552, 16880582, 49628109, 31065071, -+ 64326972, 6993760, 49014979, 10114654 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2189427607417022, 699801937082607, 412764402319267, -+ 1478091893643349, 2244675696854460 -+#else -+ 47001790, 32625013, 31422703, 10427861, 59998115, 6150668, -+ 38017109, 22025285, 25953724, 33448274 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1712292055966563, 204413590624874, 1405738637332841, -+ 408981300829763, 861082219276721 -+#else -+ 62874467, 25515139, 57989738, 3045999, 2101609, 20947138, -+ 19390019, 6094296, 63793585, 12831124 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 508561155940631, 966928475686665, 2236717801150132, -+ 424543858577297, 2089272956986143 -+#else -+ 51110167, 7578151, 5310217, 14408357, 33560244, 33329692, -+ 31575953, 6326196, 7381791, 31132593 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 221245220129925, 1156020201681217, 491145634799213, -+ 542422431960839, 828100817819207 -+#else -+ 46206085, 3296810, 24736065, 17226043, 18374253, 7318640, -+ 6295303, 8082724, 51746375, 12339663 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 153756971240384, 1299874139923977, 393099165260502, -+ 1058234455773022, 996989038681183 -+#else -+ 27724736, 2291157, 6088201, 19369634, 1792726, 5857634, -+ 13848414, 15768922, 25091167, 14856294 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 559086812798481, 573177704212711, 1629737083816402, -+ 1399819713462595, 1646954378266038 -+#else -+ 48242193, 8331042, 24373479, 8541013, 66406866, 24284974, -+ 12927299, 20858939, 44926390, 24541532 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1887963056288059, 228507035730124, 1468368348640282, -+ 930557653420194, 613513962454686 -+#else -+ 55685435, 28132841, 11632844, 3405020, 30536730, 21880393, -+ 39848098, 13866389, 30146206, 9142070 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1224529808187553, 1577022856702685, 2206946542980843, -+ 625883007765001, 279930793512158 -+#else -+ 3924129, 18246916, 53291741, 23499471, 12291819, 32886066, -+ 39406089, 9326383, 58871006, 4171293 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1076287717051609, 1114455570543035, 187297059715481, -+ 250446884292121, 1885187512550540 -+#else -+ 51186905, 16037936, 6713787, 16606682, 45496729, 2790943, -+ 26396185, 3731949, 345228, 28091483 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 902497362940219, 76749815795675, 1657927525633846, -+ 1420238379745202, 1340321636548352 -+#else -+ 45781307, 13448258, 25284571, 1143661, 20614966, 24705045, -+ 2031538, 21163201, 50855680, 19972348 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1129576631190784, 1281994010027327, 996844254743018, -+ 257876363489249, 1150850742055018 -+#else -+ 31016192, 16832003, 26371391, 19103199, 62081514, 14854136, -+ 17477601, 3842657, 28012650, 17149012 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 628740660038789, 1943038498527841, 467786347793886, -+ 1093341428303375, 235413859513003 -+#else -+ 62033029, 9368965, 58546785, 28953529, 51858910, 6970559, -+ 57918991, 16292056, 58241707, 3507939 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 237425418909360, 469614029179605, 1512389769174935, -+ 1241726368345357, 441602891065214 -+#else -+ 29439664, 3537914, 23333589, 6997794, 49553303, 22536363, -+ 51899661, 18503164, 57943934, 6580395 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1736417953058555, 726531315520508, 1833335034432527, -+ 1629442561574747, 624418919286085 -+#else -+ 54923003, 25874643, 16438268, 10826160, 58412047, 27318820, -+ 17860443, 24280586, 65013061, 9304566 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1960754663920689, 497040957888962, 1909832851283095, -+ 1271432136996826, 2219780368020940 -+#else -+ 20714545, 29217521, 29088194, 7406487, 11426967, 28458727, -+ 14792666, 18945815, 5289420, 33077305 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1537037379417136, 1358865369268262, 2130838645654099, -+ 828733687040705, 1999987652890901 -+#else -+ 50443312, 22903641, 60948518, 20248671, 9192019, 31751970, -+ 17271489, 12349094, 26939669, 29802138 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 629042105241814, 1098854999137608, 887281544569320, -+ 1423102019874777, 7911258951561 -+#else -+ 54218966, 9373457, 31595848, 16374215, 21471720, 13221525, -+ 39825369, 21205872, 63410057, 117886 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1811562332665373, 1501882019007673, 2213763501088999, -+ 359573079719636, 36370565049116 -+#else -+ 22263325, 26994382, 3984569, 22379786, 51994855, 32987646, -+ 28311252, 5358056, 43789084, 541963 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 218907117361280, 1209298913016966, 1944312619096112, -+ 1130690631451061, 1342327389191701 -+#else -+ 16259200, 3261970, 2309254, 18019958, 50223152, 28972515, -+ 24134069, 16848603, 53771797, 20002236 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1369976867854704, 1396479602419169, 1765656654398856, -+ 2203659200586299, 998327836117241 -+#else -+ 9378160, 20414246, 44262881, 20809167, 28198280, 26310334, -+ 64709179, 32837080, 690425, 14876244 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2230701885562825, 1348173180338974, 2172856128624598, -+ 1426538746123771, 444193481326151 -+#else -+ 24977353, 33240048, 58884894, 20089345, 28432342, 32378079, -+ 54040059, 21257083, 44727879, 6618998 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 784210426627951, 918204562375674, 1284546780452985, -+ 1324534636134684, 1872449409642708 -+#else -+ 65570671, 11685645, 12944378, 13682314, 42719353, 19141238, -+ 8044828, 19737104, 32239828, 27901670 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 319638829540294, 596282656808406, 2037902696412608, -+ 1557219121643918, 341938082688094 -+#else -+ 48505798, 4762989, 66182614, 8885303, 38696384, 30367116, -+ 9781646, 23204373, 32779358, 5095274 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1901860206695915, 2004489122065736, 1625847061568236, -+ 973529743399879, 2075287685312905 -+#else -+ 34100715, 28339925, 34843976, 29869215, 9460460, 24227009, -+ 42507207, 14506723, 21639561, 30924196 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1371853944110545, 1042332820512553, 1949855697918254, -+ 1791195775521505, 37487364849293 -+#else -+ 50707921, 20442216, 25239337, 15531969, 3987758, 29055114, -+ 65819361, 26690896, 17874573, 558605 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 687200189577855, 1082536651125675, 644224940871546, -+ 340923196057951, 343581346747396 -+#else -+ 53508735, 10240080, 9171883, 16131053, 46239610, 9599699, -+ 33499487, 5080151, 2085892, 5119761 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2082717129583892, 27829425539422, 145655066671970, -+ 1690527209845512, 1865260509673478 -+#else -+ 44903700, 31034903, 50727262, 414690, 42089314, 2170429, -+ 30634760, 25190818, 35108870, 27794547 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1059729620568824, 2163709103470266, 1440302280256872, -+ 1769143160546397, 869830310425069 -+#else -+ 60263160, 15791201, 8550074, 32241778, 29928808, 21462176, -+ 27534429, 26362287, 44757485, 12961481 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1609516219779025, 777277757338817, 2101121130363987, -+ 550762194946473, 1905542338659364 -+#else -+ 42616785, 23983660, 10368193, 11582341, 43711571, 31309144, -+ 16533929, 8206996, 36914212, 28394793 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2024821921041576, 426948675450149, 595133284085473, -+ 471860860885970, 600321679413000 -+#else -+ 55987368, 30172197, 2307365, 6362031, 66973409, 8868176, -+ 50273234, 7031274, 7589640, 8945490 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 598474602406721, 1468128276358244, 1191923149557635, -+ 1501376424093216, 1281662691293476 -+#else -+ 34956097, 8917966, 6661220, 21876816, 65916803, 17761038, -+ 7251488, 22372252, 24099108, 19098262 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1721138489890707, 1264336102277790, 433064545421287, -+ 1359988423149466, 1561871293409447 -+#else -+ 5019539, 25646962, 4244126, 18840076, 40175591, 6453164, -+ 47990682, 20265406, 60876967, 23273695 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 719520245587143, 393380711632345, 132350400863381, -+ 1543271270810729, 1819543295798660 -+#else -+ 10853575, 10721687, 26480089, 5861829, 44113045, 1972174, -+ 65242217, 22996533, 63745412, 27113307 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 396397949784152, 1811354474471839, 1362679985304303, -+ 2117033964846756, 498041172552279 -+#else -+ 50106456, 5906789, 221599, 26991285, 7828207, 20305514, -+ 24362660, 31546264, 53242455, 7421391 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1812471844975748, 1856491995543149, 126579494584102, -+ 1036244859282620, 1975108050082550 -+#else -+ 8139908, 27007935, 32257645, 27663886, 30375718, 1886181, -+ 45933756, 15441251, 28826358, 29431403 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 650623932407995, 1137551288410575, 2125223403615539, -+ 1725658013221271, 2134892965117796 -+#else -+ 6267067, 9695052, 7709135, 16950835, 34239795, 31668296, -+ 14795159, 25714308, 13746020, 31812384 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 522584000310195, 1241762481390450, 1743702789495384, -+ 2227404127826575, 1686746002148897 -+#else -+ 28584883, 7787108, 60375922, 18503702, 22846040, 25983196, -+ 63926927, 33190907, 4771361, 25134474 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 427904865186312, 1703211129693455, 1585368107547509, -+ 1436984488744336, 761188534613978 -+#else -+ 24949256, 6376279, 39642383, 25379823, 48462709, 23623825, -+ 33543568, 21412737, 3569626, 11342593 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 318101947455002, 248138407995851, 1481904195303927, -+ 309278454311197, 1258516760217879 -+#else -+ 26514970, 4740088, 27912651, 3697550, 19331575, 22082093, -+ 6809885, 4608608, 7325975, 18753361 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1275068538599310, 513726919533379, 349926553492294, -+ 688428871968420, 1702400196000666 -+#else -+ 55490446, 19000001, 42787651, 7655127, 65739590, 5214311, -+ 39708324, 10258389, 49462170, 25367739 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1061864036265233, 961611260325381, 321859632700838, -+ 1045600629959517, 1985130202504038 -+#else -+ 11431185, 15823007, 26570245, 14329124, 18029990, 4796082, -+ 35662685, 15580663, 9280358, 29580745 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1558816436882417, 1962896332636523, 1337709822062152, -+ 1501413830776938, 294436165831932 -+#else -+ 66948081, 23228174, 44253547, 29249434, 46247496, 19933429, -+ 34297962, 22372809, 51563772, 4387440 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 818359826554971, 1862173000996177, 626821592884859, -+ 573655738872376, 1749691246745455 -+#else -+ 46309467, 12194511, 3937617, 27748540, 39954043, 9340369, -+ 42594872, 8548136, 20617071, 26072431 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1988022651432119, 1082111498586040, 1834020786104821, -+ 1454826876423687, 692929915223122 -+#else -+ 66170039, 29623845, 58394552, 16124717, 24603125, 27329039, -+ 53333511, 21678609, 24345682, 10325460 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2146513703733331, 584788900394667, 464965657279958, -+ 2183973639356127, 238371159456790 -+#else -+ 47253587, 31985546, 44906155, 8714033, 14007766, 6928528, -+ 16318175, 32543743, 4766742, 3552007 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1129007025494441, 2197883144413266, 265142755578169, -+ 971864464758890, 1983715884903702 -+#else -+ 45357481, 16823515, 1351762, 32751011, 63099193, 3950934, -+ 3217514, 14481909, 10988822, 29559670 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1291366624493075, 381456718189114, 1711482489312444, -+ 1815233647702022, 892279782992467 -+#else -+ 15564307, 19242862, 3101242, 5684148, 30446780, 25503076, -+ 12677126, 27049089, 58813011, 13296004 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 444548969917454, 1452286453853356, 2113731441506810, -+ 645188273895859, 810317625309512 -+#else -+ 57666574, 6624295, 36809900, 21640754, 62437882, 31497052, -+ 31521203, 9614054, 37108040, 12074673 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2242724082797924, 1373354730327868, 1006520110883049, -+ 2147330369940688, 1151816104883620 -+#else -+ 4771172, 33419193, 14290748, 20464580, 27992297, 14998318, -+ 65694928, 31997715, 29832612, 17163397 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1745720200383796, 1911723143175317, 2056329390702074, -+ 355227174309849, 879232794371100 -+#else -+ 7064884, 26013258, 47946901, 28486894, 48217594, 30641695, -+ 25825241, 5293297, 39986204, 13101589 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 163723479936298, 115424889803150, 1156016391581227, -+ 1894942220753364, 1970549419986329 -+#else -+ 64810282, 2439669, 59642254, 1719964, 39841323, 17225986, -+ 32512468, 28236839, 36752793, 29363474 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 681981452362484, 267208874112496, 1374683991933094, -+ 638600984916117, 646178654558546 -+#else -+ 37102324, 10162315, 33928688, 3981722, 50626726, 20484387, -+ 14413973, 9515896, 19568978, 9628812 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 13378654854251, 106237307029567, 1944412051589651, -+ 1841976767925457, 230702819835573 -+#else -+ 33053803, 199357, 15894591, 1583059, 27380243, 28973997, -+ 49269969, 27447592, 60817077, 3437739 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 260683893467075, 854060306077237, 913639551980112, -+ 4704576840123, 280254810808712 -+#else -+ 48129987, 3884492, 19469877, 12726490, 15913552, 13614290, -+ 44147131, 70103, 7463304, 4176122 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 715374893080287, 1173334812210491, 1806524662079626, -+ 1894596008000979, 398905715033393 -+#else -+ 39984863, 10659916, 11482427, 17484051, 12771466, 26919315, -+ 34389459, 28231680, 24216881, 5944158 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 500026409727661, 1596431288195371, 1420380351989370, -+ 985211561521489, 392444930785633 -+#else -+ 8894125, 7450974, 64444715, 23788679, 39028346, 21165316, -+ 19345745, 14680796, 11632993, 5847885 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2096421546958141, 1922523000950363, 789831022876840, -+ 427295144688779, 320923973161730 -+#else -+ 26942781, 31239115, 9129563, 28647825, 26024104, 11769399, -+ 55590027, 6367193, 57381634, 4782139 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1927770723575450, 1485792977512719, 1850996108474547, -+ 551696031508956, 2126047405475647 -+#else -+ 19916442, 28726022, 44198159, 22140040, 25606323, 27581991, -+ 33253852, 8220911, 6358847, 31680575 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2112099158080148, 742570803909715, 6484558077432, -+ 1951119898618916, 93090382703416 -+#else -+ 801428, 31472730, 16569427, 11065167, 29875704, 96627, 7908388, -+ 29073952, 53570360, 1387154 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 383905201636970, 859946997631870, 855623867637644, -+ 1017125780577795, 794250831877809 -+#else -+ 19646058, 5720633, 55692158, 12814208, 11607948, 12749789, -+ 14147075, 15156355, 45242033, 11835259 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 77571826285752, 999304298101753, 487841111777762, -+ 1038031143212339, 339066367948762 -+#else -+ 19299512, 1155910, 28703737, 14890794, 2925026, 7269399, -+ 26121523, 15467869, 40548314, 5052482 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 674994775520533, 266035846330789, 826951213393478, -+ 1405007746162285, 1781791018620876 -+#else -+ 64091413, 10058205, 1980837, 3964243, 22160966, 12322533, -+ 60677741, 20936246, 12228556, 26550755 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1001412661522686, 348196197067298, 1666614366723946, -+ 888424995032760, 580747687801357 -+#else -+ 32944382, 14922211, 44263970, 5188527, 21913450, 24834489, -+ 4001464, 13238564, 60994061, 8653814 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1939560076207777, 1409892634407635, 552574736069277, -+ 383854338280405, 190706709864139 -+#else -+ 22865569, 28901697, 27603667, 21009037, 14348957, 8234005, -+ 24808405, 5719875, 28483275, 2841751 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2177087163428741, 1439255351721944, 1208070840382793, -+ 2230616362004769, 1396886392021913 -+#else -+ 50687877, 32441126, 66781144, 21446575, 21886281, 18001658, -+ 65220897, 33238773, 19932057, 20815229 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 676962063230039, 1880275537148808, 2046721011602706, -+ 888463247083003, 1318301552024067 -+#else -+ 55452759, 10087520, 58243976, 28018288, 47830290, 30498519, -+ 3999227, 13239134, 62331395, 19644223 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1466980508178206, 617045217998949, 652303580573628, -+ 757303753529064, 207583137376902 -+#else -+ 1382174, 21859713, 17266789, 9194690, 53784508, 9720080, -+ 20403944, 11284705, 53095046, 3093229 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1511056752906902, 105403126891277, 493434892772846, -+ 1091943425335976, 1802717338077427 -+#else -+ 16650902, 22516500, 66044685, 1570628, 58779118, 7352752, -+ 66806440, 16271224, 43059443, 26862581 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1853982405405128, 1878664056251147, 1528011020803992, -+ 1019626468153565, 1128438412189035 -+#else -+ 45197768, 27626490, 62497547, 27994275, 35364760, 22769138, -+ 24123613, 15193618, 45456747, 16815042 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1963939888391106, 293456433791664, 697897559513649, -+ 985882796904380, 796244541237972 -+#else -+ 57172930, 29264984, 41829040, 4372841, 2087473, 10399484, -+ 31870908, 14690798, 17361620, 11864968 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 416770998629779, 389655552427054, 1314476859406756, -+ 1749382513022778, 1161905598739491 -+#else -+ 55801235, 6210371, 13206574, 5806320, 38091172, 19587231, -+ 54777658, 26067830, 41530403, 17313742 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1428358296490651, 1027115282420478, 304840698058337, -+ 441410174026628, 1819358356278573 -+#else -+ 14668443, 21284197, 26039038, 15305210, 25515617, 4542480, -+ 10453892, 6577524, 9145645, 27110552 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 204943430200135, 1554861433819175, 216426658514651, -+ 264149070665950, 2047097371738319 -+#else -+ 5974855, 3053895, 57675815, 23169240, 35243739, 3225008, -+ 59136222, 3936127, 61456591, 30504127 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1934415182909034, 1393285083565062, 516409331772960, -+ 1157690734993892, 121039666594268 -+#else -+ 30625386, 28825032, 41552902, 20761565, 46624288, 7695098, -+ 17097188, 17250936, 39109084, 1803631 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 662035583584445, 286736105093098, 1131773000510616, -+ 818494214211439, 472943792054479 -+#else -+ 63555773, 9865098, 61880298, 4272700, 61435032, 16864731, -+ 14911343, 12196514, 45703375, 7047411 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 665784778135882, 1893179629898606, 808313193813106, -+ 276797254706413, 1563426179676396 -+#else -+ 20093258, 9920966, 55970670, 28210574, 13161586, 12044805, -+ 34252013, 4124600, 34765036, 23296865 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 945205108984232, 526277562959295, 1324180513733566, -+ 1666970227868664, 153547609289173 -+#else -+ 46320040, 14084653, 53577151, 7842146, 19119038, 19731827, -+ 4752376, 24839792, 45429205, 2288037 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2031433403516252, 203996615228162, 170487168837083, -+ 981513604791390, 843573964916831 -+#else -+ 40289628, 30270716, 29965058, 3039786, 52635099, 2540456, -+ 29457502, 14625692, 42289247, 12570231 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1476570093962618, 838514669399805, 1857930577281364, -+ 2017007352225784, 317085545220047 -+#else -+ 66045306, 22002608, 16920317, 12494842, 1278292, 27685323, -+ 45948920, 30055751, 55134159, 4724942 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1461557121912842, 1600674043318359, 2157134900399597, -+ 1670641601940616, 127765583803283 -+#else -+ 17960970, 21778898, 62967895, 23851901, 58232301, 32143814, -+ 54201480, 24894499, 37532563, 1903855 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1293543509393474, 2143624609202546, 1058361566797508, -+ 214097127393994, 946888515472729 -+#else -+ 23134274, 19275300, 56426866, 31942495, 20684484, 15770816, -+ 54119114, 3190295, 26955097, 14109738 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 357067959932916, 1290876214345711, 521245575443703, -+ 1494975468601005, 800942377643885 -+#else -+ 15308788, 5320727, 36995055, 19235554, 22902007, 7767164, -+ 29425325, 22276870, 31960941, 11934971 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 566116659100033, 820247422481740, 994464017954148, -+ 327157611686365, 92591318111744 -+#else -+ 39713153, 8435795, 4109644, 12222639, 42480996, 14818668, -+ 20638173, 4875028, 10491392, 1379718 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 617256647603209, 1652107761099439, 1857213046645471, -+ 1085597175214970, 817432759830522 -+#else -+ 53949449, 9197840, 3875503, 24618324, 65725151, 27674630, -+ 33518458, 16176658, 21432314, 12180697 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 771808161440705, 1323510426395069, 680497615846440, -+ 851580615547985, 1320806384849017 -+#else -+ 55321537, 11500837, 13787581, 19721842, 44678184, 10140204, -+ 1465425, 12689540, 56807545, 19681548 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1219260086131915, 647169006596815, 79601124759706, -+ 2161724213426748, 404861897060198 -+#else -+ 5414091, 18168391, 46101199, 9643569, 12834970, 1186149, -+ 64485948, 32212200, 26128230, 6032912 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1327968293887866, 1335500852943256, 1401587164534264, -+ 558137311952440, 1551360549268902 -+#else -+ 40771450, 19788269, 32496024, 19900513, 17847800, 20885276, -+ 3604024, 8316894, 41233830, 23117073 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 417621685193956, 1429953819744454, 396157358457099, -+ 1940470778873255, 214000046234152 -+#else -+ 3296484, 6223048, 24680646, 21307972, 44056843, 5903204, -+ 58246567, 28915267, 12376616, 3188849 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1268047918491973, 2172375426948536, 1533916099229249, -+ 1761293575457130, 1590622667026765 -+#else -+ 29190469, 18895386, 27549112, 32370916, 3520065, 22857131, -+ 32049514, 26245319, 50999629, 23702124 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1627072914981959, 2211603081280073, 1912369601616504, -+ 1191770436221309, 2187309757525860 -+#else -+ 52364359, 24245275, 735817, 32955454, 46701176, 28496527, -+ 25246077, 17758763, 18640740, 32593455 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1149147819689533, 378692712667677, 828475842424202, -+ 2218619146419342, 70688125792186 -+#else -+ 60180029, 17123636, 10361373, 5642961, 4910474, 12345252, -+ 35470478, 33060001, 10530746, 1053335 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1299739417079761, 1438616663452759, 1536729078504412, -+ 2053896748919838, 1008421032591246 -+#else -+ 37842897, 19367626, 53570647, 21437058, 47651804, 22899047, -+ 35646494, 30605446, 24018830, 15026644 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2040723824657366, 399555637875075, 632543375452995, -+ 872649937008051, 1235394727030233 -+#else -+ 44516310, 30409154, 64819587, 5953842, 53668675, 9425630, -+ 25310643, 13003497, 64794073, 18408815 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2211311599327900, 2139787259888175, 938706616835350, -+ 12609661139114, 2081897930719789 -+#else -+ 39688860, 32951110, 59064879, 31885314, 41016598, 13987818, -+ 39811242, 187898, 43942445, 31022696 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1324994503390450, 336982330582631, 1183998925654177, -+ 1091654665913274, 48727673971319 -+#else -+ 45364466, 19743956, 1844839, 5021428, 56674465, 17642958, -+ 9716666, 16266922, 62038647, 726098 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1845522914617879, 1222198248335542, 150841072760134, -+ 1927029069940982, 1189913404498011 -+#else -+ 29370903, 27500434, 7334070, 18212173, 9385286, 2247707, -+ 53446902, 28714970, 30007387, 17731091 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1079559557592645, 2215338383666441, 1903569501302605, -+ 49033973033940, 305703433934152 -+#else -+ 66172485, 16086690, 23751945, 33011114, 65941325, 28365395, -+ 9137108, 730663, 9835848, 4555336 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 94653405416909, 1386121349852999, 1062130477891762, -+ 36553947479274, 833669648948846 -+#else -+ 43732429, 1410445, 44855111, 20654817, 30867634, 15826977, -+ 17693930, 544696, 55123566, 12422645 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1432015813136298, 440364795295369, 1395647062821501, -+ 1976874522764578, 934452372723352 -+#else -+ 31117226, 21338698, 53606025, 6561946, 57231997, 20796761, -+ 61990178, 29457725, 29120152, 13924425 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1296625309219774, 2068273464883862, 1858621048097805, -+ 1492281814208508, 2235868981918946 -+#else -+ 49707966, 19321222, 19675798, 30819676, 56101901, 27695611, -+ 57724924, 22236731, 7240930, 33317044 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1490330266465570, 1858795661361448, 1436241134969763, -+ 294573218899647, 1208140011028933 -+#else -+ 35747106, 22207651, 52101416, 27698213, 44655523, 21401660, -+ 1222335, 4389483, 3293637, 18002689 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1282462923712748, 741885683986255, 2027754642827561, -+ 518989529541027, 1826610009555945 -+#else -+ 50424044, 19110186, 11038543, 11054958, 53307689, 30215898, -+ 42789283, 7733546, 12796905, 27218610 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1525827120027511, 723686461809551, 1597702369236987, -+ 244802101764964, 1502833890372311 -+#else -+ 58349431, 22736595, 41689999, 10783768, 36493307, 23807620, -+ 38855524, 3647835, 3222231, 22393970 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 113622036244513, 1233740067745854, 674109952278496, -+ 2114345180342965, 166764512856263 -+#else -+ 18606113, 1693100, 41660478, 18384159, 4112352, 10045021, -+ 23603893, 31506198, 59558087, 2484984 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2041668749310338, 2184405322203901, 1633400637611036, -+ 2110682505536899, 2048144390084644 -+#else -+ 9255298, 30423235, 54952701, 32550175, 13098012, 24339566, -+ 16377219, 31451620, 47306788, 30519729 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 503058759232932, 760293024620937, 2027152777219493, -+ 666858468148475, 1539184379870952 -+#else -+ 44379556, 7496159, 61366665, 11329248, 19991973, 30206930, -+ 35390715, 9936965, 37011176, 22935634 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1916168475367211, 915626432541343, 883217071712575, -+ 363427871374304, 1976029821251593 -+#else -+ 21878571, 28553135, 4338335, 13643897, 64071999, 13160959, -+ 19708896, 5415497, 59748361, 29445138 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 678039535434506, 570587290189340, 1605302676614120, -+ 2147762562875701, 1706063797091704 -+#else -+ 27736842, 10103576, 12500508, 8502413, 63695848, 23920873, -+ 10436917, 32004156, 43449720, 25422331 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1439489648586438, 2194580753290951, 832380563557396, -+ 561521973970522, 584497280718389 -+#else -+ 19492550, 21450067, 37426887, 32701801, 63900692, 12403436, -+ 30066266, 8367329, 13243957, 8709688 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 187989455492609, 681223515948275, 1933493571072456, -+ 1872921007304880, 488162364135671 -+#else -+ 12015105, 2801261, 28198131, 10151021, 24818120, 28811299, -+ 55914672, 27908697, 5150967, 7274186 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1413466089534451, 410844090765630, 1397263346404072, -+ 408227143123410, 1594561803147811 -+#else -+ 2831347, 21062286, 1478974, 6122054, 23825128, 20820846, -+ 31097298, 6083058, 31021603, 23760822 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2102170800973153, 719462588665004, 1479649438510153, -+ 1097529543970028, 1302363283777685 -+#else -+ 64578913, 31324785, 445612, 10720828, 53259337, 22048494, -+ 43601132, 16354464, 15067285, 19406725 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 942065717847195, 1069313679352961, 2007341951411051, -+ 70973416446291, 1419433790163706 -+#else -+ 7840923, 14037873, 33744001, 15934015, 66380651, 29911725, -+ 21403987, 1057586, 47729402, 21151211 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1146565545556377, 1661971299445212, 406681704748893, -+ 564452436406089, 1109109865829139 -+#else -+ 915865, 17085158, 15608284, 24765302, 42751837, 6060029, -+ 49737545, 8410996, 59888403, 16527024 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2214421081775077, 1165671861210569, 1890453018796184, -+ 3556249878661, 442116172656317 -+#else -+ 32922597, 32997445, 20336073, 17369864, 10903704, 28169945, -+ 16957573, 52992, 23834301, 6588044 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 753830546620811, 1666955059895019, 1530775289309243, -+ 1119987029104146, 2164156153857580 -+#else -+ 32752011, 11232950, 3381995, 24839566, 22652987, 22810329, -+ 17159698, 16689107, 46794284, 32248439 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 615171919212796, 1523849404854568, 854560460547503, -+ 2067097370290715, 1765325848586042 -+#else -+ 62419196, 9166775, 41398568, 22707125, 11576751, 12733943, -+ 7924251, 30802151, 1976122, 26305405 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1094538949313667, 1796592198908825, 870221004284388, -+ 2025558921863561, 1699010892802384 -+#else -+ 21251203, 16309901, 64125849, 26771309, 30810596, 12967303, -+ 156041, 30183180, 12331344, 25317235 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1951351290725195, 1916457206844795, 198025184438026, -+ 1909076887557595, 1938542290318919 -+#else -+ 8651595, 29077400, 51023227, 28557437, 13002506, 2950805, -+ 29054427, 28447462, 10008135, 28886531 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1014323197538413, 869150639940606, 1756009942696599, -+ 1334952557375672, 1544945379082874 -+#else -+ 31486061, 15114593, 52847614, 12951353, 14369431, 26166587, -+ 16347320, 19892343, 8684154, 23021480 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 764055910920305, 1603590757375439, 146805246592357, -+ 1843313433854297, 954279890114939 -+#else -+ 19443825, 11385320, 24468943, 23895364, 43189605, 2187568, -+ 40845657, 27467510, 31316347, 14219878 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 80113526615750, 764536758732259, 1055139345100233, -+ 469252651759390, 617897512431515 -+#else -+ 38514374, 1193784, 32245219, 11392485, 31092169, 15722801, -+ 27146014, 6992409, 29126555, 9207390 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 74497112547268, 740094153192149, 1745254631717581, -+ 727713886503130, 1283034364416928 -+#else -+ 32382916, 1110093, 18477781, 11028262, 39697101, 26006320, -+ 62128346, 10843781, 59151264, 19118701 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 525892105991110, 1723776830270342, 1476444848991936, -+ 573789489857760, 133864092632978 -+#else -+ 2814918, 7836403, 27519878, 25686276, 46214848, 22000742, -+ 45614304, 8550129, 28346258, 1994730 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 542611720192581, 1986812262899321, 1162535242465837, -+ 481498966143464, 544600533583622 -+#else -+ 47530565, 8085544, 53108345, 29605809, 2785837, 17323125, -+ 47591912, 7174893, 22628102, 8115180 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 64123227344372, 1239927720647794, 1360722983445904, -+ 222610813654661, 62429487187991 -+#else -+ 36703732, 955510, 55975026, 18476362, 34661776, 20276352, -+ 41457285, 3317159, 57165847, 930271 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1793193323953132, 91096687857833, 70945970938921, -+ 2158587638946380, 1537042406482111 -+#else -+ 51805164, 26720662, 28856489, 1357446, 23421993, 1057177, -+ 24091212, 32165462, 44343487, 22903716 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1895854577604609, 1394895708949416, 1728548428495944, -+ 1140864900240149, 563645333603061 -+#else -+ 44357633, 28250434, 54201256, 20785565, 51297352, 25757378, -+ 52269845, 17000211, 65241845, 8398969 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 141358280486863, 91435889572504, 1087208572552643, -+ 1829599652522921, 1193307020643647 -+#else -+ 35139535, 2106402, 62372504, 1362500, 12813763, 16200670, -+ 22981545, 27263159, 18009407, 17781660 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1611230858525381, 950720175540785, 499589887488610, -+ 2001656988495019, 88977313255908 -+#else -+ 49887941, 24009210, 39324209, 14166834, 29815394, 7444469, -+ 29551787, 29827013, 19288548, 1325865 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1189080501479658, 2184348804772597, 1040818725742319, -+ 2018318290311834, 1712060030915354 -+#else -+ 15100138, 17718680, 43184885, 32549333, 40658671, 15509407, -+ 12376730, 30075286, 33166106, 25511682 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 873966876953756, 1090638350350440, 1708559325189137, -+ 672344594801910, 1320437969700239 -+#else -+ 20909212, 13023121, 57899112, 16251777, 61330449, 25459517, -+ 12412150, 10018715, 2213263, 19676059 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1508590048271766, 1131769479776094, 101550868699323, -+ 428297785557897, 561791648661744 -+#else -+ 32529814, 22479743, 30361438, 16864679, 57972923, 1513225, -+ 22922121, 6382134, 61341936, 8371347 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 756417570499462, 237882279232602, 2136263418594016, -+ 1701968045454886, 703713185137472 -+#else -+ 9923462, 11271500, 12616794, 3544722, 37110496, 31832805, -+ 12891686, 25361300, 40665920, 10486143 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1781187809325462, 1697624151492346, 1381393690939988, -+ 175194132284669, 1483054666415238 -+#else -+ 44511638, 26541766, 8587002, 25296571, 4084308, 20584370, -+ 361725, 2610596, 43187334, 22099236 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2175517777364616, 708781536456029, 955668231122942, -+ 1967557500069555, 2021208005604118 -+#else -+ 5408392, 32417741, 62139741, 10561667, 24145918, 14240566, -+ 31319731, 29318891, 19985174, 30118346 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1115135966606887, 224217372950782, 915967306279222, -+ 593866251291540, 561747094208006 -+#else -+ 53114407, 16616820, 14549246, 3341099, 32155958, 13648976, -+ 49531796, 8849296, 65030, 8370684 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1443163092879439, 391875531646162, 2180847134654632, -+ 464538543018753, 1594098196837178 -+#else -+ 58787919, 21504805, 31204562, 5839400, 46481576, 32497154, -+ 47665921, 6922163, 12743482, 23753914 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 850858855888869, 319436476624586, 327807784938441, -+ 740785849558761, 17128415486016 -+#else -+ 64747493, 12678784, 28815050, 4759974, 43215817, 4884716, -+ 23783145, 11038569, 18800704, 255233 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2132756334090067, 536247820155645, 48907151276867, -+ 608473197600695, 1261689545022784 -+#else -+ 61839187, 31780545, 13957885, 7990715, 23132995, 728773, -+ 13393847, 9066957, 19258688, 18800639 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1525176236978354, 974205476721062, 293436255662638, -+ 148269621098039, 137961998433963 -+#else -+ 64172210, 22726896, 56676774, 14516792, 63468078, 4372540, -+ 35173943, 2209389, 65584811, 2055793 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1121075518299410, 2071745529082111, 1265567917414828, -+ 1648196578317805, 496232102750820 -+#else -+ 580882, 16705327, 5468415, 30871414, 36182444, 18858431, -+ 59905517, 24560042, 37087844, 7394434 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 122321229299801, 1022922077493685, 2001275453369484, -+ 2017441881607947, 993205880778002 -+#else -+ 23838809, 1822728, 51370421, 15242726, 8318092, 29821328, -+ 45436683, 30062226, 62287122, 14799920 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 654925550560074, 1168810995576858, 575655959430926, -+ 905758704861388, 496774564663534 -+#else -+ 13345610, 9759151, 3371034, 17416641, 16353038, 8577942, -+ 31129804, 13496856, 58052846, 7402517 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1954109525779738, 2117022646152485, 338102630417180, -+ 1194140505732026, 107881734943492 -+#else -+ 2286874, 29118501, 47066405, 31546095, 53412636, 5038121, -+ 11006906, 17794080, 8205060, 1607563 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1714785840001267, 2036500018681589, 1876380234251966, -+ 2056717182974196, 1645855254384642 -+#else -+ 14414067, 25552300, 3331829, 30346215, 22249150, 27960244, -+ 18364660, 30647474, 30019586, 24525154 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 106431476499341, 62482972120563, 1513446655109411, -+ 807258751769522, 538491469114 -+#else -+ 39420813, 1585952, 56333811, 931068, 37988643, 22552112, -+ 52698034, 12029092, 9944378, 8024 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2002850762893643, 1243624520538135, 1486040410574605, -+ 2184752338181213, 378495998083531 -+#else -+ 4368715, 29844802, 29874199, 18531449, 46878477, 22143727, -+ 50994269, 32555346, 58966475, 5640029 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 922510868424903, 1089502620807680, 402544072617374, -+ 1131446598479839, 1290278588136533 -+#else -+ 10299591, 13746483, 11661824, 16234854, 7630238, 5998374, -+ 9809887, 16859868, 15219797, 19226649 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1867998812076769, 715425053580701, 39968586461416, -+ 2173068014586163, 653822651801304 -+#else -+ 27425505, 27835351, 3055005, 10660664, 23458024, 595578, -+ 51710259, 32381236, 48766680, 9742716 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 162892278589453, 182585796682149, 75093073137630, -+ 497037941226502, 133871727117371 -+#else -+ 6744077, 2427284, 26042789, 2720740, 66260958, 1118973, -+ 32324614, 7406442, 12420155, 1994844 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1914596576579670, 1608999621851578, 1987629837704609, -+ 1519655314857977, 1819193753409464 -+#else -+ 14012502, 28529712, 48724410, 23975962, 40623521, 29617992, -+ 54075385, 22644628, 24319928, 27108099 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1949315551096831, 1069003344994464, 1939165033499916, -+ 1548227205730856, 1933767655861407 -+#else -+ 16412671, 29047065, 10772640, 15929391, 50040076, 28895810, -+ 10555944, 23070383, 37006495, 28815383 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1730519386931635, 1393284965610134, 1597143735726030, -+ 416032382447158, 1429665248828629 -+#else -+ 22397363, 25786748, 57815702, 20761563, 17166286, 23799296, -+ 39775798, 6199365, 21880021, 21303672 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 360275475604565, 547835731063078, 215360904187529, -+ 596646739879007, 332709650425085 -+#else -+ 62825557, 5368522, 35991846, 8163388, 36785801, 3209127, -+ 16557151, 8890729, 8840445, 4957760 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 47602113726801, 1522314509708010, 437706261372925, -+ 814035330438027, 335930650933545 -+#else -+ 51661137, 709326, 60189418, 22684253, 37330941, 6522331, -+ 45388683, 12130071, 52312361, 5005756 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1291597595523886, 1058020588994081, 402837842324045, -+ 1363323695882781, 2105763393033193 -+#else -+ 64994094, 19246303, 23019041, 15765735, 41839181, 6002751, -+ 10183197, 20315106, 50713577, 31378319 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 109521982566564, 1715257748585139, 1112231216891516, -+ 2046641005101484, 134249157157013 -+#else -+ 48083108, 1632004, 13466291, 25559332, 43468412, 16573536, -+ 35094956, 30497327, 22208661, 2000468 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2156991030936798, 2227544497153325, 1869050094431622, -+ 754875860479115, 1754242344267058 -+#else -+ 3065054, 32141671, 41510189, 33192999, 49425798, 27851016, -+ 58944651, 11248526, 63417650, 26140247 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1846089562873800, 98894784984326, 1412430299204844, -+ 171351226625762, 1100604760929008 -+#else -+ 10379208, 27508878, 8877318, 1473647, 37817580, 21046851, -+ 16690914, 2553332, 63976176, 16400288 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 84172382130492, 499710970700046, 425749630620778, -+ 1762872794206857, 612842602127960 -+#else -+ 15716668, 1254266, 48636174, 7446273, 58659946, 6344163, -+ 45011593, 26268851, 26894936, 9132066 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 868309334532756, 1703010512741873, 1952690008738057, -+ 4325269926064, 2071083554962116 -+#else -+ 24158868, 12938817, 11085297, 25376834, 39045385, 29097348, -+ 36532400, 64451, 60291780, 30861549 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 523094549451158, 401938899487815, 1407690589076010, -+ 2022387426254453, 158660516411257 -+#else -+ 13488534, 7794716, 22236231, 5989356, 25426474, 20976224, -+ 2350709, 30135921, 62420857, 2364225 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 612867287630009, 448212612103814, 571629077419196, -+ 1466796750919376, 1728478129663858 -+#else -+ 16335033, 9132434, 25640582, 6678888, 1725628, 8517937, -+ 55301840, 21856974, 15445874, 25756331 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1723848973783452, 2208822520534681, 1718748322776940, -+ 1974268454121942, 1194212502258141 -+#else -+ 29004188, 25687351, 28661401, 32914020, 54314860, 25611345, -+ 31863254, 29418892, 66830813, 17795152 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1254114807944608, 977770684047110, 2010756238954993, -+ 1783628927194099, 1525962994408256 -+#else -+ 60986784, 18687766, 38493958, 14569918, 56250865, 29962602, -+ 10343411, 26578142, 37280576, 22738620 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 232464058235826, 1948628555342434, 1835348780427694, -+ 1031609499437291, 64472106918373 -+#else -+ 27081650, 3463984, 14099042, 29036828, 1616302, 27348828, -+ 29542635, 15372179, 17293797, 960709 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 767338676040683, 754089548318405, 1523192045639075, -+ 435746025122062, 512692508440385 -+#else -+ 20263915, 11434237, 61343429, 11236809, 13505955, 22697330, -+ 50997518, 6493121, 47724353, 7639713 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1255955808701983, 1700487367990941, 1166401238800299, -+ 1175121994891534, 1190934801395380 -+#else -+ 64278047, 18715199, 25403037, 25339236, 58791851, 17380732, -+ 18006286, 17510682, 29994676, 17746311 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 349144008168292, 1337012557669162, 1475912332999108, -+ 1321618454900458, 47611291904320 -+#else -+ 9769828, 5202651, 42951466, 19923039, 39057860, 21992807, -+ 42495722, 19693649, 35924288, 709463 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 877519947135419, 2172838026132651, 272304391224129, -+ 1655143327559984, 886229406429814 -+#else -+ 12286395, 13076066, 45333675, 32377809, 42105665, 4057651, -+ 35090736, 24663557, 16102006, 13205847 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 375806028254706, 214463229793940, 572906353144089, -+ 572168269875638, 697556386112979 -+#else -+ 13733362, 5599946, 10557076, 3195751, 61550873, 8536969, -+ 41568694, 8525971, 10151379, 10394400 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1168827102357844, 823864273033637, 2071538752104697, -+ 788062026895924, 599578340743362 -+#else -+ 4024660, 17416881, 22436261, 12276534, 58009849, 30868332, -+ 19698228, 11743039, 33806530, 8934413 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1948116082078088, 2054898304487796, 2204939184983900, -+ 210526805152138, 786593586607626 -+#else -+ 51229064, 29029191, 58528116, 30620370, 14634844, 32856154, -+ 57659786, 3137093, 55571978, 11721157 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1915320147894736, 156481169009469, 655050471180417, -+ 592917090415421, 2165897438660879 -+#else -+ 17555920, 28540494, 8268605, 2331751, 44370049, 9761012, -+ 9319229, 8835153, 57903375, 32274386 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1726336468579724, 1119932070398949, 1929199510967666, -+ 33918788322959, 1836837863503150 -+#else -+ 66647436, 25724417, 20614117, 16688288, 59594098, 28747312, -+ 22300303, 505429, 6108462, 27371017 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 829996854845988, 217061778005138, 1686565909803640, -+ 1346948817219846, 1723823550730181 -+#else -+ 62038564, 12367916, 36445330, 3234472, 32617080, 25131790, -+ 29880582, 20071101, 40210373, 25686972 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 384301494966394, 687038900403062, 2211195391021739, -+ 254684538421383, 1245698430589680 -+#else -+ 35133562, 5726538, 26934134, 10237677, 63935147, 32949378, -+ 24199303, 3795095, 7592688, 18562353 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1247567493562688, 1978182094455847, 183871474792955, -+ 806570235643435, 288461518067916 -+#else -+ 21594432, 18590204, 17466407, 29477210, 32537083, 2739898, -+ 6407723, 12018833, 38852812, 4298411 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1449077384734201, 38285445457996, 2136537659177832, -+ 2146493000841573, 725161151123125 -+#else -+ 46458361, 21592935, 39872588, 570497, 3767144, 31836892, -+ 13891941, 31985238, 13717173, 10805743 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1201928866368855, 800415690605445, 1703146756828343, -+ 997278587541744, 1858284414104014 -+#else -+ 52432215, 17910135, 15287173, 11927123, 24177847, 25378864, -+ 66312432, 14860608, 40169934, 27690595 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 356468809648877, 782373916933152, 1718002439402870, -+ 1392222252219254, 663171266061951 -+#else -+ 12962541, 5311799, 57048096, 11658279, 18855286, 25600231, -+ 13286262, 20745728, 62727807, 9882021 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 759628738230460, 1012693474275852, 353780233086498, -+ 246080061387552, 2030378857679162 -+#else -+ 18512060, 11319350, 46985740, 15090308, 18818594, 5271736, -+ 44380960, 3666878, 43141434, 30255002 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2040672435071076, 888593182036908, 1298443657189359, -+ 1804780278521327, 354070726137060 -+#else -+ 60319844, 30408388, 16192428, 13241070, 15898607, 19348318, -+ 57023983, 26893321, 64705764, 5276064 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1894938527423184, 1463213041477277, 474410505497651, -+ 247294963033299, 877975941029128 -+#else -+ 30169808, 28236784, 26306205, 21803573, 27814963, 7069267, -+ 7152851, 3684982, 1449224, 13082861 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 207937160991127, 12966911039119, 820997788283092, -+ 1010440472205286, 1701372890140810 -+#else -+ 10342807, 3098505, 2119311, 193222, 25702612, 12233820, -+ 23697382, 15056736, 46092426, 25352431 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 218882774543183, 533427444716285, 1233243976733245, -+ 435054256891319, 1509568989549904 -+#else -+ 33958735, 3261607, 22745853, 7948688, 19370557, 18376767, -+ 40936887, 6482813, 56808784, 22494330 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1888838535711826, 1052177758340622, 1213553803324135, -+ 169182009127332, 463374268115872 -+#else -+ 32869458, 28145887, 25609742, 15678670, 56421095, 18083360, -+ 26112420, 2521008, 44444576, 6904814 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 299137589460312, 1594371588983567, 868058494039073, -+ 257771590636681, 1805012993142921 -+#else -+ 29506904, 4457497, 3377935, 23757988, 36598817, 12935079, -+ 1561737, 3841096, 38105225, 26896789 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1806842755664364, 2098896946025095, 1356630998422878, -+ 1458279806348064, 347755825962072 -+#else -+ 10340844, 26924055, 48452231, 31276001, 12621150, 20215377, -+ 30878496, 21730062, 41524312, 5181965 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1402334161391744, 1560083671046299, 1008585416617747, -+ 1147797150908892, 1420416683642459 -+#else -+ 25940096, 20896407, 17324187, 23247058, 58437395, 15029093, -+ 24396252, 17103510, 64786011, 21165857 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 665506704253369, 273770475169863, 799236974202630, -+ 848328990077558, 1811448782807931 -+#else -+ 45343161, 9916822, 65808455, 4079497, 66080518, 11909558, -+ 1782390, 12641087, 20603771, 26992690 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1468412523962641, 771866649897997, 1931766110147832, -+ 799561180078482, 524837559150077 -+#else -+ 48226577, 21881051, 24849421, 11501709, 13161720, 28785558, -+ 1925522, 11914390, 4662781, 7820689 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2223212657821850, 630416247363666, 2144451165500328, -+ 816911130947791, 1024351058410032 -+#else -+ 12241050, 33128450, 8132690, 9393934, 32846760, 31954812, -+ 29749455, 12172924, 16136752, 15264020 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1266603897524861, 156378408858100, 1275649024228779, -+ 447738405888420, 253186462063095 -+#else -+ 56758909, 18873868, 58896884, 2330219, 49446315, 19008651, -+ 10658212, 6671822, 19012087, 3772772 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2022215964509735, 136144366993649, 1800716593296582, -+ 1193970603800203, 871675847064218 -+#else -+ 3753511, 30133366, 10617073, 2028709, 14841030, 26832768, -+ 28718731, 17791548, 20527770, 12988982 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1862751661970328, 851596246739884, 1519315554814041, -+ 1542798466547449, 1417975335901520 -+#else -+ 52286360, 27757162, 63400876, 12689772, 66209881, 22639565, -+ 42925817, 22989488, 3299664, 21129479 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1228168094547481, 334133883362894, 587567568420081, -+ 433612590281181, 603390400373205 -+#else -+ 50331161, 18301130, 57466446, 4978982, 3308785, 8755439, -+ 6943197, 6461331, 41525717, 8991217 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 121893973206505, 1843345804916664, 1703118377384911, -+ 497810164760654, 101150811654673 -+#else -+ 49882601, 1816361, 65435576, 27467992, 31783887, 25378441, -+ 34160718, 7417949, 36866577, 1507264 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 458346255946468, 290909935619344, 1452768413850679, -+ 550922875254215, 1537286854336538 -+#else -+ 29692644, 6829891, 56610064, 4334895, 20945975, 21647936, -+ 38221255, 8209390, 14606362, 22907359 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 584322311184395, 380661238802118, 114839394528060, -+ 655082270500073, 2111856026034852 -+#else -+ 63627275, 8707080, 32188102, 5672294, 22096700, 1711240, -+ 34088169, 9761486, 4170404, 31469107 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 996965581008991, 2148998626477022, 1012273164934654, -+ 1073876063914522, 1688031788934939 -+#else -+ 55521375, 14855944, 62981086, 32022574, 40459774, 15084045, -+ 22186522, 16002000, 52832027, 25153633 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 923487018849600, 2085106799623355, 528082801620136, -+ 1606206360876188, 735907091712524 -+#else -+ 62297408, 13761028, 35404987, 31070512, 63796392, 7869046, -+ 59995292, 23934339, 13240844, 10965870 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1697697887804317, 1335343703828273, 831288615207040, -+ 949416685250051, 288760277392022 -+#else -+ 59366301, 25297669, 52340529, 19898171, 43876480, 12387165, -+ 4498947, 14147411, 29514390, 4302863 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1419122478109648, 1325574567803701, 602393874111094, -+ 2107893372601700, 1314159682671307 -+#else -+ 53695440, 21146572, 20757301, 19752600, 14785142, 8976368, -+ 62047588, 31410058, 17846987, 19582505 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2201150872731804, 2180241023425241, 97663456423163, -+ 1633405770247824, 848945042443986 -+#else -+ 64864412, 32799703, 62511833, 32488122, 60861691, 1455298, -+ 45461136, 24339642, 61886162, 12650266 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1173339555550611, 818605084277583, 47521504364289, -+ 924108720564965, 735423405754506 -+#else -+ 57202067, 17484121, 21134159, 12198166, 40044289, 708125, -+ 387813, 13770293, 47974538, 10958662 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 830104860549448, 1886653193241086, 1600929509383773, -+ 1475051275443631, 286679780900937 -+#else -+ 22470984, 12369526, 23446014, 28113323, 45588061, 23855708, -+ 55336367, 21979976, 42025033, 4271861 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1577111294832995, 1030899169768747, 144900916293530, -+ 1964672592979567, 568390100955250 -+#else -+ 41939299, 23500789, 47199531, 15361594, 61124506, 2159191, -+ 75375, 29275903, 34582642, 8469672 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 278388655910247, 487143369099838, 927762205508727, -+ 181017540174210, 1616886700741287 -+#else -+ 15854951, 4148314, 58214974, 7259001, 11666551, 13824734, -+ 36577666, 2697371, 24154791, 24093489 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1191033906638969, 940823957346562, 1606870843663445, -+ 861684761499847, 658674867251089 -+#else -+ 15446137, 17747788, 29759746, 14019369, 30811221, 23944241, -+ 35526855, 12840103, 24913809, 9815020 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1875032594195546, 1427106132796197, 724736390962158, -+ 901860512044740, 635268497268760 -+#else -+ 62399578, 27940162, 35267365, 21265538, 52665326, 10799413, -+ 58005188, 13438768, 18735128, 9466238 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 622869792298357, 1903919278950367, 1922588621661629, -+ 1520574711600434, 1087100760174640 -+#else -+ 11933045, 9281483, 5081055, 28370608, 64480701, 28648802, -+ 59381042, 22658328, 44380208, 16199063 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 25465949416618, 1693639527318811, 1526153382657203, -+ 125943137857169, 145276964043999 -+#else -+ 14576810, 379472, 40322331, 25237195, 37682355, 22741457, -+ 67006097, 1876698, 30801119, 2164795 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 214739857969358, 920212862967915, 1939901550972269, -+ 1211862791775221, 85097515720120 -+#else -+ 15995086, 3199873, 13672555, 13712240, 47730029, 28906785, -+ 54027253, 18058162, 53616056, 1268051 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2006245852772938, 734762734836159, 254642929763427, -+ 1406213292755966, 239303749517686 -+#else -+ 56818250, 29895392, 63822271, 10948817, 23037027, 3794475, -+ 63638526, 20954210, 50053494, 3565903 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1619678837192149, 1919424032779215, 1357391272956794, -+ 1525634040073113, 1310226789796241 -+#else -+ 29210069, 24135095, 61189071, 28601646, 10834810, 20226706, -+ 50596761, 22733718, 39946641, 19523900 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1040763709762123, 1704449869235352, 605263070456329, -+ 1998838089036355, 1312142911487502 -+#else -+ 53946955, 15508587, 16663704, 25398282, 38758921, 9019122, -+ 37925443, 29785008, 2244110, 19552453 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1996723311435669, 1844342766567060, 985455700466044, -+ 1165924681400960, 311508689870129 -+#else -+ 61955989, 29753495, 57802388, 27482848, 16243068, 14684434, -+ 41435776, 17373631, 13491505, 4641841 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 43173156290518, 2202883069785309, 1137787467085917, -+ 1733636061944606, 1394992037553852 -+#else -+ 10813398, 643330, 47920349, 32825515, 30292061, 16954354, -+ 27548446, 25833190, 14476988, 20787001 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 670078326344559, 555655025059356, 471959386282438, -+ 2141455487356409, 849015953823125 -+#else -+ 10292079, 9984945, 6481436, 8279905, 59857350, 7032742, -+ 27282937, 31910173, 39196053, 12651323 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2197214573372804, 794254097241315, 1030190060513737, -+ 267632515541902, 2040478049202624 -+#else -+ 35923332, 32741048, 22271203, 11835308, 10201545, 15351028, -+ 17099662, 3988035, 21721536, 30405492 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1812516004670529, 1609256702920783, 1706897079364493, -+ 258549904773295, 996051247540686 -+#else -+ 10202177, 27008593, 35735631, 23979793, 34958221, 25434748, -+ 54202543, 3852693, 13216206, 14842320 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1540374301420584, 1764656898914615, 1810104162020396, -+ 923808779163088, 664390074196579 -+#else -+ 51293224, 22953365, 60569911, 26295436, 60124204, 26972653, -+ 35608016, 13765823, 39674467, 9900183 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1323460699404750, 1262690757880991, 871777133477900, -+ 1060078894988977, 1712236889662886 -+#else -+ 14465486, 19721101, 34974879, 18815558, 39665676, 12990491, -+ 33046193, 15796406, 60056998, 25514317 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1696163952057966, 1391710137550823, 608793846867416, -+ 1034391509472039, 1780770894075012 -+#else -+ 30924398, 25274812, 6359015, 20738097, 16508376, 9071735, -+ 41620263, 15413634, 9524356, 26535554 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1367603834210841, 2131988646583224, 890353773628144, -+ 1908908219165595, 270836895252891 -+#else -+ 12274201, 20378885, 32627640, 31769106, 6736624, 13267305, -+ 5237659, 28444949, 15663515, 4035784 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 597536315471731, 40375058742586, 1942256403956049, -+ 1185484645495932, 312666282024145 -+#else -+ 64157555, 8903984, 17349946, 601635, 50676049, 28941875, -+ 53376124, 17665097, 44850385, 4659090 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1919411405316294, 1234508526402192, 1066863051997083, -+ 1008444703737597, 1348810787701552 -+#else -+ 50192582, 28601458, 36715152, 18395610, 20774811, 15897498, -+ 5736189, 15026997, 64930608, 20098846 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2102881477513865, 1570274565945361, 1573617900503708, -+ 18662635732583, 2232324307922098 -+#else -+ 58249865, 31335375, 28571665, 23398914, 66634396, 23448733, -+ 63307367, 278094, 23440562, 33264224 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1853931367696942, 8107973870707, 350214504129299, -+ 775206934582587, 1752317649166792 -+#else -+ 10226222, 27625730, 15139955, 120818, 52241171, 5218602, -+ 32937275, 11551483, 50536904, 26111567 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1417148368003523, 721357181628282, 505725498207811, -+ 373232277872983, 261634707184480 -+#else -+ 17932739, 21117156, 43069306, 10749059, 11316803, 7535897, -+ 22503767, 5561594, 63462240, 3898660 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2186733281493267, 2250694917008620, 1014829812957440, -+ 479998161452389, 83566193876474 -+#else -+ 7749907, 32584865, 50769132, 33537967, 42090752, 15122142, -+ 65535333, 7152529, 21831162, 1245233 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1268116367301224, 560157088142809, 802626839600444, -+ 2210189936605713, 1129993785579988 -+#else -+ 26958440, 18896406, 4314585, 8346991, 61431100, 11960071, -+ 34519569, 32934396, 36706772, 16838219 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 615183387352312, 917611676109240, 878893615973325, -+ 978940963313282, 938686890583575 -+#else -+ 54942968, 9166946, 33491384, 13673479, 29787085, 13096535, -+ 6280834, 14587357, 44770839, 13987524 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 522024729211672, 1045059315315808, 1892245413707790, -+ 1907891107684253, 2059998109500714 -+#else -+ 42758936, 7778774, 21116000, 15572597, 62275598, 28196653, -+ 62807965, 28429792, 59639082, 30696363 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1799679152208884, 912132775900387, 25967768040979, -+ 432130448590461, 274568990261996 -+#else -+ 9681908, 26817309, 35157219, 13591837, 60225043, 386949, -+ 31622781, 6439245, 52527852, 4091396 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 98698809797682, 2144627600856209, 1907959298569602, -+ 811491302610148, 1262481774981493 -+#else -+ 58682418, 1470726, 38999185, 31957441, 3978626, 28430809, -+ 47486180, 12092162, 29077877, 18812444 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1791451399743152, 1713538728337276, 118349997257490, -+ 1882306388849954, 158235232210248 -+#else -+ 5269168, 26694706, 53878652, 25533716, 25932562, 1763552, -+ 61502754, 28048550, 47091016, 2357888 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1217809823321928, 2173947284933160, 1986927836272325, -+ 1388114931125539, 12686131160169 -+#else -+ 32264008, 18146780, 61721128, 32394338, 65017541, 29607531, -+ 23104803, 20684524, 5727337, 189038 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1650875518872272, 1136263858253897, 1732115601395988, -+ 734312880662190, 1252904681142109 -+#else -+ 14609104, 24599962, 61108297, 16931650, 52531476, 25810533, -+ 40363694, 10942114, 41219933, 18669734 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 372986456113865, 525430915458171, 2116279931702135, -+ 501422713587815, 1907002872974925 -+#else -+ 20513481, 5557931, 51504251, 7829530, 26413943, 31535028, -+ 45729895, 7471780, 13913677, 28416557 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 803147181835288, 868941437997146, 316299302989663, -+ 943495589630550, 571224287904572 -+#else -+ 41534488, 11967825, 29233242, 12948236, 60354399, 4713226, -+ 58167894, 14059179, 12878652, 8511905 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 227742695588364, 1776969298667369, 628602552821802, -+ 457210915378118, 2041906378111140 -+#else -+ 41452044, 3393630, 64153449, 26478905, 64858154, 9366907, -+ 36885446, 6812973, 5568676, 30426776 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 815000523470260, 913085688728307, 1052060118271173, -+ 1345536665214223, 541623413135555 -+#else -+ 11630004, 12144454, 2116339, 13606037, 27378885, 15676917, -+ 49700111, 20050058, 52713667, 8070817 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1580216071604333, 1877997504342444, 857147161260913, -+ 703522726778478, 2182763974211603 -+#else -+ 27117677, 23547054, 35826092, 27984343, 1127281, 12772488, -+ 37262958, 10483305, 55556115, 32525717 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1870080310923419, 71988220958492, 1783225432016732, -+ 615915287105016, 1035570475990230 -+#else -+ 10637467, 27866368, 5674780, 1072708, 40765276, 26572129, -+ 65424888, 9177852, 39615702, 15431202 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 730987750830150, 857613889540280, 1083813157271766, -+ 1002817255970169, 1719228484436074 -+#else -+ 20525126, 10892566, 54366392, 12779442, 37615830, 16150074, -+ 38868345, 14943141, 52052074, 25618500 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 377616581647602, 1581980403078513, 804044118130621, -+ 2034382823044191, 643844048472185 -+#else -+ 37084402, 5626925, 66557297, 23573344, 753597, 11981191, -+ 25244767, 30314666, 63752313, 9594023 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 176957326463017, 1573744060478586, 528642225008045, -+ 1816109618372371, 1515140189765006 -+#else -+ 43356201, 2636869, 61944954, 23450613, 585133, 7877383, -+ 11345683, 27062142, 13352334, 22577348 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1888911448245718, 1387110895611080, 1924503794066429, -+ 1731539523700949, 2230378382645454 -+#else -+ 65177046, 28146973, 3304648, 20669563, 17015805, 28677341, -+ 37325013, 25801949, 53893326, 33235227 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 443392177002051, 233793396845137, 2199506622312416, -+ 1011858706515937, 974676837063129 -+#else -+ 20239939, 6607058, 6203985, 3483793, 48721888, 32775202, -+ 46385121, 15077869, 44358105, 14523816 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1846351103143623, 1949984838808427, 671247021915253, -+ 1946756846184401, 1929296930380217 -+#else -+ 27406023, 27512775, 27423595, 29057038, 4996213, 10002360, -+ 38266833, 29008937, 36936121, 28748764 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 849646212452002, 1410198775302919, 73767886183695, -+ 1641663456615812, 762256272452411 -+#else -+ 11374242, 12660715, 17861383, 21013599, 10935567, 1099227, -+ 53222788, 24462691, 39381819, 11358503 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 692017667358279, 723305578826727, 1638042139863265, -+ 748219305990306, 334589200523901 -+#else -+ 54378055, 10311866, 1510375, 10778093, 64989409, 24408729, -+ 32676002, 11149336, 40985213, 4985767 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 22893968530686, 2235758574399251, 1661465835630252, -+ 925707319443452, 1203475116966621 -+#else -+ 48012542, 341146, 60911379, 33315398, 15756972, 24757770, -+ 66125820, 13794113, 47694557, 17933176 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 801299035785166, 1733292596726131, 1664508947088596, -+ 467749120991922, 1647498584535623 -+#else -+ 6490062, 11940286, 25495923, 25828072, 8668372, 24803116, -+ 3367602, 6970005, 65417799, 24549641 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 903105258014366, 427141894933047, 561187017169777, -+ 1884330244401954, 1914145708422219 -+#else -+ 1656478, 13457317, 15370807, 6364910, 13605745, 8362338, -+ 47934242, 28078708, 50312267, 28522993 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1344191060517578, 1960935031767890, 1518838929955259, -+ 1781502350597190, 1564784025565682 -+#else -+ 44835530, 20030007, 67044178, 29220208, 48503227, 22632463, -+ 46537798, 26546453, 67009010, 23317098 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 673723351748086, 1979969272514923, 1175287312495508, -+ 1187589090978666, 1881897672213940 -+#else -+ 17747446, 10039260, 19368299, 29503841, 46478228, 17513145, -+ 31992682, 17696456, 37848500, 28042460 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1917185587363432, 1098342571752737, 5935801044414, -+ 2000527662351839, 1538640296181569 -+#else -+ 31932008, 28568291, 47496481, 16366579, 22023614, 88450, -+ 11371999, 29810185, 4882241, 22927527 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2495540013192, 678856913479236, 224998292422872, -+ 219635787698590, 1972465269000940 -+#else -+ 29796488, 37186, 19818052, 10115756, 55279832, 3352735, -+ 18551198, 3272828, 61917932, 29392022 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 271413961212179, 1353052061471651, 344711291283483, -+ 2014925838520662, 2006221033113941 -+#else -+ 12501267, 4044383, 58495907, 20162046, 34678811, 5136598, -+ 47878486, 30024734, 330069, 29895023 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 194583029968109, 514316781467765, 829677956235672, -+ 1676415686873082, 810104584395840 -+#else -+ 6384877, 2899513, 17807477, 7663917, 64749976, 12363164, -+ 25366522, 24980540, 66837568, 12071498 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1980510813313589, 1948645276483975, 152063780665900, -+ 129968026417582, 256984195613935 -+#else -+ 58743349, 29511910, 25133447, 29037077, 60897836, 2265926, -+ 34339246, 1936674, 61949167, 3829362 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1860190562533102, 1936576191345085, 461100292705964, -+ 1811043097042830, 957486749306835 -+#else -+ 28425966, 27718999, 66531773, 28857233, 52891308, 6870929, -+ 7921550, 26986645, 26333139, 14267664 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 796664815624365, 1543160838872951, 1500897791837765, -+ 1667315977988401, 599303877030711 -+#else -+ 56041645, 11871230, 27385719, 22994888, 62522949, 22365119, -+ 10004785, 24844944, 45347639, 8930323 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1151480509533204, 2136010406720455, 738796060240027, -+ 319298003765044, 1150614464349587 -+#else -+ 45911060, 17158396, 25654215, 31829035, 12282011, 11008919, -+ 1541940, 4757911, 40617363, 17145491 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1731069268103150, 735642447616087, 1364750481334268, -+ 417232839982871, 927108269127661 -+#else -+ 13537262, 25794942, 46504023, 10961926, 61186044, 20336366, -+ 53952279, 6217253, 51165165, 13814989 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1017222050227968, 1987716148359, 2234319589635701, -+ 621282683093392, 2132553131763026 -+#else -+ 49686272, 15157789, 18705543, 29619, 24409717, 33293956, -+ 27361680, 9257833, 65152338, 31777517 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1567828528453324, 1017807205202360, 565295260895298, -+ 829541698429100, 307243822276582 -+#else -+ 42063564, 23362465, 15366584, 15166509, 54003778, 8423555, -+ 37937324, 12361134, 48422886, 4578289 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 249079270936248, 1501514259790706, 947909724204848, -+ 944551802437487, 552658763982480 -+#else -+ 24579768, 3711570, 1342322, 22374306, 40103728, 14124955, -+ 44564335, 14074918, 21964432, 8235257 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2089966982947227, 1854140343916181, 2151980759220007, -+ 2139781292261749, 158070445864917 -+#else -+ 60580251, 31142934, 9442965, 27628844, 12025639, 32067012, -+ 64127349, 31885225, 13006805, 2355433 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1338766321464554, 1906702607371284, 1519569445519894, -+ 115384726262267, 1393058953390992 -+#else -+ 50803946, 19949172, 60476436, 28412082, 16974358, 22643349, -+ 27202043, 1719366, 1141648, 20758196 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1364621558265400, 1512388234908357, 1926731583198686, -+ 2041482526432505, 920401122333774 -+#else -+ 54244920, 20334445, 58790597, 22536340, 60298718, 28710537, -+ 13475065, 30420460, 32674894, 13715045 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1884844597333588, 601480070269079, 620203503079537, -+ 1079527400117915, 1202076693132015 -+#else -+ 11423316, 28086373, 32344215, 8962751, 24989809, 9241752, -+ 53843611, 16086211, 38367983, 17912338 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 840922919763324, 727955812569642, 1303406629750194, -+ 522898432152867, 294161410441865 -+#else -+ 65699196, 12530727, 60740138, 10847386, 19531186, 19422272, -+ 55399715, 7791793, 39862921, 4383346 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 353760790835310, 1598361541848743, 1122905698202299, -+ 1922533590158905, 419107700666580 -+#else -+ 38137966, 5271446, 65842855, 23817442, 54653627, 16732598, -+ 62246457, 28647982, 27193556, 6245191 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 359856369838236, 180914355488683, 861726472646627, -+ 218807937262986, 575626773232501 -+#else -+ 51914908, 5362277, 65324971, 2695833, 4960227, 12840725, -+ 23061898, 3260492, 22510453, 8577507 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 755467689082474, 909202735047934, 730078068932500, -+ 936309075711518, 2007798262842972 -+#else -+ 54476394, 11257345, 34415870, 13548176, 66387860, 10879010, -+ 31168030, 13952092, 37537372, 29918525 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1609384177904073, 362745185608627, 1335318541768201, -+ 800965770436248, 547877979267412 -+#else -+ 3877321, 23981693, 32416691, 5405324, 56104457, 19897796, -+ 3759768, 11935320, 5611860, 8164018 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 984339177776787, 815727786505884, 1645154585713747, -+ 1659074964378553, 1686601651984156 -+#else -+ 50833043, 14667796, 15906460, 12155291, 44997715, 24514713, -+ 32003001, 24722143, 5773084, 25132323 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1697863093781930, 599794399429786, 1104556219769607, -+ 830560774794755, 12812858601017 -+#else -+ 43320746, 25300131, 1950874, 8937633, 18686727, 16459170, -+ 66203139, 12376319, 31632953, 190926 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1168737550514982, 897832437380552, 463140296333799, -+ 302564600022547, 2008360505135501 -+#else -+ 42515238, 17415546, 58684872, 13378745, 14162407, 6901328, -+ 58820115, 4508563, 41767309, 29926903 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1856930662813910, 678090852002597, 1920179140755167, -+ 1259527833759868, 55540971895511 -+#else -+ 8884438, 27670423, 6023973, 10104341, 60227295, 28612898, -+ 18722940, 18768427, 65436375, 827624 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1158643631044921, 476554103621892, 178447851439725, -+ 1305025542653569, 103433927680625 -+#else -+ 34388281, 17265135, 34605316, 7101209, 13354605, 2659080, -+ 65308289, 19446395, 42230385, 1541285 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2176793111709008, 1576725716350391, 2009350167273523, -+ 2012390194631546, 2125297410909580 -+#else -+ 2901328, 32436745, 3880375, 23495044, 49487923, 29941650, -+ 45306746, 29986950, 20456844, 31669399 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 825403285195098, 2144208587560784, 1925552004644643, -+ 1915177840006985, 1015952128947864 -+#else -+ 27019610, 12299467, 53450576, 31951197, 54247203, 28692960, -+ 47568713, 28538373, 29439640, 15138866 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1807108316634472, 1534392066433717, 347342975407218, -+ 1153820745616376, 7375003497471 -+#else -+ 21536104, 26928012, 34661045, 22864223, 44700786, 5175813, -+ 61688824, 17193268, 7779327, 109896 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 983061001799725, 431211889901241, 2201903782961093, -+ 817393911064341, 2214616493042167 -+#else -+ 30279725, 14648750, 59063993, 6425557, 13639621, 32810923, -+ 28698389, 12180118, 23177719, 33000357 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 228567918409756, 865093958780220, 358083886450556, -+ 159617889659320, 1360637926292598 -+#else -+ 26572828, 3405927, 35407164, 12890904, 47843196, 5335865, -+ 60615096, 2378491, 4439158, 20275085 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 234147501399755, 2229469128637390, 2175289352258889, -+ 1397401514549353, 1885288963089922 -+#else -+ 44392139, 3489069, 57883598, 33221678, 18875721, 32414337, -+ 14819433, 20822905, 49391106, 28092994 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1111762412951562, 252849572507389, 1048714233823341, -+ 146111095601446, 1237505378776770 -+#else -+ 62052362, 16566550, 15953661, 3767752, 56672365, 15627059, -+ 66287910, 2177224, 8550082, 18440267 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1113790697840279, 1051167139966244, 1045930658550944, -+ 2011366241542643, 1686166824620755 -+#else -+ 48635543, 16596774, 66727204, 15663610, 22860960, 15585581, -+ 39264755, 29971692, 43848403, 25125843 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1054097349305049, 1872495070333352, 182121071220717, -+ 1064378906787311, 100273572924182 -+#else -+ 34628313, 15707274, 58902952, 27902350, 29464557, 2713815, -+ 44383727, 15860481, 45206294, 1494192 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1306410853171605, 1627717417672447, 50983221088417, -+ 1109249951172250, 870201789081392 -+#else -+ 47546773, 19467038, 41524991, 24254879, 13127841, 759709, -+ 21923482, 16529112, 8742704, 12967017 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 104233794644221, 1548919791188248, 2224541913267306, -+ 2054909377116478, 1043803389015153 -+#else -+ 38643965, 1553204, 32536856, 23080703, 42417258, 33148257, -+ 58194238, 30620535, 37205105, 15553882 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 216762189468802, 707284285441622, 190678557969733, -+ 973969342604308, 1403009538434867 -+#else -+ 21877890, 3230008, 9881174, 10539357, 62311749, 2841331, -+ 11543572, 14513274, 19375923, 20906471 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1279024291038477, 344776835218310, 273722096017199, -+ 1834200436811442, 634517197663804 -+#else -+ 8832269, 19058947, 13253510, 5137575, 5037871, 4078777, -+ 24880818, 27331716, 2862652, 9455043 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 343805853118335, 1302216857414201, 566872543223541, -+ 2051138939539004, 321428858384280 -+#else -+ 29306751, 5123106, 20245049, 19404543, 9592565, 8447059, -+ 65031740, 30564351, 15511448, 4789663 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 470067171324852, 1618629234173951, 2000092177515639, -+ 7307679772789, 1117521120249968 -+#else -+ 46429108, 7004546, 8824831, 24119455, 63063159, 29803695, -+ 61354101, 108892, 23513200, 16652362 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 278151578291475, 1810282338562947, 1771599529530998, -+ 1383659409671631, 685373414471841 -+#else -+ 33852691, 4144781, 62632835, 26975308, 10770038, 26398890, -+ 60458447, 20618131, 48789665, 10212859 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 577009397403102, 1791440261786291, 2177643735971638, -+ 174546149911960, 1412505077782326 -+#else -+ 2756062, 8598110, 7383731, 26694540, 22312758, 32449420, -+ 21179800, 2600940, 57120566, 21047965 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 893719721537457, 1201282458018197, 1522349501711173, -+ 58011597740583, 1130406465887139 -+#else -+ 42463153, 13317461, 36659605, 17900503, 21365573, 22684775, -+ 11344423, 864440, 64609187, 16844368 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 412607348255453, 1280455764199780, 2233277987330768, -+ 14180080401665, 331584698417165 -+#else -+ 40676061, 6148328, 49924452, 19080277, 18782928, 33278435, -+ 44547329, 211299, 2719757, 4940997 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 262483770854550, 990511055108216, 526885552771698, -+ 571664396646158, 354086190278723 -+#else -+ 65784982, 3911312, 60160120, 14759764, 37081714, 7851206, -+ 21690126, 8518463, 26699843, 5276295 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1820352417585487, 24495617171480, 1547899057533253, -+ 10041836186225, 480457105094042 -+#else -+ 53958991, 27125364, 9396248, 365013, 24703301, 23065493, -+ 1321585, 149635, 51656090, 7159368 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2023310314989233, 637905337525881, 2106474638900687, -+ 557820711084072, 1687858215057826 -+#else -+ 9987761, 30149673, 17507961, 9505530, 9731535, 31388918, -+ 22356008, 8312176, 22477218, 25151047 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1144168702609745, 604444390410187, 1544541121756138, -+ 1925315550126027, 626401428894002 -+#else -+ 18155857, 17049442, 19744715, 9006923, 15154154, 23015456, -+ 24256459, 28689437, 44560690, 9334108 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1922168257351784, 2018674099908659, 1776454117494445, -+ 956539191509034, 36031129147635 -+#else -+ 2986088, 28642539, 10776627, 30080588, 10620589, 26471229, -+ 45695018, 14253544, 44521715, 536905 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 544644538748041, 1039872944430374, 876750409130610, -+ 710657711326551, 1216952687484972 -+#else -+ 4377737, 8115836, 24567078, 15495314, 11625074, 13064599, -+ 7390551, 10589625, 10838060, 18134008 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 58242421545916, 2035812695641843, 2118491866122923, -+ 1191684463816273, 46921517454099 -+#else -+ 47766460, 867879, 9277171, 30335973, 52677291, 31567988, -+ 19295825, 17757482, 6378259, 699185 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 272268252444639, 1374166457774292, 2230115177009552, -+ 1053149803909880, 1354288411641016 -+#else -+ 7895007, 4057113, 60027092, 20476675, 49222032, 33231305, -+ 66392824, 15693154, 62063800, 20180469 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1857910905368338, 1754729879288912, 885945464109877, -+ 1516096106802166, 1602902393369811 -+#else -+ 59371282, 27685029, 52542544, 26147512, 11385653, 13201616, -+ 31730678, 22591592, 63190227, 23885106 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1193437069800958, 901107149704790, 999672920611411, -+ 477584824802207, 364239578697845 -+#else -+ 10188286, 17783598, 59772502, 13427542, 22223443, 14896287, -+ 30743455, 7116568, 45322357, 5427592 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 886299989548838, 1538292895758047, 1590564179491896, -+ 1944527126709657, 837344427345298 -+#else -+ 696102, 13206899, 27047647, 22922350, 15285304, 23701253, -+ 10798489, 28975712, 19236242, 12477404 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 754558365378305, 1712186480903618, 1703656826337531, -+ 750310918489786, 518996040250900 -+#else -+ 55879425, 11243795, 50054594, 25513566, 66320635, 25386464, -+ 63211194, 11180503, 43939348, 7733643 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1309847803895382, 1462151862813074, 211370866671570, -+ 1544595152703681, 1027691798954090 -+#else -+ 17800790, 19518253, 40108434, 21787760, 23887826, 3149671, -+ 23466177, 23016261, 10322026, 15313801 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 803217563745370, 1884799722343599, 1357706345069218, -+ 2244955901722095, 730869460037413 -+#else -+ 26246234, 11968874, 32263343, 28085704, 6830754, 20231401, -+ 51314159, 33452449, 42659621, 10890803 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 689299471295966, 1831210565161071, 1375187341585438, -+ 1106284977546171, 1893781834054269 -+#else -+ 35743198, 10271362, 54448239, 27287163, 16690206, 20491888, -+ 52126651, 16484930, 25180797, 28219548 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 696351368613042, 1494385251239250, 738037133616932, -+ 636385507851544, 927483222611406 -+#else -+ 66522290, 10376443, 34522450, 22268075, 19801892, 10997610, -+ 2276632, 9482883, 316878, 13820577 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1949114198209333, 1104419699537997, 783495707664463, -+ 1747473107602770, 2002634765788641 -+#else -+ 57226037, 29044064, 64993357, 16457135, 56008783, 11674995, -+ 30756178, 26039378, 30696929, 29841583 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1607325776830197, 530883941415333, 1451089452727895, -+ 1581691157083423, 496100432831154 -+#else -+ 32988917, 23951020, 12499365, 7910787, 56491607, 21622917, -+ 59766047, 23569034, 34759346, 7392472 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1068900648804224, 2006891997072550, 1134049269345549, -+ 1638760646180091, 2055396084625778 -+#else -+ 58253184, 15927860, 9866406, 29905021, 64711949, 16898650, -+ 36699387, 24419436, 25112946, 30627788 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2222475519314561, 1870703901472013, 1884051508440561, -+ 1344072275216753, 1318025677799069 -+#else -+ 64604801, 33117465, 25621773, 27875660, 15085041, 28074555, -+ 42223985, 20028237, 5537437, 19640113 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 155711679280656, 681100400509288, 389811735211209, -+ 2135723811340709, 408733211204125 -+#else -+ 55883280, 2320284, 57524584, 10149186, 33664201, 5808647, -+ 52232613, 31824764, 31234589, 6090599 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 7813206966729, 194444201427550, 2071405409526507, -+ 1065605076176312, 1645486789731291 -+#else -+ 57475529, 116425, 26083934, 2897444, 60744427, 30866345, 609720, -+ 15878753, 60138459, 24519663 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 16625790644959, 1647648827778410, 1579910185572704, -+ 436452271048548, 121070048451050 -+#else -+ 39351007, 247743, 51914090, 24551880, 23288160, 23542496, -+ 43239268, 6503645, 20650474, 1804084 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1037263028552531, 568385780377829, 297953104144430, -+ 1558584511931211, 2238221839292471 -+#else -+ 39519059, 15456423, 8972517, 8469608, 15640622, 4439847, -+ 3121995, 23224719, 27842615, 33352104 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 190565267697443, 672855706028058, 338796554369226, -+ 337687268493904, 853246848691734 -+#else -+ 51801891, 2839643, 22530074, 10026331, 4602058, 5048462, -+ 28248656, 5031932, 55733782, 12714368 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1763863028400139, 766498079432444, 1321118624818005, -+ 69494294452268, 858786744165651 -+#else -+ 20807691, 26283607, 29286140, 11421711, 39232341, 19686201, -+ 45881388, 1035545, 47375635, 12796919 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1292056768563024, 1456632109855638, 1100631247050184, -+ 1386133165675321, 1232898350193752 -+#else -+ 12076880, 19253146, 58323862, 21705509, 42096072, 16400683, -+ 49517369, 20654993, 3480664, 18371617 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 366253102478259, 525676242508811, 1449610995265438, -+ 1183300845322183, 185960306491545 -+#else -+ 34747315, 5457596, 28548107, 7833186, 7303070, 21600887, -+ 42745799, 17632556, 33734809, 2771024 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 28315355815982, 460422265558930, 1799675876678724, -+ 1969256312504498, 1051823843138725 -+#else -+ 45719598, 421931, 26597266, 6860826, 22486084, 26817260, -+ 49971378, 29344205, 42556581, 15673396 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 156914999361983, 1606148405719949, 1665208410108430, -+ 317643278692271, 1383783705665320 -+#else -+ 46924223, 2338215, 19788685, 23933476, 63107598, 24813538, -+ 46837679, 4733253, 3727144, 20619984 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 54684536365732, 2210010038536222, 1194984798155308, -+ 535239027773705, 1516355079301361 -+#else -+ 6120100, 814863, 55314462, 32931715, 6812204, 17806661, 2019593, -+ 7975683, 31123697, 22595451 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1484387703771650, 198537510937949, 2186282186359116, -+ 617687444857508, 647477376402122 -+#else -+ 30069250, 22119100, 30434653, 2958439, 18399564, 32578143, -+ 12296868, 9204260, 50676426, 9648164 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2147715541830533, 500032538445817, 646380016884826, -+ 352227855331122, 1488268620408052 -+#else -+ 32705413, 32003455, 30705657, 7451065, 55303258, 9631812, -+ 3305266, 5248604, 41100532, 22176930 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 159386186465542, 1877626593362941, 618737197060512, -+ 1026674284330807, 1158121760792685 -+#else -+ 17219846, 2375039, 35537917, 27978816, 47649184, 9219902, -+ 294711, 15298639, 2662509, 17257359 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1744544377739822, 1964054180355661, 1685781755873170, -+ 2169740670377448, 1286112621104591 -+#else -+ 65935918, 25995736, 62742093, 29266687, 45762450, 25120105, -+ 32087528, 32331655, 32247247, 19164571 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 81977249784993, 1667943117713086, 1668983819634866, -+ 1605016835177615, 1353960708075544 -+#else -+ 14312609, 1221556, 17395390, 24854289, 62163122, 24869796, -+ 38911119, 23916614, 51081240, 20175586 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1602253788689063, 439542044889886, 2220348297664483, -+ 657877410752869, 157451572512238 -+#else -+ 65680039, 23875441, 57873182, 6549686, 59725795, 33085767, -+ 23046501, 9803137, 17597934, 2346211 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1029287186166717, 65860128430192, 525298368814832, -+ 1491902500801986, 1461064796385400 -+#else -+ 18510781, 15337574, 26171504, 981392, 44867312, 7827555, -+ 43617730, 22231079, 3059832, 21771562 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 408216988729246, 2121095722306989, 913562102267595, -+ 1879708920318308, 241061448436731 -+#else -+ 10141598, 6082907, 17829293, 31606789, 9830091, 13613136, -+ 41552228, 28009845, 33606651, 3592095 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1185483484383269, 1356339572588553, 584932367316448, -+ 102132779946470, 1792922621116791 -+#else -+ 33114149, 17665080, 40583177, 20211034, 33076704, 8716171, -+ 1151462, 1521897, 66126199, 26716628 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1966196870701923, 2230044620318636, 1425982460745905, -+ 261167817826569, 46517743394330 -+#else -+ 34169699, 29298616, 23947180, 33230254, 34035889, 21248794, -+ 50471177, 3891703, 26353178, 693168 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 107077591595359, 884959942172345, 27306869797400, -+ 2224911448949390, 964352058245223 -+#else -+ 30374239, 1595580, 50224825, 13186930, 4600344, 406904, 9585294, -+ 33153764, 31375463, 14369965 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1730194207717538, 431790042319772, 1831515233279467, -+ 1372080552768581, 1074513929381760 -+#else -+ 52738210, 25781902, 1510300, 6434173, 48324075, 27291703, -+ 32732229, 20445593, 17901440, 16011505 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1450880638731607, 1019861580989005, 1229729455116861, -+ 1174945729836143, 826083146840706 -+#else -+ 18171223, 21619806, 54608461, 15197121, 56070717, 18324396, -+ 47936623, 17508055, 8764034, 12309598 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1899935429242705, 1602068751520477, 940583196550370, -+ 82431069053859, 1540863155745696 -+#else -+ 5975889, 28311244, 47649501, 23872684, 55567586, 14015781, -+ 43443107, 1228318, 17544096, 22960650 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2136688454840028, 2099509000964294, 1690800495246475, -+ 1217643678575476, 828720645084218 -+#else -+ 5811932, 31839139, 3442886, 31285122, 48741515, 25194890, -+ 49064820, 18144304, 61543482, 12348899 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 765548025667841, 462473984016099, 998061409979798, -+ 546353034089527, 2212508972466858 -+#else -+ 35709185, 11407554, 25755363, 6891399, 63851926, 14872273, -+ 42259511, 8141294, 56476330, 32968952 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 46575283771160, 892570971573071, 1281983193144090, -+ 1491520128287375, 75847005908304 -+#else -+ 54433560, 694025, 62032719, 13300343, 14015258, 19103038, -+ 57410191, 22225381, 30944592, 1130208 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1801436127943107, 1734436817907890, 1268728090345068, -+ 167003097070711, 2233597765834956 -+#else -+ 8247747, 26843490, 40546482, 25845122, 52706924, 18905521, -+ 4652151, 2488540, 23550156, 33283200 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1997562060465113, 1048700225534011, 7615603985628, -+ 1855310849546841, 2242557647635213 -+#else -+ 17294297, 29765994, 7026747, 15626851, 22990044, 113481, -+ 2267737, 27646286, 66700045, 33416712 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1161017320376250, 492624580169043, 2169815802355237, -+ 976496781732542, 1770879511019629 -+#else -+ 16091066, 17300506, 18599251, 7340678, 2137637, 32332775, -+ 63744702, 14550935, 3260525, 26388161 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1357044908364776, 729130645262438, 1762469072918979, -+ 1365633616878458, 181282906404941 -+#else -+ 62198760, 20221544, 18550886, 10864893, 50649539, 26262835, -+ 44079994, 20349526, 54360141, 2701325 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1080413443139865, 1155205815510486, 1848782073549786, -+ 622566975152580, 124965574467971 -+#else -+ 58534169, 16099414, 4629974, 17213908, 46322650, 27548999, -+ 57090500, 9276970, 11329923, 1862132 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1184526762066993, 247622751762817, 692129017206356, -+ 820018689412496, 2188697339828085 -+#else -+ 14763057, 17650824, 36190593, 3689866, 3511892, 10313526, -+ 45157776, 12219230, 58070901, 32614131 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2020536369003019, 202261491735136, 1053169669150884, -+ 2056531979272544, 778165514694311 -+#else -+ 8894987, 30108338, 6150752, 3013931, 301220, 15693451, 35127648, -+ 30644714, 51670695, 11595569 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 237404399610207, 1308324858405118, 1229680749538400, -+ 720131409105291, 1958958863624906 -+#else -+ 15214943, 3537601, 40870142, 19495559, 4418656, 18323671, -+ 13947275, 10730794, 53619402, 29190761 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 515583508038846, 17656978857189, 1717918437373989, -+ 1568052070792483, 46975803123923 -+#else -+ 64570558, 7682792, 32759013, 263109, 37124133, 25598979, -+ 44776739, 23365796, 977107, 699994 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 281527309158085, 36970532401524, 866906920877543, -+ 2222282602952734, 1289598729589882 -+#else -+ 54642373, 4195083, 57897332, 550903, 51543527, 12917919, -+ 19118110, 33114591, 36574330, 19216518 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1278207464902042, 494742455008756, 1262082121427081, -+ 1577236621659884, 1888786707293291 -+#else -+ 31788442, 19046775, 4799988, 7372237, 8808585, 18806489, -+ 9408236, 23502657, 12493931, 28145115 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 353042527954210, 1830056151907359, 1111731275799225, -+ 174960955838824, 404312815582675 -+#else -+ 41428258, 5260743, 47873055, 27269961, 63412921, 16566086, -+ 27218280, 2607121, 29375955, 6024730 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2064251142068628, 1666421603389706, 1419271365315441, -+ 468767774902855, 191535130366583 -+#else -+ 842132, 30759739, 62345482, 24831616, 26332017, 21148791, -+ 11831879, 6985184, 57168503, 2854095 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1716987058588002, 1859366439773457, 1767194234188234, -+ 64476199777924, 1117233614485261 -+#else -+ 62261602, 25585100, 2516241, 27706719, 9695690, 26333246, -+ 16512644, 960770, 12121869, 16648078 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 984292135520292, 135138246951259, 2220652137473167, -+ 1722843421165029, 190482558012909 -+#else -+ 51890212, 14667095, 53772635, 2013716, 30598287, 33090295, -+ 35603941, 25672367, 20237805, 2838411 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 298845952651262, 1166086588952562, 1179896526238434, -+ 1347812759398693, 1412945390096208 -+#else -+ 47820798, 4453151, 15298546, 17376044, 22115042, 17581828, -+ 12544293, 20083975, 1068880, 21054527 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1143239552672925, 906436640714209, 2177000572812152, -+ 2075299936108548, 325186347798433 -+#else -+ 57549981, 17035596, 33238497, 13506958, 30505848, 32439836, -+ 58621956, 30924378, 12521377, 4845654 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 721024854374772, 684487861263316, 1373438744094159, -+ 2193186935276995, 1387043709851261 -+#else -+ 38910324, 10744107, 64150484, 10199663, 7759311, 20465832, -+ 3409347, 32681032, 60626557, 20668561 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 418098668140962, 715065997721283, 1471916138376055, -+ 2168570337288357, 937812682637044 -+#else -+ 43547042, 6230155, 46726851, 10655313, 43068279, 21933259, -+ 10477733, 32314216, 63995636, 13974497 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1043584187226485, 2143395746619356, 2209558562919611, -+ 482427979307092, 847556718384018 -+#else -+ 12966261, 15550616, 35069916, 31939085, 21025979, 32924988, -+ 5642324, 7188737, 18895762, 12629579 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1248731221520759, 1465200936117687, 540803492710140, -+ 52978634680892, 261434490176109 -+#else -+ 14741879, 18607545, 22177207, 21833195, 1279740, 8058600, -+ 11758140, 789443, 32195181, 3895677 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1057329623869501, 620334067429122, 461700859268034, -+ 2012481616501857, 297268569108938 -+#else -+ 10758205, 15755439, 62598914, 9243697, 62229442, 6879878, -+ 64904289, 29988312, 58126794, 4429646 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1055352180870759, 1553151421852298, 1510903185371259, -+ 1470458349428097, 1226259419062731 -+#else -+ 64654951, 15725972, 46672522, 23143759, 61304955, 22514211, -+ 59972993, 21911536, 18047435, 18272689 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1492988790301668, 790326625573331, 1190107028409745, -+ 1389394752159193, 1620408196604194 -+#else -+ 41935844, 22247266, 29759955, 11776784, 44846481, 17733976, -+ 10993113, 20703595, 49488162, 24145963 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 47000654413729, 1004754424173864, 1868044813557703, -+ 173236934059409, 588771199737015 -+#else -+ 21987233, 700364, 42603816, 14972007, 59334599, 27836036, -+ 32155025, 2581431, 37149879, 8773374 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 30498470091663, 1082245510489825, 576771653181956, -+ 806509986132686, 1317634017056939 -+#else -+ 41540495, 454462, 53896929, 16126714, 25240068, 8594567, -+ 20656846, 12017935, 59234475, 19634276 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 420308055751555, 1493354863316002, 165206721528088, -+ 1884845694919786, 2065456951573059 -+#else -+ 6028163, 6263078, 36097058, 22252721, 66289944, 2461771, -+ 35267690, 28086389, 65387075, 30777706 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1115636332012334, 1854340990964155, 83792697369514, -+ 1972177451994021, 457455116057587 -+#else -+ 54829870, 16624276, 987579, 27631834, 32908202, 1248608, -+ 7719845, 29387734, 28408819, 6816612 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1698968457310898, 1435137169051090, 1083661677032510, -+ 938363267483709, 340103887207182 -+#else -+ 56750770, 25316602, 19549650, 21385210, 22082622, 16147817, -+ 20613181, 13982702, 56769294, 5067942 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1995325341336574, 911500251774648, 164010755403692, -+ 855378419194762, 1573601397528842 -+#else -+ 36602878, 29732664, 12074680, 13582412, 47230892, 2443950, -+ 47389578, 12746131, 5331210, 23448488 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 241719380661528, 310028521317150, 1215881323380194, -+ 1408214976493624, 2141142156467363 -+#else -+ 30528792, 3601899, 65151774, 4619784, 39747042, 18118043, -+ 24180792, 20984038, 27679907, 31905504 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1315157046163473, 727368447885818, 1363466668108618, -+ 1668921439990361, 1398483384337907 -+#else -+ 9402385, 19597367, 32834042, 10838634, 40528714, 20317236, -+ 26653273, 24868867, 22611443, 20839026 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 75029678299646, 1015388206460473, 1849729037055212, -+ 1939814616452984, 444404230394954 -+#else -+ 22190590, 1118029, 22736441, 15130463, 36648172, 27563110, -+ 19189624, 28905490, 4854858, 6622139 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2053597130993710, 2024431685856332, 2233550957004860, -+ 2012407275509545, 872546993104440 -+#else -+ 58798126, 30600981, 58846284, 30166382, 56707132, 33282502, -+ 13424425, 29987205, 26404408, 13001963 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1217269667678610, 599909351968693, 1390077048548598, -+ 1471879360694802, 739586172317596 -+#else -+ 35867026, 18138731, 64114613, 8939345, 11562230, 20713762, -+ 41044498, 21932711, 51703708, 11020692 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1718318639380794, 1560510726633958, 904462881159922, -+ 1418028351780052, 94404349451937 -+#else -+ 1866042, 25604943, 59210214, 23253421, 12483314, 13477547, -+ 3175636, 21130269, 28761761, 1406734 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2132502667405250, 214379346175414, 1502748313768060, -+ 1960071701057800, 1353971822643138 -+#else -+ 66660290, 31776765, 13018550, 3194501, 57528444, 22392694, -+ 24760584, 29207344, 25577410, 20175752 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 319394212043702, 2127459436033571, 717646691535162, -+ 663366796076914, 318459064945314 -+#else -+ 42818486, 4759344, 66418211, 31701615, 2066746, 10693769, -+ 37513074, 9884935, 57739938, 4745409 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 405989424923593, 1960452633787083, 667349034401665, -+ 1492674260767112, 1451061489880787 -+#else -+ 57967561, 6049713, 47577803, 29213020, 35848065, 9944275, -+ 51646856, 22242579, 10931923, 21622501 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 947085906234007, 323284730494107, 1485778563977200, -+ 728576821512394, 901584347702286 -+#else -+ 50547351, 14112679, 59096219, 4817317, 59068400, 22139825, -+ 44255434, 10856640, 46638094, 13434653 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1575783124125742, 2126210792434375, 1569430791264065, -+ 1402582372904727, 1891780248341114 -+#else -+ 22759470, 23480998, 50342599, 31683009, 13637441, 23386341, -+ 1765143, 20900106, 28445306, 28189722 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 838432205560695, 1997703511451664, 1018791879907867, -+ 1662001808174331, 78328132957753 -+#else -+ 29875063, 12493613, 2795536, 29768102, 1710619, 15181182, -+ 56913147, 24765756, 9074233, 1167180 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 739152638255629, 2074935399403557, 505483666745895, -+ 1611883356514088, 628654635394878 -+#else -+ 40903181, 11014232, 57266213, 30918946, 40200743, 7532293, -+ 48391976, 24018933, 3843902, 9367684 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1822054032121349, 643057948186973, 7306757352712, -+ 577249257962099, 284735863382083 -+#else -+ 56139269, 27150720, 9591133, 9582310, 11349256, 108879, -+ 16235123, 8601684, 66969667, 4242894 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1366558556363930, 1448606567552086, 1478881020944768, -+ 165803179355898, 1115718458123498 -+#else -+ 22092954, 20363309, 65066070, 21585919, 32186752, 22037044, -+ 60534522, 2470659, 39691498, 16625500 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 204146226972102, 1630511199034723, 2215235214174763, -+ 174665910283542, 956127674017216 -+#else -+ 56051142, 3042015, 13770083, 24296510, 584235, 33009577, -+ 59338006, 2602724, 39757248, 14247412 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1562934578796716, 1070893489712745, 11324610642270, -+ 958989751581897, 2172552325473805 -+#else -+ 6314156, 23289540, 34336361, 15957556, 56951134, 168749, -+ 58490057, 14290060, 27108877, 32373552 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1770564423056027, 735523631664565, 1326060113795289, -+ 1509650369341127, 65892421582684 -+#else -+ 58522267, 26383465, 13241781, 10960156, 34117849, 19759835, -+ 33547975, 22495543, 39960412, 981873 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 623682558650637, 1337866509471512, 990313350206649, -+ 1314236615762469, 1164772974270275 -+#else -+ 22833421, 9293594, 34459416, 19935764, 57971897, 14756818, -+ 44180005, 19583651, 56629059, 17356469 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 223256821462517, 723690150104139, 1000261663630601, -+ 933280913953265, 254872671543046 -+#else -+ 59340277, 3326785, 38997067, 10783823, 19178761, 14905060, -+ 22680049, 13906969, 51175174, 3797898 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1969087237026041, 624795725447124, 1335555107635969, -+ 2069986355593023, 1712100149341902 -+#else -+ 21721337, 29341686, 54902740, 9310181, 63226625, 19901321, -+ 23740223, 30845200, 20491982, 25512280 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1236103475266979, 1837885883267218, 1026072585230455, -+ 1025865513954973, 1801964901432134 -+#else -+ 9209251, 18419377, 53852306, 27386633, 66377847, 15289672, -+ 25947805, 15286587, 30997318, 26851369 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1115241013365517, 1712251818829143, 2148864332502771, -+ 2096001471438138, 2235017246626125 -+#else -+ 7392013, 16618386, 23946583, 25514540, 53843699, 32020573, -+ 52911418, 31232855, 17649997, 33304352 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1299268198601632, 2047148477845621, 2165648650132450, -+ 1612539282026145, 514197911628890 -+#else -+ 57807776, 19360604, 30609525, 30504889, 41933794, 32270679, -+ 51867297, 24028707, 64875610, 7662145 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 118352772338543, 1067608711804704, 1434796676193498, -+ 1683240170548391, 230866769907437 -+#else -+ 49550191, 1763593, 33994528, 15908609, 37067994, 21380136, -+ 7335079, 25082233, 63934189, 3440182 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1850689576796636, 1601590730430274, 1139674615958142, -+ 1954384401440257, 76039205311 -+#else -+ 47219164, 27577423, 42997570, 23865561, 10799742, 16982475, -+ 40449, 29122597, 4862399, 1133 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1723387471374172, 997301467038410, 533927635123657, -+ 20928644693965, 1756575222802513 -+#else -+ 34252636, 25680474, 61686474, 14860949, 50789833, 7956141, -+ 7258061, 311861, 36513873, 26175010 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2146711623855116, 503278928021499, 625853062251406, -+ 1109121378393107, 1033853809911861 -+#else -+ 63335436, 31988495, 28985339, 7499440, 24445838, 9325937, -+ 29727763, 16527196, 18278453, 15405622 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 571005965509422, 2005213373292546, 1016697270349626, -+ 56607856974274, 914438579435146 -+#else -+ 62726958, 8508651, 47210498, 29880007, 61124410, 15149969, -+ 53795266, 843522, 45233802, 13626196 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1346698876211176, 2076651707527589, 1084761571110205, -+ 265334478828406, 1068954492309671 -+#else -+ 2281448, 20067377, 56193445, 30944521, 1879357, 16164207, -+ 56324982, 3953791, 13340839, 15928663 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1769967932677654, 1695893319756416, 1151863389675920, -+ 1781042784397689, 400287774418285 -+#else -+ 31727126, 26374577, 48671360, 25270779, 2875792, 17164102, -+ 41838969, 26539605, 43656557, 5964752 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1851867764003121, 403841933237558, 820549523771987, -+ 761292590207581, 1743735048551143 -+#else -+ 4100401, 27594980, 49929526, 6017713, 48403027, 12227140, -+ 40424029, 11344143, 2538215, 25983677 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 410915148140008, 2107072311871739, 1004367461876503, -+ 99684895396761, 1180818713503224 -+#else -+ 57675240, 6123112, 11159803, 31397824, 30016279, 14966241, -+ 46633881, 1485420, 66479608, 17595569 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 285945406881439, 648174397347453, 1098403762631981, -+ 1366547441102991, 1505876883139217 -+#else -+ 40304287, 4260918, 11851389, 9658551, 35091757, 16367491, -+ 46903439, 20363143, 11659921, 22439314 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 672095903120153, 1675918957959872, 636236529315028, -+ 1569297300327696, 2164144194785875 -+#else -+ 26180377, 10015009, 36264640, 24973138, 5418196, 9480663, -+ 2231568, 23384352, 33100371, 32248261 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1902708175321798, 1035343530915438, 1178560808893263, -+ 301095684058146, 1280977479761118 -+#else -+ 15121094, 28352561, 56718958, 15427820, 39598927, 17561924, -+ 21670946, 4486675, 61177054, 19088051 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1615357281742403, 404257611616381, 2160201349780978, -+ 1160947379188955, 1578038619549541 -+#else -+ 16166467, 24070699, 56004733, 6023907, 35182066, 32189508, -+ 2340059, 17299464, 56373093, 23514607 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2013087639791217, 822734930507457, 1785668418619014, -+ 1668650702946164, 389450875221715 -+#else -+ 28042865, 29997343, 54982337, 12259705, 63391366, 26608532, -+ 6766452, 24864833, 18036435, 5803270 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 453918449698368, 106406819929001, 2072540975937135, -+ 308588860670238, 1304394580755385 -+#else -+ 66291264, 6763911, 11803561, 1585585, 10958447, 30883267, -+ 23855390, 4598332, 60949433, 19436993 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1295082798350326, 2091844511495996, 1851348972587817, -+ 3375039684596, 789440738712837 -+#else -+ 36077558, 19298237, 17332028, 31170912, 31312681, 27587249, -+ 696308, 50292, 47013125, 11763583 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2083069137186154, 848523102004566, 993982213589257, -+ 1405313299916317, 1532824818698468 -+#else -+ 66514282, 31040148, 34874710, 12643979, 12650761, 14811489, -+ 665117, 20940800, 47335652, 22840869 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1495961298852430, 1397203457344779, 1774950217066942, -+ 139302743555696, 66603584342787 -+#else -+ 30464590, 22291560, 62981387, 20819953, 19835326, 26448819, -+ 42712688, 2075772, 50088707, 992470 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1782411379088302, 1096724939964781, 27593390721418, -+ 542241850291353, 1540337798439873 -+#else -+ 18357166, 26559999, 7766381, 16342475, 37783946, 411173, -+ 14578841, 8080033, 55534529, 22952821 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 693543956581437, 171507720360750, 1557908942697227, -+ 1074697073443438, 1104093109037196 -+#else -+ 19598397, 10334610, 12555054, 2555664, 18821899, 23214652, -+ 21873262, 16014234, 26224780, 16452269 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 345288228393419, 1099643569747172, 134881908403743, -+ 1740551994106740, 248212179299770 -+#else -+ 36884939, 5145195, 5944548, 16385966, 3976735, 2009897, -+ 55731060, 25936245, 46575034, 3698649 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 231429562203065, 1526290236421172, 2021375064026423, -+ 1520954495658041, 806337791525116 -+#else -+ 14187449, 3448569, 56472628, 22743496, 44444983, 30120835, -+ 7268409, 22663988, 27394300, 12015369 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1079623667189886, 872403650198613, 766894200588288, -+ 2163700860774109, 2023464507911816 -+#else -+ 19695742, 16087646, 28032085, 12999827, 6817792, 11427614, -+ 20244189, 32241655, 53849736, 30151970 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 854645372543796, 1936406001954827, 151460662541253, -+ 825325739271555, 1554306377287556 -+#else -+ 30860084, 12735208, 65220619, 28854697, 50133957, 2256939, -+ 58942851, 12298311, 58558340, 23160969 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1497138821904622, 1044820250515590, 1742593886423484, -+ 1237204112746837, 849047450816987 -+#else -+ 61389038, 22309106, 65198214, 15569034, 26642876, 25966672, -+ 61319509, 18435777, 62132699, 12651792 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 667962773375330, 1897271816877105, 1399712621683474, -+ 1143302161683099, 2081798441209593 -+#else -+ 64260450, 9953420, 11531313, 28271553, 26895122, 20857343, -+ 53990043, 17036529, 9768697, 31021214 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 127147851567005, 1936114012888110, 1704424366552046, -+ 856674880716312, 716603621335359 -+#else -+ 42389405, 1894650, 66821166, 28850346, 15348718, 25397902, -+ 32767512, 12765450, 4940095, 10678226 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1072409664800960, 2146937497077528, 1508780108920651, -+ 935767602384853, 1112800433544068 -+#else -+ 18860224, 15980149, 48121624, 31991861, 40875851, 22482575, -+ 59264981, 13944023, 42736516, 16582018 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 333549023751292, 280219272863308, 2104176666454852, -+ 1036466864875785, 536135186520207 -+#else -+ 51604604, 4970267, 37215820, 4175592, 46115652, 31354675, -+ 55404809, 15444559, 56105103, 7989036 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 373666279883137, 146457241530109, 304116267127857, -+ 416088749147715, 1258577131183391 -+#else -+ 31490433, 5568061, 64696061, 2182382, 34772017, 4531685, -+ 35030595, 6200205, 47422751, 18754260 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1186115062588401, 2251609796968486, 1098944457878953, -+ 1153112761201374, 1791625503417267 -+#else -+ 49800177, 17674491, 35586086, 33551600, 34221481, 16375548, -+ 8680158, 17182719, 28550067, 26697300 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1870078460219737, 2129630962183380, 852283639691142, -+ 292865602592851, 401904317342226 -+#else -+ 38981977, 27866340, 16837844, 31733974, 60258182, 12700015, -+ 37068883, 4364037, 1155602, 5988841 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1361070124828035, 815664541425524, 1026798897364671, -+ 1951790935390647, 555874891834790 -+#else -+ 21890435, 20281525, 54484852, 12154348, 59276991, 15300495, -+ 23148983, 29083951, 24618406, 8283181 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1546301003424277, 459094500062839, 1097668518375311, -+ 1780297770129643, 720763293687608 -+#else -+ 33972757, 23041680, 9975415, 6841041, 35549071, 16356535, -+ 3070187, 26528504, 1466168, 10740210 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1212405311403990, 1536693382542438, 61028431067459, -+ 1863929423417129, 1223219538638038 -+#else -+ 65599446, 18066246, 53605478, 22898515, 32799043, 909394, -+ 53169961, 27774712, 34944214, 18227391 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1294303766540260, 1183557465955093, 882271357233093, -+ 63854569425375, 2213283684565087 -+#else -+ 3960804, 19286629, 39082773, 17636380, 47704005, 13146867, -+ 15567327, 951507, 63848543, 32980496 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 339050984211414, 601386726509773, 413735232134068, -+ 966191255137228, 1839475899458159 -+#else -+ 24740822, 5052253, 37014733, 8961360, 25877428, 6165135, -+ 42740684, 14397371, 59728495, 27410326 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 235605972169408, 2174055643032978, 1538335001838863, -+ 1281866796917192, 1815940222628465 -+#else -+ 38220480, 3510802, 39005586, 32395953, 55870735, 22922977, -+ 51667400, 19101303, 65483377, 27059617 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1632352921721536, 1833328609514701, 2092779091951987, -+ 1923956201873226, 2210068022482919 -+#else -+ 793280, 24323954, 8836301, 27318725, 39747955, 31184838, -+ 33152842, 28669181, 57202663, 32932579 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 35271216625062, 1712350667021807, 983664255668860, -+ 98571260373038, 1232645608559836 -+#else -+ 5666214, 525582, 20782575, 25516013, 42570364, 14657739, -+ 16099374, 1468826, 60937436, 18367850 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1998172393429622, 1798947921427073, 784387737563581, -+ 1589352214827263, 1589861734168180 -+#else -+ 62249590, 29775088, 64191105, 26806412, 7778749, 11688288, -+ 36704511, 23683193, 65549940, 23690785 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1733739258725305, 31715717059538, 201969945218860, -+ 992093044556990, 1194308773174556 -+#else -+ 10896313, 25834728, 824274, 472601, 47648556, 3009586, 25248958, -+ 14783338, 36527388, 17796587 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 846415389605137, 746163495539180, 829658752826080, -+ 592067705956946, 957242537821393 -+#else -+ 10566929, 12612572, 35164652, 11118702, 54475488, 12362878, -+ 21752402, 8822496, 24003793, 14264025 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1758148849754419, 619249044817679, 168089007997045, -+ 1371497636330523, 1867101418880350 -+#else -+ 27713843, 26198459, 56100623, 9227529, 27050101, 2504721, -+ 23886875, 20436907, 13958494, 27821979 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 326633984209635, 261759506071016, 1700682323676193, -+ 1577907266349064, 1217647663383016 -+#else -+ 43627235, 4867225, 39861736, 3900520, 29838369, 25342141, -+ 35219464, 23512650, 7340520, 18144364 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1714182387328607, 1477856482074168, 574895689942184, -+ 2159118410227270, 1555532449716575 -+#else -+ 4646495, 25543308, 44342840, 22021777, 23184552, 8566613, -+ 31366726, 32173371, 52042079, 23179239 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 853828206885131, 998498946036955, 1835887550391235, -+ 207627336608048, 258363815956050 -+#else -+ 49838347, 12723031, 50115803, 14878793, 21619651, 27356856, -+ 27584816, 3093888, 58265170, 3849920 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 141141474651677, 1236728744905256, 643101419899887, -+ 1646615130509173, 1208239602291765 -+#else -+ 58043933, 2103171, 25561640, 18428694, 61869039, 9582957, -+ 32477045, 24536477, 5002293, 18004173 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1501663228068911, 1354879465566912, 1444432675498247, -+ 897812463852601, 855062598754348 -+#else -+ 55051311, 22376525, 21115584, 20189277, 8808711, 21523724, -+ 16489529, 13378448, 41263148, 12741425 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 714380763546606, 1032824444965790, 1774073483745338, -+ 1063840874947367, 1738680636537158 -+#else -+ 61162478, 10645102, 36197278, 15390283, 63821882, 26435754, -+ 24306471, 15852464, 28834118, 25908360 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1640635546696252, 633168953192112, 2212651044092396, -+ 30590958583852, 368515260889378 -+#else -+ 49773116, 24447374, 42577584, 9434952, 58636780, 32971069, -+ 54018092, 455840, 20461858, 5491305 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1171650314802029, 1567085444565577, 1453660792008405, -+ 757914533009261, 1619511342778196 -+#else -+ 13669229, 17458950, 54626889, 23351392, 52539093, 21661233, -+ 42112877, 11293806, 38520660, 24132599 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 420958967093237, 971103481109486, 2169549185607107, -+ 1301191633558497, 1661514101014240 -+#else -+ 28497909, 6272777, 34085870, 14470569, 8906179, 32328802, -+ 18504673, 19389266, 29867744, 24758489 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 907123651818302, 1332556122804146, 1824055253424487, -+ 1367614217442959, 1982558335973172 -+#else -+ 50901822, 13517195, 39309234, 19856633, 24009063, 27180541, -+ 60741263, 20379039, 22853428, 29542421 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1121533090144639, 1021251337022187, 110469995947421, -+ 1511059774758394, 2110035908131662 -+#else -+ 24191359, 16712145, 53177067, 15217830, 14542237, 1646131, -+ 18603514, 22516545, 12876622, 31441985 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 303213233384524, 2061932261128138, 352862124777736, -+ 40828818670255, 249879468482660 -+#else -+ 17902668, 4518229, 66697162, 30725184, 26878216, 5258055, -+ 54248111, 608396, 16031844, 3723494 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 856559257852200, 508517664949010, 1378193767894916, -+ 1723459126947129, 1962275756614521 -+#else -+ 38476072, 12763727, 46662418, 7577503, 33001348, 20536687, -+ 17558841, 25681542, 23896953, 29240187 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1445691340537320, 40614383122127, 402104303144865, -+ 485134269878232, 1659439323587426 -+#else -+ 47103464, 21542479, 31520463, 605201, 2543521, 5991821, -+ 64163800, 7229063, 57189218, 24727572 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 20057458979482, 1183363722525800, 2140003847237215, -+ 2053873950687614, 2112017736174909 -+#else -+ 28816026, 298879, 38943848, 17633493, 19000927, 31888542, -+ 54428030, 30605106, 49057085, 31471516 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2228654250927986, 1483591363415267, 1368661293910956, -+ 1076511285177291, 526650682059608 -+#else -+ 16000882, 33209536, 3493091, 22107234, 37604268, 20394642, -+ 12577739, 16041268, 47393624, 7847706 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 709481497028540, 531682216165724, 316963769431931, -+ 1814315888453765, 258560242424104 -+#else -+ 10151868, 10572098, 27312476, 7922682, 14825339, 4723128, -+ 34252933, 27035413, 57088296, 3852847 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1053447823660455, 1955135194248683, 1010900954918985, -+ 1182614026976701, 1240051576966610 -+#else -+ 55678375, 15697595, 45987307, 29133784, 5386313, 15063598, -+ 16514493, 17622322, 29330898, 18478208 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1957943897155497, 1788667368028035, 137692910029106, -+ 1039519607062, 826404763313028 -+#else -+ 41609129, 29175637, 51885955, 26653220, 16615730, 2051784, -+ 3303702, 15490, 39560068, 12314390 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1848942433095597, 1582009882530495, 1849292741020143, -+ 1068498323302788, 2001402229799484 -+#else -+ 15683501, 27551389, 18109119, 23573784, 15337967, 27556609, -+ 50391428, 15921865, 16103996, 29823217 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1528282417624269, 2142492439828191, 2179662545816034, -+ 362568973150328, 1591374675250271 -+#else -+ 43939021, 22773182, 13588191, 31925625, 63310306, 32479502, -+ 47835256, 5402698, 37293151, 23713330 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 160026679434388, 232341189218716, 2149181472355545, -+ 598041771119831, 183859001910173 -+#else -+ 23190676, 2384583, 34394524, 3462153, 37205209, 32025299, -+ 55842007, 8911516, 41903005, 2739712 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2013278155187349, 662660471354454, 793981225706267, -+ 411706605985744, 804490933124791 -+#else -+ 21374101, 30000182, 33584214, 9874410, 15377179, 11831242, -+ 33578960, 6134906, 4931255, 11987849 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2051892037280204, 488391251096321, 2230187337030708, -+ 930221970662692, 679002758255210 -+#else -+ 67101132, 30575573, 50885377, 7277596, 105524, 33232381, -+ 35628324, 13861387, 37032554, 10117929 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1530723630438670, 875873929577927, 341560134269988, -+ 449903119530753, 1055551308214179 -+#else -+ 37607694, 22809559, 40945095, 13051538, 41483300, 5089642, -+ 60783361, 6704078, 12890019, 15728940 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1461835919309432, 1955256480136428, 180866187813063, -+ 1551979252664528, 557743861963950 -+#else -+ 45136504, 21783052, 66157804, 29135591, 14704839, 2695116, -+ 903376, 23126293, 12885166, 8311031 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 359179641731115, 1324915145732949, 902828372691474, -+ 294254275669987, 1887036027752957 -+#else -+ 49592363, 5352193, 10384213, 19742774, 7506450, 13453191, -+ 26423267, 4384730, 1888765, 28119028 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2043271609454323, 2038225437857464, 1317528426475850, -+ 1398989128982787, 2027639881006861 -+#else -+ 41291507, 30447119, 53614264, 30371925, 30896458, 19632703, -+ 34857219, 20846562, 47644429, 30214188 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2072902725256516, 312132452743412, 309930885642209, -+ 996244312618453, 1590501300352303 -+#else -+ 43500868, 30888657, 66582772, 4651135, 5765089, 4618330, -+ 6092245, 14845197, 17151279, 23700316 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1397254305160710, 695734355138021, 2233992044438756, -+ 1776180593969996, 1085588199351115 -+#else -+ 42278406, 20820711, 51942885, 10367249, 37577956, 33289075, -+ 22825804, 26467153, 50242379, 16176524 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 440567051331029, 254894786356681, 493869224930222, -+ 1556322069683366, 1567456540319218 -+#else -+ 43525589, 6564960, 20063689, 3798228, 62368686, 7359224, -+ 2006182, 23191006, 38362610, 23356922 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1950722461391320, 1907845598854797, 1822757481635527, -+ 2121567704750244, 73811931471221 -+#else -+ 56482264, 29068029, 53788301, 28429114, 3432135, 27161203, -+ 23632036, 31613822, 32808309, 1099883 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 387139307395758, 2058036430315676, 1220915649965325, -+ 1794832055328951, 1230009312169328 -+#else -+ 15030958, 5768825, 39657628, 30667132, 60681485, 18193060, -+ 51830967, 26745081, 2051440, 18328567 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1765973779329517, 659344059446977, 19821901606666, -+ 1301928341311214, 1116266004075885 -+#else -+ 63746541, 26315059, 7517889, 9824992, 23555850, 295369, 5148398, -+ 19400244, 44422509, 16633659 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1127572801181483, 1224743760571696, 1276219889847274, -+ 1529738721702581, 1589819666871853 -+#else -+ 4577067, 16802144, 13249840, 18250104, 19958762, 19017158, -+ 18559669, 22794883, 8402477, 23690159 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2181229378964934, 2190885205260020, 1511536077659137, -+ 1246504208580490, 668883326494241 -+#else -+ 38702534, 32502850, 40318708, 32646733, 49896449, 22523642, -+ 9453450, 18574360, 17983009, 9967138 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 437866655573314, 669026411194768, 81896997980338, -+ 523874406393178, 245052060935236 -+#else -+ 41346370, 6524721, 26585488, 9969270, 24709298, 1220360, -+ 65430874, 7806336, 17507396, 3651560 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1975438052228868, 1071801519999806, 594652299224319, -+ 1877697652668809, 1489635366987285 -+#else -+ 56688388, 29436320, 14584638, 15971087, 51340543, 8861009, -+ 26556809, 27979875, 48555541, 22197296 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 958592545673770, 233048016518599, 851568750216589, -+ 567703851596087, 1740300006094761 -+#else -+ 2839082, 14284142, 4029895, 3472686, 14402957, 12689363, -+ 40466743, 8459446, 61503401, 25932490 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2014540178270324, 192672779514432, 213877182641530, -+ 2194819933853411, 1716422829364835 -+#else -+ 62269556, 30018987, 9744960, 2871048, 25113978, 3187018, -+ 41998051, 32705365, 17258083, 25576693 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1540769606609725, 2148289943846077, 1597804156127445, -+ 1230603716683868, 815423458809453 -+#else -+ 18164541, 22959256, 49953981, 32012014, 19237077, 23809137, -+ 23357532, 18337424, 26908269, 12150756 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1738560251245018, 1779576754536888, 1783765347671392, -+ 1880170990446751, 1088225159617541 -+#else -+ 36843994, 25906566, 5112248, 26517760, 65609056, 26580174, -+ 43167, 28016731, 34806789, 16215818 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 659303913929492, 1956447718227573, 1830568515922666, -+ 841069049744408, 1669607124206368 -+#else -+ 60209940, 9824393, 54804085, 29153342, 35711722, 27277596, -+ 32574488, 12532905, 59605792, 24879084 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1143465490433355, 1532194726196059, 1093276745494697, -+ 481041706116088, 2121405433561163 -+#else -+ 39765323, 17038963, 39957339, 22831480, 946345, 16291093, -+ 254968, 7168080, 21676107, 31611404 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1686424298744462, 1451806974487153, 266296068846582, -+ 1834686947542675, 1720762336132256 -+#else -+ 21260942, 25129680, 50276977, 21633609, 43430902, 3968120, -+ 63456915, 27338965, 63552672, 25641356 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 889217026388959, 1043290623284660, 856125087551909, -+ 1669272323124636, 1603340330827879 -+#else -+ 16544735, 13250366, 50304436, 15546241, 62525861, 12757257, -+ 64646556, 24874095, 48201831, 23891632 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1206396181488998, 333158148435054, 1402633492821422, -+ 1120091191722026, 1945474114550509 -+#else -+ 64693606, 17976703, 18312302, 4964443, 51836334, 20900867, -+ 26820650, 16690659, 25459437, 28989823 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 766720088232571, 1512222781191002, 1189719893490790, -+ 2091302129467914, 2141418006894941 -+#else -+ 41964155, 11425019, 28423002, 22533875, 60963942, 17728207, -+ 9142794, 31162830, 60676445, 31909614 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 419663647306612, 1998875112167987, 1426599870253707, -+ 1154928355379510, 486538532138187 -+#else -+ 44004212, 6253475, 16964147, 29785560, 41994891, 21257994, -+ 39651638, 17209773, 6335691, 7249989 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 938160078005954, 1421776319053174, 1941643234741774, -+ 180002183320818, 1414380336750546 -+#else -+ 36775618, 13979674, 7503222, 21186118, 55152142, 28932738, -+ 36836594, 2682241, 25993170, 21075909 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 398001940109652, 1577721237663248, 1012748649830402, -+ 1540516006905144, 1011684812884559 -+#else -+ 4364628, 5930691, 32304656, 23509878, 59054082, 15091130, -+ 22857016, 22955477, 31820367, 15075278 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1653276489969630, 6081825167624, 1921777941170836, -+ 1604139841794531, 861211053640641 -+#else -+ 31879134, 24635739, 17258760, 90626, 59067028, 28636722, -+ 24162787, 23903546, 49138625, 12833044 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 996661541407379, 1455877387952927, 744312806857277, -+ 139213896196746, 1000282908547789 -+#else -+ 19073683, 14851414, 42705695, 21694263, 7625277, 11091125, -+ 47489674, 2074448, 57694925, 14905376 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1450817495603008, 1476865707053229, 1030490562252053, -+ 620966950353376, 1744760161539058 -+#else -+ 24483648, 21618865, 64589997, 22007013, 65555733, 15355505, -+ 41826784, 9253128, 27628530, 25998952 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 559728410002599, 37056661641185, 2038622963352006, -+ 1637244893271723, 1026565352238948 -+#else -+ 17597607, 8340603, 19355617, 552187, 26198470, 30377849, -+ 4593323, 24396850, 52997988, 15297015 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 962165956135846, 1116599660248791, 182090178006815, -+ 1455605467021751, 196053588803284 -+#else -+ 510886, 14337390, 35323607, 16638631, 6328095, 2713355, -+ 46891447, 21690211, 8683220, 2921426 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 796863823080135, 1897365583584155, 420466939481601, -+ 2165972651724672, 932177357788289 -+#else -+ 18606791, 11874196, 27155355, 28272950, 43077121, 6265445, -+ 41930624, 32275507, 4674689, 13890525 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 877047233620632, 1375632631944375, 643773611882121, -+ 660022738847877, 19353932331831 -+#else -+ 13609624, 13069022, 39736503, 20498523, 24360585, 9592974, -+ 14977157, 9835105, 4389687, 288396 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2216943882299338, 394841323190322, 2222656898319671, -+ 558186553950529, 1077236877025190 -+#else -+ 9922506, 33035038, 13613106, 5883594, 48350519, 33120168, -+ 54804801, 8317627, 23388070, 16052080 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 801118384953213, 1914330175515892, 574541023311511, -+ 1471123787903705, 1526158900256288 -+#else -+ 12719997, 11937594, 35138804, 28525742, 26900119, 8561328, -+ 46953177, 21921452, 52354592, 22741539 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 949617889087234, 2207116611267331, 912920039141287, -+ 501158539198789, 62362560771472 -+#else -+ 15961858, 14150409, 26716931, 32888600, 44314535, 13603568, -+ 11829573, 7467844, 38286736, 929274 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1474518386765335, 1760793622169197, 1157399790472736, -+ 1622864308058898, 165428294422792 -+#else -+ 11038231, 21972036, 39798381, 26237869, 56610336, 17246600, -+ 43629330, 24182562, 45715720, 2465073 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1961673048027128, 102619413083113, 1051982726768458, -+ 1603657989805485, 1941613251499678 -+#else -+ 20017144, 29231206, 27915241, 1529148, 12396362, 15675764, -+ 13817261, 23896366, 2463390, 28932292 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1401939116319266, 335306339903072, 72046196085786, -+ 862423201496006, 850518754531384 -+#else -+ 50749986, 20890520, 55043680, 4996453, 65852442, 1073571, -+ 9583558, 12851107, 4003896, 12673717 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1234706593321979, 1083343891215917, 898273974314935, -+ 1640859118399498, 157578398571149 -+#else -+ 65377275, 18398561, 63845933, 16143081, 19294135, 13385325, -+ 14741514, 24450706, 7903885, 2348101 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1143483057726416, 1992614991758919, 674268662140796, -+ 1773370048077526, 674318359920189 -+#else -+ 24536016, 17039225, 12715591, 29692277, 1511292, 10047386, -+ 63266518, 26425272, 38731325, 10048126 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1835401379538542, 173900035308392, 818247630716732, -+ 1762100412152786, 1021506399448291 -+#else -+ 54486638, 27349611, 30718824, 2591312, 56491836, 12192839, -+ 18873298, 26257342, 34811107, 15221631 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1506632088156630, 2127481795522179, 513812919490255, -+ 140643715928370, 442476620300318 -+#else -+ 40630742, 22450567, 11546243, 31701949, 9180879, 7656409, -+ 45764914, 2095754, 29769758, 6593415 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2056683376856736, 219094741662735, 2193541883188309, -+ 1841182310235800, 556477468664293 -+#else -+ 35114656, 30646970, 4176911, 3264766, 12538965, 32686321, -+ 26312344, 27435754, 30958053, 8292160 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1315019427910827, 1049075855992603, 2066573052986543, -+ 266904467185534, 2040482348591520 -+#else -+ 31429803, 19595316, 29173531, 15632448, 12174511, 30794338, -+ 32808830, 3977186, 26143136, 30405556 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 94096246544434, 922482381166992, 24517828745563, -+ 2139430508542503, 2097139044231004 -+#else -+ 22648882, 1402143, 44308880, 13746058, 7936347, 365344, -+ 58440231, 31879998, 63350620, 31249806 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 537697207950515, 1399352016347350, 1563663552106345, -+ 2148749520888918, 549922092988516 -+#else -+ 51616947, 8012312, 64594134, 20851969, 43143017, 23300402, -+ 65496150, 32018862, 50444388, 8194477 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1747985413252434, 680511052635695, 1809559829982725, -+ 594274250930054, 201673170745982 -+#else -+ 27338066, 26047012, 59694639, 10140404, 48082437, 26964542, -+ 27277190, 8855376, 28572286, 3005164 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 323583936109569, 1973572998577657, 1192219029966558, -+ 79354804385273, 1374043025560347 -+#else -+ 26287105, 4821776, 25476601, 29408529, 63344350, 17765447, -+ 49100281, 1182478, 41014043, 20474836 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 213277331329947, 416202017849623, 1950535221091783, -+ 1313441578103244, 2171386783823658 -+#else -+ 59937691, 3178079, 23970071, 6201893, 49913287, 29065239, -+ 45232588, 19571804, 32208682, 32356184 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 189088804229831, 993969372859110, 895870121536987, -+ 1547301535298256, 1477373024911350 -+#else -+ 50451143, 2817642, 56822502, 14811297, 6024667, 13349505, -+ 39793360, 23056589, 39436278, 22014573 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1620578418245010, 541035331188469, 2235785724453865, -+ 2154865809088198, 1974627268751826 -+#else -+ 15941010, 24148500, 45741813, 8062054, 31876073, 33315803, -+ 51830470, 32110002, 15397330, 29424239 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1346805451740245, 1350981335690626, 942744349501813, -+ 2155094562545502, 1012483751693409 -+#else -+ 8934485, 20068965, 43822466, 20131190, 34662773, 14047985, -+ 31170398, 32113411, 39603297, 15087183 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2107080134091762, 1132567062788208, 1824935377687210, -+ 769194804343737, 1857941799971888 -+#else -+ 48751602, 31397940, 24524912, 16876564, 15520426, 27193656, -+ 51606457, 11461895, 16788528, 27685490 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1074666112436467, 249279386739593, 1174337926625354, -+ 1559013532006480, 1472287775519121 -+#else -+ 65161459, 16013772, 21750665, 3714552, 49707082, 17498998, -+ 63338576, 23231111, 31322513, 21938797 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1872620123779532, 1892932666768992, 1921559078394978, -+ 1270573311796160, 1438913646755037 -+#else -+ 21426636, 27904214, 53460576, 28206894, 38296674, 28633461, -+ 48833472, 18933017, 13040861, 21441484 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 837390187648199, 1012253300223599, 989780015893987, -+ 1351393287739814, 328627746545550 -+#else -+ 11293895, 12478086, 39972463, 15083749, 37801443, 14748871, -+ 14555558, 20137329, 1613710, 4896935 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1028328827183114, 1711043289969857, 1350832470374933, -+ 1923164689604327, 1495656368846911 -+#else -+ 41213962, 15323293, 58619073, 25496531, 25967125, 20128972, -+ 2825959, 28657387, 43137087, 22287016 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1900828492104143, 430212361082163, 687437570852799, -+ 832514536673512, 1685641495940794 -+#else -+ 51184079, 28324551, 49665331, 6410663, 3622847, 10243618, -+ 20615400, 12405433, 43355834, 25118015 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 842632847936398, 605670026766216, 290836444839585, -+ 163210774892356, 2213815011799645 -+#else -+ 60017550, 12556207, 46917512, 9025186, 50036385, 4333800, -+ 4378436, 2432030, 23097949, 32988414 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1176336383453996, 1725477294339771, 12700622672454, -+ 678015708818208, 162724078519879 -+#else -+ 4565804, 17528778, 20084411, 25711615, 1724998, 189254, -+ 24767264, 10103221, 48596551, 2424777 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1448049969043497, 1789411762943521, 385587766217753, -+ 90201620913498, 832999441066823 -+#else -+ 366633, 21577626, 8173089, 26664313, 30788633, 5745705, -+ 59940186, 1344108, 63466311, 12412658 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 516086333293313, 2240508292484616, 1351669528166508, -+ 1223255565316488, 750235824427138 -+#else -+ 43107073, 7690285, 14929416, 33386175, 34898028, 20141445, -+ 24162696, 18227928, 63967362, 11179384 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1263624896582495, 1102602401673328, 526302183714372, -+ 2152015839128799, 1483839308490010 -+#else -+ 18289503, 18829478, 8056944, 16430056, 45379140, 7842513, -+ 61107423, 32067534, 48424218, 22110928 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 442991718646863, 1599275157036458, 1925389027579192, -+ 899514691371390, 350263251085160 -+#else -+ 476239, 6601091, 60956074, 23831056, 17503544, 28690532, -+ 27672958, 13403813, 11052904, 5219329 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1689713572022143, 593854559254373, 978095044791970, -+ 1985127338729499, 1676069120347625 -+#else -+ 20678527, 25178694, 34436965, 8849122, 62099106, 14574751, -+ 31186971, 29580702, 9014761, 24975376 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1557207018622683, 340631692799603, 1477725909476187, -+ 614735951619419, 2033237123746766 -+#else -+ 53464795, 23204192, 51146355, 5075807, 65594203, 22019831, -+ 34006363, 9160279, 8473550, 30297594 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 968764929340557, 1225534776710944, 662967304013036, -+ 1155521416178595, 791142883466590 -+#else -+ 24900749, 14435722, 17209120, 18261891, 44516588, 9878982, -+ 59419555, 17218610, 42540382, 11788947 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1487081286167458, 993039441814934, 1792378982844640, -+ 698652444999874, 2153908693179754 -+#else -+ 63990690, 22159237, 53306774, 14797440, 9652448, 26708528, -+ 47071426, 10410732, 42540394, 32095740 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1123181311102823, 685575944875442, 507605465509927, -+ 1412590462117473, 568017325228626 -+#else -+ 51449703, 16736705, 44641714, 10215877, 58011687, 7563910, -+ 11871841, 21049238, 48595538, 8464117 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 560258797465417, 2193971151466401, 1824086900849026, -+ 579056363542056, 1690063960036441 -+#else -+ 43708233, 8348506, 52522913, 32692717, 63158658, 27181012, -+ 14325288, 8628612, 33313881, 25183915 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1918407319222416, 353767553059963, 1930426334528099, -+ 1564816146005724, 1861342381708096 -+#else -+ 46921872, 28586496, 22367355, 5271547, 66011747, 28765593, -+ 42303196, 23317577, 58168128, 27736162 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2131325168777276, 1176636658428908, 1756922641512981, -+ 1390243617176012, 1966325177038383 -+#else -+ 60160060, 31759219, 34483180, 17533252, 32635413, 26180187, -+ 15989196, 20716244, 28358191, 29300528 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2063958120364491, 2140267332393533, 699896251574968, -+ 273268351312140, 375580724713232 -+#else -+ 43547083, 30755372, 34757181, 31892468, 57961144, 10429266, -+ 50471180, 4072015, 61757200, 5596588 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2024297515263178, 416959329722687, 1079014235017302, -+ 171612225573183, 1031677520051053 -+#else -+ 38872266, 30164383, 12312895, 6213178, 3117142, 16078565, -+ 29266239, 2557221, 1768301, 15373193 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2033900009388450, 1744902869870788, 2190580087917640, -+ 1949474984254121, 231049754293748 -+#else -+ 59865506, 30307471, 62515396, 26001078, 66980936, 32642186, -+ 66017961, 29049440, 42448372, 3442909 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 343868674606581, 550155864008088, 1450580864229630, -+ 481603765195050, 896972360018042 -+#else -+ 36898293, 5124042, 14181784, 8197961, 18964734, 21615339, -+ 22597930, 7176455, 48523386, 13365929 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2151139328380127, 314745882084928, 59756825775204, -+ 1676664391494651, 2048348075599360 -+#else -+ 59231455, 32054473, 8324672, 4690079, 6261860, 890446, 24538107, -+ 24984246, 57419264, 30522764 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1528930066340597, 1605003907059576, 1055061081337675, -+ 1458319101947665, 1234195845213142 -+#else -+ 25008885, 22782833, 62803832, 23916421, 16265035, 15721635, -+ 683793, 21730648, 15723478, 18390951 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 830430507734812, 1780282976102377, 1425386760709037, -+ 362399353095425, 2168861579799910 -+#else -+ 57448220, 12374378, 40101865, 26528283, 59384749, 21239917, -+ 11879681, 5400171, 519526, 32318556 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1155762232730333, 980662895504006, 2053766700883521, -+ 490966214077606, 510405877041357 -+#else -+ 22258397, 17222199, 59239046, 14613015, 44588609, 30603508, -+ 46754982, 7315966, 16648397, 7605640 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1683750316716132, 652278688286128, 1221798761193539, -+ 1897360681476669, 319658166027343 -+#else -+ 59027556, 25089834, 58885552, 9719709, 19259459, 18206220, -+ 23994941, 28272877, 57640015, 4763277 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 618808732869972, 72755186759744, 2060379135624181, -+ 1730731526741822, 48862757828238 -+#else -+ 45409620, 9220968, 51378240, 1084136, 41632757, 30702041, -+ 31088446, 25789909, 55752334, 728111 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1463171970593505, 1143040711767452, 614590986558883, -+ 1409210575145591, 1882816996436803 -+#else -+ 26047201, 21802961, 60208540, 17032633, 24092067, 9158119, -+ 62835319, 20998873, 37743427, 28056159 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2230133264691131, 563950955091024, 2042915975426398, -+ 827314356293472, 672028980152815 -+#else -+ 17510331, 33231575, 5854288, 8403524, 17133918, 30441820, -+ 38997856, 12327944, 10750447, 10014012 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 264204366029760, 1654686424479449, 2185050199932931, -+ 2207056159091748, 506015669043634 -+#else -+ 56796096, 3936951, 9156313, 24656749, 16498691, 32559785, -+ 39627812, 32887699, 3424690, 7540221 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1784446333136569, 1973746527984364, 334856327359575, -+ 1156769775884610, 1023950124675478 -+#else -+ 30322361, 26590322, 11361004, 29411115, 7433303, 4989748, -+ 60037442, 17237212, 57864598, 15258045 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2065270940578383, 31477096270353, 306421879113491, -+ 181958643936686, 1907105536686083 -+#else -+ 13054543, 30774935, 19155473, 469045, 54626067, 4566041, -+ 5631406, 2711395, 1062915, 28418087 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1496516440779464, 1748485652986458, 872778352227340, -+ 818358834654919, 97932669284220 -+#else -+ 47868616, 22299832, 37599834, 26054466, 61273100, 13005410, -+ 61042375, 12194496, 32960380, 1459310 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 471636015770351, 672455402793577, 1804995246884103, -+ 1842309243470804, 1501862504981682 -+#else -+ 19852015, 7027924, 23669353, 10020366, 8586503, 26896525, -+ 394196, 27452547, 18638002, 22379495 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1013216974933691, 538921919682598, 1915776722521558, -+ 1742822441583877, 1886550687916656 -+#else -+ 31395515, 15098109, 26581030, 8030562, 50580950, 28547297, -+ 9012485, 25970078, 60465776, 28111795 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2094270000643336, 303971879192276, 40801275554748, -+ 649448917027930, 1818544418535447 -+#else -+ 57916680, 31207054, 65111764, 4529533, 25766844, 607986, -+ 67095642, 9677542, 34813975, 27098423 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2241737709499165, 549397817447461, 838180519319392, -+ 1725686958520781, 1705639080897747 -+#else -+ 64664349, 33404494, 29348901, 8186665, 1873760, 12489863, -+ 36174285, 25714739, 59256019, 25416002 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1216074541925116, 50120933933509, 1565829004133810, -+ 721728156134580, 349206064666188 -+#else -+ 51872508, 18120922, 7766469, 746860, 26346930, 23332670, -+ 39775412, 10754587, 57677388, 5203575 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 948617110470858, 346222547451945, 1126511960599975, -+ 1759386906004538, 493053284802266 -+#else -+ 31834314, 14135496, 66338857, 5159117, 20917671, 16786336, -+ 59640890, 26216907, 31809242, 7347066 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1454933046815146, 874696014266362, 1467170975468588, -+ 1432316382418897, 2111710746366763 -+#else -+ 57502122, 21680191, 20414458, 13033986, 13716524, 21862551, -+ 19797969, 21343177, 15192875, 31466942 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2105387117364450, 1996463405126433, 1303008614294500, -+ 851908115948209, 1353742049788635 -+#else -+ 54445282, 31372712, 1168161, 29749623, 26747876, 19416341, -+ 10609329, 12694420, 33473243, 20172328 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 750300956351719, 1487736556065813, 15158817002104, -+ 1511998221598392, 971739901354129 -+#else -+ 33184999, 11180355, 15832085, 22169002, 65475192, 225883, -+ 15089336, 22530529, 60973201, 14480052 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1874648163531693, 2124487685930551, 1810030029384882, -+ 918400043048335, 586348627300650 -+#else -+ 31308717, 27934434, 31030839, 31657333, 15674546, 26971549, -+ 5496207, 13685227, 27595050, 8737275 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1235084464747900, 1166111146432082, 1745394857881591, -+ 1405516473883040, 4463504151617 -+#else -+ 46790012, 18404192, 10933842, 17376410, 8335351, 26008410, -+ 36100512, 20943827, 26498113, 66511 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1663810156463827, 327797390285791, 1341846161759410, -+ 1964121122800605, 1747470312055380 -+#else -+ 22644435, 24792703, 50437087, 4884561, 64003250, 19995065, -+ 30540765, 29267685, 53781076, 26039336 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 660005247548233, 2071860029952887, 1358748199950107, -+ 911703252219107, 1014379923023831 -+#else -+ 39091017, 9834844, 18617207, 30873120, 63706907, 20246925, -+ 8205539, 13585437, 49981399, 15115438 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2206641276178231, 1690587809721504, 1600173622825126, -+ 2156096097634421, 1106822408548216 -+#else -+ 23711543, 32881517, 31206560, 25191721, 6164646, 23844445, -+ 33572981, 32128335, 8236920, 16492939 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1344788193552206, 1949552134239140, 1735915881729557, -+ 675891104100469, 1834220014427292 -+#else -+ 43198286, 20038905, 40809380, 29050590, 25005589, 25867162, -+ 19574901, 10071562, 6708380, 27332008 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1920949492387964, 158885288387530, 70308263664033, -+ 626038464897817, 1468081726101009 -+#else -+ 2101372, 28624378, 19702730, 2367575, 51681697, 1047674, -+ 5301017, 9328700, 29955601, 21876122 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 622221042073383, 1210146474039168, 1742246422343683, -+ 1403839361379025, 417189490895736 -+#else -+ 3096359, 9271816, 45488000, 18032587, 52260867, 25961494, -+ 41216721, 20918836, 57191288, 6216607 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 22727256592983, 168471543384997, 1324340989803650, -+ 1839310709638189, 504999476432775 -+#else -+ 34493015, 338662, 41913253, 2510421, 37895298, 19734218, -+ 24822829, 27407865, 40341383, 7525078 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1313240518756327, 1721896294296942, 52263574587266, -+ 2065069734239232, 804910473424630 -+#else -+ 44042215, 19568808, 16133486, 25658254, 63719298, 778787, -+ 66198528, 30771936, 47722230, 11994100 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1337466662091884, 1287645354669772, 2018019646776184, -+ 652181229374245, 898011753211715 -+#else -+ 21691500, 19929806, 66467532, 19187410, 3285880, 30070836, -+ 42044197, 9718257, 59631427, 13381417 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1969792547910734, 779969968247557, 2011350094423418, -+ 1823964252907487, 1058949448296945 -+#else -+ 18445390, 29352196, 14979845, 11622458, 65381754, 29971451, -+ 23111647, 27179185, 28535281, 15779576 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 207343737062002, 1118176942430253, 758894594548164, -+ 806764629546266, 1157700123092949 -+#else -+ 30098034, 3089662, 57874477, 16662134, 45801924, 11308410, -+ 53040410, 12021729, 9955285, 17251076 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1273565321399022, 1638509681964574, 759235866488935, -+ 666015124346707, 897983460943405 -+#else -+ 9734894, 18977602, 59635230, 24415696, 2060391, 11313496, -+ 48682835, 9924398, 20194861, 13380996 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1717263794012298, 1059601762860786, 1837819172257618, -+ 1054130665797229, 680893204263559 -+#else -+ 40730762, 25589224, 44941042, 15789296, 49053522, 27385639, -+ 65123949, 15707770, 26342023, 10146099 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2237039662793603, 2249022333361206, 2058613546633703, -+ 149454094845279, 2215176649164582 -+#else -+ 41091971, 33334488, 21339190, 33513044, 19745255, 30675732, -+ 37471583, 2227039, 21612326, 33008704 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 79472182719605, 1851130257050174, 1825744808933107, -+ 821667333481068, 781795293511946 -+#else -+ 54031477, 1184227, 23562814, 27583990, 46757619, 27205717, -+ 25764460, 12243797, 46252298, 11649657 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 755822026485370, 152464789723500, 1178207602290608, -+ 410307889503239, 156581253571278 -+#else -+ 57077370, 11262625, 27384172, 2271902, 26947504, 17556661, -+ 39943, 6114064, 33514190, 2333242 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1418185496130297, 484520167728613, 1646737281442950, -+ 1401487684670265, 1349185550126961 -+#else -+ 45675257, 21132610, 8119781, 7219913, 45278342, 24538297, -+ 60429113, 20883793, 24350577, 20104431 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1495380034400429, 325049476417173, 46346894893933, -+ 1553408840354856, 828980101835683 -+#else -+ 62992557, 22282898, 43222677, 4843614, 37020525, 690622, -+ 35572776, 23147595, 8317859, 12352766 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1280337889310282, 2070832742866672, 1640940617225222, -+ 2098284908289951, 450929509534434 -+#else -+ 18200138, 19078521, 34021104, 30857812, 43406342, 24451920, -+ 43556767, 31266881, 20712162, 6719373 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 407703353998781, 126572141483652, 286039827513621, -+ 1999255076709338, 2030511179441770 -+#else -+ 26656189, 6075253, 59250308, 1886071, 38764821, 4262325, -+ 11117530, 29791222, 26224234, 30256974 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1254958221100483, 1153235960999843, 942907704968834, -+ 637105404087392, 1149293270147267 -+#else -+ 49939907, 18700334, 63713187, 17184554, 47154818, 14050419, -+ 21728352, 9493610, 18620611, 17125804 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 894249020470196, 400291701616810, 406878712230981, -+ 1599128793487393, 1145868722604026 -+#else -+ 53785524, 13325348, 11432106, 5964811, 18609221, 6062965, -+ 61839393, 23828875, 36407290, 17074774 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1497955250203334, 110116344653260, 1128535642171976, -+ 1900106496009660, 129792717460909 -+#else -+ 43248326, 22321272, 26961356, 1640861, 34695752, 16816491, -+ 12248508, 28313793, 13735341, 1934062 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 452487513298665, 1352120549024569, 1173495883910956, -+ 1999111705922009, 367328130454226 -+#else -+ 25089769, 6742589, 17081145, 20148166, 21909292, 17486451, -+ 51972569, 29789085, 45830866, 5473615 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1717539401269642, 1475188995688487, 891921989653942, -+ 836824441505699, 1885988485608364 -+#else -+ 31883658, 25593331, 1083431, 21982029, 22828470, 13290673, -+ 59983779, 12469655, 29111212, 28103418 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1241784121422547, 187337051947583, 1118481812236193, -+ 428747751936362, 30358898927325 -+#else -+ 24244947, 18504025, 40845887, 2791539, 52111265, 16666677, -+ 24367466, 6388839, 56813277, 452382 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2022432361201842, 1088816090685051, 1977843398539868, -+ 1854834215890724, 564238862029357 -+#else -+ 41468082, 30136590, 5217915, 16224624, 19987036, 29472163, -+ 42872612, 27639183, 15766061, 8407814 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 938868489100585, 1100285072929025, 1017806255688848, -+ 1957262154788833, 152787950560442 -+#else -+ 46701865, 13990230, 15495425, 16395525, 5377168, 15166495, -+ 58191841, 29165478, 59040954, 2276717 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 867319417678923, 620471962942542, 226032203305716, -+ 342001443957629, 1761675818237336 -+#else -+ 30157899, 12924066, 49396814, 9245752, 19895028, 3368142, -+ 43281277, 5096218, 22740376, 26251015 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1295072362439987, 931227904689414, 1355731432641687, -+ 922235735834035, 892227229410209 -+#else -+ 2041139, 19298082, 7783686, 13876377, 41161879, 20201972, -+ 24051123, 13742383, 51471265, 13295221 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1680989767906154, 535362787031440, 2136691276706570, -+ 1942228485381244, 1267350086882274 -+#else -+ 33338218, 25048699, 12532112, 7977527, 9106186, 31839181, -+ 49388668, 28941459, 62657506, 18884987 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 366018233770527, 432660629755596, 126409707644535, -+ 1973842949591662, 645627343442376 -+#else -+ 47063583, 5454096, 52762316, 6447145, 28862071, 1883651, -+ 64639598, 29412551, 7770568, 9620597 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 535509430575217, 546885533737322, 1524675609547799, -+ 2138095752851703, 1260738089896827 -+#else -+ 23208049, 7979712, 33071466, 8149229, 1758231, 22719437, -+ 30945527, 31860109, 33606523, 18786461 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1159906385590467, 2198530004321610, 714559485023225, -+ 81880727882151, 1484020820037082 -+#else -+ 1439939, 17283952, 66028874, 32760649, 4625401, 10647766, -+ 62065063, 1220117, 30494170, 22113633 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1377485731340769, 2046328105512000, 1802058637158797, -+ 62146136768173, 1356993908853901 -+#else -+ 62071265, 20526136, 64138304, 30492664, 15640973, 26852766, -+ 40369837, 926049, 65424525, 20220784 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2013612215646735, 1830770575920375, 536135310219832, -+ 609272325580394, 270684344495013 -+#else -+ 13908495, 30005160, 30919927, 27280607, 45587000, 7989038, -+ 9021034, 9078865, 3353509, 4033511 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1237542585982777, 2228682050256790, 1385281931622824, -+ 593183794882890, 493654978552689 -+#else -+ 37445433, 18440821, 32259990, 33209950, 24295848, 20642309, -+ 23161162, 8839127, 27485041, 7356032 -+#endif -+ }}, -+ }, -+ }, -+ { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 47341488007760, 1891414891220257, 983894663308928, -+ 176161768286818, 1126261115179708 -+#else -+ 9661008, 705443, 11980065, 28184278, 65480320, 14661172, -+ 60762722, 2625014, 28431036, 16782598 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1694030170963455, 502038567066200, 1691160065225467, -+ 949628319562187, 275110186693066 -+#else -+ 43269631, 25243016, 41163352, 7480957, 49427195, 25200248, -+ 44562891, 14150564, 15970762, 4099461 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1124515748676336, 1661673816593408, 1499640319059718, -+ 1584929449166988, 558148594103306 -+#else -+ 29262576, 16756590, 26350592, 24760869, 8529670, 22346382, -+ 13617292, 23617289, 11465738, 8317062 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1784525599998356, 1619698033617383, 2097300287550715, -+ 258265458103756, 1905684794832758 -+#else -+ 41615764, 26591503, 32500199, 24135381, 44070139, 31252209, -+ 14898636, 3848455, 20969334, 28396916 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1288941072872766, 931787902039402, 190731008859042, -+ 2006859954667190, 1005931482221702 -+#else -+ 46724414, 19206718, 48772458, 13884721, 34069410, 2842113, -+ 45498038, 29904543, 11177094, 14989547 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1465551264822703, 152905080555927, 680334307368453, -+ 173227184634745, 666407097159852 -+#else -+ 42612143, 21838415, 16959895, 2278463, 12066309, 10137771, -+ 13515641, 2581286, 38621356, 9930239 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2111017076203943, 1378760485794347, 1248583954016456, -+ 1352289194864422, 1895180776543896 -+#else -+ 49357223, 31456605, 16544299, 20545132, 51194056, 18605350, -+ 18345766, 20150679, 16291480, 28240394 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 171348223915638, 662766099800389, 462338943760497, -+ 466917763340314, 656911292869115 -+#else -+ 33879670, 2553287, 32678213, 9875984, 8534129, 6889387, -+ 57432090, 6957616, 4368891, 9788741 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 488623681976577, 866497561541722, 1708105560937768, -+ 1673781214218839, 1506146329818807 -+#else -+ 16660737, 7281060, 56278106, 12911819, 20108584, 25452756, -+ 45386327, 24941283, 16250551, 22443329 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 160425464456957, 950394373239689, 430497123340934, -+ 711676555398832, 320964687779005 -+#else -+ 47343357, 2390525, 50557833, 14161979, 1905286, 6414907, -+ 4689584, 10604807, 36918461, 4782746 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 988979367990485, 1359729327576302, 1301834257246029, -+ 294141160829308, 29348272277475 -+#else -+ 65754325, 14736940, 59741422, 20261545, 7710541, 19398842, -+ 57127292, 4383044, 22546403, 437323 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1434382743317910, 100082049942065, 221102347892623, -+ 186982837860588, 1305765053501834 -+#else -+ 31665558, 21373968, 50922033, 1491338, 48740239, 3294681, -+ 27343084, 2786261, 36475274, 19457415 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2205916462268190, 499863829790820, 961960554686616, -+ 158062762756985, 1841471168298305 -+#else -+ 52641566, 32870716, 33734756, 7448551, 19294360, 14334329, -+ 47418233, 2355318, 47824193, 27440058 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1191737341426592, 1847042034978363, 1382213545049056, -+ 1039952395710448, 788812858896859 -+#else -+ 15121312, 17758270, 6377019, 27523071, 56310752, 20596586, -+ 18952176, 15496498, 37728731, 11754227 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1346965964571152, 1291881610839830, 2142916164336056, -+ 786821641205979, 1571709146321039 -+#else -+ 64471568, 20071356, 8488726, 19250536, 12728760, 31931939, -+ 7141595, 11724556, 22761615, 23420291 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 787164375951248, 202869205373189, 1356590421032140, -+ 1431233331032510, 786341368775957 -+#else -+ 16918416, 11729663, 49025285, 3022986, 36093132, 20214772, -+ 38367678, 21327038, 32851221, 11717399 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 492448143532951, 304105152670757, 1761767168301056, -+ 233782684697790, 1981295323106089 -+#else -+ 11166615, 7338049, 60386341, 4531519, 37640192, 26252376, -+ 31474878, 3483633, 65915689, 29523600 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 665807507761866, 1343384868355425, 895831046139653, -+ 439338948736892, 1986828765695105 -+#else -+ 66923210, 9921304, 31456609, 20017994, 55095045, 13348922, -+ 33142652, 6546660, 47123585, 29606055 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 756096210874553, 1721699973539149, 258765301727885, -+ 1390588532210645, 1212530909934781 -+#else -+ 34648249, 11266711, 55911757, 25655328, 31703693, 3855903, -+ 58571733, 20721383, 36336829, 18068118 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 852891097972275, 1816988871354562, 1543772755726524, -+ 1174710635522444, 202129090724628 -+#else -+ 49102387, 12709067, 3991746, 27075244, 45617340, 23004006, -+ 35973516, 17504552, 10928916, 3011958 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1205281565824323, 22430498399418, 992947814485516, -+ 1392458699738672, 688441466734558 -+#else -+ 60151107, 17960094, 31696058, 334240, 29576716, 14796075, -+ 36277808, 20749251, 18008030, 10258577 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1050627428414972, 1955849529137135, 2171162376368357, -+ 91745868298214, 447733118757826 -+#else -+ 44660220, 15655568, 7018479, 29144429, 36794597, 32352840, -+ 65255398, 1367119, 25127874, 6671743 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1287181461435438, 622722465530711, 880952150571872, -+ 741035693459198, 311565274989772 -+#else -+ 29701166, 19180498, 56230743, 9279287, 67091296, 13127209, -+ 21382910, 11042292, 25838796, 4642684 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1003649078149734, 545233927396469, 1849786171789880, -+ 1318943684880434, 280345687170552 -+#else -+ 46678630, 14955536, 42982517, 8124618, 61739576, 27563961, -+ 30468146, 19653792, 18423288, 4177476 -+#endif -+ }}, -+ }, -+ }, -+}; -+ -+#endif // CONFIG_SMALL -+ -+// Bi[i] = (2*i+1)*B -+static const ge_precomp Bi[8] = { -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1288382639258501, 245678601348599, 269427782077623, -+ 1462984067271730, 137412439391563 -+#else -+ 25967493, 19198397, 29566455, 3660896, 54414519, 4014786, 27544626, -+ 21800161, 61029707, 2047604 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 62697248952638, 204681361388450, 631292143396476, 338455783676468, -+ 1213667448819585 -+#else -+ 54563134, 934261, 64385954, 3049989, 66381436, 9406985, 12720692, -+ 5043384, 19500929, 18085054 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 301289933810280, 1259582250014073, 1422107436869536, -+ 796239922652654, 1953934009299142 -+#else -+ 58370664, 4489569, 9688441, 18769238, 10184608, 21191052, 29287918, -+ 11864899, 42594502, 29115885 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1601611775252272, 1720807796594148, 1132070835939856, -+ 1260455018889551, 2147779492816911 -+#else -+ 15636272, 23865875, 24204772, 25642034, 616976, 16869170, 27787599, -+ 18782243, 28944399, 32004408 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 316559037616741, 2177824224946892, 1459442586438991, -+ 1461528397712656, 751590696113597 -+#else -+ 16568933, 4717097, 55552716, 32452109, 15682895, 21747389, 16354576, -+ 21778470, 7689661, 11199574 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1850748884277385, 1200145853858453, 1068094770532492, -+ 672251375690438, 1586055907191707 -+#else -+ 30464137, 27578307, 55329429, 17883566, 23220364, 15915852, 7512774, -+ 10017326, 49359771, 23634074 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 769950342298419, 132954430919746, 844085933195555, 974092374476333, -+ 726076285546016 -+#else -+ 10861363, 11473154, 27284546, 1981175, 37044515, 12577860, 32867885, -+ 14515107, 51670560, 10819379 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 425251763115706, 608463272472562, 442562545713235, 837766094556764, -+ 374555092627893 -+#else -+ 4708026, 6336745, 20377586, 9066809, 55836755, 6594695, 41455196, -+ 12483687, 54440373, 5581305 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1086255230780037, 274979815921559, 1960002765731872, -+ 929474102396301, 1190409889297339 -+#else -+ 19563141, 16186464, 37722007, 4097518, 10237984, 29206317, 28542349, -+ 13850243, 43430843, 17738489 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 665000864555967, 2065379846933859, 370231110385876, 350988370788628, -+ 1233371373142985 -+#else -+ 5153727, 9909285, 1723747, 30776558, 30523604, 5516873, 19480852, -+ 5230134, 43156425, 18378665 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2019367628972465, 676711900706637, 110710997811333, -+ 1108646842542025, 517791959672113 -+#else -+ 36839857, 30090922, 7665485, 10083793, 28475525, 1649722, 20654025, -+ 16520125, 30598449, 7715701 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 965130719900578, 247011430587952, 526356006571389, 91986625355052, -+ 2157223321444601 -+#else -+ 28881826, 14381568, 9657904, 3680757, 46927229, 7843315, 35708204, -+ 1370707, 29794553, 32145132 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1802695059465007, 1664899123557221, 593559490740857, -+ 2160434469266659, 927570450755031 -+#else -+ 44589871, 26862249, 14201701, 24808930, 43598457, 8844725, 18474211, -+ 32192982, 54046167, 13821876 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1725674970513508, 1933645953859181, 1542344539275782, -+ 1767788773573747, 1297447965928905 -+#else -+ 60653668, 25714560, 3374701, 28813570, 40010246, 22982724, 31655027, -+ 26342105, 18853321, 19333481 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1381809363726107, 1430341051343062, 2061843536018959, -+ 1551778050872521, 2036394857967624 -+#else -+ 4566811, 20590564, 38133974, 21313742, 59506191, 30723862, 58594505, -+ 23123294, 2207752, 30344648 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1970894096313054, 528066325833207, 1619374932191227, -+ 2207306624415883, 1169170329061080 -+#else -+ 41954014, 29368610, 29681143, 7868801, 60254203, 24130566, 54671499, -+ 32891431, 35997400, 17421995 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 2070390218572616, 1458919061857835, 624171843017421, -+ 1055332792707765, 433987520732508 -+#else -+ 25576264, 30851218, 7349803, 21739588, 16472781, 9300885, 3844789, -+ 15725684, 171356, 6466918 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 893653801273833, 1168026499324677, 1242553501121234, -+ 1306366254304474, 1086752658510815 -+#else -+ 23103977, 13316479, 9739013, 17404951, 817874, 18515490, 8965338, -+ 19466374, 36393951, 16193876 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 213454002618221, 939771523987438, 1159882208056014, 317388369627517, -+ 621213314200687 -+#else -+ 33587053, 3180712, 64714734, 14003686, 50205390, 17283591, 17238397, -+ 4729455, 49034351, 9256799 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1971678598905747, 338026507889165, 762398079972271, 655096486107477, -+ 42299032696322 -+#else -+ 41926547, 29380300, 32336397, 5036987, 45872047, 11360616, 22616405, -+ 9761698, 47281666, 630304 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 177130678690680, 1754759263300204, 1864311296286618, -+ 1180675631479880, 1292726903152791 -+#else -+ 53388152, 2639452, 42871404, 26147950, 9494426, 27780403, 60554312, -+ 17593437, 64659607, 19263131 -+#endif -+ }}, -+ }, -+ { -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1913163449625248, 460779200291993, 2193883288642314, -+ 1008900146920800, 1721983679009502 -+#else -+ 63957664, 28508356, 9282713, 6866145, 35201802, 32691408, 48168288, -+ 15033783, 25105118, 25659556 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 1070401523076875, 1272492007800961, 1910153608563310, -+ 2075579521696771, 1191169788841221 -+#else -+ 42782475, 15950225, 35307649, 18961608, 55446126, 28463506, 1573891, -+ 30928545, 2198789, 17749813 -+#endif -+ }}, -+ {{ -+#if defined(BORINGSSL_CURVE25519_64BIT) -+ 692896803108118, 500174642072499, 2068223309439677, -+ 1162190621851337, 1426986007309901 -+#else -+ 64009494, 10324966, 64867251, 7453182, 61661885, 30818928, 53296841, -+ 17317989, 34647629, 21263748 -+#endif -+ }}, -+ }, -+}; -diff --git a/src/plugins/preauth/spake/groups.c b/src/plugins/preauth/spake/groups.c -new file mode 100644 -index 000000000..a195cc195 ---- /dev/null -+++ b/src/plugins/preauth/spake/groups.c -@@ -0,0 +1,442 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* plugins/preauth/spake/groups.c - SPAKE group interfaces */ -+/* -+ * Copyright (C) 2015 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+/* -+ * The SPAKE2 algorithm works as follows: -+ * -+ * 1. The parties agree on a group, a base element G, and constant elements M -+ * and N. In this mechanism, these parameters are determined by the -+ * registered group number. -+ * 2. Both parties derive a scalar value w from the initial key. -+ * 3. The first party (the KDC, in this mechanism) chooses a random secret -+ * scalar x and sends T=xG+wM. -+ * 4. The second party (the client, in this mechanism) chooses a random -+ * secret scalar y and sends S=yG+wN. -+ * 5. The first party computes K=x(S-wN). -+ * 6. The second party computes the same value as K=y(T-wM). -+ * 7. Both parties derive a key from a random oracle whose input incorporates -+ * the party identities, w, T, S, and K. -+ * -+ * We implement the algorithm using a vtable for each group, where the primary -+ * vtable methods are "keygen" (corresponding to step 3 or 4) and "result" -+ * (corresponding to step 5 or 6). We use the term "private scalar" to refer -+ * to x or y, and "public element" to refer to S or T. -+ */ -+ -+#include "iana.h" -+#include "trace.h" -+#include "groups.h" -+ -+#define DEFAULT_GROUPS_CLIENT "edwards25519" -+#define DEFAULT_GROUPS_KDC "" -+ -+typedef struct groupent_st { -+ const groupdef *gdef; -+ groupdata *gdata; -+} groupent; -+ -+struct groupstate_st { -+ krb5_boolean is_kdc; -+ -+ /* Permitted and groups, from configuration */ -+ int32_t *permitted; -+ size_t npermitted; -+ -+ /* Optimistic challenge group, from configuration */ -+ int32_t challenge_group; -+ -+ /* Lazily-initialized list of gdata objects. */ -+ groupent *data; -+ size_t ndata; -+}; -+ -+extern groupdef builtin_edwards25519; -+#ifdef SPAKE_OPENSSL -+extern groupdef ossl_P256; -+extern groupdef ossl_P384; -+extern groupdef ossl_P521; -+#endif -+ -+static const groupdef *groupdefs[] = { -+ &builtin_edwards25519, -+#ifdef SPAKE_OPENSSL -+ &ossl_P256, -+ &ossl_P384, -+ &ossl_P521, -+#endif -+ NULL -+}; -+ -+/* Find a groupdef structure by group number. Return NULL on failure. */ -+static const groupdef * -+find_gdef(int32_t group) -+{ -+ size_t i; -+ -+ for (i = 0; groupdefs[i] != NULL; i++) { -+ if (groupdefs[i]->reg->id == group) -+ return groupdefs[i]; -+ } -+ -+ return NULL; -+} -+ -+/* Find a group number by name. Return 0 on failure. */ -+static int32_t -+find_gnum(const char *name) -+{ -+ size_t i; -+ -+ for (i = 0; groupdefs[i] != NULL; i++) { -+ if (strcasecmp(name, groupdefs[i]->reg->name) == 0) -+ return groupdefs[i]->reg->id; -+ } -+ return 0; -+} -+ -+static krb5_boolean -+in_grouplist(const int32_t *list, size_t count, int32_t group) -+{ -+ size_t i; -+ -+ for (i = 0; i < count; i++) { -+ if (list[i] == group) -+ return TRUE; -+ } -+ -+ return FALSE; -+} -+ -+/* Retrieve a group data object for group within gstate, lazily initializing it -+ * if necessary. */ -+static krb5_error_code -+get_gdata(krb5_context context, groupstate *gstate, const groupdef *gdef, -+ groupdata **gdata_out) -+{ -+ krb5_error_code ret; -+ groupent *ent, *newptr; -+ -+ *gdata_out = NULL; -+ -+ /* Look for an existing entry. */ -+ for (ent = gstate->data; ent < gstate->data + gstate->ndata; ent++) { -+ if (ent->gdef == gdef) { -+ *gdata_out = ent->gdata; -+ return 0; -+ } -+ } -+ -+ /* Make a new entry. */ -+ newptr = realloc(gstate->data, (gstate->ndata + 1) * sizeof(groupent)); -+ if (newptr == NULL) -+ return ENOMEM; -+ gstate->data = newptr; -+ ent = &gstate->data[gstate->ndata]; -+ ent->gdef = gdef; -+ ent->gdata = NULL; -+ if (gdef->init != NULL) { -+ ret = gdef->init(context, gdef, &ent->gdata); -+ if (ret) -+ return ret; -+ } -+ gstate->ndata++; -+ *gdata_out = ent->gdata; -+ return 0; -+} -+ -+/* Destructively parse str into a list of group numbers. */ -+static krb5_error_code -+parse_groups(krb5_context context, char *str, int32_t **list_out, -+ size_t *count_out) -+{ -+ const char *const delim = " \t\r\n,"; -+ char *token, *save = NULL; -+ int32_t group, *newptr, *list = NULL; -+ size_t count = 0; -+ -+ *list_out = NULL; -+ *count_out = 0; -+ -+ /* Walk through the words in profstr. */ -+ for (token = strtok_r(str, delim, &save); token != NULL; -+ token = strtok_r(NULL, delim, &save)) { -+ group = find_gnum(token); -+ if (!group) { -+ TRACE_SPAKE_UNKNOWN_GROUP(context, token); -+ continue; -+ } -+ if (in_grouplist(list, count, group)) -+ continue; -+ newptr = realloc(list, (count + 1) * sizeof(*list)); -+ if (newptr == NULL) { -+ free(list); -+ return ENOMEM; -+ } -+ list = newptr; -+ list[count++] = group; -+ } -+ -+ *list_out = list; -+ *count_out = count; -+ return 0; -+} -+ -+krb5_error_code -+group_init_state(krb5_context context, krb5_boolean is_kdc, -+ groupstate **gstate_out) -+{ -+ krb5_error_code ret; -+ groupstate *gstate; -+ const char *defgroups; -+ char *profstr1 = NULL, *profstr2 = NULL; -+ int32_t *permitted = NULL, challenge_group = 0; -+ size_t npermitted; -+ -+ *gstate_out = NULL; -+ -+ defgroups = is_kdc ? DEFAULT_GROUPS_KDC : DEFAULT_GROUPS_CLIENT; -+ ret = profile_get_string(context->profile, KRB5_CONF_LIBDEFAULTS, -+ KRB5_CONF_SPAKE_PREAUTH_GROUPS, NULL, defgroups, -+ &profstr1); -+ if (ret) -+ goto cleanup; -+ ret = parse_groups(context, profstr1, &permitted, &npermitted); -+ if (ret) -+ goto cleanup; -+ if (npermitted == 0) { -+ ret = KRB5_PLUGIN_OP_NOTSUPP; -+ k5_setmsg(context, ret, _("No SPAKE preauth groups configured")); -+ goto cleanup; -+ } -+ -+ if (is_kdc) { -+ /* -+ * Check for a configured optimistic challenge group. If one is set, -+ * the KDC will send a challenge in the PREAUTH_REQUIRED method data, -+ * before receiving the list of supported groups. -+ */ -+ ret = profile_get_string(context->profile, KRB5_CONF_KDCDEFAULTS, -+ KRB5_CONF_SPAKE_PREAUTH_KDC_CHALLENGE, NULL, -+ NULL, &profstr2); -+ if (ret) -+ goto cleanup; -+ if (profstr2 != NULL) { -+ challenge_group = find_gnum(profstr2); -+ if (!in_grouplist(permitted, npermitted, challenge_group)) { -+ ret = KRB5_PLUGIN_OP_NOTSUPP; -+ k5_setmsg(context, ret, -+ _("SPAKE challenge group not a permitted group: %s"), -+ profstr2); -+ goto cleanup; -+ } -+ } -+ } -+ -+ gstate = k5alloc(sizeof(*gstate), &ret); -+ if (gstate == NULL) -+ goto cleanup; -+ gstate->is_kdc = is_kdc; -+ gstate->permitted = permitted; -+ gstate->npermitted = npermitted; -+ gstate->challenge_group = challenge_group; -+ permitted = NULL; -+ gstate->data = NULL; -+ gstate->ndata = 0; -+ *gstate_out = gstate; -+ -+cleanup: -+ profile_release_string(profstr1); -+ profile_release_string(profstr2); -+ free(permitted); -+ return ret; -+} -+ -+ -+void -+group_free_state(groupstate *gstate) -+{ -+ groupent *ent; -+ -+ for (ent = gstate->data; ent < gstate->data + gstate->ndata; ent++) { -+ if (ent->gdata != NULL && ent->gdef->fini != NULL) -+ ent->gdef->fini(ent->gdata); -+ } -+ -+ free(gstate->permitted); -+ free(gstate->data); -+ free(gstate); -+} -+ -+krb5_boolean -+group_is_permitted(groupstate *gstate, int32_t group) -+{ -+ return in_grouplist(gstate->permitted, gstate->npermitted, group); -+} -+ -+void -+group_get_permitted(groupstate *gstate, int32_t **list_out, int32_t *count_out) -+{ -+ *list_out = gstate->permitted; -+ *count_out = gstate->npermitted; -+} -+ -+krb5_int32 -+group_optimistic_challenge(groupstate *gstate) -+{ -+ assert(gstate->is_kdc); -+ return gstate->challenge_group; -+} -+ -+krb5_error_code -+group_mult_len(int32_t group, size_t *len_out) -+{ -+ const groupdef *gdef; -+ -+ *len_out = 0; -+ gdef = find_gdef(group); -+ if (gdef == NULL) -+ return EINVAL; -+ *len_out = gdef->reg->mult_len; -+ return 0; -+} -+ -+krb5_error_code -+group_keygen(krb5_context context, groupstate *gstate, int32_t group, -+ const krb5_data *wbytes, krb5_data *priv_out, krb5_data *pub_out) -+{ -+ krb5_error_code ret; -+ const groupdef *gdef; -+ groupdata *gdata; -+ uint8_t *priv = NULL, *pub = NULL; -+ -+ *priv_out = empty_data(); -+ *pub_out = empty_data(); -+ gdef = find_gdef(group); -+ if (gdef == NULL || wbytes->length != gdef->reg->mult_len) -+ return EINVAL; -+ ret = get_gdata(context, gstate, gdef, &gdata); -+ if (ret) -+ return ret; -+ -+ priv = k5alloc(gdef->reg->mult_len, &ret); -+ if (priv == NULL) -+ goto cleanup; -+ pub = k5alloc(gdef->reg->elem_len, &ret); -+ if (pub == NULL) -+ goto cleanup; -+ -+ ret = gdef->keygen(context, gdata, (uint8_t *)wbytes->data, gstate->is_kdc, -+ priv, pub); -+ if (ret) -+ goto cleanup; -+ -+ *priv_out = make_data(priv, gdef->reg->mult_len); -+ *pub_out = make_data(pub, gdef->reg->elem_len); -+ priv = pub = NULL; -+ TRACE_SPAKE_KEYGEN(context, pub_out); -+ -+cleanup: -+ zapfree(priv, gdef->reg->mult_len); -+ free(pub); -+ return ret; -+} -+ -+krb5_error_code -+group_result(krb5_context context, groupstate *gstate, int32_t group, -+ const krb5_data *wbytes, const krb5_data *ourpriv, -+ const krb5_data *theirpub, krb5_data *spakeresult_out) -+{ -+ krb5_error_code ret; -+ const groupdef *gdef; -+ groupdata *gdata; -+ uint8_t *spakeresult = NULL; -+ -+ *spakeresult_out = empty_data(); -+ gdef = find_gdef(group); -+ if (gdef == NULL || wbytes->length != gdef->reg->mult_len) -+ return EINVAL; -+ if (ourpriv->length != gdef->reg->mult_len || -+ theirpub->length != gdef->reg->elem_len) -+ return EINVAL; -+ ret = get_gdata(context, gstate, gdef, &gdata); -+ if (ret) -+ return ret; -+ -+ spakeresult = k5alloc(gdef->reg->elem_len, &ret); -+ if (spakeresult == NULL) -+ goto cleanup; -+ -+ /* Invert is_kdc here to use the other party's constant. */ -+ ret = gdef->result(context, gdata, (uint8_t *)wbytes->data, -+ (uint8_t *)ourpriv->data, (uint8_t *)theirpub->data, -+ !gstate->is_kdc, spakeresult); -+ if (ret) -+ goto cleanup; -+ -+ *spakeresult_out = make_data(spakeresult, gdef->reg->elem_len); -+ spakeresult = NULL; -+ TRACE_SPAKE_RESULT(context, spakeresult_out); -+ -+cleanup: -+ zapfree(spakeresult, gdef->reg->elem_len); -+ return ret; -+} -+ -+krb5_error_code -+group_hash_len(int32_t group, size_t *len_out) -+{ -+ const groupdef *gdef; -+ -+ *len_out = 0; -+ gdef = find_gdef(group); -+ if (gdef == NULL) -+ return EINVAL; -+ *len_out = gdef->reg->hash_len; -+ return 0; -+} -+ -+krb5_error_code -+group_hash(krb5_context context, groupstate *gstate, int32_t group, -+ const krb5_data *dlist, size_t ndata, uint8_t *result_out) -+{ -+ krb5_error_code ret; -+ const groupdef *gdef; -+ groupdata *gdata; -+ -+ gdef = find_gdef(group); -+ if (gdef == NULL) -+ return EINVAL; -+ ret = get_gdata(context, gstate, gdef, &gdata); -+ if (ret) -+ return ret; -+ return gdef->hash(context, gdata, dlist, ndata, result_out); -+} -diff --git a/src/plugins/preauth/spake/groups.h b/src/plugins/preauth/spake/groups.h -new file mode 100644 -index 000000000..3add69494 ---- /dev/null -+++ b/src/plugins/preauth/spake/groups.h -@@ -0,0 +1,148 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* plugins/preauth/spake/groups.h - SPAKE group interfaces */ -+/* -+ * Copyright (C) 2015 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#ifndef GROUPS_H -+#define GROUPS_H -+ -+#include "k5-int.h" -+#include "iana.h" -+ -+typedef struct groupstate_st groupstate; -+typedef struct groupdata_st groupdata; -+typedef struct groupdef_st groupdef; -+ -+struct groupdef_st { -+ const spake_iana *reg; -+ -+ /* -+ * Optional: create a per-group data object to allow more efficient keygen -+ * and result computations. Saving a reference to gdef is okay; its -+ * lifetime will always be longer than the resulting object. -+ */ -+ krb5_error_code (*init)(krb5_context context, const groupdef *gdef, -+ groupdata **gdata_out); -+ -+ /* Optional: release a group data object. */ -+ void (*fini)(groupdata *gdata); -+ -+ /* -+ * Mandatory: generate a random private scalar (x or y) and a public -+ * element (T or S), using wbytes for the w value. If use_m is true, use -+ * the M element (generating T); otherwise use the N element (generating -+ * S). wbytes and priv_out have length reg->mult_len; pub_out has length -+ * reg->elem_len. priv_out and pub_out are caller-allocated. -+ */ -+ krb5_error_code (*keygen)(krb5_context context, groupdata *gdata, -+ const uint8_t *wbytes, krb5_boolean use_m, -+ uint8_t *priv_out, uint8_t *pub_out); -+ -+ /* -+ * Mandatory: compute K given a private scalar (x or y) and the other -+ * party's public element (S or T), using wbytes for the w value. If use_m -+ * is true, use the M element (computing K from y and T); otherwise use the -+ * N element (computing K from x and S). wbytes and ourpriv have length -+ * reg->mult_len; theirpub and elem_out have length reg->elem_len. -+ * elem_out is caller-allocated. -+ */ -+ krb5_error_code (*result)(krb5_context context, groupdata *gdata, -+ const uint8_t *wbytes, const uint8_t *ourpriv, -+ const uint8_t *theirpub, krb5_boolean use_m, -+ uint8_t *elem_out); -+ -+ /* -+ * Mandatory: compute the group's specified hash function over datas (with -+ * ndata elements), placing the result in result_out. result_out is -+ * caller-allocated with length reg->hash_len. -+ */ -+ krb5_error_code (*hash)(krb5_context context, groupdata *gdata, -+ const krb5_data *datas, size_t ndata, -+ uint8_t *result_out); -+}; -+ -+/* Initialize an object which holds group configuration and pre-computation -+ * state for each group. is_kdc is true for KDCs, false for clients. */ -+krb5_error_code group_init_state(krb5_context context, krb5_boolean is_kdc, -+ groupstate **out); -+ -+/* Release resources held by gstate. */ -+void group_free_state(groupstate *gstate); -+ -+/* Return true if group is permitted by configuration. */ -+krb5_boolean group_is_permitted(groupstate *gstate, int32_t group); -+ -+/* Set *list_out and *count_out to the list of groups permitted by -+ * configuration. */ -+void group_get_permitted(groupstate *gstate, int32_t **list_out, -+ int32_t *count_out); -+ -+/* Return the KDC optimistic challenge group if one is configured. Valid for -+ * KDC groupstate objects only. */ -+krb5_int32 group_optimistic_challenge(groupstate *gstate); -+ -+/* Set *len_out to the multiplier length for group. */ -+krb5_error_code group_mult_len(int32_t group, size_t *len_out); -+ -+/* -+ * Generate a SPAKE private scalar (x or y) and public element (T or S), given -+ * an input multiplier wbytes. Use constant M if gstate is a KDC groupstate -+ * object, N if it is a client object. Allocate storage and place the results -+ * in *priv_out and *pub_out. -+ */ -+krb5_error_code group_keygen(krb5_context context, groupstate *gstate, -+ int32_t group, const krb5_data *wbytes, -+ krb5_data *priv_out, krb5_data *pub_out); -+ -+/* -+ * Compute the SPAKE result K from our private scalar (x or y) and their public -+ * key (S or T), deriving the input scalar w from ikey. Use the other party's -+ * constant, N if gstate is a KDC groupstate object or M if it is a client -+ * object. Allocate storage and place the result in *spakeresult_out. -+ */ -+krb5_error_code group_result(krb5_context context, groupstate *gstate, -+ int32_t group, const krb5_data *wbytes, -+ const krb5_data *ourpriv, -+ const krb5_data *theirpub, -+ krb5_data *spakeresult_out); -+ -+/* Set *result_out to the hash output length for group. */ -+krb5_error_code group_hash_len(int32_t group, size_t *result_out); -+ -+/* -+ * Compute the group's specified hash function over dlist (with ndata -+ * elements). result_out is caller-allocated with enough bytes for the hash -+ * output as given by group_hash_len(). -+ */ -+krb5_error_code group_hash(krb5_context context, groupstate *gstate, -+ int32_t group, const krb5_data *dlist, size_t ndata, -+ uint8_t *result_out); -+ -+#endif /* GROUPS_H */ -diff --git a/src/plugins/preauth/spake/iana.c b/src/plugins/preauth/spake/iana.c -new file mode 100644 -index 000000000..e7901dedf ---- /dev/null -+++ b/src/plugins/preauth/spake/iana.c -@@ -0,0 +1,108 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* plugins/preauth/spake/iana.c - SPAKE IANA registry contents */ -+/* -+ * Copyright (C) 2015 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include "iana.h" -+ -+static uint8_t edwards25519_M[] = { -+ 0xD0, 0x48, 0x03, 0x2C, 0x6E, 0xA0, 0xB6, 0xD6, 0x97, 0xDD, 0xC2, 0xE8, -+ 0x6B, 0xDA, 0x85, 0xA3, 0x3A, 0xDA, 0xC9, 0x20, 0xF1, 0xBF, 0x18, 0xE1, -+ 0xB0, 0xC6, 0xD1, 0x66, 0xA5, 0xCE, 0xCD, 0xAF -+}; -+ -+static uint8_t edwards25519_N[] = { -+ 0xD3, 0xBF, 0xB5, 0x18, 0xF4, 0x4F, 0x34, 0x30, 0xF2, 0x9D, 0x0C, 0x92, -+ 0xAF, 0x50, 0x38, 0x65, 0xA1, 0xED, 0x32, 0x81, 0xDC, 0x69, 0xB3, 0x5D, -+ 0xD8, 0x68, 0xBA, 0x85, 0xF8, 0x86, 0xC4, 0xAB -+}; -+ -+static uint8_t P256_M[] = { -+ 0x02, 0x88, 0x6E, 0x2F, 0x97, 0xAC, 0xE4, 0x6E, 0x55, 0xBA, 0x9D, 0xD7, -+ 0x24, 0x25, 0x79, 0xF2, 0x99, 0x3B, 0x64, 0xE1, 0x6E, 0xF3, 0xDC, 0xAB, -+ 0x95, 0xAF, 0xD4, 0x97, 0x33, 0x3D, 0x8F, 0xA1, 0x2F -+}; -+ -+static uint8_t P256_N[] = { -+ 0x03, 0xD8, 0xBB, 0xD6, 0xC6, 0x39, 0xC6, 0x29, 0x37, 0xB0, 0x4D, 0x99, -+ 0x7F, 0x38, 0xC3, 0x77, 0x07, 0x19, 0xC6, 0x29, 0xD7, 0x01, 0x4D, 0x49, -+ 0xA2, 0x4B, 0x4F, 0x98, 0xBA, 0xA1, 0x29, 0x2B, 0x49 -+}; -+ -+static uint8_t P384_M[] = { -+ 0x03, 0x0F, 0xF0, 0x89, 0x5A, 0xE5, 0xEB, 0xF6, 0x18, 0x70, 0x80, 0xA8, -+ 0x2D, 0x82, 0xB4, 0x2E, 0x27, 0x65, 0xE3, 0xB2, 0xF8, 0x74, 0x9C, 0x7E, -+ 0x05, 0xEB, 0xA3, 0x66, 0x43, 0x4B, 0x36, 0x3D, 0x3D, 0xC3, 0x6F, 0x15, -+ 0x31, 0x47, 0x39, 0x07, 0x4D, 0x2E, 0xB8, 0x61, 0x3F, 0xCE, 0xEC, 0x28, -+ 0x53 -+}; -+ -+static uint8_t P384_N[] = { -+ 0x02, 0xC7, 0x2C, 0xF2, 0xE3, 0x90, 0x85, 0x3A, 0x1C, 0x1C, 0x4A, 0xD8, -+ 0x16, 0xA6, 0x2F, 0xD1, 0x58, 0x24, 0xF5, 0x60, 0x78, 0x91, 0x8F, 0x43, -+ 0xF9, 0x22, 0xCA, 0x21, 0x51, 0x8F, 0x9C, 0x54, 0x3B, 0xB2, 0x52, 0xC5, -+ 0x49, 0x02, 0x14, 0xCF, 0x9A, 0xA3, 0xF0, 0xBA, 0xAB, 0x4B, 0x66, 0x5C, -+ 0x10 -+}; -+ -+static uint8_t P521_M[] = { -+ 0x02, 0x00, 0x3F, 0x06, 0xF3, 0x81, 0x31, 0xB2, 0xBA, 0x26, 0x00, 0x79, -+ 0x1E, 0x82, 0x48, 0x8E, 0x8D, 0x20, 0xAB, 0x88, 0x9A, 0xF7, 0x53, 0xA4, -+ 0x18, 0x06, 0xC5, 0xDB, 0x18, 0xD3, 0x7D, 0x85, 0x60, 0x8C, 0xFA, 0xE0, -+ 0x6B, 0x82, 0xE4, 0xA7, 0x2C, 0xD7, 0x44, 0xC7, 0x19, 0x19, 0x35, 0x62, -+ 0xA6, 0x53, 0xEA, 0x1F, 0x11, 0x9E, 0xEF, 0x93, 0x56, 0x90, 0x7E, 0xDC, -+ 0x9B, 0x56, 0x97, 0x99, 0x62, 0xD7, 0xAA -+}; -+ -+static uint8_t P521_N[] = { -+ 0x02, 0x00, 0xC7, 0x92, 0x4B, 0x9E, 0xC0, 0x17, 0xF3, 0x09, 0x45, 0x62, -+ 0x89, 0x43, 0x36, 0xA5, 0x3C, 0x50, 0x16, 0x7B, 0xA8, 0xC5, 0x96, 0x38, -+ 0x76, 0x88, 0x05, 0x42, 0xBC, 0x66, 0x9E, 0x49, 0x4B, 0x25, 0x32, 0xD7, -+ 0x6C, 0x5B, 0x53, 0xDF, 0xB3, 0x49, 0xFD, 0xF6, 0x91, 0x54, 0xB9, 0xE0, -+ 0x04, 0x8C, 0x58, 0xA4, 0x2E, 0x8E, 0xD0, 0x4C, 0xEF, 0x05, 0x2A, 0x3B, -+ 0xC3, 0x49, 0xD9, 0x55, 0x75, 0xCD, 0x25 -+}; -+ -+const spake_iana spake_iana_edwards25519 = { -+ SPAKE_GROUP_EDWARDS25519, "edwards25519", 32, 32, -+ edwards25519_M, edwards25519_N, 32 -+}; -+ -+const spake_iana spake_iana_p256 = { -+ SPAKE_GROUP_P256, "P-256", 32, 33, P256_M, P256_N, 32 -+}; -+ -+const spake_iana spake_iana_p384 = { -+ SPAKE_GROUP_P384, "P-384", 48, 49, P384_M, P384_N, 48 -+}; -+ -+const spake_iana spake_iana_p521 = { -+ SPAKE_GROUP_P521, "P-521", 66, 67, P521_M, P521_N, 64 -+}; -diff --git a/src/plugins/preauth/spake/iana.h b/src/plugins/preauth/spake/iana.h -new file mode 100644 -index 000000000..1d99c4dd6 ---- /dev/null -+++ b/src/plugins/preauth/spake/iana.h -@@ -0,0 +1,65 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* plugins/preauth/spake/iana.h - SPAKE IANA registry contents */ -+/* -+ * Copyright (C) 2015 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#ifndef IANA_H -+#define IANA_H -+ -+#include -+#include -+ -+typedef enum { -+ SPAKE_SF_NONE = 1, -+} spake_sf_type; -+ -+typedef enum { -+ SPAKE_GROUP_EDWARDS25519 = 1, -+ SPAKE_GROUP_P256 = 2, -+ SPAKE_GROUP_P384 = 3, -+ SPAKE_GROUP_P521 = 4, -+} spake_group; -+ -+typedef struct { -+ int32_t id; -+ const char *name; -+ size_t mult_len; -+ size_t elem_len; -+ const uint8_t *m; -+ const uint8_t *n; -+ size_t hash_len; -+} spake_iana; -+ -+extern const spake_iana spake_iana_edwards25519; -+extern const spake_iana spake_iana_p256; -+extern const spake_iana spake_iana_p384; -+extern const spake_iana spake_iana_p521; -+ -+#endif /* IANA_H */ -diff --git a/src/plugins/preauth/spake/openssl.c b/src/plugins/preauth/spake/openssl.c -new file mode 100644 -index 000000000..b821a9158 ---- /dev/null -+++ b/src/plugins/preauth/spake/openssl.c -@@ -0,0 +1,315 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* plugins/preauth/spake/openssl.c - SPAKE implementations using OpenSSL */ -+/* -+ * Copyright (C) 2015 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include "k5-int.h" -+ -+#include "groups.h" -+#include "iana.h" -+ -+#ifdef SPAKE_OPENSSL -+#include -+#include -+#include -+#include -+ -+/* OpenSSL 1.1 standardizes constructor and destructor names, renaming -+ * EVP_MD_CTX_create and EVP_MD_CTX_destroy. */ -+#if OPENSSL_VERSION_NUMBER < 0x10100000L -+#define EVP_MD_CTX_new EVP_MD_CTX_create -+#define EVP_MD_CTX_free EVP_MD_CTX_destroy -+#endif -+ -+struct groupdata_st { -+ const groupdef *gdef; -+ EC_GROUP *group; -+ BIGNUM *order; -+ BN_CTX *ctx; -+ EC_POINT *M; -+ EC_POINT *N; -+ const EVP_MD *md; -+}; -+ -+static void -+ossl_fini(groupdata *gd) -+{ -+ if (gd == NULL) -+ return; -+ -+ EC_GROUP_free(gd->group); -+ EC_POINT_free(gd->M); -+ EC_POINT_free(gd->N); -+ BN_CTX_free(gd->ctx); -+ BN_free(gd->order); -+} -+ -+static krb5_error_code -+ossl_init(krb5_context context, const groupdef *gdef, groupdata **gdata_out) -+{ -+ const spake_iana *reg = gdef->reg; -+ const EVP_MD *md; -+ groupdata *gd; -+ int nid; -+ -+ switch (reg->id) { -+ case SPAKE_GROUP_P256: -+ nid = NID_X9_62_prime256v1; -+ md = EVP_sha256(); -+ break; -+ case SPAKE_GROUP_P384: -+ nid = NID_secp384r1; -+ md = EVP_sha384(); -+ break; -+ case SPAKE_GROUP_P521: -+ nid = NID_secp521r1; -+ md = EVP_sha512(); -+ break; -+ default: -+ return EINVAL; -+ }; -+ -+ gd = calloc(1, sizeof(*gd)); -+ if (gd == NULL) -+ return ENOMEM; -+ gd->gdef = gdef; -+ -+ gd->group = EC_GROUP_new_by_curve_name(nid); -+ if (gd->group == NULL) -+ goto error; -+ -+ gd->ctx = BN_CTX_new(); -+ if (gd->ctx == NULL) -+ goto error; -+ -+ gd->order = BN_new(); -+ if (gd->order == NULL) -+ goto error; -+ if (!EC_GROUP_get_order(gd->group, gd->order, gd->ctx)) -+ goto error; -+ -+ gd->M = EC_POINT_new(gd->group); -+ if (gd->M == NULL) -+ goto error; -+ if (!EC_POINT_oct2point(gd->group, gd->M, reg->m, reg->elem_len, gd->ctx)) -+ goto error; -+ -+ gd->N = EC_POINT_new(gd->group); -+ if (gd->N == NULL) -+ goto error; -+ if (!EC_POINT_oct2point(gd->group, gd->N, reg->n, reg->elem_len, gd->ctx)) -+ goto error; -+ -+ gd->md = md; -+ -+ *gdata_out = gd; -+ return 0; -+ -+error: -+ ossl_fini(gd); -+ return ENOMEM; -+} -+ -+/* Convert pseudo-random bytes into a scalar value in constant time. -+ * Return NULL on failure. */ -+static BIGNUM * -+unmarshal_w(const groupdata *gdata, const uint8_t *wbytes) -+{ -+ const spake_iana *reg = gdata->gdef->reg; -+ BIGNUM *w = NULL; -+ -+ w = BN_new(); -+ if (w == NULL) -+ return NULL; -+ -+ BN_set_flags(w, BN_FLG_CONSTTIME); -+ -+ if (BN_bin2bn(wbytes, reg->mult_len, w) && -+ BN_div(NULL, w, w, gdata->order, gdata->ctx)) -+ return w; -+ -+ BN_free(w); -+ return NULL; -+} -+ -+static krb5_error_code -+ossl_keygen(krb5_context context, groupdata *gdata, const uint8_t *wbytes, -+ krb5_boolean use_m, uint8_t *priv_out, uint8_t *pub_out) -+{ -+ const spake_iana *reg = gdata->gdef->reg; -+ const EC_POINT *constant = use_m ? gdata->M : gdata->N; -+ krb5_boolean success = FALSE; -+ EC_POINT *pub = NULL; -+ BIGNUM *priv = NULL, *w = NULL; -+ size_t len; -+ -+ w = unmarshal_w(gdata, wbytes); -+ if (w == NULL) -+ goto cleanup; -+ -+ pub = EC_POINT_new(gdata->group); -+ if (pub == NULL) -+ goto cleanup; -+ -+ priv = BN_new(); -+ if (priv == NULL) -+ goto cleanup; -+ -+ if (!BN_rand_range(priv, gdata->order)) -+ goto cleanup; -+ -+ /* Compute priv*G + w*constant; EC_POINT_mul() does this in one call. */ -+ if (!EC_POINT_mul(gdata->group, pub, priv, constant, w, gdata->ctx)) -+ goto cleanup; -+ -+ /* Marshal priv into priv_out. */ -+ memset(priv_out, 0, reg->mult_len); -+ BN_bn2bin(priv, &priv_out[reg->mult_len - BN_num_bytes(priv)]); -+ -+ /* Marshal pub into pub_out. */ -+ len = EC_POINT_point2oct(gdata->group, pub, POINT_CONVERSION_COMPRESSED, -+ pub_out, reg->elem_len, gdata->ctx); -+ if (len != reg->elem_len) -+ goto cleanup; -+ -+ success = TRUE; -+ -+cleanup: -+ EC_POINT_free(pub); -+ BN_clear_free(priv); -+ BN_clear_free(w); -+ return success ? 0 : ENOMEM; -+} -+ -+static krb5_error_code -+ossl_result(krb5_context context, groupdata *gdata, const uint8_t *wbytes, -+ const uint8_t *ourpriv, const uint8_t *theirpub, -+ krb5_boolean use_m, uint8_t *elem_out) -+{ -+ const spake_iana *reg = gdata->gdef->reg; -+ const EC_POINT *constant = use_m ? gdata->M : gdata->N; -+ krb5_boolean success = FALSE, invalid = FALSE; -+ EC_POINT *result = NULL, *pub = NULL; -+ BIGNUM *priv = NULL, *w = NULL; -+ size_t len; -+ -+ w = unmarshal_w(gdata, wbytes); -+ if (w == NULL) -+ goto cleanup; -+ -+ priv = BN_bin2bn(ourpriv, reg->mult_len, NULL); -+ if (priv == NULL) -+ goto cleanup; -+ -+ pub = EC_POINT_new(gdata->group); -+ if (pub == NULL) -+ goto cleanup; -+ if (!EC_POINT_oct2point(gdata->group, pub, theirpub, reg->elem_len, -+ gdata->ctx)) { -+ invalid = TRUE; -+ goto cleanup; -+ } -+ -+ /* Compute result = priv*(pub - w*constant), using result to hold the -+ * intermediate steps. */ -+ result = EC_POINT_new(gdata->group); -+ if (result == NULL) -+ goto cleanup; -+ if (!EC_POINT_mul(gdata->group, result, NULL, constant, w, gdata->ctx)) -+ goto cleanup; -+ if (!EC_POINT_invert(gdata->group, result, gdata->ctx)) -+ goto cleanup; -+ if (!EC_POINT_add(gdata->group, result, pub, result, gdata->ctx)) -+ goto cleanup; -+ if (!EC_POINT_mul(gdata->group, result, NULL, result, priv, gdata->ctx)) -+ goto cleanup; -+ -+ /* Marshal result into elem_out. */ -+ len = EC_POINT_point2oct(gdata->group, result, POINT_CONVERSION_COMPRESSED, -+ elem_out, reg->elem_len, gdata->ctx); -+ if (len != reg->elem_len) -+ goto cleanup; -+ -+ success = TRUE; -+ -+cleanup: -+ BN_clear_free(priv); -+ BN_clear_free(w); -+ EC_POINT_free(pub); -+ EC_POINT_clear_free(result); -+ return invalid ? EINVAL : (success ? 0 : ENOMEM); -+} -+ -+static krb5_error_code -+ossl_hash(krb5_context context, groupdata *gdata, const krb5_data *dlist, -+ size_t ndata, uint8_t *result_out) -+{ -+ EVP_MD_CTX *ctx; -+ size_t i; -+ int ok; -+ -+ ctx = EVP_MD_CTX_new(); -+ if (ctx == NULL) -+ return ENOMEM; -+ ok = EVP_DigestInit_ex(ctx, gdata->md, NULL); -+ for (i = 0; i < ndata; i++) -+ ok = ok && EVP_DigestUpdate(ctx, dlist[i].data, dlist[i].length); -+ ok = ok && EVP_DigestFinal_ex(ctx, result_out, NULL); -+ EVP_MD_CTX_free(ctx); -+ return ok ? 0 : ENOMEM; -+} -+ -+groupdef ossl_P256 = { -+ .reg = &spake_iana_p256, -+ .init = ossl_init, -+ .fini = ossl_fini, -+ .keygen = ossl_keygen, -+ .result = ossl_result, -+ .hash = ossl_hash, -+}; -+ -+groupdef ossl_P384 = { -+ .reg = &spake_iana_p384, -+ .init = ossl_init, -+ .fini = ossl_fini, -+ .keygen = ossl_keygen, -+ .result = ossl_result, -+ .hash = ossl_hash, -+}; -+ -+groupdef ossl_P521 = { -+ .reg = &spake_iana_p521, -+ .init = ossl_init, -+ .fini = ossl_fini, -+ .keygen = ossl_keygen, -+ .result = ossl_result, -+ .hash = ossl_hash, -+}; -+#endif /* SPAKE_OPENSSL */ -diff --git a/src/plugins/preauth/spake/spake.exports b/src/plugins/preauth/spake/spake.exports -new file mode 100644 -index 000000000..81d100228 ---- /dev/null -+++ b/src/plugins/preauth/spake/spake.exports -@@ -0,0 +1,2 @@ -+clpreauth_spake_initvt -+kdcpreauth_spake_initvt -diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c -new file mode 100644 -index 000000000..d72bd64aa ---- /dev/null -+++ b/src/plugins/preauth/spake/spake_client.c -@@ -0,0 +1,363 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* plugins/preauth/spake/spake_client.c - SPAKE clpreauth module */ -+/* -+ * Copyright (C) 2015 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include "k5-int.h" -+#include "k5-spake.h" -+#include "trace.h" -+#include "util.h" -+#include "iana.h" -+#include "groups.h" -+#include -+ -+typedef struct reqstate_st { -+ krb5_keyblock *initial_key; -+ krb5_data *support; -+ krb5_data thash; -+ krb5_data spakeresult; -+} reqstate; -+ -+static krb5_error_code -+spake_init(krb5_context context, krb5_clpreauth_moddata *moddata_out) -+{ -+ krb5_error_code ret; -+ groupstate *gstate; -+ -+ ret = group_init_state(context, FALSE, &gstate); -+ if (ret) -+ return ret; -+ *moddata_out = (krb5_clpreauth_moddata)gstate; -+ return 0; -+} -+ -+static void -+spake_fini(krb5_context context, krb5_clpreauth_moddata moddata) -+{ -+ group_free_state((groupstate *)moddata); -+} -+ -+static void -+spake_request_init(krb5_context context, krb5_clpreauth_moddata moddata, -+ krb5_clpreauth_modreq *modreq_out) -+{ -+ *modreq_out = calloc(1, sizeof(reqstate)); -+} -+ -+static void -+spake_request_fini(krb5_context context, krb5_clpreauth_moddata moddata, -+ krb5_clpreauth_modreq modreq) -+{ -+ reqstate *st = (reqstate *)modreq; -+ -+ krb5_free_keyblock(context, st->initial_key); -+ krb5_free_data(context, st->support); -+ krb5_free_data_contents(context, &st->thash); -+ zapfree(st->spakeresult.data, st->spakeresult.length); -+ free(st); -+} -+ -+static krb5_error_code -+spake_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata, -+ krb5_clpreauth_modreq modreq, -+ krb5_get_init_creds_opt *opt, krb5_clpreauth_callbacks cb, -+ krb5_clpreauth_rock rock, krb5_kdc_req *req, -+ krb5_data *enc_req, krb5_data *enc_prev_req, -+ krb5_pa_data *pa_data) -+{ -+ reqstate *st = (reqstate *)modreq; -+ -+ if (st == NULL) -+ return ENOMEM; -+ if (st->initial_key == NULL && pa_data->length > 0) -+ cb->need_as_key(context, rock); -+ -+ /* When second-factor is implemented, we should ask questions based on the -+ * factors in the challenge. */ -+ -+ return 0; -+} -+ -+/* -+ * Output a PA-SPAKE support message indicating which groups we support. This -+ * may be done for optimistic preauth, in response to an empty message, or in -+ * response to a challenge using a group we do not support. Save the support -+ * message in st->support. -+ */ -+static krb5_error_code -+send_support(krb5_context context, groupstate *gstate, reqstate *st, -+ krb5_pa_data ***pa_out) -+{ -+ krb5_error_code ret; -+ krb5_data *support; -+ krb5_pa_spake msg; -+ -+ msg.choice = SPAKE_MSGTYPE_SUPPORT; -+ group_get_permitted(gstate, &msg.u.support.groups, &msg.u.support.ngroups); -+ ret = encode_krb5_pa_spake(&msg, &support); -+ if (ret) -+ return ret; -+ -+ /* Save the support message for later use in the transcript hash. */ -+ ret = krb5_copy_data(context, support, &st->support); -+ if (ret) { -+ krb5_free_data(context, support); -+ return ret; -+ } -+ -+ TRACE_SPAKE_SEND_SUPPORT(context); -+ return convert_to_padata(support, pa_out); -+} -+ -+/* Return true if SF-NONE is present in factors. */ -+static krb5_boolean -+contains_sf_none(krb5_spake_factor **factors) -+{ -+ int i; -+ -+ for (i = 0; factors != NULL && factors[i] != NULL; i++) { -+ if (factors[i]->type == SPAKE_SF_NONE) -+ return TRUE; -+ } -+ return FALSE; -+} -+ -+static krb5_error_code -+process_challenge(krb5_context context, groupstate *gstate, reqstate *st, -+ krb5_spake_challenge *ch, const krb5_data *der_msg, -+ krb5_clpreauth_callbacks cb, krb5_clpreauth_rock rock, -+ krb5_prompter_fct prompter, void *prompter_data, -+ const krb5_data *der_req, krb5_pa_data ***pa_out) -+{ -+ krb5_error_code ret; -+ krb5_keyblock *k0 = NULL, *k1 = NULL; -+ krb5_spake_factor factor; -+ krb5_pa_spake msg; -+ krb5_data *der_factor = NULL, *response; -+ krb5_data clpriv = empty_data(), clpub = empty_data(); -+ krb5_data wbytes = empty_data(); -+ krb5_enc_data enc_factor; -+ -+ enc_factor.ciphertext = empty_data(); -+ -+ /* Not expected if we already computed the SPAKE result. */ -+ if (st->spakeresult.length != 0) -+ return KRB5KDC_ERR_PREAUTH_FAILED; -+ -+ if (!group_is_permitted(gstate, ch->group)) { -+ TRACE_SPAKE_REJECT_CHALLENGE(context, ch->group); -+ /* No point in sending a second support message. */ -+ if (st->support != NULL) -+ return KRB5KDC_ERR_PREAUTH_FAILED; -+ return send_support(context, gstate, st, pa_out); -+ } -+ -+ /* Initialize and update the transcript with the concatenation of the -+ * support message (if we sent one) and the received challenge. */ -+ ret = update_thash(context, gstate, ch->group, &st->thash, st->support, -+ der_msg); -+ if (ret) -+ return ret; -+ -+ TRACE_SPAKE_RECEIVE_CHALLENGE(context, ch->group, &ch->pubkey); -+ -+ /* When second factor support is implemented, we should check for a -+ * supported factor type instead of just checking for SF-NONE. */ -+ if (!contains_sf_none(ch->factors)) -+ return KRB5KDC_ERR_PREAUTH_FAILED; -+ -+ ret = derive_wbytes(context, ch->group, st->initial_key, &wbytes); -+ if (ret) -+ goto cleanup; -+ ret = group_keygen(context, gstate, ch->group, &wbytes, &clpriv, &clpub); -+ if (ret) -+ goto cleanup; -+ ret = group_result(context, gstate, ch->group, &wbytes, &clpriv, -+ &ch->pubkey, &st->spakeresult); -+ if (ret) -+ goto cleanup; -+ -+ ret = update_thash(context, gstate, ch->group, &st->thash, &clpub, NULL); -+ if (ret) -+ goto cleanup; -+ TRACE_SPAKE_CLIENT_THASH(context, &st->thash); -+ -+ /* Replace the reply key with K'[0]. */ -+ ret = derive_key(context, gstate, ch->group, st->initial_key, &wbytes, -+ &st->spakeresult, &st->thash, der_req, 0, &k0); -+ if (ret) -+ goto cleanup; -+ ret = cb->set_as_key(context, rock, k0); -+ if (ret) -+ goto cleanup; -+ -+ /* Encrypt a SPAKESecondFactor message with K'[1]. */ -+ ret = derive_key(context, gstate, ch->group, st->initial_key, &wbytes, -+ &st->spakeresult, &st->thash, der_req, 1, &k1); -+ if (ret) -+ goto cleanup; -+ /* When second factor support is implemented, we should construct an -+ * appropriate factor here instead of hardcoding SF-NONE. */ -+ factor.type = SPAKE_SF_NONE; -+ factor.data = NULL; -+ ret = encode_krb5_spake_factor(&factor, &der_factor); -+ if (ret) -+ goto cleanup; -+ ret = krb5_encrypt_helper(context, k1, KRB5_KEYUSAGE_SPAKE, der_factor, -+ &enc_factor); -+ if (ret) -+ goto cleanup; -+ -+ /* Encode and output a response message. */ -+ msg.choice = SPAKE_MSGTYPE_RESPONSE; -+ msg.u.response.pubkey = clpub; -+ msg.u.response.factor = enc_factor; -+ ret = encode_krb5_pa_spake(&msg, &response); -+ if (ret) -+ goto cleanup; -+ TRACE_SPAKE_SEND_RESPONSE(context); -+ ret = convert_to_padata(response, pa_out); -+ -+cleanup: -+ krb5_free_keyblock(context, k0); -+ krb5_free_keyblock(context, k1); -+ krb5_free_data_contents(context, &enc_factor.ciphertext); -+ krb5_free_data_contents(context, &clpub); -+ zapfree(clpriv.data, clpriv.length); -+ zapfree(wbytes.data, wbytes.length); -+ if (der_factor != NULL) { -+ zapfree(der_factor->data, der_factor->length); -+ free(der_factor); -+ } -+ return ret; -+} -+ -+static krb5_error_code -+process_encdata(krb5_context context, reqstate *st, krb5_enc_data *enc, -+ krb5_clpreauth_callbacks cb, krb5_clpreauth_rock rock, -+ krb5_prompter_fct prompter, void *prompter_data, -+ const krb5_data *der_prev_req, const krb5_data *der_req, -+ krb5_pa_data ***pa_out) -+{ -+ /* Not expected if we haven't sent a response yet. */ -+ if (st->spakeresult.length == 0) -+ return KRB5KDC_ERR_PREAUTH_FAILED; -+ -+ /* -+ * When second factor support is implemented, we should process encdata -+ * messages according to the factor type. We should make sure to re-derive -+ * K'[0] and replace the reply key again, in case the request has changed. -+ * We should use der_prev_req to derive K'[n] to decrypt factor from the -+ * KDC. We should use der_req to derive K'[n+1] for the next message to -+ * send to the KDC. -+ */ -+ return KRB5_PLUGIN_OP_NOTSUPP; -+} -+ -+static krb5_error_code -+spake_process(krb5_context context, krb5_clpreauth_moddata moddata, -+ krb5_clpreauth_modreq modreq, krb5_get_init_creds_opt *opt, -+ krb5_clpreauth_callbacks cb, krb5_clpreauth_rock rock, -+ krb5_kdc_req *req, krb5_data *der_req, krb5_data *der_prev_req, -+ krb5_pa_data *pa_in, krb5_prompter_fct prompter, -+ void *prompter_data, krb5_pa_data ***pa_out) -+{ -+ krb5_error_code ret; -+ groupstate *gstate = (groupstate *)moddata; -+ reqstate *st = (reqstate *)modreq; -+ krb5_pa_spake *msg; -+ krb5_data in_data; -+ krb5_keyblock *as_key; -+ -+ if (st == NULL) -+ return ENOMEM; -+ -+ if (pa_in->length == 0) { -+ /* Not expected if we already sent a support message. */ -+ if (st->support != NULL) -+ return KRB5KDC_ERR_PREAUTH_FAILED; -+ return send_support(context, gstate, st, pa_out); -+ } -+ -+ /* We need the initial reply key to process any non-trivial message. */ -+ if (st->initial_key == NULL) { -+ ret = cb->get_as_key(context, rock, &as_key); -+ if (ret) -+ return ret; -+ ret = krb5_copy_keyblock(context, as_key, &st->initial_key); -+ if (ret) -+ return ret; -+ } -+ -+ in_data = make_data(pa_in->contents, pa_in->length); -+ ret = decode_krb5_pa_spake(&in_data, &msg); -+ if (ret) -+ return ret; -+ -+ if (msg->choice == SPAKE_MSGTYPE_CHALLENGE) { -+ ret = process_challenge(context, gstate, st, &msg->u.challenge, -+ &in_data, cb, rock, prompter, prompter_data, -+ der_req, pa_out); -+ } else if (msg->choice == SPAKE_MSGTYPE_ENCDATA) { -+ ret = process_encdata(context, st, &msg->u.encdata, cb, rock, prompter, -+ prompter_data, der_prev_req, der_req, pa_out); -+ } else { -+ /* Unexpected message type */ -+ ret = KRB5KDC_ERR_PREAUTH_FAILED; -+ } -+ -+ k5_free_pa_spake(context, msg); -+ return ret; -+} -+ -+krb5_error_code -+clpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable); -+ -+krb5_error_code -+clpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable) -+{ -+ krb5_clpreauth_vtable vt; -+ static krb5_preauthtype pa_types[] = { KRB5_PADATA_SPAKE, 0 }; -+ -+ if (maj_ver != 1) -+ return KRB5_PLUGIN_VER_NOTSUPP; -+ vt = (krb5_clpreauth_vtable)vtable; -+ vt->name = "spake"; -+ vt->pa_type_list = pa_types; -+ vt->init = spake_init; -+ vt->fini = spake_fini; -+ vt->request_init = spake_request_init; -+ vt->request_fini = spake_request_fini; -+ vt->process = spake_process; -+ vt->prep_questions = spake_prep_questions; -+ return 0; -+} -diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c -new file mode 100644 -index 000000000..c1723ebaf ---- /dev/null -+++ b/src/plugins/preauth/spake/spake_kdc.c -@@ -0,0 +1,590 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* plugins/preauth/spake/spake_kdc.c - SPAKE kdcpreauth module */ -+/* -+ * Copyright (C) 2015 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include "k5-int.h" -+#include "k5-input.h" -+#include "k5-spake.h" -+ -+#include "groups.h" -+#include "trace.h" -+#include "iana.h" -+#include "util.h" -+ -+#include -+ -+/* -+ * The SPAKE kdcpreauth module uses a secure cookie containing the following -+ * concatenated fields (all integer fields are big-endian): -+ * -+ * version (16-bit unsigned integer) -+ * stage (16-bit unsigned integer) -+ * group (32-bit signed integer) -+ * SPAKE value (32-bit unsigned length, followed by data) -+ * Transcript hash (32-bit unsigned length, followed by data) -+ * Zero or more instances of: -+ * second-factor number (32-bit signed integer) -+ * second-factor data (32-bit unsigned length, followed by data) -+ * -+ * The only currently supported version is 1. stage is 0 if the cookie was -+ * sent with a challenge message. stage is n>0 if the cookie was sent with an -+ * encdata message encrypted in K'[2n]. group indicates the group number used -+ * in the SPAKE challenge. The SPAKE value is the KDC private key for a -+ * stage-0 cookie, represented in the scalar marshalling form of the group; for -+ * other cookies, the SPAKE value is the SPAKE result K, represented in the -+ * group element marshalling form. The transcript hash is the intermediate -+ * hash after updating with the support and challenge messages for a stage-0 -+ * cookie, or the final hash for other cookies. For a stage 0 cookie, there -+ * may be any number of second-factor records, including none (no record is -+ * generated for SF-NONE); for other cookies, there must be exactly one -+ * second-factor record corresponding to the factor type chosen by the client. -+ */ -+ -+/* From a k5input structure representing the remainder of a secure cookie -+ * plaintext, parse a four-byte length and data. */ -+static void -+parse_data(struct k5input *in, krb5_data *out) -+{ -+ out->length = k5_input_get_uint32_be(in); -+ out->data = (char *)k5_input_get_bytes(in, out->length); -+} -+ -+/* Parse a received cookie into its components. The pointers stored in the -+ * krb5_data outputs are aliases into cookie and should not be freed. */ -+static krb5_error_code -+parse_cookie(const krb5_data *cookie, int *stage_out, int32_t *group_out, -+ krb5_data *spake_out, krb5_data *thash_out, -+ krb5_data *factors_out) -+{ -+ struct k5input in; -+ int version, stage; -+ int32_t group; -+ krb5_data thash, spake, factors; -+ -+ *spake_out = *thash_out = *factors_out = empty_data(); -+ k5_input_init(&in, cookie->data, cookie->length); -+ -+ /* Parse and check the version, and read the other integer fields. */ -+ version = k5_input_get_uint16_be(&in); -+ if (version != 1) -+ return KRB5KDC_ERR_PREAUTH_FAILED; -+ stage = k5_input_get_uint16_be(&in); -+ group = k5_input_get_uint32_be(&in); -+ -+ /* Parse the data fields. The factor data is anything remaining after the -+ * transcript hash. */ -+ parse_data(&in, &spake); -+ parse_data(&in, &thash); -+ if (in.status) -+ return in.status; -+ factors = make_data((char *)in.ptr, in.len); -+ -+ *stage_out = stage; -+ *group_out = group; -+ *spake_out = spake; -+ *thash_out = thash; -+ *factors_out = factors; -+ return 0; -+} -+ -+/* Marshal data into buf as a four-byte length followed by the contents. */ -+static void -+marshal_data(struct k5buf *buf, const krb5_data *data) -+{ -+ uint8_t lenbuf[4]; -+ -+ store_32_be(data->length, lenbuf); -+ k5_buf_add_len(buf, lenbuf, 4); -+ k5_buf_add_len(buf, data->data, data->length); -+} -+ -+/* Marshal components into a cookie. */ -+static krb5_error_code -+make_cookie(int stage, int32_t group, const krb5_data *spake, -+ const krb5_data *thash, krb5_data *cookie_out) -+{ -+ struct k5buf buf; -+ uint8_t intbuf[4]; -+ -+ *cookie_out = empty_data(); -+ k5_buf_init_dynamic_zap(&buf); -+ -+ /* Marshal the version, stage, and group. */ -+ store_16_be(1, intbuf); -+ k5_buf_add_len(&buf, intbuf, 2); -+ store_16_be(stage, intbuf); -+ k5_buf_add_len(&buf, intbuf, 2); -+ store_32_be(group, intbuf); -+ k5_buf_add_len(&buf, intbuf, 4); -+ -+ /* Marshal the data fields. */ -+ marshal_data(&buf, spake); -+ marshal_data(&buf, thash); -+ -+ /* When second factor support is implemented, we should add factor data -+ * here. */ -+ -+ if (buf.data == NULL) -+ return ENOMEM; -+ *cookie_out = make_data(buf.data, buf.len); -+ return 0; -+} -+ -+/* Add authentication indicators if any are configured for SPAKE. */ -+static krb5_error_code -+add_indicators(krb5_context context, const krb5_data *realm, -+ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock) -+{ -+ krb5_error_code ret; -+ const char *keys[4]; -+ char *realmstr, **indicators, **ind; -+ -+ realmstr = k5memdup0(realm->data, realm->length, &ret); -+ if (realmstr == NULL) -+ return ret; -+ keys[0] = KRB5_CONF_REALMS; -+ keys[1] = realmstr; -+ keys[2] = KRB5_CONF_SPAKE_PREAUTH_INDICATOR; -+ keys[3] = NULL; -+ ret = profile_get_values(context->profile, keys, &indicators); -+ free(realmstr); -+ if (ret == PROF_NO_RELATION) -+ return 0; -+ if (ret) -+ return ret; -+ -+ for (ind = indicators; *ind != NULL && !ret; ind++) -+ ret = cb->add_auth_indicator(context, rock, *ind); -+ -+ profile_free_list(indicators); -+ return ret; -+} -+ -+/* Initialize a SPAKE module data object. */ -+static krb5_error_code -+spake_init(krb5_context context, krb5_kdcpreauth_moddata *moddata_out, -+ const char **realmnames) -+{ -+ krb5_error_code ret; -+ groupstate *gstate; -+ -+ ret = group_init_state(context, TRUE, &gstate); -+ if (ret) -+ return ret; -+ *moddata_out = (krb5_kdcpreauth_moddata)gstate; -+ return 0; -+} -+ -+/* Release a SPAKE module data object. */ -+static void -+spake_fini(krb5_context context, krb5_kdcpreauth_moddata moddata) -+{ -+ group_free_state((groupstate *)moddata); -+} -+ -+/* -+ * Generate a SPAKE challenge message for the specified group. Use cb and rock -+ * to retrieve the initial reply key and to set a stage-0 cookie. Invoke -+ * either erespond or vrespond with the result. -+ */ -+static void -+send_challenge(krb5_context context, groupstate *gstate, int32_t group, -+ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, -+ const krb5_data *support, -+ krb5_kdcpreauth_edata_respond_fn erespond, -+ krb5_kdcpreauth_verify_respond_fn vrespond, void *arg) -+{ -+ krb5_error_code ret; -+ const krb5_keyblock *ikey; -+ krb5_pa_data **padata = NULL, *pa; -+ krb5_data kdcpriv = empty_data(), kdcpub = empty_data(), *der_msg = NULL; -+ krb5_data thash = empty_data(), cookie = empty_data(); -+ krb5_data wbytes = empty_data(); -+ krb5_spake_factor f, *flist[2]; -+ krb5_pa_spake msg; -+ -+ ikey = cb->client_keyblock(context, rock); -+ if (ikey == NULL) { -+ ret = KRB5KDC_ERR_ETYPE_NOSUPP; -+ goto cleanup; -+ } -+ -+ ret = derive_wbytes(context, group, ikey, &wbytes); -+ if (ret) -+ goto cleanup; -+ ret = group_keygen(context, gstate, group, &wbytes, &kdcpriv, &kdcpub); -+ if (ret) -+ goto cleanup; -+ -+ /* Encode the challenge. When second factor support is implemented, we -+ * should construct a factor list instead of hardcoding SF-NONE. */ -+ f.type = SPAKE_SF_NONE; -+ f.data = NULL; -+ flist[0] = &f; -+ flist[1] = NULL; -+ msg.choice = SPAKE_MSGTYPE_CHALLENGE; -+ msg.u.challenge.group = group; -+ msg.u.challenge.pubkey = kdcpub; -+ msg.u.challenge.factors = flist; -+ ret = encode_krb5_pa_spake(&msg, &der_msg); -+ if (ret) -+ goto cleanup; -+ -+ /* Initialize and update the transcript hash with the support message (if -+ * we received one) and challenge message. */ -+ ret = update_thash(context, gstate, group, &thash, support, der_msg); -+ if (ret) -+ goto cleanup; -+ -+ /* Save the group, transcript hash, and private key in a stage-0 cookie. -+ * When second factor support is implemented, also save factor state. */ -+ ret = make_cookie(0, group, &kdcpriv, &thash, &cookie); -+ if (ret) -+ goto cleanup; -+ ret = cb->set_cookie(context, rock, KRB5_PADATA_SPAKE, &cookie); -+ if (ret) -+ goto cleanup; -+ -+ ret = convert_to_padata(der_msg, &padata); -+ der_msg = NULL; -+ TRACE_SPAKE_SEND_CHALLENGE(context, group); -+ -+cleanup: -+ zapfree(wbytes.data, wbytes.length); -+ zapfree(kdcpriv.data, kdcpriv.length); -+ zapfree(cookie.data, cookie.length); -+ krb5_free_data_contents(context, &kdcpub); -+ krb5_free_data_contents(context, &thash); -+ krb5_free_data(context, der_msg); -+ -+ if (erespond != NULL) { -+ assert(vrespond == NULL); -+ /* Grab the first pa-data element from the list, if we made one. */ -+ pa = (padata == NULL) ? NULL : padata[0]; -+ free(padata); -+ (*erespond)(arg, ret, pa); -+ } else { -+ assert(vrespond != NULL); -+ if (!ret) -+ ret = KRB5KDC_ERR_MORE_PREAUTH_DATA_REQUIRED; -+ (*vrespond)(arg, ret, NULL, padata, NULL); -+ } -+} -+ -+/* Generate the METHOD-DATA entry indicating support for SPAKE. Include an -+ * optimistic challenge if configured to do so. */ -+static void -+spake_edata(krb5_context context, krb5_kdc_req *req, -+ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, -+ krb5_kdcpreauth_moddata moddata, krb5_preauthtype pa_type, -+ krb5_kdcpreauth_edata_respond_fn respond, void *arg) -+{ -+ const krb5_keyblock *ikey; -+ groupstate *gstate = (groupstate *)moddata; -+ krb5_data empty = empty_data(); -+ int32_t group; -+ -+ /* SPAKE requires a client key, which cannot be a single-DES key. */ -+ ikey = cb->client_keyblock(context, rock); -+ if (ikey == NULL) { -+ (*respond)(arg, KRB5KDC_ERR_ETYPE_NOSUPP, NULL); -+ return; -+ } -+ -+ group = group_optimistic_challenge(gstate); -+ if (group) { -+ send_challenge(context, gstate, group, cb, rock, &empty, respond, NULL, -+ arg); -+ } else { -+ /* No optimistic challenge configured; send an empty pa-data value. */ -+ (*respond)(arg, 0, NULL); -+ } -+} -+ -+/* Choose a group from the client's support message and generate a -+ * challenge. */ -+static void -+verify_support(krb5_context context, groupstate *gstate, -+ krb5_spake_support *support, const krb5_data *der_msg, -+ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, -+ krb5_kdcpreauth_verify_respond_fn respond, void *arg) -+{ -+ krb5_error_code ret; -+ int32_t i, group; -+ -+ for (i = 0; i < support->ngroups; i++) { -+ if (group_is_permitted(gstate, support->groups[i])) -+ break; -+ } -+ if (i == support->ngroups) { -+ TRACE_SPAKE_REJECT_SUPPORT(context); -+ ret = KRB5KDC_ERR_PREAUTH_FAILED; -+ goto error; -+ } -+ group = support->groups[i]; -+ TRACE_SPAKE_RECEIVE_SUPPORT(context, group); -+ -+ send_challenge(context, gstate, group, cb, rock, der_msg, NULL, respond, -+ arg); -+ return; -+ -+error: -+ (*respond)(arg, ret, NULL, NULL, NULL); -+} -+ -+/* -+ * From the client's response message, compute the SPAKE result and decrypt the -+ * factor reply. On success, either mark the reply as pre-authenticated and -+ * set a reply key in the pre-request module data, or generate an additional -+ * factor challenge and ask for another round of pre-authentication. -+ */ -+static void -+verify_response(krb5_context context, groupstate *gstate, -+ krb5_spake_response *resp, const krb5_data *realm, -+ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, -+ krb5_enc_tkt_part *enc_tkt_reply, -+ krb5_kdcpreauth_verify_respond_fn respond, void *arg) -+{ -+ krb5_error_code ret; -+ const krb5_keyblock *ikey; -+ krb5_keyblock *k1 = NULL, *reply_key = NULL; -+ krb5_data cookie, thash_in, kdcpriv, factors, *der_req; -+ krb5_data thash = empty_data(), der_factor = empty_data(); -+ krb5_data wbytes = empty_data(), spakeresult = empty_data(); -+ krb5_spake_factor *factor = NULL; -+ int stage; -+ int32_t group; -+ -+ ikey = cb->client_keyblock(context, rock); -+ if (ikey == NULL) { -+ ret = KRB5KDC_ERR_ETYPE_NOSUPP; -+ goto cleanup; -+ } -+ -+ /* Fetch the stage-0 cookie and parse it. (All of the krb5_data results -+ * are aliases into memory owned by rock). */ -+ if (!cb->get_cookie(context, rock, KRB5_PADATA_SPAKE, &cookie)) { -+ ret = KRB5KDC_ERR_PREAUTH_FAILED; -+ goto cleanup; -+ } -+ ret = parse_cookie(&cookie, &stage, &group, &kdcpriv, &thash_in, &factors); -+ if (ret) -+ goto cleanup; -+ if (stage != 0) { -+ /* The received cookie wasn't sent with a challenge. */ -+ ret = KRB5KDC_ERR_PREAUTH_FAILED; -+ goto cleanup; -+ } -+ TRACE_SPAKE_RECEIVE_RESPONSE(context, &resp->pubkey); -+ -+ /* Update the transcript hash with the client public key. */ -+ ret = krb5int_copy_data_contents(context, &thash_in, &thash); -+ if (ret) -+ goto cleanup; -+ ret = update_thash(context, gstate, group, &thash, &resp->pubkey, NULL); -+ if (ret) -+ goto cleanup; -+ TRACE_SPAKE_KDC_THASH(context, &thash); -+ -+ ret = derive_wbytes(context, group, ikey, &wbytes); -+ if (ret) -+ goto cleanup; -+ ret = group_result(context, gstate, group, &wbytes, &kdcpriv, -+ &resp->pubkey, &spakeresult); -+ if (ret) -+ goto cleanup; -+ -+ /* Decrypt the response factor field using K'[1]. If the decryption -+ * integrity check fails, the client probably used the wrong password. */ -+ der_req = cb->request_body(context, rock); -+ ret = derive_key(context, gstate, group, ikey, &wbytes, &spakeresult, -+ &thash, der_req, 1, &k1); -+ if (ret) -+ goto cleanup; -+ ret = alloc_data(&der_factor, resp->factor.ciphertext.length); -+ if (ret) -+ goto cleanup; -+ ret = krb5_c_decrypt(context, k1, KRB5_KEYUSAGE_SPAKE, NULL, &resp->factor, -+ &der_factor); -+ if (ret == KRB5KRB_AP_ERR_BAD_INTEGRITY) -+ ret = KRB5KDC_ERR_PREAUTH_FAILED; -+ if (ret) -+ goto cleanup; -+ ret = decode_krb5_spake_factor(&der_factor, &factor); -+ if (ret) -+ goto cleanup; -+ -+ /* -+ * When second factor support is implemented, we should verify the factor -+ * data here, and possibly generate an encdata message for another hop. -+ * This function may need to be split at this point to allow for -+ * asynchronous verification of the second-factor value. We might also -+ * need to collect authentication indicators from the second-factor module; -+ * alternatively the module could have access to cb and rock so that it can -+ * add indicators itself. -+ */ -+ if (factor->type != SPAKE_SF_NONE) { -+ ret = KRB5KDC_ERR_PREAUTH_FAILED; -+ goto cleanup; -+ } -+ -+ ret = add_indicators(context, realm, cb, rock); -+ if (ret) -+ goto cleanup; -+ -+ enc_tkt_reply->flags |= TKT_FLG_PRE_AUTH; -+ -+ ret = derive_key(context, gstate, group, ikey, &wbytes, &spakeresult, -+ &thash, der_req, 0, &reply_key); -+ -+cleanup: -+ zapfree(wbytes.data, wbytes.length); -+ zapfree(der_factor.data, der_factor.length); -+ zapfree(spakeresult.data, spakeresult.length); -+ krb5_free_data_contents(context, &thash); -+ krb5_free_keyblock(context, k1); -+ k5_free_spake_factor(context, factor); -+ (*respond)(arg, ret, (krb5_kdcpreauth_modreq)reply_key, NULL, NULL); -+} -+ -+/* -+ * Decrypt and validate an additional second-factor reply. On success, either -+ * mark the reply as pre-authenticated and set a reply key in the pre-request -+ * module data, or generate an additional factor challenge and ask for another -+ * round of pre-authentication. -+ */ -+static void -+verify_encdata(krb5_context context, krb5_enc_data *enc, -+ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, -+ krb5_enc_tkt_part *enc_tkt_reply, -+ krb5_kdcpreauth_verify_respond_fn respond, void *arg) -+{ -+ /* -+ * When second factor support is implemented, we should process encdata -+ * message according to the factor type recorded in the cookie. If the -+ * second factor exchange finishes successfully, we should set -+ * TKT_FLG_PRE_AUTH, set the reply key to K'[0], and add any auth -+ * indicators from configuration (with a call to add_indicators()) or the -+ * second factor module (unless the module has access to cb and rock and -+ * can add indicators itself). -+ */ -+ (*respond)(arg, KRB5KDC_ERR_PREAUTH_FAILED, NULL, NULL, NULL); -+} -+ -+/* -+ * Respond to a client padata message, either by generating a SPAKE challenge, -+ * generating an additional second-factor challenge, or marking the reply as -+ * pre-authenticated and setting an additional reply key in the pre-request -+ * module data. -+ */ -+static void -+spake_verify(krb5_context context, krb5_data *req_pkt, krb5_kdc_req *request, -+ krb5_enc_tkt_part *enc_tkt_reply, krb5_pa_data *data, -+ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, -+ krb5_kdcpreauth_moddata moddata, -+ krb5_kdcpreauth_verify_respond_fn respond, void *arg) -+{ -+ krb5_error_code ret; -+ krb5_pa_spake *pa_spake = NULL; -+ krb5_data in_data = make_data(data->contents, data->length); -+ groupstate *gstate = (groupstate *)moddata; -+ -+ ret = decode_krb5_pa_spake(&in_data, &pa_spake); -+ if (ret) { -+ (*respond)(arg, ret, NULL, NULL, NULL); -+ } else if (pa_spake->choice == SPAKE_MSGTYPE_SUPPORT) { -+ verify_support(context, gstate, &pa_spake->u.support, &in_data, cb, -+ rock, respond, arg); -+ } else if (pa_spake->choice == SPAKE_MSGTYPE_RESPONSE) { -+ verify_response(context, gstate, &pa_spake->u.response, -+ &request->server->realm, cb, rock, enc_tkt_reply, -+ respond, arg); -+ } else if (pa_spake->choice == SPAKE_MSGTYPE_ENCDATA) { -+ verify_encdata(context, &pa_spake->u.encdata, cb, rock, enc_tkt_reply, -+ respond, arg); -+ } else { -+ ret = KRB5KDC_ERR_PREAUTH_FAILED; -+ k5_setmsg(context, ret, _("Unknown SPAKE request type")); -+ (*respond)(arg, ret, NULL, NULL, NULL); -+ } -+ -+ k5_free_pa_spake(context, pa_spake); -+} -+ -+/* If a key was set in the per-request module data, replace the reply key. Do -+ * not generate any pa-data to include with the KDC reply. */ -+static krb5_error_code -+spake_return(krb5_context context, krb5_pa_data *padata, krb5_data *req_pkt, -+ krb5_kdc_req *request, krb5_kdc_rep *reply, -+ krb5_keyblock *encrypting_key, krb5_pa_data **send_pa_out, -+ krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, -+ krb5_kdcpreauth_moddata moddata, krb5_kdcpreauth_modreq modreq) -+{ -+ krb5_keyblock *reply_key = (krb5_keyblock *)modreq; -+ -+ if (reply_key == NULL) -+ return 0; -+ krb5_free_keyblock_contents(context, encrypting_key); -+ return krb5_copy_keyblock_contents(context, reply_key, encrypting_key); -+} -+ -+/* Release a per-request module data object. */ -+static void -+spake_free_modreq(krb5_context context, krb5_kdcpreauth_moddata moddata, -+ krb5_kdcpreauth_modreq modreq) -+{ -+ krb5_free_keyblock(context, (krb5_keyblock *)modreq); -+} -+ -+krb5_error_code -+kdcpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable); -+ -+krb5_error_code -+kdcpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, -+ krb5_plugin_vtable vtable) -+{ -+ krb5_kdcpreauth_vtable vt; -+ static krb5_preauthtype pa_types[] = { KRB5_PADATA_SPAKE, 0 }; -+ -+ if (maj_ver != 1) -+ return KRB5_PLUGIN_VER_NOTSUPP; -+ vt = (krb5_kdcpreauth_vtable)vtable; -+ vt->name = "spake"; -+ vt->pa_type_list = pa_types; -+ vt->init = spake_init; -+ vt->fini = spake_fini; -+ vt->edata = spake_edata; -+ vt->verify = spake_verify; -+ vt->return_padata = spake_return; -+ vt->free_modreq = spake_free_modreq; -+ return 0; -+} -diff --git a/src/plugins/preauth/spake/t_krb5.conf b/src/plugins/preauth/spake/t_krb5.conf -new file mode 100644 -index 000000000..65fdaec63 ---- /dev/null -+++ b/src/plugins/preauth/spake/t_krb5.conf -@@ -0,0 +1,2 @@ -+[libdefaults] -+ spake_preauth_groups = edwards25519 -diff --git a/src/plugins/preauth/spake/t_vectors.c b/src/plugins/preauth/spake/t_vectors.c -new file mode 100644 -index 000000000..2279202d3 ---- /dev/null -+++ b/src/plugins/preauth/spake/t_vectors.c -@@ -0,0 +1,476 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* plugins/preauth/spake/t_vectors.c - SPAKE test vector verification */ -+/* -+ * Copyright (C) 2015 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include "k5-int.h" -+#include "k5-hex.h" -+#include "groups.h" -+#include "iana.h" -+#include "util.h" -+#include -+ -+struct test { -+ krb5_enctype enctype; -+ int32_t group; -+ const char *ikey; -+ const char *w; -+ const char *x; -+ const char *y; -+ const char *T; -+ const char *S; -+ const char *K; -+ const char *support; -+ const char *challenge; -+ const char *thash; -+ const char *body; -+ const char *K0; -+ const char *K1; -+ const char *K2; -+ const char *K3; -+} tests[] = { -+ { ENCTYPE_DES3_CBC_SHA1, SPAKE_GROUP_EDWARDS25519, -+ /* initial key, w, x, y, T, S, K */ -+ "850BB51358548CD05E86768C313E3BFEF7511937DCF72C3E", -+ "686D84730CB8679AE95416C6567C6A63F2C9CEF124F7A3371AE81E11CAD42A37", -+ "201012D07BFD48DDFA33C4AAC4FB1E229FB0D043CFE65EBFB14399091C71A723", -+ "500B294797B8B042ACA1BEDC0F5931A4F52C537B3608B2D05CC8A2372F439F25", -+ "18F511E750C97B592ACD30DB7D9E5FCA660389102E6BF610C1BFBED4616C8362", -+ "5D10705E0D1E43D5DBF30240CCFBDE4A0230C70D4C79147AB0B317EDAD2F8AE7", -+ "25BDE0D875F0FEB5755F45BA5E857889D916ECF7476F116AA31DC3E037EC4292", -+ /* support, challenge, thash, body */ -+ "A0093007A0053003020101", -+ "A1363034A003020101A122042018F511E750C97B592ACD30DB7D9E5FCA660389" -+ "102E6BF610C1BFBED4616C8362A20930073005A003020101", -+ "EAAA08807D0616026FF51C849EFBF35BA0CE3C5300E7D486DA46351B13D4605B", -+ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" -+ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" -+ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" -+ "303130313030303030305AA703020100A8053003020110", -+ /* K'[0], K'[1], K'[2], K'[3] */ -+ "BAF12FAE7CD958CBF1A29BFBC71F89CE49E03E295D89DAFD", -+ "64F73DD9C41908206BCEC1F719026B574F9D13463D7A2520", -+ "0454520B086B152C455829E6BAEFF78A61DFE9E3D04A895D", -+ "4A92260B25E3EF94C125D5C24C3E5BCED5B37976E67F25C4", -+ }, -+ -+ { ENCTYPE_ARCFOUR_HMAC, SPAKE_GROUP_EDWARDS25519, -+ /* initial key, w, x, y, T, S, K */ -+ "8846F7EAEE8FB117AD06BDD830B7586C", -+ "7C86659D29CF2B2EA93BFE79C3CEFB8850E82215B3EA6FCD896561D48048F49C", -+ "C8A62E7B626F44CAD807B2D695450697E020D230A738C5CD5691CC781DCE8754", -+ "18FE7C1512708C7FD06DB270361F04593775BC634CEAF45347E5C11C38AAE017", -+ "7DB465F1C08C64983A19F560BCE966FE5306C4B447F70A5BCA14612A92DA1D63", -+ "38F8D4568090148EBC9FD17C241B4CC2769505A7CA6F3F7104417B72B5B5CF54", -+ "03E75EDD2CD7E7677642DD68736E91700953AC55DC650E3C2A1B3B4ACDB800F8", -+ /* support, challenge, thash, body */ -+ "A0093007A0053003020101", -+ "A1363034A003020101A12204207DB465F1C08C64983A19F560BCE966FE5306C4" -+ "B447F70A5BCA14612A92DA1D63A20930073005A003020101", -+ "F4B208458017DE6EF7F6A307D47D87DB6C2AF1D291B726860F68BC08BFEF440A", -+ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" -+ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" -+ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" -+ "303130313030303030305AA703020100A8053003020117", -+ /* K'[0], K'[1], K'[2], K'[3] */ -+ "770B720C82384CBB693E85411EEDECBA", -+ "621DEEC88E2865837C4D3462BB50A1D5", -+ "1CC8F6333B9FA3B42662FD9914FBD5BB", -+ "EDB4032B7FC3806D5211A534DCBC390C", -+ }, -+ -+ { ENCTYPE_AES128_CTS_HMAC_SHA1_96, SPAKE_GROUP_EDWARDS25519, -+ /* initial key, w, x, y, T, S, K */ -+ "FCA822951813FB252154C883F5EE1CF4", -+ "0D591B197B667E083C2F5F98AC891D3C9F99E710E464E62F1FB7C9B67936F3EB", -+ "50BE049A5A570FA1459FB9F666E6FD80602E4E87790A0E567F12438A2C96C138", -+ "B877AFE8612B406D96BE85BD9F19D423E95BE96C0E1E0B5824127195C3ED5917", -+ "9E9311D985C1355E022D7C3C694AD8D6F7AD6D647B68A90B0FE46992818002DA", -+ "FBE08F7F96CD5D4139E7C9ECCB95E79B8ACE41E270A60198C007DF18525B628E", -+ "C2F7F99997C585E6B686CEB62DB42F17CC70932DEF3BB4CF009E36F22EA5473D", -+ /* support, challenge, thash, body */ -+ "A0093007A0053003020101", -+ "A1363034A003020101A12204209E9311D985C1355E022D7C3C694AD8D6F7AD6D" -+ "647B68A90B0FE46992818002DAA20930073005A003020101", -+ "951285F107C87F0169B9C918A1F51F60CB1A75B9F8BB799A99F53D03ADD94B5F", -+ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" -+ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" -+ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" -+ "303130313030303030305AA703020100A8053003020111", -+ /* K'[0], K'[1], K'[2], K'[3] */ -+ "548022D58A7C47EAE8C49DCCF6BAA407", -+ "B2C9BA0E13FC8AB3A9D96B51B601CF4A", -+ "69F0EE5FDB6C237E7FCD38D9F87DF1BD", -+ "78F91E2240B5EE528A5CC8D7CBEBFBA5", -+ }, -+ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, SPAKE_GROUP_EDWARDS25519, -+ /* initial key, w, x, y, T, S, K */ -+ "01B897121D933AB44B47EB5494DB15E50EB74530DBDAE9B634D65020FF5D88C1", -+ "E902341590A1B4BB4D606A1C643CCCB3F2108F1B6AA97B381012B9400C9E3F4E", -+ "88C6C0A4F0241EF217C9788F02C32D00B72E4310748CD8FB5F94717607E6417D", -+ "88B859DF58EF5C69BACDFE681C582754EAAB09A74DC29CFF50B328613C232F55", -+ "6F301AACAE1220E91BE42868C163C5009AEEA1E9D9E28AFCFC339CDA5E7105B5", -+ "9E2CC32908FC46273279EC75354B4AEAFA70C3D99A4D507175ED70D80B255DDA", -+ "CF57F58F6E60169D2ECC8F20BB923A8E4C16E5BC95B9E64B5DC870DA7026321B", -+ /* support, challenge, thash, body */ -+ "A0093007A0053003020101", -+ "A1363034A003020101A12204206F301AACAE1220E91BE42868C163C5009AEEA1" -+ "E9D9E28AFCFC339CDA5E7105B5A20930073005A003020101", -+ "1C605649D4658B58CBE79A5FAF227ACC16C355C58B7DADE022F90C158FE5ED8E", -+ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" -+ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" -+ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" -+ "303130313030303030305AA703020100A8053003020112", -+ /* K'[0], K'[1], K'[2], K'[3] */ -+ "A9BFA71C95C575756F922871524B65288B3F695573CCC0633E87449568210C23", -+ "1865A9EE1EF0640EC28AC007391CAC624C42639C714767A974E99AA10003015F", -+ "E57781513FEFDB978E374E156B0DA0C1A08148F5EB26B8E157AC3C077E28BF49", -+ "008E6487293C3CC9FABBBCDD8B392D6DCB88222317FD7FE52D12FBC44FA047F1", -+ }, -+ -+#ifdef SPAKE_OPENSSL -+ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, SPAKE_GROUP_P256, -+ /* initial key, w, x, y, T, S, K */ -+ "01B897121D933AB44B47EB5494DB15E50EB74530DBDAE9B634D65020FF5D88C1", -+ "EB2984AF18703F94DD5288B8596CD36988D0D4E83BFB2B44DE14D0E95E2090BD", -+ "935DDD725129FB7C6288E1A5CC45782198A6416D1775336D71EACD0549A3E80E", -+ "E07405EB215663ABC1F254B8ADC0DA7A16FEBAA011AF923D79FDEF7C42930B33", -+ "024F62078CEB53840D02612195494D0D0D88DE21FEEB81187C71CBF3D01E71788D", -+ "021D07DC31266FC7CFD904CE2632111A169B7EC730E5F74A7E79700F86638E13C8", -+ "0268489D7A9983F2FDE69C6E6A1307E9D252259264F5F2DFC32F58CCA19671E79B", -+ /* support, challenge, thash, body */ -+ "A0093007A0053003020102", -+ "A1373035A003020102A1230421024F62078CEB53840D02612195494D0D0D88DE" -+ "21FEEB81187C71CBF3D01E71788DA20930073005A003020101", -+ "20AD3C1A9A90FC037D1963A1C4BFB15AB4484D7B6CF07B12D24984F14652DE60", -+ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" -+ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" -+ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" -+ "303130313030303030305AA703020100A8053003020112", -+ /* K'[0], K'[1], K'[2], K'[3] */ -+ "7D3B906F7BE49932DB22CD3463F032D06C9C078BE4B1D076D201FC6E61EF531E", -+ "17D74E36F8993841FBB7FEB12FA4F011243D3AE4D2ACE55B39379294BBC4DB2C", -+ "D192C9044081A2AA6A97A6C69E2724E8E5671C2C9CE073DD439CDBAF96D7DAB0", -+ "41E5BAD6B67F12C53CE0E2720DD6A9887F877BF9463C2D5209C74C36F8D776B7", -+ }, -+ -+ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, SPAKE_GROUP_P384, -+ /* initial key, w, x, y, T, S, K */ -+ "01B897121D933AB44B47EB5494DB15E50EB74530DBDAE9B634D65020FF5D88C1", -+ "0304CFC55151C6BBE889653DB96DBFE0BA4ACAFC024C1E8840CB3A486F6D80C1" -+ "6E1B8974016AA4B7FA43042A9B3825B1", -+ "F323CA74D344749096FD35D0ADF20806E521460637176E84D977E9933C49D76F" -+ "CFC6E62585940927468FF53D864A7A50", -+ "5B7C709ACB175A5AFB82860DEABCA8D0B341FACDFF0AC0F1A425799AA905D750" -+ "7E1EA9C573581A81467437419466E472", -+ "02A1524603EF14F184696F854229D3397507A66C63F841BA748451056BE07879" -+ "AC298912387B1C5CDFF6381C264701BE57", -+ "020D5ADFDB92BC377041CF5837412574C5D13E0F4739208A4F0C859A0A302BC6" -+ "A533440A245B9D97A0D34AF5016A20053D", -+ "0264AA8C61DA9600DFB0BEB5E46550D63740E4EF29E73F1A30D543EB43C25499" -+ "037AD16538586552761B093CF0E37C703A", -+ /* support, challenge, thash, body */ -+ "A0093007A0053003020103", -+ "A1473045A003020103A133043102A1524603EF14F184696F854229D3397507A6" -+ "6C63F841BA748451056BE07879AC298912387B1C5CDFF6381C264701BE57A209" -+ "30073005A003020101", -+ "5AC0D99EF9E5A73998797FE64F074673E3952DEC4C7D1AACCE8B75F64D2B0276" -+ "A901CB8539B4E8ED69E4DB0CE805B47B", -+ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" -+ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" -+ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" -+ "303130313030303030305AA703020100A8053003020112", -+ /* K'[0], K'[1], K'[2], K'[3] */ -+ "B917D37C16DD1D8567FBE379F64E1EE36CA3FD127AA4E60F97E4AFA3D9E56D91", -+ "93D40079DAB229B9C79366829F4E7E7282E6A4B943AC7BAC69922D516673F49A", -+ "BFC4F16F12F683E71589F9A888E232875EF293AC9793DB6C919567CD7B94BCD4", -+ "3630E2B5B99938E7506733141E8EC344166F6407E5FC2EF107C156E764D1BC20", -+ }, -+ -+ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, SPAKE_GROUP_P521, -+ /* initial key, w, x, y, T, S, K */ -+ "01B897121D933AB44B47EB5494DB15E50EB74530DBDAE9B634D65020FF5D88C1", -+ "DE3A095A2B2386EFF3EB15B735398DA1CAF95BC8425665D82370AFF58B0471F3" -+ "4A57BCCDDF1EBF0A2965B58A93EE5B45E85D1A5435D1C8C83662999722D54283" -+ "1F9A", -+ "017C38701A14B490B6081DFC83524562BE7FBB42E0B20426465E3E37952D30BC" -+ "AB0ED857010255D44936A1515607964A870C7C879B741D878F9F9CDF5A865306" -+ "F3F5", -+ "003E2E2950656FA231E959ACDD984D125E7FA59CEC98126CBC8F3888447911EB" -+ "CD49428A1C22D5FDB76A19FBEB1D9EDFA3DA6CF55B158B53031D05D51433ADE9" -+ "B2B4", -+ "02017D3DE19A3EC53D0174905665EF37947D142535102CD9809C0DFBD0DFE007" -+ "353D54CF406CE2A59950F2BB540DF6FBE75F8BBBEF811C9BA06CC275ADBD9675" -+ "6696EC", -+ "02004D142D87477841F6BA053C8F651F3395AD264B7405CA5911FB9A55ABD454" -+ "FEF658A5F9ED97D1EFAC68764E9092FA15B9E0050880D78E95FD03ABF5931791" -+ "6822B5", -+ "03007C303F62F09282CC849490805BD4457A6793A832CBEB55DF427DB6A31E99" -+ "B055D5DC99756D24D47B70AD8B6015B0FB8742A718462ED423B90FA3FE631AC1" -+ "3FA916", -+ /* support, challenge, thash, body */ -+ "A0093007A0053003020104", -+ "A1593057A003020104A145044302017D3DE19A3EC53D0174905665EF37947D14" -+ "2535102CD9809C0DFBD0DFE007353D54CF406CE2A59950F2BB540DF6FBE75F8B" -+ "BBEF811C9BA06CC275ADBD96756696ECA20930073005A003020101", -+ "8D6A89AE4D80CC4E47B6F4E48EA3E57919CC69598D0D3DC7C8BD49B6F1DB1409" -+ "CA0312944CD964E213ABA98537041102237CFF5B331E5347A0673869B412302E", -+ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" -+ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" -+ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" -+ "303130313030303030305AA703020100A8053003020112", -+ /* K'[0], K'[1], K'[2], K'[3] */ -+ "1EB3D10BEE8FAB483ADCD3EB38F3EBF1F4FEB8DB96ECC035F563CF2E1115D276", -+ "482B92781CE57F49176E4C94153CC622FE247A7DBE931D1478315F856F085890", -+ "A2C215126DD3DF280AAB5A27E1E0FB7E594192CBFF8D6D8E1B6F1818D9BB8FAC", -+ "CC06603DE984324013A01F888DE6D43B410A4DA2DEA53509F30E433C352FB668", -+ }, -+#endif /* SPAKE_OPENSSL */ -+ -+ /* Successful optimistic challenge (no support message in transcript) */ -+ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, SPAKE_GROUP_EDWARDS25519, -+ /* initial key, w, x, y, T, S, K */ -+ "01B897121D933AB44B47EB5494DB15E50EB74530DBDAE9B634D65020FF5D88C1", -+ "E902341590A1B4BB4D606A1C643CCCB3F2108F1B6AA97B381012B9400C9E3F4E", -+ "70937207344CAFBC53C8A55070E399C584CBAFCE00B836980DD4E7E74FAD2A64", -+ "785D6801A2490DF028903AC6449B105F2FF0DB895B252953CDC2076649526103", -+ "83523B35F1565006CBFC4F159885467C2FB9BC6FE23D36CB1DA43D199F1A3118", -+ "2A8F70F46CEE9030700037B77F22CEC7970DCC238E3E066D9D726BAF183992C6", -+ "D3C5E4266AA6D1B2873A97CE8AF91C7E4D7A7AC456ACCED7908D34C561AD8FA6", -+ /* support, challenge, thash, body */ -+ NULL, -+ "A1363034A003020101A122042083523B35F1565006CBFC4F159885467C2FB9BC" -+ "6FE23D36CB1DA43D199F1A3118A20930073005A003020101", -+ "26F07F9F8965307434D11EA855461D41E0CBABCC0A1BAB48ECEE0C6C1A4292B7", -+ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" -+ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" -+ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" -+ "303130313030303030305AA703020100A8053003020112", -+ /* K'[0], K'[1], K'[2], K'[3] */ -+ "4569EC08B5DE5C3CC19D941725913ACE8D74524B521A341DC746ACD5C3784D92", -+ "0D96CE1A4AC0F2E280A0CFC31742B06461D83D04AE45433DB2D80478DD882A4C", -+ "58018C19315A1BA5D5BB9813B58029F0AEC18A6F9CA59E0847DE1C60BC25945C", -+ "ED7E9BFFD68C54D86FB19CD3C03F317F88A71AD9A5E94C28581D93FC4EC72B6A", -+ }, -+ -+#ifdef SPAKE_OPENSSL -+ /* Rejected optimistic challenge (no support message in transcript), -+ * falling back from edwards25519 to P-521 */ -+ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, SPAKE_GROUP_P521, -+ /* initial key, w, x, y, T, S, K */ -+ "01B897121D933AB44B47EB5494DB15E50EB74530DBDAE9B634D65020FF5D88C1", -+ "DE3A095A2B2386EFF3EB15B735398DA1CAF95BC8425665D82370AFF58B0471F3" -+ "4A57BCCDDF1EBF0A2965B58A93EE5B45E85D1A5435D1C8C83662999722D54283" -+ "1F9A", -+ "01687B59051BF40048D7C31D5A973D792FA12284B7A447E7F5938B5885CA0BB2" -+ "C3F0BD30291A55FEA08E143E2E04BDD7D19B753C7C99032F06CAB0D9C2AA8F83" -+ "7EF7", -+ "01DED675EBF74FE30C9A53710F577E9CF84F09F6048FE245A4600004884CC167" -+ "733F9A9E43108FB83BABE8754CD37CBD7025E28BC9FF870F084C7244F536285E" -+ "25B4", -+ "02014CB2E5B592ECE5990F0EF30D308C061DE1598BC4272B4A6599BED466FD15" -+ "21693642ABCF4DBE36CE1A2D13967DE45F6C4F8D0FA8E14428BF03FB96EF5F1E" -+ "D3E645", -+ "02016C64995E804416F748FD5FA3AA678CBC7CBB596A4F523132DC8AF7CE84E5" -+ "41F484A2C74808C6B21DCF7775BAEFA6753398425BECC7B838B210AC5DAA0CB0" -+ "B710E2", -+ "0200997F4848AE2E7A98C23D14AC662030743AB37FCCC2A45F1C721114F40BCC" -+ "80FE6EC6ABA49868F8AEA1AA994D50E81B86D3E4D3C1130C8695B68907C673D9" -+ "E5886A", -+ /* support, challenge, thash, body */ -+ "A0093007A0053003020104", -+ "A1593057A003020104A145044302014CB2E5B592ECE5990F0EF30D308C061DE1" -+ "598BC4272B4A6599BED466FD1521693642ABCF4DBE36CE1A2D13967DE45F6C4F" -+ "8D0FA8E14428BF03FB96EF5F1ED3E645A20930073005A003020101", -+ "D0EFED5E3E2C39C26034756D92A66FEC3082AD793D0197F3F89AD36026F146A3" -+ "996E548AA3FC49E2E82F8CAC5D132C505AA475B39E7BE79CDED22C26C41AA777", -+ "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" -+ "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" -+ "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" -+ "303130313030303030305AA703020100A8053003020112", -+ /* K'[0], K'[1], K'[2], K'[3] */ -+ "631FCC8596E7F40E59045950D72AA0B7BAC2810A07B767050E983841CF3A2D4C", -+ "881464920117074DBC67155A8F3341D1121EF65F78EA0380BFA81A134C1C47B1", -+ "377B72AC3AF2CAAD582D73AE4682FD56B531EE56706200DD6C38C42B8219837A", -+ "35AD8E4D580ED3F0D15AD928329773C081BD19F9A56363F3A5F77C7E66108C26", -+ }, -+#endif /* SPAKE_OPENSSL */ -+}; -+ -+static krb5_context ctx; -+ -+static void -+check(krb5_error_code code) -+{ -+ const char *errmsg; -+ -+ if (code) { -+ errmsg = krb5_get_error_message(ctx, code); -+ assert(errmsg != NULL); -+ abort(); -+ } -+} -+ -+static void -+check_key_equal(const krb5_keyblock *kb1, const krb5_keyblock *kb2) -+{ -+ assert(kb1->enctype == kb2->enctype); -+ assert(kb1->length == kb2->length); -+ assert(memcmp(kb1->contents, kb2->contents, kb1->length) == 0); -+} -+ -+static krb5_data * -+decode_data(const char *s) -+{ -+ uint8_t *bytes; -+ size_t len; -+ krb5_data *d; -+ -+ if (k5_hex_decode(s, &bytes, &len) != 0) -+ abort(); -+ d = malloc(sizeof(*d)); -+ assert(d != NULL); -+ *d = make_data(bytes, len); -+ return d; -+} -+ -+static krb5_keyblock * -+decode_keyblock(krb5_enctype enctype, const char *s) -+{ -+ uint8_t *bytes; -+ size_t len; -+ krb5_keyblock *kb; -+ -+ if (k5_hex_decode(s, &bytes, &len) != 0) -+ abort(); -+ kb = malloc(sizeof(*kb)); -+ kb->magic = KV5M_KEYBLOCK; -+ kb->enctype = enctype; -+ kb->length = len; -+ kb->contents = bytes; -+ return kb; -+} -+ -+static void -+run_test(const struct test *t) -+{ -+ groupstate *gstate; -+ krb5_keyblock *ikey, *K0, *K1, *K2, *K3, *kb; -+ krb5_data *w, *x, *y, *T, *S, *K, *support, *challenge, *thash; -+ krb5_data *body, wbytes, result, hash, empty = empty_data(); -+ -+ /* Decode hex strings into keyblocks and byte strings. */ -+ ikey = decode_keyblock(t->enctype, t->ikey); -+ w = decode_data(t->w); -+ x = decode_data(t->x); -+ y = decode_data(t->y); -+ T = decode_data(t->T); -+ S = decode_data(t->S); -+ K = decode_data(t->K); -+ support = (t->support != NULL) ? decode_data(t->support) : NULL; -+ challenge = decode_data(t->challenge); -+ thash = decode_data(t->thash); -+ body = decode_data(t->body); -+ K0 = decode_keyblock(t->enctype, t->K0); -+ K1 = decode_keyblock(t->enctype, t->K1); -+ K2 = decode_keyblock(t->enctype, t->K2); -+ K3 = decode_keyblock(t->enctype, t->K3); -+ -+ check(derive_wbytes(ctx, t->group, ikey, &wbytes)); -+ assert(data_eq(*w, wbytes)); -+ -+ /* Verify KDC-side result computation. */ -+ check(group_init_state(ctx, TRUE, &gstate)); -+ check(group_result(ctx, gstate, t->group, &wbytes, x, S, &result)); -+ assert(data_eq(*K, result)); -+ krb5_free_data_contents(ctx, &result); -+ group_free_state(gstate); -+ -+ /* Verify client-side result computation. */ -+ check(group_init_state(ctx, FALSE, &gstate)); -+ check(group_result(ctx, gstate, t->group, &wbytes, y, T, &result)); -+ assert(data_eq(*K, result)); -+ krb5_free_data_contents(ctx, &result); -+ -+ /* Verify transcript hash. */ -+ hash = empty_data(); -+ check(update_thash(ctx, gstate, t->group, &hash, support, challenge)); -+ check(update_thash(ctx, gstate, t->group, &hash, S, &empty)); -+ assert(data_eq(*thash, hash)); -+ krb5_free_data_contents(ctx, &hash); -+ -+ /* Verify derived keys. */ -+ check(derive_key(ctx, gstate, t->group, ikey, &wbytes, K, thash, body, 0, -+ &kb)); -+ check_key_equal(K0, kb); -+ krb5_free_keyblock(ctx, kb); -+ check(derive_key(ctx, gstate, t->group, ikey, &wbytes, K, thash, body, 1, -+ &kb)); -+ check_key_equal(K1, kb); -+ krb5_free_keyblock(ctx, kb); -+ check(derive_key(ctx, gstate, t->group, ikey, &wbytes, K, thash, body, 2, -+ &kb)); -+ check_key_equal(K2, kb); -+ krb5_free_keyblock(ctx, kb); -+ check(derive_key(ctx, gstate, t->group, ikey, &wbytes, K, thash, body, 3, -+ &kb)); -+ check_key_equal(K3, kb); -+ krb5_free_keyblock(ctx, kb); -+ -+ group_free_state(gstate); -+ krb5_free_data_contents(ctx, &wbytes); -+ krb5_free_keyblock(ctx, ikey); -+ krb5_free_data(ctx, w); -+ krb5_free_data(ctx, x); -+ krb5_free_data(ctx, y); -+ krb5_free_data(ctx, T); -+ krb5_free_data(ctx, S); -+ krb5_free_data(ctx, K); -+ krb5_free_data(ctx, support); -+ krb5_free_data(ctx, challenge); -+ krb5_free_data(ctx, thash); -+ krb5_free_data(ctx, body); -+ krb5_free_keyblock(ctx, K0); -+ krb5_free_keyblock(ctx, K1); -+ krb5_free_keyblock(ctx, K2); -+ krb5_free_keyblock(ctx, K3); -+} -+ -+int -+main() -+{ -+ size_t i; -+ -+ check(krb5_init_context(&ctx)); -+ for (i = 0; i < sizeof(tests) / sizeof(*tests); i++) -+ run_test(&tests[i]); -+ krb5_free_context(ctx); -+ return 0; -+} -diff --git a/src/plugins/preauth/spake/trace.h b/src/plugins/preauth/spake/trace.h -new file mode 100644 -index 000000000..9dd964260 ---- /dev/null -+++ b/src/plugins/preauth/spake/trace.h -@@ -0,0 +1,74 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* plugins/preauth/spake/internal.h - SPAKE internal function declarations */ -+/* -+ * Copyright (C) 2015 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#ifndef TRACE_H -+#define TRACE_H -+ -+#include "k5-int.h" -+ -+/* -+ * Possible improvements at the cost of more code: -+ * - Groups could be displayed by name instead of number -+ * - We could display the group list when tracing support messages -+ */ -+ -+#define TRACE_SPAKE_CLIENT_THASH(c, thash) \ -+ TRACE(c, "SPAKE final transcript hash: {hexdata}", thash) -+#define TRACE_SPAKE_DERIVE_KEY(c, n, kb) \ -+ TRACE(c, "SPAKE derived K'[{int}] = {keyblock}", n, kb) -+#define TRACE_SPAKE_KDC_THASH(c, thash) \ -+ TRACE(c, "SPAKE final transcript hash: {hexdata}", thash) -+#define TRACE_SPAKE_KEYGEN(c, pubkey) \ -+ TRACE(c, "SPAKE key generated with pubkey {hexdata}", pubkey) -+#define TRACE_SPAKE_RECEIVE_CHALLENGE(c, group, pubkey) \ -+ TRACE(c, "SPAKE challenge received with group {int}, pubkey {hexdata}", \ -+ group, pubkey) -+#define TRACE_SPAKE_RECEIVE_RESPONSE(c, pubkey) \ -+ TRACE(c, "SPAKE response received with pubkey {hexdata}", pubkey) -+#define TRACE_SPAKE_RECEIVE_SUPPORT(c, group) \ -+ TRACE(c, "SPAKE support message received, selected group {int}", group) -+#define TRACE_SPAKE_REJECT_CHALLENGE(c, group) \ -+ TRACE(c, "SPAKE challenge with group {int} rejected", (int)group) -+#define TRACE_SPAKE_REJECT_SUPPORT(c) \ -+ TRACE(c, "SPAKE support message rejected") -+#define TRACE_SPAKE_RESULT(c, result) \ -+ TRACE(c, "SPAKE algorithm result: {hexdata}", result) -+#define TRACE_SPAKE_SEND_CHALLENGE(c, group) \ -+ TRACE(c, "Sending SPAKE challenge with group {int}", group) -+#define TRACE_SPAKE_SEND_RESPONSE(c) \ -+ TRACE(c, "Sending SPAKE response") -+#define TRACE_SPAKE_SEND_SUPPORT(c) \ -+ TRACE(c, "Sending SPAKE support message") -+#define TRACE_SPAKE_UNKNOWN_GROUP(c, name) \ -+ TRACE(c, "Unrecognized SPAKE group name: {string}", name) -+ -+#endif /* TRACE_H */ -diff --git a/src/plugins/preauth/spake/util.c b/src/plugins/preauth/spake/util.c -new file mode 100644 -index 000000000..cbdbbd7ac ---- /dev/null -+++ b/src/plugins/preauth/spake/util.c -@@ -0,0 +1,211 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* plugins/preauth/spake/util.c - Utility functions for SPAKE preauth module */ -+/* -+ * Copyright (C) 2015 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include "k5-int.h" -+#include "trace.h" -+#include "util.h" -+#include "groups.h" -+ -+/* Use data to construct a single-element pa-data list of type -+ * KRB5_PADATA_SPAKE. Claim data's memory on success or failure. */ -+krb5_error_code -+convert_to_padata(krb5_data *data, krb5_pa_data ***pa_out) -+{ -+ krb5_pa_data *pa = NULL, **list = NULL; -+ -+ list = calloc(2, sizeof(*list)); -+ if (list == NULL) -+ goto fail; -+ pa = calloc(1, sizeof(*pa)); -+ if (pa == NULL) -+ goto fail; -+ pa->magic = KV5M_PA_DATA; -+ pa->pa_type = KRB5_PADATA_SPAKE; -+ pa->length = data->length; -+ pa->contents = (uint8_t *)data->data; -+ list[0] = pa; -+ list[1] = NULL; -+ *pa_out = list; -+ free(data); -+ return 0; -+ -+fail: -+ free(list); -+ free(pa); -+ free(data->data); -+ free(data); -+ return ENOMEM; -+} -+ -+/* -+ * Update the transcript hash thash with its current value and the -+ * concatenation of data1 and data2, using the hash function for group. Either -+ * data1 or data2 may be NULL to omit it. Allocate thash if it is empty. -+ */ -+krb5_error_code -+update_thash(krb5_context context, groupstate *gstate, int32_t group, -+ krb5_data *thash, const krb5_data *data1, const krb5_data *data2) -+{ -+ krb5_error_code ret; -+ size_t hashlen; -+ krb5_data dlist[3]; -+ -+ if (thash->length == 0) { -+ /* Initialize the transcript hash to all zeros. */ -+ ret = group_hash_len(group, &hashlen); -+ if (ret) -+ return ret; -+ ret = alloc_data(thash, hashlen); -+ if (ret) -+ return ret; -+ } -+ -+ /* Set up the data array and hash it with the group's hash function. */ -+ dlist[0] = *thash; -+ dlist[1] = (data1 != NULL) ? *data1 : empty_data(); -+ dlist[2] = (data2 != NULL) ? *data2 : empty_data(); -+ return group_hash(context, gstate, group, dlist, 3, -+ (uint8_t *)thash->data); -+} -+ -+/* Derive a byte vector for the SPAKE w multiplier input from ikey. Place -+ * result in allocated storage in *wbytes_out. */ -+krb5_error_code -+derive_wbytes(krb5_context context, int32_t group, const krb5_keyblock *ikey, -+ krb5_data *wbytes_out) -+{ -+ krb5_error_code ret; -+ const char prefix[] = "SPAKEsecret"; -+ size_t mult_len, prefix_len = sizeof(prefix) - 1; -+ krb5_data prf_input = empty_data(), wbytes = empty_data(); -+ -+ *wbytes_out = empty_data(); -+ -+ /* Allocate space for a multiplier. */ -+ ret = group_mult_len(group, &mult_len); -+ if (ret) -+ goto cleanup; -+ ret = alloc_data(&wbytes, mult_len); -+ if (ret) -+ goto cleanup; -+ -+ /* Compose the PRF input string. */ -+ ret = alloc_data(&prf_input, prefix_len + 4); -+ if (ret) -+ goto cleanup; -+ memcpy(prf_input.data, prefix, prefix_len); -+ store_32_be(group, prf_input.data + prefix_len); -+ -+ /* Derive the SPAKE input from the initial reply key with PRF+. */ -+ ret = krb5_c_prfplus(context, ikey, &prf_input, &wbytes); -+ if (ret) -+ goto cleanup; -+ -+ *wbytes_out = wbytes; -+ wbytes = empty_data(); -+ -+cleanup: -+ free(prf_input.data); -+ zapfree(wbytes.data, wbytes.length); -+ return ret; -+} -+ -+/* -+ * Derive K'[n] from the group number, the initial key enctype, the initial -+ * multiplier, the SPAKE result, the transcript hash, and the encoded -+ * KDC-REQ-BODY. Place the result in allocated storage in *out. -+ */ -+krb5_error_code -+derive_key(krb5_context context, groupstate *gstate, int32_t group, -+ const krb5_keyblock *ikey, const krb5_data *wbytes, -+ const krb5_data *spakeresult, const krb5_data *thash, -+ const krb5_data *der_req, uint32_t n, krb5_keyblock **out) -+{ -+ krb5_error_code ret; -+ krb5_data dlist[9], seed = empty_data(), d; -+ uint8_t groupnbuf[4], etypenbuf[4], nbuf[4], bcount; -+ size_t hashlen, seedlen, keylen, nblocks, i; -+ size_t ndata = sizeof(dlist) / sizeof(*dlist); -+ krb5_keyblock *hkey = NULL; -+ -+ *out = NULL; -+ -+ store_32_be(group, groupnbuf); -+ store_32_be(n, nbuf); -+ store_32_be(ikey->enctype, etypenbuf); -+ dlist[0] = string2data("SPAKEkey"); -+ dlist[1] = make_data(groupnbuf, sizeof(groupnbuf)); -+ dlist[2] = make_data(etypenbuf, sizeof(etypenbuf)); -+ dlist[3] = *wbytes; -+ dlist[4] = *spakeresult; -+ dlist[5] = *thash; -+ dlist[6] = *der_req; -+ dlist[7] = make_data(nbuf, sizeof(nbuf)); -+ dlist[8] = make_data(&bcount, 1); -+ -+ /* Count the number of hash blocks required (should be 1 for all current -+ * scenarios) and allocate space. */ -+ ret = group_hash_len(group, &hashlen); -+ if (ret) -+ goto cleanup; -+ ret = krb5_c_keylengths(context, ikey->enctype, &seedlen, &keylen); -+ if (ret) -+ goto cleanup; -+ nblocks = (seedlen + hashlen - 1) / hashlen; -+ ret = alloc_data(&seed, nblocks * hashlen); -+ if (ret) -+ goto cleanup; -+ -+ /* Compute and concatenate hash blocks to fill the seed buffer. */ -+ for (i = 0; i < nblocks; i++) { -+ bcount = i + 1; -+ ret = group_hash(context, gstate, group, dlist, ndata, -+ (uint8_t *)seed.data + i * hashlen); -+ if (ret) -+ goto cleanup; -+ } -+ -+ ret = krb5_init_keyblock(context, ikey->enctype, keylen, &hkey); -+ if (ret) -+ goto cleanup; -+ d = make_data(seed.data, seedlen); -+ ret = krb5_c_random_to_key(context, ikey->enctype, &d, hkey); -+ if (ret) -+ goto cleanup; -+ -+ ret = krb5_c_fx_cf2_simple(context, ikey, "SPAKE", hkey, "keyderiv", out); -+ -+cleanup: -+ zapfree(seed.data, seed.length); -+ krb5_free_keyblock(context, hkey); -+ return ret; -+} -diff --git a/src/plugins/preauth/spake/util.h b/src/plugins/preauth/spake/util.h -new file mode 100644 -index 000000000..3ab2bead1 ---- /dev/null -+++ b/src/plugins/preauth/spake/util.h -@@ -0,0 +1,56 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* plugins/preauth/spake/internal.h - SPAKE internal function declarations */ -+/* -+ * Copyright (C) 2015 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#ifndef UTIL_H -+#define UTIL_H -+ -+#include "k5-int.h" -+#include "groups.h" -+ -+krb5_error_code convert_to_padata(krb5_data *data, krb5_pa_data ***pa_out); -+ -+krb5_error_code update_thash(krb5_context context, groupstate *gstate, -+ int32_t group, krb5_data *thash, -+ const krb5_data *data1, const krb5_data *data2); -+ -+krb5_error_code derive_wbytes(krb5_context context, int32_t group, -+ const krb5_keyblock *ikey, -+ krb5_data *wbytes_out); -+ -+krb5_error_code derive_key(krb5_context context, groupstate *gstate, -+ int32_t group, const krb5_keyblock *ikey, -+ const krb5_data *wbytes, -+ const krb5_data *spakeresult, -+ const krb5_data *thash, const krb5_data *der_req, -+ uint32_t n, krb5_keyblock **out); -+ -+#endif /* UTIL_H */ -diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in -index 67d3e8200..aed23e570 100644 ---- a/src/tests/Makefile.in -+++ b/src/tests/Makefile.in -@@ -130,6 +130,7 @@ check-pytests: unlockiter - $(RUNPYTEST) $(srcdir)/t_changepw.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_pkinit.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_otp.py $(PYTESTFLAGS) -+ $(RUNPYTEST) $(srcdir)/t_spake.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_localauth.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_kadm5_hook.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_kadm5_auth.py $(PYTESTFLAGS) -diff --git a/src/tests/t_spake.py b/src/tests/t_spake.py -new file mode 100644 -index 000000000..a81a238b4 ---- /dev/null -+++ b/src/tests/t_spake.py -@@ -0,0 +1,151 @@ -+#!/usr/bin/python -+from k5test import * -+ -+# The name and number of each supported SPAKE group. -+builtin_groups = ((1, 'edwards25519'),) -+openssl_groups = ((2, 'P-256'), (3, 'P-384'), (4, 'P-521')) -+if runenv.have_spake_openssl == 'yes': -+ groups = builtin_groups + openssl_groups -+else: -+ groups = builtin_groups -+ -+for gnum, gname in groups: -+ output('*** Testing group %s\n' % gname) -+ conf = {'libdefaults': {'spake_preauth_groups': gname}} -+ for realm in multipass_realms(create_user=False, create_host=False, -+ krb5_conf=conf): -+ realm.run([kadminl, 'addprinc', '+preauth', '-pw', 'pw', 'user']) -+ -+ # Test a basic SPAKE preauth scenario with no optimizations. -+ msgs = ('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Selected etype info:', -+ 'Sending SPAKE support message', -+ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', -+ '/More preauthentication data is required', -+ 'Continuing preauth mech PA-SPAKE (151)', -+ 'SPAKE challenge received with group ' + str(gnum), -+ 'Sending SPAKE response', -+ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', -+ 'AS key determined by preauth:', -+ 'Decrypted AS reply') -+ realm.kinit('user', 'pw', expected_trace=msgs) -+ -+ # Test an unsuccessful authentication. (The client will try -+ # again with encrypted timestamp, which isn't really desired, -+ # but check for that as long as it is expected.) -+ msgs = ('/Additional pre-authentication required', -+ 'Selected etype info:', -+ 'Sending SPAKE support message', -+ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', -+ '/More preauthentication data is required', -+ 'Continuing preauth mech PA-SPAKE (151)', -+ 'SPAKE challenge received with group ' + str(gnum), -+ 'Sending SPAKE response', -+ '/Preauthentication failed', -+ 'Encrypted timestamp ', -+ 'for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', -+ '/Preauthentication failed') -+ realm.kinit('user', 'wrongpw', expected_code=1, expected_trace=msgs) -+ -+conf = {'libdefaults': {'spake_preauth_groups': 'edwards25519'}} -+kdcconf = {'realms': {'$realm': {'spake_preauth_indicator': 'indspake'}}} -+realm = K5Realm(create_user=False, krb5_conf=conf, kdc_conf=kdcconf) -+realm.run([kadminl, 'addprinc', '+preauth', '-pw', 'pw', 'user']) -+ -+# Test with FAST. -+msgs = ('Using FAST due to armor ccache negotiation', -+ 'FAST armor key:', -+ 'Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Decoding FAST response', -+ 'Selected etype info:', -+ 'Sending SPAKE support message', -+ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', -+ '/More preauthentication data is required', -+ 'Continuing preauth mech PA-SPAKE (151)', -+ 'SPAKE challenge received with group 1', -+ 'Sending SPAKE response', -+ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', -+ 'AS key determined by preauth:', -+ 'FAST reply key:') -+realm.kinit(realm.host_princ, flags=['-k']) -+realm.kinit('user', 'pw', flags=['-T', realm.ccache], expected_trace=msgs) -+ -+# Test optimistic client preauth (151 is PA-SPAKE). -+msgs = ('Attempting optimistic preauth', -+ 'Processing preauth types: PA-SPAKE (151)', -+ 'Sending SPAKE support message', -+ 'for next request: PA-SPAKE (151)', -+ '/More preauthentication data is required', -+ 'Selected etype info:', -+ 'SPAKE challenge received with group 1', -+ 'Sending SPAKE response', -+ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', -+ 'AS key determined by preauth:', -+ 'Decrypted AS reply') -+realm.run(['./icred', '-o', '151', 'user', 'pw'], expected_trace=msgs) -+ -+# Test KDC optimistic challenge (accepted by client). -+oconf = {'kdcdefaults': {'spake_preauth_kdc_challenge': 'edwards25519'}} -+oenv = realm.special_env('ochal', True, krb5_conf=oconf) -+realm.stop_kdc() -+realm.start_kdc(env=oenv) -+msgs = ('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Selected etype info:', -+ 'SPAKE challenge received with group 1', -+ 'Sending SPAKE response', -+ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', -+ 'AS key determined by preauth:', -+ 'Decrypted AS reply') -+realm.kinit('user', 'pw', expected_trace=msgs) -+ -+if runenv.have_spake_openssl != 'yes': -+ skip_rest('SPAKE fallback tests', 'SPAKE not built using OpenSSL') -+ -+# Test optimistic client preauth falling back to encrypted timestamp -+# because the KDC doesn't support any of the client groups. -+p256conf={'libdefaults': {'spake_preauth_groups': 'P-256'}} -+p256env = realm.special_env('p256', False, krb5_conf=p256conf) -+msgs = ('Attempting optimistic preauth', -+ 'Processing preauth types: PA-SPAKE (151)', -+ 'Sending SPAKE support message', -+ 'for next request: PA-SPAKE (151)', -+ '/Preauthentication failed', -+ 'Selected etype info:', -+ 'SPAKE challenge with group 1 rejected', -+ 'spake (151) (real) returned: -1765328360/Preauthentication failed', -+ 'Encrypted timestamp ', -+ 'for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', -+ 'AS key determined by preauth:', -+ 'Decrypted AS reply') -+realm.run(['./icred', '-o', '151', 'user', 'pw'], env=p256env, -+ expected_trace=msgs) -+ -+# Test KDC optimistic challenge (rejected by client). -+rconf = {'libdefaults': {'spake_preauth_groups': 'P-384,edwards25519'}, -+ 'kdcdefaults': {'spake_preauth_kdc_challenge': 'P-384'}} -+renv = realm.special_env('ochal', True, krb5_conf=rconf) -+realm.stop_kdc() -+realm.start_kdc(env=renv) -+msgs = ('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Selected etype info:', -+ 'SPAKE challenge with group 3 rejected', -+ 'Sending SPAKE support message', -+ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', -+ '/More preauthentication data is required', -+ 'Continuing preauth mech PA-SPAKE (151)', -+ 'SPAKE challenge received with group 1', -+ 'Sending SPAKE response', -+ 'for next request: PA-FX-COOKIE (133), PA-SPAKE (151)', -+ 'AS key determined by preauth:', -+ 'Decrypted AS reply') -+realm.kinit('user', 'pw', expected_trace=msgs) -+ -+# Check that the auth indicator for SPAKE is properly included by the KDC. -+realm.run([kvno, realm.host_princ]) -+realm.run(['./adata', realm.host_princ], expected_msg='+97: [indspake]') -+ -+success('SPAKE pre-authentication tests') diff --git a/Add-doc-index-entries-for-SPAKE-constants.patch b/Add-doc-index-entries-for-SPAKE-constants.patch deleted file mode 100644 index 7ac2afe..0000000 --- a/Add-doc-index-entries-for-SPAKE-constants.patch +++ /dev/null @@ -1,31 +0,0 @@ -From c891e4bc54c8083a1af8d28aa9b12ab1177ebb9a Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 27 Mar 2018 00:49:43 -0400 -Subject: [PATCH] Add doc index entries for SPAKE constants - -ticket: 8647 -(cherry picked from commit c010c9031753f356bb380e8a1324cc34721f8221) ---- - doc/appdev/refs/macros/index.rst | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst -index dba818b26..47c6d4413 100644 ---- a/doc/appdev/refs/macros/index.rst -+++ b/doc/appdev/refs/macros/index.rst -@@ -190,6 +190,7 @@ Public - KRB5_KEYUSAGE_PA_SAM_CHALLENGE_CKSUM.rst - KRB5_KEYUSAGE_PA_SAM_CHALLENGE_TRACKID.rst - KRB5_KEYUSAGE_PA_SAM_RESPONSE.rst -+ KRB5_KEYUSAGE_SPAKE.rst - KRB5_KEYUSAGE_TGS_REP_ENCPART_SESSKEY.rst - KRB5_KEYUSAGE_TGS_REP_ENCPART_SUBKEY.rst - KRB5_KEYUSAGE_TGS_REQ_AD_SESSKEY.rst -@@ -274,6 +275,7 @@ Public - KRB5_PADATA_SAM_RESPONSE.rst - KRB5_PADATA_SAM_RESPONSE_2.rst - KRB5_PADATA_SESAME.rst -+ KRB5_PADATA_SPAKE.rst - KRB5_PADATA_SVR_REFERRAL_INFO.rst - KRB5_PADATA_TGS_REQ.rst - KRB5_PADATA_USE_SPECIFIED_KVNO.rst diff --git a/Add-flag-to-disable-encrypted-timestamp-on-client.patch b/Add-flag-to-disable-encrypted-timestamp-on-client.patch deleted file mode 100644 index adc4f41..0000000 --- a/Add-flag-to-disable-encrypted-timestamp-on-client.patch +++ /dev/null @@ -1,204 +0,0 @@ -From f44ef4893050e673f495444c27a19525813f75a8 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 11 Jun 2018 13:53:27 -0400 -Subject: [PATCH] Add flag to disable encrypted timestamp on client - -ticket: 8655 -(cherry picked from commit 4ad376134b8d456392edbac7a7d351e6c7a7f0e7) ---- - doc/admin/conf_files/krb5_conf.rst | 10 ++++++++++ - doc/admin/spake.rst | 8 ++++++++ - src/include/k5-int.h | 1 + - src/include/k5-trace.h | 2 ++ - src/lib/krb5/krb/get_in_tkt.c | 23 +++++++++++++++++++++++ - src/lib/krb5/krb/init_creds_ctx.h | 1 + - src/lib/krb5/krb/preauth_encts.c | 14 +++++++++++++- - src/tests/t_referral.py | 13 +++++++++++++ - 8 files changed, 71 insertions(+), 1 deletion(-) - -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index ce545492d..eb5c29e5d 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -475,6 +475,16 @@ following tags may be specified in the realm's subsection: - (for example, when converting ``rcmd.hostname`` to - ``host/hostname.domain``). - -+**disable_encrypted_timestamp** -+ If this flag is true, the client will not perform encrypted -+ timestamp preauthentication if requested by the KDC. Setting this -+ flag can help to prevent dictionary attacks by active attackers, -+ if the realm's KDCs support SPAKE preauthentication or if initial -+ authentication always uses another mechanism or always uses FAST. -+ This flag persists across client referrals during initial -+ authentication. This flag does not prevent the KDC from offering -+ encrypted timestamp. New in release 1.17. -+ - **http_anchors** - When KDCs and kpasswd servers are accessed through HTTPS proxies, this tag - can be used to specify the location of the CA certificate which should be -diff --git a/doc/admin/spake.rst b/doc/admin/spake.rst -index b65c694aa..4f6eeaf53 100644 ---- a/doc/admin/spake.rst -+++ b/doc/admin/spake.rst -@@ -30,6 +30,14 @@ principal entries, as you would for any preauthentication mechanism:: - Clients which do not implement SPAKE preauthentication will fall back - to encrypted timestamp. - -+An active attacker can force a fallback to encrypted timestamp by -+modifying the initial KDC response, defeating the protection against -+dictionary attacks. To prevent this fallback on clients which do -+implement SPAKE preauthentication, set the -+**disable_encrypted_timestamp** variable to ``true`` in the -+:ref:`realms` subsection for realms whose KDCs offer SPAKE -+preauthentication. -+ - By default, SPAKE preauthentication requires an extra network round - trip to the KDC during initial authentication. If most of the clients - in a realm support SPAKE, this extra round trip can be eliminated -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 86b53c76b..e4a9a1412 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -204,6 +204,7 @@ typedef unsigned char u_char; - #define KRB5_CONF_DES_CRC_SESSION_SUPPORTED "des_crc_session_supported" - #define KRB5_CONF_DICT_FILE "dict_file" - #define KRB5_CONF_DISABLE "disable" -+#define KRB5_CONF_DISABLE_ENCRYPTED_TIMESTAMP "disable_encrypted_timestamp" - #define KRB5_CONF_DISABLE_LAST_SUCCESS "disable_last_success" - #define KRB5_CONF_DISABLE_LOCKOUT "disable_lockout" - #define KRB5_CONF_DNS_CANONICALIZE_HOSTNAME "dns_canonicalize_hostname" -diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h -index 5f7eb9517..0854974dc 100644 ---- a/src/include/k5-trace.h -+++ b/src/include/k5-trace.h -@@ -299,6 +299,8 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); - #define TRACE_PREAUTH_ENC_TS(c, sec, usec, plain, enc) \ - TRACE(c, "Encrypted timestamp (for {long}.{int}): plain {hexdata}, " \ - "encrypted {hexdata}", (long) sec, (int) usec, plain, enc) -+#define TRACE_PREAUTH_ENC_TS_DISABLED(c) \ -+ TRACE(c, "Ignoring encrypted timestamp because it is disabled") - #define TRACE_PREAUTH_ETYPE_INFO(c, etype, salt, s2kparams) \ - TRACE(c, "Selected etype info: etype {etype}, salt \"{data}\", " \ - "params \"{data}\"", etype, salt, s2kparams) -diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c -index c026bbc6d..79dede2c6 100644 ---- a/src/lib/krb5/krb/get_in_tkt.c -+++ b/src/lib/krb5/krb/get_in_tkt.c -@@ -801,6 +801,24 @@ read_allowed_preauth_type(krb5_context context, krb5_init_creds_context ctx) - free(tmp); - } - -+/* Return true if encrypted timestamp is disabled for realm. */ -+static krb5_boolean -+encts_disabled(profile_t profile, const krb5_data *realm) -+{ -+ krb5_error_code ret; -+ char *realmstr; -+ int bval; -+ -+ realmstr = k5memdup0(realm->data, realm->length, &ret); -+ if (realmstr == NULL) -+ return FALSE; -+ ret = profile_get_boolean(profile, KRB5_CONF_REALMS, realmstr, -+ KRB5_CONF_DISABLE_ENCRYPTED_TIMESTAMP, FALSE, -+ &bval); -+ free(realmstr); -+ return (ret == 0) ? bval : FALSE; -+} -+ - /** - * Throw away any pre-authentication realm state and begin with a - * unauthenticated or optimistically authenticated request. If fast_upgrade is -@@ -842,6 +860,11 @@ restart_init_creds_loop(krb5_context context, krb5_init_creds_context ctx, - goto cleanup; - } - -+ /* Never set encts_disabled back to false, so it can't be circumvented with -+ * client realm referrals. */ -+ if (encts_disabled(context->profile, &ctx->request->client->realm)) -+ ctx->encts_disabled = TRUE; -+ - krb5_free_principal(context, ctx->request->server); - ctx->request->server = NULL; - -diff --git a/src/lib/krb5/krb/init_creds_ctx.h b/src/lib/krb5/krb/init_creds_ctx.h -index 7ba61e17c..7a6219b1c 100644 ---- a/src/lib/krb5/krb/init_creds_ctx.h -+++ b/src/lib/krb5/krb/init_creds_ctx.h -@@ -61,6 +61,7 @@ struct _krb5_init_creds_context { - krb5_boolean info_pa_permitted; - krb5_boolean restarted; - krb5_boolean fallback_disabled; -+ krb5_boolean encts_disabled; - struct krb5_responder_context_st rctx; - krb5_preauthtype selected_preauth_type; - krb5_preauthtype allowed_preauth_type; -diff --git a/src/lib/krb5/krb/preauth_encts.c b/src/lib/krb5/krb/preauth_encts.c -index 45bf9da92..345701984 100644 ---- a/src/lib/krb5/krb/preauth_encts.c -+++ b/src/lib/krb5/krb/preauth_encts.c -@@ -28,6 +28,7 @@ - #include - #include - #include "int-proto.h" -+#include "init_creds_ctx.h" - - static krb5_error_code - encts_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata, -@@ -38,7 +39,10 @@ encts_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata, - krb5_data *encoded_previous_request, - krb5_pa_data *pa_data) - { -- cb->need_as_key(context, rock); -+ krb5_init_creds_context ctx = (krb5_init_creds_context)rock; -+ -+ if (!ctx->encts_disabled) -+ cb->need_as_key(context, rock); - return 0; - } - -@@ -51,6 +55,7 @@ encts_process(krb5_context context, krb5_clpreauth_moddata moddata, - krb5_prompter_fct prompter, void *prompter_data, - krb5_pa_data ***out_padata) - { -+ krb5_init_creds_context ctx = (krb5_init_creds_context)rock; - krb5_error_code ret; - krb5_pa_enc_ts pa_enc; - krb5_data *ts = NULL, *enc_ts = NULL; -@@ -60,6 +65,13 @@ encts_process(krb5_context context, krb5_clpreauth_moddata moddata, - - enc_data.ciphertext = empty_data(); - -+ if (ctx->encts_disabled) { -+ TRACE_PREAUTH_ENC_TS_DISABLED(context); -+ k5_setmsg(context, KRB5_PREAUTH_FAILED, -+ _("Encrypted timestamp is disabled")); -+ return KRB5_PREAUTH_FAILED; -+ } -+ - ret = cb->get_as_key(context, rock, &as_key); - if (ret) - goto cleanup; -diff --git a/src/tests/t_referral.py b/src/tests/t_referral.py -index 98fdf2925..e12fdc2e9 100755 ---- a/src/tests/t_referral.py -+++ b/src/tests/t_referral.py -@@ -126,4 +126,17 @@ r1.klist('user@KRBTEST2.COM', 'krbtgt/KRBTEST2.COM') - r1.kinit('abc@XYZ', 'pw', ['-E']) - r1.klist('abc\@XYZ@KRBTEST2.COM', 'krbtgt/KRBTEST2.COM') - -+# Test that disable_encrypted_timestamp persists across client -+# referrals. (This test relies on SPAKE not being enabled by default -+# on the KDC.) -+r2.run([kadminl, 'modprinc', '+preauth', 'user']) -+msgs = ('Encrypted timestamp (for ') -+r1.kinit('user', password('user'), ['-C'], expected_trace=msgs) -+dconf = {'realms': {'$realm': {'disable_encrypted_timestamp': 'true'}}} -+denv = r1.special_env('disable_encts', False, krb5_conf=dconf) -+msgs = ('Ignoring encrypted timestamp because it is disabled', -+ '/Encrypted timestamp is disabled') -+r1.kinit('user', None, ['-C'], env=denv, expected_code=1, expected_trace=msgs, -+ expected_msg='Encrypted timestamp is disabled') -+ - success('KDC host referral tests') diff --git a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch b/Add-k5_buf_add_vfmt-to-k5buf-interface.patch deleted file mode 100644 index 1a333a7..0000000 --- a/Add-k5_buf_add_vfmt-to-k5buf-interface.patch +++ /dev/null @@ -1,119 +0,0 @@ -From 74e1079df0cc6e8932e487455177a69f782b863a Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 4 Jan 2018 14:35:12 -0500 -Subject: [PATCH] Add k5_buf_add_vfmt to k5buf interface - -(cherry picked from commit f05766469efc2a055085c0bcf9d40c4cdf47fe36) ---- - src/include/k5-buf.h | 8 ++++++ - src/util/support/k5buf.c | 26 +++++++++++-------- - src/util/support/libkrb5support-fixed.exports | 1 + - 3 files changed, 24 insertions(+), 11 deletions(-) - -diff --git a/src/include/k5-buf.h b/src/include/k5-buf.h -index f3207bd09..1223916a6 100644 ---- a/src/include/k5-buf.h -+++ b/src/include/k5-buf.h -@@ -76,6 +76,14 @@ void k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) - #endif - ; - -+/* Add sprintf-style formatted data to BUF, with a va_list. The value of ap is -+ * undefined after the call. */ -+void k5_buf_add_vfmt(struct k5buf *buf, const char *fmt, va_list ap) -+#if !defined(__cplusplus) && (__GNUC__ > 2) -+ __attribute__((__format__(__printf__, 2, 0))) -+#endif -+ ; -+ - /* Extend the length of buf by len and return a pointer to the reserved space, - * to be filled in by the caller. Return NULL on error. */ - void *k5_buf_get_space(struct k5buf *buf, size_t len); -diff --git a/src/util/support/k5buf.c b/src/util/support/k5buf.c -index f619f6a48..35978f238 100644 ---- a/src/util/support/k5buf.c -+++ b/src/util/support/k5buf.c -@@ -141,9 +141,9 @@ k5_buf_add_len(struct k5buf *buf, const void *data, size_t len) - } - - void --k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) -+k5_buf_add_vfmt(struct k5buf *buf, const char *fmt, va_list ap) - { -- va_list ap; -+ va_list apcopy; - int r; - size_t remaining; - char *tmp; -@@ -154,9 +154,7 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) - - if (buf->buftype == K5BUF_FIXED) { - /* Format the data directly into the fixed buffer. */ -- va_start(ap, fmt); - r = vsnprintf(endptr(buf), remaining, fmt, ap); -- va_end(ap); - if (SNPRINTF_OVERFLOW(r, remaining)) - set_error(buf); - else -@@ -166,9 +164,9 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) - - /* Optimistically format the data directly into the dynamic buffer. */ - assert(buf->buftype == K5BUF_DYNAMIC); -- va_start(ap, fmt); -- r = vsnprintf(endptr(buf), remaining, fmt, ap); -- va_end(ap); -+ va_copy(apcopy, ap); -+ r = vsnprintf(endptr(buf), remaining, fmt, apcopy); -+ va_end(apcopy); - if (!SNPRINTF_OVERFLOW(r, remaining)) { - buf->len += (unsigned int) r; - return; -@@ -179,9 +177,7 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) - if (!ensure_space(buf, r)) - return; - remaining = buf->space - buf->len; -- va_start(ap, fmt); - r = vsnprintf(endptr(buf), remaining, fmt, ap); -- va_end(ap); - if (SNPRINTF_OVERFLOW(r, remaining)) /* Shouldn't ever happen. */ - k5_buf_free(buf); - else -@@ -191,9 +187,7 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) - - /* It's a pre-C99 snprintf implementation, or something else went wrong. - * Fall back to asprintf. */ -- va_start(ap, fmt); - r = vasprintf(&tmp, fmt, ap); -- va_end(ap); - if (r < 0) { - k5_buf_free(buf); - return; -@@ -206,6 +200,16 @@ k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) - free(tmp); - } - -+void -+k5_buf_add_fmt(struct k5buf *buf, const char *fmt, ...) -+{ -+ va_list ap; -+ -+ va_start(ap, fmt); -+ k5_buf_add_vfmt(buf, fmt, ap); -+ va_end(ap); -+} -+ - void * - k5_buf_get_space(struct k5buf *buf, size_t len) - { -diff --git a/src/util/support/libkrb5support-fixed.exports b/src/util/support/libkrb5support-fixed.exports -index 30c946e7e..cb9bf0826 100644 ---- a/src/util/support/libkrb5support-fixed.exports -+++ b/src/util/support/libkrb5support-fixed.exports -@@ -6,6 +6,7 @@ k5_buf_init_dynamic - k5_buf_add - k5_buf_add_len - k5_buf_add_fmt -+k5_buf_add_vfmt - k5_buf_get_space - k5_buf_truncate - k5_buf_status diff --git a/Add-k5_dir_filenames-to-libkrb5support.patch b/Add-k5_dir_filenames-to-libkrb5support.patch deleted file mode 100644 index d420f15..0000000 --- a/Add-k5_dir_filenames-to-libkrb5support.patch +++ /dev/null @@ -1,222 +0,0 @@ -From 9010a0dbf59771cb0a9c1e6fd5a18a92a1200ca7 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 5 Jun 2018 14:01:05 -0400 -Subject: [PATCH] Add k5_dir_filenames() to libkrb5support - -Add a support function to get a list of filenames from a directory in -sorted order. - -(cherry picked from commit 27534121eb39089ff4335d8b465027e9ba783682) ---- - src/include/k5-platform.h | 7 + - src/util/support/Makefile.in | 3 + - src/util/support/dir_filenames.c | 135 ++++++++++++++++++ - src/util/support/libkrb5support-fixed.exports | 2 + - 4 files changed, 147 insertions(+) - create mode 100644 src/util/support/dir_filenames.c - -diff --git a/src/include/k5-platform.h b/src/include/k5-platform.h -index 07ef6a4ca..763408a09 100644 ---- a/src/include/k5-platform.h -+++ b/src/include/k5-platform.h -@@ -44,6 +44,8 @@ - * + constant time memory comparison - * + path manipulation - * + _, N_, dgettext, bindtextdomain (for localization) -+ * + getopt_long -+ * + fetching filenames from a directory - */ - - #ifndef K5_PLATFORM_H -@@ -1148,4 +1150,9 @@ extern int k5_getopt_long(int nargc, char **nargv, char *options, - #define getopt_long k5_getopt_long - #endif /* HAVE_GETOPT_LONG */ - -+/* Set *fnames_out to a null-terminated list of filenames within dirname, -+ * sorted according to strcmp(). Return 0 on success, or ENOENT/ENOMEM. */ -+int k5_dir_filenames(const char *dirname, char ***fnames_out); -+void k5_free_filenames(char **fnames); -+ - #endif /* K5_PLATFORM_H */ -diff --git a/src/util/support/Makefile.in b/src/util/support/Makefile.in -index caaf15822..4715e0391 100644 ---- a/src/util/support/Makefile.in -+++ b/src/util/support/Makefile.in -@@ -85,6 +85,7 @@ STLIBOBJS= \ - hex.o \ - bcmp.o \ - strerror_r.o \ -+ dir_filenames.o \ - $(GETTIMEOFDAY_ST_OBJ) \ - $(IPC_ST_OBJ) \ - $(STRLCPY_ST_OBJ) \ -@@ -111,6 +112,7 @@ LIBOBJS= \ - $(OUTPRE)hex.$(OBJEXT) \ - $(OUTPRE)bcmp.$(OBJEXT) \ - $(OUTPRE)strerror_r.$(OBJEXT) \ -+ $(OUTPRE)dir_filenames.$(OBJEXT) \ - $(GETTIMEOFDAY_OBJ) \ - $(IPC_OBJ) \ - $(STRLCPY_OBJ) \ -@@ -147,6 +149,7 @@ SRCS=\ - $(srcdir)/hex.c \ - $(srcdir)/bcmp.c \ - $(srcdir)/strerror_r.c \ -+ $(srcdir)/dir_filenames.c \ - $(srcdir)/t_utf8.c \ - $(srcdir)/t_utf16.c \ - $(srcdir)/getopt.c \ -diff --git a/src/util/support/dir_filenames.c b/src/util/support/dir_filenames.c -new file mode 100644 -index 000000000..9312b0238 ---- /dev/null -+++ b/src/util/support/dir_filenames.c -@@ -0,0 +1,135 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* util/support/dir_filenames.c - fetch filenames in a directory */ -+/* -+ * Copyright (C) 2018 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include "k5-platform.h" -+ -+void -+k5_free_filenames(char **fnames) -+{ -+ char **fn; -+ -+ for (fn = fnames; fn != NULL && *fn != NULL; fn++) -+ free(*fn); -+ free(fnames); -+} -+ -+/* Resize the filename list and add a name. */ -+static int -+add_filename(char ***fnames, int *n_fnames, const char *name) -+{ -+ char **newlist; -+ -+ newlist = realloc(*fnames, (*n_fnames + 2) * sizeof(*newlist)); -+ if (newlist == NULL) -+ return ENOMEM; -+ *fnames = newlist; -+ newlist[*n_fnames] = strdup(name); -+ if (newlist[*n_fnames] == NULL) -+ return ENOMEM; -+ (*n_fnames)++; -+ newlist[*n_fnames] = NULL; -+ return 0; -+} -+ -+static int -+compare_with_strcmp(const void *a, const void *b) -+{ -+ return strcmp(*(char **)a, *(char **)b); -+} -+ -+#ifdef _WIN32 -+ -+int -+k5_dir_filenames(const char *dirname, char ***fnames_out) -+{ -+ char *wildcard; -+ WIN32_FIND_DATA ffd; -+ HANDLE handle; -+ char **fnames = NULL; -+ int n_fnames = 0; -+ -+ *fnames_out = NULL; -+ -+ if (asprintf(&wildcard, "%s\\*", dirname) < 0) -+ return ENOMEM; -+ handle = FindFirstFile(wildcard, &ffd); -+ free(wildcard); -+ if (handle == INVALID_HANDLE_VALUE) -+ return ENOENT; -+ -+ do { -+ if (add_filename(&fnames, &n_fnames, &ffd.cFileName) != 0) { -+ k5_free_filenames(fnames); -+ FindClose(handle); -+ return ENOMEM; -+ } -+ } while (FindNextFile(handle, &ffd) != 0); -+ -+ FindClose(handle); -+ qsort(fnames, n_fnames, sizeof(*fnames), compare_with_strcmp); -+ *fnames_out = fnames; -+ return 0; -+} -+ -+#else /* _WIN32 */ -+ -+#include -+ -+int -+k5_dir_filenames(const char *dirname, char ***fnames_out) -+{ -+ DIR *dir; -+ struct dirent *ent; -+ char **fnames = NULL; -+ int n_fnames = 0; -+ -+ *fnames_out = NULL; -+ -+ dir = opendir(dirname); -+ if (dir == NULL) -+ return ENOENT; -+ -+ while ((ent = readdir(dir)) != NULL) { -+ if (add_filename(&fnames, &n_fnames, ent->d_name) != 0) { -+ k5_free_filenames(fnames); -+ closedir(dir); -+ return ENOMEM; -+ } -+ } -+ -+ closedir(dir); -+ qsort(fnames, n_fnames, sizeof(*fnames), compare_with_strcmp); -+ *fnames_out = fnames; -+ return 0; -+} -+ -+#endif /* not _WIN32 */ -diff --git a/src/util/support/libkrb5support-fixed.exports b/src/util/support/libkrb5support-fixed.exports -index a5e2ade04..16ed5a6c1 100644 ---- a/src/util/support/libkrb5support-fixed.exports -+++ b/src/util/support/libkrb5support-fixed.exports -@@ -58,6 +58,8 @@ k5_path_split - k5_strerror_r - k5_utf8_to_utf16le - k5_utf16le_to_utf8 -+k5_dir_filenames -+k5_free_filenames - krb5int_key_register - krb5int_key_delete - krb5int_getspecific diff --git a/Add-k5test-mark-function.patch b/Add-k5test-mark-function.patch deleted file mode 100644 index 0b2b9fa..0000000 --- a/Add-k5test-mark-function.patch +++ /dev/null @@ -1,60 +0,0 @@ -From 68b61c6d6402c0ad57509705137c92ae814ace27 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 18 Apr 2018 19:21:40 -0400 -Subject: [PATCH] Add k5test mark() function - -Make it easier to locate a failing command in long Python test scripts -by allowing the script to output marks, and displaying the most recent -mark with command failures. - -(cherry picked from commit 4e813204ac3dace93297f47d64dfc0aaecc370f8) ---- - src/util/k5test.py | 14 ++++++++++++++ - 1 file changed, 14 insertions(+) - -diff --git a/src/util/k5test.py b/src/util/k5test.py -index 4d30baf40..bc32877a7 100644 ---- a/src/util/k5test.py -+++ b/src/util/k5test.py -@@ -141,6 +141,11 @@ Scripts may use the following functions and variables: - added newline) in testlog, and write it to stdout if running - verbosely. - -+* mark(message): Place a divider message in the test output, to make -+ it easier to determine what part of the test script a command -+ invocation belongs to. The last mark message will also be displayed -+ if a command invocation fails. Do not include a newline in message. -+ - * which(progname): Return the location of progname in the executable - path, or None if it is not found. - -@@ -376,6 +381,8 @@ def fail(msg): - """Print a message and exit with failure.""" - global _current_pass - print "*** Failure:", msg -+ if _last_mark: -+ print "*** Last mark: %s" % _last_mark - if _last_cmd: - print "*** Last command (#%d): %s" % (_cmd_index - 1, _last_cmd) - if _last_cmd_output: -@@ -392,6 +399,12 @@ def success(msg): - _success = True - - -+def mark(msg): -+ global _last_mark -+ output('\n====== %s ======\n' % msg) -+ _last_mark = msg -+ -+ - def skipped(whatmsg, whymsg): - output('*** Skipping: %s: %s\n' % (whatmsg, whymsg), force_verbose=True) - f = open(os.path.join(buildtop, 'skiptests'), 'a') -@@ -1275,6 +1288,7 @@ atexit.register(_onexit) - signal.signal(signal.SIGINT, _onsigint) - _outfile = open('testlog', 'w') - _cmd_index = 1 -+_last_mark = None - _last_cmd = None - _last_cmd_output = None - buildtop = _find_buildtop() diff --git a/Add-libkrb5support-hex-functions-and-tests.patch b/Add-libkrb5support-hex-functions-and-tests.patch deleted file mode 100644 index d7caab2..0000000 --- a/Add-libkrb5support-hex-functions-and-tests.patch +++ /dev/null @@ -1,484 +0,0 @@ -From 507b1aff60fdadc91ca7c56d39711049aeeb1e58 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 19 Feb 2018 00:51:44 -0500 -Subject: [PATCH] Add libkrb5support hex functions and tests - -(cherry picked from commit 720dea558da0062d3cea4385327161e62cf09a5e) -[rharwood@redhat.com Remove .gitignore] ---- - src/include/k5-hex.h | 53 ++++++ - src/util/support/Makefile.in | 15 +- - src/util/support/deps | 6 + - src/util/support/hex.c | 116 ++++++++++++ - src/util/support/libkrb5support-fixed.exports | 2 + - src/util/support/t_hex.c | 169 ++++++++++++++++++ - 6 files changed, 358 insertions(+), 3 deletions(-) - create mode 100644 src/include/k5-hex.h - create mode 100644 src/util/support/hex.c - create mode 100644 src/util/support/t_hex.c - -diff --git a/src/include/k5-hex.h b/src/include/k5-hex.h -new file mode 100644 -index 000000000..75bd2cb19 ---- /dev/null -+++ b/src/include/k5-hex.h -@@ -0,0 +1,53 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* include/k5-hex.h - libkrb5support hex encoding/decoding declarations */ -+/* -+ * Copyright (C) 2018 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#ifndef K5_HEX_H -+#define K5_HEX_H -+ -+#include "k5-platform.h" -+ -+/* -+ * Encode len bytes in hex, placing the result in allocated storage in -+ * *hex_out. Use uppercase hex digits if uppercase is non-zero. Return 0 on -+ * success, ENOMEM on error. -+ */ -+int k5_hex_encode(const void *bytes, size_t len, int uppercase, -+ char **hex_out); -+ -+/* -+ * Decode hex bytes, placing the result in allocated storage in *bytes_out and -+ * *len_out. Null-terminate the result (primarily for decoding passwords in -+ * libkdb_ldap). Return 0 on success, ENOMEM or EINVAL on error. -+ */ -+int k5_hex_decode(const char *hex, uint8_t **bytes_out, size_t *len_out); -+ -+#endif /* K5_HEX_H */ -diff --git a/src/util/support/Makefile.in b/src/util/support/Makefile.in -index 58ac2e333..caaf15822 100644 ---- a/src/util/support/Makefile.in -+++ b/src/util/support/Makefile.in -@@ -82,6 +82,7 @@ STLIBOBJS= \ - path.o \ - base64.o \ - json.o \ -+ hex.o \ - bcmp.o \ - strerror_r.o \ - $(GETTIMEOFDAY_ST_OBJ) \ -@@ -107,6 +108,7 @@ LIBOBJS= \ - $(OUTPRE)path.$(OBJEXT) \ - $(OUTPRE)base64.$(OBJEXT) \ - $(OUTPRE)json.$(OBJEXT) \ -+ $(OUTPRE)hex.$(OBJEXT) \ - $(OUTPRE)bcmp.$(OBJEXT) \ - $(OUTPRE)strerror_r.$(OBJEXT) \ - $(GETTIMEOFDAY_OBJ) \ -@@ -137,10 +139,12 @@ SRCS=\ - $(srcdir)/t_unal.c \ - $(srcdir)/t_path.c \ - $(srcdir)/t_json.c \ -+ $(srcdir)/t_hex.c \ - $(srcdir)/zap.c \ - $(srcdir)/path.c \ - $(srcdir)/base64.c \ - $(srcdir)/json.c \ -+ $(srcdir)/hex.c \ - $(srcdir)/bcmp.c \ - $(srcdir)/strerror_r.c \ - $(srcdir)/t_utf8.c \ -@@ -216,6 +220,9 @@ T_JSON_OBJS= t_json.o json.o base64.o k5buf.o $(PRINTF_ST_OBJ) - t_json: $(T_JSON_OBJS) - $(CC_LINK) -o $@ $(T_JSON_OBJS) - -+t_hex: t_hex.o hex.o -+ $(CC_LINK) -o $@ t_hex.o hex.o -+ - t_unal: t_unal.o - $(CC_LINK) -o t_unal t_unal.o - -@@ -227,7 +234,8 @@ T_UTF16_OBJS= t_utf16.o utf8_conv.o utf8.o k5buf.o $(PRINTF_ST_OBJ) - t_utf16: $(T_UTF16_OBJS) - $(CC_LINK) -o $@ $(T_UTF16_OBJS) - --TEST_PROGS= t_k5buf t_path t_path_win t_base64 t_json t_unal t_utf8 t_utf16 -+TEST_PROGS= t_k5buf t_path t_path_win t_base64 t_json t_hex t_unal t_utf8 \ -+ t_utf16 - - check-unix: $(TEST_PROGS) - ./t_k5buf -@@ -235,6 +243,7 @@ check-unix: $(TEST_PROGS) - ./t_path_win - ./t_base64 - ./t_json -+ ./t_hex - ./t_unal - ./t_utf8 - ./t_utf16 -@@ -242,8 +251,8 @@ check-unix: $(TEST_PROGS) - clean: - $(RM) t_k5buf.o t_k5buf t_unal.o t_unal path_win.o path_win - $(RM) t_path_win.o t_path_win t_path.o t_path t_base64.o t_base64 -- $(RM) t_json.o t_json libkrb5support.exports t_utf8.o t_utf8 -- $(RM) t_utf16.o t_utf16 -+ $(RM) t_json.o t_json t_hex.o t_hex libkrb5support.exports -+ $(RM) t_utf8.o t_utf8 t_utf16.o t_utf16 - - @lib_frag@ - @libobj_frag@ -diff --git a/src/util/support/deps b/src/util/support/deps -index 34d8a884b..80e9a1c58 100644 ---- a/src/util/support/deps -+++ b/src/util/support/deps -@@ -63,6 +63,9 @@ t_path.so t_path.po $(OUTPRE)t_path.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - t_path.c - t_json.so t_json.po $(OUTPRE)t_json.$(OBJEXT): $(top_srcdir)/include/k5-json.h \ - t_json.c -+t_hex.so t_hex.po $(OUTPRE)t_hex.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-platform.h \ -+ $(top_srcdir)/include/k5-thread.h t_hex.c - zap.so zap.po $(OUTPRE)zap.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-thread.h \ - zap.c -@@ -76,6 +79,9 @@ json.so json.po $(OUTPRE)json.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(top_srcdir)/include/k5-base64.h $(top_srcdir)/include/k5-buf.h \ - $(top_srcdir)/include/k5-json.h $(top_srcdir)/include/k5-platform.h \ - $(top_srcdir)/include/k5-thread.h json.c -+hex.so hex.po $(OUTPRE)hex.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-platform.h \ -+ $(top_srcdir)/include/k5-thread.h hex.c - bcmp.so bcmp.po $(OUTPRE)bcmp.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-thread.h \ - bcmp.c -diff --git a/src/util/support/hex.c b/src/util/support/hex.c -new file mode 100644 -index 000000000..4407ff9ff ---- /dev/null -+++ b/src/util/support/hex.c -@@ -0,0 +1,116 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* util/support/hex.c - hex encoding/decoding implementation */ -+/* -+ * Copyright (C) 2018 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include -+#include -+#include -+ -+static inline char -+hex_digit(uint8_t bval, int uppercase) -+{ -+ assert(bval >= 0 && bval <= 0xF); -+ if (bval < 10) -+ return '0' + bval; -+ else if (uppercase) -+ return 'A' + (bval - 10); -+ else -+ return 'a' + (bval - 10); -+} -+ -+int -+k5_hex_encode(const void *bytes, size_t len, int uppercase, char **hex_out) -+{ -+ size_t i; -+ const uint8_t *p = bytes; -+ char *hex; -+ -+ *hex_out = NULL; -+ -+ hex = malloc(len * 2 + 1); -+ if (hex == NULL) -+ return ENOMEM; -+ -+ for (i = 0; i < len; i++) { -+ hex[i * 2] = hex_digit(p[i] >> 4, uppercase); -+ hex[i * 2 + 1] = hex_digit(p[i] & 0xF, uppercase); -+ } -+ hex[len * 2] = '\0'; -+ -+ *hex_out = hex; -+ return 0; -+} -+ -+/* Decode a hex digit. Return 0-15 on success, -1 on invalid input. */ -+static inline int -+decode_hexchar(unsigned char c) -+{ -+ if (isdigit(c)) -+ return c - '0'; -+ if (c >= 'A' && c <= 'F') -+ return c - 'A' + 10; -+ if (c >= 'a' && c <= 'f') -+ return c - 'a' + 10; -+ return -1; -+} -+ -+int -+k5_hex_decode(const char *hex, uint8_t **bytes_out, size_t *len_out) -+{ -+ size_t hexlen, i; -+ int h1, h2; -+ uint8_t *bytes; -+ -+ *bytes_out = NULL; -+ *len_out = 0; -+ -+ hexlen = strlen(hex); -+ if (hexlen % 2 != 0) -+ return EINVAL; -+ bytes = malloc(hexlen / 2 + 1); -+ if (bytes == NULL) -+ return ENOMEM; -+ -+ for (i = 0; i < hexlen / 2; i++) { -+ h1 = decode_hexchar(hex[i * 2]); -+ h2 = decode_hexchar(hex[i * 2 + 1]); -+ if (h1 == -1 || h2 == -1) { -+ free(bytes); -+ return EINVAL; -+ } -+ bytes[i] = h1 * 16 + h2; -+ } -+ bytes[i] = 0; -+ -+ *bytes_out = bytes; -+ *len_out = hexlen / 2; -+ return 0; -+} -diff --git a/src/util/support/libkrb5support-fixed.exports b/src/util/support/libkrb5support-fixed.exports -index fd74a1897..30c946e7e 100644 ---- a/src/util/support/libkrb5support-fixed.exports -+++ b/src/util/support/libkrb5support-fixed.exports -@@ -16,6 +16,8 @@ k5_get_error - k5_free_error - k5_clear_error - k5_set_error_info_callout_fn -+k5_hex_decode -+k5_hex_encode - k5_json_array_add - k5_json_array_create - k5_json_array_fmt -diff --git a/src/util/support/t_hex.c b/src/util/support/t_hex.c -new file mode 100644 -index 000000000..a586a1bc8 ---- /dev/null -+++ b/src/util/support/t_hex.c -@@ -0,0 +1,169 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* util/support/t_hex.c - Test hex encoding and decoding */ -+/* -+ * Copyright (C) 2018 by the Massachusetts Institute of Technology. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include -+#include -+ -+struct { -+ const char *hex; -+ const char *binary; -+ size_t binary_len; -+ int uppercase; -+} tests[] = { -+ /* Invalid hex strings */ -+ { "1" }, -+ { "123" }, -+ { "0/" }, -+ { "/0" }, -+ { "0:" }, -+ { ":0" }, -+ { "0@" }, -+ { "@0" }, -+ { "0G" }, -+ { "G0" }, -+ { "0`" }, -+ { "`0" }, -+ { "0g" }, -+ { "g0" }, -+ { " 00 " }, -+ { "0\x01" }, -+ -+ { "", "", 0 }, -+ { "00", "\x00", 1 }, -+ { "01", "\x01", 1 }, -+ { "10", "\x10", 1 }, -+ { "01ff", "\x01\xFF", 2 }, -+ { "A0B0C0", "\xA0\xB0\xC0", 3, 1 }, -+ { "1a2b3c4d5e6f", "\x1A\x2B\x3C\x4D\x5E\x6F", 6 }, -+ { "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff", -+ "\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF" -+ "\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF\xFF", 32 }, -+ -+ /* All byte values, lowercase */ -+ { "0001020304050607", "\x00\x01\x02\x03\x04\x05\x06\x07", 8 }, -+ { "08090a0b0c0d0e0f", "\x08\x09\x0A\x0B\x0C\x0D\x0E\x0F", 8 }, -+ { "1011121314151617", "\x10\x11\x12\x13\x14\x15\x16\x17", 8 }, -+ { "18191a1b1c1d1e1f", "\x18\x19\x1A\x1B\x1C\x1D\x1E\x1F", 8 }, -+ { "2021222324252627", "\x20\x21\x22\x23\x24\x25\x26\x27", 8 }, -+ { "28292a2b2c2d2e2f", "\x28\x29\x2A\x2B\x2C\x2D\x2E\x2F", 8 }, -+ { "3031323334353637", "\x30\x31\x32\x33\x34\x35\x36\x37", 8 }, -+ { "38393a3b3c3d3e3f", "\x38\x39\x3A\x3B\x3C\x3D\x3E\x3F", 8 }, -+ { "4041424344454647", "\x40\x41\x42\x43\x44\x45\x46\x47", 8 }, -+ { "48494a4b4c4d4e4f", "\x48\x49\x4A\x4B\x4C\x4D\x4E\x4F", 8 }, -+ { "5051525354555657", "\x50\x51\x52\x53\x54\x55\x56\x57", 8 }, -+ { "58595a5b5c5d5e5f", "\x58\x59\x5A\x5B\x5C\x5D\x5E\x5F", 8 }, -+ { "6061626364656667", "\x60\x61\x62\x63\x64\x65\x66\x67", 8 }, -+ { "68696a6b6c6d6e6f", "\x68\x69\x6A\x6B\x6C\x6D\x6E\x6F", 8 }, -+ { "7071727374757677", "\x70\x71\x72\x73\x74\x75\x76\x77", 8 }, -+ { "78797a7b7c7d7e7f", "\x78\x79\x7A\x7B\x7C\x7D\x7E\x7F", 8 }, -+ { "8081828384858687", "\x80\x81\x82\x83\x84\x85\x86\x87", 8 }, -+ { "88898a8b8c8d8e8f", "\x88\x89\x8A\x8B\x8C\x8D\x8E\x8F", 8 }, -+ { "9091929394959697", "\x90\x91\x92\x93\x94\x95\x96\x97", 8 }, -+ { "98999a9b9c9d9e9f", "\x98\x99\x9A\x9B\x9C\x9D\x9E\x9F", 8 }, -+ { "a0a1a2a3a4a5a6a7", "\xA0\xA1\xA2\xA3\xA4\xA5\xA6\xA7", 8 }, -+ { "a8a9aaabacadaeaf", "\xA8\xA9\xAA\xAB\xAC\xAD\xAE\xAF", 8 }, -+ { "b0b1b2b3b4b5b6b7", "\xB0\xB1\xB2\xB3\xB4\xB5\xB6\xB7", 8 }, -+ { "b8b9babbbcbdbebf", "\xB8\xB9\xBA\xBB\xBC\xBD\xBE\xBF", 8 }, -+ { "c0c1c2c3c4c5c6c7", "\xC0\xC1\xC2\xC3\xC4\xC5\xC6\xC7", 8 }, -+ { "c8c9cacbcccdcecf", "\xC8\xC9\xCA\xCB\xCC\xCD\xCE\xCF", 8 }, -+ { "d0d1d2d3d4d5d6d7", "\xD0\xD1\xD2\xD3\xD4\xD5\xD6\xD7", 8 }, -+ { "d8d9dadbdcdddedf", "\xD8\xD9\xDA\xDB\xDC\xDD\xDE\xDF", 8 }, -+ { "e0e1e2e3e4e5e6e7", "\xE0\xE1\xE2\xE3\xE4\xE5\xE6\xE7", 8 }, -+ { "e8e9eaebecedeeef", "\xE8\xE9\xEA\xEB\xEC\xED\xEE\xEF", 8 }, -+ { "f0f1f2f3f4f5f6f7", "\xF0\xF1\xF2\xF3\xF4\xF5\xF6\xF7", 8 }, -+ { "f8f9fafbfcfdfeff", "\xF8\xF9\xFA\xFB\xFC\xFD\xFE\xFF", 8 }, -+ -+ /* All byte values, uppercase */ -+ { "0001020304050607", "\x00\x01\x02\x03\x04\x05\x06\x07", 8, 1 }, -+ { "08090A0B0C0D0E0F", "\x08\x09\x0A\x0B\x0C\x0D\x0E\x0F", 8, 1 }, -+ { "1011121314151617", "\x10\x11\x12\x13\x14\x15\x16\x17", 8, 1 }, -+ { "18191A1B1C1D1E1F", "\x18\x19\x1A\x1B\x1C\x1D\x1E\x1F", 8, 1 }, -+ { "2021222324252627", "\x20\x21\x22\x23\x24\x25\x26\x27", 8, 1 }, -+ { "28292A2B2C2D2E2F", "\x28\x29\x2A\x2B\x2C\x2D\x2E\x2F", 8, 1 }, -+ { "3031323334353637", "\x30\x31\x32\x33\x34\x35\x36\x37", 8, 1 }, -+ { "38393A3B3C3D3E3F", "\x38\x39\x3A\x3B\x3C\x3D\x3E\x3F", 8, 1 }, -+ { "4041424344454647", "\x40\x41\x42\x43\x44\x45\x46\x47", 8, 1 }, -+ { "48494A4B4C4D4E4F", "\x48\x49\x4A\x4B\x4C\x4D\x4E\x4F", 8, 1 }, -+ { "5051525354555657", "\x50\x51\x52\x53\x54\x55\x56\x57", 8, 1 }, -+ { "58595A5B5C5D5E5F", "\x58\x59\x5A\x5B\x5C\x5D\x5E\x5F", 8, 1 }, -+ { "6061626364656667", "\x60\x61\x62\x63\x64\x65\x66\x67", 8, 1 }, -+ { "68696A6B6C6D6E6F", "\x68\x69\x6A\x6B\x6C\x6D\x6E\x6F", 8, 1 }, -+ { "7071727374757677", "\x70\x71\x72\x73\x74\x75\x76\x77", 8, 1 }, -+ { "78797A7B7C7D7E7F", "\x78\x79\x7A\x7B\x7C\x7D\x7E\x7F", 8, 1 }, -+ { "8081828384858687", "\x80\x81\x82\x83\x84\x85\x86\x87", 8, 1 }, -+ { "88898A8B8C8D8E8F", "\x88\x89\x8A\x8B\x8C\x8D\x8E\x8F", 8, 1 }, -+ { "9091929394959697", "\x90\x91\x92\x93\x94\x95\x96\x97", 8, 1 }, -+ { "98999A9B9C9D9E9F", "\x98\x99\x9A\x9B\x9C\x9D\x9E\x9F", 8, 1 }, -+ { "A0A1A2A3A4A5A6A7", "\xA0\xA1\xA2\xA3\xA4\xA5\xA6\xA7", 8, 1 }, -+ { "A8A9AAABACADAEAF", "\xA8\xA9\xAA\xAB\xAC\xAD\xAE\xAF", 8, 1 }, -+ { "B0B1B2B3B4B5B6B7", "\xB0\xB1\xB2\xB3\xB4\xB5\xB6\xB7", 8, 1 }, -+ { "B8B9BABBBCBDBEBF", "\xB8\xB9\xBA\xBB\xBC\xBD\xBE\xBF", 8, 1 }, -+ { "C0C1C2C3C4C5C6C7", "\xC0\xC1\xC2\xC3\xC4\xC5\xC6\xC7", 8, 1 }, -+ { "C8C9CACBCCCDCECF", "\xC8\xC9\xCA\xCB\xCC\xCD\xCE\xCF", 8, 1 }, -+ { "D0D1D2D3D4D5D6D7", "\xD0\xD1\xD2\xD3\xD4\xD5\xD6\xD7", 8, 1 }, -+ { "D8D9DADBDCDDDEDF", "\xD8\xD9\xDA\xDB\xDC\xDD\xDE\xDF", 8, 1 }, -+ { "E0E1E2E3E4E5E6E7", "\xE0\xE1\xE2\xE3\xE4\xE5\xE6\xE7", 8, 1 }, -+ { "E8E9EAEBECEDEEEF", "\xE8\xE9\xEA\xEB\xEC\xED\xEE\xEF", 8, 1 }, -+ { "F0F1F2F3F4F5F6F7", "\xF0\xF1\xF2\xF3\xF4\xF5\xF6\xF7", 8, 1 }, -+ { "F8F9FAFBFCFDFEFF", "\xF8\xF9\xFA\xFB\xFC\xFD\xFE\xFF", 8, 1 }, -+}; -+ -+int main() -+{ -+ size_t i; -+ char *hex; -+ int ret; -+ uint8_t *bytes; -+ size_t len; -+ -+ for (i = 0; i < sizeof(tests) / sizeof(*tests); i++) { -+ if (tests[i].binary == NULL) { -+ ret = k5_hex_decode(tests[i].hex, &bytes, &len); -+ assert(ret == EINVAL && bytes == NULL && len == 0); -+ continue; -+ } -+ -+ ret = k5_hex_decode(tests[i].hex, &bytes, &len); -+ assert(ret == 0); -+ assert(len == tests[i].binary_len); -+ assert(memcmp(bytes, tests[i].binary, len) == 0); -+ assert(bytes[len] == 0); -+ free(bytes); -+ -+ ret = k5_hex_encode((uint8_t *)tests[i].binary, tests[i].binary_len, -+ tests[i].uppercase, &hex); -+ assert(ret == 0); -+ assert(strcmp(tests[i].hex, hex) == 0); -+ free(hex); -+ } -+ return 0; -+} diff --git a/Add-vector-support-to-k5_sha256.patch b/Add-vector-support-to-k5_sha256.patch deleted file mode 100644 index f9a3233..0000000 --- a/Add-vector-support-to-k5_sha256.patch +++ /dev/null @@ -1,106 +0,0 @@ -From f8b14b92cc4c82578f8fc56dd1fddebe88120769 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 3 Feb 2018 20:53:42 -0500 -Subject: [PATCH] Add vector support to k5_sha256() - -Add a length argument so that multiple krb5_data values can be passed -to k5_sha256(), for efficient computation of SHA-256 hashes over -concatenations of data values. - -(cherry picked from commit 4f3373e8c55b3e9bdfb5b065e07214c5816c85fa) ---- - src/include/k5-int.h | 4 ++-- - src/lib/crypto/builtin/sha2/sha256.c | 6 ++++-- - src/lib/crypto/crypto_tests/t_sha2.c | 2 +- - src/lib/crypto/openssl/sha256.c | 6 ++++-- - src/lib/krb5/rcache/rc_conv.c | 2 +- - 5 files changed, 12 insertions(+), 8 deletions(-) - -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 9378ae047..1c1d9783b 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -635,9 +635,9 @@ krb5int_arcfour_gsscrypt(const krb5_keyblock *keyblock, krb5_keyusage usage, - - #define K5_SHA256_HASHLEN (256 / 8) - --/* Write the SHA-256 hash of in to out. */ -+/* Write the SHA-256 hash of in (containing n elements) to out. */ - krb5_error_code --k5_sha256(const krb5_data *in, uint8_t out[K5_SHA256_HASHLEN]); -+k5_sha256(const krb5_data *in, size_t n, uint8_t out[K5_SHA256_HASHLEN]); - - /* - * Attempt to zero memory in a way that compilers won't optimize out. -diff --git a/src/lib/crypto/builtin/sha2/sha256.c b/src/lib/crypto/builtin/sha2/sha256.c -index 2b5cbe480..9a940b3f8 100644 ---- a/src/lib/crypto/builtin/sha2/sha256.c -+++ b/src/lib/crypto/builtin/sha2/sha256.c -@@ -257,12 +257,14 @@ k5_sha256_final(void *res, SHA256_CTX *m) - } - - krb5_error_code --k5_sha256(const krb5_data *in, uint8_t out[K5_SHA256_HASHLEN]) -+k5_sha256(const krb5_data *in, size_t n, uint8_t out[K5_SHA256_HASHLEN]) - { - SHA256_CTX ctx; -+ size_t i; - - k5_sha256_init(&ctx); -- k5_sha256_update(&ctx, in->data, in->length); -+ for (i = 0; i < n; i++) -+ k5_sha256_update(&ctx, in[i].data, in[i].length); - k5_sha256_final(out, &ctx); - return 0; - } -diff --git a/src/lib/crypto/crypto_tests/t_sha2.c b/src/lib/crypto/crypto_tests/t_sha2.c -index 12f32869b..e6fa58498 100644 ---- a/src/lib/crypto/crypto_tests/t_sha2.c -+++ b/src/lib/crypto/crypto_tests/t_sha2.c -@@ -125,7 +125,7 @@ hash_test(const struct krb5_hash_provider *hash, struct test *tests) - - if (hash == &krb5int_hash_sha256) { - /* Try again using k5_sha256(). */ -- if (k5_sha256(&iov.data, (uint8_t *)hval.data) != 0) -+ if (k5_sha256(&iov.data, 1, (uint8_t *)hval.data) != 0) - abort(); - if (memcmp(hval.data, t->hash, hval.length) != 0) - abort(); -diff --git a/src/lib/crypto/openssl/sha256.c b/src/lib/crypto/openssl/sha256.c -index fa095d472..0edd8b7ba 100644 ---- a/src/lib/crypto/openssl/sha256.c -+++ b/src/lib/crypto/openssl/sha256.c -@@ -34,16 +34,18 @@ - #include - - krb5_error_code --k5_sha256(const krb5_data *in, uint8_t out[K5_SHA256_HASHLEN]) -+k5_sha256(const krb5_data *in, size_t n, uint8_t out[K5_SHA256_HASHLEN]) - { - EVP_MD_CTX *ctx; -+ size_t i; - int ok; - - ctx = EVP_MD_CTX_new(); - if (ctx == NULL) - return ENOMEM; - ok = EVP_DigestInit_ex(ctx, EVP_sha256(), NULL); -- ok = ok && EVP_DigestUpdate(ctx, in->data, in->length); -+ for (i = 0; i < n; i++) -+ ok = ok && EVP_DigestUpdate(ctx, in[i].data, in[i].length); - ok = ok && EVP_DigestFinal_ex(ctx, out, NULL); - EVP_MD_CTX_free(ctx); - return ok ? 0 : ENOMEM; -diff --git a/src/lib/krb5/rcache/rc_conv.c b/src/lib/krb5/rcache/rc_conv.c -index 0e021f5d8..f2fe528ac 100644 ---- a/src/lib/krb5/rcache/rc_conv.c -+++ b/src/lib/krb5/rcache/rc_conv.c -@@ -58,7 +58,7 @@ krb5_rc_hash_message(krb5_context context, const krb5_data *message, - *out = NULL; - - /* Calculate the binary checksum. */ -- retval = k5_sha256(message, cksum); -+ retval = k5_sha256(message, 1, cksum); - if (retval) - return retval; - diff --git a/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch b/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch deleted file mode 100644 index 692f4ad..0000000 --- a/Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch +++ /dev/null @@ -1,229 +0,0 @@ -From 2b9e79d58b28196dba5f7d3ff2f32ca577444ddc Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 31 Mar 2018 10:43:49 -0400 -Subject: [PATCH] Be more careful asking for AS key in SPAKE client - -Asking for the AS key too early can result in password prompts in -situations where SPAKE won't proceed, such as when the KDC offers only -second factor types not supported by the client. - -In spake_prep_questions(), decode the received message and make sure -it's a challenge with a supported group and second factor type -(SF-NONE at the moment). Save the decoded message and use it in -spake_process(). Do not retrieve the AS key at the beginning of -spake_process(); instead do so in process_challenge() after checking -the challenge group and factor types. - -Move contains_sf_none() earlier in the file so that it can be used by -spake_prep_questions() without a prototype. - -ticket: 8659 -(cherry picked from commit f240f1b0d324312be8aa59ead7cfbe0c329ed064) ---- - src/plugins/preauth/spake/spake_client.c | 111 ++++++++++++++--------- - 1 file changed, 66 insertions(+), 45 deletions(-) - -diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c -index d72bd64aa..47a6ba26c 100644 ---- a/src/plugins/preauth/spake/spake_client.c -+++ b/src/plugins/preauth/spake/spake_client.c -@@ -39,12 +39,26 @@ - #include - - typedef struct reqstate_st { -+ krb5_pa_spake *msg; /* set in prep_questions, used in process */ - krb5_keyblock *initial_key; - krb5_data *support; - krb5_data thash; - krb5_data spakeresult; - } reqstate; - -+/* Return true if SF-NONE is present in factors. */ -+static krb5_boolean -+contains_sf_none(krb5_spake_factor **factors) -+{ -+ int i; -+ -+ for (i = 0; factors != NULL && factors[i] != NULL; i++) { -+ if (factors[i]->type == SPAKE_SF_NONE) -+ return TRUE; -+ } -+ return FALSE; -+} -+ - static krb5_error_code - spake_init(krb5_context context, krb5_clpreauth_moddata *moddata_out) - { -@@ -77,6 +91,7 @@ spake_request_fini(krb5_context context, krb5_clpreauth_moddata moddata, - { - reqstate *st = (reqstate *)modreq; - -+ k5_free_pa_spake(context, st->msg); - krb5_free_keyblock(context, st->initial_key); - krb5_free_data(context, st->support); - krb5_free_data_contents(context, &st->thash); -@@ -92,16 +107,42 @@ spake_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata, - krb5_data *enc_req, krb5_data *enc_prev_req, - krb5_pa_data *pa_data) - { -+ krb5_error_code ret; -+ groupstate *gstate = (groupstate *)moddata; - reqstate *st = (reqstate *)modreq; -+ krb5_data in_data; -+ krb5_spake_challenge *ch; - - if (st == NULL) - return ENOMEM; -- if (st->initial_key == NULL && pa_data->length > 0) -+ -+ /* We don't need to ask any questions to send a support message. */ -+ if (pa_data->length == 0) -+ return 0; -+ -+ /* Decode the incoming message, replacing any previous one in the request -+ * state. If we can't decode it, we have no questions to ask. */ -+ k5_free_pa_spake(context, st->msg); -+ st->msg = NULL; -+ in_data = make_data(pa_data->contents, pa_data->length); -+ ret = decode_krb5_pa_spake(&in_data, &st->msg); -+ if (ret) -+ return (ret == ENOMEM) ? ENOMEM : 0; -+ -+ if (st->msg->choice == SPAKE_MSGTYPE_CHALLENGE) { -+ ch = &st->msg->u.challenge; -+ if (!group_is_permitted(gstate, ch->group)) -+ return 0; -+ /* When second factor support is implemented, we should ask questions -+ * based on the factors in the challenge. */ -+ if (!contains_sf_none(ch->factors)) -+ return 0; -+ /* We will need the AS key to respond to the challenge. */ - cb->need_as_key(context, rock); -- -- /* When second-factor is implemented, we should ask questions based on the -- * factors in the challenge. */ -- -+ } else if (st->msg->choice == SPAKE_MSGTYPE_ENCDATA) { -+ /* When second factor support is implemented, we should decrypt the -+ * encdata message and ask questions based on the factor data. */ -+ } - return 0; - } - -@@ -136,19 +177,6 @@ send_support(krb5_context context, groupstate *gstate, reqstate *st, - return convert_to_padata(support, pa_out); - } - --/* Return true if SF-NONE is present in factors. */ --static krb5_boolean --contains_sf_none(krb5_spake_factor **factors) --{ -- int i; -- -- for (i = 0; factors != NULL && factors[i] != NULL; i++) { -- if (factors[i]->type == SPAKE_SF_NONE) -- return TRUE; -- } -- return FALSE; --} -- - static krb5_error_code - process_challenge(krb5_context context, groupstate *gstate, reqstate *st, - krb5_spake_challenge *ch, const krb5_data *der_msg, -@@ -157,7 +185,7 @@ process_challenge(krb5_context context, groupstate *gstate, reqstate *st, - const krb5_data *der_req, krb5_pa_data ***pa_out) - { - krb5_error_code ret; -- krb5_keyblock *k0 = NULL, *k1 = NULL; -+ krb5_keyblock *k0 = NULL, *k1 = NULL, *as_key; - krb5_spake_factor factor; - krb5_pa_spake msg; - krb5_data *der_factor = NULL, *response; -@@ -167,8 +195,8 @@ process_challenge(krb5_context context, groupstate *gstate, reqstate *st, - - enc_factor.ciphertext = empty_data(); - -- /* Not expected if we already computed the SPAKE result. */ -- if (st->spakeresult.length != 0) -+ /* Not expected if we processed a challenge and didn't reject it. */ -+ if (st->initial_key != NULL) - return KRB5KDC_ERR_PREAUTH_FAILED; - - if (!group_is_permitted(gstate, ch->group)) { -@@ -193,6 +221,12 @@ process_challenge(krb5_context context, groupstate *gstate, reqstate *st, - if (!contains_sf_none(ch->factors)) - return KRB5KDC_ERR_PREAUTH_FAILED; - -+ ret = cb->get_as_key(context, rock, &as_key); -+ if (ret) -+ goto cleanup; -+ ret = krb5_copy_keyblock(context, as_key, &st->initial_key); -+ if (ret) -+ goto cleanup; - ret = derive_wbytes(context, ch->group, st->initial_key, &wbytes); - if (ret) - goto cleanup; -@@ -267,7 +301,7 @@ process_encdata(krb5_context context, reqstate *st, krb5_enc_data *enc, - krb5_pa_data ***pa_out) - { - /* Not expected if we haven't sent a response yet. */ -- if (st->spakeresult.length == 0) -+ if (st->initial_key == NULL || st->spakeresult.length == 0) - return KRB5KDC_ERR_PREAUTH_FAILED; - - /* -@@ -292,9 +326,7 @@ spake_process(krb5_context context, krb5_clpreauth_moddata moddata, - krb5_error_code ret; - groupstate *gstate = (groupstate *)moddata; - reqstate *st = (reqstate *)modreq; -- krb5_pa_spake *msg; - krb5_data in_data; -- krb5_keyblock *as_key; - - if (st == NULL) - return ENOMEM; -@@ -306,34 +338,23 @@ spake_process(krb5_context context, krb5_clpreauth_moddata moddata, - return send_support(context, gstate, st, pa_out); - } - -- /* We need the initial reply key to process any non-trivial message. */ -- if (st->initial_key == NULL) { -- ret = cb->get_as_key(context, rock, &as_key); -- if (ret) -- return ret; -- ret = krb5_copy_keyblock(context, as_key, &st->initial_key); -- if (ret) -- return ret; -- } -- -- in_data = make_data(pa_in->contents, pa_in->length); -- ret = decode_krb5_pa_spake(&in_data, &msg); -- if (ret) -- return ret; -- -- if (msg->choice == SPAKE_MSGTYPE_CHALLENGE) { -- ret = process_challenge(context, gstate, st, &msg->u.challenge, -+ if (st->msg == NULL) { -+ /* The message failed to decode in spake_prep_questions(). */ -+ ret = KRB5KDC_ERR_PREAUTH_FAILED; -+ } else if (st->msg->choice == SPAKE_MSGTYPE_CHALLENGE) { -+ in_data = make_data(pa_in->contents, pa_in->length); -+ ret = process_challenge(context, gstate, st, &st->msg->u.challenge, - &in_data, cb, rock, prompter, prompter_data, - der_req, pa_out); -- } else if (msg->choice == SPAKE_MSGTYPE_ENCDATA) { -- ret = process_encdata(context, st, &msg->u.encdata, cb, rock, prompter, -- prompter_data, der_prev_req, der_req, pa_out); -+ } else if (st->msg->choice == SPAKE_MSGTYPE_ENCDATA) { -+ ret = process_encdata(context, st, &st->msg->u.encdata, cb, rock, -+ prompter, prompter_data, der_prev_req, der_req, -+ pa_out); - } else { - /* Unexpected message type */ - ret = KRB5KDC_ERR_PREAUTH_FAILED; - } - -- k5_free_pa_spake(context, msg); - return ret; - } - diff --git a/Bring-back-general-kerberos-man-page.patch b/Bring-back-general-kerberos-man-page.patch deleted file mode 100644 index 65a9966..0000000 --- a/Bring-back-general-kerberos-man-page.patch +++ /dev/null @@ -1,468 +0,0 @@ -From 67653084e8770fe4af4e06848452e83dc37b7ade Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 9 Oct 2018 17:05:10 -0400 -Subject: [PATCH] Bring back general kerberos man page - -Restore the content of kerberos(1) as it stood in -0f81e372a2830c9170f6e08dfa956841d0ebdfb1. Convert to ReST to match -the other man pages, and install it as the more appropriate -kerberos(7). - -Build kerberos(7) and check it in to avoid breaking the build. - -ticket: 8755 (new) -tags: pullup -target_version: 1.16-next - -(cherry picked from commit c38197ee9808503f86ccffd4a2bd94389e17df0b) ---- - doc/conf.py | 1 + - doc/user/user_config/index.rst | 1 + - doc/user/user_config/kerberos.rst | 148 ++++++++++++++++++++++++ - src/Makefile.in | 4 +- - src/config/pre.in | 2 + - src/man/Makefile.in | 14 ++- - src/man/kerberos.man | 180 ++++++++++++++++++++++++++++++ - 7 files changed, 345 insertions(+), 5 deletions(-) - create mode 100644 doc/user/user_config/kerberos.rst - create mode 100644 src/man/kerberos.man - -diff --git a/doc/conf.py b/doc/conf.py -index 0555808e6..f8bf588b6 100644 ---- a/doc/conf.py -+++ b/doc/conf.py -@@ -292,6 +292,7 @@ man_pages = [ - ('user/user_commands/krb5-config', 'krb5-config', u'tool for linking against MIT Kerberos libraries', [u'MIT'], 1), - ('user/user_config/k5login', 'k5login', u'Kerberos V5 acl file for host access', [u'MIT'], 5), - ('user/user_config/k5identity', 'k5identity', u'Kerberos V5 client principal selection rules', [u'MIT'], 5), -+ ('user/user_config/kerberos', 'kerberos', u'Overview of using Kerberos', [u'MIT'], 7), - ('admin/admin_commands/krb5kdc', 'krb5kdc', u'Kerberos V5 KDC', [u'MIT'], 8), - ('admin/admin_commands/kadmin_local', 'kadmin', u'Kerberos V5 database administration program', [u'MIT'], 1), - ('admin/admin_commands/kprop', 'kprop', u'propagate a Kerberos V5 principal database to a slave server', [u'MIT'], 8), -diff --git a/doc/user/user_config/index.rst b/doc/user/user_config/index.rst -index 6b3d4393b..ad0dc1a72 100644 ---- a/doc/user/user_config/index.rst -+++ b/doc/user/user_config/index.rst -@@ -8,5 +8,6 @@ been disabled by your host's configuration): - .. toctree:: - :maxdepth: 1 - -+ kerberos.rst - k5login.rst - k5identity.rst -diff --git a/doc/user/user_config/kerberos.rst b/doc/user/user_config/kerberos.rst -new file mode 100644 -index 000000000..6c4453b3b ---- /dev/null -+++ b/doc/user/user_config/kerberos.rst -@@ -0,0 +1,148 @@ -+.. _kerberos(7): -+ -+kerberos -+======== -+ -+DESCRIPTION -+----------- -+ -+The Kerberos system authenticates individual users in a network -+environment. After authenticating yourself to Kerberos, you can use -+Kerberos-enabled programs without having to present passwords. -+ -+If you enter your username and :ref:`kinit(1)` responds with this -+message: -+ -+kinit(v5): Client not found in Kerberos database while getting initial -+credentials -+ -+you haven't been registered as a Kerberos user. See your system -+administrator. -+ -+A Kerberos name usually contains three parts. The first is the -+**primary**, which is usually a user's or service's name. The second -+is the **instance**, which in the case of a user is usually null. -+Some users may have privileged instances, however, such as ``root`` or -+``admin``. In the case of a service, the instance is the fully -+qualified name of the machine on which it runs; i.e. there can be an -+rlogin service running on the machine ABC, which is different from the -+rlogin service running on the machine XYZ. The third part of a -+Kerberos name is the **realm**. The realm corresponds to the Kerberos -+service providing authentication for the principal. -+ -+When writing a Kerberos name, the principal name is separated from the -+instance (if not null) by a slash, and the realm (if not the local -+realm) follows, preceded by an "@" sign. The following are examples -+of valid Kerberos names:: -+ -+ david -+ jennifer/admin -+ joeuser@BLEEP.COM -+ cbrown/root@FUBAR.ORG -+ -+When you authenticate yourself with Kerberos you get an initial -+Kerberos **ticket**. (A Kerberos ticket is an encrypted protocol -+message that provides authentication.) Kerberos uses this ticket for -+network utilities such as rlogin and rcp. The ticket transactions are -+done transparently, so you don't have to worry about their management. -+ -+Note, however, that tickets expire. Privileged tickets, such as those -+with the instance ``root``, expire in a few minutes, while tickets -+that carry more ordinary privileges may be good for several hours or a -+day, depending on the installation's policy. If your login session -+extends beyond the time limit, you will have to re-authenticate -+yourself to Kerberos to get new tickets. Use the :ref:`kinit(1)` -+command to re-authenticate yourself. -+ -+If you use the kinit command to get your tickets, make sure you use -+the kdestroy command to destroy your tickets before you end your login -+session. You should put the kdestroy command in your ``.logout`` file -+so that your tickets will be destroyed automatically when you logout. -+For more information about the kinit and kdestroy commands, see the -+:ref:`kinit(1)` and :ref:`kdestroy(1)` manual pages. -+ -+Kerberos tickets can be forwarded. In order to forward tickets, you -+must request **forwardable** tickets when you kinit. Once you have -+forwardable tickets, most Kerberos programs have a command line option -+to forward them to the remote host. -+ -+ENVIRONMENT VARIABLES -+--------------------- -+ -+Several environment variables affect the operation of Kerberos-enabled -+programs. These inclide: -+ -+**KRB5CCNAME** -+ Specifies the location of the credential cache, in the form -+ *TYPE*:*residual*. If no *type* prefix is present, the **FILE** -+ type is assumed and *residual* is the pathname of the cache file. -+ A collection of multiple caches may be used by specifying the -+ **dir** type and the pathname of a private directory (which must -+ already exist). The default cache file is /tmp/krb5cc_*uid*, -+ where *uid* is the decimal user ID of the user. -+ -+**KRB5_KTNAME** -+ Specifies the location of the keytab file, in the form -+ *TYPE*:*residual*. If no *type* is present, the **FILE** type is -+ assumed and *residual* is the pathname of the keytab file. The -+ default keytab file is ``/etc/krb5.keytab``. -+ -+**KRB5_CONFIG** -+ Specifies the location of the Kerberos configuration file. The -+ default is ``/etc/krb5.conf``. -+ -+**KRB5_KDC_PROFILE** -+ Specifies the location of the KDC configuration file, which -+ contains additional configuration directives for the Key -+ Distribution Center daemon and associated programs. The default -+ is ``/usr/local/var/krb5kdc/kdc.conf``. -+ -+**KRB5RCACHETYPE** -+ Specifies the default type of replay cache to use for servers. -+ Valid types include **dfl** for the normal file type and **none** -+ for no replay cache. -+ -+**KRB5RCACHEDIR** -+ Specifies the default directory for replay caches used by servers. -+ The default is the value of the **TMPDIR** environment variable, -+ or ``/var/tmp`` if **TMPDIR** is not set. -+ -+**KRB5_TRACE** -+ Specifies a filename to write trace log output to. Trace logs can -+ help illuminate decisions made internally by the Kerberos -+ libraries. The default is not to write trace log output anywhere. -+ -+Most environment variables are disabled for certain programs, such as -+login system programs and setuid programs, which are designed to be -+secure when run within an untrusted process environment. -+ -+SEE ALSO -+-------- -+ -+:ref:`kdestroy(1)`, :ref:`kinit(1)`, :ref:`klist(1)`, -+:ref:`kswitch(1)`, :ref:`kpasswd(1)`, :ref:`ksu(1)`, -+:ref:`krb5.conf(5)`, :ref:`kdc.conf(5)`, :ref:`kadmin(1)`, -+:ref:`kadmind(8)`, :ref:`kdb5_util(8)`, :ref:`krb5kdc(8)` -+ -+BUGS -+---- -+ -+AUTHORS -+------- -+ -+| Steve Miller, MIT Project Athena/Digital Equipment Corporation -+| Clifford Neuman, MIT Project Athena -+| Greg Hudson, MIT Kerberos Consortium -+ -+HISTORY -+------- -+ -+The MIT Kerberos 5 implementation was developed at MIT, with -+contributions from many outside parties. It is currently maintained -+by the MIT Kerberos Consortium. -+ -+RESTRICTIONS -+------------ -+ -+Copyright 1985, 1986, 1989-1996, 2002, 2011 Masachusetts Institute of -+Technology -diff --git a/src/Makefile.in b/src/Makefile.in -index 79b8d5f98..745cbc497 100644 ---- a/src/Makefile.in -+++ b/src/Makefile.in -@@ -62,9 +62,9 @@ world: - INSTALLMKDIRS = $(KRB5ROOT) $(KRB5MANROOT) $(KRB5OTHERMKDIRS) \ - $(ADMIN_BINDIR) $(SERVER_BINDIR) $(CLIENT_BINDIR) \ - $(ADMIN_MANDIR) $(SERVER_MANDIR) $(CLIENT_MANDIR) \ -- $(FILE_MANDIR) \ -+ $(FILE_MANDIR) $(OVERVIEW_MANDIR) \ - $(ADMIN_CATDIR) $(SERVER_CATDIR) $(CLIENT_CATDIR) \ -- $(FILE_CATDIR) \ -+ $(FILE_CATDIR) $(OVERVIEW_CATDIR) \ - $(KRB5_LIBDIR) $(KRB5_INCDIR) \ - $(KRB5_DB_MODULE_DIR) $(KRB5_PA_MODULE_DIR) \ - $(KRB5_AD_MODULE_DIR) \ -diff --git a/src/config/pre.in b/src/config/pre.in -index 6317d3564..42bccf14c 100644 ---- a/src/config/pre.in -+++ b/src/config/pre.in -@@ -210,6 +210,8 @@ ADMIN_CATDIR = $(KRB5MANROOT)/cat8 - SERVER_CATDIR = $(KRB5MANROOT)/cat8 - CLIENT_CATDIR = $(KRB5MANROOT)/cat1 - FILE_CATDIR = $(KRB5MANROOT)/cat5 -+OVERVIEW_MANDIR = $(KRB5MANROOT)/man7 -+OVERVIEW_CATDIR = $(KRB5MANROOT)/cat7 - KRB5_LIBDIR = @libdir@ - KRB5_INCDIR = @includedir@ - MODULE_DIR = @libdir@/krb5/plugins -diff --git a/src/man/Makefile.in b/src/man/Makefile.in -index 4bc670bad..e3722b1cd 100644 ---- a/src/man/Makefile.in -+++ b/src/man/Makefile.in -@@ -15,7 +15,7 @@ MANSUBS=k5identity.sub k5login.sub k5srvutil.sub kadm5.acl.sub kadmin.sub \ - kadmind.sub kdb5_ldap_util.sub kdb5_util.sub kdc.conf.sub \ - kdestroy.sub kinit.sub klist.sub kpasswd.sub kprop.sub kpropd.sub \ - kproplog.sub krb5.conf.sub krb5-config.sub krb5kdc.sub ksu.sub \ -- kswitch.sub ktutil.sub kvno.sub sclient.sub sserver.sub -+ kswitch.sub ktutil.sub kvno.sub sclient.sub sserver.sub kerberos.sub - - docsrc=$(top_srcdir)/../doc - -@@ -56,9 +56,11 @@ all: $(MANSUBS) - clean: - rm -rf $(MANSUBS) rst_man - --install: install-clientman install-fileman install-adminman install-serverman -+install: install-clientman install-fileman install-adminman \ -+ install-overviewman install-serverman - --install-catman: install-clientcat install-filecat install-admincat install-servercat -+install-catman: install-clientcat install-filecat install-admincat \ -+ install-overviewcat install-servercat - - install-clientman: - $(INSTALL_DATA) k5srvutil.sub $(DESTDIR)$(CLIENT_MANDIR)/k5srvutil.1 -@@ -85,6 +87,9 @@ install-fileman: - $(INSTALL_DATA) kdc.conf.sub $(DESTDIR)$(FILE_MANDIR)/kdc.conf.5 - $(INSTALL_DATA) krb5.conf.sub $(DESTDIR)$(FILE_MANDIR)/krb5.conf.5 - -+install-overviewman: -+ $(INSTALL_DATA) kerberos.sub $(DESTDIR)$(OVERVIEW_MANDIR)/kerberos.7 -+ - install-adminman: - $(INSTALL_DATA) $(srcdir)/kadmin.local.8 \ - $(DESTDIR)$(ADMIN_MANDIR)/kadmin.local.8 -@@ -127,6 +132,9 @@ install-filecat: - $(GROFF_MAN) kdc.conf.sub > $(DESTDIR)$(FILE_CATDIR)/kdc.conf.5 - $(GROFF_MAN) krb5.conf.sub > $(DESTDIR)$(FILE_CATDIR)/krb5.conf.5 - -+install-overviewcat: -+ $(GROFF_MAN) kerberos.sub > $(DESTDIR)$(OVERVIEW_CATDIR)/kerberos.7 -+ - install-admincat: - ($(RM) $(DESTDIR)$(ADMIN_CATDIR)/kadmin.local.8; \ - $(LN_S) $(CLIENT_CATDIR)/kadmin.1 \ -diff --git a/src/man/kerberos.man b/src/man/kerberos.man -new file mode 100644 -index 000000000..7b2b5d932 ---- /dev/null -+++ b/src/man/kerberos.man -@@ -0,0 +1,180 @@ -+.\" Man page generated from reStructuredText. -+. -+.TH "KERBEROS" "7" " " "1.17" "MIT Kerberos" -+.SH NAME -+kerberos \- Overview of using Kerberos -+. -+.nr rst2man-indent-level 0 -+. -+.de1 rstReportMargin -+\\$1 \\n[an-margin] -+level \\n[rst2man-indent-level] -+level margin: \\n[rst2man-indent\\n[rst2man-indent-level]] -+- -+\\n[rst2man-indent0] -+\\n[rst2man-indent1] -+\\n[rst2man-indent2] -+.. -+.de1 INDENT -+.\" .rstReportMargin pre: -+. RS \\$1 -+. nr rst2man-indent\\n[rst2man-indent-level] \\n[an-margin] -+. nr rst2man-indent-level +1 -+.\" .rstReportMargin post: -+.. -+.de UNINDENT -+. RE -+.\" indent \\n[an-margin] -+.\" old: \\n[rst2man-indent\\n[rst2man-indent-level]] -+.nr rst2man-indent-level -1 -+.\" new: \\n[rst2man-indent\\n[rst2man-indent-level]] -+.in \\n[rst2man-indent\\n[rst2man-indent-level]]u -+.. -+.SH DESCRIPTION -+.sp -+The Kerberos system authenticates individual users in a network -+environment. After authenticating yourself to Kerberos, you can use -+Kerberos\-enabled programs without having to present passwords. -+.sp -+If you enter your username and kinit(1) responds with this -+message: -+.sp -+kinit(v5): Client not found in Kerberos database while getting initial -+credentials -+.sp -+you haven\(aqt been registered as a Kerberos user. See your system -+administrator. -+.sp -+A Kerberos name usually contains three parts. The first is the -+\fBprimary\fP, which is usually a user\(aqs or service\(aqs name. The second -+is the \fBinstance\fP, which in the case of a user is usually null. -+Some users may have privileged instances, however, such as \fBroot\fP or -+\fBadmin\fP\&. In the case of a service, the instance is the fully -+qualified name of the machine on which it runs; i.e. there can be an -+rlogin service running on the machine ABC, which is different from the -+rlogin service running on the machine XYZ. The third part of a -+Kerberos name is the \fBrealm\fP\&. The realm corresponds to the Kerberos -+service providing authentication for the principal. -+.sp -+When writing a Kerberos name, the principal name is separated from the -+instance (if not null) by a slash, and the realm (if not the local -+realm) follows, preceded by an "@" sign. The following are examples -+of valid Kerberos names: -+.INDENT 0.0 -+.INDENT 3.5 -+.sp -+.nf -+.ft C -+david -+jennifer/admin -+joeuser@BLEEP.COM -+cbrown/root@FUBAR.ORG -+.ft P -+.fi -+.UNINDENT -+.UNINDENT -+.sp -+When you authenticate yourself with Kerberos you get an initial -+Kerberos \fBticket\fP\&. (A Kerberos ticket is an encrypted protocol -+message that provides authentication.) Kerberos uses this ticket for -+network utilities such as rlogin and rcp. The ticket transactions are -+done transparently, so you don\(aqt have to worry about their management. -+.sp -+Note, however, that tickets expire. Privileged tickets, such as those -+with the instance \fBroot\fP, expire in a few minutes, while tickets -+that carry more ordinary privileges may be good for several hours or a -+day, depending on the installation\(aqs policy. If your login session -+extends beyond the time limit, you will have to re\-authenticate -+yourself to Kerberos to get new tickets. Use the kinit(1) -+command to re\-authenticate yourself. -+.sp -+If you use the kinit command to get your tickets, make sure you use -+the kdestroy command to destroy your tickets before you end your login -+session. You should put the kdestroy command in your \fB\&.logout\fP file -+so that your tickets will be destroyed automatically when you logout. -+For more information about the kinit and kdestroy commands, see the -+kinit(1) and kdestroy(1) manual pages. -+.sp -+Kerberos tickets can be forwarded. In order to forward tickets, you -+must request \fBforwardable\fP tickets when you kinit. Once you have -+forwardable tickets, most Kerberos programs have a command line option -+to forward them to the remote host. -+.SH ENVIRONMENT VARIABLES -+.sp -+Several environment variables affect the operation of Kerberos\-enabled -+programs. These inclide: -+.INDENT 0.0 -+.TP -+\fBKRB5CCNAME\fP -+Specifies the location of the credential cache, in the form -+\fITYPE\fP:\fIresidual\fP\&. If no \fItype\fP prefix is present, the \fBFILE\fP -+type is assumed and \fIresidual\fP is the pathname of the cache file. -+A collection of multiple caches may be used by specifying the -+\fBdir\fP type and the pathname of a private directory (which must -+already exist). The default cache file is /tmp/krb5cc_*uid*, -+where \fIuid\fP is the decimal user ID of the user. -+.TP -+\fBKRB5_KTNAME\fP -+Specifies the location of the keytab file, in the form -+\fITYPE\fP:\fIresidual\fP\&. If no \fItype\fP is present, the \fBFILE\fP type is -+assumed and \fIresidual\fP is the pathname of the keytab file. The -+default keytab file is \fB/etc/krb5.keytab\fP\&. -+.TP -+\fBKRB5_CONFIG\fP -+Specifies the location of the Kerberos configuration file. The -+default is \fB/etc/krb5.conf\fP\&. -+.TP -+\fBKRB5_KDC_PROFILE\fP -+Specifies the location of the KDC configuration file, which -+contains additional configuration directives for the Key -+Distribution Center daemon and associated programs. The default -+is \fB/usr/local/var/krb5kdc/kdc.conf\fP\&. -+.TP -+\fBKRB5RCACHETYPE\fP -+Specifies the default type of replay cache to use for servers. -+Valid types include \fBdfl\fP for the normal file type and \fBnone\fP -+for no replay cache. -+.TP -+\fBKRB5RCACHEDIR\fP -+Specifies the default directory for replay caches used by servers. -+The default is the value of the \fBTMPDIR\fP environment variable, -+or \fB/var/tmp\fP if \fBTMPDIR\fP is not set. -+.TP -+\fBKRB5_TRACE\fP -+Specifies a filename to write trace log output to. Trace logs can -+help illuminate decisions made internally by the Kerberos -+libraries. The default is not to write trace log output anywhere. -+.UNINDENT -+.sp -+Most environment variables are disabled for certain programs, such as -+login system programs and setuid programs, which are designed to be -+secure when run within an untrusted process environment. -+.SH SEE ALSO -+.sp -+kdestroy(1), kinit(1), klist(1), -+kswitch(1), kpasswd(1), ksu(1), -+krb5.conf(5), kdc.conf(5), kadmin(1), -+kadmind(8), kdb5_util(8), krb5kdc(8) -+.SH BUGS -+.SH AUTHORS -+.nf -+Steve Miller, MIT Project Athena/Digital Equipment Corporation -+Clifford Neuman, MIT Project Athena -+Greg Hudson, MIT Kerberos Consortium -+.fi -+.sp -+.SH HISTORY -+.sp -+The MIT Kerberos 5 implementation was developed at MIT, with -+contributions from many outside parties. It is currently maintained -+by the MIT Kerberos Consortium. -+.SH RESTRICTIONS -+.sp -+Copyright 1985, 1986, 1989\-1996, 2002, 2011 Masachusetts Institute of -+Technology -+.SH AUTHOR -+MIT -+.SH COPYRIGHT -+1985-2018, MIT -+.\" Generated by docutils manpage writer. -+. diff --git a/Convert-Python-tests-to-Python-3.patch b/Convert-Python-tests-to-Python-3.patch deleted file mode 100644 index 5f5dc23..0000000 --- a/Convert-Python-tests-to-Python-3.patch +++ /dev/null @@ -1,536 +0,0 @@ -From 2bc365f12282cdd83a191478b97f4ea0d9aa60dd Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 19 Feb 2018 21:10:09 -0500 -Subject: [PATCH] Convert Python tests to Python 3 - -Look for python3 in configure.in and verify that we got it. Convert -test code to conform to Python 3. - -ticket: 8710 (new) -(cherry picked from commit e23d24beacb73581bbf4351250f3955e6fd44361) -[rharwood@redhat.com: Context skew due to not having LMDB in tests] ---- - src/Makefile.in | 1 + - src/configure.in | 6 ++-- - src/kadmin/dbutil/t_tdumputil.py | 4 +-- - src/tests/jsonwalker.py | 16 +++++------ - src/tests/t_cve-2012-1014.py | 2 +- - src/tests/t_cve-2012-1015.py | 2 +- - src/tests/t_hostrealm.py | 4 ++- - src/tests/t_kdb.py | 11 ++++--- - src/tests/t_keytab.py | 34 +++++++++++----------- - src/tests/t_mkey.py | 6 ++-- - src/tests/t_otp.py | 7 +++-- - src/tests/t_tabdump.py | 4 +-- - src/util/Makefile.in | 1 + - src/util/k5test.py | 49 +++++++++++++++++--------------- - src/util/princflags.py | 25 ++++++++-------- - 15 files changed, 88 insertions(+), 84 deletions(-) - -diff --git a/src/Makefile.in b/src/Makefile.in -index 77beff8bc..79b8d5f98 100644 ---- a/src/Makefile.in -+++ b/src/Makefile.in -@@ -533,6 +533,7 @@ runenv.py: pyrunenv.vals - - clean-unix:: - $(RM) runenv.py runenv.pyc pyrunenv.vals -+ $(RM) -r __pycache__ - - COV_BUILD= cov-build - COV_ANALYZE= cov-analyze -diff --git a/src/configure.in b/src/configure.in -index 3f45784b5..00cb297b8 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -1098,15 +1098,13 @@ fi - AC_SUBST(HAVE_RUNTEST) - - # For Python tests. --AC_CHECK_PROG(PYTHON,python2,python2) -+AC_CHECK_PROG(PYTHON,python3,python3) - if text x"$PYTHON" = x; then - AC_CHECK_PROG(PYTHON,python,python) - fi - HAVE_PYTHON=no - if test x"$PYTHON" != x; then -- # k5test.py requires python 2.4 (for the subprocess module). -- # Some code needs python 2.5 (for syntax like conditional expressions). -- wantver="(sys.hexversion >= 0x2050000 and sys.hexversion < 0x3000000)" -+ wantver="(sys.hexversion >= 0x3000000)" - if "$PYTHON" -c "import sys; sys.exit(not $wantver and 1 or 0)"; then - HAVE_PYTHON=yes - fi -diff --git a/src/kadmin/dbutil/t_tdumputil.py b/src/kadmin/dbutil/t_tdumputil.py -index 52e356533..47b2aa7a3 100755 ---- a/src/kadmin/dbutil/t_tdumputil.py -+++ b/src/kadmin/dbutil/t_tdumputil.py -@@ -6,8 +6,8 @@ realm = K5Realm(create_kdb=False) - def compare(s, expected, msg): - if s == expected: - return -- print 'expected:', repr(expected) -- print 'got:', repr(s) -+ print('expected:', repr(expected)) -+ print('got:', repr(s)) - fail(msg) - - out = realm.run(['./t_tdumputil', '2', 'field1', 'field2', -diff --git a/src/tests/jsonwalker.py b/src/tests/jsonwalker.py -index 942ca2db7..7a0675e08 100644 ---- a/src/tests/jsonwalker.py -+++ b/src/tests/jsonwalker.py -@@ -2,8 +2,8 @@ import sys - try: - import cjson - except ImportError: -- print "Warning: skipping audit log verification because the cjson module" \ -- " is unavailable" -+ print("Warning: skipping audit log verification because the cjson module" \ -+ " is unavailable") - sys.exit(0) - from collections import defaultdict - from optparse import OptionParser -@@ -22,10 +22,10 @@ class Parser(object): - result = self.parse(logs) - if len(result) != len(self.defaults): - diff = set(self.defaults.keys()).difference(result.keys()) -- print 'Test failed.' -- print 'The following attributes were not set:' -+ print('Test failed.') -+ print('The following attributes were not set:') - for it in diff: -- print it -+ print(it) - sys.exit(1) - - def flatten(self, defaults): -@@ -42,7 +42,7 @@ class Parser(object): - result = dict() - for path,value in self._walk(defaults): - if path in result: -- print 'Warning: attribute path %s already exists' % path -+ print('Warning: attribute path %s already exists' % path) - result[path] = value - - return result -@@ -60,7 +60,7 @@ class Parser(object): - if v is not None: - dv = self.DEFAULTS[type(v)] - else: -- print 'Warning: attribute %s is set to None' % a -+ print('Warning: attribute %s is set to None' % a) - continue - # by now we have default value - if v != dv: -@@ -96,7 +96,7 @@ if __name__ == '__main__': - content.append(cjson.decode(l.rstrip())) - f.close() - else: -- print 'Input file in jason format is required' -+ print('Input file in jason format is required') - exit() - - defaults = None -diff --git a/src/tests/t_cve-2012-1014.py b/src/tests/t_cve-2012-1014.py -index dcff95f6e..8447e0ee7 100755 ---- a/src/tests/t_cve-2012-1014.py -+++ b/src/tests/t_cve-2012-1014.py -@@ -20,7 +20,7 @@ x2 = base64.b16decode('A44F304DA007030500FEDCBA90A10E30' + - '01') - - for x in range(11, 128): -- s.sendto(''.join([x1, chr(x), x2]), a) -+ s.sendto(x1 + bytes([x]) + x2, a) - - # Make sure kinit still works. - -diff --git a/src/tests/t_cve-2012-1015.py b/src/tests/t_cve-2012-1015.py -index 28b1e619b..ae5678cac 100755 ---- a/src/tests/t_cve-2012-1015.py -+++ b/src/tests/t_cve-2012-1015.py -@@ -27,7 +27,7 @@ x1 = base64.b16decode('6A81A030819DA103020105A20302010A' + - x2 = base64.b16decode('A8083006020106020112') - - for x in range(0, 128): -- s.sendto(''.join([x1, chr(x), x2]), a) -+ s.sendto(x1 + bytes([x]) + x2, a) - - # Make sure kinit still works. - -diff --git a/src/tests/t_hostrealm.py b/src/tests/t_hostrealm.py -index 256ba2a38..beea6f3bc 100755 ---- a/src/tests/t_hostrealm.py -+++ b/src/tests/t_hostrealm.py -@@ -119,7 +119,9 @@ testd(realm, 'KRBTEST.COM', 'default_realm profile', env=notest2) - # see the first. Remove the profile default_realm setting to expose - # this behavior. - remove_default = {'libdefaults': {'default_realm': None}} --nodefault_conf = dict(disable_conf.items() + remove_default.items()) -+# Python 3.5+: nodefault_conf = {**disable_conf, **remove_default} -+nodefault_conf = dict(list(disable_conf.items()) + -+ list(remove_default.items())) - nodefault = realm.special_env('nodefault', False, krb5_conf=nodefault_conf) - testd(realm, 'one', 'default_realm test1', env=nodefault) - -diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py -index 983cd93c8..42237f7a1 100755 ---- a/src/tests/t_kdb.py -+++ b/src/tests/t_kdb.py -@@ -1,6 +1,5 @@ - from k5test import * - import time --from itertools import imap - - # Run kdbtest against the BDB module. - realm = K5Realm(create_kdb=False) -@@ -51,7 +50,7 @@ else: - def slap_add(ldif): - proc = subprocess.Popen([slapadd, '-b', 'cn=config', '-F', slapd_conf], - stdin=subprocess.PIPE, stdout=subprocess.PIPE, -- stderr=subprocess.STDOUT) -+ stderr=subprocess.STDOUT, universal_newlines=True) - (out, dummy) = proc.communicate(ldif) - output(out) - return proc.wait() -@@ -98,7 +97,7 @@ if slap_add('include: file://%s\n' % schema) != 0: - ldap_homes = ['/etc/ldap', '/etc/openldap', '/usr/local/etc/openldap', - '/usr/local/etc/ldap'] - local_schema_path = '/schema/core.ldif' --core_schema = next((i for i in imap(lambda x:x+local_schema_path, ldap_homes) -+core_schema = next((i for i in map(lambda x:x+local_schema_path, ldap_homes) - if os.path.isfile(i)), None) - if core_schema: - if slap_add('include: file://%s\n' % core_schema) != 0: -@@ -114,7 +113,7 @@ atexit.register(kill_slapd) - - out = open(slapd_out, 'w') - subprocess.call([slapd, '-h', ldap_uri, '-F', slapd_conf], stdout=out, -- stderr=out) -+ stderr=out, universal_newlines=True) - out.close() - pidf = open(slapd_pidfile, 'r') - slapd_pid = int(pidf.read()) -@@ -158,7 +157,7 @@ def ldap_search(args): - proc = subprocess.Popen([ldapsearch, '-H', ldap_uri, '-b', top_dn, - '-D', admin_dn, '-w', admin_pw, args], - stdin=subprocess.PIPE, stdout=subprocess.PIPE, -- stderr=subprocess.STDOUT) -+ stderr=subprocess.STDOUT, universal_newlines=True) - (out, dummy) = proc.communicate() - return out - -@@ -166,7 +165,7 @@ def ldap_modify(ldif, args=[]): - proc = subprocess.Popen([ldapmodify, '-H', ldap_uri, '-D', admin_dn, - '-x', '-w', admin_pw] + args, - stdin=subprocess.PIPE, stdout=subprocess.PIPE, -- stderr=subprocess.STDOUT) -+ stderr=subprocess.STDOUT, universal_newlines=True) - (out, dummy) = proc.communicate(ldif) - output(out) - -diff --git a/src/tests/t_keytab.py b/src/tests/t_keytab.py -index 228c36334..8a17ae2eb 100755 ---- a/src/tests/t_keytab.py -+++ b/src/tests/t_keytab.py -@@ -90,36 +90,36 @@ test_key_rotate(realm, princ, 2) - - # Test that klist -k can read a keytab entry without a 32-bit kvno and - # reports the 8-bit key version. --record = '\x00\x01' # principal component count --record += '\x00\x0bKRBTEST.COM' # realm --record += '\x00\x04user' # principal component --record += '\x00\x00\x00\x01' # name type (NT-PRINCIPAL) --record += '\x54\xf7\x4d\x35' # timestamp --record += '\x02' # key version --record += '\x00\x12' # enctype --record += '\x00\x20' # key length --record += '\x00' * 32 # key bytes --f = open(realm.keytab, 'w') --f.write('\x05\x02\x00\x00\x00' + chr(len(record))) -+record = b'\x00\x01' # principal component count -+record += b'\x00\x0bKRBTEST.COM' # realm -+record += b'\x00\x04user' # principal component -+record += b'\x00\x00\x00\x01' # name type (NT-PRINCIPAL) -+record += b'\x54\xf7\x4d\x35' # timestamp -+record += b'\x02' # key version -+record += b'\x00\x12' # enctype -+record += b'\x00\x20' # key length -+record += b'\x00' * 32 # key bytes -+f = open(realm.keytab, 'wb') -+f.write(b'\x05\x02\x00\x00\x00' + bytes([len(record)])) - f.write(record) - f.close() - msg = ' 2 %s' % realm.user_princ - out = realm.run([klist, '-k'], expected_msg=msg) - - # Make sure zero-fill isn't treated as a 32-bit kvno. --f = open(realm.keytab, 'w') --f.write('\x05\x02\x00\x00\x00' + chr(len(record) + 4)) -+f = open(realm.keytab, 'wb') -+f.write(b'\x05\x02\x00\x00\x00' + bytes([len(record) + 4])) - f.write(record) --f.write('\x00\x00\x00\x00') -+f.write(b'\x00\x00\x00\x00') - f.close() - msg = ' 2 %s' % realm.user_princ - out = realm.run([klist, '-k'], expected_msg=msg) - - # Make sure a hand-crafted 32-bit kvno is recognized. --f = open(realm.keytab, 'w') --f.write('\x05\x02\x00\x00\x00' + chr(len(record) + 4)) -+f = open(realm.keytab, 'wb') -+f.write(b'\x05\x02\x00\x00\x00' + bytes([len(record) + 4])) - f.write(record) --f.write('\x00\x00\x00\x03') -+f.write(b'\x00\x00\x00\x03') - f.close() - msg = ' 3 %s' % realm.user_princ - out = realm.run([klist, '-k'], expected_msg=msg) -diff --git a/src/tests/t_mkey.py b/src/tests/t_mkey.py -index 48a533059..cbc830235 100755 ---- a/src/tests/t_mkey.py -+++ b/src/tests/t_mkey.py -@@ -296,10 +296,10 @@ realm.stop() - # 2. list_mkeys displays the same list as for a post-1.7 KDB. - dumpfile = os.path.join(srctop, 'tests', 'dumpfiles', 'dump.16') - os.remove(stash_file) --f = open(stash_file, 'w') -+f = open(stash_file, 'wb') - f.write(struct.pack('=HL24s', 16, 24, -- '\xF8\x3E\xFB\xBA\x6D\x80\xD9\x54\xE5\x5D\xF2\xE0' -- '\x94\xAD\x6D\x86\xB5\x16\x37\xEC\x7C\x8A\xBC\x86')) -+ b'\xF8\x3E\xFB\xBA\x6D\x80\xD9\x54\xE5\x5D\xF2\xE0' -+ b'\x94\xAD\x6D\x86\xB5\x16\x37\xEC\x7C\x8A\xBC\x86')) - f.close() - realm.run([kdb5_util, 'load', dumpfile]) - nprincs = len(realm.run([kadminl, 'listprincs']).splitlines()) -diff --git a/src/tests/t_otp.py b/src/tests/t_otp.py -index 0fd35d576..617a8ecf5 100755 ---- a/src/tests/t_otp.py -+++ b/src/tests/t_otp.py -@@ -29,8 +29,8 @@ - # - - from k5test import * --from Queue import Empty --import StringIO -+from queue import Empty -+from io import StringIO - import struct - - try: -@@ -120,7 +120,8 @@ class UnixRadiusDaemon(RadiusDaemon): - sock.listen(1) - return (sock, addr) - -- def recvRequest(self, (sock, addr)): -+ def recvRequest(self, sock_and_addr): -+ sock, addr = sock_and_addr - conn = sock.accept()[0] - sock.close() - os.remove(addr) -diff --git a/src/tests/t_tabdump.py b/src/tests/t_tabdump.py -index 2a86136dd..49531bf49 100755 ---- a/src/tests/t_tabdump.py -+++ b/src/tests/t_tabdump.py -@@ -1,10 +1,10 @@ - from k5test import * - - import csv --import StringIO -+from io import StringIO - - def tab_csv(s): -- io = StringIO.StringIO(s) -+ io = StringIO(s) - return list(csv.DictReader(io, dialect=csv.excel_tab)) - - -diff --git a/src/util/Makefile.in b/src/util/Makefile.in -index 2611581c1..19a6bd312 100644 ---- a/src/util/Makefile.in -+++ b/src/util/Makefile.in -@@ -26,3 +26,4 @@ install: - - clean-unix:: - $(RM) *.pyc -+ $(RM) -r __pycache__ -diff --git a/src/util/k5test.py b/src/util/k5test.py -index bc32877a7..81fac3063 100644 ---- a/src/util/k5test.py -+++ b/src/util/k5test.py -@@ -380,16 +380,16 @@ import imp - def fail(msg): - """Print a message and exit with failure.""" - global _current_pass -- print "*** Failure:", msg -+ print("*** Failure:", msg) - if _last_mark: -- print "*** Last mark: %s" % _last_mark -+ print("*** Last mark: %s" % _last_mark) - if _last_cmd: -- print "*** Last command (#%d): %s" % (_cmd_index - 1, _last_cmd) -+ print("*** Last command (#%d): %s" % (_cmd_index - 1, _last_cmd)) - if _last_cmd_output: -- print "*** Output of last command:" -+ print("*** Output of last command:") - sys.stdout.write(_last_cmd_output) - if _current_pass: -- print "*** Failed in test pass:", _current_pass -+ print("*** Failed in test pass:", _current_pass) - sys.exit(1) - - -@@ -465,15 +465,16 @@ def _onexit(): - if not verbose: - testlogfile = os.path.join(os.getcwd(), 'testlog') - utildir = os.path.join(srctop, 'util') -- print 'For details, see: %s' % testlogfile -- print 'Or re-run this test script with the -v flag:' -- print ' cd %s' % os.getcwd() -- print ' PYTHONPATH=%s %s %s -v' % \ -- (utildir, sys.executable, sys.argv[0]) -- print -- print 'Use --debug=NUM to run a command under a debugger. Use' -- print '--stop-after=NUM to stop after a daemon is started in order to' -- print 'attach to it with a debugger. Use --help to see other options.' -+ print('For details, see: %s' % testlogfile) -+ print('Or re-run this test script with the -v flag:') -+ print(' cd %s' % os.getcwd()) -+ print(' PYTHONPATH=%s %s %s -v' % -+ (utildir, sys.executable, sys.argv[0])) -+ print() -+ print('Use --debug=NUM to run a command under a debugger. Use') -+ print('--stop-after=NUM to stop after a daemon is started in order to') -+ print('attach to it with a debugger. Use --help to see other') -+ print('options.') - - - def _onsigint(signum, frame): -@@ -523,8 +524,8 @@ def _get_hostname(): - hostname = socket.gethostname() - try: - ai = socket.getaddrinfo(hostname, None, 0, 0, 0, socket.AI_CANONNAME) -- except socket.gaierror, (error, errstr): -- fail('Local hostname "%s" does not resolve: %s.' % (hostname, errstr)) -+ except socket.gaierror as e: -+ fail('Local hostname "%s" does not resolve: %s.' % (hostname, e[1])) - (family, socktype, proto, canonname, sockaddr) = ai[0] - try: - name = socket.getnameinfo(sockaddr, socket.NI_NAMEREQD) -@@ -594,7 +595,7 @@ def _match_cmdnum(cmdnum, ind): - def _build_env(): - global buildtop, runenv - env = os.environ.copy() -- for (k, v) in runenv.env.iteritems(): -+ for (k, v) in runenv.env.items(): - if v.find('./') == 0: - env[k] = os.path.join(buildtop, v) - else: -@@ -704,7 +705,8 @@ def _run_cmd(args, env, input=None, expected_code=0, expected_msg=None, - - # Run the command and log the result, folding stderr into stdout. - proc = subprocess.Popen(args, stdin=infile, stdout=subprocess.PIPE, -- stderr=subprocess.STDOUT, env=env) -+ stderr=subprocess.STDOUT, env=env, -+ universal_newlines=True) - (outdata, dummy_errdata) = proc.communicate(input) - _last_cmd_output = outdata - code = proc.returncode -@@ -734,10 +736,10 @@ def _debug_cmd(args, env, input): - (_cmd_index, _shell_equiv(args)), True) - if input: - print -- print '*** Enter the following input when appropriate:' -- print -- print input -- print -+ print('*** Enter the following input when appropriate:') -+ print() -+ print(input) -+ print() - code = subprocess.call(args, env=env) - output('*** [%d] Completed in debugger with return code %d\n' % - (_cmd_index, code)) -@@ -765,7 +767,8 @@ def _start_daemon(args, env, sentinel): - - # Start the daemon and look for the sentinel in stdout or stderr. - proc = subprocess.Popen(args, stdin=null_input, stdout=subprocess.PIPE, -- stderr=subprocess.STDOUT, env=env) -+ stderr=subprocess.STDOUT, env=env, -+ universal_newlines=True) - _last_cmd_output = '' - while True: - line = proc.stdout.readline() -diff --git a/src/util/princflags.py b/src/util/princflags.py -index f568dd2f1..f645e86e4 100644 ---- a/src/util/princflags.py -+++ b/src/util/princflags.py -@@ -1,5 +1,4 @@ - import re --import string - - # Module for translating KDB principal flags between string and - # integer forms. -@@ -81,7 +80,7 @@ _prefixlen = len(_prefix) - _flagnames = {} - - # Translation table to map hyphens to underscores --_squash = string.maketrans('-', '_') -+_squash = str.maketrans('-', '_') - - # Combined input-to-flag lookup table, to be filled in by - # _setup_tables() -@@ -176,7 +175,7 @@ def flagnum2str(n): - # Return a list of flag names from a flag word. - def flags2namelist(flags): - a = [] -- for n in xrange(32): -+ for n in range(32): - if flags & (1 << n): - a.append(flagnum2str(n)) - return a -@@ -225,21 +224,21 @@ def speclist2mask(s): - - # Print C table of input flag specifiers for lib/kadm5/str_conv.c. - def _print_ftbl(): -- print 'static const struct flag_table_row ftbl[] = {' -- a = sorted(pflags.items(), key=lambda (k, v): (v.flag, -v.invert, k)) -+ print('static const struct flag_table_row ftbl[] = {') -+ a = sorted(pflags.items(), key=lambda k, v: (v.flag, -v.invert, k)) - for k, v in a: - s1 = ' {"%s",' % k - s2 = '%-31s KRB5_KDB_%s,' % (s1, v.flagname()) -- print '%-63s %d},' % (s2, 1 if v.invert else 0) -+ print('%-63s %d},' % (s2, 1 if v.invert else 0)) - -- print '};' -- print '#define NFTBL (sizeof(ftbl) / sizeof(ftbl[0]))' -+ print('};') -+ print('#define NFTBL (sizeof(ftbl) / sizeof(ftbl[0]))') - - - # Print C table of output flag names for lib/kadm5/str_conv.c. - def _print_outflags(): -- print 'static const char *outflags[] = {' -- for i in xrange(32): -+ print('static const char *outflags[] = {') -+ for i in range(32): - flag = 1 << i - if flag > max(_flagnames.keys()): - break -@@ -247,10 +246,10 @@ def _print_outflags(): - s = ' "%s",' % _flagnames[flag] - except KeyError: - s = ' NULL,' -- print '%-32s/* 0x%08x */' % (s, flag) -+ print('%-32s/* 0x%08x */' % (s, flag)) - -- print '};' -- print '#define NOUTFLAGS (sizeof(outflags) / sizeof(outflags[0]))' -+ print('};') -+ print('#define NOUTFLAGS (sizeof(outflags) / sizeof(outflags[0]))') - - - # Print out C tables to insert into lib/kadm5/str_conv.c. diff --git a/Correct-kpasswd_server-description-in-krb5.conf-5.patch b/Correct-kpasswd_server-description-in-krb5.conf-5.patch deleted file mode 100644 index 07e10d1..0000000 --- a/Correct-kpasswd_server-description-in-krb5.conf-5.patch +++ /dev/null @@ -1,28 +0,0 @@ -From c5d97d45431509fe972ce24fed2429027221b0ec Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 16 Oct 2018 17:32:29 -0400 -Subject: [PATCH] Correct kpasswd_server description in krb5.conf(5) - -ticket: 8754 (new) -tags: pullup -target_version: 1.16-next - -(cherry picked from commit 762d804701f78fc76f728ec05a205eea6a2b2dd7) ---- - doc/admin/conf_files/krb5_conf.rst | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index eb5c29e5d..f5139244b 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -523,7 +523,8 @@ following tags may be specified in the realm's subsection: - - **kpasswd_server** - Points to the server where all the password changes are performed. -- If there is no such entry, the port 464 on the **admin_server** -+ If there is no such entry, DNS will be queried (unless forbidden -+ by **dns_lookup_kdc**). Finally, port 464 on the **admin_server** - host will be tried. - - **master_kdc** diff --git a/Eliminate-preprocessor-disabled-dead-code.patch b/Eliminate-preprocessor-disabled-dead-code.patch deleted file mode 100644 index 9c55c67..0000000 --- a/Eliminate-preprocessor-disabled-dead-code.patch +++ /dev/null @@ -1,2950 +0,0 @@ -From 904a5789da342857a50de5874fe6aae1f96cbc5c Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 16 Jul 2018 15:35:15 -0400 -Subject: [PATCH] Eliminate preprocessor-disabled dead code - -It's been policy for a while now not to create "dead hunks" like -these. A great deal of this code simply doesn't work because it -hasn't been kept up-to-date, and may never have worked. Eliminate -these dead hunks along with the complexity to support them. - -(cherry picked from commit 2bc951d3c88b460a16249115cbd51d69c3c57e22) -[rharwood@redhat.com: context skew] ---- - src/ccapi/common/win/OldCC/ccutils.c | 6 -- - src/ccapi/common/win/OldCC/ccutils.h | 3 - - src/ccapi/common/win/OldCC/opts.cxx | 39 ---------- - src/ccapi/common/win/OldCC/secure.hxx | 6 -- - src/ccapi/common/win/OldCC/util.h | 3 - - src/ccapi/lib/win/OldCC/client.cxx | 39 ---------- - src/ccapi/lib/win/ccapi_os_ipc.cxx | 15 ---- - src/ccapi/lib/win/ccs_reply_proc.c | 8 +- - src/ccapi/lib/win/dllmain.cxx | 12 +-- - src/ccapi/server/win/ccs_os_server.cpp | 23 +----- - src/ccapi/server/win/ccs_request_proc.c | 12 +-- - src/ccapi/server/win/ccs_win_pipe.c | 4 +- - src/ccapi/test/pingtest.c | 6 -- - src/clients/ksu/authorization.c | 17 ----- - src/config/win-post.in | 8 -- - src/include/gssrpc/auth.h | 15 ---- - src/include/gssrpc/rename.h | 26 +------ - src/include/gssrpc/rpc.h | 25 ------- - src/include/gssrpc/types.hin | 7 -- - src/include/k5-platform.h | 28 +------ - src/kadmin/dbutil/kdb5_util.c | 38 ---------- - src/kadmin/server/ipropd_svc.c | 29 ------- - src/kdc/kdc_log.c | 8 -- - src/kdc/kdc_preauth.c | 13 ---- - src/lib/apputils/net-server.c | 27 ------- - src/lib/crypto/builtin/des/destest.c | 4 - - src/lib/crypto/builtin/des/t_verify.c | 24 ------ - src/lib/crypto/builtin/pbkdf2.c | 38 +--------- - src/lib/crypto/builtin/sha1/t_shs.c | 15 ---- - src/lib/crypto/crypto_tests/t_cksums.c | 4 - - src/lib/crypto/crypto_tests/t_crc.c | 45 +---------- - src/lib/crypto/crypto_tests/t_cts.c | 27 ------- - src/lib/crypto/crypto_tests/t_decrypt.c | 4 - - src/lib/crypto/crypto_tests/t_derive.c | 4 - - src/lib/crypto/crypto_tests/t_hmac.c | 11 --- - src/lib/crypto/crypto_tests/t_str2key.c | 4 - - src/lib/crypto/crypto_tests/vectors.c | 5 -- - src/lib/crypto/krb/nfold.c | 10 --- - src/lib/gssapi/generic/util_set.c | 15 ---- - src/lib/gssapi/krb5/accept_sec_context.c | 11 --- - src/lib/gssapi/krb5/gssapi_krb5.c | 28 ------- - src/lib/gssapi/krb5/naming_exts.c | 10 --- - src/lib/gssapi/mechglue/g_initialize.c | 25 ------- - src/lib/gssapi/mechglue/g_inq_cred.c | 5 -- - src/lib/gssapi/mechglue/mglueP.h | 5 -- - src/lib/kadm5/clnt/client_init.c | 48 +----------- - src/lib/kadm5/srv/server_init.c | 11 --- - src/lib/kadm5/unit-test/setkey-test.c | 9 --- - src/lib/krb5/asn.1/ldap_key_seq.c | 3 - - src/lib/krb5/ccache/ccapi/stdcc.c | 58 -------------- - src/lib/krb5/ccache/ccapi/winccld.h | 36 --------- - src/lib/krb5/keytab/t_keytab.c | 13 ---- - src/lib/krb5/krb/gc_via_tkt.c | 11 --- - src/lib/krb5/krb/init_ctx.c | 7 -- - src/lib/krb5/krb/rd_req_dec.c | 31 +------- - src/lib/krb5/krb/t_ser.c | 75 +------------------ - src/lib/krb5/krb/unparse.c | 7 -- - src/lib/krb5/os/localaddr.c | 22 ------ - src/lib/krb5/rcache/rc_io.c | 4 - - src/lib/rpc/auth_gssapi.c | 8 -- - src/lib/rpc/svc_auth.c | 3 - - src/lib/rpc/svc_auth_gssapi.c | 4 - - src/lib/win_glue.c | 9 --- - src/plugins/kdb/db2/lockout.c | 4 - - src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c | 3 - - src/plugins/preauth/pkinit/pkinit_clnt.c | 18 ----- - src/plugins/preauth/pkinit/pkinit_matching.c | 11 --- - src/plugins/preauth/pkinit/pkinit_srv.c | 18 ----- - src/tests/asn.1/krb5_decode_leak.c | 12 --- - src/tests/dejagnu/config/default.exp | 20 ----- - src/tests/shlib/t_loader.c | 12 --- - src/tests/threads/t_rcache.c | 6 -- - src/util/profile/prof_file.c | 43 ----------- - src/util/support/fake-addrinfo.c | 6 -- - src/util/support/utf8.c | 22 ------ - src/windows/include/loadfuncs-krb5.h | 23 ------ - src/windows/kfwlogon/kfwlogon.c | 11 --- - src/windows/leash/Leash.cpp | 4 - - src/windows/leash/Makefile.in | 3 - - src/windows/leash/VSroutines.c | 64 ---------------- - src/windows/leashdll/lsh_pwd.c | 11 --- - src/windows/leashdll/lshfunc.c | 32 +------- - src/windows/leashdll/lshutil.cpp | 11 --- - src/windows/lib/cacheapi.h | 15 ---- - 84 files changed, 23 insertions(+), 1396 deletions(-) - delete mode 100644 src/windows/leash/VSroutines.c - -diff --git a/src/ccapi/common/win/OldCC/ccutils.c b/src/ccapi/common/win/OldCC/ccutils.c -index 13f72cbe0..403c67ebe 100644 ---- a/src/ccapi/common/win/OldCC/ccutils.c -+++ b/src/ccapi/common/win/OldCC/ccutils.c -@@ -101,9 +101,6 @@ HANDLE createThreadEvent(char* uuid, char* suffix) { - event_name = allocEventName(uuid, suffix); - if (!event_name) status = cci_check_error(ccErrNoMem); - } --#if 0 -- cci_debug_printf("%s event_name:%s", __FUNCTION__, event_name); --#endif - if (!status) { - hEvent = CreateEvent(psa, FALSE, FALSE, event_name); - if (!hEvent) status = cci_check_error(GetLastError()); -@@ -125,9 +122,6 @@ HANDLE openThreadEvent(char* uuid, char* suffix) { - - event_name = allocEventName(uuid, suffix); - if (!event_name) status = cci_check_error(ccErrNoMem); --#if 0 -- cci_debug_printf("%s event_name:%s", __FUNCTION__, event_name); --#endif - if (!status) { - hEvent = OpenEvent(EVENT_MODIFY_STATE, FALSE, event_name); - if (!hEvent) status = cci_check_error(GetLastError()); -diff --git a/src/ccapi/common/win/OldCC/ccutils.h b/src/ccapi/common/win/OldCC/ccutils.h -index f91c77702..9da3d87fd 100644 ---- a/src/ccapi/common/win/OldCC/ccutils.h -+++ b/src/ccapi/common/win/OldCC/ccutils.h -@@ -29,9 +29,6 @@ - #ifdef __cplusplus - extern "C" { - #endif --#if 0 --} --#endif - - #define REPLY_SUFFIX (char*)"reply" - #define LISTEN_SUFFIX (char*)"listen" -diff --git a/src/ccapi/common/win/OldCC/opts.cxx b/src/ccapi/common/win/OldCC/opts.cxx -index bd5f503ea..c9776638b 100644 ---- a/src/ccapi/common/win/OldCC/opts.cxx -+++ b/src/ccapi/common/win/OldCC/opts.cxx -@@ -29,45 +29,6 @@ - #include - #include - --#if 0 --const struct Opts* --GetOpts( -- ) --{ -- bool done = false; -- struct Opts* o; -- if (!(o = new Opts)) -- goto cleanup; -- if (!(o->pszString = new char[lstrlenA(opts.pszString) + 1])) -- goto cleanup; -- if (!(o->pszEndpoint = new char[lstrlenA(opts.pszEndpoint) + 1])) -- goto cleanup; -- strcpy(o->pszString, opts.pszString); -- strcpy(o->pszEndpoint, opts.pszEndpoint); -- done = true; -- cleanup: -- if (!done) { -- FreeOpts(o); -- o = 0; -- } -- return o; --} -- --void --FreeOpts( -- struct Opts* o -- ) --{ -- if (o) { -- if (o->pszString) -- delete [] o->pszString; -- if (o->pszEndpoint) -- delete [] o->pszEndpoint; -- delete o; -- } --} --#endif -- - bool - ParseOpts::IsValidOpt( - char ch -diff --git a/src/ccapi/common/win/OldCC/secure.hxx b/src/ccapi/common/win/OldCC/secure.hxx -index 3714c6f84..1b2e7532d 100644 ---- a/src/ccapi/common/win/OldCC/secure.hxx -+++ b/src/ccapi/common/win/OldCC/secure.hxx -@@ -38,12 +38,6 @@ public: - static void Start(SecureClient*& s); - static void Stop(SecureClient*& s); - --#if 0 -- static DWORD CheckImpersonation(); -- static bool IsImp(); -- static DWORD DuplicateImpAsPrimary(HANDLE& hPrimary); --#endif -- - SecureClient(); - ~SecureClient(); - DWORD Error(); -diff --git a/src/ccapi/common/win/OldCC/util.h b/src/ccapi/common/win/OldCC/util.h -index 082f6080b..45e069a71 100644 ---- a/src/ccapi/common/win/OldCC/util.h -+++ b/src/ccapi/common/win/OldCC/util.h -@@ -29,9 +29,6 @@ - #ifdef __cplusplus - extern "C" { - #endif --#if 0 --} --#endif - - BOOL isNT(); - -diff --git a/src/ccapi/lib/win/OldCC/client.cxx b/src/ccapi/lib/win/OldCC/client.cxx -index 4b2d718cc..0f95dfceb 100644 ---- a/src/ccapi/lib/win/OldCC/client.cxx -+++ b/src/ccapi/lib/win/OldCC/client.cxx -@@ -118,9 +118,6 @@ DWORD find_server(Init::InitInfo& info, LPSTR endpoint) { - char* szDir = 0; - BOOL bRes = FALSE; - char* cmdline = NULL; --#if 0 -- HANDLE hToken = 0; --#endif - - psa = isNT() ? &sa : 0; - -@@ -156,38 +153,6 @@ DWORD find_server(Init::InitInfo& info, LPSTR endpoint) { - } - - if (!status) { -- --#if 0 -- if (SecureClient::IsImp()) { -- cci_debug_printf(STARTUP "Token is impersonation token")); -- SecureClient::DuplicateImpAsPrimary(hToken); -- } -- else { -- cci_debug_printf(STARTUP "Token is NOT impersonation token")); -- } --#endif -- --#if 0 -- if (hToken) -- bRes = CreateProcessAsUser(hToken, -- szExe, // app name -- NULL, // cmd line -- psa, // SA -- psa, // SA -- FALSE, -- CREATE_NEW_PROCESS_GROUP | -- //CREATE_NEW_CONSOLE | -- NORMAL_PRIORITY_CLASS | -- // CREATE_NO_WINDOW | -- DETACHED_PROCESS | -- 0 -- , -- NULL, // environment -- szDir, // current dir -- &si, -- &pi); -- else --#endif - alloc_cmdline_2_args(szExe, endpoint, "-D", &cmdline); - bRes = CreateProcess( szExe, // app name - NULL, //cmdline, // cmd line is -@@ -223,10 +188,6 @@ DWORD find_server(Init::InitInfo& info, LPSTR endpoint) { - cci_debug_printf(" unexpected error while looking for server: 0D%d / 0U%u / 0X%X", status, status, status); - } - --#if 0 -- if (hToken) -- CloseHandle(hToken); --#endif - if (szDir) free_alloc_p(&szDir); - if (szExe) free_alloc_p(&szExe); - if (hEvent) CloseHandle(hEvent); -diff --git a/src/ccapi/lib/win/ccapi_os_ipc.cxx b/src/ccapi/lib/win/ccapi_os_ipc.cxx -index 35589a54f..1b1f874e9 100644 ---- a/src/ccapi/lib/win/ccapi_os_ipc.cxx -+++ b/src/ccapi/lib/win/ccapi_os_ipc.cxx -@@ -132,9 +132,6 @@ extern "C" cc_int32 cci_os_ipc_thread_init (void) { - cci_check_error(err); - } - --#if 0 -- cci_debug_printf("%s UUID:<%s>", __FUNCTION__, tspdata_getUUID(ptspdata)); --#endif - // Initialize old CCAPI if necessary: - if (!err) if (!Init:: Initialized()) err = Init:: Initialize( ); - if (!err) if (!Client::Initialized()) err = Client::Initialize(0); -@@ -243,10 +240,6 @@ extern "C" cc_int32 cci_os_ipc_msg( cc_int32 in_launch_server, - if (!GetTspData(GetTlsIndex(), &ptspdata)) {return ccErrBadParam;} - uuid = tspdata_getUUID(ptspdata); - lenUUID = 1 + strlen(uuid); /* 1+ includes terminating \0. */ --#if 0 -- cci_debug_printf("%s calling remote ccs_rpc_request tsp*:0x%X", __FUNCTION__, ptspdata); -- cci_debug_printf(" rpcmsg:%d; UUID[%d]:<%s> SST:%ld", in_msg, lenUUID, uuid, sst); --#endif - /* copy ptr into handle; ptr may be 4 or 8 bytes, depending on platform; handle is always 8 */ - memcpy(tspdata_handle, &ptspdata, sizeof(ptspdata)); - ccs_rpc_request( /* make call with user message: */ -@@ -282,11 +275,6 @@ extern "C" cc_int32 cci_os_ipc_msg( cc_int32 in_launch_server, - if (!err && server_died) { - err = cci_check_error (ccErrServerUnavailable); - } --#if 0 -- if (err == BOOTSTRAP_UNKNOWN_SERVICE && !in_launch_server) { -- err = ccNoError; /* If the server is not running just return an empty stream. */ -- } --#endif - - if (!err) { - *out_reply_stream = tspdata_getStream(ptspdata); -@@ -365,9 +353,6 @@ cc_int32 ccapi_connect(const struct tspdata* tsp) { - ReleaseMutex(hCCAPIv2Mutex); - - if (!status) { --#if 0 -- cci_debug_printf("%s Waiting for replyEvent.", __FUNCTION__); --#endif - status = WaitForSingleObject(replyEvent, INFINITE);//(SECONDS_TO_WAIT)*1000); - status = cci_check_error(RpcMgmtIsServerListening(CLIENT_REQUEST_RPC_HANDLE)); - cci_debug_printf(" Server %sFOUND!", (status) ? "NOT " : ""); -diff --git a/src/ccapi/lib/win/ccs_reply_proc.c b/src/ccapi/lib/win/ccs_reply_proc.c -index bf8c7f4f4..b4dbc0d19 100644 ---- a/src/ccapi/lib/win/ccs_reply_proc.c -+++ b/src/ccapi/lib/win/ccs_reply_proc.c -@@ -47,9 +47,7 @@ void ccs_rpc_request_reply( - struct tspdata* tsp; - k5_ipc_stream stream; - long status = 0; --#if 0 -- cci_debug_printf("%s! msg#:%d SST:%ld uuid:%s", __FUNCTION__, rpcmsg, srvStartTime, uuid); --#endif -+ - memcpy(&tsp, tspHandle, sizeof(tsp)); - if (!status) { - status = krb5int_ipc_stream_new (&stream); /* Create a stream for the request data */ -@@ -77,9 +75,7 @@ void ccs_rpc_connect_reply( - - HANDLE hEvent = openThreadEvent(uuid, REPLY_SUFFIX); - DWORD* p = (DWORD*)(tspHandle); --#if 0 -- cci_debug_printf("%s! msg#:%d SST:%ld uuid:%s", __FUNCTION__, rpcmsg, srvStartTime, uuid); --#endif -+ - SetEvent(hEvent); - CloseHandle(hEvent); - } -diff --git a/src/ccapi/lib/win/dllmain.cxx b/src/ccapi/lib/win/dllmain.cxx -index 82cacad9c..aa5d00a65 100644 ---- a/src/ccapi/lib/win/dllmain.cxx -+++ b/src/ccapi/lib/win/dllmain.cxx -@@ -163,17 +163,7 @@ BOOL WINAPI DllMain(HINSTANCE hinstDLL, // DLL module handle - // using multiple DLLs that use this DLL. - // - WaitForSingleObject( hCCAPIv2Mutex, INFINITE ); --#if 0 -- bool process_teardown_workaround = false; -- if (lpvReserved) { -- Init::InitInfo info; -- status = Init::Info(info); -- if (status) break; -- if (!info.isNT) process_teardown_workaround = true; -- } -- if (process_teardown_workaround) -- break; --#endif -+ - // return value is ignored, so we set status for debugging purposes - status = Client::Cleanup(); - status = Init::Cleanup(); -diff --git a/src/ccapi/server/win/ccs_os_server.cpp b/src/ccapi/server/win/ccs_os_server.cpp -index f84239491..7c5012039 100644 ---- a/src/ccapi/server/win/ccs_os_server.cpp -+++ b/src/ccapi/server/win/ccs_os_server.cpp -@@ -245,10 +245,7 @@ cc_int32 ccs_os_server_listen_loop (int argc, const char *argv[]) { - - if (worklist_remove(&rpcmsg, &pipe, &buf, &serverStartTime)) { - uuid = ccs_win_pipe_getUuid(pipe); --#if 0 -- cci_debug_printf("%s: processing WorkItem msg:%ld pipeUUID:<%s> pipeHandle:0x%X SST:%ld", -- __FUNCTION__, rpcmsg, uuid, ccs_win_pipe_getHandle(pipe), serverStartTime); --#endif -+ - if (serverStartTime <= getMySST()) { - switch (rpcmsg) { - case CCMSG_CONNECT: { -@@ -472,13 +469,6 @@ void receiveLoop(void* rpcargs) { - } // End receiveLoop - - --#if 0 -- -- return status; --} --#endif -- -- - - /* ------------------------------------------------------------------------ */ - /* The connection listener thread waits forever for a call to the CCAPI_CLIENT_ -@@ -647,17 +637,6 @@ RPC_STATUS send_connection_reply(ccs_pipe_t in_pipe) { - return (status); - } - --#if 0 --DWORD alloc_name(LPSTR* pname, LPSTR postfix) { -- DWORD len = strlen(sessID) + 1 + strlen(postfix) + 1; -- -- *pname = (LPSTR)malloc(len); -- if (!*pname) return GetLastError(); -- _snprintf(*pname, len, "%s.%s", sessID, postfix); -- return 0; -- } --#endif -- - RPC_STATUS GetPeerName( RPC_BINDING_HANDLE hClient, - LPTSTR pszClientName, - int iMaxLen) { -diff --git a/src/ccapi/server/win/ccs_request_proc.c b/src/ccapi/server/win/ccs_request_proc.c -index 461c441ed..c0328ea7e 100644 ---- a/src/ccapi/server/win/ccs_request_proc.c -+++ b/src/ccapi/server/win/ccs_request_proc.c -@@ -45,9 +45,7 @@ void ccs_rpc_request( - k5_ipc_stream stream; - UINT64* p = (UINT64*)(tspHandle); - WIN_PIPE* pipe = NULL; --#if 0 -- cci_debug_printf("%s rpcmsg:%d; UUID:<%s> SST:<%s>", __FUNCTION__, rpcmsg, pszUUID, serverStartTime); --#endif -+ - status = (rpcmsg != CCMSG_REQUEST) && (rpcmsg != CCMSG_PING); - - if (!status) { -@@ -72,9 +70,7 @@ void ccs_rpc_connect( - - UINT64* p = (UINT64*)(tspHandle); - WIN_PIPE* pipe = ccs_win_pipe_new(pszUUID, *p); --#if 0 -- cci_debug_printf("%s; rpcmsg:%d; UUID: <%s>", __FUNCTION__, rpcmsg, pszUUID); --#endif -+ - worklist_add( rpcmsg, - pipe, - NULL, /* No payload with connect request */ -@@ -89,9 +85,7 @@ CC_UINT32 ccs_authenticate(const CC_CHAR* name) { - PDWORD pvalue = 0; - CC_UINT32 result = 0; - DWORD status = 0; --#if 0 -- cci_debug_printf("%s ( %s )", __FUNCTION__, name); --#endif -+ - hMap = OpenFileMapping(FILE_MAP_ALL_ACCESS, FALSE, (LPSTR)name); - status = !hMap; - -diff --git a/src/ccapi/server/win/ccs_win_pipe.c b/src/ccapi/server/win/ccs_win_pipe.c -index d23e4448e..99c667017 100644 ---- a/src/ccapi/server/win/ccs_win_pipe.c -+++ b/src/ccapi/server/win/ccs_win_pipe.c -@@ -61,9 +61,7 @@ struct ccs_win_pipe_t* ccs_win_pipe_new (const char* uuid, const UINT64 h) { - out_pipe->uuid = uuidCopy; - out_pipe->clientHandle = h; - } --#if 0 -- cci_debug_printf("0x%X = %s(%s, 0x%X)", out_pipe, __FUNCTION__, uuid, h); --#endif -+ - return out_pipe; - } - -diff --git a/src/ccapi/test/pingtest.c b/src/ccapi/test/pingtest.c -index d44839f71..0ffc15e7a 100644 ---- a/src/ccapi/test/pingtest.c -+++ b/src/ccapi/test/pingtest.c -@@ -74,12 +74,6 @@ int main( int argc, char *argv[]) { - - if ((dwTlsIndex = TlsAlloc()) == TLS_OUT_OF_INDEXES) return FALSE; - --// send_test("krbcc.229026.0.ep"); -- --#if 0 -- err = cc_initialize(&context, ccapi_version_7, NULL, NULL); --#endif -- - if (!err) { - err = cci_os_ipc_thread_init(); - } -diff --git a/src/clients/ksu/authorization.c b/src/clients/ksu/authorization.c -index 90aafbd75..891921870 100644 ---- a/src/clients/ksu/authorization.c -+++ b/src/clients/ksu/authorization.c -@@ -123,23 +123,6 @@ krb5_error_code krb5_authorization(context, principal, luser, - "In krb5_authorization: if auth files exist -> can access\n"); - } - --#if 0 -- if (cmd){ -- if(k5users_flag){ -- return 0; /* if kusers does not exist -> done */ -- }else{ -- if(retval = k5users_lookup(users_fp,princname, -- cmd,&retbool,out_fcmd)){ -- auth_cleanup(users_fp, login_fp, princname); -- return retval; -- }else{ -- *ok =retbool; -- return retval; -- } -- } -- } --#endif -- - /* if either file exists, - first see if the principal is in the login in file, - if it's not there check the k5users file */ -diff --git a/src/config/win-post.in b/src/config/win-post.in -index 6535c1ba5..3f43bda77 100644 ---- a/src/config/win-post.in -+++ b/src/config/win-post.in -@@ -121,14 +121,6 @@ clean-windows-files: - !else - @if exist $(OUTPRE3)$(DIRNUL) deltree /y $(OUTPRE3) - !endif --!if 0 -- $(RM) .\$(OUTPRE)*.obj .\$(OUTPRE)*.res -- $(RM) .\$(OUTPRE)*.exe .\$(OUTPRE)*.dll -- $(RM) .\$(OUTPRE)*.lib .\$(OUTPRE)*.pdb -- $(RM) .\$(OUTPRE)*.exp .\$(OUTPRE)*.map -- $(RM) .\$(OUTPRE)*.idb .\$(OUTPRE)*.ilk -- $(RM) .\$(OUTPRE)*.manifest --!endif - - # Dependencies - !if exist($(srcdir)/deps) -diff --git a/src/include/gssrpc/auth.h b/src/include/gssrpc/auth.h -index 0f653fcc7..8576c5142 100644 ---- a/src/include/gssrpc/auth.h -+++ b/src/include/gssrpc/auth.h -@@ -75,12 +75,6 @@ enum auth_stat { - }; - - union des_block { --#if 0 /* XXX nothing uses this, anyway */ -- struct { -- uint32_t high; -- uint32_t low; -- } key; --#endif - char c[8]; - }; - typedef union des_block des_block; -@@ -207,15 +201,6 @@ extern bool_t xdr_opaque_auth(XDR *, struct opaque_auth *); - #define AUTH_GSSAPI 300001 /* GSS-API style */ - #define RPCSEC_GSS 6 /* RPCSEC_GSS */ - --#if 0 --/* -- * BACKWARDS COMPATIBILIY! OpenV*Secure 1.0 had AUTH_GSSAPI == 4. We -- * need to accept this value until 1.0 is dead. -- */ --/* This conflicts with AUTH_KERB (Solaris). */ --#define AUTH_GSSAPI_COMPAT 4 --#endif -- - GSSRPC__END_DECLS - - #endif /* !defined(GSSRPC_AUTH_H) */ -diff --git a/src/include/gssrpc/rename.h b/src/include/gssrpc/rename.h -index 669a0580c..df37e95b7 100644 ---- a/src/include/gssrpc/rename.h -+++ b/src/include/gssrpc/rename.h -@@ -50,10 +50,7 @@ - * External names in the RPC API not beginning with "_" get renamed - * with the prefix "gssrpc_" via #define, e.g., "foo" -> "gssrpc_foo". - * External names in the RPC API beginning with "_" get textually -- * rewritten, with "#if 0"-disabled #defines mapping them back to -- * their original forms, e.g., "_foo" is rewrittten to "gssrpc__foo" -- * in the original files, with an unused "#define gssrpc__foo _foo" -- * here. -+ * rewritten. - */ - - #ifndef GSSRPC_RENAME_H -@@ -72,10 +69,6 @@ - #define authdes_create gssrpc_authdes_create - #define xdr_opaque_auth gssrpc_xdr_opaque_auth - --#if 0 --#define gssrpc__null_auth _null_auth --#endif -- - /* auth_gss.c */ - - #define auth_debug_gss gssrpc_auth_debug_gss -@@ -181,10 +174,6 @@ - #define callrpc gssrpc_callrpc - #define getrpcport gssrpc_getrpcport - --#if 0 --#define gssrpc__rpc_getdtablesize _rpc_getdtablesize --#endif -- - /* rpc_msg.h */ - - #define xdr_callmsg gssrpc_xdr_callmsg -@@ -193,10 +182,6 @@ - #define xdr_accepted_reply gssrpc_xdr_accepted_reply - #define xdr_rejected_reply gssrpc_xdr_rejected_reply - --#if 0 --#define gssrpc__seterr_reply _seterr_reply --#endif -- - /* svc.h */ - - #define svc_register gssrpc_svc_register -@@ -244,15 +229,6 @@ - #define svcauth_gss_set_svc_name gssrpc_svcauth_gss_set_svc_name - #define svcauth_gss_get_principal gssrpc_svcauth_gss_get_principal - --#if 0 --#define gssrpc__authenticate _authenticate --#define gssrpc__svcauth_none _svcauth_none --#define gssrpc__svcauth_unix _svcauth_unix --#define gssrpc__svcauth_short _svcauth_short --#define gssrpc__svcauth_gssapi _svcauth_gssapi --#define gssrpc__svcauth_gss _svcauth_gss --#endif -- - /* svc_auth_gss.c */ - - #define svc_debug_gss gssrpc_svc_debug_gss -diff --git a/src/include/gssrpc/rpc.h b/src/include/gssrpc/rpc.h -index 2d94a7fe9..78727c49d 100644 ---- a/src/include/gssrpc/rpc.h -+++ b/src/include/gssrpc/rpc.h -@@ -55,36 +55,11 @@ - #include /* protocol for rpc messages */ - #include /* protocol for unix style cred */ - #include /* RPCSEC_GSS */ --/* -- * Uncomment-out the next line if you are building the rpc library with -- * DES Authentication (see the README file in the secure_rpc/ directory). -- */ --#if 0 --#include protocol for des style cred --#endif - - /* Server side only remote procedure callee */ - #include /* service side authenticator */ - #include /* service manager and multiplexer */ - --/* -- * Punt the rpc/netdb.h everywhere because it just makes things much more -- * difficult. We don't use the *rpcent functions anyway. -- */ --#if 0 --/* -- * COMMENT OUT THE NEXT INCLUDE IF RUNNING ON SUN OS OR ON A VERSION -- * OF UNIX BASED ON NFSSRC. These systems will already have the structures -- * defined by included in . -- */ --/* routines for parsing /etc/rpc */ --#if 0 /* netdb.h already included in rpc/types.h */ --#include --#endif -- --#include /* structures and routines to parse /etc/rpc */ --#endif -- - /* - * get the local host's IP address without consulting - * name service library functions -diff --git a/src/include/gssrpc/types.hin b/src/include/gssrpc/types.hin -index 022ab4fa9..4c4120c6f 100644 ---- a/src/include/gssrpc/types.hin -+++ b/src/include/gssrpc/types.hin -@@ -116,13 +116,6 @@ typedef int32_t rpc_inline_t; - #define mem_alloc(bsize) malloc(bsize) - #define mem_free(ptr, bsize) free(ptr) - --#if 0 --#include /* XXX This should not have to be here. -- * I got sick of seeing the warnings for MAXHOSTNAMELEN -- * and the two values were different. -- shanzer -- */ --#endif -- - #ifndef INADDR_LOOPBACK - #define INADDR_LOOPBACK (uint32_t)0x7F000001 - #endif -diff --git a/src/include/k5-platform.h b/src/include/k5-platform.h -index 763408a09..3368c7193 100644 ---- a/src/include/k5-platform.h -+++ b/src/include/k5-platform.h -@@ -526,15 +526,11 @@ typedef struct { int error; unsigned char did_run; } k5_init_t; - # endif - #elif TARGET_OS_MAC - # include --# if 0 /* This causes compiler warnings. */ --# define SWAP16 OSSwapInt16 --# else --# define SWAP16 k5_swap16 -+# define SWAP16 k5_swap16 - static inline unsigned int k5_swap16 (unsigned int x) { - x &= 0xffff; - return (x >> 8) | ((x & 0xff) << 8); - } --# endif - # define SWAP32 OSSwapInt32 - # define SWAP64 OSSwapInt64 - #elif defined(HAVE_SYS_BSWAP_H) -@@ -848,25 +844,6 @@ k5_ntohll (uint64_t val) - business. Probably most callers won't check the return status - anyways. */ - --#if 0 --static inline void --set_cloexec_fd(int fd) --{ --#if defined(F_SETFD) --# ifdef FD_CLOEXEC -- (void)fcntl(fd, F_SETFD, FD_CLOEXEC); --# else -- (void)fcntl(fd, F_SETFD, 1); --# endif --#endif --} -- --static inline void --set_cloexec_file(FILE *f) --{ -- return set_cloexec_fd(fileno(f)); --} --#else - /* Macros make the Sun compiler happier, and all variants of this do a - single evaluation of the argument, and fcntl and fileno should - produce reasonable error messages on type mismatches, on any system -@@ -881,9 +858,6 @@ set_cloexec_file(FILE *f) - # define set_cloexec_fd(FD) ((void)(FD)) - #endif - #define set_cloexec_file(F) set_cloexec_fd(fileno(F)) --#endif -- -- - - /* Since the original ANSI C spec left it undefined whether or - how you could copy around a va_list, C 99 added va_copy. -diff --git a/src/kadmin/dbutil/kdb5_util.c b/src/kadmin/dbutil/kdb5_util.c -index 000b5595c..4ff1cdf38 100644 ---- a/src/kadmin/dbutil/kdb5_util.c -+++ b/src/kadmin/dbutil/kdb5_util.c -@@ -358,44 +358,6 @@ int main(argc, argv) - return exit_status; - } - --#if 0 --/* -- * This function is no longer used in kdb5_util (and it would no -- * longer work, anyway). -- */ --void set_dbname(argc, argv) -- int argc; -- char *argv[]; --{ -- krb5_error_code retval; -- -- if (argc < 3) { -- com_err(argv[0], 0, _("Too few arguments")); -- com_err(progname, 0, _("Usage: %s dbpathname realmname"), argv[0]); -- exit_status++; -- return; -- } -- if (dbactive) { -- if ((retval = krb5_db_fini(util_context)) && retval!= KRB5_KDB_DBNOTINITED) { -- com_err(progname, retval, _("while closing previous database")); -- exit_status++; -- return; -- } -- if (valid_master_key) { -- krb5_free_keyblock_contents(util_context, &master_keyblock); -- master_keyblock.contents = NULL; -- valid_master_key = 0; -- } -- krb5_free_principal(util_context, master_princ); -- free(mkey_fullname); -- dbactive = FALSE; -- } -- -- (void) set_dbname_help(progname, argv[1]); -- return; --} --#endif -- - /* - * open_db_and_mkey: Opens the KDC and policy database, and sets the - * global master_* variables. Sets dbactive to TRUE if the databases -diff --git a/src/kadmin/server/ipropd_svc.c b/src/kadmin/server/ipropd_svc.c -index e6e190136..3228687c7 100644 ---- a/src/kadmin/server/ipropd_svc.c -+++ b/src/kadmin/server/ipropd_svc.c -@@ -621,32 +621,3 @@ krb5_iprop_prog_1(struct svc_req *rqstp, - } - - } -- --#if 0 --/* -- * Get the host base service name for the kiprop principal. Returns -- * KADM5_OK on success. Caller must free the storage allocated for -- * host_service_name. -- */ --kadm5_ret_t --kiprop_get_adm_host_srv_name(krb5_context context, -- const char *realm, -- char **host_service_name) --{ -- kadm5_ret_t ret; -- char *name; -- char *host; -- -- if (ret = kadm5_get_master(context, realm, &host)) -- return (ret); -- -- if (asprintf(&name, "%s@%s", KIPROP_SVC_NAME, host) < 0) { -- free(host); -- return (ENOMEM); -- } -- free(host); -- *host_service_name = name; -- -- return (KADM5_OK); --} --#endif -diff --git a/src/kdc/kdc_log.c b/src/kdc/kdc_log.c -index 7e8733980..4eec50373 100644 ---- a/src/kdc/kdc_log.c -+++ b/src/kdc/kdc_log.c -@@ -94,14 +94,6 @@ log_as_req(krb5_context context, - krb5_db_audit_as_req(context, request, - local_addr->address, remote_addr->address, - client, server, authtime, errcode); --#if 0 -- /* Sun (OpenSolaris) version would probably something like this. -- The client and server names passed can be null, unlike in the -- logging routines used above. Note that a struct in_addr is -- used, but the real address could be an IPv6 address. */ -- audit_krb5kdc_as_req(some in_addr *, (in_port_t)remote_addr->port, 0, -- cname, sname, errcode); --#endif - } - - /* -diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c -index 86b9e2991..811c16368 100644 ---- a/src/kdc/kdc_preauth.c -+++ b/src/kdc/kdc_preauth.c -@@ -712,19 +712,6 @@ const char *missing_required_preauth(krb5_db_entry *client, - krb5_db_entry *server, - krb5_enc_tkt_part *enc_tkt_reply) - { --#if 0 -- /* -- * If this is the pwchange service, and the pre-auth bit is set, -- * allow it even if the HW preauth would normally be required. -- * -- * Sandia national labs wanted this for some strange reason... we -- * leave it disabled normally. -- */ -- if (isflagset(server->attributes, KRB5_KDB_PWCHANGE_SERVICE) && -- isflagset(enc_tkt_reply->flags, TKT_FLG_PRE_AUTH)) -- return 0; --#endif -- - #ifdef DEBUG - krb5_klog_syslog ( - LOG_DEBUG, -diff --git a/src/lib/apputils/net-server.c b/src/lib/apputils/net-server.c -index a40da927e..54ee4c5c5 100644 ---- a/src/lib/apputils/net-server.c -+++ b/src/lib/apputils/net-server.c -@@ -1060,17 +1060,6 @@ process_packet(verto_ctx *ctx, verto_ev *ev) - return; - } - --#if 0 -- if (state->daddr_len > 0) { -- char addrbuf[100]; -- if (getnameinfo(ss2sa(&state->daddr), state->daddr_len, -- addrbuf, sizeof(addrbuf), -- 0, 0, NI_NUMERICHOST)) -- strlcpy(addrbuf, "?", sizeof(addrbuf)); -- com_err(conn->prog, 0, _("pktinfo says local addr is %s"), addrbuf); -- } --#endif -- - if (state->daddr_len == 0 && conn->type == CONN_UDP) { - /* - * An address couldn't be obtained, so the PKTINFO option probably -@@ -1116,11 +1105,6 @@ kill_lru_tcp_or_rpc_connection(void *handle, verto_ev *newev) - continue; - if (c->type != CONN_TCP && c->type != CONN_RPC) - continue; --#if 0 -- krb5_klog_syslog(LOG_INFO, "fd %d started at %ld", -- verto_get_fd(oldest_ev), -- c->start_time); --#endif - if (oldest_c == NULL - || oldest_c->start_time > c->start_time) { - oldest_ev = ev; -@@ -1186,10 +1170,6 @@ accept_tcp_connection(verto_ctx *ctx, verto_ev *ev) - strlcpy(p, tmpbuf, end - p); - } - } --#if 0 -- krb5_klog_syslog(LOG_INFO, "accepted TCP connection on socket %d from %s", -- s, newconn->addrbuf); --#endif - - newconn->addr_s = addr_s; - newconn->addrlen = addrlen; -@@ -1481,9 +1461,6 @@ accept_rpc_connection(verto_ctx *ctx, verto_ev *ev) - newconn = verto_get_private(newev); - - set_cloexec_fd(s); --#if 0 -- setnbio(s), setnolinger(s), setkeepalive(s); --#endif - - if (getpeername(s, addr, &addrlen) || - getnameinfo(addr, addrlen, -@@ -1503,10 +1480,6 @@ accept_rpc_connection(verto_ctx *ctx, verto_ev *ev) - strlcpy(p, tmpbuf, end - p); - } - } --#if 0 -- krb5_klog_syslog(LOG_INFO, _("accepted RPC connection on socket %d " -- "from %s"), s, newconn->addrbuf); --#endif - - newconn->addr_s = addr_s; - newconn->addrlen = addrlen; -diff --git a/src/lib/crypto/builtin/des/destest.c b/src/lib/crypto/builtin/des/destest.c -index dd2f68ec4..0d92b365b 100644 ---- a/src/lib/crypto/builtin/des/destest.c -+++ b/src/lib/crypto/builtin/des/destest.c -@@ -67,9 +67,6 @@ main(argc, argv) - char *argv[]; - { - char block1[17], block2[17], block3[17]; --#if 0 -- mit_des_cblock key, input, output, output2; --#else - /* Force tests of unaligned accesses. */ - union { unsigned char c[8*4+3]; long l; } u; - unsigned char *ioblocks = u.c; -@@ -77,7 +74,6 @@ main(argc, argv) - unsigned char *output = ioblocks+10; - unsigned char *output2 = ioblocks+19; - unsigned char *key = ioblocks+27; --#endif - mit_des_key_schedule sched; - int num = 0; - int retval; -diff --git a/src/lib/crypto/builtin/des/t_verify.c b/src/lib/crypto/builtin/des/t_verify.c -index 1f3239fed..f4332f5c0 100644 ---- a/src/lib/crypto/builtin/des/t_verify.c -+++ b/src/lib/crypto/builtin/des/t_verify.c -@@ -334,30 +334,6 @@ main(argc,argv) - exit(0); - } - --#if 0 --void --flip(array) -- char *array; --{ -- register int old,new,i,j; -- /* flips the bit order within each byte from 0 lsb to 0 msb */ -- for (i = 0; i<=7; i++) { -- old = *array; -- new = 0; -- for (j = 0; j<=7; j++) { -- if (old & 01) -- new = new | 01; -- if (j < 7) { -- old = old >> 1; -- new = new << 1; -- } -- } -- *array = new; -- array++; -- } --} --#endif -- - static void - do_encrypt(in,out) - unsigned char *in; -diff --git a/src/lib/crypto/builtin/pbkdf2.c b/src/lib/crypto/builtin/pbkdf2.c -index d36b32e7e..8905f2671 100644 ---- a/src/lib/crypto/builtin/pbkdf2.c -+++ b/src/lib/crypto/builtin/pbkdf2.c -@@ -102,11 +102,6 @@ F(char *output, char *u_tmp1, char *u_tmp2, - krb5_data out; - krb5_error_code err; - --#if 0 -- printf("F(i=%d, count=%lu, pass=%d:%s)\n", i, count, -- pass->length, pass->data); --#endif -- - /* Compute U_1. */ - store_32_be(i, ibytes); - -@@ -114,45 +109,25 @@ F(char *output, char *u_tmp1, char *u_tmp2, - memcpy(u_tmp2 + salt->length, ibytes, 4); - sdata = make_data(u_tmp2, salt->length + 4); - --#if 0 -- printd("initial salt", &sdata); --#endif -- - out = make_data(u_tmp1, hlen); - --#if 0 -- printf("F: computing hmac #1 (U_1) with %s\n", pdata.contents); --#endif - err = hmac(hash, pass, &sdata, &out); - if (err) - return err; --#if 0 -- printd("F: prf return value", &out); --#endif -+ - memcpy(output, u_tmp1, hlen); - - /* Compute U_2, .. U_c. */ - sdata.length = hlen; - for (j = 2; j <= count; j++) { --#if 0 -- printf("F: computing hmac #%d (U_%d)\n", j, j); --#endif - memcpy(u_tmp2, u_tmp1, hlen); - err = hmac(hash, pass, &sdata, &out); - if (err) - return err; --#if 0 -- printd("F: prf return value", &out); --#endif -+ - /* And xor them together. */ - for (k = 0; k < hlen; k++) - output[k] ^= u_tmp1[k]; --#if 0 -- printf("F: xor result:\n"); -- for (k = 0; k < hlen; k++) -- printf(" %02x", 0xff & output[k]); -- printf("\n"); --#endif - } - return 0; - } -@@ -185,9 +160,6 @@ pbkdf2(const struct krb5_hash_provider *hash, krb5_keyblock *pass, - - /* Step 3. */ - for (i = 1; i <= l; i++) { --#if 0 -- int j; --#endif - krb5_error_code err; - char *out; - -@@ -205,12 +177,6 @@ pbkdf2(const struct krb5_hash_provider *hash, krb5_keyblock *pass, - memcpy(output->data + (i-1) * hlen, utmp3, - output->length - (i-1) * hlen); - --#if 0 -- printf("after F(%d), @%p:\n", i, output->data); -- for (j = (i-1) * hlen; j < i * hlen; j++) -- printf(" %02x", 0xff & output->data[j]); -- printf ("\n"); --#endif - } - free(utmp1); - free(utmp2); -diff --git a/src/lib/crypto/builtin/sha1/t_shs.c b/src/lib/crypto/builtin/sha1/t_shs.c -index 08157b662..c1d18f557 100644 ---- a/src/lib/crypto/builtin/sha1/t_shs.c -+++ b/src/lib/crypto/builtin/sha1/t_shs.c -@@ -59,10 +59,6 @@ main() - { - SHS_INFO shsInfo; - unsigned int i; --#if 0 -- time_t secondCount; -- SHS_BYTE data[ 200 ]; --#endif - - /* Make sure we've got the endianness set right. If the machine is - big-endian (up to 64 bits) the following value will be signed, -@@ -120,17 +116,6 @@ main() - puts( "passed, result= 3232AFFA48628A26653B5AAA44541FD90D690603" ); - #endif /* NEW_SHS */ - --#if 0 -- printf( "\nTesting speed for 100MB data... " ); -- shsInit( &shsInfo ); -- secondCount = time( NULL ); -- for( i = 0; i < 500000U; i++ ) -- shsUpdate( &shsInfo, data, 200 ); -- secondCount = time( NULL ) - secondCount; -- printf( "done. Time = %ld seconds, %ld kbytes/second.\n", \ -- secondCount, 100500L / secondCount ); --#endif -- - puts( "\nAll SHS tests passed" ); - exit( 0 ); - } -diff --git a/src/lib/crypto/crypto_tests/t_cksums.c b/src/lib/crypto/crypto_tests/t_cksums.c -index 4b5406e67..5afc90ed8 100644 ---- a/src/lib/crypto/crypto_tests/t_cksums.c -+++ b/src/lib/crypto/crypto_tests/t_cksums.c -@@ -175,15 +175,11 @@ printhex(const char *head, void *data, size_t len) - - printf("%s", head); - for (i = 0; i < len; i++) { --#if 0 /* For convenience when updating test cases. */ -- printf("\\x%02X", ((unsigned char*)data)[i]); --#else - printf("%02X", ((unsigned char*)data)[i]); - if (i % 16 == 15 && i + 1 < len) - printf("\n%*s", (int)strlen(head), ""); - else if (i + 1 < len) - printf(" "); --#endif - } - printf("\n"); - } -diff --git a/src/lib/crypto/crypto_tests/t_crc.c b/src/lib/crypto/crypto_tests/t_crc.c -index 1a35cfba5..8cd1d36cb 100644 ---- a/src/lib/crypto/crypto_tests/t_crc.c -+++ b/src/lib/crypto/crypto_tests/t_crc.c -@@ -107,41 +107,9 @@ struct crc_trial trials[] = { - - #define NTRIALS (sizeof(trials) / sizeof(trials[0])) - --#if 0 --static void --timetest(unsigned int nblk, unsigned int blksiz) --{ -- char *block; -- unsigned int i; -- struct tms before, after; -- unsigned long cksum; - -- block = malloc(blksiz * nblk); -- if (block == NULL) -- exit(1); -- for (i = 0; i < blksiz * nblk; i++) -- block[i] = i % 256; -- times(&before); -- for (i = 0; i < nblk; i++) { -- cksum = 0; -- mit_crc32(block + i * blksiz, blksiz, &cksum); -- } -- -- times(&after); -- printf("shift-8 implementation, %d blocks of %d bytes:\n", -- nblk, blksiz); -- printf("\tu=%ld s=%ld cu=%ld cs=%ld\n", -- (long)(after.tms_utime - before.tms_utime), -- (long)(after.tms_stime - before.tms_stime), -- (long)(after.tms_cutime - before.tms_cutime), -- (long)(after.tms_cstime - before.tms_cstime)); -- -- free(block); --} --#endif -- --static void --verify(void) -+int -+main(void) - { - unsigned int i; - struct crc_trial trial; -@@ -176,14 +144,5 @@ verify(void) - (trial.sum == cksum) ? "OK" : "***BAD***", - typestr, trial.data, cksum); - } --} -- --int --main(void) --{ --#if 0 -- timetest(64*1024, 1024); --#endif -- verify(); - exit(0); - } -diff --git a/src/lib/crypto/crypto_tests/t_cts.c b/src/lib/crypto/crypto_tests/t_cts.c -index 2b022b4ac..fe505169f 100644 ---- a/src/lib/crypto/crypto_tests/t_cts.c -+++ b/src/lib/crypto/crypto_tests/t_cts.c -@@ -44,37 +44,10 @@ - - const char *whoami; - --#if 0 --static void printhex (size_t len, const char *p) --{ -- while (len--) -- printf ("%02x", 0xff & *p++); --} -- --static void printstringhex (const char *p) { printhex (strlen (p), p); } -- --static void printdata (krb5_data *d) { printhex (d->length, d->data); } -- --static void printkey (krb5_keyblock *k) { printhex (k->length, k->contents); } --#endif -- -- - #define JURISIC "Juri\305\241i\304\207" /* hi Miro */ - #define ESZETT "\303\237" - #define GCLEF "\360\235\204\236" /* outside BMP, woo hoo! */ - --#if 0 --static void --check_error (int r, int line) { -- if (r != 0) { -- fprintf (stderr, "%s:%d: %s\n", __FILE__, line, -- error_message (r)); -- exit (1); -- } --} --#define CHECK check_error(r, __LINE__) --#endif -- - static void printd (const char *descr, krb5_data *d) { - unsigned int i, j; - const int r = 16; -diff --git a/src/lib/crypto/crypto_tests/t_decrypt.c b/src/lib/crypto/crypto_tests/t_decrypt.c -index 1dbc4dd1b..4ae0256cc 100644 ---- a/src/lib/crypto/crypto_tests/t_decrypt.c -+++ b/src/lib/crypto/crypto_tests/t_decrypt.c -@@ -658,15 +658,11 @@ printhex(const char *head, void *data, size_t len) - - printf("%s", head); - for (i = 0; i < len; i++) { --#if 0 /* For convenience when updating test cases. */ -- printf("\\x%02X", ((unsigned char*)data)[i]); --#else - printf("%02X", ((unsigned char*)data)[i]); - if (i % 16 == 15 && i + 1 < len) - printf("\n%*s", (int)strlen(head), ""); - else if (i + 1 < len) - printf(" "); --#endif - } - printf("\n"); - } -diff --git a/src/lib/crypto/crypto_tests/t_derive.c b/src/lib/crypto/crypto_tests/t_derive.c -index 381ae4393..afbf7477f 100644 ---- a/src/lib/crypto/crypto_tests/t_derive.c -+++ b/src/lib/crypto/crypto_tests/t_derive.c -@@ -273,15 +273,11 @@ printhex(const char *head, void *data, size_t len) - - printf("%s", head); - for (i = 0; i < len; i++) { --#if 0 /* For convenience when updating test cases. */ -- printf("\\x%02X", ((unsigned char*)data)[i]); --#else - printf("%02X", ((unsigned char*)data)[i]); - if (i % 16 == 15 && i + 1 < len) - printf("\n%*s", (int)strlen(head), ""); - else if (i + 1 < len) - printf(" "); --#endif - } - printf("\n"); - } -diff --git a/src/lib/crypto/crypto_tests/t_hmac.c b/src/lib/crypto/crypto_tests/t_hmac.c -index 93d54828f..da359cb49 100644 ---- a/src/lib/crypto/crypto_tests/t_hmac.c -+++ b/src/lib/crypto/crypto_tests/t_hmac.c -@@ -46,17 +46,6 @@ static void keyToData (krb5_keyblock *k, krb5_data *d) { - d->data = (char *) k->contents; - } - --#if 0 --static void check_error (int r, int line) { -- if (r != 0) { -- fprintf (stderr, "%s:%d: %s\n", __FILE__, line, -- error_message (r)); -- exit (1); -- } --} --#define CHECK check_error(r, __LINE__) --#endif -- - static void printd (const char *descr, krb5_data *d) { - unsigned int i, j; - const int r = 16; -diff --git a/src/lib/crypto/crypto_tests/t_str2key.c b/src/lib/crypto/crypto_tests/t_str2key.c -index 7a7813874..27896e61e 100644 ---- a/src/lib/crypto/crypto_tests/t_str2key.c -+++ b/src/lib/crypto/crypto_tests/t_str2key.c -@@ -719,15 +719,11 @@ printhex(const char *head, void *data, size_t len) - - printf("%s", head); - for (i = 0; i < len; i++) { --#if 0 /* For convenience when updating test cases. */ -- printf("\\x%02X", ((unsigned char*)data)[i]); --#else - printf("%02X", ((unsigned char*)data)[i]); - if (i % 16 == 15 && i + 1 < len) - printf("\n%*s", (int)strlen(head), ""); - else if (i + 1 < len) - printf(" "); --#endif - } - printf("\n"); - } -diff --git a/src/lib/crypto/crypto_tests/vectors.c b/src/lib/crypto/crypto_tests/vectors.c -index 482d2de20..c1a765732 100644 ---- a/src/lib/crypto/crypto_tests/vectors.c -+++ b/src/lib/crypto/crypto_tests/vectors.c -@@ -448,11 +448,6 @@ int main (int argc, char **argv) - { - whoami = argv[0]; - test_nfold (); --#if 0 -- test_mit_des_s2k (); -- test_des3_s2k (); -- test_dr_dk (); --#endif - test_pbkdf2(); - return 0; - } -diff --git a/src/lib/crypto/krb/nfold.c b/src/lib/crypto/krb/nfold.c -index ea02fddcf..75bceaecd 100644 ---- a/src/lib/crypto/krb/nfold.c -+++ b/src/lib/crypto/krb/nfold.c -@@ -98,19 +98,9 @@ krb5int_nfold(unsigned int inbits, const unsigned char *in, unsigned int outbits - byte += out[i%outbits]; - out[i%outbits] = byte&0xff; - --#if 0 -- printf("msbit[%d] = %d\tbyte = %02x\tsum = %03x\n", i, msbit, -- (((in[((inbits-1)-(msbit>>3))%inbits]<<8)| -- (in[((inbits)-(msbit>>3))%inbits])) -- >>((msbit&7)+1))&0xff, byte); --#endif -- - /* keep around the carry bit, if any */ - byte >>= 8; - --#if 0 -- printf("carry=%d\n", byte); --#endif - } - - /* if there's a carry bit left over, add it back in */ -diff --git a/src/lib/gssapi/generic/util_set.c b/src/lib/gssapi/generic/util_set.c -index 8866f525f..432a9ee0d 100644 ---- a/src/lib/gssapi/generic/util_set.c -+++ b/src/lib/gssapi/generic/util_set.c -@@ -40,21 +40,6 @@ int g_set_init(g_set_elt *s) - return(0); - } - --#if 0 --int g_set_destroy(g_set_elt *s) --{ -- g_set next; -- -- while (*s) { -- next = (*s)->next; -- free(*s); -- *s = next; -- } -- -- return(0); --} --#endif -- - int g_set_entry_add(g_set_elt *s, void *key, void *value) - { - g_set_elt first; -diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index 06967aa27..5baa6cecf 100644 ---- a/src/lib/gssapi/krb5/accept_sec_context.c -+++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -654,17 +654,6 @@ kg_accept_krb5(minor_status, context_handle, - - krb5_auth_con_getauthenticator(context, auth_context, &authdat); - --#if 0 -- /* make sure the necessary parts of the authdat are present */ -- -- if ((authdat->authenticator->subkey == NULL) || -- (authdat->ticket->enc_part2 == NULL)) { -- code = KG_NO_SUBKEY; -- major_status = GSS_S_FAILURE; -- goto fail; -- } --#endif -- - if (authdat->checksum == NULL) { - /* - * Some SMB client implementations use handcrafted GSSAPI code that -diff --git a/src/lib/gssapi/krb5/gssapi_krb5.c b/src/lib/gssapi/krb5/gssapi_krb5.c -index 43930dd61..1eaf2bffb 100644 ---- a/src/lib/gssapi/krb5/gssapi_krb5.c -+++ b/src/lib/gssapi/krb5/gssapi_krb5.c -@@ -465,28 +465,12 @@ krb5_gss_inquire_cred_by_oid(OM_uint32 *minor_status, - return GSS_S_UNAVAILABLE; - } - --/* -- * gss_set_sec_context_option() methods -- * (Disabled until we have something to populate the array.) -- */ --#if 0 --static struct { -- gss_OID_desc oid; -- OM_uint32 (*func)(OM_uint32 *, gss_ctx_id_t *, const gss_OID, const gss_buffer_t); --} krb5_gss_set_sec_context_option_ops[] = { --}; --#endif -- - OM_uint32 KRB5_CALLCONV - krb5_gss_set_sec_context_option (OM_uint32 *minor_status, - gss_ctx_id_t *context_handle, - const gss_OID desired_object, - const gss_buffer_t value) - { --#if 0 -- size_t i; --#endif -- - if (minor_status == NULL) - return GSS_S_CALL_INACCESSIBLE_WRITE; - -@@ -498,18 +482,6 @@ krb5_gss_set_sec_context_option (OM_uint32 *minor_status, - if (desired_object == GSS_C_NO_OID) - return GSS_S_CALL_INACCESSIBLE_READ; - --#if 0 -- for (i = 0; i < sizeof(krb5_gss_set_sec_context_option_ops)/ -- sizeof(krb5_gss_set_sec_context_option_ops[0]); i++) { -- if (g_OID_prefix_equal(desired_object, &krb5_gss_set_sec_context_option_ops[i].oid)) { -- return (*krb5_gss_set_sec_context_option_ops[i].func)(minor_status, -- context_handle, -- desired_object, -- value); -- } -- } --#endif -- - *minor_status = EINVAL; - - return GSS_S_UNAVAILABLE; -diff --git a/src/lib/gssapi/krb5/naming_exts.c b/src/lib/gssapi/krb5/naming_exts.c -index 5f00efe34..41752d90b 100644 ---- a/src/lib/gssapi/krb5/naming_exts.c -+++ b/src/lib/gssapi/krb5/naming_exts.c -@@ -664,13 +664,3 @@ cleanup: - - return kg_map_name_error(minor_status, code); - } -- --#if 0 --OM_uint32 --krb5_gss_display_name_ext(OM_uint32 *minor_status, -- gss_name_t name, -- gss_OID display_as_name_type, -- gss_buffer_t display_name) --{ --} --#endif -diff --git a/src/lib/gssapi/mechglue/g_initialize.c b/src/lib/gssapi/mechglue/g_initialize.c -index 9197666e1..0ad11c0b0 100644 ---- a/src/lib/gssapi/mechglue/g_initialize.c -+++ b/src/lib/gssapi/mechglue/g_initialize.c -@@ -391,9 +391,6 @@ build_mechSet(void) - g_mechSet.count = count; - } - --#if 0 -- g_mechSetTime = fileInfo.st_mtime; --#endif - k5_mutex_unlock(&g_mechSetLock); - k5_mutex_unlock(&g_mechListLock); - -@@ -916,10 +913,6 @@ loadInterMech(gss_mech_info minfo) - - if (krb5int_open_plugin(minfo->uLibName, &dl, &errinfo) != 0 || - errinfo.code != 0) { --#if 0 -- (void) syslog(LOG_INFO, "libgss dlopen(%s): %s\n", -- aMech->uLibName, dlerror()); --#endif - return; - } - -@@ -959,12 +952,6 @@ loadInterMech(gss_mech_info minfo) - dl = NULL; - - cleanup: --#if 0 -- if (aMech->mech == NULL) { -- (void) syslog(LOG_INFO, "unable to initialize mechanism" -- " library [%s]\n", aMech->uLibName); -- } --#endif - if (dl != NULL) - krb5int_close_plugin(dl); - k5_clear_error(&errinfo); -@@ -1161,10 +1148,6 @@ gssint_get_mechanism(gss_const_OID oid) - - if (krb5int_open_plugin(aMech->uLibName, &dl, &errinfo) != 0 || - errinfo.code != 0) { --#if 0 -- (void) syslog(LOG_INFO, "libgss dlopen(%s): %s\n", -- aMech->uLibName, dlerror()); --#endif - k5_mutex_unlock(&g_mechListLock); - return ((gss_mechanism)NULL); - } -@@ -1180,10 +1163,6 @@ gssint_get_mechanism(gss_const_OID oid) - } - if (aMech->mech == NULL) { - (void) krb5int_close_plugin(dl); --#if 0 -- (void) syslog(LOG_INFO, "unable to initialize mechanism" -- " library [%s]\n", aMech->uLibName); --#endif - k5_mutex_unlock(&g_mechListLock); - return ((gss_mechanism)NULL); - } -@@ -1503,10 +1482,6 @@ addConfigEntry(const char *oidStr, const char *oid, const char *sharedLib, - oidBuf.length = strlen(oid); - if (generic_gss_str_to_oid(&minor, &oidBuf, &mechOid) - != GSS_S_COMPLETE) { --#if 0 -- (void) syslog(LOG_INFO, "invalid mechanism oid" -- " [%s] in configuration file", oid); --#endif - return; - } - -diff --git a/src/lib/gssapi/mechglue/g_inq_cred.c b/src/lib/gssapi/mechglue/g_inq_cred.c -index 911196264..cbe045ab9 100644 ---- a/src/lib/gssapi/mechglue/g_inq_cred.c -+++ b/src/lib/gssapi/mechglue/g_inq_cred.c -@@ -198,11 +198,6 @@ gss_inquire_cred_by_mech(minor_status, cred_handle, mech_type, name, - union_cred = (gss_union_cred_t) cred_handle; - mech_cred = gssint_get_mechanism_cred(union_cred, selected_mech); - --#if 0 -- if (mech_cred == NULL) -- return (GSS_S_DEFECTIVE_CREDENTIAL); --#endif -- - public_mech = gssint_get_public_oid(selected_mech); - status = mech->gss_inquire_cred_by_mech(minor_status, - mech_cred, public_mech, -diff --git a/src/lib/gssapi/mechglue/mglueP.h b/src/lib/gssapi/mechglue/mglueP.h -index 2b5145e07..2b00987e6 100644 ---- a/src/lib/gssapi/mechglue/mglueP.h -+++ b/src/lib/gssapi/mechglue/mglueP.h -@@ -730,11 +730,6 @@ typedef struct gss_mech_config { - /********************************************************/ - /* Internal mechglue routines */ - --#if 0 --int gssint_mechglue_init(void); --void gssint_mechglue_fini(void); --#endif -- - OM_uint32 gssint_select_mech_type(OM_uint32 *minor, gss_const_OID in_oid, - gss_OID *selected_oid); - gss_OID gssint_get_public_oid(gss_const_OID internal_oid); -diff --git a/src/lib/kadm5/clnt/client_init.c b/src/lib/kadm5/clnt/client_init.c -index 4350a9eb0..6f10db018 100644 ---- a/src/lib/kadm5/clnt/client_init.c -+++ b/src/lib/kadm5/clnt/client_init.c -@@ -161,7 +161,6 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, - generic_ret r = { 0, 0 }; - - initialize_ovk_error_table(); --/* initialize_adb_error_table(); */ - initialize_ovku_error_table(); - - if (! server_handle) { -@@ -612,53 +611,8 @@ setup_gss(kadm5_server_handle_t handle, kadm5_config_params *params_in, - gssstat = gss_acquire_cred(&minor_stat, gss_client, 0, - GSS_C_NULL_OID_SET, GSS_C_INITIATE, - &handle->cred, NULL, NULL); -- if (gssstat != GSS_S_COMPLETE) { --#if 0 /* for debugging only */ -- { -- OM_uint32 maj_status, min_status, message_context = 0; -- gss_buffer_desc status_string; -- do { -- maj_status = gss_display_status(&min_status, -- gssstat, -- GSS_C_GSS_CODE, -- GSS_C_NO_OID, -- &message_context, -- &status_string); -- if (maj_status == GSS_S_COMPLETE) { -- fprintf(stderr, "MAJ: %.*s\n", -- (int) status_string.length, -- (char *)status_string.value); -- gss_release_buffer(&min_status, &status_string); -- } else { -- fprintf(stderr, -- "MAJ? gss_display_status returns 0x%lx?!\n", -- (unsigned long) maj_status); -- message_context = 0; -- } -- } while (message_context != 0); -- do { -- maj_status = gss_display_status(&min_status, -- minor_stat, -- GSS_C_MECH_CODE, -- GSS_C_NO_OID, -- &message_context, -- &status_string); -- if (maj_status == GSS_S_COMPLETE) { -- fprintf(stderr, "MIN: %.*s\n", -- (int) status_string.length, -- (char *)status_string.value); -- gss_release_buffer(&min_status, &status_string); -- } else { -- fprintf(stderr, -- "MIN? gss_display_status returns 0x%lx?!\n", -- (unsigned long) maj_status); -- message_context = 0; -- } -- } while (message_context != 0); -- } --#endif -+ if (gssstat != GSS_S_COMPLETE) - goto error; -- } - - /* - * Do actual creation of RPC auth handle. Implements auth flavor -diff --git a/src/lib/kadm5/srv/server_init.c b/src/lib/kadm5/srv/server_init.c -index b3ae4ff5c..87a732292 100644 ---- a/src/lib/kadm5/srv/server_init.c -+++ b/src/lib/kadm5/srv/server_init.c -@@ -186,7 +186,6 @@ kadm5_ret_t kadm5_init(krb5_context context, char *client_name, char *pass, - handle->context = context; - - initialize_ovk_error_table(); --/* initialize_adb_error_table(); */ - initialize_ovku_error_table(); - - handle->magic_number = KADM5_SERVER_HANDLE_MAGIC; -@@ -207,16 +206,6 @@ kadm5_ret_t kadm5_init(krb5_context context, char *client_name, char *pass, - */ - memset(¶ms_local, 0, sizeof(params_local)); - --#if 0 /* Now that we look at krb5.conf as well as kdc.conf, we can -- expect to see admin_server being set sometimes. */ --#define ILLEGAL_PARAMS (KADM5_CONFIG_ADMIN_SERVER) -- if (params_in && (params_in->mask & ILLEGAL_PARAMS)) { -- free_db_args(handle); -- free(handle); -- return KADM5_BAD_SERVER_PARAMS; -- } --#endif -- - ret = kadm5_get_config_params(handle->context, 1, params_in, - &handle->params); - if (ret) { -diff --git a/src/lib/kadm5/unit-test/setkey-test.c b/src/lib/kadm5/unit-test/setkey-test.c -index 0431653bf..fa2392f81 100644 ---- a/src/lib/kadm5/unit-test/setkey-test.c -+++ b/src/lib/kadm5/unit-test/setkey-test.c -@@ -35,15 +35,6 @@ krb5_keyblock *tests[] = { - test1, test2, test3, NULL - }; - --#if 0 --int keyblocks_equal(krb5_keyblock *kb1, krb5_keyblock *kb2) --{ -- return (kb1->enctype == kb2->enctype && -- kb1->length == kb2->length && -- memcmp(kb1->contents, kb2->contents, kb1->length) == 0); --} --#endif -- - krb5_data tgtname = { - 0, - KRB5_TGS_NAME_SIZE, -diff --git a/src/lib/krb5/asn.1/ldap_key_seq.c b/src/lib/krb5/asn.1/ldap_key_seq.c -index 74569d9e2..f0be2d6d9 100644 ---- a/src/lib/krb5/asn.1/ldap_key_seq.c -+++ b/src/lib/krb5/asn.1/ldap_key_seq.c -@@ -96,9 +96,6 @@ no_salt(void *p) - DEFOPTIONALTYPE(key_data_salt_if_present, is_salt_present, no_salt, krbsalt); - DEFCTAGGEDTYPE(key_data_0, 0, key_data_salt_if_present); - DEFCTAGGEDTYPE(key_data_1, 1, encryptionkey); --#if 0 /* We don't support this field currently. */ --DEFCTAGGEDTYPE(key_data_2, 2, s2kparams), --#endif - static const struct atype_info *key_data_fields[] = { - &k5_atype_key_data_0, &k5_atype_key_data_1 - }; -diff --git a/src/lib/krb5/ccache/ccapi/stdcc.c b/src/lib/krb5/ccache/ccapi/stdcc.c -index 0256a0a5d..db69eebb4 100644 ---- a/src/lib/krb5/ccache/ccapi/stdcc.c -+++ b/src/lib/krb5/ccache/ccapi/stdcc.c -@@ -1300,14 +1300,6 @@ krb5_error_code KRB5_CALLCONV krb5_stdcc_initialize - return cc_err_xlate(err); - } - --#if 0 -- /* -- * Some implementations don't set the principal name -- * correctly, so we force set it to the correct value. -- */ -- err = cc_set_principal(gCntrlBlock, ccapi_data->NamedCache, -- CC_CRED_V5, cName); --#endif - krb5_free_unparsed_name(context, cName); - cache_changed(); - -@@ -1432,54 +1424,6 @@ krb5_error_code KRB5_CALLCONV krb5_stdcc_next_cred - * - * - try to find a matching credential in the cache - */ --#if 0 --krb5_error_code KRB5_CALLCONV krb5_stdcc_retrieve --(krb5_context context, -- krb5_ccache id, -- krb5_flags whichfields, -- krb5_creds *mcreds, -- krb5_creds *creds ) --{ -- krb5_error_code retval; -- krb5_cc_cursor curs = NULL; -- krb5_creds *fetchcreds; -- -- if ((retval = stdcc_setup(context, NULL))) -- return retval; -- -- fetchcreds = (krb5_creds *)malloc(sizeof(krb5_creds)); -- if (fetchcreds == NULL) return KRB5_CC_NOMEM; -- -- /* we're going to use the iterators */ -- krb5_stdcc_start_seq_get(context, id, &curs); -- -- while (!krb5_stdcc_next_cred(context, id, &curs, fetchcreds)) { -- /* -- * look at each credential for a match -- * use this match routine since it takes the -- * whichfields and the API doesn't -- */ -- if (stdccCredsMatch(context, fetchcreds, -- mcreds, whichfields)) { -- /* we found it, copy and exit */ -- *creds = *fetchcreds; -- krb5_stdcc_end_seq_get(context, id, &curs); -- return 0; -- } -- /* free copy allocated by next_cred */ -- krb5_free_cred_contents(context, fetchcreds); -- } -- -- /* no luck, end get and exit */ -- krb5_stdcc_end_seq_get(context, id, &curs); -- -- /* we're not using this anymore so we should get rid of it! */ -- free(fetchcreds); -- -- return KRB5_CC_NOTFOUND; --} --#else -- - krb5_error_code KRB5_CALLCONV - krb5_stdcc_retrieve(context, id, whichfields, mcreds, creds) - krb5_context context; -@@ -1492,8 +1436,6 @@ krb5_stdcc_retrieve(context, id, whichfields, mcreds, creds) - creds); - } - --#endif -- - /* - * end seq - * -diff --git a/src/lib/krb5/ccache/ccapi/winccld.h b/src/lib/krb5/ccache/ccapi/winccld.h -index 85017abbd..df34e3346 100644 ---- a/src/lib/krb5/ccache/ccapi/winccld.h -+++ b/src/lib/krb5/ccache/ccapi/winccld.h -@@ -85,24 +85,10 @@ DECL_FUNC_PTR(cc_create); - DECL_FUNC_PTR(cc_open); - DECL_FUNC_PTR(cc_close); - DECL_FUNC_PTR(cc_destroy); --#if 0 /* Not used */ --#ifdef CC_API_VER2 --DECL_FUNC_PTR(cc_seq_fetch_NCs_begin); --DECL_FUNC_PTR(cc_seq_fetch_NCs_next); --DECL_FUNC_PTR(cc_seq_fetch_NCs_end); --#else --DECL_FUNC_PTR(cc_seq_fetch_NCs); --#endif --DECL_FUNC_PTR(cc_get_NC_info); --DECL_FUNC_PTR(cc_free_NC_info); --#endif - DECL_FUNC_PTR(cc_get_name); - DECL_FUNC_PTR(cc_set_principal); - DECL_FUNC_PTR(cc_get_principal); - DECL_FUNC_PTR(cc_get_cred_version); --#if 0 /* Not used */ --DECL_FUNC_PTR(cc_lock_request); --#endif - DECL_FUNC_PTR(cc_store); - DECL_FUNC_PTR(cc_remove_cred); - #ifdef CC_API_VER2 -@@ -127,18 +113,10 @@ FUNC_INFO krbcc_fi[] = { - MAKE_FUNC_INFO(cc_open), - MAKE_FUNC_INFO(cc_close), - MAKE_FUNC_INFO(cc_destroy), --#if 0 /* Not used */ -- MAKE_FUNC_INFO(cc_seq_fetch_NCs), -- MAKE_FUNC_INFO(cc_get_NC_info), -- MAKE_FUNC_INFO(cc_free_NC_info), --#endif - MAKE_FUNC_INFO(cc_get_name), - MAKE_FUNC_INFO(cc_set_principal), - MAKE_FUNC_INFO(cc_get_principal), - MAKE_FUNC_INFO(cc_get_cred_version), --#if 0 /* Not used */ -- MAKE_FUNC_INFO(cc_lock_request), --#endif - MAKE_FUNC_INFO(cc_store), - MAKE_FUNC_INFO(cc_remove_cred), - #ifdef CC_API_VER2 -@@ -166,24 +144,10 @@ FUNC_INFO krbcc_fi[] = { - #define cc_open pcc_open - #define cc_close pcc_close - #define cc_destroy pcc_destroy --#if 0 /* Not used */ --#ifdef CC_API_VER2 --#define cc_seq_fetch_NCs_begin pcc_seq_fetch_NCs_begin --#define cc_seq_fetch_NCs_next pcc_seq_fetch_NCs_next --#define cc_seq_fetch_NCs_end pcc_seq_fetch_NCs_end --#else --#define cc_seq_fetch_NCs pcc_seq_fetch_NCs --#endif --#define cc_get_NC_info pcc_get_NC_info --#define cc_free_NC_info pcc_free_NC_info --#endif /* End of Not used */ - #define cc_get_name pcc_get_name - #define cc_set_principal pcc_set_principal - #define cc_get_principal pcc_get_principal - #define cc_get_cred_version pcc_get_cred_version --#if 0 /* Not used */ --#define cc_lock_request pcc_lock_request --#endif - #define cc_store pcc_store - #define cc_remove_cred pcc_remove_cred - #ifdef CC_API_VER2 -diff --git a/src/lib/krb5/keytab/t_keytab.c b/src/lib/krb5/keytab/t_keytab.c -index 80a94eafe..c845596d6 100644 ---- a/src/lib/krb5/keytab/t_keytab.c -+++ b/src/lib/krb5/keytab/t_keytab.c -@@ -441,16 +441,3 @@ main(void) - return 0; - - } -- -- --#if 0 --/* remove and add are functions, so that they can return NOWRITE -- if not a writable keytab */ --krb5_error_code KRB5_CALLCONV krb5_kt_remove_entry --(krb5_context, -- krb5_keytab, -- krb5_keytab_entry * ); -- -- -- --#endif -diff --git a/src/lib/krb5/krb/gc_via_tkt.c b/src/lib/krb5/krb/gc_via_tkt.c -index 5b9bb9573..e7a3b01f8 100644 ---- a/src/lib/krb5/krb/gc_via_tkt.c -+++ b/src/lib/krb5/krb/gc_via_tkt.c -@@ -131,17 +131,6 @@ check_reply_server(krb5_context context, krb5_flags kdcoptions, - /* Canonicalization not requested, and not a TGS referral. */ - return KRB5_KDCREP_MODIFIED; - } --#if 0 -- /* -- * Is this check needed? find_nxt_kdc() in gc_frm_kdc.c already -- * effectively checks this. -- */ -- if (krb5_realm_compare(context, in_cred->client, in_cred->server) && -- data_eq(*in_cred->server->data[1], *in_cred->client->realm)) { -- /* Attempted to rewrite local TGS. */ -- return KRB5_KDCREP_MODIFIED; -- } --#endif - return 0; - } - -diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index 4246c5dd2..c90b2af87 100644 ---- a/src/lib/krb5/krb/init_ctx.c -+++ b/src/lib/krb5/krb/init_ctx.c -@@ -232,13 +232,6 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, - get_integer(ctx, KRB5_CONF_CLOCKSKEW, DEFAULT_CLOCKSKEW, &tmp); - ctx->clockskew = tmp; - --#if 0 -- /* Default ticket lifetime is currently not supported */ -- profile_get_integer(ctx->profile, KRB5_CONF_LIBDEFAULTS, "tkt_lifetime", -- 0, 10 * 60 * 60, &tmp); -- ctx->tkt_lifetime = tmp; --#endif -- - /* DCE 1.1 and below only support CKSUMTYPE_RSA_MD4 (2) */ - /* DCE add kdc_req_checksum_type = 2 to krb5.conf */ - get_integer(ctx, KRB5_CONF_KDC_REQ_CHECKSUM_TYPE, CKSUMTYPE_RSA_MD5, -diff --git a/src/lib/krb5/krb/rd_req_dec.c b/src/lib/krb5/krb/rd_req_dec.c -index 6defbdbf0..4cd429a11 100644 ---- a/src/lib/krb5/krb/rd_req_dec.c -+++ b/src/lib/krb5/krb/rd_req_dec.c -@@ -441,30 +441,6 @@ decrypt_ticket(krb5_context context, const krb5_ap_req *req, - #endif /* LEAN_CLIENT */ - } - --#if 0 --#include --static void --debug_log_authz_data(const char *which, krb5_authdata **a) --{ -- if (a) { -- syslog(LOG_ERR|LOG_DAEMON, "%s authz data:", which); -- while (*a) { -- syslog(LOG_ERR|LOG_DAEMON, " ad_type:%d length:%d '%.*s'", -- (*a)->ad_type, (*a)->length, (*a)->length, -- (char *) (*a)->contents); -- a++; -- } -- syslog(LOG_ERR|LOG_DAEMON, " [end]"); -- } else -- syslog(LOG_ERR|LOG_DAEMON, "no %s authz data", which); --} --#else --static void --debug_log_authz_data(const char *which, krb5_authdata **a) --{ --} --#endif -- - static krb5_error_code - rd_req_decoded_opt(krb5_context context, krb5_auth_context *auth_context, - const krb5_ap_req *req, krb5_const_principal server, -@@ -759,8 +735,6 @@ rd_req_decoded_opt(krb5_context context, krb5_auth_context *auth_context, - &((*auth_context)->key)))) - goto cleanup; - -- debug_log_authz_data("ticket", req->ticket->enc_part2->authorization_data); -- - /* - * If not AP_OPTS_MUTUAL_REQUIRED then and sequence numbers are used - * then the default sequence number is the one's complement of the -@@ -855,10 +829,9 @@ decrypt_authenticator(krb5_context context, const krb5_ap_req *request, - free(scratch.data);} - - /* now decode the decrypted stuff */ -- if (!(retval = decode_krb5_authenticator(&scratch, &local_auth))) { -+ if (!(retval = decode_krb5_authenticator(&scratch, &local_auth))) - *authpp = local_auth; -- debug_log_authz_data("authenticator", local_auth->authorization_data); -- } -+ - clean_scratch(); - return retval; - } -diff --git a/src/lib/krb5/krb/t_ser.c b/src/lib/krb5/krb/t_ser.c -index 9cdf5e641..1d6cceaa2 100644 ---- a/src/lib/krb5/krb/t_ser.c -+++ b/src/lib/krb5/krb/t_ser.c -@@ -151,10 +151,6 @@ ser_data(int verbose, char *msg, krb5_pointer ctx, krb5_magic dtype) - krb5_encrypt_block *eblock; - - eblock = (krb5_encrypt_block *) nctx; --#if 0 -- if (eblock->priv && eblock->priv_size) -- free(eblock->priv); --#endif - if (eblock->key) - krb5_free_keyblock(ser_ctx, eblock->key); - free(eblock); -@@ -450,60 +446,6 @@ ser_rcache_test(krb5_context kcontext, int verbose) - return(kret); - } - --#if 0 --/* -- * Serialize krb5_encrypt_block. -- */ --static krb5_error_code --ser_eblock_test(kcontext, verbose) -- krb5_context kcontext; -- int verbose; --{ -- krb5_error_code kret; -- krb5_encrypt_block eblock; -- krb5_keyblock ukeyblock; -- krb5_octet keydata[8]; -- -- memset(&eblock, 0, sizeof(krb5_encrypt_block)); -- eblock.magic = KV5M_ENCRYPT_BLOCK; -- krb5_use_enctype(kcontext, &eblock, DEFAULT_KDC_ENCTYPE); -- if (!(kret = ser_data(verbose, "> NULL eblock", -- (krb5_pointer) &eblock, KV5M_ENCRYPT_BLOCK))) { --#if 0 -- eblock.priv = (krb5_pointer) stuff; -- eblock.priv_size = 8; --#endif -- if (!(kret = ser_data(verbose, "> eblock with private data", -- (krb5_pointer) &eblock, -- KV5M_ENCRYPT_BLOCK))) { -- memset(&ukeyblock, 0, sizeof(ukeyblock)); -- memset(keydata, 0, sizeof(keydata)); -- ukeyblock.enctype = ENCTYPE_DES_CBC_MD5; -- ukeyblock.length = sizeof(keydata); -- ukeyblock.contents = keydata; -- keydata[0] = 0xde; -- keydata[1] = 0xad; -- keydata[2] = 0xbe; -- keydata[3] = 0xef; -- keydata[4] = 0xfe; -- keydata[5] = 0xed; -- keydata[6] = 0xf0; -- keydata[7] = 0xd; -- eblock.key = &ukeyblock; -- if (!(kret = ser_data(verbose, "> eblock with private key", -- (krb5_pointer) &eblock, -- KV5M_ENCRYPT_BLOCK))) { -- if (verbose) -- printf("* eblock test succeeded\n"); -- } -- } -- } -- if (kret) -- printf("* eblock test failed\n"); -- return(kret); --} --#endif -- - /* - * Serialize krb5_principal - */ -@@ -584,7 +526,7 @@ main(int argc, char **argv) - do_ptest = 1; - do_rtest = 1; - do_stest = 1; -- while ((option = getopt(argc, argv, "acekprsxvACEKPRSX")) != -1) { -+ while ((option = getopt(argc, argv, "acekprsxvACKPRSX")) != -1) { - switch (option) { - case 'a': - do_atest = 0; -@@ -619,11 +561,6 @@ main(int argc, char **argv) - case 'C': - do_ctest = 1; - break; --#if 0 -- case 'E': -- do_etest = 1; -- break; --#endif - case 'K': - do_ktest = 1; - break; -@@ -641,7 +578,7 @@ main(int argc, char **argv) - break; - default: - fprintf(stderr, -- "%s: usage is %s [-acekprsxvACEKPRSX]\n", -+ "%s: usage is %s [-acekprsxvACKPRSX]\n", - argv[0], argv[0]); - exit(1); - break; -@@ -682,14 +619,6 @@ main(int argc, char **argv) - if (kret) - goto fail; - } --#if 0 /* code to be tested is currently disabled */ -- if (do_etest) { -- ch_err = 'e'; -- kret = ser_eblock_test(kcontext, verbose); -- if (kret) -- goto fail; -- } --#endif - if (do_ptest) { - ch_err = 'p'; - kret = ser_princ_test(kcontext, verbose); -diff --git a/src/lib/krb5/krb/unparse.c b/src/lib/krb5/krb/unparse.c -index 5bb64d00a..d94aa3cfa 100644 ---- a/src/lib/krb5/krb/unparse.c -+++ b/src/lib/krb5/krb/unparse.c -@@ -122,13 +122,6 @@ copy_component_quoting(char *dest, const krb5_data *src, int flags) - *q++ = '\\'; - *q++ = 'b'; - break; --#if 0 -- /* Heimdal escapes spaces in principal names upon unparsing */ -- case ' ': -- *q++ = '\\'; -- *q++ = ' '; -- break; --#endif - case '\0': - *q++ = '\\'; - *q++ = '0'; -diff --git a/src/lib/krb5/os/localaddr.c b/src/lib/krb5/os/localaddr.c -index 58443f6e3..92d765f4b 100644 ---- a/src/lib/krb5/os/localaddr.c -+++ b/src/lib/krb5/os/localaddr.c -@@ -392,20 +392,6 @@ get_linux_ipv6_addrs () - a6.s6_addr[i] = addrbyte[i]; - if (scope != 0) - continue; --#if 0 /* These symbol names are as used by ifconfig, but none of the -- system header files export them. Dig up the kernel versions -- someday and see if they're exported. */ -- switch (scope) { -- case 0: -- default: -- break; -- case IPV6_ADDR_LINKLOCAL: -- case IPV6_ADDR_SITELOCAL: -- case IPV6_ADDR_COMPATv4: -- case IPV6_ADDR_LOOPBACK: -- continue; -- } --#endif - nw = calloc (1, sizeof (struct linux_ipv6_addr_list)); - if (nw == 0) - continue; -@@ -1331,14 +1317,6 @@ krb5_os_localaddr(krb5_context context, krb5_address ***addr) - return get_localaddrs(context, addr, 1); - } - --#if 0 /* not actually used anywhere currently */ --krb5_error_code --krb5int_local_addresses(krb5_context context, krb5_address ***addr) --{ -- return get_localaddrs(context, addr, 0); --} --#endif -- - static krb5_error_code - get_localaddrs (krb5_context context, krb5_address ***addr, int use_profile) - { -diff --git a/src/lib/krb5/rcache/rc_io.c b/src/lib/krb5/rcache/rc_io.c -index b9859fe9f..35fa14a1f 100644 ---- a/src/lib/krb5/rcache/rc_io.c -+++ b/src/lib/krb5/rcache/rc_io.c -@@ -117,10 +117,6 @@ krb5_rc_io_mkstemp(krb5_context context, krb5_rc_iostuff *d, char *dir) - return 0; - } - --#if 0 --static krb5_error_code rc_map_errno (int) __attribute__((cold)); --#endif -- - static krb5_error_code - rc_map_errno (krb5_context context, int e, const char *fn, - const char *operation) -diff --git a/src/lib/rpc/auth_gssapi.c b/src/lib/rpc/auth_gssapi.c -index ace0be925..568ec6d87 100644 ---- a/src/lib/rpc/auth_gssapi.c -+++ b/src/lib/rpc/auth_gssapi.c -@@ -744,14 +744,6 @@ skip_call: - } - - free(AUTH_PRIVATE(auth)->client_handle.value); -- --#if 0 -- PRINTF(("gssapi_destroy: calling GSSAPI_EXIT\n")); -- AUTH_PRIVATE(auth)->established = FALSE; -- callstat = clnt_call(AUTH_PRIVATE(auth)->clnt, AUTH_GSSAPI_EXIT, -- xdr_void, NULL, xdr_void, NULL, timeout); --#endif -- - free(auth->ah_private); - free(auth); - PRINTF(("gssapi_destroy: done\n")); -diff --git a/src/lib/rpc/svc_auth.c b/src/lib/rpc/svc_auth.c -index 5fedef7d7..e0f80af0b 100644 ---- a/src/lib/rpc/svc_auth.c -+++ b/src/lib/rpc/svc_auth.c -@@ -59,9 +59,6 @@ static struct svcauthsw_type { - } svcauthsw[] = { - {AUTH_GSSAPI, gssrpc__svcauth_gssapi}, /* AUTH_GSSAPI */ - {AUTH_NONE, gssrpc__svcauth_none}, /* AUTH_NONE */ --#if 0 -- {AUTH_GSSAPI_COMPAT, gssrpc__svcauth_gssapi}, /* AUTH_GSSAPI_COMPAT */ --#endif - {AUTH_UNIX, gssrpc__svcauth_unix}, /* AUTH_UNIX */ - {AUTH_SHORT, gssrpc__svcauth_short}, /* AUTH_SHORT */ - {RPCSEC_GSS, gssrpc__svcauth_gss} /* RPCSEC_GSS */ -diff --git a/src/lib/rpc/svc_auth_gssapi.c b/src/lib/rpc/svc_auth_gssapi.c -index f3b3e35b8..384bdc336 100644 ---- a/src/lib/rpc/svc_auth_gssapi.c -+++ b/src/lib/rpc/svc_auth_gssapi.c -@@ -869,10 +869,6 @@ done: - L_PRINTF(2, ("destroy_client: client %d destroyed\n", client_data->key)); - - free(client_data); -- --#if 0 /*ifdef PURIFY*/ -- purify_watch_n(client_data, sizeof(*client_data), "rw"); --#endif - } - - static void dump_db(char *msg) -diff --git a/src/lib/win_glue.c b/src/lib/win_glue.c -index 3d6dd7206..e149a1226 100644 ---- a/src/lib/win_glue.c -+++ b/src/lib/win_glue.c -@@ -111,10 +111,6 @@ void GetCallingAppVerInfo( char *AppTitle, char *AppVer, char *AppIni, - * hey , I bet we don't have a version resource, let's - * punt - */ --#if 0 -- /* let's see what we have? (1813 means no resource) */ -- size = GetLastError(); /* WIN32 only */ --#endif - *VSflag = FALSE; - return; - } -@@ -291,11 +287,6 @@ krb5_error_code krb5_vercheck() - return retval; - #endif - #ifdef VERSERV --#if 0 -- /* Check library ? */ -- if (CallVersionServer(APP_TITLE, APP_VER, APP_INI, NULL)) -- return KRB5_LIB_EXPIRED; --#endif - { - #ifdef APP_TITLE - if (CallVersionServer(APP_TITLE, APP_VER, APP_INI, NULL)) -diff --git a/src/plugins/kdb/db2/lockout.c b/src/plugins/kdb/db2/lockout.c -index 3a4f41821..30fb554db 100644 ---- a/src/plugins/kdb/db2/lockout.c -+++ b/src/plugins/kdb/db2/lockout.c -@@ -157,10 +157,6 @@ krb5_db2_lockout_audit(krb5_context context, - case KRB5KDC_ERR_PREAUTH_FAILED: - case KRB5KRB_AP_ERR_BAD_INTEGRITY: - break; --#if 0 -- case KRB5KDC_ERR_CLIENT_REVOKED: -- break; --#endif - default: - return 0; - } -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c -index 28dffe0c2..f6d00be9f 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c -@@ -777,9 +777,6 @@ krb5_ldap_read_realm_params(krb5_context context, char *lrealm, - ent = ldap_first_entry (ld, result); - if (ent == NULL) { - ldap_get_option (ld, LDAP_OPT_ERROR_NUMBER, (void *) &st); --#if 0 -- st = translate_ldap_error(st, OP_SEARCH); --#endif - goto cleanup; - } - -diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c -index 77e9e5308..238101762 100644 ---- a/src/plugins/preauth/pkinit/pkinit_clnt.c -+++ b/src/plugins/preauth/pkinit/pkinit_clnt.c -@@ -507,24 +507,6 @@ verify_kdc_san(krb5_context context, - for (hostptr = certhosts; *hostptr != NULL; hostptr++) - TRACE_PKINIT_CLIENT_SAN_KDCCERT_DNSNAME(context, *hostptr); - } --#if 0 -- retval = call_san_checking_plugins(context, plgctx, reqctx, idctx, -- princs, hosts, &plugin_decision, -- need_eku_checking); -- pkiDebug("%s: call_san_checking_plugins() returned retval %d\n", -- __FUNCTION__); -- if (retval) { -- retval = KRB5KDC_ERR_KDC_NAME_MISMATCH; -- goto out; -- } -- pkiDebug("%s: call_san_checking_plugins() returned decision %d and " -- "need_eku_checking %d\n", -- __FUNCTION__, plugin_decision, *need_eku_checking); -- if (plugin_decision != NO_DECISION) { -- retval = plugin_decision; -- goto out; -- } --#endif - - pkiDebug("%s: Checking pkinit sans\n", __FUNCTION__); - for (i = 0; princs != NULL && princs[i] != NULL; i++) { -diff --git a/src/plugins/preauth/pkinit/pkinit_matching.c b/src/plugins/preauth/pkinit/pkinit_matching.c -index c2a4c084d..afcce3f8b 100644 ---- a/src/plugins/preauth/pkinit/pkinit_matching.c -+++ b/src/plugins/preauth/pkinit/pkinit_matching.c -@@ -572,17 +572,6 @@ check_all_certs(krb5_context context, - */ - for (i = 0, md = matchdata[i]; md != NULL; md = matchdata[++i]) { - pkiDebug("%s: subject: '%s'\n", __FUNCTION__, md->subject_dn); --#if 0 -- pkiDebug("%s: issuer: '%s'\n", __FUNCTION__, md->subject_dn); -- for (j = 0; md->sans != NULL && md->sans[j] != NULL; j++) { -- char *san_string; -- krb5_unparse_name(context, md->sans[j], &san_string); -- pkiDebug("%s: PKINIT san: '%s'\n", __FUNCTION__, san_string); -- krb5_free_unparsed_name(context, san_string); -- } -- for (j = 0; md->upns != NULL && md->upns[j] != NULL; j++) -- pkiDebug("%s: UPN san: '%s'\n", __FUNCTION__, md->upns[j]); --#endif - certs_checked++; - for (rc = rs->crs; rc != NULL; rc = rc->next) { - comp_match = component_match(context, rc, md); -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index 76ad5bf19..27e6ef4d2 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -204,24 +204,6 @@ verify_client_san(krb5_context context, - goto out; - } - -- /* XXX Verify this is consistent with client side XXX */ --#if 0 -- retval = call_san_checking_plugins(context, plgctx, reqctx, princs, -- upns, NULL, &plugin_decision, &ignore); -- pkiDebug("%s: call_san_checking_plugins() returned retval %d\n", -- __FUNCTION__); -- if (retval) { -- retval = KRB5KDC_ERR_CLIENT_NAME_MISMATCH; -- goto cleanup; -- } -- pkiDebug("%s: call_san_checking_plugins() returned decision %d\n", -- __FUNCTION__, plugin_decision); -- if (plugin_decision != NO_DECISION) { -- retval = plugin_decision; -- goto out; -- } --#endif -- - #ifdef DEBUG_SAN_INFO - krb5_unparse_name(context, client, &client_string); - #endif -diff --git a/src/tests/asn.1/krb5_decode_leak.c b/src/tests/asn.1/krb5_decode_leak.c -index 22601c7bf..77fd3ee40 100644 ---- a/src/tests/asn.1/krb5_decode_leak.c -+++ b/src/tests/asn.1/krb5_decode_leak.c -@@ -633,18 +633,6 @@ main(int argc, char **argv) - krb5_free_ad_kdcissued); - ktest_empty_ad_kdcissued(&kdci); - } --#if 0 -- /****************************************************************/ -- /* encode_krb5_ad_signedpath_data */ -- { -- krb5_ad_signedpath_data spd, *tmp; -- ktest_make_sample_ad_signedpath_data(&spd); -- leak_test(spd, encode_krb5_ad_signedpath_data, -- decode_krb5_ad_signedpath_data, -- NULL); -- ktest_empty_ad_signedpath_data(&spd); -- } --#endif - /****************************************************************/ - /* encode_krb5_ad_signedpath */ - { -diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp -index 2d1686c56..daf3c7d3b 100644 ---- a/src/tests/dejagnu/config/default.exp -+++ b/src/tests/dejagnu/config/default.exp -@@ -32,26 +32,6 @@ set tgt_support_desmd5 0 - # request a des-cbc-md4 session key. Since only des-cbc-crc is in the - # KDC's permitted_enctypes list, the TGT will be unusable. - --# KLUDGE for tracking down leaking ptys --if 0 { -- rename spawn oldspawn -- rename wait oldwait -- proc spawn { args } { -- upvar 1 spawn_id spawn_id -- verbose "spawn: args=$args" -- set pid [eval oldspawn $args] -- verbose "spawn: pid=$pid spawn_id=$spawn_id" -- return $pid -- } -- proc wait { args } { -- upvar 1 spawn_id spawn_id -- verbose "wait: args=$args" -- set ret [eval oldwait $args] -- verbose "wait: $ret" -- return $ret -- } --} -- - if { [string length $VALGRIND] } { - rename spawn valgrind_aux_spawn - proc spawn { args } { -diff --git a/src/tests/shlib/t_loader.c b/src/tests/shlib/t_loader.c -index 869be800a..29481a7be 100644 ---- a/src/tests/shlib/t_loader.c -+++ b/src/tests/shlib/t_loader.c -@@ -186,18 +186,6 @@ int main() - - (void) setvbuf(stdout, 0, _IONBF, 0); - --#if 0 -- /* Simplest test: Load, then unload out of order. */ -- celib = do_open("com_err", "3.0", 0); -- k5lib = do_open("krb5", "3.2", 0); -- gsslib = do_open("gssapi_krb5", "2.2", 0); -- celib2 = do_open("com_err", "3.0", 0); -- do_close(celib); -- do_close(k5lib); -- do_close(celib2); -- do_close(gsslib); --#endif -- - celib = do_open("com_err", "3.0", 0); - k5lib = do_open("krb5", "3.2", 0); - gsslib = do_open("gssapi_krb5", "2.2", 0); -diff --git a/src/tests/threads/t_rcache.c b/src/tests/threads/t_rcache.c -index d6187f061..9d9b1acd3 100644 ---- a/src/tests/threads/t_rcache.c -+++ b/src/tests/threads/t_rcache.c -@@ -106,7 +106,6 @@ static void try_one (struct tinfo *t) - static void *run_a_loop (void *x) - { - struct tinfo t = { 0 }; --/* int chr = "ABCDEFGHIJKLMNOPQRSTUVWXYZ_"[(*(int*)x) % 27]; */ - - t.now = time(0); - t.idx = *(int *)x; -@@ -117,12 +116,7 @@ static void *run_a_loop (void *x) - t.now = time(0); - try_one(&t); - t.total++; --#if 0 -- printf("%c", chr); -- fflush(stdout); --#endif - } --/* printf("thread %u total %u\n", (unsigned) ((int *)x-ip), t.total);*/ - *(int*)x = t.total; - return 0; - } -diff --git a/src/util/profile/prof_file.c b/src/util/profile/prof_file.c -index 0f5462aea..64b32dbf1 100644 ---- a/src/util/profile/prof_file.c -+++ b/src/util/profile/prof_file.c -@@ -79,39 +79,6 @@ void profile_library_finalizer(void) - - static void profile_free_file_data(prf_data_t); - --#if 0 -- --#define scan_shared_trees_locked() \ -- { \ -- prf_data_t d; \ -- k5_mutex_assert_locked(&g_shared_trees_mutex); \ -- for (d = g_shared_trees; d; d = d->next) { \ -- assert(d->magic == PROF_MAGIC_FILE_DATA); \ -- assert((d->flags & PROFILE_FILE_SHARED) != 0); \ -- assert(d->filespec[0] != 0); \ -- assert(d->fslen <= 1000); /* XXX */ \ -- assert(d->filespec[d->fslen] == 0); \ -- assert(d->fslen = strlen(d->filespec)); \ -- assert(d->root != NULL); \ -- } \ -- } -- --#define scan_shared_trees_unlocked() \ -- { \ -- int r; \ -- r = k5_mutex_lock(&g_shared_trees_mutex); \ -- assert (r == 0); \ -- scan_shared_trees_locked(); \ -- k5_mutex_unlock(&g_shared_trees_mutex); \ -- } -- --#else -- --#define scan_shared_trees_locked() { ; } --#define scan_shared_trees_unlocked() { ; } -- --#endif -- - static int rw_access(const_profile_filespec_t filespec) - { - #ifdef HAVE_ACCESS -@@ -209,8 +176,6 @@ errcode_t profile_open_file(const_profile_filespec_t filespec, - if (retval) - return retval; - -- scan_shared_trees_unlocked(); -- - prf = malloc(sizeof(struct _prf_file_t)); - if (!prf) - return ENOMEM; -@@ -244,7 +209,6 @@ errcode_t profile_open_file(const_profile_filespec_t filespec, - } - - k5_mutex_lock(&g_shared_trees_mutex); -- scan_shared_trees_locked(); - for (data = g_shared_trees; data; data = data->next) { - if (!strcmp(data->filespec, expanded_filename) - /* Check that current uid has read access. */ -@@ -264,7 +228,6 @@ errcode_t profile_open_file(const_profile_filespec_t filespec, - } - prf->data = data; - *ret_prof = prf; -- scan_shared_trees_unlocked(); - return 0; - } - k5_mutex_unlock(&g_shared_trees_mutex); -@@ -291,11 +254,9 @@ errcode_t profile_open_file(const_profile_filespec_t filespec, - } - - k5_mutex_lock(&g_shared_trees_mutex); -- scan_shared_trees_locked(); - data->flags |= PROFILE_FILE_SHARED; - data->next = g_shared_trees; - g_shared_trees = data; -- scan_shared_trees_locked(); - k5_mutex_unlock(&g_shared_trees_mutex); - - *ret_prof = prf; -@@ -537,11 +498,9 @@ void profile_dereference_data(prf_data_t data) - } - void profile_dereference_data_locked(prf_data_t data) - { -- scan_shared_trees_locked(); - data->refcount--; - if (data->refcount == 0) - profile_free_file_data(data); -- scan_shared_trees_locked(); - } - - void profile_lock_global() -@@ -562,7 +521,6 @@ void profile_free_file(prf_file_t prf) - /* Call with mutex locked! */ - static void profile_free_file_data(prf_data_t data) - { -- scan_shared_trees_locked(); - if (data->flags & PROFILE_FILE_SHARED) { - /* Remove from linked list. */ - if (g_shared_trees == data) -@@ -586,7 +544,6 @@ static void profile_free_file_data(prf_data_t data) - data->magic = 0; - k5_mutex_destroy(&data->lock); - free(data); -- scan_shared_trees_locked(); - } - - errcode_t profile_close_file(prf_file_t prf) -diff --git a/src/util/support/fake-addrinfo.c b/src/util/support/fake-addrinfo.c -index 3ee162e0d..0fb35cf15 100644 ---- a/src/util/support/fake-addrinfo.c -+++ b/src/util/support/fake-addrinfo.c -@@ -888,16 +888,10 @@ fake_getaddrinfo (const char *name, const char *serv, - If it's not set, don't accept such names. */ - if (flags & AI_NUMERICHOST) { - struct in_addr addr4; --#if 0 -- ret = inet_aton (name, &addr4); -- if (ret) -- return EAI_NONAME; --#else - addr4.s_addr = inet_addr (name); - if (addr4.s_addr == 0xffffffff || addr4.s_addr == -1) - /* 255.255.255.255 or parse error, both bad */ - return EAI_NONAME; --#endif - ret = fai_add_entry (&res, &addr4, port, &template); - } else { - ret = fai_add_hosts_by_name (name, &template, port, flags, -diff --git a/src/util/support/utf8.c b/src/util/support/utf8.c -index 34e2b6adb..ea8818116 100644 ---- a/src/util/support/utf8.c -+++ b/src/util/support/utf8.c -@@ -404,28 +404,6 @@ int krb5int_utf8_isalnum(const char * p) - - return KRB5_ALNUM(c); - } -- --#if 0 --int krb5int_utf8_islower(const char * p) --{ -- unsigned c = * (const unsigned char *) p; -- -- if (!KRB5_ASCII(c)) -- return 0; -- -- return KRB5_LOWER(c); --} -- --int krb5int_utf8_isupper(const char * p) --{ -- unsigned c = * (const unsigned char *) p; -- -- if (!KRB5_ASCII(c)) -- return 0; -- -- return KRB5_UPPER(c); --} --#endif - #endif - - -diff --git a/src/windows/include/loadfuncs-krb5.h b/src/windows/include/loadfuncs-krb5.h -index a90678878..39a3504f6 100644 ---- a/src/windows/include/loadfuncs-krb5.h -+++ b/src/windows/include/loadfuncs-krb5.h -@@ -106,29 +106,6 @@ TYPEDEF_FUNC( - krb5_free_ap_rep, - (krb5_context, krb5_ap_rep * ) - ); -- --/* Removed around the time of krb5_rc_* change... */ --#if 0 --TYPEDEF_FUNC( -- void, -- KRB5_CALLCONV, -- krb5_free_safe, -- (krb5_context, krb5_safe * ) -- ); --TYPEDEF_FUNC( -- void, -- KRB5_CALLCONV, -- krb5_free_priv, -- (krb5_context, krb5_priv * ) -- ); --TYPEDEF_FUNC( -- void, -- KRB5_CALLCONV, -- krb5_free_priv_enc_part, -- (krb5_context, krb5_priv_enc_part * ) -- ); --#endif -- - TYPEDEF_FUNC( - void, - KRB5_CALLCONV, -diff --git a/src/windows/kfwlogon/kfwlogon.c b/src/windows/kfwlogon/kfwlogon.c -index d851c4685..c388fffcd 100644 ---- a/src/windows/kfwlogon/kfwlogon.c -+++ b/src/windows/kfwlogon/kfwlogon.c -@@ -434,9 +434,6 @@ static BOOL - GetSecurityLogonSessionData(HANDLE hToken, PSECURITY_LOGON_SESSION_DATA * ppSessionData) - { - NTSTATUS Status = 0; --#if 0 -- HANDLE TokenHandle; --#endif - TOKEN_STATISTICS Stats; - DWORD ReqLen; - BOOL Success; -@@ -445,16 +442,8 @@ GetSecurityLogonSessionData(HANDLE hToken, PSECURITY_LOGON_SESSION_DATA * ppSess - return FALSE; - *ppSessionData = NULL; - --#if 0 -- Success = OpenProcessToken( HANDLE GetCurrentProcess(), TOKEN_QUERY, &TokenHandle ); -- if ( !Success ) -- return FALSE; --#endif - - Success = GetTokenInformation( hToken, TokenStatistics, &Stats, sizeof(TOKEN_STATISTICS), &ReqLen ); --#if 0 -- CloseHandle( TokenHandle ); --#endif - if ( !Success ) - return FALSE; - -diff --git a/src/windows/leash/Leash.cpp b/src/windows/leash/Leash.cpp -index f4e749350..cafcda7ce 100644 ---- a/src/windows/leash/Leash.cpp -+++ b/src/windows/leash/Leash.cpp -@@ -46,8 +46,6 @@ - static char THIS_FILE[] = __FILE__; - #endif - --extern "C" int VScheckVersion(HWND hWnd, HANDLE hThisInstance); -- - TicketInfoWrapper ticketinfo; - - HWND CLeashApp::m_hProgram = 0; -@@ -479,8 +477,6 @@ BOOL CLeashApp::InitInstance() - } - } - -- VScheckVersion(m_pMainWnd->m_hWnd, AfxGetInstanceHandle()); -- - // The one and only window has been initialized, so show and update it. - m_pMainWnd->SetWindowText("MIT Kerberos"); - m_pMainWnd->UpdateWindow(); -diff --git a/src/windows/leash/Makefile.in b/src/windows/leash/Makefile.in -index 1b124e90f..57f93a418 100644 ---- a/src/windows/leash/Makefile.in -+++ b/src/windows/leash/Makefile.in -@@ -61,9 +61,6 @@ OBJS= \ - $(OUTPRE)MainFrm.obj \ - $(OUTPRE)out2con.obj \ - $(OUTPRE)StdAfx.obj \ -- $(OUTPRE)AfsProperties.obj \ -- $(OUTPRE)VSroutines.obj \ -- $(OUTPRE)KrbMiscConfigOpt.obj \ - $(OUTPRE)KrbListTickets.obj - - RESFILE = $(OUTPRE)Leash.res -diff --git a/src/windows/leash/VSroutines.c b/src/windows/leash/VSroutines.c -deleted file mode 100644 -index 63f0b4ae1..000000000 ---- a/src/windows/leash/VSroutines.c -+++ /dev/null -@@ -1,64 +0,0 @@ --#include --#include -- --#if 0 --//#ifdef USE_VS --#include -- --#define ININAME "leash.ini" -- --int VScheckVersion(HWND hWnd, HANDLE hThisInstance) --{ -- VS_Request vrequest; -- VS_Status status; -- BOOL ok_to_continue; -- HCURSOR hcursor; -- char szFilename[255]; -- char szVerQ[90]; -- char *cp; -- LPSTR lpAppVersion; -- LPSTR lpAppName; -- LONG FAR *lpLangInfo; -- DWORD hVersionInfoID; -- DWORD size; -- GLOBALHANDLE hVersionInfo; -- LPSTR lpVersionInfo; -- int dumint; -- int retval; -- -- GetModuleFileName(hThisInstance, (LPSTR)szFilename, 255); -- size = GetFileVersionInfoSize((LPSTR) szFilename, &hVersionInfoID); -- hVersionInfo = GlobalAlloc(GHND, size); -- lpVersionInfo = GlobalLock(hVersionInfo); -- retval = GetFileVersionInfo(szFilename, hVersionInfoID, size, -- lpVersionInfo); -- retval = VerQueryValue(lpVersionInfo, "\\VarFileInfo\\Translation", -- (LPSTR FAR *)&lpLangInfo, &dumint); -- wsprintf(szVerQ, "\\StringFileInfo\\%04x%04x\\", -- LOWORD(*lpLangInfo), HIWORD(*lpLangInfo)); -- cp = szVerQ + lstrlen(szVerQ); -- lstrcpy(cp, "ProductName"); -- retval = VerQueryValue(lpVersionInfo, szVerQ, &lpAppName, &dumint); -- lstrcpy(cp, "ProductVersion"); -- -- retval = VerQueryValue(lpVersionInfo, szVerQ, &lpAppVersion, &dumint); -- hcursor = SetCursor(LoadCursor((HINSTANCE)NULL, IDC_WAIT)); -- vrequest = VSFormRequest(lpAppName, lpAppVersion, ININAME, NULL, hWnd, -- V_CHECK_AND_LOG); -- if ((ok_to_continue = (ReqStatus(vrequest) != V_E_CANCEL)) -- && v_complain((status = VSProcessRequest(vrequest)), ININAME)) -- WinVSReportRequest(vrequest, hWnd, "Version Server Status Report"); -- if (ok_to_continue && status == V_REQUIRED) -- ok_to_continue = FALSE; -- VSDestroyRequest(vrequest); -- SetCursor(hcursor); -- GlobalUnlock(hVersionInfo); -- GlobalFree(hVersionInfo); -- return(ok_to_continue); --} --#else --int VScheckVersion(HWND hWnd, HANDLE hThisInstance) --{ -- return(1); --} --#endif -diff --git a/src/windows/leashdll/lsh_pwd.c b/src/windows/leashdll/lsh_pwd.c -index ac85625a0..7cbe3d7e4 100644 ---- a/src/windows/leashdll/lsh_pwd.c -+++ b/src/windows/leashdll/lsh_pwd.c -@@ -1426,11 +1426,6 @@ AuthenticateProc( - CSetDlgItemText(hDialog, IDC_EDIT_PRINCIPAL, principal); - CSetDlgItemText(hDialog, IDC_EDIT_PASSWORD, ""); - --#if 0 /* 20030619 - mjv wishes to return to the default character */ -- /* echo spaces */ -- CSendDlgItemMessage(hDialog, IDC_EDIT_PASSWORD, EM_SETPASSWORDCHAR, 32, 0); --#endif -- - /* Set Lifetime Slider - * min value = 5 - * max value = 1440 -@@ -1817,12 +1812,6 @@ NewPasswordProc( - if (hEditCtrl) - pAutoComplete = Leash_pec_create(hEditCtrl); - --#if 0 /* 20030619 - mjv wishes to return to the default character */ -- /* echo spaces */ -- CSendDlgItemMessage(hDialog, IDC_EDIT_PASSWORD, EM_SETPASSWORDCHAR, 32, 0); -- CSendDlgItemMessage(hDialog, IDC_EDIT_PASSWORD2, EM_SETPASSWORDCHAR, 32, 0); -- CSendDlgItemMessage(hDialog, IDC_EDIT_PASSWORD3, EM_SETPASSWORDCHAR, 32, 0); --#endif - /* setup text of stuff. */ - - if (Position.x > 0 && Position.y > 0 && -diff --git a/src/windows/leashdll/lshfunc.c b/src/windows/leashdll/lshfunc.c -index 8dafb7bed..47337de5d 100644 ---- a/src/windows/leashdll/lshfunc.c -+++ b/src/windows/leashdll/lshfunc.c -@@ -279,19 +279,11 @@ Leash_changepwd_v5( - if ( !pkrb5_init_context ) - goto cleanup; - -- if (rc = pkrb5_init_context(&context)) { --#if 0 -- com_err(argv[0], ret, "initializing kerberos library"); --#endif -+ if (rc = pkrb5_init_context(&context)) - goto cleanup; -- } - -- if (rc = pkrb5_parse_name(context, principal, &princ)) { --#if 0 -- com_err(argv[0], ret, "parsing client name"); --#endif -+ if (rc = pkrb5_parse_name(context, principal, &princ)) - goto cleanup; -- } - - pkrb5_get_init_creds_opt_init(&opts); - pkrb5_get_init_creds_opt_set_tkt_life(&opts, 5*60); -@@ -305,29 +297,13 @@ Leash_changepwd_v5( - - - if (rc = pkrb5_get_init_creds_password(context, &creds, princ, password, -- 0, 0, 0, "kadmin/changepw", &opts)) { -- if (rc == KRB5KRB_AP_ERR_BAD_INTEGRITY) { --#if 0 -- com_err(argv[0], 0, -- "Password incorrect while getting initial ticket"); --#endif -- } -- else { --#if 0 -- com_err(argv[0], ret, "getting initial ticket"); --#endif -- } -+ 0, 0, 0, "kadmin/changepw", &opts)) - goto cleanup; -- } - - if (rc = pkrb5_change_password(context, &creds, newpassword, - &result_code, &result_code_string, -- &result_string)) { --#if 0 -- com_err(argv[0], ret, "changing password"); --#endif -+ &result_string)) - goto cleanup; -- } - - if (result_code) { - int len = result_code_string.length + -diff --git a/src/windows/leashdll/lshutil.cpp b/src/windows/leashdll/lshutil.cpp -index 37c0723f3..a90e7e92e 100644 ---- a/src/windows/leashdll/lshutil.cpp -+++ b/src/windows/leashdll/lshutil.cpp -@@ -531,17 +531,6 @@ protected: - IAutoCompleteDropDown* pacdd = NULL; - hRes = pac->QueryInterface(IID_IAutoCompleteDropDown, (LPVOID*)&pacdd); - pac->Release(); -- -- // @TODO: auto-suggest; other advanced options? --#if 0 -- IAutoComplete2 *pac2; -- -- if (SUCCEEDED(pac->QueryInterface(IID_IAutoComplete2, -- (LPVOID*)&pac2))) { -- pac2->SetOptions(ACO_AUTOSUGGEST); -- pac2->Release(); -- } --#endif - m_acdd = pacdd; - } - } -diff --git a/src/windows/lib/cacheapi.h b/src/windows/lib/cacheapi.h -index c485080c1..b30857810 100644 ---- a/src/windows/lib/cacheapi.h -+++ b/src/windows/lib/cacheapi.h -@@ -102,21 +102,6 @@ typedef struct opaque_dll_control_block_type* apiCB; - typedef struct opaque_ccache_pointer_type* ccache_p; - typedef struct opaque_credential_iterator_type* ccache_cit; - --#if 0 --enum _cc_data_type { -- type_ticket = 0, /* 0 for ticket, second_ticket */ -- /* Ted's draft spec says these are to be -- "as defined in the Kerberos V5 protocol" -- all I can find are typdefs, -- can't find an enumerated type or #define -- */ -- type_address, /* = <"as defined in the Kerberos V5 protocol"> */ -- type_authdata, /* = <"as defined in the Kerberos V5 protocol"> */ -- type_encryption, /* = <"as defined in the Kerberos V5 protocol"> */ -- cc_data_type_max /* for validation */ --}; --#endif -- - typedef struct _cc_data - { - cc_uint32 type; // should be one of _cc_data_type diff --git a/Exit-with-status-0-from-kadmind.patch b/Exit-with-status-0-from-kadmind.patch deleted file mode 100644 index 5fbdff8..0000000 --- a/Exit-with-status-0-from-kadmind.patch +++ /dev/null @@ -1,31 +0,0 @@ -From 3bfe632c7011c335362d78356232507d9ee26f73 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 14 Mar 2018 14:31:22 -0400 -Subject: [PATCH] Exit with status 0 from kadmind - -Typically, 0 denotes successful exit. In particular, init systems -will complain if another different value is returned. This presents a -problem for automated installation jobs which want to restart kadmind. - -`service kadmin stop` typically sends SIGTERM, which is caught by -verto and passed to our handler. Besides cleanup, we then call -verto_break(), which causes the verto_run() event loop to return. The -weird return code has been present since the addition of the kadmin -code, which used a similar event model for signals. - -(cherry picked from commit f970ad412aca36f8a7d3addb1cd4026ed22e5592) ---- - src/kadmin/server/ovsec_kadmd.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/kadmin/server/ovsec_kadmd.c b/src/kadmin/server/ovsec_kadmd.c -index aac4d4ffd..0a28b2384 100644 ---- a/src/kadmin/server/ovsec_kadmd.c -+++ b/src/kadmin/server/ovsec_kadmd.c -@@ -559,5 +559,5 @@ main(int argc, char *argv[]) - - krb5_klog_close(context); - krb5_free_context(context); -- exit(2); -+ exit(0); - } diff --git a/Explicitly-look-for-python2-in-configure.in.patch b/Explicitly-look-for-python2-in-configure.in.patch deleted file mode 100644 index cb6620f..0000000 --- a/Explicitly-look-for-python2-in-configure.in.patch +++ /dev/null @@ -1,816 +0,0 @@ -From 1d0c0db7755076834519fd02c271a78bbf26bb19 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 3 Jul 2018 01:20:50 -0400 -Subject: [PATCH] Explicitly look for python2 in configure.in - -The executable "python" has traditionally been Python 2, but is -becoming more ambiguous as operating systems transition towards Python -3. Look for "python2" in the path in preference to "python", and -check that what we found isn't Python 3. - -Remove the "#!/usr/bin/python" headers at the start of Python test -scripts since we run them explicitly under python, not as executables. -Execute paste-kdcproxy.py via sys.executable in t_proxy.py so that it -doesn't need a #!/usr/bin/python header. - -ticket: 8709 (new) -(cherry picked from commit 2bd410ecdb366083fe9b4e5f6ac4b741b624230b) ---- - src/appl/gss-sample/t_gss_sample.py | 2 -- - src/appl/user_user/t_user2user.py | 1 - - src/configure.in | 9 ++++++--- - src/kadmin/dbutil/t_tdumputil.py | 2 -- - src/kdc/t_bigreply.py | 1 - - src/kdc/t_emptytgt.py | 1 - - src/kdc/t_workers.py | 1 - - src/lib/kdb/t_stringattr.py | 1 - - src/lib/krad/t_daemon.py | 2 -- - src/lib/krb5/ccache/t_cccol.py | 1 - - src/lib/krb5/krb/t_expire_warn.py | 2 -- - src/lib/krb5/krb/t_in_ccache_patypes.py | 2 -- - src/lib/krb5/krb/t_vfy_increds.py | 2 -- - src/lib/krb5/os/t_discover_uri.py | 1 - - src/tests/gssapi/t_authind.py | 1 - - src/tests/gssapi/t_ccselect.py | 2 -- - src/tests/gssapi/t_client_keytab.py | 1 - - src/tests/gssapi/t_enctypes.py | 1 - - src/tests/gssapi/t_export_cred.py | 1 - - src/tests/gssapi/t_gssapi.py | 1 - - src/tests/gssapi/t_s4u.py | 1 - - src/tests/jsonwalker.py | 2 -- - src/tests/t_audit.py | 1 - - src/tests/t_authdata.py | 1 - - src/tests/t_bogus_kdc_req.py | 2 -- - src/tests/t_ccache.py | 2 -- - src/tests/t_certauth.py | 1 - - src/tests/t_changepw.py | 1 - - src/tests/t_crossrealm.py | 2 -- - src/tests/t_cve-2012-1014.py | 2 -- - src/tests/t_cve-2012-1015.py | 2 -- - src/tests/t_cve-2013-1416.py | 2 -- - src/tests/t_cve-2013-1417.py | 2 -- - src/tests/t_dump.py | 1 - - src/tests/t_errmsg.py | 1 - - src/tests/t_etype_info.py | 1 - - src/tests/t_general.py | 1 - - src/tests/t_hooks.py | 1 - - src/tests/t_hostrealm.py | 1 - - src/tests/t_iprop.py | 2 -- - src/tests/t_kadm5_auth.py | 1 - - src/tests/t_kadm5_hook.py | 1 - - src/tests/t_kadmin_acl.py | 1 - - src/tests/t_kadmin_parsing.py | 1 - - src/tests/t_kdb.py | 1 - - src/tests/t_kdb_locking.py | 2 -- - src/tests/t_kdc_log.py | 2 -- - src/tests/t_kdcpolicy.py | 1 - - src/tests/t_keydata.py | 1 - - src/tests/t_keyrollover.py | 1 - - src/tests/t_keytab.py | 1 - - src/tests/t_kprop.py | 1 - - src/tests/t_localauth.py | 1 - - src/tests/t_mkey.py | 1 - - src/tests/t_otp.py | 2 -- - src/tests/t_pkinit.py | 1 - - src/tests/t_policy.py | 1 - - src/tests/t_preauth.py | 1 - - src/tests/t_princflags.py | 1 - - src/tests/t_proxy.py | 4 ++-- - src/tests/t_pwqual.py | 1 - - src/tests/t_rdreq.py | 1 - - src/tests/t_referral.py | 1 - - src/tests/t_renew.py | 1 - - src/tests/t_renprinc.py | 2 -- - src/tests/t_salt.py | 1 - - src/tests/t_sesskeynego.py | 1 - - src/tests/t_skew.py | 1 - - src/tests/t_sn2princ.py | 1 - - src/tests/t_spake.py | 1 - - src/tests/t_stringattr.py | 2 -- - src/tests/t_tabdump.py | 1 - - src/tests/t_unlockiter.py | 1 - - src/tests/t_y2038.py | 1 - - src/util/paste-kdcproxy.py | 1 - - 75 files changed, 8 insertions(+), 99 deletions(-) - -diff --git a/src/appl/gss-sample/t_gss_sample.py b/src/appl/gss-sample/t_gss_sample.py -index 0299e4590..2f537823a 100755 ---- a/src/appl/gss-sample/t_gss_sample.py -+++ b/src/appl/gss-sample/t_gss_sample.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - # Copyright (C) 2010 by the Massachusetts Institute of Technology. - # All rights reserved. - # -diff --git a/src/appl/user_user/t_user2user.py b/src/appl/user_user/t_user2user.py -index 2a7d03f8d..2c054f181 100755 ---- a/src/appl/user_user/t_user2user.py -+++ b/src/appl/user_user/t_user2user.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # If uuserver is not compiled under -DDEBUG, then set to 0 -diff --git a/src/configure.in b/src/configure.in -index 08c63beca..3f45784b5 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -1098,13 +1098,16 @@ fi - AC_SUBST(HAVE_RUNTEST) - - # For Python tests. --AC_CHECK_PROG(PYTHON,python,python) -+AC_CHECK_PROG(PYTHON,python2,python2) -+if text x"$PYTHON" = x; then -+ AC_CHECK_PROG(PYTHON,python,python) -+fi - HAVE_PYTHON=no - if test x"$PYTHON" != x; then - # k5test.py requires python 2.4 (for the subprocess module). - # Some code needs python 2.5 (for syntax like conditional expressions). -- vercheck="import sys;sys.exit((sys.hexversion < 0x2050000) and 1 or 0)" -- if python -c "$vercheck"; then -+ wantver="(sys.hexversion >= 0x2050000 and sys.hexversion < 0x3000000)" -+ if "$PYTHON" -c "import sys; sys.exit(not $wantver and 1 or 0)"; then - HAVE_PYTHON=yes - fi - fi -diff --git a/src/kadmin/dbutil/t_tdumputil.py b/src/kadmin/dbutil/t_tdumputil.py -index 5d7ac38d2..52e356533 100755 ---- a/src/kadmin/dbutil/t_tdumputil.py -+++ b/src/kadmin/dbutil/t_tdumputil.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - from k5test import * - from subprocess import * - -diff --git a/src/kdc/t_bigreply.py b/src/kdc/t_bigreply.py -index 6bc9a8fe0..b6300154f 100644 ---- a/src/kdc/t_bigreply.py -+++ b/src/kdc/t_bigreply.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Set the maximum UDP reply size very low, so that all replies go -diff --git a/src/kdc/t_emptytgt.py b/src/kdc/t_emptytgt.py -index 2d0432e33..c601c010c 100755 ---- a/src/kdc/t_emptytgt.py -+++ b/src/kdc/t_emptytgt.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - realm = K5Realm(create_host=False) -diff --git a/src/kdc/t_workers.py b/src/kdc/t_workers.py -index 6dd4f6805..8de3f34d9 100755 ---- a/src/kdc/t_workers.py -+++ b/src/kdc/t_workers.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - realm = K5Realm(start_kdc=False, create_host=False) -diff --git a/src/lib/kdb/t_stringattr.py b/src/lib/kdb/t_stringattr.py -index 085e179e4..93e2b0c01 100755 ---- a/src/lib/kdb/t_stringattr.py -+++ b/src/lib/kdb/t_stringattr.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - realm = K5Realm(create_kdb=False) -diff --git a/src/lib/krad/t_daemon.py b/src/lib/krad/t_daemon.py -index dcda0050b..7d7a5d0c8 100755 ---- a/src/lib/krad/t_daemon.py -+++ b/src/lib/krad/t_daemon.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python --# - # Copyright 2013 Red Hat, Inc. All rights reserved. - # - # Redistribution and use in source and binary forms, with or without -diff --git a/src/lib/krb5/ccache/t_cccol.py b/src/lib/krb5/ccache/t_cccol.py -index f7f178564..1467512e2 100755 ---- a/src/lib/krb5/ccache/t_cccol.py -+++ b/src/lib/krb5/ccache/t_cccol.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - realm = K5Realm(create_kdb=False) -diff --git a/src/lib/krb5/krb/t_expire_warn.py b/src/lib/krb5/krb/t_expire_warn.py -index aed39e399..781f2728a 100755 ---- a/src/lib/krb5/krb/t_expire_warn.py -+++ b/src/lib/krb5/krb/t_expire_warn.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - # Copyright (C) 2010 by the Massachusetts Institute of Technology. - # All rights reserved. - # -diff --git a/src/lib/krb5/krb/t_in_ccache_patypes.py b/src/lib/krb5/krb/t_in_ccache_patypes.py -index c04234064..b2812688c 100755 ---- a/src/lib/krb5/krb/t_in_ccache_patypes.py -+++ b/src/lib/krb5/krb/t_in_ccache_patypes.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - # Copyright (C) 2010,2012 by the Massachusetts Institute of Technology. - # All rights reserved. - # -diff --git a/src/lib/krb5/krb/t_vfy_increds.py b/src/lib/krb5/krb/t_vfy_increds.py -index c820cc690..b899308a8 100755 ---- a/src/lib/krb5/krb/t_vfy_increds.py -+++ b/src/lib/krb5/krb/t_vfy_increds.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - # Copyright (C) 2011 by the Massachusetts Institute of Technology. - # All rights reserved. - # -diff --git a/src/lib/krb5/os/t_discover_uri.py b/src/lib/krb5/os/t_discover_uri.py -index 278f98371..87bac1792 100644 ---- a/src/lib/krb5/os/t_discover_uri.py -+++ b/src/lib/krb5/os/t_discover_uri.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - entries = ('URI _kerberos.TEST krb5srv::kkdcp:https://kdc1 1 1\n', -diff --git a/src/tests/gssapi/t_authind.py b/src/tests/gssapi/t_authind.py -index 84793beb6..af1741a23 100644 ---- a/src/tests/gssapi/t_authind.py -+++ b/src/tests/gssapi/t_authind.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Test authentication indicators. Load the test preauth module so we -diff --git a/src/tests/gssapi/t_ccselect.py b/src/tests/gssapi/t_ccselect.py -index 3503f9269..cd62da231 100755 ---- a/src/tests/gssapi/t_ccselect.py -+++ b/src/tests/gssapi/t_ccselect.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - # Copyright (C) 2011 by the Massachusetts Institute of Technology. - # All rights reserved. - -diff --git a/src/tests/gssapi/t_client_keytab.py b/src/tests/gssapi/t_client_keytab.py -index 2da87f45b..e474a27c7 100755 ---- a/src/tests/gssapi/t_client_keytab.py -+++ b/src/tests/gssapi/t_client_keytab.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Set up a basic realm and a client keytab containing two user principals. -diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py -index f513db2b5..ee43ff028 100755 ---- a/src/tests/gssapi/t_enctypes.py -+++ b/src/tests/gssapi/t_enctypes.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Define some convenience abbreviations for enctypes we will see in -diff --git a/src/tests/gssapi/t_export_cred.py b/src/tests/gssapi/t_export_cred.py -index b98962788..89167bcc5 100755 ---- a/src/tests/gssapi/t_export_cred.py -+++ b/src/tests/gssapi/t_export_cred.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Test gss_export_cred and gss_import_cred for initiator creds, -diff --git a/src/tests/gssapi/t_gssapi.py b/src/tests/gssapi/t_gssapi.py -index 6da5fceff..a7dda20fb 100755 ---- a/src/tests/gssapi/t_gssapi.py -+++ b/src/tests/gssapi/t_gssapi.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Test krb5 negotiation under SPNEGO for all enctype configurations. Also -diff --git a/src/tests/gssapi/t_s4u.py b/src/tests/gssapi/t_s4u.py -index e4cd68469..fc9d9e8a4 100755 ---- a/src/tests/gssapi/t_s4u.py -+++ b/src/tests/gssapi/t_s4u.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - realm = K5Realm(create_host=False, get_creds=False) -diff --git a/src/tests/jsonwalker.py b/src/tests/jsonwalker.py -index 265c69c70..942ca2db7 100644 ---- a/src/tests/jsonwalker.py -+++ b/src/tests/jsonwalker.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - import sys - try: - import cjson -diff --git a/src/tests/t_audit.py b/src/tests/t_audit.py -index 00e96bfea..0f880edb2 100755 ---- a/src/tests/t_audit.py -+++ b/src/tests/t_audit.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - conf = {'plugins': {'audit': { -diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py -index 8a577b4b1..5cff80348 100644 ---- a/src/tests/t_authdata.py -+++ b/src/tests/t_authdata.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Load the sample KDC authdata module. -diff --git a/src/tests/t_bogus_kdc_req.py b/src/tests/t_bogus_kdc_req.py -index b6208ca68..a101c0e10 100755 ---- a/src/tests/t_bogus_kdc_req.py -+++ b/src/tests/t_bogus_kdc_req.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - import base64 - import socket - from k5test import * -diff --git a/src/tests/t_ccache.py b/src/tests/t_ccache.py -index 61d549b7b..a913eb025 100755 ---- a/src/tests/t_ccache.py -+++ b/src/tests/t_ccache.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - # Copyright (C) 2011 by the Massachusetts Institute of Technology. - # All rights reserved. - -diff --git a/src/tests/t_certauth.py b/src/tests/t_certauth.py -index e64a57b0d..9c7094525 100644 ---- a/src/tests/t_certauth.py -+++ b/src/tests/t_certauth.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Skip this test if pkinit wasn't built. -diff --git a/src/tests/t_changepw.py b/src/tests/t_changepw.py -index 37fe4fce1..211cda6c3 100755 ---- a/src/tests/t_changepw.py -+++ b/src/tests/t_changepw.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # This file is intended to cover any password-changing mechanism. For -diff --git a/src/tests/t_crossrealm.py b/src/tests/t_crossrealm.py -index 4d595dca6..09028bfa7 100755 ---- a/src/tests/t_crossrealm.py -+++ b/src/tests/t_crossrealm.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - # Copyright (C) 2011 by the Massachusetts Institute of Technology. - # All rights reserved. - # -diff --git a/src/tests/t_cve-2012-1014.py b/src/tests/t_cve-2012-1014.py -index e02162d6c..dcff95f6e 100755 ---- a/src/tests/t_cve-2012-1014.py -+++ b/src/tests/t_cve-2012-1014.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - import base64 - import socket - from k5test import * -diff --git a/src/tests/t_cve-2012-1015.py b/src/tests/t_cve-2012-1015.py -index e00c4dc90..28b1e619b 100755 ---- a/src/tests/t_cve-2012-1015.py -+++ b/src/tests/t_cve-2012-1015.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - import base64 - import socket - from k5test import * -diff --git a/src/tests/t_cve-2013-1416.py b/src/tests/t_cve-2013-1416.py -index 94fb6d5ef..8c4391a86 100755 ---- a/src/tests/t_cve-2013-1416.py -+++ b/src/tests/t_cve-2013-1416.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - from k5test import * - - realm = K5Realm() -diff --git a/src/tests/t_cve-2013-1417.py b/src/tests/t_cve-2013-1417.py -index c26930a30..ce47d21ca 100755 ---- a/src/tests/t_cve-2013-1417.py -+++ b/src/tests/t_cve-2013-1417.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - from k5test import * - - realm = K5Realm(realm='TEST') -diff --git a/src/tests/t_dump.py b/src/tests/t_dump.py -index 8a9462bd8..2cfeada6c 100755 ---- a/src/tests/t_dump.py -+++ b/src/tests/t_dump.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - from filecmp import cmp - -diff --git a/src/tests/t_errmsg.py b/src/tests/t_errmsg.py -index c9ae6637f..4aacf4e0a 100755 ---- a/src/tests/t_errmsg.py -+++ b/src/tests/t_errmsg.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - realm = K5Realm(create_kdb=False) -diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py -index b2eb0f7af..b12fb53c8 100644 ---- a/src/tests/t_etype_info.py -+++ b/src/tests/t_etype_info.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac des-cbc-crc:afs3' -diff --git a/src/tests/t_general.py b/src/tests/t_general.py -index 91ad0cb8a..96ba8a4b0 100755 ---- a/src/tests/t_general.py -+++ b/src/tests/t_general.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - for realm in multipass_realms(create_host=False): -diff --git a/src/tests/t_hooks.py b/src/tests/t_hooks.py -index 58dff3ae7..4fd3822e8 100755 ---- a/src/tests/t_hooks.py -+++ b/src/tests/t_hooks.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Test that KDC send and recv hooks work correctly. -diff --git a/src/tests/t_hostrealm.py b/src/tests/t_hostrealm.py -index 224c067ef..256ba2a38 100755 ---- a/src/tests/t_hostrealm.py -+++ b/src/tests/t_hostrealm.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - plugin = os.path.join(buildtop, "plugins", "hostrealm", "test", -diff --git a/src/tests/t_iprop.py b/src/tests/t_iprop.py -index 8e23cd5de..9cbeb3e68 100755 ---- a/src/tests/t_iprop.py -+++ b/src/tests/t_iprop.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - import os - import re - -diff --git a/src/tests/t_kadm5_auth.py b/src/tests/t_kadm5_auth.py -index ba4ab8ef1..6e0f42b08 100644 ---- a/src/tests/t_kadm5_auth.py -+++ b/src/tests/t_kadm5_auth.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Create a realm with the welcomer and bouncer kadm5_auth test modules -diff --git a/src/tests/t_kadm5_hook.py b/src/tests/t_kadm5_hook.py -index c1c8c9419..32fab781d 100755 ---- a/src/tests/t_kadm5_hook.py -+++ b/src/tests/t_kadm5_hook.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - plugin = os.path.join(buildtop, "plugins", "kadm5_hook", "test", -diff --git a/src/tests/t_kadmin_acl.py b/src/tests/t_kadmin_acl.py -index 42bdf423c..01a3eda29 100755 ---- a/src/tests/t_kadmin_acl.py -+++ b/src/tests/t_kadmin_acl.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - import os - -diff --git a/src/tests/t_kadmin_parsing.py b/src/tests/t_kadmin_parsing.py -index 8de387c64..bebb01488 100644 ---- a/src/tests/t_kadmin_parsing.py -+++ b/src/tests/t_kadmin_parsing.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # This file contains tests for kadmin command parsing. Principal -diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py -index 6e563b103..983cd93c8 100755 ---- a/src/tests/t_kdb.py -+++ b/src/tests/t_kdb.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - import time - from itertools import imap -diff --git a/src/tests/t_kdb_locking.py b/src/tests/t_kdb_locking.py -index aac0a220f..b5afd6d23 100755 ---- a/src/tests/t_kdb_locking.py -+++ b/src/tests/t_kdb_locking.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - # This is a regression test for - # https://bugzilla.redhat.com/show_bug.cgi?id=586032 . - # -diff --git a/src/tests/t_kdc_log.py b/src/tests/t_kdc_log.py -index 8ddb7691b..1b14828de 100755 ---- a/src/tests/t_kdc_log.py -+++ b/src/tests/t_kdc_log.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - from k5test import * - - # Make a TGS request with an expired ticket. -diff --git a/src/tests/t_kdcpolicy.py b/src/tests/t_kdcpolicy.py -index 5b198bb43..a44adfdb5 100644 ---- a/src/tests/t_kdcpolicy.py -+++ b/src/tests/t_kdcpolicy.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - from datetime import datetime - import re -diff --git a/src/tests/t_keydata.py b/src/tests/t_keydata.py -index 5c04a8523..b37233b21 100755 ---- a/src/tests/t_keydata.py -+++ b/src/tests/t_keydata.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - realm = K5Realm(create_user=False, create_host=False) -diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py -index bfd38914b..7c8d828f0 100755 ---- a/src/tests/t_keyrollover.py -+++ b/src/tests/t_keyrollover.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - rollover_krb5_conf = {'libdefaults': {'allow_weak_crypto': 'true'}} -diff --git a/src/tests/t_keytab.py b/src/tests/t_keytab.py -index a48740ba5..228c36334 100755 ---- a/src/tests/t_keytab.py -+++ b/src/tests/t_keytab.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - for realm in multipass_realms(create_user=False): -diff --git a/src/tests/t_kprop.py b/src/tests/t_kprop.py -index 39169675d..f352ec8d7 100755 ---- a/src/tests/t_kprop.py -+++ b/src/tests/t_kprop.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - conf_slave = {'dbmodules': {'db': {'database_name': '$testdir/db.slave'}}} -diff --git a/src/tests/t_localauth.py b/src/tests/t_localauth.py -index aa625d038..ebc9cdfde 100755 ---- a/src/tests/t_localauth.py -+++ b/src/tests/t_localauth.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Unfortunately, we can't reliably test the k5login module. We can control -diff --git a/src/tests/t_mkey.py b/src/tests/t_mkey.py -index 615cd91ca..48a533059 100755 ---- a/src/tests/t_mkey.py -+++ b/src/tests/t_mkey.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - import random - import re -diff --git a/src/tests/t_otp.py b/src/tests/t_otp.py -index 9b18ff94b..0fd35d576 100755 ---- a/src/tests/t_otp.py -+++ b/src/tests/t_otp.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python --# - # Author: Nathaniel McCallum - # - # Copyright (c) 2013 Red Hat, Inc. -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index 0e964c689..850db4fdd 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Skip this test if pkinit wasn't built. -diff --git a/src/tests/t_policy.py b/src/tests/t_policy.py -index 26c4e466e..eb3865d7c 100755 ---- a/src/tests/t_policy.py -+++ b/src/tests/t_policy.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - import re - -diff --git a/src/tests/t_preauth.py b/src/tests/t_preauth.py -index 32e35b08b..f597c3d08 100644 ---- a/src/tests/t_preauth.py -+++ b/src/tests/t_preauth.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Test that the kdcpreauth client_keyblock() callback matches the key -diff --git a/src/tests/t_princflags.py b/src/tests/t_princflags.py -index 6378ef94f..aa3660217 100755 ---- a/src/tests/t_princflags.py -+++ b/src/tests/t_princflags.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - from princflags import * - import re -diff --git a/src/tests/t_proxy.py b/src/tests/t_proxy.py -index 4e86fce8f..ff1929bef 100755 ---- a/src/tests/t_proxy.py -+++ b/src/tests/t_proxy.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Skip this test if we're missing proxy functionality or parts of the proxy. -@@ -62,7 +61,8 @@ def start_proxy(realm, keycertpem): - conf.write('kpasswd = kpasswd://localhost:%d\n' % (realm.portbase + 2)) - conf.close() - realm.env['KDCPROXY_CONFIG'] = proxy_conf_path -- cmd = [proxy_exec_path, str(realm.server_port()), keycertpem] -+ cmd = [sys.executable, proxy_exec_path, str(realm.server_port()), -+ keycertpem] - return realm.start_server(cmd, sentinel='proxy server ready') - - # Fail: untrusted issuer and hostname doesn't match. -diff --git a/src/tests/t_pwqual.py b/src/tests/t_pwqual.py -index 011110bd1..171805697 100755 ---- a/src/tests/t_pwqual.py -+++ b/src/tests/t_pwqual.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - plugin = os.path.join(buildtop, "plugins", "pwqual", "test", "pwqual_test.so") -diff --git a/src/tests/t_rdreq.py b/src/tests/t_rdreq.py -index f67c34866..00cd5cbb4 100755 ---- a/src/tests/t_rdreq.py -+++ b/src/tests/t_rdreq.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - conf = {'realms': {'$realm': {'supported_enctypes': 'aes256-cts aes128-cts'}}} -diff --git a/src/tests/t_referral.py b/src/tests/t_referral.py -index e12fdc2e9..2f29d5712 100755 ---- a/src/tests/t_referral.py -+++ b/src/tests/t_referral.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Create a pair of realms, where KRBTEST1.COM can authenticate to -diff --git a/src/tests/t_renew.py b/src/tests/t_renew.py -index 034190c80..67b4182fd 100755 ---- a/src/tests/t_renew.py -+++ b/src/tests/t_renew.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - from datetime import datetime - import re -diff --git a/src/tests/t_renprinc.py b/src/tests/t_renprinc.py -index cc780839a..46cbed441 100755 ---- a/src/tests/t_renprinc.py -+++ b/src/tests/t_renprinc.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - # Copyright (C) 2011 by the Massachusetts Institute of Technology. - # All rights reserved. - -diff --git a/src/tests/t_salt.py b/src/tests/t_salt.py -index ddb1905ed..278911a22 100755 ---- a/src/tests/t_salt.py -+++ b/src/tests/t_salt.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - import re - -diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py -index 732c306ea..448092387 100755 ---- a/src/tests/t_sesskeynego.py -+++ b/src/tests/t_sesskeynego.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - import re - -diff --git a/src/tests/t_skew.py b/src/tests/t_skew.py -index f2ae06695..36d5a95c5 100755 ---- a/src/tests/t_skew.py -+++ b/src/tests/t_skew.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Create a realm with the KDC one hour in the past. -diff --git a/src/tests/t_sn2princ.py b/src/tests/t_sn2princ.py -index 19a0d2fa7..e2c85e665 100755 ---- a/src/tests/t_sn2princ.py -+++ b/src/tests/t_sn2princ.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - offline = (len(args) > 0 and args[0] != "no") -diff --git a/src/tests/t_spake.py b/src/tests/t_spake.py -index 5b47e62d3..65af46d18 100644 ---- a/src/tests/t_spake.py -+++ b/src/tests/t_spake.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # The name and number of each supported SPAKE group. -diff --git a/src/tests/t_stringattr.py b/src/tests/t_stringattr.py -index 5672a0f20..c2dc348e9 100755 ---- a/src/tests/t_stringattr.py -+++ b/src/tests/t_stringattr.py -@@ -1,5 +1,3 @@ --#!/usr/bin/python -- - # Copyright (C) 2011 by the Massachusetts Institute of Technology. - # All rights reserved. - -diff --git a/src/tests/t_tabdump.py b/src/tests/t_tabdump.py -index 066e48418..2a86136dd 100755 ---- a/src/tests/t_tabdump.py -+++ b/src/tests/t_tabdump.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - import csv -diff --git a/src/tests/t_unlockiter.py b/src/tests/t_unlockiter.py -index 2a438e99a..603cf721d 100755 ---- a/src/tests/t_unlockiter.py -+++ b/src/tests/t_unlockiter.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # Default KDB iteration is locked. Expect write lock failure unless -diff --git a/src/tests/t_y2038.py b/src/tests/t_y2038.py -index 02e946df4..42a4ff7ed 100644 ---- a/src/tests/t_y2038.py -+++ b/src/tests/t_y2038.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - from k5test import * - - # These tests will become much less important after the y2038 boundary -diff --git a/src/util/paste-kdcproxy.py b/src/util/paste-kdcproxy.py -index 1e56b8954..30467fd74 100755 ---- a/src/util/paste-kdcproxy.py -+++ b/src/util/paste-kdcproxy.py -@@ -1,4 +1,3 @@ --#!/usr/bin/python - import kdcproxy - from paste import httpserver - import os diff --git a/Fix-SPAKE-memory-leak.patch b/Fix-SPAKE-memory-leak.patch deleted file mode 100644 index e1cacca..0000000 --- a/Fix-SPAKE-memory-leak.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 390c515e13dffc8c00b44623cba47e27c2f20cf7 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 27 Mar 2018 10:36:05 -0400 -Subject: [PATCH] Fix SPAKE memory leak - -In the NIST group implementations, ossl_fini() needs to free the -groupdata container as well as its fields. Also in -spake_kdc.c:parse_data(), initialize the magic field of the resulting -data object to avoid a harmless uninitialized memory copy. - -ticket: 8647 -(cherry picked from commit 70b88b8018658e052d6eabf06f8fdad17fbe993c) ---- - src/plugins/preauth/spake/openssl.c | 1 + - src/plugins/preauth/spake/spake_kdc.c | 1 + - 2 files changed, 2 insertions(+) - -diff --git a/src/plugins/preauth/spake/openssl.c b/src/plugins/preauth/spake/openssl.c -index b821a9158..f2e4b53ec 100644 ---- a/src/plugins/preauth/spake/openssl.c -+++ b/src/plugins/preauth/spake/openssl.c -@@ -69,6 +69,7 @@ ossl_fini(groupdata *gd) - EC_POINT_free(gd->N); - BN_CTX_free(gd->ctx); - BN_free(gd->order); -+ free(gd); - } - - static krb5_error_code -diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c -index c1723ebaf..59e88409e 100644 ---- a/src/plugins/preauth/spake/spake_kdc.c -+++ b/src/plugins/preauth/spake/spake_kdc.c -@@ -75,6 +75,7 @@ parse_data(struct k5input *in, krb5_data *out) - { - out->length = k5_input_get_uint32_be(in); - out->data = (char *)k5_input_get_bytes(in, out->length); -+ out->magic = KV5M_DATA; - } - - /* Parse a received cookie into its components. The pointers stored in the diff --git a/Fix-hex-conversion-of-PKINIT-certid-strings.patch b/Fix-hex-conversion-of-PKINIT-certid-strings.patch deleted file mode 100644 index 57d561b..0000000 --- a/Fix-hex-conversion-of-PKINIT-certid-strings.patch +++ /dev/null @@ -1,92 +0,0 @@ -From 8b898badbe8051270c6da96f5c15f3bc8b6d974e Mon Sep 17 00:00:00 2001 -From: Sumit Bose -Date: Fri, 26 Jan 2018 11:47:50 -0500 -Subject: [PATCH] Fix hex conversion of PKINIT certid strings - -When parsing a PKCS11 token specification, correctly convert from hex -to binary instead of using OpenSSL bignum functions (which would strip -leading zeros). - -[ghudson@mit.edu: made hex_string_to_bin() a bit less verbose; wrote -commit message] - -ticket: 8636 -(cherry picked from commit 63e8b8142fd7b3931a7bf2d6448978ca536bafc0) ---- - .../preauth/pkinit/pkinit_crypto_openssl.c | 55 +++++++++++++++---- - 1 file changed, 44 insertions(+), 11 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 2064eb7bd..eb2953fe1 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -4616,6 +4616,43 @@ reassemble_pkcs11_name(pkinit_identity_opts *idopts) - return ret; - } - -+static int -+hex_string_to_bin(const char *str, int *bin_len_out, CK_BYTE **bin_out) -+{ -+ size_t str_len, i; -+ CK_BYTE *bin; -+ char *endptr, tmp[3] = { '\0', '\0', '\0' }; -+ long val; -+ -+ *bin_len_out = 0; -+ *bin_out = NULL; -+ -+ str_len = strlen(str); -+ if (str_len % 2 != 0) -+ return EINVAL; -+ bin = malloc(str_len / 2); -+ if (bin == NULL) -+ return ENOMEM; -+ -+ errno = 0; -+ for (i = 0; i < str_len / 2; i++) { -+ tmp[0] = str[i * 2]; -+ tmp[1] = str[i * 2 + 1]; -+ -+ val = strtol(tmp, &endptr, 16); -+ if (val < 0 || val > 255 || errno != 0 || endptr != &tmp[2]) { -+ free(bin); -+ return EINVAL; -+ } -+ -+ bin[i] = (CK_BYTE)val; -+ } -+ -+ *bin_len_out = str_len / 2; -+ *bin_out = bin; -+ return 0; -+} -+ - static krb5_error_code - pkinit_get_certs_pkcs11(krb5_context context, - pkinit_plg_crypto_context plg_cryptoctx, -@@ -4658,18 +4695,14 @@ pkinit_get_certs_pkcs11(krb5_context context, - } - /* Convert the ascii cert_id string into a binary blob */ - if (idopts->cert_id_string != NULL) { -- BIGNUM *bn = NULL; -- BN_hex2bn(&bn, idopts->cert_id_string); -- if (bn == NULL) -- return ENOMEM; -- id_cryptoctx->cert_id_len = BN_num_bytes(bn); -- id_cryptoctx->cert_id = malloc((size_t) id_cryptoctx->cert_id_len); -- if (id_cryptoctx->cert_id == NULL) { -- BN_free(bn); -- return ENOMEM; -+ r = hex_string_to_bin(idopts->cert_id_string, -+ &id_cryptoctx->cert_id_len, -+ &id_cryptoctx->cert_id); -+ if (r != 0) { -+ pkiDebug("Failed to convert certid string [%s]\n", -+ idopts->cert_id_string); -+ return r; - } -- BN_bn2bin(bn, id_cryptoctx->cert_id); -- BN_free(bn); - } - id_cryptoctx->slotid = idopts->slotid; - id_cryptoctx->pkcs11_method = 1; diff --git a/Fix-k5test-prompts-for-Python-3.patch b/Fix-k5test-prompts-for-Python-3.patch deleted file mode 100644 index 4adb451..0000000 --- a/Fix-k5test-prompts-for-Python-3.patch +++ /dev/null @@ -1,35 +0,0 @@ -From 43cf653d21d931b792b36c7e6e4cfab3a6236bef Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 25 Jul 2018 11:50:02 -0400 -Subject: [PATCH] Fix k5test prompts for Python 3 - -With Python 3, sys.stdout.write() of a partial line followed by -sys.stdin.readline() does not display the partial line. Add explicit -flushes to make prompts visible in k5test.py. - -ticket: 8710 -(cherry picked from commit 297535b72177dcced036b78107e9d0e37781c7a3) ---- - src/util/k5test.py | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/src/util/k5test.py b/src/util/k5test.py -index 81fac3063..e4f99b211 100644 ---- a/src/util/k5test.py -+++ b/src/util/k5test.py -@@ -457,6 +457,7 @@ def _onexit(): - if _debug or _stop_before or _stop_after or _shell_before or _shell_after: - # Wait before killing daemons in case one is being debugged. - sys.stdout.write('*** Press return to kill daemons and exit script: ') -+ sys.stdout.flush() - sys.stdin.readline() - for proc in _daemons: - os.kill(proc.pid, signal.SIGTERM) -@@ -658,6 +659,7 @@ def _valgrind(args): - def _stop_or_shell(stop, shell, env, ind): - if (_match_cmdnum(stop, ind)): - sys.stdout.write('*** [%d] Waiting for return: ' % ind) -+ sys.stdout.flush() - sys.stdin.readline() - if (_match_cmdnum(shell, ind)): - output('*** [%d] Spawning shell\n' % ind, True) diff --git a/Fix-read-overflow-in-KDC-sort_pa_data.patch b/Fix-read-overflow-in-KDC-sort_pa_data.patch deleted file mode 100644 index 4f46827..0000000 --- a/Fix-read-overflow-in-KDC-sort_pa_data.patch +++ /dev/null @@ -1,48 +0,0 @@ -From 59a28991e15496e6f9cf867c32dc18e7e1062f59 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 15 Mar 2018 20:27:30 -0400 -Subject: [PATCH] Fix read overflow in KDC sort_pa_data() - -sort_pa_data() could read past the end of pa_order if all preauth -systems in the table have the PA_REPLACES_KEY flag, causing a -dereference of preauth_systems[-1]. This situation became possible -after commit fea1a488924faa3938ef723feaa1ff12d22a91ff with the -elimination of static_preauth_systems; before that there were always -table entries which did not have PA_REPLACES_KEY set. - -Fix this bug by removing the loop to count n_key_replacers, and -instead get the count from the prior loop by stopping once we move all -of the key-replacing modules to the front. - -(cherry picked from commit b38e318cea18fd65647189eed64aef83bf1cb772) ---- - src/kdc/kdc_preauth.c | 9 +++++---- - 1 file changed, 5 insertions(+), 4 deletions(-) - -diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c -index 80b130222..62ff9a8a7 100644 ---- a/src/kdc/kdc_preauth.c -+++ b/src/kdc/kdc_preauth.c -@@ -663,17 +663,18 @@ sort_pa_order(krb5_context context, krb5_kdc_req *request, int *pa_order) - break; - } - } -+ /* If we didn't find one, we have moved all of the key-replacing -+ * modules, and i is the count of those modules. */ -+ if (j == n_repliers) -+ break; - } -+ n_key_replacers = i; - - if (request->padata != NULL) { - /* Now reorder the subset of modules which replace the key, - * bubbling those which handle pa_data types provided by the - * client ahead of the others. - */ -- for (i = 0; preauth_systems[pa_order[i]].flags & PA_REPLACES_KEY; i++) { -- continue; -- } -- n_key_replacers = i; - for (i = 0; i < n_key_replacers; i++) { - if (pa_list_includes(request->padata, - preauth_systems[pa_order[i]].type)) diff --git a/Fix-securid_sam2-preauth-for-non-default-salt.patch b/Fix-securid_sam2-preauth-for-non-default-salt.patch deleted file mode 100644 index 610bf4e..0000000 --- a/Fix-securid_sam2-preauth-for-non-default-salt.patch +++ /dev/null @@ -1,43 +0,0 @@ -From e405f42b532e377e7e3d654313a07f8c11f48f9a Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 3 Jan 2018 12:06:08 -0500 -Subject: [PATCH] Fix securid_sam2 preauth for non-default salt - -When looking up the client long-term key, look for any salt type, not -just the default salt type. - -ticket: 8629 -(cherry picked from commit a2339099ad13c84de0843fd04d0ba612fc194a1e) ---- - src/plugins/preauth/securid_sam2/grail.c | 3 +-- - src/plugins/preauth/securid_sam2/securid2.c | 3 +-- - 2 files changed, 2 insertions(+), 4 deletions(-) - -diff --git a/src/plugins/preauth/securid_sam2/grail.c b/src/plugins/preauth/securid_sam2/grail.c -index 18d48f924..48b61b0d1 100644 ---- a/src/plugins/preauth/securid_sam2/grail.c -+++ b/src/plugins/preauth/securid_sam2/grail.c -@@ -213,8 +213,7 @@ verify_grail_data(krb5_context context, krb5_db_entry *client, - return KRB5KDC_ERR_PREAUTH_FAILED; - - ret = krb5_dbe_find_enctype(context, client, -- sr2->sam_enc_nonce_or_sad.enctype, -- KRB5_KDB_SALTTYPE_NORMAL, -+ sr2->sam_enc_nonce_or_sad.enctype, -1, - sr2->sam_enc_nonce_or_sad.kvno, - &client_key_data); - if (ret) -diff --git a/src/plugins/preauth/securid_sam2/securid2.c b/src/plugins/preauth/securid_sam2/securid2.c -index ca99ce3ef..363e17a10 100644 ---- a/src/plugins/preauth/securid_sam2/securid2.c -+++ b/src/plugins/preauth/securid_sam2/securid2.c -@@ -313,8 +313,7 @@ verify_securid_data_2(krb5_context context, krb5_db_entry *client, - } - - retval = krb5_dbe_find_enctype(context, client, -- sr2->sam_enc_nonce_or_sad.enctype, -- KRB5_KDB_SALTTYPE_NORMAL, -+ sr2->sam_enc_nonce_or_sad.enctype, -1, - sr2->sam_enc_nonce_or_sad.kvno, - &client_key_data); - if (retval) { diff --git a/Fix-segfault-in-finish_dispatch.patch b/Fix-segfault-in-finish_dispatch.patch deleted file mode 100644 index ff28848..0000000 --- a/Fix-segfault-in-finish_dispatch.patch +++ /dev/null @@ -1,133 +0,0 @@ -From 617d153bb32d0bd7db33ccec21043d1113651f3a Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 18 Apr 2018 14:13:28 -0400 -Subject: [PATCH] Fix segfault in finish_dispatch() - -dispatch() doesn't necessarily initialize state->active_realm which -led to an explicit NULL dereference in finish_dispatch(). - -Additionally, fix make_too_big_error() so that it won't subsequently -dereference state->active_realm. - -tags: pullup -target_version: 1.16-next -target_version: 1.15-next ---- - src/kdc/dispatch.c | 79 ++++++++++++++++++++++++---------------------- - 1 file changed, 42 insertions(+), 37 deletions(-) - -diff --git a/src/kdc/dispatch.c b/src/kdc/dispatch.c -index 3ed5176a8..fb3686c98 100644 ---- a/src/kdc/dispatch.c -+++ b/src/kdc/dispatch.c -@@ -35,9 +35,6 @@ - - static krb5_int32 last_usec = 0, last_os_random = 0; - --static krb5_error_code make_too_big_error(kdc_realm_t *kdc_active_realm, -- krb5_data **out); -- - struct dispatch_state { - loop_respond_fn respond; - void *arg; -@@ -47,6 +44,41 @@ struct dispatch_state { - krb5_context kdc_err_context; - }; - -+ -+static krb5_error_code -+make_too_big_error(krb5_context context, krb5_principal tgsprinc, -+ krb5_data **out) -+{ -+ krb5_error errpkt; -+ krb5_error_code retval; -+ krb5_data *scratch; -+ -+ *out = NULL; -+ memset(&errpkt, 0, sizeof(errpkt)); -+ -+ retval = krb5_us_timeofday(context, &errpkt.stime, &errpkt.susec); -+ if (retval) -+ return retval; -+ errpkt.error = KRB_ERR_RESPONSE_TOO_BIG; -+ errpkt.server = tgsprinc; -+ errpkt.client = NULL; -+ errpkt.text.length = 0; -+ errpkt.text.data = 0; -+ errpkt.e_data.length = 0; -+ errpkt.e_data.data = 0; -+ scratch = malloc(sizeof(*scratch)); -+ if (scratch == NULL) -+ return ENOMEM; -+ retval = krb5_mk_error(context, &errpkt, scratch); -+ if (retval) { -+ free(scratch); -+ return retval; -+ } -+ -+ *out = scratch; -+ return 0; -+} -+ - static void - finish_dispatch(struct dispatch_state *state, krb5_error_code code, - krb5_data *response) -@@ -54,12 +86,17 @@ finish_dispatch(struct dispatch_state *state, krb5_error_code code, - loop_respond_fn oldrespond = state->respond; - void *oldarg = state->arg; - kdc_realm_t *kdc_active_realm = state->active_realm; -+ krb5_principal tgsprinc = NULL; -+ -+ if (kdc_active_realm != NULL) -+ tgsprinc = kdc_active_realm->realm_tgsprinc; - - if (state->is_tcp == 0 && response && - response->length > (unsigned int)max_dgram_reply_size) { -- krb5_free_data(kdc_context, response); -+ krb5_free_data(state->kdc_err_context, response); - response = NULL; -- code = make_too_big_error(kdc_active_realm, &response); -+ code = make_too_big_error(state->kdc_err_context, tgsprinc, -+ &response); - if (code) - krb5_klog_syslog(LOG_ERR, "error constructing " - "KRB_ERR_RESPONSE_TOO_BIG error: %s", -@@ -208,38 +245,6 @@ done: - finish_dispatch_cache(state, retval, response); - } - --static krb5_error_code --make_too_big_error(kdc_realm_t *kdc_active_realm, krb5_data **out) --{ -- krb5_error errpkt; -- krb5_error_code retval; -- krb5_data *scratch; -- -- *out = NULL; -- memset(&errpkt, 0, sizeof(errpkt)); -- -- retval = krb5_us_timeofday(kdc_context, &errpkt.stime, &errpkt.susec); -- if (retval) -- return retval; -- errpkt.error = KRB_ERR_RESPONSE_TOO_BIG; -- errpkt.server = tgs_server; -- errpkt.client = NULL; -- errpkt.text.length = 0; -- errpkt.text.data = 0; -- errpkt.e_data.length = 0; -- errpkt.e_data.data = 0; -- scratch = malloc(sizeof(*scratch)); -- if (scratch == NULL) -- return ENOMEM; -- retval = krb5_mk_error(kdc_context, &errpkt, scratch); -- if (retval) { -- free(scratch); -- return retval; -- } -- -- *out = scratch; -- return 0; --} - - krb5_context get_context(void *handle) - { diff --git a/Fix-some-broken-tests-for-Python-3.patch b/Fix-some-broken-tests-for-Python-3.patch deleted file mode 100644 index 42825b0..0000000 --- a/Fix-some-broken-tests-for-Python-3.patch +++ /dev/null @@ -1,81 +0,0 @@ -From eb60404564852a262d4082c3e38086742afb1bd9 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 16 Jul 2018 16:44:01 -0400 -Subject: [PATCH] Fix some broken tests for Python 3 - -Remove python2 dependencies in .travis.yml and add python3-paste. -Convert t_daemon.py and jsonwalker.py to python3. csjon has no -python3 version, so replace it with python's built-in JSON module. - -python3-pyrad isn't available for Trusty, so krad and OTP tests are -currently not exercised by Travis. - -[ghudson@mit.edu: squashed commits; edited commit message] - -ticket: 8710 -(cherry picked from commit d1fb3551c0dff5c3e6555b31fcbf04ff04d577fe) -[rharwood@redhat.com: .travis.yml] ---- - src/lib/krad/t_daemon.py | 2 +- - src/tests/jsonwalker.py | 16 +++++----------- - 2 files changed, 6 insertions(+), 12 deletions(-) - -diff --git a/src/lib/krad/t_daemon.py b/src/lib/krad/t_daemon.py -index 7d7a5d0c8..7668cd7f8 100755 ---- a/src/lib/krad/t_daemon.py -+++ b/src/lib/krad/t_daemon.py -@@ -23,7 +23,7 @@ - # NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS - # SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. - --import StringIO -+from io import StringIO - import os - import sys - import signal -diff --git a/src/tests/jsonwalker.py b/src/tests/jsonwalker.py -index 7a0675e08..1880363d2 100644 ---- a/src/tests/jsonwalker.py -+++ b/src/tests/jsonwalker.py -@@ -1,10 +1,5 @@ - import sys --try: -- import cjson --except ImportError: -- print("Warning: skipping audit log verification because the cjson module" \ -- " is unavailable") -- sys.exit(0) -+import json - from collections import defaultdict - from optparse import OptionParser - -@@ -72,7 +67,7 @@ class Parser(object): - """ - Generator that works through dictionary. - """ -- for a,v in adict.iteritems(): -+ for a,v in adict.items(): - if isinstance(v,dict): - for (attrpath,u) in self._walk(v): - yield (a+'.'+attrpath,u) -@@ -93,17 +88,16 @@ if __name__ == '__main__': - with open(options.filename, 'r') as f: - content = list() - for l in f: -- content.append(cjson.decode(l.rstrip())) -+ content.append(json.loads(l.rstrip())) - f.close() - else: -- print('Input file in jason format is required') -+ print('Input file in JSON format is required') - exit() - - defaults = None - if options.defaults is not None: - with open(options.defaults, 'r') as f: -- defaults = cjson.decode(f.read()) -- f.close() -+ defaults = json.load(f) - - # run test - p = Parser(defaults) diff --git a/Implement-k5_buf_init_dynamic_zap.patch b/Implement-k5_buf_init_dynamic_zap.patch deleted file mode 100644 index 28fd16b..0000000 --- a/Implement-k5_buf_init_dynamic_zap.patch +++ /dev/null @@ -1,149 +0,0 @@ -From 3d651a6e234bed4c4d4865a56c5fa47dab89a5a6 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 26 Mar 2018 11:12:39 -0400 -Subject: [PATCH] Implement k5_buf_init_dynamic_zap - -Add a variant of dynamic k5buf objects which zeroes memory when -reallocating or freeing the buffer. - -(cherry picked from commit 8ee8246c14702dc03b02e31b9fb5b7c2bb674bfb) ---- - src/include/k5-buf.h | 6 ++- - src/util/support/k5buf.c | 41 +++++++++++++++---- - src/util/support/libkrb5support-fixed.exports | 1 + - 3 files changed, 39 insertions(+), 9 deletions(-) - -diff --git a/src/include/k5-buf.h b/src/include/k5-buf.h -index 1223916a6..48e2a7d53 100644 ---- a/src/include/k5-buf.h -+++ b/src/include/k5-buf.h -@@ -45,7 +45,7 @@ - */ - - /* Buffer type values */ --enum k5buftype { K5BUF_ERROR, K5BUF_FIXED, K5BUF_DYNAMIC }; -+enum k5buftype { K5BUF_ERROR, K5BUF_FIXED, K5BUF_DYNAMIC, K5BUF_DYNAMIC_ZAP }; - - struct k5buf { - enum k5buftype buftype; -@@ -63,6 +63,10 @@ void k5_buf_init_fixed(struct k5buf *buf, char *data, size_t space); - /* Initialize a k5buf using an internally allocated dynamic buffer. */ - void k5_buf_init_dynamic(struct k5buf *buf); - -+/* Initialize a k5buf using an internally allocated dynamic buffer, zeroing -+ * memory when reallocating or freeing. */ -+void k5_buf_init_dynamic_zap(struct k5buf *buf); -+ - /* Add a C string to BUF. */ - void k5_buf_add(struct k5buf *buf, const char *data); - -diff --git a/src/util/support/k5buf.c b/src/util/support/k5buf.c -index 35978f238..b2b5e5b67 100644 ---- a/src/util/support/k5buf.c -+++ b/src/util/support/k5buf.c -@@ -37,7 +37,7 @@ - /* - * Structure invariants: - * -- * buftype is K5BUF_FIXED, K5BUF_DYNAMIC, or K5BUF_ERROR -+ * buftype is K5BUF_FIXED, K5BUF_DYNAMIC, K5BUF_DYNAMIC_ZAP, or K5BUF_ERROR - * if buftype is K5BUF_ERROR, the other fields are NULL or 0 - * if buftype is not K5BUF_ERROR: - * space > 0 -@@ -77,22 +77,35 @@ ensure_space(struct k5buf *buf, size_t len) - return 1; - if (buf->buftype == K5BUF_FIXED) /* Can't resize a fixed buffer. */ - goto error_exit; -- assert(buf->buftype == K5BUF_DYNAMIC); -+ assert(buf->buftype == K5BUF_DYNAMIC || buf->buftype == K5BUF_DYNAMIC_ZAP); - new_space = buf->space * 2; - while (new_space - buf->len - 1 < len) { - if (new_space > SIZE_MAX / 2) - goto error_exit; - new_space *= 2; - } -- new_data = realloc(buf->data, new_space); -- if (new_data == NULL) -- goto error_exit; -+ if (buf->buftype == K5BUF_DYNAMIC_ZAP) { -+ /* realloc() could leave behind a partial copy of sensitive data. */ -+ new_data = malloc(new_space); -+ if (new_data == NULL) -+ goto error_exit; -+ memcpy(new_data, buf->data, buf->len); -+ new_data[buf->len] = '\0'; -+ zap(buf->data, buf->len); -+ free(buf->data); -+ } else { -+ new_data = realloc(buf->data, new_space); -+ if (new_data == NULL) -+ goto error_exit; -+ } - buf->data = new_data; - buf->space = new_space; - return 1; - - error_exit: -- if (buf->buftype == K5BUF_DYNAMIC) -+ if (buf->buftype == K5BUF_DYNAMIC_ZAP) -+ zap(buf->data, buf->len); -+ if (buf->buftype == K5BUF_DYNAMIC_ZAP || buf->buftype == K5BUF_DYNAMIC) - free(buf->data); - set_error(buf); - return 0; -@@ -123,6 +136,14 @@ k5_buf_init_dynamic(struct k5buf *buf) - *endptr(buf) = '\0'; - } - -+void -+k5_buf_init_dynamic_zap(struct k5buf *buf) -+{ -+ k5_buf_init_dynamic(buf); -+ if (buf->buftype == K5BUF_DYNAMIC) -+ buf->buftype = K5BUF_DYNAMIC_ZAP; -+} -+ - void - k5_buf_add(struct k5buf *buf, const char *data) - { -@@ -163,7 +184,7 @@ k5_buf_add_vfmt(struct k5buf *buf, const char *fmt, va_list ap) - } - - /* Optimistically format the data directly into the dynamic buffer. */ -- assert(buf->buftype == K5BUF_DYNAMIC); -+ assert(buf->buftype == K5BUF_DYNAMIC || buf->buftype == K5BUF_DYNAMIC_ZAP); - va_copy(apcopy, ap); - r = vsnprintf(endptr(buf), remaining, fmt, apcopy); - va_end(apcopy); -@@ -197,6 +218,8 @@ k5_buf_add_vfmt(struct k5buf *buf, const char *fmt, va_list ap) - memcpy(endptr(buf), tmp, r + 1); - buf->len += r; - } -+ if (buf->buftype == K5BUF_DYNAMIC_ZAP) -+ zap(tmp, strlen(tmp)); - free(tmp); - } - -@@ -241,7 +264,9 @@ k5_buf_free(struct k5buf *buf) - { - if (buf->buftype == K5BUF_ERROR) - return; -- assert(buf->buftype == K5BUF_DYNAMIC); -+ assert(buf->buftype == K5BUF_DYNAMIC || buf->buftype == K5BUF_DYNAMIC_ZAP); -+ if (buf->buftype == K5BUF_DYNAMIC_ZAP) -+ zap(buf->data, buf->len); - free(buf->data); - set_error(buf); - } -diff --git a/src/util/support/libkrb5support-fixed.exports b/src/util/support/libkrb5support-fixed.exports -index cb9bf0826..a5e2ade04 100644 ---- a/src/util/support/libkrb5support-fixed.exports -+++ b/src/util/support/libkrb5support-fixed.exports -@@ -3,6 +3,7 @@ k5_base64_encode - k5_bcmp - k5_buf_init_fixed - k5_buf_init_dynamic -+k5_buf_init_dynamic_zap - k5_buf_add - k5_buf_add_len - k5_buf_add_fmt diff --git a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch b/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch index 73ac10d..2e5969f 100644 --- a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch +++ b/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch @@ -1,4 +1,4 @@ -From a9f547544ae43c2a71f21cab4fa61388c2f67553 Mon Sep 17 00:00:00 2001 +From 9bb35cc29293de37ef92bf151a601884e602eb39 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 31 Jul 2018 13:47:26 -0400 Subject: [PATCH] In FIPS mode, add plaintext fallback for RC4 usages and taint diff --git a/Include-etype-info-in-for-hardware-preauth-hints.patch b/Include-etype-info-in-for-hardware-preauth-hints.patch deleted file mode 100644 index 82aba62..0000000 --- a/Include-etype-info-in-for-hardware-preauth-hints.patch +++ /dev/null @@ -1,38 +0,0 @@ -From bbc68d1657306a61a7646dd7b9690f67705e24be Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 3 Jan 2018 11:59:14 -0500 -Subject: [PATCH] Include etype-info in for hardware preauth hints - -If a principal has the requires_hwauth bit set, include PA-ETYPE-INFO -or PA-ETYPE-INFO2 padata in the PREAUTH_REQUIRED error, as preauth -mechs involving hardware tokens may also use the principal's Kerberos -password. - -ticket: 8629 -(cherry picked from commit ba92da05accc524b8037453b63ced1a6c65fd2a1) ---- - src/kdc/kdc_preauth.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c -index 81d0b8cff..739c5e776 100644 ---- a/src/kdc/kdc_preauth.c -+++ b/src/kdc/kdc_preauth.c -@@ -144,7 +144,7 @@ static preauth_system static_preauth_systems[] = { - { - "etype-info", - KRB5_PADATA_ETYPE_INFO, -- 0, -+ PA_HARDWARE, - NULL, - NULL, - NULL, -@@ -155,7 +155,7 @@ static preauth_system static_preauth_systems[] = { - { - "etype-info2", - KRB5_PADATA_ETYPE_INFO2, -- 0, -+ PA_HARDWARE, - NULL, - NULL, - NULL, diff --git a/Include-preauth-name-in-trace-output-if-possible.patch b/Include-preauth-name-in-trace-output-if-possible.patch deleted file mode 100644 index fe88920..0000000 --- a/Include-preauth-name-in-trace-output-if-possible.patch +++ /dev/null @@ -1,514 +0,0 @@ -From b623881ec039bffc758f53906f7e4f9b884f1cf4 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 15 Mar 2018 14:37:28 -0400 -Subject: [PATCH] Include preauth name in trace output if possible - -Add a {patype} trace format specifier for a single pa-type value. Add -a krb5_preauthtype to string conversion function to trace machinery -and use it when formatting {patype} or {patypes}. - -[ghudson@mit.edu: wrote conversion function; edited commit message] - -ticket: 8653 (new) -(cherry picked from commit 9c68fe39b018666eabe033b639c1f35d03ba51c7) ---- - src/include/k5-trace.h | 17 +-- - src/lib/krb5/os/t_trace.ref | 2 +- - src/lib/krb5/os/trace.c | 61 +++++++++- - src/tests/t_pkinit.py | 43 +++---- - src/tests/t_preauth.py | 216 ++++++++++++++++++------------------ - 5 files changed, 200 insertions(+), 139 deletions(-) - -diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h -index 390a8b7d6..5f7eb9517 100644 ---- a/src/include/k5-trace.h -+++ b/src/include/k5-trace.h -@@ -75,6 +75,7 @@ - * {cksum} const krb5_checksum *, display cksumtype and hex checksum - * {princ} krb5_principal, unparse and display - * {ptype} krb5_int32, krb5_principal type, display name -+ * {patype} krb5_preauthtype, a single padata type number - * {patypes} krb5_pa_data **, display list of padata type numbers - * {etype} krb5_enctype, display shortest name of enctype - * {etypes} krb5_enctype *, display list of enctypes -@@ -232,14 +233,14 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); - #define TRACE_INIT_CREDS_PREAUTH_DECRYPT_FAIL(c, code) \ - TRACE(c, "Decrypt with preauth AS key failed: {kerr}", code) - #define TRACE_INIT_CREDS_PREAUTH_MORE(c, patype) \ -- TRACE(c, "Continuing preauth mech {int}", (int)patype) -+ TRACE(c, "Continuing preauth mech {patype}", patype) - #define TRACE_INIT_CREDS_PREAUTH_NONE(c) \ - TRACE(c, "Sending unauthenticated request") - #define TRACE_INIT_CREDS_PREAUTH_OPTIMISTIC(c) \ - TRACE(c, "Attempting optimistic preauth") - #define TRACE_INIT_CREDS_PREAUTH_TRYAGAIN(c, patype, code) \ -- TRACE(c, "Recovering from KDC error {int} using preauth mech {int}", \ -- (int)patype, (int)code) -+ TRACE(c, "Recovering from KDC error {int} using preauth mech {patype}", \ -+ patype, (int)code) - #define TRACE_INIT_CREDS_RESTART_FAST(c) \ - TRACE(c, "Restarting to upgrade to FAST") - #define TRACE_INIT_CREDS_RESTART_PREAUTH_FAILED(c) \ -@@ -290,7 +291,7 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); - - #define TRACE_PREAUTH_CONFLICT(c, name1, name2, patype) \ - TRACE(c, "Preauth module {str} conflicts with module {str} for pa " \ -- "type {int}", name1, name2, (int) patype) -+ "type {patype}", name1, name2, patype) - #define TRACE_PREAUTH_COOKIE(c, len, data) \ - TRACE(c, "Received cookie: {lenstr}", (size_t) len, data) - #define TRACE_PREAUTH_ENC_TS_KEY_GAK(c, keyblock) \ -@@ -302,8 +303,8 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); - TRACE(c, "Selected etype info: etype {etype}, salt \"{data}\", " \ - "params \"{data}\"", etype, salt, s2kparams) - #define TRACE_PREAUTH_INFO_FAIL(c, patype, code) \ -- TRACE(c, "Preauth builtin info function failure, type={int}: {kerr}", \ -- (int) patype, code) -+ TRACE(c, "Preauth builtin info function failure, type={patype}: {kerr}", \ -+ patype, code) - #define TRACE_PREAUTH_INPUT(c, padata) \ - TRACE(c, "Processing preauth types: {patypes}", padata) - #define TRACE_PREAUTH_OUTPUT(c, padata) \ -@@ -314,8 +315,8 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); - #define TRACE_PREAUTH_SAM_KEY_GAK(c, keyblock) \ - TRACE(c, "AS key obtained for SAM: {keyblock}", keyblock) - #define TRACE_PREAUTH_SALT(c, salt, patype) \ -- TRACE(c, "Received salt \"{data}\" via padata type {int}", salt, \ -- (int) patype) -+ TRACE(c, "Received salt \"{data}\" via padata type {patype}", salt, \ -+ patype) - #define TRACE_PREAUTH_SKIP(c, name, patype) \ - TRACE(c, "Skipping previously used preauth module {str} ({int})", \ - name, (int) patype) -diff --git a/src/lib/krb5/os/t_trace.ref b/src/lib/krb5/os/t_trace.ref -index ca5818a1e..bd5d9b6b6 100644 ---- a/src/lib/krb5/os/t_trace.ref -+++ b/src/lib/krb5/os/t_trace.ref -@@ -38,7 +38,7 @@ int, krb5_principal type: Windows 2000 UPN and SID - int, krb5_principal type: NT 4 style name - int, krb5_principal type: NT 4 style name and SID - int, krb5_principal type: ? --krb5_pa_data **, display list of padata type numbers: 3, 0 -+krb5_pa_data **, display list of padata type numbers: PA-PW-SALT (3), 0 - krb5_pa_data **, display list of padata type numbers: (empty) - krb5_enctype, display shortest name of enctype: des-cbc-crc - krb5_enctype *, display list of enctypes: 5, rc4-hmac-exp, 511 -diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c -index 779f184cb..10b4f0c14 100644 ---- a/src/lib/krb5/os/trace.c -+++ b/src/lib/krb5/os/trace.c -@@ -123,6 +123,50 @@ principal_type_string(krb5_int32 type) - } - } - -+static char * -+padata_type_string(krb5_preauthtype type) -+{ -+ switch (type) { -+ case KRB5_PADATA_TGS_REQ: return "PA-TGS-REQ"; -+ case KRB5_PADATA_ENC_TIMESTAMP: return "PA-ENC-TIMESTAMP"; -+ case KRB5_PADATA_PW_SALT: return "PA-PW-SALT"; -+ case KRB5_PADATA_ENC_UNIX_TIME: return "PA-ENC-UNIX-TIME"; -+ case KRB5_PADATA_ENC_SANDIA_SECURID: return "PA-SANDIA-SECUREID"; -+ case KRB5_PADATA_SESAME: return "PA-SESAME"; -+ case KRB5_PADATA_OSF_DCE: return "PA-OSF-DCE"; -+ case KRB5_CYBERSAFE_SECUREID: return "PA-CYBERSAFE-SECUREID"; -+ case KRB5_PADATA_AFS3_SALT: return "PA-AFS3-SALT"; -+ case KRB5_PADATA_ETYPE_INFO: return "PA-ETYPE-INFO"; -+ case KRB5_PADATA_SAM_CHALLENGE: return "PA-SAM-CHALLENGE"; -+ case KRB5_PADATA_SAM_RESPONSE: return "PA-SAM-RESPONSE"; -+ case KRB5_PADATA_PK_AS_REQ_OLD: return "PA-PK-AS-REQ_OLD"; -+ case KRB5_PADATA_PK_AS_REP_OLD: return "PA-PK-AS-REP_OLD"; -+ case KRB5_PADATA_PK_AS_REQ: return "PA-PK-AS-REQ"; -+ case KRB5_PADATA_PK_AS_REP: return "PA-PK-AS-REP"; -+ case KRB5_PADATA_ETYPE_INFO2: return "PA-ETYPE-INFO2"; -+ case KRB5_PADATA_SVR_REFERRAL_INFO: return "PA-SVR-REFERRAL-INFO"; -+ case KRB5_PADATA_SAM_REDIRECT: return "PA-SAM-REDIRECT"; -+ case KRB5_PADATA_GET_FROM_TYPED_DATA: return "PA-GET-FROM-TYPED-DATA"; -+ case KRB5_PADATA_SAM_CHALLENGE_2: return "PA-SAM-CHALLENGE2"; -+ case KRB5_PADATA_SAM_RESPONSE_2: return "PA-SAM-RESPONSE2"; -+ case KRB5_PADATA_PAC_REQUEST: return "PA-PAC-REQUEST"; -+ case KRB5_PADATA_FOR_USER: return "PA-FOR_USER"; -+ case KRB5_PADATA_S4U_X509_USER: return "PA-FOR-X509-USER"; -+ case KRB5_PADATA_AS_CHECKSUM: return "PA-AS-CHECKSUM"; -+ case KRB5_PADATA_FX_COOKIE: return "PA-FX-COOKIE"; -+ case KRB5_PADATA_FX_FAST: return "PA-FX-FAST"; -+ case KRB5_PADATA_FX_ERROR: return "PA-FX-ERROR"; -+ case KRB5_PADATA_ENCRYPTED_CHALLENGE: return "PA-ENCRYPTED-CHALLENGE"; -+ case KRB5_PADATA_OTP_CHALLENGE: return "PA-OTP-CHALLENGE"; -+ case KRB5_PADATA_OTP_REQUEST: return "PA-OTP-REQUEST"; -+ case KRB5_PADATA_OTP_PIN_CHANGE: return "PA-OTP-PIN-CHANGE"; -+ case KRB5_PADATA_PKINIT_KX: return "PA-PKINIT-KX"; -+ case KRB5_ENCPADATA_REQ_ENC_PA_REP: return "PA-REQ-ENC-PA-REP"; -+ case KRB5_PADATA_AS_FRESHNESS: return "PA_AS_FRESHNESS"; -+ default: return NULL; -+ } -+} -+ - static char * - trace_format(krb5_context context, const char *fmt, va_list ap) - { -@@ -140,6 +184,8 @@ trace_format(krb5_context context, const char *fmt, va_list ap) - krb5_key key; - const krb5_checksum *cksum; - krb5_pa_data **padata; -+ krb5_preauthtype pa_type; -+ const char *name; - krb5_ccache ccache; - krb5_keytab keytab; - krb5_creds *creds; -@@ -271,10 +317,23 @@ trace_format(krb5_context context, const char *fmt, va_list ap) - if (padata == NULL || *padata == NULL) - k5_buf_add(&buf, "(empty)"); - for (; padata != NULL && *padata != NULL; padata++) { -- k5_buf_add_fmt(&buf, "%d", (int)(*padata)->pa_type); -+ pa_type = (*padata)->pa_type; -+ name = padata_type_string(pa_type); -+ if (name != NULL) -+ k5_buf_add_fmt(&buf, "%s (%d)", name, (int)pa_type); -+ else -+ k5_buf_add_fmt(&buf, "%d", (int)pa_type); -+ - if (*(padata + 1) != NULL) - k5_buf_add(&buf, ", "); - } -+ } else if (strcmp(tmpbuf, "patype") == 0) { -+ pa_type = va_arg(ap, krb5_preauthtype); -+ name = padata_type_string(pa_type); -+ if (name != NULL) -+ k5_buf_add_fmt(&buf, "%s (%d)", name, (int)pa_type); -+ else -+ k5_buf_add_fmt(&buf, "%d", (int)pa_type); - } else if (strcmp(tmpbuf, "etype") == 0) { - etype = va_arg(ap, krb5_enctype); - if (krb5_enctype_to_name(etype, TRUE, tmpbuf, sizeof(tmpbuf)) == 0) -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index 5bc60cb1e..0e964c689 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -164,18 +164,19 @@ realm.stop_kdc() - realm.start_kdc() - - # Run the basic test - PKINIT with FILE: identity, with no password on the key. -+msgs = ('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Preauthenticating using KDC method data', -+ 'PKINIT client received freshness token from KDC', -+ 'PKINIT loading CA certs and CRLs from FILE', -+ 'PKINIT client making DH request', -+ ' preauth for next request: PA-FX-COOKIE (133), PA-PK-AS-REQ (16)', -+ 'PKINIT client verified DH reply', -+ 'PKINIT client found id-pkinit-san in KDC cert', -+ 'PKINIT client matched KDC principal krbtgt/') - realm.kinit(realm.user_princ, - flags=['-X', 'X509_user_identity=%s' % file_identity], -- expected_trace=('Sending unauthenticated request', -- '/Additional pre-authentication required', -- 'Preauthenticating using KDC method data', -- 'PKINIT client received freshness token from KDC', -- 'PKINIT loading CA certs and CRLs from FILE', -- 'PKINIT client making DH request', -- 'Produced preauth for next request: 133, 16', -- 'PKINIT client verified DH reply', -- 'PKINIT client found id-pkinit-san in KDC cert', -- 'PKINIT client matched KDC principal krbtgt/')) -+ expected_trace=msgs) - realm.klist(realm.user_princ) - realm.run([kvno, realm.host_princ]) - -@@ -194,19 +195,19 @@ minbits_kdc_conf = {'realms': {'$realm': {'pkinit_dh_min_bits': '4096'}}} - minbits_env = realm.special_env('restrict', True, kdc_conf=minbits_kdc_conf) - realm.stop_kdc() - realm.start_kdc(env=minbits_env) --expected_trace = ('Sending unauthenticated request', -- '/Additional pre-authentication required', -- 'Preauthenticating using KDC method data', -- 'Preauth module pkinit (16) (real) returned: 0/Success', -- 'Produced preauth for next request: 133, 16', -- '/Key parameters not accepted', -- 'Preauth tryagain input types (16): 109, 133', -- 'trying again with KDC-provided parameters', -- 'Preauth module pkinit (16) tryagain returned: 0/Success', -- 'Followup preauth for next request: 16, 133') -+msgs = ('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Preauthenticating using KDC method data', -+ 'Preauth module pkinit (16) (real) returned: 0/Success', -+ ' preauth for next request: PA-FX-COOKIE (133), PA-PK-AS-REQ (16)', -+ '/Key parameters not accepted', -+ 'Preauth tryagain input types (16): 109, PA-FX-COOKIE (133)', -+ 'trying again with KDC-provided parameters', -+ 'Preauth module pkinit (16) tryagain returned: 0/Success', -+ ' preauth for next request: PA-PK-AS-REQ (16), PA-FX-COOKIE (133)') - realm.kinit(realm.user_princ, - flags=['-X', 'X509_user_identity=%s' % file_identity], -- expected_trace=expected_trace) -+ expected_trace=msgs) - - # Test enforcement of required freshness tokens. (We can leave - # freshness tokens required after this test.) -diff --git a/src/tests/t_preauth.py b/src/tests/t_preauth.py -index fec0bf619..efb3ea20d 100644 ---- a/src/tests/t_preauth.py -+++ b/src/tests/t_preauth.py -@@ -18,15 +18,15 @@ realm.kinit('nokeyuser', password('user'), expected_code=1, - # PA-FX-COOKIE; 2 is encrypted timestamp. - - # Test normal preauth flow. --expected_trace = ('Sending unauthenticated request', -- '/Additional pre-authentication required', -- 'Preauthenticating using KDC method data', -- 'Processing preauth types:', -- 'Preauth module test (-123) (real) returned: 0/Success', -- 'Produced preauth for next request: 133, -123', -- 'Decrypted AS reply') -+msgs = ('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Preauthenticating using KDC method data', -+ 'Processing preauth types:', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ 'Decrypted AS reply') - realm.run(['./icred', realm.user_princ, password('user')], -- expected_msg='testval', expected_trace=expected_trace) -+ expected_msg='testval', expected_trace=msgs) - - # Test successful optimistic preauth. - expected_trace = ('Attempting optimistic preauth', -@@ -39,136 +39,136 @@ realm.run(['./icred', '-o', '-123', realm.user_princ, password('user')], - - # Test optimistic preauth failing on client, followed by successful - # preauth using the same module. --expected_trace = ('Attempting optimistic preauth', -- 'Processing preauth types: -123', -- '/induced optimistic fail', -- 'Sending unauthenticated request', -- '/Additional pre-authentication required', -- 'Preauthenticating using KDC method data', -- 'Processing preauth types:', -- 'Preauth module test (-123) (real) returned: 0/Success', -- 'Produced preauth for next request: 133, -123', -- 'Decrypted AS reply') -+msgs = ('Attempting optimistic preauth', -+ 'Processing preauth types: -123', -+ '/induced optimistic fail', -+ 'Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Preauthenticating using KDC method data', -+ 'Processing preauth types:', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ 'Decrypted AS reply') - realm.run(['./icred', '-o', '-123', '-X', 'fail_optimistic', realm.user_princ, - password('user')], expected_msg='testval', -- expected_trace=expected_trace) -+ expected_trace=msgs) - - # Test optimistic preauth failing on KDC, followed by successful preauth - # using the same module. - realm.run([kadminl, 'setstr', realm.user_princ, 'failopt', 'yes']) --expected_trace = ('Attempting optimistic preauth', -- 'Processing preauth types: -123', -- 'Preauth module test (-123) (real) returned: 0/Success', -- 'Produced preauth for next request: -123', -- '/Preauthentication failed', -- 'Preauthenticating using KDC method data', -- 'Processing preauth types:', -- 'Preauth module test (-123) (real) returned: 0/Success', -- 'Produced preauth for next request: 133, -123', -- 'Decrypted AS reply') -+msgs = ('Attempting optimistic preauth', -+ 'Processing preauth types: -123', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: -123', -+ '/Preauthentication failed', -+ 'Preauthenticating using KDC method data', -+ 'Processing preauth types:', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ 'Decrypted AS reply') - realm.run(['./icred', '-o', '-123', realm.user_princ, password('user')], -- expected_msg='testval', expected_trace=expected_trace) -+ expected_msg='testval', expected_trace=msgs) - realm.run([kadminl, 'delstr', realm.user_princ, 'failopt']) - - # Test KDC_ERR_MORE_PREAUTH_DATA_REQUIRED and secure cookies. - realm.run([kadminl, 'setstr', realm.user_princ, '2rt', 'secondtrip']) --expected_trace = ('Sending unauthenticated request', -- '/Additional pre-authentication required', -- 'Preauthenticating using KDC method data', -- 'Processing preauth types:', -- 'Preauth module test (-123) (real) returned: 0/Success', -- 'Produced preauth for next request: 133, -123', -- '/More preauthentication data is required', -- 'Continuing preauth mech -123', -- 'Processing preauth types: -123, 133', -- 'Produced preauth for next request: 133, -123', -- 'Decrypted AS reply') -+msgs = ('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Preauthenticating using KDC method data', -+ 'Processing preauth types:', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ '/More preauthentication data is required', -+ 'Continuing preauth mech -123', -+ 'Processing preauth types: -123, PA-FX-COOKIE (133)', -+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ 'Decrypted AS reply') - realm.run(['./icred', realm.user_princ, password('user')], -- expected_msg='2rt: secondtrip', expected_trace=expected_trace) -+ expected_msg='2rt: secondtrip', expected_trace=msgs) - - # Test client-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED, - # falling back to encrypted timestamp. --expected_trace = ('Sending unauthenticated request', -- '/Additional pre-authentication required', -- 'Preauthenticating using KDC method data', -- 'Processing preauth types:', -- 'Preauth module test (-123) (real) returned: 0/Success', -- 'Produced preauth for next request: 133, -123', -- '/More preauthentication data is required', -- 'Continuing preauth mech -123', -- 'Processing preauth types: -123, 133', -- '/induced 2rt fail', -- 'Preauthenticating using KDC method data', -- 'Processing preauth types:', -- 'Encrypted timestamp (for ', -- 'module encrypted_timestamp (2) (real) returned: 0/Success', -- 'Produced preauth for next request: 133, 2', -- 'Decrypted AS reply') -+msgs = ('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Preauthenticating using KDC method data', -+ 'Processing preauth types:', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ '/More preauthentication data is required', -+ 'Continuing preauth mech -123', -+ 'Processing preauth types: -123, PA-FX-COOKIE (133)', -+ '/induced 2rt fail', -+ 'Preauthenticating using KDC method data', -+ 'Processing preauth types:', -+ 'Encrypted timestamp (for ', -+ 'module encrypted_timestamp (2) (real) returned: 0/Success', -+ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', -+ 'Decrypted AS reply') - realm.run(['./icred', '-X', 'fail_2rt', realm.user_princ, password('user')], -- expected_msg='2rt: secondtrip', expected_trace=expected_trace) -+ expected_msg='2rt: secondtrip', expected_trace=msgs) - - # Test KDC-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED, - # falling back to encrypted timestamp. - realm.run([kadminl, 'setstr', realm.user_princ, 'fail2rt', 'yes']) --expected_trace = ('Sending unauthenticated request', -- '/Additional pre-authentication required', -- 'Preauthenticating using KDC method data', -- 'Processing preauth types:', -- 'Preauth module test (-123) (real) returned: 0/Success', -- 'Produced preauth for next request: 133, -123', -- '/More preauthentication data is required', -- 'Continuing preauth mech -123', -- 'Processing preauth types: -123, 133', -- 'Preauth module test (-123) (real) returned: 0/Success', -- 'Produced preauth for next request: 133, -123', -- '/Preauthentication failed', -- 'Preauthenticating using KDC method data', -- 'Processing preauth types:', -- 'Encrypted timestamp (for ', -- 'module encrypted_timestamp (2) (real) returned: 0/Success', -- 'Produced preauth for next request: 133, 2', -- 'Decrypted AS reply') -+msgs = ('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Preauthenticating using KDC method data', -+ 'Processing preauth types:', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ '/More preauthentication data is required', -+ 'Continuing preauth mech -123', -+ 'Processing preauth types: -123, PA-FX-COOKIE (133)', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ '/Preauthentication failed', -+ 'Preauthenticating using KDC method data', -+ 'Processing preauth types:', -+ 'Encrypted timestamp (for ', -+ 'module encrypted_timestamp (2) (real) returned: 0/Success', -+ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', -+ 'Decrypted AS reply') - realm.run(['./icred', realm.user_princ, password('user')], -- expected_msg='2rt: secondtrip', expected_trace=expected_trace) -+ expected_msg='2rt: secondtrip', expected_trace=msgs) - realm.run([kadminl, 'delstr', realm.user_princ, 'fail2rt']) - - # Test tryagain flow by inducing a KDC_ERR_ENCTYPE_NOSUPP error on the KDC. - realm.run([kadminl, 'setstr', realm.user_princ, 'err', 'testagain']) --expected_trace = ('Sending unauthenticated request', -- '/Additional pre-authentication required', -- 'Preauthenticating using KDC method data', -- 'Processing preauth types:', -- 'Preauth module test (-123) (real) returned: 0/Success', -- 'Produced preauth for next request: 133, -123', -- '/KDC has no support for encryption type', -- 'Recovering from KDC error 14 using preauth mech -123', -- 'Preauth tryagain input types (-123): -123, 133', -- 'Preauth module test (-123) tryagain returned: 0/Success', -- 'Followup preauth for next request: -123, 133', -- 'Decrypted AS reply') -+msgs = ('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Preauthenticating using KDC method data', -+ 'Processing preauth types:', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ '/KDC has no support for encryption type', -+ 'Recovering from KDC error 14 using preauth mech -123', -+ 'Preauth tryagain input types (-123): -123, PA-FX-COOKIE (133)', -+ 'Preauth module test (-123) tryagain returned: 0/Success', -+ 'Followup preauth for next request: -123, PA-FX-COOKIE (133)', -+ 'Decrypted AS reply') - realm.run(['./icred', realm.user_princ, password('user')], -- expected_msg='tryagain: testagain', expected_trace=expected_trace) -+ expected_msg='tryagain: testagain', expected_trace=msgs) - - # Test a client-side tryagain failure, falling back to encrypted - # timestamp. --expected_trace = ('Sending unauthenticated request', -- '/Additional pre-authentication required', -- 'Preauthenticating using KDC method data', -- 'Processing preauth types:', -- 'Preauth module test (-123) (real) returned: 0/Success', -- 'Produced preauth for next request: 133, -123', -- '/KDC has no support for encryption type', -- 'Recovering from KDC error 14 using preauth mech -123', -- 'Preauth tryagain input types (-123): -123, 133', -- '/induced tryagain fail', -- 'Preauthenticating using KDC method data', -- 'Processing preauth types:', -- 'Encrypted timestamp (for ', -- 'module encrypted_timestamp (2) (real) returned: 0/Success', -- 'Produced preauth for next request: 133, 2', -- 'Decrypted AS reply') -+msgs = ('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Preauthenticating using KDC method data', -+ 'Processing preauth types:', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ '/KDC has no support for encryption type', -+ 'Recovering from KDC error 14 using preauth mech -123', -+ 'Preauth tryagain input types (-123): -123, PA-FX-COOKIE (133)', -+ '/induced tryagain fail', -+ 'Preauthenticating using KDC method data', -+ 'Processing preauth types:', -+ 'Encrypted timestamp (for ', -+ 'module encrypted_timestamp (2) (real) returned: 0/Success', -+ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', -+ 'Decrypted AS reply') - realm.run(['./icred', '-X', 'fail_tryagain', realm.user_princ, -- password('user')], expected_trace=expected_trace) -+ password('user')], expected_trace=msgs) - - # Test that multiple stepwise initial creds operations can be - # performed with the same krb5_context, with proper tracking of diff --git a/Log-when-non-root-ksu-authorization-fails.patch b/Log-when-non-root-ksu-authorization-fails.patch deleted file mode 100644 index 704b5a9..0000000 --- a/Log-when-non-root-ksu-authorization-fails.patch +++ /dev/null @@ -1,35 +0,0 @@ -From 9dd3a84f324979c29e8ab4b472e98dfa73e6b290 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 7 May 2018 16:42:59 -0400 -Subject: [PATCH] Log when non-root ksu authorization fails - -If non-root user attempts to ksu but is denied by policy, log to -syslog at LOG_WARNING in keeping with other failure messages. - -ticket: 8270 -(cherry picked from commit 6cfa5c113e981f14f70ccafa20abfa5c46b665ba) ---- - src/clients/ksu/main.c | 10 ++++++++++ - 1 file changed, 10 insertions(+) - -diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c -index c6321c01b..35ff8978f 100644 ---- a/src/clients/ksu/main.c -+++ b/src/clients/ksu/main.c -@@ -417,6 +417,16 @@ main (argc, argv) - if (hp){ - if (gb_err) fprintf(stderr, "%s", gb_err); - fprintf(stderr, _("account %s: authorization failed\n"), target_user); -+ -+ if (cmd != NULL) { -+ syslog(LOG_WARNING, -+ "Account %s: authorization for %s for execution of %s failed", -+ target_user, source_user, cmd); -+ } else { -+ syslog(LOG_WARNING, "Account %s: authorization of %s failed", -+ target_user, source_user); -+ } -+ - exit(1); - } - diff --git a/Make-docs-build-python3-compatible.patch b/Make-docs-build-python3-compatible.patch deleted file mode 100644 index 58a3e86..0000000 --- a/Make-docs-build-python3-compatible.patch +++ /dev/null @@ -1,36 +0,0 @@ -From 16c745b7e9e239535a8c71dc7022b477a5165e01 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 13 Jun 2018 15:07:48 -0400 -Subject: [PATCH] Make docs build python3-compatible - -python3 removed execfile(), which we use for loading version data and -paths information in docs. Call exec() directly instead. - -ticket: 8692 (new) -(cherry picked from commit a7c6d98480f1e33454173f88381921472d72f80a) ---- - doc/conf.py | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/doc/conf.py b/doc/conf.py -index 25ba214a8..0555808e6 100644 ---- a/doc/conf.py -+++ b/doc/conf.py -@@ -50,7 +50,7 @@ copyright = u'1985-2018, MIT' - # The version info for the project you're documenting, acts as replacement for - # |version| and |release|, also used in various other places throughout the - # built documents. --execfile("version.py") -+exec(open("version.py").read()) - # The short X.Y version. - r_list = [r_major, r_minor] - if r_patch: -@@ -238,7 +238,7 @@ if 'mansubs' in tags: - ckeytab = '``@CKTNAME@``' - elif 'pathsubs' in tags: - # Read configured paths from a file produced by the build system. -- execfile('paths.py') -+ exec(open("paths.py").read()) - else: - bindir = ':ref:`BINDIR `' - sbindir = ':ref:`SBINDIR `' diff --git a/Make-krb5kdc-p-affect-TCP-ports.patch b/Make-krb5kdc-p-affect-TCP-ports.patch deleted file mode 100644 index ac5bc30..0000000 --- a/Make-krb5kdc-p-affect-TCP-ports.patch +++ /dev/null @@ -1,67 +0,0 @@ -From 5587c1de938324faa1871e08ccfc835415acb443 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 17 Jul 2018 11:29:19 -0400 -Subject: [PATCH] Make krb5kdc -p affect TCP ports - -Now that the KDC listens for TCP connections by default (ticket 6731), -the "-p" option should affect both UDP and TCP default listening -ports. - -ticket: 8715 (new) -(cherry picked from commit eb514587acc5c357bf0f554199bf0489b5515f8b) ---- - doc/admin/admin_commands/krb5kdc.rst | 12 ++++++------ - src/kdc/main.c | 12 ++++-------- - 2 files changed, 10 insertions(+), 14 deletions(-) - -diff --git a/doc/admin/admin_commands/krb5kdc.rst b/doc/admin/admin_commands/krb5kdc.rst -index 7ec4ee4d3..bda2c015c 100644 ---- a/doc/admin/admin_commands/krb5kdc.rst -+++ b/doc/admin/admin_commands/krb5kdc.rst -@@ -57,12 +57,12 @@ The **-P** *pid_file* option tells the KDC to write its PID into - the KDC is still running and to allow init scripts to stop the correct - process. - --The **-p** *portnum* option specifies the default UDP port numbers --which the KDC should listen on for Kerberos version 5 requests, as a --comma-separated list. This value overrides the UDP port numbers --specified in the :ref:`kdcdefaults` section of :ref:`kdc.conf(5)`, but --may be overridden by realm-specific values. If no value is given from --any source, the default port is 88. -+The **-p** *portnum* option specifies the default UDP and TCP port -+numbers which the KDC should listen on for Kerberos version 5 -+requests, as a comma-separated list. This value overrides the port -+numbers specified in the :ref:`kdcdefaults` section of -+:ref:`kdc.conf(5)`, but may be overridden by realm-specific values. -+If no value is given from any source, the default port is 88. - - The **-w** *numworkers* option tells the KDC to fork *numworkers* - processes to listen to the KDC ports and process requests in parallel. -diff --git a/src/kdc/main.c b/src/kdc/main.c -index ccac3a759..89dac23ae 100644 ---- a/src/kdc/main.c -+++ b/src/kdc/main.c -@@ -793,19 +793,15 @@ initialize_realms(krb5_context kcontext, int argc, char **argv, - pid_file = optarg; - break; - case 'p': -- if (def_udp_listen) -- free(def_udp_listen); -+ free(def_udp_listen); -+ free(def_tcp_listen); - def_udp_listen = strdup(optarg); -- if (!def_udp_listen) { -+ def_tcp_listen = strdup(optarg); -+ if (def_udp_listen == NULL || def_tcp_listen == NULL) { - fprintf(stderr, _(" KDC cannot initialize. Not enough " - "memory\n")); - exit(1); - } --#if 0 /* not yet */ -- if (default_tcp_ports) -- free(default_tcp_ports); -- default_tcp_ports = strdup(optarg); --#endif - break; - case 'T': - time_offset = atoi(optarg); diff --git a/Modernize-kerberos-7.patch b/Modernize-kerberos-7.patch deleted file mode 100644 index f82b878..0000000 --- a/Modernize-kerberos-7.patch +++ /dev/null @@ -1,429 +0,0 @@ -From a6baae6bfddb5a56c64e19e5bff9f0455dc89e53 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 15 Oct 2018 13:20:30 -0400 -Subject: [PATCH] Modernize kerberos(7) - -Update environment variable descriptions, using env_variables.rst as a -guide. Replace the content in env_variables.rst with a pointer to -documentation at kerberos(7) so that we don't break external links and -don't duplicate content. - -Replace references to rlogin. Clarify and modernize other language. - -ticket: 8755 -(cherry picked from commit cdccdefa2d74d3abf5a8ae126e423af9d467d34f) ---- - doc/admin/env_variables.rst | 44 +------------ - doc/user/user_config/kerberos.rst | 106 ++++++++++++++++++------------ - src/man/kerberos.man | 104 +++++++++++++++++------------ - 3 files changed, 128 insertions(+), 126 deletions(-) - -diff --git a/doc/admin/env_variables.rst b/doc/admin/env_variables.rst -index 0c146d3e3..a2d15bea8 100644 ---- a/doc/admin/env_variables.rst -+++ b/doc/admin/env_variables.rst -@@ -1,46 +1,4 @@ - Environment variables - ===================== - --The following environment variables can be used during runtime: -- --**KRB5_CONFIG** -- Main Kerberos configuration file. Multiple filenames can be -- specified, separated by a colon; all files which are present will -- be read. (See :ref:`mitK5defaults` for the default path.) -- --**KRB5_KDC_PROFILE** -- KDC configuration file. (See :ref:`mitK5defaults` for the default -- name.) -- --**KRB5_KTNAME** -- Default keytab file name. (See :ref:`mitK5defaults` for the -- default name.) -- --**KRB5_CLIENT_KTNAME** -- Default client keytab file name. (See :ref:`mitK5defaults` for -- the default name.) -- --**KRB5CCNAME** -- Default name for the credentials cache file, in the form *type*\:\ -- *residual*. The type of the default cache may determine the -- availability of a cache collection. For instance, a default cache -- of type ``DIR`` causes caches within the directory to be present -- in the global cache collection. -- --**KRB5RCACHETYPE** -- Default replay cache type. Defaults to ``dfl``. A value of -- ``none`` disables the replay cache. -- --**KRB5RCACHEDIR** -- Default replay cache directory. (See :ref:`mitK5defaults` for the -- default location.) -- --**KPROP_PORT** -- :ref:`kprop(8)` port to use. Defaults to 754. -- --**KRB5_TRACE** -- Filename for trace-logging output (introduced in release 1.9). -- For example, ``env KRB5_TRACE=/dev/stdout kinit`` would send -- tracing information for kinit to ``/dev/stdout``. Some programs -- may ignore this variable (particularly setuid or login system -- programs). -+This content has moved to :ref:`kerberos(7)`. -diff --git a/doc/user/user_config/kerberos.rst b/doc/user/user_config/kerberos.rst -index 6c4453b3b..56412f099 100644 ---- a/doc/user/user_config/kerberos.rst -+++ b/doc/user/user_config/kerberos.rst -@@ -8,12 +8,12 @@ DESCRIPTION - - The Kerberos system authenticates individual users in a network - environment. After authenticating yourself to Kerberos, you can use --Kerberos-enabled programs without having to present passwords. -+Kerberos-enabled programs without having to present passwords or -+certificates to those programs. - --If you enter your username and :ref:`kinit(1)` responds with this --message: -+If you receive the following response from :ref:`kinit(1)`: - --kinit(v5): Client not found in Kerberos database while getting initial -+kinit: Client not found in Kerberos database while getting initial - credentials - - you haven't been registered as a Kerberos user. See your system -@@ -25,10 +25,13 @@ is the **instance**, which in the case of a user is usually null. - Some users may have privileged instances, however, such as ``root`` or - ``admin``. In the case of a service, the instance is the fully - qualified name of the machine on which it runs; i.e. there can be an --rlogin service running on the machine ABC, which is different from the --rlogin service running on the machine XYZ. The third part of a --Kerberos name is the **realm**. The realm corresponds to the Kerberos --service providing authentication for the principal. -+ssh service running on the machine ABC (ssh/ABC@REALM), which is -+different from the ssh service running on the machine XYZ -+(ssh/XYZ@REALM). The third part of a Kerberos name is the **realm**. -+The realm corresponds to the Kerberos service providing authentication -+for the principal. Realms are conventionally all-uppercase, and often -+match the end of hostnames in the realm (for instance, host01.example.com -+might be in realm EXAMPLE.COM). - - When writing a Kerberos name, the principal name is separated from the - instance (if not null) by a slash, and the realm (if not the local -@@ -43,64 +46,72 @@ of valid Kerberos names:: - When you authenticate yourself with Kerberos you get an initial - Kerberos **ticket**. (A Kerberos ticket is an encrypted protocol - message that provides authentication.) Kerberos uses this ticket for --network utilities such as rlogin and rcp. The ticket transactions are --done transparently, so you don't have to worry about their management. -+network utilities such as ssh. The ticket transactions are done -+transparently, so you don't have to worry about their management. - --Note, however, that tickets expire. Privileged tickets, such as those --with the instance ``root``, expire in a few minutes, while tickets --that carry more ordinary privileges may be good for several hours or a --day, depending on the installation's policy. If your login session --extends beyond the time limit, you will have to re-authenticate --yourself to Kerberos to get new tickets. Use the :ref:`kinit(1)` --command to re-authenticate yourself. -+Note, however, that tickets expire. Administrators may configure more -+privileged tickets, such as those with service or instance of ``root`` -+or ``admin``, to expire in a few minutes, while tickets that carry -+more ordinary privileges may be good for several hours or a day. If -+your login session extends beyond the time limit, you will have to -+re-authenticate yourself to Kerberos to get new tickets using the -+:ref:`kinit(1)` command. - --If you use the kinit command to get your tickets, make sure you use --the kdestroy command to destroy your tickets before you end your login --session. You should put the kdestroy command in your ``.logout`` file --so that your tickets will be destroyed automatically when you logout. --For more information about the kinit and kdestroy commands, see the --:ref:`kinit(1)` and :ref:`kdestroy(1)` manual pages. -+Some tickets are **renewable** beyond their initial lifetime. This -+means that ``kinit -R`` can extend their lifetime without requiring -+you to re-authenticate. -+ -+If you wish to delete your local tickets, use the :ref:`kdestroy(1)` -+command. - - Kerberos tickets can be forwarded. In order to forward tickets, you - must request **forwardable** tickets when you kinit. Once you have - forwardable tickets, most Kerberos programs have a command line option --to forward them to the remote host. -+to forward them to the remote host. This can be useful for, e.g., -+running kinit on your local machine and then sshing into another to do -+work. Note that this should not be done on untrusted machines since -+they will then have your tickets. - - ENVIRONMENT VARIABLES - --------------------- - - Several environment variables affect the operation of Kerberos-enabled --programs. These inclide: -+programs. These include: - - **KRB5CCNAME** -- Specifies the location of the credential cache, in the form -- *TYPE*:*residual*. If no *type* prefix is present, the **FILE** -- type is assumed and *residual* is the pathname of the cache file. -- A collection of multiple caches may be used by specifying the -- **dir** type and the pathname of a private directory (which must -- already exist). The default cache file is /tmp/krb5cc_*uid*, -- where *uid* is the decimal user ID of the user. -+ Default name for the credentials cache file, in the form -+ *TYPE*:*residual*. The type of the default cache may determine -+ the availability of a cache collection. ``FILE`` is not a -+ collection type; ``KEYRING``, ``DIR``, and ``KCM`` are. -+ -+ If not set, the value of **default_ccache_name** from -+ configuration files (see **KRB5_CONFIG**) will be used. If that -+ is also not set, the default *type* is ``FILE``, and the -+ *residual* is the path /tmp/krb5cc_*uid*, where *uid* is the -+ decimal user ID of the user. - - **KRB5_KTNAME** -- Specifies the location of the keytab file, in the form -+ Specifies the location of the default keytab file, in the form - *TYPE*:*residual*. If no *type* is present, the **FILE** type is -- assumed and *residual* is the pathname of the keytab file. The -- default keytab file is ``/etc/krb5.keytab``. -+ assumed and *residual* is the pathname of the keytab file. If -+ unset, |keytab| will be used. - - **KRB5_CONFIG** - Specifies the location of the Kerberos configuration file. The -- default is ``/etc/krb5.conf``. -+ default is |sysconfdir|\ ``/krb5.conf``. Multiple filenames can -+ be specified, separated by a colon; all files which are present -+ will be read. - - **KRB5_KDC_PROFILE** - Specifies the location of the KDC configuration file, which - contains additional configuration directives for the Key - Distribution Center daemon and associated programs. The default -- is ``/usr/local/var/krb5kdc/kdc.conf``. -+ is |kdcdir|\ ``/kdc.conf``. - - **KRB5RCACHETYPE** - Specifies the default type of replay cache to use for servers. -- Valid types include **dfl** for the normal file type and **none** -- for no replay cache. -+ Valid types include ``dfl`` for the normal file type and ``none`` -+ for no replay cache. The default is ``dfl``. - - **KRB5RCACHEDIR** - Specifies the default directory for replay caches used by servers. -@@ -110,7 +121,17 @@ programs. These inclide: - **KRB5_TRACE** - Specifies a filename to write trace log output to. Trace logs can - help illuminate decisions made internally by the Kerberos -- libraries. The default is not to write trace log output anywhere. -+ libraries. For example, ``env KRB5_TRACE=/dev/stderr kinit`` -+ would send tracing information for :ref:`kinit(1)` to -+ ``/dev/stderr``. The default is not to write trace log output -+ anywhere. -+ -+**KRB5_CLIENT_KTNAME** -+ Default client keytab file name. If unset, |ckeytab| will be -+ used). -+ -+**KPROP_PORT** -+ :ref:`kprop(8)` port to use. Defaults to 754. - - Most environment variables are disabled for certain programs, such as - login system programs and setuid programs, which are designed to be -@@ -133,6 +154,7 @@ AUTHORS - | Steve Miller, MIT Project Athena/Digital Equipment Corporation - | Clifford Neuman, MIT Project Athena - | Greg Hudson, MIT Kerberos Consortium -+| Robbie Harwood, Red Hat, Inc. - - HISTORY - ------- -@@ -144,5 +166,5 @@ by the MIT Kerberos Consortium. - RESTRICTIONS - ------------ - --Copyright 1985, 1986, 1989-1996, 2002, 2011 Masachusetts Institute of --Technology -+Copyright 1985, 1986, 1989-1996, 2002, 2011, 2018 Masachusetts -+Institute of Technology -diff --git a/src/man/kerberos.man b/src/man/kerberos.man -index 7b2b5d932..026f4604a 100644 ---- a/src/man/kerberos.man -+++ b/src/man/kerberos.man -@@ -34,12 +34,12 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]] - .sp - The Kerberos system authenticates individual users in a network - environment. After authenticating yourself to Kerberos, you can use --Kerberos\-enabled programs without having to present passwords. -+Kerberos\-enabled programs without having to present passwords or -+certificates to those programs. - .sp --If you enter your username and kinit(1) responds with this --message: -+If you receive the following response from kinit(1): - .sp --kinit(v5): Client not found in Kerberos database while getting initial -+kinit: Client not found in Kerberos database while getting initial - credentials - .sp - you haven\(aqt been registered as a Kerberos user. See your system -@@ -51,10 +51,13 @@ is the \fBinstance\fP, which in the case of a user is usually null. - Some users may have privileged instances, however, such as \fBroot\fP or - \fBadmin\fP\&. In the case of a service, the instance is the fully - qualified name of the machine on which it runs; i.e. there can be an --rlogin service running on the machine ABC, which is different from the --rlogin service running on the machine XYZ. The third part of a --Kerberos name is the \fBrealm\fP\&. The realm corresponds to the Kerberos --service providing authentication for the principal. -+ssh service running on the machine ABC (\fI\%ssh/ABC@REALM\fP), which is -+different from the ssh service running on the machine XYZ -+(\fI\%ssh/XYZ@REALM\fP). The third part of a Kerberos name is the \fBrealm\fP\&. -+The realm corresponds to the Kerberos service providing authentication -+for the principal. Realms are conventionally all\-uppercase, and often -+match the end of hostnames in the realm (for instance, host01.example.com -+might be in realm EXAMPLE.COM). - .sp - When writing a Kerberos name, the principal name is separated from the - instance (if not null) by a slash, and the realm (if not the local -@@ -77,63 +80,71 @@ cbrown/root@FUBAR.ORG - When you authenticate yourself with Kerberos you get an initial - Kerberos \fBticket\fP\&. (A Kerberos ticket is an encrypted protocol - message that provides authentication.) Kerberos uses this ticket for --network utilities such as rlogin and rcp. The ticket transactions are --done transparently, so you don\(aqt have to worry about their management. -+network utilities such as ssh. The ticket transactions are done -+transparently, so you don\(aqt have to worry about their management. - .sp --Note, however, that tickets expire. Privileged tickets, such as those --with the instance \fBroot\fP, expire in a few minutes, while tickets --that carry more ordinary privileges may be good for several hours or a --day, depending on the installation\(aqs policy. If your login session --extends beyond the time limit, you will have to re\-authenticate --yourself to Kerberos to get new tickets. Use the kinit(1) --command to re\-authenticate yourself. -+Note, however, that tickets expire. Administrators may configure more -+privileged tickets, such as those with service or instance of \fBroot\fP -+or \fBadmin\fP, to expire in a few minutes, while tickets that carry -+more ordinary privileges may be good for several hours or a day. If -+your login session extends beyond the time limit, you will have to -+re\-authenticate yourself to Kerberos to get new tickets using the -+kinit(1) command. - .sp --If you use the kinit command to get your tickets, make sure you use --the kdestroy command to destroy your tickets before you end your login --session. You should put the kdestroy command in your \fB\&.logout\fP file --so that your tickets will be destroyed automatically when you logout. --For more information about the kinit and kdestroy commands, see the --kinit(1) and kdestroy(1) manual pages. -+Some tickets are \fBrenewable\fP beyond their initial lifetime. This -+means that \fBkinit \-R\fP can extend their lifetime without requiring -+you to re\-authenticate. -+.sp -+If you wish to delete your local tickets, use the kdestroy(1) -+command. - .sp - Kerberos tickets can be forwarded. In order to forward tickets, you - must request \fBforwardable\fP tickets when you kinit. Once you have - forwardable tickets, most Kerberos programs have a command line option --to forward them to the remote host. -+to forward them to the remote host. This can be useful for, e.g., -+running kinit on your local machine and then sshing into another to do -+work. Note that this should not be done on untrusted machines since -+they will then have your tickets. - .SH ENVIRONMENT VARIABLES - .sp - Several environment variables affect the operation of Kerberos\-enabled --programs. These inclide: -+programs. These include: - .INDENT 0.0 - .TP - \fBKRB5CCNAME\fP --Specifies the location of the credential cache, in the form --\fITYPE\fP:\fIresidual\fP\&. If no \fItype\fP prefix is present, the \fBFILE\fP --type is assumed and \fIresidual\fP is the pathname of the cache file. --A collection of multiple caches may be used by specifying the --\fBdir\fP type and the pathname of a private directory (which must --already exist). The default cache file is /tmp/krb5cc_*uid*, --where \fIuid\fP is the decimal user ID of the user. -+Default name for the credentials cache file, in the form -+\fITYPE\fP:\fIresidual\fP\&. The type of the default cache may determine -+the availability of a cache collection. \fBFILE\fP is not a -+collection type; \fBKEYRING\fP, \fBDIR\fP, and \fBKCM\fP are. -+.sp -+If not set, the value of \fBdefault_ccache_name\fP from -+configuration files (see \fBKRB5_CONFIG\fP) will be used. If that -+is also not set, the default \fItype\fP is \fBFILE\fP, and the -+\fIresidual\fP is the path /tmp/krb5cc_*uid*, where \fIuid\fP is the -+decimal user ID of the user. - .TP - \fBKRB5_KTNAME\fP --Specifies the location of the keytab file, in the form -+Specifies the location of the default keytab file, in the form - \fITYPE\fP:\fIresidual\fP\&. If no \fItype\fP is present, the \fBFILE\fP type is --assumed and \fIresidual\fP is the pathname of the keytab file. The --default keytab file is \fB/etc/krb5.keytab\fP\&. -+assumed and \fIresidual\fP is the pathname of the keytab file. If -+unset, \fB@KTNAME@\fP will be used. - .TP - \fBKRB5_CONFIG\fP - Specifies the location of the Kerberos configuration file. The --default is \fB/etc/krb5.conf\fP\&. -+default is \fB@SYSCONFDIR@\fP\fB/krb5.conf\fP\&. Multiple filenames can -+be specified, separated by a colon; all files which are present -+will be read. - .TP - \fBKRB5_KDC_PROFILE\fP - Specifies the location of the KDC configuration file, which - contains additional configuration directives for the Key - Distribution Center daemon and associated programs. The default --is \fB/usr/local/var/krb5kdc/kdc.conf\fP\&. -+is \fB@LOCALSTATEDIR@\fP\fB/krb5kdc\fP\fB/kdc.conf\fP\&. - .TP - \fBKRB5RCACHETYPE\fP - Specifies the default type of replay cache to use for servers. - Valid types include \fBdfl\fP for the normal file type and \fBnone\fP --for no replay cache. -+for no replay cache. The default is \fBdfl\fP\&. - .TP - \fBKRB5RCACHEDIR\fP - Specifies the default directory for replay caches used by servers. -@@ -143,7 +154,17 @@ or \fB/var/tmp\fP if \fBTMPDIR\fP is not set. - \fBKRB5_TRACE\fP - Specifies a filename to write trace log output to. Trace logs can - help illuminate decisions made internally by the Kerberos --libraries. The default is not to write trace log output anywhere. -+libraries. For example, \fBenv KRB5_TRACE=/dev/stderr kinit\fP -+would send tracing information for kinit(1) to -+\fB/dev/stderr\fP\&. The default is not to write trace log output -+anywhere. -+.TP -+\fBKRB5_CLIENT_KTNAME\fP -+Default client keytab file name. If unset, \fB@CKTNAME@\fP will be -+used). -+.TP -+\fBKPROP_PORT\fP -+kprop(8) port to use. Defaults to 754. - .UNINDENT - .sp - Most environment variables are disabled for certain programs, such as -@@ -161,6 +182,7 @@ kadmind(8), kdb5_util(8), krb5kdc(8) - Steve Miller, MIT Project Athena/Digital Equipment Corporation - Clifford Neuman, MIT Project Athena - Greg Hudson, MIT Kerberos Consortium -+Robbie Harwood, Red Hat, Inc. - .fi - .sp - .SH HISTORY -@@ -170,8 +192,8 @@ contributions from many outside parties. It is currently maintained - by the MIT Kerberos Consortium. - .SH RESTRICTIONS - .sp --Copyright 1985, 1986, 1989\-1996, 2002, 2011 Masachusetts Institute of --Technology -+Copyright 1985, 1986, 1989\-1996, 2002, 2011, 2018 Masachusetts -+Institute of Technology - .SH AUTHOR - MIT - .SH COPYRIGHT diff --git a/Move-zap-definition-to-k5-platform.h.patch b/Move-zap-definition-to-k5-platform.h.patch deleted file mode 100644 index f181701..0000000 --- a/Move-zap-definition-to-k5-platform.h.patch +++ /dev/null @@ -1,151 +0,0 @@ -From ee941a490268bb045ec7e153bdf229adcd6d2f73 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 26 Mar 2018 10:54:29 -0400 -Subject: [PATCH] Move zap() definition to k5-platform.h - -Make it possible to use zap() in parts of the code which should not -include k5-int.h by moving its definition to k5-platform.h. - -(cherry picked from commit df6bef6f9ea6a5f6f3956a2988cd658c78aae817) ---- - src/include/k5-int.h | 45 ------------------------------------- - src/include/k5-platform.h | 47 ++++++++++++++++++++++++++++++++++++++- - src/util/support/zap.c | 4 ++-- - 3 files changed, 48 insertions(+), 48 deletions(-) - -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 1c1d9783b..69b81a7f7 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -639,51 +639,6 @@ krb5int_arcfour_gsscrypt(const krb5_keyblock *keyblock, krb5_keyusage usage, - krb5_error_code - k5_sha256(const krb5_data *in, size_t n, uint8_t out[K5_SHA256_HASHLEN]); - --/* -- * Attempt to zero memory in a way that compilers won't optimize out. -- * -- * This mechanism should work even for heap storage about to be freed, -- * or automatic storage right before we return from a function. -- * -- * Then, even if we leak uninitialized memory someplace, or UNIX -- * "core" files get created with world-read access, some of the most -- * sensitive data in the process memory will already be safely wiped. -- * -- * We're not going so far -- yet -- as to try to protect key data that -- * may have been written into swap space.... -- */ --#ifdef _WIN32 --# define zap(ptr, len) SecureZeroMemory(ptr, len) --#elif defined(__STDC_LIB_EXT1__) --/* -- * Use memset_s() which cannot be optimized out. Avoid memset_s(NULL, 0, 0, 0) -- * which would cause a runtime constraint violation. -- */ --static inline void zap(void *ptr, size_t len) --{ -- if (len > 0) -- memset_s(ptr, len, 0, len); --} --#elif defined(__GNUC__) || defined(__clang__) --/* -- * Use an asm statement which declares a memory clobber to force the memset to -- * be carried out. Avoid memset(NULL, 0, 0) which has undefined behavior. -- */ --static inline void zap(void *ptr, size_t len) --{ -- if (len > 0) -- memset(ptr, 0, len); -- __asm__ __volatile__("" : : "r" (ptr) : "memory"); --} --#else --/* -- * Use a function from libkrb5support to defeat inlining unless link-time -- * optimization is used. The function uses a volatile pointer, which prevents -- * current compilers from optimizing out the memset. -- */ --# define zap(ptr, len) krb5int_zap(ptr, len) --#endif -- - /* Convenience function: zap and free ptr if it is non-NULL. */ - static inline void - zapfree(void *ptr, size_t len) -diff --git a/src/include/k5-platform.h b/src/include/k5-platform.h -index 548c0486d..07ef6a4ca 100644 ---- a/src/include/k5-platform.h -+++ b/src/include/k5-platform.h -@@ -40,7 +40,7 @@ - * + [v]asprintf - * + strerror_r - * + mkstemp -- * + zap (support function; macro is in k5-int.h) -+ * + zap (support function and macro) - * + constant time memory comparison - * + path manipulation - * + _, N_, dgettext, bindtextdomain (for localization) -@@ -1022,6 +1022,51 @@ extern int krb5int_gettimeofday(struct timeval *tp, void *ignore); - #define gettimeofday krb5int_gettimeofday - #endif - -+/* -+ * Attempt to zero memory in a way that compilers won't optimize out. -+ * -+ * This mechanism should work even for heap storage about to be freed, -+ * or automatic storage right before we return from a function. -+ * -+ * Then, even if we leak uninitialized memory someplace, or UNIX -+ * "core" files get created with world-read access, some of the most -+ * sensitive data in the process memory will already be safely wiped. -+ * -+ * We're not going so far -- yet -- as to try to protect key data that -+ * may have been written into swap space.... -+ */ -+#ifdef _WIN32 -+# define zap(ptr, len) SecureZeroMemory(ptr, len) -+#elif defined(__STDC_LIB_EXT1__) -+/* -+ * Use memset_s() which cannot be optimized out. Avoid memset_s(NULL, 0, 0, 0) -+ * which would cause a runtime constraint violation. -+ */ -+static inline void zap(void *ptr, size_t len) -+{ -+ if (len > 0) -+ memset_s(ptr, len, 0, len); -+} -+#elif defined(__GNUC__) || defined(__clang__) -+/* -+ * Use an asm statement which declares a memory clobber to force the memset to -+ * be carried out. Avoid memset(NULL, 0, 0) which has undefined behavior. -+ */ -+static inline void zap(void *ptr, size_t len) -+{ -+ if (len > 0) -+ memset(ptr, 0, len); -+ __asm__ __volatile__("" : : "r" (ptr) : "memory"); -+} -+#else -+/* -+ * Use a function from libkrb5support to defeat inlining unless link-time -+ * optimization is used. The function uses a volatile pointer, which prevents -+ * current compilers from optimizing out the memset. -+ */ -+# define zap(ptr, len) krb5int_zap(ptr, len) -+#endif -+ - extern void krb5int_zap(void *ptr, size_t len); - - /* -diff --git a/src/util/support/zap.c b/src/util/support/zap.c -index ed31630db..2f6cdd70e 100644 ---- a/src/util/support/zap.c -+++ b/src/util/support/zap.c -@@ -25,8 +25,8 @@ - */ - - /* -- * krb5int_zap() is used by zap() (a static inline function defined in -- * k5-int.h) on non-Windows, non-gcc compilers, in order to prevent the -+ * krb5int_zap() is used by zap() (a macro or static inline function defined in -+ * k5-platform.h) on non-Windows, non-gcc compilers, in order to prevent the - * compiler from inlining and optimizing out the memset() call. - */ - diff --git a/Prefer-TCP-to-UDP-for-password-changes.patch b/Prefer-TCP-to-UDP-for-password-changes.patch deleted file mode 100644 index 6df2bc1..0000000 --- a/Prefer-TCP-to-UDP-for-password-changes.patch +++ /dev/null @@ -1,168 +0,0 @@ -From dd40cfaf0eef43157afed58795e78de0bb7142eb Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 8 Oct 2018 16:02:12 -0400 -Subject: [PATCH] Prefer TCP to UDP for password changes - -When password changes are performed over UDP, spotty networks may -cause the client to retransmit. This leads to replay errors if the -kpasswd server receives both requests, which hide the actual request -status and make it appear that the password has not been changed, when -it may in fact have been. Use TCP instead with UDP fallback to avoid -this issue. - -ticket: 7905 -(cherry picked from commit d7b3018d338fc9c989c3fa17505870f23c3759a8) ---- - src/lib/krb5/os/changepw.c | 110 ++++++++++++++----------------------- - 1 file changed, 42 insertions(+), 68 deletions(-) - -diff --git a/src/lib/krb5/os/changepw.c b/src/lib/krb5/os/changepw.c -index e4db57084..9f968da7f 100644 ---- a/src/lib/krb5/os/changepw.c -+++ b/src/lib/krb5/os/changepw.c -@@ -59,13 +59,12 @@ struct sendto_callback_context { - - static krb5_error_code - locate_kpasswd(krb5_context context, const krb5_data *realm, -- struct serverlist *serverlist, krb5_boolean no_udp) -+ struct serverlist *serverlist) - { - krb5_error_code code; - - code = k5_locate_server(context, realm, serverlist, locate_service_kpasswd, -- no_udp); -- -+ FALSE); - if (code == KRB5_REALM_CANT_RESOLVE || code == KRB5_REALM_UNKNOWN) { - code = k5_locate_server(context, realm, serverlist, - locate_service_kadmin, TRUE); -@@ -76,7 +75,7 @@ locate_kpasswd(krb5_context context, const krb5_data *realm, - for (i = 0; i < serverlist->nservers; i++) { - struct server_entry *s = &serverlist->servers[i]; - -- if (!no_udp && s->transport == TCP) -+ if (s->transport == TCP) - s->transport = TCP_OR_UDP; - if (s->hostname != NULL) - s->port = DEFAULT_KPASSWD_PORT; -@@ -214,7 +213,6 @@ change_set_password(krb5_context context, - krb5_data *result_string) - { - krb5_data chpw_rep; -- krb5_boolean no_udp = FALSE; - GETSOCKNAME_ARG3_TYPE addrlen; - krb5_error_code code = 0; - char *code_string; -@@ -246,73 +244,49 @@ change_set_password(krb5_context context, - callback_ctx.remote_seq_num = callback_ctx.auth_context->remote_seq_number; - callback_ctx.local_seq_num = callback_ctx.auth_context->local_seq_number; - -- do { -- k5_transport_strategy strategy = no_udp ? NO_UDP : UDP_FIRST; -+ code = locate_kpasswd(callback_ctx.context, &creds->server->realm, &sl); -+ if (code) -+ goto cleanup; - -- code = locate_kpasswd(callback_ctx.context, &creds->server->realm, &sl, -- no_udp); -+ addrlen = sizeof(remote_addr); -+ -+ callback_info.data = &callback_ctx; -+ callback_info.pfn_callback = kpasswd_sendto_msg_callback; -+ callback_info.pfn_cleanup = kpasswd_sendto_msg_cleanup; -+ krb5_free_data_contents(callback_ctx.context, &chpw_rep); -+ -+ code = k5_sendto(callback_ctx.context, NULL, &creds->server->realm, -+ &sl, UDP_LAST, &callback_info, &chpw_rep, -+ ss2sa(&remote_addr), &addrlen, NULL, NULL, NULL); -+ if (code) -+ goto cleanup; -+ -+ code = krb5int_rd_chpw_rep(callback_ctx.context, -+ callback_ctx.auth_context, -+ &chpw_rep, &local_result_code, -+ result_string); -+ -+ if (code) -+ goto cleanup; -+ -+ if (result_code) -+ *result_code = local_result_code; -+ -+ if (result_code_string) { -+ code = krb5_chpw_result_code_string(callback_ctx.context, -+ local_result_code, -+ &code_string); - if (code) -- break; -+ goto cleanup; - -- addrlen = sizeof(remote_addr); -- -- callback_info.data = &callback_ctx; -- callback_info.pfn_callback = kpasswd_sendto_msg_callback; -- callback_info.pfn_cleanup = kpasswd_sendto_msg_cleanup; -- krb5_free_data_contents(callback_ctx.context, &chpw_rep); -- -- code = k5_sendto(callback_ctx.context, NULL, &creds->server->realm, -- &sl, strategy, &callback_info, &chpw_rep, -- ss2sa(&remote_addr), &addrlen, NULL, NULL, NULL); -- if (code) { -- /* -- * Here we may want to switch to TCP on some errors. -- * right? -- */ -- break; -+ result_code_string->length = strlen(code_string); -+ result_code_string->data = malloc(result_code_string->length); -+ if (result_code_string->data == NULL) { -+ code = ENOMEM; -+ goto cleanup; - } -- -- code = krb5int_rd_chpw_rep(callback_ctx.context, -- callback_ctx.auth_context, -- &chpw_rep, &local_result_code, -- result_string); -- -- if (code) { -- if (code == KRB5KRB_ERR_RESPONSE_TOO_BIG && !no_udp) { -- k5_free_serverlist(&sl); -- no_udp = 1; -- continue; -- } -- -- break; -- } -- -- if (result_code) -- *result_code = local_result_code; -- -- if (result_code_string) { -- code = krb5_chpw_result_code_string(callback_ctx.context, -- local_result_code, -- &code_string); -- if (code) -- goto cleanup; -- -- result_code_string->length = strlen(code_string); -- result_code_string->data = malloc(result_code_string->length); -- if (result_code_string->data == NULL) { -- code = ENOMEM; -- goto cleanup; -- } -- strncpy(result_code_string->data, code_string, result_code_string->length); -- } -- -- if (code == KRB5KRB_ERR_RESPONSE_TOO_BIG && !no_udp) { -- k5_free_serverlist(&sl); -- no_udp = 1; -- } else { -- break; -- } -- } while (TRUE); -+ strncpy(result_code_string->data, code_string, result_code_string->length); -+ } - - cleanup: - if (callback_ctx.auth_context != NULL) diff --git a/Prevent-SIGPIPE-from-socket-writes-on-UNIX-likes.patch b/Prevent-SIGPIPE-from-socket-writes-on-UNIX-likes.patch deleted file mode 100644 index d8238ba..0000000 --- a/Prevent-SIGPIPE-from-socket-writes-on-UNIX-likes.patch +++ /dev/null @@ -1,86 +0,0 @@ -From 23e01e9a966ee0aa08668a75f5753a55e1ea4547 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 12 Oct 2018 16:57:05 -0400 -Subject: [PATCH] Prevent SIGPIPE from socket writes on UNIX-likes - -When writing to a disconnected socket, try to only get EPIPE rather -than taking down the process with SIGPIPE. - -On recent Linux and other systems which have it, switch from writev to -sendmsg and pass MSG_NOSIGNAL. - -On BSD-likes, set SO_NOSIGPIPE at connect time. - -ticket: 8753 (new) -(cherry picked from commit 98bf22027bd6e746f456a671ca5e257ca4bd371e) ---- - src/include/port-sockets.h | 43 +++++++++++++++++++++++++++++++++++--- - 1 file changed, 40 insertions(+), 3 deletions(-) - -diff --git a/src/include/port-sockets.h b/src/include/port-sockets.h -index b3ab9c906..3b05e022d 100644 ---- a/src/include/port-sockets.h -+++ b/src/include/port-sockets.h -@@ -158,6 +158,7 @@ typedef int socklen_t; - #include /* For struct sockaddr_in and in_addr */ - #include /* For inet_ntoa */ - #include -+#include /* For memset */ - - #ifndef HAVE_NETDB_H_H_ERRNO - extern int h_errno; /* In case it's missing, e.g., HP-UX 10.20. */ -@@ -218,15 +219,51 @@ typedef struct iovec sg_buf; - #define SOCKET_NFDS(f) ((f)+1) /* select() arg for a single fd */ - #define SOCKET_READ read - #define SOCKET_WRITE write --#define SOCKET_CONNECT connect -+static inline int -+socket_connect(int fd, const struct sockaddr *addr, socklen_t addrlen) -+{ -+ int st; -+#ifdef SO_NOSIGPIPE -+ int set = 1; -+#endif -+ -+ st = connect(fd, addr, addrlen); -+ if (st == -1) -+ return st; -+ -+#ifdef SO_NOSIGPIPE -+ st = setsockopt(fd, SOL_SOCKET, SO_NOSIGPIPE, &set, sizeof(set)); -+ if (st != 0) -+ st = -1; -+#endif -+ -+ return st; -+} -+#define SOCKET_CONNECT socket_connect - #define SOCKET_GETSOCKNAME getsockname - #define SOCKET_CLOSE close - #define SOCKET_EINTR EINTR - #define SOCKET_WRITEV_TEMP int -+static inline ssize_t -+socket_sendmsg(SOCKET fd, sg_buf *iov, int iovcnt) -+{ -+ struct msghdr msg; -+ int flags = 0; -+ -+#ifdef MSG_NOSIGNAL -+ flags |= MSG_NOSIGNAL; -+#endif -+ -+ memset(&msg, 0, sizeof(msg)); -+ msg.msg_iov = iov; -+ msg.msg_iovlen = iovcnt; -+ -+ return sendmsg(fd, &msg, flags); -+} - /* Use TMP to avoid compiler warnings and keep things consistent with - * Windows version. */ --#define SOCKET_WRITEV(FD, SG, LEN, TMP) \ -- ((TMP) = writev((FD), (SG), (LEN)), (TMP)) -+#define SOCKET_WRITEV(FD, SG, LEN, TMP) \ -+ ((TMP) = socket_sendmsg((FD), (SG), (LEN)), (TMP)) - - #define SHUTDOWN_READ 0 - #define SHUTDOWN_WRITE 1 diff --git a/Process-profile-includedir-in-sorted-order.patch b/Process-profile-includedir-in-sorted-order.patch deleted file mode 100644 index 92efffc..0000000 --- a/Process-profile-includedir-in-sorted-order.patch +++ /dev/null @@ -1,114 +0,0 @@ -From 5d868264bca1771aa16abbc8cc0aefb0e1750a73 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 6 Jun 2018 17:58:41 -0400 -Subject: [PATCH] Process profile includedir in sorted order - -In the profile library, use k5_dir_filenames() so that files within an -included directory are read in a predictable order (alphanumeric -within the C locale). - -ticket: 8686 -(cherry picked from commit f574eda48740ad192f51e9a382a205e2ea0e60ad) ---- - doc/admin/conf_files/krb5_conf.rst | 4 ++- - src/util/profile/prof_parse.c | 56 +++++------------------------- - 2 files changed, 12 insertions(+), 48 deletions(-) - -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 2574e5c26..ce545492d 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -60,7 +60,9 @@ alphanumeric characters, dashes, or underscores. Starting in release - 1.15, files with names ending in ".conf" are also included, unless the - name begins with ".". Included profile files are syntactically - independent of their parents, so each included file must begin with a --section header. -+section header. Starting in release 1.17, files are read in -+alphanumeric order; in previous releases, they may be read in any -+order. - - The krb5.conf file can specify that configuration should be obtained - from a loadable module, rather than the file itself, using the -diff --git a/src/util/profile/prof_parse.c b/src/util/profile/prof_parse.c -index 1baceea9e..531e4a099 100644 ---- a/src/util/profile/prof_parse.c -+++ b/src/util/profile/prof_parse.c -@@ -246,59 +246,22 @@ static int valid_name(const char *filename) - * Include files within dirname. Only files with names ending in ".conf", or - * consisting entirely of alphanumeric characters, dashes, and underscores are - * included. This restriction avoids including editor backup files, .rpmsave -- * files, and the like. -+ * files, and the like. Files are processed in alphanumeric order. - */ - static errcode_t parse_include_dir(const char *dirname, - struct profile_node *root_section) - { --#ifdef _WIN32 -- char *wildcard = NULL, *pathname; -- WIN32_FIND_DATA ffd; -- HANDLE handle; - errcode_t retval = 0; -+ char **fnames, *pathname; -+ int i; - -- if (asprintf(&wildcard, "%s\\*", dirname) < 0) -- return ENOMEM; -- -- handle = FindFirstFile(wildcard, &ffd); -- if (handle == INVALID_HANDLE_VALUE) { -- retval = PROF_FAIL_INCLUDE_DIR; -- goto cleanup; -- } -- -- do { -- if (!valid_name(ffd.cFileName)) -- continue; -- if (asprintf(&pathname, "%s\\%s", dirname, ffd.cFileName) < 0) { -- retval = ENOMEM; -- break; -- } -- retval = parse_include_file(pathname, root_section); -- free(pathname); -- if (retval) -- break; -- } while (FindNextFile(handle, &ffd) != 0); -- -- FindClose(handle); -- --cleanup: -- free(wildcard); -- return retval; -- --#else /* not _WIN32 */ -- -- DIR *dir; -- char *pathname; -- errcode_t retval = 0; -- struct dirent *ent; -- -- dir = opendir(dirname); -- if (dir == NULL) -+ if (k5_dir_filenames(dirname, &fnames) != 0) - return PROF_FAIL_INCLUDE_DIR; -- while ((ent = readdir(dir)) != NULL) { -- if (!valid_name(ent->d_name)) -+ -+ for (i = 0; fnames != NULL && fnames[i] != NULL; i++) { -+ if (!valid_name(fnames[i])) - continue; -- if (asprintf(&pathname, "%s/%s", dirname, ent->d_name) < 0) { -+ if (asprintf(&pathname, "%s/%s", dirname, fnames[i]) < 0) { - retval = ENOMEM; - break; - } -@@ -307,9 +270,8 @@ cleanup: - if (retval) - break; - } -- closedir(dir); -+ k5_free_filenames(fnames); - return retval; --#endif /* not _WIN32 */ - } - - static errcode_t parse_line(char *line, struct parse_state *state, diff --git a/Refactor-KDC-krb5_pa_data-utility-functions.patch b/Refactor-KDC-krb5_pa_data-utility-functions.patch deleted file mode 100644 index 41e7cbe..0000000 --- a/Refactor-KDC-krb5_pa_data-utility-functions.patch +++ /dev/null @@ -1,393 +0,0 @@ -From 7c59b7ee063489a4259c34b725728fee7e411c46 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 21 Dec 2017 11:28:52 -0500 -Subject: [PATCH] Refactor KDC krb5_pa_data utility functions - -Move alloc_padata from fast_util.c to kdc_util.c and make it -non-static so it can be used by other files. Rename it to -alloc_pa_data for consistency with add_pa_data_element. Make it -correctly handle zero length using a null contents pointer. - -Make add_pa_data_element claim both the container and contents memory -from the caller, now that callers can use alloc_pa_data to simplify -allocation and copying. Remove the copy parameter and the unused -context parameter, and put the list parameter first. Adjust all -callers accordingly, making small simplifications to memory handling -where applicable. - -(cherry picked from commit 4af478c18b02e1d2444a328bb79e6976ef3d312b) ---- - src/kdc/fast_util.c | 28 +------ - src/kdc/kdc_preauth.c | 14 ++-- - src/kdc/kdc_util.c | 187 +++++++++++++++++++++--------------------- - src/kdc/kdc_util.h | 8 +- - 4 files changed, 109 insertions(+), 128 deletions(-) - -diff --git a/src/kdc/fast_util.c b/src/kdc/fast_util.c -index e05107ef3..6a3fc11b9 100644 ---- a/src/kdc/fast_util.c -+++ b/src/kdc/fast_util.c -@@ -451,36 +451,12 @@ kdc_fast_hide_client(struct kdc_request_state *state) - return (state->fast_options & KRB5_FAST_OPTION_HIDE_CLIENT_NAMES) != 0; - } - --/* Allocate a pa-data entry with an uninitialized buffer of size len. */ --static krb5_error_code --alloc_padata(krb5_preauthtype pa_type, size_t len, krb5_pa_data **out) --{ -- krb5_pa_data *pa; -- uint8_t *buf; -- -- *out = NULL; -- buf = malloc(len); -- if (buf == NULL) -- return ENOMEM; -- pa = malloc(sizeof(*pa)); -- if (pa == NULL) { -- free(buf); -- return ENOMEM; -- } -- pa->magic = KV5M_PA_DATA; -- pa->pa_type = pa_type; -- pa->length = len; -- pa->contents = buf; -- *out = pa; -- return 0; --} -- - /* Create a pa-data entry with the specified type and contents. */ - static krb5_error_code - make_padata(krb5_preauthtype pa_type, const void *contents, size_t len, - krb5_pa_data **out) - { -- if (alloc_padata(pa_type, len, out) != 0) -+ if (alloc_pa_data(pa_type, len, out) != 0) - return ENOMEM; - memcpy((*out)->contents, contents, len); - return 0; -@@ -720,7 +696,7 @@ kdc_fast_make_cookie(krb5_context context, struct kdc_request_state *state, - goto cleanup; - - /* Construct the cookie pa-data entry. */ -- ret = alloc_padata(KRB5_PADATA_FX_COOKIE, 8 + enc.ciphertext.length, &pa); -+ ret = alloc_pa_data(KRB5_PADATA_FX_COOKIE, 8 + enc.ciphertext.length, &pa); - memcpy(pa->contents, "MIT1", 4); - store_32_be(kvno, pa->contents + 4); - memcpy(pa->contents + 8, enc.ciphertext.data, enc.ciphertext.length); -diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c -index 739c5e776..edc30bd83 100644 ---- a/src/kdc/kdc_preauth.c -+++ b/src/kdc/kdc_preauth.c -@@ -1617,18 +1617,20 @@ return_referral_enc_padata( krb5_context context, - { - krb5_error_code code; - krb5_tl_data tl_data; -- krb5_pa_data pa_data; -+ krb5_pa_data *pa; - - tl_data.tl_data_type = KRB5_TL_SVR_REFERRAL_DATA; - code = krb5_dbe_lookup_tl_data(context, server, &tl_data); - if (code || tl_data.tl_data_length == 0) - return 0; - -- pa_data.magic = KV5M_PA_DATA; -- pa_data.pa_type = KRB5_PADATA_SVR_REFERRAL_INFO; -- pa_data.length = tl_data.tl_data_length; -- pa_data.contents = tl_data.tl_data_contents; -- return add_pa_data_element(context, &pa_data, &reply->enc_padata, TRUE); -+ code = alloc_pa_data(KRB5_PADATA_SVR_REFERRAL_INFO, tl_data.tl_data_length, -+ &pa); -+ if (code) -+ return code; -+ memcpy(pa->contents, tl_data.tl_data_contents, tl_data.tl_data_length); -+ /* add_pa_data_element() claims pa on success or failure. */ -+ return add_pa_data_element(&reply->enc_padata, pa); - } - - krb5_error_code -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index 754570c01..13111215d 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -1353,9 +1353,9 @@ kdc_make_s4u2self_rep(krb5_context context, - krb5_enc_kdc_rep_part *reply_encpart) - { - krb5_error_code code; -- krb5_data *data = NULL; -+ krb5_data *der_user_id = NULL, *der_s4u_x509_user = NULL; - krb5_pa_s4u_x509_user rep_s4u_user; -- krb5_pa_data padata; -+ krb5_pa_data *pa; - krb5_enctype enctype; - krb5_keyusage usage; - -@@ -1366,7 +1366,7 @@ kdc_make_s4u2self_rep(krb5_context context, - rep_s4u_user.user_id.options = - req_s4u_user->user_id.options & KRB5_S4U_OPTS_USE_REPLY_KEY_USAGE; - -- code = encode_krb5_s4u_userid(&rep_s4u_user.user_id, &data); -+ code = encode_krb5_s4u_userid(&rep_s4u_user.user_id, &der_user_id); - if (code != 0) - goto cleanup; - -@@ -1377,29 +1377,25 @@ kdc_make_s4u2self_rep(krb5_context context, - - code = krb5_c_make_checksum(context, req_s4u_user->cksum.checksum_type, - tgs_subkey != NULL ? tgs_subkey : tgs_session, -- usage, data, -- &rep_s4u_user.cksum); -+ usage, der_user_id, &rep_s4u_user.cksum); - if (code != 0) - goto cleanup; - -- krb5_free_data(context, data); -- data = NULL; -- -- code = encode_krb5_pa_s4u_x509_user(&rep_s4u_user, &data); -+ code = encode_krb5_pa_s4u_x509_user(&rep_s4u_user, &der_s4u_x509_user); - if (code != 0) - goto cleanup; - -- padata.magic = KV5M_PA_DATA; -- padata.pa_type = KRB5_PADATA_S4U_X509_USER; -- padata.length = data->length; -- padata.contents = (krb5_octet *)data->data; -- -- code = add_pa_data_element(context, &padata, &reply->padata, FALSE); -+ /* Add a padata element, stealing memory from der_s4u_x509_user. */ -+ code = alloc_pa_data(KRB5_PADATA_S4U_X509_USER, 0, &pa); -+ if (code != 0) -+ goto cleanup; -+ pa->length = der_s4u_x509_user->length; -+ pa->contents = (uint8_t *)der_s4u_x509_user->data; -+ der_s4u_x509_user->data = NULL; -+ /* add_pa_data_element() claims pa on success or failure. */ -+ code = add_pa_data_element(&reply->padata, pa); - if (code != 0) - goto cleanup; -- -- free(data); -- data = NULL; - - if (tgs_subkey != NULL) - enctype = tgs_subkey->enctype; -@@ -1413,33 +1409,27 @@ kdc_make_s4u2self_rep(krb5_context context, - */ - if ((req_s4u_user->user_id.options & KRB5_S4U_OPTS_USE_REPLY_KEY_USAGE) && - enctype_requires_etype_info_2(enctype) == FALSE) { -- padata.length = req_s4u_user->cksum.length + -- rep_s4u_user.cksum.length; -- padata.contents = malloc(padata.length); -- if (padata.contents == NULL) { -- code = ENOMEM; -+ code = alloc_pa_data(KRB5_PADATA_S4U_X509_USER, -+ req_s4u_user->cksum.length + -+ rep_s4u_user.cksum.length, &pa); -+ if (code != 0) - goto cleanup; -- } -+ memcpy(pa->contents, -+ req_s4u_user->cksum.contents, req_s4u_user->cksum.length); -+ memcpy(&pa->contents[req_s4u_user->cksum.length], -+ rep_s4u_user.cksum.contents, rep_s4u_user.cksum.length); - -- memcpy(padata.contents, -- req_s4u_user->cksum.contents, -- req_s4u_user->cksum.length); -- memcpy(&padata.contents[req_s4u_user->cksum.length], -- rep_s4u_user.cksum.contents, -- rep_s4u_user.cksum.length); -- -- code = add_pa_data_element(context,&padata, -- &reply_encpart->enc_padata, FALSE); -- if (code != 0) { -- free(padata.contents); -+ /* add_pa_data_element() claims pa on success or failure. */ -+ code = add_pa_data_element(&reply_encpart->enc_padata, pa); -+ if (code != 0) - goto cleanup; -- } - } - - cleanup: - if (rep_s4u_user.cksum.contents != NULL) - krb5_free_checksum_contents(context, &rep_s4u_user.cksum); -- krb5_free_data(context, data); -+ krb5_free_data(context, der_user_id); -+ krb5_free_data(context, der_s4u_x509_user); - - return code; - } -@@ -1707,46 +1697,50 @@ enctype_requires_etype_info_2(krb5_enctype enctype) - } - } - --/* XXX where are the generic helper routines for this? */ -+/* Allocate a pa-data entry with an uninitialized buffer of size len. */ - krb5_error_code --add_pa_data_element(krb5_context context, -- krb5_pa_data *padata, -- krb5_pa_data ***inout_padata, -- krb5_boolean copy) -+alloc_pa_data(krb5_preauthtype pa_type, size_t len, krb5_pa_data **out) - { -- int i; -- krb5_pa_data **p; -+ krb5_pa_data *pa; -+ uint8_t *buf = NULL; - -- if (*inout_padata != NULL) { -- for (i = 0; (*inout_padata)[i] != NULL; i++) -- ; -- } else -- i = 0; -- -- p = realloc(*inout_padata, (i + 2) * sizeof(krb5_pa_data *)); -- if (p == NULL) -- return ENOMEM; -- -- *inout_padata = p; -- -- p[i] = (krb5_pa_data *)malloc(sizeof(krb5_pa_data)); -- if (p[i] == NULL) -- return ENOMEM; -- *(p[i]) = *padata; -- -- p[i + 1] = NULL; -- -- if (copy) { -- p[i]->contents = (krb5_octet *)malloc(padata->length); -- if (p[i]->contents == NULL) { -- free(p[i]); -- p[i] = NULL; -+ *out = NULL; -+ if (len > 0) { -+ buf = malloc(len); -+ if (buf == NULL) - return ENOMEM; -- } -- -- memcpy(p[i]->contents, padata->contents, padata->length); - } -+ pa = malloc(sizeof(*pa)); -+ if (pa == NULL) { -+ free(buf); -+ return ENOMEM; -+ } -+ pa->magic = KV5M_PA_DATA; -+ pa->pa_type = pa_type; -+ pa->length = len; -+ pa->contents = buf; -+ *out = pa; -+ return 0; -+} - -+/* Add pa to list, claiming its memory. Free pa on failure. */ -+krb5_error_code -+add_pa_data_element(krb5_pa_data ***list, krb5_pa_data *pa) -+{ -+ size_t count; -+ krb5_pa_data **newlist; -+ -+ for (count = 0; *list != NULL && (*list)[count] != NULL; count++); -+ -+ newlist = realloc(*list, (count + 2) * sizeof(*newlist)); -+ if (newlist == NULL) { -+ free(pa->contents); -+ free(pa); -+ return ENOMEM; -+ } -+ newlist[count] = pa; -+ newlist[count + 1] = NULL; -+ *list = newlist; - return 0; - } - -@@ -1850,38 +1844,47 @@ kdc_handle_protected_negotiation(krb5_context context, - { - krb5_error_code retval = 0; - krb5_checksum checksum; -- krb5_data *out = NULL; -- krb5_pa_data pa, *pa_in; -+ krb5_data *der_cksum = NULL; -+ krb5_pa_data *pa, *pa_in; -+ -+ memset(&checksum, 0, sizeof(checksum)); -+ - pa_in = krb5int_find_pa_data(context, request->padata, - KRB5_ENCPADATA_REQ_ENC_PA_REP); - if (pa_in == NULL) - return 0; -- pa.magic = KV5M_PA_DATA; -- pa.pa_type = KRB5_ENCPADATA_REQ_ENC_PA_REP; -- memset(&checksum, 0, sizeof(checksum)); -- retval = krb5_c_make_checksum(context,0, reply_key, -- KRB5_KEYUSAGE_AS_REQ, req_pkt, &checksum); -+ -+ /* Compute and encode a checksum over the AS-REQ. */ -+ retval = krb5_c_make_checksum(context, 0, reply_key, KRB5_KEYUSAGE_AS_REQ, -+ req_pkt, &checksum); - if (retval != 0) - goto cleanup; -- retval = encode_krb5_checksum(&checksum, &out); -+ retval = encode_krb5_checksum(&checksum, &der_cksum); - if (retval != 0) - goto cleanup; -- pa.contents = (krb5_octet *) out->data; -- pa.length = out->length; -- retval = add_pa_data_element(context, &pa, out_enc_padata, FALSE); -+ -+ /* Add a pa-data element to the list, stealing memory from der_cksum. */ -+ retval = alloc_pa_data(KRB5_ENCPADATA_REQ_ENC_PA_REP, 0, &pa); - if (retval) - goto cleanup; -- out->data = NULL; -- pa.magic = KV5M_PA_DATA; -- pa.pa_type = KRB5_PADATA_FX_FAST; -- pa.length = 0; -- pa.contents = NULL; -- retval = add_pa_data_element(context, &pa, out_enc_padata, FALSE); -+ pa->length = der_cksum->length; -+ pa->contents = (uint8_t *)der_cksum->data; -+ der_cksum->data = NULL; -+ /* add_pa_data_element() claims pa on success or failure. */ -+ retval = add_pa_data_element(out_enc_padata, pa); -+ if (retval) -+ goto cleanup; -+ -+ /* Add a zero-length PA-FX-FAST element to the list. */ -+ retval = alloc_pa_data(KRB5_PADATA_FX_FAST, 0, &pa); -+ if (retval) -+ goto cleanup; -+ /* add_pa_data_element() claims pa on success or failure. */ -+ retval = add_pa_data_element(out_enc_padata, pa); -+ - cleanup: -- if (checksum.contents) -- krb5_free_checksum_contents(context, &checksum); -- if (out != NULL) -- krb5_free_data(context, out); -+ krb5_free_checksum_contents(context, &checksum); -+ krb5_free_data(context, der_cksum); - return retval; - } - -diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index c57d48f73..198eab9c4 100644 ---- a/src/kdc/kdc_util.h -+++ b/src/kdc/kdc_util.h -@@ -202,10 +202,10 @@ void - free_padata_context(krb5_context context, void *padata_context); - - krb5_error_code --add_pa_data_element (krb5_context context, -- krb5_pa_data *padata, -- krb5_pa_data ***out_padata, -- krb5_boolean copy); -+alloc_pa_data(krb5_preauthtype pa_type, size_t len, krb5_pa_data **out); -+ -+krb5_error_code -+add_pa_data_element(krb5_pa_data ***list, krb5_pa_data *pa); - - /* kdc_preauth_ec.c */ - krb5_error_code diff --git a/Remove-nodes-option-from-make-certs-scripts.patch b/Remove-nodes-option-from-make-certs-scripts.patch deleted file mode 100644 index 402f5fb..0000000 --- a/Remove-nodes-option-from-make-certs-scripts.patch +++ /dev/null @@ -1,45 +0,0 @@ -From 83da5675551dba13fee837adc26ce885a061dbc1 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 3 May 2018 14:40:45 -0400 -Subject: [PATCH] Remove "-nodes" option from make-certs scripts - -The openssl command does not recognize options after positional -arguments, so in "openssl genrsa $KEYSIZE -nodes", the "-nodes" was -ignored as a excess positional argument prior to OpenSSL 1.1.0h, and -now causes an error. "-nodes" is an option to the openssl req and -pkcs12 subcommands, but genrsa creates unencrypted keys by default. - -[ghudson@mit.edu: edited commit message] - -(cherry picked from commit 928a36aae326d496c9a73f2cd41b4da45eef577c) ---- - src/tests/dejagnu/pkinit-certs/make-certs.sh | 2 +- - src/tests/dejagnu/proxy-certs/make-certs.sh | 2 +- - 2 files changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/tests/dejagnu/pkinit-certs/make-certs.sh b/src/tests/dejagnu/pkinit-certs/make-certs.sh -index 63f0c6f75..387311aed 100755 ---- a/src/tests/dejagnu/pkinit-certs/make-certs.sh -+++ b/src/tests/dejagnu/pkinit-certs/make-certs.sh -@@ -114,7 +114,7 @@ extendedKeyUsage = $CLIENT_EKU_LIST - EOF - - # Generate a private key. --openssl genrsa $KEYSIZE -nodes > privkey.pem -+openssl genrsa $KEYSIZE > privkey.pem - openssl rsa -in privkey.pem -out privkey-enc.pem -des3 -passout pass:encrypted - - # Generate a "CA" certificate. -diff --git a/src/tests/dejagnu/proxy-certs/make-certs.sh b/src/tests/dejagnu/proxy-certs/make-certs.sh -index 1191bf05e..24ef91bde 100755 ---- a/src/tests/dejagnu/proxy-certs/make-certs.sh -+++ b/src/tests/dejagnu/proxy-certs/make-certs.sh -@@ -79,7 +79,7 @@ extendedKeyUsage = $PROXY_EKU_LIST - EOF - - # Generate a private key. --openssl genrsa $KEYSIZE -nodes > privkey.pem -+openssl genrsa $KEYSIZE > privkey.pem - - # Generate a "CA" certificate. - SUBJECT=signer openssl req -config openssl.cnf -new -x509 -extensions exts_ca \ diff --git a/Remove-outdated-note-in-krb5kdc-man-page.patch b/Remove-outdated-note-in-krb5kdc-man-page.patch deleted file mode 100644 index 6845b89..0000000 --- a/Remove-outdated-note-in-krb5kdc-man-page.patch +++ /dev/null @@ -1,37 +0,0 @@ -From 65130d13c59c13b7e5e07cfe69421ce1a08c0b7f Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 17 Jul 2018 11:33:03 -0400 -Subject: [PATCH] Remove outdated note in krb5kdc man page - -Commit af5b77c887bfff24603715f8296c00d5eb839b0c (ticket 8348) removed -the interface-scanning workaround for platforms without pktinfo -support, so there is no longer an interaction between the krb5kdc -w -option and this workaround. - -ticket: 8716 (new) -tags: pullup -target_version: 1.16-next - -(cherry picked from commit 728b66ab867e31c4c338c6a6309d629d39a4ec3f) ---- - doc/admin/admin_commands/krb5kdc.rst | 7 ------- - 1 file changed, 7 deletions(-) - -diff --git a/doc/admin/admin_commands/krb5kdc.rst b/doc/admin/admin_commands/krb5kdc.rst -index bda2c015c..b605b563d 100644 ---- a/doc/admin/admin_commands/krb5kdc.rst -+++ b/doc/admin/admin_commands/krb5kdc.rst -@@ -72,13 +72,6 @@ will relay SIGHUP signals to the worker subprocesses, and will - terminate the worker subprocess if the it is itself terminated or if - any other worker process exits. - --.. note:: -- -- On operating systems which do not have *pktinfo* support, -- using worker processes will prevent the KDC from listening -- for UDP packets on network interfaces created after the KDC -- starts. -- - The **-x** *db_args* option specifies database-specific arguments. - See :ref:`Database Options ` in :ref:`kadmin(1)` for - supported arguments. diff --git a/Report-extended-errors-in-kinit-k-t-KDB.patch b/Report-extended-errors-in-kinit-k-t-KDB.patch deleted file mode 100644 index 6859b55..0000000 --- a/Report-extended-errors-in-kinit-k-t-KDB.patch +++ /dev/null @@ -1,27 +0,0 @@ -From 3b3e31316ae247e18ea22293dffbc8f604338fa7 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 17 Mar 2018 22:47:34 -0400 -Subject: [PATCH] Report extended errors in kinit -k -t KDB: - -In kinit, if we recreate the context using kinit_kdb_init(), also -reset the global errctx so that we use the new context to retrieve -extended error messages. - -ticket: 8652 (new) -(cherry picked from commit d4d902d317a2acc46ee71094a33a9203b6135275) ---- - src/clients/kinit/kinit.c | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/src/clients/kinit/kinit.c b/src/clients/kinit/kinit.c -index a518284ea..3fdae2878 100644 ---- a/src/clients/kinit/kinit.c -+++ b/src/clients/kinit/kinit.c -@@ -718,6 +718,7 @@ k5_kinit(struct k_opts *opts, struct k5_data *k5) - #ifndef _WIN32 - if (strncmp(opts->keytab_name, "KDB:", 4) == 0) { - ret = kinit_kdb_init(&k5->ctx, k5->me->realm.data); -+ errctx = k5->ctx; - if (ret) { - com_err(progname, ret, - _("while setting up KDB keytab for realm %s"), diff --git a/Restrict-pre-authentication-fallback-cases.patch b/Restrict-pre-authentication-fallback-cases.patch deleted file mode 100644 index f519557..0000000 --- a/Restrict-pre-authentication-fallback-cases.patch +++ /dev/null @@ -1,491 +0,0 @@ -From 70f41a8dafaadfb43aba4918564c22460f812dca Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 5 Apr 2018 16:23:34 -0400 -Subject: [PATCH] Restrict pre-authentication fallback cases - -Add a new callback disable_fallback() and call it from each clpreauth -module when it generates a client message using credentials to -authenticate. (For SPAKE, this is the message responding to a -challenge; for all other current mechanisms, it is the first and only -client message.) If disable_fallback() is called, do not try another -mechanism after a KDC error. - -Remove k5_reset_preauth_types_tried() and its call sites, so that -preauth mechanisms which are tried optimistically will no longer be -retried after a failure. - -ticket: 8654 -(cherry picked from commit 7a24a088c16d326127dd2b29084d4ca085c70d10) ---- - src/include/krb5/clpreauth_plugin.h | 14 ++++ - src/lib/krb5/krb/get_in_tkt.c | 21 +++--- - src/lib/krb5/krb/init_creds_ctx.h | 1 + - src/lib/krb5/krb/int-proto.h | 3 - - src/lib/krb5/krb/preauth2.c | 23 +++---- - src/lib/krb5/krb/preauth_ec.c | 1 + - src/lib/krb5/krb/preauth_encts.c | 2 + - src/lib/krb5/krb/preauth_otp.c | 4 ++ - src/lib/krb5/krb/preauth_sam2.c | 1 + - src/plugins/preauth/pkinit/pkinit_clnt.c | 1 + - src/plugins/preauth/spake/spake_client.c | 4 ++ - src/plugins/preauth/test/cltest.c | 11 +++ - src/tests/t_preauth.py | 88 +++++++++++++++++++++--- - src/tests/t_spake.py | 9 +-- - 14 files changed, 134 insertions(+), 49 deletions(-) - -diff --git a/src/include/krb5/clpreauth_plugin.h b/src/include/krb5/clpreauth_plugin.h -index 0106734ad..5317669b7 100644 ---- a/src/include/krb5/clpreauth_plugin.h -+++ b/src/include/krb5/clpreauth_plugin.h -@@ -160,7 +160,21 @@ typedef struct krb5_clpreauth_callbacks_st { - krb5_error_code (*set_cc_config)(krb5_context context, - krb5_clpreauth_rock rock, - const char *key, const char *data); -+ - /* End of version 2 clpreauth callbacks (added in 1.11). */ -+ -+ /* -+ * Prevent further fallbacks to other preauth mechanisms if the KDC replies -+ * with an error. (The module itself can still respond to errors with its -+ * tryagain method, or continue after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED -+ * errors with its process method.) A module should invoke this callback -+ * from the process method when it generates an authenticated request using -+ * credentials; often this will be the first or only client message -+ * generated by the mechanism. -+ */ -+ void (*disable_fallback)(krb5_context context, krb5_clpreauth_rock rock); -+ -+ /* End of version 3 clpreauth callbacks (added in 1.17). */ - } *krb5_clpreauth_callbacks; - - /* -diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c -index 1d96ff163..c026bbc6d 100644 ---- a/src/lib/krb5/krb/get_in_tkt.c -+++ b/src/lib/krb5/krb/get_in_tkt.c -@@ -1331,9 +1331,7 @@ init_creds_step_request(krb5_context context, - krb5_free_pa_data(context, ctx->optimistic_padata); - ctx->optimistic_padata = NULL; - if (code) { -- /* Make an unauthenticated request, and possibly try again using -- * the same mechanisms as we tried optimistically. */ -- k5_reset_preauth_types_tried(ctx); -+ /* Make an unauthenticated request. */ - krb5_clear_error_message(context); - code = 0; - } -@@ -1361,6 +1359,9 @@ init_creds_step_request(krb5_context context, - /* Don't continue after a keyboard interrupt. */ - if (code == KRB5_LIBOS_PWDINTR) - goto cleanup; -+ /* Don't continue if fallback is disabled. */ -+ if (code && ctx->fallback_disabled) -+ goto cleanup; - if (code) { - /* See if we can try a different preauth mech before giving up. */ - k5_save_ctx_error(context, code, &save); -@@ -1549,16 +1550,10 @@ init_creds_step_reply(krb5_context context, - } else if (reply_code == KDC_ERR_PREAUTH_FAILED && retry) { - note_req_timestamp(context, ctx, ctx->err_reply->stime, - ctx->err_reply->susec); -- if (ctx->method_padata == NULL) { -- /* Optimistic preauth failed on the KDC. Allow all mechanisms -- * to be tried again using method data. */ -- k5_reset_preauth_types_tried(ctx); -- } else { -- /* Don't try again with the mechanism that failed. */ -- code = k5_preauth_note_failed(ctx, ctx->selected_preauth_type); -- if (code) -- goto cleanup; -- } -+ /* Don't try again with the mechanism that failed. */ -+ code = k5_preauth_note_failed(ctx, ctx->selected_preauth_type); -+ if (code) -+ goto cleanup; - ctx->selected_preauth_type = KRB5_PADATA_NONE; - /* Accept or update method data if the KDC sent it. */ - if (ctx->err_padata != NULL) -diff --git a/src/lib/krb5/krb/init_creds_ctx.h b/src/lib/krb5/krb/init_creds_ctx.h -index b19410a13..7ba61e17c 100644 ---- a/src/lib/krb5/krb/init_creds_ctx.h -+++ b/src/lib/krb5/krb/init_creds_ctx.h -@@ -60,6 +60,7 @@ struct _krb5_init_creds_context { - krb5_enctype etype; - krb5_boolean info_pa_permitted; - krb5_boolean restarted; -+ krb5_boolean fallback_disabled; - struct krb5_responder_context_st rctx; - krb5_preauthtype selected_preauth_type; - krb5_preauthtype allowed_preauth_type; -diff --git a/src/lib/krb5/krb/int-proto.h b/src/lib/krb5/krb/int-proto.h -index cda9010e3..d20133885 100644 ---- a/src/lib/krb5/krb/int-proto.h -+++ b/src/lib/krb5/krb/int-proto.h -@@ -197,9 +197,6 @@ k5_init_preauth_context(krb5_context context); - void - k5_free_preauth_context(krb5_context context); - --void --k5_reset_preauth_types_tried(krb5_init_creds_context ctx); -- - krb5_error_code - k5_preauth_note_failed(krb5_init_creds_context ctx, krb5_preauthtype pa_type); - -diff --git a/src/lib/krb5/krb/preauth2.c b/src/lib/krb5/krb/preauth2.c -index 451e0b7a8..1f17ec2b0 100644 ---- a/src/lib/krb5/krb/preauth2.c -+++ b/src/lib/krb5/krb/preauth2.c -@@ -203,18 +203,6 @@ cleanup: - free_handles(context, list); - } - --/* Reset the memory of which preauth types we have already tried. */ --void --k5_reset_preauth_types_tried(krb5_init_creds_context ctx) --{ -- krb5_preauth_req_context reqctx = ctx->preauth_reqctx; -- -- if (reqctx == NULL) -- return; -- free(reqctx->failed); -- reqctx->failed = NULL; --} -- - /* Add pa_type to the list of types which has previously failed. */ - krb5_error_code - k5_preauth_note_failed(krb5_init_creds_context ctx, krb5_preauthtype pa_type) -@@ -553,8 +541,14 @@ set_cc_config(krb5_context context, krb5_clpreauth_rock rock, - return ret; - } - -+static void -+disable_fallback(krb5_context context, krb5_clpreauth_rock rock) -+{ -+ ((krb5_init_creds_context)rock)->fallback_disabled = TRUE; -+} -+ - static struct krb5_clpreauth_callbacks_st callbacks = { -- 2, -+ 3, - get_etype, - fast_armor, - get_as_key, -@@ -564,7 +558,8 @@ static struct krb5_clpreauth_callbacks_st callbacks = { - responder_get_answer, - need_as_key, - get_cc_config, -- set_cc_config -+ set_cc_config, -+ disable_fallback - }; - - /* Tweak the request body, for now adding any enctypes which the module claims -diff --git a/src/lib/krb5/krb/preauth_ec.c b/src/lib/krb5/krb/preauth_ec.c -index c1aa9090f..75aab770e 100644 ---- a/src/lib/krb5/krb/preauth_ec.c -+++ b/src/lib/krb5/krb/preauth_ec.c -@@ -138,6 +138,7 @@ ec_process(krb5_context context, krb5_clpreauth_moddata moddata, - encoded_ts->data = NULL; - *out_padata = pa; - pa = NULL; -+ cb->disable_fallback(context, rock); - } - free(pa); - krb5_free_data(context, encoded_ts); -diff --git a/src/lib/krb5/krb/preauth_encts.c b/src/lib/krb5/krb/preauth_encts.c -index cec384227..45bf9da92 100644 ---- a/src/lib/krb5/krb/preauth_encts.c -+++ b/src/lib/krb5/krb/preauth_encts.c -@@ -109,6 +109,8 @@ encts_process(krb5_context context, krb5_clpreauth_moddata moddata, - *out_padata = pa; - pa = NULL; - -+ cb->disable_fallback(context, rock); -+ - cleanup: - krb5_free_data(context, ts); - krb5_free_data(context, enc_ts); -diff --git a/src/lib/krb5/krb/preauth_otp.c b/src/lib/krb5/krb/preauth_otp.c -index 48fcbb5d5..13e584657 100644 ---- a/src/lib/krb5/krb/preauth_otp.c -+++ b/src/lib/krb5/krb/preauth_otp.c -@@ -1123,6 +1123,10 @@ otp_client_process(krb5_context context, krb5_clpreauth_moddata moddata, - - /* Encode the request into the pa_data output. */ - retval = set_pa_data(req, pa_data_out); -+ if (retval != 0) -+ goto error; -+ cb->disable_fallback(context, rock); -+ - error: - krb5_free_data_contents(context, &value); - krb5_free_data_contents(context, &pin); -diff --git a/src/lib/krb5/krb/preauth_sam2.c b/src/lib/krb5/krb/preauth_sam2.c -index c8a330655..4c70021a9 100644 ---- a/src/lib/krb5/krb/preauth_sam2.c -+++ b/src/lib/krb5/krb/preauth_sam2.c -@@ -410,6 +410,7 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata, - sam_padata[1] = NULL; - - *out_padata = sam_padata; -+ cb->disable_fallback(context, rock); - - return(0); - } -diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c -index 9483d69e5..77e9e5308 100644 ---- a/src/plugins/preauth/pkinit/pkinit_clnt.c -+++ b/src/plugins/preauth/pkinit/pkinit_clnt.c -@@ -179,6 +179,7 @@ pa_pkinit_gen_req(krb5_context context, - - *out_padata = return_pa_data; - return_pa_data = NULL; -+ cb->disable_fallback(context, rock); - - cleanup: - krb5_free_data(context, der_req); -diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c -index 47a6ba26c..00734a13b 100644 ---- a/src/plugins/preauth/spake/spake_client.c -+++ b/src/plugins/preauth/spake/spake_client.c -@@ -278,6 +278,10 @@ process_challenge(krb5_context context, groupstate *gstate, reqstate *st, - goto cleanup; - TRACE_SPAKE_SEND_RESPONSE(context); - ret = convert_to_padata(response, pa_out); -+ if (ret) -+ goto cleanup; -+ -+ cb->disable_fallback(context, rock); - - cleanup: - krb5_free_keyblock(context, k0); -diff --git a/src/plugins/preauth/test/cltest.c b/src/plugins/preauth/test/cltest.c -index f5f7c5aba..51b848481 100644 ---- a/src/plugins/preauth/test/cltest.c -+++ b/src/plugins/preauth/test/cltest.c -@@ -53,6 +53,9 @@ - * - If the "fail_optimistic", "fail_2rt", or "fail_tryagain" gic options are - * set, it fails with a recognizable error string at the requested point in - * processing. -+ * -+ * - If the "disable_fallback" gic option is set, fallback is disabled when a -+ * client message is generated. - */ - - #include "k5-int.h" -@@ -66,6 +69,7 @@ struct client_state { - krb5_boolean fail_optimistic; - krb5_boolean fail_2rt; - krb5_boolean fail_tryagain; -+ krb5_boolean disable_fallback; - }; - - struct client_request_state { -@@ -81,6 +85,7 @@ test_init(krb5_context context, krb5_clpreauth_moddata *moddata_out) - assert(st != NULL); - st->indicators = NULL; - st->fail_optimistic = st->fail_2rt = st->fail_tryagain = FALSE; -+ st->disable_fallback = FALSE; - *moddata_out = (krb5_clpreauth_moddata)st; - return 0; - } -@@ -138,6 +143,8 @@ test_process(krb5_context context, krb5_clpreauth_moddata moddata, - return KRB5_PREAUTH_FAILED; - } - *out_pa_data = make_pa_list("optimistic", 10); -+ if (st->disable_fallback) -+ cb->disable_fallback(context, rock); - return 0; - } else if (reqst->second_round_trip) { - printf("2rt: %.*s\n", pa_data->length, pa_data->contents); -@@ -166,6 +173,8 @@ test_process(krb5_context context, krb5_clpreauth_moddata moddata, - - indstr = (st->indicators != NULL) ? st->indicators : ""; - *out_pa_data = make_pa_list(indstr, strlen(indstr)); -+ if (st->disable_fallback) -+ cb->disable_fallback(context, rock); - return 0; - } - -@@ -212,6 +221,8 @@ test_gic_opt(krb5_context kcontext, krb5_clpreauth_moddata moddata, - st->fail_2rt = TRUE; - } else if (strcmp(attr, "fail_tryagain") == 0) { - st->fail_tryagain = TRUE; -+ } else if (strcmp(attr, "disable_fallback") == 0) { -+ st->disable_fallback = TRUE; - } - return 0; - } -diff --git a/src/tests/t_preauth.py b/src/tests/t_preauth.py -index efb3ea20d..32e35b08b 100644 ---- a/src/tests/t_preauth.py -+++ b/src/tests/t_preauth.py -@@ -37,8 +37,8 @@ expected_trace = ('Attempting optimistic preauth', - realm.run(['./icred', '-o', '-123', realm.user_princ, password('user')], - expected_trace=expected_trace) - --# Test optimistic preauth failing on client, followed by successful --# preauth using the same module. -+# Test optimistic preauth failing on client, falling back to encrypted -+# timestamp. - msgs = ('Attempting optimistic preauth', - 'Processing preauth types: -123', - '/induced optimistic fail', -@@ -46,15 +46,15 @@ msgs = ('Attempting optimistic preauth', - '/Additional pre-authentication required', - 'Preauthenticating using KDC method data', - 'Processing preauth types:', -- 'Preauth module test (-123) (real) returned: 0/Success', -- 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ 'Encrypted timestamp (for ', -+ 'module encrypted_timestamp (2) (real) returned: 0/Success', -+ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', - 'Decrypted AS reply') - realm.run(['./icred', '-o', '-123', '-X', 'fail_optimistic', realm.user_princ, -- password('user')], expected_msg='testval', -- expected_trace=msgs) -+ password('user')], expected_trace=msgs) - --# Test optimistic preauth failing on KDC, followed by successful preauth --# using the same module. -+# Test optimistic preauth failing on KDC, falling back to encrypted -+# timestamp. - realm.run([kadminl, 'setstr', realm.user_princ, 'failopt', 'yes']) - msgs = ('Attempting optimistic preauth', - 'Processing preauth types: -123', -@@ -63,11 +63,24 @@ msgs = ('Attempting optimistic preauth', - '/Preauthentication failed', - 'Preauthenticating using KDC method data', - 'Processing preauth types:', -- 'Preauth module test (-123) (real) returned: 0/Success', -- 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ 'Encrypted timestamp (for ', -+ 'module encrypted_timestamp (2) (real) returned: 0/Success', -+ 'preauth for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', - 'Decrypted AS reply') - realm.run(['./icred', '-o', '-123', realm.user_princ, password('user')], -- expected_msg='testval', expected_trace=msgs) -+ expected_trace=msgs) -+# Leave failopt set for the next test. -+ -+# Test optimistic preauth failing on KDC, stopping because the test -+# module disabled fallback. -+msgs = ('Attempting optimistic preauth', -+ 'Processing preauth types: -123', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: -123', -+ '/Preauthentication failed') -+realm.run(['./icred', '-X', 'disable_fallback', '-o', '-123', realm.user_princ, -+ password('user')], expected_code=1, -+ expected_msg='Preauthentication failed', expected_trace=msgs) - realm.run([kadminl, 'delstr', realm.user_princ, 'failopt']) - - # Test KDC_ERR_MORE_PREAUTH_DATA_REQUIRED and secure cookies. -@@ -107,6 +120,23 @@ msgs = ('Sending unauthenticated request', - realm.run(['./icred', '-X', 'fail_2rt', realm.user_princ, password('user')], - expected_msg='2rt: secondtrip', expected_trace=msgs) - -+# Test client-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED, -+# stopping because the test module disabled fallback. -+msgs = ('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Preauthenticating using KDC method data', -+ 'Processing preauth types:', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ '/More preauthentication data is required', -+ 'Continuing preauth mech -123', -+ 'Processing preauth types: -123, PA-FX-COOKIE (133)', -+ '/induced 2rt fail') -+realm.run(['./icred', '-X', 'fail_2rt', '-X', 'disable_fallback', -+ realm.user_princ, password('user')], expected_code=1, -+ expected_msg='Pre-authentication failed: induced 2rt fail', -+ expected_trace=msgs) -+ - # Test KDC-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED, - # falling back to encrypted timestamp. - realm.run([kadminl, 'setstr', realm.user_princ, 'fail2rt', 'yes']) -@@ -130,6 +160,25 @@ msgs = ('Sending unauthenticated request', - 'Decrypted AS reply') - realm.run(['./icred', realm.user_princ, password('user')], - expected_msg='2rt: secondtrip', expected_trace=msgs) -+# Leave fail2rt set for the next test. -+ -+# Test KDC-side failure after KDC_ERR_MORE_PREAUTH_DATA_REQUIRED, -+# stopping because the test module disabled fallback. -+msgs = ('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Preauthenticating using KDC method data', -+ 'Processing preauth types:', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ '/More preauthentication data is required', -+ 'Continuing preauth mech -123', -+ 'Processing preauth types: -123, PA-FX-COOKIE (133)', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ '/Preauthentication failed') -+realm.run(['./icred', '-X', 'disable_fallback', -+ realm.user_princ, password('user')], expected_code=1, -+ expected_msg='Preauthentication failed', expected_trace=msgs) - realm.run([kadminl, 'delstr', realm.user_princ, 'fail2rt']) - - # Test tryagain flow by inducing a KDC_ERR_ENCTYPE_NOSUPP error on the KDC. -@@ -170,6 +219,23 @@ msgs = ('Sending unauthenticated request', - realm.run(['./icred', '-X', 'fail_tryagain', realm.user_princ, - password('user')], expected_trace=msgs) - -+# Test a client-side tryagain failure, stopping because the test -+# module disabled fallback. -+msgs = ('Sending unauthenticated request', -+ '/Additional pre-authentication required', -+ 'Preauthenticating using KDC method data', -+ 'Processing preauth types:', -+ 'Preauth module test (-123) (real) returned: 0/Success', -+ 'Produced preauth for next request: PA-FX-COOKIE (133), -123', -+ '/KDC has no support for encryption type', -+ 'Recovering from KDC error 14 using preauth mech -123', -+ 'Preauth tryagain input types (-123): -123, PA-FX-COOKIE (133)', -+ '/induced tryagain fail') -+realm.run(['./icred', '-X', 'fail_tryagain', '-X', 'disable_fallback', -+ realm.user_princ, password('user')], expected_code=1, -+ expected_msg='KDC has no support for encryption type', -+ expected_trace=msgs) -+ - # Test that multiple stepwise initial creds operations can be - # performed with the same krb5_context, with proper tracking of - # clpreauth module request handles. -diff --git a/src/tests/t_spake.py b/src/tests/t_spake.py -index a81a238b4..5b47e62d3 100644 ---- a/src/tests/t_spake.py -+++ b/src/tests/t_spake.py -@@ -31,9 +31,7 @@ for gnum, gname in groups: - 'Decrypted AS reply') - realm.kinit('user', 'pw', expected_trace=msgs) - -- # Test an unsuccessful authentication. (The client will try -- # again with encrypted timestamp, which isn't really desired, -- # but check for that as long as it is expected.) -+ # Test an unsuccessful authentication. - msgs = ('/Additional pre-authentication required', - 'Selected etype info:', - 'Sending SPAKE support message', -@@ -42,9 +40,6 @@ for gnum, gname in groups: - 'Continuing preauth mech PA-SPAKE (151)', - 'SPAKE challenge received with group ' + str(gnum), - 'Sending SPAKE response', -- '/Preauthentication failed', -- 'Encrypted timestamp ', -- 'for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', - '/Preauthentication failed') - realm.kinit('user', 'wrongpw', expected_code=1, expected_trace=msgs) - -@@ -114,8 +109,6 @@ msgs = ('Attempting optimistic preauth', - 'for next request: PA-SPAKE (151)', - '/Preauthentication failed', - 'Selected etype info:', -- 'SPAKE challenge with group 1 rejected', -- 'spake (151) (real) returned: -1765328360/Preauthentication failed', - 'Encrypted timestamp ', - 'for next request: PA-FX-COOKIE (133), PA-ENC-TIMESTAMP (2)', - 'AS key determined by preauth:', diff --git a/Simplify-kdc_preauth.c-systems-table.patch b/Simplify-kdc_preauth.c-systems-table.patch deleted file mode 100644 index 08853d4..0000000 --- a/Simplify-kdc_preauth.c-systems-table.patch +++ /dev/null @@ -1,738 +0,0 @@ -From 65f078dfc68f5680e87e686a59970291b64ebd95 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sun, 11 Feb 2018 15:23:35 -0500 -Subject: [PATCH] Simplify kdc_preauth.c systems table - -Get rid of static_preauth_systems, and replace it with explicit calls -to helper functions in get_preauth_hint_list() and return_padata(). -Stop preallocating pa-data lists, instead reallocating on each -addition using add_pa_data_element(). Also simplify -maybe_add_etype_info2() using add_pa_data_element(). - -The KRB5_PADATA_PAC_REQUEST table entry did nothing, and was probably -originally added back when the KDC would error out on unrecognized -padata types. The KRB5_PADATA_SERVER_REFERRAL entry has been disabled -since it was first added. - -(cherry picked from commit fea1a488924faa3938ef723feaa1ff12d22a91ff) ---- - src/kdc/kdc_preauth.c | 526 +++++++++++++++--------------------------- - 1 file changed, 184 insertions(+), 342 deletions(-) - -diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c -index edc30bd83..6f34dc289 100644 ---- a/src/kdc/kdc_preauth.c -+++ b/src/kdc/kdc_preauth.c -@@ -101,108 +101,14 @@ typedef struct preauth_system_st { - krb5_kdcpreauth_loop_fn loop; - } preauth_system; - -+static preauth_system *preauth_systems; -+static size_t n_preauth_systems; -+ - static krb5_error_code - make_etype_info(krb5_context context, krb5_preauthtype pa_type, - krb5_principal client, krb5_key_data *client_key, - krb5_enctype enctype, krb5_pa_data **pa_out); - --static void --get_etype_info(krb5_context context, krb5_kdc_req *request, -- krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, -- krb5_kdcpreauth_moddata moddata, krb5_preauthtype pa_type, -- krb5_kdcpreauth_edata_respond_fn respond, void *arg); -- --static krb5_error_code --return_etype_info(krb5_context, krb5_pa_data *padata, -- krb5_data *req_pkt, krb5_kdc_req *request, -- krb5_kdc_rep *reply, krb5_keyblock *encrypting_key, -- krb5_pa_data **send_pa, krb5_kdcpreauth_callbacks cb, -- krb5_kdcpreauth_rock rock, krb5_kdcpreauth_moddata moddata, -- krb5_kdcpreauth_modreq modreq); -- --static krb5_error_code --return_pw_salt(krb5_context, krb5_pa_data *padata, -- krb5_data *req_pkt, krb5_kdc_req *request, krb5_kdc_rep *reply, -- krb5_keyblock *encrypting_key, krb5_pa_data **send_pa, -- krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, -- krb5_kdcpreauth_moddata moddata, krb5_kdcpreauth_modreq modreq); -- -- -- --static preauth_system static_preauth_systems[] = { -- { -- "FAST", -- KRB5_PADATA_FX_FAST, -- PA_HARDWARE, -- NULL, -- NULL, -- NULL, -- NULL, -- NULL, -- 0 -- }, -- { -- "etype-info", -- KRB5_PADATA_ETYPE_INFO, -- PA_HARDWARE, -- NULL, -- NULL, -- NULL, -- get_etype_info, -- 0, -- return_etype_info -- }, -- { -- "etype-info2", -- KRB5_PADATA_ETYPE_INFO2, -- PA_HARDWARE, -- NULL, -- NULL, -- NULL, -- get_etype_info, -- 0, -- return_etype_info -- }, -- { -- "pw-salt", -- KRB5_PADATA_PW_SALT, -- PA_PSEUDO, /* Don't include this in the error list */ -- NULL, -- NULL, -- NULL, -- 0, -- 0, -- return_pw_salt -- }, -- { -- "pac-request", -- KRB5_PADATA_PAC_REQUEST, -- PA_PSEUDO, -- NULL, -- NULL, -- NULL, -- NULL, -- NULL, -- NULL -- }, --#if 0 -- { -- "server-referral", -- KRB5_PADATA_SERVER_REFERRAL, -- PA_PSEUDO, -- 0, -- 0, -- return_server_referral -- }, --#endif --}; -- --#define NUM_STATIC_PREAUTH_SYSTEMS (sizeof(static_preauth_systems) / \ -- sizeof(*static_preauth_systems)) -- --static preauth_system *preauth_systems; --static size_t n_preauth_systems; -- - /* Get all available kdcpreauth vtables and a count of preauth types they - * support. Return an empty list on failure. */ - static void -@@ -284,7 +190,6 @@ load_preauth_plugins(struct server_handle *handle, krb5_context context, - get_plugin_vtables(context, &vtables, &n_tables, &n_systems); - - /* Allocate the list of static and plugin preauth systems. */ -- n_systems += NUM_STATIC_PREAUTH_SYSTEMS; - preauth_systems = calloc(n_systems + 1, sizeof(preauth_system)); - if (preauth_systems == NULL) - goto cleanup; -@@ -292,13 +197,8 @@ load_preauth_plugins(struct server_handle *handle, krb5_context context, - if (get_realm_names(handle, &realm_names)) - goto cleanup; - -- /* Add the static system to the list first. No static systems require -- * initialization, so just make a direct copy. */ -- memcpy(preauth_systems, static_preauth_systems, -- sizeof(static_preauth_systems)); -- - /* Add the dynamically-loaded mechanisms to the list. */ -- n_systems = NUM_STATIC_PREAUTH_SYSTEMS; -+ n_systems = 0; - for (i = 0; i < n_tables; i++) { - /* Try to initialize this module. */ - vt = &vtables[i]; -@@ -622,7 +522,9 @@ find_pa_system(int type, preauth_system **preauth) - { - preauth_system *ap; - -- ap = preauth_systems ? preauth_systems : static_preauth_systems; -+ if (preauth_systems == NULL) -+ return KRB5_PREAUTH_BAD_TYPE; -+ ap = preauth_systems; - while ((ap->type != -1) && (ap->type != type)) - ap++; - if (ap->type == -1) -@@ -776,6 +678,98 @@ const char *missing_required_preauth(krb5_db_entry *client, - return 0; - } - -+/* Return true if request's enctypes indicate support for etype-info2. */ -+static krb5_boolean -+requires_info2(const krb5_kdc_req *request) -+{ -+ int i; -+ -+ for (i = 0; i < request->nktypes; i++) { -+ if (enctype_requires_etype_info_2(request->ktype[i])) -+ return TRUE; -+ } -+ return FALSE; -+} -+ -+/* Add PA-ETYPE-INFO2 and possibly PA-ETYPE-INFO entries to pa_list as -+ * appropriate for the request and client principal. */ -+static krb5_error_code -+add_etype_info(krb5_context context, krb5_kdcpreauth_rock rock, -+ krb5_pa_data ***pa_list) -+{ -+ krb5_error_code ret; -+ krb5_pa_data *pa; -+ -+ if (rock->client_key == NULL) -+ return 0; -+ -+ if (!requires_info2(rock->request)) { -+ /* Include PA-ETYPE-INFO only for old clients. */ -+ ret = make_etype_info(context, KRB5_PADATA_ETYPE_INFO, -+ rock->client->princ, rock->client_key, -+ rock->client_keyblock->enctype, &pa); -+ if (ret) -+ return ret; -+ /* add_pa_data_element() claims pa on success or failure. */ -+ ret = add_pa_data_element(pa_list, pa); -+ if (ret) -+ return ret; -+ } -+ -+ /* Always include PA-ETYPE-INFO2. */ -+ ret = make_etype_info(context, KRB5_PADATA_ETYPE_INFO2, -+ rock->client->princ, rock->client_key, -+ rock->client_keyblock->enctype, &pa); -+ if (ret) -+ return ret; -+ /* add_pa_data_element() claims pa on success or failure. */ -+ return add_pa_data_element(pa_list, pa); -+} -+ -+/* Add PW-SALT or AFS3-SALT entries to pa_list as appropriate for the request -+ * and client principal. */ -+static krb5_error_code -+add_pw_salt(krb5_context context, krb5_kdcpreauth_rock rock, -+ krb5_pa_data ***pa_list) -+{ -+ krb5_error_code ret; -+ krb5_pa_data *pa; -+ krb5_data *salt = NULL; -+ krb5_int16 salttype; -+ -+ /* Only include this pa-data for old clients. */ -+ if (rock->client_key == NULL || requires_info2(rock->request)) -+ return 0; -+ -+ ret = krb5_dbe_compute_salt(context, rock->client_key, -+ rock->request->client, &salttype, &salt); -+ if (ret) -+ return 0; -+ -+ if (salttype == KRB5_KDB_SALTTYPE_AFS3) { -+ ret = alloc_pa_data(KRB5_PADATA_AFS3_SALT, salt->length + 1, &pa); -+ if (ret) -+ goto cleanup; -+ memcpy(pa->contents, salt->data, salt->length); -+ pa->contents[salt->length] = '\0'; -+ } else { -+ /* Steal memory from salt to make the pa-data entry. */ -+ ret = alloc_pa_data(KRB5_PADATA_PW_SALT, 0, &pa); -+ if (ret) -+ goto cleanup; -+ pa->length = salt->length; -+ pa->contents = (uint8_t *)salt->data; -+ salt->data = NULL; -+ } -+ -+ /* add_pa_data_element() claims pa on success or failure. */ -+ ret = add_pa_data_element(pa_list, pa); -+ -+cleanup: -+ krb5_free_data(context, salt); -+ return ret; -+} -+ - struct hint_state { - kdc_hint_respond_fn respond; - void *arg; -@@ -787,7 +781,7 @@ struct hint_state { - - int hw_only; - preauth_system *ap; -- krb5_pa_data **pa_data, **pa_cur; -+ krb5_pa_data **pa_data; - krb5_preauthtype pa_type; - }; - -@@ -799,7 +793,7 @@ hint_list_finish(struct hint_state *state, krb5_error_code code) - kdc_realm_t *kdc_active_realm = state->realm; - - if (!code) { -- if (state->pa_data[0] == 0) { -+ if (state->pa_data == NULL) { - krb5_klog_syslog(LOG_INFO, - _("%spreauth required but hint list is empty"), - state->hw_only ? "hw" : ""); -@@ -820,20 +814,27 @@ hint_list_next(struct hint_state *arg); - static void - finish_get_edata(void *arg, krb5_error_code code, krb5_pa_data *pa) - { -+ krb5_error_code ret; - struct hint_state *state = arg; - - if (code == 0) { - if (pa == NULL) { -- /* Include an empty value of the current type. */ -- pa = calloc(1, sizeof(*pa)); -- pa->magic = KV5M_PA_DATA; -- pa->pa_type = state->pa_type; -+ ret = alloc_pa_data(state->pa_type, 0, &pa); -+ if (ret) -+ goto error; - } -- *state->pa_cur++ = pa; -+ /* add_pa_data_element() claims pa on success or failure. */ -+ ret = add_pa_data_element(&state->pa_data, pa); -+ if (ret) -+ goto error; - } - - state->ap++; - hint_list_next(state); -+ return; -+ -+error: -+ hint_list_finish(state, ret); - } - - static void -@@ -870,16 +871,16 @@ get_preauth_hint_list(krb5_kdc_req *request, krb5_kdcpreauth_rock rock, - krb5_pa_data ***e_data_out, kdc_hint_respond_fn respond, - void *arg) - { -+ kdc_realm_t *kdc_active_realm = rock->rstate->realm_data; - struct hint_state *state; -+ krb5_pa_data *pa; - - *e_data_out = NULL; - - /* Allocate our state. */ - state = calloc(1, sizeof(*state)); -- if (state == NULL) { -- (*respond)(arg); -- return; -- } -+ if (state == NULL) -+ goto error; - state->hw_only = isflagset(rock->client->attributes, - KRB5_KDB_REQUIRES_HW_AUTH); - state->respond = respond; -@@ -888,17 +889,27 @@ get_preauth_hint_list(krb5_kdc_req *request, krb5_kdcpreauth_rock rock, - state->rock = rock; - state->realm = rock->rstate->realm_data; - state->e_data_out = e_data_out; -- -- state->pa_data = calloc(n_preauth_systems + 1, sizeof(krb5_pa_data *)); -- if (!state->pa_data) { -- free(state); -- (*respond)(arg); -- return; -- } -- -- state->pa_cur = state->pa_data; -+ state->pa_data = NULL; - state->ap = preauth_systems; -+ -+ /* Add an empty PA-FX-FAST element to advertise FAST support. */ -+ if (alloc_pa_data(KRB5_PADATA_FX_FAST, 0, &pa) != 0) -+ goto error; -+ /* add_pa_data_element() claims pa on success or failure. */ -+ if (add_pa_data_element(&state->pa_data, pa) != 0) -+ goto error; -+ -+ if (add_etype_info(kdc_context, rock, &state->pa_data) != 0) -+ goto error; -+ - hint_list_next(state); -+ return; -+ -+error: -+ if (state != NULL) -+ krb5_free_pa_data(kdc_context, state->pa_data); -+ free(state); -+ (*respond)(arg); - } - - /* -@@ -1029,10 +1040,10 @@ filter_preauth_error(krb5_error_code code) - static krb5_error_code - maybe_add_etype_info2(struct padata_state *state, krb5_error_code code) - { -+ krb5_error_code ret; - krb5_context context = state->context; - krb5_kdcpreauth_rock rock = state->rock; -- krb5_pa_data **list = state->pa_e_data; -- size_t count; -+ krb5_pa_data *pa; - - /* Only add key information when requesting another preauth round trip. */ - if (code != KRB5KDC_ERR_MORE_PREAUTH_DATA_REQUIRED) -@@ -1048,18 +1059,14 @@ maybe_add_etype_info2(struct padata_state *state, krb5_error_code code) - KRB5_PADATA_FX_COOKIE) != NULL) - return 0; - -- /* Reallocate state->pa_e_data to make room for the etype-info2 element. */ -- for (count = 0; list != NULL && list[count] != NULL; count++); -- list = realloc(list, (count + 2) * sizeof(*list)); -- if (list == NULL) -- return ENOMEM; -- list[count] = list[count + 1] = NULL; -- state->pa_e_data = list; -+ ret = make_etype_info(context, KRB5_PADATA_ETYPE_INFO2, -+ rock->client->princ, rock->client_key, -+ rock->client_keyblock->enctype, &pa); -+ if (ret) -+ return ret; - -- /* Generate an etype-info2 element in the new slot. */ -- return make_etype_info(context, KRB5_PADATA_ETYPE_INFO2, -- rock->client->princ, rock->client_key, -- rock->client_keyblock->enctype, &list[count]); -+ /* add_pa_data_element() claims pa on success or failure. */ -+ return add_pa_data_element(&state->pa_e_data, pa); - } - - /* Release state and respond to the AS-REQ processing code with the result of -@@ -1279,17 +1286,20 @@ return_padata(krb5_context context, krb5_kdcpreauth_rock rock, - { - krb5_error_code retval; - krb5_pa_data ** padata; -- krb5_pa_data ** send_pa_list; -- krb5_pa_data ** send_pa; -+ krb5_pa_data ** send_pa_list = NULL; -+ krb5_pa_data * send_pa; - krb5_pa_data * pa = 0; - krb5_pa_data null_item; - preauth_system * ap; -- int * pa_order; -+ int * pa_order = NULL; - int * pa_type; - int size = 0; - krb5_kdcpreauth_modreq *modreq_ptr; - krb5_boolean key_modified; - krb5_keyblock original_key; -+ -+ memset(&original_key, 0, sizeof(original_key)); -+ - if ((!*padata_context) && - (make_padata_context(context, padata_context) != 0)) { - return KRB5KRB_ERR_GENERIC; -@@ -1300,26 +1310,18 @@ return_padata(krb5_context context, krb5_kdcpreauth_rock rock, - size++; - } - -- if ((send_pa_list = malloc((size+1) * sizeof(krb5_pa_data *))) == NULL) -- return ENOMEM; -- if ((pa_order = malloc((size+1) * sizeof(int))) == NULL) { -- free(send_pa_list); -- return ENOMEM; -- } -+ pa_order = k5calloc(size + 1, sizeof(int), &retval); -+ if (pa_order == NULL) -+ goto cleanup; - sort_pa_order(context, request, pa_order); - - retval = krb5_copy_keyblock_contents(context, encrypting_key, - &original_key); -- if (retval) { -- free(send_pa_list); -- free(pa_order); -- return retval; -- } -+ if (retval) -+ goto cleanup; - key_modified = FALSE; - null_item.contents = NULL; - null_item.length = 0; -- send_pa = send_pa_list; -- *send_pa = 0; - - for (pa_type = pa_order; *pa_type != -1; pa_type++) { - ap = &preauth_systems[*pa_type]; -@@ -1349,20 +1351,30 @@ return_padata(krb5_context context, krb5_kdcpreauth_rock rock, - } - } - } -+ send_pa = NULL; - retval = ap->return_padata(context, pa, req_pkt, request, reply, -- encrypting_key, send_pa, &callbacks, rock, -+ encrypting_key, &send_pa, &callbacks, rock, - ap->moddata, *modreq_ptr); - if (retval) - goto cleanup; - -- if (*send_pa) -- send_pa++; -- *send_pa = 0; -+ if (send_pa != NULL) { -+ /* add_pa_data_element() claims send_pa on success or failure. */ -+ retval = add_pa_data_element(&send_pa_list, send_pa); -+ if (retval) -+ goto cleanup; -+ } - } - -- retval = 0; -+ /* Add etype-info and pw-salt pa-data as needed. */ -+ retval = add_etype_info(context, rock, &send_pa_list); -+ if (retval) -+ goto cleanup; -+ retval = add_pw_salt(context, rock, &send_pa_list); -+ if (retval) -+ goto cleanup; - -- if (send_pa_list[0]) { -+ if (send_pa_list != NULL) { - reply->padata = send_pa_list; - send_pa_list = 0; - } -@@ -1370,8 +1382,7 @@ return_padata(krb5_context context, krb5_kdcpreauth_rock rock, - cleanup: - krb5_free_keyblock_contents(context, &original_key); - free(pa_order); -- if (send_pa_list) -- krb5_free_pa_data(context, send_pa_list); -+ krb5_free_pa_data(context, send_pa_list); - - return (retval); - } -@@ -1438,9 +1449,8 @@ make_etype_info(krb5_context context, krb5_preauthtype pa_type, - krb5_enctype enctype, krb5_pa_data **pa_out) - { - krb5_error_code retval; -- krb5_pa_data *pa = NULL; - krb5_etype_info_entry **entry = NULL; -- krb5_data *scratch = NULL; -+ krb5_data *der_etype_info = NULL; - int etype_info2 = (pa_type == KRB5_PADATA_ETYPE_INFO2); - - *pa_out = NULL; -@@ -1454,125 +1464,23 @@ make_etype_info(krb5_context context, krb5_preauthtype pa_type, - goto cleanup; - - if (etype_info2) -- retval = encode_krb5_etype_info2(entry, &scratch); -+ retval = encode_krb5_etype_info2(entry, &der_etype_info); - else -- retval = encode_krb5_etype_info(entry, &scratch); -+ retval = encode_krb5_etype_info(entry, &der_etype_info); - if (retval) - goto cleanup; -- pa = k5alloc(sizeof(*pa), &retval); -- if (pa == NULL) -+ -+ /* Steal the data from der_etype_info to create a pa-data element. */ -+ retval = alloc_pa_data(pa_type, 0, pa_out); -+ if (retval) - goto cleanup; -- pa->magic = KV5M_PA_DATA; -- pa->pa_type = pa_type; -- pa->contents = (unsigned char *)scratch->data; -- pa->length = scratch->length; -- scratch->data = NULL; -- *pa_out = pa; -+ (*pa_out)->contents = (uint8_t *)der_etype_info->data; -+ (*pa_out)->length = der_etype_info->length; -+ der_etype_info->data = NULL; - - cleanup: - krb5_free_etype_info(context, entry); -- krb5_free_data(context, scratch); -- return retval; --} -- --/* Return true if request's enctypes indicate support for etype-info2. */ --static krb5_boolean --requires_info2(const krb5_kdc_req *request) --{ -- int i; -- -- for (i = 0; i < request->nktypes; i++) { -- if (enctype_requires_etype_info_2(request->ktype[i])) -- return TRUE; -- } -- return FALSE; --} -- --/* Generate hint list padata for PA-ETYPE-INFO or PA-ETYPE-INFO2. */ --static void --get_etype_info(krb5_context context, krb5_kdc_req *request, -- krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, -- krb5_kdcpreauth_moddata moddata, krb5_preauthtype pa_type, -- krb5_kdcpreauth_edata_respond_fn respond, void *arg) --{ -- krb5_error_code ret; -- krb5_pa_data *pa = NULL; -- -- if (rock->client_key == NULL) { -- ret = KRB5KDC_ERR_PADATA_TYPE_NOSUPP; -- } else if (pa_type == KRB5_PADATA_ETYPE_INFO && requires_info2(request)) { -- ret = KRB5KDC_ERR_PADATA_TYPE_NOSUPP; -- } else { -- ret = make_etype_info(context, pa_type, rock->client->princ, -- rock->client_key, rock->client_keyblock->enctype, -- &pa); -- } -- (*respond)(arg, ret, pa); --} -- --/* Generate AS-REP padata for PA-ETYPE-INFO or PA-ETYPE-INFO2. */ --static krb5_error_code --return_etype_info(krb5_context context, krb5_pa_data *padata, -- krb5_data *req_pkt, krb5_kdc_req *request, -- krb5_kdc_rep *reply, krb5_keyblock *encrypting_key, -- krb5_pa_data **send_pa, krb5_kdcpreauth_callbacks cb, -- krb5_kdcpreauth_rock rock, krb5_kdcpreauth_moddata moddata, -- krb5_kdcpreauth_modreq modreq) --{ -- *send_pa = NULL; -- if (rock->client_key == NULL) -- return 0; -- if (padata->pa_type == KRB5_PADATA_ETYPE_INFO && requires_info2(request)) -- return 0; -- return make_etype_info(context, padata->pa_type, rock->client->princ, -- rock->client_key, encrypting_key->enctype, send_pa); --} -- --static krb5_error_code --return_pw_salt(krb5_context context, krb5_pa_data *in_padata, -- krb5_data *req_pkt, krb5_kdc_req *request, krb5_kdc_rep *reply, -- krb5_keyblock *encrypting_key, krb5_pa_data **send_pa, -- krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, -- krb5_kdcpreauth_moddata moddata, krb5_kdcpreauth_modreq modreq) --{ -- krb5_error_code retval; -- krb5_pa_data * padata; -- krb5_data * salt = NULL; -- krb5_int16 salttype; -- krb5_key_data * client_key = rock->client_key; -- -- if (client_key == NULL || requires_info2(request)) -- return 0; -- -- retval = krb5_dbe_compute_salt(context, client_key, request->client, -- &salttype, &salt); -- if (retval) -- return 0; -- -- padata = k5alloc(sizeof(*padata), &retval); -- if (padata == NULL) -- goto cleanup; -- padata->magic = KV5M_PA_DATA; -- -- if (salttype == KRB5_KDB_SALTTYPE_AFS3) { -- padata->contents = k5memdup0(salt->data, salt->length, &retval); -- if (padata->contents == NULL) -- goto cleanup; -- padata->pa_type = KRB5_PADATA_AFS3_SALT; -- padata->length = salt->length + 1; -- } else { -- padata->pa_type = KRB5_PADATA_PW_SALT; -- padata->length = salt->length; -- padata->contents = (krb5_octet *)salt->data; -- salt->data = NULL; -- } -- -- *send_pa = padata; -- padata = NULL; -- --cleanup: -- free(padata); -- krb5_free_data(context, salt); -+ krb5_free_data(context, der_etype_info); - return retval; - } - -@@ -1656,69 +1564,3 @@ return_enc_padata(krb5_context context, krb5_data *req_pkt, - cleanup: - return code; - } -- -- --#if 0 --static krb5_error_code return_server_referral(krb5_context context, -- krb5_pa_data * padata, -- krb5_db_entry *client, -- krb5_db_entry *server, -- krb5_kdc_req *request, -- krb5_kdc_rep *reply, -- krb5_key_data *client_key, -- krb5_keyblock *encrypting_key, -- krb5_pa_data **send_pa) --{ -- krb5_error_code code; -- krb5_tl_data tl_data; -- krb5_pa_data *pa_data; -- krb5_enc_data enc_data; -- krb5_data plain; -- krb5_data *enc_pa_data; -- -- *send_pa = NULL; -- -- tl_data.tl_data_type = KRB5_TL_SERVER_REFERRAL; -- -- code = krb5_dbe_lookup_tl_data(context, server, &tl_data); -- if (code || tl_data.tl_data_length == 0) -- return 0; /* no server referrals to return */ -- -- plain.length = tl_data.tl_data_length; -- plain.data = tl_data.tl_data_contents; -- -- /* Encrypt ServerReferralData */ -- code = krb5_encrypt_helper(context, encrypting_key, -- KRB5_KEYUSAGE_PA_SERVER_REFERRAL_DATA, -- &plain, &enc_data); -- if (code) -- return code; -- -- /* Encode ServerReferralData into PA-SERVER-REFERRAL-DATA */ -- code = encode_krb5_enc_data(&enc_data, &enc_pa_data); -- if (code) { -- krb5_free_data_contents(context, &enc_data.ciphertext); -- return code; -- } -- -- krb5_free_data_contents(context, &enc_data.ciphertext); -- -- /* Return PA-SERVER-REFERRAL-DATA */ -- pa_data = (krb5_pa_data *)malloc(sizeof(*pa_data)); -- if (pa_data == NULL) { -- krb5_free_data(context, enc_pa_data); -- return ENOMEM; -- } -- -- pa_data->magic = KV5M_PA_DATA; -- pa_data->pa_type = KRB5_PADATA_SVR_REFERRAL_INFO; -- pa_data->length = enc_pa_data->length; -- pa_data->contents = enc_pa_data->data; -- -- free(enc_pa_data); /* don't free contents */ -- -- *send_pa = pa_data; -- -- return 0; --} --#endif diff --git a/Update-man-pages-to-reference-kerberos-7.patch b/Update-man-pages-to-reference-kerberos-7.patch deleted file mode 100644 index 50dcf83..0000000 --- a/Update-man-pages-to-reference-kerberos-7.patch +++ /dev/null @@ -1,476 +0,0 @@ -From 92984a6d7208ceab384d5a21d03de08b4cb4c8d8 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 15 Oct 2018 15:19:12 -0400 -Subject: [PATCH] Update man pages to reference kerberos(7) - -Remove broken references to old kerberos(1). Reference kerberos(7) -from all man pages, and create/update their environment section so -that it references kerberos(7). - -ticket: 8755 -(cherry picked from commit 52cbe198d0d6f0085d4653b2f6a1ecc84d139118) -[rharwood@redhat.com: conflicts: kvno doesn't have u2u yet, git derped -on kswitch] ---- - doc/admin/admin_commands/k5srvutil.rst | 9 ++++++++- - doc/admin/admin_commands/kadmin_local.rst | 9 ++++++++- - doc/admin/admin_commands/kadmind.rst | 9 ++++++++- - doc/admin/admin_commands/kdb5_ldap_util.rst | 9 ++++++++- - doc/admin/admin_commands/kdb5_util.rst | 9 ++++++++- - doc/admin/admin_commands/kprop.rst | 8 ++++---- - doc/admin/admin_commands/kpropd.rst | 10 +++++++++- - doc/admin/admin_commands/kproplog.rst | 7 +++---- - doc/admin/admin_commands/krb5kdc.rst | 8 +++----- - doc/admin/admin_commands/ktutil.rst | 9 ++++++++- - doc/admin/admin_commands/sserver.rst | 9 ++++++++- - doc/user/user_commands/kdestroy.rst | 13 +++---------- - doc/user/user_commands/kinit.rst | 14 +++----------- - doc/user/user_commands/klist.rst | 13 +++---------- - doc/user/user_commands/kpasswd.rst | 9 ++++++++- - doc/user/user_commands/krb5-config.rst | 2 +- - doc/user/user_commands/ksu.rst | 13 +++++++++++++ - doc/user/user_commands/kswitch.rst | 14 ++++---------- - doc/user/user_commands/kvno.rst | 9 +++------ - doc/user/user_commands/sclient.rst | 8 +++++++- - 20 files changed, 120 insertions(+), 71 deletions(-) - -diff --git a/doc/admin/admin_commands/k5srvutil.rst b/doc/admin/admin_commands/k5srvutil.rst -index b873d9077..79502cf9e 100644 ---- a/doc/admin/admin_commands/k5srvutil.rst -+++ b/doc/admin/admin_commands/k5srvutil.rst -@@ -56,7 +56,14 @@ k5srvutil uses the :ref:`kadmin(1)` program to edit the keytab in - place. - - -+ENVIRONMENT -+----------- -+ -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. -+ -+ - SEE ALSO - -------- - --:ref:`kadmin(1)`, :ref:`ktutil(1)` -+:ref:`kadmin(1)`, :ref:`ktutil(1)`, :ref:`kerberos(7)` -diff --git a/doc/admin/admin_commands/kadmin_local.rst b/doc/admin/admin_commands/kadmin_local.rst -index 9b5ccf4e9..cefe6054b 100644 ---- a/doc/admin/admin_commands/kadmin_local.rst -+++ b/doc/admin/admin_commands/kadmin_local.rst -@@ -996,7 +996,14 @@ The kadmin program was originally written by Tom Yu at MIT, as an - interface to the OpenVision Kerberos administration program. - - -+ENVIRONMENT -+----------- -+ -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. -+ -+ - SEE ALSO - -------- - --:ref:`kpasswd(1)`, :ref:`kadmind(8)` -+:ref:`kpasswd(1)`, :ref:`kadmind(8)`, :ref:`kerberos(7)` -diff --git a/doc/admin/admin_commands/kadmind.rst b/doc/admin/admin_commands/kadmind.rst -index f5b7733ea..8bfb48a32 100644 ---- a/doc/admin/admin_commands/kadmind.rst -+++ b/doc/admin/admin_commands/kadmind.rst -@@ -116,8 +116,15 @@ OPTIONS - ` in :ref:`kadmin(1)` for supported arguments. - - -+ENVIRONMENT -+----------- -+ -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. -+ -+ - SEE ALSO - -------- - - :ref:`kpasswd(1)`, :ref:`kadmin(1)`, :ref:`kdb5_util(8)`, --:ref:`kdb5_ldap_util(8)`, :ref:`kadm5.acl(5)` -+:ref:`kdb5_ldap_util(8)`, :ref:`kadm5.acl(5)`, :ref:`kerberos(7)` -diff --git a/doc/admin/admin_commands/kdb5_ldap_util.rst b/doc/admin/admin_commands/kdb5_ldap_util.rst -index cbf313f55..343df4dd9 100644 ---- a/doc/admin/admin_commands/kdb5_ldap_util.rst -+++ b/doc/admin/admin_commands/kdb5_ldap_util.rst -@@ -456,7 +456,14 @@ Example:: - .. _kdb5_ldap_util_list_policy_end: - - -+ENVIRONMENT -+----------- -+ -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. -+ -+ - SEE ALSO - -------- - --:ref:`kadmin(1)` -+:ref:`kadmin(1)`, :ref:`kerberos(7)` -diff --git a/doc/admin/admin_commands/kdb5_util.rst b/doc/admin/admin_commands/kdb5_util.rst -index 258498f0d..18a3fb627 100644 ---- a/doc/admin/admin_commands/kdb5_util.rst -+++ b/doc/admin/admin_commands/kdb5_util.rst -@@ -491,7 +491,14 @@ Examples:: - bar@EXAMPLE.COM 1 1 des-cbc-crc normal -1 - - -+ENVIRONMENT -+----------- -+ -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. -+ -+ - SEE ALSO - -------- - --:ref:`kadmin(1)` -+:ref:`kadmin(1)`, :ref:`kerberos(7)` -diff --git a/doc/admin/admin_commands/kprop.rst b/doc/admin/admin_commands/kprop.rst -index 726c8cc2f..0bc353239 100644 ---- a/doc/admin/admin_commands/kprop.rst -+++ b/doc/admin/admin_commands/kprop.rst -@@ -49,12 +49,12 @@ OPTIONS - ENVIRONMENT - ----------- - --*kprop* uses the following environment variable: -- --* **KRB5_CONFIG** -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. - - - SEE ALSO - -------- - --:ref:`kpropd(8)`, :ref:`kdb5_util(8)`, :ref:`krb5kdc(8)` -+:ref:`kpropd(8)`, :ref:`kdb5_util(8)`, :ref:`krb5kdc(8)`, -+:ref:`kerberos(7)` -diff --git a/doc/admin/admin_commands/kpropd.rst b/doc/admin/admin_commands/kpropd.rst -index 5468b0675..03aa8ce90 100644 ---- a/doc/admin/admin_commands/kpropd.rst -+++ b/doc/admin/admin_commands/kpropd.rst -@@ -129,7 +129,15 @@ kpropd.acl - will allow Kerberos database propagation via :ref:`kprop(8)`. - - -+ENVIRONMENT -+----------- -+ -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. -+ -+ - SEE ALSO - -------- - --:ref:`kprop(8)`, :ref:`kdb5_util(8)`, :ref:`krb5kdc(8)`, inetd(8) -+:ref:`kprop(8)`, :ref:`kdb5_util(8)`, :ref:`krb5kdc(8)`, -+:ref:`kerberos(7)`, inetd(8) -diff --git a/doc/admin/admin_commands/kproplog.rst b/doc/admin/admin_commands/kproplog.rst -index ed906398d..b98e1b29b 100644 ---- a/doc/admin/admin_commands/kproplog.rst -+++ b/doc/admin/admin_commands/kproplog.rst -@@ -74,12 +74,11 @@ OPTIONS - ENVIRONMENT - ----------- - --kproplog uses the following environment variables: -- --* **KRB5_KDC_PROFILE** -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. - - - SEE ALSO - -------- - --:ref:`kpropd(8)` -+:ref:`kpropd(8)`, :ref:`kerberos(7)` -diff --git a/doc/admin/admin_commands/krb5kdc.rst b/doc/admin/admin_commands/krb5kdc.rst -index b605b563d..0342d0d18 100644 ---- a/doc/admin/admin_commands/krb5kdc.rst -+++ b/doc/admin/admin_commands/krb5kdc.rst -@@ -103,14 +103,12 @@ description for further details. - ENVIRONMENT - ----------- - --krb5kdc uses the following environment variables: -- --* **KRB5_CONFIG** --* **KRB5_KDC_PROFILE** -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. - - - SEE ALSO - -------- - - :ref:`kdb5_util(8)`, :ref:`kdc.conf(5)`, :ref:`krb5.conf(5)`, --:ref:`kdb5_ldap_util(8)` -+:ref:`kdb5_ldap_util(8)`, :ref:`kerberos(7)` -diff --git a/doc/admin/admin_commands/ktutil.rst b/doc/admin/admin_commands/ktutil.rst -index 2eb19ded2..7d8ab4913 100644 ---- a/doc/admin/admin_commands/ktutil.rst -+++ b/doc/admin/admin_commands/ktutil.rst -@@ -127,7 +127,14 @@ EXAMPLE - ktutil: - - -+ENVIRONMENT -+----------- -+ -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. -+ -+ - SEE ALSO - -------- - --:ref:`kadmin(1)`, :ref:`kdb5_util(8)` -+:ref:`kadmin(1)`, :ref:`kdb5_util(8)`, :ref:`kerberos(7)` -diff --git a/doc/admin/admin_commands/sserver.rst b/doc/admin/admin_commands/sserver.rst -index b4e464466..a8dcf5d5b 100644 ---- a/doc/admin/admin_commands/sserver.rst -+++ b/doc/admin/admin_commands/sserver.rst -@@ -99,7 +99,14 @@ COMMON ERROR MESSAGES - probably not installed in the proper directory. - - -+ENVIRONMENT -+----------- -+ -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. -+ -+ - SEE ALSO - -------- - --:ref:`sclient(1)`, services(5), inetd(8) -+:ref:`sclient(1)`, :ref:`kerberos(7)`, services(5), inetd(8) -diff --git a/doc/user/user_commands/kdestroy.rst b/doc/user/user_commands/kdestroy.rst -index b8c67aba4..c69d65667 100644 ---- a/doc/user/user_commands/kdestroy.rst -+++ b/doc/user/user_commands/kdestroy.rst -@@ -53,15 +53,8 @@ when you log out. - ENVIRONMENT - ----------- - --kdestroy uses the following environment variable: -- --**KRB5CCNAME** -- Location of the default Kerberos 5 credentials (ticket) cache, in -- the form *type*:*residual*. If no *type* prefix is present, the -- **FILE** type is assumed. The type of the default cache may -- determine the availability of a cache collection; for instance, a -- default cache of type **DIR** causes caches within the directory -- to be present in the collection. -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. - - - FILES -@@ -74,4 +67,4 @@ FILES - SEE ALSO - -------- - --:ref:`kinit(1)`, :ref:`klist(1)` -+:ref:`kinit(1)`, :ref:`klist(1)`, :ref:`kerberos(7)` -diff --git a/doc/user/user_commands/kinit.rst b/doc/user/user_commands/kinit.rst -index 1f696920f..d692e2791 100644 ---- a/doc/user/user_commands/kinit.rst -+++ b/doc/user/user_commands/kinit.rst -@@ -200,19 +200,11 @@ OPTIONS - **disable_freshness**\ [**=yes**] - disable sending freshness tokens (for testing purposes only) - -- - ENVIRONMENT - ----------- - --kinit uses the following environment variables: -- --**KRB5CCNAME** -- Location of the default Kerberos 5 credentials cache, in the form -- *type*:*residual*. If no *type* prefix is present, the **FILE** -- type is assumed. The type of the default cache may determine the -- availability of a cache collection; for instance, a default cache -- of type **DIR** causes caches within the directory to be present -- in the collection. -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. - - - FILES -@@ -228,4 +220,4 @@ FILES - SEE ALSO - -------- - --:ref:`klist(1)`, :ref:`kdestroy(1)`, kerberos(1) -+:ref:`klist(1)`, :ref:`kdestroy(1)`, :ref:`kerberos(7)` -diff --git a/doc/user/user_commands/klist.rst b/doc/user/user_commands/klist.rst -index c24c74132..88e457846 100644 ---- a/doc/user/user_commands/klist.rst -+++ b/doc/user/user_commands/klist.rst -@@ -105,15 +105,8 @@ value is used to locate the default ticket cache. - ENVIRONMENT - ----------- - --klist uses the following environment variable: -- --**KRB5CCNAME** -- Location of the default Kerberos 5 credentials (ticket) cache, in -- the form *type*:*residual*. If no *type* prefix is present, the -- **FILE** type is assumed. The type of the default cache may -- determine the availability of a cache collection; for instance, a -- default cache of type **DIR** causes caches within the directory -- to be present in the collection. -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. - - - FILES -@@ -129,4 +122,4 @@ FILES - SEE ALSO - -------- - --:ref:`kinit(1)`, :ref:`kdestroy(1)` -+:ref:`kinit(1)`, :ref:`kdestroy(1)`, :ref:`kerberos(7)` -diff --git a/doc/user/user_commands/kpasswd.rst b/doc/user/user_commands/kpasswd.rst -index 1b6463265..0583bbd05 100644 ---- a/doc/user/user_commands/kpasswd.rst -+++ b/doc/user/user_commands/kpasswd.rst -@@ -33,7 +33,14 @@ OPTIONS - identity of the user invoking the kpasswd command. - - -+ENVIRONMENT -+----------- -+ -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. -+ -+ - SEE ALSO - -------- - --:ref:`kadmin(1)`, :ref:`kadmind(8)` -+:ref:`kadmin(1)`, :ref:`kadmind(8)`, :ref:`kerberos(7)` -diff --git a/doc/user/user_commands/krb5-config.rst b/doc/user/user_commands/krb5-config.rst -index ee0fceaa3..2c09141a1 100644 ---- a/doc/user/user_commands/krb5-config.rst -+++ b/doc/user/user_commands/krb5-config.rst -@@ -80,4 +80,4 @@ the following output:: - SEE ALSO - -------- - --kerberos(1), cc(1) -+:ref:`kerberos(7)`, cc(1) -diff --git a/doc/user/user_commands/ksu.rst b/doc/user/user_commands/ksu.rst -index b2f9121f0..29487a838 100644 ---- a/doc/user/user_commands/ksu.rst -+++ b/doc/user/user_commands/ksu.rst -@@ -385,3 +385,16 @@ AUTHOR OF KSU - ------------- - - GENNADY (ARI) MEDVINSKY -+ -+ -+ENVIRONMENT -+----------- -+ -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. -+ -+ -+SEE ALSO -+-------- -+ -+:ref:`kerberos(7)`, :ref:`kinit(1)` -diff --git a/doc/user/user_commands/kswitch.rst b/doc/user/user_commands/kswitch.rst -index 56e5915ac..010332e6a 100644 ---- a/doc/user/user_commands/kswitch.rst -+++ b/doc/user/user_commands/kswitch.rst -@@ -32,15 +32,8 @@ OPTIONS - ENVIRONMENT - ----------- - --kswitch uses the following environment variables: -- --**KRB5CCNAME** -- Location of the default Kerberos 5 credentials (ticket) cache, in -- the form *type*:*residual*. If no *type* prefix is present, the -- **FILE** type is assumed. The type of the default cache may -- determine the availability of a cache collection; for instance, a -- default cache of type **DIR** causes caches within the directory -- to be present in the collection. -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. - - - FILES -@@ -53,4 +46,5 @@ FILES - SEE ALSO - -------- - --:ref:`kinit(1)`, :ref:`kdestroy(1)`, :ref:`klist(1)`), kerberos(1) -+:ref:`kinit(1)`, :ref:`kdestroy(1)`, :ref:`klist(1)`, -+:ref:`kerberos(7)` -diff --git a/doc/user/user_commands/kvno.rst b/doc/user/user_commands/kvno.rst -index 31ca24460..f269fb3f9 100644 ---- a/doc/user/user_commands/kvno.rst -+++ b/doc/user/user_commands/kvno.rst -@@ -63,14 +63,11 @@ OPTIONS - delegation is not requested, the service name must match the - credentials cache client principal. - -- - ENVIRONMENT - ----------- - --kvno uses the following environment variable: -- --**KRB5CCNAME** -- Location of the credentials (ticket) cache. -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. - - - FILES -@@ -83,4 +80,4 @@ FILES - SEE ALSO - -------- - --:ref:`kinit(1)`, :ref:`kdestroy(1)` -+:ref:`kinit(1)`, :ref:`kdestroy(1)`, :ref:`kerberos(7)` -diff --git a/doc/user/user_commands/sclient.rst b/doc/user/user_commands/sclient.rst -index ebf797253..1e3d38f82 100644 ---- a/doc/user/user_commands/sclient.rst -+++ b/doc/user/user_commands/sclient.rst -@@ -17,8 +17,14 @@ purposes. It contacts a sample server :ref:`sserver(8)` and - authenticates to it using Kerberos version 5 tickets, then displays - the server's response. - -+ENVIRONMENT -+----------- -+ -+See :ref:`kerberos(7)` for a description of Kerberos environment -+variables. -+ - - SEE ALSO - -------- - --:ref:`kinit(1)`, :ref:`sserver(8)` -+:ref:`kinit(1)`, :ref:`sserver(8)`, :ref:`kerberos(7)` diff --git a/Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch b/Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch deleted file mode 100644 index 26df25a..0000000 --- a/Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch +++ /dev/null @@ -1,53 +0,0 @@ -From a9bc03fe03ef4b00bcdad13c99bb4c376a8b9964 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 10 Jul 2018 16:17:15 -0400 -Subject: [PATCH] Use SHA-256 instead of MD5 for audit ticket IDs - -ticket: 8711 (new) -(cherry picked from commit c1e1bfa26bd2f045e88e6013c500fca9428c98f3) ---- - src/kdc/kdc_audit.c | 21 ++++++++++----------- - 1 file changed, 10 insertions(+), 11 deletions(-) - -diff --git a/src/kdc/kdc_audit.c b/src/kdc/kdc_audit.c -index c9a7f9f9d..f40913dc8 100644 ---- a/src/kdc/kdc_audit.c -+++ b/src/kdc/kdc_audit.c -@@ -146,7 +146,7 @@ kau_make_tkt_id(krb5_context context, - { - krb5_error_code ret = 0; - char *hash = NULL, *ptr; -- krb5_checksum cksum; -+ uint8_t hashbytes[K5_SHA256_HASHLEN]; - unsigned int i; - - *out = NULL; -@@ -154,19 +154,18 @@ kau_make_tkt_id(krb5_context context, - if (ticket == NULL) - return EINVAL; - -- ret = krb5_c_make_checksum(context, CKSUMTYPE_RSA_MD5, NULL, 0, -- &ticket->enc_part.ciphertext, &cksum); -+ ret = k5_sha256(&ticket->enc_part.ciphertext, 1, hashbytes); - if (ret) - return ret; - -- hash = k5alloc(cksum.length * 2 + 1, &ret); -- if (hash != NULL) { -- for (i = 0, ptr = hash; i < cksum.length; i++, ptr += 2) -- snprintf(ptr, 3, "%02X", cksum.contents[i]); -- *ptr = '\0'; -- *out = hash; -- } -- krb5_free_checksum_contents(context, &cksum); -+ hash = k5alloc(sizeof(hashbytes) * 2 + 1, &ret); -+ if (hash == NULL) -+ return ret; -+ -+ for (i = 0, ptr = hash; i < sizeof(hashbytes); i++, ptr += 2) -+ snprintf(ptr, 3, "%02X", hashbytes[i]); -+ *ptr = '\0'; -+ *out = hash; - - return 0; - } diff --git a/Use-k5_buf_init_dynamic_zap-where-appropriate.patch b/Use-k5_buf_init_dynamic_zap-where-appropriate.patch deleted file mode 100644 index 3d3bcd8..0000000 --- a/Use-k5_buf_init_dynamic_zap-where-appropriate.patch +++ /dev/null @@ -1,62 +0,0 @@ -From c5df16a88027d7f9b6eb53b1c3fa949d6538616b Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 26 Mar 2018 11:24:49 -0400 -Subject: [PATCH] Use k5_buf_init_dynamic_zap where appropriate - -(cherry picked from commit 9172599008f3a6790d4a9a67acff58049742dcb6) ---- - src/lib/krb5/ccache/cc_file.c | 4 ++-- - src/lib/krb5/ccache/cc_keyring.c | 2 +- - src/util/support/utf8_conv.c | 4 +++- - 3 files changed, 6 insertions(+), 4 deletions(-) - -diff --git a/src/lib/krb5/ccache/cc_file.c b/src/lib/krb5/ccache/cc_file.c -index 6789c09e1..9263a0054 100644 ---- a/src/lib/krb5/ccache/cc_file.c -+++ b/src/lib/krb5/ccache/cc_file.c -@@ -758,7 +758,7 @@ fcc_next_cred(krb5_context context, krb5_ccache id, krb5_cc_cursor *cursor, - - memset(creds, 0, sizeof(*creds)); - k5_cc_mutex_lock(context, &data->lock); -- k5_buf_init_dynamic(&buf); -+ k5_buf_init_dynamic_zap(&buf); - - ret = krb5_lock_file(context, fileno(fcursor->fp), KRB5_LOCKMODE_SHARED); - if (ret) -@@ -982,7 +982,7 @@ fcc_store(krb5_context context, krb5_ccache id, krb5_creds *creds) - goto cleanup; - - /* Marshal the cred and write it to the file with a single append write. */ -- k5_buf_init_dynamic(&buf); -+ k5_buf_init_dynamic_zap(&buf); - k5_marshal_cred(&buf, version, creds); - ret = k5_buf_status(&buf); - if (ret) -diff --git a/src/lib/krb5/ccache/cc_keyring.c b/src/lib/krb5/ccache/cc_keyring.c -index fba710b1b..8419f6ebf 100644 ---- a/src/lib/krb5/ccache/cc_keyring.c -+++ b/src/lib/krb5/ccache/cc_keyring.c -@@ -1295,7 +1295,7 @@ krcc_store(krb5_context context, krb5_ccache id, krb5_creds *creds) - goto errout; - - /* Serialize credential using the file ccache version 4 format. */ -- k5_buf_init_dynamic(&buf); -+ k5_buf_init_dynamic_zap(&buf); - k5_marshal_cred(&buf, 4, creds); - ret = k5_buf_status(&buf); - if (ret) -diff --git a/src/util/support/utf8_conv.c b/src/util/support/utf8_conv.c -index 5cfc2c512..08cef4168 100644 ---- a/src/util/support/utf8_conv.c -+++ b/src/util/support/utf8_conv.c -@@ -99,7 +99,9 @@ k5_utf8_to_utf16le(const char *utf8, uint8_t **utf16_out, size_t *nbytes_out) - *utf16_out = NULL; - *nbytes_out = 0; - -- k5_buf_init_dynamic(&buf); -+ /* UTF-16 conversion is used for RC4 string-to-key, so treat this data as -+ * sensitive. */ -+ k5_buf_init_dynamic_zap(&buf); - - /* Examine next UTF-8 character. */ - while (*utf8 != '\0') { diff --git a/Use-libkrb5support-hex-functions-where-appropriate.patch b/Use-libkrb5support-hex-functions-where-appropriate.patch deleted file mode 100644 index eab05bc..0000000 --- a/Use-libkrb5support-hex-functions-where-appropriate.patch +++ /dev/null @@ -1,869 +0,0 @@ -From 19109505ad04efdfd70df3ee922e22bcf5a294f3 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 19 Feb 2018 00:52:35 -0500 -Subject: [PATCH] Use libkrb5support hex functions where appropriate - -(cherry picked from commit b0c700608be7455041a8afc0e4502e8783ee7f30) ---- - src/kadmin/dbutil/deps | 16 ++--- - src/kadmin/dbutil/tabdump.c | 19 +++--- - src/kadmin/ktutil/deps | 13 ++-- - src/kadmin/ktutil/ktutil_funcs.c | 30 ++++----- - src/lib/crypto/crypto_tests/deps | 39 ++++++----- - src/lib/crypto/crypto_tests/t_cksum.c | 35 +++------- - src/lib/crypto/crypto_tests/t_crc.c | 28 ++------ - src/lib/crypto/crypto_tests/t_hmac.c | 34 +++++----- - src/plugins/kdb/ldap/ldap_util/deps | 18 ++--- - .../kdb/ldap/ldap_util/kdb5_ldap_services.c | 32 +++------ - .../kdb/ldap/ldap_util/kdb5_ldap_services.h | 2 - - src/plugins/kdb/ldap/libkdb_ldap/deps | 19 +++--- - .../kdb/ldap/libkdb_ldap/ldap_service_stash.c | 65 +++---------------- - .../kdb/ldap/libkdb_ldap/ldap_service_stash.h | 3 - - .../kdb/ldap/libkdb_ldap/libkdb_ldap.exports | 1 - - src/slave/deps | 15 +++-- - src/slave/kproplog.c | 11 ++-- - src/tests/gssapi/deps | 14 ++-- - src/tests/gssapi/t_prf.c | 13 ++-- - 19 files changed, 152 insertions(+), 255 deletions(-) - -diff --git a/src/kadmin/dbutil/deps b/src/kadmin/dbutil/deps -index 4dcc33628..8b0965aac 100644 ---- a/src/kadmin/dbutil/deps -+++ b/src/kadmin/dbutil/deps -@@ -185,14 +185,14 @@ $(OUTPRE)tabdump.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/iprop.h \ - $(top_srcdir)/include/iprop_hdr.h $(top_srcdir)/include/k5-buf.h \ - $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/kdb.h $(top_srcdir)/include/kdb_log.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h kdb5_util.h tabdump.c \ -- tdumputil.h -+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ -+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/kdb.h \ -+ $(top_srcdir)/include/kdb_log.h $(top_srcdir)/include/krb5.h \ -+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -+ kdb5_util.h tabdump.c tdumputil.h - $(OUTPRE)tdumputil.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ -diff --git a/src/kadmin/dbutil/tabdump.c b/src/kadmin/dbutil/tabdump.c -index fb36b060a..2f313dbb0 100644 ---- a/src/kadmin/dbutil/tabdump.c -+++ b/src/kadmin/dbutil/tabdump.c -@@ -32,6 +32,7 @@ - - #include - #include "k5-platform.h" /* for asprintf */ -+#include "k5-hex.h" - - #include - #include -@@ -230,9 +231,7 @@ static int - write_data(struct rec_args *args, krb5_data *data) - { - int ret; -- char *p; -- size_t i; -- struct k5buf buf; -+ char *hex; - struct rechandle *h = args->rh; - struct tdopts *opts = args->opts; - -@@ -241,17 +240,15 @@ write_data(struct rec_args *args, krb5_data *data) - return -1; - return 0; - } -- k5_buf_init_dynamic(&buf); -- p = data->data; -- for (i = 0; i < data->length; i++) -- k5_buf_add_fmt(&buf, "%02x", (unsigned char)p[i]); - -- if (buf.data == NULL) { -- errno = ENOMEM; -+ ret = k5_hex_encode(data->data, data->length, FALSE, &hex); -+ if (ret) { -+ errno = ret; - return -1; - } -- ret = writefield(h, "%s", (char *)buf.data); -- k5_buf_free(&buf); -+ -+ ret = writefield(h, "%s", hex); -+ free(hex); - return ret; - } - -diff --git a/src/kadmin/ktutil/deps b/src/kadmin/ktutil/deps -index 4df399924..5863e63c7 100644 ---- a/src/kadmin/ktutil/deps -+++ b/src/kadmin/ktutil/deps -@@ -18,9 +18,10 @@ $(OUTPRE)ktutil_funcs.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ - $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h ktutil.h ktutil_funcs.c -+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ -+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -+ ktutil.h ktutil_funcs.c -diff --git a/src/kadmin/ktutil/ktutil_funcs.c b/src/kadmin/ktutil/ktutil_funcs.c -index 7a3aa0dca..5843e24b7 100644 ---- a/src/kadmin/ktutil/ktutil_funcs.c -+++ b/src/kadmin/ktutil/ktutil_funcs.c -@@ -29,6 +29,7 @@ - */ - - #include "k5-int.h" -+#include "k5-hex.h" - #include "ktutil.h" - #include - #include -@@ -106,9 +107,8 @@ krb5_error_code ktutil_add(context, list, princ_str, kvno, - krb5_keyblock key; - char buf[BUFSIZ]; - char promptstr[1024]; -- -- char *cp; -- int i, tmp; -+ uint8_t *keybytes; -+ size_t keylen; - unsigned int pwsize = BUFSIZ; - - retval = krb5_parse_name(context, princ_str, &princ); -@@ -199,24 +199,18 @@ krb5_error_code ktutil_add(context, list, princ_str, kvno, - goto cleanup; - } - -- lp->entry->key.enctype = enctype; -- lp->entry->key.contents = (krb5_octet *) malloc((strlen(buf) + 1) / 2); -- if (!lp->entry->key.contents) { -- retval = ENOMEM; -+ retval = k5_hex_decode(buf, &keybytes, &keylen); -+ if (retval) { -+ if (retval == EINVAL) { -+ fprintf(stderr, _("addent: Illegal character in key.\n")); -+ retval = 0; -+ } - goto cleanup; - } - -- i = 0; -- for (cp = buf; *cp; cp += 2) { -- if (!isxdigit((int) cp[0]) || !isxdigit((int) cp[1])) { -- fprintf(stderr, _("addent: Illegal character in key.\n")); -- retval = 0; -- goto cleanup; -- } -- sscanf(cp, "%02x", &tmp); -- lp->entry->key.contents[i++] = (krb5_octet) tmp; -- } -- lp->entry->key.length = i; -+ lp->entry->key.enctype = enctype; -+ lp->entry->key.contents = keybytes; -+ lp->entry->key.length = keylen; - } - lp->entry->principal = princ; - lp->entry->vno = kvno; -diff --git a/src/lib/crypto/crypto_tests/deps b/src/lib/crypto/crypto_tests/deps -index bc5422a06..5d94a593d 100644 ---- a/src/lib/crypto/crypto_tests/deps -+++ b/src/lib/crypto/crypto_tests/deps -@@ -73,12 +73,13 @@ $(OUTPRE)t_hmac.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(srcdir)/../builtin/crypto_mod.h $(srcdir)/../builtin/sha2/sha2.h \ - $(srcdir)/../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ - $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h t_hmac.c -+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ -+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -+ t_hmac.c - $(OUTPRE)t_pkcs5.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ -@@ -143,12 +144,13 @@ $(OUTPRE)t_cksum.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ - $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h t_cksum.c -+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ -+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -+ t_cksum.c - $(OUTPRE)t_cksums.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ -@@ -165,12 +167,13 @@ $(OUTPRE)t_crc.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(srcdir)/../builtin/crypto_mod.h $(srcdir)/../builtin/sha2/sha2.h \ - $(srcdir)/../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ - $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h t_crc.c -+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ -+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -+ t_crc.c - $(OUTPRE)t_mddriver.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \ -diff --git a/src/lib/crypto/crypto_tests/t_cksum.c b/src/lib/crypto/crypto_tests/t_cksum.c -index 2200fe76e..0edaeb850 100644 ---- a/src/lib/crypto/crypto_tests/t_cksum.c -+++ b/src/lib/crypto/crypto_tests/t_cksum.c -@@ -27,6 +27,7 @@ - /* Test checksum and checksum compatability for rsa-md[4,5]-des. */ - - #include "k5-int.h" -+#include "k5-hex.h" - - #define MD5_K5BETA_COMPAT - #define MD4_K5BETA_COMPAT -@@ -50,29 +51,6 @@ print_checksum(char *text, int number, char *message, krb5_checksum *checksum) - printf("\n"); - } - --static void --parse_hexstring(const char *s, krb5_checksum *cksum) --{ -- size_t i, len; -- unsigned int byte; -- unsigned char *cp; -- -- len = strlen(s); -- cp = malloc(len / 2); -- cksum->contents = cp; -- if (cp == NULL) { -- cksum->length = 0; -- return; -- } -- cksum->length = len / 2; -- for (i = 0; i + 1 < len; i += 2) { -- sscanf(&s[i], "%2x", &byte); -- *cp++ = byte; -- } -- cksum->checksum_type = CKTYPE; -- cksum->magic = KV5M_CHECKSUM; --} -- - /* - * Test the checksum verification of Old Style (tm) and correct RSA-MD[4,5]-DES - * checksums. -@@ -86,6 +64,7 @@ main(argc, argv) - char **argv; - { - int msgindex; -+ size_t len; - krb5_boolean valid; - krb5_keyblock keyblock; - krb5_key key; -@@ -150,12 +129,14 @@ main(argc, argv) - free(checksum.contents); - - /* Verify a known-good checksum for this plaintext. */ -- parse_hexstring(argv[msgindex+1], &knowncksum); -- if (knowncksum.contents == NULL) { -- printf("parse_hexstring failed\n"); -- kret = 1; -+ kret = k5_hex_decode(argv[msgindex + 1], &knowncksum.contents, &len); -+ if (kret) { -+ printf("k5_hex_decode failed\n"); - break; - } -+ knowncksum.length = len; -+ knowncksum.checksum_type = CKTYPE; -+ knowncksum.magic = KV5M_CHECKSUM; - kret = krb5_k_verify_checksum(NULL, key, 0, &plaintext, &knowncksum, - &valid); - if (kret != 0) { -diff --git a/src/lib/crypto/crypto_tests/t_crc.c b/src/lib/crypto/crypto_tests/t_crc.c -index 190773252..1a35cfba5 100644 ---- a/src/lib/crypto/crypto_tests/t_crc.c -+++ b/src/lib/crypto/crypto_tests/t_crc.c -@@ -32,6 +32,7 @@ - #include - #include - #include -+#include - #include "crypto_int.h" - - #define HEX 1 -@@ -139,31 +140,12 @@ timetest(unsigned int nblk, unsigned int blksiz) - } - #endif - --static void gethexstr(char *data, size_t *outlen, unsigned char *outbuf, -- size_t buflen) --{ -- size_t inlen; -- char *cp, buf[3]; -- long n; -- -- inlen = strlen(data); -- *outlen = 0; -- for (cp = data; (size_t) (cp - data) < inlen; cp += 2) { -- strncpy(buf, cp, 2); -- buf[2] = '\0'; -- n = strtol(buf, NULL, 16); -- outbuf[(*outlen)++] = n; -- if (*outlen > buflen) -- break; -- } --} -- - static void - verify(void) - { - unsigned int i; - struct crc_trial trial; -- unsigned char buf[4]; -+ uint8_t *bytes; - size_t len; - unsigned long cksum; - char *typestr; -@@ -179,9 +161,11 @@ verify(void) - break; - case HEX: - typestr = "HEX"; -- gethexstr(trial.data, &len, buf, 4); -+ if (k5_hex_decode(trial.data, &bytes, &len) != 0) -+ abort(); - cksum = 0; -- mit_crc32(buf, len, &cksum); -+ mit_crc32(bytes, len, &cksum); -+ free(bytes); - break; - default: - typestr = "BOGUS"; -diff --git a/src/lib/crypto/crypto_tests/t_hmac.c b/src/lib/crypto/crypto_tests/t_hmac.c -index 8961380ea..93d54828f 100644 ---- a/src/lib/crypto/crypto_tests/t_hmac.c -+++ b/src/lib/crypto/crypto_tests/t_hmac.c -@@ -34,6 +34,7 @@ - #include - #include - -+#include - #include "crypto_int.h" - - #define ASIZE(ARRAY) (sizeof(ARRAY)/sizeof(ARRAY[0])) -@@ -136,12 +137,10 @@ static void test_hmac() - { - krb5_keyblock key; - krb5_data in, out; -- char outbuf[20]; -- char stroutbuf[80]; -+ char outbuf[20], *hexdigest; - krb5_error_code err; -- unsigned int i, j; -+ unsigned int i; - int lose = 0; -- struct k5buf buf; - - /* RFC 2202 test vector. */ - static const struct hmac_test md5tests[] = { -@@ -151,13 +150,13 @@ static void test_hmac() - 0xb, 0xb, 0xb, 0xb, 0xb, 0xb, 0xb, 0xb, - }, - 8, "Hi There", -- "0x9294727a3638bb1c13f48ef8158bfc9d" -+ "9294727a3638bb1c13f48ef8158bfc9d" - }, - - { - 4, "Jefe", - 28, "what do ya want for nothing?", -- "0x750c783e6ab0b503eaa86e310a5db738" -+ "750c783e6ab0b503eaa86e310a5db738" - }, - - { -@@ -172,7 +171,7 @@ static void test_hmac() - 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, - 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, - }, -- "0x56be34521d144c88dbb8c733f0e8b3f6" -+ "56be34521d144c88dbb8c733f0e8b3f6" - }, - - { -@@ -188,7 +187,7 @@ static void test_hmac() - 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, - 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, 0xcd, - }, -- "0x697eaf0aca3a3aea3a75164746ffaa79" -+ "697eaf0aca3a3aea3a75164746ffaa79" - }, - - { -@@ -197,7 +196,7 @@ static void test_hmac() - 0x0c, 0x0c, 0x0c, 0x0c, 0x0c, 0x0c, 0x0c, 0x0c - }, - 20, "Test With Truncation", -- "0x56461ef2342edc00f9bab995690efd4c" -+ "56461ef2342edc00f9bab995690efd4c" - }, - - { -@@ -212,7 +211,7 @@ static void test_hmac() - 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, - }, - 54, "Test Using Larger Than Block-Size Key - Hash Key First", -- "0x6b1ab7fe4bd7bf8f0b62e6ce61b9d0cd" -+ "6b1ab7fe4bd7bf8f0b62e6ce61b9d0cd" - }, - - { -@@ -228,7 +227,7 @@ static void test_hmac() - }, - 73, - "Test Using Larger Than Block-Size Key and Larger Than One Block-Size Data", -- "0x6f630fad67cda0ee1fb1f562db3aa53e" -+ "6f630fad67cda0ee1fb1f562db3aa53e" - }, - }; - -@@ -246,19 +245,16 @@ static void test_hmac() - exit(1); - } - -- k5_buf_init_fixed(&buf, stroutbuf, sizeof(stroutbuf)); -- k5_buf_add(&buf, "0x"); -- for (j = 0; j < out.length; j++) -- k5_buf_add_fmt(&buf, "%02x", 0xff & outbuf[j]); -- if (k5_buf_status(&buf) != 0) -+ if (k5_hex_encode(out.data, out.length, FALSE, &hexdigest) != 0) - abort(); -- if (strcmp(stroutbuf, md5tests[i].hexdigest)) { -+ if (strcmp(hexdigest, md5tests[i].hexdigest)) { - printf("*** CHECK FAILED!\n" -- "\tReturned: %s.\n" -- "\tExpected: %s.\n", stroutbuf, md5tests[i].hexdigest); -+ "\tReturned: 0x%s.\n" -+ "\tExpected: 0x%s.\n", hexdigest, md5tests[i].hexdigest); - lose++; - } else - printf("Matches expected result.\n"); -+ free(hexdigest); - } - - /* Do again with SHA-1 tests.... */ -diff --git a/src/plugins/kdb/ldap/ldap_util/deps b/src/plugins/kdb/ldap/ldap_util/deps -index 75d4dd0cf..be0194c00 100644 ---- a/src/plugins/kdb/ldap/ldap_util/deps -+++ b/src/plugins/kdb/ldap/ldap_util/deps -@@ -89,15 +89,15 @@ $(OUTPRE)kdb5_ldap_services.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(srcdir)/../libkdb_ldap/ldap_krbcontainer.h $(srcdir)/../libkdb_ldap/ldap_misc.h \ - $(srcdir)/../libkdb_ldap/ldap_realm.h $(top_srcdir)/include/k5-buf.h \ - $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/kdb.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- $(top_srcdir)/lib/kdb/kdb5.h kdb5_ldap_list.h kdb5_ldap_policy.h \ -- kdb5_ldap_realm.h kdb5_ldap_services.c kdb5_ldap_services.h \ -- kdb5_ldap_util.h -+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ -+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/kdb.h \ -+ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -+ $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -+ $(top_srcdir)/include/socket-utils.h $(top_srcdir)/lib/kdb/kdb5.h \ -+ kdb5_ldap_list.h kdb5_ldap_policy.h kdb5_ldap_realm.h \ -+ kdb5_ldap_services.c kdb5_ldap_services.h kdb5_ldap_util.h - $(OUTPRE)getdate.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h \ - getdate.c -diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c -index 3d6994c67..ce038fc3d 100644 ---- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c -+++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c -@@ -37,6 +37,7 @@ - */ - - #include -+#include - #include "kdb5_ldap_util.h" - #include "kdb5_ldap_list.h" - -@@ -96,11 +97,10 @@ kdb5_ldap_stash_service_password(int argc, char **argv) - char *service_object = NULL; - char *file_name = NULL, *tmp_file = NULL; - char passwd[MAX_SERVICE_PASSWD_LEN]; -- char *str = NULL; -+ char *str = NULL, *hexpasswd = NULL; - char line[MAX_LEN]; - FILE *pfile = NULL; - krb5_boolean print_usage = FALSE; -- krb5_data hexpasswd = {0, 0, NULL}; - mode_t old_mode = 0; - - /* -@@ -183,21 +183,12 @@ kdb5_ldap_stash_service_password(int argc, char **argv) - } - - /* Convert the password to hexadecimal */ -- { -- krb5_data pwd; -- -- pwd.length = passwd_len; -- pwd.data = passwd; -- -- ret = tohex(pwd, &hexpasswd); -- if (ret != 0) { -- com_err(me, ret, -- _("Failed to convert the password to hexadecimal")); -- memset(passwd, 0, passwd_len); -- goto cleanup; -- } -+ ret = k5_hex_encode(passwd, passwd_len, FALSE, &hexpasswd); -+ zap(passwd, passwd_len); -+ if (ret != 0) { -+ com_err(me, ret, _("Failed to convert the password to hexadecimal")); -+ goto cleanup; - } -- memset(passwd, 0, passwd_len); - - /* TODO: file lock for the service password file */ - -@@ -225,7 +216,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv) - if (str == NULL) { - if (feof(pfile)) { - /* If the service object dn is not present in the service password file */ -- if (fprintf(pfile, "%s#{HEX}%s\n", service_object, hexpasswd.data) < 0) { -+ if (fprintf(pfile, "%s#{HEX}%s\n", service_object, hexpasswd) < 0) { - com_err(me, errno, - _("Failed to write service object password to file")); - fclose(pfile); -@@ -277,7 +268,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv) - while (fgets(line, MAX_LEN, pfile) != NULL) { - if (((str = strstr(line, service_object)) != NULL) && - (line[strlen(service_object)] == '#')) { -- if (fprintf(newfile, "%s#{HEX}%s\n", service_object, hexpasswd.data) < 0) { -+ if (fprintf(newfile, "%s#{HEX}%s\n", service_object, hexpasswd) < 0) { - com_err(me, errno, _("Failed to write service object " - "password to file")); - fclose(newfile); -@@ -322,10 +313,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv) - - cleanup: - -- if (hexpasswd.length != 0) { -- memset(hexpasswd.data, 0, hexpasswd.length); -- free(hexpasswd.data); -- } -+ zapfreestr(hexpasswd); - - if (service_object) - free(service_object); -diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.h b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.h -index cf652c578..08af62e17 100644 ---- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.h -+++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.h -@@ -32,6 +32,4 @@ - #define MAX_LEN 1024 - #define MAX_SERVICE_PASSWD_LEN 256 - --extern int tohex(krb5_data, krb5_data *); -- - extern void kdb5_ldap_stash_service_password(int argc, char **argv); -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/deps b/src/plugins/kdb/ldap/libkdb_ldap/deps -index 1ff28553f..afca604dc 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/deps -+++ b/src/plugins/kdb/ldap/libkdb_ldap/deps -@@ -220,15 +220,16 @@ ldap_service_stash.so ldap_service_stash.po $(OUTPRE)ldap_service_stash.$(OBJEXT - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ - $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/kdb.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h $(top_srcdir)/lib/kdb/kdb5.h \ -- kdb_ldap.h ldap_handle.h ldap_krbcontainer.h ldap_main.h \ -- ldap_misc.h ldap_realm.h ldap_service_stash.c ldap_service_stash.h -+ $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-hex.h \ -+ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -+ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -+ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -+ $(top_srcdir)/include/kdb.h $(top_srcdir)/include/krb5.h \ -+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -+ $(top_srcdir)/lib/kdb/kdb5.h kdb_ldap.h ldap_handle.h \ -+ ldap_krbcontainer.h ldap_main.h ldap_misc.h ldap_realm.h \ -+ ldap_service_stash.c ldap_service_stash.h - kdb_xdr.so kdb_xdr.po $(OUTPRE)kdb_xdr.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c -index 87a2118ff..cb30f4a7f 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.c -@@ -31,16 +31,16 @@ - #include "ldap_main.h" - #include "kdb_ldap.h" - #include "ldap_service_stash.h" -+#include - #include - - /* Decode a password of the form {HEX}. */ - static krb5_error_code - dec_password(krb5_context context, const char *str, char **password_out) - { -+ krb5_error_code ret; -+ uint8_t *bytes; - size_t len; -- const unsigned char *p; -- unsigned char *password, *q; -- unsigned int k; - - *password_out = NULL; - -@@ -48,30 +48,15 @@ dec_password(krb5_context context, const char *str, char **password_out) - k5_setmsg(context, EINVAL, _("Not a hexadecimal password")); - return EINVAL; - } -- str += 5; - -- len = strlen(str); -- if (len % 2 != 0) { -- k5_setmsg(context, EINVAL, _("Password corrupt")); -- return EINVAL; -+ ret = k5_hex_decode(str + 5, &bytes, &len); -+ if (ret) { -+ if (ret == EINVAL) -+ k5_setmsg(context, ret, _("Password corrupt")); -+ return ret; - } - -- q = password = malloc(len / 2 + 1); -- if (password == NULL) -- return ENOMEM; -- -- for (p = (unsigned char *)str; *p != '\0'; p += 2) { -- if (!isxdigit(*p) || !isxdigit(p[1])) { -- free(password); -- k5_setmsg(context, EINVAL, _("Password corrupt")); -- return EINVAL; -- } -- sscanf((char *)p, "%2x", &k); -- *q++ = k; -- } -- *q = '\0'; -- -- *password_out = (char *)password; -+ *password_out = (char *)bytes; - return 0; - } - -@@ -128,35 +113,3 @@ krb5_ldap_readpassword(krb5_context context, const char *filename, - /* Extract the plain password information. */ - return dec_password(context, val, password_out); - } -- --/* Encodes a sequence of bytes in hexadecimal */ -- --int --tohex(krb5_data in, krb5_data *ret) --{ -- unsigned int i=0; -- int err = 0; -- -- ret->length = 0; -- ret->data = NULL; -- -- ret->data = malloc((unsigned int)in.length * 2 + 1 /*Null termination */); -- if (ret->data == NULL) { -- err = ENOMEM; -- goto cleanup; -- } -- ret->length = in.length * 2; -- ret->data[ret->length] = 0; -- -- for (i = 0; i < in.length; i++) -- snprintf(ret->data + 2 * i, 3, "%02x", in.data[i] & 0xff); -- --cleanup: -- -- if (ret->length == 0) { -- free(ret->data); -- ret->data = NULL; -- } -- -- return err; --} -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.h b/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.h -index dbf62443a..03cf9a1f7 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.h -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_service_stash.h -@@ -37,7 +37,4 @@ krb5_error_code - krb5_ldap_readpassword(krb5_context context, const char *filename, - const char *name, char **password_out); - --int --tohex(krb5_data, krb5_data *); -- - #endif -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/libkdb_ldap.exports b/src/plugins/kdb/ldap/libkdb_ldap/libkdb_ldap.exports -index 2342f1db8..5376d3453 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/libkdb_ldap.exports -+++ b/src/plugins/kdb/ldap/libkdb_ldap/libkdb_ldap.exports -@@ -1,4 +1,3 @@ --tohex - krb5_ldap_open - krb5_ldap_close - krb5_ldap_db_init -diff --git a/src/slave/deps b/src/slave/deps -index c3677a5e1..c0f558ecd 100644 ---- a/src/slave/deps -+++ b/src/slave/deps -@@ -64,10 +64,11 @@ $(OUTPRE)kproplog.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/iprop.h \ - $(top_srcdir)/include/iprop_hdr.h $(top_srcdir)/include/k5-buf.h \ - $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/kdb.h $(top_srcdir)/include/kdb_log.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h kproplog.c -+ $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ -+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/kdb.h \ -+ $(top_srcdir)/include/kdb_log.h $(top_srcdir)/include/krb5.h \ -+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -+ $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -+ kproplog.c -diff --git a/src/slave/kproplog.c b/src/slave/kproplog.c -index 4f19eeb8c..d4aed7ba6 100644 ---- a/src/slave/kproplog.c -+++ b/src/slave/kproplog.c -@@ -9,6 +9,7 @@ - */ - - #include "k5-int.h" -+#include "k5-hex.h" - #include - #include - #include -@@ -106,15 +107,15 @@ print_deltat(uint32_t *deltat) - static void - print_hex(const char *tag, utf8str_t *str) - { -- unsigned int i; - unsigned int len; -+ char *hex; - - len = str->utf8str_t_len; - -- printf("\t\t\t%s(%d): 0x", tag, len); -- for (i = 0; i < len; i++) -- printf("%02x", (krb5_octet)str->utf8str_t_val[i]); -- printf("\n"); -+ if (k5_hex_encode(str->utf8str_t_val, len, FALSE, &hex) != 0) -+ abort(); -+ printf("\t\t\t%s(%d): 0x%s\n", tag, len, hex); -+ free(hex); - } - - /* Display string primitive. */ -diff --git a/src/tests/gssapi/deps b/src/tests/gssapi/deps -index b784deb63..0b50d9ed3 100644 ---- a/src/tests/gssapi/deps -+++ b/src/tests/gssapi/deps -@@ -149,13 +149,13 @@ $(OUTPRE)t_prf.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(srcdir)/../../lib/gssapi/krb5/gssapiP_krb5.h $(srcdir)/../../lib/gssapi/krb5/gssapi_krb5.h \ - $(srcdir)/../../lib/gssapi/mechglue/mechglue.h $(srcdir)/../../lib/gssapi/mechglue/mglueP.h \ - $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- common.h t_prf.c -+ $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-hex.h \ -+ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -+ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -+ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -+ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -+ $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -+ $(top_srcdir)/include/socket-utils.h common.h t_prf.c - $(OUTPRE)t_s4u.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ - $(BUILDTOP)/include/gssapi/gssapi_ext.h $(BUILDTOP)/include/gssapi/gssapi_krb5.h \ - $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h \ -diff --git a/src/tests/gssapi/t_prf.c b/src/tests/gssapi/t_prf.c -index 2c8c85188..6a698ce0f 100644 ---- a/src/tests/gssapi/t_prf.c -+++ b/src/tests/gssapi/t_prf.c -@@ -24,6 +24,7 @@ - */ - - #include "k5-int.h" -+#include "k5-hex.h" - #include "common.h" - #include "mglueP.h" - #include "gssapiP_krb5.h" -@@ -109,12 +110,14 @@ static struct { - static size_t - fromhex(const char *hexstr, unsigned char *out) - { -- const char *p; -- size_t count; -+ uint8_t *bytes; -+ size_t len; - -- for (p = hexstr, count = 0; *p != '\0'; p += 2, count++) -- sscanf(p, "%2hhx", &out[count]); -- return count; -+ if (k5_hex_decode(hexstr, &bytes, &len) != 0) -+ abort(); -+ memcpy(out, bytes, len); -+ free(bytes); -+ return len; - } - - int diff --git a/Use-port-sockets.h-macros-in-cc_kcm-sendto_kdc.patch b/Use-port-sockets.h-macros-in-cc_kcm-sendto_kdc.patch deleted file mode 100644 index 56b83c3..0000000 --- a/Use-port-sockets.h-macros-in-cc_kcm-sendto_kdc.patch +++ /dev/null @@ -1,138 +0,0 @@ -From 76fc514d3d00b8ac9f7844ade35c08eaa7c8a1fc Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 15 Oct 2018 19:12:45 -0400 -Subject: [PATCH] Use port-sockets.h macros in cc_kcm, sendto_kdc - -Use SOCKET_CONNECT in cc_kcm.c and sendto_kdc.c to prevent SIGPIPE on -BSD-like systems. Use other port-sockets.h macros in cc_kcm.c in case -it is ever used on Windows. - -ticket: 8753 -(cherry picked from commit 2aaf0e74805e295358627ac1e5d589d625d8e6b0) ---- - src/lib/krb5/ccache/cc_kcm.c | 34 ++++++++++++++++++---------------- - src/lib/krb5/os/sendto_kdc.c | 3 ++- - 2 files changed, 20 insertions(+), 17 deletions(-) - -diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c -index a777f2710..b260cd81b 100644 ---- a/src/lib/krb5/ccache/cc_kcm.c -+++ b/src/lib/krb5/ccache/cc_kcm.c -@@ -42,6 +42,7 @@ - #include "k5-input.h" - #include "cc-int.h" - #include "kcm.h" -+#include "../os/os-proto.h" - #include - #include - #ifdef __APPLE__ -@@ -61,7 +62,7 @@ struct uuid_list { - }; - - struct kcmio { -- int fd; -+ SOCKET fd; - #ifdef __APPLE__ - mach_port_t mport; - #endif -@@ -252,7 +253,7 @@ static krb5_error_code - kcmio_unix_socket_connect(krb5_context context, struct kcmio *io) - { - krb5_error_code ret; -- int fd = -1; -+ SOCKET fd = INVALID_SOCKET; - struct sockaddr_un addr; - char *path = NULL; - -@@ -267,25 +268,25 @@ kcmio_unix_socket_connect(krb5_context context, struct kcmio *io) - } - - fd = socket(AF_UNIX, SOCK_STREAM, 0); -- if (fd == -1) { -- ret = errno; -+ if (fd == INVALID_SOCKET) { -+ ret = SOCKET_ERRNO; - goto cleanup; - } - - memset(&addr, 0, sizeof(addr)); - addr.sun_family = AF_UNIX; - strlcpy(addr.sun_path, path, sizeof(addr.sun_path)); -- if (connect(fd, (struct sockaddr *)&addr, sizeof(addr)) != 0) { -- ret = (errno == ENOENT) ? KRB5_KCM_NO_SERVER : errno; -+ if (SOCKET_CONNECT(fd, (struct sockaddr *)&addr, sizeof(addr)) != 0) { -+ ret = (SOCKET_ERRNO == ENOENT) ? KRB5_KCM_NO_SERVER : SOCKET_ERRNO; - goto cleanup; - } - - io->fd = fd; -- fd = -1; -+ fd = INVALID_SOCKET; - - cleanup: -- if (fd != -1) -- close(fd); -+ if (fd != INVALID_SOCKET) -+ closesocket(fd); - profile_release_string(path); - return ret; - } -@@ -297,11 +298,12 @@ kcmio_unix_socket_write(krb5_context context, struct kcmio *io, void *request, - size_t len) - { - char lenbytes[4]; -+ sg_buf sg[2]; - -+ SG_SET(&sg[0], lenbytes, sizeof(lenbytes)); -+ SG_SET(&sg[1], request, len); - store_32_be(len, lenbytes); -- if (krb5_net_write(context, io->fd, lenbytes, 4) < 0) -- return errno; -- if (krb5_net_write(context, io->fd, request, len) < 0) -+ if (krb5int_net_writev(context, io->fd, sg, 2) < 0) - return errno; - return 0; - } -@@ -358,7 +360,7 @@ kcmio_connect(krb5_context context, struct kcmio **io_out) - io = calloc(1, sizeof(*io)); - if (io == NULL) - return ENOMEM; -- io->fd = -1; -+ io->fd = INVALID_SOCKET; - - /* Try Mach RPC (macOS only), then fall back to Unix domain sockets */ - ret = kcmio_mach_connect(context, io); -@@ -384,7 +386,7 @@ kcmio_call(krb5_context context, struct kcmio *io, struct kcmreq *req) - if (k5_buf_status(&req->reqbuf) != 0) - return ENOMEM; - -- if (io->fd != -1) { -+ if (io->fd != INVALID_SOCKET) { - ret = kcmio_unix_socket_write(context, io, req->reqbuf.data, - req->reqbuf.len); - if (ret) -@@ -411,8 +413,8 @@ kcmio_close(struct kcmio *io) - { - if (io != NULL) { - kcmio_mach_close(io); -- if (io->fd != -1) -- close(io->fd); -+ if (io->fd != INVALID_SOCKET) -+ closesocket(io->fd); - free(io); - } - } -diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c -index e8bc0ad6e..0ed6b1d70 100644 ---- a/src/lib/krb5/os/sendto_kdc.c -+++ b/src/lib/krb5/os/sendto_kdc.c -@@ -880,7 +880,8 @@ start_connection(krb5_context context, struct conn_state *state, - } - - /* Start connecting to KDC. */ -- e = connect(fd, (struct sockaddr *)&state->addr.saddr, state->addr.len); -+ e = SOCKET_CONNECT(fd, (struct sockaddr *)&state->addr.saddr, -+ state->addr.len); - if (e != 0) { - /* - * This is the path that should be followed for non-blocking diff --git a/Zap-copy-of-secret-in-RC4-string-to-key.patch b/Zap-copy-of-secret-in-RC4-string-to-key.patch deleted file mode 100644 index 7502c25..0000000 --- a/Zap-copy-of-secret-in-RC4-string-to-key.patch +++ /dev/null @@ -1,30 +0,0 @@ -From 55a8161c3f5238df522447499a38bf2e9497b074 Mon Sep 17 00:00:00 2001 -From: Dylan Gray <35609490+Dylan-MSFT@users.noreply.github.com> -Date: Fri, 13 Jul 2018 15:09:01 -0700 -Subject: [PATCH] Zap copy of secret in RC4 string-to-key - -Commit b8814745049b5f401e3ae39a81dc1e14598ae48c (ticket 8576) added a -zero-terminated copy of the input string in -krb5int_arcfour_string_to_key(). This copy should be zeroed when -freed as the input string typically contains a password. - -[ghudson@mit.edu: rewrote commit message] - -ticket: 8713 (new) ---- - src/lib/crypto/krb/s2k_rc4.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/lib/crypto/krb/s2k_rc4.c b/src/lib/crypto/krb/s2k_rc4.c -index 081a91217..f7e699d60 100644 ---- a/src/lib/crypto/krb/s2k_rc4.c -+++ b/src/lib/crypto/krb/s2k_rc4.c -@@ -25,7 +25,7 @@ krb5int_arcfour_string_to_key(const struct krb5_keytypes *ktp, - if (utf8 == NULL) - return err; - err = k5_utf8_to_utf16le(utf8, ©str, ©strlen); -- free(utf8); -+ zapfree(utf8, string->length); - if (err) - return err; - diff --git a/Zap-data-when-freeing-krb5_spake_factor.patch b/Zap-data-when-freeing-krb5_spake_factor.patch deleted file mode 100644 index 9ce2462..0000000 --- a/Zap-data-when-freeing-krb5_spake_factor.patch +++ /dev/null @@ -1,29 +0,0 @@ -From 5d970e16e768a134e65ee7cf367b8f34a80e0980 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 27 Mar 2018 15:42:28 -0400 -Subject: [PATCH] Zap data when freeing krb5_spake_factor - -krb5_spake_factor structures will sometimes hold sensitive data when -second-factor SPAKE is implemented, so should be zapped when freed. - -ticket: 8647 -(cherry picked from commit 9cc94a3f1ce06a4430f684300a747ec079102403) ---- - src/lib/krb5/krb/kfree.c | 4 +++- - 1 file changed, 3 insertions(+), 1 deletion(-) - -diff --git a/src/lib/krb5/krb/kfree.c b/src/lib/krb5/krb/kfree.c -index e1ea1494a..71e7fcad0 100644 ---- a/src/lib/krb5/krb/kfree.c -+++ b/src/lib/krb5/krb/kfree.c -@@ -897,7 +897,9 @@ k5_free_spake_factor(krb5_context context, krb5_spake_factor *val) - { - if (val == NULL) - return; -- krb5_free_data(context, val->data); -+ if (val->data != NULL) -+ zapfree(val->data->data, val->data->length); -+ free(val->data); - free(val); - } - diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch index ddd3ec2..8cff1ca 100644 --- a/krb5-1.11-kpasswdtest.patch +++ b/krb5-1.11-kpasswdtest.patch @@ -1,4 +1,4 @@ -From fc2953ce9ce06ff896b1687e1c0cc9b8a4357d09 Mon Sep 17 00:00:00 2001 +From 90dd728245603a47e84dd3ba783c9c0a81ffc1a7 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:52:01 -0400 Subject: [PATCH] krb5-1.11-kpasswdtest.patch diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch index febb3b3..bbe3b7c 100644 --- a/krb5-1.11-run_user_0.patch +++ b/krb5-1.11-run_user_0.patch @@ -1,4 +1,4 @@ -From b0adf9a65d5c22a77cf957ceb1c298baff01555d Mon Sep 17 00:00:00 2001 +From f325467c9d2298fd17d0fb223a2aeff37fed6ce6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:57 -0400 Subject: [PATCH] krb5-1.11-run_user_0.patch diff --git a/krb5-1.12-api.patch b/krb5-1.12-api.patch index 9eba2ff..eccb1a1 100644 --- a/krb5-1.12-api.patch +++ b/krb5-1.12-api.patch @@ -1,4 +1,4 @@ -From abb19d2d2eac5f9f6e4a1bf26f59f3a62143dab9 Mon Sep 17 00:00:00 2001 +From 77ac260bdbd1fdd5fded4738b57bb05c5f1e7480 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:00 -0400 Subject: [PATCH] krb5-1.12-api.patch diff --git a/krb5-1.12-ksu-path.patch b/krb5-1.12-ksu-path.patch index 19b9e73..0ecb9d8 100644 --- a/krb5-1.12-ksu-path.patch +++ b/krb5-1.12-ksu-path.patch @@ -1,4 +1,4 @@ -From 7f076496c7441cd108929aa05dbe009f34054bf5 Mon Sep 17 00:00:00 2001 +From 5bd610ea4b4898b64e92e335327d9c5bc17c01fc Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:32:09 -0400 Subject: [PATCH] krb5-1.12-ksu-path.patch diff --git a/krb5-1.12-ktany.patch b/krb5-1.12-ktany.patch index de59827..d5d116f 100644 --- a/krb5-1.12-ktany.patch +++ b/krb5-1.12-ktany.patch @@ -1,4 +1,4 @@ -From 01acbf3cbd60bd460e6ec6702589451d19c89933 Mon Sep 17 00:00:00 2001 +From 4950d6b9bff6fd4ede043946d20fffc0303af2ea Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:33:53 -0400 Subject: [PATCH] krb5-1.12-ktany.patch diff --git a/krb5-1.12.1-pam.patch b/krb5-1.12.1-pam.patch index 97c1e8f..4696ea5 100644 --- a/krb5-1.12.1-pam.patch +++ b/krb5-1.12.1-pam.patch @@ -1,4 +1,4 @@ -From 4cbb4325a86d1d71fa45d254221ec460c41b434d Mon Sep 17 00:00:00 2001 +From 6d4f52b62dd2213704ac4361f9ef6c017ec78085 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] krb5-1.12.1-pam.patch @@ -28,10 +28,10 @@ changes we're proposing for how it handles cache collections. create mode 100644 src/clients/ksu/pam.h diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index d6d1279c3..5c9c13e5f 100644 +index 3752d9bd5..340546d80 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -1696,3 +1696,70 @@ AC_DEFUN(KRB5_AC_PERSISTENT_KEYRING,[ +@@ -1697,3 +1697,70 @@ AC_DEFUN(KRB5_AC_PERSISTENT_KEYRING,[ ])) ])dnl dnl @@ -141,7 +141,7 @@ index b2fcbf240..5755bb58a 100644 clean: $(RM) ksu diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c -index 7ff676ca7..c6321c01b 100644 +index d9596d948..ec06788bc 100644 --- a/src/clients/ksu/main.c +++ b/src/clients/ksu/main.c @@ -26,6 +26,7 @@ @@ -171,7 +171,7 @@ index 7ff676ca7..c6321c01b 100644 /***********/ #define KS_TEMPORARY_CACHE "MEMORY:_ksu" -@@ -515,6 +521,23 @@ main (argc, argv) +@@ -528,6 +534,23 @@ main (argc, argv) prog_name,target_user,client_name, source_user,ontty()); @@ -195,7 +195,7 @@ index 7ff676ca7..c6321c01b 100644 /* Run authorization as target.*/ if (krb5_seteuid(target_uid)) { com_err(prog_name, errno, _("while switching to target for " -@@ -575,6 +598,24 @@ main (argc, argv) +@@ -588,6 +611,24 @@ main (argc, argv) exit(1); } @@ -220,7 +220,7 @@ index 7ff676ca7..c6321c01b 100644 } if( some_rest_copy){ -@@ -632,6 +673,30 @@ main (argc, argv) +@@ -645,6 +686,30 @@ main (argc, argv) exit(1); } @@ -251,7 +251,7 @@ index 7ff676ca7..c6321c01b 100644 /* set permissions */ if (setgid(target_pwd->pw_gid) < 0) { perror("ksu: setgid"); -@@ -729,7 +794,7 @@ main (argc, argv) +@@ -742,7 +807,7 @@ main (argc, argv) fprintf(stderr, "program to be execed %s\n",params[0]); } @@ -260,7 +260,7 @@ index 7ff676ca7..c6321c01b 100644 execv(params[0], params); com_err(prog_name, errno, _("while trying to execv %s"), params[0]); sweep_up(ksu_context, cc_target); -@@ -759,16 +824,35 @@ main (argc, argv) +@@ -772,16 +837,35 @@ main (argc, argv) if (ret_pid == -1) { com_err(prog_name, errno, _("while calling waitpid")); } @@ -756,10 +756,10 @@ index 000000000..0ab76569c +void appl_pam_cleanup(void); +#endif diff --git a/src/configure.in b/src/configure.in -index 10f45eb12..7288a71ec 100644 +index 84529c120..5d5f148ca 100644 --- a/src/configure.in +++ b/src/configure.in -@@ -1306,6 +1306,8 @@ AC_SUBST([VERTO_VERSION]) +@@ -1348,6 +1348,8 @@ AC_SUBST([VERTO_VERSION]) AC_PATH_PROG(GROFF, groff) diff --git a/krb5-1.13-dirsrv-accountlock.patch b/krb5-1.13-dirsrv-accountlock.patch index ff5f73e..199630d 100644 --- a/krb5-1.13-dirsrv-accountlock.patch +++ b/krb5-1.13-dirsrv-accountlock.patch @@ -1,4 +1,4 @@ -From bd9a3cc0c53f6dc47a124eb6e8f698c7f1d3cd36 Mon Sep 17 00:00:00 2001 +From c6f1e5922c457e46566728b859c8cfd7dfcca873 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:44 -0400 Subject: [PATCH] krb5-1.13-dirsrv-accountlock.patch @@ -12,10 +12,10 @@ original version filed as RT#5891. 3 files changed, 29 insertions(+) diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 5eeaa2d8a..1fd243094 100644 +index db18226ed..518b1a547 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -1677,6 +1677,15 @@ if test "$with_ldap" = yes; then +@@ -1678,6 +1678,15 @@ if test "$with_ldap" = yes; then AC_MSG_NOTICE(enabling OpenLDAP database backend module support) OPENLDAP_PLUGIN=yes fi diff --git a/krb5-1.15-beta1-buildconf.patch b/krb5-1.15-beta1-buildconf.patch index a949727..da392ac 100644 --- a/krb5-1.15-beta1-buildconf.patch +++ b/krb5-1.15-beta1-buildconf.patch @@ -1,4 +1,4 @@ -From 162ba7fbce23d82719956de1b126e48fe676e9d1 Mon Sep 17 00:00:00 2001 +From 15a15da6b29fd16faee37560a0d099164fc927a1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] krb5-1.15-beta1-buildconf.patch @@ -33,7 +33,7 @@ index c17cb5eb5..1891dea99 100755 lib_flags="$lib_flags -lkdb5 $KDB5_DB_LIB" library=krb5 diff --git a/src/config/pre.in b/src/config/pre.in -index d4714d29a..03f5c8890 100644 +index 917357df9..a8540ae2a 100644 --- a/src/config/pre.in +++ b/src/config/pre.in @@ -185,7 +185,7 @@ INSTALL_PROGRAM=@INSTALL_PROGRAM@ $(INSTALL_STRIP) diff --git a/krb5-1.15.1-selinux-label.patch b/krb5-1.17-beta1-selinux-label.patch similarity index 93% rename from krb5-1.15.1-selinux-label.patch rename to krb5-1.17-beta1-selinux-label.patch index 728c72e..8e67789 100644 --- a/krb5-1.15.1-selinux-label.patch +++ b/krb5-1.17-beta1-selinux-label.patch @@ -1,7 +1,7 @@ -From c79d3881fefb6108306eb56cff62de03897d4bbc Mon Sep 17 00:00:00 2001 +From f1ccca4209dea8da5135a3b4c34f925ef9e08824 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 -Subject: [PATCH] krb5-1.15.1-selinux-label.patch +Subject: [PATCH] krb5-1.17-beta1-selinux-label.patch SELinux bases access to files on the domain of the requesting process, the operation being performed, and the context applied to the file. @@ -45,6 +45,7 @@ which we used earlier, is some improvement. src/include/krb5/krb5.hin | 6 + src/kadmin/dbutil/dump.c | 11 +- src/kdc/main.c | 2 +- + src/kprop/kpropd.c | 9 + src/lib/kadm5/logger.c | 4 +- src/lib/kdb/kdb_log.c | 2 +- src/lib/krb5/ccache/cc_dir.c | 26 +- @@ -57,7 +58,6 @@ which we used earlier, is some improvement. src/plugins/kdb/db2/libdb2/hash/hash.c | 3 +- src/plugins/kdb/db2/libdb2/recno/rec_open.c | 4 +- .../kdb/ldap/ldap_util/kdb5_ldap_services.c | 11 +- - src/slave/kpropd.c | 9 + src/util/profile/prof_file.c | 3 +- src/util/support/Makefile.in | 3 +- src/util/support/selinux.c | 406 ++++++++++++++++++ @@ -66,7 +66,7 @@ which we used earlier, is some improvement. create mode 100644 src/util/support/selinux.c diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 5c9c13e5f..6257dba40 100644 +index 340546d80..a7afec09e 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 @@ -89,6 +89,7 @@ AC_SUBST_FILE(libnodeps_frag) @@ -77,7 +77,7 @@ index 5c9c13e5f..6257dba40 100644 KRB5_LIB_PARAMS KRB5_AC_INITFINI KRB5_AC_ENABLE_THREADS -@@ -1763,3 +1764,51 @@ AC_SUBST(PAM_LIBS) +@@ -1764,3 +1765,51 @@ AC_SUBST(PAM_LIBS) AC_SUBST(PAM_MAN) AC_SUBST(NON_PAM_MAN) ])dnl @@ -151,7 +151,7 @@ index f6184da3f..c17cb5eb5 100755 echo $lib_flags diff --git a/src/config/pre.in b/src/config/pre.in -index 3f267eb1f..d4714d29a 100644 +index ce87e21ca..917357df9 100644 --- a/src/config/pre.in +++ b/src/config/pre.in @@ -177,6 +177,7 @@ LD = $(PURE) @LD@ @@ -162,7 +162,7 @@ index 3f267eb1f..d4714d29a 100644 INSTALL=@INSTALL@ INSTALL_STRIP= -@@ -399,7 +400,7 @@ SUPPORT_LIB = -l$(SUPPORT_LIBNAME) +@@ -402,7 +403,7 @@ SUPPORT_LIB = -l$(SUPPORT_LIBNAME) # HESIOD_LIBS is -lhesiod... HESIOD_LIBS = @HESIOD_LIBS@ @@ -172,10 +172,10 @@ index 3f267eb1f..d4714d29a 100644 GSS_LIBS = $(GSS_KRB5_LIB) # needs fixing if ever used on macOS! diff --git a/src/configure.in b/src/configure.in -index 7288a71ec..2b6d5baa7 100644 +index 5d5f148ca..16e785017 100644 --- a/src/configure.in +++ b/src/configure.in -@@ -1308,6 +1308,8 @@ AC_PATH_PROG(GROFF, groff) +@@ -1350,6 +1350,8 @@ AC_PATH_PROG(GROFF, groff) KRB5_WITH_PAM @@ -185,7 +185,7 @@ index 7288a71ec..2b6d5baa7 100644 if test "${localedir+set}" != set; then localedir='$(datadir)/locale' diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index e1b1cb040..9378ae047 100644 +index 652242207..8f9329c59 100644 --- a/src/include/k5-int.h +++ b/src/include/k5-int.h @@ -128,6 +128,7 @@ typedef unsigned char u_char; @@ -235,7 +235,7 @@ index 000000000..dfaaa847c +#endif +#endif diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index c86e78274..e81bb0a6d 100644 +index c40a6cca8..3ff86d7ff 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin @@ -87,6 +87,12 @@ @@ -252,7 +252,7 @@ index c86e78274..e81bb0a6d 100644 #include diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c -index aca136f0b..22e926ae4 100644 +index c9574c6e1..8301a33d0 100644 --- a/src/kadmin/dbutil/dump.c +++ b/src/kadmin/dbutil/dump.c @@ -148,12 +148,21 @@ create_ofile(char *ofile, char **tmpname) @@ -277,20 +277,20 @@ index aca136f0b..22e926ae4 100644 if (fd == -1) goto error; -@@ -194,7 +203,7 @@ prep_ok_file(krb5_context context, char *file_name, int *fd) - return 0; +@@ -197,7 +206,7 @@ prep_ok_file(krb5_context context, char *file_name, int *fd_out) + goto cleanup; } -- *fd = open(file_ok, O_WRONLY | O_CREAT | O_TRUNC, 0600); -+ *fd = THREEPARAMOPEN(file_ok, O_WRONLY | O_CREAT | O_TRUNC, 0600); - if (*fd == -1) { +- fd = open(file_ok, O_WRONLY | O_CREAT | O_TRUNC, 0600); ++ fd = THREEPARAMOPEN(file_ok, O_WRONLY | O_CREAT | O_TRUNC, 0600); + if (fd == -1) { com_err(progname, errno, _("while creating 'ok' file, '%s'"), file_ok); - exit_status++; + goto cleanup; diff --git a/src/kdc/main.c b/src/kdc/main.c -index f2226da25..ccac3a759 100644 +index 408c723f5..663fd6303 100644 --- a/src/kdc/main.c +++ b/src/kdc/main.c -@@ -873,7 +873,7 @@ write_pid_file(const char *path) +@@ -858,7 +858,7 @@ write_pid_file(const char *path) FILE *file; unsigned long pid; @@ -299,11 +299,41 @@ index f2226da25..ccac3a759 100644 if (file == NULL) return errno; pid = (unsigned long) getpid(); +diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c +index 68323dd0f..4cc035dc6 100644 +--- a/src/kprop/kpropd.c ++++ b/src/kprop/kpropd.c +@@ -488,6 +488,9 @@ doit(int fd) + krb5_enctype etype; + int database_fd; + char host[INET6_ADDRSTRLEN + 1]; ++#ifdef USE_SELINUX ++ void *selabel; ++#endif + + signal_wrapper(SIGALRM, alarm_handler); + alarm(params.iprop_resync_timeout); +@@ -543,9 +546,15 @@ doit(int fd) + free(name); + exit(1); + } ++#ifdef USE_SELINUX ++ selabel = krb5int_push_fscreatecon_for(file); ++#endif + omask = umask(077); + lock_fd = open(temp_file_name, O_RDWR | O_CREAT, 0600); + (void)umask(omask); ++#ifdef USE_SELINUX ++ krb5int_pop_fscreatecon(selabel); ++#endif + retval = krb5_lock_file(kpropd_context, lock_fd, + KRB5_LOCKMODE_EXCLUSIVE | KRB5_LOCKMODE_DONTBLOCK); + if (retval) { diff --git a/src/lib/kadm5/logger.c b/src/lib/kadm5/logger.c -index ce79fabf7..c53a5743f 100644 +index c6885edf2..9aec3c05e 100644 --- a/src/lib/kadm5/logger.c +++ b/src/lib/kadm5/logger.c -@@ -414,7 +414,7 @@ krb5_klog_init(krb5_context kcontext, char *ename, char *whoami, krb5_boolean do +@@ -309,7 +309,7 @@ krb5_klog_init(krb5_context kcontext, char *ename, char *whoami, krb5_boolean do */ append = (cp[4] == ':') ? O_APPEND : 0; if (append || cp[4] == '=') { @@ -312,7 +342,7 @@ index ce79fabf7..c53a5743f 100644 S_IRUSR | S_IWUSR | S_IRGRP); if (fd != -1) f = fdopen(fd, append ? "a" : "w"); -@@ -918,7 +918,7 @@ krb5_klog_reopen(krb5_context kcontext) +@@ -776,7 +776,7 @@ krb5_klog_reopen(krb5_context kcontext) * In case the old logfile did not get moved out of the * way, open for append to prevent squashing the old logs. */ @@ -322,18 +352,18 @@ index ce79fabf7..c53a5743f 100644 set_cloexec_file(f); log_control.log_entries[lindex].lfu_filep = f; diff --git a/src/lib/kdb/kdb_log.c b/src/lib/kdb/kdb_log.c -index 766d3002a..6466417b7 100644 +index 2659a2501..e9b95fce5 100644 --- a/src/lib/kdb/kdb_log.c +++ b/src/lib/kdb/kdb_log.c -@@ -476,7 +476,7 @@ ulog_map(krb5_context context, const char *logname, uint32_t ulogentries) - int ulogfd = -1; +@@ -480,7 +480,7 @@ ulog_map(krb5_context context, const char *logname, uint32_t ulogentries) + return ENOMEM; if (stat(logname, &st) == -1) { -- ulogfd = open(logname, O_RDWR | O_CREAT, 0600); -+ ulogfd = THREEPARAMOPEN(logname, O_RDWR | O_CREAT, 0600); - if (ulogfd == -1) - return errno; - +- log_ctx->ulogfd = open(logname, O_RDWR | O_CREAT, 0600); ++ log_ctx->ulogfd = THREEPARAMOPEN(logname, O_RDWR | O_CREAT, 0600); + if (log_ctx->ulogfd == -1) { + retval = errno; + goto cleanup; diff --git a/src/lib/krb5/ccache/cc_dir.c b/src/lib/krb5/ccache/cc_dir.c index bba64e516..73f0fe62d 100644 --- a/src/lib/krb5/ccache/cc_dir.c @@ -385,7 +415,7 @@ index bba64e516..73f0fe62d 100644 _("Credential cache directory %s does not exist"), dirname); diff --git a/src/lib/krb5/keytab/kt_file.c b/src/lib/krb5/keytab/kt_file.c -index 091f2c43f..ecc97ee2f 100644 +index 89cb68680..21c80d419 100644 --- a/src/lib/krb5/keytab/kt_file.c +++ b/src/lib/krb5/keytab/kt_file.c @@ -1024,14 +1024,14 @@ krb5_ktfileint_open(krb5_context context, krb5_keytab id, int mode) @@ -406,10 +436,10 @@ index 091f2c43f..ecc97ee2f 100644 goto report_errno; writevno = 1; diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c -index e97ce5fe5..779f184cb 100644 +index 4fff8f38c..40a9e7b10 100644 --- a/src/lib/krb5/os/trace.c +++ b/src/lib/krb5/os/trace.c -@@ -398,7 +398,7 @@ krb5_set_trace_filename(krb5_context context, const char *filename) +@@ -458,7 +458,7 @@ krb5_set_trace_filename(krb5_context context, const char *filename) fd = malloc(sizeof(*fd)); if (fd == NULL) return ENOMEM; @@ -464,7 +494,7 @@ index 7db30a33b..2b9d01921 100644 * maybe someone took away write permission so we could only * get shared locks? diff --git a/src/plugins/kdb/db2/kdb_db2.c b/src/plugins/kdb/db2/kdb_db2.c -index d23587a59..e2825650b 100644 +index 5106a5c99..e481e8121 100644 --- a/src/plugins/kdb/db2/kdb_db2.c +++ b/src/plugins/kdb/db2/kdb_db2.c @@ -694,8 +694,8 @@ ctx_create_db(krb5_context context, krb5_db2_context *dbc) @@ -543,10 +573,10 @@ index d8b26e701..b0daa7c02 100644 if (fname != NULL && fcntl(rfd, F_SETFD, 1) == -1) { diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c -index 022156a5e..3d6994c67 100644 +index 1ed72afe9..ce038fc3d 100644 --- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c +++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c -@@ -203,7 +203,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv) +@@ -194,7 +194,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv) /* set password in the file */ old_mode = umask(0177); @@ -555,7 +585,7 @@ index 022156a5e..3d6994c67 100644 if (pfile == NULL) { com_err(me, errno, _("Failed to open file %s: %s"), file_name, strerror (errno)); -@@ -244,6 +244,9 @@ kdb5_ldap_stash_service_password(int argc, char **argv) +@@ -235,6 +235,9 @@ kdb5_ldap_stash_service_password(int argc, char **argv) * Delete the existing entry and add the new entry */ FILE *newfile; @@ -565,7 +595,7 @@ index 022156a5e..3d6994c67 100644 mode_t omask; -@@ -255,7 +258,13 @@ kdb5_ldap_stash_service_password(int argc, char **argv) +@@ -246,7 +249,13 @@ kdb5_ldap_stash_service_password(int argc, char **argv) } omask = umask(077); @@ -579,38 +609,8 @@ index 022156a5e..3d6994c67 100644 umask (omask); if (newfile == NULL) { com_err(me, errno, _("Error creating file %s"), tmp_file); -diff --git a/src/slave/kpropd.c b/src/slave/kpropd.c -index d621f108f..99676cc97 100644 ---- a/src/slave/kpropd.c -+++ b/src/slave/kpropd.c -@@ -488,6 +488,9 @@ doit(int fd) - krb5_enctype etype; - int database_fd; - char host[INET6_ADDRSTRLEN + 1]; -+#ifdef USE_SELINUX -+ void *selabel; -+#endif - - signal_wrapper(SIGALRM, alarm_handler); - alarm(params.iprop_resync_timeout); -@@ -543,9 +546,15 @@ doit(int fd) - free(name); - exit(1); - } -+#ifdef USE_SELINUX -+ selabel = krb5int_push_fscreatecon_for(file); -+#endif - omask = umask(077); - lock_fd = open(temp_file_name, O_RDWR | O_CREAT, 0600); - (void)umask(omask); -+#ifdef USE_SELINUX -+ krb5int_pop_fscreatecon(selabel); -+#endif - retval = krb5_lock_file(kpropd_context, lock_fd, - KRB5_LOCKMODE_EXCLUSIVE | KRB5_LOCKMODE_DONTBLOCK); - if (retval) { diff --git a/src/util/profile/prof_file.c b/src/util/profile/prof_file.c -index 907c119bb..0f5462aea 100644 +index 24e41fb80..0dcb6b543 100644 --- a/src/util/profile/prof_file.c +++ b/src/util/profile/prof_file.c @@ -33,6 +33,7 @@ @@ -621,7 +621,7 @@ index 907c119bb..0f5462aea 100644 struct global_shared_profile_data { /* This is the head of the global list of shared trees */ -@@ -423,7 +424,7 @@ static errcode_t write_data_to_file(prf_data_t data, const char *outfile, +@@ -391,7 +392,7 @@ static errcode_t write_data_to_file(prf_data_t data, const char *outfile, errno = 0; @@ -631,7 +631,7 @@ index 907c119bb..0f5462aea 100644 retval = errno; if (retval == 0) diff --git a/src/util/support/Makefile.in b/src/util/support/Makefile.in -index 0bf0b7a87..58ac2e333 100644 +index b1842daf9..82d08943c 100644 --- a/src/util/support/Makefile.in +++ b/src/util/support/Makefile.in @@ -69,6 +69,7 @@ IPC_SYMS= \ @@ -642,7 +642,7 @@ index 0bf0b7a87..58ac2e333 100644 init-addrinfo.o \ plugins.o \ errors.o \ -@@ -149,7 +150,7 @@ SRCS=\ +@@ -160,7 +161,7 @@ SRCS=\ SHLIB_EXPDEPS = # Add -lm if dumping thread stats, for sqrt. diff --git a/krb5-1.3.1-dns.patch b/krb5-1.3.1-dns.patch index 1af7c12..8b33141 100644 --- a/krb5-1.3.1-dns.patch +++ b/krb5-1.3.1-dns.patch @@ -1,4 +1,4 @@ -From 2338e73d8dced4f85d6b4f5a0f7df21033ac78c1 Mon Sep 17 00:00:00 2001 +From 3bca5a822eb3af61d345074d131bb4399a03412c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] krb5-1.3.1-dns.patch @@ -9,7 +9,7 @@ We want to be able to use --with-netlib and --enable-dns at the same time. 1 file changed, 1 insertion(+) diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 6257dba40..5eeaa2d8a 100644 +index a7afec09e..db18226ed 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 @@ -726,6 +726,7 @@ AC_HELP_STRING([--with-netlib=LIBS], use user defined resolver library), diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index 5b0f5bc..22278d4 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -1,4 +1,4 @@ -From 20bc1c9b1d37138d1a8538f9cef22108c8fabf4f Mon Sep 17 00:00:00 2001 +From 3ea3d661c77a3a096cf2a24e48a0610ff308e3bc Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] krb5-1.9-debuginfo.patch diff --git a/krb5.spec b/krb5.spec index 6eca6f7..7cbc883 100644 --- a/krb5.spec +++ b/krb5.spec @@ -9,16 +9,16 @@ %global configured_default_ccache_name KEYRING:persistent:%%{uid} # leave empty or set to e.g., -beta2 -%global prerelease %{nil} +%global prerelease -beta1 # Should be in form 5.0, 6.1, etc. %global kdbversion 7.0 Summary: The Kerberos network authentication system Name: krb5 -Version: 1.16.1 +Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 25%{?dist} +Release: 0.beta1.1%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -50,7 +50,7 @@ Source39: krb5-krb5kdc.conf Source100: noport.c Patch26: krb5-1.12.1-pam.patch -Patch27: krb5-1.15.1-selinux-label.patch +Patch27: krb5-1.17-beta1-selinux-label.patch Patch28: krb5-1.12-ksu-path.patch Patch29: krb5-1.12-ktany.patch Patch30: krb5-1.15-beta1-buildconf.patch @@ -60,56 +60,7 @@ Patch33: krb5-1.13-dirsrv-accountlock.patch Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch -Patch40: Fix-hex-conversion-of-PKINIT-certid-strings.patch -Patch41: Exit-with-status-0-from-kadmind.patch -Patch42: Include-etype-info-in-for-hardware-preauth-hints.patch -Patch43: Fix-securid_sam2-preauth-for-non-default-salt.patch -Patch44: Refactor-KDC-krb5_pa_data-utility-functions.patch -Patch45: Simplify-kdc_preauth.c-systems-table.patch -Patch46: Add-PKINIT-client-support-for-freshness-token.patch -Patch47: Add-PKINIT-KDC-support-for-freshness-token.patch -Patch49: Fix-read-overflow-in-KDC-sort_pa_data.patch -Patch50: Include-preauth-name-in-trace-output-if-possible.patch -Patch51: Report-extended-errors-in-kinit-k-t-KDB.patch -Patch52: Add-libkrb5support-hex-functions-and-tests.patch -Patch53: Use-libkrb5support-hex-functions-where-appropriate.patch -Patch54: Add-ASN.1-encoders-and-decoders-for-SPAKE-types.patch -Patch55: Add-k5_buf_add_vfmt-to-k5buf-interface.patch -Patch56: Add-vector-support-to-k5_sha256.patch -Patch57: Move-zap-definition-to-k5-platform.h.patch -Patch58: Implement-k5_buf_init_dynamic_zap.patch -Patch59: Use-k5_buf_init_dynamic_zap-where-appropriate.patch -Patch60: Add-SPAKE-preauth-support.patch -Patch61: Add-doc-index-entries-for-SPAKE-constants.patch -Patch62: Fix-SPAKE-memory-leak.patch -Patch64: Zap-data-when-freeing-krb5_spake_factor.patch -Patch65: Be-more-careful-asking-for-AS-key-in-SPAKE-client.patch -Patch68: Restrict-pre-authentication-fallback-cases.patch -Patch69: Remove-nodes-option-from-make-certs-scripts.patch -Patch70: Fix-segfault-in-finish_dispatch.patch -Patch71: Log-when-non-root-ksu-authorization-fails.patch -Patch72: Add-k5_dir_filenames-to-libkrb5support.patch -Patch73: Process-profile-includedir-in-sorted-order.patch -Patch74: Make-docs-build-python3-compatible.patch -Patch75: Add-flag-to-disable-encrypted-timestamp-on-client.patch -Patch76: Explicitly-look-for-python2-in-configure.in.patch -Patch77: Use-SHA-256-instead-of-MD5-for-audit-ticket-IDs.patch -Patch78: Add-k5test-mark-function.patch -Patch79: Convert-Python-tests-to-Python-3.patch -Patch80: Zap-copy-of-secret-in-RC4-string-to-key.patch -Patch81: Fix-some-broken-tests-for-Python-3.patch -Patch82: Eliminate-preprocessor-disabled-dead-code.patch -Patch83: Make-krb5kdc-p-affect-TCP-ports.patch -Patch84: Remove-outdated-note-in-krb5kdc-man-page.patch -Patch85: Fix-k5test-prompts-for-Python-3.patch Patch86: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch -Patch87: Prefer-TCP-to-UDP-for-password-changes.patch -Patch88: Correct-kpasswd_server-description-in-krb5.conf-5.patch -Patch89: Prevent-SIGPIPE-from-socket-writes-on-UNIX-likes.patch -Patch90: Use-port-sockets.h-macros-in-cc_kcm-sendto_kdc.patch -Patch91: Bring-back-general-kerberos-man-page.patch -Patch92: Modernize-kerberos-7.patch -Patch93: Update-man-pages-to-reference-kerberos-7.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -757,6 +708,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Nov 01 2018 Robbie Harwood - 1.17-0.beta2.1 +- New upstream beta release + * Wed Oct 24 2018 Robbie Harwood - 1.16.1-25 - Update man pages to reference kerberos(7) - Resolves: #1143767 diff --git a/sources b/sources index 771c76f..36da90e 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (krb5-1.16.1-pdfs.tar) = 89a5a709720ee9028e9bfbcbc808eec436c4b9c6e105888b37660e97cff48e190bc77affa9809353de9cf2f39e517e8a6ab22792263978b403a4a6317ac24a46 -SHA512 (krb5-1.16.1.tar.gz) = fa4ec14a4ffe690861e2dd7ea39d7698af2058ce181bb733ea891f80279f4dde4bb891adec5ccb0eaddf737306e6ceb1fe3744a2946e6189a7d7d2dd3bc5ba84 -SHA512 (krb5-1.16.1.tar.gz.asc) = 2d24fec31ca71ee93a1339ff4fa50a9397693deff2cc7097927617e04c2509fe7e671b58b982360cbdf80c0df066e03f289a2ecacdb270dc65d7abad1e6812de +SHA512 (krb5-1.17-beta1.tar.gz) = 4981894e771d5d7cf5eaac9be94e8fcb6b818bc7c03953e15e6187a2b9d5184f354ffe8213e2a9d695b270b8088d2912ba913927c86b6171442a14071458f6c6 +SHA512 (krb5-1.17-beta1.tar.gz.asc) = 81655664d0b6517500c14dc3af5ac741ae22c5029ea2502ad4816e856cf8637dc8394b69921d484d35513cff8b190b25e5f6a6640238ce597e087bf18bfb323d +SHA512 (krb5-1.17-beta1-pdfs.tar) = 1ddd97432c1210b9b62b67e7027636c2df23041f3a21e73e2de09e7bd741e20c3005e173c80f576272956e91fc01bd6f957bf9df41a24f50f7d1811021cc2a98 From d401b30b5f93340cc44dece225e5b296679e0878 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 8 Nov 2018 11:22:27 -0500 Subject: [PATCH 075/304] Fix spurious errors from kcmio_unix_socket_write Resolves: #1645912 --- ...-errors-from-kcmio_unix_socket_write.patch | 44 +++++++++++++++++++ krb5.spec | 7 ++- 2 files changed, 50 insertions(+), 1 deletion(-) create mode 100644 Fix-spurious-errors-from-kcmio_unix_socket_write.patch diff --git a/Fix-spurious-errors-from-kcmio_unix_socket_write.patch b/Fix-spurious-errors-from-kcmio_unix_socket_write.patch new file mode 100644 index 0000000..c98ea73 --- /dev/null +++ b/Fix-spurious-errors-from-kcmio_unix_socket_write.patch @@ -0,0 +1,44 @@ +From 9fb4942026ba77ae51a9fa3623c62a07328e3bd5 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 5 Nov 2018 13:49:52 -0500 +Subject: [PATCH] Fix spurious errors from kcmio_unix_socket_write + +Commit 33634a940166d0b21c3105bab8dcf5550fbbd678 accidentally changed +the return value from kcmio_unix_socket_write to be the result of the +write call. Most commonly this resulted in it returning 8, which led +to many commands failing with "Exec format error". + +ticket: 8758 (new) +tags: pullup +target_version: 1.17-next + +(cherry picked from commit 3e76ea104cdaf22c4537833b203f8aeed1691f18) +--- + src/lib/krb5/ccache/cc_kcm.c | 7 +++---- + 1 file changed, 3 insertions(+), 4 deletions(-) + +diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c +index 2b9f82e32..092ab7daf 100644 +--- a/src/lib/krb5/ccache/cc_kcm.c ++++ b/src/lib/krb5/ccache/cc_kcm.c +@@ -308,8 +308,9 @@ kcmio_unix_socket_write(krb5_context context, struct kcmio *io, void *request, + + for (;;) { + ret = krb5int_net_writev(context, io->fd, sg, 2); +- if (ret < 0) +- ret = errno; ++ if (ret >= 0) ++ return 0; ++ ret = errno; + if (ret != EPIPE || reconnected) + return ret; + +@@ -327,8 +328,6 @@ kcmio_unix_socket_write(krb5_context context, struct kcmio *io, void *request, + return ret; + reconnected = TRUE; + } +- +- return ret; + } + + /* Read a KCM reply: 4-byte big-endian length, 4-byte big-endian status code, diff --git a/krb5.spec b/krb5.spec index 7cbc883..d33b85a 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 0.beta1.1%{?dist} +Release: 1.beta1.1%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -61,6 +61,7 @@ Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch Patch86: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch +Patch87: Fix-spurious-errors-from-kcmio_unix_socket_write.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -708,6 +709,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Nov 08 2018 Robbie Harwood - 1.17-1 +- Fix spurious errors from kcmio_unix_socket_write +- Resolves: #1645912 + * Thu Nov 01 2018 Robbie Harwood - 1.17-0.beta2.1 - New upstream beta release From 83e3cdfc7d52d113e7a0f49e9c5d0e23f7ff3f1b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 12 Nov 2018 15:38:14 -0500 Subject: [PATCH 076/304] Gain FIPS awareness --- Become-FIPS-aware.patch | 135 ++++++++++++++++++ ...-errors-from-kcmio_unix_socket_write.patch | 2 +- ...-plaintext-fallback-for-RC4-usages-a.patch | 126 +++++++++------- krb5.spec | 12 +- 4 files changed, 220 insertions(+), 55 deletions(-) create mode 100644 Become-FIPS-aware.patch diff --git a/Become-FIPS-aware.patch b/Become-FIPS-aware.patch new file mode 100644 index 0000000..d5f7911 --- /dev/null +++ b/Become-FIPS-aware.patch @@ -0,0 +1,135 @@ +From d49cdc4f701d072b59d57d14bc9c19e9fba42396 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 9 Nov 2018 15:12:21 -0500 +Subject: [PATCH] Become FIPS-aware + +A lot of the FIPS error conditions from OpenSSL are incredibly +mysterious (at best, things return NULL unexpectedly; at worst, +internal assertions are tripped; most of the time, you just get +ENOMEM). In order to cope with this, we need to have some level of +awareness of what we can and can't safely call. + +This will slow down some calls slightly (FIPS_mode() takes multiple +locks), but not for any crypto we care about - AES is fine, for +instance. + +(cherry picked from commit ee05742839df659d2136b37f91d0a888de2b5e26) +(cherry picked from commit b38ed4d97152f1dce126235935d30e549ead77b3) +--- + src/lib/crypto/openssl/enc_provider/camellia.c | 6 ++++++ + src/lib/crypto/openssl/enc_provider/des.c | 9 +++++++++ + src/lib/crypto/openssl/enc_provider/rc4.c | 3 +++ + src/lib/crypto/openssl/hash_provider/hash_evp.c | 4 ++++ + src/lib/crypto/openssl/hmac.c | 6 +++++- + 5 files changed, 27 insertions(+), 1 deletion(-) + +diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c +index 2da691329..f79679a0b 100644 +--- a/src/lib/crypto/openssl/enc_provider/camellia.c ++++ b/src/lib/crypto/openssl/enc_provider/camellia.c +@@ -304,6 +304,9 @@ krb5int_camellia_cbc_mac(krb5_key key, const krb5_crypto_iov *data, + unsigned char blockY[CAMELLIA_BLOCK_SIZE], blockB[CAMELLIA_BLOCK_SIZE]; + struct iov_cursor cursor; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + if (output->length < CAMELLIA_BLOCK_SIZE) + return KRB5_BAD_MSIZE; + +@@ -331,6 +334,9 @@ static krb5_error_code + krb5int_camellia_init_state (const krb5_keyblock *key, krb5_keyusage usage, + krb5_data *state) + { ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + state->length = 16; + state->data = (void *) malloc(16); + if (state->data == NULL) +diff --git a/src/lib/crypto/openssl/enc_provider/des.c b/src/lib/crypto/openssl/enc_provider/des.c +index a662db512..7d17d287e 100644 +--- a/src/lib/crypto/openssl/enc_provider/des.c ++++ b/src/lib/crypto/openssl/enc_provider/des.c +@@ -85,6 +85,9 @@ k5_des_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx; + krb5_boolean empty; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + ret = validate(key, ivec, data, num_data, &empty); + if (ret != 0 || empty) + return ret; +@@ -133,6 +136,9 @@ k5_des_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx; + krb5_boolean empty; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + ret = validate(key, ivec, data, num_data, &empty); + if (ret != 0 || empty) + return ret; +@@ -182,6 +188,9 @@ k5_des_cbc_mac(krb5_key key, const krb5_crypto_iov *data, size_t num_data, + DES_key_schedule sched; + krb5_boolean empty; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + ret = validate(key, ivec, data, num_data, &empty); + if (ret != 0) + return ret; +diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c +index 7f3c086ed..ef8205535 100644 +--- a/src/lib/crypto/openssl/enc_provider/rc4.c ++++ b/src/lib/crypto/openssl/enc_provider/rc4.c +@@ -125,6 +125,9 @@ k5_arcfour_init_state(const krb5_keyblock *key, + { + struct arcfour_state *arcstate; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + /* Create a state structure with an uninitialized context. */ + arcstate = calloc(1, sizeof(*arcstate)); + if (arcstate == NULL) +diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c +index 957ed8d9c..8c1fd7f59 100644 +--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c ++++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c +@@ -64,12 +64,16 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, + static krb5_error_code + hash_md4(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) + { ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; + return hash_evp(EVP_md4(), data, num_data, output); + } + + static krb5_error_code + hash_md5(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) + { ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; + return hash_evp(EVP_md5(), data, num_data, output); + } + +diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c +index b2db6ec02..d94d9ac94 100644 +--- a/src/lib/crypto/openssl/hmac.c ++++ b/src/lib/crypto/openssl/hmac.c +@@ -103,7 +103,11 @@ map_digest(const struct krb5_hash_provider *hash) + return EVP_sha256(); + else if (!strncmp(hash->hash_name, "SHA-384",7)) + return EVP_sha384(); +- else if (!strncmp(hash->hash_name, "MD5", 3)) ++ ++ if (FIPS_mode()) ++ return NULL; ++ ++ if (!strncmp(hash->hash_name, "MD5", 3)) + return EVP_md5(); + else if (!strncmp(hash->hash_name, "MD4", 3)) + return EVP_md4(); diff --git a/Fix-spurious-errors-from-kcmio_unix_socket_write.patch b/Fix-spurious-errors-from-kcmio_unix_socket_write.patch index c98ea73..876f5ac 100644 --- a/Fix-spurious-errors-from-kcmio_unix_socket_write.patch +++ b/Fix-spurious-errors-from-kcmio_unix_socket_write.patch @@ -1,4 +1,4 @@ -From 9fb4942026ba77ae51a9fa3623c62a07328e3bd5 Mon Sep 17 00:00:00 2001 +From 5d925544465008f1695b3595531443aa78613365 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 5 Nov 2018 13:49:52 -0500 Subject: [PATCH] Fix spurious errors from kcmio_unix_socket_write diff --git a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch b/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch index 2e5969f..37de314 100644 --- a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch +++ b/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch @@ -1,23 +1,32 @@ -From 9bb35cc29293de37ef92bf151a601884e602eb39 Mon Sep 17 00:00:00 2001 +From 461739cdd608724020362bf0de07f76844bbfe10 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 31 Jul 2018 13:47:26 -0400 Subject: [PATCH] In FIPS mode, add plaintext fallback for RC4 usages and taint +(cherry picked from commit a327e3bf5b992ac829c7b2d3317fb7d93b1c88ef) --- - src/lib/krad/attr.c | 38 ++++++++++++++++++++++++++++---------- + src/lib/krad/attr.c | 45 +++++++++++++++++++++++++++++----------- src/lib/krad/attrset.c | 5 +++-- - src/lib/krad/internal.h | 13 +++++++++++-- - src/lib/krad/packet.c | 18 +++++++++--------- - src/lib/krad/remote.c | 10 ++++++++-- + src/lib/krad/internal.h | 13 ++++++++++-- + src/lib/krad/packet.c | 22 +++++++++++--------- + src/lib/krad/remote.c | 10 +++++++-- src/lib/krad/t_attr.c | 3 ++- src/lib/krad/t_attrset.c | 4 +++- - 7 files changed, 64 insertions(+), 27 deletions(-) + 7 files changed, 72 insertions(+), 30 deletions(-) diff --git a/src/lib/krad/attr.c b/src/lib/krad/attr.c -index 9c13d9d75..3a2d0243b 100644 +index 9c13d9d75..275327e67 100644 --- a/src/lib/krad/attr.c +++ b/src/lib/krad/attr.c -@@ -38,7 +38,8 @@ +@@ -30,6 +30,7 @@ + #include + #include "internal.h" + ++#include + #include + + /* RFC 2865 */ +@@ -38,7 +39,8 @@ typedef krb5_error_code (*attribute_transform_fn)(krb5_context ctx, const char *secret, const unsigned char *auth, const krb5_data *in, @@ -27,7 +36,7 @@ index 9c13d9d75..3a2d0243b 100644 typedef struct { const char *name; -@@ -51,12 +52,14 @@ typedef struct { +@@ -51,12 +53,14 @@ typedef struct { static krb5_error_code user_password_encode(krb5_context ctx, const char *secret, const unsigned char *auth, const krb5_data *in, @@ -44,7 +53,7 @@ index 9c13d9d75..3a2d0243b 100644 static const attribute_record attributes[UCHAR_MAX] = { {"User-Name", 1, MAX_ATTRSIZE, NULL, NULL}, -@@ -128,7 +131,8 @@ static const attribute_record attributes[UCHAR_MAX] = { +@@ -128,7 +132,8 @@ static const attribute_record attributes[UCHAR_MAX] = { static krb5_error_code user_password_encode(krb5_context ctx, const char *secret, const unsigned char *auth, const krb5_data *in, @@ -54,21 +63,24 @@ index 9c13d9d75..3a2d0243b 100644 { const unsigned char *indx; krb5_error_code retval; -@@ -156,7 +160,12 @@ user_password_encode(krb5_context ctx, const char *secret, +@@ -154,8 +159,14 @@ user_password_encode(krb5_context ctx, const char *secret, + for (blck = 0, indx = auth; blck * BLOCKSIZE < len; blck++) { + memcpy(tmp.data + seclen, indx, BLOCKSIZE); - retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &tmp, - &sum); -- if (retval != 0) { -+ if (retval == ENOMEM) { -+ /* I'm Linux, so we know this is a FIPS failure. Taint so we -+ * don't send it later. */ +- retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &tmp, +- &sum); ++ if (FIPS_mode()) { ++ /* Skip encryption here. Taint so that we won't pass it out of ++ * the machine by accident. */ + *is_fips = TRUE; + sum.contents = calloc(1, BLOCKSIZE); -+ } else if (retval != 0) { ++ } else ++ retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &tmp, ++ &sum); + if (retval != 0) { zap(tmp.data, tmp.length); zap(outbuf, len); - krb5_free_data_contents(ctx, &tmp); -@@ -180,7 +189,8 @@ user_password_encode(krb5_context ctx, const char *secret, +@@ -180,7 +191,8 @@ user_password_encode(krb5_context ctx, const char *secret, static krb5_error_code user_password_decode(krb5_context ctx, const char *secret, const unsigned char *auth, const krb5_data *in, @@ -78,21 +90,24 @@ index 9c13d9d75..3a2d0243b 100644 { const unsigned char *indx; krb5_error_code retval; -@@ -206,7 +216,12 @@ user_password_decode(krb5_context ctx, const char *secret, +@@ -204,8 +216,14 @@ user_password_decode(krb5_context ctx, const char *secret, + for (blck = 0, indx = auth; blck * BLOCKSIZE < in->length; blck++) { + memcpy(tmp.data + seclen, indx, BLOCKSIZE); - retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, - &tmp, &sum); -- if (retval != 0) { -+ if (retval == ENOMEM) { -+ /* I'm Linux, so we know this is a FIPS failure. Assume the -+ * other side is running locally and move on. */ +- retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, +- &tmp, &sum); ++ if (FIPS_mode()) { ++ /* Skip encryption here. Taint so that we won't pass it out of ++ * the machine by accident. */ + *is_fips = TRUE; + sum.contents = calloc(1, BLOCKSIZE); -+ } else if (retval != 0) { ++ } else ++ retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, ++ &tmp, &sum); + if (retval != 0) { zap(tmp.data, tmp.length); zap(outbuf, in->length); - krb5_free_data_contents(ctx, &tmp); -@@ -248,7 +263,7 @@ krb5_error_code +@@ -248,7 +266,7 @@ krb5_error_code kr_attr_encode(krb5_context ctx, const char *secret, const unsigned char *auth, krad_attr type, const krb5_data *in, unsigned char outbuf[MAX_ATTRSIZE], @@ -101,7 +116,7 @@ index 9c13d9d75..3a2d0243b 100644 { krb5_error_code retval; -@@ -265,7 +280,8 @@ kr_attr_encode(krb5_context ctx, const char *secret, +@@ -265,7 +283,8 @@ kr_attr_encode(krb5_context ctx, const char *secret, return 0; } @@ -111,7 +126,7 @@ index 9c13d9d75..3a2d0243b 100644 } krb5_error_code -@@ -274,6 +290,7 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, +@@ -274,6 +293,7 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen) { krb5_error_code retval; @@ -119,7 +134,7 @@ index 9c13d9d75..3a2d0243b 100644 retval = kr_attr_valid(type, in); if (retval != 0) -@@ -288,7 +305,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, +@@ -288,7 +308,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, return 0; } @@ -191,10 +206,18 @@ index 996a89372..a53ce31ce 100644 /* Decode attributes from a buffer. */ krb5_error_code diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c -index c597174b6..2fbf0ee1e 100644 +index c597174b6..794ac84c4 100644 --- a/src/lib/krad/packet.c +++ b/src/lib/krad/packet.c -@@ -53,12 +53,6 @@ typedef unsigned char uchar; +@@ -32,6 +32,7 @@ + #include + + #include ++#include + + typedef unsigned char uchar; + +@@ -53,12 +54,6 @@ typedef unsigned char uchar; #define pkt_auth(p) ((uchar *)offset(&(p)->pkt, OFFSET_AUTH)) #define pkt_attr(p) ((unsigned char *)offset(&(p)->pkt, OFFSET_ATTR)) @@ -207,20 +230,23 @@ index c597174b6..2fbf0ee1e 100644 typedef struct { uchar x[(UCHAR_MAX + 1) / 8]; } idmap; -@@ -190,7 +184,11 @@ auth_generate_response(krb5_context ctx, const char *secret, - retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &data, - &hash); - free(data.data); -- if (retval != 0) -+ if (retval == ENOMEM) { -+ /* We're on Linux, so this is a FIPS failure, and this checksum -+ * does very little security-wise anyway, so don't taint. */ -+ hash.contents = calloc(1, AUTH_FIELD_SIZE); -+ } else if (retval != 0) - return retval; +@@ -187,8 +182,13 @@ auth_generate_response(krb5_context ctx, const char *secret, + memcpy(data.data + response->pkt.length, secret, strlen(secret)); - memcpy(rauth, hash.contents, AUTH_FIELD_SIZE); -@@ -276,7 +274,7 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code, + /* Hash it. */ +- retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &data, +- &hash); ++ if (FIPS_mode()) { ++ /* This checksum does very little security-wise anyway, so don't ++ * taint. */ ++ hash.contents = calloc(1, AUTH_FIELD_SIZE); ++ } else ++ retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &data, ++ &hash); + free(data.data); + if (retval != 0) + return retval; +@@ -276,7 +276,7 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code, /* Encode the attributes. */ retval = kr_attrset_encode(set, secret, pkt_auth(pkt), pkt_attr(pkt), @@ -229,7 +255,7 @@ index c597174b6..2fbf0ee1e 100644 if (retval != 0) goto error; -@@ -314,7 +312,7 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code, +@@ -314,7 +314,7 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code, /* Encode the attributes. */ retval = kr_attrset_encode(set, secret, pkt_auth(request), pkt_attr(pkt), @@ -238,7 +264,7 @@ index c597174b6..2fbf0ee1e 100644 if (retval != 0) goto error; -@@ -451,6 +449,8 @@ krad_packet_decode_response(krb5_context ctx, const char *secret, +@@ -451,6 +451,8 @@ krad_packet_decode_response(krb5_context ctx, const char *secret, const krb5_data * krad_packet_encode(const krad_packet *pkt) { diff --git a/krb5.spec b/krb5.spec index d33b85a..27df122 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1.beta1.1%{?dist} +Release: 1.beta1.2%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -60,8 +60,9 @@ Patch33: krb5-1.13-dirsrv-accountlock.patch Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch -Patch86: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch Patch87: Fix-spurious-errors-from-kcmio_unix_socket_write.patch +Patch88: Become-FIPS-aware.patch +Patch89: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -709,11 +710,14 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog -* Thu Nov 08 2018 Robbie Harwood - 1.17-1 +* Mon Nov 12 2018 Robbie Harwood - 1.17-1.beta1.2 +- Gain FIPS awareness + +* Thu Nov 08 2018 Robbie Harwood - 1.17-1.beta1.1 - Fix spurious errors from kcmio_unix_socket_write - Resolves: #1645912 -* Thu Nov 01 2018 Robbie Harwood - 1.17-0.beta2.1 +* Thu Nov 01 2018 Robbie Harwood - 1.17-0.beta1.1 - New upstream beta release * Wed Oct 24 2018 Robbie Harwood - 1.16.1-25 From fef40744ec834ea8719f28e75876c0ff0585a8ff Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 29 Nov 2018 14:58:18 -0500 Subject: [PATCH 077/304] Add tests for KCM ccache type --- Add-tests-for-KCM-ccache-type.patch | 294 ++++++++++++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 299 insertions(+), 1 deletion(-) create mode 100644 Add-tests-for-KCM-ccache-type.patch diff --git a/Add-tests-for-KCM-ccache-type.patch b/Add-tests-for-KCM-ccache-type.patch new file mode 100644 index 0000000..e51fc20 --- /dev/null +++ b/Add-tests-for-KCM-ccache-type.patch @@ -0,0 +1,294 @@ +From 38fb1102b18d6720d4c0aa4db879d05dfce87618 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 22 Nov 2018 00:27:35 -0500 +Subject: [PATCH] Add tests for KCM ccache type + +Using a trivial Python implementation of a KCM server, run the +t_ccache.py tests against the KCM ccache type. + +(cherry picked from commit f0bcb86131e385b2603ccf0f3c7d65aa3891b220) +--- + src/tests/kcmserver.py | 246 +++++++++++++++++++++++++++++++++++++++++ + src/tests/t_ccache.py | 9 +- + 2 files changed, 254 insertions(+), 1 deletion(-) + create mode 100644 src/tests/kcmserver.py + +diff --git a/src/tests/kcmserver.py b/src/tests/kcmserver.py +new file mode 100644 +index 000000000..57432e5a7 +--- /dev/null ++++ b/src/tests/kcmserver.py +@@ -0,0 +1,246 @@ ++# This is a simple KCM test server, used to exercise the KCM ccache ++# client code. It will generally throw an uncaught exception if the ++# client sends anything unexpected, so is unsuitable for production. ++# (It also imposes no namespace or access constraints, and blocks ++# while reading requests and writing responses.) ++ ++# This code knows nothing about how to marshal and unmarshal principal ++# names and credentials as is required in the KCM protocol; instead, ++# it just remembers the marshalled forms and replays them to the ++# client when asked. This works because marshalled creds and ++# principal names are always the last part of marshalled request ++# arguments, and because we don't need to implement remove_cred (which ++# would need to know how to match a cred tag against previously stored ++# credentials). ++ ++# The following code is useful for debugging if anything appears to be ++# going wrong in the server, since daemon output is generally not ++# visible in Python test scripts. ++# ++# import sys, traceback ++# def ehook(etype, value, tb): ++# with open('/tmp/exception', 'w') as f: ++# traceback.print_exception(etype, value, tb, file=f) ++# sys.excepthook = ehook ++ ++import select ++import socket ++import struct ++import sys ++ ++caches = {} ++cache_uuidmap = {} ++defname = b'default' ++next_unique = 1 ++next_uuid = 1 ++ ++class KCMOpcodes(object): ++ GEN_NEW = 3 ++ INITIALIZE = 4 ++ DESTROY = 5 ++ STORE = 6 ++ GET_PRINCIPAL = 8 ++ GET_CRED_UUID_LIST = 9 ++ GET_CRED_BY_UUID = 10 ++ REMOVE_CRED = 11 ++ GET_CACHE_UUID_LIST = 18 ++ GET_CACHE_BY_UUID = 19 ++ GET_DEFAULT_CACHE = 20 ++ SET_DEFAULT_CACHE = 21 ++ GET_KDC_OFFSET = 22 ++ SET_KDC_OFFSET = 23 ++ ++ ++class KRB5Errors(object): ++ KRB5_CC_END = -1765328242 ++ KRB5_CC_NOSUPP = -1765328137 ++ KRB5_FCC_NOFILE = -1765328189 ++ ++ ++def make_uuid(): ++ global next_uuid ++ uuid = bytes(12) + struct.pack('>L', next_uuid) ++ next_uuid = next_uuid + 1 ++ return uuid ++ ++ ++class Cache(object): ++ def __init__(self, name): ++ self.name = name ++ self.princ = None ++ self.uuid = make_uuid() ++ self.cred_uuids = [] ++ self.creds = {} ++ self.time_offset = 0 ++ ++ ++def get_cache(name): ++ if name in caches: ++ return caches[name] ++ cache = Cache(name) ++ caches[name] = cache ++ cache_uuidmap[cache.uuid] = cache ++ return cache ++ ++ ++def unmarshal_name(argbytes): ++ offset = argbytes.find(b'\0') ++ return argbytes[0:offset], argbytes[offset+1:] ++ ++ ++def op_gen_new(argbytes): ++ # Does not actually check for uniqueness. ++ global next_unique ++ name = b'unique' + str(next_unique).encode('ascii') ++ next_unique += 1 ++ return 0, name + b'\0' ++ ++ ++def op_initialize(argbytes): ++ name, princ = unmarshal_name(argbytes) ++ cache = get_cache(name) ++ cache.princ = princ ++ cache.cred_uuids = [] ++ cache.creds = {} ++ cache.time_offset = 0 ++ return 0, b'' ++ ++ ++def op_destroy(argbytes): ++ name, rest = unmarshal_name(argbytes) ++ cache = get_cache(name) ++ del cache_uuidmap[cache.uuid] ++ del caches[name] ++ return 0, b'' ++ ++ ++def op_store(argbytes): ++ name, cred = unmarshal_name(argbytes) ++ cache = get_cache(name) ++ uuid = make_uuid() ++ cache.creds[uuid] = cred ++ cache.cred_uuids.append(uuid) ++ return 0, b'' ++ ++ ++def op_get_principal(argbytes): ++ name, rest = unmarshal_name(argbytes) ++ cache = get_cache(name) ++ if cache.princ is None: ++ return KRB5Errors.KRB5_FCC_NOFILE, b'' ++ return 0, cache.princ + b'\0' ++ ++ ++def op_get_cred_uuid_list(argbytes): ++ name, rest = unmarshal_name(argbytes) ++ cache = get_cache(name) ++ return 0, b''.join(cache.cred_uuids) ++ ++ ++def op_get_cred_by_uuid(argbytes): ++ name, uuid = unmarshal_name(argbytes) ++ cache = get_cache(name) ++ if uuid not in cache.creds: ++ return KRB5Errors.KRB5_CC_END, b'' ++ return 0, cache.creds[uuid] ++ ++ ++def op_remove_cred(argbytes): ++ return KRB5Errors.KRB5_CC_NOSUPP, b'' ++ ++ ++def op_get_cache_uuid_list(argbytes): ++ return 0, b''.join(cache_uuidmap.keys()) ++ ++ ++def op_get_cache_by_uuid(argbytes): ++ uuid = argbytes ++ if uuid not in cache_uuidmap: ++ return KRB5Errors.KRB5_CC_END, b'' ++ return 0, cache_uuidmap[uuid].name + b'\0' ++ ++ ++def op_get_default_cache(argbytes): ++ return 0, defname + b'\0' ++ ++ ++def op_set_default_cache(argbytes): ++ global defname ++ defname, rest = unmarshal_name(argbytes) ++ return 0, b'' ++ ++ ++def op_get_kdc_offset(argbytes): ++ name, rest = unmarshal_name(argbytes) ++ cache = get_cache(name) ++ return 0, struct.pack('>l', cache.time_offset) ++ ++ ++def op_set_kdc_offset(argbytes): ++ name, obytes = unmarshal_name(argbytes) ++ cache = get_cache(name) ++ cache.time_offset, = struct.unpack('>l', obytes) ++ return 0, b'' ++ ++ ++ophandlers = { ++ KCMOpcodes.GEN_NEW : op_gen_new, ++ KCMOpcodes.INITIALIZE : op_initialize, ++ KCMOpcodes.DESTROY : op_destroy, ++ KCMOpcodes.STORE : op_store, ++ KCMOpcodes.GET_PRINCIPAL : op_get_principal, ++ KCMOpcodes.GET_CRED_UUID_LIST : op_get_cred_uuid_list, ++ KCMOpcodes.GET_CRED_BY_UUID : op_get_cred_by_uuid, ++ KCMOpcodes.REMOVE_CRED : op_remove_cred, ++ KCMOpcodes.GET_CACHE_UUID_LIST : op_get_cache_uuid_list, ++ KCMOpcodes.GET_CACHE_BY_UUID : op_get_cache_by_uuid, ++ KCMOpcodes.GET_DEFAULT_CACHE : op_get_default_cache, ++ KCMOpcodes.SET_DEFAULT_CACHE : op_set_default_cache, ++ KCMOpcodes.GET_KDC_OFFSET : op_get_kdc_offset, ++ KCMOpcodes.SET_KDC_OFFSET : op_set_kdc_offset ++} ++ ++# Read and respond to a request from the socket s. ++def service_request(s): ++ lenbytes = b'' ++ while len(lenbytes) < 4: ++ lenbytes += s.recv(4 - len(lenbytes)) ++ if lenbytes == b'': ++ return False ++ ++ reqlen, = struct.unpack('>L', lenbytes) ++ req = b'' ++ while len(req) < reqlen: ++ req += s.recv(reqlen - len(req)) ++ ++ majver, minver, op = struct.unpack('>BBH', req[:4]) ++ argbytes = req[4:] ++ code, payload = ophandlers[op](argbytes) ++ ++ # The KCM response is the code (4 bytes) and the response payload. ++ # The Heimdal IPC response is the length of the KCM response (4 ++ # bytes), a status code which is essentially always 0 (4 bytes), ++ # and the KCM response. ++ kcm_response = struct.pack('>l', code) + payload ++ hipc_response = struct.pack('>LL', len(kcm_response), 0) + kcm_response ++ s.sendall(hipc_response) ++ return True ++ ++ ++server = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM) ++server.bind(sys.argv[1]) ++server.listen(5) ++select_input = [server,] ++sys.stderr.write('starting...\n') ++sys.stderr.flush() ++ ++while True: ++ iready, oready, xready = select.select(select_input, [], []) ++ for s in iready: ++ if s == server: ++ client, addr = server.accept() ++ select_input.append(client) ++ else: ++ if not service_request(s): ++ select_input.remove(s) ++ s.close() +diff --git a/src/tests/t_ccache.py b/src/tests/t_ccache.py +index fcf1a611e..66804afa5 100755 +--- a/src/tests/t_ccache.py ++++ b/src/tests/t_ccache.py +@@ -22,7 +22,10 @@ + + from k5test import * + +-realm = K5Realm(create_host=False) ++kcm_socket_path = os.path.join(os.getcwd(), 'testdir', 'kcm') ++conf = {'libdefaults': {'kcm_socket': kcm_socket_path, ++ 'kcm_mach_service': '-'}} ++realm = K5Realm(create_host=False, krb5_conf=conf) + + keyctl = which('keyctl') + out = realm.run([klist, '-c', 'KEYRING:process:abcd'], expected_code=1) +@@ -122,6 +125,10 @@ def collection_test(realm, ccname): + + + collection_test(realm, 'DIR:' + os.path.join(realm.testdir, 'cc')) ++kcmserver_path = os.path.join(srctop, 'tests', 'kcmserver.py') ++realm.start_server([sys.executable, kcmserver_path, kcm_socket_path], ++ 'starting...') ++collection_test(realm, 'KCM:') + if test_keyring: + def cleanup_keyring(anchor, name): + out = realm.run(['keyctl', 'list', anchor]) diff --git a/krb5.spec b/krb5.spec index 27df122..68791c3 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1.beta1.2%{?dist} +Release: 1.beta1.3%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -63,6 +63,7 @@ Patch36: krb5-1.11-kpasswdtest.patch Patch87: Fix-spurious-errors-from-kcmio_unix_socket_write.patch Patch88: Become-FIPS-aware.patch Patch89: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch +Patch90: Add-tests-for-KCM-ccache-type.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -710,6 +711,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Nov 29 2018 Robbie Harwood - 1.17-1.beta1.3 +- Add tests for KCM ccache type + * Mon Nov 12 2018 Robbie Harwood - 1.17-1.beta1.2 - Gain FIPS awareness From 59f64bf750ab4cda8df1fc90b75e6640c0e62f81 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 6 Dec 2018 12:59:15 -0500 Subject: [PATCH 078/304] New upstream release (1.17-beta2) Drop pdfs source file --- .gitignore | 2 + Add-tests-for-KCM-ccache-type.patch | 2 +- Become-FIPS-aware.patch | 2 +- ...-errors-from-kcmio_unix_socket_write.patch | 44 ------------------- ...-plaintext-fallback-for-RC4-usages-a.patch | 2 +- krb5-1.11-kpasswdtest.patch | 2 +- krb5-1.11-run_user_0.patch | 2 +- krb5-1.12-api.patch | 2 +- krb5-1.12-ksu-path.patch | 2 +- krb5-1.12-ktany.patch | 2 +- krb5-1.12.1-pam.patch | 2 +- krb5-1.13-dirsrv-accountlock.patch | 2 +- krb5-1.15-beta1-buildconf.patch | 2 +- krb5-1.17-beta1-selinux-label.patch | 2 +- krb5-1.3.1-dns.patch | 2 +- krb5-1.9-debuginfo.patch | 2 +- krb5.spec | 22 +++------- sources | 5 +-- 18 files changed, 25 insertions(+), 76 deletions(-) delete mode 100644 Fix-spurious-errors-from-kcmio_unix_socket_write.patch diff --git a/.gitignore b/.gitignore index 1eed1cf..98f42ec 100644 --- a/.gitignore +++ b/.gitignore @@ -169,3 +169,5 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.17-beta1.tar.gz /krb5-1.17-beta1.tar.gz.asc /krb5-1.17-beta1-pdfs.tar +/krb5-1.17-beta2.tar.gz +/krb5-1.17-beta2.tar.gz.asc diff --git a/Add-tests-for-KCM-ccache-type.patch b/Add-tests-for-KCM-ccache-type.patch index e51fc20..ef9b875 100644 --- a/Add-tests-for-KCM-ccache-type.patch +++ b/Add-tests-for-KCM-ccache-type.patch @@ -1,4 +1,4 @@ -From 38fb1102b18d6720d4c0aa4db879d05dfce87618 Mon Sep 17 00:00:00 2001 +From b361f6bbc2873bd54963076738dc3ae6224261a0 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Nov 2018 00:27:35 -0500 Subject: [PATCH] Add tests for KCM ccache type diff --git a/Become-FIPS-aware.patch b/Become-FIPS-aware.patch index d5f7911..20c211d 100644 --- a/Become-FIPS-aware.patch +++ b/Become-FIPS-aware.patch @@ -1,4 +1,4 @@ -From d49cdc4f701d072b59d57d14bc9c19e9fba42396 Mon Sep 17 00:00:00 2001 +From 6e1f7b50b36e0036838c91841c83360fdd567ec5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] Become FIPS-aware diff --git a/Fix-spurious-errors-from-kcmio_unix_socket_write.patch b/Fix-spurious-errors-from-kcmio_unix_socket_write.patch deleted file mode 100644 index 876f5ac..0000000 --- a/Fix-spurious-errors-from-kcmio_unix_socket_write.patch +++ /dev/null @@ -1,44 +0,0 @@ -From 5d925544465008f1695b3595531443aa78613365 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 5 Nov 2018 13:49:52 -0500 -Subject: [PATCH] Fix spurious errors from kcmio_unix_socket_write - -Commit 33634a940166d0b21c3105bab8dcf5550fbbd678 accidentally changed -the return value from kcmio_unix_socket_write to be the result of the -write call. Most commonly this resulted in it returning 8, which led -to many commands failing with "Exec format error". - -ticket: 8758 (new) -tags: pullup -target_version: 1.17-next - -(cherry picked from commit 3e76ea104cdaf22c4537833b203f8aeed1691f18) ---- - src/lib/krb5/ccache/cc_kcm.c | 7 +++---- - 1 file changed, 3 insertions(+), 4 deletions(-) - -diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c -index 2b9f82e32..092ab7daf 100644 ---- a/src/lib/krb5/ccache/cc_kcm.c -+++ b/src/lib/krb5/ccache/cc_kcm.c -@@ -308,8 +308,9 @@ kcmio_unix_socket_write(krb5_context context, struct kcmio *io, void *request, - - for (;;) { - ret = krb5int_net_writev(context, io->fd, sg, 2); -- if (ret < 0) -- ret = errno; -+ if (ret >= 0) -+ return 0; -+ ret = errno; - if (ret != EPIPE || reconnected) - return ret; - -@@ -327,8 +328,6 @@ kcmio_unix_socket_write(krb5_context context, struct kcmio *io, void *request, - return ret; - reconnected = TRUE; - } -- -- return ret; - } - - /* Read a KCM reply: 4-byte big-endian length, 4-byte big-endian status code, diff --git a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch b/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch index 37de314..78fb0d9 100644 --- a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch +++ b/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch @@ -1,4 +1,4 @@ -From 461739cdd608724020362bf0de07f76844bbfe10 Mon Sep 17 00:00:00 2001 +From 2bd85da058d2d73eb2818a8e64656fec9b21b3c3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 31 Jul 2018 13:47:26 -0400 Subject: [PATCH] In FIPS mode, add plaintext fallback for RC4 usages and taint diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch index 8cff1ca..c5dc157 100644 --- a/krb5-1.11-kpasswdtest.patch +++ b/krb5-1.11-kpasswdtest.patch @@ -1,4 +1,4 @@ -From 90dd728245603a47e84dd3ba783c9c0a81ffc1a7 Mon Sep 17 00:00:00 2001 +From 6e8f8054396459c1f53c838801b0a75d235fdabb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:52:01 -0400 Subject: [PATCH] krb5-1.11-kpasswdtest.patch diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch index bbe3b7c..d8dd892 100644 --- a/krb5-1.11-run_user_0.patch +++ b/krb5-1.11-run_user_0.patch @@ -1,4 +1,4 @@ -From f325467c9d2298fd17d0fb223a2aeff37fed6ce6 Mon Sep 17 00:00:00 2001 +From ac7370914ab1646ac79475399ff5e9ca4ec58737 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:57 -0400 Subject: [PATCH] krb5-1.11-run_user_0.patch diff --git a/krb5-1.12-api.patch b/krb5-1.12-api.patch index eccb1a1..1ec3e8c 100644 --- a/krb5-1.12-api.patch +++ b/krb5-1.12-api.patch @@ -1,4 +1,4 @@ -From 77ac260bdbd1fdd5fded4738b57bb05c5f1e7480 Mon Sep 17 00:00:00 2001 +From eaaca3b6e9eb279ba7c50af95f0c84068927da16 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:00 -0400 Subject: [PATCH] krb5-1.12-api.patch diff --git a/krb5-1.12-ksu-path.patch b/krb5-1.12-ksu-path.patch index 0ecb9d8..773b134 100644 --- a/krb5-1.12-ksu-path.patch +++ b/krb5-1.12-ksu-path.patch @@ -1,4 +1,4 @@ -From 5bd610ea4b4898b64e92e335327d9c5bc17c01fc Mon Sep 17 00:00:00 2001 +From b4804625f0b778ceaabdcc4fb448e7b5ba1523a5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:32:09 -0400 Subject: [PATCH] krb5-1.12-ksu-path.patch diff --git a/krb5-1.12-ktany.patch b/krb5-1.12-ktany.patch index d5d116f..b0691dc 100644 --- a/krb5-1.12-ktany.patch +++ b/krb5-1.12-ktany.patch @@ -1,4 +1,4 @@ -From 4950d6b9bff6fd4ede043946d20fffc0303af2ea Mon Sep 17 00:00:00 2001 +From 001a4204b41823b939ca7f6ff82cc55c084e69d9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:33:53 -0400 Subject: [PATCH] krb5-1.12-ktany.patch diff --git a/krb5-1.12.1-pam.patch b/krb5-1.12.1-pam.patch index 4696ea5..e89f2b0 100644 --- a/krb5-1.12.1-pam.patch +++ b/krb5-1.12.1-pam.patch @@ -1,4 +1,4 @@ -From 6d4f52b62dd2213704ac4361f9ef6c017ec78085 Mon Sep 17 00:00:00 2001 +From c734e307fb5cf75d2a54147ffe9b14b0c8a0558b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] krb5-1.12.1-pam.patch diff --git a/krb5-1.13-dirsrv-accountlock.patch b/krb5-1.13-dirsrv-accountlock.patch index 199630d..cfdd2d8 100644 --- a/krb5-1.13-dirsrv-accountlock.patch +++ b/krb5-1.13-dirsrv-accountlock.patch @@ -1,4 +1,4 @@ -From c6f1e5922c457e46566728b859c8cfd7dfcca873 Mon Sep 17 00:00:00 2001 +From 6ac22c213525b704183106053e7a49d7a18f3903 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:44 -0400 Subject: [PATCH] krb5-1.13-dirsrv-accountlock.patch diff --git a/krb5-1.15-beta1-buildconf.patch b/krb5-1.15-beta1-buildconf.patch index da392ac..9dcbd9a 100644 --- a/krb5-1.15-beta1-buildconf.patch +++ b/krb5-1.15-beta1-buildconf.patch @@ -1,4 +1,4 @@ -From 15a15da6b29fd16faee37560a0d099164fc927a1 Mon Sep 17 00:00:00 2001 +From ee22f82b9a68f39a7c02b8eb75981c978d0f6e8c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] krb5-1.15-beta1-buildconf.patch diff --git a/krb5-1.17-beta1-selinux-label.patch b/krb5-1.17-beta1-selinux-label.patch index 8e67789..4895fec 100644 --- a/krb5-1.17-beta1-selinux-label.patch +++ b/krb5-1.17-beta1-selinux-label.patch @@ -1,4 +1,4 @@ -From f1ccca4209dea8da5135a3b4c34f925ef9e08824 Mon Sep 17 00:00:00 2001 +From 08e57eb589daa83dcbada0d1f81d5fb8dbe31fc4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] krb5-1.17-beta1-selinux-label.patch diff --git a/krb5-1.3.1-dns.patch b/krb5-1.3.1-dns.patch index 8b33141..a03312f 100644 --- a/krb5-1.3.1-dns.patch +++ b/krb5-1.3.1-dns.patch @@ -1,4 +1,4 @@ -From 3bca5a822eb3af61d345074d131bb4399a03412c Mon Sep 17 00:00:00 2001 +From fdfee89c7e849d8aa9d69fb453d87d1dcf750b84 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] krb5-1.3.1-dns.patch diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index 22278d4..7594a6c 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -1,4 +1,4 @@ -From 3ea3d661c77a3a096cf2a24e48a0610ff308e3bc Mon Sep 17 00:00:00 2001 +From a766fdb8929635483ae7b8f7ff13ad105571f8c1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] krb5-1.9-debuginfo.patch diff --git a/krb5.spec b/krb5.spec index 68791c3..33bdcea 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,18 +18,12 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1.beta1.3%{?dist} +Release: 1.beta2.1%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz # rharwood has trust path to signing key and verifies on check-in Source1: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz.asc -# This source is generated during the build because it is documentation. -# To override this behavior (e.g., new upstream version), do: -# tar cfT krb5-1.15.2-pdfs.tar /dev/null -# or the like. This logic persists due to how slow the stranger Fedora -# architecture builders are. 5 minutes on my laptop, 45 on koji easy. -Source3: krb5-%{version}%{prerelease}-pdfs.tar # Numbering is a relic of old init systems etc. It's easiest to just leave. Source2: kprop.service @@ -60,7 +54,6 @@ Patch33: krb5-1.13-dirsrv-accountlock.patch Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch -Patch87: Fix-spurious-errors-from-kcmio_unix_socket_write.patch Patch88: Become-FIPS-aware.patch Patch89: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch Patch90: Add-tests-for-KCM-ccache-type.patch @@ -248,7 +241,7 @@ contains only the libkadm5clnt and libkadm5serv shared objects. This interface is not considered stable. %prep -%autosetup -S git -n %{name}-%{version}%{prerelease} -a 3 +%autosetup -S git -n %{name}-%{version}%{prerelease} ln NOTICE LICENSE # Take the execute bit off of documentation. @@ -349,12 +342,7 @@ sphinx-build -a -b man -t pathsubs doc build-man sphinx-build -a -b html -t pathsubs doc build-html rm -fr build-html/_sources sphinx-build -a -b latex -t pathsubs doc build-pdf -# Build the PDFs if we didn't have pre-built ones. -for pdf in admin appdev basic build plugindev user ; do - test -s build-pdf/$pdf.pdf || make -C build-pdf -done -# new krb5-%{version}-pdf -tar -cf "krb5-%{version}%{prerelease}-pdfs.tar.new" build-pdf/*.pdf +make -C build-pdf # We need to cut off any access to locally-running nameservers, too. %{__cc} -fPIC -shared -o noport.so -Wall -Wextra $RPM_SOURCE_DIR/noport.c @@ -711,6 +699,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Dec 06 2018 Robbie Harwood - 1.17-1.beta2.1 +- New upstream release (1.17-beta2) +- Drop pdfs source file + * Thu Nov 29 2018 Robbie Harwood - 1.17-1.beta1.3 - Add tests for KCM ccache type diff --git a/sources b/sources index 36da90e..4bc45cb 100644 --- a/sources +++ b/sources @@ -1,3 +1,2 @@ -SHA512 (krb5-1.17-beta1.tar.gz) = 4981894e771d5d7cf5eaac9be94e8fcb6b818bc7c03953e15e6187a2b9d5184f354ffe8213e2a9d695b270b8088d2912ba913927c86b6171442a14071458f6c6 -SHA512 (krb5-1.17-beta1.tar.gz.asc) = 81655664d0b6517500c14dc3af5ac741ae22c5029ea2502ad4816e856cf8637dc8394b69921d484d35513cff8b190b25e5f6a6640238ce597e087bf18bfb323d -SHA512 (krb5-1.17-beta1-pdfs.tar) = 1ddd97432c1210b9b62b67e7027636c2df23041f3a21e73e2de09e7bd741e20c3005e173c80f576272956e91fc01bd6f957bf9df41a24f50f7d1811021cc2a98 +SHA512 (krb5-1.17-beta2.tar.gz) = 4611e2091c74e6de7fe5a3e57c44c4afcc2ebd590dcc1fe99f73fac95aec64574b06bb636acb4cd694e49db76ccdee5448202ab4c653c4330b40b9e42cc1d206 +SHA512 (krb5-1.17-beta2.tar.gz.asc) = cfb826cd69701071411270b75ed8241487e2aef032ae407f866e63c7871dbb23103b02fec73ab8ee4ae085b03216c91e688ad0b77e068054e4b1d3a625fcfc8b From 56c48beaec87d0736af945a7d139bd5aa22508d4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 6 Dec 2018 18:35:50 +0000 Subject: [PATCH 079/304] Forgot to bump prerelease... --- krb5.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 33bdcea..6ec906b 100644 --- a/krb5.spec +++ b/krb5.spec @@ -9,7 +9,7 @@ %global configured_default_ccache_name KEYRING:persistent:%%{uid} # leave empty or set to e.g., -beta2 -%global prerelease -beta1 +%global prerelease -beta2 # Should be in form 5.0, 6.1, etc. %global kdbversion 7.0 From 8968aa45c74d9127d2d3f4d60f68d48f3ab2e040 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 17 Dec 2018 20:39:53 +0000 Subject: [PATCH 080/304] Restore pdfs source file Resolves: #1659716 --- .gitignore | 1 + krb5.spec | 21 ++++++++++++++++++--- sources | 1 + 3 files changed, 20 insertions(+), 3 deletions(-) diff --git a/.gitignore b/.gitignore index 98f42ec..7d8ad15 100644 --- a/.gitignore +++ b/.gitignore @@ -171,3 +171,4 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.17-beta1-pdfs.tar /krb5-1.17-beta2.tar.gz /krb5-1.17-beta2.tar.gz.asc +/krb5-1.17-beta2-pdfs.tar diff --git a/krb5.spec b/krb5.spec index 6ec906b..84d1a83 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,12 +18,18 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1.beta2.1%{?dist} +Release: 1.beta2.2%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz # rharwood has trust path to signing key and verifies on check-in Source1: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz.asc +# This source is generated during the build because sphinx doesn't +# give me architecture-deterministic documentation builds. +# To override this behavior (e.g., new upstream version), do: +# tar cfT krb5-1.15.2-pdfs.tar /dev/null +# or the like. +Source3: krb5-%{version}%{prerelease}-pdfs.tar # Numbering is a relic of old init systems etc. It's easiest to just leave. Source2: kprop.service @@ -241,7 +247,7 @@ contains only the libkadm5clnt and libkadm5serv shared objects. This interface is not considered stable. %prep -%autosetup -S git -n %{name}-%{version}%{prerelease} +%autosetup -S git -n %{name}-%{version}%{prerelease} -a 3 ln NOTICE LICENSE # Take the execute bit off of documentation. @@ -342,7 +348,12 @@ sphinx-build -a -b man -t pathsubs doc build-man sphinx-build -a -b html -t pathsubs doc build-html rm -fr build-html/_sources sphinx-build -a -b latex -t pathsubs doc build-pdf -make -C build-pdf +# Build the PDFs if we don't have pre-built ones +for pdf in admin appdev basic build plugindev user ; do + test -s build-pdf/$pdf.pdf || make -C build-pdf +done +# new krb5-%{version}-pdf +tar -cf "krb5-%{version}%{prerelease}-pdfs.tar.new" build-pdf/*.pdf # We need to cut off any access to locally-running nameservers, too. %{__cc} -fPIC -shared -o noport.so -Wall -Wextra $RPM_SOURCE_DIR/noport.c @@ -699,6 +710,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Dec 17 2018 Robbie Harwood - 1.17-1.beta2.2 +- Restore pdfs source file +- Resolves: #1659716 + * Thu Dec 06 2018 Robbie Harwood - 1.17-1.beta2.1 - New upstream release (1.17-beta2) - Drop pdfs source file diff --git a/sources b/sources index 4bc45cb..5a03b5d 100644 --- a/sources +++ b/sources @@ -1,2 +1,3 @@ SHA512 (krb5-1.17-beta2.tar.gz) = 4611e2091c74e6de7fe5a3e57c44c4afcc2ebd590dcc1fe99f73fac95aec64574b06bb636acb4cd694e49db76ccdee5448202ab4c653c4330b40b9e42cc1d206 SHA512 (krb5-1.17-beta2.tar.gz.asc) = cfb826cd69701071411270b75ed8241487e2aef032ae407f866e63c7871dbb23103b02fec73ab8ee4ae085b03216c91e688ad0b77e068054e4b1d3a625fcfc8b +SHA512 (krb5-1.17-beta2-pdfs.tar) = 24140822150a32ed3efa855741da7c220c8cf5875b4517fa48591d4c90454653d70558e2a31461a2c32d21b801eac7c96c0a75a5cd6989dbabe6454a802002dd From 6c692d18f2b3ed89b7858f94781fed8950e4c6a9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 20 Dec 2018 21:46:31 +0000 Subject: [PATCH 081/304] Fix syntax on pkinit_anchors field in default krb5.conf --- krb5.conf | 2 +- krb5.spec | 5 ++++- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/krb5.conf b/krb5.conf index 99b8859..c45f388 100644 --- a/krb5.conf +++ b/krb5.conf @@ -13,7 +13,7 @@ includedir /etc/krb5.conf.d/ renew_lifetime = 7d forwardable = true rdns = false - pkinit_anchors = /etc/pki/tls/certs/ca-bundle.crt + pkinit_anchors = FILE:/etc/pki/tls/certs/ca-bundle.crt spake_preauth_groups = edwards25519 # default_realm = EXAMPLE.COM diff --git a/krb5.spec b/krb5.spec index 84d1a83..3cb7961 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1.beta2.2%{?dist} +Release: 1.beta2.3%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -710,6 +710,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Dec 20 2018 Robbie Harwood - 1.17-1.beta2.3 +- Fix syntax on pkinit_anchors field in default krb5.conf + * Mon Dec 17 2018 Robbie Harwood - 1.17-1.beta2.2 - Restore pdfs source file - Resolves: #1659716 From 7338b669da992c679d0bd69c3e2817113dfbfcac Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 20 Dec 2018 18:00:42 -0500 Subject: [PATCH 082/304] Remove incorrect KDC assertion --- Remove-incorrect-KDC-assertion.patch | 61 ++++++++++++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 66 insertions(+), 1 deletion(-) create mode 100644 Remove-incorrect-KDC-assertion.patch diff --git a/Remove-incorrect-KDC-assertion.patch b/Remove-incorrect-KDC-assertion.patch new file mode 100644 index 0000000..f951269 --- /dev/null +++ b/Remove-incorrect-KDC-assertion.patch @@ -0,0 +1,61 @@ +From 5ab44ff3ecdf362a792f193cf18df42866b70f80 Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Sat, 15 Dec 2018 11:56:36 +0200 +Subject: [PATCH] Remove incorrect KDC assertion + +The assertion in return_enc_padata() is reachable because +kdc_make_s4u2self_rep() may have previously added encrypted padata. +It is no longer necessary because the code uses add_pa_data_element() +instead of allocating a new list. + +CVE-2018-20217: + +In MIT krb5 1.8 or later, an authenticated user who can obtain a TGT +using an older encryption type (DES, DES3, or RC4) can cause an +assertion failure in the KDC by sending an S4U2Self request. + +[ghudson@mit.edu: rewrote commit message with CVE description] + +ticket: 8767 (new) +tags: pullup +target_version: 1.17 +target_version: 1.16-next +target_version: 1.15-next + +(cherry picked from commit 94e5eda5bb94d1d44733a49c3d9b6d1e42c74def) +--- + src/kdc/kdc_preauth.c | 1 - + src/tests/gssapi/t_s4u.py | 8 ++++++++ + 2 files changed, 8 insertions(+), 1 deletion(-) + +diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c +index 74953c99f..caf133c14 100644 +--- a/src/kdc/kdc_preauth.c ++++ b/src/kdc/kdc_preauth.c +@@ -1683,7 +1683,6 @@ return_enc_padata(krb5_context context, krb5_data *req_pkt, + krb5_error_code code = 0; + /* This should be initialized and only used for Win2K compat and other + * specific standardized uses such as FAST negotiation. */ +- assert(reply_encpart->enc_padata == NULL); + if (is_referral) { + code = return_referral_enc_padata(context, reply_encpart, server); + if (code) +diff --git a/src/tests/gssapi/t_s4u.py b/src/tests/gssapi/t_s4u.py +index fd29e1a27..f02c2fd13 100755 +--- a/src/tests/gssapi/t_s4u.py ++++ b/src/tests/gssapi/t_s4u.py +@@ -139,6 +139,14 @@ if 'auth1: user@' not in out or 'auth2: user@' not in out: + + realm.stop() + ++mark('S4U2Self with various enctypes') ++for realm in multipass_realms(create_host=False, get_creds=False): ++ service1 = 'service/1@%s' % realm.realm ++ realm.addprinc(service1) ++ realm.extract_keytab(service1, realm.keytab) ++ realm.kinit(service1, None, ['-k']) ++ realm.run(['./t_s4u', 'e:user', '-']) ++ + # Test cross realm S4U2Self using server referrals. + mark('cross-realm S4U2Self') + testprincs = {'krbtgt/SREALM': {'keys': 'aes128-cts'}, diff --git a/krb5.spec b/krb5.spec index 3cb7961..4618dc2 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1.beta2.3%{?dist} +Release: 1.beta2.4%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -63,6 +63,7 @@ Patch36: krb5-1.11-kpasswdtest.patch Patch88: Become-FIPS-aware.patch Patch89: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch Patch90: Add-tests-for-KCM-ccache-type.patch +Patch91: Remove-incorrect-KDC-assertion.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -710,6 +711,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Dec 20 2018 Robbie Harwood - 1.17-1.beta2.4 +- Remove incorrect KDC assertion + * Thu Dec 20 2018 Robbie Harwood - 1.17-1.beta2.3 - Fix syntax on pkinit_anchors field in default krb5.conf From 645562ea2ff3064758928543b0eae8b1ed6bf658 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 4 Jan 2019 10:52:20 -0500 Subject: [PATCH 083/304] Address some optimized-out memset() calls --- Address-some-optimized-out-memset-calls.patch | 94 +++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 99 insertions(+), 1 deletion(-) create mode 100644 Address-some-optimized-out-memset-calls.patch diff --git a/Address-some-optimized-out-memset-calls.patch b/Address-some-optimized-out-memset-calls.patch new file mode 100644 index 0000000..781d14a --- /dev/null +++ b/Address-some-optimized-out-memset-calls.patch @@ -0,0 +1,94 @@ +From 0d83197140d2040d47ca79f006126e503680f661 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sun, 30 Dec 2018 16:40:28 -0500 +Subject: [PATCH] Address some optimized-out memset() calls + +Ilja Van Sprundel reported a list of memset() calls which gcc +optimizes out. In krb_auth_su.c, use zap() to clear the password, and +remove two memset() calls when there is no password to clear. In +iakerb.c, remove an unnecessary memset() before setting the only two +fields of the IAKERB header structure. In svr_principal.c, use +krb5_free_key_keyblock_contents() instead of hand-freeing key data. +In asn1_k_encode.c, remove an unnecessary memset() of the kdc_req_hack +shell before returning. + +(cherry picked from commit 1057b0befec1f1c0e9d4da5521a58496e2dc0997) +--- + src/clients/ksu/krb_auth_su.c | 4 +--- + src/lib/gssapi/krb5/iakerb.c | 1 - + src/lib/kadm5/srv/svr_principal.c | 10 ++-------- + src/lib/krb5/asn.1/asn1_k_encode.c | 1 - + 4 files changed, 3 insertions(+), 13 deletions(-) + +diff --git a/src/clients/ksu/krb_auth_su.c b/src/clients/ksu/krb_auth_su.c +index 7af48195c..e39685fff 100644 +--- a/src/clients/ksu/krb_auth_su.c ++++ b/src/clients/ksu/krb_auth_su.c +@@ -183,21 +183,19 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, + if (code ) { + com_err(prog_name, code, _("while reading password for '%s'\n"), + client_name); +- memset(password, 0, sizeof(password)); + return (FALSE); + } + + if ( pwsize == 0) { + fprintf(stderr, _("No password given\n")); + *zero_password = TRUE; +- memset(password, 0, sizeof(password)); + return (FALSE); + } + + code = krb5_get_init_creds_password(context, &creds, client, password, + krb5_prompter_posix, NULL, 0, NULL, + options); +- memset(password, 0, sizeof(password)); ++ zap(password, sizeof(password)); + + + if (code) { +diff --git a/src/lib/gssapi/krb5/iakerb.c b/src/lib/gssapi/krb5/iakerb.c +index bb1072fe4..47c161ec9 100644 +--- a/src/lib/gssapi/krb5/iakerb.c ++++ b/src/lib/gssapi/krb5/iakerb.c +@@ -262,7 +262,6 @@ iakerb_make_token(iakerb_ctx_id_t ctx, + /* + * Assemble the IAKERB-HEADER from the realm and cookie + */ +- memset(&iah, 0, sizeof(iah)); + iah.target_realm = *realm; + iah.cookie = cookie; + +diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c +index 21c53ece1..9ab2c5a74 100644 +--- a/src/lib/kadm5/srv/svr_principal.c ++++ b/src/lib/kadm5/srv/svr_principal.c +@@ -2093,14 +2093,8 @@ static int decrypt_key_data(krb5_context context, + ret = krb5_dbe_decrypt_key_data(context, NULL, &key_data[i], &keys[i], + NULL); + if (ret) { +- for (; i >= 0; i--) { +- if (keys[i].contents) { +- memset (keys[i].contents, 0, keys[i].length); +- free( keys[i].contents ); +- } +- } +- +- memset(keys, 0, n_key_data*sizeof(krb5_keyblock)); ++ for (; i >= 0; i--) ++ krb5_free_keyblock_contents(context, &keys[i]); + free(keys); + return ret; + } +diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c +index 65c84be2f..81a34bac9 100644 +--- a/src/lib/krb5/asn.1/asn1_k_encode.c ++++ b/src/lib/krb5/asn.1/asn1_k_encode.c +@@ -528,7 +528,6 @@ decode_kdc_req_body(const taginfo *t, const uint8_t *asn1, size_t len, + if (ret) { + free_kdc_req_body(b); + free(h.server_realm.data); +- memset(&h, 0, sizeof(h)); + return ret; + } + b->server->realm = h.server_realm; diff --git a/krb5.spec b/krb5.spec index 4618dc2..8e26deb 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1.beta2.4%{?dist} +Release: 1.beta2.5%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -64,6 +64,7 @@ Patch88: Become-FIPS-aware.patch Patch89: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch Patch90: Add-tests-for-KCM-ccache-type.patch Patch91: Remove-incorrect-KDC-assertion.patch +Patch92: Address-some-optimized-out-memset-calls.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -711,6 +712,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Jan 04 2019 Robbie Harwood - 1.17-1.beta2.5 +- Address some optimized-out memset() calls + * Thu Dec 20 2018 Robbie Harwood - 1.17-1.beta2.4 - Remove incorrect KDC assertion From 7e29fac83e7132b03b24ae6a2464d86c403a9e6e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 4 Jan 2019 17:01:07 -0500 Subject: [PATCH 084/304] Use openssl's PRNG in FIPS mode --- Use-openssl-s-PRNG-in-FIPS-mode.patch | 40 +++++++++++++++++++++++++++ krb5.spec | 6 +++- 2 files changed, 45 insertions(+), 1 deletion(-) create mode 100644 Use-openssl-s-PRNG-in-FIPS-mode.patch diff --git a/Use-openssl-s-PRNG-in-FIPS-mode.patch b/Use-openssl-s-PRNG-in-FIPS-mode.patch new file mode 100644 index 0000000..c9aa284 --- /dev/null +++ b/Use-openssl-s-PRNG-in-FIPS-mode.patch @@ -0,0 +1,40 @@ +From 643b5e486624989acddf66ac7ce2cf71b3816fda Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 4 Jan 2019 17:00:15 -0500 +Subject: [PATCH] Use openssl's PRNG in FIPS mode + +--- + src/lib/crypto/krb/prng.c | 11 ++++++++++- + 1 file changed, 10 insertions(+), 1 deletion(-) + +diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c +index cb9ca9b98..f0e9984ca 100644 +--- a/src/lib/crypto/krb/prng.c ++++ b/src/lib/crypto/krb/prng.c +@@ -26,6 +26,8 @@ + + #include "crypto_int.h" + ++#include ++ + krb5_error_code KRB5_CALLCONV + krb5_c_random_seed(krb5_context context, krb5_data *data) + { +@@ -99,9 +101,16 @@ krb5_boolean + k5_get_os_entropy(unsigned char *buf, size_t len, int strong) + { + const char *device; +-#if defined(__linux__) && defined(SYS_getrandom) + int r; + ++ /* A wild FIPS mode appeared! */ ++ if (FIPS_mode()) { ++ /* The return codes on this API are not good */ ++ r = RAND_bytes(buf, len); ++ return r == 1; ++ } ++ ++#if defined(__linux__) && defined(SYS_getrandom) + while (len > 0) { + /* + * Pull from the /dev/urandom pool, but require it to have been seeded. diff --git a/krb5.spec b/krb5.spec index 8e26deb..16f2ba5 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1.beta2.5%{?dist} +Release: 1.beta2.6%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -65,6 +65,7 @@ Patch89: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch Patch90: Add-tests-for-KCM-ccache-type.patch Patch91: Remove-incorrect-KDC-assertion.patch Patch92: Address-some-optimized-out-memset-calls.patch +Patch93: Use-openssl-s-PRNG-in-FIPS-mode.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -712,6 +713,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Jan 04 2019 Robbie Harwood - 1.17-1.beta2.6 +- Use openssl's PRNG in FIPS mode + * Fri Jan 04 2019 Robbie Harwood - 1.17-1.beta2.5 - Address some optimized-out memset() calls From 658f28f754efb14ddd0a8b2dcc54c8e7f3f3e6d5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 8 Jan 2019 19:15:01 +0000 Subject: [PATCH 085/304] New upstream version (1.17) --- .gitignore | 3 + Add-tests-for-KCM-ccache-type.patch | 2 +- Address-some-optimized-out-memset-calls.patch | 2 +- Become-FIPS-aware.patch | 2 +- ...-plaintext-fallback-for-RC4-usages-a.patch | 2 +- Remove-incorrect-KDC-assertion.patch | 61 ------------------- Use-openssl-s-PRNG-in-FIPS-mode.patch | 2 +- krb5-1.11-kpasswdtest.patch | 2 +- krb5-1.11-run_user_0.patch | 2 +- krb5-1.12-api.patch | 2 +- krb5-1.12-ksu-path.patch | 2 +- krb5-1.12-ktany.patch | 2 +- krb5-1.12.1-pam.patch | 6 +- krb5-1.13-dirsrv-accountlock.patch | 2 +- krb5-1.15-beta1-buildconf.patch | 2 +- krb5-1.17-beta1-selinux-label.patch | 8 +-- krb5-1.3.1-dns.patch | 2 +- krb5-1.9-debuginfo.patch | 2 +- krb5.spec | 8 ++- sources | 6 +- 20 files changed, 32 insertions(+), 88 deletions(-) delete mode 100644 Remove-incorrect-KDC-assertion.patch diff --git a/.gitignore b/.gitignore index 7d8ad15..523856e 100644 --- a/.gitignore +++ b/.gitignore @@ -172,3 +172,6 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.17-beta2.tar.gz /krb5-1.17-beta2.tar.gz.asc /krb5-1.17-beta2-pdfs.tar +/krb5-1.17-pdfs.tar +/krb5-1.17.tar.gz +/krb5-1.17.tar.gz.asc diff --git a/Add-tests-for-KCM-ccache-type.patch b/Add-tests-for-KCM-ccache-type.patch index ef9b875..fac526f 100644 --- a/Add-tests-for-KCM-ccache-type.patch +++ b/Add-tests-for-KCM-ccache-type.patch @@ -1,4 +1,4 @@ -From b361f6bbc2873bd54963076738dc3ae6224261a0 Mon Sep 17 00:00:00 2001 +From 528f9ef3842ef5caba0990568e3cd7104e640c52 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Nov 2018 00:27:35 -0500 Subject: [PATCH] Add tests for KCM ccache type diff --git a/Address-some-optimized-out-memset-calls.patch b/Address-some-optimized-out-memset-calls.patch index 781d14a..099f238 100644 --- a/Address-some-optimized-out-memset-calls.patch +++ b/Address-some-optimized-out-memset-calls.patch @@ -1,4 +1,4 @@ -From 0d83197140d2040d47ca79f006126e503680f661 Mon Sep 17 00:00:00 2001 +From 028ed9cee24159b25ecb8f62e8d171b850ed0a41 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 30 Dec 2018 16:40:28 -0500 Subject: [PATCH] Address some optimized-out memset() calls diff --git a/Become-FIPS-aware.patch b/Become-FIPS-aware.patch index 20c211d..9c4bb5f 100644 --- a/Become-FIPS-aware.patch +++ b/Become-FIPS-aware.patch @@ -1,4 +1,4 @@ -From 6e1f7b50b36e0036838c91841c83360fdd567ec5 Mon Sep 17 00:00:00 2001 +From ebcee0c8dc5f3055597e0b574d98cbe65f55319e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] Become FIPS-aware diff --git a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch b/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch index 78fb0d9..b34aed1 100644 --- a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch +++ b/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch @@ -1,4 +1,4 @@ -From 2bd85da058d2d73eb2818a8e64656fec9b21b3c3 Mon Sep 17 00:00:00 2001 +From 1caf8246184211e06708e01a106632e26d9a84a8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 31 Jul 2018 13:47:26 -0400 Subject: [PATCH] In FIPS mode, add plaintext fallback for RC4 usages and taint diff --git a/Remove-incorrect-KDC-assertion.patch b/Remove-incorrect-KDC-assertion.patch deleted file mode 100644 index f951269..0000000 --- a/Remove-incorrect-KDC-assertion.patch +++ /dev/null @@ -1,61 +0,0 @@ -From 5ab44ff3ecdf362a792f193cf18df42866b70f80 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Sat, 15 Dec 2018 11:56:36 +0200 -Subject: [PATCH] Remove incorrect KDC assertion - -The assertion in return_enc_padata() is reachable because -kdc_make_s4u2self_rep() may have previously added encrypted padata. -It is no longer necessary because the code uses add_pa_data_element() -instead of allocating a new list. - -CVE-2018-20217: - -In MIT krb5 1.8 or later, an authenticated user who can obtain a TGT -using an older encryption type (DES, DES3, or RC4) can cause an -assertion failure in the KDC by sending an S4U2Self request. - -[ghudson@mit.edu: rewrote commit message with CVE description] - -ticket: 8767 (new) -tags: pullup -target_version: 1.17 -target_version: 1.16-next -target_version: 1.15-next - -(cherry picked from commit 94e5eda5bb94d1d44733a49c3d9b6d1e42c74def) ---- - src/kdc/kdc_preauth.c | 1 - - src/tests/gssapi/t_s4u.py | 8 ++++++++ - 2 files changed, 8 insertions(+), 1 deletion(-) - -diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c -index 74953c99f..caf133c14 100644 ---- a/src/kdc/kdc_preauth.c -+++ b/src/kdc/kdc_preauth.c -@@ -1683,7 +1683,6 @@ return_enc_padata(krb5_context context, krb5_data *req_pkt, - krb5_error_code code = 0; - /* This should be initialized and only used for Win2K compat and other - * specific standardized uses such as FAST negotiation. */ -- assert(reply_encpart->enc_padata == NULL); - if (is_referral) { - code = return_referral_enc_padata(context, reply_encpart, server); - if (code) -diff --git a/src/tests/gssapi/t_s4u.py b/src/tests/gssapi/t_s4u.py -index fd29e1a27..f02c2fd13 100755 ---- a/src/tests/gssapi/t_s4u.py -+++ b/src/tests/gssapi/t_s4u.py -@@ -139,6 +139,14 @@ if 'auth1: user@' not in out or 'auth2: user@' not in out: - - realm.stop() - -+mark('S4U2Self with various enctypes') -+for realm in multipass_realms(create_host=False, get_creds=False): -+ service1 = 'service/1@%s' % realm.realm -+ realm.addprinc(service1) -+ realm.extract_keytab(service1, realm.keytab) -+ realm.kinit(service1, None, ['-k']) -+ realm.run(['./t_s4u', 'e:user', '-']) -+ - # Test cross realm S4U2Self using server referrals. - mark('cross-realm S4U2Self') - testprincs = {'krbtgt/SREALM': {'keys': 'aes128-cts'}, diff --git a/Use-openssl-s-PRNG-in-FIPS-mode.patch b/Use-openssl-s-PRNG-in-FIPS-mode.patch index c9aa284..29cceff 100644 --- a/Use-openssl-s-PRNG-in-FIPS-mode.patch +++ b/Use-openssl-s-PRNG-in-FIPS-mode.patch @@ -1,4 +1,4 @@ -From 643b5e486624989acddf66ac7ce2cf71b3816fda Mon Sep 17 00:00:00 2001 +From a81c558f4fc75ef988a283729fd9c7e79e9df70f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 4 Jan 2019 17:00:15 -0500 Subject: [PATCH] Use openssl's PRNG in FIPS mode diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch index c5dc157..0a9fff6 100644 --- a/krb5-1.11-kpasswdtest.patch +++ b/krb5-1.11-kpasswdtest.patch @@ -1,4 +1,4 @@ -From 6e8f8054396459c1f53c838801b0a75d235fdabb Mon Sep 17 00:00:00 2001 +From d4035585df4b3132d1897067d6c452cc06aa16dd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:52:01 -0400 Subject: [PATCH] krb5-1.11-kpasswdtest.patch diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch index d8dd892..705af96 100644 --- a/krb5-1.11-run_user_0.patch +++ b/krb5-1.11-run_user_0.patch @@ -1,4 +1,4 @@ -From ac7370914ab1646ac79475399ff5e9ca4ec58737 Mon Sep 17 00:00:00 2001 +From 3d09297c65f27033cce8abbab2e50716abdae48f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:57 -0400 Subject: [PATCH] krb5-1.11-run_user_0.patch diff --git a/krb5-1.12-api.patch b/krb5-1.12-api.patch index 1ec3e8c..159ad57 100644 --- a/krb5-1.12-api.patch +++ b/krb5-1.12-api.patch @@ -1,4 +1,4 @@ -From eaaca3b6e9eb279ba7c50af95f0c84068927da16 Mon Sep 17 00:00:00 2001 +From f267d34d0dea6778c700036b89156fc17ca506e9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:00 -0400 Subject: [PATCH] krb5-1.12-api.patch diff --git a/krb5-1.12-ksu-path.patch b/krb5-1.12-ksu-path.patch index 773b134..4b990ce 100644 --- a/krb5-1.12-ksu-path.patch +++ b/krb5-1.12-ksu-path.patch @@ -1,4 +1,4 @@ -From b4804625f0b778ceaabdcc4fb448e7b5ba1523a5 Mon Sep 17 00:00:00 2001 +From e62b5022c129229e86f40f97d2e1c71a01d7227b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:32:09 -0400 Subject: [PATCH] krb5-1.12-ksu-path.patch diff --git a/krb5-1.12-ktany.patch b/krb5-1.12-ktany.patch index b0691dc..8049432 100644 --- a/krb5-1.12-ktany.patch +++ b/krb5-1.12-ktany.patch @@ -1,4 +1,4 @@ -From 001a4204b41823b939ca7f6ff82cc55c084e69d9 Mon Sep 17 00:00:00 2001 +From c93c099e3d3e0a78393e7445fe17d58cf1abc666 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:33:53 -0400 Subject: [PATCH] krb5-1.12-ktany.patch diff --git a/krb5-1.12.1-pam.patch b/krb5-1.12.1-pam.patch index e89f2b0..10892d4 100644 --- a/krb5-1.12.1-pam.patch +++ b/krb5-1.12.1-pam.patch @@ -1,4 +1,4 @@ -From c734e307fb5cf75d2a54147ffe9b14b0c8a0558b Mon Sep 17 00:00:00 2001 +From c8f2e321b2d8471feee69bbca3179e675228bd8a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] krb5-1.12.1-pam.patch @@ -756,10 +756,10 @@ index 000000000..0ab76569c +void appl_pam_cleanup(void); +#endif diff --git a/src/configure.in b/src/configure.in -index 84529c120..5d5f148ca 100644 +index 61ef738dc..e9a12ac16 100644 --- a/src/configure.in +++ b/src/configure.in -@@ -1348,6 +1348,8 @@ AC_SUBST([VERTO_VERSION]) +@@ -1352,6 +1352,8 @@ AC_SUBST([VERTO_VERSION]) AC_PATH_PROG(GROFF, groff) diff --git a/krb5-1.13-dirsrv-accountlock.patch b/krb5-1.13-dirsrv-accountlock.patch index cfdd2d8..7faa245 100644 --- a/krb5-1.13-dirsrv-accountlock.patch +++ b/krb5-1.13-dirsrv-accountlock.patch @@ -1,4 +1,4 @@ -From 6ac22c213525b704183106053e7a49d7a18f3903 Mon Sep 17 00:00:00 2001 +From 3da19a991cce8861c092ed1341d9cd7837b2f6f7 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:44 -0400 Subject: [PATCH] krb5-1.13-dirsrv-accountlock.patch diff --git a/krb5-1.15-beta1-buildconf.patch b/krb5-1.15-beta1-buildconf.patch index 9dcbd9a..5725758 100644 --- a/krb5-1.15-beta1-buildconf.patch +++ b/krb5-1.15-beta1-buildconf.patch @@ -1,4 +1,4 @@ -From ee22f82b9a68f39a7c02b8eb75981c978d0f6e8c Mon Sep 17 00:00:00 2001 +From 7b457b5b4130208745b8c592e53e42c10f356e27 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] krb5-1.15-beta1-buildconf.patch diff --git a/krb5-1.17-beta1-selinux-label.patch b/krb5-1.17-beta1-selinux-label.patch index 4895fec..bf5d4eb 100644 --- a/krb5-1.17-beta1-selinux-label.patch +++ b/krb5-1.17-beta1-selinux-label.patch @@ -1,4 +1,4 @@ -From 08e57eb589daa83dcbada0d1f81d5fb8dbe31fc4 Mon Sep 17 00:00:00 2001 +From e1c4f8894d22da9c157bfcf31e28f9ceaeebe39e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] krb5-1.17-beta1-selinux-label.patch @@ -172,10 +172,10 @@ index ce87e21ca..917357df9 100644 GSS_LIBS = $(GSS_KRB5_LIB) # needs fixing if ever used on macOS! diff --git a/src/configure.in b/src/configure.in -index 5d5f148ca..16e785017 100644 +index e9a12ac16..93aec682e 100644 --- a/src/configure.in +++ b/src/configure.in -@@ -1350,6 +1350,8 @@ AC_PATH_PROG(GROFF, groff) +@@ -1354,6 +1354,8 @@ AC_PATH_PROG(GROFF, groff) KRB5_WITH_PAM @@ -631,7 +631,7 @@ index 24e41fb80..0dcb6b543 100644 retval = errno; if (retval == 0) diff --git a/src/util/support/Makefile.in b/src/util/support/Makefile.in -index b1842daf9..82d08943c 100644 +index db7b030b8..321672bcb 100644 --- a/src/util/support/Makefile.in +++ b/src/util/support/Makefile.in @@ -69,6 +69,7 @@ IPC_SYMS= \ diff --git a/krb5-1.3.1-dns.patch b/krb5-1.3.1-dns.patch index a03312f..d213d71 100644 --- a/krb5-1.3.1-dns.patch +++ b/krb5-1.3.1-dns.patch @@ -1,4 +1,4 @@ -From fdfee89c7e849d8aa9d69fb453d87d1dcf750b84 Mon Sep 17 00:00:00 2001 +From 40259729fa4fbec2b22e9ca8043202ac914cca24 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] krb5-1.3.1-dns.patch diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index 7594a6c..6b1c220 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -1,4 +1,4 @@ -From a766fdb8929635483ae7b8f7ff13ad105571f8c1 Mon Sep 17 00:00:00 2001 +From d6758af31afecc3835043a8e599302f372fcef82 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] krb5-1.9-debuginfo.patch diff --git a/krb5.spec b/krb5.spec index 16f2ba5..8da9d25 100644 --- a/krb5.spec +++ b/krb5.spec @@ -9,7 +9,7 @@ %global configured_default_ccache_name KEYRING:persistent:%%{uid} # leave empty or set to e.g., -beta2 -%global prerelease -beta2 +%global prerelease %{nil} # Should be in form 5.0, 6.1, etc. %global kdbversion 7.0 @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1.beta2.6%{?dist} +Release: 2 # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -63,7 +63,6 @@ Patch36: krb5-1.11-kpasswdtest.patch Patch88: Become-FIPS-aware.patch Patch89: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch Patch90: Add-tests-for-KCM-ccache-type.patch -Patch91: Remove-incorrect-KDC-assertion.patch Patch92: Address-some-optimized-out-memset-calls.patch Patch93: Use-openssl-s-PRNG-in-FIPS-mode.patch @@ -713,6 +712,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Jan 08 2019 Robbie Harwood - 1.17-2 +- New upstream version (1.17) + * Fri Jan 04 2019 Robbie Harwood - 1.17-1.beta2.6 - Use openssl's PRNG in FIPS mode diff --git a/sources b/sources index 5a03b5d..3517dec 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (krb5-1.17-beta2.tar.gz) = 4611e2091c74e6de7fe5a3e57c44c4afcc2ebd590dcc1fe99f73fac95aec64574b06bb636acb4cd694e49db76ccdee5448202ab4c653c4330b40b9e42cc1d206 -SHA512 (krb5-1.17-beta2.tar.gz.asc) = cfb826cd69701071411270b75ed8241487e2aef032ae407f866e63c7871dbb23103b02fec73ab8ee4ae085b03216c91e688ad0b77e068054e4b1d3a625fcfc8b -SHA512 (krb5-1.17-beta2-pdfs.tar) = 24140822150a32ed3efa855741da7c220c8cf5875b4517fa48591d4c90454653d70558e2a31461a2c32d21b801eac7c96c0a75a5cd6989dbabe6454a802002dd +SHA512 (krb5-1.17-pdfs.tar) = 89a5a709720ee9028e9bfbcbc808eec436c4b9c6e105888b37660e97cff48e190bc77affa9809353de9cf2f39e517e8a6ab22792263978b403a4a6317ac24a46 +SHA512 (krb5-1.17.tar.gz) = 7462a578b936bd17f155a362dbb5d388e157a80a096549028be6c55400b11361c7f8a28e424fd5674801873651df4e694d536cae66728b7ae5e840e532358c52 +SHA512 (krb5-1.17.tar.gz.asc) = 7ee81ccd05559ca1ff945619165297db251010db7c0205855f89ae66a73bc78e98f5e28ea154dcb752f5d4afb9349a293dcf8f64858d2129a869295fa8946e0f From 1458a863a4d11475c712920e2fba1c5f4f1e637d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 17 Jan 2019 13:44:00 -0500 Subject: [PATCH 086/304] enctype logging and explicit_bzero() --- ...on-and-enctype-flag-for-deprecations.patch | 183 +++++++++++ ...llocating-a-register-in-zap-assembly.patch | 55 ++++ ...ebug-log-proper-ticket-enctype-names.patch | 28 ++ ...ec-always-log-non-permitted-enctypes.patch | 54 ++++ ...ype-names-in-KDC-logs-human-readable.patch | 296 ++++++++++++++++++ Mark-deprecated-enctypes-when-used.patch | 250 +++++++++++++++ krb5.spec | 11 +- 7 files changed, 876 insertions(+), 1 deletion(-) create mode 100644 Add-function-and-enctype-flag-for-deprecations.patch create mode 100644 Avoid-allocating-a-register-in-zap-assembly.patch create mode 100644 In-kpropd-debug-log-proper-ticket-enctype-names.patch create mode 100644 In-rd_req_dec-always-log-non-permitted-enctypes.patch create mode 100644 Make-etype-names-in-KDC-logs-human-readable.patch create mode 100644 Mark-deprecated-enctypes-when-used.patch diff --git a/Add-function-and-enctype-flag-for-deprecations.patch b/Add-function-and-enctype-flag-for-deprecations.patch new file mode 100644 index 0000000..ee1628b --- /dev/null +++ b/Add-function-and-enctype-flag-for-deprecations.patch @@ -0,0 +1,183 @@ +From e0c8eb1bf93e0591e363e414378c70c255a6e6b6 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 15 Jan 2019 16:16:57 -0500 +Subject: [PATCH] Add function and enctype flag for deprecations + +krb5int_c_deprecated_enctype() checks for the ETYPE_DEPRECATED flag on +enctypes. All ENCTYPE_WEAK enctypes are currently deprecated; not all +deprecated enctypes are considered weak. Deprecations follow RFC 6649 +and RFC 8429. + +(cherry picked from commit 484a6e7712f9b66e782b2520f07b0883889e116f) +--- + src/include/k5-int.h | 1 + + src/lib/crypto/krb/crypto_int.h | 9 ++++++++- + src/lib/crypto/krb/enctype_util.c | 7 +++++++ + src/lib/crypto/krb/etypes.c | 19 ++++++++++--------- + src/lib/crypto/libk5crypto.exports | 1 + + src/lib/krb5_32.def | 3 +++ + 6 files changed, 30 insertions(+), 10 deletions(-) + +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 8f9329c59..255cee822 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -2077,6 +2077,7 @@ krb5_get_tgs_ktypes(krb5_context, krb5_const_principal, krb5_enctype **); + krb5_boolean krb5_is_permitted_enctype(krb5_context, krb5_enctype); + + krb5_boolean KRB5_CALLCONV krb5int_c_weak_enctype(krb5_enctype); ++krb5_boolean KRB5_CALLCONV krb5int_c_deprecated_enctype(krb5_enctype); + krb5_error_code k5_enctype_to_ssf(krb5_enctype enctype, unsigned int *ssf_out); + + krb5_error_code krb5_kdc_rep_decrypt_proc(krb5_context, const krb5_keyblock *, +diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h +index e5099291e..6c1c77cac 100644 +--- a/src/lib/crypto/krb/crypto_int.h ++++ b/src/lib/crypto/krb/crypto_int.h +@@ -114,7 +114,14 @@ struct krb5_keytypes { + unsigned int ssf; + }; + +-#define ETYPE_WEAK 1 ++/* ++ * "Weak" means the enctype is believed to be vulnerable to practical attacks, ++ * and will be disabled unless allow_weak_crypto is set to true. "Deprecated" ++ * means the enctype has been deprecated by the IETF, and affects display and ++ * logging. ++ */ ++#define ETYPE_WEAK (1 << 0) ++#define ETYPE_DEPRECATED (1 << 1) + + extern const struct krb5_keytypes krb5int_enctypes_list[]; + extern const int krb5int_enctypes_length; +diff --git a/src/lib/crypto/krb/enctype_util.c b/src/lib/crypto/krb/enctype_util.c +index b1b40e7ec..e394f4e19 100644 +--- a/src/lib/crypto/krb/enctype_util.c ++++ b/src/lib/crypto/krb/enctype_util.c +@@ -51,6 +51,13 @@ krb5int_c_weak_enctype(krb5_enctype etype) + return (ktp != NULL && (ktp->flags & ETYPE_WEAK) != 0); + } + ++krb5_boolean KRB5_CALLCONV ++krb5int_c_deprecated_enctype(krb5_enctype etype) ++{ ++ const struct krb5_keytypes *ktp = find_enctype(etype); ++ return ktp != NULL && (ktp->flags & ETYPE_DEPRECATED) != 0; ++} ++ + krb5_error_code KRB5_CALLCONV + krb5_c_enctype_compare(krb5_context context, krb5_enctype e1, krb5_enctype e2, + krb5_boolean *similar) +diff --git a/src/lib/crypto/krb/etypes.c b/src/lib/crypto/krb/etypes.c +index 53d4a5c79..8f44c37e7 100644 +--- a/src/lib/crypto/krb/etypes.c ++++ b/src/lib/crypto/krb/etypes.c +@@ -33,6 +33,7 @@ + that the keytypes are all near each other. I'd rather not make + that assumption. */ + ++/* Deprecations come from RFC 6649 and RFC 8249. */ + const struct krb5_keytypes krb5int_enctypes_list[] = { + { ENCTYPE_DES_CBC_CRC, + "des-cbc-crc", { 0 }, "DES cbc mode with CRC-32", +@@ -42,7 +43,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { + krb5int_des_string_to_key, k5_rand2key_des, + krb5int_des_prf, + CKSUMTYPE_RSA_MD5_DES, +- ETYPE_WEAK, 56 }, ++ ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, + { ENCTYPE_DES_CBC_MD4, + "des-cbc-md4", { 0 }, "DES cbc mode with RSA-MD4", + &krb5int_enc_des, &krb5int_hash_md4, +@@ -51,7 +52,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { + krb5int_des_string_to_key, k5_rand2key_des, + krb5int_des_prf, + CKSUMTYPE_RSA_MD4_DES, +- ETYPE_WEAK, 56 }, ++ ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, + { ENCTYPE_DES_CBC_MD5, + "des-cbc-md5", { "des" }, "DES cbc mode with RSA-MD5", + &krb5int_enc_des, &krb5int_hash_md5, +@@ -60,7 +61,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { + krb5int_des_string_to_key, k5_rand2key_des, + krb5int_des_prf, + CKSUMTYPE_RSA_MD5_DES, +- ETYPE_WEAK, 56 }, ++ ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, + { ENCTYPE_DES_CBC_RAW, + "des-cbc-raw", { 0 }, "DES cbc mode raw", + &krb5int_enc_des, NULL, +@@ -69,7 +70,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { + krb5int_des_string_to_key, k5_rand2key_des, + krb5int_des_prf, + 0, +- ETYPE_WEAK, 56 }, ++ ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, + { ENCTYPE_DES3_CBC_RAW, + "des3-cbc-raw", { 0 }, "Triple DES cbc mode raw", + &krb5int_enc_des3, NULL, +@@ -78,7 +79,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { + krb5int_dk_string_to_key, k5_rand2key_des3, + NULL, /*PRF*/ + 0, +- ETYPE_WEAK, 112 }, ++ ETYPE_WEAK | ETYPE_DEPRECATED, 112 }, + + { ENCTYPE_DES3_CBC_SHA1, + "des3-cbc-sha1", { "des3-hmac-sha1", "des3-cbc-sha1-kd" }, +@@ -89,7 +90,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { + krb5int_dk_string_to_key, k5_rand2key_des3, + krb5int_dk_prf, + CKSUMTYPE_HMAC_SHA1_DES3, +- 0 /*flags*/, 112 }, ++ ETYPE_DEPRECATED, 112 }, + + { ENCTYPE_DES_HMAC_SHA1, + "des-hmac-sha1", { 0 }, "DES with HMAC/sha1", +@@ -99,7 +100,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { + krb5int_dk_string_to_key, k5_rand2key_des, + NULL, /*PRF*/ + 0, +- ETYPE_WEAK, 56 }, ++ ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, + + /* rc4-hmac uses a 128-bit key, but due to weaknesses in the RC4 cipher, we + * consider its strength degraded and assign it an SSF value of 64. */ +@@ -113,7 +114,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { + krb5int_arcfour_decrypt, krb5int_arcfour_string_to_key, + k5_rand2key_direct, krb5int_arcfour_prf, + CKSUMTYPE_HMAC_MD5_ARCFOUR, +- 0 /*flags*/, 64 }, ++ ETYPE_DEPRECATED, 64 }, + { ENCTYPE_ARCFOUR_HMAC_EXP, + "arcfour-hmac-exp", { "rc4-hmac-exp", "arcfour-hmac-md5-exp" }, + "Exportable ArcFour with HMAC/md5", +@@ -124,7 +125,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { + krb5int_arcfour_decrypt, krb5int_arcfour_string_to_key, + k5_rand2key_direct, krb5int_arcfour_prf, + CKSUMTYPE_HMAC_MD5_ARCFOUR, +- ETYPE_WEAK, 40 ++ ETYPE_WEAK | ETYPE_DEPRECATED, 40 + }, + + { ENCTYPE_AES128_CTS_HMAC_SHA1_96, +diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports +index 82eb5f30c..90afdf5f7 100644 +--- a/src/lib/crypto/libk5crypto.exports ++++ b/src/lib/crypto/libk5crypto.exports +@@ -109,3 +109,4 @@ k5_allow_weak_pbkdf2iter + krb5_c_prfplus + krb5_c_derive_prfplus + k5_enctype_to_ssf ++krb5int_c_deprecated_enctype +diff --git a/src/lib/krb5_32.def b/src/lib/krb5_32.def +index c35022931..e6a487593 100644 +--- a/src/lib/krb5_32.def ++++ b/src/lib/krb5_32.def +@@ -487,3 +487,6 @@ EXPORTS + encode_krb5_pa_spake @444 ; PRIVATE + decode_krb5_pa_spake @445 ; PRIVATE + k5_free_pa_spake @446 ; PRIVATE ++ ++; new in 1.18 ++ krb5int_c_deprecated_enctype @450 ; PRIVATE diff --git a/Avoid-allocating-a-register-in-zap-assembly.patch b/Avoid-allocating-a-register-in-zap-assembly.patch new file mode 100644 index 0000000..71677ca --- /dev/null +++ b/Avoid-allocating-a-register-in-zap-assembly.patch @@ -0,0 +1,55 @@ +From 77b1ce65e7777395cee5a79e4068ff4340fcc680 Mon Sep 17 00:00:00 2001 +From: Andreas Schneider +Date: Thu, 3 Jan 2019 17:19:32 +0100 +Subject: [PATCH] Avoid allocating a register in zap() assembly + +See https://bugs.llvm.org/show_bug.cgi?id=15495 + +Also add explicit_bzero() (glibc, FreeBSD) and explicit_memset() +(NetBSD) as alternatives. + +[ghudson@mit.edu: added explicit_bzero() and explicit_memset()] + +(cherry picked from commit 7391e8b541061d0f584193b4a53365b64364b0e8) +--- + src/configure.in | 2 +- + src/include/k5-platform.h | 6 +++++- + 2 files changed, 6 insertions(+), 2 deletions(-) + +diff --git a/src/configure.in b/src/configure.in +index 93aec682e..7c309a26b 100644 +--- a/src/configure.in ++++ b/src/configure.in +@@ -421,7 +421,7 @@ AC_PROG_LEX + AC_C_CONST + AC_HEADER_DIRENT + AC_FUNC_STRERROR_R +-AC_CHECK_FUNCS(strdup setvbuf seteuid setresuid setreuid setegid setresgid setregid setsid flock fchmod chmod strptime geteuid setenv unsetenv getenv gmtime_r localtime_r bswap16 bswap64 mkstemp getusershell access getcwd srand48 srand srandom stat strchr strerror timegm) ++AC_CHECK_FUNCS(strdup setvbuf seteuid setresuid setreuid setegid setresgid setregid setsid flock fchmod chmod strptime geteuid setenv unsetenv getenv gmtime_r localtime_r bswap16 bswap64 mkstemp getusershell access getcwd srand48 srand srandom stat strchr strerror timegm explicit_bzero explicit_memset) + + AC_CHECK_FUNC(mkstemp, + [MKSTEMP_ST_OBJ= +diff --git a/src/include/k5-platform.h b/src/include/k5-platform.h +index 997b655e1..1fcd68e8c 100644 +--- a/src/include/k5-platform.h ++++ b/src/include/k5-platform.h +@@ -1023,6 +1023,10 @@ static inline void zap(void *ptr, size_t len) + if (len > 0) + memset_s(ptr, len, 0, len); + } ++#elif defined(HAVE_EXPLICIT_BZERO) ++# define zap(ptr, len) explicit_bzero(ptr, len) ++#elif defined(HAVE_EXPLICIT_MEMSET) ++# define zap(ptr, len) explicit_memset(ptr, 0, len) + #elif defined(__GNUC__) || defined(__clang__) + /* + * Use an asm statement which declares a memory clobber to force the memset to +@@ -1032,7 +1036,7 @@ static inline void zap(void *ptr, size_t len) + { + if (len > 0) + memset(ptr, 0, len); +- __asm__ __volatile__("" : : "r" (ptr) : "memory"); ++ __asm__ __volatile__("" : : "g" (ptr) : "memory"); + } + #else + /* diff --git a/In-kpropd-debug-log-proper-ticket-enctype-names.patch b/In-kpropd-debug-log-proper-ticket-enctype-names.patch new file mode 100644 index 0000000..6090842 --- /dev/null +++ b/In-kpropd-debug-log-proper-ticket-enctype-names.patch @@ -0,0 +1,28 @@ +From d2990ce023e000e1628007a5d24aad5a5abdb0a3 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 15 Jan 2019 13:41:16 -0500 +Subject: [PATCH] In kpropd, debug-log proper ticket enctype names + +This change replaces the last call of krb5_enctype_to_string() in our +sources with krb5_enctype_to_name(), ensuring that we log consistently +to users using readily discoverable strings. + +(cherry picked from commit 30e12a2ecdf7e2a034a91626a03b5c9909e4c68d) +--- + src/kprop/kpropd.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c +index 4cc035dc6..0c7bffa24 100644 +--- a/src/kprop/kpropd.c ++++ b/src/kprop/kpropd.c +@@ -1279,7 +1279,8 @@ kerberos_authenticate(krb5_context context, int fd, krb5_principal *clientp, + exit(1); + } + +- retval = krb5_enctype_to_string(*etype, etypebuf, sizeof(etypebuf)); ++ retval = krb5_enctype_to_name(*etype, FALSE, etypebuf, ++ sizeof(etypebuf)); + if (retval) { + com_err(progname, retval, _("while unparsing ticket etype")); + exit(1); diff --git a/In-rd_req_dec-always-log-non-permitted-enctypes.patch b/In-rd_req_dec-always-log-non-permitted-enctypes.patch new file mode 100644 index 0000000..787ce20 --- /dev/null +++ b/In-rd_req_dec-always-log-non-permitted-enctypes.patch @@ -0,0 +1,54 @@ +From e595f7a4c1c95aadcb1bc3ea2bb88fce66fb826b Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 14 Jan 2019 17:14:42 -0500 +Subject: [PATCH] In rd_req_dec, always log non-permitted enctypes + +The buffer specified in negotiate_etype() is too small for use with +the AES enctypes when used with krb5_enctype_to_string(), so switch to +using krb5_enctype_to_name(). + +(cherry picked from commit bf75ebf583a51bf00005a96d17924818d19377be) +--- + src/lib/krb5/krb/rd_req_dec.c | 5 ++--- + src/tests/gssapi/t_enctypes.py | 5 +++-- + 2 files changed, 5 insertions(+), 5 deletions(-) + +diff --git a/src/lib/krb5/krb/rd_req_dec.c b/src/lib/krb5/krb/rd_req_dec.c +index 4cd429a11..e75192fee 100644 +--- a/src/lib/krb5/krb/rd_req_dec.c ++++ b/src/lib/krb5/krb/rd_req_dec.c +@@ -864,9 +864,8 @@ negotiate_etype(krb5_context context, + if (permitted == FALSE) { + char enctype_name[30]; + +- if (krb5_enctype_to_string(desired_etypes[i], +- enctype_name, +- sizeof(enctype_name)) == 0) ++ if (krb5_enctype_to_name(desired_etypes[i], FALSE, enctype_name, ++ sizeof(enctype_name)) == 0) + k5_setmsg(context, KRB5_NOPERM_ETYPE, + _("Encryption type %s not permitted"), enctype_name); + return KRB5_NOPERM_ETYPE; +diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py +index ee43ff028..5d9f80e04 100755 +--- a/src/tests/gssapi/t_enctypes.py ++++ b/src/tests/gssapi/t_enctypes.py +@@ -85,7 +85,8 @@ test('both aes128', 'aes128-cts', 'aes128-cts', + # If only the acceptor constrains the permitted session enctypes to + # aes128, subkey negotiation fails because the acceptor considers the + # aes256 session key to be non-permitted. +-test_err('acc aes128', None, 'aes128-cts', 'Encryption type not permitted') ++test_err('acc aes128', None, 'aes128-cts', ++ 'Encryption type aes256-cts-hmac-sha1-96 not permitted') + + # If the initiator constrains the permitted session enctypes to des3, + # no acceptor subkey will be generated because we can't upgrade to a +@@ -128,7 +129,7 @@ test('upgrade init des3+rc4', 'des3 rc4', None, + # is only for the sake of the kernel, since we could upgrade to an + # aes128 subkey, but it's the current semantics.) + test_err('upgrade acc aes128', None, 'aes128-cts', +- 'Encryption type ArcFour with HMAC/md5 not permitted') ++ 'Encryption type arcfour-hmac not permitted') + + # If the acceptor permits rc4 but prefers aes128, it will negotiate an + # upgrade to aes128. diff --git a/Make-etype-names-in-KDC-logs-human-readable.patch b/Make-etype-names-in-KDC-logs-human-readable.patch new file mode 100644 index 0000000..2761ba3 --- /dev/null +++ b/Make-etype-names-in-KDC-logs-human-readable.patch @@ -0,0 +1,296 @@ +From b999ade3996817ccb9c9362e4c06dd236e4a854b Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 8 Jan 2019 17:42:35 -0500 +Subject: [PATCH] Make etype names in KDC logs human-readable + +Introduce enctype_name() as a wrapper over krb5_enctype_to_name for +converting between registered constants and names. Adjust signatures +and rewrite ktypes2str() and rep_etypes2str() to operate on dynamic +buffers. + +ticket: 8772 (new) +(cherry picked from commit a649279727490687d54becad91fde8cf7429d951) +--- + src/kdc/kdc_log.c | 42 +++++++-------- + src/kdc/kdc_util.c | 131 +++++++++++++++++++++++---------------------- + src/kdc/kdc_util.h | 6 +-- + 3 files changed, 90 insertions(+), 89 deletions(-) + +diff --git a/src/kdc/kdc_log.c b/src/kdc/kdc_log.c +index 4eec50373..b160ba21a 100644 +--- a/src/kdc/kdc_log.c ++++ b/src/kdc/kdc_log.c +@@ -65,7 +65,7 @@ log_as_req(krb5_context context, + { + const char *fromstring = 0; + char fromstringbuf[70]; +- char ktypestr[128]; ++ char *ktypestr = NULL; + const char *cname2 = cname ? cname : ""; + const char *sname2 = sname ? sname : ""; + +@@ -74,26 +74,29 @@ log_as_req(krb5_context context, + fromstringbuf, sizeof(fromstringbuf)); + if (!fromstring) + fromstring = ""; +- ktypes2str(ktypestr, sizeof(ktypestr), +- request->nktypes, request->ktype); ++ ++ ktypestr = ktypes2str(request->ktype, request->nktypes); + + if (status == NULL) { + /* success */ +- char rep_etypestr[128]; +- rep_etypes2str(rep_etypestr, sizeof(rep_etypestr), reply); ++ char *rep_etypestr = rep_etypes2str(reply); + krb5_klog_syslog(LOG_INFO, _("AS_REQ (%s) %s: ISSUE: authtime %u, %s, " + "%s for %s"), +- ktypestr, fromstring, (unsigned int)authtime, +- rep_etypestr, cname2, sname2); ++ ktypestr ? ktypestr : "", fromstring, ++ (unsigned int)authtime, ++ rep_etypestr ? rep_etypestr : "", cname2, sname2); ++ free(rep_etypestr); + } else { + /* fail */ + krb5_klog_syslog(LOG_INFO, _("AS_REQ (%s) %s: %s: %s for %s%s%s"), +- ktypestr, fromstring, status, +- cname2, sname2, emsg ? ", " : "", emsg ? emsg : ""); ++ ktypestr ? ktypestr : "", fromstring, status, cname2, ++ sname2, emsg ? ", " : "", emsg ? emsg : ""); + } + krb5_db_audit_as_req(context, request, + local_addr->address, remote_addr->address, + client, server, authtime, errcode); ++ ++ free(ktypestr); + } + + /* +@@ -122,10 +125,9 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from, + unsigned int c_flags, + const char *status, krb5_error_code errcode, const char *emsg) + { +- char ktypestr[128]; ++ char *ktypestr = NULL, *rep_etypestr = NULL; + const char *fromstring = 0; + char fromstringbuf[70]; +- char rep_etypestr[128]; + char *cname = NULL, *sname = NULL, *altcname = NULL; + char *logcname = NULL, *logsname = NULL, *logaltcname = NULL; + +@@ -134,11 +136,6 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from, + fromstringbuf, sizeof(fromstringbuf)); + if (!fromstring) + fromstring = ""; +- ktypes2str(ktypestr, sizeof(ktypestr), request->nktypes, request->ktype); +- if (!errcode) +- rep_etypes2str(rep_etypestr, sizeof(rep_etypestr), reply); +- else +- rep_etypestr[0] = 0; + + unparse_and_limit(ctx, cprinc, &cname); + logcname = (cname != NULL) ? cname : ""; +@@ -151,10 +148,14 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from, + name (useful), and doesn't log ktypestr (probably not + important). */ + if (errcode != KRB5KDC_ERR_SERVER_NOMATCH) { ++ ktypestr = ktypes2str(request->ktype, request->nktypes); ++ rep_etypestr = rep_etypes2str(reply); + krb5_klog_syslog(LOG_INFO, _("TGS_REQ (%s) %s: %s: authtime %u, %s%s " + "%s for %s%s%s"), +- ktypestr, fromstring, status, (unsigned int)authtime, +- rep_etypestr, !errcode ? "," : "", logcname, logsname, ++ ktypestr ? ktypestr : "", fromstring, status, ++ (unsigned int)authtime, ++ rep_etypestr ? rep_etypestr : "", ++ !errcode ? "," : "", logcname, logsname, + errcode ? ", " : "", errcode ? emsg : ""); + if (isflagset(c_flags, KRB5_KDB_FLAG_PROTOCOL_TRANSITION)) + krb5_klog_syslog(LOG_INFO, +@@ -171,9 +172,8 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from, + fromstring, status, (unsigned int)authtime, + logcname, logsname, logaltcname); + +- /* OpenSolaris: audit_krb5kdc_tgs_req(...) or +- audit_krb5kdc_tgs_req_2ndtktmm(...) */ +- ++ free(rep_etypestr); ++ free(ktypestr); + krb5_free_unparsed_name(ctx, cname); + krb5_free_unparsed_name(ctx, sname); + krb5_free_unparsed_name(ctx, altcname); +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index 0155c28c6..f5c581c82 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1043,84 +1043,87 @@ void limit_string(char *name) + return; + } + +-/* +- * L10_2 = log10(2**x), rounded up; log10(2) ~= 0.301. +- */ +-#define L10_2(x) ((int)(((x * 301) + 999) / 1000)) +- +-/* +- * Max length of sprintf("%ld") for an int of type T; includes leading +- * minus sign and terminating NUL. +- */ +-#define D_LEN(t) (L10_2(sizeof(t) * CHAR_BIT) + 2) +- +-void +-ktypes2str(char *s, size_t len, int nktypes, krb5_enctype *ktype) ++/* Wrapper of krb5_enctype_to_name() to include the PKINIT types. */ ++static krb5_error_code ++enctype_name(krb5_enctype ktype, char *buf, size_t buflen) + { +- int i; +- char stmp[D_LEN(krb5_enctype) + 1]; +- char *p; ++ char *name; + +- if (nktypes < 0 +- || len < (sizeof(" etypes {...}") + D_LEN(int))) { +- *s = '\0'; +- return; +- } ++ if (buflen == 0) ++ return EINVAL; ++ *buf = '\0'; /* ensure these are always valid C-strings */ + +- snprintf(s, len, "%d etypes {", nktypes); +- for (i = 0; i < nktypes; i++) { +- snprintf(stmp, sizeof(stmp), "%s%ld", i ? " " : "", (long)ktype[i]); +- if (strlen(s) + strlen(stmp) + sizeof("}") > len) +- break; +- strlcat(s, stmp, len); +- } +- if (i < nktypes) { +- /* +- * We broke out of the loop. Try to truncate the list. +- */ +- p = s + strlen(s); +- while (p - s + sizeof("...}") > len) { +- while (p > s && *p != ' ' && *p != '{') +- *p-- = '\0'; +- if (p > s && *p == ' ') { +- *p-- = '\0'; +- continue; +- } +- } +- strlcat(s, "...", len); +- } +- strlcat(s, "}", len); +- return; ++ /* rfc4556 recommends that clients wishing to indicate support for these ++ * pkinit algorithms include them in the etype field of the AS-REQ. */ ++ if (ktype == ENCTYPE_DSA_SHA1_CMS) ++ name = "id-dsa-with-sha1-CmsOID"; ++ else if (ktype == ENCTYPE_MD5_RSA_CMS) ++ name = "md5WithRSAEncryption-CmsOID"; ++ else if (ktype == ENCTYPE_SHA1_RSA_CMS) ++ name = "sha-1WithRSAEncryption-CmsOID"; ++ else if (ktype == ENCTYPE_RC2_CBC_ENV) ++ name = "rc2-cbc-EnvOID"; ++ else if (ktype == ENCTYPE_RSA_ENV) ++ name = "rsaEncryption-EnvOID"; ++ else if (ktype == ENCTYPE_RSA_ES_OAEP_ENV) ++ name = "id-RSAES-OAEP-EnvOID"; ++ else if (ktype == ENCTYPE_DES3_CBC_ENV) ++ name = "des-ede3-cbc-EnvOID"; ++ else ++ return krb5_enctype_to_name(ktype, FALSE, buf, buflen); ++ ++ if (strlcpy(name, buf, buflen) >= buflen) ++ return ENOMEM; ++ return 0; + } + +-void +-rep_etypes2str(char *s, size_t len, krb5_kdc_rep *rep) ++char * ++ktypes2str(krb5_enctype *ktype, int nktypes) + { +- char stmp[sizeof("ses=") + D_LEN(krb5_enctype)]; ++ struct k5buf buf; ++ int i; ++ char name[64]; + +- if (len < (3 * D_LEN(krb5_enctype) +- + sizeof("etypes {rep= tkt= ses=}"))) { +- *s = '\0'; +- return; ++ if (nktypes < 0) ++ return NULL; ++ ++ k5_buf_init_dynamic(&buf); ++ k5_buf_add_fmt(&buf, "%d etypes {", nktypes); ++ for (i = 0; i < nktypes; i++) { ++ enctype_name(ktype[i], name, sizeof(name)); ++ k5_buf_add_fmt(&buf, "%s%s(%ld)", i ? ", " : "", name, (long)ktype[i]); + } ++ k5_buf_add(&buf, "}"); ++ return buf.data; ++} + +- snprintf(s, len, "etypes {rep=%ld", (long)rep->enc_part.enctype); ++char * ++rep_etypes2str(krb5_kdc_rep *rep) ++{ ++ struct k5buf buf; ++ char name[64]; ++ krb5_enctype etype; ++ ++ k5_buf_init_dynamic(&buf); ++ k5_buf_add(&buf, "etypes {rep="); ++ enctype_name(rep->enc_part.enctype, name, sizeof(name)); ++ k5_buf_add_fmt(&buf, "%s(%ld)", name, (long)rep->enc_part.enctype); + + if (rep->ticket != NULL) { +- snprintf(stmp, sizeof(stmp), +- " tkt=%ld", (long)rep->ticket->enc_part.enctype); +- strlcat(s, stmp, len); ++ etype = rep->ticket->enc_part.enctype; ++ enctype_name(etype, name, sizeof(name)); ++ k5_buf_add_fmt(&buf, ", tkt=%s(%ld)", name, (long)etype); + } + +- if (rep->ticket != NULL +- && rep->ticket->enc_part2 != NULL +- && rep->ticket->enc_part2->session != NULL) { +- snprintf(stmp, sizeof(stmp), " ses=%ld", +- (long)rep->ticket->enc_part2->session->enctype); +- strlcat(s, stmp, len); ++ if (rep->ticket != NULL && rep->ticket->enc_part2 != NULL && ++ rep->ticket->enc_part2->session != NULL) { ++ etype = rep->ticket->enc_part2->session->enctype; ++ enctype_name(etype, name, sizeof(name)); ++ k5_buf_add_fmt(&buf, ", ses=%s(%ld)", name, (long)etype); + } +- strlcat(s, "}", len); +- return; ++ ++ k5_buf_add(&buf, "}"); ++ return buf.data; + } + + static krb5_error_code +diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h +index 6ec645fc3..25077cbf5 100644 +--- a/src/kdc/kdc_util.h ++++ b/src/kdc/kdc_util.h +@@ -110,11 +110,9 @@ select_session_keytype (kdc_realm_t *kdc_active_realm, + + void limit_string (char *name); + +-void +-ktypes2str(char *s, size_t len, int nktypes, krb5_enctype *ktype); ++char *ktypes2str(krb5_enctype *ktype, int nktypes); + +-void +-rep_etypes2str(char *s, size_t len, krb5_kdc_rep *rep); ++char *rep_etypes2str(krb5_kdc_rep *rep); + + /* authind.c */ + krb5_boolean diff --git a/Mark-deprecated-enctypes-when-used.patch b/Mark-deprecated-enctypes-when-used.patch new file mode 100644 index 0000000..cb74384 --- /dev/null +++ b/Mark-deprecated-enctypes-when-used.patch @@ -0,0 +1,250 @@ +From 1d1db003481768092410dc36a41e240c48a136e0 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 10 Jan 2019 16:34:54 -0500 +Subject: [PATCH] Mark deprecated enctypes when used + +Preface ETYPE_DEPRECATED enctypes with "DEPRECATED:" in klist output, +KDC logs, and kadmin interactions. Also complain in krb5kdc when the +stash file has a deprecated enctype or a deprecated enctype is +requested with -k. + +ticket: 8773 (new) +(cherry picked from commit 8d8e68283b599e680f9fe45eff8af397e827bd6c) +--- + src/clients/klist/klist.c | 14 ++++++++++---- + src/kadmin/cli/kadmin.c | 6 +++++- + src/kdc/kdc_util.c | 9 +++++++++ + src/kdc/main.c | 19 +++++++++++++++++++ + src/tests/gssapi/t_enctypes.py | 15 +++++++++------ + src/tests/t_keyrollover.py | 8 +++++--- + src/tests/t_sesskeynego.py | 4 ++-- + 7 files changed, 59 insertions(+), 16 deletions(-) + +diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c +index 70adb54e8..8c307151a 100644 +--- a/src/clients/klist/klist.c ++++ b/src/clients/klist/klist.c +@@ -571,11 +571,17 @@ static char * + etype_string(krb5_enctype enctype) + { + static char buf[100]; +- krb5_error_code ret; ++ char *bp = buf; ++ size_t deplen, buflen = sizeof(buf); + +- ret = krb5_enctype_to_name(enctype, FALSE, buf, sizeof(buf)); +- if (ret) +- snprintf(buf, sizeof(buf), "etype %d", enctype); ++ if (krb5int_c_deprecated_enctype(enctype)) { ++ deplen = strlcpy(bp, "DEPRECATED:", buflen); ++ buflen -= deplen; ++ bp += deplen; ++ } ++ ++ if (krb5_enctype_to_name(enctype, FALSE, bp, buflen)) ++ snprintf(bp, buflen, "etype %d", enctype); + return buf; + } + +diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c +index ed581ee79..cc74921bf 100644 +--- a/src/kadmin/cli/kadmin.c ++++ b/src/kadmin/cli/kadmin.c +@@ -1451,12 +1451,16 @@ kadmin_getprinc(int argc, char *argv[]) + for (i = 0; i < dprinc.n_key_data; i++) { + krb5_key_data *key_data = &dprinc.key_data[i]; + char enctype[BUFSIZ], salttype[BUFSIZ]; ++ char *deprecated = ""; + + if (krb5_enctype_to_name(key_data->key_data_type[0], FALSE, + enctype, sizeof(enctype))) + snprintf(enctype, sizeof(enctype), _(""), + key_data->key_data_type[0]); +- printf("Key: vno %d, %s", key_data->key_data_kvno, enctype); ++ if (krb5int_c_deprecated_enctype(key_data->key_data_type[0])) ++ deprecated = "DEPRECATED:"; ++ printf("Key: vno %d, %s%s", key_data->key_data_kvno, deprecated, ++ enctype); + if (key_data->key_data_ver > 1 && + key_data->key_data_type[1] != KRB5_KDB_SALTTYPE_NORMAL) { + if (krb5_salttype_to_string(key_data->key_data_type[1], +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index f5c581c82..96c88edc1 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1048,11 +1048,20 @@ static krb5_error_code + enctype_name(krb5_enctype ktype, char *buf, size_t buflen) + { + char *name; ++ size_t len; + + if (buflen == 0) + return EINVAL; + *buf = '\0'; /* ensure these are always valid C-strings */ + ++ if (krb5int_c_deprecated_enctype(ktype)) { ++ len = strlcpy(buf, "DEPRECATED:", buflen); ++ if (len >= buflen) ++ return ENOMEM; ++ buflen -= len; ++ buf += len; ++ } ++ + /* rfc4556 recommends that clients wishing to indicate support for these + * pkinit algorithms include them in the etype field of the AS-REQ. */ + if (ktype == ENCTYPE_DSA_SHA1_CMS) +diff --git a/src/kdc/main.c b/src/kdc/main.c +index 663fd6303..60092a0df 100644 +--- a/src/kdc/main.c ++++ b/src/kdc/main.c +@@ -210,12 +210,23 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm, + char *svalue = NULL; + const char *hierarchy[4]; + krb5_kvno mkvno = IGNORE_VNO; ++ char ename[32]; + + memset(rdp, 0, sizeof(kdc_realm_t)); + if (!realm) { + kret = EINVAL; + goto whoops; + } ++ ++ if (def_enctype != ENCTYPE_UNKNOWN && ++ krb5int_c_deprecated_enctype(def_enctype)) { ++ if (krb5_enctype_to_name(def_enctype, FALSE, ename, sizeof(ename))) ++ ename[0] = '\0'; ++ fprintf(stderr, ++ _("Requested master password enctype %s in %s is DEPRECATED!"), ++ ename, realm); ++ } ++ + hierarchy[0] = KRB5_CONF_REALMS; + hierarchy[1] = realm; + hierarchy[3] = NULL; +@@ -370,6 +381,14 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm, + goto whoops; + } + ++ if (krb5int_c_deprecated_enctype(rdp->realm_mkey.enctype)) { ++ if (krb5_enctype_to_name(rdp->realm_mkey.enctype, FALSE, ename, ++ sizeof(ename))) ++ ename[0] = '\0'; ++ fprintf(stderr, _("Stash file %s uses DEPRECATED enctype %s!"), ++ rdp->realm_stash, ename); ++ } ++ + if ((kret = krb5_db_fetch_mkey_list(rdp->realm_context, rdp->realm_mprinc, + &rdp->realm_mkey))) { + kdc_err(rdp->realm_context, kret, +diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py +index 5d9f80e04..ca3d32d21 100755 +--- a/src/tests/gssapi/t_enctypes.py ++++ b/src/tests/gssapi/t_enctypes.py +@@ -9,8 +9,11 @@ from k5test import * + aes256 = 'aes256-cts-hmac-sha1-96' + aes128 = 'aes128-cts-hmac-sha1-96' + des3 = 'des3-cbc-sha1' ++d_des3 = 'DEPRECATED:des3-cbc-sha1' + des3raw = 'des3-cbc-raw' ++d_des3raw = 'DEPRECATED:des3-cbc-raw' + rc4 = 'arcfour-hmac' ++d_rc4 = 'DEPRECATED:arcfour-hmac' + + # These tests make assumptions about the default enctype lists, so set + # them explicitly rather than relying on the library defaults. +@@ -92,7 +95,7 @@ test_err('acc aes128', None, 'aes128-cts', + # no acceptor subkey will be generated because we can't upgrade to a + # CFX enctype. + test('init des3', 'des3', None, +- tktenc=aes256, tktsession=des3, ++ tktenc=aes256, tktsession=d_des3, + proto='rfc1964', isubkey=des3raw, asubkey=None) + + # Force the ticket session key to be rc4, so we can test some subkey +@@ -103,7 +106,7 @@ realm.run([kadminl, 'setstr', realm.host_princ, 'session_enctypes', 'rc4']) + # [aes256 aes128 des3] and the acceptor should upgrade to an aes256 + # subkey. + test('upgrade noargs', None, None, +- tktenc=aes256, tktsession=rc4, ++ tktenc=aes256, tktsession=d_rc4, + proto='cfx', isubkey=rc4, asubkey=aes256) + + # If the initiator won't permit rc4 as a session key, it won't be able +@@ -113,14 +116,14 @@ test_err('upgrade init aes', 'aes', None, 'no support for encryption type') + # If the initiator permits rc4 but prefers aes128, it will send an + # upgrade list of [aes128] and the acceptor will upgrade to aes128. + test('upgrade init aes128+rc4', 'aes128-cts rc4', None, +- tktenc=aes256, tktsession=rc4, ++ tktenc=aes256, tktsession=d_rc4, + proto='cfx', isubkey=rc4, asubkey=aes128) + + # If the initiator permits rc4 but prefers des3, it will send an + # upgrade list of [des3], but the acceptor won't generate a subkey + # because des3 isn't a CFX enctype. + test('upgrade init des3+rc4', 'des3 rc4', None, +- tktenc=aes256, tktsession=rc4, ++ tktenc=aes256, tktsession=d_rc4, + proto='rfc1964', isubkey=rc4, asubkey=None) + + # If the acceptor permits only aes128, subkey negotiation will fail +@@ -134,14 +137,14 @@ test_err('upgrade acc aes128', None, 'aes128-cts', + # If the acceptor permits rc4 but prefers aes128, it will negotiate an + # upgrade to aes128. + test('upgrade acc aes128 rc4', None, 'aes128-cts rc4', +- tktenc=aes256, tktsession=rc4, ++ tktenc=aes256, tktsession=d_rc4, + proto='cfx', isubkey=rc4, asubkey=aes128) + + # In this test, the initiator and acceptor each prefer an AES enctype + # to rc4, but they can't agree on which one, so no subkey is + # generated. + test('upgrade mismatch', 'aes128-cts rc4', 'aes256-cts rc4', +- tktenc=aes256, tktsession=rc4, ++ tktenc=aes256, tktsession=d_rc4, + proto='rfc1964', isubkey=rc4, asubkey=None) + + success('gss_krb5_set_allowable_enctypes tests') +diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py +index 7c8d828f0..4af6804f2 100755 +--- a/src/tests/t_keyrollover.py ++++ b/src/tests/t_keyrollover.py +@@ -22,8 +22,9 @@ realm.run([kvno, princ1]) + realm.run([kadminl, 'purgekeys', realm.krbtgt_princ]) + # Make sure an old TGT fails after purging old TGS key. + realm.run([kvno, princ2], expected_code=1) +-msg = 'krbtgt/%s@%s\n\tEtype (skey, tkt): des-cbc-crc, des-cbc-crc' % \ +- (realm.realm, realm.realm) ++ddes = "DEPRECATED:des-cbc-crc" ++msg = 'krbtgt/%s@%s\n\tEtype (skey, tkt): %s, %s' % \ ++ (realm.realm, realm.realm, ddes, ddes) + realm.run([klist, '-e'], expected_msg=msg) + + # Check that new key actually works. +@@ -48,7 +49,8 @@ realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', 'aes256-cts', + realm.krbtgt_princ]) + realm.run([kadminl, 'modprinc', '-kvno', '1', realm.krbtgt_princ]) + out = realm.run([kadminl, 'getprinc', realm.krbtgt_princ]) +-if 'vno 1, aes256' not in out or 'vno 1, des3' not in out: ++if 'vno 1, aes256-cts' not in out or \ ++ 'vno 1, DEPRECATED:des3-cbc-sha1' not in out: + fail('keyrollover: setup for TGS enctype test failed') + # Now present the DES3 ticket to the KDC and make sure it's rejected. + realm.run([kvno, realm.host_princ], expected_code=1) +diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py +index 448092387..da02f224a 100755 +--- a/src/tests/t_sesskeynego.py ++++ b/src/tests/t_sesskeynego.py +@@ -62,11 +62,11 @@ test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96') + # 3b: Negotiate rc4-hmac session key when principal only has aes256 long-term. + realm.run([kadminl, 'setstr', 'server', 'session_enctypes', + 'rc4-hmac,aes128-cts,aes256-cts']) +-test_kvno(realm, 'arcfour-hmac', 'aes256-cts-hmac-sha1-96') ++test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') + + # 3c: Test des-cbc-crc default assumption. + realm.run([kadminl, 'delstr', 'server', 'session_enctypes']) +-test_kvno(realm, 'des-cbc-crc', 'aes256-cts-hmac-sha1-96') ++test_kvno(realm, 'DEPRECATED:des-cbc-crc', 'aes256-cts-hmac-sha1-96') + realm.stop() + + # Last go: test that we can disable the des-cbc-crc assumption diff --git a/krb5.spec b/krb5.spec index 8da9d25..5ed1f33 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 2 +Release: 3%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -65,6 +65,12 @@ Patch89: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch Patch90: Add-tests-for-KCM-ccache-type.patch Patch92: Address-some-optimized-out-memset-calls.patch Patch93: Use-openssl-s-PRNG-in-FIPS-mode.patch +Patch94: Avoid-allocating-a-register-in-zap-assembly.patch +Patch95: In-rd_req_dec-always-log-non-permitted-enctypes.patch +Patch96: In-kpropd-debug-log-proper-ticket-enctype-names.patch +Patch97: Add-function-and-enctype-flag-for-deprecations.patch +Patch98: Make-etype-names-in-KDC-logs-human-readable.patch +Patch99: Mark-deprecated-enctypes-when-used.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -712,6 +718,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jan 17 2019 Robbie Harwood - 1.17-3 +- enctype logging and explicit_bzero() + * Tue Jan 08 2019 Robbie Harwood - 1.17-2 - New upstream version (1.17) From acad58ce13870b07db1c3911b0a88075ae0caa2b Mon Sep 17 00:00:00 2001 From: Igor Gnatenko Date: Mon, 28 Jan 2019 20:17:50 +0100 Subject: [PATCH 087/304] Remove obsolete Group tag References: https://fedoraproject.org/wiki/Changes/Remove_Group_Tag --- krb5.spec | 8 -------- 1 file changed, 8 deletions(-) diff --git a/krb5.spec b/krb5.spec index 5ed1f33..7616a62 100644 --- a/krb5.spec +++ b/krb5.spec @@ -74,7 +74,6 @@ Patch99: Mark-deprecated-enctypes-when-used.patch License: MIT URL: http://web.mit.edu/kerberos/www/ -Group: System Environment/Libraries BuildRequires: autoconf, bison, cmake, flex, gawk, gettext, pkgconfig, sed BuildRequires: gcc BuildRequires: libcom_err-devel, libedit-devel, libss-devel @@ -138,7 +137,6 @@ practice of sending passwords over the network in unencrypted form. %package devel Summary: Development files needed to compile Kerberos 5 programs -Group: Development/Libraries Requires: %{name}-libs%{?_isa} = %{version}-%{release} Requires: libkadm5%{?_isa} = %{version}-%{release} Requires: libcom_err-devel @@ -154,7 +152,6 @@ to install this package. %package libs Summary: The non-admin shared libraries used by Kerberos 5 -Group: System Environment/Libraries Requires: coreutils, gawk, grep, sed Requires: keyutils-libs >= 1.5.8 Requires: /etc/crypto-policies/back-ends/krb5.config @@ -165,7 +162,6 @@ contains the shared libraries needed by Kerberos 5. If you are using Kerberos, you need to install this package. %package server -Group: System Environment/Daemons Summary: The KDC and related programs for Kerberos 5 Requires: %{name}-libs%{?_isa} = %{version}-%{release} Requires(post): systemd-units @@ -197,7 +193,6 @@ you need to install this package (in other words, most people should NOT install this package). %package server-ldap -Group: System Environment/Daemons Summary: The LDAP storage plugin for the Kerberos 5 KDC Requires: %{name}-server%{?_isa} = %{version}-%{release} Requires: %{name}-libs%{?_isa} = %{version}-%{release} @@ -221,7 +216,6 @@ realm, you need to install this package. %package workstation Summary: Kerberos 5 programs for use on workstations -Group: System Environment/Base Requires: %{name}-libs%{?_isa} = %{version}-%{release} Requires: libkadm5%{?_isa} = %{version}-%{release} @@ -233,7 +227,6 @@ installed on every workstation. %package pkinit Summary: The PKINIT module for Kerberos 5 -Group: System Environment/Libraries Requires: %{name}-libs%{?_isa} = %{version}-%{release} Obsoletes: krb5-pkinit-openssl < %{version}-%{release} Provides: krb5-pkinit-openssl = %{version}-%{release} @@ -246,7 +239,6 @@ certificate. %package -n libkadm5 Summary: Kerberos 5 Administrative libraries -Group: System Environment/Base Requires: %{name}-libs%{?_isa} = %{version}-%{release} %description -n libkadm5 From f4175006673bafd67aa6e8a7fdebe778eea69399 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 1 Feb 2019 06:00:21 +0000 Subject: [PATCH 088/304] - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 7616a62..1cb1639 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 3%{?dist} +Release: 4%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -710,6 +710,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Feb 01 2019 Fedora Release Engineering - 1.17-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild + * Thu Jan 17 2019 Robbie Harwood - 1.17-3 - enctype logging and explicit_bzero() From ae3b43243915b433fbaf8c9a1ad2343d3e9a71a3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 1 Feb 2019 16:11:20 -0500 Subject: [PATCH 089/304] Update FIPS blocking for RC4 --- ...on-and-enctype-flag-for-deprecations.patch | 2 +- Add-tests-for-KCM-ccache-type.patch | 2 +- Address-some-optimized-out-memset-calls.patch | 2 +- ...llocating-a-register-in-zap-assembly.patch | 2 +- Become-FIPS-aware.patch | 45 ++++++++++++++----- ...-plaintext-fallback-for-RC4-usages-a.patch | 3 +- ...ebug-log-proper-ticket-enctype-names.patch | 2 +- ...ec-always-log-non-permitted-enctypes.patch | 2 +- ...ype-names-in-KDC-logs-human-readable.patch | 2 +- Mark-deprecated-enctypes-when-used.patch | 2 +- Use-openssl-s-PRNG-in-FIPS-mode.patch | 2 +- krb5.spec | 5 ++- 12 files changed, 48 insertions(+), 23 deletions(-) diff --git a/Add-function-and-enctype-flag-for-deprecations.patch b/Add-function-and-enctype-flag-for-deprecations.patch index ee1628b..b4462c5 100644 --- a/Add-function-and-enctype-flag-for-deprecations.patch +++ b/Add-function-and-enctype-flag-for-deprecations.patch @@ -1,4 +1,4 @@ -From e0c8eb1bf93e0591e363e414378c70c255a6e6b6 Mon Sep 17 00:00:00 2001 +From 71c582c1490d128ed0ee1c817ecb15ed425aca46 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 16:16:57 -0500 Subject: [PATCH] Add function and enctype flag for deprecations diff --git a/Add-tests-for-KCM-ccache-type.patch b/Add-tests-for-KCM-ccache-type.patch index fac526f..3cc9e70 100644 --- a/Add-tests-for-KCM-ccache-type.patch +++ b/Add-tests-for-KCM-ccache-type.patch @@ -1,4 +1,4 @@ -From 528f9ef3842ef5caba0990568e3cd7104e640c52 Mon Sep 17 00:00:00 2001 +From 5ecbe8d3ab4f53c0923a0442273bf18a9ff04fd5 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Nov 2018 00:27:35 -0500 Subject: [PATCH] Add tests for KCM ccache type diff --git a/Address-some-optimized-out-memset-calls.patch b/Address-some-optimized-out-memset-calls.patch index 099f238..6e260ad 100644 --- a/Address-some-optimized-out-memset-calls.patch +++ b/Address-some-optimized-out-memset-calls.patch @@ -1,4 +1,4 @@ -From 028ed9cee24159b25ecb8f62e8d171b850ed0a41 Mon Sep 17 00:00:00 2001 +From 1dfff7202448a950c9133cdfe43d650092d930fd Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 30 Dec 2018 16:40:28 -0500 Subject: [PATCH] Address some optimized-out memset() calls diff --git a/Avoid-allocating-a-register-in-zap-assembly.patch b/Avoid-allocating-a-register-in-zap-assembly.patch index 71677ca..6673530 100644 --- a/Avoid-allocating-a-register-in-zap-assembly.patch +++ b/Avoid-allocating-a-register-in-zap-assembly.patch @@ -1,4 +1,4 @@ -From 77b1ce65e7777395cee5a79e4068ff4340fcc680 Mon Sep 17 00:00:00 2001 +From 623414ccbb47eb6c334d838aa9023f16f0df5322 Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Thu, 3 Jan 2019 17:19:32 +0100 Subject: [PATCH] Avoid allocating a register in zap() assembly diff --git a/Become-FIPS-aware.patch b/Become-FIPS-aware.patch index 9c4bb5f..4011e25 100644 --- a/Become-FIPS-aware.patch +++ b/Become-FIPS-aware.patch @@ -1,4 +1,4 @@ -From ebcee0c8dc5f3055597e0b574d98cbe65f55319e Mon Sep 17 00:00:00 2001 +From d8db85101c535a32937136118561aeb5646d2136 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] Become FIPS-aware @@ -13,15 +13,14 @@ This will slow down some calls slightly (FIPS_mode() takes multiple locks), but not for any crypto we care about - AES is fine, for instance. -(cherry picked from commit ee05742839df659d2136b37f91d0a888de2b5e26) -(cherry picked from commit b38ed4d97152f1dce126235935d30e549ead77b3) +(cherry picked from commit ce06474e3b12430480374f923c25bae9581fb146) --- - src/lib/crypto/openssl/enc_provider/camellia.c | 6 ++++++ - src/lib/crypto/openssl/enc_provider/des.c | 9 +++++++++ - src/lib/crypto/openssl/enc_provider/rc4.c | 3 +++ - src/lib/crypto/openssl/hash_provider/hash_evp.c | 4 ++++ - src/lib/crypto/openssl/hmac.c | 6 +++++- - 5 files changed, 27 insertions(+), 1 deletion(-) + src/lib/crypto/openssl/enc_provider/camellia.c | 6 ++++++ + src/lib/crypto/openssl/enc_provider/des.c | 9 +++++++++ + src/lib/crypto/openssl/enc_provider/rc4.c | 13 ++++++++++++- + src/lib/crypto/openssl/hash_provider/hash_evp.c | 4 ++++ + src/lib/crypto/openssl/hmac.c | 6 +++++- + 5 files changed, 36 insertions(+), 2 deletions(-) diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c index 2da691329..f79679a0b 100644 @@ -82,10 +81,34 @@ index a662db512..7d17d287e 100644 if (ret != 0) return ret; diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c -index 7f3c086ed..ef8205535 100644 +index 7f3c086ed..a3f2a7442 100644 --- a/src/lib/crypto/openssl/enc_provider/rc4.c +++ b/src/lib/crypto/openssl/enc_provider/rc4.c -@@ -125,6 +125,9 @@ k5_arcfour_init_state(const krb5_keyblock *key, +@@ -66,6 +66,9 @@ k5_arcfour_docrypt(krb5_key key,const krb5_data *state, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx = NULL; + struct arcfour_state *arcstate; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + arcstate = (state != NULL) ? (struct arcfour_state *) state->data : NULL; + if (arcstate != NULL) { + ctx = arcstate->ctx; +@@ -113,7 +116,12 @@ k5_arcfour_docrypt(krb5_key key,const krb5_data *state, krb5_crypto_iov *data, + static void + k5_arcfour_free_state(krb5_data *state) + { +- struct arcfour_state *arcstate = (struct arcfour_state *) state->data; ++ struct arcfour_state *arcstate; ++ ++ if (FIPS_mode()) ++ return; ++ ++ arcstate = (struct arcfour_state *) state->data; + + EVP_CIPHER_CTX_free(arcstate->ctx); + free(arcstate); +@@ -125,6 +133,9 @@ k5_arcfour_init_state(const krb5_keyblock *key, { struct arcfour_state *arcstate; diff --git a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch b/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch index b34aed1..a24904f 100644 --- a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch +++ b/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch @@ -1,9 +1,8 @@ -From 1caf8246184211e06708e01a106632e26d9a84a8 Mon Sep 17 00:00:00 2001 +From e44494c87ea3086b824e972df5566cedf5ad7e15 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 31 Jul 2018 13:47:26 -0400 Subject: [PATCH] In FIPS mode, add plaintext fallback for RC4 usages and taint -(cherry picked from commit a327e3bf5b992ac829c7b2d3317fb7d93b1c88ef) --- src/lib/krad/attr.c | 45 +++++++++++++++++++++++++++++----------- src/lib/krad/attrset.c | 5 +++-- diff --git a/In-kpropd-debug-log-proper-ticket-enctype-names.patch b/In-kpropd-debug-log-proper-ticket-enctype-names.patch index 6090842..0df245e 100644 --- a/In-kpropd-debug-log-proper-ticket-enctype-names.patch +++ b/In-kpropd-debug-log-proper-ticket-enctype-names.patch @@ -1,4 +1,4 @@ -From d2990ce023e000e1628007a5d24aad5a5abdb0a3 Mon Sep 17 00:00:00 2001 +From 5331faee19a97508f1089f113ecaee852e73c83c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 13:41:16 -0500 Subject: [PATCH] In kpropd, debug-log proper ticket enctype names diff --git a/In-rd_req_dec-always-log-non-permitted-enctypes.patch b/In-rd_req_dec-always-log-non-permitted-enctypes.patch index 787ce20..e84e0d0 100644 --- a/In-rd_req_dec-always-log-non-permitted-enctypes.patch +++ b/In-rd_req_dec-always-log-non-permitted-enctypes.patch @@ -1,4 +1,4 @@ -From e595f7a4c1c95aadcb1bc3ea2bb88fce66fb826b Mon Sep 17 00:00:00 2001 +From 8ca2006679539a7675c94148ff338a178d7689eb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Jan 2019 17:14:42 -0500 Subject: [PATCH] In rd_req_dec, always log non-permitted enctypes diff --git a/Make-etype-names-in-KDC-logs-human-readable.patch b/Make-etype-names-in-KDC-logs-human-readable.patch index 2761ba3..f596034 100644 --- a/Make-etype-names-in-KDC-logs-human-readable.patch +++ b/Make-etype-names-in-KDC-logs-human-readable.patch @@ -1,4 +1,4 @@ -From b999ade3996817ccb9c9362e4c06dd236e4a854b Mon Sep 17 00:00:00 2001 +From 809ecc10090688d78fc45d611c58db15aae053ad Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 8 Jan 2019 17:42:35 -0500 Subject: [PATCH] Make etype names in KDC logs human-readable diff --git a/Mark-deprecated-enctypes-when-used.patch b/Mark-deprecated-enctypes-when-used.patch index cb74384..c797d05 100644 --- a/Mark-deprecated-enctypes-when-used.patch +++ b/Mark-deprecated-enctypes-when-used.patch @@ -1,4 +1,4 @@ -From 1d1db003481768092410dc36a41e240c48a136e0 Mon Sep 17 00:00:00 2001 +From 2af719291eb4344ee9e87b883390433539d59ada Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 10 Jan 2019 16:34:54 -0500 Subject: [PATCH] Mark deprecated enctypes when used diff --git a/Use-openssl-s-PRNG-in-FIPS-mode.patch b/Use-openssl-s-PRNG-in-FIPS-mode.patch index 29cceff..f78744c 100644 --- a/Use-openssl-s-PRNG-in-FIPS-mode.patch +++ b/Use-openssl-s-PRNG-in-FIPS-mode.patch @@ -1,4 +1,4 @@ -From a81c558f4fc75ef988a283729fd9c7e79e9df70f Mon Sep 17 00:00:00 2001 +From 31277d79675a76612015ea00d420b41b9a232d5a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 4 Jan 2019 17:00:15 -0500 Subject: [PATCH] Use openssl's PRNG in FIPS mode diff --git a/krb5.spec b/krb5.spec index 1cb1639..5234207 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 4%{?dist} +Release: 5%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -710,6 +710,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Feb 01 2019 Robbie Harwood - 1.17-5 +- Update FIPS blocking for RC4 + * Fri Feb 01 2019 Fedora Release Engineering - 1.17-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild From bf081fdccdfb1bc621f58ac8fa2b0bc6a3b4ce59 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 25 Feb 2019 15:24:36 -0500 Subject: [PATCH 090/304] Fix memory leak in 'none' replay cache type Silence a coverity warning while we're here. --- ...emory-leak-in-none-replay-cache-type.patch | 33 +++++++++++++++++++ Properly-size-ifdef-in-k5_cccol_lock.patch | 33 +++++++++++++++++++ krb5.spec | 8 ++++- 3 files changed, 73 insertions(+), 1 deletion(-) create mode 100644 Fix-memory-leak-in-none-replay-cache-type.patch create mode 100644 Properly-size-ifdef-in-k5_cccol_lock.patch diff --git a/Fix-memory-leak-in-none-replay-cache-type.patch b/Fix-memory-leak-in-none-replay-cache-type.patch new file mode 100644 index 0000000..c093c4a --- /dev/null +++ b/Fix-memory-leak-in-none-replay-cache-type.patch @@ -0,0 +1,33 @@ +From ff79351c4755d6df7c3245274708454311c25731 Mon Sep 17 00:00:00 2001 +From: Corene Casper +Date: Sat, 16 Feb 2019 00:49:26 -0500 +Subject: [PATCH] Fix memory leak in 'none' replay cache type + +Commit 0f06098e2ab419d02e89a1ca6bc9f2828f6bdb1e fixed part of a memory +leak in the 'none' replay cache type by freeing the outer container, +but we also need to free the mutex. + +[ghudson@mit.edu: wrote commit message] + +ticket: 8783 +tags: pullup +target_version: 1.17-next +target_version: 1.16-next + +(cherry picked from commit af2a3115cb8feb5174151b4b40223ae45aa9db17) +--- + src/lib/krb5/rcache/rc_none.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/src/lib/krb5/rcache/rc_none.c b/src/lib/krb5/rcache/rc_none.c +index e30aed09f..0b2274df7 100644 +--- a/src/lib/krb5/rcache/rc_none.c ++++ b/src/lib/krb5/rcache/rc_none.c +@@ -50,6 +50,7 @@ krb5_rc_none_noargs(krb5_context ctx, krb5_rcache rc) + static krb5_error_code KRB5_CALLCONV + krb5_rc_none_close(krb5_context ctx, krb5_rcache rc) + { ++ k5_mutex_destroy(&rc->lock); + free (rc); + return 0; + } diff --git a/Properly-size-ifdef-in-k5_cccol_lock.patch b/Properly-size-ifdef-in-k5_cccol_lock.patch new file mode 100644 index 0000000..5e6bac8 --- /dev/null +++ b/Properly-size-ifdef-in-k5_cccol_lock.patch @@ -0,0 +1,33 @@ +From e2a0e04fb3be9297a8c532dd35a7c1045cae88f4 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 14 Feb 2019 11:50:35 -0500 +Subject: [PATCH] Properly size #ifdef in k5_cccol_lock() + +The cleanup code only could get executed in the USE_CCAPI_V3 case, so +move it inside that block. Reported by Coverity. + +(cherry picked from commit 444a15f9cf82b9a6c1bca3f20307f82fee91c228) +--- + src/lib/krb5/ccache/ccbase.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/lib/krb5/ccache/ccbase.c b/src/lib/krb5/ccache/ccbase.c +index 8198f2b9b..2702bef69 100644 +--- a/src/lib/krb5/ccache/ccbase.c ++++ b/src/lib/krb5/ccache/ccbase.c +@@ -511,7 +511,6 @@ krb5_cccol_lock(krb5_context context) + #endif + #ifdef USE_CCAPI_V3 + ret = krb5_stdccv3_context_lock(context); +-#endif + if (ret) { + k5_cc_mutex_unlock(context, &krb5int_mcc_mutex); + k5_cc_mutex_unlock(context, &krb5int_cc_file_mutex); +@@ -519,6 +518,7 @@ krb5_cccol_lock(krb5_context context) + k5_cc_mutex_unlock(context, &cccol_lock); + return ret; + } ++#endif + k5_mutex_unlock(&cc_typelist_lock); + return ret; + } diff --git a/krb5.spec b/krb5.spec index 5234207..0e6c34d 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 5%{?dist} +Release: 6%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -71,6 +71,8 @@ Patch96: In-kpropd-debug-log-proper-ticket-enctype-names.patch Patch97: Add-function-and-enctype-flag-for-deprecations.patch Patch98: Make-etype-names-in-KDC-logs-human-readable.patch Patch99: Mark-deprecated-enctypes-when-used.patch +Patch100: Properly-size-ifdef-in-k5_cccol_lock.patch +Patch101: Fix-memory-leak-in-none-replay-cache-type.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -710,6 +712,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Feb 25 2019 Robbie Harwood - 1.17-6 +- Fix memory leak in 'none' replay cache type +- Silence a coverity warning while we're here. + * Fri Feb 01 2019 Robbie Harwood - 1.17-5 - Update FIPS blocking for RC4 From caa2dd1a263f12a2d3ddd369380118d25ef3fc02 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 1 Apr 2019 13:13:49 -0400 Subject: [PATCH 091/304] FIPS-aware SPAKE group negotiation --- 2010-007-patch.txt | 202 ------------------ ...on-and-enctype-flag-for-deprecations.patch | 2 +- Add-tests-for-KCM-ccache-type.patch | 2 +- Address-some-optimized-out-memset-calls.patch | 2 +- ...llocating-a-register-in-zap-assembly.patch | 2 +- ...patch => Become-FIPS-aware-with-3DES.patch | 37 +++- FIPS-aware-SPAKE-group-negotiation.patch | 42 ++++ ...emory-leak-in-none-replay-cache-type.patch | 2 +- ...-plaintext-fallback-for-RC4-usages-a.patch | 2 +- ...ebug-log-proper-ticket-enctype-names.patch | 2 +- ...ec-always-log-non-permitted-enctypes.patch | 2 +- ...ype-names-in-KDC-logs-human-readable.patch | 2 +- Mark-deprecated-enctypes-when-used.patch | 2 +- Properly-size-ifdef-in-k5_cccol_lock.patch | 2 +- Use-openssl-s-PRNG-in-FIPS-mode.patch | 2 +- krb5.spec | 8 +- 16 files changed, 90 insertions(+), 223 deletions(-) delete mode 100644 2010-007-patch.txt rename Become-FIPS-aware.patch => Become-FIPS-aware-with-3DES.patch (82%) create mode 100644 FIPS-aware-SPAKE-group-negotiation.patch diff --git a/2010-007-patch.txt b/2010-007-patch.txt deleted file mode 100644 index b1c3793..0000000 --- a/2010-007-patch.txt +++ /dev/null @@ -1,202 +0,0 @@ -Index: krb5-1.8/src/plugins/preauth/pkinit/pkinit_srv.c -=================================================================== ---- krb5-1.8/src/plugins/preauth/pkinit/pkinit_srv.c (revision 24455) -+++ krb5-1.8/src/plugins/preauth/pkinit/pkinit_srv.c (working copy) -@@ -691,8 +691,7 @@ - krb5_reply_key_pack *key_pack = NULL; - krb5_reply_key_pack_draft9 *key_pack9 = NULL; - krb5_data *encoded_key_pack = NULL; -- unsigned int num_types; -- krb5_cksumtype *cksum_types = NULL; -+ krb5_cksumtype cksum_type; - - pkinit_kdc_context plgctx; - pkinit_kdc_req_context reqctx; -@@ -882,14 +881,25 @@ - retval = ENOMEM; - goto cleanup; - } -- /* retrieve checksums for a given enctype of the reply key */ -- retval = krb5_c_keyed_checksum_types(context, -- encrypting_key->enctype, &num_types, &cksum_types); -- if (retval) -- goto cleanup; - -- /* pick the first of acceptable enctypes for the checksum */ -- retval = krb5_c_make_checksum(context, cksum_types[0], -+ switch (encrypting_key->enctype) { -+ case ENCTYPE_DES_CBC_MD4: -+ cksum_type = CKSUMTYPE_RSA_MD4_DES; -+ break; -+ case ENCTYPE_DES_CBC_MD5: -+ case ENCTYPE_DES_CBC_CRC: -+ cksum_type = CKSUMTYPE_RSA_MD5_DES; -+ break; -+ default: -+ retval = krb5int_c_mandatory_cksumtype(context, -+ encrypting_key->enctype, -+ &cksum_type); -+ if (retval) -+ goto cleanup; -+ break; -+ } -+ -+ retval = krb5_c_make_checksum(context, cksum_type, - encrypting_key, KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, - req_pkt, &key_pack->asChecksum); - if (retval) { -@@ -1033,7 +1043,6 @@ - krb5_free_data(context, encoded_key_pack); - free(dh_pubkey); - free(server_key); -- free(cksum_types); - - switch ((int)padata->pa_type) { - case KRB5_PADATA_PK_AS_REQ: -Index: krb5-1.8/src/lib/crypto/krb/cksumtypes.c -=================================================================== ---- krb5-1.8/src/lib/crypto/krb/cksumtypes.c (revision 24455) -+++ krb5-1.8/src/lib/crypto/krb/cksumtypes.c (working copy) -@@ -101,7 +101,7 @@ - - { CKSUMTYPE_MD5_HMAC_ARCFOUR, - "md5-hmac-rc4", { 0 }, "Microsoft MD5 HMAC", -- NULL, &krb5int_hash_md5, -+ &krb5int_enc_arcfour, &krb5int_hash_md5, - krb5int_hmacmd5_checksum, NULL, - 16, 16, 0 }, - }; -Index: krb5-1.8/src/lib/crypto/krb/keyed_checksum_types.c -=================================================================== ---- krb5-1.8/src/lib/crypto/krb/keyed_checksum_types.c (revision 24455) -+++ krb5-1.8/src/lib/crypto/krb/keyed_checksum_types.c (working copy) -@@ -35,6 +35,13 @@ - { - if (ctp->flags & CKSUM_UNKEYED) - return FALSE; -+ /* Stream ciphers do not play well with RFC 3961 key derivation, so be -+ * conservative with RC4. */ -+ if ((ktp->etype == ENCTYPE_ARCFOUR_HMAC || -+ ktp->etype == ENCTYPE_ARCFOUR_HMAC_EXP) && -+ ctp->ctype != CKSUMTYPE_HMAC_MD5_ARCFOUR && -+ ctp->ctype != CKSUMTYPE_MD5_HMAC_ARCFOUR) -+ return FALSE; - return (!ctp->enc || ktp->enc == ctp->enc); - } - -Index: krb5-1.8/src/lib/crypto/krb/dk/derive.c -=================================================================== ---- krb5-1.8/src/lib/crypto/krb/dk/derive.c (revision 24455) -+++ krb5-1.8/src/lib/crypto/krb/dk/derive.c (working copy) -@@ -91,6 +91,8 @@ - blocksize = enc->block_size; - keybytes = enc->keybytes; - -+ if (blocksize == 1) -+ return KRB5_BAD_ENCTYPE; - if (inkey->keyblock.length != enc->keylength || outrnd->length != keybytes) - return KRB5_CRYPTO_INTERNAL; - -Index: krb5-1.8/src/lib/gssapi/krb5/util_crypt.c -=================================================================== ---- krb5-1.8/src/lib/gssapi/krb5/util_crypt.c (revision 24455) -+++ krb5-1.8/src/lib/gssapi/krb5/util_crypt.c (working copy) -@@ -119,10 +119,22 @@ - if (code != 0) - return code; - -- code = (*kaccess.mandatory_cksumtype)(context, subkey->keyblock.enctype, -- cksumtype); -- if (code != 0) -- return code; -+ switch (subkey->keyblock.enctype) { -+ case ENCTYPE_DES_CBC_MD4: -+ *cksumtype = CKSUMTYPE_RSA_MD4_DES; -+ break; -+ case ENCTYPE_DES_CBC_MD5: -+ case ENCTYPE_DES_CBC_CRC: -+ *cksumtype = CKSUMTYPE_RSA_MD5_DES; -+ break; -+ default: -+ code = (*kaccess.mandatory_cksumtype)(context, -+ subkey->keyblock.enctype, -+ cksumtype); -+ if (code != 0) -+ return code; -+ break; -+ } - - switch (subkey->keyblock.enctype) { - case ENCTYPE_DES_CBC_MD5: -Index: krb5-1.8/src/lib/krb5/krb/pac.c -=================================================================== ---- krb5-1.8/src/lib/krb5/krb/pac.c (revision 24455) -+++ krb5-1.8/src/lib/krb5/krb/pac.c (working copy) -@@ -582,6 +582,8 @@ - checksum.checksum_type = load_32_le(p); - checksum.length = checksum_data.length - PAC_SIGNATURE_DATA_LENGTH; - checksum.contents = p + PAC_SIGNATURE_DATA_LENGTH; -+ if (!krb5_c_is_keyed_cksum(checksum.checksum_type)) -+ return KRB5KRB_AP_ERR_INAPP_CKSUM; - - pac_data.length = pac->data.length; - pac_data.data = malloc(pac->data.length); -Index: krb5-1.8/src/lib/krb5/krb/preauth2.c -=================================================================== ---- krb5-1.8/src/lib/krb5/krb/preauth2.c (revision 24455) -+++ krb5-1.8/src/lib/krb5/krb/preauth2.c (working copy) -@@ -1578,7 +1578,9 @@ - - cksum = sc2->sam_cksum; - -- while (*cksum) { -+ for (; *cksum; cksum++) { -+ if (!krb5_c_is_keyed_cksum((*cksum)->checksum_type)) -+ continue; - /* Check this cksum */ - retval = krb5_c_verify_checksum(context, as_key, - KRB5_KEYUSAGE_PA_SAM_CHALLENGE_CKSUM, -@@ -1592,7 +1594,6 @@ - } - if (valid_cksum) - break; -- cksum++; - } - - if (!valid_cksum) { -Index: krb5-1.8/src/lib/krb5/krb/mk_safe.c -=================================================================== ---- krb5-1.8/src/lib/krb5/krb/mk_safe.c (revision 24455) -+++ krb5-1.8/src/lib/krb5/krb/mk_safe.c (working copy) -@@ -215,10 +215,28 @@ - for (i = 0; i < nsumtypes; i++) - if (auth_context->safe_cksumtype == sumtypes[i]) - break; -- if (i == nsumtypes) -- i = 0; -- sumtype = sumtypes[i]; - krb5_free_cksumtypes (context, sumtypes); -+ if (i < nsumtypes) -+ sumtype = auth_context->safe_cksumtype; -+ else { -+ switch (enctype) { -+ case ENCTYPE_DES_CBC_MD4: -+ sumtype = CKSUMTYPE_RSA_MD4_DES; -+ break; -+ case ENCTYPE_DES_CBC_MD5: -+ case ENCTYPE_DES_CBC_CRC: -+ sumtype = CKSUMTYPE_RSA_MD5_DES; -+ break; -+ default: -+ retval = krb5int_c_mandatory_cksumtype(context, enctype, -+ &sumtype); -+ if (retval) { -+ CLEANUP_DONE(); -+ goto error; -+ } -+ break; -+ } -+ } - } - if ((retval = krb5_mk_safe_basic(context, userdata, key, &replaydata, - plocal_fulladdr, premote_fulladdr, diff --git a/Add-function-and-enctype-flag-for-deprecations.patch b/Add-function-and-enctype-flag-for-deprecations.patch index b4462c5..687eba4 100644 --- a/Add-function-and-enctype-flag-for-deprecations.patch +++ b/Add-function-and-enctype-flag-for-deprecations.patch @@ -1,4 +1,4 @@ -From 71c582c1490d128ed0ee1c817ecb15ed425aca46 Mon Sep 17 00:00:00 2001 +From 15d1cbd15d4ea8113fc5dd7bc446ca2b99ab4085 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 16:16:57 -0500 Subject: [PATCH] Add function and enctype flag for deprecations diff --git a/Add-tests-for-KCM-ccache-type.patch b/Add-tests-for-KCM-ccache-type.patch index 3cc9e70..177a042 100644 --- a/Add-tests-for-KCM-ccache-type.patch +++ b/Add-tests-for-KCM-ccache-type.patch @@ -1,4 +1,4 @@ -From 5ecbe8d3ab4f53c0923a0442273bf18a9ff04fd5 Mon Sep 17 00:00:00 2001 +From e863c1e068775d066241edacff2bdb50cf1be27c Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Nov 2018 00:27:35 -0500 Subject: [PATCH] Add tests for KCM ccache type diff --git a/Address-some-optimized-out-memset-calls.patch b/Address-some-optimized-out-memset-calls.patch index 6e260ad..60cd6a0 100644 --- a/Address-some-optimized-out-memset-calls.patch +++ b/Address-some-optimized-out-memset-calls.patch @@ -1,4 +1,4 @@ -From 1dfff7202448a950c9133cdfe43d650092d930fd Mon Sep 17 00:00:00 2001 +From d3690641a5eecf8ee031053bdedbaa4e249cc771 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 30 Dec 2018 16:40:28 -0500 Subject: [PATCH] Address some optimized-out memset() calls diff --git a/Avoid-allocating-a-register-in-zap-assembly.patch b/Avoid-allocating-a-register-in-zap-assembly.patch index 6673530..3406b63 100644 --- a/Avoid-allocating-a-register-in-zap-assembly.patch +++ b/Avoid-allocating-a-register-in-zap-assembly.patch @@ -1,4 +1,4 @@ -From 623414ccbb47eb6c334d838aa9023f16f0df5322 Mon Sep 17 00:00:00 2001 +From d8cba3893687a3976569fef97c1614b9b51ad573 Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Thu, 3 Jan 2019 17:19:32 +0100 Subject: [PATCH] Avoid allocating a register in zap() assembly diff --git a/Become-FIPS-aware.patch b/Become-FIPS-aware-with-3DES.patch similarity index 82% rename from Become-FIPS-aware.patch rename to Become-FIPS-aware-with-3DES.patch index 4011e25..8bf76c1 100644 --- a/Become-FIPS-aware.patch +++ b/Become-FIPS-aware-with-3DES.patch @@ -1,7 +1,7 @@ -From d8db85101c535a32937136118561aeb5646d2136 Mon Sep 17 00:00:00 2001 +From 9f5fbf191d74cae9b28d318fff4c80d3d3e49c86 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 -Subject: [PATCH] Become FIPS-aware +Subject: [PATCH] Become FIPS-aware (with 3DES) A lot of the FIPS error conditions from OpenSSL are incredibly mysterious (at best, things return NULL unexpectedly; at worst, @@ -10,17 +10,16 @@ ENOMEM). In order to cope with this, we need to have some level of awareness of what we can and can't safely call. This will slow down some calls slightly (FIPS_mode() takes multiple -locks), but not for any crypto we care about - AES is fine, for -instance. - -(cherry picked from commit ce06474e3b12430480374f923c25bae9581fb146) +locks), but not for any crypto we care about - which is to say that +AES is fine. --- src/lib/crypto/openssl/enc_provider/camellia.c | 6 ++++++ src/lib/crypto/openssl/enc_provider/des.c | 9 +++++++++ + src/lib/crypto/openssl/enc_provider/des3.c | 6 ++++++ src/lib/crypto/openssl/enc_provider/rc4.c | 13 ++++++++++++- src/lib/crypto/openssl/hash_provider/hash_evp.c | 4 ++++ src/lib/crypto/openssl/hmac.c | 6 +++++- - 5 files changed, 36 insertions(+), 2 deletions(-) + 6 files changed, 42 insertions(+), 2 deletions(-) diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c index 2da691329..f79679a0b 100644 @@ -80,6 +79,30 @@ index a662db512..7d17d287e 100644 ret = validate(key, ivec, data, num_data, &empty); if (ret != 0) return ret; +diff --git a/src/lib/crypto/openssl/enc_provider/des3.c b/src/lib/crypto/openssl/enc_provider/des3.c +index 1c439c2cd..8be555a8d 100644 +--- a/src/lib/crypto/openssl/enc_provider/des3.c ++++ b/src/lib/crypto/openssl/enc_provider/des3.c +@@ -84,6 +84,9 @@ k5_des3_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx; + krb5_boolean empty; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + ret = validate(key, ivec, data, num_data, &empty); + if (ret != 0 || empty) + return ret; +@@ -133,6 +136,9 @@ k5_des3_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx; + krb5_boolean empty; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + ret = validate(key, ivec, data, num_data, &empty); + if (ret != 0 || empty) + return ret; diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c index 7f3c086ed..a3f2a7442 100644 --- a/src/lib/crypto/openssl/enc_provider/rc4.c diff --git a/FIPS-aware-SPAKE-group-negotiation.patch b/FIPS-aware-SPAKE-group-negotiation.patch new file mode 100644 index 0000000..6017f4b --- /dev/null +++ b/FIPS-aware-SPAKE-group-negotiation.patch @@ -0,0 +1,42 @@ +From 59269fca96168aa89dc32834d188a54eea8953ac Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 1 Apr 2019 13:13:09 -0400 +Subject: [PATCH] FIPS-aware SPAKE group negotiation + +--- + src/plugins/preauth/spake/groups.c | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/src/plugins/preauth/spake/groups.c b/src/plugins/preauth/spake/groups.c +index a195cc195..8a913cb5a 100644 +--- a/src/plugins/preauth/spake/groups.c ++++ b/src/plugins/preauth/spake/groups.c +@@ -56,6 +56,8 @@ + #include "trace.h" + #include "groups.h" + ++#include ++ + #define DEFAULT_GROUPS_CLIENT "edwards25519" + #define DEFAULT_GROUPS_KDC "" + +@@ -102,6 +104,9 @@ find_gdef(int32_t group) + { + size_t i; + ++ if (group == builtin_edwards25519.reg->id && FIPS_mode()) ++ return NULL; ++ + for (i = 0; groupdefs[i] != NULL; i++) { + if (groupdefs[i]->reg->id == group) + return groupdefs[i]; +@@ -116,6 +121,9 @@ find_gnum(const char *name) + { + size_t i; + ++ if (strcasecmp(name, builtin_edwards25519.reg->name) == 0 && FIPS_mode()) ++ return 0; ++ + for (i = 0; groupdefs[i] != NULL; i++) { + if (strcasecmp(name, groupdefs[i]->reg->name) == 0) + return groupdefs[i]->reg->id; diff --git a/Fix-memory-leak-in-none-replay-cache-type.patch b/Fix-memory-leak-in-none-replay-cache-type.patch index c093c4a..8141247 100644 --- a/Fix-memory-leak-in-none-replay-cache-type.patch +++ b/Fix-memory-leak-in-none-replay-cache-type.patch @@ -1,4 +1,4 @@ -From ff79351c4755d6df7c3245274708454311c25731 Mon Sep 17 00:00:00 2001 +From 472131596213337ae01b792aef2fb2580738a1df Mon Sep 17 00:00:00 2001 From: Corene Casper Date: Sat, 16 Feb 2019 00:49:26 -0500 Subject: [PATCH] Fix memory leak in 'none' replay cache type diff --git a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch b/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch index a24904f..99acb66 100644 --- a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch +++ b/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch @@ -1,4 +1,4 @@ -From e44494c87ea3086b824e972df5566cedf5ad7e15 Mon Sep 17 00:00:00 2001 +From 1382f982a18aec4bc14780b175638d44969ac1d2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 31 Jul 2018 13:47:26 -0400 Subject: [PATCH] In FIPS mode, add plaintext fallback for RC4 usages and taint diff --git a/In-kpropd-debug-log-proper-ticket-enctype-names.patch b/In-kpropd-debug-log-proper-ticket-enctype-names.patch index 0df245e..1450698 100644 --- a/In-kpropd-debug-log-proper-ticket-enctype-names.patch +++ b/In-kpropd-debug-log-proper-ticket-enctype-names.patch @@ -1,4 +1,4 @@ -From 5331faee19a97508f1089f113ecaee852e73c83c Mon Sep 17 00:00:00 2001 +From 220762a0bdc5151a0d4a25bc7e56251ef351b560 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 13:41:16 -0500 Subject: [PATCH] In kpropd, debug-log proper ticket enctype names diff --git a/In-rd_req_dec-always-log-non-permitted-enctypes.patch b/In-rd_req_dec-always-log-non-permitted-enctypes.patch index e84e0d0..b36321a 100644 --- a/In-rd_req_dec-always-log-non-permitted-enctypes.patch +++ b/In-rd_req_dec-always-log-non-permitted-enctypes.patch @@ -1,4 +1,4 @@ -From 8ca2006679539a7675c94148ff338a178d7689eb Mon Sep 17 00:00:00 2001 +From 28528d8169d9af3830b3a162c525a8e1a71f05f4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Jan 2019 17:14:42 -0500 Subject: [PATCH] In rd_req_dec, always log non-permitted enctypes diff --git a/Make-etype-names-in-KDC-logs-human-readable.patch b/Make-etype-names-in-KDC-logs-human-readable.patch index f596034..9915f69 100644 --- a/Make-etype-names-in-KDC-logs-human-readable.patch +++ b/Make-etype-names-in-KDC-logs-human-readable.patch @@ -1,4 +1,4 @@ -From 809ecc10090688d78fc45d611c58db15aae053ad Mon Sep 17 00:00:00 2001 +From d32d0cfbbe1386b2cf9b31682df4c35ccc029bda Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 8 Jan 2019 17:42:35 -0500 Subject: [PATCH] Make etype names in KDC logs human-readable diff --git a/Mark-deprecated-enctypes-when-used.patch b/Mark-deprecated-enctypes-when-used.patch index c797d05..6faf378 100644 --- a/Mark-deprecated-enctypes-when-used.patch +++ b/Mark-deprecated-enctypes-when-used.patch @@ -1,4 +1,4 @@ -From 2af719291eb4344ee9e87b883390433539d59ada Mon Sep 17 00:00:00 2001 +From 0f4d9265c808a1e78fb90b54d39e58f3f89e672f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 10 Jan 2019 16:34:54 -0500 Subject: [PATCH] Mark deprecated enctypes when used diff --git a/Properly-size-ifdef-in-k5_cccol_lock.patch b/Properly-size-ifdef-in-k5_cccol_lock.patch index 5e6bac8..23fb478 100644 --- a/Properly-size-ifdef-in-k5_cccol_lock.patch +++ b/Properly-size-ifdef-in-k5_cccol_lock.patch @@ -1,4 +1,4 @@ -From e2a0e04fb3be9297a8c532dd35a7c1045cae88f4 Mon Sep 17 00:00:00 2001 +From 8bdcbe143adc71918bd6e5f2e075df6b8e31267a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Feb 2019 11:50:35 -0500 Subject: [PATCH] Properly size #ifdef in k5_cccol_lock() diff --git a/Use-openssl-s-PRNG-in-FIPS-mode.patch b/Use-openssl-s-PRNG-in-FIPS-mode.patch index f78744c..837a747 100644 --- a/Use-openssl-s-PRNG-in-FIPS-mode.patch +++ b/Use-openssl-s-PRNG-in-FIPS-mode.patch @@ -1,4 +1,4 @@ -From 31277d79675a76612015ea00d420b41b9a232d5a Mon Sep 17 00:00:00 2001 +From 9724b7f409410a7c3cc0330089009d7b9aa92ae6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 4 Jan 2019 17:00:15 -0500 Subject: [PATCH] Use openssl's PRNG in FIPS mode diff --git a/krb5.spec b/krb5.spec index 0e6c34d..76cf5ae 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 6%{?dist} +Release: 7%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -60,7 +60,6 @@ Patch33: krb5-1.13-dirsrv-accountlock.patch Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch -Patch88: Become-FIPS-aware.patch Patch89: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch Patch90: Add-tests-for-KCM-ccache-type.patch Patch92: Address-some-optimized-out-memset-calls.patch @@ -73,6 +72,8 @@ Patch98: Make-etype-names-in-KDC-logs-human-readable.patch Patch99: Mark-deprecated-enctypes-when-used.patch Patch100: Properly-size-ifdef-in-k5_cccol_lock.patch Patch101: Fix-memory-leak-in-none-replay-cache-type.patch +Patch102: Become-FIPS-aware-with-3DES.patch +Patch103: FIPS-aware-SPAKE-group-negotiation.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -712,6 +713,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Apr 01 2019 Robbie Harwood - 1.17-7 +- FIPS-aware SPAKE group negotiation + * Mon Feb 25 2019 Robbie Harwood - 1.17-6 - Fix memory leak in 'none' replay cache type - Silence a coverity warning while we're here. From 7f7eba0cefe434725cf53d86518220f6e7727862 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 11 Apr 2019 13:18:46 -0400 Subject: [PATCH 092/304] Implement krb5_cc_remove_cred for remaining types Resolves: #1693836 --- ...er-comment-for-krb5_cc_start_seq_get.patch | 31 + ...5_cc_remove_cred-for-remaining-types.patch | 599 ++++++++++++++++++ krb5.spec | 8 +- 3 files changed, 637 insertions(+), 1 deletion(-) create mode 100644 Clarify-header-comment-for-krb5_cc_start_seq_get.patch create mode 100644 Implement-krb5_cc_remove_cred-for-remaining-types.patch diff --git a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch new file mode 100644 index 0000000..a36c364 --- /dev/null +++ b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch @@ -0,0 +1,31 @@ +From 7f4af607c9362acc596bc63ca4c46699327d0cae Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 2 Apr 2019 14:18:57 -0400 +Subject: [PATCH] Clarify header comment for krb5_cc_start_seq_get() + +Previously this comment seemed to suggest that applications needed to +block all other access to the ccache (including by other processes) +during iteration. + +(cherry picked from commit f4f51a25dd38601357e2f64b17b51eb23f45a53e) +--- + src/include/krb5/krb5.hin | 6 ++++-- + 1 file changed, 4 insertions(+), 2 deletions(-) + +diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin +index 3ff86d7ff..346e796a5 100644 +--- a/src/include/krb5/krb5.hin ++++ b/src/include/krb5/krb5.hin +@@ -2491,8 +2491,10 @@ krb5_cc_get_principal(krb5_context context, krb5_ccache cache, + * + * krb5_cc_end_seq_get() must be called to complete the retrieve operation. + * +- * @note If @a cache is modified between the time of the call to this function +- * and the time of the final krb5_cc_end_seq_get(), the results are undefined. ++ * @note If the cache represented by @a cache is modified between the time of ++ * the call to this function and the time of the final krb5_cc_end_seq_get(), ++ * these changes may not be reflected in the results of krb5_cc_next_cred() ++ * calls. + * + * @retval 0 Success; otherwise - Kerberos error codes + */ diff --git a/Implement-krb5_cc_remove_cred-for-remaining-types.patch b/Implement-krb5_cc_remove_cred-for-remaining-types.patch new file mode 100644 index 0000000..dfb57bd --- /dev/null +++ b/Implement-krb5_cc_remove_cred-for-remaining-types.patch @@ -0,0 +1,599 @@ +From f1449621399def78384c34216454bd1dfceefb8f Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 1 Apr 2019 14:28:48 -0400 +Subject: [PATCH] Implement krb5_cc_remove_cred for remaining types + +Previously, only KCM and MSLA implemented credential removal. Add +support for FILE (and therefore DIR), MEMORY, and KEYRING. + +The FILE logic is similar Heimdal's implementation, with additional +logic for skipping removed creds during iteration. In addition to +setting endtime to 0 and changing the realm for config entries as +Heimdal does, we set authtime to -1 to make deleted entries +distinguishable from gssproxy encrypted creds and config entries. + +For MEMORY, leave behind empty list elements when removing a cred will +leave behind an empty list element, in case an iterator holds a +pointer to that element. + +[ghudson@mit.edu: edited commit message; made minor style and comment +changes; fixed memory leaks detected by asan] + +ticket: 8792 (new) +(cherry picked from commit d3b39a8bac6206b5ea78b0bf6a2958c1df0b0dd5) +--- + src/lib/krb5/ccache/cc_file.c | 177 ++++++++++++++++++++++++++++--- + src/lib/krb5/ccache/cc_keyring.c | 89 +++++++++++----- + src/lib/krb5/ccache/cc_memory.c | 36 +++++-- + src/lib/krb5/ccache/t_cc.c | 129 +++++++++++++++++++++- + 4 files changed, 381 insertions(+), 50 deletions(-) + +diff --git a/src/lib/krb5/ccache/cc_file.c b/src/lib/krb5/ccache/cc_file.c +index 9263a0054..09da38fa9 100644 +--- a/src/lib/krb5/ccache/cc_file.c ++++ b/src/lib/krb5/ccache/cc_file.c +@@ -744,6 +744,14 @@ cleanup: + return set_errmsg_filename(context, ret, data->filename); + } + ++/* Return true if cred is a removed entry (assuming that no legitimate cred ++ * entries will have authtime=-1 and endtime=0). */ ++static inline krb5_boolean ++cred_removed(krb5_creds *c) ++{ ++ return c->times.endtime == 0 && c->times.authtime == -1; ++} ++ + /* Get the next credential from the cache file. */ + static krb5_error_code KRB5_CALLCONV + fcc_next_cred(krb5_context context, krb5_ccache id, krb5_cc_cursor *cursor, +@@ -765,19 +773,30 @@ fcc_next_cred(krb5_context context, krb5_ccache id, krb5_cc_cursor *cursor, + goto cleanup; + file_locked = TRUE; + +- /* Load a marshalled cred into memory. */ +- ret = get_size(context, fcursor->fp, &maxsize); +- if (ret) +- goto cleanup; +- ret = load_cred(context, fcursor->fp, fcursor->version, maxsize, &buf); +- if (ret) +- goto cleanup; +- ret = k5_buf_status(&buf); +- if (ret) +- goto cleanup; ++ for (;;) { ++ /* Load a marshalled cred into memory. */ ++ ret = get_size(context, fcursor->fp, &maxsize); ++ if (ret) ++ goto cleanup; ++ ret = load_cred(context, fcursor->fp, fcursor->version, maxsize, &buf); ++ if (ret) ++ goto cleanup; ++ ret = k5_buf_status(&buf); ++ if (ret) ++ goto cleanup; + +- /* Unmarshal it from buf into creds. */ +- ret = k5_unmarshal_cred(buf.data, buf.len, fcursor->version, creds); ++ /* Unmarshal it from buf into creds. */ ++ ret = k5_unmarshal_cred(buf.data, buf.len, fcursor->version, creds); ++ if (ret) ++ goto cleanup; ++ ++ /* Keep going if this entry has been removed; otherwise stop. */ ++ if (!cred_removed(creds)) ++ break; ++ ++ k5_buf_truncate(&buf, 0); ++ krb5_free_cred_contents(context, creds); ++ } + + cleanup: + if (file_locked) +@@ -1002,12 +1021,142 @@ cleanup: + return set_errmsg_filename(context, ret ? ret : ret2, data->filename); + } + +-/* Non-functional stub for removing a cred from the cache file. */ ++/* ++ * Overwrite cred in the ccache file with an entry that should not match any ++ * reasonable search. Deletion is not guaranteed. This method is originally ++ * from Heimdal, with the addition of setting authtime to -1. ++ */ ++static krb5_error_code ++delete_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor, ++ krb5_creds *cred) ++{ ++ krb5_error_code ret; ++ krb5_fcc_cursor *fcursor = *cursor; ++ fcc_data *data = cache->data; ++ struct k5buf expected = EMPTY_K5BUF, overwrite = EMPTY_K5BUF; ++ int fd = -1; ++ uint8_t *on_disk = NULL; ++ ssize_t rwret; ++ off_t start_offset; ++ ++ k5_buf_init_dynamic_zap(&expected); ++ k5_buf_init_dynamic_zap(&overwrite); ++ ++ /* Re-marshal cred to get its byte representation in the file. */ ++ k5_marshal_cred(&expected, fcursor->version, cred); ++ ret = k5_buf_status(&expected); ++ if (ret) ++ goto cleanup; ++ ++ /* ++ * Mark the cred expired so that it will be skipped over by any future ++ * match checks. Heimdal only sets endtime, but we also set authtime to ++ * distinguish from gssproxy's creds. ++ */ ++ cred->times.endtime = 0; ++ cred->times.authtime = -1; ++ ++ /* For config entries, also change the realm so that other implementations ++ * won't match them. */ ++ if (cred->server != NULL && cred->server->realm.length > 0 && ++ strcmp(cred->server->realm.data, "X-CACHECONF:") == 0) ++ memcpy(cred->server->realm.data, "X-RMED-CONF:", 12); ++ ++ k5_marshal_cred(&overwrite, fcursor->version, cred); ++ ret = k5_buf_status(&overwrite); ++ if (ret) ++ goto cleanup; ++ ++ if (expected.len != overwrite.len) { ++ ret = KRB5_CC_FORMAT; ++ goto cleanup; ++ } ++ ++ /* Get a non-O_APPEND handle to the raw file. */ ++ fd = open(data->filename, O_RDWR | O_BINARY | O_CLOEXEC); ++ if (fd == -1) { ++ ret = interpret_errno(context, errno); ++ goto cleanup; ++ } ++ ++ start_offset = ftell(fcursor->fp); ++ if (start_offset == -1) { ++ ret = interpret_errno(context, errno); ++ goto cleanup; ++ } ++ start_offset -= expected.len; ++ ++ /* Read the bytes at the entry to be overwritten. */ ++ if (lseek(fd, start_offset, SEEK_SET) == -1) { ++ ret = interpret_errno(context, errno); ++ goto cleanup; ++ } ++ on_disk = k5alloc(expected.len, &ret); ++ if (ret != 0) ++ goto cleanup; ++ rwret = read(fd, on_disk, expected.len); ++ if (rwret < 0) { ++ ret = interpret_errno(context, errno); ++ goto cleanup; ++ } else if ((size_t)rwret != expected.len) { ++ ret = KRB5_CC_FORMAT; ++ goto cleanup; ++ } ++ ++ /* ++ * If the bytes have changed, either someone else removed the same cred or ++ * the cache was reinitialized. Either way the cred is no longer present, ++ * so return successfully. ++ */ ++ if (memcmp(on_disk, expected.data, expected.len) != 0) ++ goto cleanup; ++ ++ /* Write out the altered entry. */ ++ if (lseek(fd, start_offset, SEEK_SET) == -1) { ++ ret = interpret_errno(context, errno); ++ goto cleanup; ++ } ++ rwret = write(fd, overwrite.data, overwrite.len); ++ if (rwret < 0) { ++ ret = interpret_errno(context, errno); ++ goto cleanup; ++ } ++ ++cleanup: ++ close(fd); ++ zapfree(on_disk, expected.len); ++ k5_buf_free(&expected); ++ k5_buf_free(&overwrite); ++ return ret; ++} ++ ++/* Remove the given creds from the ccache file. */ + static krb5_error_code KRB5_CALLCONV + fcc_remove_cred(krb5_context context, krb5_ccache cache, krb5_flags flags, + krb5_creds *creds) + { +- return KRB5_CC_NOSUPP; ++ krb5_error_code ret; ++ krb5_cc_cursor cursor; ++ krb5_creds cur; ++ ++ ret = krb5_cc_start_seq_get(context, cache, &cursor); ++ if (ret) ++ return ret; ++ ++ for (;;) { ++ ret = krb5_cc_next_cred(context, cache, &cursor, &cur); ++ if (ret) ++ break; ++ ++ if (krb5int_cc_creds_match_request(context, flags, creds, &cur)) ++ ret = delete_cred(context, cache, &cursor, &cur); ++ krb5_free_cred_contents(context, &cur); ++ if (ret) ++ break; ++ } ++ ++ krb5_cc_end_seq_get(context, cache, &cursor); ++ return (ret == KRB5_CC_END) ? 0 : ret; + } + + static krb5_error_code KRB5_CALLCONV +diff --git a/src/lib/krb5/ccache/cc_keyring.c b/src/lib/krb5/ccache/cc_keyring.c +index 8419f6ebf..98723fe2e 100644 +--- a/src/lib/krb5/ccache/cc_keyring.c ++++ b/src/lib/krb5/ccache/cc_keyring.c +@@ -1032,40 +1032,44 @@ krcc_next_cred(krb5_context context, krb5_ccache id, krb5_cc_cursor *cursor, + + memset(creds, 0, sizeof(krb5_creds)); + +- /* The cursor has the entire list of keys. (Note that we don't support +- * remove_cred.) */ ++ /* The cursor has the entire list of keys. */ + krcursor = *cursor; + if (krcursor == NULL) + return KRB5_CC_END; + +- /* If we're pointing past the end of the keys array, there are no more. */ +- if (krcursor->currkey >= krcursor->numkeys) +- return KRB5_CC_END; ++ while (krcursor->currkey < krcursor->numkeys) { ++ /* If we're pointing at the entry with the principal, or at the key ++ * with the time offsets, skip it. */ ++ if (krcursor->keys[krcursor->currkey] == krcursor->princ_id || ++ krcursor->keys[krcursor->currkey] == krcursor->offsets_id) { ++ krcursor->currkey++; ++ continue; ++ } + +- /* If we're pointing at the entry with the principal, or at the key +- * with the time offsets, skip it. */ +- while (krcursor->keys[krcursor->currkey] == krcursor->princ_id || +- krcursor->keys[krcursor->currkey] == krcursor->offsets_id) { ++ /* Read the key; the right size buffer will be allocated and ++ * returned. */ ++ psize = keyctl_read_alloc(krcursor->keys[krcursor->currkey], ++ &payload); ++ if (psize != -1) { ++ krcursor->currkey++; ++ ++ /* Unmarshal the cred using the file ccache version 4 format. */ ++ ret = k5_unmarshal_cred(payload, psize, 4, creds); ++ free(payload); ++ return ret; ++ } else if (errno != ENOKEY && errno != EACCES) { ++ DEBUG_PRINT(("Error reading key %d: %s\n", ++ krcursor->keys[krcursor->currkey], strerror(errno))); ++ return KRB5_FCC_NOFILE; ++ } ++ ++ /* The current key was unlinked, probably by a remove_cred call; move ++ * on to the next one. */ + krcursor->currkey++; +- /* Check if we have now reached the end */ +- if (krcursor->currkey >= krcursor->numkeys) +- return KRB5_CC_END; + } + +- /* Read the key; the right size buffer will be allocated and returned. */ +- psize = keyctl_read_alloc(krcursor->keys[krcursor->currkey], &payload); +- if (psize == -1) { +- DEBUG_PRINT(("Error reading key %d: %s\n", +- krcursor->keys[krcursor->currkey], +- strerror(errno))); +- return KRB5_FCC_NOFILE; +- } +- krcursor->currkey++; +- +- /* Unmarshal the credential using the file ccache version 4 format. */ +- ret = k5_unmarshal_cred(payload, psize, 4, creds); +- free(payload); +- return ret; ++ /* No more keys in keyring. */ ++ return KRB5_CC_END; + } + + /* Release an iteration cursor. */ +@@ -1248,12 +1252,41 @@ krcc_retrieve(krb5_context context, krb5_ccache id, + creds); + } + +-/* Non-functional stub for removing a cred from the cache keyring. */ ++/* Remove a credential from the cache keyring. */ + static krb5_error_code KRB5_CALLCONV + krcc_remove_cred(krb5_context context, krb5_ccache cache, + krb5_flags flags, krb5_creds *creds) + { +- return KRB5_CC_NOSUPP; ++ krb5_error_code ret; ++ krcc_data *data = cache->data; ++ krb5_cc_cursor cursor; ++ krb5_creds c; ++ krcc_cursor krcursor; ++ key_serial_t key; ++ krb5_boolean match; ++ ++ ret = krcc_start_seq_get(context, cache, &cursor); ++ if (ret) ++ return ret; ++ ++ for (;;) { ++ ret = krcc_next_cred(context, cache, &cursor, &c); ++ if (ret) ++ break; ++ match = krb5int_cc_creds_match_request(context, flags, creds, &c); ++ krb5_free_cred_contents(context, &c); ++ if (match) { ++ krcursor = cursor; ++ key = krcursor->keys[krcursor->currkey - 1]; ++ if (keyctl_unlink(key, data->cache_id) == -1) { ++ ret = errno; ++ break; ++ } ++ } ++ } ++ ++ krcc_end_seq_get(context, cache, &cursor); ++ return (ret == KRB5_CC_END) ? 0 : ret; + } + + /* Set flags on the cache. (We don't care about any flags.) */ +diff --git a/src/lib/krb5/ccache/cc_memory.c b/src/lib/krb5/ccache/cc_memory.c +index 114ef6913..edf6fcc26 100644 +--- a/src/lib/krb5/ccache/cc_memory.c ++++ b/src/lib/krb5/ccache/cc_memory.c +@@ -405,14 +405,23 @@ krb5_mcc_next_cred(krb5_context context, krb5_ccache id, + */ + k5_cc_mutex_lock(context, &d->lock); + if (mcursor->generation != d->generation) { +- k5_cc_mutex_unlock(context, &d->lock); +- return KRB5_CC_END; ++ retval = KRB5_CC_END; ++ goto done; ++ } ++ ++ /* Skip over removed creds. */ ++ while (mcursor->next_link != NULL && mcursor->next_link->creds == NULL) ++ mcursor->next_link = mcursor->next_link->next; ++ if (mcursor->next_link == NULL) { ++ retval = KRB5_CC_END; ++ goto done; + } + + retval = k5_copy_creds_contents(context, mcursor->next_link->creds, creds); + if (retval == 0) + mcursor->next_link = mcursor->next_link->next; + ++done: + k5_cc_mutex_unlock(context, &d->lock); + return retval; + } +@@ -592,16 +601,31 @@ krb5_mcc_retrieve(krb5_context context, krb5_ccache id, krb5_flags whichfields, + } + + /* +- * Non-functional stub implementation for krb5_mcc_remove ++ * Modifies: ++ * the memory cache + * +- * Errors: +- * KRB5_CC_NOSUPP - not implemented ++ * Effects: ++ * Remove the given creds from the ccache. + */ + static krb5_error_code KRB5_CALLCONV + krb5_mcc_remove_cred(krb5_context context, krb5_ccache cache, krb5_flags flags, + krb5_creds *creds) + { +- return KRB5_CC_NOSUPP; ++ krb5_mcc_data *data = (krb5_mcc_data *)cache->data; ++ krb5_mcc_link *l; ++ ++ k5_cc_mutex_lock(context, &data->lock); ++ ++ for (l = data->link; l != NULL; l = l->next) { ++ if (l->creds != NULL && ++ krb5int_cc_creds_match_request(context, flags, creds, l->creds)) { ++ krb5_free_creds(context, l->creds); ++ l->creds = NULL; ++ } ++ } ++ ++ k5_cc_mutex_unlock(context, &data->lock); ++ return 0; + } + + +diff --git a/src/lib/krb5/ccache/t_cc.c b/src/lib/krb5/ccache/t_cc.c +index cd4569c4c..954f2f465 100644 +--- a/src/lib/krb5/ccache/t_cc.c ++++ b/src/lib/krb5/ccache/t_cc.c +@@ -36,7 +36,7 @@ + + #define KRB5_OK 0 + +-krb5_creds test_creds; ++krb5_creds test_creds, test_creds2; + + int debug=0; + +@@ -144,6 +144,10 @@ init_test_cred(krb5_context context) + a->length = 2; + test_creds.authdata[1] = a; + ++ memcpy(&test_creds2, &test_creds, sizeof(test_creds)); ++ kret = krb5_build_principal(context, &test_creds2.server, sizeof(REALM), ++ REALM, "server-comp1", "server-comp3", NULL); ++ + cleanup: + if(kret) { + if (test_creds.client) { +@@ -170,6 +174,7 @@ free_test_cred(krb5_context context) + krb5_free_principal(context, test_creds.client); + + krb5_free_principal(context, test_creds.server); ++ krb5_free_principal(context, test_creds2.server); + + if(test_creds.authdata) { + krb5_free_authdata(context, test_creds.authdata); +@@ -199,6 +204,44 @@ free_test_cred(krb5_context context) + #define CHECK_FAIL(experr, kret, msg) \ + if (experr != kret) { CHECK(kret, msg);} + ++static void ++check_num_entries(krb5_context context, krb5_ccache cache, int expected, ++ unsigned linenum) ++{ ++ krb5_error_code ret; ++ krb5_cc_cursor cursor; ++ krb5_creds creds; ++ int count = 0; ++ ++ ret = krb5_cc_start_seq_get(context, cache, &cursor); ++ if (ret != 0) { ++ com_err("", ret, "(on line %d) - krb5_cc_start_seq_get", linenum); ++ fflush(stderr); ++ exit(1); ++ } ++ ++ while (1) { ++ ret = krb5_cc_next_cred(context, cache, &cursor, &creds); ++ if (ret) ++ break; ++ ++ count++; ++ krb5_free_cred_contents(context, &creds); ++ } ++ krb5_cc_end_seq_get(context, cache, &cursor); ++ if (ret != KRB5_CC_END) { ++ CHECK(ret, "counting entries in ccache"); ++ } ++ ++ if (count != expected) { ++ com_err("", KRB5_FCC_INTERNAL, ++ "(on line %d) - count didn't match (expected %d, got %d)", ++ linenum, expected, count); ++ fflush(stderr); ++ exit(1); ++ } ++} ++ + static void + cc_test(krb5_context context, const char *name, krb5_flags flags) + { +@@ -207,6 +250,7 @@ cc_test(krb5_context context, const char *name, krb5_flags flags) + krb5_error_code kret; + krb5_cc_cursor cursor; + krb5_principal tmp; ++ krb5_flags matchflags = KRB5_TC_MATCH_IS_SKEY; + + const char *c_name; + char newcache[300]; +@@ -311,9 +355,90 @@ cc_test(krb5_context context, const char *name, krb5_flags flags) + kret = krb5_cc_destroy(context, id2); + CHECK(kret, "destroy id2"); + ++ /* ----------------------------------------------------- */ ++ /* Test credential removal */ ++ kret = krb5_cc_resolve(context, name, &id); ++ CHECK(kret, "resolving for remove"); ++ ++ kret = krb5_cc_initialize(context, id, test_creds.client); ++ CHECK(kret, "initialize for remove"); ++ check_num_entries(context, id, 0, __LINE__); ++ ++ kret = krb5_cc_store_cred(context, id, &test_creds); ++ CHECK(kret, "store for remove (first pass)"); ++ check_num_entries(context, id, 1, __LINE__); /* 1 */ ++ ++ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds); ++ CHECK(kret, "removing credential (first pass)"); ++ check_num_entries(context, id, 0, __LINE__); /* empty */ ++ ++ kret = krb5_cc_store_cred(context, id, &test_creds); ++ CHECK(kret, "first store for remove (second pass)"); ++ check_num_entries(context, id, 1, __LINE__); /* 1 */ ++ ++ kret = krb5_cc_store_cred(context, id, &test_creds2); ++ CHECK(kret, "second store for remove (second pass)"); ++ check_num_entries(context, id, 2, __LINE__); /* 1, 2 */ ++ ++ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds2); ++ CHECK(kret, "first remove (second pass)"); ++ check_num_entries(context, id, 1, __LINE__); /* 1 */ ++ ++ kret = krb5_cc_store_cred(context, id, &test_creds2); ++ CHECK(kret, "third store for remove (second pass)"); ++ check_num_entries(context, id, 2, __LINE__); /* 1, 2 */ ++ ++ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds); ++ CHECK(kret, "second remove (second pass)"); ++ check_num_entries(context, id, 1, __LINE__); /* 2 */ ++ ++ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds2); ++ CHECK(kret, "third remove (second pass)"); ++ check_num_entries(context, id, 0, __LINE__); /* empty */ ++ ++ kret = krb5_cc_destroy(context, id); ++ CHECK(kret, "destruction for remove"); ++ ++ /* Test removal with iteration. */ ++ kret = krb5_cc_resolve(context, name, &id); ++ CHECK(kret, "resolving for remove-iter"); ++ ++ kret = krb5_cc_initialize(context, id, test_creds.client); ++ CHECK(kret, "initialize for remove-iter"); ++ ++ kret = krb5_cc_store_cred(context, id, &test_creds); ++ CHECK(kret, "first store for remove-iter"); ++ ++ kret = krb5_cc_store_cred(context, id, &test_creds2); ++ CHECK(kret, "second store for remove-iter"); ++ ++ kret = krb5_cc_start_seq_get(context, id, &cursor); ++ CHECK(kret, "start_seq_get for remove-iter"); ++ ++ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds); ++ CHECK(kret, "remove for remove-iter"); ++ ++ while (1) { ++ /* The removed credential may or may not be present in the cache - ++ * either behavior is technically correct. */ ++ kret = krb5_cc_next_cred(context, id, &cursor, &creds); ++ if (kret == KRB5_CC_END) ++ break; ++ CHECK(kret, "next_cred for remove-iter: %s"); ++ ++ CHECK(creds.times.endtime == 0, "no-lifetime cred"); ++ ++ krb5_free_cred_contents(context, &creds); ++ } ++ ++ kret = krb5_cc_end_seq_get(context, id, &cursor); ++ CHECK(kret, "end_seq_get for remove-iter"); ++ ++ kret = krb5_cc_destroy(context, id); ++ CHECK(kret, "destruction for remove-iter"); ++ + free(save_type); + free_test_cred(context); +- + } + + /* diff --git a/krb5.spec b/krb5.spec index 76cf5ae..9fbbb43 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 7%{?dist} +Release: 8%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -74,6 +74,8 @@ Patch100: Properly-size-ifdef-in-k5_cccol_lock.patch Patch101: Fix-memory-leak-in-none-replay-cache-type.patch Patch102: Become-FIPS-aware-with-3DES.patch Patch103: FIPS-aware-SPAKE-group-negotiation.patch +Patch104: Clarify-header-comment-for-krb5_cc_start_seq_get.patch +Patch105: Implement-krb5_cc_remove_cred-for-remaining-types.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -713,6 +715,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Apr 11 2019 Robbie Harwood - 1.17-8 +- Implement krb5_cc_remove_cred for remaining types +- Resolves: #1693836 + * Mon Apr 01 2019 Robbie Harwood - 1.17-7 - FIPS-aware SPAKE group negotiation From 05efb47898b7a29edcfca4b1f0d7c57e0a2bab89 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 11 Apr 2019 16:42:55 -0400 Subject: [PATCH 093/304] Remove Kerberos v4 support vestiges (including ktany support) --- ...on-and-enctype-flag-for-deprecations.patch | 2 +- Add-tests-for-KCM-ccache-type.patch | 2 +- Address-some-optimized-out-memset-calls.patch | 2 +- ...llocating-a-register-in-zap-assembly.patch | 2 +- ...er-comment-for-krb5_cc_start_seq_get.patch | 2 +- ...emory-leak-in-none-replay-cache-type.patch | 2 +- ...5_cc_remove_cred-for-remaining-types.patch | 2 +- ...ebug-log-proper-ticket-enctype-names.patch | 2 +- ...ec-always-log-non-permitted-enctypes.patch | 2 +- ...ype-names-in-KDC-logs-human-readable.patch | 2 +- Mark-deprecated-enctypes-when-used.patch | 2 +- Properly-size-ifdef-in-k5_cccol_lock.patch | 2 +- ...beros-v4-support-vestiges-from-ccapi.patch | 1604 ++++ ...api-related-comments-in-configure.ac.patch | 34 + ...ygen-generated-HTML-output-for-ccapi.patch | 7653 +++++++++++++++++ ...admin-RPC-support-for-setting-v4-key.patch | 466 + Remove-srvtab-support.patch | 1410 +++ krb5-1.11-kpasswdtest.patch | 2 +- krb5-1.11-run_user_0.patch | 2 +- krb5-1.12-api.patch | 2 +- krb5-1.12-ktany.patch | 366 - krb5-1.13-dirsrv-accountlock.patch | 2 +- krb5-1.15-beta1-buildconf.patch | 2 +- ...patch => krb5-1.17-Become-FIPS-aware.patch | 4 +- ...7-FIPS-aware-SPAKE-group-negotiation.patch | 4 +- ...S-mode-add-plaintext-fallback-for-RC.patch | 5 +- ...1.17-Use-openssl-s-PRNG-in-FIPS-mode.patch | 4 +- krb5-1.3.1-dns.patch | 2 +- krb5-1.9-debuginfo.patch | 2 +- krb5.spec | 22 +- 30 files changed, 11208 insertions(+), 402 deletions(-) create mode 100644 Remove-Kerberos-v4-support-vestiges-from-ccapi.patch create mode 100644 Remove-ccapi-related-comments-in-configure.ac.patch create mode 100644 Remove-doxygen-generated-HTML-output-for-ccapi.patch create mode 100644 Remove-kadmin-RPC-support-for-setting-v4-key.patch create mode 100644 Remove-srvtab-support.patch delete mode 100644 krb5-1.12-ktany.patch rename Become-FIPS-aware-with-3DES.patch => krb5-1.17-Become-FIPS-aware.patch (98%) rename FIPS-aware-SPAKE-group-negotiation.patch => krb5-1.17-FIPS-aware-SPAKE-group-negotiation.patch (90%) rename In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch => krb5-1.17-In-FIPS-mode-add-plaintext-fallback-for-RC.patch (98%) rename Use-openssl-s-PRNG-in-FIPS-mode.patch => krb5-1.17-Use-openssl-s-PRNG-in-FIPS-mode.patch (89%) diff --git a/Add-function-and-enctype-flag-for-deprecations.patch b/Add-function-and-enctype-flag-for-deprecations.patch index 687eba4..61c865e 100644 --- a/Add-function-and-enctype-flag-for-deprecations.patch +++ b/Add-function-and-enctype-flag-for-deprecations.patch @@ -1,4 +1,4 @@ -From 15d1cbd15d4ea8113fc5dd7bc446ca2b99ab4085 Mon Sep 17 00:00:00 2001 +From 461e3a4d81c73db832401592d417489dc0151a2c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 16:16:57 -0500 Subject: [PATCH] Add function and enctype flag for deprecations diff --git a/Add-tests-for-KCM-ccache-type.patch b/Add-tests-for-KCM-ccache-type.patch index 177a042..a20a682 100644 --- a/Add-tests-for-KCM-ccache-type.patch +++ b/Add-tests-for-KCM-ccache-type.patch @@ -1,4 +1,4 @@ -From e863c1e068775d066241edacff2bdb50cf1be27c Mon Sep 17 00:00:00 2001 +From 306c0260dca7809c90dfa9e8889a6bd2401cee84 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Nov 2018 00:27:35 -0500 Subject: [PATCH] Add tests for KCM ccache type diff --git a/Address-some-optimized-out-memset-calls.patch b/Address-some-optimized-out-memset-calls.patch index 60cd6a0..6572ba0 100644 --- a/Address-some-optimized-out-memset-calls.patch +++ b/Address-some-optimized-out-memset-calls.patch @@ -1,4 +1,4 @@ -From d3690641a5eecf8ee031053bdedbaa4e249cc771 Mon Sep 17 00:00:00 2001 +From 3dd99db324de1492444aab3e5468aea5f1767c6d Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 30 Dec 2018 16:40:28 -0500 Subject: [PATCH] Address some optimized-out memset() calls diff --git a/Avoid-allocating-a-register-in-zap-assembly.patch b/Avoid-allocating-a-register-in-zap-assembly.patch index 3406b63..b0c139f 100644 --- a/Avoid-allocating-a-register-in-zap-assembly.patch +++ b/Avoid-allocating-a-register-in-zap-assembly.patch @@ -1,4 +1,4 @@ -From d8cba3893687a3976569fef97c1614b9b51ad573 Mon Sep 17 00:00:00 2001 +From 26dc343d4e59ef0f80e1ecca09b40f120b79d809 Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Thu, 3 Jan 2019 17:19:32 +0100 Subject: [PATCH] Avoid allocating a register in zap() assembly diff --git a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch index a36c364..b898655 100644 --- a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch +++ b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch @@ -1,4 +1,4 @@ -From 7f4af607c9362acc596bc63ca4c46699327d0cae Mon Sep 17 00:00:00 2001 +From 18dd4d5c622238d1607671198cf2b2ddec9abda5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Apr 2019 14:18:57 -0400 Subject: [PATCH] Clarify header comment for krb5_cc_start_seq_get() diff --git a/Fix-memory-leak-in-none-replay-cache-type.patch b/Fix-memory-leak-in-none-replay-cache-type.patch index 8141247..07e1091 100644 --- a/Fix-memory-leak-in-none-replay-cache-type.patch +++ b/Fix-memory-leak-in-none-replay-cache-type.patch @@ -1,4 +1,4 @@ -From 472131596213337ae01b792aef2fb2580738a1df Mon Sep 17 00:00:00 2001 +From 050acb871c242931b3fb51c59461f22555046d19 Mon Sep 17 00:00:00 2001 From: Corene Casper Date: Sat, 16 Feb 2019 00:49:26 -0500 Subject: [PATCH] Fix memory leak in 'none' replay cache type diff --git a/Implement-krb5_cc_remove_cred-for-remaining-types.patch b/Implement-krb5_cc_remove_cred-for-remaining-types.patch index dfb57bd..a656d57 100644 --- a/Implement-krb5_cc_remove_cred-for-remaining-types.patch +++ b/Implement-krb5_cc_remove_cred-for-remaining-types.patch @@ -1,4 +1,4 @@ -From f1449621399def78384c34216454bd1dfceefb8f Mon Sep 17 00:00:00 2001 +From 57ce492d6700ca6417cc43f3e97e0186b2cdfa90 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 1 Apr 2019 14:28:48 -0400 Subject: [PATCH] Implement krb5_cc_remove_cred for remaining types diff --git a/In-kpropd-debug-log-proper-ticket-enctype-names.patch b/In-kpropd-debug-log-proper-ticket-enctype-names.patch index 1450698..8f0c0ca 100644 --- a/In-kpropd-debug-log-proper-ticket-enctype-names.patch +++ b/In-kpropd-debug-log-proper-ticket-enctype-names.patch @@ -1,4 +1,4 @@ -From 220762a0bdc5151a0d4a25bc7e56251ef351b560 Mon Sep 17 00:00:00 2001 +From c06d20bf241059059cc3ffd810a44e310ff9970d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 13:41:16 -0500 Subject: [PATCH] In kpropd, debug-log proper ticket enctype names diff --git a/In-rd_req_dec-always-log-non-permitted-enctypes.patch b/In-rd_req_dec-always-log-non-permitted-enctypes.patch index b36321a..9947e2f 100644 --- a/In-rd_req_dec-always-log-non-permitted-enctypes.patch +++ b/In-rd_req_dec-always-log-non-permitted-enctypes.patch @@ -1,4 +1,4 @@ -From 28528d8169d9af3830b3a162c525a8e1a71f05f4 Mon Sep 17 00:00:00 2001 +From 6a316b681a2e0b6917285b9a0cdde605d463288b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Jan 2019 17:14:42 -0500 Subject: [PATCH] In rd_req_dec, always log non-permitted enctypes diff --git a/Make-etype-names-in-KDC-logs-human-readable.patch b/Make-etype-names-in-KDC-logs-human-readable.patch index 9915f69..6fd40d7 100644 --- a/Make-etype-names-in-KDC-logs-human-readable.patch +++ b/Make-etype-names-in-KDC-logs-human-readable.patch @@ -1,4 +1,4 @@ -From d32d0cfbbe1386b2cf9b31682df4c35ccc029bda Mon Sep 17 00:00:00 2001 +From 2a8005296c3da39f6d0c6ecd48b950447897af91 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 8 Jan 2019 17:42:35 -0500 Subject: [PATCH] Make etype names in KDC logs human-readable diff --git a/Mark-deprecated-enctypes-when-used.patch b/Mark-deprecated-enctypes-when-used.patch index 6faf378..596c74b 100644 --- a/Mark-deprecated-enctypes-when-used.patch +++ b/Mark-deprecated-enctypes-when-used.patch @@ -1,4 +1,4 @@ -From 0f4d9265c808a1e78fb90b54d39e58f3f89e672f Mon Sep 17 00:00:00 2001 +From 6d265afd53ead9290948b5ba07438b6a91939bfd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 10 Jan 2019 16:34:54 -0500 Subject: [PATCH] Mark deprecated enctypes when used diff --git a/Properly-size-ifdef-in-k5_cccol_lock.patch b/Properly-size-ifdef-in-k5_cccol_lock.patch index 23fb478..bdaa775 100644 --- a/Properly-size-ifdef-in-k5_cccol_lock.patch +++ b/Properly-size-ifdef-in-k5_cccol_lock.patch @@ -1,4 +1,4 @@ -From 8bdcbe143adc71918bd6e5f2e075df6b8e31267a Mon Sep 17 00:00:00 2001 +From ec9e4597188234e402cd318aebe0fa0a3587a993 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Feb 2019 11:50:35 -0500 Subject: [PATCH] Properly size #ifdef in k5_cccol_lock() diff --git a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch new file mode 100644 index 0000000..12c58a4 --- /dev/null +++ b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch @@ -0,0 +1,1604 @@ +From 7fa37c0c80b3bbd611ba27dd162aa0b6016c20b3 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 4 Apr 2019 14:37:38 -0400 +Subject: [PATCH] Remove Kerberos v4 support vestiges from ccapi + +(cherry picked from commit 51395dc956ce9eef27c0d6843561d3d3828b03cd) +--- + src/ccapi/common/cci_cred_union.c | 280 +------------------------ + src/ccapi/lib/ccapi_v2.c | 34 +-- + src/ccapi/lib/win/OldCC/ccapi.h | 20 -- + src/ccapi/server/ccs_ccache.c | 69 +----- + src/ccapi/test/test_ccapi_ccache.c | 223 +++----------------- + src/ccapi/test/test_ccapi_constants.c | 2 - + src/ccapi/test/test_ccapi_context.c | 3 - + src/ccapi/test/test_ccapi_v2.c | 89 -------- + src/include/CredentialsCache.h | 156 ++++---------- + src/include/CredentialsCache2.h | 26 +-- + src/lib/krb5/ccache/ccapi/stdcc.c | 2 - + src/lib/krb5/ccache/ccapi/stdcc_util.c | 8 +- + src/windows/kfwlogon/kfwlogon.h | 2 +- + src/windows/leashdll/leash-int.h | 2 +- + src/windows/lib/cacheapi.h | 53 +---- + 15 files changed, 98 insertions(+), 871 deletions(-) + +diff --git a/src/ccapi/common/cci_cred_union.c b/src/ccapi/common/cci_cred_union.c +index 4c8981610..424a93dab 100644 +--- a/src/ccapi/common/cci_cred_union.c ++++ b/src/ccapi/common/cci_cred_union.c +@@ -25,181 +25,6 @@ + + #include "cci_common.h" + +-#ifdef TARGET_OS_MAC +-#pragma mark - +-#endif +- +-/* ------------------------------------------------------------------------ */ +- +-static cc_uint32 cci_credentials_v4_release (cc_credentials_v4_t *io_v4creds) +-{ +- cc_int32 err = ccNoError; +- +- if (!io_v4creds) { err = ccErrBadParam; } +- +- if (!err) { +- memset (io_v4creds, 0, sizeof (*io_v4creds)); +- free (io_v4creds); +- } +- +- return err; +-} +- +-/* ------------------------------------------------------------------------ */ +- +-static cc_uint32 cci_credentials_v4_read (cc_credentials_v4_t **out_v4creds, +- k5_ipc_stream io_stream) +-{ +- cc_int32 err = ccNoError; +- cc_credentials_v4_t *v4creds = NULL; +- +- if (!io_stream ) { err = cci_check_error (ccErrBadParam); } +- if (!out_v4creds) { err = cci_check_error (ccErrBadParam); } +- +- if (!err) { +- v4creds = malloc (sizeof (*v4creds)); +- if (!v4creds) { err = cci_check_error (ccErrNoMem); } +- } +- +- if (!err) { +- err = krb5int_ipc_stream_read_uint32 (io_stream, &v4creds->version); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_read (io_stream, v4creds->principal, cc_v4_name_size); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_read (io_stream, v4creds->principal_instance, cc_v4_instance_size); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_read (io_stream, v4creds->service, cc_v4_name_size); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_read (io_stream, v4creds->service_instance, cc_v4_instance_size); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_read (io_stream, v4creds->realm, cc_v4_realm_size); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_read (io_stream, v4creds->session_key, cc_v4_key_size); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_read_int32 (io_stream, &v4creds->kvno); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_read_int32 (io_stream, &v4creds->string_to_key_type); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_read_time (io_stream, &v4creds->issue_date); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_read_int32 (io_stream, &v4creds->lifetime); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_read_uint32 (io_stream, &v4creds->address); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_read_int32 (io_stream, &v4creds->ticket_size); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_read (io_stream, v4creds->ticket, cc_v4_ticket_size); +- } +- +- if (!err) { +- *out_v4creds = v4creds; +- v4creds = NULL; +- } +- +- free (v4creds); +- +- return cci_check_error (err); +-} +- +-/* ------------------------------------------------------------------------ */ +- +-static cc_uint32 cci_credentials_v4_write (cc_credentials_v4_t *in_v4creds, +- k5_ipc_stream io_stream) +-{ +- cc_int32 err = ccNoError; +- +- if (!io_stream ) { err = cci_check_error (ccErrBadParam); } +- if (!in_v4creds) { err = cci_check_error (ccErrBadParam); } +- +- if (!err) { +- err = krb5int_ipc_stream_write_uint32 (io_stream, in_v4creds->version); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_write (io_stream, in_v4creds->principal, cc_v4_name_size); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_write (io_stream, in_v4creds->principal_instance, cc_v4_instance_size); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_write (io_stream, in_v4creds->service, cc_v4_name_size); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_write (io_stream, in_v4creds->service_instance, cc_v4_instance_size); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_write (io_stream, in_v4creds->realm, cc_v4_realm_size); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_write (io_stream, in_v4creds->session_key, cc_v4_key_size); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_write_int32 (io_stream, in_v4creds->kvno); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_write_int32 (io_stream, in_v4creds->string_to_key_type); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_write_time (io_stream, in_v4creds->issue_date); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_write_int32 (io_stream, in_v4creds->lifetime); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_write_uint32 (io_stream, in_v4creds->address); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_write_int32 (io_stream, in_v4creds->ticket_size); +- } +- +- if (!err) { +- err = krb5int_ipc_stream_write (io_stream, in_v4creds->ticket, cc_v4_ticket_size); +- } +- +- return cci_check_error (err); +-} +- +-#ifdef TARGET_OS_MAC +-#pragma mark - +-#endif +- + /* ------------------------------------------------------------------------ */ + + static cc_uint32 cci_cc_data_contents_release (cc_data *io_ccdata) +@@ -600,9 +425,7 @@ cc_uint32 cci_credentials_union_release (cc_credentials_union *io_cred_union) + if (!io_cred_union) { err = ccErrBadParam; } + + if (!err) { +- if (io_cred_union->version == cc_credentials_v4) { +- cci_credentials_v4_release (io_cred_union->credentials.credentials_v4); +- } else if (io_cred_union->version == cc_credentials_v5) { ++ if (io_cred_union->version == cc_credentials_v5) { + cci_credentials_v5_release (io_cred_union->credentials.credentials_v5); + } + free (io_cred_union); +@@ -632,11 +455,7 @@ cc_uint32 cci_credentials_union_read (cc_credentials_union **out_credentials_uni + } + + if (!err) { +- if (credentials_union->version == cc_credentials_v4) { +- err = cci_credentials_v4_read (&credentials_union->credentials.credentials_v4, +- io_stream); +- +- } else if (credentials_union->version == cc_credentials_v5) { ++ if (credentials_union->version == cc_credentials_v5) { + err = cci_credentials_v5_read (&credentials_union->credentials.credentials_v5, + io_stream); + +@@ -671,11 +490,7 @@ cc_uint32 cci_credentials_union_write (const cc_credentials_union *in_credential + } + + if (!err) { +- if (in_credentials_union->version == cc_credentials_v4) { +- err = cci_credentials_v4_write (in_credentials_union->credentials.credentials_v4, +- io_stream); +- +- } else if (in_credentials_union->version == cc_credentials_v5) { ++ if (in_credentials_union->version == cc_credentials_v5) { + err = cci_credentials_v5_write (in_credentials_union->credentials.credentials_v5, + io_stream); + +@@ -714,11 +529,7 @@ cc_uint32 cci_cred_union_release (cred_union *io_cred_union) + if (!io_cred_union) { err = ccErrBadParam; } + + if (!err) { +- if (io_cred_union->cred_type == CC_CRED_V4) { +- memset (io_cred_union->cred.pV4Cred, 0, sizeof (cc_credentials_v4_compat)); +- free (io_cred_union->cred.pV4Cred); +- +- } else if (io_cred_union->cred_type == CC_CRED_V5) { ++ if (io_cred_union->cred_type == CC_CRED_V5) { + free (io_cred_union->cred.pV5Cred->client); + free (io_cred_union->cred.pV5Cred->server); + cci_cc_data_contents_release (&io_cred_union->cred.pV5Cred->keyblock); +@@ -829,36 +640,7 @@ cc_uint32 cci_credentials_union_to_cred_union (const cc_credentials_union *in_c + } + + if (!err) { +- if (in_credentials_union->version == cc_credentials_v4) { +- cc_credentials_v4_compat *compat_v4creds = NULL; +- +- compat_v4creds = malloc (sizeof (*compat_v4creds)); +- if (!compat_v4creds) { err = cci_check_error (ccErrNoMem); } +- +- if (!err) { +- cc_credentials_v4_t *v4creds = in_credentials_union->credentials.credentials_v4; +- +- compat_cred_union->cred_type = CC_CRED_V4; +- compat_cred_union->cred.pV4Cred = compat_v4creds; +- +- compat_v4creds->kversion = v4creds->version; +- strncpy (compat_v4creds->principal, v4creds->principal, KRB_NAME_SZ+1); +- strncpy (compat_v4creds->principal_instance, v4creds->principal_instance, KRB_INSTANCE_SZ+1); +- strncpy (compat_v4creds->service, v4creds->service, KRB_NAME_SZ+1); +- strncpy (compat_v4creds->service_instance, v4creds->service_instance, KRB_INSTANCE_SZ+1); +- strncpy (compat_v4creds->realm, v4creds->realm, KRB_REALM_SZ+1); +- memcpy (compat_v4creds->session_key, v4creds->session_key, 8); +- compat_v4creds->kvno = v4creds->kvno; +- compat_v4creds->str_to_key = v4creds->string_to_key_type; +- compat_v4creds->issue_date = v4creds->issue_date; +- compat_v4creds->lifetime = v4creds->lifetime; +- compat_v4creds->address = v4creds->address; +- compat_v4creds->ticket_sz = v4creds->ticket_size; +- memcpy (compat_v4creds->ticket, v4creds->ticket, MAX_V4_CRED_LEN); +- compat_v4creds->oops = 0; +- } +- +- } else if (in_credentials_union->version == cc_credentials_v5) { ++ if (in_credentials_union->version == cc_credentials_v5) { + cc_credentials_v5_t *v5creds = in_credentials_union->credentials.credentials_v5; + cc_credentials_v5_compat *compat_v5creds = NULL; + +@@ -951,36 +733,7 @@ cc_uint32 cci_cred_union_to_credentials_union (const cred_union *in_cred_un + } + + if (!err) { +- if (in_cred_union->cred_type == CC_CRED_V4) { +- cc_credentials_v4_compat *compat_v4creds = in_cred_union->cred.pV4Cred; +- cc_credentials_v4_t *v4creds = NULL; +- +- if (!err) { +- v4creds = malloc (sizeof (*v4creds)); +- if (!v4creds) { err = cci_check_error (ccErrNoMem); } +- } +- +- if (!err) { +- creds_union->version = cc_credentials_v4; +- creds_union->credentials.credentials_v4 = v4creds; +- +- v4creds->version = compat_v4creds->kversion; +- strncpy (v4creds->principal, compat_v4creds->principal, KRB_NAME_SZ); +- strncpy (v4creds->principal_instance, compat_v4creds->principal_instance, KRB_INSTANCE_SZ); +- strncpy (v4creds->service, compat_v4creds->service, KRB_NAME_SZ); +- strncpy (v4creds->service_instance, compat_v4creds->service_instance, KRB_INSTANCE_SZ); +- strncpy (v4creds->realm, compat_v4creds->realm, KRB_REALM_SZ); +- memcpy (v4creds->session_key, compat_v4creds->session_key, 8); +- v4creds->kvno = compat_v4creds->kvno; +- v4creds->string_to_key_type = compat_v4creds->str_to_key; +- v4creds->issue_date = compat_v4creds->issue_date; +- v4creds->lifetime = compat_v4creds->lifetime; +- v4creds->address = compat_v4creds->address; +- v4creds->ticket_size = compat_v4creds->ticket_sz; +- memcpy (v4creds->ticket, compat_v4creds->ticket, MAX_V4_CRED_LEN); +- } +- +- } else if (in_cred_union->cred_type == CC_CRED_V5) { ++ if (in_cred_union->cred_type == CC_CRED_V5) { + cc_credentials_v5_compat *compat_v5creds = in_cred_union->cred.pV5Cred; + cc_credentials_v5_t *v5creds = NULL; + +@@ -1072,26 +825,7 @@ cc_uint32 cci_cred_union_compare_to_credentials_union (const cred_union + if (!out_equal ) { err = cci_check_error (ccErrBadParam); } + + if (!err) { +- if (in_cred_union_compat->cred_type == CC_CRED_V4 && +- in_credentials_union->version == cc_credentials_v4) { +- cc_credentials_v4_compat *old_creds_v4 = in_cred_union_compat->cred.pV4Cred; +- cc_credentials_v4_t *new_creds_v4 = in_credentials_union->credentials.credentials_v4; +- +- if (old_creds_v4 && new_creds_v4 && +- !strcmp (old_creds_v4->principal, +- new_creds_v4->principal) && +- !strcmp (old_creds_v4->principal_instance, +- new_creds_v4->principal_instance) && +- !strcmp (old_creds_v4->service, +- new_creds_v4->service) && +- !strcmp (old_creds_v4->service_instance, +- new_creds_v4->service_instance) && +- !strcmp (old_creds_v4->realm, new_creds_v4->realm) && +- (old_creds_v4->issue_date == (long) new_creds_v4->issue_date)) { +- equal = 1; +- } +- +- } else if (in_cred_union_compat->cred_type == CC_CRED_V5 && ++ if (in_cred_union_compat->cred_type == CC_CRED_V5 && + in_credentials_union->version == cc_credentials_v5) { + cc_credentials_v5_compat *old_creds_v5 = in_cred_union_compat->cred.pV5Cred; + cc_credentials_v5_t *new_creds_v5 = in_credentials_union->credentials.credentials_v5; +diff --git a/src/ccapi/lib/ccapi_v2.c b/src/ccapi/lib/ccapi_v2.c +index 8a831d796..ae9b790b0 100644 +--- a/src/ccapi/lib/ccapi_v2.c ++++ b/src/ccapi/lib/ccapi_v2.c +@@ -44,10 +44,7 @@ static cc_int32 cci_remap_version (cc_int32 in_v2_version, + if (!out_v3_version) { err = cci_check_error (ccErrBadParam); } + + if (!err) { +- if (in_v2_version == CC_CRED_V4) { +- *out_v3_version = cc_credentials_v4; +- +- } else if (in_v2_version == CC_CRED_V5) { ++ if (in_v2_version == CC_CRED_V5) { + *out_v3_version = cc_credentials_v5; + + } else { +@@ -450,10 +447,7 @@ cc_result cc_get_cred_version (apiCB *in_context, + } + + if (!err) { +- if (compat_version == cc_credentials_v4) { +- *out_version = CC_CRED_V4; +- +- } else if (compat_version == cc_credentials_v5) { ++ if (compat_version == cc_credentials_v5) { + *out_version = CC_CRED_V5; + + } else { +@@ -642,10 +636,6 @@ cc_result cc_seq_fetch_NCs_next (apiCB *in_context, + if (!out_ccache ) { err = cci_check_error (ccErrBadParam); } + if (!in_iterator) { err = cci_check_error (ccErrBadParam); } + +- /* CCache iterators need to return some ccaches twice (when v3 ccache has +- * two kinds of credentials). To do that, we return such ccaches twice +- * v4 first, then v5. */ +- + if (!err) { + err = cci_ccache_iterator_get_saved_ccache_name (iterator, + &saved_ccache_name); +@@ -674,25 +664,7 @@ cc_result cc_seq_fetch_NCs_next (apiCB *in_context, + } + + if (!err) { +- if (version == cc_credentials_v4_v5) { +- cc_string_t name = NULL; +- +- err = cci_ccache_set_compat_version (ccache, cc_credentials_v4); +- +- if (!err) { +- err = ccapi_ccache_get_name (ccache, &name); +- } +- +- if (!err) { +- err = cci_ccache_iterator_set_saved_ccache_name (iterator, +- name->data); +- } +- +- if (name) { ccapi_string_release (name); } +- +- } else { +- err = cci_ccache_set_compat_version (ccache, version); +- } ++ err = cci_ccache_set_compat_version (ccache, version); + } + } + } +diff --git a/src/ccapi/lib/win/OldCC/ccapi.h b/src/ccapi/lib/win/OldCC/ccapi.h +index 82512771a..4d6f3faaf 100644 +--- a/src/ccapi/lib/win/OldCC/ccapi.h ++++ b/src/ccapi/lib/win/OldCC/ccapi.h +@@ -80,7 +80,6 @@ enum __MIDL_ccapi_0003 + { KRB_NAME_SZ = 40, + KRB_INSTANCE_SZ = 40, + KRB_REALM_SZ = 40, +- MAX_V4_CRED_LEN = 1250 + } ; + typedef struct _NC_INFO + { +@@ -95,24 +94,6 @@ typedef struct _NC_INFO_LIST + /* [size_is] */ NC_INFO *info; + } NC_INFO_LIST; + +-typedef struct _V4_CRED +- { +- CC_UCHAR kversion; +- CC_CHAR principal[ 41 ]; +- CC_CHAR principal_instance[ 41 ]; +- CC_CHAR service[ 41 ]; +- CC_CHAR service_instance[ 41 ]; +- CC_CHAR realm[ 41 ]; +- CC_UCHAR session_key[ 8 ]; +- CC_INT32 kvno; +- CC_INT32 str_to_key; +- CC_INT32 issue_date; +- CC_INT32 lifetime; +- CC_UINT32 address; +- CC_INT32 ticket_sz; +- CC_UCHAR ticket[ 1250 ]; +- } V4_CRED; +- + typedef struct _CC_DATA + { + CC_UINT32 type; +@@ -145,7 +126,6 @@ typedef struct _V5_CRED + + typedef /* [switch_type] */ union _CRED_PTR_UNION + { +- /* [case()] */ V4_CRED *pV4Cred; + /* [case()] */ V5_CRED *pV5Cred; + } CRED_PTR_UNION; + +diff --git a/src/ccapi/server/ccs_ccache.c b/src/ccapi/server/ccs_ccache.c +index 65c59e4be..645380a7b 100644 +--- a/src/ccapi/server/ccs_ccache.c ++++ b/src/ccapi/server/ccs_ccache.c +@@ -31,19 +31,16 @@ struct ccs_ccache_d { + ccs_lock_state_t lock_state; + cc_uint32 creds_version; + char *name; +- char *v4_principal; + char *v5_principal; + cc_time_t last_default_time; + cc_time_t last_changed_time; +- cc_uint32 kdc_time_offset_v4_valid; +- cc_time_t kdc_time_offset_v4; + cc_uint32 kdc_time_offset_v5_valid; + cc_time_t kdc_time_offset_v5; + ccs_credentials_list_t credentials; + ccs_callback_array_t change_callbacks; + }; + +-struct ccs_ccache_d ccs_ccache_initializer = { NULL, NULL, 0, NULL, NULL, NULL, 0, 0, 0, 0, 0, 0, NULL, NULL }; ++struct ccs_ccache_d ccs_ccache_initializer = { NULL, NULL, 0, NULL, NULL, 0, 0, 0, 0, NULL, NULL }; + + /* ------------------------------------------------------------------------ */ + +@@ -88,11 +85,7 @@ cc_int32 ccs_ccache_new (ccs_ccache_t *out_ccache, + if (!err) { + ccache->creds_version = in_creds_version; + +- if (ccache->creds_version == cc_credentials_v4) { +- ccache->v4_principal = strdup (in_principal); +- if (!ccache->v4_principal) { err = cci_check_error (ccErrNoMem); } +- +- } else if (ccache->creds_version == cc_credentials_v5) { ++ if (ccache->creds_version == cc_credentials_v5) { + ccache->v5_principal = strdup (in_principal); + if (!ccache->v5_principal) { err = cci_check_error (ccErrNoMem); } + +@@ -147,7 +140,6 @@ cc_int32 ccs_ccache_reset (ccs_ccache_t io_ccache, + const char *in_principal) + { + cc_int32 err = ccNoError; +- char *v4_principal = NULL; + char *v5_principal = NULL; + ccs_credentials_list_t credentials = NULL; + +@@ -158,11 +150,7 @@ cc_int32 ccs_ccache_reset (ccs_ccache_t io_ccache, + if (!err) { + io_ccache->creds_version = in_creds_version; + +- if (io_ccache->creds_version == cc_credentials_v4) { +- v4_principal = strdup (in_principal); +- if (!v4_principal) { err = cci_check_error (ccErrNoMem); } +- +- } else if (io_ccache->creds_version == cc_credentials_v5) { ++ if (io_ccache->creds_version == cc_credentials_v5) { + v5_principal = strdup (in_principal); + if (!v5_principal) { err = cci_check_error (ccErrNoMem); } + +@@ -176,15 +164,9 @@ cc_int32 ccs_ccache_reset (ccs_ccache_t io_ccache, + } + + if (!err) { +- io_ccache->kdc_time_offset_v4 = 0; +- io_ccache->kdc_time_offset_v4_valid = 0; + io_ccache->kdc_time_offset_v5 = 0; + io_ccache->kdc_time_offset_v5_valid = 0; + +- if (io_ccache->v4_principal) { free (io_ccache->v4_principal); } +- io_ccache->v4_principal = v4_principal; +- v4_principal = NULL; /* take ownership */ +- + if (io_ccache->v5_principal) { free (io_ccache->v5_principal); } + io_ccache->v5_principal = v5_principal; + v5_principal = NULL; /* take ownership */ +@@ -196,7 +178,6 @@ cc_int32 ccs_ccache_reset (ccs_ccache_t io_ccache, + err = ccs_ccache_changed (io_ccache, io_cache_collection); + } + +- free (v4_principal); + free (v5_principal); + ccs_credentials_list_release (credentials); + +@@ -250,7 +231,6 @@ cc_int32 ccs_ccache_release (ccs_ccache_t io_ccache) + cci_identifier_release (io_ccache->identifier); + ccs_lock_state_release (io_ccache->lock_state); + free (io_ccache->name); +- free (io_ccache->v4_principal); + free (io_ccache->v5_principal); + ccs_credentials_list_release (io_ccache->credentials); + ccs_callback_array_release (io_ccache->change_callbacks); +@@ -607,15 +587,8 @@ static cc_int32 ccs_ccache_get_principal (ccs_ccache_t io_ccache, + err = krb5int_ipc_stream_read_uint32 (in_request_data, &version); + } + +- if (!err && version == cc_credentials_v4_v5) { +- err = cci_check_error (ccErrBadCredentialsVersion); +- } +- + if (!err) { +- if (version == cc_credentials_v4) { +- err = krb5int_ipc_stream_write_string (io_reply_data, io_ccache->v4_principal); +- +- } else if (version == cc_credentials_v5) { ++ if (version == cc_credentials_v5) { + err = krb5int_ipc_stream_write_string (io_reply_data, io_ccache->v5_principal); + + } else { +@@ -652,16 +625,7 @@ static cc_int32 ccs_ccache_set_principal (ccs_ccache_t io_ccache, + + if (!err) { + /* reset KDC time offsets because they are per-KDC */ +- if (version == cc_credentials_v4) { +- io_ccache->kdc_time_offset_v4 = 0; +- io_ccache->kdc_time_offset_v4_valid = 0; +- +- if (io_ccache->v4_principal) { free (io_ccache->v4_principal); } +- io_ccache->v4_principal = principal; +- principal = NULL; /* take ownership */ +- +- +- } else if (version == cc_credentials_v5) { ++ if (version == cc_credentials_v5) { + io_ccache->kdc_time_offset_v5 = 0; + io_ccache->kdc_time_offset_v5_valid = 0; + +@@ -998,14 +962,7 @@ static cc_int32 ccs_ccache_get_kdc_time_offset (ccs_ccache_t io_ccache + } + + if (!err) { +- if (cred_vers == cc_credentials_v4) { +- if (io_ccache->kdc_time_offset_v4_valid) { +- err = krb5int_ipc_stream_write_time (io_reply_data, io_ccache->kdc_time_offset_v4); +- } else { +- err = cci_check_error (ccErrTimeOffsetNotSet); +- } +- +- } else if (cred_vers == cc_credentials_v5) { ++ if (cred_vers == cc_credentials_v5) { + if (io_ccache->kdc_time_offset_v5_valid) { + err = krb5int_ipc_stream_write_time (io_reply_data, io_ccache->kdc_time_offset_v5); + } else { +@@ -1040,13 +997,7 @@ static cc_int32 ccs_ccache_set_kdc_time_offset (ccs_ccache_t io_ccache + } + + if (!err) { +- if (cred_vers == cc_credentials_v4) { +- err = krb5int_ipc_stream_read_time (in_request_data, &io_ccache->kdc_time_offset_v4); +- +- if (!err) { +- io_ccache->kdc_time_offset_v4_valid = 1; +- } +- } else if (cred_vers == cc_credentials_v5) { ++ if (cred_vers == cc_credentials_v5) { + err = krb5int_ipc_stream_read_time (in_request_data, &io_ccache->kdc_time_offset_v5); + + if (!err) { +@@ -1084,11 +1035,7 @@ static cc_int32 ccs_ccache_clear_kdc_time_offset (ccs_ccache_t io_ccac + } + + if (!err) { +- if (cred_vers == cc_credentials_v4) { +- io_ccache->kdc_time_offset_v4 = 0; +- io_ccache->kdc_time_offset_v4_valid = 0; +- +- } else if (cred_vers == cc_credentials_v5) { ++ if (cred_vers == cc_credentials_v5) { + io_ccache->kdc_time_offset_v5 = 0; + io_ccache->kdc_time_offset_v5_valid = 0; + +diff --git a/src/ccapi/test/test_ccapi_ccache.c b/src/ccapi/test/test_ccapi_ccache.c +index a0fd84af1..fe63e6710 100644 +--- a/src/ccapi/test/test_ccapi_ccache.c ++++ b/src/ccapi/test/test_ccapi_ccache.c +@@ -303,18 +303,6 @@ int check_cc_ccache_get_credentials_version(void) { + failure_count++; + } + +- // try it with added v4 creds +- if (!err) { +- err = cc_ccache_set_principal(ccache, cc_credentials_v4, "foo@BAR.ORG"); +- } +- if (!err) { +- check_once_cc_ccache_get_credentials_version(ccache, cc_credentials_v4_v5, ccNoError, "v5 with v4 creds added"); +- } +- else { +- log_error("cc_ccache_set_principal failed, can't complete test"); +- failure_count++; +- } +- + if (ccache) { + cc_ccache_destroy(ccache); + ccache = NULL; +@@ -322,35 +310,6 @@ int check_cc_ccache_get_credentials_version(void) { + + err = ccNoError; + +- // try one created with v4 creds +- if (!err) { +- err = cc_context_create_new_ccache(context, cc_credentials_v4, "foo@BAR.ORG", &ccache); +- } +- if (!err) { +- check_once_cc_ccache_get_credentials_version(ccache, cc_credentials_v4, ccNoError, "v4 creds"); +- } +- else { +- log_error("cc_context_create_new_ccache failed, can't complete test"); +- failure_count++; +- } +- +- // try it with added v5 creds +- if (!err) { +- err = cc_ccache_set_principal(ccache, cc_credentials_v5, "foo@BAR.ORG"); +- } +- if (!err) { +- check_once_cc_ccache_get_credentials_version(ccache, cc_credentials_v4_v5, ccNoError, "v4 with v5 creds added"); +- } +- else { +- log_error("cc_ccache_set_principal failed, can't complete test"); +- failure_count++; +- } +- +- if (ccache) { +- cc_ccache_destroy(ccache); +- ccache = NULL; +- } +- + if (context) { cc_context_release(context); } + + #endif /* cc_ccache_get_credentials_version */ +@@ -582,31 +541,13 @@ int check_cc_ccache_get_principal(void) { + log_error("cc_context_create_new_ccache failed, can't complete test"); + failure_count++; + } +- if (ccache) { +- cc_ccache_release(ccache); +- ccache = NULL; +- } + +- // try with krb4 principal +- if (!err) { +- err = cc_context_create_new_ccache(context, cc_credentials_v4, "foo.BAR@BAZ.ORG", &ccache); +- } +- if (!err) { +- check_once_cc_ccache_get_principal(ccache, cc_credentials_v4, "foo.BAR@BAZ.ORG", ccNoError, "trying to get krb4 princ for krb4 ccache"); +- } +- else { +- log_error("cc_context_create_new_ccache failed, can't complete test"); +- failure_count++; +- } +- +- // try with bad param +- if (!err) { +- // cc_ccache_t doesn't have any concept of the difference between a v4 and v5 principal +- check_once_cc_ccache_get_principal(ccache, cc_credentials_v4_v5, "foo.BAR@BAZ.ORG", +- ccErrBadCredentialsVersion, +- "passing cc_credentials_v4_v5 (shouldn't be allowed)"); +- check_once_cc_ccache_get_principal(ccache, cc_credentials_v5, NULL, ccErrBadParam, "passed null out param"); +- } ++ // try with bad param ++ if (!err) { ++ check_once_cc_ccache_get_principal(ccache, cc_credentials_v5, ++ NULL, ccErrBadParam, ++ "passed null out param"); ++ } + + if (ccache) { + cc_ccache_release(ccache); +@@ -643,99 +584,33 @@ int check_cc_ccache_set_principal(void) { + err = destroy_all_ccaches(context); + } + +- // bad params +- if (!err) { +- err = cc_context_create_new_ccache(context, cc_credentials_v5, "foo@BAZ.ORG", &ccache); +- } +- if (!err) { +- check_once_cc_ccache_set_principal(ccache, cc_credentials_v4_v5, "foo/BAZ@BAR.ORG", ccErrBadCredentialsVersion, "cc_credentials_v4_v5 (not allowed)"); +- check_once_cc_ccache_set_principal(ccache, cc_credentials_v5, NULL, ccErrBadParam, "NULL principal"); +- } +- else { +- log_error("cc_context_create_new_ccache failed, can't complete test"); +- failure_count++; +- } +- if (ccache) { +- cc_ccache_destroy(ccache); +- ccache = NULL; +- } ++ // replace v5 only ccache's principal ++ if (!err) { ++ err = cc_context_create_new_ccache(context, cc_credentials_v5, ++ "foo@BAZ.ORG", &ccache); ++ } ++ if (!err) { ++ check_once_cc_ccache_set_principal( ++ ccache, cc_credentials_v5, "foo/BAZ@BAR.ORG", ccNoError, ++ "replace v5 only ccache's principal (empty ccache)"); ++ } ++ else { ++ log_error( ++ "cc_context_create_new_ccache failed, can't complete test"); ++ failure_count++; ++ } + ++ // bad params ++ if (!err) { ++ check_once_cc_ccache_set_principal(ccache, cc_credentials_v5, ++ NULL, ccErrBadParam, ++ "NULL principal"); ++ } + +- // empty ccache +- +- // replace v5 only ccache's principal +- if (!err) { +- err = cc_context_create_new_ccache(context, cc_credentials_v5, "foo@BAZ.ORG", &ccache); +- } +- if (!err) { +- check_once_cc_ccache_set_principal(ccache, cc_credentials_v5, "foo/BAZ@BAR.ORG", ccNoError, "replace v5 only ccache's principal (empty ccache)"); +- } +- else { +- log_error("cc_context_create_new_ccache failed, can't complete test"); +- failure_count++; +- } +- if (ccache) { +- cc_ccache_destroy(ccache); +- ccache = NULL; +- } +- +- // add v4 principal to v5 only ccache +- if (!err) { +- err = cc_context_create_new_ccache(context, cc_credentials_v5, "foo@BAZ.ORG", &ccache); +- } +- if (!err) { +- check_once_cc_ccache_set_principal(ccache, cc_credentials_v4, "foo.BAZ@BAR.ORG", ccNoError, "add v4 principal to v5 only ccache (empty ccache)"); +- } +- else { +- log_error("cc_context_create_new_ccache failed, can't complete test"); +- failure_count++; +- } +- if (ccache) { +- cc_ccache_destroy(ccache); +- ccache = NULL; +- } +- +- // replace v4 only ccache's principal +- if (!err) { +- err = cc_context_create_new_ccache(context, cc_credentials_v4, "foo@BAZ.ORG", &ccache); +- } +- if (!err) { +- check_once_cc_ccache_set_principal(ccache, cc_credentials_v4, "foo.BAZ@BAR.ORG", ccNoError, "replace v4 only ccache's principal (empty ccache)"); +- } +- else { +- log_error("cc_context_create_new_ccache failed, can't complete test"); +- failure_count++; +- } +- if (ccache) { +- cc_ccache_destroy(ccache); +- ccache = NULL; +- } +- +- // add v5 principal to v4 only ccache +- if (!err) { +- err = cc_context_create_new_ccache(context, cc_credentials_v4, "foo@BAZ.ORG", &ccache); +- } +- if (!err) { +- check_once_cc_ccache_set_principal(ccache, cc_credentials_v5, "foo/BAZ@BAR.ORG", ccNoError, "add v5 principal to v4 only ccache (empty ccache)"); +- } +- else { +- log_error("cc_context_create_new_ccache failed, can't complete test"); +- failure_count++; +- } +- if (ccache) { +- cc_ccache_destroy(ccache); +- ccache = NULL; +- } +- +- // with credentials +- +- // replace v5 only ccache's principal +- +- // add v4 principal to v5 only ccache +- +- // replace v4 only ccache's principal +- +- // add v5 principal to v4 only ccache ++ if (ccache) { ++ cc_ccache_destroy(ccache); ++ ccache = NULL; ++ } + + if (context) { + err = destroy_all_ccaches(context); +@@ -847,21 +722,6 @@ int check_cc_ccache_store_credentials(void) { + + if (&creds_union) { release_v5_creds_union(&creds_union); } + +- // bad creds version +- if (!err) { +- err = new_v5_creds_union(&creds_union, "BAR.ORG"); +- } +- +- if (!err) { +- creds_union.version = cc_credentials_v4_v5; +- check_once_cc_ccache_store_credentials(ccache, &creds_union, ccErrBadCredentialsVersion, "v4_v5 creds (invalid) into a ccache with only v5 princ"); +- creds_union.version = cc_credentials_v4; +- check_once_cc_ccache_store_credentials(ccache, &creds_union, ccErrBadCredentialsVersion, "v4 creds into a ccache with only v5 princ"); +- creds_union.version = cc_credentials_v5; +- } +- +- if (&creds_union) { release_v5_creds_union(&creds_union); } +- + // non-existent ccache + if (ccache) { + err = cc_ccache_get_name(ccache, &name); +@@ -1809,21 +1669,10 @@ int check_cc_ccache_get_kdc_time_offset(void) { + err = cc_ccache_set_kdc_time_offset(ccache, cc_credentials_v5, time_offset); + } + if (!err) { +- check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v5, &time_offset, ccNoError, "offset set for v5 but not v4"); ++ check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v5, &time_offset, ccNoError, "offset set for v5"); + } +- if (!err) { +- check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v4, &time_offset, ccErrTimeOffsetNotSet, "asking for v4 offset when only v5 is set"); +- } +- if (!err) { +- err = cc_ccache_set_kdc_time_offset(ccache, cc_credentials_v4, time_offset); +- } +- if (!err) { +- check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v4, &time_offset, ccNoError, "asking for v4 offset when v4 and v5 are set"); +- } +- + + check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v5, NULL, ccErrBadParam, "NULL time_offset out param"); +- check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v4_v5, &time_offset, ccErrBadCredentialsVersion, "v4_v5 creds_vers in param (invalid)"); + + if (ccache) { cc_ccache_release(ccache); } + +@@ -1900,9 +1749,6 @@ int check_cc_ccache_set_kdc_time_offset(void) { + } + + check_once_cc_ccache_set_kdc_time_offset(ccache, cc_credentials_v5, 0, ccNoError, "first time setting offset (v5)"); +- check_once_cc_ccache_set_kdc_time_offset(ccache, cc_credentials_v4, 0, ccNoError, "first time setting offset (v4)"); +- +- check_once_cc_ccache_set_kdc_time_offset(ccache, cc_credentials_v4_v5, 0, ccErrBadCredentialsVersion, "invalid creds_vers (v4_v5)"); + + if (ccache) { cc_ccache_release(ccache); } + +@@ -1978,15 +1824,10 @@ int check_cc_ccache_clear_kdc_time_offset(void) { + } + + check_once_cc_ccache_clear_kdc_time_offset(ccache, cc_credentials_v5, ccNoError, "clearing an offset that was never set (v5)"); +- check_once_cc_ccache_clear_kdc_time_offset(ccache, cc_credentials_v4, ccNoError, "clearing an offset that was never set (v4)"); + + err = cc_ccache_set_kdc_time_offset(ccache, cc_credentials_v5, 0); +- err = cc_ccache_set_kdc_time_offset(ccache, cc_credentials_v4, 0); + + check_once_cc_ccache_clear_kdc_time_offset(ccache, cc_credentials_v5, ccNoError, "clearing v5"); +- check_once_cc_ccache_clear_kdc_time_offset(ccache, cc_credentials_v4, ccNoError, "clearing v4"); +- +- check_once_cc_ccache_clear_kdc_time_offset(ccache, cc_credentials_v4_v5, ccErrBadCredentialsVersion, "bad in param creds vers (v4_v5)"); + + if (ccache) { cc_ccache_release(ccache); } + +diff --git a/src/ccapi/test/test_ccapi_constants.c b/src/ccapi/test/test_ccapi_constants.c +index 9f2aecbc2..57377262e 100644 +--- a/src/ccapi/test/test_ccapi_constants.c ++++ b/src/ccapi/test/test_ccapi_constants.c +@@ -46,9 +46,7 @@ int check_constants(void) { + + /* Credentials versions */ + +- check_int(cc_credentials_v4, 1); + check_int(cc_credentials_v5, 2); +- check_int(cc_credentials_v4_v5, (cc_credentials_v4 | cc_credentials_v5)); + + /* Lock types */ + +diff --git a/src/ccapi/test/test_ccapi_context.c b/src/ccapi/test/test_ccapi_context.c +index 09feebee5..2dc348ea0 100644 +--- a/src/ccapi/test/test_ccapi_context.c ++++ b/src/ccapi/test/test_ccapi_context.c +@@ -583,7 +583,6 @@ int check_cc_context_create_ccache(void) { + + // try bad parameters + err = check_once_cc_context_create_ccache(context, NULL, cc_credentials_v5, "foo@BAR.ORG", &ccache, ccErrBadParam, "NULL name"); // NULL name +- err = check_once_cc_context_create_ccache(context, "name", cc_credentials_v4_v5, "foo@BAR.ORG", &ccache, ccErrBadCredentialsVersion, "invalid creds_vers"); // invalid creds_vers + err = check_once_cc_context_create_ccache(context, "name", cc_credentials_v5, NULL, &ccache, ccErrBadParam, "NULL principal"); // NULL principal + err = check_once_cc_context_create_ccache(context, "name", cc_credentials_v5, "foo@BAR.ORG", NULL, ccErrBadParam, "NULL ccache"); // NULL ccache + } +@@ -681,7 +680,6 @@ int check_cc_context_create_default_ccache(void) { + } + + // try bad parameters +- err = check_once_cc_context_create_default_ccache(context, cc_credentials_v4_v5, "foo@BAR.ORG", &ccache, ccErrBadCredentialsVersion, "invalid creds_vers"); // invalid creds_vers + err = check_once_cc_context_create_default_ccache(context, cc_credentials_v5, NULL, &ccache, ccErrBadParam, "NULL principal"); // NULL principal + err = check_once_cc_context_create_default_ccache(context, cc_credentials_v5, "foo@BAR.ORG", NULL, ccErrBadParam, "NULL ccache"); // NULL ccache + } +@@ -773,7 +771,6 @@ int check_cc_context_create_new_ccache(void) { + if (ccache) { cc_ccache_release(ccache); } + + // try bad parameters +- err = check_once_cc_context_create_new_ccache(context, 1, cc_credentials_v4_v5, "foo@BAR.ORG", &ccache, ccErrBadCredentialsVersion, "invalid creds_vers"); // invalid creds_vers + err = check_once_cc_context_create_new_ccache(context, 1, cc_credentials_v5, NULL, &ccache, ccErrBadParam, "NULL principal"); // NULL principal + err = check_once_cc_context_create_new_ccache(context, 1, cc_credentials_v5, "foo@BAR.ORG", NULL, ccErrBadParam, "NULL ccache"); // NULL ccache + } +diff --git a/src/ccapi/test/test_ccapi_v2.c b/src/ccapi/test/test_ccapi_v2.c +index e0205ce46..c71bb45a8 100644 +--- a/src/ccapi/test/test_ccapi_v2.c ++++ b/src/ccapi/test/test_ccapi_v2.c +@@ -45,20 +45,6 @@ static int compare_v5_creds_unions_compat(const cred_union *a, const cred_union + a->cred.pV5Cred->starttime == b->cred.pV5Cred->starttime) { + retval = 0; + } +- } else if (a->cred_type == CC_CRED_V4) { +- if (!strcmp (a->cred.pV4Cred->principal, +- b->cred.pV4Cred->principal) && +- !strcmp (a->cred.pV4Cred->principal_instance, +- b->cred.pV4Cred->principal_instance) && +- !strcmp (a->cred.pV4Cred->service, +- b->cred.pV4Cred->service) && +- !strcmp (a->cred.pV4Cred->service_instance, +- b->cred.pV4Cred->service_instance) && +- !strcmp (a->cred.pV4Cred->realm, +- b->cred.pV4Cred->realm) && +- a->cred.pV4Cred->issue_date == b->cred.pV4Cred->issue_date) { +- retval = 0; +- } + } + } + +@@ -361,10 +347,6 @@ int check_cc_open(void) { + err = check_once_cc_open(context, name, CC_CRED_V5, &ccache, CC_NOERROR, NULL); + } + +- // check version +- if (!err) { +- err = check_once_cc_open(context, name, CC_CRED_V4, &ccache, CC_ERR_CRED_VERSION, NULL); +- } + // try bad parameters + err = check_once_cc_open(context, NULL, CC_CRED_V5, &ccache, CC_BAD_PARM, NULL); + err = check_once_cc_open(context, name, CC_CRED_V5, NULL, CC_BAD_PARM, NULL); +@@ -681,17 +663,6 @@ int check_cc_get_cred_version(void) { + + err = CC_NOERROR; + +- // try one created with v4 creds +- if (!err) { +- err = cc_create(context, name, "foo@BAR.ORG", CC_CRED_V4, 0, &ccache); +- } +- if (!err) { +- check_once_cc_get_cred_version(context, ccache, CC_CRED_V4, CC_NOERROR, "v4 creds"); +- } +- else { +- log_error("cc_context_create_new_ccache failed, can't complete test"); +- failure_count++; +- } + if (ccache) { + cc_destroy(context, &ccache); + ccache = NULL; +@@ -840,7 +811,6 @@ int check_cc_get_principal(void) { + apiCB *context = NULL; + ccache_p *ccache = NULL; + char *name_v5 = "TEST_CC_GET_PRINCIPAL_V5"; +- char *name_v4 = "TEST_CC_GET_PRINCIPAL_V4"; + + BEGIN_TEST("cc_get_principal"); + +@@ -866,18 +836,6 @@ int check_cc_get_principal(void) { + ccache = NULL; + } + +- // try with krb4 principal +- if (!err) { +- err = cc_create(context, name_v4, "foo.BAR@BAZ.ORG", CC_CRED_V4, 0, &ccache); +- } +- if (!err) { +- check_once_cc_get_principal(context, ccache, "foo.BAR@BAZ.ORG", CC_NOERROR, "trying to get krb4 princ for krb4 ccache"); +- } +- else { +- log_error("cc_create failed, can't complete test"); +- failure_count++; +- } +- + // try with bad param + if (!err) { + check_once_cc_get_principal(context, ccache, NULL, CC_BAD_PARM, "passed null out param"); +@@ -945,7 +903,6 @@ int check_cc_set_principal(void) { + apiCB *context = NULL; + ccache_p *ccache = NULL; + char *name_v5 = "TEST_CC_GET_PRINCIPAL_V5"; +- char *name_v4 = "TEST_CC_GET_PRINCIPAL_V4"; + + BEGIN_TEST("cc_set_principal"); + +@@ -972,37 +929,6 @@ int check_cc_set_principal(void) { + ccache = NULL; + } + +- // empty ccache +- +- // replace v5 ccache's principal +- if (!err) { +- err = cc_create(context, name_v5, "foo@BAZ.ORG", CC_CRED_V5, 0, &ccache); +- } +- if (!err) { +- check_once_cc_set_principal(context, ccache, CC_CRED_V5, "foo/BAZ@BAR.ORG", CC_NOERROR, "replace v5 only ccache's principal (empty ccache)"); +- check_once_cc_set_principal(context, ccache, CC_CRED_V4, "foo.BAZ@BAR.ORG", CC_ERR_CRED_VERSION, "replace v5 principal with v4"); +- } +- else { +- log_error("cc_create failed, can't complete test"); +- failure_count++; +- } +- if (ccache) { +- cc_destroy(context, &ccache); +- ccache = NULL; +- } +- +- // replace v4 ccache's principal +- if (!err) { +- err = cc_create(context, name_v4, "foo@BAZ.ORG", CC_CRED_V4, 0, &ccache); +- } +- if (!err) { +- check_once_cc_set_principal(context, ccache, CC_CRED_V4, "foo.BAZ@BAR.ORG", CC_NOERROR, "replace v4 only ccache's principal (empty ccache)"); +- check_once_cc_set_principal(context, ccache, CC_CRED_V5, "foo/BAZ@BAR.ORG", CC_ERR_CRED_VERSION, "replace v4 principal with v5"); +- } +- else { +- log_error("cc_create failed, can't complete test"); +- failure_count++; +- } + if (ccache) { + cc_destroy(context, &ccache); + ccache = NULL; +@@ -1102,21 +1028,6 @@ int check_cc_store(void) { + } + } + +- // bad creds version +- if (!err) { +- err = new_v5_creds_union_compat(&creds_union, "BAR.ORG"); +- +- if (!err) { +- creds_union.cred_type = CC_CRED_MAX; +- check_once_cc_store(context, ccache, creds_union, CC_ERR_CRED_VERSION, "CC_CRED_MAX (invalid) into a ccache with only v5 princ"); +- creds_union.cred_type = CC_CRED_V4; +- check_once_cc_store(context, ccache, creds_union, CC_ERR_CRED_VERSION, "v4 creds into a v5 ccache"); +- creds_union.cred_type = CC_CRED_V5; +- +- release_v5_creds_union_compat(&creds_union); +- } +- } +- + // non-existent ccache + if (ccache) { + err = cc_get_name(context, ccache, &name); +diff --git a/src/include/CredentialsCache.h b/src/include/CredentialsCache.h +index 54f71a1a0..c18159639 100644 +--- a/src/include/CredentialsCache.h ++++ b/src/include/CredentialsCache.h +@@ -104,19 +104,19 @@ extern "C" { + * \section introduction Introduction + * + * This is the specification for an API which provides Credentials Cache +- * services for both Kerberos v5 and v4. The idea behind this API is that +- * multiple Kerberos implementations can share a single collection of +- * credentials caches, mediated by this API specification. On the Mac OS +- * and Microsoft Windows platforms this will allow single-login, even when +- * more than one Kerberos shared library is in use on a particular system. ++ * services for Kerberos v5 (and previously v4). The idea behind this API is ++ * that multiple Kerberos implementations can share a single collection of ++ * credentials caches, mediated by this API specification. On the Mac OS and ++ * Microsoft Windows platforms this will allow single-login, even when more ++ * than one Kerberos shared library is in use on a particular system. + * + * Abstractly, a credentials cache collection contains one or more credentials + * caches, or ccaches. A ccache is uniquely identified by its name, which is + * a string internal to the API and not intended to be presented to users. + * The user presentable identifier of a ccache is its principal. + * +- * Unlike the previous versions of the API, version 3 of the API stores both +- * Kerberos v4 and v5 credentials in the same ccache. ++ * Unlike the previous versions of the API, version 3 of the API could store ++ * credentials for multiple Kerberos versions in the same ccache. + * + * At any given time, one ccache is the "default" ccache. The exact meaning + * of a default ccache is OS-specific; refer to implementation requirements +@@ -305,10 +305,9 @@ enum { + /*! + * Credentials versions + * +- * These constants are used in several places in the API to discern +- * between Kerberos v4 and Kerberos v5. Not all values are valid +- * inputs and outputs for all functions; function specifications +- * below detail the allowed values. ++ * These constants are used in several places in the API to discern Kerberos ++ * versions. Not all values are valid inputs and outputs for all functions; ++ * function specifications below detail the allowed values. + * + * Kerberos version constants will always be a bit-field, and can be + * tested as such; for example the following test will tell you if +@@ -317,9 +316,9 @@ enum { + * if ((ccacheVersion & cc_credentials_v5) != 0) + */ + enum cc_credential_versions { +- cc_credentials_v4 = 1, ++ /* cc_credentials_v4 = 1, */ + cc_credentials_v5 = 2, +- cc_credentials_v4_v5 = 3 ++ /* cc_credentials_v4_v5 = 3 */ + }; + + /*! +@@ -353,29 +352,6 @@ enum cc_lock_modes { + cc_lock_block = 1 + }; + +-/*! +- * Sizes of fields in cc_credentials_v4_t. +- */ +-enum { +- /* Make sure all of these are multiples of four (for alignment sanity) */ +- cc_v4_name_size = 40, +- cc_v4_instance_size = 40, +- cc_v4_realm_size = 40, +- cc_v4_ticket_size = 1254, +- cc_v4_key_size = 8 +-}; +- +-/*! +- * String to key type (Kerberos v4 only) +- */ +-enum cc_string_to_key_type { +- cc_v4_stk_afs = 0, +- cc_v4_stk_des = 1, +- cc_v4_stk_columbia_special = 2, +- cc_v4_stk_krb5 = 3, +- cc_v4_stk_unknown = 4 +-}; +- + /*!@}*/ + + /*! +@@ -482,15 +458,13 @@ typedef cc_ccache_iterator_d *cc_ccache_iterator_t; + * \defgroup cc_credentials_reference cc_credentials_t Overview + * @{ + * +- * The cc_credentials_t type is used to store a single set of +- * credentials for either Kerberos v4 or Kerberos v5. In addition +- * to its only function, release(), it contains a pointer to a +- * cc_credentials_union structure. A cc_credentials_union ++ * The cc_credentials_t type is used to store a single set of credentials for ++ * Kerberos v5. In addition to its only function, release(), it contains a ++ * pointer to a cc_credentials_union structure. A cc_credentials_union + * structure contains an integer of the enumerator type +- * cc_credentials_version, which is either #cc_credentials_v4 or +- * #cc_credentials_v5, and a pointer union, which contains either a +- * cc_credentials_v4_t pointer or a cc_credentials_v5_t pointer, +- * depending on the value in version. ++ * cc_credentials_version, which is #cc_credentials_v5, and a pointer union, ++ * which contains a cc_credentials_v5_t pointer, depending on the value in ++ * version. + * + * Variables of the type cc_credentials_t are allocated by the CCAPI + * implementation, and should be released with their release() +@@ -501,43 +475,6 @@ typedef cc_ccache_iterator_d *cc_ccache_iterator_t; + * For API functions see \ref cc_credentials_f. + */ + +-/*! +- * If a cc_credentials_t variable is used to store Kerberos v4 +- * credentials, then credentials.credentials_v4 points to a v4 +- * credentials structure. This structure is similar to a +- * krb4 API CREDENTIALS structure. +- */ +-struct cc_credentials_v4_t { +- cc_uint32 version; +- /*! A properly quoted string representation of the first component of the client principal */ +- char principal [cc_v4_name_size]; +- /*! A properly quoted string representation of the second component of the client principal */ +- char principal_instance [cc_v4_instance_size]; +- /*! A properly quoted string representation of the first component of the service principal */ +- char service [cc_v4_name_size]; +- /*! A properly quoted string representation of the second component of the service principal */ +- char service_instance [cc_v4_instance_size]; +- /*! A properly quoted string representation of the realm */ +- char realm [cc_v4_realm_size]; +- /*! Ticket session key */ +- unsigned char session_key [cc_v4_key_size]; +- /*! Key version number */ +- cc_int32 kvno; +- /*! String to key type used. See cc_string_to_key_type for valid values */ +- cc_int32 string_to_key_type; +- /*! Time when the ticket was issued */ +- cc_time_t issue_date; +- /*! Ticket lifetime in 5 minute units */ +- cc_int32 lifetime; +- /*! IPv4 address of the client the ticket was issued for */ +- cc_uint32 address; +- /*! Ticket size (no greater than cc_v4_ticket_size) */ +- cc_int32 ticket_size; +- /*! Ticket data */ +- unsigned char ticket [cc_v4_ticket_size]; +-}; +-typedef struct cc_credentials_v4_t cc_credentials_v4_t; +- + /*! + * The CCAPI data structure. This structure is similar to a krb5_data structure. + * In a v5 credentials structure, cc_data structures are used +@@ -602,8 +539,6 @@ struct cc_credentials_union { + cc_uint32 version; + /*! The credentials. */ + union { +- /*! If \a version is #cc_credentials_v4, a pointer to a cc_credentials_v4_t. */ +- cc_credentials_v4_t* credentials_v4; + /*! If \a version is #cc_credentials_v5, a pointer to a cc_credentials_v5_t. */ + cc_credentials_v5_t* credentials_v5; + } credentials; +@@ -781,13 +716,11 @@ struct cc_context_f { + * \return On success, #ccNoError. On failure, an error code representing the failure. + * \brief \b cc_context_create_ccache(): Create a new ccache. + * +- * Create a new credentials cache. The ccache is uniquely identified by its name. +- * The principal given is also associated with the ccache and the credentials +- * version specified. A NULL name is not allowed (and ccErrBadName is returned +- * if one is passed in). Only cc_credentials_v4 and cc_credentials_v5 are valid +- * input values for cred_vers. If you want to create a new ccache that will hold +- * both versions of credentials, call cc_context_create_ccache() with one version, +- * and then cc_ccache_set_principal() with the other version. ++ * Create a new credentials cache. The ccache is uniquely identified by ++ * its name. The principal given is also associated with the ccache and ++ * the credentials version specified. A NULL name is not allowed (and ++ * ccErrBadName is returned if one is passed in). Only cc_credentials_v5 ++ * can be an input value for cred_vers. + * + * If you want to create a new ccache (with a unique name), you should use + * cc_context_create_new_ccache() instead. If you want to create or reinitialize +@@ -814,10 +747,9 @@ struct cc_context_f { + * cc_context_get_default_ccache_name()); see the description of + * cc_context_get_default_ccache_name() for details. + * +- * The principal should be a C string containing an unparsed Kerberos principal +- * in the format of the appropriate Kerberos version, i.e. \verbatim foo.bar/@BAZ +- * \endverbatim for Kerberos v4 and \verbatim foo/bar/@BAZ \endverbatim +- * for Kerberos v5. ++ * The principal should be a C string containing an unparsed Kerberos ++ * principal in the format of the appropriate Kerberos version, ++ * i.e. \verbatim foo/bar/@BAZ \endverbatim for Kerberos v5. + */ + cc_int32 (*create_ccache) (cc_context_t in_context, + const char *in_name, +@@ -1014,14 +946,11 @@ struct cc_ccache_f { + * \return On success, #ccNoError. On failure, an error code representing the failure. + * \brief \b cc_ccache_get_credentials_version(): Get the credentials version of a ccache. + * +- * cc_ccache_get_credentials_version() returns one value of the enumerated type +- * cc_credentials_vers. The possible return values are #cc_credentials_v4 +- * (if ccache's v4 principal has been set), #cc_credentials_v5 +- * (if ccache's v5 principal has been set), or #cc_credentials_v4_v5 +- * (if both ccache's v4 and v5 principals have been set). A ccache's +- * principal is set with one of cc_context_create_ccache(), +- * cc_context_create_new_ccache(), cc_context_create_default_ccache(), or +- * cc_ccache_set_principal(). ++ * cc_ccache_get_credentials_version() returns one value of the enumerated ++ * type cc_credentials_vers. The return value is #cc_credentials_v5 (if ++ * ccache's v5 principal has been set). A ccache's principal is set with ++ * one of cc_context_create_ccache(), cc_context_create_new_ccache(), ++ * cc_context_create_default_ccache(), or cc_ccache_set_principal(). + */ + cc_int32 (*get_credentials_version) (cc_ccache_t in_ccache, + cc_uint32 *out_credentials_version); +@@ -1046,10 +975,7 @@ struct cc_ccache_f { + * + * Return the principal for the ccache that was set via cc_context_create_ccache(), + * cc_context_create_default_ccache(), cc_context_create_new_ccache(), or +- * cc_ccache_set_principal(). Principals for v4 and v5 are separate, but +- * should be kept synchronized for each ccache; they can be retrieved by +- * passing cc_credentials_v4 or cc_credentials_v5 in cred_vers. Passing +- * cc_credentials_v4_v5 will result in the error ccErrBadCredentialsVersion. ++ * cc_ccache_set_principal(). + */ + cc_int32 (*get_principal) (cc_ccache_t in_ccache, + cc_uint32 in_credentials_version, +@@ -1063,10 +989,7 @@ struct cc_ccache_f { + * \return On success, #ccNoError. On failure, an error code representing the failure. + * \brief \b cc_ccache_set_principal(): Set the principal of a ccache. + * +- * Set the a principal for ccache. The v4 and v5 principals can be set +- * independently, but they should always be kept equal, up to differences in +- * string representation between v4 and v5. Passing cc_credentials_v4_v5 in +- * cred_vers will result in the error ccErrBadCredentialsVersion. ++ * Set the a principal for ccache. + */ + cc_int32 (*set_principal) (cc_ccache_t io_ccache, + cc_uint32 in_credentials_version, +@@ -1083,12 +1006,13 @@ struct cc_ccache_f { + * See the description of the credentials types for the meaning of + * cc_credentials_union fields. + * +- * Before credentials of a specific credential type can be stored in a ccache, +- * the corresponding principal version has to be set. For example, before you can +- * store Kerberos v4 credentials in a ccache, the Kerberos v4 principal has to be set +- * either by cc_context_create_ccache(), cc_context_create_default_ccache(), +- * cc_context_create_new_ccache(), or cc_ccache_set_principal(); likewise for +- * Kerberos v5. Otherwise, ccErrBadCredentialsVersion is returned. ++ * Before credentials of a specific credential type can be stored in a ++ * ccache, the corresponding principal version has to be set. That is, ++ * before you can store Kerberos v5 credentials in a ccache, the Kerberos ++ * v5 principal has to be set either by cc_context_create_ccache(), ++ * cc_context_create_default_ccache(), cc_context_create_new_ccache(), or ++ * cc_ccache_set_principal(); otherwise, ccErrBadCredentialsVersion is ++ * returned. + */ + cc_int32 (*store_credentials) (cc_ccache_t io_ccache, + const cc_credentials_union *in_credentials_union); +diff --git a/src/include/CredentialsCache2.h b/src/include/CredentialsCache2.h +index b3b48996d..9e5a346ac 100644 +--- a/src/include/CredentialsCache2.h ++++ b/src/include/CredentialsCache2.h +@@ -85,36 +85,13 @@ typedef struct cc_credentials_v5_compat { + cc_data_compat** authdata; + } cc_credentials_v5_compat; + +-enum { +- MAX_V4_CRED_LEN = 1250 +-}; +- + enum { + KRB_NAME_SZ = 40, + KRB_INSTANCE_SZ = 40, + KRB_REALM_SZ = 40 + }; + +-typedef struct cc_credentials_v4_compat { +- unsigned char kversion; +- char principal[KRB_NAME_SZ+1]; +- char principal_instance[KRB_INSTANCE_SZ+1]; +- char service[KRB_NAME_SZ+1]; +- char service_instance[KRB_INSTANCE_SZ+1]; +- char realm[KRB_REALM_SZ+1]; +- unsigned char session_key[8]; +- cc_int32 kvno; +- cc_int32 str_to_key; +- long issue_date; +- cc_int32 lifetime; +- cc_uint32 address; +- cc_int32 ticket_sz; +- unsigned char ticket[MAX_V4_CRED_LEN]; +- unsigned long oops; +-} cc_credentials_v4_compat; +- + typedef union cred_ptr_union_compat { +- cc_credentials_v4_compat* pV4Cred; + cc_credentials_v5_compat* pV5Cred; + } cred_ptr_union_compat; + +@@ -135,7 +112,6 @@ typedef struct infoNC infoNC; + + /* Some old type names */ + +-typedef cc_credentials_v4_compat V4Cred_type; + typedef cc_credentials_v5_compat cc_creds; + struct ccache_cit; + typedef struct ccache_cit ccache_cit; +@@ -166,7 +142,7 @@ enum { + + enum { + CC_CRED_UNKNOWN, +- CC_CRED_V4, ++ /* CC_CRED_V4, */ + CC_CRED_V5, + CC_CRED_MAX + }; +diff --git a/src/lib/krb5/ccache/ccapi/stdcc.c b/src/lib/krb5/ccache/ccapi/stdcc.c +index db69eebb4..cac61e45c 100644 +--- a/src/lib/krb5/ccache/ccapi/stdcc.c ++++ b/src/lib/krb5/ccache/ccapi/stdcc.c +@@ -589,7 +589,6 @@ krb5_stdccv3_next_cred (krb5_context context, + err = stdccv3_setup (context, ccapi_data); + } + +- /* Note: CCAPI v3 ccaches can contain both v4 and v5 creds */ + while (!err) { + err = cc_credentials_iterator_next (iterator, &credentials); + +@@ -836,7 +835,6 @@ krb5_stdccv3_remove (krb5_context context, + &iterator); + } + +- /* Note: CCAPI v3 ccaches can contain both v4 and v5 creds */ + while (!err && !found) { + cc_credentials_t credentials = NULL; + +diff --git a/src/lib/krb5/ccache/ccapi/stdcc_util.c b/src/lib/krb5/ccache/ccapi/stdcc_util.c +index 62d847c18..1f2a3865c 100644 +--- a/src/lib/krb5/ccache/ccapi/stdcc_util.c ++++ b/src/lib/krb5/ccache/ccapi/stdcc_util.c +@@ -521,9 +521,6 @@ cred_union_release (cc_credentials_union *in_cred_union) + + free (cv5); + +- } else if (in_cred_union->version == cc_credentials_v4 && +- in_cred_union->credentials.credentials_v4) { +- free (in_cred_union->credentials.credentials_v4); + } + free ((cc_credentials_union *) in_cred_union); + } +@@ -892,10 +889,7 @@ static void deep_free_cc_v5_creds (cc_creds* creds) + + static void deep_free_cc_creds (cred_union creds) + { +- if (creds.cred_type == CC_CRED_V4) { +- /* we shouldn't get this, of course */ +- free (creds.cred.pV4Cred); +- } else if (creds.cred_type == CC_CRED_V5) { ++ if (creds.cred_type == CC_CRED_V5) { + deep_free_cc_v5_creds (creds.cred.pV5Cred); + } + } +diff --git a/src/windows/kfwlogon/kfwlogon.h b/src/windows/kfwlogon/kfwlogon.h +index b2674573e..622d5665c 100644 +--- a/src/windows/kfwlogon/kfwlogon.h ++++ b/src/windows/kfwlogon/kfwlogon.h +@@ -94,7 +94,7 @@ typedef int cc_int32; + + enum { + CC_CRED_VUNKNOWN = 0, // For validation +- CC_CRED_V4 = 1, ++ /* CC_CRED_V4 = 1, */ + CC_CRED_V5 = 2, + CC_CRED_VMAX = 3 // For validation + }; +diff --git a/src/windows/leashdll/leash-int.h b/src/windows/leashdll/leash-int.h +index cb40c607c..bf6f6a08d 100644 +--- a/src/windows/leashdll/leash-int.h ++++ b/src/windows/leashdll/leash-int.h +@@ -182,7 +182,7 @@ typedef int cc_int32; + + enum { + CC_CRED_VUNKNOWN = 0, // For validation +- CC_CRED_V4 = 1, ++ /* CC_CRED_V4 = 1, */ + CC_CRED_V5 = 2, + CC_CRED_VMAX = 3 // For validation + }; +diff --git a/src/windows/lib/cacheapi.h b/src/windows/lib/cacheapi.h +index b30857810..9aab4a098 100644 +--- a/src/windows/lib/cacheapi.h ++++ b/src/windows/lib/cacheapi.h +@@ -126,52 +126,8 @@ typedef struct _cc_creds { + cc_data ** authdata; + } cc_creds; + +-// begin V4 stuff +-// use an enumerated type so all callers infer the same meaning +-// these values are what krbv4win uses internally. +-#define STK_AFS 0 +-#define STK_DES 1 +- +-// K4 uses a MAX_KTXT_LEN of 1250 to hold a ticket +-// K95 uses 256 +-// To be safe I'll use the larger number, but a factor of 5!!! +-#define MAX_V4_CRED_LEN 1250 +- +-// V4 Credentials +- +-enum { +- KRB_NAME_SZ = 40, +- KRB_INSTANCE_SZ = 40, +- KRB_REALM_SZ = 40 +-}; +- +-typedef struct cc_V4credential { +- unsigned char kversion; +- char principal[KRB_NAME_SZ + 1]; +- char principal_instance[KRB_INSTANCE_SZ + 1]; +- char service[KRB_NAME_SZ + 1]; +- char service_instance[KRB_INSTANCE_SZ + 1]; +- char realm[KRB_REALM_SZ + 1]; +- unsigned char session_key[8]; +- cc_int32 kvno; // k95 used BYTE skvno +- cc_int32 str_to_key; // k4 infers dynamically, k95 stores +- long issue_date; // k95 called this issue_time +- cc_int32 lifetime; // k95 used LONG expiration_time +- cc_uint32 address; // IP Address of local host +- cc_int32 ticket_sz; // k95 used BYTE, k4 ktext uses int to hold up to 1250 +- unsigned char ticket[MAX_V4_CRED_LEN]; +- unsigned long oops; // zero to catch runaways +-} V4Cred_type; +- +-enum { +- CC_CRED_VUNKNOWN = 0, // For validation +- CC_CRED_V4 = 1, +- CC_CRED_V5 = 2, +- CC_CRED_VMAX = 3 // For validation +-}; + + typedef union cred_ptr_union_type { +- V4Cred_type* pV4Cred; + cc_creds* pV5Cred; + } cred_ptr_union; + +@@ -223,16 +179,15 @@ cc_get_change_time( + ** create, open, close, destroy, get_principal, get_cred_version, & + ** lock_request + ** +-** Multiple NCs are allowed within the main cache. Each has a Name +-** and kerberos version # (V4 or V5). Caller gets "ccache_ptr"s for +-** NCs. ++** Multiple NCs are allowed within the main cache. Each has a Name and ++** kerberos version # (V5). Caller gets "ccache_ptr"s for NCs. + */ + CCACHE_API + cc_create( + apiCB* cc_ctx, // > DLL's primary control structure + const char* name, // > name of cache to be [destroyed if exists, then] created + const char* principal, +- cc_int32 vers, // > ticket version (CC_CRED_V4 or CC_CRED_V5) ++ cc_int32 vers, // > ticket version (CC_CRED_V5) + cc_uint32 cc_flags, // > options + ccache_p** ccache_ptr // < NC control structure + ); +@@ -241,7 +196,7 @@ CCACHE_API + cc_open( + apiCB* cc_ctx, // > DLL's primary control structure + const char* name, // > name of pre-created cache +- cc_int32 vers, // > ticket version (CC_CRED_V4 or CC_CRED_V5) ++ cc_int32 vers, // > ticket version (CC_CRED_V5) + cc_uint32 cc_flags, // > options + ccache_p** ccache_ptr // < NC control structure + ); diff --git a/Remove-ccapi-related-comments-in-configure.ac.patch b/Remove-ccapi-related-comments-in-configure.ac.patch new file mode 100644 index 0000000..78cf265 --- /dev/null +++ b/Remove-ccapi-related-comments-in-configure.ac.patch @@ -0,0 +1,34 @@ +From 1f214b1265bde1d8f6c9b99af0755ca8f5463385 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 3 Apr 2019 16:01:22 -0400 +Subject: [PATCH] Remove ccapi-related comments in configure.ac + +These suggested ccapi is buildable on non-Windows, and empirically it +is not. + +(cherry picked from commit eb48b176bccf3634b9c82f588dce85125a5c4bd8) +--- + src/configure.in | 3 --- + 1 file changed, 3 deletions(-) + +diff --git a/src/configure.in b/src/configure.in +index 7c309a26b..8d781a7c8 100644 +--- a/src/configure.in ++++ b/src/configure.in +@@ -1450,7 +1450,6 @@ V5_AC_OUTPUT_MAKEFILE(. + lib/crypto/crypto_tests + + lib/krb5 lib/krb5/error_tables lib/krb5/asn.1 lib/krb5/ccache +-dnl lib/krb5/ccache/ccapi + lib/krb5/keytab lib/krb5/krb lib/krb5/rcache lib/krb5/os + lib/krb5/unicode + +@@ -1463,8 +1462,6 @@ dnl lib/krb5/ccache/ccapi + lib/krad + lib/apputils + +-dnl ccapi ccapi/lib ccapi/lib/unix ccapi/server ccapi/server/unix ccapi/test +- + kdc kprop config-files build-tools man doc include + + plugins/certauth/test diff --git a/Remove-doxygen-generated-HTML-output-for-ccapi.patch b/Remove-doxygen-generated-HTML-output-for-ccapi.patch new file mode 100644 index 0000000..3165c8e --- /dev/null +++ b/Remove-doxygen-generated-HTML-output-for-ccapi.patch @@ -0,0 +1,7653 @@ +From 5f56eefcf0017d6c0c574e667f55f827b226b295 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 4 Apr 2019 14:15:58 -0400 +Subject: [PATCH] Remove doxygen-generated HTML output for ccapi + +(cherry picked from commit d4f90b750d6d81cc001f6b00266c82c1c916bbf4) +--- + doc/ccapi/Doxyfile | 281 ---- + doc/ccapi/ccache-api-v2.html | 1217 --------------- + doc/ccapi/html/doxygen.css | 310 ---- + doc/ccapi/html/doxygen.png | Bin 1281 -> 0 bytes + ...roup__cc__ccache__iterator__reference.html | 96 -- + .../html/group__cc__ccache__reference.html | 96 -- + .../html/group__cc__context__reference.html | 161 -- + ..._cc__credentials__iterator__reference.html | 133 -- + .../group__cc__credentials__reference.html | 197 --- + .../html/group__cc__string__reference.html | 96 -- + .../group__ccapi__constants__reference.html | 407 ----- + .../html/group__ccapi__types__reference.html | 138 -- + doc/ccapi/html/group__helper__macros.html | 1377 ----------------- + doc/ccapi/html/index.html | 85 - + doc/ccapi/html/structcc__ccache__d.html | 43 - + doc/ccapi/html/structcc__ccache__f.html | 722 --------- + .../html/structcc__ccache__iterator__d.html | 43 - + .../html/structcc__ccache__iterator__f.html | 117 -- + doc/ccapi/html/structcc__context__d.html | 43 - + doc/ccapi/html/structcc__context__f.html | 513 ------ + doc/ccapi/html/structcc__credentials__d.html | 67 - + doc/ccapi/html/structcc__credentials__f.html | 85 - + .../structcc__credentials__iterator__d.html | 43 - + .../structcc__credentials__iterator__f.html | 85 - + .../html/structcc__credentials__union.html | 118 -- + .../html/structcc__credentials__v4__t.html | 358 ----- + .../html/structcc__credentials__v5__t.html | 334 ---- + doc/ccapi/html/structcc__data.html | 94 -- + doc/ccapi/html/structcc__string__d.html | 67 - + doc/ccapi/html/structcc__string__f.html | 51 - + 30 files changed, 7377 deletions(-) + delete mode 100644 doc/ccapi/Doxyfile + delete mode 100755 doc/ccapi/ccache-api-v2.html + delete mode 100644 doc/ccapi/html/doxygen.css + delete mode 100644 doc/ccapi/html/doxygen.png + delete mode 100644 doc/ccapi/html/group__cc__ccache__iterator__reference.html + delete mode 100644 doc/ccapi/html/group__cc__ccache__reference.html + delete mode 100644 doc/ccapi/html/group__cc__context__reference.html + delete mode 100644 doc/ccapi/html/group__cc__credentials__iterator__reference.html + delete mode 100644 doc/ccapi/html/group__cc__credentials__reference.html + delete mode 100644 doc/ccapi/html/group__cc__string__reference.html + delete mode 100644 doc/ccapi/html/group__ccapi__constants__reference.html + delete mode 100644 doc/ccapi/html/group__ccapi__types__reference.html + delete mode 100644 doc/ccapi/html/group__helper__macros.html + delete mode 100644 doc/ccapi/html/index.html + delete mode 100644 doc/ccapi/html/structcc__ccache__d.html + delete mode 100644 doc/ccapi/html/structcc__ccache__f.html + delete mode 100644 doc/ccapi/html/structcc__ccache__iterator__d.html + delete mode 100644 doc/ccapi/html/structcc__ccache__iterator__f.html + delete mode 100644 doc/ccapi/html/structcc__context__d.html + delete mode 100644 doc/ccapi/html/structcc__context__f.html + delete mode 100644 doc/ccapi/html/structcc__credentials__d.html + delete mode 100644 doc/ccapi/html/structcc__credentials__f.html + delete mode 100644 doc/ccapi/html/structcc__credentials__iterator__d.html + delete mode 100644 doc/ccapi/html/structcc__credentials__iterator__f.html + delete mode 100644 doc/ccapi/html/structcc__credentials__union.html + delete mode 100644 doc/ccapi/html/structcc__credentials__v4__t.html + delete mode 100644 doc/ccapi/html/structcc__credentials__v5__t.html + delete mode 100644 doc/ccapi/html/structcc__data.html + delete mode 100644 doc/ccapi/html/structcc__string__d.html + delete mode 100644 doc/ccapi/html/structcc__string__f.html + +diff --git a/doc/ccapi/Doxyfile b/doc/ccapi/Doxyfile +deleted file mode 100644 +index 734c29c90..000000000 +--- a/doc/ccapi/Doxyfile ++++ /dev/null +@@ -1,281 +0,0 @@ +-# Doxyfile 1.5.3 +- +-#--------------------------------------------------------------------------- +-# Project related configuration options +-#--------------------------------------------------------------------------- +-DOXYFILE_ENCODING = UTF-8 +-PROJECT_NAME = "Credentials Cache API " +-PROJECT_NUMBER = +-OUTPUT_DIRECTORY = . +-CREATE_SUBDIRS = NO +-OUTPUT_LANGUAGE = English +-BRIEF_MEMBER_DESC = YES +-REPEAT_BRIEF = YES +-ABBREVIATE_BRIEF = "The $name class " \ +- "The $name widget " \ +- "The $name file " \ +- is \ +- provides \ +- specifies \ +- contains \ +- represents \ +- a \ +- an \ +- the +-ALWAYS_DETAILED_SEC = YES +-INLINE_INHERITED_MEMB = NO +-FULL_PATH_NAMES = NO +-STRIP_FROM_PATH = +-STRIP_FROM_INC_PATH = +-SHORT_NAMES = NO +-JAVADOC_AUTOBRIEF = NO +-QT_AUTOBRIEF = NO +-MULTILINE_CPP_IS_BRIEF = NO +-DETAILS_AT_TOP = YES +-INHERIT_DOCS = YES +-SEPARATE_MEMBER_PAGES = NO +-TAB_SIZE = 8 +-ALIASES = +-OPTIMIZE_OUTPUT_FOR_C = YES +-OPTIMIZE_OUTPUT_JAVA = NO +-BUILTIN_STL_SUPPORT = NO +-CPP_CLI_SUPPORT = NO +-DISTRIBUTE_GROUP_DOC = NO +-SUBGROUPING = YES +-#--------------------------------------------------------------------------- +-# Build related configuration options +-#--------------------------------------------------------------------------- +-EXTRACT_ALL = YES +-EXTRACT_PRIVATE = NO +-EXTRACT_STATIC = NO +-EXTRACT_LOCAL_CLASSES = NO +-EXTRACT_LOCAL_METHODS = NO +-EXTRACT_ANON_NSPACES = NO +-HIDE_UNDOC_MEMBERS = NO +-HIDE_UNDOC_CLASSES = NO +-HIDE_FRIEND_COMPOUNDS = NO +-HIDE_IN_BODY_DOCS = YES +-INTERNAL_DOCS = NO +-CASE_SENSE_NAMES = YES +-HIDE_SCOPE_NAMES = YES +-SHOW_INCLUDE_FILES = NO +-INLINE_INFO = YES +-SORT_MEMBER_DOCS = NO +-SORT_BRIEF_DOCS = NO +-SORT_BY_SCOPE_NAME = NO +-GENERATE_TODOLIST = YES +-GENERATE_TESTLIST = YES +-GENERATE_BUGLIST = YES +-GENERATE_DEPRECATEDLIST= YES +-ENABLED_SECTIONS = +-MAX_INITIALIZER_LINES = 30 +-SHOW_USED_FILES = NO +-SHOW_DIRECTORIES = NO +-FILE_VERSION_FILTER = +-#--------------------------------------------------------------------------- +-# configuration options related to warning and progress messages +-#--------------------------------------------------------------------------- +-QUIET = NO +-WARNINGS = YES +-WARN_IF_UNDOCUMENTED = YES +-WARN_IF_DOC_ERROR = YES +-WARN_NO_PARAMDOC = YES +-WARN_FORMAT = "$file:$line: $text " +-WARN_LOGFILE = +-#--------------------------------------------------------------------------- +-# configuration options related to the input files +-#--------------------------------------------------------------------------- +-INPUT = ../../Sources/include/CredentialsCache.h +-INPUT_ENCODING = UTF-8 +-FILE_PATTERNS = *.c \ +- *.cc \ +- *.cxx \ +- *.cpp \ +- *.c++ \ +- *.d \ +- *.java \ +- *.ii \ +- *.ixx \ +- *.ipp \ +- *.i++ \ +- *.inl \ +- *.h \ +- *.hh \ +- *.hxx \ +- *.hpp \ +- *.h++ \ +- *.idl \ +- *.odl \ +- *.cs \ +- *.php \ +- *.php3 \ +- *.inc \ +- *.m \ +- *.mm \ +- *.dox \ +- *.py \ +- *.C \ +- *.CC \ +- *.C++ \ +- *.II \ +- *.I++ \ +- *.H \ +- *.HH \ +- *.H++ \ +- *.CS \ +- *.PHP \ +- *.PHP3 \ +- *.M \ +- *.MM \ +- *.PY +-RECURSIVE = YES +-EXCLUDE = +-EXCLUDE_SYMLINKS = NO +-EXCLUDE_PATTERNS = +-EXCLUDE_SYMBOLS = +-EXAMPLE_PATH = +-EXAMPLE_PATTERNS = * +-EXAMPLE_RECURSIVE = NO +-IMAGE_PATH = +-INPUT_FILTER = +-FILTER_PATTERNS = +-FILTER_SOURCE_FILES = NO +-#--------------------------------------------------------------------------- +-# configuration options related to source browsing +-#--------------------------------------------------------------------------- +-SOURCE_BROWSER = NO +-INLINE_SOURCES = NO +-STRIP_CODE_COMMENTS = YES +-REFERENCED_BY_RELATION = YES +-REFERENCES_RELATION = YES +-REFERENCES_LINK_SOURCE = YES +-USE_HTAGS = NO +-VERBATIM_HEADERS = NO +-#--------------------------------------------------------------------------- +-# configuration options related to the alphabetical class index +-#--------------------------------------------------------------------------- +-ALPHABETICAL_INDEX = NO +-COLS_IN_ALPHA_INDEX = 5 +-IGNORE_PREFIX = +-#--------------------------------------------------------------------------- +-# configuration options related to the HTML output +-#--------------------------------------------------------------------------- +-GENERATE_HTML = YES +-HTML_OUTPUT = html +-HTML_FILE_EXTENSION = .html +-HTML_HEADER = +-HTML_FOOTER = +-HTML_STYLESHEET = +-HTML_ALIGN_MEMBERS = NO +-GENERATE_HTMLHELP = NO +-HTML_DYNAMIC_SECTIONS = NO +-CHM_FILE = +-HHC_LOCATION = +-GENERATE_CHI = NO +-BINARY_TOC = NO +-TOC_EXPAND = NO +-DISABLE_INDEX = YES +-ENUM_VALUES_PER_LINE = 4 +-GENERATE_TREEVIEW = NO +-TREEVIEW_WIDTH = 250 +-#--------------------------------------------------------------------------- +-# configuration options related to the LaTeX output +-#--------------------------------------------------------------------------- +-GENERATE_LATEX = NO +-LATEX_OUTPUT = latex +-LATEX_CMD_NAME = latex +-MAKEINDEX_CMD_NAME = makeindex +-COMPACT_LATEX = NO +-PAPER_TYPE = letter +-EXTRA_PACKAGES = +-LATEX_HEADER = +-PDF_HYPERLINKS = YES +-USE_PDFLATEX = YES +-LATEX_BATCHMODE = NO +-LATEX_HIDE_INDICES = NO +-#--------------------------------------------------------------------------- +-# configuration options related to the RTF output +-#--------------------------------------------------------------------------- +-GENERATE_RTF = YES +-RTF_OUTPUT = rtf +-COMPACT_RTF = YES +-RTF_HYPERLINKS = YES +-RTF_STYLESHEET_FILE = +-RTF_EXTENSIONS_FILE = +-#--------------------------------------------------------------------------- +-# configuration options related to the man page output +-#--------------------------------------------------------------------------- +-GENERATE_MAN = NO +-MAN_OUTPUT = man +-MAN_EXTENSION = .3 +-MAN_LINKS = NO +-#--------------------------------------------------------------------------- +-# configuration options related to the XML output +-#--------------------------------------------------------------------------- +-GENERATE_XML = NO +-XML_OUTPUT = xml +-XML_SCHEMA = +-XML_DTD = +-XML_PROGRAMLISTING = YES +-#--------------------------------------------------------------------------- +-# configuration options for the AutoGen Definitions output +-#--------------------------------------------------------------------------- +-GENERATE_AUTOGEN_DEF = NO +-#--------------------------------------------------------------------------- +-# configuration options related to the Perl module output +-#--------------------------------------------------------------------------- +-GENERATE_PERLMOD = NO +-PERLMOD_LATEX = NO +-PERLMOD_PRETTY = YES +-PERLMOD_MAKEVAR_PREFIX = +-#--------------------------------------------------------------------------- +-# Configuration options related to the preprocessor +-#--------------------------------------------------------------------------- +-ENABLE_PREPROCESSING = YES +-MACRO_EXPANSION = NO +-EXPAND_ONLY_PREDEF = NO +-SEARCH_INCLUDES = NO +-INCLUDE_PATH = +-INCLUDE_FILE_PATTERNS = +-PREDEFINED = +-EXPAND_AS_DEFINED = +-SKIP_FUNCTION_MACROS = YES +-#--------------------------------------------------------------------------- +-# Configuration::additions related to external references +-#--------------------------------------------------------------------------- +-TAGFILES = +-GENERATE_TAGFILE = +-ALLEXTERNALS = NO +-EXTERNAL_GROUPS = NO +-PERL_PATH = /usr/bin/perl +-#--------------------------------------------------------------------------- +-# Configuration options related to the dot tool +-#--------------------------------------------------------------------------- +-CLASS_DIAGRAMS = NO +-MSCGEN_PATH = /Volumes/Ragna-Blade/Developer/Doxygen/Doxygen.app/Contents/Resources/ +-HIDE_UNDOC_RELATIONS = YES +-HAVE_DOT = NO +-CLASS_GRAPH = YES +-COLLABORATION_GRAPH = YES +-GROUP_GRAPHS = YES +-UML_LOOK = NO +-TEMPLATE_RELATIONS = NO +-INCLUDE_GRAPH = YES +-INCLUDED_BY_GRAPH = YES +-CALL_GRAPH = NO +-CALLER_GRAPH = NO +-GRAPHICAL_HIERARCHY = YES +-DIRECTORY_GRAPH = YES +-DOT_IMAGE_FORMAT = png +-DOT_PATH = +-DOTFILE_DIRS = +-DOT_GRAPH_MAX_NODES = 50 +-MAX_DOT_GRAPH_DEPTH = 1000 +-DOT_TRANSPARENT = NO +-DOT_MULTI_TARGETS = NO +-GENERATE_LEGEND = YES +-DOT_CLEANUP = YES +-#--------------------------------------------------------------------------- +-# Configuration::additions related to the search engine +-#--------------------------------------------------------------------------- +-SEARCHENGINE = NO +diff --git a/doc/ccapi/ccache-api-v2.html b/doc/ccapi/ccache-api-v2.html +deleted file mode 100755 +index b8d3f06e5..000000000 +--- a/doc/ccapi/ccache-api-v2.html ++++ /dev/null +@@ -1,1217 +0,0 @@ +- +- +- +- Credentials Cache API v2 Specification +- +- +-

Credentials Cache API v2 Specification

+-

This version of the API is deprecated.
+-Please refer to CCAPI version 3 or later for the current API.

+- +- +- +-

+-


+- +- +-

Abstract

+- +-

This is the specification for an API which provides Credentials +-Cache services for both +-Kerberos V5 and V4. +-The idea behind this API is that multiple Kerberos implementations +-can share a single Credentials Cache, mediated by this API +-specification. On the Microsoft Windows platform this will allow +-single-signon, even when more than one Kerberos DLL is in use on a +-particular system. Ideally, this problem could be solved by +-standardizing the Kerberos V5 API library interface. However, the +-Kerberos API is complicated enough that this would be hard to +-accomplish. Standardizing the interface for credentials cache access +-is much simpler. This API has also been adopted in the MIT Kerberos +-for the Macintosh implementation. +- +-

This specification has been revised to allow storage and +-manipulation of both V4 and V5 tickets. A cache contains one or more +-"Named Cache"s. It is assumed that V4 and V5 credentials would each +-be stored in separate "Named Cache"s and not mixed in a single "Named +-Cache". +- +-

Below, "NC" refers to "Named Cache".
+- +- +- +-

+-


+- +- +-

Revision History/Notes

+- +-

Original version (Draft Version 1)

+- +-

1/27/96 by +-Theodore Ts'o +- +-

Revision 2 (Draft Version 1)

+- +-

970628 by Steve Rothwell +-for the V4Cache Team (Paul Hill, Jenny Khuon, Jean Luker, Dave +-Detlefs, Allan Bjorklund, & Steve Rothwell) +- +-

+- +-

Revision 3 (Draft Version 1)

+- +-

970725 by Steve Rothwell after initial implementation and alpha +-release. The term "credentials cache" was previously used to mean +-both "the main cache" and individual "named cache"s within the main +-cache. I have started using the term "NC" for "named cache" to make +-the distinction clearer and to reduce the overloading of the word +-"cache". +- +-

Changes made for revision 3 of this API:
+- +-
    +-
  • Added cred version type to cc_create() & cc_open() +- +-
  • New functions +- +-
      +-
    • cc_get_NC_info(), returns NC_info list for all NCs +- +-
    • cc_free_NC_info(), frees NC_info list +- +-
    • cc_get_cred_version(), returns version type of NC +- +-
    • cc_get_name(), returns name of NC +- +-
    • cc_free_name(), frees name aquired via cc_get_name() +- +-
    • cc_seq_fetch_NCs(), iterate over all NCs +-
    +- +-
  • New return codes +- +-
      +-
    • CC_BAD_PARM +- +-
    • CC_ERR_CACHE_ATTACH +- +-
    • CC_ERR_CACHE_RELEASE +- +-
    • CC_ERR_CACHE_FULL +- +-
    • CC_ERR_CRED_VERSION +-
    +- +-
  • Modified functions +- +-
      +-
    • cc_create(), cc_open(), pass version type of NC +- +-
    • cc_store(), cc_remove(), cc_ +-
    +- +-
  • New & Modified typedefs & data structures +- +-
      +-
    • cc_cred_vers { CC_CRED_VUNKNOWN, CC_CRED_V4, CC_CRED_V5 } +- +-
    • cred_ptr_union : contains pointer to credentials (either V4 +- or V5) +- +-
    • cred_union : contains version type and cred_ptr_union +- +-
    • modified V4Cred_type +- +-
    • enum StringToKey_Type { STK_AFS or STK_DES } +- +-
    • copies of the maximum V4 string size indicators +- KRB_PRINCIPAL_SZ, KRB_SERVICE_SZ, KRB_INSTANCE_SZ, +- KRB_REALM_SZ, ADDR_SZ +-
    +-
+- +-

Revision 4 (Draft Version 1)

+- +-

970908 by Steve Rothwell to incorporate changes initiated by Ted +-Tso. Further changes are expected in the comments for cc_create() and +-cc_get_change_time(). +- +-

Revision 4a (Final Version 1)

+- +-

980603 by Scott McGuire to +-correct typographical errors, HTML errors, and minor clarifications. +-Final API Version 1 spec. +- +-

Revision 5 (Draft Version 2)

+- +-

990201 by Scott McGuire. +- +-

    +-
  • Increased API version number to 2. +- +-
  • Added enum's defining version numbers. +- +-
  • Changes to cc_initialize() to specify how to deal with +- different API version numbers. +- +-
  • Added description of cc_int32 and cc_uint32 types. +- +-
  • Change some cc_int32's to cc_uint32's. +- +-
  • Changed way cc_create() will behave when called on an existing +- cache. +- +-
  • Replaced cc_seq_fetch_NCs() with cc_seq_fetch_NCs_begin(), +- cc_seq_fetch_NCs_next(), and cc_seq_fetch_NCs_end(); +- +-
  • Replaced cc_seq_fetch_creds() with cc_seq_fetch_creds_begin(), +- cc_seq_fetch_creds_next(), and cc_seq_fetch_creds_end(); +- +-
  • Replaced enum type references in structs and function +- paramenters with cc_int32 references; +- +-
  • Replaced int type references in function parameters with +- cc_int32; +- +-
  • Added return type of cc_int32 to all functions; +- +-
  • Removed #ifdef from cred_union structure; +- +-
  • Constant definitions and changes to V4Cred_type structure; +- +-
  • Removed incorrect const ccache_p * parameters from cc_store() +- and cc_remove_cred(); +- +-
  • Added CC_NOERROR and CC_BAD_PARM as possible return codes from +- all functions (except no CC_BAD_PARM from cc_shutdown() ); +- +-
  • Added CC_ERR_CRED_VERSION as possible return code from +- cc_open() and cc_create(); +- +-
  • Moved infoNC structure definition up to be with rest of +- structure definitions; +- +-
  • Changed "struct _infoNC" to "infoNC" in parameter type +- references. +- +-
  • cc_free_principal() and cc_free_name() now take char ** +- instead of char * for final parameter. (This change was made +- between rev 4a and rev 5, but I'm re-emphasizing it here.) +- +-
  • Added Implementation Notes section with requirement that all +- functions must be atomic and name requirements for Windows DLL's. +- +-
  • Renamed "the proposed changes to this API are" section to +- "Ideas for Future Versions" -- but removed all items but one +- because they'd all been done. +- +-
  • Removed most of the notes about differences with the Win NT/95 +- implementation of the API -- the differences have been reconciled. +- +-
  • Removed unnecessary and inconsistent italicizing. +-
+- +-

Revsion 5a (Final Version 2)

+- +-

990723 by Scott McGuire. +- +-

    +-
  • cc_create(): Removed text about "expected" form of name. +- Removed note about "the alpha version does not do this." +- +-
  • cc_destroy(): Clarified that you do not need to call +- cc_close() on the cache_pointer after calling this function. +- +-
  • Removed note about Windows cc_get_instance() and +- cc_set_instance() functions, they are no longer part of the +- Windows code! +-
+- +-

Ideas for Future Versions

+- +-
    +-
  • Define Get/Set functions for all components of _cc_creds? +- (This will allow future changes to the data structure to be +- transparent to the caller. This also makes backward compatibility +- much easier to maintain.) +-
+- +-


+- +- +-


+- +- +-

Type definitions

+- +-
// enums for API versions used in cc_initialize()
+-enum {
+-   CC_API_VER_1 = 1,
+-   CC_API_VER_2 = 2
+-};
+- 
+-
+-// cc_int32 and cc_uint32 are not exactly defined in this API due
+-// to a lack of standard 32-bit integer size between platforms
+-// (although there is the C9X standard).
+-// However, we will place the following constraints:
+-//
+-// cc_int32 is a signed integer that is at least 32 bits wide.
+-// cc_uint32 is an unsigned integer that is at least 32 bits wide
+- 
+-
+-typedef cc_int32 cc_time_t;  //see notes below
+-
+-typedef cc_uint32 cc_nc_flags;
+- 
+- 
+-
+-typedef struct opaque_dll_control_block_type* apiCB;
+-typedef struct opaque_ccache_pointer_type* ccache_p;
+-typedef struct opaque_credential_iterator_type* ccache_cit;
+- 
+-// These really are intended to be opaque. All implementations of the cache API must have
+-// them but what they are is implementation specific. In the case of SGR's implementation,
+-// the cc_ctx returned available after a call to cc_initialize, is a CCache_ctx class object. The 
+-// code that normally calls the cc_initialize function is straight C, which means the calling
+-// application doesn't have a chance in hell of manipulating this directly. The API is designed
+-// so that it does not have to. It does have to pass the pointer to the class around, one reason 
+-// being so that the destructor can eventually be called.
+- 
+- 
+-
+-typedef struct _cc_data {
+-    cc_uint32            type;
+-    cc_uint32            length;
+-    unsigned char*      data;
+-} cc_data;
+- 
+-
+-typedef struct _cc_creds {
+-    char*       client; /* client's principal identifier */
+-    char*       server; /* server's principal identifier */
+-    cc_data     keyblock;       /* session encryption key info */
+-    cc_time_t   authtime;
+-    cc_time_t   starttime;
+-    cc_time_t   endtime;
+-    cc_time_t   renew_till;
+-    cc_uint32    is_skey;        /* true if ticket is encrypted in
+-                                   another ticket's skey */
+-    cc_uint32    ticket_flags;   /* flags in ticket */
+-    cc_data**   addresses;      /* addrs in ticket */
+-    cc_data     ticket;         /* ticket string itself */
+-    cc_data     second_ticket;  /* second ticket, if related to
+-                                   ticket (via DUPLICATE-SKEY or
+-                                   ENC-TKT-IN-SKEY) */
+-    cc_data**   authdata;       /* authorization data */
+-} cc_creds;
+- 
+- 
+-// use an enumerated type so all callers infer the same meaning
+-// these values are what krbv4win uses internally.
+-
+-enum StringToKey_Type { STK_AFS = 0, STK_DES = 1 };
+- 
+-enum { MAX_V4_CRED_LEN = 1250 };
+- 
+- 
+-// V4 Credentials
+-
+-enum {
+-  KRB_NAME_SZ = 40,
+-  KRB_INSTANCE_SZ = 40,
+-  KRB_REALM_SZ = 40
+-};
+- 
+-typedef struct _V4credential {
+-    unsigned char              kversion;
+-    char                       principal[KRB_NAME_SZ+1];
+-    char                       principal_instance[KRB_INSTANCE_SZ+1];
+-    char                       service[KRB_NAME_SZ+1];
+-    char                       service_instance[KRB_INSTANCE_SZ+1];
+-    char                       realm[KRB_REALM_SZ+1];
+-    unsigned char              session_key[8];
+-    cc_int32                   kvno;                   // k95 used BYTE skvno
+-    cc_int32                   str_to_key;             // k4 infers dynamically, k95 stores; of type enum StringToKey_Type
+-    long                       issue_date;             // k95 called this issue_time
+-    cc_int32                   lifetime;               // k95 used LONG expiration_time
+-    cc_uint32                  address;                // IP Address of local host as an unsigned 32-bit integer
+-    cc_int32                   ticket_sz;              // k95 used BYTE, k4 ktext uses int to hold up to 1250
+-    unsigned char              ticket[MAX_V4_CRED_LEN];
+-    unsigned long              oops;                   // zero to catch runaways
+-} V4Cred_type;
+- 
+-
+-enum cc_cred_vers {  
+-    CC_CRED_VUNKNOWN = 0,       // For validation
+-    CC_CRED_V4 = 1,
+-    CC_CRED_V5 = 2,
+-    CC_CRED_VMAX = 3            // For validation
+-};
+- 
+-
+-typedef union cred_ptr_union_type {
+-    V4Cred_type* pV4Cred;
+-    cc_creds*    pV5Cred;
+-} cred_ptr_union;
+- 
+-
+-typedef struct cred_union_type {
+-    cc_int32 cred_type;  // cc_cred_vers
+-    cred_ptr_union cred;
+-} cred_union;
+- 
+-
+-typedef struct _infoNC {
+-        char*   name;
+-        char*   principal;
+-        cc_int32 vers;   // cc_cred_vers
+-} infoNC;
+- +-

The cc_data structure

+- +-

The cc_data structure is used to store the following elements: +- +-

    +-
  • keyblock +- +-
  • addresses +- +-
  • ticket (and second_ticket) +- +-
  • authorization data +-
+- +-

For cc_creds.ticket and cc_creds.second_ticket, the cc_data.type +-field MUST be zero. For the cc_creds.addresses, cc_creds.authdata, +-and cc_data.keyblock, the cc_data.type field should be the address +-type, authorization data type, and encryption type, as defined by the +-Kerberos V5 protocol definition. +- +-

cc_time_t

+- +-

The cc_time_t fields are used to represent time. The time must be +-stored as the number of seconds since midnight GMT on January 1, +-1970. +- +-

Principal names

+- +-

Principal names are stored as C strings in this API. The C strings +-may contain UTF-8 encoded strings for internationalization +-purposes.
+- +- +-


+- +- +-

Error Codes Definition

+- +-

+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
+-

0  +-

+-

CC_NOERROR  +-

+-

"Successful return"  +-

+-

1  +-

+-

CC_BADNAME  +-

+-

"Bad credential cache name format"  +-

+-

2  +-

+-

CC_NOTFOUD  +-

+-

"Matching credential not found"  +-

+-

3  +-

+-

CC_END  +-

+-

"End of credential cache reached"  +-

+-

4  +-

+-

CC_IO  +-

+-

"Credentials cache I/O operation failed"  +-

+-

5  +-

+-

CC_WRITE  +-

+-

"Error writing to credentials cache file"  +-

+-

6  +-

+-

CC_NOMEM  +-

+-

"No memory"  +-

+-

7  +-

+-

CC_FORMAT  +-

+-

"Corrupted credentials cache"  +-

+-

8  +-

+-

CC_LOCKED  +-

+-

"The credentials cache or NC is locked"  +-

+-

9  +-

+-

CC_BAD_API_VERSION  +-

+-

"Unsupported API version"  +-

+-

10  +-

+-

CC_NO_EXIST  +-

+-

"Credentials cache or NC does not exist"  +-

+-

11  +-

+-

CC_NOT_SUPP  +-

+-

"Function not supported"  +-

+-

12  +-

+-

CC_BAD_PARM  +-

+-

"Bad Paramter Passed"  +-

+-

13  +-

+-

CC_ERR_CACHE_ATTACH  +-

+-

"Failed to attach cache"  +-

+-

14  +-

+-

CC_ERR_CACHE_RELEASE  +-

+-

"Failed to release cache"  +-

+-

15  +-

+-

CC_ERR_CACHE_FULL  +-

+-

"Cache FULL"  +-

+-

16  +-

+-

CC_ERR_CRED_VERSION  +-

+-

"Wrong Cred Version"  +-

+- +-

+-


+- +- +-

Implementation Notes

+- +-

All functions are atomic

+- +-

All Credentials Cache API functions must be atomic. +- +-

Windows +- +-

DLLs should be named KrbCC16.dll and KrbCC32.dll. +- +-

+-


+- +- +-

Function definitions

+- +-

+- +-

Main Cache Functions

+- +-

+- +- +-

+- +-

cc_initialize

+- +-
cc_int32 cc_initialize(apiCB** cc_ctx, cc_int32 api_version, cc_int32* api_supported, char** vendor)
+- +-

This function performs any initialization required by the +-API. It must be called before any other function in the +-API is called. The cc_ctx returned by this function must be +-passed to all other API functions as the first argument. +- +-

The application must pass in the maximum version number of the API +-it supports in the api_version parameter. +- +-

If api_supported non-NULL, then cc_initialize will store +-the maximum API version number supported by the library implementing +-the API there. +- +-

If the version requested by api_version is not equal to the +-version supported by the library, CC_BAD_API_VERSION will be returned +-as the error code (along with the version the library does support in +-api_supported) and cc_initialize should not allocate any +-memory. +- +-

If the vendor is non-NULL, then cc_initialize will store a +-pointer to a read/only C string which contains a string describing +-the vendor which implemented the credentials cache API. +- +-

Possible error codes: CC_NOERROR, CC_NOMEM, CC_BAD_API_VERSION, +-CC_BAD_PARM +- +-


+- +- +- +-

cc_shutdown

+- +-
cc_int32 cc_shutdown(apiCB** cc_ctx)
+- +-

This function performs any cleanup required by the API. +-cc_ctx will be NULL on return. The application program must call +-cc_initialize() again before making any credentials cache API +-calls. +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM +- +-


+- +- +- +-

cc_get_change_time

+- +-
cc_int32 cc_get_change_time(apiCB* cc_ctx, cc_time_t* time)
+- +-

This function returns the time of the most recent change for the +-entire cache. There is ONE timestamp maintained for the entire cache. +-By maintaining a local copy the caller can deduce whether "something +-changed" or not. +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_NOMEM, +-CC_BAD_PARM +- +-


+- +- +- +-

cc_get_NC_info

+- +-
cc_int32 cc_get_NC_info(apiCB* cc_ctx, infoNC*** ppNCi)
+- +-

cc_get_NC_info() is a wrapper for cc_seq_fetch_NCs(), +-cc_get_name() cc_get_cred_version(), and cc_get_principal(). It +-returns all the information needed to uniquely identify each NC in +-the cache (name and cred_version) and the associated principal. +-Specifically it returns a null terminated list of pointers to infoNC +-structs. Each infoNC struct contain a pointer to the NC's name, a +-pointer to the the principal associated with the NC, and the version +-number (as an enumerated type) of the credentials stored in this NC. +- +-

The ppNCi (the entire data structure) aquired by this routine +-should be freed with cc_free_NC_info(). +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_NOMEM, +-CC_BAD_PARM +- +-


+- +- +- +-

cc_open

+- +-
cc_int32 cc_open(apiCB* cc_ctx, const char* name, cc_int32 cred_vers, cc_uint32 cc_flags,
+-                 ccache_p** ccache_pointer)
+- +-

Opens an already exising NC identified by both name, and +-cred_vers. It fills in the parameter **ccache_pointer with a +-pointer to the NC. +- +-

The list of cache names, principals, and credentials versions may +-be retrieved via cc_seq_fetch_NCs(), cc_get_name(), +-cc_get_cred_version(), & cc_get_principal() OR via +-cc_get_NC_info(). +- +-

Possible error codes: CC_NOERROR, CC_BADNAME, CC_NO_EXIST, +-CC_NOMEM, CC_ERR_CRED_VERSION, CC_BAD_PARM +- +-


+- +- +- +-

cc_create

+- +-
cc_int32 cc_create(apiCB* cc_ctx, const char* name, const char* principal,
+-                cc_int32 cred_vers, cc_uint32 cc_flags, ccache_p** ccache_pointer)
+- +-

Create a new NC. The NC is uniquely identified by the combination +-of it's name and the "cc_creds_vers" (i.e. which credentials version +-it holds). The principal given is also associated with the NC. A NULL +-name is not allowed (and CC_BADNAME should be returned if one +-is passed in). If name is non-null and there is already a NC +-named name, all credentials in the cache are removed, and +-handle for the existing cache is returned. If there is already a NC +-named name, all existing handles for this cache remain valid. The NC +-is created with a primary principal specified by principal. +- +-

(Removed text about the "expected" form of the NC name.) +- +-

An NC is intended to hold credentials for a single principal in a +-single realm, and for a single credentials version (i.e. V4 or V5). +-The cache can contain credentials for other credential versions, +-other realms, and even other principals, but each in a separate NC. +-This rule will allow callers that can only handle a single principal +-in a single realm to continue to work by dealing with only one NC. +-Callers that can deal with multiple principals, multiple realms, +-and/or multiple credentials versions can do so by dealing with +-multiple NCs. By doing it this way, the callers that are able to +-handle multiple principals, realms, and/or versions can do so without +-interfering with "differently abled" code. +- +-

The list of cache names, principals, & cred_versions may be +-retrieved via cc_get_NC_info(). +- +-

Possible error codes: CC_NOERROR, CC_BADNAME, CC_BAD_PARM, +-CC_NO_EXIST, CC_NOMEM, CC_ERR_CRED_VERSION +- +-


+- +- +- +-

cc_close

+- +-
cc_int32 cc_close(apiCB* cc_ctx, ccache_p** ccache_pointer)
+- +-

Close the NC. The ccache_pointer related memory is +-deallocated, and ccache_pointer is set to NULL before being returned +-to caller. +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM +- +-


+- +- +- +-

cc_destroy

+- +-
cc_int32 cc_destroy(apiCB* cc_ctx, ccache_p** ccache_pointer)
+- +-

Destroy the NC pointed to by ccache_pointer. The +-ccache_pointer related memory is deallocated, and +-ccache_pointer is set to NULL before being returned to caller. The +-caller does not need to call cc_close() on the cache_pointer +-afterwards. +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM +- +-


+- +- +- +-

+- +-

cc_seq_fetch_NCs_begin

+- +-
cc_int32 cc_seq_fetch_NCs_begin(apiCB* cc_ctx, ccache_cit** itNCs)
+- +-

Used to allocate memory and initialize the iterator *itNCs. Use +-cc_seq_fetch_NCs_end() to deallocate the memory used by *itNCs. +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM, +-CC_NOMEM +- +-

+- +-

cc_seq_fetch_NCs_next

+- +-
cc_int32 cc_seq_fetch_NCs_next(apiCB* cc_ctx, ccache_p** ccache_pointer, ccache_cit* itNCs)
+- +-

Used to sequentially open every NC in the cache. +- +-

Ccache_pointer must be a pointer to a ccache_p*. The +-ccache_pointer returned may be used to get information about the NC +-by calling cc_get_name(), cc_get_cred_version(), and +-cc_get_principal(). Ccache_pointer's returned must be freed via +-cc_close() between calls to cc_seq_fetch_NCs_next(). +- +-

itNCs must be a pointer to a ccache_cit* variable provided by the +-calling application and which is used by cc_seq_fetch_NCs_next() to +-determine the next NC to return. It must have been initialized by +-cc_seq_fetch_NCs_begin(). +- +-

If changes are made to the credentials cache while it iterator is +-being used, it must return at least the intersection, and at most the +-union, of the set of NC's that were in the cache when the iteration +-began and the set of NC's that are in the cache when it ends. +- +-

When the last NC in the sequence is returned, the return code from +-cc_seq_fetch_NCs_next() will be CC_END. +- +-

Possible error codes: CC_NOERROR, CC_END, CC_NO_EXIST. +-CC_BAD_PARM, CC_NOMEM +- +-

 

+- +-

+- +-

cc_seq_fetch_NCs_end

+- +-
cc_int32 cc_seq_fetch_NCs_end(apiCB* cc_ctx, ccache_cit** itNCs)
+- +-

Deallocates the memory used by *itNCs, and sets *itNCs to NULL. +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM +- +-

  +- +-

+- +-

NC Functions

+- +-

+- +- +-

cc_get_name

+- +-
cc_int32 cc_get_name(apiCB* cc_ctx, const ccache_p* ccache_pointer, char** name)
+- +-

cc_get_name() returns the name of the NC indicated by +-ccache_pointer. The name can be used in cc_open() or cc_create(). The +-combination of the name and the credentials version uniqeuly identify +-an NC. The returned name should be freed via cc_free_name(). +- +-

Possible error codes: CC_NOERROR, CC_NOMEM, CC_NO_EXIST, +-CC_BAD_PARM +- +-


+- +- +- +-

cc_get_cred_version

+- +-
cc_int32 cc_get_cred_version(apiCB* cc_ctx, const ccache_p* ccache_pointer, cc_int32* cred_vers)
+- +-

cc_get_cred_version() returns one of the enumerated type +-cc_cred_vers in cred_vers. The expected values are CC_CRED_V4, or +-CC_CRED_V5. The combination of the name and the credentials version +-uniquely identify an NC. +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM +- +-


+- +- +- +-

cc_set_principal

+- +-
cc_int32 cc_set_principal(apiCB* cc_ctx, const ccache_p* ccache_pointer, const cc_int32 cred_vers,
+-                          const char* principal)
+- +-

Set the primary principal for the NC indicated by ccache_pointer. +-This is the complement to cc_get_principal(). +- +-

cred_vers is used as a double check. +- +-

principal points to a null terminated string that will be copied +-into the NC. This new principal will be returned if you call +-cc_get_principal() for this NC. +- +-

Possible error codes: CC_NOERROR, CC_NOMEM, CC_NO_EXIST, +-CC_ERR_CRED_VERSION, CC_BAD_PARM
+- +-  +- +-


+- +- +- +-

cc_get_principal

+- +-
cc_int32 cc_get_principal(apiCB* cc_ctx, const ccache_p* ccache_pointer, char** principal)
+- +-

Return the primary principal for the NC that was set via +-cc_create() or cc_set_principal(). The returned principal should be +-freed via cc_free_principal() . +- +-

Possible error codes: CC_NOERROR, CC_NOMEM, CC_NO_EXIST, +-CC_BAD_PARM
+- +- +- +-


+- +- +- +-

cc_store

+- +-
cc_int32 cc_store(apiCB* cc_ctx, ccache_p* ccache_pointer, const cred_union cred)
+- +-

Store (make a copy of) cred in the NC indicated by +-ccache_pointer. +- +-

A cred_union contains a cred_type indicator and a cred_ptr_union. +-A cred_ptr_union can contain either a V4Cred_type pointer or a +-cc_creds (V5 creds) pointer. Cred_type indicates which type of +-pointer is in the cred_ptr_union. This also allows the API to +-enforce the credentials version declared in cc_create() or cc_open(). +- +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_ERR_CACHE_FULL, +-CC_ERR_CRED_VERSION, CC_BAD_PARM +- +-


+- +- +- +-

cc_remove_cred

+- +-
cc_int32 cc_remove_cred(apiCB* cc_ctx, ccache_p* ccache_pointer, const cred_union cred)
+- +-

Removes the credential cred from ccache_pointer. The +-credentials in the NC indicated by ccache_pointer are searched to +-find a matching credential. If found, that credential is removed from +-the NC. The cred parameter is not modified and should be freed via +-cc_free_creds(). It is legitimate to call this function during a +-sequential fetch, and the deletion of a credential already returned +-by cc_seq_fetch_creds() should not disturb sequence of credentials +-returned by cc_seq_fetch_creds(). +- +-

Use of cred_union is the same as is explained in cc_store(). +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_NOTFOUND, +-CC_ERR_CRED_VERSION, CC_BAD_PARM +- +-


+- +- +- +-

cc_seq_fetch_creds_begin

+- +-
cc_int32 cc_seq_fetch_creds_begin(apiCB* cc_ctx, const ccache_p* ccache_pointer, ccache_cit** itCreds)
+- +-

Allocates memory for and initializes *itCreds. This memory must be +-deallocated using cc_seq_fetch_creds_end(). +- +-

Ccache_pointer must be a valid pointer to the NC containing the +-creds to be returned by the iterator. +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM, +-CC_NOMEM +- +-

  +- +-

+- +-

cc_seq_fetch_creds_next

+- +-
cc_int32 cc_seq_fetch_creds_next(apiCB* cc_ctx, cred_union** cred, ccache_cit* itCreds)
+- +-

cc_seq_fetch_creds_next() is used to sequentially read every set +-of credentials in an NC. The NC has been indicated in the call to +-cc_seq_fetch_creds_begin(). +- +-

itCreds must be a pointer to a ccache_cit* variable provided by +-the calling application and which is used by +-cc_seq_fetch_creds_next() to determine the next cached credential to +-return. The ccache_cit* variable must be initialized by calling +-cc_seq_fetch_creds_begin(). +- +-

The credentials are filled into the cred_union pointed to by +-creds. Note that the cred_union contains elements which are +-dynamically allocated, so must be freed using cc_free_creds() between +-calls to cc_seq_fetch_creds_next(). +- +-

If changes are made to the NC while it iterator is being used, it +-must return at least the intersection, and at most the union, of the +-set of credentials that were in the NC when the iteration began and +-the set of credentials that are in the NC when it ends. +- +-

When the last credential in the sequence is returned, the return +-code from cc_seq_fetch_creds_next() will be CC_END. +- +-

Possible error codes: CC_NOERROR, CC_END, CC_NO_EXIST, +-CC_BAD_PARM, CC_NOMEM +- +-

  +- +-

+- +-

cc_seq_fetch_creds_end

+- +-
cc_int32 cc_seq_fetch_creds_end(apiCB* cc_ctx, ccache_cit** itCreds)
+- +-

Deallocates memory used by *itCreds and sets *itCreds to NULL. +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM +- +-


+- +- +- +-

cc_lock_request

+- +-
cc_int32 cc_lock_request(apiCB* cc_ctx, const ccache_p* ccache_pointer, cc_int32 lock_type)
+- +-
+-
99/02/11 - smcguire +- +-
As of this date there is no locking in the Win NT/95 +- or Machintosh implementations. The description below may not be +- completely accurate as to how this function should be +- implemented. +-
+- +-

This function is currently NOT IMPLEMENTED. All functions attach +-to the cache, take action, and detach from the cache before returning +-to the caller. +- +-

This function will lock or unlock the NC based on the argument +-value of lock_type: +- +-

        CC_LOCK_UNLOCK  1       Unlock the NC
+-        CC_LOCK_READER  2       Lock the NC for reading
+-        CC_LOCK_WRITER  3       Lock the NC for writing
+- 
+-        CC_LOCK_NOBLOCK 16      Don't block, but return an error code if
+-                                the request cannot be satisfied.
+- 
+- +-

Locking is done on a per-thread basis. At most one thread may have +-the credentials locked for writing; if so, there must not be any +-threads that have the credentials locked for reading. +- +-

Multiple threads may have the cache locked for reading, as long as +-there is not a writer lock asserted on the cache. +- +-

If a thread has a cache locked for reading, that lock may be +-upgraded to a writer lock by calling cc_lock_request() with a +-lock_type of CC_LOCK_WRITER. If a thread has the cache locked for +-reading or writing, a request to cc_lock_request() for a reader or +-writer lock, respectively, is a no-op. If a thread does not have the +-cache locked, and calls cc_lock_request() with a lock_type of +-CC_LOCK_UNLOCK, this is also a no-op. +- +-

A request for CC_LOCK_READER and CC_LOCK_WRITER may be made +-non-blocking by logical or'ing the value CC_LOCK_NOBLOCK. In that +-case, if it is not possible to satisfy the lock request, the error +-CC_LOCKED will be returned. +- +-

  +- +-

+- +-

Liberation Functions

+- +-

+- +- +-

cc_free_principal

+- +-
cc_int32 cc_free_principal(apiCB* cc_ctx, char** principal)
+- +-

This function frees the principal returned by +-cc_get_principal() and sets *principal to NULL. +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM +- +-


+- +- +- +-

cc_free_name

+- +-
cc_int32 cc_free_name(apiCB* cc_ctx, char** name)
+- +-

This function frees the name returned by cc_get_name() and +-sets *name to NULL. +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM +- +-


+- +- +- +-

cc_free_creds

+- +-
cc_int32 cc_free_creds(apiCB* cc_ctx, cred_union** creds)
+- +-

This function frees all storage associated with creds returned by +-cc_seq_fetch_creds() and sets the creds pointer to NULL. +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM +- +-


+- +- +- +-

cc_free_NC_info

+- +-
cc_int32 cc_free_NC_info(apiCB* cc_ctx, infoNC*** ppNCi)
+- +-

This routine frees all storage aquired by cc_get_NC_info() and +-sets ppNCi to NULL. +- +-

Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM +- +- +- +- +- +diff --git a/doc/ccapi/html/doxygen.css b/doc/ccapi/html/doxygen.css +deleted file mode 100644 +index 05615b2e6..000000000 +--- a/doc/ccapi/html/doxygen.css ++++ /dev/null +@@ -1,310 +0,0 @@ +-BODY,H1,H2,H3,H4,H5,H6,P,CENTER,TD,TH,UL,DL,DIV { +- font-family: Geneva, Arial, Helvetica, sans-serif; +-} +-BODY,TD { +- font-size: 90%; +-} +-H1 { +- text-align: center; +- font-size: 160%; +-} +-H2 { +- font-size: 120%; +-} +-H3 { +- font-size: 100%; +-} +-CAPTION { font-weight: bold } +-DIV.qindex { +- width: 100%; +- background-color: #e8eef2; +- border: 1px solid #84b0c7; +- text-align: center; +- margin: 2px; +- padding: 2px; +- line-height: 140%; +-} +-DIV.nav { +- width: 100%; +- background-color: #e8eef2; +- border: 1px solid #84b0c7; +- text-align: center; +- margin: 2px; +- padding: 2px; +- line-height: 140%; +-} +-DIV.navtab { +- background-color: #e8eef2; +- border: 1px solid #84b0c7; +- text-align: center; +- margin: 2px; +- margin-right: 15px; +- padding: 2px; +-} +-TD.navtab { +- font-size: 70%; +-} +-A.qindex { +- text-decoration: none; +- font-weight: bold; +- color: #1A419D; +-} +-A.qindex:visited { +- text-decoration: none; +- font-weight: bold; +- color: #1A419D +-} +-A.qindex:hover { +- text-decoration: none; +- background-color: #ddddff; +-} +-A.qindexHL { +- text-decoration: none; +- font-weight: bold; +- background-color: #6666cc; +- color: #ffffff; +- border: 1px double #9295C2; +-} +-A.qindexHL:hover { +- text-decoration: none; +- background-color: #6666cc; +- color: #ffffff; +-} +-A.qindexHL:visited { text-decoration: none; background-color: #6666cc; color: #ffffff } +-A.el { text-decoration: none; font-weight: bold } +-A.elRef { font-weight: bold } +-A.code:link { text-decoration: none; font-weight: normal; color: #0000FF} +-A.code:visited { text-decoration: none; font-weight: normal; color: #0000FF} +-A.codeRef:link { font-weight: normal; color: #0000FF} +-A.codeRef:visited { font-weight: normal; color: #0000FF} +-A:hover { text-decoration: none; background-color: #f2f2ff } +-DL.el { margin-left: -1cm } +-.fragment { +- font-family: Fixed, monospace; +- font-size: 95%; +-} +-PRE.fragment { +- border: 1px solid #CCCCCC; +- background-color: #f5f5f5; +- margin-top: 4px; +- margin-bottom: 4px; +- margin-left: 2px; +- margin-right: 8px; +- padding-left: 6px; +- padding-right: 6px; +- padding-top: 4px; +- padding-bottom: 4px; +-} +-DIV.ah { background-color: black; font-weight: bold; color: #ffffff; margin-bottom: 3px; margin-top: 3px } +-TD.md { background-color: #F4F4FB; font-weight: bold; } +-TD.mdPrefix { +- background-color: #F4F4FB; +- color: #606060; +- font-size: 80%; +-} +-TD.mdname1 { background-color: #F4F4FB; font-weight: bold; color: #602020; } +-TD.mdname { background-color: #F4F4FB; font-weight: bold; color: #602020; width: 600px; } +-DIV.groupHeader { +- margin-left: 16px; +- margin-top: 12px; +- margin-bottom: 6px; +- font-weight: bold; +-} +-DIV.groupText { margin-left: 16px; font-style: italic; font-size: 90% } +-BODY { +- background: white; +- color: black; +- margin-right: 20px; +- margin-left: 20px; +-} +-TD.indexkey { +- background-color: #e8eef2; +- font-weight: bold; +- padding-right : 10px; +- padding-top : 2px; +- padding-left : 10px; +- padding-bottom : 2px; +- margin-left : 0px; +- margin-right : 0px; +- margin-top : 2px; +- margin-bottom : 2px; +- border: 1px solid #CCCCCC; +-} +-TD.indexvalue { +- background-color: #e8eef2; +- font-style: italic; +- padding-right : 10px; +- padding-top : 2px; +- padding-left : 10px; +- padding-bottom : 2px; +- margin-left : 0px; +- margin-right : 0px; +- margin-top : 2px; +- margin-bottom : 2px; +- border: 1px solid #CCCCCC; +-} +-TR.memlist { +- background-color: #f0f0f0; +-} +-P.formulaDsp { text-align: center; } +-IMG.formulaDsp { } +-IMG.formulaInl { vertical-align: middle; } +-SPAN.keyword { color: #008000 } +-SPAN.keywordtype { color: #604020 } +-SPAN.keywordflow { color: #e08000 } +-SPAN.comment { color: #800000 } +-SPAN.preprocessor { color: #806020 } +-SPAN.stringliteral { color: #002080 } +-SPAN.charliteral { color: #008080 } +-.mdTable { +- border: 1px solid #868686; +- background-color: #F4F4FB; +-} +-.mdRow { +- padding: 8px 10px; +-} +-.mdescLeft { +- padding: 0px 8px 4px 8px; +- font-size: 80%; +- font-style: italic; +- background-color: #FAFAFA; +- border-top: 1px none #E0E0E0; +- border-right: 1px none #E0E0E0; +- border-bottom: 1px none #E0E0E0; +- border-left: 1px none #E0E0E0; +- margin: 0px; +-} +-.mdescRight { +- padding: 0px 8px 4px 8px; +- font-size: 80%; +- font-style: italic; +- background-color: #FAFAFA; +- border-top: 1px none #E0E0E0; +- border-right: 1px none #E0E0E0; +- border-bottom: 1px none #E0E0E0; +- border-left: 1px none #E0E0E0; +- margin: 0px; +-} +-.memItemLeft { +- padding: 1px 0px 0px 8px; +- margin: 4px; +- border-top-width: 1px; +- border-right-width: 1px; +- border-bottom-width: 1px; +- border-left-width: 1px; +- border-top-color: #E0E0E0; +- border-right-color: #E0E0E0; +- border-bottom-color: #E0E0E0; +- border-left-color: #E0E0E0; +- border-top-style: solid; +- border-right-style: none; +- border-bottom-style: none; +- border-left-style: none; +- background-color: #FAFAFA; +- font-size: 80%; +-} +-.memItemRight { +- padding: 1px 8px 0px 8px; +- margin: 4px; +- border-top-width: 1px; +- border-right-width: 1px; +- border-bottom-width: 1px; +- border-left-width: 1px; +- border-top-color: #E0E0E0; +- border-right-color: #E0E0E0; +- border-bottom-color: #E0E0E0; +- border-left-color: #E0E0E0; +- border-top-style: solid; +- border-right-style: none; +- border-bottom-style: none; +- border-left-style: none; +- background-color: #FAFAFA; +- font-size: 80%; +-} +-.memTemplItemLeft { +- padding: 1px 0px 0px 8px; +- margin: 4px; +- border-top-width: 1px; +- border-right-width: 1px; +- border-bottom-width: 1px; +- border-left-width: 1px; +- border-top-color: #E0E0E0; +- border-right-color: #E0E0E0; +- border-bottom-color: #E0E0E0; +- border-left-color: #E0E0E0; +- border-top-style: none; +- border-right-style: none; +- border-bottom-style: none; +- border-left-style: none; +- background-color: #FAFAFA; +- font-size: 80%; +-} +-.memTemplItemRight { +- padding: 1px 8px 0px 8px; +- margin: 4px; +- border-top-width: 1px; +- border-right-width: 1px; +- border-bottom-width: 1px; +- border-left-width: 1px; +- border-top-color: #E0E0E0; +- border-right-color: #E0E0E0; +- border-bottom-color: #E0E0E0; +- border-left-color: #E0E0E0; +- border-top-style: none; +- border-right-style: none; +- border-bottom-style: none; +- border-left-style: none; +- background-color: #FAFAFA; +- font-size: 80%; +-} +-.memTemplParams { +- padding: 1px 0px 0px 8px; +- margin: 4px; +- border-top-width: 1px; +- border-right-width: 1px; +- border-bottom-width: 1px; +- border-left-width: 1px; +- border-top-color: #E0E0E0; +- border-right-color: #E0E0E0; +- border-bottom-color: #E0E0E0; +- border-left-color: #E0E0E0; +- border-top-style: solid; +- border-right-style: none; +- border-bottom-style: none; +- border-left-style: none; +- color: #606060; +- background-color: #FAFAFA; +- font-size: 80%; +-} +-.search { color: #003399; +- font-weight: bold; +-} +-FORM.search { +- margin-bottom: 0px; +- margin-top: 0px; +-} +-INPUT.search { font-size: 75%; +- color: #000080; +- font-weight: normal; +- background-color: #e8eef2; +-} +-TD.tiny { font-size: 75%; +-} +-a { +- color: #1A41A8; +-} +-a:visited { +- color: #2A3798; +-} +-.dirtab { padding: 4px; +- border-collapse: collapse; +- border: 1px solid #84b0c7; +-} +-TH.dirtab { background: #e8eef2; +- font-weight: bold; +-} +-HR { height: 1px; +- border: none; +- border-top: 1px solid black; +-} +- +diff --git a/doc/ccapi/html/doxygen.png b/doc/ccapi/html/doxygen.png +deleted file mode 100644 +index f0a274bbaffdd67f6d784c894d9cf28729db0e14..0000000000000000000000000000000000000000 +GIT binary patch +literal 0 +HcmV?d00001 + +literal 1281 +zcmaJ>ZA?>F7(Vx-ms?uoS`b@hdRtpo6o^%HU>M$hfGrBvQnk$LE?p^P!kn&ikhyq! +zX~V@&tPF5Qt@V?oTL96Bi%aRiwbe1)9DWQI#?)=HxS7QSw`J`5fAJ*eJbB;uNuKA& +zdERDo*{Y<(If(#(B$Lr#;nB(8Y#ia=ZCeW?JfPLuQY`=@cW$k}Rivq|vbxGrRq1Tl9;+(gNt?}UtVKM2`T5t1jLzuL@0UIs`S#vlhl4)^ +zLgSYrPj@$+`|j?eSbXTmiHGkWxV8V}BzNR?pl9k_s4pDu9vd5a_UzZEPk)}Ad{AV_ +zzddrjrh4=Imr`E06;LY{)YYt?o}L~H@7C}F^WB!Ra=v`Q0bj{>5&$66CWF>mf6vjP +z2N>RRY6ZYa=K`76>+|_)Xdwko+7wv}7cN|btOhWb(*{sta~6b?S8Omrxw}!4`NhGr +zZVpNqpu1@BE`QGWNTpEpcJVW5izu~2B^GlM?1(OPg)zwW;QcP@Ltcclm>XbJL9C|j +z=9!2?ua=uIlf0%AndzHsRC}IyTL$EhAee(fdKB`?27KeS^2M8M_7b~PiCFO&r5LC7 +z7gl1*a<8;SjNaw#h=843_AV9iZbWQOAp5YOC^&_F*9K0> +zB|6%IDb?aM#3viTxkLU4aXg&@+CkNTOnQ1iMP*^?b|^lJy$4C)Zk4isV!|RZ*XhXh +zw8q3$=*0LeGC!XI_Wc?dkT~3+*Gu%%yIqP+Wr3H$=&ROMQU6q}Ag^P~>c5vAEO;a- +z_dK-3PPeKar%)6$j~vI2#*-YH!1h6HYVtwCX5_wM`iF#UKz&&@9Oo5w3%XGYrX +zW>dY~)SG-((Yim%`InwgTvyRC?e=Wh^8KCao!R6Eg&TpVWUY1sN~4G}V?nFnEGo-; +zHZ_$eW9-GnC%^WS9b +z@p;-$oH#MtC0v>Q$HX%4^JdFdO$0cbv-W)Q +TtK}Eh@>>I#ipmV1>S*>q-hkC} + +diff --git a/doc/ccapi/html/group__cc__ccache__iterator__reference.html b/doc/ccapi/html/group__cc__ccache__iterator__reference.html +deleted file mode 100644 +index 2c8bfe27b..000000000 +--- a/doc/ccapi/html/group__cc__ccache__iterator__reference.html ++++ /dev/null +@@ -1,96 +0,0 @@ +- +- +-Credentials Cache API : cc_ccache_iterator_t Overview +- +- +- +- +-

cc_ccache_iterator_t Overview


Detailed Description

+-The cc_ccache_iterator_t type represents an iterator that iterates over a set of ccaches and returns them in all in some order. A new instance of this type can be obtained by calling cc_context_new_ccache_iterator().

+-For API function documentation see cc_ccache_iterator_f. +-

+-

Data Structures

+- +-

Typedefs

+- +-

Typedef Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_ccache_iterator_f cc_ccache_iterator_f
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_ccache_iterator_d cc_ccache_iterator_d
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef cc_ccache_iterator_d* cc_ccache_iterator_t
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/group__cc__ccache__reference.html b/doc/ccapi/html/group__cc__ccache__reference.html +deleted file mode 100644 +index ce47b73c6..000000000 +--- a/doc/ccapi/html/group__cc__ccache__reference.html ++++ /dev/null +@@ -1,96 +0,0 @@ +- +- +-Credentials Cache API : cc_ccache_t Overview +- +- +- +- +-

cc_ccache_t Overview


Detailed Description

+-The cc_ccache_t type represents a reference to a ccache. Callers can access a ccache and the credentials stored in it via a cc_ccache_t. A cc_ccache_t can be acquired via cc_context_open_ccache(), cc_context_open_default_ccache(), or cc_ccache_iterator_next().

+-For API function documentation see cc_ccache_f. +-

+-

Data Structures

+- +-

Typedefs

+- +-

Typedef Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_ccache_f cc_ccache_f
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_ccache_d cc_ccache_d
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef cc_ccache_d* cc_ccache_t
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/group__cc__context__reference.html b/doc/ccapi/html/group__cc__context__reference.html +deleted file mode 100644 +index cd7e6be3d..000000000 +--- a/doc/ccapi/html/group__cc__context__reference.html ++++ /dev/null +@@ -1,161 +0,0 @@ +- +- +-Credentials Cache API : cc_context_t Overview +- +- +- +- +-

cc_context_t Overview


Detailed Description

+-The cc_context_t type gives the caller access to a ccache collection. Before being able to call any functions in the CCache API, the caller needs to acquire an instance of cc_context_t by calling cc_initialize().

+-For API function documentation see cc_context_f. +-

+-

Data Structures

+- +-

Typedefs

+- +-

Functions

+- +-

Typedef Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_context_f cc_context_f
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_context_d cc_context_d
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef cc_context_d* cc_context_t
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-


Function Documentation

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
CCACHE_API cc_int32 cc_initialize cc_context_t out_context,
cc_int32  in_version,
cc_int32 out_supported_version,
char const **  out_vendor
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Initialize a new cc_context. +-

+-

Parameters:
+- +- +- +- +- +-
out_context on exit, a new context object. Must be free with cc_context_release().
in_version the requested API version. This should be the maximum version the application supports.
out_supported_version if non-NULL, on exit contains the maximum API version supported by the implementation.
out_vendor if non-NULL, on exit contains a pointer to a read-only C string which contains a string describing the vendor which implemented the credentials cache API.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure. May return CCAPI v2 error CC_BAD_API_VERSION if ccapi_version_2 is passed in.
+-
+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/group__cc__credentials__iterator__reference.html b/doc/ccapi/html/group__cc__credentials__iterator__reference.html +deleted file mode 100644 +index 41ba42f86..000000000 +--- a/doc/ccapi/html/group__cc__credentials__iterator__reference.html ++++ /dev/null +@@ -1,133 +0,0 @@ +- +- +-Credentials Cache API : cc_credentials_iterator_t +- +- +- +- +-

cc_credentials_iterator_t


Detailed Description

+-The cc_credentials_iterator_t type represents an iterator that iterates over a set of credentials. A new instance of this type can be obtained by calling cc_ccache_new_credentials_iterator().

+-For API function documentation see cc_credentials_iterator_f. +-

+-

Data Structures

+- +-

Typedefs

+- +-

Variables

+- +-

Typedef Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_credentials_iterator_f cc_credentials_iterator_f
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_credentials_iterator_d cc_credentials_iterator_d
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef cc_credentials_iterator_d* cc_credentials_iterator_t
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-


Variable Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* clone)(cc_credentials_iterator_t in_credentials_iterator, cc_credentials_iterator_t *out_credentials_iterator) [inherited]
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_credentials_iterator_clone(): Make a copy of a credentials iterator. +-

+-

Parameters:
+- +- +- +-
in_credentials_iterator a credentials iterator object.
out_credentials_iterator on exit, a copy of in_credentials_iterator.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/group__cc__credentials__reference.html b/doc/ccapi/html/group__cc__credentials__reference.html +deleted file mode 100644 +index d083e6c07..000000000 +--- a/doc/ccapi/html/group__cc__credentials__reference.html ++++ /dev/null +@@ -1,197 +0,0 @@ +- +- +-Credentials Cache API : cc_credentials_t Overview +- +- +- +- +-

cc_credentials_t Overview


Detailed Description

+-The cc_credentials_t type is used to store a single set of credentials for either Kerberos v4 or Kerberos v5. In addition to its only function, release(), it contains a pointer to a cc_credentials_union structure. A cc_credentials_union structure contains an integer of the enumerator type cc_credentials_version, which is either cc_credentials_v4 or cc_credentials_v5, and a pointer union, which contains either a cc_credentials_v4_t pointer or a cc_credentials_v5_t pointer, depending on the value in version.

+-Variables of the type cc_credentials_t are allocated by the CCAPI implementation, and should be released with their release() function. API functions which receive credentials structures from the caller always accept cc_credentials_union, which is allocated by the caller, and accordingly disposed by the caller.

+-For API functions see cc_credentials_f. +-

+-

Data Structures

+- +-

Typedefs

+- +-

Typedef Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_credentials_v4_t cc_credentials_v4_t
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_data cc_data
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_credentials_v5_t cc_credentials_v5_t
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_credentials_union cc_credentials_union
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_credentials_f cc_credentials_f
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_credentials_d cc_credentials_d
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef cc_credentials_d* cc_credentials_t
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/group__cc__string__reference.html b/doc/ccapi/html/group__cc__string__reference.html +deleted file mode 100644 +index 9ce3b7195..000000000 +--- a/doc/ccapi/html/group__cc__string__reference.html ++++ /dev/null +@@ -1,96 +0,0 @@ +- +- +-Credentials Cache API : cc_string_t Overview +- +- +- +- +-

cc_string_t Overview


Detailed Description

+-The cc_string_t represents a C string returned by the API. It has a pointer to the string data and a release() function. This type is used for both principal names and ccache names returned by the API. Principal names may contain UTF-8 encoded strings for internationalization purposes.

+-For API function documentation see cc_string_f. +-

+-

Data Structures

+- +-

Typedefs

+- +-

Typedef Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_string_f cc_string_f
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef struct cc_string_d cc_string_d
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
typedef cc_string_d* cc_string_t
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/group__ccapi__constants__reference.html b/doc/ccapi/html/group__ccapi__constants__reference.html +deleted file mode 100644 +index 87ec30b83..000000000 +--- a/doc/ccapi/html/group__ccapi__constants__reference.html ++++ /dev/null +@@ -1,407 +0,0 @@ +- +- +-Credentials Cache API : Constants +- +- +- +- +-

Constants

+-

+-

Enumerations

+- +-

Enumeration Type Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
anonymous enum
+-
+- +- +- +- +- +-
+-   +- +- +-

+-API version numbers

+-These constants are passed into cc_initialize() to indicate the version of the API the caller wants to use.

+-CCAPI v1 and v2 are deprecated and should not be used.

Enumerator:
+- +- +- +- +- +- +- +- +-
ccapi_version_2  +-
ccapi_version_3  +-
ccapi_version_4  +-
ccapi_version_5  +-
ccapi_version_6  +-
ccapi_version_7  +-
ccapi_version_max  +-
+-
+-
+-

+- +- +- +- +-
+- +- +- +- +-
anonymous enum
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Error codes

Enumerator:
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
ccNoError  +-Success.
ccIteratorEnd  +-Iterator is done iterating.
ccErrBadParam  +-Bad parameter (NULL or invalid pointer where valid pointer expected).
ccErrNoMem  +-Not enough memory to complete the operation.
ccErrInvalidContext  +-Context is invalid (e.g., it was released).
ccErrInvalidCCache  +-CCache is invalid (e.g., it was released or destroyed).
ccErrInvalidString  +-String is invalid (e.g., it was released).
ccErrInvalidCredentials  +-Credentials are invalid (e.g., they were released), or they have a bad version.
ccErrInvalidCCacheIterator  +-CCache iterator is invalid (e.g., it was released).
ccErrInvalidCredentialsIterator  +-Credentials iterator is invalid (e.g., it was released).
ccErrInvalidLock  +-Lock is invalid (e.g., it was released).
ccErrBadName  +-Bad credential cache name format.
ccErrBadCredentialsVersion  +-Credentials version is invalid.
ccErrBadAPIVersion  +-Unsupported API version.
ccErrContextLocked  +-Context is already locked.
ccErrContextUnlocked  +-Context is not locked by the caller.
ccErrCCacheLocked  +-CCache is already locked.
ccErrCCacheUnlocked  +-CCache is not locked by the caller.
ccErrBadLockType  +-Bad lock type.
ccErrNeverDefault  +-CCache was never default.
ccErrCredentialsNotFound  +-Matching credentials not found in the ccache.
ccErrCCacheNotFound  +-Matching ccache not found in the collection.
ccErrContextNotFound  +-Matching cache collection not found.
ccErrServerUnavailable  +-CCacheServer is unavailable.
ccErrServerInsecure  +-CCacheServer has detected that it is running as the wrong user.
ccErrServerCantBecomeUID  +-CCacheServer failed to start running as the user.
ccErrTimeOffsetNotSet  +-KDC time offset not set for this ccache.
ccErrBadInternalMessage  +-The client and CCacheServer can't communicate (e.g., a version mismatch).
ccErrNotImplemented  +-API function not supported by this implementation.
ccErrClientNotFound  +-CCacheServer has no record of the caller's process (e.g., the server crashed).
+-
+-
+-

+- +- +- +- +-
+- +- +- +- +-
enum cc_credential_versions
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Credentials versions

+-These constants are used in several places in the API to discern between Kerberos v4 and Kerberos v5. Not all values are valid inputs and outputs for all functions; function specifications below detail the allowed values.

+-Kerberos version constants will always be a bit-field, and can be tested as such; for example the following test will tell you if a ccacheVersion includes v5 credentials:

+-if ((ccacheVersion & cc_credentials_v5) != 0)

Enumerator:
+- +- +- +- +-
cc_credentials_v4  +-
cc_credentials_v5  +-
cc_credentials_v4_v5  +-
+-
+-
+-

+- +- +- +- +-
+- +- +- +- +-
enum cc_lock_types
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Lock types

+-These constants are used in the locking functions to describe the type of lock requested. Note that all CCAPI locks are advisory so only callers using the lock calls will be blocked by each other. This is because locking functions were introduced after the CCAPI came into common use and we did not want to break existing callers.

Enumerator:
+- +- +- +- +- +-
cc_lock_read  +-
cc_lock_write  +-
cc_lock_upgrade  +-
cc_lock_downgrade  +-
+-
+-
+-

+- +- +- +- +-
+- +- +- +- +-
enum cc_lock_modes
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Locking Modes

+-These constants are used in the advisory locking functions to describe whether or not the lock function should block waiting for a lock or return an error immediately. For example, attempting to acquire a lock with a non-blocking call will result in an error if the lock cannot be acquired; otherwise, the call will block until the lock can be acquired.

Enumerator:
+- +- +- +-
cc_lock_noblock  +-
cc_lock_block  +-
+-
+-
+-

+- +- +- +- +-
+- +- +- +- +-
anonymous enum
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Sizes of fields in cc_credentials_v4_t.

Enumerator:
+- +- +- +- +- +- +-
cc_v4_name_size  +-
cc_v4_instance_size  +-
cc_v4_realm_size  +-
cc_v4_ticket_size  +-
cc_v4_key_size  +-
+-
+-
+-

+- +- +- +- +-
+- +- +- +- +-
enum cc_string_to_key_type
+-
+- +- +- +- +- +-
+-   +- +- +-

+-String to key type (Kerberos v4 only)

Enumerator:
+- +- +- +- +- +- +-
cc_v4_stk_afs  +-
cc_v4_stk_des  +-
cc_v4_stk_columbia_special  +-
cc_v4_stk_krb5  +-
cc_v4_stk_unknown  +-
+-
+-
+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/group__ccapi__types__reference.html b/doc/ccapi/html/group__ccapi__types__reference.html +deleted file mode 100644 +index 9c646b8d9..000000000 +--- a/doc/ccapi/html/group__ccapi__types__reference.html ++++ /dev/null +@@ -1,138 +0,0 @@ +- +- +-Credentials Cache API : Basic Types +- +- +- +- +-

Basic Types

+-

+-

Typedefs

+- +-

Typedef Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
typedef uint32_t cc_uint32
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Unsigned 32-bit integer type

+-

+- +- +- +- +-
+- +- +- +- +-
typedef int32_t cc_int32
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Signed 32-bit integer type

+-

+- +- +- +- +-
+- +- +- +- +-
typedef int64_t cc_int64
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Unsigned 64-bit integer type

+-

+- +- +- +- +-
+- +- +- +- +-
typedef uint64_t cc_uint64
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Signed 64-bit integer type

+-

+- +- +- +- +-
+- +- +- +- +-
typedef cc_uint32 cc_time_t
+-
+- +- +- +- +- +-
+-   +- +- +-

+-The cc_time_t type is used to represent a time in seconds. The time must be stored as the number of seconds since midnight GMT on January 1, 1970.

+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/group__helper__macros.html b/doc/ccapi/html/group__helper__macros.html +deleted file mode 100644 +index cf1c681dc..000000000 +--- a/doc/ccapi/html/group__helper__macros.html ++++ /dev/null +@@ -1,1377 +0,0 @@ +- +- +-Credentials Cache API : CCAPI Function Helper Macros +- +- +- +- +-

CCAPI Function Helper Macros

+-

+-

Defines

+-
    +-
  • #define cc_context_release(context)   ((context) -> functions -> release (context)) +-
  • #define cc_context_get_change_time(context, change_time)   ((context) -> functions -> get_change_time (context, change_time)) +-
  • #define cc_context_get_default_ccache_name(context, name)   ((context) -> functions -> get_default_ccache_name (context, name)) +-
  • #define cc_context_open_ccache(context, name, ccache)   ((context) -> functions -> open_ccache (context, name, ccache)) +-
  • #define cc_context_open_default_ccache(context, ccache)   ((context) -> functions -> open_default_ccache (context, ccache)) +-
  • #define cc_context_create_ccache(context, name, version, principal, ccache)   ((context) -> functions -> create_ccache (context, name, version, principal, ccache)) +-
  • #define cc_context_create_default_ccache(context, version, principal, ccache)   ((context) -> functions -> create_default_ccache (context, version, principal, ccache)) +-
  • #define cc_context_create_new_ccache(context, version, principal, ccache)   ((context) -> functions -> create_new_ccache (context, version, principal, ccache)) +-
  • #define cc_context_new_ccache_iterator(context, iterator)   ((context) -> functions -> new_ccache_iterator (context, iterator)) +-
  • #define cc_context_lock(context, type, block)   ((context) -> functions -> lock (context, type, block)) +-
  • #define cc_context_unlock(context)   ((context) -> functions -> unlock (context)) +-
  • #define cc_context_compare(context, compare_to, equal)   ((context) -> functions -> compare (context, compare_to, equal)) +-
  • #define cc_context_wait_for_change(context)   ((context) -> functions -> wait_for_change (context)) +-
  • #define cc_ccache_release(ccache)   ((ccache) -> functions -> release (ccache)) +-
  • #define cc_ccache_destroy(ccache)   ((ccache) -> functions -> destroy (ccache)) +-
  • #define cc_ccache_set_default(ccache)   ((ccache) -> functions -> set_default (ccache)) +-
  • #define cc_ccache_get_credentials_version(ccache, version)   ((ccache) -> functions -> get_credentials_version (ccache, version)) +-
  • #define cc_ccache_get_name(ccache, name)   ((ccache) -> functions -> get_name (ccache, name)) +-
  • #define cc_ccache_get_principal(ccache, version, principal)   ((ccache) -> functions -> get_principal (ccache, version, principal)) +-
  • #define cc_ccache_set_principal(ccache, version, principal)   ((ccache) -> functions -> set_principal (ccache, version, principal)) +-
  • #define cc_ccache_store_credentials(ccache, credentials)   ((ccache) -> functions -> store_credentials (ccache, credentials)) +-
  • #define cc_ccache_remove_credentials(ccache, credentials)   ((ccache) -> functions -> remove_credentials (ccache, credentials)) +-
  • #define cc_ccache_new_credentials_iterator(ccache, iterator)   ((ccache) -> functions -> new_credentials_iterator (ccache, iterator)) +-
  • #define cc_ccache_lock(ccache, type, block)   ((ccache) -> functions -> lock (ccache, type, block)) +-
  • #define cc_ccache_unlock(ccache)   ((ccache) -> functions -> unlock (ccache)) +-
  • #define cc_ccache_get_last_default_time(ccache, last_default_time)   ((ccache) -> functions -> get_last_default_time (ccache, last_default_time)) +-
  • #define cc_ccache_get_change_time(ccache, change_time)   ((ccache) -> functions -> get_change_time (ccache, change_time)) +-
  • #define cc_ccache_move(source, destination)   ((source) -> functions -> move (source, destination)) +-
  • #define cc_ccache_compare(ccache, compare_to, equal)   ((ccache) -> functions -> compare (ccache, compare_to, equal)) +-
  • #define cc_ccache_get_kdc_time_offset(ccache, version, time_offset)   ((ccache) -> functions -> get_kdc_time_offset (ccache, version, time_offset)) +-
  • #define cc_ccache_set_kdc_time_offset(ccache, version, time_offset)   ((ccache) -> functions -> set_kdc_time_offset (ccache, version, time_offset)) +-
  • #define cc_ccache_clear_kdc_time_offset(ccache, version)   ((ccache) -> functions -> clear_kdc_time_offset (ccache, version)) +-
  • #define cc_ccache_wait_for_change(ccache)   ((ccache) -> functions -> wait_for_change (ccache)) +-
  • #define cc_string_release(string)   ((string) -> functions -> release (string)) +-
  • #define cc_credentials_release(credentials)   ((credentials) -> functions -> release (credentials)) +-
  • #define cc_credentials_compare(credentials, compare_to, equal)   ((credentials) -> functions -> compare (credentials, compare_to, equal)) +-
  • #define cc_ccache_iterator_release(iterator)   ((iterator) -> functions -> release (iterator)) +-
  • #define cc_ccache_iterator_next(iterator, ccache)   ((iterator) -> functions -> next (iterator, ccache)) +-
  • #define cc_ccache_iterator_clone(iterator, new_iterator)   ((iterator) -> functions -> clone (iterator, new_iterator)) +-
  • #define cc_credentials_iterator_release(iterator)   ((iterator) -> functions -> release (iterator)) +-
  • #define cc_credentials_iterator_next(iterator, credentials)   ((iterator) -> functions -> next (iterator, credentials)) +-
  • #define cc_credentials_iterator_clone(iterator, new_iterator)   ((iterator) -> functions -> clone (iterator, new_iterator)) +-
+-

Define Documentation

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +-
#define cc_context_release context   )    ((context) -> functions -> release (context))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_context_f release()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_context_get_change_time context,
change_time   )    ((context) -> functions -> get_change_time (context, change_time))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_context_f get_change_time()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_context_get_default_ccache_name context,
name   )    ((context) -> functions -> get_default_ccache_name (context, name))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_context_f get_default_ccache_name()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_context_open_ccache context,
name,
ccache   )    ((context) -> functions -> open_ccache (context, name, ccache))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_context_f open_ccache()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_context_open_default_ccache context,
ccache   )    ((context) -> functions -> open_default_ccache (context, ccache))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_context_f open_default_ccache()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_context_create_ccache context,
name,
version,
principal,
ccache   )    ((context) -> functions -> create_ccache (context, name, version, principal, ccache))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_context_f create_ccache()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_context_create_default_ccache context,
version,
principal,
ccache   )    ((context) -> functions -> create_default_ccache (context, version, principal, ccache))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_context_f create_default_ccache()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_context_create_new_ccache context,
version,
principal,
ccache   )    ((context) -> functions -> create_new_ccache (context, version, principal, ccache))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_context_f create_new_ccache()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_context_new_ccache_iterator context,
iterator   )    ((context) -> functions -> new_ccache_iterator (context, iterator))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_context_f new_ccache_iterator()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_context_lock context,
type,
block   )    ((context) -> functions -> lock (context, type, block))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_context_f lock()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +-
#define cc_context_unlock context   )    ((context) -> functions -> unlock (context))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_context_f unlock()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_context_compare context,
compare_to,
equal   )    ((context) -> functions -> compare (context, compare_to, equal))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_context_f compare()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +-
#define cc_context_wait_for_change context   )    ((context) -> functions -> wait_for_change (context))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_context_f wait_for_change()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +-
#define cc_ccache_release ccache   )    ((ccache) -> functions -> release (ccache))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f release()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +-
#define cc_ccache_destroy ccache   )    ((ccache) -> functions -> destroy (ccache))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f destroy()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +-
#define cc_ccache_set_default ccache   )    ((ccache) -> functions -> set_default (ccache))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f set_default()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_get_credentials_version ccache,
version   )    ((ccache) -> functions -> get_credentials_version (ccache, version))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f get_credentials_version()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_get_name ccache,
name   )    ((ccache) -> functions -> get_name (ccache, name))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f get_name()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_get_principal ccache,
version,
principal   )    ((ccache) -> functions -> get_principal (ccache, version, principal))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f get_principal()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_set_principal ccache,
version,
principal   )    ((ccache) -> functions -> set_principal (ccache, version, principal))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f set_principal()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_store_credentials ccache,
credentials   )    ((ccache) -> functions -> store_credentials (ccache, credentials))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f store_credentials()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_remove_credentials ccache,
credentials   )    ((ccache) -> functions -> remove_credentials (ccache, credentials))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f remove_credentials()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_new_credentials_iterator ccache,
iterator   )    ((ccache) -> functions -> new_credentials_iterator (ccache, iterator))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f new_credentials_iterator()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_lock ccache,
type,
block   )    ((ccache) -> functions -> lock (ccache, type, block))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f lock()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +-
#define cc_ccache_unlock ccache   )    ((ccache) -> functions -> unlock (ccache))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f unlock()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_get_last_default_time ccache,
last_default_time   )    ((ccache) -> functions -> get_last_default_time (ccache, last_default_time))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f get_last_default_time()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_get_change_time ccache,
change_time   )    ((ccache) -> functions -> get_change_time (ccache, change_time))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f get_change_time()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_move source,
destination   )    ((source) -> functions -> move (source, destination))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f move()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_compare ccache,
compare_to,
equal   )    ((ccache) -> functions -> compare (ccache, compare_to, equal))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f compare()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_get_kdc_time_offset ccache,
version,
time_offset   )    ((ccache) -> functions -> get_kdc_time_offset (ccache, version, time_offset))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f get_kdc_time_offset()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_set_kdc_time_offset ccache,
version,
time_offset   )    ((ccache) -> functions -> set_kdc_time_offset (ccache, version, time_offset))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f set_kdc_time_offset()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_clear_kdc_time_offset ccache,
version   )    ((ccache) -> functions -> clear_kdc_time_offset (ccache, version))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f clear_kdc_time_offset()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +-
#define cc_ccache_wait_for_change ccache   )    ((ccache) -> functions -> wait_for_change (ccache))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_f wait_for_change()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +-
#define cc_string_release string   )    ((string) -> functions -> release (string))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_string_f release()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +-
#define cc_credentials_release credentials   )    ((credentials) -> functions -> release (credentials))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_credentials_f release()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_credentials_compare credentials,
compare_to,
equal   )    ((credentials) -> functions -> compare (credentials, compare_to, equal))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_credentials_f compare()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +-
#define cc_ccache_iterator_release iterator   )    ((iterator) -> functions -> release (iterator))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_iterator_f release()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_iterator_next iterator,
ccache   )    ((iterator) -> functions -> next (iterator, ccache))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_iterator_f next()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_ccache_iterator_clone iterator,
new_iterator   )    ((iterator) -> functions -> clone (iterator, new_iterator))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_ccache_iterator_f clone()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +-
#define cc_credentials_iterator_release iterator   )    ((iterator) -> functions -> release (iterator))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_credentials_iterator_f release()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_credentials_iterator_next iterator,
credentials   )    ((iterator) -> functions -> next (iterator, credentials))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_credentials_iterator_f next()

+-

+- +- +- +- +-
+- +- +- +- +- +- +- +- +- +- +- +- +-
#define cc_credentials_iterator_clone iterator,
new_iterator   )    ((iterator) -> functions -> clone (iterator, new_iterator))
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Helper macro for cc_credentials_iterator_f clone()

+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/index.html b/doc/ccapi/html/index.html +deleted file mode 100644 +index bf920052f..000000000 +--- a/doc/ccapi/html/index.html ++++ /dev/null +@@ -1,85 +0,0 @@ +- +- +-Credentials Cache API : Credentials Cache API (CCAPI) Documentation +- +- +- +- +-

Credentials Cache API (CCAPI) Documentation

+-

+-

+-Table of Contents

+- +- +- +- +- +- +- +- +-

+-Introduction

+-This is the specification for an API which provides Credentials Cache services for both Kerberos v5 and v4. The idea behind this API is that multiple Kerberos implementations can share a single collection of credentials caches, mediated by this API specification. On the Mac OS and Microsoft Windows platforms this will allow single-login, even when more than one Kerberos shared library is in use on a particular system.

+-Abstractly, a credentials cache collection contains one or more credentials caches, or ccaches. A ccache is uniquely identified by its name, which is a string internal to the API and not intended to be presented to users. The user presentable identifier of a ccache is its principal.

+-Unlike the previous versions of the API, version 3 of the API stores both Kerberos v4 and v5 credentials in the same ccache.

+-At any given time, one ccache is the "default" ccache. The exact meaning of a default ccache is OS-specific; refer to implementation requirements for details.

+-Error Handling

+-All functions of the API return some of the error constants listed FIXME; the exact list of error constants returned by any API function is provided in the function descriptions below.

+-When returning an error constant other than ccNoError or ccIteratorEnd, API functions never modify any of the values passed in by reference.

+-Synchronization and Atomicity

+-Every function in the API is atomic. In order to make a series of calls atomic, callers should lock the ccache or cache collection they are working with to advise other callers not to modify that container. Note that advisory locks are per container so even if you have a read lock on the cache collection other callers can obtain write locks on ccaches in that cache collection.

+-Note that iterators do not iterate over ccaches and credentials atomically because locking ccaches and the cache collection over every iteration would degrade performance considerably under high load. However, iterators do guarantee a consistent view of items they are iterating over. Iterators will never return duplicate entries or skip entries when items are removed or added to the container they are iterating over.

+-An application can always lock a ccache or the cache collection to guarantee that other callers participating in the advisory locking system do not modify the ccache or cache collection.

+-Implementations should not use copy-on-write techniques to implement locks because those techniques imply that same parts of the ccache collection remain visible to some callers even though they are not present in the collection, which is a potential security risk. For example, a copy-on-write technique might make a copy of the entire collection when a read lock is acquired, so as to allow the owner of the lock to access the collection in an apparently unmodified state, while also allowing others to make modifications to the collection. However, this would also enable the owner of the lock to indefinitely (until the expiration time) use credentials that have actually been deleted from the collection.

+-Object Memory Management

+-The lifetime of an object returned by the API is until release() is called for it. Releasing one object has no effect on existence of any other object. For example, a ccache obtained within a context continue to exist when the context is released.

+-Every object returned by the API (cc_context_t, cc_ccache_t, cc_ccache_iterator_t, cc_credentials_t, cc_credentials_iterator_t, cc_string_t) is owned by the caller of the API, and it is the responsibility of the caller to call release() for every object to prevent memory leaks.

+-Opaque Types

+-All of the opaque high-level types in CCache API are implemented as structures of function pointers and private data. To perform some operation on a type, the caller of the API has to first obtain an instance of that type, and then call the appropriate function pointer from that instance. For example, to call get_change_time() on a cc_context_t, one would call cc_initialize() which creates a new cc_context_t and then call its get_change_time(), like this:

+-

 cc_context_t context;
+- cc_int32 err = cc_initialize (&context, ccapi_version_3, nil, nil);
+- if (err == ccNoError)
+- time = context->functions->get_change_time (context)
+-

+-All API functions also have convenience preprocessor macros, which make the API seem completely function-based. For example, cc_context_get_change_time (context, time) is equivalent to context->functions->get_change_time (context, time). The convenience macros follow the following naming convention:

+-The API function some_function()

 cc_type_t an_object;
+- result = an_object->functions->some_function (opaque_pointer, args)
+-

+-has an equivalent convenience macro of the form cc_type_some_function():

 cc_type_t an_object;
+- result = cc_type_some_function (an_object, args)
+-

+-The specifications below include the names for both the functions and the convenience macros, in that order. For clarity, it is recommended that clients using the API use the convenience macros, but that is merely a stylistic choice.

+-Implementing the API in this manner allows us to extend and change the interface in the future, while preserving compatibility with older clients.

+-For example, consider the case when the signature or the semantics of a cc_ccache_t function is changed. The API version number is incremented. The library implementation contains both a function with the old signature and semantics and a function with the new signature and semantics. When a context is created, the API version number used in that context is stored in the context, and therefore it can be used whenever a ccache is created in that context. When a ccache is created in a context with the old API version number, the function pointer structure for the ccache is filled with pointers to functions implementing the old semantics; when a ccache is created in a context with the new API version number, the function pointer structure for the ccache is filled with poitners to functions implementing the new semantics.

+-Similarly, if a function is added to the API, the version number in the context can be used to decide whether to include the implementation of the new function in the appropriate function pointer structure or not.


Generated on Tue Oct 2 17:16:05 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__ccache__d.html b/doc/ccapi/html/structcc__ccache__d.html +deleted file mode 100644 +index c19aa2b59..000000000 +--- a/doc/ccapi/html/structcc__ccache__d.html ++++ /dev/null +@@ -1,43 +0,0 @@ +- +- +-Credentials Cache API : cc_ccache_d Struct Reference +- +- +- +- +-

cc_ccache_d Struct Reference
+- +-[cc_ccache_t Overview] +-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
const cc_ccache_f* functions
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-


Generated on Tue Oct 2 17:16:05 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__ccache__f.html b/doc/ccapi/html/structcc__ccache__f.html +deleted file mode 100644 +index ddab94ff9..000000000 +--- a/doc/ccapi/html/structcc__ccache__f.html ++++ /dev/null +@@ -1,722 +0,0 @@ +- +- +-Credentials Cache API : cc_ccache_f Struct Reference +- +- +- +- +-

cc_ccache_f Struct Reference


Detailed Description

+-Function pointer table for cc_ccache_t. For more information see cc_ccache_t Overview. +-

+-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* release)(cc_ccache_t io_ccache)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_release(): Release memory associated with a cc_ccache_t object. +-

+-

Parameters:
+- +- +-
io_ccache the ccache object to release.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
Note:
Does not modify the ccache. If you wish to remove the ccache see cc_ccache_destroy().
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* destroy)(cc_ccache_t io_ccache)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_destroy(): Destroy a ccache. +-

+-

Parameters:
+- +- +-
io_ccache the ccache object to destroy and release.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-Destroy the ccache referred to by io_ccache and releases memory associated with the io_ccache object. After this call io_ccache becomes invalid. If io_ccache was the default ccache, the next ccache in the cache collection (if any) becomes the new default.
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* set_default)(cc_ccache_t io_ccache)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_set_default(): Make a ccache the default ccache. +-

+-

Parameters:
+- +- +-
io_ccache a ccache object to make the new default ccache.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* get_credentials_version)(cc_ccache_t in_ccache, cc_uint32 *out_credentials_version)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_get_credentials_version(): Get the credentials version of a ccache. +-

+-

Parameters:
+- +- +- +-
in_ccache a ccache object.
out_credentials_version on exit, the credentials version of in_ccache.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-cc_ccache_get_credentials_version() returns one value of the enumerated type cc_credentials_vers. The possible return values are cc_credentials_v4 (if ccache's v4 principal has been set), cc_credentials_v5 (if ccache's v5 principal has been set), or cc_credentials_v4_v5 (if both ccache's v4 and v5 principals have been set). A ccache's principal is set with one of cc_context_create_ccache(), cc_context_create_new_ccache(), cc_context_create_default_ccache(), or cc_ccache_set_principal().
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* get_name)(cc_ccache_t in_ccache, cc_string_t *out_name)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_get_name(): Get the name of a ccache. +-

+-

Parameters:
+- +- +- +-
in_ccache a ccache object.
out_name on exit, a cc_string_t representing the name of in_ccache. out_name must be released with cc_string_release().
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* get_principal)(cc_ccache_t in_ccache, cc_uint32 in_credentials_version, cc_string_t *out_principal)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_get_principal(): Get the principal of a ccache. +-

+-

Parameters:
+- +- +- +- +-
in_ccache a ccache object.
in_credentials_version the credentials version to get the principal for.
out_principal on exit, a cc_string_t representing the principal of in_ccache. out_principal must be released with cc_string_release().
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-Return the principal for the ccache that was set via cc_context_create_ccache(), cc_context_create_default_ccache(), cc_context_create_new_ccache(), or cc_ccache_set_principal(). Principals for v4 and v5 are separate, but should be kept synchronized for each ccache; they can be retrieved by passing cc_credentials_v4 or cc_credentials_v5 in cred_vers. Passing cc_credentials_v4_v5 will result in the error ccErrBadCredentialsVersion.
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* set_principal)(cc_ccache_t io_ccache, cc_uint32 in_credentials_version, const char *in_principal)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_set_principal(): Set the principal of a ccache. +-

+-

Parameters:
+- +- +- +- +-
in_ccache a ccache object.
in_credentials_version the credentials version to set the principal for.
in_principal a C string representing the new principal of in_ccache.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-Set the a principal for ccache. The v4 and v5 principals can be set independently, but they should always be kept equal, up to differences in string representation between v4 and v5. Passing cc_credentials_v4_v5 in cred_vers will result in the error ccErrBadCredentialsVersion.
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* store_credentials)(cc_ccache_t io_ccache, const cc_credentials_union *in_credentials_union)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_store_credentials(): Store credentials in a ccache. +-

+-

Parameters:
+- +- +- +-
io_ccache a ccache object.
in_credentials_union the credentials to store in io_ccache.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-Store a copy of credentials in the ccache.

+-See the description of the credentials types for the meaning of cc_credentials_union fields.

+-Before credentials of a specific credential type can be stored in a ccache, the corresponding principal version has to be set. For example, before you can store Kerberos v4 credentials in a ccache, the Kerberos v4 principal has to be set either by cc_context_create_ccache(), cc_context_create_default_ccache(), cc_context_create_new_ccache(), or cc_ccache_set_principal(); likewise for Kerberos v5. Otherwise, ccErrBadCredentialsVersion is returned.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* remove_credentials)(cc_ccache_t io_ccache, cc_credentials_t in_credentials)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_remove_credentials(): Remove credentials from a ccache. +-

+-

Parameters:
+- +- +- +-
io_ccache a ccache object.
in_credentials the credentials to remove from io_ccache.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-Removes credentials from a ccache. Note that credentials must be previously acquired from the CCache API; only exactly matching credentials will be removed. (This places the burden of determining exactly which credentials to remove on the caller, but ensures there is no ambigity about which credentials will be removed.) cc_credentials_t objects can be obtained by iterating over the ccache's credentials with cc_ccache_new_credentials_iterator().

+-If found, the credentials are removed from the ccache. The credentials parameter is not modified and should be freed by the caller. It is legitimate to call this function while an iterator is traversing the ccache, and the deletion of a credential already returned by cc_credentials_iterator_next() will not disturb sequence of credentials returned by cc_credentials_iterator_next().

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* new_credentials_iterator)(cc_ccache_t in_ccache, cc_credentials_iterator_t *out_credentials_iterator)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_new_credentials_iterator(): Iterate over credentials in a ccache. +-

+-

Parameters:
+- +- +- +-
in_ccache a ccache object.
out_credentials_iterator a credentials iterator for io_ccache.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-Allocates memory for iterator and initializes it. Successive calls to cc_credentials_iterator_next() will return credentials from the ccache.

+-If changes are made to the ccache while an iterator is being used on it, the iterator must return at least the intersection, and at most the union, of the set of credentials that were in the ccache when the iteration began and the set of credentials that are in the ccache when it ends.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* move)(cc_ccache_t io_source_ccache, cc_ccache_t io_destination_ccache)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_move(): Move the contents of one ccache into another, destroying the source. +-

+-

Parameters:
+- +- +- +-
io_source_ccache a ccache object to move.
io_destination_ccache a ccache object replace with the contents of io_source_ccache.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-cc_ccache_move() atomically copies the credentials, credential versions and principals from one ccache to another. On successful completion io_source_ccache will be released and the ccache it points to will be destroyed. Any credentials previously in io_destination_ccache will be replaced with credentials from io_source_ccache. The only part of io_destination_ccache which remains constant is the name. Any other callers referring to io_destination_ccache will suddenly see new data in it.

+-Typically cc_ccache_move() is used when the caller wishes to safely overwrite the contents of a ccache with new data which requires several steps to generate. cc_ccache_move() allows the caller to create a temporary ccache (which can be destroyed if any intermediate step fails) and the atomically copy the temporary cache into the destination.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* lock)(cc_ccache_t io_ccache, cc_uint32 in_lock_type, cc_uint32 in_block)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_lock(): Lock a ccache. +-

+-

Parameters:
+- +- +- +- +-
io_ccache the ccache object for the ccache you wish to lock.
in_lock_type the type of lock to obtain.
in_block whether or not the function should block if the lock cannot be obtained immediately.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-Attempts to acquire an advisory lock for a ccache. Allowed values for lock_type are:

+-

    +-
  • cc_lock_read: a read lock.
  • +-
  • cc_lock_write: a write lock
  • +-
  • cc_lock_upgrade: upgrade an already-obtained read lock to a write lock
  • +-
  • cc_lock_downgrade: downgrade an already-obtained write lock to a read lock
  • +-
+-If block is cc_lock_block, lock() will not return until the lock is acquired. If block is cc_lock_noblock, lock() will return immediately, either acquiring the lock and returning ccNoError, or failing to acquire the lock and returning an error explaining why.

+-To avoid having to deal with differences between thread semantics on different platforms, locks are granted per ccache, rather than per thread or per process. That means that different threads of execution have to acquire separate contexts in order to be able to synchronize with each other.

+-The lock should be unlocked by using cc_ccache_unlock().

+-

Note:
All locks are advisory. For example, callers which do not call cc_ccache_lock() and cc_ccache_unlock() will not be prevented from writing to the ccache when you have a read lock. This is because the CCAPI locking was added after the first release and thus adding mandatory locks would have changed the user experience and performance of existing applications.
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* unlock)(cc_ccache_t io_ccache)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_unlock(): Unlock a ccache. +-

+-

Parameters:
+- +- +-
io_ccache a ccache object.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* get_last_default_time)(cc_ccache_t in_ccache, cc_time_t *out_last_default_time)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_get_change_time(): Get the last time a ccache was the default ccache. +-

+-

Parameters:
+- +- +- +-
in_ccache a cache object.
out_last_default_time on exit, the last time the ccache was default.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-This function returns the last time when the ccache was made the default ccache. This allows clients to sort the ccaches by how recently they were default, which is useful for user listing of ccaches. If the ccache was never default, ccErrNeverDefault is returned.
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* get_change_time)(cc_ccache_t in_ccache, cc_time_t *out_change_time)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_get_change_time(): Get the last time a ccache changed. +-

+-

Parameters:
+- +- +- +-
in_ccache a cache object.
out_change_time on exit, the last time the ccache changed.
+-
+-
Returns:
On success, ccNoError. If the ccache was never the default ccache, ccErrNeverDefault. Otherwise, an error code representing the failure.
+-This function returns the time of the most recent change made to a ccache. By maintaining a local copy the caller can deduce whether or not the ccache has been modified since the previous call to cc_ccache_get_change_time().

+-The time returned by cc_ccache_get_change_time() increases whenever:

+-

    +-
  • a credential is stored
  • +-
  • a credential is removed
  • +-
  • a ccache principal is changed
  • +-
  • the ccache becomes the default ccache
  • +-
  • the ccache is no longer the default ccache
  • +-
+-
Note:
In order to be able to compare two values returned by cc_ccache_get_change_time(), the caller must use the same ccache object to acquire them. Callers should maintain a single ccache object in memory for cc_ccache_get_change_time() calls rather than creating a new ccache object for every call.
+-
See also:
wait_for_change
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* compare)(cc_ccache_t in_ccache, cc_ccache_t in_compare_to_ccache, cc_uint32 *out_equal)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_compare(): Compare two ccache objects. +-

+-

Parameters:
+- +- +- +- +-
in_ccache a ccache object.
in_compare_to_ccache a ccache object to compare with in_ccache.
out_equal on exit, whether or not the two ccaches refer to the same ccache.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* get_kdc_time_offset)(cc_ccache_t in_ccache, cc_uint32 in_credentials_version, cc_time_t *out_time_offset)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_get_kdc_time_offset(): Get the KDC time offset for credentials in a ccache. +-

+-

Parameters:
+- +- +- +- +-
in_ccache a ccache object.
in_credentials_version the credentials version to get the time offset for.
out_time_offset on exit, the KDC time offset for in_ccache for credentials version in_credentials_version.
+-
+-
Returns:
On success, ccNoError if a time offset was obtained or ccErrTimeOffsetNotSet if a time offset has not been set. On failure, an error code representing the failure.
+-
See also:
set_kdc_time_offset, clear_kdc_time_offset
+-Sometimes the KDC and client's clocks get out of sync. cc_ccache_get_kdc_time_offset() returns the difference between the KDC and client's clocks at the time credentials were acquired. This offset allows callers to figure out how much time is left on a given credential even though the end_time is based on the KDC's clock not the client's clock.
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* set_kdc_time_offset)(cc_ccache_t io_ccache, cc_uint32 in_credentials_version, cc_time_t in_time_offset)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_set_kdc_time_offset(): Set the KDC time offset for credentials in a ccache. +-

+-

Parameters:
+- +- +- +- +-
in_ccache a ccache object.
in_credentials_version the credentials version to get the time offset for.
in_time_offset the new KDC time offset for in_ccache for credentials version in_credentials_version.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
See also:
get_kdc_time_offset, clear_kdc_time_offset
+-Sometimes the KDC and client's clocks get out of sync. cc_ccache_set_kdc_time_offset() sets the difference between the KDC and client's clocks at the time credentials were acquired. This offset allows callers to figure out how much time is left on a given credential even though the end_time is based on the KDC's clock not the client's clock.
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* clear_kdc_time_offset)(cc_ccache_t io_ccache, cc_uint32 in_credentials_version)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_clear_kdc_time_offset(): Clear the KDC time offset for credentials in a ccache. +-

+-

Parameters:
+- +- +- +-
in_ccache a ccache object.
in_credentials_version the credentials version to get the time offset for.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
See also:
get_kdc_time_offset, set_kdc_time_offset
+-Sometimes the KDC and client's clocks get out of sync. cc_ccache_clear_kdc_time_offset() clears the difference between the KDC and client's clocks at the time credentials were acquired. This offset allows callers to figure out how much time is left on a given credential even though the end_time is based on the KDC's clock not the client's clock.
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* wait_for_change)(cc_ccache_t in_ccache)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_wait_for_change(): Wait for the next change to a ccache. +-

+-

Parameters:
+- +- +-
in_ccache a ccache object.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-This function blocks until the next change is made to the ccache referenced by in_ccache. By repeatedly calling cc_ccache_wait_for_change() from a worker thread the caller can effectively receive callbacks whenever the ccache changes. This is considerably more efficient than polling with cc_ccache_get_change_time().

+-cc_ccache_wait_for_change() will return whenever:

+-

    +-
  • a credential is stored
  • +-
  • a credential is removed
  • +-
  • the ccache principal is changed
  • +-
  • the ccache becomes the default ccache
  • +-
  • the ccache is no longer the default ccache
  • +-
+-
Note:
In order to make sure that the caller doesn't miss any changes, cc_ccache_wait_for_change() always returns immediately after the first time it is called on a new ccache object. Callers must use the same ccache object for successive calls to cc_ccache_wait_for_change() rather than creating a new ccache object for every call.
+-
See also:
get_change_time
+-
+-


Generated on Tue Oct 2 17:16:05 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__ccache__iterator__d.html b/doc/ccapi/html/structcc__ccache__iterator__d.html +deleted file mode 100644 +index 5e85ee2da..000000000 +--- a/doc/ccapi/html/structcc__ccache__iterator__d.html ++++ /dev/null +@@ -1,43 +0,0 @@ +- +- +-Credentials Cache API : cc_ccache_iterator_d Struct Reference +- +- +- +- +-

cc_ccache_iterator_d Struct Reference
+- +-[cc_ccache_iterator_t Overview] +-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
const cc_ccache_iterator_f* functions
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-


Generated on Tue Oct 2 17:16:05 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__ccache__iterator__f.html b/doc/ccapi/html/structcc__ccache__iterator__f.html +deleted file mode 100644 +index 333aab8f4..000000000 +--- a/doc/ccapi/html/structcc__ccache__iterator__f.html ++++ /dev/null +@@ -1,117 +0,0 @@ +- +- +-Credentials Cache API : cc_ccache_iterator_f Struct Reference +- +- +- +- +-

cc_ccache_iterator_f Struct Reference


Detailed Description

+-Function pointer table for cc_ccache_iterator_t. For more information see cc_ccache_iterator_t Overview. +-

+-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* release)(cc_ccache_iterator_t io_ccache_iterator)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_iterator_release(): Release memory associated with a cc_ccache_iterator_t object. +-

+-

Parameters:
+- +- +-
io_ccache_iterator the ccache iterator object to release.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* next)(cc_ccache_iterator_t in_ccache_iterator, cc_ccache_t *out_ccache)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_iterator_next(): Get the next ccache in the cache collection. +-

+-

Parameters:
+- +- +- +-
in_ccache_iterator a ccache iterator object.
out_ccache on exit, the next ccache in the cache collection.
+-
+-
Returns:
On success, ccNoError if the next ccache in the cache collection was obtained or ccIteratorEnd if there are no more ccaches. On failure, an error code representing the failure.
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* clone)(cc_ccache_iterator_t in_ccache_iterator, cc_ccache_iterator_t *out_ccache_iterator)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_ccache_iterator_clone(): Make a copy of a ccache iterator. +-

+-

Parameters:
+- +- +- +-
in_ccache_iterator a ccache iterator object.
out_ccache_iterator on exit, a copy of in_ccache_iterator.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
+-


Generated on Tue Oct 2 17:16:05 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__context__d.html b/doc/ccapi/html/structcc__context__d.html +deleted file mode 100644 +index d3904a2a1..000000000 +--- a/doc/ccapi/html/structcc__context__d.html ++++ /dev/null +@@ -1,43 +0,0 @@ +- +- +-Credentials Cache API : cc_context_d Struct Reference +- +- +- +- +-

cc_context_d Struct Reference
+- +-[cc_context_t Overview] +-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
const cc_context_f* functions
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-


Generated on Tue Oct 2 17:16:05 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__context__f.html b/doc/ccapi/html/structcc__context__f.html +deleted file mode 100644 +index fe310518a..000000000 +--- a/doc/ccapi/html/structcc__context__f.html ++++ /dev/null +@@ -1,513 +0,0 @@ +- +- +-Credentials Cache API : cc_context_f Struct Reference +- +- +- +- +-

cc_context_f Struct Reference


Detailed Description

+-Function pointer table for cc_context_t. For more information see cc_context_t Overview. +-

+-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* release)(cc_context_t io_context)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_context_release(): Release memory associated with a cc_context_t. +-

+-

Parameters:
+- +- +-
io_context the context object to free.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* get_change_time)(cc_context_t in_context, cc_time_t *out_time)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_context_get_change_time(): Get the last time the cache collection changed. +-

+-

Parameters:
+- +- +- +-
in_context the context object for the cache collection to examine.
out_time on exit, the time of the most recent change for the entire ccache collection.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-This function returns the time of the most recent change for the entire ccache collection. By maintaining a local copy the caller can deduce whether or not the ccache collection has been modified since the previous call to cc_context_get_change_time().

+-The time returned by cc_context_get_changed_time() increases whenever:

+-

    +-
  • a ccache is created
  • +-
  • a ccache is destroyed
  • +-
  • a credential is stored
  • +-
  • a credential is removed
  • +-
  • a ccache principal is changed
  • +-
  • the default ccache is changed
  • +-
+-
Note:
In order to be able to compare two values returned by cc_context_get_change_time(), the caller must use the same context to acquire them. Callers should maintain a single context in memory for cc_context_get_change_time() calls rather than creating a new context for every call.
+-
See also:
wait_for_change
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* get_default_ccache_name)(cc_context_t in_context, cc_string_t *out_name)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_context_get_default_ccache_name(): Get the name of the default ccache. +-

+-

Parameters:
+- +- +- +-
in_context the context object for the cache collection.
out_name on exit, the name of the default ccache.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-This function returns the name of the default ccache. When the default ccache exists, its name is returned. If there are no ccaches in the collection, and thus there is no default ccache, the name that the default ccache should have is returned. The ccache with that name will be used as the default ccache by all processes which initialized Kerberos libraries before the ccache was created.

+-If there is no default ccache, and the client is creating a new ccache, it should be created with the default name. If there already is a default ccache, and the client wants to create a new ccache (as opposed to reusing an existing ccache), it should be created with any unique name; create_new_ccache() can be used to accomplish that more easily.

+-If the first ccache is created with a name other than the default name, then the processes already running will not notice the credentials stored in the new ccache, which is normally undesirable.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* open_ccache)(cc_context_t in_context, const char *in_name, cc_ccache_t *out_ccache)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_context_open_ccache(): Open a ccache. +-

+-

Parameters:
+- +- +- +- +-
in_context the context object for the cache collection.
in_name the name of the ccache to open.
out_ccache on exit, a ccache object for the ccache
+-
+-
Returns:
On success, ccNoError. If no ccache named in_name exists, ccErrCCacheNotFound. On failure, an error code representing the failure.
+-Opens an already existing ccache identified by its name. It returns a reference to the ccache in out_ccache.

+-The list of all ccache names, principals, and credentials versions may be retrieved by calling cc_context_new_cache_iterator(), cc_ccache_get_name(), cc_ccache_get_principal(), and cc_ccache_get_cred_version().

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* open_default_ccache)(cc_context_t in_context, cc_ccache_t *out_ccache)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_context_open_default_ccache(): Open the default ccache. +-

+-

Parameters:
+- +- +- +-
in_context the context object for the cache collection.
out_ccache on exit, a ccache object for the default ccache
+-
+-
Returns:
On success, ccNoError. If no default ccache exists, ccErrCCacheNotFound. On failure, an error code representing the failure.
+-Opens the default ccache. It returns a reference to the ccache in *ccache.

+-This function performs the same function as calling cc_context_get_default_ccache_name followed by cc_context_open_ccache, but it performs it atomically.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* create_ccache)(cc_context_t in_context, const char *in_name, cc_uint32 in_cred_vers, const char *in_principal, cc_ccache_t *out_ccache)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_context_create_ccache(): Create a new ccache. +-

+-

Parameters:
+- +- +- +- +- +- +-
in_context the context object for the cache collection.
in_name the name of the new ccache to create
in_cred_vers the version of the credentials the new ccache will hold
in_principal the client principal of the credentials the new ccache will hold
out_ccache on exit, a ccache object for the newly created ccache
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-Create a new credentials cache. The ccache is uniquely identified by its name. The principal given is also associated with the ccache and the credentials version specified. A NULL name is not allowed (and ccErrBadName is returned if one is passed in). Only cc_credentials_v4 and cc_credentials_v5 are valid input values for cred_vers. If you want to create a new ccache that will hold both versions of credentials, call cc_context_create_ccache() with one version, and then cc_ccache_set_principal() with the other version.

+-If you want to create a new ccache (with a unique name), you should use cc_context_create_new_ccache() instead. If you want to create or reinitialize the default cache, you should use cc_context_create_default_ccache().

+-If name is non-NULL and there is already a ccache named name:

+-

    +-
  • the credentials in the ccache whose version is cred_vers are removed
  • +-
  • the principal (of the existing ccache) associated with cred_vers is set to principal
  • +-
  • a handle for the existing ccache is returned and all existing handles for the ccache remain valid
  • +-
+-If no ccache named name already exists:

+-

    +-
  • a new empty ccache is created
  • +-
  • the principal of the new ccache associated with cred_vers is set to principal
  • +-
  • a handle for the new ccache is returned
  • +-
+-For a new ccache, the name should be any unique string. The name is not intended to be presented to users.

+-If the created ccache is the first ccache in the collection, it is made the default ccache. Note that normally it is undesirable to create the first ccache with a name different from the default ccache name (as returned by cc_context_get_default_ccache_name()); see the description of cc_context_get_default_ccache_name() for details.

+-The principal should be a C string containing an unparsed Kerberos principal in the format of the appropriate Kerberos version, i.e.

foo.bar/@BAZ 
+-      * 
for Kerberos v4 and
foo/bar/@BAZ 
for Kerberos v5.
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* create_default_ccache)(cc_context_t in_context, cc_uint32 in_cred_vers, const char *in_principal, cc_ccache_t *out_ccache)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_context_create_default_ccache(): Create a new default ccache. +-

+-

Parameters:
+- +- +- +- +- +-
in_context the context object for the cache collection.
in_cred_vers the version of the credentials the new default ccache will hold
in_principal the client principal of the credentials the new default ccache will hold
out_ccache on exit, a ccache object for the newly created default ccache
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-Create the default credentials cache. The behavior of this function is similar to that of cc_create_ccache(). If there is a default ccache (which is always the case except when there are no ccaches at all in the collection), it is initialized with the specified credentials version and principal, as per cc_create_ccache(); otherwise, a new ccache is created, and its name is the name returned by cc_context_get_default_ccache_name().
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* create_new_ccache)(cc_context_t in_context, cc_uint32 in_cred_vers, const char *in_principal, cc_ccache_t *out_ccache)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_context_create_new_ccache(): Create a new uniquely named ccache. +-

+-

Parameters:
+- +- +- +- +- +-
in_context the context object for the cache collection.
in_cred_vers the version of the credentials the new ccache will hold
in_principal the client principal of the credentials the new ccache will hold
out_ccache on exit, a ccache object for the newly created ccache
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-Create a new unique credentials cache. The behavior of this function is similar to that of cc_create_ccache(). If there are no ccaches, and therefore no default ccache, the new ccache is created with the default ccache name as would be returned by get_default_ccache_name(). If there are some ccaches, and therefore there is a default ccache, the new ccache is created with a new unique name. Clearly, this function never reinitializes a ccache, since it always uses a unique name.
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* new_ccache_iterator)(cc_context_t in_context, cc_ccache_iterator_t *out_iterator)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_context_new_ccache_iterator(): Get an iterator for the cache collection. +-

+-

Parameters:
+- +- +- +-
in_context the context object for the cache collection.
out_iterator on exit, a ccache iterator object for the ccache collection.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-Used to allocate memory and initialize iterator. Successive calls to iterator's next() function will return ccaches in the collection.

+-If changes are made to the collection while an iterator is being used on it, the iterator must return at least the intersection, and at most the union, of the set of ccaches that were present when the iteration began and the set of ccaches that are present when it ends.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* lock)(cc_context_t in_context, cc_uint32 in_lock_type, cc_uint32 in_block)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_context_lock(): Lock the cache collection. +-

+-

Parameters:
+- +- +- +- +-
in_context the context object for the cache collection.
in_lock_type the type of lock to obtain.
in_block whether or not the function should block if the lock cannot be obtained immediately.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-Attempts to acquire an advisory lock for the ccache collection. Allowed values for lock_type are:

+-

    +-
  • cc_lock_read: a read lock.
  • +-
  • cc_lock_write: a write lock
  • +-
  • cc_lock_upgrade: upgrade an already-obtained read lock to a write lock
  • +-
  • cc_lock_downgrade: downgrade an already-obtained write lock to a read lock
  • +-
+-If block is cc_lock_block, lock() will not return until the lock is acquired. If block is cc_lock_noblock, lock() will return immediately, either acquiring the lock and returning ccNoError, or failing to acquire the lock and returning an error explaining why.

+-Locks apply only to the list of ccaches, not the contents of those ccaches. To prevent callers participating in the advisory locking from changing the credentials in a cache you must also lock that ccache with cc_ccache_lock(). This is so that you can get the list of ccaches without preventing applications from simultaneously obtaining service tickets.

+-To avoid having to deal with differences between thread semantics on different platforms, locks are granted per context, rather than per thread or per process. That means that different threads of execution have to acquire separate contexts in order to be able to synchronize with each other.

+-The lock should be unlocked by using cc_context_unlock().

+-

Note:
All locks are advisory. For example, callers which do not call cc_context_lock() and cc_context_unlock() will not be prevented from writing to the cache collection when you have a read lock. This is because the CCAPI locking was added after the first release and thus adding mandatory locks would have changed the user experience and performance of existing applications.
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* unlock)(cc_context_t in_cc_context)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_context_unlock(): Unlock the cache collection. +-

+-

Parameters:
+- +- +-
in_context the context object for the cache collection.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* compare)(cc_context_t in_cc_context, cc_context_t in_compare_to_context, cc_uint32 *out_equal)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_context_compare(): Compare two context objects. +-

+-

Parameters:
+- +- +- +- +-
in_context a context object.
in_compare_to_context a context object to compare with in_context.
out_equal on exit, whether or not the two contexts refer to the same cache collection.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* wait_for_change)(cc_context_t in_cc_context)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_context_wait_for_change(): Wait for the next change in the cache collection. +-

+-

Parameters:
+- +- +-
in_context a context object.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-This function blocks until the next change is made to the cache collection ccache collection. By repeatedly calling cc_context_wait_for_change() from a worker thread the caller can effectively receive callbacks whenever the cache collection changes. This is considerably more efficient than polling with cc_context_get_change_time().

+-cc_context_wait_for_change() will return whenever:

+-

    +-
  • a ccache is created
  • +-
  • a ccache is destroyed
  • +-
  • a credential is stored
  • +-
  • a credential is removed
  • +-
  • a ccache principal is changed
  • +-
  • the default ccache is changed
  • +-
+-
Note:
In order to make sure that the caller doesn't miss any changes, cc_context_wait_for_change() always returns immediately after the first time it is called on a new context object. Callers must use the same context object for successive calls to cc_context_wait_for_change() rather than creating a new context for every call.
+-
See also:
get_change_time
+-
+-


Generated on Tue Oct 2 17:16:05 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__credentials__d.html b/doc/ccapi/html/structcc__credentials__d.html +deleted file mode 100644 +index 8a13251e5..000000000 +--- a/doc/ccapi/html/structcc__credentials__d.html ++++ /dev/null +@@ -1,67 +0,0 @@ +- +- +-Credentials Cache API : cc_credentials_d Struct Reference +- +- +- +- +-

cc_credentials_d Struct Reference
+- +-[cc_credentials_t Overview] +-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
const cc_credentials_union* data
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
const cc_credentials_f* functions
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__credentials__f.html b/doc/ccapi/html/structcc__credentials__f.html +deleted file mode 100644 +index 91f4b3adb..000000000 +--- a/doc/ccapi/html/structcc__credentials__f.html ++++ /dev/null +@@ -1,85 +0,0 @@ +- +- +-Credentials Cache API : cc_credentials_f Struct Reference +- +- +- +- +-

cc_credentials_f Struct Reference


Detailed Description

+-Function pointer table for cc_credentials_t. For more information see cc_credentials_t Overview. +-

+-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* release)(cc_credentials_t io_credentials)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_credentials_release(): Release memory associated with a cc_credentials_t object. +-

+-

Parameters:
+- +- +-
io_credentials the credentials object to release.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* compare)(cc_credentials_t in_credentials, cc_credentials_t in_compare_to_credentials, cc_uint32 *out_equal)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_credentials_compare(): Compare two credentials objects. +-

+-

Parameters:
+- +- +- +- +-
in_credentials a credentials object.
in_compare_to_credentials a credentials object to compare with in_credentials.
out_equal on exit, whether or not the two credentials objects refer to the same credentials in the cache collection.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__credentials__iterator__d.html b/doc/ccapi/html/structcc__credentials__iterator__d.html +deleted file mode 100644 +index 5682db0ed..000000000 +--- a/doc/ccapi/html/structcc__credentials__iterator__d.html ++++ /dev/null +@@ -1,43 +0,0 @@ +- +- +-Credentials Cache API : cc_credentials_iterator_d Struct Reference +- +- +- +- +-

cc_credentials_iterator_d Struct Reference
+- +-[cc_credentials_iterator_t] +-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
const cc_credentials_iterator_f* functions
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__credentials__iterator__f.html b/doc/ccapi/html/structcc__credentials__iterator__f.html +deleted file mode 100644 +index 66aec178a..000000000 +--- a/doc/ccapi/html/structcc__credentials__iterator__f.html ++++ /dev/null +@@ -1,85 +0,0 @@ +- +- +-Credentials Cache API : cc_credentials_iterator_f Struct Reference +- +- +- +- +-

cc_credentials_iterator_f Struct Reference


Detailed Description

+-Function pointer table for cc_credentials_iterator_t. For more information see cc_credentials_iterator_t. +-

+-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* release)(cc_credentials_iterator_t io_credentials_iterator)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_credentials_iterator_release(): Release memory associated with a cc_credentials_iterator_t object. +-

+-

Parameters:
+- +- +-
io_credentials_iterator the credentials iterator object to release.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* next)(cc_credentials_iterator_t in_credentials_iterator, cc_credentials_t *out_credentials)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_credentials_iterator_next(): Get the next credentials in the ccache. +-

+-

Parameters:
+- +- +- +-
in_credentials_iterator a credentials iterator object.
out_credentials on exit, the next credentials in the ccache.
+-
+-
Returns:
On success, ccNoError if the next credential in the ccache was obtained or ccIteratorEnd if there are no more credentials. On failure, an error code representing the failure.
+-
+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__credentials__union.html b/doc/ccapi/html/structcc__credentials__union.html +deleted file mode 100644 +index 6082346cc..000000000 +--- a/doc/ccapi/html/structcc__credentials__union.html ++++ /dev/null +@@ -1,118 +0,0 @@ +- +- +-Credentials Cache API : cc_credentials_union Struct Reference +- +- +- +- +-

cc_credentials_union Struct Reference
+- +-[cc_credentials_t Overview] +-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
cc_uint32 version
+-
+- +- +- +- +- +-
+-   +- +- +-

+-The credentials version of this credentials object.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_credentials_v4_t* credentials_v4
+-
+- +- +- +- +- +-
+-   +- +- +-

+-If version is cc_credentials_v4, a pointer to a cc_credentials_v4_t.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_credentials_v5_t* credentials_v5
+-
+- +- +- +- +- +-
+-   +- +- +-

+-If version is cc_credentials_v5, a pointer to a cc_credentials_v5_t.

+-

+- +- +- +- +-
+- +- +- +- +-
union { ... } credentials
+-
+- +- +- +- +- +-
+-   +- +- +-

+-The credentials.

+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__credentials__v4__t.html b/doc/ccapi/html/structcc__credentials__v4__t.html +deleted file mode 100644 +index 086e7fea7..000000000 +--- a/doc/ccapi/html/structcc__credentials__v4__t.html ++++ /dev/null +@@ -1,358 +0,0 @@ +- +- +-Credentials Cache API : cc_credentials_v4_t Struct Reference +- +- +- +- +-

cc_credentials_v4_t Struct Reference
+- +-[cc_credentials_t Overview] +-


Detailed Description

+-If a cc_credentials_t variable is used to store Kerberos v4 credentials, then credentials.credentials_v4 points to a v4 credentials structure. This structure is similar to a krb4 API CREDENTIALS structure. +-

+-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
cc_uint32 version
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
char principal[cc_v4_name_size]
+-
+- +- +- +- +- +-
+-   +- +- +-

+-A properly quoted string representation of the first component of the client principal

+-

+- +- +- +- +-
+- +- +- +- +-
char principal_instance[cc_v4_instance_size]
+-
+- +- +- +- +- +-
+-   +- +- +-

+-A properly quoted string representation of the second component of the client principal

+-

+- +- +- +- +-
+- +- +- +- +-
char service[cc_v4_name_size]
+-
+- +- +- +- +- +-
+-   +- +- +-

+-A properly quoted string representation of the first component of the service principal

+-

+- +- +- +- +-
+- +- +- +- +-
char service_instance[cc_v4_instance_size]
+-
+- +- +- +- +- +-
+-   +- +- +-

+-A properly quoted string representation of the second component of the service principal

+-

+- +- +- +- +-
+- +- +- +- +-
char realm[cc_v4_realm_size]
+-
+- +- +- +- +- +-
+-   +- +- +-

+-A properly quoted string representation of the realm

+-

+- +- +- +- +-
+- +- +- +- +-
unsigned char session_key[cc_v4_key_size]
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Ticket session key

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32 kvno
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Key version number

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32 string_to_key_type
+-
+- +- +- +- +- +-
+-   +- +- +-

+-String to key type used. See cc_string_to_key_type for valid values

+-

+- +- +- +- +-
+- +- +- +- +-
cc_time_t issue_date
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Time when the ticket was issued

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32 lifetime
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Ticket lifetime in 5 minute units

+-

+- +- +- +- +-
+- +- +- +- +-
cc_uint32 address
+-
+- +- +- +- +- +-
+-   +- +- +-

+-IPv4 address of the client the ticket was issued for

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32 ticket_size
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Ticket size (no greater than cc_v4_ticket_size)

+-

+- +- +- +- +-
+- +- +- +- +-
unsigned char ticket[cc_v4_ticket_size]
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Ticket data

+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__credentials__v5__t.html b/doc/ccapi/html/structcc__credentials__v5__t.html +deleted file mode 100644 +index ad0996281..000000000 +--- a/doc/ccapi/html/structcc__credentials__v5__t.html ++++ /dev/null +@@ -1,334 +0,0 @@ +- +- +-Credentials Cache API : cc_credentials_v5_t Struct Reference +- +- +- +- +-

cc_credentials_v5_t Struct Reference
+- +-[cc_credentials_t Overview] +-


Detailed Description

+-If a cc_credentials_t variable is used to store Kerberos v5 c redentials, and then credentials.credentials_v5 points to a v5 credentials structure. This structure is similar to a krb5_creds structure. +-

+-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
char* client
+-
+- +- +- +- +- +-
+-   +- +- +-

+-A properly quoted string representation of the client principal.

+-

+- +- +- +- +-
+- +- +- +- +-
char* server
+-
+- +- +- +- +- +-
+-   +- +- +-

+-A properly quoted string representation of the service principal.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_data keyblock
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Session encryption key info.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_time_t authtime
+-
+- +- +- +- +- +-
+-   +- +- +-

+-The time when the ticket was issued.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_time_t starttime
+-
+- +- +- +- +- +-
+-   +- +- +-

+-The time when the ticket becomes valid.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_time_t endtime
+-
+- +- +- +- +- +-
+-   +- +- +-

+-The time when the ticket expires.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_time_t renew_till
+-
+- +- +- +- +- +-
+-   +- +- +-

+-The time when the ticket becomes no longer renewable (if renewable).

+-

+- +- +- +- +-
+- +- +- +- +-
cc_uint32 is_skey
+-
+- +- +- +- +- +-
+-   +- +- +-

+-1 if the ticket is encrypted in another ticket's key, or 0 otherwise.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_uint32 ticket_flags
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Ticket flags, as defined by the Kerberos 5 API.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_data** addresses
+-
+- +- +- +- +- +-
+-   +- +- +-

+-The the list of network addresses of hosts that are allowed to authenticate using this ticket.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_data ticket
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Ticket data.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_data second_ticket
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Second ticket data.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_data** authdata
+-
+- +- +- +- +- +-
+-   +- +- +-

+-Authorization data.

+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__data.html b/doc/ccapi/html/structcc__data.html +deleted file mode 100644 +index 346f6a41d..000000000 +--- a/doc/ccapi/html/structcc__data.html ++++ /dev/null +@@ -1,94 +0,0 @@ +- +- +-Credentials Cache API : cc_data Struct Reference +- +- +- +- +-

cc_data Struct Reference
+- +-[cc_credentials_t Overview] +-


Detailed Description

+-The CCAPI data structure. This structure is similar to a krb5_data structure. In a v5 credentials structure, cc_data structures are used to store tagged variable-length binary data. Specifically, for cc_credentials_v5.ticket and cc_credentials_v5.second_ticket, the cc_data.type field must be zero. For the cc_credentials_v5.addresses, cc_credentials_v5.authdata, and cc_credentials_v5.keyblock, the cc_data.type field should be the address type, authorization data type, and encryption type, as defined by the Kerberos v5 protocol definition. +-

+-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
cc_uint32 type
+-
+- +- +- +- +- +-
+-   +- +- +-

+-The type of the data as defined by the krb5_data structure.

+-

+- +- +- +- +-
+- +- +- +- +-
cc_uint32 length
+-
+- +- +- +- +- +-
+-   +- +- +-

+-The length of data.

+-

+- +- +- +- +-
+- +- +- +- +-
void* data
+-
+- +- +- +- +- +-
+-   +- +- +-

+-The data buffer.

+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__string__d.html b/doc/ccapi/html/structcc__string__d.html +deleted file mode 100644 +index b38286b3e..000000000 +--- a/doc/ccapi/html/structcc__string__d.html ++++ /dev/null +@@ -1,67 +0,0 @@ +- +- +-Credentials Cache API : cc_string_d Struct Reference +- +- +- +- +-

cc_string_d Struct Reference
+- +-[cc_string_t Overview] +-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
const char* data
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-

+- +- +- +- +-
+- +- +- +- +-
const cc_string_f* functions
+-
+- +- +- +- +- +-
+-   +- +- +-

+-

+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- +diff --git a/doc/ccapi/html/structcc__string__f.html b/doc/ccapi/html/structcc__string__f.html +deleted file mode 100644 +index d5f738f49..000000000 +--- a/doc/ccapi/html/structcc__string__f.html ++++ /dev/null +@@ -1,51 +0,0 @@ +- +- +-Credentials Cache API : cc_string_f Struct Reference +- +- +- +- +-

cc_string_f Struct Reference


Detailed Description

+-Function pointer table for cc_string_t. For more information see cc_string_t Overview. +-

+-

Data Fields

+- +-

Field Documentation

+-

+- +- +- +- +-
+- +- +- +- +-
cc_int32(* release)(cc_string_t io_string)
+-
+- +- +- +- +- +-
+-   +- +- +-

+-cc_string_release(): Release memory associated with a cc_string_t object. +-

+-

Parameters:
+- +- +-
io_string the string object to release.
+-
+-
Returns:
On success, ccNoError. On failure, an error code representing the failure.
+-
+-


Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  +- +-doxygen 1.4.6
+- +- diff --git a/Remove-kadmin-RPC-support-for-setting-v4-key.patch b/Remove-kadmin-RPC-support-for-setting-v4-key.patch new file mode 100644 index 0000000..17d63c5 --- /dev/null +++ b/Remove-kadmin-RPC-support-for-setting-v4-key.patch @@ -0,0 +1,466 @@ +From a2fc99321c797c1534f6314d17560c622ec93418 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 4 Apr 2019 16:14:46 -0400 +Subject: [PATCH] Remove kadmin RPC support for setting v4 key + +ticket: 8794 (new) +(cherry picked from commit 752187a441ed0f301f1a8adb1fea843080ac8c97) +--- + src/kadmin/server/kadm_rpc_svc.c | 7 -- + src/kadmin/server/ovsec_kadmd.c | 2 +- + src/kadmin/server/server_stubs.c | 50 --------- + src/lib/kadm5/admin.h | 3 - + src/lib/kadm5/admin_xdr.h | 1 - + src/lib/kadm5/clnt/Makefile.in | 2 +- + src/lib/kadm5/clnt/client_principal.c | 22 ---- + src/lib/kadm5/clnt/client_rpc.c | 8 -- + src/lib/kadm5/clnt/libkadm5clnt_mit.exports | 2 - + src/lib/kadm5/kadm_rpc.h | 16 +-- + src/lib/kadm5/kadm_rpc_xdr.c | 19 ---- + src/lib/kadm5/srv/Makefile.in | 2 +- + src/lib/kadm5/srv/libkadm5srv_mit.exports | 2 - + src/lib/kadm5/srv/svr_principal.c | 118 -------------------- + 14 files changed, 6 insertions(+), 248 deletions(-) + +diff --git a/src/kadmin/server/kadm_rpc_svc.c b/src/kadmin/server/kadm_rpc_svc.c +index 41fc88ac8..d343e2c25 100644 +--- a/src/kadmin/server/kadm_rpc_svc.c ++++ b/src/kadmin/server/kadm_rpc_svc.c +@@ -53,7 +53,6 @@ void kadm_1(rqstp, transp) + mpol_arg modify_policy_2_arg; + gpol_arg get_policy_2_arg; + setkey_arg setkey_principal_2_arg; +- setv4key_arg setv4key_principal_2_arg; + cprinc3_arg create_principal3_2_arg; + chpass3_arg chpass_principal3_2_arg; + chrand3_arg chrand_principal3_2_arg; +@@ -134,12 +133,6 @@ void kadm_1(rqstp, transp) + local = (bool_t (*)()) chpass_principal_2_svc; + break; + +- case SETV4KEY_PRINCIPAL: +- xdr_argument = xdr_setv4key_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) setv4key_principal_2_svc; +- break; +- + case SETKEY_PRINCIPAL: + xdr_argument = xdr_setkey_arg; + xdr_result = xdr_generic_ret; +diff --git a/src/kadmin/server/ovsec_kadmd.c b/src/kadmin/server/ovsec_kadmd.c +index 6a6b21401..3737791b6 100644 +--- a/src/kadmin/server/ovsec_kadmd.c ++++ b/src/kadmin/server/ovsec_kadmd.c +@@ -227,7 +227,7 @@ log_badverf(gss_name_t client_name, gss_name_t server_name, + {14, "GET_PRINCS"}, + {15, "GET_POLS"}, + {16, "SETKEY_PRINCIPAL"}, +- {17, "SETV4KEY_PRINCIPAL"}, ++ /* 17 was "SETV4KEY_PRINCIPAL" */ + {18, "CREATE_PRINCIPAL3"}, + {19, "CHPASS_PRINCIPAL3"}, + {20, "CHRAND_PRINCIPAL3"}, +diff --git a/src/kadmin/server/server_stubs.c b/src/kadmin/server/server_stubs.c +index cfef97fec..d5a25e502 100644 +--- a/src/kadmin/server/server_stubs.c ++++ b/src/kadmin/server/server_stubs.c +@@ -893,56 +893,6 @@ exit_func: + return TRUE; + } + +-bool_t +-setv4key_principal_2_svc(setv4key_arg *arg, generic_ret *ret, +- struct svc_req *rqstp) +-{ +- char *prime_arg = NULL; +- gss_buffer_desc client_name = GSS_C_EMPTY_BUFFER; +- gss_buffer_desc service_name = GSS_C_EMPTY_BUFFER; +- kadm5_server_handle_t handle; +- const char *errmsg = NULL; +- +- ret->code = stub_setup(arg->api_version, rqstp, arg->princ, &handle, +- &ret->api_version, &client_name, &service_name, +- &prime_arg); +- if (ret->code) +- goto exit_func; +- +- ret->code = check_lockdown_keys(handle, arg->princ); +- if (ret->code != KADM5_OK) { +- if (ret->code == KADM5_PROTECT_KEYS) { +- log_unauth("kadm5_setv4key_principal", prime_arg, &client_name, +- &service_name, rqstp); +- ret->code = KADM5_AUTH_SETKEY; +- } +- } else if (!(CHANGEPW_SERVICE(rqstp)) && +- stub_auth(handle, OP_SETKEY, arg->princ, NULL, NULL, NULL)) { +- ret->code = kadm5_setv4key_principal(handle, arg->princ, +- arg->keyblock); +- } else { +- log_unauth("kadm5_setv4key_principal", prime_arg, +- &client_name, &service_name, rqstp); +- ret->code = KADM5_AUTH_SETKEY; +- } +- +- if (ret->code != KADM5_AUTH_SETKEY) { +- if (ret->code != 0) +- errmsg = krb5_get_error_message(handle->context, ret->code); +- +- log_done("kadm5_setv4key_principal", prime_arg, errmsg, +- &client_name, &service_name, rqstp); +- +- if (errmsg != NULL) +- krb5_free_error_message(handle->context, errmsg); +- } +- +-exit_func: +- stub_cleanup(handle, prime_arg, &client_name, &service_name); +- return TRUE; +-} +- +- + bool_t + setkey_principal_2_svc(setkey_arg *arg, generic_ret *ret, + struct svc_req *rqstp) +diff --git a/src/lib/kadm5/admin.h b/src/lib/kadm5/admin.h +index b765148b3..7268be44e 100644 +--- a/src/lib/kadm5/admin.h ++++ b/src/lib/kadm5/admin.h +@@ -394,9 +394,6 @@ kadm5_ret_t kadm5_randkey_principal_3(void *server_handle, + krb5_key_salt_tuple *ks_tuple, + krb5_keyblock **keyblocks, + int *n_keys); +-kadm5_ret_t kadm5_setv4key_principal(void *server_handle, +- krb5_principal principal, +- krb5_keyblock *keyblock); + + kadm5_ret_t kadm5_setkey_principal(void *server_handle, + krb5_principal principal, +diff --git a/src/lib/kadm5/admin_xdr.h b/src/lib/kadm5/admin_xdr.h +index 2d22611e7..9da98451e 100644 +--- a/src/lib/kadm5/admin_xdr.h ++++ b/src/lib/kadm5/admin_xdr.h +@@ -37,7 +37,6 @@ bool_t xdr_mprinc_arg(XDR *xdrs, mprinc_arg *objp); + bool_t xdr_rprinc_arg(XDR *xdrs, rprinc_arg *objp); + bool_t xdr_chpass_arg(XDR *xdrs, chpass_arg *objp); + bool_t xdr_chpass3_arg(XDR *xdrs, chpass3_arg *objp); +-bool_t xdr_setv4key_arg(XDR *xdrs, setv4key_arg *objp); + bool_t xdr_setkey_arg(XDR *xdrs, setkey_arg *objp); + bool_t xdr_setkey3_arg(XDR *xdrs, setkey3_arg *objp); + bool_t xdr_setkey4_arg(XDR *xdrs, setkey4_arg *objp); +diff --git a/src/lib/kadm5/clnt/Makefile.in b/src/lib/kadm5/clnt/Makefile.in +index a180e85cd..2bc385afe 100644 +--- a/src/lib/kadm5/clnt/Makefile.in ++++ b/src/lib/kadm5/clnt/Makefile.in +@@ -3,7 +3,7 @@ BUILDTOP=$(REL)..$(S)..$(S).. + LOCALINCLUDES = -I$(BUILDTOP)/include/kadm5 + + LIBBASE=kadm5clnt_mit +-LIBMAJOR=11 ++LIBMAJOR=12 + LIBMINOR=0 + STOBJLISTS=../OBJS.ST OBJS.ST + SHLIB_EXPDEPS=\ +diff --git a/src/lib/kadm5/clnt/client_principal.c b/src/lib/kadm5/clnt/client_principal.c +index 18714bf37..96d9d1932 100644 +--- a/src/lib/kadm5/clnt/client_principal.c ++++ b/src/lib/kadm5/clnt/client_principal.c +@@ -273,28 +273,6 @@ kadm5_chpass_principal_3(void *server_handle, + return r.code; + } + +-kadm5_ret_t +-kadm5_setv4key_principal(void *server_handle, +- krb5_principal princ, +- krb5_keyblock *keyblock) +-{ +- setv4key_arg arg; +- generic_ret r = { 0, 0 }; +- kadm5_server_handle_t handle = server_handle; +- +- CHECK_HANDLE(server_handle); +- +- arg.princ = princ; +- arg.keyblock = keyblock; +- arg.api_version = handle->api_version; +- +- if(princ == NULL || keyblock == NULL) +- return EINVAL; +- if (setv4key_principal_2(&arg, &r, handle->clnt)) +- eret(); +- return r.code; +-} +- + kadm5_ret_t + kadm5_setkey_principal(void *server_handle, + krb5_principal princ, +diff --git a/src/lib/kadm5/clnt/client_rpc.c b/src/lib/kadm5/clnt/client_rpc.c +index df5455fd8..d84d158b4 100644 +--- a/src/lib/kadm5/clnt/client_rpc.c ++++ b/src/lib/kadm5/clnt/client_rpc.c +@@ -84,14 +84,6 @@ chpass_principal3_2(chpass3_arg *argp, generic_ret *res, CLIENT *clnt) + (xdrproc_t)xdr_generic_ret, (caddr_t)res, TIMEOUT); + } + +-enum clnt_stat +-setv4key_principal_2(setv4key_arg *argp, generic_ret *res, CLIENT *clnt) +-{ +- return clnt_call(clnt, SETV4KEY_PRINCIPAL, +- (xdrproc_t)xdr_setv4key_arg, (caddr_t)argp, +- (xdrproc_t)xdr_generic_ret, (caddr_t)res, TIMEOUT); +-} +- + enum clnt_stat + setkey_principal_2(setkey_arg *argp, generic_ret *res, CLIENT *clnt) + { +diff --git a/src/lib/kadm5/clnt/libkadm5clnt_mit.exports b/src/lib/kadm5/clnt/libkadm5clnt_mit.exports +index f122b31ab..e41c8e4f7 100644 +--- a/src/lib/kadm5/clnt/libkadm5clnt_mit.exports ++++ b/src/lib/kadm5/clnt/libkadm5clnt_mit.exports +@@ -44,7 +44,6 @@ kadm5_set_string + kadm5_setkey_principal + kadm5_setkey_principal_3 + kadm5_setkey_principal_4 +-kadm5_setv4key_principal + kadm5_unlock + krb5_aprof_finish + krb5_aprof_get_boolean +@@ -114,6 +113,5 @@ xdr_rprinc_arg + xdr_setkey3_arg + xdr_setkey4_arg + xdr_setkey_arg +-xdr_setv4key_arg + xdr_ui_4 + kadm5_init_iprop +diff --git a/src/lib/kadm5/kadm_rpc.h b/src/lib/kadm5/kadm_rpc.h +index 8d7cf3b36..5099c6c14 100644 +--- a/src/lib/kadm5/kadm_rpc.h ++++ b/src/lib/kadm5/kadm_rpc.h +@@ -82,13 +82,6 @@ struct chpass3_arg { + }; + typedef struct chpass3_arg chpass3_arg; + +-struct setv4key_arg { +- krb5_ui_4 api_version; +- krb5_principal princ; +- krb5_keyblock *keyblock; +-}; +-typedef struct setv4key_arg setv4key_arg; +- + struct setkey_arg { + krb5_ui_4 api_version; + krb5_principal princ; +@@ -322,11 +315,9 @@ extern enum clnt_stat setkey_principal_2(setkey_arg *, generic_ret *, + CLIENT *); + extern bool_t setkey_principal_2_svc(setkey_arg *, generic_ret *, + struct svc_req *); +-#define SETV4KEY_PRINCIPAL 17 +-extern enum clnt_stat setv4key_principal_2(setv4key_arg *, generic_ret *, +- CLIENT *); +-extern bool_t setv4key_principal_2_svc(setv4key_arg *, generic_ret *, +- struct svc_req *); ++ ++/* 17 was SETV4KEY_PRINCIPAL (removed in 1.18). */ ++ + #define CREATE_PRINCIPAL3 18 + extern enum clnt_stat create_principal3_2(cprinc3_arg *, generic_ret *, + CLIENT *); +@@ -380,7 +371,6 @@ extern bool_t xdr_gprincs_arg (); + extern bool_t xdr_gprincs_ret (); + extern bool_t xdr_chpass_arg (); + extern bool_t xdr_chpass3_arg (); +-extern bool_t xdr_setv4key_arg (); + extern bool_t xdr_setkey_arg (); + extern bool_t xdr_setkey3_arg (); + extern bool_t xdr_setkey4_arg (); +diff --git a/src/lib/kadm5/kadm_rpc_xdr.c b/src/lib/kadm5/kadm_rpc_xdr.c +index 2892d4147..745ee857e 100644 +--- a/src/lib/kadm5/kadm_rpc_xdr.c ++++ b/src/lib/kadm5/kadm_rpc_xdr.c +@@ -710,25 +710,6 @@ xdr_chpass3_arg(XDR *xdrs, chpass3_arg *objp) + return (TRUE); + } + +-bool_t +-xdr_setv4key_arg(XDR *xdrs, setv4key_arg *objp) +-{ +- unsigned int n_keys = 1; +- +- if (!xdr_ui_4(xdrs, &objp->api_version)) { +- return (FALSE); +- } +- if (!xdr_krb5_principal(xdrs, &objp->princ)) { +- return (FALSE); +- } +- if (!xdr_array(xdrs, (caddr_t *) &objp->keyblock, +- &n_keys, ~0, +- sizeof(krb5_keyblock), xdr_krb5_keyblock)) { +- return (FALSE); +- } +- return (TRUE); +-} +- + bool_t + xdr_setkey_arg(XDR *xdrs, setkey_arg *objp) + { +diff --git a/src/lib/kadm5/srv/Makefile.in b/src/lib/kadm5/srv/Makefile.in +index 617d65666..89e6097cf 100644 +--- a/src/lib/kadm5/srv/Makefile.in ++++ b/src/lib/kadm5/srv/Makefile.in +@@ -9,7 +9,7 @@ DEFINES = @HESIOD_DEFS@ + ##DOSLIBNAME = libkadm5srv.lib + + LIBBASE=kadm5srv_mit +-LIBMAJOR=11 ++LIBMAJOR=12 + LIBMINOR=0 + STOBJLISTS=../OBJS.ST OBJS.ST + +diff --git a/src/lib/kadm5/srv/libkadm5srv_mit.exports b/src/lib/kadm5/srv/libkadm5srv_mit.exports +index 64ad5dd69..e3c04e690 100644 +--- a/src/lib/kadm5/srv/libkadm5srv_mit.exports ++++ b/src/lib/kadm5/srv/libkadm5srv_mit.exports +@@ -45,7 +45,6 @@ kadm5_set_string + kadm5_setkey_principal + kadm5_setkey_principal_3 + kadm5_setkey_principal_4 +-kadm5_setv4key_principal + kadm5_unlock + kdb_delete_entry + kdb_free_entry +@@ -133,7 +132,6 @@ xdr_rprinc_arg + xdr_setkey3_arg + xdr_setkey4_arg + xdr_setkey_arg +-xdr_setv4key_arg + xdr_sstring_arg + xdr_ui_4 + kadm5_init_iprop +diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c +index 9ab2c5a74..48cac0c11 100644 +--- a/src/lib/kadm5/srv/svr_principal.c ++++ b/src/lib/kadm5/srv/svr_principal.c +@@ -1645,124 +1645,6 @@ done: + return ret; + } + +-/* +- * kadm5_setv4key_principal: +- * +- * Set only ONE key of the principal, removing all others. This key +- * must have the DES_CBC_CRC enctype and is entered as having the +- * krb4 salttype. This is to enable things like kadmind4 to work. +- */ +-kadm5_ret_t +-kadm5_setv4key_principal(void *server_handle, +- krb5_principal principal, +- krb5_keyblock *keyblock) +-{ +- krb5_db_entry *kdb; +- osa_princ_ent_rec adb; +- krb5_timestamp now; +- kadm5_policy_ent_rec pol; +- krb5_keysalt keysalt; +- int i, kvno, ret; +- krb5_boolean have_pol = FALSE; +- kadm5_server_handle_t handle = server_handle; +- krb5_key_data tmp_key_data; +- krb5_keyblock *act_mkey; +- +- memset( &tmp_key_data, 0, sizeof(tmp_key_data)); +- +- CHECK_HANDLE(server_handle); +- +- krb5_clear_error_message(handle->context); +- +- if (principal == NULL || keyblock == NULL) +- return EINVAL; +- if (hist_princ && /* this will be NULL when initializing the databse */ +- ((krb5_principal_compare(handle->context, +- principal, hist_princ)) == TRUE)) +- return KADM5_PROTECT_PRINCIPAL; +- +- if (keyblock->enctype != ENCTYPE_DES_CBC_CRC) +- return KADM5_SETV4KEY_INVAL_ENCTYPE; +- +- if ((ret = kdb_get_entry(handle, principal, &kdb, &adb))) +- return(ret); +- +- for (kvno = 0, i=0; in_key_data; i++) +- if (kdb->key_data[i].key_data_kvno > kvno) +- kvno = kdb->key_data[i].key_data_kvno; +- +- if (kdb->key_data != NULL) +- cleanup_key_data(handle->context, kdb->n_key_data, kdb->key_data); +- +- kdb->key_data = calloc(1, sizeof(krb5_key_data)); +- if (kdb->key_data == NULL) +- return ENOMEM; +- kdb->n_key_data = 1; +- keysalt.type = KRB5_KDB_SALTTYPE_V4; +- /* XXX data.magic? */ +- keysalt.data.length = 0; +- keysalt.data.data = NULL; +- +- ret = kdb_get_active_mkey(handle, NULL, &act_mkey); +- if (ret) +- goto done; +- +- /* use tmp_key_data as temporary location and reallocate later */ +- ret = krb5_dbe_encrypt_key_data(handle->context, act_mkey, keyblock, +- &keysalt, kvno + 1, kdb->key_data); +- if (ret) { +- goto done; +- } +- +- kdb->attributes &= ~KRB5_KDB_REQUIRES_PWCHANGE; +- +- ret = krb5_timeofday(handle->context, &now); +- if (ret) +- goto done; +- +- if ((adb.aux_attributes & KADM5_POLICY)) { +- ret = get_policy(handle, adb.policy, &pol, &have_pol); +- if (ret) +- goto done; +- } +- if (have_pol) { +- if (pol.pw_max_life) +- kdb->pw_expiration = ts_incr(now, pol.pw_max_life); +- else +- kdb->pw_expiration = 0; +- } else { +- kdb->pw_expiration = 0; +- } +- +- ret = krb5_dbe_update_last_pwd_change(handle->context, kdb, now); +- if (ret) +- goto done; +- +- /* unlock principal on this KDC */ +- kdb->fail_auth_count = 0; +- +- /* key data changed, let the database provider know */ +- kdb->mask = KADM5_KEY_DATA | KADM5_FAIL_AUTH_COUNT; +- +- if ((ret = kdb_put_entry(handle, kdb, &adb))) +- goto done; +- +- ret = KADM5_OK; +-done: +- for (i = 0; i < tmp_key_data.key_data_ver; i++) { +- if (tmp_key_data.key_data_contents[i]) { +- memset (tmp_key_data.key_data_contents[i], 0, tmp_key_data.key_data_length[i]); +- free (tmp_key_data.key_data_contents[i]); +- } +- } +- +- kdb_free_entry(handle, kdb, &adb); +- if (have_pol) +- kadm5_free_policy_ent(handle->lhandle, &pol); +- +- return ret; +-} +- + kadm5_ret_t + kadm5_setkey_principal(void *server_handle, + krb5_principal principal, diff --git a/Remove-srvtab-support.patch b/Remove-srvtab-support.patch new file mode 100644 index 0000000..48535af --- /dev/null +++ b/Remove-srvtab-support.patch @@ -0,0 +1,1410 @@ +From 152f5ed9961f54dd9d764ffb3c6298eb85d8f934 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 9 Oct 2017 15:58:33 -0400 +Subject: [PATCH] Remove srvtab support + +Also change internal names from "srvtab" to "keytab" where the old +name was used. + +ticket: 8793 (new) +(cherry picked from commit a23e670b40f69b6be0024f8a60d2afaf7f7a005a) +--- + doc/admin/admin_commands/ktutil.rst | 22 +- + doc/basic/keytab_def.rst | 6 +- + src/kadmin/ktutil/ktutil.c | 11 +- + src/kadmin/ktutil/ktutil.h | 4 - + src/kadmin/ktutil/ktutil_ct.ct | 4 +- + src/kadmin/ktutil/ktutil_funcs.c | 19 - + src/kadmin/testing/proto/krb5.conf.proto | 2 +- + src/kadmin/testing/scripts/env-setup.shin | 2 +- + src/kadmin/testing/scripts/init_db | 2 +- + .../testing/scripts/make-host-keytab.plin | 2 +- + .../testing/scripts/start_servers_local | 3 - + src/kprop/kprop.c | 10 +- + src/kprop/kpropd.c | 12 +- + src/lib/kadm5/unit-test/api.current/init.exp | 4 +- + src/lib/krb5/keytab/Makefile.in | 3 - + src/lib/krb5/keytab/deps | 11 - + src/lib/krb5/keytab/kt_srvtab.c | 435 ------------------ + src/lib/krb5/keytab/ktbase.c | 7 +- + src/lib/krb5/krb/in_tkt_sky.c | 6 +- + src/lib/krb5/libkrb5.exports | 1 - + src/lib/rpc/unit-test/Makefile.in | 6 +- + src/lib/rpc/unit-test/config/unix.exp | 2 +- + src/lib/rpc/unit-test/lib/helpers.exp | 4 +- + src/lib/rpc/unit-test/rpc_test_setup.sh | 6 +- + src/man/ktutil.man | 26 +- + src/tests/dejagnu/config/default.exp | 58 ++- + src/tests/dejagnu/krb-standalone/gssapi.exp | 8 +- + src/tests/dejagnu/krb-standalone/kadmin.exp | 48 +- + src/tests/dejagnu/krb-standalone/kprop.exp | 6 +- + src/tests/dejagnu/krb-standalone/sample.exp | 8 +- + src/tests/dejagnu/krb-standalone/simple.exp | 6 +- + .../dejagnu/krb-standalone/standalone.exp | 4 +- + src/tests/dejagnu/krb-standalone/tcp.exp | 5 - + 33 files changed, 86 insertions(+), 667 deletions(-) + delete mode 100644 src/lib/krb5/keytab/kt_srvtab.c + +diff --git a/doc/admin/admin_commands/ktutil.rst b/doc/admin/admin_commands/ktutil.rst +index 0dbc08f60..0897c7757 100644 +--- a/doc/admin/admin_commands/ktutil.rst ++++ b/doc/admin/admin_commands/ktutil.rst +@@ -13,8 +13,8 @@ DESCRIPTION + ----------- + + The ktutil command invokes a command interface from which an +-administrator can read, write, or edit entries in a keytab or Kerberos +-V4 srvtab file. ++administrator can read, write, or edit entries in a keytab. (Kerberos ++V4 srvtab files are no longer supported.) + + + COMMANDS +@@ -38,15 +38,6 @@ Read the Kerberos V5 keytab file *keytab* into the current keylist. + + Alias: **rkt** + +-read_st +-~~~~~~~ +- +- **read_st** *srvtab* +- +-Read the Kerberos V4 srvtab file *srvtab* into the current keylist. +- +-Alias: **rst** +- + write_kt + ~~~~~~~~ + +@@ -56,15 +47,6 @@ Write the current keylist into the Kerberos V5 keytab file *keytab*. + + Alias: **wkt** + +-write_st +-~~~~~~~~ +- +- **write_st** *srvtab* +- +-Write the current keylist into the Kerberos V4 srvtab file *srvtab*. +- +-Alias: **wst** +- + clear_list + ~~~~~~~~~~ + +diff --git a/doc/basic/keytab_def.rst b/doc/basic/keytab_def.rst +index 33ae67c6c..6c7fcc3b0 100644 +--- a/doc/basic/keytab_def.rst ++++ b/doc/basic/keytab_def.rst +@@ -12,10 +12,8 @@ credentials for client applications. + + Keytabs are named using the format *type*\ ``:``\ *value*. Usually + *type* is ``FILE`` and *value* is the absolute pathname of the file. +-Other possible values for *type* are ``SRVTAB``, which indicates a +-file in the deprecated Kerberos 4 srvtab format, and ``MEMORY``, which +-indicates a temporary keytab stored in the memory of the current +-process. ++The other possible value for *type* is ``MEMORY``, which indicates a ++temporary keytab stored in the memory of the current process. + + A keytab contains one or more entries, where each entry consists of a + timestamp (indicating when the entry was written to the keytab), a +diff --git a/src/kadmin/ktutil/ktutil.c b/src/kadmin/ktutil/ktutil.c +index 196f20786..92d7023a4 100644 +--- a/src/kadmin/ktutil/ktutil.c ++++ b/src/kadmin/ktutil/ktutil.c +@@ -98,15 +98,8 @@ void ktutil_read_v4(argc, argv) + int argc; + char *argv[]; + { +- krb5_error_code retval; +- +- if (argc != 2) { +- fprintf(stderr, _("%s: must specify the srvtab to read\n"), argv[0]); +- return; +- } +- retval = ktutil_read_srvtab(kcontext, argv[1], &ktlist); +- if (retval) +- com_err(argv[0], retval, _("while reading srvtab \"%s\""), argv[1]); ++ fprintf(stderr, _("%s: reading srvtabs is no longer supported\n"), ++ argv[0]); + } + + void ktutil_write_v5(argc, argv) +diff --git a/src/kadmin/ktutil/ktutil.h b/src/kadmin/ktutil/ktutil.h +index ddb754bae..acaf0239a 100644 +--- a/src/kadmin/ktutil/ktutil.h ++++ b/src/kadmin/ktutil/ktutil.h +@@ -50,10 +50,6 @@ krb5_error_code ktutil_write_keytab (krb5_context, + krb5_kt_list, + char *); + +-krb5_error_code ktutil_read_srvtab (krb5_context, +- char *, +- krb5_kt_list *); +- + void ktutil_add_entry (int, char *[]); + + void ktutil_clear_list (int, char *[]); +diff --git a/src/kadmin/ktutil/ktutil_ct.ct b/src/kadmin/ktutil/ktutil_ct.ct +index 0c7ccb689..2061ef9d0 100644 +--- a/src/kadmin/ktutil/ktutil_ct.ct ++++ b/src/kadmin/ktutil/ktutil_ct.ct +@@ -32,13 +32,13 @@ request ktutil_clear_list, "Clear the current keylist.", + request ktutil_read_v5, "Read a krb5 keytab into the current keylist.", + read_kt, rkt; + +-request ktutil_read_v4, "Read a krb4 srvtab into the current keylist.", ++request ktutil_read_v4, "Deprecated and removed.", + read_st, rst; + + request ktutil_write_v5, "Write the current keylist to a krb5 keytab.", + write_kt, wkt; + +-request ktutil_write_v4, "Write the current keylist to a krb4 srvtab.", ++request ktutil_write_v4, "Deprecated and removed.", + write_st, wst; + + request ktutil_add_entry, "Add an entry to the current keylist.", +diff --git a/src/kadmin/ktutil/ktutil_funcs.c b/src/kadmin/ktutil/ktutil_funcs.c +index 6d119a2b6..e2e005d22 100644 +--- a/src/kadmin/ktutil/ktutil_funcs.c ++++ b/src/kadmin/ktutil/ktutil_funcs.c +@@ -368,22 +368,3 @@ krb5_error_code ktutil_write_keytab(context, list, name) + krb5_kt_close(context, kt); + return retval; + } +- +-/* +- * Read in a named krb4 srvtab and append to list. Allocate new list +- * if needed. +- */ +-krb5_error_code ktutil_read_srvtab(context, name, list) +- krb5_context context; +- char *name; +- krb5_kt_list *list; +-{ +- char *ktname; +- krb5_error_code result; +- +- if (asprintf(&ktname, "SRVTAB:%s", name) < 0) +- return ENOMEM; +- result = ktutil_read_keytab(context, ktname, list); +- free(ktname); +- return result; +-} +diff --git a/src/kadmin/testing/proto/krb5.conf.proto b/src/kadmin/testing/proto/krb5.conf.proto +index 9c4bc1de7..f91cf70f3 100644 +--- a/src/kadmin/testing/proto/krb5.conf.proto ++++ b/src/kadmin/testing/proto/krb5.conf.proto +@@ -1,6 +1,6 @@ + [libdefaults] + default_realm = __REALM__ +- default_keytab_name = FILE:__K5ROOT__/v5srvtab ++ default_keytab_name = FILE:__K5ROOT__/keytab + dns_fallback = no + plugin_base_dir = __PLUGIN_DIR__ + allow_weak_crypto = true +diff --git a/src/kadmin/testing/scripts/env-setup.shin b/src/kadmin/testing/scripts/env-setup.shin +index c8d866f15..726298351 100755 +--- a/src/kadmin/testing/scripts/env-setup.shin ++++ b/src/kadmin/testing/scripts/env-setup.shin +@@ -77,7 +77,7 @@ SRVTCL=$TESTDIR/util/kadm5_srv_tcl; export SRVTCL + + KRB5_CONFIG=$K5ROOT/krb5.conf; export KRB5_CONFIG + KRB5_KDC_PROFILE=$K5ROOT/kdc.conf; export KRB5_KDC_PROFILE +-KRB5_KTNAME=$K5ROOT/ovsec_adm.srvtab; export KRB5_KTNAME ++KRB5_KTNAME=$K5ROOT/ovsec_adm.keytab; export KRB5_KTNAME + KRB5_CLIENT_KTNAME=$K5ROOT/client_keytab; export KRB5_CLIENT_KTNAME + KRB5CCNAME=$K5ROOT/krb5cc_unit-test; export KRB5CCNAME + +diff --git a/src/kadmin/testing/scripts/init_db b/src/kadmin/testing/scripts/init_db +index cd7165628..bf119f2ac 100755 +--- a/src/kadmin/testing/scripts/init_db ++++ b/src/kadmin/testing/scripts/init_db +@@ -218,7 +218,7 @@ changepw/kerberos@$REALM cil + + EOF + +-eval $LOCAL_MAKE_KEYTAB -princ kadmin/admin -princ kadmin/changepw -princ ovsec_adm/admin -princ ovsec_adm/changepw $K5ROOT/ovsec_adm.srvtab $REDIRECT ++eval $LOCAL_MAKE_KEYTAB -princ kadmin/admin -princ kadmin/changepw -princ ovsec_adm/admin -princ ovsec_adm/changepw $K5ROOT/ovsec_adm.keytab $REDIRECT + + # Create $K5ROOT/setup.csh to make it easy to run other programs against + # the test db +diff --git a/src/kadmin/testing/scripts/make-host-keytab.plin b/src/kadmin/testing/scripts/make-host-keytab.plin +index dfe0b3a01..c77d61c70 100755 +--- a/src/kadmin/testing/scripts/make-host-keytab.plin ++++ b/src/kadmin/testing/scripts/make-host-keytab.plin +@@ -11,7 +11,7 @@ $usage = "Usage: $whoami [ -server server ] [ -princ principal ] + Default principals are host/hostname\@SECURE-TEST.OV.COM and + test/hostname\@SECURE-TEST.OV.COM. + If any principals are specified, the default principals are +- not added to the srvtab. ++ not added to the keytab. + The string \"xCANONHOSTx\" in a principal specification will be + replaced by the canonical host name of the local host."; + +diff --git a/src/kadmin/testing/scripts/start_servers_local b/src/kadmin/testing/scripts/start_servers_local +index 0cbed462d..809892974 100755 +--- a/src/kadmin/testing/scripts/start_servers_local ++++ b/src/kadmin/testing/scripts/start_servers_local +@@ -98,9 +98,6 @@ x=$? + rm /tmp/start_servers_local$$ + if test $x != 0 ; then exit 1 ; fi + +-# rm -f /etc/v5srvtab +-# eval $LOCAL_MAKE_KEYTAB -princ host/xCANONHOSTx /etc/v5srvtab $REDIRECT +- + # run the servers (from the build tree) + + adm_start_file=/tmp/adm_server_start.$$ +diff --git a/src/kprop/kprop.c b/src/kprop/kprop.c +index b7fb63777..0b53aae7e 100644 +--- a/src/kprop/kprop.c ++++ b/src/kprop/kprop.c +@@ -49,7 +49,7 @@ static char *kprop_version = KPROP_PROT_VERSION; + + static char *progname = NULL; + static int debug = 0; +-static char *srvtab = NULL; ++static char *keytab_path = NULL; + static char *replica_host; + static char *realm = NULL; + static char *def_realm = NULL; +@@ -83,7 +83,7 @@ static void update_last_prop_file(char *hostname, char *file_name); + static void usage() + { + fprintf(stderr, _("\nUsage: %s [-r realm] [-f file] [-d] [-P port] " +- "[-s srvtab] replica_host\n\n"), progname); ++ "[-s keytab] replica_host\n\n"), progname); + exit(1); + } + +@@ -140,7 +140,7 @@ parse_args(krb5_context context, int argc, char **argv) + port = optarg; + break; + case 's': +- srvtab = optarg; ++ keytab_path = optarg; + break; + default: + usage(); +@@ -191,8 +191,8 @@ get_tickets(krb5_context context) + exit(1); + } + +- if (srvtab != NULL) { +- retval = krb5_kt_resolve(context, srvtab, &keytab); ++ if (keytab_path != NULL) { ++ retval = krb5_kt_resolve(context, keytab_path, &keytab); + if (retval) { + com_err(progname, retval, _("while resolving keytab")); + exit(1); +diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c +index 0c7bffa24..e4aaf553c 100644 +--- a/src/kprop/kpropd.c ++++ b/src/kprop/kpropd.c +@@ -117,7 +117,7 @@ static kadm5_config_params params; + static char *progname; + static int debug = 0; + static int nodaemon = 0; +-static char *srvtab = NULL; ++static char *keytab_path = NULL; + static int standalone = 0; + static const char *pid_file = NULL; + +@@ -168,7 +168,7 @@ static void + usage() + { + fprintf(stderr, +- _("\nUsage: %s [-r realm] [-s srvtab] [-dS] [-f replica_file]\n"), ++ _("\nUsage: %s [-r realm] [-s keytab] [-dS] [-f replica_file]\n"), + progname); + fprintf(stderr, _("\t[-F kerberos_db_file ] [-p kdb5_util_pathname]\n")); + fprintf(stderr, _("\t[-x db_args]* [-P port] [-a acl_file]\n")); +@@ -701,7 +701,7 @@ reinit: + iprop_svc_princstr); + } + retval = kadm5_init_with_skey(kpropd_context, iprop_svc_princstr, +- srvtab, ++ keytab_path, + master_svc_princstr, + ¶ms, + KADM5_STRUCT_VERSION, +@@ -1092,7 +1092,7 @@ parse_args(int argc, char **argv) + realm = optarg; + break; + case 's': +- srvtab = optarg; ++ keytab_path = optarg; + break; + case 'D': + nodaemon++; +@@ -1246,8 +1246,8 @@ kerberos_authenticate(krb5_context context, int fd, krb5_principal *clientp, + exit(1); + } + +- if (srvtab != NULL) { +- retval = krb5_kt_resolve(context, srvtab, &keytab); ++ if (keytab_path != NULL) { ++ retval = krb5_kt_resolve(context, keytab_path, &keytab); + if (retval) { + syslog(LOG_ERR, _("Error in krb5_kt_resolve: %s"), + error_message(retval)); +diff --git a/src/lib/kadm5/unit-test/api.current/init.exp b/src/lib/kadm5/unit-test/api.current/init.exp +index d9ae3fbd8..f78261376 100644 +--- a/src/lib/kadm5/unit-test/api.current/init.exp ++++ b/src/lib/kadm5/unit-test/api.current/init.exp +@@ -695,10 +695,10 @@ if {$RPC} { + test45_46 ovsec_adm/changepw + + # re-extract the keytab so it is right +- exec rm $env(K5ROOT)/ovsec_adm.srvtab ++ exec rm $env(K5ROOT)/ovsec_adm.keytab + exec $env(MAKE_KEYTAB) -princ ovsec_adm/admin -princ ovsec_adm/changepw \ + -princ kadmin/admin -princ kadmin/changepw \ +- $env(K5ROOT)/ovsec_adm.srvtab ++ $env(K5ROOT)/ovsec_adm.keytab + } + + return "" +diff --git a/src/lib/krb5/keytab/Makefile.in b/src/lib/krb5/keytab/Makefile.in +index 2a8fceb00..4621bf714 100644 +--- a/src/lib/krb5/keytab/Makefile.in ++++ b/src/lib/krb5/keytab/Makefile.in +@@ -14,7 +14,6 @@ STLIBOBJS= \ + ktfns.o \ + kt_file.o \ + kt_memory.o \ +- kt_srvtab.o \ + read_servi.o + + OBJS= \ +@@ -26,7 +25,6 @@ OBJS= \ + $(OUTPRE)ktfns.$(OBJEXT) \ + $(OUTPRE)kt_file.$(OBJEXT) \ + $(OUTPRE)kt_memory.$(OBJEXT) \ +- $(OUTPRE)kt_srvtab.$(OBJEXT) \ + $(OUTPRE)read_servi.$(OBJEXT) + + SRCS= \ +@@ -38,7 +36,6 @@ SRCS= \ + $(srcdir)/ktfns.c \ + $(srcdir)/kt_file.c \ + $(srcdir)/kt_memory.c \ +- $(srcdir)/kt_srvtab.c \ + $(srcdir)/read_servi.c + + EXTRADEPSRCS= \ +diff --git a/src/lib/krb5/keytab/deps b/src/lib/krb5/keytab/deps +index 4c98188ca..522cad0e8 100644 +--- a/src/lib/krb5/keytab/deps ++++ b/src/lib/krb5/keytab/deps +@@ -87,17 +87,6 @@ kt_memory.so kt_memory.po $(OUTPRE)kt_memory.$(OBJEXT): \ + $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ + $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ + kt-int.h kt_memory.c +-kt_srvtab.so kt_srvtab.po $(OUTPRE)kt_srvtab.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- kt_srvtab.c + read_servi.so read_servi.po $(OUTPRE)read_servi.$(OBJEXT): \ + $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ + $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +diff --git a/src/lib/krb5/keytab/kt_srvtab.c b/src/lib/krb5/keytab/kt_srvtab.c +deleted file mode 100644 +index bbfaadfc2..000000000 +--- a/src/lib/krb5/keytab/kt_srvtab.c ++++ /dev/null +@@ -1,435 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/krb5/keytab/kt_srvtab.c */ +-/* +- * Copyright 1990,1991,2002,2007,2008 by the Massachusetts Institute of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +-/* +- * Copyright (c) Hewlett-Packard Company 1991 +- * Released to the Massachusetts Institute of Technology for inclusion +- * in the Kerberos source code distribution. +- * +- * Copyright 1990,1991 by the Massachusetts Institute of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-#include "k5-int.h" +-#include +- +-#ifndef LEAN_CLIENT +- +-/* +- * Constants +- */ +- +-#define KRB5_KT_VNO_1 0x0501 /* krb v5, keytab version 1 (DCE compat) */ +-#define KRB5_KT_VNO 0x0502 /* krb v5, keytab version 2 (standard) */ +- +-#define KRB5_KT_DEFAULT_VNO KRB5_KT_VNO +- +-/* +- * Types +- */ +-typedef struct _krb5_ktsrvtab_data { +- char *name; /* Name of the file */ +- FILE *openf; /* open file, if any. */ +-} krb5_ktsrvtab_data; +- +-/* +- * Macros +- */ +-#define KTPRIVATE(id) ((krb5_ktsrvtab_data *)(id)->data) +-#define KTFILENAME(id) (((krb5_ktsrvtab_data *)(id)->data)->name) +-#define KTFILEP(id) (((krb5_ktsrvtab_data *)(id)->data)->openf) +- +-extern const struct _krb5_kt_ops krb5_kts_ops; +- +-static krb5_error_code KRB5_CALLCONV +-krb5_ktsrvtab_resolve(krb5_context, const char *, krb5_keytab *); +- +-static krb5_error_code KRB5_CALLCONV +-krb5_ktsrvtab_get_name(krb5_context, krb5_keytab, char *, unsigned int); +- +-static krb5_error_code KRB5_CALLCONV +-krb5_ktsrvtab_close(krb5_context, krb5_keytab); +- +-static krb5_error_code KRB5_CALLCONV +-krb5_ktsrvtab_get_entry(krb5_context, krb5_keytab, krb5_const_principal, +- krb5_kvno, krb5_enctype, krb5_keytab_entry *); +- +-static krb5_error_code KRB5_CALLCONV +-krb5_ktsrvtab_start_seq_get(krb5_context, krb5_keytab, krb5_kt_cursor *); +- +-static krb5_error_code KRB5_CALLCONV +-krb5_ktsrvtab_get_next(krb5_context, krb5_keytab, krb5_keytab_entry *, +- krb5_kt_cursor *); +- +-static krb5_error_code KRB5_CALLCONV +-krb5_ktsrvtab_end_get(krb5_context, krb5_keytab, krb5_kt_cursor *); +- +-static krb5_error_code +-krb5_ktsrvint_open(krb5_context, krb5_keytab); +- +-static krb5_error_code +-krb5_ktsrvint_close(krb5_context, krb5_keytab); +- +-static krb5_error_code +-krb5_ktsrvint_read_entry(krb5_context, krb5_keytab, krb5_keytab_entry *); +- +-/* +- * This is an implementation specific resolver. It returns a keytab id +- * initialized with srvtab keytab routines. +- */ +- +-static krb5_error_code KRB5_CALLCONV +-krb5_ktsrvtab_resolve(krb5_context context, const char *name, krb5_keytab *id) +-{ +- krb5_ktsrvtab_data *data; +- +- if ((*id = (krb5_keytab) malloc(sizeof(**id))) == NULL) +- return(ENOMEM); +- +- (*id)->ops = &krb5_kts_ops; +- data = (krb5_ktsrvtab_data *)malloc(sizeof(krb5_ktsrvtab_data)); +- if (data == NULL) { +- free(*id); +- return(ENOMEM); +- } +- +- data->name = strdup(name); +- if (data->name == NULL) { +- free(data); +- free(*id); +- return(ENOMEM); +- } +- +- data->openf = 0; +- +- (*id)->data = (krb5_pointer)data; +- (*id)->magic = KV5M_KEYTAB; +- return(0); +-} +- +-/* +- * "Close" a file-based keytab and invalidate the id. This means +- * free memory hidden in the structures. +- */ +- +-krb5_error_code KRB5_CALLCONV +-krb5_ktsrvtab_close(krb5_context context, krb5_keytab id) +-/* +- * This routine is responsible for freeing all memory allocated +- * for this keytab. There are no system resources that need +- * to be freed nor are there any open files. +- * +- * This routine should undo anything done by krb5_ktsrvtab_resolve(). +- */ +-{ +- free(KTFILENAME(id)); +- free(id->data); +- id->ops = 0; +- free(id); +- return (0); +-} +- +-/* +- * This is the get_entry routine for the file based keytab implementation. +- * It opens the keytab file, and either retrieves the entry or returns +- * an error. +- */ +- +-krb5_error_code KRB5_CALLCONV +-krb5_ktsrvtab_get_entry(krb5_context context, krb5_keytab id, krb5_const_principal principal, krb5_kvno kvno, krb5_enctype enctype, krb5_keytab_entry *entry) +-{ +- krb5_keytab_entry best_entry, ent; +- krb5_error_code kerror = 0; +- int found_wrong_kvno = 0; +- +- /* Open the srvtab. */ +- if ((kerror = krb5_ktsrvint_open(context, id))) +- return(kerror); +- +- /* srvtab files only have DES_CBC_CRC keys. */ +- switch (enctype) { +- case ENCTYPE_DES_CBC_CRC: +- case ENCTYPE_DES_CBC_MD5: +- case ENCTYPE_DES_CBC_MD4: +- case ENCTYPE_DES_CBC_RAW: +- case IGNORE_ENCTYPE: +- break; +- default: +- return KRB5_KT_NOTFOUND; +- } +- +- best_entry.principal = 0; +- best_entry.vno = 0; +- best_entry.key.contents = 0; +- while ((kerror = krb5_ktsrvint_read_entry(context, id, &ent)) == 0) { +- ent.key.enctype = enctype; +- if (krb5_principal_compare(context, principal, ent.principal)) { +- if (kvno == IGNORE_VNO || ent.vno == IGNORE_VNO) { +- if (!best_entry.principal || (best_entry.vno < ent.vno)) { +- krb5_kt_free_entry(context, &best_entry); +- best_entry = ent; +- } +- } else { +- if (ent.vno == kvno) { +- best_entry = ent; +- break; +- } else { +- found_wrong_kvno = 1; +- } +- } +- } else { +- krb5_kt_free_entry(context, &ent); +- } +- } +- if (kerror == KRB5_KT_END) { +- if (best_entry.principal) +- kerror = 0; +- else if (found_wrong_kvno) +- kerror = KRB5_KT_KVNONOTFOUND; +- else +- kerror = KRB5_KT_NOTFOUND; +- } +- if (kerror) { +- (void) krb5_ktsrvint_close(context, id); +- krb5_kt_free_entry(context, &best_entry); +- return kerror; +- } +- if ((kerror = krb5_ktsrvint_close(context, id)) != 0) { +- krb5_kt_free_entry(context, &best_entry); +- return kerror; +- } +- *entry = best_entry; +- return 0; +-} +- +-/* +- * Get the name of the file containing a srvtab-based keytab. +- */ +- +-krb5_error_code KRB5_CALLCONV +-krb5_ktsrvtab_get_name(krb5_context context, krb5_keytab id, char *name, unsigned int len) +-/* +- * This routine returns the name of the name of the file associated with +- * this srvtab-based keytab. The name is prefixed with PREFIX:, so that +- * trt will happen if the name is passed back to resolve. +- */ +-{ +- int result; +- +- memset(name, 0, len); +- result = snprintf(name, len, "%s:%s", id->ops->prefix, KTFILENAME(id)); +- if (SNPRINTF_OVERFLOW(result, len)) +- return(KRB5_KT_NAME_TOOLONG); +- return(0); +-} +- +-/* +- * krb5_ktsrvtab_start_seq_get() +- */ +- +-krb5_error_code KRB5_CALLCONV +-krb5_ktsrvtab_start_seq_get(krb5_context context, krb5_keytab id, krb5_kt_cursor *cursorp) +-{ +- krb5_error_code retval; +- long *fileoff; +- +- if ((retval = krb5_ktsrvint_open(context, id))) +- return retval; +- +- if (!(fileoff = (long *)malloc(sizeof(*fileoff)))) { +- krb5_ktsrvint_close(context, id); +- return ENOMEM; +- } +- *fileoff = ftell(KTFILEP(id)); +- *cursorp = (krb5_kt_cursor)fileoff; +- +- return 0; +-} +- +-/* +- * krb5_ktsrvtab_get_next() +- */ +- +-krb5_error_code KRB5_CALLCONV +-krb5_ktsrvtab_get_next(krb5_context context, krb5_keytab id, krb5_keytab_entry *entry, krb5_kt_cursor *cursor) +-{ +- long *fileoff = (long *)*cursor; +- krb5_keytab_entry cur_entry; +- krb5_error_code kerror; +- +- if (fseek(KTFILEP(id), *fileoff, 0) == -1) +- return KRB5_KT_END; +- if ((kerror = krb5_ktsrvint_read_entry(context, id, &cur_entry))) +- return kerror; +- *fileoff = ftell(KTFILEP(id)); +- *entry = cur_entry; +- return 0; +-} +- +-/* +- * krb5_ktsrvtab_end_get() +- */ +- +-krb5_error_code KRB5_CALLCONV +-krb5_ktsrvtab_end_get(krb5_context context, krb5_keytab id, krb5_kt_cursor *cursor) +-{ +- free(*cursor); +- return krb5_ktsrvint_close(context, id); +-} +- +-/* +- * krb5_kts_ops +- */ +- +-const struct _krb5_kt_ops krb5_kts_ops = { +- 0, +- "SRVTAB", /* Prefix -- this string should not appear anywhere else! */ +- krb5_ktsrvtab_resolve, +- krb5_ktsrvtab_get_name, +- krb5_ktsrvtab_close, +- krb5_ktsrvtab_get_entry, +- krb5_ktsrvtab_start_seq_get, +- krb5_ktsrvtab_get_next, +- krb5_ktsrvtab_end_get, +- 0, +- 0, +- 0 +-}; +- +-/* formerly: lib/krb5/keytab/srvtab/kts_util.c */ +- +-#include +- +-/* The maximum sizes for V4 aname, realm, sname, and instance +1 */ +-/* Taken from krb.h */ +-#define ANAME_SZ 40 +-#define REALM_SZ 40 +-#define SNAME_SZ 40 +-#define INST_SZ 40 +- +-static krb5_error_code +-read_field(FILE *fp, char *s, int len) +-{ +- int c; +- +- while ((c = getc(fp)) != 0) { +- if (c == EOF || len <= 1) +- return KRB5_KT_END; +- *s = c; +- s++; +- len--; +- } +- *s = 0; +- return 0; +-} +- +-krb5_error_code +-krb5_ktsrvint_open(krb5_context context, krb5_keytab id) +-{ +- KTFILEP(id) = fopen(KTFILENAME(id), "rb"); +- if (!KTFILEP(id)) +- return errno; +- set_cloexec_file(KTFILEP(id)); +- return 0; +-} +- +-krb5_error_code +-krb5_ktsrvint_close(krb5_context context, krb5_keytab id) +-{ +- if (!KTFILEP(id)) +- return 0; +- (void) fclose(KTFILEP(id)); +- KTFILEP(id) = 0; +- return 0; +-} +- +-krb5_error_code +-krb5_ktsrvint_read_entry(krb5_context context, krb5_keytab id, krb5_keytab_entry *ret_entry) +-{ +- FILE *fp; +- char name[SNAME_SZ], instance[INST_SZ], realm[REALM_SZ]; +- unsigned char key[8]; +- int vno; +- krb5_error_code kerror; +- +- /* Read in an entry from the srvtab file. */ +- fp = KTFILEP(id); +- kerror = read_field(fp, name, sizeof(name)); +- if (kerror != 0) +- return kerror; +- kerror = read_field(fp, instance, sizeof(instance)); +- if (kerror != 0) +- return kerror; +- kerror = read_field(fp, realm, sizeof(realm)); +- if (kerror != 0) +- return kerror; +- vno = getc(fp); +- if (vno == EOF) +- return KRB5_KT_END; +- if (fread(key, 1, sizeof(key), fp) != sizeof(key)) +- return KRB5_KT_END; +- +- /* Fill in ret_entry with the data we read. Everything maps well +- * except for the timestamp, which we don't have a value for. For +- * now we just set it to 0. */ +- memset(ret_entry, 0, sizeof(*ret_entry)); +- ret_entry->magic = KV5M_KEYTAB_ENTRY; +- kerror = krb5_425_conv_principal(context, name, instance, realm, +- &ret_entry->principal); +- if (kerror != 0) +- return kerror; +- ret_entry->vno = vno; +- ret_entry->timestamp = 0; +- ret_entry->key.enctype = ENCTYPE_DES_CBC_CRC; +- ret_entry->key.magic = KV5M_KEYBLOCK; +- ret_entry->key.length = sizeof(key); +- ret_entry->key.contents = k5memdup(key, sizeof(key), &kerror); +- if (ret_entry->key.contents == NULL) { +- krb5_free_principal(context, ret_entry->principal); +- return kerror; +- } +- +- return 0; +-} +-#endif /* LEAN_CLIENT */ +diff --git a/src/lib/krb5/keytab/ktbase.c b/src/lib/krb5/keytab/ktbase.c +index 0d39b2940..25752245a 100644 +--- a/src/lib/krb5/keytab/ktbase.c ++++ b/src/lib/krb5/keytab/ktbase.c +@@ -55,20 +55,15 @@ + + extern const krb5_kt_ops krb5_ktf_ops; + extern const krb5_kt_ops krb5_ktf_writable_ops; +-extern const krb5_kt_ops krb5_kts_ops; + extern const krb5_kt_ops krb5_mkt_ops; + + struct krb5_kt_typelist { + const krb5_kt_ops *ops; + const struct krb5_kt_typelist *next; + }; +-const static struct krb5_kt_typelist krb5_kt_typelist_srvtab = { +- &krb5_kts_ops, +- NULL +-}; + const static struct krb5_kt_typelist krb5_kt_typelist_memory = { + &krb5_mkt_ops, +- &krb5_kt_typelist_srvtab ++ NULL + }; + const static struct krb5_kt_typelist krb5_kt_typelist_wrfile = { + &krb5_ktf_writable_ops, +diff --git a/src/lib/krb5/krb/in_tkt_sky.c b/src/lib/krb5/krb/in_tkt_sky.c +index 7a8922623..342fe18dc 100644 +--- a/src/lib/krb5/krb/in_tkt_sky.c ++++ b/src/lib/krb5/krb/in_tkt_sky.c +@@ -56,9 +56,9 @@ get_as_key_skey(krb5_context context, krb5_principal client, + If addrs is non-NULL, it is used for the addresses requested. If it is + null, the system standard addresses are used. + +- If keyblock is NULL, an appropriate key for creds->client is retrieved +- from the system key store (e.g. /etc/srvtab). If keyblock is non-NULL, +- it is used as the decryption key. ++ If keyblock is NULL, an appropriate key for creds->client is retrieved from ++ the system key store (e.g. /etc/krb5.keytab). If keyblock is non-NULL, it ++ is used as the decryption key. + + A succesful call will place the ticket in the credentials cache ccache. + +diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports +index dfdb72daf..038e4de4b 100644 +--- a/src/lib/krb5/libkrb5.exports ++++ b/src/lib/krb5/libkrb5.exports +@@ -459,7 +459,6 @@ krb5_kt_resolve + krb5_kt_start_seq_get + krb5_ktf_ops + krb5_ktf_writable_ops +-krb5_kts_ops + krb5_kuserok + krb5_lock_file + krb5_make_authdata_kdc_issued +diff --git a/src/lib/rpc/unit-test/Makefile.in b/src/lib/rpc/unit-test/Makefile.in +index 6f29e33c9..46f2f1d4b 100644 +--- a/src/lib/rpc/unit-test/Makefile.in ++++ b/src/lib/rpc/unit-test/Makefile.in +@@ -45,8 +45,8 @@ PASS=@PASS@ + unit-test-body: + $(RM) krb5cc_rpc_test_* + $(ENV_SETUP) $(VALGRIND) $(START_SERVERS) +- RPC_TEST_SRVTAB=/tmp/rpc_test_v5srvtab.$$$$ ; export RPC_TEST_SRVTAB ; \ +- trap "echo Failed, cleaning up... ; rm -f $$RPC_TEST_SRVTAB ; $(ENV_SETUP) $(STOP_SERVERS) ; trap '' 0 ; exit 1" 0 1 2 3 14 15 ; \ ++ RPC_TEST_KEYTAB=/tmp/rpc_test_keytab.$$$$ ; export RPC_TEST_KEYTAB ; \ ++ trap "echo Failed, cleaning up... ; rm -f $$RPC_TEST_KEYTAB ; $(ENV_SETUP) $(STOP_SERVERS) ; trap '' 0 ; exit 1" 0 1 2 3 14 15 ; \ + if $(ENV_SETUP) \ + $(RUNTEST) SERVER=./server CLIENT=./client \ + KINIT=$(BUILDTOP)/clients/kinit/kinit \ +@@ -55,7 +55,7 @@ unit-test-body: + PASS="$(PASS)" --tool rpc_test $(RUNTESTFLAGS) ; \ + then \ + echo Cleaning up... ; \ +- rm -f $$RPC_TEST_SRVTAB krb5cc_rpc_test_* ; \ ++ rm -f $$RPC_TEST_KEYTAB krb5cc_rpc_test_* ; \ + $(ENV_SETUP) $(STOP_SERVERS) ; \ + trap 0 ; exit 0 ; \ + else exit 1 ; fi +diff --git a/src/lib/rpc/unit-test/config/unix.exp b/src/lib/rpc/unit-test/config/unix.exp +index ba57b703e..ed179bbe3 100644 +--- a/src/lib/rpc/unit-test/config/unix.exp ++++ b/src/lib/rpc/unit-test/config/unix.exp +@@ -139,7 +139,7 @@ proc rpc_test_start { } { + + if [info exists server_pid] { rpc_test_exit } + +- set env(KRB5_KTNAME) FILE:$env(RPC_TEST_SRVTAB) ++ set env(KRB5_KTNAME) FILE:$env(RPC_TEST_KEYTAB) + + verbose "% $SERVER" 1 + set server_pid [spawn $SERVER $PROT] +diff --git a/src/lib/rpc/unit-test/lib/helpers.exp b/src/lib/rpc/unit-test/lib/helpers.exp +index a1b078374..6ba2b10ae 100644 +--- a/src/lib/rpc/unit-test/lib/helpers.exp ++++ b/src/lib/rpc/unit-test/lib/helpers.exp +@@ -121,8 +121,8 @@ proc setup_database {} { + if ![info exists CANON_HOST] { + set CANON_HOST [exec $env(QUALNAME)] + setup_database +- file delete $env(RPC_TEST_SRVTAB) +- exec $env(MAKE_KEYTAB) -princ "server/$CANON_HOST" $env(RPC_TEST_SRVTAB) ++ file delete $env(RPC_TEST_KEYTAB) ++ exec $env(MAKE_KEYTAB) -princ "server/$CANON_HOST" $env(RPC_TEST_KEYTAB) + } + + +diff --git a/src/lib/rpc/unit-test/rpc_test_setup.sh b/src/lib/rpc/unit-test/rpc_test_setup.sh +index 968f52a67..b610f87ef 100755 +--- a/src/lib/rpc/unit-test/rpc_test_setup.sh ++++ b/src/lib/rpc/unit-test/rpc_test_setup.sh +@@ -1,7 +1,7 @@ + #!/bin/sh + # + # This script performs additional setup for the RPC unit test. It +-# assumes that gmake has put TOP and RPC_TEST_SRVTAB into the ++# assumes that gmake has put TOP and RPC_TEST_KEYTAB into the + # environment. + # + # $Id$ +@@ -42,9 +42,9 @@ if test $? != 0 ; then + fi + rm /tmp/rpc_test_setup$$ + +-rm -f $RPC_TEST_SRVTAB ++rm -f $RPC_TEST_KEYTAB + +-eval $MAKE_KEYTAB -princ server/$CANON_HOST $RPC_TEST_SRVTAB $REDIRECT ++eval $MAKE_KEYTAB -princ server/$CANON_HOST $RPC_TEST_KEYTAB $REDIRECT + + # grep -s "$CANON_HOST SECURE-TEST.OV.COM" /etc/krb.realms + # if [ $? != 0 ]; then +diff --git a/src/man/ktutil.man b/src/man/ktutil.man +index 4e174c0fe..233329468 100644 +--- a/src/man/ktutil.man ++++ b/src/man/ktutil.man +@@ -1,6 +1,6 @@ + .\" Man page generated from reStructuredText. + . +-.TH "KTUTIL" "1" " " "1.17" "MIT Kerberos" ++.TH "KTUTIL" "1" " " "1.18" "MIT Kerberos" + .SH NAME + ktutil \- Kerberos keytab file maintenance utility + . +@@ -36,8 +36,8 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]] + .SH DESCRIPTION + .sp + The ktutil command invokes a command interface from which an +-administrator can read, write, or edit entries in a keytab or Kerberos +-V4 srvtab file. ++administrator can read, write, or edit entries in a keytab. (Kerberos ++V4 srvtab files are no longer supported.) + .SH COMMANDS + .SS list + .INDENT 0.0 +@@ -59,16 +59,6 @@ Alias: \fBl\fP + Read the Kerberos V5 keytab file \fIkeytab\fP into the current keylist. + .sp + Alias: \fBrkt\fP +-.SS read_st +-.INDENT 0.0 +-.INDENT 3.5 +-\fBread_st\fP \fIsrvtab\fP +-.UNINDENT +-.UNINDENT +-.sp +-Read the Kerberos V4 srvtab file \fIsrvtab\fP into the current keylist. +-.sp +-Alias: \fBrst\fP + .SS write_kt + .INDENT 0.0 + .INDENT 3.5 +@@ -79,16 +69,6 @@ Alias: \fBrst\fP + Write the current keylist into the Kerberos V5 keytab file \fIkeytab\fP\&. + .sp + Alias: \fBwkt\fP +-.SS write_st +-.INDENT 0.0 +-.INDENT 3.5 +-\fBwrite_st\fP \fIsrvtab\fP +-.UNINDENT +-.UNINDENT +-.sp +-Write the current keylist into the Kerberos V4 srvtab file \fIsrvtab\fP\&. +-.sp +-Alias: \fBwst\fP + .SS clear_list + .INDENT 0.0 + .INDENT 3.5 +diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp +index d7b296516..ea9bedd45 100644 +--- a/src/tests/dejagnu/config/default.exp ++++ b/src/tests/dejagnu/config/default.exp +@@ -440,8 +440,8 @@ proc delete_db {} { + $tmppwd/kdc-db.ulog \ + $tmppwd/replica-db $tmppwd/replica-db.ok $tmppwd/replica-db.kadm5 $tmppwd/replica-db.kadm5.lock \ + $tmppwd/replica-db~ $tmppwd/replica-db~.ok $tmppwd/replica-db~.kadm5 $tmppwd/replica-db~.kadm5.lock +- # Creating a new database means we need a new srvtab. +- file delete $tmppwd/srvtab $tmppwd/cpw_srvtab ++ # Creating a new database means we need a new keytab. ++ file delete $tmppwd/keytab $tmppwd/cpw_keytab + } + + delete_db +@@ -1510,11 +1510,9 @@ proc start_kpropd {} { + + envstack_push + setup_kerberos_env replica +- spawn $KPROPD -S -d -t -P [expr 10 + $portbase] -s $tmppwd/srvtab -f $tmppwd/incoming-replica-datatrans -p $KDB5_UTIL -a $tmppwd/kpropd-acl ++ spawn $KPROPD -S -d -t -P [expr 10 + $portbase] -s $tmppwd/keytab -f $tmppwd/incoming-replica-datatrans -p $KDB5_UTIL -a $tmppwd/kpropd-acl + set kpropd_pid [exp_pid] + set kpropd_spawn_id $spawn_id +-# send_user [list $KPROPD -S -d -P [expr 10 + $portbase] -s $tmppwd/srvtab -f $tmppwd/incoming-replica-datatrans -p $KDB5_UTIL -a $tmppwd/kpropd-acl]\n +-# spawn_shell + envstack_pop + } + +@@ -1859,13 +1857,13 @@ proc add_random_key { kkey standalone } { + } + } + +-# setup_srvtab +-# Set up a srvtab file. start_kerberos_daemons and add_random_key ++# setup_keytab ++# Set up a keytab file. start_kerberos_daemons and add_random_key + # $id/$hostname must be called before this procedure. If the + # argument is non-zero, call pass at relevant points. Returns 1 on + # success, 0 on failure. If the id field is not provided, host is used. + +-proc setup_srvtab { standalone {id host} } { ++proc setup_keytab { standalone {id host} } { + global REALMNAME + global KADMIN_LOCAL + global KEY +@@ -1874,17 +1872,17 @@ proc setup_srvtab { standalone {id host} } { + global spawn_id + global last_service + +- if {!$standalone && [file exists $tmppwd/srvtab] && $last_service == $id} { ++ if {!$standalone && [file exists $tmppwd/keytab] && $last_service == $id} { + return 1 + } + +- file delete $tmppwd/srvtab $tmppwd/srvtab.old ++ file delete $tmppwd/keytab $tmppwd/keytab.old + + if ![get_hostname] { + return 0 + } + +- file delete $hostname-new-srvtab ++ file delete $hostname-new-keytab + + envstack_push + setup_kerberos_env kdc +@@ -1892,40 +1890,40 @@ proc setup_srvtab { standalone {id host} } { + envstack_pop + expect_after { + -re "(.*)\r\nkadmin.local: " { +- fail "kadmin.local srvtab (unmatched output: $expect_out(1,string))" ++ fail "kadmin.local keytab (unmatched output: $expect_out(1,string))" + if {!$standalone} { +- file delete $tmppwd/srvtab ++ file delete $tmppwd/keytab + } + catch "expect_after" + return 0 + } + timeout { +- fail "kadmin.local srvtab" ++ fail "kadmin.local keytab" + if {!$standalone} { +- file delete $tmppwd/srvtab ++ file delete $tmppwd/keytab + } + catch "expect_after" + return 0 + } + eof { +- fail "kadmin.local srvtab" ++ fail "kadmin.local keytab" + if {!$standalone} { +- file delete $tmppwd/srvtab ++ file delete $tmppwd/keytab + } + catch "expect_after" + return 0 + } + } + expect "kadmin.local: " +- send "xst -k $hostname-new-srvtab $id/$hostname kiprop/$hostname\r" +- expect "xst -k $hostname-new-srvtab $id/$hostname kiprop/$hostname\r\n" ++ send "xst -k $hostname-new-keytab $id/$hostname kiprop/$hostname\r" ++ expect "xst -k $hostname-new-keytab $id/$hostname kiprop/$hostname\r\n" + expect { +- -re ".*Entry for principal $id/$hostname.* added to keytab WRFILE:$hostname-new-srvtab." { } ++ -re ".*Entry for principal $id/$hostname.* added to keytab WRFILE:$hostname-new-keytab." { } + -re "\r\nkadmin.local: " { + if {$standalone} { +- fail "kadmin.local srvtab" ++ fail "kadmin.local keytab" + } else { +- file delete $tmppwd/srvtab ++ file delete $tmppwd/keytab + } + catch expect_after + return 0 +@@ -1935,27 +1933,27 @@ proc setup_srvtab { standalone {id host} } { + send "quit\r" + expect eof + catch expect_after +- if ![check_exit_status "kadmin.local srvtab"] { ++ if ![check_exit_status "kadmin.local keytab"] { + if {!$standalone} { +- file delete $tmppwd/srvtab ++ file delete $tmppwd/keytab + } + return 0 + } + +- catch "exec mv -f $hostname-new-srvtab $tmppwd/srvtab" exec_output ++ catch "exec mv -f $hostname-new-keytab $tmppwd/keytab" exec_output + if ![string match "" $exec_output] { + verbose -log "$exec_output" +- perror "can't mv new srvtab" ++ perror "can't mv new keytab" + return 0 + } + + if {$standalone} { +- pass "kadmin.local srvtab" ++ pass "kadmin.local keytab" + } + +- # Make the srvtab file globally readable in case we are using a +- # root shell and the srvtab is NFS mounted. +- catch "exec chmod a+r $tmppwd/srvtab" ++ # Make the keytab file globally readable in case we are using a ++ # root shell and the keytab is NFS mounted. ++ catch "exec chmod a+r $tmppwd/keytab" + + # Remember what we just extracted + set last_service $id +diff --git a/src/tests/dejagnu/krb-standalone/gssapi.exp b/src/tests/dejagnu/krb-standalone/gssapi.exp +index 582e08719..e3357e769 100644 +--- a/src/tests/dejagnu/krb-standalone/gssapi.exp ++++ b/src/tests/dejagnu/krb-standalone/gssapi.exp +@@ -238,9 +238,9 @@ proc doit { } { + perror "failed to set up gssservice/$hostname key" + } + +- # Use kdb5_edit to create a srvtab entry for gssservice +- if ![setup_srvtab 0 gssservice] { +- perror "failed to set up gssservice srvtab" ++ # Use kdb5_edit to create a keytab entry for gssservice ++ if ![setup_keytab 0 gssservice] { ++ perror "failed to set up gssservice keytab" + } + + catch "exec rm -f $tmppwd/gss_tk_0 $tmppwd/gss_tk_1 $tmppwd/gss_tk_2 $tmppwd/gss_tk_3" +@@ -278,7 +278,7 @@ proc doit { } { + # + # set KRB5CCNAME and KRB5_KTNAME + # +- set env(KRB5_KTNAME) FILE:$tmppwd/srvtab ++ set env(KRB5_KTNAME) FILE:$tmppwd/keytab + verbose "KRB5_KTNAME=$env(KRB5_KTNAME)" + + # Now start the gss-server. +diff --git a/src/tests/dejagnu/krb-standalone/kadmin.exp b/src/tests/dejagnu/krb-standalone/kadmin.exp +index 33fc34a7b..36a345258 100644 +--- a/src/tests/dejagnu/krb-standalone/kadmin.exp ++++ b/src/tests/dejagnu/krb-standalone/kadmin.exp +@@ -457,62 +457,16 @@ proc kadmin_extract { instance name } { + expect -re "assword\[^\r\n\]*: *" { + send "adminpass$KEY\r" + } +-# expect -re "kadmin: Entry for principal $name/$instance with kvno [0-9], encryption type .* added to keytab WRFILE:$tmppwd/keytab." + expect_after + expect eof + set k_stat [wait -i $spawn_id] + verbose "wait -i $spawn_id returned $k_stat (kadmin xst)" + catch "close -i $spawn_id" +- catch "exec rm -f $instance-new-srvtab" ++ catch "exec rm -f $instance-new-keytab" + pass "kadmin xst $instance $name" + return 1 + } + +-#++ +-# kadmin_extractv4 - Test extract service key in v4 format function of +-# kadmin. +-# +-# Extracts service key for service name $name instance $instance in version +-# 4 format. Returns 1 on success. +-#-- +-#proc kadmin_extractv4 { instance name } { +-# global REALMNAME +-# global KADMIN +-# global KEY +-# global spawn_id +-# +-# spawn $KADMIN -p krbtest/admin@$REALMNAME -q "xst4 $instance $name" +-# expect_after { +-# "Cannot contact any KDC" { +-# fail "kadmin xst4 $instance $name lost KDC" +-# catch "expect_after" +-# return 0 +-# } +-# timeout { +-# fail "kadmin xst4 $instance $name" +-# catch "expect_after" +-# return 0 +-# } +-# eof { +-# fail "kadmin xst4 $instance $name" +-# catch "expect_after" +-# return 0 +-# } +-# } +-# expect -re "assword\[^\r\n\]*: *" { +-# send "adminpass$KEY\r" +-# } +-# expect "extracted entry $name to key table $instance-new-v4-srvtab" +-# expect_after +-# expect eof +-# set k_stat [wait -i $spawn_id] +-# verbose "wait -i $spawn_id returned $k_stat (kadmin xst4)" +-# catch "close -i $spawn_id" +-# catch "exec rm -f $instance-new-v4-srvtab" +-# pass "kadmin xst4 $instance $name" +-# return 1 +-#} +- + #++ + # kadmin_delete - Test delete principal function of kadmin. + # +diff --git a/src/tests/dejagnu/krb-standalone/kprop.exp b/src/tests/dejagnu/krb-standalone/kprop.exp +index 2221a65e4..f71ee8638 100644 +--- a/src/tests/dejagnu/krb-standalone/kprop.exp ++++ b/src/tests/dejagnu/krb-standalone/kprop.exp +@@ -72,8 +72,8 @@ proc doit { } { + fail "kprop (host key)" + return + } +- if ![setup_srvtab 0] { +- fail "kprop (srvtab)" ++ if ![setup_keytab 0] { ++ fail "kprop (keytab)" + return + } + +@@ -99,7 +99,7 @@ proc doit { } { + sleep 1 + + # Try a propagation. +- spawn $KPROP -f $tmppwd/replica_datatrans -P [expr 10 + $portbase] -s $tmppwd/srvtab $hostname ++ spawn $KPROP -f $tmppwd/replica_datatrans -P [expr 10 + $portbase] -s $tmppwd/keytab $hostname + expect eof + set kprop_exit [check_exit_status "kprop (exit status)"] + # log output for debugging +diff --git a/src/tests/dejagnu/krb-standalone/sample.exp b/src/tests/dejagnu/krb-standalone/sample.exp +index 326f1848d..93a75f1d0 100644 +--- a/src/tests/dejagnu/krb-standalone/sample.exp ++++ b/src/tests/dejagnu/krb-standalone/sample.exp +@@ -42,7 +42,7 @@ proc start_sserver_daemon { inetd } { + # if inetd = 0, then we are running stand-alone + if !{$inetd} { + # Start the sserver +- spawn $SSERVER -p [expr 8 + $portbase] -S $tmppwd/srvtab ++ spawn $SSERVER -p [expr 8 + $portbase] -S $tmppwd/keytab + set sserver_pid [exp_pid] + set sserver_spawn_id $spawn_id + +@@ -52,7 +52,7 @@ proc start_sserver_daemon { inetd } { + sleep 2 + } else { + # Start the sserver +- spawn $T_INETD [expr 8 + $portbase] $SSERVER sserver -S $tmppwd/srvtab ++ spawn $T_INETD [expr 8 + $portbase] $SSERVER sserver -S $tmppwd/keytab + set sserver_pid [exp_pid] + set sserver_spawn_id $spawn_id + +@@ -166,8 +166,8 @@ proc doit { } { + return + } + +- # Use ksrvutil to create a srvtab entry for sample +- if ![setup_srvtab 1 sample] { ++ # Use ksrvutil to create a keytab entry for sample ++ if ![setup_keytab 1 sample] { + return + } + +diff --git a/src/tests/dejagnu/krb-standalone/simple.exp b/src/tests/dejagnu/krb-standalone/simple.exp +index fa749035f..d8b218248 100644 +--- a/src/tests/dejagnu/krb-standalone/simple.exp ++++ b/src/tests/dejagnu/krb-standalone/simple.exp +@@ -40,7 +40,7 @@ proc start_sim_server_daemon { } { + global portbase + + # Start the sim_server +- spawn $SIM_SERVER -p [expr 8 + $portbase] -S $tmppwd/srvtab ++ spawn $SIM_SERVER -p [expr 8 + $portbase] -S $tmppwd/keytab + set sim_server_pid [exp_pid] + set sim_server_spawn_id $spawn_id + +@@ -179,8 +179,8 @@ proc doit { } { + return + } + +- # Use ksrvutil to create a srvtab entry for sample +- if ![setup_srvtab 1 sample] { ++ # Use ksrvutil to create a keytab entry for sample ++ if ![setup_keytab 1 sample] { + return + } + +diff --git a/src/tests/dejagnu/krb-standalone/standalone.exp b/src/tests/dejagnu/krb-standalone/standalone.exp +index 5b5970fba..d284297e8 100644 +--- a/src/tests/dejagnu/krb-standalone/standalone.exp ++++ b/src/tests/dejagnu/krb-standalone/standalone.exp +@@ -166,8 +166,8 @@ proc doit { } { + verbose "wait -i $spawn_id returned $k_stat (kadmin addpol)" + catch "close -i $spawn_id" + +- # Use ksrvutil to create a srvtab entry. +- if ![setup_srvtab 1] { ++ # Use ksrvutil to create a keytab entry. ++ if ![setup_keytab 1] { + return + } + +diff --git a/src/tests/dejagnu/krb-standalone/tcp.exp b/src/tests/dejagnu/krb-standalone/tcp.exp +index db09b895e..df3195bb6 100644 +--- a/src/tests/dejagnu/krb-standalone/tcp.exp ++++ b/src/tests/dejagnu/krb-standalone/tcp.exp +@@ -33,11 +33,6 @@ proc doit { } { + return + } + +- # Use ksrvutil to create a srvtab entry. +-# if ![setup_srvtab 1] { +-# return +-# } +- + # Use kinit to get a ticket. + if ![kinit krbtest/admin adminpass$KEY 1] { + return diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch index 0a9fff6..ccb92aa 100644 --- a/krb5-1.11-kpasswdtest.patch +++ b/krb5-1.11-kpasswdtest.patch @@ -1,4 +1,4 @@ -From d4035585df4b3132d1897067d6c452cc06aa16dd Mon Sep 17 00:00:00 2001 +From 1da0d2fdbd9cb2ded1913e05664986dce1e1a916 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:52:01 -0400 Subject: [PATCH] krb5-1.11-kpasswdtest.patch diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch index 705af96..196944e 100644 --- a/krb5-1.11-run_user_0.patch +++ b/krb5-1.11-run_user_0.patch @@ -1,4 +1,4 @@ -From 3d09297c65f27033cce8abbab2e50716abdae48f Mon Sep 17 00:00:00 2001 +From c95d33cc1c66122bc229beb65d36f988fbd05e59 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:57 -0400 Subject: [PATCH] krb5-1.11-run_user_0.patch diff --git a/krb5-1.12-api.patch b/krb5-1.12-api.patch index 159ad57..b49cea6 100644 --- a/krb5-1.12-api.patch +++ b/krb5-1.12-api.patch @@ -1,4 +1,4 @@ -From f267d34d0dea6778c700036b89156fc17ca506e9 Mon Sep 17 00:00:00 2001 +From 4ddac573dfc8fea30b5f8750c8c0733c553afcfa Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:00 -0400 Subject: [PATCH] krb5-1.12-api.patch diff --git a/krb5-1.12-ktany.patch b/krb5-1.12-ktany.patch deleted file mode 100644 index 8049432..0000000 --- a/krb5-1.12-ktany.patch +++ /dev/null @@ -1,366 +0,0 @@ -From c93c099e3d3e0a78393e7445fe17d58cf1abc666 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:33:53 -0400 -Subject: [PATCH] krb5-1.12-ktany.patch - -Adds an "ANY" keytab type which is a list of other keytab locations to search -when searching for a specific entry. When iterated through, it only presents -the contents of the first keytab. ---- - src/lib/krb5/keytab/Makefile.in | 3 + - src/lib/krb5/keytab/kt_any.c | 292 ++++++++++++++++++++++++++++++++ - src/lib/krb5/keytab/ktbase.c | 7 +- - 3 files changed, 301 insertions(+), 1 deletion(-) - create mode 100644 src/lib/krb5/keytab/kt_any.c - -diff --git a/src/lib/krb5/keytab/Makefile.in b/src/lib/krb5/keytab/Makefile.in -index 2a8fceb00..ffd179fb2 100644 ---- a/src/lib/krb5/keytab/Makefile.in -+++ b/src/lib/krb5/keytab/Makefile.in -@@ -12,6 +12,7 @@ STLIBOBJS= \ - ktfr_entry.o \ - ktremove.o \ - ktfns.o \ -+ kt_any.o \ - kt_file.o \ - kt_memory.o \ - kt_srvtab.o \ -@@ -24,6 +25,7 @@ OBJS= \ - $(OUTPRE)ktfr_entry.$(OBJEXT) \ - $(OUTPRE)ktremove.$(OBJEXT) \ - $(OUTPRE)ktfns.$(OBJEXT) \ -+ $(OUTPRE)kt_any.$(OBJEXT) \ - $(OUTPRE)kt_file.$(OBJEXT) \ - $(OUTPRE)kt_memory.$(OBJEXT) \ - $(OUTPRE)kt_srvtab.$(OBJEXT) \ -@@ -36,6 +38,7 @@ SRCS= \ - $(srcdir)/ktfr_entry.c \ - $(srcdir)/ktremove.c \ - $(srcdir)/ktfns.c \ -+ $(srcdir)/kt_any.c \ - $(srcdir)/kt_file.c \ - $(srcdir)/kt_memory.c \ - $(srcdir)/kt_srvtab.c \ -diff --git a/src/lib/krb5/keytab/kt_any.c b/src/lib/krb5/keytab/kt_any.c -new file mode 100644 -index 000000000..1b9b7765b ---- /dev/null -+++ b/src/lib/krb5/keytab/kt_any.c -@@ -0,0 +1,292 @@ -+/* -+ * lib/krb5/keytab/kt_any.c -+ * -+ * Copyright 1998, 1999 by the Massachusetts Institute of Technology. -+ * All Rights Reserved. -+ * -+ * Export of this software from the United States of America may -+ * require a specific license from the United States Government. -+ * It is the responsibility of any person or organization contemplating -+ * export to obtain such a license before exporting. -+ * -+ * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -+ * distribute this software and its documentation for any purpose and -+ * without fee is hereby granted, provided that the above copyright -+ * notice appear in all copies and that both that copyright notice and -+ * this permission notice appear in supporting documentation, and that -+ * the name of M.I.T. not be used in advertising or publicity pertaining -+ * to distribution of the software without specific, written prior -+ * permission. M.I.T. makes no representations about the suitability of -+ * this software for any purpose. It is provided "as is" without express -+ * or implied warranty. -+ * -+ * -+ * krb5_kta_ops -+ */ -+ -+#include "k5-int.h" -+ -+typedef struct _krb5_ktany_data { -+ char *name; -+ krb5_keytab *choices; -+ int nchoices; -+} krb5_ktany_data; -+ -+typedef struct _krb5_ktany_cursor_data { -+ int which; -+ krb5_kt_cursor cursor; -+} krb5_ktany_cursor_data; -+ -+static krb5_error_code krb5_ktany_resolve -+ (krb5_context, -+ const char *, -+ krb5_keytab *); -+static krb5_error_code krb5_ktany_get_name -+ (krb5_context context, -+ krb5_keytab id, -+ char *name, -+ unsigned int len); -+static krb5_error_code krb5_ktany_close -+ (krb5_context context, -+ krb5_keytab id); -+static krb5_error_code krb5_ktany_get_entry -+ (krb5_context context, -+ krb5_keytab id, -+ krb5_const_principal principal, -+ krb5_kvno kvno, -+ krb5_enctype enctype, -+ krb5_keytab_entry *entry); -+static krb5_error_code krb5_ktany_start_seq_get -+ (krb5_context context, -+ krb5_keytab id, -+ krb5_kt_cursor *cursorp); -+static krb5_error_code krb5_ktany_next_entry -+ (krb5_context context, -+ krb5_keytab id, -+ krb5_keytab_entry *entry, -+ krb5_kt_cursor *cursor); -+static krb5_error_code krb5_ktany_end_seq_get -+ (krb5_context context, -+ krb5_keytab id, -+ krb5_kt_cursor *cursor); -+static void cleanup -+ (krb5_context context, -+ krb5_ktany_data *data, -+ int nchoices); -+ -+struct _krb5_kt_ops krb5_kta_ops = { -+ 0, -+ "ANY", /* Prefix -- this string should not appear anywhere else! */ -+ krb5_ktany_resolve, -+ krb5_ktany_get_name, -+ krb5_ktany_close, -+ krb5_ktany_get_entry, -+ krb5_ktany_start_seq_get, -+ krb5_ktany_next_entry, -+ krb5_ktany_end_seq_get, -+ NULL, -+ NULL, -+ NULL, -+}; -+ -+static krb5_error_code -+krb5_ktany_resolve(context, name, id) -+ krb5_context context; -+ const char *name; -+ krb5_keytab *id; -+{ -+ const char *p, *q; -+ char *copy; -+ krb5_error_code kerror; -+ krb5_ktany_data *data; -+ int i; -+ -+ /* Allocate space for our data and remember a copy of the name. */ -+ if ((data = (krb5_ktany_data *)malloc(sizeof(krb5_ktany_data))) == NULL) -+ return(ENOMEM); -+ if ((data->name = (char *)malloc(strlen(name) + 1)) == NULL) { -+ free(data); -+ return(ENOMEM); -+ } -+ strcpy(data->name, name); -+ -+ /* Count the number of choices and allocate memory for them. */ -+ data->nchoices = 1; -+ for (p = name; (q = strchr(p, ',')) != NULL; p = q + 1) -+ data->nchoices++; -+ if ((data->choices = (krb5_keytab *) -+ malloc(data->nchoices * sizeof(krb5_keytab))) == NULL) { -+ free(data->name); -+ free(data); -+ return(ENOMEM); -+ } -+ -+ /* Resolve each of the choices. */ -+ i = 0; -+ for (p = name; (q = strchr(p, ',')) != NULL; p = q + 1) { -+ /* Make a copy of the choice name so we can terminate it. */ -+ if ((copy = (char *)malloc(q - p + 1)) == NULL) { -+ cleanup(context, data, i); -+ return(ENOMEM); -+ } -+ memcpy(copy, p, q - p); -+ copy[q - p] = 0; -+ -+ /* Try resolving the choice name. */ -+ kerror = krb5_kt_resolve(context, copy, &data->choices[i]); -+ free(copy); -+ if (kerror) { -+ cleanup(context, data, i); -+ return(kerror); -+ } -+ i++; -+ } -+ if ((kerror = krb5_kt_resolve(context, p, &data->choices[i]))) { -+ cleanup(context, data, i); -+ return(kerror); -+ } -+ -+ /* Allocate and fill in an ID for the caller. */ -+ if ((*id = (krb5_keytab)malloc(sizeof(**id))) == NULL) { -+ cleanup(context, data, i); -+ return(ENOMEM); -+ } -+ (*id)->ops = &krb5_kta_ops; -+ (*id)->data = (krb5_pointer)data; -+ (*id)->magic = KV5M_KEYTAB; -+ -+ return(0); -+} -+ -+static krb5_error_code -+krb5_ktany_get_name(context, id, name, len) -+ krb5_context context; -+ krb5_keytab id; -+ char *name; -+ unsigned int len; -+{ -+ krb5_ktany_data *data = (krb5_ktany_data *)id->data; -+ -+ if (len < strlen(data->name) + 1) -+ return(KRB5_KT_NAME_TOOLONG); -+ strcpy(name, data->name); -+ return(0); -+} -+ -+static krb5_error_code -+krb5_ktany_close(context, id) -+ krb5_context context; -+ krb5_keytab id; -+{ -+ krb5_ktany_data *data = (krb5_ktany_data *)id->data; -+ -+ cleanup(context, data, data->nchoices); -+ id->ops = 0; -+ free(id); -+ return(0); -+} -+ -+static krb5_error_code -+krb5_ktany_get_entry(context, id, principal, kvno, enctype, entry) -+ krb5_context context; -+ krb5_keytab id; -+ krb5_const_principal principal; -+ krb5_kvno kvno; -+ krb5_enctype enctype; -+ krb5_keytab_entry *entry; -+{ -+ krb5_ktany_data *data = (krb5_ktany_data *)id->data; -+ krb5_error_code kerror = KRB5_KT_NOTFOUND; -+ int i; -+ -+ for (i = 0; i < data->nchoices; i++) { -+ if ((kerror = krb5_kt_get_entry(context, data->choices[i], principal, -+ kvno, enctype, entry)) != ENOENT) -+ return kerror; -+ } -+ return kerror; -+} -+ -+static krb5_error_code -+krb5_ktany_start_seq_get(context, id, cursorp) -+ krb5_context context; -+ krb5_keytab id; -+ krb5_kt_cursor *cursorp; -+{ -+ krb5_ktany_data *data = (krb5_ktany_data *)id->data; -+ krb5_ktany_cursor_data *cdata; -+ krb5_error_code kerror = ENOENT; -+ int i; -+ -+ if ((cdata = (krb5_ktany_cursor_data *) -+ malloc(sizeof(krb5_ktany_cursor_data))) == NULL) -+ return(ENOMEM); -+ -+ /* Find a choice which can handle the serialization request. */ -+ for (i = 0; i < data->nchoices; i++) { -+ if ((kerror = krb5_kt_start_seq_get(context, data->choices[i], -+ &cdata->cursor)) == 0) -+ break; -+ else if (kerror != ENOENT) { -+ free(cdata); -+ return(kerror); -+ } -+ } -+ -+ if (i == data->nchoices) { -+ /* Everyone returned ENOENT, so no go. */ -+ free(cdata); -+ return(kerror); -+ } -+ -+ cdata->which = i; -+ *cursorp = (krb5_kt_cursor)cdata; -+ return(0); -+} -+ -+static krb5_error_code -+krb5_ktany_next_entry(context, id, entry, cursor) -+ krb5_context context; -+ krb5_keytab id; -+ krb5_keytab_entry *entry; -+ krb5_kt_cursor *cursor; -+{ -+ krb5_ktany_data *data = (krb5_ktany_data *)id->data; -+ krb5_ktany_cursor_data *cdata = (krb5_ktany_cursor_data *)*cursor; -+ krb5_keytab choice_id; -+ -+ choice_id = data->choices[cdata->which]; -+ return(krb5_kt_next_entry(context, choice_id, entry, &cdata->cursor)); -+} -+ -+static krb5_error_code -+krb5_ktany_end_seq_get(context, id, cursor) -+ krb5_context context; -+ krb5_keytab id; -+ krb5_kt_cursor *cursor; -+{ -+ krb5_ktany_data *data = (krb5_ktany_data *)id->data; -+ krb5_ktany_cursor_data *cdata = (krb5_ktany_cursor_data *)*cursor; -+ krb5_keytab choice_id; -+ krb5_error_code kerror; -+ -+ choice_id = data->choices[cdata->which]; -+ kerror = krb5_kt_end_seq_get(context, choice_id, &cdata->cursor); -+ free(cdata); -+ return(kerror); -+} -+ -+static void -+cleanup(context, data, nchoices) -+ krb5_context context; -+ krb5_ktany_data *data; -+ int nchoices; -+{ -+ int i; -+ -+ free(data->name); -+ for (i = 0; i < nchoices; i++) -+ krb5_kt_close(context, data->choices[i]); -+ free(data->choices); -+ free(data); -+} -diff --git a/src/lib/krb5/keytab/ktbase.c b/src/lib/krb5/keytab/ktbase.c -index 0d39b2940..6534d7c52 100644 ---- a/src/lib/krb5/keytab/ktbase.c -+++ b/src/lib/krb5/keytab/ktbase.c -@@ -57,14 +57,19 @@ extern const krb5_kt_ops krb5_ktf_ops; - extern const krb5_kt_ops krb5_ktf_writable_ops; - extern const krb5_kt_ops krb5_kts_ops; - extern const krb5_kt_ops krb5_mkt_ops; -+extern const krb5_kt_ops krb5_kta_ops; - - struct krb5_kt_typelist { - const krb5_kt_ops *ops; - const struct krb5_kt_typelist *next; - }; -+static struct krb5_kt_typelist krb5_kt_typelist_any = { -+ &krb5_kta_ops, -+ NULL -+}; - const static struct krb5_kt_typelist krb5_kt_typelist_srvtab = { - &krb5_kts_ops, -- NULL -+ &krb5_kt_typelist_any - }; - const static struct krb5_kt_typelist krb5_kt_typelist_memory = { - &krb5_mkt_ops, diff --git a/krb5-1.13-dirsrv-accountlock.patch b/krb5-1.13-dirsrv-accountlock.patch index 7faa245..56500af 100644 --- a/krb5-1.13-dirsrv-accountlock.patch +++ b/krb5-1.13-dirsrv-accountlock.patch @@ -1,4 +1,4 @@ -From 3da19a991cce8861c092ed1341d9cd7837b2f6f7 Mon Sep 17 00:00:00 2001 +From 10f64f13ee3d44a31bcdc124e9ce721bc17b3e00 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:44 -0400 Subject: [PATCH] krb5-1.13-dirsrv-accountlock.patch diff --git a/krb5-1.15-beta1-buildconf.patch b/krb5-1.15-beta1-buildconf.patch index 5725758..ad1f7e9 100644 --- a/krb5-1.15-beta1-buildconf.patch +++ b/krb5-1.15-beta1-buildconf.patch @@ -1,4 +1,4 @@ -From 7b457b5b4130208745b8c592e53e42c10f356e27 Mon Sep 17 00:00:00 2001 +From fd8c1f7e68fd999c07ca47243ef85ac726f775ce Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] krb5-1.15-beta1-buildconf.patch diff --git a/Become-FIPS-aware-with-3DES.patch b/krb5-1.17-Become-FIPS-aware.patch similarity index 98% rename from Become-FIPS-aware-with-3DES.patch rename to krb5-1.17-Become-FIPS-aware.patch index 8bf76c1..b67f95c 100644 --- a/Become-FIPS-aware-with-3DES.patch +++ b/krb5-1.17-Become-FIPS-aware.patch @@ -1,7 +1,7 @@ -From 9f5fbf191d74cae9b28d318fff4c80d3d3e49c86 Mon Sep 17 00:00:00 2001 +From 15c0aec4315cc5cfae864b179848f043e2b100c6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 -Subject: [PATCH] Become FIPS-aware (with 3DES) +Subject: [PATCH] krb5-1.17 Become FIPS-aware A lot of the FIPS error conditions from OpenSSL are incredibly mysterious (at best, things return NULL unexpectedly; at worst, diff --git a/FIPS-aware-SPAKE-group-negotiation.patch b/krb5-1.17-FIPS-aware-SPAKE-group-negotiation.patch similarity index 90% rename from FIPS-aware-SPAKE-group-negotiation.patch rename to krb5-1.17-FIPS-aware-SPAKE-group-negotiation.patch index 6017f4b..a3b72d1 100644 --- a/FIPS-aware-SPAKE-group-negotiation.patch +++ b/krb5-1.17-FIPS-aware-SPAKE-group-negotiation.patch @@ -1,7 +1,7 @@ -From 59269fca96168aa89dc32834d188a54eea8953ac Mon Sep 17 00:00:00 2001 +From e039796a0fbefac03a3fd888aef7d192e7c1437e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 1 Apr 2019 13:13:09 -0400 -Subject: [PATCH] FIPS-aware SPAKE group negotiation +Subject: [PATCH] krb5-1.17 FIPS-aware SPAKE group negotiation --- src/plugins/preauth/spake/groups.c | 8 ++++++++ diff --git a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch b/krb5-1.17-In-FIPS-mode-add-plaintext-fallback-for-RC.patch similarity index 98% rename from In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch rename to krb5-1.17-In-FIPS-mode-add-plaintext-fallback-for-RC.patch index 99acb66..f74faa0 100644 --- a/In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch +++ b/krb5-1.17-In-FIPS-mode-add-plaintext-fallback-for-RC.patch @@ -1,7 +1,8 @@ -From 1382f982a18aec4bc14780b175638d44969ac1d2 Mon Sep 17 00:00:00 2001 +From 105bd2c8be23ab94ba6e0601ee8e531f013389d6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 31 Jul 2018 13:47:26 -0400 -Subject: [PATCH] In FIPS mode, add plaintext fallback for RC4 usages and taint +Subject: [PATCH] krb5-1.17 In FIPS mode, add plaintext fallback for RC4 usages + and taint --- src/lib/krad/attr.c | 45 +++++++++++++++++++++++++++++----------- diff --git a/Use-openssl-s-PRNG-in-FIPS-mode.patch b/krb5-1.17-Use-openssl-s-PRNG-in-FIPS-mode.patch similarity index 89% rename from Use-openssl-s-PRNG-in-FIPS-mode.patch rename to krb5-1.17-Use-openssl-s-PRNG-in-FIPS-mode.patch index 837a747..97d2bc8 100644 --- a/Use-openssl-s-PRNG-in-FIPS-mode.patch +++ b/krb5-1.17-Use-openssl-s-PRNG-in-FIPS-mode.patch @@ -1,7 +1,7 @@ -From 9724b7f409410a7c3cc0330089009d7b9aa92ae6 Mon Sep 17 00:00:00 2001 +From e307112cfcc52474d07eac890825303655ef8b6f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 4 Jan 2019 17:00:15 -0500 -Subject: [PATCH] Use openssl's PRNG in FIPS mode +Subject: [PATCH] krb5-1.17 Use openssl's PRNG in FIPS mode --- src/lib/crypto/krb/prng.c | 11 ++++++++++- diff --git a/krb5-1.3.1-dns.patch b/krb5-1.3.1-dns.patch index d213d71..5d87aa1 100644 --- a/krb5-1.3.1-dns.patch +++ b/krb5-1.3.1-dns.patch @@ -1,4 +1,4 @@ -From 40259729fa4fbec2b22e9ca8043202ac914cca24 Mon Sep 17 00:00:00 2001 +From 64c9cb22ec6d7ecdeafaf60bfc8d26780d2cb4ad Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] krb5-1.3.1-dns.patch diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index 6b1c220..6cf5368 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -1,4 +1,4 @@ -From d6758af31afecc3835043a8e599302f372fcef82 Mon Sep 17 00:00:00 2001 +From 8ee5efa6aec5d02e25081b6dc809cef668ce45ea Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] krb5-1.9-debuginfo.patch diff --git a/krb5.spec b/krb5.spec index 9fbbb43..9af8128 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 8%{?dist} +Release: 9%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -52,7 +52,6 @@ Source100: noport.c Patch26: krb5-1.12.1-pam.patch Patch27: krb5-1.17-beta1-selinux-label.patch Patch28: krb5-1.12-ksu-path.patch -Patch29: krb5-1.12-ktany.patch Patch30: krb5-1.15-beta1-buildconf.patch Patch31: krb5-1.3.1-dns.patch Patch32: krb5-1.12-api.patch @@ -60,10 +59,10 @@ Patch33: krb5-1.13-dirsrv-accountlock.patch Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch -Patch89: In-FIPS-mode-add-plaintext-fallback-for-RC4-usages-a.patch +Patch37: krb5-1.17-In-FIPS-mode-add-plaintext-fallback-for-RC.patch Patch90: Add-tests-for-KCM-ccache-type.patch Patch92: Address-some-optimized-out-memset-calls.patch -Patch93: Use-openssl-s-PRNG-in-FIPS-mode.patch +Patch93: krb5-1.17-Use-openssl-s-PRNG-in-FIPS-mode.patch Patch94: Avoid-allocating-a-register-in-zap-assembly.patch Patch95: In-rd_req_dec-always-log-non-permitted-enctypes.patch Patch96: In-kpropd-debug-log-proper-ticket-enctype-names.patch @@ -72,10 +71,15 @@ Patch98: Make-etype-names-in-KDC-logs-human-readable.patch Patch99: Mark-deprecated-enctypes-when-used.patch Patch100: Properly-size-ifdef-in-k5_cccol_lock.patch Patch101: Fix-memory-leak-in-none-replay-cache-type.patch -Patch102: Become-FIPS-aware-with-3DES.patch -Patch103: FIPS-aware-SPAKE-group-negotiation.patch +Patch102: krb5-1.17-Become-FIPS-aware.patch +Patch103: krb5-1.17-FIPS-aware-SPAKE-group-negotiation.patch Patch104: Clarify-header-comment-for-krb5_cc_start_seq_get.patch Patch105: Implement-krb5_cc_remove_cred-for-remaining-types.patch +Patch106: Remove-srvtab-support.patch +Patch107: Remove-kadmin-RPC-support-for-setting-v4-key.patch +Patch108: Remove-ccapi-related-comments-in-configure.ac.patch +Patch109: Remove-doxygen-generated-HTML-output-for-ccapi.patch +Patch110: Remove-Kerberos-v4-support-vestiges-from-ccapi.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -255,9 +259,6 @@ interface is not considered stable. %autosetup -S git -n %{name}-%{version}%{prerelease} -a 3 ln NOTICE LICENSE -# Take the execute bit off of documentation. -chmod -x doc/ccapi/*.html - # Generate an FDS-compatible LDIF file. inldif=src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif cat > '60kerberos.ldif' << EOF @@ -715,6 +716,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Apr 11 2019 Robbie Harwood - 1.17-9 +- Remove Kerberos v4 support vestiges (including ktany support) + * Thu Apr 11 2019 Robbie Harwood - 1.17-8 - Implement krb5_cc_remove_cred for remaining types - Resolves: #1693836 From 5ebfb70254e6db60564d341940e5f7d72c2db7cd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 17 Apr 2019 16:16:38 -0400 Subject: [PATCH 094/304] Fix config realm change logic in FILE remove_cred --- ...alm-change-logic-in-FILE-remove_cred.patch | 29 +++++++++++++++++++ krb5.spec | 6 +++- 2 files changed, 34 insertions(+), 1 deletion(-) create mode 100644 Fix-config-realm-change-logic-in-FILE-remove_cred.patch diff --git a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch new file mode 100644 index 0000000..899183e --- /dev/null +++ b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch @@ -0,0 +1,29 @@ +From 908eb6dde51917bb50d388a1769c50eede68fc10 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 16 Apr 2019 10:47:35 -0400 +Subject: [PATCH] Fix config realm change logic in FILE remove_cred + +Use data_eq_string() to check the server realm, and do not check if +cred->server is NULL since it is not expected to be (and +k5_marshal_cred() would have already crashed if it were). + +ticket: 8792 +(cherry picked from commit e5367fcddd53dc4db0c1fd2279e91eda3791960a) +--- + src/lib/krb5/ccache/cc_file.c | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +diff --git a/src/lib/krb5/ccache/cc_file.c b/src/lib/krb5/ccache/cc_file.c +index 09da38fa9..a3f67766e 100644 +--- a/src/lib/krb5/ccache/cc_file.c ++++ b/src/lib/krb5/ccache/cc_file.c +@@ -1058,8 +1058,7 @@ delete_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor, + + /* For config entries, also change the realm so that other implementations + * won't match them. */ +- if (cred->server != NULL && cred->server->realm.length > 0 && +- strcmp(cred->server->realm.data, "X-CACHECONF:") == 0) ++ if (data_eq_string(cred->server->realm, "X-CACHECONF:")) + memcpy(cred->server->realm.data, "X-RMED-CONF:", 12); + + k5_marshal_cred(&overwrite, fcursor->version, cred); diff --git a/krb5.spec b/krb5.spec index 9af8128..d8a4805 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 9%{?dist} +Release: 10%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -80,6 +80,7 @@ Patch107: Remove-kadmin-RPC-support-for-setting-v4-key.patch Patch108: Remove-ccapi-related-comments-in-configure.ac.patch Patch109: Remove-doxygen-generated-HTML-output-for-ccapi.patch Patch110: Remove-Kerberos-v4-support-vestiges-from-ccapi.patch +Patch111: Fix-config-realm-change-logic-in-FILE-remove_cred.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -716,6 +717,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Apr 17 2019 Robbie Harwood - 1.17-10 +- Fix config realm change logic in FILE remove_cred + * Thu Apr 11 2019 Robbie Harwood - 1.17-9 - Remove Kerberos v4 support vestiges (including ktany support) From 707673a5059f9cba18f6f2733a20ee2f9e639ae9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 17 Apr 2019 16:17:17 -0400 Subject: [PATCH 095/304] Remove ovsec_adm_export and confvalidator --- Remove-confvalidator-utility.patch | 430 ++++++++++++++++++ ...ovsec_adm_export-dump-format-support.patch | 385 ++++++++++++++++ krb5.spec | 7 +- 3 files changed, 821 insertions(+), 1 deletion(-) create mode 100644 Remove-confvalidator-utility.patch create mode 100644 Remove-ovsec_adm_export-dump-format-support.patch diff --git a/Remove-confvalidator-utility.patch b/Remove-confvalidator-utility.patch new file mode 100644 index 0000000..d002286 --- /dev/null +++ b/Remove-confvalidator-utility.patch @@ -0,0 +1,430 @@ +From 32a6caec15bafd37fdf5746c08cf1a385166020e Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 3 Apr 2019 14:58:19 -0400 +Subject: [PATCH] Remove confvalidator utility + +This utility has not been maintained with encryption types and salt +changes, which suggests it is unused. + +(cherry picked from commit 482a366793d9338e9edb504b407d7704a4bb2f8f) +--- + src/util/confvalidator/README | 25 ---- + src/util/confvalidator/confparser.py | 144 ------------------- + src/util/confvalidator/rules.yml | 13 -- + src/util/confvalidator/validator.conf | 2 - + src/util/confvalidator/validator.py | 194 -------------------------- + 5 files changed, 378 deletions(-) + delete mode 100644 src/util/confvalidator/README + delete mode 100644 src/util/confvalidator/confparser.py + delete mode 100644 src/util/confvalidator/rules.yml + delete mode 100644 src/util/confvalidator/validator.conf + delete mode 100644 src/util/confvalidator/validator.py + +diff --git a/src/util/confvalidator/README b/src/util/confvalidator/README +deleted file mode 100644 +index 7bf7a106a..000000000 +--- a/src/util/confvalidator/README ++++ /dev/null +@@ -1,25 +0,0 @@ +-validator.py is a command line tool for identifying invalid attributes, values and some formating problems in Kerberos configuration files. +-The list of the valid attributes is created based on the “configuration variables” section in k5-int.h and user defined attributes from the rules file. +- +-Usage: +- +-validator.py path [-d defPath] [-r rulesPath] [-c validatorConfPath] +- +-Options: +- +-path – the path to the configuration file to validate +- +--d defPath – path to the k5-int.h file. Starting from the 1.7 release this header holds the profile attribute names in the form #define KRB5_CONF_xxx ”ZZZ”. +- +--r rulesPath - path the rules file in yaml format. It may be used to manage the list of the valid attributes and to define the additional validation rules. +- +--c validatorConfPath – the same as -r and -d options, but in validator configuration file format. +- +-Example: +- +-python validator.py src/config-files/krb5.conf -r rules.yml -d src/include/k5-int.h +-or +-python validator.py src/config-files/krb5.conf -c validator.conf +- +-For more details please refer to the sample files validator.conf and rules.yml +- +diff --git a/src/util/confvalidator/confparser.py b/src/util/confvalidator/confparser.py +deleted file mode 100644 +index 2fea142a5..000000000 +--- a/src/util/confvalidator/confparser.py ++++ /dev/null +@@ -1,144 +0,0 @@ +-''' +-Created on Jan 31, 2010 +- +-@author: tsitkova +-''' +-import re +-import copy +-import yaml +- +-class ConfParser(object): +- def __init__(self, path): +- self.configuration = self._parse(path) +- +- def walk(self): +- for trio in self._walk(self.configuration): +- yield trio +- +- def _parse(self, path): +- comment_pattern = re.compile(r'(\s*[#].*)') +- section_pattern = re.compile(r'^\s*\[(?P
\w+)\]\s+$') +- empty_pattern = re.compile(r'^\s*$') +- equalsign_pattern = re.compile(r'=') +- +- section = None +- parser_stack = list() +- result = dict() +- value = None +- f = open(path, 'r') +- for (ln,line) in enumerate(f): +- line = comment_pattern.sub('', line) +- line = equalsign_pattern.sub(' = ',line,count=1) +- if empty_pattern.match(line) is not None: +- continue +- m = section_pattern.match(line) +- if m is not None: +- section = m.group('section') +- value = dict() +- result[section] = value +- continue +- if section is None: +- msg = 'Failed to determine section for line #%i' % ln +- raise ValueError(msg) +- try: +- value = self._parseLine(value, line, parser_stack) +- except: +- print 'Error while parsing line %i: %s' % (ln+1, line) +- raise +- f.close() +- +- if len(parser_stack): +- raise 'Parsing error.' +- +- return result +- +- def _parseLine(self, value, content, stack): +- token_pattern = re.compile(r'(?P\S+)(?=\s+)') +- attr = None +- token_stack = list() +- +- for m in token_pattern.finditer(content): +- token = m.group('token') +- if not self._validate(token): +- raise ValueError('Invalid token %s' % token) +- if token == '=': +- if len(token_stack) == 0: +- raise ValueError('Failed to find attribute.') +- elif len(token_stack) == 1: +- attr = token_stack.pop() +- else: +- value[attr] = token_stack[:-1] +- attr = token_stack[-1] +- token_stack = list() +- elif token == '{': +- if attr is None: +- raise ValueError('Failed to find attribute.') +- stack.append((attr,value)) +- value = dict() +- elif token == '}': +- if len(stack) == 0: +- raise ValueError('Failed to parse: unbalanced braces') +- if len(token_stack): +- if attr is None: +- raise ValueError('Missing attribute') +- value[attr] = token_stack +- attr = None +- token_stack = list() +- (attr,parent_value) = stack.pop() +- parent_value[attr] = value +- value = parent_value +- else: +- token_stack.append(token) +- if len(token_stack): +- if attr is None: +- raise ValueError('Missing attribute') +- value[attr] = token_stack +- +- return value +- +- def _validate(self, token): +- result = True +- for s in ['{','}']: +- if s in token and s != token: +- result = False +- +- return result +- +- def _walk(self, parsedData, path='root'): +- dirs = list() +- av = list() +- for (key, value) in parsedData.iteritems(): +- if type(value) == dict: +- new_path = path + '.' + key +- for trio in self._walk(value, new_path): +- yield trio +- dirs.append(key) +- else: +- av.append((key,value)) +- yield (path, dirs, av) +- +- +- +-class ConfParserTest(ConfParser): +- def __init__(self): +- self.conf_path = '../tests/krb5.conf' +- super(ConfParserTest, self).__init__(self.conf_path) +- +- def run_tests(self): +- self._test_walk() +- +- def _test_parse(self): +- result = self._parse(self.conf_path) +- print yaml.dump(result) +- +- def _test_walk(self): +- configuration = self._parse(self.conf_path) +- for (path,dirs,av) in self.walk(): +- print path,dirs,av +- +- +- +- +-if __name__ == '__main__': +- tester = ConfParserTest() +- tester.run_tests() +diff --git a/src/util/confvalidator/rules.yml b/src/util/confvalidator/rules.yml +deleted file mode 100644 +index c6ccc89fe..000000000 +--- a/src/util/confvalidator/rules.yml ++++ /dev/null +@@ -1,13 +0,0 @@ +-# Extend the list of the allowed enctypes and salts as needed +-Types: +- supported_enctypes: +- '(aes256-cts-hmac-sha1-96|aes256-cts|aes128-cts-hmac-sha1-96|aes128-cts|des3-hmac-sha1|des3-cbc-raw|des3-cbc-sha1|des3-hmac-sha1|rc4-hmac|arcfour-hmac-md5)(:(normal|v4))?$' +- default_tgs_enctypes: +- '(aes256-cts-hmac-sha1-96|aes256-cts|aes128-cts-hmac-sha1-96|aes128-cts|des3-hmac-sha1|des3-cbc-raw|des3-cbc-sha1|des3-hmac-sha1|rc4-hmac|arcfour-hmac-md5)' +- default_tkt_enctypes: +- '(aes256-cts-hmac-sha1-96|aes256-cts|aes128-cts-hmac-sha1-96|aes128-cts|des3-hmac-sha1|des3-cbc-raw|des3-cbc-sha1|des3-hmac-sha1|rc4-hmac|arcfour-hmac-md5)' +- +-# Add all valid profile attributes that are not listed in k5-int.h +-Attributes: +- - logging +- - dbmodules +diff --git a/src/util/confvalidator/validator.conf b/src/util/confvalidator/validator.conf +deleted file mode 100644 +index 71e205c3b..000000000 +--- a/src/util/confvalidator/validator.conf ++++ /dev/null +@@ -1,2 +0,0 @@ +-RulesPath=./rules.yml +-HfilePath=../../include/k5-int.h +diff --git a/src/util/confvalidator/validator.py b/src/util/confvalidator/validator.py +deleted file mode 100644 +index d739bc091..000000000 +--- a/src/util/confvalidator/validator.py ++++ /dev/null +@@ -1,194 +0,0 @@ +-''' +-Created on Jan 25, 2010 +- +-@author: tsitkova +-''' +-import os +-import sys +-import re +-import yaml +-from optparse import OptionParser +-from confparser import ConfParser +- +-class Rule(object): +- def __init__(self): +- pass +- +- def validate(self,node): +- (path,dirs,avs) = node +- +- +-class Validator(object): +- def __init__(self, kerberosPath, confPath=None, rulesPath=None, hfilePath=None): +- self.parser = ConfParser(kerberosPath) +- if confPath is not None: +- content = self._readConfigFile(confPath) +- rulesPath = content['RulesPath'] +- hfilePath = content['HfilePath'] +- if rulesPath is not None and hfilePath is not None: +- self.rules = self._loadRules(rulesPath) +- self.validKeys = SupportedKeys(hfilePath).validKeys.union(self.rules['Attributes']) +- else: +- raise ValueError('Invalid arguments for validator: no path to rules and definition files') +- +- self._attribute_pattern = re.compile(r'^\w+$') +- self._lowercase_pattern = re.compile(r'[a-z]') +- +- def _readConfigFile(self,path): +- f = open(path) +- result = dict() +- for line in f: +- line = line.rstrip() +- fields = line.split('=') +- result[fields[0]] = fields[1] +- +- return result +- +- def _loadRules(self, path): +- f = open(path) +- rules = yaml.load(f) +- f.close() +- +- return rules +- +- def validate(self): +- typeInfo = self.rules['Types'] +- +- for node in self.parser.walk(): +- self._validateTypes(node, typeInfo) +- self._validateAttrubutes(node, self.validKeys) +- # self._validateRealm(node) +- +- +- def _validateTypes(self, node, typeInfo): +- (path, dirs, avs) = node +- for (key, value) in avs: +- valid_type_pattern = typeInfo.get(key) +- if valid_type_pattern is not None: +- for t in value: +- if re.match(valid_type_pattern, t) is None: +- print 'Wrong type %s for attribute %s.%s' % (t,path,key) +- +- def _validateAttrubutes(self, node, validKeys): +- (path, dirs, avs) = node +- attributes = list() +- for attr in dirs: +- if self._attribute_pattern.match(attr) is not None: +- attributes.append(attr) +- for (attr, value) in avs: +- if self._attribute_pattern.match(attr) is not None: +- attributes.append(attr) +- +- for attr in attributes: +- if attr not in validKeys: +- print 'Unrecognized attribute %s at %s' % (attr, path) +- +-# def _validateRealm(self, node): +-# (path, dirs, avs) = node +-# if path == 'root.realms': +-# for attr in dirs: +-# if self._lowercase_pattern.search(attr) is not None: +-# print 'Lower case letter in realm attribute: %s at %s' % (attr, path) +- +-class SupportedKeys(object): +- def __init__(self, path): +- self.validKeys = self.getKeysFromHfile(path) +- +- def getKeysFromHfile(self, path): +- pattern = re.compile(r'^[#]define KRB5_CONF_\w+\s+["](\w+)["]') +- f = open(path) +- result = set() +- for l in f: +- l = l.rstrip() +- m = pattern.match(l) +- if m is not None: +- result.add(m.groups()[0]) +- f.close() +- +- return result +- +- +-class ValidatorTest(Validator): +- def __init__(self): +- self.kerberosPath = '../tests/kdc1.conf' +- self.rulesPath = '../tests/rules.yml' +- self.hfilePath = '../tests/k5-int.h' +- self.confPath = '../tests/validator.conf' +- +- super(ValidatorTest, self).__init__(self.kerberosPath, +- rulesPath=self.rulesPath, +- hfilePath=self.hfilePath) +- +- def run_tests(self): +- self._test_validate() +- +- def _test__loadRules(self): +- result = self._loadRules(self.rulesPath) +- print result +- +- def _test_validate(self): +- self.validate() +- +- def _test__readConfigFile(self): +- result = self._readConfigFile(self.confPath) +- print result +- +-class SupportedKeysTest(SupportedKeys): +- def __init__(self): +- self.path = '../tests/k5-int.h' +- +- def run_tests(self): +- self._test_getKeysFromHFile() +- +- def _test_getKeysFromHFile(self): +- result = set() +- krb5keys = self.getKeysFromHfile(self.path) +- for key in krb5keys: +- print key +- result.update(key) +- print len(krb5keys) +- +- return result +- +-def _test(): +- tester = ValidatorTest() +- krb5keys = tester.run_tests() +- +-if __name__ == '__main__': +- TEST = False +- if TEST: +- _test() +- sys.exit() +- +- +- usage = "\n\t%prog path [-d defPath] [-r rulesPath] [-c validatorConfPath]" +- description = 'Description: validates kerberos configuration file' +- parser = OptionParser(usage = usage, description = description) +- parser.add_option("-c", dest="confPath", +- help='path to validator config file') +- parser.add_option("-d", dest="hfilePath", +- help='path to h-file with attribute definition') +- parser.add_option("-r", dest="rulesPath", +- help='path to file with validation rules') +- (options, args) = parser.parse_args() +- +- if len(args) != 1 and len(sys.argv) <= 3: +- print '\n%s' % parser.get_usage() +- sys.exit() +- +- validator = None +- if options.confPath is not None: +- validator = Validator(args[0], confPath=options.confPath) +- elif options.hfilePath is not None and options.rulesPath is not None: +- validator = Validator(args[0], hfilePath=options.hfilePath, rulesPath=options.rulesPath) +- else: +- print '\nMust specify either configuration file or paths to rules and definitions files' +- print '%s' % parser.get_usage() +- sys.exit() +- +- validator.validate() +- +- +- +- +- diff --git a/Remove-ovsec_adm_export-dump-format-support.patch b/Remove-ovsec_adm_export-dump-format-support.patch new file mode 100644 index 0000000..12008d6 --- /dev/null +++ b/Remove-ovsec_adm_export-dump-format-support.patch @@ -0,0 +1,385 @@ +From 34bde16a10c0cf0f05732376b955af0302af155d Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 22 Jan 2019 18:34:58 -0500 +Subject: [PATCH] Remove ovsec_adm_export dump format support + +Dumping only suported single-DES principals. While importing still +functioned, it would only have been useful for extremely old (1.3-era) +KDCs. + +ticket: 8798 (new) +(cherry picked from commit 23b93fd48bc445005436c5be98a7269b599b1800) +--- + doc/admin/admin_commands/kdb5_util.rst | 11 +-- + doc/admin/database.rst | 14 ---- + src/kadmin/dbutil/dump.c | 109 ++----------------------- + src/kadmin/dbutil/kdb5_util.c | 4 +- + src/man/kdb5_util.man | 13 +-- + src/tests/Makefile.in | 6 -- + src/tests/t_dump.py | 8 -- + 7 files changed, 13 insertions(+), 152 deletions(-) + +diff --git a/doc/admin/admin_commands/kdb5_util.rst b/doc/admin/admin_commands/kdb5_util.rst +index fee68261a..7dd54f797 100644 +--- a/doc/admin/admin_commands/kdb5_util.rst ++++ b/doc/admin/admin_commands/kdb5_util.rst +@@ -136,7 +136,7 @@ dump + + .. _kdb5_util_dump: + +- **dump** [**-b7**\|\ **-ov**\|\ **-r13**\|\ **-r18**] ++ **dump** [**-b7**\|\ **-r13**\|\ **-r18**] + [**-verbose**] [**-mkey_convert**] [**-new_mkey_file** + *mkey_file*] [**-rev**] [**-recurse**] [*filename* + [*principals*...]] +@@ -151,9 +151,6 @@ load_dump version 7". If filename is not specified, or is the string + load_dump version 4"). This was the dump format produced on + releases prior to 1.2.2. + +-**-ov** +- causes the dump to be in "ovsec_adm_export" format. +- + **-r13** + causes the dump to be in the Kerberos 5 1.3 format ("kdb5_util + load_dump version 5"). This was the dump format produced on +@@ -204,7 +201,7 @@ load + + .. _kdb5_util_load: + +- **load** [**-b7**\|\ **-ov**\|\ **-r13**\|\ **-r18**] [**-hash**] ++ **load** [**-b7**\|\ **-r13**\|\ **-r18**] [**-hash**] + [**-verbose**] [**-update**] *filename* + + Loads a database dump from the named file into the named database. If +@@ -222,10 +219,6 @@ Options: + ("kdb5_util load_dump version 4"). This was the dump format + produced on releases prior to 1.2.2. + +-**-ov** +- requires the database to be in "ovsec_adm_import" format. Must be +- used with the **-update** option. +- + **-r13** + requires the database to be in Kerberos 5 1.3 format ("kdb5_util + load_dump version 5"). This was the dump format produced on +diff --git a/doc/admin/database.rst b/doc/admin/database.rst +index 2b02af3a0..113a680a6 100644 +--- a/doc/admin/database.rst ++++ b/doc/admin/database.rst +@@ -393,20 +393,6 @@ To dump a single principal and later load it, updating the database: + If the database file exists, and the *-update* flag was not + given, *kdb5_util* will overwrite the existing database. + +-Using kdb5_util to upgrade a master KDC from krb5 1.1.x: +- +-:: +- +- shell% kdb5_util dump old-kdb-dump +- shell% kdb5_util dump -ov old-kdb-dump.ov +- [Create a new KDC installation, using the old stash file/master password] +- shell% kdb5_util load old-kdb-dump +- shell% kdb5_util load -update old-kdb-dump.ov +- +-The use of old-kdb-dump.ov for an extra dump and load is necessary +-to preserve per-principal policy information, which is not included in +-the default dump format of krb5 1.1.x. +- + .. note:: + + Using kdb5_util to dump and reload the principal database is +diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c +index 8301a33d0..19f2cc230 100644 +--- a/src/kadmin/dbutil/dump.c ++++ b/src/kadmin/dbutil/dump.c +@@ -484,83 +484,6 @@ dump_r1_11_policy(void *data, osa_policy_ent_t entry) + fprintf(arg->ofile, "\n"); + } + +-static void +-print_key_data(FILE *f, krb5_key_data *kd) +-{ +- int c; +- +- fprintf(f, "%d\t%d\t", kd->key_data_type[0], kd->key_data_length[0]); +- for (c = 0; c < kd->key_data_length[0]; c++) +- fprintf(f, "%02x ", kd->key_data_contents[0][c]); +-} +- +-/* Output osa_adb_princ_ent data in a printable serialized format, suitable for +- * ovsec_adm_import consumption. */ +-static krb5_error_code +-dump_ov_princ(krb5_context context, krb5_db_entry *entry, const char *name, +- FILE *fp, krb5_boolean verbose, krb5_boolean omit_nra) +-{ +- char *princstr; +- unsigned int x; +- int y, foundcrc; +- krb5_tl_data tl_data; +- osa_princ_ent_rec adb; +- XDR xdrs; +- krb5_key_data *key_data; +- +- tl_data.tl_data_type = KRB5_TL_KADM_DATA; +- if (krb5_dbe_lookup_tl_data(context, entry, &tl_data) || +- tl_data.tl_data_length == 0) +- return 0; +- +- memset(&adb, 0, sizeof(adb)); +- xdrmem_create(&xdrs, (caddr_t)tl_data.tl_data_contents, +- tl_data.tl_data_length, XDR_DECODE); +- if (!xdr_osa_princ_ent_rec(&xdrs, &adb)) { +- xdr_destroy(&xdrs); +- return KADM5_XDR_FAILURE; +- } +- xdr_destroy(&xdrs); +- +- krb5_unparse_name(context, entry->princ, &princstr); +- fprintf(fp, "princ\t%s\t", princstr); +- if (adb.policy == NULL) +- fputc('\t', fp); +- else +- fprintf(fp, "%s\t", adb.policy); +- fprintf(fp, "%lx\t%d\t%d\t%d", adb.aux_attributes, adb.old_key_len, +- adb.old_key_next, adb.admin_history_kvno); +- +- for (x = 0; x < adb.old_key_len; x++) { +- foundcrc = 0; +- for (y = 0; y < adb.old_keys[x].n_key_data; y++) { +- key_data = &adb.old_keys[x].key_data[y]; +- if (key_data->key_data_type[0] != ENCTYPE_DES_CBC_CRC) +- continue; +- if (foundcrc) { +- fprintf(stderr, _("Warning! Multiple DES-CBC-CRC keys for " +- "principal %s; skipping duplicates.\n"), +- princstr); +- continue; +- } +- foundcrc++; +- +- fputc('\t', fp); +- print_key_data(fp, key_data); +- } +- if (!foundcrc) { +- fprintf(stderr, _("Warning! No DES-CBC-CRC key for principal %s, " +- "cannot generate OV-compatible record; " +- "skipping\n"), princstr); +- } +- } +- +- fputc('\n', fp); +- free(princstr); +- xdr_free(xdr_osa_princ_ent_rec, &adb); +- return 0; +-} +- + static krb5_error_code + dump_iterator(void *ptr, krb5_db_entry *entry) + { +@@ -1101,14 +1024,6 @@ process_k5beta7_record(krb5_context context, const char *fname, FILE *filep, + process_k5beta7_princ, process_k5beta7_policy); + } + +-static int +-process_ov_record(krb5_context context, const char *fname, FILE *filep, +- krb5_boolean verbose, int *linenop) +-{ +- return process_tagged(context, fname, filep, verbose, linenop, +- process_ov_principal, process_k5beta7_policy); +-} +- + static int + process_r1_8_record(krb5_context context, const char *fname, FILE *filep, + krb5_boolean verbose, int *linenop) +@@ -1135,16 +1050,6 @@ dump_version beta7_version = { + dump_k5beta7_policy, + process_k5beta7_record, + }; +-dump_version ov_version = { +- "OpenV*Secure V1.0", +- "OpenV*Secure V1.0\t", +- 1, +- 0, +- 0, +- dump_ov_princ, +- dump_k5beta7_policy, +- process_ov_record +-}; + dump_version r1_3_version = { + "Kerberos version 5 release 1.3", + "kdb5_util load_dump version 5\n", +@@ -1267,7 +1172,7 @@ current_dump_sno_in_ulog(krb5_context context, const char *ifile) + + /* + * usage is: +- * dump_db [-b7] [-ov] [-r13] [-r18] [-verbose] [-mkey_convert] ++ * dump_db [-b7] [-r13] [-r18] [-verbose] [-mkey_convert] + * [-new_mkey_file mkey_file] [-rev] [-recurse] + * [filename [principals...]] + */ +@@ -1302,7 +1207,8 @@ dump_db(int argc, char **argv) + if (!strcmp(argv[aindex], "-b7")) { + dump = &beta7_version; + } else if (!strcmp(argv[aindex], "-ov")) { +- dump = &ov_version; ++ fprintf(stderr, _("OV dump format not supported\n")); ++ goto error; + } else if (!strcmp(argv[aindex], "-r13")) { + dump = &r1_3_version; + } else if (!strcmp(argv[aindex], "-r18")) { +@@ -1515,8 +1421,7 @@ restore_dump(krb5_context context, char *dumpfile, FILE *f, + } + + /* +- * Usage: load_db [-ov] [-b7] [-r13] [-r18] [-verbose] [-update] [-hash] +- * filename ++ * Usage: load_db [-b7] [-r13] [-r18] [-verbose] [-update] [-hash] filename + */ + void + load_db(int argc, char **argv) +@@ -1540,7 +1445,8 @@ load_db(int argc, char **argv) + if (!strcmp(argv[aindex], "-b7")){ + load = &beta7_version; + } else if (!strcmp(argv[aindex], "-ov")) { +- load = &ov_version; ++ fprintf(stderr, _("OV dump format not supported\n")); ++ goto error; + } else if (!strcmp(argv[aindex], "-r13")) { + load = &r1_3_version; + } else if (!strcmp(argv[aindex], "-r18")){ +@@ -1605,9 +1511,6 @@ load_db(int argc, char **argv) + load = &r1_8_version; + } else if (strcmp(buf, r1_11_version.header) == 0) { + load = &r1_11_version; +- } else if (strncmp(buf, ov_version.header, +- strlen(ov_version.header)) == 0) { +- load = &ov_version; + } else { + fprintf(stderr, _("%s: dump header bad in %s\n"), progname, + dumpfile); +diff --git a/src/kadmin/dbutil/kdb5_util.c b/src/kadmin/dbutil/kdb5_util.c +index accc959e0..e73e2c68e 100644 +--- a/src/kadmin/dbutil/kdb5_util.c ++++ b/src/kadmin/dbutil/kdb5_util.c +@@ -85,10 +85,10 @@ void usage() + "\tcreate [-s]\n" + "\tdestroy [-f]\n" + "\tstash [-f keyfile]\n" +- "\tdump [-old|-ov|-b6|-b7|-r13|-r18] [-verbose]\n" ++ "\tdump [-old|-b6|-b7|-r13|-r18] [-verbose]\n" + "\t [-mkey_convert] [-new_mkey_file mkey_file]\n" + "\t [-rev] [-recurse] [filename [princs...]]\n" +- "\tload [-old|-ov|-b6|-b7|-r13|-r18] [-verbose] [-update] " ++ "\tload [-old|-b6|-b7|-r13|-r18] [-verbose] [-update] " + "filename\n" + "\tark [-e etype_list] principal\n" + "\tadd_mkey [-e etype] [-s]\n" +diff --git a/src/man/kdb5_util.man b/src/man/kdb5_util.man +index 5ebc68a57..9a36ef0df 100644 +--- a/src/man/kdb5_util.man ++++ b/src/man/kdb5_util.man +@@ -1,6 +1,6 @@ + .\" Man page generated from reStructuredText. + . +-.TH "KDB5_UTIL" "8" " " "1.17" "MIT Kerberos" ++.TH "KDB5_UTIL" "8" " " "1.18" "MIT Kerberos" + .SH NAME + kdb5_util \- Kerberos database maintenance utility + . +@@ -136,7 +136,7 @@ kdc.conf(5)\&. + .SS dump + .INDENT 0.0 + .INDENT 3.5 +-\fBdump\fP [\fB\-b7\fP|\fB\-ov\fP|\fB\-r13\fP|\fB\-r18\fP] ++\fBdump\fP [\fB\-b7\fP|\fB\-r13\fP|\fB\-r18\fP] + [\fB\-verbose\fP] [\fB\-mkey_convert\fP] [\fB\-new_mkey_file\fP + \fImkey_file\fP] [\fB\-rev\fP] [\fB\-recurse\fP] [\fIfilename\fP + [\fIprincipals\fP\&...]] +@@ -154,9 +154,6 @@ causes the dump to be in the Kerberos 5 Beta 7 format ("kdb5_util + load_dump version 4"). This was the dump format produced on + releases prior to 1.2.2. + .TP +-\fB\-ov\fP +-causes the dump to be in "ovsec_adm_export" format. +-.TP + \fB\-r13\fP + causes the dump to be in the Kerberos 5 1.3 format ("kdb5_util + load_dump version 5"). This was the dump format produced on +@@ -203,7 +200,7 @@ doing a normal dump instead of a recursive traversal. + .SS load + .INDENT 0.0 + .INDENT 3.5 +-\fBload\fP [\fB\-b7\fP|\fB\-ov\fP|\fB\-r13\fP|\fB\-r18\fP] [\fB\-hash\fP] ++\fBload\fP [\fB\-b7\fP|\fB\-r13\fP|\fB\-r18\fP] [\fB\-hash\fP] + [\fB\-verbose\fP] [\fB\-update\fP] \fIfilename\fP + .UNINDENT + .UNINDENT +@@ -224,10 +221,6 @@ requires the database to be in the Kerberos 5 Beta 7 format + ("kdb5_util load_dump version 4"). This was the dump format + produced on releases prior to 1.2.2. + .TP +-\fB\-ov\fP +-requires the database to be in "ovsec_adm_import" format. Must be +-used with the \fB\-update\fP option. +-.TP + \fB\-r13\fP + requires the database to be in Kerberos 5 1.3 format ("kdb5_util + load_dump version 5"). This was the dump format produced on +diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in +index e27617ee2..c96c5d6b7 100644 +--- a/src/tests/Makefile.in ++++ b/src/tests/Makefile.in +@@ -97,7 +97,6 @@ kdb_check: kdc.conf krb5.conf + $(RUN_DB_TEST) ../tests/create/kdb5_mkdums $(KTEST_OPTS) + $(RUN_DB_TEST) ../tests/verify/kdb5_verify $(KTEST_OPTS) + $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) dump $(TEST_DB).dump +- $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) dump -ov $(TEST_DB).ovdump + $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) destroy -f + @echo "====> NOTE!" + @echo "The following 'create' command is needed due to a change" +@@ -105,16 +104,11 @@ kdb_check: kdc.conf krb5.conf + @echo ==== + $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) create -W + $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) load $(TEST_DB).dump +- $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) load -update -ov $(TEST_DB).ovdump + $(RUN_DB_TEST) ../tests/verify/kdb5_verify $(KTEST_OPTS) + $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) dump $(TEST_DB).dump2 +- $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) dump -ov $(TEST_DB).ovdump2 + sort $(TEST_DB).dump > $(TEST_DB).sort + sort $(TEST_DB).dump2 > $(TEST_DB).sort2 +- sort $(TEST_DB).ovdump > $(TEST_DB).ovsort +- sort $(TEST_DB).ovdump2 > $(TEST_DB).ovsort2 + cmp $(TEST_DB).sort $(TEST_DB).sort2 +- cmp $(TEST_DB).ovsort $(TEST_DB).ovsort2 + $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) destroy -f + $(RM) $(TEST_DB)* stash_file + +diff --git a/src/tests/t_dump.py b/src/tests/t_dump.py +index d803d5602..5d692df99 100755 +--- a/src/tests/t_dump.py ++++ b/src/tests/t_dump.py +@@ -73,7 +73,6 @@ for realm in multidb_realms(start_kdc=False): + srcdump_r18 = os.path.join(srcdumpdir, 'dump.r18') + srcdump_r13 = os.path.join(srcdumpdir, 'dump.r13') + srcdump_b7 = os.path.join(srcdumpdir, 'dump.b7') +- srcdump_ov = os.path.join(srcdumpdir, 'dump.ov') + + # Load a dump file from the source directory. + realm.run([kdb5_util, 'destroy', '-f']) +@@ -86,17 +85,10 @@ for realm in multidb_realms(start_kdc=False): + dump_compare(realm, ['-r18'], srcdump_r18) + dump_compare(realm, ['-r13'], srcdump_r13) + dump_compare(realm, ['-b7'], srcdump_b7) +- dump_compare(realm, ['-ov'], srcdump_ov) + + # Load each format of dump, check it, re-dump it, and compare. + load_dump_check_compare(realm, ['-r18'], srcdump_r18) + load_dump_check_compare(realm, ['-r13'], srcdump_r13) + load_dump_check_compare(realm, ['-b7'], srcdump_b7) + +- # Loading the last (-b7 format) dump won't have loaded the +- # per-principal kadm data. Load that incrementally with -ov. +- realm.run([kadminl, 'getprinc', 'user'], expected_msg='Policy: [none]') +- realm.run([kdb5_util, 'load', '-update', '-ov', srcdump_ov]) +- realm.run([kadminl, 'getprinc', 'user'], expected_msg='Policy: testpol') +- + success('Dump/load tests') diff --git a/krb5.spec b/krb5.spec index d8a4805..9863c9f 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 10%{?dist} +Release: 11%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -81,6 +81,8 @@ Patch108: Remove-ccapi-related-comments-in-configure.ac.patch Patch109: Remove-doxygen-generated-HTML-output-for-ccapi.patch Patch110: Remove-Kerberos-v4-support-vestiges-from-ccapi.patch Patch111: Fix-config-realm-change-logic-in-FILE-remove_cred.patch +Patch112: Remove-confvalidator-utility.patch +Patch113: Remove-ovsec_adm_export-dump-format-support.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -717,6 +719,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Apr 17 2019 Robbie Harwood - 1.17-11 +- Remove ovsec_adm_export and confvalidator + * Wed Apr 17 2019 Robbie Harwood - 1.17-10 - Fix config realm change logic in FILE remove_cred From aa800df20462fd9b8047754bdef59b6306e06225 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 22 Apr 2019 13:09:23 -0400 Subject: [PATCH 096/304] Fix potential close(-1) in cc_file.c --- Fix-potential-close-1-in-cc_file.c.patch | 30 ++++++++++++++++++++++++ krb5.spec | 6 ++++- 2 files changed, 35 insertions(+), 1 deletion(-) create mode 100644 Fix-potential-close-1-in-cc_file.c.patch diff --git a/Fix-potential-close-1-in-cc_file.c.patch b/Fix-potential-close-1-in-cc_file.c.patch new file mode 100644 index 0000000..931f085 --- /dev/null +++ b/Fix-potential-close-1-in-cc_file.c.patch @@ -0,0 +1,30 @@ +From b2002f8286c0f77e57c7387123328a31125cda2e Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 18 Apr 2019 13:39:37 -0400 +Subject: [PATCH] Fix potential close(-1) in cc_file.c + +As part of error handling in d3b39a8bac6206b5ea78b0bf6a2958c1df0b0dd5, +an error path in delete_cred() may result in close(-1). While this +shouldn't be a prolblem in practice (just returning EBADF), it does +upset Coverity. + +ticket: 8792 +(cherry picked from commit 5ccfbaf2f0c8871d2f0ea87ad4b21cc33392ca2c) +--- + src/lib/krb5/ccache/cc_file.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/src/lib/krb5/ccache/cc_file.c b/src/lib/krb5/ccache/cc_file.c +index a3f67766e..bf58c1d45 100644 +--- a/src/lib/krb5/ccache/cc_file.c ++++ b/src/lib/krb5/ccache/cc_file.c +@@ -1122,7 +1122,8 @@ delete_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor, + } + + cleanup: +- close(fd); ++ if (fd >= 0) ++ close(fd); + zapfree(on_disk, expected.len); + k5_buf_free(&expected); + k5_buf_free(&overwrite); diff --git a/krb5.spec b/krb5.spec index 9863c9f..73d6a53 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 11%{?dist} +Release: 12%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -83,6 +83,7 @@ Patch110: Remove-Kerberos-v4-support-vestiges-from-ccapi.patch Patch111: Fix-config-realm-change-logic-in-FILE-remove_cred.patch Patch112: Remove-confvalidator-utility.patch Patch113: Remove-ovsec_adm_export-dump-format-support.patch +Patch114: Fix-potential-close-1-in-cc_file.c.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -719,6 +720,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Apr 22 2019 Robbie Harwood - 1.17-12 +- Fix potential close(-1) in cc_file.c + * Wed Apr 17 2019 Robbie Harwood - 1.17-11 - Remove ovsec_adm_export and confvalidator From 9d9730eb07a9bf9b41c937d73ad0cbb2d704a3d6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 24 Apr 2019 11:39:04 -0400 Subject: [PATCH 097/304] Check more errors in OpenSSL crypto backend --- ...ore-errors-in-OpenSSL-crypto-backend.patch | 88 +++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 93 insertions(+), 1 deletion(-) create mode 100644 Check-more-errors-in-OpenSSL-crypto-backend.patch diff --git a/Check-more-errors-in-OpenSSL-crypto-backend.patch b/Check-more-errors-in-OpenSSL-crypto-backend.patch new file mode 100644 index 0000000..1c55efb --- /dev/null +++ b/Check-more-errors-in-OpenSSL-crypto-backend.patch @@ -0,0 +1,88 @@ +From 27bc3f5a90533af509202d851374ea40f3982864 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 22 Apr 2019 14:26:42 -0400 +Subject: [PATCH] Check more errors in OpenSSL crypto backend + +In krb5int_hmac_keyblock() and krb5int_pbkdf2_hmac(), check for errors +from previously unchecked OpenSSL function calls and return +KRB5_CRYPTO_INTERNAL if they fail. + +HMAC_Init() is deprecated in OpenSSL 1.0 and later; as we are +modifying the call to check for errors, call HMAC_Init_ex() instead. + +ticket: 8799 (new) +(cherry picked from commit 2298e5c2ff1122bcaff715129f5b746e77c3f42a) +--- + src/lib/crypto/openssl/hmac.c | 18 +++++++++--------- + src/lib/crypto/openssl/pbkdf2.c | 9 +++++---- + 2 files changed, 14 insertions(+), 13 deletions(-) + +diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c +index d94d9ac94..769a50c00 100644 +--- a/src/lib/crypto/openssl/hmac.c ++++ b/src/lib/crypto/openssl/hmac.c +@@ -121,7 +121,7 @@ krb5int_hmac_keyblock(const struct krb5_hash_provider *hash, + const krb5_crypto_iov *data, size_t num_data, + krb5_data *output) + { +- unsigned int i = 0, md_len = 0; ++ unsigned int i = 0, md_len = 0, ok; + unsigned char md[EVP_MAX_MD_SIZE]; + HMAC_CTX *ctx; + size_t hashsize, blocksize; +@@ -141,22 +141,22 @@ krb5int_hmac_keyblock(const struct krb5_hash_provider *hash, + if (ctx == NULL) + return ENOMEM; + +- HMAC_Init(ctx, keyblock->contents, keyblock->length, map_digest(hash)); +- for (i = 0; i < num_data; i++) { ++ ok = HMAC_Init_ex(ctx, keyblock->contents, keyblock->length, ++ map_digest(hash), NULL); ++ for (i = 0; ok && i < num_data; i++) { + const krb5_crypto_iov *iov = &data[i]; + + if (SIGN_IOV(iov)) +- HMAC_Update(ctx, (uint8_t *)iov->data.data, iov->data.length); ++ ok = HMAC_Update(ctx, (uint8_t *)iov->data.data, iov->data.length); + } +- HMAC_Final(ctx, md, &md_len); +- if ( md_len <= output->length) { ++ if (ok) ++ ok = HMAC_Final(ctx, md, &md_len); ++ if (ok && md_len <= output->length) { + output->length = md_len; + memcpy(output->data, md, output->length); + } + HMAC_CTX_free(ctx); +- return 0; +- +- ++ return ok ? 0 : KRB5_CRYPTO_INTERNAL; + } + + krb5_error_code +diff --git a/src/lib/crypto/openssl/pbkdf2.c b/src/lib/crypto/openssl/pbkdf2.c +index 00c2116fc..732ec6405 100644 +--- a/src/lib/crypto/openssl/pbkdf2.c ++++ b/src/lib/crypto/openssl/pbkdf2.c +@@ -35,6 +35,7 @@ krb5int_pbkdf2_hmac(const struct krb5_hash_provider *hash, + const krb5_data *pass, const krb5_data *salt) + { + const EVP_MD *md = NULL; ++ int ok; + + /* Get the message digest handle corresponding to the hash. */ + if (hash == &krb5int_hash_sha1) +@@ -46,8 +47,8 @@ krb5int_pbkdf2_hmac(const struct krb5_hash_provider *hash, + if (md == NULL) + return KRB5_CRYPTO_INTERNAL; + +- PKCS5_PBKDF2_HMAC(pass->data, pass->length, (unsigned char *)salt->data, +- salt->length, count, md, out->length, +- (unsigned char *)out->data); +- return 0; ++ ok = PKCS5_PBKDF2_HMAC(pass->data, pass->length, ++ (unsigned char *)salt->data, salt->length, count, ++ md, out->length, (unsigned char *)out->data); ++ return ok ? 0 : KRB5_CRYPTO_INTERNAL; + } diff --git a/krb5.spec b/krb5.spec index 73d6a53..b4f962b 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 12%{?dist} +Release: 13%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -84,6 +84,7 @@ Patch111: Fix-config-realm-change-logic-in-FILE-remove_cred.patch Patch112: Remove-confvalidator-utility.patch Patch113: Remove-ovsec_adm_export-dump-format-support.patch Patch114: Fix-potential-close-1-in-cc_file.c.patch +Patch115: Check-more-errors-in-OpenSSL-crypto-backend.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -720,6 +721,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Apr 24 2019 Robbie Harwood - 1.17-13 +- Check more errors in OpenSSL crypto backend + * Mon Apr 22 2019 Robbie Harwood - 1.17-12 - Fix potential close(-1) in cc_file.c From 0555bc87c876946235076aca1fdcbfaedd60ca0f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 24 Apr 2019 11:45:11 -0400 Subject: [PATCH 098/304] Add dns_canonicalize_hostname=fallback support --- ...nonicalize_hostname-fallback-support.patch | 409 +++++++++++++++ ...able-flag-instead-of-denying-request.patch | 484 ++++++++++++++++++ krb5.spec | 7 +- 3 files changed, 899 insertions(+), 1 deletion(-) create mode 100644 Add-dns_canonicalize_hostname-fallback-support.patch create mode 100644 Clear-forwardable-flag-instead-of-denying-request.patch diff --git a/Add-dns_canonicalize_hostname-fallback-support.patch b/Add-dns_canonicalize_hostname-fallback-support.patch new file mode 100644 index 0000000..07eb422 --- /dev/null +++ b/Add-dns_canonicalize_hostname-fallback-support.patch @@ -0,0 +1,409 @@ +From 18d45e4b48c363f631b1acd7dac5902351bf1a0e Mon Sep 17 00:00:00 2001 +From: Simo Sorce +Date: Tue, 4 Dec 2018 15:22:55 -0500 +Subject: [PATCH] Add dns_canonicalize_hostname=fallback support + +Turn dns_canonicalize_hostname into a tristate variable, allowing the +value "fallback" as well as the true/false booleans. If it is set to +fallback, delay DNS canonicalization and attempt it only in +krb5_get_credentials() if the KDC responds that the requested server +principal name is unknown. + +[ghudson@mit.edu: added TGS tests; refactored code; edited commit +message and documentation] + +ticket: 8765 (new) +(cherry picked from commit 6c20cb1c89acaa03db897182a3b28d5f8f284907) +--- + doc/admin/conf_files/krb5_conf.rst | 4 ++ + src/include/k5-int.h | 8 ++- + src/include/k5-trace.h | 3 ++ + src/lib/krb5/krb/get_creds.c | 79 ++++++++++++++++++++++++++---- + src/lib/krb5/krb/init_ctx.c | 27 +++++++++- + src/lib/krb5/krb/t_copy_context.c | 2 +- + src/lib/krb5/os/os-proto.h | 4 ++ + src/lib/krb5/os/sn2princ.c | 19 +++++-- + src/tests/gcred.c | 5 +- + src/tests/t_sn2princ.py | 34 ++++++++++++- + 10 files changed, 167 insertions(+), 18 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index 7b4389f6b..e9f7e8c59 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -201,6 +201,10 @@ The libdefaults section may contain any of the following relations: + means that short hostnames will not be canonicalized to + fully-qualified hostnames. The default value is true. + ++ If this option is set to ``fallback`` (new in release 1.18), DNS ++ canonicalization will only be performed the server hostname is not ++ found with the original name when requesting credentials. ++ + **dns_lookup_kdc** + Indicate whether DNS SRV records should be used to locate the KDCs + and other servers for a realm, if they are not listed in the +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 255cee822..1e6a739e9 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -1159,6 +1159,12 @@ k5_plugin_register_dyn(krb5_context context, int interface_id, + void + k5_plugin_free_context(krb5_context context); + ++enum dns_canonhost { ++ CANONHOST_FALSE = 0, ++ CANONHOST_TRUE = 1, ++ CANONHOST_FALLBACK = 2 ++}; ++ + struct _kdb5_dal_handle; /* private, in kdb5.h */ + typedef struct _kdb5_dal_handle kdb5_dal_handle; + struct _kdb_log_context; +@@ -1222,7 +1228,7 @@ struct _krb5_context { + + krb5_boolean allow_weak_crypto; + krb5_boolean ignore_acceptor_hostname; +- krb5_boolean dns_canonicalize_hostname; ++ enum dns_canonhost dns_canonicalize_hostname; + + krb5_trace_callback trace_callback; + void *trace_callback_data; +diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h +index 2aa379b76..f3ed6a45d 100644 +--- a/src/include/k5-trace.h ++++ b/src/include/k5-trace.h +@@ -191,6 +191,9 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); + #define TRACE_FAST_REQUIRED(c) \ + TRACE(c, "Using FAST due to KRB5_FAST_REQUIRED flag") + ++#define TRACE_GET_CREDS_FALLBACK(c, hostname) \ ++ TRACE(c, "Falling back to canonicalized server hostname {str}", hostname) ++ + #define TRACE_GIC_PWD_CHANGED(c) \ + TRACE(c, "Getting initial TGT with changed password") + #define TRACE_GIC_PWD_CHANGEPW(c, tries) \ +diff --git a/src/lib/krb5/krb/get_creds.c b/src/lib/krb5/krb/get_creds.c +index 69900adfa..0a04d68b9 100644 +--- a/src/lib/krb5/krb/get_creds.c ++++ b/src/lib/krb5/krb/get_creds.c +@@ -39,6 +39,7 @@ + + #include "k5-int.h" + #include "int-proto.h" ++#include "os-proto.h" + #include "fast.h" + + /* +@@ -1249,6 +1250,26 @@ krb5_tkt_creds_step(krb5_context context, krb5_tkt_creds_context ctx, + return EINVAL; + } + ++static krb5_error_code ++try_get_creds(krb5_context context, krb5_flags options, krb5_ccache ccache, ++ krb5_creds *in_creds, krb5_creds *creds_out) ++{ ++ krb5_error_code code; ++ krb5_tkt_creds_context ctx = NULL; ++ ++ code = krb5_tkt_creds_init(context, ccache, in_creds, options, &ctx); ++ if (code) ++ goto cleanup; ++ code = krb5_tkt_creds_get(context, ctx); ++ if (code) ++ goto cleanup; ++ code = krb5_tkt_creds_get_creds(context, ctx, creds_out); ++ ++cleanup: ++ krb5_tkt_creds_free(context, ctx); ++ return code; ++} ++ + krb5_error_code KRB5_CALLCONV + krb5_get_credentials(krb5_context context, krb5_flags options, + krb5_ccache ccache, krb5_creds *in_creds, +@@ -1256,7 +1277,10 @@ krb5_get_credentials(krb5_context context, krb5_flags options, + { + krb5_error_code code; + krb5_creds *ncreds = NULL; +- krb5_tkt_creds_context ctx = NULL; ++ krb5_creds canon_creds, store_creds; ++ krb5_principal_data canon_server; ++ krb5_data canon_components[2]; ++ char *hostname = NULL, *canon_hostname = NULL; + + *out_creds = NULL; + +@@ -1265,22 +1289,59 @@ krb5_get_credentials(krb5_context context, krb5_flags options, + if (ncreds == NULL) + goto cleanup; + +- /* Make and execute a krb5_tkt_creds context to get the credential. */ +- code = krb5_tkt_creds_init(context, ccache, in_creds, options, &ctx); +- if (code != 0) ++ code = try_get_creds(context, options, ccache, in_creds, ncreds); ++ if (!code) { ++ *out_creds = ncreds; ++ return 0; ++ } ++ ++ /* Possibly try again with the canonicalized hostname, if the server is ++ * host-based and we are configured for fallback canonicalization. */ ++ if (code != KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN) + goto cleanup; +- code = krb5_tkt_creds_get(context, ctx); +- if (code != 0) ++ if (context->dns_canonicalize_hostname != CANONHOST_FALLBACK) + goto cleanup; +- code = krb5_tkt_creds_get_creds(context, ctx, ncreds); +- if (code != 0) ++ if (in_creds->server->type != KRB5_NT_SRV_HST || ++ in_creds->server->length != 2) + goto cleanup; + ++ hostname = k5memdup0(in_creds->server->data[1].data, ++ in_creds->server->data[1].length, &code); ++ if (hostname == NULL) ++ goto cleanup; ++ code = k5_expand_hostname(context, hostname, TRUE, &canon_hostname); ++ if (code) ++ goto cleanup; ++ ++ TRACE_GET_CREDS_FALLBACK(context, canon_hostname); ++ ++ /* Make shallow copies of in_creds and its server to alter the hostname. */ ++ canon_components[0] = in_creds->server->data[0]; ++ canon_components[1] = string2data(canon_hostname); ++ canon_server = *in_creds->server; ++ canon_server.data = canon_components; ++ canon_creds = *in_creds; ++ canon_creds.server = &canon_server; ++ ++ code = try_get_creds(context, options | KRB5_GC_NO_STORE, ccache, ++ &canon_creds, ncreds); ++ if (code) ++ goto cleanup; ++ ++ if (!(options & KRB5_GC_NO_STORE)) { ++ /* Store the creds under the originally requested server name. The ++ * ccache layer will also store them under the ticket server name. */ ++ store_creds = *ncreds; ++ store_creds.server = in_creds->server; ++ (void)krb5_cc_store_cred(context, ccache, &store_creds); ++ } ++ + *out_creds = ncreds; + ncreds = NULL; + + cleanup: ++ free(hostname); ++ free(canon_hostname); + krb5_free_creds(context, ncreds); +- krb5_tkt_creds_free(context, ctx); + return code; + } +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index 947e50400..d263d5cc5 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -101,6 +101,30 @@ get_boolean(krb5_context ctx, const char *name, int def_val, int *boolean_out) + return retval; + } + ++static krb5_error_code ++get_tristate(krb5_context ctx, const char *name, const char *third_option, ++ int third_option_val, int def_val, int *val_out) ++{ ++ krb5_error_code retval; ++ char *str; ++ int match; ++ ++ retval = profile_get_boolean(ctx->profile, KRB5_CONF_LIBDEFAULTS, name, ++ NULL, def_val, val_out); ++ if (retval != PROF_BAD_BOOLEAN) ++ return retval; ++ retval = profile_get_string(ctx->profile, KRB5_CONF_LIBDEFAULTS, name, ++ NULL, NULL, &str); ++ if (retval) ++ return retval; ++ match = (strcasecmp(third_option, str) == 0); ++ free(str); ++ if (!match) ++ return EINVAL; ++ *val_out = third_option_val; ++ return 0; ++} ++ + krb5_error_code KRB5_CALLCONV + krb5_init_context(krb5_context *context) + { +@@ -213,7 +237,8 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + goto cleanup; + ctx->ignore_acceptor_hostname = tmp; + +- retval = get_boolean(ctx, KRB5_CONF_DNS_CANONICALIZE_HOSTNAME, 1, &tmp); ++ retval = get_tristate(ctx, KRB5_CONF_DNS_CANONICALIZE_HOSTNAME, "fallback", ++ CANONHOST_FALLBACK, 1, &tmp); + if (retval) + goto cleanup; + ctx->dns_canonicalize_hostname = tmp; +diff --git a/src/lib/krb5/krb/t_copy_context.c b/src/lib/krb5/krb/t_copy_context.c +index fa810be8a..a6e48cd25 100644 +--- a/src/lib/krb5/krb/t_copy_context.c ++++ b/src/lib/krb5/krb/t_copy_context.c +@@ -145,7 +145,7 @@ main(int argc, char **argv) + ctx->udp_pref_limit = 2345; + ctx->use_conf_ktypes = TRUE; + ctx->ignore_acceptor_hostname = TRUE; +- ctx->dns_canonicalize_hostname = FALSE; ++ ctx->dns_canonicalize_hostname = CANONHOST_FALSE; + free(ctx->plugin_base_dir); + check((ctx->plugin_base_dir = strdup("/a/b/c/d")) != NULL); + +diff --git a/src/lib/krb5/os/os-proto.h b/src/lib/krb5/os/os-proto.h +index 634e82d70..066d30221 100644 +--- a/src/lib/krb5/os/os-proto.h ++++ b/src/lib/krb5/os/os-proto.h +@@ -83,6 +83,10 @@ struct sendto_callback_info { + void *data; + }; + ++krb5_error_code k5_expand_hostname(krb5_context context, const char *host, ++ krb5_boolean is_fallback, ++ char **canonhost_out); ++ + krb5_error_code k5_locate_server(krb5_context, const krb5_data *realm, + struct serverlist *serverlist, + enum locate_service_type svc, +diff --git a/src/lib/krb5/os/sn2princ.c b/src/lib/krb5/os/sn2princ.c +index 5932fd9b3..98d2600aa 100644 +--- a/src/lib/krb5/os/sn2princ.c ++++ b/src/lib/krb5/os/sn2princ.c +@@ -53,19 +53,23 @@ use_reverse_dns(krb5_context context) + return value; + } + +-krb5_error_code KRB5_CALLCONV +-krb5_expand_hostname(krb5_context context, const char *host, +- char **canonhost_out) ++krb5_error_code ++k5_expand_hostname(krb5_context context, const char *host, ++ krb5_boolean is_fallback, char **canonhost_out) + { + struct addrinfo *ai = NULL, hint; + char namebuf[NI_MAXHOST], *copy, *p; + int err; + const char *canonhost; ++ krb5_boolean use_dns; + + *canonhost_out = NULL; + + canonhost = host; +- if (context->dns_canonicalize_hostname) { ++ use_dns = (context->dns_canonicalize_hostname == CANONHOST_TRUE || ++ (is_fallback && ++ context->dns_canonicalize_hostname == CANONHOST_FALLBACK)); ++ if (use_dns) { + /* Try a forward lookup of the hostname. */ + memset(&hint, 0, sizeof(hint)); + hint.ai_flags = AI_CANONNAME; +@@ -112,6 +116,13 @@ cleanup: + return (*canonhost_out == NULL) ? ENOMEM : 0; + } + ++krb5_error_code KRB5_CALLCONV ++krb5_expand_hostname(krb5_context context, const char *host, ++ char **canonhost_out) ++{ ++ return k5_expand_hostname(context, host, FALSE, canonhost_out); ++} ++ + /* If hostname appears to have a :port or :instance trailer (used in MSSQLSvc + * principals), return a pointer to the separator. Otherwise return NULL. */ + static const char * +diff --git a/src/tests/gcred.c b/src/tests/gcred.c +index b14e4fc9a..cac524c51 100644 +--- a/src/tests/gcred.c ++++ b/src/tests/gcred.c +@@ -66,6 +66,7 @@ main(int argc, char **argv) + krb5_principal client, server; + krb5_ccache ccache; + krb5_creds in_creds, *creds; ++ krb5_ticket *ticket; + krb5_flags options = 0; + char *name; + int c; +@@ -102,9 +103,11 @@ main(int argc, char **argv) + in_creds.client = client; + in_creds.server = server; + check(krb5_get_credentials(ctx, options, ccache, &in_creds, &creds)); +- check(krb5_unparse_name(ctx, creds->server, &name)); ++ check(krb5_decode_ticket(&creds->ticket, &ticket)); ++ check(krb5_unparse_name(ctx, ticket->server, &name)); + printf("%s\n", name); + ++ krb5_free_ticket(ctx, ticket); + krb5_free_unparsed_name(ctx, name); + krb5_free_creds(ctx, creds); + krb5_free_principal(ctx, client); +diff --git a/src/tests/t_sn2princ.py b/src/tests/t_sn2princ.py +index 1ffda51f4..fe435a2d5 100755 +--- a/src/tests/t_sn2princ.py ++++ b/src/tests/t_sn2princ.py +@@ -7,10 +7,15 @@ conf = {'domain_realm': {'kerberos.org': 'R1', + 'mit.edu': 'R3'}} + no_rdns_conf = {'libdefaults': {'rdns': 'false'}} + no_canon_conf = {'libdefaults': {'dns_canonicalize_hostname': 'false'}} ++fallback_canon_conf = {'libdefaults': ++ {'rdns': 'false', ++ 'dns_canonicalize_hostname': 'fallback'}} + +-realm = K5Realm(create_kdb=False, krb5_conf=conf) ++realm = K5Realm(realm='R1', create_host=False, krb5_conf=conf) + no_rdns = realm.special_env('no_rdns', False, krb5_conf=no_rdns_conf) + no_canon = realm.special_env('no_canon', False, krb5_conf=no_canon_conf) ++fallback_canon = realm.special_env('fallback_canon', False, ++ krb5_conf=fallback_canon_conf) + + def testbase(host, nametype, princhost, princrealm, env=None): + # Run the sn2princ harness with a specified host and name type and +@@ -37,6 +42,10 @@ def testu(host, princhost, princrealm): + # Test with the unknown name type. + testbase(host, 'unknown', princhost, princrealm) + ++def testfc(host, princhost, princrealm): ++ # Test with the host-based name type with canonicalization fallback. ++ testbase(host, 'srv-hst', princhost, princrealm, env=fallback_canon) ++ + # With the unknown principal type, we do not canonicalize or downcase, + # but we do remove a trailing period and look up the realm. + mark('unknown type') +@@ -71,6 +80,29 @@ if offline: + oname = 'ptr-mismatch.kerberos.org' + fname = 'www.kerberos.org' + ++# Test fallback canonicalization krb5_sname_to_principal() results ++# (same as dns_canonicalize_hostname=false). ++mark('dns_canonicalize_host=fallback') ++testfc(oname, oname, 'R1') ++ ++# Test fallback canonicalization in krb5_get_credentials(). ++oprinc = 'host/' + oname ++fprinc = 'host/' + fname ++shutil.copy(realm.ccache, realm.ccache + '.save') ++realm.addprinc(fprinc) ++# oprinc doesn't exist, so we get the canonicalized fprinc as a fallback. ++msgs = ('Falling back to canonicalized server hostname ' + fname,) ++realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon, ++ expected_msg=fprinc, expected_trace=msgs) ++realm.addprinc(oprinc) ++# oprinc now exists, but we still get the fprinc ticket from the cache. ++realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon, ++ expected_msg=fprinc) ++# Without the cached result, we sould get oprinc in preference to fprinc. ++os.rename(realm.ccache + '.save', realm.ccache) ++realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon, ++ expected_msg=oprinc) ++ + # Verify forward resolution before testing for it. + try: + ai = socket.getaddrinfo(oname, None, 0, 0, 0, socket.AI_CANONNAME) diff --git a/Clear-forwardable-flag-instead-of-denying-request.patch b/Clear-forwardable-flag-instead-of-denying-request.patch new file mode 100644 index 0000000..4b29e0f --- /dev/null +++ b/Clear-forwardable-flag-instead-of-denying-request.patch @@ -0,0 +1,484 @@ +From 297ad5039231e655eaae7c142991326fd863e70a Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 15 Nov 2018 13:40:43 -0500 +Subject: [PATCH] Clear forwardable flag instead of denying request + +If the client requests a forwardable or proxiable ticket and the +option cannot be honored by policy, issue a non-forwardable or +non-proxiable ticket rather than denying the request. + +Add a test script for testing KDC request options and populate it with +tests for the forwardable and proxiable flags. + +ticket: 7871 +(cherry picked from commit 08e948cce2c79a3604066fcf7a64fc527456f83d) +--- + src/kdc/do_as_req.c | 19 ++------ + src/kdc/do_tgs_req.c | 56 ++++----------------- + src/kdc/kdc_util.c | 82 ++++++++++++++++++------------- + src/kdc/kdc_util.h | 9 ++-- + src/kdc/tgs_policy.c | 8 +-- + src/tests/Makefile.in | 1 + + src/tests/gcred.c | 28 ++++++++--- + src/tests/t_kdcoptions.py | 100 ++++++++++++++++++++++++++++++++++++++ + 8 files changed, 189 insertions(+), 114 deletions(-) + create mode 100644 src/tests/t_kdcoptions.py + +diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c +index 588c1375a..8a96c12a9 100644 +--- a/src/kdc/do_as_req.c ++++ b/src/kdc/do_as_req.c +@@ -192,13 +192,6 @@ finish_process_as_req(struct as_req_state *state, krb5_error_code errcode) + + au_state->stage = ENCR_REP; + +- if ((errcode = validate_forwardable(state->request, *state->client, +- *state->server, state->kdc_time, +- &state->status))) { +- errcode += ERROR_TABLE_BASE_krb5; +- goto egress; +- } +- + errcode = check_indicators(kdc_context, state->server, + state->auth_indicators); + if (errcode) { +@@ -708,12 +701,11 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, + } + + /* Copy options that request the corresponding ticket flags. */ +- state->enc_tkt_reply.flags = OPTS2FLAGS(state->request->kdc_options); ++ state->enc_tkt_reply.flags = get_ticket_flags(state->request->kdc_options, ++ state->client, state->server, ++ NULL); + state->enc_tkt_reply.times.authtime = state->authtime; + +- setflag(state->enc_tkt_reply.flags, TKT_FLG_INITIAL); +- setflag(state->enc_tkt_reply.flags, TKT_FLG_ENC_PA_REP); +- + /* + * It should be noted that local policy may affect the + * processing of any of these flags. For example, some +@@ -732,10 +724,9 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, + state->enc_tkt_reply.transited.tr_type = KRB5_DOMAIN_X500_COMPRESS; + state->enc_tkt_reply.transited.tr_contents = empty_string; + +- if (isflagset(state->request->kdc_options, KDC_OPT_POSTDATED)) { +- setflag(state->enc_tkt_reply.flags, TKT_FLG_INVALID); ++ if (isflagset(state->request->kdc_options, KDC_OPT_POSTDATED)) + state->enc_tkt_reply.times.starttime = state->request->from; +- } else ++ else + state->enc_tkt_reply.times.starttime = state->kdc_time; + + kdc_get_ticket_endtime(kdc_active_realm, +diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c +index 587342a6c..1da099318 100644 +--- a/src/kdc/do_tgs_req.c ++++ b/src/kdc/do_tgs_req.c +@@ -378,15 +378,16 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, + else + ticket_reply.server = request->server; /* XXX careful for realm... */ + +- enc_tkt_reply.flags = OPTS2FLAGS(request->kdc_options); +- enc_tkt_reply.flags |= COPY_TKT_FLAGS(header_enc_tkt->flags); ++ enc_tkt_reply.flags = get_ticket_flags(request->kdc_options, client, ++ server, header_enc_tkt); + enc_tkt_reply.times.starttime = 0; + +- if (isflagset(server->attributes, KRB5_KDB_OK_AS_DELEGATE)) +- setflag(enc_tkt_reply.flags, TKT_FLG_OK_AS_DELEGATE); +- +- /* Indicate support for encrypted padata (RFC 6806). */ +- setflag(enc_tkt_reply.flags, TKT_FLG_ENC_PA_REP); ++ /* OK_TO_AUTH_AS_DELEGATE must be set on the service requesting S4U2Self ++ * for forwardable tickets to be issued. */ ++ if (isflagset(c_flags, KRB5_KDB_FLAG_PROTOCOL_TRANSITION) && ++ !is_referral && ++ !isflagset(server->attributes, KRB5_KDB_OK_TO_AUTH_AS_DELEGATE)) ++ clear(enc_tkt_reply.flags, TKT_FLG_FORWARDABLE); + + /* don't use new addresses unless forwarded, see below */ + +@@ -401,37 +402,6 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, + * realms may refuse to issue renewable tickets + */ + +- if (isflagset(request->kdc_options, KDC_OPT_FORWARDABLE)) { +- +- if (isflagset(c_flags, KRB5_KDB_FLAG_PROTOCOL_TRANSITION)) { +- /* +- * If S4U2Self principal is not forwardable, then mark ticket as +- * unforwardable. This behaviour matches Windows, but it is +- * different to the MIT AS-REQ path, which returns an error +- * (KDC_ERR_POLICY) if forwardable tickets cannot be issued. +- * +- * Consider this block the S4U2Self equivalent to +- * validate_forwardable(). +- */ +- if (client != NULL && +- isflagset(client->attributes, KRB5_KDB_DISALLOW_FORWARDABLE)) +- clear(enc_tkt_reply.flags, TKT_FLG_FORWARDABLE); +- /* +- * Forwardable flag is propagated along referral path. +- */ +- else if (!isflagset(header_enc_tkt->flags, TKT_FLG_FORWARDABLE)) +- clear(enc_tkt_reply.flags, TKT_FLG_FORWARDABLE); +- /* +- * OK_TO_AUTH_AS_DELEGATE must be set on the service requesting +- * S4U2Self in order for forwardable tickets to be returned. +- */ +- else if (!is_referral && +- !isflagset(server->attributes, +- KRB5_KDB_OK_TO_AUTH_AS_DELEGATE)) +- clear(enc_tkt_reply.flags, TKT_FLG_FORWARDABLE); +- } +- } +- + if (isflagset(request->kdc_options, KDC_OPT_FORWARDED) || + isflagset(request->kdc_options, KDC_OPT_PROXY)) { + +@@ -440,16 +410,10 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, + enc_tkt_reply.caddrs = request->addresses; + reply_encpart.caddrs = request->addresses; + } +- /* We don't currently handle issuing anonymous tickets based on +- * non-anonymous ones, so just ignore the option. */ +- if (isflagset(request->kdc_options, KDC_OPT_REQUEST_ANONYMOUS) && +- !isflagset(header_enc_tkt->flags, TKT_FLG_ANONYMOUS)) +- clear(enc_tkt_reply.flags, TKT_FLG_ANONYMOUS); + +- if (isflagset(request->kdc_options, KDC_OPT_POSTDATED)) { +- setflag(enc_tkt_reply.flags, TKT_FLG_INVALID); ++ if (isflagset(request->kdc_options, KDC_OPT_POSTDATED)) + enc_tkt_reply.times.starttime = request->from; +- } else ++ else + enc_tkt_reply.times.starttime = kdc_time; + + if (isflagset(request->kdc_options, KDC_OPT_VALIDATE)) { +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index 96c88edc1..f2741090e 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -697,29 +697,6 @@ validate_as_request(kdc_realm_t *kdc_active_realm, + return(KDC_ERR_CANNOT_POSTDATE); + } + +- /* +- * A Windows KDC will return KDC_ERR_PREAUTH_REQUIRED instead of +- * KDC_ERR_POLICY in the following case: +- * +- * - KDC_OPT_FORWARDABLE is set in KDCOptions but local +- * policy has KRB5_KDB_DISALLOW_FORWARDABLE set for the +- * client, and; +- * - KRB5_KDB_REQUIRES_PRE_AUTH is set for the client but +- * preauthentication data is absent in the request. +- * +- * Hence, this check most be done after the check for preauth +- * data, and is now performed by validate_forwardable() (the +- * contents of which were previously below). +- */ +- +- /* Client and server must allow proxiable tickets */ +- if (isflagset(request->kdc_options, KDC_OPT_PROXIABLE) && +- (isflagset(client.attributes, KRB5_KDB_DISALLOW_PROXIABLE) || +- isflagset(server.attributes, KRB5_KDB_DISALLOW_PROXIABLE))) { +- *status = "PROXIABLE NOT ALLOWED"; +- return(KDC_ERR_POLICY); +- } +- + /* Check to see if client is locked out */ + if (isflagset(client.attributes, KRB5_KDB_DISALLOW_ALL_TIX)) { + *status = "CLIENT LOCKED OUT"; +@@ -752,19 +729,54 @@ validate_as_request(kdc_realm_t *kdc_active_realm, + return 0; + } + +-int +-validate_forwardable(krb5_kdc_req *request, krb5_db_entry client, +- krb5_db_entry server, krb5_timestamp kdc_time, +- const char **status) ++/* ++ * Compute ticket flags based on the request, the client and server DB entry ++ * (which may prohibit forwardable or proxiable tickets), and the header ++ * ticket. client may be NULL for a TGS request (although it may be set, such ++ * as for an S4U2Self request). header_enc may be NULL for an AS request. ++ */ ++krb5_flags ++get_ticket_flags(krb5_flags reqflags, krb5_db_entry *client, ++ krb5_db_entry *server, krb5_enc_tkt_part *header_enc) + { +- *status = NULL; +- if (isflagset(request->kdc_options, KDC_OPT_FORWARDABLE) && +- (isflagset(client.attributes, KRB5_KDB_DISALLOW_FORWARDABLE) || +- isflagset(server.attributes, KRB5_KDB_DISALLOW_FORWARDABLE))) { +- *status = "FORWARDABLE NOT ALLOWED"; +- return(KDC_ERR_POLICY); +- } else +- return 0; ++ krb5_flags flags; ++ ++ /* Indicate support for encrypted padata (RFC 6806), and set flags based on ++ * request options and the header ticket. */ ++ flags = OPTS2FLAGS(reqflags) | TKT_FLG_ENC_PA_REP; ++ if (reqflags & KDC_OPT_POSTDATED) ++ flags |= TKT_FLG_INVALID; ++ if (header_enc != NULL) ++ flags |= COPY_TKT_FLAGS(header_enc->flags); ++ if (header_enc == NULL) ++ flags |= TKT_FLG_INITIAL; ++ ++ /* For TGS requests, indicate if the service is marked ok-as-delegate. */ ++ if (header_enc != NULL && (server->attributes & KRB5_KDB_OK_AS_DELEGATE)) ++ flags |= TKT_FLG_OK_AS_DELEGATE; ++ ++ /* Unset PROXIABLE if it is disallowed. */ ++ if (client != NULL && (client->attributes & KRB5_KDB_DISALLOW_PROXIABLE)) ++ flags &= ~TKT_FLG_PROXIABLE; ++ if (server->attributes & KRB5_KDB_DISALLOW_PROXIABLE) ++ flags &= ~TKT_FLG_PROXIABLE; ++ if (header_enc != NULL && !(header_enc->flags & TKT_FLG_PROXIABLE)) ++ flags &= ~TKT_FLG_PROXIABLE; ++ ++ /* Unset FORWARDABLE if it is disallowed. */ ++ if (client != NULL && (client->attributes & KRB5_KDB_DISALLOW_FORWARDABLE)) ++ flags &= ~TKT_FLG_FORWARDABLE; ++ if (server->attributes & KRB5_KDB_DISALLOW_FORWARDABLE) ++ flags &= ~TKT_FLG_FORWARDABLE; ++ if (header_enc != NULL && !(header_enc->flags & TKT_FLG_FORWARDABLE)) ++ flags &= ~TKT_FLG_FORWARDABLE; ++ ++ /* We don't currently handle issuing anonymous tickets based on ++ * non-anonymous ones. */ ++ if (header_enc != NULL && !(header_enc->flags & TKT_FLG_ANONYMOUS)) ++ flags &= ~TKT_FLG_ANONYMOUS; ++ ++ return flags; + } + + /* Return KRB5KDC_ERR_POLICY if indicators does not contain the required auth +diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h +index 25077cbf5..1314bdd58 100644 +--- a/src/kdc/kdc_util.h ++++ b/src/kdc/kdc_util.h +@@ -85,16 +85,15 @@ validate_as_request (kdc_realm_t *, krb5_kdc_req *, krb5_db_entry, + krb5_db_entry, krb5_timestamp, + const char **, krb5_pa_data ***); + +-int +-validate_forwardable(krb5_kdc_req *, krb5_db_entry, +- krb5_db_entry, krb5_timestamp, +- const char **); +- + int + validate_tgs_request (kdc_realm_t *, krb5_kdc_req *, krb5_db_entry, + krb5_ticket *, krb5_timestamp, + const char **, krb5_pa_data ***); + ++krb5_flags ++get_ticket_flags(krb5_flags reqflags, krb5_db_entry *client, ++ krb5_db_entry *server, krb5_enc_tkt_part *header_enc); ++ + krb5_error_code + check_indicators(krb5_context context, krb5_db_entry *server, + krb5_data *const *indicators); +diff --git a/src/kdc/tgs_policy.c b/src/kdc/tgs_policy.c +index 907fcd330..554345ba5 100644 +--- a/src/kdc/tgs_policy.c ++++ b/src/kdc/tgs_policy.c +@@ -63,9 +63,9 @@ static check_tgs_svc_pol_fn * const svc_pol_fns[] = { + }; + + static const struct tgsflagrule tgsflagrules[] = { +- { (KDC_OPT_FORWARDED | KDC_OPT_FORWARDABLE), TKT_FLG_FORWARDABLE, ++ { KDC_OPT_FORWARDED, TKT_FLG_FORWARDABLE, + "TGT NOT FORWARDABLE", KDC_ERR_BADOPTION }, +- { (KDC_OPT_PROXY | KDC_OPT_PROXIABLE), TKT_FLG_PROXIABLE, ++ { KDC_OPT_PROXY, TKT_FLG_PROXIABLE, + "TGT NOT PROXIABLE", KDC_ERR_BADOPTION }, + { (KDC_OPT_ALLOW_POSTDATE | KDC_OPT_POSTDATED), TKT_FLG_MAY_POSTDATE, + "TGT NOT POSTDATABLE", KDC_ERR_BADOPTION }, +@@ -98,12 +98,8 @@ check_tgs_opts(krb5_kdc_req *req, krb5_ticket *tkt, const char **status) + } + + static const struct tgsflagrule svcdenyrules[] = { +- { KDC_OPT_FORWARDABLE, KRB5_KDB_DISALLOW_FORWARDABLE, +- "NON-FORWARDABLE TICKET", KDC_ERR_POLICY }, + { KDC_OPT_RENEWABLE, KRB5_KDB_DISALLOW_RENEWABLE, + "NON-RENEWABLE TICKET", KDC_ERR_POLICY }, +- { KDC_OPT_PROXIABLE, KRB5_KDB_DISALLOW_PROXIABLE, +- "NON-PROXIABLE TICKET", KDC_ERR_POLICY }, + { KDC_OPT_ALLOW_POSTDATE, KRB5_KDB_DISALLOW_POSTDATED, + "NON-POSTDATABLE TICKET", KDC_ERR_CANNOT_POSTDATE }, + { KDC_OPT_ENC_TKT_IN_SKEY, KRB5_KDB_DISALLOW_DUP_SKEY, +diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in +index c96c5d6b7..d2a37c616 100644 +--- a/src/tests/Makefile.in ++++ b/src/tests/Makefile.in +@@ -171,6 +171,7 @@ check-pytests: unlockiter + $(RUNPYTEST) $(srcdir)/t_y2038.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_kdcpolicy.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_u2u.py $(PYTESTFLAGS) ++ $(RUNPYTEST) $(srcdir)/t_kdcoptions.py $(PYTESTFLAGS) + + clean: + $(RM) adata etinfo forward gcred hist hooks hrealm icinterleave icred +diff --git a/src/tests/gcred.c b/src/tests/gcred.c +index cb0ae6af5..b14e4fc9a 100644 +--- a/src/tests/gcred.c ++++ b/src/tests/gcred.c +@@ -66,20 +66,32 @@ main(int argc, char **argv) + krb5_principal client, server; + krb5_ccache ccache; + krb5_creds in_creds, *creds; ++ krb5_flags options = 0; + char *name; ++ int c; + + check(krb5_init_context(&ctx)); + +- /* Parse arguments. */ +- assert(argc == 3); +- check(krb5_parse_name(ctx, argv[2], &server)); +- if (strcmp(argv[1], "unknown") == 0) ++ while ((c = getopt(argc, argv, "f")) != -1) { ++ switch (c) { ++ case 'f': ++ options |= KRB5_GC_FORWARDABLE; ++ break; ++ default: ++ abort(); ++ } ++ } ++ argc -= optind; ++ argv += optind; ++ assert(argc == 2); ++ check(krb5_parse_name(ctx, argv[1], &server)); ++ if (strcmp(argv[0], "unknown") == 0) + server->type = KRB5_NT_UNKNOWN; +- else if (strcmp(argv[1], "principal") == 0) ++ else if (strcmp(argv[0], "principal") == 0) + server->type = KRB5_NT_PRINCIPAL; +- else if (strcmp(argv[1], "srv-inst") == 0) ++ else if (strcmp(argv[0], "srv-inst") == 0) + server->type = KRB5_NT_SRV_INST; +- else if (strcmp(argv[1], "srv-hst") == 0) ++ else if (strcmp(argv[0], "srv-hst") == 0) + server->type = KRB5_NT_SRV_HST; + else + abort(); +@@ -89,7 +101,7 @@ main(int argc, char **argv) + memset(&in_creds, 0, sizeof(in_creds)); + in_creds.client = client; + in_creds.server = server; +- check(krb5_get_credentials(ctx, 0, ccache, &in_creds, &creds)); ++ check(krb5_get_credentials(ctx, options, ccache, &in_creds, &creds)); + check(krb5_unparse_name(ctx, creds->server, &name)); + printf("%s\n", name); + +diff --git a/src/tests/t_kdcoptions.py b/src/tests/t_kdcoptions.py +new file mode 100644 +index 000000000..7ec57508c +--- /dev/null ++++ b/src/tests/t_kdcoptions.py +@@ -0,0 +1,100 @@ ++from k5test import * ++import re ++ ++# KDC option test coverage notes: ++# ++# FORWARDABLE here ++# FORWARDED no test ++# PROXIABLE here ++# PROXY no test ++# ALLOW_POSTDATE no test ++# POSTDATED no test ++# RENEWABLE t_renew.py ++# CNAME_IN_ADDL_TKT gssapi/t_s4u.py ++# CANONICALIZE t_kdb.py and various other tests ++# REQUEST_ANONYMOUS t_pkinit.py ++# DISABLE_TRANSITED_CHECK no test ++# RENEWABLE_OK t_renew.py ++# ENC_TKT_IN_SKEY t_u2u.py ++# RENEW t_renew.py ++# VALIDATE no test ++ ++# Run klist -f and return the flags on the ticket for svcprinc. ++def get_flags(realm, svcprinc): ++ grab_flags = False ++ for line in realm.run([klist, '-f']).splitlines(): ++ if grab_flags: ++ return re.findall(r'Flags: ([a-zA-Z]*)', line)[0] ++ grab_flags = line.endswith(svcprinc) ++ ++ ++# Get the flags on the ticket for svcprinc, and check for an expected ++# element and an expected-absent element, either of which can be None. ++def check_flags(realm, svcprinc, expected_flag, expected_noflag): ++ flags = get_flags(realm, svcprinc) ++ if expected_flag is not None and not expected_flag in flags: ++ fail('expected flag ' + expected_flag) ++ if expected_noflag is not None and expected_noflag in flags: ++ fail('did not expect flag ' + expected_noflag) ++ ++ ++# Run kinit with the given flags, and check the flags on the resulting ++# TGT. ++def kinit_check_flags(realm, flags, expected_flag, expected_noflag): ++ realm.kinit(realm.user_princ, password('user'), flags) ++ check_flags(realm, realm.krbtgt_princ, expected_flag, expected_noflag) ++ ++ ++# Run kinit with kflags. Then get credentials for the host principal ++# with gflags, and check the flags on the resulting ticket. ++def gcred_check_flags(realm, kflags, gflags, expected_flag, expected_noflag): ++ realm.kinit(realm.user_princ, password('user'), kflags) ++ realm.run(['./gcred'] + gflags + ['unknown', realm.host_princ]) ++ check_flags(realm, realm.host_princ, expected_flag, expected_noflag) ++ ++ ++realm = K5Realm() ++ ++mark('proxiable (AS)') ++kinit_check_flags(realm, [], None, 'P') ++kinit_check_flags(realm, ['-p'], 'P', None) ++realm.run([kadminl, 'modprinc', '-allow_proxiable', realm.user_princ]) ++kinit_check_flags(realm, ['-p'], None, 'P') ++realm.run([kadminl, 'modprinc', '+allow_proxiable', realm.user_princ]) ++realm.run([kadminl, 'modprinc', '-allow_proxiable', realm.krbtgt_princ]) ++kinit_check_flags(realm, ['-p'], None, 'P') ++realm.run([kadminl, 'modprinc', '+allow_proxiable', realm.krbtgt_princ]) ++ ++mark('proxiable (TGS)') ++gcred_check_flags(realm, [], [], None, 'P') ++gcred_check_flags(realm, ['-p'], [], 'P', None) ++ ++# Not tested: PROXIABLE option set with a non-proxiable TGT (because ++# there is no krb5_get_credentials() flag to request this; would ++# expect a non-proxiable ticket). ++ ++# Not tested: proxiable TGT but PROXIABLE flag not set (because we ++# internally set the PROXIABLE option when using a proxiable TGT; ++# would expect a non-proxiable ticket). ++ ++mark('forwardable (AS)') ++kinit_check_flags(realm, [], None, 'F') ++kinit_check_flags(realm, ['-f'], 'F', None) ++realm.run([kadminl, 'modprinc', '-allow_forwardable', realm.user_princ]) ++kinit_check_flags(realm, ['-f'], None, 'F') ++realm.run([kadminl, 'modprinc', '+allow_forwardable', realm.user_princ]) ++realm.run([kadminl, 'modprinc', '-allow_forwardable', realm.krbtgt_princ]) ++kinit_check_flags(realm, ['-f'], None, 'F') ++realm.run([kadminl, 'modprinc', '+allow_forwardable', realm.krbtgt_princ]) ++ ++mark('forwardable (TGS)') ++realm.kinit(realm.user_princ, password('user')) ++gcred_check_flags(realm, [], [], None, 'F') ++gcred_check_flags(realm, [], ['-f'], None, 'F') ++gcred_check_flags(realm, ['-f'], [], 'F', None) ++ ++# Not tested: forwardable TGT but FORWARDABLE flag not set (because we ++# internally set the FORWARDABLE option when using a forwardable TGT; ++# would expect a non-proxiable ticket). ++ ++success('KDC option tests') diff --git a/krb5.spec b/krb5.spec index b4f962b..99818a0 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 13%{?dist} +Release: 14%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz @@ -85,6 +85,8 @@ Patch112: Remove-confvalidator-utility.patch Patch113: Remove-ovsec_adm_export-dump-format-support.patch Patch114: Fix-potential-close-1-in-cc_file.c.patch Patch115: Check-more-errors-in-OpenSSL-crypto-backend.patch +Patch116: Clear-forwardable-flag-instead-of-denying-request.patch +Patch117: Add-dns_canonicalize_hostname-fallback-support.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -721,6 +723,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Apr 24 2019 Robbie Harwood - 1.17-14 +- Add dns_canonicalize_hostname=fallback support + * Wed Apr 24 2019 Robbie Harwood - 1.17-13 - Check more errors in OpenSSL crypto backend From cdfd42332f614f3bb756a15c29d786ce290b2ceb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 24 Apr 2019 17:50:42 +0000 Subject: [PATCH 099/304] Get that squeaky rpmlint clean --- krb5.rpmlintrc | 14 +++++ krb5.spec | 152 ++++++++++++++++++++----------------------------- 2 files changed, 77 insertions(+), 89 deletions(-) create mode 100644 krb5.rpmlintrc diff --git a/krb5.rpmlintrc b/krb5.rpmlintrc new file mode 100644 index 0000000..ad8e989 --- /dev/null +++ b/krb5.rpmlintrc @@ -0,0 +1,14 @@ +addFilter(r'spelling-error .* en_US (unencrypted)') +addFilter(r'Source3: krb5-1.17-pdfs.tar') +addFilter(r'hidden-file-or-dir /usr/share/man/man5/.k5identity.5.gz') +addFilter(r'non-standard-dir-in-var kerberos') +addFilter(r'explicit-lib-dependency libverto-module-base') +addFilter(r'shared-lib-calls-exit') +addFilter(r'dir-or-file-in-var-run /var/run/krb5kdc') +addFilter(r'devel-file-in-non-devel-package /usr/lib64/libkadm5(clnt|srv)_mit.so') +addFilter(r'non-readable /var/kerberos/krb5kdc') +addFilter(r'devel-file-in-non-devel-package /usr/lib64/libkdb_ldap.so') +addFilter(r'/usr/bin/ksu') +addFilter(r'no-documentation') +addFilter(r'invalid-directory-reference .*pkgconfig') +addFilter(r'incoherent-logrotate-file /etc/logrotate.d/k') diff --git a/krb5.spec b/krb5.spec index 99818a0..1981f28 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,12 +18,12 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 14%{?dist} +Release: 15%{?dist} # lookaside-cached sources; two downloads and a build artifact -Source0: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz +Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz # rharwood has trust path to signing key and verifies on check-in -Source1: https://web.mit.edu/kerberos/dist/krb5/1.16/krb5-%{version}%{prerelease}.tar.gz.asc +Source1: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz.asc # This source is generated during the build because sphinx doesn't # give me architecture-deterministic documentation builds. # To override this behavior (e.g., new upstream version), do: @@ -190,15 +190,6 @@ Requires: /usr/share/dict/words # for run-time, and for parts of the test suite BuildRequires: libverto-module-base Requires: libverto-module-base -%ifarch x86_64 -Obsoletes: %{name}-server-%{version}-%{release}.i686 -%endif -%ifarch ppc64 -Obsoletes: %{name}-server-%{version}-%{release}.ppc -%endif -%ifarch s390x -Obsoletes: %{name}-server-%{version}-%{release}.s390 -%endif Requires: libkadm5%{?_isa} = %{version}-%{release} %description server @@ -213,15 +204,6 @@ Summary: The LDAP storage plugin for the Kerberos 5 KDC Requires: %{name}-server%{?_isa} = %{version}-%{release} Requires: %{name}-libs%{?_isa} = %{version}-%{release} Requires: libkadm5%{?_isa} = %{version}-%{release} -%ifarch x86_64 -Obsoletes: %{name}-server-ldap-%{version}-%{release}.i686 -%endif -%ifarch ppc64 -Obsoletes: %{name}-server-ldap-%{version}-%{release}.ppc -%endif -%ifarch s390x -Obsoletes: %{name}-server-ldap-%{version}-%{release}.s390 -%endif %description server-ldap Kerberos is a network authentication system. The krb5-server package @@ -272,9 +254,7 @@ cat > '60kerberos.ldif' << EOF # This is a variation on kerberos.ldif which 389 Directory Server will like. dn: cn=schema EOF -egrep -iv '(^$|^dn:|^changetype:|^add:)' $inldif | \ -sed -r 's,^ , ,g' | \ -sed -r 's,^ , ,g' >> 60kerberos.ldif +grep -Eiv '(^$|^dn:|^changetype:|^add:)' $inldif >> 60kerberos.ldif touch -r $inldif 60kerberos.ldif # Rebuild the configure scripts. @@ -316,32 +296,32 @@ INCLUDES=-I%{_includedir}/et CFLAGS="`echo $RPM_OPT_FLAGS $DEFINES $INCLUDES -fPIC -fno-strict-aliasing -fstack-protector-all`" CPPFLAGS="`echo $DEFINES $INCLUDES`" %configure \ - CC="%{__cc}" \ - CFLAGS="$CFLAGS" \ - CPPFLAGS="$CPPFLAGS" \ - SS_LIB="-lss" \ - --enable-shared \ - --localstatedir=%{_var}/kerberos \ - --disable-rpath \ - --without-krb5-config \ - --with-system-et \ - --with-system-ss \ - --with-netlib=-lresolv \ - --with-tcl \ - --enable-dns-for-realm \ - --with-ldap \ + CC="%{__cc}" \ + CFLAGS="$CFLAGS" \ + CPPFLAGS="$CPPFLAGS" \ + SS_LIB="-lss" \ + --enable-shared \ + --localstatedir=%{_var}/kerberos \ + --disable-rpath \ + --without-krb5-config \ + --with-system-et \ + --with-system-ss \ + --with-netlib=-lresolv \ + --with-tcl \ + --enable-dns-for-realm \ + --with-ldap \ %if %{WITH_DIRSRV} - --with-dirsrv-account-locking \ + --with-dirsrv-account-locking \ %endif - --enable-pkinit \ - --with-crypto-impl=openssl \ - --with-pkinit-crypto-impl=openssl \ - --with-tls-impl=openssl \ - --with-system-verto \ - --with-pam \ - --with-selinux \ - --with-prng-alg=os \ - || (cat config.log; exit 1) + --enable-pkinit \ + --with-crypto-impl=openssl \ + --with-pkinit-crypto-impl=openssl \ + --with-tls-impl=openssl \ + --with-system-verto \ + --with-pam \ + --with-selinux \ + --with-prng-alg=os \ + || (cat config.log; exit 1) # Now build it. make popd @@ -350,7 +330,7 @@ popd configured_kdcrundir=`grep KDC_RUN_DIR src/include/osconf.h | awk '{print $NF}'` configured_kdcrundir=`eval echo $configured_kdcrundir` if test "$configured_kdcrundir" != %{_localstatedir}/run/krb5kdc ; then - exit 1 + exit 1 fi # Build the docs. @@ -365,11 +345,11 @@ sphinx-build -a -b latex -t pathsubs doc build-pdf for pdf in admin appdev basic build plugindev user ; do test -s build-pdf/$pdf.pdf || make -C build-pdf done -# new krb5-%{version}-pdf +# new krb5-version-pdf tar -cf "krb5-%{version}%{prerelease}-pdfs.tar.new" build-pdf/*.pdf # We need to cut off any access to locally-running nameservers, too. -%{__cc} -fPIC -shared -o noport.so -Wall -Wextra $RPM_SOURCE_DIR/noport.c +%{__cc} -fPIC -shared -o noport.so -Wall -Wextra %{SOURCE100} %check mkdir nss_wrapper @@ -441,42 +421,38 @@ grep default_ccache_name $RPM_BUILD_ROOT/etc/krb5.conf # Server init scripts (krb5kdc,kadmind,kpropd) and their sysconfig files. mkdir -p $RPM_BUILD_ROOT%{_unitdir} for unit in \ - %{SOURCE5}\ - %{SOURCE4} \ - %{SOURCE2} ; do - # In the past, the init script was supposed to be named after the - # service that the started daemon provided. Changing their names - # is an upgrade-time problem I'm in no hurry to deal with. - install -pm 644 ${unit} $RPM_BUILD_ROOT%{_unitdir} + %{SOURCE5}\ + %{SOURCE4} \ + %{SOURCE2} ; do + # In the past, the init script was supposed to be named after the service + # that the started daemon provided. Changing their names is an + # upgrade-time problem I'm in no hurry to deal with. + install -pm 644 ${unit} $RPM_BUILD_ROOT%{_unitdir} done mkdir -p $RPM_BUILD_ROOT/%{_tmpfilesdir} install -pm 644 %{SOURCE39} $RPM_BUILD_ROOT/%{_tmpfilesdir}/ mkdir -p $RPM_BUILD_ROOT/%{_localstatedir}/run/krb5kdc mkdir -p $RPM_BUILD_ROOT/etc/sysconfig -for sysconfig in \ - %{SOURCE19}\ - %{SOURCE20}\ - %{SOURCE21} ; do - install -pm 644 ${sysconfig} \ - $RPM_BUILD_ROOT/etc/sysconfig/`basename ${sysconfig} .sysconfig` +for sysconfig in %{SOURCE19} %{SOURCE20} %{SOURCE21} ; do + install -pm 644 ${sysconfig} \ + $RPM_BUILD_ROOT/etc/sysconfig/`basename ${sysconfig} .sysconfig` done # logrotate configuration files mkdir -p $RPM_BUILD_ROOT/etc/logrotate.d/ for logrotate in \ - %{SOURCE33} \ - %{SOURCE34} ; do - install -pm 644 ${logrotate} \ - $RPM_BUILD_ROOT/etc/logrotate.d/`basename ${logrotate} .logrotate` + %{SOURCE33} \ + %{SOURCE34} ; do + install -pm 644 ${logrotate} \ + $RPM_BUILD_ROOT/etc/logrotate.d/`basename ${logrotate} .logrotate` done # PAM configuration files. mkdir -p $RPM_BUILD_ROOT/etc/pam.d/ -for pam in \ - %{SOURCE29} ; do - install -pm 644 ${pam} \ - $RPM_BUILD_ROOT/etc/pam.d/`basename ${pam} .pamd` +for pam in %{SOURCE29} ; do + install -pm 644 ${pam} \ + $RPM_BUILD_ROOT/etc/pam.d/`basename ${pam} .pamd` done # Plug-in directories. @@ -497,19 +473,24 @@ sed -r -i -e 's|^libdir=/usr/lib(64)?$|libdir=/usr/lib|g' $RPM_BUILD_ROOT%{_bind sed -r -i -e "s/-specs=\/.+?\/redhat-hardened-ld//g" $RPM_BUILD_ROOT%{_bindir}/krb5-config if [[ "$(< $RPM_BUILD_ROOT%{_bindir}/krb5-config )" == *redhat-hardened-ld* ]] ; then - printf '# redhat-hardened-ld for krb5-config failed' 1>&2 - exit 1 + printf '# redhat-hardened-ld for krb5-config failed' 1>&2 + exit 1 fi # Install processed man pages. for section in 1 5 8 ; do - install -m 644 build-man/*.${section} \ - $RPM_BUILD_ROOT/%{_mandir}/man${section}/ + install -m 644 build-man/*.${section} \ + $RPM_BUILD_ROOT/%{_mandir}/man${section}/ done -# This script just tells you to send bug reports to krb5-bugs@mit.edu, but -# since we don't have a man page for it, just drop it. +# I'm tired of warnings about these not having man pages rm -- "$RPM_BUILD_ROOT/%{_sbindir}/krb5-send-pr" +rm -- "$RPM_BUILD_ROOT/%{_sbindir}/sim_server" +rm -- "$RPM_BUILD_ROOT/%{_sbindir}/gss-server" +rm -- "$RPM_BUILD_ROOT/%{_sbindir}/uuserver" +rm -- "$RPM_BUILD_ROOT/%{_bindir}/sim_client" +rm -- "$RPM_BUILD_ROOT/%{_bindir}/gss-client" +rm -- "$RPM_BUILD_ROOT/%{_bindir}/uuclient" # These files are already packaged elsewhere rm -- "$RPM_BUILD_ROOT/%{_docdir}/krb5-libs/examples/kdc.conf" @@ -704,16 +685,6 @@ exit 0 %{_bindir}/krb5-config %{_mandir}/man1/krb5-config.1* -# Protocol test clients. -%{_bindir}/sim_client -%{_bindir}/gss-client -%{_bindir}/uuclient - -# Protocol test servers. -%{_sbindir}/sim_server -%{_sbindir}/gss-server -%{_sbindir}/uuserver - %files -n libkadm5 %{_libdir}/libkadm5clnt.so %{_libdir}/libkadm5clnt_mit.so @@ -723,6 +694,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Apr 24 2019 Robbie Harwood - 1.17-15 +- Fix us up real nice with rpmlint + * Wed Apr 24 2019 Robbie Harwood - 1.17-14 - Add dns_canonicalize_hostname=fallback support @@ -2429,7 +2403,7 @@ exit 0 * Thu Feb 25 2010 Nalin Dahyabhai - 1.7.1-4 - move the package changelog to the end to match the usual style (jdennis) -- scrub out references to $RPM_SOURCE_DIR (jdennis) +- scrub out references to RPM_SOURCE_DIR (jdennis) - include a symlink to the readme with the name LICENSE so that people can find it more easily (jdennis) From 4c5654d0fb791f1a0204b0d77623cc94b747c5eb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 1 May 2019 12:47:31 -0400 Subject: [PATCH 100/304] Use secure_getenv() where appropriate --- Use-secure_getenv-where-appropriate.patch | 240 ++++++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 245 insertions(+), 1 deletion(-) create mode 100644 Use-secure_getenv-where-appropriate.patch diff --git a/Use-secure_getenv-where-appropriate.patch b/Use-secure_getenv-where-appropriate.patch new file mode 100644 index 0000000..708548d --- /dev/null +++ b/Use-secure_getenv-where-appropriate.patch @@ -0,0 +1,240 @@ +From 8987708dbafbb7d3eb743f06d9fbef40a04275e3 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 24 Apr 2019 16:19:50 -0400 +Subject: [PATCH] Use secure_getenv() where appropriate + +ticket: 8800 +(cherry picked from commit d439e370b70f7af4ed2da9c692a3be7dcf7b4ac6) +--- + src/lib/kadm5/alt_prof.c | 2 +- + src/lib/krb5/ccache/ccselect_k5identity.c | 2 +- + src/lib/krb5/os/ccdefname.c | 2 +- + src/lib/krb5/os/expand_path.c | 2 +- + src/lib/krb5/os/init_os_ctx.c | 6 +++--- + src/lib/krb5/os/ktdefname.c | 4 ++-- + src/lib/krb5/os/trace.c | 2 +- + src/lib/krb5/rcache/rc_base.c | 4 ++-- + src/lib/krb5/rcache/rc_io.c | 4 ++-- + src/plugins/preauth/pkinit/pkinit_identity.c | 13 ++++--------- + src/plugins/tls/k5tls/openssl.c | 2 +- + src/util/profile/prof_file.c | 2 +- + 12 files changed, 20 insertions(+), 25 deletions(-) + +diff --git a/src/lib/kadm5/alt_prof.c b/src/lib/kadm5/alt_prof.c +index 3f6b53651..5531a10fb 100644 +--- a/src/lib/kadm5/alt_prof.c ++++ b/src/lib/kadm5/alt_prof.c +@@ -73,7 +73,7 @@ krb5_aprof_init(char *fname, char *envname, krb5_pointer *acontextp) + ret = krb5_get_default_config_files(&filenames); + if (ret) + return ret; +- if (envname == NULL || (kdc_config = getenv(envname)) == NULL) ++ if (envname == NULL || (kdc_config = secure_getenv(envname)) == NULL) + kdc_config = fname; + k5_buf_init_dynamic(&buf); + if (kdc_config) +diff --git a/src/lib/krb5/ccache/ccselect_k5identity.c b/src/lib/krb5/ccache/ccselect_k5identity.c +index bee541658..b2dbf8a09 100644 +--- a/src/lib/krb5/ccache/ccselect_k5identity.c ++++ b/src/lib/krb5/ccache/ccselect_k5identity.c +@@ -135,7 +135,7 @@ get_homedir(krb5_context context) + struct passwd pwx, *pwd; + + if (!context->profile_secure) +- homedir = getenv("HOME"); ++ homedir = secure_getenv("HOME"); + + if (homedir == NULL) { + if (k5_getpwuid_r(geteuid(), &pwx, pwbuf, sizeof(pwbuf), &pwd) != 0) +diff --git a/src/lib/krb5/os/ccdefname.c b/src/lib/krb5/os/ccdefname.c +index e5cb3e44c..233173d35 100644 +--- a/src/lib/krb5/os/ccdefname.c ++++ b/src/lib/krb5/os/ccdefname.c +@@ -300,7 +300,7 @@ krb5_cc_default_name(krb5_context context) + return os_ctx->default_ccname; + + /* Try the environment variable first. */ +- envstr = getenv(KRB5_ENV_CCNAME); ++ envstr = secure_getenv(KRB5_ENV_CCNAME); + if (envstr != NULL) { + os_ctx->default_ccname = strdup(envstr); + return os_ctx->default_ccname; +diff --git a/src/lib/krb5/os/expand_path.c b/src/lib/krb5/os/expand_path.c +index 61fb23459..4ce466c19 100644 +--- a/src/lib/krb5/os/expand_path.c ++++ b/src/lib/krb5/os/expand_path.c +@@ -280,7 +280,7 @@ expand_temp_folder(krb5_context context, PTYPE param, const char *postfix, + const char *p = NULL; + + if (context == NULL || !context->profile_secure) +- p = getenv("TMPDIR"); ++ p = secure_getenv("TMPDIR"); + *ret = strdup((p != NULL) ? p : "/tmp"); + if (*ret == NULL) + return ENOMEM; +diff --git a/src/lib/krb5/os/init_os_ctx.c b/src/lib/krb5/os/init_os_ctx.c +index 09809b932..3aa86f4ad 100644 +--- a/src/lib/krb5/os/init_os_ctx.c ++++ b/src/lib/krb5/os/init_os_ctx.c +@@ -243,7 +243,7 @@ os_get_default_config_files(profile_filespec_t **pfiles, krb5_boolean secure) + char *name = 0; + + if (!secure) { +- char *env = getenv("KRB5_CONFIG"); ++ char *env = secure_getenv("KRB5_CONFIG"); + if (env) { + name = strdup(env); + if (!name) return ENOMEM; +@@ -298,7 +298,7 @@ os_get_default_config_files(profile_filespec_t **pfiles, krb5_boolean secure) + if (secure) { + filepath = DEFAULT_SECURE_PROFILE_PATH; + } else { +- filepath = getenv("KRB5_CONFIG"); ++ filepath = secure_getenv("KRB5_CONFIG"); + if (!filepath) filepath = DEFAULT_PROFILE_PATH; + } + +@@ -344,7 +344,7 @@ add_kdc_config_file(profile_filespec_t **pfiles) + size_t count = 0; + profile_filespec_t *newfiles; + +- file = getenv(KDC_PROFILE_ENV); ++ file = secure_getenv(KDC_PROFILE_ENV); + if (file == NULL) + file = DEFAULT_KDC_PROFILE; + +diff --git a/src/lib/krb5/os/ktdefname.c b/src/lib/krb5/os/ktdefname.c +index ffbd14d51..fbe4e98b4 100644 +--- a/src/lib/krb5/os/ktdefname.c ++++ b/src/lib/krb5/os/ktdefname.c +@@ -42,7 +42,7 @@ kt_default_name(krb5_context context, char **name_out) + *name_out = strdup(krb5_overridekeyname); + return (*name_out == NULL) ? ENOMEM : 0; + } else if (context->profile_secure == FALSE && +- (str = getenv("KRB5_KTNAME")) != NULL) { ++ (str = secure_getenv("KRB5_KTNAME")) != NULL) { + *name_out = strdup(str); + return (*name_out == NULL) ? ENOMEM : 0; + } else if (profile_get_string(context->profile, KRB5_CONF_LIBDEFAULTS, +@@ -63,7 +63,7 @@ k5_kt_client_default_name(krb5_context context, char **name_out) + char *str; + + if (context->profile_secure == FALSE && +- (str = getenv("KRB5_CLIENT_KTNAME")) != NULL) { ++ (str = secure_getenv("KRB5_CLIENT_KTNAME")) != NULL) { + *name_out = strdup(str); + return (*name_out == NULL) ? ENOMEM : 0; + } else if (profile_get_string(context->profile, KRB5_CONF_LIBDEFAULTS, +diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c +index 40a9e7b10..85dbfeb47 100644 +--- a/src/lib/krb5/os/trace.c ++++ b/src/lib/krb5/os/trace.c +@@ -389,7 +389,7 @@ k5_init_trace(krb5_context context) + { + const char *filename; + +- filename = getenv("KRB5_TRACE"); ++ filename = secure_getenv("KRB5_TRACE"); + if (filename) + (void) krb5_set_trace_filename(context, filename); + } +diff --git a/src/lib/krb5/rcache/rc_base.c b/src/lib/krb5/rcache/rc_base.c +index 373ac3046..9fa46432d 100644 +--- a/src/lib/krb5/rcache/rc_base.c ++++ b/src/lib/krb5/rcache/rc_base.c +@@ -107,7 +107,7 @@ char * + krb5_rc_default_type(krb5_context context) + { + char *s; +- if ((s = getenv("KRB5RCACHETYPE"))) ++ if ((s = secure_getenv("KRB5RCACHETYPE"))) + return s; + else + return "dfl"; +@@ -117,7 +117,7 @@ char * + krb5_rc_default_name(krb5_context context) + { + char *s; +- if ((s = getenv("KRB5RCACHENAME"))) ++ if ((s = secure_getenv("KRB5RCACHENAME"))) + return s; + else + return (char *) 0; +diff --git a/src/lib/krb5/rcache/rc_io.c b/src/lib/krb5/rcache/rc_io.c +index 35fa14a1f..1800460b2 100644 +--- a/src/lib/krb5/rcache/rc_io.c ++++ b/src/lib/krb5/rcache/rc_io.c +@@ -48,13 +48,13 @@ getdir(void) + { + char *dir; + +- if (!(dir = getenv("KRB5RCACHEDIR"))) { ++ if (!(dir = secure_getenv("KRB5RCACHEDIR"))) { + #if defined(_WIN32) + if (!(dir = getenv("TEMP"))) + if (!(dir = getenv("TMP"))) + dir = "C:"; + #else +- if (!(dir = getenv("TMPDIR"))) { ++ if (!(dir = secure_getenv("TMPDIR"))) { + #ifdef RCTMPDIR + dir = RCTMPDIR; + #else +diff --git a/src/plugins/preauth/pkinit/pkinit_identity.c b/src/plugins/preauth/pkinit/pkinit_identity.c +index 8cd3fc640..b89c5d015 100644 +--- a/src/plugins/preauth/pkinit/pkinit_identity.c ++++ b/src/plugins/preauth/pkinit/pkinit_identity.c +@@ -29,15 +29,9 @@ + * SUCH DAMAGES. + */ + +-#include +-#include +-#include +-#include +-#include +-#include +-#include +- + #include "pkinit.h" ++#include ++#include + + static void + free_list(char **list) +@@ -430,7 +424,8 @@ process_option_identity(krb5_context context, + switch (idtype) { + case IDTYPE_ENVVAR: + return process_option_identity(context, plg_cryptoctx, req_cryptoctx, +- idopts, id_cryptoctx, getenv(residual)); ++ idopts, id_cryptoctx, ++ secure_getenv(residual)); + break; + case IDTYPE_FILE: + retval = parse_fs_options(context, idopts, residual); +diff --git a/src/plugins/tls/k5tls/openssl.c b/src/plugins/tls/k5tls/openssl.c +index 822632c90..76a43b3cd 100644 +--- a/src/plugins/tls/k5tls/openssl.c ++++ b/src/plugins/tls/k5tls/openssl.c +@@ -399,7 +399,7 @@ load_anchor(SSL_CTX *ctx, const char *location) + } else if (strncmp(location, "DIR:", 4) == 0) { + return load_anchor_dir(store, location + 4); + } else if (strncmp(location, "ENV:", 4) == 0) { +- envloc = getenv(location + 4); ++ envloc = secure_getenv(location + 4); + if (envloc == NULL) + return ENOENT; + return load_anchor(ctx, envloc); +diff --git a/src/util/profile/prof_file.c b/src/util/profile/prof_file.c +index 0dcb6b543..79f9500f6 100644 +--- a/src/util/profile/prof_file.c ++++ b/src/util/profile/prof_file.c +@@ -183,7 +183,7 @@ errcode_t profile_open_file(const_profile_filespec_t filespec, + prf->magic = PROF_MAGIC_FILE; + + if (filespec[0] == '~' && filespec[1] == '/') { +- home_env = getenv("HOME"); ++ home_env = secure_getenv("HOME"); + #ifdef HAVE_PWD_H + if (home_env == NULL) { + uid_t uid; diff --git a/krb5.spec b/krb5.spec index 1981f28..59cbaf8 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 15%{?dist} +Release: 16%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -87,6 +87,7 @@ Patch114: Fix-potential-close-1-in-cc_file.c.patch Patch115: Check-more-errors-in-OpenSSL-crypto-backend.patch Patch116: Clear-forwardable-flag-instead-of-denying-request.patch Patch117: Add-dns_canonicalize_hostname-fallback-support.patch +Patch118: Use-secure_getenv-where-appropriate.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -694,6 +695,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed May 01 2019 Robbie Harwood - 1.17-16 +- Use secure_getenv() where appropriate + * Wed Apr 24 2019 Robbie Harwood - 1.17-15 - Fix us up real nice with rpmlint From 85664dde3d27769b4e9b4237815d06869cb40dc5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 3 May 2019 18:36:31 +0000 Subject: [PATCH 101/304] Move krb5-kdb-version provide into krb5-server for freeipa --- krb5.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/krb5.spec b/krb5.spec index 59cbaf8..3fab1b4 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 16%{?dist} +Release: 17%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -159,7 +159,6 @@ Requires: libkadm5%{?_isa} = %{version}-%{release} Requires: libcom_err-devel Requires: keyutils-libs-devel, libselinux-devel Requires: libverto-devel -Provides: krb5-kdb-version = %{kdbversion} %description devel Kerberos is a network authentication system. The krb5-devel package @@ -192,6 +191,7 @@ Requires: /usr/share/dict/words BuildRequires: libverto-module-base Requires: libverto-module-base Requires: libkadm5%{?_isa} = %{version}-%{release} +Provides: krb5-kdb-version = %{kdbversion} %description server Kerberos is a network authentication system. The krb5-server package @@ -695,6 +695,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri May 03 2019 Robbie Harwood - 1.17-17 +- Move krb5-kdb-version provide into krb5-server for freeipa + * Wed May 01 2019 Robbie Harwood - 1.17-16 - Use secure_getenv() where appropriate From d1b5e24f4c4948c53a8347097d474efe1af2f622 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 14:38:08 -0400 Subject: [PATCH 102/304] Drop --with-pkinit-crypto-impl --- krb5.spec | 1 - 1 file changed, 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 3fab1b4..286cf09 100644 --- a/krb5.spec +++ b/krb5.spec @@ -316,7 +316,6 @@ CPPFLAGS="`echo $DEFINES $INCLUDES`" %endif --enable-pkinit \ --with-crypto-impl=openssl \ - --with-pkinit-crypto-impl=openssl \ --with-tls-impl=openssl \ --with-system-verto \ --with-pam \ From 0b0d802a54971de954e7775350d43086eb559eca Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 10 May 2019 13:50:56 -0400 Subject: [PATCH 103/304] Pull in 2019-05-02 static analysis updates --- ...nonicalize_hostname-fallback-support.patch | 2 +- ...on-and-enctype-flag-for-deprecations.patch | 2 +- ...-alignment-warnings-in-openssl-rc4.c.patch | 63 ++++ ...llocating-a-register-in-zap-assembly.patch | 2 +- ...ore-errors-in-OpenSSL-crypto-backend.patch | 8 +- ...er-comment-for-krb5_cc_start_seq_get.patch | 2 +- ...able-flag-instead-of-denying-request.patch | 2 +- ...alm-change-logic-in-FILE-remove_cred.patch | 2 +- ...emory-leak-in-none-replay-cache-type.patch | 2 +- Fix-potential-close-1-in-cc_file.c.patch | 2 +- Fix-some-return-code-handling-bugs.patch | 103 ++++++ ...5_cc_remove_cred-for-remaining-types.patch | 2 +- ...messages-from-kadmin-change_password.patch | 55 ++++ ...ebug-log-proper-ticket-enctype-names.patch | 2 +- ...ec-always-log-non-permitted-enctypes.patch | 2 +- ...ize-some-data-structure-magic-fields.patch | 55 ++++ ...ype-names-in-KDC-logs-human-readable.patch | 2 +- Mark-deprecated-enctypes-when-used.patch | 2 +- ...exit-path-in-gss_krb5int_copy_ccache.patch | 68 ++++ Properly-size-ifdef-in-k5_cccol_lock.patch | 2 +- ...beros-v4-support-vestiges-from-ccapi.patch | 2 +- ...api-related-comments-in-configure.ac.patch | 2 +- Remove-confvalidator-utility.patch | 2 +- ...ygen-generated-HTML-output-for-ccapi.patch | 2 +- ...admin-RPC-support-for-setting-v4-key.patch | 2 +- Remove-more-dead-code.patch | 276 ++++++++++++++++ ...ovsec_adm_export-dump-format-support.patch | 2 +- Remove-srvtab-support.patch | 2 +- Simplify-SAM-2-as_key-handling.patch | 76 +++++ Simply-OpenSSL-PKCS7-decryption-code.patch | 301 ++++++++++++++++++ Use-secure_getenv-where-appropriate.patch | 2 +- ...7-FIPS-aware-SPAKE-group-negotiation.patch | 42 --- ...1.17-Use-openssl-s-PRNG-in-FIPS-mode.patch | 40 --- ...5-1.17post1-FIPS-with-PRNG-and-SPAKE.patch | 99 +++++- krb5.spec | 17 +- 35 files changed, 1120 insertions(+), 127 deletions(-) create mode 100644 Avoid-alignment-warnings-in-openssl-rc4.c.patch create mode 100644 Fix-some-return-code-handling-bugs.patch create mode 100644 Improve-error-messages-from-kadmin-change_password.patch create mode 100644 Initialize-some-data-structure-magic-fields.patch create mode 100644 Modernize-exit-path-in-gss_krb5int_copy_ccache.patch create mode 100644 Remove-more-dead-code.patch create mode 100644 Simplify-SAM-2-as_key-handling.patch create mode 100644 Simply-OpenSSL-PKCS7-decryption-code.patch delete mode 100644 krb5-1.17-FIPS-aware-SPAKE-group-negotiation.patch delete mode 100644 krb5-1.17-Use-openssl-s-PRNG-in-FIPS-mode.patch rename krb5-1.17-Become-FIPS-aware.patch => krb5-1.17post1-FIPS-with-PRNG-and-SPAKE.patch (66%) diff --git a/Add-dns_canonicalize_hostname-fallback-support.patch b/Add-dns_canonicalize_hostname-fallback-support.patch index 07eb422..188c2b4 100644 --- a/Add-dns_canonicalize_hostname-fallback-support.patch +++ b/Add-dns_canonicalize_hostname-fallback-support.patch @@ -1,4 +1,4 @@ -From 18d45e4b48c363f631b1acd7dac5902351bf1a0e Mon Sep 17 00:00:00 2001 +From 05672fdc2530618441710361daba097bccf51f61 Mon Sep 17 00:00:00 2001 From: Simo Sorce Date: Tue, 4 Dec 2018 15:22:55 -0500 Subject: [PATCH] Add dns_canonicalize_hostname=fallback support diff --git a/Add-function-and-enctype-flag-for-deprecations.patch b/Add-function-and-enctype-flag-for-deprecations.patch index 61c865e..13a8fcc 100644 --- a/Add-function-and-enctype-flag-for-deprecations.patch +++ b/Add-function-and-enctype-flag-for-deprecations.patch @@ -1,4 +1,4 @@ -From 461e3a4d81c73db832401592d417489dc0151a2c Mon Sep 17 00:00:00 2001 +From 4cd829c935319049142052ac45f252a8c3c54b49 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 16:16:57 -0500 Subject: [PATCH] Add function and enctype flag for deprecations diff --git a/Avoid-alignment-warnings-in-openssl-rc4.c.patch b/Avoid-alignment-warnings-in-openssl-rc4.c.patch new file mode 100644 index 0000000..1081afc --- /dev/null +++ b/Avoid-alignment-warnings-in-openssl-rc4.c.patch @@ -0,0 +1,63 @@ +From 05c4ea24fa8603572ea1bffc767886bb26b8d542 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 6 May 2019 15:14:49 -0400 +Subject: [PATCH] Avoid alignment warnings in openssl rc4.c + +Add a comment to k5_arcfour_init_state() explaining how we stretch the +krb5_data cipher state contract. Use void * casts when interpreting +the data pointer to avoid alignment warnings. + +[ghudson@mit.edu: moved and expanded comment; rewrote commit message] + +(cherry picked from commit 1cd41d76c12fc1cea0a8bf0d6a40f34623c60d6d) +--- + src/lib/crypto/openssl/enc_provider/rc4.c | 15 ++++++++++++--- + 1 file changed, 12 insertions(+), 3 deletions(-) + +diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c +index 7f3c086ed..a65d57b7a 100644 +--- a/src/lib/crypto/openssl/enc_provider/rc4.c ++++ b/src/lib/crypto/openssl/enc_provider/rc4.c +@@ -57,7 +57,7 @@ struct arcfour_state { + + /* In-place IOV crypto */ + static krb5_error_code +-k5_arcfour_docrypt(krb5_key key,const krb5_data *state, krb5_crypto_iov *data, ++k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, + size_t num_data) + { + size_t i; +@@ -66,7 +66,7 @@ k5_arcfour_docrypt(krb5_key key,const krb5_data *state, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx = NULL; + struct arcfour_state *arcstate; + +- arcstate = (state != NULL) ? (struct arcfour_state *) state->data : NULL; ++ arcstate = (state != NULL) ? (void *)state->data : NULL; + if (arcstate != NULL) { + ctx = arcstate->ctx; + if (arcstate->loopback != arcstate) +@@ -113,7 +113,7 @@ k5_arcfour_docrypt(krb5_key key,const krb5_data *state, krb5_crypto_iov *data, + static void + k5_arcfour_free_state(krb5_data *state) + { +- struct arcfour_state *arcstate = (struct arcfour_state *) state->data; ++ struct arcfour_state *arcstate = (void *)state->data; + + EVP_CIPHER_CTX_free(arcstate->ctx); + free(arcstate); +@@ -125,6 +125,15 @@ k5_arcfour_init_state(const krb5_keyblock *key, + { + struct arcfour_state *arcstate; + ++ /* ++ * The cipher state here is a saved pointer to a struct arcfour_state ++ * object, rather than a flat byte array as in most enc providers. The ++ * object includes a loopback pointer to detect if if the caller made a ++ * copy of the krb5_data value or otherwise assumed it was a simple byte ++ * array. When we cast the data pointer back, we need to go through void * ++ * to avoid increased alignment warnings. ++ */ ++ + /* Create a state structure with an uninitialized context. */ + arcstate = calloc(1, sizeof(*arcstate)); + if (arcstate == NULL) diff --git a/Avoid-allocating-a-register-in-zap-assembly.patch b/Avoid-allocating-a-register-in-zap-assembly.patch index b0c139f..096ffc0 100644 --- a/Avoid-allocating-a-register-in-zap-assembly.patch +++ b/Avoid-allocating-a-register-in-zap-assembly.patch @@ -1,4 +1,4 @@ -From 26dc343d4e59ef0f80e1ecca09b40f120b79d809 Mon Sep 17 00:00:00 2001 +From 273475be9d8aafb41edf417f6317c9537a03c3fa Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Thu, 3 Jan 2019 17:19:32 +0100 Subject: [PATCH] Avoid allocating a register in zap() assembly diff --git a/Check-more-errors-in-OpenSSL-crypto-backend.patch b/Check-more-errors-in-OpenSSL-crypto-backend.patch index 1c55efb..fdb937f 100644 --- a/Check-more-errors-in-OpenSSL-crypto-backend.patch +++ b/Check-more-errors-in-OpenSSL-crypto-backend.patch @@ -1,4 +1,4 @@ -From 27bc3f5a90533af509202d851374ea40f3982864 Mon Sep 17 00:00:00 2001 +From b87d0cd119732b9066606d388b4fdebde2facbe5 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 22 Apr 2019 14:26:42 -0400 Subject: [PATCH] Check more errors in OpenSSL crypto backend @@ -18,10 +18,10 @@ ticket: 8799 (new) 2 files changed, 14 insertions(+), 13 deletions(-) diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c -index d94d9ac94..769a50c00 100644 +index b2db6ec02..7dc59dcc0 100644 --- a/src/lib/crypto/openssl/hmac.c +++ b/src/lib/crypto/openssl/hmac.c -@@ -121,7 +121,7 @@ krb5int_hmac_keyblock(const struct krb5_hash_provider *hash, +@@ -117,7 +117,7 @@ krb5int_hmac_keyblock(const struct krb5_hash_provider *hash, const krb5_crypto_iov *data, size_t num_data, krb5_data *output) { @@ -30,7 +30,7 @@ index d94d9ac94..769a50c00 100644 unsigned char md[EVP_MAX_MD_SIZE]; HMAC_CTX *ctx; size_t hashsize, blocksize; -@@ -141,22 +141,22 @@ krb5int_hmac_keyblock(const struct krb5_hash_provider *hash, +@@ -137,22 +137,22 @@ krb5int_hmac_keyblock(const struct krb5_hash_provider *hash, if (ctx == NULL) return ENOMEM; diff --git a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch index b898655..e287f3c 100644 --- a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch +++ b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch @@ -1,4 +1,4 @@ -From 18dd4d5c622238d1607671198cf2b2ddec9abda5 Mon Sep 17 00:00:00 2001 +From dc0ff969a963c0dcbf203a636cf12030ea2845d9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Apr 2019 14:18:57 -0400 Subject: [PATCH] Clarify header comment for krb5_cc_start_seq_get() diff --git a/Clear-forwardable-flag-instead-of-denying-request.patch b/Clear-forwardable-flag-instead-of-denying-request.patch index 4b29e0f..523d04a 100644 --- a/Clear-forwardable-flag-instead-of-denying-request.patch +++ b/Clear-forwardable-flag-instead-of-denying-request.patch @@ -1,4 +1,4 @@ -From 297ad5039231e655eaae7c142991326fd863e70a Mon Sep 17 00:00:00 2001 +From 561ac441f046a01a4e71e3c475760cc2d42b8213 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 15 Nov 2018 13:40:43 -0500 Subject: [PATCH] Clear forwardable flag instead of denying request diff --git a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch index 899183e..87d2afc 100644 --- a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch +++ b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch @@ -1,4 +1,4 @@ -From 908eb6dde51917bb50d388a1769c50eede68fc10 Mon Sep 17 00:00:00 2001 +From 7eb42e3fbdb854b085eceaa500f1c18569bd044d Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 16 Apr 2019 10:47:35 -0400 Subject: [PATCH] Fix config realm change logic in FILE remove_cred diff --git a/Fix-memory-leak-in-none-replay-cache-type.patch b/Fix-memory-leak-in-none-replay-cache-type.patch index 07e1091..c785882 100644 --- a/Fix-memory-leak-in-none-replay-cache-type.patch +++ b/Fix-memory-leak-in-none-replay-cache-type.patch @@ -1,4 +1,4 @@ -From 050acb871c242931b3fb51c59461f22555046d19 Mon Sep 17 00:00:00 2001 +From aeae5941ff8beea66516a31cd16fe4df6e8165f9 Mon Sep 17 00:00:00 2001 From: Corene Casper Date: Sat, 16 Feb 2019 00:49:26 -0500 Subject: [PATCH] Fix memory leak in 'none' replay cache type diff --git a/Fix-potential-close-1-in-cc_file.c.patch b/Fix-potential-close-1-in-cc_file.c.patch index 931f085..b9457f5 100644 --- a/Fix-potential-close-1-in-cc_file.c.patch +++ b/Fix-potential-close-1-in-cc_file.c.patch @@ -1,4 +1,4 @@ -From b2002f8286c0f77e57c7387123328a31125cda2e Mon Sep 17 00:00:00 2001 +From c1fe784e79b847a7e9ae9009193dee66bc1b6164 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 18 Apr 2019 13:39:37 -0400 Subject: [PATCH] Fix potential close(-1) in cc_file.c diff --git a/Fix-some-return-code-handling-bugs.patch b/Fix-some-return-code-handling-bugs.patch new file mode 100644 index 0000000..32ad2ed --- /dev/null +++ b/Fix-some-return-code-handling-bugs.patch @@ -0,0 +1,103 @@ +From 202a4ef4b2d1fa88d1a5c7f0b673bc4f563c57cd Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 2 May 2019 14:05:38 -0400 +Subject: [PATCH] Fix some return code handling bugs + +Fix five cases where return codes could be set (in unlikely cases) but +did not result in error exits. + +[ghudson@mit.edu: squashed commits and rewrote commit message] + +ticket: 8801 (new) +tags: pullup +target_version: 1.17-next +target_version: 1.16-next + +(cherry picked from commit 7c26740f9df3c79c3f01c3a4dda4d9dabba5298d) +--- + src/kdc/fast_util.c | 16 ++++++++-------- + src/lib/gssapi/krb5/k5unsealiov.c | 1 + + src/lib/kadm5/clnt/client_init.c | 3 +++ + src/tests/gssapi/t_pcontok.c | 1 + + 4 files changed, 13 insertions(+), 8 deletions(-) + +diff --git a/src/kdc/fast_util.c b/src/kdc/fast_util.c +index 6a3fc11b9..c9ba83e5e 100644 +--- a/src/kdc/fast_util.c ++++ b/src/kdc/fast_util.c +@@ -47,9 +47,10 @@ static krb5_error_code armor_ap_request + if (retval == 0) + retval = krb5_auth_con_setflags(kdc_context, + authcontext, 0); /*disable replay cache*/ +- retval = krb5_rd_req(kdc_context, &authcontext, +- &armor->armor_value, NULL /*server*/, +- kdc_active_realm->realm_keytab, NULL, &ticket); ++ if (retval == 0) ++ retval = krb5_rd_req(kdc_context, &authcontext, &armor->armor_value, ++ NULL /*server*/, kdc_active_realm->realm_keytab, ++ NULL, &ticket); + if (retval != 0) { + const char * errmsg = krb5_get_error_message(kdc_context, retval); + k5_setmsg(kdc_context, retval, _("%s while handling ap-request armor"), +@@ -132,7 +133,7 @@ kdc_find_fast(krb5_kdc_req **requestptr, + { + krb5_error_code retval = 0; + krb5_pa_data *fast_padata; +- krb5_data scratch, *inner_body = NULL; ++ krb5_data scratch, plaintext, *inner_body = NULL; + krb5_fast_req * fast_req = NULL; + krb5_kdc_req *request = *requestptr; + krb5_fast_armored_req *fast_armored_req = NULL; +@@ -183,11 +184,10 @@ kdc_find_fast(krb5_kdc_req **requestptr, + } + } + if (retval == 0) { +- krb5_data plaintext; + plaintext.length = fast_armored_req->enc_part.ciphertext.length; +- plaintext.data = malloc(plaintext.length); +- if (plaintext.data == NULL) +- retval = ENOMEM; ++ plaintext.data = k5alloc(plaintext.length, &retval); ++ } ++ if (retval == 0) { + retval = krb5_c_decrypt(kdc_context, + state->armor_key, + KRB5_KEYUSAGE_FAST_ENC, NULL, +diff --git a/src/lib/gssapi/krb5/k5unsealiov.c b/src/lib/gssapi/krb5/k5unsealiov.c +index 8b6704274..f15d2db69 100644 +--- a/src/lib/gssapi/krb5/k5unsealiov.c ++++ b/src/lib/gssapi/krb5/k5unsealiov.c +@@ -281,6 +281,7 @@ kg_unseal_v1_iov(krb5_context context, + (!ctx->initiate && direction != 0)) { + *minor_status = (OM_uint32)G_BAD_DIRECTION; + retval = GSS_S_BAD_SIG; ++ goto cleanup; + } + + code = 0; +diff --git a/src/lib/kadm5/clnt/client_init.c b/src/lib/kadm5/clnt/client_init.c +index 6f10db018..aa08918e2 100644 +--- a/src/lib/kadm5/clnt/client_init.c ++++ b/src/lib/kadm5/clnt/client_init.c +@@ -465,6 +465,9 @@ gic_iter(kadm5_server_handle_t handle, enum init_type init_type, + /* Credentials for kadmin don't need to be forwardable or proxiable. */ + if (init_type != INIT_CREDS) { + code = krb5_get_init_creds_opt_alloc(ctx, &opt); ++ if (code) ++ goto error; ++ + krb5_get_init_creds_opt_set_forwardable(opt, 0); + krb5_get_init_creds_opt_set_proxiable(opt, 0); + krb5_get_init_creds_opt_set_out_ccache(ctx, opt, ccache); +diff --git a/src/tests/gssapi/t_pcontok.c b/src/tests/gssapi/t_pcontok.c +index b966f8129..c40ea434c 100644 +--- a/src/tests/gssapi/t_pcontok.c ++++ b/src/tests/gssapi/t_pcontok.c +@@ -126,6 +126,7 @@ make_delete_token(gss_krb5_lucid_context_v1_t *lctx, gss_buffer_desc *out) + iov.flags = KRB5_CRYPTO_TYPE_DATA; + iov.data = make_data(cksum.contents, 16); + ret = krb5_k_encrypt_iov(context, seq, 0, NULL, &iov, 1); ++ check_k5err(context, "krb5_k_encrypt_iov", ret); + memcpy(ptr + 8, cksum.contents + 8, 8); + } else { + memcpy(ptr + 8, cksum.contents, cksize); diff --git a/Implement-krb5_cc_remove_cred-for-remaining-types.patch b/Implement-krb5_cc_remove_cred-for-remaining-types.patch index a656d57..7e9ea4c 100644 --- a/Implement-krb5_cc_remove_cred-for-remaining-types.patch +++ b/Implement-krb5_cc_remove_cred-for-remaining-types.patch @@ -1,4 +1,4 @@ -From 57ce492d6700ca6417cc43f3e97e0186b2cdfa90 Mon Sep 17 00:00:00 2001 +From fd67573d4f0e2ac155752697ebf750c43fab3c59 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 1 Apr 2019 14:28:48 -0400 Subject: [PATCH] Implement krb5_cc_remove_cred for remaining types diff --git a/Improve-error-messages-from-kadmin-change_password.patch b/Improve-error-messages-from-kadmin-change_password.patch new file mode 100644 index 0000000..d9d1116 --- /dev/null +++ b/Improve-error-messages-from-kadmin-change_password.patch @@ -0,0 +1,55 @@ +From a479ad01696f97114cdc1734a7fe5f3d4bd80e80 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 6 May 2019 13:13:16 -0400 +Subject: [PATCH] Improve error messages from kadmin change_password + +The checks for missing option arguments were dead code, because the +loop condition requires at least two remaining arguments. Instead +check for at least one argument with a leading "-", and check for too +many or too few arguments after the loop. Add an initial message for +unrecognized options. + +[ghudson@mit.edu: adjusted logic to improve mesages in more cases] + +(cherry picked from commit 13ba54002d362ebb09be464b4e7ec75050d1348f) +--- + src/kadmin/cli/kadmin.c | 12 ++++++++---- + 1 file changed, 8 insertions(+), 4 deletions(-) + +diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c +index cc74921bf..fe4cb493c 100644 +--- a/src/kadmin/cli/kadmin.c ++++ b/src/kadmin/cli/kadmin.c +@@ -797,11 +797,11 @@ kadmin_cpw(int argc, char *argv[]) + char **db_args = NULL; + int db_args_size = 0; + +- if (argc < 2) { ++ if (argc < 1) { + cpw_usage(NULL); + return; + } +- for (argv++, argc--; argc > 1; argc--, argv++) { ++ for (argv++, argc--; argc > 0 && **argv == '-'; argc--, argv++) { + if (!strcmp("-x", *argv)) { + argc--; + if (argc < 1) { +@@ -841,12 +841,16 @@ kadmin_cpw(int argc, char *argv[]) + goto cleanup; + } + } else { ++ com_err("change_password", 0, _("unrecognized option %s"), *argv); + cpw_usage(NULL); + goto cleanup; + } + } +- if (*argv == NULL) { +- com_err("change_password", 0, _("missing principal name")); ++ if (argc != 1) { ++ if (argc < 1) ++ com_err("change_password", 0, _("missing principal name")); ++ else ++ com_err("change_password", 0, _("too many arguments")); + cpw_usage(NULL); + goto cleanup; + } diff --git a/In-kpropd-debug-log-proper-ticket-enctype-names.patch b/In-kpropd-debug-log-proper-ticket-enctype-names.patch index 8f0c0ca..93b4615 100644 --- a/In-kpropd-debug-log-proper-ticket-enctype-names.patch +++ b/In-kpropd-debug-log-proper-ticket-enctype-names.patch @@ -1,4 +1,4 @@ -From c06d20bf241059059cc3ffd810a44e310ff9970d Mon Sep 17 00:00:00 2001 +From fe497f16d8da570dea363dacb18cfc2fcfa52f24 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 13:41:16 -0500 Subject: [PATCH] In kpropd, debug-log proper ticket enctype names diff --git a/In-rd_req_dec-always-log-non-permitted-enctypes.patch b/In-rd_req_dec-always-log-non-permitted-enctypes.patch index 9947e2f..702ab0b 100644 --- a/In-rd_req_dec-always-log-non-permitted-enctypes.patch +++ b/In-rd_req_dec-always-log-non-permitted-enctypes.patch @@ -1,4 +1,4 @@ -From 6a316b681a2e0b6917285b9a0cdde605d463288b Mon Sep 17 00:00:00 2001 +From d868f6753cd6e9de447f097626f5e5155c727414 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Jan 2019 17:14:42 -0500 Subject: [PATCH] In rd_req_dec, always log non-permitted enctypes diff --git a/Initialize-some-data-structure-magic-fields.patch b/Initialize-some-data-structure-magic-fields.patch new file mode 100644 index 0000000..8bb00a5 --- /dev/null +++ b/Initialize-some-data-structure-magic-fields.patch @@ -0,0 +1,55 @@ +From a1327230380d0c73ebb9a22e4c6bbb1b6f3e0c64 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 2 May 2019 13:36:38 -0400 +Subject: [PATCH] Initialize some data structure magic fields + +Static analyzers may complain if they see a data structure copied with +an uninitialized field, even if the copy target won't use the field. +Add magic field initializers in three such places. + +[ghudson@mit.edu: rewrote commit message] + +(cherry picked from commit 551e88e76e537e45f6c80eadaefeb790994f83f9) +--- + src/lib/gssapi/krb5/util_cksum.c | 1 + + src/lib/krb5/krb/authdata.c | 8 ++------ + 2 files changed, 3 insertions(+), 6 deletions(-) + +diff --git a/src/lib/gssapi/krb5/util_cksum.c b/src/lib/gssapi/krb5/util_cksum.c +index cfd585ec7..a1770774e 100644 +--- a/src/lib/gssapi/krb5/util_cksum.c ++++ b/src/lib/gssapi/krb5/util_cksum.c +@@ -48,6 +48,7 @@ kg_checksum_channel_bindings(context, cb, cksum) + + cksum->checksum_type = CKSUMTYPE_RSA_MD5; + cksum->length = sumlen; ++ cksum->magic = KV5M_CHECKSUM; + + /* generate a buffer full of zeros if no cb specified */ + +diff --git a/src/lib/krb5/krb/authdata.c b/src/lib/krb5/krb/authdata.c +index 7fbcfab68..3e7dfbe49 100644 +--- a/src/lib/krb5/krb/authdata.c ++++ b/src/lib/krb5/krb/authdata.c +@@ -976,9 +976,7 @@ krb5_authdata_export_internal(krb5_context kcontext, + + *ptr = NULL; + +- name.length = strlen(module_name); +- name.data = (char *)module_name; +- ++ name = make_data((char *)module_name, strlen(module_name)); + module = k5_ad_find_module(kcontext, context, AD_USAGE_MASK, &name); + if (module == NULL) + return ENOENT; +@@ -1005,9 +1003,7 @@ krb5_authdata_free_internal(krb5_context kcontext, + krb5_data name; + struct _krb5_authdata_context_module *module; + +- name.length = strlen(module_name); +- name.data = (char *)module_name; +- ++ name = make_data((char *)module_name, strlen(module_name)); + module = k5_ad_find_module(kcontext, context, AD_USAGE_MASK, &name); + if (module == NULL) + return ENOENT; diff --git a/Make-etype-names-in-KDC-logs-human-readable.patch b/Make-etype-names-in-KDC-logs-human-readable.patch index 6fd40d7..612181c 100644 --- a/Make-etype-names-in-KDC-logs-human-readable.patch +++ b/Make-etype-names-in-KDC-logs-human-readable.patch @@ -1,4 +1,4 @@ -From 2a8005296c3da39f6d0c6ecd48b950447897af91 Mon Sep 17 00:00:00 2001 +From c14796879b9c4601a3333444c9aa6388031e6ab2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 8 Jan 2019 17:42:35 -0500 Subject: [PATCH] Make etype names in KDC logs human-readable diff --git a/Mark-deprecated-enctypes-when-used.patch b/Mark-deprecated-enctypes-when-used.patch index 596c74b..a3fc96a 100644 --- a/Mark-deprecated-enctypes-when-used.patch +++ b/Mark-deprecated-enctypes-when-used.patch @@ -1,4 +1,4 @@ -From 6d265afd53ead9290948b5ba07438b6a91939bfd Mon Sep 17 00:00:00 2001 +From 5b81e75e1c5ec39a070df7c87c64aa74b5b9c0ba Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 10 Jan 2019 16:34:54 -0500 Subject: [PATCH] Mark deprecated enctypes when used diff --git a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch new file mode 100644 index 0000000..54b7580 --- /dev/null +++ b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch @@ -0,0 +1,68 @@ +From ae9b51bc4f4ca5e88d7675d373e35fde8470e223 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 2 May 2019 14:32:33 -0400 +Subject: [PATCH] Modernize exit path in gss_krb5int_copy_ccache() + +Move to a single lock / single unlock paradigm, and eliminate some +dead code in the old error handling. + +(cherry picked from commit 1b89e3d8e949f52901bce74c9afc7a1a64099520) +--- + src/lib/gssapi/krb5/copy_ccache.c | 31 ++++++++++++------------------- + 1 file changed, 12 insertions(+), 19 deletions(-) + +diff --git a/src/lib/gssapi/krb5/copy_ccache.c b/src/lib/gssapi/krb5/copy_ccache.c +index 027ed4847..2b2806e70 100644 +--- a/src/lib/gssapi/krb5/copy_ccache.c ++++ b/src/lib/gssapi/krb5/copy_ccache.c +@@ -9,7 +9,7 @@ gss_krb5int_copy_ccache(OM_uint32 *minor_status, + { + krb5_gss_cred_id_t k5creds; + krb5_error_code code; +- krb5_context context; ++ krb5_context context = NULL; + krb5_ccache out_ccache; + + assert(value->length == sizeof(out_ccache)); +@@ -23,30 +23,23 @@ gss_krb5int_copy_ccache(OM_uint32 *minor_status, + k5creds = (krb5_gss_cred_id_t) *cred_handle; + k5_mutex_lock(&k5creds->lock); + if (k5creds->usage == GSS_C_ACCEPT) { +- k5_mutex_unlock(&k5creds->lock); +- *minor_status = (OM_uint32) G_BAD_USAGE; +- return(GSS_S_FAILURE); ++ code = G_BAD_USAGE; ++ goto cleanup; + } + + code = krb5_gss_init_context(&context); +- if (code) { +- k5_mutex_unlock(&k5creds->lock); +- *minor_status = code; +- return GSS_S_FAILURE; +- } ++ if (code) ++ goto cleanup; + + code = krb5_cc_copy_creds(context, k5creds->ccache, out_ccache); +- if (code) { +- k5_mutex_unlock(&k5creds->lock); +- *minor_status = code; +- save_error_info(*minor_status, context); +- krb5_free_context(context); +- return(GSS_S_FAILURE); +- } ++ ++cleanup: + k5_mutex_unlock(&k5creds->lock); + *minor_status = code; +- if (code) +- save_error_info(*minor_status, context); +- krb5_free_context(context); ++ if (context != NULL) { ++ if (code) ++ save_error_info(*minor_status, context); ++ krb5_free_context(context); ++ } + return code ? GSS_S_FAILURE : GSS_S_COMPLETE; + } diff --git a/Properly-size-ifdef-in-k5_cccol_lock.patch b/Properly-size-ifdef-in-k5_cccol_lock.patch index bdaa775..74eef51 100644 --- a/Properly-size-ifdef-in-k5_cccol_lock.patch +++ b/Properly-size-ifdef-in-k5_cccol_lock.patch @@ -1,4 +1,4 @@ -From ec9e4597188234e402cd318aebe0fa0a3587a993 Mon Sep 17 00:00:00 2001 +From 85577bdae928613c87828fff79d5d6c6b9b8b291 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Feb 2019 11:50:35 -0500 Subject: [PATCH] Properly size #ifdef in k5_cccol_lock() diff --git a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch index 12c58a4..e09efcf 100644 --- a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch +++ b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch @@ -1,4 +1,4 @@ -From 7fa37c0c80b3bbd611ba27dd162aa0b6016c20b3 Mon Sep 17 00:00:00 2001 +From 6bd60d3985df4e327f86d2a19349f52058d09a17 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 14:37:38 -0400 Subject: [PATCH] Remove Kerberos v4 support vestiges from ccapi diff --git a/Remove-ccapi-related-comments-in-configure.ac.patch b/Remove-ccapi-related-comments-in-configure.ac.patch index 78cf265..a2563f8 100644 --- a/Remove-ccapi-related-comments-in-configure.ac.patch +++ b/Remove-ccapi-related-comments-in-configure.ac.patch @@ -1,4 +1,4 @@ -From 1f214b1265bde1d8f6c9b99af0755ca8f5463385 Mon Sep 17 00:00:00 2001 +From 74c45a65b34e49aecfedfb8451b857350fbbe616 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Apr 2019 16:01:22 -0400 Subject: [PATCH] Remove ccapi-related comments in configure.ac diff --git a/Remove-confvalidator-utility.patch b/Remove-confvalidator-utility.patch index d002286..0dd66b7 100644 --- a/Remove-confvalidator-utility.patch +++ b/Remove-confvalidator-utility.patch @@ -1,4 +1,4 @@ -From 32a6caec15bafd37fdf5746c08cf1a385166020e Mon Sep 17 00:00:00 2001 +From 841be050c7f02d09aade0ed2c708bff8787afcd2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Apr 2019 14:58:19 -0400 Subject: [PATCH] Remove confvalidator utility diff --git a/Remove-doxygen-generated-HTML-output-for-ccapi.patch b/Remove-doxygen-generated-HTML-output-for-ccapi.patch index 3165c8e..58b1177 100644 --- a/Remove-doxygen-generated-HTML-output-for-ccapi.patch +++ b/Remove-doxygen-generated-HTML-output-for-ccapi.patch @@ -1,4 +1,4 @@ -From 5f56eefcf0017d6c0c574e667f55f827b226b295 Mon Sep 17 00:00:00 2001 +From 33acfff1a6ec51f2d60933c362ec8afb89d5d548 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 14:15:58 -0400 Subject: [PATCH] Remove doxygen-generated HTML output for ccapi diff --git a/Remove-kadmin-RPC-support-for-setting-v4-key.patch b/Remove-kadmin-RPC-support-for-setting-v4-key.patch index 17d63c5..b0e5830 100644 --- a/Remove-kadmin-RPC-support-for-setting-v4-key.patch +++ b/Remove-kadmin-RPC-support-for-setting-v4-key.patch @@ -1,4 +1,4 @@ -From a2fc99321c797c1534f6314d17560c622ec93418 Mon Sep 17 00:00:00 2001 +From 76b39ce5081eb3b288532d615c356ab508e93495 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 16:14:46 -0400 Subject: [PATCH] Remove kadmin RPC support for setting v4 key diff --git a/Remove-more-dead-code.patch b/Remove-more-dead-code.patch new file mode 100644 index 0000000..fc77326 --- /dev/null +++ b/Remove-more-dead-code.patch @@ -0,0 +1,276 @@ +From eb6d9cd533d087d38b7f3c1b7086a712cb0bfe46 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 9 May 2019 14:07:24 -0400 +Subject: [PATCH] Remove more dead code + +(cherry picked from commit 0269810b1aec6c554fb746433f045d59fd34ab3a) +--- + src/clients/klist/klist.c | 5 --- + src/kadmin/dbutil/kdb5_mkey.c | 2 -- + src/kadmin/server/ipropd_svc.c | 4 --- + src/lib/gssapi/krb5/gssapi_krb5.c | 2 +- + src/lib/gssapi/krb5/k5sealv3.c | 5 ++- + src/lib/gssapi/krb5/k5sealv3iov.c | 5 ++- + src/lib/kdb/kdb_convert.c | 36 +++---------------- + .../kdb/ldap/ldap_util/kdb5_ldap_services.c | 4 --- + .../kdb/ldap/libkdb_ldap/ldap_create.c | 10 ------ + src/plugins/preauth/pkinit/pkinit_srv.c | 8 ----- + src/tests/hammer/kdc5_hammer.c | 4 +-- + 11 files changed, 10 insertions(+), 75 deletions(-) + +diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c +index 8c307151a..4261ac96c 100644 +--- a/src/clients/klist/klist.c ++++ b/src/clients/klist/klist.c +@@ -720,11 +720,6 @@ show_credential(krb5_creds *cred) + extra_field += 2; + } + +- if (extra_field > 3) { +- fputs("\n", stdout); +- extra_field = 0; +- } +- + if (show_flags) { + flags = flags_string(cred); + if (flags && *flags) { +diff --git a/src/kadmin/dbutil/kdb5_mkey.c b/src/kadmin/dbutil/kdb5_mkey.c +index 19796c202..aceb0a9b8 100644 +--- a/src/kadmin/dbutil/kdb5_mkey.c ++++ b/src/kadmin/dbutil/kdb5_mkey.c +@@ -1240,7 +1240,6 @@ kdb5_purge_mkeys(int argc, char *argv[]) + if (actkvno_entry == actkvno_list) { + /* remove from head */ + actkvno_list = actkvno_entry->next; +- prev_actkvno_entry = actkvno_list; + } else if (actkvno_entry->next == NULL) { + /* remove from tail */ + prev_actkvno_entry->next = NULL; +@@ -1263,7 +1262,6 @@ kdb5_purge_mkeys(int argc, char *argv[]) + if (mkey_aux_entry->mkey_kvno == args.kvnos[j].kvno) { + if (mkey_aux_entry == mkey_aux_list) { + mkey_aux_list = mkey_aux_entry->next; +- prev_mkey_aux_entry = mkey_aux_list; + } else if (mkey_aux_entry->next == NULL) { + prev_mkey_aux_entry->next = NULL; + } else { +diff --git a/src/kadmin/server/ipropd_svc.c b/src/kadmin/server/ipropd_svc.c +index dc9984c2c..56e9b90b2 100644 +--- a/src/kadmin/server/ipropd_svc.c ++++ b/src/kadmin/server/ipropd_svc.c +@@ -263,8 +263,6 @@ ipropx_resync(uint32_t vers, struct svc_req *rqstp) + int pret, fret; + FILE *p; + kadm5_server_handle_t handle = global_server_handle; +- OM_uint32 min_stat; +- gss_name_t name = NULL; + char *client_name = NULL, *service_name = NULL; + char *whoami = "iprop_full_resync_1"; + +@@ -440,8 +438,6 @@ out: + debprret(whoami, ret.ret, 0); + free(client_name); + free(service_name); +- if (name) +- gss_release_name(&min_stat, &name); + free(ubuf); + return (&ret); + } +diff --git a/src/lib/gssapi/krb5/gssapi_krb5.c b/src/lib/gssapi/krb5/gssapi_krb5.c +index 79b83e0c6..f09cda007 100644 +--- a/src/lib/gssapi/krb5/gssapi_krb5.c ++++ b/src/lib/gssapi/krb5/gssapi_krb5.c +@@ -780,7 +780,7 @@ krb5_gss_localname(OM_uint32 *minor, + localname->value = gssalloc_strdup(lname); + localname->length = strlen(lname); + +- return (code == 0) ? GSS_S_COMPLETE : GSS_S_FAILURE; ++ return GSS_S_COMPLETE; + } + + +diff --git a/src/lib/gssapi/krb5/k5sealv3.c b/src/lib/gssapi/krb5/k5sealv3.c +index 25d9f2711..3b4f8cb83 100644 +--- a/src/lib/gssapi/krb5/k5sealv3.c ++++ b/src/lib/gssapi/krb5/k5sealv3.c +@@ -145,9 +145,8 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + /* TOK_ID */ + store_16_be(KG2_TOK_WRAP_MSG, outbuf); + /* flags */ +- outbuf[2] = (acceptor_flag +- | (conf_req_flag ? FLAG_WRAP_CONFIDENTIAL : 0) +- | (ctx->have_acceptor_subkey ? FLAG_ACCEPTOR_SUBKEY : 0)); ++ outbuf[2] = (acceptor_flag | FLAG_WRAP_CONFIDENTIAL | ++ (ctx->have_acceptor_subkey ? FLAG_ACCEPTOR_SUBKEY : 0)); + /* filler */ + outbuf[3] = 0xff; + /* EC */ +diff --git a/src/lib/gssapi/krb5/k5sealv3iov.c b/src/lib/gssapi/krb5/k5sealv3iov.c +index a73edb6a4..333ee124d 100644 +--- a/src/lib/gssapi/krb5/k5sealv3iov.c ++++ b/src/lib/gssapi/krb5/k5sealv3iov.c +@@ -144,9 +144,8 @@ gss_krb5int_make_seal_token_v3_iov(krb5_context context, + /* TOK_ID */ + store_16_be(KG2_TOK_WRAP_MSG, outbuf); + /* flags */ +- outbuf[2] = (acceptor_flag +- | (conf_req_flag ? FLAG_WRAP_CONFIDENTIAL : 0) +- | (ctx->have_acceptor_subkey ? FLAG_ACCEPTOR_SUBKEY : 0)); ++ outbuf[2] = (acceptor_flag | FLAG_WRAP_CONFIDENTIAL | ++ (ctx->have_acceptor_subkey ? FLAG_ACCEPTOR_SUBKEY : 0)); + /* filler */ + outbuf[3] = 0xFF; + /* EC */ +diff --git a/src/lib/kdb/kdb_convert.c b/src/lib/kdb/kdb_convert.c +index 76140732f..e1bf1919f 100644 +--- a/src/lib/kdb/kdb_convert.c ++++ b/src/lib/kdb/kdb_convert.c +@@ -305,8 +305,6 @@ ulog_conv_2logentry(krb5_context context, krb5_db_entry *entry, + krb5_error_code ret; + kdbe_attr_type_t *attr_types; + int kadm_data_yes; +- /* always exclude non-replicated attributes, for now */ +- krb5_boolean exclude_nra = TRUE; + + nattrs = tmpint = 0; + final = -1; +@@ -356,7 +354,8 @@ ulog_conv_2logentry(krb5_context context, krb5_db_entry *entry, + nattrs++; + } + } else { +- find_changed_attrs(curr, entry, exclude_nra, attr_types, &nattrs); ++ /* Always exclude non-replicated attributes for now. */ ++ find_changed_attrs(curr, entry, TRUE, attr_types, &nattrs); + krb5_db_free_principal(context, curr); + } + +@@ -402,31 +401,6 @@ ulog_conv_2logentry(krb5_context context, krb5_db_entry *entry, + } + break; + +- case AT_LAST_SUCCESS: +- if (!exclude_nra && entry->last_success >= 0) { +- ULOG_ENTRY_TYPE(update, ++final).av_type = AT_LAST_SUCCESS; +- ULOG_ENTRY(update, final).av_last_success = +- (uint32_t)entry->last_success; +- } +- break; +- +- case AT_LAST_FAILED: +- if (!exclude_nra && entry->last_failed >= 0) { +- ULOG_ENTRY_TYPE(update, ++final).av_type = AT_LAST_FAILED; +- ULOG_ENTRY(update, final).av_last_failed = +- (uint32_t)entry->last_failed; +- } +- break; +- +- case AT_FAIL_AUTH_COUNT: +- if (!exclude_nra) { +- ULOG_ENTRY_TYPE(update, ++final).av_type = +- AT_FAIL_AUTH_COUNT; +- ULOG_ENTRY(update, final).av_fail_auth_count = +- (uint32_t)entry->fail_auth_count; +- } +- break; +- + case AT_PRINC: + if (entry->princ->length > 0) { + ULOG_ENTRY_TYPE(update, ++final).av_type = AT_PRINC; +@@ -552,10 +526,8 @@ ulog_conv_2logentry(krb5_context context, krb5_db_entry *entry, + /* END CSTYLED */ + + case AT_LEN: +- if (entry->len >= 0) { +- ULOG_ENTRY_TYPE(update, ++final).av_type = AT_LEN; +- ULOG_ENTRY(update, final).av_len = (int16_t)entry->len; +- } ++ ULOG_ENTRY_TYPE(update, ++final).av_type = AT_LEN; ++ ULOG_ENTRY(update, final).av_len = (int16_t)entry->len; + break; + + default: +diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c +index ce038fc3d..0a95101ad 100644 +--- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c ++++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c +@@ -135,10 +135,6 @@ kdb5_ldap_stash_service_password(int argc, char **argv) + print_usage = TRUE; + goto cleanup; + } +- if (file_name == NULL) { +- com_err(me, ENOMEM, _("while setting service object password")); +- goto cleanup; +- } + } else { /* argc == 2 */ + service_object = strdup (argv[1]); + if (service_object == NULL) { +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c +index 1e6fffee5..5b57c799a 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c ++++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c +@@ -56,7 +56,6 @@ krb5_ldap_create(krb5_context context, char *conf_section, char **db_args) + krb5_ldap_realm_params *rparams = NULL; + krb5_ldap_context *ldap_context=NULL; + krb5_boolean realm_obj_created = FALSE; +- krb5_boolean krbcontainer_obj_created = FALSE; + int mask = 0; + + /* Clear the global error string */ +@@ -121,15 +120,6 @@ krb5_ldap_create(krb5_context context, char *conf_section, char **db_args) + goto cleanup; + + cleanup: +- /* If the krbcontainer/realm creation is not complete, do the roll-back here */ +- if ((krbcontainer_obj_created) && (!realm_obj_created)) { +- int rc; +- rc = krb5_ldap_delete_krbcontainer(context, +- ldap_context->container_dn); +- k5_setmsg(context, rc, _("could not complete roll-back, error " +- "deleting Kerberos Container")); +- } +- + if (rparams) + krb5_ldap_free_realm_params(rparams); + +diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c +index 27e6ef4d2..6aa646cc6 100644 +--- a/src/plugins/preauth/pkinit/pkinit_srv.c ++++ b/src/plugins/preauth/pkinit/pkinit_srv.c +@@ -258,15 +258,7 @@ verify_client_san(krb5_context context, + } + pkiDebug("%s: no upn san match found\n", __FUNCTION__); + +- /* We found no match */ +- if (princs != NULL || upns != NULL) { +- *valid_san = 0; +- /* XXX ??? If there was one or more name in the cert, but +- * none matched the client name, then return mismatch? */ +- retval = KRB5KDC_ERR_CLIENT_NAME_MISMATCH; +- } + retval = 0; +- + out: + if (princs != NULL) { + for (i = 0; princs[i] != NULL; i++) +diff --git a/src/tests/hammer/kdc5_hammer.c b/src/tests/hammer/kdc5_hammer.c +index 086c21d1c..8220fd97b 100644 +--- a/src/tests/hammer/kdc5_hammer.c ++++ b/src/tests/hammer/kdc5_hammer.c +@@ -439,7 +439,6 @@ int get_tgt (context, p_client_str, p_client, ccache) + krb5_principal *p_client; + krb5_ccache ccache; + { +- char *cache_name = NULL; /* -f option */ + long lifetime = KRB5_DEFAULT_LIFE; /* -l option */ + krb5_error_code code; + krb5_creds my_creds; +@@ -464,8 +463,7 @@ int get_tgt (context, p_client_str, p_client, ccache) + + code = krb5_cc_initialize (context, ccache, *p_client); + if (code != 0) { +- com_err (prog, code, "when initializing cache %s", +- cache_name?cache_name:""); ++ com_err (prog, code, "when initializing cache"); + return(-1); + } + diff --git a/Remove-ovsec_adm_export-dump-format-support.patch b/Remove-ovsec_adm_export-dump-format-support.patch index 12008d6..ce890cf 100644 --- a/Remove-ovsec_adm_export-dump-format-support.patch +++ b/Remove-ovsec_adm_export-dump-format-support.patch @@ -1,4 +1,4 @@ -From 34bde16a10c0cf0f05732376b955af0302af155d Mon Sep 17 00:00:00 2001 +From e7766b4c1df19738a4cf34d498046cfa8dd91637 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 22 Jan 2019 18:34:58 -0500 Subject: [PATCH] Remove ovsec_adm_export dump format support diff --git a/Remove-srvtab-support.patch b/Remove-srvtab-support.patch index 48535af..237cecb 100644 --- a/Remove-srvtab-support.patch +++ b/Remove-srvtab-support.patch @@ -1,4 +1,4 @@ -From 152f5ed9961f54dd9d764ffb3c6298eb85d8f934 Mon Sep 17 00:00:00 2001 +From e74dc82235b3948dee706310ebf5b1878d08d7df Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 9 Oct 2017 15:58:33 -0400 Subject: [PATCH] Remove srvtab support diff --git a/Simplify-SAM-2-as_key-handling.patch b/Simplify-SAM-2-as_key-handling.patch new file mode 100644 index 0000000..c990067 --- /dev/null +++ b/Simplify-SAM-2-as_key-handling.patch @@ -0,0 +1,76 @@ +From 4f9e21c9daf505f5147dcab2fb4d1b241e1b90f8 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sun, 5 May 2019 18:53:27 -0400 +Subject: [PATCH] Simplify SAM-2 as_key handling + +The ctx->gak_fct() call in sam2_process() used an empty salt instead +of the default salt when the KDC did not supply an explicit salt. +This bug arose when commit bc096a77ffdab283d77c2e0fc1fdd15b9f77eb41 +changed the internal contracts around salts but did not adjust the +SAM-2 code. Commit e9aa891fcdb4c08d39902ab89afb268042b60c86 fixed the +resulting bug, but mistakenly did not adjust the gak_fct call to use +the correct salt. + +Later on, the code contains a redundant call to krb5_c_string_to_key() +in the non-USE_SAD_AS_KEY modes, replacing ctx->as_key. This call was +properly adjusted by commit e9aa891fcdb4c08d39902ab89afb268042b60c86, +so the improper gak_fct call did not manifest as a bug. + +Fix the gak_fct call to supply the correct salt, and remove the +redundant string_to_key operation. + +(cherry picked from commit d48670c51460e9a74b4f4a9966f85ca6f77c1d8b) +--- + src/lib/krb5/krb/preauth_sam2.c | 25 +++---------------------- + 1 file changed, 3 insertions(+), 22 deletions(-) + +diff --git a/src/lib/krb5/krb/preauth_sam2.c b/src/lib/krb5/krb/preauth_sam2.c +index 4c70021a9..c7484c47e 100644 +--- a/src/lib/krb5/krb/preauth_sam2.c ++++ b/src/lib/krb5/krb/preauth_sam2.c +@@ -95,7 +95,6 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata, + krb5_prompt kprompt; + krb5_prompt_type prompt_type; + krb5_data defsalt, *salt; +- struct gak_password *gakpw; + krb5_checksum **cksum; + krb5_data *scratch = NULL; + krb5_boolean valid_cksum = 0; +@@ -152,9 +151,8 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata, + + salt = ctx->default_salt ? NULL : &ctx->salt; + retval = ctx->gak_fct(context, request->client, sc2b->sam_etype, +- prompter, prompter_data, &ctx->salt, +- &ctx->s2kparams, &ctx->as_key, +- ctx->gak_data, ctx->rctx.items); ++ prompter, prompter_data, salt, &ctx->s2kparams, ++ &ctx->as_key, ctx->gak_data, ctx->rctx.items); + if (retval) { + krb5_free_sam_challenge_2(context, sc2); + krb5_free_sam_challenge_2_body(context, sc2b); +@@ -212,24 +210,7 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata, + + /* Get encryption key to be used for checksum and sam_response */ + if (!(sc2b->sam_flags & KRB5_SAM_USE_SAD_AS_KEY)) { +- /* as_key = string_to_key(password) */ +- +- if (ctx->as_key.length) { +- krb5_free_keyblock_contents(context, &ctx->as_key); +- ctx->as_key.length = 0; +- } +- +- /* generate a key using the supplied password */ +- gakpw = ctx->gak_data; +- retval = krb5_c_string_to_key(context, sc2b->sam_etype, +- gakpw->password, salt, &ctx->as_key); +- +- if (retval) { +- krb5_free_sam_challenge_2(context, sc2); +- krb5_free_sam_challenge_2_body(context, sc2b); +- if (defsalt.length) free(defsalt.data); +- return(retval); +- } ++ /* Retain as_key from above gak_fct call. */ + + if (!(sc2b->sam_flags & KRB5_SAM_SEND_ENCRYPTED_SAD)) { + /* as_key = combine_key (as_key, string_to_key(SAD)) */ diff --git a/Simply-OpenSSL-PKCS7-decryption-code.patch b/Simply-OpenSSL-PKCS7-decryption-code.patch new file mode 100644 index 0000000..0ab4f51 --- /dev/null +++ b/Simply-OpenSSL-PKCS7-decryption-code.patch @@ -0,0 +1,301 @@ +From 89470cb724edb9a3c9d31f6fb5c967fed73e38a1 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 6 May 2019 13:13:06 -0400 +Subject: [PATCH] Simply OpenSSL PKCS7 decryption code + +Fold pkcs7_decrypt() and pkcs7_dataDecode() into a single function, +and make it output the plaintext rather than a BIO. + +[ghudson@mit.edu: continued a modernization of pkcs7_dataDecode() into +a larger refactoring] + +(cherry picked from commit 210356653a2f963ffe9a8a1b1627c64fb8ca7a3d) +--- + .../preauth/pkinit/pkinit_crypto_openssl.c | 213 ++++++------------ + 1 file changed, 63 insertions(+), 150 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 5ff81d8cf..8aa2c5257 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -81,12 +81,8 @@ static int openssl_callback (int, X509_STORE_CTX *); + static int openssl_callback_ignore_crls (int, X509_STORE_CTX *); + + static int pkcs7_decrypt +-(krb5_context context, pkinit_identity_crypto_context id_cryptoctx, +- PKCS7 *p7, BIO *bio); +- +-static BIO * pkcs7_dataDecode +-(krb5_context context, pkinit_identity_crypto_context id_cryptoctx, +- PKCS7 *p7); ++(krb5_context context, pkinit_identity_crypto_context id_cryptoctx, PKCS7 *p7, ++ unsigned char **data_out, unsigned int *len_out); + + static ASN1_OBJECT * pkinit_pkcs7type2oid + (pkinit_plg_crypto_context plg_cryptoctx, int pkcs7_type); +@@ -1964,9 +1960,6 @@ cms_envelopeddata_verify(krb5_context context, + { + krb5_error_code retval = KRB5KDC_ERR_PREAUTH_FAILED; + PKCS7 *p7 = NULL; +- BIO *out = NULL; +- int i = 0; +- unsigned int size = 0; + const unsigned char *p = enveloped_data; + unsigned int tmp_buf_len = 0, tmp_buf2_len = 0, vfy_buf_len = 0; + unsigned char *tmp_buf = NULL, *tmp_buf2 = NULL, *vfy_buf = NULL; +@@ -1991,26 +1984,13 @@ cms_envelopeddata_verify(krb5_context context, + } + + /* decrypt received PKCS7 message */ +- out = BIO_new(BIO_s_mem()); +- if (pkcs7_decrypt(context, id_cryptoctx, p7, out)) { ++ if (pkcs7_decrypt(context, id_cryptoctx, p7, &tmp_buf, &tmp_buf_len)) { + pkiDebug("PKCS7 decryption successful\n"); + } else { + retval = oerr(context, 0, _("Failed to decrypt PKCS7 message")); + goto cleanup; + } + +- /* transfer the decoded PKCS7 SignedData message into a separate buffer */ +- for (;;) { +- if ((tmp_buf = realloc(tmp_buf, size + 1024 * 10)) == NULL) +- goto cleanup; +- i = BIO_read(out, &(tmp_buf[size]), 1024 * 10); +- if (i <= 0) +- break; +- else +- size += i; +- } +- tmp_buf_len = size; +- + #ifdef DEBUG_ASN1 + print_buffer_bin(tmp_buf, tmp_buf_len, "/tmp/client_enc_keypack"); + #endif +@@ -2072,8 +2052,6 @@ cleanup: + + if (p7 != NULL) + PKCS7_free(p7); +- if (out != NULL) +- BIO_free(out); + free(tmp_buf); + free(tmp_buf2); + +@@ -5714,39 +5692,6 @@ cleanup: + return retval; + } + +-static int +-pkcs7_decrypt(krb5_context context, +- pkinit_identity_crypto_context id_cryptoctx, +- PKCS7 *p7, +- BIO *data) +-{ +- BIO *tmpmem = NULL; +- int retval = 0, i = 0; +- char buf[4096]; +- +- if(p7 == NULL) +- return 0; +- +- if(!PKCS7_type_is_enveloped(p7)) { +- pkiDebug("wrong pkcs7 content type\n"); +- return 0; +- } +- +- if(!(tmpmem = pkcs7_dataDecode(context, id_cryptoctx, p7))) { +- pkiDebug("unable to decrypt pkcs7 object\n"); +- return 0; +- } +- +- for(;;) { +- i = BIO_read(tmpmem, buf, sizeof(buf)); +- if (i <= 0) break; +- BIO_write(data, buf, i); +- BIO_free_all(tmpmem); +- return 1; +- } +- return retval; +-} +- + krb5_error_code + pkinit_process_td_trusted_certifiers( + krb5_context context, +@@ -5827,118 +5772,86 @@ cleanup: + return retval; + } + +-static BIO * +-pkcs7_dataDecode(krb5_context context, +- pkinit_identity_crypto_context id_cryptoctx, +- PKCS7 *p7) ++/* Originally based on OpenSSL's PKCS7_dataDecode(), now modified to remove the ++ * use of BIO objects and to fit the PKINIT internal interfaces. */ ++static int ++pkcs7_decrypt(krb5_context context, ++ pkinit_identity_crypto_context id_cryptoctx, PKCS7 *p7, ++ unsigned char **data_out, unsigned int *len_out) + { +- unsigned int eklen=0, tkeylen=0; +- BIO *out=NULL,*etmp=NULL,*bio=NULL; +- unsigned char *ek=NULL, *tkey=NULL; +- ASN1_OCTET_STRING *data_body=NULL; +- const EVP_CIPHER *evp_cipher=NULL; +- EVP_CIPHER_CTX *evp_ctx=NULL; +- X509_ALGOR *enc_alg=NULL; +- STACK_OF(PKCS7_RECIP_INFO) *rsk=NULL; +- PKCS7_RECIP_INFO *ri=NULL; ++ krb5_error_code ret; ++ int ok = 0, plaintext_len = 0, final_len; ++ unsigned int keylen = 0, eklen = 0, blocksize; ++ unsigned char *ek = NULL, *tkey = NULL, *plaintext = NULL, *use_key; ++ ASN1_OCTET_STRING *data_body = p7->d.enveloped->enc_data->enc_data; ++ const EVP_CIPHER *evp_cipher; ++ EVP_CIPHER_CTX *evp_ctx = NULL; ++ X509_ALGOR *enc_alg = p7->d.enveloped->enc_data->algorithm; ++ STACK_OF(PKCS7_RECIP_INFO) *rsk = p7->d.enveloped->recipientinfo; ++ PKCS7_RECIP_INFO *ri = NULL; + +- p7->state=PKCS7_S_HEADER; ++ *data_out = NULL; ++ *len_out = 0; + +- rsk=p7->d.enveloped->recipientinfo; +- enc_alg=p7->d.enveloped->enc_data->algorithm; +- data_body=p7->d.enveloped->enc_data->enc_data; +- evp_cipher=EVP_get_cipherbyobj(enc_alg->algorithm); +- if (evp_cipher == NULL) { +- PKCS7err(PKCS7_F_PKCS7_DATADECODE,PKCS7_R_UNSUPPORTED_CIPHER_TYPE); +- goto cleanup; +- } +- +- if ((etmp=BIO_new(BIO_f_cipher())) == NULL) { +- PKCS7err(PKCS7_F_PKCS7_DATADECODE,ERR_R_BIO_LIB); +- goto cleanup; +- } +- +- /* It was encrypted, we need to decrypt the secret key +- * with the private key */ ++ p7->state = PKCS7_S_HEADER; + + /* RFC 4556 section 3.2.3.2 requires that there be exactly one + * recipientInfo. */ + if (sk_PKCS7_RECIP_INFO_num(rsk) != 1) { + pkiDebug("invalid number of EnvelopedData RecipientInfos\n"); +- goto cleanup; ++ return 0; + } +- + ri = sk_PKCS7_RECIP_INFO_value(rsk, 0); +- (void)pkinit_decode_data(context, id_cryptoctx, +- ASN1_STRING_get0_data(ri->enc_key), +- ASN1_STRING_length(ri->enc_key), &ek, &eklen); + +- evp_ctx=NULL; +- BIO_get_cipher_ctx(etmp,&evp_ctx); +- if (EVP_CipherInit_ex(evp_ctx,evp_cipher,NULL,NULL,NULL,0) <= 0) ++ evp_cipher = EVP_get_cipherbyobj(enc_alg->algorithm); ++ if (evp_cipher == NULL) + goto cleanup; +- if (EVP_CIPHER_asn1_to_param(evp_ctx,enc_alg->parameter) < 0) ++ keylen = EVP_CIPHER_key_length(evp_cipher); ++ blocksize = EVP_CIPHER_block_size(evp_cipher); ++ ++ evp_ctx = EVP_CIPHER_CTX_new(); ++ if (evp_ctx == NULL) ++ goto cleanup; ++ if (!EVP_DecryptInit(evp_ctx, evp_cipher, NULL, NULL) || ++ EVP_CIPHER_asn1_to_param(evp_ctx, enc_alg->parameter) <= 0) + goto cleanup; + + /* Generate a random symmetric key to avoid exposing timing data if RSA + * decryption fails the padding check. */ +- tkeylen = EVP_CIPHER_CTX_key_length(evp_ctx); +- tkey = OPENSSL_malloc(tkeylen); +- if (tkey == NULL) +- goto cleanup; +- if (EVP_CIPHER_CTX_rand_key(evp_ctx, tkey) <= 0) +- goto cleanup; +- if (ek == NULL) { +- ek = tkey; +- eklen = tkeylen; +- tkey = NULL; +- } +- +- if (eklen != (unsigned)EVP_CIPHER_CTX_key_length(evp_ctx)) { +- /* Some S/MIME clients don't use the same key +- * and effective key length. The key length is +- * determined by the size of the decrypted RSA key. +- */ +- if (!EVP_CIPHER_CTX_set_key_length(evp_ctx, (int)eklen)) { +- ek = tkey; +- eklen = tkeylen; +- tkey = NULL; +- } +- } +- if (EVP_CipherInit_ex(evp_ctx,NULL,NULL,ek,NULL,0) <= 0) ++ tkey = malloc(keylen); ++ if (tkey == NULL || !EVP_CIPHER_CTX_rand_key(evp_ctx, tkey)) + goto cleanup; + +- if (out == NULL) +- out=etmp; +- else +- BIO_push(out,etmp); +- etmp=NULL; ++ /* Decrypt the secret key with the private key. */ ++ ret = pkinit_decode_data(context, id_cryptoctx, ++ ASN1_STRING_get0_data(ri->enc_key), ++ ASN1_STRING_length(ri->enc_key), &ek, &eklen); ++ use_key = (ret || eklen != keylen) ? tkey : ek; + +- if (data_body->length > 0) +- bio = BIO_new_mem_buf(data_body->data, data_body->length); +- else { +- bio=BIO_new(BIO_s_mem()); +- BIO_set_mem_eof_return(bio,0); +- } +- BIO_push(out,bio); +- bio=NULL; ++ /* Allocate a plaintext buffer and decrypt data_body into it. */ ++ plaintext = malloc(data_body->length + blocksize); ++ if (plaintext == NULL) ++ goto cleanup; ++ if (!EVP_DecryptInit(evp_ctx, NULL, use_key, NULL)) ++ goto cleanup; ++ if (!EVP_DecryptUpdate(evp_ctx, plaintext, &plaintext_len, ++ data_body->data, data_body->length)) ++ goto cleanup; ++ if (!EVP_DecryptFinal(evp_ctx, plaintext + plaintext_len, &final_len)) ++ goto cleanup; ++ plaintext_len += final_len; + +- if (0) { +- cleanup: +- if (out != NULL) BIO_free_all(out); +- if (etmp != NULL) BIO_free_all(etmp); +- if (bio != NULL) BIO_free_all(bio); +- out=NULL; +- } +- if (ek != NULL) { +- OPENSSL_cleanse(ek, eklen); +- OPENSSL_free(ek); +- } +- if (tkey != NULL) { +- OPENSSL_cleanse(tkey, tkeylen); +- OPENSSL_free(tkey); +- } +- return(out); ++ *len_out = plaintext_len; ++ *data_out = plaintext; ++ plaintext = NULL; ++ ok = 1; ++ ++cleanup: ++ EVP_CIPHER_CTX_free(evp_ctx); ++ zapfree(plaintext, plaintext_len); ++ zapfree(ek, eklen); ++ zapfree(tkey, keylen); ++ return ok; + } + + #ifdef DEBUG_DH diff --git a/Use-secure_getenv-where-appropriate.patch b/Use-secure_getenv-where-appropriate.patch index 708548d..2ddb7f0 100644 --- a/Use-secure_getenv-where-appropriate.patch +++ b/Use-secure_getenv-where-appropriate.patch @@ -1,4 +1,4 @@ -From 8987708dbafbb7d3eb743f06d9fbef40a04275e3 Mon Sep 17 00:00:00 2001 +From ec428980300c85ba2c4b220174c2c05447cf4bd8 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 24 Apr 2019 16:19:50 -0400 Subject: [PATCH] Use secure_getenv() where appropriate diff --git a/krb5-1.17-FIPS-aware-SPAKE-group-negotiation.patch b/krb5-1.17-FIPS-aware-SPAKE-group-negotiation.patch deleted file mode 100644 index a3b72d1..0000000 --- a/krb5-1.17-FIPS-aware-SPAKE-group-negotiation.patch +++ /dev/null @@ -1,42 +0,0 @@ -From e039796a0fbefac03a3fd888aef7d192e7c1437e Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 1 Apr 2019 13:13:09 -0400 -Subject: [PATCH] krb5-1.17 FIPS-aware SPAKE group negotiation - ---- - src/plugins/preauth/spake/groups.c | 8 ++++++++ - 1 file changed, 8 insertions(+) - -diff --git a/src/plugins/preauth/spake/groups.c b/src/plugins/preauth/spake/groups.c -index a195cc195..8a913cb5a 100644 ---- a/src/plugins/preauth/spake/groups.c -+++ b/src/plugins/preauth/spake/groups.c -@@ -56,6 +56,8 @@ - #include "trace.h" - #include "groups.h" - -+#include -+ - #define DEFAULT_GROUPS_CLIENT "edwards25519" - #define DEFAULT_GROUPS_KDC "" - -@@ -102,6 +104,9 @@ find_gdef(int32_t group) - { - size_t i; - -+ if (group == builtin_edwards25519.reg->id && FIPS_mode()) -+ return NULL; -+ - for (i = 0; groupdefs[i] != NULL; i++) { - if (groupdefs[i]->reg->id == group) - return groupdefs[i]; -@@ -116,6 +121,9 @@ find_gnum(const char *name) - { - size_t i; - -+ if (strcasecmp(name, builtin_edwards25519.reg->name) == 0 && FIPS_mode()) -+ return 0; -+ - for (i = 0; groupdefs[i] != NULL; i++) { - if (strcasecmp(name, groupdefs[i]->reg->name) == 0) - return groupdefs[i]->reg->id; diff --git a/krb5-1.17-Use-openssl-s-PRNG-in-FIPS-mode.patch b/krb5-1.17-Use-openssl-s-PRNG-in-FIPS-mode.patch deleted file mode 100644 index 97d2bc8..0000000 --- a/krb5-1.17-Use-openssl-s-PRNG-in-FIPS-mode.patch +++ /dev/null @@ -1,40 +0,0 @@ -From e307112cfcc52474d07eac890825303655ef8b6f Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 4 Jan 2019 17:00:15 -0500 -Subject: [PATCH] krb5-1.17 Use openssl's PRNG in FIPS mode - ---- - src/lib/crypto/krb/prng.c | 11 ++++++++++- - 1 file changed, 10 insertions(+), 1 deletion(-) - -diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c -index cb9ca9b98..f0e9984ca 100644 ---- a/src/lib/crypto/krb/prng.c -+++ b/src/lib/crypto/krb/prng.c -@@ -26,6 +26,8 @@ - - #include "crypto_int.h" - -+#include -+ - krb5_error_code KRB5_CALLCONV - krb5_c_random_seed(krb5_context context, krb5_data *data) - { -@@ -99,9 +101,16 @@ krb5_boolean - k5_get_os_entropy(unsigned char *buf, size_t len, int strong) - { - const char *device; --#if defined(__linux__) && defined(SYS_getrandom) - int r; - -+ /* A wild FIPS mode appeared! */ -+ if (FIPS_mode()) { -+ /* The return codes on this API are not good */ -+ r = RAND_bytes(buf, len); -+ return r == 1; -+ } -+ -+#if defined(__linux__) && defined(SYS_getrandom) - while (len > 0) { - /* - * Pull from the /dev/urandom pool, but require it to have been seeded. diff --git a/krb5-1.17-Become-FIPS-aware.patch b/krb5-1.17post1-FIPS-with-PRNG-and-SPAKE.patch similarity index 66% rename from krb5-1.17-Become-FIPS-aware.patch rename to krb5-1.17post1-FIPS-with-PRNG-and-SPAKE.patch index b67f95c..4ce69ab 100644 --- a/krb5-1.17-Become-FIPS-aware.patch +++ b/krb5-1.17post1-FIPS-with-PRNG-and-SPAKE.patch @@ -1,7 +1,10 @@ -From 15c0aec4315cc5cfae864b179848f043e2b100c6 Mon Sep 17 00:00:00 2001 +From dff44c20d9d9ed6a3e71888406b2913d9309e738 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 -Subject: [PATCH] krb5-1.17 Become FIPS-aware +Subject: [PATCH] krb5-1.17post1 FIPS with PRNG and SPAKE + +NB: Use openssl's PRNG in FIPS mode, and be aware during SPAKE group +negotiation. A lot of the FIPS error conditions from OpenSSL are incredibly mysterious (at best, things return NULL unexpectedly; at worst, @@ -10,17 +13,50 @@ ENOMEM). In order to cope with this, we need to have some level of awareness of what we can and can't safely call. This will slow down some calls slightly (FIPS_mode() takes multiple -locks), but not for any crypto we care about - which is to say that -AES is fine. +locks), but not for any ciphers we care about - which is to say that +AES is fine. Shame about the SPAKE groups though. --- + src/lib/crypto/krb/prng.c | 11 ++++++++++- src/lib/crypto/openssl/enc_provider/camellia.c | 6 ++++++ src/lib/crypto/openssl/enc_provider/des.c | 9 +++++++++ src/lib/crypto/openssl/enc_provider/des3.c | 6 ++++++ src/lib/crypto/openssl/enc_provider/rc4.c | 13 ++++++++++++- src/lib/crypto/openssl/hash_provider/hash_evp.c | 4 ++++ src/lib/crypto/openssl/hmac.c | 6 +++++- - 6 files changed, 42 insertions(+), 2 deletions(-) + src/plugins/preauth/spake/groups.c | 8 ++++++++ + 8 files changed, 60 insertions(+), 3 deletions(-) +diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c +index cb9ca9b98..f0e9984ca 100644 +--- a/src/lib/crypto/krb/prng.c ++++ b/src/lib/crypto/krb/prng.c +@@ -26,6 +26,8 @@ + + #include "crypto_int.h" + ++#include ++ + krb5_error_code KRB5_CALLCONV + krb5_c_random_seed(krb5_context context, krb5_data *data) + { +@@ -99,9 +101,16 @@ krb5_boolean + k5_get_os_entropy(unsigned char *buf, size_t len, int strong) + { + const char *device; +-#if defined(__linux__) && defined(SYS_getrandom) + int r; + ++ /* A wild FIPS mode appeared! */ ++ if (FIPS_mode()) { ++ /* The return codes on this API are not good */ ++ r = RAND_bytes(buf, len); ++ return r == 1; ++ } ++ ++#if defined(__linux__) && defined(SYS_getrandom) + while (len > 0) { + /* + * Pull from the /dev/urandom pool, but require it to have been seeded. diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c index 2da691329..f79679a0b 100644 --- a/src/lib/crypto/openssl/enc_provider/camellia.c @@ -104,30 +140,30 @@ index 1c439c2cd..8be555a8d 100644 if (ret != 0 || empty) return ret; diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c -index 7f3c086ed..a3f2a7442 100644 +index a65d57b7a..6ccaca94a 100644 --- a/src/lib/crypto/openssl/enc_provider/rc4.c +++ b/src/lib/crypto/openssl/enc_provider/rc4.c -@@ -66,6 +66,9 @@ k5_arcfour_docrypt(krb5_key key,const krb5_data *state, krb5_crypto_iov *data, +@@ -66,6 +66,9 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, EVP_CIPHER_CTX *ctx = NULL; struct arcfour_state *arcstate; + if (FIPS_mode()) + return KRB5_CRYPTO_INTERNAL; + - arcstate = (state != NULL) ? (struct arcfour_state *) state->data : NULL; + arcstate = (state != NULL) ? (void *)state->data : NULL; if (arcstate != NULL) { ctx = arcstate->ctx; -@@ -113,7 +116,12 @@ k5_arcfour_docrypt(krb5_key key,const krb5_data *state, krb5_crypto_iov *data, +@@ -113,7 +116,12 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, static void k5_arcfour_free_state(krb5_data *state) { -- struct arcfour_state *arcstate = (struct arcfour_state *) state->data; +- struct arcfour_state *arcstate = (void *)state->data; + struct arcfour_state *arcstate; + + if (FIPS_mode()) + return; + -+ arcstate = (struct arcfour_state *) state->data; ++ arcstate = (void *) state->data; EVP_CIPHER_CTX_free(arcstate->ctx); free(arcstate); @@ -138,9 +174,9 @@ index 7f3c086ed..a3f2a7442 100644 + if (FIPS_mode()) + return KRB5_CRYPTO_INTERNAL; + - /* Create a state structure with an uninitialized context. */ - arcstate = calloc(1, sizeof(*arcstate)); - if (arcstate == NULL) + /* + * The cipher state here is a saved pointer to a struct arcfour_state + * object, rather than a flat byte array as in most enc providers. The diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c index 957ed8d9c..8c1fd7f59 100644 --- a/src/lib/crypto/openssl/hash_provider/hash_evp.c @@ -163,7 +199,7 @@ index 957ed8d9c..8c1fd7f59 100644 } diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c -index b2db6ec02..d94d9ac94 100644 +index 7dc59dcc0..769a50c00 100644 --- a/src/lib/crypto/openssl/hmac.c +++ b/src/lib/crypto/openssl/hmac.c @@ -103,7 +103,11 @@ map_digest(const struct krb5_hash_provider *hash) @@ -179,3 +215,36 @@ index b2db6ec02..d94d9ac94 100644 return EVP_md5(); else if (!strncmp(hash->hash_name, "MD4", 3)) return EVP_md4(); +diff --git a/src/plugins/preauth/spake/groups.c b/src/plugins/preauth/spake/groups.c +index a195cc195..8a913cb5a 100644 +--- a/src/plugins/preauth/spake/groups.c ++++ b/src/plugins/preauth/spake/groups.c +@@ -56,6 +56,8 @@ + #include "trace.h" + #include "groups.h" + ++#include ++ + #define DEFAULT_GROUPS_CLIENT "edwards25519" + #define DEFAULT_GROUPS_KDC "" + +@@ -102,6 +104,9 @@ find_gdef(int32_t group) + { + size_t i; + ++ if (group == builtin_edwards25519.reg->id && FIPS_mode()) ++ return NULL; ++ + for (i = 0; groupdefs[i] != NULL; i++) { + if (groupdefs[i]->reg->id == group) + return groupdefs[i]; +@@ -116,6 +121,9 @@ find_gnum(const char *name) + { + size_t i; + ++ if (strcasecmp(name, builtin_edwards25519.reg->name) == 0 && FIPS_mode()) ++ return 0; ++ + for (i = 0; groupdefs[i] != NULL; i++) { + if (strcasecmp(name, groupdefs[i]->reg->name) == 0) + return groupdefs[i]->reg->id; diff --git a/krb5.spec b/krb5.spec index 286cf09..16dc2e4 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 17%{?dist} +Release: 18%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -62,7 +62,6 @@ Patch36: krb5-1.11-kpasswdtest.patch Patch37: krb5-1.17-In-FIPS-mode-add-plaintext-fallback-for-RC.patch Patch90: Add-tests-for-KCM-ccache-type.patch Patch92: Address-some-optimized-out-memset-calls.patch -Patch93: krb5-1.17-Use-openssl-s-PRNG-in-FIPS-mode.patch Patch94: Avoid-allocating-a-register-in-zap-assembly.patch Patch95: In-rd_req_dec-always-log-non-permitted-enctypes.patch Patch96: In-kpropd-debug-log-proper-ticket-enctype-names.patch @@ -71,8 +70,6 @@ Patch98: Make-etype-names-in-KDC-logs-human-readable.patch Patch99: Mark-deprecated-enctypes-when-used.patch Patch100: Properly-size-ifdef-in-k5_cccol_lock.patch Patch101: Fix-memory-leak-in-none-replay-cache-type.patch -Patch102: krb5-1.17-Become-FIPS-aware.patch -Patch103: krb5-1.17-FIPS-aware-SPAKE-group-negotiation.patch Patch104: Clarify-header-comment-for-krb5_cc_start_seq_get.patch Patch105: Implement-krb5_cc_remove_cred-for-remaining-types.patch Patch106: Remove-srvtab-support.patch @@ -88,6 +85,15 @@ Patch115: Check-more-errors-in-OpenSSL-crypto-backend.patch Patch116: Clear-forwardable-flag-instead-of-denying-request.patch Patch117: Add-dns_canonicalize_hostname-fallback-support.patch Patch118: Use-secure_getenv-where-appropriate.patch +Patch119: Initialize-some-data-structure-magic-fields.patch +Patch120: Fix-some-return-code-handling-bugs.patch +Patch121: Modernize-exit-path-in-gss_krb5int_copy_ccache.patch +Patch122: Simplify-SAM-2-as_key-handling.patch +Patch123: Avoid-alignment-warnings-in-openssl-rc4.c.patch +Patch124: Simply-OpenSSL-PKCS7-decryption-code.patch +Patch125: Improve-error-messages-from-kadmin-change_password.patch +Patch126: Remove-more-dead-code.patch +Patch127: krb5-1.17post1-FIPS-with-PRNG-and-SPAKE.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -694,6 +700,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri May 10 2019 Robbie Harwood - 1.17-18 +- Pull in 2019-05-02 static analysis updates + * Fri May 03 2019 Robbie Harwood - 1.17-17 - Move krb5-kdb-version provide into krb5-server for freeipa From 4b3d9079ae315c8d7201c75d6813871393bc981c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 14 May 2019 11:07:43 -0400 Subject: [PATCH 104/304] Remove checksum type profile variables --- Remove-checksum-type-profile-variables.patch | 428 ++++++++++++++++++ ...d-variable-def_kslist-from-two-files.patch | 69 +++ krb5.spec | 7 +- 3 files changed, 503 insertions(+), 1 deletion(-) create mode 100644 Remove-checksum-type-profile-variables.patch create mode 100644 Remove-dead-variable-def_kslist-from-two-files.patch diff --git a/Remove-checksum-type-profile-variables.patch b/Remove-checksum-type-profile-variables.patch new file mode 100644 index 0000000..90596e5 --- /dev/null +++ b/Remove-checksum-type-profile-variables.patch @@ -0,0 +1,428 @@ +From 443b8989c5d554f5347b72364d704d4626ca9a92 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 13 May 2019 14:19:57 -0400 +Subject: [PATCH] Remove checksum type profile variables + +Remove support for the krb5.conf relations ap_req_checksum_type, +kdc_req_checksum_type, and safe_checksum_type. These values were +useful for interoperating with very old KDCs, which should no longer +be deployed. + +Additionally, kdc_req_checksum_type was incorrectly documented as only +applying to single-DES keys; in practice it also worked for RC4. The +other two were not clearly documented, but safe_checksum_type did +allow use of hmac-md5-rc4 for any enctype, and ap_req_checksum_type +did not impose any limitations. + +[ghudson@mit.edu: edited commit message] + +ticket: 8804 (new) +(cherry picked from commit a5a140dc85201faf1ba3a687553058354722a1b4) +--- + doc/admin/conf_files/krb5_conf.rst | 37 ------------ + src/include/k5-int.h | 6 -- + src/lib/krb5/krb/auth_con.c | 2 - + src/lib/krb5/krb/init_ctx.c | 13 ----- + src/lib/krb5/krb/send_tgs.c | 19 +------ + src/lib/krb5/krb/ser_ctx.c | 38 +------------ + src/lib/krb5/krb/t_copy_context.c | 6 -- + src/man/krb5.conf.man | 90 ++---------------------------- + 8 files changed, 7 insertions(+), 204 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index e9f7e8c59..5df3bfe36 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -111,14 +111,6 @@ The libdefaults section may contain any of the following relations: + strong crypto. Users in affected environments should set this tag + to true until their infrastructure adopts stronger ciphers. + +-**ap_req_checksum_type** +- An integer which specifies the type of AP-REQ checksum to use in +- authenticators. This variable should be unset so the appropriate +- checksum for the encryption key in use will be used. This can be +- set if backward compatibility requires a specific checksum type. +- See the **kdc_req_checksum_type** configuration option for the +- possible values and their meanings. +- + **canonicalize** + If this flag is set to true, initial ticket requests to the KDC + will request canonicalization of the client principal name, and +@@ -297,26 +289,6 @@ The libdefaults section may contain any of the following relations: + corrective factor is only used by the Kerberos library; it is not + used to change the system clock. The default value is 1. + +-**kdc_req_checksum_type** +- An integer which specifies the type of checksum to use for the KDC +- requests, for compatibility with very old KDC implementations. +- This value is only used for DES keys; other keys use the preferred +- checksum type for those keys. +- +- The possible values and their meanings are as follows. +- +- ======== =============================== +- 1 CRC32 +- 2 RSA MD4 +- 3 RSA MD4 DES +- 4 DES CBC +- 7 RSA MD5 +- 8 RSA MD5 DES +- 9 NIST SHA +- 12 HMAC SHA1 DES3 +- -138 Microsoft MD5 HMAC checksum type +- ======== =============================== +- + **noaddresses** + If this flag is true, requests for initial tickets will not be + made with address restrictions set, allowing the tickets to be +@@ -365,15 +337,6 @@ The libdefaults section may contain any of the following relations: + (:ref:`duration` string.) Sets the default renewable lifetime + for initial ticket requests. The default value is 0. + +-**safe_checksum_type** +- An integer which specifies the type of checksum to use for the +- KRB-SAFE requests. By default it is set to 8 (RSA MD5 DES). For +- compatibility with applications linked against DCE version 1.1 or +- earlier Kerberos libraries, use a value of 3 to use the RSA MD4 +- DES instead. This field is ignored when its value is incompatible +- with the session key type. See the **kdc_req_checksum_type** +- configuration option for the possible values and their meanings. +- + **spake_preauth_groups** + A whitespace or comma-separated list of words which specifies the + groups allowed for SPAKE preauthentication. The possible values +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 1e6a739e9..1a78fd7a9 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -182,7 +182,6 @@ typedef unsigned char u_char; + #define KRB5_CONF_ACL_FILE "acl_file" + #define KRB5_CONF_ADMIN_SERVER "admin_server" + #define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto" +-#define KRB5_CONF_AP_REQ_CHECKSUM_TYPE "ap_req_checksum_type" + #define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local" + #define KRB5_CONF_AUTH_TO_LOCAL_NAMES "auth_to_local_names" + #define KRB5_CONF_CANONICALIZE "canonicalize" +@@ -241,7 +240,6 @@ typedef unsigned char u_char; + #define KRB5_CONF_KDC_LISTEN "kdc_listen" + #define KRB5_CONF_KDC_MAX_DGRAM_REPLY_SIZE "kdc_max_dgram_reply_size" + #define KRB5_CONF_KDC_PORTS "kdc_ports" +-#define KRB5_CONF_KDC_REQ_CHECKSUM_TYPE "kdc_req_checksum_type" + #define KRB5_CONF_KDC_TCP_PORTS "kdc_tcp_ports" + #define KRB5_CONF_KDC_TCP_LISTEN "kdc_tcp_listen" + #define KRB5_CONF_KDC_TCP_LISTEN_BACKLOG "kdc_tcp_listen_backlog" +@@ -289,7 +287,6 @@ typedef unsigned char u_char; + #define KRB5_CONF_REJECT_BAD_TRANSIT "reject_bad_transit" + #define KRB5_CONF_RENEW_LIFETIME "renew_lifetime" + #define KRB5_CONF_RESTRICT_ANONYMOUS_TO_TGT "restrict_anonymous_to_tgt" +-#define KRB5_CONF_SAFE_CHECKSUM_TYPE "safe_checksum_type" + #define KRB5_CONF_SUPPORTED_ENCTYPES "supported_enctypes" + #define KRB5_CONF_SPAKE_PREAUTH_INDICATOR "spake_preauth_indicator" + #define KRB5_CONF_SPAKE_PREAUTH_KDC_CHALLENGE "spake_preauth_kdc_challenge" +@@ -1185,9 +1182,6 @@ struct _krb5_context { + void *ser_ctx; + /* allowable clock skew */ + krb5_deltat clockskew; +- krb5_cksumtype kdc_req_sumtype; +- krb5_cksumtype default_ap_req_sumtype; +- krb5_cksumtype default_safe_sumtype; + krb5_flags kdc_default_options; + krb5_flags library_options; + krb5_boolean profile_secure; +diff --git a/src/lib/krb5/krb/auth_con.c b/src/lib/krb5/krb/auth_con.c +index c86a4af63..1dfce631c 100644 +--- a/src/lib/krb5/krb/auth_con.c ++++ b/src/lib/krb5/krb/auth_con.c +@@ -40,8 +40,6 @@ krb5_auth_con_init(krb5_context context, krb5_auth_context *auth_context) + (*auth_context)->auth_context_flags = + KRB5_AUTH_CONTEXT_DO_TIME | KRB5_AUTH_CONN_INITIALIZED; + +- (*auth_context)->req_cksumtype = context->default_ap_req_sumtype; +- (*auth_context)->safe_cksumtype = context->default_safe_sumtype; + (*auth_context)->checksum_func = NULL; + (*auth_context)->checksum_func_data = NULL; + (*auth_context)->negotiated_etype = ENCTYPE_NULL; +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index d263d5cc5..37405728c 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -258,19 +258,6 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + get_integer(ctx, KRB5_CONF_CLOCKSKEW, DEFAULT_CLOCKSKEW, &tmp); + ctx->clockskew = tmp; + +- /* DCE 1.1 and below only support CKSUMTYPE_RSA_MD4 (2) */ +- /* DCE add kdc_req_checksum_type = 2 to krb5.conf */ +- get_integer(ctx, KRB5_CONF_KDC_REQ_CHECKSUM_TYPE, CKSUMTYPE_RSA_MD5, +- &tmp); +- ctx->kdc_req_sumtype = tmp; +- +- get_integer(ctx, KRB5_CONF_AP_REQ_CHECKSUM_TYPE, 0, &tmp); +- ctx->default_ap_req_sumtype = tmp; +- +- get_integer(ctx, KRB5_CONF_SAFE_CHECKSUM_TYPE, CKSUMTYPE_RSA_MD5_DES, +- &tmp); +- ctx->default_safe_sumtype = tmp; +- + get_integer(ctx, KRB5_CONF_KDC_DEFAULT_OPTIONS, KDC_OPT_RENEWABLE_OK, + &tmp); + ctx->kdc_default_options = tmp; +diff --git a/src/lib/krb5/krb/send_tgs.c b/src/lib/krb5/krb/send_tgs.c +index e43a5cc5b..3dda2fdaa 100644 +--- a/src/lib/krb5/krb/send_tgs.c ++++ b/src/lib/krb5/krb/send_tgs.c +@@ -53,7 +53,6 @@ tgs_construct_ap_req(krb5_context context, krb5_data *checksum_data, + krb5_creds *tgt, krb5_keyblock *subkey, + krb5_data **ap_req_asn1_out) + { +- krb5_cksumtype cksumtype; + krb5_error_code ret; + krb5_checksum checksum; + krb5_authenticator authent; +@@ -67,24 +66,8 @@ tgs_construct_ap_req(krb5_context context, krb5_data *checksum_data, + memset(&ap_req, 0, sizeof(ap_req)); + memset(&authent_enc, 0, sizeof(authent_enc)); + +- /* Determine the authenticator checksum type. */ +- switch (tgt->keyblock.enctype) { +- case ENCTYPE_DES_CBC_CRC: +- case ENCTYPE_DES_CBC_MD4: +- case ENCTYPE_DES_CBC_MD5: +- case ENCTYPE_ARCFOUR_HMAC: +- case ENCTYPE_ARCFOUR_HMAC_EXP: +- cksumtype = context->kdc_req_sumtype; +- break; +- default: +- ret = krb5int_c_mandatory_cksumtype(context, tgt->keyblock.enctype, +- &cksumtype); +- if (ret) +- goto cleanup; +- } +- + /* Generate checksum. */ +- ret = krb5_c_make_checksum(context, cksumtype, &tgt->keyblock, ++ ret = krb5_c_make_checksum(context, 0, &tgt->keyblock, + KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, checksum_data, + &checksum); + if (ret) +diff --git a/src/lib/krb5/krb/ser_ctx.c b/src/lib/krb5/krb/ser_ctx.c +index a9f50b239..39f656322 100644 +--- a/src/lib/krb5/krb/ser_ctx.c ++++ b/src/lib/krb5/krb/ser_ctx.c +@@ -124,9 +124,6 @@ krb5_context_size(krb5_context kcontext, krb5_pointer arg, size_t *sizep) + * krb5_int32 for n_tgs_etypes*sizeof(krb5_int32) + * nktypes*sizeof(krb5_int32) for tgs_etypes. + * krb5_int32 for clockskew +- * krb5_int32 for kdc_req_sumtype +- * krb5_int32 for ap_req_sumtype +- * krb5_int32 for safe_sumtype + * krb5_int32 for kdc_default_options + * krb5_int32 for library_options + * krb5_int32 for profile_secure +@@ -139,7 +136,7 @@ krb5_context_size(krb5_context kcontext, krb5_pointer arg, size_t *sizep) + kret = EINVAL; + if ((context = (krb5_context) arg)) { + /* Calculate base length */ +- required = (14 * sizeof(krb5_int32) + ++ required = (11 * sizeof(krb5_int32) + + (etypes_len(context->in_tkt_etypes) * sizeof(krb5_int32)) + + (etypes_len(context->tgs_etypes) * sizeof(krb5_int32))); + +@@ -255,24 +252,6 @@ krb5_context_externalize(krb5_context kcontext, krb5_pointer arg, krb5_octet **b + if (kret) + return (kret); + +- /* Now kdc_req_sumtype */ +- kret = krb5_ser_pack_int32((krb5_int32) context->kdc_req_sumtype, +- &bp, &remain); +- if (kret) +- return (kret); +- +- /* Now default ap_req_sumtype */ +- kret = krb5_ser_pack_int32((krb5_int32) context->default_ap_req_sumtype, +- &bp, &remain); +- if (kret) +- return (kret); +- +- /* Now default safe_sumtype */ +- kret = krb5_ser_pack_int32((krb5_int32) context->default_safe_sumtype, +- &bp, &remain); +- if (kret) +- return (kret); +- + /* Now kdc_default_options */ + kret = krb5_ser_pack_int32((krb5_int32) context->kdc_default_options, + &bp, &remain); +@@ -426,21 +405,6 @@ krb5_context_internalize(krb5_context kcontext, krb5_pointer *argp, krb5_octet * + goto cleanup; + context->clockskew = (krb5_deltat) ibuf; + +- /* kdc_req_sumtype */ +- if ((kret = krb5_ser_unpack_int32(&ibuf, &bp, &remain))) +- goto cleanup; +- context->kdc_req_sumtype = (krb5_cksumtype) ibuf; +- +- /* default ap_req_sumtype */ +- if ((kret = krb5_ser_unpack_int32(&ibuf, &bp, &remain))) +- goto cleanup; +- context->default_ap_req_sumtype = (krb5_cksumtype) ibuf; +- +- /* default_safe_sumtype */ +- if ((kret = krb5_ser_unpack_int32(&ibuf, &bp, &remain))) +- goto cleanup; +- context->default_safe_sumtype = (krb5_cksumtype) ibuf; +- + /* kdc_default_options */ + if ((kret = krb5_ser_unpack_int32(&ibuf, &bp, &remain))) + goto cleanup; +diff --git a/src/lib/krb5/krb/t_copy_context.c b/src/lib/krb5/krb/t_copy_context.c +index a6e48cd25..22be2198b 100644 +--- a/src/lib/krb5/krb/t_copy_context.c ++++ b/src/lib/krb5/krb/t_copy_context.c +@@ -77,9 +77,6 @@ check_context(krb5_context c, krb5_context r) + check(c->os_context.os_flags == r->os_context.os_flags); + compare_string(c->os_context.default_ccname, r->os_context.default_ccname); + check(c->clockskew == r->clockskew); +- check(c->kdc_req_sumtype == r->kdc_req_sumtype); +- check(c->default_ap_req_sumtype == r->default_ap_req_sumtype); +- check(c->default_safe_sumtype == r->default_safe_sumtype); + check(c->kdc_default_options == r->kdc_default_options); + check(c->library_options == r->library_options); + check(c->profile_secure == r->profile_secure); +@@ -136,9 +133,6 @@ main(int argc, char **argv) + check(krb5_cc_set_default_name(ctx, "defccname") == 0); + check(krb5_set_default_realm(ctx, "defrealm") == 0); + ctx->clockskew = 18; +- ctx->kdc_req_sumtype = CKSUMTYPE_NIST_SHA; +- ctx->default_ap_req_sumtype = CKSUMTYPE_HMAC_SHA1_96_AES128; +- ctx->default_safe_sumtype = CKSUMTYPE_HMAC_SHA1_96_AES256; + ctx->kdc_default_options = KDC_OPT_FORWARDABLE; + ctx->library_options = 0; + ctx->profile_secure = TRUE; +diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man +index d431dce75..aafdf7f83 100644 +--- a/src/man/krb5.conf.man ++++ b/src/man/krb5.conf.man +@@ -1,6 +1,6 @@ + .\" Man page generated from reStructuredText. + . +-.TH "KRB5.CONF" "5" " " "1.17" "MIT Kerberos" ++.TH "KRB5.CONF" "5" " " "1.18" "MIT Kerberos" + .SH NAME + krb5.conf \- Kerberos configuration file + . +@@ -202,14 +202,6 @@ failures in existing Kerberos infrastructures that do not support + strong crypto. Users in affected environments should set this tag + to true until their infrastructure adopts stronger ciphers. + .TP +-\fBap_req_checksum_type\fP +-An integer which specifies the type of AP\-REQ checksum to use in +-authenticators. This variable should be unset so the appropriate +-checksum for the encryption key in use will be used. This can be +-set if backward compatibility requires a specific checksum type. +-See the \fBkdc_req_checksum_type\fP configuration option for the +-possible values and their meanings. +-.TP + \fBcanonicalize\fP + If this flag is set to true, initial ticket requests to the KDC + will request canonicalization of the client principal name, and +@@ -291,6 +283,10 @@ hostnames for use in service principal names. Setting this flag + to false can improve security by reducing reliance on DNS, but + means that short hostnames will not be canonicalized to + fully\-qualified hostnames. The default value is true. ++.sp ++If this option is set to \fBfallback\fP (new in release 1.18), DNS ++canonicalization will only be performed the server hostname is not ++found with the original name when requesting credentials. + .TP + \fBdns_lookup_kdc\fP + Indicate whether DNS SRV records should be used to locate the KDCs +@@ -384,73 +380,6 @@ requesting service tickets or authenticating to services. This + corrective factor is only used by the Kerberos library; it is not + used to change the system clock. The default value is 1. + .TP +-\fBkdc_req_checksum_type\fP +-An integer which specifies the type of checksum to use for the KDC +-requests, for compatibility with very old KDC implementations. +-This value is only used for DES keys; other keys use the preferred +-checksum type for those keys. +-.sp +-The possible values and their meanings are as follows. +-.TS +-center; +-|l|l|. +-_ +-T{ +-1 +-T} T{ +-CRC32 +-T} +-_ +-T{ +-2 +-T} T{ +-RSA MD4 +-T} +-_ +-T{ +-3 +-T} T{ +-RSA MD4 DES +-T} +-_ +-T{ +-4 +-T} T{ +-DES CBC +-T} +-_ +-T{ +-7 +-T} T{ +-RSA MD5 +-T} +-_ +-T{ +-8 +-T} T{ +-RSA MD5 DES +-T} +-_ +-T{ +-9 +-T} T{ +-NIST SHA +-T} +-_ +-T{ +-12 +-T} T{ +-HMAC SHA1 DES3 +-T} +-_ +-T{ +-\-138 +-T} T{ +-Microsoft MD5 HMAC checksum type +-T} +-_ +-.TE +-.TP + \fBnoaddresses\fP + If this flag is true, requests for initial tickets will not be + made with address restrictions set, allowing the tickets to be +@@ -499,15 +428,6 @@ set. The default is not to search domain components. + (duration string.) Sets the default renewable lifetime + for initial ticket requests. The default value is 0. + .TP +-\fBsafe_checksum_type\fP +-An integer which specifies the type of checksum to use for the +-KRB\-SAFE requests. By default it is set to 8 (RSA MD5 DES). For +-compatibility with applications linked against DCE version 1.1 or +-earlier Kerberos libraries, use a value of 3 to use the RSA MD4 +-DES instead. This field is ignored when its value is incompatible +-with the session key type. See the \fBkdc_req_checksum_type\fP +-configuration option for the possible values and their meanings. +-.TP + \fBspake_preauth_groups\fP + A whitespace or comma\-separated list of words which specifies the + groups allowed for SPAKE preauthentication. The possible values diff --git a/Remove-dead-variable-def_kslist-from-two-files.patch b/Remove-dead-variable-def_kslist-from-two-files.patch new file mode 100644 index 0000000..80b6a1f --- /dev/null +++ b/Remove-dead-variable-def_kslist-from-two-files.patch @@ -0,0 +1,69 @@ +From f18a482eec20369d7bcb4a7b2b6440c907215eff Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 2 May 2019 16:57:51 -0400 +Subject: [PATCH] Remove dead variable def_kslist from two files + +def_kslist was part of kdb5_create.c since its addition (commit +edf8b4d8a6a665c2aa150993cd813ea6c5cf12e1) and has always been +irrelevant since the rblock structure is fully initialized in +kdb5_create(). + +def_klist was copied into kdb5_ldap_realm.c (present in addition at +commit 42d9d6ab320ee3a661fe21472be542acd542d5be). The global rblock +structure (and therefore the initializer) was removed in commit +9c850f8b62784170a5e42315c1a9552ddcf4ca2b, leaving def_kslist +unreferenced. + +Remove def_kslist from both files, and remove the rblock initializer +from kdb5_create.c. + +[ghudson@mit.edu: edited commit message] + +(cherry picked from commit 6309f5e3508cd24151222b2cd095766283e205f2) +--- + src/kadmin/dbutil/kdb5_create.c | 12 +----------- + src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c | 1 - + 2 files changed, 1 insertion(+), 12 deletions(-) + +diff --git a/src/kadmin/dbutil/kdb5_create.c b/src/kadmin/dbutil/kdb5_create.c +index bc1b9195d..efdb8adb0 100644 +--- a/src/kadmin/dbutil/kdb5_create.c ++++ b/src/kadmin/dbutil/kdb5_create.c +@@ -66,8 +66,6 @@ enum ap_op { + TGT_KEY /* special handling for tgt key */ + }; + +-krb5_key_salt_tuple def_kslist = { ENCTYPE_DES_CBC_CRC, KRB5_KDB_SALTTYPE_NORMAL }; +- + struct realm_info { + krb5_deltat max_life; + krb5_deltat max_rlife; +@@ -76,15 +74,7 @@ struct realm_info { + krb5_keyblock *key; + krb5_int32 nkslist; + krb5_key_salt_tuple *kslist; +-} rblock = { /* XXX */ +- KRB5_KDB_MAX_LIFE, +- KRB5_KDB_MAX_RLIFE, +- KRB5_KDB_EXPIRATION, +- KRB5_KDB_DEF_FLAGS, +- (krb5_keyblock *) NULL, +- 1, +- &def_kslist +-}; ++} rblock; + + struct iterate_args { + krb5_context ctx; +diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c +index 5a745e21d..c21d19981 100644 +--- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c ++++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c +@@ -91,7 +91,6 @@ + extern time_t get_date(char *); /* kadmin/cli/getdate.o */ + + char *yes = "yes\n"; /* \n to compare against result of fgets */ +-krb5_key_salt_tuple def_kslist = {ENCTYPE_DES_CBC_CRC, KRB5_KDB_SALTTYPE_NORMAL}; + + krb5_data tgt_princ_entries[] = { + {0, KRB5_TGS_NAME_SIZE, KRB5_TGS_NAME}, diff --git a/krb5.spec b/krb5.spec index 16dc2e4..b3a6e0b 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 18%{?dist} +Release: 19%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -94,6 +94,8 @@ Patch124: Simply-OpenSSL-PKCS7-decryption-code.patch Patch125: Improve-error-messages-from-kadmin-change_password.patch Patch126: Remove-more-dead-code.patch Patch127: krb5-1.17post1-FIPS-with-PRNG-and-SPAKE.patch +Patch128: Remove-checksum-type-profile-variables.patch +Patch129: Remove-dead-variable-def_kslist-from-two-files.patch License: MIT URL: http://web.mit.edu/kerberos/www/ @@ -700,6 +702,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue May 14 2019 Robbie Harwood - 1.17-19 +- Remove checksum type profile variables + * Fri May 10 2019 Robbie Harwood - 1.17-18 - Pull in 2019-05-02 static analysis updates From aa55266a84a9bbc429b2056d7fede7358eebdb4c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 14 May 2019 12:34:12 -0400 Subject: [PATCH 105/304] (Patch consolidation; hopefully no changes) --- ...nonicalize_hostname-fallback-support.patch | 2 +- ...on-and-enctype-flag-for-deprecations.patch | 2 +- Add-tests-for-KCM-ccache-type.patch | 2 +- Address-some-optimized-out-memset-calls.patch | 2 +- ...-alignment-warnings-in-openssl-rc4.c.patch | 2 +- ...llocating-a-register-in-zap-assembly.patch | 2 +- ...ore-errors-in-OpenSSL-crypto-backend.patch | 2 +- ...er-comment-for-krb5_cc_start_seq_get.patch | 2 +- ...able-flag-instead-of-denying-request.patch | 2 +- ...alm-change-logic-in-FILE-remove_cred.patch | 2 +- ...emory-leak-in-none-replay-cache-type.patch | 2 +- Fix-potential-close-1-in-cc_file.c.patch | 2 +- Fix-some-return-code-handling-bugs.patch | 2 +- ...5_cc_remove_cred-for-remaining-types.patch | 2 +- ...messages-from-kadmin-change_password.patch | 2 +- ...ebug-log-proper-ticket-enctype-names.patch | 2 +- ...ec-always-log-non-permitted-enctypes.patch | 2 +- ...ize-some-data-structure-magic-fields.patch | 2 +- ...ype-names-in-KDC-logs-human-readable.patch | 2 +- Mark-deprecated-enctypes-when-used.patch | 2 +- ...exit-path-in-gss_krb5int_copy_ccache.patch | 2 +- Properly-size-ifdef-in-k5_cccol_lock.patch | 2 +- ...beros-v4-support-vestiges-from-ccapi.patch | 2 +- ...api-related-comments-in-configure.ac.patch | 2 +- Remove-checksum-type-profile-variables.patch | 2 +- Remove-confvalidator-utility.patch | 2 +- ...d-variable-def_kslist-from-two-files.patch | 2 +- ...ygen-generated-HTML-output-for-ccapi.patch | 2 +- ...admin-RPC-support-for-setting-v4-key.patch | 2 +- Remove-more-dead-code.patch | 2 +- ...ovsec_adm_export-dump-format-support.patch | 2 +- Remove-srvtab-support.patch | 2 +- Simplify-SAM-2-as_key-handling.patch | 2 +- Simply-OpenSSL-PKCS7-decryption-code.patch | 2 +- Use-secure_getenv-where-appropriate.patch | 2 +- krb5-1.17post1-FIPS-with-PRNG-and-SPAKE.patch | 250 ----------------- ...ost2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch | 265 +++++++++++++++++- krb5.spec | 10 +- 38 files changed, 294 insertions(+), 301 deletions(-) delete mode 100644 krb5-1.17post1-FIPS-with-PRNG-and-SPAKE.patch rename krb5-1.17-In-FIPS-mode-add-plaintext-fallback-for-RC.patch => krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch (58%) diff --git a/Add-dns_canonicalize_hostname-fallback-support.patch b/Add-dns_canonicalize_hostname-fallback-support.patch index 188c2b4..e5a7e09 100644 --- a/Add-dns_canonicalize_hostname-fallback-support.patch +++ b/Add-dns_canonicalize_hostname-fallback-support.patch @@ -1,4 +1,4 @@ -From 05672fdc2530618441710361daba097bccf51f61 Mon Sep 17 00:00:00 2001 +From f256aeea76ad81305d005d3a052e7d2e0250dccc Mon Sep 17 00:00:00 2001 From: Simo Sorce Date: Tue, 4 Dec 2018 15:22:55 -0500 Subject: [PATCH] Add dns_canonicalize_hostname=fallback support diff --git a/Add-function-and-enctype-flag-for-deprecations.patch b/Add-function-and-enctype-flag-for-deprecations.patch index 13a8fcc..26d876d 100644 --- a/Add-function-and-enctype-flag-for-deprecations.patch +++ b/Add-function-and-enctype-flag-for-deprecations.patch @@ -1,4 +1,4 @@ -From 4cd829c935319049142052ac45f252a8c3c54b49 Mon Sep 17 00:00:00 2001 +From 81fe68ce11a676f93c101ddd7523e8de9b419deb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 16:16:57 -0500 Subject: [PATCH] Add function and enctype flag for deprecations diff --git a/Add-tests-for-KCM-ccache-type.patch b/Add-tests-for-KCM-ccache-type.patch index a20a682..3d34b3b 100644 --- a/Add-tests-for-KCM-ccache-type.patch +++ b/Add-tests-for-KCM-ccache-type.patch @@ -1,4 +1,4 @@ -From 306c0260dca7809c90dfa9e8889a6bd2401cee84 Mon Sep 17 00:00:00 2001 +From deedc59d6ab6dd4f988db931a3a0d43f977ca708 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Nov 2018 00:27:35 -0500 Subject: [PATCH] Add tests for KCM ccache type diff --git a/Address-some-optimized-out-memset-calls.patch b/Address-some-optimized-out-memset-calls.patch index 6572ba0..805edb5 100644 --- a/Address-some-optimized-out-memset-calls.patch +++ b/Address-some-optimized-out-memset-calls.patch @@ -1,4 +1,4 @@ -From 3dd99db324de1492444aab3e5468aea5f1767c6d Mon Sep 17 00:00:00 2001 +From 3909d11478c7bbfc988b5c09ed7b2d32a5959947 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 30 Dec 2018 16:40:28 -0500 Subject: [PATCH] Address some optimized-out memset() calls diff --git a/Avoid-alignment-warnings-in-openssl-rc4.c.patch b/Avoid-alignment-warnings-in-openssl-rc4.c.patch index 1081afc..60f603c 100644 --- a/Avoid-alignment-warnings-in-openssl-rc4.c.patch +++ b/Avoid-alignment-warnings-in-openssl-rc4.c.patch @@ -1,4 +1,4 @@ -From 05c4ea24fa8603572ea1bffc767886bb26b8d542 Mon Sep 17 00:00:00 2001 +From 041a4f3507ffe9f19bb69f8c1959230753b73f90 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 15:14:49 -0400 Subject: [PATCH] Avoid alignment warnings in openssl rc4.c diff --git a/Avoid-allocating-a-register-in-zap-assembly.patch b/Avoid-allocating-a-register-in-zap-assembly.patch index 096ffc0..518323d 100644 --- a/Avoid-allocating-a-register-in-zap-assembly.patch +++ b/Avoid-allocating-a-register-in-zap-assembly.patch @@ -1,4 +1,4 @@ -From 273475be9d8aafb41edf417f6317c9537a03c3fa Mon Sep 17 00:00:00 2001 +From e66fc8b903cded3aed007310815a8f1fac7e6c30 Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Thu, 3 Jan 2019 17:19:32 +0100 Subject: [PATCH] Avoid allocating a register in zap() assembly diff --git a/Check-more-errors-in-OpenSSL-crypto-backend.patch b/Check-more-errors-in-OpenSSL-crypto-backend.patch index fdb937f..ead5ef5 100644 --- a/Check-more-errors-in-OpenSSL-crypto-backend.patch +++ b/Check-more-errors-in-OpenSSL-crypto-backend.patch @@ -1,4 +1,4 @@ -From b87d0cd119732b9066606d388b4fdebde2facbe5 Mon Sep 17 00:00:00 2001 +From f48e578e443cf0217360dee6cef1fe2869059be4 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 22 Apr 2019 14:26:42 -0400 Subject: [PATCH] Check more errors in OpenSSL crypto backend diff --git a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch index e287f3c..a3f5be5 100644 --- a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch +++ b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch @@ -1,4 +1,4 @@ -From dc0ff969a963c0dcbf203a636cf12030ea2845d9 Mon Sep 17 00:00:00 2001 +From b804c5ec00580cf62fd3660939f0f3baf71822fe Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Apr 2019 14:18:57 -0400 Subject: [PATCH] Clarify header comment for krb5_cc_start_seq_get() diff --git a/Clear-forwardable-flag-instead-of-denying-request.patch b/Clear-forwardable-flag-instead-of-denying-request.patch index 523d04a..cec478b 100644 --- a/Clear-forwardable-flag-instead-of-denying-request.patch +++ b/Clear-forwardable-flag-instead-of-denying-request.patch @@ -1,4 +1,4 @@ -From 561ac441f046a01a4e71e3c475760cc2d42b8213 Mon Sep 17 00:00:00 2001 +From 6a23d8a1cf2ff7e247dbd4a737b87c792f78e5ab Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 15 Nov 2018 13:40:43 -0500 Subject: [PATCH] Clear forwardable flag instead of denying request diff --git a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch index 87d2afc..b13d677 100644 --- a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch +++ b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch @@ -1,4 +1,4 @@ -From 7eb42e3fbdb854b085eceaa500f1c18569bd044d Mon Sep 17 00:00:00 2001 +From 5215fad65699527aaea73add2cbbbb40de770fa6 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 16 Apr 2019 10:47:35 -0400 Subject: [PATCH] Fix config realm change logic in FILE remove_cred diff --git a/Fix-memory-leak-in-none-replay-cache-type.patch b/Fix-memory-leak-in-none-replay-cache-type.patch index c785882..00fc8ab 100644 --- a/Fix-memory-leak-in-none-replay-cache-type.patch +++ b/Fix-memory-leak-in-none-replay-cache-type.patch @@ -1,4 +1,4 @@ -From aeae5941ff8beea66516a31cd16fe4df6e8165f9 Mon Sep 17 00:00:00 2001 +From 7e3cb737332fad7803205035a90237a9b50e0a36 Mon Sep 17 00:00:00 2001 From: Corene Casper Date: Sat, 16 Feb 2019 00:49:26 -0500 Subject: [PATCH] Fix memory leak in 'none' replay cache type diff --git a/Fix-potential-close-1-in-cc_file.c.patch b/Fix-potential-close-1-in-cc_file.c.patch index b9457f5..3a7cd17 100644 --- a/Fix-potential-close-1-in-cc_file.c.patch +++ b/Fix-potential-close-1-in-cc_file.c.patch @@ -1,4 +1,4 @@ -From c1fe784e79b847a7e9ae9009193dee66bc1b6164 Mon Sep 17 00:00:00 2001 +From cfe28dcc4a478fa99639b48476316936db87d69e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 18 Apr 2019 13:39:37 -0400 Subject: [PATCH] Fix potential close(-1) in cc_file.c diff --git a/Fix-some-return-code-handling-bugs.patch b/Fix-some-return-code-handling-bugs.patch index 32ad2ed..610e009 100644 --- a/Fix-some-return-code-handling-bugs.patch +++ b/Fix-some-return-code-handling-bugs.patch @@ -1,4 +1,4 @@ -From 202a4ef4b2d1fa88d1a5c7f0b673bc4f563c57cd Mon Sep 17 00:00:00 2001 +From 0bbbeeacc3c8bf22064db4d049e2069a81ab4270 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 14:05:38 -0400 Subject: [PATCH] Fix some return code handling bugs diff --git a/Implement-krb5_cc_remove_cred-for-remaining-types.patch b/Implement-krb5_cc_remove_cred-for-remaining-types.patch index 7e9ea4c..9b70559 100644 --- a/Implement-krb5_cc_remove_cred-for-remaining-types.patch +++ b/Implement-krb5_cc_remove_cred-for-remaining-types.patch @@ -1,4 +1,4 @@ -From fd67573d4f0e2ac155752697ebf750c43fab3c59 Mon Sep 17 00:00:00 2001 +From 78bfdbba03bbeb3c86c41273a3c3157bfbab7878 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 1 Apr 2019 14:28:48 -0400 Subject: [PATCH] Implement krb5_cc_remove_cred for remaining types diff --git a/Improve-error-messages-from-kadmin-change_password.patch b/Improve-error-messages-from-kadmin-change_password.patch index d9d1116..d231acb 100644 --- a/Improve-error-messages-from-kadmin-change_password.patch +++ b/Improve-error-messages-from-kadmin-change_password.patch @@ -1,4 +1,4 @@ -From a479ad01696f97114cdc1734a7fe5f3d4bd80e80 Mon Sep 17 00:00:00 2001 +From 93717ffc7a5f213e3040e60431df199a5f6e9c76 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 13:13:16 -0400 Subject: [PATCH] Improve error messages from kadmin change_password diff --git a/In-kpropd-debug-log-proper-ticket-enctype-names.patch b/In-kpropd-debug-log-proper-ticket-enctype-names.patch index 93b4615..2bdcbdd 100644 --- a/In-kpropd-debug-log-proper-ticket-enctype-names.patch +++ b/In-kpropd-debug-log-proper-ticket-enctype-names.patch @@ -1,4 +1,4 @@ -From fe497f16d8da570dea363dacb18cfc2fcfa52f24 Mon Sep 17 00:00:00 2001 +From 7483ca4dbac8fedca5bd5ac1ea310e020df0d843 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 13:41:16 -0500 Subject: [PATCH] In kpropd, debug-log proper ticket enctype names diff --git a/In-rd_req_dec-always-log-non-permitted-enctypes.patch b/In-rd_req_dec-always-log-non-permitted-enctypes.patch index 702ab0b..b804639 100644 --- a/In-rd_req_dec-always-log-non-permitted-enctypes.patch +++ b/In-rd_req_dec-always-log-non-permitted-enctypes.patch @@ -1,4 +1,4 @@ -From d868f6753cd6e9de447f097626f5e5155c727414 Mon Sep 17 00:00:00 2001 +From 9503055f4caad2ab71db488ec434494cc23ce74e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Jan 2019 17:14:42 -0500 Subject: [PATCH] In rd_req_dec, always log non-permitted enctypes diff --git a/Initialize-some-data-structure-magic-fields.patch b/Initialize-some-data-structure-magic-fields.patch index 8bb00a5..f733dc0 100644 --- a/Initialize-some-data-structure-magic-fields.patch +++ b/Initialize-some-data-structure-magic-fields.patch @@ -1,4 +1,4 @@ -From a1327230380d0c73ebb9a22e4c6bbb1b6f3e0c64 Mon Sep 17 00:00:00 2001 +From 7973ef9891219a5179592db7081b7ffd6db95103 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 13:36:38 -0400 Subject: [PATCH] Initialize some data structure magic fields diff --git a/Make-etype-names-in-KDC-logs-human-readable.patch b/Make-etype-names-in-KDC-logs-human-readable.patch index 612181c..5065e9c 100644 --- a/Make-etype-names-in-KDC-logs-human-readable.patch +++ b/Make-etype-names-in-KDC-logs-human-readable.patch @@ -1,4 +1,4 @@ -From c14796879b9c4601a3333444c9aa6388031e6ab2 Mon Sep 17 00:00:00 2001 +From 64843356847cc944d246eedd45e34d65c3336e05 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 8 Jan 2019 17:42:35 -0500 Subject: [PATCH] Make etype names in KDC logs human-readable diff --git a/Mark-deprecated-enctypes-when-used.patch b/Mark-deprecated-enctypes-when-used.patch index a3fc96a..d84f0c4 100644 --- a/Mark-deprecated-enctypes-when-used.patch +++ b/Mark-deprecated-enctypes-when-used.patch @@ -1,4 +1,4 @@ -From 5b81e75e1c5ec39a070df7c87c64aa74b5b9c0ba Mon Sep 17 00:00:00 2001 +From a3df9ce1ebe05300aaf930d11d53bd354561f044 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 10 Jan 2019 16:34:54 -0500 Subject: [PATCH] Mark deprecated enctypes when used diff --git a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch index 54b7580..5e2eb29 100644 --- a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch +++ b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch @@ -1,4 +1,4 @@ -From ae9b51bc4f4ca5e88d7675d373e35fde8470e223 Mon Sep 17 00:00:00 2001 +From 50116db1dcf88ad7a5fbe03e5045c6d3059e2bb0 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 14:32:33 -0400 Subject: [PATCH] Modernize exit path in gss_krb5int_copy_ccache() diff --git a/Properly-size-ifdef-in-k5_cccol_lock.patch b/Properly-size-ifdef-in-k5_cccol_lock.patch index 74eef51..3af884c 100644 --- a/Properly-size-ifdef-in-k5_cccol_lock.patch +++ b/Properly-size-ifdef-in-k5_cccol_lock.patch @@ -1,4 +1,4 @@ -From 85577bdae928613c87828fff79d5d6c6b9b8b291 Mon Sep 17 00:00:00 2001 +From 3e750e184a870a7bc96dac75e2da61ca4414ddd1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Feb 2019 11:50:35 -0500 Subject: [PATCH] Properly size #ifdef in k5_cccol_lock() diff --git a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch index e09efcf..8485948 100644 --- a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch +++ b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch @@ -1,4 +1,4 @@ -From 6bd60d3985df4e327f86d2a19349f52058d09a17 Mon Sep 17 00:00:00 2001 +From 69c1393e9077ecedea84cffc4d2721981aa9205a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 14:37:38 -0400 Subject: [PATCH] Remove Kerberos v4 support vestiges from ccapi diff --git a/Remove-ccapi-related-comments-in-configure.ac.patch b/Remove-ccapi-related-comments-in-configure.ac.patch index a2563f8..520ef61 100644 --- a/Remove-ccapi-related-comments-in-configure.ac.patch +++ b/Remove-ccapi-related-comments-in-configure.ac.patch @@ -1,4 +1,4 @@ -From 74c45a65b34e49aecfedfb8451b857350fbbe616 Mon Sep 17 00:00:00 2001 +From fad2355105eaa8ec34cd4c4d3bed05f66d0157ce Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Apr 2019 16:01:22 -0400 Subject: [PATCH] Remove ccapi-related comments in configure.ac diff --git a/Remove-checksum-type-profile-variables.patch b/Remove-checksum-type-profile-variables.patch index 90596e5..88a5945 100644 --- a/Remove-checksum-type-profile-variables.patch +++ b/Remove-checksum-type-profile-variables.patch @@ -1,4 +1,4 @@ -From 443b8989c5d554f5347b72364d704d4626ca9a92 Mon Sep 17 00:00:00 2001 +From 9d0403155222b7815d5db6063cecd79d530f7e93 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 13 May 2019 14:19:57 -0400 Subject: [PATCH] Remove checksum type profile variables diff --git a/Remove-confvalidator-utility.patch b/Remove-confvalidator-utility.patch index 0dd66b7..40104fc 100644 --- a/Remove-confvalidator-utility.patch +++ b/Remove-confvalidator-utility.patch @@ -1,4 +1,4 @@ -From 841be050c7f02d09aade0ed2c708bff8787afcd2 Mon Sep 17 00:00:00 2001 +From 6d289b110c39c1d617c5e8252cc0bb1d25450b0e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Apr 2019 14:58:19 -0400 Subject: [PATCH] Remove confvalidator utility diff --git a/Remove-dead-variable-def_kslist-from-two-files.patch b/Remove-dead-variable-def_kslist-from-two-files.patch index 80b6a1f..76a248a 100644 --- a/Remove-dead-variable-def_kslist-from-two-files.patch +++ b/Remove-dead-variable-def_kslist-from-two-files.patch @@ -1,4 +1,4 @@ -From f18a482eec20369d7bcb4a7b2b6440c907215eff Mon Sep 17 00:00:00 2001 +From 29262595f5c603276dbeb016b122141839304755 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 16:57:51 -0400 Subject: [PATCH] Remove dead variable def_kslist from two files diff --git a/Remove-doxygen-generated-HTML-output-for-ccapi.patch b/Remove-doxygen-generated-HTML-output-for-ccapi.patch index 58b1177..5fd0aa4 100644 --- a/Remove-doxygen-generated-HTML-output-for-ccapi.patch +++ b/Remove-doxygen-generated-HTML-output-for-ccapi.patch @@ -1,4 +1,4 @@ -From 33acfff1a6ec51f2d60933c362ec8afb89d5d548 Mon Sep 17 00:00:00 2001 +From 7e85faa6d1df1af351c00a92219e789939d2924c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 14:15:58 -0400 Subject: [PATCH] Remove doxygen-generated HTML output for ccapi diff --git a/Remove-kadmin-RPC-support-for-setting-v4-key.patch b/Remove-kadmin-RPC-support-for-setting-v4-key.patch index b0e5830..b8966c1 100644 --- a/Remove-kadmin-RPC-support-for-setting-v4-key.patch +++ b/Remove-kadmin-RPC-support-for-setting-v4-key.patch @@ -1,4 +1,4 @@ -From 76b39ce5081eb3b288532d615c356ab508e93495 Mon Sep 17 00:00:00 2001 +From 93ee33d4b7ab08c041868a2e43111924c578b5b5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 16:14:46 -0400 Subject: [PATCH] Remove kadmin RPC support for setting v4 key diff --git a/Remove-more-dead-code.patch b/Remove-more-dead-code.patch index fc77326..708f08a 100644 --- a/Remove-more-dead-code.patch +++ b/Remove-more-dead-code.patch @@ -1,4 +1,4 @@ -From eb6d9cd533d087d38b7f3c1b7086a712cb0bfe46 Mon Sep 17 00:00:00 2001 +From dbc7e1a5ca3afad7ac6d057266358c6cbe517db5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 9 May 2019 14:07:24 -0400 Subject: [PATCH] Remove more dead code diff --git a/Remove-ovsec_adm_export-dump-format-support.patch b/Remove-ovsec_adm_export-dump-format-support.patch index ce890cf..edf73e6 100644 --- a/Remove-ovsec_adm_export-dump-format-support.patch +++ b/Remove-ovsec_adm_export-dump-format-support.patch @@ -1,4 +1,4 @@ -From e7766b4c1df19738a4cf34d498046cfa8dd91637 Mon Sep 17 00:00:00 2001 +From 17d6296546fc363731e10c986ba19e0d85bd9e0c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 22 Jan 2019 18:34:58 -0500 Subject: [PATCH] Remove ovsec_adm_export dump format support diff --git a/Remove-srvtab-support.patch b/Remove-srvtab-support.patch index 237cecb..a82e2be 100644 --- a/Remove-srvtab-support.patch +++ b/Remove-srvtab-support.patch @@ -1,4 +1,4 @@ -From e74dc82235b3948dee706310ebf5b1878d08d7df Mon Sep 17 00:00:00 2001 +From aec66c783ddba8b036ea1077bb852832cffcc432 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 9 Oct 2017 15:58:33 -0400 Subject: [PATCH] Remove srvtab support diff --git a/Simplify-SAM-2-as_key-handling.patch b/Simplify-SAM-2-as_key-handling.patch index c990067..407aa12 100644 --- a/Simplify-SAM-2-as_key-handling.patch +++ b/Simplify-SAM-2-as_key-handling.patch @@ -1,4 +1,4 @@ -From 4f9e21c9daf505f5147dcab2fb4d1b241e1b90f8 Mon Sep 17 00:00:00 2001 +From c63484d9ff8199261e778169474af50883ea11f5 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 5 May 2019 18:53:27 -0400 Subject: [PATCH] Simplify SAM-2 as_key handling diff --git a/Simply-OpenSSL-PKCS7-decryption-code.patch b/Simply-OpenSSL-PKCS7-decryption-code.patch index 0ab4f51..cdba8fa 100644 --- a/Simply-OpenSSL-PKCS7-decryption-code.patch +++ b/Simply-OpenSSL-PKCS7-decryption-code.patch @@ -1,4 +1,4 @@ -From 89470cb724edb9a3c9d31f6fb5c967fed73e38a1 Mon Sep 17 00:00:00 2001 +From bcc55c108502402d2d1f6e4a6ce9a348dd655609 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 13:13:06 -0400 Subject: [PATCH] Simply OpenSSL PKCS7 decryption code diff --git a/Use-secure_getenv-where-appropriate.patch b/Use-secure_getenv-where-appropriate.patch index 2ddb7f0..57c8ea3 100644 --- a/Use-secure_getenv-where-appropriate.patch +++ b/Use-secure_getenv-where-appropriate.patch @@ -1,4 +1,4 @@ -From ec428980300c85ba2c4b220174c2c05447cf4bd8 Mon Sep 17 00:00:00 2001 +From d7cb05ad91e778c1de0c977b053a22060e6ed579 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 24 Apr 2019 16:19:50 -0400 Subject: [PATCH] Use secure_getenv() where appropriate diff --git a/krb5-1.17post1-FIPS-with-PRNG-and-SPAKE.patch b/krb5-1.17post1-FIPS-with-PRNG-and-SPAKE.patch deleted file mode 100644 index 4ce69ab..0000000 --- a/krb5-1.17post1-FIPS-with-PRNG-and-SPAKE.patch +++ /dev/null @@ -1,250 +0,0 @@ -From dff44c20d9d9ed6a3e71888406b2913d9309e738 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 9 Nov 2018 15:12:21 -0500 -Subject: [PATCH] krb5-1.17post1 FIPS with PRNG and SPAKE - -NB: Use openssl's PRNG in FIPS mode, and be aware during SPAKE group -negotiation. - -A lot of the FIPS error conditions from OpenSSL are incredibly -mysterious (at best, things return NULL unexpectedly; at worst, -internal assertions are tripped; most of the time, you just get -ENOMEM). In order to cope with this, we need to have some level of -awareness of what we can and can't safely call. - -This will slow down some calls slightly (FIPS_mode() takes multiple -locks), but not for any ciphers we care about - which is to say that -AES is fine. Shame about the SPAKE groups though. ---- - src/lib/crypto/krb/prng.c | 11 ++++++++++- - src/lib/crypto/openssl/enc_provider/camellia.c | 6 ++++++ - src/lib/crypto/openssl/enc_provider/des.c | 9 +++++++++ - src/lib/crypto/openssl/enc_provider/des3.c | 6 ++++++ - src/lib/crypto/openssl/enc_provider/rc4.c | 13 ++++++++++++- - src/lib/crypto/openssl/hash_provider/hash_evp.c | 4 ++++ - src/lib/crypto/openssl/hmac.c | 6 +++++- - src/plugins/preauth/spake/groups.c | 8 ++++++++ - 8 files changed, 60 insertions(+), 3 deletions(-) - -diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c -index cb9ca9b98..f0e9984ca 100644 ---- a/src/lib/crypto/krb/prng.c -+++ b/src/lib/crypto/krb/prng.c -@@ -26,6 +26,8 @@ - - #include "crypto_int.h" - -+#include -+ - krb5_error_code KRB5_CALLCONV - krb5_c_random_seed(krb5_context context, krb5_data *data) - { -@@ -99,9 +101,16 @@ krb5_boolean - k5_get_os_entropy(unsigned char *buf, size_t len, int strong) - { - const char *device; --#if defined(__linux__) && defined(SYS_getrandom) - int r; - -+ /* A wild FIPS mode appeared! */ -+ if (FIPS_mode()) { -+ /* The return codes on this API are not good */ -+ r = RAND_bytes(buf, len); -+ return r == 1; -+ } -+ -+#if defined(__linux__) && defined(SYS_getrandom) - while (len > 0) { - /* - * Pull from the /dev/urandom pool, but require it to have been seeded. -diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c -index 2da691329..f79679a0b 100644 ---- a/src/lib/crypto/openssl/enc_provider/camellia.c -+++ b/src/lib/crypto/openssl/enc_provider/camellia.c -@@ -304,6 +304,9 @@ krb5int_camellia_cbc_mac(krb5_key key, const krb5_crypto_iov *data, - unsigned char blockY[CAMELLIA_BLOCK_SIZE], blockB[CAMELLIA_BLOCK_SIZE]; - struct iov_cursor cursor; - -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; -+ - if (output->length < CAMELLIA_BLOCK_SIZE) - return KRB5_BAD_MSIZE; - -@@ -331,6 +334,9 @@ static krb5_error_code - krb5int_camellia_init_state (const krb5_keyblock *key, krb5_keyusage usage, - krb5_data *state) - { -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; -+ - state->length = 16; - state->data = (void *) malloc(16); - if (state->data == NULL) -diff --git a/src/lib/crypto/openssl/enc_provider/des.c b/src/lib/crypto/openssl/enc_provider/des.c -index a662db512..7d17d287e 100644 ---- a/src/lib/crypto/openssl/enc_provider/des.c -+++ b/src/lib/crypto/openssl/enc_provider/des.c -@@ -85,6 +85,9 @@ k5_des_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx; - krb5_boolean empty; - -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; -+ - ret = validate(key, ivec, data, num_data, &empty); - if (ret != 0 || empty) - return ret; -@@ -133,6 +136,9 @@ k5_des_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx; - krb5_boolean empty; - -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; -+ - ret = validate(key, ivec, data, num_data, &empty); - if (ret != 0 || empty) - return ret; -@@ -182,6 +188,9 @@ k5_des_cbc_mac(krb5_key key, const krb5_crypto_iov *data, size_t num_data, - DES_key_schedule sched; - krb5_boolean empty; - -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; -+ - ret = validate(key, ivec, data, num_data, &empty); - if (ret != 0) - return ret; -diff --git a/src/lib/crypto/openssl/enc_provider/des3.c b/src/lib/crypto/openssl/enc_provider/des3.c -index 1c439c2cd..8be555a8d 100644 ---- a/src/lib/crypto/openssl/enc_provider/des3.c -+++ b/src/lib/crypto/openssl/enc_provider/des3.c -@@ -84,6 +84,9 @@ k5_des3_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx; - krb5_boolean empty; - -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; -+ - ret = validate(key, ivec, data, num_data, &empty); - if (ret != 0 || empty) - return ret; -@@ -133,6 +136,9 @@ k5_des3_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx; - krb5_boolean empty; - -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; -+ - ret = validate(key, ivec, data, num_data, &empty); - if (ret != 0 || empty) - return ret; -diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c -index a65d57b7a..6ccaca94a 100644 ---- a/src/lib/crypto/openssl/enc_provider/rc4.c -+++ b/src/lib/crypto/openssl/enc_provider/rc4.c -@@ -66,6 +66,9 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx = NULL; - struct arcfour_state *arcstate; - -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; -+ - arcstate = (state != NULL) ? (void *)state->data : NULL; - if (arcstate != NULL) { - ctx = arcstate->ctx; -@@ -113,7 +116,12 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, - static void - k5_arcfour_free_state(krb5_data *state) - { -- struct arcfour_state *arcstate = (void *)state->data; -+ struct arcfour_state *arcstate; -+ -+ if (FIPS_mode()) -+ return; -+ -+ arcstate = (void *) state->data; - - EVP_CIPHER_CTX_free(arcstate->ctx); - free(arcstate); -@@ -125,6 +133,9 @@ k5_arcfour_init_state(const krb5_keyblock *key, - { - struct arcfour_state *arcstate; - -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; -+ - /* - * The cipher state here is a saved pointer to a struct arcfour_state - * object, rather than a flat byte array as in most enc providers. The -diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c -index 957ed8d9c..8c1fd7f59 100644 ---- a/src/lib/crypto/openssl/hash_provider/hash_evp.c -+++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c -@@ -64,12 +64,16 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, - static krb5_error_code - hash_md4(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) - { -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; - return hash_evp(EVP_md4(), data, num_data, output); - } - - static krb5_error_code - hash_md5(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) - { -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; - return hash_evp(EVP_md5(), data, num_data, output); - } - -diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c -index 7dc59dcc0..769a50c00 100644 ---- a/src/lib/crypto/openssl/hmac.c -+++ b/src/lib/crypto/openssl/hmac.c -@@ -103,7 +103,11 @@ map_digest(const struct krb5_hash_provider *hash) - return EVP_sha256(); - else if (!strncmp(hash->hash_name, "SHA-384",7)) - return EVP_sha384(); -- else if (!strncmp(hash->hash_name, "MD5", 3)) -+ -+ if (FIPS_mode()) -+ return NULL; -+ -+ if (!strncmp(hash->hash_name, "MD5", 3)) - return EVP_md5(); - else if (!strncmp(hash->hash_name, "MD4", 3)) - return EVP_md4(); -diff --git a/src/plugins/preauth/spake/groups.c b/src/plugins/preauth/spake/groups.c -index a195cc195..8a913cb5a 100644 ---- a/src/plugins/preauth/spake/groups.c -+++ b/src/plugins/preauth/spake/groups.c -@@ -56,6 +56,8 @@ - #include "trace.h" - #include "groups.h" - -+#include -+ - #define DEFAULT_GROUPS_CLIENT "edwards25519" - #define DEFAULT_GROUPS_KDC "" - -@@ -102,6 +104,9 @@ find_gdef(int32_t group) - { - size_t i; - -+ if (group == builtin_edwards25519.reg->id && FIPS_mode()) -+ return NULL; -+ - for (i = 0; groupdefs[i] != NULL; i++) { - if (groupdefs[i]->reg->id == group) - return groupdefs[i]; -@@ -116,6 +121,9 @@ find_gnum(const char *name) - { - size_t i; - -+ if (strcasecmp(name, builtin_edwards25519.reg->name) == 0 && FIPS_mode()) -+ return 0; -+ - for (i = 0; groupdefs[i] != NULL; i++) { - if (strcasecmp(name, groupdefs[i]->reg->name) == 0) - return groupdefs[i]->reg->id; diff --git a/krb5-1.17-In-FIPS-mode-add-plaintext-fallback-for-RC.patch b/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch similarity index 58% rename from krb5-1.17-In-FIPS-mode-add-plaintext-fallback-for-RC.patch rename to krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch index f74faa0..03ab3fb 100644 --- a/krb5-1.17-In-FIPS-mode-add-plaintext-fallback-for-RC.patch +++ b/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch @@ -1,19 +1,227 @@ -From 105bd2c8be23ab94ba6e0601ee8e531f013389d6 Mon Sep 17 00:00:00 2001 +From 0c6860f5213e35226670772b53d70c858258a63e Mon Sep 17 00:00:00 2001 From: Robbie Harwood -Date: Tue, 31 Jul 2018 13:47:26 -0400 -Subject: [PATCH] krb5-1.17 In FIPS mode, add plaintext fallback for RC4 usages - and taint +Date: Fri, 9 Nov 2018 15:12:21 -0500 +Subject: [PATCH] krb5-1.17post2 FIPS with PRNG, SPAKE, and RADIUS +NB: Use openssl's PRNG in FIPS mode, be aware during SPAKE group +negotiation, and taint within krad. + +A lot of the FIPS error conditions from OpenSSL are incredibly +mysterious (at best, things return NULL unexpectedly; at worst, +internal assertions are tripped; most of the time, you just get +ENOMEM). In order to cope with this, we need to have some level of +awareness of what we can and can't safely call. + +This will slow down some calls slightly (FIPS_mode() takes multiple +locks), but not for any ciphers we care about - which is to say that +AES is fine. Shame about the SPAKE groups though. --- - src/lib/krad/attr.c | 45 +++++++++++++++++++++++++++++----------- - src/lib/krad/attrset.c | 5 +++-- - src/lib/krad/internal.h | 13 ++++++++++-- - src/lib/krad/packet.c | 22 +++++++++++--------- - src/lib/krad/remote.c | 10 +++++++-- - src/lib/krad/t_attr.c | 3 ++- - src/lib/krad/t_attrset.c | 4 +++- - 7 files changed, 72 insertions(+), 30 deletions(-) + src/lib/crypto/krb/prng.c | 11 ++++- + .../crypto/openssl/enc_provider/camellia.c | 6 +++ + src/lib/crypto/openssl/enc_provider/des.c | 9 ++++ + src/lib/crypto/openssl/enc_provider/des3.c | 6 +++ + src/lib/crypto/openssl/enc_provider/rc4.c | 13 +++++- + .../crypto/openssl/hash_provider/hash_evp.c | 4 ++ + src/lib/crypto/openssl/hmac.c | 6 ++- + src/lib/krad/attr.c | 45 ++++++++++++++----- + src/lib/krad/attrset.c | 5 ++- + src/lib/krad/internal.h | 13 +++++- + src/lib/krad/packet.c | 22 ++++----- + src/lib/krad/remote.c | 10 ++++- + src/lib/krad/t_attr.c | 3 +- + src/lib/krad/t_attrset.c | 4 +- + src/plugins/preauth/spake/groups.c | 8 ++++ + 15 files changed, 132 insertions(+), 33 deletions(-) +diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c +index cb9ca9b98..f0e9984ca 100644 +--- a/src/lib/crypto/krb/prng.c ++++ b/src/lib/crypto/krb/prng.c +@@ -26,6 +26,8 @@ + + #include "crypto_int.h" + ++#include ++ + krb5_error_code KRB5_CALLCONV + krb5_c_random_seed(krb5_context context, krb5_data *data) + { +@@ -99,9 +101,16 @@ krb5_boolean + k5_get_os_entropy(unsigned char *buf, size_t len, int strong) + { + const char *device; +-#if defined(__linux__) && defined(SYS_getrandom) + int r; + ++ /* A wild FIPS mode appeared! */ ++ if (FIPS_mode()) { ++ /* The return codes on this API are not good */ ++ r = RAND_bytes(buf, len); ++ return r == 1; ++ } ++ ++#if defined(__linux__) && defined(SYS_getrandom) + while (len > 0) { + /* + * Pull from the /dev/urandom pool, but require it to have been seeded. +diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c +index 2da691329..f79679a0b 100644 +--- a/src/lib/crypto/openssl/enc_provider/camellia.c ++++ b/src/lib/crypto/openssl/enc_provider/camellia.c +@@ -304,6 +304,9 @@ krb5int_camellia_cbc_mac(krb5_key key, const krb5_crypto_iov *data, + unsigned char blockY[CAMELLIA_BLOCK_SIZE], blockB[CAMELLIA_BLOCK_SIZE]; + struct iov_cursor cursor; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + if (output->length < CAMELLIA_BLOCK_SIZE) + return KRB5_BAD_MSIZE; + +@@ -331,6 +334,9 @@ static krb5_error_code + krb5int_camellia_init_state (const krb5_keyblock *key, krb5_keyusage usage, + krb5_data *state) + { ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + state->length = 16; + state->data = (void *) malloc(16); + if (state->data == NULL) +diff --git a/src/lib/crypto/openssl/enc_provider/des.c b/src/lib/crypto/openssl/enc_provider/des.c +index a662db512..7d17d287e 100644 +--- a/src/lib/crypto/openssl/enc_provider/des.c ++++ b/src/lib/crypto/openssl/enc_provider/des.c +@@ -85,6 +85,9 @@ k5_des_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx; + krb5_boolean empty; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + ret = validate(key, ivec, data, num_data, &empty); + if (ret != 0 || empty) + return ret; +@@ -133,6 +136,9 @@ k5_des_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx; + krb5_boolean empty; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + ret = validate(key, ivec, data, num_data, &empty); + if (ret != 0 || empty) + return ret; +@@ -182,6 +188,9 @@ k5_des_cbc_mac(krb5_key key, const krb5_crypto_iov *data, size_t num_data, + DES_key_schedule sched; + krb5_boolean empty; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + ret = validate(key, ivec, data, num_data, &empty); + if (ret != 0) + return ret; +diff --git a/src/lib/crypto/openssl/enc_provider/des3.c b/src/lib/crypto/openssl/enc_provider/des3.c +index 1c439c2cd..8be555a8d 100644 +--- a/src/lib/crypto/openssl/enc_provider/des3.c ++++ b/src/lib/crypto/openssl/enc_provider/des3.c +@@ -84,6 +84,9 @@ k5_des3_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx; + krb5_boolean empty; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + ret = validate(key, ivec, data, num_data, &empty); + if (ret != 0 || empty) + return ret; +@@ -133,6 +136,9 @@ k5_des3_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx; + krb5_boolean empty; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + ret = validate(key, ivec, data, num_data, &empty); + if (ret != 0 || empty) + return ret; +diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c +index a65d57b7a..6ccaca94a 100644 +--- a/src/lib/crypto/openssl/enc_provider/rc4.c ++++ b/src/lib/crypto/openssl/enc_provider/rc4.c +@@ -66,6 +66,9 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx = NULL; + struct arcfour_state *arcstate; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + arcstate = (state != NULL) ? (void *)state->data : NULL; + if (arcstate != NULL) { + ctx = arcstate->ctx; +@@ -113,7 +116,12 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, + static void + k5_arcfour_free_state(krb5_data *state) + { +- struct arcfour_state *arcstate = (void *)state->data; ++ struct arcfour_state *arcstate; ++ ++ if (FIPS_mode()) ++ return; ++ ++ arcstate = (void *) state->data; + + EVP_CIPHER_CTX_free(arcstate->ctx); + free(arcstate); +@@ -125,6 +133,9 @@ k5_arcfour_init_state(const krb5_keyblock *key, + { + struct arcfour_state *arcstate; + ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + /* + * The cipher state here is a saved pointer to a struct arcfour_state + * object, rather than a flat byte array as in most enc providers. The +diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c +index 957ed8d9c..8c1fd7f59 100644 +--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c ++++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c +@@ -64,12 +64,16 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, + static krb5_error_code + hash_md4(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) + { ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; + return hash_evp(EVP_md4(), data, num_data, output); + } + + static krb5_error_code + hash_md5(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) + { ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; + return hash_evp(EVP_md5(), data, num_data, output); + } + +diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c +index 7dc59dcc0..769a50c00 100644 +--- a/src/lib/crypto/openssl/hmac.c ++++ b/src/lib/crypto/openssl/hmac.c +@@ -103,7 +103,11 @@ map_digest(const struct krb5_hash_provider *hash) + return EVP_sha256(); + else if (!strncmp(hash->hash_name, "SHA-384",7)) + return EVP_sha384(); +- else if (!strncmp(hash->hash_name, "MD5", 3)) ++ ++ if (FIPS_mode()) ++ return NULL; ++ ++ if (!strncmp(hash->hash_name, "MD5", 3)) + return EVP_md5(); + else if (!strncmp(hash->hash_name, "MD4", 3)) + return EVP_md4(); diff --git a/src/lib/krad/attr.c b/src/lib/krad/attr.c index 9c13d9d75..275327e67 100644 --- a/src/lib/krad/attr.c @@ -351,3 +559,36 @@ index 7928335ca..0f9576253 100644 krad_attrset_free(set); /* Manually encode User-Name. */ +diff --git a/src/plugins/preauth/spake/groups.c b/src/plugins/preauth/spake/groups.c +index a195cc195..8a913cb5a 100644 +--- a/src/plugins/preauth/spake/groups.c ++++ b/src/plugins/preauth/spake/groups.c +@@ -56,6 +56,8 @@ + #include "trace.h" + #include "groups.h" + ++#include ++ + #define DEFAULT_GROUPS_CLIENT "edwards25519" + #define DEFAULT_GROUPS_KDC "" + +@@ -102,6 +104,9 @@ find_gdef(int32_t group) + { + size_t i; + ++ if (group == builtin_edwards25519.reg->id && FIPS_mode()) ++ return NULL; ++ + for (i = 0; groupdefs[i] != NULL; i++) { + if (groupdefs[i]->reg->id == group) + return groupdefs[i]; +@@ -116,6 +121,9 @@ find_gnum(const char *name) + { + size_t i; + ++ if (strcasecmp(name, builtin_edwards25519.reg->name) == 0 && FIPS_mode()) ++ return 0; ++ + for (i = 0; groupdefs[i] != NULL; i++) { + if (strcasecmp(name, groupdefs[i]->reg->name) == 0) + return groupdefs[i]->reg->id; diff --git a/krb5.spec b/krb5.spec index b3a6e0b..3c4ccc5 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 19%{?dist} +Release: 20%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -59,7 +59,6 @@ Patch33: krb5-1.13-dirsrv-accountlock.patch Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch -Patch37: krb5-1.17-In-FIPS-mode-add-plaintext-fallback-for-RC.patch Patch90: Add-tests-for-KCM-ccache-type.patch Patch92: Address-some-optimized-out-memset-calls.patch Patch94: Avoid-allocating-a-register-in-zap-assembly.patch @@ -93,12 +92,12 @@ Patch123: Avoid-alignment-warnings-in-openssl-rc4.c.patch Patch124: Simply-OpenSSL-PKCS7-decryption-code.patch Patch125: Improve-error-messages-from-kadmin-change_password.patch Patch126: Remove-more-dead-code.patch -Patch127: krb5-1.17post1-FIPS-with-PRNG-and-SPAKE.patch +Patch127: krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch Patch128: Remove-checksum-type-profile-variables.patch Patch129: Remove-dead-variable-def_kslist-from-two-files.patch License: MIT -URL: http://web.mit.edu/kerberos/www/ +URL: https://web.mit.edu/kerberos/www/ BuildRequires: autoconf, bison, cmake, flex, gawk, gettext, pkgconfig, sed BuildRequires: gcc BuildRequires: libcom_err-devel, libedit-devel, libss-devel @@ -702,6 +701,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue May 14 2019 Robbie Harwood - 1.17-20 +- (Patch consolidation; hopefully no changes) + * Tue May 14 2019 Robbie Harwood - 1.17-19 - Remove checksum type profile variables From bebe7bd29f9410b7a553698bf9801e4918469057 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 15 May 2019 15:16:18 +0000 Subject: [PATCH 106/304] Re-provide krb5-kdb-version in -devel as well (IPA wants it) --- krb5.spec | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 3c4ccc5..0f897a7 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 20%{?dist} +Release: 21%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -166,6 +166,9 @@ Requires: libkadm5%{?_isa} = %{version}-%{release} Requires: libcom_err-devel Requires: keyutils-libs-devel, libselinux-devel Requires: libverto-devel +Provides: krb5-kdb-devel-version = %{kdbversion} +# IPA wants ^ to be a separate symbol because they don't trust package +# managers to match -server and -devel in version. Just go with it. %description devel Kerberos is a network authentication system. The krb5-devel package @@ -701,6 +704,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed May 15 2019 Robbie Harwood - 1.17-21 +- Re-provide krb5-kdb-version in -devel as well (IPA wants it) + * Tue May 14 2019 Robbie Harwood - 1.17-20 - (Patch consolidation; hopefully no changes) From f91545040c64f8d6a41b9801744f8ca3c39048b3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 15 May 2019 17:01:26 -0400 Subject: [PATCH 107/304] Drop krb5_realm_compare() etc. NULL check patches --- ...nonicalize_hostname-fallback-support.patch | 2 +- ...on-and-enctype-flag-for-deprecations.patch | 2 +- Add-tests-for-KCM-ccache-type.patch | 2 +- Address-some-optimized-out-memset-calls.patch | 2 +- ...-alignment-warnings-in-openssl-rc4.c.patch | 2 +- ...llocating-a-register-in-zap-assembly.patch | 2 +- ...ore-errors-in-OpenSSL-crypto-backend.patch | 2 +- ...er-comment-for-krb5_cc_start_seq_get.patch | 2 +- ...able-flag-instead-of-denying-request.patch | 2 +- ...alm-change-logic-in-FILE-remove_cred.patch | 2 +- ...emory-leak-in-none-replay-cache-type.patch | 2 +- Fix-potential-close-1-in-cc_file.c.patch | 2 +- Fix-some-return-code-handling-bugs.patch | 2 +- ...5_cc_remove_cred-for-remaining-types.patch | 2 +- ...messages-from-kadmin-change_password.patch | 2 +- ...ebug-log-proper-ticket-enctype-names.patch | 2 +- ...ec-always-log-non-permitted-enctypes.patch | 2 +- ...ize-some-data-structure-magic-fields.patch | 2 +- ...ype-names-in-KDC-logs-human-readable.patch | 2 +- Mark-deprecated-enctypes-when-used.patch | 2 +- ...exit-path-in-gss_krb5int_copy_ccache.patch | 2 +- Properly-size-ifdef-in-k5_cccol_lock.patch | 2 +- ...beros-v4-support-vestiges-from-ccapi.patch | 2 +- ...api-related-comments-in-configure.ac.patch | 2 +- Remove-checksum-type-profile-variables.patch | 2 +- Remove-confvalidator-utility.patch | 2 +- ...d-variable-def_kslist-from-two-files.patch | 2 +- ...ygen-generated-HTML-output-for-ccapi.patch | 2 +- ...admin-RPC-support-for-setting-v4-key.patch | 2 +- Remove-more-dead-code.patch | 2 +- ...ovsec_adm_export-dump-format-support.patch | 2 +- Remove-srvtab-support.patch | 2 +- Simplify-SAM-2-as_key-handling.patch | 2 +- Simply-OpenSSL-PKCS7-decryption-code.patch | 2 +- Use-secure_getenv-where-appropriate.patch | 2 +- krb5-1.11-kpasswdtest.patch | 2 +- krb5-1.11-run_user_0.patch | 2 +- krb5-1.12-api.patch | 37 ------------------- krb5-1.13-dirsrv-accountlock.patch | 2 +- ...ost2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch | 2 +- krb5-1.9-debuginfo.patch | 2 +- krb5.spec | 7 +++- 42 files changed, 45 insertions(+), 79 deletions(-) delete mode 100644 krb5-1.12-api.patch diff --git a/Add-dns_canonicalize_hostname-fallback-support.patch b/Add-dns_canonicalize_hostname-fallback-support.patch index e5a7e09..7fb6a91 100644 --- a/Add-dns_canonicalize_hostname-fallback-support.patch +++ b/Add-dns_canonicalize_hostname-fallback-support.patch @@ -1,4 +1,4 @@ -From f256aeea76ad81305d005d3a052e7d2e0250dccc Mon Sep 17 00:00:00 2001 +From 770a525f940a319b4f9a91423a9f48bde28429b9 Mon Sep 17 00:00:00 2001 From: Simo Sorce Date: Tue, 4 Dec 2018 15:22:55 -0500 Subject: [PATCH] Add dns_canonicalize_hostname=fallback support diff --git a/Add-function-and-enctype-flag-for-deprecations.patch b/Add-function-and-enctype-flag-for-deprecations.patch index 26d876d..739371b 100644 --- a/Add-function-and-enctype-flag-for-deprecations.patch +++ b/Add-function-and-enctype-flag-for-deprecations.patch @@ -1,4 +1,4 @@ -From 81fe68ce11a676f93c101ddd7523e8de9b419deb Mon Sep 17 00:00:00 2001 +From 0713281743627e32f234e55bdaaeb58b37036675 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 16:16:57 -0500 Subject: [PATCH] Add function and enctype flag for deprecations diff --git a/Add-tests-for-KCM-ccache-type.patch b/Add-tests-for-KCM-ccache-type.patch index 3d34b3b..08b6b03 100644 --- a/Add-tests-for-KCM-ccache-type.patch +++ b/Add-tests-for-KCM-ccache-type.patch @@ -1,4 +1,4 @@ -From deedc59d6ab6dd4f988db931a3a0d43f977ca708 Mon Sep 17 00:00:00 2001 +From b8be4f3272dcca4b34f9d79b47b88e510e0d4926 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Nov 2018 00:27:35 -0500 Subject: [PATCH] Add tests for KCM ccache type diff --git a/Address-some-optimized-out-memset-calls.patch b/Address-some-optimized-out-memset-calls.patch index 805edb5..51318c7 100644 --- a/Address-some-optimized-out-memset-calls.patch +++ b/Address-some-optimized-out-memset-calls.patch @@ -1,4 +1,4 @@ -From 3909d11478c7bbfc988b5c09ed7b2d32a5959947 Mon Sep 17 00:00:00 2001 +From 31df8a3ef6b01b11a5956e16206069907a7acf17 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 30 Dec 2018 16:40:28 -0500 Subject: [PATCH] Address some optimized-out memset() calls diff --git a/Avoid-alignment-warnings-in-openssl-rc4.c.patch b/Avoid-alignment-warnings-in-openssl-rc4.c.patch index 60f603c..fdfe144 100644 --- a/Avoid-alignment-warnings-in-openssl-rc4.c.patch +++ b/Avoid-alignment-warnings-in-openssl-rc4.c.patch @@ -1,4 +1,4 @@ -From 041a4f3507ffe9f19bb69f8c1959230753b73f90 Mon Sep 17 00:00:00 2001 +From dac87fb5d866251731ba524053d55482bf5fad2a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 15:14:49 -0400 Subject: [PATCH] Avoid alignment warnings in openssl rc4.c diff --git a/Avoid-allocating-a-register-in-zap-assembly.patch b/Avoid-allocating-a-register-in-zap-assembly.patch index 518323d..4444b3a 100644 --- a/Avoid-allocating-a-register-in-zap-assembly.patch +++ b/Avoid-allocating-a-register-in-zap-assembly.patch @@ -1,4 +1,4 @@ -From e66fc8b903cded3aed007310815a8f1fac7e6c30 Mon Sep 17 00:00:00 2001 +From 087dd4f2cfde763b3b4ac1e34de87a3b9217037f Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Thu, 3 Jan 2019 17:19:32 +0100 Subject: [PATCH] Avoid allocating a register in zap() assembly diff --git a/Check-more-errors-in-OpenSSL-crypto-backend.patch b/Check-more-errors-in-OpenSSL-crypto-backend.patch index ead5ef5..64fbfa1 100644 --- a/Check-more-errors-in-OpenSSL-crypto-backend.patch +++ b/Check-more-errors-in-OpenSSL-crypto-backend.patch @@ -1,4 +1,4 @@ -From f48e578e443cf0217360dee6cef1fe2869059be4 Mon Sep 17 00:00:00 2001 +From 43fa850e47233f95c429c5b06fc74130a9c2b2b1 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 22 Apr 2019 14:26:42 -0400 Subject: [PATCH] Check more errors in OpenSSL crypto backend diff --git a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch index a3f5be5..56d3027 100644 --- a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch +++ b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch @@ -1,4 +1,4 @@ -From b804c5ec00580cf62fd3660939f0f3baf71822fe Mon Sep 17 00:00:00 2001 +From f6f799d2581251529c28bbb4644e42e19c6980ab Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Apr 2019 14:18:57 -0400 Subject: [PATCH] Clarify header comment for krb5_cc_start_seq_get() diff --git a/Clear-forwardable-flag-instead-of-denying-request.patch b/Clear-forwardable-flag-instead-of-denying-request.patch index cec478b..ea19b4b 100644 --- a/Clear-forwardable-flag-instead-of-denying-request.patch +++ b/Clear-forwardable-flag-instead-of-denying-request.patch @@ -1,4 +1,4 @@ -From 6a23d8a1cf2ff7e247dbd4a737b87c792f78e5ab Mon Sep 17 00:00:00 2001 +From 63e531d3545d74d734f56987bbc77256cbcd7763 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 15 Nov 2018 13:40:43 -0500 Subject: [PATCH] Clear forwardable flag instead of denying request diff --git a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch index b13d677..53c69e8 100644 --- a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch +++ b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch @@ -1,4 +1,4 @@ -From 5215fad65699527aaea73add2cbbbb40de770fa6 Mon Sep 17 00:00:00 2001 +From 4cacf2fa4a181b728742bce8c1ea11c07ba9a143 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 16 Apr 2019 10:47:35 -0400 Subject: [PATCH] Fix config realm change logic in FILE remove_cred diff --git a/Fix-memory-leak-in-none-replay-cache-type.patch b/Fix-memory-leak-in-none-replay-cache-type.patch index 00fc8ab..31753d3 100644 --- a/Fix-memory-leak-in-none-replay-cache-type.patch +++ b/Fix-memory-leak-in-none-replay-cache-type.patch @@ -1,4 +1,4 @@ -From 7e3cb737332fad7803205035a90237a9b50e0a36 Mon Sep 17 00:00:00 2001 +From 492872c4581f8b7f6d78cbc2e50e0b819c47a168 Mon Sep 17 00:00:00 2001 From: Corene Casper Date: Sat, 16 Feb 2019 00:49:26 -0500 Subject: [PATCH] Fix memory leak in 'none' replay cache type diff --git a/Fix-potential-close-1-in-cc_file.c.patch b/Fix-potential-close-1-in-cc_file.c.patch index 3a7cd17..94b96a8 100644 --- a/Fix-potential-close-1-in-cc_file.c.patch +++ b/Fix-potential-close-1-in-cc_file.c.patch @@ -1,4 +1,4 @@ -From cfe28dcc4a478fa99639b48476316936db87d69e Mon Sep 17 00:00:00 2001 +From 0201f95a60194c99bd3139235eb46e13e7f4484f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 18 Apr 2019 13:39:37 -0400 Subject: [PATCH] Fix potential close(-1) in cc_file.c diff --git a/Fix-some-return-code-handling-bugs.patch b/Fix-some-return-code-handling-bugs.patch index 610e009..436b65a 100644 --- a/Fix-some-return-code-handling-bugs.patch +++ b/Fix-some-return-code-handling-bugs.patch @@ -1,4 +1,4 @@ -From 0bbbeeacc3c8bf22064db4d049e2069a81ab4270 Mon Sep 17 00:00:00 2001 +From e196f175f5b551290efab029295dcf728feb4fac Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 14:05:38 -0400 Subject: [PATCH] Fix some return code handling bugs diff --git a/Implement-krb5_cc_remove_cred-for-remaining-types.patch b/Implement-krb5_cc_remove_cred-for-remaining-types.patch index 9b70559..4cf15a1 100644 --- a/Implement-krb5_cc_remove_cred-for-remaining-types.patch +++ b/Implement-krb5_cc_remove_cred-for-remaining-types.patch @@ -1,4 +1,4 @@ -From 78bfdbba03bbeb3c86c41273a3c3157bfbab7878 Mon Sep 17 00:00:00 2001 +From 6e199a7d007bbfd72ed76ff5534b9b3b88a82227 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 1 Apr 2019 14:28:48 -0400 Subject: [PATCH] Implement krb5_cc_remove_cred for remaining types diff --git a/Improve-error-messages-from-kadmin-change_password.patch b/Improve-error-messages-from-kadmin-change_password.patch index d231acb..afff2a1 100644 --- a/Improve-error-messages-from-kadmin-change_password.patch +++ b/Improve-error-messages-from-kadmin-change_password.patch @@ -1,4 +1,4 @@ -From 93717ffc7a5f213e3040e60431df199a5f6e9c76 Mon Sep 17 00:00:00 2001 +From 35681c176f3519df4700fd799ed66efd323f8c66 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 13:13:16 -0400 Subject: [PATCH] Improve error messages from kadmin change_password diff --git a/In-kpropd-debug-log-proper-ticket-enctype-names.patch b/In-kpropd-debug-log-proper-ticket-enctype-names.patch index 2bdcbdd..7972d01 100644 --- a/In-kpropd-debug-log-proper-ticket-enctype-names.patch +++ b/In-kpropd-debug-log-proper-ticket-enctype-names.patch @@ -1,4 +1,4 @@ -From 7483ca4dbac8fedca5bd5ac1ea310e020df0d843 Mon Sep 17 00:00:00 2001 +From 34883789b60e7961ac0c63062ffadbb2e628a76e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 13:41:16 -0500 Subject: [PATCH] In kpropd, debug-log proper ticket enctype names diff --git a/In-rd_req_dec-always-log-non-permitted-enctypes.patch b/In-rd_req_dec-always-log-non-permitted-enctypes.patch index b804639..9eb6a77 100644 --- a/In-rd_req_dec-always-log-non-permitted-enctypes.patch +++ b/In-rd_req_dec-always-log-non-permitted-enctypes.patch @@ -1,4 +1,4 @@ -From 9503055f4caad2ab71db488ec434494cc23ce74e Mon Sep 17 00:00:00 2001 +From 4d178af94f1a5f187b43de96ae16b2fb1cf4ba8a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Jan 2019 17:14:42 -0500 Subject: [PATCH] In rd_req_dec, always log non-permitted enctypes diff --git a/Initialize-some-data-structure-magic-fields.patch b/Initialize-some-data-structure-magic-fields.patch index f733dc0..d3ee55d 100644 --- a/Initialize-some-data-structure-magic-fields.patch +++ b/Initialize-some-data-structure-magic-fields.patch @@ -1,4 +1,4 @@ -From 7973ef9891219a5179592db7081b7ffd6db95103 Mon Sep 17 00:00:00 2001 +From da7349429a2985423ad006cc1f9d149e594118b7 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 13:36:38 -0400 Subject: [PATCH] Initialize some data structure magic fields diff --git a/Make-etype-names-in-KDC-logs-human-readable.patch b/Make-etype-names-in-KDC-logs-human-readable.patch index 5065e9c..a77c4bc 100644 --- a/Make-etype-names-in-KDC-logs-human-readable.patch +++ b/Make-etype-names-in-KDC-logs-human-readable.patch @@ -1,4 +1,4 @@ -From 64843356847cc944d246eedd45e34d65c3336e05 Mon Sep 17 00:00:00 2001 +From fddfa2abbc9e1ccd138d66a8c462a6a0eba1ecaa Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 8 Jan 2019 17:42:35 -0500 Subject: [PATCH] Make etype names in KDC logs human-readable diff --git a/Mark-deprecated-enctypes-when-used.patch b/Mark-deprecated-enctypes-when-used.patch index d84f0c4..b165d7f 100644 --- a/Mark-deprecated-enctypes-when-used.patch +++ b/Mark-deprecated-enctypes-when-used.patch @@ -1,4 +1,4 @@ -From a3df9ce1ebe05300aaf930d11d53bd354561f044 Mon Sep 17 00:00:00 2001 +From c40eb78a918138369f6d7142590732f563968909 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 10 Jan 2019 16:34:54 -0500 Subject: [PATCH] Mark deprecated enctypes when used diff --git a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch index 5e2eb29..489987d 100644 --- a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch +++ b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch @@ -1,4 +1,4 @@ -From 50116db1dcf88ad7a5fbe03e5045c6d3059e2bb0 Mon Sep 17 00:00:00 2001 +From bca13182a78bc3c62bd7e616c9b69ce96fe00b98 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 14:32:33 -0400 Subject: [PATCH] Modernize exit path in gss_krb5int_copy_ccache() diff --git a/Properly-size-ifdef-in-k5_cccol_lock.patch b/Properly-size-ifdef-in-k5_cccol_lock.patch index 3af884c..b38fc66 100644 --- a/Properly-size-ifdef-in-k5_cccol_lock.patch +++ b/Properly-size-ifdef-in-k5_cccol_lock.patch @@ -1,4 +1,4 @@ -From 3e750e184a870a7bc96dac75e2da61ca4414ddd1 Mon Sep 17 00:00:00 2001 +From 5601f9e0291feedeba7a420396d83b38c7332e86 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Feb 2019 11:50:35 -0500 Subject: [PATCH] Properly size #ifdef in k5_cccol_lock() diff --git a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch index 8485948..796ad66 100644 --- a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch +++ b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch @@ -1,4 +1,4 @@ -From 69c1393e9077ecedea84cffc4d2721981aa9205a Mon Sep 17 00:00:00 2001 +From ff88e21470d374f057107148de8b972a04f59641 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 14:37:38 -0400 Subject: [PATCH] Remove Kerberos v4 support vestiges from ccapi diff --git a/Remove-ccapi-related-comments-in-configure.ac.patch b/Remove-ccapi-related-comments-in-configure.ac.patch index 520ef61..7f3fa56 100644 --- a/Remove-ccapi-related-comments-in-configure.ac.patch +++ b/Remove-ccapi-related-comments-in-configure.ac.patch @@ -1,4 +1,4 @@ -From fad2355105eaa8ec34cd4c4d3bed05f66d0157ce Mon Sep 17 00:00:00 2001 +From 32b05ffd5f0d6eff5f989a8c30a030a3e1972e5d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Apr 2019 16:01:22 -0400 Subject: [PATCH] Remove ccapi-related comments in configure.ac diff --git a/Remove-checksum-type-profile-variables.patch b/Remove-checksum-type-profile-variables.patch index 88a5945..af1112e 100644 --- a/Remove-checksum-type-profile-variables.patch +++ b/Remove-checksum-type-profile-variables.patch @@ -1,4 +1,4 @@ -From 9d0403155222b7815d5db6063cecd79d530f7e93 Mon Sep 17 00:00:00 2001 +From e3de3f9916acc4ba0ac2e15c2d9a6826802170d2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 13 May 2019 14:19:57 -0400 Subject: [PATCH] Remove checksum type profile variables diff --git a/Remove-confvalidator-utility.patch b/Remove-confvalidator-utility.patch index 40104fc..134ba1e 100644 --- a/Remove-confvalidator-utility.patch +++ b/Remove-confvalidator-utility.patch @@ -1,4 +1,4 @@ -From 6d289b110c39c1d617c5e8252cc0bb1d25450b0e Mon Sep 17 00:00:00 2001 +From 2ea1badfb30f8549a5ec00dc8c5f5e58caea5a03 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Apr 2019 14:58:19 -0400 Subject: [PATCH] Remove confvalidator utility diff --git a/Remove-dead-variable-def_kslist-from-two-files.patch b/Remove-dead-variable-def_kslist-from-two-files.patch index 76a248a..ee60f78 100644 --- a/Remove-dead-variable-def_kslist-from-two-files.patch +++ b/Remove-dead-variable-def_kslist-from-two-files.patch @@ -1,4 +1,4 @@ -From 29262595f5c603276dbeb016b122141839304755 Mon Sep 17 00:00:00 2001 +From a37470b4f45cd40318c8ad84d92f56bdaac4993e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 16:57:51 -0400 Subject: [PATCH] Remove dead variable def_kslist from two files diff --git a/Remove-doxygen-generated-HTML-output-for-ccapi.patch b/Remove-doxygen-generated-HTML-output-for-ccapi.patch index 5fd0aa4..9825899 100644 --- a/Remove-doxygen-generated-HTML-output-for-ccapi.patch +++ b/Remove-doxygen-generated-HTML-output-for-ccapi.patch @@ -1,4 +1,4 @@ -From 7e85faa6d1df1af351c00a92219e789939d2924c Mon Sep 17 00:00:00 2001 +From 90324f46fe8aed4054ecad4f3a0357ffa3716852 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 14:15:58 -0400 Subject: [PATCH] Remove doxygen-generated HTML output for ccapi diff --git a/Remove-kadmin-RPC-support-for-setting-v4-key.patch b/Remove-kadmin-RPC-support-for-setting-v4-key.patch index b8966c1..66a08c2 100644 --- a/Remove-kadmin-RPC-support-for-setting-v4-key.patch +++ b/Remove-kadmin-RPC-support-for-setting-v4-key.patch @@ -1,4 +1,4 @@ -From 93ee33d4b7ab08c041868a2e43111924c578b5b5 Mon Sep 17 00:00:00 2001 +From 962e49c0ef0faf00210a1f88044782f6fa47a779 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 16:14:46 -0400 Subject: [PATCH] Remove kadmin RPC support for setting v4 key diff --git a/Remove-more-dead-code.patch b/Remove-more-dead-code.patch index 708f08a..ed67434 100644 --- a/Remove-more-dead-code.patch +++ b/Remove-more-dead-code.patch @@ -1,4 +1,4 @@ -From dbc7e1a5ca3afad7ac6d057266358c6cbe517db5 Mon Sep 17 00:00:00 2001 +From f708c93e82dc34c6ab2bd04be2149bd539faec4d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 9 May 2019 14:07:24 -0400 Subject: [PATCH] Remove more dead code diff --git a/Remove-ovsec_adm_export-dump-format-support.patch b/Remove-ovsec_adm_export-dump-format-support.patch index edf73e6..aad68b3 100644 --- a/Remove-ovsec_adm_export-dump-format-support.patch +++ b/Remove-ovsec_adm_export-dump-format-support.patch @@ -1,4 +1,4 @@ -From 17d6296546fc363731e10c986ba19e0d85bd9e0c Mon Sep 17 00:00:00 2001 +From 56be395114bed8e8dd41b91e41e233637488d3ab Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 22 Jan 2019 18:34:58 -0500 Subject: [PATCH] Remove ovsec_adm_export dump format support diff --git a/Remove-srvtab-support.patch b/Remove-srvtab-support.patch index a82e2be..0fa5c2a 100644 --- a/Remove-srvtab-support.patch +++ b/Remove-srvtab-support.patch @@ -1,4 +1,4 @@ -From aec66c783ddba8b036ea1077bb852832cffcc432 Mon Sep 17 00:00:00 2001 +From 42b1d879cf0705d3bc76c4b546275f1c608ebda9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 9 Oct 2017 15:58:33 -0400 Subject: [PATCH] Remove srvtab support diff --git a/Simplify-SAM-2-as_key-handling.patch b/Simplify-SAM-2-as_key-handling.patch index 407aa12..54123ec 100644 --- a/Simplify-SAM-2-as_key-handling.patch +++ b/Simplify-SAM-2-as_key-handling.patch @@ -1,4 +1,4 @@ -From c63484d9ff8199261e778169474af50883ea11f5 Mon Sep 17 00:00:00 2001 +From 251694f155bd132a162f876e59abf5caf7140c70 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 5 May 2019 18:53:27 -0400 Subject: [PATCH] Simplify SAM-2 as_key handling diff --git a/Simply-OpenSSL-PKCS7-decryption-code.patch b/Simply-OpenSSL-PKCS7-decryption-code.patch index cdba8fa..16436e0 100644 --- a/Simply-OpenSSL-PKCS7-decryption-code.patch +++ b/Simply-OpenSSL-PKCS7-decryption-code.patch @@ -1,4 +1,4 @@ -From bcc55c108502402d2d1f6e4a6ce9a348dd655609 Mon Sep 17 00:00:00 2001 +From 02c3a9756cba8676a3074ae8c1c96b26e1b47c98 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 13:13:06 -0400 Subject: [PATCH] Simply OpenSSL PKCS7 decryption code diff --git a/Use-secure_getenv-where-appropriate.patch b/Use-secure_getenv-where-appropriate.patch index 57c8ea3..6338aee 100644 --- a/Use-secure_getenv-where-appropriate.patch +++ b/Use-secure_getenv-where-appropriate.patch @@ -1,4 +1,4 @@ -From d7cb05ad91e778c1de0c977b053a22060e6ed579 Mon Sep 17 00:00:00 2001 +From a46c1dd1be09217f9f19e9c70381893dc3995c45 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 24 Apr 2019 16:19:50 -0400 Subject: [PATCH] Use secure_getenv() where appropriate diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch index ccb92aa..7c763ce 100644 --- a/krb5-1.11-kpasswdtest.patch +++ b/krb5-1.11-kpasswdtest.patch @@ -1,4 +1,4 @@ -From 1da0d2fdbd9cb2ded1913e05664986dce1e1a916 Mon Sep 17 00:00:00 2001 +From d3e720a17e4284c791541840dcbc8652d33a75c4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:52:01 -0400 Subject: [PATCH] krb5-1.11-kpasswdtest.patch diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch index 196944e..673d127 100644 --- a/krb5-1.11-run_user_0.patch +++ b/krb5-1.11-run_user_0.patch @@ -1,4 +1,4 @@ -From c95d33cc1c66122bc229beb65d36f988fbd05e59 Mon Sep 17 00:00:00 2001 +From 75ba8f42c0e9426af80c71aaaa490cc6262e259c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:57 -0400 Subject: [PATCH] krb5-1.11-run_user_0.patch diff --git a/krb5-1.12-api.patch b/krb5-1.12-api.patch deleted file mode 100644 index b49cea6..0000000 --- a/krb5-1.12-api.patch +++ /dev/null @@ -1,37 +0,0 @@ -From 4ddac573dfc8fea30b5f8750c8c0733c553afcfa Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:47:00 -0400 -Subject: [PATCH] krb5-1.12-api.patch - -Reference docs don't define what happens if you call krb5_realm_compare() with -malformed krb5_principal structures. Define a behavior which keeps it from -crashing if applications don't check ahead of time. ---- - src/lib/krb5/krb/princ_comp.c | 7 +++++++ - 1 file changed, 7 insertions(+) - -diff --git a/src/lib/krb5/krb/princ_comp.c b/src/lib/krb5/krb/princ_comp.c -index a6936107d..0ed78833b 100644 ---- a/src/lib/krb5/krb/princ_comp.c -+++ b/src/lib/krb5/krb/princ_comp.c -@@ -36,6 +36,10 @@ realm_compare_flags(krb5_context context, - const krb5_data *realm1 = &princ1->realm; - const krb5_data *realm2 = &princ2->realm; - -+ if (princ1 == NULL || princ2 == NULL) -+ return FALSE; -+ if (realm1 == NULL || realm2 == NULL) -+ return FALSE; - if (realm1->length != realm2->length) - return FALSE; - if (realm1->length == 0) -@@ -88,6 +92,9 @@ krb5_principal_compare_flags(krb5_context context, - krb5_principal upn2 = NULL; - krb5_boolean ret = FALSE; - -+ if (princ1 == NULL || princ2 == NULL) -+ return FALSE; -+ - if (flags & KRB5_PRINCIPAL_COMPARE_ENTERPRISE) { - /* Treat UPNs as if they were real principals */ - if (princ1->type == KRB5_NT_ENTERPRISE_PRINCIPAL) { diff --git a/krb5-1.13-dirsrv-accountlock.patch b/krb5-1.13-dirsrv-accountlock.patch index 56500af..e5fbd7f 100644 --- a/krb5-1.13-dirsrv-accountlock.patch +++ b/krb5-1.13-dirsrv-accountlock.patch @@ -1,4 +1,4 @@ -From 10f64f13ee3d44a31bcdc124e9ce721bc17b3e00 Mon Sep 17 00:00:00 2001 +From eb26e32b7cce535a7a70168b7f44aa07eb989264 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:44 -0400 Subject: [PATCH] krb5-1.13-dirsrv-accountlock.patch diff --git a/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch b/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch index 03ab3fb..8acdf1b 100644 --- a/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch +++ b/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch @@ -1,4 +1,4 @@ -From 0c6860f5213e35226670772b53d70c858258a63e Mon Sep 17 00:00:00 2001 +From 853a9aacfbc842037b30607bacb5c60f5918cccb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] krb5-1.17post2 FIPS with PRNG, SPAKE, and RADIUS diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index 6cf5368..6723eb4 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -1,4 +1,4 @@ -From 8ee5efa6aec5d02e25081b6dc809cef668ce45ea Mon Sep 17 00:00:00 2001 +From 454b35ce48bb8de491cad93c8944c783d1c47fd1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] krb5-1.9-debuginfo.patch diff --git a/krb5.spec b/krb5.spec index 0f897a7..3774e73 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 21%{?dist} +Release: 22%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -54,7 +54,6 @@ Patch27: krb5-1.17-beta1-selinux-label.patch Patch28: krb5-1.12-ksu-path.patch Patch30: krb5-1.15-beta1-buildconf.patch Patch31: krb5-1.3.1-dns.patch -Patch32: krb5-1.12-api.patch Patch33: krb5-1.13-dirsrv-accountlock.patch Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch @@ -704,6 +703,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed May 15 2019 Robbie Harwood - 1.17-22 +- Drop krb5_realm_compare() etc. NULL check patches + + * Wed May 15 2019 Robbie Harwood - 1.17-21 - Re-provide krb5-kdb-version in -devel as well (IPA wants it) From 39ba823db63ab6db1be81fb776a96700f0c61c91 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 20 May 2019 16:49:04 -0400 Subject: [PATCH 108/304] Test & docs fixes in preparation for DES removal --- ...-the-doc-kadm5-tex-files-as-historic.patch | 139 +++++++++++ ...ze-example-enctypes-in-documentation.patch | 231 ++++++++++++++++++ ....1-SAM-tests-to-use-a-modern-enctype.patch | 85 +++++++ krb5.spec | 8 +- 4 files changed, 462 insertions(+), 1 deletion(-) create mode 100644 Mark-the-doc-kadm5-tex-files-as-historic.patch create mode 100644 Modernize-example-enctypes-in-documentation.patch create mode 100644 Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch diff --git a/Mark-the-doc-kadm5-tex-files-as-historic.patch b/Mark-the-doc-kadm5-tex-files-as-historic.patch new file mode 100644 index 0000000..bacbb1b --- /dev/null +++ b/Mark-the-doc-kadm5-tex-files-as-historic.patch @@ -0,0 +1,139 @@ +From 7385ae430280e839a2a0b5a7c5a6be1b2b24aef4 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 11 Apr 2019 18:33:04 -0400 +Subject: [PATCH] Mark the doc/kadm5 tex files as historic + +Remove rcsid.sty and the uses of the \rcsId macro as git does not +perform the keyword expansion necessary to make it work. Add comments +indicating the historic status of the kadm5 documentation. + +[ghudson@mit.edu: fix the tex files instead of marking them as +non-building] + +(cherry picked from commit e6047bdd6dec0d104417f9a1318bbafe022b81c1) +--- + doc/kadm5/adb-unit-test.tex | 7 ++++--- + doc/kadm5/api-funcspec.tex | 9 +++++---- + doc/kadm5/api-server-design.tex | 9 +++++---- + doc/kadm5/api-unit-test.tex | 7 ++++--- + doc/kadm5/rcsid.sty | 5 ----- + 5 files changed, 18 insertions(+), 19 deletions(-) + delete mode 100644 doc/kadm5/rcsid.sty + +diff --git a/doc/kadm5/adb-unit-test.tex b/doc/kadm5/adb-unit-test.tex +index d401342df..987af1a5e 100644 +--- a/doc/kadm5/adb-unit-test.tex ++++ b/doc/kadm5/adb-unit-test.tex +@@ -1,6 +1,7 @@ +-\documentstyle[times,fullpage,rcsid]{article} ++% This document is included for historical purposes only, and does not ++% apply to krb5 today. + +-\rcs$Id$ ++\documentstyle[times,fullpage]{article} + + %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% + %% Make _ actually generate an _, and allow line-breaking after it. +@@ -39,7 +40,7 @@ + %\newcommand{\Priority}[1]{} + + \title{OpenV*Secure Admin Database API\\ +-Unit Test Description\footnote{\rcsId}} ++Unit Test Description} + \author{Jonathan I. Kamens} + + \begin{document} +diff --git a/doc/kadm5/api-funcspec.tex b/doc/kadm5/api-funcspec.tex +index c13090a51..76d2bb5d0 100644 +--- a/doc/kadm5/api-funcspec.tex ++++ b/doc/kadm5/api-funcspec.tex +@@ -1,4 +1,7 @@ +-\documentstyle[12pt,fullpage,rcsid]{article} ++% This document is included for historical purposes only, and does not ++% apply to krb5 today. ++ ++\documentstyle[12pt,fullpage]{article} + + %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% + %% Make _ actually generate an _, and allow line-breaking after it. +@@ -7,15 +10,13 @@ + \def_{\underscore\penalty75\relax} + %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% + +-\rcs$Id$ +- + \setlength{\parskip}{.7\baselineskip} + \setlength{\parindent}{0pt} + + \def\v#1{\verb+#1+} + + \title{Kerberos Administration System \\ +- KADM5 API Functional Specifications\thanks{\rcsId}} ++ KADM5 API Functional Specifications} + \author{Barry Jaspan} + + \begin{document} +diff --git a/doc/kadm5/api-server-design.tex b/doc/kadm5/api-server-design.tex +index 228e83113..94e05b877 100644 +--- a/doc/kadm5/api-server-design.tex ++++ b/doc/kadm5/api-server-design.tex +@@ -1,4 +1,7 @@ +-\documentstyle[12pt,fullpage,rcsid]{article} ++% This document is included for historical purposes only, and does not ++% apply to krb5 today. ++ ++\documentstyle[12pt,fullpage]{article} + + %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% + %% Make _ actually generate an _, and allow line-breaking after it. +@@ -7,15 +10,13 @@ + \def_{\underscore\penalty75\relax} + %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% + +-\rcs$Id$ +- + \setlength{\parskip}{.7\baselineskip} + \setlength{\parindent}{0pt} + + \def\v#1{\verb+#1+} + \def\k#1{K$_#1$} + +-\title{KADM5 Library and Server \\ Implementation Design\thanks{\rcsId}} ++\title{KADM5 Library and Server \\ Implementation Design} + \author{Barry Jaspan} + + \begin{document} +diff --git a/doc/kadm5/api-unit-test.tex b/doc/kadm5/api-unit-test.tex +index 3e0eb503e..bfd6280bb 100644 +--- a/doc/kadm5/api-unit-test.tex ++++ b/doc/kadm5/api-unit-test.tex +@@ -1,6 +1,7 @@ +-\documentstyle[times,fullpage,rcsid]{article} ++% This document is included for historical purposes only, and does not ++% apply to krb5 today. + +-\rcs$Id$ ++\documentstyle[times,fullpage]{article} + + %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% + %% Make _ actually generate an _, and allow line-breaking after it. +@@ -41,7 +42,7 @@ + %\newcommand{\Priority}[1]{} + + \title{KADM5 Admin API\\ +-Unit Test Description\footnote{\rcsId}} ++Unit Test Description} + \author{Jonathan I. Kamens} + + \begin{document} +diff --git a/doc/kadm5/rcsid.sty b/doc/kadm5/rcsid.sty +deleted file mode 100644 +index 3ad7826ff..000000000 +--- a/doc/kadm5/rcsid.sty ++++ /dev/null +@@ -1,5 +0,0 @@ +-\def\rcs$#1: #2${\expandafter\def\csname rcs#1\endcsname{#2}} +- +-% example usage: +-% \rcs$Version$ +-% Version \rcsVersion diff --git a/Modernize-example-enctypes-in-documentation.patch b/Modernize-example-enctypes-in-documentation.patch new file mode 100644 index 0000000..7c3d87c --- /dev/null +++ b/Modernize-example-enctypes-in-documentation.patch @@ -0,0 +1,231 @@ +From 6eb0931738f26890952de08d4ea9de24b0f684f5 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 11 Apr 2019 18:25:41 -0400 +Subject: [PATCH] Modernize example enctypes in documentation + +ticket: 8805 (new) +(cherry picked from commit ccb4a3e4b35fa9ea63af0e98a42eba4aadb099e2) +--- + doc/admin/admin_commands/kadmin_local.rst | 8 ++++---- + doc/admin/admin_commands/kdb5_util.rst | 10 +++++----- + doc/admin/database.rst | 2 +- + doc/admin/install_appl_srv.rst | 19 +++++++------------ + doc/admin/install_kdc.rst | 2 +- + src/man/kadmin.man | 10 +++++----- + src/man/kdb5_util.man | 10 +++++----- + .../kdb/ldap/libkdb_ldap/kerberos.ldif | 4 ++-- + .../kdb/ldap/libkdb_ldap/kerberos.schema | 4 ++-- + 9 files changed, 32 insertions(+), 37 deletions(-) + +diff --git a/doc/admin/admin_commands/kadmin_local.rst b/doc/admin/admin_commands/kadmin_local.rst +index 150da1fad..71aa894f6 100644 +--- a/doc/admin/admin_commands/kadmin_local.rst ++++ b/doc/admin/admin_commands/kadmin_local.rst +@@ -569,16 +569,16 @@ Examples:: + Principal: tlyu/admin@BLEEP.COM + Expiration date: [never] + Last password change: Mon Aug 12 14:16:47 EDT 1996 +- Password expiration date: [none] ++ Password expiration date: [never] + Maximum ticket life: 0 days 10:00:00 + Maximum renewable life: 7 days 00:00:00 + Last modified: Mon Aug 12 14:16:47 EDT 1996 (bjaspan/admin@BLEEP.COM) + Last successful authentication: [never] + Last failed authentication: [never] + Failed password attempts: 0 +- Number of keys: 2 +- Key: vno 1, des-cbc-crc +- Key: vno 1, des-cbc-crc:v4 ++ Number of keys: 1 ++ Key: vno 1, aes256-cts-hmac-sha384-192 ++ MKey: vno 1 + Attributes: + Policy: [none] + +diff --git a/doc/admin/admin_commands/kdb5_util.rst b/doc/admin/admin_commands/kdb5_util.rst +index 7dd54f797..444c58bcd 100644 +--- a/doc/admin/admin_commands/kdb5_util.rst ++++ b/doc/admin/admin_commands/kdb5_util.rst +@@ -476,17 +476,17 @@ Examples:: + $ kdb5_util tabdump -o keyinfo.txt keyinfo + $ cat keyinfo.txt + name keyindex kvno enctype salttype salt ++ K/M@EXAMPLE.COM 0 1 aes256-cts-hmac-sha384-192 normal -1 + foo@EXAMPLE.COM 0 1 aes128-cts-hmac-sha1-96 normal -1 + bar@EXAMPLE.COM 0 1 aes128-cts-hmac-sha1-96 normal -1 +- bar@EXAMPLE.COM 1 1 des-cbc-crc normal -1 + $ sqlite3 + sqlite> .mode tabs + sqlite> .import keyinfo.txt keyinfo +- sqlite> select * from keyinfo where enctype like 'des-cbc-%'; +- bar@EXAMPLE.COM 1 1 des-cbc-crc normal -1 ++ sqlite> select * from keyinfo where enctype like 'aes256-%'; ++ K/M@EXAMPLE.COM 1 1 aes256-cts-hmac-sha384-192 normal -1 + sqlite> .quit +- $ awk -F'\t' '$4 ~ /des-cbc-/ { print }' keyinfo.txt +- bar@EXAMPLE.COM 1 1 des-cbc-crc normal -1 ++ $ awk -F'\t' '$4 ~ /aes256-/ { print }' keyinfo.txt ++ K/M@EXAMPLE.COM 1 1 aes256-cts-hmac-sha384-192 normal -1 + + + ENVIRONMENT +diff --git a/doc/admin/database.rst b/doc/admin/database.rst +index 113a680a6..0eb5ccde7 100644 +--- a/doc/admin/database.rst ++++ b/doc/admin/database.rst +@@ -483,7 +483,7 @@ availability. To roll over the master key, follow these steps: + + $ kdb5_util list_mkeys + Master keys for Principal: K/M@KRBTEST.COM +- KVNO: 1, Enctype: des-cbc-crc, Active on: Wed Dec 31 19:00:00 EST 1969 * ++ KVNO: 1, Enctype: aes256-cts-hmac-sha384-192, Active on: Thu Jan 01 00:00:00 UTC 1970 * + + #. On the master KDC, run ``kdb5_util use_mkey 1`` to ensure that a + master key activation list is present in the database. This step +diff --git a/doc/admin/install_appl_srv.rst b/doc/admin/install_appl_srv.rst +index 6bae7248f..6b2d8e471 100644 +--- a/doc/admin/install_appl_srv.rst ++++ b/doc/admin/install_appl_srv.rst +@@ -44,18 +44,13 @@ pop, the administrator ``joeadmin`` would issue the command (on + ``trillium.mit.edu``):: + + trillium% kadmin +- kadmin5: ktadd host/trillium.mit.edu ftp/trillium.mit.edu +- pop/trillium.mit.edu +- kadmin: Entry for principal host/trillium.mit.edu@ATHENA.MIT.EDU with +- kvno 3, encryption type DES-CBC-CRC added to keytab +- FILE:/etc/krb5.keytab. +- kadmin: Entry for principal ftp/trillium.mit.edu@ATHENA.MIT.EDU with +- kvno 3, encryption type DES-CBC-CRC added to keytab +- FILE:/etc/krb5.keytab. +- kadmin: Entry for principal pop/trillium.mit.edu@ATHENA.MIT.EDU with +- kvno 3, encryption type DES-CBC-CRC added to keytab +- FILE:/etc/krb5.keytab. +- kadmin5: quit ++ Authenticating as principal root/admin@ATHENA.MIT.EDU with password. ++ Password for root/admin@ATHENA.MIT.EDU: ++ kadmin: ktadd host/trillium.mit.edu ftp/trillium.mit.edu pop/trillium.mit.edu ++ Entry for principal host/trillium.mit.edu@ATHENA.MIT.EDU with kvno 3, encryption type aes256-cts-hmac-sha384-192 added to keytab FILE:/etc/krb5.keytab. ++ kadmin: Entry for principal ftp/trillium.mit.edu@ATHENA.MIT.EDU with kvno 3, encryption type aes256-cts-hmac-sha384-192 added to keytab FILE:/etc/krb5.keytab. ++ kadmin: Entry for principal pop/trillium.mit.edu@ATHENA.MIT.EDU with kvno 3, encryption type aes256-cts-hmac-sha384-192 added to keytab FILE:/etc/krb5.keytab. ++ kadmin: quit + trillium% + + If you generate the keytab file on another host, you need to get a +diff --git a/doc/admin/install_kdc.rst b/doc/admin/install_kdc.rst +index 5d1e70ede..3bec59f96 100644 +--- a/doc/admin/install_kdc.rst ++++ b/doc/admin/install_kdc.rst +@@ -340,7 +340,7 @@ To extract a keytab directly on a replica KDC called + Entry for principal host/kerberos-1.mit.edu with kvno 2, encryption + type aes128-cts-hmac-sha1-96 added to keytab FILE:/etc/krb5.keytab. + Entry for principal host/kerberos-1.mit.edu with kvno 2, encryption +- type des3-cbc-sha1 added to keytab FILE:/etc/krb5.keytab. ++ type aes256-cts-hmac-sha384-192 added to keytab FILE:/etc/krb5.keytab. + Entry for principal host/kerberos-1.mit.edu with kvno 2, encryption + type arcfour-hmac added to keytab FILE:/etc/krb5.keytab. + +diff --git a/src/man/kadmin.man b/src/man/kadmin.man +index 849677258..44859a378 100644 +--- a/src/man/kadmin.man ++++ b/src/man/kadmin.man +@@ -1,6 +1,6 @@ + .\" Man page generated from reStructuredText. + . +-.TH "KADMIN" "1" " " "1.17" "MIT Kerberos" ++.TH "KADMIN" "1" " " "1.18" "MIT Kerberos" + .SH NAME + kadmin \- Kerberos V5 database administration program + . +@@ -610,16 +610,16 @@ kadmin: getprinc tlyu/admin + Principal: tlyu/admin@BLEEP.COM + Expiration date: [never] + Last password change: Mon Aug 12 14:16:47 EDT 1996 +-Password expiration date: [none] ++Password expiration date: [never] + Maximum ticket life: 0 days 10:00:00 + Maximum renewable life: 7 days 00:00:00 + Last modified: Mon Aug 12 14:16:47 EDT 1996 (bjaspan/admin@BLEEP.COM) + Last successful authentication: [never] + Last failed authentication: [never] + Failed password attempts: 0 +-Number of keys: 2 +-Key: vno 1, des\-cbc\-crc +-Key: vno 1, des\-cbc\-crc:v4 ++Number of keys: 1 ++Key: vno 1, aes256\-cts\-hmac\-sha384\-192 ++MKey: vno 1 + Attributes: + Policy: [none] + +diff --git a/src/man/kdb5_util.man b/src/man/kdb5_util.man +index 9a36ef0df..46772a236 100644 +--- a/src/man/kdb5_util.man ++++ b/src/man/kdb5_util.man +@@ -529,17 +529,17 @@ Examples: + $ kdb5_util tabdump \-o keyinfo.txt keyinfo + $ cat keyinfo.txt + name keyindex kvno enctype salttype salt ++K/M@EXAMPLE.COM 0 1 aes256\-cts\-hmac\-sha384\-192 normal \-1 + foo@EXAMPLE.COM 0 1 aes128\-cts\-hmac\-sha1\-96 normal \-1 + bar@EXAMPLE.COM 0 1 aes128\-cts\-hmac\-sha1\-96 normal \-1 +-bar@EXAMPLE.COM 1 1 des\-cbc\-crc normal \-1 + $ sqlite3 + sqlite> .mode tabs + sqlite> .import keyinfo.txt keyinfo +-sqlite> select * from keyinfo where enctype like \(aqdes\-cbc\-%\(aq; +-bar@EXAMPLE.COM 1 1 des\-cbc\-crc normal \-1 ++sqlite> select * from keyinfo where enctype like \(aqaes256\-%\(aq; ++K/M@EXAMPLE.COM 1 1 aes256\-cts\-hmac\-sha384\-192 normal \-1 + sqlite> .quit +-$ awk \-F\(aq\et\(aq \(aq$4 ~ /des\-cbc\-/ { print }\(aq keyinfo.txt +-bar@EXAMPLE.COM 1 1 des\-cbc\-crc normal \-1 ++$ awk \-F\(aq\et\(aq \(aq$4 ~ /aes256\-/ { print }\(aq keyinfo.txt ++K/M@EXAMPLE.COM 1 1 aes256\-cts\-hmac\-sha384\-192 normal \-1 + .ft P + .fi + .UNINDENT +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif b/src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif +index 13db48609..4224f0850 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif ++++ b/src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif +@@ -512,7 +512,7 @@ attributetypes: ( 2.16.840.1.113719.1.301.4.41.1 + + ##### Holds the default encryption/salt type combinations of principals for + ##### the Realm. Stores in the form of key:salt strings. +-##### Example: des-cbc-crc:normal ++##### Example: aes256-cts-hmac-sha384-192:normal + + dn: cn=schema + changetype: modify +@@ -533,7 +533,7 @@ attributetypes: ( 2.16.840.1.113719.1.301.4.42.1 + ##### ONLYREALM + ##### SPECIAL + ##### AFS3 +-##### Example: des-cbc-crc:normal ++##### Example: aes256-cts-hmac-sha384-192:normal + ##### + ##### This attribute obsoletes the krbSupportedEncTypes and krbSupportedSaltTypes + ##### attributes. +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema b/src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema +index 52036a178..171f66927 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema ++++ b/src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema +@@ -410,7 +410,7 @@ attributetype ( 2.16.840.1.113719.1.301.4.41.1 + ##### Holds the default encryption/salt type combinations of principals for + ##### the Realm. Stores in the form of key:salt strings. This will be + ##### subset of the supported encryption/salt types. +-##### Example: des-cbc-crc:normal ++##### Example: aes256-cts-hmac-sha384-192:normal + + attributetype ( 2.16.840.1.113719.1.301.4.42.1 + NAME 'krbDefaultEncSaltTypes' +@@ -428,7 +428,7 @@ attributetype ( 2.16.840.1.113719.1.301.4.42.1 + ##### ONLYREALM + ##### SPECIAL + ##### AFS3 +-##### Example: des-cbc-crc:normal ++##### Example: aes256-cts-hmac-sha384-192:normal + + attributetype ( 2.16.840.1.113719.1.301.4.43.1 + NAME 'krbSupportedEncSaltTypes' diff --git a/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch b/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch new file mode 100644 index 0000000..f90a723 --- /dev/null +++ b/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch @@ -0,0 +1,85 @@ +From f3f8effd4978bc6671adc85d98105ca10a67df1f Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 16 Apr 2019 14:16:39 -0400 +Subject: [PATCH] Update ASN.1 SAM tests to use a modern enctype + +(cherry picked from commit 3e94e53febc6d5636272f31ae9dba8e3babe9263) +--- + src/tests/asn.1/krb5_decode_test.c | 2 +- + src/tests/asn.1/ktest.c | 4 ++-- + src/tests/asn.1/reference_encode.out | 4 ++-- + src/tests/asn.1/trval_reference.out | 4 ++-- + 4 files changed, 7 insertions(+), 7 deletions(-) + +diff --git a/src/tests/asn.1/krb5_decode_test.c b/src/tests/asn.1/krb5_decode_test.c +index ee70fa4b9..cbd99ba63 100644 +--- a/src/tests/asn.1/krb5_decode_test.c ++++ b/src/tests/asn.1/krb5_decode_test.c +@@ -934,7 +934,7 @@ int main(argc, argv) + /* decode_sam_challenge_2_body */ + { + setup(krb5_sam_challenge_2_body,ktest_make_sample_sam_challenge_2_body); +- decode_run("sam_challenge_2_body","","30 64 A0 03 02 01 2A A1 07 03 05 00 80 00 00 00 A2 0B 04 09 74 79 70 65 20 6E 61 6D 65 A4 11 04 0F 63 68 61 6C 6C 65 6E 67 65 20 6C 61 62 65 6C A5 10 04 0E 63 68 61 6C 6C 65 6E 67 65 20 69 70 73 65 A6 16 04 14 72 65 73 70 6F 6E 73 65 5F 70 72 6F 6D 70 74 20 69 70 73 65 A8 05 02 03 54 32 10 A9 03 02 01 01",decode_krb5_sam_challenge_2_body,ktest_equal_sam_challenge_2_body,krb5_free_sam_challenge_2_body); ++ decode_run("sam_challenge_2_body","","30 64 A0 03 02 01 2A A1 07 03 05 00 80 00 00 00 A2 0B 04 09 74 79 70 65 20 6E 61 6D 65 A4 11 04 0F 63 68 61 6C 6C 65 6E 67 65 20 6C 61 62 65 6C A5 10 04 0E 63 68 61 6C 6C 65 6E 67 65 20 69 70 73 65 A6 16 04 14 72 65 73 70 6F 6E 73 65 5F 70 72 6F 6D 70 74 20 69 70 73 65 A8 05 02 03 54 32 10 A9 03 02 01 14",decode_krb5_sam_challenge_2_body,ktest_equal_sam_challenge_2_body,krb5_free_sam_challenge_2_body); + ktest_empty_sam_challenge_2_body(&ref); + + } +diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c +index 5bfdc5be2..6bf6e54ac 100644 +--- a/src/tests/asn.1/ktest.c ++++ b/src/tests/asn.1/ktest.c +@@ -507,7 +507,7 @@ ktest_make_sample_sam_challenge_2_body(krb5_sam_challenge_2_body *p) + krb5_data_parse(&p->sam_response_prompt, "response_prompt ipse"); + p->sam_pk_for_sad = empty_data(); + p->sam_nonce = 0x543210; +- p->sam_etype = ENCTYPE_DES_CBC_CRC; ++ p->sam_etype = ENCTYPE_AES256_CTS_HMAC_SHA384_192; + } + + void +@@ -518,7 +518,7 @@ ktest_make_sample_sam_response_2(krb5_sam_response_2 *p) + p->sam_flags = KRB5_SAM_USE_SAD_AS_KEY; /* KRB5_SAM_* values */ + krb5_data_parse(&p->sam_track_id, "track data"); + krb5_data_parse(&p->sam_enc_nonce_or_sad.ciphertext, "nonce or sad"); +- p->sam_enc_nonce_or_sad.enctype = ENCTYPE_DES_CBC_CRC; ++ p->sam_enc_nonce_or_sad.enctype = ENCTYPE_AES256_CTS_HMAC_SHA384_192; + p->sam_enc_nonce_or_sad.kvno = 3382; + p->sam_nonce = 0x543210; + } +diff --git a/src/tests/asn.1/reference_encode.out b/src/tests/asn.1/reference_encode.out +index a76deead2..80b18a2fb 100644 +--- a/src/tests/asn.1/reference_encode.out ++++ b/src/tests/asn.1/reference_encode.out +@@ -49,8 +49,8 @@ encode_krb5_enc_data: 30 23 A0 03 02 01 00 A1 03 02 01 05 A2 17 04 15 6B 72 62 4 + encode_krb5_enc_data(MSB-set kvno): 30 26 A0 03 02 01 00 A1 06 02 04 FF 00 00 00 A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65 + encode_krb5_enc_data(kvno=-1): 30 23 A0 03 02 01 00 A1 03 02 01 FF A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65 + encode_krb5_sam_challenge_2: 30 22 A0 0D 30 0B 04 09 63 68 61 6C 6C 65 6E 67 65 A1 11 30 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34 +-encode_krb5_sam_challenge_2_body: 30 64 A0 03 02 01 2A A1 07 03 05 00 80 00 00 00 A2 0B 04 09 74 79 70 65 20 6E 61 6D 65 A4 11 04 0F 63 68 61 6C 6C 65 6E 67 65 20 6C 61 62 65 6C A5 10 04 0E 63 68 61 6C 6C 65 6E 67 65 20 69 70 73 65 A6 16 04 14 72 65 73 70 6F 6E 73 65 5F 70 72 6F 6D 70 74 20 69 70 73 65 A8 05 02 03 54 32 10 A9 03 02 01 01 +-encode_krb5_sam_response_2: 30 42 A0 03 02 01 2B A1 07 03 05 00 80 00 00 00 A2 0C 04 0A 74 72 61 63 6B 20 64 61 74 61 A3 1D 30 1B A0 03 02 01 01 A1 04 02 02 0D 36 A2 0E 04 0C 6E 6F 6E 63 65 20 6F 72 20 73 61 64 A4 05 02 03 54 32 10 ++encode_krb5_sam_challenge_2_body: 30 64 A0 03 02 01 2A A1 07 03 05 00 80 00 00 00 A2 0B 04 09 74 79 70 65 20 6E 61 6D 65 A4 11 04 0F 63 68 61 6C 6C 65 6E 67 65 20 6C 61 62 65 6C A5 10 04 0E 63 68 61 6C 6C 65 6E 67 65 20 69 70 73 65 A6 16 04 14 72 65 73 70 6F 6E 73 65 5F 70 72 6F 6D 70 74 20 69 70 73 65 A8 05 02 03 54 32 10 A9 03 02 01 14 ++encode_krb5_sam_response_2: 30 42 A0 03 02 01 2B A1 07 03 05 00 80 00 00 00 A2 0C 04 0A 74 72 61 63 6B 20 64 61 74 61 A3 1D 30 1B A0 03 02 01 14 A1 04 02 02 0D 36 A2 0E 04 0C 6E 6F 6E 63 65 20 6F 72 20 73 61 64 A4 05 02 03 54 32 10 + encode_krb5_enc_sam_response_enc_2: 30 1F A0 03 02 01 58 A1 18 04 16 65 6E 63 5F 73 61 6D 5F 72 65 73 70 6F 6E 73 65 5F 65 6E 63 5F 32 + encode_krb5_pa_for_user: 30 4B A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A2 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34 A3 0A 1B 08 6B 72 62 35 64 61 74 61 + encode_krb5_pa_s4u_x509_user: 30 68 A0 55 30 53 A0 06 02 04 00 CA 14 9A A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A2 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A3 12 04 10 70 61 5F 73 34 75 5F 78 35 30 39 5F 75 73 65 72 A4 07 03 05 00 80 00 00 00 A1 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34 +diff --git a/src/tests/asn.1/trval_reference.out b/src/tests/asn.1/trval_reference.out +index e5c715924..432fdcebb 100644 +--- a/src/tests/asn.1/trval_reference.out ++++ b/src/tests/asn.1/trval_reference.out +@@ -1180,7 +1180,7 @@ encode_krb5_sam_challenge_2_body: + . [5] [Octet String] "challenge ipse" + . [6] [Octet String] "response_prompt ipse" + . [8] [Integer] 5517840 +-. [9] [Integer] 1 ++. [9] [Integer] 20 + + encode_krb5_sam_response_2: + +@@ -1189,7 +1189,7 @@ encode_krb5_sam_response_2: + . [1] [Bit String] 0x80000000 + . [2] [Octet String] "track data" + . [3] [Sequence/Sequence Of] +-. . [0] [Integer] 1 ++. . [0] [Integer] 20 + . . [1] [Integer] 3382 + . . [2] [Octet String] "nonce or sad" + . [4] [Integer] 5517840 diff --git a/krb5.spec b/krb5.spec index 3774e73..f679038 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 22%{?dist} +Release: 23%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -94,6 +94,9 @@ Patch126: Remove-more-dead-code.patch Patch127: krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch Patch128: Remove-checksum-type-profile-variables.patch Patch129: Remove-dead-variable-def_kslist-from-two-files.patch +Patch130: Mark-the-doc-kadm5-tex-files-as-historic.patch +Patch131: Modernize-example-enctypes-in-documentation.patch +Patch132: Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -703,6 +706,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon May 20 2019 Robbie Harwood - 1.17-23 +- Test & docs fixes in preparation for DES removal + * Wed May 15 2019 Robbie Harwood - 1.17-22 - Drop krb5_realm_compare() etc. NULL check patches From 79613952e317c33391752d3f35143e88f649f607 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 21 May 2019 12:59:56 -0400 Subject: [PATCH 109/304] Update default krb5kdc mkey manual-entry enctype Also update account lockout patch to upstream version --- ...nonicalize_hostname-fallback-support.patch | 2 +- ...on-and-enctype-flag-for-deprecations.patch | 2 +- Add-tests-for-KCM-ccache-type.patch | 2 +- Address-some-optimized-out-memset-calls.patch | 2 +- ...-alignment-warnings-in-openssl-rc4.c.patch | 2 +- ...llocating-a-register-in-zap-assembly.patch | 2 +- ...ore-errors-in-OpenSSL-crypto-backend.patch | 2 +- ...er-comment-for-krb5_cc_start_seq_get.patch | 2 +- ...able-flag-instead-of-denying-request.patch | 2 +- ...alm-change-logic-in-FILE-remove_cred.patch | 2 +- ...emory-leak-in-none-replay-cache-type.patch | 2 +- Fix-potential-close-1-in-cc_file.c.patch | 2 +- Fix-some-return-code-handling-bugs.patch | 2 +- ...5_cc_remove_cred-for-remaining-types.patch | 2 +- ...messages-from-kadmin-change_password.patch | 2 +- ...ebug-log-proper-ticket-enctype-names.patch | 2 +- ...ec-always-log-non-permitted-enctypes.patch | 2 +- ...ize-some-data-structure-magic-fields.patch | 2 +- ...ype-names-in-KDC-logs-human-readable.patch | 2 +- Mark-deprecated-enctypes-when-used.patch | 2 +- ...-the-doc-kadm5-tex-files-as-historic.patch | 2 +- ...ze-example-enctypes-in-documentation.patch | 2 +- ...exit-path-in-gss_krb5int_copy_ccache.patch | 2 +- Properly-size-ifdef-in-k5_cccol_lock.patch | 2 +- ...beros-v4-support-vestiges-from-ccapi.patch | 2 +- ...api-related-comments-in-configure.ac.patch | 2 +- Remove-checksum-type-profile-variables.patch | 2 +- Remove-confvalidator-utility.patch | 2 +- ...d-variable-def_kslist-from-two-files.patch | 2 +- ...ygen-generated-HTML-output-for-ccapi.patch | 2 +- ...admin-RPC-support-for-setting-v4-key.patch | 2 +- Remove-more-dead-code.patch | 2 +- ...ovsec_adm_export-dump-format-support.patch | 2 +- Remove-srvtab-support.patch | 2 +- Simplify-SAM-2-as_key-handling.patch | 2 +- Simply-OpenSSL-PKCS7-decryption-code.patch | 2 +- Support-389ds-s-lockout-model.patch | 63 ++++++++++++++++ ....1-SAM-tests-to-use-a-modern-enctype.patch | 2 +- ...lt-krb5kdc-mkey-manual-entry-enctype.patch | 54 +++++++++++++ Use-secure_getenv-where-appropriate.patch | 2 +- krb5-1.11-kpasswdtest.patch | 2 +- krb5-1.11-run_user_0.patch | 2 +- krb5-1.13-dirsrv-accountlock.patch | 75 ------------------- ...ost2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch | 2 +- krb5-1.9-debuginfo.patch | 2 +- krb5.spec | 9 ++- 46 files changed, 166 insertions(+), 119 deletions(-) create mode 100644 Support-389ds-s-lockout-model.patch create mode 100644 Update-default-krb5kdc-mkey-manual-entry-enctype.patch delete mode 100644 krb5-1.13-dirsrv-accountlock.patch diff --git a/Add-dns_canonicalize_hostname-fallback-support.patch b/Add-dns_canonicalize_hostname-fallback-support.patch index 7fb6a91..6e4c8c0 100644 --- a/Add-dns_canonicalize_hostname-fallback-support.patch +++ b/Add-dns_canonicalize_hostname-fallback-support.patch @@ -1,4 +1,4 @@ -From 770a525f940a319b4f9a91423a9f48bde28429b9 Mon Sep 17 00:00:00 2001 +From 8ec4a9ab41c73e7955ed7929a3d2a19592811596 Mon Sep 17 00:00:00 2001 From: Simo Sorce Date: Tue, 4 Dec 2018 15:22:55 -0500 Subject: [PATCH] Add dns_canonicalize_hostname=fallback support diff --git a/Add-function-and-enctype-flag-for-deprecations.patch b/Add-function-and-enctype-flag-for-deprecations.patch index 739371b..b511554 100644 --- a/Add-function-and-enctype-flag-for-deprecations.patch +++ b/Add-function-and-enctype-flag-for-deprecations.patch @@ -1,4 +1,4 @@ -From 0713281743627e32f234e55bdaaeb58b37036675 Mon Sep 17 00:00:00 2001 +From 8491894d2bad21026d73b999814baffe8a695fb7 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 16:16:57 -0500 Subject: [PATCH] Add function and enctype flag for deprecations diff --git a/Add-tests-for-KCM-ccache-type.patch b/Add-tests-for-KCM-ccache-type.patch index 08b6b03..ca70e00 100644 --- a/Add-tests-for-KCM-ccache-type.patch +++ b/Add-tests-for-KCM-ccache-type.patch @@ -1,4 +1,4 @@ -From b8be4f3272dcca4b34f9d79b47b88e510e0d4926 Mon Sep 17 00:00:00 2001 +From 01dcc90e901491196a7ce5da893eec0b699c28b5 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Nov 2018 00:27:35 -0500 Subject: [PATCH] Add tests for KCM ccache type diff --git a/Address-some-optimized-out-memset-calls.patch b/Address-some-optimized-out-memset-calls.patch index 51318c7..aa28531 100644 --- a/Address-some-optimized-out-memset-calls.patch +++ b/Address-some-optimized-out-memset-calls.patch @@ -1,4 +1,4 @@ -From 31df8a3ef6b01b11a5956e16206069907a7acf17 Mon Sep 17 00:00:00 2001 +From ef4610f2ca0337bf5522dca3dc6800f795cc6a82 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 30 Dec 2018 16:40:28 -0500 Subject: [PATCH] Address some optimized-out memset() calls diff --git a/Avoid-alignment-warnings-in-openssl-rc4.c.patch b/Avoid-alignment-warnings-in-openssl-rc4.c.patch index fdfe144..5fee63b 100644 --- a/Avoid-alignment-warnings-in-openssl-rc4.c.patch +++ b/Avoid-alignment-warnings-in-openssl-rc4.c.patch @@ -1,4 +1,4 @@ -From dac87fb5d866251731ba524053d55482bf5fad2a Mon Sep 17 00:00:00 2001 +From cf0981bf39558c6501fe1dd2386231ac5f430918 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 15:14:49 -0400 Subject: [PATCH] Avoid alignment warnings in openssl rc4.c diff --git a/Avoid-allocating-a-register-in-zap-assembly.patch b/Avoid-allocating-a-register-in-zap-assembly.patch index 4444b3a..c8c8589 100644 --- a/Avoid-allocating-a-register-in-zap-assembly.patch +++ b/Avoid-allocating-a-register-in-zap-assembly.patch @@ -1,4 +1,4 @@ -From 087dd4f2cfde763b3b4ac1e34de87a3b9217037f Mon Sep 17 00:00:00 2001 +From f516db322b1469a13e59e1c2847e62cb265ce92c Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Thu, 3 Jan 2019 17:19:32 +0100 Subject: [PATCH] Avoid allocating a register in zap() assembly diff --git a/Check-more-errors-in-OpenSSL-crypto-backend.patch b/Check-more-errors-in-OpenSSL-crypto-backend.patch index 64fbfa1..707c05d 100644 --- a/Check-more-errors-in-OpenSSL-crypto-backend.patch +++ b/Check-more-errors-in-OpenSSL-crypto-backend.patch @@ -1,4 +1,4 @@ -From 43fa850e47233f95c429c5b06fc74130a9c2b2b1 Mon Sep 17 00:00:00 2001 +From f001aa86071aabc398b0d7c38033c26b21fe85f2 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 22 Apr 2019 14:26:42 -0400 Subject: [PATCH] Check more errors in OpenSSL crypto backend diff --git a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch index 56d3027..82995e6 100644 --- a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch +++ b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch @@ -1,4 +1,4 @@ -From f6f799d2581251529c28bbb4644e42e19c6980ab Mon Sep 17 00:00:00 2001 +From 8f22ca7ddc9765e3d7a1de867164d307f8662cb3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Apr 2019 14:18:57 -0400 Subject: [PATCH] Clarify header comment for krb5_cc_start_seq_get() diff --git a/Clear-forwardable-flag-instead-of-denying-request.patch b/Clear-forwardable-flag-instead-of-denying-request.patch index ea19b4b..ff7e090 100644 --- a/Clear-forwardable-flag-instead-of-denying-request.patch +++ b/Clear-forwardable-flag-instead-of-denying-request.patch @@ -1,4 +1,4 @@ -From 63e531d3545d74d734f56987bbc77256cbcd7763 Mon Sep 17 00:00:00 2001 +From ab1435ed0654df9991bddb29971c913ef1f957be Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 15 Nov 2018 13:40:43 -0500 Subject: [PATCH] Clear forwardable flag instead of denying request diff --git a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch index 53c69e8..ac58f37 100644 --- a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch +++ b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch @@ -1,4 +1,4 @@ -From 4cacf2fa4a181b728742bce8c1ea11c07ba9a143 Mon Sep 17 00:00:00 2001 +From 2f5531f3cffb497902241e4932db20617f4d30eb Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 16 Apr 2019 10:47:35 -0400 Subject: [PATCH] Fix config realm change logic in FILE remove_cred diff --git a/Fix-memory-leak-in-none-replay-cache-type.patch b/Fix-memory-leak-in-none-replay-cache-type.patch index 31753d3..bb51241 100644 --- a/Fix-memory-leak-in-none-replay-cache-type.patch +++ b/Fix-memory-leak-in-none-replay-cache-type.patch @@ -1,4 +1,4 @@ -From 492872c4581f8b7f6d78cbc2e50e0b819c47a168 Mon Sep 17 00:00:00 2001 +From 75b39bfb256b639cf6ca491568fd6ef667b19d46 Mon Sep 17 00:00:00 2001 From: Corene Casper Date: Sat, 16 Feb 2019 00:49:26 -0500 Subject: [PATCH] Fix memory leak in 'none' replay cache type diff --git a/Fix-potential-close-1-in-cc_file.c.patch b/Fix-potential-close-1-in-cc_file.c.patch index 94b96a8..5b504f2 100644 --- a/Fix-potential-close-1-in-cc_file.c.patch +++ b/Fix-potential-close-1-in-cc_file.c.patch @@ -1,4 +1,4 @@ -From 0201f95a60194c99bd3139235eb46e13e7f4484f Mon Sep 17 00:00:00 2001 +From 4faa872c4fc674b791a1c05652833ff40dac7889 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 18 Apr 2019 13:39:37 -0400 Subject: [PATCH] Fix potential close(-1) in cc_file.c diff --git a/Fix-some-return-code-handling-bugs.patch b/Fix-some-return-code-handling-bugs.patch index 436b65a..7b151c7 100644 --- a/Fix-some-return-code-handling-bugs.patch +++ b/Fix-some-return-code-handling-bugs.patch @@ -1,4 +1,4 @@ -From e196f175f5b551290efab029295dcf728feb4fac Mon Sep 17 00:00:00 2001 +From b7bbc88f5ebc6000a8dec95e7f0ff92bbeb54ad4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 14:05:38 -0400 Subject: [PATCH] Fix some return code handling bugs diff --git a/Implement-krb5_cc_remove_cred-for-remaining-types.patch b/Implement-krb5_cc_remove_cred-for-remaining-types.patch index 4cf15a1..9594ed0 100644 --- a/Implement-krb5_cc_remove_cred-for-remaining-types.patch +++ b/Implement-krb5_cc_remove_cred-for-remaining-types.patch @@ -1,4 +1,4 @@ -From 6e199a7d007bbfd72ed76ff5534b9b3b88a82227 Mon Sep 17 00:00:00 2001 +From 7d3da40bd7f44f2d6960b5a9245a1d773c4ee1a0 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 1 Apr 2019 14:28:48 -0400 Subject: [PATCH] Implement krb5_cc_remove_cred for remaining types diff --git a/Improve-error-messages-from-kadmin-change_password.patch b/Improve-error-messages-from-kadmin-change_password.patch index afff2a1..6ecb07a 100644 --- a/Improve-error-messages-from-kadmin-change_password.patch +++ b/Improve-error-messages-from-kadmin-change_password.patch @@ -1,4 +1,4 @@ -From 35681c176f3519df4700fd799ed66efd323f8c66 Mon Sep 17 00:00:00 2001 +From ae3053282d879cdbb803c0ff1d6deef8940eeb2a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 13:13:16 -0400 Subject: [PATCH] Improve error messages from kadmin change_password diff --git a/In-kpropd-debug-log-proper-ticket-enctype-names.patch b/In-kpropd-debug-log-proper-ticket-enctype-names.patch index 7972d01..e1b19e3 100644 --- a/In-kpropd-debug-log-proper-ticket-enctype-names.patch +++ b/In-kpropd-debug-log-proper-ticket-enctype-names.patch @@ -1,4 +1,4 @@ -From 34883789b60e7961ac0c63062ffadbb2e628a76e Mon Sep 17 00:00:00 2001 +From 71cbe768d29bbe35cff9c37959f3e5352569af39 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 13:41:16 -0500 Subject: [PATCH] In kpropd, debug-log proper ticket enctype names diff --git a/In-rd_req_dec-always-log-non-permitted-enctypes.patch b/In-rd_req_dec-always-log-non-permitted-enctypes.patch index 9eb6a77..a2a4c53 100644 --- a/In-rd_req_dec-always-log-non-permitted-enctypes.patch +++ b/In-rd_req_dec-always-log-non-permitted-enctypes.patch @@ -1,4 +1,4 @@ -From 4d178af94f1a5f187b43de96ae16b2fb1cf4ba8a Mon Sep 17 00:00:00 2001 +From 4c59f0f53a698c9c4242791e8d620d50a394d5c6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Jan 2019 17:14:42 -0500 Subject: [PATCH] In rd_req_dec, always log non-permitted enctypes diff --git a/Initialize-some-data-structure-magic-fields.patch b/Initialize-some-data-structure-magic-fields.patch index d3ee55d..e418b9f 100644 --- a/Initialize-some-data-structure-magic-fields.patch +++ b/Initialize-some-data-structure-magic-fields.patch @@ -1,4 +1,4 @@ -From da7349429a2985423ad006cc1f9d149e594118b7 Mon Sep 17 00:00:00 2001 +From 37b73dd837a05c14d422379b686b8a10de0083fa Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 13:36:38 -0400 Subject: [PATCH] Initialize some data structure magic fields diff --git a/Make-etype-names-in-KDC-logs-human-readable.patch b/Make-etype-names-in-KDC-logs-human-readable.patch index a77c4bc..ba85392 100644 --- a/Make-etype-names-in-KDC-logs-human-readable.patch +++ b/Make-etype-names-in-KDC-logs-human-readable.patch @@ -1,4 +1,4 @@ -From fddfa2abbc9e1ccd138d66a8c462a6a0eba1ecaa Mon Sep 17 00:00:00 2001 +From e05c448510fc20946fb6d777bd7e3841dd986e75 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 8 Jan 2019 17:42:35 -0500 Subject: [PATCH] Make etype names in KDC logs human-readable diff --git a/Mark-deprecated-enctypes-when-used.patch b/Mark-deprecated-enctypes-when-used.patch index b165d7f..8d9f327 100644 --- a/Mark-deprecated-enctypes-when-used.patch +++ b/Mark-deprecated-enctypes-when-used.patch @@ -1,4 +1,4 @@ -From c40eb78a918138369f6d7142590732f563968909 Mon Sep 17 00:00:00 2001 +From 7acee539da508c10aabbc8483243da6c6ba37892 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 10 Jan 2019 16:34:54 -0500 Subject: [PATCH] Mark deprecated enctypes when used diff --git a/Mark-the-doc-kadm5-tex-files-as-historic.patch b/Mark-the-doc-kadm5-tex-files-as-historic.patch index bacbb1b..abf1f4a 100644 --- a/Mark-the-doc-kadm5-tex-files-as-historic.patch +++ b/Mark-the-doc-kadm5-tex-files-as-historic.patch @@ -1,4 +1,4 @@ -From 7385ae430280e839a2a0b5a7c5a6be1b2b24aef4 Mon Sep 17 00:00:00 2001 +From 28a605c2411c3def3e5eaa19be5326777e959a1a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 11 Apr 2019 18:33:04 -0400 Subject: [PATCH] Mark the doc/kadm5 tex files as historic diff --git a/Modernize-example-enctypes-in-documentation.patch b/Modernize-example-enctypes-in-documentation.patch index 7c3d87c..428ac2b 100644 --- a/Modernize-example-enctypes-in-documentation.patch +++ b/Modernize-example-enctypes-in-documentation.patch @@ -1,4 +1,4 @@ -From 6eb0931738f26890952de08d4ea9de24b0f684f5 Mon Sep 17 00:00:00 2001 +From cef9a57dc094bb2ca57d5b765981fbb2ab93adde Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 11 Apr 2019 18:25:41 -0400 Subject: [PATCH] Modernize example enctypes in documentation diff --git a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch index 489987d..ff1d987 100644 --- a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch +++ b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch @@ -1,4 +1,4 @@ -From bca13182a78bc3c62bd7e616c9b69ce96fe00b98 Mon Sep 17 00:00:00 2001 +From 894bcbfcf27c9bc1117bb624f27123eb25fcd7bf Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 14:32:33 -0400 Subject: [PATCH] Modernize exit path in gss_krb5int_copy_ccache() diff --git a/Properly-size-ifdef-in-k5_cccol_lock.patch b/Properly-size-ifdef-in-k5_cccol_lock.patch index b38fc66..d7af9bf 100644 --- a/Properly-size-ifdef-in-k5_cccol_lock.patch +++ b/Properly-size-ifdef-in-k5_cccol_lock.patch @@ -1,4 +1,4 @@ -From 5601f9e0291feedeba7a420396d83b38c7332e86 Mon Sep 17 00:00:00 2001 +From 6f9bd0a292f1b84e16cab8c89efee87359b007d2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Feb 2019 11:50:35 -0500 Subject: [PATCH] Properly size #ifdef in k5_cccol_lock() diff --git a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch index 796ad66..b00a745 100644 --- a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch +++ b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch @@ -1,4 +1,4 @@ -From ff88e21470d374f057107148de8b972a04f59641 Mon Sep 17 00:00:00 2001 +From ff011e05cfb28b408778f4ace22a745f19c0bdd2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 14:37:38 -0400 Subject: [PATCH] Remove Kerberos v4 support vestiges from ccapi diff --git a/Remove-ccapi-related-comments-in-configure.ac.patch b/Remove-ccapi-related-comments-in-configure.ac.patch index 7f3fa56..0fb5d50 100644 --- a/Remove-ccapi-related-comments-in-configure.ac.patch +++ b/Remove-ccapi-related-comments-in-configure.ac.patch @@ -1,4 +1,4 @@ -From 32b05ffd5f0d6eff5f989a8c30a030a3e1972e5d Mon Sep 17 00:00:00 2001 +From 7f015c7ed945d1d51ffd0ba1dd5b89c150eacf83 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Apr 2019 16:01:22 -0400 Subject: [PATCH] Remove ccapi-related comments in configure.ac diff --git a/Remove-checksum-type-profile-variables.patch b/Remove-checksum-type-profile-variables.patch index af1112e..eebabea 100644 --- a/Remove-checksum-type-profile-variables.patch +++ b/Remove-checksum-type-profile-variables.patch @@ -1,4 +1,4 @@ -From e3de3f9916acc4ba0ac2e15c2d9a6826802170d2 Mon Sep 17 00:00:00 2001 +From a642ac26ca00d4cfaae84398372035b0c1e444ed Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 13 May 2019 14:19:57 -0400 Subject: [PATCH] Remove checksum type profile variables diff --git a/Remove-confvalidator-utility.patch b/Remove-confvalidator-utility.patch index 134ba1e..302df29 100644 --- a/Remove-confvalidator-utility.patch +++ b/Remove-confvalidator-utility.patch @@ -1,4 +1,4 @@ -From 2ea1badfb30f8549a5ec00dc8c5f5e58caea5a03 Mon Sep 17 00:00:00 2001 +From ecab56bca80824913e98a5b25f34a5ebe483990d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Apr 2019 14:58:19 -0400 Subject: [PATCH] Remove confvalidator utility diff --git a/Remove-dead-variable-def_kslist-from-two-files.patch b/Remove-dead-variable-def_kslist-from-two-files.patch index ee60f78..9fd92c9 100644 --- a/Remove-dead-variable-def_kslist-from-two-files.patch +++ b/Remove-dead-variable-def_kslist-from-two-files.patch @@ -1,4 +1,4 @@ -From a37470b4f45cd40318c8ad84d92f56bdaac4993e Mon Sep 17 00:00:00 2001 +From 85416629f6d120bf272d9aaa9c661b8a849c40b3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 16:57:51 -0400 Subject: [PATCH] Remove dead variable def_kslist from two files diff --git a/Remove-doxygen-generated-HTML-output-for-ccapi.patch b/Remove-doxygen-generated-HTML-output-for-ccapi.patch index 9825899..48b515a 100644 --- a/Remove-doxygen-generated-HTML-output-for-ccapi.patch +++ b/Remove-doxygen-generated-HTML-output-for-ccapi.patch @@ -1,4 +1,4 @@ -From 90324f46fe8aed4054ecad4f3a0357ffa3716852 Mon Sep 17 00:00:00 2001 +From cf25d152b2b1f54bbd92e235a30de20e154f3e7a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 14:15:58 -0400 Subject: [PATCH] Remove doxygen-generated HTML output for ccapi diff --git a/Remove-kadmin-RPC-support-for-setting-v4-key.patch b/Remove-kadmin-RPC-support-for-setting-v4-key.patch index 66a08c2..9b2ea36 100644 --- a/Remove-kadmin-RPC-support-for-setting-v4-key.patch +++ b/Remove-kadmin-RPC-support-for-setting-v4-key.patch @@ -1,4 +1,4 @@ -From 962e49c0ef0faf00210a1f88044782f6fa47a779 Mon Sep 17 00:00:00 2001 +From 12e48c208c042f219d5cb8fb984094c5c958c99b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 16:14:46 -0400 Subject: [PATCH] Remove kadmin RPC support for setting v4 key diff --git a/Remove-more-dead-code.patch b/Remove-more-dead-code.patch index ed67434..ef9a747 100644 --- a/Remove-more-dead-code.patch +++ b/Remove-more-dead-code.patch @@ -1,4 +1,4 @@ -From f708c93e82dc34c6ab2bd04be2149bd539faec4d Mon Sep 17 00:00:00 2001 +From 98e6b0ada15075ea017fe8086f21b95fc2280fcd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 9 May 2019 14:07:24 -0400 Subject: [PATCH] Remove more dead code diff --git a/Remove-ovsec_adm_export-dump-format-support.patch b/Remove-ovsec_adm_export-dump-format-support.patch index aad68b3..f4b0510 100644 --- a/Remove-ovsec_adm_export-dump-format-support.patch +++ b/Remove-ovsec_adm_export-dump-format-support.patch @@ -1,4 +1,4 @@ -From 56be395114bed8e8dd41b91e41e233637488d3ab Mon Sep 17 00:00:00 2001 +From 6f9222fb372af6d7988c65cc4ec3cb56f6cc747a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 22 Jan 2019 18:34:58 -0500 Subject: [PATCH] Remove ovsec_adm_export dump format support diff --git a/Remove-srvtab-support.patch b/Remove-srvtab-support.patch index 0fa5c2a..6f2a7ec 100644 --- a/Remove-srvtab-support.patch +++ b/Remove-srvtab-support.patch @@ -1,4 +1,4 @@ -From 42b1d879cf0705d3bc76c4b546275f1c608ebda9 Mon Sep 17 00:00:00 2001 +From 0869d133743446612c512ce9aec5832ce10e282b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 9 Oct 2017 15:58:33 -0400 Subject: [PATCH] Remove srvtab support diff --git a/Simplify-SAM-2-as_key-handling.patch b/Simplify-SAM-2-as_key-handling.patch index 54123ec..b9f877b 100644 --- a/Simplify-SAM-2-as_key-handling.patch +++ b/Simplify-SAM-2-as_key-handling.patch @@ -1,4 +1,4 @@ -From 251694f155bd132a162f876e59abf5caf7140c70 Mon Sep 17 00:00:00 2001 +From 48cca5e6134e6137cab7d592dfb31f0a19e4e7ea Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 5 May 2019 18:53:27 -0400 Subject: [PATCH] Simplify SAM-2 as_key handling diff --git a/Simply-OpenSSL-PKCS7-decryption-code.patch b/Simply-OpenSSL-PKCS7-decryption-code.patch index 16436e0..cc40c6e 100644 --- a/Simply-OpenSSL-PKCS7-decryption-code.patch +++ b/Simply-OpenSSL-PKCS7-decryption-code.patch @@ -1,4 +1,4 @@ -From 02c3a9756cba8676a3074ae8c1c96b26e1b47c98 Mon Sep 17 00:00:00 2001 +From 0b4433c4ab9653eb298e2b7d959e957d468fd3f9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 13:13:06 -0400 Subject: [PATCH] Simply OpenSSL PKCS7 decryption code diff --git a/Support-389ds-s-lockout-model.patch b/Support-389ds-s-lockout-model.patch new file mode 100644 index 0000000..6bf16fc --- /dev/null +++ b/Support-389ds-s-lockout-model.patch @@ -0,0 +1,63 @@ +From 5673f1c22b602ac4b72e59c84b70ecedf3132c11 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 23 Aug 2016 16:47:44 -0400 +Subject: [PATCH] Support 389ds's lockout model + +Handle the attribute 'nsAccountLock' from Netscape derivatives. Based +on a patch by Nalin Dahyabhai and Simo Sorce. + +ticket: 5891 +(cherry picked from commit 6ad061e24eca41a61eebed61db39768bfa51a084) +--- + src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c | 18 ++++++++++++++++++ + .../kdb/ldap/libkdb_ldap/ldap_principal.c | 1 + + 2 files changed, 19 insertions(+) + +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c +index 5b9d1e9fa..2ade63719 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c ++++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c +@@ -1420,6 +1420,7 @@ populate_krb5_db_entry(krb5_context context, krb5_ldap_context *ldap_context, + struct berval **ber_key_data = NULL, **ber_tl_data = NULL; + krb5_tl_data userinfo_tl_data = { NULL }, **endp, *tl; + osa_princ_ent_rec princ_ent; ++ char *is_login_disabled = NULL; + + memset(&princ_ent, 0, sizeof(princ_ent)); + +@@ -1653,6 +1654,23 @@ populate_krb5_db_entry(krb5_context context, krb5_ldap_context *ldap_context, + if (ret) + goto cleanup; + ++ /* ++ * 389ds and other Netscape directory server derivatives support an ++ * attribute "nsAccountLock" which functions similarly to eDirectory's ++ * "loginDisabled". When the user's account object is also a ++ * krbPrincipalAux object, the kdb entry should be treated as if ++ * DISALLOW_ALL_TIX has been set. ++ */ ++ ret = krb5_ldap_get_string(ld, ent, "nsAccountLock", &is_login_disabled, ++ &attr_present); ++ if (ret) ++ goto cleanup; ++ if (attr_present == TRUE) { ++ if (strcasecmp(is_login_disabled, "TRUE") == 0) ++ entry->attributes |= KRB5_KDB_DISALLOW_ALL_TIX; ++ free(is_login_disabled); ++ } ++ + ret = krb5_read_tkt_policy(context, ldap_context, entry, tktpolname); + if (ret) + goto cleanup; +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c +index d722dbfa6..a5180c73f 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c ++++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c +@@ -54,6 +54,7 @@ char *principal_attributes[] = { "krbprincipalname", + "krbLastFailedAuth", + "krbLoginFailedCount", + "krbLastSuccessfulAuth", ++ "nsAccountLock", + "krbLastPwdChange", + "krbLastAdminUnlock", + "krbPrincipalAuthInd", diff --git a/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch b/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch index f90a723..526b44c 100644 --- a/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch +++ b/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch @@ -1,4 +1,4 @@ -From f3f8effd4978bc6671adc85d98105ca10a67df1f Mon Sep 17 00:00:00 2001 +From a7db3ad8e75a865c2de8c522f582129051bbe958 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 16 Apr 2019 14:16:39 -0400 Subject: [PATCH] Update ASN.1 SAM tests to use a modern enctype diff --git a/Update-default-krb5kdc-mkey-manual-entry-enctype.patch b/Update-default-krb5kdc-mkey-manual-entry-enctype.patch new file mode 100644 index 0000000..d8e85a5 --- /dev/null +++ b/Update-default-krb5kdc-mkey-manual-entry-enctype.patch @@ -0,0 +1,54 @@ +From 32d2b3e6dc3ab6aa9bb824701752ccfc23d61c1c Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 20 May 2019 16:52:57 -0400 +Subject: [PATCH] Update default krb5kdc mkey manual-entry enctype + +Change from the legacy des-cbc-crc to the default for kdb5_util and +kadmind, which is currently aes256-cts-hmac-sha1-96. + +(cherry picked from commit 512f5cde625253cba1e6f87e037a00ef88178882) +--- + doc/admin/admin_commands/krb5kdc.rst | 2 +- + src/kdc/main.c | 2 +- + src/man/krb5kdc.man | 2 +- + 3 files changed, 3 insertions(+), 3 deletions(-) + +diff --git a/doc/admin/admin_commands/krb5kdc.rst b/doc/admin/admin_commands/krb5kdc.rst +index 0342d0d18..455bb6858 100644 +--- a/doc/admin/admin_commands/krb5kdc.rst ++++ b/doc/admin/admin_commands/krb5kdc.rst +@@ -39,7 +39,7 @@ LDAP database. + + The **-k** *keytype* option specifies the key type of the master key + to be entered manually as a password when **-m** is given; the default +-is ``des-cbc-crc``. ++is |defmkey|. + + The **-M** *mkeyname* option specifies the principal name for the + master key in the database (usually ``K/M`` in the KDC's realm). +diff --git a/src/kdc/main.c b/src/kdc/main.c +index 60092a0df..04393772f 100644 +--- a/src/kdc/main.c ++++ b/src/kdc/main.c +@@ -777,7 +777,7 @@ initialize_realms(krb5_context kcontext, int argc, char **argv, + case 'm': /* manual type-in of master key */ + manual = TRUE; + if (menctype == ENCTYPE_UNKNOWN) +- menctype = ENCTYPE_DES_CBC_CRC; ++ menctype = DEFAULT_KDC_ENCTYPE; + break; + case 'M': /* master key name in DB */ + mkey_name = optarg; +diff --git a/src/man/krb5kdc.man b/src/man/krb5kdc.man +index 8ace9662f..aa8614698 100644 +--- a/src/man/krb5kdc.man ++++ b/src/man/krb5kdc.man +@@ -59,7 +59,7 @@ LDAP database. + .sp + The \fB\-k\fP \fIkeytype\fP option specifies the key type of the master key + to be entered manually as a password when \fB\-m\fP is given; the default +-is \fBdes\-cbc\-crc\fP\&. ++is \fBaes256\-cts\-hmac\-sha1\-96\fP\&. + .sp + The \fB\-M\fP \fImkeyname\fP option specifies the principal name for the + master key in the database (usually \fBK/M\fP in the KDC\(aqs realm). diff --git a/Use-secure_getenv-where-appropriate.patch b/Use-secure_getenv-where-appropriate.patch index 6338aee..65d813e 100644 --- a/Use-secure_getenv-where-appropriate.patch +++ b/Use-secure_getenv-where-appropriate.patch @@ -1,4 +1,4 @@ -From a46c1dd1be09217f9f19e9c70381893dc3995c45 Mon Sep 17 00:00:00 2001 +From 4ed88289e0b3c5a6fcda13078abf211fb8e4f84c Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 24 Apr 2019 16:19:50 -0400 Subject: [PATCH] Use secure_getenv() where appropriate diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch index 7c763ce..4b4358b 100644 --- a/krb5-1.11-kpasswdtest.patch +++ b/krb5-1.11-kpasswdtest.patch @@ -1,4 +1,4 @@ -From d3e720a17e4284c791541840dcbc8652d33a75c4 Mon Sep 17 00:00:00 2001 +From 8e03102127701980c1ace62cbea93e4003a0ef5d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:52:01 -0400 Subject: [PATCH] krb5-1.11-kpasswdtest.patch diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch index 673d127..c23e0a1 100644 --- a/krb5-1.11-run_user_0.patch +++ b/krb5-1.11-run_user_0.patch @@ -1,4 +1,4 @@ -From 75ba8f42c0e9426af80c71aaaa490cc6262e259c Mon Sep 17 00:00:00 2001 +From 44ecf1e570aacff7630334fbf1650e2f33f8675e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:57 -0400 Subject: [PATCH] krb5-1.11-run_user_0.patch diff --git a/krb5-1.13-dirsrv-accountlock.patch b/krb5-1.13-dirsrv-accountlock.patch deleted file mode 100644 index e5fbd7f..0000000 --- a/krb5-1.13-dirsrv-accountlock.patch +++ /dev/null @@ -1,75 +0,0 @@ -From eb26e32b7cce535a7a70168b7f44aa07eb989264 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:47:44 -0400 -Subject: [PATCH] krb5-1.13-dirsrv-accountlock.patch - -Treat 'nsAccountLock: true' the same as 'loginDisabled: true'. Updated from -original version filed as RT#5891. ---- - src/aclocal.m4 | 9 +++++++++ - src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c | 17 +++++++++++++++++ - .../kdb/ldap/libkdb_ldap/ldap_principal.c | 3 +++ - 3 files changed, 29 insertions(+) - -diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index db18226ed..518b1a547 100644 ---- a/src/aclocal.m4 -+++ b/src/aclocal.m4 -@@ -1678,6 +1678,15 @@ if test "$with_ldap" = yes; then - AC_MSG_NOTICE(enabling OpenLDAP database backend module support) - OPENLDAP_PLUGIN=yes - fi -+AC_ARG_WITH([dirsrv-account-locking], -+[ --with-dirsrv-account-locking compile 389/Red Hat/Fedora/Netscape Directory Server database backend module], -+[case "$withval" in -+ yes | no) ;; -+ *) AC_MSG_ERROR(Invalid option value --with-dirsrv-account-locking="$withval") ;; -+esac], with_dirsrv_account_locking=no) -+if test $with_dirsrv_account_locking = yes; then -+ AC_DEFINE(HAVE_DIRSRV_ACCOUNT_LOCKING,1,[Define if LDAP KDB interface should heed 389 DS's nsAccountLock attribute.]) -+fi - ])dnl - dnl - dnl If libkeyutils exists (on Linux) include it and use keyring ccache -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c -index 5b9d1e9fa..4e7270065 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c -@@ -1652,6 +1652,23 @@ populate_krb5_db_entry(krb5_context context, krb5_ldap_context *ldap_context, - ret = krb5_dbe_update_tl_data(context, entry, &userinfo_tl_data); - if (ret) - goto cleanup; -+#ifdef HAVE_DIRSRV_ACCOUNT_LOCKING -+ { -+ krb5_timestamp expiretime=0; -+ char *is_login_disabled=NULL; -+ -+ /* LOGIN DISABLED */ -+ ret = krb5_ldap_get_string(ld, ent, "nsAccountLock", &is_login_disabled, -+ &attr_present); -+ if (ret) -+ goto cleanup; -+ if (attr_present == TRUE) { -+ if (strcasecmp(is_login_disabled, "TRUE")== 0) -+ entry->attributes |= KRB5_KDB_DISALLOW_ALL_TIX; -+ free (is_login_disabled); -+ } -+ } -+#endif - - ret = krb5_read_tkt_policy(context, ldap_context, entry, tktpolname); - if (ret) -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c -index d722dbfa6..5e8e9a897 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c -@@ -54,6 +54,9 @@ char *principal_attributes[] = { "krbprincipalname", - "krbLastFailedAuth", - "krbLoginFailedCount", - "krbLastSuccessfulAuth", -+#ifdef HAVE_DIRSRV_ACCOUNT_LOCKING -+ "nsAccountLock", -+#endif - "krbLastPwdChange", - "krbLastAdminUnlock", - "krbPrincipalAuthInd", diff --git a/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch b/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch index 8acdf1b..37adcee 100644 --- a/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch +++ b/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch @@ -1,4 +1,4 @@ -From 853a9aacfbc842037b30607bacb5c60f5918cccb Mon Sep 17 00:00:00 2001 +From 3cd7636a824638f880e7512fa1f547ec379b8499 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] krb5-1.17post2 FIPS with PRNG, SPAKE, and RADIUS diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index 6723eb4..cbe852c 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -1,4 +1,4 @@ -From 454b35ce48bb8de491cad93c8944c783d1c47fd1 Mon Sep 17 00:00:00 2001 +From 371770fc1d545414838685bcd2542450dfb0e097 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] krb5-1.9-debuginfo.patch diff --git a/krb5.spec b/krb5.spec index f679038..ee5b5d6 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 23%{?dist} +Release: 24%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -54,7 +54,6 @@ Patch27: krb5-1.17-beta1-selinux-label.patch Patch28: krb5-1.12-ksu-path.patch Patch30: krb5-1.15-beta1-buildconf.patch Patch31: krb5-1.3.1-dns.patch -Patch33: krb5-1.13-dirsrv-accountlock.patch Patch34: krb5-1.9-debuginfo.patch Patch35: krb5-1.11-run_user_0.patch Patch36: krb5-1.11-kpasswdtest.patch @@ -97,6 +96,8 @@ Patch129: Remove-dead-variable-def_kslist-from-two-files.patch Patch130: Mark-the-doc-kadm5-tex-files-as-historic.patch Patch131: Modernize-example-enctypes-in-documentation.patch Patch132: Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch +Patch133: Update-default-krb5kdc-mkey-manual-entry-enctype.patch +Patch134: Support-389ds-s-lockout-model.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -706,6 +707,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue May 21 2019 Robbie Harwood - 1.17-24 +- Update default krb5kdc mkey manual-entry enctype +- Also update account lockout patch to upstream version + * Mon May 20 2019 Robbie Harwood - 1.17-23 - Test & docs fixes in preparation for DES removal From f50ceacadfdae3f61c560c119368227d4cac7674 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 22 May 2019 10:59:16 -0400 Subject: [PATCH 110/304] Add missing newlines to deprecation warnings Switch to upstream's ksu path patch --- ...nonicalize_hostname-fallback-support.patch | 2 +- ...on-and-enctype-flag-for-deprecations.patch | 2 +- ...ing-newlines-to-deprecation-warnings.patch | 37 +++++++++++++++++++ Add-tests-for-KCM-ccache-type.patch | 2 +- Address-some-optimized-out-memset-calls.patch | 2 +- ...-alignment-warnings-in-openssl-rc4.c.patch | 2 +- ...llocating-a-register-in-zap-assembly.patch | 2 +- ...ore-errors-in-OpenSSL-crypto-backend.patch | 2 +- ...er-comment-for-krb5_cc_start_seq_get.patch | 2 +- ...able-flag-instead-of-denying-request.patch | 2 +- ...alm-change-logic-in-FILE-remove_cred.patch | 2 +- ...emory-leak-in-none-replay-cache-type.patch | 2 +- Fix-potential-close-1-in-cc_file.c.patch | 2 +- Fix-some-return-code-handling-bugs.patch | 2 +- ...5_cc_remove_cred-for-remaining-types.patch | 2 +- ...messages-from-kadmin-change_password.patch | 2 +- ...ebug-log-proper-ticket-enctype-names.patch | 2 +- ...ec-always-log-non-permitted-enctypes.patch | 2 +- ...ize-some-data-structure-magic-fields.patch | 2 +- ...ype-names-in-KDC-logs-human-readable.patch | 2 +- Mark-deprecated-enctypes-when-used.patch | 2 +- ...-the-doc-kadm5-tex-files-as-historic.patch | 2 +- ...ze-example-enctypes-in-documentation.patch | 2 +- ...exit-path-in-gss_krb5int_copy_ccache.patch | 2 +- Properly-size-ifdef-in-k5_cccol_lock.patch | 2 +- ...beros-v4-support-vestiges-from-ccapi.patch | 2 +- ...api-related-comments-in-configure.ac.patch | 2 +- Remove-checksum-type-profile-variables.patch | 2 +- Remove-confvalidator-utility.patch | 2 +- ...d-variable-def_kslist-from-two-files.patch | 2 +- ...ygen-generated-HTML-output-for-ccapi.patch | 2 +- ...admin-RPC-support-for-setting-v4-key.patch | 2 +- Remove-more-dead-code.patch | 2 +- ...ovsec_adm_export-dump-format-support.patch | 2 +- Remove-srvtab-support.patch | 2 +- ...t-a-more-modern-default-ksu-CMD_PATH.patch | 10 +++-- Simplify-SAM-2-as_key-handling.patch | 2 +- Simply-OpenSSL-PKCS7-decryption-code.patch | 2 +- Support-389ds-s-lockout-model.patch | 2 +- ....1-SAM-tests-to-use-a-modern-enctype.patch | 2 +- ...lt-krb5kdc-mkey-manual-entry-enctype.patch | 2 +- Use-secure_getenv-where-appropriate.patch | 2 +- krb5-1.11-kpasswdtest.patch | 2 +- krb5-1.11-run_user_0.patch | 2 +- krb5-1.15-beta1-buildconf.patch | 2 +- ...ost2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch | 2 +- krb5-1.3.1-dns.patch | 2 +- krb5-1.9-debuginfo.patch | 2 +- krb5.spec | 9 ++++- 49 files changed, 97 insertions(+), 51 deletions(-) create mode 100644 Add-missing-newlines-to-deprecation-warnings.patch rename krb5-1.12-ksu-path.patch => Set-a-more-modern-default-ksu-CMD_PATH.patch (66%) diff --git a/Add-dns_canonicalize_hostname-fallback-support.patch b/Add-dns_canonicalize_hostname-fallback-support.patch index 6e4c8c0..caa8c58 100644 --- a/Add-dns_canonicalize_hostname-fallback-support.patch +++ b/Add-dns_canonicalize_hostname-fallback-support.patch @@ -1,4 +1,4 @@ -From 8ec4a9ab41c73e7955ed7929a3d2a19592811596 Mon Sep 17 00:00:00 2001 +From 1723d5cf07693d8fb249956ee73ca9f4436f95da Mon Sep 17 00:00:00 2001 From: Simo Sorce Date: Tue, 4 Dec 2018 15:22:55 -0500 Subject: [PATCH] Add dns_canonicalize_hostname=fallback support diff --git a/Add-function-and-enctype-flag-for-deprecations.patch b/Add-function-and-enctype-flag-for-deprecations.patch index b511554..f268fcf 100644 --- a/Add-function-and-enctype-flag-for-deprecations.patch +++ b/Add-function-and-enctype-flag-for-deprecations.patch @@ -1,4 +1,4 @@ -From 8491894d2bad21026d73b999814baffe8a695fb7 Mon Sep 17 00:00:00 2001 +From 5817cf4b254ab7f266d74ba30ca2a0ffa26e803e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 16:16:57 -0500 Subject: [PATCH] Add function and enctype flag for deprecations diff --git a/Add-missing-newlines-to-deprecation-warnings.patch b/Add-missing-newlines-to-deprecation-warnings.patch new file mode 100644 index 0000000..a62701f --- /dev/null +++ b/Add-missing-newlines-to-deprecation-warnings.patch @@ -0,0 +1,37 @@ +From d60851da93427e05793d52825ebc49448ae365b2 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 21 May 2019 12:52:26 -0400 +Subject: [PATCH] Add missing newlines to deprecation warnings + +Commit 8d8e68283b599e680f9fe45eff8af397e827bd6c omitted newlines in +two warning messages sent to stderr. Add them now. + +ticket: 8773 +(cherry picked from commit 274fee295d1429668b31c6ed898fc5d11a7e3589) +--- + src/kdc/main.c | 5 +++-- + 1 file changed, 3 insertions(+), 2 deletions(-) + +diff --git a/src/kdc/main.c b/src/kdc/main.c +index 04393772f..1596c1c5b 100644 +--- a/src/kdc/main.c ++++ b/src/kdc/main.c +@@ -223,7 +223,8 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm, + if (krb5_enctype_to_name(def_enctype, FALSE, ename, sizeof(ename))) + ename[0] = '\0'; + fprintf(stderr, +- _("Requested master password enctype %s in %s is DEPRECATED!"), ++ _("Requested master password enctype %s in %s is " ++ "DEPRECATED!\n"), + ename, realm); + } + +@@ -385,7 +386,7 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm, + if (krb5_enctype_to_name(rdp->realm_mkey.enctype, FALSE, ename, + sizeof(ename))) + ename[0] = '\0'; +- fprintf(stderr, _("Stash file %s uses DEPRECATED enctype %s!"), ++ fprintf(stderr, _("Stash file %s uses DEPRECATED enctype %s!\n"), + rdp->realm_stash, ename); + } + diff --git a/Add-tests-for-KCM-ccache-type.patch b/Add-tests-for-KCM-ccache-type.patch index ca70e00..1397480 100644 --- a/Add-tests-for-KCM-ccache-type.patch +++ b/Add-tests-for-KCM-ccache-type.patch @@ -1,4 +1,4 @@ -From 01dcc90e901491196a7ce5da893eec0b699c28b5 Mon Sep 17 00:00:00 2001 +From ae2475679b7b0e9381eac5d134c06cfc559d7d1b Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Nov 2018 00:27:35 -0500 Subject: [PATCH] Add tests for KCM ccache type diff --git a/Address-some-optimized-out-memset-calls.patch b/Address-some-optimized-out-memset-calls.patch index aa28531..5a5880d 100644 --- a/Address-some-optimized-out-memset-calls.patch +++ b/Address-some-optimized-out-memset-calls.patch @@ -1,4 +1,4 @@ -From ef4610f2ca0337bf5522dca3dc6800f795cc6a82 Mon Sep 17 00:00:00 2001 +From b54bce8e7b54c8700467fefcc74623fa50234046 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 30 Dec 2018 16:40:28 -0500 Subject: [PATCH] Address some optimized-out memset() calls diff --git a/Avoid-alignment-warnings-in-openssl-rc4.c.patch b/Avoid-alignment-warnings-in-openssl-rc4.c.patch index 5fee63b..7aa9e28 100644 --- a/Avoid-alignment-warnings-in-openssl-rc4.c.patch +++ b/Avoid-alignment-warnings-in-openssl-rc4.c.patch @@ -1,4 +1,4 @@ -From cf0981bf39558c6501fe1dd2386231ac5f430918 Mon Sep 17 00:00:00 2001 +From c39a5710d0e4039a4f2bbd53ec284eb89d3b83c4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 15:14:49 -0400 Subject: [PATCH] Avoid alignment warnings in openssl rc4.c diff --git a/Avoid-allocating-a-register-in-zap-assembly.patch b/Avoid-allocating-a-register-in-zap-assembly.patch index c8c8589..20d1fac 100644 --- a/Avoid-allocating-a-register-in-zap-assembly.patch +++ b/Avoid-allocating-a-register-in-zap-assembly.patch @@ -1,4 +1,4 @@ -From f516db322b1469a13e59e1c2847e62cb265ce92c Mon Sep 17 00:00:00 2001 +From 7491d9ed5c358960c6344c2581db9cafaf308f06 Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Thu, 3 Jan 2019 17:19:32 +0100 Subject: [PATCH] Avoid allocating a register in zap() assembly diff --git a/Check-more-errors-in-OpenSSL-crypto-backend.patch b/Check-more-errors-in-OpenSSL-crypto-backend.patch index 707c05d..4143944 100644 --- a/Check-more-errors-in-OpenSSL-crypto-backend.patch +++ b/Check-more-errors-in-OpenSSL-crypto-backend.patch @@ -1,4 +1,4 @@ -From f001aa86071aabc398b0d7c38033c26b21fe85f2 Mon Sep 17 00:00:00 2001 +From 842524798c7f69edcef3f01cae7a9a6f126ed1dc Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 22 Apr 2019 14:26:42 -0400 Subject: [PATCH] Check more errors in OpenSSL crypto backend diff --git a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch index 82995e6..6bfc18f 100644 --- a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch +++ b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch @@ -1,4 +1,4 @@ -From 8f22ca7ddc9765e3d7a1de867164d307f8662cb3 Mon Sep 17 00:00:00 2001 +From 2f50c282127bf8d4c570986c212fbc1e910fb8c5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Apr 2019 14:18:57 -0400 Subject: [PATCH] Clarify header comment for krb5_cc_start_seq_get() diff --git a/Clear-forwardable-flag-instead-of-denying-request.patch b/Clear-forwardable-flag-instead-of-denying-request.patch index ff7e090..7105d6c 100644 --- a/Clear-forwardable-flag-instead-of-denying-request.patch +++ b/Clear-forwardable-flag-instead-of-denying-request.patch @@ -1,4 +1,4 @@ -From ab1435ed0654df9991bddb29971c913ef1f957be Mon Sep 17 00:00:00 2001 +From 6bd9bc03f2ad2aa5415d738c28180def7e17874f Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 15 Nov 2018 13:40:43 -0500 Subject: [PATCH] Clear forwardable flag instead of denying request diff --git a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch index ac58f37..28dfd3c 100644 --- a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch +++ b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch @@ -1,4 +1,4 @@ -From 2f5531f3cffb497902241e4932db20617f4d30eb Mon Sep 17 00:00:00 2001 +From 7ed0d71eb3eef640e57f3c55f8aeac636cce3110 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 16 Apr 2019 10:47:35 -0400 Subject: [PATCH] Fix config realm change logic in FILE remove_cred diff --git a/Fix-memory-leak-in-none-replay-cache-type.patch b/Fix-memory-leak-in-none-replay-cache-type.patch index bb51241..03b5f59 100644 --- a/Fix-memory-leak-in-none-replay-cache-type.patch +++ b/Fix-memory-leak-in-none-replay-cache-type.patch @@ -1,4 +1,4 @@ -From 75b39bfb256b639cf6ca491568fd6ef667b19d46 Mon Sep 17 00:00:00 2001 +From e215c213a068d96599a3069339bfb3e4024ef61b Mon Sep 17 00:00:00 2001 From: Corene Casper Date: Sat, 16 Feb 2019 00:49:26 -0500 Subject: [PATCH] Fix memory leak in 'none' replay cache type diff --git a/Fix-potential-close-1-in-cc_file.c.patch b/Fix-potential-close-1-in-cc_file.c.patch index 5b504f2..598dc72 100644 --- a/Fix-potential-close-1-in-cc_file.c.patch +++ b/Fix-potential-close-1-in-cc_file.c.patch @@ -1,4 +1,4 @@ -From 4faa872c4fc674b791a1c05652833ff40dac7889 Mon Sep 17 00:00:00 2001 +From 013037d7c4f6073d28ea2b0bd53eca04bae170ea Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 18 Apr 2019 13:39:37 -0400 Subject: [PATCH] Fix potential close(-1) in cc_file.c diff --git a/Fix-some-return-code-handling-bugs.patch b/Fix-some-return-code-handling-bugs.patch index 7b151c7..5b62208 100644 --- a/Fix-some-return-code-handling-bugs.patch +++ b/Fix-some-return-code-handling-bugs.patch @@ -1,4 +1,4 @@ -From b7bbc88f5ebc6000a8dec95e7f0ff92bbeb54ad4 Mon Sep 17 00:00:00 2001 +From 6f0b53aea2dfcccf1efe0c1c6142eeeaf998f2bb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 14:05:38 -0400 Subject: [PATCH] Fix some return code handling bugs diff --git a/Implement-krb5_cc_remove_cred-for-remaining-types.patch b/Implement-krb5_cc_remove_cred-for-remaining-types.patch index 9594ed0..b24aa05 100644 --- a/Implement-krb5_cc_remove_cred-for-remaining-types.patch +++ b/Implement-krb5_cc_remove_cred-for-remaining-types.patch @@ -1,4 +1,4 @@ -From 7d3da40bd7f44f2d6960b5a9245a1d773c4ee1a0 Mon Sep 17 00:00:00 2001 +From ebc913ea73bfc439f293831f19db83ec83622d51 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 1 Apr 2019 14:28:48 -0400 Subject: [PATCH] Implement krb5_cc_remove_cred for remaining types diff --git a/Improve-error-messages-from-kadmin-change_password.patch b/Improve-error-messages-from-kadmin-change_password.patch index 6ecb07a..a656099 100644 --- a/Improve-error-messages-from-kadmin-change_password.patch +++ b/Improve-error-messages-from-kadmin-change_password.patch @@ -1,4 +1,4 @@ -From ae3053282d879cdbb803c0ff1d6deef8940eeb2a Mon Sep 17 00:00:00 2001 +From f9123277a5b4e27d5fea3dbae0889dcb527115fc Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 13:13:16 -0400 Subject: [PATCH] Improve error messages from kadmin change_password diff --git a/In-kpropd-debug-log-proper-ticket-enctype-names.patch b/In-kpropd-debug-log-proper-ticket-enctype-names.patch index e1b19e3..d7a9e67 100644 --- a/In-kpropd-debug-log-proper-ticket-enctype-names.patch +++ b/In-kpropd-debug-log-proper-ticket-enctype-names.patch @@ -1,4 +1,4 @@ -From 71cbe768d29bbe35cff9c37959f3e5352569af39 Mon Sep 17 00:00:00 2001 +From 0e1c9fa82ea2a5f32a6ce937ffe9b1aef21e133e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 13:41:16 -0500 Subject: [PATCH] In kpropd, debug-log proper ticket enctype names diff --git a/In-rd_req_dec-always-log-non-permitted-enctypes.patch b/In-rd_req_dec-always-log-non-permitted-enctypes.patch index a2a4c53..ce45dec 100644 --- a/In-rd_req_dec-always-log-non-permitted-enctypes.patch +++ b/In-rd_req_dec-always-log-non-permitted-enctypes.patch @@ -1,4 +1,4 @@ -From 4c59f0f53a698c9c4242791e8d620d50a394d5c6 Mon Sep 17 00:00:00 2001 +From 92e46dabccaf7dfecfcb85bb87b773b734724ccb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Jan 2019 17:14:42 -0500 Subject: [PATCH] In rd_req_dec, always log non-permitted enctypes diff --git a/Initialize-some-data-structure-magic-fields.patch b/Initialize-some-data-structure-magic-fields.patch index e418b9f..09f846c 100644 --- a/Initialize-some-data-structure-magic-fields.patch +++ b/Initialize-some-data-structure-magic-fields.patch @@ -1,4 +1,4 @@ -From 37b73dd837a05c14d422379b686b8a10de0083fa Mon Sep 17 00:00:00 2001 +From 0f05d25ddecba6d8dd5de5c1b2e31f45942b9a85 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 13:36:38 -0400 Subject: [PATCH] Initialize some data structure magic fields diff --git a/Make-etype-names-in-KDC-logs-human-readable.patch b/Make-etype-names-in-KDC-logs-human-readable.patch index ba85392..b6b57c9 100644 --- a/Make-etype-names-in-KDC-logs-human-readable.patch +++ b/Make-etype-names-in-KDC-logs-human-readable.patch @@ -1,4 +1,4 @@ -From e05c448510fc20946fb6d777bd7e3841dd986e75 Mon Sep 17 00:00:00 2001 +From c955111643b4ef9a005a083d8f2aa39ec4af81ec Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 8 Jan 2019 17:42:35 -0500 Subject: [PATCH] Make etype names in KDC logs human-readable diff --git a/Mark-deprecated-enctypes-when-used.patch b/Mark-deprecated-enctypes-when-used.patch index 8d9f327..a5f93ca 100644 --- a/Mark-deprecated-enctypes-when-used.patch +++ b/Mark-deprecated-enctypes-when-used.patch @@ -1,4 +1,4 @@ -From 7acee539da508c10aabbc8483243da6c6ba37892 Mon Sep 17 00:00:00 2001 +From 945c21ddafbedfe57dfbf9ca3e7b0185cb4b7175 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 10 Jan 2019 16:34:54 -0500 Subject: [PATCH] Mark deprecated enctypes when used diff --git a/Mark-the-doc-kadm5-tex-files-as-historic.patch b/Mark-the-doc-kadm5-tex-files-as-historic.patch index abf1f4a..bd068d5 100644 --- a/Mark-the-doc-kadm5-tex-files-as-historic.patch +++ b/Mark-the-doc-kadm5-tex-files-as-historic.patch @@ -1,4 +1,4 @@ -From 28a605c2411c3def3e5eaa19be5326777e959a1a Mon Sep 17 00:00:00 2001 +From 1b138c349fa167f713572c8a37bc6fa39280396c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 11 Apr 2019 18:33:04 -0400 Subject: [PATCH] Mark the doc/kadm5 tex files as historic diff --git a/Modernize-example-enctypes-in-documentation.patch b/Modernize-example-enctypes-in-documentation.patch index 428ac2b..0f14e5d 100644 --- a/Modernize-example-enctypes-in-documentation.patch +++ b/Modernize-example-enctypes-in-documentation.patch @@ -1,4 +1,4 @@ -From cef9a57dc094bb2ca57d5b765981fbb2ab93adde Mon Sep 17 00:00:00 2001 +From c60e5d66e2aaa9123a333c4f7d5a44fdc735ec66 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 11 Apr 2019 18:25:41 -0400 Subject: [PATCH] Modernize example enctypes in documentation diff --git a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch index ff1d987..83c6526 100644 --- a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch +++ b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch @@ -1,4 +1,4 @@ -From 894bcbfcf27c9bc1117bb624f27123eb25fcd7bf Mon Sep 17 00:00:00 2001 +From b3ccfda0de6a9dd1248d9b15f31819421e36848e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 14:32:33 -0400 Subject: [PATCH] Modernize exit path in gss_krb5int_copy_ccache() diff --git a/Properly-size-ifdef-in-k5_cccol_lock.patch b/Properly-size-ifdef-in-k5_cccol_lock.patch index d7af9bf..ede89ef 100644 --- a/Properly-size-ifdef-in-k5_cccol_lock.patch +++ b/Properly-size-ifdef-in-k5_cccol_lock.patch @@ -1,4 +1,4 @@ -From 6f9bd0a292f1b84e16cab8c89efee87359b007d2 Mon Sep 17 00:00:00 2001 +From 4b087e84f6c399df56143eca50858c185d31633f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Feb 2019 11:50:35 -0500 Subject: [PATCH] Properly size #ifdef in k5_cccol_lock() diff --git a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch index b00a745..47b013f 100644 --- a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch +++ b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch @@ -1,4 +1,4 @@ -From ff011e05cfb28b408778f4ace22a745f19c0bdd2 Mon Sep 17 00:00:00 2001 +From 275df1b1b846a66c966a8108ba3b4d148f68ef6f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 14:37:38 -0400 Subject: [PATCH] Remove Kerberos v4 support vestiges from ccapi diff --git a/Remove-ccapi-related-comments-in-configure.ac.patch b/Remove-ccapi-related-comments-in-configure.ac.patch index 0fb5d50..8770cb8 100644 --- a/Remove-ccapi-related-comments-in-configure.ac.patch +++ b/Remove-ccapi-related-comments-in-configure.ac.patch @@ -1,4 +1,4 @@ -From 7f015c7ed945d1d51ffd0ba1dd5b89c150eacf83 Mon Sep 17 00:00:00 2001 +From 68fdf968da2ed338340a835a0c942991c7c02986 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Apr 2019 16:01:22 -0400 Subject: [PATCH] Remove ccapi-related comments in configure.ac diff --git a/Remove-checksum-type-profile-variables.patch b/Remove-checksum-type-profile-variables.patch index eebabea..62f04c8 100644 --- a/Remove-checksum-type-profile-variables.patch +++ b/Remove-checksum-type-profile-variables.patch @@ -1,4 +1,4 @@ -From a642ac26ca00d4cfaae84398372035b0c1e444ed Mon Sep 17 00:00:00 2001 +From 69bd1ba5a7002856778cf1d46082423ef89a0c0c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 13 May 2019 14:19:57 -0400 Subject: [PATCH] Remove checksum type profile variables diff --git a/Remove-confvalidator-utility.patch b/Remove-confvalidator-utility.patch index 302df29..e361ef6 100644 --- a/Remove-confvalidator-utility.patch +++ b/Remove-confvalidator-utility.patch @@ -1,4 +1,4 @@ -From ecab56bca80824913e98a5b25f34a5ebe483990d Mon Sep 17 00:00:00 2001 +From f7b50b3e40ae43666fb10b0a1502f9cd88b6a2fe Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Apr 2019 14:58:19 -0400 Subject: [PATCH] Remove confvalidator utility diff --git a/Remove-dead-variable-def_kslist-from-two-files.patch b/Remove-dead-variable-def_kslist-from-two-files.patch index 9fd92c9..b6bb3d9 100644 --- a/Remove-dead-variable-def_kslist-from-two-files.patch +++ b/Remove-dead-variable-def_kslist-from-two-files.patch @@ -1,4 +1,4 @@ -From 85416629f6d120bf272d9aaa9c661b8a849c40b3 Mon Sep 17 00:00:00 2001 +From 5a009bddbec41c5811db9f7d0583fa4e4b726ee9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 16:57:51 -0400 Subject: [PATCH] Remove dead variable def_kslist from two files diff --git a/Remove-doxygen-generated-HTML-output-for-ccapi.patch b/Remove-doxygen-generated-HTML-output-for-ccapi.patch index 48b515a..0cb10b6 100644 --- a/Remove-doxygen-generated-HTML-output-for-ccapi.patch +++ b/Remove-doxygen-generated-HTML-output-for-ccapi.patch @@ -1,4 +1,4 @@ -From cf25d152b2b1f54bbd92e235a30de20e154f3e7a Mon Sep 17 00:00:00 2001 +From 8629596d91d41914a6996b897845f601af7b59fc Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 14:15:58 -0400 Subject: [PATCH] Remove doxygen-generated HTML output for ccapi diff --git a/Remove-kadmin-RPC-support-for-setting-v4-key.patch b/Remove-kadmin-RPC-support-for-setting-v4-key.patch index 9b2ea36..28fc9e4 100644 --- a/Remove-kadmin-RPC-support-for-setting-v4-key.patch +++ b/Remove-kadmin-RPC-support-for-setting-v4-key.patch @@ -1,4 +1,4 @@ -From 12e48c208c042f219d5cb8fb984094c5c958c99b Mon Sep 17 00:00:00 2001 +From 43c7d037b5e6bac3345c069af70f3cd6fd947f3f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 16:14:46 -0400 Subject: [PATCH] Remove kadmin RPC support for setting v4 key diff --git a/Remove-more-dead-code.patch b/Remove-more-dead-code.patch index ef9a747..2d547cb 100644 --- a/Remove-more-dead-code.patch +++ b/Remove-more-dead-code.patch @@ -1,4 +1,4 @@ -From 98e6b0ada15075ea017fe8086f21b95fc2280fcd Mon Sep 17 00:00:00 2001 +From 740ab812bedd022ec60e7ef63bf4be12dd730d67 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 9 May 2019 14:07:24 -0400 Subject: [PATCH] Remove more dead code diff --git a/Remove-ovsec_adm_export-dump-format-support.patch b/Remove-ovsec_adm_export-dump-format-support.patch index f4b0510..ebc053c 100644 --- a/Remove-ovsec_adm_export-dump-format-support.patch +++ b/Remove-ovsec_adm_export-dump-format-support.patch @@ -1,4 +1,4 @@ -From 6f9222fb372af6d7988c65cc4ec3cb56f6cc747a Mon Sep 17 00:00:00 2001 +From 5125a9bd20b2fa2b0f420dc20780d08af1cc91a6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 22 Jan 2019 18:34:58 -0500 Subject: [PATCH] Remove ovsec_adm_export dump format support diff --git a/Remove-srvtab-support.patch b/Remove-srvtab-support.patch index 6f2a7ec..dbdf99f 100644 --- a/Remove-srvtab-support.patch +++ b/Remove-srvtab-support.patch @@ -1,4 +1,4 @@ -From 0869d133743446612c512ce9aec5832ce10e282b Mon Sep 17 00:00:00 2001 +From c742a3eacc7b2dc92bf8dc83f5e8ea602dded8c2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 9 Oct 2017 15:58:33 -0400 Subject: [PATCH] Remove srvtab support diff --git a/krb5-1.12-ksu-path.patch b/Set-a-more-modern-default-ksu-CMD_PATH.patch similarity index 66% rename from krb5-1.12-ksu-path.patch rename to Set-a-more-modern-default-ksu-CMD_PATH.patch index 4b990ce..4cf3da5 100644 --- a/krb5-1.12-ksu-path.patch +++ b/Set-a-more-modern-default-ksu-CMD_PATH.patch @@ -1,9 +1,13 @@ -From e62b5022c129229e86f40f97d2e1c71a01d7227b Mon Sep 17 00:00:00 2001 +From 4b11c083e2019ece267cfa5379bd417334e2038e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:32:09 -0400 -Subject: [PATCH] krb5-1.12-ksu-path.patch +Subject: [PATCH] Set a more modern default ksu CMD_PATH -Set the default PATH to the one set by login. +ksu uses CMD_PATH to expand command names in .k5users. Include the /usr +tree and .../sbin variants. Drop nonstandard /local. + +ticket: 8807 (new) +(cherry picked from commit 9eb937a6e1f740d323221813e5da096d30bd68de) --- src/clients/ksu/Makefile.in | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Simplify-SAM-2-as_key-handling.patch b/Simplify-SAM-2-as_key-handling.patch index b9f877b..8929e65 100644 --- a/Simplify-SAM-2-as_key-handling.patch +++ b/Simplify-SAM-2-as_key-handling.patch @@ -1,4 +1,4 @@ -From 48cca5e6134e6137cab7d592dfb31f0a19e4e7ea Mon Sep 17 00:00:00 2001 +From 3b4f517a3a403943877e925ae0eb1745611b996f Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 5 May 2019 18:53:27 -0400 Subject: [PATCH] Simplify SAM-2 as_key handling diff --git a/Simply-OpenSSL-PKCS7-decryption-code.patch b/Simply-OpenSSL-PKCS7-decryption-code.patch index cc40c6e..973480e 100644 --- a/Simply-OpenSSL-PKCS7-decryption-code.patch +++ b/Simply-OpenSSL-PKCS7-decryption-code.patch @@ -1,4 +1,4 @@ -From 0b4433c4ab9653eb298e2b7d959e957d468fd3f9 Mon Sep 17 00:00:00 2001 +From 172390c584726ecd5747b064587acc1db44a98ca Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 13:13:06 -0400 Subject: [PATCH] Simply OpenSSL PKCS7 decryption code diff --git a/Support-389ds-s-lockout-model.patch b/Support-389ds-s-lockout-model.patch index 6bf16fc..3b4c595 100644 --- a/Support-389ds-s-lockout-model.patch +++ b/Support-389ds-s-lockout-model.patch @@ -1,4 +1,4 @@ -From 5673f1c22b602ac4b72e59c84b70ecedf3132c11 Mon Sep 17 00:00:00 2001 +From 49ca1fc11d4e58289b518db7cdd4093b06ca9cf1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:44 -0400 Subject: [PATCH] Support 389ds's lockout model diff --git a/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch b/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch index 526b44c..bd98230 100644 --- a/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch +++ b/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch @@ -1,4 +1,4 @@ -From a7db3ad8e75a865c2de8c522f582129051bbe958 Mon Sep 17 00:00:00 2001 +From f179301f52e0e40eee9ac493bae0e82be49b7c28 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 16 Apr 2019 14:16:39 -0400 Subject: [PATCH] Update ASN.1 SAM tests to use a modern enctype diff --git a/Update-default-krb5kdc-mkey-manual-entry-enctype.patch b/Update-default-krb5kdc-mkey-manual-entry-enctype.patch index d8e85a5..462d774 100644 --- a/Update-default-krb5kdc-mkey-manual-entry-enctype.patch +++ b/Update-default-krb5kdc-mkey-manual-entry-enctype.patch @@ -1,4 +1,4 @@ -From 32d2b3e6dc3ab6aa9bb824701752ccfc23d61c1c Mon Sep 17 00:00:00 2001 +From e2b0a71ca45d6895c9df132560789774993e657d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 20 May 2019 16:52:57 -0400 Subject: [PATCH] Update default krb5kdc mkey manual-entry enctype diff --git a/Use-secure_getenv-where-appropriate.patch b/Use-secure_getenv-where-appropriate.patch index 65d813e..6d92f10 100644 --- a/Use-secure_getenv-where-appropriate.patch +++ b/Use-secure_getenv-where-appropriate.patch @@ -1,4 +1,4 @@ -From 4ed88289e0b3c5a6fcda13078abf211fb8e4f84c Mon Sep 17 00:00:00 2001 +From 13cc24f4e631ee54176430eac73be14bcd9052d3 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 24 Apr 2019 16:19:50 -0400 Subject: [PATCH] Use secure_getenv() where appropriate diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch index 4b4358b..5e29cad 100644 --- a/krb5-1.11-kpasswdtest.patch +++ b/krb5-1.11-kpasswdtest.patch @@ -1,4 +1,4 @@ -From 8e03102127701980c1ace62cbea93e4003a0ef5d Mon Sep 17 00:00:00 2001 +From 37c9242bf19d63c6f35086a931b9a072d5b71caf Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:52:01 -0400 Subject: [PATCH] krb5-1.11-kpasswdtest.patch diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch index c23e0a1..5b9ef9b 100644 --- a/krb5-1.11-run_user_0.patch +++ b/krb5-1.11-run_user_0.patch @@ -1,4 +1,4 @@ -From 44ecf1e570aacff7630334fbf1650e2f33f8675e Mon Sep 17 00:00:00 2001 +From 76a67da3510e761eb01822a6db551fa3092189a3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:57 -0400 Subject: [PATCH] krb5-1.11-run_user_0.patch diff --git a/krb5-1.15-beta1-buildconf.patch b/krb5-1.15-beta1-buildconf.patch index ad1f7e9..ec96987 100644 --- a/krb5-1.15-beta1-buildconf.patch +++ b/krb5-1.15-beta1-buildconf.patch @@ -1,4 +1,4 @@ -From fd8c1f7e68fd999c07ca47243ef85ac726f775ce Mon Sep 17 00:00:00 2001 +From b7ba0fa6a2f8324c58b57dedde33c1ae5d1ddb41 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] krb5-1.15-beta1-buildconf.patch diff --git a/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch b/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch index 37adcee..295bc5d 100644 --- a/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch +++ b/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch @@ -1,4 +1,4 @@ -From 3cd7636a824638f880e7512fa1f547ec379b8499 Mon Sep 17 00:00:00 2001 +From 35dbfaa4a224bbbdd0d75a0383fbe09d7deb389f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] krb5-1.17post2 FIPS with PRNG, SPAKE, and RADIUS diff --git a/krb5-1.3.1-dns.patch b/krb5-1.3.1-dns.patch index 5d87aa1..1cbb6f8 100644 --- a/krb5-1.3.1-dns.patch +++ b/krb5-1.3.1-dns.patch @@ -1,4 +1,4 @@ -From 64c9cb22ec6d7ecdeafaf60bfc8d26780d2cb4ad Mon Sep 17 00:00:00 2001 +From 2cf42007974a9c72e8e6a6cc02295e9c2a89317e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] krb5-1.3.1-dns.patch diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index cbe852c..89f5729 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -1,4 +1,4 @@ -From 371770fc1d545414838685bcd2542450dfb0e097 Mon Sep 17 00:00:00 2001 +From d205539d89b857f7bd2b09dfc875d5cdd79167b7 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] krb5-1.9-debuginfo.patch diff --git a/krb5.spec b/krb5.spec index ee5b5d6..7808495 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 24%{?dist} +Release: 25%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -51,7 +51,6 @@ Source100: noport.c Patch26: krb5-1.12.1-pam.patch Patch27: krb5-1.17-beta1-selinux-label.patch -Patch28: krb5-1.12-ksu-path.patch Patch30: krb5-1.15-beta1-buildconf.patch Patch31: krb5-1.3.1-dns.patch Patch34: krb5-1.9-debuginfo.patch @@ -98,6 +97,8 @@ Patch131: Modernize-example-enctypes-in-documentation.patch Patch132: Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch Patch133: Update-default-krb5kdc-mkey-manual-entry-enctype.patch Patch134: Support-389ds-s-lockout-model.patch +Patch135: Add-missing-newlines-to-deprecation-warnings.patch +Patch136: Set-a-more-modern-default-ksu-CMD_PATH.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -707,6 +708,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed May 22 2019 Robbie Harwood - 1.17-25 +- Add missing newlines to deprecation warnings +- Switch to upstream's ksu path patch + * Tue May 21 2019 Robbie Harwood - 1.17-24 - Update default krb5kdc mkey manual-entry enctype - Also update account lockout patch to upstream version From 3f80a77313f94e3f1bcd0041f222e6a2b81de35a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 28 May 2019 15:22:45 -0400 Subject: [PATCH 111/304] Remove support for single-DES and CRC --- ...ing-newlines-to-deprecation-warnings.patch | 2 +- Display-unsupported-enctype-names.patch | 79 + ...-the-doc-kadm5-tex-files-as-historic.patch | 2 +- ...ze-example-enctypes-in-documentation.patch | 2 +- Remove-checksum-type-profile-variables.patch | 2 +- ...d-variable-def_kslist-from-two-files.patch | 2 +- Remove-support-for-single-DES-and-CRC.patch | 3336 +++++++++++++++++ Remove-the-v4-and-afs3-salt-types.patch | 508 +++ Set-a-more-modern-default-ksu-CMD_PATH.patch | 2 +- Support-389ds-s-lockout-model.patch | 2 +- ....1-SAM-tests-to-use-a-modern-enctype.patch | 2 +- ...lt-krb5kdc-mkey-manual-entry-enctype.patch | 2 +- ...t-suite-to-avoid-single-DES-enctypes.patch | 2328 ++++++++++++ ...ost3-FIPS-with-PRNG-SPAKE-and-RADIUS.patch | 43 +- krb5.spec | 11 +- 15 files changed, 6274 insertions(+), 49 deletions(-) create mode 100644 Display-unsupported-enctype-names.patch create mode 100644 Remove-support-for-single-DES-and-CRC.patch create mode 100644 Remove-the-v4-and-afs3-salt-types.patch create mode 100644 Update-test-suite-to-avoid-single-DES-enctypes.patch rename krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch => krb5-1.17post3-FIPS-with-PRNG-SPAKE-and-RADIUS.patch (93%) diff --git a/Add-missing-newlines-to-deprecation-warnings.patch b/Add-missing-newlines-to-deprecation-warnings.patch index a62701f..173cd61 100644 --- a/Add-missing-newlines-to-deprecation-warnings.patch +++ b/Add-missing-newlines-to-deprecation-warnings.patch @@ -1,4 +1,4 @@ -From d60851da93427e05793d52825ebc49448ae365b2 Mon Sep 17 00:00:00 2001 +From 4928699bdfd051bf0d69afee0b15574c15f40a48 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 21 May 2019 12:52:26 -0400 Subject: [PATCH] Add missing newlines to deprecation warnings diff --git a/Display-unsupported-enctype-names.patch b/Display-unsupported-enctype-names.patch new file mode 100644 index 0000000..af727f7 --- /dev/null +++ b/Display-unsupported-enctype-names.patch @@ -0,0 +1,79 @@ +From 144eea330aba65a140c0e0bf66ad3cfe06f28899 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 21 May 2019 13:34:39 -0400 +Subject: [PATCH] Display unsupported enctype names + +Add a table of unsupported enctype numbers to enctype_util.c and +consult it in krb5_enctype_to_name(). Treat unsupported enctype +numbers as deprecated in krb5int_c_deprecated_enctype(). In kadmin, +display "UNSUPPORTED:" before invalid enctype names. + +ticket: 8808 +(cherry picked from commit ebbc6e8e99ee9d5d757411200a6a3173171774df) +--- + src/kadmin/cli/kadmin.c | 4 +++- + src/lib/crypto/krb/enctype_util.c | 22 +++++++++++++++++++++- + 2 files changed, 24 insertions(+), 2 deletions(-) + +diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c +index fe4cb493c..b4d1aad93 100644 +--- a/src/kadmin/cli/kadmin.c ++++ b/src/kadmin/cli/kadmin.c +@@ -1461,7 +1461,9 @@ kadmin_getprinc(int argc, char *argv[]) + enctype, sizeof(enctype))) + snprintf(enctype, sizeof(enctype), _(""), + key_data->key_data_type[0]); +- if (krb5int_c_deprecated_enctype(key_data->key_data_type[0])) ++ if (!krb5_c_valid_enctype(key_data->key_data_type[0])) ++ deprecated = "UNSUPPORTED:"; ++ else if (krb5int_c_deprecated_enctype(key_data->key_data_type[0])) + deprecated = "DEPRECATED:"; + printf("Key: vno %d, %s%s", key_data->key_data_kvno, deprecated, + enctype); +diff --git a/src/lib/crypto/krb/enctype_util.c b/src/lib/crypto/krb/enctype_util.c +index e394f4e19..1542d4062 100644 +--- a/src/lib/crypto/krb/enctype_util.c ++++ b/src/lib/crypto/krb/enctype_util.c +@@ -36,6 +36,18 @@ + + #include "crypto_int.h" + ++struct { ++ krb5_enctype etype; ++ const char *name; ++} unsupported_etypes[] = { ++ { ENCTYPE_DES_CBC_CRC, "des-cbc-crc" }, ++ { ENCTYPE_DES_CBC_MD4, "des-cbc-md4" }, ++ { ENCTYPE_DES_CBC_MD5, "des-cbc-md5" }, ++ { ENCTYPE_DES_CBC_RAW, "des-cbc-raw" }, ++ { ENCTYPE_DES_HMAC_SHA1, "des-hmac-sha1" }, ++ { ENCTYPE_NULL, NULL } ++}; ++ + krb5_boolean KRB5_CALLCONV + krb5_c_valid_enctype(krb5_enctype etype) + { +@@ -55,7 +67,7 @@ krb5_boolean KRB5_CALLCONV + krb5int_c_deprecated_enctype(krb5_enctype etype) + { + const struct krb5_keytypes *ktp = find_enctype(etype); +- return ktp != NULL && (ktp->flags & ETYPE_DEPRECATED) != 0; ++ return ktp == NULL || (ktp->flags & ETYPE_DEPRECATED) != 0; + } + + krb5_error_code KRB5_CALLCONV +@@ -122,6 +134,14 @@ krb5_enctype_to_name(krb5_enctype enctype, krb5_boolean shortest, + const char *name; + int i; + ++ for (i = 0; unsupported_etypes[i].etype != ENCTYPE_NULL; i++) { ++ if (enctype == unsupported_etypes[i].etype) { ++ if (strlcpy(buffer, unsupported_etypes[i].name, buflen) >= buflen) ++ return ENOMEM; ++ return 0; ++ } ++ } ++ + ktp = find_enctype(enctype); + if (ktp == NULL) + return EINVAL; diff --git a/Mark-the-doc-kadm5-tex-files-as-historic.patch b/Mark-the-doc-kadm5-tex-files-as-historic.patch index bd068d5..1956a98 100644 --- a/Mark-the-doc-kadm5-tex-files-as-historic.patch +++ b/Mark-the-doc-kadm5-tex-files-as-historic.patch @@ -1,4 +1,4 @@ -From 1b138c349fa167f713572c8a37bc6fa39280396c Mon Sep 17 00:00:00 2001 +From b68ee166602b787c5acabe3d1b4780e527d672a7 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 11 Apr 2019 18:33:04 -0400 Subject: [PATCH] Mark the doc/kadm5 tex files as historic diff --git a/Modernize-example-enctypes-in-documentation.patch b/Modernize-example-enctypes-in-documentation.patch index 0f14e5d..a94494e 100644 --- a/Modernize-example-enctypes-in-documentation.patch +++ b/Modernize-example-enctypes-in-documentation.patch @@ -1,4 +1,4 @@ -From c60e5d66e2aaa9123a333c4f7d5a44fdc735ec66 Mon Sep 17 00:00:00 2001 +From eb4fb8cb24e6cac194acc2c507b334658fc5431d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 11 Apr 2019 18:25:41 -0400 Subject: [PATCH] Modernize example enctypes in documentation diff --git a/Remove-checksum-type-profile-variables.patch b/Remove-checksum-type-profile-variables.patch index 62f04c8..a392a60 100644 --- a/Remove-checksum-type-profile-variables.patch +++ b/Remove-checksum-type-profile-variables.patch @@ -1,4 +1,4 @@ -From 69bd1ba5a7002856778cf1d46082423ef89a0c0c Mon Sep 17 00:00:00 2001 +From 46aa5ffd844a280f368d78c7c395bb1b2323dfbe Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 13 May 2019 14:19:57 -0400 Subject: [PATCH] Remove checksum type profile variables diff --git a/Remove-dead-variable-def_kslist-from-two-files.patch b/Remove-dead-variable-def_kslist-from-two-files.patch index b6bb3d9..fa8e263 100644 --- a/Remove-dead-variable-def_kslist-from-two-files.patch +++ b/Remove-dead-variable-def_kslist-from-two-files.patch @@ -1,4 +1,4 @@ -From 5a009bddbec41c5811db9f7d0583fa4e4b726ee9 Mon Sep 17 00:00:00 2001 +From cc4aace493d1caaca9edebcc5d836e847e358afd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 16:57:51 -0400 Subject: [PATCH] Remove dead variable def_kslist from two files diff --git a/Remove-support-for-single-DES-and-CRC.patch b/Remove-support-for-single-DES-and-CRC.patch new file mode 100644 index 0000000..6c7e2e9 --- /dev/null +++ b/Remove-support-for-single-DES-and-CRC.patch @@ -0,0 +1,3336 @@ +From 2cc75213f2227cffeaf60ad0c4ef60b5466b073e Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 24 May 2019 13:12:03 -0400 +Subject: [PATCH] Remove support for single-DES and CRC + +Single-DES removal brings us closer to compliance with RFC 6649. +Single-DES was disabled by default starting in release 1.8, and +user-visible deprecation warnings were issued starting in release +1.17. + +ticket: 8808 +(cherry picked from commit fb2dada5eb89c4cd4e39dedd6dbb7dbd5e94f8b8) +[rharwood@redhat.com: .gitignore removal] +--- + doc/admin/advanced/retiring-des.rst | 5 + + doc/admin/conf_files/kdc_conf.rst | 17 +- + doc/admin/conf_files/krb5_conf.rst | 17 +- + doc/admin/enctypes.rst | 38 +- + doc/appdev/refs/macros/index.rst | 1 + + doc/conf.py | 2 +- + doc/mitK5features.rst | 2 +- + src/include/k5-int.h | 1 - + src/include/krb5/krb5.hin | 10 +- + src/include/win-mac.h | 12 - + src/kdc/kdc_util.c | 14 - + src/kdc/main.c | 6 - + src/kdc/realm_data.h | 1 - + src/lib/crypto/builtin/des/des_int.h | 1 - + .../crypto/builtin/enc_provider/Makefile.in | 3 - + src/lib/crypto/builtin/enc_provider/deps | 12 - + src/lib/crypto/builtin/enc_provider/des.c | 120 --- + .../crypto/builtin/hash_provider/Makefile.in | 7 +- + src/lib/crypto/builtin/hash_provider/deps | 13 - + .../crypto/builtin/hash_provider/hash_crc32.c | 56 -- + src/lib/crypto/krb/Makefile.in | 9 - + src/lib/crypto/krb/cksumtypes.c | 24 - + src/lib/crypto/krb/combine_keys.c | 3 - + src/lib/crypto/krb/crc32.c | 165 ----- + src/lib/crypto/krb/crypto_int.h | 16 - + src/lib/crypto/krb/default_state.c | 4 - + src/lib/crypto/krb/deps | 36 - + src/lib/crypto/krb/enc_old.c | 181 ----- + src/lib/crypto/krb/etypes.c | 46 -- + src/lib/crypto/krb/s2k_des.c | 691 ------------------ + src/lib/crypto/libk5crypto.exports | 1 - + .../crypto/openssl/enc_provider/Makefile.in | 3 - + src/lib/crypto/openssl/enc_provider/deps | 11 - + src/lib/crypto/openssl/enc_provider/des.c | 218 ------ + .../crypto/openssl/hash_provider/Makefile.in | 10 +- + src/lib/crypto/openssl/hash_provider/deps | 12 - + .../crypto/openssl/hash_provider/hash_crc32.c | 56 -- + src/lib/gssapi/krb5/accept_sec_context.c | 3 - + src/lib/gssapi/krb5/gssapiP_krb5.h | 20 +- + src/lib/gssapi/krb5/k5seal.c | 28 +- + src/lib/gssapi/krb5/k5sealiov.c | 20 - + src/lib/gssapi/krb5/k5unseal.c | 112 --- + src/lib/gssapi/krb5/k5unsealiov.c | 34 +- + src/lib/gssapi/krb5/util_crypt.c | 41 -- + src/lib/kadm5/kadm_rpc_xdr.c | 10 - + src/lib/krb5/ccache/cc_mslsa.c | 11 +- + src/lib/krb5/krb/auth_con.c | 23 +- + src/lib/krb5/krb/gic_keytab.c | 4 - + src/lib/krb5/krb/init_ctx.c | 9 - + src/lib/krb5/krb/mk_req_ext.c | 43 +- + src/lib/krb5/krb/s4u_creds.c | 3 - + src/lib/krb5/krb/ser_ctx.c | 2 +- + src/man/kdc.conf.man | 47 +- + src/man/krb5.conf.man | 6 +- + .../leash/htmlhelp/html/Encryption_Types.htm | 14 +- + 55 files changed, 74 insertions(+), 2180 deletions(-) + delete mode 100644 src/lib/crypto/builtin/enc_provider/des.c + delete mode 100644 src/lib/crypto/builtin/hash_provider/hash_crc32.c + delete mode 100644 src/lib/crypto/krb/crc32.c + delete mode 100644 src/lib/crypto/krb/enc_old.c + delete mode 100644 src/lib/crypto/krb/s2k_des.c + delete mode 100644 src/lib/crypto/openssl/enc_provider/des.c + delete mode 100644 src/lib/crypto/openssl/hash_provider/hash_crc32.c + +diff --git a/doc/admin/advanced/retiring-des.rst b/doc/admin/advanced/retiring-des.rst +index ebac95f24..4a964c15c 100644 +--- a/doc/admin/advanced/retiring-des.rst ++++ b/doc/admin/advanced/retiring-des.rst +@@ -22,6 +22,11 @@ However, deployments of krb5 using Kerberos databases created with older + versions of krb5 will not necessarily start using strong crypto for + ordinary operation without administrator intervention. + ++MIT krb5 began flagging deprecated encryption types with release 1.17, ++and removed DES (single-DES) support in release 1.18. As a ++consequence, a release prior to 1.18 is required to perform these ++migrations. ++ + Types of keys + ------------- + +diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst +index 62d1bfc05..2c6ea1855 100644 +--- a/doc/admin/conf_files/kdc_conf.rst ++++ b/doc/admin/conf_files/kdc_conf.rst +@@ -381,13 +381,6 @@ The following tags may be specified in a [realms] subsection: + listed in **host_based_services**. ``no_host_referral = *`` will + disable referral processing altogether. + +-**des_crc_session_supported** +- (Boolean value). If set to true, the KDC will assume that service +- principals support des-cbc-crc for session key enctype negotiation +- purposes. If **allow_weak_crypto** in :ref:`libdefaults` is +- false, or if des-cbc-crc is not a permitted enctype, then this +- variable has no effect. Defaults to true. New in release 1.11. +- + **reject_bad_transit** + (Boolean value.) If set to true, the KDC will check the list of + transited realms for cross-realm tickets against the transit path +@@ -848,13 +841,8 @@ Encryption types marked as "weak" are available for compatibility but + not recommended for use. + + ==================================================== ========================================================= +-des-cbc-crc DES cbc mode with CRC-32 (weak) +-des-cbc-md4 DES cbc mode with RSA-MD4 (weak) +-des-cbc-md5 DES cbc mode with RSA-MD5 (weak) +-des-cbc-raw DES cbc mode raw (weak) + des3-cbc-raw Triple DES cbc mode raw (weak) + des3-cbc-sha1 des3-hmac-sha1 des3-cbc-sha1-kd Triple DES cbc mode with HMAC/sha1 +-des-hmac-sha1 DES with HMAC/sha1 (weak) + aes256-cts-hmac-sha1-96 aes256-cts aes256-sha1 AES-256 CTS mode with 96-bit SHA-1 HMAC + aes128-cts-hmac-sha1-96 aes128-cts aes128-sha1 AES-128 CTS mode with 96-bit SHA-1 HMAC + aes256-cts-hmac-sha384-192 aes256-sha2 AES-256 CTS mode with 192-bit SHA-384 HMAC +@@ -863,7 +851,6 @@ arcfour-hmac rc4-hmac arcfour-hmac-md5 RC4 with HMAC/MD5 + arcfour-hmac-exp rc4-hmac-exp arcfour-hmac-md5-exp Exportable RC4 with HMAC/MD5 (weak) + camellia256-cts-cmac camellia256-cts Camellia-256 CTS mode with CMAC + camellia128-cts-cmac camellia128-cts Camellia-128 CTS mode with CMAC +-des The DES family: des-cbc-crc, des-cbc-md5, and des-cbc-md4 (weak) + des3 The triple DES family: des3-cbc-sha1 + aes The AES family: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, aes256-cts-hmac-sha384-192, and aes128-cts-hmac-sha256-128 + rc4 The RC4 family: arcfour-hmac +@@ -875,8 +862,8 @@ types for the variable in question. Types or families can be removed + from the current list by prefixing them with a minus sign ("-"). + Types or families can be prefixed with a plus sign ("+") for symmetry; + it has the same meaning as just listing the type or family. For +-example, "``DEFAULT -des``" would be the default set of encryption +-types with DES types removed, and "``des3 DEFAULT``" would be the ++example, "``DEFAULT -rc4``" would be the default set of encryption ++types with RC4 types removed, and "``des3 DEFAULT``" would be the + default set of encryption types with triple DES types moved to the + front. + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index 5df3bfe36..89f02434b 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -106,10 +106,7 @@ The libdefaults section may contain any of the following relations: + in :ref:`Encryption_types` in :ref:`kdc.conf(5)`) will be filtered + out of the lists **default_tgs_enctypes**, + **default_tkt_enctypes**, and **permitted_enctypes**. The default +- value for this tag is false, which may cause authentication +- failures in existing Kerberos infrastructures that do not support +- strong crypto. Users in affected environments should set this tag +- to true until their infrastructure adopts stronger ciphers. ++ value for this tag is false. + + **canonicalize** + If this flag is set to true, initial ticket requests to the KDC +@@ -163,9 +160,7 @@ The libdefaults section may contain any of the following relations: + preference from highest to lowest. The list may be delimited with + commas or whitespace. See :ref:`Encryption_types` in + :ref:`kdc.conf(5)` for a list of the accepted values for this tag. +- The default value is |defetypes|, but single-DES encryption types +- will be implicitly removed from this list if the value of +- **allow_weak_crypto** is false. ++ The default value is |defetypes|. + + Do not set this unless required for specific backward + compatibility purposes; stale values of this setting can prevent +@@ -177,9 +172,7 @@ The libdefaults section may contain any of the following relations: + the client should request when making an AS-REQ, in order of + preference from highest to lowest. The format is the same as for + default_tgs_enctypes. The default value for this tag is +- |defetypes|, but single-DES encryption types will be implicitly +- removed from this list if the value of **allow_weak_crypto** is +- false. ++ |defetypes|. + + Do not set this unless required for specific backward + compatibility purposes; stale values of this setting can prevent +@@ -297,9 +290,7 @@ The libdefaults section may contain any of the following relations: + **permitted_enctypes** + Identifies all encryption types that are permitted for use in + session key encryption. The default value for this tag is +- |defetypes|, but single-DES encryption types will be implicitly +- removed from this list if the value of **allow_weak_crypto** is +- false. ++ |defetypes|. + + **plugin_base_dir** + If set, determines the base directory where krb5 plugins are +diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst +index 3cdfc92cf..84183a53c 100644 +--- a/doc/admin/enctypes.rst ++++ b/doc/admin/enctypes.rst +@@ -48,17 +48,12 @@ Session key selection + The KDC chooses the session key enctype by taking the intersection of + its **permitted_enctypes** list, the list of long-term keys for the + most recent kvno of the service, and the client's requested list of +-enctypes. If **allow_weak_crypto** is true, all services are assumed +-to support des-cbc-crc. ++enctypes. + +-Starting in krb5-1.11, **des_crc_session_supported** in +-:ref:`kdc.conf(5)` allows additional control over whether the KDC +-issues des-cbc-crc session keys. +- +-Also starting in krb5-1.11, it is possible to set a string attribute +-on a service principal to control what session key enctypes the KDC +-may issue for service tickets for that principal. See +-:ref:`set_string` in :ref:`kadmin(1)` for details. ++Starting in krb5-1.11, it is possible to set a string attribute on a ++service principal to control what session key enctypes the KDC may ++issue for service tickets for that principal. See :ref:`set_string` ++in :ref:`kadmin(1)` for details. + + + Choosing enctypes for a service +@@ -86,11 +81,11 @@ affect how enctypes are chosen. + + **allow_weak_crypto** + defaults to *false* starting with krb5-1.8. When *false*, removes +- single-DES enctypes (and other weak enctypes) from +- **permitted_enctypes**, **default_tkt_enctypes**, and +- **default_tgs_enctypes**. Do not set this to *true* unless the +- use of weak enctypes is an acceptable risk for your environment +- and the weak enctypes are required for backward compatibility. ++ weak enctypes from **permitted_enctypes**, ++ **default_tkt_enctypes**, and **default_tgs_enctypes**. Do not ++ set this to *true* unless the use of weak enctypes is an ++ acceptable risk for your environment and the weak enctypes are ++ required for backward compatibility. + + **permitted_enctypes** + controls the set of enctypes that a service will accept as session +@@ -127,9 +122,9 @@ See :ref:`Encryption_types` for additional information about enctypes. + ========================== ===== ======== ======= + enctype weak? krb5 Windows + ========================== ===== ======== ======= +-des-cbc-crc weak all >=2000 +-des-cbc-md4 weak all ? +-des-cbc-md5 weak all >=2000 ++des-cbc-crc weak <1.18 >=2000 ++des-cbc-md4 weak <1.18 ? ++des-cbc-md5 weak <1.18 >=2000 + des3-cbc-sha1 >=1.1 none + arcfour-hmac >=1.3 >=2000 + arcfour-hmac-exp weak >=1.3 >=2000 +@@ -141,6 +136,7 @@ camellia128-cts-cmac >=1.9 none + camellia256-cts-cmac >=1.9 none + ========================== ===== ======== ======= + +-krb5 releases 1.8 and later disable the single-DES enctypes by +-default. Microsoft Windows releases Windows 7 and later disable +-single-DES enctypes by default. ++krb5 releases 1.18 and later do not support single-DES. krb5 releases ++1.8 and later disable the single-DES enctypes by default. Microsoft ++Windows releases Windows 7 and later disable single-DES enctypes by ++default. +diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst +index 47c6d4413..534795d15 100644 +--- a/doc/appdev/refs/macros/index.rst ++++ b/doc/appdev/refs/macros/index.rst +@@ -55,6 +55,7 @@ Public + ENCTYPE_DES3_CBC_RAW.rst + ENCTYPE_DES3_CBC_SHA.rst + ENCTYPE_DES3_CBC_SHA1.rst ++ ENCTYPE_DES3_CBC_SHA1.rst + ENCTYPE_DES_CBC_CRC.rst + ENCTYPE_DES_CBC_MD4.rst + ENCTYPE_DES_CBC_MD5.rst +diff --git a/doc/conf.py b/doc/conf.py +index c32e33001..759367c21 100644 +--- a/doc/conf.py ++++ b/doc/conf.py +@@ -272,7 +272,7 @@ else: + rst_epilog += ''' + .. |krb5conf| replace:: ``/etc/krb5.conf`` + .. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal des3-cbc-sha1:normal arcfour-hmac-md5:normal`` +-.. |defetypes| replace:: ``aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha384-192 aes128-cts-hmac-sha256-128 des3-cbc-sha1 arcfour-hmac-md5 camellia256-cts-cmac camellia128-cts-cmac des-cbc-crc des-cbc-md5 des-cbc-md4`` ++.. |defetypes| replace:: ``aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha384-192 aes128-cts-hmac-sha256-128 des3-cbc-sha1 arcfour-hmac-md5 camellia256-cts-cmac camellia128-cts-cmac`` + .. |defmkey| replace:: ``aes256-cts-hmac-sha1-96`` + .. |copy| unicode:: U+000A9 + ''' +diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst +index 584f7b893..a19068e26 100644 +--- a/doc/mitK5features.rst ++++ b/doc/mitK5features.rst +@@ -37,7 +37,7 @@ Database backends: LDAP, DB2, LMDB + + krb4 support: Kerberos 5 release < 1.8 + +-DES support: configurable (See :ref:`retiring-des`) ++DES support: Kerberos 5 release < 1.18 (See :ref:`retiring-des`) + + Interoperability + ---------------- +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 1a78fd7a9..e0c557554 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -200,7 +200,6 @@ typedef unsigned char u_char; + #define KRB5_CONF_DEFAULT_REALM "default_realm" + #define KRB5_CONF_DEFAULT_TGS_ENCTYPES "default_tgs_enctypes" + #define KRB5_CONF_DEFAULT_TKT_ENCTYPES "default_tkt_enctypes" +-#define KRB5_CONF_DES_CRC_SESSION_SUPPORTED "des_crc_session_supported" + #define KRB5_CONF_DICT_FILE "dict_file" + #define KRB5_CONF_DISABLE "disable" + #define KRB5_CONF_DISABLE_ENCRYPTED_TIMESTAMP "disable_encrypted_timestamp" +diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin +index 346e796a5..5f596d1fc 100644 +--- a/src/include/krb5/krb5.hin ++++ b/src/include/krb5/krb5.hin +@@ -422,13 +422,13 @@ typedef struct _krb5_crypto_iov { + + /* per Kerberos v5 protocol spec */ + #define ENCTYPE_NULL 0x0000 +-#define ENCTYPE_DES_CBC_CRC 0x0001 /**< DES cbc mode with CRC-32 */ +-#define ENCTYPE_DES_CBC_MD4 0x0002 /**< DES cbc mode with RSA-MD4 */ +-#define ENCTYPE_DES_CBC_MD5 0x0003 /**< DES cbc mode with RSA-MD5 */ +-#define ENCTYPE_DES_CBC_RAW 0x0004 /**< @deprecated DES cbc mode raw */ ++#define ENCTYPE_DES_CBC_CRC 0x0001 /**< @deprecated no longer supported */ ++#define ENCTYPE_DES_CBC_MD4 0x0002 /**< @deprecated no longer supported */ ++#define ENCTYPE_DES_CBC_MD5 0x0003 /**< @deprecated no longer supported */ ++#define ENCTYPE_DES_CBC_RAW 0x0004 /**< @deprecated no longer supported */ + #define ENCTYPE_DES3_CBC_SHA 0x0005 /**< @deprecated DES-3 cbc with SHA1 */ + #define ENCTYPE_DES3_CBC_RAW 0x0006 /**< @deprecated DES-3 cbc mode raw */ +-#define ENCTYPE_DES_HMAC_SHA1 0x0008 /**< @deprecated */ ++#define ENCTYPE_DES_HMAC_SHA1 0x0008 /**< @deprecated no longer supported */ + /* PKINIT */ + #define ENCTYPE_DSA_SHA1_CMS 0x0009 /**< DSA with SHA1, CMS signature */ + #define ENCTYPE_MD5_RSA_CMS 0x000a /**< MD5 with RSA, CMS signature */ +diff --git a/src/include/win-mac.h b/src/include/win-mac.h +index c3744ed14..dc0f2a1ae 100644 +--- a/src/include/win-mac.h ++++ b/src/include/win-mac.h +@@ -176,18 +176,6 @@ typedef _W64 int ssize_t; + #define HAVE_STDLIB_H + #endif + +-/* This controls which encryption routines libcrypto will provide */ +-#define PROVIDE_DES_CBC_MD5 +-#define PROVIDE_DES_CBC_CRC +-#define PROVIDE_DES_CBC_RAW +-#define PROVIDE_DES_CBC_CKSUM +-#define PROVIDE_CRC32 +-#define PROVIDE_RSA_MD4 +-#define PROVIDE_RSA_MD5 +-/* #define PROVIDE_DES3_CBC_SHA */ +-/* #define PROVIDE_DES3_CBC_RAW */ +-/* #define PROVIDE_NIST_SHA */ +- + /* Ugly. Microsoft, in stdc mode, doesn't support the low-level i/o + * routines directly. Rather, they only export the _ version. + * The following defines works around this problem. +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index f2741090e..df1ba6acf 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -991,17 +991,6 @@ dbentry_supports_enctype(kdc_realm_t *kdc_active_realm, krb5_db_entry *server, + free(etypes_str); + free(etypes); + +- /* If configured to, assume every server without a session_enctypes +- * attribute supports DES_CBC_CRC. */ +- if (kdc_active_realm->realm_assume_des_crc_sess && +- enctype == ENCTYPE_DES_CBC_CRC) +- return TRUE; +- +- /* Due to an ancient interop problem, assume nothing supports des-cbc-md5 +- * unless there's a session_enctypes explicitly saying that it does. */ +- if (enctype == ENCTYPE_DES_CBC_MD5) +- return FALSE; +- + /* Assume the server supports any enctype it has a long-term key for. */ + return !krb5_dbe_find_enctype(kdc_context, server, enctype, -1, 0, &datap); + } +@@ -1752,9 +1741,6 @@ krb5_boolean + enctype_requires_etype_info_2(krb5_enctype enctype) + { + switch(enctype) { +- case ENCTYPE_DES_CBC_CRC: +- case ENCTYPE_DES_CBC_MD4: +- case ENCTYPE_DES_CBC_MD5: + case ENCTYPE_DES3_CBC_SHA1: + case ENCTYPE_DES3_CBC_RAW: + case ENCTYPE_ARCFOUR_HMAC: +diff --git a/src/kdc/main.c b/src/kdc/main.c +index 1596c1c5b..8d4df4d6a 100644 +--- a/src/kdc/main.c ++++ b/src/kdc/main.c +@@ -307,12 +307,6 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm, + &rdp->realm_reject_bad_transit)) + rdp->realm_reject_bad_transit = TRUE; + +- /* Handle assume des-cbc-crc is supported for session keys */ +- hierarchy[2] = KRB5_CONF_DES_CRC_SESSION_SUPPORTED; +- if (krb5_aprof_get_boolean(aprof, hierarchy, TRUE, +- &rdp->realm_assume_des_crc_sess)) +- rdp->realm_assume_des_crc_sess = TRUE; +- + /* Handle ticket maximum life */ + hierarchy[2] = KRB5_CONF_MAX_LIFE; + if (krb5_aprof_get_deltat(aprof, hierarchy, TRUE, &rdp->realm_maxlife)) +diff --git a/src/kdc/realm_data.h b/src/kdc/realm_data.h +index 859daf159..8d698dcb8 100644 +--- a/src/kdc/realm_data.h ++++ b/src/kdc/realm_data.h +@@ -73,7 +73,6 @@ typedef struct __kdc_realm_data { + krb5_deltat realm_maxrlife; /* Maximum renewable life for realm */ + krb5_boolean realm_reject_bad_transit; /* Accept unverifiable transited_realm ? */ + krb5_boolean realm_restrict_anon; /* Anon to local TGT only */ +- krb5_boolean realm_assume_des_crc_sess; /* Assume princs support des-cbc-crc for session keys */ + } kdc_realm_t; + + struct server_handle { +diff --git a/src/lib/crypto/builtin/des/des_int.h b/src/lib/crypto/builtin/des/des_int.h +index 67e40a19c..f8dc6b296 100644 +--- a/src/lib/crypto/builtin/des/des_int.h ++++ b/src/lib/crypto/builtin/des/des_int.h +@@ -131,7 +131,6 @@ typedef struct mit_des_ran_key_seed { + /* the first byte of the key is already in the keyblock */ + + #define MIT_DES_BLOCK_LENGTH (8*sizeof(krb5_octet)) +-#define MIT_DES_CBC_CRC_PAD_MINIMUM CRC32_CKSUM_LENGTH + /* This used to be 8*sizeof(krb5_octet) */ + #define MIT_DES_KEYSIZE 8 + +diff --git a/src/lib/crypto/builtin/enc_provider/Makefile.in b/src/lib/crypto/builtin/enc_provider/Makefile.in +index 4fd3311b4..3459e1d0e 100644 +--- a/src/lib/crypto/builtin/enc_provider/Makefile.in ++++ b/src/lib/crypto/builtin/enc_provider/Makefile.in +@@ -11,21 +11,18 @@ LOCALINCLUDES = -I$(srcdir)/../des \ + ##DOS##OBJFILE = ..\..\$(OUTPRE)enc_provider.lst + + STLIBOBJS= \ +- des.o \ + des3.o \ + rc4.o \ + aes.o \ + camellia.o + + OBJS= \ +- $(OUTPRE)des.$(OBJEXT) \ + $(OUTPRE)des3.$(OBJEXT) \ + $(OUTPRE)aes.$(OBJEXT) \ + $(OUTPRE)camellia.$(OBJEXT) \ + $(OUTPRE)rc4.$(OBJEXT) + + SRCS= \ +- $(srcdir)/des.c \ + $(srcdir)/des3.c \ + $(srcdir)/aes.c \ + $(srcdir)/camellia.c \ +diff --git a/src/lib/crypto/builtin/enc_provider/deps b/src/lib/crypto/builtin/enc_provider/deps +index 72e340766..7a3324c44 100644 +--- a/src/lib/crypto/builtin/enc_provider/deps ++++ b/src/lib/crypto/builtin/enc_provider/deps +@@ -1,18 +1,6 @@ + # + # Generated makefile dependencies follow. + # +-des.so des.po $(OUTPRE)des.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +- $(srcdir)/../aes/aes.h $(srcdir)/../crypto_mod.h $(srcdir)/../des/des_int.h \ +- $(srcdir)/../sha2/sha2.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des.c + des3.so des3.po $(OUTPRE)des3.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +diff --git a/src/lib/crypto/builtin/enc_provider/des.c b/src/lib/crypto/builtin/enc_provider/des.c +deleted file mode 100644 +index 30b8229f8..000000000 +--- a/src/lib/crypto/builtin/enc_provider/des.c ++++ /dev/null +@@ -1,120 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-#include "crypto_int.h" +-#include "des_int.h" +- +-static krb5_error_code +-validate_and_schedule(krb5_key key, const krb5_data *ivec, +- const krb5_crypto_iov *data, size_t num_data, +- mit_des_key_schedule schedule) +-{ +- if (key->keyblock.length != 8) +- return KRB5_BAD_KEYSIZE; +- if (iov_total_length(data, num_data, FALSE) % 8 != 0) +- return KRB5_BAD_MSIZE; +- if (ivec != NULL && ivec->length != 8) +- return KRB5_BAD_MSIZE; +- +- switch (mit_des_key_sched(key->keyblock.contents, schedule)) { +- case -1: +- return(KRB5DES_BAD_KEYPAR); +- case -2: +- return(KRB5DES_WEAK_KEY); +- } +- return 0; +-} +- +-static krb5_error_code +-des_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, +- size_t num_data) +-{ +- mit_des_key_schedule schedule; +- krb5_error_code err; +- +- err = validate_and_schedule(key, ivec, data, num_data, schedule); +- if (err) +- return err; +- +- krb5int_des_cbc_encrypt(data, num_data, schedule, +- ivec != NULL ? (unsigned char *) ivec->data : +- NULL); +- +- zap(schedule, sizeof(schedule)); +- return 0; +-} +- +-static krb5_error_code +-des_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, +- size_t num_data) +-{ +- mit_des_key_schedule schedule; +- krb5_error_code err; +- +- err = validate_and_schedule(key, ivec, data, num_data, schedule); +- if (err) +- return err; +- +- krb5int_des_cbc_decrypt(data, num_data, schedule, +- ivec != NULL ? (unsigned char *) ivec->data : +- NULL); +- +- zap(schedule, sizeof(schedule)); +- return 0; +-} +- +-static krb5_error_code +-des_cbc_mac(krb5_key key, const krb5_crypto_iov *data, size_t num_data, +- const krb5_data *ivec, krb5_data *output) +-{ +- mit_des_key_schedule schedule; +- krb5_error_code err; +- +- err = validate_and_schedule(key, ivec, data, num_data, schedule); +- if (err) +- return err; +- +- if (output->length != 8) +- return KRB5_CRYPTO_INTERNAL; +- +- krb5int_des_cbc_mac(data, num_data, schedule, +- ivec != NULL ? (unsigned char *) ivec->data : NULL, +- (unsigned char *) output->data); +- +- zap(schedule, sizeof(schedule)); +- return 0; +-} +- +-const struct krb5_enc_provider krb5int_enc_des = { +- 8, +- 7, 8, +- des_encrypt, +- des_decrypt, +- des_cbc_mac, +- krb5int_des_init_state, +- krb5int_default_free_state +-}; +diff --git a/src/lib/crypto/builtin/hash_provider/Makefile.in b/src/lib/crypto/builtin/hash_provider/Makefile.in +index 2f587a497..ceebf9380 100644 +--- a/src/lib/crypto/builtin/hash_provider/Makefile.in ++++ b/src/lib/crypto/builtin/hash_provider/Makefile.in +@@ -8,20 +8,17 @@ LOCALINCLUDES = -I$(srcdir)/.. -I$(srcdir)/../../krb -I$(srcdir)/../md4 \ + ##DOS##OBJFILE = ..\..\$(OUTPRE)hash_provider.lst + + STLIBOBJS= \ +- hash_crc32.o \ + hash_md4.o \ + hash_md5.o \ + hash_sha1.o \ + hash_sha2.o + +-OBJS= $(OUTPRE)hash_crc32.$(OBJEXT) \ +- $(OUTPRE)hash_md4.$(OBJEXT) \ ++OBJS= $(OUTPRE)hash_md4.$(OBJEXT) \ + $(OUTPRE)hash_md5.$(OBJEXT) \ + $(OUTPRE)hash_sha1.$(OBJEXT) \ + $(OUTPRE)hash_sha2.$(OBJEXT) + +-SRCS= $(srcdir)/hash_crc32.c \ +- $(srcdir)/hash_md4.c \ ++SRCS= $(srcdir)/hash_md4.c \ + $(srcdir)/hash_md5.c \ + $(srcdir)/hash_sha1.c \ + $(srcdir)/hash_sha2.c +diff --git a/src/lib/crypto/builtin/hash_provider/deps b/src/lib/crypto/builtin/hash_provider/deps +index 18f89b383..fb65a44be 100644 +--- a/src/lib/crypto/builtin/hash_provider/deps ++++ b/src/lib/crypto/builtin/hash_provider/deps +@@ -1,19 +1,6 @@ + # + # Generated makefile dependencies follow. + # +-hash_crc32.so hash_crc32.po $(OUTPRE)hash_crc32.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(srcdir)/../aes/aes.h \ +- $(srcdir)/../crypto_mod.h $(srcdir)/../sha2/sha2.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- hash_crc32.c + hash_md4.so hash_md4.po $(OUTPRE)hash_md4.$(OBJEXT): \ + $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ + $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +diff --git a/src/lib/crypto/builtin/hash_provider/hash_crc32.c b/src/lib/crypto/builtin/hash_provider/hash_crc32.c +deleted file mode 100644 +index 1d0be5563..000000000 +--- a/src/lib/crypto/builtin/hash_provider/hash_crc32.c ++++ /dev/null +@@ -1,56 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-#include "crypto_int.h" +- +-static krb5_error_code +-k5_crc32_hash(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) +-{ +- unsigned long c; +- unsigned int i; +- +- if (output->length != CRC32_CKSUM_LENGTH) +- return KRB5_CRYPTO_INTERNAL; +- +- c = 0; +- for (i = 0; i < num_data; i++) { +- const krb5_crypto_iov *iov = &data[i]; +- +- if (SIGN_IOV(iov)) +- mit_crc32(iov->data.data, iov->data.length, &c); +- } +- +- store_32_le(c, output->data); +- return 0; +-} +- +-const struct krb5_hash_provider krb5int_hash_crc32 = { +- "CRC32", +- CRC32_CKSUM_LENGTH, +- 1, +- k5_crc32_hash +-}; +diff --git a/src/lib/crypto/krb/Makefile.in b/src/lib/crypto/krb/Makefile.in +index fc01a2ced..c0e0b791b 100644 +--- a/src/lib/crypto/krb/Makefile.in ++++ b/src/lib/crypto/krb/Makefile.in +@@ -23,7 +23,6 @@ STLIBOBJS=\ + cmac.o \ + coll_proof_cksum.o \ + combine_keys.o \ +- crc32.o \ + crypto_length.o \ + crypto_libinit.o \ + default_state.o \ +@@ -37,7 +36,6 @@ STLIBOBJS=\ + enc_dk_cmac.o \ + enc_dk_hmac.o \ + enc_etm.o \ +- enc_old.o \ + enc_raw.o \ + enc_rc4.o \ + etypes.o \ +@@ -61,7 +59,6 @@ STLIBOBJS=\ + prng.o \ + prng_$(PRNG_ALG).o \ + random_to_key.o \ +- s2k_des.o \ + s2k_pbkdf2.o \ + s2k_rc4.o \ + state.o \ +@@ -88,7 +85,6 @@ OBJS=\ + $(OUTPRE)cmac.$(OBJEXT) \ + $(OUTPRE)coll_proof_cksum.$(OBJEXT) \ + $(OUTPRE)combine_keys.$(OBJEXT) \ +- $(OUTPRE)crc32.$(OBJEXT) \ + $(OUTPRE)crypto_length.$(OBJEXT) \ + $(OUTPRE)crypto_libinit.$(OBJEXT) \ + $(OUTPRE)default_state.$(OBJEXT) \ +@@ -102,7 +98,6 @@ OBJS=\ + $(OUTPRE)enc_dk_cmac.$(OBJEXT) \ + $(OUTPRE)enc_dk_hmac.$(OBJEXT) \ + $(OUTPRE)enc_etm.$(OBJEXT) \ +- $(OUTPRE)enc_old.$(OBJEXT) \ + $(OUTPRE)enc_raw.$(OBJEXT) \ + $(OUTPRE)enc_rc4.$(OBJEXT) \ + $(OUTPRE)etypes.$(OBJEXT) \ +@@ -126,7 +121,6 @@ OBJS=\ + $(OUTPRE)prng.$(OBJEXT) \ + $(OUTPRE)prng_$(PRNG_ALG).$(OBJEXT) \ + $(OUTPRE)random_to_key.$(OBJEXT) \ +- $(OUTPRE)s2k_des.$(OBJEXT) \ + $(OUTPRE)s2k_pbkdf2.$(OBJEXT) \ + $(OUTPRE)s2k_rc4.$(OBJEXT) \ + $(OUTPRE)state.$(OBJEXT) \ +@@ -153,7 +147,6 @@ SRCS=\ + $(srcdir)/cmac.c \ + $(srcdir)/coll_proof_cksum.c \ + $(srcdir)/combine_keys.c \ +- $(srcdir)/crc32.c \ + $(srcdir)/crypto_length.c \ + $(srcdir)/crypto_libinit.c \ + $(srcdir)/default_state.c \ +@@ -167,7 +160,6 @@ SRCS=\ + $(srcdir)/enc_dk_cmac.c \ + $(srcdir)/enc_dk_hmac.c \ + $(srcdir)/enc_etm.c \ +- $(srcdir)/enc_old.c \ + $(srcdir)/enc_raw.c \ + $(srcdir)/enc_rc4.c \ + $(srcdir)/etypes.c \ +@@ -192,7 +184,6 @@ SRCS=\ + $(srcdir)/prng_$(PRNG_ALG).c \ + $(srcdir)/cf2.c \ + $(srcdir)/random_to_key.c \ +- $(srcdir)/s2k_des.c \ + $(srcdir)/s2k_pbkdf2.c \ + $(srcdir)/s2k_rc4.c \ + $(srcdir)/state.c \ +diff --git a/src/lib/crypto/krb/cksumtypes.c b/src/lib/crypto/krb/cksumtypes.c +index 85967f9aa..ecc2e08c9 100644 +--- a/src/lib/crypto/krb/cksumtypes.c ++++ b/src/lib/crypto/krb/cksumtypes.c +@@ -28,42 +28,18 @@ + #include "crypto_int.h" + + const struct krb5_cksumtypes krb5int_cksumtypes_list[] = { +- { CKSUMTYPE_CRC32, +- "crc32", { 0 }, "CRC-32", +- NULL, &krb5int_hash_crc32, +- krb5int_unkeyed_checksum, NULL, +- 4, 4, CKSUM_UNKEYED | CKSUM_NOT_COLL_PROOF }, +- + { CKSUMTYPE_RSA_MD4, + "md4", { 0 }, "RSA-MD4", + NULL, &krb5int_hash_md4, + krb5int_unkeyed_checksum, NULL, + 16, 16, CKSUM_UNKEYED }, + +- { CKSUMTYPE_RSA_MD4_DES, +- "md4-des", { 0 }, "RSA-MD4 with DES cbc mode", +- &krb5int_enc_des, &krb5int_hash_md4, +- krb5int_confounder_checksum, krb5int_confounder_verify, +- 24, 24, 0 }, +- +- { CKSUMTYPE_DESCBC, +- "des-cbc", { 0 }, "DES cbc mode", +- &krb5int_enc_des, NULL, +- krb5int_cbc_checksum, NULL, +- 8, 8, 0 }, +- + { CKSUMTYPE_RSA_MD5, + "md5", { 0 }, "RSA-MD5", + NULL, &krb5int_hash_md5, + krb5int_unkeyed_checksum, NULL, + 16, 16, CKSUM_UNKEYED }, + +- { CKSUMTYPE_RSA_MD5_DES, +- "md5-des", { 0 }, "RSA-MD5 with DES cbc mode", +- &krb5int_enc_des, &krb5int_hash_md5, +- krb5int_confounder_checksum, krb5int_confounder_verify, +- 24, 24, 0 }, +- + { CKSUMTYPE_NIST_SHA, + "sha", { 0 }, "NIST-SHA", + NULL, &krb5int_hash_sha1, +diff --git a/src/lib/crypto/krb/combine_keys.c b/src/lib/crypto/krb/combine_keys.c +index 90905c5ae..c36434e17 100644 +--- a/src/lib/crypto/krb/combine_keys.c ++++ b/src/lib/crypto/krb/combine_keys.c +@@ -60,9 +60,6 @@ static krb5_boolean + enctype_ok(krb5_enctype e) + { + switch (e) { +- case ENCTYPE_DES_CBC_CRC: +- case ENCTYPE_DES_CBC_MD4: +- case ENCTYPE_DES_CBC_MD5: + case ENCTYPE_DES3_CBC_SHA1: + return TRUE; + default: +diff --git a/src/lib/crypto/krb/crc32.c b/src/lib/crypto/krb/crc32.c +deleted file mode 100644 +index 11fe312da..000000000 +--- a/src/lib/crypto/krb/crc32.c ++++ /dev/null +@@ -1,165 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/krb/crc32.c */ +-/* +- * Copyright 1990, 2002 by the Massachusetts Institute of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +-/* +- * Copyright (C) 1986 Gary S. Brown. You may use this program, or +- * code or tables extracted from it, as desired without restriction. +- */ +- +-/* +- * +- * CRC-32/AUTODIN-II routines +- */ +- +-#include "crypto_int.h" +- +-/* First, the polynomial itself and its table of feedback terms. The */ +-/* polynomial is */ +-/* X^32+X^26+X^23+X^22+X^16+X^12+X^11+X^10+X^8+X^7+X^5+X^4+X^2+X^1+X^0 */ +-/* Note that we take it "backwards" and put the highest-order term in */ +-/* the lowest-order bit. The X^32 term is "implied"; the LSB is the */ +-/* X^31 term, etc. The X^0 term (usually shown as "+1") results in */ +-/* the MSB being 1. */ +- +-/* Note that the usual hardware shift register implementation, which */ +-/* is what we're using (we're merely optimizing it by doing eight-bit */ +-/* chunks at a time) shifts bits into the lowest-order term. In our */ +-/* implementation, that means shifting towards the right. Why do we */ +-/* do it this way? Because the calculated CRC must be transmitted in */ +-/* order from highest-order term to lowest-order term. UARTs transmit */ +-/* characters in order from LSB to MSB. By storing the CRC this way, */ +-/* we hand it to the UART in the order low-byte to high-byte; the UART */ +-/* sends each low-bit to hight-bit; and the result is transmission bit */ +-/* by bit from highest- to lowest-order term without requiring any bit */ +-/* shuffling on our part. Reception works similarly. */ +- +-/* The feedback terms table consists of 256, 32-bit entries. Notes: */ +-/* */ +-/* 1. The table can be generated at runtime if desired; code to do so */ +-/* is shown later. It might not be obvious, but the feedback */ +-/* terms simply represent the results of eight shift/xor opera- */ +-/* tions for all combinations of data and CRC register values. */ +-/* */ +-/* 2. The CRC accumulation logic is the same for all CRC polynomials, */ +-/* be they sixteen or thirty-two bits wide. You simply choose the */ +-/* appropriate table. Alternatively, because the table can be */ +-/* generated at runtime, you can start by generating the table for */ +-/* the polynomial in question and use exactly the same "updcrc", */ +-/* if your application needn't simultaneously handle two CRC */ +-/* polynomials. (Note, however, that XMODEM is strange.) */ +-/* */ +-/* 3. For 16-bit CRCs, the table entries need be only 16 bits wide; */ +-/* of course, 32-bit entries work OK if the high 16 bits are zero. */ +-/* */ +-/* 4. The values must be right-shifted by eight bits by the "updcrc" */ +-/* logic; the shift must be unsigned (bring in zeroes). On some */ +-/* hardware you could probably optimize the shift in assembler by */ +-/* using byte-swap instructions. */ +- +-static u_long const crc_table[256] = { +- 0x00000000, 0x77073096, 0xee0e612c, 0x990951ba, +- 0x076dc419, 0x706af48f, 0xe963a535, 0x9e6495a3, +- 0x0edb8832, 0x79dcb8a4, 0xe0d5e91e, 0x97d2d988, +- 0x09b64c2b, 0x7eb17cbd, 0xe7b82d07, 0x90bf1d91, +- 0x1db71064, 0x6ab020f2, 0xf3b97148, 0x84be41de, +- 0x1adad47d, 0x6ddde4eb, 0xf4d4b551, 0x83d385c7, +- 0x136c9856, 0x646ba8c0, 0xfd62f97a, 0x8a65c9ec, +- 0x14015c4f, 0x63066cd9, 0xfa0f3d63, 0x8d080df5, +- 0x3b6e20c8, 0x4c69105e, 0xd56041e4, 0xa2677172, +- 0x3c03e4d1, 0x4b04d447, 0xd20d85fd, 0xa50ab56b, +- 0x35b5a8fa, 0x42b2986c, 0xdbbbc9d6, 0xacbcf940, +- 0x32d86ce3, 0x45df5c75, 0xdcd60dcf, 0xabd13d59, +- 0x26d930ac, 0x51de003a, 0xc8d75180, 0xbfd06116, +- 0x21b4f4b5, 0x56b3c423, 0xcfba9599, 0xb8bda50f, +- 0x2802b89e, 0x5f058808, 0xc60cd9b2, 0xb10be924, +- 0x2f6f7c87, 0x58684c11, 0xc1611dab, 0xb6662d3d, +- 0x76dc4190, 0x01db7106, 0x98d220bc, 0xefd5102a, +- 0x71b18589, 0x06b6b51f, 0x9fbfe4a5, 0xe8b8d433, +- 0x7807c9a2, 0x0f00f934, 0x9609a88e, 0xe10e9818, +- 0x7f6a0dbb, 0x086d3d2d, 0x91646c97, 0xe6635c01, +- 0x6b6b51f4, 0x1c6c6162, 0x856530d8, 0xf262004e, +- 0x6c0695ed, 0x1b01a57b, 0x8208f4c1, 0xf50fc457, +- 0x65b0d9c6, 0x12b7e950, 0x8bbeb8ea, 0xfcb9887c, +- 0x62dd1ddf, 0x15da2d49, 0x8cd37cf3, 0xfbd44c65, +- 0x4db26158, 0x3ab551ce, 0xa3bc0074, 0xd4bb30e2, +- 0x4adfa541, 0x3dd895d7, 0xa4d1c46d, 0xd3d6f4fb, +- 0x4369e96a, 0x346ed9fc, 0xad678846, 0xda60b8d0, +- 0x44042d73, 0x33031de5, 0xaa0a4c5f, 0xdd0d7cc9, +- 0x5005713c, 0x270241aa, 0xbe0b1010, 0xc90c2086, +- 0x5768b525, 0x206f85b3, 0xb966d409, 0xce61e49f, +- 0x5edef90e, 0x29d9c998, 0xb0d09822, 0xc7d7a8b4, +- 0x59b33d17, 0x2eb40d81, 0xb7bd5c3b, 0xc0ba6cad, +- 0xedb88320, 0x9abfb3b6, 0x03b6e20c, 0x74b1d29a, +- 0xead54739, 0x9dd277af, 0x04db2615, 0x73dc1683, +- 0xe3630b12, 0x94643b84, 0x0d6d6a3e, 0x7a6a5aa8, +- 0xe40ecf0b, 0x9309ff9d, 0x0a00ae27, 0x7d079eb1, +- 0xf00f9344, 0x8708a3d2, 0x1e01f268, 0x6906c2fe, +- 0xf762575d, 0x806567cb, 0x196c3671, 0x6e6b06e7, +- 0xfed41b76, 0x89d32be0, 0x10da7a5a, 0x67dd4acc, +- 0xf9b9df6f, 0x8ebeeff9, 0x17b7be43, 0x60b08ed5, +- 0xd6d6a3e8, 0xa1d1937e, 0x38d8c2c4, 0x4fdff252, +- 0xd1bb67f1, 0xa6bc5767, 0x3fb506dd, 0x48b2364b, +- 0xd80d2bda, 0xaf0a1b4c, 0x36034af6, 0x41047a60, +- 0xdf60efc3, 0xa867df55, 0x316e8eef, 0x4669be79, +- 0xcb61b38c, 0xbc66831a, 0x256fd2a0, 0x5268e236, +- 0xcc0c7795, 0xbb0b4703, 0x220216b9, 0x5505262f, +- 0xc5ba3bbe, 0xb2bd0b28, 0x2bb45a92, 0x5cb36a04, +- 0xc2d7ffa7, 0xb5d0cf31, 0x2cd99e8b, 0x5bdeae1d, +- 0x9b64c2b0, 0xec63f226, 0x756aa39c, 0x026d930a, +- 0x9c0906a9, 0xeb0e363f, 0x72076785, 0x05005713, +- 0x95bf4a82, 0xe2b87a14, 0x7bb12bae, 0x0cb61b38, +- 0x92d28e9b, 0xe5d5be0d, 0x7cdcefb7, 0x0bdbdf21, +- 0x86d3d2d4, 0xf1d4e242, 0x68ddb3f8, 0x1fda836e, +- 0x81be16cd, 0xf6b9265b, 0x6fb077e1, 0x18b74777, +- 0x88085ae6, 0xff0f6a70, 0x66063bca, 0x11010b5c, +- 0x8f659eff, 0xf862ae69, 0x616bffd3, 0x166ccf45, +- 0xa00ae278, 0xd70dd2ee, 0x4e048354, 0x3903b3c2, +- 0xa7672661, 0xd06016f7, 0x4969474d, 0x3e6e77db, +- 0xaed16a4a, 0xd9d65adc, 0x40df0b66, 0x37d83bf0, +- 0xa9bcae53, 0xdebb9ec5, 0x47b2cf7f, 0x30b5ffe9, +- 0xbdbdf21c, 0xcabac28a, 0x53b39330, 0x24b4a3a6, +- 0xbad03605, 0xcdd70693, 0x54de5729, 0x23d967bf, +- 0xb3667a2e, 0xc4614ab8, 0x5d681b02, 0x2a6f2b94, +- 0xb40bbe37, 0xc30c8ea1, 0x5a05df1b, 0x2d02ef8d +-}; +- +-void +-mit_crc32(krb5_pointer in, size_t in_length, unsigned long *cksum) +-{ +- u_char *data; +- u_long c = *cksum; +- int idx; +- size_t i; +- +- data = (u_char *)in; +- for (i = 0; i < in_length; i++) { +- idx = (int) (data[i] ^ c); +- idx &= 0xff; +- c >>= 8; +- c ^= crc_table[idx]; +- } +- +- *cksum = c; +-} +diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h +index 6c1c77cac..b18d5e2e3 100644 +--- a/src/lib/crypto/krb/crypto_int.h ++++ b/src/lib/crypto/krb/crypto_int.h +@@ -180,8 +180,6 @@ extern const size_t krb5int_cksumtypes_length; + /*** Prototypes for enctype table functions ***/ + + /* Length */ +-unsigned int krb5int_old_crypto_length(const struct krb5_keytypes *ktp, +- krb5_cryptotype type); + unsigned int krb5int_raw_crypto_length(const struct krb5_keytypes *ktp, + krb5_cryptotype type); + unsigned int krb5int_arcfour_crypto_length(const struct krb5_keytypes *ktp, +@@ -196,10 +194,6 @@ unsigned int krb5int_aes2_crypto_length(const struct krb5_keytypes *ktp, + krb5_cryptotype type); + + /* Encrypt */ +-krb5_error_code krb5int_old_encrypt(const struct krb5_keytypes *ktp, +- krb5_key key, krb5_keyusage usage, +- const krb5_data *ivec, +- krb5_crypto_iov *data, size_t num_data); + krb5_error_code krb5int_raw_encrypt(const struct krb5_keytypes *ktp, + krb5_key key, krb5_keyusage usage, + const krb5_data *ivec, +@@ -224,10 +218,6 @@ krb5_error_code krb5int_etm_encrypt(const struct krb5_keytypes *ktp, + krb5_crypto_iov *data, size_t num_data); + + /* Decrypt */ +-krb5_error_code krb5int_old_decrypt(const struct krb5_keytypes *ktp, +- krb5_key key, krb5_keyusage usage, +- const krb5_data *ivec, +- krb5_crypto_iov *data, size_t num_data); + krb5_error_code krb5int_raw_decrypt(const struct krb5_keytypes *ktp, + krb5_key key, krb5_keyusage usage, + const krb5_data *ivec, +@@ -388,10 +378,6 @@ krb5_error_code krb5int_cmac_checksum(const struct krb5_enc_provider *enc, + size_t num_data, + krb5_data *output); + +-/* Compute a CRC-32 checksum. c is in-out to allow chaining; init to 0. */ +-#define CRC32_CKSUM_LENGTH 4 +-void mit_crc32(krb5_pointer in, size_t in_length, unsigned long *c); +- + /* Translate an RFC 3961 key usage to a Microsoft RC4 usage. */ + krb5_keyusage krb5int_arcfour_translate_usage(krb5_keyusage usage); + +@@ -455,7 +441,6 @@ void k5_iov_cursor_put(struct iov_cursor *cursor, unsigned char *block); + /* Modules must implement the k5_sha256() function prototyped in k5-int.h. */ + + /* Modules must implement the following enc_providers and hash_providers: */ +-extern const struct krb5_enc_provider krb5int_enc_des; + extern const struct krb5_enc_provider krb5int_enc_des3; + extern const struct krb5_enc_provider krb5int_enc_arcfour; + extern const struct krb5_enc_provider krb5int_enc_aes128; +@@ -465,7 +450,6 @@ extern const struct krb5_enc_provider krb5int_enc_aes256_ctr; + extern const struct krb5_enc_provider krb5int_enc_camellia128; + extern const struct krb5_enc_provider krb5int_enc_camellia256; + +-extern const struct krb5_hash_provider krb5int_hash_crc32; + extern const struct krb5_hash_provider krb5int_hash_md4; + extern const struct krb5_hash_provider krb5int_hash_md5; + extern const struct krb5_hash_provider krb5int_hash_sha1; +diff --git a/src/lib/crypto/krb/default_state.c b/src/lib/crypto/krb/default_state.c +index c7bfe323f..0757c8b02 100644 +--- a/src/lib/crypto/krb/default_state.c ++++ b/src/lib/crypto/krb/default_state.c +@@ -39,10 +39,6 @@ krb5int_des_init_state(const krb5_keyblock *key, krb5_keyusage usage, + if (alloc_data(state_out, 8)) + return ENOMEM; + +- /* des-cbc-crc uses the key as the initial ivec. */ +- if (key->enctype == ENCTYPE_DES_CBC_CRC) +- memcpy(state_out->data, key->contents, state_out->length); +- + return 0; + } + +diff --git a/src/lib/crypto/krb/deps b/src/lib/crypto/krb/deps +index 2a7f9b0ef..f9a740860 100644 +--- a/src/lib/crypto/krb/deps ++++ b/src/lib/crypto/krb/deps +@@ -204,18 +204,6 @@ combine_keys.so combine_keys.po $(OUTPRE)combine_keys.$(OBJEXT): \ + $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ + $(top_srcdir)/include/socket-utils.h combine_keys.c \ + crypto_int.h +-crc32.so crc32.po $(OUTPRE)crc32.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \ +- $(srcdir)/../builtin/crypto_mod.h $(srcdir)/../builtin/sha2/sha2.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- crc32.c crypto_int.h + crypto_length.so crypto_length.po $(OUTPRE)crypto_length.$(OBJEXT): \ + $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ + $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +@@ -372,18 +360,6 @@ enc_etm.so enc_etm.po $(OUTPRE)enc_etm.$(OBJEXT): $(BUILDTOP)/include/autoconf.h + $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ + $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ + crypto_int.h enc_etm.c +-enc_old.so enc_old.po $(OUTPRE)enc_old.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \ +- $(srcdir)/../builtin/crypto_mod.h $(srcdir)/../builtin/sha2/sha2.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- crypto_int.h enc_old.c + enc_raw.so enc_raw.po $(OUTPRE)enc_raw.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \ +@@ -660,18 +636,6 @@ random_to_key.so random_to_key.po $(OUTPRE)random_to_key.$(OBJEXT): \ + $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ + $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ + $(top_srcdir)/include/socket-utils.h crypto_int.h random_to_key.c +-s2k_des.so s2k_des.po $(OUTPRE)s2k_des.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \ +- $(srcdir)/../builtin/crypto_mod.h $(srcdir)/../builtin/sha2/sha2.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- crypto_int.h s2k_des.c + s2k_pbkdf2.so s2k_pbkdf2.po $(OUTPRE)s2k_pbkdf2.$(OBJEXT): \ + $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ + $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +diff --git a/src/lib/crypto/krb/enc_old.c b/src/lib/crypto/krb/enc_old.c +deleted file mode 100644 +index 1b02a5915..000000000 +--- a/src/lib/crypto/krb/enc_old.c ++++ /dev/null +@@ -1,181 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/krb/enc_old.c */ +-/* +- * Copyright 2008 by the Massachusetts Institute of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-#include "crypto_int.h" +- +-unsigned int +-krb5int_old_crypto_length(const struct krb5_keytypes *ktp, +- krb5_cryptotype type) +-{ +- switch (type) { +- case KRB5_CRYPTO_TYPE_HEADER: +- return ktp->enc->block_size + ktp->hash->hashsize; +- case KRB5_CRYPTO_TYPE_PADDING: +- return ktp->enc->block_size; +- case KRB5_CRYPTO_TYPE_TRAILER: +- return 0; +- case KRB5_CRYPTO_TYPE_CHECKSUM: +- return ktp->hash->hashsize; +- default: +- assert(0 && "invalid cryptotype passed to krb5int_old_crypto_length"); +- return 0; +- } +-} +- +-krb5_error_code +-krb5int_old_encrypt(const struct krb5_keytypes *ktp, krb5_key key, +- krb5_keyusage usage, const krb5_data *ivec, +- krb5_crypto_iov *data, size_t num_data) +-{ +- const struct krb5_enc_provider *enc = ktp->enc; +- const struct krb5_hash_provider *hash = ktp->hash; +- krb5_error_code ret; +- krb5_crypto_iov *header, *trailer, *padding; +- krb5_data checksum, confounder, crcivec = empty_data(); +- unsigned int plainlen, padsize; +- size_t i; +- +- /* E(Confounder | Checksum | Plaintext | Pad) */ +- +- plainlen = enc->block_size + hash->hashsize; +- for (i = 0; i < num_data; i++) { +- krb5_crypto_iov *iov = &data[i]; +- +- if (iov->flags == KRB5_CRYPTO_TYPE_DATA) +- plainlen += iov->data.length; +- } +- +- header = krb5int_c_locate_iov(data, num_data, KRB5_CRYPTO_TYPE_HEADER); +- if (header == NULL || +- header->data.length < enc->block_size + hash->hashsize) +- return KRB5_BAD_MSIZE; +- +- /* Trailer may be absent. */ +- trailer = krb5int_c_locate_iov(data, num_data, KRB5_CRYPTO_TYPE_TRAILER); +- if (trailer != NULL) +- trailer->data.length = 0; +- +- /* Check that the input data is correctly padded. */ +- padsize = krb5_roundup(plainlen, enc->block_size) - plainlen; +- padding = krb5int_c_locate_iov(data, num_data, KRB5_CRYPTO_TYPE_PADDING); +- if (padsize > 0 && (padding == NULL || padding->data.length < padsize)) +- return KRB5_BAD_MSIZE; +- if (padding) { +- padding->data.length = padsize; +- memset(padding->data.data, 0, padsize); +- } +- +- /* Generate a confounder in the header block. */ +- confounder = make_data(header->data.data, enc->block_size); +- ret = krb5_c_random_make_octets(0, &confounder); +- if (ret != 0) +- goto cleanup; +- checksum = make_data(header->data.data + enc->block_size, hash->hashsize); +- memset(checksum.data, 0, hash->hashsize); +- +- /* Checksum the plaintext with zeroed checksum and padding. */ +- ret = hash->hash(data, num_data, &checksum); +- if (ret != 0) +- goto cleanup; +- +- /* Use the key as the ivec for des-cbc-crc if none was provided. */ +- if (key->keyblock.enctype == ENCTYPE_DES_CBC_CRC && ivec == NULL) { +- ret = alloc_data(&crcivec, key->keyblock.length); +- if (ret != 0) +- goto cleanup; +- memcpy(crcivec.data, key->keyblock.contents, key->keyblock.length); +- ivec = &crcivec; +- } +- +- ret = enc->encrypt(key, ivec, data, num_data); +- if (ret != 0) +- goto cleanup; +- +-cleanup: +- zapfree(crcivec.data, crcivec.length); +- return ret; +-} +- +-krb5_error_code +-krb5int_old_decrypt(const struct krb5_keytypes *ktp, krb5_key key, +- krb5_keyusage usage, const krb5_data *ivec, +- krb5_crypto_iov *data, size_t num_data) +-{ +- const struct krb5_enc_provider *enc = ktp->enc; +- const struct krb5_hash_provider *hash = ktp->hash; +- krb5_error_code ret; +- krb5_crypto_iov *header, *trailer; +- krb5_data checksum, crcivec = empty_data(); +- char *saved_checksum = NULL; +- +- /* Check that the input data is correctly padded. */ +- if (iov_total_length(data, num_data, FALSE) % enc->block_size != 0) +- return KRB5_BAD_MSIZE; +- +- header = krb5int_c_locate_iov(data, num_data, KRB5_CRYPTO_TYPE_HEADER); +- if (header == NULL || +- header->data.length != enc->block_size + hash->hashsize) +- return KRB5_BAD_MSIZE; +- +- trailer = krb5int_c_locate_iov(data, num_data, KRB5_CRYPTO_TYPE_TRAILER); +- if (trailer != NULL && trailer->data.length != 0) +- return KRB5_BAD_MSIZE; +- +- /* Use the key as the ivec for des-cbc-crc if none was provided. */ +- if (key->keyblock.enctype == ENCTYPE_DES_CBC_CRC && ivec == NULL) { +- ret = alloc_data(&crcivec, key->keyblock.length); +- memcpy(crcivec.data, key->keyblock.contents, key->keyblock.length); +- ivec = &crcivec; +- } +- +- /* Decrypt the ciphertext. */ +- ret = enc->decrypt(key, ivec, data, num_data); +- if (ret != 0) +- goto cleanup; +- +- /* Save the checksum, then zero it out in the plaintext. */ +- checksum = make_data(header->data.data + enc->block_size, hash->hashsize); +- saved_checksum = k5memdup(checksum.data, checksum.length, &ret); +- if (saved_checksum == NULL) +- goto cleanup; +- memset(checksum.data, 0, checksum.length); +- +- /* +- * Checksum the plaintext (with zeroed checksum field), storing the result +- * back into the plaintext field we just zeroed out. Then compare it to +- * the saved checksum. +- */ +- ret = hash->hash(data, num_data, &checksum); +- if (k5_bcmp(checksum.data, saved_checksum, checksum.length) != 0) { +- ret = KRB5KRB_AP_ERR_BAD_INTEGRITY; +- goto cleanup; +- } +- +-cleanup: +- zapfree(crcivec.data, crcivec.length); +- zapfree(saved_checksum, hash->hashsize); +- return ret; +-} +diff --git a/src/lib/crypto/krb/etypes.c b/src/lib/crypto/krb/etypes.c +index 8f44c37e7..fc278783b 100644 +--- a/src/lib/crypto/krb/etypes.c ++++ b/src/lib/crypto/krb/etypes.c +@@ -35,42 +35,6 @@ + + /* Deprecations come from RFC 6649 and RFC 8249. */ + const struct krb5_keytypes krb5int_enctypes_list[] = { +- { ENCTYPE_DES_CBC_CRC, +- "des-cbc-crc", { 0 }, "DES cbc mode with CRC-32", +- &krb5int_enc_des, &krb5int_hash_crc32, +- 16, +- krb5int_old_crypto_length, krb5int_old_encrypt, krb5int_old_decrypt, +- krb5int_des_string_to_key, k5_rand2key_des, +- krb5int_des_prf, +- CKSUMTYPE_RSA_MD5_DES, +- ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, +- { ENCTYPE_DES_CBC_MD4, +- "des-cbc-md4", { 0 }, "DES cbc mode with RSA-MD4", +- &krb5int_enc_des, &krb5int_hash_md4, +- 16, +- krb5int_old_crypto_length, krb5int_old_encrypt, krb5int_old_decrypt, +- krb5int_des_string_to_key, k5_rand2key_des, +- krb5int_des_prf, +- CKSUMTYPE_RSA_MD4_DES, +- ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, +- { ENCTYPE_DES_CBC_MD5, +- "des-cbc-md5", { "des" }, "DES cbc mode with RSA-MD5", +- &krb5int_enc_des, &krb5int_hash_md5, +- 16, +- krb5int_old_crypto_length, krb5int_old_encrypt, krb5int_old_decrypt, +- krb5int_des_string_to_key, k5_rand2key_des, +- krb5int_des_prf, +- CKSUMTYPE_RSA_MD5_DES, +- ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, +- { ENCTYPE_DES_CBC_RAW, +- "des-cbc-raw", { 0 }, "DES cbc mode raw", +- &krb5int_enc_des, NULL, +- 16, +- krb5int_raw_crypto_length, krb5int_raw_encrypt, krb5int_raw_decrypt, +- krb5int_des_string_to_key, k5_rand2key_des, +- krb5int_des_prf, +- 0, +- ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, + { ENCTYPE_DES3_CBC_RAW, + "des3-cbc-raw", { 0 }, "Triple DES cbc mode raw", + &krb5int_enc_des3, NULL, +@@ -92,16 +56,6 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { + CKSUMTYPE_HMAC_SHA1_DES3, + ETYPE_DEPRECATED, 112 }, + +- { ENCTYPE_DES_HMAC_SHA1, +- "des-hmac-sha1", { 0 }, "DES with HMAC/sha1", +- &krb5int_enc_des, &krb5int_hash_sha1, +- 8, +- krb5int_dk_crypto_length, krb5int_dk_encrypt, krb5int_dk_decrypt, +- krb5int_dk_string_to_key, k5_rand2key_des, +- NULL, /*PRF*/ +- 0, +- ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, +- + /* rc4-hmac uses a 128-bit key, but due to weaknesses in the RC4 cipher, we + * consider its strength degraded and assign it an SSF value of 64. */ + { ENCTYPE_ARCFOUR_HMAC, +diff --git a/src/lib/crypto/krb/s2k_des.c b/src/lib/crypto/krb/s2k_des.c +deleted file mode 100644 +index d5c29befc..000000000 +--- a/src/lib/crypto/krb/s2k_des.c ++++ /dev/null +@@ -1,691 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-/* +- * RFC 3961 and AFS string to key. These are not standard crypto primitives +- * (RFC 3961 string-to-key is implemented in OpenSSL for historical reasons but +- * it doesn't get weak keys right), so we have to implement them here. +- */ +- +-#include +-#include "crypto_int.h" +- +-#undef min +-#define min(a,b) ((a)>(b)?(b):(a)) +- +-/* Compute a CBC checksum of in (with length len) using the specified key and +- * ivec. The result is written into out. */ +-static krb5_error_code +-des_cbc_mac(const unsigned char *keybits, const unsigned char *ivec, +- const unsigned char *in, size_t len, unsigned char *out) +-{ +- krb5_error_code ret; +- krb5_keyblock kb; +- krb5_key key; +- krb5_crypto_iov iov[2]; +- unsigned char zero[8] = { 0, 0, 0, 0, 0, 0, 0, 0 }; +- krb5_data outd, ivecd; +- +- /* Make a key from keybits. */ +- kb.magic = KV5M_KEYBLOCK; +- kb.enctype = ENCTYPE_DES_CBC_CRC; +- kb.length = 8; +- kb.contents = (unsigned char *)keybits; +- ret = krb5_k_create_key(NULL, &kb, &key); +- if (ret) +- return ret; +- +- /* Make iovs for the input data, padding it out to the block size. */ +- iov[0].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[0].data = make_data((unsigned char *)in, len); +- iov[1].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[1].data = make_data(zero, krb5_roundup(len, 8) - len); +- +- /* Make krb5_data structures for the ivec and output. */ +- ivecd = make_data((unsigned char *)ivec, 8); +- outd = make_data(out, 8); +- +- /* Call the cbc_mac operation of the module's DES enc-provider. */ +- ret = krb5int_enc_des.cbc_mac(key, iov, 2, &ivecd, &outd); +- krb5_k_free_key(NULL, key); +- return ret; +-} +- +-/*** AFS string-to-key constants ***/ +- +-/* Initial permutation */ +-static const char IP[] = { +- 58,50,42,34,26,18,10, 2, +- 60,52,44,36,28,20,12, 4, +- 62,54,46,38,30,22,14, 6, +- 64,56,48,40,32,24,16, 8, +- 57,49,41,33,25,17, 9, 1, +- 59,51,43,35,27,19,11, 3, +- 61,53,45,37,29,21,13, 5, +- 63,55,47,39,31,23,15, 7, +-}; +- +-/* Final permutation, FP = IP^(-1) */ +-static const char FP[] = { +- 40, 8,48,16,56,24,64,32, +- 39, 7,47,15,55,23,63,31, +- 38, 6,46,14,54,22,62,30, +- 37, 5,45,13,53,21,61,29, +- 36, 4,44,12,52,20,60,28, +- 35, 3,43,11,51,19,59,27, +- 34, 2,42,10,50,18,58,26, +- 33, 1,41, 9,49,17,57,25, +-}; +- +-/* +- * Permuted-choice 1 from the key bits to yield C and D. +- * Note that bits 8,16... are left out: They are intended for a parity check. +- */ +-static const char PC1_C[] = { +- 57,49,41,33,25,17, 9, +- 1,58,50,42,34,26,18, +- 10, 2,59,51,43,35,27, +- 19,11, 3,60,52,44,36, +-}; +- +-static const char PC1_D[] = { +- 63,55,47,39,31,23,15, +- 7,62,54,46,38,30,22, +- 14, 6,61,53,45,37,29, +- 21,13, 5,28,20,12, 4, +-}; +- +-/* Sequence of shifts used for the key schedule */ +-static const char shifts[] = { +- 1,1,2,2,2,2,2,2,1,2,2,2,2,2,2,1, +-}; +- +-/* Permuted-choice 2, to pick out the bits from the CD array that generate the +- * key schedule */ +-static const char PC2_C[] = { +- 14,17,11,24, 1, 5, +- 3,28,15, 6,21,10, +- 23,19,12, 4,26, 8, +- 16, 7,27,20,13, 2, +-}; +- +-static const char PC2_D[] = { +- 41,52,31,37,47,55, +- 30,40,51,45,33,48, +- 44,49,39,56,34,53, +- 46,42,50,36,29,32, +-}; +- +-/* The E bit-selection table */ +-static const char e[] = { +- 32, 1, 2, 3, 4, 5, +- 4, 5, 6, 7, 8, 9, +- 8, 9,10,11,12,13, +- 12,13,14,15,16,17, +- 16,17,18,19,20,21, +- 20,21,22,23,24,25, +- 24,25,26,27,28,29, +- 28,29,30,31,32, 1, +-}; +- +-/* P is a permutation on the selected combination of the current L and key. */ +-static const char P[] = { +- 16, 7,20,21, +- 29,12,28,17, +- 1,15,23,26, +- 5,18,31,10, +- 2, 8,24,14, +- 32,27, 3, 9, +- 19,13,30, 6, +- 22,11, 4,25, +-}; +- +-/* +- * The 8 selection functions. +- * For some reason, they give a 0-origin +- * index, unlike everything else. +- */ +-static const char S[8][64] = { +- {14, 4,13, 1, 2,15,11, 8, 3,10, 6,12, 5, 9, 0, 7, +- 0,15, 7, 4,14, 2,13, 1,10, 6,12,11, 9, 5, 3, 8, +- 4, 1,14, 8,13, 6, 2,11,15,12, 9, 7, 3,10, 5, 0, +- 15,12, 8, 2, 4, 9, 1, 7, 5,11, 3,14,10, 0, 6,13}, +- +- {15, 1, 8,14, 6,11, 3, 4, 9, 7, 2,13,12, 0, 5,10, +- 3,13, 4, 7,15, 2, 8,14,12, 0, 1,10, 6, 9,11, 5, +- 0,14, 7,11,10, 4,13, 1, 5, 8,12, 6, 9, 3, 2,15, +- 13, 8,10, 1, 3,15, 4, 2,11, 6, 7,12, 0, 5,14, 9}, +- +- {10, 0, 9,14, 6, 3,15, 5, 1,13,12, 7,11, 4, 2, 8, +- 13, 7, 0, 9, 3, 4, 6,10, 2, 8, 5,14,12,11,15, 1, +- 13, 6, 4, 9, 8,15, 3, 0,11, 1, 2,12, 5,10,14, 7, +- 1,10,13, 0, 6, 9, 8, 7, 4,15,14, 3,11, 5, 2,12}, +- +- { 7,13,14, 3, 0, 6, 9,10, 1, 2, 8, 5,11,12, 4,15, +- 13, 8,11, 5, 6,15, 0, 3, 4, 7, 2,12, 1,10,14, 9, +- 10, 6, 9, 0,12,11, 7,13,15, 1, 3,14, 5, 2, 8, 4, +- 3,15, 0, 6,10, 1,13, 8, 9, 4, 5,11,12, 7, 2,14}, +- +- { 2,12, 4, 1, 7,10,11, 6, 8, 5, 3,15,13, 0,14, 9, +- 14,11, 2,12, 4, 7,13, 1, 5, 0,15,10, 3, 9, 8, 6, +- 4, 2, 1,11,10,13, 7, 8,15, 9,12, 5, 6, 3, 0,14, +- 11, 8,12, 7, 1,14, 2,13, 6,15, 0, 9,10, 4, 5, 3}, +- +- {12, 1,10,15, 9, 2, 6, 8, 0,13, 3, 4,14, 7, 5,11, +- 10,15, 4, 2, 7,12, 9, 5, 6, 1,13,14, 0,11, 3, 8, +- 9,14,15, 5, 2, 8,12, 3, 7, 0, 4,10, 1,13,11, 6, +- 4, 3, 2,12, 9, 5,15,10,11,14, 1, 7, 6, 0, 8,13}, +- +- { 4,11, 2,14,15, 0, 8,13, 3,12, 9, 7, 5,10, 6, 1, +- 13, 0,11, 7, 4, 9, 1,10,14, 3, 5,12, 2,15, 8, 6, +- 1, 4,11,13,12, 3, 7,14,10,15, 6, 8, 0, 5, 9, 2, +- 6,11,13, 8, 1, 4,10, 7, 9, 5, 0,15,14, 2, 3,12}, +- +- {13, 2, 8, 4, 6,15,11, 1,10, 9, 3,14, 5, 0,12, 7, +- 1,15,13, 8,10, 3, 7, 4,12, 5, 6,11, 0,14, 9, 2, +- 7,11, 4, 1, 9,12,14, 2, 0, 6,10,13,15, 3, 5, 8, +- 2, 1,14, 7, 4,10, 8,13,15,12, 9, 0, 3, 5, 6,11}, +-}; +- +- +-/* Set up the key schedule from the key. */ +-static void +-afs_crypt_setkey(char *key, char *E, char (*KS)[48]) +-{ +- int i, j, k, t; +- char C[28], D[28]; /* Used to calculate key schedule. */ +- +- /* +- * First, generate C and D by permuting +- * the key. The low order bit of each +- * 8-bit char is not used, so C and D are only 28 +- * bits apiece. +- */ +- for (i = 0; i < 28; i++) { +- C[i] = key[PC1_C[i] - 1]; +- D[i] = key[PC1_D[i] - 1]; +- } +- /* +- * To generate Ki, rotate C and D according +- * to schedule and pick up a permutation +- * using PC2. +- */ +- for (i = 0; i < 16; i++) { +- /* Rotate. */ +- for (k = 0; k < shifts[i]; k++) { +- t = C[0]; +- for (j = 0; j < 28 - 1; j++) +- C[j] = C[j + 1]; +- C[27] = t; +- t = D[0]; +- for (j = 0; j < 28 - 1; j++) +- D[j] = D[j + 1]; +- D[27] = t; +- } +- /* Get Ki. Note C and D are concatenated. */ +- for (j = 0; j < 24; j++) { +- KS[i][j] = C[PC2_C[j]-1]; +- KS[i][j+24] = D[PC2_D[j]-28-1]; +- } +- } +- +- memcpy(E, e, 48); +-} +- +-/* +- * The payoff: encrypt a block. +- */ +- +-static void +-afs_encrypt_block(char *block, char *E, char (*KS)[48]) +-{ +- const long edflag = 0; +- int i, ii; +- int t, j, k; +- char tempL[32]; +- char f[32]; +- char L[64]; /* Current block divided into two halves */ +- char *const R = &L[32]; +- /* The combination of the key and the input, before selection. */ +- char preS[48]; +- +- /* First, permute the bits in the input. */ +- for (j = 0; j < 64; j++) +- L[j] = block[IP[j] - 1]; +- /* Perform an encryption operation 16 times. */ +- for (ii = 0; ii < 16; ii++) { +- /* Set direction. */ +- i = (edflag) ? 15 - ii : ii; +- /* Save the R array, which will be the new L. */ +- memcpy(tempL, R, 32); +- /* Expand R to 48 bits using the E selector; exclusive-or with the +- * current key bits. */ +- for (j = 0; j < 48; j++) +- preS[j] = R[E[j] - 1] ^ KS[i][j]; +- /* +- * The pre-select bits are now considered in 8 groups of 6 bits each. +- * The 8 selection functions map these 6-bit quantities into 4-bit +- * quantities and the results permuted to make an f(R, K). The +- * indexing into the selection functions is peculiar; it could be +- * simplified by rewriting the tables. +- */ +- for (j = 0; j < 8; j++) { +- t = 6 * j; +- k = S[j][(preS[t + 0] << 5) + +- (preS[t + 1] << 3) + +- (preS[t + 2] << 2) + +- (preS[t + 3] << 1) + +- (preS[t + 4] << 0) + +- (preS[t + 5] << 4)]; +- t = 4 * j; +- f[t + 0] = (k >> 3) & 1; +- f[t + 1] = (k >> 2) & 1; +- f[t + 2] = (k >> 1) & 1; +- f[t + 3] = (k >> 0) & 1; +- } +- /* The new R is L ^ f(R, K). The f here has to be permuted first, +- * though. */ +- for (j = 0; j < 32; j++) +- R[j] = L[j] ^ f[P[j] - 1]; +- /* Finally, the new L (the original R) is copied back. */ +- memcpy(L, tempL, 32); +- } +- /* The output L and R are reversed. */ +- for (j = 0; j < 32; j++) { +- t = L[j]; +- L[j] = R[j]; +- R[j] = t; +- } +- /* The final output gets the inverse permutation of the very original. */ +- for (j = 0; j < 64; j++) +- block[j] = L[FP[j] - 1]; +-} +- +-/* iobuf must be at least 16 bytes */ +-static char * +-afs_crypt(const char *pw, const char *salt, char *iobuf) +-{ +- int i, j, c; +- int temp; +- char block[66]; +- char E[48]; +- char KS[16][48]; /* Key schedule, generated from key */ +- +- for (i = 0; i < 66; i++) +- block[i] = 0; +- for (i = 0; (c = *pw) != '\0' && i < 64; pw++){ +- for(j = 0; j < 7; j++, i++) +- block[i] = (c >> (6 - j)) & 01; +- i++; +- } +- +- afs_crypt_setkey(block, E, KS); +- +- for (i = 0; i < 66; i++) +- block[i] = 0; +- +- for (i = 0; i < 2; i++) { +- c = *salt++; +- iobuf[i] = c; +- if (c > 'Z') +- c -= 6; +- if (c > '9') +- c -= 7; +- c -= '.'; +- for (j = 0; j < 6; j++) { +- if ((c >> j) & 01) { +- temp = E[6 * i + j]; +- E[6 * i + j] = E[6 * i + j + 24]; +- E[6 * i + j + 24] = temp; +- } +- } +- } +- +- for (i = 0; i < 25; i++) +- afs_encrypt_block(block, E, KS); +- +- for (i = 0; i < 11; i++) { +- c = 0; +- for (j = 0; j < 6; j++) { +- c <<= 1; +- c |= block[6 * i + j]; +- } +- c += '.'; +- if (c > '9') +- c += 7; +- if (c > 'Z') +- c += 6; +- iobuf[i + 2] = c; +- } +- iobuf[i + 2] = 0; +- if (iobuf[1] == 0) +- iobuf[1] = iobuf[0]; +- return iobuf; +-} +- +-static krb5_error_code +-afs_s2k_oneblock(const krb5_data *data, const krb5_data *salt, +- unsigned char *key_out) +-{ +- unsigned int i; +- unsigned char password[9]; /* trailing nul for crypt() */ +- char afs_crypt_buf[16]; +- +- /* +- * Run afs_crypt and use the first eight returned bytes after the copy of +- * the (fixed) salt. +- * +- * Since the returned bytes are alphanumeric, the output is limited to +- * 2**48 possibilities; for each byte, only 64 possible values can be used. +- */ +- +- memset(password, 0, sizeof(password)); +- if (salt->length > 0) +- memcpy(password, salt->data, min(salt->length, 8)); +- for (i = 0; i < 8; i++) { +- if (isupper(password[i])) +- password[i] = tolower(password[i]); +- } +- for (i = 0; i < data->length; i++) +- password[i] ^= data->data[i]; +- for (i = 0; i < 8; i++) { +- if (password[i] == '\0') +- password[i] = 'X'; +- } +- password[8] = '\0'; +- /* Out-of-bounds salt characters are equivalent to a salt string +- * of "p1". */ +- strncpy((char *)key_out, +- (char *)afs_crypt((char *)password, "#~", afs_crypt_buf) + 2, 8); +- for (i = 0; i < 8; i++) +- key_out[i] <<= 1; +- /* Fix up key parity again. */ +- k5_des_fixup_key_parity(key_out); +- zap(password, sizeof(password)); +- return 0; +-} +- +-static krb5_error_code +-afs_s2k_multiblock(const krb5_data *data, const krb5_data *salt, +- unsigned char *key_out) +-{ +- krb5_error_code ret; +- unsigned char ivec[8], tkey[8], *password; +- size_t pw_len = salt->length + data->length; +- unsigned int i, j; +- +- /* Do a CBC checksum, twice, and use the result as the new key. */ +- +- password = malloc(pw_len); +- if (!password) +- return ENOMEM; +- +- if (data->length > 0) +- memcpy(password, data->data, data->length); +- for (i = data->length, j = 0; j < salt->length; i++, j++) { +- password[i] = salt->data[j]; +- if (isupper(password[i])) +- password[i] = tolower(password[i]); +- } +- +- memcpy(ivec, "kerberos", sizeof(ivec)); +- memcpy(tkey, ivec, sizeof(tkey)); +- k5_des_fixup_key_parity(tkey); +- ret = des_cbc_mac(tkey, ivec, password, pw_len, tkey); +- if (ret) +- goto cleanup; +- +- memcpy(ivec, tkey, sizeof(ivec)); +- k5_des_fixup_key_parity(tkey); +- ret = des_cbc_mac(tkey, ivec, password, pw_len, key_out); +- if (ret) +- goto cleanup; +- k5_des_fixup_key_parity(key_out); +- +-cleanup: +- zapfree(password, pw_len); +- return ret; +-} +- +-static krb5_error_code +-afs_s2k(const krb5_data *data, const krb5_data *salt, unsigned char *key_out) +-{ +- if (data->length <= 8) +- return afs_s2k_oneblock(data, salt, key_out); +- else +- return afs_s2k_multiblock(data, salt, key_out); +-} +- +-static krb5_error_code +-des_s2k(const krb5_data *pw, const krb5_data *salt, unsigned char *key_out) +-{ +- union { +- /* 8 "forward" bytes, 8 "reverse" bytes */ +- unsigned char uc[16]; +- krb5_ui_4 ui[4]; +- } temp; +- unsigned int i; +- krb5_ui_4 x, y, z; +- unsigned char *p, *copy; +- size_t copylen; +- krb5_error_code ret; +- +- /* As long as the architecture is big-endian or little-endian, it +- doesn't matter which it is. Think of it as reversing the +- bytes, and also reversing the bits within each byte. But this +- current algorithm is dependent on having four 8-bit char values +- exactly overlay a 32-bit integral type. */ +- if (sizeof(temp.uc) != sizeof(temp.ui) +- || (unsigned char)~0 != 0xFF +- || (krb5_ui_4)~(krb5_ui_4)0 != 0xFFFFFFFF +- || (temp.uc[0] = 1, temp.uc[1] = 2, temp.uc[2] = 3, temp.uc[3] = 4, +- !(temp.ui[0] == 0x01020304 +- || temp.ui[0] == 0x04030201))) +- abort(); +-#define FETCH4(VAR, IDX) VAR = temp.ui[IDX/4] +-#define PUT4(VAR, IDX) temp.ui[IDX/4] = VAR +- +- copylen = pw->length + salt->length; +- /* Don't need NUL termination, at this point we're treating it as +- a byte array, not a string. */ +- copy = malloc(copylen); +- if (copy == NULL) +- return ENOMEM; +- if (pw->length > 0) +- memcpy(copy, pw->data, pw->length); +- if (salt->length > 0) +- memcpy(copy + pw->length, salt->data, salt->length); +- +- memset(&temp, 0, sizeof(temp)); +- p = temp.uc; +- /* Handle the fan-fold xor operation by splitting the data into +- forward and reverse sections, and combine them later, rather +- than having to do the reversal over and over again. */ +- for (i = 0; i < copylen; i++) { +- *p++ ^= copy[i]; +- if (p == temp.uc+16) { +- p = temp.uc; +-#ifdef PRINT_TEST_VECTORS +- { +- int j; +- printf("after %d input bytes:\nforward block:\t", i+1); +- for (j = 0; j < 8; j++) +- printf(" %02x", temp.uc[j] & 0xff); +- printf("\nreverse block:\t"); +- for (j = 8; j < 16; j++) +- printf(" %02x", temp.uc[j] & 0xff); +- printf("\n"); +- } +-#endif +- } +- } +- +-#ifdef PRINT_TEST_VECTORS +- if (p != temp.uc) { +- int j; +- printf("at end, after %d input bytes:\nforward block:\t", i); +- for (j = 0; j < 8; j++) +- printf(" %02x", temp.uc[j] & 0xff); +- printf("\nreverse block:\t"); +- for (j = 8; j < 16; j++) +- printf(" %02x", temp.uc[j] & 0xff); +- printf("\n"); +- } +-#endif +-#define REVERSE(VAR) \ +- { \ +- krb5_ui_4 old = VAR, temp1 = 0; \ +- int j; \ +- for (j = 0; j < 32; j++) { \ +- temp1 = (temp1 << 1) | (old & 1); \ +- old >>= 1; \ +- } \ +- VAR = temp1; \ +- } +- +- FETCH4 (x, 8); +- FETCH4 (y, 12); +- /* Ignore high bits of each input byte. */ +- x &= 0x7F7F7F7F; +- y &= 0x7F7F7F7F; +- /* Reverse the bit strings -- after this, y is "before" x. */ +- REVERSE (x); +- REVERSE (y); +-#ifdef PRINT_TEST_VECTORS +- { +- int j; +- union { unsigned char uc[4]; krb5_ui_4 ui; } t2; +- printf("after reversal, reversed block:\n\t\t"); +- t2.ui = y; +- for (j = 0; j < 4; j++) +- printf(" %02x", t2.uc[j] & 0xff); +- t2.ui = x; +- for (j = 0; j < 4; j++) +- printf(" %02x", t2.uc[j] & 0xff); +- printf("\n"); +- } +-#endif +- /* Ignored bits are now at the bottom of each byte, where we'll +- * put the parity bits. Good. */ +- FETCH4 (z, 0); +- z &= 0x7F7F7F7F; +- /* Ignored bits for z are at the top of each byte; fix that. */ +- z <<= 1; +- /* Finish the fan-fold xor for these four bytes. */ +- z ^= y; +- PUT4 (z, 0); +- /* Now do the second four bytes. */ +- FETCH4 (z, 4); +- z &= 0x7F7F7F7F; +- /* Ignored bits for z are at the top of each byte; fix that. */ +- z <<= 1; +- /* Finish the fan-fold xor for these four bytes. */ +- z ^= x; +- PUT4 (z, 4); +- +-#ifdef PRINT_TEST_VECTORS +- { +- int j; +- printf("after reversal, combined block:\n\t\t"); +- for (j = 0; j < 8; j++) +- printf(" %02x", temp.uc[j] & 0xff); +- printf("\n"); +- } +-#endif +- +-#define FIXUP(k) (k5_des_fixup_key_parity(k), \ +- k5_des_is_weak_key(k) ? (k[7] ^= 0xF0) : 0) +- +- /* Now temp.cb is the temporary key, with invalid parity. */ +- FIXUP(temp.uc); +- +-#ifdef PRINT_TEST_VECTORS +- { +- int j; +- printf("after fixing parity and weak keys:\n\t\t"); +- for (j = 0; j < 8; j++) +- printf(" %02x", temp.uc[j] & 0xff); +- printf("\n"); +- } +-#endif +- +- ret = des_cbc_mac(temp.uc, temp.uc, copy, copylen, temp.uc); +- if (ret) +- goto cleanup; +- +-#ifdef PRINT_TEST_VECTORS +- { +- int j; +- printf("cbc checksum:\n\t\t"); +- for (j = 0; j < 8; j++) +- printf(" %02x", temp.uc[j] & 0xff); +- printf("\n"); +- } +-#endif +- +- FIXUP(temp.uc); +- +-#ifdef PRINT_TEST_VECTORS +- { +- int j; +- printf("after fixing parity and weak keys:\n\t\t"); +- for (j = 0; j < 8; j++) +- printf(" %02x", temp.uc[j] & 0xff); +- printf("\n"); +- } +-#endif +- +- memcpy(key_out, temp.uc, 8); +- +-cleanup: +- zap(&temp, sizeof(temp)); +- zapfree(copy, copylen); +- return ret; +-} +- +-krb5_error_code +-krb5int_des_string_to_key(const struct krb5_keytypes *ktp, +- const krb5_data *string, const krb5_data *salt, +- const krb5_data *parm, krb5_keyblock *keyblock) +-{ +- int type; +- +- if (parm != NULL) { +- if (parm->length != 1) +- return KRB5_ERR_BAD_S2K_PARAMS; +- type = parm->data[0]; +- if (type != 0 && type != 1) +- return KRB5_ERR_BAD_S2K_PARAMS; +- } else +- type = 0; +- +- /* Use AFS string to key if we were told to. */ +- if (type == 1) +- return afs_s2k(string, salt, keyblock->contents); +- +- return des_s2k(string, salt, keyblock->contents); +-} +diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports +index 90afdf5f7..63804299f 100644 +--- a/src/lib/crypto/libk5crypto.exports ++++ b/src/lib/crypto/libk5crypto.exports +@@ -85,7 +85,6 @@ krb5_k_prf + krb5_k_reference_key + krb5_k_verify_checksum + krb5_k_verify_checksum_iov +-mit_crc32 + krb5int_aes_encrypt + krb5int_aes_decrypt + krb5int_enc_des3 +diff --git a/src/lib/crypto/openssl/enc_provider/Makefile.in b/src/lib/crypto/openssl/enc_provider/Makefile.in +index b9e28c9cd..a9069d22d 100644 +--- a/src/lib/crypto/openssl/enc_provider/Makefile.in ++++ b/src/lib/crypto/openssl/enc_provider/Makefile.in +@@ -3,21 +3,18 @@ BUILDTOP=$(REL)..$(S)..$(S)..$(S).. + LOCALINCLUDES = -I$(srcdir)/../../krb -I$(srcdir)/.. + + STLIBOBJS= \ +- des.o \ + des3.o \ + rc4.o \ + aes.o \ + camellia.o + + OBJS= \ +- $(OUTPRE)des.$(OBJEXT) \ + $(OUTPRE)des3.$(OBJEXT) \ + $(OUTPRE)aes.$(OBJEXT) \ + $(OUTPRE)camellia.$(OBJEXT) \ + $(OUTPRE)rc4.$(OBJEXT) + + SRCS= \ +- $(srcdir)/des.c \ + $(srcdir)/des3.c \ + $(srcdir)/aes.c \ + $(srcdir)/camellia.c \ +diff --git a/src/lib/crypto/openssl/enc_provider/deps b/src/lib/crypto/openssl/enc_provider/deps +index 428fcf6f5..1c28cc842 100644 +--- a/src/lib/crypto/openssl/enc_provider/deps ++++ b/src/lib/crypto/openssl/enc_provider/deps +@@ -1,17 +1,6 @@ + # + # Generated makefile dependencies follow. + # +-des.so des.po $(OUTPRE)des.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +- $(srcdir)/../crypto_mod.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des.c + des3.so des3.po $(OUTPRE)des3.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +diff --git a/src/lib/crypto/openssl/enc_provider/des.c b/src/lib/crypto/openssl/enc_provider/des.c +deleted file mode 100644 +index a662db512..000000000 +--- a/src/lib/crypto/openssl/enc_provider/des.c ++++ /dev/null +@@ -1,218 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/openssl/enc_provider/des.c */ +-/* +- * Copyright (C) 2009 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-#include "crypto_int.h" +-#include +-#include +- +-#define DES_BLOCK_SIZE 8 +-#define DES_KEY_SIZE 8 +-#define DES_KEY_BYTES 7 +- +-static krb5_error_code +-validate(krb5_key key, const krb5_data *ivec, const krb5_crypto_iov *data, +- size_t num_data, krb5_boolean *empty) +-{ +- size_t input_length = iov_total_length(data, num_data, FALSE); +- +- if (key->keyblock.length != DES_KEY_SIZE) +- return(KRB5_BAD_KEYSIZE); +- if ((input_length%DES_BLOCK_SIZE) != 0) +- return(KRB5_BAD_MSIZE); +- if (ivec && (ivec->length != 8)) +- return(KRB5_BAD_MSIZE); +- +- *empty = (input_length == 0); +- return 0; +-} +- +-static krb5_error_code +-k5_des_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, +- size_t num_data) +-{ +- int ret, olen = DES_BLOCK_SIZE; +- unsigned char iblock[DES_BLOCK_SIZE], oblock[DES_BLOCK_SIZE]; +- struct iov_cursor cursor; +- EVP_CIPHER_CTX *ctx; +- krb5_boolean empty; +- +- ret = validate(key, ivec, data, num_data, &empty); +- if (ret != 0 || empty) +- return ret; +- +- ctx = EVP_CIPHER_CTX_new(); +- if (ctx == NULL) +- return ENOMEM; +- +- ret = EVP_EncryptInit_ex(ctx, EVP_des_cbc(), NULL, +- key->keyblock.contents, (ivec && ivec->data) ? (unsigned char*)ivec->data : NULL); +- if (!ret) { +- EVP_CIPHER_CTX_free(ctx); +- return KRB5_CRYPTO_INTERNAL; +- } +- +- EVP_CIPHER_CTX_set_padding(ctx, 0); +- +- k5_iov_cursor_init(&cursor, data, num_data, DES_BLOCK_SIZE, FALSE); +- while (k5_iov_cursor_get(&cursor, iblock)) { +- ret = EVP_EncryptUpdate(ctx, oblock, &olen, iblock, DES_BLOCK_SIZE); +- if (!ret) +- break; +- k5_iov_cursor_put(&cursor, oblock); +- } +- +- if (ivec != NULL) +- memcpy(ivec->data, oblock, DES_BLOCK_SIZE); +- +- EVP_CIPHER_CTX_free(ctx); +- +- zap(iblock, sizeof(iblock)); +- zap(oblock, sizeof(oblock)); +- +- if (ret != 1) +- return KRB5_CRYPTO_INTERNAL; +- return 0; +-} +- +-static krb5_error_code +-k5_des_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, +- size_t num_data) +-{ +- int ret, olen = DES_BLOCK_SIZE; +- unsigned char iblock[DES_BLOCK_SIZE], oblock[DES_BLOCK_SIZE]; +- struct iov_cursor cursor; +- EVP_CIPHER_CTX *ctx; +- krb5_boolean empty; +- +- ret = validate(key, ivec, data, num_data, &empty); +- if (ret != 0 || empty) +- return ret; +- +- ctx = EVP_CIPHER_CTX_new(); +- if (ctx == NULL) +- return ENOMEM; +- +- ret = EVP_DecryptInit_ex(ctx, EVP_des_cbc(), NULL, +- key->keyblock.contents, +- (ivec) ? (unsigned char*)ivec->data : NULL); +- if (!ret) { +- EVP_CIPHER_CTX_free(ctx); +- return KRB5_CRYPTO_INTERNAL; +- } +- +- EVP_CIPHER_CTX_set_padding(ctx,0); +- +- k5_iov_cursor_init(&cursor, data, num_data, DES_BLOCK_SIZE, FALSE); +- while (k5_iov_cursor_get(&cursor, iblock)) { +- ret = EVP_DecryptUpdate(ctx, oblock, &olen, iblock, DES_BLOCK_SIZE); +- if (!ret) +- break; +- k5_iov_cursor_put(&cursor, oblock); +- } +- +- if (ivec != NULL) +- memcpy(ivec->data, iblock, DES_BLOCK_SIZE); +- +- EVP_CIPHER_CTX_free(ctx); +- +- zap(iblock, sizeof(iblock)); +- zap(oblock, sizeof(oblock)); +- +- if (ret != 1) +- return KRB5_CRYPTO_INTERNAL; +- return 0; +-} +- +-static krb5_error_code +-k5_des_cbc_mac(krb5_key key, const krb5_crypto_iov *data, size_t num_data, +- const krb5_data *ivec, krb5_data *output) +-{ +- int ret; +- struct iov_cursor cursor; +- DES_cblock blockY, blockB; +- DES_key_schedule sched; +- krb5_boolean empty; +- +- ret = validate(key, ivec, data, num_data, &empty); +- if (ret != 0) +- return ret; +- +- if (output->length != DES_BLOCK_SIZE) +- return KRB5_BAD_MSIZE; +- +- if (DES_set_key((DES_cblock *)key->keyblock.contents, &sched) != 0) +- return KRB5_CRYPTO_INTERNAL; +- +- if (ivec != NULL) +- memcpy(blockY, ivec->data, DES_BLOCK_SIZE); +- else +- memset(blockY, 0, DES_BLOCK_SIZE); +- +- k5_iov_cursor_init(&cursor, data, num_data, DES_BLOCK_SIZE, FALSE); +- while (k5_iov_cursor_get(&cursor, blockB)) { +- store_64_n(load_64_n(blockB) ^ load_64_n(blockY), blockB); +- DES_ecb_encrypt(&blockB, &blockY, &sched, 1); +- } +- +- memcpy(output->data, blockY, DES_BLOCK_SIZE); +- return 0; +-} +- +-const struct krb5_enc_provider krb5int_enc_des = { +- DES_BLOCK_SIZE, +- DES_KEY_BYTES, DES_KEY_SIZE, +- k5_des_encrypt, +- k5_des_decrypt, +- k5_des_cbc_mac, +- krb5int_des_init_state, +- krb5int_default_free_state +-}; +diff --git a/src/lib/crypto/openssl/hash_provider/Makefile.in b/src/lib/crypto/openssl/hash_provider/Makefile.in +index 7762e20a5..f7245fbd1 100644 +--- a/src/lib/crypto/openssl/hash_provider/Makefile.in ++++ b/src/lib/crypto/openssl/hash_provider/Makefile.in +@@ -2,15 +2,11 @@ mydir=lib$(S)crypto$(S)openssl$(S)hash_provider + BUILDTOP=$(REL)..$(S)..$(S)..$(S).. + LOCALINCLUDES = -I$(srcdir)/../../krb -I$(srcdir)/.. + +-STLIBOBJS= \ +- hash_crc32.o \ +- hash_evp.o ++STLIBOBJS= hash_evp.o + +-OBJS= $(OUTPRE)hash_crc32.$(OBJEXT) \ +- $(OUTPRE)hash_evp.$(OBJEXT) ++OBJS= $(OUTPRE)hash_evp.$(OBJEXT) + +-SRCS= $(srcdir)/hash_crc32.c \ +- $(srcdir)/hash_evp.c ++SRCS= $(srcdir)/hash_evp.c + + all-unix: all-libobjs + +diff --git a/src/lib/crypto/openssl/hash_provider/deps b/src/lib/crypto/openssl/hash_provider/deps +index 87dd02012..690574cab 100644 +--- a/src/lib/crypto/openssl/hash_provider/deps ++++ b/src/lib/crypto/openssl/hash_provider/deps +@@ -1,18 +1,6 @@ + # + # Generated makefile dependencies follow. + # +-hash_crc32.so hash_crc32.po $(OUTPRE)hash_crc32.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(srcdir)/../crypto_mod.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- hash_crc32.c + hash_evp.so hash_evp.po $(OUTPRE)hash_evp.$(OBJEXT): \ + $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ + $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +diff --git a/src/lib/crypto/openssl/hash_provider/hash_crc32.c b/src/lib/crypto/openssl/hash_provider/hash_crc32.c +deleted file mode 100644 +index 4013843ed..000000000 +--- a/src/lib/crypto/openssl/hash_provider/hash_crc32.c ++++ /dev/null +@@ -1,56 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-#include "crypto_int.h" +- +-static krb5_error_code +-k5_crc32_hash(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) +-{ +- unsigned long c; +- unsigned int i; +- +- if (output->length != CRC32_CKSUM_LENGTH) +- return(KRB5_CRYPTO_INTERNAL); +- +- c = 0; +- for (i = 0; i < num_data; i++) { +- const krb5_crypto_iov *iov = &data[i]; +- +- if (SIGN_IOV(iov)) +- mit_crc32(iov->data.data, iov->data.length, &c); +- } +- +- store_32_le(c, output->data); +- return(0); +-} +- +-const struct krb5_hash_provider krb5int_hash_crc32 = { +- "CRC32", +- CRC32_CKSUM_LENGTH, +- 1, +- k5_crc32_hash +-}; +diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c +index 5baa6cecf..439ae6aeb 100644 +--- a/src/lib/gssapi/krb5/accept_sec_context.c ++++ b/src/lib/gssapi/krb5/accept_sec_context.c +@@ -1011,9 +1011,6 @@ kg_accept_krb5(minor_status, context_handle, + } + + switch (negotiated_etype) { +- case ENCTYPE_DES_CBC_MD5: +- case ENCTYPE_DES_CBC_MD4: +- case ENCTYPE_DES_CBC_CRC: + case ENCTYPE_DES3_CBC_SHA1: + case ENCTYPE_ARCFOUR_HMAC: + case ENCTYPE_ARCFOUR_HMAC_EXP: +diff --git a/src/lib/gssapi/krb5/gssapiP_krb5.h b/src/lib/gssapi/krb5/gssapiP_krb5.h +index e92be88b4..2647434ba 100644 +--- a/src/lib/gssapi/krb5/gssapiP_krb5.h ++++ b/src/lib/gssapi/krb5/gssapiP_krb5.h +@@ -120,17 +120,17 @@ extern const gss_OID_set kg_all_mechs; + /* These are to be stored in little-endian order, i.e., des-mac is + stored as 02 00. */ + enum sgn_alg { +- SGN_ALG_DES_MAC_MD5 = 0x0000, +- SGN_ALG_MD2_5 = 0x0001, +- SGN_ALG_DES_MAC = 0x0002, +- SGN_ALG_3 = 0x0003, /* not published */ ++ /* SGN_ALG_DES_MAC_MD5 = 0x0000, */ ++ /* SGN_ALG_MD2_5 = 0x0001, */ ++ /* SGN_ALG_DES_MAC = 0x0002, */ ++ /* SGN_ALG_3 = 0x0003, /\* not published *\/ */ + SGN_ALG_HMAC_MD5 = 0x0011, /* microsoft w2k; */ + SGN_ALG_HMAC_SHA1_DES3_KD = 0x0004 + }; + enum seal_alg { + SEAL_ALG_NONE = 0xffff, +- SEAL_ALG_DES = 0x0000, +- SEAL_ALG_1 = 0x0001, /* not published */ ++ /* SEAL_ALG_DES = 0x0000, */ ++ /* SEAL_ALG_1 = 0x0001, /\* not published *\/ */ + SEAL_ALG_MICROSOFT_RC4 = 0x0010, /* microsoft w2k; */ + SEAL_ALG_DES3KD = 0x0002 + }; +@@ -147,12 +147,12 @@ enum seal_alg { + #define KG_USAGE_INITIATOR_SIGN 25 + + enum qop { +- GSS_KRB5_INTEG_C_QOP_MD5 = 0x0001, /* *partial* MD5 = "MD2.5" */ +- GSS_KRB5_INTEG_C_QOP_DES_MD5 = 0x0002, +- GSS_KRB5_INTEG_C_QOP_DES_MAC = 0x0003, ++ /* GSS_KRB5_INTEG_C_QOP_MD5 = 0x0001, */ ++ /* GSS_KRB5_INTEG_C_QOP_DES_MD5 = 0x0002, */ ++ /* GSS_KRB5_INTEG_C_QOP_DES_MAC = 0x0003, */ + GSS_KRB5_INTEG_C_QOP_HMAC_SHA1 = 0x0004, + GSS_KRB5_INTEG_C_QOP_MASK = 0x00ff, +- GSS_KRB5_CONF_C_QOP_DES = 0x0100, ++ /* GSS_KRB5_CONF_C_QOP_DES = 0x0100, */ + GSS_KRB5_CONF_C_QOP_DES3_KD = 0x0200, + GSS_KRB5_CONF_C_QOP_MASK = 0xff00 + }; +diff --git a/src/lib/gssapi/krb5/k5seal.c b/src/lib/gssapi/krb5/k5seal.c +index 4da531b58..d1cdce486 100644 +--- a/src/lib/gssapi/krb5/k5seal.c ++++ b/src/lib/gssapi/krb5/k5seal.c +@@ -71,7 +71,6 @@ make_seal_token_v1 (krb5_context context, + char *data_ptr; + krb5_data plaind; + krb5_checksum md5cksum; +- krb5_checksum cksum; + /* msglen contains the message length + * we are signing/encrypting. tmsglen + * contains the length of the message +@@ -137,12 +136,8 @@ make_seal_token_v1 (krb5_context context, + + /* pad the plaintext, encrypt if needed, and stick it in the token */ + +- /* initialize the the cksum */ ++ /* initialize the the checksum */ + switch (signalg) { +- case SGN_ALG_DES_MAC_MD5: +- case SGN_ALG_MD2_5: +- md5cksum.checksum_type = CKSUMTYPE_RSA_MD5; +- break; + case SGN_ALG_HMAC_SHA1_DES3_KD: + md5cksum.checksum_type = CKSUMTYPE_HMAC_SHA1_DES3; + break; +@@ -152,7 +147,6 @@ make_seal_token_v1 (krb5_context context, + sign_usage = 15; + break; + default: +- case SGN_ALG_DES_MAC: + abort (); + } + +@@ -203,26 +197,6 @@ make_seal_token_v1 (krb5_context context, + return(code); + } + switch(signalg) { +- case SGN_ALG_DES_MAC_MD5: +- case 3: +- +- code = kg_encrypt_inplace(context, seq, KG_USAGE_SEAL, +- (g_OID_equal(oid, gss_mech_krb5_old) ? +- seq->keyblock.contents : NULL), +- md5cksum.contents, 16); +- if (code) { +- krb5_free_checksum_contents(context, &md5cksum); +- xfree (plain); +- gssalloc_free(t); +- return code; +- } +- +- cksum.length = cksum_size; +- cksum.contents = md5cksum.contents + 16 - cksum.length; +- +- memcpy(ptr+14, cksum.contents, cksum.length); +- break; +- + case SGN_ALG_HMAC_SHA1_DES3_KD: + /* + * Using key derivation, the call to krb5_c_make_checksum +diff --git a/src/lib/gssapi/krb5/k5sealiov.c b/src/lib/gssapi/krb5/k5sealiov.c +index 88caa856f..9bb2ee109 100644 +--- a/src/lib/gssapi/krb5/k5sealiov.c ++++ b/src/lib/gssapi/krb5/k5sealiov.c +@@ -145,10 +145,6 @@ make_seal_token_v1_iov(krb5_context context, + + /* initialize the checksum */ + switch (ctx->signalg) { +- case SGN_ALG_DES_MAC_MD5: +- case SGN_ALG_MD2_5: +- md5cksum.checksum_type = CKSUMTYPE_RSA_MD5; +- break; + case SGN_ALG_HMAC_SHA1_DES3_KD: + md5cksum.checksum_type = CKSUMTYPE_HMAC_SHA1_DES3; + break; +@@ -158,7 +154,6 @@ make_seal_token_v1_iov(krb5_context context, + sign_usage = 15; + break; + default: +- case SGN_ALG_DES_MAC: + abort (); + } + +@@ -183,21 +178,6 @@ make_seal_token_v1_iov(krb5_context context, + goto cleanup; + + switch (ctx->signalg) { +- case SGN_ALG_DES_MAC_MD5: +- case SGN_ALG_3: +- code = kg_encrypt_inplace(context, ctx->seq, KG_USAGE_SEAL, +- (g_OID_equal(ctx->mech_used, +- gss_mech_krb5_old) ? +- ctx->seq->keyblock.contents : NULL), +- md5cksum.contents, 16); +- if (code != 0) +- goto cleanup; +- +- cksum.length = ctx->cksum_size; +- cksum.contents = md5cksum.contents + 16 - cksum.length; +- +- memcpy(ptr + 14, cksum.contents, cksum.length); +- break; + case SGN_ALG_HMAC_SHA1_DES3_KD: + assert(md5cksum.length == ctx->cksum_size); + memcpy(ptr + 14, md5cksum.contents, md5cksum.length); +diff --git a/src/lib/gssapi/krb5/k5unseal.c b/src/lib/gssapi/krb5/k5unseal.c +index 57720c2ea..9b183bc33 100644 +--- a/src/lib/gssapi/krb5/k5unseal.c ++++ b/src/lib/gssapi/krb5/k5unseal.c +@@ -76,7 +76,6 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, + int sealalg; + int bad_pad = 0; + gss_buffer_desc token; +- krb5_checksum cksum; + krb5_checksum md5cksum; + krb5_data plaind; + char *data_ptr; +@@ -132,7 +131,6 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, + but few enough that we can try them all. */ + + if ((ctx->sealalg == SEAL_ALG_NONE && signalg > 1) || +- (ctx->sealalg == SEAL_ALG_1 && signalg != SGN_ALG_3) || + (ctx->sealalg == SEAL_ALG_DES3KD && + signalg != SGN_ALG_HMAC_SHA1_DES3_KD)|| + (ctx->sealalg == SEAL_ALG_MICROSOFT_RC4 && +@@ -142,16 +140,11 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, + } + + switch (signalg) { +- case SGN_ALG_DES_MAC_MD5: +- case SGN_ALG_MD2_5: + case SGN_ALG_HMAC_MD5: + cksum_len = 8; + if (toktype != KG_TOK_SEAL_MSG) + sign_usage = 15; + break; +- case SGN_ALG_3: +- cksum_len = 16; +- break; + case SGN_ALG_HMAC_SHA1_DES3_KD: + cksum_len = 20; + break; +@@ -260,12 +253,6 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, + + /* initialize the the cksum */ + switch (signalg) { +- case SGN_ALG_DES_MAC_MD5: +- case SGN_ALG_MD2_5: +- case SGN_ALG_DES_MAC: +- case SGN_ALG_3: +- md5cksum.checksum_type = CKSUMTYPE_RSA_MD5; +- break; + case SGN_ALG_HMAC_MD5: + md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; + break; +@@ -282,105 +269,6 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, + md5cksum.length = sumlen; + + switch (signalg) { +- case SGN_ALG_DES_MAC_MD5: +- case SGN_ALG_3: +- /* compute the checksum of the message */ +- +- /* 8 = bytes of token body to be checksummed according to spec */ +- +- if (! (data_ptr = xmalloc(8 + plainlen))) { +- if (sealalg != 0xffff) +- xfree(plain); +- if (toktype == KG_TOK_SEAL_MSG) +- gssalloc_free(token.value); +- *minor_status = ENOMEM; +- return(GSS_S_FAILURE); +- } +- +- (void) memcpy(data_ptr, ptr-2, 8); +- +- (void) memcpy(data_ptr+8, plain, plainlen); +- +- plaind.length = 8 + plainlen; +- plaind.data = data_ptr; +- code = krb5_k_make_checksum(context, md5cksum.checksum_type, +- ctx->seq, sign_usage, +- &plaind, &md5cksum); +- xfree(data_ptr); +- +- if (code) { +- if (toktype == KG_TOK_SEAL_MSG) +- gssalloc_free(token.value); +- *minor_status = code; +- return(GSS_S_FAILURE); +- } +- +- code = kg_encrypt_inplace(context, ctx->seq, KG_USAGE_SEAL, +- (g_OID_equal(ctx->mech_used, +- gss_mech_krb5_old) ? +- ctx->seq->keyblock.contents : NULL), +- md5cksum.contents, 16); +- if (code) { +- krb5_free_checksum_contents(context, &md5cksum); +- if (toktype == KG_TOK_SEAL_MSG) +- gssalloc_free(token.value); +- *minor_status = code; +- return GSS_S_FAILURE; +- } +- +- if (signalg == 0) +- cksum.length = 8; +- else +- cksum.length = 16; +- cksum.contents = md5cksum.contents + 16 - cksum.length; +- +- code = k5_bcmp(cksum.contents, ptr + 14, cksum.length); +- break; +- +- case SGN_ALG_MD2_5: +- if (!ctx->seed_init && +- (code = kg_make_seed(context, ctx->subkey, ctx->seed))) { +- krb5_free_checksum_contents(context, &md5cksum); +- if (sealalg != 0xffff) +- xfree(plain); +- if (toktype == KG_TOK_SEAL_MSG) +- gssalloc_free(token.value); +- *minor_status = code; +- return GSS_S_FAILURE; +- } +- +- if (! (data_ptr = xmalloc(sizeof(ctx->seed) + 8 + plainlen))) { +- krb5_free_checksum_contents(context, &md5cksum); +- if (sealalg == 0) +- xfree(plain); +- if (toktype == KG_TOK_SEAL_MSG) +- gssalloc_free(token.value); +- *minor_status = ENOMEM; +- return(GSS_S_FAILURE); +- } +- (void) memcpy(data_ptr, ptr-2, 8); +- (void) memcpy(data_ptr+8, ctx->seed, sizeof(ctx->seed)); +- (void) memcpy(data_ptr+8+sizeof(ctx->seed), plain, plainlen); +- plaind.length = 8 + sizeof(ctx->seed) + plainlen; +- plaind.data = data_ptr; +- krb5_free_checksum_contents(context, &md5cksum); +- code = krb5_k_make_checksum(context, md5cksum.checksum_type, +- ctx->seq, sign_usage, +- &plaind, &md5cksum); +- xfree(data_ptr); +- +- if (code) { +- if (sealalg == 0) +- xfree(plain); +- if (toktype == KG_TOK_SEAL_MSG) +- gssalloc_free(token.value); +- *minor_status = code; +- return(GSS_S_FAILURE); +- } +- +- code = k5_bcmp(md5cksum.contents, ptr + 14, 8); +- /* Falls through to defective-token?? */ +- + default: + *minor_status = 0; + return(GSS_S_DEFECTIVE_TOKEN); +diff --git a/src/lib/gssapi/krb5/k5unsealiov.c b/src/lib/gssapi/krb5/k5unsealiov.c +index f15d2db69..85a9574f3 100644 +--- a/src/lib/gssapi/krb5/k5unsealiov.c ++++ b/src/lib/gssapi/krb5/k5unsealiov.c +@@ -44,7 +44,6 @@ kg_unseal_v1_iov(krb5_context context, + unsigned char *ptr; + int sealalg; + int signalg; +- krb5_checksum cksum; + krb5_checksum md5cksum; + size_t cksum_len = 0; + size_t conflen = 0; +@@ -54,8 +53,8 @@ kg_unseal_v1_iov(krb5_context context, + size_t sumlen; + krb5_keyusage sign_usage = KG_USAGE_SIGN; + +- md5cksum.length = cksum.length = 0; +- md5cksum.contents = cksum.contents = NULL; ++ md5cksum.length = 0; ++ md5cksum.contents = NULL; + + header = kg_locate_header_iov(iov, iov_count, toktype); + assert(header != NULL); +@@ -103,7 +102,6 @@ kg_unseal_v1_iov(krb5_context context, + } + + if ((ctx->sealalg == SEAL_ALG_NONE && signalg > 1) || +- (ctx->sealalg == SEAL_ALG_1 && signalg != SGN_ALG_3) || + (ctx->sealalg == SEAL_ALG_DES3KD && + signalg != SGN_ALG_HMAC_SHA1_DES3_KD)|| + (ctx->sealalg == SEAL_ALG_MICROSOFT_RC4 && +@@ -113,16 +111,11 @@ kg_unseal_v1_iov(krb5_context context, + } + + switch (signalg) { +- case SGN_ALG_DES_MAC_MD5: +- case SGN_ALG_MD2_5: + case SGN_ALG_HMAC_MD5: + cksum_len = 8; + if (toktype != KG_TOK_WRAP_MSG) + sign_usage = 15; + break; +- case SGN_ALG_3: +- cksum_len = 16; +- break; + case SGN_ALG_HMAC_SHA1_DES3_KD: + cksum_len = 20; + break; +@@ -189,12 +182,6 @@ kg_unseal_v1_iov(krb5_context context, + /* initialize the checksum */ + + switch (signalg) { +- case SGN_ALG_DES_MAC_MD5: +- case SGN_ALG_MD2_5: +- case SGN_ALG_DES_MAC: +- case SGN_ALG_3: +- md5cksum.checksum_type = CKSUMTYPE_RSA_MD5; +- break; + case SGN_ALG_HMAC_MD5: + md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; + break; +@@ -223,23 +210,6 @@ kg_unseal_v1_iov(krb5_context context, + } + + switch (signalg) { +- case SGN_ALG_DES_MAC_MD5: +- case SGN_ALG_3: +- code = kg_encrypt_inplace(context, ctx->seq, KG_USAGE_SEAL, +- (g_OID_equal(ctx->mech_used, +- gss_mech_krb5_old) ? +- ctx->seq->keyblock.contents : NULL), +- md5cksum.contents, 16); +- if (code != 0) { +- retval = GSS_S_FAILURE; +- goto cleanup; +- } +- +- cksum.length = cksum_len; +- cksum.contents = md5cksum.contents + 16 - cksum.length; +- +- code = k5_bcmp(cksum.contents, ptr + 14, cksum.length); +- break; + case SGN_ALG_HMAC_SHA1_DES3_KD: + case SGN_ALG_HMAC_MD5: + code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); +diff --git a/src/lib/gssapi/krb5/util_crypt.c b/src/lib/gssapi/krb5/util_crypt.c +index 0cebde12a..80954aff7 100644 +--- a/src/lib/gssapi/krb5/util_crypt.c ++++ b/src/lib/gssapi/krb5/util_crypt.c +@@ -74,27 +74,6 @@ kg_copy_keys(krb5_context context, krb5_gss_ctx_id_rec *ctx, krb5_key subkey) + return 0; + } + +-static krb5_error_code +-kg_derive_des_enc_key(krb5_context context, krb5_key subkey, krb5_key *out) +-{ +- krb5_error_code code; +- krb5_keyblock *keyblock; +- unsigned int i; +- +- *out = NULL; +- +- code = krb5_k_key_keyblock(context, subkey, &keyblock); +- if (code != 0) +- return code; +- +- for (i = 0; i < keyblock->length; i++) +- keyblock->contents[i] ^= 0xF0; +- +- code = krb5_k_create_key(context, keyblock, out); +- krb5_free_keyblock(context, keyblock); +- return code; +-} +- + krb5_error_code + kg_setup_keys(krb5_context context, krb5_gss_ctx_id_rec *ctx, krb5_key subkey, + krb5_cksumtype *cksumtype) +@@ -118,26 +97,6 @@ kg_setup_keys(krb5_context context, krb5_gss_ctx_id_rec *ctx, krb5_key subkey, + return code; + + switch (subkey->keyblock.enctype) { +- case ENCTYPE_DES_CBC_MD5: +- case ENCTYPE_DES_CBC_MD4: +- case ENCTYPE_DES_CBC_CRC: +- krb5_k_free_key(context, ctx->seq); +- code = krb5_k_create_key(context, &subkey->keyblock, &ctx->seq); +- if (code != 0) +- return code; +- +- krb5_k_free_key(context, ctx->enc); +- code = kg_derive_des_enc_key(context, subkey, &ctx->enc); +- if (code != 0) +- return code; +- +- ctx->enc->keyblock.enctype = ENCTYPE_DES_CBC_RAW; +- ctx->seq->keyblock.enctype = ENCTYPE_DES_CBC_RAW; +- ctx->signalg = SGN_ALG_DES_MAC_MD5; +- ctx->cksum_size = 8; +- ctx->sealalg = SEAL_ALG_DES; +- +- break; + case ENCTYPE_DES3_CBC_SHA1: + code = kg_copy_keys(context, ctx, subkey); + if (code != 0) +diff --git a/src/lib/kadm5/kadm_rpc_xdr.c b/src/lib/kadm5/kadm_rpc_xdr.c +index 745ee857e..f22ea7f1f 100644 +--- a/src/lib/kadm5/kadm_rpc_xdr.c ++++ b/src/lib/kadm5/kadm_rpc_xdr.c +@@ -1109,16 +1109,6 @@ xdr_krb5_octet(XDR *xdrs, krb5_octet *objp) + bool_t + xdr_krb5_enctype(XDR *xdrs, krb5_enctype *objp) + { +- /* +- * This used to be xdr_krb5_keytype, but keytypes and enctypes have +- * been merged into only enctypes. However, randkey_principal +- * already ensures that only a key of ENCTYPE_DES_CBC_CRC will be +- * returned to v1 clients, and ENCTYPE_DES_CBC_CRC has the same +- * value as KEYTYPE_DES used too, which is what all v1 clients +- * expect. Therefore, IMHO, just encoding whatever enctype we get +- * is safe. +- */ +- + if (!xdr_int32(xdrs, (int32_t *) objp)) + return (FALSE); + return (TRUE); +diff --git a/src/lib/krb5/ccache/cc_mslsa.c b/src/lib/krb5/ccache/cc_mslsa.c +index 0d00c86d4..4367322b7 100644 +--- a/src/lib/krb5/ccache/cc_mslsa.c ++++ b/src/lib/krb5/ccache/cc_mslsa.c +@@ -1103,13 +1103,14 @@ GetMSTGT(krb5_context context, HANDLE LogonHandle, ULONG PackageId, KERB_EXTERNA + } + + if (krb5_get_tgs_ktypes(context, NULL, &etype_list)) { +- ptr = etype_list = NULL; +- etype = ENCTYPE_DES_CBC_CRC; +- } else { +- ptr = etype_list + 1; +- etype = *etype_list; ++ /* No enctypes - nothing we can do. */ ++ bIsLsaError = TRUE; ++ goto cleanup; + } + ++ ptr = etype_list + 1; ++ etype = *etype_list; ++ + while ( etype ) { + // Try once more but this time specify the Encryption Type + // (This will not store the retrieved tickets in the LSA cache unless +diff --git a/src/lib/krb5/krb/auth_con.c b/src/lib/krb5/krb/auth_con.c +index 1dfce631c..aa90454f3 100644 +--- a/src/lib/krb5/krb/auth_con.c ++++ b/src/lib/krb5/krb/auth_con.c +@@ -313,28 +313,11 @@ krb5_auth_con_getremoteseqnumber(krb5_context context, krb5_auth_context auth_co + krb5_error_code KRB5_CALLCONV + krb5_auth_con_initivector(krb5_context context, krb5_auth_context auth_context) + { +- krb5_error_code ret; +- krb5_enctype enctype; +- + if (auth_context->key == NULL) + return EINVAL; +- ret = krb5_c_init_state(context, &auth_context->key->keyblock, +- KRB5_KEYUSAGE_KRB_PRIV_ENCPART, +- &auth_context->cstate); +- if (ret) +- return ret; +- +- /* +- * Historically we used a zero-filled buffer of the enctype block size. +- * This matches every existing enctype except RC4 (which has a block size +- * of 1) and des-cbc-crc (which uses the key instead of a zero-filled +- * buffer). Special-case des-cbc-crc to remain interoperable. +- */ +- enctype = krb5_k_key_enctype(context, auth_context->key); +- if (enctype == ENCTYPE_DES_CBC_CRC) +- zap(auth_context->cstate.data, auth_context->cstate.length); +- +- return 0; ++ return krb5_c_init_state(context, &auth_context->key->keyblock, ++ KRB5_KEYUSAGE_KRB_PRIV_ENCPART, ++ &auth_context->cstate); + } + + krb5_error_code +diff --git a/src/lib/krb5/krb/gic_keytab.c b/src/lib/krb5/krb/gic_keytab.c +index e82f42581..1d70cf46f 100644 +--- a/src/lib/krb5/krb/gic_keytab.c ++++ b/src/lib/krb5/krb/gic_keytab.c +@@ -130,10 +130,6 @@ lookup_etypes_for_keytab(krb5_context context, krb5_keytab keytab, + } + etypes = p; + etypes[count++] = etype; +- /* All DES key types work with des-cbc-crc, which is more likely to be +- * accepted by the KDC (since MIT KDCs refuse des-cbc-md5). */ +- if (etype == ENCTYPE_DES_CBC_MD5 || etype == ENCTYPE_DES_CBC_MD4) +- etypes[count++] = ENCTYPE_DES_CBC_CRC; + etypes[count] = 0; + } + if (ret != KRB5_KT_END) +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index 37405728c..b597dda54 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -56,17 +56,12 @@ + #include "brand.c" + #include "../krb5_libinit.h" + +-/* The des-mdX entries are last for now, because it's easy to +- configure KDCs to issue TGTs with des-mdX keys and then not accept +- them. This'll be fixed, but for better compatibility, let's prefer +- des-crc for now. */ + static krb5_enctype default_enctype_list[] = { + ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, + ENCTYPE_AES256_CTS_HMAC_SHA384_192, ENCTYPE_AES128_CTS_HMAC_SHA256_128, + ENCTYPE_DES3_CBC_SHA1, + ENCTYPE_ARCFOUR_HMAC, + ENCTYPE_CAMELLIA128_CTS_CMAC, ENCTYPE_CAMELLIA256_CTS_CMAC, +- ENCTYPE_DES_CBC_CRC, ENCTYPE_DES_CBC_MD5, ENCTYPE_DES_CBC_MD4, + 0 + }; + +@@ -483,10 +478,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, + /* Set all enctypes in the default list. */ + for (i = 0; default_list[i]; i++) + mod_list(default_list[i], sel, weak, &list); +- } else if (strcasecmp(token, "des") == 0) { +- mod_list(ENCTYPE_DES_CBC_CRC, sel, weak, &list); +- mod_list(ENCTYPE_DES_CBC_MD5, sel, weak, &list); +- mod_list(ENCTYPE_DES_CBC_MD4, sel, weak, &list); + } else if (strcasecmp(token, "des3") == 0) { + mod_list(ENCTYPE_DES3_CBC_SHA1, sel, weak, &list); + } else if (strcasecmp(token, "aes") == 0) { +diff --git a/src/lib/krb5/krb/mk_req_ext.c b/src/lib/krb5/krb/mk_req_ext.c +index dce092781..9fc6a0e52 100644 +--- a/src/lib/krb5/krb/mk_req_ext.c ++++ b/src/lib/krb5/krb/mk_req_ext.c +@@ -82,36 +82,6 @@ generate_authenticator(krb5_context, + krb5_enctype *desired_etypes, + krb5_enctype tkt_enctype); + +-/* Return the checksum type for the AP request, or 0 to use the enctype's +- * mandatory checksum. */ +-static krb5_cksumtype +-ap_req_cksum(krb5_context context, krb5_auth_context auth_context, +- krb5_enctype enctype) +-{ +- /* Use the configured checksum type if one was set. */ +- if (auth_context->req_cksumtype) +- return auth_context->req_cksumtype; +- +- /* +- * Otherwise choose based on the enctype. For interoperability with very +- * old implementations, use unkeyed MD4 or MD5 checkums for DES enctypes. +- * (The authenticator checksum does not have to be keyed since it is +- * contained within an encrypted blob.) +- */ +- switch (enctype) { +- case ENCTYPE_DES_CBC_CRC: +- case ENCTYPE_DES_CBC_MD5: +- return CKSUMTYPE_RSA_MD5; +- break; +- case ENCTYPE_DES_CBC_MD4: +- return CKSUMTYPE_RSA_MD4; +- break; +- default: +- /* Use the mandatory checksum type for the enctype. */ +- return 0; +- } +-} +- + krb5_error_code KRB5_CALLCONV + krb5_mk_req_extended(krb5_context context, krb5_auth_context *auth_context, + krb5_flags ap_req_options, krb5_data *in_data, +@@ -198,15 +168,10 @@ krb5_mk_req_extended(krb5_context context, krb5_auth_context *auth_context, + checksum.length = in_data->length; + checksum.contents = (krb5_octet *) in_data->data; + } else { +- krb5_enctype enctype = krb5_k_key_enctype(context, +- (*auth_context)->key); +- krb5_cksumtype cksumtype = ap_req_cksum(context, *auth_context, +- enctype); +- if ((retval = krb5_k_make_checksum(context, +- cksumtype, +- (*auth_context)->key, +- KRB5_KEYUSAGE_AP_REQ_AUTH_CKSUM, +- in_data, &checksum))) ++ retval = krb5_k_make_checksum(context, 0, (*auth_context)->key, ++ KRB5_KEYUSAGE_AP_REQ_AUTH_CKSUM, ++ in_data, &checksum); ++ if (retval) + goto cleanup_cksum; + } + checksump = &checksum; +diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c +index 614ed4190..d8015c64a 100644 +--- a/src/lib/krb5/krb/s4u_creds.c ++++ b/src/lib/krb5/krb/s4u_creds.c +@@ -341,9 +341,6 @@ verify_s4u2self_reply(krb5_context context, + assert(req_s4u_user != NULL); + + switch (subkey->enctype) { +- case ENCTYPE_DES_CBC_CRC: +- case ENCTYPE_DES_CBC_MD4: +- case ENCTYPE_DES_CBC_MD5: + case ENCTYPE_DES3_CBC_SHA1: + case ENCTYPE_DES3_CBC_RAW: + case ENCTYPE_ARCFOUR_HMAC: +diff --git a/src/lib/krb5/krb/ser_ctx.c b/src/lib/krb5/krb/ser_ctx.c +index 39f656322..55491428b 100644 +--- a/src/lib/krb5/krb/ser_ctx.c ++++ b/src/lib/krb5/krb/ser_ctx.c +@@ -400,7 +400,7 @@ krb5_context_internalize(krb5_context kcontext, krb5_pointer *argp, krb5_octet * + } else + context->tgs_etypes = NULL; + +- /* Allowable checksum */ ++ /* Allowable clockskew */ + if ((kret = krb5_ser_unpack_int32(&ibuf, &bp, &remain))) + goto cleanup; + context->clockskew = (krb5_deltat) ibuf; +diff --git a/src/man/kdc.conf.man b/src/man/kdc.conf.man +index 4a75be8cb..8058134ac 100644 +--- a/src/man/kdc.conf.man ++++ b/src/man/kdc.conf.man +@@ -441,13 +441,6 @@ marks the server principal as host\-based or the service is also + listed in \fBhost_based_services\fP\&. \fBno_host_referral = *\fP will + disable referral processing altogether. + .TP +-\fBdes_crc_session_supported\fP +-(Boolean value). If set to true, the KDC will assume that service +-principals support des\-cbc\-crc for session key enctype negotiation +-purposes. If \fBallow_weak_crypto\fP in libdefaults is +-false, or if des\-cbc\-crc is not a permitted enctype, then this +-variable has no effect. Defaults to true. New in release 1.11. +-.TP + \fBreject_bad_transit\fP + (Boolean value.) If set to true, the KDC will check the list of + transited realms for cross\-realm tickets against the transit path +@@ -969,30 +962,6 @@ center; + |l|l|. + _ + T{ +-des\-cbc\-crc +-T} T{ +-DES cbc mode with CRC\-32 (weak) +-T} +-_ +-T{ +-des\-cbc\-md4 +-T} T{ +-DES cbc mode with RSA\-MD4 (weak) +-T} +-_ +-T{ +-des\-cbc\-md5 +-T} T{ +-DES cbc mode with RSA\-MD5 (weak) +-T} +-_ +-T{ +-des\-cbc\-raw +-T} T{ +-DES cbc mode raw (weak) +-T} +-_ +-T{ + des3\-cbc\-raw + T} T{ + Triple DES cbc mode raw (weak) +@@ -1005,12 +974,6 @@ Triple DES cbc mode with HMAC/sha1 + T} + _ + T{ +-des\-hmac\-sha1 +-T} T{ +-DES with HMAC/sha1 (weak) +-T} +-_ +-T{ + aes256\-cts\-hmac\-sha1\-96 aes256\-cts aes256\-sha1 + T} T{ + AES\-256 CTS mode with 96\-bit SHA\-1 HMAC +@@ -1059,12 +1022,6 @@ Camellia\-128 CTS mode with CMAC + T} + _ + T{ +-des +-T} T{ +-The DES family: des\-cbc\-crc, des\-cbc\-md5, and des\-cbc\-md4 (weak) +-T} +-_ +-T{ + des3 + T} T{ + The triple DES family: des3\-cbc\-sha1 +@@ -1095,8 +1052,8 @@ types for the variable in question. Types or families can be removed + from the current list by prefixing them with a minus sign ("\-"). + Types or families can be prefixed with a plus sign ("+") for symmetry; + it has the same meaning as just listing the type or family. For +-example, "\fBDEFAULT \-des\fP" would be the default set of encryption +-types with DES types removed, and "\fBdes3 DEFAULT\fP" would be the ++example, "\fBDEFAULT \-rc4\fP" would be the default set of encryption ++types with RC4 types removed, and "\fBdes3 DEFAULT\fP" would be the + default set of encryption types with triple DES types moved to the + front. + .sp +diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man +index aafdf7f83..d6ff91c3b 100644 +--- a/src/man/krb5.conf.man ++++ b/src/man/krb5.conf.man +@@ -254,7 +254,7 @@ the client should request when making a TGS\-REQ, in order of + preference from highest to lowest. The list may be delimited with + commas or whitespace. See Encryption_types in + kdc.conf(5) for a list of the accepted values for this tag. +-The default value is \fBaes256\-cts\-hmac\-sha1\-96 aes128\-cts\-hmac\-sha1\-96 aes256\-cts\-hmac\-sha384\-192 aes128\-cts\-hmac\-sha256\-128 des3\-cbc\-sha1 arcfour\-hmac\-md5 camellia256\-cts\-cmac camellia128\-cts\-cmac des\-cbc\-crc des\-cbc\-md5 des\-cbc\-md4\fP, but single\-DES encryption types ++The default value is \fBaes256\-cts\-hmac\-sha1\-96 aes128\-cts\-hmac\-sha1\-96 aes256\-cts\-hmac\-sha384\-192 aes128\-cts\-hmac\-sha256\-128 des3\-cbc\-sha1 arcfour\-hmac\-md5 camellia256\-cts\-cmac camellia128\-cts\-cmac\fP, but weak encryption types + will be implicitly removed from this list if the value of + \fBallow_weak_crypto\fP is false. + .sp +@@ -268,7 +268,7 @@ Identifies the supported list of session key encryption types that + the client should request when making an AS\-REQ, in order of + preference from highest to lowest. The format is the same as for + default_tgs_enctypes. The default value for this tag is +-\fBaes256\-cts\-hmac\-sha1\-96 aes128\-cts\-hmac\-sha1\-96 aes256\-cts\-hmac\-sha384\-192 aes128\-cts\-hmac\-sha256\-128 des3\-cbc\-sha1 arcfour\-hmac\-md5 camellia256\-cts\-cmac camellia128\-cts\-cmac des\-cbc\-crc des\-cbc\-md5 des\-cbc\-md4\fP, but single\-DES encryption types will be implicitly ++\fBaes256\-cts\-hmac\-sha1\-96 aes128\-cts\-hmac\-sha1\-96 aes256\-cts\-hmac\-sha384\-192 aes128\-cts\-hmac\-sha256\-128 des3\-cbc\-sha1 arcfour\-hmac\-md5 camellia256\-cts\-cmac camellia128\-cts\-cmac\fP, but weak encryption types will be implicitly + removed from this list if the value of \fBallow_weak_crypto\fP is + false. + .sp +@@ -388,7 +388,7 @@ used across NATs. The default value is true. + \fBpermitted_enctypes\fP + Identifies all encryption types that are permitted for use in + session key encryption. The default value for this tag is +-\fBaes256\-cts\-hmac\-sha1\-96 aes128\-cts\-hmac\-sha1\-96 aes256\-cts\-hmac\-sha384\-192 aes128\-cts\-hmac\-sha256\-128 des3\-cbc\-sha1 arcfour\-hmac\-md5 camellia256\-cts\-cmac camellia128\-cts\-cmac des\-cbc\-crc des\-cbc\-md5 des\-cbc\-md4\fP, but single\-DES encryption types will be implicitly ++\fBaes256\-cts\-hmac\-sha1\-96 aes128\-cts\-hmac\-sha1\-96 aes256\-cts\-hmac\-sha384\-192 aes128\-cts\-hmac\-sha256\-128 des3\-cbc\-sha1 arcfour\-hmac\-md5 camellia256\-cts\-cmac camellia128\-cts\-cmac\fP, but weak encryption types will be implicitly + removed from this list if the value of \fBallow_weak_crypto\fP is + false. + .TP +diff --git a/src/windows/leash/htmlhelp/html/Encryption_Types.htm b/src/windows/leash/htmlhelp/html/Encryption_Types.htm +index aad42a389..1aebdd0b4 100644 +--- a/src/windows/leash/htmlhelp/html/Encryption_Types.htm ++++ b/src/windows/leash/htmlhelp/html/Encryption_Types.htm +@@ -79,18 +79,6 @@ will have an entry in the Encryption type column.
+ Description + + +- des- +- The DES (Data Encryption Standard) +-family is a symmetric block cipher. It was designed to handle only +-56-bit keys which is not enough for modern computing power. It is now +-considered to be weak encryption.
    +-
  • des-cbc-crc (weak)
  • +-
  • des-cbc-md5 (weak)
  • +-
  • des-cbc-md4 (weak)
  • +- +-
+- +- + des3- + The triple DES family improves on + the original DES (Data Encryption Standard) by using 3 separate 56-bit +@@ -106,7 +94,7 @@ keys. Some modes of 3DES are considered weak while others are strong + + aes + The AES Advanced Encryption Standard +-family, like DES and 3DES, is a symmetric block cipher and was designed ++family, like 3DES, is a symmetric block cipher and was designed + to replace them. It can use multiple key sizes. Kerberos specifies use + for 256-bit and 128-bit keys. +
    diff --git a/Remove-the-v4-and-afs3-salt-types.patch b/Remove-the-v4-and-afs3-salt-types.patch new file mode 100644 index 0000000..671e933 --- /dev/null +++ b/Remove-the-v4-and-afs3-salt-types.patch @@ -0,0 +1,508 @@ +From 35395701a34f68e99abfe23d07b93c59cd63ad50 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 24 May 2019 13:11:44 -0400 +Subject: [PATCH] Remove the v4 and afs3 salt types + +In preparation for removing single-DES support, remove the v4 and afs3 +salt types. The afs3 salt type could only be used with single-DES +keys, and the v4 salt type was only useful for single-DES keys from +krb4 databases. + +[ghudson@mit.edu: wrote commit message] + +ticket: 8808 +(cherry picked from commit e0a35ff48c09a26ebb9aefd7e98855a84574b8be) +--- + doc/admin/conf_files/kdc_conf.rst | 2 - + src/include/kdb.h | 4 +- + src/kadmin/testing/proto/kdc.conf.proto | 2 +- + src/kdc/kdc_preauth.c | 40 +++++-------------- + .../api.current/chpass-principal-v2.exp | 8 ++-- + .../api.current/get-principal-v2.exp | 4 +- + src/lib/kdb/kdb5.c | 4 -- + src/lib/kdb/kdb_cpw.c | 16 +------- + src/lib/krb5/krb/str_conv.c | 2 - + src/lib/krb5/krb/t_get_etype_info.py | 7 ---- + src/man/kdc.conf.man | 14 +------ + src/tests/dejagnu/config/default.exp | 17 -------- + src/tests/t_etype_info.py | 24 +---------- + src/tests/t_keytab.py | 5 --- + src/tests/t_renprinc.py | 2 +- + src/tests/t_salt.py | 26 +----------- + src/util/k5test.py | 11 ----- + 17 files changed, 24 insertions(+), 164 deletions(-) + +diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst +index c73791ceb..62d1bfc05 100644 +--- a/doc/admin/conf_files/kdc_conf.rst ++++ b/doc/admin/conf_files/kdc_conf.rst +@@ -917,10 +917,8 @@ follows: + + ================= ============================================ + normal default for Kerberos Version 5 +-v4 the only type used by Kerberos Version 4 (no salt) + norealm same as the default, without using realm information + onlyrealm uses only realm information as the salt +-afs3 AFS version 3, only used for compatibility with Kerberos 4 in AFS + special generate a random salt + ================= ============================================ + +diff --git a/src/include/kdb.h b/src/include/kdb.h +index 9812a35e6..7749cfc99 100644 +--- a/src/include/kdb.h ++++ b/src/include/kdb.h +@@ -73,11 +73,11 @@ + + /* Salt types */ + #define KRB5_KDB_SALTTYPE_NORMAL 0 +-#define KRB5_KDB_SALTTYPE_V4 1 ++/* #define KRB5_KDB_SALTTYPE_V4 1 */ + #define KRB5_KDB_SALTTYPE_NOREALM 2 + #define KRB5_KDB_SALTTYPE_ONLYREALM 3 + #define KRB5_KDB_SALTTYPE_SPECIAL 4 +-#define KRB5_KDB_SALTTYPE_AFS3 5 ++/* #define KRB5_KDB_SALTTYPE_AFS3 5 */ + #define KRB5_KDB_SALTTYPE_CERTHASH 6 + + /* Attributes */ +diff --git a/src/kadmin/testing/proto/kdc.conf.proto b/src/kadmin/testing/proto/kdc.conf.proto +index 61283ac77..45df78b91 100644 +--- a/src/kadmin/testing/proto/kdc.conf.proto ++++ b/src/kadmin/testing/proto/kdc.conf.proto +@@ -12,5 +12,5 @@ + kadmind_port = 1751 + kpasswd_port = 1752 + master_key_type = des3-hmac-sha1 +- supported_enctypes = des3-hmac-sha1:normal des-cbc-crc:normal des-cbc-crc:v4 des-cbc-md5:normal des-cbc-raw:normal ++ supported_enctypes = des3-hmac-sha1:normal des-cbc-crc:normal des-cbc-md5:normal des-cbc-raw:normal + } +diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c +index caf133c14..508a5cf89 100644 +--- a/src/kdc/kdc_preauth.c ++++ b/src/kdc/kdc_preauth.c +@@ -781,8 +781,8 @@ add_etype_info(krb5_context context, krb5_kdcpreauth_rock rock, + return add_pa_data_element(pa_list, pa); + } + +-/* Add PW-SALT or AFS3-SALT entries to pa_list as appropriate for the request +- * and client principal. */ ++/* Add PW-SALT entries to pa_list as appropriate for the request and client ++ * principal. */ + static krb5_error_code + add_pw_salt(krb5_context context, krb5_kdcpreauth_rock rock, + krb5_pa_data ***pa_list) +@@ -801,21 +801,13 @@ add_pw_salt(krb5_context context, krb5_kdcpreauth_rock rock, + if (ret) + return 0; + +- if (salttype == KRB5_KDB_SALTTYPE_AFS3) { +- ret = alloc_pa_data(KRB5_PADATA_AFS3_SALT, salt->length + 1, &pa); +- if (ret) +- goto cleanup; +- memcpy(pa->contents, salt->data, salt->length); +- pa->contents[salt->length] = '\0'; +- } else { +- /* Steal memory from salt to make the pa-data entry. */ +- ret = alloc_pa_data(KRB5_PADATA_PW_SALT, 0, &pa); +- if (ret) +- goto cleanup; +- pa->length = salt->length; +- pa->contents = (uint8_t *)salt->data; +- salt->data = NULL; +- } ++ /* Steal memory from salt to make the pa-data entry. */ ++ ret = alloc_pa_data(KRB5_PADATA_PW_SALT, 0, &pa); ++ if (ret) ++ goto cleanup; ++ pa->length = salt->length; ++ pa->contents = (uint8_t *)salt->data; ++ salt->data = NULL; + + /* add_pa_data_element() claims pa on success or failure. */ + ret = add_pa_data_element(pa_list, pa); +@@ -1545,20 +1537,6 @@ _make_etype_info_entry(krb5_context context, + &salttype, &salt); + if (retval) + goto cleanup; +- if (etype_info2 && salttype == KRB5_KDB_SALTTYPE_AFS3) { +- switch (etype) { +- case ENCTYPE_DES_CBC_CRC: +- case ENCTYPE_DES_CBC_MD4: +- case ENCTYPE_DES_CBC_MD5: +- retval = alloc_data(&entry->s2kparams, 1); +- if (retval) +- goto cleanup; +- entry->s2kparams.data[0] = 1; +- break; +- default: +- break; +- } +- } + + entry->length = salt->length; + entry->salt = (unsigned char *)salt->data; +diff --git a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp +index 8361fb085..db899a1dc 100644 +--- a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp ++++ b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp +@@ -18,8 +18,8 @@ proc test200 {} { + + # I'd like to specify a long list of keysalt tuples and make sure + # that chpass does the right thing, but we can only use those +- # enctypes that krbtgt has a key for: des-cbc-crc:normal and +- # des-cbc-crc:v4, according to the prototype kdc.conf. ++ # enctypes that krbtgt has a key for: des-cbc-crc:normal ++ # according to the prototype kdc.conf. + if {! [cmd [format { + kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ + $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +@@ -53,10 +53,10 @@ proc test200 {} { + } + + # XXX Perhaps I should actually check the key type returned. +- if {$num_keys == 3} { ++ if {$num_keys == 2} { + pass "$test" + } else { +- fail "$test: $num_keys keys, should be 3" ++ fail "$test: $num_keys keys, should be 2" + } + if { ! [cmd {kadm5_destroy $server_handle}]} { + perror "$test: unexpected failure in destroy" +diff --git a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp +index 86c45f49e..8526897ed 100644 +--- a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp ++++ b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp +@@ -143,8 +143,8 @@ proc test101_102 {rpc} { + } + + set failed 0 +- if {$num_keys != 3} { +- fail "$test: num_keys $num_keys should be 3" ++ if {$num_keys != 2} { ++ fail "$test: num_keys $num_keys should be 2" + set failed 1 + } + for {set i 0} {$i < $num_keys} {incr i} { +diff --git a/src/lib/kdb/kdb5.c b/src/lib/kdb/kdb5.c +index da5332217..b81a44312 100644 +--- a/src/lib/kdb/kdb5.c ++++ b/src/lib/kdb/kdb5.c +@@ -2312,15 +2312,11 @@ krb5_dbe_compute_salt(krb5_context context, const krb5_key_data *key, + if (retval) + return retval; + break; +- case KRB5_KDB_SALTTYPE_V4: +- sdata = empty_data(); +- break; + case KRB5_KDB_SALTTYPE_NOREALM: + retval = krb5_principal2salt_norealm(context, princ, &sdata); + if (retval) + return retval; + break; +- case KRB5_KDB_SALTTYPE_AFS3: + case KRB5_KDB_SALTTYPE_ONLYREALM: + return krb5_copy_data(context, &princ->realm, salt_out); + case KRB5_KDB_SALTTYPE_SPECIAL: +diff --git a/src/lib/kdb/kdb_cpw.c b/src/lib/kdb/kdb_cpw.c +index 03efc28ed..450860f47 100644 +--- a/src/lib/kdb/kdb_cpw.c ++++ b/src/lib/kdb/kdb_cpw.c +@@ -260,7 +260,6 @@ add_key_pwd(context, master_key, ks_tuple, ks_tuple_count, passwd, + krb5_keysalt key_salt; + krb5_keyblock key; + krb5_data pwd; +- krb5_data afs_params = string2data("\1"), *s2k_params; + int i, j; + krb5_key_data *kd_slot; + +@@ -268,7 +267,6 @@ add_key_pwd(context, master_key, ks_tuple, ks_tuple_count, passwd, + krb5_boolean similar; + + similar = 0; +- s2k_params = NULL; + + /* + * We could use krb5_keysalt_iterate to replace this loop, or use +@@ -316,18 +314,6 @@ add_key_pwd(context, master_key, ks_tuple, ks_tuple_count, passwd, + &key_salt.data))) + return(retval); + break; +- case KRB5_KDB_SALTTYPE_V4: +- key_salt.data.length = 0; +- key_salt.data.data = 0; +- break; +- case KRB5_KDB_SALTTYPE_AFS3: +- retval = krb5int_copy_data_contents(context, +- &db_entry->princ->realm, +- &key_salt.data); +- if (retval) +- return retval; +- s2k_params = &afs_params; +- break; + case KRB5_KDB_SALTTYPE_SPECIAL: + retval = make_random_salt(context, &key_salt); + if (retval) +@@ -342,7 +328,7 @@ add_key_pwd(context, master_key, ks_tuple, ks_tuple_count, passwd, + retval = krb5_c_string_to_key_with_params(context, + ks_tuple[i].ks_enctype, + &pwd, &key_salt.data, +- s2k_params, &key); ++ NULL, &key); + if (retval) { + free(key_salt.data.data); + return retval; +diff --git a/src/lib/krb5/krb/str_conv.c b/src/lib/krb5/krb/str_conv.c +index 3d057241b..c8421a8c1 100644 +--- a/src/lib/krb5/krb/str_conv.c ++++ b/src/lib/krb5/krb/str_conv.c +@@ -61,11 +61,9 @@ struct salttype_lookup_entry { + #include "kdb.h" + static const struct salttype_lookup_entry salttype_table[] = { + { KRB5_KDB_SALTTYPE_NORMAL, "normal" }, +- { KRB5_KDB_SALTTYPE_V4, "v4", }, + { KRB5_KDB_SALTTYPE_NOREALM, "norealm", }, + { KRB5_KDB_SALTTYPE_ONLYREALM, "onlyrealm", }, + { KRB5_KDB_SALTTYPE_SPECIAL, "special", }, +- { KRB5_KDB_SALTTYPE_AFS3, "afs3", }, + }; + static const int salttype_table_nents = sizeof(salttype_table)/ + sizeof(salttype_table[0]); +diff --git a/src/lib/krb5/krb/t_get_etype_info.py b/src/lib/krb5/krb/t_get_etype_info.py +index 7c400be86..3c9168591 100644 +--- a/src/lib/krb5/krb/t_get_etype_info.py ++++ b/src/lib/krb5/krb/t_get_etype_info.py +@@ -9,9 +9,6 @@ realm.run([kadminl, 'ank', '-nokey', '+preauth', 'pnokey']) + realm.run([kadminl, 'ank', '-e', 'aes256-cts:special', '-pw', 'pw', 'exp']) + realm.run([kadminl, 'ank', '-e', 'aes256-cts:special', '-pw', 'pw', '+preauth', + 'pexp']) +-realm.run([kadminl, 'ank', '-e', 'des-cbc-crc:afs3', '-pw', 'pw', 'afs']) +-realm.run([kadminl, 'ank', '-e', 'des-cbc-crc:afs3', '-pw', 'pw', '+preauth', +- 'pafs']) + + # Extract the explicit salt values from the database. + out = realm.run([kdb5_util, 'tabdump', 'keyinfo']) +@@ -56,8 +53,4 @@ realm.run(['./t_get_etype_info', 'exp'], + realm.run(['./t_get_etype_info', 'pexp'], + expected_msg='etype: aes256-cts\nsalt: ' + pexp_salt + '\n') + +-msg = 'etype: des-cbc-crc\nsalt: KRBTEST.COM\ns2kparams: 01\n' +-realm.run(['./t_get_etype_info', 'afs'], expected_msg=msg) +-realm.run(['./t_get_etype_info', 'pafs'], expected_msg=msg) +- + success('krb5_get_etype_info() tests') +diff --git a/src/man/kdc.conf.man b/src/man/kdc.conf.man +index ab3ee0289..4a75be8cb 100644 +--- a/src/man/kdc.conf.man ++++ b/src/man/kdc.conf.man +@@ -1,6 +1,6 @@ + .\" Man page generated from reStructuredText. + . +-.TH "KDC.CONF" "5" " " "1.17" "MIT Kerberos" ++.TH "KDC.CONF" "5" " " "1.18" "MIT Kerberos" + .SH NAME + kdc.conf \- Kerberos V5 KDC configuration file + . +@@ -1148,12 +1148,6 @@ default for Kerberos Version 5 + T} + _ + T{ +-v4 +-T} T{ +-the only type used by Kerberos Version 4 (no salt) +-T} +-_ +-T{ + norealm + T} T{ + same as the default, without using realm information +@@ -1166,12 +1160,6 @@ uses only realm information as the salt + T} + _ + T{ +-afs3 +-T} T{ +-AFS version 3, only used for compatibility with Kerberos 4 in AFS +-T} +-_ +-T{ + special + T} T{ + generate a random salt +diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp +index ea9bedd45..c061d764e 100644 +--- a/src/tests/dejagnu/config/default.exp ++++ b/src/tests/dejagnu/config/default.exp +@@ -238,22 +238,6 @@ set passes { + {master_key_type=aes256-cts-hmac-sha1-96} + {dummy=[verbose -log "AES + DES enctypes, DES3 TGT"]} + } +- { +- des-v4 +- mode=udp +- des3_krbtgt=0 +- {supported_enctypes=des-cbc-crc:v4} +- {default_tkt_enctypes(client)=des-cbc-crc} +- {dummy=[verbose -log "DES TGT, DES-CRC enctype, V4 salt"]} +- } +- { +- des-md5-v4 +- mode=udp +- des3_krbtgt=0 +- {supported_enctypes=des-cbc-md5:v4 des-cbc-crc:v4} +- {default_tkt_enctypes(client)=des-cbc-md5 des-cbc-crc} +- {dummy=[verbose -log "DES TGT, DES-MD5 and -CRC enctypes, V4 salt"]} +- } + { + all-enctypes + mode=udp +@@ -356,7 +340,6 @@ set unused_passes { + aes128-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:norealm \ + des3-cbc-sha1:normal des3-cbc-sha1:none \ + des-cbc-md5:normal des-cbc-md4:normal des-cbc-crc:normal \ +- des-cbc-md5:v4 des-cbc-md4:v4 des-cbc-crc:v4 \ + } + {dummy=[verbose -log "DES3 TGT, default enctypes"]} + } +diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py +index 2026e7876..c21d054f1 100644 +--- a/src/tests/t_etype_info.py ++++ b/src/tests/t_etype_info.py +@@ -1,6 +1,6 @@ + from k5test import * + +-supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac des-cbc-crc:afs3' ++supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac' + conf = {'libdefaults': {'allow_weak_crypto': 'true'}, + 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} + realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) +@@ -43,28 +43,6 @@ test_etinfo('preauthuser', 'rc4-hmac-exp des3 rc4 des-cbc-crc', + test_etinfo('preauthuser', 'rc4 aes256-cts', + ['error etype_info2 rc4-hmac KRBTEST.COMpreauthuser']) + +-# AFS3 salt for DES enctypes is conveyed using s2kparams in +-# PA-ETYPE-INFO2, not at all in PA-ETYPE-INFO, and with a special padata +-# type instead of PA-PW-SALT. +-test_etinfo('user', 'des-cbc-crc rc4', +- ['asrep etype_info2 des-cbc-crc KRBTEST.COM 01', +- 'asrep etype_info des-cbc-crc KRBTEST.COM', +- 'asrep afs3_salt KRBTEST.COM']) +-test_etinfo('preauthuser', 'des-cbc-crc rc4', +- ['error etype_info2 des-cbc-crc KRBTEST.COM 01', +- 'error etype_info des-cbc-crc KRBTEST.COM']) +- +-# DES keys can be used with other DES enctypes. The requested enctype +-# shows up in the etype-info, not the database key enctype. +-test_etinfo('user', 'des-cbc-md4 rc4', +- ['asrep etype_info2 des-cbc-md4 KRBTEST.COM 01', +- 'asrep etype_info des-cbc-md4 KRBTEST.COM', +- 'asrep afs3_salt KRBTEST.COM']) +-test_etinfo('user', 'des-cbc-md5 rc4', +- ['asrep etype_info2 des KRBTEST.COM 01', +- 'asrep etype_info des KRBTEST.COM', +- 'asrep afs3_salt KRBTEST.COM']) +- + # If no keys are found matching the request enctypes, a + # preauth-required error can be generated with no etype-info at all + # (to allow for preauth mechs which don't depend on long-term keys). +diff --git a/src/tests/t_keytab.py b/src/tests/t_keytab.py +index 72e09daac..633f7c7ef 100755 +--- a/src/tests/t_keytab.py ++++ b/src/tests/t_keytab.py +@@ -155,9 +155,6 @@ realm.run([kadminl, 'ank', '-pw', 'pw', 'default']) + realm.run([kadminl, 'ank', '-e', 'aes256-cts:special', '-pw', 'pw', 'exp']) + realm.run([kadminl, 'ank', '-e', 'aes256-cts:special', '-pw', 'pw', '+preauth', + 'pexp']) +-realm.run([kadminl, 'ank', '-e', 'des-cbc-crc:afs3', '-pw', 'pw', 'afs']) +-realm.run([kadminl, 'ank', '-e', 'des-cbc-crc:afs3', '-pw', 'pw', '+preauth', +- 'pafs']) + + # Extract one of the explicit salt values from the database. + out = realm.run([kdb5_util, 'tabdump', 'keyinfo']) +@@ -187,8 +184,6 @@ test_addent(realm, 'default', '-f') + test_addent(realm, 'default', '-f -e aes128-cts') + test_addent(realm, 'exp', '-f') + test_addent(realm, 'pexp', '-f') +-test_addent(realm, 'afs', '-f') +-test_addent(realm, 'pafs', '-f') + + success('Keytab-related tests') + success('Keytab-related tests') +diff --git a/src/tests/t_renprinc.py b/src/tests/t_renprinc.py +index 46cbed441..3dbb3e77e 100755 +--- a/src/tests/t_renprinc.py ++++ b/src/tests/t_renprinc.py +@@ -25,7 +25,7 @@ from k5test import * + enctype = "aes128-cts" + + realm = K5Realm(create_host=False, create_user=False) +-salttypes = ('normal', 'v4', 'norealm', 'onlyrealm') ++salttypes = ('normal', 'norealm', 'onlyrealm') + + # For a variety of salt types, test that we can rename a principal and + # still get tickets with the same password. +diff --git a/src/tests/t_salt.py b/src/tests/t_salt.py +index 278911a22..008efcb03 100755 +--- a/src/tests/t_salt.py ++++ b/src/tests/t_salt.py +@@ -15,13 +15,9 @@ def test_salt(realm, e1, salt, e2): + realm.run([kadminl, 'delprinc', 'user']) + + # Enctype/salt pairs chosen with non-default salt types. +-# The enctypes are mostly arbitrary, though afs3 must only be used with des. +-# We do not enforce that v4 salts must only be used with des, but it seems +-# like a good idea. +-salts = [('des-cbc-crc', 'afs3'), +- ('des3-cbc-sha1', 'norealm'), ++# The enctypes are mostly arbitrary. ++salts = [('des3-cbc-sha1', 'norealm'), + ('arcfour-hmac', 'onlyrealm'), +- ('des-cbc-crc', 'v4'), + ('aes128-cts-hmac-sha1-96', 'special')] + # These enctypes are chosen to cover the different string-to-key routines. + # Omit ":normal" from aes256 to check that salttype defaulting works. +@@ -56,22 +52,4 @@ dup_kstypes = ['arcfour-hmac-md5:normal,rc4-hmac:normal', + for ks in dup_kstypes: + test_dup(realm, ks) + +-# Attempt to create a principal with a non-des enctype and the afs3 salt, +-# verifying that the expected error is received and the principal creation +-# fails. +-def test_reject_afs3(realm, etype): +- query = 'ank -e ' + etype + ':afs3 -pw password princ1' +- realm.run([kadminl, 'ank', '-e', etype + ':afs3', '-pw', 'password', +- 'princ1'], expected_code=1, +- expected_msg='Invalid key generation parameters from KDC') +- realm.run([kadminl, 'getprinc', 'princ1'], expected_code=1, +- expected_msg='Principal does not exist') +- +-# Verify that the afs3 salt is rejected for arcfour and pbkdf2 enctypes. +-# We do not currently do any verification on the key-generation parameters +-# for the triple-DES enctypes, so that test is commented out. +-test_reject_afs3(realm, 'arcfour-hmac') +-test_reject_afs3(realm, 'aes256-cts-hmac-sha1-96') +-#test_reject_afs3(realm, 'des3-cbc-sha1') +- + success("Salt types") +diff --git a/src/util/k5test.py b/src/util/k5test.py +index 3aec1ef92..b6d93f1d8 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -1246,17 +1246,6 @@ _passes = [ + # No special settings; exercises AES256. + ('default', None, None, None), + +- # Exercise a DES enctype and the v4 salt type. +- ('desv4', None, +- {'libdefaults': { +- 'default_tgs_enctypes': 'des-cbc-crc', +- 'default_tkt_enctypes': 'des-cbc-crc', +- 'permitted_enctypes': 'des-cbc-crc', +- 'allow_weak_crypto': 'true'}}, +- {'realms': {'$realm': { +- 'supported_enctypes': 'des-cbc-crc:v4', +- 'master_key_type': 'des-cbc-crc'}}}), +- + # Exercise the DES3 enctype. + ('des3', None, + {'libdefaults': { diff --git a/Set-a-more-modern-default-ksu-CMD_PATH.patch b/Set-a-more-modern-default-ksu-CMD_PATH.patch index 4cf3da5..31f9602 100644 --- a/Set-a-more-modern-default-ksu-CMD_PATH.patch +++ b/Set-a-more-modern-default-ksu-CMD_PATH.patch @@ -1,4 +1,4 @@ -From 4b11c083e2019ece267cfa5379bd417334e2038e Mon Sep 17 00:00:00 2001 +From 6b50f9c5b2a1b856e65fa69de05e7c05d2b89614 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:32:09 -0400 Subject: [PATCH] Set a more modern default ksu CMD_PATH diff --git a/Support-389ds-s-lockout-model.patch b/Support-389ds-s-lockout-model.patch index 3b4c595..2800e0b 100644 --- a/Support-389ds-s-lockout-model.patch +++ b/Support-389ds-s-lockout-model.patch @@ -1,4 +1,4 @@ -From 49ca1fc11d4e58289b518db7cdd4093b06ca9cf1 Mon Sep 17 00:00:00 2001 +From 2c00970b3fe53b38f976c79f648fdd75a2682287 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:44 -0400 Subject: [PATCH] Support 389ds's lockout model diff --git a/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch b/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch index bd98230..980797e 100644 --- a/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch +++ b/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch @@ -1,4 +1,4 @@ -From f179301f52e0e40eee9ac493bae0e82be49b7c28 Mon Sep 17 00:00:00 2001 +From 152e88043117927c334fead93bb3bd3dd74593b7 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 16 Apr 2019 14:16:39 -0400 Subject: [PATCH] Update ASN.1 SAM tests to use a modern enctype diff --git a/Update-default-krb5kdc-mkey-manual-entry-enctype.patch b/Update-default-krb5kdc-mkey-manual-entry-enctype.patch index 462d774..ff99839 100644 --- a/Update-default-krb5kdc-mkey-manual-entry-enctype.patch +++ b/Update-default-krb5kdc-mkey-manual-entry-enctype.patch @@ -1,4 +1,4 @@ -From e2b0a71ca45d6895c9df132560789774993e657d Mon Sep 17 00:00:00 2001 +From 2957d2186ee2b60b80e6ba97a1f5d661ccb20f30 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 20 May 2019 16:52:57 -0400 Subject: [PATCH] Update default krb5kdc mkey manual-entry enctype diff --git a/Update-test-suite-to-avoid-single-DES-enctypes.patch b/Update-test-suite-to-avoid-single-DES-enctypes.patch new file mode 100644 index 0000000..56aa947 --- /dev/null +++ b/Update-test-suite-to-avoid-single-DES-enctypes.patch @@ -0,0 +1,2328 @@ +From 8fe2563e133e904e56c3ed3b9b970bb632c843b6 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 24 May 2019 13:11:55 -0400 +Subject: [PATCH] Update test suite to avoid single-DES enctypes + +Remove the CRC exercise code, since CRC is DES-only. + +ticket: 8808 +(cherry picked from commit 50588db5d26e81f3d564d1f69435af34ae80d9b2) +--- + src/kadmin/testing/proto/kdc.conf.proto | 2 +- + src/kadmin/testing/util/tcl_kadm5.c | 2 - + src/lib/crypto/crypto_tests/CRC.pm | 156 ---------- + src/lib/crypto/crypto_tests/Makefile.in | 31 +- + src/lib/crypto/crypto_tests/crc.pl | 111 ------- + src/lib/crypto/crypto_tests/deps | 24 -- + src/lib/crypto/crypto_tests/t_cf2.expected | 1 - + src/lib/crypto/crypto_tests/t_cf2.in | 5 - + src/lib/crypto/crypto_tests/t_cksum.c | 160 ---------- + src/lib/crypto/crypto_tests/t_cksums.c | 8 +- + src/lib/crypto/crypto_tests/t_combine.c | 18 -- + src/lib/crypto/crypto_tests/t_crc.c | 148 ---------- + src/lib/crypto/crypto_tests/t_decrypt.c | 148 ---------- + src/lib/crypto/crypto_tests/t_encrypt.c | 3 - + src/lib/crypto/crypto_tests/t_short.c | 3 - + src/lib/crypto/crypto_tests/t_str2key.c | 274 ------------------ + src/lib/crypto/crypto_tests/vectors.c | 3 +- + .../api.current/chpass-principal-v2.exp | 8 +- + .../api.current/get-principal-v2.exp | 4 +- + .../api.current/randkey-principal-v2.exp | 11 +- + src/lib/kadm5/unit-test/setkey-test.c | 6 +- + src/lib/krb5/keytab/t_keytab.c | 40 +-- + src/lib/krb5/krb/t_etypes.c | 67 +---- + src/lib/krb5/krb/t_ser.c | 2 +- + src/lib/krb5/os/t_trace.c | 2 +- + src/lib/krb5/os/t_trace.ref | 2 +- + src/tests/asn.1/ktest.c | 2 +- + src/tests/asn.1/pkinit_encode.out | 2 +- + src/tests/asn.1/pkinit_trval.out | 2 +- + src/tests/dejagnu/config/default.exp | 226 ++------------- + src/tests/gssapi/t_invalid.c | 20 +- + src/tests/gssapi/t_pcontok.c | 17 +- + src/tests/gssapi/t_prf.c | 7 - + src/tests/t_etype_info.py | 4 +- + src/tests/t_keyrollover.py | 6 +- + src/tests/t_salt.py | 2 +- + src/tests/t_sesskeynego.py | 18 +- + src/util/k5test.py | 2 +- + 38 files changed, 88 insertions(+), 1459 deletions(-) + delete mode 100644 src/lib/crypto/crypto_tests/CRC.pm + delete mode 100644 src/lib/crypto/crypto_tests/crc.pl + delete mode 100644 src/lib/crypto/crypto_tests/t_cksum.c + delete mode 100644 src/lib/crypto/crypto_tests/t_crc.c + +diff --git a/src/kadmin/testing/proto/kdc.conf.proto b/src/kadmin/testing/proto/kdc.conf.proto +index 45df78b91..8a4b87de1 100644 +--- a/src/kadmin/testing/proto/kdc.conf.proto ++++ b/src/kadmin/testing/proto/kdc.conf.proto +@@ -12,5 +12,5 @@ + kadmind_port = 1751 + kpasswd_port = 1752 + master_key_type = des3-hmac-sha1 +- supported_enctypes = des3-hmac-sha1:normal des-cbc-crc:normal des-cbc-md5:normal des-cbc-raw:normal ++ supported_enctypes = des3-hmac-sha1:normal aes256-cts:normal aes128-cts:normal aes256-sha2:normal aes128-sha2:normal + } +diff --git a/src/kadmin/testing/util/tcl_kadm5.c b/src/kadmin/testing/util/tcl_kadm5.c +index 9dde579ef..4d3114b11 100644 +--- a/src/kadmin/testing/util/tcl_kadm5.c ++++ b/src/kadmin/testing/util/tcl_kadm5.c +@@ -1514,8 +1514,6 @@ static Tcl_DString *unparse_keytype(krb5_enctype enctype) + switch (enctype) { + /* XXX is this right? */ + case ENCTYPE_NULL: Tcl_DStringAppend(str, "ENCTYPE_NULL", -1); break; +- case ENCTYPE_DES_CBC_CRC: +- Tcl_DStringAppend(str, "ENCTYPE_DES_CBC_CRC", -1); break; + default: + sprintf(buf, "UNKNOWN KEYTYPE (0x%x)", enctype); + Tcl_DStringAppend(str, buf, -1); +diff --git a/src/lib/crypto/crypto_tests/CRC.pm b/src/lib/crypto/crypto_tests/CRC.pm +deleted file mode 100644 +index ee2ab2ae8..000000000 +--- a/src/lib/crypto/crypto_tests/CRC.pm ++++ /dev/null +@@ -1,156 +0,0 @@ +-# Copyright 2002 by the Massachusetts Institute of Technology. +-# All Rights Reserved. +-# +-# Export of this software from the United States of America may +-# require a specific license from the United States Government. +-# It is the responsibility of any person or organization contemplating +-# export to obtain such a license before exporting. +-# +-# WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +-# distribute this software and its documentation for any purpose and +-# without fee is hereby granted, provided that the above copyright +-# notice appear in all copies and that both that copyright notice and +-# this permission notice appear in supporting documentation, and that +-# the name of M.I.T. not be used in advertising or publicity pertaining +-# to distribution of the software without specific, written prior +-# permission. Furthermore if you modify this software you must label +-# your software as modified software and not distribute it in such a +-# fashion that it might be confused with the original M.I.T. software. +-# M.I.T. makes no representations about the suitability of +-# this software for any purpose. It is provided "as is" without express +-# or implied warranty. +- +-package CRC; +- +-# CRC: implement a CRC using the Poly package (yes this is slow) +-# +-# message M(x) = m_0 * x^0 + m_1 * x^1 + ... + m_(k-1) * x^(k-1) +-# generator P(x) = p_0 * x^0 + p_1 * x^1 + ... + p_n * x^n +-# remainder R(x) = r_0 * x^0 + r_1 * x^1 + ... + r_(n-1) * x^(n-1) +-# +-# R(x) = (x^n * M(x)) % P(x) +-# +-# Note that if F(x) = x^n * M(x) + R(x), then F(x) = 0 mod P(x) . +-# +-# In MIT Kerberos 5, R(x) is taken as the CRC, as opposed to what +-# ISO 3309 does. +-# +-# ISO 3309 adds a precomplement and a postcomplement. +-# +-# The ISO 3309 postcomplement is of the form +-# +-# A(x) = x^0 + x^1 + ... + x^(n-1) . +-# +-# The ISO 3309 precomplement is of the form +-# +-# B(x) = x^k * A(x) . +-# +-# The ISO 3309 FCS is then +-# +-# (x^n * M(x)) % P(x) + B(x) % P(x) + A(x) , +-# +-# which is equivalent to +-# +-# (x^n * M(x) + B(x)) % P(x) + A(x) . +-# +-# In ISO 3309, the transmitted frame is +-# +-# F'(x) = x^n * M(x) + R(x) + R'(x) + A(x) , +-# +-# where +-# +-# R'(x) = B(x) % P(x) . +-# +-# Note that this means that if a new remainder is computed over the +-# frame F'(x) (treating F'(x) as the new M(x)), it will be equal to a +-# constant. +-# +-# F'(x) = 0 + R'(x) + A(x) mod P(x) , +-# +-# then +-# +-# (F'(x) + x^k * A(x)) * x^n +-# +-# = ((R'(x) + A(x)) + x^k * A(x)) * x^n mod P(x) +-# +-# = (x^k * A(x) + A(x) + x^k * A(x)) * x^n mod P(x) +-# +-# = (0 + A(x)) * x^n mod P(x) +-# +-# Note that (A(x) * x^n) % P(x) is a constant, and that this result +-# depends on B(x) being x^k * A(x). +- +-use Carp; +-use Poly; +- +-sub new { +- my $self = shift; +- my $class = ref($self) || $self; +- my %args = @_; +- $self = {bitsendian => "little"}; +- bless $self, $class; +- $self->setpoly($args{"Poly"}) if exists $args{"Poly"}; +- $self->bitsendian($args{"bitsendian"}) +- if exists $args{"bitsendian"}; +- $self->{precomp} = $args{precomp} if exists $args{precomp}; +- $self->{postcomp} = $args{postcomp} if exists $args{postcomp}; +- return $self; +-} +- +-sub setpoly { +- my $self = shift; +- my($arg) = @_; +- croak "need a polynomial" if !$arg->isa("Poly"); +- $self->{Poly} = $arg; +- return $self; +-} +- +-sub crc { +- my $self = shift; +- my $msg = Poly->new(@_); +- my($order, $r, $precomp); +- $order = $self->{Poly}->order; +- # B(x) = x^k * precomp +- $precomp = $self->{precomp} ? +- $self->{precomp} * Poly->powers2poly(scalar(@_)) : Poly->new; +- # R(x) = (x^n * M(x)) % P(x) +- $r = ($msg * Poly->powers2poly($order)) % $self->{Poly}; +- # B(x) % P(x) +- $r += $precomp % $self->{Poly}; +- $r += $self->{postcomp} if exists $self->{postcomp}; +- return $r; +-} +- +-# endianness of bits of each octet +-# +-# Note that the message is always treated as being sent in big-endian +-# octet order. +-# +-# Usually, the message will be treated as bits being little-endian, +-# since that is the common case for serial implementations that +-# present data in octets; e.g., most UARTs shift octets onto the line +-# in little-endian order, and protocols such as ISO 3309, V.42, +-# etc. treat individual octets as being sent LSB-first. +- +-sub bitsendian { +- my $self = shift; +- my($arg) = @_; +- croak "bad bit endianness" if $arg !~ /big|little/; +- $self->{bitsendian} = $arg; +- return $self; +-} +- +-sub crcstring { +- my $self = shift; +- my($arg) = @_; +- my($packstr, @m); +- { +- $packstr = "B*", last if $self->{bitsendian} =~ /big/; +- $packstr = "b*", last if $self->{bitsendian} =~ /little/; +- croak "bad bit endianness"; +- }; +- @m = split //, unpack $packstr, $arg; +- return $self->crc(@m); +-} +- +-1; +diff --git a/src/lib/crypto/crypto_tests/Makefile.in b/src/lib/crypto/crypto_tests/Makefile.in +index c5eba1b10..09feeb50e 100644 +--- a/src/lib/crypto/crypto_tests/Makefile.in ++++ b/src/lib/crypto/crypto_tests/Makefile.in +@@ -16,9 +16,7 @@ EXTRADEPSRCS=\ + $(srcdir)/aes-test.c \ + $(srcdir)/camellia-test.c \ + $(srcdir)/t_cf2.c \ +- $(srcdir)/t_cksum.c \ + $(srcdir)/t_cksums.c \ +- $(srcdir)/t_crc.c \ + $(srcdir)/t_mddriver.c \ + $(srcdir)/t_kperf.c \ + $(srcdir)/t_sha2.c \ +@@ -30,15 +28,12 @@ EXTRADEPSRCS=\ + + ##DOS##BUILDTOP = ..\..\.. + +-# NOTE: The t_cksum known checksum values are primarily for regression +-# testing. They are not derived a priori, but are known to produce +-# checksums that interoperate. + check-unix: t_nfold t_encrypt t_decrypt t_prf t_prng t_cmac t_hmac \ +- t_cksum4 t_cksum5 t_cksums \ ++ t_cksums \ + aes-test \ + camellia-test \ + t_mddriver4 t_mddriver \ +- t_crc t_cts t_sha2 t_short t_str2key t_derive t_fork t_cf2 \ ++ t_cts t_sha2 t_short t_str2key t_derive t_fork t_cf2 \ + t_combine + $(RUN_TEST) ./t_nfold + $(RUN_TEST) ./t_encrypt +@@ -47,10 +42,7 @@ check-unix: t_nfold t_encrypt t_decrypt t_prf t_prng t_cmac t_hmac \ + $(RUN_TEST) ./t_cmac + $(RUN_TEST) ./t_hmac + $(RUN_TEST) ./t_prf +- $(RUN_TEST) ./t_cksum4 "this is a test" e3f76a07f3401e3536b43a3f54226c39422c35682c354835 +- $(RUN_TEST) ./t_cksum5 "this is a test" e3f76a07f3401e351143ee6f4c09be1edb4264d55015db53 + $(RUN_TEST) ./t_cksums +- $(RUN_TEST) ./t_crc + $(RUN_TEST) ./t_cts + $(RUN_TEST) ./aes-test -k > vk.txt + cmp vk.txt $(srcdir)/expect-vk.txt +@@ -109,24 +101,9 @@ t_short$(EXEEXT): t_short.$(OBJEXT) $(KRB5_BASE_DEPLIBS) + $(CC_LINK) -o $@ t_short.$(OBJEXT) \ + $(KRB5_BASE_LIBS) + +-t_cksum4.o: $(srcdir)/t_cksum.c +- $(CC) -DMD=4 $(ALL_CFLAGS) -o t_cksum4.o -c $(srcdir)/t_cksum.c +- +-t_cksum5.o: $(srcdir)/t_cksum.c +- $(CC) -DMD=5 $(ALL_CFLAGS) -o t_cksum5.o -c $(srcdir)/t_cksum.c +- +-t_cksum4: t_cksum4.o $(CRYTPO_DEPLIB) +- $(CC_LINK) -o t_cksum4 t_cksum4.o $(KRB5_BASE_LIBS) +- +-t_cksum5: t_cksum5.o $(CRYPTO_DEPLIB) +- $(CC_LINK) -o t_cksum5 t_cksum5.o $(KRB5_BASE_LIBS) +- + t_cksums: t_cksums.o $(CRYTPO_DEPLIB) + $(CC_LINK) -o t_cksums t_cksums.o -lkrb5 $(KRB5_BASE_LIBS) + +-t_crc: t_crc.o $(KRB5_BASE_DEPLIBS) +- $(CC_LINK) -o $@ t_crc.o $(KRB5_BASE_LIBS) +- + aes-test: aes-test.$(OBJEXT) $(KRB5_BASE_DEPLIBS) + $(CC_LINK) -o aes-test aes-test.$(OBJEXT) $(KRB5_BASE_LIBS) + +@@ -165,9 +142,9 @@ clean: + t_decrypt.o t_decrypt t_prng.o t_prng t_cmac.o t_cmac \ + t_hmac.o t_hmac t_pkcs5.o t_pkcs5 pbkdf2.o t_prf t_prf.o \ + aes-test.o aes-test vt.txt vk.txt kresults.out \ +- t_crc.o t_crc t_cts.o t_cts \ ++ t_cts.o t_cts \ + t_mddriver4.o t_mddriver4 t_mddriver.o t_mddriver \ +- t_cksum4 t_cksum4.o t_cksum5 t_cksum5.o t_cksums t_cksums.o \ ++ t_cksums t_cksums.o \ + t_kperf.o t_kperf t_sha2.o t_sha2 t_short t_short.o t_str2key \ + t_str2key.o t_derive t_derive.o t_fork t_fork.o \ + t_mddriver$(EXEEXT) $(OUTPRE)t_mddriver.$(OBJEXT) \ +diff --git a/src/lib/crypto/crypto_tests/crc.pl b/src/lib/crypto/crypto_tests/crc.pl +deleted file mode 100644 +index b21b6b15d..000000000 +--- a/src/lib/crypto/crypto_tests/crc.pl ++++ /dev/null +@@ -1,111 +0,0 @@ +-# Copyright 2002 by the Massachusetts Institute of Technology. +-# All Rights Reserved. +-# +-# Export of this software from the United States of America may +-# require a specific license from the United States Government. +-# It is the responsibility of any person or organization contemplating +-# export to obtain such a license before exporting. +-# +-# WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +-# distribute this software and its documentation for any purpose and +-# without fee is hereby granted, provided that the above copyright +-# notice appear in all copies and that both that copyright notice and +-# this permission notice appear in supporting documentation, and that +-# the name of M.I.T. not be used in advertising or publicity pertaining +-# to distribution of the software without specific, written prior +-# permission. Furthermore if you modify this software you must label +-# your software as modified software and not distribute it in such a +-# fashion that it might be confused with the original M.I.T. software. +-# M.I.T. makes no representations about the suitability of +-# this software for any purpose. It is provided "as is" without express +-# or implied warranty. +- +-use CRC; +- +-print "*** crudely testing polynomial functions ***\n"; +- +-$x = Poly->new(1,1,1,1); +-$y = Poly->new(1,1); +-print "x = @{[$x->pretty]}\ny = @{[$y->pretty]}\n"; +-$q = $x / $y; +-$r = $x % $y; +-print $x->pretty, " = (", $y->pretty , ") * (", $q->pretty, +- ") + ", $r->pretty, "\n"; +-$q = $y / $x; +-$r = $y % $x; +-print "y / x = @{[$q->pretty]}\ny % x = @{[$r->pretty]}\n"; +- +-# ISO 3309 32-bit FCS polynomial +-$fcs32 = Poly->powers2poly(32,26,23,22,16,12,11,10,8,7,5,4,2,1,0); +-print "fcs32 = ", $fcs32->pretty, "\n"; +- +-$crc = CRC->new(Poly => $fcs32, bitsendian => "little"); +- +-print "\n"; +- +-print "*** little endian, no complementation ***\n"; +-for ($i = 0; $i < 256; $i++) { +- $r = $crc->crcstring(pack "C", $i); +- printf ("%02x: ", $i) if !($i % 8); +- print ($r->revhex, ($i % 8 == 7) ? "\n" : " "); +-} +- +-print "\n"; +- +-print "*** little endian, 4 bits, no complementation ***\n"; +-for ($i = 0; $i < 16; $i++) { +- @m = (split //, unpack "b*", pack "C", $i)[0..3]; +- $r = $crc->crc(@m); +- printf ("%02x: ", $i) if !($i % 8); +- print ($r->revhex, ($i % 8 == 7) ? "\n" : " "); +-} +- +-print "\n"; +- +-print "*** test vectors for t_crc.c, little endian ***\n"; +-for ($i = 1; $i <= 4; $i *=2) { +- for ($j = 0; $j < $i * 8; $j++) { +- @m = split //, unpack "b*", pack "V", 1 << $j; +- splice @m, $i * 8; +- $r = $crc->crc(@m); +- $m = unpack "H*", pack "b*", join("", @m); +- print "{HEX, \"$m\", 0x", $r->revhex, "},\n"; +- } +-} +-@m = ("foo", "test0123456789", +- "MASSACHVSETTS INSTITVTE OF TECHNOLOGY"); +-foreach $m (@m) { +- $r = $crc->crcstring($m); +- print "{STR, \"$m\", 0x", $r->revhex, "},\n"; +-} +-__END__ +- +-print "*** big endian, no complementation ***\n"; +-for ($i = 0; $i < 256; $i++) { +- $r = $crc->crcstring(pack "C", $i); +- printf ("%02x: ", $i) if !($i % 8); +- print ($r->hex, ($i % 8 == 7) ? "\n" : " "); +-} +- +-# all ones polynomial of order 31 +-$ones = Poly->new((1) x 32); +- +-print "*** big endian, ISO-3309 style\n"; +-$crc = CRC->new(Poly => $fcs32, +- bitsendian => "little", +- precomp => $ones, +- postcomp => $ones); +-for ($i = 0; $i < 256; $i++) { +- $r = $crc->crcstring(pack "C", $i); +- print ($r->hex, ($i % 8 == 7) ? "\n" : " "); +-} +- +-for ($i = 0; $i < 0; $i++) { +- $x = Poly->new((1) x 32, (0) x $i); +- $y = Poly->new((1) x 32); +- $f = ($x % $fcs32) + $y; +- $r = (($f + $x) * Poly->powers2poly(32)) % $fcs32; +- @out = @$r; +- unshift @out, 0 while @out < 32; +- print @out, "\n"; +-} +diff --git a/src/lib/crypto/crypto_tests/deps b/src/lib/crypto/crypto_tests/deps +index 5d94a593d..19fef2582 100644 +--- a/src/lib/crypto/crypto_tests/deps ++++ b/src/lib/crypto/crypto_tests/deps +@@ -140,17 +140,6 @@ $(OUTPRE)camellia-test.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(top_srcdir)/include/socket-utils.h camellia-test.c + $(OUTPRE)t_cf2.$(OBJEXT): $(BUILDTOP)/include/krb5/krb5.h \ + $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h t_cf2.c +-$(OUTPRE)t_cksum.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- t_cksum.c + $(OUTPRE)t_cksums.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ +@@ -161,19 +150,6 @@ $(OUTPRE)t_cksums.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ + $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ + $(top_srcdir)/include/socket-utils.h t_cksums.c +-$(OUTPRE)t_crc.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \ +- $(srcdir)/../builtin/crypto_mod.h $(srcdir)/../builtin/sha2/sha2.h \ +- $(srcdir)/../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- t_crc.c + $(OUTPRE)t_mddriver.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \ +diff --git a/src/lib/crypto/crypto_tests/t_cf2.expected b/src/lib/crypto/crypto_tests/t_cf2.expected +index 11a24b800..f8251a16c 100644 +--- a/src/lib/crypto/crypto_tests/t_cf2.expected ++++ b/src/lib/crypto/crypto_tests/t_cf2.expected +@@ -1,6 +1,5 @@ + 97df97e4b798b29eb31ed7280287a92a + 4d6ca4e629785c1f01baf55e2e548566b9617ae3a96868c337cb93b5e72b1c7b +-43bae3738c9467e6 + e58f9eb643862c13ad38e529313462a7f73e62834fe54a01 + 24d7f6b6bae4e5c00d2082c5ebab3672 + edd02a39d2dbde31611c16e610be062c +diff --git a/src/lib/crypto/crypto_tests/t_cf2.in b/src/lib/crypto/crypto_tests/t_cf2.in +index e62ead7d8..73e2f8fbc 100644 +--- a/src/lib/crypto/crypto_tests/t_cf2.in ++++ b/src/lib/crypto/crypto_tests/t_cf2.in +@@ -8,11 +8,6 @@ key1 + key2 + a + b +-1 +-key1 +-key2 +-a +-b + 16 + key1 + key2 +diff --git a/src/lib/crypto/crypto_tests/t_cksum.c b/src/lib/crypto/crypto_tests/t_cksum.c +deleted file mode 100644 +index 0edaeb850..000000000 +--- a/src/lib/crypto/crypto_tests/t_cksum.c ++++ /dev/null +@@ -1,160 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/crypto_tests/t_cksum.c */ +-/* +- * Copyright 1995 by the Massachusetts Institute of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* Test checksum and checksum compatability for rsa-md[4,5]-des. */ +- +-#include "k5-int.h" +-#include "k5-hex.h" +- +-#define MD5_K5BETA_COMPAT +-#define MD4_K5BETA_COMPAT +- +-#if MD == 4 +-#define CKTYPE CKSUMTYPE_RSA_MD4_DES +-#endif +- +-#if MD == 5 +-#define CKTYPE CKSUMTYPE_RSA_MD5_DES +-#endif +- +-static void +-print_checksum(char *text, int number, char *message, krb5_checksum *checksum) +-{ +- unsigned int i; +- +- printf("%s MD%d checksum(\"%s\") = ", text, number, message); +- for (i=0; ilength; i++) +- printf("%02x", (unsigned char) checksum->contents[i]); +- printf("\n"); +-} +- +-/* +- * Test the checksum verification of Old Style (tm) and correct RSA-MD[4,5]-DES +- * checksums. +- */ +- +-krb5_octet testkey[8] = { 0x45, 0x01, 0x49, 0x61, 0x58, 0x19, 0x1a, 0x3d }; +- +-int +-main(argc, argv) +- int argc; +- char **argv; +-{ +- int msgindex; +- size_t len; +- krb5_boolean valid; +- krb5_keyblock keyblock; +- krb5_key key; +- krb5_error_code kret=0; +- krb5_data plaintext; +- krb5_checksum checksum, knowncksum; +- +- /* this is a terrible seed, but that's ok for the test. */ +- +- plaintext.length = 8; +- plaintext.data = (char *) testkey; +- +- krb5_c_random_seed(/* XXX */ 0, &plaintext); +- +- keyblock.enctype = ENCTYPE_DES_CBC_CRC; +- keyblock.length = sizeof(testkey); +- keyblock.contents = testkey; +- +- krb5_k_create_key(NULL, &keyblock, &key); +- +- for (msgindex = 1; msgindex + 1 < argc; msgindex += 2) { +- plaintext.length = strlen(argv[msgindex]); +- plaintext.data = argv[msgindex]; +- +- /* Create a checksum. */ +- kret = krb5_k_make_checksum(NULL, CKTYPE, key, 0, &plaintext, +- &checksum); +- if (kret != 0) { +- printf("krb5_calculate_checksum choked with %d\n", kret); +- break; +- } +- print_checksum("correct", MD, argv[msgindex], &checksum); +- +- /* Verify it. */ +- kret = krb5_k_verify_checksum(NULL, key, 0, &plaintext, &checksum, +- &valid); +- if (kret != 0) { +- printf("verify on new checksum choked with %d\n", kret); +- break; +- } +- if (!valid) { +- printf("verify on new checksum failed\n"); +- kret = 1; +- break; +- } +- printf("Verify succeeded for \"%s\"\n", argv[msgindex]); +- +- /* Corrupt the checksum and see if it still verifies. */ +- checksum.contents[0]++; +- kret = krb5_k_verify_checksum(NULL, key, 0, &plaintext, &checksum, +- &valid); +- if (kret != 0) { +- printf("verify on new checksum choked with %d\n", kret); +- break; +- } +- if (valid) { +- printf("verify on new checksum succeeded, but shouldn't have\n"); +- kret = 1; +- break; +- } +- printf("Verify of bad checksum OK for \"%s\"\n", argv[msgindex]); +- free(checksum.contents); +- +- /* Verify a known-good checksum for this plaintext. */ +- kret = k5_hex_decode(argv[msgindex + 1], &knowncksum.contents, &len); +- if (kret) { +- printf("k5_hex_decode failed\n"); +- break; +- } +- knowncksum.length = len; +- knowncksum.checksum_type = CKTYPE; +- knowncksum.magic = KV5M_CHECKSUM; +- kret = krb5_k_verify_checksum(NULL, key, 0, &plaintext, &knowncksum, +- &valid); +- if (kret != 0) { +- printf("verify on known checksum choked with %d\n", kret); +- break; +- } +- if (!valid) { +- printf("verify on known checksum failed\n"); +- kret = 1; +- break; +- } +- printf("Verify on known checksum succeeded\n"); +- free(knowncksum.contents); +- } +- if (!kret) +- printf("%d tests passed successfully for MD%d checksum\n", (argc-1)/2, MD); +- +- krb5_k_free_key(NULL, key); +- +- return(kret); +-} +diff --git a/src/lib/crypto/crypto_tests/t_cksums.c b/src/lib/crypto/crypto_tests/t_cksums.c +index 5afc90ed8..4da14ea43 100644 +--- a/src/lib/crypto/crypto_tests/t_cksums.c ++++ b/src/lib/crypto/crypto_tests/t_cksums.c +@@ -27,7 +27,7 @@ + /* + * This harness tests checksum results against known values. With the -v flag, + * results for all tests are displayed. This harness only works for +- * deterministic checksums; for rsa-md4-des and rsa-md5-des, see t_cksum.c. ++ * deterministic checksums. + */ + + #include "k5-int.h" +@@ -40,12 +40,6 @@ struct test { + krb5_data keybits; + krb5_data cksum; + } test_cases[] = { +- { +- { KV5M_DATA, 3, "abc" }, +- CKSUMTYPE_CRC32, 0, 0, { KV5M_DATA, 0, "" }, +- { KV5M_DATA, 4, +- "\xD0\x98\x65\xCA" } +- }, + { + { KV5M_DATA, 3, "one" }, + CKSUMTYPE_RSA_MD4, 0, 0, { KV5M_DATA, 0, "" }, +diff --git a/src/lib/crypto/crypto_tests/t_combine.c b/src/lib/crypto/crypto_tests/t_combine.c +index 89219c762..ba0622bcf 100644 +--- a/src/lib/crypto/crypto_tests/t_combine.c ++++ b/src/lib/crypto/crypto_tests/t_combine.c +@@ -32,10 +32,6 @@ + + #include "k5-int.h" + +-unsigned char des_key1[] = "\x04\x86\xCD\x97\x61\xDF\xD6\x29"; +-unsigned char des_key2[] = "\x1A\x54\x9B\x7F\xDC\x20\x83\x0E"; +-unsigned char des_result[] = "\xC2\x13\x01\x52\x89\x26\xC4\xF7"; +- + unsigned char des3_key1[] = "\x10\xB6\x75\xD5\x5B\xD9\x6E\x73" + "\xFD\x54\xB3\x3D\x37\x52\xC1\x2A\xF7\x43\x91\xFE\x1C\x02\x37\x13"; + unsigned char des3_key2[] = "\xC8\xDA\x3E\xA7\xB6\x64\xAE\x7A" +@@ -48,20 +44,6 @@ main(int argc, char **argv) + { + krb5_keyblock kb1, kb2, result; + +- kb1.enctype = ENCTYPE_DES_CBC_CRC; +- kb1.contents = des_key1; +- kb1.length = 8; +- kb2.enctype = ENCTYPE_DES_CBC_CRC; +- kb2.contents = des_key2; +- kb2.length = 8; +- memset(&result, 0, sizeof(result)); +- if (krb5int_c_combine_keys(NULL, &kb1, &kb2, &result) != 0) +- abort(); +- if (result.enctype != ENCTYPE_DES_CBC_CRC || result.length != 8 || +- memcmp(result.contents, des_result, 8) != 0) +- abort(); +- krb5_free_keyblock_contents(NULL, &result); +- + kb1.enctype = ENCTYPE_DES3_CBC_SHA1; + kb1.contents = des3_key1; + kb1.length = 24; +diff --git a/src/lib/crypto/crypto_tests/t_crc.c b/src/lib/crypto/crypto_tests/t_crc.c +deleted file mode 100644 +index 8cd1d36cb..000000000 +--- a/src/lib/crypto/crypto_tests/t_crc.c ++++ /dev/null +@@ -1,148 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/crypto_tests/t_crc.c */ +-/* +- * Copyright 2002,2005 by the Massachusetts Institute of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* +- * Sanity checks for CRC32. +- */ +-#include +-#include +-#include +-#include +-#include +-#include +-#include "crypto_int.h" +- +-#define HEX 1 +-#define STR 2 +-struct crc_trial { +- int type; +- char *data; +- unsigned long sum; +-}; +- +-struct crc_trial trials[] = { +- {HEX, "01", 0x77073096}, +- {HEX, "02", 0xee0e612c}, +- {HEX, "04", 0x076dc419}, +- {HEX, "08", 0x0edb8832}, +- {HEX, "10", 0x1db71064}, +- {HEX, "20", 0x3b6e20c8}, +- {HEX, "40", 0x76dc4190}, +- {HEX, "80", 0xedb88320}, +- {HEX, "0100", 0x191b3141}, +- {HEX, "0200", 0x32366282}, +- {HEX, "0400", 0x646cc504}, +- {HEX, "0800", 0xc8d98a08}, +- {HEX, "1000", 0x4ac21251}, +- {HEX, "2000", 0x958424a2}, +- {HEX, "4000", 0xf0794f05}, +- {HEX, "8000", 0x3b83984b}, +- {HEX, "0001", 0x77073096}, +- {HEX, "0002", 0xee0e612c}, +- {HEX, "0004", 0x076dc419}, +- {HEX, "0008", 0x0edb8832}, +- {HEX, "0010", 0x1db71064}, +- {HEX, "0020", 0x3b6e20c8}, +- {HEX, "0040", 0x76dc4190}, +- {HEX, "0080", 0xedb88320}, +- {HEX, "01000000", 0xb8bc6765}, +- {HEX, "02000000", 0xaa09c88b}, +- {HEX, "04000000", 0x8f629757}, +- {HEX, "08000000", 0xc5b428ef}, +- {HEX, "10000000", 0x5019579f}, +- {HEX, "20000000", 0xa032af3e}, +- {HEX, "40000000", 0x9b14583d}, +- {HEX, "80000000", 0xed59b63b}, +- {HEX, "00010000", 0x01c26a37}, +- {HEX, "00020000", 0x0384d46e}, +- {HEX, "00040000", 0x0709a8dc}, +- {HEX, "00080000", 0x0e1351b8}, +- {HEX, "00100000", 0x1c26a370}, +- {HEX, "00200000", 0x384d46e0}, +- {HEX, "00400000", 0x709a8dc0}, +- {HEX, "00800000", 0xe1351b80}, +- {HEX, "00000100", 0x191b3141}, +- {HEX, "00000200", 0x32366282}, +- {HEX, "00000400", 0x646cc504}, +- {HEX, "00000800", 0xc8d98a08}, +- {HEX, "00001000", 0x4ac21251}, +- {HEX, "00002000", 0x958424a2}, +- {HEX, "00004000", 0xf0794f05}, +- {HEX, "00008000", 0x3b83984b}, +- {HEX, "00000001", 0x77073096}, +- {HEX, "00000002", 0xee0e612c}, +- {HEX, "00000004", 0x076dc419}, +- {HEX, "00000008", 0x0edb8832}, +- {HEX, "00000010", 0x1db71064}, +- {HEX, "00000020", 0x3b6e20c8}, +- {HEX, "00000040", 0x76dc4190}, +- {HEX, "00000080", 0xedb88320}, +- {STR, "foo", 0x7332bc33}, +- {STR, "test0123456789", 0xb83e88d6}, +- {STR, "MASSACHVSETTS INSTITVTE OF TECHNOLOGY", 0xe34180f7} +-}; +- +-#define NTRIALS (sizeof(trials) / sizeof(trials[0])) +- +- +-int +-main(void) +-{ +- unsigned int i; +- struct crc_trial trial; +- uint8_t *bytes; +- size_t len; +- unsigned long cksum; +- char *typestr; +- +- for (i = 0; i < NTRIALS; i++) { +- trial = trials[i]; +- switch (trial.type) { +- case STR: +- len = strlen(trial.data); +- typestr = "STR"; +- cksum = 0; +- mit_crc32(trial.data, len, &cksum); +- break; +- case HEX: +- typestr = "HEX"; +- if (k5_hex_decode(trial.data, &bytes, &len) != 0) +- abort(); +- cksum = 0; +- mit_crc32(bytes, len, &cksum); +- free(bytes); +- break; +- default: +- typestr = "BOGUS"; +- fprintf(stderr, "bad trial type %d\n", trial.type); +- exit(1); +- } +- printf("%s: %s \"%s\" = 0x%08lx\n", +- (trial.sum == cksum) ? "OK" : "***BAD***", +- typestr, trial.data, cksum); +- } +- exit(0); +-} +diff --git a/src/lib/crypto/crypto_tests/t_decrypt.c b/src/lib/crypto/crypto_tests/t_decrypt.c +index 4ae0256cc..a40a85500 100644 +--- a/src/lib/crypto/crypto_tests/t_decrypt.c ++++ b/src/lib/crypto/crypto_tests/t_decrypt.c +@@ -39,151 +39,6 @@ struct test { + krb5_data keybits; + krb5_data ciphertext; + } test_cases[] = { +- { +- ENCTYPE_DES_CBC_CRC, +- { KV5M_DATA, 0, "" }, 0, +- { KV5M_DATA, 8, +- "\x45\xE6\x08\x7C\xDF\x13\x8F\xB5" }, +- { KV5M_DATA, 16, +- "\x28\xF6\xB0\x9A\x01\x2B\xCC\xF7\x2F\xB0\x51\x22\xB2\x83\x9E\x6E" } +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- { KV5M_DATA, 1, "1" }, 1, +- { KV5M_DATA, 8, +- "\x92\xA7\x15\x58\x10\x58\x6B\x2F" }, +- { KV5M_DATA, 16, +- "\xB4\xC8\x71\xC2\xF3\xE7\xBF\x76\x05\xEF\xD6\x2F\x2E\xEE\xC2\x05" } +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- { KV5M_DATA, 9, "9 bytesss" }, 2, +- { KV5M_DATA, 8, +- "\xA4\xB9\x51\x4A\x61\x64\x64\x23" }, +- { KV5M_DATA, 24, +- "\x5F\x14\xC3\x51\x78\xD3\x3D\x7C\xDE\x0E\xC1\x69\xC6\x23\xCC\x83" +- "\x21\xB7\xB8\xBD\x34\xEA\x7E\xFE" } +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- { KV5M_DATA, 13, "13 bytes byte", }, 3, +- { KV5M_DATA, 8, +- "\x2F\x16\xA2\xA7\xFD\xB0\x57\x68" }, +- { KV5M_DATA, 32, +- "\x0B\x58\x8E\x38\xD9\x71\x43\x3C\x9D\x86\xD8\xBA\xEB\xF6\x3E\x4C" +- "\x1A\x01\x66\x6E\x76\xD8\xA5\x4A\x32\x93\xF7\x26\x79\xED\x88\xC9" } +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- { KV5M_DATA, 30, "30 bytes bytes bytes bytes byt", }, 4, +- { KV5M_DATA, 8, +- "\xBC\x8F\x70\xFD\x20\x97\xD6\x7C" }, +- { KV5M_DATA, 48, +- "\x38\xD6\x32\xD2\xC2\x0A\x7C\x2E\xA2\x50\xFC\x8E\xCE\x42\x93\x8E" +- "\x92\xA9\xF5\xD3\x02\x50\x26\x65\xC1\xA3\x37\x29\xC1\x05\x0D\xC2" +- "\x05\x62\x98\xFB\xFB\x16\x82\xCE\xEB\x65\xE5\x92\x04\xFD\xA7\xDF" } +- }, +- +- { +- ENCTYPE_DES_CBC_MD4, +- { KV5M_DATA, 0, "", }, 0, +- { KV5M_DATA, 8, +- "\x13\xEF\x45\xD0\xD6\xD9\xA1\x5D" }, +- { KV5M_DATA, 24, +- "\x1F\xB2\x02\xBF\x07\xAF\x30\x47\xFB\x78\x01\xE5\x88\x56\x86\x86" +- "\xBA\x63\xD7\x8B\xE3\xE8\x7D\xC7" } +- }, +- { +- ENCTYPE_DES_CBC_MD4, +- { KV5M_DATA, 1, "1", }, 1, +- { KV5M_DATA, 8, +- "\x64\x68\x86\x54\xDC\x26\x9E\x67" }, +- { KV5M_DATA, 32, +- "\x1F\x6C\xB9\xCE\xCB\x73\xF7\x55\xAB\xFD\xB3\xD5\x65\xBD\x31\xD5" +- "\xA2\xE6\x4B\xFE\x44\xC4\x91\xE2\x0E\xEB\xE5\xBD\x20\xE4\xD2\xA9" } +- }, +- { +- ENCTYPE_DES_CBC_MD4, +- { KV5M_DATA, 9, "9 bytesss", }, 2, +- { KV5M_DATA, 8, +- "\x68\x04\xFB\x26\xDF\x8A\x4C\x32" }, +- { KV5M_DATA, 40, +- "\x08\xA5\x3D\x62\xFE\xC3\x33\x8A\xD1\xD2\x18\xE6\x0D\xBD\xD3\xB2" +- "\x12\x94\x06\x79\xD1\x25\xE0\x62\x1B\x3B\xAB\x46\x80\xCE\x03\x67" +- "\x6A\x2C\x42\x0E\x9B\xE7\x84\xEB" } +- }, +- { +- ENCTYPE_DES_CBC_MD4, +- { KV5M_DATA, 13, "13 bytes byte", }, 3, +- { KV5M_DATA, 8, +- "\x23\x4A\x43\x6E\xC7\x2F\xA8\x0B" }, +- { KV5M_DATA, 40, +- "\x17\xCD\x45\xE1\x4F\xF0\x6B\x28\x40\xA6\x03\x6E\x9A\xA7\xA4\x14" +- "\x4E\x29\x76\x81\x44\xA0\xC1\x82\x7D\x8C\x4B\xC7\xC9\x90\x6E\x72" +- "\xCD\x4D\xC3\x28\xF6\x64\x8C\x99" } +- }, +- { +- ENCTYPE_DES_CBC_MD4, +- { KV5M_DATA, 30, "30 bytes bytes bytes bytes byt", }, 4, +- { KV5M_DATA, 8, +- "\x1F\xD5\xF7\x43\x34\xC4\xFB\x8C" }, +- { KV5M_DATA, 56, +- "\x51\x13\x4C\xD8\x95\x1E\x9D\x57\xC0\xA3\x60\x53\xE0\x4C\xE0\x3E" +- "\xCB\x84\x22\x48\x8F\xDD\xC5\xC0\x74\xC4\xD8\x5E\x60\xA2\xAE\x42" +- "\x3C\x3C\x70\x12\x01\x31\x4F\x36\x2C\xB0\x74\x48\x09\x16\x79\xC6" +- "\xA4\x96\xC1\x1D\x7B\x93\xC7\x1B" } +- }, +- +- { +- ENCTYPE_DES_CBC_MD5, +- { KV5M_DATA, 0, "", }, 0, +- { KV5M_DATA, 8, +- "\x4A\x54\x5E\x0B\xF7\xA2\x26\x31" }, +- { KV5M_DATA, 24, +- "\x78\x4C\xD8\x15\x91\xA0\x34\xBE\x82\x55\x6F\x56\xDC\xA3\x22\x4B" +- "\x62\xD9\x95\x6F\xA9\x0B\x1B\x93" } +- }, +- { +- ENCTYPE_DES_CBC_MD5, +- { KV5M_DATA, 1, "1", }, 1, +- { KV5M_DATA, 8, +- "\xD5\x80\x4A\x26\x9D\xC4\xE6\x45" }, +- { KV5M_DATA, 32, +- "\xFF\xA2\x5C\x7B\xE2\x87\x59\x6B\xFE\x58\x12\x6E\x90\xAA\xA0\xF1" +- "\x2D\x9A\x82\xA0\xD8\x6D\xF6\xD5\xF9\x07\x4B\x6B\x39\x9E\x7F\xF1" } +- }, +- { +- ENCTYPE_DES_CBC_MD5, +- { KV5M_DATA, 9, "9 bytesss", }, 2, +- { KV5M_DATA, 8, +- "\xC8\x31\x2F\x7F\x83\xEA\x46\x40" }, +- { KV5M_DATA, 40, +- "\xE7\x85\x03\x37\xF2\xCC\x5E\x3F\x35\xCE\x3D\x69\xE2\xC3\x29\x86" +- "\x38\xA7\xAA\x44\xB8\x78\x03\x1E\x39\x85\x1E\x47\xC1\x5B\x5D\x0E" +- "\xE7\xE7\xAC\x54\xDE\x11\x1D\x80" } +- }, +- { +- ENCTYPE_DES_CBC_MD5, +- { KV5M_DATA, 13, "13 bytes byte", }, 3, +- { KV5M_DATA, 8, +- "\x7F\xDA\x3E\x62\xAD\x8A\xF1\x8C" }, +- { KV5M_DATA, 40, +- "\xD7\xA8\x03\x2E\x19\x99\x4C\x92\x87\x77\x50\x65\x95\xFB\xDA\x98" +- "\x83\x15\x8A\x85\x14\x54\x8E\x29\x6E\x91\x1C\x29\xF4\x65\xC6\x72" +- "\x36\x60\x00\x55\x8B\xFC\x2E\x88" } +- }, +- { +- ENCTYPE_DES_CBC_MD5, +- { KV5M_DATA, 30, "30 bytes bytes bytes bytes byt", }, 4, +- { KV5M_DATA, 8, +- "\xD3\xD6\x83\x29\x70\xA7\x37\x52" }, +- { KV5M_DATA, 56, +- "\x8A\x48\x16\x6A\x4C\x6F\xEA\xE6\x07\xA8\xCF\x68\xB3\x81\xC0\x75" +- "\x5E\x40\x2B\x19\xDB\xC0\xF8\x1A\x7D\x7C\xA1\x9A\x25\xE0\x52\x23" +- "\xF6\x06\x44\x09\xBF\x5A\x4F\x50\xAC\xD8\x26\x63\x9F\xFA\x76\x73" +- "\xFD\x32\x4E\xC1\x9E\x42\x95\x02" } +- }, +- + { + ENCTYPE_DES3_CBC_SHA1, + { KV5M_DATA, 0, "", }, 0, +@@ -669,9 +524,6 @@ printhex(const char *head, void *data, size_t len) + + static krb5_enctype + enctypes[] = { +- ENCTYPE_DES_CBC_CRC, +- ENCTYPE_DES_CBC_MD4, +- ENCTYPE_DES_CBC_MD5, + ENCTYPE_DES3_CBC_SHA1, + ENCTYPE_ARCFOUR_HMAC, + ENCTYPE_ARCFOUR_HMAC_EXP, +diff --git a/src/lib/crypto/crypto_tests/t_encrypt.c b/src/lib/crypto/crypto_tests/t_encrypt.c +index 4afbddedb..bd9b94691 100644 +--- a/src/lib/crypto/crypto_tests/t_encrypt.c ++++ b/src/lib/crypto/crypto_tests/t_encrypt.c +@@ -37,9 +37,6 @@ + + /* What enctypes should we test?*/ + krb5_enctype interesting_enctypes[] = { +- ENCTYPE_DES_CBC_CRC, +- ENCTYPE_DES_CBC_MD4, +- ENCTYPE_DES_CBC_MD5, + ENCTYPE_DES3_CBC_SHA1, + ENCTYPE_ARCFOUR_HMAC, + ENCTYPE_ARCFOUR_HMAC_EXP, +diff --git a/src/lib/crypto/crypto_tests/t_short.c b/src/lib/crypto/crypto_tests/t_short.c +index 40fa2821f..d4c2b97df 100644 +--- a/src/lib/crypto/crypto_tests/t_short.c ++++ b/src/lib/crypto/crypto_tests/t_short.c +@@ -34,9 +34,6 @@ + #include "k5-int.h" + + krb5_enctype interesting_enctypes[] = { +- ENCTYPE_DES_CBC_CRC, +- ENCTYPE_DES_CBC_MD4, +- ENCTYPE_DES_CBC_MD5, + ENCTYPE_DES3_CBC_SHA1, + ENCTYPE_ARCFOUR_HMAC, + ENCTYPE_ARCFOUR_HMAC_EXP, +diff --git a/src/lib/crypto/crypto_tests/t_str2key.c b/src/lib/crypto/crypto_tests/t_str2key.c +index 27896e61e..cdb1acc6d 100644 +--- a/src/lib/crypto/crypto_tests/t_str2key.c ++++ b/src/lib/crypto/crypto_tests/t_str2key.c +@@ -35,280 +35,6 @@ struct test { + krb5_error_code expected_err; + krb5_boolean allow_weak; + } test_cases[] = { +- /* AFS string-to-key tests from old t_afss2k.c. */ +- { +- ENCTYPE_DES_CBC_CRC, +- "", +- { KV5M_DATA, 15, "Sodium Chloride" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xA4\xD0\xD0\x9B\x86\x92\xB0\xC2" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "M", +- { KV5M_DATA, 15, "Sodium Chloride" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xF1\xF2\x9E\xAB\xD0\xEF\xDF\x73" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My", +- { KV5M_DATA, 15, "Sodium Chloride" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xD6\x85\x61\xC4\xF2\x94\xF4\xA1" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My ", +- { KV5M_DATA, 15, "Sodium Chloride" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xD0\xE3\xA7\x83\x94\x61\xE0\xD0" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My P", +- { KV5M_DATA, 15, "Sodium Chloride" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xD5\x62\xCD\x94\x61\xCB\x97\xDF" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My Pa", +- { KV5M_DATA, 15, "Sodium Chloride" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\x9E\xA2\xA2\xEC\xA8\x8C\x6B\x8F" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My Pas", +- { KV5M_DATA, 15, "Sodium Chloride" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xE3\x91\x6D\xD3\x85\xF1\x67\xC4" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My Pass", +- { KV5M_DATA, 15, "Sodium Chloride" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xF4\xC4\x73\xC8\x8A\xE9\x94\x6D" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My Passw", +- { KV5M_DATA, 15, "Sodium Chloride" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xA1\x9E\xB3\xAD\x6B\xE3\xAB\xD9" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My Passwo", +- { KV5M_DATA, 15, "Sodium Chloride" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xAD\xA1\xCE\x10\x37\x83\xA7\x8C" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My Passwor", +- { KV5M_DATA, 15, "Sodium Chloride" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xD3\x01\xD0\xF7\x3E\x7A\x49\x0B" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My Password", +- { KV5M_DATA, 15, "Sodium Chloride" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xB6\x2A\x4A\xEC\x9D\x4C\x68\xDF" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "", +- { KV5M_DATA, 4, "NaCl" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\x61\xEF\xE6\x83\xE5\x8A\x6B\x98" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "M", +- { KV5M_DATA, 4, "NaCl" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\x68\xCD\x68\xAD\xC4\x86\xCD\xE5" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My", +- { KV5M_DATA, 4, "NaCl" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\x83\xA1\xC8\x86\x8F\x67\xD0\x62" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My ", +- { KV5M_DATA, 4, "NaCl" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\x9E\xC7\x8F\xA4\xA4\xB3\xE0\xD5" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My P", +- { KV5M_DATA, 4, "NaCl" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xD9\x92\x86\x8F\x9D\x8C\x85\xE6" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My Pa", +- { KV5M_DATA, 4, "NaCl" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xDA\xF2\x92\x83\xF4\x9B\xA7\xAD" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My Pas", +- { KV5M_DATA, 4, "NaCl" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\x91\xCD\xAD\xEF\x86\xDF\xD3\xA2" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My Pass", +- { KV5M_DATA, 4, "NaCl" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\x73\xD3\x67\x68\x8F\x6E\xE3\x73" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My Passw", +- { KV5M_DATA, 4, "NaCl" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xC4\x61\x85\x9D\xAD\xF4\xDC\xB0" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My Passwo", +- { KV5M_DATA, 4, "NaCl" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\xE9\x02\x83\x16\x2C\xEC\xE0\x08" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My Passwor", +- { KV5M_DATA, 4, "NaCl" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\x61\xC8\x26\x29\xD9\x73\x6E\xB6" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "My Password", +- { KV5M_DATA, 4, "NaCl" }, +- { KV5M_DATA, 1, "\1" }, +- { KV5M_DATA, 8, "\x8C\xA8\x9E\xC4\xA8\xDC\x31\x73" }, +- 0, +- FALSE +- }, +- +- /* Test vectors from RFC 3961 appendix A.2. */ +- { +- ENCTYPE_DES_CBC_CRC, +- "password", +- { KV5M_DATA, 21, "ATHENA.MIT.EDUraeburn" }, +- { KV5M_DATA, 1, "\0" }, +- { KV5M_DATA, 8, "\xCB\xC2\x2F\xAE\x23\x52\x98\xE3" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "potatoe", +- { KV5M_DATA, 19, "WHITEHOUSE.GOVdanny" }, +- { KV5M_DATA, 1, "\0" }, +- { KV5M_DATA, 8, "\xDF\x3D\x32\xA7\x4F\xD9\x2A\x01" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "\xF0\x9D\x84\x9E", +- { KV5M_DATA, 18, "EXAMPLE.COMpianist" }, +- { KV5M_DATA, 1, "\0" }, +- { KV5M_DATA, 8, "\x4F\xFB\x26\xBA\xB0\xCD\x94\x13" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "\xC3\x9F", +- { KV5M_DATA, 23, "ATHENA.MIT.EDUJuri\xC5\xA1\x69\xC4\x87" }, +- { KV5M_DATA, 1, "\0" }, +- { KV5M_DATA, 8, "\x62\xC8\x1A\x52\x32\xB5\xE6\x9D" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "11119999", +- { KV5M_DATA, 8, "AAAAAAAA" }, +- { KV5M_DATA, 1, "\0" }, +- { KV5M_DATA, 8, "\x98\x40\x54\xd0\xf1\xa7\x3e\x31" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES_CBC_CRC, +- "NNNN6666", +- { KV5M_DATA, 8, "FFFFAAAA" }, +- { KV5M_DATA, 1, "\0" }, +- { KV5M_DATA, 8, "\xC4\xBF\x6B\x25\xAD\xF7\xA4\xF8" }, +- 0, +- FALSE +- }, +- + /* Test vectors from RFC 3961 appendix A.4. */ + { + ENCTYPE_DES3_CBC_SHA1, +diff --git a/src/lib/crypto/crypto_tests/vectors.c b/src/lib/crypto/crypto_tests/vectors.c +index c1a765732..bcf5c9106 100644 +--- a/src/lib/crypto/crypto_tests/vectors.c ++++ b/src/lib/crypto/crypto_tests/vectors.c +@@ -30,7 +30,8 @@ + * + * N.B.: Doesn't compile -- this file uses some routines internal to our + * crypto library which are declared "static" and thus aren't accessible +- * without modifying the other sources. ++ * without modifying the other sources. Additionally, some ciphers have been ++ * removed. + */ + + #include +diff --git a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp +index db899a1dc..740425c69 100644 +--- a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp ++++ b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp +@@ -18,8 +18,8 @@ proc test200 {} { + + # I'd like to specify a long list of keysalt tuples and make sure + # that chpass does the right thing, but we can only use those +- # enctypes that krbtgt has a key for: des-cbc-crc:normal +- # according to the prototype kdc.conf. ++ # enctypes that krbtgt has a key for: the AES enctypes, according to ++ # the prototype kdc.conf. + if {! [cmd [format { + kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ + $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +@@ -53,10 +53,10 @@ proc test200 {} { + } + + # XXX Perhaps I should actually check the key type returned. +- if {$num_keys == 2} { ++ if {$num_keys == 5} { + pass "$test" + } else { +- fail "$test: $num_keys keys, should be 2" ++ fail "$test: $num_keys keys, should be 5" + } + if { ! [cmd {kadm5_destroy $server_handle}]} { + perror "$test: unexpected failure in destroy" +diff --git a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp +index 8526897ed..3ea1ba29b 100644 +--- a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp ++++ b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp +@@ -143,8 +143,8 @@ proc test101_102 {rpc} { + } + + set failed 0 +- if {$num_keys != 2} { +- fail "$test: num_keys $num_keys should be 2" ++ if {$num_keys != 5} { ++ fail "$test: num_keys $num_keys should be 5" + set failed 1 + } + for {set i 0} {$i < $num_keys} {incr i} { +diff --git a/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp +index ee652cbd3..2925c1c43 100644 +--- a/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp ++++ b/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp +@@ -16,10 +16,9 @@ proc test100 {} { + return + } + +- # I'd like to specify a long list of keysalt tuples and make sure +- # that randkey does the right thing, but we can only use those +- # enctypes that krbtgt has a key for: des-cbc-crc:normal and +- # des-cbc-crc:v4, according to the prototype kdc.conf. ++ # I'd like to specify a long list of keysalt tuples and make sure that ++ # randkey does the right thing, but we can only use those enctypes that ++ # krbtgt has a key for: 3DES and AES, according to the prototype kdc.conf. + if {! [cmd [format { + kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ + $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +@@ -47,10 +46,10 @@ proc test100 {} { + } + + # XXX Perhaps I should actually check the key type returned. +- if {$num_keys == 2} { ++ if {$num_keys == 5} { + pass "$test" + } else { +- fail "$test: $num_keys keys, should be 2" ++ fail "$test: $num_keys keys, should be 5" + } + if { ! [cmd {kadm5_destroy $server_handle}]} { + perror "$test: unexpected failure in destroy" +diff --git a/src/lib/kadm5/unit-test/setkey-test.c b/src/lib/kadm5/unit-test/setkey-test.c +index fa2392f81..8e7df96e9 100644 +--- a/src/lib/kadm5/unit-test/setkey-test.c ++++ b/src/lib/kadm5/unit-test/setkey-test.c +@@ -19,15 +19,15 @@ need a random number generator + #endif /* no random */ + + krb5_keyblock test1[] = { +- {0, ENCTYPE_DES_CBC_CRC, 0, 0}, ++ {0, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0, 0}, + {-1}, + }; + krb5_keyblock test2[] = { +- {0, ENCTYPE_DES_CBC_CRC, 0, 0}, ++ {0, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0, 0}, + {-1}, + }; + krb5_keyblock test3[] = { +- {0, ENCTYPE_DES_CBC_CRC, 0, 0}, ++ {0, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0, 0}, + {-1}, + }; + +diff --git a/src/lib/krb5/keytab/t_keytab.c b/src/lib/krb5/keytab/t_keytab.c +index c845596d6..ea4ce6819 100644 +--- a/src/lib/krb5/keytab/t_keytab.c ++++ b/src/lib/krb5/keytab/t_keytab.c +@@ -96,6 +96,8 @@ kt_test(krb5_context context, const char *name) + krb5_principal princ; + krb5_kt_cursor cursor, cursor2; + int cnt; ++ krb5_enctype e1 = ENCTYPE_AES128_CTS_HMAC_SHA256_128, ++ e2 = ENCTYPE_AES256_CTS_HMAC_SHA384_192; + + kret = krb5_kt_resolve(context, name, &kt); + CHECK(kret, "resolve"); +@@ -139,9 +141,9 @@ kt_test(krb5_context context, const char *name) + /* =================== Add entries to keytab ================= */ + /* + * Add the following for this principal +- * enctype 1, kvno 1, key = "1" +- * enctype 2, kvno 1, key = "1" +- * enctype 1, kvno 2, key = "2" ++ * enctype e1, kvno 1, key = "1" ++ * enctype e2, kvno 1, key = "1" ++ * enctype e1, kvno 2, key = "2" + */ + memset(&kent, 0, sizeof(kent)); + kent.magic = KV5M_KEYTAB_ENTRY; +@@ -149,7 +151,7 @@ kt_test(krb5_context context, const char *name) + kent.timestamp = 327689; + kent.vno = 1; + kent.key.magic = KV5M_KEYBLOCK; +- kent.key.enctype = 1; ++ kent.key.enctype = e1; + kent.key.length = 1; + kent.key.contents = (krb5_octet *) "1"; + +@@ -157,11 +159,11 @@ kt_test(krb5_context context, const char *name) + kret = krb5_kt_add_entry(context, kt, &kent); + CHECK(kret, "Adding initial entry"); + +- kent.key.enctype = 2; ++ kent.key.enctype = e2; + kret = krb5_kt_add_entry(context, kt, &kent); + CHECK(kret, "Adding second entry"); + +- kent.key.enctype = 1; ++ kent.key.enctype = e1; + kent.vno = 2; + kent.key.contents = (krb5_octet *) "2"; + kret = krb5_kt_add_entry(context, kt, &kent); +@@ -183,7 +185,7 @@ kt_test(krb5_context context, const char *name) + cnt = 0; + while((kret = krb5_kt_next_entry(context, kt, &kent, &cursor)) == 0) { + if(((kent.vno != 1) && (kent.vno != 2)) || +- ((kent.key.enctype != 1) && (kent.key.enctype != 2)) || ++ ((kent.key.enctype != e1) && (kent.key.enctype != e2)) || + (kent.key.length != 1) || + (kent.key.contents[0] != kent.vno +'0')) { + fprintf(stderr, "Error in read contents\n"); +@@ -231,7 +233,7 @@ kt_test(krb5_context context, const char *name) + /* Ensure a valid answer - we did not specify an enctype or kvno */ + if (!krb5_principal_compare(context, princ, kent.principal) || + ((kent.vno != 1) && (kent.vno != 2)) || +- ((kent.key.enctype != 1) && (kent.key.enctype != 2)) || ++ ((kent.key.enctype != e1) && (kent.key.enctype != e2)) || + (kent.key.length != 1) || + (kent.key.contents[0] != kent.vno +'0')) { + fprintf(stderr, "Retrieved principal does not check\n"); +@@ -243,12 +245,12 @@ kt_test(krb5_context context, const char *name) + /* Try to lookup a specific enctype - but unspecified kvno - should give + * max kvno + */ +- kret = krb5_kt_get_entry(context, kt, princ, 0, 1, &kent); ++ kret = krb5_kt_get_entry(context, kt, princ, 0, e1, &kent); + CHECK(kret, "looking up principal"); + + /* Ensure a valid answer - we did specified an enctype */ + if (!krb5_principal_compare(context, princ, kent.principal) || +- (kent.vno != 2) || (kent.key.enctype != 1) || ++ (kent.vno != 2) || (kent.key.enctype != e1) || + (kent.key.length != 1) || + (kent.key.contents[0] != kent.vno +'0')) { + fprintf(stderr, "Retrieved principal does not check\n"); +@@ -266,7 +268,7 @@ kt_test(krb5_context context, const char *name) + + /* Ensure a valid answer - we did not specify a kvno */ + if (!krb5_principal_compare(context, princ, kent.principal) || +- (kent.vno != 2) || (kent.key.enctype != 1) || ++ (kent.vno != 2) || (kent.key.enctype != e1) || + (kent.key.length != 1) || + (kent.key.contents[0] != kent.vno +'0')) { + fprintf(stderr, "Retrieved principal does not check\n"); +@@ -281,11 +283,11 @@ kt_test(krb5_context context, const char *name) + + /* Try to lookup specified enctype and kvno */ + +- kret = krb5_kt_get_entry(context, kt, princ, 1, 1, &kent); ++ kret = krb5_kt_get_entry(context, kt, princ, 1, e1, &kent); + CHECK(kret, "looking up principal"); + + if (!krb5_principal_compare(context, princ, kent.principal) || +- (kent.vno != 1) || (kent.key.enctype != 1) || ++ (kent.vno != 1) || (kent.key.enctype != e1) || + (kent.key.length != 1) || + (kent.key.contents[0] != kent.vno +'0')) { + fprintf(stderr, "Retrieved principal does not check\n"); +@@ -334,7 +336,7 @@ kt_test(krb5_context context, const char *name) + + /* Try to lookup specified enctype and kvno - that does not exist*/ + +- kret = krb5_kt_get_entry(context, kt, princ, 3, 1, &kent); ++ kret = krb5_kt_get_entry(context, kt, princ, 3, e1, &kent); + CHECK_ERR(kret, KRB5_KT_KVNONOTFOUND, + "looking up specific principal, kvno, enctype"); + +@@ -347,12 +349,12 @@ kt_test(krb5_context context, const char *name) + kret = krb5_parse_name(context, "test/test2@TEST.MIT.EDU", &princ); + CHECK(kret, "parsing principal"); + +- kret = krb5_kt_get_entry(context, kt, princ, 0, 1, &kent); ++ kret = krb5_kt_get_entry(context, kt, princ, 0, e1, &kent); + CHECK(kret, "looking up principal"); + +- /* Ensure a valid answer - we are looking for max(kvno) and enc=1 */ ++ /* Ensure a valid answer - we are looking for max(kvno) and enc=e1 */ + if (!krb5_principal_compare(context, princ, kent.principal) || +- (kent.vno != 2) || (kent.key.enctype != 1) || ++ (kent.vno != 2) || (kent.key.enctype != e1) || + (kent.key.length != 1) || + (kent.key.contents[0] != kent.vno +'0')) { + fprintf(stderr, "Retrieved principal does not check\n"); +@@ -368,12 +370,12 @@ kt_test(krb5_context context, const char *name) + krb5_free_keytab_entry_contents(context, &kent); + /* And ensure gone */ + +- kret = krb5_kt_get_entry(context, kt, princ, 0, 1, &kent); ++ kret = krb5_kt_get_entry(context, kt, princ, 0, e1, &kent); + CHECK(kret, "looking up principal"); + + /* Ensure a valid answer - kvno should now be 1 - we deleted 2 */ + if (!krb5_principal_compare(context, princ, kent.principal) || +- (kent.vno != 1) || (kent.key.enctype != 1) || ++ (kent.vno != 1) || (kent.key.enctype != e1) || + (kent.key.length != 1) || + (kent.key.contents[0] != kent.vno +'0')) { + fprintf(stderr, "Delete principal check failed\n"); +diff --git a/src/lib/krb5/krb/t_etypes.c b/src/lib/krb5/krb/t_etypes.c +index 317637684..f609e938a 100644 +--- a/src/lib/krb5/krb/t_etypes.c ++++ b/src/lib/krb5/krb/t_etypes.c +@@ -36,20 +36,6 @@ static struct { + krb5_error_code expected_err_noweak; + krb5_error_code expected_err_weak; + } tests[] = { +- /* Empty string, unused default list */ +- { "", +- { ENCTYPE_DES_CBC_CRC, 0 }, +- { 0 }, +- { 0 }, +- 0, 0 +- }, +- /* Single weak enctype */ +- { "des-cbc-md4", +- { 0 }, +- { 0 }, +- { ENCTYPE_DES_CBC_MD4, 0 }, +- 0, 0 +- }, + /* Single non-weak enctype */ + { "aes128-cts-hmac-sha1-96", + { 0 }, +@@ -57,35 +43,11 @@ static struct { + { ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0 }, + 0, 0 + }, +- /* Two enctypes, one an alias, one weak */ +- { "rc4-hmac des-cbc-md5", +- { 0 }, +- { ENCTYPE_ARCFOUR_HMAC, 0 }, +- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_DES_CBC_MD5, 0 }, +- 0, 0 +- }, +- /* Three enctypes, all weak, case variation, funky separators */ +- { " deS-HMac-shA1 , arCFour-hmaC-mD5-exp\tdeS3-Cbc-RAw\n", +- { 0 }, +- { 0 }, +- { ENCTYPE_DES_HMAC_SHA1, ENCTYPE_ARCFOUR_HMAC_EXP, +- ENCTYPE_DES3_CBC_RAW, 0 }, +- 0, 0 +- }, +- /* Default set with enctypes added (one weak in each pair) */ +- { "DEFAULT des-cbc-raw +des3-hmac-sha1", +- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_ARCFOUR_HMAC_EXP, 0 }, +- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_DES3_CBC_SHA1, 0 }, +- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_ARCFOUR_HMAC_EXP, +- ENCTYPE_DES_CBC_RAW, ENCTYPE_DES3_CBC_SHA1, 0 }, +- 0, 0 +- }, + /* Default set with enctypes removed */ + { "default -aes128-cts -des-hmac-sha1", +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +- ENCTYPE_DES_CBC_MD5, ENCTYPE_DES_HMAC_SHA1, 0 }, ++ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0 }, ++ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, + { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_DES_CBC_MD5, 0 }, + 0, 0 + }, + /* Family followed by enctype */ +@@ -105,31 +67,22 @@ static struct { + { ENCTYPE_CAMELLIA128_CTS_CMAC, 0 }, + { ENCTYPE_CAMELLIA128_CTS_CMAC, 0 } + }, +- /* Enctype followed by two families */ +- { "+rc4-hmAC des3 +des", +- { 0 }, +- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_DES3_CBC_SHA1, 0 }, +- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_DES3_CBC_SHA1, ENCTYPE_DES_CBC_CRC, +- ENCTYPE_DES_CBC_MD5, ENCTYPE_DES_CBC_MD4 }, +- 0, 0 +- }, + /* Default set with family added and enctype removed */ + { "DEFAULT +aes -arcfour-hmac-md5", +- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_DES3_CBC_SHA1, ENCTYPE_DES_CBC_CRC, 0 }, ++ { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_DES3_CBC_SHA1, 0 }, + { ENCTYPE_DES3_CBC_SHA1, ENCTYPE_AES256_CTS_HMAC_SHA1_96, + ENCTYPE_AES128_CTS_HMAC_SHA1_96, ENCTYPE_AES256_CTS_HMAC_SHA384_192, + ENCTYPE_AES128_CTS_HMAC_SHA256_128, 0 }, +- { ENCTYPE_DES3_CBC_SHA1, ENCTYPE_DES_CBC_CRC, ++ { ENCTYPE_DES3_CBC_SHA1, + ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, + ENCTYPE_AES256_CTS_HMAC_SHA384_192, ENCTYPE_AES128_CTS_HMAC_SHA256_128, + 0 }, + 0, 0 + }, + /* Default set with families removed and enctypes added (one redundant) */ +- { "DEFAULT -des -des3 rc4-hmac rc4-hmac-exp", ++ { "DEFAULT -des3 rc4-hmac rc4-hmac-exp", + { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +- ENCTYPE_DES3_CBC_SHA1, ENCTYPE_ARCFOUR_HMAC, +- ENCTYPE_DES_CBC_CRC, ENCTYPE_DES_CBC_MD5, ENCTYPE_DES_CBC_MD4, 0 }, ++ ENCTYPE_DES3_CBC_SHA1, ENCTYPE_ARCFOUR_HMAC, 0 }, + { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, + ENCTYPE_ARCFOUR_HMAC, 0 }, + { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +@@ -158,17 +111,17 @@ static struct { + }, + /* Test krb5_set_default_in_tkt_ktypes */ + { NULL, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_DES_CBC_CRC, 0 }, + { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_DES_CBC_CRC, 0 }, ++ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, ++ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, + 0, 0 + }, + /* Should get KRB5_CONFIG_ETYPE_NOSUPP if app-provided list has no strong + * enctypes and allow_weak_crypto=false. */ + { NULL, +- { ENCTYPE_DES_CBC_CRC, 0 }, ++ { ENCTYPE_ARCFOUR_HMAC_EXP, 0 }, + { 0 }, +- { ENCTYPE_DES_CBC_CRC, 0 }, ++ { ENCTYPE_ARCFOUR_HMAC_EXP, 0 }, + KRB5_CONFIG_ETYPE_NOSUPP, 0 + }, + /* Should get EINVAL if app provides an empty list. */ +diff --git a/src/lib/krb5/krb/t_ser.c b/src/lib/krb5/krb/t_ser.c +index 1d6cceaa2..f1a8c2553 100644 +--- a/src/lib/krb5/krb/t_ser.c ++++ b/src/lib/krb5/krb/t_ser.c +@@ -272,7 +272,7 @@ ser_acontext_test(krb5_context kcontext, int verbose) + KV5M_AUTH_CONTEXT))) { + memset(&ukeyblock, 0, sizeof(ukeyblock)); + memset(keydata, 0, sizeof(keydata)); +- ukeyblock.enctype = ENCTYPE_DES_CBC_MD5; ++ ukeyblock.enctype = ENCTYPE_AES128_CTS_HMAC_SHA256_128; + ukeyblock.length = sizeof(keydata); + ukeyblock.contents = keydata; + keydata[0] = 0xde; +diff --git a/src/lib/krb5/os/t_trace.c b/src/lib/krb5/os/t_trace.c +index 5aea68e8d..10ba8d0ac 100644 +--- a/src/lib/krb5/os/t_trace.c ++++ b/src/lib/krb5/os/t_trace.c +@@ -204,7 +204,7 @@ main (int argc, char *argv[]) + padatap = NULL; + + TRACE(ctx, "krb5_enctype, display shortest name of enctype: {etype}", +- ENCTYPE_DES_CBC_CRC); ++ ENCTYPE_AES128_CTS_HMAC_SHA1_96); + TRACE(ctx, "krb5_enctype *, display list of enctypes: {etypes}", enctypes); + TRACE(ctx, "krb5_enctype *, display list of enctypes: {etypes}", NULL); + +diff --git a/src/lib/krb5/os/t_trace.ref b/src/lib/krb5/os/t_trace.ref +index bd5d9b6b6..044a66999 100644 +--- a/src/lib/krb5/os/t_trace.ref ++++ b/src/lib/krb5/os/t_trace.ref +@@ -40,7 +40,7 @@ int, krb5_principal type: NT 4 style name and SID + int, krb5_principal type: ? + krb5_pa_data **, display list of padata type numbers: PA-PW-SALT (3), 0 + krb5_pa_data **, display list of padata type numbers: (empty) +-krb5_enctype, display shortest name of enctype: des-cbc-crc ++krb5_enctype, display shortest name of enctype: aes128-cts + krb5_enctype *, display list of enctypes: 5, rc4-hmac-exp, 511 + krb5_enctype *, display list of enctypes: (empty) + krb5_ccache, display type:name: FILE:/path/to/ccache +diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c +index 6bf6e54ac..258377299 100644 +--- a/src/tests/asn.1/ktest.c ++++ b/src/tests/asn.1/ktest.c +@@ -893,7 +893,7 @@ ktest_make_sample_sp80056a_other_info(krb5_sp80056a_other_info *p) + void + ktest_make_sample_pkinit_supp_pub_info(krb5_pkinit_supp_pub_info *p) + { +- p->enctype = ENCTYPE_DES_CBC_CRC; ++ p->enctype = ENCTYPE_AES256_CTS_HMAC_SHA384_192; + ktest_make_sample_data(&p->as_req); + ktest_make_sample_data(&p->pk_as_rep); + } +diff --git a/src/tests/asn.1/pkinit_encode.out b/src/tests/asn.1/pkinit_encode.out +index 3b0f7190a..55a60bbef 100644 +--- a/src/tests/asn.1/pkinit_encode.out ++++ b/src/tests/asn.1/pkinit_encode.out +@@ -10,4 +10,4 @@ encode_krb5_kdc_dh_key_info: 30 25 A0 0B 03 09 00 6B 72 62 35 64 61 74 61 A1 03 + encode_krb5_reply_key_pack: 30 26 A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34 + encode_krb5_reply_key_pack_draft9: 30 1A A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 03 02 01 2A + encode_krb5_sp80056a_other_info: 30 81 81 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A0 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A2 0A 04 08 6B 72 62 35 64 61 74 61 +-encode_krb5_pkinit_supp_pub_info: 30 1D A0 03 02 01 01 A1 0A 04 08 6B 72 62 35 64 61 74 61 A2 0A 04 08 6B 72 62 35 64 61 74 61 ++encode_krb5_pkinit_supp_pub_info: 30 1D A0 03 02 01 14 A1 0A 04 08 6B 72 62 35 64 61 74 61 A2 0A 04 08 6B 72 62 35 64 61 74 61 +diff --git a/src/tests/asn.1/pkinit_trval.out b/src/tests/asn.1/pkinit_trval.out +index f9edbe154..9557188a8 100644 +--- a/src/tests/asn.1/pkinit_trval.out ++++ b/src/tests/asn.1/pkinit_trval.out +@@ -145,6 +145,6 @@ encode_krb5_sp80056a_other_info: + encode_krb5_pkinit_supp_pub_info: + + [Sequence/Sequence Of] +-. [0] [Integer] 1 ++. [0] [Integer] 20 + . [1] [Octet String] "krb5data" + . [2] [Octet String] "krb5data" +diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp +index c061d764e..e8adee234 100644 +--- a/src/tests/dejagnu/config/default.exp ++++ b/src/tests/dejagnu/config/default.exp +@@ -16,21 +16,6 @@ set stty_init {erase \^h kill \^u} + set env(TERM) dumb + + set des3_krbtgt 0 +-set tgt_support_desmd5 0 +- +-# The names of the individual passes must be unique; lots of things +-# depend on it. The PASSES variable may not contain comments; only +-# small pieces get evaluated, so comments will do strange things. +- +-# Most of the purpose of using multiple passes is to exercise the +-# dependency of various bugs on configuration file settings, +-# particularly with regards to encryption types. +- +-# The des.no-kdc-md5 pass will fail if the KDC does not constrain +-# session key enctypes to those in its permitted_enctypes list. It +-# works by assuming enctype similarity, thus allowing the client to +-# request a des-cbc-md4 session key. Since only des-cbc-crc is in the +-# KDC's permitted_enctypes list, the TGT will be unusable. + + if { [string length $VALGRIND] } { + rename spawn valgrind_aux_spawn +@@ -111,47 +96,21 @@ if { $PRIOCNTL_HACK } { + } + } + +-# The des.des3-tgt.no-kdc-des3 pass will fail if the KDC doesn't +-# constrain ticket key enctypes to those in permitted_enctypes. It +-# does this by not putting des3 in the permitted_enctypes, while +-# creating a TGT princpal that has a des3 key as well as a des key. ++# The names of the individual passes must be unique; lots of things ++# depend on it. The PASSES variable may not contain comments; only ++# small pieces get evaluated, so comments will do strange things. + +-# XXX -- master_key_type is fragile w.r.t. permitted_enctypes; it is +-# possible to configure things such that you have a master_key_type +-# that is not permitted, and the error message used to be cryptic. ++# Most of the purpose of using multiple passes is to exercise the ++# dependency of various bugs on configuration file settings, ++# particularly with regards to encryption types. + + set passes { +- { +- des +- mode=udp +- des3_krbtgt=0 +- {supported_enctypes=des-cbc-crc:normal} +- {dummy=[verbose -log "DES TGT, DES enctype"]} +- } +- { +- des.des3tgt +- mode=udp +- des3_krbtgt=1 +- {supported_enctypes=des-cbc-crc:normal} +- {dummy=[verbose -log "DES3 TGT, DES enctype"]} +- } + { + des3 + mode=udp + des3_krbtgt=1 +- {supported_enctypes=des3-cbc-sha1:normal des-cbc-crc:normal} +- {dummy=[verbose -log "DES3 TGT, DES3 + DES enctypes"]} +- } +- { +- aes-des +- mode=udp +- des3_krbtgt=0 +- {supported_enctypes=aes256-cts-hmac-sha1-96:normal des-cbc-crc:normal} +- {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96 des-cbc-crc} +- {permitted_enctypes(client)=aes256-cts-hmac-sha1-96 des-cbc-crc} +- {permitted_enctypes(server)=aes256-cts-hmac-sha1-96 des-cbc-crc} +- {master_key_type=aes256-cts-hmac-sha1-96} +- {dummy=[verbose -log "AES + DES enctypes"]} ++ {supported_enctypes=des3-cbc-sha1:normal} ++ {dummy=[verbose -log "DES3 TGT, DES3 enctype"]} + } + { + aes-only +@@ -220,10 +179,10 @@ set passes { + aes-des3 + mode=udp + des3_krbtgt=0 +- {supported_enctypes=aes256-cts-hmac-sha1-96:normal des3-cbc-sha1:normal des-cbc-crc:normal} +- {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96 des3-cbc-sha1 des-cbc-crc} +- {permitted_enctypes(client)=aes256-cts-hmac-sha1-96 des3-cbc-sha1 des-cbc-crc} +- {permitted_enctypes(server)=aes256-cts-hmac-sha1-96 des3-cbc-sha1 des-cbc-crc} ++ {supported_enctypes=aes256-cts-hmac-sha1-96:normal des3-cbc-sha1:normal} ++ {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} ++ {permitted_enctypes(client)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} ++ {permitted_enctypes(server)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} + {master_key_type=aes256-cts-hmac-sha1-96} + {dummy=[verbose -log "AES + DES3 + DES enctypes"]} + } +@@ -231,12 +190,12 @@ set passes { + aes-des3tgt + mode=udp + des3_krbtgt=1 +- {supported_enctypes=aes256-cts-hmac-sha1-96:normal des3-cbc-sha1:normal des-cbc-crc:normal} +- {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96 des3-cbc-sha1 des-cbc-crc} +- {permitted_enctypes(client)=aes256-cts-hmac-sha1-96 des3-cbc-sha1 des-cbc-crc} +- {permitted_enctypes(server)=aes256-cts-hmac-sha1-96 des3-cbc-sha1 des-cbc-crc} ++ {supported_enctypes=aes256-cts-hmac-sha1-96:normal des3-cbc-sha1:normal} ++ {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} ++ {permitted_enctypes(client)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} ++ {permitted_enctypes(server)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} + {master_key_type=aes256-cts-hmac-sha1-96} +- {dummy=[verbose -log "AES + DES enctypes, DES3 TGT"]} ++ {dummy=[verbose -log "AES enctypes, DES3 TGT"]} + } + { + all-enctypes +@@ -248,115 +207,8 @@ set passes { + {allow_weak_crypto(server)=false} + {dummy=[verbose -log "all default enctypes"]} + } +- { +- des.no-kdc-md5 +- mode=udp +- des3_krbtgt=0 +- tgt_support_desmd5=0 +- {permitted_enctypes(kdc)=des-cbc-crc} +- {default_tgs_enctypes(client)=des-cbc-md5 des-cbc-md4 des-cbc-crc} +- {default_tkt_enctypes(client)=des-cbc-md5 des-cbc-md4 des-cbc-crc} +- {supported_enctypes=des-cbc-crc:normal} +- {master_key_type=des-cbc-crc} +- {dummy=[verbose -log \ +- "DES TGT, KDC permitting only des-cbc-crc"]} +- } +- { +- des.des3-tgt.no-kdc-des3 +- mode=udp +- tgt_support_desmd5=0 +- {permitted_enctypes(kdc)=des-cbc-crc} +- {default_tgs_enctypes(client)=des-cbc-crc} +- {default_tkt_enctypes(client)=des-cbc-crc} +- {supported_enctypes=des3-cbc-sha1:normal des-cbc-crc:normal} +- {master_key_type=des-cbc-crc} +- {dummy=[verbose -log \ +- "DES3 TGT, KDC permitting only des-cbc-crc"]} +- } + } + +-# des.md5-tgt is set as unused, since it won't trigger the error case +-# if SUPPORT_DESMD5 isn't honored. +- +-# The des.md5-tgt pass will fail if enctype similarity is inconsisent; +-# between 1.0.x and 1.1, the decrypt functions became more strict +-# about matching enctypes, while the KDB retrieval functions didn't +-# coerce the enctype to match what was requested. It works by setting +-# SUPPORT_DESMD5 on the TGT principal, forcing an enctype of +-# des-cbc-md5 on the TGT key. Since the database only contains a +-# des-cbc-crc key, the decrypt will fail if enctypes are not coerced. +- +-# des.no-kdc-md5.client-md4-skey is retained in unsed_passes, even +-# though des.no-kdc-md5 is roughly equivalent, since the associated +-# comment needs additional investigation at some point re the kadmin +-# client. +- +-# The des.no-kdc-md5.client-md4-skey will fail on TGS requests due to +-# the KDC issuing session keys that it won't accept. It will also +-# fail for a kadmin client, but for different reasons, since the kadm5 +-# library does some curious filtering of enctypes, and also uses +-# get_in_tkt() rather than get_init_creds(); the former does an +-# intersection of the enctypes provided by the caller and those listed +-# in the config file! +- +-set unused_passes { +- { +- des.md5-tgt +- des3_krbtgt=0 +- tgt_support_desmd5=1 +- supported_enctypes=des-cbc-crc:normal +- {permitted_enctypes(kdc)=des-cbc-md5 des-cbc-md4 des-cbc-crc} +- {permitted_enctypes(client)=des-cbc-md5 des-cbc-md4 des-cbc-crc} +- {dummy=[verbose -log "DES TGT, SUPPORTS_DESMD5"]} +- } +- { +- des.md5-tgt.no-kdc-md5 +- des3_krbtgt=0 +- tgt_support_desmd5=1 +- {permitted_enctypes(kdc)=des-cbc-crc} +- {default_tgs_enctypes(client)=des-cbc-crc} +- {default_tkt_enctypes(client)=des-cbc-crc} +- {supported_enctypes=des-cbc-crc:normal} +- {master_key_type=des-cbc-crc} +- {dummy=[verbose -log \ +- "DES TGT, SUPPORTS_DESMD5, KDC permitting only des-cbc-crc"]} +- } +- { +- des.no-kdc-md5.client-md4-skey +- des3_krbtgt=0 +- {permitted_enctypes(kdc)=des-cbc-crc} +- {permitted_enctypes(client)=des-cbc-crc des-cbc-md4} +- {default_tgs_enctypes(client)=des-cbc-crc des-cbc-md4} +- {default_tkt_enctypes(client)=des-cbc-md4} +- {supported_enctypes=des-cbc-crc:normal} +- {dummy=[verbose -log \ +- "DES TGT, DES enctype, KDC permitting only des-cbc-crc, client requests des-cbc-md4 session key"]} +- } +- { +- all-enctypes +- des3_krbtgt=1 +- {supported_enctypes=\ +- aes256-cts-hmac-sha1-96:normal aes256-cts-hmac-sha1-96:norealm \ +- aes128-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:norealm \ +- des3-cbc-sha1:normal des3-cbc-sha1:none \ +- des-cbc-md5:normal des-cbc-md4:normal des-cbc-crc:normal \ +- } +- {dummy=[verbose -log "DES3 TGT, default enctypes"]} +- } +- { +- aes-tcp +- mode=tcp +- des3_krbtgt=0 +- {supported_enctypes=aes256-cts-hmac-sha1-96:normal} +- {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96} +- {permitted_enctypes(client)=aes256-cts-hmac-sha1-96} +- {permitted_enctypes(server)=aes256-cts-hmac-sha1-96} +- {master_key_type=aes256-cts-hmac-sha1-96} +- {dummy=[verbose -log "AES via TCP"]} +- } +-} +-# {supported_enctypes=des-cbc-md5:normal des-cbc-crc:normal twofish256-hmac-sha1:normal } +- + # This shouldn't be necessary on dejagnu-1.4 and later, but 1.3 seems + # to need it because its runtest.exp doesn't deal with PASS at all. + if [info exists PASS] { +@@ -1095,7 +947,7 @@ proc setup_kerberos_db { standalone } { + global REALMNAME KDB5_UTIL KADMIN_LOCAL KEY + global tmppwd hostname + global spawn_id +- global des3_krbtgt tgt_support_desmd5 ++ global des3_krbtgt + global multipass_name last_passname_db + + set failall 0 +@@ -1334,48 +1186,6 @@ proc setup_kerberos_db { standalone } { + } + } + } +- if $tgt_support_desmd5 { +- # Make TGT support des-cbc-md5 +- set test "kadmin.local TGT to SUPPORT_DESMD5" +- set body { +- if $failall { +- break +- } +- spawn $KADMIN_LOCAL -r $REALMNAME +- verbose "starting $test" +- expect_after $def_exp_after +- +- expect "kadmin.local: " +- send "modprinc +support_desmd5 krbtgt/$REALMNAME@$REALMNAME\r" +- # It echos... +- expect "modprinc +support_desmd5 krbtgt/$REALMNAME@$REALMNAME\r" +- expect { +- "Principal \"krbtgt/$REALMNAME@$REALMNAME\" modified.\r\n" { } +- } +- expect "kadmin.local: " +- send "quit\r" +- expect eof +- catch expect_after +- if ![check_exit_status kadmin_local] { +- break +- } +- } +- set ret [catch $body] +- catch "expect eof" +- catch expect_after +- if $ret { +- set failall 1 +- if $standalone { +- fail $test +- } else { +- delete_db +- } +- } else { +- if $standalone { +- pass $test +- } +- } +- } + envstack_pop + + # create the admin database lock file +diff --git a/src/tests/gssapi/t_invalid.c b/src/tests/gssapi/t_invalid.c +index 2a332a8ae..9876a11e6 100644 +--- a/src/tests/gssapi/t_invalid.c ++++ b/src/tests/gssapi/t_invalid.c +@@ -84,17 +84,6 @@ struct test { + size_t toklen; + const char *token; + } tests[] = { +- { +- ENCTYPE_DES_CBC_CRC, ENCTYPE_DES_CBC_RAW, +- SEAL_ALG_DES, SGN_ALG_DES_MAC_MD5, 8, +- 8, +- "\x26\xEC\xBA\xB6\xFE\xBA\x91\xCE", +- 53, +- "\x60\x33\x06\x09\x2A\x86\x48\x86\xF7\x12\x01\x02\x02\x02\x01\x00" +- "\x00\x00\x00\xFF\xFF\xF0\x0B\x90\x7B\xC4\xFC\xEB\xF4\x84\x9C\x5A" +- "\xA8\x56\x41\x3E\xE1\x62\xEE\x38\xD1\x34\x9A\xE3\xFB\xC9\xFD\x0A" +- "\xDC\x83\xE1\x4A\xE4" +- }, + { + ENCTYPE_DES3_CBC_SHA1, ENCTYPE_DES3_CBC_RAW, + SEAL_ALG_DES3KD, SGN_ALG_HMAC_SHA1_DES3_KD, 20, +@@ -160,8 +149,6 @@ make_fake_context(const struct test *test) + gss_union_ctx_id_t uctx; + krb5_gss_ctx_id_t kgctx; + krb5_keyblock kb; +- unsigned char encbuf[8]; +- size_t i; + + kgctx = calloc(1, sizeof(*kgctx)); + if (kgctx == NULL) +@@ -184,11 +171,6 @@ make_fake_context(const struct test *test) + if (krb5_k_create_key(NULL, &kb, &kgctx->seq) != 0) + abort(); + +- if (kb.enctype == ENCTYPE_DES_CBC_RAW) { +- for (i = 0; i < 8; i++) +- encbuf[i] = kb.contents[i] ^ 0xF0; +- kb.contents = encbuf; +- } + if (krb5_k_create_key(NULL, &kb, &kgctx->enc) != 0) + abort(); + +@@ -248,7 +230,7 @@ test_bogus_1964_token(gss_ctx_id_t ctx) + gss_iov_buffer_desc iov; + + store_16_be(KG_TOK_SIGN_MSG, tokbuf); +- store_16_le(SGN_ALG_DES_MAC_MD5, tokbuf + 2); ++ store_16_le(SGN_ALG_HMAC_MD5, tokbuf + 2); + store_16_le(SEAL_ALG_NONE, tokbuf + 4); + store_16_le(0xFFFF, tokbuf + 6); + memset(tokbuf + 8, 0, 16); +diff --git a/src/tests/gssapi/t_pcontok.c b/src/tests/gssapi/t_pcontok.c +index c40ea434c..7368f752f 100644 +--- a/src/tests/gssapi/t_pcontok.c ++++ b/src/tests/gssapi/t_pcontok.c +@@ -43,7 +43,6 @@ + #include "k5-int.h" + #include "common.h" + +-#define SGN_ALG_DES_MAC_MD5 0x00 + #define SGN_ALG_HMAC_SHA1_DES3_KD 0x04 + #define SGN_ALG_HMAC_MD5 0x11 + +@@ -78,11 +77,7 @@ make_delete_token(gss_krb5_lucid_context_v1_t *lctx, gss_buffer_desc *out) + ret = krb5_k_create_key(context, &seqkb, &seq); + check_k5err(context, "krb5_k_create_key", ret); + +- if (signalg == SGN_ALG_DES_MAC_MD5) { +- cktype = CKSUMTYPE_RSA_MD5; +- cksize = 8; +- ckusage = 0; +- } else if (signalg == SGN_ALG_HMAC_SHA1_DES3_KD) { ++ if (signalg == SGN_ALG_HMAC_SHA1_DES3_KD) { + cktype = CKSUMTYPE_HMAC_SHA1_DES3; + cksize = 20; + ckusage = 23; +@@ -122,15 +117,7 @@ make_delete_token(gss_krb5_lucid_context_v1_t *lctx, gss_buffer_desc *out) + d = make_data(ptr - 8, 8); + ret = krb5_k_make_checksum(context, cktype, seq, ckusage, &d, &cksum); + check_k5err(context, "krb5_k_make_checksum", ret); +- if (signalg == SGN_ALG_DES_MAC_MD5) { +- iov.flags = KRB5_CRYPTO_TYPE_DATA; +- iov.data = make_data(cksum.contents, 16); +- ret = krb5_k_encrypt_iov(context, seq, 0, NULL, &iov, 1); +- check_k5err(context, "krb5_k_encrypt_iov", ret); +- memcpy(ptr + 8, cksum.contents + 8, 8); +- } else { +- memcpy(ptr + 8, cksum.contents, cksize); +- } ++ memcpy(ptr + 8, cksum.contents, cksize); + + /* Create the sequence number (8 bytes). */ + iov.flags = KRB5_CRYPTO_TYPE_DATA; +diff --git a/src/tests/gssapi/t_prf.c b/src/tests/gssapi/t_prf.c +index 6a698ce0f..f71774cdc 100644 +--- a/src/tests/gssapi/t_prf.c ++++ b/src/tests/gssapi/t_prf.c +@@ -41,13 +41,6 @@ static struct { + const char *key2; + const char *out2; + } tests[] = { +- { ENCTYPE_DES_CBC_CRC, +- "E607FE9DABB57AE0", +- "803C4121379FC4B87CE413B67707C4632EBED2C6D6B7" +- "2A55E878836E35E21600D915D590DED5B6D77BB30A1F", +- "54758316B6257A75", +- "279E4105F7ADC9BD6EF28ABE31D89B442FE0058388BA" +- "33264ACB5729562DC637950F6BD144B654BE7700B2D6" }, + { ENCTYPE_DES3_CBC_SHA1, + "70378A19CD64134580C27C0115D6B34A1CF2FEECEF9886A2", + "9F8D127C520BB826BFF3E0FE5EF352389C17E0C073D9" +diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py +index c21d054f1..2a052fc17 100644 +--- a/src/tests/t_etype_info.py ++++ b/src/tests/t_etype_info.py +@@ -24,7 +24,7 @@ def test_etinfo(princ, enctypes, expected_lines): + # With no newer enctypes in the request, PA-ETYPE-INFO2, + # PA-ETYPE-INFO, and PA-PW-SALT appear in the AS-REP, each listing one + # key for the most preferred matching enctype. +-test_etinfo('user', 'rc4-hmac-exp des3 rc4 des-cbc-crc', ++test_etinfo('user', 'rc4-hmac-exp des3 rc4', + ['asrep etype_info2 des3-cbc-sha1 KRBTEST.COMuser', + 'asrep etype_info des3-cbc-sha1 KRBTEST.COMuser', + 'asrep pw_salt KRBTEST.COMuser']) +@@ -37,7 +37,7 @@ test_etinfo('user', 'rc4 aes256-cts', + + # In preauth-required errors, PA-PW-SALT does not appear, but the same + # etype-info2 values are expected. +-test_etinfo('preauthuser', 'rc4-hmac-exp des3 rc4 des-cbc-crc', ++test_etinfo('preauthuser', 'rc4-hmac-exp des3 rc4', + ['error etype_info2 des3-cbc-sha1 KRBTEST.COMpreauthuser', + 'error etype_info des3-cbc-sha1 KRBTEST.COMpreauthuser']) + test_etinfo('preauthuser', 'rc4 aes256-cts', +diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py +index 4af6804f2..2c825a692 100755 +--- a/src/tests/t_keyrollover.py ++++ b/src/tests/t_keyrollover.py +@@ -2,7 +2,7 @@ from k5test import * + + rollover_krb5_conf = {'libdefaults': {'allow_weak_crypto': 'true'}} + +-realm = K5Realm(krbtgt_keysalt='des-cbc-crc:normal', ++realm = K5Realm(krbtgt_keysalt='aes128-cts-hmac-sha256-128:normal', + krb5_conf=rollover_krb5_conf) + + princ1 = 'host/test1@%s' % (realm.realm,) +@@ -22,9 +22,9 @@ realm.run([kvno, princ1]) + realm.run([kadminl, 'purgekeys', realm.krbtgt_princ]) + # Make sure an old TGT fails after purging old TGS key. + realm.run([kvno, princ2], expected_code=1) +-ddes = "DEPRECATED:des-cbc-crc" ++et = "aes128-cts-hmac-sha256-128" + msg = 'krbtgt/%s@%s\n\tEtype (skey, tkt): %s, %s' % \ +- (realm.realm, realm.realm, ddes, ddes) ++ (realm.realm, realm.realm, et, et) + realm.run([klist, '-e'], expected_msg=msg) + + # Check that new key actually works. +diff --git a/src/tests/t_salt.py b/src/tests/t_salt.py +index 008efcb03..65084bbf3 100755 +--- a/src/tests/t_salt.py ++++ b/src/tests/t_salt.py +@@ -22,7 +22,7 @@ salts = [('des3-cbc-sha1', 'norealm'), + # These enctypes are chosen to cover the different string-to-key routines. + # Omit ":normal" from aes256 to check that salttype defaulting works. + second_kstypes = ['aes256-cts-hmac-sha1-96', 'arcfour-hmac:normal', +- 'des3-cbc-sha1:normal', 'des-cbc-crc:normal'] ++ 'des3-cbc-sha1:normal'] + + # Test using different salt types in a principal's key list. + # Parameters from one key in the list must not leak over to later ones. +diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py +index da02f224a..621b27156 100755 +--- a/src/tests/t_sesskeynego.py ++++ b/src/tests/t_sesskeynego.py +@@ -23,13 +23,7 @@ conf2 = {'libdefaults': {'default_tgs_enctypes': 'aes256-cts,aes128-cts'}} + conf3 = {'libdefaults': { + 'allow_weak_crypto': 'true', + 'default_tkt_enctypes': 'aes128-cts', +- 'default_tgs_enctypes': 'rc4-hmac,aes128-cts,des-cbc-crc'}} +-conf4 = {'libdefaults': { +- 'allow_weak_crypto': 'true', +- 'default_tkt_enctypes': 'aes256-cts', +- 'default_tgs_enctypes': 'des-cbc-crc,rc4-hmac,aes256-cts'}, +- 'realms': {'$realm': {'des_crc_session_supported': 'false'}}} +- ++ 'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}} + # Test with client request and session_enctypes preferring aes128, but + # aes256 long-term key. + realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False) +@@ -63,16 +57,6 @@ test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96') + realm.run([kadminl, 'setstr', 'server', 'session_enctypes', + 'rc4-hmac,aes128-cts,aes256-cts']) + test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') +- +-# 3c: Test des-cbc-crc default assumption. +-realm.run([kadminl, 'delstr', 'server', 'session_enctypes']) +-test_kvno(realm, 'DEPRECATED:des-cbc-crc', 'aes256-cts-hmac-sha1-96') +-realm.stop() +- +-# Last go: test that we can disable the des-cbc-crc assumption +-realm = K5Realm(krb5_conf=conf4, get_creds=False) +-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server']) +-test_kvno(realm, 'aes256-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96') + realm.stop() + + success('sesskeynego') +diff --git a/src/util/k5test.py b/src/util/k5test.py +index b6d93f1d8..da2782e15 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -1307,7 +1307,7 @@ _passes = [ + 'master_key_type': 'aes256-sha2'}}}), + + # Test a setup with modern principal keys but an old TGT key. +- ('aes256.destgt', 'des-cbc-crc:normal', ++ ('aes256.destgt', 'arcfour-hmac:normal', + {'libdefaults': {'allow_weak_crypto': 'true'}}, + None) + ] diff --git a/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch b/krb5-1.17post3-FIPS-with-PRNG-SPAKE-and-RADIUS.patch similarity index 93% rename from krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch rename to krb5-1.17post3-FIPS-with-PRNG-SPAKE-and-RADIUS.patch index 295bc5d..98c4782 100644 --- a/krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch +++ b/krb5-1.17post3-FIPS-with-PRNG-SPAKE-and-RADIUS.patch @@ -1,7 +1,7 @@ -From 35dbfaa4a224bbbdd0d75a0383fbe09d7deb389f Mon Sep 17 00:00:00 2001 +From b52fa25acec9c0302532e1610ffe390d714e8f7a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 -Subject: [PATCH] krb5-1.17post2 FIPS with PRNG, SPAKE, and RADIUS +Subject: [PATCH] krb5-1.17post3 FIPS with PRNG, SPAKE, and RADIUS NB: Use openssl's PRNG in FIPS mode, be aware during SPAKE group negotiation, and taint within krad. @@ -15,10 +15,11 @@ awareness of what we can and can't safely call. This will slow down some calls slightly (FIPS_mode() takes multiple locks), but not for any ciphers we care about - which is to say that AES is fine. Shame about the SPAKE groups though. + +post3 is (confusingly) on top of the 1DES removal. --- src/lib/crypto/krb/prng.c | 11 ++++- .../crypto/openssl/enc_provider/camellia.c | 6 +++ - src/lib/crypto/openssl/enc_provider/des.c | 9 ++++ src/lib/crypto/openssl/enc_provider/des3.c | 6 +++ src/lib/crypto/openssl/enc_provider/rc4.c | 13 +++++- .../crypto/openssl/hash_provider/hash_evp.c | 4 ++ @@ -31,7 +32,7 @@ AES is fine. Shame about the SPAKE groups though. src/lib/krad/t_attr.c | 3 +- src/lib/krad/t_attrset.c | 4 +- src/plugins/preauth/spake/groups.c | 8 ++++ - 15 files changed, 132 insertions(+), 33 deletions(-) + 14 files changed, 123 insertions(+), 33 deletions(-) diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c index cb9ca9b98..f0e9984ca 100644 @@ -88,40 +89,6 @@ index 2da691329..f79679a0b 100644 state->length = 16; state->data = (void *) malloc(16); if (state->data == NULL) -diff --git a/src/lib/crypto/openssl/enc_provider/des.c b/src/lib/crypto/openssl/enc_provider/des.c -index a662db512..7d17d287e 100644 ---- a/src/lib/crypto/openssl/enc_provider/des.c -+++ b/src/lib/crypto/openssl/enc_provider/des.c -@@ -85,6 +85,9 @@ k5_des_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx; - krb5_boolean empty; - -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; -+ - ret = validate(key, ivec, data, num_data, &empty); - if (ret != 0 || empty) - return ret; -@@ -133,6 +136,9 @@ k5_des_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx; - krb5_boolean empty; - -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; -+ - ret = validate(key, ivec, data, num_data, &empty); - if (ret != 0 || empty) - return ret; -@@ -182,6 +188,9 @@ k5_des_cbc_mac(krb5_key key, const krb5_crypto_iov *data, size_t num_data, - DES_key_schedule sched; - krb5_boolean empty; - -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; -+ - ret = validate(key, ivec, data, num_data, &empty); - if (ret != 0) - return ret; diff --git a/src/lib/crypto/openssl/enc_provider/des3.c b/src/lib/crypto/openssl/enc_provider/des3.c index 1c439c2cd..8be555a8d 100644 --- a/src/lib/crypto/openssl/enc_provider/des3.c diff --git a/krb5.spec b/krb5.spec index 7808495..2b86cc1 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 25%{?dist} +Release: 26%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -89,7 +89,6 @@ Patch123: Avoid-alignment-warnings-in-openssl-rc4.c.patch Patch124: Simply-OpenSSL-PKCS7-decryption-code.patch Patch125: Improve-error-messages-from-kadmin-change_password.patch Patch126: Remove-more-dead-code.patch -Patch127: krb5-1.17post2-FIPS-with-PRNG-SPAKE-and-RADIUS.patch Patch128: Remove-checksum-type-profile-variables.patch Patch129: Remove-dead-variable-def_kslist-from-two-files.patch Patch130: Mark-the-doc-kadm5-tex-files-as-historic.patch @@ -99,6 +98,11 @@ Patch133: Update-default-krb5kdc-mkey-manual-entry-enctype.patch Patch134: Support-389ds-s-lockout-model.patch Patch135: Add-missing-newlines-to-deprecation-warnings.patch Patch136: Set-a-more-modern-default-ksu-CMD_PATH.patch +Patch137: Remove-the-v4-and-afs3-salt-types.patch +Patch138: Update-test-suite-to-avoid-single-DES-enctypes.patch +Patch139: Remove-support-for-single-DES-and-CRC.patch +Patch140: Display-unsupported-enctype-names.patch +Patch141: krb5-1.17post3-FIPS-with-PRNG-SPAKE-and-RADIUS.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -708,6 +712,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue May 28 2019 Robbie Harwood - 1.17-26 +- Remove support for single-DES and CRC + * Wed May 22 2019 Robbie Harwood - 1.17-25 - Add missing newlines to deprecation warnings - Switch to upstream's ksu path patch From 48af99c1f7058205129c088545778894428b3afb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 30 May 2019 13:32:37 -0400 Subject: [PATCH 112/304] Remove krb5int_c_combine_keys() and no-flags SAM-2 preauth --- Add-zapfreedata-convenience-function.patch | 31 ++ Remove-krb5int_c_combine_keys.patch | 479 ++++++++++++++++++ ...e-support-for-no-flags-SAM-2-preauth.patch | 73 +++ krb5.spec | 8 +- 4 files changed, 590 insertions(+), 1 deletion(-) create mode 100644 Add-zapfreedata-convenience-function.patch create mode 100644 Remove-krb5int_c_combine_keys.patch create mode 100644 Remove-support-for-no-flags-SAM-2-preauth.patch diff --git a/Add-zapfreedata-convenience-function.patch b/Add-zapfreedata-convenience-function.patch new file mode 100644 index 0000000..d979c17 --- /dev/null +++ b/Add-zapfreedata-convenience-function.patch @@ -0,0 +1,31 @@ +From c83490ced3ef77d1933caa893efbc4a54d03a1ad Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 14 Mar 2019 11:26:44 -0400 +Subject: [PATCH] Add zapfreedata() convenience function + +(cherry picked from commit abd974cf867db5a398aa87ba9b9aaa34346e12a4) +--- + src/include/k5-int.h | 10 ++++++++++ + 1 file changed, 10 insertions(+) + +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index e0c557554..2bc59e636 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -663,6 +663,16 @@ zapfreestr(void *str) + } + } + ++/* Convenience function: zap and free krb5_data pointer if it is non-NULL. */ ++static inline void ++zapfreedata(krb5_data *data) ++{ ++ if (data != NULL) { ++ zapfree(data->data, data->length); ++ free(data); ++ } ++} ++ + /* + * Combine two keys (normally used by the hardware preauth mechanism) + */ diff --git a/Remove-krb5int_c_combine_keys.patch b/Remove-krb5int_c_combine_keys.patch new file mode 100644 index 0000000..7ac088c --- /dev/null +++ b/Remove-krb5int_c_combine_keys.patch @@ -0,0 +1,479 @@ +From 320f2d5b0f2671e41b383161093a73d9dea5cbf7 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 18 Apr 2019 17:27:07 -0400 +Subject: [PATCH] Remove krb5int_c_combine_keys() + +This method of combining keys was specified by +draft-ietf-krb-wg-kerberos-sam for DES and 3DES enctypes, and is +otherwise unused. Remove it. + +[ghudson@mit.edu: rewrote commit message] + +ticket: 8812 +(cherry picked from commit 925a7df2f486aaa3ff137d2bcdf8ff57186638c6) +[rharwood@redhat.com: conflicts: .gitignore] +--- + src/include/k5-int.h | 7 - + src/lib/crypto/crypto_tests/Makefile.in | 12 +- + src/lib/crypto/crypto_tests/deps | 10 -- + src/lib/crypto/crypto_tests/t_combine.c | 62 ------- + src/lib/crypto/krb/Makefile.in | 3 - + src/lib/crypto/krb/combine_keys.c | 227 ------------------------ + src/lib/crypto/krb/deps | 13 -- + src/lib/crypto/libk5crypto.exports | 1 - + 8 files changed, 3 insertions(+), 332 deletions(-) + delete mode 100644 src/lib/crypto/crypto_tests/t_combine.c + delete mode 100644 src/lib/crypto/krb/combine_keys.c + +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 2bc59e636..0857fd1cc 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -673,13 +673,6 @@ zapfreedata(krb5_data *data) + } + } + +-/* +- * Combine two keys (normally used by the hardware preauth mechanism) +- */ +-krb5_error_code +-krb5int_c_combine_keys(krb5_context context, krb5_keyblock *key1, +- krb5_keyblock *key2, krb5_keyblock *outkey); +- + void krb5int_c_free_keyblock(krb5_context, krb5_keyblock *key); + void krb5int_c_free_keyblock_contents(krb5_context, krb5_keyblock *); + krb5_error_code krb5int_c_init_keyblock(krb5_context, krb5_enctype enctype, +diff --git a/src/lib/crypto/crypto_tests/Makefile.in b/src/lib/crypto/crypto_tests/Makefile.in +index 09feeb50e..0295ee14f 100644 +--- a/src/lib/crypto/crypto_tests/Makefile.in ++++ b/src/lib/crypto/crypto_tests/Makefile.in +@@ -23,8 +23,7 @@ EXTRADEPSRCS=\ + $(srcdir)/t_short.c \ + $(srcdir)/t_str2key.c \ + $(srcdir)/t_derive.c \ +- $(srcdir)/t_fork.c \ +- $(srcdir)/t_combine.c ++ $(srcdir)/t_fork.c + + ##DOS##BUILDTOP = ..\..\.. + +@@ -33,8 +32,7 @@ check-unix: t_nfold t_encrypt t_decrypt t_prf t_prng t_cmac t_hmac \ + aes-test \ + camellia-test \ + t_mddriver4 t_mddriver \ +- t_cts t_sha2 t_short t_str2key t_derive t_fork t_cf2 \ +- t_combine ++ t_cts t_sha2 t_short t_str2key t_derive t_fork t_cf2 + $(RUN_TEST) ./t_nfold + $(RUN_TEST) ./t_encrypt + $(RUN_TEST) ./t_decrypt +@@ -59,7 +57,6 @@ check-unix: t_nfold t_encrypt t_decrypt t_prf t_prng t_cmac t_hmac \ + $(RUN_TEST) ./t_fork + $(RUN_TEST) ./t_cf2 <$(srcdir)/t_cf2.in >t_cf2.output + diff t_cf2.output $(srcdir)/t_cf2.expected +- $(RUN_TEST) ./t_combine + # $(RUN_TEST) ./t_pkcs5 + + t_nfold$(EXEEXT): t_nfold.$(OBJEXT) $(KRB5_BASE_DEPLIBS) +@@ -134,9 +131,6 @@ t_fork$(EXEEXT): t_fork.$(OBJEXT) $(KRB5_BASE_DEPLIBS) + t_cf2$(EXEEXT): t_cf2.$(OBJEXT) $(KRB5_BASE_DEPLIBS) + $(CC_LINK) -o $@ t_cf2.$(OBJEXT) $(KRB5_BASE_LIBS) + +-t_combine$(EXEEXT): t_combine.$(OBJEXT) $(KRB5_BASE_DEPLIBS) +- $(CC_LINK) -o $@ t_combine.$(OBJEXT) $(KRB5_BASE_LIBS) +- + clean: + $(RM) t_nfold.o t_nfold t_encrypt t_encrypt.o \ + t_decrypt.o t_decrypt t_prng.o t_prng t_cmac.o t_cmac \ +@@ -149,7 +143,7 @@ clean: + t_str2key.o t_derive t_derive.o t_fork t_fork.o \ + t_mddriver$(EXEEXT) $(OUTPRE)t_mddriver.$(OBJEXT) \ + camellia-test camellia-test.o camellia-vt.txt \ +- t_cf2 t_cf2.o t_cf2.output t_combine.o t_combine ++ t_cf2 t_cf2.o t_cf2.output + + -$(RM) t_prng.output + -$(RM) t_prf.output +diff --git a/src/lib/crypto/crypto_tests/deps b/src/lib/crypto/crypto_tests/deps +index 19fef2582..0d10d4a1a 100644 +--- a/src/lib/crypto/crypto_tests/deps ++++ b/src/lib/crypto/crypto_tests/deps +@@ -226,13 +226,3 @@ $(OUTPRE)t_fork.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ + $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ + $(top_srcdir)/include/socket-utils.h t_fork.c +-$(OUTPRE)t_combine.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h t_combine.c +diff --git a/src/lib/crypto/crypto_tests/t_combine.c b/src/lib/crypto/crypto_tests/t_combine.c +deleted file mode 100644 +index ba0622bcf..000000000 +--- a/src/lib/crypto/crypto_tests/t_combine.c ++++ /dev/null +@@ -1,62 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/crypto_tests/t_combine.c - krb5int_c_combine_keys tests */ +-/* +- * Copyright (C) 2014 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Redistribution and use in source and binary forms, with or without +- * modification, are permitted provided that the following conditions +- * are met: +- * +- * * Redistributions of source code must retain the above copyright +- * notice, this list of conditions and the following disclaimer. +- * +- * * Redistributions in binary form must reproduce the above copyright +- * notice, this list of conditions and the following disclaimer in +- * the documentation and/or other materials provided with the +- * distribution. +- * +- * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +- * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +- * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS +- * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE +- * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, +- * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES +- * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR +- * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +- * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, +- * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) +- * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED +- * OF THE POSSIBILITY OF SUCH DAMAGE. +- */ +- +-#include "k5-int.h" +- +-unsigned char des3_key1[] = "\x10\xB6\x75\xD5\x5B\xD9\x6E\x73" +- "\xFD\x54\xB3\x3D\x37\x52\xC1\x2A\xF7\x43\x91\xFE\x1C\x02\x37\x13"; +-unsigned char des3_key2[] = "\xC8\xDA\x3E\xA7\xB6\x64\xAE\x7A" +- "\xB5\x70\x2A\x29\xB3\xBF\x9B\xA8\x46\x7C\x5B\xA8\x8A\x46\x70\x10"; +-unsigned char des3_result[] = "\x2F\x79\x97\x3E\x3E\xA4\x73\x1A" +- "\xB9\x3D\xEF\x5E\x7C\x29\xFB\x2A\x68\x86\x1F\xC1\x85\x0E\x79\x92"; +- +-int +-main(int argc, char **argv) +-{ +- krb5_keyblock kb1, kb2, result; +- +- kb1.enctype = ENCTYPE_DES3_CBC_SHA1; +- kb1.contents = des3_key1; +- kb1.length = 24; +- kb2.enctype = ENCTYPE_DES3_CBC_SHA1; +- kb2.contents = des3_key2; +- kb2.length = 24; +- memset(&result, 0, sizeof(result)); +- if (krb5int_c_combine_keys(NULL, &kb1, &kb2, &result) != 0) +- abort(); +- if (result.enctype != ENCTYPE_DES3_CBC_SHA1 || result.length != 24 || +- memcmp(result.contents, des3_result, 24) != 0) +- abort(); +- krb5_free_keyblock_contents(NULL, &result); +- +- return 0; +-} +diff --git a/src/lib/crypto/krb/Makefile.in b/src/lib/crypto/krb/Makefile.in +index c0e0b791b..536bacb6e 100644 +--- a/src/lib/crypto/krb/Makefile.in ++++ b/src/lib/crypto/krb/Makefile.in +@@ -22,7 +22,6 @@ STLIBOBJS=\ + cksumtypes.o \ + cmac.o \ + coll_proof_cksum.o \ +- combine_keys.o \ + crypto_length.o \ + crypto_libinit.o \ + default_state.o \ +@@ -84,7 +83,6 @@ OBJS=\ + $(OUTPRE)cksumtypes.$(OBJEXT) \ + $(OUTPRE)cmac.$(OBJEXT) \ + $(OUTPRE)coll_proof_cksum.$(OBJEXT) \ +- $(OUTPRE)combine_keys.$(OBJEXT) \ + $(OUTPRE)crypto_length.$(OBJEXT) \ + $(OUTPRE)crypto_libinit.$(OBJEXT) \ + $(OUTPRE)default_state.$(OBJEXT) \ +@@ -146,7 +144,6 @@ SRCS=\ + $(srcdir)/cksumtypes.c \ + $(srcdir)/cmac.c \ + $(srcdir)/coll_proof_cksum.c \ +- $(srcdir)/combine_keys.c \ + $(srcdir)/crypto_length.c \ + $(srcdir)/crypto_libinit.c \ + $(srcdir)/default_state.c \ +diff --git a/src/lib/crypto/krb/combine_keys.c b/src/lib/crypto/krb/combine_keys.c +deleted file mode 100644 +index c36434e17..000000000 +--- a/src/lib/crypto/krb/combine_keys.c ++++ /dev/null +@@ -1,227 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* Copyright (c) 2002 Naval Research Laboratory (NRL/CCS) */ +-/* +- * Permission to use, copy, modify and distribute this software and its +- * documentation is hereby granted, provided that both the copyright +- * notice and this permission notice appear in all copies of the software, +- * derivative works or modified versions, and any portions thereof. +- * +- * NRL ALLOWS FREE USE OF THIS SOFTWARE IN ITS "AS IS" CONDITION AND +- * DISCLAIMS ANY LIABILITY OF ANY KIND FOR ANY DAMAGES WHATSOEVER +- * RESULTING FROM THE USE OF THIS SOFTWARE. +- */ +- +-/* +- * Key combination function. +- * +- * If Key1 and Key2 are two keys to be combined, the algorithm to combine +- * them is as follows. +- * +- * Definitions: +- * +- * k-truncate is defined as truncating to the key size the input. +- * +- * DR is defined as the generate "random" data from a key +- * (defined in crypto draft) +- * +- * DK is defined as the key derivation function (krb5int_derive_key()) +- * +- * (note: | means "concatenate") +- * +- * Combine key algorithm: +- * +- * R1 = DR(Key1, n-fold(Key2)) [ Output is length of Key1 ] +- * R2 = DR(Key2, n-fold(Key1)) [ Output is length of Key2 ] +- * +- * rnd = n-fold(R1 | R2) [ Note: output size of nfold must be appropriately +- * sized for random-to-key function ] +- * tkey = random-to-key(rnd) +- * Combine-Key(Key1, Key2) = DK(tkey, CombineConstant) +- * +- * CombineConstant is defined as the byte string: +- * +- * { 0x63 0x6f 0x6d 0x62 0x69 0x6e 0x65 }, which corresponds to the +- * ASCII encoding of the string "combine" +- */ +- +-#include "crypto_int.h" +- +-static krb5_error_code dr(const struct krb5_enc_provider *enc, +- const krb5_keyblock *inkey, unsigned char *outdata, +- const krb5_data *in_constant); +- +-/* +- * We only support this combine_keys algorithm for des and 3des keys. +- * Everything else should use the PRF defined in the crypto framework. +- * We don't implement that yet. +- */ +- +-static krb5_boolean +-enctype_ok(krb5_enctype e) +-{ +- switch (e) { +- case ENCTYPE_DES3_CBC_SHA1: +- return TRUE; +- default: +- return FALSE; +- } +-} +- +-krb5_error_code +-krb5int_c_combine_keys(krb5_context context, krb5_keyblock *key1, +- krb5_keyblock *key2, krb5_keyblock *outkey) +-{ +- unsigned char *r1 = NULL, *r2 = NULL, *combined = NULL, *rnd = NULL; +- unsigned char *output = NULL; +- size_t keybytes, keylength; +- const struct krb5_enc_provider *enc; +- krb5_data input, randbits; +- krb5_keyblock tkeyblock; +- krb5_key tkey = NULL; +- krb5_error_code ret; +- const struct krb5_keytypes *ktp; +- krb5_boolean myalloc = FALSE; +- +- if (!enctype_ok(key1->enctype) || !enctype_ok(key2->enctype)) +- return KRB5_CRYPTO_INTERNAL; +- +- if (key1->length != key2->length || key1->enctype != key2->enctype) +- return KRB5_CRYPTO_INTERNAL; +- +- /* Find our encryption algorithm. */ +- ktp = find_enctype(key1->enctype); +- if (ktp == NULL) +- return KRB5_BAD_ENCTYPE; +- enc = ktp->enc; +- +- keybytes = enc->keybytes; +- keylength = enc->keylength; +- +- /* Allocate and set up buffers. */ +- r1 = k5alloc(keybytes, &ret); +- if (ret) +- goto cleanup; +- r2 = k5alloc(keybytes, &ret); +- if (ret) +- goto cleanup; +- rnd = k5alloc(keybytes, &ret); +- if (ret) +- goto cleanup; +- combined = k5calloc(2, keybytes, &ret); +- if (ret) +- goto cleanup; +- output = k5alloc(keylength, &ret); +- if (ret) +- goto cleanup; +- +- /* +- * Get R1 and R2 (by running the input keys through the DR algorithm. +- * Note this is most of derive-key, but not all. +- */ +- +- input.length = key2->length; +- input.data = (char *) key2->contents; +- ret = dr(enc, key1, r1, &input); +- if (ret) +- goto cleanup; +- +- input.length = key1->length; +- input.data = (char *) key1->contents; +- ret = dr(enc, key2, r2, &input); +- if (ret) +- goto cleanup; +- +- /* +- * Concatenate the two keys together, and then run them through +- * n-fold to reduce them to a length appropriate for the random-to-key +- * operation. Note here that krb5int_nfold() takes sizes in bits, hence +- * the multiply by 8. +- */ +- +- memcpy(combined, r1, keybytes); +- memcpy(combined + keybytes, r2, keybytes); +- +- krb5int_nfold((keybytes * 2) * 8, combined, keybytes * 8, rnd); +- +- /* +- * Run the "random" bits through random-to-key to produce a encryption +- * key. +- */ +- +- randbits.length = keybytes; +- randbits.data = (char *) rnd; +- tkeyblock.length = keylength; +- tkeyblock.contents = output; +- tkeyblock.enctype = key1->enctype; +- +- ret = (*ktp->rand2key)(&randbits, &tkeyblock); +- if (ret) +- goto cleanup; +- +- ret = krb5_k_create_key(NULL, &tkeyblock, &tkey); +- if (ret) +- goto cleanup; +- +- /* +- * Run through derive-key one more time to produce the final key. +- * Note that the input to derive-key is the ASCII string "combine". +- */ +- +- input.length = 7; +- input.data = "combine"; +- +- /* +- * Just FYI: _if_ we have space here in the key, then simply use it +- * without modification. But if the key is blank (no allocated storage) +- * then allocate some memory for it. This allows programs to use one of +- * the existing keys as the output key, _or_ pass in a blank keyblock +- * for us to allocate. It's easier for us to allocate it since we already +- * know the crypto library internals +- */ +- +- if (outkey->length == 0 || outkey->contents == NULL) { +- outkey->contents = k5alloc(keylength, &ret); +- if (ret) +- goto cleanup; +- outkey->length = keylength; +- outkey->enctype = key1->enctype; +- myalloc = TRUE; +- } +- +- ret = krb5int_derive_keyblock(enc, NULL, tkey, outkey, &input, +- DERIVE_RFC3961); +- if (ret) { +- if (myalloc) { +- free(outkey->contents); +- outkey->contents = NULL; +- } +- goto cleanup; +- } +- +-cleanup: +- zapfree(r1, keybytes); +- zapfree(r2, keybytes); +- zapfree(rnd, keybytes); +- zapfree(combined, keybytes * 2); +- zapfree(output, keylength); +- krb5_k_free_key(NULL, tkey); +- return ret; +-} +- +-/* Our DR function, a simple wrapper around krb5int_derive_random(). */ +-static krb5_error_code +-dr(const struct krb5_enc_provider *enc, const krb5_keyblock *inkey, +- unsigned char *out, const krb5_data *in_constant) +-{ +- krb5_data outdata = make_data(out, enc->keybytes); +- krb5_key key = NULL; +- krb5_error_code ret; +- +- ret = krb5_k_create_key(NULL, inkey, &key); +- if (ret != 0) +- return ret; +- ret = krb5int_derive_random(enc, NULL, key, &outdata, in_constant, +- DERIVE_RFC3961); +- krb5_k_free_key(NULL, key); +- return ret; +-} +diff --git a/src/lib/crypto/krb/deps b/src/lib/crypto/krb/deps +index f9a740860..2f4af1906 100644 +--- a/src/lib/crypto/krb/deps ++++ b/src/lib/crypto/krb/deps +@@ -191,19 +191,6 @@ coll_proof_cksum.so coll_proof_cksum.po $(OUTPRE)coll_proof_cksum.$(OBJEXT): \ + $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ + $(top_srcdir)/include/socket-utils.h coll_proof_cksum.c \ + crypto_int.h +-combine_keys.so combine_keys.po $(OUTPRE)combine_keys.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h $(srcdir)/../builtin/crypto_mod.h \ +- $(srcdir)/../builtin/sha2/sha2.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h combine_keys.c \ +- crypto_int.h + crypto_length.so crypto_length.po $(OUTPRE)crypto_length.$(OBJEXT): \ + $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ + $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports +index 63804299f..451d5e035 100644 +--- a/src/lib/crypto/libk5crypto.exports ++++ b/src/lib/crypto/libk5crypto.exports +@@ -58,7 +58,6 @@ krb5_c_prf_length + krb5int_c_mandatory_cksumtype + krb5_c_fx_cf2_simple + krb5int_c_weak_enctype +-krb5int_c_combine_keys + krb5_encrypt_data + krb5int_c_copy_keyblock + krb5int_c_copy_keyblock_contents diff --git a/Remove-support-for-no-flags-SAM-2-preauth.patch b/Remove-support-for-no-flags-SAM-2-preauth.patch new file mode 100644 index 0000000..971a366 --- /dev/null +++ b/Remove-support-for-no-flags-SAM-2-preauth.patch @@ -0,0 +1,73 @@ +From 2c6a5bea4319b6b1705d6c9c6a2bb78c9999089f Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 17 Apr 2019 17:07:46 -0400 +Subject: [PATCH] Remove support for no-flags SAM-2 preauth + +When neither the send-encrypted-sad nor the use-sad-as-key flag is set +in the SAM-2 challenge, the protocol calls for the AS key to be +combined with the string-to-key of the SAD using a key combination +method which has only been implemented for DES and 3DES enctypes. +Rather than extending key combination, remove support for this case. + +[ghudson@mit.edu: rewrote commit message, added comment] + +ticket: 8812 (new) +(cherry picked from commit c30e0af224ef3716513744fd86aec3eeea90abf9) +--- + src/lib/krb5/krb/preauth_sam2.c | 40 +++++++++------------------------ + 1 file changed, 11 insertions(+), 29 deletions(-) + +diff --git a/src/lib/krb5/krb/preauth_sam2.c b/src/lib/krb5/krb/preauth_sam2.c +index c7484c47e..fda86bee2 100644 +--- a/src/lib/krb5/krb/preauth_sam2.c ++++ b/src/lib/krb5/krb/preauth_sam2.c +@@ -211,38 +211,20 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata, + /* Get encryption key to be used for checksum and sam_response */ + if (!(sc2b->sam_flags & KRB5_SAM_USE_SAD_AS_KEY)) { + /* Retain as_key from above gak_fct call. */ +- +- if (!(sc2b->sam_flags & KRB5_SAM_SEND_ENCRYPTED_SAD)) { +- /* as_key = combine_key (as_key, string_to_key(SAD)) */ +- krb5_keyblock tmp_kb; +- +- retval = krb5_c_string_to_key(context, sc2b->sam_etype, +- &response_data, salt, &tmp_kb); +- +- if (retval) { +- krb5_free_sam_challenge_2(context, sc2); +- krb5_free_sam_challenge_2_body(context, sc2b); +- if (defsalt.length) free(defsalt.data); +- return(retval); +- } +- +- /* This should be a call to the crypto library some day */ +- /* key types should already match the sam_etype */ +- retval = krb5int_c_combine_keys(context, &ctx->as_key, &tmp_kb, +- &ctx->as_key); +- +- if (retval) { +- krb5_free_sam_challenge_2(context, sc2); +- krb5_free_sam_challenge_2_body(context, sc2b); +- if (defsalt.length) free(defsalt.data); +- return(retval); +- } +- krb5_free_keyblock_contents(context, &tmp_kb); +- } +- + if (defsalt.length) + free(defsalt.data); + ++ if (!(sc2b->sam_flags & KRB5_SAM_SEND_ENCRYPTED_SAD)) { ++ /* ++ * If no flags are set, the protocol calls for us to combine the ++ * initial reply key with the SAD, using a method which is only ++ * specified for DES and 3DES enctypes. We no longer support this ++ * case. ++ */ ++ krb5_free_sam_challenge_2(context, sc2); ++ krb5_free_sam_challenge_2_body(context, sc2b); ++ return(KRB5_SAM_UNSUPPORTED); ++ } + } else { + /* as_key = string_to_key(SAD) */ + diff --git a/krb5.spec b/krb5.spec index 2b86cc1..d1ecd63 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 26%{?dist} +Release: 27%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -103,6 +103,9 @@ Patch138: Update-test-suite-to-avoid-single-DES-enctypes.patch Patch139: Remove-support-for-single-DES-and-CRC.patch Patch140: Display-unsupported-enctype-names.patch Patch141: krb5-1.17post3-FIPS-with-PRNG-SPAKE-and-RADIUS.patch +Patch142: Add-zapfreedata-convenience-function.patch +Patch143: Remove-support-for-no-flags-SAM-2-preauth.patch +Patch144: Remove-krb5int_c_combine_keys.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -712,6 +715,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu May 30 2019 Robbie Harwood - 1.17-27 +- Remove krb5int_c_combine_keys() and no-flags SAM-2 preauth + * Tue May 28 2019 Robbie Harwood - 1.17-26 - Remove support for single-DES and CRC From 19e2656c1570f3f8fab91fd4ca3111c02e989db0 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 3 Jun 2019 17:25:49 -0400 Subject: [PATCH 113/304] Remove 3des support --- Add-zapfreedata-convenience-function.patch | 2 +- Remove-3des-support.patch | 6457 +++++++++++++++++ Remove-krb5int_c_combine_keys.patch | 2 +- ...e-support-for-no-flags-SAM-2-preauth.patch | 2 +- ...ost4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch | 34 +- krb5.spec | 8 +- 6 files changed, 6471 insertions(+), 34 deletions(-) create mode 100644 Remove-3des-support.patch rename krb5-1.17post3-FIPS-with-PRNG-SPAKE-and-RADIUS.patch => krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch (94%) diff --git a/Add-zapfreedata-convenience-function.patch b/Add-zapfreedata-convenience-function.patch index d979c17..4a6ce0b 100644 --- a/Add-zapfreedata-convenience-function.patch +++ b/Add-zapfreedata-convenience-function.patch @@ -1,4 +1,4 @@ -From c83490ced3ef77d1933caa893efbc4a54d03a1ad Mon Sep 17 00:00:00 2001 +From 7fb0b432d9192360ec3439a7f5c33ad8366064f1 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 14 Mar 2019 11:26:44 -0400 Subject: [PATCH] Add zapfreedata() convenience function diff --git a/Remove-3des-support.patch b/Remove-3des-support.patch new file mode 100644 index 0000000..0231140 --- /dev/null +++ b/Remove-3des-support.patch @@ -0,0 +1,6457 @@ +From 44511dc2463b516065f5b88b6d2a61045b1333f2 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 26 Mar 2019 18:51:10 -0400 +Subject: [PATCH] Remove 3des support + +Completely remove support for all DES3 enctypes (des3-cbc-raw, +des3-hmac-sha1, des3-cbc-sha1-kd). Update all tests and documentation +to user other enctypes. Mark the 3DES enctypes UNSUPPORTED and retain +their constants. +--- + doc/admin/advanced/retiring-des.rst | 11 + + doc/admin/conf_files/kdc_conf.rst | 7 +- + doc/admin/enctypes.rst | 13 +- + doc/admin/troubleshoot.rst | 9 +- + doc/appdev/refs/macros/index.rst | 1 - + doc/mitK5features.rst | 2 +- + src/Makefile.in | 4 +- + src/configure.in | 1 - + src/include/krb5/krb5.hin | 12 +- + src/kadmin/testing/proto/kdc.conf.proto | 4 +- + src/kdc/kdc_util.c | 4 - + src/lib/crypto/Makefile.in | 8 +- + src/lib/crypto/builtin/Makefile.in | 6 +- + src/lib/crypto/builtin/des/ISSUES | 13 - + src/lib/crypto/builtin/des/Makefile.in | 80 ---- + src/lib/crypto/builtin/des/d3_aead.c | 133 ------ + src/lib/crypto/builtin/des/d3_kysched.c | 51 --- + src/lib/crypto/builtin/des/deps | 148 ------- + src/lib/crypto/builtin/des/des_int.h | 285 ------------- + src/lib/crypto/builtin/des/des_keys.c | 40 -- + src/lib/crypto/builtin/des/destest.c | 240 ----------- + src/lib/crypto/builtin/des/doc/libdes.doc | 208 --------- + src/lib/crypto/builtin/des/f_aead.c | 173 -------- + src/lib/crypto/builtin/des/f_cbc.c | 256 ------------ + src/lib/crypto/builtin/des/f_cksum.c | 136 ------ + src/lib/crypto/builtin/des/f_parity.c | 56 --- + src/lib/crypto/builtin/des/f_sched.c | 359 ---------------- + src/lib/crypto/builtin/des/f_tables.c | 370 ---------------- + src/lib/crypto/builtin/des/f_tables.h | 285 ------------- + src/lib/crypto/builtin/des/key_sched.c | 62 --- + src/lib/crypto/builtin/des/keytest.data | 171 -------- + src/lib/crypto/builtin/des/t_verify.c | 395 ------------------ + src/lib/crypto/builtin/des/weak_key.c | 86 ---- + .../crypto/builtin/enc_provider/Makefile.in | 6 +- + src/lib/crypto/builtin/enc_provider/deps | 12 - + src/lib/crypto/builtin/enc_provider/des3.c | 105 ----- + src/lib/crypto/crypto_tests/t_cf2.expected | 1 - + src/lib/crypto/crypto_tests/t_cf2.in | 5 - + src/lib/crypto/crypto_tests/t_cksums.c | 10 - + src/lib/crypto/crypto_tests/t_decrypt.c | 57 --- + src/lib/crypto/crypto_tests/t_derive.c | 36 -- + src/lib/crypto/crypto_tests/t_encrypt.c | 1 - + src/lib/crypto/crypto_tests/t_short.c | 1 - + src/lib/crypto/crypto_tests/t_str2key.c | 52 --- + src/lib/crypto/krb/Makefile.in | 3 - + src/lib/crypto/krb/cksumtypes.c | 6 - + src/lib/crypto/krb/crypto_int.h | 16 - + src/lib/crypto/krb/default_state.c | 10 - + src/lib/crypto/krb/enctype_util.c | 3 + + src/lib/crypto/krb/etypes.c | 21 - + src/lib/crypto/krb/prf_des.c | 47 --- + src/lib/crypto/krb/random_to_key.c | 45 -- + src/lib/crypto/libk5crypto.exports | 1 - + src/lib/crypto/openssl/Makefile.in | 8 +- + src/lib/crypto/openssl/des/Makefile.in | 20 - + src/lib/crypto/openssl/des/deps | 15 - + src/lib/crypto/openssl/des/des_keys.c | 40 -- + .../crypto/openssl/enc_provider/Makefile.in | 3 - + src/lib/crypto/openssl/enc_provider/deps | 11 - + src/lib/crypto/openssl/enc_provider/des3.c | 184 -------- + src/lib/gssapi/krb5/accept_sec_context.c | 1 - + src/lib/gssapi/krb5/gssapiP_krb5.h | 6 +- + src/lib/gssapi/krb5/k5seal.c | 35 +- + src/lib/gssapi/krb5/k5sealiov.c | 27 +- + src/lib/gssapi/krb5/k5unseal.c | 102 ++--- + src/lib/gssapi/krb5/k5unsealiov.c | 38 +- + src/lib/gssapi/krb5/util_crypt.c | 11 - + .../api.current/chpass-principal-v2.exp | 4 +- + .../api.current/get-principal-v2.exp | 4 +- + .../api.current/randkey-principal-v2.exp | 4 +- + src/lib/krb5/krb/init_ctx.c | 3 - + src/lib/krb5/krb/s4u_creds.c | 2 - + src/lib/krb5/krb/t_copy_context.c | 2 +- + src/lib/krb5/krb/t_etypes.c | 48 +-- + src/lib/krb5/os/t_trace.c | 4 +- + src/lib/krb5/os/t_trace.ref | 2 +- + src/plugins/preauth/pkinit/pkcs11.h | 6 +- + src/plugins/preauth/pkinit/pkinit_clnt.c | 8 - + src/plugins/preauth/pkinit/pkinit_crypto.h | 12 - + .../preauth/pkinit/pkinit_crypto_openssl.c | 38 -- + src/plugins/preauth/pkinit/pkinit_kdf_test.c | 31 -- + src/plugins/preauth/spake/t_vectors.c | 25 -- + src/tests/dejagnu/config/default.exp | 78 ---- + src/tests/dejagnu/krb-standalone/kprop.exp | 2 +- + src/tests/gssapi/t_enctypes.py | 33 +- + src/tests/gssapi/t_invalid.c | 12 - + src/tests/gssapi/t_pcontok.c | 16 +- + src/tests/gssapi/t_prf.c | 7 - + src/tests/t_authdata.py | 2 +- + src/tests/t_etype_info.py | 18 +- + src/tests/t_keyrollover.py | 8 +- + src/tests/t_mkey.py | 35 -- + src/tests/t_salt.py | 5 +- + src/util/k5test.py | 10 - + .../leash/htmlhelp/html/Encryption_Types.htm | 13 - + 95 files changed, 163 insertions(+), 4837 deletions(-) + delete mode 100644 src/lib/crypto/builtin/des/ISSUES + delete mode 100644 src/lib/crypto/builtin/des/Makefile.in + delete mode 100644 src/lib/crypto/builtin/des/d3_aead.c + delete mode 100644 src/lib/crypto/builtin/des/d3_kysched.c + delete mode 100644 src/lib/crypto/builtin/des/deps + delete mode 100644 src/lib/crypto/builtin/des/des_int.h + delete mode 100644 src/lib/crypto/builtin/des/des_keys.c + delete mode 100644 src/lib/crypto/builtin/des/destest.c + delete mode 100644 src/lib/crypto/builtin/des/doc/libdes.doc + delete mode 100644 src/lib/crypto/builtin/des/f_aead.c + delete mode 100644 src/lib/crypto/builtin/des/f_cbc.c + delete mode 100644 src/lib/crypto/builtin/des/f_cksum.c + delete mode 100644 src/lib/crypto/builtin/des/f_parity.c + delete mode 100644 src/lib/crypto/builtin/des/f_sched.c + delete mode 100644 src/lib/crypto/builtin/des/f_tables.c + delete mode 100644 src/lib/crypto/builtin/des/f_tables.h + delete mode 100644 src/lib/crypto/builtin/des/key_sched.c + delete mode 100644 src/lib/crypto/builtin/des/keytest.data + delete mode 100644 src/lib/crypto/builtin/des/t_verify.c + delete mode 100644 src/lib/crypto/builtin/des/weak_key.c + delete mode 100644 src/lib/crypto/builtin/enc_provider/des3.c + delete mode 100644 src/lib/crypto/krb/prf_des.c + delete mode 100644 src/lib/crypto/openssl/des/Makefile.in + delete mode 100644 src/lib/crypto/openssl/des/deps + delete mode 100644 src/lib/crypto/openssl/des/des_keys.c + delete mode 100644 src/lib/crypto/openssl/enc_provider/des3.c + +diff --git a/doc/admin/advanced/retiring-des.rst b/doc/admin/advanced/retiring-des.rst +index 4a964c15c..cb6258d77 100644 +--- a/doc/admin/advanced/retiring-des.rst ++++ b/doc/admin/advanced/retiring-des.rst +@@ -10,6 +10,13 @@ ability have rendered DES vulnerable to brute force attacks on its 56-bit + keyspace. As such, it is now considered insecure and should not be + used (:rfc:`6649`). + ++In 1999, MIT krb5 added support for Triple-DES (3DES) encryption types. ++However, due to weakenings of DES and other security concerns, it is now also ++considered insecure and should not be used (:rfc:`8429`). AES encryption ++types were added to MIT in 2003, meaning that the number of deployments with ++3DES as the strongest encryption type is hopefully small. The rotation ++procedure described herein works for both DES and 3DES. ++ + History + ------- + +@@ -27,6 +34,10 @@ and removed DES (single-DES) support in release 1.18. As a + consequence, a release prior to 1.18 is required to perform these + migrations. + ++3DES (a flagged deprecated encryption type) was also removed downstream by ++rharwood@redhat.com starting in 1.18; likewise, a pre-1.18 release is required ++to perform these migrations. ++ + Types of keys + ------------- + +diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst +index 2c6ea1855..a9ecaf4a9 100644 +--- a/doc/admin/conf_files/kdc_conf.rst ++++ b/doc/admin/conf_files/kdc_conf.rst +@@ -841,8 +841,6 @@ Encryption types marked as "weak" are available for compatibility but + not recommended for use. + + ==================================================== ========================================================= +-des3-cbc-raw Triple DES cbc mode raw (weak) +-des3-cbc-sha1 des3-hmac-sha1 des3-cbc-sha1-kd Triple DES cbc mode with HMAC/sha1 + aes256-cts-hmac-sha1-96 aes256-cts aes256-sha1 AES-256 CTS mode with 96-bit SHA-1 HMAC + aes128-cts-hmac-sha1-96 aes128-cts aes128-sha1 AES-128 CTS mode with 96-bit SHA-1 HMAC + aes256-cts-hmac-sha384-192 aes256-sha2 AES-256 CTS mode with 192-bit SHA-384 HMAC +@@ -851,7 +849,6 @@ arcfour-hmac rc4-hmac arcfour-hmac-md5 RC4 with HMAC/MD5 + arcfour-hmac-exp rc4-hmac-exp arcfour-hmac-md5-exp Exportable RC4 with HMAC/MD5 (weak) + camellia256-cts-cmac camellia256-cts Camellia-256 CTS mode with CMAC + camellia128-cts-cmac camellia128-cts Camellia-128 CTS mode with CMAC +-des3 The triple DES family: des3-cbc-sha1 + aes The AES family: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, aes256-cts-hmac-sha384-192, and aes128-cts-hmac-sha256-128 + rc4 The RC4 family: arcfour-hmac + camellia The Camellia family: camellia256-cts-cmac and camellia128-cts-cmac +@@ -863,8 +860,8 @@ from the current list by prefixing them with a minus sign ("-"). + Types or families can be prefixed with a plus sign ("+") for symmetry; + it has the same meaning as just listing the type or family. For + example, "``DEFAULT -rc4``" would be the default set of encryption +-types with RC4 types removed, and "``des3 DEFAULT``" would be the +-default set of encryption types with triple DES types moved to the ++types with RC4 types removed, and "``aes128-sha2 DEFAULT``" would be ++the default set of encryption types with aes128-sha2 moved to the + front. + + While **aes128-cts** and **aes256-cts** are supported for all Kerberos +diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst +index 84183a53c..b3fdc7c8b 100644 +--- a/doc/admin/enctypes.rst ++++ b/doc/admin/enctypes.rst +@@ -125,7 +125,7 @@ enctype weak? krb5 Windows + des-cbc-crc weak <1.18 >=2000 + des-cbc-md4 weak <1.18 ? + des-cbc-md5 weak <1.18 >=2000 +-des3-cbc-sha1 >=1.1 none ++des3-cbc-sha1 <1.18 none + arcfour-hmac >=1.3 >=2000 + arcfour-hmac-exp weak >=1.3 >=2000 + aes128-cts-hmac-sha1-96 >=1.3 >=Vista +@@ -136,7 +136,10 @@ camellia128-cts-cmac >=1.9 none + camellia256-cts-cmac >=1.9 none + ========================== ===== ======== ======= + +-krb5 releases 1.18 and later do not support single-DES. krb5 releases +-1.8 and later disable the single-DES enctypes by default. Microsoft +-Windows releases Windows 7 and later disable single-DES enctypes by +-default. ++krb5 releases 1.8 and later disable the single-DES enctypes by ++default. Microsoft Windows releases Windows 7 and later disable ++single-DES enctypes by default. ++ ++krb5 releases 1.18 and later remove single-DES and 3DES ++(downstream-only patch) enctype support. Microsoft Windows never ++supported 3DES. +diff --git a/doc/admin/troubleshoot.rst b/doc/admin/troubleshoot.rst +index 6a0c7f89b..263fc9c97 100644 +--- a/doc/admin/troubleshoot.rst ++++ b/doc/admin/troubleshoot.rst +@@ -73,11 +73,10 @@ credential verification failed: KDC has no support for encryption type + ...................................................................... + + This most commonly happens when trying to use a principal with only +-DES keys, in a release (MIT krb5 1.7 or later) which disables DES by +-default. DES encryption is considered weak due to its inadequate key +-size. If you cannot migrate away from its use, you can re-enable DES +-by adding ``allow_weak_crypto = true`` to the :ref:`libdefaults` +-section of :ref:`krb5.conf(5)`. ++DES/3DES keys, in a release (MIT krb5 1.7 or later) which disables DES ++by default. DES encryption is considered weak due to its inadequate ++key size and has been removed upstream; 3DES is not recommended, and ++has been removed downstream by rharwood@redhat.com. + + + .. _err_cert_chain_cert_expired: +diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst +index 534795d15..9542611ea 100644 +--- a/doc/appdev/refs/macros/index.rst ++++ b/doc/appdev/refs/macros/index.rst +@@ -36,7 +36,6 @@ Public + CKSUMTYPE_HMAC_SHA1_96_AES256.rst + CKSUMTYPE_HMAC_SHA256_128_AES128.rst + CKSUMTYPE_HMAC_SHA384_192_AES256.rst +- CKSUMTYPE_HMAC_SHA1_DES3.rst + CKSUMTYPE_MD5_HMAC_ARCFOUR.rst + CKSUMTYPE_NIST_SHA.rst + CKSUMTYPE_RSA_MD4.rst +diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst +index a19068e26..5bfdc3936 100644 +--- a/doc/mitK5features.rst ++++ b/doc/mitK5features.rst +@@ -37,7 +37,7 @@ Database backends: LDAP, DB2, LMDB + + krb4 support: Kerberos 5 release < 1.8 + +-DES support: Kerberos 5 release < 1.18 (See :ref:`retiring-des`) ++DES/3DES support: Kerberos 5 release < 1.18 (See :ref:`retiring-des`) + + Interoperability + ---------------- +diff --git a/src/Makefile.in b/src/Makefile.in +index 91a5f4bf8..0197e5b6d 100644 +--- a/src/Makefile.in ++++ b/src/Makefile.in +@@ -129,7 +129,7 @@ WINMAKEFILES=Makefile \ + lib\Makefile lib\crypto\Makefile lib\crypto\krb\Makefile \ + lib\crypto\builtin\Makefile lib\crypto\builtin\aes\Makefile \ + lib\crypto\builtin\enc_provider\Makefile \ +- lib\crypto\builtin\des\Makefile lib\crypto\builtin\md5\Makefile \ ++ lib\crypto\builtin\md5\Makefile \ + lib\crypto\builtin\camellia\Makefile lib\crypto\builtin\md4\Makefile \ + lib\crypto\builtin\hash_provider\Makefile \ + lib\crypto\builtin\sha2\Makefile lib\crypto\builtin\sha1\Makefile \ +@@ -201,8 +201,6 @@ WINMAKEFILES=Makefile \ + ##DOS## $(WCONFIG) config < $@.in > $@ + ##DOS##lib\crypto\builtin\enc_provider\Makefile: lib\crypto\builtin\enc_provider\Makefile.in $(MKFDEP) + ##DOS## $(WCONFIG) config < $@.in > $@ +-##DOS##lib\crypto\builtin\des\Makefile: lib\crypto\builtin\des\Makefile.in $(MKFDEP) +-##DOS## $(WCONFIG) config < $@.in > $@ + ##DOS##lib\crypto\builtin\md5\Makefile: lib\crypto\builtin\md5\Makefile.in $(MKFDEP) + ##DOS## $(WCONFIG) config < $@.in > $@ + ##DOS##lib\crypto\builtin\camellia\Makefile: lib\crypto\builtin\camellia\Makefile.in $(MKFDEP) +diff --git a/src/configure.in b/src/configure.in +index 8d781a7c8..a19a0ea97 100644 +--- a/src/configure.in ++++ b/src/configure.in +@@ -1443,7 +1443,6 @@ V5_AC_OUTPUT_MAKEFILE(. + lib/crypto lib/crypto/krb lib/crypto/$CRYPTO_IMPL + lib/crypto/$CRYPTO_IMPL/enc_provider + lib/crypto/$CRYPTO_IMPL/hash_provider +- lib/crypto/$CRYPTO_IMPL/des + lib/crypto/$CRYPTO_IMPL/md4 lib/crypto/$CRYPTO_IMPL/md5 + lib/crypto/$CRYPTO_IMPL/sha1 lib/crypto/$CRYPTO_IMPL/sha2 + lib/crypto/$CRYPTO_IMPL/aes lib/crypto/$CRYPTO_IMPL/camellia +diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin +index 5f596d1fc..ca7eb6a80 100644 +--- a/src/include/krb5/krb5.hin ++++ b/src/include/krb5/krb5.hin +@@ -1,4 +1,4 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++./* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ + /* General definitions for Kerberos version 5. */ + /* + * Copyright 1989, 1990, 1995, 2001, 2003, 2007, 2011 by the Massachusetts +@@ -426,8 +426,8 @@ typedef struct _krb5_crypto_iov { + #define ENCTYPE_DES_CBC_MD4 0x0002 /**< @deprecated no longer supported */ + #define ENCTYPE_DES_CBC_MD5 0x0003 /**< @deprecated no longer supported */ + #define ENCTYPE_DES_CBC_RAW 0x0004 /**< @deprecated no longer supported */ +-#define ENCTYPE_DES3_CBC_SHA 0x0005 /**< @deprecated DES-3 cbc with SHA1 */ +-#define ENCTYPE_DES3_CBC_RAW 0x0006 /**< @deprecated DES-3 cbc mode raw */ ++#define ENCTYPE_DES3_CBC_SHA 0x0005 /**< @deprecated no longer supported */ ++#define ENCTYPE_DES3_CBC_RAW 0x0006 /**< @deprecated no longer supported */ + #define ENCTYPE_DES_HMAC_SHA1 0x0008 /**< @deprecated no longer supported */ + /* PKINIT */ + #define ENCTYPE_DSA_SHA1_CMS 0x0009 /**< DSA with SHA1, CMS signature */ +@@ -436,9 +436,9 @@ typedef struct _krb5_crypto_iov { + #define ENCTYPE_RC2_CBC_ENV 0x000c /**< RC2 cbc mode, CMS enveloped data */ + #define ENCTYPE_RSA_ENV 0x000d /**< RSA encryption, CMS enveloped data */ + #define ENCTYPE_RSA_ES_OAEP_ENV 0x000e /**< RSA w/OEAP encryption, CMS enveloped data */ +-#define ENCTYPE_DES3_CBC_ENV 0x000f /**< DES-3 cbc mode, CMS enveloped data */ ++#define ENCTYPE_DES3_CBC_ENV 0x000f /**< @deprecated no longer supported */ + +-#define ENCTYPE_DES3_CBC_SHA1 0x0010 ++#define ENCTYPE_DES3_CBC_SHA1 0x0010 /**< @deprecated removed */ + #define ENCTYPE_AES128_CTS_HMAC_SHA1_96 0x0011 /**< RFC 3962 */ + #define ENCTYPE_AES256_CTS_HMAC_SHA1_96 0x0012 /**< RFC 3962 */ + #define ENCTYPE_AES128_CTS_HMAC_SHA256_128 0x0013 /**< RFC 8009 */ +@@ -458,7 +458,7 @@ typedef struct _krb5_crypto_iov { + #define CKSUMTYPE_RSA_MD5 0x0007 + #define CKSUMTYPE_RSA_MD5_DES 0x0008 + #define CKSUMTYPE_NIST_SHA 0x0009 +-#define CKSUMTYPE_HMAC_SHA1_DES3 0x000c ++#define CKSUMTYPE_HMAC_SHA1_DES3 0x000c /* @deprecated removed */ + #define CKSUMTYPE_HMAC_SHA1_96_AES128 0x000f /**< RFC 3962. Used with + ENCTYPE_AES128_CTS_HMAC_SHA1_96 */ + #define CKSUMTYPE_HMAC_SHA1_96_AES256 0x0010 /**< RFC 3962. Used with +diff --git a/src/kadmin/testing/proto/kdc.conf.proto b/src/kadmin/testing/proto/kdc.conf.proto +index 8a4b87de1..d7f1d076b 100644 +--- a/src/kadmin/testing/proto/kdc.conf.proto ++++ b/src/kadmin/testing/proto/kdc.conf.proto +@@ -11,6 +11,6 @@ + dict_file = __K5ROOT__/ovsec_adm.dict + kadmind_port = 1751 + kpasswd_port = 1752 +- master_key_type = des3-hmac-sha1 +- supported_enctypes = des3-hmac-sha1:normal aes256-cts:normal aes128-cts:normal aes256-sha2:normal aes128-sha2:normal ++ master_key_type = aes256-cts ++ supported_enctypes = aes256-cts:normal aes128-cts:normal aes256-sha2:normal aes128-sha2:normal + } +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index df1ba6acf..23ad6c584 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1077,8 +1077,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) + name = "rsaEncryption-EnvOID"; + else if (ktype == ENCTYPE_RSA_ES_OAEP_ENV) + name = "id-RSAES-OAEP-EnvOID"; +- else if (ktype == ENCTYPE_DES3_CBC_ENV) +- name = "des-ede3-cbc-EnvOID"; + else + return krb5_enctype_to_name(ktype, FALSE, buf, buflen); + +@@ -1741,8 +1739,6 @@ krb5_boolean + enctype_requires_etype_info_2(krb5_enctype enctype) + { + switch(enctype) { +- case ENCTYPE_DES3_CBC_SHA1: +- case ENCTYPE_DES3_CBC_RAW: + case ENCTYPE_ARCFOUR_HMAC: + case ENCTYPE_ARCFOUR_HMAC_EXP : + return 0; +diff --git a/src/lib/crypto/Makefile.in b/src/lib/crypto/Makefile.in +index c3fcfd7e8..890d54adf 100644 +--- a/src/lib/crypto/Makefile.in ++++ b/src/lib/crypto/Makefile.in +@@ -13,7 +13,7 @@ STOBJLISTS=$(CRYPTO_IMPL)/enc_provider/OBJS.ST \ + $(CRYPTO_IMPL)/hash_provider/OBJS.ST \ + $(CRYPTO_IMPL)/md4/OBJS.ST $(CRYPTO_IMPL)/md5/OBJS.ST \ + $(CRYPTO_IMPL)/sha1/OBJS.ST $(CRYPTO_IMPL)/sha2/OBJS.ST \ +- $(CRYPTO_IMPL)/aes/OBJS.ST $(CRYPTO_IMPL)/des/OBJS.ST \ ++ $(CRYPTO_IMPL)/aes/OBJS.ST \ + $(CRYPTO_IMPL)/camellia/OBJS.ST krb/OBJS.ST \ + $(CRYPTO_IMPL)/OBJS.ST + +@@ -21,7 +21,7 @@ SUBDIROBJLISTS=$(CRYPTO_IMPL)/enc_provider/OBJS.ST \ + $(CRYPTO_IMPL)/hash_provider/OBJS.ST \ + $(CRYPTO_IMPL)/md4/OBJS.ST $(CRYPTO_IMPL)/md5/OBJS.ST \ + $(CRYPTO_IMPL)/sha1/OBJS.ST $(CRYPTO_IMPL)/sha2/OBJS.ST \ +- $(CRYPTO_IMPL)/aes/OBJS.ST $(CRYPTO_IMPL)/des/OBJS.ST \ ++ $(CRYPTO_IMPL)/aes/OBJS.ST \ + $(CRYPTO_IMPL)/camellia/OBJS.ST krb/OBJS.ST \ + $(CRYPTO_IMPL)/OBJS.ST + +@@ -34,8 +34,8 @@ SHLIB_EXPDEPLIBS= $(SUPPORT_DEPLIB) + SHLIB_LDFLAGS= $(LDFLAGS) @SHLIB_RPATH_DIRS@ + + ##DOS##LIBNAME=$(OUTPRE)crypto.lib +-##DOS##OBJFILEDEP=$(OUTPRE)krb.lst $(OUTPRE)aes.lst $(OUTPRE)enc_provider.lst $(OUTPRE)des.lst $(OUTPRE)md5.lst $(OUTPRE)camellia.lst $(OUTPRE)md4.lst $(OUTPRE)hash_provider.lst $(OUTPRE)sha2.lst $(OUTPRE)sha1.lst $(OUTPRE)builtin.lst +-##DOS##OBJFILELIST=@$(OUTPRE)krb.lst @$(OUTPRE)aes.lst @$(OUTPRE)enc_provider.lst @$(OUTPRE)des.lst @$(OUTPRE)md5.lst @$(OUTPRE)camellia.lst @$(OUTPRE)md4.lst @$(OUTPRE)hash_provider.lst @$(OUTPRE)sha2.lst @$(OUTPRE)sha1.lst @$(OUTPRE)builtin.lst ++##DOS##OBJFILEDEP=$(OUTPRE)krb.lst $(OUTPRE)aes.lst $(OUTPRE)enc_provider.lst $(OUTPRE)md5.lst $(OUTPRE)camellia.lst $(OUTPRE)md4.lst $(OUTPRE)hash_provider.lst $(OUTPRE)sha2.lst $(OUTPRE)sha1.lst $(OUTPRE)builtin.lst ++##DOS##OBJFILELIST=@$(OUTPRE)krb.lst @$(OUTPRE)aes.lst @$(OUTPRE)enc_provider.lst @$(OUTPRE)md5.lst @$(OUTPRE)camellia.lst @$(OUTPRE)md4.lst @$(OUTPRE)hash_provider.lst @$(OUTPRE)sha2.lst @$(OUTPRE)sha1.lst @$(OUTPRE)builtin.lst + + all-unix: all-liblinks + install-unix: install-libs +diff --git a/src/lib/crypto/builtin/Makefile.in b/src/lib/crypto/builtin/Makefile.in +index baf5d974f..82adf1dec 100644 +--- a/src/lib/crypto/builtin/Makefile.in ++++ b/src/lib/crypto/builtin/Makefile.in +@@ -1,6 +1,6 @@ + mydir=lib$(S)crypto$(S)builtin + BUILDTOP=$(REL)..$(S)..$(S).. +-SUBDIRS=camellia des aes md4 md5 sha1 sha2 enc_provider hash_provider ++SUBDIRS=camellia aes md4 md5 sha1 sha2 enc_provider hash_provider + LOCALINCLUDES = -I$(srcdir)/../krb -I$(srcdir) + + ##DOS##BUILDTOP = ..\..\.. +@@ -22,7 +22,7 @@ SRCS=\ + $(srcdir)/init.c \ + $(srcdir)/pbkdf2.c + +-STOBJLISTS= des/OBJS.ST md4/OBJS.ST \ ++STOBJLISTS= md4/OBJS.ST \ + md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \ + enc_provider/OBJS.ST \ + hash_provider/OBJS.ST \ +@@ -30,7 +30,7 @@ STOBJLISTS= des/OBJS.ST md4/OBJS.ST \ + camellia/OBJS.ST \ + OBJS.ST + +-SUBDIROBJLISTS= des/OBJS.ST md4/OBJS.ST \ ++SUBDIROBJLISTS= md4/OBJS.ST \ + md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \ + enc_provider/OBJS.ST \ + hash_provider/OBJS.ST \ +diff --git a/src/lib/crypto/builtin/des/ISSUES b/src/lib/crypto/builtin/des/ISSUES +deleted file mode 100644 +index 157891103..000000000 +--- a/src/lib/crypto/builtin/des/ISSUES ++++ /dev/null +@@ -1,13 +0,0 @@ +-Issues to be addressed for src/lib/crypto/des: -*- text -*- +- +- +-"const" could be used in more places +- +- +-Array types are used in calling interfaces. Under ANSI C, a value of +-type "arraytype *" cannot be assigned to a variable of type "const +-arraytype *", so we get compilation warnings. +- +-Possible fix: Rewrite internal interfaces to not use arrays this way. +-Provide external routines compatible with old API, but not using +-const? +diff --git a/src/lib/crypto/builtin/des/Makefile.in b/src/lib/crypto/builtin/des/Makefile.in +deleted file mode 100644 +index ed25dab7c..000000000 +--- a/src/lib/crypto/builtin/des/Makefile.in ++++ /dev/null +@@ -1,80 +0,0 @@ +-mydir=lib$(S)crypto$(S)builtin$(S)des +-BUILDTOP=$(REL)..$(S)..$(S)..$(S).. +-LOCALINCLUDES = -I$(srcdir)/.. -I$(srcdir)/../../krb +- +-##DOS##BUILDTOP = ..\..\..\.. +-##DOS##PREFIXDIR = builtin\des +-##DOS##OBJFILE = ..\..\$(OUTPRE)des.lst +- +-STLIBOBJS=\ +- d3_aead.o \ +- d3_kysched.o \ +- des_keys.o \ +- f_aead.o \ +- f_cksum.o \ +- f_parity.o \ +- f_sched.o \ +- f_tables.o \ +- key_sched.o \ +- weak_key.o +- +-OBJS= $(OUTPRE)d3_aead.$(OBJEXT) \ +- $(OUTPRE)d3_kysched.$(OBJEXT) \ +- $(OUTPRE)des_keys.$(OBJEXT) \ +- $(OUTPRE)f_aead.$(OBJEXT) \ +- $(OUTPRE)f_cksum.$(OBJEXT) \ +- $(OUTPRE)f_parity.$(OBJEXT) \ +- $(OUTPRE)f_sched.$(OBJEXT) \ +- $(OUTPRE)f_tables.$(OBJEXT) \ +- $(OUTPRE)key_sched.$(OBJEXT) \ +- $(OUTPRE)weak_key.$(OBJEXT) +- +-SRCS= $(srcdir)/d3_aead.c \ +- $(srcdir)/d3_kysched.c \ +- $(srcdir)/des_keys.c \ +- $(srcdir)/f_aead.c \ +- $(srcdir)/f_cksum.c \ +- $(srcdir)/f_parity.c \ +- $(srcdir)/f_sched.c \ +- $(srcdir)/f_tables.c \ +- $(srcdir)/key_sched.c \ +- $(srcdir)/weak_key.c +- +-EXTRADEPSRCS = $(srcdir)/destest.c $(srcdir)/f_cbc.c $(srcdir)/t_verify.c +- +-##DOS##LIBOBJS = $(OBJS) +- +-TOBJS = $(OUTPRE)key_sched.$(OBJEXT) $(OUTPRE)f_sched.$(OBJEXT) \ +- $(OUTPRE)f_cbc.$(OBJEXT) $(OUTPRE)f_tables.$(OBJEXT) \ +- $(OUTPRE)f_cksum.$(OBJEXT) +- +-verify$(EXEEXT): t_verify.$(OBJEXT) $(TOBJS) f_parity.$(OBJEXT) \ +- $(COM_ERR_DEPLIB) $(SUPPORT_DEPLIB) +- $(CC_LINK) -o $@ t_verify.$(OBJEXT) $(TOBJS) f_parity.$(OBJEXT) \ +- -lcom_err $(SUPPORT_LIB) +- +-destest$(EXEEXT): destest.$(OBJEXT) $(TOBJS) $(SUPPORT_DEPLIB) +- $(CC_LINK) -o $@ destest.$(OBJEXT) $(TOBJS) $(SUPPORT_LIB) +- +-all-unix: all-libobjs +- +-check-unix: verify destest +- $(RUN_TEST) ./verify -z +- $(RUN_TEST) ./verify -m +- $(RUN_TEST) ./verify +- $(RUN_TEST) ./destest < $(srcdir)/keytest.data +- +-includes: depend +- +-depend: $(SRCS) +- +-check-windows: +- +-clean: +- $(RM) destest.$(OBJEXT) destest$(EXEEXT) verify$(EXEEXT) \ +- t_verify.$(OBJEXT) $(TOBJS) +- +-clean-unix:: clean-libobjs +- +-@libobj_frag@ +- +diff --git a/src/lib/crypto/builtin/des/d3_aead.c b/src/lib/crypto/builtin/des/d3_aead.c +deleted file mode 100644 +index bddf75a47..000000000 +--- a/src/lib/crypto/builtin/des/d3_aead.c ++++ /dev/null +@@ -1,133 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * Copyright (C) 2008 by the Massachusetts Institute of Technology. +- * Copyright 1995 by Richard P. Basch. All Rights Reserved. +- * Copyright 1995 by Lehman Brothers, Inc. All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of Richard P. Basch, Lehman Brothers and M.I.T. not be used +- * in advertising or publicity pertaining to distribution of the software +- * without specific, written prior permission. Richard P. Basch, +- * Lehman Brothers and M.I.T. make no representations about the suitability +- * of this software for any purpose. It is provided "as is" without +- * express or implied warranty. +- */ +- +-#include "crypto_int.h" +-#include "des_int.h" +-#include "f_tables.h" +- +-void +-krb5int_des3_cbc_encrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule ks1, +- const mit_des_key_schedule ks2, +- const mit_des_key_schedule ks3, +- mit_des_cblock ivec) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp1, *kp2, *kp3; +- const unsigned char *ip; +- struct iov_cursor cursor; +- unsigned char block[MIT_DES_BLOCK_LENGTH]; +- +- /* Get key pointers here. These won't need to be reinitialized. */ +- kp1 = (const unsigned DES_INT32 *)ks1; +- kp2 = (const unsigned DES_INT32 *)ks2; +- kp3 = (const unsigned DES_INT32 *)ks3; +- +- /* Initialize left and right with the contents of the initial vector. */ +- ip = (ivec != NULL) ? ivec : mit_des_zeroblock; +- left = load_32_be(ip); +- right = load_32_be(ip + 4); +- +- k5_iov_cursor_init(&cursor, data, num_data, MIT_DES_BLOCK_LENGTH, FALSE); +- while (k5_iov_cursor_get(&cursor, block)) { +- /* xor this block with the previous ciphertext. */ +- left ^= load_32_be(block); +- right ^= load_32_be(block + 4); +- +- /* Encrypt what we have and store it back into block. */ +- DES_DO_ENCRYPT(left, right, kp1); +- DES_DO_DECRYPT(left, right, kp2); +- DES_DO_ENCRYPT(left, right, kp3); +- store_32_be(left, block); +- store_32_be(right, block + 4); +- +- k5_iov_cursor_put(&cursor, block); +- } +- +- if (ivec != NULL) { +- store_32_be(left, ivec); +- store_32_be(right, ivec + 4); +- } +-} +- +-void +-krb5int_des3_cbc_decrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule ks1, +- const mit_des_key_schedule ks2, +- const mit_des_key_schedule ks3, +- mit_des_cblock ivec) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp1, *kp2, *kp3; +- const unsigned char *ip; +- unsigned DES_INT32 ocipherl, ocipherr; +- unsigned DES_INT32 cipherl, cipherr; +- struct iov_cursor cursor; +- unsigned char block[MIT_DES_BLOCK_LENGTH]; +- +- /* Get key pointers here. These won't need to be reinitialized. */ +- kp1 = (const unsigned DES_INT32 *)ks1; +- kp2 = (const unsigned DES_INT32 *)ks2; +- kp3 = (const unsigned DES_INT32 *)ks3; +- +- /* +- * Decrypting is harder than encrypting because of +- * the necessity of remembering a lot more things. +- * Should think about this a little more... +- */ +- +- /* Prime the old cipher with ivec.*/ +- ip = (ivec != NULL) ? ivec : mit_des_zeroblock; +- ocipherl = load_32_be(ip); +- ocipherr = load_32_be(ip + 4); +- +- k5_iov_cursor_init(&cursor, data, num_data, MIT_DES_BLOCK_LENGTH, FALSE); +- while (k5_iov_cursor_get(&cursor, block)) { +- /* Split this block into left and right. */ +- cipherl = left = load_32_be(block); +- cipherr = right = load_32_be(block + 4); +- +- /* Decrypt and xor with the old cipher to get plain text. */ +- DES_DO_DECRYPT(left, right, kp3); +- DES_DO_ENCRYPT(left, right, kp2); +- DES_DO_DECRYPT(left, right, kp1); +- left ^= ocipherl; +- right ^= ocipherr; +- +- /* Store the encrypted halves back into block. */ +- store_32_be(left, block); +- store_32_be(right, block + 4); +- +- /* Save current cipher block halves. */ +- ocipherl = cipherl; +- ocipherr = cipherr; +- +- k5_iov_cursor_put(&cursor, block); +- } +- +- if (ivec != NULL) { +- store_32_be(ocipherl, ivec); +- store_32_be(ocipherr, ivec + 4); +- } +-} +diff --git a/src/lib/crypto/builtin/des/d3_kysched.c b/src/lib/crypto/builtin/des/d3_kysched.c +deleted file mode 100644 +index ebd1050b1..000000000 +--- a/src/lib/crypto/builtin/des/d3_kysched.c ++++ /dev/null +@@ -1,51 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * Copyright 1995 by Richard P. Basch. All Rights Reserved. +- * Copyright 1995 by Lehman Brothers, Inc. All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of Richard P. Basch, Lehman Brothers and M.I.T. not be used +- * in advertising or publicity pertaining to distribution of the software +- * without specific, written prior permission. Richard P. Basch, +- * Lehman Brothers and M.I.T. make no representations about the suitability +- * of this software for any purpose. It is provided "as is" without +- * express or implied warranty. +- */ +- +-#include "k5-int.h" +-#include "des_int.h" +- +-int +-mit_des3_key_sched(mit_des3_cblock k, mit_des3_key_schedule schedule) +-{ +- mit_des_make_key_sched(k[0],schedule[0]); +- mit_des_make_key_sched(k[1],schedule[1]); +- mit_des_make_key_sched(k[2],schedule[2]); +- +- if (!mit_des_check_key_parity(k[0])) /* bad parity --> return -1 */ +- return(-1); +- if (mit_des_is_weak_key(k[0])) +- return(-2); +- +- if (!mit_des_check_key_parity(k[1])) +- return(-1); +- if (mit_des_is_weak_key(k[1])) +- return(-2); +- +- if (!mit_des_check_key_parity(k[2])) +- return(-1); +- if (mit_des_is_weak_key(k[2])) +- return(-2); +- +- /* if key was good, return 0 */ +- return 0; +-} +diff --git a/src/lib/crypto/builtin/des/deps b/src/lib/crypto/builtin/des/deps +deleted file mode 100644 +index df2a31dac..000000000 +--- a/src/lib/crypto/builtin/des/deps ++++ /dev/null +@@ -1,148 +0,0 @@ +-# +-# Generated makefile dependencies follow. +-# +-d3_aead.so d3_aead.po $(OUTPRE)d3_aead.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +- $(srcdir)/../aes/aes.h $(srcdir)/../crypto_mod.h $(srcdir)/../sha2/sha2.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- d3_aead.c des_int.h f_tables.h +-d3_kysched.so d3_kysched.po $(OUTPRE)d3_kysched.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- d3_kysched.c des_int.h +-des_keys.so des_keys.po $(OUTPRE)des_keys.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(srcdir)/../aes/aes.h \ +- $(srcdir)/../crypto_mod.h $(srcdir)/../sha2/sha2.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des_int.h des_keys.c +-f_aead.so f_aead.po $(OUTPRE)f_aead.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +- $(srcdir)/../aes/aes.h $(srcdir)/../crypto_mod.h $(srcdir)/../sha2/sha2.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des_int.h f_aead.c f_tables.h +-f_cksum.so f_cksum.po $(OUTPRE)f_cksum.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h f_cksum.c \ +- f_tables.h +-f_parity.so f_parity.po $(OUTPRE)f_parity.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des_int.h f_parity.c +-f_sched.so f_sched.po $(OUTPRE)f_sched.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h f_sched.c +-f_tables.so f_tables.po $(OUTPRE)f_tables.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des_int.h f_tables.c f_tables.h +-key_sched.so key_sched.po $(OUTPRE)key_sched.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des_int.h key_sched.c +-weak_key.so weak_key.po $(OUTPRE)weak_key.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des_int.h weak_key.c +-destest.so destest.po $(OUTPRE)destest.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h destest.c +-f_cbc.so f_cbc.po $(OUTPRE)f_cbc.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h f_cbc.c \ +- f_tables.h +-t_verify.so t_verify.po $(OUTPRE)t_verify.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des_int.h t_verify.c +diff --git a/src/lib/crypto/builtin/des/des_int.h b/src/lib/crypto/builtin/des/des_int.h +deleted file mode 100644 +index f8dc6b296..000000000 +--- a/src/lib/crypto/builtin/des/des_int.h ++++ /dev/null +@@ -1,285 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/des_int.h */ +-/* +- * Copyright 1987, 1988, 1990, 2002 by the Massachusetts Institute of +- * Technology. All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-/* Private include file for the Data Encryption Standard library. */ +- +-/* only do the whole thing once */ +-#ifndef DES_INTERNAL_DEFS +-#define DES_INTERNAL_DEFS +- +-#include "k5-int.h" +-/* +- * Begin "mit-des.h" +- */ +-#ifndef KRB5_MIT_DES__ +-#define KRB5_MIT_DES__ +- +-#if defined(__MACH__) && defined(__APPLE__) +-#include +-#include +-#if TARGET_RT_MAC_CFM +-#error "Use KfM 4.0 SDK headers for CFM compilation." +-#endif +-#if defined(DEPRECATED_IN_MAC_OS_X_VERSION_10_5) && !defined(KRB5_SUPRESS_DEPRECATED_WARNINGS) +-#define KRB5INT_DES_DEPRECATED DEPRECATED_IN_MAC_OS_X_VERSION_10_5 +-#endif +-#endif /* defined(__MACH__) && defined(__APPLE__) */ +- +-/* Macro to add deprecated attribute to DES types and functions */ +-/* Currently only defined on macOS 10.5 and later. */ +-#ifndef KRB5INT_DES_DEPRECATED +-#define KRB5INT_DES_DEPRECATED +-#endif +- +-#include +- +-#if UINT_MAX >= 0xFFFFFFFFUL +-#define DES_INT32 int +-#define DES_UINT32 unsigned int +-#else +-#define DES_INT32 long +-#define DES_UINT32 unsigned long +-#endif +- +-typedef unsigned char des_cblock[8] /* crypto-block size */ +-KRB5INT_DES_DEPRECATED; +- +-/* +- * Key schedule. +- * +- * This used to be +- * +- * typedef struct des_ks_struct { +- * union { DES_INT32 pad; des_cblock _;} __; +- * } des_key_schedule[16]; +- * +- * but it would cause trouble if DES_INT32 were ever more than 4 +- * bytes. The reason is that all the encryption functions cast it to +- * (DES_INT32 *), and treat it as if it were DES_INT32[32]. If +- * 2*sizeof(DES_INT32) is ever more than sizeof(des_cblock), the +- * caller-allocated des_key_schedule will be overflowed by the key +- * scheduling functions. We can't assume that every platform will +- * have an exact 32-bit int, and nothing should be looking inside a +- * des_key_schedule anyway. +- */ +-typedef struct des_ks_struct { DES_INT32 _[2]; } des_key_schedule[16] +-KRB5INT_DES_DEPRECATED; +- +-typedef des_cblock mit_des_cblock; +-typedef des_key_schedule mit_des_key_schedule; +- +-/* Triple-DES structures */ +-typedef mit_des_cblock mit_des3_cblock[3]; +-typedef mit_des_key_schedule mit_des3_key_schedule[3]; +- +-#define MIT_DES_ENCRYPT 1 +-#define MIT_DES_DECRYPT 0 +- +-typedef struct mit_des_ran_key_seed { +- krb5_encrypt_block eblock; +- krb5_data sequence; +-} mit_des_random_state; +- +-/* the first byte of the key is already in the keyblock */ +- +-#define MIT_DES_BLOCK_LENGTH (8*sizeof(krb5_octet)) +-/* This used to be 8*sizeof(krb5_octet) */ +-#define MIT_DES_KEYSIZE 8 +- +-#define MIT_DES_CBC_CKSUM_LENGTH (4*sizeof(krb5_octet)) +- +-#endif /* KRB5_MIT_DES__ */ +-/* +- * End "mit-des.h" +- */ +- +-/* afsstring2key.c */ +-krb5_error_code mit_afs_string_to_key(krb5_keyblock *keyblock, +- const krb5_data *data, +- const krb5_data *salt); +-char *mit_afs_crypt(const char *pw, const char *salt, char *iobuf); +- +-/* f_cksum.c */ +-unsigned long mit_des_cbc_cksum(const krb5_octet *, krb5_octet *, +- unsigned long, const mit_des_key_schedule, +- const krb5_octet *); +- +-/* f_cbc.c (used by test programs) */ +-int +-mit_des_cbc_encrypt(const mit_des_cblock *in, mit_des_cblock *out, +- unsigned long length, const mit_des_key_schedule schedule, +- const mit_des_cblock ivec, int enc); +- +-#define mit_des_zeroblock krb5int_c_mit_des_zeroblock +-extern const mit_des_cblock mit_des_zeroblock; +- +-/* fin_rndkey.c */ +-krb5_error_code mit_des_finish_random_key(const krb5_encrypt_block *, +- krb5_pointer *); +- +-/* finish_key.c */ +-krb5_error_code mit_des_finish_key(krb5_encrypt_block *); +- +-/* init_rkey.c */ +-krb5_error_code mit_des_init_random_key(const krb5_encrypt_block *, +- const krb5_keyblock *, +- krb5_pointer *); +- +-/* key_parity.c */ +-void mit_des_fixup_key_parity(mit_des_cblock); +-int mit_des_check_key_parity(mit_des_cblock); +- +-/* key_sched.c */ +-int mit_des_key_sched(mit_des_cblock, mit_des_key_schedule); +- +-/* process_ky.c */ +-krb5_error_code mit_des_process_key(krb5_encrypt_block *, +- const krb5_keyblock *); +- +-/* random_key.c */ +-krb5_error_code mit_des_random_key(const krb5_encrypt_block *, +- krb5_pointer, krb5_keyblock **); +- +-/* string2key.c */ +-krb5_error_code mit_des_string_to_key(const krb5_encrypt_block *, +- krb5_keyblock *, const krb5_data *, +- const krb5_data *); +-krb5_error_code mit_des_string_to_key_int(krb5_keyblock *, const krb5_data *, +- const krb5_data *); +- +-/* weak_key.c */ +-int mit_des_is_weak_key(mit_des_cblock); +- +-/* cmb_keys.c */ +-krb5_error_code mit_des_combine_subkeys(const krb5_keyblock *, +- const krb5_keyblock *, +- krb5_keyblock **); +- +-/* f_pcbc.c */ +-int mit_des_pcbc_encrypt(); +- +-/* f_sched.c */ +-int mit_des_make_key_sched(mit_des_cblock, mit_des_key_schedule); +- +- +-/* misc.c */ +-extern void swap_bits(char *); +-extern unsigned long long_swap_bits(unsigned long); +-extern unsigned long swap_six_bits_to_ansi(unsigned long); +-extern unsigned long swap_four_bits_to_ansi(unsigned long); +-extern unsigned long swap_bit_pos_1(unsigned long); +-extern unsigned long swap_bit_pos_0(unsigned long); +-extern unsigned long swap_bit_pos_0_to_ansi(unsigned long); +-extern unsigned long rev_swap_bit_pos_0(unsigned long); +-extern unsigned long swap_byte_bits(unsigned long); +-extern unsigned long swap_long_bytes_bit_number(unsigned long); +-#ifdef FILE +-/* XXX depends on FILE being a #define! */ +-extern void test_set(FILE *, const char *, int, const char *, int); +-#endif +- +-void +-krb5int_des3_cbc_encrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule ks1, +- const mit_des_key_schedule ks2, +- const mit_des_key_schedule ks3, +- mit_des_cblock ivec); +- +-void +-krb5int_des3_cbc_decrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule ks1, +- const mit_des_key_schedule ks2, +- const mit_des_key_schedule ks3, +- mit_des_cblock ivec); +- +-void +-krb5int_des_cbc_encrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule schedule, +- mit_des_cblock ivec); +- +-void +-krb5int_des_cbc_decrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule schedule, +- mit_des_cblock ivec); +- +-void +-krb5int_des_cbc_mac(const krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule schedule, mit_des_cblock ivec, +- mit_des_cblock out); +- +-/* d3_procky.c */ +-krb5_error_code mit_des3_process_key(krb5_encrypt_block *eblock, +- const krb5_keyblock *keyblock); +- +-/* d3_kysched.c */ +-int mit_des3_key_sched(mit_des3_cblock key, mit_des3_key_schedule schedule); +- +-/* d3_str2ky.c */ +-krb5_error_code mit_des3_string_to_key(const krb5_encrypt_block *eblock, +- krb5_keyblock *keyblock, +- const krb5_data *data, +- const krb5_data *salt); +- +-/* u_nfold.c */ +-krb5_error_code mit_des_n_fold(const krb5_octet *input, const size_t in_len, +- krb5_octet *output, const size_t out_len); +- +-/* u_rn_key.c */ +-int mit_des_is_weak_keyblock(krb5_keyblock *keyblock); +- +-void mit_des_fixup_keyblock_parity(krb5_keyblock *keyblock); +- +-krb5_error_code mit_des_set_random_generator_seed(const krb5_data *seed, +- krb5_pointer random_state); +- +-krb5_error_code mit_des_set_random_sequence_number(const krb5_data *sequence, +- krb5_pointer random_state); +-#endif /*DES_INTERNAL_DEFS*/ +diff --git a/src/lib/crypto/builtin/des/des_keys.c b/src/lib/crypto/builtin/des/des_keys.c +deleted file mode 100644 +index 32b119aad..000000000 +--- a/src/lib/crypto/builtin/des/des_keys.c ++++ /dev/null +@@ -1,40 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/des_keys.c - Key functions used by Kerberos code */ +-/* +- * Copyright (C) 2011 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-#include "crypto_int.h" +-#include "des_int.h" +- +-void +-k5_des_fixup_key_parity(unsigned char *keybits) +-{ +- mit_des_fixup_key_parity(keybits); +-} +- +-krb5_boolean +-k5_des_is_weak_key(unsigned char *keybits) +-{ +- return mit_des_is_weak_key(keybits); +-} +diff --git a/src/lib/crypto/builtin/des/destest.c b/src/lib/crypto/builtin/des/destest.c +deleted file mode 100644 +index 52114304e..000000000 +--- a/src/lib/crypto/builtin/des/destest.c ++++ /dev/null +@@ -1,240 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/destest.c */ +-/* +- * Copyright 1990,1991 by the Massachusetts Institute of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-/* Test a DES implementation against known inputs & outputs. */ +- +-#include "des_int.h" +-#include +-#include +- +-void convert (char *, unsigned char []); +- +-void des_cblock_print_file (mit_des_cblock, FILE *); +- +-krb5_octet zeroblock[8] = {0,0,0,0,0,0,0,0}; +- +-int +-main(argc, argv) +- int argc; +- char *argv[]; +-{ +- char block1[17], block2[17], block3[17]; +- /* Force tests of unaligned accesses. */ +- union { unsigned char c[8*4+3]; long l; } u; +- unsigned char *ioblocks = u.c; +- unsigned char *input = ioblocks+1; +- unsigned char *output = ioblocks+10; +- unsigned char *output2 = ioblocks+19; +- unsigned char *key = ioblocks+27; +- mit_des_key_schedule sched; +- int num = 0; +- int retval; +- +- int error = 0; +- +- while (scanf("%16s %16s %16s", block1, block2, block3) == 3) { +- convert(block1, key); +- convert(block2, input); +- convert(block3, output); +- +- retval = mit_des_key_sched(key, sched); +- if (retval) { +- fprintf(stderr, "des test: can't process key: %d\n", retval); +- fprintf(stderr, "des test: %s %s %s\n", block1, block2, block3); +- exit(1); +- } +- mit_des_cbc_encrypt((const mit_des_cblock *) input, +- (mit_des_cblock *) output2, 8, +- sched, zeroblock, 1); +- +- if (memcmp((char *)output2, (char *)output, 8)) { +- fprintf(stderr, +- "DES ENCRYPT ERROR, key %s, text %s, real cipher %s, computed cyphertext %02X%02X%02X%02X%02X%02X%02X%02X\n", +- block1, block2, block3, +- output2[0],output2[1],output2[2],output2[3], +- output2[4],output2[5],output2[6],output2[7]); +- error++; +- } +- +- /* +- * Now try decrypting.... +- */ +- mit_des_cbc_encrypt((const mit_des_cblock *) output, +- (mit_des_cblock *) output2, 8, +- sched, zeroblock, 0); +- +- if (memcmp((char *)output2, (char *)input, 8)) { +- fprintf(stderr, +- "DES DECRYPT ERROR, key %s, text %s, real cipher %s, computed cleartext %02X%02X%02X%02X%02X%02X%02X%02X\n", +- block1, block2, block3, +- output2[0],output2[1],output2[2],output2[3], +- output2[4],output2[5],output2[6],output2[7]); +- error++; +- } +- +- num++; +- } +- +- if (error) +- printf("destest: failed to pass the test\n"); +- else +- printf("destest: %d tests passed successfully\n", num); +- +- exit( (error > 256 && error % 256) ? 1 : error); +-} +- +-int value[128] = { +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- 0, 1, 2, 3, 4, 5, 6, 7, +- 8, 9, -1, -1, -1, -1, -1, -1, +- -1, 10, 11, 12, 13, 14, 15, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +- -1, -1, -1, -1, -1, -1, -1, -1, +-}; +- +-void +-convert(text, cblock) +- char *text; +- unsigned char cblock[]; +-{ +- int i; +- for (i = 0; i < 8; i++) { +- if (!isascii((unsigned char)text[i * 2])) +- abort (); +- if (value[(int) text[i*2]] == -1 || value[(int) text[i*2+1]] == -1) { +- printf("Bad value byte %d in %s\n", i, text); +- exit(1); +- } +- cblock[i] = 16*value[(int) text[i*2]] + value[(int) text[i*2+1]]; +- } +- return; +-} +- +-/* +- * Fake out the DES library, for the purposes of testing. +- */ +- +-int +-mit_des_is_weak_key(key) +- mit_des_cblock key; +-{ +- return 0; /* fake it out for testing */ +-} +- +-void +-des_cblock_print_file(x, fp) +- mit_des_cblock x; +- FILE *fp; +-{ +- unsigned char *y = (unsigned char *) x; +- int i = 0; +- fprintf(fp," 0x { "); +- +- while (i++ < 8) { +- fprintf(fp,"%x",*y++); +- if (i < 8) +- fprintf(fp,", "); +- } +- fprintf(fp," }"); +-} +- +- +-#define smask(step) ((1<>step)&smask(step))) +-#define parity_char(x) pstep(pstep(pstep((x),4),2),1) +- +-/* +- * des_check_key_parity: returns true iff key has the correct des parity. +- * See des_fix_key_parity for the definition of +- * correct des parity. +- */ +-int +-mit_des_check_key_parity(key) +- mit_des_cblock key; +-{ +- unsigned int i; +- +- for (i=0; i decrypt, else encrypt */ +- Key_schedule schedule; /* addr of key schedule */ +- +-This is the low level routine that encrypts or decrypts a single 8-byte +-block in electronic code book mode. Always transforms the input +-data into the output data. +- +-If encrypt is non-zero, the input (cleartext) is encrypted into the +-output (ciphertext) using the specified key_schedule, pre-set via "des_set_key". +- +-If encrypt is zero, the input (now ciphertext) is decrypted into +-the output (now cleartext). +- +-Input and output may be the same space. +- +-Does not return any meaningful value. Void is not used for compatibility +-with other compilers. +- +-/* -------------------------------------------------------------- */ +- +-int +- cbc_encrypt(input,output,length,schedule,ivec,encrypt) +- +- C_Block *input; /* ptr to input data */ +- C_Block *output; /* ptr to output data */ +- int length; /* desired length, in bytes */ +- Key_schedule schedule; /* addr of precomputed schedule */ +- C_Block *ivec; /* pointer to 8 byte initialization +- * vector +- */ +- int encrypt /* 0 ==> decrypt; else encrypt*/ +- +- +- If encrypt is non-zero, the routine cipher-block-chain encrypts +- the INPUT (cleartext) into the OUTPUT (ciphertext) using the provided +- key schedule and initialization vector. If the length is not an integral +- multiple of eight bytes, the last block is copied to a temp and zero +- filled (highest addresses). The output is ALWAYS an integral multiple +- of eight bytes. +- +- If encrypt is zero, the routine cipher-block chain decrypts the INPUT +- (ciphertext) into the OUTPUT (cleartext) using the provided key schedule +- and initialization vector. Decryption ALWAYS operates on integral +- multiples of 8 bytes, so will round the length provided up to the +- appropriate multiple. Consequently, it will always produce the rounded-up +- number of bytes of output cleartext. The application must determine if +- the output cleartext was zero-padded due to cleartext lengths not integral +- multiples of 8. +- +- No errors or meaningful value are returned. Void is not used for +- compatibility with other compilers. +- +- +-/* cbc checksum (MAC) only routine ---------------------------------------- */ +-int +- cbc_cksum(input,output,length,schedule,ivec) +- +- C_Block *input; /* >= length bytes of inputtext */ +- C_Block *output; /* >= length bytes of outputtext */ +- int length; /* in bytes */ +- Key_schedule schedule; /* precomputed key schedule */ +- C_Block *ivec; /* 8 bytes of ivec */ +- +- +- Produces a cryptographic checksum, 8 bytes, by cipher-block-chain +- encrypting the input, discarding the ciphertext output, and only retaining +- the last ciphertext 8-byte block. Uses the provided key schedule and ivec. +- The input is effectively zero-padded to an integral multiple of +- eight bytes, though the original input is not modified. +- +- No meaningful value is returned. Void is not used for compatibility +- with other compilers. +- +- +-/* random_key ----------------------------------------*/ +-int +- random_key(key) +- +- C_Block *key; +- +- The start for the random number generated is set from the current time +- in microseconds, then the random number generator is invoked +- to create an eight byte output key (not a schedule). The key +- generated is set to odd parity per FIPS spec. +- +- The caller must supply space for the output key, pointed to +- by "*key", then after getting a new key, call the des_set_key() +- routine when needed. +- +- No meaningfull value is returned. Void is not used for compatibility +- with other compilers. +- +- +-/* string_to_key --------------------------------------------*/ +- +-int +- string_to_key(str,key) +- char *str; +- C_Block *key; +- +- This routines converts an arbitrary length, null terminated string +- to an 8 byte DES key, with each byte parity set to odd, per FIPS spec. +- +- The algorithm is as follows: +- +-| Take the first 8 bytes and remove the parity (leaving 56 bits). +-| Do the same for the second 8 bytes, and the third, etc. Do this for +-| as many sets of 8 bytes as necessary, filling in the remainder of the +-| last set with nulls. Fold the second set back on the first (i.e. bit +-| 0 over bit 55, and bit 55 over bit 0). Fold the third over the second +-| (bit 0 of the third set is now over bit 0 of the first set). Repeat +-| until you have done this to all sets. Xor the folded sets. Break the +-| result into 8 7 bit bytes, and generate odd parity for each byte. You +-| now have 64 bits. Note that DES takes a 64 bit key, and uses only the +-| non parity bits. +- +- +-/* read_password -------------------------------------------*/ +- +-read_password(k,prompt,verify) +- C_Block *k; +- char *prompt; +- int verify; +- +-This routine issues the supplied prompt, turns off echo, if possible, and +-reads an input string. If verify is non-zero, it does it again, for use +-in applications such as changing a password. If verify is non-zero, both +-versions are compared, and the input is requested repeatedly until they +-match. Then, the input string is mapped into a valid DES key, internally +-using the string_to_key routine. The newly created key is copied to the +-area pointed to by parameter "k". +- +-No meaningful value is returned. If an error occurs trying to manipulate +-the terminal echo, the routine forces the process to exit. +- +-/* get_line ------------------------*/ +-long get_line(p,max) +- char *p; +- long max; +- +-Reads input characters from standard input until either a newline appears or +-else the max length is reached. The characters read are stuffed into +-the string pointed to, which will always be null terminated. The newline +-is not inserted in the string. The max parameter includes the byte needed +-for the null terminator, so allocate and pass one more than the maximum +-string length desired. +diff --git a/src/lib/crypto/builtin/des/f_aead.c b/src/lib/crypto/builtin/des/f_aead.c +deleted file mode 100644 +index 71b8dff4d..000000000 +--- a/src/lib/crypto/builtin/des/f_aead.c ++++ /dev/null +@@ -1,173 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * Copyright (C) 2008 by the Massachusetts Institute of Technology. +- * Copyright 1995 by Richard P. Basch. All Rights Reserved. +- * Copyright 1995 by Lehman Brothers, Inc. All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of Richard P. Basch, Lehman Brothers and M.I.T. not be used +- * in advertising or publicity pertaining to distribution of the software +- * without specific, written prior permission. Richard P. Basch, +- * Lehman Brothers and M.I.T. make no representations about the suitability +- * of this software for any purpose. It is provided "as is" without +- * express or implied warranty. +- */ +- +-#include "crypto_int.h" +-#include "des_int.h" +-#include "f_tables.h" +- +-const mit_des_cblock mit_des_zeroblock /* = all zero */; +- +-void +-krb5int_des_cbc_encrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule schedule, +- mit_des_cblock ivec) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp; +- const unsigned char *ip; +- struct iov_cursor cursor; +- unsigned char block[MIT_DES_BLOCK_LENGTH]; +- +- /* Get key pointer here. This won't need to be reinitialized. */ +- kp = (const unsigned DES_INT32 *)schedule; +- +- /* Initialize left and right with the contents of the initial vector. */ +- ip = (ivec != NULL) ? ivec : mit_des_zeroblock; +- left = load_32_be(ip); +- right = load_32_be(ip + 4); +- +- k5_iov_cursor_init(&cursor, data, num_data, MIT_DES_BLOCK_LENGTH, FALSE); +- while (k5_iov_cursor_get(&cursor, block)) { +- /* Decompose this block and xor it with the previous ciphertext. */ +- left ^= load_32_be(block); +- right ^= load_32_be(block + 4); +- +- /* Encrypt what we have and put back into block. */ +- DES_DO_ENCRYPT(left, right, kp); +- store_32_be(left, block); +- store_32_be(right, block + 4); +- +- k5_iov_cursor_put(&cursor, block); +- } +- +- if (ivec != NULL) { +- store_32_be(left, ivec); +- store_32_be(right, ivec + 4); +- } +-} +- +-void +-krb5int_des_cbc_decrypt(krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule schedule, +- mit_des_cblock ivec) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp; +- const unsigned char *ip; +- unsigned DES_INT32 ocipherl, ocipherr; +- unsigned DES_INT32 cipherl, cipherr; +- struct iov_cursor cursor; +- unsigned char block[MIT_DES_BLOCK_LENGTH]; +- +- /* Get key pointer here. This won't need to be reinitialized. */ +- kp = (const unsigned DES_INT32 *)schedule; +- +- /* +- * Decrypting is harder than encrypting because of +- * the necessity of remembering a lot more things. +- * Should think about this a little more... +- */ +- +- /* Prime the old cipher with ivec. */ +- ip = (ivec != NULL) ? ivec : mit_des_zeroblock; +- ocipherl = load_32_be(ip); +- ocipherr = load_32_be(ip + 4); +- +- k5_iov_cursor_init(&cursor, data, num_data, MIT_DES_BLOCK_LENGTH, FALSE); +- while (k5_iov_cursor_get(&cursor, block)) { +- /* Split this block into left and right. */ +- cipherl = left = load_32_be(block); +- cipherr = right = load_32_be(block + 4); +- +- /* Decrypt and xor with the old cipher to get plain text. */ +- DES_DO_DECRYPT(left, right, kp); +- left ^= ocipherl; +- right ^= ocipherr; +- +- /* Store the encrypted halves back into block. */ +- store_32_be(left, block); +- store_32_be(right, block + 4); +- +- /* Save current cipher block halves. */ +- ocipherl = cipherl; +- ocipherr = cipherr; +- +- k5_iov_cursor_put(&cursor, block); +- } +- +- if (ivec != NULL) { +- store_32_be(ocipherl, ivec); +- store_32_be(ocipherr, ivec + 4); +- } +-} +- +-void +-krb5int_des_cbc_mac(const krb5_crypto_iov *data, unsigned long num_data, +- const mit_des_key_schedule schedule, mit_des_cblock ivec, +- mit_des_cblock out) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp; +- const unsigned char *ip; +- struct iov_cursor cursor; +- unsigned char block[MIT_DES_BLOCK_LENGTH]; +- +- /* Get key pointer here. This won't need to be reinitialized. */ +- kp = (const unsigned DES_INT32 *)schedule; +- +- /* Initialize left and right with the contents of the initial vector. */ +- ip = (ivec != NULL) ? ivec : mit_des_zeroblock; +- left = load_32_be(ip); +- right = load_32_be(ip + 4); +- +- k5_iov_cursor_init(&cursor, data, num_data, MIT_DES_BLOCK_LENGTH, TRUE); +- while (k5_iov_cursor_get(&cursor, block)) { +- /* Decompose this block and xor it with the previous ciphertext. */ +- left ^= load_32_be(block); +- right ^= load_32_be(block + 4); +- +- /* Encrypt what we have. */ +- DES_DO_ENCRYPT(left, right, kp); +- } +- +- /* Output the final ciphertext block. */ +- store_32_be(left, out); +- store_32_be(right, out + 4); +-} +- +-#if defined(CONFIG_SMALL) && !defined(CONFIG_SMALL_NO_CRYPTO) +-void krb5int_des_do_encrypt_2 (unsigned DES_INT32 *left, +- unsigned DES_INT32 *right, +- const unsigned DES_INT32 *kp) +-{ +- DES_DO_ENCRYPT_1 (*left, *right, kp); +-} +- +-void krb5int_des_do_decrypt_2 (unsigned DES_INT32 *left, +- unsigned DES_INT32 *right, +- const unsigned DES_INT32 *kp) +-{ +- DES_DO_DECRYPT_1 (*left, *right, kp); +-} +-#endif +diff --git a/src/lib/crypto/builtin/des/f_cbc.c b/src/lib/crypto/builtin/des/f_cbc.c +deleted file mode 100644 +index 84d5382f2..000000000 +--- a/src/lib/crypto/builtin/des/f_cbc.c ++++ /dev/null +@@ -1,256 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/f_cbc.c */ +-/* +- * Copyright (C) 1990 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* +- * CBC functions; used only by the test programs at this time. (krb5 uses the +- * functions in f_aead.c instead.) +- */ +- +-/* +- * des_cbc_encrypt.c - an implementation of the DES cipher function in cbc mode +- */ +-#include "des_int.h" +-#include "f_tables.h" +- +-/* +- * des_cbc_encrypt - {en,de}crypt a stream in CBC mode +- */ +- +-/* +- * This routine performs DES cipher-block-chaining operation, either +- * encrypting from cleartext to ciphertext, if encrypt != 0 or +- * decrypting from ciphertext to cleartext, if encrypt == 0. +- * +- * The key schedule is passed as an arg, as well as the cleartext or +- * ciphertext. The cleartext and ciphertext should be in host order. +- * +- * NOTE-- the output is ALWAYS an multiple of 8 bytes long. If not +- * enough space was provided, your program will get trashed. +- * +- * For encryption, the cleartext string is null padded, at the end, to +- * an integral multiple of eight bytes. +- * +- * For decryption, the ciphertext will be used in integral multiples +- * of 8 bytes, but only the first "length" bytes returned into the +- * cleartext. +- */ +- +-const mit_des_cblock mit_des_zeroblock /* = all zero */; +- +-static void +-des_cbc_encrypt(const mit_des_cblock *in, mit_des_cblock *out, +- unsigned long length, const mit_des_key_schedule schedule, +- const mit_des_cblock ivec) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp; +- const unsigned char *ip; +- unsigned char *op; +- +- /* +- * Get key pointer here. This won't need to be reinitialized +- */ +- kp = (const unsigned DES_INT32 *)schedule; +- +- /* +- * Initialize left and right with the contents of the initial +- * vector. +- */ +- ip = ivec; +- GET_HALF_BLOCK(left, ip); +- GET_HALF_BLOCK(right, ip); +- +- /* +- * Suitably initialized, now work the length down 8 bytes +- * at a time. +- */ +- ip = *in; +- op = *out; +- while (length > 0) { +- /* +- * Get more input, xor it in. If the length is +- * greater than or equal to 8 this is straight +- * forward. Otherwise we have to fart around. +- */ +- if (length >= 8) { +- unsigned DES_INT32 temp; +- GET_HALF_BLOCK(temp, ip); +- left ^= temp; +- GET_HALF_BLOCK(temp, ip); +- right ^= temp; +- length -= 8; +- } else { +- /* +- * Oh, shoot. We need to pad the +- * end with zeroes. Work backwards +- * to do this. +- */ +- ip += (int) length; +- switch(length) { +- case 7: +- right ^= (*(--ip) & FF_UINT32) << 8; +- case 6: +- right ^= (*(--ip) & FF_UINT32) << 16; +- case 5: +- right ^= (*(--ip) & FF_UINT32) << 24; +- case 4: +- left ^= *(--ip) & FF_UINT32; +- case 3: +- left ^= (*(--ip) & FF_UINT32) << 8; +- case 2: +- left ^= (*(--ip) & FF_UINT32) << 16; +- case 1: +- left ^= (*(--ip) & FF_UINT32) << 24; +- break; +- } +- length = 0; +- } +- +- /* +- * Encrypt what we have +- */ +- DES_DO_ENCRYPT(left, right, kp); +- +- /* +- * Copy the results out +- */ +- PUT_HALF_BLOCK(left, op); +- PUT_HALF_BLOCK(right, op); +- } +-} +- +-static void +-des_cbc_decrypt(const mit_des_cblock *in, mit_des_cblock *out, +- unsigned long length, const mit_des_key_schedule schedule, +- const mit_des_cblock ivec) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp; +- const unsigned char *ip; +- unsigned char *op; +- unsigned DES_INT32 ocipherl, ocipherr; +- unsigned DES_INT32 cipherl, cipherr; +- +- /* +- * Get key pointer here. This won't need to be reinitialized +- */ +- kp = (const unsigned DES_INT32 *)schedule; +- +- /* +- * Decrypting is harder than encrypting because of +- * the necessity of remembering a lot more things. +- * Should think about this a little more... +- */ +- +- if (length <= 0) +- return; +- +- /* +- * Prime the old cipher with ivec. +- */ +- ip = ivec; +- GET_HALF_BLOCK(ocipherl, ip); +- GET_HALF_BLOCK(ocipherr, ip); +- +- /* +- * Now do this in earnest until we run out of length. +- */ +- ip = *in; +- op = *out; +- for (;;) { /* check done inside loop */ +- /* +- * Read a block from the input into left and +- * right. Save this cipher block for later. +- */ +- GET_HALF_BLOCK(left, ip); +- GET_HALF_BLOCK(right, ip); +- cipherl = left; +- cipherr = right; +- +- /* +- * Decrypt this. +- */ +- DES_DO_DECRYPT(left, right, kp); +- +- /* +- * Xor with the old cipher to get plain +- * text. Output 8 or less bytes of this. +- */ +- left ^= ocipherl; +- right ^= ocipherr; +- if (length > 8) { +- length -= 8; +- PUT_HALF_BLOCK(left, op); +- PUT_HALF_BLOCK(right, op); +- /* +- * Save current cipher block here +- */ +- ocipherl = cipherl; +- ocipherr = cipherr; +- } else { +- /* +- * Trouble here. Start at end of output, +- * work backwards. +- */ +- op += (int) length; +- switch(length) { +- case 8: +- *(--op) = (unsigned char) (right & 0xff); +- case 7: +- *(--op) = (unsigned char) ((right >> 8) & 0xff); +- case 6: +- *(--op) = (unsigned char) ((right >> 16) & 0xff); +- case 5: +- *(--op) = (unsigned char) ((right >> 24) & 0xff); +- case 4: +- *(--op) = (unsigned char) (left & 0xff); +- case 3: +- *(--op) = (unsigned char) ((left >> 8) & 0xff); +- case 2: +- *(--op) = (unsigned char) ((left >> 16) & 0xff); +- case 1: +- *(--op) = (unsigned char) ((left >> 24) & 0xff); +- break; +- } +- break; /* we're done */ +- } +- } +-} +- +-int +-mit_des_cbc_encrypt(const mit_des_cblock *in, mit_des_cblock *out, +- unsigned long length, const mit_des_key_schedule schedule, +- const mit_des_cblock ivec, int enc) +-{ +- /* +- * Deal with encryption and decryption separately. +- */ +- if (enc) +- des_cbc_encrypt(in, out, length, schedule, ivec); +- else +- des_cbc_decrypt(in, out, length, schedule, ivec); +- return 0; +-} +diff --git a/src/lib/crypto/builtin/des/f_cksum.c b/src/lib/crypto/builtin/des/f_cksum.c +deleted file mode 100644 +index cb482b009..000000000 +--- a/src/lib/crypto/builtin/des/f_cksum.c ++++ /dev/null +@@ -1,136 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/f_cksum.c */ +-/* +- * Copyright (C) 1990 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* DES implementation donated by Dennis Ferguson */ +- +-/* +- * des_cbc_cksum.c - compute an 8 byte checksum using DES in CBC mode +- */ +-#include "des_int.h" +-#include "f_tables.h" +- +-/* +- * This routine performs DES cipher-block-chaining checksum operation, +- * a.k.a. Message Authentication Code. It ALWAYS encrypts from input +- * to a single 64 bit output MAC checksum. +- * +- * The key schedule is passed as an arg, as well as the cleartext or +- * ciphertext. The cleartext and ciphertext should be in host order. +- * +- * NOTE-- the output is ALWAYS 8 bytes long. If not enough space was +- * provided, your program will get trashed. +- * +- * The input is null padded, at the end (highest addr), to an integral +- * multiple of eight bytes. +- */ +- +-unsigned long +-mit_des_cbc_cksum(const krb5_octet *in, krb5_octet *out, +- unsigned long length, const mit_des_key_schedule schedule, +- const krb5_octet *ivec) +-{ +- unsigned DES_INT32 left, right; +- const unsigned DES_INT32 *kp; +- const unsigned char *ip; +- unsigned char *op; +- DES_INT32 len; +- +- /* +- * Initialize left and right with the contents of the initial +- * vector. +- */ +- ip = ivec; +- GET_HALF_BLOCK(left, ip); +- GET_HALF_BLOCK(right, ip); +- +- /* +- * Suitably initialized, now work the length down 8 bytes +- * at a time. +- */ +- ip = in; +- len = length; +- while (len > 0) { +- /* +- * Get more input, xor it in. If the length is +- * greater than or equal to 8 this is straight +- * forward. Otherwise we have to fart around. +- */ +- if (len >= 8) { +- unsigned DES_INT32 temp; +- GET_HALF_BLOCK(temp, ip); +- left ^= temp; +- GET_HALF_BLOCK(temp, ip); +- right ^= temp; +- len -= 8; +- } else { +- /* +- * Oh, shoot. We need to pad the +- * end with zeroes. Work backwards +- * to do this. +- */ +- ip += (int) len; +- switch(len) { +- case 7: +- right ^= (*(--ip) & FF_UINT32) << 8; +- case 6: +- right ^= (*(--ip) & FF_UINT32) << 16; +- case 5: +- right ^= (*(--ip) & FF_UINT32) << 24; +- case 4: +- left ^= *(--ip) & FF_UINT32; +- case 3: +- left ^= (*(--ip) & FF_UINT32) << 8; +- case 2: +- left ^= (*(--ip) & FF_UINT32) << 16; +- case 1: +- left ^= (*(--ip) & FF_UINT32) << 24; +- break; +- } +- len = 0; +- } +- +- /* +- * Encrypt what we have +- */ +- kp = (const unsigned DES_INT32 *)schedule; +- DES_DO_ENCRYPT(left, right, kp); +- } +- +- /* +- * Done. Left and right have the checksum. Put it into +- * the output. +- */ +- op = out; +- PUT_HALF_BLOCK(left, op); +- PUT_HALF_BLOCK(right, op); +- +- /* +- * Return right. I'll bet the MIT code returns this +- * inconsistantly (with the low order byte of the checksum +- * not always in the low order byte of the DES_INT32). We won't. +- */ +- return right & 0xFFFFFFFFUL; +-} +diff --git a/src/lib/crypto/builtin/des/f_parity.c b/src/lib/crypto/builtin/des/f_parity.c +deleted file mode 100644 +index 460b5061b..000000000 +--- a/src/lib/crypto/builtin/des/f_parity.c ++++ /dev/null +@@ -1,56 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * These routines check and fix parity of encryption keys for the DES +- * algorithm. +- * +- * They are a replacement for routines in key_parity.c, that don't require +- * the table building that they do. +- * +- * Mark Eichin -- Cygnus Support +- */ +- +- +-#include "des_int.h" +- +-/* +- * des_fixup_key_parity: Forces odd parity per byte; parity is bits +- * 8,16,...64 in des order, implies 0, 8, 16, ... +- * vax order. +- */ +-#define smask(step) ((1<>step)&smask(step))) +-#define parity_char(x) pstep(pstep(pstep((x),4),2),1) +- +-void +-mit_des_fixup_key_parity(mit_des_cblock key) +-{ +- unsigned int i; +- for (i=0; i> 29) & 0x7] +- | (PC1_CL[(tmp >> 21) & 0x7] << 1) +- | (PC1_CL[(tmp >> 13) & 0x7] << 2) +- | (PC1_CL[(tmp >> 5) & 0x7] << 3); +- d = PC1_DL[(tmp >> 25) & 0xf] +- | (PC1_DL[(tmp >> 17) & 0xf] << 1) +- | (PC1_DL[(tmp >> 9) & 0xf] << 2) +- | (PC1_DL[(tmp >> 1) & 0xf] << 3); +- +- tmp = load_32_be(k), k += 4; +- +- c |= PC1_CR[(tmp >> 28) & 0xf] +- | (PC1_CR[(tmp >> 20) & 0xf] << 1) +- | (PC1_CR[(tmp >> 12) & 0xf] << 2) +- | (PC1_CR[(tmp >> 4) & 0xf] << 3); +- d |= PC1_DR[(tmp >> 25) & 0x7] +- | (PC1_DR[(tmp >> 17) & 0x7] << 1) +- | (PC1_DR[(tmp >> 9) & 0x7] << 2) +- | (PC1_DR[(tmp >> 1) & 0x7] << 3); +- } +- +- { +- /* +- * Need several temporaries in here +- */ +- unsigned DES_INT32 ltmp, rtmp; +- unsigned DES_INT32 *k; +- int two_bit_shifts; +- int i; +- /* +- * Now iterate to compute the key schedule. Note that we +- * record the entire set of subkeys in 6 bit chunks since +- * they are used that way. At 6 bits/char, we need +- * 48/6 char's/subkey * 16 subkeys/encryption == 128 bytes. +- * The schedule must be this big. +- */ +- k = (unsigned DES_INT32 *)schedule; +- two_bit_shifts = TWO_BIT_SHIFTS; +- for (i = 16; i > 0; i--) { +- /* +- * Do the rotation. One bit and two bit rotations +- * are done separately. Note C and D are 28 bits. +- */ +- if (two_bit_shifts & 0x1) { +- c = ((c << 2) & 0xffffffc) | (c >> 26); +- d = ((d << 2) & 0xffffffc) | (d >> 26); +- } else { +- c = ((c << 1) & 0xffffffe) | (c >> 27); +- d = ((d << 1) & 0xffffffe) | (d >> 27); +- } +- two_bit_shifts >>= 1; +- +- /* +- * Apply permutted choice 2 to C to get the first +- * 24 bits worth of keys. Note that bits 9, 18, 22 +- * and 25 (using DES numbering) in C are unused. The +- * shift-mask stuff is done to delete these bits from +- * the indices, since this cuts the table size in half. +- * +- * The table is torqued, by the way. If the standard +- * byte order for this (high to low order) is 1234, +- * the table actually gives us 4132. +- */ +- ltmp = PC2_C[0][((c >> 22) & 0x3f)] +- | PC2_C[1][((c >> 15) & 0xf) | ((c >> 16) & 0x30)] +- | PC2_C[2][((c >> 4) & 0x3) | ((c >> 9) & 0x3c)] +- | PC2_C[3][((c ) & 0x7) | ((c >> 4) & 0x38)]; +- /* +- * Apply permutted choice 2 to D to get the other half. +- * Here, bits 7, 10, 15 and 26 go unused. The sqeezing +- * actually turns out to be cheaper here. +- * +- * This table is similarly torqued. If the standard +- * byte order is 5678, the table has the bytes permuted +- * to give us 7685. +- */ +- rtmp = PC2_D[0][((d >> 22) & 0x3f)] +- | PC2_D[1][((d >> 14) & 0xf) | ((d >> 15) & 0x30)] +- | PC2_D[2][((d >> 7) & 0x3f)] +- | PC2_D[3][((d ) & 0x3) | ((d >> 1) & 0x3c)]; +- +- /* +- * Make up two words of the key schedule, with a +- * byte order which is convenient for the DES +- * inner loop. The high order (first) word will +- * hold bytes 7135 (high to low order) while the +- * second holds bytes 4682. +- */ +- *k++ = (ltmp & 0x00ffff00) | (rtmp & 0xff0000ff); +- *k++ = (ltmp & 0xff0000ff) | (rtmp & 0x00ffff00); +- } +- } +- return (0); +-} +diff --git a/src/lib/crypto/builtin/des/f_tables.c b/src/lib/crypto/builtin/des/f_tables.c +deleted file mode 100644 +index 6308cb0d5..000000000 +--- a/src/lib/crypto/builtin/des/f_tables.c ++++ /dev/null +@@ -1,370 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/f_tables.c */ +-/* +- * Copyright (C) 1990 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* DES implementation donated by Dennis Ferguson */ +- +-/* +- * des_tables.c - precomputed tables used for the DES cipher function +- */ +- +-/* +- * Include the header file so something will complain if the +- * declarations get out of sync +- */ +-#include "des_int.h" +-#include "f_tables.h" +- +-/* +- * These tables may be declared const if you want. Many compilers +- * don't support this, though. +- */ +- +-/* +- * The DES algorithm which uses these is intended to be fairly speedy +- * at the expense of some memory. All the standard hacks are used. +- * The S boxes and the P permutation are precomputed into one table. +- * The E box never actually appears explicitly since it is easy to apply +- * this algorithmically as needed. The initial permutation and final +- * (inverse initial) permutation are computed from tables designed to +- * permute one byte at a time. This should run pretty fast on machines +- * with 32 bit words and bit field/multiple bit shift instructions which +- * are fast. +- */ +- +-/* +- * The initial permutation array. This is used to compute both the +- * left and the right halves of the initial permutation using bytes +- * from words made from the following operations: +- * +- * ((left & 0x55555555) << 1) | (right & 0x55555555) for left half +- * (left & 0xaaaaaaaa) | ((right & 0xaaaaaaaa) >> 1) for right half +- * +- * The scheme is that we index into the table using each byte. The +- * result from the high order byte is or'd with the result from the +- * next byte shifted left once is or'd with the result from the next +- * byte shifted left twice if or'd with the result from the low order +- * byte shifted left by three. Clear? +- */ +- +-const unsigned DES_INT32 des_IP_table[256] = { +- 0x00000000, 0x00000010, 0x00000001, 0x00000011, +- 0x00001000, 0x00001010, 0x00001001, 0x00001011, +- 0x00000100, 0x00000110, 0x00000101, 0x00000111, +- 0x00001100, 0x00001110, 0x00001101, 0x00001111, +- 0x00100000, 0x00100010, 0x00100001, 0x00100011, +- 0x00101000, 0x00101010, 0x00101001, 0x00101011, +- 0x00100100, 0x00100110, 0x00100101, 0x00100111, +- 0x00101100, 0x00101110, 0x00101101, 0x00101111, +- 0x00010000, 0x00010010, 0x00010001, 0x00010011, +- 0x00011000, 0x00011010, 0x00011001, 0x00011011, +- 0x00010100, 0x00010110, 0x00010101, 0x00010111, +- 0x00011100, 0x00011110, 0x00011101, 0x00011111, +- 0x00110000, 0x00110010, 0x00110001, 0x00110011, +- 0x00111000, 0x00111010, 0x00111001, 0x00111011, +- 0x00110100, 0x00110110, 0x00110101, 0x00110111, +- 0x00111100, 0x00111110, 0x00111101, 0x00111111, +- 0x10000000, 0x10000010, 0x10000001, 0x10000011, +- 0x10001000, 0x10001010, 0x10001001, 0x10001011, +- 0x10000100, 0x10000110, 0x10000101, 0x10000111, +- 0x10001100, 0x10001110, 0x10001101, 0x10001111, +- 0x10100000, 0x10100010, 0x10100001, 0x10100011, +- 0x10101000, 0x10101010, 0x10101001, 0x10101011, +- 0x10100100, 0x10100110, 0x10100101, 0x10100111, +- 0x10101100, 0x10101110, 0x10101101, 0x10101111, +- 0x10010000, 0x10010010, 0x10010001, 0x10010011, +- 0x10011000, 0x10011010, 0x10011001, 0x10011011, +- 0x10010100, 0x10010110, 0x10010101, 0x10010111, +- 0x10011100, 0x10011110, 0x10011101, 0x10011111, +- 0x10110000, 0x10110010, 0x10110001, 0x10110011, +- 0x10111000, 0x10111010, 0x10111001, 0x10111011, +- 0x10110100, 0x10110110, 0x10110101, 0x10110111, +- 0x10111100, 0x10111110, 0x10111101, 0x10111111, +- 0x01000000, 0x01000010, 0x01000001, 0x01000011, +- 0x01001000, 0x01001010, 0x01001001, 0x01001011, +- 0x01000100, 0x01000110, 0x01000101, 0x01000111, +- 0x01001100, 0x01001110, 0x01001101, 0x01001111, +- 0x01100000, 0x01100010, 0x01100001, 0x01100011, +- 0x01101000, 0x01101010, 0x01101001, 0x01101011, +- 0x01100100, 0x01100110, 0x01100101, 0x01100111, +- 0x01101100, 0x01101110, 0x01101101, 0x01101111, +- 0x01010000, 0x01010010, 0x01010001, 0x01010011, +- 0x01011000, 0x01011010, 0x01011001, 0x01011011, +- 0x01010100, 0x01010110, 0x01010101, 0x01010111, +- 0x01011100, 0x01011110, 0x01011101, 0x01011111, +- 0x01110000, 0x01110010, 0x01110001, 0x01110011, +- 0x01111000, 0x01111010, 0x01111001, 0x01111011, +- 0x01110100, 0x01110110, 0x01110101, 0x01110111, +- 0x01111100, 0x01111110, 0x01111101, 0x01111111, +- 0x11000000, 0x11000010, 0x11000001, 0x11000011, +- 0x11001000, 0x11001010, 0x11001001, 0x11001011, +- 0x11000100, 0x11000110, 0x11000101, 0x11000111, +- 0x11001100, 0x11001110, 0x11001101, 0x11001111, +- 0x11100000, 0x11100010, 0x11100001, 0x11100011, +- 0x11101000, 0x11101010, 0x11101001, 0x11101011, +- 0x11100100, 0x11100110, 0x11100101, 0x11100111, +- 0x11101100, 0x11101110, 0x11101101, 0x11101111, +- 0x11010000, 0x11010010, 0x11010001, 0x11010011, +- 0x11011000, 0x11011010, 0x11011001, 0x11011011, +- 0x11010100, 0x11010110, 0x11010101, 0x11010111, +- 0x11011100, 0x11011110, 0x11011101, 0x11011111, +- 0x11110000, 0x11110010, 0x11110001, 0x11110011, +- 0x11111000, 0x11111010, 0x11111001, 0x11111011, +- 0x11110100, 0x11110110, 0x11110101, 0x11110111, +- 0x11111100, 0x11111110, 0x11111101, 0x11111111 +-}; +- +-/* +- * The final permutation array. Like the IP array, used +- * to compute both the left and right results from the bytes +- * of words computed from: +- * +- * ((left & 0x0f0f0f0f) << 4) | (right & 0x0f0f0f0f) for left result +- * (left & 0xf0f0f0f0) | ((right & 0xf0f0f0f0) >> 4) for right result +- * +- * The result from the high order byte is shifted left 6 bits and +- * or'd with the result from the next byte shifted left 4 bits, which +- * is or'd with the result from the next byte shifted left 2 bits, +- * which is or'd with the result from the low byte. +- */ +-const unsigned DES_INT32 des_FP_table[256] = { +- 0x00000000, 0x02000000, 0x00020000, 0x02020000, +- 0x00000200, 0x02000200, 0x00020200, 0x02020200, +- 0x00000002, 0x02000002, 0x00020002, 0x02020002, +- 0x00000202, 0x02000202, 0x00020202, 0x02020202, +- 0x01000000, 0x03000000, 0x01020000, 0x03020000, +- 0x01000200, 0x03000200, 0x01020200, 0x03020200, +- 0x01000002, 0x03000002, 0x01020002, 0x03020002, +- 0x01000202, 0x03000202, 0x01020202, 0x03020202, +- 0x00010000, 0x02010000, 0x00030000, 0x02030000, +- 0x00010200, 0x02010200, 0x00030200, 0x02030200, +- 0x00010002, 0x02010002, 0x00030002, 0x02030002, +- 0x00010202, 0x02010202, 0x00030202, 0x02030202, +- 0x01010000, 0x03010000, 0x01030000, 0x03030000, +- 0x01010200, 0x03010200, 0x01030200, 0x03030200, +- 0x01010002, 0x03010002, 0x01030002, 0x03030002, +- 0x01010202, 0x03010202, 0x01030202, 0x03030202, +- 0x00000100, 0x02000100, 0x00020100, 0x02020100, +- 0x00000300, 0x02000300, 0x00020300, 0x02020300, +- 0x00000102, 0x02000102, 0x00020102, 0x02020102, +- 0x00000302, 0x02000302, 0x00020302, 0x02020302, +- 0x01000100, 0x03000100, 0x01020100, 0x03020100, +- 0x01000300, 0x03000300, 0x01020300, 0x03020300, +- 0x01000102, 0x03000102, 0x01020102, 0x03020102, +- 0x01000302, 0x03000302, 0x01020302, 0x03020302, +- 0x00010100, 0x02010100, 0x00030100, 0x02030100, +- 0x00010300, 0x02010300, 0x00030300, 0x02030300, +- 0x00010102, 0x02010102, 0x00030102, 0x02030102, +- 0x00010302, 0x02010302, 0x00030302, 0x02030302, +- 0x01010100, 0x03010100, 0x01030100, 0x03030100, +- 0x01010300, 0x03010300, 0x01030300, 0x03030300, +- 0x01010102, 0x03010102, 0x01030102, 0x03030102, +- 0x01010302, 0x03010302, 0x01030302, 0x03030302, +- 0x00000001, 0x02000001, 0x00020001, 0x02020001, +- 0x00000201, 0x02000201, 0x00020201, 0x02020201, +- 0x00000003, 0x02000003, 0x00020003, 0x02020003, +- 0x00000203, 0x02000203, 0x00020203, 0x02020203, +- 0x01000001, 0x03000001, 0x01020001, 0x03020001, +- 0x01000201, 0x03000201, 0x01020201, 0x03020201, +- 0x01000003, 0x03000003, 0x01020003, 0x03020003, +- 0x01000203, 0x03000203, 0x01020203, 0x03020203, +- 0x00010001, 0x02010001, 0x00030001, 0x02030001, +- 0x00010201, 0x02010201, 0x00030201, 0x02030201, +- 0x00010003, 0x02010003, 0x00030003, 0x02030003, +- 0x00010203, 0x02010203, 0x00030203, 0x02030203, +- 0x01010001, 0x03010001, 0x01030001, 0x03030001, +- 0x01010201, 0x03010201, 0x01030201, 0x03030201, +- 0x01010003, 0x03010003, 0x01030003, 0x03030003, +- 0x01010203, 0x03010203, 0x01030203, 0x03030203, +- 0x00000101, 0x02000101, 0x00020101, 0x02020101, +- 0x00000301, 0x02000301, 0x00020301, 0x02020301, +- 0x00000103, 0x02000103, 0x00020103, 0x02020103, +- 0x00000303, 0x02000303, 0x00020303, 0x02020303, +- 0x01000101, 0x03000101, 0x01020101, 0x03020101, +- 0x01000301, 0x03000301, 0x01020301, 0x03020301, +- 0x01000103, 0x03000103, 0x01020103, 0x03020103, +- 0x01000303, 0x03000303, 0x01020303, 0x03020303, +- 0x00010101, 0x02010101, 0x00030101, 0x02030101, +- 0x00010301, 0x02010301, 0x00030301, 0x02030301, +- 0x00010103, 0x02010103, 0x00030103, 0x02030103, +- 0x00010303, 0x02010303, 0x00030303, 0x02030303, +- 0x01010101, 0x03010101, 0x01030101, 0x03030101, +- 0x01010301, 0x03010301, 0x01030301, 0x03030301, +- 0x01010103, 0x03010103, 0x01030103, 0x03030103, +- 0x01010303, 0x03010303, 0x01030303, 0x03030303 +-}; +- +- +-/* +- * The SP table is actually the S boxes and the P permutation +- * table combined. This table is actually reordered from the +- * spec, to match the order of key application we follow. +- */ +-const unsigned DES_INT32 des_SP_table[8][64] = { +- { +- 0x00100000, 0x02100001, 0x02000401, 0x00000000, /* 7 */ +- 0x00000400, 0x02000401, 0x00100401, 0x02100400, +- 0x02100401, 0x00100000, 0x00000000, 0x02000001, +- 0x00000001, 0x02000000, 0x02100001, 0x00000401, +- 0x02000400, 0x00100401, 0x00100001, 0x02000400, +- 0x02000001, 0x02100000, 0x02100400, 0x00100001, +- 0x02100000, 0x00000400, 0x00000401, 0x02100401, +- 0x00100400, 0x00000001, 0x02000000, 0x00100400, +- 0x02000000, 0x00100400, 0x00100000, 0x02000401, +- 0x02000401, 0x02100001, 0x02100001, 0x00000001, +- 0x00100001, 0x02000000, 0x02000400, 0x00100000, +- 0x02100400, 0x00000401, 0x00100401, 0x02100400, +- 0x00000401, 0x02000001, 0x02100401, 0x02100000, +- 0x00100400, 0x00000000, 0x00000001, 0x02100401, +- 0x00000000, 0x00100401, 0x02100000, 0x00000400, +- 0x02000001, 0x02000400, 0x00000400, 0x00100001, +- }, +- { +- 0x00808200, 0x00000000, 0x00008000, 0x00808202, /* 1 */ +- 0x00808002, 0x00008202, 0x00000002, 0x00008000, +- 0x00000200, 0x00808200, 0x00808202, 0x00000200, +- 0x00800202, 0x00808002, 0x00800000, 0x00000002, +- 0x00000202, 0x00800200, 0x00800200, 0x00008200, +- 0x00008200, 0x00808000, 0x00808000, 0x00800202, +- 0x00008002, 0x00800002, 0x00800002, 0x00008002, +- 0x00000000, 0x00000202, 0x00008202, 0x00800000, +- 0x00008000, 0x00808202, 0x00000002, 0x00808000, +- 0x00808200, 0x00800000, 0x00800000, 0x00000200, +- 0x00808002, 0x00008000, 0x00008200, 0x00800002, +- 0x00000200, 0x00000002, 0x00800202, 0x00008202, +- 0x00808202, 0x00008002, 0x00808000, 0x00800202, +- 0x00800002, 0x00000202, 0x00008202, 0x00808200, +- 0x00000202, 0x00800200, 0x00800200, 0x00000000, +- 0x00008002, 0x00008200, 0x00000000, 0x00808002, +- }, +- { +- 0x00000104, 0x04010100, 0x00000000, 0x04010004, /* 3 */ +- 0x04000100, 0x00000000, 0x00010104, 0x04000100, +- 0x00010004, 0x04000004, 0x04000004, 0x00010000, +- 0x04010104, 0x00010004, 0x04010000, 0x00000104, +- 0x04000000, 0x00000004, 0x04010100, 0x00000100, +- 0x00010100, 0x04010000, 0x04010004, 0x00010104, +- 0x04000104, 0x00010100, 0x00010000, 0x04000104, +- 0x00000004, 0x04010104, 0x00000100, 0x04000000, +- 0x04010100, 0x04000000, 0x00010004, 0x00000104, +- 0x00010000, 0x04010100, 0x04000100, 0x00000000, +- 0x00000100, 0x00010004, 0x04010104, 0x04000100, +- 0x04000004, 0x00000100, 0x00000000, 0x04010004, +- 0x04000104, 0x00010000, 0x04000000, 0x04010104, +- 0x00000004, 0x00010104, 0x00010100, 0x04000004, +- 0x04010000, 0x04000104, 0x00000104, 0x04010000, +- 0x00010104, 0x00000004, 0x04010004, 0x00010100, +- }, +- { +- 0x00000080, 0x01040080, 0x01040000, 0x21000080, /* 5 */ +- 0x00040000, 0x00000080, 0x20000000, 0x01040000, +- 0x20040080, 0x00040000, 0x01000080, 0x20040080, +- 0x21000080, 0x21040000, 0x00040080, 0x20000000, +- 0x01000000, 0x20040000, 0x20040000, 0x00000000, +- 0x20000080, 0x21040080, 0x21040080, 0x01000080, +- 0x21040000, 0x20000080, 0x00000000, 0x21000000, +- 0x01040080, 0x01000000, 0x21000000, 0x00040080, +- 0x00040000, 0x21000080, 0x00000080, 0x01000000, +- 0x20000000, 0x01040000, 0x21000080, 0x20040080, +- 0x01000080, 0x20000000, 0x21040000, 0x01040080, +- 0x20040080, 0x00000080, 0x01000000, 0x21040000, +- 0x21040080, 0x00040080, 0x21000000, 0x21040080, +- 0x01040000, 0x00000000, 0x20040000, 0x21000000, +- 0x00040080, 0x01000080, 0x20000080, 0x00040000, +- 0x00000000, 0x20040000, 0x01040080, 0x20000080, +- }, +- { +- 0x80401000, 0x80001040, 0x80001040, 0x00000040, /* 4 */ +- 0x00401040, 0x80400040, 0x80400000, 0x80001000, +- 0x00000000, 0x00401000, 0x00401000, 0x80401040, +- 0x80000040, 0x00000000, 0x00400040, 0x80400000, +- 0x80000000, 0x00001000, 0x00400000, 0x80401000, +- 0x00000040, 0x00400000, 0x80001000, 0x00001040, +- 0x80400040, 0x80000000, 0x00001040, 0x00400040, +- 0x00001000, 0x00401040, 0x80401040, 0x80000040, +- 0x00400040, 0x80400000, 0x00401000, 0x80401040, +- 0x80000040, 0x00000000, 0x00000000, 0x00401000, +- 0x00001040, 0x00400040, 0x80400040, 0x80000000, +- 0x80401000, 0x80001040, 0x80001040, 0x00000040, +- 0x80401040, 0x80000040, 0x80000000, 0x00001000, +- 0x80400000, 0x80001000, 0x00401040, 0x80400040, +- 0x80001000, 0x00001040, 0x00400000, 0x80401000, +- 0x00000040, 0x00400000, 0x00001000, 0x00401040, +- }, +- { +- 0x10000008, 0x10200000, 0x00002000, 0x10202008, /* 6 */ +- 0x10200000, 0x00000008, 0x10202008, 0x00200000, +- 0x10002000, 0x00202008, 0x00200000, 0x10000008, +- 0x00200008, 0x10002000, 0x10000000, 0x00002008, +- 0x00000000, 0x00200008, 0x10002008, 0x00002000, +- 0x00202000, 0x10002008, 0x00000008, 0x10200008, +- 0x10200008, 0x00000000, 0x00202008, 0x10202000, +- 0x00002008, 0x00202000, 0x10202000, 0x10000000, +- 0x10002000, 0x00000008, 0x10200008, 0x00202000, +- 0x10202008, 0x00200000, 0x00002008, 0x10000008, +- 0x00200000, 0x10002000, 0x10000000, 0x00002008, +- 0x10000008, 0x10202008, 0x00202000, 0x10200000, +- 0x00202008, 0x10202000, 0x00000000, 0x10200008, +- 0x00000008, 0x00002000, 0x10200000, 0x00202008, +- 0x00002000, 0x00200008, 0x10002008, 0x00000000, +- 0x10202000, 0x10000000, 0x00200008, 0x10002008, +- }, +- { +- 0x08000820, 0x00000800, 0x00020000, 0x08020820, /* 8 */ +- 0x08000000, 0x08000820, 0x00000020, 0x08000000, +- 0x00020020, 0x08020000, 0x08020820, 0x00020800, +- 0x08020800, 0x00020820, 0x00000800, 0x00000020, +- 0x08020000, 0x08000020, 0x08000800, 0x00000820, +- 0x00020800, 0x00020020, 0x08020020, 0x08020800, +- 0x00000820, 0x00000000, 0x00000000, 0x08020020, +- 0x08000020, 0x08000800, 0x00020820, 0x00020000, +- 0x00020820, 0x00020000, 0x08020800, 0x00000800, +- 0x00000020, 0x08020020, 0x00000800, 0x00020820, +- 0x08000800, 0x00000020, 0x08000020, 0x08020000, +- 0x08020020, 0x08000000, 0x00020000, 0x08000820, +- 0x00000000, 0x08020820, 0x00020020, 0x08000020, +- 0x08020000, 0x08000800, 0x08000820, 0x00000000, +- 0x08020820, 0x00020800, 0x00020800, 0x00000820, +- 0x00000820, 0x00020020, 0x08000000, 0x08020800, +- }, +- { +- 0x40084010, 0x40004000, 0x00004000, 0x00084010, /* 2 */ +- 0x00080000, 0x00000010, 0x40080010, 0x40004010, +- 0x40000010, 0x40084010, 0x40084000, 0x40000000, +- 0x40004000, 0x00080000, 0x00000010, 0x40080010, +- 0x00084000, 0x00080010, 0x40004010, 0x00000000, +- 0x40000000, 0x00004000, 0x00084010, 0x40080000, +- 0x00080010, 0x40000010, 0x00000000, 0x00084000, +- 0x00004010, 0x40084000, 0x40080000, 0x00004010, +- 0x00000000, 0x00084010, 0x40080010, 0x00080000, +- 0x40004010, 0x40080000, 0x40084000, 0x00004000, +- 0x40080000, 0x40004000, 0x00000010, 0x40084010, +- 0x00084010, 0x00000010, 0x00004000, 0x40000000, +- 0x00004010, 0x40084000, 0x00080000, 0x40000010, +- 0x00080010, 0x40004010, 0x40000010, 0x00080010, +- 0x00084000, 0x00000000, 0x40004000, 0x00004010, +- 0x40000000, 0x40080010, 0x40084010, 0x00084000 +- }, +-}; +diff --git a/src/lib/crypto/builtin/des/f_tables.h b/src/lib/crypto/builtin/des/f_tables.h +deleted file mode 100644 +index fc91b566c..000000000 +--- a/src/lib/crypto/builtin/des/f_tables.h ++++ /dev/null +@@ -1,285 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/f_tables.h */ +-/* +- * Copyright (C) 1990 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* +- * DES implementation donated by Dennis Ferguson +- */ +- +-/* +- * des_tables.h - declarations to import the DES tables, used internally +- * by some of the library routines. +- */ +-#ifndef __DES_TABLES_H__ +-#define __DES_TABLES_H__ /* nothing */ +- +-#include "k5-platform.h" +-/* +- * These may be declared const if you wish. Be sure to change the +- * declarations in des_tables.c as well. +- */ +-extern const unsigned DES_INT32 des_IP_table[256]; +-extern const unsigned DES_INT32 des_FP_table[256]; +-extern const unsigned DES_INT32 des_SP_table[8][64]; +- +-/* +- * Use standard shortforms to reference these to save typing +- */ +-#define IP des_IP_table +-#define FP des_FP_table +-#define SP des_SP_table +- +-#ifdef DEBUG +-#define DEB(foofraw) printf foofraw +-#else +-#define DEB(foofraw) /* nothing */ +-#endif +- +-/* +- * Code to do a DES round using the tables. Note that the E expansion +- * is easy to compute algorithmically, especially if done out-of-order. +- * Take a look at its form and compare it to everything involving temp +- * below. Since SP[0-7] don't have any bits in common set it is okay +- * to do the successive xor's. +- * +- * Note too that the SP table has been reordered to match the order of +- * the keys (if the original order of SP was 12345678, the reordered +- * table is 71354682). This is unnecessary, but was done since some +- * compilers seem to like you going through the matrix from beginning +- * to end. +- * +- * There is a difference in the best way to do this depending on whether +- * one is encrypting or decrypting. If encrypting we move forward through +- * the keys and hence should move forward through the table. If decrypting +- * we go back. Part of the need for this comes from trying to emulate +- * existing software which generates a single key schedule and uses it +- * both for encrypting and decrypting. Generating separate encryption +- * and decryption key schedules would allow one to use the same code +- * for both. +- * +- * left, right and temp should be unsigned DES_INT32 values. left and right +- * should be the high and low order parts of the cipher block at the +- * current stage of processing (this makes sense if you read the spec). +- * kp should be an unsigned DES_INT32 pointer which points at the current +- * set of subkeys in the key schedule. It is advanced to the next set +- * (i.e. by 8 bytes) when this is done. +- * +- * This occurs in the innermost loop of the DES function. The four +- * variables should really be in registers. +- * +- * When using this, the inner loop of the DES function might look like: +- * +- * for (i = 0; i < 8; i++) { +- * DES_SP_{EN,DE}CRYPT_ROUND(left, right, temp, kp); +- * DES_SP_{EN,DE}CRYPT_ROUND(right, left, temp, kp); +- * } +- * +- * Note the trick above. You are supposed to do 16 rounds, swapping +- * left and right at the end of each round. By doing two rounds at +- * a time and swapping left and right in the code we can avoid the +- * swaps altogether. +- */ +-#define DES_SP_ENCRYPT_ROUND(left, right, temp, kp) do { \ +- (temp) = (((right) >> 11) | ((right) << 21)) ^ *(kp)++; \ +- (left) ^= SP[0][((temp) >> 24) & 0x3f] \ +- | SP[1][((temp) >> 16) & 0x3f] \ +- | SP[2][((temp) >> 8) & 0x3f] \ +- | SP[3][((temp) ) & 0x3f]; \ +- (temp) = (((right) >> 23) | ((right) << 9)) ^ *(kp)++; \ +- (left) ^= SP[4][((temp) >> 24) & 0x3f] \ +- | SP[5][((temp) >> 16) & 0x3f] \ +- | SP[6][((temp) >> 8) & 0x3f] \ +- | SP[7][((temp) ) & 0x3f]; \ +- } while(0); +- +-#define DES_SP_DECRYPT_ROUND(left, right, temp, kp) do { \ +- (temp) = (((right) >> 23) | ((right) << 9)) ^ *(--(kp)); \ +- (left) ^= SP[7][((temp) ) & 0x3f] \ +- | SP[6][((temp) >> 8) & 0x3f] \ +- | SP[5][((temp) >> 16) & 0x3f] \ +- | SP[4][((temp) >> 24) & 0x3f]; \ +- (temp) = (((right) >> 11) | ((right) << 21)) ^ *(--(kp)); \ +- (left) ^= SP[3][((temp) ) & 0x3f] \ +- | SP[2][((temp) >> 8) & 0x3f] \ +- | SP[1][((temp) >> 16) & 0x3f] \ +- | SP[0][((temp) >> 24) & 0x3f]; \ +- } while (0); +- +-/* +- * Macros to help deal with the initial permutation table. Note +- * the IP table only deals with 32 bits at a time, allowing us to +- * collect the bits we need to deal with each half into an unsigned +- * DES_INT32. By carefully selecting how the bits are ordered we also +- * take advantages of symmetries in the table so that we can use a +- * single table to compute the permutation of all bytes. This sounds +- * complicated, but if you go through the process of designing the +- * table you'll find the symmetries fall right out. +- * +- * The follow macros compute the set of bits used to index the +- * table for produce the left and right permuted result. +- * +- * The inserted cast to unsigned DES_INT32 circumvents a bug in +- * the Macintosh MPW 3.2 C compiler which loses the unsignedness and +- * propagates the high-order bit in the shift. +- */ +-#define DES_IP_LEFT_BITS(left, right) \ +- ((((left) & 0x55555555) << 1) | ((right) & 0x55555555)) +-#define DES_IP_RIGHT_BITS(left, right) \ +- (((left) & 0xaaaaaaaa) | \ +- ( ( (unsigned DES_INT32) ((right) & 0xaaaaaaaa) ) >> 1)) +- +-/* +- * The following macro does an in-place initial permutation given +- * the current left and right parts of the block and a single +- * temporary. Use this more as a guide for rolling your own, though. +- * The best way to do the IP depends on the form of the data you +- * are dealing with. If you use this, though, try to make left, +- * right and temp unsigned DES_INT32s. +- */ +-#define DES_INITIAL_PERM(left, right, temp) do { \ +- (temp) = DES_IP_RIGHT_BITS((left), (right)); \ +- (right) = DES_IP_LEFT_BITS((left), (right)); \ +- (left) = IP[((right) >> 24) & 0xff] \ +- | (IP[((right) >> 16) & 0xff] << 1) \ +- | (IP[((right) >> 8) & 0xff] << 2) \ +- | (IP[(right) & 0xff] << 3); \ +- (right) = IP[((temp) >> 24) & 0xff] \ +- | (IP[((temp) >> 16) & 0xff] << 1) \ +- | (IP[((temp) >> 8) & 0xff] << 2) \ +- | (IP[(temp) & 0xff] << 3); \ +- } while(0); +- +-/* +- * Now the final permutation stuff. The same comments apply to +- * this as to the initial permutation, except that we use different +- * bits and shifts. +- * +- * The inserted cast to unsigned DES_INT32 circumvents a bug in +- * the Macintosh MPW 3.2 C compiler which loses the unsignedness and +- * propagates the high-order bit in the shift. +- */ +-#define DES_FP_LEFT_BITS(left, right) \ +- ((((left) & 0x0f0f0f0f) << 4) | ((right) & 0x0f0f0f0f)) +-#define DES_FP_RIGHT_BITS(left, right) \ +- (((left) & 0xf0f0f0f0) | \ +- ( ( (unsigned DES_INT32) ((right) & 0xf0f0f0f0) ) >> 4)) +- +- +-/* +- * Here is a sample final permutation. Note that there is a trick +- * here. DES requires swapping the left and right parts after the +- * last cipher round but before the final permutation. We do this +- * swapping internally, which is why left and right are confused +- * at the beginning. +- */ +-#define DES_FINAL_PERM(left, right, temp) do { \ +- (temp) = DES_FP_RIGHT_BITS((right), (left)); \ +- (right) = DES_FP_LEFT_BITS((right), (left)); \ +- (left) = (FP[((right) >> 24) & 0xff] << 6) \ +- | (FP[((right) >> 16) & 0xff] << 4) \ +- | (FP[((right) >> 8) & 0xff] << 2) \ +- | FP[(right) & 0xff]; \ +- (right) = (FP[((temp) >> 24) & 0xff] << 6) \ +- | (FP[((temp) >> 16) & 0xff] << 4) \ +- | (FP[((temp) >> 8) & 0xff] << 2) \ +- | FP[temp & 0xff]; \ +- } while(0); +- +- +-/* +- * Finally, as a sample of how all this might be held together, the +- * following two macros do in-place encryptions and decryptions. left +- * and right are two unsigned DES_INT32 variables which at the beginning +- * are expected to hold the clear (encrypted) block in host byte order +- * (left the high order four bytes, right the low order). At the end +- * they will contain the encrypted (clear) block. temp is an unsigned DES_INT32 +- * used as a temporary. kp is an unsigned DES_INT32 pointer pointing at +- * the start of the key schedule. All these should be in registers. +- * +- * You can probably do better than these by rewriting for particular +- * situations. These aren't bad, though. +- * +- * The DEB macros enable debugging when this code breaks (typically +- * when a buggy compiler breaks it), by printing the intermediate values +- * at each stage of the encryption, so that by comparing the output to +- * a known good machine, the location of the first error can be found. +- */ +-#define DES_DO_ENCRYPT_1(left, right, kp) \ +- do { \ +- int i; \ +- unsigned DES_INT32 temp1; \ +- DEB (("do_encrypt %8lX %8lX \n", left, right)); \ +- DES_INITIAL_PERM((left), (right), (temp1)); \ +- DEB ((" after IP %8lX %8lX\n", left, right)); \ +- for (i = 0; i < 8; i++) { \ +- DES_SP_ENCRYPT_ROUND((left), (right), (temp1), (kp)); \ +- DEB ((" round %2d %8lX %8lX \n", i*2, left, right)); \ +- DES_SP_ENCRYPT_ROUND((right), (left), (temp1), (kp)); \ +- DEB ((" round %2d %8lX %8lX \n", 1+i*2, left, right)); \ +- } \ +- DES_FINAL_PERM((left), (right), (temp1)); \ +- (kp) -= (2 * 16); \ +- DEB ((" after FP %8lX %8lX \n", left, right)); \ +- } while (0) +- +-#define DES_DO_DECRYPT_1(left, right, kp) \ +- do { \ +- int i; \ +- unsigned DES_INT32 temp2; \ +- DES_INITIAL_PERM((left), (right), (temp2)); \ +- (kp) += (2 * 16); \ +- for (i = 0; i < 8; i++) { \ +- DES_SP_DECRYPT_ROUND((left), (right), (temp2), (kp)); \ +- DES_SP_DECRYPT_ROUND((right), (left), (temp2), (kp)); \ +- } \ +- DES_FINAL_PERM((left), (right), (temp2)); \ +- } while (0) +- +-#if defined(CONFIG_SMALL) && !defined(CONFIG_SMALL_NO_CRYPTO) +-extern void krb5int_des_do_encrypt_2(unsigned DES_INT32 *l, +- unsigned DES_INT32 *r, +- const unsigned DES_INT32 *k); +-extern void krb5int_des_do_decrypt_2(unsigned DES_INT32 *l, +- unsigned DES_INT32 *r, +- const unsigned DES_INT32 *k); +-#define DES_DO_ENCRYPT(L,R,K) krb5int_des_do_encrypt_2(&(L), &(R), (K)) +-#define DES_DO_DECRYPT(L,R,K) krb5int_des_do_decrypt_2(&(L), &(R), (K)) +-#else +-#define DES_DO_ENCRYPT DES_DO_ENCRYPT_1 +-#define DES_DO_DECRYPT DES_DO_DECRYPT_1 +-#endif +- +-/* +- * These are handy dandy utility thingies for straightening out bytes. +- * Included here because they're used a couple of places. +- */ +-#define GET_HALF_BLOCK(lr, ip) ((lr) = load_32_be(ip), (ip) += 4) +-#define PUT_HALF_BLOCK(lr, op) (store_32_be(lr, op), (op) += 4) +- +-/* Shorthand that we'll need in several places, for creating values that +- really can hold 32 bits regardless of the prevailing int size. */ +-#define FF_UINT32 ((unsigned DES_INT32) 0xFF) +- +-#endif /* __DES_TABLES_H__ */ +diff --git a/src/lib/crypto/builtin/des/key_sched.c b/src/lib/crypto/builtin/des/key_sched.c +deleted file mode 100644 +index 87f02b6a9..000000000 +--- a/src/lib/crypto/builtin/des/key_sched.c ++++ /dev/null +@@ -1,62 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/key_sched.c */ +-/* +- * Copyright 1985, 1986, 1987, 1988, 1990 by the Massachusetts Institute +- * of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* +- * This routine computes the DES key schedule given a key. The +- * permutations and shifts have been done at compile time, resulting +- * in a direct one-step mapping from the input key to the key +- * schedule. +- * +- * Also checks parity and weak keys. +- * +- * Watch out for the subscripts -- most effectively start at 1 instead +- * of at zero. Maybe some bugs in that area. +- * +- * In case the user wants to cache the computed key schedule, it is +- * passed as an arg. Also implies that caller has explicit control +- * over zeroing both the key schedule and the key. +- * +- * Originally written 6/85 by Steve Miller, MIT Project Athena. +- */ +- +-#include "k5-int.h" +-#include "des_int.h" +- +-int +-mit_des_key_sched(mit_des_cblock k, mit_des_key_schedule schedule) +-{ +- mit_des_make_key_sched(k,schedule); +- +- if (!mit_des_check_key_parity(k)) /* bad parity --> return -1 */ +- return(-1); +- +- if (mit_des_is_weak_key(k)) +- return(-2); +- +- /* if key was good, return 0 */ +- return 0; +-} +diff --git a/src/lib/crypto/builtin/des/keytest.data b/src/lib/crypto/builtin/des/keytest.data +deleted file mode 100644 +index 7ff34eedc..000000000 +--- a/src/lib/crypto/builtin/des/keytest.data ++++ /dev/null +@@ -1,171 +0,0 @@ +-0101010101010101 95F8A5E5DD31D900 8000000000000000 +-0101010101010101 DD7F121CA5015619 4000000000000000 +-0101010101010101 2E8653104F3834EA 2000000000000000 +-0101010101010101 4BD388FF6CD81D4F 1000000000000000 +-0101010101010101 20B9E767B2FB1456 0800000000000000 +-0101010101010101 55579380D77138EF 0400000000000000 +-0101010101010101 6CC5DEFAAF04512F 0200000000000000 +-0101010101010101 0D9F279BA5D87260 0100000000000000 +-0101010101010101 D9031B0271BD5A0A 0080000000000000 +-0101010101010101 424250B37C3DD951 0040000000000000 +-0101010101010101 B8061B7ECD9A21E5 0020000000000000 +-0101010101010101 F15D0F286B65BD28 0010000000000000 +-0101010101010101 ADD0CC8D6E5DEBA1 0008000000000000 +-0101010101010101 E6D5F82752AD63D1 0004000000000000 +-0101010101010101 ECBFE3BD3F591A5E 0002000000000000 +-0101010101010101 F356834379D165CD 0001000000000000 +-0101010101010101 2B9F982F20037FA9 0000800000000000 +-0101010101010101 889DE068A16F0BE6 0000400000000000 +-0101010101010101 E19E275D846A1298 0000200000000000 +-0101010101010101 329A8ED523D71AEC 0000100000000000 +-0101010101010101 E7FCE22557D23C97 0000080000000000 +-0101010101010101 12A9F5817FF2D65D 0000040000000000 +-0101010101010101 A484C3AD38DC9C19 0000020000000000 +-0101010101010101 FBE00A8A1EF8AD72 0000010000000000 +-0101010101010101 750D079407521363 0000008000000000 +-0101010101010101 64FEED9C724C2FAF 0000004000000000 +-0101010101010101 F02B263B328E2B60 0000002000000000 +-0101010101010101 9D64555A9A10B852 0000001000000000 +-0101010101010101 D106FF0BED5255D7 0000000800000000 +-0101010101010101 E1652C6B138C64A5 0000000400000000 +-0101010101010101 E428581186EC8F46 0000000200000000 +-0101010101010101 AEB5F5EDE22D1A36 0000000100000000 +-0101010101010101 E943D7568AEC0C5C 0000000080000000 +-0101010101010101 DF98C8276F54B04B 0000000040000000 +-0101010101010101 B160E4680F6C696F 0000000020000000 +-0101010101010101 FA0752B07D9C4AB8 0000000010000000 +-0101010101010101 CA3A2B036DBC8502 0000000008000000 +-0101010101010101 5E0905517BB59BCF 0000000004000000 +-0101010101010101 814EEB3B91D90726 0000000002000000 +-0101010101010101 4D49DB1532919C9F 0000000001000000 +-0101010101010101 25EB5FC3F8CF0621 0000000000800000 +-0101010101010101 AB6A20C0620D1C6F 0000000000400000 +-0101010101010101 79E90DBC98F92CCA 0000000000200000 +-0101010101010101 866ECEDD8072BB0E 0000000000100000 +-0101010101010101 8B54536F2F3E64A8 0000000000080000 +-0101010101010101 EA51D3975595B86B 0000000000040000 +-0101010101010101 CAFFC6AC4542DE31 0000000000020000 +-0101010101010101 8DD45A2DDF90796C 0000000000010000 +-0101010101010101 1029D55E880EC2D0 0000000000008000 +-0101010101010101 5D86CB23639DBEA9 0000000000004000 +-0101010101010101 1D1CA853AE7C0C5F 0000000000002000 +-0101010101010101 CE332329248F3228 0000000000001000 +-0101010101010101 8405D1ABE24FB942 0000000000000800 +-0101010101010101 E643D78090CA4207 0000000000000400 +-0101010101010101 48221B9937748A23 0000000000000200 +-0101010101010101 DD7C0BBD61FAFD54 0000000000000100 +-0101010101010101 2FBC291A570DB5C4 0000000000000080 +-0101010101010101 E07C30D7E4E26E12 0000000000000040 +-0101010101010101 0953E2258E8E90A1 0000000000000020 +-0101010101010101 5B711BC4CEEBF2EE 0000000000000010 +-0101010101010101 CC083F1E6D9E85F6 0000000000000008 +-0101010101010101 D2FD8867D50D2DFE 0000000000000004 +-0101010101010101 06E7EA22CE92708F 0000000000000002 +-0101010101010101 166B40B44ABA4BD6 0000000000000001 +-8001010101010101 0000000000000000 95A8D72813DAA94D +-4001010101010101 0000000000000000 0EEC1487DD8C26D5 +-2001010101010101 0000000000000000 7AD16FFB79C45926 +-1001010101010101 0000000000000000 D3746294CA6A6CF3 +-0801010101010101 0000000000000000 809F5F873C1FD761 +-0401010101010101 0000000000000000 C02FAFFEC989D1FC +-0201010101010101 0000000000000000 4615AA1D33E72F10 +-0180010101010101 0000000000000000 2055123350C00858 +-0140010101010101 0000000000000000 DF3B99D6577397C8 +-0120010101010101 0000000000000000 31FE17369B5288C9 +-0110010101010101 0000000000000000 DFDD3CC64DAE1642 +-0108010101010101 0000000000000000 178C83CE2B399D94 +-0104010101010101 0000000000000000 50F636324A9B7F80 +-0102010101010101 0000000000000000 A8468EE3BC18F06D +-0101800101010101 0000000000000000 A2DC9E92FD3CDE92 +-0101400101010101 0000000000000000 CAC09F797D031287 +-0101200101010101 0000000000000000 90BA680B22AEB525 +-0101100101010101 0000000000000000 CE7A24F350E280B6 +-0101080101010101 0000000000000000 882BFF0AA01A0B87 +-0101040101010101 0000000000000000 25610288924511C2 +-0101020101010101 0000000000000000 C71516C29C75D170 +-0101018001010101 0000000000000000 5199C29A52C9F059 +-0101014001010101 0000000000000000 C22F0A294A71F29F +-0101012001010101 0000000000000000 EE371483714C02EA +-0101011001010101 0000000000000000 A81FBD448F9E522F +-0101010801010101 0000000000000000 4F644C92E192DFED +-0101010401010101 0000000000000000 1AFA9A66A6DF92AE +-0101010201010101 0000000000000000 B3C1CC715CB879D8 +-0101010180010101 0000000000000000 19D032E64AB0BD8B +-0101010140010101 0000000000000000 3CFAA7A7DC8720DC +-0101010120010101 0000000000000000 B7265F7F447AC6F3 +-0101010110010101 0000000000000000 9DB73B3C0D163F54 +-0101010108010101 0000000000000000 8181B65BABF4A975 +-0101010104010101 0000000000000000 93C9B64042EAA240 +-0101010102010101 0000000000000000 5570530829705592 +-0101010101800101 0000000000000000 8638809E878787A0 +-0101010101400101 0000000000000000 41B9A79AF79AC208 +-0101010101200101 0000000000000000 7A9BE42F2009A892 +-0101010101100101 0000000000000000 29038D56BA6D2745 +-0101010101080101 0000000000000000 5495C6ABF1E5DF51 +-0101010101040101 0000000000000000 AE13DBD561488933 +-0101010101020101 0000000000000000 024D1FFA8904E389 +-0101010101018001 0000000000000000 D1399712F99BF02E +-0101010101014001 0000000000000000 14C1D7C1CFFEC79E +-0101010101012001 0000000000000000 1DE5279DAE3BED6F +-0101010101011001 0000000000000000 E941A33F85501303 +-0101010101010801 0000000000000000 DA99DBBC9A03F379 +-0101010101010401 0000000000000000 B7FC92F91D8E92E9 +-0101010101010201 0000000000000000 AE8E5CAA3CA04E85 +-0101010101010180 0000000000000000 9CC62DF43B6EED74 +-0101010101010140 0000000000000000 D863DBB5C59A91A0 +-0101010101010120 0000000000000000 A1AB2190545B91D7 +-0101010101010110 0000000000000000 0875041E64C570F7 +-0101010101010108 0000000000000000 5A594528BEBEF1CC +-0101010101010104 0000000000000000 FCDB3291DE21F0C0 +-0101010101010102 0000000000000000 869EFD7F9F265A09 +-1046913489980131 0000000000000000 88D55E54F54C97B4 +-1007103489988020 0000000000000000 0C0CC00C83EA48FD +-10071034C8980120 0000000000000000 83BC8EF3A6570183 +-1046103489988020 0000000000000000 DF725DCAD94EA2E9 +-1086911519190101 0000000000000000 E652B53B550BE8B0 +-1086911519580101 0000000000000000 AF527120C485CBB0 +-5107B01519580101 0000000000000000 0F04CE393DB926D5 +-1007B01519190101 0000000000000000 C9F00FFC74079067 +-3107915498080101 0000000000000000 7CFD82A593252B4E +-3107919498080101 0000000000000000 CB49A2F9E91363E3 +-10079115B9080140 0000000000000000 00B588BE70D23F56 +-3107911598080140 0000000000000000 406A9A6AB43399AE +-1007D01589980101 0000000000000000 6CB773611DCA9ADA +-9107911589980101 0000000000000000 67FD21C17DBB5D70 +-9107D01589190101 0000000000000000 9592CB4110430787 +-1007D01598980120 0000000000000000 A6B7FF68A318DDD3 +-1007940498190101 0000000000000000 4D102196C914CA16 +-0107910491190401 0000000000000000 2DFA9F4573594965 +-0107910491190101 0000000000000000 B46604816C0E0774 +-0107940491190401 0000000000000000 6E7E6221A4F34E87 +-19079210981A0101 0000000000000000 AA85E74643233199 +-1007911998190801 0000000000000000 2E5A19DB4D1962D6 +-10079119981A0801 0000000000000000 23A866A809D30894 +-1007921098190101 0000000000000000 D812D961F017D320 +-100791159819010B 0000000000000000 055605816E58608F +-1004801598190101 0000000000000000 ABD88E8B1B7716F1 +-1004801598190102 0000000000000000 537AC95BE69DA1E1 +-1004801598190108 0000000000000000 AED0F6AE3C25CDD8 +-1002911598100104 0000000000000000 B3E35A5EE53E7B8D +-1002911598190104 0000000000000000 61C79C71921A2EF8 +-1002911598100201 0000000000000000 E2F5728F0995013C +-1002911698100101 0000000000000000 1AEAC39A61F0A464 +-7CA110454A1A6E57 01A1D6D039776742 690F5B0D9A26939B +-0131D9619DC1376E 5CD54CA83DEF57DA 7A389D10354BD271 +-07A1133E4A0B2686 0248D43806F67172 868EBB51CAB4599A +-3849674C2602319E 51454B582DDF440A 7178876E01F19B2A +-04B915BA43FEB5B6 42FD443059577FA2 AF37FB421F8C4095 +-0113B970FD34F2CE 059B5E0851CF143A 86A560F10EC6D85B +-0170F175468FB5E6 0756D8E0774761D2 0CD3DA020021DC09 +-43297FAD38E373FE 762514B829BF486A EA676B2CB7DB2B7A +-07A7137045DA2A16 3BDD119049372802 DFD64A815CAF1A0F +-04689104C2FD3B2F 26955F6835AF609A 5C513C9C4886C088 +-37D06BB516CB7546 164D5E404F275232 0A2AEEAE3FF4AB77 +-1F08260D1AC2465E 6B056E18759F5CCA EF1BF03E5DFA575A +-584023641ABA6176 004BD6EF09176062 88BF0DB6D70DEE56 +-025816164629B007 480D39006EE762F2 A1F9915541020B56 +-49793EBC79B3258F 437540C8698F3CFA 6FBF1CAFCFFD0556 +-4FB05E1515AB73A7 072D43A077075292 2F22E49BAB7CA1AC +-49E95D6D4CA229BF 02FE55778117F12A 5A6B612CC26CCE4A +-018310DC409B26D6 1D9D5C5018F728C2 5F4C038ED12B2E41 +-1C587F1C13924FEF 305532286D6F295A 63FAC0D034D9F793 +diff --git a/src/lib/crypto/builtin/des/t_verify.c b/src/lib/crypto/builtin/des/t_verify.c +deleted file mode 100644 +index f4332f5c0..000000000 +--- a/src/lib/crypto/builtin/des/t_verify.c ++++ /dev/null +@@ -1,395 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/t_verify.c */ +-/* +- * Copyright 1988, 1990 by the Massachusetts Institute of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-/* +- * +- * Program to test the correctness of the DES library +- * implementation. +- * +- * exit returns 0 ==> success +- * -1 ==> error +- */ +- +-#include "k5-int.h" +-#include "des_int.h" +-#include +-#include "com_err.h" +- +-static void do_encrypt(unsigned char *, unsigned char *); +-static void do_decrypt(unsigned char *, unsigned char *); +- +-char *progname; +-int nflag = 2; +-int vflag; +-int mflag; +-int zflag; +-int pid; +-int mit_des_debug; +- +-unsigned char cipher_text[64]; +-unsigned char clear_text[64] = "Now is the time for all " ; +-unsigned char clear_text2[64] = "7654321 Now is the time for "; +-unsigned char clear_text3[64] = {2,0,0,0, 1,0,0,0}; +-unsigned char output[64]; +-unsigned char zero_text[8] = {0x0,0,0,0,0,0,0,0}; +-unsigned char msb_text[8] = {0x0,0,0,0, 0,0,0,0x40}; /* to ANSI MSB */ +-unsigned char *input; +- +-/* 0x0123456789abcdef */ +-unsigned char default_key[8] = { +- 0x01,0x23,0x45,0x67,0x89,0xab,0xcd,0xef +-}; +-unsigned char key2[8] = { 0x08,0x19,0x2a,0x3b,0x4c,0x5d,0x6e,0x7f }; +-unsigned char key3[8] = { 0x80,1,1,1,1,1,1,1 }; +-mit_des_cblock s_key; +-unsigned char default_ivec[8] = { +- 0x12,0x34,0x56,0x78,0x90,0xab,0xcd,0xef +-}; +-unsigned char *ivec; +-unsigned char zero_key[8] = {1,1,1,1,1,1,1,1}; /* just parity bits */ +- +-unsigned char cipher1[8] = { +- 0x25,0xdd,0xac,0x3e,0x96,0x17,0x64,0x67 +-}; +-unsigned char cipher2[8] = { +- 0x3f,0xa4,0x0e,0x8a,0x98,0x4d,0x48,0x15 +-}; +-unsigned char cipher3[64] = { +- 0xe5,0xc7,0xcd,0xde,0x87,0x2b,0xf2,0x7c, +- 0x43,0xe9,0x34,0x00,0x8c,0x38,0x9c,0x0f, +- 0x68,0x37,0x88,0x49,0x9a,0x7c,0x05,0xf6 +-}; +-unsigned char checksum[8] = { +- 0x58,0xd2,0xe7,0x7e,0x86,0x06,0x27,0x33 +-}; +- +-unsigned char zresult[8] = { +- 0x8c, 0xa6, 0x4d, 0xe9, 0xc1, 0xb1, 0x23, 0xa7 +-}; +- +-unsigned char mresult[8] = { +- 0xa3, 0x80, 0xe0, 0x2a, 0x6b, 0xe5, 0x46, 0x96 +-}; +- +- +-/* +- * Can also add : +- * plaintext = 0, key = 0, cipher = 0x8ca64de9c1b123a7 (or is it a 1?) +- */ +- +-mit_des_key_schedule sched; +- +-int +-main(argc,argv) +- int argc; +- char *argv[]; +-{ +- /* Local Declarations */ +- size_t in_length; +- int retval; +- int i, j; +- +-#ifdef WINDOWS +- /* Set screen window buffer to infinite size -- MS default is tiny. */ +- _wsetscreenbuf (fileno (stdout), _WINBUFINF); +-#endif +- progname=argv[0]; /* salt away invoking program */ +- +- while (--argc > 0 && (*++argv)[0] == '-') +- for (i=1; argv[0][i] != '\0'; i++) { +- switch (argv[0][i]) { +- +- /* debug flag */ +- case 'd': +- mit_des_debug=3; +- continue; +- +- case 'z': +- zflag = 1; +- continue; +- +- case 'm': +- mflag = 1; +- continue; +- +- default: +- printf("%s: illegal flag \"%c\" ", +- progname,argv[0][i]); +- exit(1); +- } +- }; +- +- if (argc) { +- fprintf(stderr, "Usage: %s [-dmz]\n", progname); +- exit(1); +- } +- +- /* do some initialisation */ +- +- /* use known input and key */ +- +- /* ECB zero text zero key */ +- if (zflag) { +- input = zero_text; +- mit_des_key_sched(zero_key, sched); +- printf("plaintext = key = 0, cipher = 0x8ca64de9c1b123a7\n"); +- do_encrypt(input,cipher_text); +- printf("\tcipher = (low to high bytes)\n\t\t"); +- for (j = 0; j<=7; j++) +- printf("%02x ",cipher_text[j]); +- printf("\n"); +- do_decrypt(output,cipher_text); +- if ( memcmp((char *)cipher_text, (char *)zresult, 8) ) { +- printf("verify: error in zero key test\n"); +- exit(-1); +- } +- +- exit(0); +- } +- +- if (mflag) { +- input = msb_text; +- mit_des_key_sched(key3, sched); +- printf("plaintext = 0x00 00 00 00 00 00 00 40, "); +- printf("key = 0x80 01 01 01 01 01 01 01\n"); +- printf(" cipher = 0xa380e02a6be54696\n"); +- do_encrypt(input,cipher_text); +- printf("\tcipher = (low to high bytes)\n\t\t"); +- for (j = 0; j<=7; j++) { +- printf("%02x ",cipher_text[j]); +- } +- printf("\n"); +- do_decrypt(output,cipher_text); +- if ( memcmp((char *)cipher_text, (char *)mresult, 8) ) { +- printf("verify: error in msb test\n"); +- exit(-1); +- } +- exit(0); +- } +- +- /* ECB mode Davies and Price */ +- { +- input = zero_text; +- mit_des_key_sched(key2, sched); +- printf("Examples per FIPS publication 81, keys ivs and cipher\n"); +- printf("in hex. These are the correct answers, see below for\n"); +- printf("the actual answers.\n\n"); +- printf("Examples per Davies and Price.\n\n"); +- printf("EXAMPLE ECB\tkey = 08192a3b4c5d6e7f\n"); +- printf("\tclear = 0\n"); +- printf("\tcipher = 25 dd ac 3e 96 17 64 67\n"); +- printf("ACTUAL ECB\n"); +- printf("\tclear \"%s\"\n", input); +- do_encrypt(input,cipher_text); +- printf("\tcipher = (low to high bytes)\n\t\t"); +- for (j = 0; j<=7; j++) +- printf("%02x ",cipher_text[j]); +- printf("\n\n"); +- do_decrypt(output,cipher_text); +- if ( memcmp((char *)cipher_text, (char *)cipher1, 8) ) { +- printf("verify: error in ECB encryption\n"); +- exit(-1); +- } +- else +- printf("verify: ECB encryption is correct\n\n"); +- } +- +- /* ECB mode */ +- { +- mit_des_key_sched(default_key, sched); +- input = clear_text; +- ivec = default_ivec; +- printf("EXAMPLE ECB\tkey = 0123456789abcdef\n"); +- printf("\tclear = \"Now is the time for all \"\n"); +- printf("\tcipher = 3f a4 0e 8a 98 4d 48 15 ...\n"); +- printf("ACTUAL ECB\n\tclear \"%s\"",input); +- do_encrypt(input,cipher_text); +- printf("\n\tcipher = (low to high bytes)\n\t\t"); +- for (j = 0; j<=7; j++) { +- printf("%02x ",cipher_text[j]); +- } +- printf("\n\n"); +- do_decrypt(output,cipher_text); +- if ( memcmp((char *)cipher_text, (char *)cipher2, 8) ) { +- printf("verify: error in ECB encryption\n"); +- exit(-1); +- } +- else +- printf("verify: ECB encryption is correct\n\n"); +- } +- +- /* CBC mode */ +- printf("EXAMPLE CBC\tkey = 0123456789abcdef"); +- printf("\tiv = 1234567890abcdef\n"); +- printf("\tclear = \"Now is the time for all \"\n"); +- printf("\tcipher =\te5 c7 cd de 87 2b f2 7c\n"); +- printf("\t\t\t43 e9 34 00 8c 38 9c 0f\n"); +- printf("\t\t\t68 37 88 49 9a 7c 05 f6\n"); +- +- printf("ACTUAL CBC\n\tclear \"%s\"\n",input); +- in_length = strlen((char *)input); +- if ((retval = mit_des_cbc_encrypt((const mit_des_cblock *) input, +- (mit_des_cblock *) cipher_text, +- (size_t) in_length, +- sched, +- ivec, +- MIT_DES_ENCRYPT))) { +- com_err("des verify", retval, "can't encrypt"); +- exit(-1); +- } +- printf("\tciphertext = (low to high bytes)\n"); +- for (i = 0; i <= 2; i++) { +- printf("\t\t"); +- for (j = 0; j <= 7; j++) { +- printf("%02x ",cipher_text[i*8+j]); +- } +- printf("\n"); +- } +- if ((retval = mit_des_cbc_encrypt((const mit_des_cblock *) cipher_text, +- (mit_des_cblock *) clear_text, +- (size_t) in_length, +- sched, +- ivec, +- MIT_DES_DECRYPT))) { +- com_err("des verify", retval, "can't decrypt"); +- exit(-1); +- } +- printf("\tdecrypted clear_text = \"%s\"\n",clear_text); +- +- if ( memcmp((char *)cipher_text, (char *)cipher3, in_length) ) { +- printf("verify: error in CBC encryption\n"); +- exit(-1); +- } +- else +- printf("verify: CBC encryption is correct\n\n"); +- +- printf("EXAMPLE CBC checksum"); +- printf("\tkey = 0123456789abcdef\tiv = 1234567890abcdef\n"); +- printf("\tclear =\t\t\"7654321 Now is the time for \"\n"); +- printf("\tchecksum\t58 d2 e7 7e 86 06 27 33, "); +- printf("or some part thereof\n"); +- input = clear_text2; +- mit_des_cbc_cksum(input,cipher_text, strlen((char *)input), +- sched,ivec); +- printf("ACTUAL CBC checksum\n"); +- printf("\t\tencrypted cksum = (low to high bytes)\n\t\t"); +- for (j = 0; j<=7; j++) +- printf("%02x ",cipher_text[j]); +- printf("\n\n"); +- if ( memcmp((char *)cipher_text, (char *)checksum, 8) ) { +- printf("verify: error in CBC cheksum\n"); +- exit(-1); +- } +- else +- printf("verify: CBC checksum is correct\n\n"); +- +- exit(0); +-} +- +-static void +-do_encrypt(in,out) +- unsigned char *in; +- unsigned char *out; +-{ +- int i, j; +- for (i =1; i<=nflag; i++) { +- mit_des_cbc_encrypt((const mit_des_cblock *)in, +- (mit_des_cblock *)out, +- 8, +- sched, +- zero_text, +- MIT_DES_ENCRYPT); +- if (mit_des_debug) { +- printf("\nclear %s\n",in); +- for (j = 0; j<=7; j++) +- printf("%02X ",in[j] & 0xff); +- printf("\tcipher "); +- for (j = 0; j<=7; j++) +- printf("%02X ",out[j] & 0xff); +- } +- } +-} +- +-static void +-do_decrypt(in,out) +- unsigned char *out; +- unsigned char *in; +- /* try to invert it */ +-{ +- int i, j; +- for (i =1; i<=nflag; i++) { +- mit_des_cbc_encrypt((const mit_des_cblock *)out, +- (mit_des_cblock *)in, +- 8, +- sched, +- zero_text, +- MIT_DES_DECRYPT); +- if (mit_des_debug) { +- printf("clear %s\n",in); +- for (j = 0; j<=7; j++) +- printf("%02X ",in[j] & 0xff); +- printf("\tcipher "); +- for (j = 0; j<=7; j++) +- printf("%02X ",out[j] & 0xff); +- } +- } +-} +- +-/* +- * Fake out the DES library, for the purposes of testing. +- */ +- +-int +-mit_des_is_weak_key(key) +- mit_des_cblock key; +-{ +- return 0; /* fake it out for testing */ +-} +diff --git a/src/lib/crypto/builtin/des/weak_key.c b/src/lib/crypto/builtin/des/weak_key.c +deleted file mode 100644 +index eb41b267d..000000000 +--- a/src/lib/crypto/builtin/des/weak_key.c ++++ /dev/null +@@ -1,86 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/builtin/des/weak_key.c */ +-/* +- * Copyright 1989,1990 by the Massachusetts Institute of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* +- * Under U.S. law, this software may not be exported outside the US +- * without license from the U.S. Commerce department. +- * +- * These routines form the library interface to the DES facilities. +- * +- * Originally written 8/85 by Steve Miller, MIT Project Athena. +- */ +- +-#include "k5-int.h" +-#include "des_int.h" +- +-/* +- * The following are the weak DES keys: +- */ +-static const mit_des_cblock weak[16] = { +- /* weak keys */ +- {0x01,0x01,0x01,0x01,0x01,0x01,0x01,0x01}, +- {0xfe,0xfe,0xfe,0xfe,0xfe,0xfe,0xfe,0xfe}, +- {0x1f,0x1f,0x1f,0x1f,0x0e,0x0e,0x0e,0x0e}, +- {0xe0,0xe0,0xe0,0xe0,0xf1,0xf1,0xf1,0xf1}, +- +- /* semi-weak */ +- {0x01,0xfe,0x01,0xfe,0x01,0xfe,0x01,0xfe}, +- {0xfe,0x01,0xfe,0x01,0xfe,0x01,0xfe,0x01}, +- +- {0x1f,0xe0,0x1f,0xe0,0x0e,0xf1,0x0e,0xf1}, +- {0xe0,0x1f,0xe0,0x1f,0xf1,0x0e,0xf1,0x0e}, +- +- {0x01,0xe0,0x01,0xe0,0x01,0xf1,0x01,0xf1}, +- {0xe0,0x01,0xe0,0x01,0xf1,0x01,0xf1,0x01}, +- +- {0x1f,0xfe,0x1f,0xfe,0x0e,0xfe,0x0e,0xfe}, +- {0xfe,0x1f,0xfe,0x1f,0xfe,0x0e,0xfe,0x0e}, +- +- {0x01,0x1f,0x01,0x1f,0x01,0x0e,0x01,0x0e}, +- {0x1f,0x01,0x1f,0x01,0x0e,0x01,0x0e,0x01}, +- +- {0xe0,0xfe,0xe0,0xfe,0xf1,0xfe,0xf1,0xfe}, +- {0xfe,0xe0,0xfe,0xe0,0xfe,0xf1,0xfe,0xf1} +-}; +- +-/* +- * mit_des_is_weak_key: returns true iff key is a [semi-]weak des key. +- * +- * Requires: key has correct odd parity. +- */ +-int +-mit_des_is_weak_key(mit_des_cblock key) +-{ +- unsigned int i; +- const mit_des_cblock *weak_p = weak; +- +- for (i = 0; i < (sizeof(weak)/sizeof(mit_des_cblock)); i++) { +- if (!memcmp(weak_p++,key,sizeof(mit_des_cblock))) +- return 1; +- } +- +- return 0; +-} +diff --git a/src/lib/crypto/builtin/enc_provider/Makefile.in b/src/lib/crypto/builtin/enc_provider/Makefile.in +index 3459e1d0e..af6276b96 100644 +--- a/src/lib/crypto/builtin/enc_provider/Makefile.in ++++ b/src/lib/crypto/builtin/enc_provider/Makefile.in +@@ -1,7 +1,6 @@ + mydir=lib$(S)crypto$(S)builtin$(S)enc_provider + BUILDTOP=$(REL)..$(S)..$(S)..$(S).. +-LOCALINCLUDES = -I$(srcdir)/../des \ +- -I$(srcdir)/../aes \ ++LOCALINCLUDES = -I$(srcdir)/../aes \ + -I$(srcdir)/../camellia \ + -I$(srcdir)/../../krb \ + -I$(srcdir)/.. +@@ -11,19 +10,16 @@ LOCALINCLUDES = -I$(srcdir)/../des \ + ##DOS##OBJFILE = ..\..\$(OUTPRE)enc_provider.lst + + STLIBOBJS= \ +- des3.o \ + rc4.o \ + aes.o \ + camellia.o + + OBJS= \ +- $(OUTPRE)des3.$(OBJEXT) \ + $(OUTPRE)aes.$(OBJEXT) \ + $(OUTPRE)camellia.$(OBJEXT) \ + $(OUTPRE)rc4.$(OBJEXT) + + SRCS= \ +- $(srcdir)/des3.c \ + $(srcdir)/aes.c \ + $(srcdir)/camellia.c \ + $(srcdir)/rc4.c +diff --git a/src/lib/crypto/builtin/enc_provider/deps b/src/lib/crypto/builtin/enc_provider/deps +index 7a3324c44..c1201cc1a 100644 +--- a/src/lib/crypto/builtin/enc_provider/deps ++++ b/src/lib/crypto/builtin/enc_provider/deps +@@ -1,18 +1,6 @@ + # + # Generated makefile dependencies follow. + # +-des3.so des3.po $(OUTPRE)des3.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +- $(srcdir)/../aes/aes.h $(srcdir)/../crypto_mod.h $(srcdir)/../des/des_int.h \ +- $(srcdir)/../sha2/sha2.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des3.c + aes.so aes.po $(OUTPRE)aes.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +diff --git a/src/lib/crypto/builtin/enc_provider/des3.c b/src/lib/crypto/builtin/enc_provider/des3.c +deleted file mode 100644 +index 9b8244223..000000000 +--- a/src/lib/crypto/builtin/enc_provider/des3.c ++++ /dev/null +@@ -1,105 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-#include "crypto_int.h" +-#include "des_int.h" +- +-static krb5_error_code +-validate_and_schedule(krb5_key key, const krb5_data *ivec, +- const krb5_crypto_iov *data, size_t num_data, +- mit_des3_key_schedule *schedule) +-{ +- if (key->keyblock.length != 24) +- return(KRB5_BAD_KEYSIZE); +- if (iov_total_length(data, num_data, FALSE) % 8 != 0) +- return(KRB5_BAD_MSIZE); +- if (ivec && (ivec->length != 8)) +- return(KRB5_BAD_MSIZE); +- +- switch (mit_des3_key_sched(*(mit_des3_cblock *)key->keyblock.contents, +- *schedule)) { +- case -1: +- return(KRB5DES_BAD_KEYPAR); +- case -2: +- return(KRB5DES_WEAK_KEY); +- } +- return 0; +-} +- +-static krb5_error_code +-k5_des3_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, +- size_t num_data) +-{ +- mit_des3_key_schedule schedule; +- krb5_error_code err; +- +- err = validate_and_schedule(key, ivec, data, num_data, &schedule); +- if (err) +- return err; +- +- /* this has a return value, but the code always returns zero */ +- krb5int_des3_cbc_encrypt(data, num_data, +- schedule[0], schedule[1], schedule[2], +- ivec != NULL ? (unsigned char *) ivec->data : +- NULL); +- +- zap(schedule, sizeof(schedule)); +- +- return(0); +-} +- +-static krb5_error_code +-k5_des3_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, +- size_t num_data) +-{ +- mit_des3_key_schedule schedule; +- krb5_error_code err; +- +- err = validate_and_schedule(key, ivec, data, num_data, &schedule); +- if (err) +- return err; +- +- /* this has a return value, but the code always returns zero */ +- krb5int_des3_cbc_decrypt(data, num_data, +- schedule[0], schedule[1], schedule[2], +- ivec != NULL ? (unsigned char *) ivec->data : +- NULL); +- +- zap(schedule, sizeof(schedule)); +- +- return 0; +-} +- +-const struct krb5_enc_provider krb5int_enc_des3 = { +- 8, +- 21, 24, +- k5_des3_encrypt, +- k5_des3_decrypt, +- NULL, +- krb5int_des_init_state, +- krb5int_default_free_state +-}; +diff --git a/src/lib/crypto/crypto_tests/t_cf2.expected b/src/lib/crypto/crypto_tests/t_cf2.expected +index f8251a16c..bc6aa50c8 100644 +--- a/src/lib/crypto/crypto_tests/t_cf2.expected ++++ b/src/lib/crypto/crypto_tests/t_cf2.expected +@@ -1,6 +1,5 @@ + 97df97e4b798b29eb31ed7280287a92a + 4d6ca4e629785c1f01baf55e2e548566b9617ae3a96868c337cb93b5e72b1c7b +-e58f9eb643862c13ad38e529313462a7f73e62834fe54a01 + 24d7f6b6bae4e5c00d2082c5ebab3672 + edd02a39d2dbde31611c16e610be062c + 67f6ea530aea85a37dcbb23349ea52dcc61ca8493ff557252327fd8304341584 +diff --git a/src/lib/crypto/crypto_tests/t_cf2.in b/src/lib/crypto/crypto_tests/t_cf2.in +index 73e2f8fbc..c4d23b506 100644 +--- a/src/lib/crypto/crypto_tests/t_cf2.in ++++ b/src/lib/crypto/crypto_tests/t_cf2.in +@@ -8,11 +8,6 @@ key1 + key2 + a + b +-16 +-key1 +-key2 +-a +-b + 23 + key1 + key2 +diff --git a/src/lib/crypto/crypto_tests/t_cksums.c b/src/lib/crypto/crypto_tests/t_cksums.c +index 4da14ea43..84408fb68 100644 +--- a/src/lib/crypto/crypto_tests/t_cksums.c ++++ b/src/lib/crypto/crypto_tests/t_cksums.c +@@ -59,16 +59,6 @@ struct test { + "\xDA\x39\xA3\xEE\x5E\x6B\x4B\x0D\x32\x55\xBF\xEF\x95\x60\x18\x90" + "\xAF\xD8\x07\x09" } + }, +- { +- { KV5M_DATA, 9, "six seven" }, +- CKSUMTYPE_HMAC_SHA1_DES3, ENCTYPE_DES3_CBC_SHA1, 2, +- { KV5M_DATA, 24, +- "\x7A\x25\xDF\x89\x92\x29\x6D\xCE\xDA\x0E\x13\x5B\xC4\x04\x6E\x23" +- "\x75\xB3\xC1\x4C\x98\xFB\xC1\x62" }, +- { KV5M_DATA, 20, +- "\x0E\xEF\xC9\xC3\xE0\x49\xAA\xBC\x1B\xA5\xC4\x01\x67\x7D\x9A\xB6" +- "\x99\x08\x2B\xB4" } +- }, + { + { KV5M_DATA, 37, "eight nine ten eleven twelve thirteen" }, + CKSUMTYPE_HMAC_SHA1_96_AES128, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 3, +diff --git a/src/lib/crypto/crypto_tests/t_decrypt.c b/src/lib/crypto/crypto_tests/t_decrypt.c +index a40a85500..716f2c337 100644 +--- a/src/lib/crypto/crypto_tests/t_decrypt.c ++++ b/src/lib/crypto/crypto_tests/t_decrypt.c +@@ -39,62 +39,6 @@ struct test { + krb5_data keybits; + krb5_data ciphertext; + } test_cases[] = { +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 0, "", }, 0, +- { KV5M_DATA, 24, +- "\x7A\x25\xDF\x89\x92\x29\x6D\xCE\xDA\x0E\x13\x5B\xC4\x04\x6E\x23" +- "\x75\xB3\xC1\x4C\x98\xFB\xC1\x62" }, +- { KV5M_DATA, 28, +- "\x54\x8A\xF4\xD5\x04\xF7\xD7\x23\x30\x3F\x12\x17\x5F\xE8\x38\x6B" +- "\x7B\x53\x35\xA9\x67\xBA\xD6\x1F\x3B\xF0\xB1\x43" } +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 1, "1", }, 1, +- { KV5M_DATA, 24, +- "\xBC\x07\x83\x89\x15\x13\xD5\xCE\x57\xBC\x13\x8F\xD3\xC1\x1A\xE6" +- "\x40\x45\x23\x85\x32\x29\x62\xB6" }, +- { KV5M_DATA, 36, +- "\x9C\x3C\x1D\xBA\x47\x47\xD8\x5A\xF2\x91\x6E\x47\x45\xF2\xDC\xE3" +- "\x80\x46\x79\x6E\x51\x04\xBC\xCD\xFB\x66\x9A\x91\xD4\x4B\xC3\x56" +- "\x66\x09\x45\xC7" } +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 9, "9 bytesss", }, 2, +- { KV5M_DATA, 24, +- "\x2F\xD0\xF7\x25\xCE\x04\x10\x0D\x2F\xC8\xA1\x80\x98\x83\x1F\x85" +- "\x0B\x45\xD9\xEF\x85\x0B\xD9\x20" }, +- { KV5M_DATA, 44, +- "\xCF\x91\x44\xEB\xC8\x69\x79\x81\x07\x5A\x8B\xAD\x8D\x74\xE5\xD7" +- "\xD5\x91\xEB\x7D\x97\x70\xC7\xAD\xA2\x5E\xE8\xC5\xB3\xD6\x94\x44" +- "\xDF\xEC\x79\xA5\xB7\xA0\x14\x82\xD9\xAF\x74\xE6" } +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 13, "13 bytes byte", }, 3, +- { KV5M_DATA, 24, +- "\x0D\xD5\x20\x94\xE0\xF4\x1C\xEC\xCB\x5B\xE5\x10\xA7\x64\xB3\x51" +- "\x76\xE3\x98\x13\x32\xF1\xE5\x98" }, +- { KV5M_DATA, 44, +- "\x83\x9A\x17\x08\x1E\xCB\xAF\xBC\xDC\x91\xB8\x8C\x69\x55\xDD\x3C" +- "\x45\x14\x02\x3C\xF1\x77\xB7\x7B\xF0\xD0\x17\x7A\x16\xF7\x05\xE8" +- "\x49\xCB\x77\x81\xD7\x6A\x31\x6B\x19\x3F\x8D\x30" } +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 30, "30 bytes bytes bytes bytes byt", }, 4, +- { KV5M_DATA, 24, +- "\xF1\x16\x86\xCB\xBC\x9E\x23\xEA\x54\xFE\xCD\x2A\x3D\xCD\xFB\x20" +- "\xB6\xFE\x98\xBF\x26\x45\xC4\xC4" }, +- { KV5M_DATA, 60, +- "\x89\x43\x3E\x83\xFD\x0E\xA3\x66\x6C\xFF\xCD\x18\xD8\xDE\xEB\xC5" +- "\x3B\x9A\x34\xED\xBE\xB1\x59\xD9\xF6\x67\xC6\xC2\xB9\xA9\x64\x40" +- "\x1D\x55\xE7\xE9\xC6\x8D\x64\x8D\x65\xC3\xAA\x84\xFF\xA3\x79\x0C" +- "\x14\xA8\x64\xDA\x80\x73\xA9\xA9\x5C\x4B\xA2\xBC" } +- }, +- + { + ENCTYPE_ARCFOUR_HMAC, + { KV5M_DATA, 0, "", }, 0, +@@ -524,7 +468,6 @@ printhex(const char *head, void *data, size_t len) + + static krb5_enctype + enctypes[] = { +- ENCTYPE_DES3_CBC_SHA1, + ENCTYPE_ARCFOUR_HMAC, + ENCTYPE_ARCFOUR_HMAC_EXP, + ENCTYPE_AES128_CTS_HMAC_SHA1_96, +diff --git a/src/lib/crypto/crypto_tests/t_derive.c b/src/lib/crypto/crypto_tests/t_derive.c +index afbf7477f..93ce30da2 100644 +--- a/src/lib/crypto/crypto_tests/t_derive.c ++++ b/src/lib/crypto/crypto_tests/t_derive.c +@@ -38,41 +38,6 @@ struct test { + enum deriv_alg alg; + krb5_data expected_key; + } test_cases[] = { +- /* Kc, Ke, Kei for a DES3 key */ +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 24, +- "\x85\x0B\xB5\x13\x58\x54\x8C\xD0\x5E\x86\x76\x8C\x31\x3E\x3B\xFE" +- "\xF7\x51\x19\x37\xDC\xF7\x2C\x3E" }, +- { KV5M_DATA, 5, "\0\0\0\2\x99" }, +- DERIVE_RFC3961, +- { KV5M_DATA, 24, +- "\xF7\x8C\x49\x6D\x16\xE6\xC2\xDA\xE0\xE0\xB6\xC2\x40\x57\xA8\x4C" +- "\x04\x26\xAE\xEF\x26\xFD\x6D\xCE" } +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 24, +- "\x85\x0B\xB5\x13\x58\x54\x8C\xD0\x5E\x86\x76\x8C\x31\x3E\x3B\xFE" +- "\xF7\x51\x19\x37\xDC\xF7\x2C\x3E" }, +- { KV5M_DATA, 5, "\0\0\0\2\xAA" }, +- DERIVE_RFC3961, +- { KV5M_DATA, 24, +- "\x5B\x57\x23\xD0\xB6\x34\xCB\x68\x4C\x3E\xBA\x52\x64\xE9\xA7\x0D" +- "\x52\xE6\x83\x23\x1A\xD3\xC4\xCE" } +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- { KV5M_DATA, 24, +- "\x85\x0B\xB5\x13\x58\x54\x8C\xD0\x5E\x86\x76\x8C\x31\x3E\x3B\xFE" +- "\xF7\x51\x19\x37\xDC\xF7\x2C\x3E" }, +- { KV5M_DATA, 5, "\0\0\0\2\x55" }, +- DERIVE_RFC3961, +- { KV5M_DATA, 24, +- "\xA7\x7C\x94\x98\x0E\x9B\x73\x45\xA8\x15\x25\xC4\x23\xA7\x37\xCE" +- "\x67\xF4\xCD\x91\xB6\xB3\xDA\x45" } +- }, +- + /* Kc, Ke, Ki for an AES-128 key */ + { + ENCTYPE_AES128_CTS_HMAC_SHA1_96, +@@ -286,7 +251,6 @@ static const struct krb5_enc_provider * + get_enc_provider(krb5_enctype enctype) + { + switch (enctype) { +- case ENCTYPE_DES3_CBC_SHA1: return &krb5int_enc_des3; + case ENCTYPE_AES128_CTS_HMAC_SHA1_96: return &krb5int_enc_aes128; + case ENCTYPE_AES256_CTS_HMAC_SHA1_96: return &krb5int_enc_aes256; + case ENCTYPE_CAMELLIA128_CTS_CMAC: return &krb5int_enc_camellia128; +diff --git a/src/lib/crypto/crypto_tests/t_encrypt.c b/src/lib/crypto/crypto_tests/t_encrypt.c +index bd9b94691..290a72e1e 100644 +--- a/src/lib/crypto/crypto_tests/t_encrypt.c ++++ b/src/lib/crypto/crypto_tests/t_encrypt.c +@@ -37,7 +37,6 @@ + + /* What enctypes should we test?*/ + krb5_enctype interesting_enctypes[] = { +- ENCTYPE_DES3_CBC_SHA1, + ENCTYPE_ARCFOUR_HMAC, + ENCTYPE_ARCFOUR_HMAC_EXP, + ENCTYPE_AES256_CTS_HMAC_SHA1_96, +diff --git a/src/lib/crypto/crypto_tests/t_short.c b/src/lib/crypto/crypto_tests/t_short.c +index d4c2b97df..4466b7115 100644 +--- a/src/lib/crypto/crypto_tests/t_short.c ++++ b/src/lib/crypto/crypto_tests/t_short.c +@@ -34,7 +34,6 @@ + #include "k5-int.h" + + krb5_enctype interesting_enctypes[] = { +- ENCTYPE_DES3_CBC_SHA1, + ENCTYPE_ARCFOUR_HMAC, + ENCTYPE_ARCFOUR_HMAC_EXP, + ENCTYPE_AES256_CTS_HMAC_SHA1_96, +diff --git a/src/lib/crypto/crypto_tests/t_str2key.c b/src/lib/crypto/crypto_tests/t_str2key.c +index cdb1acc6d..ef4c4a7d3 100644 +--- a/src/lib/crypto/crypto_tests/t_str2key.c ++++ b/src/lib/crypto/crypto_tests/t_str2key.c +@@ -35,58 +35,6 @@ struct test { + krb5_error_code expected_err; + krb5_boolean allow_weak; + } test_cases[] = { +- /* Test vectors from RFC 3961 appendix A.4. */ +- { +- ENCTYPE_DES3_CBC_SHA1, +- "password", +- { KV5M_DATA, 21, "ATHENA.MIT.EDUraeburn" }, +- { KV5M_DATA, 0, NULL }, +- { KV5M_DATA, 24, "\x85\x0B\xB5\x13\x58\x54\x8C\xD0\x5E\x86\x76\x8C" +- "\x31\x3E\x3B\xFE\xF7\x51\x19\x37\xDC\xF7\x2C\x3E" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- "potatoe", +- { KV5M_DATA, 19, "WHITEHOUSE.GOVdanny" }, +- { KV5M_DATA, 0, NULL }, +- { KV5M_DATA, 24, "\xDF\xCD\x23\x3D\xD0\xA4\x32\x04\xEA\x6D\xC4\x37" +- "\xFB\x15\xE0\x61\xB0\x29\x79\xC1\xF7\x4F\x37\x7A" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- "penny", +- { KV5M_DATA, 19, "EXAMPLE.COMbuckaroo" }, +- { KV5M_DATA, 0, NULL }, +- { KV5M_DATA, 24, "\x6D\x2F\xCD\xF2\xD6\xFB\xBC\x3D\xDC\xAD\xB5\xDA" +- "\x57\x10\xA2\x34\x89\xB0\xD3\xB6\x9D\x5D\x9D\x4A" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- "\xC3\x9F", +- { KV5M_DATA, 23, "ATHENA.MIT.EDUJuri\xC5\xA1\x69\xC4\x87" }, +- { KV5M_DATA, 0, NULL }, +- { KV5M_DATA, 24, "\x16\xD5\xA4\x0E\x1C\xE3\xBA\xCB\x61\xB9\xDC\xE0" +- "\x04\x70\x32\x4C\x83\x19\x73\xA7\xB9\x52\xFE\xB0" }, +- 0, +- FALSE +- }, +- { +- ENCTYPE_DES3_CBC_SHA1, +- "\xF0\x9D\x84\x9E", +- { KV5M_DATA, 18, "EXAMPLE.COMpianist" }, +- { KV5M_DATA, 0, NULL }, +- { KV5M_DATA, 24, "\x85\x76\x37\x26\x58\x5D\xBC\x1C\xCE\x6E\xC4\x3E" +- "\x1F\x75\x1F\x07\xF1\xC4\xCB\xB0\x98\xF4\x0B\x19" }, +- 0, +- FALSE +- }, +- + /* Test vectors from RFC 3962 appendix B. */ + { + ENCTYPE_AES128_CTS_HMAC_SHA1_96, +diff --git a/src/lib/crypto/krb/Makefile.in b/src/lib/crypto/krb/Makefile.in +index 536bacb6e..b587f7e19 100644 +--- a/src/lib/crypto/krb/Makefile.in ++++ b/src/lib/crypto/krb/Makefile.in +@@ -52,7 +52,6 @@ STLIBOBJS=\ + prf.o \ + prf_aes2.o \ + prf_cmac.o \ +- prf_des.o \ + prf_dk.o \ + prf_rc4.o \ + prng.o \ +@@ -113,7 +112,6 @@ OBJS=\ + $(OUTPRE)prf.$(OBJEXT) \ + $(OUTPRE)prf_aes2.$(OBJEXT) \ + $(OUTPRE)prf_cmac.$(OBJEXT) \ +- $(OUTPRE)prf_des.$(OBJEXT) \ + $(OUTPRE)prf_dk.$(OBJEXT) \ + $(OUTPRE)prf_rc4.$(OBJEXT) \ + $(OUTPRE)prng.$(OBJEXT) \ +@@ -174,7 +172,6 @@ SRCS=\ + $(srcdir)/prf.c \ + $(srcdir)/prf_aes2.c \ + $(srcdir)/prf_cmac.c \ +- $(srcdir)/prf_des.c \ + $(srcdir)/prf_dk.c \ + $(srcdir)/prf_rc4.c \ + $(srcdir)/prng.c \ +diff --git a/src/lib/crypto/krb/cksumtypes.c b/src/lib/crypto/krb/cksumtypes.c +index ecc2e08c9..f5fbe8a2a 100644 +--- a/src/lib/crypto/krb/cksumtypes.c ++++ b/src/lib/crypto/krb/cksumtypes.c +@@ -46,12 +46,6 @@ const struct krb5_cksumtypes krb5int_cksumtypes_list[] = { + krb5int_unkeyed_checksum, NULL, + 20, 20, CKSUM_UNKEYED }, + +- { CKSUMTYPE_HMAC_SHA1_DES3, +- "hmac-sha1-des3", { "hmac-sha1-des3-kd" }, "HMAC-SHA1 DES3 key", +- &krb5int_enc_des3, &krb5int_hash_sha1, +- krb5int_dk_checksum, NULL, +- 20, 20, 0 }, +- + { CKSUMTYPE_HMAC_MD5_ARCFOUR, + "hmac-md5-rc4", { "hmac-md5-enc", "hmac-md5-earcfour" }, + "Microsoft HMAC MD5", +diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h +index b18d5e2e3..1b4324d71 100644 +--- a/src/lib/crypto/krb/crypto_int.h ++++ b/src/lib/crypto/krb/crypto_int.h +@@ -276,10 +276,6 @@ krb5_error_code krb5int_aes2_string_to_key(const struct krb5_keytypes *enc, + /* Random to key */ + krb5_error_code k5_rand2key_direct(const krb5_data *randombits, + krb5_keyblock *keyblock); +-krb5_error_code k5_rand2key_des(const krb5_data *randombits, +- krb5_keyblock *keyblock); +-krb5_error_code k5_rand2key_des3(const krb5_data *randombits, +- krb5_keyblock *keyblock); + + /* Pseudo-random function */ + krb5_error_code krb5int_des_prf(const struct krb5_keytypes *ktp, +@@ -384,11 +380,6 @@ krb5_keyusage krb5int_arcfour_translate_usage(krb5_keyusage usage); + /* Ensure library initialization has occurred. */ + int krb5int_crypto_init(void); + +-/* DES default state initialization handler (used by module enc providers). */ +-krb5_error_code krb5int_des_init_state(const krb5_keyblock *key, +- krb5_keyusage keyusage, +- krb5_data *state_out); +- + /* Default state cleanup handler (used by module enc providers). */ + void krb5int_default_free_state(krb5_data *state); + +@@ -441,7 +432,6 @@ void k5_iov_cursor_put(struct iov_cursor *cursor, unsigned char *block); + /* Modules must implement the k5_sha256() function prototyped in k5-int.h. */ + + /* Modules must implement the following enc_providers and hash_providers: */ +-extern const struct krb5_enc_provider krb5int_enc_des3; + extern const struct krb5_enc_provider krb5int_enc_arcfour; + extern const struct krb5_enc_provider krb5int_enc_aes128; + extern const struct krb5_enc_provider krb5int_enc_aes256; +@@ -458,12 +448,6 @@ extern const struct krb5_hash_provider krb5int_hash_sha384; + + /* Modules must implement the following functions. */ + +-/* Set the parity bits to the correct values in keybits. */ +-void k5_des_fixup_key_parity(unsigned char *keybits); +- +-/* Return true if keybits is a weak or semi-weak DES key. */ +-krb5_boolean k5_des_is_weak_key(unsigned char *keybits); +- + /* Compute an HMAC using the provided hash function, key, and data, storing the + * result into output (caller-allocated). */ + krb5_error_code krb5int_hmac(const struct krb5_hash_provider *hash, +diff --git a/src/lib/crypto/krb/default_state.c b/src/lib/crypto/krb/default_state.c +index 0757c8b02..f89dc7902 100644 +--- a/src/lib/crypto/krb/default_state.c ++++ b/src/lib/crypto/krb/default_state.c +@@ -32,16 +32,6 @@ + + #include "crypto_int.h" + +-krb5_error_code +-krb5int_des_init_state(const krb5_keyblock *key, krb5_keyusage usage, +- krb5_data *state_out) +-{ +- if (alloc_data(state_out, 8)) +- return ENOMEM; +- +- return 0; +-} +- + void + krb5int_default_free_state(krb5_data *state) + { +diff --git a/src/lib/crypto/krb/enctype_util.c b/src/lib/crypto/krb/enctype_util.c +index 1542d4062..a0037912a 100644 +--- a/src/lib/crypto/krb/enctype_util.c ++++ b/src/lib/crypto/krb/enctype_util.c +@@ -45,6 +45,9 @@ struct { + { ENCTYPE_DES_CBC_MD5, "des-cbc-md5" }, + { ENCTYPE_DES_CBC_RAW, "des-cbc-raw" }, + { ENCTYPE_DES_HMAC_SHA1, "des-hmac-sha1" }, ++ { ENCTYPE_DES3_CBC_SHA, "des3-cbc-sha1" }, ++ { ENCTYPE_DES3_CBC_RAW, "des3-cbc-raw" }, ++ { ENCTYPE_DES3_CBC_SHA1, "des3-hmac-sha1" }, + { ENCTYPE_NULL, NULL } + }; + +diff --git a/src/lib/crypto/krb/etypes.c b/src/lib/crypto/krb/etypes.c +index fc278783b..7635393a4 100644 +--- a/src/lib/crypto/krb/etypes.c ++++ b/src/lib/crypto/krb/etypes.c +@@ -35,27 +35,6 @@ + + /* Deprecations come from RFC 6649 and RFC 8249. */ + const struct krb5_keytypes krb5int_enctypes_list[] = { +- { ENCTYPE_DES3_CBC_RAW, +- "des3-cbc-raw", { 0 }, "Triple DES cbc mode raw", +- &krb5int_enc_des3, NULL, +- 16, +- krb5int_raw_crypto_length, krb5int_raw_encrypt, krb5int_raw_decrypt, +- krb5int_dk_string_to_key, k5_rand2key_des3, +- NULL, /*PRF*/ +- 0, +- ETYPE_WEAK | ETYPE_DEPRECATED, 112 }, +- +- { ENCTYPE_DES3_CBC_SHA1, +- "des3-cbc-sha1", { "des3-hmac-sha1", "des3-cbc-sha1-kd" }, +- "Triple DES cbc mode with HMAC/sha1", +- &krb5int_enc_des3, &krb5int_hash_sha1, +- 16, +- krb5int_dk_crypto_length, krb5int_dk_encrypt, krb5int_dk_decrypt, +- krb5int_dk_string_to_key, k5_rand2key_des3, +- krb5int_dk_prf, +- CKSUMTYPE_HMAC_SHA1_DES3, +- ETYPE_DEPRECATED, 112 }, +- + /* rc4-hmac uses a 128-bit key, but due to weaknesses in the RC4 cipher, we + * consider its strength degraded and assign it an SSF value of 64. */ + { ENCTYPE_ARCFOUR_HMAC, +diff --git a/src/lib/crypto/krb/prf_des.c b/src/lib/crypto/krb/prf_des.c +deleted file mode 100644 +index 7a2d719c5..000000000 +--- a/src/lib/crypto/krb/prf_des.c ++++ /dev/null +@@ -1,47 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/krb/prf_des.c - RFC 3961 DES-based PRF */ +-/* +- * Copyright (C) 2004, 2009 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-#include "crypto_int.h" +- +-krb5_error_code +-krb5int_des_prf(const struct krb5_keytypes *ktp, krb5_key key, +- const krb5_data *in, krb5_data *out) +-{ +- const struct krb5_hash_provider *hash = &krb5int_hash_md5; +- krb5_crypto_iov iov; +- krb5_error_code ret; +- +- /* Compute a hash of the input, storing into the output buffer. */ +- iov.flags = KRB5_CRYPTO_TYPE_DATA; +- iov.data = *in; +- ret = hash->hash(&iov, 1, out); +- if (ret != 0) +- return ret; +- +- /* Encrypt the hash in place. */ +- iov.data = *out; +- return ktp->enc->encrypt(key, NULL, &iov, 1); +-} +diff --git a/src/lib/crypto/krb/random_to_key.c b/src/lib/crypto/krb/random_to_key.c +index 157462526..863090beb 100644 +--- a/src/lib/crypto/krb/random_to_key.c ++++ b/src/lib/crypto/krb/random_to_key.c +@@ -71,48 +71,3 @@ k5_rand2key_direct(const krb5_data *randombits, krb5_keyblock *keyblock) + memcpy(keyblock->contents, randombits->data, randombits->length); + return 0; + } +- +-static inline void +-eighth_byte(unsigned char *b) +-{ +- b[7] = (((b[0] & 1) << 1) | ((b[1] & 1) << 2) | ((b[2] & 1) << 3) | +- ((b[3] & 1) << 4) | ((b[4] & 1) << 5) | ((b[5] & 1) << 6) | +- ((b[6] & 1) << 7)); +-} +- +-krb5_error_code +-k5_rand2key_des(const krb5_data *randombits, krb5_keyblock *keyblock) +-{ +- if (randombits->length != 7) +- return(KRB5_CRYPTO_INTERNAL); +- +- keyblock->magic = KV5M_KEYBLOCK; +- +- /* Take the seven bytes, move them around into the top 7 bits of the +- * 8 key bytes, then compute the parity bits. */ +- memcpy(keyblock->contents, randombits->data, randombits->length); +- eighth_byte(keyblock->contents); +- k5_des_fixup_key_parity(keyblock->contents); +- +- return 0; +-} +- +-krb5_error_code +-k5_rand2key_des3(const krb5_data *randombits, krb5_keyblock *keyblock) +-{ +- int i; +- +- if (randombits->length != 21) +- return KRB5_CRYPTO_INTERNAL; +- +- keyblock->magic = KV5M_KEYBLOCK; +- +- /* Take the seven bytes, move them around into the top 7 bits of the +- * 8 key bytes, then compute the parity bits. Do this three times. */ +- for (i = 0; i < 3; i++) { +- memcpy(&keyblock->contents[i * 8], &randombits->data[i * 7], 7); +- eighth_byte(&keyblock->contents[i * 8]); +- k5_des_fixup_key_parity(&keyblock->contents[i * 8]); +- } +- return 0; +-} +diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports +index 451d5e035..9db181381 100644 +--- a/src/lib/crypto/libk5crypto.exports ++++ b/src/lib/crypto/libk5crypto.exports +@@ -86,7 +86,6 @@ krb5_k_verify_checksum + krb5_k_verify_checksum_iov + krb5int_aes_encrypt + krb5int_aes_decrypt +-krb5int_enc_des3 + krb5int_arcfour_gsscrypt + krb5int_camellia_cbc_mac + krb5int_cmac_checksum +diff --git a/src/lib/crypto/openssl/Makefile.in b/src/lib/crypto/openssl/Makefile.in +index aa434b168..234fc0e76 100644 +--- a/src/lib/crypto/openssl/Makefile.in ++++ b/src/lib/crypto/openssl/Makefile.in +@@ -1,6 +1,6 @@ + mydir=lib$(S)crypto$(S)openssl + BUILDTOP=$(REL)..$(S)..$(S).. +-SUBDIRS=camellia des aes md4 md5 sha1 sha2 enc_provider hash_provider ++SUBDIRS=camellia aes md4 md5 sha1 sha2 enc_provider hash_provider + LOCALINCLUDES = -I$(srcdir)/../krb -I$(srcdir) + + STLIBOBJS=\ +@@ -24,14 +24,14 @@ SRCS=\ + $(srcdir)/sha256.c \ + $(srcdir)/stubs.c + +-STOBJLISTS= des/OBJS.ST md4/OBJS.ST \ ++STOBJLISTS= md4/OBJS.ST \ + md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \ + enc_provider/OBJS.ST \ + hash_provider/OBJS.ST \ + aes/OBJS.ST \ + OBJS.ST + +-SUBDIROBJLISTS= des/OBJS.ST md4/OBJS.ST \ ++SUBDIROBJLISTS= md4/OBJS.ST \ + md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \ + enc_provider/OBJS.ST \ + hash_provider/OBJS.ST \ +@@ -42,7 +42,7 @@ includes: depend + + depend: $(SRCS) + +-clean-unix:: clean-libobjs ++clean-unix:: clean-libobjsn + + @lib_frag@ + @libobj_frag@ +diff --git a/src/lib/crypto/openssl/des/Makefile.in b/src/lib/crypto/openssl/des/Makefile.in +deleted file mode 100644 +index 4392fb8ea..000000000 +--- a/src/lib/crypto/openssl/des/Makefile.in ++++ /dev/null +@@ -1,20 +0,0 @@ +-mydir=lib$(S)crypto$(S)openssl$(S)des +-BUILDTOP=$(REL)..$(S)..$(S)..$(S).. +-LOCALINCLUDES = -I$(srcdir)/../../krb -I$(srcdir)/.. +- +-STLIBOBJS= des_keys.o +- +-OBJS= $(OUTPRE)des_keys.$(OBJEXT) +- +-SRCS= $(srcdir)/des_keys.c +- +-all-unix: all-libobjs +- +-includes: depend +- +-depend: $(SRCS) +- +-clean-unix:: clean-libobjs +- +-@libobj_frag@ +- +diff --git a/src/lib/crypto/openssl/des/deps b/src/lib/crypto/openssl/des/deps +deleted file mode 100644 +index 21b904f89..000000000 +--- a/src/lib/crypto/openssl/des/deps ++++ /dev/null +@@ -1,15 +0,0 @@ +-# +-# Generated makefile dependencies follow. +-# +-des_keys.so des_keys.po $(OUTPRE)des_keys.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(srcdir)/../crypto_mod.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des_keys.c +diff --git a/src/lib/crypto/openssl/des/des_keys.c b/src/lib/crypto/openssl/des/des_keys.c +deleted file mode 100644 +index 51d9db216..000000000 +--- a/src/lib/crypto/openssl/des/des_keys.c ++++ /dev/null +@@ -1,40 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/openssl/des/des_keys.c - Key functions used by Kerberos code */ +-/* +- * Copyright (C) 2011 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-#include "crypto_int.h" +-#include +- +-void +-k5_des_fixup_key_parity(unsigned char *keybits) +-{ +- DES_set_odd_parity((DES_cblock *)keybits); +-} +- +-krb5_boolean +-k5_des_is_weak_key(unsigned char *keybits) +-{ +- return DES_is_weak_key((DES_cblock *)keybits); +-} +diff --git a/src/lib/crypto/openssl/enc_provider/Makefile.in b/src/lib/crypto/openssl/enc_provider/Makefile.in +index a9069d22d..2b32c3ac4 100644 +--- a/src/lib/crypto/openssl/enc_provider/Makefile.in ++++ b/src/lib/crypto/openssl/enc_provider/Makefile.in +@@ -3,19 +3,16 @@ BUILDTOP=$(REL)..$(S)..$(S)..$(S).. + LOCALINCLUDES = -I$(srcdir)/../../krb -I$(srcdir)/.. + + STLIBOBJS= \ +- des3.o \ + rc4.o \ + aes.o \ + camellia.o + + OBJS= \ +- $(OUTPRE)des3.$(OBJEXT) \ + $(OUTPRE)aes.$(OBJEXT) \ + $(OUTPRE)camellia.$(OBJEXT) \ + $(OUTPRE)rc4.$(OBJEXT) + + SRCS= \ +- $(srcdir)/des3.c \ + $(srcdir)/aes.c \ + $(srcdir)/camellia.c \ + $(srcdir)/rc4.c +diff --git a/src/lib/crypto/openssl/enc_provider/deps b/src/lib/crypto/openssl/enc_provider/deps +index 1c28cc842..91ba48234 100644 +--- a/src/lib/crypto/openssl/enc_provider/deps ++++ b/src/lib/crypto/openssl/enc_provider/deps +@@ -1,17 +1,6 @@ + # + # Generated makefile dependencies follow. + # +-des3.so des3.po $(OUTPRE)des3.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +- $(srcdir)/../crypto_mod.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des3.c + aes.so aes.po $(OUTPRE)aes.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ + $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +diff --git a/src/lib/crypto/openssl/enc_provider/des3.c b/src/lib/crypto/openssl/enc_provider/des3.c +deleted file mode 100644 +index 1c439c2cd..000000000 +--- a/src/lib/crypto/openssl/enc_provider/des3.c ++++ /dev/null +@@ -1,184 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/openssl/enc_provider/des3.c */ +-/* +- * Copyright (C) 2009 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +-/* +- * Copyright (C) 1998 by the FundsXpress, INC. +- * +- * All rights reserved. +- * +- * Export of this software from the United States of America may require +- * a specific license from the United States Government. It is the +- * responsibility of any person or organization contemplating export to +- * obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of FundsXpress. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. FundsXpress makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- * +- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR +- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED +- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. +- */ +- +-#include "crypto_int.h" +-#include +- +- +-#define DES3_BLOCK_SIZE 8 +-#define DES3_KEY_SIZE 24 +-#define DES3_KEY_BYTES 21 +- +-static krb5_error_code +-validate(krb5_key key, const krb5_data *ivec, const krb5_crypto_iov *data, +- size_t num_data, krb5_boolean *empty) +-{ +- size_t input_length = iov_total_length(data, num_data, FALSE); +- +- if (key->keyblock.length != DES3_KEY_SIZE) +- return(KRB5_BAD_KEYSIZE); +- if ((input_length%DES3_BLOCK_SIZE) != 0) +- return(KRB5_BAD_MSIZE); +- if (ivec && (ivec->length != 8)) +- return(KRB5_BAD_MSIZE); +- +- *empty = (input_length == 0); +- return 0; +-} +- +-static krb5_error_code +-k5_des3_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, +- size_t num_data) +-{ +- int ret, olen = DES3_BLOCK_SIZE; +- unsigned char iblock[DES3_BLOCK_SIZE], oblock[DES3_BLOCK_SIZE]; +- struct iov_cursor cursor; +- EVP_CIPHER_CTX *ctx; +- krb5_boolean empty; +- +- ret = validate(key, ivec, data, num_data, &empty); +- if (ret != 0 || empty) +- return ret; +- +- ctx = EVP_CIPHER_CTX_new(); +- if (ctx == NULL) +- return ENOMEM; +- +- ret = EVP_EncryptInit_ex(ctx, EVP_des_ede3_cbc(), NULL, +- key->keyblock.contents, +- (ivec) ? (unsigned char*)ivec->data : NULL); +- if (!ret) { +- EVP_CIPHER_CTX_free(ctx); +- return KRB5_CRYPTO_INTERNAL; +- } +- +- EVP_CIPHER_CTX_set_padding(ctx,0); +- +- k5_iov_cursor_init(&cursor, data, num_data, DES3_BLOCK_SIZE, FALSE); +- while (k5_iov_cursor_get(&cursor, iblock)) { +- ret = EVP_EncryptUpdate(ctx, oblock, &olen, iblock, DES3_BLOCK_SIZE); +- if (!ret) +- break; +- k5_iov_cursor_put(&cursor, oblock); +- } +- +- if (ivec != NULL) +- memcpy(ivec->data, oblock, DES3_BLOCK_SIZE); +- +- EVP_CIPHER_CTX_free(ctx); +- +- zap(iblock, sizeof(iblock)); +- zap(oblock, sizeof(oblock)); +- +- if (ret != 1) +- return KRB5_CRYPTO_INTERNAL; +- return 0; +-} +- +-static krb5_error_code +-k5_des3_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, +- size_t num_data) +-{ +- int ret, olen = DES3_BLOCK_SIZE; +- unsigned char iblock[DES3_BLOCK_SIZE], oblock[DES3_BLOCK_SIZE]; +- struct iov_cursor cursor; +- EVP_CIPHER_CTX *ctx; +- krb5_boolean empty; +- +- ret = validate(key, ivec, data, num_data, &empty); +- if (ret != 0 || empty) +- return ret; +- +- ctx = EVP_CIPHER_CTX_new(); +- if (ctx == NULL) +- return ENOMEM; +- +- ret = EVP_DecryptInit_ex(ctx, EVP_des_ede3_cbc(), NULL, +- key->keyblock.contents, +- (ivec) ? (unsigned char*)ivec->data : NULL); +- if (!ret) { +- EVP_CIPHER_CTX_free(ctx); +- return KRB5_CRYPTO_INTERNAL; +- } +- +- EVP_CIPHER_CTX_set_padding(ctx,0); +- +- k5_iov_cursor_init(&cursor, data, num_data, DES3_BLOCK_SIZE, FALSE); +- while (k5_iov_cursor_get(&cursor, iblock)) { +- ret = EVP_DecryptUpdate(ctx, oblock, &olen, +- (unsigned char *)iblock, DES3_BLOCK_SIZE); +- if (!ret) +- break; +- k5_iov_cursor_put(&cursor, oblock); +- } +- +- if (ivec != NULL) +- memcpy(ivec->data, iblock, DES3_BLOCK_SIZE); +- +- EVP_CIPHER_CTX_free(ctx); +- +- zap(iblock, sizeof(iblock)); +- zap(oblock, sizeof(oblock)); +- +- if (ret != 1) +- return KRB5_CRYPTO_INTERNAL; +- return 0; +-} +- +-const struct krb5_enc_provider krb5int_enc_des3 = { +- DES3_BLOCK_SIZE, +- DES3_KEY_BYTES, DES3_KEY_SIZE, +- k5_des3_encrypt, +- k5_des3_decrypt, +- NULL, +- krb5int_des_init_state, +- krb5int_default_free_state +-}; +diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c +index 439ae6aeb..d8e0f93a1 100644 +--- a/src/lib/gssapi/krb5/accept_sec_context.c ++++ b/src/lib/gssapi/krb5/accept_sec_context.c +@@ -1011,7 +1011,6 @@ kg_accept_krb5(minor_status, context_handle, + } + + switch (negotiated_etype) { +- case ENCTYPE_DES3_CBC_SHA1: + case ENCTYPE_ARCFOUR_HMAC: + case ENCTYPE_ARCFOUR_HMAC_EXP: + /* RFC 4121 accidentally omits RC4-HMAC-EXP as a "not-newer" +diff --git a/src/lib/gssapi/krb5/gssapiP_krb5.h b/src/lib/gssapi/krb5/gssapiP_krb5.h +index 2647434ba..1cdd23cc8 100644 +--- a/src/lib/gssapi/krb5/gssapiP_krb5.h ++++ b/src/lib/gssapi/krb5/gssapiP_krb5.h +@@ -125,14 +125,14 @@ enum sgn_alg { + /* SGN_ALG_DES_MAC = 0x0002, */ + /* SGN_ALG_3 = 0x0003, /\* not published *\/ */ + SGN_ALG_HMAC_MD5 = 0x0011, /* microsoft w2k; */ +- SGN_ALG_HMAC_SHA1_DES3_KD = 0x0004 ++ /* SGN_ALG_HMAC_SHA1_DES3_KD = 0x0004 */ + }; + enum seal_alg { + SEAL_ALG_NONE = 0xffff, + /* SEAL_ALG_DES = 0x0000, */ + /* SEAL_ALG_1 = 0x0001, /\* not published *\/ */ + SEAL_ALG_MICROSOFT_RC4 = 0x0010, /* microsoft w2k; */ +- SEAL_ALG_DES3KD = 0x0002 ++ /* SEAL_ALG_DES3KD = 0x0002 */ + }; + + /* for 3DES */ +@@ -153,7 +153,7 @@ enum qop { + GSS_KRB5_INTEG_C_QOP_HMAC_SHA1 = 0x0004, + GSS_KRB5_INTEG_C_QOP_MASK = 0x00ff, + /* GSS_KRB5_CONF_C_QOP_DES = 0x0100, */ +- GSS_KRB5_CONF_C_QOP_DES3_KD = 0x0200, ++ /* GSS_KRB5_CONF_C_QOP_DES3_KD = 0x0200, */ + GSS_KRB5_CONF_C_QOP_MASK = 0xff00 + }; + +diff --git a/src/lib/gssapi/krb5/k5seal.c b/src/lib/gssapi/krb5/k5seal.c +index d1cdce486..7f7146a0a 100644 +--- a/src/lib/gssapi/krb5/k5seal.c ++++ b/src/lib/gssapi/krb5/k5seal.c +@@ -136,19 +136,12 @@ make_seal_token_v1 (krb5_context context, + + /* pad the plaintext, encrypt if needed, and stick it in the token */ + +- /* initialize the the checksum */ +- switch (signalg) { +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_SHA1_DES3; +- break; +- case SGN_ALG_HMAC_MD5: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; +- if (toktype != KG_TOK_SEAL_MSG) +- sign_usage = 15; +- break; +- default: +- abort (); +- } ++ if (signalg != SGN_ALG_HMAC_MD5) ++ abort(); ++ ++ md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; ++ if (toktype != KG_TOK_SEAL_MSG) ++ sign_usage = 15; + + code = krb5_c_checksum_length(context, md5cksum.checksum_type, &sumlen); + if (code) { +@@ -196,20 +189,8 @@ make_seal_token_v1 (krb5_context context, + gssalloc_free(t); + return(code); + } +- switch(signalg) { +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- /* +- * Using key derivation, the call to krb5_c_make_checksum +- * already dealt with encrypting. +- */ +- if (md5cksum.length != cksum_size) +- abort (); +- memcpy (ptr+14, md5cksum.contents, md5cksum.length); +- break; +- case SGN_ALG_HMAC_MD5: +- memcpy (ptr+14, md5cksum.contents, cksum_size); +- break; +- } ++ ++ memcpy (ptr+14, md5cksum.contents, cksum_size); + + krb5_free_checksum_contents(context, &md5cksum); + +diff --git a/src/lib/gssapi/krb5/k5sealiov.c b/src/lib/gssapi/krb5/k5sealiov.c +index 9bb2ee109..9147bb2c7 100644 +--- a/src/lib/gssapi/krb5/k5sealiov.c ++++ b/src/lib/gssapi/krb5/k5sealiov.c +@@ -144,18 +144,11 @@ make_seal_token_v1_iov(krb5_context context, + /* pad the plaintext, encrypt if needed, and stick it in the token */ + + /* initialize the checksum */ +- switch (ctx->signalg) { +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_SHA1_DES3; +- break; +- case SGN_ALG_HMAC_MD5: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; +- if (toktype != KG_TOK_WRAP_MSG) +- sign_usage = 15; +- break; +- default: +- abort (); +- } ++ if (ctx->signalg != SGN_ALG_HMAC_MD5) ++ abort(); ++ md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; ++ if (toktype != KG_TOK_WRAP_MSG) ++ sign_usage = 15; + + code = krb5_c_checksum_length(context, md5cksum.checksum_type, &k5_trailerlen); + if (code != 0) +@@ -177,15 +170,7 @@ make_seal_token_v1_iov(krb5_context context, + if (code != 0) + goto cleanup; + +- switch (ctx->signalg) { +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- assert(md5cksum.length == ctx->cksum_size); +- memcpy(ptr + 14, md5cksum.contents, md5cksum.length); +- break; +- case SGN_ALG_HMAC_MD5: +- memcpy(ptr + 14, md5cksum.contents, ctx->cksum_size); +- break; +- } ++ memcpy(ptr + 14, md5cksum.contents, ctx->cksum_size); + + /* create the seq_num */ + code = kg_make_seq_num(context, ctx->seq, ctx->initiate ? 0 : 0xFF, +diff --git a/src/lib/gssapi/krb5/k5unseal.c b/src/lib/gssapi/krb5/k5unseal.c +index 9b183bc33..f0cc4a680 100644 +--- a/src/lib/gssapi/krb5/k5unseal.c ++++ b/src/lib/gssapi/krb5/k5unseal.c +@@ -131,28 +131,21 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, + but few enough that we can try them all. */ + + if ((ctx->sealalg == SEAL_ALG_NONE && signalg > 1) || +- (ctx->sealalg == SEAL_ALG_DES3KD && +- signalg != SGN_ALG_HMAC_SHA1_DES3_KD)|| + (ctx->sealalg == SEAL_ALG_MICROSOFT_RC4 && + signalg != SGN_ALG_HMAC_MD5)) { + *minor_status = 0; + return GSS_S_DEFECTIVE_TOKEN; + } + +- switch (signalg) { +- case SGN_ALG_HMAC_MD5: +- cksum_len = 8; +- if (toktype != KG_TOK_SEAL_MSG) +- sign_usage = 15; +- break; +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- cksum_len = 20; +- break; +- default: ++ if (signalg != SGN_ALG_HMAC_MD5) { + *minor_status = 0; + return GSS_S_DEFECTIVE_TOKEN; + } + ++ cksum_len = 8; ++ if (toktype != KG_TOK_SEAL_MSG) ++ sign_usage = 15; ++ + if ((size_t)bodysize < 14 + cksum_len) { + *minor_status = 0; + return GSS_S_DEFECTIVE_TOKEN; +@@ -252,64 +245,53 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, + /* compute the checksum of the message */ + + /* initialize the the cksum */ +- switch (signalg) { +- case SGN_ALG_HMAC_MD5: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; +- break; +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_SHA1_DES3; +- break; +- default: +- abort (); +- } ++ if (signalg != SGN_ALG_HMAC_MD5) ++ abort(); ++ md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; + + code = krb5_c_checksum_length(context, md5cksum.checksum_type, &sumlen); + if (code) + return(code); + md5cksum.length = sumlen; + +- switch (signalg) { +- default: ++ if (signalg != SGN_ALG_HMAC_MD5) { + *minor_status = 0; + return(GSS_S_DEFECTIVE_TOKEN); +- +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- case SGN_ALG_HMAC_MD5: +- /* compute the checksum of the message */ +- +- /* 8 = bytes of token body to be checksummed according to spec */ +- +- if (! (data_ptr = xmalloc(8 + plainlen))) { +- if (sealalg != 0xffff) +- xfree(plain); +- if (toktype == KG_TOK_SEAL_MSG) +- gssalloc_free(token.value); +- *minor_status = ENOMEM; +- return(GSS_S_FAILURE); +- } +- +- (void) memcpy(data_ptr, ptr-2, 8); +- +- (void) memcpy(data_ptr+8, plain, plainlen); +- +- plaind.length = 8 + plainlen; +- plaind.data = data_ptr; +- code = krb5_k_make_checksum(context, md5cksum.checksum_type, +- ctx->seq, sign_usage, +- &plaind, &md5cksum); +- xfree(data_ptr); +- +- if (code) { +- if (toktype == KG_TOK_SEAL_MSG) +- gssalloc_free(token.value); +- *minor_status = code; +- return(GSS_S_FAILURE); +- } +- +- code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); +- break; + } + ++ /* compute the checksum of the message */ ++ ++ /* 8 = bytes of token body to be checksummed according to spec */ ++ ++ if (! (data_ptr = xmalloc(8 + plainlen))) { ++ if (sealalg != 0xffff) ++ xfree(plain); ++ if (toktype == KG_TOK_SEAL_MSG) ++ gssalloc_free(token.value); ++ *minor_status = ENOMEM; ++ return(GSS_S_FAILURE); ++ } ++ ++ (void) memcpy(data_ptr, ptr-2, 8); ++ ++ (void) memcpy(data_ptr+8, plain, plainlen); ++ ++ plaind.length = 8 + plainlen; ++ plaind.data = data_ptr; ++ code = krb5_k_make_checksum(context, md5cksum.checksum_type, ++ ctx->seq, sign_usage, ++ &plaind, &md5cksum); ++ xfree(data_ptr); ++ ++ if (code) { ++ if (toktype == KG_TOK_SEAL_MSG) ++ gssalloc_free(token.value); ++ *minor_status = code; ++ return(GSS_S_FAILURE); ++ } ++ ++ code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); ++ + krb5_free_checksum_contents(context, &md5cksum); + if (sealalg != 0xffff) + xfree(plain); +diff --git a/src/lib/gssapi/krb5/k5unsealiov.c b/src/lib/gssapi/krb5/k5unsealiov.c +index 85a9574f3..3ce2a90ce 100644 +--- a/src/lib/gssapi/krb5/k5unsealiov.c ++++ b/src/lib/gssapi/krb5/k5unsealiov.c +@@ -102,28 +102,21 @@ kg_unseal_v1_iov(krb5_context context, + } + + if ((ctx->sealalg == SEAL_ALG_NONE && signalg > 1) || +- (ctx->sealalg == SEAL_ALG_DES3KD && +- signalg != SGN_ALG_HMAC_SHA1_DES3_KD)|| + (ctx->sealalg == SEAL_ALG_MICROSOFT_RC4 && + signalg != SGN_ALG_HMAC_MD5)) { + *minor_status = 0; + return GSS_S_DEFECTIVE_TOKEN; + } + +- switch (signalg) { +- case SGN_ALG_HMAC_MD5: +- cksum_len = 8; +- if (toktype != KG_TOK_WRAP_MSG) +- sign_usage = 15; +- break; +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- cksum_len = 20; +- break; +- default: ++ if (signalg != SGN_ALG_HMAC_MD5) { + *minor_status = 0; + return GSS_S_DEFECTIVE_TOKEN; + } + ++ cksum_len = 8; ++ if (toktype != KG_TOK_WRAP_MSG) ++ sign_usage = 15; ++ + /* get the token parameters */ + code = kg_get_seq_num(context, ctx->seq, ptr + 14, ptr + 6, &direction, + &seqnum); +@@ -181,16 +174,10 @@ kg_unseal_v1_iov(krb5_context context, + + /* initialize the checksum */ + +- switch (signalg) { +- case SGN_ALG_HMAC_MD5: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; +- break; +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- md5cksum.checksum_type = CKSUMTYPE_HMAC_SHA1_DES3; +- break; +- default: ++ if (signalg != SGN_ALG_HMAC_MD5) + abort(); +- } ++ ++ md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; + + code = krb5_c_checksum_length(context, md5cksum.checksum_type, &sumlen); + if (code != 0) { +@@ -209,18 +196,13 @@ kg_unseal_v1_iov(krb5_context context, + goto cleanup; + } + +- switch (signalg) { +- case SGN_ALG_HMAC_SHA1_DES3_KD: +- case SGN_ALG_HMAC_MD5: +- code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); +- break; +- default: ++ if (signalg != SGN_ALG_HMAC_MD5) { + code = 0; + retval = GSS_S_DEFECTIVE_TOKEN; + goto cleanup; +- break; + } + ++ code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); + if (code != 0) { + code = 0; + retval = GSS_S_BAD_SIG; +diff --git a/src/lib/gssapi/krb5/util_crypt.c b/src/lib/gssapi/krb5/util_crypt.c +index 80954aff7..f7d3e92c4 100644 +--- a/src/lib/gssapi/krb5/util_crypt.c ++++ b/src/lib/gssapi/krb5/util_crypt.c +@@ -97,17 +97,6 @@ kg_setup_keys(krb5_context context, krb5_gss_ctx_id_rec *ctx, krb5_key subkey, + return code; + + switch (subkey->keyblock.enctype) { +- case ENCTYPE_DES3_CBC_SHA1: +- code = kg_copy_keys(context, ctx, subkey); +- if (code != 0) +- return code; +- +- ctx->enc->keyblock.enctype = ENCTYPE_DES3_CBC_RAW; +- ctx->seq->keyblock.enctype = ENCTYPE_DES3_CBC_RAW; +- ctx->signalg = SGN_ALG_HMAC_SHA1_DES3_KD; +- ctx->cksum_size = 20; +- ctx->sealalg = SEAL_ALG_DES3KD; +- break; + case ENCTYPE_ARCFOUR_HMAC: + case ENCTYPE_ARCFOUR_HMAC_EXP: + /* RFC 4121 accidentally omits RC4-HMAC-EXP as a "not-newer" enctype, +diff --git a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp +index 740425c69..6b45f5f72 100644 +--- a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp ++++ b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp +@@ -53,10 +53,10 @@ proc test200 {} { + } + + # XXX Perhaps I should actually check the key type returned. +- if {$num_keys == 5} { ++ if {$num_keys == 4} { + pass "$test" + } else { +- fail "$test: $num_keys keys, should be 5" ++ fail "$test: $num_keys keys, should be 4" + } + if { ! [cmd {kadm5_destroy $server_handle}]} { + perror "$test: unexpected failure in destroy" +diff --git a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp +index 3ea1ba29b..d2c6d1afa 100644 +--- a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp ++++ b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp +@@ -143,8 +143,8 @@ proc test101_102 {rpc} { + } + + set failed 0 +- if {$num_keys != 5} { +- fail "$test: num_keys $num_keys should be 5" ++ if {$num_keys != 4} { ++ fail "$test: num_keys $num_keys should be 4" + set failed 1 + } + for {set i 0} {$i < $num_keys} {incr i} { +diff --git a/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp +index 2925c1c43..2f76c8b43 100644 +--- a/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp ++++ b/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp +@@ -46,10 +46,10 @@ proc test100 {} { + } + + # XXX Perhaps I should actually check the key type returned. +- if {$num_keys == 5} { ++ if {$num_keys == 4} { + pass "$test" + } else { +- fail "$test: $num_keys keys, should be 5" ++ fail "$test: $num_keys keys, should be 4" + } + if { ! [cmd {kadm5_destroy $server_handle}]} { + perror "$test: unexpected failure in destroy" +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index b597dda54..ed52987a0 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -59,7 +59,6 @@ + static krb5_enctype default_enctype_list[] = { + ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, + ENCTYPE_AES256_CTS_HMAC_SHA384_192, ENCTYPE_AES128_CTS_HMAC_SHA256_128, +- ENCTYPE_DES3_CBC_SHA1, + ENCTYPE_ARCFOUR_HMAC, + ENCTYPE_CAMELLIA128_CTS_CMAC, ENCTYPE_CAMELLIA256_CTS_CMAC, + 0 +@@ -478,8 +477,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, + /* Set all enctypes in the default list. */ + for (i = 0; default_list[i]; i++) + mod_list(default_list[i], sel, weak, &list); +- } else if (strcasecmp(token, "des3") == 0) { +- mod_list(ENCTYPE_DES3_CBC_SHA1, sel, weak, &list); + } else if (strcasecmp(token, "aes") == 0) { + mod_list(ENCTYPE_AES256_CTS_HMAC_SHA1_96, sel, weak, &list); + mod_list(ENCTYPE_AES128_CTS_HMAC_SHA1_96, sel, weak, &list); +diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c +index d8015c64a..005cfd468 100644 +--- a/src/lib/krb5/krb/s4u_creds.c ++++ b/src/lib/krb5/krb/s4u_creds.c +@@ -341,8 +341,6 @@ verify_s4u2self_reply(krb5_context context, + assert(req_s4u_user != NULL); + + switch (subkey->enctype) { +- case ENCTYPE_DES3_CBC_SHA1: +- case ENCTYPE_DES3_CBC_RAW: + case ENCTYPE_ARCFOUR_HMAC: + case ENCTYPE_ARCFOUR_HMAC_EXP : + not_newer = TRUE; +diff --git a/src/lib/krb5/krb/t_copy_context.c b/src/lib/krb5/krb/t_copy_context.c +index 22be2198b..d489b78f9 100644 +--- a/src/lib/krb5/krb/t_copy_context.c ++++ b/src/lib/krb5/krb/t_copy_context.c +@@ -114,7 +114,7 @@ main(int argc, char **argv) + { + krb5_context ctx, ctx2; + krb5_plugin_initvt_fn *mods; +- const krb5_enctype etypes1[] = { ENCTYPE_DES3_CBC_SHA1, 0 }; ++ const krb5_enctype etypes1[] = { ENCTYPE_AES128_CTS_HMAC_SHA256_128, 0 }; + const krb5_enctype etypes2[] = { ENCTYPE_AES128_CTS_HMAC_SHA1_96, + ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }; + krb5_prompt_type ptypes[] = { KRB5_PROMPT_TYPE_PASSWORD }; +diff --git a/src/lib/krb5/krb/t_etypes.c b/src/lib/krb5/krb/t_etypes.c +index f609e938a..248ffea90 100644 +--- a/src/lib/krb5/krb/t_etypes.c ++++ b/src/lib/krb5/krb/t_etypes.c +@@ -50,17 +50,6 @@ static struct { + { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, + 0, 0 + }, +- /* Family followed by enctype */ +- { "aes des3-cbc-sha1-kd", +- { 0 }, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +- ENCTYPE_AES256_CTS_HMAC_SHA384_192, ENCTYPE_AES128_CTS_HMAC_SHA256_128, +- ENCTYPE_DES3_CBC_SHA1, 0 }, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +- ENCTYPE_AES256_CTS_HMAC_SHA384_192, ENCTYPE_AES128_CTS_HMAC_SHA256_128, +- ENCTYPE_DES3_CBC_SHA1, 0 }, +- 0, 0 +- }, + /* Family with enctype removed */ + { "camellia -camellia256-cts-cmac", + { 0 }, +@@ -69,46 +58,15 @@ static struct { + }, + /* Default set with family added and enctype removed */ + { "DEFAULT +aes -arcfour-hmac-md5", +- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_DES3_CBC_SHA1, 0 }, +- { ENCTYPE_DES3_CBC_SHA1, ENCTYPE_AES256_CTS_HMAC_SHA1_96, ++ { ENCTYPE_ARCFOUR_HMAC, 0 }, ++ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, + ENCTYPE_AES128_CTS_HMAC_SHA1_96, ENCTYPE_AES256_CTS_HMAC_SHA384_192, + ENCTYPE_AES128_CTS_HMAC_SHA256_128, 0 }, +- { ENCTYPE_DES3_CBC_SHA1, +- ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, ++ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, + ENCTYPE_AES256_CTS_HMAC_SHA384_192, ENCTYPE_AES128_CTS_HMAC_SHA256_128, + 0 }, + 0, 0 + }, +- /* Default set with families removed and enctypes added (one redundant) */ +- { "DEFAULT -des3 rc4-hmac rc4-hmac-exp", +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +- ENCTYPE_DES3_CBC_SHA1, ENCTYPE_ARCFOUR_HMAC, 0 }, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +- ENCTYPE_ARCFOUR_HMAC, 0 }, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +- ENCTYPE_ARCFOUR_HMAC, ENCTYPE_ARCFOUR_HMAC_EXP, 0 }, +- 0, 0 +- }, +- /* Default set with family moved to front */ +- { "des3 +DEFAULT", +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, +- ENCTYPE_DES3_CBC_SHA1, 0 }, +- { ENCTYPE_DES3_CBC_SHA1, ENCTYPE_AES256_CTS_HMAC_SHA1_96, +- ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0 }, +- { ENCTYPE_DES3_CBC_SHA1, ENCTYPE_AES256_CTS_HMAC_SHA1_96, +- ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0 }, +- 0, 0 +- }, +- /* Two families with default set removed (exotic case), enctype added */ +- { "aes +rc4 -DEFaulT des3-hmac-sha1", +- { ENCTYPE_AES128_CTS_HMAC_SHA1_96, ENCTYPE_DES3_CBC_SHA1, +- ENCTYPE_ARCFOUR_HMAC, 0 }, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES256_CTS_HMAC_SHA384_192, +- ENCTYPE_AES128_CTS_HMAC_SHA256_128, ENCTYPE_DES3_CBC_SHA1, 0 }, +- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES256_CTS_HMAC_SHA384_192, +- ENCTYPE_AES128_CTS_HMAC_SHA256_128, ENCTYPE_DES3_CBC_SHA1, 0 }, +- 0, 0 +- }, + /* Test krb5_set_default_in_tkt_ktypes */ + { NULL, + { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, +diff --git a/src/lib/krb5/os/t_trace.c b/src/lib/krb5/os/t_trace.c +index 10ba8d0ac..24064ffcf 100644 +--- a/src/lib/krb5/os/t_trace.c ++++ b/src/lib/krb5/os/t_trace.c +@@ -65,8 +65,8 @@ main (int argc, char *argv[]) + krb5_principal princ = &principal_data; + krb5_pa_data padata, padata2, **padatap; + krb5_enctype enctypes[4] = { +- ENCTYPE_DES3_CBC_SHA, ENCTYPE_ARCFOUR_HMAC_EXP, ENCTYPE_UNKNOWN, +- ENCTYPE_NULL}; ++ ENCTYPE_AES128_CTS_HMAC_SHA1_96, ENCTYPE_ARCFOUR_HMAC_EXP, ++ ENCTYPE_UNKNOWN, ENCTYPE_NULL}; + krb5_ccache ccache; + krb5_keytab keytab; + krb5_creds creds; +diff --git a/src/lib/krb5/os/t_trace.ref b/src/lib/krb5/os/t_trace.ref +index 044a66999..98fb14f3f 100644 +--- a/src/lib/krb5/os/t_trace.ref ++++ b/src/lib/krb5/os/t_trace.ref +@@ -41,7 +41,7 @@ int, krb5_principal type: ? + krb5_pa_data **, display list of padata type numbers: PA-PW-SALT (3), 0 + krb5_pa_data **, display list of padata type numbers: (empty) + krb5_enctype, display shortest name of enctype: aes128-cts +-krb5_enctype *, display list of enctypes: 5, rc4-hmac-exp, 511 ++krb5_enctype *, display list of enctypes: aes128-cts, rc4-hmac-exp, 511 + krb5_enctype *, display list of enctypes: (empty) + krb5_ccache, display type:name: FILE:/path/to/ccache + krb5_keytab, display name: FILE:/etc/krb5.keytab +diff --git a/src/plugins/preauth/pkinit/pkcs11.h b/src/plugins/preauth/pkinit/pkcs11.h +index 28ded4a89..47f4727bd 100644 +--- a/src/plugins/preauth/pkinit/pkcs11.h ++++ b/src/plugins/preauth/pkinit/pkcs11.h +@@ -339,9 +339,9 @@ typedef unsigned long ck_key_type_t; + #define CKK_GENERIC_SECRET (0x10) + #define CKK_RC2 (0x11) + #define CKK_RC4 (0x12) +-#define CKK_DES (0x13) +-#define CKK_DES2 (0x14) +-#define CKK_DES3 (0x15) ++/* #define CKK_DES (0x13) */ ++/* #define CKK_DES2 (0x14) */ ++/* #define CKK_DES3 (0x15) */ + #define CKK_CAST (0x16) + #define CKK_CAST3 (0x17) + #define CKK_CAST128 (0x18) +diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c +index 58400d555..a5337b6f5 100644 +--- a/src/plugins/preauth/pkinit/pkinit_clnt.c ++++ b/src/plugins/preauth/pkinit/pkinit_clnt.c +@@ -237,14 +237,6 @@ pkinit_as_req_create(krb5_context context, + auth_pack.clientDHNonce.length = 0; + auth_pack.clientPublicValue = &info; + auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; +- +- /* add List of CMS algorithms */ +- retval = create_krb5_supportedCMSTypes(context, plgctx->cryptoctx, +- reqctx->cryptoctx, +- reqctx->idctx, &cmstypes); +- auth_pack.supportedCMSTypes = cmstypes; +- if (retval) +- goto cleanup; + break; + default: + pkiDebug("as_req: unrecognized pa_type = %d\n", +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index 0acb731cd..d42acfa4b 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -381,18 +381,6 @@ krb5_error_code server_process_dh + unsigned int *server_key_len_out); /* OUT + receives length of DH secret key */ + +-/* +- * this functions takes in crypto specific representation of +- * supportedCMSTypes and creates a list of +- * krb5_algorithm_identifier +- */ +-krb5_error_code create_krb5_supportedCMSTypes +- (krb5_context context, /* IN */ +- pkinit_plg_crypto_context plg_cryptoctx, /* IN */ +- pkinit_req_crypto_context req_cryptoctx, /* IN */ +- pkinit_identity_crypto_context id_cryptoctx, /* IN */ +- krb5_algorithm_identifier ***supportedCMSTypes); /* OUT */ +- + /* + * this functions takes in crypto specific representation of + * trustedCertifiers and creates a list of +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 8aa2c5257..b101d179f 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -5596,44 +5596,6 @@ cleanup: + return retval; + } + +-krb5_error_code +-create_krb5_supportedCMSTypes(krb5_context context, +- pkinit_plg_crypto_context plg_cryptoctx, +- pkinit_req_crypto_context req_cryptoctx, +- pkinit_identity_crypto_context id_cryptoctx, +- krb5_algorithm_identifier ***oids) +-{ +- +- krb5_error_code retval = ENOMEM; +- krb5_algorithm_identifier **loids = NULL; +- krb5_data des3oid = {0, 8, "\x2A\x86\x48\x86\xF7\x0D\x03\x07" }; +- +- *oids = NULL; +- loids = malloc(2 * sizeof(krb5_algorithm_identifier *)); +- if (loids == NULL) +- goto cleanup; +- loids[1] = NULL; +- loids[0] = malloc(sizeof(krb5_algorithm_identifier)); +- if (loids[0] == NULL) { +- free(loids); +- goto cleanup; +- } +- retval = pkinit_copy_krb5_data(&loids[0]->algorithm, &des3oid); +- if (retval) { +- free(loids[0]); +- free(loids); +- goto cleanup; +- } +- loids[0]->parameters.length = 0; +- loids[0]->parameters.data = NULL; +- +- *oids = loids; +- retval = 0; +-cleanup: +- +- return retval; +-} +- + krb5_error_code + create_krb5_trustedCertifiers(krb5_context context, + pkinit_plg_crypto_context plg_cryptoctx, +diff --git a/src/plugins/preauth/pkinit/pkinit_kdf_test.c b/src/plugins/preauth/pkinit/pkinit_kdf_test.c +index 7acbd0d28..cd998a29a 100644 +--- a/src/plugins/preauth/pkinit/pkinit_kdf_test.c ++++ b/src/plugins/preauth/pkinit/pkinit_kdf_test.c +@@ -49,7 +49,6 @@ char eighteen_bs[9]; + char party_u_name[] = "lha@SU.SE"; + char party_v_name[] = "krbtgt/SU.SE@SU.SE"; + int enctype_aes = ENCTYPE_AES256_CTS_HMAC_SHA1_96; +-int enctype_des3 = ENCTYPE_DES3_CBC_SHA1; + const krb5_data lha_data = DATA_FROM_STRING("lha"); + + krb5_octet key1_hex[] = +@@ -185,36 +184,6 @@ main(int argc, char **argv) + goto cleanup; + } + +- /* TEST 3: SHA-512/DES3 */ +- /* set up algorithm id */ +- alg_id.algorithm.data = (char *)krb5_pkinit_sha512_oid; +- alg_id.algorithm.length = krb5_pkinit_sha512_oid_len; +- +- enctype = enctype_des3; +- +- /* call pkinit_alg_agility_kdf() with test vector values*/ +- if (0 != (retval = pkinit_alg_agility_kdf(context, &secret, +- &alg_id.algorithm, +- u_principal, v_principal, +- enctype, &as_req, &pk_as_rep, +- &key_block))) { +- printf("ERROR in pkinit_kdf_test: kdf call failed, retval = %d", +- retval); +- goto cleanup; +- } +- +- /* compare key to expected key value */ +- +- if ((key_block.length == sizeof(key3_hex)) && +- (0 == memcmp(key_block.contents, key3_hex, key_block.length))) { +- printf("SUCCESS: TEST 3 (SHA-512/DES3), Correct key value generated.\n"); +- retval = 0; +- } else { +- printf("FAILURE: TEST 2 (SHA-512/DES3), Incorrect key value generated!\n"); +- retval = 1; +- goto cleanup; +- } +- + cleanup: + /* release all allocated resources, whether good or bad return */ + free(secret.data); +diff --git a/src/plugins/preauth/spake/t_vectors.c b/src/plugins/preauth/spake/t_vectors.c +index 2279202d3..96b0307d7 100644 +--- a/src/plugins/preauth/spake/t_vectors.c ++++ b/src/plugins/preauth/spake/t_vectors.c +@@ -56,31 +56,6 @@ struct test { + const char *K2; + const char *K3; + } tests[] = { +- { ENCTYPE_DES3_CBC_SHA1, SPAKE_GROUP_EDWARDS25519, +- /* initial key, w, x, y, T, S, K */ +- "850BB51358548CD05E86768C313E3BFEF7511937DCF72C3E", +- "686D84730CB8679AE95416C6567C6A63F2C9CEF124F7A3371AE81E11CAD42A37", +- "201012D07BFD48DDFA33C4AAC4FB1E229FB0D043CFE65EBFB14399091C71A723", +- "500B294797B8B042ACA1BEDC0F5931A4F52C537B3608B2D05CC8A2372F439F25", +- "18F511E750C97B592ACD30DB7D9E5FCA660389102E6BF610C1BFBED4616C8362", +- "5D10705E0D1E43D5DBF30240CCFBDE4A0230C70D4C79147AB0B317EDAD2F8AE7", +- "25BDE0D875F0FEB5755F45BA5E857889D916ECF7476F116AA31DC3E037EC4292", +- /* support, challenge, thash, body */ +- "A0093007A0053003020101", +- "A1363034A003020101A122042018F511E750C97B592ACD30DB7D9E5FCA660389" +- "102E6BF610C1BFBED4616C8362A20930073005A003020101", +- "EAAA08807D0616026FF51C849EFBF35BA0CE3C5300E7D486DA46351B13D4605B", +- "3075A00703050000000000A1143012A003020101A10B30091B07726165627572" +- "6EA2101B0E415448454E412E4D49542E454455A3233021A003020102A11A3018" +- "1B066B72627467741B0E415448454E412E4D49542E454455A511180F31393730" +- "303130313030303030305AA703020100A8053003020110", +- /* K'[0], K'[1], K'[2], K'[3] */ +- "BAF12FAE7CD958CBF1A29BFBC71F89CE49E03E295D89DAFD", +- "64F73DD9C41908206BCEC1F719026B574F9D13463D7A2520", +- "0454520B086B152C455829E6BAEFF78A61DFE9E3D04A895D", +- "4A92260B25E3EF94C125D5C24C3E5BCED5B37976E67F25C4", +- }, +- + { ENCTYPE_ARCFOUR_HMAC, SPAKE_GROUP_EDWARDS25519, + /* initial key, w, x, y, T, S, K */ + "8846F7EAEE8FB117AD06BDD830B7586C", +diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp +index e8adee234..30a2c0967 100644 +--- a/src/tests/dejagnu/config/default.exp ++++ b/src/tests/dejagnu/config/default.exp +@@ -15,8 +15,6 @@ set timeout 100 + set stty_init {erase \^h kill \^u} + set env(TERM) dumb + +-set des3_krbtgt 0 +- + if { [string length $VALGRIND] } { + rename spawn valgrind_aux_spawn + proc spawn { args } { +@@ -105,17 +103,9 @@ if { $PRIOCNTL_HACK } { + # particularly with regards to encryption types. + + set passes { +- { +- des3 +- mode=udp +- des3_krbtgt=1 +- {supported_enctypes=des3-cbc-sha1:normal} +- {dummy=[verbose -log "DES3 TGT, DES3 enctype"]} +- } + { + aes-only + mode=udp +- des3_krbtgt=0 + {supported_enctypes=aes256-cts-hmac-sha1-96:normal} + {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96} + {permitted_enctypes(client)=aes256-cts-hmac-sha1-96} +@@ -130,7 +120,6 @@ set passes { + { + aes-sha2-only + mode=udp +- des3_krbtgt=0 + {supported_enctypes=aes256-sha2:normal} + {permitted_enctypes(kdc)=aes256-sha2} + {permitted_enctypes(replica)=aes256-sha2} +@@ -154,7 +143,6 @@ set passes { + { + camellia-only + mode=udp +- des3_krbtgt=0 + {supported_enctypes=camellia256-cts:normal} + {permitted_enctypes(kdc)=camellia256-cts} + {permitted_enctypes(replica)=camellia256-cts} +@@ -175,32 +163,9 @@ set passes { + {master_key_type=camellia256-cts} + {dummy=[verbose -log "Camellia-256 enctype"]} + } +- { +- aes-des3 +- mode=udp +- des3_krbtgt=0 +- {supported_enctypes=aes256-cts-hmac-sha1-96:normal des3-cbc-sha1:normal} +- {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} +- {permitted_enctypes(client)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} +- {permitted_enctypes(server)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} +- {master_key_type=aes256-cts-hmac-sha1-96} +- {dummy=[verbose -log "AES + DES3 + DES enctypes"]} +- } +- { +- aes-des3tgt +- mode=udp +- des3_krbtgt=1 +- {supported_enctypes=aes256-cts-hmac-sha1-96:normal des3-cbc-sha1:normal} +- {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} +- {permitted_enctypes(client)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} +- {permitted_enctypes(server)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} +- {master_key_type=aes256-cts-hmac-sha1-96} +- {dummy=[verbose -log "AES enctypes, DES3 TGT"]} +- } + { + all-enctypes + mode=udp +- des3_krbtgt=0 + {allow_weak_crypto(kdc)=false} + {allow_weak_crypto(replica)=false} + {allow_weak_crypto(client)=false} +@@ -947,7 +912,6 @@ proc setup_kerberos_db { standalone } { + global REALMNAME KDB5_UTIL KADMIN_LOCAL KEY + global tmppwd hostname + global spawn_id +- global des3_krbtgt + global multipass_name last_passname_db + + set failall 0 +@@ -1144,48 +1108,6 @@ proc setup_kerberos_db { standalone } { + } + } + +- if $des3_krbtgt { +- # Set the TGT key to DES3. +- set test "kadmin.local TGT to DES3" +- set body { +- if $failall { +- break +- } +- spawn $KADMIN_LOCAL -r $REALMNAME -e des3-cbc-sha1:normal +- verbose "starting $test" +- expect_after $def_exp_after +- +- expect "kadmin.local: " +- send "cpw -randkey krbtgt/$REALMNAME@$REALMNAME\r" +- # It echos... +- expect "cpw -randkey krbtgt/$REALMNAME@$REALMNAME\r" +- expect { +- "Key for \"krbtgt/$REALMNAME@$REALMNAME\" randomized." { } +- } +- expect "kadmin.local: " +- send "quit\r" +- expect eof +- catch expect_after +- if ![check_exit_status kadmin_local] { +- break +- } +- } +- set ret [catch $body] +- catch "expect eof" +- catch expect_after +- if $ret { +- set failall 1 +- if $standalone { +- fail $test +- } else { +- delete_db +- } +- } else { +- if $standalone { +- pass $test +- } +- } +- } + envstack_pop + + # create the admin database lock file +diff --git a/src/tests/dejagnu/krb-standalone/kprop.exp b/src/tests/dejagnu/krb-standalone/kprop.exp +index f71ee8638..8c08cf42f 100644 +--- a/src/tests/dejagnu/krb-standalone/kprop.exp ++++ b/src/tests/dejagnu/krb-standalone/kprop.exp +@@ -54,7 +54,7 @@ proc doit { } { + global REALMNAME KEY + global KADMIN_LOCAL KTUTIL KDB5_UTIL KPROPLOG KPROP kpropd_spawn_id + global hostname tmppwd spawn_id timeout +- global KRBIV supported_enctypes portbase mode ulog des3_krbtgt ++ global KRBIV supported_enctypes portbase mode ulog + + # Delete any db, ulog files + delete_db +diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py +index ca3d32d21..96d0e7330 100755 +--- a/src/tests/gssapi/t_enctypes.py ++++ b/src/tests/gssapi/t_enctypes.py +@@ -1,24 +1,17 @@ + from k5test import * + +-# Define some convenience abbreviations for enctypes we will see in +-# test program output. For background, aes256 and aes128 are "CFX +-# enctypes", meaning that they imply support for RFC 4121, while des3 +-# and rc4 are not. DES3 keys will appear as 'des3-cbc-raw' in +-# t_enctypes output because that's how GSSAPI does raw triple-DES +-# encryption without the RFC3961 framing. ++# Define some convenience abbreviations for enctypes we will see in test ++# program output. For background, aes256 and aes128 are "CFX enctypes", ++# meaning that they imply support for RFC 4121, while rc4 does not. + aes256 = 'aes256-cts-hmac-sha1-96' + aes128 = 'aes128-cts-hmac-sha1-96' +-des3 = 'des3-cbc-sha1' +-d_des3 = 'DEPRECATED:des3-cbc-sha1' +-des3raw = 'des3-cbc-raw' +-d_des3raw = 'DEPRECATED:des3-cbc-raw' + rc4 = 'arcfour-hmac' + d_rc4 = 'DEPRECATED:arcfour-hmac' + + # These tests make assumptions about the default enctype lists, so set + # them explicitly rather than relying on the library defaults. +-enctypes='aes des3 rc4' +-supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal' ++enctypes='aes rc4' ++supp='aes256-cts:normal aes128-cts:normal rc4-hmac:normal' + conf = {'libdefaults': { + 'default_tgs_enctypes': enctypes, + 'default_tkt_enctypes': enctypes, +@@ -91,19 +84,12 @@ test('both aes128', 'aes128-cts', 'aes128-cts', + test_err('acc aes128', None, 'aes128-cts', + 'Encryption type aes256-cts-hmac-sha1-96 not permitted') + +-# If the initiator constrains the permitted session enctypes to des3, +-# no acceptor subkey will be generated because we can't upgrade to a +-# CFX enctype. +-test('init des3', 'des3', None, +- tktenc=aes256, tktsession=d_des3, +- proto='rfc1964', isubkey=des3raw, asubkey=None) +- + # Force the ticket session key to be rc4, so we can test some subkey + # upgrade cases. The ticket encryption key remains aes256. + realm.run([kadminl, 'setstr', realm.host_princ, 'session_enctypes', 'rc4']) + + # With no arguments, the initiator should send an upgrade list of +-# [aes256 aes128 des3] and the acceptor should upgrade to an aes256 ++# [aes256 aes128] and the acceptor should upgrade to an aes256 + # subkey. + test('upgrade noargs', None, None, + tktenc=aes256, tktsession=d_rc4, +@@ -119,13 +105,6 @@ test('upgrade init aes128+rc4', 'aes128-cts rc4', None, + tktenc=aes256, tktsession=d_rc4, + proto='cfx', isubkey=rc4, asubkey=aes128) + +-# If the initiator permits rc4 but prefers des3, it will send an +-# upgrade list of [des3], but the acceptor won't generate a subkey +-# because des3 isn't a CFX enctype. +-test('upgrade init des3+rc4', 'des3 rc4', None, +- tktenc=aes256, tktsession=d_rc4, +- proto='rfc1964', isubkey=rc4, asubkey=None) +- + # If the acceptor permits only aes128, subkey negotiation will fail + # because the ticket session key and initiator subkey are + # non-permitted. (This is unfortunate if the acceptor's restriction +diff --git a/src/tests/gssapi/t_invalid.c b/src/tests/gssapi/t_invalid.c +index 9876a11e6..fb8fe5511 100644 +--- a/src/tests/gssapi/t_invalid.c ++++ b/src/tests/gssapi/t_invalid.c +@@ -84,18 +84,6 @@ struct test { + size_t toklen; + const char *token; + } tests[] = { +- { +- ENCTYPE_DES3_CBC_SHA1, ENCTYPE_DES3_CBC_RAW, +- SEAL_ALG_DES3KD, SGN_ALG_HMAC_SHA1_DES3_KD, 20, +- 24, +- "\x4F\xEA\x19\x19\x5E\x0E\x10\xDF\x3D\x29\xB5\x13\x8F\x01\xC7\xA7" +- "\x92\x3D\x38\xF7\x26\x73\x0D\x6D", +- 65, +- "\x60\x3F\x06\x09\x2A\x86\x48\x86\xF7\x12\x01\x02\x02\x02\x01\x04" +- "\x00\x02\x00\xFF\xFF\xEB\xF3\x9A\x89\x24\x57\xB8\x63\x95\x25\xE8" +- "\x6E\x8E\x79\xE6\x2E\xCA\xD3\xFF\x57\x9F\x8C\xAB\xEF\xDD\x28\x10" +- "\x2F\x93\x21\x2E\xF2\x52\xB6\x6F\xA8\xBB\x8A\x6D\xAA\x6F\xB7\xF4\xD4" +- }, + { + ENCTYPE_ARCFOUR_HMAC, ENCTYPE_ARCFOUR_HMAC, + SEAL_ALG_MICROSOFT_RC4, SGN_ALG_HMAC_MD5, 8, +diff --git a/src/tests/gssapi/t_pcontok.c b/src/tests/gssapi/t_pcontok.c +index 7368f752f..bf22bd3da 100644 +--- a/src/tests/gssapi/t_pcontok.c ++++ b/src/tests/gssapi/t_pcontok.c +@@ -43,7 +43,6 @@ + #include "k5-int.h" + #include "common.h" + +-#define SGN_ALG_HMAC_SHA1_DES3_KD 0x04 + #define SGN_ALG_HMAC_MD5 0x11 + + /* +@@ -77,17 +76,12 @@ make_delete_token(gss_krb5_lucid_context_v1_t *lctx, gss_buffer_desc *out) + ret = krb5_k_create_key(context, &seqkb, &seq); + check_k5err(context, "krb5_k_create_key", ret); + +- if (signalg == SGN_ALG_HMAC_SHA1_DES3_KD) { +- cktype = CKSUMTYPE_HMAC_SHA1_DES3; +- cksize = 20; +- ckusage = 23; +- } else if (signalg == SGN_ALG_HMAC_MD5) { +- cktype = CKSUMTYPE_HMAC_MD5_ARCFOUR; +- cksize = 8; +- ckusage = 15; +- } else { ++ if (signalg != SGN_ALG_HMAC_MD5) + abort(); +- } ++ ++ cktype = CKSUMTYPE_HMAC_MD5_ARCFOUR; ++ cksize = 8; ++ ckusage = 15; + + tlen = 20 + mech_krb5.length + cksize; + token = malloc(tlen); +diff --git a/src/tests/gssapi/t_prf.c b/src/tests/gssapi/t_prf.c +index f71774cdc..d1857c433 100644 +--- a/src/tests/gssapi/t_prf.c ++++ b/src/tests/gssapi/t_prf.c +@@ -41,13 +41,6 @@ static struct { + const char *key2; + const char *out2; + } tests[] = { +- { ENCTYPE_DES3_CBC_SHA1, +- "70378A19CD64134580C27C0115D6B34A1CF2FEECEF9886A2", +- "9F8D127C520BB826BFF3E0FE5EF352389C17E0C073D9" +- "AC4A333D644D21BA3EF24F4A886D143F85AC9F6377FB", +- "3452A167DF1094BA1089E0A20E9E51ABEF1525922558B69E", +- "6BF24FABC858F8DD9752E4FCD331BB831F238B5BE190" +- "4EEA42E38F7A60C588F075C5C96A67E7F8B7BD0AECF4" }, + { ENCTYPE_ARCFOUR_HMAC, + "3BB3AE288C12B3B9D06B208A4151B3B6", + "9AEA11A3BCF3C53F1F91F5A0BA2132E2501ADF5F3C28" +diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py +index d98974b36..84153d9cf 100644 +--- a/src/tests/t_authdata.py ++++ b/src/tests/t_authdata.py +@@ -172,7 +172,7 @@ realm.run([kvno, 'restricted']) + # preferred krbtgt enctype changes. + mark('#8139 regression test') + realm.kinit(realm.user_princ, password('user'), ['-f']) +-realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', 'des3-cbc-sha1', ++realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', 'aes256-sha2', + realm.krbtgt_princ]) + realm.run(['./forward']) + realm.run([kvno, realm.host_princ]) +diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py +index 2a052fc17..ace0edc3c 100644 +--- a/src/tests/t_etype_info.py ++++ b/src/tests/t_etype_info.py +@@ -1,6 +1,6 @@ + from k5test import * + +-supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac' ++supported_enctypes = 'aes128-cts rc4-hmac' + conf = {'libdefaults': {'allow_weak_crypto': 'true'}, + 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} + realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) +@@ -24,9 +24,9 @@ def test_etinfo(princ, enctypes, expected_lines): + # With no newer enctypes in the request, PA-ETYPE-INFO2, + # PA-ETYPE-INFO, and PA-PW-SALT appear in the AS-REP, each listing one + # key for the most preferred matching enctype. +-test_etinfo('user', 'rc4-hmac-exp des3 rc4', +- ['asrep etype_info2 des3-cbc-sha1 KRBTEST.COMuser', +- 'asrep etype_info des3-cbc-sha1 KRBTEST.COMuser', ++test_etinfo('user', 'rc4-hmac-exp rc4', ++ ['asrep etype_info2 rc4-hmac KRBTEST.COMuser', ++ 'asrep etype_info rc4-hmac KRBTEST.COMuser', + 'asrep pw_salt KRBTEST.COMuser']) + + # With a newer enctype in the request (even if it is not the most +@@ -37,9 +37,9 @@ test_etinfo('user', 'rc4 aes256-cts', + + # In preauth-required errors, PA-PW-SALT does not appear, but the same + # etype-info2 values are expected. +-test_etinfo('preauthuser', 'rc4-hmac-exp des3 rc4', +- ['error etype_info2 des3-cbc-sha1 KRBTEST.COMpreauthuser', +- 'error etype_info des3-cbc-sha1 KRBTEST.COMpreauthuser']) ++test_etinfo('preauthuser', 'rc4-hmac-exp rc4', ++ ['error etype_info2 rc4-hmac KRBTEST.COMpreauthuser', ++ 'error etype_info rc4-hmac KRBTEST.COMpreauthuser']) + test_etinfo('preauthuser', 'rc4 aes256-cts', + ['error etype_info2 rc4-hmac KRBTEST.COMpreauthuser']) + +@@ -48,8 +48,8 @@ test_etinfo('preauthuser', 'rc4 aes256-cts', + # (to allow for preauth mechs which don't depend on long-term keys). + # An AS-REP cannot be generated without preauth as there is no reply + # key. +-test_etinfo('rc4user', 'des3', []) +-test_etinfo('nokeyuser', 'des3', []) ++test_etinfo('rc4user', 'aes128-cts', []) ++test_etinfo('nokeyuser', 'aes128-cts', []) + + # Verify that etype-info2 is included in a MORE_PREAUTH_DATA_REQUIRED + # error if the client does optimistic preauth. +diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py +index 2c825a692..f29e0d550 100755 +--- a/src/tests/t_keyrollover.py ++++ b/src/tests/t_keyrollover.py +@@ -37,9 +37,9 @@ realm.run([klist, '-e'], expected_msg=msg) + + # Test that the KDC only accepts the first enctype for a kvno, for a + # local-realm TGS request. To set this up, we abuse an edge-case +-# behavior of modprinc -kvno. First, set up a DES3 krbtgt entry at ++# behavior of modprinc -kvno. First, set up an aes128-sha2 krbtgt entry at + # kvno 1 and cache a krbtgt ticket. +-realm.run([kadminl, 'cpw', '-randkey', '-e', 'des3-cbc-sha1', ++realm.run([kadminl, 'cpw', '-randkey', '-e', 'aes128-cts-hmac-sha256-128', + realm.krbtgt_princ]) + realm.run([kadminl, 'modprinc', '-kvno', '1', realm.krbtgt_princ]) + realm.kinit(realm.user_princ, password('user')) +@@ -50,9 +50,9 @@ realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', 'aes256-cts', + realm.run([kadminl, 'modprinc', '-kvno', '1', realm.krbtgt_princ]) + out = realm.run([kadminl, 'getprinc', realm.krbtgt_princ]) + if 'vno 1, aes256-cts' not in out or \ +- 'vno 1, DEPRECATED:des3-cbc-sha1' not in out: ++ 'vno 1, aes128-cts-hmac-sha256-128' not in out: + fail('keyrollover: setup for TGS enctype test failed') +-# Now present the DES3 ticket to the KDC and make sure it's rejected. ++# Now present the aes128-sha2 ticket to the KDC and make sure it's rejected. + realm.run([kvno, realm.host_princ], expected_code=1) + + realm.stop() +diff --git a/src/tests/t_mkey.py b/src/tests/t_mkey.py +index 99273c907..f84041ca4 100755 +--- a/src/tests/t_mkey.py ++++ b/src/tests/t_mkey.py +@@ -7,7 +7,6 @@ import struct + # default enctype for master keys. + aes256 = 'aes256-cts-hmac-sha1-96' + aes128 = 'aes128-cts-hmac-sha1-96' +-des3 = 'des3-cbc-sha1' + defetype = aes256 + + realm = K5Realm(create_host=False, start_kadmind=True) +@@ -300,40 +299,6 @@ if 'Decrypt integrity check failed' in out or 'added to keytab' not in out: + + realm.stop() + +-# Load a dump file created with krb5 1.6, before the master key +-# rollover changes were introduced. Write out an old-format stash +-# file consistent with the dump's master password ("footes"). The K/M +-# entry in this database will not have actkvno tl-data because it was +-# created prior to master key rollover support. Verify that: +-# 1. We can access the database using the old-format stash file. +-# 2. list_mkeys displays the same list as for a post-1.7 KDB. +-mark('pre-1.7 stash file') +-dumpfile = os.path.join(srctop, 'tests', 'dumpfiles', 'dump.16') +-os.remove(stash_file) +-f = open(stash_file, 'wb') +-f.write(struct.pack('=HL24s', 16, 24, +- b'\xF8\x3E\xFB\xBA\x6D\x80\xD9\x54\xE5\x5D\xF2\xE0' +- b'\x94\xAD\x6D\x86\xB5\x16\x37\xEC\x7C\x8A\xBC\x86')) +-f.close() +-realm.run([kdb5_util, 'load', dumpfile]) +-nprincs = len(realm.run([kadminl, 'listprincs']).splitlines()) +-check_mkvno('K/M', 1) +-check_mkey_list((1, des3, True, True)) +- +-# Create a new master key and verify that, without actkvkno tl-data: +-# 1. list_mkeys displays the same as for a post-1.7 KDB. +-# 2. update_princ_encryption still targets mkvno 1. +-# 3. libkadm5 still uses mkvno 1 for key changes. +-# 4. use_mkey creates the same list as for a post-1.7 KDB. +-mark('rollover from pre-1.7 KDB') +-add_mkey([]) +-check_mkey_list((2, defetype, False, False), (1, des3, True, True)) +-update_princ_encryption(False, 1, 0, nprincs - 1) +-realm.run([kadminl, 'addprinc', '-randkey', realm.user_princ]) +-check_mkvno(realm.user_princ, 1) +-realm.run([kdb5_util, 'use_mkey', '2', 'now-1day']) +-check_mkey_list((2, defetype, True, True), (1, des3, True, False)) +- + # Regression test for #8395. Purge the master key and verify that a + # master key fetch does not segfault. + mark('#8395 regression test') +diff --git a/src/tests/t_salt.py b/src/tests/t_salt.py +index 65084bbf3..55ca89745 100755 +--- a/src/tests/t_salt.py ++++ b/src/tests/t_salt.py +@@ -16,13 +16,12 @@ def test_salt(realm, e1, salt, e2): + + # Enctype/salt pairs chosen with non-default salt types. + # The enctypes are mostly arbitrary. +-salts = [('des3-cbc-sha1', 'norealm'), ++salts = [('aes128-cts-hmac-sha1-96', 'norealm'), + ('arcfour-hmac', 'onlyrealm'), + ('aes128-cts-hmac-sha1-96', 'special')] + # These enctypes are chosen to cover the different string-to-key routines. + # Omit ":normal" from aes256 to check that salttype defaulting works. +-second_kstypes = ['aes256-cts-hmac-sha1-96', 'arcfour-hmac:normal', +- 'des3-cbc-sha1:normal'] ++second_kstypes = ['aes256-cts-hmac-sha1-96', 'arcfour-hmac:normal'] + + # Test using different salt types in a principal's key list. + # Parameters from one key in the list must not leak over to later ones. +diff --git a/src/util/k5test.py b/src/util/k5test.py +index da2782e15..feb6df7a0 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -1246,16 +1246,6 @@ _passes = [ + # No special settings; exercises AES256. + ('default', None, None, None), + +- # Exercise the DES3 enctype. +- ('des3', None, +- {'libdefaults': { +- 'default_tgs_enctypes': 'des3', +- 'default_tkt_enctypes': 'des3', +- 'permitted_enctypes': 'des3'}}, +- {'realms': {'$realm': { +- 'supported_enctypes': 'des3-cbc-sha1:normal', +- 'master_key_type': 'des3-cbc-sha1'}}}), +- + # Exercise the arcfour enctype. + ('arcfour', None, + {'libdefaults': { +diff --git a/src/windows/leash/htmlhelp/html/Encryption_Types.htm b/src/windows/leash/htmlhelp/html/Encryption_Types.htm +index 1aebdd0b4..c38eefd2b 100644 +--- a/src/windows/leash/htmlhelp/html/Encryption_Types.htm ++++ b/src/windows/leash/htmlhelp/html/Encryption_Types.htm +@@ -79,19 +79,6 @@ will have an entry in the Encryption type column.
    + Description + + +- des3- +- The triple DES family improves on +-the original DES (Data Encryption Standard) by using 3 separate 56-bit +-keys. Some modes of 3DES are considered weak while others are strong +-(if slow).
      +-
    • des3-cbc-sha1
    • +-
    • des3-cbc-raw (weak)
    • +-
    • des3-hmac-sha1
    • +-
    • des3-cbc-sha1-kd
    • +-
    +- +- +- + aes + The AES Advanced Encryption Standard + family, like 3DES, is a symmetric block cipher and was designed diff --git a/Remove-krb5int_c_combine_keys.patch b/Remove-krb5int_c_combine_keys.patch index 7ac088c..64e2e72 100644 --- a/Remove-krb5int_c_combine_keys.patch +++ b/Remove-krb5int_c_combine_keys.patch @@ -1,4 +1,4 @@ -From 320f2d5b0f2671e41b383161093a73d9dea5cbf7 Mon Sep 17 00:00:00 2001 +From 343e236ed2637a826f4d53ff60d2b2bc349100d6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 18 Apr 2019 17:27:07 -0400 Subject: [PATCH] Remove krb5int_c_combine_keys() diff --git a/Remove-support-for-no-flags-SAM-2-preauth.patch b/Remove-support-for-no-flags-SAM-2-preauth.patch index 971a366..9f95b3d 100644 --- a/Remove-support-for-no-flags-SAM-2-preauth.patch +++ b/Remove-support-for-no-flags-SAM-2-preauth.patch @@ -1,4 +1,4 @@ -From 2c6a5bea4319b6b1705d6c9c6a2bb78c9999089f Mon Sep 17 00:00:00 2001 +From 9e71fcd5db98fb7ace02e8684486cc7f092d82ad Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 17 Apr 2019 17:07:46 -0400 Subject: [PATCH] Remove support for no-flags SAM-2 preauth diff --git a/krb5-1.17post3-FIPS-with-PRNG-SPAKE-and-RADIUS.patch b/krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch similarity index 94% rename from krb5-1.17post3-FIPS-with-PRNG-SPAKE-and-RADIUS.patch rename to krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch index 98c4782..d6560a9 100644 --- a/krb5-1.17post3-FIPS-with-PRNG-SPAKE-and-RADIUS.patch +++ b/krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch @@ -1,7 +1,7 @@ -From b52fa25acec9c0302532e1610ffe390d714e8f7a Mon Sep 17 00:00:00 2001 +From ebcc57122e6f2325c9b0b3cb7c600d38c013a05a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 -Subject: [PATCH] krb5-1.17post3 FIPS with PRNG, SPAKE, and RADIUS +Subject: [PATCH] krb5-1.17post4 FIPS with PRNG, SPAKE, and RADIUS NB: Use openssl's PRNG in FIPS mode, be aware during SPAKE group negotiation, and taint within krad. @@ -16,11 +16,11 @@ This will slow down some calls slightly (FIPS_mode() takes multiple locks), but not for any ciphers we care about - which is to say that AES is fine. Shame about the SPAKE groups though. -post3 is (confusingly) on top of the 1DES removal. +post4 is on top of the 3DES removal. (4 > 3; it makes sense this +time!) --- src/lib/crypto/krb/prng.c | 11 ++++- .../crypto/openssl/enc_provider/camellia.c | 6 +++ - src/lib/crypto/openssl/enc_provider/des3.c | 6 +++ src/lib/crypto/openssl/enc_provider/rc4.c | 13 +++++- .../crypto/openssl/hash_provider/hash_evp.c | 4 ++ src/lib/crypto/openssl/hmac.c | 6 ++- @@ -32,7 +32,7 @@ post3 is (confusingly) on top of the 1DES removal. src/lib/krad/t_attr.c | 3 +- src/lib/krad/t_attrset.c | 4 +- src/plugins/preauth/spake/groups.c | 8 ++++ - 14 files changed, 123 insertions(+), 33 deletions(-) + 13 files changed, 117 insertions(+), 33 deletions(-) diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c index cb9ca9b98..f0e9984ca 100644 @@ -89,30 +89,6 @@ index 2da691329..f79679a0b 100644 state->length = 16; state->data = (void *) malloc(16); if (state->data == NULL) -diff --git a/src/lib/crypto/openssl/enc_provider/des3.c b/src/lib/crypto/openssl/enc_provider/des3.c -index 1c439c2cd..8be555a8d 100644 ---- a/src/lib/crypto/openssl/enc_provider/des3.c -+++ b/src/lib/crypto/openssl/enc_provider/des3.c -@@ -84,6 +84,9 @@ k5_des3_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx; - krb5_boolean empty; - -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; -+ - ret = validate(key, ivec, data, num_data, &empty); - if (ret != 0 || empty) - return ret; -@@ -133,6 +136,9 @@ k5_des3_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx; - krb5_boolean empty; - -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; -+ - ret = validate(key, ivec, data, num_data, &empty); - if (ret != 0 || empty) - return ret; diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c index a65d57b7a..6ccaca94a 100644 --- a/src/lib/crypto/openssl/enc_provider/rc4.c diff --git a/krb5.spec b/krb5.spec index d1ecd63..f9f1fa7 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 27%{?dist} +Release: 28%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -102,10 +102,11 @@ Patch137: Remove-the-v4-and-afs3-salt-types.patch Patch138: Update-test-suite-to-avoid-single-DES-enctypes.patch Patch139: Remove-support-for-single-DES-and-CRC.patch Patch140: Display-unsupported-enctype-names.patch -Patch141: krb5-1.17post3-FIPS-with-PRNG-SPAKE-and-RADIUS.patch Patch142: Add-zapfreedata-convenience-function.patch Patch143: Remove-support-for-no-flags-SAM-2-preauth.patch Patch144: Remove-krb5int_c_combine_keys.patch +Patch145: Remove-3des-support.patch +Patch146: krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -715,6 +716,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jun 03 2019 Robbie Harwood - 1.17-28 +- Remove 3des support + * Thu May 30 2019 Robbie Harwood - 1.17-27 - Remove krb5int_c_combine_keys() and no-flags SAM-2 preauth From 1cae0b7e9670d90e2addf7c97b2312c0d7de8e2b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 3 Jun 2019 17:33:31 -0400 Subject: [PATCH 114/304] Remove 3DES support --- Remove-3des-support.patch | 14 ++++---------- ...1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch | 2 +- krb5.spec | 5 ++++- 3 files changed, 9 insertions(+), 12 deletions(-) diff --git a/Remove-3des-support.patch b/Remove-3des-support.patch index 0231140..62161e5 100644 --- a/Remove-3des-support.patch +++ b/Remove-3des-support.patch @@ -1,4 +1,4 @@ -From 44511dc2463b516065f5b88b6d2a61045b1333f2 Mon Sep 17 00:00:00 2001 +From c6e61b6ce3f305765dab2acf05a676172c596ddd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] Remove 3des support @@ -16,7 +16,7 @@ their constants. doc/mitK5features.rst | 2 +- src/Makefile.in | 4 +- src/configure.in | 1 - - src/include/krb5/krb5.hin | 12 +- + src/include/krb5/krb5.hin | 10 +- src/kadmin/testing/proto/kdc.conf.proto | 4 +- src/kdc/kdc_util.c | 4 - src/lib/crypto/Makefile.in | 8 +- @@ -103,7 +103,7 @@ their constants. src/tests/t_salt.py | 5 +- src/util/k5test.py | 10 - .../leash/htmlhelp/html/Encryption_Types.htm | 13 - - 95 files changed, 163 insertions(+), 4837 deletions(-) + 95 files changed, 162 insertions(+), 4836 deletions(-) delete mode 100644 src/lib/crypto/builtin/des/ISSUES delete mode 100644 src/lib/crypto/builtin/des/Makefile.in delete mode 100644 src/lib/crypto/builtin/des/d3_aead.c @@ -300,15 +300,9 @@ index 8d781a7c8..a19a0ea97 100644 lib/crypto/$CRYPTO_IMPL/sha1 lib/crypto/$CRYPTO_IMPL/sha2 lib/crypto/$CRYPTO_IMPL/aes lib/crypto/$CRYPTO_IMPL/camellia diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 5f596d1fc..ca7eb6a80 100644 +index 5f596d1fc..9a05ce32d 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin -@@ -1,4 +1,4 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+./* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ - /* General definitions for Kerberos version 5. */ - /* - * Copyright 1989, 1990, 1995, 2001, 2003, 2007, 2011 by the Massachusetts @@ -426,8 +426,8 @@ typedef struct _krb5_crypto_iov { #define ENCTYPE_DES_CBC_MD4 0x0002 /**< @deprecated no longer supported */ #define ENCTYPE_DES_CBC_MD5 0x0003 /**< @deprecated no longer supported */ diff --git a/krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch b/krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch index d6560a9..18ebb8c 100644 --- a/krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch +++ b/krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch @@ -1,4 +1,4 @@ -From ebcc57122e6f2325c9b0b3cb7c600d38c013a05a Mon Sep 17 00:00:00 2001 +From a57e6f65c6368b3fe99baaaeafccd166dad006b4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] krb5-1.17post4 FIPS with PRNG, SPAKE, and RADIUS diff --git a/krb5.spec b/krb5.spec index f9f1fa7..85d953a 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 28%{?dist} +Release: 29%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -716,6 +716,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jun 03 2019 Robbie Harwood - 1.17-29 +- Remove 3DES support + * Mon Jun 03 2019 Robbie Harwood - 1.17-28 - Remove 3des support From 6d60b0827fe49ae8fbed4d0cfcc438c8154f2bbf Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 7 Jun 2019 08:52:53 -0400 Subject: [PATCH 115/304] Remove 3des from kdc.conf example --- kdc.conf | 2 +- krb5.spec | 5 ++++- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/kdc.conf b/kdc.conf index b2e5e9b..f21c761 100644 --- a/kdc.conf +++ b/kdc.conf @@ -9,5 +9,5 @@ EXAMPLE.COM = { acl_file = /var/kerberos/krb5kdc/kadm5.acl dict_file = /usr/share/dict/words admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab - supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal + supported_enctypes = aes256-cts:normal aes128-cts:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal } diff --git a/krb5.spec b/krb5.spec index 85d953a..1db95af 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 29%{?dist} +Release: 30%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -716,6 +716,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Jun 07 2019 Robbie Harwood - 1.17-30 +- Remove 3des from kdc.conf example + * Mon Jun 03 2019 Robbie Harwood - 1.17-29 - Remove 3DES support From 2843572c2fca315f5c7a1097d8550d8770a0e3c4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 10 Jun 2019 12:41:26 -0400 Subject: [PATCH 116/304] Remove strerror() calls from k5_get_error() --- Remove-strerror-calls-from-k5_get_error.patch | 34 +++++++++++++++++++ krb5.spec | 6 +++- 2 files changed, 39 insertions(+), 1 deletion(-) create mode 100644 Remove-strerror-calls-from-k5_get_error.patch diff --git a/Remove-strerror-calls-from-k5_get_error.patch b/Remove-strerror-calls-from-k5_get_error.patch new file mode 100644 index 0000000..7ce77b3 --- /dev/null +++ b/Remove-strerror-calls-from-k5_get_error.patch @@ -0,0 +1,34 @@ +From f9c5dd7a9bb19dc99de8ee046b0ac1506c494f4e Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 6 Jun 2019 11:46:58 -0400 +Subject: [PATCH] Remove strerror() calls from k5_get_error() + +Coverity models strerror() as a function which cannot accept negative +values, even though it has defined behavior on all integers. +k5_get_error() contains code to call strerror_r() and strerror() if +its fptr global is unset, which isn't an expected case in practice. +To silence a large number of Coverity false positives, just return a +fixed string if fptr is null. + +(cherry picked from commit 2d400bea7a81a5a834a1be6ded439f18e0afa5ba) +--- + src/util/support/errors.c | 5 ++--- + 1 file changed, 2 insertions(+), 3 deletions(-) + +diff --git a/src/util/support/errors.c b/src/util/support/errors.c +index 70e1d59d0..f8bea07a3 100644 +--- a/src/util/support/errors.c ++++ b/src/util/support/errors.c +@@ -78,10 +78,9 @@ k5_get_error(struct errinfo *ep, long code) + + lock(); + if (fptr == NULL) { ++ /* Should be rare; fptr should be set whenever libkrb5 is loaded. */ + unlock(); +- if (strerror_r(code, buf, sizeof(buf)) == 0) +- return oom_check(strdup(buf)); +- return oom_check(strdup(strerror(code))); ++ return oom_check(strdup(_("Error code translation unavailable"))); + } + r = fptr(code); + #ifndef HAVE_COM_ERR_INTL diff --git a/krb5.spec b/krb5.spec index 1db95af..7cd5bc8 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 30%{?dist} +Release: 31%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -107,6 +107,7 @@ Patch143: Remove-support-for-no-flags-SAM-2-preauth.patch Patch144: Remove-krb5int_c_combine_keys.patch Patch145: Remove-3des-support.patch Patch146: krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch +Patch147: Remove-strerror-calls-from-k5_get_error.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -716,6 +717,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jun 10 2019 Robbie Harwood - 1.17-31 +- Remove strerror() calls from k5_get_error() + * Fri Jun 07 2019 Robbie Harwood - 1.17-30 - Remove 3des from kdc.conf example From 7bee5f19e1b1e17d80ed485adb324a746de118ec Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 26 Jun 2019 18:07:12 -0400 Subject: [PATCH 117/304] Remove PKINIT draft9 support (compat with EOL, pre-2008 Windows) --- Remove-3des-support.patch | 54 +- ...-PKINIT-draft-9-ASN.1-code-and-types.patch | 967 ++++++++++ Remove-PKINIT-draft-9-support.patch | 1712 +++++++++++++++++ Remove-strerror-calls-from-k5_get_error.patch | 2 +- ...ost4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch | 2 +- krb5.spec | 9 +- 6 files changed, 2719 insertions(+), 27 deletions(-) create mode 100644 Remove-PKINIT-draft-9-ASN.1-code-and-types.patch create mode 100644 Remove-PKINIT-draft-9-support.patch diff --git a/Remove-3des-support.patch b/Remove-3des-support.patch index 62161e5..be344a3 100644 --- a/Remove-3des-support.patch +++ b/Remove-3des-support.patch @@ -1,4 +1,4 @@ -From c6e61b6ce3f305765dab2acf05a676172c596ddd Mon Sep 17 00:00:00 2001 +From cac8b2d0da82fd625da0a351bb80b51a0bb811a2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] Remove 3des support @@ -7,6 +7,8 @@ Completely remove support for all DES3 enctypes (des3-cbc-raw, des3-hmac-sha1, des3-cbc-sha1-kd). Update all tests and documentation to user other enctypes. Mark the 3DES enctypes UNSUPPORTED and retain their constants. + +(cherry picked from commit 49b086ddbf861ad0e2e84c402f3d65e9ea8a2392) --- doc/admin/advanced/retiring-des.rst | 11 + doc/admin/conf_files/kdc_conf.rst | 7 +- @@ -16,7 +18,7 @@ their constants. doc/mitK5features.rst | 2 +- src/Makefile.in | 4 +- src/configure.in | 1 - - src/include/krb5/krb5.hin | 10 +- + src/include/krb5/krb5.hin | 12 +- src/kadmin/testing/proto/kdc.conf.proto | 4 +- src/kdc/kdc_util.c | 4 - src/lib/crypto/Makefile.in | 8 +- @@ -103,7 +105,7 @@ their constants. src/tests/t_salt.py | 5 +- src/util/k5test.py | 10 - .../leash/htmlhelp/html/Encryption_Types.htm | 13 - - 95 files changed, 162 insertions(+), 4836 deletions(-) + 95 files changed, 163 insertions(+), 4837 deletions(-) delete mode 100644 src/lib/crypto/builtin/des/ISSUES delete mode 100644 src/lib/crypto/builtin/des/Makefile.in delete mode 100644 src/lib/crypto/builtin/des/d3_aead.c @@ -300,9 +302,15 @@ index 8d781a7c8..a19a0ea97 100644 lib/crypto/$CRYPTO_IMPL/sha1 lib/crypto/$CRYPTO_IMPL/sha2 lib/crypto/$CRYPTO_IMPL/aes lib/crypto/$CRYPTO_IMPL/camellia diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 5f596d1fc..9a05ce32d 100644 +index 5f596d1fc..ca7eb6a80 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin +@@ -1,4 +1,4 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++./* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ + /* General definitions for Kerberos version 5. */ + /* + * Copyright 1989, 1990, 1995, 2001, 2003, 2007, 2011 by the Massachusetts @@ -426,8 +426,8 @@ typedef struct _krb5_crypto_iov { #define ENCTYPE_DES_CBC_MD4 0x0002 /**< @deprecated no longer supported */ #define ENCTYPE_DES_CBC_MD5 0x0003 /**< @deprecated no longer supported */ @@ -5771,29 +5779,29 @@ index 28ded4a89..47f4727bd 100644 #define CKK_CAST3 (0x17) #define CKK_CAST128 (0x18) diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c -index 58400d555..a5337b6f5 100644 +index 1a642139a..2f0431991 100644 --- a/src/plugins/preauth/pkinit/pkinit_clnt.c +++ b/src/plugins/preauth/pkinit/pkinit_clnt.c -@@ -237,14 +237,6 @@ pkinit_as_req_create(krb5_context context, - auth_pack.clientDHNonce.length = 0; - auth_pack.clientPublicValue = &info; - auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; +@@ -212,14 +212,6 @@ pkinit_as_req_create(krb5_context context, + auth_pack.clientPublicValue = &info; + auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; + +- /* add List of CMS algorithms */ +- retval = create_krb5_supportedCMSTypes(context, plgctx->cryptoctx, +- reqctx->cryptoctx, +- reqctx->idctx, &cmstypes); +- auth_pack.supportedCMSTypes = cmstypes; +- if (retval) +- goto cleanup; - -- /* add List of CMS algorithms */ -- retval = create_krb5_supportedCMSTypes(context, plgctx->cryptoctx, -- reqctx->cryptoctx, -- reqctx->idctx, &cmstypes); -- auth_pack.supportedCMSTypes = cmstypes; -- if (retval) -- goto cleanup; - break; - default: - pkiDebug("as_req: unrecognized pa_type = %d\n", + switch(protocol) { + case DH_PROTOCOL: + TRACE_PKINIT_CLIENT_REQ_DH(context); diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h -index 0acb731cd..d42acfa4b 100644 +index 8064a07d0..a291889b0 100644 --- a/src/plugins/preauth/pkinit/pkinit_crypto.h +++ b/src/plugins/preauth/pkinit/pkinit_crypto.h -@@ -381,18 +381,6 @@ krb5_error_code server_process_dh +@@ -380,18 +380,6 @@ krb5_error_code server_process_dh unsigned int *server_key_len_out); /* OUT receives length of DH secret key */ @@ -5813,10 +5821,10 @@ index 0acb731cd..d42acfa4b 100644 * this functions takes in crypto specific representation of * trustedCertifiers and creates a list of diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 8aa2c5257..b101d179f 100644 +index 8c7fd0cca..52976895b 100644 --- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -5596,44 +5596,6 @@ cleanup: +@@ -5487,44 +5487,6 @@ cleanup: return retval; } diff --git a/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch b/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch new file mode 100644 index 0000000..658991f --- /dev/null +++ b/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch @@ -0,0 +1,967 @@ +From fc909a6d2881c4b434c946023c5f581cec9e96c9 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 18 Jun 2019 11:40:48 -0400 +Subject: [PATCH] Remove PKINIT draft 9 ASN.1 code and types + +ticket: 8817 +(cherry picked from commit c82e21d8836d4cb4c6ac7047752c9f600cb1ce33) +--- + src/include/k5-int-pkinit.h | 74 -------------------------- + src/include/k5-int.h | 30 +---------- + src/lib/krb5/asn.1/asn1_k_encode.c | 81 ---------------------------- + src/lib/krb5/os/accessor.c | 7 --- + src/tests/asn.1/krb5_decode_test.c | 41 -------------- + src/tests/asn.1/krb5_encode_test.c | 40 -------------- + src/tests/asn.1/ktest.c | 85 ------------------------------ + src/tests/asn.1/ktest.h | 11 ---- + src/tests/asn.1/ktest_equal.c | 51 ------------------ + src/tests/asn.1/ktest_equal.h | 3 -- + src/tests/asn.1/pkinit_encode.out | 5 -- + src/tests/asn.1/pkinit_trval.out | 47 ----------------- + 12 files changed, 1 insertion(+), 474 deletions(-) + +diff --git a/src/include/k5-int-pkinit.h b/src/include/k5-int-pkinit.h +index 4622a629e..c23cfd304 100644 +--- a/src/include/k5-int-pkinit.h ++++ b/src/include/k5-int-pkinit.h +@@ -45,14 +45,6 @@ typedef struct _krb5_pk_authenticator { + krb5_data *freshnessToken; + } krb5_pk_authenticator; + +-/* PKAuthenticator draft9 */ +-typedef struct _krb5_pk_authenticator_draft9 { +- krb5_principal kdcName; +- krb5_int32 cusec; /* (0..999999) */ +- krb5_timestamp ctime; +- krb5_int32 nonce; /* (0..4294967295) */ +-} krb5_pk_authenticator_draft9; +- + /* AlgorithmIdentifier */ + typedef struct _krb5_algorithm_identifier { + krb5_data algorithm; /* OID */ +@@ -74,12 +66,6 @@ typedef struct _krb5_auth_pack { + krb5_data **supportedKDFs; /* OIDs of KDFs; OPTIONAL */ + } krb5_auth_pack; + +-/* AuthPack draft9 */ +-typedef struct _krb5_auth_pack_draft9 { +- krb5_pk_authenticator_draft9 pkAuthenticator; +- krb5_subject_pk_info *clientPublicValue; /* Optional */ +-} krb5_auth_pack_draft9; +- + /* ExternalPrincipalIdentifier */ + typedef struct _krb5_external_principal_identifier { + krb5_data subjectName; /* Optional */ +@@ -87,14 +73,6 @@ typedef struct _krb5_external_principal_identifier { + krb5_data subjectKeyIdentifier; /* Optional */ + } krb5_external_principal_identifier; + +-/* PA-PK-AS-REQ (Draft 9 -- PA TYPE 14) */ +-/* This has four fields, but we only care about the first and third for +- * encoding, and the only about the first for decoding. */ +-typedef struct _krb5_pa_pk_as_req_draft9 { +- krb5_data signedAuthPack; +- krb5_data kdcCert; /* Optional */ +-} krb5_pa_pk_as_req_draft9; +- + /* PA-PK-AS-REQ (rfc4556 -- PA TYPE 16) */ + typedef struct _krb5_pa_pk_as_req { + krb5_data signedAuthPack; +@@ -116,37 +94,12 @@ typedef struct _krb5_kdc_dh_key_info { + krb5_timestamp dhKeyExpiration; /* Optional */ + } krb5_kdc_dh_key_info; + +-/* KDCDHKeyInfo draft9*/ +-typedef struct _krb5_kdc_dh_key_info_draft9 { +- krb5_data subjectPublicKey; /* BIT STRING */ +- krb5_int32 nonce; /* (0..4294967295) */ +-} krb5_kdc_dh_key_info_draft9; +- + /* ReplyKeyPack */ + typedef struct _krb5_reply_key_pack { + krb5_keyblock replyKey; + krb5_checksum asChecksum; + } krb5_reply_key_pack; + +-/* ReplyKeyPack */ +-typedef struct _krb5_reply_key_pack_draft9 { +- krb5_keyblock replyKey; +- krb5_int32 nonce; +-} krb5_reply_key_pack_draft9; +- +-/* PA-PK-AS-REP (Draft 9 -- PA TYPE 15) */ +-typedef struct _krb5_pa_pk_as_rep_draft9 { +- enum krb5_pa_pk_as_rep_draft9_selection { +- choice_pa_pk_as_rep_draft9_UNKNOWN = -1, +- choice_pa_pk_as_rep_draft9_dhSignedData = 0, +- choice_pa_pk_as_rep_draft9_encKeyPack = 1 +- } choice; +- union krb5_pa_pk_as_rep_draft9_choices { +- krb5_data dhSignedData; +- krb5_data encKeyPack; +- } u; +-} krb5_pa_pk_as_rep_draft9; +- + /* PA-PK-AS-REP (rfc4556 -- PA TYPE 17) */ + typedef struct _krb5_pa_pk_as_rep { + enum krb5_pa_pk_as_rep_selection { +@@ -186,34 +139,18 @@ typedef struct _krb5_pkinit_supp_pub_info { + krb5_error_code + encode_krb5_pa_pk_as_req(const krb5_pa_pk_as_req *rep, krb5_data **code); + +-krb5_error_code +-encode_krb5_pa_pk_as_req_draft9(const krb5_pa_pk_as_req_draft9 *rep, +- krb5_data **code); +- + krb5_error_code + encode_krb5_pa_pk_as_rep(const krb5_pa_pk_as_rep *rep, krb5_data **code); + +-krb5_error_code +-encode_krb5_pa_pk_as_rep_draft9(const krb5_pa_pk_as_rep_draft9 *rep, +- krb5_data **code); +- + krb5_error_code + encode_krb5_auth_pack(const krb5_auth_pack *rep, krb5_data **code); + +-krb5_error_code +-encode_krb5_auth_pack_draft9(const krb5_auth_pack_draft9 *rep, +- krb5_data **code); +- + krb5_error_code + encode_krb5_kdc_dh_key_info(const krb5_kdc_dh_key_info *rep, krb5_data **code); + + krb5_error_code + encode_krb5_reply_key_pack(const krb5_reply_key_pack *, krb5_data **code); + +-krb5_error_code +-encode_krb5_reply_key_pack_draft9(const krb5_reply_key_pack_draft9 *, +- krb5_data **code); +- + krb5_error_code + encode_krb5_td_trusted_certifiers(krb5_external_principal_identifier *const *, + krb5_data **code); +@@ -237,19 +174,12 @@ encode_krb5_pkinit_supp_pub_info(const krb5_pkinit_supp_pub_info *, + krb5_error_code + decode_krb5_pa_pk_as_req(const krb5_data *, krb5_pa_pk_as_req **); + +-krb5_error_code +-decode_krb5_pa_pk_as_req_draft9(const krb5_data *, +- krb5_pa_pk_as_req_draft9 **); +- + krb5_error_code + decode_krb5_pa_pk_as_rep(const krb5_data *, krb5_pa_pk_as_rep **); + + krb5_error_code + decode_krb5_auth_pack(const krb5_data *, krb5_auth_pack **); + +-krb5_error_code +-decode_krb5_auth_pack_draft9(const krb5_data *, krb5_auth_pack_draft9 **); +- + krb5_error_code + decode_krb5_kdc_dh_key_info(const krb5_data *, krb5_kdc_dh_key_info **); + +@@ -259,10 +189,6 @@ decode_krb5_principal_name(const krb5_data *, krb5_principal_data **); + krb5_error_code + decode_krb5_reply_key_pack(const krb5_data *, krb5_reply_key_pack **); + +-krb5_error_code +-decode_krb5_reply_key_pack_draft9(const krb5_data *, +- krb5_reply_key_pack_draft9 **); +- + krb5_error_code + decode_krb5_td_trusted_certifiers(const krb5_data *, + krb5_external_principal_identifier ***); +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 0857fd1cc..cb328785d 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -1836,7 +1836,7 @@ krb5int_random_string(krb5_context, char *string, unsigned int length); + /* To keep happy libraries which are (for now) accessing internal stuff */ + + /* Make sure to increment by one when changing the struct */ +-#define KRB5INT_ACCESS_STRUCT_VERSION 22 ++#define KRB5INT_ACCESS_STRUCT_VERSION 23 + + typedef struct _krb5int_access { + krb5_error_code (*auth_con_get_subkey_enctype)(krb5_context, +@@ -1865,10 +1865,6 @@ typedef struct _krb5int_access { + krb5_error_code + (*encode_krb5_auth_pack)(const krb5_auth_pack *rep, krb5_data **code); + +- krb5_error_code +- (*encode_krb5_auth_pack_draft9)(const krb5_auth_pack_draft9 *rep, +- krb5_data **code); +- + krb5_error_code + (*encode_krb5_kdc_dh_key_info)(const krb5_kdc_dh_key_info *rep, + krb5_data **code); +@@ -1877,26 +1873,14 @@ typedef struct _krb5int_access { + (*encode_krb5_pa_pk_as_rep)(const krb5_pa_pk_as_rep *rep, + krb5_data **code); + +- krb5_error_code +- (*encode_krb5_pa_pk_as_rep_draft9)(const krb5_pa_pk_as_rep_draft9 *rep, +- krb5_data **code); +- + krb5_error_code + (*encode_krb5_pa_pk_as_req)(const krb5_pa_pk_as_req *rep, + krb5_data **code); + +- krb5_error_code +- (*encode_krb5_pa_pk_as_req_draft9)(const krb5_pa_pk_as_req_draft9 *rep, +- krb5_data **code); +- + krb5_error_code + (*encode_krb5_reply_key_pack)(const krb5_reply_key_pack *, + krb5_data **code); + +- krb5_error_code +- (*encode_krb5_reply_key_pack_draft9)(const krb5_reply_key_pack_draft9 *, +- krb5_data **code); +- + krb5_error_code + (*encode_krb5_td_dh_parameters)(krb5_algorithm_identifier *const *, + krb5_data **code); +@@ -1908,17 +1892,9 @@ typedef struct _krb5int_access { + krb5_error_code + (*decode_krb5_auth_pack)(const krb5_data *, krb5_auth_pack **); + +- krb5_error_code +- (*decode_krb5_auth_pack_draft9)(const krb5_data *, +- krb5_auth_pack_draft9 **); +- + krb5_error_code + (*decode_krb5_pa_pk_as_req)(const krb5_data *, krb5_pa_pk_as_req **); + +- krb5_error_code +- (*decode_krb5_pa_pk_as_req_draft9)(const krb5_data *, +- krb5_pa_pk_as_req_draft9 **); +- + krb5_error_code + (*decode_krb5_pa_pk_as_rep)(const krb5_data *, krb5_pa_pk_as_rep **); + +@@ -1931,10 +1907,6 @@ typedef struct _krb5int_access { + krb5_error_code + (*decode_krb5_reply_key_pack)(const krb5_data *, krb5_reply_key_pack **); + +- krb5_error_code +- (*decode_krb5_reply_key_pack_draft9)(const krb5_data *, +- krb5_reply_key_pack_draft9 **); +- + krb5_error_code + (*decode_krb5_td_dh_parameters)(const krb5_data *, + krb5_algorithm_identifier ***); +diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c +index 81a34bac9..a026ab390 100644 +--- a/src/lib/krb5/asn.1/asn1_k_encode.c ++++ b/src/lib/krb5/asn.1/asn1_k_encode.c +@@ -1446,19 +1446,6 @@ static const struct atype_info *pk_authenticator_fields[] = { + }; + DEFSEQTYPE(pk_authenticator, krb5_pk_authenticator, pk_authenticator_fields); + +-DEFFIELD(pkauth9_0, krb5_pk_authenticator_draft9, kdcName, 0, principal); +-DEFFIELD(pkauth9_1, krb5_pk_authenticator_draft9, kdcName, 1, +- realm_of_principal); +-DEFFIELD(pkauth9_2, krb5_pk_authenticator_draft9, cusec, 2, int32); +-DEFFIELD(pkauth9_3, krb5_pk_authenticator_draft9, ctime, 3, kerberos_time); +-DEFFIELD(pkauth9_4, krb5_pk_authenticator_draft9, nonce, 4, int32); +-static const struct atype_info *pk_authenticator_draft9_fields[] = { +- &k5_atype_pkauth9_0, &k5_atype_pkauth9_1, &k5_atype_pkauth9_2, +- &k5_atype_pkauth9_3, &k5_atype_pkauth9_4 +-}; +-DEFSEQTYPE(pk_authenticator_draft9, krb5_pk_authenticator_draft9, +- pk_authenticator_draft9_fields); +- + DEFCOUNTEDSTRINGTYPE(s_bitstring, char *, unsigned int, + k5_asn1_encode_bitstring, k5_asn1_decode_bitstring, + ASN1_BITSTRING); +@@ -1488,15 +1475,6 @@ static const struct atype_info *auth_pack_fields[] = { + }; + DEFSEQTYPE(auth_pack, krb5_auth_pack, auth_pack_fields); + +-DEFFIELD(auth_pack9_0, krb5_auth_pack_draft9, pkAuthenticator, 0, +- pk_authenticator_draft9); +-DEFFIELD(auth_pack9_1, krb5_auth_pack_draft9, clientPublicValue, 1, +- opt_subject_pk_info_ptr); +-static const struct atype_info *auth_pack_draft9_fields[] = { +- &k5_atype_auth_pack9_0, &k5_atype_auth_pack9_1 +-}; +-DEFSEQTYPE(auth_pack_draft9, krb5_auth_pack_draft9, auth_pack_draft9_fields); +- + DEFFIELD_IMPLICIT(extprinc_0, krb5_external_principal_identifier, + subjectName, 0, opt_ostring_data); + DEFFIELD_IMPLICIT(extprinc_1, krb5_external_principal_identifier, +@@ -1529,29 +1507,6 @@ static const struct atype_info *pa_pk_as_req_fields[] = { + }; + DEFSEQTYPE(pa_pk_as_req, krb5_pa_pk_as_req, pa_pk_as_req_fields); + +-/* +- * In draft-ietf-cat-kerberos-pk-init-09, this sequence has four fields, but we +- * only ever use the first and third. The fields are specified as explicitly +- * tagged, but our historical behavior is to pretend that they are wrapped in +- * IMPLICIT OCTET STRING (i.e., generate primitive context tags), and we don't +- * want to change that without interop testing. +- */ +-DEFFIELD_IMPLICIT(pa_pk_as_req9_0, krb5_pa_pk_as_req_draft9, signedAuthPack, 0, +- ostring_data); +-DEFFIELD_IMPLICIT(pa_pk_as_req9_2, krb5_pa_pk_as_req_draft9, kdcCert, 2, +- opt_ostring_data); +-static const struct atype_info *pa_pk_as_req_draft9_fields[] = { +- &k5_atype_pa_pk_as_req9_0, &k5_atype_pa_pk_as_req9_2 +-}; +-DEFSEQTYPE(pa_pk_as_req_draft9, krb5_pa_pk_as_req_draft9, +- pa_pk_as_req_draft9_fields); +-/* For decoding, we only care about the first field; we can ignore the rest. */ +-static const struct atype_info *pa_pk_as_req_draft9_decode_fields[] = { +- &k5_atype_pa_pk_as_req9_0 +-}; +-DEFSEQTYPE(pa_pk_as_req_draft9_decode, krb5_pa_pk_as_req_draft9, +- pa_pk_as_req_draft9_decode_fields); +- + DEFFIELD_IMPLICIT(dh_rep_info_0, krb5_dh_rep_info, dhSignedData, 0, + ostring_data); + DEFFIELD(dh_rep_info_1, krb5_dh_rep_info, serverDHNonce, 1, opt_ostring_data); +@@ -1577,14 +1532,6 @@ static const struct atype_info *reply_key_pack_fields[] = { + }; + DEFSEQTYPE(reply_key_pack, krb5_reply_key_pack, reply_key_pack_fields); + +-DEFFIELD(key_pack9_0, krb5_reply_key_pack_draft9, replyKey, 0, encryption_key); +-DEFFIELD(key_pack9_1, krb5_reply_key_pack_draft9, nonce, 1, int32); +-static const struct atype_info *reply_key_pack_draft9_fields[] = { +- &k5_atype_key_pack9_0, &k5_atype_key_pack9_1 +-}; +-DEFSEQTYPE(reply_key_pack_draft9, krb5_reply_key_pack_draft9, +- reply_key_pack_draft9_fields); +- + DEFCTAGGEDTYPE(pa_pk_as_rep_0, 0, dh_rep_info); + DEFCTAGGEDTYPE_IMPLICIT(pa_pk_as_rep_1, 1, ostring_data); + static const struct atype_info *pa_pk_as_rep_alternatives[] = { +@@ -1595,44 +1542,16 @@ DEFCHOICETYPE(pa_pk_as_rep_choice, union krb5_pa_pk_as_rep_choices, + DEFCOUNTEDTYPE_SIGNED(pa_pk_as_rep, krb5_pa_pk_as_rep, u, choice, + pa_pk_as_rep_choice); + +-/* +- * draft-ietf-cat-kerberos-pk-init-09 specifies these alternatives as +- * explicitly tagged SignedData and EnvelopedData respectively, which means +- * they should have constructed context tags. However, our historical behavior +- * is to use primitive context tags, and we don't want to change that behavior +- * without interop testing. We have the encodings for each alternative in a +- * krb5_data object; pretend that they are wrapped in IMPLICIT OCTET STRING in +- * order to wrap them in primitive [0] and [1] tags. +- */ +-DEFCTAGGEDTYPE_IMPLICIT(pa_pk_as_rep9_0, 0, ostring_data); +-DEFCTAGGEDTYPE_IMPLICIT(pa_pk_as_rep9_1, 1, ostring_data); +-static const struct atype_info *pa_pk_as_rep_draft9_alternatives[] = { +- &k5_atype_pa_pk_as_rep9_0, &k5_atype_pa_pk_as_rep9_1 +-}; +-DEFCHOICETYPE(pa_pk_as_rep_draft9_choice, +- union krb5_pa_pk_as_rep_draft9_choices, +- enum krb5_pa_pk_as_rep_draft9_selection, +- pa_pk_as_rep_draft9_alternatives); +-DEFCOUNTEDTYPE_SIGNED(pa_pk_as_rep_draft9, krb5_pa_pk_as_rep_draft9, u, choice, +- pa_pk_as_rep_draft9_choice); +- + MAKE_ENCODER(encode_krb5_pa_pk_as_req, pa_pk_as_req); + MAKE_DECODER(decode_krb5_pa_pk_as_req, pa_pk_as_req); +-MAKE_ENCODER(encode_krb5_pa_pk_as_req_draft9, pa_pk_as_req_draft9); +-MAKE_DECODER(decode_krb5_pa_pk_as_req_draft9, pa_pk_as_req_draft9_decode); + MAKE_ENCODER(encode_krb5_pa_pk_as_rep, pa_pk_as_rep); + MAKE_DECODER(decode_krb5_pa_pk_as_rep, pa_pk_as_rep); +-MAKE_ENCODER(encode_krb5_pa_pk_as_rep_draft9, pa_pk_as_rep_draft9); + MAKE_ENCODER(encode_krb5_auth_pack, auth_pack); + MAKE_DECODER(decode_krb5_auth_pack, auth_pack); +-MAKE_ENCODER(encode_krb5_auth_pack_draft9, auth_pack_draft9); +-MAKE_DECODER(decode_krb5_auth_pack_draft9, auth_pack_draft9); + MAKE_ENCODER(encode_krb5_kdc_dh_key_info, kdc_dh_key_info); + MAKE_DECODER(decode_krb5_kdc_dh_key_info, kdc_dh_key_info); + MAKE_ENCODER(encode_krb5_reply_key_pack, reply_key_pack); + MAKE_DECODER(decode_krb5_reply_key_pack, reply_key_pack); +-MAKE_ENCODER(encode_krb5_reply_key_pack_draft9, reply_key_pack_draft9); +-MAKE_DECODER(decode_krb5_reply_key_pack_draft9, reply_key_pack_draft9); + MAKE_ENCODER(encode_krb5_td_trusted_certifiers, + seqof_external_principal_identifier); + MAKE_DECODER(decode_krb5_td_trusted_certifiers, +diff --git a/src/lib/krb5/os/accessor.c b/src/lib/krb5/os/accessor.c +index d77f8c6b7..12a39a2ab 100644 +--- a/src/lib/krb5/os/accessor.c ++++ b/src/lib/krb5/os/accessor.c +@@ -80,25 +80,18 @@ krb5int_accessor(krb5int_access *internals, krb5_int32 version) + #define SC(FIELD, VAL) S(FIELD, 0) + #endif + SC (encode_krb5_pa_pk_as_req, encode_krb5_pa_pk_as_req), +- SC (encode_krb5_pa_pk_as_req_draft9, encode_krb5_pa_pk_as_req_draft9), + SC (encode_krb5_pa_pk_as_rep, encode_krb5_pa_pk_as_rep), +- SC (encode_krb5_pa_pk_as_rep_draft9, encode_krb5_pa_pk_as_rep_draft9), + SC (encode_krb5_auth_pack, encode_krb5_auth_pack), +- SC (encode_krb5_auth_pack_draft9, encode_krb5_auth_pack_draft9), + SC (encode_krb5_kdc_dh_key_info, encode_krb5_kdc_dh_key_info), + SC (encode_krb5_reply_key_pack, encode_krb5_reply_key_pack), +- SC (encode_krb5_reply_key_pack_draft9, encode_krb5_reply_key_pack_draft9), + SC (encode_krb5_td_trusted_certifiers, encode_krb5_td_trusted_certifiers), + SC (encode_krb5_td_dh_parameters, encode_krb5_td_dh_parameters), + SC (decode_krb5_pa_pk_as_req, decode_krb5_pa_pk_as_req), +- SC (decode_krb5_pa_pk_as_req_draft9, decode_krb5_pa_pk_as_req_draft9), + SC (decode_krb5_pa_pk_as_rep, decode_krb5_pa_pk_as_rep), + SC (decode_krb5_auth_pack, decode_krb5_auth_pack), +- SC (decode_krb5_auth_pack_draft9, decode_krb5_auth_pack_draft9), + SC (decode_krb5_kdc_dh_key_info, decode_krb5_kdc_dh_key_info), + SC (decode_krb5_principal_name, decode_krb5_principal_name), + SC (decode_krb5_reply_key_pack, decode_krb5_reply_key_pack), +- SC (decode_krb5_reply_key_pack_draft9, decode_krb5_reply_key_pack_draft9), + SC (decode_krb5_td_trusted_certifiers, decode_krb5_td_trusted_certifiers), + SC (decode_krb5_td_dh_parameters, decode_krb5_td_dh_parameters), + SC (encode_krb5_kdc_req_body, encode_krb5_kdc_req_body), +diff --git a/src/tests/asn.1/krb5_decode_test.c b/src/tests/asn.1/krb5_decode_test.c +index cbd99ba63..7a116b40d 100644 +--- a/src/tests/asn.1/krb5_decode_test.c ++++ b/src/tests/asn.1/krb5_decode_test.c +@@ -42,8 +42,6 @@ void krb5_ktest_free_enc_data(krb5_context context, krb5_enc_data *val); + #ifndef DISABLE_PKINIT + static int equal_principal(krb5_principal *ref, krb5_principal var); + static void ktest_free_auth_pack(krb5_context context, krb5_auth_pack *val); +-static void ktest_free_auth_pack_draft9(krb5_context context, +- krb5_auth_pack_draft9 *val); + static void ktest_free_kdc_dh_key_info(krb5_context context, + krb5_kdc_dh_key_info *val); + static void ktest_free_pa_pk_as_req(krb5_context context, +@@ -52,8 +50,6 @@ static void ktest_free_pa_pk_as_rep(krb5_context context, + krb5_pa_pk_as_rep *val); + static void ktest_free_reply_key_pack(krb5_context context, + krb5_reply_key_pack *val); +-static void ktest_free_reply_key_pack_draft9(krb5_context context, +- krb5_reply_key_pack_draft9 *val); + #endif + static void ktest_free_kkdcp_message(krb5_context context, + krb5_kkdcp_message *val); +@@ -1183,16 +1179,6 @@ int main(argc, argv) + ktest_empty_auth_pack(&ref); + } + +- /****************************************************************/ +- /* decode_krb5_auth_pack_draft9 */ +- { +- setup(krb5_auth_pack_draft9,ktest_make_sample_auth_pack_draft9); +- decode_run("krb5_auth_pack_draft9","","30 75 A0 4F 30 4D A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A2 05 02 03 01 E2 40 A3 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A4 03 02 01 2A A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61", +- acc.decode_krb5_auth_pack_draft9, +- ktest_equal_auth_pack_draft9,ktest_free_auth_pack_draft9); +- ktest_empty_auth_pack_draft9(&ref); +- } +- + /****************************************************************/ + /* decode_krb5_kdc_dh_key_info */ + { +@@ -1213,16 +1199,6 @@ int main(argc, argv) + ktest_empty_reply_key_pack(&ref); + } + +- /****************************************************************/ +- /* decode_krb5_reply_key_pack_draft9 */ +- { +- setup(krb5_reply_key_pack_draft9,ktest_make_sample_reply_key_pack_draft9); +- decode_run("krb5_reply_key_pack_draft9","","30 1A A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 03 02 01 2A", +- acc.decode_krb5_reply_key_pack_draft9, +- ktest_equal_reply_key_pack_draft9,ktest_free_reply_key_pack_draft9); +- ktest_empty_reply_key_pack_draft9(&ref); +- } +- + /****************************************************************/ + /* decode_krb5_principal_name */ + /* We have no encoder for this type (KerberosName from RFC 4556); the +@@ -1279,14 +1255,6 @@ ktest_free_auth_pack(krb5_context context, krb5_auth_pack *val) + free(val); + } + +-static void +-ktest_free_auth_pack_draft9(krb5_context context, krb5_auth_pack_draft9 *val) +-{ +- if (val) +- ktest_empty_auth_pack_draft9(val); +- free(val); +-} +- + static void + ktest_free_kdc_dh_key_info(krb5_context context, krb5_kdc_dh_key_info *val) + { +@@ -1319,15 +1287,6 @@ ktest_free_reply_key_pack(krb5_context context, krb5_reply_key_pack *val) + free(val); + } + +-static void +-ktest_free_reply_key_pack_draft9(krb5_context context, +- krb5_reply_key_pack_draft9 *val) +-{ +- if (val) +- ktest_empty_reply_key_pack_draft9(val); +- free(val); +-} +- + #endif /* not DISABLE_PKINIT */ + + static void +diff --git a/src/tests/asn.1/krb5_encode_test.c b/src/tests/asn.1/krb5_encode_test.c +index 3efbfb4c0..72c013468 100644 +--- a/src/tests/asn.1/krb5_encode_test.c ++++ b/src/tests/asn.1/krb5_encode_test.c +@@ -798,15 +798,6 @@ main(argc, argv) + ktest_empty_pa_pk_as_req(&req); + } + /****************************************************************/ +- /* encode_krb5_pa_pk_as_req_draft9 */ +- { +- krb5_pa_pk_as_req_draft9 req; +- ktest_make_sample_pa_pk_as_req_draft9(&req); +- encode_run(req, "pa_pk_as_req_draft9", "", +- acc.encode_krb5_pa_pk_as_req_draft9); +- ktest_empty_pa_pk_as_req_draft9(&req); +- } +- /****************************************************************/ + /* encode_krb5_pa_pk_as_rep */ + { + krb5_pa_pk_as_rep rep; +@@ -820,19 +811,6 @@ main(argc, argv) + ktest_empty_pa_pk_as_rep(&rep); + } + /****************************************************************/ +- /* encode_krb5_pa_pk_as_rep_draft9 */ +- { +- krb5_pa_pk_as_rep_draft9 rep; +- ktest_make_sample_pa_pk_as_rep_draft9_dhSignedData(&rep); +- encode_run(rep, "pa_pk_as_rep_draft9", "(dhSignedData)", +- acc.encode_krb5_pa_pk_as_rep_draft9); +- ktest_empty_pa_pk_as_rep_draft9(&rep); +- ktest_make_sample_pa_pk_as_rep_draft9_encKeyPack(&rep); +- encode_run(rep, "pa_pk_as_rep_draft9", "(encKeyPack)", +- acc.encode_krb5_pa_pk_as_rep_draft9); +- ktest_empty_pa_pk_as_rep_draft9(&rep); +- } +- /****************************************************************/ + /* encode_krb5_auth_pack */ + { + krb5_auth_pack pack; +@@ -841,15 +819,6 @@ main(argc, argv) + ktest_empty_auth_pack(&pack); + } + /****************************************************************/ +- /* encode_krb5_auth_pack_draft9_draft9 */ +- { +- krb5_auth_pack_draft9 pack; +- ktest_make_sample_auth_pack_draft9(&pack); +- encode_run(pack, "auth_pack_draft9", "", +- acc.encode_krb5_auth_pack_draft9); +- ktest_empty_auth_pack_draft9(&pack); +- } +- /****************************************************************/ + /* encode_krb5_kdc_dh_key_info */ + { + krb5_kdc_dh_key_info ki; +@@ -866,15 +835,6 @@ main(argc, argv) + ktest_empty_reply_key_pack(&pack); + } + /****************************************************************/ +- /* encode_krb5_reply_key_pack_draft9 */ +- { +- krb5_reply_key_pack_draft9 pack; +- ktest_make_sample_reply_key_pack_draft9(&pack); +- encode_run(pack, "reply_key_pack_draft9", "", +- acc.encode_krb5_reply_key_pack_draft9); +- ktest_empty_reply_key_pack_draft9(&pack); +- } +- /****************************************************************/ + /* encode_krb5_sp80056a_other_info */ + { + krb5_sp80056a_other_info info; +diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c +index 258377299..7bb698732 100644 +--- a/src/tests/asn.1/ktest.c ++++ b/src/tests/asn.1/ktest.c +@@ -729,15 +729,6 @@ ktest_make_sample_pk_authenticator(krb5_pk_authenticator *p) + ktest_make_sample_data(p->freshnessToken); + } + +-static void +-ktest_make_sample_pk_authenticator_draft9(krb5_pk_authenticator_draft9 *p) +-{ +- ktest_make_sample_principal(&p->kdcName); +- p->cusec = SAMPLE_USEC; +- p->ctime = SAMPLE_TIME; +- p->nonce = SAMPLE_NONCE; +-} +- + static void + ktest_make_sample_oid(krb5_data *p) + { +@@ -788,13 +779,6 @@ ktest_make_sample_pa_pk_as_req(krb5_pa_pk_as_req *p) + ktest_make_sample_data(&p->kdcPkId); + } + +-void +-ktest_make_sample_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *p) +-{ +- ktest_make_sample_data(&p->signedAuthPack); +- ktest_make_sample_data(&p->kdcCert); +-} +- + static void + ktest_make_sample_dh_rep_info(krb5_dh_rep_info *p) + { +@@ -818,20 +802,6 @@ ktest_make_sample_pa_pk_as_rep_encKeyPack(krb5_pa_pk_as_rep *p) + ktest_make_sample_data(&p->u.encKeyPack); + } + +-void +-ktest_make_sample_pa_pk_as_rep_draft9_dhSignedData(krb5_pa_pk_as_rep_draft9 *p) +-{ +- p->choice = choice_pa_pk_as_rep_draft9_dhSignedData; +- ktest_make_sample_data(&p->u.dhSignedData); +-} +- +-void +-ktest_make_sample_pa_pk_as_rep_draft9_encKeyPack(krb5_pa_pk_as_rep_draft9 *p) +-{ +- p->choice = choice_pa_pk_as_rep_draft9_encKeyPack; +- ktest_make_sample_data(&p->u.encKeyPack); +-} +- + void + ktest_make_sample_auth_pack(krb5_auth_pack *p) + { +@@ -851,14 +821,6 @@ ktest_make_sample_auth_pack(krb5_auth_pack *p) + p->supportedKDFs[1] = NULL; + } + +-void +-ktest_make_sample_auth_pack_draft9(krb5_auth_pack_draft9 *p) +-{ +- ktest_make_sample_pk_authenticator_draft9(&p->pkAuthenticator); +- p->clientPublicValue = ealloc(sizeof(krb5_subject_pk_info)); +- ktest_make_sample_subject_pk_info(p->clientPublicValue); +-} +- + void + ktest_make_sample_kdc_dh_key_info(krb5_kdc_dh_key_info *p) + { +@@ -874,13 +836,6 @@ ktest_make_sample_reply_key_pack(krb5_reply_key_pack *p) + ktest_make_sample_checksum(&p->asChecksum); + } + +-void +-ktest_make_sample_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *p) +-{ +- ktest_make_sample_keyblock(&p->replyKey); +- p->nonce = SAMPLE_NONCE; +-} +- + void + ktest_make_sample_sp80056a_other_info(krb5_sp80056a_other_info *p) + { +@@ -1717,12 +1672,6 @@ ktest_empty_pk_authenticator(krb5_pk_authenticator *p) + p->freshnessToken = NULL; + } + +-static void +-ktest_empty_pk_authenticator_draft9(krb5_pk_authenticator_draft9 *p) +-{ +- ktest_destroy_principal(&p->kdcName); +-} +- + static void + ktest_empty_subject_pk_info(krb5_subject_pk_info *p) + { +@@ -1754,13 +1703,6 @@ ktest_empty_pa_pk_as_req(krb5_pa_pk_as_req *p) + ktest_empty_data(&p->kdcPkId); + } + +-void +-ktest_empty_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *p) +-{ +- ktest_empty_data(&p->signedAuthPack); +- ktest_empty_data(&p->kdcCert); +-} +- + static void + ktest_empty_dh_rep_info(krb5_dh_rep_info *p) + { +@@ -1779,16 +1721,6 @@ ktest_empty_pa_pk_as_rep(krb5_pa_pk_as_rep *p) + p->choice = choice_pa_pk_as_rep_UNKNOWN; + } + +-void +-ktest_empty_pa_pk_as_rep_draft9(krb5_pa_pk_as_rep_draft9 *p) +-{ +- if (p->choice == choice_pa_pk_as_rep_draft9_dhSignedData) +- ktest_empty_data(&p->u.dhSignedData); +- else if (p->choice == choice_pa_pk_as_rep_draft9_encKeyPack) +- ktest_empty_data(&p->u.encKeyPack); +- p->choice = choice_pa_pk_as_rep_draft9_UNKNOWN; +-} +- + void + ktest_empty_auth_pack(krb5_auth_pack *p) + { +@@ -1820,17 +1752,6 @@ ktest_empty_auth_pack(krb5_auth_pack *p) + } + } + +-void +-ktest_empty_auth_pack_draft9(krb5_auth_pack_draft9 *p) +-{ +- ktest_empty_pk_authenticator_draft9(&p->pkAuthenticator); +- if (p->clientPublicValue != NULL) { +- ktest_empty_subject_pk_info(p->clientPublicValue); +- free(p->clientPublicValue); +- p->clientPublicValue = NULL; +- } +-} +- + void + ktest_empty_kdc_dh_key_info(krb5_kdc_dh_key_info *p) + { +@@ -1844,12 +1765,6 @@ ktest_empty_reply_key_pack(krb5_reply_key_pack *p) + ktest_empty_checksum(&p->asChecksum); + } + +-void +-ktest_empty_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *p) +-{ +- ktest_empty_keyblock(&p->replyKey); +-} +- + void ktest_empty_sp80056a_other_info(krb5_sp80056a_other_info *p) + { + ktest_empty_algorithm_identifier(&p->algorithm_identifier); +diff --git a/src/tests/asn.1/ktest.h b/src/tests/asn.1/ktest.h +index 1413cfae1..d9cc90a5c 100644 +--- a/src/tests/asn.1/ktest.h ++++ b/src/tests/asn.1/ktest.h +@@ -101,18 +101,11 @@ void ktest_make_maximal_pa_otp_req(krb5_pa_otp_req *p); + + #ifndef DISABLE_PKINIT + void ktest_make_sample_pa_pk_as_req(krb5_pa_pk_as_req *p); +-void ktest_make_sample_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *p); + void ktest_make_sample_pa_pk_as_rep_dhInfo(krb5_pa_pk_as_rep *p); + void ktest_make_sample_pa_pk_as_rep_encKeyPack(krb5_pa_pk_as_rep *p); +-void ktest_make_sample_pa_pk_as_rep_draft9_dhSignedData( +- krb5_pa_pk_as_rep_draft9 *p); +-void ktest_make_sample_pa_pk_as_rep_draft9_encKeyPack( +- krb5_pa_pk_as_rep_draft9 *p); + void ktest_make_sample_auth_pack(krb5_auth_pack *p); +-void ktest_make_sample_auth_pack_draft9(krb5_auth_pack_draft9 *p); + void ktest_make_sample_kdc_dh_key_info(krb5_kdc_dh_key_info *p); + void ktest_make_sample_reply_key_pack(krb5_reply_key_pack *p); +-void ktest_make_sample_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *p); + void ktest_make_sample_sp80056a_other_info(krb5_sp80056a_other_info *p); + void ktest_make_sample_pkinit_supp_pub_info(krb5_pkinit_supp_pub_info *p); + #endif +@@ -197,14 +190,10 @@ void ktest_empty_pa_otp_req(krb5_pa_otp_req *p); + + #ifndef DISABLE_PKINIT + void ktest_empty_pa_pk_as_req(krb5_pa_pk_as_req *p); +-void ktest_empty_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *p); + void ktest_empty_pa_pk_as_rep(krb5_pa_pk_as_rep *p); +-void ktest_empty_pa_pk_as_rep_draft9(krb5_pa_pk_as_rep_draft9 *p); + void ktest_empty_auth_pack(krb5_auth_pack *p); +-void ktest_empty_auth_pack_draft9(krb5_auth_pack_draft9 *p); + void ktest_empty_kdc_dh_key_info(krb5_kdc_dh_key_info *p); + void ktest_empty_reply_key_pack(krb5_reply_key_pack *p); +-void ktest_empty_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *p); + void ktest_empty_sp80056a_other_info(krb5_sp80056a_other_info *p); + void ktest_empty_pkinit_supp_pub_info(krb5_pkinit_supp_pub_info *p); + #endif +diff --git a/src/tests/asn.1/ktest_equal.c b/src/tests/asn.1/ktest_equal.c +index 714cc4398..8a3911cdc 100644 +--- a/src/tests/asn.1/ktest_equal.c ++++ b/src/tests/asn.1/ktest_equal.c +@@ -876,20 +876,6 @@ ktest_equal_pk_authenticator(krb5_pk_authenticator *ref, + return p; + } + +-static int +-ktest_equal_pk_authenticator_draft9(krb5_pk_authenticator_draft9 *ref, +- krb5_pk_authenticator_draft9 *var) +-{ +- int p = TRUE; +- if (ref == var) return TRUE; +- else if (ref == NULL || var == NULL) return FALSE; +- p = p && ptr_equal(kdcName, ktest_equal_principal_data); +- p = p && scalar_equal(cusec); +- p = p && scalar_equal(ctime); +- p = p && scalar_equal(nonce); +- return p; +-} +- + static int + ktest_equal_subject_pk_info(krb5_subject_pk_info *ref, + krb5_subject_pk_info *var) +@@ -937,18 +923,6 @@ ktest_equal_pa_pk_as_req(krb5_pa_pk_as_req *ref, krb5_pa_pk_as_req *var) + return p; + } + +-int +-ktest_equal_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *ref, +- krb5_pa_pk_as_req_draft9 *var) +-{ +- int p = TRUE; +- if (ref == var) return TRUE; +- else if (ref == NULL || var == NULL) return FALSE; +- p = p && equal_str(signedAuthPack); +- p = p && equal_str(kdcCert); +- return p; +-} +- + static int + ktest_equal_dh_rep_info(krb5_dh_rep_info *ref, krb5_dh_rep_info *var) + { +@@ -996,19 +970,6 @@ ktest_equal_auth_pack(krb5_auth_pack *ref, krb5_auth_pack *var) + return p; + } + +-int +-ktest_equal_auth_pack_draft9(krb5_auth_pack_draft9 *ref, +- krb5_auth_pack_draft9 *var) +-{ +- int p = TRUE; +- if (ref == var) return TRUE; +- else if (ref == NULL || var == NULL) return FALSE; +- p = p && struct_equal(pkAuthenticator, +- ktest_equal_pk_authenticator_draft9); +- p = p && ptr_equal(clientPublicValue, ktest_equal_subject_pk_info); +- return p; +-} +- + int + ktest_equal_kdc_dh_key_info(krb5_kdc_dh_key_info *ref, + krb5_kdc_dh_key_info *var) +@@ -1033,18 +994,6 @@ ktest_equal_reply_key_pack(krb5_reply_key_pack *ref, krb5_reply_key_pack *var) + return p; + } + +-int +-ktest_equal_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *ref, +- krb5_reply_key_pack_draft9 *var) +-{ +- int p = TRUE; +- if (ref == var) return TRUE; +- else if (ref == NULL || var == NULL) return FALSE; +- p = p && struct_equal(replyKey, ktest_equal_keyblock); +- p = p && scalar_equal(nonce); +- return p; +-} +- + #endif /* not DISABLE_PKINIT */ + + int +diff --git a/src/tests/asn.1/ktest_equal.h b/src/tests/asn.1/ktest_equal.h +index cfa82ac6e..80a0d781a 100644 +--- a/src/tests/asn.1/ktest_equal.h ++++ b/src/tests/asn.1/ktest_equal.h +@@ -139,13 +139,10 @@ int ktest_equal_ldap_sequence_of_keys(ldap_seqof_key_data *ref, + + #ifndef DISABLE_PKINIT + generic(ktest_equal_pa_pk_as_req, krb5_pa_pk_as_req); +-generic(ktest_equal_pa_pk_as_req_draft9, krb5_pa_pk_as_req_draft9); + generic(ktest_equal_pa_pk_as_rep, krb5_pa_pk_as_rep); + generic(ktest_equal_auth_pack, krb5_auth_pack); +-generic(ktest_equal_auth_pack_draft9, krb5_auth_pack_draft9); + generic(ktest_equal_kdc_dh_key_info, krb5_kdc_dh_key_info); + generic(ktest_equal_reply_key_pack, krb5_reply_key_pack); +-generic(ktest_equal_reply_key_pack_draft9, krb5_reply_key_pack_draft9); + #endif /* not DISABLE_PKINIT */ + + int ktest_equal_kkdcp_message(krb5_kkdcp_message *ref, +diff --git a/src/tests/asn.1/pkinit_encode.out b/src/tests/asn.1/pkinit_encode.out +index 55a60bbef..9bd08e159 100644 +--- a/src/tests/asn.1/pkinit_encode.out ++++ b/src/tests/asn.1/pkinit_encode.out +@@ -1,13 +1,8 @@ + encode_krb5_pa_pk_as_req: 30 38 80 08 6B 72 62 35 64 61 74 61 A1 22 30 20 30 1E 80 08 6B 72 62 35 64 61 74 61 81 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61 +-encode_krb5_pa_pk_as_req_draft9: 30 14 80 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61 + encode_krb5_pa_pk_as_rep(dhInfo): A0 28 30 26 80 08 6B 72 62 35 64 61 74 61 A1 0A 04 08 6B 72 62 35 64 61 74 61 A2 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61 + encode_krb5_pa_pk_as_rep(encKeyPack): 81 08 6B 72 62 35 64 61 74 61 +-encode_krb5_pa_pk_as_rep_draft9(dhSignedData): 80 08 6B 72 62 35 64 61 74 61 +-encode_krb5_pa_pk_as_rep_draft9(encKeyPack): 81 08 6B 72 62 35 64 61 74 61 + encode_krb5_auth_pack: 30 81 9F A0 35 30 33 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61 +-encode_krb5_auth_pack_draft9: 30 75 A0 4F 30 4D A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A2 05 02 03 01 E2 40 A3 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A4 03 02 01 2A A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61 + encode_krb5_kdc_dh_key_info: 30 25 A0 0B 03 09 00 6B 72 62 35 64 61 74 61 A1 03 02 01 2A A2 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A + encode_krb5_reply_key_pack: 30 26 A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34 +-encode_krb5_reply_key_pack_draft9: 30 1A A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 03 02 01 2A + encode_krb5_sp80056a_other_info: 30 81 81 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A0 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A2 0A 04 08 6B 72 62 35 64 61 74 61 + encode_krb5_pkinit_supp_pub_info: 30 1D A0 03 02 01 14 A1 0A 04 08 6B 72 62 35 64 61 74 61 A2 0A 04 08 6B 72 62 35 64 61 74 61 +diff --git a/src/tests/asn.1/pkinit_trval.out b/src/tests/asn.1/pkinit_trval.out +index 9557188a8..3675fba38 100644 +--- a/src/tests/asn.1/pkinit_trval.out ++++ b/src/tests/asn.1/pkinit_trval.out +@@ -15,14 +15,6 @@ encode_krb5_pa_pk_as_req: + . [2] <8> + 6b 72 62 35 64 61 74 61 krb5data + +-encode_krb5_pa_pk_as_req_draft9: +- +-[Sequence/Sequence Of] +-. [0] <8> +- 6b 72 62 35 64 61 74 61 krb5data +-. [2] <8> +- 6b 72 62 35 64 61 74 61 krb5data +- + encode_krb5_pa_pk_as_rep(dhInfo): + + [CONT 0] +@@ -36,16 +28,6 @@ encode_krb5_pa_pk_as_rep(dhInfo): + + encode_krb5_pa_pk_as_rep(encKeyPack): + +-[CONT 1] <8> +- 6b 72 62 35 64 61 74 61 krb5data +- +-encode_krb5_pa_pk_as_rep_draft9(dhSignedData): +- +-[CONT 0] <8> +- 6b 72 62 35 64 61 74 61 krb5data +- +-encode_krb5_pa_pk_as_rep_draft9(encKeyPack): +- + [CONT 1] <8> + 6b 72 62 35 64 61 74 61 krb5data + +@@ -79,27 +61,6 @@ encode_krb5_auth_pack: + . . . [0] [Object Identifier] <8> + 6b 72 62 35 64 61 74 61 krb5data + +-encode_krb5_auth_pack_draft9: +- +-[Sequence/Sequence Of] +-. [0] [Sequence/Sequence Of] +-. . [0] [Sequence/Sequence Of] +-. . . [0] [Integer] 1 +-. . . [1] [Sequence/Sequence Of] +-. . . . [General string] "hftsai" +-. . . . [General string] "extra" +-. . [1] [General string] "ATHENA.MIT.EDU" +-. . [2] [Integer] 123456 +-. . [3] [Generalized Time] "19940610060317Z" +-. . [4] [Integer] 42 +-. [1] [Sequence/Sequence Of] +-. . [Sequence/Sequence Of] +-. . . [Object Identifier] <9> +- 2a 86 48 86 f7 12 01 02 02 *.H...... +-. . . [Octet String] "params" +-. . [Bit String] <9> +- 00 6b 72 62 35 64 61 74 61 .krb5data +- + encode_krb5_kdc_dh_key_info: + + [Sequence/Sequence Of] +@@ -118,14 +79,6 @@ encode_krb5_reply_key_pack: + . . [0] [Integer] 1 + . . [1] [Octet String] "1234" + +-encode_krb5_reply_key_pack_draft9: +- +-[Sequence/Sequence Of] +-. [0] [Sequence/Sequence Of] +-. . [0] [Integer] 1 +-. . [1] [Octet String] "12345678" +-. [1] [Integer] 42 +- + encode_krb5_sp80056a_other_info: + + [Sequence/Sequence Of] diff --git a/Remove-PKINIT-draft-9-support.patch b/Remove-PKINIT-draft-9-support.patch new file mode 100644 index 0000000..3a25343 --- /dev/null +++ b/Remove-PKINIT-draft-9-support.patch @@ -0,0 +1,1712 @@ +From b26cbaa597305c9e16b455e4bd310ac86b6221cc Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 18 Jun 2019 13:06:44 -0400 +Subject: [PATCH] Remove PKINIT draft 9 support + +PKINIT draft 9 support is required to interoperate with Windows 2000, +Windows XP, and Windows Server 2003, all of which are well beyond +end-of-life. Remove it. + +ticket: 8817 (new) +(cherry picked from commit bb82690be39a033669388154964486e213d84e76) +--- + src/plugins/preauth/pkinit/pkinit.h | 9 - + src/plugins/preauth/pkinit/pkinit_accessor.c | 12 - + src/plugins/preauth/pkinit/pkinit_accessor.h | 6 - + src/plugins/preauth/pkinit/pkinit_clnt.c | 231 +++----- + src/plugins/preauth/pkinit/pkinit_crypto.h | 1 - + .../preauth/pkinit/pkinit_crypto_openssl.c | 219 ++----- + src/plugins/preauth/pkinit/pkinit_lib.c | 65 --- + src/plugins/preauth/pkinit/pkinit_srv.c | 543 ++++++------------ + src/plugins/preauth/pkinit/pkinit_trace.h | 4 - + src/tests/t_pkinit.py | 6 +- + 10 files changed, 282 insertions(+), 814 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h +index fe2ec0d31..b437fd53f 100644 +--- a/src/plugins/preauth/pkinit/pkinit.h ++++ b/src/plugins/preauth/pkinit/pkinit.h +@@ -213,7 +213,6 @@ struct _pkinit_req_context { + pkinit_identity_opts *idopts; + int do_identity_matching; + krb5_preauthtype pa_type; +- int rfc4556_kdc; + int rfc6112_kdc; + int identity_initialized; + int identity_prompted; +@@ -244,7 +243,6 @@ struct _pkinit_kdc_req_context { + int magic; + pkinit_req_crypto_context cryptoctx; + krb5_auth_pack *rcv_auth_pack; +- krb5_auth_pack_draft9 *rcv_auth_pack9; + krb5_preauthtype pa_type; + }; + typedef struct _pkinit_kdc_req_context *pkinit_kdc_req_context; +@@ -329,22 +327,15 @@ void pkinit_free_deferred_ids(pkinit_deferred_id *identities); + * initialization and free functions + */ + void init_krb5_pa_pk_as_req(krb5_pa_pk_as_req **in); +-void init_krb5_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 **in); + void init_krb5_reply_key_pack(krb5_reply_key_pack **in); +-void init_krb5_reply_key_pack_draft9(krb5_reply_key_pack_draft9 **in); + + void init_krb5_pa_pk_as_rep(krb5_pa_pk_as_rep **in); +-void init_krb5_pa_pk_as_rep_draft9(krb5_pa_pk_as_rep_draft9 **in); + void init_krb5_subject_pk_info(krb5_subject_pk_info **in); + + void free_krb5_pa_pk_as_req(krb5_pa_pk_as_req **in); +-void free_krb5_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 **in); + void free_krb5_reply_key_pack(krb5_reply_key_pack **in); +-void free_krb5_reply_key_pack_draft9(krb5_reply_key_pack_draft9 **in); + void free_krb5_auth_pack(krb5_auth_pack **in); +-void free_krb5_auth_pack_draft9(krb5_context, krb5_auth_pack_draft9 **in); + void free_krb5_pa_pk_as_rep(krb5_pa_pk_as_rep **in); +-void free_krb5_pa_pk_as_rep_draft9(krb5_pa_pk_as_rep_draft9 **in); + void free_krb5_external_principal_identifier(krb5_external_principal_identifier ***in); + void free_krb5_algorithm_identifiers(krb5_algorithm_identifier ***in); + void free_krb5_algorithm_identifier(krb5_algorithm_identifier *in); +diff --git a/src/plugins/preauth/pkinit/pkinit_accessor.c b/src/plugins/preauth/pkinit/pkinit_accessor.c +index 6bae94969..0908f1b9b 100644 +--- a/src/plugins/preauth/pkinit/pkinit_accessor.c ++++ b/src/plugins/preauth/pkinit/pkinit_accessor.c +@@ -41,22 +41,15 @@ + krb5_error_code (*k5int_decode_##type)(const krb5_data *, type ***) + + DEF_FUNC_PTRS(krb5_auth_pack); +-DEF_FUNC_PTRS(krb5_auth_pack_draft9); + DEF_FUNC_PTRS(krb5_kdc_dh_key_info); + DEF_FUNC_PTRS(krb5_pa_pk_as_rep); + DEF_FUNC_PTRS(krb5_pa_pk_as_req); +-DEF_FUNC_PTRS(krb5_pa_pk_as_req_draft9); + DEF_FUNC_PTRS(krb5_reply_key_pack); +-DEF_FUNC_PTRS(krb5_reply_key_pack_draft9); + + /* special cases... */ + krb5_error_code + (*k5int_decode_krb5_principal_name)(const krb5_data *, krb5_principal_data **); + +-krb5_error_code +-(*k5int_encode_krb5_pa_pk_as_rep_draft9)(const krb5_pa_pk_as_rep_draft9 *, +- krb5_data **code); +- + krb5_error_code + (*k5int_encode_krb5_td_dh_parameters)(krb5_algorithm_identifier *const *, + krb5_data **code); +@@ -101,21 +94,16 @@ pkinit_accessor_init(void) + k5int_decode_##type = k5int.decode_##type; + + SET_PTRS(krb5_auth_pack); +- SET_PTRS(krb5_auth_pack_draft9); + SET_PTRS(krb5_kdc_dh_key_info); + SET_PTRS(krb5_pa_pk_as_rep); + SET_PTRS(krb5_pa_pk_as_req); +- SET_PTRS(krb5_pa_pk_as_req_draft9); + SET_PTRS(krb5_reply_key_pack); +- SET_PTRS(krb5_reply_key_pack_draft9); + SET_PTRS(krb5_td_dh_parameters); + SET_PTRS(krb5_td_trusted_certifiers); + + /* special cases... */ + k5int_decode_krb5_principal_name = k5int.decode_krb5_principal_name; + k5int_encode_krb5_kdc_req_body = k5int.encode_krb5_kdc_req_body; +- k5int_encode_krb5_pa_pk_as_rep_draft9 = \ +- k5int.encode_krb5_pa_pk_as_rep_draft9; + k5int_krb5_free_kdc_req = k5int.free_kdc_req; + k5int_set_prompt_types = k5int.set_prompt_types; + return 0; +diff --git a/src/plugins/preauth/pkinit/pkinit_accessor.h b/src/plugins/preauth/pkinit/pkinit_accessor.h +index dcee3db53..e510ab624 100644 +--- a/src/plugins/preauth/pkinit/pkinit_accessor.h ++++ b/src/plugins/preauth/pkinit/pkinit_accessor.h +@@ -45,21 +45,15 @@ extern krb5_error_code (*k5int_encode_##type)(const type **, krb5_data **); \ + extern krb5_error_code (*k5int_decode_##type)(const krb5_data *, type ***) + + DEF_EXT_FUNC_PTRS(krb5_auth_pack); +-DEF_EXT_FUNC_PTRS(krb5_auth_pack_draft9); + DEF_EXT_FUNC_PTRS(krb5_kdc_dh_key_info); + DEF_EXT_FUNC_PTRS(krb5_pa_pk_as_rep); + DEF_EXT_FUNC_PTRS(krb5_pa_pk_as_req); +-DEF_EXT_FUNC_PTRS(krb5_pa_pk_as_req_draft9); + DEF_EXT_FUNC_PTRS(krb5_reply_key_pack); +-DEF_EXT_FUNC_PTRS(krb5_reply_key_pack_draft9); + + /* special cases... */ + extern krb5_error_code (*k5int_decode_krb5_principal_name) + (const krb5_data *, krb5_principal_data **); + +-extern krb5_error_code (*k5int_encode_krb5_pa_pk_as_rep_draft9) +- (const krb5_pa_pk_as_rep_draft9 *, krb5_data **code); +- + extern krb5_error_code (*k5int_encode_krb5_td_dh_parameters) + (krb5_algorithm_identifier *const *, krb5_data **code); + extern krb5_error_code (*k5int_decode_krb5_td_dh_parameters) +diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c +index 58400d555..1a642139a 100644 +--- a/src/plugins/preauth/pkinit/pkinit_clnt.c ++++ b/src/plugins/preauth/pkinit/pkinit_clnt.c +@@ -148,11 +148,7 @@ pa_pkinit_gen_req(krb5_context context, + goto cleanup; + } + +- /* +- * The most we'll return is two pa_data, normally just one. +- * We need to make room for the NULL terminator. +- */ +- return_pa_data = k5calloc(3, sizeof(*return_pa_data), &retval); ++ return_pa_data = k5calloc(2, sizeof(*return_pa_data), &retval); + if (return_pa_data == NULL) + goto cleanup; + +@@ -162,21 +158,11 @@ pa_pkinit_gen_req(krb5_context context, + + return_pa_data[0]->magic = KV5M_PA_DATA; + +- if (pa_type == KRB5_PADATA_PK_AS_REQ_OLD) +- return_pa_data[0]->pa_type = KRB5_PADATA_PK_AS_REP_OLD; +- else +- return_pa_data[0]->pa_type = pa_type; ++ return_pa_data[0]->pa_type = pa_type; + return_pa_data[0]->length = out_data->length; + return_pa_data[0]->contents = (krb5_octet *) out_data->data; + *out_data = empty_data(); + +- if (return_pa_data[0]->pa_type == KRB5_PADATA_PK_AS_REP_OLD) { +- return_pa_data[1] = k5alloc(sizeof(*return_pa_data[1]), &retval); +- if (return_pa_data[1] == NULL) +- goto cleanup; +- return_pa_data[1]->pa_type = KRB5_PADATA_AS_CHECKSUM; +- } +- + *out_padata = return_pa_data; + return_pa_data = NULL; + cb->disable_fallback(context, rock); +@@ -206,8 +192,6 @@ pkinit_as_req_create(krb5_context context, + krb5_data *coded_auth_pack = NULL; + krb5_auth_pack auth_pack; + krb5_pa_pk_as_req *req = NULL; +- krb5_auth_pack_draft9 auth_pack9; +- krb5_pa_pk_as_req_draft9 *req9 = NULL; + krb5_algorithm_identifier **cmstypes = NULL; + int protocol = reqctx->opts->dh_or_rsa; + unsigned char *dh_params = NULL, *dh_pubkey = NULL; +@@ -216,42 +200,25 @@ pkinit_as_req_create(krb5_context context, + pkiDebug("pkinit_as_req_create pa_type = %d\n", reqctx->pa_type); + + /* Create the authpack */ +- switch((int)reqctx->pa_type) { +- case KRB5_PADATA_PK_AS_REQ_OLD: +- protocol = RSA_PROTOCOL; +- memset(&auth_pack9, 0, sizeof(auth_pack9)); +- auth_pack9.pkAuthenticator.ctime = ctsec; +- auth_pack9.pkAuthenticator.cusec = cusec; +- auth_pack9.pkAuthenticator.nonce = nonce; +- auth_pack9.pkAuthenticator.kdcName = server; +- break; +- case KRB5_PADATA_PK_AS_REQ: +- memset(&info, 0, sizeof(info)); +- memset(&auth_pack, 0, sizeof(auth_pack)); +- auth_pack.pkAuthenticator.ctime = ctsec; +- auth_pack.pkAuthenticator.cusec = cusec; +- auth_pack.pkAuthenticator.nonce = nonce; +- auth_pack.pkAuthenticator.paChecksum = *cksum; +- if (!reqctx->opts->disable_freshness) +- auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token; +- auth_pack.clientDHNonce.length = 0; +- auth_pack.clientPublicValue = &info; +- auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; ++ memset(&info, 0, sizeof(info)); ++ memset(&auth_pack, 0, sizeof(auth_pack)); ++ auth_pack.pkAuthenticator.ctime = ctsec; ++ auth_pack.pkAuthenticator.cusec = cusec; ++ auth_pack.pkAuthenticator.nonce = nonce; ++ auth_pack.pkAuthenticator.paChecksum = *cksum; ++ if (!reqctx->opts->disable_freshness) ++ auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token; ++ auth_pack.clientDHNonce.length = 0; ++ auth_pack.clientPublicValue = &info; ++ auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; + +- /* add List of CMS algorithms */ +- retval = create_krb5_supportedCMSTypes(context, plgctx->cryptoctx, +- reqctx->cryptoctx, +- reqctx->idctx, &cmstypes); +- auth_pack.supportedCMSTypes = cmstypes; +- if (retval) +- goto cleanup; +- break; +- default: +- pkiDebug("as_req: unrecognized pa_type = %d\n", +- (int)reqctx->pa_type); +- retval = -1; ++ /* add List of CMS algorithms */ ++ retval = create_krb5_supportedCMSTypes(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, ++ reqctx->idctx, &cmstypes); ++ auth_pack.supportedCMSTypes = cmstypes; ++ if (retval) + goto cleanup; +- } + + switch(protocol) { + case DH_PROTOCOL: +@@ -274,14 +241,7 @@ pkinit_as_req_create(krb5_context context, + case RSA_PROTOCOL: + TRACE_PKINIT_CLIENT_REQ_RSA(context); + pkiDebug("as_req: RSA key transport algorithm\n"); +- switch((int)reqctx->pa_type) { +- case KRB5_PADATA_PK_AS_REQ_OLD: +- auth_pack9.clientPublicValue = NULL; +- break; +- case KRB5_PADATA_PK_AS_REQ: +- auth_pack.clientPublicValue = NULL; +- break; +- } ++ auth_pack.clientPublicValue = NULL; + break; + default: + pkiDebug("as_req: unknown key transport protocol %d\n", +@@ -290,16 +250,7 @@ pkinit_as_req_create(krb5_context context, + goto cleanup; + } + +- /* Encode the authpack */ +- switch((int)reqctx->pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- retval = k5int_encode_krb5_auth_pack(&auth_pack, &coded_auth_pack); +- break; +- case KRB5_PADATA_PK_AS_REQ_OLD: +- retval = k5int_encode_krb5_auth_pack_draft9(&auth_pack9, +- &coded_auth_pack); +- break; +- } ++ retval = k5int_encode_krb5_auth_pack(&auth_pack, &coded_auth_pack); + if (retval) { + pkiDebug("failed to encode the AuthPack %d\n", retval); + goto cleanup; +@@ -311,60 +262,39 @@ pkinit_as_req_create(krb5_context context, + #endif + + /* create PKCS7 object from authpack */ +- switch((int)reqctx->pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- init_krb5_pa_pk_as_req(&req); +- if (req == NULL) { +- retval = ENOMEM; +- goto cleanup; +- } +- if (use_content_info(context, reqctx, client)) { +- retval = cms_contentinfo_create(context, plgctx->cryptoctx, +- reqctx->cryptoctx, reqctx->idctx, +- CMS_SIGN_CLIENT, +- (unsigned char *) +- coded_auth_pack->data, +- coded_auth_pack->length, +- (unsigned char **) +- &req->signedAuthPack.data, +- &req->signedAuthPack.length); +- } else { +- retval = cms_signeddata_create(context, plgctx->cryptoctx, +- reqctx->cryptoctx, reqctx->idctx, +- CMS_SIGN_CLIENT, 1, +- (unsigned char *) +- coded_auth_pack->data, +- coded_auth_pack->length, +- (unsigned char **) +- &req->signedAuthPack.data, +- &req->signedAuthPack.length); +- } +-#ifdef DEBUG_ASN1 +- print_buffer_bin((unsigned char *)req->signedAuthPack.data, +- req->signedAuthPack.length, +- "/tmp/client_signed_data"); +-#endif +- break; +- case KRB5_PADATA_PK_AS_REQ_OLD: +- init_krb5_pa_pk_as_req_draft9(&req9); +- if (req9 == NULL) { +- retval = ENOMEM; +- goto cleanup; +- } ++ init_krb5_pa_pk_as_req(&req); ++ if (req == NULL) { ++ retval = ENOMEM; ++ goto cleanup; ++ } ++ if (use_content_info(context, reqctx, client)) { ++ retval = cms_contentinfo_create(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, reqctx->idctx, ++ CMS_SIGN_CLIENT, ++ (unsigned char *) ++ coded_auth_pack->data, ++ coded_auth_pack->length, ++ (unsigned char **) ++ &req->signedAuthPack.data, ++ &req->signedAuthPack.length); ++ } else { + retval = cms_signeddata_create(context, plgctx->cryptoctx, +- reqctx->cryptoctx, reqctx->idctx, CMS_SIGN_DRAFT9, 1, +- (unsigned char *)coded_auth_pack->data, ++ reqctx->cryptoctx, reqctx->idctx, ++ CMS_SIGN_CLIENT, 1, ++ (unsigned char *) ++ coded_auth_pack->data, + coded_auth_pack->length, + (unsigned char **) +- &req9->signedAuthPack.data, +- &req9->signedAuthPack.length); +- break; +-#ifdef DEBUG_ASN1 +- print_buffer_bin((unsigned char *)req9->signedAuthPack.data, +- req9->signedAuthPack.length, +- "/tmp/client_signed_data_draft9"); +-#endif ++ &req->signedAuthPack.data, ++ &req->signedAuthPack.length); + } ++ ++#ifdef DEBUG_ASN1 ++ print_buffer_bin((unsigned char *)req->signedAuthPack.data, ++ req->signedAuthPack.length, ++ "/tmp/client_signed_data"); ++#endif ++ + krb5_free_data(context, coded_auth_pack); + if (retval) { + pkiDebug("failed to create pkcs7 signed data\n"); +@@ -372,33 +302,21 @@ pkinit_as_req_create(krb5_context context, + } + + /* create a list of trusted CAs */ +- switch((int)reqctx->pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- retval = create_krb5_trustedCertifiers(context, plgctx->cryptoctx, +- reqctx->cryptoctx, reqctx->idctx, &req->trustedCertifiers); +- if (retval) +- goto cleanup; +- retval = create_issuerAndSerial(context, plgctx->cryptoctx, +- reqctx->cryptoctx, reqctx->idctx, +- (unsigned char **)&req->kdcPkId.data, +- &req->kdcPkId.length); +- if (retval) +- goto cleanup; ++ retval = create_krb5_trustedCertifiers(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, reqctx->idctx, ++ &req->trustedCertifiers); ++ if (retval) ++ goto cleanup; ++ retval = create_issuerAndSerial(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, reqctx->idctx, ++ (unsigned char **)&req->kdcPkId.data, ++ &req->kdcPkId.length); ++ if (retval) ++ goto cleanup; ++ ++ /* Encode the as-req */ ++ retval = k5int_encode_krb5_pa_pk_as_req(req, as_req); + +- /* Encode the as-req */ +- retval = k5int_encode_krb5_pa_pk_as_req(req, as_req); +- break; +- case KRB5_PADATA_PK_AS_REQ_OLD: +- retval = create_issuerAndSerial(context, plgctx->cryptoctx, +- reqctx->cryptoctx, reqctx->idctx, +- (unsigned char **)&req9->kdcCert.data, +- &req9->kdcCert.length); +- if (retval) +- goto cleanup; +- /* Encode the as-req */ +- retval = k5int_encode_krb5_pa_pk_as_req_draft9(req9, as_req); +- break; +- } + #ifdef DEBUG_ASN1 + if (!retval) + print_buffer_bin((unsigned char *)(*as_req)->data, (*as_req)->length, +@@ -410,7 +328,6 @@ cleanup: + free(dh_params); + free(dh_pubkey); + free_krb5_pa_pk_as_req(&req); +- free_krb5_pa_pk_as_req_draft9(&req9); + + pkiDebug("pkinit_as_req_create retval=%d\n", (int) retval); + +@@ -1165,31 +1082,13 @@ pkinit_client_process(krb5_context context, krb5_clpreauth_moddata moddata, + d = make_data(in_padata->contents, in_padata->length); + return krb5_copy_data(context, &d, &reqctx->freshness_token); + case KRB5_PADATA_PK_AS_REQ: +- reqctx->rfc4556_kdc = 1; + pkiDebug("processing KRB5_PADATA_PK_AS_REQ\n"); + processing_request = 1; + break; + + case KRB5_PADATA_PK_AS_REP: +- reqctx->rfc4556_kdc = 1; + pkiDebug("processing KRB5_PADATA_PK_AS_REP\n"); + break; +- case KRB5_PADATA_PK_AS_REP_OLD: +- case KRB5_PADATA_PK_AS_REQ_OLD: +- /* Don't fall back to draft9 code if the KDC supports RFC 4556. */ +- if (reqctx->rfc4556_kdc) { +- TRACE_PKINIT_CLIENT_NO_DRAFT9(context); +- return KRB5KDC_ERR_PREAUTH_FAILED; +- } +- if (in_padata->length == 0) { +- pkiDebug("processing KRB5_PADATA_PK_AS_REQ_OLD\n"); +- in_padata->pa_type = KRB5_PADATA_PK_AS_REQ_OLD; +- processing_request = 1; +- } else { +- pkiDebug("processing KRB5_PADATA_PK_AS_REP_OLD\n"); +- in_padata->pa_type = KRB5_PADATA_PK_AS_REP_OLD; +- } +- break; + default: + pkiDebug("unrecognized patype = %d for PKINIT\n", + in_padata->pa_type); +@@ -1363,8 +1262,6 @@ pkinit_client_get_flags(krb5_context kcontext, krb5_preauthtype patype) + static krb5_preauthtype supported_client_pa_types[] = { + KRB5_PADATA_PK_AS_REP, + KRB5_PADATA_PK_AS_REQ, +- KRB5_PADATA_PK_AS_REP_OLD, +- KRB5_PADATA_PK_AS_REQ_OLD, + KRB5_PADATA_PKINIT_KX, + KRB5_PADATA_AS_FRESHNESS, + 0 +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index 0acb731cd..8064a07d0 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -46,7 +46,6 @@ + */ + enum cms_msg_types { + CMS_SIGN_CLIENT, +- CMS_SIGN_DRAFT9, + CMS_SIGN_SERVER, + CMS_ENVEL_SERVER + }; +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 8aa2c5257..8c7fd0cca 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -1050,17 +1050,11 @@ create_contentinfo(krb5_context context, ASN1_OBJECT *oid, + if (p7->type == NULL) + goto oom; + +- if (OBJ_obj2nid(oid) == NID_pkcs7_data) { +- /* Draft 9 uses id-pkcs7-data for signed data. For this type OpenSSL +- * expects an octet string in d.data. */ +- p7->d.data = ostr; +- } else { +- p7->d.other = ASN1_TYPE_new(); +- if (p7->d.other == NULL) +- goto oom; +- p7->d.other->type = V_ASN1_OCTET_STRING; +- p7->d.other->value.octet_string = ostr; +- } ++ p7->d.other = ASN1_TYPE_new(); ++ if (p7->d.other == NULL) ++ goto oom; ++ p7->d.other->type = V_ASN1_OCTET_STRING; ++ p7->d.other->value.octet_string = ostr; + + *p7_out = p7; + return 0; +@@ -1249,43 +1243,37 @@ cms_signeddata_create(krb5_context context, + goto cleanup; + p7si->digest_enc_alg->parameter->type = V_ASN1_NULL; + +- if (cms_msg_type == CMS_SIGN_DRAFT9){ +- /* don't include signed attributes for pa-type 15 request */ +- abuf = data; +- alen = data_len; +- } else { +- /* add signed attributes */ +- /* compute sha1 digest over the EncapsulatedContentInfo */ +- ctx = EVP_MD_CTX_new(); +- if (ctx == NULL) +- goto cleanup; +- EVP_DigestInit_ex(ctx, EVP_sha1(), NULL); +- EVP_DigestUpdate(ctx, data, data_len); +- md_tmp = EVP_MD_CTX_md(ctx); +- EVP_DigestFinal_ex(ctx, md_data, &md_len); +- EVP_MD_CTX_free(ctx); ++ /* add signed attributes */ ++ /* compute sha1 digest over the EncapsulatedContentInfo */ ++ ctx = EVP_MD_CTX_new(); ++ if (ctx == NULL) ++ goto cleanup; ++ EVP_DigestInit_ex(ctx, EVP_sha1(), NULL); ++ EVP_DigestUpdate(ctx, data, data_len); ++ md_tmp = EVP_MD_CTX_md(ctx); ++ EVP_DigestFinal_ex(ctx, md_data, &md_len); ++ EVP_MD_CTX_free(ctx); + +- /* create a message digest attr */ +- digest_attr = ASN1_OCTET_STRING_new(); +- ASN1_OCTET_STRING_set(digest_attr, md_data, (int)md_len); +- PKCS7_add_signed_attribute(p7si, NID_pkcs9_messageDigest, +- V_ASN1_OCTET_STRING, (char *) digest_attr); ++ /* create a message digest attr */ ++ digest_attr = ASN1_OCTET_STRING_new(); ++ ASN1_OCTET_STRING_set(digest_attr, md_data, (int)md_len); ++ PKCS7_add_signed_attribute(p7si, NID_pkcs9_messageDigest, ++ V_ASN1_OCTET_STRING, (char *)digest_attr); + +- /* create a content-type attr */ +- oid_copy = OBJ_dup(oid); +- if (oid_copy == NULL) +- goto cleanup2; +- PKCS7_add_signed_attribute(p7si, NID_pkcs9_contentType, +- V_ASN1_OBJECT, oid_copy); ++ /* create a content-type attr */ ++ oid_copy = OBJ_dup(oid); ++ if (oid_copy == NULL) ++ goto cleanup2; ++ PKCS7_add_signed_attribute(p7si, NID_pkcs9_contentType, ++ V_ASN1_OBJECT, oid_copy); + +- /* create the signature over signed attributes. get DER encoded value */ +- /* This is the place where smartcard signature needs to be calculated */ +- sk = p7si->auth_attr; +- alen = ASN1_item_i2d((ASN1_VALUE *) sk, &abuf, +- ASN1_ITEM_rptr(PKCS7_ATTR_SIGN)); +- if (abuf == NULL) +- goto cleanup2; +- } /* signed attributes */ ++ /* create the signature over signed attributes. get DER encoded value */ ++ /* This is the place where smartcard signature needs to be calculated */ ++ sk = p7si->auth_attr; ++ alen = ASN1_item_i2d((ASN1_VALUE *)sk, &abuf, ++ ASN1_ITEM_rptr(PKCS7_ATTR_SIGN)); ++ if (abuf == NULL) ++ goto cleanup2; + + #ifndef WITHOUT_PKCS11 + /* Some tokens can only do RSAEncryption without sha1 hash */ +@@ -1301,11 +1289,7 @@ cms_signeddata_create(krb5_context context, + ctx = EVP_MD_CTX_new(); + if (ctx == NULL) + goto cleanup; +- /* if this is not draft9 request, include digest signed attribute */ +- if (cms_msg_type != CMS_SIGN_DRAFT9) +- EVP_DigestInit_ex(ctx, md_tmp, NULL); +- else +- EVP_DigestInit_ex(ctx, EVP_sha1(), NULL); ++ EVP_DigestInit_ex(ctx, md_tmp, NULL); + EVP_DigestUpdate(ctx, abuf, alen); + EVP_DigestFinal_ex(ctx, md_data2, &md_len2); + EVP_MD_CTX_free(ctx); +@@ -1349,8 +1333,7 @@ cms_signeddata_create(krb5_context context, + #ifdef DEBUG_SIG + print_buffer(sig, sig_len); + #endif +- if (cms_msg_type != CMS_SIGN_DRAFT9 ) +- free(abuf); ++ free(abuf); + if (retval) + goto cleanup2; + +@@ -1393,19 +1376,13 @@ cms_signeddata_create(krb5_context context, + print_buffer_bin(*signed_data, *signed_data_len, + "/tmp/client_pkcs7_signeddata"); + } else { +- if (cms_msg_type == CMS_SIGN_SERVER) { +- print_buffer_bin(*signed_data, *signed_data_len, +- "/tmp/kdc_pkcs7_signeddata"); +- } else { +- print_buffer_bin(*signed_data, *signed_data_len, +- "/tmp/draft9_pkcs7_signeddata"); +- } ++ print_buffer_bin(*signed_data, *signed_data_len, ++ "/tmp/kdc_pkcs7_signeddata"); + } + #endif + + cleanup2: + if (p7si) { +- if (cms_msg_type != CMS_SIGN_DRAFT9) + #ifndef WITHOUT_PKCS11 + if (id_cryptoctx->pkcs11_method == 1 && + id_cryptoctx->mech == CKM_RSA_PKCS) { +@@ -1692,15 +1669,13 @@ cms_signeddata_verify(krb5_context context, + #endif + } else { + /* retrieve verified certificate chain */ +- if (cms_msg_type == CMS_SIGN_CLIENT || cms_msg_type == CMS_SIGN_DRAFT9) ++ if (cms_msg_type == CMS_SIGN_CLIENT) + verified_chain = X509_STORE_CTX_get1_chain(cert_ctx); + } + X509_STORE_CTX_free(cert_ctx); + if (i <= 0) + goto cleanup; + out = BIO_new(BIO_s_mem()); +- if (cms_msg_type == CMS_SIGN_DRAFT9) +- flags |= CMS_NOATTR; + if (CMS_verify(cms, NULL, store, NULL, out, flags) == 0) { + unsigned long err = ERR_peek_error(); + switch(ERR_GET_REASON(err)) { +@@ -1717,21 +1692,6 @@ cms_signeddata_verify(krb5_context context, + } /* message was signed */ + if (!OBJ_cmp(etype, oid)) + valid_oid = 1; +- else if (cms_msg_type == CMS_SIGN_DRAFT9) { +- /* +- * Various implementations of the pa-type 15 request use +- * different OIDS. We check that the returned object +- * has any of the acceptable OIDs +- */ +- ASN1_OBJECT *client_oid = NULL, *server_oid = NULL, *rsa_oid = NULL; +- client_oid = pkinit_pkcs7type2oid(plgctx, CMS_SIGN_CLIENT); +- server_oid = pkinit_pkcs7type2oid(plgctx, CMS_SIGN_SERVER); +- rsa_oid = pkinit_pkcs7type2oid(plgctx, CMS_ENVEL_SERVER); +- if (!OBJ_cmp(etype, client_oid) || +- !OBJ_cmp(etype, server_oid) || +- !OBJ_cmp(etype, rsa_oid)) +- valid_oid = 1; +- } + + if (valid_oid) + pkiDebug("CMS Verification successful\n"); +@@ -1761,7 +1721,7 @@ cms_signeddata_verify(krb5_context context, + reqctx->received_cert = X509_dup(x); + + /* generate authorization data */ +- if (cms_msg_type == CMS_SIGN_CLIENT || cms_msg_type == CMS_SIGN_DRAFT9) { ++ if (cms_msg_type == CMS_SIGN_CLIENT) { + + if (authz_data == NULL || authz_data_len == NULL) + goto out; +@@ -1841,24 +1801,11 @@ cms_envelopeddata_create(krb5_context context, + int signed_data_len = 0, enc_data_len = 0, flags = PKCS7_BINARY; + STACK_OF(X509) *encerts = NULL; + const EVP_CIPHER *cipher = NULL; +- int cms_msg_type; +- +- /* create the PKCS7 SignedData portion of the PKCS7 EnvelopedData */ +- switch ((int)pa_type) { +- case KRB5_PADATA_PK_AS_REQ_OLD: +- case KRB5_PADATA_PK_AS_REP_OLD: +- cms_msg_type = CMS_SIGN_DRAFT9; +- break; +- case KRB5_PADATA_PK_AS_REQ: +- cms_msg_type = CMS_ENVEL_SERVER; +- break; +- default: +- goto cleanup; +- } + + retval = cms_signeddata_create(context, plgctx, reqctx, idctx, +- cms_msg_type, include_certchain, key_pack, key_pack_len, +- &signed_data, (unsigned int *)&signed_data_len); ++ CMS_ENVEL_SERVER, include_certchain, ++ key_pack, key_pack_len, &signed_data, ++ (unsigned int *)&signed_data_len); + if (retval) { + pkiDebug("failed to create pkcs7 signed data\n"); + goto cleanup; +@@ -1874,26 +1821,11 @@ cms_envelopeddata_create(krb5_context context, + + cipher = EVP_des_ede3_cbc(); + in = BIO_new(BIO_s_mem()); +- switch (pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- prepare_enc_data(signed_data, signed_data_len, &enc_data, +- &enc_data_len); +- retval = BIO_write(in, enc_data, enc_data_len); +- if (retval != enc_data_len) { +- pkiDebug("BIO_write only wrote %d\n", retval); +- goto cleanup; +- } +- break; +- case KRB5_PADATA_PK_AS_REP_OLD: +- case KRB5_PADATA_PK_AS_REQ_OLD: +- retval = BIO_write(in, signed_data, signed_data_len); +- if (retval != signed_data_len) { +- pkiDebug("BIO_write only wrote %d\n", retval); +- goto cleanup; +- } +- break; +- default: +- retval = -1; ++ prepare_enc_data(signed_data, signed_data_len, &enc_data, ++ &enc_data_len); ++ retval = BIO_write(in, enc_data, enc_data_len); ++ if (retval != enc_data_len) { ++ pkiDebug("BIO_write only wrote %d\n", retval); + goto cleanup; + } + +@@ -1902,20 +1834,7 @@ cms_envelopeddata_create(krb5_context context, + retval = oerr(context, 0, _("Failed to encrypt PKCS7 object")); + goto cleanup; + } +- switch (pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- p7->d.enveloped->enc_data->content_type = +- OBJ_nid2obj(NID_pkcs7_signed); +- break; +- case KRB5_PADATA_PK_AS_REP_OLD: +- case KRB5_PADATA_PK_AS_REQ_OLD: +- p7->d.enveloped->enc_data->content_type = +- OBJ_nid2obj(NID_pkcs7_data); +- break; +- break; +- break; +- break; +- } ++ p7->d.enveloped->enc_data->content_type = OBJ_nid2obj(NID_pkcs7_signed); + + *out_len = i2d_PKCS7(p7, NULL); + if (!*out_len || (p = *out = malloc(*out_len)) == NULL) { +@@ -1963,7 +1882,6 @@ cms_envelopeddata_verify(krb5_context context, + const unsigned char *p = enveloped_data; + unsigned int tmp_buf_len = 0, tmp_buf2_len = 0, vfy_buf_len = 0; + unsigned char *tmp_buf = NULL, *tmp_buf2 = NULL, *vfy_buf = NULL; +- int msg_type = 0; + + #ifdef DEBUG_ASN1 + print_buffer_bin(enveloped_data, enveloped_data_len, +@@ -1995,46 +1913,21 @@ cms_envelopeddata_verify(krb5_context context, + print_buffer_bin(tmp_buf, tmp_buf_len, "/tmp/client_enc_keypack"); + #endif + /* verify PKCS7 SignedData message */ +- switch (pa_type) { +- case KRB5_PADATA_PK_AS_REP: +- msg_type = CMS_ENVEL_SERVER; +- +- break; +- case KRB5_PADATA_PK_AS_REP_OLD: +- msg_type = CMS_SIGN_DRAFT9; +- break; +- default: +- pkiDebug("%s: unrecognized pa_type = %d\n", __FUNCTION__, pa_type); +- retval = KRB5KDC_ERR_PREAUTH_FAILED; ++ /* Wrap the signed data to make decoding easier in the verify routine. */ ++ retval = wrap_signeddata(tmp_buf, tmp_buf_len, &tmp_buf2, &tmp_buf2_len); ++ if (retval) { ++ pkiDebug("failed to encode signeddata\n"); + goto cleanup; + } +- /* +- * If this is the RFC style, wrap the signed data to make +- * decoding easier in the verify routine. +- * For draft9-compatible, we don't do anything because it +- * is already wrapped. +- */ +- if (msg_type == CMS_ENVEL_SERVER) { +- retval = wrap_signeddata(tmp_buf, tmp_buf_len, +- &tmp_buf2, &tmp_buf2_len); +- if (retval) { +- pkiDebug("failed to encode signeddata\n"); +- goto cleanup; +- } +- vfy_buf = tmp_buf2; +- vfy_buf_len = tmp_buf2_len; +- +- } else { +- vfy_buf = tmp_buf; +- vfy_buf_len = tmp_buf_len; +- } ++ vfy_buf = tmp_buf2; ++ vfy_buf_len = tmp_buf2_len; + + #ifdef DEBUG_ASN1 + print_buffer_bin(vfy_buf, vfy_buf_len, "/tmp/client_enc_keypack2"); + #endif + + retval = cms_signeddata_verify(context, plg_cryptoctx, req_cryptoctx, +- id_cryptoctx, msg_type, ++ id_cryptoctx, CMS_ENVEL_SERVER, + require_crl_checking, + vfy_buf, vfy_buf_len, + data, data_len, NULL, NULL, NULL); +@@ -3580,8 +3473,6 @@ pkinit_pkcs7type2oid(pkinit_plg_crypto_context cryptoctx, int pkcs7_type) + switch (pkcs7_type) { + case CMS_SIGN_CLIENT: + return cryptoctx->id_pkinit_authData; +- case CMS_SIGN_DRAFT9: +- return OBJ_nid2obj(NID_pkcs7_data); + case CMS_SIGN_SERVER: + return cryptoctx->id_pkinit_DHKeyData; + case CMS_ENVEL_SERVER: +diff --git a/src/plugins/preauth/pkinit/pkinit_lib.c b/src/plugins/preauth/pkinit/pkinit_lib.c +index d5858c424..bb2916bd5 100644 +--- a/src/plugins/preauth/pkinit/pkinit_lib.c ++++ b/src/plugins/preauth/pkinit/pkinit_lib.c +@@ -110,15 +110,6 @@ free_krb5_pa_pk_as_req(krb5_pa_pk_as_req **in) + free(*in); + } + +-void +-free_krb5_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 **in) +-{ +- if (*in == NULL) return; +- free((*in)->signedAuthPack.data); +- free((*in)->kdcCert.data); +- free(*in); +-} +- + void + free_krb5_reply_key_pack(krb5_reply_key_pack **in) + { +@@ -128,14 +119,6 @@ free_krb5_reply_key_pack(krb5_reply_key_pack **in) + free(*in); + } + +-void +-free_krb5_reply_key_pack_draft9(krb5_reply_key_pack_draft9 **in) +-{ +- if (*in == NULL) return; +- free((*in)->replyKey.contents); +- free(*in); +-} +- + void + free_krb5_auth_pack(krb5_auth_pack **in) + { +@@ -160,15 +143,6 @@ free_krb5_auth_pack(krb5_auth_pack **in) + free(*in); + } + +-void +-free_krb5_auth_pack_draft9(krb5_context context, +- krb5_auth_pack_draft9 **in) +-{ +- if ((*in) == NULL) return; +- krb5_free_principal(context, (*in)->pkAuthenticator.kdcName); +- free(*in); +-} +- + void + free_krb5_pa_pk_as_rep(krb5_pa_pk_as_rep **in) + { +@@ -187,14 +161,6 @@ free_krb5_pa_pk_as_rep(krb5_pa_pk_as_rep **in) + free(*in); + } + +-void +-free_krb5_pa_pk_as_rep_draft9(krb5_pa_pk_as_rep_draft9 **in) +-{ +- if (*in == NULL) return; +- free((*in)->u.encKeyPack.data); +- free(*in); +-} +- + void + free_krb5_external_principal_identifier(krb5_external_principal_identifier ***in) + { +@@ -261,17 +227,6 @@ init_krb5_pa_pk_as_req(krb5_pa_pk_as_req **in) + (*in)->kdcPkId.length = 0; + } + +-void +-init_krb5_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 **in) +-{ +- (*in) = malloc(sizeof(krb5_pa_pk_as_req_draft9)); +- if ((*in) == NULL) return; +- (*in)->signedAuthPack.data = NULL; +- (*in)->signedAuthPack.length = 0; +- (*in)->kdcCert.data = NULL; +- (*in)->kdcCert.length = 0; +-} +- + void + init_krb5_reply_key_pack(krb5_reply_key_pack **in) + { +@@ -283,15 +238,6 @@ init_krb5_reply_key_pack(krb5_reply_key_pack **in) + (*in)->asChecksum.length = 0; + } + +-void +-init_krb5_reply_key_pack_draft9(krb5_reply_key_pack_draft9 **in) +-{ +- (*in) = malloc(sizeof(krb5_reply_key_pack_draft9)); +- if ((*in) == NULL) return; +- (*in)->replyKey.contents = NULL; +- (*in)->replyKey.length = 0; +-} +- + void + init_krb5_pa_pk_as_rep(krb5_pa_pk_as_rep **in) + { +@@ -306,17 +252,6 @@ init_krb5_pa_pk_as_rep(krb5_pa_pk_as_rep **in) + (*in)->u.dh_Info.kdfID = NULL; + } + +-void +-init_krb5_pa_pk_as_rep_draft9(krb5_pa_pk_as_rep_draft9 **in) +-{ +- (*in) = malloc(sizeof(krb5_pa_pk_as_rep_draft9)); +- if ((*in) == NULL) return; +- (*in)->u.dhSignedData.length = 0; +- (*in)->u.dhSignedData.data = NULL; +- (*in)->u.encKeyPack.length = 0; +- (*in)->u.encKeyPack.data = NULL; +-} +- + void + init_krb5_subject_pk_info(krb5_subject_pk_info **in) + { +diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c +index 6aa646cc6..c44be9c74 100644 +--- a/src/plugins/preauth/pkinit/pkinit_srv.c ++++ b/src/plugins/preauth/pkinit/pkinit_srv.c +@@ -421,9 +421,7 @@ pkinit_server_verify_padata(krb5_context context, + krb5_error_code retval = 0; + krb5_data authp_data = {0, 0, NULL}, krb5_authz = {0, 0, NULL}; + krb5_pa_pk_as_req *reqp = NULL; +- krb5_pa_pk_as_req_draft9 *reqp9 = NULL; + krb5_auth_pack *auth_pack = NULL; +- krb5_auth_pack_draft9 *auth_pack9 = NULL; + pkinit_kdc_context plgctx = NULL; + pkinit_kdc_req_context reqctx = NULL; + krb5_checksum cksum = {0, 0, 0, NULL}; +@@ -464,58 +462,32 @@ pkinit_server_verify_padata(krb5_context context, + + PADATA_TO_KRB5DATA(data, &k5data); + +- switch ((int)data->pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- TRACE_PKINIT_SERVER_PADATA_VERIFY(context); +- retval = k5int_decode_krb5_pa_pk_as_req(&k5data, &reqp); +- if (retval) { +- pkiDebug("decode_krb5_pa_pk_as_req failed\n"); +- goto cleanup; +- } +-#ifdef DEBUG_ASN1 +- print_buffer_bin(reqp->signedAuthPack.data, +- reqp->signedAuthPack.length, +- "/tmp/kdc_signed_data"); +-#endif +- retval = cms_signeddata_verify(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, CMS_SIGN_CLIENT, +- plgctx->opts->require_crl_checking, +- (unsigned char *) +- reqp->signedAuthPack.data, reqp->signedAuthPack.length, +- (unsigned char **)&authp_data.data, +- &authp_data.length, +- (unsigned char **)&krb5_authz.data, +- &krb5_authz.length, &is_signed); +- break; +- case KRB5_PADATA_PK_AS_REP_OLD: +- case KRB5_PADATA_PK_AS_REQ_OLD: +- TRACE_PKINIT_SERVER_PADATA_VERIFY_OLD(context); +- retval = k5int_decode_krb5_pa_pk_as_req_draft9(&k5data, &reqp9); +- if (retval) { +- pkiDebug("decode_krb5_pa_pk_as_req_draft9 failed\n"); +- goto cleanup; +- } +-#ifdef DEBUG_ASN1 +- print_buffer_bin(reqp9->signedAuthPack.data, +- reqp9->signedAuthPack.length, +- "/tmp/kdc_signed_data_draft9"); +-#endif +- +- retval = cms_signeddata_verify(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, CMS_SIGN_DRAFT9, +- plgctx->opts->require_crl_checking, +- (unsigned char *) +- reqp9->signedAuthPack.data, reqp9->signedAuthPack.length, +- (unsigned char **)&authp_data.data, +- &authp_data.length, +- (unsigned char **)&krb5_authz.data, +- &krb5_authz.length, NULL); +- break; +- default: ++ if (data->pa_type != KRB5_PADATA_PK_AS_REQ) { + pkiDebug("unrecognized pa_type = %d\n", data->pa_type); + retval = EINVAL; + goto cleanup; + } ++ ++ TRACE_PKINIT_SERVER_PADATA_VERIFY(context); ++ retval = k5int_decode_krb5_pa_pk_as_req(&k5data, &reqp); ++ if (retval) { ++ pkiDebug("decode_krb5_pa_pk_as_req failed\n"); ++ goto cleanup; ++ } ++#ifdef DEBUG_ASN1 ++ print_buffer_bin(reqp->signedAuthPack.data, reqp->signedAuthPack.length, ++ "/tmp/kdc_signed_data"); ++#endif ++ retval = cms_signeddata_verify(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, plgctx->idctx, ++ CMS_SIGN_CLIENT, ++ plgctx->opts->require_crl_checking, ++ (unsigned char *)reqp->signedAuthPack.data, ++ reqp->signedAuthPack.length, ++ (unsigned char **)&authp_data.data, ++ &authp_data.length, ++ (unsigned char **)&krb5_authz.data, ++ &krb5_authz.length, &is_signed); + if (retval) { + TRACE_PKINIT_SERVER_PADATA_VERIFY_FAIL(context); + goto cleanup; +@@ -541,118 +513,88 @@ pkinit_server_verify_padata(krb5_context context, + #endif + + OCTETDATA_TO_KRB5DATA(&authp_data, &k5data); +- switch ((int)data->pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- retval = k5int_decode_krb5_auth_pack(&k5data, &auth_pack); ++ retval = k5int_decode_krb5_auth_pack(&k5data, &auth_pack); ++ if (retval) { ++ pkiDebug("failed to decode krb5_auth_pack\n"); ++ goto cleanup; ++ } ++ ++ retval = krb5_check_clockskew(context, auth_pack->pkAuthenticator.ctime); ++ if (retval) ++ goto cleanup; ++ ++ /* check dh parameters */ ++ if (auth_pack->clientPublicValue != NULL) { ++ retval = server_check_dh(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, plgctx->idctx, ++ &auth_pack->clientPublicValue->algorithm.parameters, ++ plgctx->opts->dh_min_bits); + if (retval) { +- pkiDebug("failed to decode krb5_auth_pack\n"); ++ pkiDebug("bad dh parameters\n"); + goto cleanup; + } +- +- retval = krb5_check_clockskew(context, +- auth_pack->pkAuthenticator.ctime); +- if (retval) +- goto cleanup; +- +- /* check dh parameters */ +- if (auth_pack->clientPublicValue != NULL) { +- retval = server_check_dh(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, +- &auth_pack->clientPublicValue->algorithm.parameters, +- plgctx->opts->dh_min_bits); +- +- if (retval) { +- pkiDebug("bad dh parameters\n"); +- goto cleanup; +- } +- } else if (!is_signed) { +- /*Anonymous pkinit requires DH*/ +- retval = KRB5KDC_ERR_PREAUTH_FAILED; +- krb5_set_error_message(context, retval, +- _("Anonymous pkinit without DH public " +- "value not supported.")); +- goto cleanup; +- } +- der_req = cb->request_body(context, rock); +- retval = krb5_c_make_checksum(context, CKSUMTYPE_NIST_SHA, NULL, +- 0, der_req, &cksum); +- if (retval) { +- pkiDebug("unable to calculate AS REQ checksum\n"); +- goto cleanup; +- } +- if (cksum.length != auth_pack->pkAuthenticator.paChecksum.length || +- k5_bcmp(cksum.contents, +- auth_pack->pkAuthenticator.paChecksum.contents, +- cksum.length) != 0) { +- pkiDebug("failed to match the checksum\n"); ++ } else if (!is_signed) { ++ /*Anonymous pkinit requires DH*/ ++ retval = KRB5KDC_ERR_PREAUTH_FAILED; ++ krb5_set_error_message(context, retval, ++ _("Anonymous pkinit without DH public " ++ "value not supported.")); ++ goto cleanup; ++ } ++ der_req = cb->request_body(context, rock); ++ retval = krb5_c_make_checksum(context, CKSUMTYPE_NIST_SHA, NULL, 0, ++ der_req, &cksum); ++ if (retval) { ++ pkiDebug("unable to calculate AS REQ checksum\n"); ++ goto cleanup; ++ } ++ if (cksum.length != auth_pack->pkAuthenticator.paChecksum.length || ++ k5_bcmp(cksum.contents, auth_pack->pkAuthenticator.paChecksum.contents, ++ cksum.length) != 0) { ++ pkiDebug("failed to match the checksum\n"); + #ifdef DEBUG_CKSUM +- pkiDebug("calculating checksum on buf size (%d)\n", +- req_pkt->length); +- print_buffer(req_pkt->data, req_pkt->length); +- pkiDebug("received checksum type=%d size=%d ", +- auth_pack->pkAuthenticator.paChecksum.checksum_type, ++ pkiDebug("calculating checksum on buf size (%d)\n", req_pkt->length); ++ print_buffer(req_pkt->data, req_pkt->length); ++ pkiDebug("received checksum type=%d size=%d ", ++ auth_pack->pkAuthenticator.paChecksum.checksum_type, ++ auth_pack->pkAuthenticator.paChecksum.length); ++ print_buffer(auth_pack->pkAuthenticator.paChecksum.contents, + auth_pack->pkAuthenticator.paChecksum.length); +- print_buffer(auth_pack->pkAuthenticator.paChecksum.contents, +- auth_pack->pkAuthenticator.paChecksum.length); +- pkiDebug("expected checksum type=%d size=%d ", +- cksum.checksum_type, cksum.length); +- print_buffer(cksum.contents, cksum.length); ++ pkiDebug("expected checksum type=%d size=%d ", ++ cksum.checksum_type, cksum.length); ++ print_buffer(cksum.contents, cksum.length); + #endif + +- retval = KRB5KDC_ERR_PA_CHECKSUM_MUST_BE_INCLUDED; +- goto cleanup; +- } +- +- ftoken = auth_pack->pkAuthenticator.freshnessToken; +- if (ftoken != NULL) { +- retval = cb->check_freshness_token(context, rock, ftoken); +- if (retval) +- goto cleanup; +- valid_freshness_token = TRUE; +- } +- +- /* check if kdcPkId present and match KDC's subjectIdentifier */ +- if (reqp->kdcPkId.data != NULL) { +- int valid_kdcPkId = 0; +- retval = pkinit_check_kdc_pkid(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, +- (unsigned char *)reqp->kdcPkId.data, +- reqp->kdcPkId.length, &valid_kdcPkId); +- if (retval) +- goto cleanup; +- if (!valid_kdcPkId) +- pkiDebug("kdcPkId in AS_REQ does not match KDC's cert" +- "RFC says to ignore and proceed\n"); +- +- } +- /* remember the decoded auth_pack for verify_padata routine */ +- reqctx->rcv_auth_pack = auth_pack; +- auth_pack = NULL; +- break; +- case KRB5_PADATA_PK_AS_REP_OLD: +- case KRB5_PADATA_PK_AS_REQ_OLD: +- retval = k5int_decode_krb5_auth_pack_draft9(&k5data, &auth_pack9); +- if (retval) { +- pkiDebug("failed to decode krb5_auth_pack_draft9\n"); +- goto cleanup; +- } +- if (auth_pack9->clientPublicValue != NULL) { +- retval = server_check_dh(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, +- &auth_pack9->clientPublicValue->algorithm.parameters, +- plgctx->opts->dh_min_bits); +- +- if (retval) { +- pkiDebug("bad dh parameters\n"); +- goto cleanup; +- } +- } +- /* remember the decoded auth_pack for verify_padata routine */ +- reqctx->rcv_auth_pack9 = auth_pack9; +- auth_pack9 = NULL; +- break; ++ retval = KRB5KDC_ERR_PA_CHECKSUM_MUST_BE_INCLUDED; ++ goto cleanup; + } + ++ ftoken = auth_pack->pkAuthenticator.freshnessToken; ++ if (ftoken != NULL) { ++ retval = cb->check_freshness_token(context, rock, ftoken); ++ if (retval) ++ goto cleanup; ++ valid_freshness_token = TRUE; ++ } ++ ++ /* check if kdcPkId present and match KDC's subjectIdentifier */ ++ if (reqp->kdcPkId.data != NULL) { ++ int valid_kdcPkId = 0; ++ retval = pkinit_check_kdc_pkid(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, plgctx->idctx, ++ (unsigned char *)reqp->kdcPkId.data, ++ reqp->kdcPkId.length, &valid_kdcPkId); ++ if (retval) ++ goto cleanup; ++ if (!valid_kdcPkId) { ++ pkiDebug("kdcPkId in AS_REQ does not match KDC's cert; " ++ "RFC says to ignore and proceed\n"); ++ } ++ } ++ /* remember the decoded auth_pack for verify_padata routine */ ++ reqctx->rcv_auth_pack = auth_pack; ++ auth_pack = NULL; ++ + if (is_signed) { + retval = check_log_freshness(context, plgctx, request, + valid_freshness_token); +@@ -682,21 +624,13 @@ cleanup: + pkiDebug("pkinit_create_edata failed\n"); + } + +- switch ((int)data->pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- free_krb5_pa_pk_as_req(&reqp); +- free(cksum.contents); +- break; +- case KRB5_PADATA_PK_AS_REP_OLD: +- case KRB5_PADATA_PK_AS_REQ_OLD: +- free_krb5_pa_pk_as_req_draft9(&reqp9); +- } ++ free_krb5_pa_pk_as_req(&reqp); ++ free(cksum.contents); + free(authp_data.data); + free(krb5_authz.data); + if (reqctx != NULL) + pkinit_fini_kdc_req_context(context, reqctx); + free_krb5_auth_pack(&auth_pack); +- free_krb5_auth_pack_draft9(context, &auth_pack9); + + (*respond)(arg, retval, modreq, e_data, NULL); + } +@@ -817,7 +751,6 @@ pkinit_server_return_padata(krb5_context context, + krb5_error_code retval = 0; + krb5_data scratch = {0, 0, NULL}; + krb5_pa_pk_as_req *reqp = NULL; +- krb5_pa_pk_as_req_draft9 *reqp9 = NULL; + int i = 0; + + unsigned char *subjectPublicKey = NULL; +@@ -828,21 +761,17 @@ pkinit_server_return_padata(krb5_context context, + krb5_kdc_dh_key_info dhkey_info; + krb5_data *encoded_dhkey_info = NULL; + krb5_pa_pk_as_rep *rep = NULL; +- krb5_pa_pk_as_rep_draft9 *rep9 = NULL; + krb5_data *out_data = NULL; + krb5_data secret; + + krb5_enctype enctype = -1; + + krb5_reply_key_pack *key_pack = NULL; +- krb5_reply_key_pack_draft9 *key_pack9 = NULL; + krb5_data *encoded_key_pack = NULL; + + pkinit_kdc_context plgctx; + pkinit_kdc_req_context reqctx; + +- int fixed_keypack = 0; +- + *send_pa = NULL; + if (padata->pa_type == KRB5_PADATA_PKINIT_KX) { + return return_pkinit_kx(context, request, reply, +@@ -886,29 +815,13 @@ pkinit_server_return_padata(krb5_context context, + goto cleanup; + } + +- switch((int)reqctx->pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- init_krb5_pa_pk_as_rep(&rep); +- if (rep == NULL) { +- retval = ENOMEM; +- goto cleanup; +- } +- /* let's assume it's RSA. we'll reset it to DH if needed */ +- rep->choice = choice_pa_pk_as_rep_encKeyPack; +- break; +- case KRB5_PADATA_PK_AS_REP_OLD: +- case KRB5_PADATA_PK_AS_REQ_OLD: +- init_krb5_pa_pk_as_rep_draft9(&rep9); +- if (rep9 == NULL) { +- retval = ENOMEM; +- goto cleanup; +- } +- rep9->choice = choice_pa_pk_as_rep_draft9_encKeyPack; +- break; +- default: +- retval = KRB5KDC_ERR_PREAUTH_FAILED; ++ init_krb5_pa_pk_as_rep(&rep); ++ if (rep == NULL) { ++ retval = ENOMEM; + goto cleanup; + } ++ /* let's assume it's RSA. we'll reset it to DH if needed */ ++ rep->choice = choice_pa_pk_as_rep_encKeyPack; + + if (reqctx->rcv_auth_pack != NULL && + reqctx->rcv_auth_pack->clientPublicValue != NULL) { +@@ -917,18 +830,7 @@ pkinit_server_return_padata(krb5_context context, + subjectPublicKey_len = + reqctx->rcv_auth_pack->clientPublicValue->subjectPublicKey.length; + rep->choice = choice_pa_pk_as_rep_dhInfo; +- } else if (reqctx->rcv_auth_pack9 != NULL && +- reqctx->rcv_auth_pack9->clientPublicValue != NULL) { +- subjectPublicKey = (unsigned char *) +- reqctx->rcv_auth_pack9->clientPublicValue->subjectPublicKey.data; +- subjectPublicKey_len = +- reqctx->rcv_auth_pack9->clientPublicValue->subjectPublicKey.length; +- rep9->choice = choice_pa_pk_as_rep_draft9_dhSignedData; +- } + +- /* if this DH, then process finish computing DH key */ +- if (rep != NULL && (rep->choice == choice_pa_pk_as_rep_dhInfo || +- rep->choice == choice_pa_pk_as_rep_draft9_dhSignedData)) { + pkiDebug("received DH key delivery AS REQ\n"); + retval = server_process_dh(context, plgctx->cryptoctx, + reqctx->cryptoctx, plgctx->idctx, subjectPublicKey, +@@ -938,10 +840,6 @@ pkinit_server_return_padata(krb5_context context, + pkiDebug("failed to process/create dh paramters\n"); + goto cleanup; + } +- } +- if ((rep9 != NULL && +- rep9->choice == choice_pa_pk_as_rep_draft9_dhSignedData) || +- (rep != NULL && rep->choice == choice_pa_pk_as_rep_dhInfo)) { + + /* + * This is DH, so don't generate the key until after we +@@ -966,36 +864,18 @@ pkinit_server_return_padata(krb5_context context, + "/tmp/kdc_dh_key_info"); + #endif + +- switch ((int)padata->pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- retval = cms_signeddata_create(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, CMS_SIGN_SERVER, 1, +- (unsigned char *) +- encoded_dhkey_info->data, +- encoded_dhkey_info->length, +- (unsigned char **) +- &rep->u.dh_Info.dhSignedData.data, +- &rep->u.dh_Info.dhSignedData.length); +- if (retval) { +- pkiDebug("failed to create pkcs7 signed data\n"); +- goto cleanup; +- } +- break; +- case KRB5_PADATA_PK_AS_REP_OLD: +- case KRB5_PADATA_PK_AS_REQ_OLD: +- retval = cms_signeddata_create(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, CMS_SIGN_DRAFT9, 1, +- (unsigned char *) +- encoded_dhkey_info->data, +- encoded_dhkey_info->length, +- (unsigned char **) +- &rep9->u.dhSignedData.data, +- &rep9->u.dhSignedData.length); +- if (retval) { +- pkiDebug("failed to create pkcs7 signed data\n"); +- goto cleanup; +- } +- break; ++ retval = cms_signeddata_create(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, plgctx->idctx, ++ CMS_SIGN_SERVER, 1, ++ (unsigned char *) ++ encoded_dhkey_info->data, ++ encoded_dhkey_info->length, ++ (unsigned char **) ++ &rep->u.dh_Info.dhSignedData.data, ++ &rep->u.dh_Info.dhSignedData.length); ++ if (retval) { ++ pkiDebug("failed to create pkcs7 signed data\n"); ++ goto cleanup; + } + + } else { +@@ -1007,102 +887,49 @@ pkinit_server_return_padata(krb5_context context, + goto cleanup; + } + +- /* check if PA_TYPE of KRB5_PADATA_AS_CHECKSUM (132) is present which +- * means the client is requesting that a checksum is send back instead +- * of the nonce. +- */ +- for (i = 0; request->padata[i] != NULL; i++) { +- pkiDebug("%s: Checking pa_type 0x%08x\n", +- __FUNCTION__, request->padata[i]->pa_type); +- if (request->padata[i]->pa_type == KRB5_PADATA_AS_CHECKSUM) +- fixed_keypack = 1; ++ init_krb5_reply_key_pack(&key_pack); ++ if (key_pack == NULL) { ++ retval = ENOMEM; ++ goto cleanup; + } +- pkiDebug("%s: return checksum instead of nonce = %d\n", +- __FUNCTION__, fixed_keypack); + +- /* if this is an RFC reply or draft9 client requested a checksum +- * in the reply instead of the nonce, create an RFC-style keypack +- */ +- if ((int)padata->pa_type == KRB5_PADATA_PK_AS_REQ || fixed_keypack) { +- init_krb5_reply_key_pack(&key_pack); +- if (key_pack == NULL) { +- retval = ENOMEM; +- goto cleanup; +- } +- +- retval = krb5_c_make_checksum(context, 0, +- encrypting_key, KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, +- req_pkt, &key_pack->asChecksum); +- if (retval) { +- pkiDebug("unable to calculate AS REQ checksum\n"); +- goto cleanup; +- } ++ retval = krb5_c_make_checksum(context, 0, encrypting_key, ++ KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, ++ req_pkt, &key_pack->asChecksum); ++ if (retval) { ++ pkiDebug("unable to calculate AS REQ checksum\n"); ++ goto cleanup; ++ } + #ifdef DEBUG_CKSUM +- pkiDebug("calculating checksum on buf size = %d\n", req_pkt->length); +- print_buffer(req_pkt->data, req_pkt->length); +- pkiDebug("checksum size = %d\n", key_pack->asChecksum.length); +- print_buffer(key_pack->asChecksum.contents, +- key_pack->asChecksum.length); +- pkiDebug("encrypting key (%d)\n", encrypting_key->length); +- print_buffer(encrypting_key->contents, encrypting_key->length); ++ pkiDebug("calculating checksum on buf size = %d\n", req_pkt->length); ++ print_buffer(req_pkt->data, req_pkt->length); ++ pkiDebug("checksum size = %d\n", key_pack->asChecksum.length); ++ print_buffer(key_pack->asChecksum.contents, ++ key_pack->asChecksum.length); ++ pkiDebug("encrypting key (%d)\n", encrypting_key->length); ++ print_buffer(encrypting_key->contents, encrypting_key->length); + #endif + +- krb5_copy_keyblock_contents(context, encrypting_key, +- &key_pack->replyKey); ++ krb5_copy_keyblock_contents(context, encrypting_key, ++ &key_pack->replyKey); + +- retval = k5int_encode_krb5_reply_key_pack(key_pack, +- &encoded_key_pack); +- if (retval) { +- pkiDebug("failed to encode reply_key_pack\n"); +- goto cleanup; +- } ++ retval = k5int_encode_krb5_reply_key_pack(key_pack, ++ &encoded_key_pack); ++ if (retval) { ++ pkiDebug("failed to encode reply_key_pack\n"); ++ goto cleanup; + } + +- switch ((int)padata->pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- rep->choice = choice_pa_pk_as_rep_encKeyPack; +- retval = cms_envelopeddata_create(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, padata->pa_type, 1, +- (unsigned char *) +- encoded_key_pack->data, +- encoded_key_pack->length, +- (unsigned char **) +- &rep->u.encKeyPack.data, +- &rep->u.encKeyPack.length); +- break; +- case KRB5_PADATA_PK_AS_REP_OLD: +- case KRB5_PADATA_PK_AS_REQ_OLD: +- /* if the request is from the broken draft9 client that +- * expects back a nonce, create it now +- */ +- if (!fixed_keypack) { +- init_krb5_reply_key_pack_draft9(&key_pack9); +- if (key_pack9 == NULL) { +- retval = ENOMEM; +- goto cleanup; +- } +- key_pack9->nonce = reqctx->rcv_auth_pack9->pkAuthenticator.nonce; +- krb5_copy_keyblock_contents(context, encrypting_key, +- &key_pack9->replyKey); +- +- retval = k5int_encode_krb5_reply_key_pack_draft9(key_pack9, +- &encoded_key_pack); +- if (retval) { +- pkiDebug("failed to encode reply_key_pack\n"); +- goto cleanup; +- } +- } +- +- rep9->choice = choice_pa_pk_as_rep_draft9_encKeyPack; +- retval = cms_envelopeddata_create(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, padata->pa_type, 1, +- (unsigned char *) +- encoded_key_pack->data, +- encoded_key_pack->length, +- (unsigned char **) +- &rep9->u.encKeyPack.data, &rep9->u.encKeyPack.length); +- break; +- } ++ rep->choice = choice_pa_pk_as_rep_encKeyPack; ++ retval = cms_envelopeddata_create(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, plgctx->idctx, ++ padata->pa_type, 1, ++ (unsigned char *) ++ encoded_key_pack->data, ++ encoded_key_pack->length, ++ (unsigned char **) ++ &rep->u.encKeyPack.data, ++ &rep->u.encKeyPack.length); + if (retval) { + pkiDebug("failed to create pkcs7 enveloped data: %s\n", + error_message(retval)); +@@ -1112,23 +939,12 @@ pkinit_server_return_padata(krb5_context context, + print_buffer_bin((unsigned char *)encoded_key_pack->data, + encoded_key_pack->length, + "/tmp/kdc_key_pack"); +- switch ((int)padata->pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- print_buffer_bin(rep->u.encKeyPack.data, +- rep->u.encKeyPack.length, +- "/tmp/kdc_enc_key_pack"); +- break; +- case KRB5_PADATA_PK_AS_REP_OLD: +- case KRB5_PADATA_PK_AS_REQ_OLD: +- print_buffer_bin(rep9->u.encKeyPack.data, +- rep9->u.encKeyPack.length, +- "/tmp/kdc_enc_key_pack"); +- break; +- } ++ print_buffer_bin(rep->u.encKeyPack.data, rep->u.encKeyPack.length, ++ "/tmp/kdc_enc_key_pack"); + #endif + } + +- if ((rep != NULL && rep->choice == choice_pa_pk_as_rep_dhInfo) && ++ if (rep->choice == choice_pa_pk_as_rep_dhInfo && + ((reqctx->rcv_auth_pack != NULL && + reqctx->rcv_auth_pack->supportedKDFs != NULL))) { + +@@ -1147,15 +963,7 @@ pkinit_server_return_padata(krb5_context context, + } + } + +- switch ((int)padata->pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- retval = k5int_encode_krb5_pa_pk_as_rep(rep, &out_data); +- break; +- case KRB5_PADATA_PK_AS_REP_OLD: +- case KRB5_PADATA_PK_AS_REQ_OLD: +- retval = k5int_encode_krb5_pa_pk_as_rep_draft9(rep9, &out_data); +- break; +- } ++ retval = k5int_encode_krb5_pa_pk_as_rep(rep, &out_data); + if (retval) { + pkiDebug("failed to encode AS_REP\n"); + goto cleanup; +@@ -1167,13 +975,11 @@ pkinit_server_return_padata(krb5_context context, + #endif + + /* If this is DH, we haven't computed the key yet, so do it now. */ +- if ((rep9 != NULL && +- rep9->choice == choice_pa_pk_as_rep_draft9_dhSignedData) || +- (rep != NULL && rep->choice == choice_pa_pk_as_rep_dhInfo)) { ++ if (rep->choice == choice_pa_pk_as_rep_dhInfo) { + +- /* If we're not doing draft 9, and mutually supported KDFs were found, +- * use the algorithm agility KDF. */ +- if (rep != NULL && rep->u.dh_Info.kdfID) { ++ /* If mutually supported KDFs were found, use the algorithm agility ++ * KDF. */ ++ if (rep->u.dh_Info.kdfID) { + secret.data = (char *)server_key; + secret.length = server_key_len; + +@@ -1209,15 +1015,7 @@ pkinit_server_return_padata(krb5_context context, + goto cleanup; + } + (*send_pa)->magic = KV5M_PA_DATA; +- switch ((int)padata->pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- (*send_pa)->pa_type = KRB5_PADATA_PK_AS_REP; +- break; +- case KRB5_PADATA_PK_AS_REQ_OLD: +- case KRB5_PADATA_PK_AS_REP_OLD: +- (*send_pa)->pa_type = KRB5_PADATA_PK_AS_REP_OLD; +- break; +- } ++ (*send_pa)->pa_type = KRB5_PADATA_PK_AS_REP; + (*send_pa)->length = out_data->length; + (*send_pa)->contents = (krb5_octet *) out_data->data; + +@@ -1231,23 +1029,9 @@ cleanup: + krb5_free_data(context, encoded_key_pack); + free(dh_pubkey); + free(server_key); +- +- switch ((int)padata->pa_type) { +- case KRB5_PADATA_PK_AS_REQ: +- free_krb5_pa_pk_as_req(&reqp); +- free_krb5_pa_pk_as_rep(&rep); +- free_krb5_reply_key_pack(&key_pack); +- break; +- case KRB5_PADATA_PK_AS_REP_OLD: +- case KRB5_PADATA_PK_AS_REQ_OLD: +- free_krb5_pa_pk_as_req_draft9(&reqp9); +- free_krb5_pa_pk_as_rep_draft9(&rep9); +- if (!fixed_keypack) +- free_krb5_reply_key_pack_draft9(&key_pack9); +- else +- free_krb5_reply_key_pack(&key_pack); +- break; +- } ++ free_krb5_pa_pk_as_req(&reqp); ++ free_krb5_pa_pk_as_rep(&rep); ++ free_krb5_reply_key_pack(&key_pack); + + if (retval) + pkiDebug("pkinit_verify_padata failure"); +@@ -1265,8 +1049,6 @@ pkinit_server_get_flags(krb5_context kcontext, krb5_preauthtype patype) + + static krb5_preauthtype supported_server_pa_types[] = { + KRB5_PADATA_PK_AS_REQ, +- KRB5_PADATA_PK_AS_REQ_OLD, +- KRB5_PADATA_PK_AS_REP_OLD, + KRB5_PADATA_PKINIT_KX, + 0 + }; +@@ -1796,7 +1578,6 @@ pkinit_init_kdc_req_context(krb5_context context, pkinit_kdc_req_context *ctx) + if (retval) + goto cleanup; + reqctx->rcv_auth_pack = NULL; +- reqctx->rcv_auth_pack9 = NULL; + + pkiDebug("%s: returning reqctx at %p\n", __FUNCTION__, reqctx); + *ctx = reqctx; +@@ -1822,8 +1603,6 @@ pkinit_fini_kdc_req_context(krb5_context context, void *ctx) + pkinit_fini_req_crypto(reqctx->cryptoctx); + if (reqctx->rcv_auth_pack != NULL) + free_krb5_auth_pack(&reqctx->rcv_auth_pack); +- if (reqctx->rcv_auth_pack9 != NULL) +- free_krb5_auth_pack_draft9(context, &reqctx->rcv_auth_pack9); + + free(reqctx); + } +diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h +index 4da735f80..bba3226bd 100644 +--- a/src/plugins/preauth/pkinit/pkinit_trace.h ++++ b/src/plugins/preauth/pkinit/pkinit_trace.h +@@ -49,8 +49,6 @@ + #define TRACE_PKINIT_CLIENT_KDF_OS2K(c, keyblock) \ + TRACE(c, "PKINIT client used octetstring2key to compute reply key " \ + "{keyblock}", keyblock) +-#define TRACE_PKINIT_CLIENT_NO_DRAFT9(c) \ +- TRACE(c, "PKINIT client ignoring draft 9 offer from RFC 4556 KDC") + #define TRACE_PKINIT_CLIENT_NO_IDENTITY(c) \ + TRACE(c, "PKINIT client has no configured identity; giving up") + #define TRACE_PKINIT_CLIENT_REP_CHECKSUM_FAIL(c, expected, received) \ +@@ -115,8 +113,6 @@ + TRACE(c, "PKINIT server found no SAN in client cert") + #define TRACE_PKINIT_SERVER_PADATA_VERIFY(c) \ + TRACE(c, "PKINIT server verifying KRB5_PADATA_PK_AS_REQ") +-#define TRACE_PKINIT_SERVER_PADATA_VERIFY_OLD(c) \ +- TRACE(c, "PKINIT server verifying KRB5_PADATA_PK_AS_REQ_OLD") + #define TRACE_PKINIT_SERVER_PADATA_VERIFY_FAIL(c) \ + TRACE(c, "PKINIT server failed to verify PA data") + #define TRACE_PKINIT_SERVER_RETURN_PADATA(c) \ +diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py +index 1dadb1b96..93f0f2632 100755 +--- a/src/tests/t_pkinit.py ++++ b/src/tests/t_pkinit.py +@@ -432,11 +432,9 @@ realm.kinit(realm.user_princ, + realm.klist(realm.user_princ) + realm.run([kvno, realm.host_princ]) + +-# Supply the wrong PIN, and verify that we ignore the draft9 padata offer +-# in the KDC method data after RFC 4556 PKINIT fails. ++# Supply the wrong PIN. + mark('PKCS11 identity, wrong PIN') +-expected_trace = ('PKINIT client has no configured identity; giving up', +- 'PKINIT client ignoring draft 9 offer from RFC 4556 KDC') ++expected_trace = ('PKINIT client has no configured identity; giving up',) + realm.kinit(realm.user_princ, + flags=['-X', 'X509_user_identity=%s' % p11_identity], + password='wrong', expected_code=1, expected_trace=expected_trace) diff --git a/Remove-strerror-calls-from-k5_get_error.patch b/Remove-strerror-calls-from-k5_get_error.patch index 7ce77b3..6dbe4e1 100644 --- a/Remove-strerror-calls-from-k5_get_error.patch +++ b/Remove-strerror-calls-from-k5_get_error.patch @@ -1,4 +1,4 @@ -From f9c5dd7a9bb19dc99de8ee046b0ac1506c494f4e Mon Sep 17 00:00:00 2001 +From 80ce19337573b31c372251ea5af4e66f4b75e7ef Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 6 Jun 2019 11:46:58 -0400 Subject: [PATCH] Remove strerror() calls from k5_get_error() diff --git a/krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch b/krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch index 18ebb8c..334a93b 100644 --- a/krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch +++ b/krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch @@ -1,4 +1,4 @@ -From a57e6f65c6368b3fe99baaaeafccd166dad006b4 Mon Sep 17 00:00:00 2001 +From fd2088635e27ce571e2d98c40fea34db15243b7a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] krb5-1.17post4 FIPS with PRNG, SPAKE, and RADIUS diff --git a/krb5.spec b/krb5.spec index 7cd5bc8..7d9a5a6 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 31%{?dist} +Release: 32%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -105,9 +105,11 @@ Patch140: Display-unsupported-enctype-names.patch Patch142: Add-zapfreedata-convenience-function.patch Patch143: Remove-support-for-no-flags-SAM-2-preauth.patch Patch144: Remove-krb5int_c_combine_keys.patch -Patch145: Remove-3des-support.patch Patch146: krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch Patch147: Remove-strerror-calls-from-k5_get_error.patch +Patch148: Remove-PKINIT-draft-9-support.patch +Patch149: Remove-PKINIT-draft-9-ASN.1-code-and-types.patch +Patch150: Remove-3des-support.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -717,6 +719,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Jun 26 2019 Robbie Harwood - 1.17-32 +- Remove PKINIT draft9 support (compat with EOL, pre-2008 Windows) + * Mon Jun 10 2019 Robbie Harwood - 1.17-31 - Remove strerror() calls from k5_get_error() From 490a817464119d944fcc8f657918a4b0b9a385c6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 26 Jun 2019 18:23:02 -0400 Subject: [PATCH 118/304] Fix typo in 3des commit --- Remove-3des-support.patch | 16 +++++----------- krb5.spec | 5 ++++- 2 files changed, 9 insertions(+), 12 deletions(-) diff --git a/Remove-3des-support.patch b/Remove-3des-support.patch index be344a3..9214ccb 100644 --- a/Remove-3des-support.patch +++ b/Remove-3des-support.patch @@ -1,4 +1,4 @@ -From cac8b2d0da82fd625da0a351bb80b51a0bb811a2 Mon Sep 17 00:00:00 2001 +From c524c375aef17009e3dcca4a2001e102e022c24b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] Remove 3des support @@ -8,7 +8,7 @@ des3-hmac-sha1, des3-cbc-sha1-kd). Update all tests and documentation to user other enctypes. Mark the 3DES enctypes UNSUPPORTED and retain their constants. -(cherry picked from commit 49b086ddbf861ad0e2e84c402f3d65e9ea8a2392) +(cherry picked from commit 57a8a84e035000b515ca9efd56e5cbe1568b95e7) --- doc/admin/advanced/retiring-des.rst | 11 + doc/admin/conf_files/kdc_conf.rst | 7 +- @@ -18,7 +18,7 @@ their constants. doc/mitK5features.rst | 2 +- src/Makefile.in | 4 +- src/configure.in | 1 - - src/include/krb5/krb5.hin | 12 +- + src/include/krb5/krb5.hin | 10 +- src/kadmin/testing/proto/kdc.conf.proto | 4 +- src/kdc/kdc_util.c | 4 - src/lib/crypto/Makefile.in | 8 +- @@ -105,7 +105,7 @@ their constants. src/tests/t_salt.py | 5 +- src/util/k5test.py | 10 - .../leash/htmlhelp/html/Encryption_Types.htm | 13 - - 95 files changed, 163 insertions(+), 4837 deletions(-) + 95 files changed, 162 insertions(+), 4836 deletions(-) delete mode 100644 src/lib/crypto/builtin/des/ISSUES delete mode 100644 src/lib/crypto/builtin/des/Makefile.in delete mode 100644 src/lib/crypto/builtin/des/d3_aead.c @@ -302,15 +302,9 @@ index 8d781a7c8..a19a0ea97 100644 lib/crypto/$CRYPTO_IMPL/sha1 lib/crypto/$CRYPTO_IMPL/sha2 lib/crypto/$CRYPTO_IMPL/aes lib/crypto/$CRYPTO_IMPL/camellia diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 5f596d1fc..ca7eb6a80 100644 +index 5f596d1fc..9a05ce32d 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin -@@ -1,4 +1,4 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+./* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ - /* General definitions for Kerberos version 5. */ - /* - * Copyright 1989, 1990, 1995, 2001, 2003, 2007, 2011 by the Massachusetts @@ -426,8 +426,8 @@ typedef struct _krb5_crypto_iov { #define ENCTYPE_DES_CBC_MD4 0x0002 /**< @deprecated no longer supported */ #define ENCTYPE_DES_CBC_MD5 0x0003 /**< @deprecated no longer supported */ diff --git a/krb5.spec b/krb5.spec index 7d9a5a6..02efe4e 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 32%{?dist} +Release: 33%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -719,6 +719,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Jun 26 2019 Robbie Harwood - 1.17-33 +- Fix typo in 3des commit + * Wed Jun 26 2019 Robbie Harwood - 1.17-32 - Remove PKINIT draft9 support (compat with EOL, pre-2008 Windows) From a0277fd3965293216fd1daadd1046d8a02c2282c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Jul 2019 11:42:28 -0400 Subject: [PATCH 119/304] Remove now-unused checksum functions --- Remove-now-unused-checksum-functions.patch | 335 +++++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 340 insertions(+), 1 deletion(-) create mode 100644 Remove-now-unused-checksum-functions.patch diff --git a/Remove-now-unused-checksum-functions.patch b/Remove-now-unused-checksum-functions.patch new file mode 100644 index 0000000..640f059 --- /dev/null +++ b/Remove-now-unused-checksum-functions.patch @@ -0,0 +1,335 @@ +From 3c132f6e129f3e4805ae44a8db749930f1e398b1 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 28 Jun 2019 13:09:47 -0400 +Subject: [PATCH] Remove now-unused checksum functions + +fb2dada5eb89c4cd4e39dedd6dbb7dbd5e94f8b8 removed all call sites of +krb5int_cbc_checksum(), krb5int_confounder_verify(), and +krb5int_confounder_checksum(), but neglected the functions themselves. + +ticket: 8808 +(cherry picked from commit 2063ff09b384d466c15aca8970c01d074230c815) +--- + src/lib/crypto/krb/Makefile.in | 6 - + src/lib/crypto/krb/checksum_cbc.c | 41 ------ + src/lib/crypto/krb/checksum_confounder.c | 159 ----------------------- + src/lib/crypto/krb/crypto_int.h | 16 --- + src/lib/crypto/krb/deps | 26 ---- + 5 files changed, 248 deletions(-) + delete mode 100644 src/lib/crypto/krb/checksum_cbc.c + delete mode 100644 src/lib/crypto/krb/checksum_confounder.c + +diff --git a/src/lib/crypto/krb/Makefile.in b/src/lib/crypto/krb/Makefile.in +index b587f7e19..2b0c4163d 100644 +--- a/src/lib/crypto/krb/Makefile.in ++++ b/src/lib/crypto/krb/Makefile.in +@@ -10,8 +10,6 @@ STLIBOBJS=\ + aead.o \ + block_size.o \ + cf2.o \ +- checksum_cbc.o \ +- checksum_confounder.o \ + checksum_dk_cmac.o \ + checksum_dk_hmac.o \ + checksum_etm.o \ +@@ -70,8 +68,6 @@ OBJS=\ + $(OUTPRE)aead.$(OBJEXT) \ + $(OUTPRE)block_size.$(OBJEXT) \ + $(OUTPRE)cf2.$(OBJEXT) \ +- $(OUTPRE)checksum_cbc.$(OBJEXT) \ +- $(OUTPRE)checksum_confounder.$(OBJEXT) \ + $(OUTPRE)checksum_dk_cmac.$(OBJEXT) \ + $(OUTPRE)checksum_dk_hmac.$(OBJEXT) \ + $(OUTPRE)checksum_etm.$(OBJEXT) \ +@@ -130,8 +126,6 @@ SRCS=\ + $(srcdir)/aead.c \ + $(srcdir)/block_size.c \ + $(srcdir)/cf2.c \ +- $(srcdir)/checksum_cbc.c \ +- $(srcdir)/checksum_confounder.c \ + $(srcdir)/checksum_dk_cmac.c \ + $(srcdir)/checksum_dk_hmac.c \ + $(srcdir)/checksum_etm.c \ +diff --git a/src/lib/crypto/krb/checksum_cbc.c b/src/lib/crypto/krb/checksum_cbc.c +deleted file mode 100644 +index 48afeb0e5..000000000 +--- a/src/lib/crypto/krb/checksum_cbc.c ++++ /dev/null +@@ -1,41 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/krb/checksum_cbc.c */ +-/* +- * Copyright (C) 2009 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* CBC checksum, which computes the ivec resulting from CBC encryption of the +- * input. */ +- +-#include "crypto_int.h" +- +-krb5_error_code +-krb5int_cbc_checksum(const struct krb5_cksumtypes *ctp, +- krb5_key key, krb5_keyusage usage, +- const krb5_crypto_iov *data, size_t num_data, +- krb5_data *output) +-{ +- if (ctp->enc->cbc_mac == NULL) +- return KRB5_CRYPTO_INTERNAL; +- return ctp->enc->cbc_mac(key, data, num_data, NULL, output); +-} +diff --git a/src/lib/crypto/krb/checksum_confounder.c b/src/lib/crypto/krb/checksum_confounder.c +deleted file mode 100644 +index 34941562c..000000000 +--- a/src/lib/crypto/krb/checksum_confounder.c ++++ /dev/null +@@ -1,159 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* lib/crypto/krb/checksum_confounder.c */ +-/* +- * Copyright (C) 2009 by the Massachusetts Institute of Technology. +- * All rights reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* +- * Confounder checksum implementation, using tokens of the form: +- * enc(xorkey, confounder | hash(confounder | data)) +- * where xorkey is the key XOR'd with 0xf0 bytes. +- */ +- +-#include "crypto_int.h" +- +-/* Derive a key by XOR with 0xF0 bytes. */ +-static krb5_error_code +-mk_xorkey(krb5_key origkey, krb5_key *xorkey) +-{ +- krb5_error_code retval = 0; +- unsigned char *xorbytes; +- krb5_keyblock xorkeyblock; +- size_t i = 0; +- +- xorbytes = k5memdup(origkey->keyblock.contents, origkey->keyblock.length, +- &retval); +- if (xorbytes == NULL) +- return retval; +- for (i = 0; i < origkey->keyblock.length; i++) +- xorbytes[i] ^= 0xf0; +- +- /* Do a shallow copy here. */ +- xorkeyblock = origkey->keyblock; +- xorkeyblock.contents = xorbytes; +- +- retval = krb5_k_create_key(0, &xorkeyblock, xorkey); +- zapfree(xorbytes, origkey->keyblock.length); +- return retval; +-} +- +-krb5_error_code +-krb5int_confounder_checksum(const struct krb5_cksumtypes *ctp, +- krb5_key key, krb5_keyusage usage, +- const krb5_crypto_iov *data, size_t num_data, +- krb5_data *output) +-{ +- krb5_error_code ret; +- krb5_data conf, hashval; +- krb5_key xorkey = NULL; +- krb5_crypto_iov *hash_iov, iov; +- size_t blocksize = ctp->enc->block_size, hashsize = ctp->hash->hashsize; +- +- /* Partition the output buffer into confounder and hash. */ +- conf = make_data(output->data, blocksize); +- hashval = make_data(output->data + blocksize, hashsize); +- +- /* Create the confounder. */ +- ret = krb5_c_random_make_octets(NULL, &conf); +- if (ret != 0) +- return ret; +- +- ret = mk_xorkey(key, &xorkey); +- if (ret) +- return ret; +- +- /* Hash the confounder, then the input data. */ +- hash_iov = k5calloc(num_data + 1, sizeof(krb5_crypto_iov), &ret); +- if (hash_iov == NULL) +- goto cleanup; +- hash_iov[0].flags = KRB5_CRYPTO_TYPE_DATA; +- hash_iov[0].data = conf; +- memcpy(hash_iov + 1, data, num_data * sizeof(krb5_crypto_iov)); +- ret = ctp->hash->hash(hash_iov, num_data + 1, &hashval); +- if (ret != 0) +- goto cleanup; +- +- /* Confounder and hash are in output buffer; encrypt them in place. */ +- iov.flags = KRB5_CRYPTO_TYPE_DATA; +- iov.data = *output; +- ret = ctp->enc->encrypt(xorkey, NULL, &iov, 1); +- +-cleanup: +- free(hash_iov); +- krb5_k_free_key(NULL, xorkey); +- return ret; +-} +- +-krb5_error_code krb5int_confounder_verify(const struct krb5_cksumtypes *ctp, +- krb5_key key, krb5_keyusage usage, +- const krb5_crypto_iov *data, +- size_t num_data, +- const krb5_data *input, +- krb5_boolean *valid) +-{ +- krb5_error_code ret; +- unsigned char *plaintext = NULL; +- krb5_key xorkey = NULL; +- krb5_data computed = empty_data(); +- krb5_crypto_iov *hash_iov = NULL, iov; +- size_t blocksize = ctp->enc->block_size, hashsize = ctp->hash->hashsize; +- +- plaintext = k5memdup(input->data, input->length, &ret); +- if (plaintext == NULL) +- return ret; +- +- ret = mk_xorkey(key, &xorkey); +- if (ret != 0) +- goto cleanup; +- +- /* Decrypt the input checksum. */ +- iov.flags = KRB5_CRYPTO_TYPE_DATA; +- iov.data = make_data(plaintext, input->length); +- ret = ctp->enc->decrypt(xorkey, NULL, &iov, 1); +- if (ret != 0) +- goto cleanup; +- +- /* Hash the confounder, then the input data. */ +- hash_iov = k5calloc(num_data + 1, sizeof(krb5_crypto_iov), &ret); +- if (hash_iov == NULL) +- goto cleanup; +- hash_iov[0].flags = KRB5_CRYPTO_TYPE_DATA; +- hash_iov[0].data = make_data(plaintext, blocksize); +- memcpy(hash_iov + 1, data, num_data * sizeof(krb5_crypto_iov)); +- ret = alloc_data(&computed, hashsize); +- if (ret != 0) +- goto cleanup; +- ret = ctp->hash->hash(hash_iov, num_data + 1, &computed); +- if (ret != 0) +- goto cleanup; +- +- /* Compare the decrypted hash to the computed one. */ +- *valid = (k5_bcmp(plaintext + blocksize, computed.data, hashsize) == 0); +- +-cleanup: +- zapfree(plaintext, input->length); +- zapfree(computed.data, hashsize); +- free(hash_iov); +- krb5_k_free_key(NULL, xorkey); +- return ret; +-} +diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h +index 1b4324d71..5cc1f8e43 100644 +--- a/src/lib/crypto/krb/crypto_int.h ++++ b/src/lib/crypto/krb/crypto_int.h +@@ -299,11 +299,6 @@ krb5_error_code krb5int_unkeyed_checksum(const struct krb5_cksumtypes *ctp, + const krb5_crypto_iov *data, + size_t num_data, + krb5_data *output); +-krb5_error_code krb5int_cbc_checksum(const struct krb5_cksumtypes *ctp, +- krb5_key key, krb5_keyusage usage, +- const krb5_crypto_iov *data, +- size_t num_data, +- krb5_data *output); + krb5_error_code krb5int_hmacmd5_checksum(const struct krb5_cksumtypes *ctp, + krb5_key key, krb5_keyusage usage, + const krb5_crypto_iov *data, +@@ -317,17 +312,6 @@ krb5_error_code krb5int_dk_cmac_checksum(const struct krb5_cksumtypes *ctp, + krb5_key key, krb5_keyusage usage, + const krb5_crypto_iov *data, + size_t num_data, krb5_data *output); +-krb5_error_code krb5int_confounder_checksum(const struct krb5_cksumtypes *ctp, +- krb5_key key, krb5_keyusage usage, +- const krb5_crypto_iov *data, +- size_t num_data, +- krb5_data *output); +-krb5_error_code krb5int_confounder_verify(const struct krb5_cksumtypes *ctp, +- krb5_key key, krb5_keyusage usage, +- const krb5_crypto_iov *data, +- size_t num_data, +- const krb5_data *input, +- krb5_boolean *valid); + krb5_error_code krb5int_etm_checksum(const struct krb5_cksumtypes *ctp, + krb5_key key, krb5_keyusage usage, + const krb5_crypto_iov *data, +diff --git a/src/lib/crypto/krb/deps b/src/lib/crypto/krb/deps +index 2f4af1906..883d12c56 100644 +--- a/src/lib/crypto/krb/deps ++++ b/src/lib/crypto/krb/deps +@@ -37,32 +37,6 @@ cf2.so cf2.po $(OUTPRE)cf2.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ + $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ + cf2.c crypto_int.h +-checksum_cbc.so checksum_cbc.po $(OUTPRE)checksum_cbc.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h $(srcdir)/../builtin/crypto_mod.h \ +- $(srcdir)/../builtin/sha2/sha2.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h checksum_cbc.c \ +- crypto_int.h +-checksum_confounder.so checksum_confounder.po $(OUTPRE)checksum_confounder.$(OBJEXT): \ +- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h $(srcdir)/../builtin/crypto_mod.h \ +- $(srcdir)/../builtin/sha2/sha2.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h checksum_confounder.c \ +- crypto_int.h + checksum_dk_cmac.so checksum_dk_cmac.po $(OUTPRE)checksum_dk_cmac.$(OBJEXT): \ + $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ + $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ diff --git a/krb5.spec b/krb5.spec index 02efe4e..1604fef 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 33%{?dist} +Release: 34%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -110,6 +110,7 @@ Patch147: Remove-strerror-calls-from-k5_get_error.patch Patch148: Remove-PKINIT-draft-9-support.patch Patch149: Remove-PKINIT-draft-9-ASN.1-code-and-types.patch Patch150: Remove-3des-support.patch +Patch151: Remove-now-unused-checksum-functions.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -719,6 +720,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Jul 02 2019 Robbie Harwood - 1.17-34 +- Remove now-unused checksum functions + * Wed Jun 26 2019 Robbie Harwood - 1.17-33 - Fix typo in 3des commit From 4c8ed386668c82b014d57ca12fd0d8f8754c0132 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 15 Jul 2019 13:07:54 -0400 Subject: [PATCH 120/304] Don't error on invalid enctypes in keytab Resolves: #1724380 --- ...-error-on-invalid-enctypes-in-keytab.patch | 67 +++++++++++++++++++ krb5.spec | 7 +- 2 files changed, 73 insertions(+), 1 deletion(-) create mode 100644 Don-t-error-on-invalid-enctypes-in-keytab.patch diff --git a/Don-t-error-on-invalid-enctypes-in-keytab.patch b/Don-t-error-on-invalid-enctypes-in-keytab.patch new file mode 100644 index 0000000..e61ae21 --- /dev/null +++ b/Don-t-error-on-invalid-enctypes-in-keytab.patch @@ -0,0 +1,67 @@ +From 56f59b21814cca0b68e1506d5d8bd15636812c0f Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 10 Jul 2019 17:10:16 -0400 +Subject: [PATCH] Don't error on invalid enctypes in keytab + +krb5_ktfile_get_entry() used krb5_c_enctype_compare() to compare +enctypes, in order to share keys between single-DES enctypes. As +key-sharing between enctypes is no longer done and single-DES support +has been removed, use a simple equality test to match the enctype. +This fixes a bug where krb5_kt_get_entry() would error out if the +keytab contained any entries with invalid enctypes (include single-DES +entries, after commit fb2dada5eb89c4cd4e39dedd6dbb7dbd5e94f8b8) even +if a matching entry is found. + +[ghudson@mit.edu: rewrote commit message] + +ticket: 8808 +(cherry picked from commit 38be1a0a31a6104cdf8c8d72828905775f6d6636) +--- + src/lib/krb5/keytab/kt_file.c | 27 +++++---------------------- + 1 file changed, 5 insertions(+), 22 deletions(-) + +diff --git a/src/lib/krb5/keytab/kt_file.c b/src/lib/krb5/keytab/kt_file.c +index 21c80d419..df2530a45 100644 +--- a/src/lib/krb5/keytab/kt_file.c ++++ b/src/lib/krb5/keytab/kt_file.c +@@ -289,7 +289,6 @@ krb5_ktfile_get_entry(krb5_context context, krb5_keytab id, + krb5_keytab_entry cur_entry, new_entry; + krb5_error_code kerror = 0; + int found_wrong_kvno = 0; +- krb5_boolean similar; + int was_open; + char *princname; + +@@ -336,27 +335,11 @@ krb5_ktfile_get_entry(krb5_context context, krb5_keytab id, + continue; + } + +- /* if the enctype is not ignored and doesn't match, free new_entry +- and continue to the next */ +- +- if (enctype != IGNORE_ENCTYPE) { +- if ((kerror = krb5_c_enctype_compare(context, enctype, +- new_entry.key.enctype, +- &similar))) { +- krb5_kt_free_entry(context, &new_entry); +- break; +- } +- +- if (!similar) { +- krb5_kt_free_entry(context, &new_entry); +- continue; +- } +- /* +- * Coerce the enctype of the output keyblock in case we +- * got an inexact match on the enctype. +- */ +- new_entry.key.enctype = enctype; +- ++ /* If the enctype is not ignored and doesn't match, free new_entry and ++ continue to the next. */ ++ if (enctype != IGNORE_ENCTYPE && enctype != new_entry.key.enctype) { ++ krb5_kt_free_entry(context, &new_entry); ++ continue; + } + + if (kvno == IGNORE_VNO || new_entry.vno == IGNORE_VNO) { diff --git a/krb5.spec b/krb5.spec index 1604fef..373bf85 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 34%{?dist} +Release: 35%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -111,6 +111,7 @@ Patch148: Remove-PKINIT-draft-9-support.patch Patch149: Remove-PKINIT-draft-9-ASN.1-code-and-types.patch Patch150: Remove-3des-support.patch Patch151: Remove-now-unused-checksum-functions.patch +Patch152: Don-t-error-on-invalid-enctypes-in-keytab.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -720,6 +721,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jul 15 2019 Robbie Harwood - 1.17-35 +- Don't error on invalid enctypes in keytab +- Resolves: #1724380 + * Tue Jul 02 2019 Robbie Harwood - 1.17-34 - Remove now-unused checksum functions From 7c5b49f8287af62961670fbef8f394aaa4e9d770 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 18 Jul 2019 12:49:23 -0400 Subject: [PATCH 121/304] Filter enctypes in gss_set_allowable_enctypes() --- ...ctypes-in-gss_set_allowable_enctypes.patch | 70 +++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 75 insertions(+), 1 deletion(-) create mode 100644 Filter-enctypes-in-gss_set_allowable_enctypes.patch diff --git a/Filter-enctypes-in-gss_set_allowable_enctypes.patch b/Filter-enctypes-in-gss_set_allowable_enctypes.patch new file mode 100644 index 0000000..2c7b0d6 --- /dev/null +++ b/Filter-enctypes-in-gss_set_allowable_enctypes.patch @@ -0,0 +1,70 @@ +From 6aeef2d2e19109cc97f6b1f4621fb97247edfa73 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 16 Jul 2019 00:15:42 -0400 +Subject: [PATCH] Filter enctypes in gss_set_allowable_enctypes() + +Instead of erroring out when any invalid enctypes are present in the +caller's list, filter out the invalid ones and only error if no +enctypes remain. + +ticket: 8819 +(cherry picked from commit 37ab7ea128a4c2aa2dad65ab9006baded5335bc7) +--- + src/lib/gssapi/krb5/set_allowable_enctypes.c | 29 ++++++++++---------- + 1 file changed, 14 insertions(+), 15 deletions(-) + +diff --git a/src/lib/gssapi/krb5/set_allowable_enctypes.c b/src/lib/gssapi/krb5/set_allowable_enctypes.c +index d9fd279ed..a74b161cb 100644 +--- a/src/lib/gssapi/krb5/set_allowable_enctypes.c ++++ b/src/lib/gssapi/krb5/set_allowable_enctypes.c +@@ -66,7 +66,7 @@ gss_krb5int_set_allowable_enctypes(OM_uint32 *minor_status, + const gss_OID desired_oid, + const gss_buffer_t value) + { +- unsigned int i; ++ unsigned int i, j; + krb5_enctype * new_ktypes; + OM_uint32 major_status; + krb5_gss_cred_id_t cred; +@@ -83,14 +83,7 @@ gss_krb5int_set_allowable_enctypes(OM_uint32 *minor_status, + /* verify and valildate cred handle */ + cred = (krb5_gss_cred_id_t) *cred_handle; + +- if (req->ktypes) { +- for (i = 0; i < req->num_ktypes && req->ktypes[i]; i++) { +- if (!krb5_c_valid_enctype(req->ktypes[i])) { +- kerr = KRB5_PROG_ETYPE_NOSUPP; +- goto error_out; +- } +- } +- } else { ++ if (req->ktypes == NULL) { + k5_mutex_lock(&cred->lock); + if (cred->req_enctypes) + free(cred->req_enctypes); +@@ -99,13 +92,19 @@ gss_krb5int_set_allowable_enctypes(OM_uint32 *minor_status, + return GSS_S_COMPLETE; + } + +- /* Copy the requested ktypes into the cred structure */ +- if ((new_ktypes = (krb5_enctype *)malloc(sizeof(krb5_enctype) * (i + 1)))) { +- memcpy(new_ktypes, req->ktypes, sizeof(krb5_enctype) * i); +- new_ktypes[i] = 0; /* "null-terminate" the list */ ++ /* Copy the requested enctypes into the cred structure. Filter out the ++ * ones we don't consider valid. Error out if no enctypes are valid. */ ++ new_ktypes = k5calloc(req->num_ktypes + 1, sizeof(*new_ktypes), &kerr); ++ if (new_ktypes == NULL) ++ goto error_out; ++ for (i = 0, j = 0; i < req->num_ktypes && req->ktypes[i]; i++) { ++ if (krb5_c_valid_enctype(req->ktypes[i])) ++ new_ktypes[j++] = req->ktypes[i]; + } +- else { +- kerr = ENOMEM; ++ new_ktypes[j] = 0; ++ if (j == 0) { ++ free(new_ktypes); ++ kerr = KRB5_PROG_ETYPE_NOSUPP; + goto error_out; + } + k5_mutex_lock(&cred->lock); diff --git a/krb5.spec b/krb5.spec index 373bf85..82ac301 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 35%{?dist} +Release: 36%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -112,6 +112,7 @@ Patch149: Remove-PKINIT-draft-9-ASN.1-code-and-types.patch Patch150: Remove-3des-support.patch Patch151: Remove-now-unused-checksum-functions.patch Patch152: Don-t-error-on-invalid-enctypes-in-keytab.patch +Patch153: Filter-enctypes-in-gss_set_allowable_enctypes.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -721,6 +722,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jul 18 2019 Robbie Harwood - 1.17-36 +- Filter enctypes in gss_set_allowable_enctypes() + * Mon Jul 15 2019 Robbie Harwood - 1.17-35 - Don't error on invalid enctypes in keytab - Resolves: #1724380 From 52c0e4ab88e1d4b71dc46b1b15e59cd010f6578e Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 25 Jul 2019 12:06:52 +0000 Subject: [PATCH 122/304] - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 82ac301..fd0e7fe 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 36%{?dist} +Release: 37%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -722,6 +722,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jul 25 2019 Fedora Release Engineering - 1.17-37 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild + * Thu Jul 18 2019 Robbie Harwood - 1.17-36 - Filter enctypes in gss_set_allowable_enctypes() From f4c04f8cde82e1216cdceed89b01944dc5502da8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 30 Jul 2019 08:56:06 -0400 Subject: [PATCH 123/304] Add soft-pkcs11 and use it for testing --- Add-soft-pkcs11-source-code.patch | 2071 +++++++++++++++++ ...ity-defects-in-soft-pkcs11-test-code.patch | 206 ++ Use-imported-soft-pkcs11-for-tests.patch | 471 ++++ krb5.spec | 8 +- 4 files changed, 2755 insertions(+), 1 deletion(-) create mode 100644 Add-soft-pkcs11-source-code.patch create mode 100644 Fix-Coverity-defects-in-soft-pkcs11-test-code.patch create mode 100644 Use-imported-soft-pkcs11-for-tests.patch diff --git a/Add-soft-pkcs11-source-code.patch b/Add-soft-pkcs11-source-code.patch new file mode 100644 index 0000000..9779459 --- /dev/null +++ b/Add-soft-pkcs11-source-code.patch @@ -0,0 +1,2071 @@ +From a8b987b3730214d568cc51ddc1b218677b17b799 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 20 Jun 2019 10:45:18 -0400 +Subject: [PATCH] Add soft-pkcs11 source code + +soft-pkcs11 is no longer available upstream and is not generally +packaged in distributions, making it inconvenient to use for tests. +Import the 1.8 source code, detabified and with trailing whitespace +removed but otherwise unmodified. + +(cherry picked from commit a4bc3e513a58b0d1292f3506ac3b35be8c178086) +--- + src/tests/softpkcs11/main.c | 2049 +++++++++++++++++++++++++++++++++++ + 1 file changed, 2049 insertions(+) + create mode 100644 src/tests/softpkcs11/main.c + +diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c +new file mode 100644 +index 000000000..2acec5169 +--- /dev/null ++++ b/src/tests/softpkcs11/main.c +@@ -0,0 +1,2049 @@ ++/* ++ * Copyright (c) 2004-2006, Stockholms universitet ++ * (Stockholm University, Stockholm Sweden) ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * 1. Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * 2. Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in the ++ * documentation and/or other materials provided with the distribution. ++ * ++ * 3. Neither the name of the university nor the names of its contributors ++ * may be used to endorse or promote products derived from this software ++ * without specific prior written permission. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" ++ * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE ++ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ++ * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE ++ * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR ++ * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF ++ * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS ++ * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN ++ * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE ++ * POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#include "locl.h" ++ ++/* RCSID("$Id: main.c,v 1.24 2006/01/11 12:42:53 lha Exp $"); */ ++ ++#define OBJECT_ID_MASK 0xfff ++#define HANDLE_OBJECT_ID(h) ((h) & OBJECT_ID_MASK) ++#define OBJECT_ID(obj) HANDLE_OBJECT_ID((obj)->object_handle) ++ ++struct st_attr { ++ CK_ATTRIBUTE attribute; ++ int secret; ++}; ++ ++struct st_object { ++ CK_OBJECT_HANDLE object_handle; ++ struct st_attr *attrs; ++ int num_attributes; ++ enum { ++ STO_T_CERTIFICATE, ++ STO_T_PRIVATE_KEY, ++ STO_T_PUBLIC_KEY ++ } type; ++ union { ++ X509 *cert; ++ EVP_PKEY *public_key; ++ struct { ++ const char *file; ++ EVP_PKEY *key; ++ X509 *cert; ++ } private_key; ++ } u; ++}; ++ ++static struct soft_token { ++ CK_VOID_PTR application; ++ CK_NOTIFY notify; ++ struct { ++ struct st_object **objs; ++ int num_objs; ++ } object; ++ struct { ++ int hardware_slot; ++ int app_error_fatal; ++ int login_done; ++ } flags; ++ int open_sessions; ++ struct session_state { ++ CK_SESSION_HANDLE session_handle; ++ ++ struct { ++ CK_ATTRIBUTE *attributes; ++ CK_ULONG num_attributes; ++ int next_object; ++ } find; ++ ++ int encrypt_object; ++ CK_MECHANISM_PTR encrypt_mechanism; ++ int decrypt_object; ++ CK_MECHANISM_PTR decrypt_mechanism; ++ int sign_object; ++ CK_MECHANISM_PTR sign_mechanism; ++ int verify_object; ++ CK_MECHANISM_PTR verify_mechanism; ++ int digest_object; ++ } state[10]; ++#define MAX_NUM_SESSION (sizeof(soft_token.state)/sizeof(soft_token.state[0])) ++ FILE *logfile; ++} soft_token; ++ ++static void ++application_error(const char *fmt, ...) ++{ ++ va_list ap; ++ va_start(ap, fmt); ++ vprintf(fmt, ap); ++ va_end(ap); ++ if (soft_token.flags.app_error_fatal) ++ abort(); ++} ++ ++static void ++st_logf(const char *fmt, ...) ++{ ++ va_list ap; ++ if (soft_token.logfile == NULL) ++ return; ++ va_start(ap, fmt); ++ vfprintf(soft_token.logfile, fmt, ap); ++ va_end(ap); ++ fflush(soft_token.logfile); ++} ++ ++static void ++snprintf_fill(char *str, size_t size, char fillchar, const char *fmt, ...) ++{ ++ int len; ++ va_list ap; ++ len = vsnprintf(str, size, fmt, ap); ++ va_end(ap); ++ if (len < 0 || len > size) ++ return; ++ while(len < size) ++ str[len++] = fillchar; ++} ++ ++#ifndef TEST_APP ++#define printf error_use_st_logf ++#endif ++ ++#define VERIFY_SESSION_HANDLE(s, state) \ ++{ \ ++ CK_RV ret; \ ++ ret = verify_session_handle(s, state); \ ++ if (ret != CKR_OK) { \ ++ /* return CKR_OK */; \ ++ } \ ++} ++ ++static CK_RV ++verify_session_handle(CK_SESSION_HANDLE hSession, ++ struct session_state **state) ++{ ++ int i; ++ ++ for (i = 0; i < MAX_NUM_SESSION; i++){ ++ if (soft_token.state[i].session_handle == hSession) ++ break; ++ } ++ if (i == MAX_NUM_SESSION) { ++ application_error("use of invalid handle: 0x%08lx\n", ++ (unsigned long)hSession); ++ return CKR_SESSION_HANDLE_INVALID; ++ } ++ if (state) ++ *state = &soft_token.state[i]; ++ return CKR_OK; ++} ++ ++static CK_RV ++object_handle_to_object(CK_OBJECT_HANDLE handle, ++ struct st_object **object) ++{ ++ int i = HANDLE_OBJECT_ID(handle); ++ ++ *object = NULL; ++ if (i >= soft_token.object.num_objs) ++ return CKR_ARGUMENTS_BAD; ++ if (soft_token.object.objs[i] == NULL) ++ return CKR_ARGUMENTS_BAD; ++ if (soft_token.object.objs[i]->object_handle != handle) ++ return CKR_ARGUMENTS_BAD; ++ *object = soft_token.object.objs[i]; ++ return CKR_OK; ++} ++ ++static int ++attributes_match(const struct st_object *obj, ++ const CK_ATTRIBUTE *attributes, ++ CK_ULONG num_attributes) ++{ ++ CK_ULONG i; ++ int j; ++ st_logf("attributes_match: %ld\n", (unsigned long)OBJECT_ID(obj)); ++ ++ for (i = 0; i < num_attributes; i++) { ++ int match = 0; ++ for (j = 0; j < obj->num_attributes; j++) { ++ if (attributes[i].type == obj->attrs[j].attribute.type && ++ attributes[i].ulValueLen == obj->attrs[j].attribute.ulValueLen && ++ memcmp(attributes[i].pValue, obj->attrs[j].attribute.pValue, ++ attributes[i].ulValueLen) == 0) { ++ match = 1; ++ break; ++ } ++ } ++ if (match == 0) { ++ st_logf("type %d attribute have no match\n", attributes[i].type); ++ return 0; ++ } ++ } ++ st_logf("attribute matches\n"); ++ return 1; ++} ++ ++static void ++print_attributes(const CK_ATTRIBUTE *attributes, ++ CK_ULONG num_attributes) ++{ ++ CK_ULONG i; ++ ++ st_logf("find objects: attrs: %lu\n", (unsigned long)num_attributes); ++ ++ for (i = 0; i < num_attributes; i++) { ++ st_logf(" type: "); ++ switch (attributes[i].type) { ++ case CKA_TOKEN: { ++ CK_BBOOL *ck_true; ++ if (attributes[i].ulValueLen != sizeof(CK_BBOOL)) { ++ application_error("token attribute wrong length\n"); ++ break; ++ } ++ ck_true = attributes[i].pValue; ++ st_logf("token: %s", *ck_true ? "TRUE" : "FALSE"); ++ break; ++ } ++ case CKA_CLASS: { ++ CK_OBJECT_CLASS *class; ++ if (attributes[i].ulValueLen != sizeof(CK_ULONG)) { ++ application_error("class attribute wrong length\n"); ++ break; ++ } ++ class = attributes[i].pValue; ++ st_logf("class "); ++ switch (*class) { ++ case CKO_CERTIFICATE: ++ st_logf("certificate"); ++ break; ++ case CKO_PUBLIC_KEY: ++ st_logf("public key"); ++ break; ++ case CKO_PRIVATE_KEY: ++ st_logf("private key"); ++ break; ++ case CKO_SECRET_KEY: ++ st_logf("secret key"); ++ break; ++ case CKO_DOMAIN_PARAMETERS: ++ st_logf("domain parameters"); ++ break; ++ default: ++ st_logf("[class %lx]", (long unsigned)*class); ++ break; ++ } ++ break; ++ } ++ case CKA_PRIVATE: ++ st_logf("private"); ++ break; ++ case CKA_LABEL: ++ st_logf("label"); ++ break; ++ case CKA_APPLICATION: ++ st_logf("application"); ++ break; ++ case CKA_VALUE: ++ st_logf("value"); ++ break; ++ case CKA_ID: ++ st_logf("id"); ++ break; ++ default: ++ st_logf("[unknown 0x%08lx]", (unsigned long)attributes[i].type); ++ break; ++ } ++ st_logf("\n"); ++ } ++} ++ ++static struct st_object * ++add_st_object(void) ++{ ++ struct st_object *o, **objs; ++ int i; ++ ++ o = malloc(sizeof(*o)); ++ if (o == NULL) ++ return NULL; ++ memset(o, 0, sizeof(*o)); ++ o->attrs = NULL; ++ o->num_attributes = 0; ++ ++ for (i = 0; i < soft_token.object.num_objs; i++) { ++ if (soft_token.object.objs == NULL) { ++ soft_token.object.objs[i] = o; ++ break; ++ } ++ } ++ if (i == soft_token.object.num_objs) { ++ objs = realloc(soft_token.object.objs, ++ (soft_token.object.num_objs + 1) * sizeof(soft_token.object.objs[0])); ++ if (objs == NULL) { ++ free(o); ++ return NULL; ++ } ++ soft_token.object.objs = objs; ++ soft_token.object.objs[soft_token.object.num_objs++] = o; ++ } ++ soft_token.object.objs[i]->object_handle = ++ (random() & (~OBJECT_ID_MASK)) | i; ++ ++ return o; ++} ++ ++static CK_RV ++add_object_attribute(struct st_object *o, ++ int secret, ++ CK_ATTRIBUTE_TYPE type, ++ CK_VOID_PTR pValue, ++ CK_ULONG ulValueLen) ++{ ++ struct st_attr *a; ++ int i; ++ ++ i = o->num_attributes; ++ a = realloc(o->attrs, (i + 1) * sizeof(o->attrs[0])); ++ if (a == NULL) ++ return CKR_DEVICE_MEMORY; ++ o->attrs = a; ++ o->attrs[i].secret = secret; ++ o->attrs[i].attribute.type = type; ++ o->attrs[i].attribute.pValue = malloc(ulValueLen); ++ if (o->attrs[i].attribute.pValue == NULL && ulValueLen != 0) ++ return CKR_DEVICE_MEMORY; ++ memcpy(o->attrs[i].attribute.pValue, pValue, ulValueLen); ++ o->attrs[i].attribute.ulValueLen = ulValueLen; ++ o->num_attributes++; ++ ++ return CKR_OK; ++} ++ ++static CK_RV ++add_pubkey_info(struct st_object *o, CK_KEY_TYPE key_type, EVP_PKEY *key) ++{ ++ switch (key_type) { ++ case CKK_RSA: { ++ CK_BYTE *modulus = NULL; ++ size_t modulus_len = 0; ++ CK_ULONG modulus_bits = 0; ++ CK_BYTE *exponent = NULL; ++ size_t exponent_len = 0; ++ ++ modulus_bits = BN_num_bits(key->pkey.rsa->n); ++ ++ modulus_len = BN_num_bytes(key->pkey.rsa->n); ++ modulus = malloc(modulus_len); ++ BN_bn2bin(key->pkey.rsa->n, modulus); ++ ++ exponent_len = BN_num_bytes(key->pkey.rsa->e); ++ exponent = malloc(exponent_len); ++ BN_bn2bin(key->pkey.rsa->e, exponent); ++ ++ add_object_attribute(o, 0, CKA_MODULUS, modulus, modulus_len); ++ add_object_attribute(o, 0, CKA_MODULUS_BITS, ++ &modulus_bits, sizeof(modulus_bits)); ++ add_object_attribute(o, 0, CKA_PUBLIC_EXPONENT, ++ exponent, exponent_len); ++ ++ RSA_set_method(key->pkey.rsa, RSA_PKCS1_SSLeay()); ++ ++ free(modulus); ++ free(exponent); ++ } ++ default: ++ /* XXX */ ++ break; ++ } ++ return CKR_OK; ++} ++ ++ ++static int ++pem_callback(char *buf, int num, int w, void *key) ++{ ++ return -1; ++} ++ ++ ++static CK_RV ++add_certificate(char *label, ++ const char *cert_file, ++ const char *private_key_file, ++ char *id, ++ int anchor) ++{ ++ struct st_object *o = NULL; ++ CK_BBOOL bool_true = CK_TRUE; ++ CK_BBOOL bool_false = CK_FALSE; ++ CK_OBJECT_CLASS c; ++ CK_CERTIFICATE_TYPE cert_type = CKC_X_509; ++ CK_KEY_TYPE key_type; ++ CK_MECHANISM_TYPE mech_type; ++ void *cert_data = NULL; ++ size_t cert_length; ++ void *subject_data = NULL; ++ size_t subject_length; ++ void *issuer_data = NULL; ++ size_t issuer_length; ++ void *serial_data = NULL; ++ size_t serial_length; ++ CK_RV ret = CKR_GENERAL_ERROR; ++ X509 *cert; ++ EVP_PKEY *public_key; ++ ++ size_t id_len = strlen(id); ++ ++ { ++ FILE *f; ++ ++ f = fopen(cert_file, "r"); ++ if (f == NULL) { ++ st_logf("failed to open file %s\n", cert_file); ++ return CKR_GENERAL_ERROR; ++ } ++ ++ cert = PEM_read_X509(f, NULL, NULL, NULL); ++ fclose(f); ++ if (cert == NULL) { ++ st_logf("failed reading PEM cert\n"); ++ return CKR_GENERAL_ERROR; ++ } ++ ++ OPENSSL_ASN1_MALLOC_ENCODE(X509, cert_data, cert_length, cert, ret); ++ if (ret) ++ goto out; ++ ++ OPENSSL_ASN1_MALLOC_ENCODE(X509_NAME, issuer_data, issuer_length, ++ X509_get_issuer_name(cert), ret); ++ if (ret) ++ goto out; ++ ++ OPENSSL_ASN1_MALLOC_ENCODE(X509_NAME, subject_data, subject_length, ++ X509_get_subject_name(cert), ret); ++ if (ret) ++ goto out; ++ ++ OPENSSL_ASN1_MALLOC_ENCODE(ASN1_INTEGER, serial_data, serial_length, ++ X509_get_serialNumber(cert), ret); ++ if (ret) ++ goto out; ++ ++ } ++ ++ st_logf("done parsing, adding to internal structure\n"); ++ ++ o = add_st_object(); ++ if (o == NULL) { ++ ret = CKR_DEVICE_MEMORY; ++ goto out; ++ } ++ o->type = STO_T_CERTIFICATE; ++ o->u.cert = cert; ++ public_key = X509_get_pubkey(o->u.cert); ++ ++ switch (EVP_PKEY_type(public_key->type)) { ++ case EVP_PKEY_RSA: ++ key_type = CKK_RSA; ++ break; ++ case EVP_PKEY_DSA: ++ key_type = CKK_DSA; ++ break; ++ default: ++ /* XXX */ ++ break; ++ } ++ ++ c = CKO_CERTIFICATE; ++ add_object_attribute(o, 0, CKA_CLASS, &c, sizeof(c)); ++ add_object_attribute(o, 0, CKA_TOKEN, &bool_true, sizeof(bool_true)); ++ add_object_attribute(o, 0, CKA_PRIVATE, &bool_false, sizeof(bool_false)); ++ add_object_attribute(o, 0, CKA_MODIFIABLE, &bool_false, sizeof(bool_false)); ++ add_object_attribute(o, 0, CKA_LABEL, label, strlen(label)); ++ ++ add_object_attribute(o, 0, CKA_CERTIFICATE_TYPE, &cert_type, sizeof(cert_type)); ++ add_object_attribute(o, 0, CKA_ID, id, id_len); ++ ++ add_object_attribute(o, 0, CKA_SUBJECT, subject_data, subject_length); ++ add_object_attribute(o, 0, CKA_ISSUER, issuer_data, issuer_length); ++ add_object_attribute(o, 0, CKA_SERIAL_NUMBER, serial_data, serial_length); ++ add_object_attribute(o, 0, CKA_VALUE, cert_data, cert_length); ++ if (anchor) ++ add_object_attribute(o, 0, CKA_TRUSTED, &bool_true, sizeof(bool_true)); ++ else ++ add_object_attribute(o, 0, CKA_TRUSTED, &bool_false, sizeof(bool_false)); ++ ++ st_logf("add cert ok: %lx\n", (unsigned long)OBJECT_ID(o)); ++ ++ o = add_st_object(); ++ if (o == NULL) { ++ ret = CKR_DEVICE_MEMORY; ++ goto out; ++ } ++ o->type = STO_T_PUBLIC_KEY; ++ o->u.public_key = public_key; ++ ++ c = CKO_PUBLIC_KEY; ++ add_object_attribute(o, 0, CKA_CLASS, &c, sizeof(c)); ++ add_object_attribute(o, 0, CKA_TOKEN, &bool_true, sizeof(bool_true)); ++ add_object_attribute(o, 0, CKA_PRIVATE, &bool_false, sizeof(bool_false)); ++ add_object_attribute(o, 0, CKA_MODIFIABLE, &bool_false, sizeof(bool_false)); ++ add_object_attribute(o, 0, CKA_LABEL, label, strlen(label)); ++ ++ add_object_attribute(o, 0, CKA_KEY_TYPE, &key_type, sizeof(key_type)); ++ add_object_attribute(o, 0, CKA_ID, id, id_len); ++ add_object_attribute(o, 0, CKA_START_DATE, "", 1); /* XXX */ ++ add_object_attribute(o, 0, CKA_END_DATE, "", 1); /* XXX */ ++ add_object_attribute(o, 0, CKA_DERIVE, &bool_false, sizeof(bool_false)); ++ add_object_attribute(o, 0, CKA_LOCAL, &bool_false, sizeof(bool_false)); ++ mech_type = CKM_RSA_X_509; ++ add_object_attribute(o, 0, CKA_KEY_GEN_MECHANISM, &mech_type, sizeof(mech_type)); ++ ++ add_object_attribute(o, 0, CKA_SUBJECT, subject_data, subject_length); ++ add_object_attribute(o, 0, CKA_ENCRYPT, &bool_true, sizeof(bool_true)); ++ add_object_attribute(o, 0, CKA_VERIFY, &bool_true, sizeof(bool_true)); ++ add_object_attribute(o, 0, CKA_VERIFY_RECOVER, &bool_false, sizeof(bool_false)); ++ add_object_attribute(o, 0, CKA_WRAP, &bool_true, sizeof(bool_true)); ++ add_object_attribute(o, 0, CKA_TRUSTED, &bool_true, sizeof(bool_true)); ++ ++ add_pubkey_info(o, key_type, public_key); ++ ++ st_logf("add key ok: %lx\n", (unsigned long)OBJECT_ID(o)); ++ ++ if (private_key_file) { ++ CK_FLAGS flags; ++ FILE *f; ++ ++ o = add_st_object(); ++ if (o == NULL) { ++ ret = CKR_DEVICE_MEMORY; ++ goto out; ++ } ++ o->type = STO_T_PRIVATE_KEY; ++ o->u.private_key.file = strdup(private_key_file); ++ o->u.private_key.key = NULL; ++ ++ o->u.private_key.cert = cert; ++ ++ c = CKO_PRIVATE_KEY; ++ add_object_attribute(o, 0, CKA_CLASS, &c, sizeof(c)); ++ add_object_attribute(o, 0, CKA_TOKEN, &bool_true, sizeof(bool_true)); ++ add_object_attribute(o, 0, CKA_PRIVATE, &bool_true, sizeof(bool_false)); ++ add_object_attribute(o, 0, CKA_MODIFIABLE, &bool_false, sizeof(bool_false)); ++ add_object_attribute(o, 0, CKA_LABEL, label, strlen(label)); ++ ++ add_object_attribute(o, 0, CKA_KEY_TYPE, &key_type, sizeof(key_type)); ++ add_object_attribute(o, 0, CKA_ID, id, id_len); ++ add_object_attribute(o, 0, CKA_START_DATE, "", 1); /* XXX */ ++ add_object_attribute(o, 0, CKA_END_DATE, "", 1); /* XXX */ ++ add_object_attribute(o, 0, CKA_DERIVE, &bool_false, sizeof(bool_false)); ++ add_object_attribute(o, 0, CKA_LOCAL, &bool_false, sizeof(bool_false)); ++ mech_type = CKM_RSA_X_509; ++ add_object_attribute(o, 0, CKA_KEY_GEN_MECHANISM, &mech_type, sizeof(mech_type)); ++ ++ add_object_attribute(o, 0, CKA_SUBJECT, subject_data, subject_length); ++ add_object_attribute(o, 0, CKA_SENSITIVE, &bool_true, sizeof(bool_true)); ++ add_object_attribute(o, 0, CKA_SECONDARY_AUTH, &bool_false, sizeof(bool_true)); ++ flags = 0; ++ add_object_attribute(o, 0, CKA_AUTH_PIN_FLAGS, &flags, sizeof(flags)); ++ ++ add_object_attribute(o, 0, CKA_DECRYPT, &bool_true, sizeof(bool_true)); ++ add_object_attribute(o, 0, CKA_SIGN, &bool_true, sizeof(bool_true)); ++ add_object_attribute(o, 0, CKA_SIGN_RECOVER, &bool_false, sizeof(bool_false)); ++ add_object_attribute(o, 0, CKA_UNWRAP, &bool_true, sizeof(bool_true)); ++ add_object_attribute(o, 0, CKA_EXTRACTABLE, &bool_true, sizeof(bool_true)); ++ add_object_attribute(o, 0, CKA_NEVER_EXTRACTABLE, &bool_false, sizeof(bool_false)); ++ ++ add_pubkey_info(o, key_type, public_key); ++ ++ f = fopen(private_key_file, "r"); ++ if (f == NULL) { ++ st_logf("failed to open private key\n"); ++ return CKR_GENERAL_ERROR; ++ } ++ ++ o->u.private_key.key = PEM_read_PrivateKey(f, NULL, pem_callback, NULL); ++ fclose(f); ++ if (o->u.private_key.key == NULL) { ++ st_logf("failed to read private key a startup\n"); ++ /* don't bother with this failure for now, ++ fix it at C_Login time */; ++ } else { ++ /* XXX verify keytype */ ++ ++ if (key_type == CKK_RSA) ++ RSA_set_method(o->u.private_key.key->pkey.rsa, ++ RSA_PKCS1_SSLeay()); ++ ++ if (X509_check_private_key(cert, o->u.private_key.key) != 1) { ++ EVP_PKEY_free(o->u.private_key.key); ++ o->u.private_key.key = NULL; ++ st_logf("private key doesn't verify\n"); ++ } else { ++ st_logf("private key usable\n"); ++ soft_token.flags.login_done = 1; ++ } ++ } ++ } ++ ++ ret = CKR_OK; ++ out: ++ if (ret != CKR_OK) { ++ st_logf("something went wrong when adding cert!\n"); ++ ++ /* XXX wack o */; ++ } ++ free(cert_data); ++ free(serial_data); ++ free(issuer_data); ++ free(subject_data); ++ ++ return ret; ++} ++ ++static void ++find_object_final(struct session_state *state) ++{ ++ if (state->find.attributes) { ++ CK_ULONG i; ++ ++ for (i = 0; i < state->find.num_attributes; i++) { ++ if (state->find.attributes[i].pValue) ++ free(state->find.attributes[i].pValue); ++ } ++ free(state->find.attributes); ++ state->find.attributes = NULL; ++ state->find.num_attributes = 0; ++ state->find.next_object = -1; ++ } ++} ++ ++static void ++reset_crypto_state(struct session_state *state) ++{ ++ state->encrypt_object = -1; ++ if (state->encrypt_mechanism) ++ free(state->encrypt_mechanism); ++ state->encrypt_mechanism = NULL_PTR; ++ state->decrypt_object = -1; ++ if (state->decrypt_mechanism) ++ free(state->decrypt_mechanism); ++ state->decrypt_mechanism = NULL_PTR; ++ state->sign_object = -1; ++ if (state->sign_mechanism) ++ free(state->sign_mechanism); ++ state->sign_mechanism = NULL_PTR; ++ state->verify_object = -1; ++ if (state->verify_mechanism) ++ free(state->verify_mechanism); ++ state->verify_mechanism = NULL_PTR; ++ state->digest_object = -1; ++} ++ ++static void ++close_session(struct session_state *state) ++{ ++ if (state->find.attributes) { ++ application_error("application didn't do C_FindObjectsFinal\n"); ++ find_object_final(state); ++ } ++ ++ state->session_handle = CK_INVALID_HANDLE; ++ soft_token.application = NULL_PTR; ++ soft_token.notify = NULL_PTR; ++ reset_crypto_state(state); ++} ++ ++static const char * ++has_session(void) ++{ ++ return soft_token.open_sessions > 0 ? "yes" : "no"; ++} ++ ++static void ++read_conf_file(const char *fn) ++{ ++ char buf[1024], *cert, *key, *id, *label, *s, *p; ++ int anchor; ++ FILE *f; ++ ++ f = fopen(fn, "r"); ++ if (f == NULL) { ++ st_logf("can't open configuration file %s\n", fn); ++ return; ++ } ++ ++ while(fgets(buf, sizeof(buf), f) != NULL) { ++ buf[strcspn(buf, "\n")] = '\0'; ++ ++ anchor = 0; ++ ++ st_logf("line: %s\n", buf); ++ ++ p = buf; ++ while (isspace(*p)) ++ p++; ++ if (*p == '#') ++ continue; ++ while (isspace(*p)) ++ p++; ++ ++ s = NULL; ++ id = strtok_r(p, "\t", &s); ++ if (id == NULL) ++ continue; ++ label = strtok_r(NULL, "\t", &s); ++ if (label == NULL) ++ continue; ++ cert = strtok_r(NULL, "\t", &s); ++ if (cert == NULL) ++ continue; ++ key = strtok_r(NULL, "\t", &s); ++ ++ /* XXX */ ++ if (strcmp(id, "anchor") == 0) { ++ id = "\x00\x00"; ++ anchor = 1; ++ } ++ ++ st_logf("adding: %s\n", label); ++ ++ add_certificate(label, cert, key, id, anchor); ++ } ++} ++ ++static CK_RV ++func_not_supported(void) ++{ ++ st_logf("function not supported\n"); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++CK_RV ++C_Initialize(CK_VOID_PTR a) ++{ ++ CK_C_INITIALIZE_ARGS_PTR args = a; ++ st_logf("Initialize\n"); ++ int i; ++ ++ OpenSSL_add_all_algorithms(); ++ ERR_load_crypto_strings(); ++ ++ srandom(getpid() ^ time(NULL)); ++ ++ for (i = 0; i < MAX_NUM_SESSION; i++) { ++ soft_token.state[i].session_handle = CK_INVALID_HANDLE; ++ soft_token.state[i].find.attributes = NULL; ++ soft_token.state[i].find.num_attributes = 0; ++ soft_token.state[i].find.next_object = -1; ++ reset_crypto_state(&soft_token.state[i]); ++ } ++ ++ soft_token.flags.hardware_slot = 1; ++ soft_token.flags.app_error_fatal = 0; ++ soft_token.flags.login_done = 0; ++ ++ soft_token.object.objs = NULL; ++ soft_token.object.num_objs = 0; ++ ++ soft_token.logfile = NULL; ++#if 0 ++ soft_token.logfile = stdout; ++#endif ++#if 0 ++ soft_token.logfile = fopen("/tmp/log-pkcs11.txt", "a"); ++#endif ++ ++ if (a != NULL_PTR) { ++ st_logf("\tCreateMutex:\t%p\n", args->CreateMutex); ++ st_logf("\tDestroyMutext\t%p\n", args->DestroyMutex); ++ st_logf("\tLockMutext\t%p\n", args->LockMutex); ++ st_logf("\tUnlockMutext\t%p\n", args->UnlockMutex); ++ st_logf("\tFlags\t%04x\n", (unsigned int)args->flags); ++ } ++ ++ { ++ char *fn = NULL, *home = NULL; ++ ++ if (getuid() == geteuid()) { ++ fn = getenv("SOFTPKCS11RC"); ++ if (fn) ++ fn = strdup(fn); ++ home = getenv("HOME"); ++ } ++ if (fn == NULL && home == NULL) { ++ struct passwd *pw = getpwuid(getuid()); ++ if(pw != NULL) ++ home = pw->pw_dir; ++ } ++ if (fn == NULL) { ++ if (home) ++ asprintf(&fn, "%s/.soft-token.rc", home); ++ else ++ fn = strdup("/etc/soft-token.rc"); ++ } ++ ++ read_conf_file(fn); ++ free(fn); ++ } ++ ++ return CKR_OK; ++} ++ ++CK_RV ++C_Finalize(CK_VOID_PTR args) ++{ ++ int i; ++ ++ st_logf("Finalize\n"); ++ ++ for (i = 0; i < MAX_NUM_SESSION; i++) { ++ if (soft_token.state[i].session_handle != CK_INVALID_HANDLE) { ++ application_error("application finalized without " ++ "closing session\n"); ++ close_session(&soft_token.state[i]); ++ } ++ } ++ ++ return CKR_OK; ++} ++ ++CK_RV ++C_GetInfo(CK_INFO_PTR args) ++{ ++ st_logf("GetInfo\n"); ++ ++ memset(args, 17, sizeof(*args)); ++ args->cryptokiVersion.major = 2; ++ args->cryptokiVersion.minor = 10; ++ snprintf_fill((char *)args->manufacturerID, ++ sizeof(args->manufacturerID), ++ ' ', ++ "SoftToken"); ++ snprintf_fill((char *)args->libraryDescription, ++ sizeof(args->libraryDescription), ' ', ++ "SoftToken"); ++ args->libraryVersion.major = 1; ++ args->libraryVersion.minor = 8; ++ ++ return CKR_OK; ++} ++ ++extern CK_FUNCTION_LIST funcs; ++ ++CK_RV ++C_GetFunctionList(CK_FUNCTION_LIST_PTR_PTR ppFunctionList) ++{ ++ *ppFunctionList = &funcs; ++ return CKR_OK; ++} ++ ++CK_RV ++C_GetSlotList(CK_BBOOL tokenPresent, ++ CK_SLOT_ID_PTR pSlotList, ++ CK_ULONG_PTR pulCount) ++{ ++ st_logf("GetSlotList: %s\n", ++ tokenPresent ? "tokenPresent" : "token not Present"); ++ if (pSlotList) ++ pSlotList[0] = 1; ++ *pulCount = 1; ++ return CKR_OK; ++} ++ ++CK_RV ++C_GetSlotInfo(CK_SLOT_ID slotID, ++ CK_SLOT_INFO_PTR pInfo) ++{ ++ st_logf("GetSlotInfo: slot: %d : %s\n", (int)slotID, has_session()); ++ ++ memset(pInfo, 18, sizeof(*pInfo)); ++ ++ if (slotID != 1) ++ return CKR_ARGUMENTS_BAD; ++ ++ snprintf_fill((char *)pInfo->slotDescription, ++ sizeof(pInfo->slotDescription), ++ ' ', ++ "SoftToken (slot)"); ++ snprintf_fill((char *)pInfo->manufacturerID, ++ sizeof(pInfo->manufacturerID), ++ ' ', ++ "SoftToken (slot)"); ++ pInfo->flags = CKF_TOKEN_PRESENT; ++ if (soft_token.flags.hardware_slot) ++ pInfo->flags |= CKF_HW_SLOT; ++ pInfo->hardwareVersion.major = 1; ++ pInfo->hardwareVersion.minor = 0; ++ pInfo->firmwareVersion.major = 1; ++ pInfo->firmwareVersion.minor = 0; ++ ++ return CKR_OK; ++} ++ ++CK_RV ++C_GetTokenInfo(CK_SLOT_ID slotID, ++ CK_TOKEN_INFO_PTR pInfo) ++{ ++ st_logf("GetTokenInfo: %s\n", has_session()); ++ ++ memset(pInfo, 19, sizeof(*pInfo)); ++ ++ snprintf_fill((char *)pInfo->label, ++ sizeof(pInfo->label), ++ ' ', ++ "SoftToken (token)"); ++ snprintf_fill((char *)pInfo->manufacturerID, ++ sizeof(pInfo->manufacturerID), ++ ' ', ++ "SoftToken (token)"); ++ snprintf_fill((char *)pInfo->model, ++ sizeof(pInfo->model), ++ ' ', ++ "SoftToken (token)"); ++ snprintf_fill((char *)pInfo->serialNumber, ++ sizeof(pInfo->serialNumber), ++ ' ', ++ "4711"); ++ pInfo->flags = ++ CKF_TOKEN_INITIALIZED | ++ CKF_USER_PIN_INITIALIZED; ++ ++ if (soft_token.flags.login_done == 0) ++ pInfo->flags |= CKF_LOGIN_REQUIRED; ++ ++ /* CFK_RNG | ++ CKF_RESTORE_KEY_NOT_NEEDED | ++ */ ++ pInfo->ulMaxSessionCount = MAX_NUM_SESSION; ++ pInfo->ulSessionCount = soft_token.open_sessions; ++ pInfo->ulMaxRwSessionCount = MAX_NUM_SESSION; ++ pInfo->ulRwSessionCount = soft_token.open_sessions; ++ pInfo->ulMaxPinLen = 1024; ++ pInfo->ulMinPinLen = 0; ++ pInfo->ulTotalPublicMemory = 4711; ++ pInfo->ulFreePublicMemory = 4712; ++ pInfo->ulTotalPrivateMemory = 4713; ++ pInfo->ulFreePrivateMemory = 4714; ++ pInfo->hardwareVersion.major = 2; ++ pInfo->hardwareVersion.minor = 0; ++ pInfo->firmwareVersion.major = 2; ++ pInfo->firmwareVersion.minor = 0; ++ ++ return CKR_OK; ++} ++ ++CK_RV ++C_GetMechanismList(CK_SLOT_ID slotID, ++ CK_MECHANISM_TYPE_PTR pMechanismList, ++ CK_ULONG_PTR pulCount) ++{ ++ st_logf("GetMechanismList\n"); ++ ++ *pulCount = 2; ++ if (pMechanismList == NULL_PTR) ++ return CKR_OK; ++ pMechanismList[0] = CKM_RSA_X_509; ++ pMechanismList[1] = CKM_RSA_PKCS; ++ ++ return CKR_OK; ++} ++ ++CK_RV ++C_GetMechanismInfo(CK_SLOT_ID slotID, ++ CK_MECHANISM_TYPE type, ++ CK_MECHANISM_INFO_PTR pInfo) ++{ ++ st_logf("GetMechanismInfo: slot %d type: %d\n", ++ (int)slotID, (int)type); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++CK_RV ++C_InitToken(CK_SLOT_ID slotID, ++ CK_UTF8CHAR_PTR pPin, ++ CK_ULONG ulPinLen, ++ CK_UTF8CHAR_PTR pLabel) ++{ ++ st_logf("InitToken: slot %d\n", (int)slotID); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++CK_RV ++C_OpenSession(CK_SLOT_ID slotID, ++ CK_FLAGS flags, ++ CK_VOID_PTR pApplication, ++ CK_NOTIFY Notify, ++ CK_SESSION_HANDLE_PTR phSession) ++{ ++ int i; ++ ++ st_logf("OpenSession: slot: %d\n", (int)slotID); ++ ++ if (soft_token.open_sessions == MAX_NUM_SESSION) ++ return CKR_SESSION_COUNT; ++ ++ soft_token.application = pApplication; ++ soft_token.notify = Notify; ++ ++ for (i = 0; i < MAX_NUM_SESSION; i++) ++ if (soft_token.state[i].session_handle == CK_INVALID_HANDLE) ++ break; ++ if (i == MAX_NUM_SESSION) ++ abort(); ++ ++ soft_token.open_sessions++; ++ ++ soft_token.state[i].session_handle = ++ (CK_SESSION_HANDLE)(random() & 0xfffff); ++ *phSession = soft_token.state[i].session_handle; ++ ++ return CKR_OK; ++} ++ ++CK_RV ++C_CloseSession(CK_SESSION_HANDLE hSession) ++{ ++ struct session_state *state; ++ st_logf("CloseSession\n"); ++ ++ if (verify_session_handle(hSession, &state) != CKR_OK) ++ application_error("closed session not open"); ++ else ++ close_session(state); ++ ++ return CKR_OK; ++} ++ ++CK_RV ++C_CloseAllSessions(CK_SLOT_ID slotID) ++{ ++ int i; ++ ++ st_logf("CloseAllSessions\n"); ++ ++ for (i = 0; i < MAX_NUM_SESSION; i++) ++ if (soft_token.state[i].session_handle != CK_INVALID_HANDLE) ++ close_session(&soft_token.state[i]); ++ ++ return CKR_OK; ++} ++ ++CK_RV ++C_GetSessionInfo(CK_SESSION_HANDLE hSession, ++ CK_SESSION_INFO_PTR pInfo) ++{ ++ st_logf("GetSessionInfo\n"); ++ ++ VERIFY_SESSION_HANDLE(hSession, NULL); ++ ++ memset(pInfo, 20, sizeof(*pInfo)); ++ ++ pInfo->slotID = 1; ++ if (soft_token.flags.login_done) ++ pInfo->state = CKS_RO_USER_FUNCTIONS; ++ else ++ pInfo->state = CKS_RO_PUBLIC_SESSION; ++ pInfo->flags = CKF_SERIAL_SESSION; ++ pInfo->ulDeviceError = 0; ++ ++ return CKR_OK; ++} ++ ++CK_RV ++C_Login(CK_SESSION_HANDLE hSession, ++ CK_USER_TYPE userType, ++ CK_UTF8CHAR_PTR pPin, ++ CK_ULONG ulPinLen) ++{ ++ char *pin = NULL; ++ int i; ++ ++ st_logf("Login\n"); ++ ++ VERIFY_SESSION_HANDLE(hSession, NULL); ++ ++ if (pPin != NULL_PTR) { ++ asprintf(&pin, "%.*s", (int)ulPinLen, pPin); ++ st_logf("type: %d password: %s\n", (int)userType, pin); ++ } ++ ++ for (i = 0; i < soft_token.object.num_objs; i++) { ++ struct st_object *o = soft_token.object.objs[i]; ++ FILE *f; ++ ++ if (o->type != STO_T_PRIVATE_KEY) ++ continue; ++ ++ if (o->u.private_key.key) ++ continue; ++ ++ f = fopen(o->u.private_key.file, "r"); ++ if (f == NULL) { ++ st_logf("can't open private file: %s\n", o->u.private_key.file); ++ continue; ++ } ++ ++ o->u.private_key.key = PEM_read_PrivateKey(f, NULL, NULL, pin); ++ fclose(f); ++ if (o->u.private_key.key == NULL) { ++ st_logf("failed to read key: %s error: %s\n", ++ o->u.private_key.file, ++ ERR_error_string(ERR_get_error(), NULL)); ++ /* just ignore failure */; ++ continue; ++ } ++ ++ /* XXX check keytype */ ++ RSA_set_method(o->u.private_key.key->pkey.rsa, RSA_PKCS1_SSLeay()); ++ ++ if (X509_check_private_key(o->u.private_key.cert, o->u.private_key.key) != 1) { ++ EVP_PKEY_free(o->u.private_key.key); ++ o->u.private_key.key = NULL; ++ st_logf("private key %s doesn't verify\n", o->u.private_key.file); ++ continue; ++ } ++ ++ soft_token.flags.login_done = 1; ++ } ++ free(pin); ++ ++ return soft_token.flags.login_done ? CKR_OK : CKR_PIN_INCORRECT; ++} ++ ++CK_RV ++C_Logout(CK_SESSION_HANDLE hSession) ++{ ++ st_logf("Logout\n"); ++ VERIFY_SESSION_HANDLE(hSession, NULL); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++CK_RV ++C_GetObjectSize(CK_SESSION_HANDLE hSession, ++ CK_OBJECT_HANDLE hObject, ++ CK_ULONG_PTR pulSize) ++{ ++ st_logf("GetObjectSize\n"); ++ VERIFY_SESSION_HANDLE(hSession, NULL); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++CK_RV ++C_GetAttributeValue(CK_SESSION_HANDLE hSession, ++ CK_OBJECT_HANDLE hObject, ++ CK_ATTRIBUTE_PTR pTemplate, ++ CK_ULONG ulCount) ++{ ++ struct session_state *state; ++ struct st_object *obj; ++ CK_ULONG i; ++ CK_RV ret; ++ int j; ++ ++ st_logf("GetAttributeValue: %lx\n", ++ (unsigned long)HANDLE_OBJECT_ID(hObject)); ++ VERIFY_SESSION_HANDLE(hSession, &state); ++ ++ if ((ret = object_handle_to_object(hObject, &obj)) != CKR_OK) { ++ st_logf("object not found: %lx\n", ++ (unsigned long)HANDLE_OBJECT_ID(hObject)); ++ return ret; ++ } ++ ++ for (i = 0; i < ulCount; i++) { ++ st_logf(" getting 0x%08lx\n", (unsigned long)pTemplate[i].type); ++ for (j = 0; j < obj->num_attributes; j++) { ++ if (obj->attrs[j].secret) { ++ pTemplate[i].ulValueLen = (CK_ULONG)-1; ++ break; ++ } ++ if (pTemplate[i].type == obj->attrs[j].attribute.type) { ++ if (pTemplate[i].pValue != NULL_PTR && obj->attrs[j].secret == 0) { ++ if (pTemplate[i].ulValueLen >= obj->attrs[j].attribute.ulValueLen) ++ memcpy(pTemplate[i].pValue, obj->attrs[j].attribute.pValue, ++ obj->attrs[j].attribute.ulValueLen); ++ } ++ pTemplate[i].ulValueLen = obj->attrs[j].attribute.ulValueLen; ++ break; ++ } ++ } ++ if (j == obj->num_attributes) { ++ st_logf("key type: 0x%08lx not found\n", (unsigned long)pTemplate[i].type); ++ pTemplate[i].ulValueLen = (CK_ULONG)-1; ++ } ++ ++ } ++ return CKR_OK; ++} ++ ++CK_RV ++C_FindObjectsInit(CK_SESSION_HANDLE hSession, ++ CK_ATTRIBUTE_PTR pTemplate, ++ CK_ULONG ulCount) ++{ ++ struct session_state *state; ++ ++ st_logf("FindObjectsInit\n"); ++ ++ VERIFY_SESSION_HANDLE(hSession, &state); ++ ++ if (state->find.next_object != -1) { ++ application_error("application didn't do C_FindObjectsFinal\n"); ++ find_object_final(state); ++ } ++ if (ulCount) { ++ CK_ULONG i; ++ size_t len; ++ ++ print_attributes(pTemplate, ulCount); ++ ++ state->find.attributes = ++ calloc(1, ulCount * sizeof(state->find.attributes[0])); ++ if (state->find.attributes == NULL) ++ return CKR_DEVICE_MEMORY; ++ for (i = 0; i < ulCount; i++) { ++ state->find.attributes[i].pValue = ++ malloc(pTemplate[i].ulValueLen); ++ if (state->find.attributes[i].pValue == NULL) { ++ find_object_final(state); ++ return CKR_DEVICE_MEMORY; ++ } ++ memcpy(state->find.attributes[i].pValue, ++ pTemplate[i].pValue, pTemplate[i].ulValueLen); ++ state->find.attributes[i].type = pTemplate[i].type; ++ state->find.attributes[i].ulValueLen = pTemplate[i].ulValueLen; ++ } ++ state->find.num_attributes = ulCount; ++ state->find.next_object = 0; ++ } else { ++ st_logf("find all objects\n"); ++ state->find.attributes = NULL; ++ state->find.num_attributes = 0; ++ state->find.next_object = 0; ++ } ++ ++ return CKR_OK; ++} ++ ++CK_RV ++C_FindObjects(CK_SESSION_HANDLE hSession, ++ CK_OBJECT_HANDLE_PTR phObject, ++ CK_ULONG ulMaxObjectCount, ++ CK_ULONG_PTR pulObjectCount) ++{ ++ struct session_state *state; ++ int i; ++ ++ st_logf("FindObjects\n"); ++ ++ VERIFY_SESSION_HANDLE(hSession, &state); ++ ++ if (state->find.next_object == -1) { ++ application_error("application didn't do C_FindObjectsInit\n"); ++ return CKR_ARGUMENTS_BAD; ++ } ++ if (ulMaxObjectCount == 0) { ++ application_error("application asked for 0 objects\n"); ++ return CKR_ARGUMENTS_BAD; ++ } ++ *pulObjectCount = 0; ++ for (i = state->find.next_object; i < soft_token.object.num_objs; i++) { ++ st_logf("FindObjects: %d\n", i); ++ state->find.next_object = i + 1; ++ if (attributes_match(soft_token.object.objs[i], ++ state->find.attributes, ++ state->find.num_attributes)) { ++ *phObject++ = soft_token.object.objs[i]->object_handle; ++ ulMaxObjectCount--; ++ (*pulObjectCount)++; ++ if (ulMaxObjectCount == 0) ++ break; ++ } ++ } ++ return CKR_OK; ++} ++ ++CK_RV ++C_FindObjectsFinal(CK_SESSION_HANDLE hSession) ++{ ++ struct session_state *state; ++ ++ st_logf("FindObjectsFinal\n"); ++ VERIFY_SESSION_HANDLE(hSession, &state); ++ find_object_final(state); ++ return CKR_OK; ++} ++ ++static CK_RV ++commonInit(CK_ATTRIBUTE *attr_match, int attr_match_len, ++ const CK_MECHANISM_TYPE *mechs, int mechs_len, ++ const CK_MECHANISM_PTR pMechanism, CK_OBJECT_HANDLE hKey, ++ struct st_object **o) ++{ ++ CK_RV ret; ++ int i; ++ ++ *o = NULL; ++ if ((ret = object_handle_to_object(hKey, o)) != CKR_OK) ++ return ret; ++ ++ ret = attributes_match(*o, attr_match, attr_match_len); ++ if (!ret) { ++ application_error("called commonInit on key that doesn't " ++ "support required attr"); ++ return CKR_ARGUMENTS_BAD; ++ } ++ ++ for (i = 0; i < mechs_len; i++) ++ if (mechs[i] == pMechanism->mechanism) ++ break; ++ if (i == mechs_len) { ++ application_error("called mech (%08lx) not supported\n", ++ pMechanism->mechanism); ++ return CKR_ARGUMENTS_BAD; ++ } ++ return CKR_OK; ++} ++ ++ ++static CK_RV ++dup_mechanism(CK_MECHANISM_PTR *dup, const CK_MECHANISM_PTR pMechanism) ++{ ++ CK_MECHANISM_PTR p; ++ ++ p = malloc(sizeof(*p)); ++ if (p == NULL) ++ return CKR_DEVICE_MEMORY; ++ ++ if (*dup) ++ free(*dup); ++ *dup = p; ++ memcpy(p, pMechanism, sizeof(*p)); ++ ++ return CKR_OK; ++} ++ ++ ++CK_RV ++C_EncryptInit(CK_SESSION_HANDLE hSession, ++ CK_MECHANISM_PTR pMechanism, ++ CK_OBJECT_HANDLE hKey) ++{ ++ struct session_state *state; ++ CK_MECHANISM_TYPE mechs[] = { CKM_RSA_PKCS, CKM_RSA_X_509 }; ++ CK_BBOOL bool_true = CK_TRUE; ++ CK_ATTRIBUTE attr[] = { ++ { CKA_ENCRYPT, &bool_true, sizeof(bool_true) } ++ }; ++ struct st_object *o; ++ CK_RV ret; ++ ++ st_logf("EncryptInit\n"); ++ VERIFY_SESSION_HANDLE(hSession, &state); ++ ++ ret = commonInit(attr, sizeof(attr)/sizeof(attr[0]), ++ mechs, sizeof(mechs)/sizeof(mechs[0]), ++ pMechanism, hKey, &o); ++ if (ret) ++ return ret; ++ ++ ret = dup_mechanism(&state->encrypt_mechanism, pMechanism); ++ if (ret == CKR_OK) ++ state->encrypt_object = OBJECT_ID(o); ++ ++ return ret; ++} ++ ++CK_RV ++C_Encrypt(CK_SESSION_HANDLE hSession, ++ CK_BYTE_PTR pData, ++ CK_ULONG ulDataLen, ++ CK_BYTE_PTR pEncryptedData, ++ CK_ULONG_PTR pulEncryptedDataLen) ++{ ++ struct session_state *state; ++ struct st_object *o; ++ void *buffer = NULL; ++ CK_RV ret; ++ RSA *rsa; ++ int padding, len, buffer_len, padding_len; ++ ++ st_logf("Encrypt\n"); ++ ++ VERIFY_SESSION_HANDLE(hSession, &state); ++ ++ if (state->encrypt_object == -1) ++ return CKR_ARGUMENTS_BAD; ++ ++ o = soft_token.object.objs[state->encrypt_object]; ++ ++ if (o->u.public_key == NULL) { ++ st_logf("public key NULL\n"); ++ return CKR_ARGUMENTS_BAD; ++ } ++ ++ rsa = o->u.public_key->pkey.rsa; ++ ++ if (rsa == NULL) ++ return CKR_ARGUMENTS_BAD; ++ ++ RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ ++ ++ buffer_len = RSA_size(rsa); ++ ++ buffer = malloc(buffer_len); ++ if (buffer == NULL) { ++ ret = CKR_DEVICE_MEMORY; ++ goto out; ++ } ++ ++ ret = CKR_OK; ++ switch(state->encrypt_mechanism->mechanism) { ++ case CKM_RSA_PKCS: ++ padding = RSA_PKCS1_PADDING; ++ padding_len = RSA_PKCS1_PADDING_SIZE; ++ break; ++ case CKM_RSA_X_509: ++ padding = RSA_NO_PADDING; ++ padding_len = 0; ++ break; ++ default: ++ ret = CKR_FUNCTION_NOT_SUPPORTED; ++ goto out; ++ } ++ ++ if (buffer_len + padding_len < ulDataLen) { ++ ret = CKR_ARGUMENTS_BAD; ++ goto out; ++ } ++ ++ if (pulEncryptedDataLen == NULL) { ++ st_logf("pulEncryptedDataLen NULL\n"); ++ ret = CKR_ARGUMENTS_BAD; ++ goto out; ++ } ++ ++ if (pData == NULL_PTR) { ++ st_logf("data NULL\n"); ++ ret = CKR_ARGUMENTS_BAD; ++ goto out; ++ } ++ ++ len = RSA_public_encrypt(ulDataLen, pData, buffer, rsa, padding); ++ if (len <= 0) { ++ ret = CKR_DEVICE_ERROR; ++ goto out; ++ } ++ if (len > buffer_len) ++ abort(); ++ ++ if (pEncryptedData != NULL_PTR) ++ memcpy(pEncryptedData, buffer, len); ++ *pulEncryptedDataLen = len; ++ ++ out: ++ if (buffer) { ++ memset(buffer, 0, buffer_len); ++ free(buffer); ++ } ++ return ret; ++} ++ ++CK_RV ++C_EncryptUpdate(CK_SESSION_HANDLE hSession, ++ CK_BYTE_PTR pPart, ++ CK_ULONG ulPartLen, ++ CK_BYTE_PTR pEncryptedPart, ++ CK_ULONG_PTR pulEncryptedPartLen) ++{ ++ st_logf("EncryptUpdate\n"); ++ VERIFY_SESSION_HANDLE(hSession, NULL); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++ ++CK_RV ++C_EncryptFinal(CK_SESSION_HANDLE hSession, ++ CK_BYTE_PTR pLastEncryptedPart, ++ CK_ULONG_PTR pulLastEncryptedPartLen) ++{ ++ st_logf("EncryptFinal\n"); ++ VERIFY_SESSION_HANDLE(hSession, NULL); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++ ++/* C_DecryptInit initializes a decryption operation. */ ++CK_RV ++C_DecryptInit(CK_SESSION_HANDLE hSession, ++ CK_MECHANISM_PTR pMechanism, ++ CK_OBJECT_HANDLE hKey) ++{ ++ struct session_state *state; ++ CK_MECHANISM_TYPE mechs[] = { CKM_RSA_PKCS, CKM_RSA_X_509 }; ++ CK_BBOOL bool_true = CK_TRUE; ++ CK_ATTRIBUTE attr[] = { ++ { CKA_DECRYPT, &bool_true, sizeof(bool_true) } ++ }; ++ struct st_object *o; ++ CK_RV ret; ++ ++ st_logf("DecryptInit\n"); ++ VERIFY_SESSION_HANDLE(hSession, &state); ++ ++ ret = commonInit(attr, sizeof(attr)/sizeof(attr[0]), ++ mechs, sizeof(mechs)/sizeof(mechs[0]), ++ pMechanism, hKey, &o); ++ if (ret) ++ return ret; ++ ++ ret = dup_mechanism(&state->decrypt_mechanism, pMechanism); ++ if (ret == CKR_OK) ++ state->decrypt_object = OBJECT_ID(o); ++ ++ return CKR_OK; ++} ++ ++ ++CK_RV ++C_Decrypt(CK_SESSION_HANDLE hSession, ++ CK_BYTE_PTR pEncryptedData, ++ CK_ULONG ulEncryptedDataLen, ++ CK_BYTE_PTR pData, ++ CK_ULONG_PTR pulDataLen) ++{ ++ struct session_state *state; ++ struct st_object *o; ++ void *buffer = NULL; ++ CK_RV ret; ++ RSA *rsa; ++ int padding, len, buffer_len, padding_len; ++ ++ st_logf("Decrypt\n"); ++ ++ VERIFY_SESSION_HANDLE(hSession, &state); ++ ++ if (state->decrypt_object == -1) ++ return CKR_ARGUMENTS_BAD; ++ ++ o = soft_token.object.objs[state->decrypt_object]; ++ ++ if (o->u.private_key.key == NULL) { ++ st_logf("private key NULL\n"); ++ return CKR_ARGUMENTS_BAD; ++ } ++ ++ rsa = o->u.private_key.key->pkey.rsa; ++ ++ if (rsa == NULL) ++ return CKR_ARGUMENTS_BAD; ++ ++ RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ ++ ++ buffer_len = RSA_size(rsa); ++ ++ buffer = malloc(buffer_len); ++ if (buffer == NULL) { ++ ret = CKR_DEVICE_MEMORY; ++ goto out; ++ } ++ ++ ret = CKR_OK; ++ switch(state->decrypt_mechanism->mechanism) { ++ case CKM_RSA_PKCS: ++ padding = RSA_PKCS1_PADDING; ++ padding_len = RSA_PKCS1_PADDING_SIZE; ++ break; ++ case CKM_RSA_X_509: ++ padding = RSA_NO_PADDING; ++ padding_len = 0; ++ break; ++ default: ++ ret = CKR_FUNCTION_NOT_SUPPORTED; ++ goto out; ++ } ++ ++ if (buffer_len + padding_len < ulEncryptedDataLen) { ++ ret = CKR_ARGUMENTS_BAD; ++ goto out; ++ } ++ ++ if (pulDataLen == NULL) { ++ st_logf("pulDataLen NULL\n"); ++ ret = CKR_ARGUMENTS_BAD; ++ goto out; ++ } ++ ++ if (pEncryptedData == NULL_PTR) { ++ st_logf("data NULL\n"); ++ ret = CKR_ARGUMENTS_BAD; ++ goto out; ++ } ++ ++ len = RSA_private_decrypt(ulEncryptedDataLen, pEncryptedData, buffer, ++ rsa, padding); ++ if (len <= 0) { ++ ret = CKR_DEVICE_ERROR; ++ goto out; ++ } ++ if (len > buffer_len) ++ abort(); ++ ++ if (pData != NULL_PTR) ++ memcpy(pData, buffer, len); ++ *pulDataLen = len; ++ ++ out: ++ if (buffer) { ++ memset(buffer, 0, buffer_len); ++ free(buffer); ++ } ++ return ret; ++} ++ ++ ++CK_RV ++C_DecryptUpdate(CK_SESSION_HANDLE hSession, ++ CK_BYTE_PTR pEncryptedPart, ++ CK_ULONG ulEncryptedPartLen, ++ CK_BYTE_PTR pPart, ++ CK_ULONG_PTR pulPartLen) ++ ++{ ++ st_logf("DecryptUpdate\n"); ++ VERIFY_SESSION_HANDLE(hSession, NULL); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++ ++CK_RV ++C_DecryptFinal(CK_SESSION_HANDLE hSession, ++ CK_BYTE_PTR pLastPart, ++ CK_ULONG_PTR pulLastPartLen) ++{ ++ st_logf("DecryptFinal\n"); ++ VERIFY_SESSION_HANDLE(hSession, NULL); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++CK_RV ++C_DigestInit(CK_SESSION_HANDLE hSession, ++ CK_MECHANISM_PTR pMechanism) ++{ ++ st_logf("DigestInit\n"); ++ VERIFY_SESSION_HANDLE(hSession, NULL); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++CK_RV ++C_SignInit(CK_SESSION_HANDLE hSession, ++ CK_MECHANISM_PTR pMechanism, ++ CK_OBJECT_HANDLE hKey) ++{ ++ struct session_state *state; ++ CK_MECHANISM_TYPE mechs[] = { CKM_RSA_PKCS, CKM_RSA_X_509 }; ++ CK_BBOOL bool_true = CK_TRUE; ++ CK_ATTRIBUTE attr[] = { ++ { CKA_SIGN, &bool_true, sizeof(bool_true) } ++ }; ++ struct st_object *o; ++ CK_RV ret; ++ ++ st_logf("SignInit\n"); ++ VERIFY_SESSION_HANDLE(hSession, &state); ++ ++ ret = commonInit(attr, sizeof(attr)/sizeof(attr[0]), ++ mechs, sizeof(mechs)/sizeof(mechs[0]), ++ pMechanism, hKey, &o); ++ if (ret) ++ return ret; ++ ++ ret = dup_mechanism(&state->sign_mechanism, pMechanism); ++ if (ret == CKR_OK) ++ state->sign_object = OBJECT_ID(o); ++ ++ return CKR_OK; ++} ++ ++CK_RV ++C_Sign(CK_SESSION_HANDLE hSession, ++ CK_BYTE_PTR pData, ++ CK_ULONG ulDataLen, ++ CK_BYTE_PTR pSignature, ++ CK_ULONG_PTR pulSignatureLen) ++{ ++ struct session_state *state; ++ struct st_object *o; ++ void *buffer = NULL; ++ CK_RV ret; ++ RSA *rsa; ++ int padding, len, buffer_len, padding_len; ++ ++ st_logf("Sign\n"); ++ VERIFY_SESSION_HANDLE(hSession, &state); ++ ++ if (state->sign_object == -1) ++ return CKR_ARGUMENTS_BAD; ++ ++ o = soft_token.object.objs[state->sign_object]; ++ ++ if (o->u.private_key.key == NULL) { ++ st_logf("private key NULL\n"); ++ return CKR_ARGUMENTS_BAD; ++ } ++ ++ rsa = o->u.private_key.key->pkey.rsa; ++ ++ if (rsa == NULL) ++ return CKR_ARGUMENTS_BAD; ++ ++ RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ ++ ++ buffer_len = RSA_size(rsa); ++ ++ buffer = malloc(buffer_len); ++ if (buffer == NULL) { ++ ret = CKR_DEVICE_MEMORY; ++ goto out; ++ } ++ ++ switch(state->sign_mechanism->mechanism) { ++ case CKM_RSA_PKCS: ++ padding = RSA_PKCS1_PADDING; ++ padding_len = RSA_PKCS1_PADDING_SIZE; ++ break; ++ case CKM_RSA_X_509: ++ padding = RSA_NO_PADDING; ++ padding_len = 0; ++ break; ++ default: ++ ret = CKR_FUNCTION_NOT_SUPPORTED; ++ goto out; ++ } ++ ++ if (buffer_len < ulDataLen + padding_len) { ++ ret = CKR_ARGUMENTS_BAD; ++ goto out; ++ } ++ ++ if (pulSignatureLen == NULL) { ++ st_logf("signature len NULL\n"); ++ ret = CKR_ARGUMENTS_BAD; ++ goto out; ++ } ++ ++ if (pData == NULL_PTR) { ++ st_logf("data NULL\n"); ++ ret = CKR_ARGUMENTS_BAD; ++ goto out; ++ } ++ ++ len = RSA_private_encrypt(ulDataLen, pData, buffer, rsa, padding); ++ st_logf("private encrypt done\n"); ++ if (len <= 0) { ++ ret = CKR_DEVICE_ERROR; ++ goto out; ++ } ++ if (len > buffer_len) ++ abort(); ++ ++ if (pSignature != NULL_PTR) ++ memcpy(pSignature, buffer, len); ++ *pulSignatureLen = len; ++ ++ ret = CKR_OK; ++ ++ out: ++ if (buffer) { ++ memset(buffer, 0, buffer_len); ++ free(buffer); ++ } ++ return ret; ++} ++ ++CK_RV ++C_SignUpdate(CK_SESSION_HANDLE hSession, ++ CK_BYTE_PTR pPart, ++ CK_ULONG ulPartLen) ++{ ++ st_logf("SignUpdate\n"); ++ VERIFY_SESSION_HANDLE(hSession, NULL); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++ ++CK_RV ++C_SignFinal(CK_SESSION_HANDLE hSession, ++ CK_BYTE_PTR pSignature, ++ CK_ULONG_PTR pulSignatureLen) ++{ ++ st_logf("SignUpdate\n"); ++ VERIFY_SESSION_HANDLE(hSession, NULL); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++CK_RV ++C_VerifyInit(CK_SESSION_HANDLE hSession, ++ CK_MECHANISM_PTR pMechanism, ++ CK_OBJECT_HANDLE hKey) ++{ ++ struct session_state *state; ++ CK_MECHANISM_TYPE mechs[] = { CKM_RSA_PKCS, CKM_RSA_X_509 }; ++ CK_BBOOL bool_true = CK_TRUE; ++ CK_ATTRIBUTE attr[] = { ++ { CKA_VERIFY, &bool_true, sizeof(bool_true) } ++ }; ++ struct st_object *o; ++ CK_RV ret; ++ ++ st_logf("VerifyInit\n"); ++ VERIFY_SESSION_HANDLE(hSession, &state); ++ ++ ret = commonInit(attr, sizeof(attr)/sizeof(attr[0]), ++ mechs, sizeof(mechs)/sizeof(mechs[0]), ++ pMechanism, hKey, &o); ++ if (ret) ++ return ret; ++ ++ ret = dup_mechanism(&state->verify_mechanism, pMechanism); ++ if (ret == CKR_OK) ++ state->verify_object = OBJECT_ID(o); ++ ++ return ret; ++} ++ ++CK_RV ++C_Verify(CK_SESSION_HANDLE hSession, ++ CK_BYTE_PTR pData, ++ CK_ULONG ulDataLen, ++ CK_BYTE_PTR pSignature, ++ CK_ULONG ulSignatureLen) ++{ ++ struct session_state *state; ++ struct st_object *o; ++ void *buffer = NULL; ++ CK_RV ret; ++ RSA *rsa; ++ int padding, len, buffer_len; ++ ++ st_logf("Verify\n"); ++ VERIFY_SESSION_HANDLE(hSession, &state); ++ ++ if (state->verify_object == -1) ++ return CKR_ARGUMENTS_BAD; ++ ++ o = soft_token.object.objs[state->verify_object]; ++ ++ if (o->u.public_key == NULL) { ++ st_logf("public key NULL\n"); ++ return CKR_ARGUMENTS_BAD; ++ } ++ ++ rsa = o->u.public_key->pkey.rsa; ++ ++ if (rsa == NULL) ++ return CKR_ARGUMENTS_BAD; ++ ++ RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ ++ ++ buffer_len = RSA_size(rsa); ++ ++ buffer = malloc(buffer_len); ++ if (buffer == NULL) { ++ ret = CKR_DEVICE_MEMORY; ++ goto out; ++ } ++ ++ ret = CKR_OK; ++ switch(state->verify_mechanism->mechanism) { ++ case CKM_RSA_PKCS: ++ padding = RSA_PKCS1_PADDING; ++ break; ++ case CKM_RSA_X_509: ++ padding = RSA_NO_PADDING; ++ break; ++ default: ++ ret = CKR_FUNCTION_NOT_SUPPORTED; ++ goto out; ++ } ++ ++ if (buffer_len < ulDataLen) { ++ ret = CKR_ARGUMENTS_BAD; ++ goto out; ++ } ++ ++ if (pSignature == NULL) { ++ st_logf("signature NULL\n"); ++ ret = CKR_ARGUMENTS_BAD; ++ goto out; ++ } ++ ++ if (pData == NULL_PTR) { ++ st_logf("data NULL\n"); ++ ret = CKR_ARGUMENTS_BAD; ++ goto out; ++ } ++ ++ len = RSA_public_decrypt(ulDataLen, pData, buffer, rsa, padding); ++ st_logf("private encrypt done\n"); ++ if (len <= 0) { ++ ret = CKR_DEVICE_ERROR; ++ goto out; ++ } ++ if (len > buffer_len) ++ abort(); ++ ++ if (len != ulSignatureLen) { ++ ret = CKR_GENERAL_ERROR; ++ goto out; ++ } ++ ++ if (memcmp(pSignature, buffer, len) != 0) { ++ ret = CKR_GENERAL_ERROR; ++ goto out; ++ } ++ ++ out: ++ if (buffer) { ++ memset(buffer, 0, buffer_len); ++ free(buffer); ++ } ++ return ret; ++} ++ ++ ++CK_RV ++C_VerifyUpdate(CK_SESSION_HANDLE hSession, ++ CK_BYTE_PTR pPart, ++ CK_ULONG ulPartLen) ++{ ++ st_logf("VerifyUpdate\n"); ++ VERIFY_SESSION_HANDLE(hSession, NULL); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++CK_RV ++C_VerifyFinal(CK_SESSION_HANDLE hSession, ++ CK_BYTE_PTR pSignature, ++ CK_ULONG ulSignatureLen) ++{ ++ st_logf("VerifyFinal\n"); ++ VERIFY_SESSION_HANDLE(hSession, NULL); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++CK_RV ++C_GenerateRandom(CK_SESSION_HANDLE hSession, ++ CK_BYTE_PTR RandomData, ++ CK_ULONG ulRandomLen) ++{ ++ st_logf("GenerateRandom\n"); ++ VERIFY_SESSION_HANDLE(hSession, NULL); ++ return CKR_FUNCTION_NOT_SUPPORTED; ++} ++ ++ ++CK_FUNCTION_LIST funcs = { ++ { 2, 11 }, ++ C_Initialize, ++ C_Finalize, ++ C_GetInfo, ++ C_GetFunctionList, ++ C_GetSlotList, ++ C_GetSlotInfo, ++ C_GetTokenInfo, ++ C_GetMechanismList, ++ C_GetMechanismInfo, ++ C_InitToken, ++ (void *)func_not_supported, /* C_InitPIN */ ++ (void *)func_not_supported, /* C_SetPIN */ ++ C_OpenSession, ++ C_CloseSession, ++ C_CloseAllSessions, ++ C_GetSessionInfo, ++ (void *)func_not_supported, /* C_GetOperationState */ ++ (void *)func_not_supported, /* C_SetOperationState */ ++ C_Login, ++ C_Logout, ++ (void *)func_not_supported, /* C_CreateObject */ ++ (void *)func_not_supported, /* C_CopyObject */ ++ (void *)func_not_supported, /* C_DestroyObject */ ++ (void *)func_not_supported, /* C_GetObjectSize */ ++ C_GetAttributeValue, ++ (void *)func_not_supported, /* C_SetAttributeValue */ ++ C_FindObjectsInit, ++ C_FindObjects, ++ C_FindObjectsFinal, ++ C_EncryptInit, ++ C_Encrypt, ++ C_EncryptUpdate, ++ C_EncryptFinal, ++ C_DecryptInit, ++ C_Decrypt, ++ C_DecryptUpdate, ++ C_DecryptFinal, ++ C_DigestInit, ++ (void *)func_not_supported, /* C_Digest */ ++ (void *)func_not_supported, /* C_DigestUpdate */ ++ (void *)func_not_supported, /* C_DigestKey */ ++ (void *)func_not_supported, /* C_DigestFinal */ ++ C_SignInit, ++ C_Sign, ++ C_SignUpdate, ++ C_SignFinal, ++ (void *)func_not_supported, /* C_SignRecoverInit */ ++ (void *)func_not_supported, /* C_SignRecover */ ++ C_VerifyInit, ++ C_Verify, ++ C_VerifyUpdate, ++ C_VerifyFinal, ++ (void *)func_not_supported, /* C_VerifyRecoverInit */ ++ (void *)func_not_supported, /* C_VerifyRecover */ ++ (void *)func_not_supported, /* C_DigestEncryptUpdate */ ++ (void *)func_not_supported, /* C_DecryptDigestUpdate */ ++ (void *)func_not_supported, /* C_SignEncryptUpdate */ ++ (void *)func_not_supported, /* C_DecryptVerifyUpdate */ ++ (void *)func_not_supported, /* C_GenerateKey */ ++ (void *)func_not_supported, /* C_GenerateKeyPair */ ++ (void *)func_not_supported, /* C_WrapKey */ ++ (void *)func_not_supported, /* C_UnwrapKey */ ++ (void *)func_not_supported, /* C_DeriveKey */ ++ (void *)func_not_supported, /* C_SeedRandom */ ++ C_GenerateRandom, ++ (void *)func_not_supported, /* C_GetFunctionStatus */ ++ (void *)func_not_supported, /* C_CancelFunction */ ++ (void *)func_not_supported /* C_WaitForSlotEvent */ ++}; diff --git a/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch b/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch new file mode 100644 index 0000000..737a1b2 --- /dev/null +++ b/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch @@ -0,0 +1,206 @@ +From 9fccdd784a639ffc9d4eae723a39e35cb7434fec Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sat, 20 Jul 2019 00:51:52 -0400 +Subject: [PATCH] Fix Coverity defects in soft-pkcs11 test code + +Nothing in the code removes objects from soft_token.object.obs, so +simplify add_st_object() not to search for an empty slot. Avoid using +random() by using a counter for session handles and just the array +slot number for object handles. Add a helper get_rcfilename() to +facilitate checking the result of asprintf(). Properly initialize ap +in sprintf_fill(). Close the file handle in read_conf_file(). + +(cherry picked from commit b4831515b2f3b6fd7d7fd4bff4558c10c710891d) +--- + src/tests/softpkcs11/main.c | 102 +++++++++++++++++++----------------- + 1 file changed, 53 insertions(+), 49 deletions(-) + +diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c +index 5255323d3..2d1448ca2 100644 +--- a/src/tests/softpkcs11/main.c ++++ b/src/tests/softpkcs11/main.c +@@ -78,6 +78,7 @@ compat_rsa_get0_key(const RSA *rsa, const BIGNUM **n, const BIGNUM **e, + (BL) = i2d_##T((S), &p); \ + if ((BL) <= 0) { \ + free((B)); \ ++ (B) = NULL; \ + (R) = EINVAL; \ + } \ + } \ +@@ -149,6 +150,7 @@ static struct soft_token { + } state[10]; + #define MAX_NUM_SESSION (sizeof(soft_token.state)/sizeof(soft_token.state[0])) + FILE *logfile; ++ CK_SESSION_HANDLE next_session_handle; + } soft_token; + + static void +@@ -179,6 +181,7 @@ snprintf_fill(char *str, int size, char fillchar, const char *fmt, ...) + { + int len; + va_list ap; ++ va_start(ap, fmt); + len = vsnprintf(str, size, fmt, ap); + va_end(ap); + if (len < 0 || len > size) +@@ -344,7 +347,13 @@ static struct st_object * + add_st_object(void) + { + struct st_object *o, **objs; +- int i; ++ ++ objs = realloc(soft_token.object.objs, ++ (soft_token.object.num_objs + 1) * ++ sizeof(soft_token.object.objs[0])); ++ if (objs == NULL) ++ return NULL; ++ soft_token.object.objs = objs; + + o = malloc(sizeof(*o)); + if (o == NULL) +@@ -352,26 +361,9 @@ add_st_object(void) + memset(o, 0, sizeof(*o)); + o->attrs = NULL; + o->num_attributes = 0; ++ o->object_handle = soft_token.object.num_objs; + +- for (i = 0; i < soft_token.object.num_objs; i++) { +- if (soft_token.object.objs == NULL) { +- soft_token.object.objs[i] = o; +- break; +- } +- } +- if (i == soft_token.object.num_objs) { +- objs = realloc(soft_token.object.objs, +- (soft_token.object.num_objs + 1) * sizeof(soft_token.object.objs[0])); +- if (objs == NULL) { +- free(o); +- return NULL; +- } +- soft_token.object.objs = objs; +- soft_token.object.objs[soft_token.object.num_objs++] = o; +- } +- soft_token.object.objs[i]->object_handle = +- (random() & (~OBJECT_ID_MASK)) | i; +- ++ soft_token.object.objs[soft_token.object.num_objs++] = o; + return o; + } + +@@ -797,6 +789,8 @@ read_conf_file(const char *fn) + + add_certificate(label, cert, key, id, anchor); + } ++ ++ fclose(f); + } + + static CK_RV +@@ -806,19 +800,47 @@ func_not_supported(void) + return CKR_FUNCTION_NOT_SUPPORTED; + } + ++static char * ++get_rcfilename() ++{ ++ struct passwd *pw; ++ const char *home = NULL; ++ char *fn; ++ ++ if (getuid() == geteuid()) { ++ fn = getenv("SOFTPKCS11RC"); ++ if (fn != NULL) ++ return strdup(fn); ++ ++ home = getenv("HOME"); ++ } ++ ++ if (home == NULL) { ++ pw = getpwuid(getuid()); ++ if (pw != NULL) ++ home = pw->pw_dir; ++ } ++ ++ if (home == NULL) ++ return strdup("/etc/soft-token.rc"); ++ ++ if (asprintf(&fn, "%s/.soft-token.rc", home) < 0) ++ return NULL; ++ return fn; ++} ++ + CK_RV + C_Initialize(CK_VOID_PTR a) + { + CK_C_INITIALIZE_ARGS_PTR args = a; + size_t i; ++ char *fn; + + st_logf("Initialize\n"); + + OpenSSL_add_all_algorithms(); + ERR_load_crypto_strings(); + +- srandom(getpid() ^ time(NULL)); +- + for (i = 0; i < MAX_NUM_SESSION; i++) { + soft_token.state[i].session_handle = CK_INVALID_HANDLE; + soft_token.state[i].find.attributes = NULL; +@@ -850,31 +872,13 @@ C_Initialize(CK_VOID_PTR a) + st_logf("\tFlags\t%04x\n", (unsigned int)args->flags); + } + +- { +- char *fn = NULL, *home = NULL; +- +- if (getuid() == geteuid()) { +- fn = getenv("SOFTPKCS11RC"); +- if (fn) +- fn = strdup(fn); +- home = getenv("HOME"); +- } +- if (fn == NULL && home == NULL) { +- struct passwd *pw = getpwuid(getuid()); +- if(pw != NULL) +- home = pw->pw_dir; +- } +- if (fn == NULL) { +- if (home) +- asprintf(&fn, "%s/.soft-token.rc", home); +- else +- fn = strdup("/etc/soft-token.rc"); +- } +- +- read_conf_file(fn); +- free(fn); +- } ++ soft_token.next_session_handle = 0; + ++ fn = get_rcfilename(); ++ if (fn == NULL) ++ return CKR_DEVICE_MEMORY; ++ read_conf_file(fn); ++ free(fn); + return CKR_OK; + } + +@@ -1082,8 +1086,7 @@ C_OpenSession(CK_SLOT_ID slotID, + + soft_token.open_sessions++; + +- soft_token.state[i].session_handle = +- (CK_SESSION_HANDLE)(random() & 0xfffff); ++ soft_token.state[i].session_handle = soft_token.next_session_handle++; + *phSession = soft_token.state[i].session_handle; + + return CKR_OK; +@@ -1152,7 +1155,8 @@ C_Login(CK_SESSION_HANDLE hSession, + VERIFY_SESSION_HANDLE(hSession, NULL); + + if (pPin != NULL_PTR) { +- asprintf(&pin, "%.*s", (int)ulPinLen, pPin); ++ if (asprintf(&pin, "%.*s", (int)ulPinLen, pPin) < 0) ++ return CKR_DEVICE_MEMORY; + st_logf("type: %d password: %s\n", (int)userType, pin); + } + diff --git a/Use-imported-soft-pkcs11-for-tests.patch b/Use-imported-soft-pkcs11-for-tests.patch new file mode 100644 index 0000000..5731866 --- /dev/null +++ b/Use-imported-soft-pkcs11-for-tests.patch @@ -0,0 +1,471 @@ +From 403e72295c80d3ec3343d50bf8f7b1e6525e1ea8 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 20 Jun 2019 13:41:57 -0400 +Subject: [PATCH] Use imported soft-pkcs11 for tests + +Update the soft-pkcs11 code for OpenSSL 1.1, fix some warnings, +integrate it into the build system, and use it for the PKINIT tests. + +(cherry picked from commit e5ef7b69765353ea62ad8712a229ed4e90a8fe17) +--- + src/configure.in | 1 + + src/tests/Makefile.in | 2 +- + src/tests/softpkcs11/Makefile.in | 21 ++++ + src/tests/softpkcs11/deps | 6 ++ + src/tests/softpkcs11/main.c | 124 +++++++++++++++++------- + src/tests/softpkcs11/softpkcs11.exports | 39 ++++++++ + src/tests/t_pkinit.py | 18 +--- + 7 files changed, 162 insertions(+), 49 deletions(-) + create mode 100644 src/tests/softpkcs11/Makefile.in + create mode 100644 src/tests/softpkcs11/deps + create mode 100644 src/tests/softpkcs11/softpkcs11.exports + +diff --git a/src/configure.in b/src/configure.in +index a19a0ea97..d0d8c4ed7 100644 +--- a/src/configure.in ++++ b/src/configure.in +@@ -1086,6 +1086,7 @@ int i = 1; + fi + if test "$k5_cv_openssl_version_okay" = yes && (test "$enable_pkinit" = yes || test "$enable_pkinit" = try); then + K5_GEN_MAKEFILE(plugins/preauth/pkinit) ++ K5_GEN_MAKEFILE(tests/softpkcs11) + PKINIT=yes + AC_CHECK_LIB(crypto, CMS_get0_content, [AC_DEFINE([HAVE_OPENSSL_CMS], 1, [Define if OpenSSL supports cms.])]) + elif test "$k5_cv_openssl_version_okay" = no && test "$enable_pkinit" = yes; then +diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in +index d2a37c616..8fa44fb59 100644 +--- a/src/tests/Makefile.in ++++ b/src/tests/Makefile.in +@@ -1,7 +1,7 @@ + mydir=tests + BUILDTOP=$(REL).. + SUBDIRS = resolve asn.1 create hammer verify gssapi dejagnu shlib \ +- gss-threads misc threads ++ gss-threads misc threads softpkcs11 + + RUN_DB_TEST = $(RUN_SETUP) KRB5_KDC_PROFILE=kdc.conf KRB5_CONFIG=krb5.conf \ + LC_ALL=C $(VALGRIND) +diff --git a/src/tests/softpkcs11/Makefile.in b/src/tests/softpkcs11/Makefile.in +new file mode 100644 +index 000000000..e89678154 +--- /dev/null ++++ b/src/tests/softpkcs11/Makefile.in +@@ -0,0 +1,21 @@ ++mydir=tests$(S)softpkcs11 ++BUILDTOP=$(REL)..$(S).. ++ ++LOCALINCLUDES = -I$(top_srcdir)/plugins/preauth/pkinit ++ ++LIBBASE=softpkcs11 ++LIBMAJOR=0 ++LIBMINOR=0 ++ ++SHLIB_EXPLIBS=$(SUPPORT_LIB) -lcrypto ++SHLIB_EXPDEPS=$(SUPPORT_DEPLIB) ++ ++STLIBOBJS=main.o ++ ++SRCS=$(srcdir)/main.c ++ ++all-unix: all-libs ++clean-unix:: clean-libs clean-libobjs ++ ++@libnover_frag@ ++@libobj_frag@ +diff --git a/src/tests/softpkcs11/deps b/src/tests/softpkcs11/deps +new file mode 100644 +index 000000000..1e82d9572 +--- /dev/null ++++ b/src/tests/softpkcs11/deps +@@ -0,0 +1,6 @@ ++# ++# Generated makefile dependencies follow. ++# ++main.so main.po $(OUTPRE)main.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ ++ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-thread.h \ ++ $(top_srcdir)/plugins/preauth/pkinit/pkcs11.h main.c +diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c +index 2acec5169..5255323d3 100644 +--- a/src/tests/softpkcs11/main.c ++++ b/src/tests/softpkcs11/main.c +@@ -1,3 +1,4 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ + /* + * Copyright (c) 2004-2006, Stockholms universitet + * (Stockholm University, Stockholm Sweden) +@@ -31,7 +32,57 @@ + * POSSIBILITY OF SUCH DAMAGE. + */ + +-#include "locl.h" ++#include "k5-platform.h" ++ ++#include ++#include ++#include ++#include ++#include ++ ++#include ++#include ++ ++#include ++ ++#if OPENSSL_VERSION_NUMBER < 0x10100000L ++#define EVP_PKEY_get0_RSA(key) ((key)->pkey.rsa) ++#define RSA_PKCS1_OpenSSL RSA_PKCS1_SSLeay ++#define RSA_get0_key compat_rsa_get0_key ++static void ++compat_rsa_get0_key(const RSA *rsa, const BIGNUM **n, const BIGNUM **e, ++ const BIGNUM **d) ++{ ++ if (n != NULL) ++ *n = rsa->n; ++ if (e != NULL) ++ *e = rsa->e; ++ if (d != NULL) ++ *d = rsa->d; ++} ++#endif ++ ++#define OPENSSL_ASN1_MALLOC_ENCODE(T, B, BL, S, R) \ ++ { \ ++ unsigned char *p; \ ++ (BL) = i2d_##T((S), NULL); \ ++ if ((BL) <= 0) { \ ++ (R) = EINVAL; \ ++ } else { \ ++ (B) = malloc((BL)); \ ++ if ((B) == NULL) { \ ++ (R) = ENOMEM; \ ++ } else { \ ++ p = (B); \ ++ (R) = 0; \ ++ (BL) = i2d_##T((S), &p); \ ++ if ((BL) <= 0) { \ ++ free((B)); \ ++ (R) = EINVAL; \ ++ } \ ++ } \ ++ } \ ++ } + + /* RCSID("$Id: main.c,v 1.24 2006/01/11 12:42:53 lha Exp $"); */ + +@@ -124,7 +175,7 @@ st_logf(const char *fmt, ...) + } + + static void +-snprintf_fill(char *str, size_t size, char fillchar, const char *fmt, ...) ++snprintf_fill(char *str, int size, char fillchar, const char *fmt, ...) + { + int len; + va_list ap; +@@ -141,19 +192,19 @@ snprintf_fill(char *str, size_t size, char fillchar, const char *fmt, ...) + #endif + + #define VERIFY_SESSION_HANDLE(s, state) \ +-{ \ +- CK_RV ret; \ +- ret = verify_session_handle(s, state); \ +- if (ret != CKR_OK) { \ +- /* return CKR_OK */; \ +- } \ +-} ++ { \ ++ CK_RV vshret; \ ++ vshret = verify_session_handle(s, state); \ ++ if (vshret != CKR_OK) { \ ++ /* return CKR_OK */; \ ++ } \ ++ } + + static CK_RV + verify_session_handle(CK_SESSION_HANDLE hSession, + struct session_state **state) + { +- int i; ++ size_t i; + + for (i = 0; i < MAX_NUM_SESSION; i++){ + if (soft_token.state[i].session_handle == hSession) +@@ -361,16 +412,20 @@ add_pubkey_info(struct st_object *o, CK_KEY_TYPE key_type, EVP_PKEY *key) + CK_ULONG modulus_bits = 0; + CK_BYTE *exponent = NULL; + size_t exponent_len = 0; ++ RSA *rsa; ++ const BIGNUM *n, *e; + +- modulus_bits = BN_num_bits(key->pkey.rsa->n); ++ rsa = EVP_PKEY_get0_RSA(key); ++ RSA_get0_key(rsa, &n, &e, NULL); ++ modulus_bits = BN_num_bits(n); + +- modulus_len = BN_num_bytes(key->pkey.rsa->n); ++ modulus_len = BN_num_bytes(n); + modulus = malloc(modulus_len); +- BN_bn2bin(key->pkey.rsa->n, modulus); ++ BN_bn2bin(n, modulus); + +- exponent_len = BN_num_bytes(key->pkey.rsa->e); ++ exponent_len = BN_num_bytes(e); + exponent = malloc(exponent_len); +- BN_bn2bin(key->pkey.rsa->e, exponent); ++ BN_bn2bin(e, exponent); + + add_object_attribute(o, 0, CKA_MODULUS, modulus, modulus_len); + add_object_attribute(o, 0, CKA_MODULUS_BITS, +@@ -378,7 +433,7 @@ add_pubkey_info(struct st_object *o, CK_KEY_TYPE key_type, EVP_PKEY *key) + add_object_attribute(o, 0, CKA_PUBLIC_EXPONENT, + exponent, exponent_len); + +- RSA_set_method(key->pkey.rsa, RSA_PKCS1_SSLeay()); ++ RSA_set_method(rsa, RSA_PKCS1_OpenSSL()); + + free(modulus); + free(exponent); +@@ -474,7 +529,7 @@ add_certificate(char *label, + o->u.cert = cert; + public_key = X509_get_pubkey(o->u.cert); + +- switch (EVP_PKEY_type(public_key->type)) { ++ switch (EVP_PKEY_base_id(public_key)) { + case EVP_PKEY_RSA: + key_type = CKK_RSA; + break; +@@ -604,8 +659,8 @@ add_certificate(char *label, + /* XXX verify keytype */ + + if (key_type == CKK_RSA) +- RSA_set_method(o->u.private_key.key->pkey.rsa, +- RSA_PKCS1_SSLeay()); ++ RSA_set_method(EVP_PKEY_get0_RSA(o->u.private_key.key), ++ RSA_PKCS1_OpenSSL()); + + if (X509_check_private_key(cert, o->u.private_key.key) != 1) { + EVP_PKEY_free(o->u.private_key.key); +@@ -755,8 +810,9 @@ CK_RV + C_Initialize(CK_VOID_PTR a) + { + CK_C_INITIALIZE_ARGS_PTR args = a; ++ size_t i; ++ + st_logf("Initialize\n"); +- int i; + + OpenSSL_add_all_algorithms(); + ERR_load_crypto_strings(); +@@ -825,7 +881,7 @@ C_Initialize(CK_VOID_PTR a) + CK_RV + C_Finalize(CK_VOID_PTR args) + { +- int i; ++ size_t i; + + st_logf("Finalize\n"); + +@@ -1008,7 +1064,7 @@ C_OpenSession(CK_SLOT_ID slotID, + CK_NOTIFY Notify, + CK_SESSION_HANDLE_PTR phSession) + { +- int i; ++ size_t i; + + st_logf("OpenSession: slot: %d\n", (int)slotID); + +@@ -1050,7 +1106,7 @@ C_CloseSession(CK_SESSION_HANDLE hSession) + CK_RV + C_CloseAllSessions(CK_SLOT_ID slotID) + { +- int i; ++ size_t i; + + st_logf("CloseAllSessions\n"); + +@@ -1127,7 +1183,8 @@ C_Login(CK_SESSION_HANDLE hSession, + } + + /* XXX check keytype */ +- RSA_set_method(o->u.private_key.key->pkey.rsa, RSA_PKCS1_SSLeay()); ++ RSA_set_method(EVP_PKEY_get0_RSA(o->u.private_key.key), ++ RSA_PKCS1_OpenSSL()); + + if (X509_check_private_key(o->u.private_key.cert, o->u.private_key.key) != 1) { + EVP_PKEY_free(o->u.private_key.key); +@@ -1226,7 +1283,6 @@ C_FindObjectsInit(CK_SESSION_HANDLE hSession, + } + if (ulCount) { + CK_ULONG i; +- size_t len; + + print_attributes(pTemplate, ulCount); + +@@ -1415,7 +1471,7 @@ C_Encrypt(CK_SESSION_HANDLE hSession, + return CKR_ARGUMENTS_BAD; + } + +- rsa = o->u.public_key->pkey.rsa; ++ rsa = EVP_PKEY_get0_RSA(o->u.public_key); + + if (rsa == NULL) + return CKR_ARGUMENTS_BAD; +@@ -1445,7 +1501,7 @@ C_Encrypt(CK_SESSION_HANDLE hSession, + goto out; + } + +- if (buffer_len + padding_len < ulDataLen) { ++ if ((CK_ULONG)buffer_len + padding_len < ulDataLen) { + ret = CKR_ARGUMENTS_BAD; + goto out; + } +@@ -1566,7 +1622,7 @@ C_Decrypt(CK_SESSION_HANDLE hSession, + return CKR_ARGUMENTS_BAD; + } + +- rsa = o->u.private_key.key->pkey.rsa; ++ rsa = EVP_PKEY_get0_RSA(o->u.private_key.key); + + if (rsa == NULL) + return CKR_ARGUMENTS_BAD; +@@ -1596,7 +1652,7 @@ C_Decrypt(CK_SESSION_HANDLE hSession, + goto out; + } + +- if (buffer_len + padding_len < ulEncryptedDataLen) { ++ if ((CK_ULONG)buffer_len + padding_len < ulEncryptedDataLen) { + ret = CKR_ARGUMENTS_BAD; + goto out; + } +@@ -1725,7 +1781,7 @@ C_Sign(CK_SESSION_HANDLE hSession, + return CKR_ARGUMENTS_BAD; + } + +- rsa = o->u.private_key.key->pkey.rsa; ++ rsa = EVP_PKEY_get0_RSA(o->u.private_key.key); + + if (rsa == NULL) + return CKR_ARGUMENTS_BAD; +@@ -1754,7 +1810,7 @@ C_Sign(CK_SESSION_HANDLE hSession, + goto out; + } + +- if (buffer_len < ulDataLen + padding_len) { ++ if ((CK_ULONG)buffer_len < ulDataLen + padding_len) { + ret = CKR_ARGUMENTS_BAD; + goto out; + } +@@ -1872,7 +1928,7 @@ C_Verify(CK_SESSION_HANDLE hSession, + return CKR_ARGUMENTS_BAD; + } + +- rsa = o->u.public_key->pkey.rsa; ++ rsa = EVP_PKEY_get0_RSA(o->u.public_key); + + if (rsa == NULL) + return CKR_ARGUMENTS_BAD; +@@ -1900,7 +1956,7 @@ C_Verify(CK_SESSION_HANDLE hSession, + goto out; + } + +- if (buffer_len < ulDataLen) { ++ if ((CK_ULONG)buffer_len < ulDataLen) { + ret = CKR_ARGUMENTS_BAD; + goto out; + } +@@ -1926,7 +1982,7 @@ C_Verify(CK_SESSION_HANDLE hSession, + if (len > buffer_len) + abort(); + +- if (len != ulSignatureLen) { ++ if ((CK_ULONG)len != ulSignatureLen) { + ret = CKR_GENERAL_ERROR; + goto out; + } +diff --git a/src/tests/softpkcs11/softpkcs11.exports b/src/tests/softpkcs11/softpkcs11.exports +new file mode 100644 +index 000000000..aa7284511 +--- /dev/null ++++ b/src/tests/softpkcs11/softpkcs11.exports +@@ -0,0 +1,39 @@ ++C_CloseAllSessions ++C_CloseSession ++C_Decrypt ++C_DecryptFinal ++C_DecryptInit ++C_DecryptUpdate ++C_DigestInit ++C_Encrypt ++C_EncryptFinal ++C_EncryptInit ++C_EncryptUpdate ++C_Finalize ++C_FindObjects ++C_FindObjectsFinal ++C_FindObjectsInit ++C_GenerateRandom ++C_GetAttributeValue ++C_GetFunctionList ++C_GetInfo ++C_GetMechanismInfo ++C_GetMechanismList ++C_GetObjectSize ++C_GetSessionInfo ++C_GetSlotInfo ++C_GetSlotList ++C_GetTokenInfo ++C_Initialize ++C_InitToken ++C_Login ++C_Logout ++C_OpenSession ++C_Sign ++C_SignFinal ++C_SignInit ++C_SignUpdate ++C_Verify ++C_VerifyFinal ++C_VerifyInit ++C_VerifyUpdate +diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py +index 93f0f2632..69daf4987 100755 +--- a/src/tests/t_pkinit.py ++++ b/src/tests/t_pkinit.py +@@ -4,14 +4,7 @@ from k5test import * + if not os.path.exists(os.path.join(plugins, 'preauth', 'pkinit.so')): + skip_rest('PKINIT tests', 'PKINIT module not built') + +-# Check if soft-pkcs11.so is available. +-try: +- import ctypes +- lib = ctypes.LibraryLoader(ctypes.CDLL).LoadLibrary('soft-pkcs11.so') +- del lib +- have_soft_pkcs11 = True +-except: +- have_soft_pkcs11 = False ++soft_pkcs11 = os.path.join(buildtop, 'tests', 'softpkcs11', 'softpkcs11.so') + + # Construct a krb5.conf fragment configuring pkinit. + certs = os.path.join(srctop, 'tests', 'dejagnu', 'pkinit-certs') +@@ -69,9 +62,9 @@ p12_upn2_identity = 'PKCS12:%s' % user_upn2_p12 + p12_upn3_identity = 'PKCS12:%s' % user_upn3_p12 + p12_generic_identity = 'PKCS12:%s' % generic_p12 + p12_enc_identity = 'PKCS12:%s' % user_enc_p12 +-p11_identity = 'PKCS11:soft-pkcs11.so' +-p11_token_identity = ('PKCS11:module_name=soft-pkcs11.so:' +- 'slotid=1:token=SoftToken (token)') ++p11_identity = 'PKCS11:' + soft_pkcs11 ++p11_token_identity = ('PKCS11:module_name=' + soft_pkcs11 + ++ ':slotid=1:token=SoftToken (token)') + + # Start a realm with the test kdb module for the following UPN SAN tests. + realm = K5Realm(krb5_conf=pkinit_krb5_conf, kdc_conf=alias_kdc_conf, +@@ -398,9 +391,6 @@ realm.klist(realm.user_princ) + realm.kinit(realm.user_princ, flags=['-X', 'X509_user_identity=,'], + expected_code=1, expected_msg='Preauthentication failed while') + +-if not have_soft_pkcs11: +- skip_rest('PKINIT PKCS11 tests', 'soft-pkcs11.so not found') +- + softpkcs11rc = os.path.join(os.getcwd(), 'testdir', 'soft-pkcs11.rc') + realm.env['SOFTPKCS11RC'] = softpkcs11rc + diff --git a/krb5.spec b/krb5.spec index fd0e7fe..b0803ba 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 37%{?dist} +Release: 38%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -113,6 +113,9 @@ Patch150: Remove-3des-support.patch Patch151: Remove-now-unused-checksum-functions.patch Patch152: Don-t-error-on-invalid-enctypes-in-keytab.patch Patch153: Filter-enctypes-in-gss_set_allowable_enctypes.patch +Patch154: Add-soft-pkcs11-source-code.patch +Patch155: Use-imported-soft-pkcs11-for-tests.patch +Patch156: Fix-Coverity-defects-in-soft-pkcs11-test-code.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -722,6 +725,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Jul 30 2019 Robbie Harwood - 1.17-38 +- Add soft-pkcs11 and use it for testing + * Thu Jul 25 2019 Fedora Release Engineering - 1.17-37 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild From e73c24bb365a85367e48356dc639dd5be51733ac Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 6 Aug 2019 09:46:36 -0400 Subject: [PATCH 124/304] Fix memory leaks in soft-pkcs11 code --- Fix-memory-leaks-in-soft-pkcs11-code.patch | 122 +++++++++++++++++++++ Skip-URI-tests-when-using-asan.patch | 37 +++++++ krb5.spec | 7 +- 3 files changed, 165 insertions(+), 1 deletion(-) create mode 100644 Fix-memory-leaks-in-soft-pkcs11-code.patch create mode 100644 Skip-URI-tests-when-using-asan.patch diff --git a/Fix-memory-leaks-in-soft-pkcs11-code.patch b/Fix-memory-leaks-in-soft-pkcs11-code.patch new file mode 100644 index 0000000..7df892c --- /dev/null +++ b/Fix-memory-leaks-in-soft-pkcs11-code.patch @@ -0,0 +1,122 @@ +From 26aa776c9ce531d4487c40ad6684afef74394bac Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 5 Aug 2019 01:53:51 -0400 +Subject: [PATCH] Fix memory leaks in soft-pkcs11 code + +Fix leaks detected by asan in t_pkinit.py. Add a helper to free a +struct st_object and free objects in C_Finalize(). Duplicate the X509 +cert in add_certificate() instead of creating aliases so it can be +properly freed. Start the session handle counter at 1 so that +C_Finalize() won't confuse the first session handle with +CK_INVALID_HANDLE (defined to 0 in pkinit.h) and will properly clean +the session object. + +(cherry picked from commit 15bcaf8bcb4af25ff89820ad3bf23ad5a324e863) +--- + src/tests/softpkcs11/main.c | 44 +++++++++++++++++++++++++++++++++---- + 1 file changed, 40 insertions(+), 4 deletions(-) + +diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c +index 2d1448ca2..a4c3ae78e 100644 +--- a/src/tests/softpkcs11/main.c ++++ b/src/tests/softpkcs11/main.c +@@ -109,7 +109,7 @@ struct st_object { + X509 *cert; + EVP_PKEY *public_key; + struct { +- const char *file; ++ char *file; + EVP_PKEY *key; + X509 *cert; + } private_key; +@@ -343,6 +343,26 @@ print_attributes(const CK_ATTRIBUTE *attributes, + } + } + ++static void ++free_st_object(struct st_object *o) ++{ ++ int i; ++ ++ for (i = 0; i < o->num_attributes; i++) ++ free(o->attrs[i].attribute.pValue); ++ free(o->attrs); ++ if (o->type == STO_T_CERTIFICATE) { ++ X509_free(o->u.cert); ++ } else if (o->type == STO_T_PRIVATE_KEY) { ++ free(o->u.private_key.file); ++ EVP_PKEY_free(o->u.private_key.key); ++ X509_free(o->u.private_key.cert); ++ } else if (o->type == STO_T_PUBLIC_KEY) { ++ EVP_PKEY_free(o->u.public_key); ++ } ++ free(o); ++} ++ + static struct st_object * + add_st_object(void) + { +@@ -518,7 +538,11 @@ add_certificate(char *label, + goto out; + } + o->type = STO_T_CERTIFICATE; +- o->u.cert = cert; ++ o->u.cert = X509_dup(cert); ++ if (o->u.cert == NULL) { ++ ret = CKR_DEVICE_MEMORY; ++ goto out; ++ } + public_key = X509_get_pubkey(o->u.cert); + + switch (EVP_PKEY_base_id(public_key)) { +@@ -602,7 +626,11 @@ add_certificate(char *label, + o->u.private_key.file = strdup(private_key_file); + o->u.private_key.key = NULL; + +- o->u.private_key.cert = cert; ++ o->u.private_key.cert = X509_dup(cert); ++ if (o->u.private_key.cert == NULL) { ++ ret = CKR_DEVICE_MEMORY; ++ goto out; ++ } + + c = CKO_PRIVATE_KEY; + add_object_attribute(o, 0, CKA_CLASS, &c, sizeof(c)); +@@ -676,6 +704,7 @@ add_certificate(char *label, + free(serial_data); + free(issuer_data); + free(subject_data); ++ X509_free(cert); + + return ret; + } +@@ -872,7 +901,7 @@ C_Initialize(CK_VOID_PTR a) + st_logf("\tFlags\t%04x\n", (unsigned int)args->flags); + } + +- soft_token.next_session_handle = 0; ++ soft_token.next_session_handle = 1; + + fn = get_rcfilename(); + if (fn == NULL) +@@ -886,6 +915,7 @@ CK_RV + C_Finalize(CK_VOID_PTR args) + { + size_t i; ++ int j; + + st_logf("Finalize\n"); + +@@ -897,6 +927,12 @@ C_Finalize(CK_VOID_PTR args) + } + } + ++ for (j = 0; j < soft_token.object.num_objs; j++) ++ free_st_object(soft_token.object.objs[j]); ++ free(soft_token.object.objs); ++ soft_token.object.objs = NULL; ++ soft_token.object.num_objs = 0; ++ + return CKR_OK; + } + diff --git a/Skip-URI-tests-when-using-asan.patch b/Skip-URI-tests-when-using-asan.patch new file mode 100644 index 0000000..1f4ebfc --- /dev/null +++ b/Skip-URI-tests-when-using-asan.patch @@ -0,0 +1,37 @@ +From 6099c5f17a25971defadde6f8fbc2abaa764462b Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sat, 3 Aug 2019 13:30:28 -0400 +Subject: [PATCH] Skip URI tests when using asan + +resolve_wrapper uses RTLD_DEEPBIND to load libresolv, triggering a +failure in the asan runtime. + +(cherry picked from commit dbcec74b277952adf6e49d087932d2d0ea5393d1) +--- + src/lib/krb5/os/Makefile.in | 10 +++++++--- + 1 file changed, 7 insertions(+), 3 deletions(-) + +diff --git a/src/lib/krb5/os/Makefile.in b/src/lib/krb5/os/Makefile.in +index 91b0486b8..f523a5ac8 100644 +--- a/src/lib/krb5/os/Makefile.in ++++ b/src/lib/krb5/os/Makefile.in +@@ -232,12 +232,16 @@ check-unix-locate: t_locate_kdc + echo 'Skipped t_locate_kdc test: OFFLINE' >> $(SKIPTESTS); \ + fi + ++ASAN = @ASAN@ + check-unix-uri: t_locate_kdc +- if [ $(HAVE_RESOLV_WRAPPER) = 1 ]; then \ +- $(RUNPYTEST) $(srcdir)/t_discover_uri.py $(PYTESTFLAGS); \ +- else \ ++ if [ $(HAVE_RESOLV_WRAPPER) = 0 ]; then \ + echo '*** WARNING: skipped t_discover_uri.py due to not using resolv_wrapper'; \ + echo 'Skipped URI discovery tests: resolv_wrapper 1.1.5 not found' >> $(SKIPTESTS); \ ++ elif [ $(ASAN) = yes ]; then \ ++ echo '*** Skipping URI discovery tests: resolv_wrapper is incompatible with asan'; \ ++ echo 'Skipped URI discovery tests: incompatible with asan' >> $(SKIPTESTS); \ ++ else \ ++ $(RUNPYTEST) $(srcdir)/t_discover_uri.py $(PYTESTFLAGS); \ + fi + + check-unix-trace: t_trace diff --git a/krb5.spec b/krb5.spec index b0803ba..3441d01 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 38%{?dist} +Release: 39%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -116,6 +116,8 @@ Patch153: Filter-enctypes-in-gss_set_allowable_enctypes.patch Patch154: Add-soft-pkcs11-source-code.patch Patch155: Use-imported-soft-pkcs11-for-tests.patch Patch156: Fix-Coverity-defects-in-soft-pkcs11-test-code.patch +Patch157: Skip-URI-tests-when-using-asan.patch +Patch158: Fix-memory-leaks-in-soft-pkcs11-code.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -725,6 +727,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Aug 06 2019 Robbie Harwood - 1.17-39 +- Fix memory leaks in soft-pkcs11 code + * Tue Jul 30 2019 Robbie Harwood - 1.17-38 - Add soft-pkcs11 and use it for testing From 6fb26c9d3d13a88e17379b27fe3b12fe300e656c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Aug 2019 16:05:18 -0400 Subject: [PATCH 125/304] Initialize life/rlife in kdcpolicy interface --- ...ze-life-rlife-in-kdcpolicy-interface.patch | 41 +++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 46 insertions(+), 1 deletion(-) create mode 100644 Initialize-life-rlife-in-kdcpolicy-interface.patch diff --git a/Initialize-life-rlife-in-kdcpolicy-interface.patch b/Initialize-life-rlife-in-kdcpolicy-interface.patch new file mode 100644 index 0000000..4e92043 --- /dev/null +++ b/Initialize-life-rlife-in-kdcpolicy-interface.patch @@ -0,0 +1,41 @@ +From a2065b41a6a89b273b455088a5df5304bfd1f663 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 9 Aug 2019 14:07:22 -0400 +Subject: [PATCH] Initialize life/rlife in kdcpolicy interface + +A value of 0 indicates that the plugin doesn't wish to modify lifetimes. +Make this the default, rather than requiring all plugins to set these +values themselves. + +ticket: 8824 (new) +tags: pullup +target_version: 1.17-next +target_version: 1.16-next + +(cherry picked from commit d81c5870013240c04642c8e0cb994b4c49e40ddf) +--- + src/kdc/policy.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/src/kdc/policy.c b/src/kdc/policy.c +index 26c16f97c..a3ff556c5 100644 +--- a/src/kdc/policy.c ++++ b/src/kdc/policy.c +@@ -106,7 +106,7 @@ check_kdcpolicy_as(krb5_context context, const krb5_kdc_req *request, + krb5_data *const *auth_indicators, krb5_timestamp kdc_time, + krb5_ticket_times *times, const char **status) + { +- krb5_deltat life, rlife; ++ krb5_deltat life = 0, rlife = 0; + krb5_error_code ret; + kdcpolicy_handle *hp, h; + char **ais = NULL; +@@ -146,7 +146,7 @@ check_kdcpolicy_tgs(krb5_context context, const krb5_kdc_req *request, + krb5_data *const *auth_indicators, krb5_timestamp kdc_time, + krb5_ticket_times *times, const char **status) + { +- krb5_deltat life, rlife; ++ krb5_deltat life = 0, rlife = 0; + krb5_error_code ret; + kdcpolicy_handle *hp, h; + char **ais = NULL; diff --git a/krb5.spec b/krb5.spec index 3441d01..fa766e1 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 39%{?dist} +Release: 40%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -118,6 +118,7 @@ Patch155: Use-imported-soft-pkcs11-for-tests.patch Patch156: Fix-Coverity-defects-in-soft-pkcs11-test-code.patch Patch157: Skip-URI-tests-when-using-asan.patch Patch158: Fix-memory-leaks-in-soft-pkcs11-code.patch +Patch159: Initialize-life-rlife-in-kdcpolicy-interface.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -727,6 +728,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Aug 09 2019 Robbie Harwood - 1.17-40 +- Initialize life/rlife in kdcpolicy interface + * Tue Aug 06 2019 Robbie Harwood - 1.17-39 - Fix memory leaks in soft-pkcs11 code From cdaea01dc806bbc51975a33b05d2244b966f1428 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 15 Aug 2019 16:32:06 -0400 Subject: [PATCH 126/304] Fix KCM client time offset propagation --- ...able-flag-instead-of-denying-request.patch | 7 +- Fix-KCM-client-time-offset-propagation.patch | 32 ++++ ...5_cc_remove_cred-for-remaining-types.patch | 30 ++-- ...ype-names-in-KDC-logs-human-readable.patch | 137 ++++++++------- Remove-3des-support.patch | 65 ++++--- ...beros-v4-support-vestiges-from-ccapi.patch | 60 +++---- Remove-PKINIT-draft-9-support.patch | 158 +++++++++--------- Simply-OpenSSL-PKCS7-decryption-code.patch | 85 +++++----- ...t-suite-to-avoid-single-DES-enctypes.patch | 11 +- Use-secure_getenv-where-appropriate.patch | 18 +- krb5.spec | 6 +- 11 files changed, 315 insertions(+), 294 deletions(-) create mode 100644 Fix-KCM-client-time-offset-propagation.patch diff --git a/Clear-forwardable-flag-instead-of-denying-request.patch b/Clear-forwardable-flag-instead-of-denying-request.patch index 7105d6c..05e4dbd 100644 --- a/Clear-forwardable-flag-instead-of-denying-request.patch +++ b/Clear-forwardable-flag-instead-of-denying-request.patch @@ -14,14 +14,14 @@ ticket: 7871 (cherry picked from commit 08e948cce2c79a3604066fcf7a64fc527456f83d) --- src/kdc/do_as_req.c | 19 ++------ - src/kdc/do_tgs_req.c | 56 ++++----------------- + src/kdc/do_tgs_req.c | 58 +++++----------------- src/kdc/kdc_util.c | 82 ++++++++++++++++++------------- src/kdc/kdc_util.h | 9 ++-- src/kdc/tgs_policy.c | 8 +-- src/tests/Makefile.in | 1 + src/tests/gcred.c | 28 ++++++++--- src/tests/t_kdcoptions.py | 100 ++++++++++++++++++++++++++++++++++++++ - 8 files changed, 189 insertions(+), 114 deletions(-) + 8 files changed, 190 insertions(+), 115 deletions(-) create mode 100644 src/tests/t_kdcoptions.py diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c @@ -146,9 +146,10 @@ index 587342a6c..1da099318 100644 - if (isflagset(request->kdc_options, KDC_OPT_REQUEST_ANONYMOUS) && - !isflagset(header_enc_tkt->flags, TKT_FLG_ANONYMOUS)) - clear(enc_tkt_reply.flags, TKT_FLG_ANONYMOUS); - +- - if (isflagset(request->kdc_options, KDC_OPT_POSTDATED)) { - setflag(enc_tkt_reply.flags, TKT_FLG_INVALID); ++ + if (isflagset(request->kdc_options, KDC_OPT_POSTDATED)) enc_tkt_reply.times.starttime = request->from; - } else diff --git a/Fix-KCM-client-time-offset-propagation.patch b/Fix-KCM-client-time-offset-propagation.patch new file mode 100644 index 0000000..90b1900 --- /dev/null +++ b/Fix-KCM-client-time-offset-propagation.patch @@ -0,0 +1,32 @@ +From e299c5e9442ade8c0b47d122809f76f03b64e497 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 14 Aug 2019 13:52:27 -0400 +Subject: [PATCH] Fix KCM client time offset propagation + +An inverted status check in get_kdc_offset() would cause querying the +offset time from the ccache to always fail (silently) on KCM. Fix the +status check so that KCM can properly handle desync. + +ticket: 8826 (new) +tags: pullup +target_version: 1.17-next +target_verison: 1.16-next + +(cherry picked from commit 323abb6d1ebe5469d6c2167c29aa5d696d099b90) +--- + src/lib/krb5/ccache/cc_kcm.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c +index 092ab7daf..fe93ca3dc 100644 +--- a/src/lib/krb5/ccache/cc_kcm.c ++++ b/src/lib/krb5/ccache/cc_kcm.c +@@ -583,7 +583,7 @@ get_kdc_offset(krb5_context context, krb5_ccache cache) + if (cache_call(context, cache, &req, FALSE) != 0) + goto cleanup; + time_offset = k5_input_get_uint32_be(&req.reply); +- if (!req.reply.status) ++ if (req.reply.status) + goto cleanup; + context->os_context.time_offset = time_offset; + context->os_context.usec_offset = 0; diff --git a/Implement-krb5_cc_remove_cred-for-remaining-types.patch b/Implement-krb5_cc_remove_cred-for-remaining-types.patch index b24aa05..b77a6e5 100644 --- a/Implement-krb5_cc_remove_cred-for-remaining-types.patch +++ b/Implement-krb5_cc_remove_cred-for-remaining-types.patch @@ -266,13 +266,25 @@ index 8419f6ebf..98723fe2e 100644 - * with the time offsets, skip it. */ - while (krcursor->keys[krcursor->currkey] == krcursor->princ_id || - krcursor->keys[krcursor->currkey] == krcursor->offsets_id) { +- krcursor->currkey++; +- /* Check if we have now reached the end */ +- if (krcursor->currkey >= krcursor->numkeys) +- return KRB5_CC_END; +- } + /* Read the key; the right size buffer will be allocated and + * returned. */ + psize = keyctl_read_alloc(krcursor->keys[krcursor->currkey], + &payload); + if (psize != -1) { + krcursor->currkey++; -+ + +- /* Read the key; the right size buffer will be allocated and returned. */ +- psize = keyctl_read_alloc(krcursor->keys[krcursor->currkey], &payload); +- if (psize == -1) { +- DEBUG_PRINT(("Error reading key %d: %s\n", +- krcursor->keys[krcursor->currkey], +- strerror(errno))); +- return KRB5_FCC_NOFILE; + /* Unmarshal the cred using the file ccache version 4 format. */ + ret = k5_unmarshal_cred(payload, psize, 4, creds); + free(payload); @@ -285,22 +297,10 @@ index 8419f6ebf..98723fe2e 100644 + + /* The current key was unlinked, probably by a remove_cred call; move + * on to the next one. */ - krcursor->currkey++; -- /* Check if we have now reached the end */ -- if (krcursor->currkey >= krcursor->numkeys) -- return KRB5_CC_END; ++ krcursor->currkey++; } - -- /* Read the key; the right size buffer will be allocated and returned. */ -- psize = keyctl_read_alloc(krcursor->keys[krcursor->currkey], &payload); -- if (psize == -1) { -- DEBUG_PRINT(("Error reading key %d: %s\n", -- krcursor->keys[krcursor->currkey], -- strerror(errno))); -- return KRB5_FCC_NOFILE; -- } - krcursor->currkey++; -- + - /* Unmarshal the credential using the file ccache version 4 format. */ - ret = k5_unmarshal_cred(payload, psize, 4, creds); - free(payload); diff --git a/Make-etype-names-in-KDC-logs-human-readable.patch b/Make-etype-names-in-KDC-logs-human-readable.patch index b6b57c9..abf5c29 100644 --- a/Make-etype-names-in-KDC-logs-human-readable.patch +++ b/Make-etype-names-in-KDC-logs-human-readable.patch @@ -12,9 +12,9 @@ ticket: 8772 (new) (cherry picked from commit a649279727490687d54becad91fde8cf7429d951) --- src/kdc/kdc_log.c | 42 +++++++-------- - src/kdc/kdc_util.c | 131 +++++++++++++++++++++++---------------------- + src/kdc/kdc_util.c | 125 +++++++++++++++++++++++---------------------- src/kdc/kdc_util.h | 6 +-- - 3 files changed, 90 insertions(+), 89 deletions(-) + 3 files changed, 87 insertions(+), 86 deletions(-) diff --git a/src/kdc/kdc_log.c b/src/kdc/kdc_log.c index 4eec50373..b160ba21a 100644 @@ -132,57 +132,16 @@ index 0155c28c6..f5c581c82 100644 - * L10_2 = log10(2**x), rounded up; log10(2) ~= 0.301. - */ -#define L10_2(x) ((int)(((x * 301) + 999) / 1000)) -- --/* -- * Max length of sprintf("%ld") for an int of type T; includes leading -- * minus sign and terminating NUL. -- */ --#define D_LEN(t) (L10_2(sizeof(t) * CHAR_BIT) + 2) -- --void --ktypes2str(char *s, size_t len, int nktypes, krb5_enctype *ktype) +/* Wrapper of krb5_enctype_to_name() to include the PKINIT types. */ +static krb5_error_code +enctype_name(krb5_enctype ktype, char *buf, size_t buflen) - { -- int i; -- char stmp[D_LEN(krb5_enctype) + 1]; -- char *p; ++{ + char *name; - -- if (nktypes < 0 -- || len < (sizeof(" etypes {...}") + D_LEN(int))) { -- *s = '\0'; -- return; -- } ++ + if (buflen == 0) + return EINVAL; + *buf = '\0'; /* ensure these are always valid C-strings */ - -- snprintf(s, len, "%d etypes {", nktypes); -- for (i = 0; i < nktypes; i++) { -- snprintf(stmp, sizeof(stmp), "%s%ld", i ? " " : "", (long)ktype[i]); -- if (strlen(s) + strlen(stmp) + sizeof("}") > len) -- break; -- strlcat(s, stmp, len); -- } -- if (i < nktypes) { -- /* -- * We broke out of the loop. Try to truncate the list. -- */ -- p = s + strlen(s); -- while (p - s + sizeof("...}") > len) { -- while (p > s && *p != ' ' && *p != '{') -- *p-- = '\0'; -- if (p > s && *p == ' ') { -- *p-- = '\0'; -- continue; -- } -- } -- strlcat(s, "...", len); -- } -- strlcat(s, "}", len); -- return; ++ + /* rfc4556 recommends that clients wishing to indicate support for these + * pkinit algorithms include them in the etype field of the AS-REQ. */ + if (ktype == ENCTYPE_DSA_SHA1_CMS) @@ -201,47 +160,85 @@ index 0155c28c6..f5c581c82 100644 + name = "des-ede3-cbc-EnvOID"; + else + return krb5_enctype_to_name(ktype, FALSE, buf, buflen); -+ + +-/* +- * Max length of sprintf("%ld") for an int of type T; includes leading +- * minus sign and terminating NUL. +- */ +-#define D_LEN(t) (L10_2(sizeof(t) * CHAR_BIT) + 2) + if (strlcpy(name, buf, buflen) >= buflen) + return ENOMEM; + return 0; ++} + +-void +-ktypes2str(char *s, size_t len, int nktypes, krb5_enctype *ktype) ++char * ++ktypes2str(krb5_enctype *ktype, int nktypes) + { ++ struct k5buf buf; + int i; +- char stmp[D_LEN(krb5_enctype) + 1]; +- char *p; ++ char name[64]; + +- if (nktypes < 0 +- || len < (sizeof(" etypes {...}") + D_LEN(int))) { +- *s = '\0'; +- return; +- } ++ if (nktypes < 0) ++ return NULL; + +- snprintf(s, len, "%d etypes {", nktypes); ++ k5_buf_init_dynamic(&buf); ++ k5_buf_add_fmt(&buf, "%d etypes {", nktypes); + for (i = 0; i < nktypes; i++) { +- snprintf(stmp, sizeof(stmp), "%s%ld", i ? " " : "", (long)ktype[i]); +- if (strlen(s) + strlen(stmp) + sizeof("}") > len) +- break; +- strlcat(s, stmp, len); ++ enctype_name(ktype[i], name, sizeof(name)); ++ k5_buf_add_fmt(&buf, "%s%s(%ld)", i ? ", " : "", name, (long)ktype[i]); + } +- if (i < nktypes) { +- /* +- * We broke out of the loop. Try to truncate the list. +- */ +- p = s + strlen(s); +- while (p - s + sizeof("...}") > len) { +- while (p > s && *p != ' ' && *p != '{') +- *p-- = '\0'; +- if (p > s && *p == ' ') { +- *p-- = '\0'; +- continue; +- } +- } +- strlcat(s, "...", len); +- } +- strlcat(s, "}", len); +- return; ++ k5_buf_add(&buf, "}"); ++ return buf.data; } -void -rep_etypes2str(char *s, size_t len, krb5_kdc_rep *rep) +char * -+ktypes2str(krb5_enctype *ktype, int nktypes) ++rep_etypes2str(krb5_kdc_rep *rep) { - char stmp[sizeof("ses=") + D_LEN(krb5_enctype)]; -+ struct k5buf buf; -+ int i; -+ char name[64]; - +- - if (len < (3 * D_LEN(krb5_enctype) - + sizeof("etypes {rep= tkt= ses=}"))) { - *s = '\0'; - return; -+ if (nktypes < 0) -+ return NULL; -+ -+ k5_buf_init_dynamic(&buf); -+ k5_buf_add_fmt(&buf, "%d etypes {", nktypes); -+ for (i = 0; i < nktypes; i++) { -+ enctype_name(ktype[i], name, sizeof(name)); -+ k5_buf_add_fmt(&buf, "%s%s(%ld)", i ? ", " : "", name, (long)ktype[i]); - } -+ k5_buf_add(&buf, "}"); -+ return buf.data; -+} - -- snprintf(s, len, "etypes {rep=%ld", (long)rep->enc_part.enctype); -+char * -+rep_etypes2str(krb5_kdc_rep *rep) -+{ +- } + struct k5buf buf; + char name[64]; + krb5_enctype etype; -+ + +- snprintf(s, len, "etypes {rep=%ld", (long)rep->enc_part.enctype); + k5_buf_init_dynamic(&buf); + k5_buf_add(&buf, "etypes {rep="); + enctype_name(rep->enc_part.enctype, name, sizeof(name)); diff --git a/Remove-3des-support.patch b/Remove-3des-support.patch index 9214ccb..1e258b9 100644 --- a/Remove-3des-support.patch +++ b/Remove-3des-support.patch @@ -74,7 +74,7 @@ their constants. src/lib/gssapi/krb5/gssapiP_krb5.h | 6 +- src/lib/gssapi/krb5/k5seal.c | 35 +- src/lib/gssapi/krb5/k5sealiov.c | 27 +- - src/lib/gssapi/krb5/k5unseal.c | 102 ++--- + src/lib/gssapi/krb5/k5unseal.c | 88 ++-- src/lib/gssapi/krb5/k5unsealiov.c | 38 +- src/lib/gssapi/krb5/util_crypt.c | 11 - .../api.current/chpass-principal-v2.exp | 4 +- @@ -105,7 +105,7 @@ their constants. src/tests/t_salt.py | 5 +- src/util/k5test.py | 10 - .../leash/htmlhelp/html/Encryption_Types.htm | 13 - - 95 files changed, 162 insertions(+), 4836 deletions(-) + 95 files changed, 155 insertions(+), 4829 deletions(-) delete mode 100644 src/lib/crypto/builtin/des/ISSUES delete mode 100644 src/lib/crypto/builtin/des/Makefile.in delete mode 100644 src/lib/crypto/builtin/des/d3_aead.c @@ -5384,13 +5384,15 @@ index 9b183bc33..f0cc4a680 100644 + if (signalg != SGN_ALG_HMAC_MD5) { *minor_status = 0; return(GSS_S_DEFECTIVE_TOKEN); -- ++ } + - case SGN_ALG_HMAC_SHA1_DES3_KD: - case SGN_ALG_HMAC_MD5: - /* compute the checksum of the message */ - - /* 8 = bytes of token body to be checksummed according to spec */ -- ++ /* compute the checksum of the message */ + - if (! (data_ptr = xmalloc(8 + plainlen))) { - if (sealalg != 0xffff) - xfree(plain); @@ -5399,33 +5401,9 @@ index 9b183bc33..f0cc4a680 100644 - *minor_status = ENOMEM; - return(GSS_S_FAILURE); - } -- -- (void) memcpy(data_ptr, ptr-2, 8); -- -- (void) memcpy(data_ptr+8, plain, plainlen); -- -- plaind.length = 8 + plainlen; -- plaind.data = data_ptr; -- code = krb5_k_make_checksum(context, md5cksum.checksum_type, -- ctx->seq, sign_usage, -- &plaind, &md5cksum); -- xfree(data_ptr); -- -- if (code) { -- if (toktype == KG_TOK_SEAL_MSG) -- gssalloc_free(token.value); -- *minor_status = code; -- return(GSS_S_FAILURE); -- } -- -- code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); -- break; - } - -+ /* compute the checksum of the message */ -+ + /* 8 = bytes of token body to be checksummed according to spec */ -+ + +- (void) memcpy(data_ptr, ptr-2, 8); + if (! (data_ptr = xmalloc(8 + plainlen))) { + if (sealalg != 0xffff) + xfree(plain); @@ -5434,25 +5412,40 @@ index 9b183bc33..f0cc4a680 100644 + *minor_status = ENOMEM; + return(GSS_S_FAILURE); + } -+ + +- (void) memcpy(data_ptr+8, plain, plainlen); + (void) memcpy(data_ptr, ptr-2, 8); -+ + +- plaind.length = 8 + plainlen; +- plaind.data = data_ptr; +- code = krb5_k_make_checksum(context, md5cksum.checksum_type, +- ctx->seq, sign_usage, +- &plaind, &md5cksum); +- xfree(data_ptr); + (void) memcpy(data_ptr+8, plain, plainlen); -+ + +- if (code) { +- if (toktype == KG_TOK_SEAL_MSG) +- gssalloc_free(token.value); +- *minor_status = code; +- return(GSS_S_FAILURE); +- } + plaind.length = 8 + plainlen; + plaind.data = data_ptr; + code = krb5_k_make_checksum(context, md5cksum.checksum_type, + ctx->seq, sign_usage, + &plaind, &md5cksum); + xfree(data_ptr); -+ + +- code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); +- break; + if (code) { + if (toktype == KG_TOK_SEAL_MSG) + gssalloc_free(token.value); + *minor_status = code; + return(GSS_S_FAILURE); -+ } -+ + } + + code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); + krb5_free_checksum_contents(context, &md5cksum); diff --git a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch index 47b013f..334ecff 100644 --- a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch +++ b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch @@ -9,7 +9,7 @@ Subject: [PATCH] Remove Kerberos v4 support vestiges from ccapi src/ccapi/lib/ccapi_v2.c | 34 +-- src/ccapi/lib/win/OldCC/ccapi.h | 20 -- src/ccapi/server/ccs_ccache.c | 69 +----- - src/ccapi/test/test_ccapi_ccache.c | 223 +++----------------- + src/ccapi/test/test_ccapi_ccache.c | 227 +++----------------- src/ccapi/test/test_ccapi_constants.c | 2 - src/ccapi/test/test_ccapi_context.c | 3 - src/ccapi/test/test_ccapi_v2.c | 89 -------- @@ -20,7 +20,7 @@ Subject: [PATCH] Remove Kerberos v4 support vestiges from ccapi src/windows/kfwlogon/kfwlogon.h | 2 +- src/windows/leashdll/leash-int.h | 2 +- src/windows/lib/cacheapi.h | 53 +---- - 15 files changed, 98 insertions(+), 871 deletions(-) + 15 files changed, 100 insertions(+), 873 deletions(-) diff --git a/src/ccapi/common/cci_cred_union.c b/src/ccapi/common/cci_cred_union.c index 4c8981610..424a93dab 100644 @@ -760,29 +760,8 @@ index a0fd84af1..fe63e6710 100644 - cc_ccache_destroy(ccache); - ccache = NULL; - } -+ // replace v5 only ccache's principal -+ if (!err) { -+ err = cc_context_create_new_ccache(context, cc_credentials_v5, -+ "foo@BAZ.ORG", &ccache); -+ } -+ if (!err) { -+ check_once_cc_ccache_set_principal( -+ ccache, cc_credentials_v5, "foo/BAZ@BAR.ORG", ccNoError, -+ "replace v5 only ccache's principal (empty ccache)"); -+ } -+ else { -+ log_error( -+ "cc_context_create_new_ccache failed, can't complete test"); -+ failure_count++; -+ } - -+ // bad params -+ if (!err) { -+ check_once_cc_ccache_set_principal(ccache, cc_credentials_v5, -+ NULL, ccErrBadParam, -+ "NULL principal"); -+ } - +- +- - // empty ccache - - // replace v5 only ccache's principal @@ -858,6 +837,29 @@ index a0fd84af1..fe63e6710 100644 - // replace v4 only ccache's principal - - // add v5 principal to v4 only ccache ++ // replace v5 only ccache's principal ++ if (!err) { ++ err = cc_context_create_new_ccache(context, cc_credentials_v5, ++ "foo@BAZ.ORG", &ccache); ++ } ++ if (!err) { ++ check_once_cc_ccache_set_principal( ++ ccache, cc_credentials_v5, "foo/BAZ@BAR.ORG", ccNoError, ++ "replace v5 only ccache's principal (empty ccache)"); ++ } ++ else { ++ log_error( ++ "cc_context_create_new_ccache failed, can't complete test"); ++ failure_count++; ++ } ++ ++ // bad params ++ if (!err) { ++ check_once_cc_ccache_set_principal(ccache, cc_credentials_v5, ++ NULL, ccErrBadParam, ++ "NULL principal"); ++ } ++ + if (ccache) { + cc_ccache_destroy(ccache); + ccache = NULL; @@ -892,8 +894,7 @@ index a0fd84af1..fe63e6710 100644 } if (!err) { - check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v5, &time_offset, ccNoError, "offset set for v5 but not v4"); -+ check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v5, &time_offset, ccNoError, "offset set for v5"); - } +- } - if (!err) { - check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v4, &time_offset, ccErrTimeOffsetNotSet, "asking for v4 offset when only v5 is set"); - } @@ -902,9 +903,10 @@ index a0fd84af1..fe63e6710 100644 - } - if (!err) { - check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v4, &time_offset, ccNoError, "asking for v4 offset when v4 and v5 are set"); -- } -- ++ check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v5, &time_offset, ccNoError, "offset set for v5"); + } +- check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v5, NULL, ccErrBadParam, "NULL time_offset out param"); - check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v4_v5, &time_offset, ccErrBadCredentialsVersion, "v4_v5 creds_vers in param (invalid)"); diff --git a/Remove-PKINIT-draft-9-support.patch b/Remove-PKINIT-draft-9-support.patch index 3a25343..94700c4 100644 --- a/Remove-PKINIT-draft-9-support.patch +++ b/Remove-PKINIT-draft-9-support.patch @@ -15,12 +15,12 @@ ticket: 8817 (new) src/plugins/preauth/pkinit/pkinit_accessor.h | 6 - src/plugins/preauth/pkinit/pkinit_clnt.c | 231 +++----- src/plugins/preauth/pkinit/pkinit_crypto.h | 1 - - .../preauth/pkinit/pkinit_crypto_openssl.c | 219 ++----- + .../preauth/pkinit/pkinit_crypto_openssl.c | 221 ++------ src/plugins/preauth/pkinit/pkinit_lib.c | 65 --- - src/plugins/preauth/pkinit/pkinit_srv.c | 543 ++++++------------ + src/plugins/preauth/pkinit/pkinit_srv.c | 531 +++++------------- src/plugins/preauth/pkinit/pkinit_trace.h | 4 - src/tests/t_pkinit.py | 6 +- - 10 files changed, 282 insertions(+), 814 deletions(-) + 10 files changed, 277 insertions(+), 809 deletions(-) diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h index fe2ec0d31..b437fd53f 100644 @@ -214,18 +214,7 @@ index 58400d555..1a642139a 100644 - auth_pack.clientDHNonce.length = 0; - auth_pack.clientPublicValue = &info; - auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; -+ memset(&info, 0, sizeof(info)); -+ memset(&auth_pack, 0, sizeof(auth_pack)); -+ auth_pack.pkAuthenticator.ctime = ctsec; -+ auth_pack.pkAuthenticator.cusec = cusec; -+ auth_pack.pkAuthenticator.nonce = nonce; -+ auth_pack.pkAuthenticator.paChecksum = *cksum; -+ if (!reqctx->opts->disable_freshness) -+ auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token; -+ auth_pack.clientDHNonce.length = 0; -+ auth_pack.clientPublicValue = &info; -+ auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; - +- - /* add List of CMS algorithms */ - retval = create_krb5_supportedCMSTypes(context, plgctx->cryptoctx, - reqctx->cryptoctx, @@ -238,6 +227,18 @@ index 58400d555..1a642139a 100644 - pkiDebug("as_req: unrecognized pa_type = %d\n", - (int)reqctx->pa_type); - retval = -1; ++ memset(&info, 0, sizeof(info)); ++ memset(&auth_pack, 0, sizeof(auth_pack)); ++ auth_pack.pkAuthenticator.ctime = ctsec; ++ auth_pack.pkAuthenticator.cusec = cusec; ++ auth_pack.pkAuthenticator.nonce = nonce; ++ auth_pack.pkAuthenticator.paChecksum = *cksum; ++ if (!reqctx->opts->disable_freshness) ++ auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token; ++ auth_pack.clientDHNonce.length = 0; ++ auth_pack.clientPublicValue = &info; ++ auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; ++ + /* add List of CMS algorithms */ + retval = create_krb5_supportedCMSTypes(context, plgctx->cryptoctx, + reqctx->cryptoctx, @@ -355,20 +356,19 @@ index 58400d555..1a642139a 100644 - &req9->signedAuthPack.data, - &req9->signedAuthPack.length); - break; --#ifdef DEBUG_ASN1 ++ &req->signedAuthPack.data, ++ &req->signedAuthPack.length); ++ } ++ + #ifdef DEBUG_ASN1 - print_buffer_bin((unsigned char *)req9->signedAuthPack.data, - req9->signedAuthPack.length, - "/tmp/client_signed_data_draft9"); --#endif -+ &req->signedAuthPack.data, -+ &req->signedAuthPack.length); - } -+ -+#ifdef DEBUG_ASN1 + print_buffer_bin((unsigned char *)req->signedAuthPack.data, + req->signedAuthPack.length, + "/tmp/client_signed_data"); -+#endif + #endif +- } + krb5_free_data(context, coded_auth_pack); if (retval) { @@ -556,13 +556,7 @@ index 8aa2c5257..8c7fd0cca 100644 - goto cleanup2; - PKCS7_add_signed_attribute(p7si, NID_pkcs9_contentType, - V_ASN1_OBJECT, oid_copy); -+ /* create a content-type attr */ -+ oid_copy = OBJ_dup(oid); -+ if (oid_copy == NULL) -+ goto cleanup2; -+ PKCS7_add_signed_attribute(p7si, NID_pkcs9_contentType, -+ V_ASN1_OBJECT, oid_copy); - +- - /* create the signature over signed attributes. get DER encoded value */ - /* This is the place where smartcard signature needs to be calculated */ - sk = p7si->auth_attr; @@ -571,6 +565,13 @@ index 8aa2c5257..8c7fd0cca 100644 - if (abuf == NULL) - goto cleanup2; - } /* signed attributes */ ++ /* create a content-type attr */ ++ oid_copy = OBJ_dup(oid); ++ if (oid_copy == NULL) ++ goto cleanup2; ++ PKCS7_add_signed_attribute(p7si, NID_pkcs9_contentType, ++ V_ASN1_OBJECT, oid_copy); ++ + /* create the signature over signed attributes. get DER encoded value */ + /* This is the place where smartcard signature needs to be calculated */ + sk = p7si->auth_attr; @@ -1040,47 +1041,38 @@ index 6aa646cc6..c44be9c74 100644 if (retval) { TRACE_PKINIT_SERVER_PADATA_VERIFY_FAIL(context); goto cleanup; -@@ -541,118 +513,88 @@ pkinit_server_verify_padata(krb5_context context, +@@ -541,117 +513,87 @@ pkinit_server_verify_padata(krb5_context context, #endif OCTETDATA_TO_KRB5DATA(&authp_data, &k5data); - switch ((int)data->pa_type) { - case KRB5_PADATA_PK_AS_REQ: - retval = k5int_decode_krb5_auth_pack(&k5data, &auth_pack); -+ retval = k5int_decode_krb5_auth_pack(&k5data, &auth_pack); -+ if (retval) { -+ pkiDebug("failed to decode krb5_auth_pack\n"); -+ goto cleanup; -+ } -+ -+ retval = krb5_check_clockskew(context, auth_pack->pkAuthenticator.ctime); -+ if (retval) -+ goto cleanup; -+ -+ /* check dh parameters */ -+ if (auth_pack->clientPublicValue != NULL) { -+ retval = server_check_dh(context, plgctx->cryptoctx, -+ reqctx->cryptoctx, plgctx->idctx, -+ &auth_pack->clientPublicValue->algorithm.parameters, -+ plgctx->opts->dh_min_bits); - if (retval) { +- if (retval) { - pkiDebug("failed to decode krb5_auth_pack\n"); -+ pkiDebug("bad dh parameters\n"); - goto cleanup; - } +- goto cleanup; +- } - - retval = krb5_check_clockskew(context, - auth_pack->pkAuthenticator.ctime); - if (retval) - goto cleanup; -- ++ retval = k5int_decode_krb5_auth_pack(&k5data, &auth_pack); ++ if (retval) { ++ pkiDebug("failed to decode krb5_auth_pack\n"); ++ goto cleanup; ++ } + - /* check dh parameters */ - if (auth_pack->clientPublicValue != NULL) { - retval = server_check_dh(context, plgctx->cryptoctx, - reqctx->cryptoctx, plgctx->idctx, - &auth_pack->clientPublicValue->algorithm.parameters, - plgctx->opts->dh_min_bits); -- ++ retval = krb5_check_clockskew(context, auth_pack->pkAuthenticator.ctime); ++ if (retval) ++ goto cleanup; + - if (retval) { - pkiDebug("bad dh parameters\n"); - goto cleanup; @@ -1096,10 +1088,17 @@ index 6aa646cc6..c44be9c74 100644 - der_req = cb->request_body(context, rock); - retval = krb5_c_make_checksum(context, CKSUMTYPE_NIST_SHA, NULL, - 0, der_req, &cksum); -- if (retval) { ++ /* check dh parameters */ ++ if (auth_pack->clientPublicValue != NULL) { ++ retval = server_check_dh(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, plgctx->idctx, ++ &auth_pack->clientPublicValue->algorithm.parameters, ++ plgctx->opts->dh_min_bits); + if (retval) { - pkiDebug("unable to calculate AS REQ checksum\n"); -- goto cleanup; -- } ++ pkiDebug("bad dh parameters\n"); + goto cleanup; + } - if (cksum.length != auth_pack->pkAuthenticator.paChecksum.length || - k5_bcmp(cksum.contents, - auth_pack->pkAuthenticator.paChecksum.contents, @@ -1171,7 +1170,10 @@ index 6aa646cc6..c44be9c74 100644 - if (!valid_kdcPkId) - pkiDebug("kdcPkId in AS_REQ does not match KDC's cert" - "RFC says to ignore and proceed\n"); -- ++ retval = KRB5KDC_ERR_PA_CHECKSUM_MUST_BE_INCLUDED; ++ goto cleanup; ++ } + - } - /* remember the decoded auth_pack for verify_padata routine */ - reqctx->rcv_auth_pack = auth_pack; @@ -1182,35 +1184,24 @@ index 6aa646cc6..c44be9c74 100644 - retval = k5int_decode_krb5_auth_pack_draft9(&k5data, &auth_pack9); - if (retval) { - pkiDebug("failed to decode krb5_auth_pack_draft9\n"); -- goto cleanup; ++ ftoken = auth_pack->pkAuthenticator.freshnessToken; ++ if (ftoken != NULL) { ++ retval = cb->check_freshness_token(context, rock, ftoken); ++ if (retval) + goto cleanup; - } - if (auth_pack9->clientPublicValue != NULL) { - retval = server_check_dh(context, plgctx->cryptoctx, - reqctx->cryptoctx, plgctx->idctx, - &auth_pack9->clientPublicValue->algorithm.parameters, - plgctx->opts->dh_min_bits); -- ++ valid_freshness_token = TRUE; ++ } + - if (retval) { - pkiDebug("bad dh parameters\n"); - goto cleanup; - } -- } -- /* remember the decoded auth_pack for verify_padata routine */ -- reqctx->rcv_auth_pack9 = auth_pack9; -- auth_pack9 = NULL; -- break; -+ retval = KRB5KDC_ERR_PA_CHECKSUM_MUST_BE_INCLUDED; -+ goto cleanup; - } - -+ ftoken = auth_pack->pkAuthenticator.freshnessToken; -+ if (ftoken != NULL) { -+ retval = cb->check_freshness_token(context, rock, ftoken); -+ if (retval) -+ goto cleanup; -+ valid_freshness_token = TRUE; -+ } -+ + /* check if kdcPkId present and match KDC's subjectIdentifier */ + if (reqp->kdcPkId.data != NULL) { + int valid_kdcPkId = 0; @@ -1223,15 +1214,18 @@ index 6aa646cc6..c44be9c74 100644 + if (!valid_kdcPkId) { + pkiDebug("kdcPkId in AS_REQ does not match KDC's cert; " + "RFC says to ignore and proceed\n"); -+ } -+ } + } +- /* remember the decoded auth_pack for verify_padata routine */ +- reqctx->rcv_auth_pack9 = auth_pack9; +- auth_pack9 = NULL; +- break; + } + /* remember the decoded auth_pack for verify_padata routine */ + reqctx->rcv_auth_pack = auth_pack; + auth_pack = NULL; -+ + if (is_signed) { retval = check_log_freshness(context, plgctx, request, - valid_freshness_token); @@ -682,21 +624,13 @@ cleanup: pkiDebug("pkinit_create_edata failed\n"); } @@ -1420,7 +1414,7 @@ index 6aa646cc6..c44be9c74 100644 } - pkiDebug("%s: return checksum instead of nonce = %d\n", - __FUNCTION__, fixed_keypack); - +- - /* if this is an RFC reply or draft9 client requested a checksum - * in the reply instead of the nonce, create an RFC-style keypack - */ @@ -1430,7 +1424,7 @@ index 6aa646cc6..c44be9c74 100644 - retval = ENOMEM; - goto cleanup; - } -- + - retval = krb5_c_make_checksum(context, 0, - encrypting_key, KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, - req_pkt, &key_pack->asChecksum); diff --git a/Simply-OpenSSL-PKCS7-decryption-code.patch b/Simply-OpenSSL-PKCS7-decryption-code.patch index 973480e..94ef2a1 100644 --- a/Simply-OpenSSL-PKCS7-decryption-code.patch +++ b/Simply-OpenSSL-PKCS7-decryption-code.patch @@ -11,8 +11,8 @@ a larger refactoring] (cherry picked from commit 210356653a2f963ffe9a8a1b1627c64fb8ca7a3d) --- - .../preauth/pkinit/pkinit_crypto_openssl.c | 213 ++++++------------ - 1 file changed, 63 insertions(+), 150 deletions(-) + .../preauth/pkinit/pkinit_crypto_openssl.c | 211 +++++------------- + 1 file changed, 62 insertions(+), 149 deletions(-) diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c index 5ff81d8cf..8aa2c5257 100644 @@ -144,6 +144,17 @@ index 5ff81d8cf..8aa2c5257 100644 - X509_ALGOR *enc_alg=NULL; - STACK_OF(PKCS7_RECIP_INFO) *rsk=NULL; - PKCS7_RECIP_INFO *ri=NULL; +- +- p7->state=PKCS7_S_HEADER; +- +- rsk=p7->d.enveloped->recipientinfo; +- enc_alg=p7->d.enveloped->enc_data->algorithm; +- data_body=p7->d.enveloped->enc_data->enc_data; +- evp_cipher=EVP_get_cipherbyobj(enc_alg->algorithm); +- if (evp_cipher == NULL) { +- PKCS7err(PKCS7_F_PKCS7_DATADECODE,PKCS7_R_UNSUPPORTED_CIPHER_TYPE); +- goto cleanup; +- } + krb5_error_code ret; + int ok = 0, plaintext_len = 0, final_len; + unsigned int keylen = 0, eklen = 0, blocksize; @@ -155,24 +166,13 @@ index 5ff81d8cf..8aa2c5257 100644 + STACK_OF(PKCS7_RECIP_INFO) *rsk = p7->d.enveloped->recipientinfo; + PKCS7_RECIP_INFO *ri = NULL; -- p7->state=PKCS7_S_HEADER; -+ *data_out = NULL; -+ *len_out = 0; - -- rsk=p7->d.enveloped->recipientinfo; -- enc_alg=p7->d.enveloped->enc_data->algorithm; -- data_body=p7->d.enveloped->enc_data->enc_data; -- evp_cipher=EVP_get_cipherbyobj(enc_alg->algorithm); -- if (evp_cipher == NULL) { -- PKCS7err(PKCS7_F_PKCS7_DATADECODE,PKCS7_R_UNSUPPORTED_CIPHER_TYPE); -- goto cleanup; -- } -- - if ((etmp=BIO_new(BIO_f_cipher())) == NULL) { - PKCS7err(PKCS7_F_PKCS7_DATADECODE,ERR_R_BIO_LIB); - goto cleanup; - } -- ++ *data_out = NULL; ++ *len_out = 0; + - /* It was encrypted, we need to decrypt the secret key - * with the private key */ + p7->state = PKCS7_S_HEADER; @@ -195,14 +195,14 @@ index 5ff81d8cf..8aa2c5257 100644 - if (EVP_CipherInit_ex(evp_ctx,evp_cipher,NULL,NULL,NULL,0) <= 0) + evp_cipher = EVP_get_cipherbyobj(enc_alg->algorithm); + if (evp_cipher == NULL) - goto cleanup; -- if (EVP_CIPHER_asn1_to_param(evp_ctx,enc_alg->parameter) < 0) ++ goto cleanup; + keylen = EVP_CIPHER_key_length(evp_cipher); + blocksize = EVP_CIPHER_block_size(evp_cipher); + + evp_ctx = EVP_CIPHER_CTX_new(); + if (evp_ctx == NULL) -+ goto cleanup; + goto cleanup; +- if (EVP_CIPHER_asn1_to_param(evp_ctx,enc_alg->parameter) < 0) + if (!EVP_DecryptInit(evp_ctx, evp_cipher, NULL, NULL) || + EVP_CIPHER_asn1_to_param(evp_ctx, enc_alg->parameter) <= 0) goto cleanup; @@ -212,7 +212,9 @@ index 5ff81d8cf..8aa2c5257 100644 - tkeylen = EVP_CIPHER_CTX_key_length(evp_ctx); - tkey = OPENSSL_malloc(tkeylen); - if (tkey == NULL) -- goto cleanup; ++ tkey = malloc(keylen); ++ if (tkey == NULL || !EVP_CIPHER_CTX_rand_key(evp_ctx, tkey)) + goto cleanup; - if (EVP_CIPHER_CTX_rand_key(evp_ctx, tkey) <= 0) - goto cleanup; - if (ek == NULL) { @@ -220,7 +222,7 @@ index 5ff81d8cf..8aa2c5257 100644 - eklen = tkeylen; - tkey = NULL; - } -- + - if (eklen != (unsigned)EVP_CIPHER_CTX_key_length(evp_ctx)) { - /* Some S/MIME clients don't use the same key - * and effective key length. The key length is @@ -233,29 +235,18 @@ index 5ff81d8cf..8aa2c5257 100644 - } - } - if (EVP_CipherInit_ex(evp_ctx,NULL,NULL,ek,NULL,0) <= 0) -+ tkey = malloc(keylen); -+ if (tkey == NULL || !EVP_CIPHER_CTX_rand_key(evp_ctx, tkey)) - goto cleanup; - -- if (out == NULL) -- out=etmp; -- else -- BIO_push(out,etmp); -- etmp=NULL; +- goto cleanup; + /* Decrypt the secret key with the private key. */ + ret = pkinit_decode_data(context, id_cryptoctx, + ASN1_STRING_get0_data(ri->enc_key), + ASN1_STRING_length(ri->enc_key), &ek, &eklen); + use_key = (ret || eklen != keylen) ? tkey : ek; -- if (data_body->length > 0) -- bio = BIO_new_mem_buf(data_body->data, data_body->length); -- else { -- bio=BIO_new(BIO_s_mem()); -- BIO_set_mem_eof_return(bio,0); -- } -- BIO_push(out,bio); -- bio=NULL; +- if (out == NULL) +- out=etmp; +- else +- BIO_push(out,etmp); +- etmp=NULL; + /* Allocate a plaintext buffer and decrypt data_body into it. */ + plaintext = malloc(data_body->length + blocksize); + if (plaintext == NULL) @@ -269,6 +260,19 @@ index 5ff81d8cf..8aa2c5257 100644 + goto cleanup; + plaintext_len += final_len; +- if (data_body->length > 0) +- bio = BIO_new_mem_buf(data_body->data, data_body->length); +- else { +- bio=BIO_new(BIO_s_mem()); +- BIO_set_mem_eof_return(bio,0); +- } +- BIO_push(out,bio); +- bio=NULL; ++ *len_out = plaintext_len; ++ *data_out = plaintext; ++ plaintext = NULL; ++ ok = 1; + - if (0) { - cleanup: - if (out != NULL) BIO_free_all(out); @@ -285,11 +289,6 @@ index 5ff81d8cf..8aa2c5257 100644 - OPENSSL_free(tkey); - } - return(out); -+ *len_out = plaintext_len; -+ *data_out = plaintext; -+ plaintext = NULL; -+ ok = 1; -+ +cleanup: + EVP_CIPHER_CTX_free(evp_ctx); + zapfree(plaintext, plaintext_len); diff --git a/Update-test-suite-to-avoid-single-DES-enctypes.patch b/Update-test-suite-to-avoid-single-DES-enctypes.patch index 56aa947..a6ef987 100644 --- a/Update-test-suite-to-avoid-single-DES-enctypes.patch +++ b/Update-test-suite-to-avoid-single-DES-enctypes.patch @@ -1931,7 +1931,7 @@ index c061d764e..e8adee234 100644 } { all-enctypes -@@ -248,115 +207,8 @@ set passes { +@@ -248,114 +207,7 @@ set passes { {allow_weak_crypto(server)=false} {dummy=[verbose -log "all default enctypes"]} } @@ -1960,8 +1960,8 @@ index c061d764e..e8adee234 100644 - {dummy=[verbose -log \ - "DES3 TGT, KDC permitting only des-cbc-crc"]} - } - } - +-} +- -# des.md5-tgt is set as unused, since it won't trigger the error case -# if SUPPORT_DESMD5 isn't honored. - @@ -2041,12 +2041,11 @@ index c061d764e..e8adee234 100644 - {master_key_type=aes256-cts-hmac-sha1-96} - {dummy=[verbose -log "AES via TCP"]} - } --} + } -# {supported_enctypes=des-cbc-md5:normal des-cbc-crc:normal twofish256-hmac-sha1:normal } -- + # This shouldn't be necessary on dejagnu-1.4 and later, but 1.3 seems # to need it because its runtest.exp doesn't deal with PASS at all. - if [info exists PASS] { @@ -1095,7 +947,7 @@ proc setup_kerberos_db { standalone } { global REALMNAME KDB5_UTIL KADMIN_LOCAL KEY global tmppwd hostname diff --git a/Use-secure_getenv-where-appropriate.patch b/Use-secure_getenv-where-appropriate.patch index 6d92f10..4775663 100644 --- a/Use-secure_getenv-where-appropriate.patch +++ b/Use-secure_getenv-where-appropriate.patch @@ -15,10 +15,10 @@ ticket: 8800 src/lib/krb5/os/trace.c | 2 +- src/lib/krb5/rcache/rc_base.c | 4 ++-- src/lib/krb5/rcache/rc_io.c | 4 ++-- - src/plugins/preauth/pkinit/pkinit_identity.c | 13 ++++--------- + src/plugins/preauth/pkinit/pkinit_identity.c | 11 +++-------- src/plugins/tls/k5tls/openssl.c | 2 +- src/util/profile/prof_file.c | 2 +- - 12 files changed, 20 insertions(+), 25 deletions(-) + 12 files changed, 19 insertions(+), 24 deletions(-) diff --git a/src/lib/kadm5/alt_prof.c b/src/lib/kadm5/alt_prof.c index 3f6b53651..5531a10fb 100644 @@ -184,7 +184,7 @@ diff --git a/src/plugins/preauth/pkinit/pkinit_identity.c b/src/plugins/preauth/ index 8cd3fc640..b89c5d015 100644 --- a/src/plugins/preauth/pkinit/pkinit_identity.c +++ b/src/plugins/preauth/pkinit/pkinit_identity.c -@@ -29,15 +29,9 @@ +@@ -29,16 +29,10 @@ * SUCH DAMAGES. */ @@ -192,16 +192,16 @@ index 8cd3fc640..b89c5d015 100644 -#include -#include -#include --#include ++#include "pkinit.h" + #include -#include --#include -- - #include "pkinit.h" -+#include -+#include + #include +-#include "pkinit.h" +- static void free_list(char **list) + { @@ -430,7 +424,8 @@ process_option_identity(krb5_context context, switch (idtype) { case IDTYPE_ENVVAR: diff --git a/krb5.spec b/krb5.spec index fa766e1..ff8c2e1 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 40%{?dist} +Release: 41%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -119,6 +119,7 @@ Patch156: Fix-Coverity-defects-in-soft-pkcs11-test-code.patch Patch157: Skip-URI-tests-when-using-asan.patch Patch158: Fix-memory-leaks-in-soft-pkcs11-code.patch Patch159: Initialize-life-rlife-in-kdcpolicy-interface.patch +Patch160: Fix-KCM-client-time-offset-propagation.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -728,6 +729,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Aug 15 2019 Robbie Harwood - 1.17-41 +- Fix KCM client time offset propagation + * Fri Aug 09 2019 Robbie Harwood - 1.17-40 - Initialize life/rlife in kdcpolicy interface From 4906d9dae90ea47c7b565fa3d60725fda688638c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 16 Aug 2019 12:24:27 -0400 Subject: [PATCH 127/304] Support building in COPR now that %{copr_username} is gone --- krb5.spec | 13 +++++-------- 1 file changed, 5 insertions(+), 8 deletions(-) diff --git a/krb5.spec b/krb5.spec index ff8c2e1..c9a28c9 100644 --- a/krb5.spec +++ b/krb5.spec @@ -398,22 +398,19 @@ export SOCKET_WRAPPER_DIR="$PWD/sockets" ; mkdir -p $SOCKET_WRAPPER_DIR export LD_PRELOAD="$PWD/noport.so:libnss_wrapper.so:libsocket_wrapper.so" # ugh. COPR doesn't expose the keyring, so try to cope. -%if 0%{?copr_username:1} -%global keyctl : -%else -%global keyctl keyctl -%endif +KEYCTL=keyctl +keyctl list @u &>/dev/null || KEYCTL=: # Run the test suite. We can't actually run the whole thing in the build # system, but we can at least run more than we used to. The build system may # give us a revoked session keyring, so run affected tests with a new one. make -C src runenv.py : make -C src check TMPDIR=%{_tmppath} -%{keyctl} session - make -C src/lib check TMPDIR=%{_tmppath} OFFLINE=yes +$KEYCTL session - make -C src/lib check TMPDIR=%{_tmppath} OFFLINE=yes make -C src/kdc check TMPDIR=%{_tmppath} -%{keyctl} session - make -C src/appl check TMPDIR=%{_tmppath} +$KEYCTL session - make -C src/appl check TMPDIR=%{_tmppath} make -C src/clients check TMPDIR=%{_tmppath} -%{keyctl} session - make -C src/util check TMPDIR=%{_tmppath} +$KEYCTL session - make -C src/util check TMPDIR=%{_tmppath} %install [ "$RPM_BUILD_ROOT" != '/' ] && rm -rf -- "$RPM_BUILD_ROOT" From 2dabf02464f92b42a3aa079969629d38c94fee3b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 22 Aug 2019 15:53:25 -0400 Subject: [PATCH 128/304] Update FIPS patches to remove SPAKE --- Add-soft-pkcs11-source-code.patch | 2 +- ...-error-on-invalid-enctypes-in-keytab.patch | 2 +- ...ctypes-in-gss_set_allowable_enctypes.patch | 2 +- ...ity-defects-in-soft-pkcs11-test-code.patch | 2 +- Fix-KCM-client-time-offset-propagation.patch | 2 +- Fix-memory-leaks-in-soft-pkcs11-code.patch | 2 +- ...ze-life-rlife-in-kdcpolicy-interface.patch | 2 +- Remove-3des-support.patch | 2 +- ...-PKINIT-draft-9-ASN.1-code-and-types.patch | 2 +- Remove-PKINIT-draft-9-support.patch | 2 +- Remove-now-unused-checksum-functions.patch | 2 +- Remove-strerror-calls-from-k5_get_error.patch | 2 +- Skip-URI-tests-when-using-asan.patch | 2 +- Use-imported-soft-pkcs11-for-tests.patch | 2 +- ...IPS-with-PRNG-and-RADIUS-without-SPA.patch | 84 +++++++++++-------- krb5.spec | 7 +- 16 files changed, 68 insertions(+), 51 deletions(-) rename krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch => krb5-1.17post5-FIPS-with-PRNG-and-RADIUS-without-SPA.patch (90%) diff --git a/Add-soft-pkcs11-source-code.patch b/Add-soft-pkcs11-source-code.patch index 9779459..4152b5e 100644 --- a/Add-soft-pkcs11-source-code.patch +++ b/Add-soft-pkcs11-source-code.patch @@ -1,4 +1,4 @@ -From a8b987b3730214d568cc51ddc1b218677b17b799 Mon Sep 17 00:00:00 2001 +From a186597238ae40e167ce041857b5bd1f94ee2383 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 20 Jun 2019 10:45:18 -0400 Subject: [PATCH] Add soft-pkcs11 source code diff --git a/Don-t-error-on-invalid-enctypes-in-keytab.patch b/Don-t-error-on-invalid-enctypes-in-keytab.patch index e61ae21..cf8daea 100644 --- a/Don-t-error-on-invalid-enctypes-in-keytab.patch +++ b/Don-t-error-on-invalid-enctypes-in-keytab.patch @@ -1,4 +1,4 @@ -From 56f59b21814cca0b68e1506d5d8bd15636812c0f Mon Sep 17 00:00:00 2001 +From 84bb2b804c69830ff2dc405b1a2bd7893291d8e6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 10 Jul 2019 17:10:16 -0400 Subject: [PATCH] Don't error on invalid enctypes in keytab diff --git a/Filter-enctypes-in-gss_set_allowable_enctypes.patch b/Filter-enctypes-in-gss_set_allowable_enctypes.patch index 2c7b0d6..f63eba1 100644 --- a/Filter-enctypes-in-gss_set_allowable_enctypes.patch +++ b/Filter-enctypes-in-gss_set_allowable_enctypes.patch @@ -1,4 +1,4 @@ -From 6aeef2d2e19109cc97f6b1f4621fb97247edfa73 Mon Sep 17 00:00:00 2001 +From aa3b2bb07bf48375b2391b31e68d0abf7ba5e4ea Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 16 Jul 2019 00:15:42 -0400 Subject: [PATCH] Filter enctypes in gss_set_allowable_enctypes() diff --git a/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch b/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch index 737a1b2..a4324c2 100644 --- a/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch +++ b/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch @@ -1,4 +1,4 @@ -From 9fccdd784a639ffc9d4eae723a39e35cb7434fec Mon Sep 17 00:00:00 2001 +From 28db01445d2807d51b5045c0a04d5e49905de504 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 20 Jul 2019 00:51:52 -0400 Subject: [PATCH] Fix Coverity defects in soft-pkcs11 test code diff --git a/Fix-KCM-client-time-offset-propagation.patch b/Fix-KCM-client-time-offset-propagation.patch index 90b1900..4071488 100644 --- a/Fix-KCM-client-time-offset-propagation.patch +++ b/Fix-KCM-client-time-offset-propagation.patch @@ -1,4 +1,4 @@ -From e299c5e9442ade8c0b47d122809f76f03b64e497 Mon Sep 17 00:00:00 2001 +From 7e81b8077cf2cf186dadb96b064573f7c221fbf3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 14 Aug 2019 13:52:27 -0400 Subject: [PATCH] Fix KCM client time offset propagation diff --git a/Fix-memory-leaks-in-soft-pkcs11-code.patch b/Fix-memory-leaks-in-soft-pkcs11-code.patch index 7df892c..9bcb794 100644 --- a/Fix-memory-leaks-in-soft-pkcs11-code.patch +++ b/Fix-memory-leaks-in-soft-pkcs11-code.patch @@ -1,4 +1,4 @@ -From 26aa776c9ce531d4487c40ad6684afef74394bac Mon Sep 17 00:00:00 2001 +From 5cc80472e7a8b0fb3002f229ffb104dccf8bd120 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 5 Aug 2019 01:53:51 -0400 Subject: [PATCH] Fix memory leaks in soft-pkcs11 code diff --git a/Initialize-life-rlife-in-kdcpolicy-interface.patch b/Initialize-life-rlife-in-kdcpolicy-interface.patch index 4e92043..6922f09 100644 --- a/Initialize-life-rlife-in-kdcpolicy-interface.patch +++ b/Initialize-life-rlife-in-kdcpolicy-interface.patch @@ -1,4 +1,4 @@ -From a2065b41a6a89b273b455088a5df5304bfd1f663 Mon Sep 17 00:00:00 2001 +From b448801a1ab19d89cc069e63f5ce5acbc9f3cd8d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Aug 2019 14:07:22 -0400 Subject: [PATCH] Initialize life/rlife in kdcpolicy interface diff --git a/Remove-3des-support.patch b/Remove-3des-support.patch index 1e258b9..f3b07fc 100644 --- a/Remove-3des-support.patch +++ b/Remove-3des-support.patch @@ -1,4 +1,4 @@ -From c524c375aef17009e3dcca4a2001e102e022c24b Mon Sep 17 00:00:00 2001 +From 17365a6131488b518b0f50e08d24697acce79d44 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] Remove 3des support diff --git a/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch b/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch index 658991f..ddbd8bb 100644 --- a/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch +++ b/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch @@ -1,4 +1,4 @@ -From fc909a6d2881c4b434c946023c5f581cec9e96c9 Mon Sep 17 00:00:00 2001 +From 054cd1bad9941e6936345da3e9a839c8fdbd9ba3 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 18 Jun 2019 11:40:48 -0400 Subject: [PATCH] Remove PKINIT draft 9 ASN.1 code and types diff --git a/Remove-PKINIT-draft-9-support.patch b/Remove-PKINIT-draft-9-support.patch index 94700c4..8b43a05 100644 --- a/Remove-PKINIT-draft-9-support.patch +++ b/Remove-PKINIT-draft-9-support.patch @@ -1,4 +1,4 @@ -From b26cbaa597305c9e16b455e4bd310ac86b6221cc Mon Sep 17 00:00:00 2001 +From a3e44c1ab745535fe9e2c396a09ff8d713810cc4 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 18 Jun 2019 13:06:44 -0400 Subject: [PATCH] Remove PKINIT draft 9 support diff --git a/Remove-now-unused-checksum-functions.patch b/Remove-now-unused-checksum-functions.patch index 640f059..e84ae39 100644 --- a/Remove-now-unused-checksum-functions.patch +++ b/Remove-now-unused-checksum-functions.patch @@ -1,4 +1,4 @@ -From 3c132f6e129f3e4805ae44a8db749930f1e398b1 Mon Sep 17 00:00:00 2001 +From 25418e054868301e1a1a5824913b74f2479e1b15 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 28 Jun 2019 13:09:47 -0400 Subject: [PATCH] Remove now-unused checksum functions diff --git a/Remove-strerror-calls-from-k5_get_error.patch b/Remove-strerror-calls-from-k5_get_error.patch index 6dbe4e1..42db53c 100644 --- a/Remove-strerror-calls-from-k5_get_error.patch +++ b/Remove-strerror-calls-from-k5_get_error.patch @@ -1,4 +1,4 @@ -From 80ce19337573b31c372251ea5af4e66f4b75e7ef Mon Sep 17 00:00:00 2001 +From bf8f84d2116af9aba33202f44fdaf04a76430410 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 6 Jun 2019 11:46:58 -0400 Subject: [PATCH] Remove strerror() calls from k5_get_error() diff --git a/Skip-URI-tests-when-using-asan.patch b/Skip-URI-tests-when-using-asan.patch index 1f4ebfc..4c82306 100644 --- a/Skip-URI-tests-when-using-asan.patch +++ b/Skip-URI-tests-when-using-asan.patch @@ -1,4 +1,4 @@ -From 6099c5f17a25971defadde6f8fbc2abaa764462b Mon Sep 17 00:00:00 2001 +From 345ffa545ef85ae5c6384c931759cc5353f4d434 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 3 Aug 2019 13:30:28 -0400 Subject: [PATCH] Skip URI tests when using asan diff --git a/Use-imported-soft-pkcs11-for-tests.patch b/Use-imported-soft-pkcs11-for-tests.patch index 5731866..22e7759 100644 --- a/Use-imported-soft-pkcs11-for-tests.patch +++ b/Use-imported-soft-pkcs11-for-tests.patch @@ -1,4 +1,4 @@ -From 403e72295c80d3ec3343d50bf8f7b1e6525e1ea8 Mon Sep 17 00:00:00 2001 +From 47e66724b9d5cfef84965d99c83d29e4739932e3 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 20 Jun 2019 13:41:57 -0400 Subject: [PATCH] Use imported soft-pkcs11 for tests diff --git a/krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch b/krb5-1.17post5-FIPS-with-PRNG-and-RADIUS-without-SPA.patch similarity index 90% rename from krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch rename to krb5-1.17post5-FIPS-with-PRNG-and-RADIUS-without-SPA.patch index 334a93b..29c8f67 100644 --- a/krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch +++ b/krb5-1.17post5-FIPS-with-PRNG-and-RADIUS-without-SPA.patch @@ -1,10 +1,9 @@ -From fd2088635e27ce571e2d98c40fea34db15243b7a Mon Sep 17 00:00:00 2001 +From ca3c0fc3fd80b3a9953da47f64beb8b24bd46f08 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 -Subject: [PATCH] krb5-1.17post4 FIPS with PRNG, SPAKE, and RADIUS +Subject: [PATCH] krb5-1.17post5 FIPS with PRNG and RADIUS without SPAKE -NB: Use openssl's PRNG in FIPS mode, be aware during SPAKE group -negotiation, and taint within krad. +NB: Use openssl's PRNG in FIPS mode and taint within krad. A lot of the FIPS error conditions from OpenSSL are incredibly mysterious (at best, things return NULL unexpectedly; at worst, @@ -14,10 +13,9 @@ awareness of what we can and can't safely call. This will slow down some calls slightly (FIPS_mode() takes multiple locks), but not for any ciphers we care about - which is to say that -AES is fine. Shame about the SPAKE groups though. +AES is fine. Shame about SPAKE though. -post4 is on top of the 3DES removal. (4 > 3; it makes sense this -time!) +post5 removes SPAKE entirely. --- src/lib/crypto/krb/prng.c | 11 ++++- .../crypto/openssl/enc_provider/camellia.c | 6 +++ @@ -31,8 +29,9 @@ time!) src/lib/krad/remote.c | 10 ++++- src/lib/krad/t_attr.c | 3 +- src/lib/krad/t_attrset.c | 4 +- - src/plugins/preauth/spake/groups.c | 8 ++++ - 13 files changed, 117 insertions(+), 33 deletions(-) + src/plugins/preauth/spake/spake_client.c | 6 +++ + src/plugins/preauth/spake/spake_kdc.c | 6 +++ + 14 files changed, 121 insertions(+), 33 deletions(-) diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c index cb9ca9b98..f0e9984ca 100644 @@ -502,36 +501,51 @@ index 7928335ca..0f9576253 100644 krad_attrset_free(set); /* Manually encode User-Name. */ -diff --git a/src/plugins/preauth/spake/groups.c b/src/plugins/preauth/spake/groups.c -index a195cc195..8a913cb5a 100644 ---- a/src/plugins/preauth/spake/groups.c -+++ b/src/plugins/preauth/spake/groups.c -@@ -56,6 +56,8 @@ - #include "trace.h" +diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c +index 00734a13b..a3ce22b70 100644 +--- a/src/plugins/preauth/spake/spake_client.c ++++ b/src/plugins/preauth/spake/spake_client.c +@@ -38,6 +38,8 @@ #include "groups.h" + #include +#include + - #define DEFAULT_GROUPS_CLIENT "edwards25519" - #define DEFAULT_GROUPS_KDC "" + typedef struct reqstate_st { + krb5_pa_spake *msg; /* set in prep_questions, used in process */ + krb5_keyblock *initial_key; +@@ -375,6 +377,10 @@ clpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, -@@ -102,6 +104,9 @@ find_gdef(int32_t group) - { - size_t i; - -+ if (group == builtin_edwards25519.reg->id && FIPS_mode()) -+ return NULL; + if (maj_ver != 1) + return KRB5_PLUGIN_VER_NOTSUPP; + - for (i = 0; groupdefs[i] != NULL; i++) { - if (groupdefs[i]->reg->id == group) - return groupdefs[i]; -@@ -116,6 +121,9 @@ find_gnum(const char *name) - { - size_t i; - -+ if (strcasecmp(name, builtin_edwards25519.reg->name) == 0 && FIPS_mode()) -+ return 0; ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; + - for (i = 0; groupdefs[i] != NULL; i++) { - if (strcasecmp(name, groupdefs[i]->reg->name) == 0) - return groupdefs[i]->reg->id; + vt = (krb5_clpreauth_vtable)vtable; + vt->name = "spake"; + vt->pa_type_list = pa_types; +diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c +index 59e88409e..1b3e569e9 100644 +--- a/src/plugins/preauth/spake/spake_kdc.c ++++ b/src/plugins/preauth/spake/spake_kdc.c +@@ -41,6 +41,8 @@ + + #include + ++#include ++ + /* + * The SPAKE kdcpreauth module uses a secure cookie containing the following + * concatenated fields (all integer fields are big-endian): +@@ -578,6 +580,10 @@ kdcpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, + + if (maj_ver != 1) + return KRB5_PLUGIN_VER_NOTSUPP; ++ ++ if (FIPS_mode()) ++ return KRB5_CRYPTO_INTERNAL; ++ + vt = (krb5_kdcpreauth_vtable)vtable; + vt->name = "spake"; + vt->pa_type_list = pa_types; diff --git a/krb5.spec b/krb5.spec index c9a28c9..a7c11c0 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 41%{?dist} +Release: 42%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -105,7 +105,6 @@ Patch140: Display-unsupported-enctype-names.patch Patch142: Add-zapfreedata-convenience-function.patch Patch143: Remove-support-for-no-flags-SAM-2-preauth.patch Patch144: Remove-krb5int_c_combine_keys.patch -Patch146: krb5-1.17post4-FIPS-with-PRNG-SPAKE-and-RADIUS.patch Patch147: Remove-strerror-calls-from-k5_get_error.patch Patch148: Remove-PKINIT-draft-9-support.patch Patch149: Remove-PKINIT-draft-9-ASN.1-code-and-types.patch @@ -120,6 +119,7 @@ Patch157: Skip-URI-tests-when-using-asan.patch Patch158: Fix-memory-leaks-in-soft-pkcs11-code.patch Patch159: Initialize-life-rlife-in-kdcpolicy-interface.patch Patch160: Fix-KCM-client-time-offset-propagation.patch +Patch161: krb5-1.17post5-FIPS-with-PRNG-and-RADIUS-without-SPA.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -726,6 +726,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Aug 22 2019 Robbie Harwood - 1.17-42 +- Update FIPS patches to remove SPAKE + * Thu Aug 15 2019 Robbie Harwood - 1.17-41 - Fix KCM client time offset propagation From 6ea5e5fa9a27ef0bf7ff20ef96e6c36197e63f05 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 27 Aug 2019 11:24:25 -0400 Subject: [PATCH 129/304] Simplify krb5_dbe_def_search_enctype() --- Simplify-krb5_dbe_def_search_enctype.patch | 165 +++++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 170 insertions(+), 1 deletion(-) create mode 100644 Simplify-krb5_dbe_def_search_enctype.patch diff --git a/Simplify-krb5_dbe_def_search_enctype.patch b/Simplify-krb5_dbe_def_search_enctype.patch new file mode 100644 index 0000000..f9f9365 --- /dev/null +++ b/Simplify-krb5_dbe_def_search_enctype.patch @@ -0,0 +1,165 @@ +From 18bd513161900357110e96b06c53144a212ab00c Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 22 Aug 2019 16:19:12 -0400 +Subject: [PATCH] Simplify krb5_dbe_def_search_enctype() + +Key data is now sorted in descending kvno order (since commit +44ad57d8d38efc944f64536354435f5b721c0ee0) and key enctypes can be +compared with a simple equality test (since single-DES support was +removed in commit fb2dada5eb89c4cd4e39dedd6dbb7dbd5e94f8b8). Use +these assumptions to simplify krb5_dbe_def_search_enctype(). + +The rewrite contains one probably-unnoticeable bugfix: if enctype, +salttype, and kvno are all given as -1 in a repeated search, yield all +key entries of permitted enctype, not just entries of the maximum +kvno. + +(cherry picked from commit fcfb0e47c995a7e9f956c3716be3175f44ad26e0) +--- + src/lib/kdb/kdb_default.c | 117 +++++++++++++++----------------------- + 1 file changed, 45 insertions(+), 72 deletions(-) + +diff --git a/src/lib/kdb/kdb_default.c b/src/lib/kdb/kdb_default.c +index a1021f13a..231a0d8b4 100644 +--- a/src/lib/kdb/kdb_default.c ++++ b/src/lib/kdb/kdb_default.c +@@ -37,94 +37,67 @@ + + + /* +- * Given a particular enctype and optional salttype and kvno, find the +- * most appropriate krb5_key_data entry of the database entry. +- * +- * If stype or kvno is negative, it is ignored. +- * If kvno is 0 get the key which is maxkvno for the princ and matches +- * the other attributes. ++ * Set *kd_out to the key data entry matching kvno, enctype, and salttype. If ++ * any of those three parameters are -1, ignore them. If kvno is 0, match only ++ * the highest kvno. Begin searching at the index *start and set *start to the ++ * index after the match. Do not return keys of non-permitted enctypes; return ++ * KRB5_KDB_NO_PERMITTED_KEY if the whole list was searched and only ++ * non-permitted matches were found. + */ + krb5_error_code +-krb5_dbe_def_search_enctype(kcontext, dbentp, start, ktype, stype, kvno, kdatap) +- krb5_context kcontext; +- krb5_db_entry *dbentp; +- krb5_int32 *start; +- krb5_int32 ktype; +- krb5_int32 stype; +- krb5_int32 kvno; +- krb5_key_data **kdatap; ++krb5_dbe_def_search_enctype(krb5_context context, krb5_db_entry *ent, ++ krb5_int32 *start, krb5_int32 enctype, ++ krb5_int32 salttype, krb5_int32 kvno, ++ krb5_key_data **kd_out) + { +- int i, idx; +- int maxkvno; +- krb5_key_data *datap; +- krb5_error_code ret; +- krb5_boolean saw_non_permitted = FALSE; +- +- ret = 0; +- if (ktype != -1 && !krb5_is_permitted_enctype(kcontext, ktype)) +- return KRB5_KDB_NO_PERMITTED_KEY; +- +- if (kvno == -1 && stype == -1 && ktype == -1) +- kvno = 0; ++ krb5_key_data *kd; ++ krb5_int32 db_salttype; ++ krb5_boolean saw_non_permitted = FALSE; ++ int i; + +- if (kvno == 0) { +- /* Get the max key version */ +- for (i = 0; i < dbentp->n_key_data; i++) { +- if (kvno < dbentp->key_data[i].key_data_kvno) { +- kvno = dbentp->key_data[i].key_data_kvno; +- } +- } +- } ++ *kd_out = NULL; + +- maxkvno = -1; +- idx = -1; +- datap = (krb5_key_data *) NULL; +- for (i = *start; i < dbentp->n_key_data; i++) { +- krb5_boolean similar; +- krb5_int32 db_stype; +- +- ret = 0; +- if (dbentp->key_data[i].key_data_ver > 1) { +- db_stype = dbentp->key_data[i].key_data_type[1]; +- } else { +- db_stype = KRB5_KDB_SALTTYPE_NORMAL; +- } +- +- /* Match this entry against the arguments. */ +- if (ktype != -1) { +- ret = krb5_c_enctype_compare(kcontext, (krb5_enctype) ktype, +- dbentp->key_data[i].key_data_type[0], +- &similar); +- if (ret != 0 || !similar) +- continue; +- } +- if (stype >= 0 && db_stype != stype) ++ if (enctype != -1 && !krb5_is_permitted_enctype(context, enctype)) ++ return KRB5_KDB_NO_PERMITTED_KEY; ++ if (ent->n_key_data == 0) ++ return KRB5_KDB_NO_MATCHING_KEY; ++ ++ /* Match the highest kvno if kvno is 0. Key data is sorted in descending ++ * order of kvno. */ ++ if (kvno == 0) ++ kvno = ent->key_data[0].key_data_kvno; ++ ++ for (i = *start; i < ent->n_key_data; i++) { ++ kd = &ent->key_data[i]; ++ db_salttype = (kd->key_data_ver > 1) ? kd->key_data_type[1] : ++ KRB5_KDB_SALTTYPE_NORMAL; ++ ++ /* Match this entry against the arguments. Stop searching if we have ++ * passed the entries for the requested kvno. */ ++ if (enctype != -1 && kd->key_data_type[0] != enctype) ++ continue; ++ if (salttype >= 0 && db_salttype != salttype) + continue; +- if (kvno >= 0 && dbentp->key_data[i].key_data_kvno != kvno) ++ if (kvno >= 0 && kd->key_data_kvno < kvno) ++ break; ++ if (kvno >= 0 && kd->key_data_kvno != kvno) + continue; + + /* Filter out non-permitted enctypes. */ +- if (!krb5_is_permitted_enctype(kcontext, +- dbentp->key_data[i].key_data_type[0])) { ++ if (!krb5_is_permitted_enctype(context, kd->key_data_type[0])) { + saw_non_permitted = TRUE; + continue; + } + +- if (dbentp->key_data[i].key_data_kvno > maxkvno) { +- maxkvno = dbentp->key_data[i].key_data_kvno; +- datap = &dbentp->key_data[i]; +- idx = i; +- } ++ *start = i + 1; ++ *kd_out = kd; ++ return 0; + } ++ + /* If we scanned the whole set of keys and matched only non-permitted + * enctypes, indicate that. */ +- if (maxkvno < 0 && *start == 0 && saw_non_permitted) +- ret = KRB5_KDB_NO_PERMITTED_KEY; +- if (maxkvno < 0) +- return ret ? ret : KRB5_KDB_NO_MATCHING_KEY; +- *kdatap = datap; +- *start = idx+1; +- return 0; ++ return (*start == 0 && saw_non_permitted) ? KRB5_KDB_NO_PERMITTED_KEY : ++ KRB5_KDB_NO_MATCHING_KEY; + } + + /* diff --git a/krb5.spec b/krb5.spec index a7c11c0..9c36a6e 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 42%{?dist} +Release: 43%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -120,6 +120,7 @@ Patch158: Fix-memory-leaks-in-soft-pkcs11-code.patch Patch159: Initialize-life-rlife-in-kdcpolicy-interface.patch Patch160: Fix-KCM-client-time-offset-propagation.patch Patch161: krb5-1.17post5-FIPS-with-PRNG-and-RADIUS-without-SPA.patch +Patch162: Simplify-krb5_dbe_def_search_enctype.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -726,6 +727,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Aug 27 2019 Robbie Harwood - 1.17-43 +- Simplify krb5_dbe_def_search_enctype() + * Thu Aug 22 2019 Robbie Harwood - 1.17-42 - Update FIPS patches to remove SPAKE From bff738a25d0479ea297b1dae594a62e63d66eb8d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 12 Sep 2019 10:15:52 -0400 Subject: [PATCH 130/304] Static analyzer appeasement --- ...ull-check-in-krb5_gss_duplicate_name.patch | 28 +++++++++++++++ ...arent-forward-null-in-clnttcp_create.patch | 34 +++++++++++++++++++ krb5.spec | 7 +++- 3 files changed, 68 insertions(+), 1 deletion(-) create mode 100644 Remove-null-check-in-krb5_gss_duplicate_name.patch create mode 100644 Squash-apparent-forward-null-in-clnttcp_create.patch diff --git a/Remove-null-check-in-krb5_gss_duplicate_name.patch b/Remove-null-check-in-krb5_gss_duplicate_name.patch new file mode 100644 index 0000000..685261a --- /dev/null +++ b/Remove-null-check-in-krb5_gss_duplicate_name.patch @@ -0,0 +1,28 @@ +From 7016aa77499732446d7bc838b95810c8cdf5b15b Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 30 Aug 2019 11:19:52 -0400 +Subject: [PATCH] Remove null check in krb5_gss_duplicate_name() + +Within the krb5 mechanism, we require minor_status to be writable +without checking. Remove the null check in krb5_gss_duplicate_name() +to squash a forward-null defect. + +(cherry picked from commit 9fd7bc179f0bd74fc83c1edf0247dcfd87fc73e6) +--- + src/lib/gssapi/krb5/duplicate_name.c | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +diff --git a/src/lib/gssapi/krb5/duplicate_name.c b/src/lib/gssapi/krb5/duplicate_name.c +index b88d97d9d..ea53e9c0d 100644 +--- a/src/lib/gssapi/krb5/duplicate_name.c ++++ b/src/lib/gssapi/krb5/duplicate_name.c +@@ -34,8 +34,7 @@ krb5_gss_duplicate_name(OM_uint32 *minor_status, const gss_name_t input_name, + krb5_error_code code; + krb5_gss_name_t princ, outprinc; + +- if (minor_status) +- *minor_status = 0; ++ *minor_status = 0; + + code = krb5_gss_init_context(&context); + if (code) { diff --git a/Squash-apparent-forward-null-in-clnttcp_create.patch b/Squash-apparent-forward-null-in-clnttcp_create.patch new file mode 100644 index 0000000..084d23a --- /dev/null +++ b/Squash-apparent-forward-null-in-clnttcp_create.patch @@ -0,0 +1,34 @@ +From e2087bcf8a10fa0ecc4f0663e8df9b7ef5752805 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 30 Aug 2019 11:16:58 -0400 +Subject: [PATCH] Squash apparent forward-null in clnttcp_create() + +clnttcp_create() only allows raddr to be NULL if *sockp is set. +Static analyzers cannot know this, so can report a forward null +defect. Add an raddr check before calling connect() to squash the +defect. + +[ghudson@mit.edu: rewrote commit message] + +(cherry picked from commit b2f688eedd4bcca525201ef9485749a8c20b808a) +--- + src/lib/rpc/clnt_tcp.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/src/lib/rpc/clnt_tcp.c b/src/lib/rpc/clnt_tcp.c +index 87761906c..dbd62d0a7 100644 +--- a/src/lib/rpc/clnt_tcp.c ++++ b/src/lib/rpc/clnt_tcp.c +@@ -168,9 +168,9 @@ clnttcp_create( + if (*sockp < 0) { + *sockp = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP); + (void)bindresvport_sa(*sockp, NULL); +- if ((*sockp < 0) +- || (connect(*sockp, (struct sockaddr *)raddr, +- sizeof(*raddr)) < 0)) { ++ if (*sockp < 0 || raddr == NULL || ++ connect(*sockp, (struct sockaddr *)raddr, ++ sizeof(*raddr)) < 0) { + rpc_createerr.cf_stat = RPC_SYSTEMERROR; + rpc_createerr.cf_error.re_errno = errno; + (void)closesocket(*sockp); diff --git a/krb5.spec b/krb5.spec index 9c36a6e..0042a61 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 43%{?dist} +Release: 44%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -121,6 +121,8 @@ Patch159: Initialize-life-rlife-in-kdcpolicy-interface.patch Patch160: Fix-KCM-client-time-offset-propagation.patch Patch161: krb5-1.17post5-FIPS-with-PRNG-and-RADIUS-without-SPA.patch Patch162: Simplify-krb5_dbe_def_search_enctype.patch +Patch163: Squash-apparent-forward-null-in-clnttcp_create.patch +Patch164: Remove-null-check-in-krb5_gss_duplicate_name.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -727,6 +729,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Sep 12 2019 Robbie Harwood - 1.17-44 +- Static analyzer appeasement + * Tue Aug 27 2019 Robbie Harwood - 1.17-43 - Simplify krb5_dbe_def_search_enctype() From 1a6673d2eebb6c0bda2dfcb9fddeecb8315de4f1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 25 Sep 2019 13:15:11 -0400 Subject: [PATCH 131/304] Fix KDC crash when logging PKINIT enctypes (CVE-2019-14844) --- ...C-crash-when-logging-PKINIT-enctypes.patch | 31 +++++++++++++++++++ krb5.spec | 6 +++- 2 files changed, 36 insertions(+), 1 deletion(-) create mode 100644 Fix-KDC-crash-when-logging-PKINIT-enctypes.patch diff --git a/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch b/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch new file mode 100644 index 0000000..947ffe2 --- /dev/null +++ b/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch @@ -0,0 +1,31 @@ +From 55353df13814c6d711a1d947dd6690b334269122 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 25 Sep 2019 12:57:56 -0400 +Subject: [PATCH] Fix KDC crash when logging PKINIT enctypes + +Commit a649279727490687d54becad91fde8cf7429d951 introduced a KDC crash +bug due to transposed strlcpy() arguments. Fix the argument order. + +This bug does not affect any MIT krb5 release, but affects the Fedora +krb5 packages due to backports. CVE-2019-14844 has been issued as a +result. + +ticket: 8772 +(cherry picked from commit 275c9a1aad36a1a7b56042f1a2c21c33e7d16eaf) +--- + src/kdc/kdc_util.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index 23ad6c584..698f18c1c 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1080,7 +1080,7 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) + else + return krb5_enctype_to_name(ktype, FALSE, buf, buflen); + +- if (strlcpy(name, buf, buflen) >= buflen) ++ if (strlcpy(buf, name, buflen) >= buflen) + return ENOMEM; + return 0; + } diff --git a/krb5.spec b/krb5.spec index 0042a61..52ba958 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 44%{?dist} +Release: 45%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -123,6 +123,7 @@ Patch161: krb5-1.17post5-FIPS-with-PRNG-and-RADIUS-without-SPA.patch Patch162: Simplify-krb5_dbe_def_search_enctype.patch Patch163: Squash-apparent-forward-null-in-clnttcp_create.patch Patch164: Remove-null-check-in-krb5_gss_duplicate_name.patch +Patch165: Fix-KDC-crash-when-logging-PKINIT-enctypes.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -729,6 +730,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Sep 25 2019 Robbie Harwood - 1.17-45 +- Fix KDC crash when logging PKINIT enctypes (CVE-2019-14844) + * Thu Sep 12 2019 Robbie Harwood - 1.17-44 - Static analyzer appeasement From 9ce53b906d391547da28260acb8c3b56761c2632 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 2 Oct 2019 11:19:07 -0400 Subject: [PATCH 132/304] Log unknown enctypes as unsupported in KDC --- ...known-enctypes-as-unsupported-in-KDC.patch | 52 +++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 57 insertions(+), 1 deletion(-) create mode 100644 Log-unknown-enctypes-as-unsupported-in-KDC.patch diff --git a/Log-unknown-enctypes-as-unsupported-in-KDC.patch b/Log-unknown-enctypes-as-unsupported-in-KDC.patch new file mode 100644 index 0000000..a93f228 --- /dev/null +++ b/Log-unknown-enctypes-as-unsupported-in-KDC.patch @@ -0,0 +1,52 @@ +From 0f91902e92ea411582e56c0495860d523d223bf9 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 27 Sep 2019 16:55:37 -0400 +Subject: [PATCH] Log unknown enctypes as unsupported in KDC + +Commit 8d8e68283b599e680f9fe45eff8af397e827bd6c logs both invalid and +deprecated enctypes as "DEPRECATED:". An invalid enctype might be too +old or marginal to be supported (like single-DES) or too new to be +recognized. For clarity, prefix invalid enctypes with "UNSUPPORTED:" +instead. + +ticket: 8773 +(cherry picked from commit 5ee99b0007f480f01f86340d1c30da51cc80da96) +--- + src/kdc/kdc_util.c | 18 ++++++++++-------- + 1 file changed, 10 insertions(+), 8 deletions(-) + +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index 698f18c1c..8700ec02c 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1048,20 +1048,22 @@ void limit_string(char *name) + static krb5_error_code + enctype_name(krb5_enctype ktype, char *buf, size_t buflen) + { +- char *name; ++ const char *name, *prefix = ""; + size_t len; + + if (buflen == 0) + return EINVAL; + *buf = '\0'; /* ensure these are always valid C-strings */ + +- if (krb5int_c_deprecated_enctype(ktype)) { +- len = strlcpy(buf, "DEPRECATED:", buflen); +- if (len >= buflen) +- return ENOMEM; +- buflen -= len; +- buf += len; +- } ++ if (!krb5_c_valid_enctype(ktype)) ++ prefix = "UNSUPPORTED:"; ++ else if (krb5int_c_deprecated_enctype(ktype)) ++ prefix = "DEPRECATED:"; ++ len = strlcpy(buf, prefix, buflen); ++ if (len >= buflen) ++ return ENOMEM; ++ buflen -= len; ++ buf += len; + + /* rfc4556 recommends that clients wishing to indicate support for these + * pkinit algorithms include them in the etype field of the AS-REQ. */ diff --git a/krb5.spec b/krb5.spec index 52ba958..ccbae26 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 45%{?dist} +Release: 46%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -124,6 +124,7 @@ Patch162: Simplify-krb5_dbe_def_search_enctype.patch Patch163: Squash-apparent-forward-null-in-clnttcp_create.patch Patch164: Remove-null-check-in-krb5_gss_duplicate_name.patch Patch165: Fix-KDC-crash-when-logging-PKINIT-enctypes.patch +Patch166: Log-unknown-enctypes-as-unsupported-in-KDC.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -730,6 +731,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Oct 02 2019 Robbie Harwood - 1.17-46 +- Log unknown enctypes as unsupported in KDC + * Wed Sep 25 2019 Robbie Harwood - 1.17-45 - Fix KDC crash when logging PKINIT enctypes (CVE-2019-14844) From cbf35c8b1f93d72839738f1ef8bd59b964d864a0 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 8 Nov 2019 20:45:40 +0000 Subject: [PATCH 133/304] Add default_principal_flags to example kdc.conf --- kdc.conf | 1 + krb5.spec | 5 ++++- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/kdc.conf b/kdc.conf index f21c761..5d1571d 100644 --- a/kdc.conf +++ b/kdc.conf @@ -8,6 +8,7 @@ EXAMPLE.COM = { #master_key_type = aes256-cts acl_file = /var/kerberos/krb5kdc/kadm5.acl dict_file = /usr/share/dict/words + default_principal_flags = +preauth admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab supported_enctypes = aes256-cts:normal aes128-cts:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal } diff --git a/krb5.spec b/krb5.spec index ccbae26..57e54a7 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 46%{?dist} +Release: 47%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -731,6 +731,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Nov 08 2019 Robbie Harwood - 1.17-47 +- Add default_principal_flags to example kdc.conf + * Wed Oct 02 2019 Robbie Harwood - 1.17-46 - Log unknown enctypes as unsupported in KDC From 1404656ded9c00ae70542bb7f73a6bf5db07ffdf Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 19 Nov 2019 14:45:23 -0500 Subject: [PATCH 134/304] Use OpenSSL's backported KDFs Restore MD4 in FIPS mode (for samba) --- ...C-crash-when-logging-PKINIT-enctypes.patch | 2 +- Fix-minor-errors-in-softpkcs11.patch | 41 + ...known-enctypes-as-unsupported-in-KDC.patch | 2 +- ...ull-check-in-krb5_gss_duplicate_name.patch | 2 +- Simplify-krb5_dbe_def_search_enctype.patch | 2 +- ...arent-forward-null-in-clnttcp_create.patch | 2 +- ...-suite-cert-message-digest-to-sha256.patch | 638 +++++++++++++++ ...d-version-of-OpenSSL-3-KDF-interface.patch | 746 ++++++++++++++++++ ...t6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 33 +- krb5.spec | 15 +- 10 files changed, 1466 insertions(+), 17 deletions(-) create mode 100644 Fix-minor-errors-in-softpkcs11.patch create mode 100644 Update-test-suite-cert-message-digest-to-sha256.patch create mode 100644 Use-backported-version-of-OpenSSL-3-KDF-interface.patch rename krb5-1.17post5-FIPS-with-PRNG-and-RADIUS-without-SPA.patch => krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch (95%) diff --git a/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch b/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch index 947ffe2..208d2ef 100644 --- a/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch +++ b/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch @@ -1,4 +1,4 @@ -From 55353df13814c6d711a1d947dd6690b334269122 Mon Sep 17 00:00:00 2001 +From b3ccbf6ba3f662d0671b0abd10017562f76a190a Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 25 Sep 2019 12:57:56 -0400 Subject: [PATCH] Fix KDC crash when logging PKINIT enctypes diff --git a/Fix-minor-errors-in-softpkcs11.patch b/Fix-minor-errors-in-softpkcs11.patch new file mode 100644 index 0000000..a19708a --- /dev/null +++ b/Fix-minor-errors-in-softpkcs11.patch @@ -0,0 +1,41 @@ +From df5026b47d2f90729b76071fd7cae48d46c4d1f6 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 8 Nov 2019 14:28:56 -0500 +Subject: [PATCH] Fix minor errors in softpkcs11 + +Fix a printf type mismatch in attributes_match() reported by Coverity, +and a possible uninitizlied use of key_type in add_certificate() +reported by clang. + +[ghudson@mit.edu: squashed commits and rewrote commit message] + +(cherry picked from commit 560e48fee9a192ed4eb1b6cbd62c119087b53948) +--- + src/tests/softpkcs11/main.c | 7 ++++--- + 1 file changed, 4 insertions(+), 3 deletions(-) + +diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c +index a4c3ae78e..1cccdfb43 100644 +--- a/src/tests/softpkcs11/main.c ++++ b/src/tests/softpkcs11/main.c +@@ -261,7 +261,7 @@ attributes_match(const struct st_object *obj, + } + } + if (match == 0) { +- st_logf("type %d attribute have no match\n", attributes[i].type); ++ st_logf("type %lu attribute have no match\n", attributes[i].type); + return 0; + } + } +@@ -553,8 +553,9 @@ add_certificate(char *label, + key_type = CKK_DSA; + break; + default: +- /* XXX */ +- break; ++ st_logf("invalid key_type\n"); ++ ret = CKR_GENERAL_ERROR; ++ goto out; + } + + c = CKO_CERTIFICATE; diff --git a/Log-unknown-enctypes-as-unsupported-in-KDC.patch b/Log-unknown-enctypes-as-unsupported-in-KDC.patch index a93f228..4938bd7 100644 --- a/Log-unknown-enctypes-as-unsupported-in-KDC.patch +++ b/Log-unknown-enctypes-as-unsupported-in-KDC.patch @@ -1,4 +1,4 @@ -From 0f91902e92ea411582e56c0495860d523d223bf9 Mon Sep 17 00:00:00 2001 +From 3324eb7fcc3cf4effdde891cefdc37526ff20cf7 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 27 Sep 2019 16:55:37 -0400 Subject: [PATCH] Log unknown enctypes as unsupported in KDC diff --git a/Remove-null-check-in-krb5_gss_duplicate_name.patch b/Remove-null-check-in-krb5_gss_duplicate_name.patch index 685261a..1bb832f 100644 --- a/Remove-null-check-in-krb5_gss_duplicate_name.patch +++ b/Remove-null-check-in-krb5_gss_duplicate_name.patch @@ -1,4 +1,4 @@ -From 7016aa77499732446d7bc838b95810c8cdf5b15b Mon Sep 17 00:00:00 2001 +From 09855e99697edcfb6228f266e8c7b6889ea48b23 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 30 Aug 2019 11:19:52 -0400 Subject: [PATCH] Remove null check in krb5_gss_duplicate_name() diff --git a/Simplify-krb5_dbe_def_search_enctype.patch b/Simplify-krb5_dbe_def_search_enctype.patch index f9f9365..64bf9b0 100644 --- a/Simplify-krb5_dbe_def_search_enctype.patch +++ b/Simplify-krb5_dbe_def_search_enctype.patch @@ -1,4 +1,4 @@ -From 18bd513161900357110e96b06c53144a212ab00c Mon Sep 17 00:00:00 2001 +From f311350db606e8395930b8b1e4d821096133d3c4 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Aug 2019 16:19:12 -0400 Subject: [PATCH] Simplify krb5_dbe_def_search_enctype() diff --git a/Squash-apparent-forward-null-in-clnttcp_create.patch b/Squash-apparent-forward-null-in-clnttcp_create.patch index 084d23a..b89761c 100644 --- a/Squash-apparent-forward-null-in-clnttcp_create.patch +++ b/Squash-apparent-forward-null-in-clnttcp_create.patch @@ -1,4 +1,4 @@ -From e2087bcf8a10fa0ecc4f0663e8df9b7ef5752805 Mon Sep 17 00:00:00 2001 +From d52e7db97781dbdb518368e143c031ed5c6217cc Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 30 Aug 2019 11:16:58 -0400 Subject: [PATCH] Squash apparent forward-null in clnttcp_create() diff --git a/Update-test-suite-cert-message-digest-to-sha256.patch b/Update-test-suite-cert-message-digest-to-sha256.patch new file mode 100644 index 0000000..1de5b28 --- /dev/null +++ b/Update-test-suite-cert-message-digest-to-sha256.patch @@ -0,0 +1,638 @@ +From 264cc429ce5fee191738d74f14d34ce91944ec2f Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 12 Nov 2019 13:38:59 -0500 +Subject: [PATCH] Update test suite cert message digest to sha256 + +Certain openssl configurations (such as Debian testing) will fail out +the sha1 certificates with errors like "ssl.SSLError: [SSL: +CA_MD_TOO_WEAK] ca md too weak (_ssl.c:3833)" or similar. Also update +the certs in question. + +(cherry picked from commit b1c258c6aab95198bdc340b86ca67cbd531464f8) +--- + src/tests/dejagnu/proxy-certs/ca.pem | 52 +++++----- + src/tests/dejagnu/proxy-certs/make-certs.sh | 2 +- + .../dejagnu/proxy-certs/proxy-badsig.pem | 96 +++++++++--------- + src/tests/dejagnu/proxy-certs/proxy-ideal.pem | 98 +++++++++---------- + .../dejagnu/proxy-certs/proxy-no-match.pem | 98 +++++++++---------- + src/tests/dejagnu/proxy-certs/proxy-san.pem | 98 +++++++++---------- + .../dejagnu/proxy-certs/proxy-subject.pem | 98 +++++++++---------- + 7 files changed, 271 insertions(+), 271 deletions(-) + +diff --git a/src/tests/dejagnu/proxy-certs/ca.pem b/src/tests/dejagnu/proxy-certs/ca.pem +index e0f8dc73c..ee24cba81 100644 +--- a/src/tests/dejagnu/proxy-certs/ca.pem ++++ b/src/tests/dejagnu/proxy-certs/ca.pem +@@ -1,28 +1,28 @@ + -----BEGIN CERTIFICATE----- +-MIIEuzCCA6OgAwIBAgIBATANBgkqhkiG9w0BAQUFADCBmTELMAkGA1UEBhMCVVMx +-FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcTCUNhbWJyaWRnZTEMMAoG +-A1UEChMDTUlUMSIwIAYDVQQLExlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww +-KgYDVQQDFCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x +-NDA1MDIxOTA2MDhaFw0yNTA0MTQxOTA2MDhaMIGZMQswCQYDVQQGEwJVUzEWMBQG +-A1UECBMNTWFzc2FjaHVzZXR0czESMBAGA1UEBxMJQ2FtYnJpZGdlMQwwCgYDVQQK +-EwNNSVQxIjAgBgNVBAsTGUluc2VjdXJlIEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNV +-BAMUI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlMIIBIjANBgkq +-hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1zudnpN8FP7iLn1vgkyTSn/RQxXx1yt6 +-zikHaMrVPjkjXPPUoCFpWS3eeI4aQFoj93L5MwZDmSxOflBAqLwV2AMAacrYnNPJ +-IkHtbYKdVsvw9b4INTWqV9/DOODO7UowyMppmO35/pUXaLL+AjHjLw1/EhQ3ZYtq +-fpAMOkf5TnS5GtqZFlrYgZKE8vTC8BxDKM7FYhWYz7kp/tG3S8O/RTnP7Nd+h1Yd +-pmlHBGfuwIRIJz5xNw6KIcCy3Q0NNoKnh00WVwLmR+x11BGSkMjiZZkwJ5D0RObS +-g13QD/itrGoV2gtPzjQgNPfTrjsMvyOWAAFrWVR3QLTxnnmXsqnXvwIDAQABo4IB +-CjCCAQYwHQYDVR0OBBYEFHO5+DSYzq8rvQhUldyvn0y4AqlHMIHGBgNVHSMEgb4w +-gbuAFHO5+DSYzq8rvQhUldyvn0y4AqlHoYGfpIGcMIGZMQswCQYDVQQGEwJVUzEW +-MBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAGA1UEBxMJQ2FtYnJpZGdlMQwwCgYD +-VQQKEwNNSVQxIjAgBgNVBAsTGUluc2VjdXJlIEtlcmJlcm9zIHRlc3QgQ0ExLDAq +-BgNVBAMUI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlggEBMAsG +-A1UdDwQEAwIB/jAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQAM +-Mf4ptC6WoQBH3GoTfgBL0WlIeYeSFmLO7IaSjpK0FV6F/yF7iPFSXcpmu23m6USY +-LRSxnAvxFTi+h1S5Za9O2Pjq88R9nHmesg4v8HJqOw4HpkDowYo2lumjIMfAutyR +-MQUOujYJW1WyZ2PidN5M1exDeMgQN9nVjUCx/WKD9fnzOjOOR1Sc8Us2KpoyccIi +-A+ABHubCvSO3cln0Sp7qjkssJScZtouzPu8FYiroTIR+1oSIKTpJiik1EptlsTea +-L6fHTMHspFhZaiUJFHWTBAgn/dT+UkFntHdHGI6HWBThFVW05hKoarBA7N25W7FN +-AHyfC0lKds4qFiBQkpdi ++MIIEuzCCA6OgAwIBAgIBATANBgkqhkiG9w0BAQsFADCBmTELMAkGA1UEBhMCVVMx ++FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG ++A1UECgwDTUlUMSIwIAYDVQQLDBlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww ++KgYDVQQDDCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x ++OTExMTIxODMwMzRaFw0zMDEwMjUxODMwMzRaMIGZMQswCQYDVQQGEwJVUzEWMBQG ++A1UECAwNTWFzc2FjaHVzZXR0czESMBAGA1UEBwwJQ2FtYnJpZGdlMQwwCgYDVQQK ++DANNSVQxIjAgBgNVBAsMGUluc2VjdXJlIEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNV ++BAMMI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlMIIBIjANBgkq ++hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA54HCeTTUe127pqjK8r28NGMw2r2x+hWK ++KayH5NmqOqnwnzRHkZE5UjkazQ/h97S6LZ6Yb8w3mJEyX1PdcNARDw2mbOPFk5N9 ++uXnBb6AZog7hh9wMe//g9a7PpKanfw69fSVgAr49TFFiLoKuyTgHiJOB7YgP0bTH ++EO4lLqusPQM16lRDSdoXg42udAh3uBY+QDs23snLSiB+9vt8gt6gXiaYb3BBOWs9 ++B3PKs374N9kOPsgcj+8kyR/M+q+RfK5biqS3ce/sxvPV0Kseh//1uJxlbQCwOiBd ++3TLWHLhW9F7rzEcvzn1Mfck35s0XDDRlGxRGGDy+ZCKmxf8Zu/8SwwIDAQABo4IB ++CjCCAQYwHQYDVR0OBBYEFPf/vJvFMCwrABeCC0sq7RGfYeIiMIHGBgNVHSMEgb4w ++gbuAFPf/vJvFMCwrABeCC0sq7RGfYeIioYGfpIGcMIGZMQswCQYDVQQGEwJVUzEW ++MBQGA1UECAwNTWFzc2FjaHVzZXR0czESMBAGA1UEBwwJQ2FtYnJpZGdlMQwwCgYD ++VQQKDANNSVQxIjAgBgNVBAsMGUluc2VjdXJlIEtlcmJlcm9zIHRlc3QgQ0ExLDAq ++BgNVBAMMI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlggEBMAsG ++A1UdDwQEAwIB/jAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBz ++q/t9amz4ahTFNc0v69NZrfCBgo7DWBHxXuE0Gov2/RBPwP/+Efrd4+1Tl5fSv6We ++N/cttEUTTM3Z7wtof3mkSQwkozwWpaHXm31St+0FbTuHNpN4i0Uae5lsO8/pTz/L ++VqsVLjGGpkZKP831BO9oJJbwUASNc2dpLs94pojlSlSZzf/u/T+k0wltgZexnQpU ++5IrdPIqteB32ym2XjZWSCS29jL3zoZ/y8UAPIOR/Zi77wNCehOuBx2bzc/P6RNLa ++CuuPMhDu8PPYVB3rfJInmF5wT5jQ9YX4UUb0qYXDRff5/l26fEjLHQSrA/iMqdIW ++dsDwkqTcy1lOjcP3xOMq + -----END CERTIFICATE----- +diff --git a/src/tests/dejagnu/proxy-certs/make-certs.sh b/src/tests/dejagnu/proxy-certs/make-certs.sh +index 24ef91bde..7a40e2b98 100755 +--- a/src/tests/dejagnu/proxy-certs/make-certs.sh ++++ b/src/tests/dejagnu/proxy-certs/make-certs.sh +@@ -25,7 +25,7 @@ private_key = $PWD/privkey.pem + default_days = $DAYS + x509_extensions = exts_proxy + policy = proxyname +-default_md = sha1 ++default_md = sha256 + unique_subject = no + email_in_dn = no + +diff --git a/src/tests/dejagnu/proxy-certs/proxy-badsig.pem b/src/tests/dejagnu/proxy-certs/proxy-badsig.pem +index 2b31f7d6a..40001d974 100644 +--- a/src/tests/dejagnu/proxy-certs/proxy-badsig.pem ++++ b/src/tests/dejagnu/proxy-certs/proxy-badsig.pem +@@ -1,56 +1,56 @@ + -----BEGIN RSA PRIVATE KEY----- +-MIIEpQIBAAKCAQEA1zudnpN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPU +-oCFpWS3eeI4aQFoj93L5MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4I +-NTWqV9/DOODO7UowyMppmO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZ +-FlrYgZKE8vTC8BxDKM7FYhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5x +-Nw6KIcCy3Q0NNoKnh00WVwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtP +-zjQgNPfTrjsMvyOWAAFrWVR3QLTxnnmXsqnXvwIDAQABAoIBAQCqvhpeMDXhGgoo +-Q03wmfrGwPsrMv91aIK1hYrhMPdVs1JAbRYiKh8+pcq07FYa8udRaB4UwkVh/+oM +-/nEs6niRsl/jjQ2l68TFrnNByroynvr6l9Q/EeGecF6Ygo7lY1OsFhcLQM5vjarS +-XhxvdU/6hcRmfS8tGRpUaMWqfmpiN3YgJcgt8SoYhiwAYDTMJjNyWC61lO7IqNVR +-4kntiM24sfAu1sdZynX8Gp2GrpNChapEuhilQ8RayjuStEYr2abcSIjfZFHQXN7o +-TnjL+AQUzc/ZTXDGnIe9ZzZeFz8UCueeoN6KPxfrq9UUWRL6qt7gOIMdhYR6lFxt +-6pj6kLhxAoGBAO5DTnTKDfCMY2/AsTzCJvMGSY0bT1rsdDxrpqjrbUSeMHV3s5Lm +-vEPnnm+05FD/vi99+HZjHXAZFkhA3ubij2qWFPBnQ5YUoh17IW/Ae4bzY2uXikgL +-tLZ+R+OrcGYQQlvPn//PLsxbfdk5vraqzm08kIX0T4o4Iz8ST5NFJ8hVAoGBAOdB +-ahXr14563Cjeu0pSQ1nXoz3IXdnDwePXasYhxQHl8Ayk8qZS5pt7r07H3dqq6pvn +-e09gZINJe47B9UhkR3H5bPyz/kujKS4zqo3Zlbryzm3V0BWqjNj+j8E2YuQKNQr+ +-c480jn2FzwW66w0i3n4U4KUn1w2/iq5AnVzyNkPDAoGAWLYEsyU79XE/4K79DqM3 +-P0r6/afKbw8U5B4syj4FzAOeBU6RNMPmGt5VNkBCtgnSdPpRFTsoDcG5cyN8GrkG +-Lug8WZoJJwr9pT5gH6yqEX/zZ27f1J1PJpd0CsedLNMm8eonJ2arhPkXrVZ7tKV6 +-AGAJa2agatUmAmi96hZYjpUCgYEA32abJEgsedEIhFb/GYI03ELryRCaUXfCA+gj +-lvoihn3qE1z5qGGns4adyX5dPRQmBqxtvDXDg+zl9vg6i0+MkXdCqTD8tXcOnjp9 +-RgFvmyVa9FI8beHPpQTuPNncWK3fpho/6pT8Hhi48LEsxwjrZWOnzQSaxQZH46Q6 +-IQNAFt8CgYEAkflxXvA2/2naix+riaBzv5EVJB7ilbfWiWtq2LEAtwrQ5XNFjrtK +-g45jKrZ/ezAzTfPa5Dwn4xcImd0MIavnJhDu2ATxMGB0GATLlDH2HZvU7UwKLpTW +-6Hlol4yRcX4GSEOxJ2ZpWYNIOYH0yDf1qLJXs1j8Fi3zWRe+V1kff4w= ++MIIEpAIBAAKCAQEA54HCeTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRH ++kZE5UjkazQ/h97S6LZ6Yb8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wM ++e//g9a7PpKanfw69fSVgAr49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRD ++SdoXg42udAh3uBY+QDs23snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgc ++j+8kyR/M+q+RfK5biqS3ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcv ++zn1Mfck35s0XDDRlGxRGGDy+ZCKmxf8Zu/8SwwIDAQABAoIBAGxzOBQpsIReQ6Lu ++HaybP4hXEzLVfIOIBaJCJaMKaJl0tLkP95r0qiKfh7OahiPRMQpf6k8tHrpFApDv ++q6PGhMdFgLov9YWNqW7y37AYEwn86KAJcHvCQbM2AiXCwGJgGFqA4LpIPlT7JwBc ++zd6LddQALfSFMcvuYPbIaPi1CUnGy/AAyxGjUrc60KO57NbI+dHSTOwTHO1QjOz9 ++ESk4fb34beUuZQzR6s/s1N0k09GJyklLpAAblRs5M6w9IlAn781eRLUAHTafLm4b ++21J9k2Q2UaOofn0Cvh8ggyJMiYqAJ0CsRy5pJroEyboA51WU+8THNFkNtRX5SxY5 ++YY3xE7ECgYEA/qkq7BPMkr/SnBPm32G1Eux5eLVd65qbox0oTLodZbusuxutqXTp ++1MseDPQtHlrq6CQBizwElx//pdKnIiU9iBS/QkMR9CviitMTt+WrWRrM54/A4CJP ++AU2Jg7b2DmhW1ombHHiBZ1tWzyiv9zxrtwR8kmKqv9aTOuPn4l7jY5kCgYEA6Llr ++47pQjp/YhkBBvlriRwM9RXek++ythgsWvEswORaUalnaZ9gxZOKKas35GLDDuVyT ++RnEhIqVlTg9iz6x5fXRtm6VzQvy9yFLzPMnlwsiSnRNOfMVIETUTOhNgm45tYY8f ++lN5bcdY6k6VZ/g/N3zqddnxkjocrd6lAayjjIrsCgYEAyZLYAcPuQx6JM7fhIGIz ++tQXvZKeS7yITHbq/onQTPuqd4AEZpi9/w0r/v1srt4JZvGR7wF1CeOkAL56dYr69 ++hNB/T5DNTkvKZv6K9h5aUg6PsJ8uGXuus6ZPOi4BeAgI7IpBd/i+3TQEc7eOCZIO ++5PAtNqXY6D6NjajGbH2VWckCgYA2KRDmyrF8v86QT9v9BQGsLSDRTerjhk1L6MC9 ++yXHLl2mq5oZhrHqyU9aKzKywBlNGjDjqJ+HiQkO1SvdgBW+wtqvbkUGl0VQJjuR0 ++vTfvgOY+EAQwHWmMN6Hl3iSZjyf9kGV1K9p0P7saKV0sN1leHjIPJRvx35tKGeWY ++CsfxiQKBgQCVUvsX/HeWyc4bxxMuzw8JniUG2JftZqIC1haHEFNElASjt4hARM7Y ++X/dkpYPXOZaN+qfvP949rS1WPXRtwMjt7bYzm7MGbXW7OiGGY3LV2CuVmbXJupvr ++Usvi+YnpqKDY/miOYd+541NJm76AQTSgQ8K7XitX7Beddh1U9e17mg== + -----END RSA PRIVATE KEY----- + -----BEGIN CERTIFICATE----- +-MIIE3TCCA8WgAwIBAgIBBTANBgkqhkiG9w0BAQUFADCBmTELMAkGA1UEBhMCVVMx +-FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcTCUNhbWJyaWRnZTEMMAoG +-A1UEChMDTUlUMSIwIAYDVQQLExlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww +-KgYDVQQDFCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x +-NDA1MDIxOTA2MDlaFw0yNTA0MTQxOTA2MDlaME8xCzAJBgNVBAYTAlVTMRYwFAYD +-VQQIEw1NYXNzYWNodXNldHRzMRQwEgYDVQQKEwtLUkJURVNULkNPTTESMBAGA1UE +-AxMJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1zud +-npN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPUoCFpWS3eeI4aQFoj93L5 +-MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4INTWqV9/DOODO7UowyMpp +-mO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZFlrYgZKE8vTC8BxDKM7F +-YhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5xNw6KIcCy3Q0NNoKnh00W +-VwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtPzjQgNPfTrjsMvyOWAAFr +-WVR3QLTxnnmXsqnXvwIDAQABo4IBdzCCAXMwHQYDVR0OBBYEFHO5+DSYzq8rvQhU +-ldyvn0y4AqlHMIHGBgNVHSMEgb4wgbuAFHO5+DSYzq8rvQhUldyvn0y4AqlHoYGf +-pIGcMIGZMQswCQYDVQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAG +-A1UEBxMJQ2FtYnJpZGdlMQwwCgYDVQQKEwNNSVQxIjAgBgNVBAsTGUluc2VjdXJl +-IEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNVBAMUI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5v ++MIIE3TCCA8WgAwIBAgIBBTANBgkqhkiG9w0BAQsFADCBmTELMAkGA1UEBhMCVVMx ++FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG ++A1UECgwDTUlUMSIwIAYDVQQLDBlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww ++KgYDVQQDDCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x ++OTExMTIxODMwMzRaFw0zMDEwMjUxODMwMzRaME8xCzAJBgNVBAYTAlVTMRYwFAYD ++VQQIDA1NYXNzYWNodXNldHRzMRQwEgYDVQQKDAtLUkJURVNULkNPTTESMBAGA1UE ++AwwJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA54HC ++eTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRHkZE5UjkazQ/h97S6LZ6Y ++b8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wMe//g9a7PpKanfw69fSVg ++Ar49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRDSdoXg42udAh3uBY+QDs2 ++3snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgcj+8kyR/M+q+RfK5biqS3 ++ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcvzn1Mfck35s0XDDRlGxRG ++GDy+ZCKmxf8Zu/8SwwIDAQABo4IBdzCCAXMwHQYDVR0OBBYEFPf/vJvFMCwrABeC ++C0sq7RGfYeIiMIHGBgNVHSMEgb4wgbuAFPf/vJvFMCwrABeCC0sq7RGfYeIioYGf ++pIGcMIGZMQswCQYDVQQGEwJVUzEWMBQGA1UECAwNTWFzc2FjaHVzZXR0czESMBAG ++A1UEBwwJQ2FtYnJpZGdlMQwwCgYDVQQKDANNSVQxIjAgBgNVBAsMGUluc2VjdXJl ++IEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNVBAMMI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5v + dCB1c2Ugb3RoZXJ3aXNlggEBMAsGA1UdDwQEAwID6DAMBgNVHRMBAf8EAjAAMFkG + A1UdEQRSMFCCFnByb3h5xaB1YmplY3TDhGx0w5FhbWWCE3Byb3h5U3ViamVjdEFs + dE5hbWWHBH8AAAGHEAAAAAAAAAAAAAAAAAAAAAGCCWxvY2FsaG9zdDATBgNVHSUE +-DDAKBggrBgEFBQcDATANBgkqhkiG9w0BAQUFAAOCAQEAfTctgFjQSaevBi64q7yh +-GNsK3PqeNEALZz4pSXRbOwm0E4RpYIS7uqg1C4zJ5Zbd4V/dOX7q+T/iBS7gErzS +-rj21jH3Ggc92TmXzcFxMDCxLV0hO8xFkqg3P4sslJESOHxvEMTTf5s893yUb8vJ/ +-DCvZXXRoRwPot9MFozkmcQcaTNunREWFvn4i4JXcMCSAfWTd+/VkpVsy69u3tj68 +-7G2/K5nalvZikutEC+DyfyBuvDAoxIYzCi3VtQxCalW28Q5hzWV21QsvKTP5QBsh +-RaU2r0O58lZPPvrOrtWQBCudUgsnoraVLrjJshEQ4z/ZAAAAAAAAAAAAAAAAAAAA ++DDAKBggrBgEFBQcDATANBgkqhkiG9w0BAQsFAAOCAQEAsMRJnxdbnpm5VlCFwNyU ++8ra1wCjj+ZH0POVCM4iXQ77bV6UBpcqlaQUvR7R/H1Bt5t3Cp0ycN/dy+RcXtj+5 ++FA84bRM767rsakxTEwjOjWw6GiK6bGjBfQ4F6Q97ELmiM0OZgmW8D56UHZxrI+o7 ++QrKWBpFf1UA8n/BmupHBtyW3gudtJS9a71u6lBRydPFqJ4l8YxHckbgPFceSRbRj ++x7E2pQVQ0p2nvG/NVyuC+2L29p81KAsG3vPzwOOfr1Tnpl1/B4R0+XEIy33KHpbz ++Ceyitz6k16fOVNxMI59W2OACPTQ/s99kygh+cARRPfEUAAAAAAAAAAAAAAAAAAAA + AA== + -----END CERTIFICATE----- +diff --git a/src/tests/dejagnu/proxy-certs/proxy-ideal.pem b/src/tests/dejagnu/proxy-certs/proxy-ideal.pem +index 4588f7d4e..3bb09dc94 100644 +--- a/src/tests/dejagnu/proxy-certs/proxy-ideal.pem ++++ b/src/tests/dejagnu/proxy-certs/proxy-ideal.pem +@@ -1,56 +1,56 @@ + -----BEGIN RSA PRIVATE KEY----- +-MIIEpQIBAAKCAQEA1zudnpN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPU +-oCFpWS3eeI4aQFoj93L5MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4I +-NTWqV9/DOODO7UowyMppmO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZ +-FlrYgZKE8vTC8BxDKM7FYhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5x +-Nw6KIcCy3Q0NNoKnh00WVwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtP +-zjQgNPfTrjsMvyOWAAFrWVR3QLTxnnmXsqnXvwIDAQABAoIBAQCqvhpeMDXhGgoo +-Q03wmfrGwPsrMv91aIK1hYrhMPdVs1JAbRYiKh8+pcq07FYa8udRaB4UwkVh/+oM +-/nEs6niRsl/jjQ2l68TFrnNByroynvr6l9Q/EeGecF6Ygo7lY1OsFhcLQM5vjarS +-XhxvdU/6hcRmfS8tGRpUaMWqfmpiN3YgJcgt8SoYhiwAYDTMJjNyWC61lO7IqNVR +-4kntiM24sfAu1sdZynX8Gp2GrpNChapEuhilQ8RayjuStEYr2abcSIjfZFHQXN7o +-TnjL+AQUzc/ZTXDGnIe9ZzZeFz8UCueeoN6KPxfrq9UUWRL6qt7gOIMdhYR6lFxt +-6pj6kLhxAoGBAO5DTnTKDfCMY2/AsTzCJvMGSY0bT1rsdDxrpqjrbUSeMHV3s5Lm +-vEPnnm+05FD/vi99+HZjHXAZFkhA3ubij2qWFPBnQ5YUoh17IW/Ae4bzY2uXikgL +-tLZ+R+OrcGYQQlvPn//PLsxbfdk5vraqzm08kIX0T4o4Iz8ST5NFJ8hVAoGBAOdB +-ahXr14563Cjeu0pSQ1nXoz3IXdnDwePXasYhxQHl8Ayk8qZS5pt7r07H3dqq6pvn +-e09gZINJe47B9UhkR3H5bPyz/kujKS4zqo3Zlbryzm3V0BWqjNj+j8E2YuQKNQr+ +-c480jn2FzwW66w0i3n4U4KUn1w2/iq5AnVzyNkPDAoGAWLYEsyU79XE/4K79DqM3 +-P0r6/afKbw8U5B4syj4FzAOeBU6RNMPmGt5VNkBCtgnSdPpRFTsoDcG5cyN8GrkG +-Lug8WZoJJwr9pT5gH6yqEX/zZ27f1J1PJpd0CsedLNMm8eonJ2arhPkXrVZ7tKV6 +-AGAJa2agatUmAmi96hZYjpUCgYEA32abJEgsedEIhFb/GYI03ELryRCaUXfCA+gj +-lvoihn3qE1z5qGGns4adyX5dPRQmBqxtvDXDg+zl9vg6i0+MkXdCqTD8tXcOnjp9 +-RgFvmyVa9FI8beHPpQTuPNncWK3fpho/6pT8Hhi48LEsxwjrZWOnzQSaxQZH46Q6 +-IQNAFt8CgYEAkflxXvA2/2naix+riaBzv5EVJB7ilbfWiWtq2LEAtwrQ5XNFjrtK +-g45jKrZ/ezAzTfPa5Dwn4xcImd0MIavnJhDu2ATxMGB0GATLlDH2HZvU7UwKLpTW +-6Hlol4yRcX4GSEOxJ2ZpWYNIOYH0yDf1qLJXs1j8Fi3zWRe+V1kff4w= ++MIIEpAIBAAKCAQEA54HCeTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRH ++kZE5UjkazQ/h97S6LZ6Yb8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wM ++e//g9a7PpKanfw69fSVgAr49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRD ++SdoXg42udAh3uBY+QDs23snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgc ++j+8kyR/M+q+RfK5biqS3ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcv ++zn1Mfck35s0XDDRlGxRGGDy+ZCKmxf8Zu/8SwwIDAQABAoIBAGxzOBQpsIReQ6Lu ++HaybP4hXEzLVfIOIBaJCJaMKaJl0tLkP95r0qiKfh7OahiPRMQpf6k8tHrpFApDv ++q6PGhMdFgLov9YWNqW7y37AYEwn86KAJcHvCQbM2AiXCwGJgGFqA4LpIPlT7JwBc ++zd6LddQALfSFMcvuYPbIaPi1CUnGy/AAyxGjUrc60KO57NbI+dHSTOwTHO1QjOz9 ++ESk4fb34beUuZQzR6s/s1N0k09GJyklLpAAblRs5M6w9IlAn781eRLUAHTafLm4b ++21J9k2Q2UaOofn0Cvh8ggyJMiYqAJ0CsRy5pJroEyboA51WU+8THNFkNtRX5SxY5 ++YY3xE7ECgYEA/qkq7BPMkr/SnBPm32G1Eux5eLVd65qbox0oTLodZbusuxutqXTp ++1MseDPQtHlrq6CQBizwElx//pdKnIiU9iBS/QkMR9CviitMTt+WrWRrM54/A4CJP ++AU2Jg7b2DmhW1ombHHiBZ1tWzyiv9zxrtwR8kmKqv9aTOuPn4l7jY5kCgYEA6Llr ++47pQjp/YhkBBvlriRwM9RXek++ythgsWvEswORaUalnaZ9gxZOKKas35GLDDuVyT ++RnEhIqVlTg9iz6x5fXRtm6VzQvy9yFLzPMnlwsiSnRNOfMVIETUTOhNgm45tYY8f ++lN5bcdY6k6VZ/g/N3zqddnxkjocrd6lAayjjIrsCgYEAyZLYAcPuQx6JM7fhIGIz ++tQXvZKeS7yITHbq/onQTPuqd4AEZpi9/w0r/v1srt4JZvGR7wF1CeOkAL56dYr69 ++hNB/T5DNTkvKZv6K9h5aUg6PsJ8uGXuus6ZPOi4BeAgI7IpBd/i+3TQEc7eOCZIO ++5PAtNqXY6D6NjajGbH2VWckCgYA2KRDmyrF8v86QT9v9BQGsLSDRTerjhk1L6MC9 ++yXHLl2mq5oZhrHqyU9aKzKywBlNGjDjqJ+HiQkO1SvdgBW+wtqvbkUGl0VQJjuR0 ++vTfvgOY+EAQwHWmMN6Hl3iSZjyf9kGV1K9p0P7saKV0sN1leHjIPJRvx35tKGeWY ++CsfxiQKBgQCVUvsX/HeWyc4bxxMuzw8JniUG2JftZqIC1haHEFNElASjt4hARM7Y ++X/dkpYPXOZaN+qfvP949rS1WPXRtwMjt7bYzm7MGbXW7OiGGY3LV2CuVmbXJupvr ++Usvi+YnpqKDY/miOYd+541NJm76AQTSgQ8K7XitX7Beddh1U9e17mg== + -----END RSA PRIVATE KEY----- + -----BEGIN CERTIFICATE----- +-MIIE3TCCA8WgAwIBAgIBBTANBgkqhkiG9w0BAQUFADCBmTELMAkGA1UEBhMCVVMx +-FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcTCUNhbWJyaWRnZTEMMAoG +-A1UEChMDTUlUMSIwIAYDVQQLExlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww +-KgYDVQQDFCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x +-NDA1MDIxOTA2MDlaFw0yNTA0MTQxOTA2MDlaME8xCzAJBgNVBAYTAlVTMRYwFAYD +-VQQIEw1NYXNzYWNodXNldHRzMRQwEgYDVQQKEwtLUkJURVNULkNPTTESMBAGA1UE +-AxMJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1zud +-npN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPUoCFpWS3eeI4aQFoj93L5 +-MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4INTWqV9/DOODO7UowyMpp +-mO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZFlrYgZKE8vTC8BxDKM7F +-YhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5xNw6KIcCy3Q0NNoKnh00W +-VwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtPzjQgNPfTrjsMvyOWAAFr +-WVR3QLTxnnmXsqnXvwIDAQABo4IBdzCCAXMwHQYDVR0OBBYEFHO5+DSYzq8rvQhU +-ldyvn0y4AqlHMIHGBgNVHSMEgb4wgbuAFHO5+DSYzq8rvQhUldyvn0y4AqlHoYGf +-pIGcMIGZMQswCQYDVQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAG +-A1UEBxMJQ2FtYnJpZGdlMQwwCgYDVQQKEwNNSVQxIjAgBgNVBAsTGUluc2VjdXJl +-IEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNVBAMUI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5v ++MIIE3TCCA8WgAwIBAgIBBTANBgkqhkiG9w0BAQsFADCBmTELMAkGA1UEBhMCVVMx ++FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG ++A1UECgwDTUlUMSIwIAYDVQQLDBlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww ++KgYDVQQDDCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x ++OTExMTIxODMwMzRaFw0zMDEwMjUxODMwMzRaME8xCzAJBgNVBAYTAlVTMRYwFAYD ++VQQIDA1NYXNzYWNodXNldHRzMRQwEgYDVQQKDAtLUkJURVNULkNPTTESMBAGA1UE ++AwwJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA54HC ++eTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRHkZE5UjkazQ/h97S6LZ6Y ++b8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wMe//g9a7PpKanfw69fSVg ++Ar49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRDSdoXg42udAh3uBY+QDs2 ++3snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgcj+8kyR/M+q+RfK5biqS3 ++ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcvzn1Mfck35s0XDDRlGxRG ++GDy+ZCKmxf8Zu/8SwwIDAQABo4IBdzCCAXMwHQYDVR0OBBYEFPf/vJvFMCwrABeC ++C0sq7RGfYeIiMIHGBgNVHSMEgb4wgbuAFPf/vJvFMCwrABeCC0sq7RGfYeIioYGf ++pIGcMIGZMQswCQYDVQQGEwJVUzEWMBQGA1UECAwNTWFzc2FjaHVzZXR0czESMBAG ++A1UEBwwJQ2FtYnJpZGdlMQwwCgYDVQQKDANNSVQxIjAgBgNVBAsMGUluc2VjdXJl ++IEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNVBAMMI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5v + dCB1c2Ugb3RoZXJ3aXNlggEBMAsGA1UdDwQEAwID6DAMBgNVHRMBAf8EAjAAMFkG + A1UdEQRSMFCCFnByb3h5xaB1YmplY3TDhGx0w5FhbWWCE3Byb3h5U3ViamVjdEFs + dE5hbWWHBH8AAAGHEAAAAAAAAAAAAAAAAAAAAAGCCWxvY2FsaG9zdDATBgNVHSUE +-DDAKBggrBgEFBQcDATANBgkqhkiG9w0BAQUFAAOCAQEAfTctgFjQSaevBi64q7yh +-GNsK3PqeNEALZz4pSXRbOwm0E4RpYIS7uqg1C4zJ5Zbd4V/dOX7q+T/iBS7gErzS +-rj21jH3Ggc92TmXzcFxMDCxLV0hO8xFkqg3P4sslJESOHxvEMTTf5s893yUb8vJ/ +-DCvZXXRoRwPot9MFozkmcQcaTNunREWFvn4i4JXcMCSAfWTd+/VkpVsy69u3tj68 +-7G2/K5nalvZikutEC+DyfyBuvDAoxIYzCi3VtQxCalW28Q5hzWV21QsvKTP5QBsh +-RaU2r0O58lZPPvrOrtWQBCudUgsnoraVLrjJshEQ4z/ZA9fVtX2ndCSIoyWpWk01 +-gQ== ++DDAKBggrBgEFBQcDATANBgkqhkiG9w0BAQsFAAOCAQEAsMRJnxdbnpm5VlCFwNyU ++8ra1wCjj+ZH0POVCM4iXQ77bV6UBpcqlaQUvR7R/H1Bt5t3Cp0ycN/dy+RcXtj+5 ++FA84bRM767rsakxTEwjOjWw6GiK6bGjBfQ4F6Q97ELmiM0OZgmW8D56UHZxrI+o7 ++QrKWBpFf1UA8n/BmupHBtyW3gudtJS9a71u6lBRydPFqJ4l8YxHckbgPFceSRbRj ++x7E2pQVQ0p2nvG/NVyuC+2L29p81KAsG3vPzwOOfr1Tnpl1/B4R0+XEIy33KHpbz ++Ceyitz6k16fOVNxMI59W2OACPTQ/s99kygh+cARRPfEUPjDcJpS1gRZ6kDKRh6Np ++ig== + -----END CERTIFICATE----- +diff --git a/src/tests/dejagnu/proxy-certs/proxy-no-match.pem b/src/tests/dejagnu/proxy-certs/proxy-no-match.pem +index a97c1c77b..7464e40db 100644 +--- a/src/tests/dejagnu/proxy-certs/proxy-no-match.pem ++++ b/src/tests/dejagnu/proxy-certs/proxy-no-match.pem +@@ -1,54 +1,54 @@ + -----BEGIN RSA PRIVATE KEY----- +-MIIEpQIBAAKCAQEA1zudnpN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPU +-oCFpWS3eeI4aQFoj93L5MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4I +-NTWqV9/DOODO7UowyMppmO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZ +-FlrYgZKE8vTC8BxDKM7FYhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5x +-Nw6KIcCy3Q0NNoKnh00WVwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtP +-zjQgNPfTrjsMvyOWAAFrWVR3QLTxnnmXsqnXvwIDAQABAoIBAQCqvhpeMDXhGgoo +-Q03wmfrGwPsrMv91aIK1hYrhMPdVs1JAbRYiKh8+pcq07FYa8udRaB4UwkVh/+oM +-/nEs6niRsl/jjQ2l68TFrnNByroynvr6l9Q/EeGecF6Ygo7lY1OsFhcLQM5vjarS +-XhxvdU/6hcRmfS8tGRpUaMWqfmpiN3YgJcgt8SoYhiwAYDTMJjNyWC61lO7IqNVR +-4kntiM24sfAu1sdZynX8Gp2GrpNChapEuhilQ8RayjuStEYr2abcSIjfZFHQXN7o +-TnjL+AQUzc/ZTXDGnIe9ZzZeFz8UCueeoN6KPxfrq9UUWRL6qt7gOIMdhYR6lFxt +-6pj6kLhxAoGBAO5DTnTKDfCMY2/AsTzCJvMGSY0bT1rsdDxrpqjrbUSeMHV3s5Lm +-vEPnnm+05FD/vi99+HZjHXAZFkhA3ubij2qWFPBnQ5YUoh17IW/Ae4bzY2uXikgL +-tLZ+R+OrcGYQQlvPn//PLsxbfdk5vraqzm08kIX0T4o4Iz8ST5NFJ8hVAoGBAOdB +-ahXr14563Cjeu0pSQ1nXoz3IXdnDwePXasYhxQHl8Ayk8qZS5pt7r07H3dqq6pvn +-e09gZINJe47B9UhkR3H5bPyz/kujKS4zqo3Zlbryzm3V0BWqjNj+j8E2YuQKNQr+ +-c480jn2FzwW66w0i3n4U4KUn1w2/iq5AnVzyNkPDAoGAWLYEsyU79XE/4K79DqM3 +-P0r6/afKbw8U5B4syj4FzAOeBU6RNMPmGt5VNkBCtgnSdPpRFTsoDcG5cyN8GrkG +-Lug8WZoJJwr9pT5gH6yqEX/zZ27f1J1PJpd0CsedLNMm8eonJ2arhPkXrVZ7tKV6 +-AGAJa2agatUmAmi96hZYjpUCgYEA32abJEgsedEIhFb/GYI03ELryRCaUXfCA+gj +-lvoihn3qE1z5qGGns4adyX5dPRQmBqxtvDXDg+zl9vg6i0+MkXdCqTD8tXcOnjp9 +-RgFvmyVa9FI8beHPpQTuPNncWK3fpho/6pT8Hhi48LEsxwjrZWOnzQSaxQZH46Q6 +-IQNAFt8CgYEAkflxXvA2/2naix+riaBzv5EVJB7ilbfWiWtq2LEAtwrQ5XNFjrtK +-g45jKrZ/ezAzTfPa5Dwn4xcImd0MIavnJhDu2ATxMGB0GATLlDH2HZvU7UwKLpTW +-6Hlol4yRcX4GSEOxJ2ZpWYNIOYH0yDf1qLJXs1j8Fi3zWRe+V1kff4w= ++MIIEpAIBAAKCAQEA54HCeTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRH ++kZE5UjkazQ/h97S6LZ6Yb8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wM ++e//g9a7PpKanfw69fSVgAr49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRD ++SdoXg42udAh3uBY+QDs23snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgc ++j+8kyR/M+q+RfK5biqS3ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcv ++zn1Mfck35s0XDDRlGxRGGDy+ZCKmxf8Zu/8SwwIDAQABAoIBAGxzOBQpsIReQ6Lu ++HaybP4hXEzLVfIOIBaJCJaMKaJl0tLkP95r0qiKfh7OahiPRMQpf6k8tHrpFApDv ++q6PGhMdFgLov9YWNqW7y37AYEwn86KAJcHvCQbM2AiXCwGJgGFqA4LpIPlT7JwBc ++zd6LddQALfSFMcvuYPbIaPi1CUnGy/AAyxGjUrc60KO57NbI+dHSTOwTHO1QjOz9 ++ESk4fb34beUuZQzR6s/s1N0k09GJyklLpAAblRs5M6w9IlAn781eRLUAHTafLm4b ++21J9k2Q2UaOofn0Cvh8ggyJMiYqAJ0CsRy5pJroEyboA51WU+8THNFkNtRX5SxY5 ++YY3xE7ECgYEA/qkq7BPMkr/SnBPm32G1Eux5eLVd65qbox0oTLodZbusuxutqXTp ++1MseDPQtHlrq6CQBizwElx//pdKnIiU9iBS/QkMR9CviitMTt+WrWRrM54/A4CJP ++AU2Jg7b2DmhW1ombHHiBZ1tWzyiv9zxrtwR8kmKqv9aTOuPn4l7jY5kCgYEA6Llr ++47pQjp/YhkBBvlriRwM9RXek++ythgsWvEswORaUalnaZ9gxZOKKas35GLDDuVyT ++RnEhIqVlTg9iz6x5fXRtm6VzQvy9yFLzPMnlwsiSnRNOfMVIETUTOhNgm45tYY8f ++lN5bcdY6k6VZ/g/N3zqddnxkjocrd6lAayjjIrsCgYEAyZLYAcPuQx6JM7fhIGIz ++tQXvZKeS7yITHbq/onQTPuqd4AEZpi9/w0r/v1srt4JZvGR7wF1CeOkAL56dYr69 ++hNB/T5DNTkvKZv6K9h5aUg6PsJ8uGXuus6ZPOi4BeAgI7IpBd/i+3TQEc7eOCZIO ++5PAtNqXY6D6NjajGbH2VWckCgYA2KRDmyrF8v86QT9v9BQGsLSDRTerjhk1L6MC9 ++yXHLl2mq5oZhrHqyU9aKzKywBlNGjDjqJ+HiQkO1SvdgBW+wtqvbkUGl0VQJjuR0 ++vTfvgOY+EAQwHWmMN6Hl3iSZjyf9kGV1K9p0P7saKV0sN1leHjIPJRvx35tKGeWY ++CsfxiQKBgQCVUvsX/HeWyc4bxxMuzw8JniUG2JftZqIC1haHEFNElASjt4hARM7Y ++X/dkpYPXOZaN+qfvP949rS1WPXRtwMjt7bYzm7MGbXW7OiGGY3LV2CuVmbXJupvr ++Usvi+YnpqKDY/miOYd+541NJm76AQTSgQ8K7XitX7Beddh1U9e17mg== + -----END RSA PRIVATE KEY----- + -----BEGIN CERTIFICATE----- +-MIIEhzCCA2+gAwIBAgIBBDANBgkqhkiG9w0BAQUFADCBmTELMAkGA1UEBhMCVVMx +-FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcTCUNhbWJyaWRnZTEMMAoG +-A1UEChMDTUlUMSIwIAYDVQQLExlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww +-KgYDVQQDFCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x +-NDA1MDIxOTA2MDhaFw0yNTA0MTQxOTA2MDhaMFQxCzAJBgNVBAYTAlVTMRYwFAYD +-VQQIEw1NYXNzYWNodXNldHRzMRQwEgYDVQQKEwtLUkJURVNULkNPTTEXMBUGA1UE +-AxMOUFJPWFlpblN1YmplY3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB +-AQDXO52ek3wU/uIufW+CTJNKf9FDFfHXK3rOKQdoytU+OSNc89SgIWlZLd54jhpA +-WiP3cvkzBkOZLE5+UECovBXYAwBpytic08kiQe1tgp1Wy/D1vgg1NapX38M44M7t +-SjDIymmY7fn+lRdosv4CMeMvDX8SFDdli2p+kAw6R/lOdLka2pkWWtiBkoTy9MLw +-HEMozsViFZjPuSn+0bdLw79FOc/s136HVh2maUcEZ+7AhEgnPnE3DoohwLLdDQ02 +-gqeHTRZXAuZH7HXUEZKQyOJlmTAnkPRE5tKDXdAP+K2sahXaC0/ONCA099OuOwy/ +-I5YAAWtZVHdAtPGeeZeyqde/AgMBAAGjggEcMIIBGDAdBgNVHQ4EFgQUc7n4NJjO +-ryu9CFSV3K+fTLgCqUcwgcYGA1UdIwSBvjCBu4AUc7n4NJjOryu9CFSV3K+fTLgC +-qUehgZ+kgZwwgZkxCzAJBgNVBAYTAlVTMRYwFAYDVQQIEw1NYXNzYWNodXNldHRz +-MRIwEAYDVQQHEwlDYW1icmlkZ2UxDDAKBgNVBAoTA01JVDEiMCAGA1UECxMZSW5z +-ZWN1cmUgS2VyYmVyb3MgdGVzdCBDQTEsMCoGA1UEAxQjdGVzdCBzdWl0ZSBDQTsg ++MIIEhzCCA2+gAwIBAgIBBDANBgkqhkiG9w0BAQsFADCBmTELMAkGA1UEBhMCVVMx ++FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG ++A1UECgwDTUlUMSIwIAYDVQQLDBlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww ++KgYDVQQDDCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x ++OTExMTIxODMwMzRaFw0zMDEwMjUxODMwMzRaMFQxCzAJBgNVBAYTAlVTMRYwFAYD ++VQQIDA1NYXNzYWNodXNldHRzMRQwEgYDVQQKDAtLUkJURVNULkNPTTEXMBUGA1UE ++AwwOUFJPWFlpblN1YmplY3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB ++AQDngcJ5NNR7XbumqMryvbw0YzDavbH6FYoprIfk2ao6qfCfNEeRkTlSORrND+H3 ++tLotnphvzDeYkTJfU91w0BEPDaZs48WTk325ecFvoBmiDuGH3Ax7/+D1rs+kpqd/ ++Dr19JWACvj1MUWIugq7JOAeIk4HtiA/RtMcQ7iUuq6w9AzXqVENJ2heDja50CHe4 ++Fj5AOzbeyctKIH72+3yC3qBeJphvcEE5az0Hc8qzfvg32Q4+yByP7yTJH8z6r5F8 ++rluKpLdx7+zG89XQqx6H//W4nGVtALA6IF3dMtYcuFb0XuvMRy/OfUx9yTfmzRcM ++NGUbFEYYPL5kIqbF/xm7/xLDAgMBAAGjggEcMIIBGDAdBgNVHQ4EFgQU9/+8m8Uw ++LCsAF4ILSyrtEZ9h4iIwgcYGA1UdIwSBvjCBu4AU9/+8m8UwLCsAF4ILSyrtEZ9h ++4iKhgZ+kgZwwgZkxCzAJBgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNldHRz ++MRIwEAYDVQQHDAlDYW1icmlkZ2UxDDAKBgNVBAoMA01JVDEiMCAGA1UECwwZSW5z ++ZWN1cmUgS2VyYmVyb3MgdGVzdCBDQTEsMCoGA1UEAwwjdGVzdCBzdWl0ZSBDQTsg + ZG8gbm90IHVzZSBvdGhlcndpc2WCAQEwCwYDVR0PBAQDAgPoMAwGA1UdEwEB/wQC +-MAAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwDQYJKoZIhvcNAQEFBQADggEBAMsP++r4 +-vki0mBJg3POpp0i+H6zNMimoYLLtM5NvwXinfFuFQKbwLm8QWuHVifjfCYxMUm+l +-iL5cS/bq+SUWGDmrlOhsuu4+aYaxgNiEyki5Rol6miSOHbfOhzX8yp0EBPpq08dg +-SEdrTd/FIl4qgkkb1A4RJYZRErn/fbsyjJN66KIfSOXJuC8XMBf03Vw9f2rdrHJa +-r5lVGvqa4wjO2MPq9vVK52VFrbU/zuyyCUtggyIOwGLGSY0Axtbci+IHToDBQes+ +-6W4WwSUCssWfIZXQDLjFw1oRHnN43fXmX5vsVLi7YvOFHOAa1BDnDtCTZit26xVA +-Mdic66hR2jHP0TE= ++MAAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwDQYJKoZIhvcNAQELBQADggEBAI0Ons8g ++6aXdZsKSmp1hbwNUvsY5GNl/QHVJIMQbe9zNVkW9Hp286fzkMar6peTB9MEnhzJ5 ++5mbJM9DkugzgJeG0+HwsSdjAQCOcG4jSQ3SaASETOo58LsaG/yssIaZiZdJBrzNb ++1D5fJVVpopZMZ/mKUNB/2ofUVGVBZCdfyOoIbVSkkm1UHJ9liLFK1ZNPDTX60613 ++YNl4BydTiXtEg+IOYgmFXuZj310dDZUMHuYdzAM5j+6i2JaIcK4PgDE+yG9Oj9N+ ++uKjj0iHWyoZW49y9Hq/oiMegi2X4XZBtbZlEUu4OkpBJ1QG0MTaz/vN94sHiLOzS ++81b7+2BMgHd51+E= + -----END CERTIFICATE----- +diff --git a/src/tests/dejagnu/proxy-certs/proxy-san.pem b/src/tests/dejagnu/proxy-certs/proxy-san.pem +index ac8bbaa16..8eaeceece 100644 +--- a/src/tests/dejagnu/proxy-certs/proxy-san.pem ++++ b/src/tests/dejagnu/proxy-certs/proxy-san.pem +@@ -1,56 +1,56 @@ + -----BEGIN RSA PRIVATE KEY----- +-MIIEpQIBAAKCAQEA1zudnpN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPU +-oCFpWS3eeI4aQFoj93L5MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4I +-NTWqV9/DOODO7UowyMppmO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZ +-FlrYgZKE8vTC8BxDKM7FYhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5x +-Nw6KIcCy3Q0NNoKnh00WVwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtP +-zjQgNPfTrjsMvyOWAAFrWVR3QLTxnnmXsqnXvwIDAQABAoIBAQCqvhpeMDXhGgoo +-Q03wmfrGwPsrMv91aIK1hYrhMPdVs1JAbRYiKh8+pcq07FYa8udRaB4UwkVh/+oM +-/nEs6niRsl/jjQ2l68TFrnNByroynvr6l9Q/EeGecF6Ygo7lY1OsFhcLQM5vjarS +-XhxvdU/6hcRmfS8tGRpUaMWqfmpiN3YgJcgt8SoYhiwAYDTMJjNyWC61lO7IqNVR +-4kntiM24sfAu1sdZynX8Gp2GrpNChapEuhilQ8RayjuStEYr2abcSIjfZFHQXN7o +-TnjL+AQUzc/ZTXDGnIe9ZzZeFz8UCueeoN6KPxfrq9UUWRL6qt7gOIMdhYR6lFxt +-6pj6kLhxAoGBAO5DTnTKDfCMY2/AsTzCJvMGSY0bT1rsdDxrpqjrbUSeMHV3s5Lm +-vEPnnm+05FD/vi99+HZjHXAZFkhA3ubij2qWFPBnQ5YUoh17IW/Ae4bzY2uXikgL +-tLZ+R+OrcGYQQlvPn//PLsxbfdk5vraqzm08kIX0T4o4Iz8ST5NFJ8hVAoGBAOdB +-ahXr14563Cjeu0pSQ1nXoz3IXdnDwePXasYhxQHl8Ayk8qZS5pt7r07H3dqq6pvn +-e09gZINJe47B9UhkR3H5bPyz/kujKS4zqo3Zlbryzm3V0BWqjNj+j8E2YuQKNQr+ +-c480jn2FzwW66w0i3n4U4KUn1w2/iq5AnVzyNkPDAoGAWLYEsyU79XE/4K79DqM3 +-P0r6/afKbw8U5B4syj4FzAOeBU6RNMPmGt5VNkBCtgnSdPpRFTsoDcG5cyN8GrkG +-Lug8WZoJJwr9pT5gH6yqEX/zZ27f1J1PJpd0CsedLNMm8eonJ2arhPkXrVZ7tKV6 +-AGAJa2agatUmAmi96hZYjpUCgYEA32abJEgsedEIhFb/GYI03ELryRCaUXfCA+gj +-lvoihn3qE1z5qGGns4adyX5dPRQmBqxtvDXDg+zl9vg6i0+MkXdCqTD8tXcOnjp9 +-RgFvmyVa9FI8beHPpQTuPNncWK3fpho/6pT8Hhi48LEsxwjrZWOnzQSaxQZH46Q6 +-IQNAFt8CgYEAkflxXvA2/2naix+riaBzv5EVJB7ilbfWiWtq2LEAtwrQ5XNFjrtK +-g45jKrZ/ezAzTfPa5Dwn4xcImd0MIavnJhDu2ATxMGB0GATLlDH2HZvU7UwKLpTW +-6Hlol4yRcX4GSEOxJ2ZpWYNIOYH0yDf1qLJXs1j8Fi3zWRe+V1kff4w= ++MIIEpAIBAAKCAQEA54HCeTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRH ++kZE5UjkazQ/h97S6LZ6Yb8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wM ++e//g9a7PpKanfw69fSVgAr49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRD ++SdoXg42udAh3uBY+QDs23snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgc ++j+8kyR/M+q+RfK5biqS3ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcv ++zn1Mfck35s0XDDRlGxRGGDy+ZCKmxf8Zu/8SwwIDAQABAoIBAGxzOBQpsIReQ6Lu ++HaybP4hXEzLVfIOIBaJCJaMKaJl0tLkP95r0qiKfh7OahiPRMQpf6k8tHrpFApDv ++q6PGhMdFgLov9YWNqW7y37AYEwn86KAJcHvCQbM2AiXCwGJgGFqA4LpIPlT7JwBc ++zd6LddQALfSFMcvuYPbIaPi1CUnGy/AAyxGjUrc60KO57NbI+dHSTOwTHO1QjOz9 ++ESk4fb34beUuZQzR6s/s1N0k09GJyklLpAAblRs5M6w9IlAn781eRLUAHTafLm4b ++21J9k2Q2UaOofn0Cvh8ggyJMiYqAJ0CsRy5pJroEyboA51WU+8THNFkNtRX5SxY5 ++YY3xE7ECgYEA/qkq7BPMkr/SnBPm32G1Eux5eLVd65qbox0oTLodZbusuxutqXTp ++1MseDPQtHlrq6CQBizwElx//pdKnIiU9iBS/QkMR9CviitMTt+WrWRrM54/A4CJP ++AU2Jg7b2DmhW1ombHHiBZ1tWzyiv9zxrtwR8kmKqv9aTOuPn4l7jY5kCgYEA6Llr ++47pQjp/YhkBBvlriRwM9RXek++ythgsWvEswORaUalnaZ9gxZOKKas35GLDDuVyT ++RnEhIqVlTg9iz6x5fXRtm6VzQvy9yFLzPMnlwsiSnRNOfMVIETUTOhNgm45tYY8f ++lN5bcdY6k6VZ/g/N3zqddnxkjocrd6lAayjjIrsCgYEAyZLYAcPuQx6JM7fhIGIz ++tQXvZKeS7yITHbq/onQTPuqd4AEZpi9/w0r/v1srt4JZvGR7wF1CeOkAL56dYr69 ++hNB/T5DNTkvKZv6K9h5aUg6PsJ8uGXuus6ZPOi4BeAgI7IpBd/i+3TQEc7eOCZIO ++5PAtNqXY6D6NjajGbH2VWckCgYA2KRDmyrF8v86QT9v9BQGsLSDRTerjhk1L6MC9 ++yXHLl2mq5oZhrHqyU9aKzKywBlNGjDjqJ+HiQkO1SvdgBW+wtqvbkUGl0VQJjuR0 ++vTfvgOY+EAQwHWmMN6Hl3iSZjyf9kGV1K9p0P7saKV0sN1leHjIPJRvx35tKGeWY ++CsfxiQKBgQCVUvsX/HeWyc4bxxMuzw8JniUG2JftZqIC1haHEFNElASjt4hARM7Y ++X/dkpYPXOZaN+qfvP949rS1WPXRtwMjt7bYzm7MGbXW7OiGGY3LV2CuVmbXJupvr ++Usvi+YnpqKDY/miOYd+541NJm76AQTSgQ8K7XitX7Beddh1U9e17mg== + -----END RSA PRIVATE KEY----- + -----BEGIN CERTIFICATE----- +-MIIE4jCCA8qgAwIBAgIBAjANBgkqhkiG9w0BAQUFADCBmTELMAkGA1UEBhMCVVMx +-FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcTCUNhbWJyaWRnZTEMMAoG +-A1UEChMDTUlUMSIwIAYDVQQLExlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww +-KgYDVQQDFCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x +-NDA1MDIxOTA2MDhaFw0yNTA0MTQxOTA2MDhaMFQxCzAJBgNVBAYTAlVTMRYwFAYD +-VQQIEw1NYXNzYWNodXNldHRzMRQwEgYDVQQKEwtLUkJURVNULkNPTTEXMBUGA1UE +-AxMOUFJPWFlpblN1YmplY3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB +-AQDXO52ek3wU/uIufW+CTJNKf9FDFfHXK3rOKQdoytU+OSNc89SgIWlZLd54jhpA +-WiP3cvkzBkOZLE5+UECovBXYAwBpytic08kiQe1tgp1Wy/D1vgg1NapX38M44M7t +-SjDIymmY7fn+lRdosv4CMeMvDX8SFDdli2p+kAw6R/lOdLka2pkWWtiBkoTy9MLw +-HEMozsViFZjPuSn+0bdLw79FOc/s136HVh2maUcEZ+7AhEgnPnE3DoohwLLdDQ02 +-gqeHTRZXAuZH7HXUEZKQyOJlmTAnkPRE5tKDXdAP+K2sahXaC0/ONCA099OuOwy/ +-I5YAAWtZVHdAtPGeeZeyqde/AgMBAAGjggF3MIIBczAdBgNVHQ4EFgQUc7n4NJjO +-ryu9CFSV3K+fTLgCqUcwgcYGA1UdIwSBvjCBu4AUc7n4NJjOryu9CFSV3K+fTLgC +-qUehgZ+kgZwwgZkxCzAJBgNVBAYTAlVTMRYwFAYDVQQIEw1NYXNzYWNodXNldHRz +-MRIwEAYDVQQHEwlDYW1icmlkZ2UxDDAKBgNVBAoTA01JVDEiMCAGA1UECxMZSW5z +-ZWN1cmUgS2VyYmVyb3MgdGVzdCBDQTEsMCoGA1UEAxQjdGVzdCBzdWl0ZSBDQTsg ++MIIE4jCCA8qgAwIBAgIBAjANBgkqhkiG9w0BAQsFADCBmTELMAkGA1UEBhMCVVMx ++FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG ++A1UECgwDTUlUMSIwIAYDVQQLDBlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww ++KgYDVQQDDCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x ++OTExMTIxODMwMzRaFw0zMDEwMjUxODMwMzRaMFQxCzAJBgNVBAYTAlVTMRYwFAYD ++VQQIDA1NYXNzYWNodXNldHRzMRQwEgYDVQQKDAtLUkJURVNULkNPTTEXMBUGA1UE ++AwwOUFJPWFlpblN1YmplY3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB ++AQDngcJ5NNR7XbumqMryvbw0YzDavbH6FYoprIfk2ao6qfCfNEeRkTlSORrND+H3 ++tLotnphvzDeYkTJfU91w0BEPDaZs48WTk325ecFvoBmiDuGH3Ax7/+D1rs+kpqd/ ++Dr19JWACvj1MUWIugq7JOAeIk4HtiA/RtMcQ7iUuq6w9AzXqVENJ2heDja50CHe4 ++Fj5AOzbeyctKIH72+3yC3qBeJphvcEE5az0Hc8qzfvg32Q4+yByP7yTJH8z6r5F8 ++rluKpLdx7+zG89XQqx6H//W4nGVtALA6IF3dMtYcuFb0XuvMRy/OfUx9yTfmzRcM ++NGUbFEYYPL5kIqbF/xm7/xLDAgMBAAGjggF3MIIBczAdBgNVHQ4EFgQU9/+8m8Uw ++LCsAF4ILSyrtEZ9h4iIwgcYGA1UdIwSBvjCBu4AU9/+8m8UwLCsAF4ILSyrtEZ9h ++4iKhgZ+kgZwwgZkxCzAJBgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNldHRz ++MRIwEAYDVQQHDAlDYW1icmlkZ2UxDDAKBgNVBAoMA01JVDEiMCAGA1UECwwZSW5z ++ZWN1cmUgS2VyYmVyb3MgdGVzdCBDQTEsMCoGA1UEAwwjdGVzdCBzdWl0ZSBDQTsg + ZG8gbm90IHVzZSBvdGhlcndpc2WCAQEwCwYDVR0PBAQDAgPoMAwGA1UdEwEB/wQC + MAAwWQYDVR0RBFIwUIIWcHJveHnFoHViamVjdMOEbHTDkWFtZYITcHJveHlTdWJq + ZWN0QWx0TmFtZYcEfwAAAYcQAAAAAAAAAAAAAAAAAAAAAYIJbG9jYWxob3N0MBMG +-A1UdJQQMMAoGCCsGAQUFBwMBMA0GCSqGSIb3DQEBBQUAA4IBAQAH6AWuyRLzMbKq +-MUlyg9ZIar8p0Ms0/UEaa6Xm3/cfm6HSujtgcYlDN3M86Z3zWzWdTrOHsRr/YSG3 +-H3YDhJToKqxcjgho+1xdBPm0xuFsJcypRqGj/mIaJSoa+wC2AdY1EdE+URsh87XC +-SHYNbxAVo8qBHMjtROm6AKb2YusYqHnkT+U6nc4Pn9UnIzmu4wfoSB+X1vtY24TP +-AtXNYQEG4BkgSrcsgoL+z/+wtZLU8QFk6JRO7Bedq711Oh/taEasZHjRAmnqC5TB +-Ab2fnwWuoVZHqz2qydeywXUKrZlctuRVdjE++wOt9xuMPKFGo0PKDw/SymCe61Q8 +-Nc/d2mhz ++A1UdJQQMMAoGCCsGAQUFBwMBMA0GCSqGSIb3DQEBCwUAA4IBAQDQI1/zeNAWvXAG ++CTJk+hFLNx7xzd28/vWGkumK60rSmLVLZNDlvfmNJZ/kd7d0YZFvZDvbzhugXigI ++5N54664XreRwXA7QkgD2laFd/Rzq+6NdhyMCno7V6j1VZUm6/FWgfYjfGEBvbGNv ++Ue50fyRSQBmFv3p87Av/Zc0OMjted0zOYUxUPH0OL+2e4BL/suo05Q5DZq+J8Dni ++7SJbDC0fp5mKVLQ500zIRwUF2y5TE4olBsYBoaMDxQl+HoG6XpzaVslTKXAvzFMk ++8beI2BmqUId1OSLa3TOKnbsK8K/MPnSnB5StINt1+ZtTjjV+dY3xB6ZC+G1Pl6Ta ++00C7EWul + -----END CERTIFICATE----- +diff --git a/src/tests/dejagnu/proxy-certs/proxy-subject.pem b/src/tests/dejagnu/proxy-certs/proxy-subject.pem +index e17918f2b..3846aece6 100644 +--- a/src/tests/dejagnu/proxy-certs/proxy-subject.pem ++++ b/src/tests/dejagnu/proxy-certs/proxy-subject.pem +@@ -1,54 +1,54 @@ + -----BEGIN RSA PRIVATE KEY----- +-MIIEpQIBAAKCAQEA1zudnpN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPU +-oCFpWS3eeI4aQFoj93L5MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4I +-NTWqV9/DOODO7UowyMppmO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZ +-FlrYgZKE8vTC8BxDKM7FYhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5x +-Nw6KIcCy3Q0NNoKnh00WVwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtP +-zjQgNPfTrjsMvyOWAAFrWVR3QLTxnnmXsqnXvwIDAQABAoIBAQCqvhpeMDXhGgoo +-Q03wmfrGwPsrMv91aIK1hYrhMPdVs1JAbRYiKh8+pcq07FYa8udRaB4UwkVh/+oM +-/nEs6niRsl/jjQ2l68TFrnNByroynvr6l9Q/EeGecF6Ygo7lY1OsFhcLQM5vjarS +-XhxvdU/6hcRmfS8tGRpUaMWqfmpiN3YgJcgt8SoYhiwAYDTMJjNyWC61lO7IqNVR +-4kntiM24sfAu1sdZynX8Gp2GrpNChapEuhilQ8RayjuStEYr2abcSIjfZFHQXN7o +-TnjL+AQUzc/ZTXDGnIe9ZzZeFz8UCueeoN6KPxfrq9UUWRL6qt7gOIMdhYR6lFxt +-6pj6kLhxAoGBAO5DTnTKDfCMY2/AsTzCJvMGSY0bT1rsdDxrpqjrbUSeMHV3s5Lm +-vEPnnm+05FD/vi99+HZjHXAZFkhA3ubij2qWFPBnQ5YUoh17IW/Ae4bzY2uXikgL +-tLZ+R+OrcGYQQlvPn//PLsxbfdk5vraqzm08kIX0T4o4Iz8ST5NFJ8hVAoGBAOdB +-ahXr14563Cjeu0pSQ1nXoz3IXdnDwePXasYhxQHl8Ayk8qZS5pt7r07H3dqq6pvn +-e09gZINJe47B9UhkR3H5bPyz/kujKS4zqo3Zlbryzm3V0BWqjNj+j8E2YuQKNQr+ +-c480jn2FzwW66w0i3n4U4KUn1w2/iq5AnVzyNkPDAoGAWLYEsyU79XE/4K79DqM3 +-P0r6/afKbw8U5B4syj4FzAOeBU6RNMPmGt5VNkBCtgnSdPpRFTsoDcG5cyN8GrkG +-Lug8WZoJJwr9pT5gH6yqEX/zZ27f1J1PJpd0CsedLNMm8eonJ2arhPkXrVZ7tKV6 +-AGAJa2agatUmAmi96hZYjpUCgYEA32abJEgsedEIhFb/GYI03ELryRCaUXfCA+gj +-lvoihn3qE1z5qGGns4adyX5dPRQmBqxtvDXDg+zl9vg6i0+MkXdCqTD8tXcOnjp9 +-RgFvmyVa9FI8beHPpQTuPNncWK3fpho/6pT8Hhi48LEsxwjrZWOnzQSaxQZH46Q6 +-IQNAFt8CgYEAkflxXvA2/2naix+riaBzv5EVJB7ilbfWiWtq2LEAtwrQ5XNFjrtK +-g45jKrZ/ezAzTfPa5Dwn4xcImd0MIavnJhDu2ATxMGB0GATLlDH2HZvU7UwKLpTW +-6Hlol4yRcX4GSEOxJ2ZpWYNIOYH0yDf1qLJXs1j8Fi3zWRe+V1kff4w= ++MIIEpAIBAAKCAQEA54HCeTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRH ++kZE5UjkazQ/h97S6LZ6Yb8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wM ++e//g9a7PpKanfw69fSVgAr49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRD ++SdoXg42udAh3uBY+QDs23snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgc ++j+8kyR/M+q+RfK5biqS3ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcv ++zn1Mfck35s0XDDRlGxRGGDy+ZCKmxf8Zu/8SwwIDAQABAoIBAGxzOBQpsIReQ6Lu ++HaybP4hXEzLVfIOIBaJCJaMKaJl0tLkP95r0qiKfh7OahiPRMQpf6k8tHrpFApDv ++q6PGhMdFgLov9YWNqW7y37AYEwn86KAJcHvCQbM2AiXCwGJgGFqA4LpIPlT7JwBc ++zd6LddQALfSFMcvuYPbIaPi1CUnGy/AAyxGjUrc60KO57NbI+dHSTOwTHO1QjOz9 ++ESk4fb34beUuZQzR6s/s1N0k09GJyklLpAAblRs5M6w9IlAn781eRLUAHTafLm4b ++21J9k2Q2UaOofn0Cvh8ggyJMiYqAJ0CsRy5pJroEyboA51WU+8THNFkNtRX5SxY5 ++YY3xE7ECgYEA/qkq7BPMkr/SnBPm32G1Eux5eLVd65qbox0oTLodZbusuxutqXTp ++1MseDPQtHlrq6CQBizwElx//pdKnIiU9iBS/QkMR9CviitMTt+WrWRrM54/A4CJP ++AU2Jg7b2DmhW1ombHHiBZ1tWzyiv9zxrtwR8kmKqv9aTOuPn4l7jY5kCgYEA6Llr ++47pQjp/YhkBBvlriRwM9RXek++ythgsWvEswORaUalnaZ9gxZOKKas35GLDDuVyT ++RnEhIqVlTg9iz6x5fXRtm6VzQvy9yFLzPMnlwsiSnRNOfMVIETUTOhNgm45tYY8f ++lN5bcdY6k6VZ/g/N3zqddnxkjocrd6lAayjjIrsCgYEAyZLYAcPuQx6JM7fhIGIz ++tQXvZKeS7yITHbq/onQTPuqd4AEZpi9/w0r/v1srt4JZvGR7wF1CeOkAL56dYr69 ++hNB/T5DNTkvKZv6K9h5aUg6PsJ8uGXuus6ZPOi4BeAgI7IpBd/i+3TQEc7eOCZIO ++5PAtNqXY6D6NjajGbH2VWckCgYA2KRDmyrF8v86QT9v9BQGsLSDRTerjhk1L6MC9 ++yXHLl2mq5oZhrHqyU9aKzKywBlNGjDjqJ+HiQkO1SvdgBW+wtqvbkUGl0VQJjuR0 ++vTfvgOY+EAQwHWmMN6Hl3iSZjyf9kGV1K9p0P7saKV0sN1leHjIPJRvx35tKGeWY ++CsfxiQKBgQCVUvsX/HeWyc4bxxMuzw8JniUG2JftZqIC1haHEFNElASjt4hARM7Y ++X/dkpYPXOZaN+qfvP949rS1WPXRtwMjt7bYzm7MGbXW7OiGGY3LV2CuVmbXJupvr ++Usvi+YnpqKDY/miOYd+541NJm76AQTSgQ8K7XitX7Beddh1U9e17mg== + -----END RSA PRIVATE KEY----- + -----BEGIN CERTIFICATE----- +-MIIEgjCCA2qgAwIBAgIBAzANBgkqhkiG9w0BAQUFADCBmTELMAkGA1UEBhMCVVMx +-FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcTCUNhbWJyaWRnZTEMMAoG +-A1UEChMDTUlUMSIwIAYDVQQLExlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww +-KgYDVQQDFCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x +-NDA1MDIxOTA2MDhaFw0yNTA0MTQxOTA2MDhaME8xCzAJBgNVBAYTAlVTMRYwFAYD +-VQQIEw1NYXNzYWNodXNldHRzMRQwEgYDVQQKEwtLUkJURVNULkNPTTESMBAGA1UE +-AxMJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1zud +-npN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPUoCFpWS3eeI4aQFoj93L5 +-MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4INTWqV9/DOODO7UowyMpp +-mO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZFlrYgZKE8vTC8BxDKM7F +-YhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5xNw6KIcCy3Q0NNoKnh00W +-VwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtPzjQgNPfTrjsMvyOWAAFr +-WVR3QLTxnnmXsqnXvwIDAQABo4IBHDCCARgwHQYDVR0OBBYEFHO5+DSYzq8rvQhU +-ldyvn0y4AqlHMIHGBgNVHSMEgb4wgbuAFHO5+DSYzq8rvQhUldyvn0y4AqlHoYGf +-pIGcMIGZMQswCQYDVQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAG +-A1UEBxMJQ2FtYnJpZGdlMQwwCgYDVQQKEwNNSVQxIjAgBgNVBAsTGUluc2VjdXJl +-IEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNVBAMUI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5v ++MIIEgjCCA2qgAwIBAgIBAzANBgkqhkiG9w0BAQsFADCBmTELMAkGA1UEBhMCVVMx ++FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG ++A1UECgwDTUlUMSIwIAYDVQQLDBlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww ++KgYDVQQDDCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x ++OTExMTIxODMwMzRaFw0zMDEwMjUxODMwMzRaME8xCzAJBgNVBAYTAlVTMRYwFAYD ++VQQIDA1NYXNzYWNodXNldHRzMRQwEgYDVQQKDAtLUkJURVNULkNPTTESMBAGA1UE ++AwwJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA54HC ++eTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRHkZE5UjkazQ/h97S6LZ6Y ++b8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wMe//g9a7PpKanfw69fSVg ++Ar49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRDSdoXg42udAh3uBY+QDs2 ++3snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgcj+8kyR/M+q+RfK5biqS3 ++ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcvzn1Mfck35s0XDDRlGxRG ++GDy+ZCKmxf8Zu/8SwwIDAQABo4IBHDCCARgwHQYDVR0OBBYEFPf/vJvFMCwrABeC ++C0sq7RGfYeIiMIHGBgNVHSMEgb4wgbuAFPf/vJvFMCwrABeCC0sq7RGfYeIioYGf ++pIGcMIGZMQswCQYDVQQGEwJVUzEWMBQGA1UECAwNTWFzc2FjaHVzZXR0czESMBAG ++A1UEBwwJQ2FtYnJpZGdlMQwwCgYDVQQKDANNSVQxIjAgBgNVBAsMGUluc2VjdXJl ++IEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNVBAMMI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5v + dCB1c2Ugb3RoZXJ3aXNlggEBMAsGA1UdDwQEAwID6DAMBgNVHRMBAf8EAjAAMBMG +-A1UdJQQMMAoGCCsGAQUFBwMBMA0GCSqGSIb3DQEBBQUAA4IBAQCzGPT+QOrl9mbJ +-nsGlPlLUOF+PYz0a/9V/iznlofxwCXiRi2ryMpLFbjLeOvjLJ3UzyNKtmEeudTBM +-yfR4i8tb9WA7Oh0BjK1+kD4688bAUXiIDhueKBjonmPvMd9kq3MDd4vDLkcZk6R4 +-4IcbdwhzSBmnJH8ha2J82XShPpRq5CZNR9+vTyFwGdGWdPDjTMiXoXAmpRemcEgO +-iO4Gxvcrg/Z06Ys3eLze7QHNMAEwXhC4rUR34j5I2zgU7CEhff3AktLmnKVa8go8 +-4BJT/n3XGB+3gdAEihQmgCEZetHH+YxAR0Ppn3ty7fpAlOnbRJqpeu6TMN8x/lL8 +-c6JtDWRG ++A1UdJQQMMAoGCCsGAQUFBwMBMA0GCSqGSIb3DQEBCwUAA4IBAQBdg7Gk/RqQpTfD ++vyFB1GPWRcLYpYW4GQh3e/dcesmwjwT8Nsd4Mzq9mA9TzJIXwffUQ8de85L5+9Oh ++k4yiwRS3vDCP0fr+GZMpBqkBVunJIHQnm+RWxT42+0kBxxmO/fqp5ztND8gGBLiW ++QPHb+mSCFgmgwnRuW+UI3TZ965oZfd2oRjjHjr51cgxcXndqnNws/kakMpxSM+KT +++ICHNz5og79nC7zpVqu0Cd56stPXbrFeU+bnN5UT9sOZNOYstWZmS8u+ddDuJwhS ++ijJZgtQNOIuBfD2TLfDmg/QfLeh5hhgBVyXC5o8g6KEtjPgm+44OF3vNZeuwVPaf ++L58YyPcO + -----END CERTIFICATE----- diff --git a/Use-backported-version-of-OpenSSL-3-KDF-interface.patch b/Use-backported-version-of-OpenSSL-3-KDF-interface.patch new file mode 100644 index 0000000..4857999 --- /dev/null +++ b/Use-backported-version-of-OpenSSL-3-KDF-interface.patch @@ -0,0 +1,746 @@ +From 0e20daf7ccfe50518c89735c3dae2fde08d92325 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 15 Nov 2019 20:05:16 +0000 +Subject: [PATCH] Use backported version of OpenSSL-3 KDF interface + +--- + src/configure.in | 4 + + src/lib/crypto/krb/derive.c | 346 +++++++++++++----- + .../preauth/pkinit/pkinit_crypto_openssl.c | 257 +++++++------ + 3 files changed, 423 insertions(+), 184 deletions(-) + +diff --git a/src/configure.in b/src/configure.in +index d0d8c4ed7..6573e8343 100644 +--- a/src/configure.in ++++ b/src/configure.in +@@ -269,6 +269,10 @@ AC_SUBST(CRYPTO_IMPL) + AC_SUBST(CRYPTO_IMPL_CFLAGS) + AC_SUBST(CRYPTO_IMPL_LIBS) + ++AC_CHECK_FUNCS(EVP_KDF_CTX_new_id EVP_KDF_ctrl EVP_KDF_derive, ++ AC_DEFINE(OSSL_KDFS, 1, [Define if using OpenSSL KDFs]), ++ AC_MSG_ERROR([backported OpenSSL KDFs not found])) ++ + AC_ARG_WITH([prng-alg], + AC_HELP_STRING([--with-prng-alg=ALG], [use specified PRNG algorithm. @<:@fortuna@:>@]), + [PRNG_ALG=$withval +diff --git a/src/lib/crypto/krb/derive.c b/src/lib/crypto/krb/derive.c +index 6707a7308..915a173dd 100644 +--- a/src/lib/crypto/krb/derive.c ++++ b/src/lib/crypto/krb/derive.c +@@ -27,6 +27,13 @@ + + #include "crypto_int.h" + ++#ifdef OSSL_KDFS ++#include ++#include ++#else ++#error "Refusing to build without OpenSSL KDFs!" ++#endif ++ + static krb5_key + find_cached_dkey(struct derived_key *list, const krb5_data *constant) + { +@@ -77,55 +84,193 @@ cleanup: + return ENOMEM; + } + ++#ifdef OSSL_KDFS + static krb5_error_code +-derive_random_rfc3961(const struct krb5_enc_provider *enc, +- krb5_key inkey, krb5_data *outrnd, +- const krb5_data *in_constant) ++openssl_kbdkf_counter_hmac(const struct krb5_hash_provider *hash, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *label, const krb5_data *context) + { +- size_t blocksize, keybytes, n; +- krb5_error_code ret; +- krb5_data block = empty_data(); ++ krb5_error_code ret = KRB5_CRYPTO_INTERNAL; ++ EVP_KDF_CTX *ctx = NULL; ++ const EVP_MD *digest; ++ ++ if (!strcmp(hash->hash_name, "SHA1")) ++ digest = EVP_sha1(); ++ else if (!strcmp(hash->hash_name, "SHA-256")) ++ digest = EVP_sha256(); ++ else if (!strcmp(hash->hash_name, "SHA-384")) ++ digest = EVP_sha384(); ++ else ++ goto done; ++ ++ ctx = EVP_KDF_CTX_new_id(EVP_KDF_KB); ++ if (!ctx) ++ goto done; ++ ++ if (EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_MD, digest) != 1 || ++ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KB_MAC_TYPE, ++ EVP_KDF_KB_MAC_TYPE_HMAC) != 1 || ++ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KEY, inkey->keyblock.contents, ++ inkey->keyblock.length) != 1 || ++ (context->length > 0 && ++ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KB_INFO, context->data, ++ context->length) != 1) || ++ (label->length > 0 && ++ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_SALT, label->data, ++ label->length) != 1) || ++ EVP_KDF_derive(ctx, (unsigned char *)outrnd->data, ++ outrnd->length) != 1) ++ goto done; ++ ++ ret = 0; ++done: ++ if (ret) ++ zap(outrnd->data, outrnd->length); ++ EVP_KDF_CTX_free(ctx); ++ return ret; ++} + +- blocksize = enc->block_size; +- keybytes = enc->keybytes; ++static krb5_error_code ++openssl_kbkdf_feedback_cmac(const struct krb5_enc_provider *enc, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *in_constant) ++{ ++ krb5_error_code ret = KRB5_CRYPTO_INTERNAL; ++ EVP_KDF_CTX *ctx = NULL; ++ const EVP_CIPHER *cipher; ++ static unsigned char zeroes[16]; ++ ++ memset(zeroes, 0, sizeof(zeroes)); ++ ++ if (enc->keylength == 16) ++ cipher = EVP_camellia_128_cbc(); ++ else if (enc->keylength == 32) ++ cipher = EVP_camellia_256_cbc(); ++ else ++ goto done; ++ ++ ctx = EVP_KDF_CTX_new_id(EVP_KDF_KB); ++ if (!ctx) ++ goto done; ++ ++ if (EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KB_MODE, ++ EVP_KDF_KB_MODE_FEEDBACK) != 1 || ++ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KB_MAC_TYPE, ++ EVP_KDF_KB_MAC_TYPE_CMAC) != 1 || ++ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_CIPHER, cipher) != 1 || ++ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KEY, inkey->keyblock.contents, ++ inkey->keyblock.length) != 1 || ++ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_SALT, in_constant->data, ++ in_constant->length) != 1 || ++ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KB_SEED, zeroes, ++ sizeof(zeroes)) != 1 || ++ EVP_KDF_derive(ctx, (unsigned char *)outrnd->data, ++ outrnd->length) != 1) ++ goto done; ++ ++ ret = 0; ++done: ++ if (ret) ++ zap(outrnd->data, outrnd->length); ++ EVP_KDF_CTX_free(ctx); ++ return ret; ++} + +- if (blocksize == 1) +- return KRB5_BAD_ENCTYPE; +- if (inkey->keyblock.length != enc->keylength || outrnd->length != keybytes) ++static krb5_error_code ++openssl_krb5kdf(const struct krb5_enc_provider *enc, krb5_key inkey, ++ krb5_data *outrnd, const krb5_data *in_constant) ++{ ++ krb5_error_code ret = KRB5_CRYPTO_INTERNAL; ++ EVP_KDF_CTX *ctx = NULL; ++ const EVP_CIPHER *cipher; ++ ++ if (inkey->keyblock.length != enc->keylength || ++ outrnd->length != enc->keybytes) { + return KRB5_CRYPTO_INTERNAL; ++ } + +- /* Allocate encryption data buffer. */ +- ret = alloc_data(&block, blocksize); ++ if (enc->encrypt == krb5int_aes_encrypt && enc->keylength == 16) ++ cipher = EVP_aes_128_cbc(); ++ else if (enc->encrypt == krb5int_aes_encrypt && enc->keylength == 32) ++ cipher = EVP_aes_256_cbc(); ++ else if (enc->keylength == 24) ++ cipher = EVP_des_ede3_cbc(); ++ else ++ goto done; ++ ++ ctx = EVP_KDF_CTX_new_id(EVP_KDF_KRB5KDF); ++ if (ctx == NULL) ++ goto done; ++ ++ if (EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_CIPHER, cipher) != 1 || ++ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KEY, inkey->keyblock.contents, ++ inkey->keyblock.length) != 1 || ++ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KRB5KDF_CONSTANT, ++ in_constant->data, in_constant->length) != 1 || ++ EVP_KDF_derive(ctx, (unsigned char *)outrnd->data, ++ outrnd->length) != 1) ++ goto done; ++ ++ ret = 0; ++done: + if (ret) +- return ret; ++ zap(outrnd->data, outrnd->length); ++ EVP_KDF_CTX_free(ctx); ++ return ret; ++} + +- /* Initialize the input block. */ +- if (in_constant->length == blocksize) { +- memcpy(block.data, in_constant->data, blocksize); +- } else { +- krb5int_nfold(in_constant->length * 8, +- (unsigned char *) in_constant->data, +- blocksize * 8, (unsigned char *) block.data); +- } ++#else /* OSSL_KDFS */ + +- /* Loop encrypting the blocks until enough key bytes are generated. */ +- n = 0; +- while (n < keybytes) { +- ret = encrypt_block(enc, inkey, &block); +- if (ret) +- goto cleanup; ++/* ++ * NIST SP800-108 KDF in counter mode (section 5.1). ++ * Parameters: ++ * - HMAC (with hash as the hash provider) is the PRF. ++ * - A block counter of four bytes is used. ++ * - Four bytes are used to encode the output length in the PRF input. ++ * ++ * There are no uses requiring more than a single PRF invocation. ++ */ ++static krb5_error_code ++builtin_sp800_108_counter_hmac(const struct krb5_hash_provider *hash, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *label, ++ const krb5_data *context) ++{ ++ krb5_crypto_iov iov[5]; ++ krb5_error_code ret; ++ krb5_data prf; ++ unsigned char ibuf[4], lbuf[4]; + +- if ((keybytes - n) <= blocksize) { +- memcpy(outrnd->data + n, block.data, (keybytes - n)); +- break; +- } ++ if (hash == NULL || outrnd->length > hash->hashsize) ++ return KRB5_CRYPTO_INTERNAL; + +- memcpy(outrnd->data + n, block.data, blocksize); +- n += blocksize; +- } ++ /* Allocate encryption data buffer. */ ++ ret = alloc_data(&prf, hash->hashsize); ++ if (ret) ++ return ret; + +-cleanup: +- zapfree(block.data, blocksize); ++ /* [i]2: four-byte big-endian binary string giving the block counter (1) */ ++ iov[0].flags = KRB5_CRYPTO_TYPE_DATA; ++ iov[0].data = make_data(ibuf, sizeof(ibuf)); ++ store_32_be(1, ibuf); ++ /* Label */ ++ iov[1].flags = KRB5_CRYPTO_TYPE_DATA; ++ iov[1].data = *label; ++ /* 0x00: separator byte */ ++ iov[2].flags = KRB5_CRYPTO_TYPE_DATA; ++ iov[2].data = make_data("", 1); ++ /* Context */ ++ iov[3].flags = KRB5_CRYPTO_TYPE_DATA; ++ iov[3].data = *context; ++ /* [L]2: four-byte big-endian binary string giving the output length */ ++ iov[4].flags = KRB5_CRYPTO_TYPE_DATA; ++ iov[4].data = make_data(lbuf, sizeof(lbuf)); ++ store_32_be(outrnd->length * 8, lbuf); ++ ++ ret = krb5int_hmac(hash, inkey, iov, 5, &prf); ++ if (!ret) ++ memcpy(outrnd->data, prf.data, outrnd->length); ++ zapfree(prf.data, prf.length); + return ret; + } + +@@ -139,9 +284,9 @@ cleanup: + * - Four bytes are used to encode the output length in the PRF input. + */ + static krb5_error_code +-derive_random_sp800_108_feedback_cmac(const struct krb5_enc_provider *enc, +- krb5_key inkey, krb5_data *outrnd, +- const krb5_data *in_constant) ++builtin_sp800_108_feedback_cmac(const struct krb5_enc_provider *enc, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *in_constant) + { + size_t blocksize, keybytes, n; + krb5_crypto_iov iov[6]; +@@ -204,57 +349,95 @@ cleanup: + return ret; + } + +-/* +- * NIST SP800-108 KDF in counter mode (section 5.1). +- * Parameters: +- * - HMAC (with hash as the hash provider) is the PRF. +- * - A block counter of four bytes is used. +- * - Four bytes are used to encode the output length in the PRF input. +- * +- * There are no uses requiring more than a single PRF invocation. +- */ +-krb5_error_code +-k5_sp800_108_counter_hmac(const struct krb5_hash_provider *hash, +- krb5_key inkey, krb5_data *outrnd, +- const krb5_data *label, const krb5_data *context) ++static krb5_error_code ++builtin_derive_random_rfc3961(const struct krb5_enc_provider *enc, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *in_constant) + { +- krb5_crypto_iov iov[5]; ++ size_t blocksize, keybytes, n; + krb5_error_code ret; +- krb5_data prf; +- unsigned char ibuf[4], lbuf[4]; ++ krb5_data block = empty_data(); + +- if (hash == NULL || outrnd->length > hash->hashsize) ++ blocksize = enc->block_size; ++ keybytes = enc->keybytes; ++ ++ if (blocksize == 1) ++ return KRB5_BAD_ENCTYPE; ++ if (inkey->keyblock.length != enc->keylength || outrnd->length != keybytes) + return KRB5_CRYPTO_INTERNAL; + + /* Allocate encryption data buffer. */ +- ret = alloc_data(&prf, hash->hashsize); ++ ret = alloc_data(&block, blocksize); + if (ret) + return ret; + +- /* [i]2: four-byte big-endian binary string giving the block counter (1) */ +- iov[0].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[0].data = make_data(ibuf, sizeof(ibuf)); +- store_32_be(1, ibuf); +- /* Label */ +- iov[1].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[1].data = *label; +- /* 0x00: separator byte */ +- iov[2].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[2].data = make_data("", 1); +- /* Context */ +- iov[3].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[3].data = *context; +- /* [L]2: four-byte big-endian binary string giving the output length */ +- iov[4].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[4].data = make_data(lbuf, sizeof(lbuf)); +- store_32_be(outrnd->length * 8, lbuf); ++ /* Initialize the input block. */ ++ if (in_constant->length == blocksize) { ++ memcpy(block.data, in_constant->data, blocksize); ++ } else { ++ krb5int_nfold(in_constant->length * 8, ++ (unsigned char *) in_constant->data, ++ blocksize * 8, (unsigned char *) block.data); ++ } + +- ret = krb5int_hmac(hash, inkey, iov, 5, &prf); +- if (!ret) +- memcpy(outrnd->data, prf.data, outrnd->length); +- zapfree(prf.data, prf.length); ++ /* Loop encrypting the blocks until enough key bytes are generated. */ ++ n = 0; ++ while (n < keybytes) { ++ ret = encrypt_block(enc, inkey, &block); ++ if (ret) ++ goto cleanup; ++ ++ if ((keybytes - n) <= blocksize) { ++ memcpy(outrnd->data + n, block.data, (keybytes - n)); ++ break; ++ } ++ ++ memcpy(outrnd->data + n, block.data, blocksize); ++ n += blocksize; ++ } ++ ++cleanup: ++ zapfree(block.data, blocksize); + return ret; + } ++#endif /* OSSL_KDFS */ ++ ++krb5_error_code ++k5_sp800_108_counter_hmac(const struct krb5_hash_provider *hash, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *label, const krb5_data *context) ++{ ++#ifdef OSSL_KDFS ++ return openssl_kbdkf_counter_hmac(hash, inkey, outrnd, label, context); ++#else ++ return builtin_sp800_108_counter_hmac(hash, inkey, outrnd, label, ++ context); ++#endif ++} ++ ++static krb5_error_code ++k5_sp800_108_feedback_cmac(const struct krb5_enc_provider *enc, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *in_constant) ++{ ++#ifdef OSSL_KDFS ++ return openssl_kbkdf_feedback_cmac(enc, inkey, outrnd, in_constant); ++#else ++ return builtin_sp800_108_feedback_cmac(enc, inkey, outrnd, in_constant); ++#endif ++} ++ ++static krb5_error_code ++k5_derive_random_rfc3961(const struct krb5_enc_provider *enc, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *in_constant) ++{ ++#ifdef OSSL_KDFS ++ return openssl_krb5kdf(enc, inkey, outrnd, in_constant); ++#else ++ return builtin_derive_random_rfc3961(enc, inkey, outrnd, in_constant); ++#endif ++} + + krb5_error_code + krb5int_derive_random(const struct krb5_enc_provider *enc, +@@ -266,10 +449,9 @@ krb5int_derive_random(const struct krb5_enc_provider *enc, + + switch (alg) { + case DERIVE_RFC3961: +- return derive_random_rfc3961(enc, inkey, outrnd, in_constant); ++ return k5_derive_random_rfc3961(enc, inkey, outrnd, in_constant); + case DERIVE_SP800_108_CMAC: +- return derive_random_sp800_108_feedback_cmac(enc, inkey, outrnd, +- in_constant); ++ return k5_sp800_108_feedback_cmac(enc, inkey, outrnd, in_constant); + case DERIVE_SP800_108_HMAC: + return k5_sp800_108_counter_hmac(hash, inkey, outrnd, in_constant, + &empty); +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 52976895b..dd718c2be 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -38,6 +38,13 @@ + #include + #include + ++#ifdef OSSL_KDFS ++#include ++#include ++#else ++#error "Refusing to build without OpenSSL KDFs!" ++#endif ++ + static krb5_error_code pkinit_init_pkinit_oids(pkinit_plg_crypto_context ); + static void pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ); + +@@ -2331,11 +2338,51 @@ pkinit_alg_values(krb5_context context, + } + } /* pkinit_alg_values() */ + ++#ifdef OSSL_KDFS ++static krb5_error_code ++openssl_sskdf(krb5_context context, size_t hash_bytes, krb5_data *key, ++ krb5_data *info, char *out, size_t out_len) ++{ ++ krb5_error_code ret = KRB5_CRYPTO_INTERNAL; ++ EVP_KDF_CTX *ctx = NULL; ++ const EVP_MD *digest; ++ ++ /* RFC 8636 defines a SHA384 variant, but we don't use it. */ ++ if (hash_bytes == 20) { ++ digest = EVP_sha1(); ++ } else if (hash_bytes == 32) { ++ digest = EVP_sha256(); ++ } else if (hash_bytes == 64) { ++ digest = EVP_sha512(); ++ } else { ++ krb5_set_error_message(context, ret, "Bad hash type for SSKDF"); ++ goto done; ++ } + +-/* pkinit_alg_agility_kdf() -- +- * This function generates a key using the KDF described in +- * draft_ietf_krb_wg_pkinit_alg_agility-04.txt. The algorithm is +- * described as follows: ++ ctx = EVP_KDF_CTX_new_id(EVP_KDF_SS); ++ if (!ctx) { ++ oerr(context, ret, _("Failed to instantiate SSKDF")); ++ goto done; ++ } ++ ++ if (EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_MD, digest) != 1 || ++ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KEY, key->data, ++ key->length) != 1 || ++ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_SSKDF_INFO, info->data, ++ info->length) != 1 || ++ EVP_KDF_derive(ctx, (unsigned char *)out, out_len) != 1) ++ goto done; ++ ++ ret = 0; ++done: ++ EVP_KDF_CTX_free(ctx); ++ return ret; ++} ++#else ++/* ++ * Generate a key using the KDF described in RFC 8636, also known as SSKDF ++ * (single-step kdf). Our caller precomputes `reps`, but otherwise the ++ * algorithm is as follows: + * + * 1. reps = keydatalen (K) / hash length (H) + * +@@ -2349,95 +2396,16 @@ pkinit_alg_values(krb5_context context, + * + * 4. Set key = Hash1 || Hash2 || ... so that length of key is K bytes. + */ +-krb5_error_code +-pkinit_alg_agility_kdf(krb5_context context, +- krb5_data *secret, +- krb5_data *alg_oid, +- krb5_const_principal party_u_info, +- krb5_const_principal party_v_info, +- krb5_enctype enctype, +- krb5_data *as_req, +- krb5_data *pk_as_rep, +- krb5_keyblock *key_block) ++static krb5_error_code ++builtin_sskdf(krb5_context context, unsigned int reps, size_t hash_len, ++ const EVP_MD *(*EVP_func)(void), krb5_data *secret, ++ krb5_data *other_info, char *out, size_t out_len) + { + krb5_error_code retval = 0; + +- unsigned int reps = 0; +- uint32_t counter = 1; /* Does this type work on Windows? */ ++ uint32_t counter = 1; + size_t offset = 0; +- size_t hash_len = 0; +- size_t rand_len = 0; +- size_t key_len = 0; +- krb5_data random_data; +- krb5_sp80056a_other_info other_info_fields; +- krb5_pkinit_supp_pub_info supp_pub_info_fields; +- krb5_data *other_info = NULL; +- krb5_data *supp_pub_info = NULL; +- krb5_algorithm_identifier alg_id; + EVP_MD_CTX *ctx = NULL; +- const EVP_MD *(*EVP_func)(void); +- +- /* initialize random_data here to make clean-up safe */ +- random_data.length = 0; +- random_data.data = NULL; +- +- /* allocate and initialize the key block */ +- key_block->magic = 0; +- key_block->enctype = enctype; +- if (0 != (retval = krb5_c_keylengths(context, enctype, &rand_len, +- &key_len))) +- goto cleanup; +- +- random_data.length = rand_len; +- key_block->length = key_len; +- +- if (NULL == (key_block->contents = malloc(key_block->length))) { +- retval = ENOMEM; +- goto cleanup; +- } +- +- memset (key_block->contents, 0, key_block->length); +- +- /* If this is anonymous pkinit, use the anonymous principle for party_u_info */ +- if (party_u_info && krb5_principal_compare_any_realm(context, party_u_info, +- krb5_anonymous_principal())) +- party_u_info = (krb5_principal)krb5_anonymous_principal(); +- +- if (0 != (retval = pkinit_alg_values(context, alg_oid, &hash_len, &EVP_func))) +- goto cleanup; +- +- /* 1. reps = keydatalen (K) / hash length (H) */ +- reps = key_block->length/hash_len; +- +- /* ... and round up, if necessary */ +- if (key_block->length > (reps * hash_len)) +- reps++; +- +- /* Allocate enough space in the random data buffer to hash directly into +- * it, even if the last hash will make it bigger than the key length. */ +- if (NULL == (random_data.data = malloc(reps * hash_len))) { +- retval = ENOMEM; +- goto cleanup; +- } +- +- /* Encode the ASN.1 octet string for "SuppPubInfo" */ +- supp_pub_info_fields.enctype = enctype; +- supp_pub_info_fields.as_req = *as_req; +- supp_pub_info_fields.pk_as_rep = *pk_as_rep; +- if (0 != ((retval = encode_krb5_pkinit_supp_pub_info(&supp_pub_info_fields, +- &supp_pub_info)))) +- goto cleanup; +- +- /* Now encode the ASN.1 octet string for "OtherInfo" */ +- memset(&alg_id, 0, sizeof alg_id); +- alg_id.algorithm = *alg_oid; /*alias*/ +- +- other_info_fields.algorithm_identifier = alg_id; +- other_info_fields.party_u_info = (krb5_principal) party_u_info; +- other_info_fields.party_v_info = (krb5_principal) party_v_info; +- other_info_fields.supp_pub_info = *supp_pub_info; +- if (0 != (retval = encode_krb5_sp80056a_other_info(&other_info_fields, &other_info))) +- goto cleanup; + + /* 2. Initialize a 32-bit, big-endian bit string counter as 1. + * 3. For i = 1 to reps by 1, do the following: +@@ -2471,8 +2439,9 @@ pkinit_alg_agility_kdf(krb5_context context, + goto cleanup; + } + +- /* 4. Set key = Hash1 || Hash2 || ... so that length of key is K bytes. */ +- if (!EVP_DigestFinal(ctx, (uint8_t *)random_data.data + offset, &s)) { ++ /* 4. Set key = Hash1 || Hash2 || ... so that length of key is K ++ * bytes. */ ++ if (!EVP_DigestFinal(ctx, (unsigned char *)out + offset, &s)) { + krb5_set_error_message(context, KRB5_CRYPTO_INTERNAL, + "Call to OpenSSL EVP_DigestUpdate() returned an error."); + retval = KRB5_CRYPTO_INTERNAL; +@@ -2484,26 +2453,110 @@ pkinit_alg_agility_kdf(krb5_context context, + EVP_MD_CTX_free(ctx); + ctx = NULL; + } +- +- retval = krb5_c_random_to_key(context, enctype, &random_data, +- key_block); +- + cleanup: + EVP_MD_CTX_free(ctx); ++ return retval; ++} /* builtin_sskdf() */ ++#endif /* OSSL_KDFS */ + +- /* If this has been an error, free the allocated key_block, if any */ +- if (retval) { +- krb5_free_keyblock_contents(context, key_block); ++/* id-pkinit-kdf family, as specified by RFC 8636. */ ++krb5_error_code ++pkinit_alg_agility_kdf(krb5_context context, krb5_data *secret, ++ krb5_data *alg_oid, krb5_const_principal party_u_info, ++ krb5_const_principal party_v_info, ++ krb5_enctype enctype, krb5_data *as_req, ++ krb5_data *pk_as_rep, krb5_keyblock *key_block) ++{ ++ krb5_error_code retval; ++ size_t hash_len = 0, rand_len = 0, key_len = 0; ++ const EVP_MD *(*EVP_func)(void); ++ krb5_sp80056a_other_info other_info_fields; ++ krb5_pkinit_supp_pub_info supp_pub_info_fields; ++ krb5_data *other_info = NULL, *supp_pub_info = NULL; ++ krb5_data random_data = empty_data(); ++ krb5_algorithm_identifier alg_id; ++ unsigned int reps; ++ ++ /* Allocate and initialize the key block. */ ++ key_block->magic = 0; ++ key_block->enctype = enctype; ++ ++ /* Use separate variables to avoid alignment restriction problems. */ ++ retval = krb5_c_keylengths(context, enctype, &rand_len, &key_len); ++ if (retval) ++ goto cleanup; ++ random_data.length = rand_len; ++ key_block->length = key_len; ++ ++ key_block->contents = k5calloc(key_block->length, 1, &retval); ++ if (key_block->contents == NULL) ++ goto cleanup; ++ ++ /* If this is anonymous pkinit, use the anonymous principle for ++ * party_u_info. */ ++ if (party_u_info && ++ krb5_principal_compare_any_realm(context, party_u_info, ++ krb5_anonymous_principal())) { ++ party_u_info = (krb5_principal)krb5_anonymous_principal(); + } + +- /* free other allocated resources, either way */ +- if (random_data.data) +- free(random_data.data); ++ retval = pkinit_alg_values(context, alg_oid, &hash_len, &EVP_func); ++ if (retval) ++ goto cleanup; ++ ++ /* 1. reps = keydatalen (K) / hash length (H) */ ++ reps = key_block->length / hash_len; ++ ++ /* ... and round up, if necessary. */ ++ if (key_block->length > (reps * hash_len)) ++ reps++; ++ ++ /* Allocate enough space in the random data buffer to hash directly into ++ * it, even if the last hash will make it bigger than the key length. */ ++ random_data.data = k5alloc(reps * hash_len, &retval); ++ if (random_data.data == NULL) ++ goto cleanup; ++ ++ /* Encode the ASN.1 octet string for "SuppPubInfo". */ ++ supp_pub_info_fields.enctype = enctype; ++ supp_pub_info_fields.as_req = *as_req; ++ supp_pub_info_fields.pk_as_rep = *pk_as_rep; ++ retval = encode_krb5_pkinit_supp_pub_info(&supp_pub_info_fields, ++ &supp_pub_info); ++ if (retval) ++ goto cleanup; ++ ++ /* Now encode the ASN.1 octet string for "OtherInfo". */ ++ memset(&alg_id, 0, sizeof(alg_id)); ++ alg_id.algorithm = *alg_oid; ++ other_info_fields.algorithm_identifier = alg_id; ++ other_info_fields.party_u_info = (krb5_principal)party_u_info; ++ other_info_fields.party_v_info = (krb5_principal)party_v_info; ++ other_info_fields.supp_pub_info = *supp_pub_info; ++ retval = encode_krb5_sp80056a_other_info(&other_info_fields, &other_info); ++ if (retval) ++ goto cleanup; ++ ++#ifdef OSSL_KDFS ++ retval = openssl_sskdf(context, hash_len, secret, other_info, ++ random_data.data, key_block->length); ++#else ++ retval = builtin_sskdf(context, reps, hash_len, EVP_func, secret, ++ other_info, random_data.data, key_block->length); ++#endif ++ if (retval) ++ goto cleanup; ++ ++ retval = krb5_c_random_to_key(context, enctype, &random_data, key_block); ++cleanup: ++ if (retval) ++ krb5_free_keyblock_contents(context, key_block); ++ ++ zapfree(random_data.data, random_data.length); + krb5_free_data(context, other_info); + krb5_free_data(context, supp_pub_info); +- + return retval; +-} /*pkinit_alg_agility_kdf() */ ++} + + /* Call DH_compute_key() and ensure that we left-pad short results instead of + * leaving junk bytes at the end of the buffer. */ diff --git a/krb5-1.17post5-FIPS-with-PRNG-and-RADIUS-without-SPA.patch b/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch similarity index 95% rename from krb5-1.17post5-FIPS-with-PRNG-and-RADIUS-without-SPA.patch rename to krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index 29c8f67..415d74b 100644 --- a/krb5-1.17post5-FIPS-with-PRNG-and-RADIUS-without-SPA.patch +++ b/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,7 +1,7 @@ -From ca3c0fc3fd80b3a9953da47f64beb8b24bd46f08 Mon Sep 17 00:00:00 2001 +From 80b56b04d90fcacd9f78fed305c7d5528d863b38 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 -Subject: [PATCH] krb5-1.17post5 FIPS with PRNG and RADIUS without SPAKE +Subject: [PATCH] krb5-1.17post6 FIPS with PRNG and RADIUS and MD4 NB: Use openssl's PRNG in FIPS mode and taint within krad. @@ -15,12 +15,12 @@ This will slow down some calls slightly (FIPS_mode() takes multiple locks), but not for any ciphers we care about - which is to say that AES is fine. Shame about SPAKE though. -post5 removes SPAKE entirely. +post6 restores MD4 (and therefore keygen-only RC4). --- src/lib/crypto/krb/prng.c | 11 ++++- .../crypto/openssl/enc_provider/camellia.c | 6 +++ src/lib/crypto/openssl/enc_provider/rc4.c | 13 +++++- - .../crypto/openssl/hash_provider/hash_evp.c | 4 ++ + .../crypto/openssl/hash_provider/hash_evp.c | 12 +++++ src/lib/crypto/openssl/hmac.c | 6 ++- src/lib/krad/attr.c | 45 ++++++++++++++----- src/lib/krad/attrset.c | 5 ++- @@ -31,7 +31,7 @@ post5 removes SPAKE entirely. src/lib/krad/t_attrset.c | 4 +- src/plugins/preauth/spake/spake_client.c | 6 +++ src/plugins/preauth/spake/spake_kdc.c | 6 +++ - 14 files changed, 121 insertions(+), 33 deletions(-) + 14 files changed, 129 insertions(+), 33 deletions(-) diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c index cb9ca9b98..f0e9984ca 100644 @@ -127,15 +127,30 @@ index a65d57b7a..6ccaca94a 100644 * The cipher state here is a saved pointer to a struct arcfour_state * object, rather than a flat byte array as in most enc providers. The diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c -index 957ed8d9c..8c1fd7f59 100644 +index 957ed8d9c..915da9dbe 100644 --- a/src/lib/crypto/openssl/hash_provider/hash_evp.c +++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c -@@ -64,12 +64,16 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, +@@ -49,6 +49,11 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, + if (ctx == NULL) + return ENOMEM; + ++ if (type == EVP_md4()) { ++ /* See comment below in hash_md4(). */ ++ EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_NON_FIPS_ALLOW); ++ } ++ + ok = EVP_DigestInit_ex(ctx, type, NULL); + for (i = 0; i < num_data; i++) { + if (!SIGN_IOV(&data[i])) +@@ -64,12 +69,19 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, static krb5_error_code hash_md4(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) { -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; ++ /* ++ * MD4 is needed in FIPS mode to perform key generation for RC4 keys used ++ * by IPA. These keys are only used along a (separately) secured channel ++ * for legacy reasons when performing trusts to Active Directory. ++ */ return hash_evp(EVP_md4(), data, num_data, output); } diff --git a/krb5.spec b/krb5.spec index 57e54a7..a0c1eac 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 47%{?dist} +Release: 48%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -119,12 +119,15 @@ Patch157: Skip-URI-tests-when-using-asan.patch Patch158: Fix-memory-leaks-in-soft-pkcs11-code.patch Patch159: Initialize-life-rlife-in-kdcpolicy-interface.patch Patch160: Fix-KCM-client-time-offset-propagation.patch -Patch161: krb5-1.17post5-FIPS-with-PRNG-and-RADIUS-without-SPA.patch Patch162: Simplify-krb5_dbe_def_search_enctype.patch Patch163: Squash-apparent-forward-null-in-clnttcp_create.patch Patch164: Remove-null-check-in-krb5_gss_duplicate_name.patch Patch165: Fix-KDC-crash-when-logging-PKINIT-enctypes.patch Patch166: Log-unknown-enctypes-as-unsupported-in-KDC.patch +Patch167: Fix-minor-errors-in-softpkcs11.patch +Patch168: Update-test-suite-cert-message-digest-to-sha256.patch +Patch169: Use-backported-version-of-OpenSSL-3-KDF-interface.patch +Patch170: krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -175,7 +178,9 @@ BuildRequires: hostname BuildRequires: iproute BuildRequires: libverto-devel BuildRequires: openldap-devel -BuildRequires: openssl-devel >= 0.9.8 + +# KDF support +BuildRequires: openssl-devel >= 1.1.1d-4 %ifarch %{ix86} x86_64 BuildRequires: yasm @@ -731,6 +736,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Nov 19 2019 Robbie Harwood - 1.17-48 +- Use OpenSSL's backported KDFs +- Restore MD4 in FIPS mode (for samba) + * Fri Nov 08 2019 Robbie Harwood - 1.17-47 - Add default_principal_flags to example kdc.conf From 4b8056ef0872ea65404ccd362a646501ed88a3d1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 20 Nov 2019 14:16:04 -0500 Subject: [PATCH 135/304] Fix kadmin addprinc -randkey -kvno --- Fix-kadmin-addprinc-randkey-kvno.patch | 45 ++++++++++++++++++++++++++ krb5.spec | 6 +++- 2 files changed, 50 insertions(+), 1 deletion(-) create mode 100644 Fix-kadmin-addprinc-randkey-kvno.patch diff --git a/Fix-kadmin-addprinc-randkey-kvno.patch b/Fix-kadmin-addprinc-randkey-kvno.patch new file mode 100644 index 0000000..8ddeba7 --- /dev/null +++ b/Fix-kadmin-addprinc-randkey-kvno.patch @@ -0,0 +1,45 @@ +From 2c0d9a91c34f315f860fc857dd84863d048b6105 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sat, 16 Nov 2019 19:54:51 -0500 +Subject: [PATCH] Fix kadmin addprinc -randkey -kvno + +Commit f07bca9fc94a5cf2e3c0f58226c7973a4b86b7a9 made addprinc -randkey +use a single RPC request, but the server-side handling always creates +the random keys with kvno 1. If a kvno is specified in the RPC +request, set the kvno of the key data after creating it. Reported by +Andreas Ladanyi. + +ticket: 8848 +tags: pullup +target_version: 1.17-next +target_version: 1.16-next + +(cherry picked from commit 462e85208d57b8d4120c99e801fbd156b9ccf16f) +--- + src/lib/kadm5/srv/svr_principal.c | 6 +++++- + 1 file changed, 5 insertions(+), 1 deletion(-) + +diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c +index 48cac0c11..a1ecdbfc4 100644 +--- a/src/lib/kadm5/srv/svr_principal.c ++++ b/src/lib/kadm5/srv/svr_principal.c +@@ -302,7 +302,7 @@ kadm5_create_principal_3(void *server_handle, + kadm5_server_handle_t handle = server_handle; + krb5_keyblock *act_mkey; + krb5_kvno act_kvno; +- int new_n_ks_tuple = 0; ++ int new_n_ks_tuple = 0, i; + krb5_key_salt_tuple *new_ks_tuple = NULL; + + CHECK_HANDLE(server_handle); +@@ -468,6 +468,10 @@ kadm5_create_principal_3(void *server_handle, + /* Null password means create with random key (new in 1.8). */ + ret = krb5_dbe_crk(handle->context, &master_keyblock, + new_ks_tuple, new_n_ks_tuple, FALSE, kdb); ++ if (mask & KADM5_KVNO) { ++ for (i = 0; i < kdb->n_key_data; i++) ++ kdb->key_data[i].key_data_kvno = entry->kvno; ++ } + } + if (ret) + goto cleanup; diff --git a/krb5.spec b/krb5.spec index a0c1eac..90dc0fc 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 48%{?dist} +Release: 49%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -128,6 +128,7 @@ Patch167: Fix-minor-errors-in-softpkcs11.patch Patch168: Update-test-suite-cert-message-digest-to-sha256.patch Patch169: Use-backported-version-of-OpenSSL-3-KDF-interface.patch Patch170: krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +Patch171: Fix-kadmin-addprinc-randkey-kvno.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -736,6 +737,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Nov 20 2019 Robbie Harwood - 1.17-49 +- Fix kadmin addprinc -randkey -kvno + * Tue Nov 19 2019 Robbie Harwood - 1.17-48 - Use OpenSSL's backported KDFs - Restore MD4 in FIPS mode (for samba) From b9ea889e2a8ee35b8d5f332e8f08f4dc11ac4107 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 20 Nov 2019 21:13:58 +0000 Subject: [PATCH 136/304] Add runtime openssl version requirement too --- krb5.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 90dc0fc..b6f1683 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 49%{?dist} +Release: 50%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -182,6 +182,7 @@ BuildRequires: openldap-devel # KDF support BuildRequires: openssl-devel >= 1.1.1d-4 +Requires: openssl-libs >= 1.1.1d-4 %ifarch %{ix86} x86_64 BuildRequires: yasm @@ -737,6 +738,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Nov 20 2019 Robbie Harwood - 1.17-50 +- Add runtime openssl version requirement too + * Wed Nov 20 2019 Robbie Harwood - 1.17-49 - Fix kadmin addprinc -randkey -kvno From 4c128ec39a027b4ce1a40558293c68099edb2f8c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 20 Nov 2019 23:03:40 +0000 Subject: [PATCH 137/304] Fix runtime openssl version to actually propogate --- krb5.spec | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/krb5.spec b/krb5.spec index b6f1683..d670cb3 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 50%{?dist} +Release: 51%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -179,10 +179,7 @@ BuildRequires: hostname BuildRequires: iproute BuildRequires: libverto-devel BuildRequires: openldap-devel - -# KDF support BuildRequires: openssl-devel >= 1.1.1d-4 -Requires: openssl-libs >= 1.1.1d-4 %ifarch %{ix86} x86_64 BuildRequires: yasm @@ -215,6 +212,7 @@ to install this package. %package libs Summary: The non-admin shared libraries used by Kerberos 5 +Requires: openssl-libs >= 1.1.1d-4 Requires: coreutils, gawk, grep, sed Requires: keyutils-libs >= 1.5.8 Requires: /etc/crypto-policies/back-ends/krb5.config @@ -738,6 +736,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Nov 20 2019 Robbie Harwood - 1.17-51 +- Fix runtime openssl version to actually propogate + * Wed Nov 20 2019 Robbie Harwood - 1.17-50 - Add runtime openssl version requirement too From 76d9979dc3b5b7c00e3a2d599732d290f5fcdafd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 21 Nov 2019 22:06:25 +0000 Subject: [PATCH 138/304] Turns out openssl has an epoch --- krb5.spec | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/krb5.spec b/krb5.spec index d670cb3..a5bae41 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 51%{?dist} +Release: 52%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -179,7 +179,7 @@ BuildRequires: hostname BuildRequires: iproute BuildRequires: libverto-devel BuildRequires: openldap-devel -BuildRequires: openssl-devel >= 1.1.1d-4 +BuildRequires: openssl-devel >= 1:1.1.1d-4 %ifarch %{ix86} x86_64 BuildRequires: yasm @@ -212,7 +212,7 @@ to install this package. %package libs Summary: The non-admin shared libraries used by Kerberos 5 -Requires: openssl-libs >= 1.1.1d-4 +Requires: openssl-libs >= 1:1.1.1d-4 Requires: coreutils, gawk, grep, sed Requires: keyutils-libs >= 1.5.8 Requires: /etc/crypto-policies/back-ends/krb5.config @@ -736,6 +736,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Nov 21 2019 Robbie Harwood - 1.17-52 +- Turns out openssl has an epoch + * Wed Nov 20 2019 Robbie Harwood - 1.17-51 - Fix runtime openssl version to actually propogate From 02c0c74c74c4ad439cb633465bff05d25c4aea72 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 27 Nov 2019 12:36:19 -0500 Subject: [PATCH 139/304] Various gssalloc fixes --- ...nonicalize_hostname-fallback-support.patch | 2 +- ...on-and-enctype-flag-for-deprecations.patch | 2 +- ...ing-newlines-to-deprecation-warnings.patch | 2 +- Add-soft-pkcs11-source-code.patch | 2 +- Add-tests-for-KCM-ccache-type.patch | 2 +- Add-zapfreedata-convenience-function.patch | 2 +- Address-some-optimized-out-memset-calls.patch | 2 +- ...-alignment-warnings-in-openssl-rc4.c.patch | 2 +- ...llocating-a-register-in-zap-assembly.patch | 2 +- ...ore-errors-in-OpenSSL-crypto-backend.patch | 2 +- ...er-comment-for-krb5_cc_start_seq_get.patch | 2 +- ...able-flag-instead-of-denying-request.patch | 2 +- Display-unsupported-enctype-names.patch | 2 +- ...-error-on-invalid-enctypes-in-keytab.patch | 2 +- ...ctypes-in-gss_set_allowable_enctypes.patch | 2 +- ...ity-defects-in-soft-pkcs11-test-code.patch | 2 +- Fix-KCM-client-time-offset-propagation.patch | 2 +- ...C-crash-when-logging-PKINIT-enctypes.patch | 2 +- ...alm-change-logic-in-FILE-remove_cred.patch | 2 +- Fix-kadmin-addprinc-randkey-kvno.patch | 2 +- ...emory-leak-in-none-replay-cache-type.patch | 2 +- Fix-memory-leaks-in-soft-pkcs11-code.patch | 2 +- Fix-minor-errors-in-softpkcs11.patch | 2 +- Fix-potential-close-1-in-cc_file.c.patch | 2 +- Fix-some-return-code-handling-bugs.patch | 2 +- ...5_cc_remove_cred-for-remaining-types.patch | 2 +- ...messages-from-kadmin-change_password.patch | 2 +- ...ebug-log-proper-ticket-enctype-names.patch | 2 +- ...ec-always-log-non-permitted-enctypes.patch | 2 +- ...ze-life-rlife-in-kdcpolicy-interface.patch | 2 +- ...ize-some-data-structure-magic-fields.patch | 2 +- ...known-enctypes-as-unsupported-in-KDC.patch | 2 +- ...ype-names-in-KDC-logs-human-readable.patch | 2 +- Mark-deprecated-enctypes-when-used.patch | 2 +- ...-the-doc-kadm5-tex-files-as-historic.patch | 2 +- ...ze-example-enctypes-in-documentation.patch | 2 +- ...exit-path-in-gss_krb5int_copy_ccache.patch | 2 +- Properly-size-ifdef-in-k5_cccol_lock.patch | 2 +- Remove-3des-support.patch | 2 +- ...beros-v4-support-vestiges-from-ccapi.patch | 2 +- ...-PKINIT-draft-9-ASN.1-code-and-types.patch | 2 +- Remove-PKINIT-draft-9-support.patch | 2 +- ...api-related-comments-in-configure.ac.patch | 2 +- Remove-checksum-type-profile-variables.patch | 2 +- Remove-confvalidator-utility.patch | 2 +- ...d-variable-def_kslist-from-two-files.patch | 2 +- ...ygen-generated-HTML-output-for-ccapi.patch | 2 +- ...admin-RPC-support-for-setting-v4-key.patch | 2 +- Remove-krb5int_c_combine_keys.patch | 2 +- Remove-more-dead-code.patch | 2 +- Remove-now-unused-checksum-functions.patch | 2 +- ...ull-check-in-krb5_gss_duplicate_name.patch | 2 +- ...ovsec_adm_export-dump-format-support.patch | 2 +- Remove-srvtab-support.patch | 4 +- Remove-strerror-calls-from-k5_get_error.patch | 2 +- ...e-support-for-no-flags-SAM-2-preauth.patch | 2 +- Remove-support-for-single-DES-and-CRC.patch | 2 +- Remove-the-v4-and-afs3-salt-types.patch | 2 +- Set-a-more-modern-default-ksu-CMD_PATH.patch | 2 +- Simplify-SAM-2-as_key-handling.patch | 2 +- Simplify-krb5_dbe_def_search_enctype.patch | 2 +- Simply-OpenSSL-PKCS7-decryption-code.patch | 2 +- Skip-URI-tests-when-using-asan.patch | 2 +- ...arent-forward-null-in-clnttcp_create.patch | 2 +- Support-389ds-s-lockout-model.patch | 2 +- ....1-SAM-tests-to-use-a-modern-enctype.patch | 2 +- ...lt-krb5kdc-mkey-manual-entry-enctype.patch | 2 +- ...-suite-cert-message-digest-to-sha256.patch | 2 +- ...t-suite-to-avoid-single-DES-enctypes.patch | 2 +- ...d-version-of-OpenSSL-3-KDF-interface.patch | 2 +- Use-imported-soft-pkcs11-for-tests.patch | 2 +- Use-secure_getenv-where-appropriate.patch | 2 +- Various-gssalloc-fixes.patch | 142 ++++++++++++++++++ krb5-1.11-kpasswdtest.patch | 21 --- krb5-1.11-run_user_0.patch | 44 ------ ...t6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 2 +- krb5.spec | 8 +- 77 files changed, 221 insertions(+), 142 deletions(-) create mode 100644 Various-gssalloc-fixes.patch delete mode 100644 krb5-1.11-kpasswdtest.patch delete mode 100644 krb5-1.11-run_user_0.patch diff --git a/Add-dns_canonicalize_hostname-fallback-support.patch b/Add-dns_canonicalize_hostname-fallback-support.patch index caa8c58..31c4db8 100644 --- a/Add-dns_canonicalize_hostname-fallback-support.patch +++ b/Add-dns_canonicalize_hostname-fallback-support.patch @@ -1,4 +1,4 @@ -From 1723d5cf07693d8fb249956ee73ca9f4436f95da Mon Sep 17 00:00:00 2001 +From 947ba07fe50c4bb6188d453fd3f6b0b9ef6d5288 Mon Sep 17 00:00:00 2001 From: Simo Sorce Date: Tue, 4 Dec 2018 15:22:55 -0500 Subject: [PATCH] Add dns_canonicalize_hostname=fallback support diff --git a/Add-function-and-enctype-flag-for-deprecations.patch b/Add-function-and-enctype-flag-for-deprecations.patch index f268fcf..937c86c 100644 --- a/Add-function-and-enctype-flag-for-deprecations.patch +++ b/Add-function-and-enctype-flag-for-deprecations.patch @@ -1,4 +1,4 @@ -From 5817cf4b254ab7f266d74ba30ca2a0ffa26e803e Mon Sep 17 00:00:00 2001 +From 15ac04c3e0d02c36643427ac943d344711cd8b50 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 16:16:57 -0500 Subject: [PATCH] Add function and enctype flag for deprecations diff --git a/Add-missing-newlines-to-deprecation-warnings.patch b/Add-missing-newlines-to-deprecation-warnings.patch index 173cd61..dfd555c 100644 --- a/Add-missing-newlines-to-deprecation-warnings.patch +++ b/Add-missing-newlines-to-deprecation-warnings.patch @@ -1,4 +1,4 @@ -From 4928699bdfd051bf0d69afee0b15574c15f40a48 Mon Sep 17 00:00:00 2001 +From 98b86c4f1ca794a18cbe957b6d520380fe424240 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 21 May 2019 12:52:26 -0400 Subject: [PATCH] Add missing newlines to deprecation warnings diff --git a/Add-soft-pkcs11-source-code.patch b/Add-soft-pkcs11-source-code.patch index 4152b5e..07b0da7 100644 --- a/Add-soft-pkcs11-source-code.patch +++ b/Add-soft-pkcs11-source-code.patch @@ -1,4 +1,4 @@ -From a186597238ae40e167ce041857b5bd1f94ee2383 Mon Sep 17 00:00:00 2001 +From d80e1a0f07591c1fedc9cfc2cbb6ab7e54b55287 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 20 Jun 2019 10:45:18 -0400 Subject: [PATCH] Add soft-pkcs11 source code diff --git a/Add-tests-for-KCM-ccache-type.patch b/Add-tests-for-KCM-ccache-type.patch index 1397480..3d3dd31 100644 --- a/Add-tests-for-KCM-ccache-type.patch +++ b/Add-tests-for-KCM-ccache-type.patch @@ -1,4 +1,4 @@ -From ae2475679b7b0e9381eac5d134c06cfc559d7d1b Mon Sep 17 00:00:00 2001 +From bb8109eaafe65f323052493f7539c88204799b70 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Nov 2018 00:27:35 -0500 Subject: [PATCH] Add tests for KCM ccache type diff --git a/Add-zapfreedata-convenience-function.patch b/Add-zapfreedata-convenience-function.patch index 4a6ce0b..9318b33 100644 --- a/Add-zapfreedata-convenience-function.patch +++ b/Add-zapfreedata-convenience-function.patch @@ -1,4 +1,4 @@ -From 7fb0b432d9192360ec3439a7f5c33ad8366064f1 Mon Sep 17 00:00:00 2001 +From 90cf4ccec641d9bc466d4e404d36d486b3573a07 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 14 Mar 2019 11:26:44 -0400 Subject: [PATCH] Add zapfreedata() convenience function diff --git a/Address-some-optimized-out-memset-calls.patch b/Address-some-optimized-out-memset-calls.patch index 5a5880d..3b234b5 100644 --- a/Address-some-optimized-out-memset-calls.patch +++ b/Address-some-optimized-out-memset-calls.patch @@ -1,4 +1,4 @@ -From b54bce8e7b54c8700467fefcc74623fa50234046 Mon Sep 17 00:00:00 2001 +From 842ffb8cd2f47844346c6a88ff7575c6d131644b Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 30 Dec 2018 16:40:28 -0500 Subject: [PATCH] Address some optimized-out memset() calls diff --git a/Avoid-alignment-warnings-in-openssl-rc4.c.patch b/Avoid-alignment-warnings-in-openssl-rc4.c.patch index 7aa9e28..848d4f6 100644 --- a/Avoid-alignment-warnings-in-openssl-rc4.c.patch +++ b/Avoid-alignment-warnings-in-openssl-rc4.c.patch @@ -1,4 +1,4 @@ -From c39a5710d0e4039a4f2bbd53ec284eb89d3b83c4 Mon Sep 17 00:00:00 2001 +From ceb6a10c14ec83b0d4d1bb6f792917e6945995d6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 15:14:49 -0400 Subject: [PATCH] Avoid alignment warnings in openssl rc4.c diff --git a/Avoid-allocating-a-register-in-zap-assembly.patch b/Avoid-allocating-a-register-in-zap-assembly.patch index 20d1fac..0ad558b 100644 --- a/Avoid-allocating-a-register-in-zap-assembly.patch +++ b/Avoid-allocating-a-register-in-zap-assembly.patch @@ -1,4 +1,4 @@ -From 7491d9ed5c358960c6344c2581db9cafaf308f06 Mon Sep 17 00:00:00 2001 +From df3bfd244f8b4601f8750599270eb98cadccdafe Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Thu, 3 Jan 2019 17:19:32 +0100 Subject: [PATCH] Avoid allocating a register in zap() assembly diff --git a/Check-more-errors-in-OpenSSL-crypto-backend.patch b/Check-more-errors-in-OpenSSL-crypto-backend.patch index 4143944..e4dba05 100644 --- a/Check-more-errors-in-OpenSSL-crypto-backend.patch +++ b/Check-more-errors-in-OpenSSL-crypto-backend.patch @@ -1,4 +1,4 @@ -From 842524798c7f69edcef3f01cae7a9a6f126ed1dc Mon Sep 17 00:00:00 2001 +From 8eee70cc192adf9c0c11061c48d708e0157a9399 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 22 Apr 2019 14:26:42 -0400 Subject: [PATCH] Check more errors in OpenSSL crypto backend diff --git a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch index 6bfc18f..8794052 100644 --- a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch +++ b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch @@ -1,4 +1,4 @@ -From 2f50c282127bf8d4c570986c212fbc1e910fb8c5 Mon Sep 17 00:00:00 2001 +From eb8d1bbf210b159384859dd482657a31de80a787 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Apr 2019 14:18:57 -0400 Subject: [PATCH] Clarify header comment for krb5_cc_start_seq_get() diff --git a/Clear-forwardable-flag-instead-of-denying-request.patch b/Clear-forwardable-flag-instead-of-denying-request.patch index 05e4dbd..2527d65 100644 --- a/Clear-forwardable-flag-instead-of-denying-request.patch +++ b/Clear-forwardable-flag-instead-of-denying-request.patch @@ -1,4 +1,4 @@ -From 6bd9bc03f2ad2aa5415d738c28180def7e17874f Mon Sep 17 00:00:00 2001 +From 24d3008698d6c654ab079413583c9f1359ad8f59 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 15 Nov 2018 13:40:43 -0500 Subject: [PATCH] Clear forwardable flag instead of denying request diff --git a/Display-unsupported-enctype-names.patch b/Display-unsupported-enctype-names.patch index af727f7..fdc118e 100644 --- a/Display-unsupported-enctype-names.patch +++ b/Display-unsupported-enctype-names.patch @@ -1,4 +1,4 @@ -From 144eea330aba65a140c0e0bf66ad3cfe06f28899 Mon Sep 17 00:00:00 2001 +From 756e069368719f53444b5a819753fdeda5561994 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 21 May 2019 13:34:39 -0400 Subject: [PATCH] Display unsupported enctype names diff --git a/Don-t-error-on-invalid-enctypes-in-keytab.patch b/Don-t-error-on-invalid-enctypes-in-keytab.patch index cf8daea..1d385b7 100644 --- a/Don-t-error-on-invalid-enctypes-in-keytab.patch +++ b/Don-t-error-on-invalid-enctypes-in-keytab.patch @@ -1,4 +1,4 @@ -From 84bb2b804c69830ff2dc405b1a2bd7893291d8e6 Mon Sep 17 00:00:00 2001 +From 261e67018b25412c53a290c429612bb55569428e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 10 Jul 2019 17:10:16 -0400 Subject: [PATCH] Don't error on invalid enctypes in keytab diff --git a/Filter-enctypes-in-gss_set_allowable_enctypes.patch b/Filter-enctypes-in-gss_set_allowable_enctypes.patch index f63eba1..1e10259 100644 --- a/Filter-enctypes-in-gss_set_allowable_enctypes.patch +++ b/Filter-enctypes-in-gss_set_allowable_enctypes.patch @@ -1,4 +1,4 @@ -From aa3b2bb07bf48375b2391b31e68d0abf7ba5e4ea Mon Sep 17 00:00:00 2001 +From 675edf995b497d681732a2909df21d8e4fe11e07 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 16 Jul 2019 00:15:42 -0400 Subject: [PATCH] Filter enctypes in gss_set_allowable_enctypes() diff --git a/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch b/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch index a4324c2..40cd54e 100644 --- a/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch +++ b/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch @@ -1,4 +1,4 @@ -From 28db01445d2807d51b5045c0a04d5e49905de504 Mon Sep 17 00:00:00 2001 +From 0acc96dccbb4f4e75584ee39239da392b919f5f8 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 20 Jul 2019 00:51:52 -0400 Subject: [PATCH] Fix Coverity defects in soft-pkcs11 test code diff --git a/Fix-KCM-client-time-offset-propagation.patch b/Fix-KCM-client-time-offset-propagation.patch index 4071488..4159a3a 100644 --- a/Fix-KCM-client-time-offset-propagation.patch +++ b/Fix-KCM-client-time-offset-propagation.patch @@ -1,4 +1,4 @@ -From 7e81b8077cf2cf186dadb96b064573f7c221fbf3 Mon Sep 17 00:00:00 2001 +From 48dd1debf9bd7b04195aeb435d54eefde39bc35e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 14 Aug 2019 13:52:27 -0400 Subject: [PATCH] Fix KCM client time offset propagation diff --git a/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch b/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch index 208d2ef..5cbe40a 100644 --- a/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch +++ b/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch @@ -1,4 +1,4 @@ -From b3ccbf6ba3f662d0671b0abd10017562f76a190a Mon Sep 17 00:00:00 2001 +From fd25fce46c2454b7386d2725dba493471a2e3fe8 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 25 Sep 2019 12:57:56 -0400 Subject: [PATCH] Fix KDC crash when logging PKINIT enctypes diff --git a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch index 28dfd3c..92201a0 100644 --- a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch +++ b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch @@ -1,4 +1,4 @@ -From 7ed0d71eb3eef640e57f3c55f8aeac636cce3110 Mon Sep 17 00:00:00 2001 +From 508863ce900694d4a78af60361e23be59143aac8 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 16 Apr 2019 10:47:35 -0400 Subject: [PATCH] Fix config realm change logic in FILE remove_cred diff --git a/Fix-kadmin-addprinc-randkey-kvno.patch b/Fix-kadmin-addprinc-randkey-kvno.patch index 8ddeba7..0bb97cf 100644 --- a/Fix-kadmin-addprinc-randkey-kvno.patch +++ b/Fix-kadmin-addprinc-randkey-kvno.patch @@ -1,4 +1,4 @@ -From 2c0d9a91c34f315f860fc857dd84863d048b6105 Mon Sep 17 00:00:00 2001 +From 5e0baa51f69ae9f67865d808213bda5872ee7dc6 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 16 Nov 2019 19:54:51 -0500 Subject: [PATCH] Fix kadmin addprinc -randkey -kvno diff --git a/Fix-memory-leak-in-none-replay-cache-type.patch b/Fix-memory-leak-in-none-replay-cache-type.patch index 03b5f59..ae20f54 100644 --- a/Fix-memory-leak-in-none-replay-cache-type.patch +++ b/Fix-memory-leak-in-none-replay-cache-type.patch @@ -1,4 +1,4 @@ -From e215c213a068d96599a3069339bfb3e4024ef61b Mon Sep 17 00:00:00 2001 +From 0bb94eb7c3b231279d8ded0484ecea10ebe89302 Mon Sep 17 00:00:00 2001 From: Corene Casper Date: Sat, 16 Feb 2019 00:49:26 -0500 Subject: [PATCH] Fix memory leak in 'none' replay cache type diff --git a/Fix-memory-leaks-in-soft-pkcs11-code.patch b/Fix-memory-leaks-in-soft-pkcs11-code.patch index 9bcb794..19c85de 100644 --- a/Fix-memory-leaks-in-soft-pkcs11-code.patch +++ b/Fix-memory-leaks-in-soft-pkcs11-code.patch @@ -1,4 +1,4 @@ -From 5cc80472e7a8b0fb3002f229ffb104dccf8bd120 Mon Sep 17 00:00:00 2001 +From 8087bdce8a5e9912f693ab199198a5bf4db54001 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 5 Aug 2019 01:53:51 -0400 Subject: [PATCH] Fix memory leaks in soft-pkcs11 code diff --git a/Fix-minor-errors-in-softpkcs11.patch b/Fix-minor-errors-in-softpkcs11.patch index a19708a..510151b 100644 --- a/Fix-minor-errors-in-softpkcs11.patch +++ b/Fix-minor-errors-in-softpkcs11.patch @@ -1,4 +1,4 @@ -From df5026b47d2f90729b76071fd7cae48d46c4d1f6 Mon Sep 17 00:00:00 2001 +From 0d27dbf488547b9ca6780f23e5e40fa820928385 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 8 Nov 2019 14:28:56 -0500 Subject: [PATCH] Fix minor errors in softpkcs11 diff --git a/Fix-potential-close-1-in-cc_file.c.patch b/Fix-potential-close-1-in-cc_file.c.patch index 598dc72..d3bd8ba 100644 --- a/Fix-potential-close-1-in-cc_file.c.patch +++ b/Fix-potential-close-1-in-cc_file.c.patch @@ -1,4 +1,4 @@ -From 013037d7c4f6073d28ea2b0bd53eca04bae170ea Mon Sep 17 00:00:00 2001 +From 5917d1d1a51c2a4b243661710b3107b1bc43fff0 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 18 Apr 2019 13:39:37 -0400 Subject: [PATCH] Fix potential close(-1) in cc_file.c diff --git a/Fix-some-return-code-handling-bugs.patch b/Fix-some-return-code-handling-bugs.patch index 5b62208..c948b89 100644 --- a/Fix-some-return-code-handling-bugs.patch +++ b/Fix-some-return-code-handling-bugs.patch @@ -1,4 +1,4 @@ -From 6f0b53aea2dfcccf1efe0c1c6142eeeaf998f2bb Mon Sep 17 00:00:00 2001 +From 3612a7873e5e07b51d47c6c38f8a83e0b3d51e20 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 14:05:38 -0400 Subject: [PATCH] Fix some return code handling bugs diff --git a/Implement-krb5_cc_remove_cred-for-remaining-types.patch b/Implement-krb5_cc_remove_cred-for-remaining-types.patch index b77a6e5..9f1a551 100644 --- a/Implement-krb5_cc_remove_cred-for-remaining-types.patch +++ b/Implement-krb5_cc_remove_cred-for-remaining-types.patch @@ -1,4 +1,4 @@ -From ebc913ea73bfc439f293831f19db83ec83622d51 Mon Sep 17 00:00:00 2001 +From 43e56c3442e7601a6e041a010f0ca9acb6021d8f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 1 Apr 2019 14:28:48 -0400 Subject: [PATCH] Implement krb5_cc_remove_cred for remaining types diff --git a/Improve-error-messages-from-kadmin-change_password.patch b/Improve-error-messages-from-kadmin-change_password.patch index a656099..192b7a4 100644 --- a/Improve-error-messages-from-kadmin-change_password.patch +++ b/Improve-error-messages-from-kadmin-change_password.patch @@ -1,4 +1,4 @@ -From f9123277a5b4e27d5fea3dbae0889dcb527115fc Mon Sep 17 00:00:00 2001 +From 3f5781029e48d7f2f5a694a4d3e19691eefde87f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 13:13:16 -0400 Subject: [PATCH] Improve error messages from kadmin change_password diff --git a/In-kpropd-debug-log-proper-ticket-enctype-names.patch b/In-kpropd-debug-log-proper-ticket-enctype-names.patch index d7a9e67..790eed1 100644 --- a/In-kpropd-debug-log-proper-ticket-enctype-names.patch +++ b/In-kpropd-debug-log-proper-ticket-enctype-names.patch @@ -1,4 +1,4 @@ -From 0e1c9fa82ea2a5f32a6ce937ffe9b1aef21e133e Mon Sep 17 00:00:00 2001 +From d1bbb1c98c3c2deb3713959281a3eee2b5019480 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 13:41:16 -0500 Subject: [PATCH] In kpropd, debug-log proper ticket enctype names diff --git a/In-rd_req_dec-always-log-non-permitted-enctypes.patch b/In-rd_req_dec-always-log-non-permitted-enctypes.patch index ce45dec..6598c56 100644 --- a/In-rd_req_dec-always-log-non-permitted-enctypes.patch +++ b/In-rd_req_dec-always-log-non-permitted-enctypes.patch @@ -1,4 +1,4 @@ -From 92e46dabccaf7dfecfcb85bb87b773b734724ccb Mon Sep 17 00:00:00 2001 +From 803290c5773eb2e6a344f0ad0a01645e30c79031 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Jan 2019 17:14:42 -0500 Subject: [PATCH] In rd_req_dec, always log non-permitted enctypes diff --git a/Initialize-life-rlife-in-kdcpolicy-interface.patch b/Initialize-life-rlife-in-kdcpolicy-interface.patch index 6922f09..7b07133 100644 --- a/Initialize-life-rlife-in-kdcpolicy-interface.patch +++ b/Initialize-life-rlife-in-kdcpolicy-interface.patch @@ -1,4 +1,4 @@ -From b448801a1ab19d89cc069e63f5ce5acbc9f3cd8d Mon Sep 17 00:00:00 2001 +From 17d1dbd3b2eb3961c061b140f8a7641405e59d44 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Aug 2019 14:07:22 -0400 Subject: [PATCH] Initialize life/rlife in kdcpolicy interface diff --git a/Initialize-some-data-structure-magic-fields.patch b/Initialize-some-data-structure-magic-fields.patch index 09f846c..952b75a 100644 --- a/Initialize-some-data-structure-magic-fields.patch +++ b/Initialize-some-data-structure-magic-fields.patch @@ -1,4 +1,4 @@ -From 0f05d25ddecba6d8dd5de5c1b2e31f45942b9a85 Mon Sep 17 00:00:00 2001 +From e4e58539348e886f9ac39881d576c7512fc37a2b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 13:36:38 -0400 Subject: [PATCH] Initialize some data structure magic fields diff --git a/Log-unknown-enctypes-as-unsupported-in-KDC.patch b/Log-unknown-enctypes-as-unsupported-in-KDC.patch index 4938bd7..75664bb 100644 --- a/Log-unknown-enctypes-as-unsupported-in-KDC.patch +++ b/Log-unknown-enctypes-as-unsupported-in-KDC.patch @@ -1,4 +1,4 @@ -From 3324eb7fcc3cf4effdde891cefdc37526ff20cf7 Mon Sep 17 00:00:00 2001 +From 78e9d11d8a6c05218d18b9b200d1de888a95503c Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 27 Sep 2019 16:55:37 -0400 Subject: [PATCH] Log unknown enctypes as unsupported in KDC diff --git a/Make-etype-names-in-KDC-logs-human-readable.patch b/Make-etype-names-in-KDC-logs-human-readable.patch index abf5c29..74a4c48 100644 --- a/Make-etype-names-in-KDC-logs-human-readable.patch +++ b/Make-etype-names-in-KDC-logs-human-readable.patch @@ -1,4 +1,4 @@ -From c955111643b4ef9a005a083d8f2aa39ec4af81ec Mon Sep 17 00:00:00 2001 +From a50161ee09ef887493afcf5f3901f9d0a9c20fc5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 8 Jan 2019 17:42:35 -0500 Subject: [PATCH] Make etype names in KDC logs human-readable diff --git a/Mark-deprecated-enctypes-when-used.patch b/Mark-deprecated-enctypes-when-used.patch index a5f93ca..5fe75e1 100644 --- a/Mark-deprecated-enctypes-when-used.patch +++ b/Mark-deprecated-enctypes-when-used.patch @@ -1,4 +1,4 @@ -From 945c21ddafbedfe57dfbf9ca3e7b0185cb4b7175 Mon Sep 17 00:00:00 2001 +From de5bdedc1d27ee3e9ff7072614ea1316064b222a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 10 Jan 2019 16:34:54 -0500 Subject: [PATCH] Mark deprecated enctypes when used diff --git a/Mark-the-doc-kadm5-tex-files-as-historic.patch b/Mark-the-doc-kadm5-tex-files-as-historic.patch index 1956a98..9c85e2e 100644 --- a/Mark-the-doc-kadm5-tex-files-as-historic.patch +++ b/Mark-the-doc-kadm5-tex-files-as-historic.patch @@ -1,4 +1,4 @@ -From b68ee166602b787c5acabe3d1b4780e527d672a7 Mon Sep 17 00:00:00 2001 +From 4ebd1454a32df78d10c7de4c09ac8dc8ebb4f41b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 11 Apr 2019 18:33:04 -0400 Subject: [PATCH] Mark the doc/kadm5 tex files as historic diff --git a/Modernize-example-enctypes-in-documentation.patch b/Modernize-example-enctypes-in-documentation.patch index a94494e..4341da7 100644 --- a/Modernize-example-enctypes-in-documentation.patch +++ b/Modernize-example-enctypes-in-documentation.patch @@ -1,4 +1,4 @@ -From eb4fb8cb24e6cac194acc2c507b334658fc5431d Mon Sep 17 00:00:00 2001 +From c547bf2cae39d503de3ac3670d99b2cc324c6567 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 11 Apr 2019 18:25:41 -0400 Subject: [PATCH] Modernize example enctypes in documentation diff --git a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch index 83c6526..9bd7966 100644 --- a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch +++ b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch @@ -1,4 +1,4 @@ -From b3ccfda0de6a9dd1248d9b15f31819421e36848e Mon Sep 17 00:00:00 2001 +From 8fe3c4bde435c68a74c8075661a432cd1d3c17b9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 14:32:33 -0400 Subject: [PATCH] Modernize exit path in gss_krb5int_copy_ccache() diff --git a/Properly-size-ifdef-in-k5_cccol_lock.patch b/Properly-size-ifdef-in-k5_cccol_lock.patch index ede89ef..ab6596e 100644 --- a/Properly-size-ifdef-in-k5_cccol_lock.patch +++ b/Properly-size-ifdef-in-k5_cccol_lock.patch @@ -1,4 +1,4 @@ -From 4b087e84f6c399df56143eca50858c185d31633f Mon Sep 17 00:00:00 2001 +From 916861d361be090965e1b4df4f60fce64206cf79 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Feb 2019 11:50:35 -0500 Subject: [PATCH] Properly size #ifdef in k5_cccol_lock() diff --git a/Remove-3des-support.patch b/Remove-3des-support.patch index f3b07fc..161f68d 100644 --- a/Remove-3des-support.patch +++ b/Remove-3des-support.patch @@ -1,4 +1,4 @@ -From 17365a6131488b518b0f50e08d24697acce79d44 Mon Sep 17 00:00:00 2001 +From bea06cc4cf4df3d545fb3da1a9429aa28f690d80 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] Remove 3des support diff --git a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch index 334ecff..2234329 100644 --- a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch +++ b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch @@ -1,4 +1,4 @@ -From 275df1b1b846a66c966a8108ba3b4d148f68ef6f Mon Sep 17 00:00:00 2001 +From 2bbf5046e0d1ad4a4927570ebed5aa661e322024 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 14:37:38 -0400 Subject: [PATCH] Remove Kerberos v4 support vestiges from ccapi diff --git a/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch b/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch index ddbd8bb..80e2b57 100644 --- a/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch +++ b/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch @@ -1,4 +1,4 @@ -From 054cd1bad9941e6936345da3e9a839c8fdbd9ba3 Mon Sep 17 00:00:00 2001 +From a52788c294f56a023b7bc05286990717ec993158 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 18 Jun 2019 11:40:48 -0400 Subject: [PATCH] Remove PKINIT draft 9 ASN.1 code and types diff --git a/Remove-PKINIT-draft-9-support.patch b/Remove-PKINIT-draft-9-support.patch index 8b43a05..a0dd50d 100644 --- a/Remove-PKINIT-draft-9-support.patch +++ b/Remove-PKINIT-draft-9-support.patch @@ -1,4 +1,4 @@ -From a3e44c1ab745535fe9e2c396a09ff8d713810cc4 Mon Sep 17 00:00:00 2001 +From f00a9416374087dbf135215a13c5316477ca2f45 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 18 Jun 2019 13:06:44 -0400 Subject: [PATCH] Remove PKINIT draft 9 support diff --git a/Remove-ccapi-related-comments-in-configure.ac.patch b/Remove-ccapi-related-comments-in-configure.ac.patch index 8770cb8..4dbf2d5 100644 --- a/Remove-ccapi-related-comments-in-configure.ac.patch +++ b/Remove-ccapi-related-comments-in-configure.ac.patch @@ -1,4 +1,4 @@ -From 68fdf968da2ed338340a835a0c942991c7c02986 Mon Sep 17 00:00:00 2001 +From 8096d0c97bcb5ac1ad830b6f354b4e32c90ac4cf Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Apr 2019 16:01:22 -0400 Subject: [PATCH] Remove ccapi-related comments in configure.ac diff --git a/Remove-checksum-type-profile-variables.patch b/Remove-checksum-type-profile-variables.patch index a392a60..c55c79f 100644 --- a/Remove-checksum-type-profile-variables.patch +++ b/Remove-checksum-type-profile-variables.patch @@ -1,4 +1,4 @@ -From 46aa5ffd844a280f368d78c7c395bb1b2323dfbe Mon Sep 17 00:00:00 2001 +From 443754ab8140d87e2e5bbd595f39827461d6498a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 13 May 2019 14:19:57 -0400 Subject: [PATCH] Remove checksum type profile variables diff --git a/Remove-confvalidator-utility.patch b/Remove-confvalidator-utility.patch index e361ef6..afaa7de 100644 --- a/Remove-confvalidator-utility.patch +++ b/Remove-confvalidator-utility.patch @@ -1,4 +1,4 @@ -From f7b50b3e40ae43666fb10b0a1502f9cd88b6a2fe Mon Sep 17 00:00:00 2001 +From 0d471a72541952ebe090919610cf9ba8b31d1291 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Apr 2019 14:58:19 -0400 Subject: [PATCH] Remove confvalidator utility diff --git a/Remove-dead-variable-def_kslist-from-two-files.patch b/Remove-dead-variable-def_kslist-from-two-files.patch index fa8e263..ae6022e 100644 --- a/Remove-dead-variable-def_kslist-from-two-files.patch +++ b/Remove-dead-variable-def_kslist-from-two-files.patch @@ -1,4 +1,4 @@ -From cc4aace493d1caaca9edebcc5d836e847e358afd Mon Sep 17 00:00:00 2001 +From 20be29dfddcbc4afda79eae2bcd3d5de3bb0330d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 16:57:51 -0400 Subject: [PATCH] Remove dead variable def_kslist from two files diff --git a/Remove-doxygen-generated-HTML-output-for-ccapi.patch b/Remove-doxygen-generated-HTML-output-for-ccapi.patch index 0cb10b6..c936cb0 100644 --- a/Remove-doxygen-generated-HTML-output-for-ccapi.patch +++ b/Remove-doxygen-generated-HTML-output-for-ccapi.patch @@ -1,4 +1,4 @@ -From 8629596d91d41914a6996b897845f601af7b59fc Mon Sep 17 00:00:00 2001 +From 33c39a069022eab2d56ccbaf0be31b3b5b0071a2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 14:15:58 -0400 Subject: [PATCH] Remove doxygen-generated HTML output for ccapi diff --git a/Remove-kadmin-RPC-support-for-setting-v4-key.patch b/Remove-kadmin-RPC-support-for-setting-v4-key.patch index 28fc9e4..a545984 100644 --- a/Remove-kadmin-RPC-support-for-setting-v4-key.patch +++ b/Remove-kadmin-RPC-support-for-setting-v4-key.patch @@ -1,4 +1,4 @@ -From 43c7d037b5e6bac3345c069af70f3cd6fd947f3f Mon Sep 17 00:00:00 2001 +From e1e27c400736ca304c9cbdc52e2946c65e047a21 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 16:14:46 -0400 Subject: [PATCH] Remove kadmin RPC support for setting v4 key diff --git a/Remove-krb5int_c_combine_keys.patch b/Remove-krb5int_c_combine_keys.patch index 64e2e72..287a586 100644 --- a/Remove-krb5int_c_combine_keys.patch +++ b/Remove-krb5int_c_combine_keys.patch @@ -1,4 +1,4 @@ -From 343e236ed2637a826f4d53ff60d2b2bc349100d6 Mon Sep 17 00:00:00 2001 +From 6181039fc3f70c073e4125d98d8a28aec9c223bf Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 18 Apr 2019 17:27:07 -0400 Subject: [PATCH] Remove krb5int_c_combine_keys() diff --git a/Remove-more-dead-code.patch b/Remove-more-dead-code.patch index 2d547cb..59f19b6 100644 --- a/Remove-more-dead-code.patch +++ b/Remove-more-dead-code.patch @@ -1,4 +1,4 @@ -From 740ab812bedd022ec60e7ef63bf4be12dd730d67 Mon Sep 17 00:00:00 2001 +From 067f8685648e4a316ea0dfe90694d5a7b64c8848 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 9 May 2019 14:07:24 -0400 Subject: [PATCH] Remove more dead code diff --git a/Remove-now-unused-checksum-functions.patch b/Remove-now-unused-checksum-functions.patch index e84ae39..780de71 100644 --- a/Remove-now-unused-checksum-functions.patch +++ b/Remove-now-unused-checksum-functions.patch @@ -1,4 +1,4 @@ -From 25418e054868301e1a1a5824913b74f2479e1b15 Mon Sep 17 00:00:00 2001 +From 3d6b547ca1454b8113c6f83161def1f995c04616 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 28 Jun 2019 13:09:47 -0400 Subject: [PATCH] Remove now-unused checksum functions diff --git a/Remove-null-check-in-krb5_gss_duplicate_name.patch b/Remove-null-check-in-krb5_gss_duplicate_name.patch index 1bb832f..9e99e78 100644 --- a/Remove-null-check-in-krb5_gss_duplicate_name.patch +++ b/Remove-null-check-in-krb5_gss_duplicate_name.patch @@ -1,4 +1,4 @@ -From 09855e99697edcfb6228f266e8c7b6889ea48b23 Mon Sep 17 00:00:00 2001 +From 13df40bef90954d1c373c5e9cece1d5897c7afcf Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 30 Aug 2019 11:19:52 -0400 Subject: [PATCH] Remove null check in krb5_gss_duplicate_name() diff --git a/Remove-ovsec_adm_export-dump-format-support.patch b/Remove-ovsec_adm_export-dump-format-support.patch index ebc053c..619397d 100644 --- a/Remove-ovsec_adm_export-dump-format-support.patch +++ b/Remove-ovsec_adm_export-dump-format-support.patch @@ -1,4 +1,4 @@ -From 5125a9bd20b2fa2b0f420dc20780d08af1cc91a6 Mon Sep 17 00:00:00 2001 +From 019dc5d64d6e1c0fabaf9957bef5b633eb6fa475 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 22 Jan 2019 18:34:58 -0500 Subject: [PATCH] Remove ovsec_adm_export dump format support diff --git a/Remove-srvtab-support.patch b/Remove-srvtab-support.patch index dbdf99f..ee8f44e 100644 --- a/Remove-srvtab-support.patch +++ b/Remove-srvtab-support.patch @@ -1,4 +1,4 @@ -From c742a3eacc7b2dc92bf8dc83f5e8ea602dded8c2 Mon Sep 17 00:00:00 2001 +From a768fb06f0df69f0b6985058e21c72448587d2a8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 9 Oct 2017 15:58:33 -0400 Subject: [PATCH] Remove srvtab support @@ -194,7 +194,7 @@ index 6d119a2b6..e2e005d22 100644 - return result; -} diff --git a/src/kadmin/testing/proto/krb5.conf.proto b/src/kadmin/testing/proto/krb5.conf.proto -index 9c4bc1de7..f91cf70f3 100644 +index 00c442978..e710852d4 100644 --- a/src/kadmin/testing/proto/krb5.conf.proto +++ b/src/kadmin/testing/proto/krb5.conf.proto @@ -1,6 +1,6 @@ diff --git a/Remove-strerror-calls-from-k5_get_error.patch b/Remove-strerror-calls-from-k5_get_error.patch index 42db53c..a42610a 100644 --- a/Remove-strerror-calls-from-k5_get_error.patch +++ b/Remove-strerror-calls-from-k5_get_error.patch @@ -1,4 +1,4 @@ -From bf8f84d2116af9aba33202f44fdaf04a76430410 Mon Sep 17 00:00:00 2001 +From 1aff5025ec486d1f8239e3a135156e33ea5e764d Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 6 Jun 2019 11:46:58 -0400 Subject: [PATCH] Remove strerror() calls from k5_get_error() diff --git a/Remove-support-for-no-flags-SAM-2-preauth.patch b/Remove-support-for-no-flags-SAM-2-preauth.patch index 9f95b3d..aac83a7 100644 --- a/Remove-support-for-no-flags-SAM-2-preauth.patch +++ b/Remove-support-for-no-flags-SAM-2-preauth.patch @@ -1,4 +1,4 @@ -From 9e71fcd5db98fb7ace02e8684486cc7f092d82ad Mon Sep 17 00:00:00 2001 +From f87c6fabd1073637c4798fcdd3fdab060edb0731 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 17 Apr 2019 17:07:46 -0400 Subject: [PATCH] Remove support for no-flags SAM-2 preauth diff --git a/Remove-support-for-single-DES-and-CRC.patch b/Remove-support-for-single-DES-and-CRC.patch index 6c7e2e9..bfe5418 100644 --- a/Remove-support-for-single-DES-and-CRC.patch +++ b/Remove-support-for-single-DES-and-CRC.patch @@ -1,4 +1,4 @@ -From 2cc75213f2227cffeaf60ad0c4ef60b5466b073e Mon Sep 17 00:00:00 2001 +From c13f1fde8931a9199a7a15a5b011f02ed2615e9f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 24 May 2019 13:12:03 -0400 Subject: [PATCH] Remove support for single-DES and CRC diff --git a/Remove-the-v4-and-afs3-salt-types.patch b/Remove-the-v4-and-afs3-salt-types.patch index 671e933..eb3e9fc 100644 --- a/Remove-the-v4-and-afs3-salt-types.patch +++ b/Remove-the-v4-and-afs3-salt-types.patch @@ -1,4 +1,4 @@ -From 35395701a34f68e99abfe23d07b93c59cd63ad50 Mon Sep 17 00:00:00 2001 +From cebf1ea82c4d2dc4494ad0af7525fd324e6d92e2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 24 May 2019 13:11:44 -0400 Subject: [PATCH] Remove the v4 and afs3 salt types diff --git a/Set-a-more-modern-default-ksu-CMD_PATH.patch b/Set-a-more-modern-default-ksu-CMD_PATH.patch index 31f9602..df99231 100644 --- a/Set-a-more-modern-default-ksu-CMD_PATH.patch +++ b/Set-a-more-modern-default-ksu-CMD_PATH.patch @@ -1,4 +1,4 @@ -From 6b50f9c5b2a1b856e65fa69de05e7c05d2b89614 Mon Sep 17 00:00:00 2001 +From 47fc137981db0b2b9834765e28f70b151a88cb83 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:32:09 -0400 Subject: [PATCH] Set a more modern default ksu CMD_PATH diff --git a/Simplify-SAM-2-as_key-handling.patch b/Simplify-SAM-2-as_key-handling.patch index 8929e65..125a91b 100644 --- a/Simplify-SAM-2-as_key-handling.patch +++ b/Simplify-SAM-2-as_key-handling.patch @@ -1,4 +1,4 @@ -From 3b4f517a3a403943877e925ae0eb1745611b996f Mon Sep 17 00:00:00 2001 +From 9c80f80f48f3b761145e97914a4488398435f2d6 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 5 May 2019 18:53:27 -0400 Subject: [PATCH] Simplify SAM-2 as_key handling diff --git a/Simplify-krb5_dbe_def_search_enctype.patch b/Simplify-krb5_dbe_def_search_enctype.patch index 64bf9b0..a12d203 100644 --- a/Simplify-krb5_dbe_def_search_enctype.patch +++ b/Simplify-krb5_dbe_def_search_enctype.patch @@ -1,4 +1,4 @@ -From f311350db606e8395930b8b1e4d821096133d3c4 Mon Sep 17 00:00:00 2001 +From 5ff802a443dfd47e2f43a37de0dc439a1c583849 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Aug 2019 16:19:12 -0400 Subject: [PATCH] Simplify krb5_dbe_def_search_enctype() diff --git a/Simply-OpenSSL-PKCS7-decryption-code.patch b/Simply-OpenSSL-PKCS7-decryption-code.patch index 94ef2a1..0cf844c 100644 --- a/Simply-OpenSSL-PKCS7-decryption-code.patch +++ b/Simply-OpenSSL-PKCS7-decryption-code.patch @@ -1,4 +1,4 @@ -From 172390c584726ecd5747b064587acc1db44a98ca Mon Sep 17 00:00:00 2001 +From 8cc93c83241cd96a8565c427418f6c3f13609b65 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 13:13:06 -0400 Subject: [PATCH] Simply OpenSSL PKCS7 decryption code diff --git a/Skip-URI-tests-when-using-asan.patch b/Skip-URI-tests-when-using-asan.patch index 4c82306..e6ff6e5 100644 --- a/Skip-URI-tests-when-using-asan.patch +++ b/Skip-URI-tests-when-using-asan.patch @@ -1,4 +1,4 @@ -From 345ffa545ef85ae5c6384c931759cc5353f4d434 Mon Sep 17 00:00:00 2001 +From 1b251fe463c1284381612aeb7f2271d28d171d9d Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 3 Aug 2019 13:30:28 -0400 Subject: [PATCH] Skip URI tests when using asan diff --git a/Squash-apparent-forward-null-in-clnttcp_create.patch b/Squash-apparent-forward-null-in-clnttcp_create.patch index b89761c..81845e3 100644 --- a/Squash-apparent-forward-null-in-clnttcp_create.patch +++ b/Squash-apparent-forward-null-in-clnttcp_create.patch @@ -1,4 +1,4 @@ -From d52e7db97781dbdb518368e143c031ed5c6217cc Mon Sep 17 00:00:00 2001 +From dabc30f0500718ef39706849b778524d4fa2152d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 30 Aug 2019 11:16:58 -0400 Subject: [PATCH] Squash apparent forward-null in clnttcp_create() diff --git a/Support-389ds-s-lockout-model.patch b/Support-389ds-s-lockout-model.patch index 2800e0b..50d81e9 100644 --- a/Support-389ds-s-lockout-model.patch +++ b/Support-389ds-s-lockout-model.patch @@ -1,4 +1,4 @@ -From 2c00970b3fe53b38f976c79f648fdd75a2682287 Mon Sep 17 00:00:00 2001 +From d46ea68d04b91320aa7eb96f85ca77b98fd44e88 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:44 -0400 Subject: [PATCH] Support 389ds's lockout model diff --git a/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch b/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch index 980797e..90b654d 100644 --- a/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch +++ b/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch @@ -1,4 +1,4 @@ -From 152e88043117927c334fead93bb3bd3dd74593b7 Mon Sep 17 00:00:00 2001 +From 12ffeca5a708add9461e71300d58a08ea99ed6e4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 16 Apr 2019 14:16:39 -0400 Subject: [PATCH] Update ASN.1 SAM tests to use a modern enctype diff --git a/Update-default-krb5kdc-mkey-manual-entry-enctype.patch b/Update-default-krb5kdc-mkey-manual-entry-enctype.patch index ff99839..b14e637 100644 --- a/Update-default-krb5kdc-mkey-manual-entry-enctype.patch +++ b/Update-default-krb5kdc-mkey-manual-entry-enctype.patch @@ -1,4 +1,4 @@ -From 2957d2186ee2b60b80e6ba97a1f5d661ccb20f30 Mon Sep 17 00:00:00 2001 +From a3e73d1a874ad68c7ef0cb2ac0fa529b87b29710 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 20 May 2019 16:52:57 -0400 Subject: [PATCH] Update default krb5kdc mkey manual-entry enctype diff --git a/Update-test-suite-cert-message-digest-to-sha256.patch b/Update-test-suite-cert-message-digest-to-sha256.patch index 1de5b28..9f91576 100644 --- a/Update-test-suite-cert-message-digest-to-sha256.patch +++ b/Update-test-suite-cert-message-digest-to-sha256.patch @@ -1,4 +1,4 @@ -From 264cc429ce5fee191738d74f14d34ce91944ec2f Mon Sep 17 00:00:00 2001 +From 73e08f464b5a55c1d86b3d08f1fd0f391253548f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 12 Nov 2019 13:38:59 -0500 Subject: [PATCH] Update test suite cert message digest to sha256 diff --git a/Update-test-suite-to-avoid-single-DES-enctypes.patch b/Update-test-suite-to-avoid-single-DES-enctypes.patch index a6ef987..8a67bdb 100644 --- a/Update-test-suite-to-avoid-single-DES-enctypes.patch +++ b/Update-test-suite-to-avoid-single-DES-enctypes.patch @@ -1,4 +1,4 @@ -From 8fe2563e133e904e56c3ed3b9b970bb632c843b6 Mon Sep 17 00:00:00 2001 +From ec9180a78e84c71940c3ef3834bb22aae1245d91 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 24 May 2019 13:11:55 -0400 Subject: [PATCH] Update test suite to avoid single-DES enctypes diff --git a/Use-backported-version-of-OpenSSL-3-KDF-interface.patch b/Use-backported-version-of-OpenSSL-3-KDF-interface.patch index 4857999..9408a87 100644 --- a/Use-backported-version-of-OpenSSL-3-KDF-interface.patch +++ b/Use-backported-version-of-OpenSSL-3-KDF-interface.patch @@ -1,4 +1,4 @@ -From 0e20daf7ccfe50518c89735c3dae2fde08d92325 Mon Sep 17 00:00:00 2001 +From b4099e1de59730ca7eb022891c1e1cce1d1eb001 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 15 Nov 2019 20:05:16 +0000 Subject: [PATCH] Use backported version of OpenSSL-3 KDF interface diff --git a/Use-imported-soft-pkcs11-for-tests.patch b/Use-imported-soft-pkcs11-for-tests.patch index 22e7759..098dbe8 100644 --- a/Use-imported-soft-pkcs11-for-tests.patch +++ b/Use-imported-soft-pkcs11-for-tests.patch @@ -1,4 +1,4 @@ -From 47e66724b9d5cfef84965d99c83d29e4739932e3 Mon Sep 17 00:00:00 2001 +From 3d1f71979d0a41e75f5169ecbdd594e171e8bbf6 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 20 Jun 2019 13:41:57 -0400 Subject: [PATCH] Use imported soft-pkcs11 for tests diff --git a/Use-secure_getenv-where-appropriate.patch b/Use-secure_getenv-where-appropriate.patch index 4775663..c699a0f 100644 --- a/Use-secure_getenv-where-appropriate.patch +++ b/Use-secure_getenv-where-appropriate.patch @@ -1,4 +1,4 @@ -From 13cc24f4e631ee54176430eac73be14bcd9052d3 Mon Sep 17 00:00:00 2001 +From e2fc380331455d023001d74efbe9563e271cee10 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 24 Apr 2019 16:19:50 -0400 Subject: [PATCH] Use secure_getenv() where appropriate diff --git a/Various-gssalloc-fixes.patch b/Various-gssalloc-fixes.patch new file mode 100644 index 0000000..244dccf --- /dev/null +++ b/Various-gssalloc-fixes.patch @@ -0,0 +1,142 @@ +From 9e574469b639220a34bbf3dc36a96854ad0c269a Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sat, 23 Nov 2019 11:42:59 -0500 +Subject: [PATCH] Various gssalloc fixes + +The DEBUG_GSSALLOC version of gssalloc_realloc() must add the sentinel +size to the byte count. + +The mechglue gss_decapsulate_token(), gss_encapsulate_token(), and +gss_export_sec_context() must use gssalloc_malloc() to allocate +output buffers. + +The krb5 mech's gss_export_name_composite() and gss_pseudo_random() +implementations must use gssalloc_malloc() to allocate output buffers. + +SPNEGO's gss_display_status() implementation must use gssalloc for the +output buffer. + +The sample GSS server must use gss_release_buffer() to free the result +of gss_export_sec_context(). + +ticket: 8852 (new) +tags: pullup +target_version: 1.17-next +target_version: 1.16-next + +(cherry picked from commit ab5c4259bdbe51dd3f4b5c5aff22628188d04322) +--- + src/appl/gss-sample/gss-server.c | 2 +- + src/lib/gssapi/generic/gssapi_alloc.h | 2 +- + src/lib/gssapi/krb5/naming_exts.c | 2 +- + src/lib/gssapi/krb5/prf.c | 2 +- + src/lib/gssapi/mechglue/g_decapsulate_token.c | 2 +- + src/lib/gssapi/mechglue/g_encapsulate_token.c | 2 +- + src/lib/gssapi/mechglue/g_exp_sec_context.c | 2 +- + src/lib/gssapi/spnego/spnego_mech.c | 2 +- + 8 files changed, 8 insertions(+), 8 deletions(-) + +diff --git a/src/appl/gss-sample/gss-server.c b/src/appl/gss-sample/gss-server.c +index 6b5959a1c..793fefc9f 100644 +--- a/src/appl/gss-sample/gss-server.c ++++ b/src/appl/gss-sample/gss-server.c +@@ -391,7 +391,7 @@ test_import_export_context(gss_ctx_id_t *context) + if (verbose && logfile) + fprintf(logfile, "Importing context: %7.4f seconds\n", + timeval_subtract(&tm1, &tm2)); +- free(context_token.value); ++ (void) gss_release_buffer(&min_stat, &context_token); + return 0; + } + +diff --git a/src/lib/gssapi/generic/gssapi_alloc.h b/src/lib/gssapi/generic/gssapi_alloc.h +index 9a5cd9892..d0bd4b2b0 100644 +--- a/src/lib/gssapi/generic/gssapi_alloc.h ++++ b/src/lib/gssapi/generic/gssapi_alloc.h +@@ -80,7 +80,7 @@ gssalloc_realloc(void *value, size_t size) + return gssalloc_malloc(size); + if (memcmp(p, "gssalloc", 8) != 0) + abort(); +- return (char *)realloc(p, size) + 8; ++ return (char *)realloc(p, size + 8) + 8; + } + + #else /* not _WIN32 or DEBUG_GSSALLOC */ +diff --git a/src/lib/gssapi/krb5/naming_exts.c b/src/lib/gssapi/krb5/naming_exts.c +index 41752d90b..2ac1aba33 100644 +--- a/src/lib/gssapi/krb5/naming_exts.c ++++ b/src/lib/gssapi/krb5/naming_exts.c +@@ -624,7 +624,7 @@ krb5_gss_export_name_composite(OM_uint32 *minor_status, + exp_composite_name->length += 4; /* length of encoded attributes */ + if (attrs != NULL) + exp_composite_name->length += attrs->length; +- exp_composite_name->value = malloc(exp_composite_name->length); ++ exp_composite_name->value = gssalloc_malloc(exp_composite_name->length); + if (exp_composite_name->value == NULL) { + code = ENOMEM; + goto cleanup; +diff --git a/src/lib/gssapi/krb5/prf.c b/src/lib/gssapi/krb5/prf.c +index e897074fc..f87957bdf 100644 +--- a/src/lib/gssapi/krb5/prf.c ++++ b/src/lib/gssapi/krb5/prf.c +@@ -86,7 +86,7 @@ krb5_gss_pseudo_random(OM_uint32 *minor_status, + if (desired_output_len == 0) + return GSS_S_COMPLETE; + +- prf_out->value = k5alloc(desired_output_len, &code); ++ prf_out->value = gssalloc_malloc(desired_output_len); + if (prf_out->value == NULL) { + code = KG_INPUT_TOO_LONG; + goto cleanup; +diff --git a/src/lib/gssapi/mechglue/g_decapsulate_token.c b/src/lib/gssapi/mechglue/g_decapsulate_token.c +index 934d2607c..1c04e2f27 100644 +--- a/src/lib/gssapi/mechglue/g_decapsulate_token.c ++++ b/src/lib/gssapi/mechglue/g_decapsulate_token.c +@@ -55,7 +55,7 @@ gss_decapsulate_token(gss_const_buffer_t input_token, + if (minor != 0) + return GSS_S_DEFECTIVE_TOKEN; + +- output_token->value = malloc(body_size); ++ output_token->value = gssalloc_malloc(body_size); + if (output_token->value == NULL) + return GSS_S_FAILURE; + +diff --git a/src/lib/gssapi/mechglue/g_encapsulate_token.c b/src/lib/gssapi/mechglue/g_encapsulate_token.c +index 6ce0eeb0f..850e3ee65 100644 +--- a/src/lib/gssapi/mechglue/g_encapsulate_token.c ++++ b/src/lib/gssapi/mechglue/g_encapsulate_token.c +@@ -51,7 +51,7 @@ gss_encapsulate_token(gss_const_buffer_t input_token, + assert(tokenSize > 2); + tokenSize -= 2; /* TOK_ID */ + +- output_token->value = malloc(tokenSize); ++ output_token->value = gssalloc_malloc(tokenSize); + if (output_token->value == NULL) + return GSS_S_FAILURE; + +diff --git a/src/lib/gssapi/mechglue/g_exp_sec_context.c b/src/lib/gssapi/mechglue/g_exp_sec_context.c +index 1d7990b1c..a04afe3d1 100644 +--- a/src/lib/gssapi/mechglue/g_exp_sec_context.c ++++ b/src/lib/gssapi/mechglue/g_exp_sec_context.c +@@ -112,7 +112,7 @@ gss_buffer_t interprocess_token; + + length = token.length + 4 + ctx->mech_type->length; + interprocess_token->length = length; +- interprocess_token->value = malloc(length); ++ interprocess_token->value = gssalloc_malloc(length); + if (interprocess_token->value == 0) { + *minor_status = ENOMEM; + status = GSS_S_FAILURE; +diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/spnego/spnego_mech.c +index 9d6027ce8..412b4c41c 100644 +--- a/src/lib/gssapi/spnego/spnego_mech.c ++++ b/src/lib/gssapi/spnego/spnego_mech.c +@@ -3731,7 +3731,7 @@ negotiate_mech(gss_OID_set supported, gss_OID_set received, + static spnego_token_t + make_spnego_token(const char *name) + { +- return (spnego_token_t)strdup(name); ++ return (spnego_token_t)gssalloc_strdup(name); + } + + static gss_buffer_desc diff --git a/krb5-1.11-kpasswdtest.patch b/krb5-1.11-kpasswdtest.patch deleted file mode 100644 index 5e29cad..0000000 --- a/krb5-1.11-kpasswdtest.patch +++ /dev/null @@ -1,21 +0,0 @@ -From 37c9242bf19d63c6f35086a931b9a072d5b71caf Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:52:01 -0400 -Subject: [PATCH] krb5-1.11-kpasswdtest.patch - ---- - src/kadmin/testing/proto/krb5.conf.proto | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/src/kadmin/testing/proto/krb5.conf.proto b/src/kadmin/testing/proto/krb5.conf.proto -index 00c442978..9c4bc1de7 100644 ---- a/src/kadmin/testing/proto/krb5.conf.proto -+++ b/src/kadmin/testing/proto/krb5.conf.proto -@@ -9,6 +9,7 @@ - __REALM__ = { - kdc = __KDCHOST__:1750 - admin_server = __KDCHOST__:1751 -+ kpasswd_server = __KDCHOST__:1752 - database_module = foobar_db2_module_blah - } - diff --git a/krb5-1.11-run_user_0.patch b/krb5-1.11-run_user_0.patch deleted file mode 100644 index 5b9ef9b..0000000 --- a/krb5-1.11-run_user_0.patch +++ /dev/null @@ -1,44 +0,0 @@ -From 76a67da3510e761eb01822a6db551fa3092189a3 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:49:57 -0400 -Subject: [PATCH] krb5-1.11-run_user_0.patch - -A hack: if we're looking at creating a ccache directory directly below -the /run/user/0 directory, and /run/user/0 doesn't exist, try to create -it, too. ---- - src/lib/krb5/ccache/cc_dir.c | 14 ++++++++++++++ - 1 file changed, 14 insertions(+) - -diff --git a/src/lib/krb5/ccache/cc_dir.c b/src/lib/krb5/ccache/cc_dir.c -index 73f0fe62d..4850c0d07 100644 ---- a/src/lib/krb5/ccache/cc_dir.c -+++ b/src/lib/krb5/ccache/cc_dir.c -@@ -61,6 +61,8 @@ - - #include - -+#define ROOT_SPECIAL_DCC_PARENT "/run/user/0" -+ - extern const krb5_cc_ops krb5_dcc_ops; - extern const krb5_cc_ops krb5_fcc_ops; - -@@ -237,6 +239,18 @@ verify_dir(krb5_context context, const char *dirname) - - if (stat(dirname, &st) < 0) { - if (errno == ENOENT) { -+ if (strncmp(dirname, ROOT_SPECIAL_DCC_PARENT "/", -+ sizeof(ROOT_SPECIAL_DCC_PARENT)) == 0 && -+ stat(ROOT_SPECIAL_DCC_PARENT, &st) < 0 && -+ errno == ENOENT) { -+#ifdef USE_SELINUX -+ selabel = krb5int_push_fscreatecon_for(ROOT_SPECIAL_DCC_PARENT); -+#endif -+ status = mkdir(ROOT_SPECIAL_DCC_PARENT, S_IRWXU); -+#ifdef USE_SELINUX -+ krb5int_pop_fscreatecon(selabel); -+#endif -+ } - #ifdef USE_SELINUX - selabel = krb5int_push_fscreatecon_for(dirname); - #endif diff --git a/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index 415d74b..e55cfd0 100644 --- a/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From 80b56b04d90fcacd9f78fed305c7d5528d863b38 Mon Sep 17 00:00:00 2001 +From 6048ef0ecbf45f239a6df3074975b926ce286e5a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] krb5-1.17post6 FIPS with PRNG and RADIUS and MD4 diff --git a/krb5.spec b/krb5.spec index a5bae41..10c06e9 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 52%{?dist} +Release: 53%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -54,8 +54,6 @@ Patch27: krb5-1.17-beta1-selinux-label.patch Patch30: krb5-1.15-beta1-buildconf.patch Patch31: krb5-1.3.1-dns.patch Patch34: krb5-1.9-debuginfo.patch -Patch35: krb5-1.11-run_user_0.patch -Patch36: krb5-1.11-kpasswdtest.patch Patch90: Add-tests-for-KCM-ccache-type.patch Patch92: Address-some-optimized-out-memset-calls.patch Patch94: Avoid-allocating-a-register-in-zap-assembly.patch @@ -129,6 +127,7 @@ Patch168: Update-test-suite-cert-message-digest-to-sha256.patch Patch169: Use-backported-version-of-OpenSSL-3-KDF-interface.patch Patch170: krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch Patch171: Fix-kadmin-addprinc-randkey-kvno.patch +Patch172: Various-gssalloc-fixes.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -736,6 +735,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Nov 27 2019 Robbie Harwood - 1.17-53 +- Various gssalloc fixes + * Thu Nov 21 2019 Robbie Harwood - 1.17-52 - Turns out openssl has an epoch From 4aee4bdd71818b7b56b40f3d98305474f557d143 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 6 Dec 2019 13:44:42 -0500 Subject: [PATCH 140/304] Qualify short hostnames when not using DNS --- ...y-short-hostnames-when-not-using-DNS.patch | 309 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 314 insertions(+), 1 deletion(-) create mode 100644 Qualify-short-hostnames-when-not-using-DNS.patch diff --git a/Qualify-short-hostnames-when-not-using-DNS.patch b/Qualify-short-hostnames-when-not-using-DNS.patch new file mode 100644 index 0000000..2555b77 --- /dev/null +++ b/Qualify-short-hostnames-when-not-using-DNS.patch @@ -0,0 +1,309 @@ +From 35160d8bf1aa1464d7e757c73ed11644478cc4d4 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 29 Nov 2019 20:39:38 -0500 +Subject: [PATCH] Qualify short hostnames when not using DNS + +When DNS forward canonicalization is turned off or fails, qualify +single-component hostnames with the first DNS search domain. Add the +qualify_shortname relation to override this suffix. + +For one of the tests we need to disable qualification, which is +accomplished with an empty value. Adjust k5test.py to correctly emit +empty values when writing profiles. + +ticket: 8855 (new) +(cherry picked from commit 996353767fe8afa7f67a3b5b465e4d70e18bad7c) +--- + doc/admin/conf_files/krb5_conf.rst | 9 +++++++ + src/include/k5-int.h | 1 + + src/lib/krb5/os/dnsglue.c | 23 ++++++++++++++++ + src/lib/krb5/os/os-proto.h | 2 ++ + src/lib/krb5/os/sn2princ.c | 43 +++++++++++++++++++++++++++++- + src/tests/gssapi/t_ccselect.py | 5 ++-- + src/tests/t_sn2princ.py | 12 ++++++--- + src/util/k5test.py | 34 ++++++++++++----------- + 8 files changed, 106 insertions(+), 23 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index 89f02434b..582ac8df0 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -308,6 +308,15 @@ The libdefaults section may contain any of the following relations: + If this flag is true, initial tickets will be proxiable by + default, if allowed by the KDC. The default value is false. + ++**qualify_shortname** ++ If this string is set, it determines the domain suffix for ++ single-component hostnames when DNS canonicalization is not used ++ (either because **dns_canonicalize_hostname** is false or because ++ forward canonicalization failed). The default value is the first ++ search domain of the system's DNS configuration. To disable ++ qualification of shortnames, set this relation to the empty string ++ with ``qualify_shortname = ""``. (New in release 1.18.) ++ + **rdns** + If this flag is true, reverse name lookup will be used in addition + to forward name lookup to canonicalizing hostnames for use in +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index cb328785d..7458319fa 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -280,6 +280,7 @@ typedef unsigned char u_char; + #define KRB5_CONF_PLUGIN_BASE_DIR "plugin_base_dir" + #define KRB5_CONF_PREFERRED_PREAUTH_TYPES "preferred_preauth_types" + #define KRB5_CONF_PROXIABLE "proxiable" ++#define KRB5_CONF_QUALIFY_SHORTNAME "qualify_shortname" + #define KRB5_CONF_RDNS "rdns" + #define KRB5_CONF_REALMS "realms" + #define KRB5_CONF_REALM_TRY_DOMAINS "realm_try_domains" +diff --git a/src/lib/krb5/os/dnsglue.c b/src/lib/krb5/os/dnsglue.c +index 59ff92963..e35ca9d76 100644 +--- a/src/lib/krb5/os/dnsglue.c ++++ b/src/lib/krb5/os/dnsglue.c +@@ -71,6 +71,7 @@ static int initparse(struct krb5int_dns_state *); + * Define macros to use the best available DNS search functions. INIT_HANDLE() + * returns true if handle initialization is successful, false if it is not. + * SEARCH() returns the length of the response or -1 on error. ++ * PRIMARY_DOMAIN() returns the first search domain in allocated memory. + * DECLARE_HANDLE() must be used last in the declaration list since it may + * evaluate to nothing. + */ +@@ -81,6 +82,7 @@ static int initparse(struct krb5int_dns_state *); + #define DECLARE_HANDLE(h) dns_handle_t h + #define INIT_HANDLE(h) ((h = dns_open(NULL)) != NULL) + #define SEARCH(h, n, c, t, a, l) dns_search(h, n, c, t, a, l, NULL, NULL) ++#define PRIMARY_DOMAIN(h) dns_search_list_domain(h, 0) + #define DESTROY_HANDLE(h) dns_free(h) + + #elif HAVE_RES_NINIT && HAVE_RES_NSEARCH +@@ -89,6 +91,7 @@ static int initparse(struct krb5int_dns_state *); + #define DECLARE_HANDLE(h) struct __res_state h + #define INIT_HANDLE(h) (memset(&h, 0, sizeof(h)), res_ninit(&h) == 0) + #define SEARCH(h, n, c, t, a, l) res_nsearch(&h, n, c, t, a, l) ++#define PRIMARY_DOMAIN(h) strdup(h.dnsrch[0]) + #if HAVE_RES_NDESTROY + #define DESTROY_HANDLE(h) res_ndestroy(&h) + #else +@@ -101,6 +104,7 @@ static int initparse(struct krb5int_dns_state *); + #define DECLARE_HANDLE(h) + #define INIT_HANDLE(h) (res_init() == 0) + #define SEARCH(h, n, c, t, a, l) res_search(n, c, t, a, l) ++#define PRIMARY_DOMAIN(h) strdup(_res.defdname) + #define DESTROY_HANDLE(h) + + #endif +@@ -433,6 +437,12 @@ cleanup: + return ret; + } + ++char * ++k5_primary_domain() ++{ ++ return NULL; ++} ++ + #else /* _WIN32 */ + + krb5_error_code +@@ -485,5 +495,18 @@ errout: + return retval; + } + ++char * ++k5_primary_domain() ++{ ++ char *domain; ++ DECLARE_HANDLE(h); ++ ++ if (!INIT_HANDLE(h)) ++ return NULL; ++ domain = PRIMARY_DOMAIN(h); ++ DESTROY_HANDLE(h); ++ return domain; ++} ++ + #endif /* not _WIN32 */ + #endif /* KRB5_DNS_LOOKUP */ +diff --git a/src/lib/krb5/os/os-proto.h b/src/lib/krb5/os/os-proto.h +index 066d30221..a16a34b74 100644 +--- a/src/lib/krb5/os/os-proto.h ++++ b/src/lib/krb5/os/os-proto.h +@@ -136,6 +136,8 @@ k5_make_uri_query(krb5_context context, const krb5_data *realm, + krb5_error_code k5_try_realm_txt_rr(krb5_context context, const char *prefix, + const char *name, char **realm); + ++char *k5_primary_domain(void); ++ + int _krb5_use_dns_realm (krb5_context); + int _krb5_use_dns_kdc (krb5_context); + int _krb5_conf_boolean (const char *); +diff --git a/src/lib/krb5/os/sn2princ.c b/src/lib/krb5/os/sn2princ.c +index 98d2600aa..a51761d0c 100644 +--- a/src/lib/krb5/os/sn2princ.c ++++ b/src/lib/krb5/os/sn2princ.c +@@ -50,15 +50,47 @@ use_reverse_dns(krb5_context context) + &value); + if (ret) + return DEFAULT_RDNS_LOOKUP; ++ + return value; + } + ++/* Append a domain suffix to host and return the result in allocated memory. ++ * Return NULL if no suffix is configured or on failure. */ ++static char * ++qualify_shortname(krb5_context context, const char *host) ++{ ++ krb5_error_code ret; ++ char *fqdn = NULL, *prof_domain = NULL, *os_domain = NULL; ++ const char *domain; ++ ++ ret = profile_get_string(context->profile, KRB5_CONF_LIBDEFAULTS, ++ KRB5_CONF_QUALIFY_SHORTNAME, NULL, NULL, ++ &prof_domain); ++ if (ret) ++ return NULL; ++ ++#ifdef KRB5_DNS_LOOKUP ++ if (prof_domain == NULL) ++ os_domain = k5_primary_domain(); ++#endif ++ ++ domain = (prof_domain != NULL) ? prof_domain : os_domain; ++ if (domain != NULL && *domain != '\0') { ++ if (asprintf(&fqdn, "%s.%s", host, domain) < 0) ++ fqdn = NULL; ++ } ++ ++ profile_release_string(prof_domain); ++ free(os_domain); ++ return fqdn; ++} ++ + krb5_error_code + k5_expand_hostname(krb5_context context, const char *host, + krb5_boolean is_fallback, char **canonhost_out) + { + struct addrinfo *ai = NULL, hint; +- char namebuf[NI_MAXHOST], *copy, *p; ++ char namebuf[NI_MAXHOST], *qualified = NULL, *copy, *p; + int err; + const char *canonhost; + krb5_boolean use_dns; +@@ -90,6 +122,14 @@ k5_expand_hostname(krb5_context context, const char *host, + } + } + ++ /* If we didn't use DNS and the name is just one component, try to add a ++ * domain suffix. */ ++ if (canonhost == host && strchr(host, '.') == NULL) { ++ qualified = qualify_shortname(context, host); ++ if (qualified != NULL) ++ canonhost = qualified; ++ } ++ + copy = strdup(canonhost); + if (copy == NULL) + goto cleanup; +@@ -113,6 +153,7 @@ cleanup: + /* We only return success or ENOMEM. */ + if (ai != NULL) + freeaddrinfo(ai); ++ free(qualified); + return (*canonhost_out == NULL) ? ENOMEM : 0; + } + +diff --git a/src/tests/gssapi/t_ccselect.py b/src/tests/gssapi/t_ccselect.py +index 9ca66554f..66d85880c 100755 +--- a/src/tests/gssapi/t_ccselect.py ++++ b/src/tests/gssapi/t_ccselect.py +@@ -24,8 +24,9 @@ from k5test import * + + # Create two independent realms (no cross-realm TGTs). For the + # fallback realm tests we need to control the precise server hostname, +-# so turn off DNS canonicalization. +-conf = {'libdefaults': {'dns_canonicalize_hostname': 'false'}} ++# so turn off DNS canonicalization and shortname qualification. ++conf = {'libdefaults': {'dns_canonicalize_hostname': 'false', ++ 'qualify_shortname': ''}} + r1 = K5Realm(create_user=False, krb5_conf=conf) + r2 = K5Realm(create_user=False, krb5_conf=conf, realm='KRBTEST2.COM', + portbase=62000, testdir=os.path.join(r1.testdir, 'r2')) +diff --git a/src/tests/t_sn2princ.py b/src/tests/t_sn2princ.py +index fe435a2d5..26dcb91c2 100755 +--- a/src/tests/t_sn2princ.py ++++ b/src/tests/t_sn2princ.py +@@ -6,7 +6,8 @@ conf = {'domain_realm': {'kerberos.org': 'R1', + 'example.com': 'R2', + 'mit.edu': 'R3'}} + no_rdns_conf = {'libdefaults': {'rdns': 'false'}} +-no_canon_conf = {'libdefaults': {'dns_canonicalize_hostname': 'false'}} ++no_canon_conf = {'libdefaults': {'dns_canonicalize_hostname': 'false', ++ 'qualify_shortname': 'example.com'}} + fallback_canon_conf = {'libdefaults': + {'rdns': 'false', + 'dns_canonicalize_hostname': 'fallback'}} +@@ -62,12 +63,15 @@ testu('Example.COM:xyZ', 'Example.COM:xyZ', 'R2') + testu('example.com.::123', 'example.com.::123', '') + + # With dns_canonicalize_hostname=false, we downcase and remove +-# trailing dots but do not canonicalize the hostname. Trailers do not +-# get downcased. ++# trailing dots but do not canonicalize the hostname. ++# Single-component names are qualified with the configured suffix ++# (defaulting to the first OS search domain, but Python cannot easily ++# retrieve that value so we don't test it). Trailers do not get ++# downcased. + mark('dns_canonicalize_host=false') + testnc('ptr-mismatch.kerberos.org', 'ptr-mismatch.kerberos.org', 'R1') + testnc('Example.COM', 'example.com', 'R2') +-testnc('abcde', 'abcde', '') ++testnc('abcde', 'abcde.example.com', 'R2') + testnc('example.com.:123', 'example.com:123', 'R2') + testnc('Example.COM:xyZ', 'example.com:xyZ', 'R2') + testnc('example.com.::123', 'example.com.::123', '') +diff --git a/src/util/k5test.py b/src/util/k5test.py +index feb6df7a0..c7f941303 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -918,22 +918,24 @@ class K5Realm(object): + def _subst_cfg_value(self, value): + global buildtop, srctop, hostname + template = string.Template(value) +- return template.substitute(realm=self.realm, +- testdir=self.testdir, +- buildtop=buildtop, +- srctop=srctop, +- plugins=plugins, +- hostname=hostname, +- port0=self.portbase, +- port1=self.portbase + 1, +- port2=self.portbase + 2, +- port3=self.portbase + 3, +- port4=self.portbase + 4, +- port5=self.portbase + 5, +- port6=self.portbase + 6, +- port7=self.portbase + 7, +- port8=self.portbase + 8, +- port9=self.portbase + 9) ++ subst = template.substitute(realm=self.realm, ++ testdir=self.testdir, ++ buildtop=buildtop, ++ srctop=srctop, ++ plugins=plugins, ++ hostname=hostname, ++ port0=self.portbase, ++ port1=self.portbase + 1, ++ port2=self.portbase + 2, ++ port3=self.portbase + 3, ++ port4=self.portbase + 4, ++ port5=self.portbase + 5, ++ port6=self.portbase + 6, ++ port7=self.portbase + 7, ++ port8=self.portbase + 8, ++ port9=self.portbase + 9) ++ # Empty values must be quoted to avoid a syntax error. ++ return subst if subst else '""' + + def _create_acl(self): + global hostname diff --git a/krb5.spec b/krb5.spec index 10c06e9..d2e903d 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 53%{?dist} +Release: 54%{?dist} # lookaside-cached sources; two downloads and a build artifact Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -128,6 +128,7 @@ Patch169: Use-backported-version-of-OpenSSL-3-KDF-interface.patch Patch170: krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch Patch171: Fix-kadmin-addprinc-randkey-kvno.patch Patch172: Various-gssalloc-fixes.patch +Patch173: Qualify-short-hostnames-when-not-using-DNS.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -735,6 +736,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Dec 06 2019 Robbie Harwood - 1.17-54 +- Qualify short hostnames when not using DNS + * Wed Nov 27 2019 Robbie Harwood - 1.17-53 - Various gssalloc fixes From 9d642021d7deb11ec953ecfdf8142af94feaeaf4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 12 Dec 2019 18:34:55 +0000 Subject: [PATCH 141/304] New upstream version - 1.17.1 Stop building and packaging PDFs --- .gitignore | 2 + ...nonicalize_hostname-fallback-support.patch | 6 +- ...on-and-enctype-flag-for-deprecations.patch | 2 +- ...ing-newlines-to-deprecation-warnings.patch | 2 +- Add-soft-pkcs11-source-code.patch | 2 +- Add-tests-for-KCM-ccache-type.patch | 2 +- Add-zapfreedata-convenience-function.patch | 2 +- Address-some-optimized-out-memset-calls.patch | 6 +- ...-alignment-warnings-in-openssl-rc4.c.patch | 2 +- ...llocating-a-register-in-zap-assembly.patch | 4 +- ...ore-errors-in-OpenSSL-crypto-backend.patch | 2 +- ...er-comment-for-krb5_cc_start_seq_get.patch | 2 +- ...able-flag-instead-of-denying-request.patch | 2 +- Display-unsupported-enctype-names.patch | 2 +- ...-error-on-invalid-enctypes-in-keytab.patch | 2 +- ...ctypes-in-gss_set_allowable_enctypes.patch | 2 +- ...ity-defects-in-soft-pkcs11-test-code.patch | 2 +- Fix-KCM-client-time-offset-propagation.patch | 32 -- ...C-crash-when-logging-PKINIT-enctypes.patch | 2 +- ...alm-change-logic-in-FILE-remove_cred.patch | 2 +- Fix-kadmin-addprinc-randkey-kvno.patch | 45 --- ...emory-leak-in-none-replay-cache-type.patch | 33 -- Fix-memory-leaks-in-soft-pkcs11-code.patch | 2 +- Fix-minor-errors-in-softpkcs11.patch | 2 +- Fix-potential-close-1-in-cc_file.c.patch | 2 +- Fix-some-return-code-handling-bugs.patch | 103 ------ ...5_cc_remove_cred-for-remaining-types.patch | 2 +- ...messages-from-kadmin-change_password.patch | 2 +- ...ebug-log-proper-ticket-enctype-names.patch | 2 +- ...ec-always-log-non-permitted-enctypes.patch | 2 +- ...ze-life-rlife-in-kdcpolicy-interface.patch | 41 --- ...ize-some-data-structure-magic-fields.patch | 2 +- ...known-enctypes-as-unsupported-in-KDC.patch | 2 +- ...ype-names-in-KDC-logs-human-readable.patch | 2 +- Mark-deprecated-enctypes-when-used.patch | 2 +- ...-the-doc-kadm5-tex-files-as-historic.patch | 2 +- ...ze-example-enctypes-in-documentation.patch | 9 +- ...exit-path-in-gss_krb5int_copy_ccache.patch | 2 +- Properly-size-ifdef-in-k5_cccol_lock.patch | 2 +- ...y-short-hostnames-when-not-using-DNS.patch | 309 ------------------ Remove-3des-support.patch | 31 +- ...beros-v4-support-vestiges-from-ccapi.patch | 2 +- ...-PKINIT-draft-9-ASN.1-code-and-types.patch | 2 +- Remove-PKINIT-draft-9-support.patch | 2 +- ...api-related-comments-in-configure.ac.patch | 4 +- Remove-checksum-type-profile-variables.patch | 23 +- Remove-confvalidator-utility.patch | 2 +- ...d-variable-def_kslist-from-two-files.patch | 2 +- ...ygen-generated-HTML-output-for-ccapi.patch | 2 +- ...admin-RPC-support-for-setting-v4-key.patch | 6 +- Remove-krb5int_c_combine_keys.patch | 2 +- Remove-more-dead-code.patch | 2 +- Remove-now-unused-checksum-functions.patch | 2 +- ...ull-check-in-krb5_gss_duplicate_name.patch | 2 +- ...ovsec_adm_export-dump-format-support.patch | 9 +- Remove-srvtab-support.patch | 27 +- Remove-strerror-calls-from-k5_get_error.patch | 2 +- ...e-support-for-no-flags-SAM-2-preauth.patch | 2 +- Remove-support-for-single-DES-and-CRC.patch | 52 +-- Remove-the-v4-and-afs3-salt-types.patch | 15 +- Set-a-more-modern-default-ksu-CMD_PATH.patch | 2 +- Simplify-SAM-2-as_key-handling.patch | 2 +- Simplify-krb5_dbe_def_search_enctype.patch | 2 +- Simply-OpenSSL-PKCS7-decryption-code.patch | 2 +- Skip-URI-tests-when-using-asan.patch | 2 +- ...arent-forward-null-in-clnttcp_create.patch | 2 +- Support-389ds-s-lockout-model.patch | 2 +- ....1-SAM-tests-to-use-a-modern-enctype.patch | 2 +- ...lt-krb5kdc-mkey-manual-entry-enctype.patch | 10 +- ...-suite-cert-message-digest-to-sha256.patch | 2 +- ...t-suite-to-avoid-single-DES-enctypes.patch | 2 +- ...d-version-of-OpenSSL-3-KDF-interface.patch | 4 +- Use-imported-soft-pkcs11-for-tests.patch | 4 +- Use-secure_getenv-where-appropriate.patch | 2 +- Various-gssalloc-fixes.patch | 142 -------- krb5-1.12.1-pam.patch | 4 +- krb5-1.15-beta1-buildconf.patch | 2 +- krb5-1.17-beta1-selinux-label.patch | 4 +- ...t6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 2 +- krb5-1.3.1-dns.patch | 2 +- krb5-1.9-debuginfo.patch | 2 +- krb5.spec | 73 +---- sources | 5 +- 83 files changed, 195 insertions(+), 920 deletions(-) delete mode 100644 Fix-KCM-client-time-offset-propagation.patch delete mode 100644 Fix-kadmin-addprinc-randkey-kvno.patch delete mode 100644 Fix-memory-leak-in-none-replay-cache-type.patch delete mode 100644 Fix-some-return-code-handling-bugs.patch delete mode 100644 Initialize-life-rlife-in-kdcpolicy-interface.patch delete mode 100644 Qualify-short-hostnames-when-not-using-DNS.patch delete mode 100644 Various-gssalloc-fixes.patch diff --git a/.gitignore b/.gitignore index 523856e..045b4dc 100644 --- a/.gitignore +++ b/.gitignore @@ -175,3 +175,5 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.17-pdfs.tar /krb5-1.17.tar.gz /krb5-1.17.tar.gz.asc +/krb5-1.17.1.tar.gz +/krb5-1.17.1.tar.gz.asc diff --git a/Add-dns_canonicalize_hostname-fallback-support.patch b/Add-dns_canonicalize_hostname-fallback-support.patch index 31c4db8..f9bc3d3 100644 --- a/Add-dns_canonicalize_hostname-fallback-support.patch +++ b/Add-dns_canonicalize_hostname-fallback-support.patch @@ -1,4 +1,4 @@ -From 947ba07fe50c4bb6188d453fd3f6b0b9ef6d5288 Mon Sep 17 00:00:00 2001 +From b952b5ac5301ed9f4ae49300e90631ae0562b012 Mon Sep 17 00:00:00 2001 From: Simo Sorce Date: Tue, 4 Dec 2018 15:22:55 -0500 Subject: [PATCH] Add dns_canonicalize_hostname=fallback support @@ -28,10 +28,10 @@ ticket: 8765 (new) 10 files changed, 167 insertions(+), 18 deletions(-) diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 7b4389f6b..e9f7e8c59 100644 +index 4adb084a6..d1e1a222d 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst -@@ -201,6 +201,10 @@ The libdefaults section may contain any of the following relations: +@@ -195,6 +195,10 @@ The libdefaults section may contain any of the following relations: means that short hostnames will not be canonicalized to fully-qualified hostnames. The default value is true. diff --git a/Add-function-and-enctype-flag-for-deprecations.patch b/Add-function-and-enctype-flag-for-deprecations.patch index 937c86c..1e15da3 100644 --- a/Add-function-and-enctype-flag-for-deprecations.patch +++ b/Add-function-and-enctype-flag-for-deprecations.patch @@ -1,4 +1,4 @@ -From 15ac04c3e0d02c36643427ac943d344711cd8b50 Mon Sep 17 00:00:00 2001 +From 397ce771e195edf63f796f1cf917bc65b4eafd8c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 16:16:57 -0500 Subject: [PATCH] Add function and enctype flag for deprecations diff --git a/Add-missing-newlines-to-deprecation-warnings.patch b/Add-missing-newlines-to-deprecation-warnings.patch index dfd555c..ecfe47b 100644 --- a/Add-missing-newlines-to-deprecation-warnings.patch +++ b/Add-missing-newlines-to-deprecation-warnings.patch @@ -1,4 +1,4 @@ -From 98b86c4f1ca794a18cbe957b6d520380fe424240 Mon Sep 17 00:00:00 2001 +From 6946ea68b719da8434fc4c09b4ed97be91d8464b Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 21 May 2019 12:52:26 -0400 Subject: [PATCH] Add missing newlines to deprecation warnings diff --git a/Add-soft-pkcs11-source-code.patch b/Add-soft-pkcs11-source-code.patch index 07b0da7..ef8dc9d 100644 --- a/Add-soft-pkcs11-source-code.patch +++ b/Add-soft-pkcs11-source-code.patch @@ -1,4 +1,4 @@ -From d80e1a0f07591c1fedc9cfc2cbb6ab7e54b55287 Mon Sep 17 00:00:00 2001 +From 5ede44dfeffca55c793fe5ea49b438497dff027b Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 20 Jun 2019 10:45:18 -0400 Subject: [PATCH] Add soft-pkcs11 source code diff --git a/Add-tests-for-KCM-ccache-type.patch b/Add-tests-for-KCM-ccache-type.patch index 3d3dd31..08d9215 100644 --- a/Add-tests-for-KCM-ccache-type.patch +++ b/Add-tests-for-KCM-ccache-type.patch @@ -1,4 +1,4 @@ -From bb8109eaafe65f323052493f7539c88204799b70 Mon Sep 17 00:00:00 2001 +From 0b63afda1a399a37274021115524db1e65675cb9 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Nov 2018 00:27:35 -0500 Subject: [PATCH] Add tests for KCM ccache type diff --git a/Add-zapfreedata-convenience-function.patch b/Add-zapfreedata-convenience-function.patch index 9318b33..b9ae932 100644 --- a/Add-zapfreedata-convenience-function.patch +++ b/Add-zapfreedata-convenience-function.patch @@ -1,4 +1,4 @@ -From 90cf4ccec641d9bc466d4e404d36d486b3573a07 Mon Sep 17 00:00:00 2001 +From b99ba3fa4bc99c2925fa4b509004d694e9d7ac68 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 14 Mar 2019 11:26:44 -0400 Subject: [PATCH] Add zapfreedata() convenience function diff --git a/Address-some-optimized-out-memset-calls.patch b/Address-some-optimized-out-memset-calls.patch index 3b234b5..a97f91d 100644 --- a/Address-some-optimized-out-memset-calls.patch +++ b/Address-some-optimized-out-memset-calls.patch @@ -1,4 +1,4 @@ -From 842ffb8cd2f47844346c6a88ff7575c6d131644b Mon Sep 17 00:00:00 2001 +From 95fec44aebd6a4d815f88a0b5a53517c4f3175f4 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 30 Dec 2018 16:40:28 -0500 Subject: [PATCH] Address some optimized-out memset() calls @@ -60,10 +60,10 @@ index bb1072fe4..47c161ec9 100644 iah.cookie = cookie; diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c -index 21c53ece1..9ab2c5a74 100644 +index 8582bbc56..be0922101 100644 --- a/src/lib/kadm5/srv/svr_principal.c +++ b/src/lib/kadm5/srv/svr_principal.c -@@ -2093,14 +2093,8 @@ static int decrypt_key_data(krb5_context context, +@@ -2097,14 +2097,8 @@ static int decrypt_key_data(krb5_context context, ret = krb5_dbe_decrypt_key_data(context, NULL, &key_data[i], &keys[i], NULL); if (ret) { diff --git a/Avoid-alignment-warnings-in-openssl-rc4.c.patch b/Avoid-alignment-warnings-in-openssl-rc4.c.patch index 848d4f6..9e7293a 100644 --- a/Avoid-alignment-warnings-in-openssl-rc4.c.patch +++ b/Avoid-alignment-warnings-in-openssl-rc4.c.patch @@ -1,4 +1,4 @@ -From ceb6a10c14ec83b0d4d1bb6f792917e6945995d6 Mon Sep 17 00:00:00 2001 +From 399b9ed8ef199b6280bf4d6564928c79a3611cc5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 15:14:49 -0400 Subject: [PATCH] Avoid alignment warnings in openssl rc4.c diff --git a/Avoid-allocating-a-register-in-zap-assembly.patch b/Avoid-allocating-a-register-in-zap-assembly.patch index 0ad558b..144d9ed 100644 --- a/Avoid-allocating-a-register-in-zap-assembly.patch +++ b/Avoid-allocating-a-register-in-zap-assembly.patch @@ -1,4 +1,4 @@ -From df3bfd244f8b4601f8750599270eb98cadccdafe Mon Sep 17 00:00:00 2001 +From c896facca7dd9d0fbbd561d3a723a90216821b72 Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Thu, 3 Jan 2019 17:19:32 +0100 Subject: [PATCH] Avoid allocating a register in zap() assembly @@ -17,7 +17,7 @@ Also add explicit_bzero() (glibc, FreeBSD) and explicit_memset() 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/src/configure.in b/src/configure.in -index 93aec682e..7c309a26b 100644 +index feae21c3e..505dabb02 100644 --- a/src/configure.in +++ b/src/configure.in @@ -421,7 +421,7 @@ AC_PROG_LEX diff --git a/Check-more-errors-in-OpenSSL-crypto-backend.patch b/Check-more-errors-in-OpenSSL-crypto-backend.patch index e4dba05..006177f 100644 --- a/Check-more-errors-in-OpenSSL-crypto-backend.patch +++ b/Check-more-errors-in-OpenSSL-crypto-backend.patch @@ -1,4 +1,4 @@ -From 8eee70cc192adf9c0c11061c48d708e0157a9399 Mon Sep 17 00:00:00 2001 +From 57e48b63b1f0b34861c66fb24dafc0feb524f47c Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 22 Apr 2019 14:26:42 -0400 Subject: [PATCH] Check more errors in OpenSSL crypto backend diff --git a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch index 8794052..0173bf8 100644 --- a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch +++ b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch @@ -1,4 +1,4 @@ -From eb8d1bbf210b159384859dd482657a31de80a787 Mon Sep 17 00:00:00 2001 +From 037981b197a6046574539ec405cc1d67b9f22473 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Apr 2019 14:18:57 -0400 Subject: [PATCH] Clarify header comment for krb5_cc_start_seq_get() diff --git a/Clear-forwardable-flag-instead-of-denying-request.patch b/Clear-forwardable-flag-instead-of-denying-request.patch index 2527d65..fd8a240 100644 --- a/Clear-forwardable-flag-instead-of-denying-request.patch +++ b/Clear-forwardable-flag-instead-of-denying-request.patch @@ -1,4 +1,4 @@ -From 24d3008698d6c654ab079413583c9f1359ad8f59 Mon Sep 17 00:00:00 2001 +From 54b5eceb45db9cf6ff86eea5efebba66cf48153e Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 15 Nov 2018 13:40:43 -0500 Subject: [PATCH] Clear forwardable flag instead of denying request diff --git a/Display-unsupported-enctype-names.patch b/Display-unsupported-enctype-names.patch index fdc118e..3ee3283 100644 --- a/Display-unsupported-enctype-names.patch +++ b/Display-unsupported-enctype-names.patch @@ -1,4 +1,4 @@ -From 756e069368719f53444b5a819753fdeda5561994 Mon Sep 17 00:00:00 2001 +From c8b24f222719df0c4b9815d26019ad96c551ec81 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 21 May 2019 13:34:39 -0400 Subject: [PATCH] Display unsupported enctype names diff --git a/Don-t-error-on-invalid-enctypes-in-keytab.patch b/Don-t-error-on-invalid-enctypes-in-keytab.patch index 1d385b7..6152aaa 100644 --- a/Don-t-error-on-invalid-enctypes-in-keytab.patch +++ b/Don-t-error-on-invalid-enctypes-in-keytab.patch @@ -1,4 +1,4 @@ -From 261e67018b25412c53a290c429612bb55569428e Mon Sep 17 00:00:00 2001 +From d39897c46818f990eb7752573c309b97d90a983e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 10 Jul 2019 17:10:16 -0400 Subject: [PATCH] Don't error on invalid enctypes in keytab diff --git a/Filter-enctypes-in-gss_set_allowable_enctypes.patch b/Filter-enctypes-in-gss_set_allowable_enctypes.patch index 1e10259..182071c 100644 --- a/Filter-enctypes-in-gss_set_allowable_enctypes.patch +++ b/Filter-enctypes-in-gss_set_allowable_enctypes.patch @@ -1,4 +1,4 @@ -From 675edf995b497d681732a2909df21d8e4fe11e07 Mon Sep 17 00:00:00 2001 +From 073c20a214df8b416b8d848412256c57feb43ef0 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 16 Jul 2019 00:15:42 -0400 Subject: [PATCH] Filter enctypes in gss_set_allowable_enctypes() diff --git a/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch b/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch index 40cd54e..a8d5901 100644 --- a/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch +++ b/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch @@ -1,4 +1,4 @@ -From 0acc96dccbb4f4e75584ee39239da392b919f5f8 Mon Sep 17 00:00:00 2001 +From 14bc517f1fbd0bc7b3a6137871c167c595747a3e Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 20 Jul 2019 00:51:52 -0400 Subject: [PATCH] Fix Coverity defects in soft-pkcs11 test code diff --git a/Fix-KCM-client-time-offset-propagation.patch b/Fix-KCM-client-time-offset-propagation.patch deleted file mode 100644 index 4159a3a..0000000 --- a/Fix-KCM-client-time-offset-propagation.patch +++ /dev/null @@ -1,32 +0,0 @@ -From 48dd1debf9bd7b04195aeb435d54eefde39bc35e Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 14 Aug 2019 13:52:27 -0400 -Subject: [PATCH] Fix KCM client time offset propagation - -An inverted status check in get_kdc_offset() would cause querying the -offset time from the ccache to always fail (silently) on KCM. Fix the -status check so that KCM can properly handle desync. - -ticket: 8826 (new) -tags: pullup -target_version: 1.17-next -target_verison: 1.16-next - -(cherry picked from commit 323abb6d1ebe5469d6c2167c29aa5d696d099b90) ---- - src/lib/krb5/ccache/cc_kcm.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c -index 092ab7daf..fe93ca3dc 100644 ---- a/src/lib/krb5/ccache/cc_kcm.c -+++ b/src/lib/krb5/ccache/cc_kcm.c -@@ -583,7 +583,7 @@ get_kdc_offset(krb5_context context, krb5_ccache cache) - if (cache_call(context, cache, &req, FALSE) != 0) - goto cleanup; - time_offset = k5_input_get_uint32_be(&req.reply); -- if (!req.reply.status) -+ if (req.reply.status) - goto cleanup; - context->os_context.time_offset = time_offset; - context->os_context.usec_offset = 0; diff --git a/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch b/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch index 5cbe40a..56bcd85 100644 --- a/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch +++ b/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch @@ -1,4 +1,4 @@ -From fd25fce46c2454b7386d2725dba493471a2e3fe8 Mon Sep 17 00:00:00 2001 +From 2f939727e531f04a24b687b9807b2e23599a2e4f Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 25 Sep 2019 12:57:56 -0400 Subject: [PATCH] Fix KDC crash when logging PKINIT enctypes diff --git a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch index 92201a0..c662158 100644 --- a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch +++ b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch @@ -1,4 +1,4 @@ -From 508863ce900694d4a78af60361e23be59143aac8 Mon Sep 17 00:00:00 2001 +From bde05bf227939691855c025ce3c79cda07093fa7 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 16 Apr 2019 10:47:35 -0400 Subject: [PATCH] Fix config realm change logic in FILE remove_cred diff --git a/Fix-kadmin-addprinc-randkey-kvno.patch b/Fix-kadmin-addprinc-randkey-kvno.patch deleted file mode 100644 index 0bb97cf..0000000 --- a/Fix-kadmin-addprinc-randkey-kvno.patch +++ /dev/null @@ -1,45 +0,0 @@ -From 5e0baa51f69ae9f67865d808213bda5872ee7dc6 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 16 Nov 2019 19:54:51 -0500 -Subject: [PATCH] Fix kadmin addprinc -randkey -kvno - -Commit f07bca9fc94a5cf2e3c0f58226c7973a4b86b7a9 made addprinc -randkey -use a single RPC request, but the server-side handling always creates -the random keys with kvno 1. If a kvno is specified in the RPC -request, set the kvno of the key data after creating it. Reported by -Andreas Ladanyi. - -ticket: 8848 -tags: pullup -target_version: 1.17-next -target_version: 1.16-next - -(cherry picked from commit 462e85208d57b8d4120c99e801fbd156b9ccf16f) ---- - src/lib/kadm5/srv/svr_principal.c | 6 +++++- - 1 file changed, 5 insertions(+), 1 deletion(-) - -diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c -index 48cac0c11..a1ecdbfc4 100644 ---- a/src/lib/kadm5/srv/svr_principal.c -+++ b/src/lib/kadm5/srv/svr_principal.c -@@ -302,7 +302,7 @@ kadm5_create_principal_3(void *server_handle, - kadm5_server_handle_t handle = server_handle; - krb5_keyblock *act_mkey; - krb5_kvno act_kvno; -- int new_n_ks_tuple = 0; -+ int new_n_ks_tuple = 0, i; - krb5_key_salt_tuple *new_ks_tuple = NULL; - - CHECK_HANDLE(server_handle); -@@ -468,6 +468,10 @@ kadm5_create_principal_3(void *server_handle, - /* Null password means create with random key (new in 1.8). */ - ret = krb5_dbe_crk(handle->context, &master_keyblock, - new_ks_tuple, new_n_ks_tuple, FALSE, kdb); -+ if (mask & KADM5_KVNO) { -+ for (i = 0; i < kdb->n_key_data; i++) -+ kdb->key_data[i].key_data_kvno = entry->kvno; -+ } - } - if (ret) - goto cleanup; diff --git a/Fix-memory-leak-in-none-replay-cache-type.patch b/Fix-memory-leak-in-none-replay-cache-type.patch deleted file mode 100644 index ae20f54..0000000 --- a/Fix-memory-leak-in-none-replay-cache-type.patch +++ /dev/null @@ -1,33 +0,0 @@ -From 0bb94eb7c3b231279d8ded0484ecea10ebe89302 Mon Sep 17 00:00:00 2001 -From: Corene Casper -Date: Sat, 16 Feb 2019 00:49:26 -0500 -Subject: [PATCH] Fix memory leak in 'none' replay cache type - -Commit 0f06098e2ab419d02e89a1ca6bc9f2828f6bdb1e fixed part of a memory -leak in the 'none' replay cache type by freeing the outer container, -but we also need to free the mutex. - -[ghudson@mit.edu: wrote commit message] - -ticket: 8783 -tags: pullup -target_version: 1.17-next -target_version: 1.16-next - -(cherry picked from commit af2a3115cb8feb5174151b4b40223ae45aa9db17) ---- - src/lib/krb5/rcache/rc_none.c | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/src/lib/krb5/rcache/rc_none.c b/src/lib/krb5/rcache/rc_none.c -index e30aed09f..0b2274df7 100644 ---- a/src/lib/krb5/rcache/rc_none.c -+++ b/src/lib/krb5/rcache/rc_none.c -@@ -50,6 +50,7 @@ krb5_rc_none_noargs(krb5_context ctx, krb5_rcache rc) - static krb5_error_code KRB5_CALLCONV - krb5_rc_none_close(krb5_context ctx, krb5_rcache rc) - { -+ k5_mutex_destroy(&rc->lock); - free (rc); - return 0; - } diff --git a/Fix-memory-leaks-in-soft-pkcs11-code.patch b/Fix-memory-leaks-in-soft-pkcs11-code.patch index 19c85de..acc2938 100644 --- a/Fix-memory-leaks-in-soft-pkcs11-code.patch +++ b/Fix-memory-leaks-in-soft-pkcs11-code.patch @@ -1,4 +1,4 @@ -From 8087bdce8a5e9912f693ab199198a5bf4db54001 Mon Sep 17 00:00:00 2001 +From b0acd2918e673a60a88cfed9fe7da08fb7fc4987 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 5 Aug 2019 01:53:51 -0400 Subject: [PATCH] Fix memory leaks in soft-pkcs11 code diff --git a/Fix-minor-errors-in-softpkcs11.patch b/Fix-minor-errors-in-softpkcs11.patch index 510151b..963faec 100644 --- a/Fix-minor-errors-in-softpkcs11.patch +++ b/Fix-minor-errors-in-softpkcs11.patch @@ -1,4 +1,4 @@ -From 0d27dbf488547b9ca6780f23e5e40fa820928385 Mon Sep 17 00:00:00 2001 +From 343068058951e343179156e895c7483ab8194236 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 8 Nov 2019 14:28:56 -0500 Subject: [PATCH] Fix minor errors in softpkcs11 diff --git a/Fix-potential-close-1-in-cc_file.c.patch b/Fix-potential-close-1-in-cc_file.c.patch index d3bd8ba..5e7136c 100644 --- a/Fix-potential-close-1-in-cc_file.c.patch +++ b/Fix-potential-close-1-in-cc_file.c.patch @@ -1,4 +1,4 @@ -From 5917d1d1a51c2a4b243661710b3107b1bc43fff0 Mon Sep 17 00:00:00 2001 +From 20e18b31bac004c13b7f2b5b1e67e80730481aea Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 18 Apr 2019 13:39:37 -0400 Subject: [PATCH] Fix potential close(-1) in cc_file.c diff --git a/Fix-some-return-code-handling-bugs.patch b/Fix-some-return-code-handling-bugs.patch deleted file mode 100644 index c948b89..0000000 --- a/Fix-some-return-code-handling-bugs.patch +++ /dev/null @@ -1,103 +0,0 @@ -From 3612a7873e5e07b51d47c6c38f8a83e0b3d51e20 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 2 May 2019 14:05:38 -0400 -Subject: [PATCH] Fix some return code handling bugs - -Fix five cases where return codes could be set (in unlikely cases) but -did not result in error exits. - -[ghudson@mit.edu: squashed commits and rewrote commit message] - -ticket: 8801 (new) -tags: pullup -target_version: 1.17-next -target_version: 1.16-next - -(cherry picked from commit 7c26740f9df3c79c3f01c3a4dda4d9dabba5298d) ---- - src/kdc/fast_util.c | 16 ++++++++-------- - src/lib/gssapi/krb5/k5unsealiov.c | 1 + - src/lib/kadm5/clnt/client_init.c | 3 +++ - src/tests/gssapi/t_pcontok.c | 1 + - 4 files changed, 13 insertions(+), 8 deletions(-) - -diff --git a/src/kdc/fast_util.c b/src/kdc/fast_util.c -index 6a3fc11b9..c9ba83e5e 100644 ---- a/src/kdc/fast_util.c -+++ b/src/kdc/fast_util.c -@@ -47,9 +47,10 @@ static krb5_error_code armor_ap_request - if (retval == 0) - retval = krb5_auth_con_setflags(kdc_context, - authcontext, 0); /*disable replay cache*/ -- retval = krb5_rd_req(kdc_context, &authcontext, -- &armor->armor_value, NULL /*server*/, -- kdc_active_realm->realm_keytab, NULL, &ticket); -+ if (retval == 0) -+ retval = krb5_rd_req(kdc_context, &authcontext, &armor->armor_value, -+ NULL /*server*/, kdc_active_realm->realm_keytab, -+ NULL, &ticket); - if (retval != 0) { - const char * errmsg = krb5_get_error_message(kdc_context, retval); - k5_setmsg(kdc_context, retval, _("%s while handling ap-request armor"), -@@ -132,7 +133,7 @@ kdc_find_fast(krb5_kdc_req **requestptr, - { - krb5_error_code retval = 0; - krb5_pa_data *fast_padata; -- krb5_data scratch, *inner_body = NULL; -+ krb5_data scratch, plaintext, *inner_body = NULL; - krb5_fast_req * fast_req = NULL; - krb5_kdc_req *request = *requestptr; - krb5_fast_armored_req *fast_armored_req = NULL; -@@ -183,11 +184,10 @@ kdc_find_fast(krb5_kdc_req **requestptr, - } - } - if (retval == 0) { -- krb5_data plaintext; - plaintext.length = fast_armored_req->enc_part.ciphertext.length; -- plaintext.data = malloc(plaintext.length); -- if (plaintext.data == NULL) -- retval = ENOMEM; -+ plaintext.data = k5alloc(plaintext.length, &retval); -+ } -+ if (retval == 0) { - retval = krb5_c_decrypt(kdc_context, - state->armor_key, - KRB5_KEYUSAGE_FAST_ENC, NULL, -diff --git a/src/lib/gssapi/krb5/k5unsealiov.c b/src/lib/gssapi/krb5/k5unsealiov.c -index 8b6704274..f15d2db69 100644 ---- a/src/lib/gssapi/krb5/k5unsealiov.c -+++ b/src/lib/gssapi/krb5/k5unsealiov.c -@@ -281,6 +281,7 @@ kg_unseal_v1_iov(krb5_context context, - (!ctx->initiate && direction != 0)) { - *minor_status = (OM_uint32)G_BAD_DIRECTION; - retval = GSS_S_BAD_SIG; -+ goto cleanup; - } - - code = 0; -diff --git a/src/lib/kadm5/clnt/client_init.c b/src/lib/kadm5/clnt/client_init.c -index 6f10db018..aa08918e2 100644 ---- a/src/lib/kadm5/clnt/client_init.c -+++ b/src/lib/kadm5/clnt/client_init.c -@@ -465,6 +465,9 @@ gic_iter(kadm5_server_handle_t handle, enum init_type init_type, - /* Credentials for kadmin don't need to be forwardable or proxiable. */ - if (init_type != INIT_CREDS) { - code = krb5_get_init_creds_opt_alloc(ctx, &opt); -+ if (code) -+ goto error; -+ - krb5_get_init_creds_opt_set_forwardable(opt, 0); - krb5_get_init_creds_opt_set_proxiable(opt, 0); - krb5_get_init_creds_opt_set_out_ccache(ctx, opt, ccache); -diff --git a/src/tests/gssapi/t_pcontok.c b/src/tests/gssapi/t_pcontok.c -index b966f8129..c40ea434c 100644 ---- a/src/tests/gssapi/t_pcontok.c -+++ b/src/tests/gssapi/t_pcontok.c -@@ -126,6 +126,7 @@ make_delete_token(gss_krb5_lucid_context_v1_t *lctx, gss_buffer_desc *out) - iov.flags = KRB5_CRYPTO_TYPE_DATA; - iov.data = make_data(cksum.contents, 16); - ret = krb5_k_encrypt_iov(context, seq, 0, NULL, &iov, 1); -+ check_k5err(context, "krb5_k_encrypt_iov", ret); - memcpy(ptr + 8, cksum.contents + 8, 8); - } else { - memcpy(ptr + 8, cksum.contents, cksize); diff --git a/Implement-krb5_cc_remove_cred-for-remaining-types.patch b/Implement-krb5_cc_remove_cred-for-remaining-types.patch index 9f1a551..23f9965 100644 --- a/Implement-krb5_cc_remove_cred-for-remaining-types.patch +++ b/Implement-krb5_cc_remove_cred-for-remaining-types.patch @@ -1,4 +1,4 @@ -From 43e56c3442e7601a6e041a010f0ca9acb6021d8f Mon Sep 17 00:00:00 2001 +From adeba65ff738184656bb9589e1e3ffb079d3adf0 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 1 Apr 2019 14:28:48 -0400 Subject: [PATCH] Implement krb5_cc_remove_cred for remaining types diff --git a/Improve-error-messages-from-kadmin-change_password.patch b/Improve-error-messages-from-kadmin-change_password.patch index 192b7a4..aff1567 100644 --- a/Improve-error-messages-from-kadmin-change_password.patch +++ b/Improve-error-messages-from-kadmin-change_password.patch @@ -1,4 +1,4 @@ -From 3f5781029e48d7f2f5a694a4d3e19691eefde87f Mon Sep 17 00:00:00 2001 +From 69a09fc7c76f443f08c437043d689669d39f46ca Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 13:13:16 -0400 Subject: [PATCH] Improve error messages from kadmin change_password diff --git a/In-kpropd-debug-log-proper-ticket-enctype-names.patch b/In-kpropd-debug-log-proper-ticket-enctype-names.patch index 790eed1..dec823a 100644 --- a/In-kpropd-debug-log-proper-ticket-enctype-names.patch +++ b/In-kpropd-debug-log-proper-ticket-enctype-names.patch @@ -1,4 +1,4 @@ -From d1bbb1c98c3c2deb3713959281a3eee2b5019480 Mon Sep 17 00:00:00 2001 +From bcd727fc66e9213e7b6ea4d22f781812033789ba Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 15 Jan 2019 13:41:16 -0500 Subject: [PATCH] In kpropd, debug-log proper ticket enctype names diff --git a/In-rd_req_dec-always-log-non-permitted-enctypes.patch b/In-rd_req_dec-always-log-non-permitted-enctypes.patch index 6598c56..148deb0 100644 --- a/In-rd_req_dec-always-log-non-permitted-enctypes.patch +++ b/In-rd_req_dec-always-log-non-permitted-enctypes.patch @@ -1,4 +1,4 @@ -From 803290c5773eb2e6a344f0ad0a01645e30c79031 Mon Sep 17 00:00:00 2001 +From 7710ba9b6d48ae82a2b2559131c6a8da802a4c0d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Jan 2019 17:14:42 -0500 Subject: [PATCH] In rd_req_dec, always log non-permitted enctypes diff --git a/Initialize-life-rlife-in-kdcpolicy-interface.patch b/Initialize-life-rlife-in-kdcpolicy-interface.patch deleted file mode 100644 index 7b07133..0000000 --- a/Initialize-life-rlife-in-kdcpolicy-interface.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 17d1dbd3b2eb3961c061b140f8a7641405e59d44 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 9 Aug 2019 14:07:22 -0400 -Subject: [PATCH] Initialize life/rlife in kdcpolicy interface - -A value of 0 indicates that the plugin doesn't wish to modify lifetimes. -Make this the default, rather than requiring all plugins to set these -values themselves. - -ticket: 8824 (new) -tags: pullup -target_version: 1.17-next -target_version: 1.16-next - -(cherry picked from commit d81c5870013240c04642c8e0cb994b4c49e40ddf) ---- - src/kdc/policy.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/kdc/policy.c b/src/kdc/policy.c -index 26c16f97c..a3ff556c5 100644 ---- a/src/kdc/policy.c -+++ b/src/kdc/policy.c -@@ -106,7 +106,7 @@ check_kdcpolicy_as(krb5_context context, const krb5_kdc_req *request, - krb5_data *const *auth_indicators, krb5_timestamp kdc_time, - krb5_ticket_times *times, const char **status) - { -- krb5_deltat life, rlife; -+ krb5_deltat life = 0, rlife = 0; - krb5_error_code ret; - kdcpolicy_handle *hp, h; - char **ais = NULL; -@@ -146,7 +146,7 @@ check_kdcpolicy_tgs(krb5_context context, const krb5_kdc_req *request, - krb5_data *const *auth_indicators, krb5_timestamp kdc_time, - krb5_ticket_times *times, const char **status) - { -- krb5_deltat life, rlife; -+ krb5_deltat life = 0, rlife = 0; - krb5_error_code ret; - kdcpolicy_handle *hp, h; - char **ais = NULL; diff --git a/Initialize-some-data-structure-magic-fields.patch b/Initialize-some-data-structure-magic-fields.patch index 952b75a..e392f10 100644 --- a/Initialize-some-data-structure-magic-fields.patch +++ b/Initialize-some-data-structure-magic-fields.patch @@ -1,4 +1,4 @@ -From e4e58539348e886f9ac39881d576c7512fc37a2b Mon Sep 17 00:00:00 2001 +From 3f8434553e5bc3551c7be651de196caf98647cf3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 13:36:38 -0400 Subject: [PATCH] Initialize some data structure magic fields diff --git a/Log-unknown-enctypes-as-unsupported-in-KDC.patch b/Log-unknown-enctypes-as-unsupported-in-KDC.patch index 75664bb..e742826 100644 --- a/Log-unknown-enctypes-as-unsupported-in-KDC.patch +++ b/Log-unknown-enctypes-as-unsupported-in-KDC.patch @@ -1,4 +1,4 @@ -From 78e9d11d8a6c05218d18b9b200d1de888a95503c Mon Sep 17 00:00:00 2001 +From f4681ed7ec9f22fdbacc5c58a9f12ef567601267 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 27 Sep 2019 16:55:37 -0400 Subject: [PATCH] Log unknown enctypes as unsupported in KDC diff --git a/Make-etype-names-in-KDC-logs-human-readable.patch b/Make-etype-names-in-KDC-logs-human-readable.patch index 74a4c48..462de34 100644 --- a/Make-etype-names-in-KDC-logs-human-readable.patch +++ b/Make-etype-names-in-KDC-logs-human-readable.patch @@ -1,4 +1,4 @@ -From a50161ee09ef887493afcf5f3901f9d0a9c20fc5 Mon Sep 17 00:00:00 2001 +From 87e5a350db1c18a92427a2a7645cc53d5813672d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 8 Jan 2019 17:42:35 -0500 Subject: [PATCH] Make etype names in KDC logs human-readable diff --git a/Mark-deprecated-enctypes-when-used.patch b/Mark-deprecated-enctypes-when-used.patch index 5fe75e1..9f520d7 100644 --- a/Mark-deprecated-enctypes-when-used.patch +++ b/Mark-deprecated-enctypes-when-used.patch @@ -1,4 +1,4 @@ -From de5bdedc1d27ee3e9ff7072614ea1316064b222a Mon Sep 17 00:00:00 2001 +From 8e3b86c1e7bdd12c649127a8a44e5a269b5b4453 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 10 Jan 2019 16:34:54 -0500 Subject: [PATCH] Mark deprecated enctypes when used diff --git a/Mark-the-doc-kadm5-tex-files-as-historic.patch b/Mark-the-doc-kadm5-tex-files-as-historic.patch index 9c85e2e..8ff592d 100644 --- a/Mark-the-doc-kadm5-tex-files-as-historic.patch +++ b/Mark-the-doc-kadm5-tex-files-as-historic.patch @@ -1,4 +1,4 @@ -From 4ebd1454a32df78d10c7de4c09ac8dc8ebb4f41b Mon Sep 17 00:00:00 2001 +From d8a20291fca962dfc88e396f2a60e41ede62be46 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 11 Apr 2019 18:33:04 -0400 Subject: [PATCH] Mark the doc/kadm5 tex files as historic diff --git a/Modernize-example-enctypes-in-documentation.patch b/Modernize-example-enctypes-in-documentation.patch index 4341da7..78ee5e6 100644 --- a/Modernize-example-enctypes-in-documentation.patch +++ b/Modernize-example-enctypes-in-documentation.patch @@ -1,10 +1,11 @@ -From c547bf2cae39d503de3ac3670d99b2cc324c6567 Mon Sep 17 00:00:00 2001 +From b90cdec363eae38cb2ea40d40668e3fbc83edeb8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 11 Apr 2019 18:25:41 -0400 Subject: [PATCH] Modernize example enctypes in documentation ticket: 8805 (new) (cherry picked from commit ccb4a3e4b35fa9ea63af0e98a42eba4aadb099e2) +[rharwood@redhat.com: release version conflict in man pages] --- doc/admin/admin_commands/kadmin_local.rst | 8 ++++---- doc/admin/admin_commands/kdb5_util.rst | 10 +++++----- @@ -70,7 +71,7 @@ index 7dd54f797..444c58bcd 100644 ENVIRONMENT diff --git a/doc/admin/database.rst b/doc/admin/database.rst -index 113a680a6..0eb5ccde7 100644 +index 33895b857..cea60b009 100644 --- a/doc/admin/database.rst +++ b/doc/admin/database.rst @@ -483,7 +483,7 @@ availability. To roll over the master key, follow these steps: @@ -126,13 +127,13 @@ index 5d1e70ede..3bec59f96 100644 type arcfour-hmac added to keytab FILE:/etc/krb5.keytab. diff --git a/src/man/kadmin.man b/src/man/kadmin.man -index 849677258..44859a378 100644 +index 3c4f013fb..44859a378 100644 --- a/src/man/kadmin.man +++ b/src/man/kadmin.man @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . --.TH "KADMIN" "1" " " "1.17" "MIT Kerberos" +-.TH "KADMIN" "1" " " "1.17.1" "MIT Kerberos" +.TH "KADMIN" "1" " " "1.18" "MIT Kerberos" .SH NAME kadmin \- Kerberos V5 database administration program diff --git a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch index 9bd7966..9914759 100644 --- a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch +++ b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch @@ -1,4 +1,4 @@ -From 8fe3c4bde435c68a74c8075661a432cd1d3c17b9 Mon Sep 17 00:00:00 2001 +From 762241d6dbcb7b90ecf6a7352553465c30fcab74 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 14:32:33 -0400 Subject: [PATCH] Modernize exit path in gss_krb5int_copy_ccache() diff --git a/Properly-size-ifdef-in-k5_cccol_lock.patch b/Properly-size-ifdef-in-k5_cccol_lock.patch index ab6596e..1afa100 100644 --- a/Properly-size-ifdef-in-k5_cccol_lock.patch +++ b/Properly-size-ifdef-in-k5_cccol_lock.patch @@ -1,4 +1,4 @@ -From 916861d361be090965e1b4df4f60fce64206cf79 Mon Sep 17 00:00:00 2001 +From c1b4612565658d64940ba4760e0b47afd21e718f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Feb 2019 11:50:35 -0500 Subject: [PATCH] Properly size #ifdef in k5_cccol_lock() diff --git a/Qualify-short-hostnames-when-not-using-DNS.patch b/Qualify-short-hostnames-when-not-using-DNS.patch deleted file mode 100644 index 2555b77..0000000 --- a/Qualify-short-hostnames-when-not-using-DNS.patch +++ /dev/null @@ -1,309 +0,0 @@ -From 35160d8bf1aa1464d7e757c73ed11644478cc4d4 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 29 Nov 2019 20:39:38 -0500 -Subject: [PATCH] Qualify short hostnames when not using DNS - -When DNS forward canonicalization is turned off or fails, qualify -single-component hostnames with the first DNS search domain. Add the -qualify_shortname relation to override this suffix. - -For one of the tests we need to disable qualification, which is -accomplished with an empty value. Adjust k5test.py to correctly emit -empty values when writing profiles. - -ticket: 8855 (new) -(cherry picked from commit 996353767fe8afa7f67a3b5b465e4d70e18bad7c) ---- - doc/admin/conf_files/krb5_conf.rst | 9 +++++++ - src/include/k5-int.h | 1 + - src/lib/krb5/os/dnsglue.c | 23 ++++++++++++++++ - src/lib/krb5/os/os-proto.h | 2 ++ - src/lib/krb5/os/sn2princ.c | 43 +++++++++++++++++++++++++++++- - src/tests/gssapi/t_ccselect.py | 5 ++-- - src/tests/t_sn2princ.py | 12 ++++++--- - src/util/k5test.py | 34 ++++++++++++----------- - 8 files changed, 106 insertions(+), 23 deletions(-) - -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 89f02434b..582ac8df0 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -308,6 +308,15 @@ The libdefaults section may contain any of the following relations: - If this flag is true, initial tickets will be proxiable by - default, if allowed by the KDC. The default value is false. - -+**qualify_shortname** -+ If this string is set, it determines the domain suffix for -+ single-component hostnames when DNS canonicalization is not used -+ (either because **dns_canonicalize_hostname** is false or because -+ forward canonicalization failed). The default value is the first -+ search domain of the system's DNS configuration. To disable -+ qualification of shortnames, set this relation to the empty string -+ with ``qualify_shortname = ""``. (New in release 1.18.) -+ - **rdns** - If this flag is true, reverse name lookup will be used in addition - to forward name lookup to canonicalizing hostnames for use in -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index cb328785d..7458319fa 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -280,6 +280,7 @@ typedef unsigned char u_char; - #define KRB5_CONF_PLUGIN_BASE_DIR "plugin_base_dir" - #define KRB5_CONF_PREFERRED_PREAUTH_TYPES "preferred_preauth_types" - #define KRB5_CONF_PROXIABLE "proxiable" -+#define KRB5_CONF_QUALIFY_SHORTNAME "qualify_shortname" - #define KRB5_CONF_RDNS "rdns" - #define KRB5_CONF_REALMS "realms" - #define KRB5_CONF_REALM_TRY_DOMAINS "realm_try_domains" -diff --git a/src/lib/krb5/os/dnsglue.c b/src/lib/krb5/os/dnsglue.c -index 59ff92963..e35ca9d76 100644 ---- a/src/lib/krb5/os/dnsglue.c -+++ b/src/lib/krb5/os/dnsglue.c -@@ -71,6 +71,7 @@ static int initparse(struct krb5int_dns_state *); - * Define macros to use the best available DNS search functions. INIT_HANDLE() - * returns true if handle initialization is successful, false if it is not. - * SEARCH() returns the length of the response or -1 on error. -+ * PRIMARY_DOMAIN() returns the first search domain in allocated memory. - * DECLARE_HANDLE() must be used last in the declaration list since it may - * evaluate to nothing. - */ -@@ -81,6 +82,7 @@ static int initparse(struct krb5int_dns_state *); - #define DECLARE_HANDLE(h) dns_handle_t h - #define INIT_HANDLE(h) ((h = dns_open(NULL)) != NULL) - #define SEARCH(h, n, c, t, a, l) dns_search(h, n, c, t, a, l, NULL, NULL) -+#define PRIMARY_DOMAIN(h) dns_search_list_domain(h, 0) - #define DESTROY_HANDLE(h) dns_free(h) - - #elif HAVE_RES_NINIT && HAVE_RES_NSEARCH -@@ -89,6 +91,7 @@ static int initparse(struct krb5int_dns_state *); - #define DECLARE_HANDLE(h) struct __res_state h - #define INIT_HANDLE(h) (memset(&h, 0, sizeof(h)), res_ninit(&h) == 0) - #define SEARCH(h, n, c, t, a, l) res_nsearch(&h, n, c, t, a, l) -+#define PRIMARY_DOMAIN(h) strdup(h.dnsrch[0]) - #if HAVE_RES_NDESTROY - #define DESTROY_HANDLE(h) res_ndestroy(&h) - #else -@@ -101,6 +104,7 @@ static int initparse(struct krb5int_dns_state *); - #define DECLARE_HANDLE(h) - #define INIT_HANDLE(h) (res_init() == 0) - #define SEARCH(h, n, c, t, a, l) res_search(n, c, t, a, l) -+#define PRIMARY_DOMAIN(h) strdup(_res.defdname) - #define DESTROY_HANDLE(h) - - #endif -@@ -433,6 +437,12 @@ cleanup: - return ret; - } - -+char * -+k5_primary_domain() -+{ -+ return NULL; -+} -+ - #else /* _WIN32 */ - - krb5_error_code -@@ -485,5 +495,18 @@ errout: - return retval; - } - -+char * -+k5_primary_domain() -+{ -+ char *domain; -+ DECLARE_HANDLE(h); -+ -+ if (!INIT_HANDLE(h)) -+ return NULL; -+ domain = PRIMARY_DOMAIN(h); -+ DESTROY_HANDLE(h); -+ return domain; -+} -+ - #endif /* not _WIN32 */ - #endif /* KRB5_DNS_LOOKUP */ -diff --git a/src/lib/krb5/os/os-proto.h b/src/lib/krb5/os/os-proto.h -index 066d30221..a16a34b74 100644 ---- a/src/lib/krb5/os/os-proto.h -+++ b/src/lib/krb5/os/os-proto.h -@@ -136,6 +136,8 @@ k5_make_uri_query(krb5_context context, const krb5_data *realm, - krb5_error_code k5_try_realm_txt_rr(krb5_context context, const char *prefix, - const char *name, char **realm); - -+char *k5_primary_domain(void); -+ - int _krb5_use_dns_realm (krb5_context); - int _krb5_use_dns_kdc (krb5_context); - int _krb5_conf_boolean (const char *); -diff --git a/src/lib/krb5/os/sn2princ.c b/src/lib/krb5/os/sn2princ.c -index 98d2600aa..a51761d0c 100644 ---- a/src/lib/krb5/os/sn2princ.c -+++ b/src/lib/krb5/os/sn2princ.c -@@ -50,15 +50,47 @@ use_reverse_dns(krb5_context context) - &value); - if (ret) - return DEFAULT_RDNS_LOOKUP; -+ - return value; - } - -+/* Append a domain suffix to host and return the result in allocated memory. -+ * Return NULL if no suffix is configured or on failure. */ -+static char * -+qualify_shortname(krb5_context context, const char *host) -+{ -+ krb5_error_code ret; -+ char *fqdn = NULL, *prof_domain = NULL, *os_domain = NULL; -+ const char *domain; -+ -+ ret = profile_get_string(context->profile, KRB5_CONF_LIBDEFAULTS, -+ KRB5_CONF_QUALIFY_SHORTNAME, NULL, NULL, -+ &prof_domain); -+ if (ret) -+ return NULL; -+ -+#ifdef KRB5_DNS_LOOKUP -+ if (prof_domain == NULL) -+ os_domain = k5_primary_domain(); -+#endif -+ -+ domain = (prof_domain != NULL) ? prof_domain : os_domain; -+ if (domain != NULL && *domain != '\0') { -+ if (asprintf(&fqdn, "%s.%s", host, domain) < 0) -+ fqdn = NULL; -+ } -+ -+ profile_release_string(prof_domain); -+ free(os_domain); -+ return fqdn; -+} -+ - krb5_error_code - k5_expand_hostname(krb5_context context, const char *host, - krb5_boolean is_fallback, char **canonhost_out) - { - struct addrinfo *ai = NULL, hint; -- char namebuf[NI_MAXHOST], *copy, *p; -+ char namebuf[NI_MAXHOST], *qualified = NULL, *copy, *p; - int err; - const char *canonhost; - krb5_boolean use_dns; -@@ -90,6 +122,14 @@ k5_expand_hostname(krb5_context context, const char *host, - } - } - -+ /* If we didn't use DNS and the name is just one component, try to add a -+ * domain suffix. */ -+ if (canonhost == host && strchr(host, '.') == NULL) { -+ qualified = qualify_shortname(context, host); -+ if (qualified != NULL) -+ canonhost = qualified; -+ } -+ - copy = strdup(canonhost); - if (copy == NULL) - goto cleanup; -@@ -113,6 +153,7 @@ cleanup: - /* We only return success or ENOMEM. */ - if (ai != NULL) - freeaddrinfo(ai); -+ free(qualified); - return (*canonhost_out == NULL) ? ENOMEM : 0; - } - -diff --git a/src/tests/gssapi/t_ccselect.py b/src/tests/gssapi/t_ccselect.py -index 9ca66554f..66d85880c 100755 ---- a/src/tests/gssapi/t_ccselect.py -+++ b/src/tests/gssapi/t_ccselect.py -@@ -24,8 +24,9 @@ from k5test import * - - # Create two independent realms (no cross-realm TGTs). For the - # fallback realm tests we need to control the precise server hostname, --# so turn off DNS canonicalization. --conf = {'libdefaults': {'dns_canonicalize_hostname': 'false'}} -+# so turn off DNS canonicalization and shortname qualification. -+conf = {'libdefaults': {'dns_canonicalize_hostname': 'false', -+ 'qualify_shortname': ''}} - r1 = K5Realm(create_user=False, krb5_conf=conf) - r2 = K5Realm(create_user=False, krb5_conf=conf, realm='KRBTEST2.COM', - portbase=62000, testdir=os.path.join(r1.testdir, 'r2')) -diff --git a/src/tests/t_sn2princ.py b/src/tests/t_sn2princ.py -index fe435a2d5..26dcb91c2 100755 ---- a/src/tests/t_sn2princ.py -+++ b/src/tests/t_sn2princ.py -@@ -6,7 +6,8 @@ conf = {'domain_realm': {'kerberos.org': 'R1', - 'example.com': 'R2', - 'mit.edu': 'R3'}} - no_rdns_conf = {'libdefaults': {'rdns': 'false'}} --no_canon_conf = {'libdefaults': {'dns_canonicalize_hostname': 'false'}} -+no_canon_conf = {'libdefaults': {'dns_canonicalize_hostname': 'false', -+ 'qualify_shortname': 'example.com'}} - fallback_canon_conf = {'libdefaults': - {'rdns': 'false', - 'dns_canonicalize_hostname': 'fallback'}} -@@ -62,12 +63,15 @@ testu('Example.COM:xyZ', 'Example.COM:xyZ', 'R2') - testu('example.com.::123', 'example.com.::123', '') - - # With dns_canonicalize_hostname=false, we downcase and remove --# trailing dots but do not canonicalize the hostname. Trailers do not --# get downcased. -+# trailing dots but do not canonicalize the hostname. -+# Single-component names are qualified with the configured suffix -+# (defaulting to the first OS search domain, but Python cannot easily -+# retrieve that value so we don't test it). Trailers do not get -+# downcased. - mark('dns_canonicalize_host=false') - testnc('ptr-mismatch.kerberos.org', 'ptr-mismatch.kerberos.org', 'R1') - testnc('Example.COM', 'example.com', 'R2') --testnc('abcde', 'abcde', '') -+testnc('abcde', 'abcde.example.com', 'R2') - testnc('example.com.:123', 'example.com:123', 'R2') - testnc('Example.COM:xyZ', 'example.com:xyZ', 'R2') - testnc('example.com.::123', 'example.com.::123', '') -diff --git a/src/util/k5test.py b/src/util/k5test.py -index feb6df7a0..c7f941303 100644 ---- a/src/util/k5test.py -+++ b/src/util/k5test.py -@@ -918,22 +918,24 @@ class K5Realm(object): - def _subst_cfg_value(self, value): - global buildtop, srctop, hostname - template = string.Template(value) -- return template.substitute(realm=self.realm, -- testdir=self.testdir, -- buildtop=buildtop, -- srctop=srctop, -- plugins=plugins, -- hostname=hostname, -- port0=self.portbase, -- port1=self.portbase + 1, -- port2=self.portbase + 2, -- port3=self.portbase + 3, -- port4=self.portbase + 4, -- port5=self.portbase + 5, -- port6=self.portbase + 6, -- port7=self.portbase + 7, -- port8=self.portbase + 8, -- port9=self.portbase + 9) -+ subst = template.substitute(realm=self.realm, -+ testdir=self.testdir, -+ buildtop=buildtop, -+ srctop=srctop, -+ plugins=plugins, -+ hostname=hostname, -+ port0=self.portbase, -+ port1=self.portbase + 1, -+ port2=self.portbase + 2, -+ port3=self.portbase + 3, -+ port4=self.portbase + 4, -+ port5=self.portbase + 5, -+ port6=self.portbase + 6, -+ port7=self.portbase + 7, -+ port8=self.portbase + 8, -+ port9=self.portbase + 9) -+ # Empty values must be quoted to avoid a syntax error. -+ return subst if subst else '""' - - def _create_acl(self): - global hostname diff --git a/Remove-3des-support.patch b/Remove-3des-support.patch index 161f68d..b3d12d0 100644 --- a/Remove-3des-support.patch +++ b/Remove-3des-support.patch @@ -1,4 +1,4 @@ -From bea06cc4cf4df3d545fb3da1a9429aa28f690d80 Mon Sep 17 00:00:00 2001 +From 98db8d2582b72fb75023c43c5bee435be960247f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] Remove 3des support @@ -9,12 +9,14 @@ to user other enctypes. Mark the 3DES enctypes UNSUPPORTED and retain their constants. (cherry picked from commit 57a8a84e035000b515ca9efd56e5cbe1568b95e7) +[rharwood@redhat.com: supported enctypes docs landed first] --- doc/admin/advanced/retiring-des.rst | 11 + doc/admin/conf_files/kdc_conf.rst | 7 +- doc/admin/enctypes.rst | 13 +- doc/admin/troubleshoot.rst | 9 +- doc/appdev/refs/macros/index.rst | 1 - + doc/conf.py | 4 +- doc/mitK5features.rst | 2 +- src/Makefile.in | 4 +- src/configure.in | 1 - @@ -105,7 +107,7 @@ their constants. src/tests/t_salt.py | 5 +- src/util/k5test.py | 10 - .../leash/htmlhelp/html/Encryption_Types.htm | 13 - - 95 files changed, 155 insertions(+), 4829 deletions(-) + 96 files changed, 157 insertions(+), 4831 deletions(-) delete mode 100644 src/lib/crypto/builtin/des/ISSUES delete mode 100644 src/lib/crypto/builtin/des/Makefile.in delete mode 100644 src/lib/crypto/builtin/des/d3_aead.c @@ -163,10 +165,10 @@ index 4a964c15c..cb6258d77 100644 ------------- diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst -index 2c6ea1855..a9ecaf4a9 100644 +index 9759756a2..cf8a12547 100644 --- a/doc/admin/conf_files/kdc_conf.rst +++ b/doc/admin/conf_files/kdc_conf.rst -@@ -841,8 +841,6 @@ Encryption types marked as "weak" are available for compatibility but +@@ -843,8 +843,6 @@ Encryption types marked as "weak" are available for compatibility but not recommended for use. ==================================================== ========================================================= @@ -175,7 +177,7 @@ index 2c6ea1855..a9ecaf4a9 100644 aes256-cts-hmac-sha1-96 aes256-cts aes256-sha1 AES-256 CTS mode with 96-bit SHA-1 HMAC aes128-cts-hmac-sha1-96 aes128-cts aes128-sha1 AES-128 CTS mode with 96-bit SHA-1 HMAC aes256-cts-hmac-sha384-192 aes256-sha2 AES-256 CTS mode with 192-bit SHA-384 HMAC -@@ -851,7 +849,6 @@ arcfour-hmac rc4-hmac arcfour-hmac-md5 RC4 with HMAC/MD5 +@@ -853,7 +851,6 @@ arcfour-hmac rc4-hmac arcfour-hmac-md5 RC4 with HMAC/MD5 arcfour-hmac-exp rc4-hmac-exp arcfour-hmac-md5-exp Exportable RC4 with HMAC/MD5 (weak) camellia256-cts-cmac camellia256-cts Camellia-256 CTS mode with CMAC camellia128-cts-cmac camellia128-cts Camellia-128 CTS mode with CMAC @@ -183,7 +185,7 @@ index 2c6ea1855..a9ecaf4a9 100644 aes The AES family: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, aes256-cts-hmac-sha384-192, and aes128-cts-hmac-sha256-128 rc4 The RC4 family: arcfour-hmac camellia The Camellia family: camellia256-cts-cmac and camellia128-cts-cmac -@@ -863,8 +860,8 @@ from the current list by prefixing them with a minus sign ("-"). +@@ -865,8 +862,8 @@ from the current list by prefixing them with a minus sign ("-"). Types or families can be prefixed with a plus sign ("+") for symmetry; it has the same meaning as just listing the type or family. For example, "``DEFAULT -rc4``" would be the default set of encryption @@ -254,6 +256,21 @@ index 534795d15..9542611ea 100644 CKSUMTYPE_MD5_HMAC_ARCFOUR.rst CKSUMTYPE_NIST_SHA.rst CKSUMTYPE_RSA_MD4.rst +diff --git a/doc/conf.py b/doc/conf.py +index 759367c21..37eda67fa 100644 +--- a/doc/conf.py ++++ b/doc/conf.py +@@ -271,8 +271,8 @@ else: + rst_epilog += '.. |ckeytab| replace:: %s\n' % ckeytab + rst_epilog += ''' + .. |krb5conf| replace:: ``/etc/krb5.conf`` +-.. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal des3-cbc-sha1:normal arcfour-hmac-md5:normal`` +-.. |defetypes| replace:: ``aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha384-192 aes128-cts-hmac-sha256-128 des3-cbc-sha1 arcfour-hmac-md5 camellia256-cts-cmac camellia128-cts-cmac`` ++.. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal`` ++.. |defetypes| replace:: ``aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha384-192 aes128-cts-hmac-sha256-128 arcfour-hmac-md5 camellia256-cts-cmac camellia128-cts-cmac`` + .. |defmkey| replace:: ``aes256-cts-hmac-sha1-96`` + .. |copy| unicode:: U+000A9 + ''' diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst index a19068e26..5bfdc3936 100644 --- a/doc/mitK5features.rst @@ -290,7 +307,7 @@ index 91a5f4bf8..0197e5b6d 100644 ##DOS## $(WCONFIG) config < $@.in > $@ ##DOS##lib\crypto\builtin\camellia\Makefile: lib\crypto\builtin\camellia\Makefile.in $(MKFDEP) diff --git a/src/configure.in b/src/configure.in -index 8d781a7c8..a19a0ea97 100644 +index 9d6825b78..3e3b95e49 100644 --- a/src/configure.in +++ b/src/configure.in @@ -1443,7 +1443,6 @@ V5_AC_OUTPUT_MAKEFILE(. diff --git a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch index 2234329..93dc484 100644 --- a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch +++ b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch @@ -1,4 +1,4 @@ -From 2bbf5046e0d1ad4a4927570ebed5aa661e322024 Mon Sep 17 00:00:00 2001 +From 34aa9b5889a48f05b4dec33d40e72e97390118a5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 14:37:38 -0400 Subject: [PATCH] Remove Kerberos v4 support vestiges from ccapi diff --git a/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch b/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch index 80e2b57..b759047 100644 --- a/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch +++ b/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch @@ -1,4 +1,4 @@ -From a52788c294f56a023b7bc05286990717ec993158 Mon Sep 17 00:00:00 2001 +From 044e7ea922800bfc17ba816780803b1d67622b7b Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 18 Jun 2019 11:40:48 -0400 Subject: [PATCH] Remove PKINIT draft 9 ASN.1 code and types diff --git a/Remove-PKINIT-draft-9-support.patch b/Remove-PKINIT-draft-9-support.patch index a0dd50d..2ac0254 100644 --- a/Remove-PKINIT-draft-9-support.patch +++ b/Remove-PKINIT-draft-9-support.patch @@ -1,4 +1,4 @@ -From f00a9416374087dbf135215a13c5316477ca2f45 Mon Sep 17 00:00:00 2001 +From b13b0e48470e03203afd4133e4be9c6471e2acb4 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 18 Jun 2019 13:06:44 -0400 Subject: [PATCH] Remove PKINIT draft 9 support diff --git a/Remove-ccapi-related-comments-in-configure.ac.patch b/Remove-ccapi-related-comments-in-configure.ac.patch index 4dbf2d5..7aa672b 100644 --- a/Remove-ccapi-related-comments-in-configure.ac.patch +++ b/Remove-ccapi-related-comments-in-configure.ac.patch @@ -1,4 +1,4 @@ -From 8096d0c97bcb5ac1ad830b6f354b4e32c90ac4cf Mon Sep 17 00:00:00 2001 +From ac8df1b0977dd5aedfaeb3d10458aaf18cece29f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Apr 2019 16:01:22 -0400 Subject: [PATCH] Remove ccapi-related comments in configure.ac @@ -12,7 +12,7 @@ is not. 1 file changed, 3 deletions(-) diff --git a/src/configure.in b/src/configure.in -index 7c309a26b..8d781a7c8 100644 +index 505dabb02..9d6825b78 100644 --- a/src/configure.in +++ b/src/configure.in @@ -1450,7 +1450,6 @@ V5_AC_OUTPUT_MAKEFILE(. diff --git a/Remove-checksum-type-profile-variables.patch b/Remove-checksum-type-profile-variables.patch index c55c79f..a2a05c2 100644 --- a/Remove-checksum-type-profile-variables.patch +++ b/Remove-checksum-type-profile-variables.patch @@ -1,4 +1,4 @@ -From 443754ab8140d87e2e5bbd595f39827461d6498a Mon Sep 17 00:00:00 2001 +From ee07471fa613fb68ddebc28577870e97cb5190cf Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 13 May 2019 14:19:57 -0400 Subject: [PATCH] Remove checksum type profile variables @@ -18,6 +18,7 @@ did not impose any limitations. ticket: 8804 (new) (cherry picked from commit a5a140dc85201faf1ba3a687553058354722a1b4) +[rharwood@redhat.com: release version conflict in man pages] --- doc/admin/conf_files/krb5_conf.rst | 37 ------------ src/include/k5-int.h | 6 -- @@ -30,10 +31,10 @@ ticket: 8804 (new) 8 files changed, 7 insertions(+), 204 deletions(-) diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index e9f7e8c59..5df3bfe36 100644 +index d1e1a222d..a3fb5d9f2 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst -@@ -111,14 +111,6 @@ The libdefaults section may contain any of the following relations: +@@ -105,14 +105,6 @@ The libdefaults section may contain any of the following relations: strong crypto. Users in affected environments should set this tag to true until their infrastructure adopts stronger ciphers. @@ -48,7 +49,7 @@ index e9f7e8c59..5df3bfe36 100644 **canonicalize** If this flag is set to true, initial ticket requests to the KDC will request canonicalization of the client principal name, and -@@ -297,26 +289,6 @@ The libdefaults section may contain any of the following relations: +@@ -291,26 +283,6 @@ The libdefaults section may contain any of the following relations: corrective factor is only used by the Kerberos library; it is not used to change the system clock. The default value is 1. @@ -75,7 +76,7 @@ index e9f7e8c59..5df3bfe36 100644 **noaddresses** If this flag is true, requests for initial tickets will not be made with address restrictions set, allowing the tickets to be -@@ -365,15 +337,6 @@ The libdefaults section may contain any of the following relations: +@@ -359,15 +331,6 @@ The libdefaults section may contain any of the following relations: (:ref:`duration` string.) Sets the default renewable lifetime for initial ticket requests. The default value is 0. @@ -299,18 +300,18 @@ index a6e48cd25..22be2198b 100644 ctx->library_options = 0; ctx->profile_secure = TRUE; diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man -index d431dce75..aafdf7f83 100644 +index 2a7af6aa4..433f38d71 100644 --- a/src/man/krb5.conf.man +++ b/src/man/krb5.conf.man @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . --.TH "KRB5.CONF" "5" " " "1.17" "MIT Kerberos" +-.TH "KRB5.CONF" "5" " " "1.17.1" "MIT Kerberos" +.TH "KRB5.CONF" "5" " " "1.18" "MIT Kerberos" .SH NAME krb5.conf \- Kerberos configuration file . -@@ -202,14 +202,6 @@ failures in existing Kerberos infrastructures that do not support +@@ -188,14 +188,6 @@ failures in existing Kerberos infrastructures that do not support strong crypto. Users in affected environments should set this tag to true until their infrastructure adopts stronger ciphers. .TP @@ -325,7 +326,7 @@ index d431dce75..aafdf7f83 100644 \fBcanonicalize\fP If this flag is set to true, initial ticket requests to the KDC will request canonicalization of the client principal name, and -@@ -291,6 +283,10 @@ hostnames for use in service principal names. Setting this flag +@@ -277,6 +269,10 @@ hostnames for use in service principal names. Setting this flag to false can improve security by reducing reliance on DNS, but means that short hostnames will not be canonicalized to fully\-qualified hostnames. The default value is true. @@ -336,7 +337,7 @@ index d431dce75..aafdf7f83 100644 .TP \fBdns_lookup_kdc\fP Indicate whether DNS SRV records should be used to locate the KDCs -@@ -384,73 +380,6 @@ requesting service tickets or authenticating to services. This +@@ -370,73 +366,6 @@ requesting service tickets or authenticating to services. This corrective factor is only used by the Kerberos library; it is not used to change the system clock. The default value is 1. .TP @@ -410,7 +411,7 @@ index d431dce75..aafdf7f83 100644 \fBnoaddresses\fP If this flag is true, requests for initial tickets will not be made with address restrictions set, allowing the tickets to be -@@ -499,15 +428,6 @@ set. The default is not to search domain components. +@@ -485,15 +414,6 @@ set. The default is not to search domain components. (duration string.) Sets the default renewable lifetime for initial ticket requests. The default value is 0. .TP diff --git a/Remove-confvalidator-utility.patch b/Remove-confvalidator-utility.patch index afaa7de..cb7d58d 100644 --- a/Remove-confvalidator-utility.patch +++ b/Remove-confvalidator-utility.patch @@ -1,4 +1,4 @@ -From 0d471a72541952ebe090919610cf9ba8b31d1291 Mon Sep 17 00:00:00 2001 +From 1df6ae50de14c8795af7f7aea7f54eede51fd206 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Apr 2019 14:58:19 -0400 Subject: [PATCH] Remove confvalidator utility diff --git a/Remove-dead-variable-def_kslist-from-two-files.patch b/Remove-dead-variable-def_kslist-from-two-files.patch index ae6022e..d9ba0dc 100644 --- a/Remove-dead-variable-def_kslist-from-two-files.patch +++ b/Remove-dead-variable-def_kslist-from-two-files.patch @@ -1,4 +1,4 @@ -From 20be29dfddcbc4afda79eae2bcd3d5de3bb0330d Mon Sep 17 00:00:00 2001 +From 5c9dce0ac1b8b6fcb048404e3830fd4619f4f1c5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 May 2019 16:57:51 -0400 Subject: [PATCH] Remove dead variable def_kslist from two files diff --git a/Remove-doxygen-generated-HTML-output-for-ccapi.patch b/Remove-doxygen-generated-HTML-output-for-ccapi.patch index c936cb0..3133482 100644 --- a/Remove-doxygen-generated-HTML-output-for-ccapi.patch +++ b/Remove-doxygen-generated-HTML-output-for-ccapi.patch @@ -1,4 +1,4 @@ -From 33c39a069022eab2d56ccbaf0be31b3b5b0071a2 Mon Sep 17 00:00:00 2001 +From a0c231f79b0b9c02120802cc5549c8576b5156bd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 14:15:58 -0400 Subject: [PATCH] Remove doxygen-generated HTML output for ccapi diff --git a/Remove-kadmin-RPC-support-for-setting-v4-key.patch b/Remove-kadmin-RPC-support-for-setting-v4-key.patch index a545984..3a08ddc 100644 --- a/Remove-kadmin-RPC-support-for-setting-v4-key.patch +++ b/Remove-kadmin-RPC-support-for-setting-v4-key.patch @@ -1,4 +1,4 @@ -From e1e27c400736ca304c9cbdc52e2946c65e047a21 Mon Sep 17 00:00:00 2001 +From 620a45acc6ea6c01cce0474883011ed47cb35458 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 4 Apr 2019 16:14:46 -0400 Subject: [PATCH] Remove kadmin RPC support for setting v4 key @@ -336,10 +336,10 @@ index 64ad5dd69..e3c04e690 100644 xdr_ui_4 kadm5_init_iprop diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c -index 9ab2c5a74..48cac0c11 100644 +index be0922101..a1ecdbfc4 100644 --- a/src/lib/kadm5/srv/svr_principal.c +++ b/src/lib/kadm5/srv/svr_principal.c -@@ -1645,124 +1645,6 @@ done: +@@ -1649,124 +1649,6 @@ done: return ret; } diff --git a/Remove-krb5int_c_combine_keys.patch b/Remove-krb5int_c_combine_keys.patch index 287a586..e78c003 100644 --- a/Remove-krb5int_c_combine_keys.patch +++ b/Remove-krb5int_c_combine_keys.patch @@ -1,4 +1,4 @@ -From 6181039fc3f70c073e4125d98d8a28aec9c223bf Mon Sep 17 00:00:00 2001 +From 90c702467b0c4373758f235512c67f80f1998e02 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 18 Apr 2019 17:27:07 -0400 Subject: [PATCH] Remove krb5int_c_combine_keys() diff --git a/Remove-more-dead-code.patch b/Remove-more-dead-code.patch index 59f19b6..b0f04ab 100644 --- a/Remove-more-dead-code.patch +++ b/Remove-more-dead-code.patch @@ -1,4 +1,4 @@ -From 067f8685648e4a316ea0dfe90694d5a7b64c8848 Mon Sep 17 00:00:00 2001 +From e470fc217b19f6d958cc891910527e43651167a3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 9 May 2019 14:07:24 -0400 Subject: [PATCH] Remove more dead code diff --git a/Remove-now-unused-checksum-functions.patch b/Remove-now-unused-checksum-functions.patch index 780de71..5a8dd90 100644 --- a/Remove-now-unused-checksum-functions.patch +++ b/Remove-now-unused-checksum-functions.patch @@ -1,4 +1,4 @@ -From 3d6b547ca1454b8113c6f83161def1f995c04616 Mon Sep 17 00:00:00 2001 +From e9cc0b8762266ed368cb50e7ba48d6196db54da5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 28 Jun 2019 13:09:47 -0400 Subject: [PATCH] Remove now-unused checksum functions diff --git a/Remove-null-check-in-krb5_gss_duplicate_name.patch b/Remove-null-check-in-krb5_gss_duplicate_name.patch index 9e99e78..4d65cbd 100644 --- a/Remove-null-check-in-krb5_gss_duplicate_name.patch +++ b/Remove-null-check-in-krb5_gss_duplicate_name.patch @@ -1,4 +1,4 @@ -From 13df40bef90954d1c373c5e9cece1d5897c7afcf Mon Sep 17 00:00:00 2001 +From 61855503e579611b2bb2f322070c2e1e0ca36ce8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 30 Aug 2019 11:19:52 -0400 Subject: [PATCH] Remove null check in krb5_gss_duplicate_name() diff --git a/Remove-ovsec_adm_export-dump-format-support.patch b/Remove-ovsec_adm_export-dump-format-support.patch index 619397d..466aea0 100644 --- a/Remove-ovsec_adm_export-dump-format-support.patch +++ b/Remove-ovsec_adm_export-dump-format-support.patch @@ -1,4 +1,4 @@ -From 019dc5d64d6e1c0fabaf9957bef5b633eb6fa475 Mon Sep 17 00:00:00 2001 +From e4c75d01bfdedfe77068a641e0053eef227dc22b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 22 Jan 2019 18:34:58 -0500 Subject: [PATCH] Remove ovsec_adm_export dump format support @@ -9,6 +9,7 @@ KDCs. ticket: 8798 (new) (cherry picked from commit 23b93fd48bc445005436c5be98a7269b599b1800) +[rharwood@redhat.com: release version conflict in man pages] --- doc/admin/admin_commands/kdb5_util.rst | 11 +-- doc/admin/database.rst | 14 ---- @@ -63,7 +64,7 @@ index fee68261a..7dd54f797 100644 requires the database to be in Kerberos 5 1.3 format ("kdb5_util load_dump version 5"). This was the dump format produced on diff --git a/doc/admin/database.rst b/doc/admin/database.rst -index 2b02af3a0..113a680a6 100644 +index d0be455f8..33895b857 100644 --- a/doc/admin/database.rst +++ b/doc/admin/database.rst @@ -393,20 +393,6 @@ To dump a single principal and later load it, updating the database: @@ -274,13 +275,13 @@ index accc959e0..e73e2c68e 100644 "\tark [-e etype_list] principal\n" "\tadd_mkey [-e etype] [-s]\n" diff --git a/src/man/kdb5_util.man b/src/man/kdb5_util.man -index 5ebc68a57..9a36ef0df 100644 +index 9c48c32fb..9a36ef0df 100644 --- a/src/man/kdb5_util.man +++ b/src/man/kdb5_util.man @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . --.TH "KDB5_UTIL" "8" " " "1.17" "MIT Kerberos" +-.TH "KDB5_UTIL" "8" " " "1.17.1" "MIT Kerberos" +.TH "KDB5_UTIL" "8" " " "1.18" "MIT Kerberos" .SH NAME kdb5_util \- Kerberos database maintenance utility diff --git a/Remove-srvtab-support.patch b/Remove-srvtab-support.patch index ee8f44e..e175243 100644 --- a/Remove-srvtab-support.patch +++ b/Remove-srvtab-support.patch @@ -1,4 +1,4 @@ -From a768fb06f0df69f0b6985058e21c72448587d2a8 Mon Sep 17 00:00:00 2001 +From ecf80eb7a536c2d78812482d9c974120725ca609 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 9 Oct 2017 15:58:33 -0400 Subject: [PATCH] Remove srvtab support @@ -8,6 +8,7 @@ name was used. ticket: 8793 (new) (cherry picked from commit a23e670b40f69b6be0024f8a60d2afaf7f7a005a) +[rharwood@redhat.com: release version conflict in man pages] --- doc/admin/admin_commands/ktutil.rst | 22 +- doc/basic/keytab_def.rst | 6 +- @@ -206,10 +207,10 @@ index 00c442978..e710852d4 100644 plugin_base_dir = __PLUGIN_DIR__ allow_weak_crypto = true diff --git a/src/kadmin/testing/scripts/env-setup.shin b/src/kadmin/testing/scripts/env-setup.shin -index c8d866f15..726298351 100755 +index 273cf6954..8c29bb996 100755 --- a/src/kadmin/testing/scripts/env-setup.shin +++ b/src/kadmin/testing/scripts/env-setup.shin -@@ -77,7 +77,7 @@ SRVTCL=$TESTDIR/util/kadm5_srv_tcl; export SRVTCL +@@ -79,7 +79,7 @@ export QUALNAME KRB5_CONFIG=$K5ROOT/krb5.conf; export KRB5_CONFIG KRB5_KDC_PROFILE=$K5ROOT/kdc.conf; export KRB5_KDC_PROFILE @@ -219,10 +220,10 @@ index c8d866f15..726298351 100755 KRB5CCNAME=$K5ROOT/krb5cc_unit-test; export KRB5CCNAME diff --git a/src/kadmin/testing/scripts/init_db b/src/kadmin/testing/scripts/init_db -index cd7165628..bf119f2ac 100755 +index c41d290d1..2496be2ab 100755 --- a/src/kadmin/testing/scripts/init_db +++ b/src/kadmin/testing/scripts/init_db -@@ -218,7 +218,7 @@ changepw/kerberos@$REALM cil +@@ -216,7 +216,7 @@ changepw/kerberos@$REALM cil EOF @@ -245,10 +246,10 @@ index dfe0b3a01..c77d61c70 100755 replaced by the canonical host name of the local host."; diff --git a/src/kadmin/testing/scripts/start_servers_local b/src/kadmin/testing/scripts/start_servers_local -index 0cbed462d..809892974 100755 +index f34444ee8..e502a6a0b 100755 --- a/src/kadmin/testing/scripts/start_servers_local +++ b/src/kadmin/testing/scripts/start_servers_local -@@ -98,9 +98,6 @@ x=$? +@@ -96,9 +96,6 @@ x=$? rm /tmp/start_servers_local$$ if test $x != 0 ; then exit 1 ; fi @@ -952,12 +953,12 @@ index ba57b703e..ed179bbe3 100644 verbose "% $SERVER" 1 set server_pid [spawn $SERVER $PROT] diff --git a/src/lib/rpc/unit-test/lib/helpers.exp b/src/lib/rpc/unit-test/lib/helpers.exp -index a1b078374..6ba2b10ae 100644 +index a7f89f636..f08c73201 100644 --- a/src/lib/rpc/unit-test/lib/helpers.exp +++ b/src/lib/rpc/unit-test/lib/helpers.exp @@ -121,8 +121,8 @@ proc setup_database {} { if ![info exists CANON_HOST] { - set CANON_HOST [exec $env(QUALNAME)] + set CANON_HOST $env(QUALNAME) setup_database - file delete $env(RPC_TEST_SRVTAB) - exec $env(MAKE_KEYTAB) -princ "server/$CANON_HOST" $env(RPC_TEST_SRVTAB) @@ -967,7 +968,7 @@ index a1b078374..6ba2b10ae 100644 diff --git a/src/lib/rpc/unit-test/rpc_test_setup.sh b/src/lib/rpc/unit-test/rpc_test_setup.sh -index 968f52a67..b610f87ef 100755 +index d147a337e..d7df0eb2b 100755 --- a/src/lib/rpc/unit-test/rpc_test_setup.sh +++ b/src/lib/rpc/unit-test/rpc_test_setup.sh @@ -1,7 +1,7 @@ @@ -979,7 +980,7 @@ index 968f52a67..b610f87ef 100755 # environment. # # $Id$ -@@ -42,9 +42,9 @@ if test $? != 0 ; then +@@ -39,9 +39,9 @@ if test $? != 0 ; then fi rm /tmp/rpc_test_setup$$ @@ -992,13 +993,13 @@ index 968f52a67..b610f87ef 100755 # grep -s "$CANON_HOST SECURE-TEST.OV.COM" /etc/krb.realms # if [ $? != 0 ]; then diff --git a/src/man/ktutil.man b/src/man/ktutil.man -index 4e174c0fe..233329468 100644 +index 711a0ed2c..233329468 100644 --- a/src/man/ktutil.man +++ b/src/man/ktutil.man @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . --.TH "KTUTIL" "1" " " "1.17" "MIT Kerberos" +-.TH "KTUTIL" "1" " " "1.17.1" "MIT Kerberos" +.TH "KTUTIL" "1" " " "1.18" "MIT Kerberos" .SH NAME ktutil \- Kerberos keytab file maintenance utility diff --git a/Remove-strerror-calls-from-k5_get_error.patch b/Remove-strerror-calls-from-k5_get_error.patch index a42610a..a46ccdc 100644 --- a/Remove-strerror-calls-from-k5_get_error.patch +++ b/Remove-strerror-calls-from-k5_get_error.patch @@ -1,4 +1,4 @@ -From 1aff5025ec486d1f8239e3a135156e33ea5e764d Mon Sep 17 00:00:00 2001 +From 128098be731775ecc2a5de6308868fae78059db9 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 6 Jun 2019 11:46:58 -0400 Subject: [PATCH] Remove strerror() calls from k5_get_error() diff --git a/Remove-support-for-no-flags-SAM-2-preauth.patch b/Remove-support-for-no-flags-SAM-2-preauth.patch index aac83a7..c7c1afb 100644 --- a/Remove-support-for-no-flags-SAM-2-preauth.patch +++ b/Remove-support-for-no-flags-SAM-2-preauth.patch @@ -1,4 +1,4 @@ -From f87c6fabd1073637c4798fcdd3fdab060edb0731 Mon Sep 17 00:00:00 2001 +From c00274de6de883d74ae231405b6ae5e1486712c9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 17 Apr 2019 17:07:46 -0400 Subject: [PATCH] Remove support for no-flags SAM-2 preauth diff --git a/Remove-support-for-single-DES-and-CRC.patch b/Remove-support-for-single-DES-and-CRC.patch index bfe5418..156e09a 100644 --- a/Remove-support-for-single-DES-and-CRC.patch +++ b/Remove-support-for-single-DES-and-CRC.patch @@ -1,4 +1,4 @@ -From c13f1fde8931a9199a7a15a5b011f02ed2615e9f Mon Sep 17 00:00:00 2001 +From e73ed142bd5baf15943069346202fe3b1a4d96d6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 24 May 2019 13:12:03 -0400 Subject: [PATCH] Remove support for single-DES and CRC @@ -11,13 +11,15 @@ user-visible deprecation warnings were issued starting in release ticket: 8808 (cherry picked from commit fb2dada5eb89c4cd4e39dedd6dbb7dbd5e94f8b8) [rharwood@redhat.com: .gitignore removal] +[rharwood@redhat.com: In this branch, supported_enctypes changes landed +first] --- doc/admin/advanced/retiring-des.rst | 5 + doc/admin/conf_files/kdc_conf.rst | 17 +- doc/admin/conf_files/krb5_conf.rst | 17 +- doc/admin/enctypes.rst | 38 +- doc/appdev/refs/macros/index.rst | 1 + - doc/conf.py | 2 +- + doc/conf.py | 4 +- doc/mitK5features.rst | 2 +- src/include/k5-int.h | 1 - src/include/krb5/krb5.hin | 10 +- @@ -67,7 +69,7 @@ ticket: 8808 src/man/kdc.conf.man | 47 +- src/man/krb5.conf.man | 6 +- .../leash/htmlhelp/html/Encryption_Types.htm | 14 +- - 55 files changed, 74 insertions(+), 2180 deletions(-) + 55 files changed, 75 insertions(+), 2181 deletions(-) delete mode 100644 src/lib/crypto/builtin/enc_provider/des.c delete mode 100644 src/lib/crypto/builtin/hash_provider/hash_crc32.c delete mode 100644 src/lib/crypto/krb/crc32.c @@ -93,7 +95,7 @@ index ebac95f24..4a964c15c 100644 ------------- diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst -index 62d1bfc05..2c6ea1855 100644 +index 7fbc8eb79..9759756a2 100644 --- a/doc/admin/conf_files/kdc_conf.rst +++ b/doc/admin/conf_files/kdc_conf.rst @@ -381,13 +381,6 @@ The following tags may be specified in a [realms] subsection: @@ -110,7 +112,7 @@ index 62d1bfc05..2c6ea1855 100644 **reject_bad_transit** (Boolean value.) If set to true, the KDC will check the list of transited realms for cross-realm tickets against the transit path -@@ -848,13 +841,8 @@ Encryption types marked as "weak" are available for compatibility but +@@ -850,13 +843,8 @@ Encryption types marked as "weak" are available for compatibility but not recommended for use. ==================================================== ========================================================= @@ -124,7 +126,7 @@ index 62d1bfc05..2c6ea1855 100644 aes256-cts-hmac-sha1-96 aes256-cts aes256-sha1 AES-256 CTS mode with 96-bit SHA-1 HMAC aes128-cts-hmac-sha1-96 aes128-cts aes128-sha1 AES-128 CTS mode with 96-bit SHA-1 HMAC aes256-cts-hmac-sha384-192 aes256-sha2 AES-256 CTS mode with 192-bit SHA-384 HMAC -@@ -863,7 +851,6 @@ arcfour-hmac rc4-hmac arcfour-hmac-md5 RC4 with HMAC/MD5 +@@ -865,7 +853,6 @@ arcfour-hmac rc4-hmac arcfour-hmac-md5 RC4 with HMAC/MD5 arcfour-hmac-exp rc4-hmac-exp arcfour-hmac-md5-exp Exportable RC4 with HMAC/MD5 (weak) camellia256-cts-cmac camellia256-cts Camellia-256 CTS mode with CMAC camellia128-cts-cmac camellia128-cts Camellia-128 CTS mode with CMAC @@ -132,7 +134,7 @@ index 62d1bfc05..2c6ea1855 100644 des3 The triple DES family: des3-cbc-sha1 aes The AES family: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, aes256-cts-hmac-sha384-192, and aes128-cts-hmac-sha256-128 rc4 The RC4 family: arcfour-hmac -@@ -875,8 +862,8 @@ types for the variable in question. Types or families can be removed +@@ -877,8 +864,8 @@ types for the variable in question. Types or families can be removed from the current list by prefixing them with a minus sign ("-"). Types or families can be prefixed with a plus sign ("+") for symmetry; it has the same meaning as just listing the type or family. For @@ -144,10 +146,10 @@ index 62d1bfc05..2c6ea1855 100644 front. diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 5df3bfe36..89f02434b 100644 +index a3fb5d9f2..d5c498c89 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst -@@ -106,10 +106,7 @@ The libdefaults section may contain any of the following relations: +@@ -100,10 +100,7 @@ The libdefaults section may contain any of the following relations: in :ref:`Encryption_types` in :ref:`kdc.conf(5)`) will be filtered out of the lists **default_tgs_enctypes**, **default_tkt_enctypes**, and **permitted_enctypes**. The default @@ -159,7 +161,7 @@ index 5df3bfe36..89f02434b 100644 **canonicalize** If this flag is set to true, initial ticket requests to the KDC -@@ -163,9 +160,7 @@ The libdefaults section may contain any of the following relations: +@@ -157,9 +154,7 @@ The libdefaults section may contain any of the following relations: preference from highest to lowest. The list may be delimited with commas or whitespace. See :ref:`Encryption_types` in :ref:`kdc.conf(5)` for a list of the accepted values for this tag. @@ -170,7 +172,7 @@ index 5df3bfe36..89f02434b 100644 Do not set this unless required for specific backward compatibility purposes; stale values of this setting can prevent -@@ -177,9 +172,7 @@ The libdefaults section may contain any of the following relations: +@@ -171,9 +166,7 @@ The libdefaults section may contain any of the following relations: the client should request when making an AS-REQ, in order of preference from highest to lowest. The format is the same as for default_tgs_enctypes. The default value for this tag is @@ -181,7 +183,7 @@ index 5df3bfe36..89f02434b 100644 Do not set this unless required for specific backward compatibility purposes; stale values of this setting can prevent -@@ -297,9 +290,7 @@ The libdefaults section may contain any of the following relations: +@@ -291,9 +284,7 @@ The libdefaults section may contain any of the following relations: **permitted_enctypes** Identifies all encryption types that are permitted for use in session key encryption. The default value for this tag is @@ -273,14 +275,16 @@ index 47c6d4413..534795d15 100644 ENCTYPE_DES_CBC_MD4.rst ENCTYPE_DES_CBC_MD5.rst diff --git a/doc/conf.py b/doc/conf.py -index c32e33001..759367c21 100644 +index 7c688d871..759367c21 100644 --- a/doc/conf.py +++ b/doc/conf.py -@@ -272,7 +272,7 @@ else: +@@ -271,8 +271,8 @@ else: + rst_epilog += '.. |ckeytab| replace:: %s\n' % ckeytab rst_epilog += ''' .. |krb5conf| replace:: ``/etc/krb5.conf`` - .. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal des3-cbc-sha1:normal arcfour-hmac-md5:normal`` +-.. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal`` -.. |defetypes| replace:: ``aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha384-192 aes128-cts-hmac-sha256-128 des3-cbc-sha1 arcfour-hmac-md5 camellia256-cts-cmac camellia128-cts-cmac des-cbc-crc des-cbc-md5 des-cbc-md4`` ++.. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal des3-cbc-sha1:normal arcfour-hmac-md5:normal`` +.. |defetypes| replace:: ``aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha384-192 aes128-cts-hmac-sha256-128 des3-cbc-sha1 arcfour-hmac-md5 camellia256-cts-cmac camellia128-cts-cmac`` .. |defmkey| replace:: ``aes256-cts-hmac-sha1-96`` .. |copy| unicode:: U+000A9 @@ -3186,7 +3190,7 @@ index 39f656322..55491428b 100644 goto cleanup; context->clockskew = (krb5_deltat) ibuf; diff --git a/src/man/kdc.conf.man b/src/man/kdc.conf.man -index 4a75be8cb..8058134ac 100644 +index fd4dbb2e2..527d5d697 100644 --- a/src/man/kdc.conf.man +++ b/src/man/kdc.conf.man @@ -441,13 +441,6 @@ marks the server principal as host\-based or the service is also @@ -3203,7 +3207,7 @@ index 4a75be8cb..8058134ac 100644 \fBreject_bad_transit\fP (Boolean value.) If set to true, the KDC will check the list of transited realms for cross\-realm tickets against the transit path -@@ -969,30 +962,6 @@ center; +@@ -970,30 +963,6 @@ center; |l|l|. _ T{ @@ -3234,7 +3238,7 @@ index 4a75be8cb..8058134ac 100644 des3\-cbc\-raw T} T{ Triple DES cbc mode raw (weak) -@@ -1005,12 +974,6 @@ Triple DES cbc mode with HMAC/sha1 +@@ -1006,12 +975,6 @@ Triple DES cbc mode with HMAC/sha1 T} _ T{ @@ -3247,7 +3251,7 @@ index 4a75be8cb..8058134ac 100644 aes256\-cts\-hmac\-sha1\-96 aes256\-cts aes256\-sha1 T} T{ AES\-256 CTS mode with 96\-bit SHA\-1 HMAC -@@ -1059,12 +1022,6 @@ Camellia\-128 CTS mode with CMAC +@@ -1060,12 +1023,6 @@ Camellia\-128 CTS mode with CMAC T} _ T{ @@ -3260,7 +3264,7 @@ index 4a75be8cb..8058134ac 100644 des3 T} T{ The triple DES family: des3\-cbc\-sha1 -@@ -1095,8 +1052,8 @@ types for the variable in question. Types or families can be removed +@@ -1096,8 +1053,8 @@ types for the variable in question. Types or families can be removed from the current list by prefixing them with a minus sign ("\-"). Types or families can be prefixed with a plus sign ("+") for symmetry; it has the same meaning as just listing the type or family. For @@ -3272,10 +3276,10 @@ index 4a75be8cb..8058134ac 100644 front. .sp diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man -index aafdf7f83..d6ff91c3b 100644 +index 433f38d71..4bc190e32 100644 --- a/src/man/krb5.conf.man +++ b/src/man/krb5.conf.man -@@ -254,7 +254,7 @@ the client should request when making a TGS\-REQ, in order of +@@ -240,7 +240,7 @@ the client should request when making a TGS\-REQ, in order of preference from highest to lowest. The list may be delimited with commas or whitespace. See Encryption_types in kdc.conf(5) for a list of the accepted values for this tag. @@ -3284,7 +3288,7 @@ index aafdf7f83..d6ff91c3b 100644 will be implicitly removed from this list if the value of \fBallow_weak_crypto\fP is false. .sp -@@ -268,7 +268,7 @@ Identifies the supported list of session key encryption types that +@@ -254,7 +254,7 @@ Identifies the supported list of session key encryption types that the client should request when making an AS\-REQ, in order of preference from highest to lowest. The format is the same as for default_tgs_enctypes. The default value for this tag is @@ -3293,7 +3297,7 @@ index aafdf7f83..d6ff91c3b 100644 removed from this list if the value of \fBallow_weak_crypto\fP is false. .sp -@@ -388,7 +388,7 @@ used across NATs. The default value is true. +@@ -374,7 +374,7 @@ used across NATs. The default value is true. \fBpermitted_enctypes\fP Identifies all encryption types that are permitted for use in session key encryption. The default value for this tag is diff --git a/Remove-the-v4-and-afs3-salt-types.patch b/Remove-the-v4-and-afs3-salt-types.patch index eb3e9fc..e135f2e 100644 --- a/Remove-the-v4-and-afs3-salt-types.patch +++ b/Remove-the-v4-and-afs3-salt-types.patch @@ -1,4 +1,4 @@ -From cebf1ea82c4d2dc4494ad0af7525fd324e6d92e2 Mon Sep 17 00:00:00 2001 +From 111e528c68393435be41f71f22f41b7a04ccad1e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 24 May 2019 13:11:44 -0400 Subject: [PATCH] Remove the v4 and afs3 salt types @@ -12,6 +12,7 @@ krb4 databases. ticket: 8808 (cherry picked from commit e0a35ff48c09a26ebb9aefd7e98855a84574b8be) +[rharwood@redhat.com: release version conflict in man pages] --- doc/admin/conf_files/kdc_conf.rst | 2 - src/include/kdb.h | 4 +- @@ -33,10 +34,10 @@ ticket: 8808 17 files changed, 24 insertions(+), 164 deletions(-) diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst -index c73791ceb..62d1bfc05 100644 +index 72f002d4d..7fbc8eb79 100644 --- a/doc/admin/conf_files/kdc_conf.rst +++ b/doc/admin/conf_files/kdc_conf.rst -@@ -917,10 +917,8 @@ follows: +@@ -919,10 +919,8 @@ follows: ================= ============================================ normal default for Kerberos Version 5 @@ -292,18 +293,18 @@ index 7c400be86..3c9168591 100644 - success('krb5_get_etype_info() tests') diff --git a/src/man/kdc.conf.man b/src/man/kdc.conf.man -index ab3ee0289..4a75be8cb 100644 +index 959f00de5..fd4dbb2e2 100644 --- a/src/man/kdc.conf.man +++ b/src/man/kdc.conf.man @@ -1,6 +1,6 @@ .\" Man page generated from reStructuredText. . --.TH "KDC.CONF" "5" " " "1.17" "MIT Kerberos" +-.TH "KDC.CONF" "5" " " "1.17.1" "MIT Kerberos" +.TH "KDC.CONF" "5" " " "1.18" "MIT Kerberos" .SH NAME kdc.conf \- Kerberos V5 KDC configuration file . -@@ -1148,12 +1148,6 @@ default for Kerberos Version 5 +@@ -1149,12 +1149,6 @@ default for Kerberos Version 5 T} _ T{ @@ -316,7 +317,7 @@ index ab3ee0289..4a75be8cb 100644 norealm T} T{ same as the default, without using realm information -@@ -1166,12 +1160,6 @@ uses only realm information as the salt +@@ -1167,12 +1161,6 @@ uses only realm information as the salt T} _ T{ diff --git a/Set-a-more-modern-default-ksu-CMD_PATH.patch b/Set-a-more-modern-default-ksu-CMD_PATH.patch index df99231..47defd5 100644 --- a/Set-a-more-modern-default-ksu-CMD_PATH.patch +++ b/Set-a-more-modern-default-ksu-CMD_PATH.patch @@ -1,4 +1,4 @@ -From 47fc137981db0b2b9834765e28f70b151a88cb83 Mon Sep 17 00:00:00 2001 +From 3d8b0bb1469295bd09f8ba81d3fb059a9ef372f2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:32:09 -0400 Subject: [PATCH] Set a more modern default ksu CMD_PATH diff --git a/Simplify-SAM-2-as_key-handling.patch b/Simplify-SAM-2-as_key-handling.patch index 125a91b..1930a5d 100644 --- a/Simplify-SAM-2-as_key-handling.patch +++ b/Simplify-SAM-2-as_key-handling.patch @@ -1,4 +1,4 @@ -From 9c80f80f48f3b761145e97914a4488398435f2d6 Mon Sep 17 00:00:00 2001 +From f7fb525d762ba42f62f1044f07f38a243980a2ba Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 5 May 2019 18:53:27 -0400 Subject: [PATCH] Simplify SAM-2 as_key handling diff --git a/Simplify-krb5_dbe_def_search_enctype.patch b/Simplify-krb5_dbe_def_search_enctype.patch index a12d203..f98922e 100644 --- a/Simplify-krb5_dbe_def_search_enctype.patch +++ b/Simplify-krb5_dbe_def_search_enctype.patch @@ -1,4 +1,4 @@ -From 5ff802a443dfd47e2f43a37de0dc439a1c583849 Mon Sep 17 00:00:00 2001 +From a7cd60bc97b4d9b171eddae391cf9ecd84c58d31 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Aug 2019 16:19:12 -0400 Subject: [PATCH] Simplify krb5_dbe_def_search_enctype() diff --git a/Simply-OpenSSL-PKCS7-decryption-code.patch b/Simply-OpenSSL-PKCS7-decryption-code.patch index 0cf844c..35f9e28 100644 --- a/Simply-OpenSSL-PKCS7-decryption-code.patch +++ b/Simply-OpenSSL-PKCS7-decryption-code.patch @@ -1,4 +1,4 @@ -From 8cc93c83241cd96a8565c427418f6c3f13609b65 Mon Sep 17 00:00:00 2001 +From db62fe97a56f8f8476e3202a492d1c3d784d52b2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 May 2019 13:13:06 -0400 Subject: [PATCH] Simply OpenSSL PKCS7 decryption code diff --git a/Skip-URI-tests-when-using-asan.patch b/Skip-URI-tests-when-using-asan.patch index e6ff6e5..05d68db 100644 --- a/Skip-URI-tests-when-using-asan.patch +++ b/Skip-URI-tests-when-using-asan.patch @@ -1,4 +1,4 @@ -From 1b251fe463c1284381612aeb7f2271d28d171d9d Mon Sep 17 00:00:00 2001 +From c58dbf05938b57a729d1b3811424866296f11998 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 3 Aug 2019 13:30:28 -0400 Subject: [PATCH] Skip URI tests when using asan diff --git a/Squash-apparent-forward-null-in-clnttcp_create.patch b/Squash-apparent-forward-null-in-clnttcp_create.patch index 81845e3..fe55a52 100644 --- a/Squash-apparent-forward-null-in-clnttcp_create.patch +++ b/Squash-apparent-forward-null-in-clnttcp_create.patch @@ -1,4 +1,4 @@ -From dabc30f0500718ef39706849b778524d4fa2152d Mon Sep 17 00:00:00 2001 +From 566fa44c8f53b3c558791bef29d01fb6a02ff559 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 30 Aug 2019 11:16:58 -0400 Subject: [PATCH] Squash apparent forward-null in clnttcp_create() diff --git a/Support-389ds-s-lockout-model.patch b/Support-389ds-s-lockout-model.patch index 50d81e9..b8f4d02 100644 --- a/Support-389ds-s-lockout-model.patch +++ b/Support-389ds-s-lockout-model.patch @@ -1,4 +1,4 @@ -From d46ea68d04b91320aa7eb96f85ca77b98fd44e88 Mon Sep 17 00:00:00 2001 +From a9c73bc1078dc6287a3838220ef1bd435273506e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:47:44 -0400 Subject: [PATCH] Support 389ds's lockout model diff --git a/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch b/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch index 90b654d..be73cc3 100644 --- a/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch +++ b/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch @@ -1,4 +1,4 @@ -From 12ffeca5a708add9461e71300d58a08ea99ed6e4 Mon Sep 17 00:00:00 2001 +From 5e7c6ac2f9ee4dfe182f28c0801811910b63be1d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 16 Apr 2019 14:16:39 -0400 Subject: [PATCH] Update ASN.1 SAM tests to use a modern enctype diff --git a/Update-default-krb5kdc-mkey-manual-entry-enctype.patch b/Update-default-krb5kdc-mkey-manual-entry-enctype.patch index b14e637..7954dcb 100644 --- a/Update-default-krb5kdc-mkey-manual-entry-enctype.patch +++ b/Update-default-krb5kdc-mkey-manual-entry-enctype.patch @@ -1,4 +1,4 @@ -From a3e73d1a874ad68c7ef0cb2ac0fa529b87b29710 Mon Sep 17 00:00:00 2001 +From 04ce158f626a683d60914f464bac24a1bd5687e3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 20 May 2019 16:52:57 -0400 Subject: [PATCH] Update default krb5kdc mkey manual-entry enctype @@ -14,10 +14,10 @@ kadmind, which is currently aes256-cts-hmac-sha1-96. 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/doc/admin/admin_commands/krb5kdc.rst b/doc/admin/admin_commands/krb5kdc.rst -index 0342d0d18..455bb6858 100644 +index 08d40cc0d..631a0de84 100644 --- a/doc/admin/admin_commands/krb5kdc.rst +++ b/doc/admin/admin_commands/krb5kdc.rst -@@ -39,7 +39,7 @@ LDAP database. +@@ -41,7 +41,7 @@ LDAP database. The **-k** *keytype* option specifies the key type of the master key to be entered manually as a password when **-m** is given; the default @@ -40,10 +40,10 @@ index 60092a0df..04393772f 100644 case 'M': /* master key name in DB */ mkey_name = optarg; diff --git a/src/man/krb5kdc.man b/src/man/krb5kdc.man -index 8ace9662f..aa8614698 100644 +index 9c9b816b3..100f371c4 100644 --- a/src/man/krb5kdc.man +++ b/src/man/krb5kdc.man -@@ -59,7 +59,7 @@ LDAP database. +@@ -61,7 +61,7 @@ LDAP database. .sp The \fB\-k\fP \fIkeytype\fP option specifies the key type of the master key to be entered manually as a password when \fB\-m\fP is given; the default diff --git a/Update-test-suite-cert-message-digest-to-sha256.patch b/Update-test-suite-cert-message-digest-to-sha256.patch index 9f91576..ec7c9df 100644 --- a/Update-test-suite-cert-message-digest-to-sha256.patch +++ b/Update-test-suite-cert-message-digest-to-sha256.patch @@ -1,4 +1,4 @@ -From 73e08f464b5a55c1d86b3d08f1fd0f391253548f Mon Sep 17 00:00:00 2001 +From 8c38e6a1cef9bee050e42f591a530d077bb11f17 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 12 Nov 2019 13:38:59 -0500 Subject: [PATCH] Update test suite cert message digest to sha256 diff --git a/Update-test-suite-to-avoid-single-DES-enctypes.patch b/Update-test-suite-to-avoid-single-DES-enctypes.patch index 8a67bdb..fe79d58 100644 --- a/Update-test-suite-to-avoid-single-DES-enctypes.patch +++ b/Update-test-suite-to-avoid-single-DES-enctypes.patch @@ -1,4 +1,4 @@ -From ec9180a78e84c71940c3ef3834bb22aae1245d91 Mon Sep 17 00:00:00 2001 +From 99077dd3855832912df7563086cd615ba430e440 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 24 May 2019 13:11:55 -0400 Subject: [PATCH] Update test suite to avoid single-DES enctypes diff --git a/Use-backported-version-of-OpenSSL-3-KDF-interface.patch b/Use-backported-version-of-OpenSSL-3-KDF-interface.patch index 9408a87..4a24a89 100644 --- a/Use-backported-version-of-OpenSSL-3-KDF-interface.patch +++ b/Use-backported-version-of-OpenSSL-3-KDF-interface.patch @@ -1,4 +1,4 @@ -From b4099e1de59730ca7eb022891c1e1cce1d1eb001 Mon Sep 17 00:00:00 2001 +From bdb78f9d3fbf9abccec9b41709bb0131e9ec28d6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 15 Nov 2019 20:05:16 +0000 Subject: [PATCH] Use backported version of OpenSSL-3 KDF interface @@ -10,7 +10,7 @@ Subject: [PATCH] Use backported version of OpenSSL-3 KDF interface 3 files changed, 423 insertions(+), 184 deletions(-) diff --git a/src/configure.in b/src/configure.in -index d0d8c4ed7..6573e8343 100644 +index 1df6f18fc..3bd5e683d 100644 --- a/src/configure.in +++ b/src/configure.in @@ -269,6 +269,10 @@ AC_SUBST(CRYPTO_IMPL) diff --git a/Use-imported-soft-pkcs11-for-tests.patch b/Use-imported-soft-pkcs11-for-tests.patch index 098dbe8..96dd953 100644 --- a/Use-imported-soft-pkcs11-for-tests.patch +++ b/Use-imported-soft-pkcs11-for-tests.patch @@ -1,4 +1,4 @@ -From 3d1f71979d0a41e75f5169ecbdd594e171e8bbf6 Mon Sep 17 00:00:00 2001 +From 923cafe924fa08c1b35ca11d5473a255d629592d Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 20 Jun 2019 13:41:57 -0400 Subject: [PATCH] Use imported soft-pkcs11 for tests @@ -21,7 +21,7 @@ integrate it into the build system, and use it for the PKINIT tests. create mode 100644 src/tests/softpkcs11/softpkcs11.exports diff --git a/src/configure.in b/src/configure.in -index a19a0ea97..d0d8c4ed7 100644 +index 3e3b95e49..1df6f18fc 100644 --- a/src/configure.in +++ b/src/configure.in @@ -1086,6 +1086,7 @@ int i = 1; diff --git a/Use-secure_getenv-where-appropriate.patch b/Use-secure_getenv-where-appropriate.patch index c699a0f..1adc322 100644 --- a/Use-secure_getenv-where-appropriate.patch +++ b/Use-secure_getenv-where-appropriate.patch @@ -1,4 +1,4 @@ -From e2fc380331455d023001d74efbe9563e271cee10 Mon Sep 17 00:00:00 2001 +From a41dc78bd3a879870eece3bf0a7c66196c90e7e8 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 24 Apr 2019 16:19:50 -0400 Subject: [PATCH] Use secure_getenv() where appropriate diff --git a/Various-gssalloc-fixes.patch b/Various-gssalloc-fixes.patch deleted file mode 100644 index 244dccf..0000000 --- a/Various-gssalloc-fixes.patch +++ /dev/null @@ -1,142 +0,0 @@ -From 9e574469b639220a34bbf3dc36a96854ad0c269a Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 23 Nov 2019 11:42:59 -0500 -Subject: [PATCH] Various gssalloc fixes - -The DEBUG_GSSALLOC version of gssalloc_realloc() must add the sentinel -size to the byte count. - -The mechglue gss_decapsulate_token(), gss_encapsulate_token(), and -gss_export_sec_context() must use gssalloc_malloc() to allocate -output buffers. - -The krb5 mech's gss_export_name_composite() and gss_pseudo_random() -implementations must use gssalloc_malloc() to allocate output buffers. - -SPNEGO's gss_display_status() implementation must use gssalloc for the -output buffer. - -The sample GSS server must use gss_release_buffer() to free the result -of gss_export_sec_context(). - -ticket: 8852 (new) -tags: pullup -target_version: 1.17-next -target_version: 1.16-next - -(cherry picked from commit ab5c4259bdbe51dd3f4b5c5aff22628188d04322) ---- - src/appl/gss-sample/gss-server.c | 2 +- - src/lib/gssapi/generic/gssapi_alloc.h | 2 +- - src/lib/gssapi/krb5/naming_exts.c | 2 +- - src/lib/gssapi/krb5/prf.c | 2 +- - src/lib/gssapi/mechglue/g_decapsulate_token.c | 2 +- - src/lib/gssapi/mechglue/g_encapsulate_token.c | 2 +- - src/lib/gssapi/mechglue/g_exp_sec_context.c | 2 +- - src/lib/gssapi/spnego/spnego_mech.c | 2 +- - 8 files changed, 8 insertions(+), 8 deletions(-) - -diff --git a/src/appl/gss-sample/gss-server.c b/src/appl/gss-sample/gss-server.c -index 6b5959a1c..793fefc9f 100644 ---- a/src/appl/gss-sample/gss-server.c -+++ b/src/appl/gss-sample/gss-server.c -@@ -391,7 +391,7 @@ test_import_export_context(gss_ctx_id_t *context) - if (verbose && logfile) - fprintf(logfile, "Importing context: %7.4f seconds\n", - timeval_subtract(&tm1, &tm2)); -- free(context_token.value); -+ (void) gss_release_buffer(&min_stat, &context_token); - return 0; - } - -diff --git a/src/lib/gssapi/generic/gssapi_alloc.h b/src/lib/gssapi/generic/gssapi_alloc.h -index 9a5cd9892..d0bd4b2b0 100644 ---- a/src/lib/gssapi/generic/gssapi_alloc.h -+++ b/src/lib/gssapi/generic/gssapi_alloc.h -@@ -80,7 +80,7 @@ gssalloc_realloc(void *value, size_t size) - return gssalloc_malloc(size); - if (memcmp(p, "gssalloc", 8) != 0) - abort(); -- return (char *)realloc(p, size) + 8; -+ return (char *)realloc(p, size + 8) + 8; - } - - #else /* not _WIN32 or DEBUG_GSSALLOC */ -diff --git a/src/lib/gssapi/krb5/naming_exts.c b/src/lib/gssapi/krb5/naming_exts.c -index 41752d90b..2ac1aba33 100644 ---- a/src/lib/gssapi/krb5/naming_exts.c -+++ b/src/lib/gssapi/krb5/naming_exts.c -@@ -624,7 +624,7 @@ krb5_gss_export_name_composite(OM_uint32 *minor_status, - exp_composite_name->length += 4; /* length of encoded attributes */ - if (attrs != NULL) - exp_composite_name->length += attrs->length; -- exp_composite_name->value = malloc(exp_composite_name->length); -+ exp_composite_name->value = gssalloc_malloc(exp_composite_name->length); - if (exp_composite_name->value == NULL) { - code = ENOMEM; - goto cleanup; -diff --git a/src/lib/gssapi/krb5/prf.c b/src/lib/gssapi/krb5/prf.c -index e897074fc..f87957bdf 100644 ---- a/src/lib/gssapi/krb5/prf.c -+++ b/src/lib/gssapi/krb5/prf.c -@@ -86,7 +86,7 @@ krb5_gss_pseudo_random(OM_uint32 *minor_status, - if (desired_output_len == 0) - return GSS_S_COMPLETE; - -- prf_out->value = k5alloc(desired_output_len, &code); -+ prf_out->value = gssalloc_malloc(desired_output_len); - if (prf_out->value == NULL) { - code = KG_INPUT_TOO_LONG; - goto cleanup; -diff --git a/src/lib/gssapi/mechglue/g_decapsulate_token.c b/src/lib/gssapi/mechglue/g_decapsulate_token.c -index 934d2607c..1c04e2f27 100644 ---- a/src/lib/gssapi/mechglue/g_decapsulate_token.c -+++ b/src/lib/gssapi/mechglue/g_decapsulate_token.c -@@ -55,7 +55,7 @@ gss_decapsulate_token(gss_const_buffer_t input_token, - if (minor != 0) - return GSS_S_DEFECTIVE_TOKEN; - -- output_token->value = malloc(body_size); -+ output_token->value = gssalloc_malloc(body_size); - if (output_token->value == NULL) - return GSS_S_FAILURE; - -diff --git a/src/lib/gssapi/mechglue/g_encapsulate_token.c b/src/lib/gssapi/mechglue/g_encapsulate_token.c -index 6ce0eeb0f..850e3ee65 100644 ---- a/src/lib/gssapi/mechglue/g_encapsulate_token.c -+++ b/src/lib/gssapi/mechglue/g_encapsulate_token.c -@@ -51,7 +51,7 @@ gss_encapsulate_token(gss_const_buffer_t input_token, - assert(tokenSize > 2); - tokenSize -= 2; /* TOK_ID */ - -- output_token->value = malloc(tokenSize); -+ output_token->value = gssalloc_malloc(tokenSize); - if (output_token->value == NULL) - return GSS_S_FAILURE; - -diff --git a/src/lib/gssapi/mechglue/g_exp_sec_context.c b/src/lib/gssapi/mechglue/g_exp_sec_context.c -index 1d7990b1c..a04afe3d1 100644 ---- a/src/lib/gssapi/mechglue/g_exp_sec_context.c -+++ b/src/lib/gssapi/mechglue/g_exp_sec_context.c -@@ -112,7 +112,7 @@ gss_buffer_t interprocess_token; - - length = token.length + 4 + ctx->mech_type->length; - interprocess_token->length = length; -- interprocess_token->value = malloc(length); -+ interprocess_token->value = gssalloc_malloc(length); - if (interprocess_token->value == 0) { - *minor_status = ENOMEM; - status = GSS_S_FAILURE; -diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/spnego/spnego_mech.c -index 9d6027ce8..412b4c41c 100644 ---- a/src/lib/gssapi/spnego/spnego_mech.c -+++ b/src/lib/gssapi/spnego/spnego_mech.c -@@ -3731,7 +3731,7 @@ negotiate_mech(gss_OID_set supported, gss_OID_set received, - static spnego_token_t - make_spnego_token(const char *name) - { -- return (spnego_token_t)strdup(name); -+ return (spnego_token_t)gssalloc_strdup(name); - } - - static gss_buffer_desc diff --git a/krb5-1.12.1-pam.patch b/krb5-1.12.1-pam.patch index 10892d4..2ce2a57 100644 --- a/krb5-1.12.1-pam.patch +++ b/krb5-1.12.1-pam.patch @@ -1,4 +1,4 @@ -From c8f2e321b2d8471feee69bbca3179e675228bd8a Mon Sep 17 00:00:00 2001 +From 5e2837a56bb6bb1fbaf371377dbffa35aa81b3f1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] krb5-1.12.1-pam.patch @@ -756,7 +756,7 @@ index 000000000..0ab76569c +void appl_pam_cleanup(void); +#endif diff --git a/src/configure.in b/src/configure.in -index 61ef738dc..e9a12ac16 100644 +index 36df71fa9..cd8ccabcd 100644 --- a/src/configure.in +++ b/src/configure.in @@ -1352,6 +1352,8 @@ AC_SUBST([VERTO_VERSION]) diff --git a/krb5-1.15-beta1-buildconf.patch b/krb5-1.15-beta1-buildconf.patch index ec96987..e074e10 100644 --- a/krb5-1.15-beta1-buildconf.patch +++ b/krb5-1.15-beta1-buildconf.patch @@ -1,4 +1,4 @@ -From b7ba0fa6a2f8324c58b57dedde33c1ae5d1ddb41 Mon Sep 17 00:00:00 2001 +From ab2b67102127e448cc1a266fbbe2c738a1a3a158 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] krb5-1.15-beta1-buildconf.patch diff --git a/krb5-1.17-beta1-selinux-label.patch b/krb5-1.17-beta1-selinux-label.patch index bf5d4eb..c82350f 100644 --- a/krb5-1.17-beta1-selinux-label.patch +++ b/krb5-1.17-beta1-selinux-label.patch @@ -1,4 +1,4 @@ -From e1c4f8894d22da9c157bfcf31e28f9ceaeebe39e Mon Sep 17 00:00:00 2001 +From b50a43ef1f09694298ec043104a59082d6f37c8c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] krb5-1.17-beta1-selinux-label.patch @@ -172,7 +172,7 @@ index ce87e21ca..917357df9 100644 GSS_LIBS = $(GSS_KRB5_LIB) # needs fixing if ever used on macOS! diff --git a/src/configure.in b/src/configure.in -index e9a12ac16..93aec682e 100644 +index cd8ccabcd..feae21c3e 100644 --- a/src/configure.in +++ b/src/configure.in @@ -1354,6 +1354,8 @@ AC_PATH_PROG(GROFF, groff) diff --git a/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index e55cfd0..89b9e2f 100644 --- a/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From 6048ef0ecbf45f239a6df3074975b926ce286e5a Mon Sep 17 00:00:00 2001 +From c874aa2c7ec16203c0be91e9e789b21221689de2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] krb5-1.17post6 FIPS with PRNG and RADIUS and MD4 diff --git a/krb5-1.3.1-dns.patch b/krb5-1.3.1-dns.patch index 1cbb6f8..ec0e306 100644 --- a/krb5-1.3.1-dns.patch +++ b/krb5-1.3.1-dns.patch @@ -1,4 +1,4 @@ -From 2cf42007974a9c72e8e6a6cc02295e9c2a89317e Mon Sep 17 00:00:00 2001 +From 35cd8e40a35ce4546eaffada2f401a7f0f6a83b3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] krb5-1.3.1-dns.patch diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index 89f5729..a5046d0 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -1,4 +1,4 @@ -From d205539d89b857f7bd2b09dfc875d5cdd79167b7 Mon Sep 17 00:00:00 2001 +From e0391c7071741e6d59025d8b4a26119f2998d90c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] krb5-1.9-debuginfo.patch diff --git a/krb5.spec b/krb5.spec index d2e903d..0a2c146 100644 --- a/krb5.spec +++ b/krb5.spec @@ -16,20 +16,13 @@ Summary: The Kerberos network authentication system Name: krb5 -Version: 1.17 +Version: 1.17.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 54%{?dist} +Release: 1%{?dist} -# lookaside-cached sources; two downloads and a build artifact -Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz # rharwood has trust path to signing key and verifies on check-in +Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz Source1: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz.asc -# This source is generated during the build because sphinx doesn't -# give me architecture-deterministic documentation builds. -# To override this behavior (e.g., new upstream version), do: -# tar cfT krb5-1.15.2-pdfs.tar /dev/null -# or the like. -Source3: krb5-%{version}%{prerelease}-pdfs.tar # Numbering is a relic of old init systems etc. It's easiest to just leave. Source2: kprop.service @@ -63,7 +56,6 @@ Patch97: Add-function-and-enctype-flag-for-deprecations.patch Patch98: Make-etype-names-in-KDC-logs-human-readable.patch Patch99: Mark-deprecated-enctypes-when-used.patch Patch100: Properly-size-ifdef-in-k5_cccol_lock.patch -Patch101: Fix-memory-leak-in-none-replay-cache-type.patch Patch104: Clarify-header-comment-for-krb5_cc_start_seq_get.patch Patch105: Implement-krb5_cc_remove_cred-for-remaining-types.patch Patch106: Remove-srvtab-support.patch @@ -80,7 +72,6 @@ Patch116: Clear-forwardable-flag-instead-of-denying-request.patch Patch117: Add-dns_canonicalize_hostname-fallback-support.patch Patch118: Use-secure_getenv-where-appropriate.patch Patch119: Initialize-some-data-structure-magic-fields.patch -Patch120: Fix-some-return-code-handling-bugs.patch Patch121: Modernize-exit-path-in-gss_krb5int_copy_ccache.patch Patch122: Simplify-SAM-2-as_key-handling.patch Patch123: Avoid-alignment-warnings-in-openssl-rc4.c.patch @@ -115,8 +106,6 @@ Patch155: Use-imported-soft-pkcs11-for-tests.patch Patch156: Fix-Coverity-defects-in-soft-pkcs11-test-code.patch Patch157: Skip-URI-tests-when-using-asan.patch Patch158: Fix-memory-leaks-in-soft-pkcs11-code.patch -Patch159: Initialize-life-rlife-in-kdcpolicy-interface.patch -Patch160: Fix-KCM-client-time-offset-propagation.patch Patch162: Simplify-krb5_dbe_def_search_enctype.patch Patch163: Squash-apparent-forward-null-in-clnttcp_create.patch Patch164: Remove-null-check-in-krb5_gss_duplicate_name.patch @@ -126,9 +115,6 @@ Patch167: Fix-minor-errors-in-softpkcs11.patch Patch168: Update-test-suite-cert-message-digest-to-sha256.patch Patch169: Use-backported-version-of-OpenSSL-3-KDF-interface.patch Patch170: krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch -Patch171: Fix-kadmin-addprinc-randkey-kvno.patch -Patch172: Various-gssalloc-fixes.patch -Patch173: Qualify-short-hostnames-when-not-using-DNS.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -136,42 +122,15 @@ BuildRequires: autoconf, bison, cmake, flex, gawk, gettext, pkgconfig, sed BuildRequires: gcc BuildRequires: libcom_err-devel, libedit-devel, libss-devel BuildRequires: gzip, ncurses-devel -BuildRequires: python3-sphinx, texlive-pdftex, latexmk - -# For autosetup -BuildRequires: git - -# Originally from \usepackage directives produced by sphinx: -BuildRequires: tex(babel.sty) -BuildRequires: tex(bookmark.sty) -BuildRequires: tex(capt-of.sty) -BuildRequires: tex(eqparbox.sty) -BuildRequires: tex(fancybox.sty) -BuildRequires: tex(fncychap.sty) -BuildRequires: tex(fontenc.sty) -BuildRequires: tex(framed.sty) -BuildRequires: tex(hyperref.sty) -BuildRequires: tex(ifthen.sty) -BuildRequires: tex(inputenc.sty) -BuildRequires: tex(longtable.sty) -BuildRequires: tex(multirow.sty) -BuildRequires: tex(needspace.sty) -BuildRequires: tex(report.cls) -BuildRequires: tex(tabulary.sty) -BuildRequires: tex(threeparttable.sty) -BuildRequires: tex(times.sty) -BuildRequires: tex(titlesec.sty) -BuildRequires: tex(upquote.sty) -BuildRequires: tex(wrapfig.sty) - -# Typical fonts, and the commands which we need to have present. -BuildRequires: texlive, texlive-latex, texlive-texmf-fonts -BuildRequires: /usr/bin/pdflatex /usr/bin/makeindex +BuildRequires: python3-sphinx BuildRequires: keyutils, keyutils-libs-devel >= 1.5.8 BuildRequires: libselinux-devel BuildRequires: pam-devel BuildRequires: systemd-units +# For autosetup +BuildRequires: git + # For the test framework. BuildRequires: perl-interpreter, dejagnu, tcl-devel, python3 BuildRequires: net-tools, rpcbind @@ -291,7 +250,7 @@ contains only the libkadm5clnt and libkadm5serv shared objects. This interface is not considered stable. %prep -%autosetup -S git -n %{name}-%{version}%{prerelease} -a 3 +%autosetup -S git -n %{name}-%{version}%{prerelease} ln NOTICE LICENSE # Generate an FDS-compatible LDIF file. @@ -381,17 +340,10 @@ fi # Build the docs. make -C src/doc paths.py version.py cp src/doc/paths.py doc/ -mkdir -p build-man build-html build-pdf +mkdir -p build-man build-html sphinx-build -a -b man -t pathsubs doc build-man sphinx-build -a -b html -t pathsubs doc build-html rm -fr build-html/_sources -sphinx-build -a -b latex -t pathsubs doc build-pdf -# Build the PDFs if we don't have pre-built ones -for pdf in admin appdev basic build plugindev user ; do - test -s build-pdf/$pdf.pdf || make -C build-pdf -done -# new krb5-version-pdf -tar -cf "krb5-%{version}%{prerelease}-pdfs.tar.new" build-pdf/*.pdf # We need to cut off any access to locally-running nameservers, too. %{__cc} -fPIC -shared -o noport.so -Wall -Wextra %{SOURCE100} @@ -574,7 +526,6 @@ exit 0 %doc src/config-files/services.append %doc src/config-files/krb5.conf %doc build-html/* -%doc build-pdf/user.pdf build-pdf/basic.pdf %attr(0755,root,root) %doc src/config-files/convert-config-files # Clients of the KDC, including tools you're likely to need if you're running @@ -606,7 +557,6 @@ exit 0 %files server %docdir %{_mandir} -%doc build-pdf/admin.pdf build-pdf/build.pdf %doc src/config-files/kdc.conf %{_unitdir}/krb5kdc.service %{_unitdir}/kadmin.service @@ -712,7 +662,6 @@ exit 0 %files devel %docdir %{_mandir} -%doc build-pdf/appdev.pdf build-pdf/plugindev.pdf %{_includedir}/* %{_libdir}/libgssapi_krb5.so @@ -736,6 +685,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Dec 12 2019 Robbie Harwood - 1.17.1-1 +- New upstream version - 1.17.1 +- Stop building and packaging PDFs + * Fri Dec 06 2019 Robbie Harwood - 1.17-54 - Qualify short hostnames when not using DNS diff --git a/sources b/sources index 3517dec..01f775d 100644 --- a/sources +++ b/sources @@ -1,3 +1,2 @@ -SHA512 (krb5-1.17-pdfs.tar) = 89a5a709720ee9028e9bfbcbc808eec436c4b9c6e105888b37660e97cff48e190bc77affa9809353de9cf2f39e517e8a6ab22792263978b403a4a6317ac24a46 -SHA512 (krb5-1.17.tar.gz) = 7462a578b936bd17f155a362dbb5d388e157a80a096549028be6c55400b11361c7f8a28e424fd5674801873651df4e694d536cae66728b7ae5e840e532358c52 -SHA512 (krb5-1.17.tar.gz.asc) = 7ee81ccd05559ca1ff945619165297db251010db7c0205855f89ae66a73bc78e98f5e28ea154dcb752f5d4afb9349a293dcf8f64858d2129a869295fa8946e0f +SHA512 (krb5-1.17.1.tar.gz) = e0c3dc0a6554ab3105ac32f3f01519f56064500213aa743816235d83250abc1db9a9ca38a2ba93a938d562b4af135a013017ce96346d6742bca0c812b842ceef +SHA512 (krb5-1.17.1.tar.gz.asc) = 9665c0b83cc5e8fafbb7f47c383c6bf00e498befa305ab7ed8b867ff6f54a09b6b1f3b7a7f007ceb6dfbc1ebfb797be21cb97ac51c1c8fc8e956d83ce30aa7b1 From d6ef09022cff53e6f4d0ed8ca5c07d5a468c6688 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 13 Dec 2019 19:11:07 +0000 Subject: [PATCH 142/304] Enable the LMDB backend for the KDB --- krb5.spec | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 0a2c146..8dcf4f6 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1%{?dist} +Release: 2%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -139,6 +139,7 @@ BuildRequires: iproute BuildRequires: libverto-devel BuildRequires: openldap-devel BuildRequires: openssl-devel >= 1:1.1.1d-4 +BuildRequires: lmdb-devel %ifarch %{ix86} x86_64 BuildRequires: yasm @@ -325,6 +326,7 @@ CPPFLAGS="`echo $DEFINES $INCLUDES`" --with-pam \ --with-selinux \ --with-prng-alg=os \ + --with-lmdb \ || (cat config.log; exit 1) # Now build it. make @@ -581,6 +583,7 @@ exit 0 %dir %{_libdir}/krb5/plugins/authdata %{_libdir}/krb5/plugins/preauth/otp.so %{_libdir}/krb5/plugins/kdb/db2.so +%{_libdir}/krb5/plugins/kdb/klmdb.so # KDC binaries and configuration. %{_mandir}/man5/kadm5.acl.5* @@ -685,6 +688,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Dec 13 2019 Robbie Harwood - 1.17.1-2 +- Enable the LMDB backend for the KDB + * Thu Dec 12 2019 Robbie Harwood - 1.17.1-1 - New upstream version - 1.17.1 - Stop building and packaging PDFs From fd463aed6a90031908e2bd65743fd6c95a4e843a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 3 Jan 2020 11:36:21 -0500 Subject: [PATCH 143/304] Don't warn in kadmin when no policy is specified Do not always canonicalize enterprise principals --- ...anonicalization-in-non-krbtgt-AS-REP.patch | 64 +++++ ...able-flag-instead-of-denying-request.patch | 7 +- ...s-canonicalize-enterprise-principals.patch | 113 +++++++++ ...n-kadmin-when-no-policy-is-specified.patch | 160 +++++++++++++ ...5_cc_remove_cred-for-remaining-types.patch | 30 +-- ...ype-names-in-KDC-logs-human-readable.patch | 137 +++++------ Remove-3des-support.patch | 65 +++--- ...beros-v4-support-vestiges-from-ccapi.patch | 60 +++-- Remove-PKINIT-draft-9-support.patch | 160 ++++++------- Simplify-krb5_dbe_def_search_enctype.patch | 51 ++-- Simply-OpenSSL-PKCS7-decryption-code.patch | 85 +++---- ...t-suite-to-avoid-single-DES-enctypes.patch | 11 +- ...d-version-of-OpenSSL-3-KDF-interface.patch | 218 +++++++++--------- Use-secure_getenv-where-appropriate.patch | 18 +- krb5.spec | 9 +- 15 files changed, 774 insertions(+), 414 deletions(-) create mode 100644 Allow-client-canonicalization-in-non-krbtgt-AS-REP.patch create mode 100644 Do-not-always-canonicalize-enterprise-principals.patch create mode 100644 Don-t-warn-in-kadmin-when-no-policy-is-specified.patch diff --git a/Allow-client-canonicalization-in-non-krbtgt-AS-REP.patch b/Allow-client-canonicalization-in-non-krbtgt-AS-REP.patch new file mode 100644 index 0000000..4402203 --- /dev/null +++ b/Allow-client-canonicalization-in-non-krbtgt-AS-REP.patch @@ -0,0 +1,64 @@ +From 0bbb2104fd6c494552c9261137fac782941b6440 Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Tue, 15 Oct 2019 20:41:49 +0300 +Subject: [PATCH] Allow client canonicalization in non-krbtgt AS-REP + +If a caller makes an AS-REQ with the canonicalize flag set (or with an +enterprise client principal or the anonymous flag), always allow the +KDC to change the client principal. Continue to restrict server name +changes to requests for TGS principals. + +Also remove the conditional for setting canon_ok for fully anonymous +requests. Both kinds of anonymous requests change the client +principal or realm, but neither kind changes the server principal or +realm, so this logic is no longer needed now that canon_ok only +applies to server name changes. + +[ghudson@mit.edu: clarified commit message; removed anonymous PKINIT +clause] + +ticket: 8843 (new) +(cherry picked from commit c6c19b1d35c6523cb7ed220c1f2e97e12e039293) +--- + src/lib/krb5/krb/get_in_tkt.c | 9 ++------- + src/tests/t_kdb.py | 3 +++ + 2 files changed, 5 insertions(+), 7 deletions(-) + +diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c +index 79dede2c6..9ee605888 100644 +--- a/src/lib/krb5/krb/get_in_tkt.c ++++ b/src/lib/krb5/krb/get_in_tkt.c +@@ -230,17 +230,12 @@ verify_as_reply(krb5_context context, + if (canon_req) { + canon_ok = IS_TGS_PRINC(request->server) && + IS_TGS_PRINC(as_reply->enc_part2->server); +- if (!canon_ok && (request->kdc_options & KDC_OPT_REQUEST_ANONYMOUS)) { +- canon_ok = krb5_principal_compare_any_realm(context, +- as_reply->client, +- krb5_anonymous_principal()); +- } + } else + canon_ok = 0; + + if ((!canon_ok && +- (!krb5_principal_compare(context, as_reply->client, request->client) || +- !krb5_principal_compare(context, as_reply->enc_part2->server, request->server))) ++ !krb5_principal_compare(context, as_reply->enc_part2->server, request->server)) ++ || (!canon_req && !krb5_principal_compare(context, as_reply->client, request->client)) + || !krb5_principal_compare(context, as_reply->enc_part2->server, as_reply->ticket->server) + || (request->nonce != as_reply->enc_part2->nonce) + /* XXX check for extraneous flags */ +diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py +index 7a082a5b9..cc5d2fc3c 100755 +--- a/src/tests/t_kdb.py ++++ b/src/tests/t_kdb.py +@@ -389,6 +389,9 @@ realm.run([kadminl, 'modprinc', '+requires_preauth', 'canon']) + realm.kinit('canon', password('canon')) + realm.kinit('alias', password('canon'), ['-C']) + ++# Test client name canonicalization in non-krbtgt AS reply ++realm.kinit('alias', password('canon'), ['-C', '-S', 'kadmin/changepw']) ++ + mark('LDAP password history') + + # Test password history. diff --git a/Clear-forwardable-flag-instead-of-denying-request.patch b/Clear-forwardable-flag-instead-of-denying-request.patch index fd8a240..88e3641 100644 --- a/Clear-forwardable-flag-instead-of-denying-request.patch +++ b/Clear-forwardable-flag-instead-of-denying-request.patch @@ -14,14 +14,14 @@ ticket: 7871 (cherry picked from commit 08e948cce2c79a3604066fcf7a64fc527456f83d) --- src/kdc/do_as_req.c | 19 ++------ - src/kdc/do_tgs_req.c | 58 +++++----------------- + src/kdc/do_tgs_req.c | 56 ++++----------------- src/kdc/kdc_util.c | 82 ++++++++++++++++++------------- src/kdc/kdc_util.h | 9 ++-- src/kdc/tgs_policy.c | 8 +-- src/tests/Makefile.in | 1 + src/tests/gcred.c | 28 ++++++++--- src/tests/t_kdcoptions.py | 100 ++++++++++++++++++++++++++++++++++++++ - 8 files changed, 190 insertions(+), 115 deletions(-) + 8 files changed, 189 insertions(+), 114 deletions(-) create mode 100644 src/tests/t_kdcoptions.py diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c @@ -146,10 +146,9 @@ index 587342a6c..1da099318 100644 - if (isflagset(request->kdc_options, KDC_OPT_REQUEST_ANONYMOUS) && - !isflagset(header_enc_tkt->flags, TKT_FLG_ANONYMOUS)) - clear(enc_tkt_reply.flags, TKT_FLG_ANONYMOUS); -- + - if (isflagset(request->kdc_options, KDC_OPT_POSTDATED)) { - setflag(enc_tkt_reply.flags, TKT_FLG_INVALID); -+ + if (isflagset(request->kdc_options, KDC_OPT_POSTDATED)) enc_tkt_reply.times.starttime = request->from; - } else diff --git a/Do-not-always-canonicalize-enterprise-principals.patch b/Do-not-always-canonicalize-enterprise-principals.patch new file mode 100644 index 0000000..fcaed36 --- /dev/null +++ b/Do-not-always-canonicalize-enterprise-principals.patch @@ -0,0 +1,113 @@ +From f1890cb3b09789e62c6711d79b032a7af0a09ea8 Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Sat, 2 Nov 2019 13:32:32 +0100 +Subject: [PATCH] Do not always canonicalize enterprise principals + +When processing an AS request in the KDC, do not assume +KRB5_KDB_FLAG_CANONICALIZE for enterprise client names. This change +allows the KDB module to only canonicalize enterprise client names if +the canonicalize flag was set on the request, as Windows does. The +KDB module may check the principal type and apply canonicalization as +appropriate. + +[ghudson@mit.edu: edited comments; rewrote commit message] + +ticket: 8858 (new) +(cherry picked from commit 3f5955631a2056f8ec4d1ce73d9681fa7da061c2) +--- + src/include/kdb.h | 21 ++++++++++++--------- + src/kdc/do_as_req.c | 9 ++++----- + src/tests/t_kdb.py | 12 ++++++++++++ + 3 files changed, 28 insertions(+), 14 deletions(-) + +diff --git a/src/include/kdb.h b/src/include/kdb.h +index 7749cfc99..1dd37cdab 100644 +--- a/src/include/kdb.h ++++ b/src/include/kdb.h +@@ -1023,15 +1023,18 @@ typedef struct _kdb_vftabl { + * in-realm alias, fill in a different value for entries->princ than the + * one requested. + * +- * A module can return out-of-realm referrals if KRB5_KDB_FLAG_CANONICALIZE +- * is set. For AS request clients (KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY is +- * also set), the module should do so by simply filling in an out-of-realm +- * name in entries->princ and setting all other fields to NULL. Otherwise, +- * the module should return the entry for the cross-realm TGS of the +- * referred-to realm. For TGS referals, the module can also include +- * tl-data of type KRB5_TL_SERVER_REFERRAL containing ASN.1-encoded Windows +- * referral data as documented in draft-ietf-krb-wg-kerberos-referrals-11 +- * appendix A; this will be returned to the client as encrypted padata. ++ * A module can return a referral to another realm if ++ * KRB5_KDB_FLAG_CANONICALIZE is set, or if ++ * KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY is set and search_for->type is ++ * KRB5_NT_ENTERPRISE_PRINCIPAL. If KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY is ++ * set, the module should return a referral by simply filling in an ++ * out-of-realm name in (*entry)->princ and setting all other fields to ++ * NULL. Otherwise, the module should return the entry for the cross-realm ++ * TGS of the referred-to realm. For TGS referals, the module can also ++ * include tl-data of type KRB5_TL_SERVER_REFERRAL containing ASN.1-encoded ++ * Windows referral data as documented in ++ * draft-ietf-krb-wg-kerberos-referrals-11 appendix A; this will be ++ * returned to the client as encrypted padata. + */ + krb5_error_code (*get_principal)(krb5_context kcontext, + krb5_const_principal search_for, +diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c +index 8a96c12a9..02c0a8a1f 100644 +--- a/src/kdc/do_as_req.c ++++ b/src/kdc/do_as_req.c +@@ -585,15 +585,14 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, + * of cross realm TGS entries. + */ + setflag(state->c_flags, KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY); +- /* +- * Note that according to the referrals draft we should +- * always canonicalize enterprise principal names. +- */ ++ /* Enterprise principals are implicitly alias-ok. */ + if (isflagset(state->request->kdc_options, KDC_OPT_CANONICALIZE) || + state->request->client->type == KRB5_NT_ENTERPRISE_PRINCIPAL) { +- setflag(state->c_flags, KRB5_KDB_FLAG_CANONICALIZE); + setflag(state->c_flags, KRB5_KDB_FLAG_ALIAS_OK); + } ++ if (isflagset(state->request->kdc_options, KDC_OPT_CANONICALIZE)) { ++ setflag(state->c_flags, KRB5_KDB_FLAG_CANONICALIZE); ++ } + if (include_pac_p(kdc_context, state->request)) { + setflag(state->c_flags, KRB5_KDB_FLAG_INCLUDE_PAC); + } +diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py +index cc5d2fc3c..7271fcbbd 100755 +--- a/src/tests/t_kdb.py ++++ b/src/tests/t_kdb.py +@@ -340,11 +340,14 @@ ldap_modify('dn: krbPrincipalName=canon@KRBTEST.COM,cn=t1,cn=krb5\n' + 'changetype: modify\n' + 'add: krbPrincipalName\n' + 'krbPrincipalName: alias@KRBTEST.COM\n' ++ 'krbPrincipalName: ent@abc@KRBTEST.COM\n' + '-\n' + 'add: krbCanonicalName\n' + 'krbCanonicalName: canon@KRBTEST.COM\n') + realm.run([kadminl, 'getprinc', 'alias'], + expected_msg='Principal: canon@KRBTEST.COM\n') ++realm.run([kadminl, 'getprinc', 'ent\@abc'], ++ expected_msg='Principal: canon@KRBTEST.COM\n') + realm.run([kadminl, 'getprinc', 'canon'], + expected_msg='Principal: canon@KRBTEST.COM\n') + realm.run([kvno, 'alias', 'canon']) +@@ -389,6 +392,15 @@ realm.run([kadminl, 'modprinc', '+requires_preauth', 'canon']) + realm.kinit('canon', password('canon')) + realm.kinit('alias', password('canon'), ['-C']) + ++# Test enterprise alias with and without canonicalization. ++realm.kinit('ent@abc', password('canon'), ['-E', '-C']) ++realm.run([kvno, 'alias']) ++realm.klist('canon@KRBTEST.COM', 'alias@KRBTEST.COM') ++ ++realm.kinit('ent@abc', password('canon'), ['-E']) ++realm.run([kvno, 'alias']) ++realm.klist('ent\@abc@KRBTEST.COM', 'alias@KRBTEST.COM') ++ + # Test client name canonicalization in non-krbtgt AS reply + realm.kinit('alias', password('canon'), ['-C', '-S', 'kadmin/changepw']) + diff --git a/Don-t-warn-in-kadmin-when-no-policy-is-specified.patch b/Don-t-warn-in-kadmin-when-no-policy-is-specified.patch new file mode 100644 index 0000000..220c59f --- /dev/null +++ b/Don-t-warn-in-kadmin-when-no-policy-is-specified.patch @@ -0,0 +1,160 @@ +From aec16ed11477f08f477f915fb8119271d688711c Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 19 Dec 2019 17:49:05 -0500 +Subject: [PATCH] Don't warn in kadmin when no policy is specified + +Not having policy defined is a normal occurrence. While it's a useful +message to log in case it's unexpected, the current form is +unnecessarily alarmist. + +ticket: 8857 (new) +(cherry picked from commit 2ca842d5cbd5981ab5fa50e418359763c9f1a6d5) +--- + doc/admin/admin_commands/kadmin_local.rst | 2 +- + doc/admin/database.rst | 4 ++-- + doc/admin/install_kdc.rst | 6 +++--- + src/kadmin/cli/kadmin.c | 4 ++-- + src/man/kadmin.man | 2 +- + src/po/de.po | 8 ++++---- + src/po/mit-krb5.pot | 4 ++-- + 7 files changed, 15 insertions(+), 15 deletions(-) + +diff --git a/doc/admin/admin_commands/kadmin_local.rst b/doc/admin/admin_commands/kadmin_local.rst +index 71aa894f6..fafa61365 100644 +--- a/doc/admin/admin_commands/kadmin_local.rst ++++ b/doc/admin/admin_commands/kadmin_local.rst +@@ -419,7 +419,7 @@ Options: + Example:: + + kadmin: addprinc jennifer +- WARNING: no policy specified for "jennifer@ATHENA.MIT.EDU"; ++ No policy specified for "jennifer@ATHENA.MIT.EDU"; + defaulting to no policy. + Enter password for principal jennifer@ATHENA.MIT.EDU: + Re-enter password for principal jennifer@ATHENA.MIT.EDU: +diff --git a/doc/admin/database.rst b/doc/admin/database.rst +index cea60b009..8505fe1ec 100644 +--- a/doc/admin/database.rst ++++ b/doc/admin/database.rst +@@ -103,7 +103,7 @@ If you want to create a principal which is contained by a LDAP object, + all you need to do is:: + + kadmin: addprinc -x dn=cn=jennifer,dc=example,dc=com jennifer +- WARNING: no policy specified for "jennifer@ATHENA.MIT.EDU"; ++ No policy specified for "jennifer@ATHENA.MIT.EDU"; + defaulting to no policy. + Enter password for principal jennifer@ATHENA.MIT.EDU: <= Type the password. + Re-enter password for principal jennifer@ATHENA.MIT.EDU: <=Type it again. +@@ -114,7 +114,7 @@ If you want to create a principal under a specific LDAP container and + link to an existing LDAP object, all you need to do is:: + + kadmin: addprinc -x containerdn=dc=example,dc=com -x linkdn=cn=david,dc=example,dc=com david +- WARNING: no policy specified for "david@ATHENA.MIT.EDU"; ++ No policy specified for "david@ATHENA.MIT.EDU"; + defaulting to no policy. + Enter password for principal david@ATHENA.MIT.EDU: <= Type the password. + Re-enter password for principal david@ATHENA.MIT.EDU: <=Type it again. +diff --git a/doc/admin/install_kdc.rst b/doc/admin/install_kdc.rst +index 3bec59f96..157c6059e 100644 +--- a/doc/admin/install_kdc.rst ++++ b/doc/admin/install_kdc.rst +@@ -239,7 +239,7 @@ is created:: + + kadmin.local: addprinc admin/admin@ATHENA.MIT.EDU + +- WARNING: no policy specified for "admin/admin@ATHENA.MIT.EDU"; ++ No policy specified for "admin/admin@ATHENA.MIT.EDU"; + assigning "default". + Enter password for principal admin/admin@ATHENA.MIT.EDU: <= Enter a password. + Re-enter password for principal admin/admin@ATHENA.MIT.EDU: <= Type it again. +@@ -316,11 +316,11 @@ following:: + + shell% kadmin + kadmin: addprinc -randkey host/kerberos.mit.edu +- NOTICE: no policy specified for "host/kerberos.mit.edu@ATHENA.MIT.EDU"; assigning "default" ++ No policy specified for "host/kerberos.mit.edu@ATHENA.MIT.EDU"; assigning "default" + Principal "host/kerberos.mit.edu@ATHENA.MIT.EDU" created. + + kadmin: addprinc -randkey host/kerberos-1.mit.edu +- NOTICE: no policy specified for "host/kerberos-1.mit.edu@ATHENA.MIT.EDU"; assigning "default" ++ No policy specified for "host/kerberos-1.mit.edu@ATHENA.MIT.EDU"; assigning "default" + Principal "host/kerberos-1.mit.edu@ATHENA.MIT.EDU" created. + + It is not strictly necessary to have the master KDC server in the +diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c +index b4d1aad93..a6e858d82 100644 +--- a/src/kadmin/cli/kadmin.c ++++ b/src/kadmin/cli/kadmin.c +@@ -1229,13 +1229,13 @@ kadmin_addprinc(int argc, char *argv[]) + /* If the policy "default" exists, assign it. */ + if (policy_exists("default")) { + if (!script_mode) { +- fprintf(stderr, _("NOTICE: no policy specified for %s; " ++ fprintf(stderr, _("No policy specified for %s; " + "assigning \"default\"\n"), canon); + } + princ.policy = "default"; + mask |= KADM5_POLICY; + } else if (!script_mode) { +- fprintf(stderr, _("WARNING: no policy specified for %s; " ++ fprintf(stderr, _("No policy specified for %s; " + "defaulting to no policy\n"), canon); + } + } +diff --git a/src/man/kadmin.man b/src/man/kadmin.man +index 44859a378..b514fe279 100644 +--- a/src/man/kadmin.man ++++ b/src/man/kadmin.man +@@ -458,7 +458,7 @@ Example: + .nf + .ft C + kadmin: addprinc jennifer +-WARNING: no policy specified for "jennifer@ATHENA.MIT.EDU"; ++No policy specified for "jennifer@ATHENA.MIT.EDU"; + defaulting to no policy. + Enter password for principal jennifer@ATHENA.MIT.EDU: + Re\-enter password for principal jennifer@ATHENA.MIT.EDU: +diff --git a/src/po/de.po b/src/po/de.po +index 40e31da90..5d78bdded 100644 +--- a/src/po/de.po ++++ b/src/po/de.po +@@ -1690,16 +1690,16 @@ msgstr "WARNUNG: Richtlinie »%s« existiert nicht.\n" + + #: ../../src/kadmin/cli/kadmin.c:1230 + #, c-format +-msgid "NOTICE: no policy specified for %s; assigning \"default\"\n" ++msgid "No policy specified for %s; assigning \"default\"\n" + msgstr "" +-"HINWEIS: Für %s wurde keine Richtlinie angegeben, es wird »default« " ++"Für %s wurde keine Richtlinie angegeben, es wird »default« " + "zugewiesen\n" + + #: ../../src/kadmin/cli/kadmin.c:1235 + #, c-format +-msgid "WARNING: no policy specified for %s; defaulting to no policy\n" ++msgid "No policy specified for %s; defaulting to no policy\n" + msgstr "" +-"WARNUNG: Für %s wurde keine Richtlinie angegeben, es wird die Vorgabe " ++"Für %s wurde keine Richtlinie angegeben, es wird die Vorgabe " + "»keine\n" + "Richtlinie« verwandt.\n" + +diff --git a/src/po/mit-krb5.pot b/src/po/mit-krb5.pot +index 8cfbe9f3c..de1998d2f 100644 +--- a/src/po/mit-krb5.pot ++++ b/src/po/mit-krb5.pot +@@ -1645,12 +1645,12 @@ msgstr "" + + #: ../../src/kadmin/cli/kadmin.c:1228 + #, c-format +-msgid "NOTICE: no policy specified for %s; assigning \"default\"\n" ++msgid "No policy specified for %s; assigning \"default\"\n" + msgstr "" + + #: ../../src/kadmin/cli/kadmin.c:1234 + #, c-format +-msgid "WARNING: no policy specified for %s; defaulting to no policy\n" ++msgid "No policy specified for %s; defaulting to no policy\n" + msgstr "" + + #: ../../src/kadmin/cli/kadmin.c:1276 diff --git a/Implement-krb5_cc_remove_cred-for-remaining-types.patch b/Implement-krb5_cc_remove_cred-for-remaining-types.patch index 23f9965..65ddcf7 100644 --- a/Implement-krb5_cc_remove_cred-for-remaining-types.patch +++ b/Implement-krb5_cc_remove_cred-for-remaining-types.patch @@ -266,25 +266,13 @@ index 8419f6ebf..98723fe2e 100644 - * with the time offsets, skip it. */ - while (krcursor->keys[krcursor->currkey] == krcursor->princ_id || - krcursor->keys[krcursor->currkey] == krcursor->offsets_id) { -- krcursor->currkey++; -- /* Check if we have now reached the end */ -- if (krcursor->currkey >= krcursor->numkeys) -- return KRB5_CC_END; -- } + /* Read the key; the right size buffer will be allocated and + * returned. */ + psize = keyctl_read_alloc(krcursor->keys[krcursor->currkey], + &payload); + if (psize != -1) { + krcursor->currkey++; - -- /* Read the key; the right size buffer will be allocated and returned. */ -- psize = keyctl_read_alloc(krcursor->keys[krcursor->currkey], &payload); -- if (psize == -1) { -- DEBUG_PRINT(("Error reading key %d: %s\n", -- krcursor->keys[krcursor->currkey], -- strerror(errno))); -- return KRB5_FCC_NOFILE; ++ + /* Unmarshal the cred using the file ccache version 4 format. */ + ret = k5_unmarshal_cred(payload, psize, 4, creds); + free(payload); @@ -297,10 +285,22 @@ index 8419f6ebf..98723fe2e 100644 + + /* The current key was unlinked, probably by a remove_cred call; move + * on to the next one. */ -+ krcursor->currkey++; + krcursor->currkey++; +- /* Check if we have now reached the end */ +- if (krcursor->currkey >= krcursor->numkeys) +- return KRB5_CC_END; } -- krcursor->currkey++; +- /* Read the key; the right size buffer will be allocated and returned. */ +- psize = keyctl_read_alloc(krcursor->keys[krcursor->currkey], &payload); +- if (psize == -1) { +- DEBUG_PRINT(("Error reading key %d: %s\n", +- krcursor->keys[krcursor->currkey], +- strerror(errno))); +- return KRB5_FCC_NOFILE; +- } +- krcursor->currkey++; +- - /* Unmarshal the credential using the file ccache version 4 format. */ - ret = k5_unmarshal_cred(payload, psize, 4, creds); - free(payload); diff --git a/Make-etype-names-in-KDC-logs-human-readable.patch b/Make-etype-names-in-KDC-logs-human-readable.patch index 462de34..451e554 100644 --- a/Make-etype-names-in-KDC-logs-human-readable.patch +++ b/Make-etype-names-in-KDC-logs-human-readable.patch @@ -12,9 +12,9 @@ ticket: 8772 (new) (cherry picked from commit a649279727490687d54becad91fde8cf7429d951) --- src/kdc/kdc_log.c | 42 +++++++-------- - src/kdc/kdc_util.c | 125 +++++++++++++++++++++++---------------------- + src/kdc/kdc_util.c | 131 +++++++++++++++++++++++---------------------- src/kdc/kdc_util.h | 6 +-- - 3 files changed, 87 insertions(+), 86 deletions(-) + 3 files changed, 90 insertions(+), 89 deletions(-) diff --git a/src/kdc/kdc_log.c b/src/kdc/kdc_log.c index 4eec50373..b160ba21a 100644 @@ -132,16 +132,57 @@ index 0155c28c6..f5c581c82 100644 - * L10_2 = log10(2**x), rounded up; log10(2) ~= 0.301. - */ -#define L10_2(x) ((int)(((x * 301) + 999) / 1000)) +- +-/* +- * Max length of sprintf("%ld") for an int of type T; includes leading +- * minus sign and terminating NUL. +- */ +-#define D_LEN(t) (L10_2(sizeof(t) * CHAR_BIT) + 2) +- +-void +-ktypes2str(char *s, size_t len, int nktypes, krb5_enctype *ktype) +/* Wrapper of krb5_enctype_to_name() to include the PKINIT types. */ +static krb5_error_code +enctype_name(krb5_enctype ktype, char *buf, size_t buflen) -+{ + { +- int i; +- char stmp[D_LEN(krb5_enctype) + 1]; +- char *p; + char *name; -+ + +- if (nktypes < 0 +- || len < (sizeof(" etypes {...}") + D_LEN(int))) { +- *s = '\0'; +- return; +- } + if (buflen == 0) + return EINVAL; + *buf = '\0'; /* ensure these are always valid C-strings */ -+ + +- snprintf(s, len, "%d etypes {", nktypes); +- for (i = 0; i < nktypes; i++) { +- snprintf(stmp, sizeof(stmp), "%s%ld", i ? " " : "", (long)ktype[i]); +- if (strlen(s) + strlen(stmp) + sizeof("}") > len) +- break; +- strlcat(s, stmp, len); +- } +- if (i < nktypes) { +- /* +- * We broke out of the loop. Try to truncate the list. +- */ +- p = s + strlen(s); +- while (p - s + sizeof("...}") > len) { +- while (p > s && *p != ' ' && *p != '{') +- *p-- = '\0'; +- if (p > s && *p == ' ') { +- *p-- = '\0'; +- continue; +- } +- } +- strlcat(s, "...", len); +- } +- strlcat(s, "}", len); +- return; + /* rfc4556 recommends that clients wishing to indicate support for these + * pkinit algorithms include them in the etype field of the AS-REQ. */ + if (ktype == ENCTYPE_DSA_SHA1_CMS) @@ -160,85 +201,47 @@ index 0155c28c6..f5c581c82 100644 + name = "des-ede3-cbc-EnvOID"; + else + return krb5_enctype_to_name(ktype, FALSE, buf, buflen); - --/* -- * Max length of sprintf("%ld") for an int of type T; includes leading -- * minus sign and terminating NUL. -- */ --#define D_LEN(t) (L10_2(sizeof(t) * CHAR_BIT) + 2) ++ + if (strlcpy(name, buf, buflen) >= buflen) + return ENOMEM; + return 0; -+} - --void --ktypes2str(char *s, size_t len, int nktypes, krb5_enctype *ktype) -+char * -+ktypes2str(krb5_enctype *ktype, int nktypes) - { -+ struct k5buf buf; - int i; -- char stmp[D_LEN(krb5_enctype) + 1]; -- char *p; -+ char name[64]; - -- if (nktypes < 0 -- || len < (sizeof(" etypes {...}") + D_LEN(int))) { -- *s = '\0'; -- return; -- } -+ if (nktypes < 0) -+ return NULL; - -- snprintf(s, len, "%d etypes {", nktypes); -+ k5_buf_init_dynamic(&buf); -+ k5_buf_add_fmt(&buf, "%d etypes {", nktypes); - for (i = 0; i < nktypes; i++) { -- snprintf(stmp, sizeof(stmp), "%s%ld", i ? " " : "", (long)ktype[i]); -- if (strlen(s) + strlen(stmp) + sizeof("}") > len) -- break; -- strlcat(s, stmp, len); -+ enctype_name(ktype[i], name, sizeof(name)); -+ k5_buf_add_fmt(&buf, "%s%s(%ld)", i ? ", " : "", name, (long)ktype[i]); - } -- if (i < nktypes) { -- /* -- * We broke out of the loop. Try to truncate the list. -- */ -- p = s + strlen(s); -- while (p - s + sizeof("...}") > len) { -- while (p > s && *p != ' ' && *p != '{') -- *p-- = '\0'; -- if (p > s && *p == ' ') { -- *p-- = '\0'; -- continue; -- } -- } -- strlcat(s, "...", len); -- } -- strlcat(s, "}", len); -- return; -+ k5_buf_add(&buf, "}"); -+ return buf.data; } -void -rep_etypes2str(char *s, size_t len, krb5_kdc_rep *rep) +char * -+rep_etypes2str(krb5_kdc_rep *rep) ++ktypes2str(krb5_enctype *ktype, int nktypes) { - char stmp[sizeof("ses=") + D_LEN(krb5_enctype)]; -- ++ struct k5buf buf; ++ int i; ++ char name[64]; + - if (len < (3 * D_LEN(krb5_enctype) - + sizeof("etypes {rep= tkt= ses=}"))) { - *s = '\0'; - return; -- } ++ if (nktypes < 0) ++ return NULL; ++ ++ k5_buf_init_dynamic(&buf); ++ k5_buf_add_fmt(&buf, "%d etypes {", nktypes); ++ for (i = 0; i < nktypes; i++) { ++ enctype_name(ktype[i], name, sizeof(name)); ++ k5_buf_add_fmt(&buf, "%s%s(%ld)", i ? ", " : "", name, (long)ktype[i]); + } ++ k5_buf_add(&buf, "}"); ++ return buf.data; ++} + +- snprintf(s, len, "etypes {rep=%ld", (long)rep->enc_part.enctype); ++char * ++rep_etypes2str(krb5_kdc_rep *rep) ++{ + struct k5buf buf; + char name[64]; + krb5_enctype etype; - -- snprintf(s, len, "etypes {rep=%ld", (long)rep->enc_part.enctype); ++ + k5_buf_init_dynamic(&buf); + k5_buf_add(&buf, "etypes {rep="); + enctype_name(rep->enc_part.enctype, name, sizeof(name)); diff --git a/Remove-3des-support.patch b/Remove-3des-support.patch index b3d12d0..dd68008 100644 --- a/Remove-3des-support.patch +++ b/Remove-3des-support.patch @@ -76,7 +76,7 @@ their constants. src/lib/gssapi/krb5/gssapiP_krb5.h | 6 +- src/lib/gssapi/krb5/k5seal.c | 35 +- src/lib/gssapi/krb5/k5sealiov.c | 27 +- - src/lib/gssapi/krb5/k5unseal.c | 88 ++-- + src/lib/gssapi/krb5/k5unseal.c | 102 ++--- src/lib/gssapi/krb5/k5unsealiov.c | 38 +- src/lib/gssapi/krb5/util_crypt.c | 11 - .../api.current/chpass-principal-v2.exp | 4 +- @@ -107,7 +107,7 @@ their constants. src/tests/t_salt.py | 5 +- src/util/k5test.py | 10 - .../leash/htmlhelp/html/Encryption_Types.htm | 13 - - 96 files changed, 157 insertions(+), 4831 deletions(-) + 96 files changed, 164 insertions(+), 4838 deletions(-) delete mode 100644 src/lib/crypto/builtin/des/ISSUES delete mode 100644 src/lib/crypto/builtin/des/Makefile.in delete mode 100644 src/lib/crypto/builtin/des/d3_aead.c @@ -5401,15 +5401,13 @@ index 9b183bc33..f0cc4a680 100644 + if (signalg != SGN_ALG_HMAC_MD5) { *minor_status = 0; return(GSS_S_DEFECTIVE_TOKEN); -+ } - +- - case SGN_ALG_HMAC_SHA1_DES3_KD: - case SGN_ALG_HMAC_MD5: - /* compute the checksum of the message */ - - /* 8 = bytes of token body to be checksummed according to spec */ -+ /* compute the checksum of the message */ - +- - if (! (data_ptr = xmalloc(8 + plainlen))) { - if (sealalg != 0xffff) - xfree(plain); @@ -5418,9 +5416,33 @@ index 9b183bc33..f0cc4a680 100644 - *minor_status = ENOMEM; - return(GSS_S_FAILURE); - } -+ /* 8 = bytes of token body to be checksummed according to spec */ - +- - (void) memcpy(data_ptr, ptr-2, 8); +- +- (void) memcpy(data_ptr+8, plain, plainlen); +- +- plaind.length = 8 + plainlen; +- plaind.data = data_ptr; +- code = krb5_k_make_checksum(context, md5cksum.checksum_type, +- ctx->seq, sign_usage, +- &plaind, &md5cksum); +- xfree(data_ptr); +- +- if (code) { +- if (toktype == KG_TOK_SEAL_MSG) +- gssalloc_free(token.value); +- *minor_status = code; +- return(GSS_S_FAILURE); +- } +- +- code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); +- break; + } + ++ /* compute the checksum of the message */ ++ ++ /* 8 = bytes of token body to be checksummed according to spec */ ++ + if (! (data_ptr = xmalloc(8 + plainlen))) { + if (sealalg != 0xffff) + xfree(plain); @@ -5429,40 +5451,25 @@ index 9b183bc33..f0cc4a680 100644 + *minor_status = ENOMEM; + return(GSS_S_FAILURE); + } - -- (void) memcpy(data_ptr+8, plain, plainlen); ++ + (void) memcpy(data_ptr, ptr-2, 8); - -- plaind.length = 8 + plainlen; -- plaind.data = data_ptr; -- code = krb5_k_make_checksum(context, md5cksum.checksum_type, -- ctx->seq, sign_usage, -- &plaind, &md5cksum); -- xfree(data_ptr); ++ + (void) memcpy(data_ptr+8, plain, plainlen); - -- if (code) { -- if (toktype == KG_TOK_SEAL_MSG) -- gssalloc_free(token.value); -- *minor_status = code; -- return(GSS_S_FAILURE); -- } ++ + plaind.length = 8 + plainlen; + plaind.data = data_ptr; + code = krb5_k_make_checksum(context, md5cksum.checksum_type, + ctx->seq, sign_usage, + &plaind, &md5cksum); + xfree(data_ptr); - -- code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); -- break; ++ + if (code) { + if (toktype == KG_TOK_SEAL_MSG) + gssalloc_free(token.value); + *minor_status = code; + return(GSS_S_FAILURE); - } - ++ } ++ + code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); + krb5_free_checksum_contents(context, &md5cksum); diff --git a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch index 93dc484..09280f0 100644 --- a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch +++ b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch @@ -9,7 +9,7 @@ Subject: [PATCH] Remove Kerberos v4 support vestiges from ccapi src/ccapi/lib/ccapi_v2.c | 34 +-- src/ccapi/lib/win/OldCC/ccapi.h | 20 -- src/ccapi/server/ccs_ccache.c | 69 +----- - src/ccapi/test/test_ccapi_ccache.c | 227 +++----------------- + src/ccapi/test/test_ccapi_ccache.c | 223 +++----------------- src/ccapi/test/test_ccapi_constants.c | 2 - src/ccapi/test/test_ccapi_context.c | 3 - src/ccapi/test/test_ccapi_v2.c | 89 -------- @@ -20,7 +20,7 @@ Subject: [PATCH] Remove Kerberos v4 support vestiges from ccapi src/windows/kfwlogon/kfwlogon.h | 2 +- src/windows/leashdll/leash-int.h | 2 +- src/windows/lib/cacheapi.h | 53 +---- - 15 files changed, 100 insertions(+), 873 deletions(-) + 15 files changed, 98 insertions(+), 871 deletions(-) diff --git a/src/ccapi/common/cci_cred_union.c b/src/ccapi/common/cci_cred_union.c index 4c8981610..424a93dab 100644 @@ -760,8 +760,29 @@ index a0fd84af1..fe63e6710 100644 - cc_ccache_destroy(ccache); - ccache = NULL; - } -- -- ++ // replace v5 only ccache's principal ++ if (!err) { ++ err = cc_context_create_new_ccache(context, cc_credentials_v5, ++ "foo@BAZ.ORG", &ccache); ++ } ++ if (!err) { ++ check_once_cc_ccache_set_principal( ++ ccache, cc_credentials_v5, "foo/BAZ@BAR.ORG", ccNoError, ++ "replace v5 only ccache's principal (empty ccache)"); ++ } ++ else { ++ log_error( ++ "cc_context_create_new_ccache failed, can't complete test"); ++ failure_count++; ++ } + ++ // bad params ++ if (!err) { ++ check_once_cc_ccache_set_principal(ccache, cc_credentials_v5, ++ NULL, ccErrBadParam, ++ "NULL principal"); ++ } + - // empty ccache - - // replace v5 only ccache's principal @@ -837,29 +858,6 @@ index a0fd84af1..fe63e6710 100644 - // replace v4 only ccache's principal - - // add v5 principal to v4 only ccache -+ // replace v5 only ccache's principal -+ if (!err) { -+ err = cc_context_create_new_ccache(context, cc_credentials_v5, -+ "foo@BAZ.ORG", &ccache); -+ } -+ if (!err) { -+ check_once_cc_ccache_set_principal( -+ ccache, cc_credentials_v5, "foo/BAZ@BAR.ORG", ccNoError, -+ "replace v5 only ccache's principal (empty ccache)"); -+ } -+ else { -+ log_error( -+ "cc_context_create_new_ccache failed, can't complete test"); -+ failure_count++; -+ } -+ -+ // bad params -+ if (!err) { -+ check_once_cc_ccache_set_principal(ccache, cc_credentials_v5, -+ NULL, ccErrBadParam, -+ "NULL principal"); -+ } -+ + if (ccache) { + cc_ccache_destroy(ccache); + ccache = NULL; @@ -894,7 +892,8 @@ index a0fd84af1..fe63e6710 100644 } if (!err) { - check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v5, &time_offset, ccNoError, "offset set for v5 but not v4"); -- } ++ check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v5, &time_offset, ccNoError, "offset set for v5"); + } - if (!err) { - check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v4, &time_offset, ccErrTimeOffsetNotSet, "asking for v4 offset when only v5 is set"); - } @@ -903,10 +902,9 @@ index a0fd84af1..fe63e6710 100644 - } - if (!err) { - check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v4, &time_offset, ccNoError, "asking for v4 offset when v4 and v5 are set"); -+ check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v5, &time_offset, ccNoError, "offset set for v5"); - } - +- } - + check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v5, NULL, ccErrBadParam, "NULL time_offset out param"); - check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v4_v5, &time_offset, ccErrBadCredentialsVersion, "v4_v5 creds_vers in param (invalid)"); diff --git a/Remove-PKINIT-draft-9-support.patch b/Remove-PKINIT-draft-9-support.patch index 2ac0254..c5b45f2 100644 --- a/Remove-PKINIT-draft-9-support.patch +++ b/Remove-PKINIT-draft-9-support.patch @@ -15,12 +15,12 @@ ticket: 8817 (new) src/plugins/preauth/pkinit/pkinit_accessor.h | 6 - src/plugins/preauth/pkinit/pkinit_clnt.c | 231 +++----- src/plugins/preauth/pkinit/pkinit_crypto.h | 1 - - .../preauth/pkinit/pkinit_crypto_openssl.c | 221 ++------ + .../preauth/pkinit/pkinit_crypto_openssl.c | 219 ++----- src/plugins/preauth/pkinit/pkinit_lib.c | 65 --- - src/plugins/preauth/pkinit/pkinit_srv.c | 531 +++++------------- + src/plugins/preauth/pkinit/pkinit_srv.c | 543 ++++++------------ src/plugins/preauth/pkinit/pkinit_trace.h | 4 - src/tests/t_pkinit.py | 6 +- - 10 files changed, 277 insertions(+), 809 deletions(-) + 10 files changed, 282 insertions(+), 814 deletions(-) diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h index fe2ec0d31..b437fd53f 100644 @@ -214,7 +214,18 @@ index 58400d555..1a642139a 100644 - auth_pack.clientDHNonce.length = 0; - auth_pack.clientPublicValue = &info; - auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; -- ++ memset(&info, 0, sizeof(info)); ++ memset(&auth_pack, 0, sizeof(auth_pack)); ++ auth_pack.pkAuthenticator.ctime = ctsec; ++ auth_pack.pkAuthenticator.cusec = cusec; ++ auth_pack.pkAuthenticator.nonce = nonce; ++ auth_pack.pkAuthenticator.paChecksum = *cksum; ++ if (!reqctx->opts->disable_freshness) ++ auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token; ++ auth_pack.clientDHNonce.length = 0; ++ auth_pack.clientPublicValue = &info; ++ auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; + - /* add List of CMS algorithms */ - retval = create_krb5_supportedCMSTypes(context, plgctx->cryptoctx, - reqctx->cryptoctx, @@ -227,18 +238,6 @@ index 58400d555..1a642139a 100644 - pkiDebug("as_req: unrecognized pa_type = %d\n", - (int)reqctx->pa_type); - retval = -1; -+ memset(&info, 0, sizeof(info)); -+ memset(&auth_pack, 0, sizeof(auth_pack)); -+ auth_pack.pkAuthenticator.ctime = ctsec; -+ auth_pack.pkAuthenticator.cusec = cusec; -+ auth_pack.pkAuthenticator.nonce = nonce; -+ auth_pack.pkAuthenticator.paChecksum = *cksum; -+ if (!reqctx->opts->disable_freshness) -+ auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token; -+ auth_pack.clientDHNonce.length = 0; -+ auth_pack.clientPublicValue = &info; -+ auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; -+ + /* add List of CMS algorithms */ + retval = create_krb5_supportedCMSTypes(context, plgctx->cryptoctx, + reqctx->cryptoctx, @@ -356,19 +355,20 @@ index 58400d555..1a642139a 100644 - &req9->signedAuthPack.data, - &req9->signedAuthPack.length); - break; -+ &req->signedAuthPack.data, -+ &req->signedAuthPack.length); -+ } -+ - #ifdef DEBUG_ASN1 +-#ifdef DEBUG_ASN1 - print_buffer_bin((unsigned char *)req9->signedAuthPack.data, - req9->signedAuthPack.length, - "/tmp/client_signed_data_draft9"); +-#endif ++ &req->signedAuthPack.data, ++ &req->signedAuthPack.length); + } ++ ++#ifdef DEBUG_ASN1 + print_buffer_bin((unsigned char *)req->signedAuthPack.data, + req->signedAuthPack.length, + "/tmp/client_signed_data"); - #endif -- } ++#endif + krb5_free_data(context, coded_auth_pack); if (retval) { @@ -556,7 +556,13 @@ index 8aa2c5257..8c7fd0cca 100644 - goto cleanup2; - PKCS7_add_signed_attribute(p7si, NID_pkcs9_contentType, - V_ASN1_OBJECT, oid_copy); -- ++ /* create a content-type attr */ ++ oid_copy = OBJ_dup(oid); ++ if (oid_copy == NULL) ++ goto cleanup2; ++ PKCS7_add_signed_attribute(p7si, NID_pkcs9_contentType, ++ V_ASN1_OBJECT, oid_copy); + - /* create the signature over signed attributes. get DER encoded value */ - /* This is the place where smartcard signature needs to be calculated */ - sk = p7si->auth_attr; @@ -565,13 +571,6 @@ index 8aa2c5257..8c7fd0cca 100644 - if (abuf == NULL) - goto cleanup2; - } /* signed attributes */ -+ /* create a content-type attr */ -+ oid_copy = OBJ_dup(oid); -+ if (oid_copy == NULL) -+ goto cleanup2; -+ PKCS7_add_signed_attribute(p7si, NID_pkcs9_contentType, -+ V_ASN1_OBJECT, oid_copy); -+ + /* create the signature over signed attributes. get DER encoded value */ + /* This is the place where smartcard signature needs to be calculated */ + sk = p7si->auth_attr; @@ -1041,38 +1040,47 @@ index 6aa646cc6..c44be9c74 100644 if (retval) { TRACE_PKINIT_SERVER_PADATA_VERIFY_FAIL(context); goto cleanup; -@@ -541,117 +513,87 @@ pkinit_server_verify_padata(krb5_context context, +@@ -541,118 +513,88 @@ pkinit_server_verify_padata(krb5_context context, #endif OCTETDATA_TO_KRB5DATA(&authp_data, &k5data); - switch ((int)data->pa_type) { - case KRB5_PADATA_PK_AS_REQ: - retval = k5int_decode_krb5_auth_pack(&k5data, &auth_pack); -- if (retval) { -- pkiDebug("failed to decode krb5_auth_pack\n"); -- goto cleanup; -- } -- -- retval = krb5_check_clockskew(context, -- auth_pack->pkAuthenticator.ctime); -- if (retval) -- goto cleanup; + retval = k5int_decode_krb5_auth_pack(&k5data, &auth_pack); + if (retval) { + pkiDebug("failed to decode krb5_auth_pack\n"); + goto cleanup; + } - ++ ++ retval = krb5_check_clockskew(context, auth_pack->pkAuthenticator.ctime); ++ if (retval) ++ goto cleanup; ++ ++ /* check dh parameters */ ++ if (auth_pack->clientPublicValue != NULL) { ++ retval = server_check_dh(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, plgctx->idctx, ++ &auth_pack->clientPublicValue->algorithm.parameters, ++ plgctx->opts->dh_min_bits); + if (retval) { +- pkiDebug("failed to decode krb5_auth_pack\n"); ++ pkiDebug("bad dh parameters\n"); + goto cleanup; + } +- +- retval = krb5_check_clockskew(context, +- auth_pack->pkAuthenticator.ctime); +- if (retval) +- goto cleanup; +- - /* check dh parameters */ - if (auth_pack->clientPublicValue != NULL) { - retval = server_check_dh(context, plgctx->cryptoctx, - reqctx->cryptoctx, plgctx->idctx, - &auth_pack->clientPublicValue->algorithm.parameters, - plgctx->opts->dh_min_bits); -+ retval = krb5_check_clockskew(context, auth_pack->pkAuthenticator.ctime); -+ if (retval) -+ goto cleanup; - +- - if (retval) { - pkiDebug("bad dh parameters\n"); - goto cleanup; @@ -1088,17 +1096,10 @@ index 6aa646cc6..c44be9c74 100644 - der_req = cb->request_body(context, rock); - retval = krb5_c_make_checksum(context, CKSUMTYPE_NIST_SHA, NULL, - 0, der_req, &cksum); -+ /* check dh parameters */ -+ if (auth_pack->clientPublicValue != NULL) { -+ retval = server_check_dh(context, plgctx->cryptoctx, -+ reqctx->cryptoctx, plgctx->idctx, -+ &auth_pack->clientPublicValue->algorithm.parameters, -+ plgctx->opts->dh_min_bits); - if (retval) { +- if (retval) { - pkiDebug("unable to calculate AS REQ checksum\n"); -+ pkiDebug("bad dh parameters\n"); - goto cleanup; - } +- goto cleanup; +- } - if (cksum.length != auth_pack->pkAuthenticator.paChecksum.length || - k5_bcmp(cksum.contents, - auth_pack->pkAuthenticator.paChecksum.contents, @@ -1170,10 +1171,7 @@ index 6aa646cc6..c44be9c74 100644 - if (!valid_kdcPkId) - pkiDebug("kdcPkId in AS_REQ does not match KDC's cert" - "RFC says to ignore and proceed\n"); -+ retval = KRB5KDC_ERR_PA_CHECKSUM_MUST_BE_INCLUDED; -+ goto cleanup; -+ } - +- - } - /* remember the decoded auth_pack for verify_padata routine */ - reqctx->rcv_auth_pack = auth_pack; @@ -1184,24 +1182,35 @@ index 6aa646cc6..c44be9c74 100644 - retval = k5int_decode_krb5_auth_pack_draft9(&k5data, &auth_pack9); - if (retval) { - pkiDebug("failed to decode krb5_auth_pack_draft9\n"); -+ ftoken = auth_pack->pkAuthenticator.freshnessToken; -+ if (ftoken != NULL) { -+ retval = cb->check_freshness_token(context, rock, ftoken); -+ if (retval) - goto cleanup; +- goto cleanup; - } - if (auth_pack9->clientPublicValue != NULL) { - retval = server_check_dh(context, plgctx->cryptoctx, - reqctx->cryptoctx, plgctx->idctx, - &auth_pack9->clientPublicValue->algorithm.parameters, - plgctx->opts->dh_min_bits); -+ valid_freshness_token = TRUE; -+ } - +- - if (retval) { - pkiDebug("bad dh parameters\n"); - goto cleanup; - } +- } +- /* remember the decoded auth_pack for verify_padata routine */ +- reqctx->rcv_auth_pack9 = auth_pack9; +- auth_pack9 = NULL; +- break; ++ retval = KRB5KDC_ERR_PA_CHECKSUM_MUST_BE_INCLUDED; ++ goto cleanup; + } + ++ ftoken = auth_pack->pkAuthenticator.freshnessToken; ++ if (ftoken != NULL) { ++ retval = cb->check_freshness_token(context, rock, ftoken); ++ if (retval) ++ goto cleanup; ++ valid_freshness_token = TRUE; ++ } ++ + /* check if kdcPkId present and match KDC's subjectIdentifier */ + if (reqp->kdcPkId.data != NULL) { + int valid_kdcPkId = 0; @@ -1214,18 +1223,15 @@ index 6aa646cc6..c44be9c74 100644 + if (!valid_kdcPkId) { + pkiDebug("kdcPkId in AS_REQ does not match KDC's cert; " + "RFC says to ignore and proceed\n"); - } -- /* remember the decoded auth_pack for verify_padata routine */ -- reqctx->rcv_auth_pack9 = auth_pack9; -- auth_pack9 = NULL; -- break; - } ++ } ++ } + /* remember the decoded auth_pack for verify_padata routine */ + reqctx->rcv_auth_pack = auth_pack; + auth_pack = NULL; - ++ if (is_signed) { retval = check_log_freshness(context, plgctx, request, + valid_freshness_token); @@ -682,21 +624,13 @@ cleanup: pkiDebug("pkinit_create_edata failed\n"); } @@ -1414,7 +1420,7 @@ index 6aa646cc6..c44be9c74 100644 } - pkiDebug("%s: return checksum instead of nonce = %d\n", - __FUNCTION__, fixed_keypack); -- + - /* if this is an RFC reply or draft9 client requested a checksum - * in the reply instead of the nonce, create an RFC-style keypack - */ @@ -1424,7 +1430,7 @@ index 6aa646cc6..c44be9c74 100644 - retval = ENOMEM; - goto cleanup; - } - +- - retval = krb5_c_make_checksum(context, 0, - encrypting_key, KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, - req_pkt, &key_pack->asChecksum); diff --git a/Simplify-krb5_dbe_def_search_enctype.patch b/Simplify-krb5_dbe_def_search_enctype.patch index f98922e..aefeeed 100644 --- a/Simplify-krb5_dbe_def_search_enctype.patch +++ b/Simplify-krb5_dbe_def_search_enctype.patch @@ -16,8 +16,8 @@ kvno. (cherry picked from commit fcfb0e47c995a7e9f956c3716be3175f44ad26e0) --- - src/lib/kdb/kdb_default.c | 117 +++++++++++++++----------------------- - 1 file changed, 45 insertions(+), 72 deletions(-) + src/lib/kdb/kdb_default.c | 111 +++++++++++++++----------------------- + 1 file changed, 42 insertions(+), 69 deletions(-) diff --git a/src/lib/kdb/kdb_default.c b/src/lib/kdb/kdb_default.c index a1021f13a..231a0d8b4 100644 @@ -59,18 +59,27 @@ index a1021f13a..231a0d8b4 100644 - krb5_key_data *datap; - krb5_error_code ret; - krb5_boolean saw_non_permitted = FALSE; -- -- ret = 0; -- if (ktype != -1 && !krb5_is_permitted_enctype(kcontext, ktype)) -- return KRB5_KDB_NO_PERMITTED_KEY; -- -- if (kvno == -1 && stype == -1 && ktype == -1) -- kvno = 0; + krb5_key_data *kd; + krb5_int32 db_salttype; + krb5_boolean saw_non_permitted = FALSE; + int i; +- ret = 0; +- if (ktype != -1 && !krb5_is_permitted_enctype(kcontext, ktype)) ++ *kd_out = NULL; ++ ++ if (enctype != -1 && !krb5_is_permitted_enctype(context, enctype)) + return KRB5_KDB_NO_PERMITTED_KEY; ++ if (ent->n_key_data == 0) ++ return KRB5_KDB_NO_MATCHING_KEY; + +- if (kvno == -1 && stype == -1 && ktype == -1) +- kvno = 0; ++ /* Match the highest kvno if kvno is 0. Key data is sorted in descending ++ * order of kvno. */ ++ if (kvno == 0) ++ kvno = ent->key_data[0].key_data_kvno; + - if (kvno == 0) { - /* Get the max key version */ - for (i = 0; i < dbentp->n_key_data; i++) { @@ -79,7 +88,10 @@ index a1021f13a..231a0d8b4 100644 - } - } - } -+ *kd_out = NULL; ++ for (i = *start; i < ent->n_key_data; i++) { ++ kd = &ent->key_data[i]; ++ db_salttype = (kd->key_data_ver > 1) ? kd->key_data_type[1] : ++ KRB5_KDB_SALTTYPE_NORMAL; - maxkvno = -1; - idx = -1; @@ -104,28 +116,13 @@ index a1021f13a..231a0d8b4 100644 - continue; - } - if (stype >= 0 && db_stype != stype) -+ if (enctype != -1 && !krb5_is_permitted_enctype(context, enctype)) -+ return KRB5_KDB_NO_PERMITTED_KEY; -+ if (ent->n_key_data == 0) -+ return KRB5_KDB_NO_MATCHING_KEY; -+ -+ /* Match the highest kvno if kvno is 0. Key data is sorted in descending -+ * order of kvno. */ -+ if (kvno == 0) -+ kvno = ent->key_data[0].key_data_kvno; -+ -+ for (i = *start; i < ent->n_key_data; i++) { -+ kd = &ent->key_data[i]; -+ db_salttype = (kd->key_data_ver > 1) ? kd->key_data_type[1] : -+ KRB5_KDB_SALTTYPE_NORMAL; -+ + /* Match this entry against the arguments. Stop searching if we have + * passed the entries for the requested kvno. */ + if (enctype != -1 && kd->key_data_type[0] != enctype) -+ continue; -+ if (salttype >= 0 && db_salttype != salttype) continue; - if (kvno >= 0 && dbentp->key_data[i].key_data_kvno != kvno) ++ if (salttype >= 0 && db_salttype != salttype) ++ continue; + if (kvno >= 0 && kd->key_data_kvno < kvno) + break; + if (kvno >= 0 && kd->key_data_kvno != kvno) diff --git a/Simply-OpenSSL-PKCS7-decryption-code.patch b/Simply-OpenSSL-PKCS7-decryption-code.patch index 35f9e28..4190846 100644 --- a/Simply-OpenSSL-PKCS7-decryption-code.patch +++ b/Simply-OpenSSL-PKCS7-decryption-code.patch @@ -11,8 +11,8 @@ a larger refactoring] (cherry picked from commit 210356653a2f963ffe9a8a1b1627c64fb8ca7a3d) --- - .../preauth/pkinit/pkinit_crypto_openssl.c | 211 +++++------------- - 1 file changed, 62 insertions(+), 149 deletions(-) + .../preauth/pkinit/pkinit_crypto_openssl.c | 213 ++++++------------ + 1 file changed, 63 insertions(+), 150 deletions(-) diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c index 5ff81d8cf..8aa2c5257 100644 @@ -144,17 +144,6 @@ index 5ff81d8cf..8aa2c5257 100644 - X509_ALGOR *enc_alg=NULL; - STACK_OF(PKCS7_RECIP_INFO) *rsk=NULL; - PKCS7_RECIP_INFO *ri=NULL; -- -- p7->state=PKCS7_S_HEADER; -- -- rsk=p7->d.enveloped->recipientinfo; -- enc_alg=p7->d.enveloped->enc_data->algorithm; -- data_body=p7->d.enveloped->enc_data->enc_data; -- evp_cipher=EVP_get_cipherbyobj(enc_alg->algorithm); -- if (evp_cipher == NULL) { -- PKCS7err(PKCS7_F_PKCS7_DATADECODE,PKCS7_R_UNSUPPORTED_CIPHER_TYPE); -- goto cleanup; -- } + krb5_error_code ret; + int ok = 0, plaintext_len = 0, final_len; + unsigned int keylen = 0, eklen = 0, blocksize; @@ -166,13 +155,24 @@ index 5ff81d8cf..8aa2c5257 100644 + STACK_OF(PKCS7_RECIP_INFO) *rsk = p7->d.enveloped->recipientinfo; + PKCS7_RECIP_INFO *ri = NULL; +- p7->state=PKCS7_S_HEADER; ++ *data_out = NULL; ++ *len_out = 0; + +- rsk=p7->d.enveloped->recipientinfo; +- enc_alg=p7->d.enveloped->enc_data->algorithm; +- data_body=p7->d.enveloped->enc_data->enc_data; +- evp_cipher=EVP_get_cipherbyobj(enc_alg->algorithm); +- if (evp_cipher == NULL) { +- PKCS7err(PKCS7_F_PKCS7_DATADECODE,PKCS7_R_UNSUPPORTED_CIPHER_TYPE); +- goto cleanup; +- } +- - if ((etmp=BIO_new(BIO_f_cipher())) == NULL) { - PKCS7err(PKCS7_F_PKCS7_DATADECODE,ERR_R_BIO_LIB); - goto cleanup; - } -+ *data_out = NULL; -+ *len_out = 0; - +- - /* It was encrypted, we need to decrypt the secret key - * with the private key */ + p7->state = PKCS7_S_HEADER; @@ -195,14 +195,14 @@ index 5ff81d8cf..8aa2c5257 100644 - if (EVP_CipherInit_ex(evp_ctx,evp_cipher,NULL,NULL,NULL,0) <= 0) + evp_cipher = EVP_get_cipherbyobj(enc_alg->algorithm); + if (evp_cipher == NULL) -+ goto cleanup; + goto cleanup; +- if (EVP_CIPHER_asn1_to_param(evp_ctx,enc_alg->parameter) < 0) + keylen = EVP_CIPHER_key_length(evp_cipher); + blocksize = EVP_CIPHER_block_size(evp_cipher); + + evp_ctx = EVP_CIPHER_CTX_new(); + if (evp_ctx == NULL) - goto cleanup; -- if (EVP_CIPHER_asn1_to_param(evp_ctx,enc_alg->parameter) < 0) ++ goto cleanup; + if (!EVP_DecryptInit(evp_ctx, evp_cipher, NULL, NULL) || + EVP_CIPHER_asn1_to_param(evp_ctx, enc_alg->parameter) <= 0) goto cleanup; @@ -212,9 +212,7 @@ index 5ff81d8cf..8aa2c5257 100644 - tkeylen = EVP_CIPHER_CTX_key_length(evp_ctx); - tkey = OPENSSL_malloc(tkeylen); - if (tkey == NULL) -+ tkey = malloc(keylen); -+ if (tkey == NULL || !EVP_CIPHER_CTX_rand_key(evp_ctx, tkey)) - goto cleanup; +- goto cleanup; - if (EVP_CIPHER_CTX_rand_key(evp_ctx, tkey) <= 0) - goto cleanup; - if (ek == NULL) { @@ -222,7 +220,7 @@ index 5ff81d8cf..8aa2c5257 100644 - eklen = tkeylen; - tkey = NULL; - } - +- - if (eklen != (unsigned)EVP_CIPHER_CTX_key_length(evp_ctx)) { - /* Some S/MIME clients don't use the same key - * and effective key length. The key length is @@ -235,18 +233,29 @@ index 5ff81d8cf..8aa2c5257 100644 - } - } - if (EVP_CipherInit_ex(evp_ctx,NULL,NULL,ek,NULL,0) <= 0) -- goto cleanup; -+ /* Decrypt the secret key with the private key. */ -+ ret = pkinit_decode_data(context, id_cryptoctx, -+ ASN1_STRING_get0_data(ri->enc_key), -+ ASN1_STRING_length(ri->enc_key), &ek, &eklen); -+ use_key = (ret || eklen != keylen) ? tkey : ek; ++ tkey = malloc(keylen); ++ if (tkey == NULL || !EVP_CIPHER_CTX_rand_key(evp_ctx, tkey)) + goto cleanup; - if (out == NULL) - out=etmp; - else - BIO_push(out,etmp); - etmp=NULL; ++ /* Decrypt the secret key with the private key. */ ++ ret = pkinit_decode_data(context, id_cryptoctx, ++ ASN1_STRING_get0_data(ri->enc_key), ++ ASN1_STRING_length(ri->enc_key), &ek, &eklen); ++ use_key = (ret || eklen != keylen) ? tkey : ek; + +- if (data_body->length > 0) +- bio = BIO_new_mem_buf(data_body->data, data_body->length); +- else { +- bio=BIO_new(BIO_s_mem()); +- BIO_set_mem_eof_return(bio,0); +- } +- BIO_push(out,bio); +- bio=NULL; + /* Allocate a plaintext buffer and decrypt data_body into it. */ + plaintext = malloc(data_body->length + blocksize); + if (plaintext == NULL) @@ -260,19 +269,6 @@ index 5ff81d8cf..8aa2c5257 100644 + goto cleanup; + plaintext_len += final_len; -- if (data_body->length > 0) -- bio = BIO_new_mem_buf(data_body->data, data_body->length); -- else { -- bio=BIO_new(BIO_s_mem()); -- BIO_set_mem_eof_return(bio,0); -- } -- BIO_push(out,bio); -- bio=NULL; -+ *len_out = plaintext_len; -+ *data_out = plaintext; -+ plaintext = NULL; -+ ok = 1; - - if (0) { - cleanup: - if (out != NULL) BIO_free_all(out); @@ -289,6 +285,11 @@ index 5ff81d8cf..8aa2c5257 100644 - OPENSSL_free(tkey); - } - return(out); ++ *len_out = plaintext_len; ++ *data_out = plaintext; ++ plaintext = NULL; ++ ok = 1; ++ +cleanup: + EVP_CIPHER_CTX_free(evp_ctx); + zapfree(plaintext, plaintext_len); diff --git a/Update-test-suite-to-avoid-single-DES-enctypes.patch b/Update-test-suite-to-avoid-single-DES-enctypes.patch index fe79d58..042bc1b 100644 --- a/Update-test-suite-to-avoid-single-DES-enctypes.patch +++ b/Update-test-suite-to-avoid-single-DES-enctypes.patch @@ -1931,7 +1931,7 @@ index c061d764e..e8adee234 100644 } { all-enctypes -@@ -248,114 +207,7 @@ set passes { +@@ -248,115 +207,8 @@ set passes { {allow_weak_crypto(server)=false} {dummy=[verbose -log "all default enctypes"]} } @@ -1960,8 +1960,8 @@ index c061d764e..e8adee234 100644 - {dummy=[verbose -log \ - "DES3 TGT, KDC permitting only des-cbc-crc"]} - } --} -- + } + -# des.md5-tgt is set as unused, since it won't trigger the error case -# if SUPPORT_DESMD5 isn't honored. - @@ -2041,11 +2041,12 @@ index c061d764e..e8adee234 100644 - {master_key_type=aes256-cts-hmac-sha1-96} - {dummy=[verbose -log "AES via TCP"]} - } - } +-} -# {supported_enctypes=des-cbc-md5:normal des-cbc-crc:normal twofish256-hmac-sha1:normal } - +- # This shouldn't be necessary on dejagnu-1.4 and later, but 1.3 seems # to need it because its runtest.exp doesn't deal with PASS at all. + if [info exists PASS] { @@ -1095,7 +947,7 @@ proc setup_kerberos_db { standalone } { global REALMNAME KDB5_UTIL KADMIN_LOCAL KEY global tmppwd hostname diff --git a/Use-backported-version-of-OpenSSL-3-KDF-interface.patch b/Use-backported-version-of-OpenSSL-3-KDF-interface.patch index 4a24a89..28bd9f9 100644 --- a/Use-backported-version-of-OpenSSL-3-KDF-interface.patch +++ b/Use-backported-version-of-OpenSSL-3-KDF-interface.patch @@ -5,9 +5,9 @@ Subject: [PATCH] Use backported version of OpenSSL-3 KDF interface --- src/configure.in | 4 + - src/lib/crypto/krb/derive.c | 346 +++++++++++++----- - .../preauth/pkinit/pkinit_crypto_openssl.c | 257 +++++++------ - 3 files changed, 423 insertions(+), 184 deletions(-) + src/lib/crypto/krb/derive.c | 356 +++++++++++++----- + .../preauth/pkinit/pkinit_crypto_openssl.c | 257 ++++++++----- + 3 files changed, 428 insertions(+), 189 deletions(-) diff --git a/src/configure.in b/src/configure.in index 1df6f18fc..3bd5e683d 100644 @@ -56,8 +56,6 @@ index 6707a7308..915a173dd 100644 + const krb5_data *label, const krb5_data *context) { - size_t blocksize, keybytes, n; -- krb5_error_code ret; -- krb5_data block = empty_data(); + krb5_error_code ret = KRB5_CRYPTO_INTERNAL; + EVP_KDF_CTX *ctx = NULL; + const EVP_MD *digest; @@ -97,9 +95,7 @@ index 6707a7308..915a173dd 100644 + EVP_KDF_CTX_free(ctx); + return ret; +} - -- blocksize = enc->block_size; -- keybytes = enc->keybytes; ++ +static krb5_error_code +openssl_kbkdf_feedback_cmac(const struct krb5_enc_provider *enc, + krb5_key inkey, krb5_data *outrnd, @@ -145,10 +141,7 @@ index 6707a7308..915a173dd 100644 + EVP_KDF_CTX_free(ctx); + return ret; +} - -- if (blocksize == 1) -- return KRB5_BAD_ENCTYPE; -- if (inkey->keyblock.length != enc->keylength || outrnd->length != keybytes) ++ +static krb5_error_code +openssl_krb5kdf(const struct krb5_enc_provider *enc, krb5_key inkey, + krb5_data *outrnd, const krb5_data *in_constant) @@ -159,11 +152,9 @@ index 6707a7308..915a173dd 100644 + + if (inkey->keyblock.length != enc->keylength || + outrnd->length != enc->keybytes) { - return KRB5_CRYPTO_INTERNAL; ++ return KRB5_CRYPTO_INTERNAL; + } - -- /* Allocate encryption data buffer. */ -- ret = alloc_data(&block, blocksize); ++ + if (enc->encrypt == krb5int_aes_encrypt && enc->keylength == 16) + cipher = EVP_aes_128_cbc(); + else if (enc->encrypt == krb5int_aes_encrypt && enc->keylength == 32) @@ -188,29 +179,14 @@ index 6707a7308..915a173dd 100644 + + ret = 0; +done: - if (ret) -- return ret; ++ if (ret) + zap(outrnd->data, outrnd->length); + EVP_KDF_CTX_free(ctx); + return ret; +} - -- /* Initialize the input block. */ -- if (in_constant->length == blocksize) { -- memcpy(block.data, in_constant->data, blocksize); -- } else { -- krb5int_nfold(in_constant->length * 8, -- (unsigned char *) in_constant->data, -- blocksize * 8, (unsigned char *) block.data); -- } ++ +#else /* OSSL_KDFS */ - -- /* Loop encrypting the blocks until enough key bytes are generated. */ -- n = 0; -- while (n < keybytes) { -- ret = encrypt_block(enc, inkey, &block); -- if (ret) -- goto cleanup; ++ +/* + * NIST SP800-108 KDF in counter mode (section 5.1). + * Parameters: @@ -227,27 +203,34 @@ index 6707a7308..915a173dd 100644 + const krb5_data *context) +{ + krb5_crypto_iov iov[5]; -+ krb5_error_code ret; + krb5_error_code ret; +- krb5_data block = empty_data(); + krb5_data prf; + unsigned char ibuf[4], lbuf[4]; -- if ((keybytes - n) <= blocksize) { -- memcpy(outrnd->data + n, block.data, (keybytes - n)); -- break; -- } +- blocksize = enc->block_size; +- keybytes = enc->keybytes; +- +- if (blocksize == 1) +- return KRB5_BAD_ENCTYPE; +- if (inkey->keyblock.length != enc->keylength || outrnd->length != keybytes) + if (hash == NULL || outrnd->length > hash->hashsize) -+ return KRB5_CRYPTO_INTERNAL; + return KRB5_CRYPTO_INTERNAL; -- memcpy(outrnd->data + n, block.data, blocksize); -- n += blocksize; -- } -+ /* Allocate encryption data buffer. */ + /* Allocate encryption data buffer. */ +- ret = alloc_data(&block, blocksize); + ret = alloc_data(&prf, hash->hashsize); -+ if (ret) -+ return ret; + if (ret) + return ret; --cleanup: -- zapfree(block.data, blocksize); +- /* Initialize the input block. */ +- if (in_constant->length == blocksize) { +- memcpy(block.data, in_constant->data, blocksize); +- } else { +- krb5int_nfold(in_constant->length * 8, +- (unsigned char *) in_constant->data, +- blocksize * 8, (unsigned char *) block.data); +- } + /* [i]2: four-byte big-endian binary string giving the block counter (1) */ + iov[0].flags = KRB5_CRYPTO_TYPE_DATA; + iov[0].data = make_data(ibuf, sizeof(ibuf)); @@ -265,7 +248,25 @@ index 6707a7308..915a173dd 100644 + iov[4].flags = KRB5_CRYPTO_TYPE_DATA; + iov[4].data = make_data(lbuf, sizeof(lbuf)); + store_32_be(outrnd->length * 8, lbuf); -+ + +- /* Loop encrypting the blocks until enough key bytes are generated. */ +- n = 0; +- while (n < keybytes) { +- ret = encrypt_block(enc, inkey, &block); +- if (ret) +- goto cleanup; +- +- if ((keybytes - n) <= blocksize) { +- memcpy(outrnd->data + n, block.data, (keybytes - n)); +- break; +- } +- +- memcpy(outrnd->data + n, block.data, blocksize); +- n += blocksize; +- } +- +-cleanup: +- zapfree(block.data, blocksize); + ret = krb5int_hmac(hash, inkey, iov, 5, &prf); + if (!ret) + memcpy(outrnd->data, prf.data, outrnd->length); @@ -286,7 +287,7 @@ index 6707a7308..915a173dd 100644 { size_t blocksize, keybytes, n; krb5_crypto_iov iov[6]; -@@ -204,57 +349,95 @@ cleanup: +@@ -204,56 +349,94 @@ cleanup: return ret; } @@ -299,54 +300,28 @@ index 6707a7308..915a173dd 100644 - * - * There are no uses requiring more than a single PRF invocation. - */ --krb5_error_code --k5_sp800_108_counter_hmac(const struct krb5_hash_provider *hash, -- krb5_key inkey, krb5_data *outrnd, -- const krb5_data *label, const krb5_data *context) +static krb5_error_code +builtin_derive_random_rfc3961(const struct krb5_enc_provider *enc, + krb5_key inkey, krb5_data *outrnd, + const krb5_data *in_constant) - { -- krb5_crypto_iov iov[5]; ++{ + size_t blocksize, keybytes, n; - krb5_error_code ret; -- krb5_data prf; -- unsigned char ibuf[4], lbuf[4]; ++ krb5_error_code ret; + krb5_data block = empty_data(); - -- if (hash == NULL || outrnd->length > hash->hashsize) ++ + blocksize = enc->block_size; + keybytes = enc->keybytes; + + if (blocksize == 1) + return KRB5_BAD_ENCTYPE; + if (inkey->keyblock.length != enc->keylength || outrnd->length != keybytes) - return KRB5_CRYPTO_INTERNAL; - - /* Allocate encryption data buffer. */ -- ret = alloc_data(&prf, hash->hashsize); ++ return KRB5_CRYPTO_INTERNAL; ++ ++ /* Allocate encryption data buffer. */ + ret = alloc_data(&block, blocksize); - if (ret) - return ret; - -- /* [i]2: four-byte big-endian binary string giving the block counter (1) */ -- iov[0].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[0].data = make_data(ibuf, sizeof(ibuf)); -- store_32_be(1, ibuf); -- /* Label */ -- iov[1].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[1].data = *label; -- /* 0x00: separator byte */ -- iov[2].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[2].data = make_data("", 1); -- /* Context */ -- iov[3].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[3].data = *context; -- /* [L]2: four-byte big-endian binary string giving the output length */ -- iov[4].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[4].data = make_data(lbuf, sizeof(lbuf)); -- store_32_be(outrnd->length * 8, lbuf); ++ if (ret) ++ return ret; ++ + /* Initialize the input block. */ + if (in_constant->length == blocksize) { + memcpy(block.data, in_constant->data, blocksize); @@ -355,11 +330,7 @@ index 6707a7308..915a173dd 100644 + (unsigned char *) in_constant->data, + blocksize * 8, (unsigned char *) block.data); + } - -- ret = krb5int_hmac(hash, inkey, iov, 5, &prf); -- if (!ret) -- memcpy(outrnd->data, prf.data, outrnd->length); -- zapfree(prf.data, prf.length); ++ + /* Loop encrypting the blocks until enough key bytes are generated. */ + n = 0; + while (n < keybytes) { @@ -378,15 +349,19 @@ index 6707a7308..915a173dd 100644 + +cleanup: + zapfree(block.data, blocksize); - return ret; - } ++ return ret; ++} +#endif /* OSSL_KDFS */ + -+krb5_error_code -+k5_sp800_108_counter_hmac(const struct krb5_hash_provider *hash, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *label, const krb5_data *context) -+{ + krb5_error_code + k5_sp800_108_counter_hmac(const struct krb5_hash_provider *hash, + krb5_key inkey, krb5_data *outrnd, + const krb5_data *label, const krb5_data *context) + { +- krb5_crypto_iov iov[5]; +- krb5_error_code ret; +- krb5_data prf; +- unsigned char ibuf[4], lbuf[4]; +#ifdef OSSL_KDFS + return openssl_kbdkf_counter_hmac(hash, inkey, outrnd, label, context); +#else @@ -394,7 +369,9 @@ index 6707a7308..915a173dd 100644 + context); +#endif +} -+ + +- if (hash == NULL || outrnd->length > hash->hashsize) +- return KRB5_CRYPTO_INTERNAL; +static krb5_error_code +k5_sp800_108_feedback_cmac(const struct krb5_enc_provider *enc, + krb5_key inkey, krb5_data *outrnd, @@ -406,7 +383,35 @@ index 6707a7308..915a173dd 100644 + return builtin_sp800_108_feedback_cmac(enc, inkey, outrnd, in_constant); +#endif +} -+ + +- /* Allocate encryption data buffer. */ +- ret = alloc_data(&prf, hash->hashsize); +- if (ret) +- return ret; +- +- /* [i]2: four-byte big-endian binary string giving the block counter (1) */ +- iov[0].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[0].data = make_data(ibuf, sizeof(ibuf)); +- store_32_be(1, ibuf); +- /* Label */ +- iov[1].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[1].data = *label; +- /* 0x00: separator byte */ +- iov[2].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[2].data = make_data("", 1); +- /* Context */ +- iov[3].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[3].data = *context; +- /* [L]2: four-byte big-endian binary string giving the output length */ +- iov[4].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[4].data = make_data(lbuf, sizeof(lbuf)); +- store_32_be(outrnd->length * 8, lbuf); +- +- ret = krb5int_hmac(hash, inkey, iov, 5, &prf); +- if (!ret) +- memcpy(outrnd->data, prf.data, outrnd->length); +- zapfree(prf.data, prf.length); +- return ret; +static krb5_error_code +k5_derive_random_rfc3961(const struct krb5_enc_provider *enc, + krb5_key inkey, krb5_data *outrnd, @@ -417,10 +422,9 @@ index 6707a7308..915a173dd 100644 +#else + return builtin_derive_random_rfc3961(enc, inkey, outrnd, in_constant); +#endif -+} + } krb5_error_code - krb5int_derive_random(const struct krb5_enc_provider *enc, @@ -266,10 +449,9 @@ krb5int_derive_random(const struct krb5_enc_provider *enc, switch (alg) { @@ -464,7 +468,11 @@ index 52976895b..dd718c2be 100644 + krb5_error_code ret = KRB5_CRYPTO_INTERNAL; + EVP_KDF_CTX *ctx = NULL; + const EVP_MD *digest; -+ + +-/* pkinit_alg_agility_kdf() -- +- * This function generates a key using the KDF described in +- * draft_ietf_krb_wg_pkinit_alg_agility-04.txt. The algorithm is +- * described as follows: + /* RFC 8636 defines a SHA384 variant, but we don't use it. */ + if (hash_bytes == 20) { + digest = EVP_sha1(); @@ -476,11 +484,7 @@ index 52976895b..dd718c2be 100644 + krb5_set_error_message(context, ret, "Bad hash type for SSKDF"); + goto done; + } - --/* pkinit_alg_agility_kdf() -- -- * This function generates a key using the KDF described in -- * draft_ietf_krb_wg_pkinit_alg_agility-04.txt. The algorithm is -- * described as follows: ++ + ctx = EVP_KDF_CTX_new_id(EVP_KDF_SS); + if (!ctx) { + oerr(context, ret, _("Failed to instantiate SSKDF")); diff --git a/Use-secure_getenv-where-appropriate.patch b/Use-secure_getenv-where-appropriate.patch index 1adc322..d8f5832 100644 --- a/Use-secure_getenv-where-appropriate.patch +++ b/Use-secure_getenv-where-appropriate.patch @@ -15,10 +15,10 @@ ticket: 8800 src/lib/krb5/os/trace.c | 2 +- src/lib/krb5/rcache/rc_base.c | 4 ++-- src/lib/krb5/rcache/rc_io.c | 4 ++-- - src/plugins/preauth/pkinit/pkinit_identity.c | 11 +++-------- + src/plugins/preauth/pkinit/pkinit_identity.c | 13 ++++--------- src/plugins/tls/k5tls/openssl.c | 2 +- src/util/profile/prof_file.c | 2 +- - 12 files changed, 19 insertions(+), 24 deletions(-) + 12 files changed, 20 insertions(+), 25 deletions(-) diff --git a/src/lib/kadm5/alt_prof.c b/src/lib/kadm5/alt_prof.c index 3f6b53651..5531a10fb 100644 @@ -184,7 +184,7 @@ diff --git a/src/plugins/preauth/pkinit/pkinit_identity.c b/src/plugins/preauth/ index 8cd3fc640..b89c5d015 100644 --- a/src/plugins/preauth/pkinit/pkinit_identity.c +++ b/src/plugins/preauth/pkinit/pkinit_identity.c -@@ -29,16 +29,10 @@ +@@ -29,15 +29,9 @@ * SUCH DAMAGES. */ @@ -192,16 +192,16 @@ index 8cd3fc640..b89c5d015 100644 -#include -#include -#include -+#include "pkinit.h" - #include +-#include -#include - #include - --#include "pkinit.h" +-#include - + #include "pkinit.h" ++#include ++#include + static void free_list(char **list) - { @@ -430,7 +424,8 @@ process_option_identity(krb5_context context, switch (idtype) { case IDTYPE_ENVVAR: diff --git a/krb5.spec b/krb5.spec index 8dcf4f6..1931d29 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 2%{?dist} +Release: 3%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -115,6 +115,9 @@ Patch167: Fix-minor-errors-in-softpkcs11.patch Patch168: Update-test-suite-cert-message-digest-to-sha256.patch Patch169: Use-backported-version-of-OpenSSL-3-KDF-interface.patch Patch170: krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +Patch171: Don-t-warn-in-kadmin-when-no-policy-is-specified.patch +Patch172: Allow-client-canonicalization-in-non-krbtgt-AS-REP.patch +Patch173: Do-not-always-canonicalize-enterprise-principals.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -688,6 +691,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Jan 03 2020 Robbie Harwood - 1.17.1-3 +- Don't warn in kadmin when no policy is specified +- Do not always canonicalize enterprise principals + * Fri Dec 13 2019 Robbie Harwood - 1.17.1-2 - Enable the LMDB backend for the KDB From 2496b50d003362ff5b76ae12ae351e0ea838d793 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 6 Jan 2020 16:36:41 -0500 Subject: [PATCH 144/304] Fix xdr_bytes() strict-aliasing violations --- ...xdr_bytes-strict-aliasing-violations.patch | 138 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 143 insertions(+), 1 deletion(-) create mode 100644 Fix-xdr_bytes-strict-aliasing-violations.patch diff --git a/Fix-xdr_bytes-strict-aliasing-violations.patch b/Fix-xdr_bytes-strict-aliasing-violations.patch new file mode 100644 index 0000000..34082c0 --- /dev/null +++ b/Fix-xdr_bytes-strict-aliasing-violations.patch @@ -0,0 +1,138 @@ +From e48e04d955c809c6f7b4f9052294d407f0d93daa Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 10 Dec 2019 12:06:05 -0500 +Subject: [PATCH] Fix xdr_bytes() strict-aliasing violations + +When xdr_bytes() is used for a gss_buffer_desc object, a temporary +character pointer must be used for the data value to avoid a strict +aliasing violation. + +When xdr_bytes() is used for a krb5_keyblock object, a temporary +character pointer must also be used, even though the data pointer is +of type unsigned char *, to avoid a clang warning on macOS due to the +"#pragma pack" declaration in krb5.h. + +(cherry picked from commit 21b39d0196e3e0bb6b1bfbf5d60a0596cfc82e27) +--- + src/lib/kadm5/kadm_rpc_xdr.c | 8 +++++--- + src/lib/rpc/auth_gssapi_misc.c | 21 +++++++++++++-------- + src/lib/rpc/authgss_prot.c | 5 ++++- + 3 files changed, 22 insertions(+), 12 deletions(-) + +diff --git a/src/lib/kadm5/kadm_rpc_xdr.c b/src/lib/kadm5/kadm_rpc_xdr.c +index f22ea7f1f..8383e4e23 100644 +--- a/src/lib/kadm5/kadm_rpc_xdr.c ++++ b/src/lib/kadm5/kadm_rpc_xdr.c +@@ -1125,14 +1125,16 @@ xdr_krb5_salttype(XDR *xdrs, krb5_int32 *objp) + bool_t + xdr_krb5_keyblock(XDR *xdrs, krb5_keyblock *objp) + { ++ char *cp; ++ + /* XXX This only works because free_keyblock assumes ->contents + is allocated by malloc() */ +- + if(!xdr_krb5_enctype(xdrs, &objp->enctype)) + return FALSE; +- if(!xdr_bytes(xdrs, (char **) &objp->contents, (unsigned int *) +- &objp->length, ~0)) ++ cp = (char *)objp->contents; ++ if(!xdr_bytes(xdrs, &cp, &objp->length, ~0)) + return FALSE; ++ objp->contents = (uint8_t *)cp; + return TRUE; + } + +diff --git a/src/lib/rpc/auth_gssapi_misc.c b/src/lib/rpc/auth_gssapi_misc.c +index a05ea19eb..a60eb7f7c 100644 +--- a/src/lib/rpc/auth_gssapi_misc.c ++++ b/src/lib/rpc/auth_gssapi_misc.c +@@ -45,9 +45,11 @@ bool_t xdr_gss_buf( + bool_t result; + /* Fix type mismatches between APIs. */ + unsigned int length = buf->length; +- result = xdr_bytes(xdrs, (char **) &buf->value, &length, ++ char *cp = buf->value; ++ result = xdr_bytes(xdrs, &cp, &length, + (xdrs->x_op == XDR_DECODE && buf->value == NULL) + ? (unsigned int) -1 : (unsigned int) buf->length); ++ buf->value = cp; + buf->length = length; + return result; + } +@@ -204,6 +206,7 @@ bool_t auth_gssapi_wrap_data( + XDR temp_xdrs; + int conf_state; + unsigned int length; ++ char *cp; + + PRINTF(("gssapi_wrap_data: starting\n")); + +@@ -243,13 +246,13 @@ bool_t auth_gssapi_wrap_data( + + /* write the token */ + length = out_buf.length; +- if (! xdr_bytes(out_xdrs, (char **) &out_buf.value, +- (unsigned int *) &length, +- out_buf.length)) { ++ cp = out_buf.value; ++ if (! xdr_bytes(out_xdrs, &cp, &length, out_buf.length)) { + PRINTF(("gssapi_wrap_data: serializing encrypted data failed\n")); + XDR_DESTROY(&temp_xdrs); + return FALSE; + } ++ out_buf.value = cp; + + *major = gss_release_buffer(minor, &out_buf); + +@@ -272,6 +275,7 @@ bool_t auth_gssapi_unwrap_data( + uint32_t verf_seq_num; + int conf, qop; + unsigned int length; ++ char *cp; + + PRINTF(("gssapi_unwrap_data: starting\n")); + +@@ -280,14 +284,15 @@ bool_t auth_gssapi_unwrap_data( + + in_buf.value = NULL; + out_buf.value = NULL; +- if (! xdr_bytes(in_xdrs, (char **) &in_buf.value, +- &length, (unsigned int) -1)) { ++ cp = in_buf.value; ++ if (! xdr_bytes(in_xdrs, &cp, &length, (unsigned int) -1)) { + PRINTF(("gssapi_unwrap_data: deserializing encrypted data failed\n")); + temp_xdrs.x_op = XDR_FREE; +- (void)xdr_bytes(&temp_xdrs, (char **) &in_buf.value, &length, +- (unsigned int) -1); ++ (void)xdr_bytes(&temp_xdrs, &cp, &length, (unsigned int) -1); ++ in_buf.value = NULL; + return FALSE; + } ++ in_buf.value = cp; + in_buf.length = length; + + *major = gss_unseal(minor, context, &in_buf, &out_buf, &conf, +diff --git a/src/lib/rpc/authgss_prot.c b/src/lib/rpc/authgss_prot.c +index a5a587f90..9a48277b3 100644 +--- a/src/lib/rpc/authgss_prot.c ++++ b/src/lib/rpc/authgss_prot.c +@@ -50,6 +50,7 @@ xdr_rpc_gss_buf(XDR *xdrs, gss_buffer_t buf, u_int maxsize) + { + bool_t xdr_stat; + u_int tmplen; ++ char *cp; + + if (xdrs->x_op != XDR_DECODE) { + if (buf->length > UINT_MAX) +@@ -57,7 +58,9 @@ xdr_rpc_gss_buf(XDR *xdrs, gss_buffer_t buf, u_int maxsize) + else + tmplen = buf->length; + } +- xdr_stat = xdr_bytes(xdrs, (char **)&buf->value, &tmplen, maxsize); ++ cp = buf->value; ++ xdr_stat = xdr_bytes(xdrs, &cp, &tmplen, maxsize); ++ buf->value = cp; + + if (xdr_stat && xdrs->x_op == XDR_DECODE) + buf->length = tmplen; diff --git a/krb5.spec b/krb5.spec index 1931d29..9ed8d49 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 3%{?dist} +Release: 4%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -118,6 +118,7 @@ Patch170: krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch Patch171: Don-t-warn-in-kadmin-when-no-policy-is-specified.patch Patch172: Allow-client-canonicalization-in-non-krbtgt-AS-REP.patch Patch173: Do-not-always-canonicalize-enterprise-principals.patch +Patch174: Fix-xdr_bytes-strict-aliasing-violations.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -691,6 +692,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jan 06 2020 Robbie Harwood - 1.17.1-4 +- Fix xdr_bytes() strict-aliasing violations + * Fri Jan 03 2020 Robbie Harwood - 1.17.1-3 - Don't warn in kadmin when no policy is specified - Do not always canonicalize enterprise principals From 84aac1fa6d4b38294368c59544b8023d94db976d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 8 Jan 2020 14:07:00 -0500 Subject: [PATCH 145/304] Fix LDAP policy enforcement of pw_expiration Fix handling of invalid CAMMAC service verifier --- ...-policy-enforcement-of-pw_expiration.patch | 302 ++++++++++++++++++ ...g-of-invalid-CAMMAC-service-verifier.patch | 30 ++ krb5.spec | 8 +- 3 files changed, 339 insertions(+), 1 deletion(-) create mode 100644 Fix-LDAP-policy-enforcement-of-pw_expiration.patch create mode 100644 Fix-handling-of-invalid-CAMMAC-service-verifier.patch diff --git a/Fix-LDAP-policy-enforcement-of-pw_expiration.patch b/Fix-LDAP-policy-enforcement-of-pw_expiration.patch new file mode 100644 index 0000000..45b0484 --- /dev/null +++ b/Fix-LDAP-policy-enforcement-of-pw_expiration.patch @@ -0,0 +1,302 @@ +From d62cb044abe57eda1216f9ab97f50bd178f1d495 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 17 Dec 2019 17:37:41 -0500 +Subject: [PATCH] Fix LDAP policy enforcement of pw_expiration + +In the LDAP backend, the change mask is used to determine what LDAP +attributes to update. As a result, password expiration was not set +from policy when running during addprinc, among other issues. +However, when the mask did not contain KADM5_PRINCIPAL, pw_expiration +would be applied regardless, which meant that (for instance) changing +the password would cause the password application to be applied. + +Remove the check for KADM5_PRINCIPAL, and fix the mask to contain +KADM5_PW_EXPIRATION where appropriate. Add a regression test to +t_kdb.py. + +[ghudson@mit.edu: also set KADM5_ATTRIBUTES for randkey and setkey +since they both unset KRB5_KDB_REQUIRES_PWCHANGE; edited comments and +commit message] + +ticket: 8861 (new) +tags: pullup +target_version: 1.17-next + +(cherry picked from commit 6b004dd5739bded71be4290c11e7ac3a816c7e09) +--- + src/lib/kadm5/srv/svr_principal.c | 92 +++++++++---------- + .../kdb/ldap/libkdb_ldap/ldap_principal2.c | 13 --- + src/tests/t_kdb.py | 17 ++++ + 3 files changed, 60 insertions(+), 62 deletions(-) + +diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c +index a1ecdbfc4..35bbf1218 100644 +--- a/src/lib/kadm5/srv/svr_principal.c ++++ b/src/lib/kadm5/srv/svr_principal.c +@@ -356,6 +356,11 @@ kadm5_create_principal_3(void *server_handle, + kdb = calloc(1, sizeof(*kdb)); + if (kdb == NULL) + return ENOMEM; ++ ++ /* In all cases the principal entry is new and key data is set; let the ++ * database provider know. */ ++ kdb->mask = mask | KADM5_KEY_DATA | KADM5_PRINCIPAL; ++ + memset(&adb, 0, sizeof(osa_princ_ent_rec)); + + /* +@@ -405,14 +410,12 @@ kadm5_create_principal_3(void *server_handle, + kdb->expiration = handle->params.expiration; + + kdb->pw_expiration = 0; +- if (have_polent) { +- if(polent.pw_max_life) +- kdb->pw_expiration = ts_incr(now, polent.pw_max_life); +- else +- kdb->pw_expiration = 0; +- } +- if ((mask & KADM5_PW_EXPIRATION)) ++ if (mask & KADM5_PW_EXPIRATION) { + kdb->pw_expiration = entry->pw_expiration; ++ } else if (have_polent && polent.pw_max_life) { ++ kdb->mask |= KADM5_PW_EXPIRATION; ++ kdb->pw_expiration = ts_incr(now, polent.pw_max_life); ++ } + + kdb->last_success = 0; + kdb->last_failed = 0; +@@ -503,9 +506,6 @@ kadm5_create_principal_3(void *server_handle, + adb.policy = entry->policy; + } + +- /* In all cases key and the principal data is set, let the database provider know */ +- kdb->mask = mask | KADM5_KEY_DATA | KADM5_PRINCIPAL ; +- + /* store the new db entry */ + ret = kdb_put_entry(handle, kdb, &adb); + +@@ -601,6 +601,9 @@ kadm5_modify_principal(void *server_handle, + if (ret) + return(ret); + ++ /* Let the mask propagate to the database provider. */ ++ kdb->mask = mask; ++ + /* + * This is pretty much the same as create ... + */ +@@ -616,11 +619,15 @@ kadm5_modify_principal(void *server_handle, + free(adb.policy); + adb.policy = strdup(entry->policy); + } +- if (have_pol) { ++ ++ if (mask & KADM5_PW_EXPIRATION) { ++ kdb->pw_expiration = entry->pw_expiration; ++ } else if (have_pol) { + /* set pw_max_life based on new policy */ ++ kdb->mask |= KADM5_PW_EXPIRATION; + if (pol.pw_max_life) { + ret = krb5_dbe_lookup_last_pwd_change(handle->context, kdb, +- &(kdb->pw_expiration)); ++ &kdb->pw_expiration); + if (ret) + goto done; + kdb->pw_expiration = ts_incr(kdb->pw_expiration, pol.pw_max_life); +@@ -642,8 +649,6 @@ kadm5_modify_principal(void *server_handle, + kdb->max_life = entry->max_life; + if ((mask & KADM5_PRINC_EXPIRE_TIME)) + kdb->expiration = entry->princ_expire_time; +- if (mask & KADM5_PW_EXPIRATION) +- kdb->pw_expiration = entry->pw_expiration; + if (mask & KADM5_MAX_RLIFE) + kdb->max_renewable_life = entry->max_renewable_life; + +@@ -682,9 +687,6 @@ kadm5_modify_principal(void *server_handle, + kdb->fail_auth_count = 0; + } + +- /* let the mask propagate to the database provider */ +- kdb->mask = mask; +- + ret = k5_kadm5_hook_modify(handle->context, handle->hook_handles, + KADM5_HOOK_STAGE_PRECOMMIT, entry, mask); + if (ret) +@@ -1362,6 +1364,11 @@ kadm5_chpass_principal_3(void *server_handle, + if ((ret = kdb_get_entry(handle, principal, &kdb, &adb))) + return(ret); + ++ /* We will always be changing the key data, attributes, auth failure count, ++ * and password expiration time. */ ++ kdb->mask = KADM5_KEY_DATA | KADM5_ATTRIBUTES | KADM5_FAIL_AUTH_COUNT | ++ KADM5_PW_EXPIRATION; ++ + ret = apply_keysalt_policy(handle, adb.policy, n_ks_tuple, ks_tuple, + &new_n_ks_tuple, &new_ks_tuple); + if (ret) +@@ -1407,6 +1414,7 @@ kadm5_chpass_principal_3(void *server_handle, + if (ret) + goto done; + ++ kdb->pw_expiration = 0; + if ((adb.aux_attributes & KADM5_POLICY)) { + /* the policy was loaded before */ + +@@ -1439,10 +1447,6 @@ kadm5_chpass_principal_3(void *server_handle, + + if (pol.pw_max_life) + kdb->pw_expiration = ts_incr(now, pol.pw_max_life); +- else +- kdb->pw_expiration = 0; +- } else { +- kdb->pw_expiration = 0; + } + + #ifdef USE_PASSWORD_SERVER +@@ -1481,11 +1485,6 @@ kadm5_chpass_principal_3(void *server_handle, + /* unlock principal on this KDC */ + kdb->fail_auth_count = 0; + +- /* key data and attributes changed, let the database provider know */ +- kdb->mask = KADM5_KEY_DATA | KADM5_ATTRIBUTES | +- KADM5_FAIL_AUTH_COUNT; +- /* | KADM5_CPW_FUNCTION */ +- + if (hist_added) + kdb->mask |= KADM5_KEY_HIST; + +@@ -1560,6 +1559,11 @@ kadm5_randkey_principal_3(void *server_handle, + if ((ret = kdb_get_entry(handle, principal, &kdb, &adb))) + return(ret); + ++ /* We will always be changing the key data, attributes, auth failure count, ++ * and password expiration time. */ ++ kdb->mask = KADM5_KEY_DATA | KADM5_ATTRIBUTES | KADM5_FAIL_AUTH_COUNT | ++ KADM5_PW_EXPIRATION; ++ + ret = apply_keysalt_policy(handle, adb.policy, n_ks_tuple, ks_tuple, + &new_n_ks_tuple, &new_ks_tuple); + if (ret) +@@ -1599,14 +1603,10 @@ kadm5_randkey_principal_3(void *server_handle, + if (ret) + goto done; + } +- if (have_pol) { +- if (pol.pw_max_life) +- kdb->pw_expiration = ts_incr(now, pol.pw_max_life); +- else +- kdb->pw_expiration = 0; +- } else { +- kdb->pw_expiration = 0; +- } ++ ++ kdb->pw_expiration = 0; ++ if (have_pol && pol.pw_max_life) ++ kdb->pw_expiration = ts_incr(now, pol.pw_max_life); + + ret = krb5_dbe_update_last_pwd_change(handle->context, kdb, now); + if (ret) +@@ -1624,10 +1624,6 @@ kadm5_randkey_principal_3(void *server_handle, + goto done; + } + +- /* key data changed, let the database provider know */ +- kdb->mask = KADM5_KEY_DATA | KADM5_FAIL_AUTH_COUNT; +- /* | KADM5_RANDKEY_USED */; +- + ret = k5_kadm5_hook_chpass(handle->context, handle->hook_handles, + KADM5_HOOK_STAGE_PRECOMMIT, principal, keepold, + new_n_ks_tuple, new_ks_tuple, NULL); +@@ -1763,6 +1759,11 @@ kadm5_setkey_principal_4(void *server_handle, krb5_principal principal, + if (ret) + return ret; + ++ /* We will always be changing the key data, attributes, auth failure count, ++ * and password expiration time. */ ++ kdb->mask = KADM5_KEY_DATA | KADM5_ATTRIBUTES | KADM5_FAIL_AUTH_COUNT | ++ KADM5_PW_EXPIRATION; ++ + if (kvno == 0) { + /* Pick the next kvno. */ + for (i = 0; i < kdb->n_key_data; i++) { +@@ -1864,14 +1865,10 @@ kadm5_setkey_principal_4(void *server_handle, krb5_principal principal, + if (ret) + goto done; + } +- if (have_pol) { +- if (pol.pw_max_life) +- kdb->pw_expiration = ts_incr(now, pol.pw_max_life); +- else +- kdb->pw_expiration = 0; +- } else { +- kdb->pw_expiration = 0; +- } ++ ++ kdb->pw_expiration = 0; ++ if (have_pol && pol.pw_max_life) ++ kdb->pw_expiration = ts_incr(now, pol.pw_max_life); + + ret = krb5_dbe_update_last_pwd_change(handle->context, kdb, now); + if (ret) +@@ -1880,9 +1877,6 @@ kadm5_setkey_principal_4(void *server_handle, krb5_principal principal, + /* Unlock principal on this KDC. */ + kdb->fail_auth_count = 0; + +- /* key data changed, let the database provider know */ +- kdb->mask = KADM5_KEY_DATA | KADM5_FAIL_AUTH_COUNT; +- + ret = kdb_put_entry(handle, kdb, &adb); + if (ret) + goto done; +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c +index ee9c02814..fa0a2c683 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c ++++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c +@@ -1233,19 +1233,6 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, + goto cleanup; + } + +- if (!(entry->mask & KADM5_PRINCIPAL)) { +- memset(strval, 0, sizeof(strval)); +- if ((strval[0]=getstringtime(entry->pw_expiration)) == NULL) +- goto cleanup; +- if ((st=krb5_add_str_mem_ldap_mod(&mods, +- "krbpasswordexpiration", +- LDAP_MOD_REPLACE, strval)) != 0) { +- free (strval[0]); +- goto cleanup; +- } +- free (strval[0]); +- } +- + /* Update last password change whenever a new key is set */ + { + krb5_timestamp last_pw_changed; +diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py +index 7271fcbbd..d18f672c1 100755 +--- a/src/tests/t_kdb.py ++++ b/src/tests/t_kdb.py +@@ -494,6 +494,23 @@ else: + realm.run([kadminl, 'modprinc', '-pwexpire', '2040-02-03', 'user']) + realm.run([kadminl, 'getprinc', 'user'], expected_msg=' 2040\n') + ++# Regression test for #8861 (pw_expiration policy enforcement). ++mark('pw_expiration propogation') ++# Create a policy with a max life and verify its application. ++realm.run([kadminl, 'addpol', '-maxlife', '1s', 'pw_e']) ++realm.run([kadminl, 'addprinc', '-policy', 'pw_e', '-pw', 'password', ++ 'pwuser']) ++out = realm.run([kadminl, 'getprinc', 'pwuser'], ++ expected_msg='Password expiration date: ') ++if 'Password expiration date: [never]' in out: ++ fail('pw_expiration not applied at principal creation') ++# Unset the policy max life and verify its application during password ++# change. ++realm.run([kadminl, 'modpol', '-maxlife', '0', 'pw_e']) ++realm.run([kadminl, 'cpw', '-pw', 'password_', 'pwuser']) ++realm.run([kadminl, 'getprinc', 'pwuser'], ++ expected_msg='Password expiration date: [never]') ++ + realm.stop() + + # Briefly test dump and load. diff --git a/Fix-handling-of-invalid-CAMMAC-service-verifier.patch b/Fix-handling-of-invalid-CAMMAC-service-verifier.patch new file mode 100644 index 0000000..bc285c2 --- /dev/null +++ b/Fix-handling-of-invalid-CAMMAC-service-verifier.patch @@ -0,0 +1,30 @@ +From 87d0a1364b9ddb4b9ed8dfaee3022172bfb879ba Mon Sep 17 00:00:00 2001 +From: Jeffrey Arbuckle +Date: Sat, 21 Dec 2019 22:59:20 -0500 +Subject: [PATCH] Fix handling of invalid CAMMAC service verifier + +In extract_cammacs(), avoid a null dereference if the CAMMAC service +verifier is invalid or the CAMMAC is empty. + +ticket: 8856 +tags: pullup +target_version: 1.17-next + +(cherry picked from commit 8451ff6ed57361de585a35f35a39c54dc48172c7) +--- + src/lib/krb5/krb/authdata.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/src/lib/krb5/krb/authdata.c b/src/lib/krb5/krb/authdata.c +index 3e7dfbe49..d3096e5a2 100644 +--- a/src/lib/krb5/krb/authdata.c ++++ b/src/lib/krb5/krb/authdata.c +@@ -557,6 +557,8 @@ extract_cammacs(krb5_context kcontext, krb5_authdata **cammacs, + if (ret && ret != KRB5KRB_AP_ERR_BAD_INTEGRITY) + goto cleanup; + ret = 0; ++ if (elements == NULL) ++ continue; + + /* Add the verified elements to list and free the container array. */ + for (n_elements = 0; elements[n_elements] != NULL; n_elements++); diff --git a/krb5.spec b/krb5.spec index 9ed8d49..c7f4735 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.17.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 4%{?dist} +Release: 5%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -119,6 +119,8 @@ Patch171: Don-t-warn-in-kadmin-when-no-policy-is-specified.patch Patch172: Allow-client-canonicalization-in-non-krbtgt-AS-REP.patch Patch173: Do-not-always-canonicalize-enterprise-principals.patch Patch174: Fix-xdr_bytes-strict-aliasing-violations.patch +Patch175: Fix-handling-of-invalid-CAMMAC-service-verifier.patch +Patch176: Fix-LDAP-policy-enforcement-of-pw_expiration.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -692,6 +694,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Jan 08 2020 Robbie Harwood - 1.17.1-5 +- Fix LDAP policy enforcement of pw_expiration +- Fix handling of invalid CAMMAC service verifier + * Mon Jan 06 2020 Robbie Harwood - 1.17.1-4 - Fix xdr_bytes() strict-aliasing violations From 7f642b1512b1891942008c7ae7ac64f3dfd83276 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 10 Jan 2020 21:31:31 +0000 Subject: [PATCH 146/304] New upstream beta release - 1.18-beta1 --- .gitignore | 2 + ...nonicalize_hostname-fallback-support.patch | 409 - ...on-and-enctype-flag-for-deprecations.patch | 183 - ...ing-newlines-to-deprecation-warnings.patch | 37 - Add-soft-pkcs11-source-code.patch | 2071 ----- Add-tests-for-KCM-ccache-type.patch | 294 - Add-zapfreedata-convenience-function.patch | 31 - Address-some-optimized-out-memset-calls.patch | 94 - ...anonicalization-in-non-krbtgt-AS-REP.patch | 64 - ...-alignment-warnings-in-openssl-rc4.c.patch | 63 - ...llocating-a-register-in-zap-assembly.patch | 55 - ...ore-errors-in-OpenSSL-crypto-backend.patch | 88 - ...er-comment-for-krb5_cc_start_seq_get.patch | 31 - ...able-flag-instead-of-denying-request.patch | 484 -- Display-unsupported-enctype-names.patch | 79 - ...s-canonicalize-enterprise-principals.patch | 113 - ...-error-on-invalid-enctypes-in-keytab.patch | 67 - ...n-kadmin-when-no-policy-is-specified.patch | 160 - ...ctypes-in-gss_set_allowable_enctypes.patch | 70 - ...ity-defects-in-soft-pkcs11-test-code.patch | 206 - ...C-crash-when-logging-PKINIT-enctypes.patch | 31 - ...-policy-enforcement-of-pw_expiration.patch | 302 - ...alm-change-logic-in-FILE-remove_cred.patch | 29 - ...g-of-invalid-CAMMAC-service-verifier.patch | 30 - Fix-memory-leaks-in-soft-pkcs11-code.patch | 122 - Fix-minor-errors-in-softpkcs11.patch | 41 - Fix-potential-close-1-in-cc_file.c.patch | 30 - ...xdr_bytes-strict-aliasing-violations.patch | 138 - ...5_cc_remove_cred-for-remaining-types.patch | 599 -- ...messages-from-kadmin-change_password.patch | 55 - ...ebug-log-proper-ticket-enctype-names.patch | 28 - ...ec-always-log-non-permitted-enctypes.patch | 54 - ...ize-some-data-structure-magic-fields.patch | 55 - ...known-enctypes-as-unsupported-in-KDC.patch | 52 - ...ype-names-in-KDC-logs-human-readable.patch | 296 - Mark-deprecated-enctypes-when-used.patch | 250 - ...-the-doc-kadm5-tex-files-as-historic.patch | 139 - ...ze-example-enctypes-in-documentation.patch | 232 - ...exit-path-in-gss_krb5int_copy_ccache.patch | 68 - Properly-size-ifdef-in-k5_cccol_lock.patch | 33 - ...beros-v4-support-vestiges-from-ccapi.patch | 1604 ---- ...-PKINIT-draft-9-ASN.1-code-and-types.patch | 967 --- Remove-PKINIT-draft-9-support.patch | 1712 ---- ...api-related-comments-in-configure.ac.patch | 34 - Remove-checksum-type-profile-variables.patch | 429 - Remove-confvalidator-utility.patch | 430 - ...d-variable-def_kslist-from-two-files.patch | 69 - ...ygen-generated-HTML-output-for-ccapi.patch | 7653 ----------------- ...admin-RPC-support-for-setting-v4-key.patch | 466 - Remove-krb5int_c_combine_keys.patch | 479 -- Remove-more-dead-code.patch | 276 - Remove-now-unused-checksum-functions.patch | 335 - ...ull-check-in-krb5_gss_duplicate_name.patch | 28 - ...ovsec_adm_export-dump-format-support.patch | 386 - Remove-srvtab-support.patch | 1411 --- Remove-strerror-calls-from-k5_get_error.patch | 34 - ...e-support-for-no-flags-SAM-2-preauth.patch | 73 - Remove-support-for-single-DES-and-CRC.patch | 3340 ------- Remove-the-v4-and-afs3-salt-types.patch | 509 -- Set-a-more-modern-default-ksu-CMD_PATH.patch | 26 - Simplify-SAM-2-as_key-handling.patch | 76 - Simplify-krb5_dbe_def_search_enctype.patch | 162 - Simply-OpenSSL-PKCS7-decryption-code.patch | 301 - Skip-URI-tests-when-using-asan.patch | 37 - ...arent-forward-null-in-clnttcp_create.patch | 34 - Support-389ds-s-lockout-model.patch | 63 - ....1-SAM-tests-to-use-a-modern-enctype.patch | 85 - ...lt-krb5kdc-mkey-manual-entry-enctype.patch | 54 - ...-suite-cert-message-digest-to-sha256.patch | 638 -- ...t-suite-to-avoid-single-DES-enctypes.patch | 2328 ----- ...d-version-of-OpenSSL-3-KDF-interface.patch | 14 +- Use-imported-soft-pkcs11-for-tests.patch | 471 - Use-secure_getenv-where-appropriate.patch | 240 - krb5-1.15-beta1-buildconf.patch | 2 +- ...t6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 6 +- ... krb5-1.18-beta1-Remove-3des-support.patch | 97 +- ...tch => krb5-1.18-beta1-selinux-label.patch | 99 +- ...12.1-pam.patch => krb5-1.18beta1-pam.patch | 46 +- krb5-1.3.1-dns.patch | 6 +- krb5-1.9-debuginfo.patch | 2 +- krb5.spec | 88 +- sources | 4 +- 82 files changed, 132 insertions(+), 32167 deletions(-) delete mode 100644 Add-dns_canonicalize_hostname-fallback-support.patch delete mode 100644 Add-function-and-enctype-flag-for-deprecations.patch delete mode 100644 Add-missing-newlines-to-deprecation-warnings.patch delete mode 100644 Add-soft-pkcs11-source-code.patch delete mode 100644 Add-tests-for-KCM-ccache-type.patch delete mode 100644 Add-zapfreedata-convenience-function.patch delete mode 100644 Address-some-optimized-out-memset-calls.patch delete mode 100644 Allow-client-canonicalization-in-non-krbtgt-AS-REP.patch delete mode 100644 Avoid-alignment-warnings-in-openssl-rc4.c.patch delete mode 100644 Avoid-allocating-a-register-in-zap-assembly.patch delete mode 100644 Check-more-errors-in-OpenSSL-crypto-backend.patch delete mode 100644 Clarify-header-comment-for-krb5_cc_start_seq_get.patch delete mode 100644 Clear-forwardable-flag-instead-of-denying-request.patch delete mode 100644 Display-unsupported-enctype-names.patch delete mode 100644 Do-not-always-canonicalize-enterprise-principals.patch delete mode 100644 Don-t-error-on-invalid-enctypes-in-keytab.patch delete mode 100644 Don-t-warn-in-kadmin-when-no-policy-is-specified.patch delete mode 100644 Filter-enctypes-in-gss_set_allowable_enctypes.patch delete mode 100644 Fix-Coverity-defects-in-soft-pkcs11-test-code.patch delete mode 100644 Fix-KDC-crash-when-logging-PKINIT-enctypes.patch delete mode 100644 Fix-LDAP-policy-enforcement-of-pw_expiration.patch delete mode 100644 Fix-config-realm-change-logic-in-FILE-remove_cred.patch delete mode 100644 Fix-handling-of-invalid-CAMMAC-service-verifier.patch delete mode 100644 Fix-memory-leaks-in-soft-pkcs11-code.patch delete mode 100644 Fix-minor-errors-in-softpkcs11.patch delete mode 100644 Fix-potential-close-1-in-cc_file.c.patch delete mode 100644 Fix-xdr_bytes-strict-aliasing-violations.patch delete mode 100644 Implement-krb5_cc_remove_cred-for-remaining-types.patch delete mode 100644 Improve-error-messages-from-kadmin-change_password.patch delete mode 100644 In-kpropd-debug-log-proper-ticket-enctype-names.patch delete mode 100644 In-rd_req_dec-always-log-non-permitted-enctypes.patch delete mode 100644 Initialize-some-data-structure-magic-fields.patch delete mode 100644 Log-unknown-enctypes-as-unsupported-in-KDC.patch delete mode 100644 Make-etype-names-in-KDC-logs-human-readable.patch delete mode 100644 Mark-deprecated-enctypes-when-used.patch delete mode 100644 Mark-the-doc-kadm5-tex-files-as-historic.patch delete mode 100644 Modernize-example-enctypes-in-documentation.patch delete mode 100644 Modernize-exit-path-in-gss_krb5int_copy_ccache.patch delete mode 100644 Properly-size-ifdef-in-k5_cccol_lock.patch delete mode 100644 Remove-Kerberos-v4-support-vestiges-from-ccapi.patch delete mode 100644 Remove-PKINIT-draft-9-ASN.1-code-and-types.patch delete mode 100644 Remove-PKINIT-draft-9-support.patch delete mode 100644 Remove-ccapi-related-comments-in-configure.ac.patch delete mode 100644 Remove-checksum-type-profile-variables.patch delete mode 100644 Remove-confvalidator-utility.patch delete mode 100644 Remove-dead-variable-def_kslist-from-two-files.patch delete mode 100644 Remove-doxygen-generated-HTML-output-for-ccapi.patch delete mode 100644 Remove-kadmin-RPC-support-for-setting-v4-key.patch delete mode 100644 Remove-krb5int_c_combine_keys.patch delete mode 100644 Remove-more-dead-code.patch delete mode 100644 Remove-now-unused-checksum-functions.patch delete mode 100644 Remove-null-check-in-krb5_gss_duplicate_name.patch delete mode 100644 Remove-ovsec_adm_export-dump-format-support.patch delete mode 100644 Remove-srvtab-support.patch delete mode 100644 Remove-strerror-calls-from-k5_get_error.patch delete mode 100644 Remove-support-for-no-flags-SAM-2-preauth.patch delete mode 100644 Remove-support-for-single-DES-and-CRC.patch delete mode 100644 Remove-the-v4-and-afs3-salt-types.patch delete mode 100644 Set-a-more-modern-default-ksu-CMD_PATH.patch delete mode 100644 Simplify-SAM-2-as_key-handling.patch delete mode 100644 Simplify-krb5_dbe_def_search_enctype.patch delete mode 100644 Simply-OpenSSL-PKCS7-decryption-code.patch delete mode 100644 Skip-URI-tests-when-using-asan.patch delete mode 100644 Squash-apparent-forward-null-in-clnttcp_create.patch delete mode 100644 Support-389ds-s-lockout-model.patch delete mode 100644 Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch delete mode 100644 Update-default-krb5kdc-mkey-manual-entry-enctype.patch delete mode 100644 Update-test-suite-cert-message-digest-to-sha256.patch delete mode 100644 Update-test-suite-to-avoid-single-DES-enctypes.patch delete mode 100644 Use-imported-soft-pkcs11-for-tests.patch delete mode 100644 Use-secure_getenv-where-appropriate.patch rename Remove-3des-support.patch => krb5-1.18-beta1-Remove-3des-support.patch (99%) rename krb5-1.17-beta1-selinux-label.patch => krb5-1.18-beta1-selinux-label.patch (92%) rename krb5-1.12.1-pam.patch => krb5-1.18beta1-pam.patch (96%) diff --git a/.gitignore b/.gitignore index 045b4dc..9c30463 100644 --- a/.gitignore +++ b/.gitignore @@ -177,3 +177,5 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.17.tar.gz.asc /krb5-1.17.1.tar.gz /krb5-1.17.1.tar.gz.asc +/krb5-1.18-beta1.tar.gz +/krb5-1.18-beta1.tar.gz.asc diff --git a/Add-dns_canonicalize_hostname-fallback-support.patch b/Add-dns_canonicalize_hostname-fallback-support.patch deleted file mode 100644 index f9bc3d3..0000000 --- a/Add-dns_canonicalize_hostname-fallback-support.patch +++ /dev/null @@ -1,409 +0,0 @@ -From b952b5ac5301ed9f4ae49300e90631ae0562b012 Mon Sep 17 00:00:00 2001 -From: Simo Sorce -Date: Tue, 4 Dec 2018 15:22:55 -0500 -Subject: [PATCH] Add dns_canonicalize_hostname=fallback support - -Turn dns_canonicalize_hostname into a tristate variable, allowing the -value "fallback" as well as the true/false booleans. If it is set to -fallback, delay DNS canonicalization and attempt it only in -krb5_get_credentials() if the KDC responds that the requested server -principal name is unknown. - -[ghudson@mit.edu: added TGS tests; refactored code; edited commit -message and documentation] - -ticket: 8765 (new) -(cherry picked from commit 6c20cb1c89acaa03db897182a3b28d5f8f284907) ---- - doc/admin/conf_files/krb5_conf.rst | 4 ++ - src/include/k5-int.h | 8 ++- - src/include/k5-trace.h | 3 ++ - src/lib/krb5/krb/get_creds.c | 79 ++++++++++++++++++++++++++---- - src/lib/krb5/krb/init_ctx.c | 27 +++++++++- - src/lib/krb5/krb/t_copy_context.c | 2 +- - src/lib/krb5/os/os-proto.h | 4 ++ - src/lib/krb5/os/sn2princ.c | 19 +++++-- - src/tests/gcred.c | 5 +- - src/tests/t_sn2princ.py | 34 ++++++++++++- - 10 files changed, 167 insertions(+), 18 deletions(-) - -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 4adb084a6..d1e1a222d 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -195,6 +195,10 @@ The libdefaults section may contain any of the following relations: - means that short hostnames will not be canonicalized to - fully-qualified hostnames. The default value is true. - -+ If this option is set to ``fallback`` (new in release 1.18), DNS -+ canonicalization will only be performed the server hostname is not -+ found with the original name when requesting credentials. -+ - **dns_lookup_kdc** - Indicate whether DNS SRV records should be used to locate the KDCs - and other servers for a realm, if they are not listed in the -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 255cee822..1e6a739e9 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -1159,6 +1159,12 @@ k5_plugin_register_dyn(krb5_context context, int interface_id, - void - k5_plugin_free_context(krb5_context context); - -+enum dns_canonhost { -+ CANONHOST_FALSE = 0, -+ CANONHOST_TRUE = 1, -+ CANONHOST_FALLBACK = 2 -+}; -+ - struct _kdb5_dal_handle; /* private, in kdb5.h */ - typedef struct _kdb5_dal_handle kdb5_dal_handle; - struct _kdb_log_context; -@@ -1222,7 +1228,7 @@ struct _krb5_context { - - krb5_boolean allow_weak_crypto; - krb5_boolean ignore_acceptor_hostname; -- krb5_boolean dns_canonicalize_hostname; -+ enum dns_canonhost dns_canonicalize_hostname; - - krb5_trace_callback trace_callback; - void *trace_callback_data; -diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h -index 2aa379b76..f3ed6a45d 100644 ---- a/src/include/k5-trace.h -+++ b/src/include/k5-trace.h -@@ -191,6 +191,9 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); - #define TRACE_FAST_REQUIRED(c) \ - TRACE(c, "Using FAST due to KRB5_FAST_REQUIRED flag") - -+#define TRACE_GET_CREDS_FALLBACK(c, hostname) \ -+ TRACE(c, "Falling back to canonicalized server hostname {str}", hostname) -+ - #define TRACE_GIC_PWD_CHANGED(c) \ - TRACE(c, "Getting initial TGT with changed password") - #define TRACE_GIC_PWD_CHANGEPW(c, tries) \ -diff --git a/src/lib/krb5/krb/get_creds.c b/src/lib/krb5/krb/get_creds.c -index 69900adfa..0a04d68b9 100644 ---- a/src/lib/krb5/krb/get_creds.c -+++ b/src/lib/krb5/krb/get_creds.c -@@ -39,6 +39,7 @@ - - #include "k5-int.h" - #include "int-proto.h" -+#include "os-proto.h" - #include "fast.h" - - /* -@@ -1249,6 +1250,26 @@ krb5_tkt_creds_step(krb5_context context, krb5_tkt_creds_context ctx, - return EINVAL; - } - -+static krb5_error_code -+try_get_creds(krb5_context context, krb5_flags options, krb5_ccache ccache, -+ krb5_creds *in_creds, krb5_creds *creds_out) -+{ -+ krb5_error_code code; -+ krb5_tkt_creds_context ctx = NULL; -+ -+ code = krb5_tkt_creds_init(context, ccache, in_creds, options, &ctx); -+ if (code) -+ goto cleanup; -+ code = krb5_tkt_creds_get(context, ctx); -+ if (code) -+ goto cleanup; -+ code = krb5_tkt_creds_get_creds(context, ctx, creds_out); -+ -+cleanup: -+ krb5_tkt_creds_free(context, ctx); -+ return code; -+} -+ - krb5_error_code KRB5_CALLCONV - krb5_get_credentials(krb5_context context, krb5_flags options, - krb5_ccache ccache, krb5_creds *in_creds, -@@ -1256,7 +1277,10 @@ krb5_get_credentials(krb5_context context, krb5_flags options, - { - krb5_error_code code; - krb5_creds *ncreds = NULL; -- krb5_tkt_creds_context ctx = NULL; -+ krb5_creds canon_creds, store_creds; -+ krb5_principal_data canon_server; -+ krb5_data canon_components[2]; -+ char *hostname = NULL, *canon_hostname = NULL; - - *out_creds = NULL; - -@@ -1265,22 +1289,59 @@ krb5_get_credentials(krb5_context context, krb5_flags options, - if (ncreds == NULL) - goto cleanup; - -- /* Make and execute a krb5_tkt_creds context to get the credential. */ -- code = krb5_tkt_creds_init(context, ccache, in_creds, options, &ctx); -- if (code != 0) -+ code = try_get_creds(context, options, ccache, in_creds, ncreds); -+ if (!code) { -+ *out_creds = ncreds; -+ return 0; -+ } -+ -+ /* Possibly try again with the canonicalized hostname, if the server is -+ * host-based and we are configured for fallback canonicalization. */ -+ if (code != KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN) - goto cleanup; -- code = krb5_tkt_creds_get(context, ctx); -- if (code != 0) -+ if (context->dns_canonicalize_hostname != CANONHOST_FALLBACK) - goto cleanup; -- code = krb5_tkt_creds_get_creds(context, ctx, ncreds); -- if (code != 0) -+ if (in_creds->server->type != KRB5_NT_SRV_HST || -+ in_creds->server->length != 2) - goto cleanup; - -+ hostname = k5memdup0(in_creds->server->data[1].data, -+ in_creds->server->data[1].length, &code); -+ if (hostname == NULL) -+ goto cleanup; -+ code = k5_expand_hostname(context, hostname, TRUE, &canon_hostname); -+ if (code) -+ goto cleanup; -+ -+ TRACE_GET_CREDS_FALLBACK(context, canon_hostname); -+ -+ /* Make shallow copies of in_creds and its server to alter the hostname. */ -+ canon_components[0] = in_creds->server->data[0]; -+ canon_components[1] = string2data(canon_hostname); -+ canon_server = *in_creds->server; -+ canon_server.data = canon_components; -+ canon_creds = *in_creds; -+ canon_creds.server = &canon_server; -+ -+ code = try_get_creds(context, options | KRB5_GC_NO_STORE, ccache, -+ &canon_creds, ncreds); -+ if (code) -+ goto cleanup; -+ -+ if (!(options & KRB5_GC_NO_STORE)) { -+ /* Store the creds under the originally requested server name. The -+ * ccache layer will also store them under the ticket server name. */ -+ store_creds = *ncreds; -+ store_creds.server = in_creds->server; -+ (void)krb5_cc_store_cred(context, ccache, &store_creds); -+ } -+ - *out_creds = ncreds; - ncreds = NULL; - - cleanup: -+ free(hostname); -+ free(canon_hostname); - krb5_free_creds(context, ncreds); -- krb5_tkt_creds_free(context, ctx); - return code; - } -diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index 947e50400..d263d5cc5 100644 ---- a/src/lib/krb5/krb/init_ctx.c -+++ b/src/lib/krb5/krb/init_ctx.c -@@ -101,6 +101,30 @@ get_boolean(krb5_context ctx, const char *name, int def_val, int *boolean_out) - return retval; - } - -+static krb5_error_code -+get_tristate(krb5_context ctx, const char *name, const char *third_option, -+ int third_option_val, int def_val, int *val_out) -+{ -+ krb5_error_code retval; -+ char *str; -+ int match; -+ -+ retval = profile_get_boolean(ctx->profile, KRB5_CONF_LIBDEFAULTS, name, -+ NULL, def_val, val_out); -+ if (retval != PROF_BAD_BOOLEAN) -+ return retval; -+ retval = profile_get_string(ctx->profile, KRB5_CONF_LIBDEFAULTS, name, -+ NULL, NULL, &str); -+ if (retval) -+ return retval; -+ match = (strcasecmp(third_option, str) == 0); -+ free(str); -+ if (!match) -+ return EINVAL; -+ *val_out = third_option_val; -+ return 0; -+} -+ - krb5_error_code KRB5_CALLCONV - krb5_init_context(krb5_context *context) - { -@@ -213,7 +237,8 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, - goto cleanup; - ctx->ignore_acceptor_hostname = tmp; - -- retval = get_boolean(ctx, KRB5_CONF_DNS_CANONICALIZE_HOSTNAME, 1, &tmp); -+ retval = get_tristate(ctx, KRB5_CONF_DNS_CANONICALIZE_HOSTNAME, "fallback", -+ CANONHOST_FALLBACK, 1, &tmp); - if (retval) - goto cleanup; - ctx->dns_canonicalize_hostname = tmp; -diff --git a/src/lib/krb5/krb/t_copy_context.c b/src/lib/krb5/krb/t_copy_context.c -index fa810be8a..a6e48cd25 100644 ---- a/src/lib/krb5/krb/t_copy_context.c -+++ b/src/lib/krb5/krb/t_copy_context.c -@@ -145,7 +145,7 @@ main(int argc, char **argv) - ctx->udp_pref_limit = 2345; - ctx->use_conf_ktypes = TRUE; - ctx->ignore_acceptor_hostname = TRUE; -- ctx->dns_canonicalize_hostname = FALSE; -+ ctx->dns_canonicalize_hostname = CANONHOST_FALSE; - free(ctx->plugin_base_dir); - check((ctx->plugin_base_dir = strdup("/a/b/c/d")) != NULL); - -diff --git a/src/lib/krb5/os/os-proto.h b/src/lib/krb5/os/os-proto.h -index 634e82d70..066d30221 100644 ---- a/src/lib/krb5/os/os-proto.h -+++ b/src/lib/krb5/os/os-proto.h -@@ -83,6 +83,10 @@ struct sendto_callback_info { - void *data; - }; - -+krb5_error_code k5_expand_hostname(krb5_context context, const char *host, -+ krb5_boolean is_fallback, -+ char **canonhost_out); -+ - krb5_error_code k5_locate_server(krb5_context, const krb5_data *realm, - struct serverlist *serverlist, - enum locate_service_type svc, -diff --git a/src/lib/krb5/os/sn2princ.c b/src/lib/krb5/os/sn2princ.c -index 5932fd9b3..98d2600aa 100644 ---- a/src/lib/krb5/os/sn2princ.c -+++ b/src/lib/krb5/os/sn2princ.c -@@ -53,19 +53,23 @@ use_reverse_dns(krb5_context context) - return value; - } - --krb5_error_code KRB5_CALLCONV --krb5_expand_hostname(krb5_context context, const char *host, -- char **canonhost_out) -+krb5_error_code -+k5_expand_hostname(krb5_context context, const char *host, -+ krb5_boolean is_fallback, char **canonhost_out) - { - struct addrinfo *ai = NULL, hint; - char namebuf[NI_MAXHOST], *copy, *p; - int err; - const char *canonhost; -+ krb5_boolean use_dns; - - *canonhost_out = NULL; - - canonhost = host; -- if (context->dns_canonicalize_hostname) { -+ use_dns = (context->dns_canonicalize_hostname == CANONHOST_TRUE || -+ (is_fallback && -+ context->dns_canonicalize_hostname == CANONHOST_FALLBACK)); -+ if (use_dns) { - /* Try a forward lookup of the hostname. */ - memset(&hint, 0, sizeof(hint)); - hint.ai_flags = AI_CANONNAME; -@@ -112,6 +116,13 @@ cleanup: - return (*canonhost_out == NULL) ? ENOMEM : 0; - } - -+krb5_error_code KRB5_CALLCONV -+krb5_expand_hostname(krb5_context context, const char *host, -+ char **canonhost_out) -+{ -+ return k5_expand_hostname(context, host, FALSE, canonhost_out); -+} -+ - /* If hostname appears to have a :port or :instance trailer (used in MSSQLSvc - * principals), return a pointer to the separator. Otherwise return NULL. */ - static const char * -diff --git a/src/tests/gcred.c b/src/tests/gcred.c -index b14e4fc9a..cac524c51 100644 ---- a/src/tests/gcred.c -+++ b/src/tests/gcred.c -@@ -66,6 +66,7 @@ main(int argc, char **argv) - krb5_principal client, server; - krb5_ccache ccache; - krb5_creds in_creds, *creds; -+ krb5_ticket *ticket; - krb5_flags options = 0; - char *name; - int c; -@@ -102,9 +103,11 @@ main(int argc, char **argv) - in_creds.client = client; - in_creds.server = server; - check(krb5_get_credentials(ctx, options, ccache, &in_creds, &creds)); -- check(krb5_unparse_name(ctx, creds->server, &name)); -+ check(krb5_decode_ticket(&creds->ticket, &ticket)); -+ check(krb5_unparse_name(ctx, ticket->server, &name)); - printf("%s\n", name); - -+ krb5_free_ticket(ctx, ticket); - krb5_free_unparsed_name(ctx, name); - krb5_free_creds(ctx, creds); - krb5_free_principal(ctx, client); -diff --git a/src/tests/t_sn2princ.py b/src/tests/t_sn2princ.py -index 1ffda51f4..fe435a2d5 100755 ---- a/src/tests/t_sn2princ.py -+++ b/src/tests/t_sn2princ.py -@@ -7,10 +7,15 @@ conf = {'domain_realm': {'kerberos.org': 'R1', - 'mit.edu': 'R3'}} - no_rdns_conf = {'libdefaults': {'rdns': 'false'}} - no_canon_conf = {'libdefaults': {'dns_canonicalize_hostname': 'false'}} -+fallback_canon_conf = {'libdefaults': -+ {'rdns': 'false', -+ 'dns_canonicalize_hostname': 'fallback'}} - --realm = K5Realm(create_kdb=False, krb5_conf=conf) -+realm = K5Realm(realm='R1', create_host=False, krb5_conf=conf) - no_rdns = realm.special_env('no_rdns', False, krb5_conf=no_rdns_conf) - no_canon = realm.special_env('no_canon', False, krb5_conf=no_canon_conf) -+fallback_canon = realm.special_env('fallback_canon', False, -+ krb5_conf=fallback_canon_conf) - - def testbase(host, nametype, princhost, princrealm, env=None): - # Run the sn2princ harness with a specified host and name type and -@@ -37,6 +42,10 @@ def testu(host, princhost, princrealm): - # Test with the unknown name type. - testbase(host, 'unknown', princhost, princrealm) - -+def testfc(host, princhost, princrealm): -+ # Test with the host-based name type with canonicalization fallback. -+ testbase(host, 'srv-hst', princhost, princrealm, env=fallback_canon) -+ - # With the unknown principal type, we do not canonicalize or downcase, - # but we do remove a trailing period and look up the realm. - mark('unknown type') -@@ -71,6 +80,29 @@ if offline: - oname = 'ptr-mismatch.kerberos.org' - fname = 'www.kerberos.org' - -+# Test fallback canonicalization krb5_sname_to_principal() results -+# (same as dns_canonicalize_hostname=false). -+mark('dns_canonicalize_host=fallback') -+testfc(oname, oname, 'R1') -+ -+# Test fallback canonicalization in krb5_get_credentials(). -+oprinc = 'host/' + oname -+fprinc = 'host/' + fname -+shutil.copy(realm.ccache, realm.ccache + '.save') -+realm.addprinc(fprinc) -+# oprinc doesn't exist, so we get the canonicalized fprinc as a fallback. -+msgs = ('Falling back to canonicalized server hostname ' + fname,) -+realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon, -+ expected_msg=fprinc, expected_trace=msgs) -+realm.addprinc(oprinc) -+# oprinc now exists, but we still get the fprinc ticket from the cache. -+realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon, -+ expected_msg=fprinc) -+# Without the cached result, we sould get oprinc in preference to fprinc. -+os.rename(realm.ccache + '.save', realm.ccache) -+realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon, -+ expected_msg=oprinc) -+ - # Verify forward resolution before testing for it. - try: - ai = socket.getaddrinfo(oname, None, 0, 0, 0, socket.AI_CANONNAME) diff --git a/Add-function-and-enctype-flag-for-deprecations.patch b/Add-function-and-enctype-flag-for-deprecations.patch deleted file mode 100644 index 1e15da3..0000000 --- a/Add-function-and-enctype-flag-for-deprecations.patch +++ /dev/null @@ -1,183 +0,0 @@ -From 397ce771e195edf63f796f1cf917bc65b4eafd8c Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 15 Jan 2019 16:16:57 -0500 -Subject: [PATCH] Add function and enctype flag for deprecations - -krb5int_c_deprecated_enctype() checks for the ETYPE_DEPRECATED flag on -enctypes. All ENCTYPE_WEAK enctypes are currently deprecated; not all -deprecated enctypes are considered weak. Deprecations follow RFC 6649 -and RFC 8429. - -(cherry picked from commit 484a6e7712f9b66e782b2520f07b0883889e116f) ---- - src/include/k5-int.h | 1 + - src/lib/crypto/krb/crypto_int.h | 9 ++++++++- - src/lib/crypto/krb/enctype_util.c | 7 +++++++ - src/lib/crypto/krb/etypes.c | 19 ++++++++++--------- - src/lib/crypto/libk5crypto.exports | 1 + - src/lib/krb5_32.def | 3 +++ - 6 files changed, 30 insertions(+), 10 deletions(-) - -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 8f9329c59..255cee822 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -2077,6 +2077,7 @@ krb5_get_tgs_ktypes(krb5_context, krb5_const_principal, krb5_enctype **); - krb5_boolean krb5_is_permitted_enctype(krb5_context, krb5_enctype); - - krb5_boolean KRB5_CALLCONV krb5int_c_weak_enctype(krb5_enctype); -+krb5_boolean KRB5_CALLCONV krb5int_c_deprecated_enctype(krb5_enctype); - krb5_error_code k5_enctype_to_ssf(krb5_enctype enctype, unsigned int *ssf_out); - - krb5_error_code krb5_kdc_rep_decrypt_proc(krb5_context, const krb5_keyblock *, -diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h -index e5099291e..6c1c77cac 100644 ---- a/src/lib/crypto/krb/crypto_int.h -+++ b/src/lib/crypto/krb/crypto_int.h -@@ -114,7 +114,14 @@ struct krb5_keytypes { - unsigned int ssf; - }; - --#define ETYPE_WEAK 1 -+/* -+ * "Weak" means the enctype is believed to be vulnerable to practical attacks, -+ * and will be disabled unless allow_weak_crypto is set to true. "Deprecated" -+ * means the enctype has been deprecated by the IETF, and affects display and -+ * logging. -+ */ -+#define ETYPE_WEAK (1 << 0) -+#define ETYPE_DEPRECATED (1 << 1) - - extern const struct krb5_keytypes krb5int_enctypes_list[]; - extern const int krb5int_enctypes_length; -diff --git a/src/lib/crypto/krb/enctype_util.c b/src/lib/crypto/krb/enctype_util.c -index b1b40e7ec..e394f4e19 100644 ---- a/src/lib/crypto/krb/enctype_util.c -+++ b/src/lib/crypto/krb/enctype_util.c -@@ -51,6 +51,13 @@ krb5int_c_weak_enctype(krb5_enctype etype) - return (ktp != NULL && (ktp->flags & ETYPE_WEAK) != 0); - } - -+krb5_boolean KRB5_CALLCONV -+krb5int_c_deprecated_enctype(krb5_enctype etype) -+{ -+ const struct krb5_keytypes *ktp = find_enctype(etype); -+ return ktp != NULL && (ktp->flags & ETYPE_DEPRECATED) != 0; -+} -+ - krb5_error_code KRB5_CALLCONV - krb5_c_enctype_compare(krb5_context context, krb5_enctype e1, krb5_enctype e2, - krb5_boolean *similar) -diff --git a/src/lib/crypto/krb/etypes.c b/src/lib/crypto/krb/etypes.c -index 53d4a5c79..8f44c37e7 100644 ---- a/src/lib/crypto/krb/etypes.c -+++ b/src/lib/crypto/krb/etypes.c -@@ -33,6 +33,7 @@ - that the keytypes are all near each other. I'd rather not make - that assumption. */ - -+/* Deprecations come from RFC 6649 and RFC 8249. */ - const struct krb5_keytypes krb5int_enctypes_list[] = { - { ENCTYPE_DES_CBC_CRC, - "des-cbc-crc", { 0 }, "DES cbc mode with CRC-32", -@@ -42,7 +43,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_des_string_to_key, k5_rand2key_des, - krb5int_des_prf, - CKSUMTYPE_RSA_MD5_DES, -- ETYPE_WEAK, 56 }, -+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, - { ENCTYPE_DES_CBC_MD4, - "des-cbc-md4", { 0 }, "DES cbc mode with RSA-MD4", - &krb5int_enc_des, &krb5int_hash_md4, -@@ -51,7 +52,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_des_string_to_key, k5_rand2key_des, - krb5int_des_prf, - CKSUMTYPE_RSA_MD4_DES, -- ETYPE_WEAK, 56 }, -+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, - { ENCTYPE_DES_CBC_MD5, - "des-cbc-md5", { "des" }, "DES cbc mode with RSA-MD5", - &krb5int_enc_des, &krb5int_hash_md5, -@@ -60,7 +61,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_des_string_to_key, k5_rand2key_des, - krb5int_des_prf, - CKSUMTYPE_RSA_MD5_DES, -- ETYPE_WEAK, 56 }, -+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, - { ENCTYPE_DES_CBC_RAW, - "des-cbc-raw", { 0 }, "DES cbc mode raw", - &krb5int_enc_des, NULL, -@@ -69,7 +70,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_des_string_to_key, k5_rand2key_des, - krb5int_des_prf, - 0, -- ETYPE_WEAK, 56 }, -+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, - { ENCTYPE_DES3_CBC_RAW, - "des3-cbc-raw", { 0 }, "Triple DES cbc mode raw", - &krb5int_enc_des3, NULL, -@@ -78,7 +79,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_dk_string_to_key, k5_rand2key_des3, - NULL, /*PRF*/ - 0, -- ETYPE_WEAK, 112 }, -+ ETYPE_WEAK | ETYPE_DEPRECATED, 112 }, - - { ENCTYPE_DES3_CBC_SHA1, - "des3-cbc-sha1", { "des3-hmac-sha1", "des3-cbc-sha1-kd" }, -@@ -89,7 +90,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_dk_string_to_key, k5_rand2key_des3, - krb5int_dk_prf, - CKSUMTYPE_HMAC_SHA1_DES3, -- 0 /*flags*/, 112 }, -+ ETYPE_DEPRECATED, 112 }, - - { ENCTYPE_DES_HMAC_SHA1, - "des-hmac-sha1", { 0 }, "DES with HMAC/sha1", -@@ -99,7 +100,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_dk_string_to_key, k5_rand2key_des, - NULL, /*PRF*/ - 0, -- ETYPE_WEAK, 56 }, -+ ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, - - /* rc4-hmac uses a 128-bit key, but due to weaknesses in the RC4 cipher, we - * consider its strength degraded and assign it an SSF value of 64. */ -@@ -113,7 +114,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_arcfour_decrypt, krb5int_arcfour_string_to_key, - k5_rand2key_direct, krb5int_arcfour_prf, - CKSUMTYPE_HMAC_MD5_ARCFOUR, -- 0 /*flags*/, 64 }, -+ ETYPE_DEPRECATED, 64 }, - { ENCTYPE_ARCFOUR_HMAC_EXP, - "arcfour-hmac-exp", { "rc4-hmac-exp", "arcfour-hmac-md5-exp" }, - "Exportable ArcFour with HMAC/md5", -@@ -124,7 +125,7 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - krb5int_arcfour_decrypt, krb5int_arcfour_string_to_key, - k5_rand2key_direct, krb5int_arcfour_prf, - CKSUMTYPE_HMAC_MD5_ARCFOUR, -- ETYPE_WEAK, 40 -+ ETYPE_WEAK | ETYPE_DEPRECATED, 40 - }, - - { ENCTYPE_AES128_CTS_HMAC_SHA1_96, -diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports -index 82eb5f30c..90afdf5f7 100644 ---- a/src/lib/crypto/libk5crypto.exports -+++ b/src/lib/crypto/libk5crypto.exports -@@ -109,3 +109,4 @@ k5_allow_weak_pbkdf2iter - krb5_c_prfplus - krb5_c_derive_prfplus - k5_enctype_to_ssf -+krb5int_c_deprecated_enctype -diff --git a/src/lib/krb5_32.def b/src/lib/krb5_32.def -index c35022931..e6a487593 100644 ---- a/src/lib/krb5_32.def -+++ b/src/lib/krb5_32.def -@@ -487,3 +487,6 @@ EXPORTS - encode_krb5_pa_spake @444 ; PRIVATE - decode_krb5_pa_spake @445 ; PRIVATE - k5_free_pa_spake @446 ; PRIVATE -+ -+; new in 1.18 -+ krb5int_c_deprecated_enctype @450 ; PRIVATE diff --git a/Add-missing-newlines-to-deprecation-warnings.patch b/Add-missing-newlines-to-deprecation-warnings.patch deleted file mode 100644 index ecfe47b..0000000 --- a/Add-missing-newlines-to-deprecation-warnings.patch +++ /dev/null @@ -1,37 +0,0 @@ -From 6946ea68b719da8434fc4c09b4ed97be91d8464b Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 21 May 2019 12:52:26 -0400 -Subject: [PATCH] Add missing newlines to deprecation warnings - -Commit 8d8e68283b599e680f9fe45eff8af397e827bd6c omitted newlines in -two warning messages sent to stderr. Add them now. - -ticket: 8773 -(cherry picked from commit 274fee295d1429668b31c6ed898fc5d11a7e3589) ---- - src/kdc/main.c | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - -diff --git a/src/kdc/main.c b/src/kdc/main.c -index 04393772f..1596c1c5b 100644 ---- a/src/kdc/main.c -+++ b/src/kdc/main.c -@@ -223,7 +223,8 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm, - if (krb5_enctype_to_name(def_enctype, FALSE, ename, sizeof(ename))) - ename[0] = '\0'; - fprintf(stderr, -- _("Requested master password enctype %s in %s is DEPRECATED!"), -+ _("Requested master password enctype %s in %s is " -+ "DEPRECATED!\n"), - ename, realm); - } - -@@ -385,7 +386,7 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm, - if (krb5_enctype_to_name(rdp->realm_mkey.enctype, FALSE, ename, - sizeof(ename))) - ename[0] = '\0'; -- fprintf(stderr, _("Stash file %s uses DEPRECATED enctype %s!"), -+ fprintf(stderr, _("Stash file %s uses DEPRECATED enctype %s!\n"), - rdp->realm_stash, ename); - } - diff --git a/Add-soft-pkcs11-source-code.patch b/Add-soft-pkcs11-source-code.patch deleted file mode 100644 index ef8dc9d..0000000 --- a/Add-soft-pkcs11-source-code.patch +++ /dev/null @@ -1,2071 +0,0 @@ -From 5ede44dfeffca55c793fe5ea49b438497dff027b Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 20 Jun 2019 10:45:18 -0400 -Subject: [PATCH] Add soft-pkcs11 source code - -soft-pkcs11 is no longer available upstream and is not generally -packaged in distributions, making it inconvenient to use for tests. -Import the 1.8 source code, detabified and with trailing whitespace -removed but otherwise unmodified. - -(cherry picked from commit a4bc3e513a58b0d1292f3506ac3b35be8c178086) ---- - src/tests/softpkcs11/main.c | 2049 +++++++++++++++++++++++++++++++++++ - 1 file changed, 2049 insertions(+) - create mode 100644 src/tests/softpkcs11/main.c - -diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c -new file mode 100644 -index 000000000..2acec5169 ---- /dev/null -+++ b/src/tests/softpkcs11/main.c -@@ -0,0 +1,2049 @@ -+/* -+ * Copyright (c) 2004-2006, Stockholms universitet -+ * (Stockholm University, Stockholm Sweden) -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * 1. Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * 2. Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in the -+ * documentation and/or other materials provided with the distribution. -+ * -+ * 3. Neither the name of the university nor the names of its contributors -+ * may be used to endorse or promote products derived from this software -+ * without specific prior written permission. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" -+ * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE -+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE -+ * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE -+ * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR -+ * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF -+ * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS -+ * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN -+ * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE -+ * POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include "locl.h" -+ -+/* RCSID("$Id: main.c,v 1.24 2006/01/11 12:42:53 lha Exp $"); */ -+ -+#define OBJECT_ID_MASK 0xfff -+#define HANDLE_OBJECT_ID(h) ((h) & OBJECT_ID_MASK) -+#define OBJECT_ID(obj) HANDLE_OBJECT_ID((obj)->object_handle) -+ -+struct st_attr { -+ CK_ATTRIBUTE attribute; -+ int secret; -+}; -+ -+struct st_object { -+ CK_OBJECT_HANDLE object_handle; -+ struct st_attr *attrs; -+ int num_attributes; -+ enum { -+ STO_T_CERTIFICATE, -+ STO_T_PRIVATE_KEY, -+ STO_T_PUBLIC_KEY -+ } type; -+ union { -+ X509 *cert; -+ EVP_PKEY *public_key; -+ struct { -+ const char *file; -+ EVP_PKEY *key; -+ X509 *cert; -+ } private_key; -+ } u; -+}; -+ -+static struct soft_token { -+ CK_VOID_PTR application; -+ CK_NOTIFY notify; -+ struct { -+ struct st_object **objs; -+ int num_objs; -+ } object; -+ struct { -+ int hardware_slot; -+ int app_error_fatal; -+ int login_done; -+ } flags; -+ int open_sessions; -+ struct session_state { -+ CK_SESSION_HANDLE session_handle; -+ -+ struct { -+ CK_ATTRIBUTE *attributes; -+ CK_ULONG num_attributes; -+ int next_object; -+ } find; -+ -+ int encrypt_object; -+ CK_MECHANISM_PTR encrypt_mechanism; -+ int decrypt_object; -+ CK_MECHANISM_PTR decrypt_mechanism; -+ int sign_object; -+ CK_MECHANISM_PTR sign_mechanism; -+ int verify_object; -+ CK_MECHANISM_PTR verify_mechanism; -+ int digest_object; -+ } state[10]; -+#define MAX_NUM_SESSION (sizeof(soft_token.state)/sizeof(soft_token.state[0])) -+ FILE *logfile; -+} soft_token; -+ -+static void -+application_error(const char *fmt, ...) -+{ -+ va_list ap; -+ va_start(ap, fmt); -+ vprintf(fmt, ap); -+ va_end(ap); -+ if (soft_token.flags.app_error_fatal) -+ abort(); -+} -+ -+static void -+st_logf(const char *fmt, ...) -+{ -+ va_list ap; -+ if (soft_token.logfile == NULL) -+ return; -+ va_start(ap, fmt); -+ vfprintf(soft_token.logfile, fmt, ap); -+ va_end(ap); -+ fflush(soft_token.logfile); -+} -+ -+static void -+snprintf_fill(char *str, size_t size, char fillchar, const char *fmt, ...) -+{ -+ int len; -+ va_list ap; -+ len = vsnprintf(str, size, fmt, ap); -+ va_end(ap); -+ if (len < 0 || len > size) -+ return; -+ while(len < size) -+ str[len++] = fillchar; -+} -+ -+#ifndef TEST_APP -+#define printf error_use_st_logf -+#endif -+ -+#define VERIFY_SESSION_HANDLE(s, state) \ -+{ \ -+ CK_RV ret; \ -+ ret = verify_session_handle(s, state); \ -+ if (ret != CKR_OK) { \ -+ /* return CKR_OK */; \ -+ } \ -+} -+ -+static CK_RV -+verify_session_handle(CK_SESSION_HANDLE hSession, -+ struct session_state **state) -+{ -+ int i; -+ -+ for (i = 0; i < MAX_NUM_SESSION; i++){ -+ if (soft_token.state[i].session_handle == hSession) -+ break; -+ } -+ if (i == MAX_NUM_SESSION) { -+ application_error("use of invalid handle: 0x%08lx\n", -+ (unsigned long)hSession); -+ return CKR_SESSION_HANDLE_INVALID; -+ } -+ if (state) -+ *state = &soft_token.state[i]; -+ return CKR_OK; -+} -+ -+static CK_RV -+object_handle_to_object(CK_OBJECT_HANDLE handle, -+ struct st_object **object) -+{ -+ int i = HANDLE_OBJECT_ID(handle); -+ -+ *object = NULL; -+ if (i >= soft_token.object.num_objs) -+ return CKR_ARGUMENTS_BAD; -+ if (soft_token.object.objs[i] == NULL) -+ return CKR_ARGUMENTS_BAD; -+ if (soft_token.object.objs[i]->object_handle != handle) -+ return CKR_ARGUMENTS_BAD; -+ *object = soft_token.object.objs[i]; -+ return CKR_OK; -+} -+ -+static int -+attributes_match(const struct st_object *obj, -+ const CK_ATTRIBUTE *attributes, -+ CK_ULONG num_attributes) -+{ -+ CK_ULONG i; -+ int j; -+ st_logf("attributes_match: %ld\n", (unsigned long)OBJECT_ID(obj)); -+ -+ for (i = 0; i < num_attributes; i++) { -+ int match = 0; -+ for (j = 0; j < obj->num_attributes; j++) { -+ if (attributes[i].type == obj->attrs[j].attribute.type && -+ attributes[i].ulValueLen == obj->attrs[j].attribute.ulValueLen && -+ memcmp(attributes[i].pValue, obj->attrs[j].attribute.pValue, -+ attributes[i].ulValueLen) == 0) { -+ match = 1; -+ break; -+ } -+ } -+ if (match == 0) { -+ st_logf("type %d attribute have no match\n", attributes[i].type); -+ return 0; -+ } -+ } -+ st_logf("attribute matches\n"); -+ return 1; -+} -+ -+static void -+print_attributes(const CK_ATTRIBUTE *attributes, -+ CK_ULONG num_attributes) -+{ -+ CK_ULONG i; -+ -+ st_logf("find objects: attrs: %lu\n", (unsigned long)num_attributes); -+ -+ for (i = 0; i < num_attributes; i++) { -+ st_logf(" type: "); -+ switch (attributes[i].type) { -+ case CKA_TOKEN: { -+ CK_BBOOL *ck_true; -+ if (attributes[i].ulValueLen != sizeof(CK_BBOOL)) { -+ application_error("token attribute wrong length\n"); -+ break; -+ } -+ ck_true = attributes[i].pValue; -+ st_logf("token: %s", *ck_true ? "TRUE" : "FALSE"); -+ break; -+ } -+ case CKA_CLASS: { -+ CK_OBJECT_CLASS *class; -+ if (attributes[i].ulValueLen != sizeof(CK_ULONG)) { -+ application_error("class attribute wrong length\n"); -+ break; -+ } -+ class = attributes[i].pValue; -+ st_logf("class "); -+ switch (*class) { -+ case CKO_CERTIFICATE: -+ st_logf("certificate"); -+ break; -+ case CKO_PUBLIC_KEY: -+ st_logf("public key"); -+ break; -+ case CKO_PRIVATE_KEY: -+ st_logf("private key"); -+ break; -+ case CKO_SECRET_KEY: -+ st_logf("secret key"); -+ break; -+ case CKO_DOMAIN_PARAMETERS: -+ st_logf("domain parameters"); -+ break; -+ default: -+ st_logf("[class %lx]", (long unsigned)*class); -+ break; -+ } -+ break; -+ } -+ case CKA_PRIVATE: -+ st_logf("private"); -+ break; -+ case CKA_LABEL: -+ st_logf("label"); -+ break; -+ case CKA_APPLICATION: -+ st_logf("application"); -+ break; -+ case CKA_VALUE: -+ st_logf("value"); -+ break; -+ case CKA_ID: -+ st_logf("id"); -+ break; -+ default: -+ st_logf("[unknown 0x%08lx]", (unsigned long)attributes[i].type); -+ break; -+ } -+ st_logf("\n"); -+ } -+} -+ -+static struct st_object * -+add_st_object(void) -+{ -+ struct st_object *o, **objs; -+ int i; -+ -+ o = malloc(sizeof(*o)); -+ if (o == NULL) -+ return NULL; -+ memset(o, 0, sizeof(*o)); -+ o->attrs = NULL; -+ o->num_attributes = 0; -+ -+ for (i = 0; i < soft_token.object.num_objs; i++) { -+ if (soft_token.object.objs == NULL) { -+ soft_token.object.objs[i] = o; -+ break; -+ } -+ } -+ if (i == soft_token.object.num_objs) { -+ objs = realloc(soft_token.object.objs, -+ (soft_token.object.num_objs + 1) * sizeof(soft_token.object.objs[0])); -+ if (objs == NULL) { -+ free(o); -+ return NULL; -+ } -+ soft_token.object.objs = objs; -+ soft_token.object.objs[soft_token.object.num_objs++] = o; -+ } -+ soft_token.object.objs[i]->object_handle = -+ (random() & (~OBJECT_ID_MASK)) | i; -+ -+ return o; -+} -+ -+static CK_RV -+add_object_attribute(struct st_object *o, -+ int secret, -+ CK_ATTRIBUTE_TYPE type, -+ CK_VOID_PTR pValue, -+ CK_ULONG ulValueLen) -+{ -+ struct st_attr *a; -+ int i; -+ -+ i = o->num_attributes; -+ a = realloc(o->attrs, (i + 1) * sizeof(o->attrs[0])); -+ if (a == NULL) -+ return CKR_DEVICE_MEMORY; -+ o->attrs = a; -+ o->attrs[i].secret = secret; -+ o->attrs[i].attribute.type = type; -+ o->attrs[i].attribute.pValue = malloc(ulValueLen); -+ if (o->attrs[i].attribute.pValue == NULL && ulValueLen != 0) -+ return CKR_DEVICE_MEMORY; -+ memcpy(o->attrs[i].attribute.pValue, pValue, ulValueLen); -+ o->attrs[i].attribute.ulValueLen = ulValueLen; -+ o->num_attributes++; -+ -+ return CKR_OK; -+} -+ -+static CK_RV -+add_pubkey_info(struct st_object *o, CK_KEY_TYPE key_type, EVP_PKEY *key) -+{ -+ switch (key_type) { -+ case CKK_RSA: { -+ CK_BYTE *modulus = NULL; -+ size_t modulus_len = 0; -+ CK_ULONG modulus_bits = 0; -+ CK_BYTE *exponent = NULL; -+ size_t exponent_len = 0; -+ -+ modulus_bits = BN_num_bits(key->pkey.rsa->n); -+ -+ modulus_len = BN_num_bytes(key->pkey.rsa->n); -+ modulus = malloc(modulus_len); -+ BN_bn2bin(key->pkey.rsa->n, modulus); -+ -+ exponent_len = BN_num_bytes(key->pkey.rsa->e); -+ exponent = malloc(exponent_len); -+ BN_bn2bin(key->pkey.rsa->e, exponent); -+ -+ add_object_attribute(o, 0, CKA_MODULUS, modulus, modulus_len); -+ add_object_attribute(o, 0, CKA_MODULUS_BITS, -+ &modulus_bits, sizeof(modulus_bits)); -+ add_object_attribute(o, 0, CKA_PUBLIC_EXPONENT, -+ exponent, exponent_len); -+ -+ RSA_set_method(key->pkey.rsa, RSA_PKCS1_SSLeay()); -+ -+ free(modulus); -+ free(exponent); -+ } -+ default: -+ /* XXX */ -+ break; -+ } -+ return CKR_OK; -+} -+ -+ -+static int -+pem_callback(char *buf, int num, int w, void *key) -+{ -+ return -1; -+} -+ -+ -+static CK_RV -+add_certificate(char *label, -+ const char *cert_file, -+ const char *private_key_file, -+ char *id, -+ int anchor) -+{ -+ struct st_object *o = NULL; -+ CK_BBOOL bool_true = CK_TRUE; -+ CK_BBOOL bool_false = CK_FALSE; -+ CK_OBJECT_CLASS c; -+ CK_CERTIFICATE_TYPE cert_type = CKC_X_509; -+ CK_KEY_TYPE key_type; -+ CK_MECHANISM_TYPE mech_type; -+ void *cert_data = NULL; -+ size_t cert_length; -+ void *subject_data = NULL; -+ size_t subject_length; -+ void *issuer_data = NULL; -+ size_t issuer_length; -+ void *serial_data = NULL; -+ size_t serial_length; -+ CK_RV ret = CKR_GENERAL_ERROR; -+ X509 *cert; -+ EVP_PKEY *public_key; -+ -+ size_t id_len = strlen(id); -+ -+ { -+ FILE *f; -+ -+ f = fopen(cert_file, "r"); -+ if (f == NULL) { -+ st_logf("failed to open file %s\n", cert_file); -+ return CKR_GENERAL_ERROR; -+ } -+ -+ cert = PEM_read_X509(f, NULL, NULL, NULL); -+ fclose(f); -+ if (cert == NULL) { -+ st_logf("failed reading PEM cert\n"); -+ return CKR_GENERAL_ERROR; -+ } -+ -+ OPENSSL_ASN1_MALLOC_ENCODE(X509, cert_data, cert_length, cert, ret); -+ if (ret) -+ goto out; -+ -+ OPENSSL_ASN1_MALLOC_ENCODE(X509_NAME, issuer_data, issuer_length, -+ X509_get_issuer_name(cert), ret); -+ if (ret) -+ goto out; -+ -+ OPENSSL_ASN1_MALLOC_ENCODE(X509_NAME, subject_data, subject_length, -+ X509_get_subject_name(cert), ret); -+ if (ret) -+ goto out; -+ -+ OPENSSL_ASN1_MALLOC_ENCODE(ASN1_INTEGER, serial_data, serial_length, -+ X509_get_serialNumber(cert), ret); -+ if (ret) -+ goto out; -+ -+ } -+ -+ st_logf("done parsing, adding to internal structure\n"); -+ -+ o = add_st_object(); -+ if (o == NULL) { -+ ret = CKR_DEVICE_MEMORY; -+ goto out; -+ } -+ o->type = STO_T_CERTIFICATE; -+ o->u.cert = cert; -+ public_key = X509_get_pubkey(o->u.cert); -+ -+ switch (EVP_PKEY_type(public_key->type)) { -+ case EVP_PKEY_RSA: -+ key_type = CKK_RSA; -+ break; -+ case EVP_PKEY_DSA: -+ key_type = CKK_DSA; -+ break; -+ default: -+ /* XXX */ -+ break; -+ } -+ -+ c = CKO_CERTIFICATE; -+ add_object_attribute(o, 0, CKA_CLASS, &c, sizeof(c)); -+ add_object_attribute(o, 0, CKA_TOKEN, &bool_true, sizeof(bool_true)); -+ add_object_attribute(o, 0, CKA_PRIVATE, &bool_false, sizeof(bool_false)); -+ add_object_attribute(o, 0, CKA_MODIFIABLE, &bool_false, sizeof(bool_false)); -+ add_object_attribute(o, 0, CKA_LABEL, label, strlen(label)); -+ -+ add_object_attribute(o, 0, CKA_CERTIFICATE_TYPE, &cert_type, sizeof(cert_type)); -+ add_object_attribute(o, 0, CKA_ID, id, id_len); -+ -+ add_object_attribute(o, 0, CKA_SUBJECT, subject_data, subject_length); -+ add_object_attribute(o, 0, CKA_ISSUER, issuer_data, issuer_length); -+ add_object_attribute(o, 0, CKA_SERIAL_NUMBER, serial_data, serial_length); -+ add_object_attribute(o, 0, CKA_VALUE, cert_data, cert_length); -+ if (anchor) -+ add_object_attribute(o, 0, CKA_TRUSTED, &bool_true, sizeof(bool_true)); -+ else -+ add_object_attribute(o, 0, CKA_TRUSTED, &bool_false, sizeof(bool_false)); -+ -+ st_logf("add cert ok: %lx\n", (unsigned long)OBJECT_ID(o)); -+ -+ o = add_st_object(); -+ if (o == NULL) { -+ ret = CKR_DEVICE_MEMORY; -+ goto out; -+ } -+ o->type = STO_T_PUBLIC_KEY; -+ o->u.public_key = public_key; -+ -+ c = CKO_PUBLIC_KEY; -+ add_object_attribute(o, 0, CKA_CLASS, &c, sizeof(c)); -+ add_object_attribute(o, 0, CKA_TOKEN, &bool_true, sizeof(bool_true)); -+ add_object_attribute(o, 0, CKA_PRIVATE, &bool_false, sizeof(bool_false)); -+ add_object_attribute(o, 0, CKA_MODIFIABLE, &bool_false, sizeof(bool_false)); -+ add_object_attribute(o, 0, CKA_LABEL, label, strlen(label)); -+ -+ add_object_attribute(o, 0, CKA_KEY_TYPE, &key_type, sizeof(key_type)); -+ add_object_attribute(o, 0, CKA_ID, id, id_len); -+ add_object_attribute(o, 0, CKA_START_DATE, "", 1); /* XXX */ -+ add_object_attribute(o, 0, CKA_END_DATE, "", 1); /* XXX */ -+ add_object_attribute(o, 0, CKA_DERIVE, &bool_false, sizeof(bool_false)); -+ add_object_attribute(o, 0, CKA_LOCAL, &bool_false, sizeof(bool_false)); -+ mech_type = CKM_RSA_X_509; -+ add_object_attribute(o, 0, CKA_KEY_GEN_MECHANISM, &mech_type, sizeof(mech_type)); -+ -+ add_object_attribute(o, 0, CKA_SUBJECT, subject_data, subject_length); -+ add_object_attribute(o, 0, CKA_ENCRYPT, &bool_true, sizeof(bool_true)); -+ add_object_attribute(o, 0, CKA_VERIFY, &bool_true, sizeof(bool_true)); -+ add_object_attribute(o, 0, CKA_VERIFY_RECOVER, &bool_false, sizeof(bool_false)); -+ add_object_attribute(o, 0, CKA_WRAP, &bool_true, sizeof(bool_true)); -+ add_object_attribute(o, 0, CKA_TRUSTED, &bool_true, sizeof(bool_true)); -+ -+ add_pubkey_info(o, key_type, public_key); -+ -+ st_logf("add key ok: %lx\n", (unsigned long)OBJECT_ID(o)); -+ -+ if (private_key_file) { -+ CK_FLAGS flags; -+ FILE *f; -+ -+ o = add_st_object(); -+ if (o == NULL) { -+ ret = CKR_DEVICE_MEMORY; -+ goto out; -+ } -+ o->type = STO_T_PRIVATE_KEY; -+ o->u.private_key.file = strdup(private_key_file); -+ o->u.private_key.key = NULL; -+ -+ o->u.private_key.cert = cert; -+ -+ c = CKO_PRIVATE_KEY; -+ add_object_attribute(o, 0, CKA_CLASS, &c, sizeof(c)); -+ add_object_attribute(o, 0, CKA_TOKEN, &bool_true, sizeof(bool_true)); -+ add_object_attribute(o, 0, CKA_PRIVATE, &bool_true, sizeof(bool_false)); -+ add_object_attribute(o, 0, CKA_MODIFIABLE, &bool_false, sizeof(bool_false)); -+ add_object_attribute(o, 0, CKA_LABEL, label, strlen(label)); -+ -+ add_object_attribute(o, 0, CKA_KEY_TYPE, &key_type, sizeof(key_type)); -+ add_object_attribute(o, 0, CKA_ID, id, id_len); -+ add_object_attribute(o, 0, CKA_START_DATE, "", 1); /* XXX */ -+ add_object_attribute(o, 0, CKA_END_DATE, "", 1); /* XXX */ -+ add_object_attribute(o, 0, CKA_DERIVE, &bool_false, sizeof(bool_false)); -+ add_object_attribute(o, 0, CKA_LOCAL, &bool_false, sizeof(bool_false)); -+ mech_type = CKM_RSA_X_509; -+ add_object_attribute(o, 0, CKA_KEY_GEN_MECHANISM, &mech_type, sizeof(mech_type)); -+ -+ add_object_attribute(o, 0, CKA_SUBJECT, subject_data, subject_length); -+ add_object_attribute(o, 0, CKA_SENSITIVE, &bool_true, sizeof(bool_true)); -+ add_object_attribute(o, 0, CKA_SECONDARY_AUTH, &bool_false, sizeof(bool_true)); -+ flags = 0; -+ add_object_attribute(o, 0, CKA_AUTH_PIN_FLAGS, &flags, sizeof(flags)); -+ -+ add_object_attribute(o, 0, CKA_DECRYPT, &bool_true, sizeof(bool_true)); -+ add_object_attribute(o, 0, CKA_SIGN, &bool_true, sizeof(bool_true)); -+ add_object_attribute(o, 0, CKA_SIGN_RECOVER, &bool_false, sizeof(bool_false)); -+ add_object_attribute(o, 0, CKA_UNWRAP, &bool_true, sizeof(bool_true)); -+ add_object_attribute(o, 0, CKA_EXTRACTABLE, &bool_true, sizeof(bool_true)); -+ add_object_attribute(o, 0, CKA_NEVER_EXTRACTABLE, &bool_false, sizeof(bool_false)); -+ -+ add_pubkey_info(o, key_type, public_key); -+ -+ f = fopen(private_key_file, "r"); -+ if (f == NULL) { -+ st_logf("failed to open private key\n"); -+ return CKR_GENERAL_ERROR; -+ } -+ -+ o->u.private_key.key = PEM_read_PrivateKey(f, NULL, pem_callback, NULL); -+ fclose(f); -+ if (o->u.private_key.key == NULL) { -+ st_logf("failed to read private key a startup\n"); -+ /* don't bother with this failure for now, -+ fix it at C_Login time */; -+ } else { -+ /* XXX verify keytype */ -+ -+ if (key_type == CKK_RSA) -+ RSA_set_method(o->u.private_key.key->pkey.rsa, -+ RSA_PKCS1_SSLeay()); -+ -+ if (X509_check_private_key(cert, o->u.private_key.key) != 1) { -+ EVP_PKEY_free(o->u.private_key.key); -+ o->u.private_key.key = NULL; -+ st_logf("private key doesn't verify\n"); -+ } else { -+ st_logf("private key usable\n"); -+ soft_token.flags.login_done = 1; -+ } -+ } -+ } -+ -+ ret = CKR_OK; -+ out: -+ if (ret != CKR_OK) { -+ st_logf("something went wrong when adding cert!\n"); -+ -+ /* XXX wack o */; -+ } -+ free(cert_data); -+ free(serial_data); -+ free(issuer_data); -+ free(subject_data); -+ -+ return ret; -+} -+ -+static void -+find_object_final(struct session_state *state) -+{ -+ if (state->find.attributes) { -+ CK_ULONG i; -+ -+ for (i = 0; i < state->find.num_attributes; i++) { -+ if (state->find.attributes[i].pValue) -+ free(state->find.attributes[i].pValue); -+ } -+ free(state->find.attributes); -+ state->find.attributes = NULL; -+ state->find.num_attributes = 0; -+ state->find.next_object = -1; -+ } -+} -+ -+static void -+reset_crypto_state(struct session_state *state) -+{ -+ state->encrypt_object = -1; -+ if (state->encrypt_mechanism) -+ free(state->encrypt_mechanism); -+ state->encrypt_mechanism = NULL_PTR; -+ state->decrypt_object = -1; -+ if (state->decrypt_mechanism) -+ free(state->decrypt_mechanism); -+ state->decrypt_mechanism = NULL_PTR; -+ state->sign_object = -1; -+ if (state->sign_mechanism) -+ free(state->sign_mechanism); -+ state->sign_mechanism = NULL_PTR; -+ state->verify_object = -1; -+ if (state->verify_mechanism) -+ free(state->verify_mechanism); -+ state->verify_mechanism = NULL_PTR; -+ state->digest_object = -1; -+} -+ -+static void -+close_session(struct session_state *state) -+{ -+ if (state->find.attributes) { -+ application_error("application didn't do C_FindObjectsFinal\n"); -+ find_object_final(state); -+ } -+ -+ state->session_handle = CK_INVALID_HANDLE; -+ soft_token.application = NULL_PTR; -+ soft_token.notify = NULL_PTR; -+ reset_crypto_state(state); -+} -+ -+static const char * -+has_session(void) -+{ -+ return soft_token.open_sessions > 0 ? "yes" : "no"; -+} -+ -+static void -+read_conf_file(const char *fn) -+{ -+ char buf[1024], *cert, *key, *id, *label, *s, *p; -+ int anchor; -+ FILE *f; -+ -+ f = fopen(fn, "r"); -+ if (f == NULL) { -+ st_logf("can't open configuration file %s\n", fn); -+ return; -+ } -+ -+ while(fgets(buf, sizeof(buf), f) != NULL) { -+ buf[strcspn(buf, "\n")] = '\0'; -+ -+ anchor = 0; -+ -+ st_logf("line: %s\n", buf); -+ -+ p = buf; -+ while (isspace(*p)) -+ p++; -+ if (*p == '#') -+ continue; -+ while (isspace(*p)) -+ p++; -+ -+ s = NULL; -+ id = strtok_r(p, "\t", &s); -+ if (id == NULL) -+ continue; -+ label = strtok_r(NULL, "\t", &s); -+ if (label == NULL) -+ continue; -+ cert = strtok_r(NULL, "\t", &s); -+ if (cert == NULL) -+ continue; -+ key = strtok_r(NULL, "\t", &s); -+ -+ /* XXX */ -+ if (strcmp(id, "anchor") == 0) { -+ id = "\x00\x00"; -+ anchor = 1; -+ } -+ -+ st_logf("adding: %s\n", label); -+ -+ add_certificate(label, cert, key, id, anchor); -+ } -+} -+ -+static CK_RV -+func_not_supported(void) -+{ -+ st_logf("function not supported\n"); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+CK_RV -+C_Initialize(CK_VOID_PTR a) -+{ -+ CK_C_INITIALIZE_ARGS_PTR args = a; -+ st_logf("Initialize\n"); -+ int i; -+ -+ OpenSSL_add_all_algorithms(); -+ ERR_load_crypto_strings(); -+ -+ srandom(getpid() ^ time(NULL)); -+ -+ for (i = 0; i < MAX_NUM_SESSION; i++) { -+ soft_token.state[i].session_handle = CK_INVALID_HANDLE; -+ soft_token.state[i].find.attributes = NULL; -+ soft_token.state[i].find.num_attributes = 0; -+ soft_token.state[i].find.next_object = -1; -+ reset_crypto_state(&soft_token.state[i]); -+ } -+ -+ soft_token.flags.hardware_slot = 1; -+ soft_token.flags.app_error_fatal = 0; -+ soft_token.flags.login_done = 0; -+ -+ soft_token.object.objs = NULL; -+ soft_token.object.num_objs = 0; -+ -+ soft_token.logfile = NULL; -+#if 0 -+ soft_token.logfile = stdout; -+#endif -+#if 0 -+ soft_token.logfile = fopen("/tmp/log-pkcs11.txt", "a"); -+#endif -+ -+ if (a != NULL_PTR) { -+ st_logf("\tCreateMutex:\t%p\n", args->CreateMutex); -+ st_logf("\tDestroyMutext\t%p\n", args->DestroyMutex); -+ st_logf("\tLockMutext\t%p\n", args->LockMutex); -+ st_logf("\tUnlockMutext\t%p\n", args->UnlockMutex); -+ st_logf("\tFlags\t%04x\n", (unsigned int)args->flags); -+ } -+ -+ { -+ char *fn = NULL, *home = NULL; -+ -+ if (getuid() == geteuid()) { -+ fn = getenv("SOFTPKCS11RC"); -+ if (fn) -+ fn = strdup(fn); -+ home = getenv("HOME"); -+ } -+ if (fn == NULL && home == NULL) { -+ struct passwd *pw = getpwuid(getuid()); -+ if(pw != NULL) -+ home = pw->pw_dir; -+ } -+ if (fn == NULL) { -+ if (home) -+ asprintf(&fn, "%s/.soft-token.rc", home); -+ else -+ fn = strdup("/etc/soft-token.rc"); -+ } -+ -+ read_conf_file(fn); -+ free(fn); -+ } -+ -+ return CKR_OK; -+} -+ -+CK_RV -+C_Finalize(CK_VOID_PTR args) -+{ -+ int i; -+ -+ st_logf("Finalize\n"); -+ -+ for (i = 0; i < MAX_NUM_SESSION; i++) { -+ if (soft_token.state[i].session_handle != CK_INVALID_HANDLE) { -+ application_error("application finalized without " -+ "closing session\n"); -+ close_session(&soft_token.state[i]); -+ } -+ } -+ -+ return CKR_OK; -+} -+ -+CK_RV -+C_GetInfo(CK_INFO_PTR args) -+{ -+ st_logf("GetInfo\n"); -+ -+ memset(args, 17, sizeof(*args)); -+ args->cryptokiVersion.major = 2; -+ args->cryptokiVersion.minor = 10; -+ snprintf_fill((char *)args->manufacturerID, -+ sizeof(args->manufacturerID), -+ ' ', -+ "SoftToken"); -+ snprintf_fill((char *)args->libraryDescription, -+ sizeof(args->libraryDescription), ' ', -+ "SoftToken"); -+ args->libraryVersion.major = 1; -+ args->libraryVersion.minor = 8; -+ -+ return CKR_OK; -+} -+ -+extern CK_FUNCTION_LIST funcs; -+ -+CK_RV -+C_GetFunctionList(CK_FUNCTION_LIST_PTR_PTR ppFunctionList) -+{ -+ *ppFunctionList = &funcs; -+ return CKR_OK; -+} -+ -+CK_RV -+C_GetSlotList(CK_BBOOL tokenPresent, -+ CK_SLOT_ID_PTR pSlotList, -+ CK_ULONG_PTR pulCount) -+{ -+ st_logf("GetSlotList: %s\n", -+ tokenPresent ? "tokenPresent" : "token not Present"); -+ if (pSlotList) -+ pSlotList[0] = 1; -+ *pulCount = 1; -+ return CKR_OK; -+} -+ -+CK_RV -+C_GetSlotInfo(CK_SLOT_ID slotID, -+ CK_SLOT_INFO_PTR pInfo) -+{ -+ st_logf("GetSlotInfo: slot: %d : %s\n", (int)slotID, has_session()); -+ -+ memset(pInfo, 18, sizeof(*pInfo)); -+ -+ if (slotID != 1) -+ return CKR_ARGUMENTS_BAD; -+ -+ snprintf_fill((char *)pInfo->slotDescription, -+ sizeof(pInfo->slotDescription), -+ ' ', -+ "SoftToken (slot)"); -+ snprintf_fill((char *)pInfo->manufacturerID, -+ sizeof(pInfo->manufacturerID), -+ ' ', -+ "SoftToken (slot)"); -+ pInfo->flags = CKF_TOKEN_PRESENT; -+ if (soft_token.flags.hardware_slot) -+ pInfo->flags |= CKF_HW_SLOT; -+ pInfo->hardwareVersion.major = 1; -+ pInfo->hardwareVersion.minor = 0; -+ pInfo->firmwareVersion.major = 1; -+ pInfo->firmwareVersion.minor = 0; -+ -+ return CKR_OK; -+} -+ -+CK_RV -+C_GetTokenInfo(CK_SLOT_ID slotID, -+ CK_TOKEN_INFO_PTR pInfo) -+{ -+ st_logf("GetTokenInfo: %s\n", has_session()); -+ -+ memset(pInfo, 19, sizeof(*pInfo)); -+ -+ snprintf_fill((char *)pInfo->label, -+ sizeof(pInfo->label), -+ ' ', -+ "SoftToken (token)"); -+ snprintf_fill((char *)pInfo->manufacturerID, -+ sizeof(pInfo->manufacturerID), -+ ' ', -+ "SoftToken (token)"); -+ snprintf_fill((char *)pInfo->model, -+ sizeof(pInfo->model), -+ ' ', -+ "SoftToken (token)"); -+ snprintf_fill((char *)pInfo->serialNumber, -+ sizeof(pInfo->serialNumber), -+ ' ', -+ "4711"); -+ pInfo->flags = -+ CKF_TOKEN_INITIALIZED | -+ CKF_USER_PIN_INITIALIZED; -+ -+ if (soft_token.flags.login_done == 0) -+ pInfo->flags |= CKF_LOGIN_REQUIRED; -+ -+ /* CFK_RNG | -+ CKF_RESTORE_KEY_NOT_NEEDED | -+ */ -+ pInfo->ulMaxSessionCount = MAX_NUM_SESSION; -+ pInfo->ulSessionCount = soft_token.open_sessions; -+ pInfo->ulMaxRwSessionCount = MAX_NUM_SESSION; -+ pInfo->ulRwSessionCount = soft_token.open_sessions; -+ pInfo->ulMaxPinLen = 1024; -+ pInfo->ulMinPinLen = 0; -+ pInfo->ulTotalPublicMemory = 4711; -+ pInfo->ulFreePublicMemory = 4712; -+ pInfo->ulTotalPrivateMemory = 4713; -+ pInfo->ulFreePrivateMemory = 4714; -+ pInfo->hardwareVersion.major = 2; -+ pInfo->hardwareVersion.minor = 0; -+ pInfo->firmwareVersion.major = 2; -+ pInfo->firmwareVersion.minor = 0; -+ -+ return CKR_OK; -+} -+ -+CK_RV -+C_GetMechanismList(CK_SLOT_ID slotID, -+ CK_MECHANISM_TYPE_PTR pMechanismList, -+ CK_ULONG_PTR pulCount) -+{ -+ st_logf("GetMechanismList\n"); -+ -+ *pulCount = 2; -+ if (pMechanismList == NULL_PTR) -+ return CKR_OK; -+ pMechanismList[0] = CKM_RSA_X_509; -+ pMechanismList[1] = CKM_RSA_PKCS; -+ -+ return CKR_OK; -+} -+ -+CK_RV -+C_GetMechanismInfo(CK_SLOT_ID slotID, -+ CK_MECHANISM_TYPE type, -+ CK_MECHANISM_INFO_PTR pInfo) -+{ -+ st_logf("GetMechanismInfo: slot %d type: %d\n", -+ (int)slotID, (int)type); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+CK_RV -+C_InitToken(CK_SLOT_ID slotID, -+ CK_UTF8CHAR_PTR pPin, -+ CK_ULONG ulPinLen, -+ CK_UTF8CHAR_PTR pLabel) -+{ -+ st_logf("InitToken: slot %d\n", (int)slotID); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+CK_RV -+C_OpenSession(CK_SLOT_ID slotID, -+ CK_FLAGS flags, -+ CK_VOID_PTR pApplication, -+ CK_NOTIFY Notify, -+ CK_SESSION_HANDLE_PTR phSession) -+{ -+ int i; -+ -+ st_logf("OpenSession: slot: %d\n", (int)slotID); -+ -+ if (soft_token.open_sessions == MAX_NUM_SESSION) -+ return CKR_SESSION_COUNT; -+ -+ soft_token.application = pApplication; -+ soft_token.notify = Notify; -+ -+ for (i = 0; i < MAX_NUM_SESSION; i++) -+ if (soft_token.state[i].session_handle == CK_INVALID_HANDLE) -+ break; -+ if (i == MAX_NUM_SESSION) -+ abort(); -+ -+ soft_token.open_sessions++; -+ -+ soft_token.state[i].session_handle = -+ (CK_SESSION_HANDLE)(random() & 0xfffff); -+ *phSession = soft_token.state[i].session_handle; -+ -+ return CKR_OK; -+} -+ -+CK_RV -+C_CloseSession(CK_SESSION_HANDLE hSession) -+{ -+ struct session_state *state; -+ st_logf("CloseSession\n"); -+ -+ if (verify_session_handle(hSession, &state) != CKR_OK) -+ application_error("closed session not open"); -+ else -+ close_session(state); -+ -+ return CKR_OK; -+} -+ -+CK_RV -+C_CloseAllSessions(CK_SLOT_ID slotID) -+{ -+ int i; -+ -+ st_logf("CloseAllSessions\n"); -+ -+ for (i = 0; i < MAX_NUM_SESSION; i++) -+ if (soft_token.state[i].session_handle != CK_INVALID_HANDLE) -+ close_session(&soft_token.state[i]); -+ -+ return CKR_OK; -+} -+ -+CK_RV -+C_GetSessionInfo(CK_SESSION_HANDLE hSession, -+ CK_SESSION_INFO_PTR pInfo) -+{ -+ st_logf("GetSessionInfo\n"); -+ -+ VERIFY_SESSION_HANDLE(hSession, NULL); -+ -+ memset(pInfo, 20, sizeof(*pInfo)); -+ -+ pInfo->slotID = 1; -+ if (soft_token.flags.login_done) -+ pInfo->state = CKS_RO_USER_FUNCTIONS; -+ else -+ pInfo->state = CKS_RO_PUBLIC_SESSION; -+ pInfo->flags = CKF_SERIAL_SESSION; -+ pInfo->ulDeviceError = 0; -+ -+ return CKR_OK; -+} -+ -+CK_RV -+C_Login(CK_SESSION_HANDLE hSession, -+ CK_USER_TYPE userType, -+ CK_UTF8CHAR_PTR pPin, -+ CK_ULONG ulPinLen) -+{ -+ char *pin = NULL; -+ int i; -+ -+ st_logf("Login\n"); -+ -+ VERIFY_SESSION_HANDLE(hSession, NULL); -+ -+ if (pPin != NULL_PTR) { -+ asprintf(&pin, "%.*s", (int)ulPinLen, pPin); -+ st_logf("type: %d password: %s\n", (int)userType, pin); -+ } -+ -+ for (i = 0; i < soft_token.object.num_objs; i++) { -+ struct st_object *o = soft_token.object.objs[i]; -+ FILE *f; -+ -+ if (o->type != STO_T_PRIVATE_KEY) -+ continue; -+ -+ if (o->u.private_key.key) -+ continue; -+ -+ f = fopen(o->u.private_key.file, "r"); -+ if (f == NULL) { -+ st_logf("can't open private file: %s\n", o->u.private_key.file); -+ continue; -+ } -+ -+ o->u.private_key.key = PEM_read_PrivateKey(f, NULL, NULL, pin); -+ fclose(f); -+ if (o->u.private_key.key == NULL) { -+ st_logf("failed to read key: %s error: %s\n", -+ o->u.private_key.file, -+ ERR_error_string(ERR_get_error(), NULL)); -+ /* just ignore failure */; -+ continue; -+ } -+ -+ /* XXX check keytype */ -+ RSA_set_method(o->u.private_key.key->pkey.rsa, RSA_PKCS1_SSLeay()); -+ -+ if (X509_check_private_key(o->u.private_key.cert, o->u.private_key.key) != 1) { -+ EVP_PKEY_free(o->u.private_key.key); -+ o->u.private_key.key = NULL; -+ st_logf("private key %s doesn't verify\n", o->u.private_key.file); -+ continue; -+ } -+ -+ soft_token.flags.login_done = 1; -+ } -+ free(pin); -+ -+ return soft_token.flags.login_done ? CKR_OK : CKR_PIN_INCORRECT; -+} -+ -+CK_RV -+C_Logout(CK_SESSION_HANDLE hSession) -+{ -+ st_logf("Logout\n"); -+ VERIFY_SESSION_HANDLE(hSession, NULL); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+CK_RV -+C_GetObjectSize(CK_SESSION_HANDLE hSession, -+ CK_OBJECT_HANDLE hObject, -+ CK_ULONG_PTR pulSize) -+{ -+ st_logf("GetObjectSize\n"); -+ VERIFY_SESSION_HANDLE(hSession, NULL); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+CK_RV -+C_GetAttributeValue(CK_SESSION_HANDLE hSession, -+ CK_OBJECT_HANDLE hObject, -+ CK_ATTRIBUTE_PTR pTemplate, -+ CK_ULONG ulCount) -+{ -+ struct session_state *state; -+ struct st_object *obj; -+ CK_ULONG i; -+ CK_RV ret; -+ int j; -+ -+ st_logf("GetAttributeValue: %lx\n", -+ (unsigned long)HANDLE_OBJECT_ID(hObject)); -+ VERIFY_SESSION_HANDLE(hSession, &state); -+ -+ if ((ret = object_handle_to_object(hObject, &obj)) != CKR_OK) { -+ st_logf("object not found: %lx\n", -+ (unsigned long)HANDLE_OBJECT_ID(hObject)); -+ return ret; -+ } -+ -+ for (i = 0; i < ulCount; i++) { -+ st_logf(" getting 0x%08lx\n", (unsigned long)pTemplate[i].type); -+ for (j = 0; j < obj->num_attributes; j++) { -+ if (obj->attrs[j].secret) { -+ pTemplate[i].ulValueLen = (CK_ULONG)-1; -+ break; -+ } -+ if (pTemplate[i].type == obj->attrs[j].attribute.type) { -+ if (pTemplate[i].pValue != NULL_PTR && obj->attrs[j].secret == 0) { -+ if (pTemplate[i].ulValueLen >= obj->attrs[j].attribute.ulValueLen) -+ memcpy(pTemplate[i].pValue, obj->attrs[j].attribute.pValue, -+ obj->attrs[j].attribute.ulValueLen); -+ } -+ pTemplate[i].ulValueLen = obj->attrs[j].attribute.ulValueLen; -+ break; -+ } -+ } -+ if (j == obj->num_attributes) { -+ st_logf("key type: 0x%08lx not found\n", (unsigned long)pTemplate[i].type); -+ pTemplate[i].ulValueLen = (CK_ULONG)-1; -+ } -+ -+ } -+ return CKR_OK; -+} -+ -+CK_RV -+C_FindObjectsInit(CK_SESSION_HANDLE hSession, -+ CK_ATTRIBUTE_PTR pTemplate, -+ CK_ULONG ulCount) -+{ -+ struct session_state *state; -+ -+ st_logf("FindObjectsInit\n"); -+ -+ VERIFY_SESSION_HANDLE(hSession, &state); -+ -+ if (state->find.next_object != -1) { -+ application_error("application didn't do C_FindObjectsFinal\n"); -+ find_object_final(state); -+ } -+ if (ulCount) { -+ CK_ULONG i; -+ size_t len; -+ -+ print_attributes(pTemplate, ulCount); -+ -+ state->find.attributes = -+ calloc(1, ulCount * sizeof(state->find.attributes[0])); -+ if (state->find.attributes == NULL) -+ return CKR_DEVICE_MEMORY; -+ for (i = 0; i < ulCount; i++) { -+ state->find.attributes[i].pValue = -+ malloc(pTemplate[i].ulValueLen); -+ if (state->find.attributes[i].pValue == NULL) { -+ find_object_final(state); -+ return CKR_DEVICE_MEMORY; -+ } -+ memcpy(state->find.attributes[i].pValue, -+ pTemplate[i].pValue, pTemplate[i].ulValueLen); -+ state->find.attributes[i].type = pTemplate[i].type; -+ state->find.attributes[i].ulValueLen = pTemplate[i].ulValueLen; -+ } -+ state->find.num_attributes = ulCount; -+ state->find.next_object = 0; -+ } else { -+ st_logf("find all objects\n"); -+ state->find.attributes = NULL; -+ state->find.num_attributes = 0; -+ state->find.next_object = 0; -+ } -+ -+ return CKR_OK; -+} -+ -+CK_RV -+C_FindObjects(CK_SESSION_HANDLE hSession, -+ CK_OBJECT_HANDLE_PTR phObject, -+ CK_ULONG ulMaxObjectCount, -+ CK_ULONG_PTR pulObjectCount) -+{ -+ struct session_state *state; -+ int i; -+ -+ st_logf("FindObjects\n"); -+ -+ VERIFY_SESSION_HANDLE(hSession, &state); -+ -+ if (state->find.next_object == -1) { -+ application_error("application didn't do C_FindObjectsInit\n"); -+ return CKR_ARGUMENTS_BAD; -+ } -+ if (ulMaxObjectCount == 0) { -+ application_error("application asked for 0 objects\n"); -+ return CKR_ARGUMENTS_BAD; -+ } -+ *pulObjectCount = 0; -+ for (i = state->find.next_object; i < soft_token.object.num_objs; i++) { -+ st_logf("FindObjects: %d\n", i); -+ state->find.next_object = i + 1; -+ if (attributes_match(soft_token.object.objs[i], -+ state->find.attributes, -+ state->find.num_attributes)) { -+ *phObject++ = soft_token.object.objs[i]->object_handle; -+ ulMaxObjectCount--; -+ (*pulObjectCount)++; -+ if (ulMaxObjectCount == 0) -+ break; -+ } -+ } -+ return CKR_OK; -+} -+ -+CK_RV -+C_FindObjectsFinal(CK_SESSION_HANDLE hSession) -+{ -+ struct session_state *state; -+ -+ st_logf("FindObjectsFinal\n"); -+ VERIFY_SESSION_HANDLE(hSession, &state); -+ find_object_final(state); -+ return CKR_OK; -+} -+ -+static CK_RV -+commonInit(CK_ATTRIBUTE *attr_match, int attr_match_len, -+ const CK_MECHANISM_TYPE *mechs, int mechs_len, -+ const CK_MECHANISM_PTR pMechanism, CK_OBJECT_HANDLE hKey, -+ struct st_object **o) -+{ -+ CK_RV ret; -+ int i; -+ -+ *o = NULL; -+ if ((ret = object_handle_to_object(hKey, o)) != CKR_OK) -+ return ret; -+ -+ ret = attributes_match(*o, attr_match, attr_match_len); -+ if (!ret) { -+ application_error("called commonInit on key that doesn't " -+ "support required attr"); -+ return CKR_ARGUMENTS_BAD; -+ } -+ -+ for (i = 0; i < mechs_len; i++) -+ if (mechs[i] == pMechanism->mechanism) -+ break; -+ if (i == mechs_len) { -+ application_error("called mech (%08lx) not supported\n", -+ pMechanism->mechanism); -+ return CKR_ARGUMENTS_BAD; -+ } -+ return CKR_OK; -+} -+ -+ -+static CK_RV -+dup_mechanism(CK_MECHANISM_PTR *dup, const CK_MECHANISM_PTR pMechanism) -+{ -+ CK_MECHANISM_PTR p; -+ -+ p = malloc(sizeof(*p)); -+ if (p == NULL) -+ return CKR_DEVICE_MEMORY; -+ -+ if (*dup) -+ free(*dup); -+ *dup = p; -+ memcpy(p, pMechanism, sizeof(*p)); -+ -+ return CKR_OK; -+} -+ -+ -+CK_RV -+C_EncryptInit(CK_SESSION_HANDLE hSession, -+ CK_MECHANISM_PTR pMechanism, -+ CK_OBJECT_HANDLE hKey) -+{ -+ struct session_state *state; -+ CK_MECHANISM_TYPE mechs[] = { CKM_RSA_PKCS, CKM_RSA_X_509 }; -+ CK_BBOOL bool_true = CK_TRUE; -+ CK_ATTRIBUTE attr[] = { -+ { CKA_ENCRYPT, &bool_true, sizeof(bool_true) } -+ }; -+ struct st_object *o; -+ CK_RV ret; -+ -+ st_logf("EncryptInit\n"); -+ VERIFY_SESSION_HANDLE(hSession, &state); -+ -+ ret = commonInit(attr, sizeof(attr)/sizeof(attr[0]), -+ mechs, sizeof(mechs)/sizeof(mechs[0]), -+ pMechanism, hKey, &o); -+ if (ret) -+ return ret; -+ -+ ret = dup_mechanism(&state->encrypt_mechanism, pMechanism); -+ if (ret == CKR_OK) -+ state->encrypt_object = OBJECT_ID(o); -+ -+ return ret; -+} -+ -+CK_RV -+C_Encrypt(CK_SESSION_HANDLE hSession, -+ CK_BYTE_PTR pData, -+ CK_ULONG ulDataLen, -+ CK_BYTE_PTR pEncryptedData, -+ CK_ULONG_PTR pulEncryptedDataLen) -+{ -+ struct session_state *state; -+ struct st_object *o; -+ void *buffer = NULL; -+ CK_RV ret; -+ RSA *rsa; -+ int padding, len, buffer_len, padding_len; -+ -+ st_logf("Encrypt\n"); -+ -+ VERIFY_SESSION_HANDLE(hSession, &state); -+ -+ if (state->encrypt_object == -1) -+ return CKR_ARGUMENTS_BAD; -+ -+ o = soft_token.object.objs[state->encrypt_object]; -+ -+ if (o->u.public_key == NULL) { -+ st_logf("public key NULL\n"); -+ return CKR_ARGUMENTS_BAD; -+ } -+ -+ rsa = o->u.public_key->pkey.rsa; -+ -+ if (rsa == NULL) -+ return CKR_ARGUMENTS_BAD; -+ -+ RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ -+ -+ buffer_len = RSA_size(rsa); -+ -+ buffer = malloc(buffer_len); -+ if (buffer == NULL) { -+ ret = CKR_DEVICE_MEMORY; -+ goto out; -+ } -+ -+ ret = CKR_OK; -+ switch(state->encrypt_mechanism->mechanism) { -+ case CKM_RSA_PKCS: -+ padding = RSA_PKCS1_PADDING; -+ padding_len = RSA_PKCS1_PADDING_SIZE; -+ break; -+ case CKM_RSA_X_509: -+ padding = RSA_NO_PADDING; -+ padding_len = 0; -+ break; -+ default: -+ ret = CKR_FUNCTION_NOT_SUPPORTED; -+ goto out; -+ } -+ -+ if (buffer_len + padding_len < ulDataLen) { -+ ret = CKR_ARGUMENTS_BAD; -+ goto out; -+ } -+ -+ if (pulEncryptedDataLen == NULL) { -+ st_logf("pulEncryptedDataLen NULL\n"); -+ ret = CKR_ARGUMENTS_BAD; -+ goto out; -+ } -+ -+ if (pData == NULL_PTR) { -+ st_logf("data NULL\n"); -+ ret = CKR_ARGUMENTS_BAD; -+ goto out; -+ } -+ -+ len = RSA_public_encrypt(ulDataLen, pData, buffer, rsa, padding); -+ if (len <= 0) { -+ ret = CKR_DEVICE_ERROR; -+ goto out; -+ } -+ if (len > buffer_len) -+ abort(); -+ -+ if (pEncryptedData != NULL_PTR) -+ memcpy(pEncryptedData, buffer, len); -+ *pulEncryptedDataLen = len; -+ -+ out: -+ if (buffer) { -+ memset(buffer, 0, buffer_len); -+ free(buffer); -+ } -+ return ret; -+} -+ -+CK_RV -+C_EncryptUpdate(CK_SESSION_HANDLE hSession, -+ CK_BYTE_PTR pPart, -+ CK_ULONG ulPartLen, -+ CK_BYTE_PTR pEncryptedPart, -+ CK_ULONG_PTR pulEncryptedPartLen) -+{ -+ st_logf("EncryptUpdate\n"); -+ VERIFY_SESSION_HANDLE(hSession, NULL); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+ -+CK_RV -+C_EncryptFinal(CK_SESSION_HANDLE hSession, -+ CK_BYTE_PTR pLastEncryptedPart, -+ CK_ULONG_PTR pulLastEncryptedPartLen) -+{ -+ st_logf("EncryptFinal\n"); -+ VERIFY_SESSION_HANDLE(hSession, NULL); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+ -+/* C_DecryptInit initializes a decryption operation. */ -+CK_RV -+C_DecryptInit(CK_SESSION_HANDLE hSession, -+ CK_MECHANISM_PTR pMechanism, -+ CK_OBJECT_HANDLE hKey) -+{ -+ struct session_state *state; -+ CK_MECHANISM_TYPE mechs[] = { CKM_RSA_PKCS, CKM_RSA_X_509 }; -+ CK_BBOOL bool_true = CK_TRUE; -+ CK_ATTRIBUTE attr[] = { -+ { CKA_DECRYPT, &bool_true, sizeof(bool_true) } -+ }; -+ struct st_object *o; -+ CK_RV ret; -+ -+ st_logf("DecryptInit\n"); -+ VERIFY_SESSION_HANDLE(hSession, &state); -+ -+ ret = commonInit(attr, sizeof(attr)/sizeof(attr[0]), -+ mechs, sizeof(mechs)/sizeof(mechs[0]), -+ pMechanism, hKey, &o); -+ if (ret) -+ return ret; -+ -+ ret = dup_mechanism(&state->decrypt_mechanism, pMechanism); -+ if (ret == CKR_OK) -+ state->decrypt_object = OBJECT_ID(o); -+ -+ return CKR_OK; -+} -+ -+ -+CK_RV -+C_Decrypt(CK_SESSION_HANDLE hSession, -+ CK_BYTE_PTR pEncryptedData, -+ CK_ULONG ulEncryptedDataLen, -+ CK_BYTE_PTR pData, -+ CK_ULONG_PTR pulDataLen) -+{ -+ struct session_state *state; -+ struct st_object *o; -+ void *buffer = NULL; -+ CK_RV ret; -+ RSA *rsa; -+ int padding, len, buffer_len, padding_len; -+ -+ st_logf("Decrypt\n"); -+ -+ VERIFY_SESSION_HANDLE(hSession, &state); -+ -+ if (state->decrypt_object == -1) -+ return CKR_ARGUMENTS_BAD; -+ -+ o = soft_token.object.objs[state->decrypt_object]; -+ -+ if (o->u.private_key.key == NULL) { -+ st_logf("private key NULL\n"); -+ return CKR_ARGUMENTS_BAD; -+ } -+ -+ rsa = o->u.private_key.key->pkey.rsa; -+ -+ if (rsa == NULL) -+ return CKR_ARGUMENTS_BAD; -+ -+ RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ -+ -+ buffer_len = RSA_size(rsa); -+ -+ buffer = malloc(buffer_len); -+ if (buffer == NULL) { -+ ret = CKR_DEVICE_MEMORY; -+ goto out; -+ } -+ -+ ret = CKR_OK; -+ switch(state->decrypt_mechanism->mechanism) { -+ case CKM_RSA_PKCS: -+ padding = RSA_PKCS1_PADDING; -+ padding_len = RSA_PKCS1_PADDING_SIZE; -+ break; -+ case CKM_RSA_X_509: -+ padding = RSA_NO_PADDING; -+ padding_len = 0; -+ break; -+ default: -+ ret = CKR_FUNCTION_NOT_SUPPORTED; -+ goto out; -+ } -+ -+ if (buffer_len + padding_len < ulEncryptedDataLen) { -+ ret = CKR_ARGUMENTS_BAD; -+ goto out; -+ } -+ -+ if (pulDataLen == NULL) { -+ st_logf("pulDataLen NULL\n"); -+ ret = CKR_ARGUMENTS_BAD; -+ goto out; -+ } -+ -+ if (pEncryptedData == NULL_PTR) { -+ st_logf("data NULL\n"); -+ ret = CKR_ARGUMENTS_BAD; -+ goto out; -+ } -+ -+ len = RSA_private_decrypt(ulEncryptedDataLen, pEncryptedData, buffer, -+ rsa, padding); -+ if (len <= 0) { -+ ret = CKR_DEVICE_ERROR; -+ goto out; -+ } -+ if (len > buffer_len) -+ abort(); -+ -+ if (pData != NULL_PTR) -+ memcpy(pData, buffer, len); -+ *pulDataLen = len; -+ -+ out: -+ if (buffer) { -+ memset(buffer, 0, buffer_len); -+ free(buffer); -+ } -+ return ret; -+} -+ -+ -+CK_RV -+C_DecryptUpdate(CK_SESSION_HANDLE hSession, -+ CK_BYTE_PTR pEncryptedPart, -+ CK_ULONG ulEncryptedPartLen, -+ CK_BYTE_PTR pPart, -+ CK_ULONG_PTR pulPartLen) -+ -+{ -+ st_logf("DecryptUpdate\n"); -+ VERIFY_SESSION_HANDLE(hSession, NULL); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+ -+CK_RV -+C_DecryptFinal(CK_SESSION_HANDLE hSession, -+ CK_BYTE_PTR pLastPart, -+ CK_ULONG_PTR pulLastPartLen) -+{ -+ st_logf("DecryptFinal\n"); -+ VERIFY_SESSION_HANDLE(hSession, NULL); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+CK_RV -+C_DigestInit(CK_SESSION_HANDLE hSession, -+ CK_MECHANISM_PTR pMechanism) -+{ -+ st_logf("DigestInit\n"); -+ VERIFY_SESSION_HANDLE(hSession, NULL); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+CK_RV -+C_SignInit(CK_SESSION_HANDLE hSession, -+ CK_MECHANISM_PTR pMechanism, -+ CK_OBJECT_HANDLE hKey) -+{ -+ struct session_state *state; -+ CK_MECHANISM_TYPE mechs[] = { CKM_RSA_PKCS, CKM_RSA_X_509 }; -+ CK_BBOOL bool_true = CK_TRUE; -+ CK_ATTRIBUTE attr[] = { -+ { CKA_SIGN, &bool_true, sizeof(bool_true) } -+ }; -+ struct st_object *o; -+ CK_RV ret; -+ -+ st_logf("SignInit\n"); -+ VERIFY_SESSION_HANDLE(hSession, &state); -+ -+ ret = commonInit(attr, sizeof(attr)/sizeof(attr[0]), -+ mechs, sizeof(mechs)/sizeof(mechs[0]), -+ pMechanism, hKey, &o); -+ if (ret) -+ return ret; -+ -+ ret = dup_mechanism(&state->sign_mechanism, pMechanism); -+ if (ret == CKR_OK) -+ state->sign_object = OBJECT_ID(o); -+ -+ return CKR_OK; -+} -+ -+CK_RV -+C_Sign(CK_SESSION_HANDLE hSession, -+ CK_BYTE_PTR pData, -+ CK_ULONG ulDataLen, -+ CK_BYTE_PTR pSignature, -+ CK_ULONG_PTR pulSignatureLen) -+{ -+ struct session_state *state; -+ struct st_object *o; -+ void *buffer = NULL; -+ CK_RV ret; -+ RSA *rsa; -+ int padding, len, buffer_len, padding_len; -+ -+ st_logf("Sign\n"); -+ VERIFY_SESSION_HANDLE(hSession, &state); -+ -+ if (state->sign_object == -1) -+ return CKR_ARGUMENTS_BAD; -+ -+ o = soft_token.object.objs[state->sign_object]; -+ -+ if (o->u.private_key.key == NULL) { -+ st_logf("private key NULL\n"); -+ return CKR_ARGUMENTS_BAD; -+ } -+ -+ rsa = o->u.private_key.key->pkey.rsa; -+ -+ if (rsa == NULL) -+ return CKR_ARGUMENTS_BAD; -+ -+ RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ -+ -+ buffer_len = RSA_size(rsa); -+ -+ buffer = malloc(buffer_len); -+ if (buffer == NULL) { -+ ret = CKR_DEVICE_MEMORY; -+ goto out; -+ } -+ -+ switch(state->sign_mechanism->mechanism) { -+ case CKM_RSA_PKCS: -+ padding = RSA_PKCS1_PADDING; -+ padding_len = RSA_PKCS1_PADDING_SIZE; -+ break; -+ case CKM_RSA_X_509: -+ padding = RSA_NO_PADDING; -+ padding_len = 0; -+ break; -+ default: -+ ret = CKR_FUNCTION_NOT_SUPPORTED; -+ goto out; -+ } -+ -+ if (buffer_len < ulDataLen + padding_len) { -+ ret = CKR_ARGUMENTS_BAD; -+ goto out; -+ } -+ -+ if (pulSignatureLen == NULL) { -+ st_logf("signature len NULL\n"); -+ ret = CKR_ARGUMENTS_BAD; -+ goto out; -+ } -+ -+ if (pData == NULL_PTR) { -+ st_logf("data NULL\n"); -+ ret = CKR_ARGUMENTS_BAD; -+ goto out; -+ } -+ -+ len = RSA_private_encrypt(ulDataLen, pData, buffer, rsa, padding); -+ st_logf("private encrypt done\n"); -+ if (len <= 0) { -+ ret = CKR_DEVICE_ERROR; -+ goto out; -+ } -+ if (len > buffer_len) -+ abort(); -+ -+ if (pSignature != NULL_PTR) -+ memcpy(pSignature, buffer, len); -+ *pulSignatureLen = len; -+ -+ ret = CKR_OK; -+ -+ out: -+ if (buffer) { -+ memset(buffer, 0, buffer_len); -+ free(buffer); -+ } -+ return ret; -+} -+ -+CK_RV -+C_SignUpdate(CK_SESSION_HANDLE hSession, -+ CK_BYTE_PTR pPart, -+ CK_ULONG ulPartLen) -+{ -+ st_logf("SignUpdate\n"); -+ VERIFY_SESSION_HANDLE(hSession, NULL); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+ -+CK_RV -+C_SignFinal(CK_SESSION_HANDLE hSession, -+ CK_BYTE_PTR pSignature, -+ CK_ULONG_PTR pulSignatureLen) -+{ -+ st_logf("SignUpdate\n"); -+ VERIFY_SESSION_HANDLE(hSession, NULL); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+CK_RV -+C_VerifyInit(CK_SESSION_HANDLE hSession, -+ CK_MECHANISM_PTR pMechanism, -+ CK_OBJECT_HANDLE hKey) -+{ -+ struct session_state *state; -+ CK_MECHANISM_TYPE mechs[] = { CKM_RSA_PKCS, CKM_RSA_X_509 }; -+ CK_BBOOL bool_true = CK_TRUE; -+ CK_ATTRIBUTE attr[] = { -+ { CKA_VERIFY, &bool_true, sizeof(bool_true) } -+ }; -+ struct st_object *o; -+ CK_RV ret; -+ -+ st_logf("VerifyInit\n"); -+ VERIFY_SESSION_HANDLE(hSession, &state); -+ -+ ret = commonInit(attr, sizeof(attr)/sizeof(attr[0]), -+ mechs, sizeof(mechs)/sizeof(mechs[0]), -+ pMechanism, hKey, &o); -+ if (ret) -+ return ret; -+ -+ ret = dup_mechanism(&state->verify_mechanism, pMechanism); -+ if (ret == CKR_OK) -+ state->verify_object = OBJECT_ID(o); -+ -+ return ret; -+} -+ -+CK_RV -+C_Verify(CK_SESSION_HANDLE hSession, -+ CK_BYTE_PTR pData, -+ CK_ULONG ulDataLen, -+ CK_BYTE_PTR pSignature, -+ CK_ULONG ulSignatureLen) -+{ -+ struct session_state *state; -+ struct st_object *o; -+ void *buffer = NULL; -+ CK_RV ret; -+ RSA *rsa; -+ int padding, len, buffer_len; -+ -+ st_logf("Verify\n"); -+ VERIFY_SESSION_HANDLE(hSession, &state); -+ -+ if (state->verify_object == -1) -+ return CKR_ARGUMENTS_BAD; -+ -+ o = soft_token.object.objs[state->verify_object]; -+ -+ if (o->u.public_key == NULL) { -+ st_logf("public key NULL\n"); -+ return CKR_ARGUMENTS_BAD; -+ } -+ -+ rsa = o->u.public_key->pkey.rsa; -+ -+ if (rsa == NULL) -+ return CKR_ARGUMENTS_BAD; -+ -+ RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ -+ -+ buffer_len = RSA_size(rsa); -+ -+ buffer = malloc(buffer_len); -+ if (buffer == NULL) { -+ ret = CKR_DEVICE_MEMORY; -+ goto out; -+ } -+ -+ ret = CKR_OK; -+ switch(state->verify_mechanism->mechanism) { -+ case CKM_RSA_PKCS: -+ padding = RSA_PKCS1_PADDING; -+ break; -+ case CKM_RSA_X_509: -+ padding = RSA_NO_PADDING; -+ break; -+ default: -+ ret = CKR_FUNCTION_NOT_SUPPORTED; -+ goto out; -+ } -+ -+ if (buffer_len < ulDataLen) { -+ ret = CKR_ARGUMENTS_BAD; -+ goto out; -+ } -+ -+ if (pSignature == NULL) { -+ st_logf("signature NULL\n"); -+ ret = CKR_ARGUMENTS_BAD; -+ goto out; -+ } -+ -+ if (pData == NULL_PTR) { -+ st_logf("data NULL\n"); -+ ret = CKR_ARGUMENTS_BAD; -+ goto out; -+ } -+ -+ len = RSA_public_decrypt(ulDataLen, pData, buffer, rsa, padding); -+ st_logf("private encrypt done\n"); -+ if (len <= 0) { -+ ret = CKR_DEVICE_ERROR; -+ goto out; -+ } -+ if (len > buffer_len) -+ abort(); -+ -+ if (len != ulSignatureLen) { -+ ret = CKR_GENERAL_ERROR; -+ goto out; -+ } -+ -+ if (memcmp(pSignature, buffer, len) != 0) { -+ ret = CKR_GENERAL_ERROR; -+ goto out; -+ } -+ -+ out: -+ if (buffer) { -+ memset(buffer, 0, buffer_len); -+ free(buffer); -+ } -+ return ret; -+} -+ -+ -+CK_RV -+C_VerifyUpdate(CK_SESSION_HANDLE hSession, -+ CK_BYTE_PTR pPart, -+ CK_ULONG ulPartLen) -+{ -+ st_logf("VerifyUpdate\n"); -+ VERIFY_SESSION_HANDLE(hSession, NULL); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+CK_RV -+C_VerifyFinal(CK_SESSION_HANDLE hSession, -+ CK_BYTE_PTR pSignature, -+ CK_ULONG ulSignatureLen) -+{ -+ st_logf("VerifyFinal\n"); -+ VERIFY_SESSION_HANDLE(hSession, NULL); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+CK_RV -+C_GenerateRandom(CK_SESSION_HANDLE hSession, -+ CK_BYTE_PTR RandomData, -+ CK_ULONG ulRandomLen) -+{ -+ st_logf("GenerateRandom\n"); -+ VERIFY_SESSION_HANDLE(hSession, NULL); -+ return CKR_FUNCTION_NOT_SUPPORTED; -+} -+ -+ -+CK_FUNCTION_LIST funcs = { -+ { 2, 11 }, -+ C_Initialize, -+ C_Finalize, -+ C_GetInfo, -+ C_GetFunctionList, -+ C_GetSlotList, -+ C_GetSlotInfo, -+ C_GetTokenInfo, -+ C_GetMechanismList, -+ C_GetMechanismInfo, -+ C_InitToken, -+ (void *)func_not_supported, /* C_InitPIN */ -+ (void *)func_not_supported, /* C_SetPIN */ -+ C_OpenSession, -+ C_CloseSession, -+ C_CloseAllSessions, -+ C_GetSessionInfo, -+ (void *)func_not_supported, /* C_GetOperationState */ -+ (void *)func_not_supported, /* C_SetOperationState */ -+ C_Login, -+ C_Logout, -+ (void *)func_not_supported, /* C_CreateObject */ -+ (void *)func_not_supported, /* C_CopyObject */ -+ (void *)func_not_supported, /* C_DestroyObject */ -+ (void *)func_not_supported, /* C_GetObjectSize */ -+ C_GetAttributeValue, -+ (void *)func_not_supported, /* C_SetAttributeValue */ -+ C_FindObjectsInit, -+ C_FindObjects, -+ C_FindObjectsFinal, -+ C_EncryptInit, -+ C_Encrypt, -+ C_EncryptUpdate, -+ C_EncryptFinal, -+ C_DecryptInit, -+ C_Decrypt, -+ C_DecryptUpdate, -+ C_DecryptFinal, -+ C_DigestInit, -+ (void *)func_not_supported, /* C_Digest */ -+ (void *)func_not_supported, /* C_DigestUpdate */ -+ (void *)func_not_supported, /* C_DigestKey */ -+ (void *)func_not_supported, /* C_DigestFinal */ -+ C_SignInit, -+ C_Sign, -+ C_SignUpdate, -+ C_SignFinal, -+ (void *)func_not_supported, /* C_SignRecoverInit */ -+ (void *)func_not_supported, /* C_SignRecover */ -+ C_VerifyInit, -+ C_Verify, -+ C_VerifyUpdate, -+ C_VerifyFinal, -+ (void *)func_not_supported, /* C_VerifyRecoverInit */ -+ (void *)func_not_supported, /* C_VerifyRecover */ -+ (void *)func_not_supported, /* C_DigestEncryptUpdate */ -+ (void *)func_not_supported, /* C_DecryptDigestUpdate */ -+ (void *)func_not_supported, /* C_SignEncryptUpdate */ -+ (void *)func_not_supported, /* C_DecryptVerifyUpdate */ -+ (void *)func_not_supported, /* C_GenerateKey */ -+ (void *)func_not_supported, /* C_GenerateKeyPair */ -+ (void *)func_not_supported, /* C_WrapKey */ -+ (void *)func_not_supported, /* C_UnwrapKey */ -+ (void *)func_not_supported, /* C_DeriveKey */ -+ (void *)func_not_supported, /* C_SeedRandom */ -+ C_GenerateRandom, -+ (void *)func_not_supported, /* C_GetFunctionStatus */ -+ (void *)func_not_supported, /* C_CancelFunction */ -+ (void *)func_not_supported /* C_WaitForSlotEvent */ -+}; diff --git a/Add-tests-for-KCM-ccache-type.patch b/Add-tests-for-KCM-ccache-type.patch deleted file mode 100644 index 08d9215..0000000 --- a/Add-tests-for-KCM-ccache-type.patch +++ /dev/null @@ -1,294 +0,0 @@ -From 0b63afda1a399a37274021115524db1e65675cb9 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 22 Nov 2018 00:27:35 -0500 -Subject: [PATCH] Add tests for KCM ccache type - -Using a trivial Python implementation of a KCM server, run the -t_ccache.py tests against the KCM ccache type. - -(cherry picked from commit f0bcb86131e385b2603ccf0f3c7d65aa3891b220) ---- - src/tests/kcmserver.py | 246 +++++++++++++++++++++++++++++++++++++++++ - src/tests/t_ccache.py | 9 +- - 2 files changed, 254 insertions(+), 1 deletion(-) - create mode 100644 src/tests/kcmserver.py - -diff --git a/src/tests/kcmserver.py b/src/tests/kcmserver.py -new file mode 100644 -index 000000000..57432e5a7 ---- /dev/null -+++ b/src/tests/kcmserver.py -@@ -0,0 +1,246 @@ -+# This is a simple KCM test server, used to exercise the KCM ccache -+# client code. It will generally throw an uncaught exception if the -+# client sends anything unexpected, so is unsuitable for production. -+# (It also imposes no namespace or access constraints, and blocks -+# while reading requests and writing responses.) -+ -+# This code knows nothing about how to marshal and unmarshal principal -+# names and credentials as is required in the KCM protocol; instead, -+# it just remembers the marshalled forms and replays them to the -+# client when asked. This works because marshalled creds and -+# principal names are always the last part of marshalled request -+# arguments, and because we don't need to implement remove_cred (which -+# would need to know how to match a cred tag against previously stored -+# credentials). -+ -+# The following code is useful for debugging if anything appears to be -+# going wrong in the server, since daemon output is generally not -+# visible in Python test scripts. -+# -+# import sys, traceback -+# def ehook(etype, value, tb): -+# with open('/tmp/exception', 'w') as f: -+# traceback.print_exception(etype, value, tb, file=f) -+# sys.excepthook = ehook -+ -+import select -+import socket -+import struct -+import sys -+ -+caches = {} -+cache_uuidmap = {} -+defname = b'default' -+next_unique = 1 -+next_uuid = 1 -+ -+class KCMOpcodes(object): -+ GEN_NEW = 3 -+ INITIALIZE = 4 -+ DESTROY = 5 -+ STORE = 6 -+ GET_PRINCIPAL = 8 -+ GET_CRED_UUID_LIST = 9 -+ GET_CRED_BY_UUID = 10 -+ REMOVE_CRED = 11 -+ GET_CACHE_UUID_LIST = 18 -+ GET_CACHE_BY_UUID = 19 -+ GET_DEFAULT_CACHE = 20 -+ SET_DEFAULT_CACHE = 21 -+ GET_KDC_OFFSET = 22 -+ SET_KDC_OFFSET = 23 -+ -+ -+class KRB5Errors(object): -+ KRB5_CC_END = -1765328242 -+ KRB5_CC_NOSUPP = -1765328137 -+ KRB5_FCC_NOFILE = -1765328189 -+ -+ -+def make_uuid(): -+ global next_uuid -+ uuid = bytes(12) + struct.pack('>L', next_uuid) -+ next_uuid = next_uuid + 1 -+ return uuid -+ -+ -+class Cache(object): -+ def __init__(self, name): -+ self.name = name -+ self.princ = None -+ self.uuid = make_uuid() -+ self.cred_uuids = [] -+ self.creds = {} -+ self.time_offset = 0 -+ -+ -+def get_cache(name): -+ if name in caches: -+ return caches[name] -+ cache = Cache(name) -+ caches[name] = cache -+ cache_uuidmap[cache.uuid] = cache -+ return cache -+ -+ -+def unmarshal_name(argbytes): -+ offset = argbytes.find(b'\0') -+ return argbytes[0:offset], argbytes[offset+1:] -+ -+ -+def op_gen_new(argbytes): -+ # Does not actually check for uniqueness. -+ global next_unique -+ name = b'unique' + str(next_unique).encode('ascii') -+ next_unique += 1 -+ return 0, name + b'\0' -+ -+ -+def op_initialize(argbytes): -+ name, princ = unmarshal_name(argbytes) -+ cache = get_cache(name) -+ cache.princ = princ -+ cache.cred_uuids = [] -+ cache.creds = {} -+ cache.time_offset = 0 -+ return 0, b'' -+ -+ -+def op_destroy(argbytes): -+ name, rest = unmarshal_name(argbytes) -+ cache = get_cache(name) -+ del cache_uuidmap[cache.uuid] -+ del caches[name] -+ return 0, b'' -+ -+ -+def op_store(argbytes): -+ name, cred = unmarshal_name(argbytes) -+ cache = get_cache(name) -+ uuid = make_uuid() -+ cache.creds[uuid] = cred -+ cache.cred_uuids.append(uuid) -+ return 0, b'' -+ -+ -+def op_get_principal(argbytes): -+ name, rest = unmarshal_name(argbytes) -+ cache = get_cache(name) -+ if cache.princ is None: -+ return KRB5Errors.KRB5_FCC_NOFILE, b'' -+ return 0, cache.princ + b'\0' -+ -+ -+def op_get_cred_uuid_list(argbytes): -+ name, rest = unmarshal_name(argbytes) -+ cache = get_cache(name) -+ return 0, b''.join(cache.cred_uuids) -+ -+ -+def op_get_cred_by_uuid(argbytes): -+ name, uuid = unmarshal_name(argbytes) -+ cache = get_cache(name) -+ if uuid not in cache.creds: -+ return KRB5Errors.KRB5_CC_END, b'' -+ return 0, cache.creds[uuid] -+ -+ -+def op_remove_cred(argbytes): -+ return KRB5Errors.KRB5_CC_NOSUPP, b'' -+ -+ -+def op_get_cache_uuid_list(argbytes): -+ return 0, b''.join(cache_uuidmap.keys()) -+ -+ -+def op_get_cache_by_uuid(argbytes): -+ uuid = argbytes -+ if uuid not in cache_uuidmap: -+ return KRB5Errors.KRB5_CC_END, b'' -+ return 0, cache_uuidmap[uuid].name + b'\0' -+ -+ -+def op_get_default_cache(argbytes): -+ return 0, defname + b'\0' -+ -+ -+def op_set_default_cache(argbytes): -+ global defname -+ defname, rest = unmarshal_name(argbytes) -+ return 0, b'' -+ -+ -+def op_get_kdc_offset(argbytes): -+ name, rest = unmarshal_name(argbytes) -+ cache = get_cache(name) -+ return 0, struct.pack('>l', cache.time_offset) -+ -+ -+def op_set_kdc_offset(argbytes): -+ name, obytes = unmarshal_name(argbytes) -+ cache = get_cache(name) -+ cache.time_offset, = struct.unpack('>l', obytes) -+ return 0, b'' -+ -+ -+ophandlers = { -+ KCMOpcodes.GEN_NEW : op_gen_new, -+ KCMOpcodes.INITIALIZE : op_initialize, -+ KCMOpcodes.DESTROY : op_destroy, -+ KCMOpcodes.STORE : op_store, -+ KCMOpcodes.GET_PRINCIPAL : op_get_principal, -+ KCMOpcodes.GET_CRED_UUID_LIST : op_get_cred_uuid_list, -+ KCMOpcodes.GET_CRED_BY_UUID : op_get_cred_by_uuid, -+ KCMOpcodes.REMOVE_CRED : op_remove_cred, -+ KCMOpcodes.GET_CACHE_UUID_LIST : op_get_cache_uuid_list, -+ KCMOpcodes.GET_CACHE_BY_UUID : op_get_cache_by_uuid, -+ KCMOpcodes.GET_DEFAULT_CACHE : op_get_default_cache, -+ KCMOpcodes.SET_DEFAULT_CACHE : op_set_default_cache, -+ KCMOpcodes.GET_KDC_OFFSET : op_get_kdc_offset, -+ KCMOpcodes.SET_KDC_OFFSET : op_set_kdc_offset -+} -+ -+# Read and respond to a request from the socket s. -+def service_request(s): -+ lenbytes = b'' -+ while len(lenbytes) < 4: -+ lenbytes += s.recv(4 - len(lenbytes)) -+ if lenbytes == b'': -+ return False -+ -+ reqlen, = struct.unpack('>L', lenbytes) -+ req = b'' -+ while len(req) < reqlen: -+ req += s.recv(reqlen - len(req)) -+ -+ majver, minver, op = struct.unpack('>BBH', req[:4]) -+ argbytes = req[4:] -+ code, payload = ophandlers[op](argbytes) -+ -+ # The KCM response is the code (4 bytes) and the response payload. -+ # The Heimdal IPC response is the length of the KCM response (4 -+ # bytes), a status code which is essentially always 0 (4 bytes), -+ # and the KCM response. -+ kcm_response = struct.pack('>l', code) + payload -+ hipc_response = struct.pack('>LL', len(kcm_response), 0) + kcm_response -+ s.sendall(hipc_response) -+ return True -+ -+ -+server = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM) -+server.bind(sys.argv[1]) -+server.listen(5) -+select_input = [server,] -+sys.stderr.write('starting...\n') -+sys.stderr.flush() -+ -+while True: -+ iready, oready, xready = select.select(select_input, [], []) -+ for s in iready: -+ if s == server: -+ client, addr = server.accept() -+ select_input.append(client) -+ else: -+ if not service_request(s): -+ select_input.remove(s) -+ s.close() -diff --git a/src/tests/t_ccache.py b/src/tests/t_ccache.py -index fcf1a611e..66804afa5 100755 ---- a/src/tests/t_ccache.py -+++ b/src/tests/t_ccache.py -@@ -22,7 +22,10 @@ - - from k5test import * - --realm = K5Realm(create_host=False) -+kcm_socket_path = os.path.join(os.getcwd(), 'testdir', 'kcm') -+conf = {'libdefaults': {'kcm_socket': kcm_socket_path, -+ 'kcm_mach_service': '-'}} -+realm = K5Realm(create_host=False, krb5_conf=conf) - - keyctl = which('keyctl') - out = realm.run([klist, '-c', 'KEYRING:process:abcd'], expected_code=1) -@@ -122,6 +125,10 @@ def collection_test(realm, ccname): - - - collection_test(realm, 'DIR:' + os.path.join(realm.testdir, 'cc')) -+kcmserver_path = os.path.join(srctop, 'tests', 'kcmserver.py') -+realm.start_server([sys.executable, kcmserver_path, kcm_socket_path], -+ 'starting...') -+collection_test(realm, 'KCM:') - if test_keyring: - def cleanup_keyring(anchor, name): - out = realm.run(['keyctl', 'list', anchor]) diff --git a/Add-zapfreedata-convenience-function.patch b/Add-zapfreedata-convenience-function.patch deleted file mode 100644 index b9ae932..0000000 --- a/Add-zapfreedata-convenience-function.patch +++ /dev/null @@ -1,31 +0,0 @@ -From b99ba3fa4bc99c2925fa4b509004d694e9d7ac68 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 14 Mar 2019 11:26:44 -0400 -Subject: [PATCH] Add zapfreedata() convenience function - -(cherry picked from commit abd974cf867db5a398aa87ba9b9aaa34346e12a4) ---- - src/include/k5-int.h | 10 ++++++++++ - 1 file changed, 10 insertions(+) - -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index e0c557554..2bc59e636 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -663,6 +663,16 @@ zapfreestr(void *str) - } - } - -+/* Convenience function: zap and free krb5_data pointer if it is non-NULL. */ -+static inline void -+zapfreedata(krb5_data *data) -+{ -+ if (data != NULL) { -+ zapfree(data->data, data->length); -+ free(data); -+ } -+} -+ - /* - * Combine two keys (normally used by the hardware preauth mechanism) - */ diff --git a/Address-some-optimized-out-memset-calls.patch b/Address-some-optimized-out-memset-calls.patch deleted file mode 100644 index a97f91d..0000000 --- a/Address-some-optimized-out-memset-calls.patch +++ /dev/null @@ -1,94 +0,0 @@ -From 95fec44aebd6a4d815f88a0b5a53517c4f3175f4 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sun, 30 Dec 2018 16:40:28 -0500 -Subject: [PATCH] Address some optimized-out memset() calls - -Ilja Van Sprundel reported a list of memset() calls which gcc -optimizes out. In krb_auth_su.c, use zap() to clear the password, and -remove two memset() calls when there is no password to clear. In -iakerb.c, remove an unnecessary memset() before setting the only two -fields of the IAKERB header structure. In svr_principal.c, use -krb5_free_key_keyblock_contents() instead of hand-freeing key data. -In asn1_k_encode.c, remove an unnecessary memset() of the kdc_req_hack -shell before returning. - -(cherry picked from commit 1057b0befec1f1c0e9d4da5521a58496e2dc0997) ---- - src/clients/ksu/krb_auth_su.c | 4 +--- - src/lib/gssapi/krb5/iakerb.c | 1 - - src/lib/kadm5/srv/svr_principal.c | 10 ++-------- - src/lib/krb5/asn.1/asn1_k_encode.c | 1 - - 4 files changed, 3 insertions(+), 13 deletions(-) - -diff --git a/src/clients/ksu/krb_auth_su.c b/src/clients/ksu/krb_auth_su.c -index 7af48195c..e39685fff 100644 ---- a/src/clients/ksu/krb_auth_su.c -+++ b/src/clients/ksu/krb_auth_su.c -@@ -183,21 +183,19 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, - if (code ) { - com_err(prog_name, code, _("while reading password for '%s'\n"), - client_name); -- memset(password, 0, sizeof(password)); - return (FALSE); - } - - if ( pwsize == 0) { - fprintf(stderr, _("No password given\n")); - *zero_password = TRUE; -- memset(password, 0, sizeof(password)); - return (FALSE); - } - - code = krb5_get_init_creds_password(context, &creds, client, password, - krb5_prompter_posix, NULL, 0, NULL, - options); -- memset(password, 0, sizeof(password)); -+ zap(password, sizeof(password)); - - - if (code) { -diff --git a/src/lib/gssapi/krb5/iakerb.c b/src/lib/gssapi/krb5/iakerb.c -index bb1072fe4..47c161ec9 100644 ---- a/src/lib/gssapi/krb5/iakerb.c -+++ b/src/lib/gssapi/krb5/iakerb.c -@@ -262,7 +262,6 @@ iakerb_make_token(iakerb_ctx_id_t ctx, - /* - * Assemble the IAKERB-HEADER from the realm and cookie - */ -- memset(&iah, 0, sizeof(iah)); - iah.target_realm = *realm; - iah.cookie = cookie; - -diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c -index 8582bbc56..be0922101 100644 ---- a/src/lib/kadm5/srv/svr_principal.c -+++ b/src/lib/kadm5/srv/svr_principal.c -@@ -2097,14 +2097,8 @@ static int decrypt_key_data(krb5_context context, - ret = krb5_dbe_decrypt_key_data(context, NULL, &key_data[i], &keys[i], - NULL); - if (ret) { -- for (; i >= 0; i--) { -- if (keys[i].contents) { -- memset (keys[i].contents, 0, keys[i].length); -- free( keys[i].contents ); -- } -- } -- -- memset(keys, 0, n_key_data*sizeof(krb5_keyblock)); -+ for (; i >= 0; i--) -+ krb5_free_keyblock_contents(context, &keys[i]); - free(keys); - return ret; - } -diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c -index 65c84be2f..81a34bac9 100644 ---- a/src/lib/krb5/asn.1/asn1_k_encode.c -+++ b/src/lib/krb5/asn.1/asn1_k_encode.c -@@ -528,7 +528,6 @@ decode_kdc_req_body(const taginfo *t, const uint8_t *asn1, size_t len, - if (ret) { - free_kdc_req_body(b); - free(h.server_realm.data); -- memset(&h, 0, sizeof(h)); - return ret; - } - b->server->realm = h.server_realm; diff --git a/Allow-client-canonicalization-in-non-krbtgt-AS-REP.patch b/Allow-client-canonicalization-in-non-krbtgt-AS-REP.patch deleted file mode 100644 index 4402203..0000000 --- a/Allow-client-canonicalization-in-non-krbtgt-AS-REP.patch +++ /dev/null @@ -1,64 +0,0 @@ -From 0bbb2104fd6c494552c9261137fac782941b6440 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Tue, 15 Oct 2019 20:41:49 +0300 -Subject: [PATCH] Allow client canonicalization in non-krbtgt AS-REP - -If a caller makes an AS-REQ with the canonicalize flag set (or with an -enterprise client principal or the anonymous flag), always allow the -KDC to change the client principal. Continue to restrict server name -changes to requests for TGS principals. - -Also remove the conditional for setting canon_ok for fully anonymous -requests. Both kinds of anonymous requests change the client -principal or realm, but neither kind changes the server principal or -realm, so this logic is no longer needed now that canon_ok only -applies to server name changes. - -[ghudson@mit.edu: clarified commit message; removed anonymous PKINIT -clause] - -ticket: 8843 (new) -(cherry picked from commit c6c19b1d35c6523cb7ed220c1f2e97e12e039293) ---- - src/lib/krb5/krb/get_in_tkt.c | 9 ++------- - src/tests/t_kdb.py | 3 +++ - 2 files changed, 5 insertions(+), 7 deletions(-) - -diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c -index 79dede2c6..9ee605888 100644 ---- a/src/lib/krb5/krb/get_in_tkt.c -+++ b/src/lib/krb5/krb/get_in_tkt.c -@@ -230,17 +230,12 @@ verify_as_reply(krb5_context context, - if (canon_req) { - canon_ok = IS_TGS_PRINC(request->server) && - IS_TGS_PRINC(as_reply->enc_part2->server); -- if (!canon_ok && (request->kdc_options & KDC_OPT_REQUEST_ANONYMOUS)) { -- canon_ok = krb5_principal_compare_any_realm(context, -- as_reply->client, -- krb5_anonymous_principal()); -- } - } else - canon_ok = 0; - - if ((!canon_ok && -- (!krb5_principal_compare(context, as_reply->client, request->client) || -- !krb5_principal_compare(context, as_reply->enc_part2->server, request->server))) -+ !krb5_principal_compare(context, as_reply->enc_part2->server, request->server)) -+ || (!canon_req && !krb5_principal_compare(context, as_reply->client, request->client)) - || !krb5_principal_compare(context, as_reply->enc_part2->server, as_reply->ticket->server) - || (request->nonce != as_reply->enc_part2->nonce) - /* XXX check for extraneous flags */ -diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py -index 7a082a5b9..cc5d2fc3c 100755 ---- a/src/tests/t_kdb.py -+++ b/src/tests/t_kdb.py -@@ -389,6 +389,9 @@ realm.run([kadminl, 'modprinc', '+requires_preauth', 'canon']) - realm.kinit('canon', password('canon')) - realm.kinit('alias', password('canon'), ['-C']) - -+# Test client name canonicalization in non-krbtgt AS reply -+realm.kinit('alias', password('canon'), ['-C', '-S', 'kadmin/changepw']) -+ - mark('LDAP password history') - - # Test password history. diff --git a/Avoid-alignment-warnings-in-openssl-rc4.c.patch b/Avoid-alignment-warnings-in-openssl-rc4.c.patch deleted file mode 100644 index 9e7293a..0000000 --- a/Avoid-alignment-warnings-in-openssl-rc4.c.patch +++ /dev/null @@ -1,63 +0,0 @@ -From 399b9ed8ef199b6280bf4d6564928c79a3611cc5 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 6 May 2019 15:14:49 -0400 -Subject: [PATCH] Avoid alignment warnings in openssl rc4.c - -Add a comment to k5_arcfour_init_state() explaining how we stretch the -krb5_data cipher state contract. Use void * casts when interpreting -the data pointer to avoid alignment warnings. - -[ghudson@mit.edu: moved and expanded comment; rewrote commit message] - -(cherry picked from commit 1cd41d76c12fc1cea0a8bf0d6a40f34623c60d6d) ---- - src/lib/crypto/openssl/enc_provider/rc4.c | 15 ++++++++++++--- - 1 file changed, 12 insertions(+), 3 deletions(-) - -diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c -index 7f3c086ed..a65d57b7a 100644 ---- a/src/lib/crypto/openssl/enc_provider/rc4.c -+++ b/src/lib/crypto/openssl/enc_provider/rc4.c -@@ -57,7 +57,7 @@ struct arcfour_state { - - /* In-place IOV crypto */ - static krb5_error_code --k5_arcfour_docrypt(krb5_key key,const krb5_data *state, krb5_crypto_iov *data, -+k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, - size_t num_data) - { - size_t i; -@@ -66,7 +66,7 @@ k5_arcfour_docrypt(krb5_key key,const krb5_data *state, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx = NULL; - struct arcfour_state *arcstate; - -- arcstate = (state != NULL) ? (struct arcfour_state *) state->data : NULL; -+ arcstate = (state != NULL) ? (void *)state->data : NULL; - if (arcstate != NULL) { - ctx = arcstate->ctx; - if (arcstate->loopback != arcstate) -@@ -113,7 +113,7 @@ k5_arcfour_docrypt(krb5_key key,const krb5_data *state, krb5_crypto_iov *data, - static void - k5_arcfour_free_state(krb5_data *state) - { -- struct arcfour_state *arcstate = (struct arcfour_state *) state->data; -+ struct arcfour_state *arcstate = (void *)state->data; - - EVP_CIPHER_CTX_free(arcstate->ctx); - free(arcstate); -@@ -125,6 +125,15 @@ k5_arcfour_init_state(const krb5_keyblock *key, - { - struct arcfour_state *arcstate; - -+ /* -+ * The cipher state here is a saved pointer to a struct arcfour_state -+ * object, rather than a flat byte array as in most enc providers. The -+ * object includes a loopback pointer to detect if if the caller made a -+ * copy of the krb5_data value or otherwise assumed it was a simple byte -+ * array. When we cast the data pointer back, we need to go through void * -+ * to avoid increased alignment warnings. -+ */ -+ - /* Create a state structure with an uninitialized context. */ - arcstate = calloc(1, sizeof(*arcstate)); - if (arcstate == NULL) diff --git a/Avoid-allocating-a-register-in-zap-assembly.patch b/Avoid-allocating-a-register-in-zap-assembly.patch deleted file mode 100644 index 144d9ed..0000000 --- a/Avoid-allocating-a-register-in-zap-assembly.patch +++ /dev/null @@ -1,55 +0,0 @@ -From c896facca7dd9d0fbbd561d3a723a90216821b72 Mon Sep 17 00:00:00 2001 -From: Andreas Schneider -Date: Thu, 3 Jan 2019 17:19:32 +0100 -Subject: [PATCH] Avoid allocating a register in zap() assembly - -See https://bugs.llvm.org/show_bug.cgi?id=15495 - -Also add explicit_bzero() (glibc, FreeBSD) and explicit_memset() -(NetBSD) as alternatives. - -[ghudson@mit.edu: added explicit_bzero() and explicit_memset()] - -(cherry picked from commit 7391e8b541061d0f584193b4a53365b64364b0e8) ---- - src/configure.in | 2 +- - src/include/k5-platform.h | 6 +++++- - 2 files changed, 6 insertions(+), 2 deletions(-) - -diff --git a/src/configure.in b/src/configure.in -index feae21c3e..505dabb02 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -421,7 +421,7 @@ AC_PROG_LEX - AC_C_CONST - AC_HEADER_DIRENT - AC_FUNC_STRERROR_R --AC_CHECK_FUNCS(strdup setvbuf seteuid setresuid setreuid setegid setresgid setregid setsid flock fchmod chmod strptime geteuid setenv unsetenv getenv gmtime_r localtime_r bswap16 bswap64 mkstemp getusershell access getcwd srand48 srand srandom stat strchr strerror timegm) -+AC_CHECK_FUNCS(strdup setvbuf seteuid setresuid setreuid setegid setresgid setregid setsid flock fchmod chmod strptime geteuid setenv unsetenv getenv gmtime_r localtime_r bswap16 bswap64 mkstemp getusershell access getcwd srand48 srand srandom stat strchr strerror timegm explicit_bzero explicit_memset) - - AC_CHECK_FUNC(mkstemp, - [MKSTEMP_ST_OBJ= -diff --git a/src/include/k5-platform.h b/src/include/k5-platform.h -index 997b655e1..1fcd68e8c 100644 ---- a/src/include/k5-platform.h -+++ b/src/include/k5-platform.h -@@ -1023,6 +1023,10 @@ static inline void zap(void *ptr, size_t len) - if (len > 0) - memset_s(ptr, len, 0, len); - } -+#elif defined(HAVE_EXPLICIT_BZERO) -+# define zap(ptr, len) explicit_bzero(ptr, len) -+#elif defined(HAVE_EXPLICIT_MEMSET) -+# define zap(ptr, len) explicit_memset(ptr, 0, len) - #elif defined(__GNUC__) || defined(__clang__) - /* - * Use an asm statement which declares a memory clobber to force the memset to -@@ -1032,7 +1036,7 @@ static inline void zap(void *ptr, size_t len) - { - if (len > 0) - memset(ptr, 0, len); -- __asm__ __volatile__("" : : "r" (ptr) : "memory"); -+ __asm__ __volatile__("" : : "g" (ptr) : "memory"); - } - #else - /* diff --git a/Check-more-errors-in-OpenSSL-crypto-backend.patch b/Check-more-errors-in-OpenSSL-crypto-backend.patch deleted file mode 100644 index 006177f..0000000 --- a/Check-more-errors-in-OpenSSL-crypto-backend.patch +++ /dev/null @@ -1,88 +0,0 @@ -From 57e48b63b1f0b34861c66fb24dafc0feb524f47c Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 22 Apr 2019 14:26:42 -0400 -Subject: [PATCH] Check more errors in OpenSSL crypto backend - -In krb5int_hmac_keyblock() and krb5int_pbkdf2_hmac(), check for errors -from previously unchecked OpenSSL function calls and return -KRB5_CRYPTO_INTERNAL if they fail. - -HMAC_Init() is deprecated in OpenSSL 1.0 and later; as we are -modifying the call to check for errors, call HMAC_Init_ex() instead. - -ticket: 8799 (new) -(cherry picked from commit 2298e5c2ff1122bcaff715129f5b746e77c3f42a) ---- - src/lib/crypto/openssl/hmac.c | 18 +++++++++--------- - src/lib/crypto/openssl/pbkdf2.c | 9 +++++---- - 2 files changed, 14 insertions(+), 13 deletions(-) - -diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c -index b2db6ec02..7dc59dcc0 100644 ---- a/src/lib/crypto/openssl/hmac.c -+++ b/src/lib/crypto/openssl/hmac.c -@@ -117,7 +117,7 @@ krb5int_hmac_keyblock(const struct krb5_hash_provider *hash, - const krb5_crypto_iov *data, size_t num_data, - krb5_data *output) - { -- unsigned int i = 0, md_len = 0; -+ unsigned int i = 0, md_len = 0, ok; - unsigned char md[EVP_MAX_MD_SIZE]; - HMAC_CTX *ctx; - size_t hashsize, blocksize; -@@ -137,22 +137,22 @@ krb5int_hmac_keyblock(const struct krb5_hash_provider *hash, - if (ctx == NULL) - return ENOMEM; - -- HMAC_Init(ctx, keyblock->contents, keyblock->length, map_digest(hash)); -- for (i = 0; i < num_data; i++) { -+ ok = HMAC_Init_ex(ctx, keyblock->contents, keyblock->length, -+ map_digest(hash), NULL); -+ for (i = 0; ok && i < num_data; i++) { - const krb5_crypto_iov *iov = &data[i]; - - if (SIGN_IOV(iov)) -- HMAC_Update(ctx, (uint8_t *)iov->data.data, iov->data.length); -+ ok = HMAC_Update(ctx, (uint8_t *)iov->data.data, iov->data.length); - } -- HMAC_Final(ctx, md, &md_len); -- if ( md_len <= output->length) { -+ if (ok) -+ ok = HMAC_Final(ctx, md, &md_len); -+ if (ok && md_len <= output->length) { - output->length = md_len; - memcpy(output->data, md, output->length); - } - HMAC_CTX_free(ctx); -- return 0; -- -- -+ return ok ? 0 : KRB5_CRYPTO_INTERNAL; - } - - krb5_error_code -diff --git a/src/lib/crypto/openssl/pbkdf2.c b/src/lib/crypto/openssl/pbkdf2.c -index 00c2116fc..732ec6405 100644 ---- a/src/lib/crypto/openssl/pbkdf2.c -+++ b/src/lib/crypto/openssl/pbkdf2.c -@@ -35,6 +35,7 @@ krb5int_pbkdf2_hmac(const struct krb5_hash_provider *hash, - const krb5_data *pass, const krb5_data *salt) - { - const EVP_MD *md = NULL; -+ int ok; - - /* Get the message digest handle corresponding to the hash. */ - if (hash == &krb5int_hash_sha1) -@@ -46,8 +47,8 @@ krb5int_pbkdf2_hmac(const struct krb5_hash_provider *hash, - if (md == NULL) - return KRB5_CRYPTO_INTERNAL; - -- PKCS5_PBKDF2_HMAC(pass->data, pass->length, (unsigned char *)salt->data, -- salt->length, count, md, out->length, -- (unsigned char *)out->data); -- return 0; -+ ok = PKCS5_PBKDF2_HMAC(pass->data, pass->length, -+ (unsigned char *)salt->data, salt->length, count, -+ md, out->length, (unsigned char *)out->data); -+ return ok ? 0 : KRB5_CRYPTO_INTERNAL; - } diff --git a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch b/Clarify-header-comment-for-krb5_cc_start_seq_get.patch deleted file mode 100644 index 0173bf8..0000000 --- a/Clarify-header-comment-for-krb5_cc_start_seq_get.patch +++ /dev/null @@ -1,31 +0,0 @@ -From 037981b197a6046574539ec405cc1d67b9f22473 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 2 Apr 2019 14:18:57 -0400 -Subject: [PATCH] Clarify header comment for krb5_cc_start_seq_get() - -Previously this comment seemed to suggest that applications needed to -block all other access to the ccache (including by other processes) -during iteration. - -(cherry picked from commit f4f51a25dd38601357e2f64b17b51eb23f45a53e) ---- - src/include/krb5/krb5.hin | 6 ++++-- - 1 file changed, 4 insertions(+), 2 deletions(-) - -diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 3ff86d7ff..346e796a5 100644 ---- a/src/include/krb5/krb5.hin -+++ b/src/include/krb5/krb5.hin -@@ -2491,8 +2491,10 @@ krb5_cc_get_principal(krb5_context context, krb5_ccache cache, - * - * krb5_cc_end_seq_get() must be called to complete the retrieve operation. - * -- * @note If @a cache is modified between the time of the call to this function -- * and the time of the final krb5_cc_end_seq_get(), the results are undefined. -+ * @note If the cache represented by @a cache is modified between the time of -+ * the call to this function and the time of the final krb5_cc_end_seq_get(), -+ * these changes may not be reflected in the results of krb5_cc_next_cred() -+ * calls. - * - * @retval 0 Success; otherwise - Kerberos error codes - */ diff --git a/Clear-forwardable-flag-instead-of-denying-request.patch b/Clear-forwardable-flag-instead-of-denying-request.patch deleted file mode 100644 index 88e3641..0000000 --- a/Clear-forwardable-flag-instead-of-denying-request.patch +++ /dev/null @@ -1,484 +0,0 @@ -From 54b5eceb45db9cf6ff86eea5efebba66cf48153e Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 15 Nov 2018 13:40:43 -0500 -Subject: [PATCH] Clear forwardable flag instead of denying request - -If the client requests a forwardable or proxiable ticket and the -option cannot be honored by policy, issue a non-forwardable or -non-proxiable ticket rather than denying the request. - -Add a test script for testing KDC request options and populate it with -tests for the forwardable and proxiable flags. - -ticket: 7871 -(cherry picked from commit 08e948cce2c79a3604066fcf7a64fc527456f83d) ---- - src/kdc/do_as_req.c | 19 ++------ - src/kdc/do_tgs_req.c | 56 ++++----------------- - src/kdc/kdc_util.c | 82 ++++++++++++++++++------------- - src/kdc/kdc_util.h | 9 ++-- - src/kdc/tgs_policy.c | 8 +-- - src/tests/Makefile.in | 1 + - src/tests/gcred.c | 28 ++++++++--- - src/tests/t_kdcoptions.py | 100 ++++++++++++++++++++++++++++++++++++++ - 8 files changed, 189 insertions(+), 114 deletions(-) - create mode 100644 src/tests/t_kdcoptions.py - -diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c -index 588c1375a..8a96c12a9 100644 ---- a/src/kdc/do_as_req.c -+++ b/src/kdc/do_as_req.c -@@ -192,13 +192,6 @@ finish_process_as_req(struct as_req_state *state, krb5_error_code errcode) - - au_state->stage = ENCR_REP; - -- if ((errcode = validate_forwardable(state->request, *state->client, -- *state->server, state->kdc_time, -- &state->status))) { -- errcode += ERROR_TABLE_BASE_krb5; -- goto egress; -- } -- - errcode = check_indicators(kdc_context, state->server, - state->auth_indicators); - if (errcode) { -@@ -708,12 +701,11 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, - } - - /* Copy options that request the corresponding ticket flags. */ -- state->enc_tkt_reply.flags = OPTS2FLAGS(state->request->kdc_options); -+ state->enc_tkt_reply.flags = get_ticket_flags(state->request->kdc_options, -+ state->client, state->server, -+ NULL); - state->enc_tkt_reply.times.authtime = state->authtime; - -- setflag(state->enc_tkt_reply.flags, TKT_FLG_INITIAL); -- setflag(state->enc_tkt_reply.flags, TKT_FLG_ENC_PA_REP); -- - /* - * It should be noted that local policy may affect the - * processing of any of these flags. For example, some -@@ -732,10 +724,9 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, - state->enc_tkt_reply.transited.tr_type = KRB5_DOMAIN_X500_COMPRESS; - state->enc_tkt_reply.transited.tr_contents = empty_string; - -- if (isflagset(state->request->kdc_options, KDC_OPT_POSTDATED)) { -- setflag(state->enc_tkt_reply.flags, TKT_FLG_INVALID); -+ if (isflagset(state->request->kdc_options, KDC_OPT_POSTDATED)) - state->enc_tkt_reply.times.starttime = state->request->from; -- } else -+ else - state->enc_tkt_reply.times.starttime = state->kdc_time; - - kdc_get_ticket_endtime(kdc_active_realm, -diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c -index 587342a6c..1da099318 100644 ---- a/src/kdc/do_tgs_req.c -+++ b/src/kdc/do_tgs_req.c -@@ -378,15 +378,16 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, - else - ticket_reply.server = request->server; /* XXX careful for realm... */ - -- enc_tkt_reply.flags = OPTS2FLAGS(request->kdc_options); -- enc_tkt_reply.flags |= COPY_TKT_FLAGS(header_enc_tkt->flags); -+ enc_tkt_reply.flags = get_ticket_flags(request->kdc_options, client, -+ server, header_enc_tkt); - enc_tkt_reply.times.starttime = 0; - -- if (isflagset(server->attributes, KRB5_KDB_OK_AS_DELEGATE)) -- setflag(enc_tkt_reply.flags, TKT_FLG_OK_AS_DELEGATE); -- -- /* Indicate support for encrypted padata (RFC 6806). */ -- setflag(enc_tkt_reply.flags, TKT_FLG_ENC_PA_REP); -+ /* OK_TO_AUTH_AS_DELEGATE must be set on the service requesting S4U2Self -+ * for forwardable tickets to be issued. */ -+ if (isflagset(c_flags, KRB5_KDB_FLAG_PROTOCOL_TRANSITION) && -+ !is_referral && -+ !isflagset(server->attributes, KRB5_KDB_OK_TO_AUTH_AS_DELEGATE)) -+ clear(enc_tkt_reply.flags, TKT_FLG_FORWARDABLE); - - /* don't use new addresses unless forwarded, see below */ - -@@ -401,37 +402,6 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, - * realms may refuse to issue renewable tickets - */ - -- if (isflagset(request->kdc_options, KDC_OPT_FORWARDABLE)) { -- -- if (isflagset(c_flags, KRB5_KDB_FLAG_PROTOCOL_TRANSITION)) { -- /* -- * If S4U2Self principal is not forwardable, then mark ticket as -- * unforwardable. This behaviour matches Windows, but it is -- * different to the MIT AS-REQ path, which returns an error -- * (KDC_ERR_POLICY) if forwardable tickets cannot be issued. -- * -- * Consider this block the S4U2Self equivalent to -- * validate_forwardable(). -- */ -- if (client != NULL && -- isflagset(client->attributes, KRB5_KDB_DISALLOW_FORWARDABLE)) -- clear(enc_tkt_reply.flags, TKT_FLG_FORWARDABLE); -- /* -- * Forwardable flag is propagated along referral path. -- */ -- else if (!isflagset(header_enc_tkt->flags, TKT_FLG_FORWARDABLE)) -- clear(enc_tkt_reply.flags, TKT_FLG_FORWARDABLE); -- /* -- * OK_TO_AUTH_AS_DELEGATE must be set on the service requesting -- * S4U2Self in order for forwardable tickets to be returned. -- */ -- else if (!is_referral && -- !isflagset(server->attributes, -- KRB5_KDB_OK_TO_AUTH_AS_DELEGATE)) -- clear(enc_tkt_reply.flags, TKT_FLG_FORWARDABLE); -- } -- } -- - if (isflagset(request->kdc_options, KDC_OPT_FORWARDED) || - isflagset(request->kdc_options, KDC_OPT_PROXY)) { - -@@ -440,16 +410,10 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, - enc_tkt_reply.caddrs = request->addresses; - reply_encpart.caddrs = request->addresses; - } -- /* We don't currently handle issuing anonymous tickets based on -- * non-anonymous ones, so just ignore the option. */ -- if (isflagset(request->kdc_options, KDC_OPT_REQUEST_ANONYMOUS) && -- !isflagset(header_enc_tkt->flags, TKT_FLG_ANONYMOUS)) -- clear(enc_tkt_reply.flags, TKT_FLG_ANONYMOUS); - -- if (isflagset(request->kdc_options, KDC_OPT_POSTDATED)) { -- setflag(enc_tkt_reply.flags, TKT_FLG_INVALID); -+ if (isflagset(request->kdc_options, KDC_OPT_POSTDATED)) - enc_tkt_reply.times.starttime = request->from; -- } else -+ else - enc_tkt_reply.times.starttime = kdc_time; - - if (isflagset(request->kdc_options, KDC_OPT_VALIDATE)) { -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index 96c88edc1..f2741090e 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -697,29 +697,6 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - return(KDC_ERR_CANNOT_POSTDATE); - } - -- /* -- * A Windows KDC will return KDC_ERR_PREAUTH_REQUIRED instead of -- * KDC_ERR_POLICY in the following case: -- * -- * - KDC_OPT_FORWARDABLE is set in KDCOptions but local -- * policy has KRB5_KDB_DISALLOW_FORWARDABLE set for the -- * client, and; -- * - KRB5_KDB_REQUIRES_PRE_AUTH is set for the client but -- * preauthentication data is absent in the request. -- * -- * Hence, this check most be done after the check for preauth -- * data, and is now performed by validate_forwardable() (the -- * contents of which were previously below). -- */ -- -- /* Client and server must allow proxiable tickets */ -- if (isflagset(request->kdc_options, KDC_OPT_PROXIABLE) && -- (isflagset(client.attributes, KRB5_KDB_DISALLOW_PROXIABLE) || -- isflagset(server.attributes, KRB5_KDB_DISALLOW_PROXIABLE))) { -- *status = "PROXIABLE NOT ALLOWED"; -- return(KDC_ERR_POLICY); -- } -- - /* Check to see if client is locked out */ - if (isflagset(client.attributes, KRB5_KDB_DISALLOW_ALL_TIX)) { - *status = "CLIENT LOCKED OUT"; -@@ -752,19 +729,54 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - return 0; - } - --int --validate_forwardable(krb5_kdc_req *request, krb5_db_entry client, -- krb5_db_entry server, krb5_timestamp kdc_time, -- const char **status) -+/* -+ * Compute ticket flags based on the request, the client and server DB entry -+ * (which may prohibit forwardable or proxiable tickets), and the header -+ * ticket. client may be NULL for a TGS request (although it may be set, such -+ * as for an S4U2Self request). header_enc may be NULL for an AS request. -+ */ -+krb5_flags -+get_ticket_flags(krb5_flags reqflags, krb5_db_entry *client, -+ krb5_db_entry *server, krb5_enc_tkt_part *header_enc) - { -- *status = NULL; -- if (isflagset(request->kdc_options, KDC_OPT_FORWARDABLE) && -- (isflagset(client.attributes, KRB5_KDB_DISALLOW_FORWARDABLE) || -- isflagset(server.attributes, KRB5_KDB_DISALLOW_FORWARDABLE))) { -- *status = "FORWARDABLE NOT ALLOWED"; -- return(KDC_ERR_POLICY); -- } else -- return 0; -+ krb5_flags flags; -+ -+ /* Indicate support for encrypted padata (RFC 6806), and set flags based on -+ * request options and the header ticket. */ -+ flags = OPTS2FLAGS(reqflags) | TKT_FLG_ENC_PA_REP; -+ if (reqflags & KDC_OPT_POSTDATED) -+ flags |= TKT_FLG_INVALID; -+ if (header_enc != NULL) -+ flags |= COPY_TKT_FLAGS(header_enc->flags); -+ if (header_enc == NULL) -+ flags |= TKT_FLG_INITIAL; -+ -+ /* For TGS requests, indicate if the service is marked ok-as-delegate. */ -+ if (header_enc != NULL && (server->attributes & KRB5_KDB_OK_AS_DELEGATE)) -+ flags |= TKT_FLG_OK_AS_DELEGATE; -+ -+ /* Unset PROXIABLE if it is disallowed. */ -+ if (client != NULL && (client->attributes & KRB5_KDB_DISALLOW_PROXIABLE)) -+ flags &= ~TKT_FLG_PROXIABLE; -+ if (server->attributes & KRB5_KDB_DISALLOW_PROXIABLE) -+ flags &= ~TKT_FLG_PROXIABLE; -+ if (header_enc != NULL && !(header_enc->flags & TKT_FLG_PROXIABLE)) -+ flags &= ~TKT_FLG_PROXIABLE; -+ -+ /* Unset FORWARDABLE if it is disallowed. */ -+ if (client != NULL && (client->attributes & KRB5_KDB_DISALLOW_FORWARDABLE)) -+ flags &= ~TKT_FLG_FORWARDABLE; -+ if (server->attributes & KRB5_KDB_DISALLOW_FORWARDABLE) -+ flags &= ~TKT_FLG_FORWARDABLE; -+ if (header_enc != NULL && !(header_enc->flags & TKT_FLG_FORWARDABLE)) -+ flags &= ~TKT_FLG_FORWARDABLE; -+ -+ /* We don't currently handle issuing anonymous tickets based on -+ * non-anonymous ones. */ -+ if (header_enc != NULL && !(header_enc->flags & TKT_FLG_ANONYMOUS)) -+ flags &= ~TKT_FLG_ANONYMOUS; -+ -+ return flags; - } - - /* Return KRB5KDC_ERR_POLICY if indicators does not contain the required auth -diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index 25077cbf5..1314bdd58 100644 ---- a/src/kdc/kdc_util.h -+++ b/src/kdc/kdc_util.h -@@ -85,16 +85,15 @@ validate_as_request (kdc_realm_t *, krb5_kdc_req *, krb5_db_entry, - krb5_db_entry, krb5_timestamp, - const char **, krb5_pa_data ***); - --int --validate_forwardable(krb5_kdc_req *, krb5_db_entry, -- krb5_db_entry, krb5_timestamp, -- const char **); -- - int - validate_tgs_request (kdc_realm_t *, krb5_kdc_req *, krb5_db_entry, - krb5_ticket *, krb5_timestamp, - const char **, krb5_pa_data ***); - -+krb5_flags -+get_ticket_flags(krb5_flags reqflags, krb5_db_entry *client, -+ krb5_db_entry *server, krb5_enc_tkt_part *header_enc); -+ - krb5_error_code - check_indicators(krb5_context context, krb5_db_entry *server, - krb5_data *const *indicators); -diff --git a/src/kdc/tgs_policy.c b/src/kdc/tgs_policy.c -index 907fcd330..554345ba5 100644 ---- a/src/kdc/tgs_policy.c -+++ b/src/kdc/tgs_policy.c -@@ -63,9 +63,9 @@ static check_tgs_svc_pol_fn * const svc_pol_fns[] = { - }; - - static const struct tgsflagrule tgsflagrules[] = { -- { (KDC_OPT_FORWARDED | KDC_OPT_FORWARDABLE), TKT_FLG_FORWARDABLE, -+ { KDC_OPT_FORWARDED, TKT_FLG_FORWARDABLE, - "TGT NOT FORWARDABLE", KDC_ERR_BADOPTION }, -- { (KDC_OPT_PROXY | KDC_OPT_PROXIABLE), TKT_FLG_PROXIABLE, -+ { KDC_OPT_PROXY, TKT_FLG_PROXIABLE, - "TGT NOT PROXIABLE", KDC_ERR_BADOPTION }, - { (KDC_OPT_ALLOW_POSTDATE | KDC_OPT_POSTDATED), TKT_FLG_MAY_POSTDATE, - "TGT NOT POSTDATABLE", KDC_ERR_BADOPTION }, -@@ -98,12 +98,8 @@ check_tgs_opts(krb5_kdc_req *req, krb5_ticket *tkt, const char **status) - } - - static const struct tgsflagrule svcdenyrules[] = { -- { KDC_OPT_FORWARDABLE, KRB5_KDB_DISALLOW_FORWARDABLE, -- "NON-FORWARDABLE TICKET", KDC_ERR_POLICY }, - { KDC_OPT_RENEWABLE, KRB5_KDB_DISALLOW_RENEWABLE, - "NON-RENEWABLE TICKET", KDC_ERR_POLICY }, -- { KDC_OPT_PROXIABLE, KRB5_KDB_DISALLOW_PROXIABLE, -- "NON-PROXIABLE TICKET", KDC_ERR_POLICY }, - { KDC_OPT_ALLOW_POSTDATE, KRB5_KDB_DISALLOW_POSTDATED, - "NON-POSTDATABLE TICKET", KDC_ERR_CANNOT_POSTDATE }, - { KDC_OPT_ENC_TKT_IN_SKEY, KRB5_KDB_DISALLOW_DUP_SKEY, -diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in -index c96c5d6b7..d2a37c616 100644 ---- a/src/tests/Makefile.in -+++ b/src/tests/Makefile.in -@@ -171,6 +171,7 @@ check-pytests: unlockiter - $(RUNPYTEST) $(srcdir)/t_y2038.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_kdcpolicy.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_u2u.py $(PYTESTFLAGS) -+ $(RUNPYTEST) $(srcdir)/t_kdcoptions.py $(PYTESTFLAGS) - - clean: - $(RM) adata etinfo forward gcred hist hooks hrealm icinterleave icred -diff --git a/src/tests/gcred.c b/src/tests/gcred.c -index cb0ae6af5..b14e4fc9a 100644 ---- a/src/tests/gcred.c -+++ b/src/tests/gcred.c -@@ -66,20 +66,32 @@ main(int argc, char **argv) - krb5_principal client, server; - krb5_ccache ccache; - krb5_creds in_creds, *creds; -+ krb5_flags options = 0; - char *name; -+ int c; - - check(krb5_init_context(&ctx)); - -- /* Parse arguments. */ -- assert(argc == 3); -- check(krb5_parse_name(ctx, argv[2], &server)); -- if (strcmp(argv[1], "unknown") == 0) -+ while ((c = getopt(argc, argv, "f")) != -1) { -+ switch (c) { -+ case 'f': -+ options |= KRB5_GC_FORWARDABLE; -+ break; -+ default: -+ abort(); -+ } -+ } -+ argc -= optind; -+ argv += optind; -+ assert(argc == 2); -+ check(krb5_parse_name(ctx, argv[1], &server)); -+ if (strcmp(argv[0], "unknown") == 0) - server->type = KRB5_NT_UNKNOWN; -- else if (strcmp(argv[1], "principal") == 0) -+ else if (strcmp(argv[0], "principal") == 0) - server->type = KRB5_NT_PRINCIPAL; -- else if (strcmp(argv[1], "srv-inst") == 0) -+ else if (strcmp(argv[0], "srv-inst") == 0) - server->type = KRB5_NT_SRV_INST; -- else if (strcmp(argv[1], "srv-hst") == 0) -+ else if (strcmp(argv[0], "srv-hst") == 0) - server->type = KRB5_NT_SRV_HST; - else - abort(); -@@ -89,7 +101,7 @@ main(int argc, char **argv) - memset(&in_creds, 0, sizeof(in_creds)); - in_creds.client = client; - in_creds.server = server; -- check(krb5_get_credentials(ctx, 0, ccache, &in_creds, &creds)); -+ check(krb5_get_credentials(ctx, options, ccache, &in_creds, &creds)); - check(krb5_unparse_name(ctx, creds->server, &name)); - printf("%s\n", name); - -diff --git a/src/tests/t_kdcoptions.py b/src/tests/t_kdcoptions.py -new file mode 100644 -index 000000000..7ec57508c ---- /dev/null -+++ b/src/tests/t_kdcoptions.py -@@ -0,0 +1,100 @@ -+from k5test import * -+import re -+ -+# KDC option test coverage notes: -+# -+# FORWARDABLE here -+# FORWARDED no test -+# PROXIABLE here -+# PROXY no test -+# ALLOW_POSTDATE no test -+# POSTDATED no test -+# RENEWABLE t_renew.py -+# CNAME_IN_ADDL_TKT gssapi/t_s4u.py -+# CANONICALIZE t_kdb.py and various other tests -+# REQUEST_ANONYMOUS t_pkinit.py -+# DISABLE_TRANSITED_CHECK no test -+# RENEWABLE_OK t_renew.py -+# ENC_TKT_IN_SKEY t_u2u.py -+# RENEW t_renew.py -+# VALIDATE no test -+ -+# Run klist -f and return the flags on the ticket for svcprinc. -+def get_flags(realm, svcprinc): -+ grab_flags = False -+ for line in realm.run([klist, '-f']).splitlines(): -+ if grab_flags: -+ return re.findall(r'Flags: ([a-zA-Z]*)', line)[0] -+ grab_flags = line.endswith(svcprinc) -+ -+ -+# Get the flags on the ticket for svcprinc, and check for an expected -+# element and an expected-absent element, either of which can be None. -+def check_flags(realm, svcprinc, expected_flag, expected_noflag): -+ flags = get_flags(realm, svcprinc) -+ if expected_flag is not None and not expected_flag in flags: -+ fail('expected flag ' + expected_flag) -+ if expected_noflag is not None and expected_noflag in flags: -+ fail('did not expect flag ' + expected_noflag) -+ -+ -+# Run kinit with the given flags, and check the flags on the resulting -+# TGT. -+def kinit_check_flags(realm, flags, expected_flag, expected_noflag): -+ realm.kinit(realm.user_princ, password('user'), flags) -+ check_flags(realm, realm.krbtgt_princ, expected_flag, expected_noflag) -+ -+ -+# Run kinit with kflags. Then get credentials for the host principal -+# with gflags, and check the flags on the resulting ticket. -+def gcred_check_flags(realm, kflags, gflags, expected_flag, expected_noflag): -+ realm.kinit(realm.user_princ, password('user'), kflags) -+ realm.run(['./gcred'] + gflags + ['unknown', realm.host_princ]) -+ check_flags(realm, realm.host_princ, expected_flag, expected_noflag) -+ -+ -+realm = K5Realm() -+ -+mark('proxiable (AS)') -+kinit_check_flags(realm, [], None, 'P') -+kinit_check_flags(realm, ['-p'], 'P', None) -+realm.run([kadminl, 'modprinc', '-allow_proxiable', realm.user_princ]) -+kinit_check_flags(realm, ['-p'], None, 'P') -+realm.run([kadminl, 'modprinc', '+allow_proxiable', realm.user_princ]) -+realm.run([kadminl, 'modprinc', '-allow_proxiable', realm.krbtgt_princ]) -+kinit_check_flags(realm, ['-p'], None, 'P') -+realm.run([kadminl, 'modprinc', '+allow_proxiable', realm.krbtgt_princ]) -+ -+mark('proxiable (TGS)') -+gcred_check_flags(realm, [], [], None, 'P') -+gcred_check_flags(realm, ['-p'], [], 'P', None) -+ -+# Not tested: PROXIABLE option set with a non-proxiable TGT (because -+# there is no krb5_get_credentials() flag to request this; would -+# expect a non-proxiable ticket). -+ -+# Not tested: proxiable TGT but PROXIABLE flag not set (because we -+# internally set the PROXIABLE option when using a proxiable TGT; -+# would expect a non-proxiable ticket). -+ -+mark('forwardable (AS)') -+kinit_check_flags(realm, [], None, 'F') -+kinit_check_flags(realm, ['-f'], 'F', None) -+realm.run([kadminl, 'modprinc', '-allow_forwardable', realm.user_princ]) -+kinit_check_flags(realm, ['-f'], None, 'F') -+realm.run([kadminl, 'modprinc', '+allow_forwardable', realm.user_princ]) -+realm.run([kadminl, 'modprinc', '-allow_forwardable', realm.krbtgt_princ]) -+kinit_check_flags(realm, ['-f'], None, 'F') -+realm.run([kadminl, 'modprinc', '+allow_forwardable', realm.krbtgt_princ]) -+ -+mark('forwardable (TGS)') -+realm.kinit(realm.user_princ, password('user')) -+gcred_check_flags(realm, [], [], None, 'F') -+gcred_check_flags(realm, [], ['-f'], None, 'F') -+gcred_check_flags(realm, ['-f'], [], 'F', None) -+ -+# Not tested: forwardable TGT but FORWARDABLE flag not set (because we -+# internally set the FORWARDABLE option when using a forwardable TGT; -+# would expect a non-proxiable ticket). -+ -+success('KDC option tests') diff --git a/Display-unsupported-enctype-names.patch b/Display-unsupported-enctype-names.patch deleted file mode 100644 index 3ee3283..0000000 --- a/Display-unsupported-enctype-names.patch +++ /dev/null @@ -1,79 +0,0 @@ -From c8b24f222719df0c4b9815d26019ad96c551ec81 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 21 May 2019 13:34:39 -0400 -Subject: [PATCH] Display unsupported enctype names - -Add a table of unsupported enctype numbers to enctype_util.c and -consult it in krb5_enctype_to_name(). Treat unsupported enctype -numbers as deprecated in krb5int_c_deprecated_enctype(). In kadmin, -display "UNSUPPORTED:" before invalid enctype names. - -ticket: 8808 -(cherry picked from commit ebbc6e8e99ee9d5d757411200a6a3173171774df) ---- - src/kadmin/cli/kadmin.c | 4 +++- - src/lib/crypto/krb/enctype_util.c | 22 +++++++++++++++++++++- - 2 files changed, 24 insertions(+), 2 deletions(-) - -diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c -index fe4cb493c..b4d1aad93 100644 ---- a/src/kadmin/cli/kadmin.c -+++ b/src/kadmin/cli/kadmin.c -@@ -1461,7 +1461,9 @@ kadmin_getprinc(int argc, char *argv[]) - enctype, sizeof(enctype))) - snprintf(enctype, sizeof(enctype), _(""), - key_data->key_data_type[0]); -- if (krb5int_c_deprecated_enctype(key_data->key_data_type[0])) -+ if (!krb5_c_valid_enctype(key_data->key_data_type[0])) -+ deprecated = "UNSUPPORTED:"; -+ else if (krb5int_c_deprecated_enctype(key_data->key_data_type[0])) - deprecated = "DEPRECATED:"; - printf("Key: vno %d, %s%s", key_data->key_data_kvno, deprecated, - enctype); -diff --git a/src/lib/crypto/krb/enctype_util.c b/src/lib/crypto/krb/enctype_util.c -index e394f4e19..1542d4062 100644 ---- a/src/lib/crypto/krb/enctype_util.c -+++ b/src/lib/crypto/krb/enctype_util.c -@@ -36,6 +36,18 @@ - - #include "crypto_int.h" - -+struct { -+ krb5_enctype etype; -+ const char *name; -+} unsupported_etypes[] = { -+ { ENCTYPE_DES_CBC_CRC, "des-cbc-crc" }, -+ { ENCTYPE_DES_CBC_MD4, "des-cbc-md4" }, -+ { ENCTYPE_DES_CBC_MD5, "des-cbc-md5" }, -+ { ENCTYPE_DES_CBC_RAW, "des-cbc-raw" }, -+ { ENCTYPE_DES_HMAC_SHA1, "des-hmac-sha1" }, -+ { ENCTYPE_NULL, NULL } -+}; -+ - krb5_boolean KRB5_CALLCONV - krb5_c_valid_enctype(krb5_enctype etype) - { -@@ -55,7 +67,7 @@ krb5_boolean KRB5_CALLCONV - krb5int_c_deprecated_enctype(krb5_enctype etype) - { - const struct krb5_keytypes *ktp = find_enctype(etype); -- return ktp != NULL && (ktp->flags & ETYPE_DEPRECATED) != 0; -+ return ktp == NULL || (ktp->flags & ETYPE_DEPRECATED) != 0; - } - - krb5_error_code KRB5_CALLCONV -@@ -122,6 +134,14 @@ krb5_enctype_to_name(krb5_enctype enctype, krb5_boolean shortest, - const char *name; - int i; - -+ for (i = 0; unsupported_etypes[i].etype != ENCTYPE_NULL; i++) { -+ if (enctype == unsupported_etypes[i].etype) { -+ if (strlcpy(buffer, unsupported_etypes[i].name, buflen) >= buflen) -+ return ENOMEM; -+ return 0; -+ } -+ } -+ - ktp = find_enctype(enctype); - if (ktp == NULL) - return EINVAL; diff --git a/Do-not-always-canonicalize-enterprise-principals.patch b/Do-not-always-canonicalize-enterprise-principals.patch deleted file mode 100644 index fcaed36..0000000 --- a/Do-not-always-canonicalize-enterprise-principals.patch +++ /dev/null @@ -1,113 +0,0 @@ -From f1890cb3b09789e62c6711d79b032a7af0a09ea8 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Sat, 2 Nov 2019 13:32:32 +0100 -Subject: [PATCH] Do not always canonicalize enterprise principals - -When processing an AS request in the KDC, do not assume -KRB5_KDB_FLAG_CANONICALIZE for enterprise client names. This change -allows the KDB module to only canonicalize enterprise client names if -the canonicalize flag was set on the request, as Windows does. The -KDB module may check the principal type and apply canonicalization as -appropriate. - -[ghudson@mit.edu: edited comments; rewrote commit message] - -ticket: 8858 (new) -(cherry picked from commit 3f5955631a2056f8ec4d1ce73d9681fa7da061c2) ---- - src/include/kdb.h | 21 ++++++++++++--------- - src/kdc/do_as_req.c | 9 ++++----- - src/tests/t_kdb.py | 12 ++++++++++++ - 3 files changed, 28 insertions(+), 14 deletions(-) - -diff --git a/src/include/kdb.h b/src/include/kdb.h -index 7749cfc99..1dd37cdab 100644 ---- a/src/include/kdb.h -+++ b/src/include/kdb.h -@@ -1023,15 +1023,18 @@ typedef struct _kdb_vftabl { - * in-realm alias, fill in a different value for entries->princ than the - * one requested. - * -- * A module can return out-of-realm referrals if KRB5_KDB_FLAG_CANONICALIZE -- * is set. For AS request clients (KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY is -- * also set), the module should do so by simply filling in an out-of-realm -- * name in entries->princ and setting all other fields to NULL. Otherwise, -- * the module should return the entry for the cross-realm TGS of the -- * referred-to realm. For TGS referals, the module can also include -- * tl-data of type KRB5_TL_SERVER_REFERRAL containing ASN.1-encoded Windows -- * referral data as documented in draft-ietf-krb-wg-kerberos-referrals-11 -- * appendix A; this will be returned to the client as encrypted padata. -+ * A module can return a referral to another realm if -+ * KRB5_KDB_FLAG_CANONICALIZE is set, or if -+ * KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY is set and search_for->type is -+ * KRB5_NT_ENTERPRISE_PRINCIPAL. If KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY is -+ * set, the module should return a referral by simply filling in an -+ * out-of-realm name in (*entry)->princ and setting all other fields to -+ * NULL. Otherwise, the module should return the entry for the cross-realm -+ * TGS of the referred-to realm. For TGS referals, the module can also -+ * include tl-data of type KRB5_TL_SERVER_REFERRAL containing ASN.1-encoded -+ * Windows referral data as documented in -+ * draft-ietf-krb-wg-kerberos-referrals-11 appendix A; this will be -+ * returned to the client as encrypted padata. - */ - krb5_error_code (*get_principal)(krb5_context kcontext, - krb5_const_principal search_for, -diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c -index 8a96c12a9..02c0a8a1f 100644 ---- a/src/kdc/do_as_req.c -+++ b/src/kdc/do_as_req.c -@@ -585,15 +585,14 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, - * of cross realm TGS entries. - */ - setflag(state->c_flags, KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY); -- /* -- * Note that according to the referrals draft we should -- * always canonicalize enterprise principal names. -- */ -+ /* Enterprise principals are implicitly alias-ok. */ - if (isflagset(state->request->kdc_options, KDC_OPT_CANONICALIZE) || - state->request->client->type == KRB5_NT_ENTERPRISE_PRINCIPAL) { -- setflag(state->c_flags, KRB5_KDB_FLAG_CANONICALIZE); - setflag(state->c_flags, KRB5_KDB_FLAG_ALIAS_OK); - } -+ if (isflagset(state->request->kdc_options, KDC_OPT_CANONICALIZE)) { -+ setflag(state->c_flags, KRB5_KDB_FLAG_CANONICALIZE); -+ } - if (include_pac_p(kdc_context, state->request)) { - setflag(state->c_flags, KRB5_KDB_FLAG_INCLUDE_PAC); - } -diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py -index cc5d2fc3c..7271fcbbd 100755 ---- a/src/tests/t_kdb.py -+++ b/src/tests/t_kdb.py -@@ -340,11 +340,14 @@ ldap_modify('dn: krbPrincipalName=canon@KRBTEST.COM,cn=t1,cn=krb5\n' - 'changetype: modify\n' - 'add: krbPrincipalName\n' - 'krbPrincipalName: alias@KRBTEST.COM\n' -+ 'krbPrincipalName: ent@abc@KRBTEST.COM\n' - '-\n' - 'add: krbCanonicalName\n' - 'krbCanonicalName: canon@KRBTEST.COM\n') - realm.run([kadminl, 'getprinc', 'alias'], - expected_msg='Principal: canon@KRBTEST.COM\n') -+realm.run([kadminl, 'getprinc', 'ent\@abc'], -+ expected_msg='Principal: canon@KRBTEST.COM\n') - realm.run([kadminl, 'getprinc', 'canon'], - expected_msg='Principal: canon@KRBTEST.COM\n') - realm.run([kvno, 'alias', 'canon']) -@@ -389,6 +392,15 @@ realm.run([kadminl, 'modprinc', '+requires_preauth', 'canon']) - realm.kinit('canon', password('canon')) - realm.kinit('alias', password('canon'), ['-C']) - -+# Test enterprise alias with and without canonicalization. -+realm.kinit('ent@abc', password('canon'), ['-E', '-C']) -+realm.run([kvno, 'alias']) -+realm.klist('canon@KRBTEST.COM', 'alias@KRBTEST.COM') -+ -+realm.kinit('ent@abc', password('canon'), ['-E']) -+realm.run([kvno, 'alias']) -+realm.klist('ent\@abc@KRBTEST.COM', 'alias@KRBTEST.COM') -+ - # Test client name canonicalization in non-krbtgt AS reply - realm.kinit('alias', password('canon'), ['-C', '-S', 'kadmin/changepw']) - diff --git a/Don-t-error-on-invalid-enctypes-in-keytab.patch b/Don-t-error-on-invalid-enctypes-in-keytab.patch deleted file mode 100644 index 6152aaa..0000000 --- a/Don-t-error-on-invalid-enctypes-in-keytab.patch +++ /dev/null @@ -1,67 +0,0 @@ -From d39897c46818f990eb7752573c309b97d90a983e Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 10 Jul 2019 17:10:16 -0400 -Subject: [PATCH] Don't error on invalid enctypes in keytab - -krb5_ktfile_get_entry() used krb5_c_enctype_compare() to compare -enctypes, in order to share keys between single-DES enctypes. As -key-sharing between enctypes is no longer done and single-DES support -has been removed, use a simple equality test to match the enctype. -This fixes a bug where krb5_kt_get_entry() would error out if the -keytab contained any entries with invalid enctypes (include single-DES -entries, after commit fb2dada5eb89c4cd4e39dedd6dbb7dbd5e94f8b8) even -if a matching entry is found. - -[ghudson@mit.edu: rewrote commit message] - -ticket: 8808 -(cherry picked from commit 38be1a0a31a6104cdf8c8d72828905775f6d6636) ---- - src/lib/krb5/keytab/kt_file.c | 27 +++++---------------------- - 1 file changed, 5 insertions(+), 22 deletions(-) - -diff --git a/src/lib/krb5/keytab/kt_file.c b/src/lib/krb5/keytab/kt_file.c -index 21c80d419..df2530a45 100644 ---- a/src/lib/krb5/keytab/kt_file.c -+++ b/src/lib/krb5/keytab/kt_file.c -@@ -289,7 +289,6 @@ krb5_ktfile_get_entry(krb5_context context, krb5_keytab id, - krb5_keytab_entry cur_entry, new_entry; - krb5_error_code kerror = 0; - int found_wrong_kvno = 0; -- krb5_boolean similar; - int was_open; - char *princname; - -@@ -336,27 +335,11 @@ krb5_ktfile_get_entry(krb5_context context, krb5_keytab id, - continue; - } - -- /* if the enctype is not ignored and doesn't match, free new_entry -- and continue to the next */ -- -- if (enctype != IGNORE_ENCTYPE) { -- if ((kerror = krb5_c_enctype_compare(context, enctype, -- new_entry.key.enctype, -- &similar))) { -- krb5_kt_free_entry(context, &new_entry); -- break; -- } -- -- if (!similar) { -- krb5_kt_free_entry(context, &new_entry); -- continue; -- } -- /* -- * Coerce the enctype of the output keyblock in case we -- * got an inexact match on the enctype. -- */ -- new_entry.key.enctype = enctype; -- -+ /* If the enctype is not ignored and doesn't match, free new_entry and -+ continue to the next. */ -+ if (enctype != IGNORE_ENCTYPE && enctype != new_entry.key.enctype) { -+ krb5_kt_free_entry(context, &new_entry); -+ continue; - } - - if (kvno == IGNORE_VNO || new_entry.vno == IGNORE_VNO) { diff --git a/Don-t-warn-in-kadmin-when-no-policy-is-specified.patch b/Don-t-warn-in-kadmin-when-no-policy-is-specified.patch deleted file mode 100644 index 220c59f..0000000 --- a/Don-t-warn-in-kadmin-when-no-policy-is-specified.patch +++ /dev/null @@ -1,160 +0,0 @@ -From aec16ed11477f08f477f915fb8119271d688711c Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 19 Dec 2019 17:49:05 -0500 -Subject: [PATCH] Don't warn in kadmin when no policy is specified - -Not having policy defined is a normal occurrence. While it's a useful -message to log in case it's unexpected, the current form is -unnecessarily alarmist. - -ticket: 8857 (new) -(cherry picked from commit 2ca842d5cbd5981ab5fa50e418359763c9f1a6d5) ---- - doc/admin/admin_commands/kadmin_local.rst | 2 +- - doc/admin/database.rst | 4 ++-- - doc/admin/install_kdc.rst | 6 +++--- - src/kadmin/cli/kadmin.c | 4 ++-- - src/man/kadmin.man | 2 +- - src/po/de.po | 8 ++++---- - src/po/mit-krb5.pot | 4 ++-- - 7 files changed, 15 insertions(+), 15 deletions(-) - -diff --git a/doc/admin/admin_commands/kadmin_local.rst b/doc/admin/admin_commands/kadmin_local.rst -index 71aa894f6..fafa61365 100644 ---- a/doc/admin/admin_commands/kadmin_local.rst -+++ b/doc/admin/admin_commands/kadmin_local.rst -@@ -419,7 +419,7 @@ Options: - Example:: - - kadmin: addprinc jennifer -- WARNING: no policy specified for "jennifer@ATHENA.MIT.EDU"; -+ No policy specified for "jennifer@ATHENA.MIT.EDU"; - defaulting to no policy. - Enter password for principal jennifer@ATHENA.MIT.EDU: - Re-enter password for principal jennifer@ATHENA.MIT.EDU: -diff --git a/doc/admin/database.rst b/doc/admin/database.rst -index cea60b009..8505fe1ec 100644 ---- a/doc/admin/database.rst -+++ b/doc/admin/database.rst -@@ -103,7 +103,7 @@ If you want to create a principal which is contained by a LDAP object, - all you need to do is:: - - kadmin: addprinc -x dn=cn=jennifer,dc=example,dc=com jennifer -- WARNING: no policy specified for "jennifer@ATHENA.MIT.EDU"; -+ No policy specified for "jennifer@ATHENA.MIT.EDU"; - defaulting to no policy. - Enter password for principal jennifer@ATHENA.MIT.EDU: <= Type the password. - Re-enter password for principal jennifer@ATHENA.MIT.EDU: <=Type it again. -@@ -114,7 +114,7 @@ If you want to create a principal under a specific LDAP container and - link to an existing LDAP object, all you need to do is:: - - kadmin: addprinc -x containerdn=dc=example,dc=com -x linkdn=cn=david,dc=example,dc=com david -- WARNING: no policy specified for "david@ATHENA.MIT.EDU"; -+ No policy specified for "david@ATHENA.MIT.EDU"; - defaulting to no policy. - Enter password for principal david@ATHENA.MIT.EDU: <= Type the password. - Re-enter password for principal david@ATHENA.MIT.EDU: <=Type it again. -diff --git a/doc/admin/install_kdc.rst b/doc/admin/install_kdc.rst -index 3bec59f96..157c6059e 100644 ---- a/doc/admin/install_kdc.rst -+++ b/doc/admin/install_kdc.rst -@@ -239,7 +239,7 @@ is created:: - - kadmin.local: addprinc admin/admin@ATHENA.MIT.EDU - -- WARNING: no policy specified for "admin/admin@ATHENA.MIT.EDU"; -+ No policy specified for "admin/admin@ATHENA.MIT.EDU"; - assigning "default". - Enter password for principal admin/admin@ATHENA.MIT.EDU: <= Enter a password. - Re-enter password for principal admin/admin@ATHENA.MIT.EDU: <= Type it again. -@@ -316,11 +316,11 @@ following:: - - shell% kadmin - kadmin: addprinc -randkey host/kerberos.mit.edu -- NOTICE: no policy specified for "host/kerberos.mit.edu@ATHENA.MIT.EDU"; assigning "default" -+ No policy specified for "host/kerberos.mit.edu@ATHENA.MIT.EDU"; assigning "default" - Principal "host/kerberos.mit.edu@ATHENA.MIT.EDU" created. - - kadmin: addprinc -randkey host/kerberos-1.mit.edu -- NOTICE: no policy specified for "host/kerberos-1.mit.edu@ATHENA.MIT.EDU"; assigning "default" -+ No policy specified for "host/kerberos-1.mit.edu@ATHENA.MIT.EDU"; assigning "default" - Principal "host/kerberos-1.mit.edu@ATHENA.MIT.EDU" created. - - It is not strictly necessary to have the master KDC server in the -diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c -index b4d1aad93..a6e858d82 100644 ---- a/src/kadmin/cli/kadmin.c -+++ b/src/kadmin/cli/kadmin.c -@@ -1229,13 +1229,13 @@ kadmin_addprinc(int argc, char *argv[]) - /* If the policy "default" exists, assign it. */ - if (policy_exists("default")) { - if (!script_mode) { -- fprintf(stderr, _("NOTICE: no policy specified for %s; " -+ fprintf(stderr, _("No policy specified for %s; " - "assigning \"default\"\n"), canon); - } - princ.policy = "default"; - mask |= KADM5_POLICY; - } else if (!script_mode) { -- fprintf(stderr, _("WARNING: no policy specified for %s; " -+ fprintf(stderr, _("No policy specified for %s; " - "defaulting to no policy\n"), canon); - } - } -diff --git a/src/man/kadmin.man b/src/man/kadmin.man -index 44859a378..b514fe279 100644 ---- a/src/man/kadmin.man -+++ b/src/man/kadmin.man -@@ -458,7 +458,7 @@ Example: - .nf - .ft C - kadmin: addprinc jennifer --WARNING: no policy specified for "jennifer@ATHENA.MIT.EDU"; -+No policy specified for "jennifer@ATHENA.MIT.EDU"; - defaulting to no policy. - Enter password for principal jennifer@ATHENA.MIT.EDU: - Re\-enter password for principal jennifer@ATHENA.MIT.EDU: -diff --git a/src/po/de.po b/src/po/de.po -index 40e31da90..5d78bdded 100644 ---- a/src/po/de.po -+++ b/src/po/de.po -@@ -1690,16 +1690,16 @@ msgstr "WARNUNG: Richtlinie »%s« existiert nicht.\n" - - #: ../../src/kadmin/cli/kadmin.c:1230 - #, c-format --msgid "NOTICE: no policy specified for %s; assigning \"default\"\n" -+msgid "No policy specified for %s; assigning \"default\"\n" - msgstr "" --"HINWEIS: Für %s wurde keine Richtlinie angegeben, es wird »default« " -+"Für %s wurde keine Richtlinie angegeben, es wird »default« " - "zugewiesen\n" - - #: ../../src/kadmin/cli/kadmin.c:1235 - #, c-format --msgid "WARNING: no policy specified for %s; defaulting to no policy\n" -+msgid "No policy specified for %s; defaulting to no policy\n" - msgstr "" --"WARNUNG: Für %s wurde keine Richtlinie angegeben, es wird die Vorgabe " -+"Für %s wurde keine Richtlinie angegeben, es wird die Vorgabe " - "»keine\n" - "Richtlinie« verwandt.\n" - -diff --git a/src/po/mit-krb5.pot b/src/po/mit-krb5.pot -index 8cfbe9f3c..de1998d2f 100644 ---- a/src/po/mit-krb5.pot -+++ b/src/po/mit-krb5.pot -@@ -1645,12 +1645,12 @@ msgstr "" - - #: ../../src/kadmin/cli/kadmin.c:1228 - #, c-format --msgid "NOTICE: no policy specified for %s; assigning \"default\"\n" -+msgid "No policy specified for %s; assigning \"default\"\n" - msgstr "" - - #: ../../src/kadmin/cli/kadmin.c:1234 - #, c-format --msgid "WARNING: no policy specified for %s; defaulting to no policy\n" -+msgid "No policy specified for %s; defaulting to no policy\n" - msgstr "" - - #: ../../src/kadmin/cli/kadmin.c:1276 diff --git a/Filter-enctypes-in-gss_set_allowable_enctypes.patch b/Filter-enctypes-in-gss_set_allowable_enctypes.patch deleted file mode 100644 index 182071c..0000000 --- a/Filter-enctypes-in-gss_set_allowable_enctypes.patch +++ /dev/null @@ -1,70 +0,0 @@ -From 073c20a214df8b416b8d848412256c57feb43ef0 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 16 Jul 2019 00:15:42 -0400 -Subject: [PATCH] Filter enctypes in gss_set_allowable_enctypes() - -Instead of erroring out when any invalid enctypes are present in the -caller's list, filter out the invalid ones and only error if no -enctypes remain. - -ticket: 8819 -(cherry picked from commit 37ab7ea128a4c2aa2dad65ab9006baded5335bc7) ---- - src/lib/gssapi/krb5/set_allowable_enctypes.c | 29 ++++++++++---------- - 1 file changed, 14 insertions(+), 15 deletions(-) - -diff --git a/src/lib/gssapi/krb5/set_allowable_enctypes.c b/src/lib/gssapi/krb5/set_allowable_enctypes.c -index d9fd279ed..a74b161cb 100644 ---- a/src/lib/gssapi/krb5/set_allowable_enctypes.c -+++ b/src/lib/gssapi/krb5/set_allowable_enctypes.c -@@ -66,7 +66,7 @@ gss_krb5int_set_allowable_enctypes(OM_uint32 *minor_status, - const gss_OID desired_oid, - const gss_buffer_t value) - { -- unsigned int i; -+ unsigned int i, j; - krb5_enctype * new_ktypes; - OM_uint32 major_status; - krb5_gss_cred_id_t cred; -@@ -83,14 +83,7 @@ gss_krb5int_set_allowable_enctypes(OM_uint32 *minor_status, - /* verify and valildate cred handle */ - cred = (krb5_gss_cred_id_t) *cred_handle; - -- if (req->ktypes) { -- for (i = 0; i < req->num_ktypes && req->ktypes[i]; i++) { -- if (!krb5_c_valid_enctype(req->ktypes[i])) { -- kerr = KRB5_PROG_ETYPE_NOSUPP; -- goto error_out; -- } -- } -- } else { -+ if (req->ktypes == NULL) { - k5_mutex_lock(&cred->lock); - if (cred->req_enctypes) - free(cred->req_enctypes); -@@ -99,13 +92,19 @@ gss_krb5int_set_allowable_enctypes(OM_uint32 *minor_status, - return GSS_S_COMPLETE; - } - -- /* Copy the requested ktypes into the cred structure */ -- if ((new_ktypes = (krb5_enctype *)malloc(sizeof(krb5_enctype) * (i + 1)))) { -- memcpy(new_ktypes, req->ktypes, sizeof(krb5_enctype) * i); -- new_ktypes[i] = 0; /* "null-terminate" the list */ -+ /* Copy the requested enctypes into the cred structure. Filter out the -+ * ones we don't consider valid. Error out if no enctypes are valid. */ -+ new_ktypes = k5calloc(req->num_ktypes + 1, sizeof(*new_ktypes), &kerr); -+ if (new_ktypes == NULL) -+ goto error_out; -+ for (i = 0, j = 0; i < req->num_ktypes && req->ktypes[i]; i++) { -+ if (krb5_c_valid_enctype(req->ktypes[i])) -+ new_ktypes[j++] = req->ktypes[i]; - } -- else { -- kerr = ENOMEM; -+ new_ktypes[j] = 0; -+ if (j == 0) { -+ free(new_ktypes); -+ kerr = KRB5_PROG_ETYPE_NOSUPP; - goto error_out; - } - k5_mutex_lock(&cred->lock); diff --git a/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch b/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch deleted file mode 100644 index a8d5901..0000000 --- a/Fix-Coverity-defects-in-soft-pkcs11-test-code.patch +++ /dev/null @@ -1,206 +0,0 @@ -From 14bc517f1fbd0bc7b3a6137871c167c595747a3e Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 20 Jul 2019 00:51:52 -0400 -Subject: [PATCH] Fix Coverity defects in soft-pkcs11 test code - -Nothing in the code removes objects from soft_token.object.obs, so -simplify add_st_object() not to search for an empty slot. Avoid using -random() by using a counter for session handles and just the array -slot number for object handles. Add a helper get_rcfilename() to -facilitate checking the result of asprintf(). Properly initialize ap -in sprintf_fill(). Close the file handle in read_conf_file(). - -(cherry picked from commit b4831515b2f3b6fd7d7fd4bff4558c10c710891d) ---- - src/tests/softpkcs11/main.c | 102 +++++++++++++++++++----------------- - 1 file changed, 53 insertions(+), 49 deletions(-) - -diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c -index 5255323d3..2d1448ca2 100644 ---- a/src/tests/softpkcs11/main.c -+++ b/src/tests/softpkcs11/main.c -@@ -78,6 +78,7 @@ compat_rsa_get0_key(const RSA *rsa, const BIGNUM **n, const BIGNUM **e, - (BL) = i2d_##T((S), &p); \ - if ((BL) <= 0) { \ - free((B)); \ -+ (B) = NULL; \ - (R) = EINVAL; \ - } \ - } \ -@@ -149,6 +150,7 @@ static struct soft_token { - } state[10]; - #define MAX_NUM_SESSION (sizeof(soft_token.state)/sizeof(soft_token.state[0])) - FILE *logfile; -+ CK_SESSION_HANDLE next_session_handle; - } soft_token; - - static void -@@ -179,6 +181,7 @@ snprintf_fill(char *str, int size, char fillchar, const char *fmt, ...) - { - int len; - va_list ap; -+ va_start(ap, fmt); - len = vsnprintf(str, size, fmt, ap); - va_end(ap); - if (len < 0 || len > size) -@@ -344,7 +347,13 @@ static struct st_object * - add_st_object(void) - { - struct st_object *o, **objs; -- int i; -+ -+ objs = realloc(soft_token.object.objs, -+ (soft_token.object.num_objs + 1) * -+ sizeof(soft_token.object.objs[0])); -+ if (objs == NULL) -+ return NULL; -+ soft_token.object.objs = objs; - - o = malloc(sizeof(*o)); - if (o == NULL) -@@ -352,26 +361,9 @@ add_st_object(void) - memset(o, 0, sizeof(*o)); - o->attrs = NULL; - o->num_attributes = 0; -+ o->object_handle = soft_token.object.num_objs; - -- for (i = 0; i < soft_token.object.num_objs; i++) { -- if (soft_token.object.objs == NULL) { -- soft_token.object.objs[i] = o; -- break; -- } -- } -- if (i == soft_token.object.num_objs) { -- objs = realloc(soft_token.object.objs, -- (soft_token.object.num_objs + 1) * sizeof(soft_token.object.objs[0])); -- if (objs == NULL) { -- free(o); -- return NULL; -- } -- soft_token.object.objs = objs; -- soft_token.object.objs[soft_token.object.num_objs++] = o; -- } -- soft_token.object.objs[i]->object_handle = -- (random() & (~OBJECT_ID_MASK)) | i; -- -+ soft_token.object.objs[soft_token.object.num_objs++] = o; - return o; - } - -@@ -797,6 +789,8 @@ read_conf_file(const char *fn) - - add_certificate(label, cert, key, id, anchor); - } -+ -+ fclose(f); - } - - static CK_RV -@@ -806,19 +800,47 @@ func_not_supported(void) - return CKR_FUNCTION_NOT_SUPPORTED; - } - -+static char * -+get_rcfilename() -+{ -+ struct passwd *pw; -+ const char *home = NULL; -+ char *fn; -+ -+ if (getuid() == geteuid()) { -+ fn = getenv("SOFTPKCS11RC"); -+ if (fn != NULL) -+ return strdup(fn); -+ -+ home = getenv("HOME"); -+ } -+ -+ if (home == NULL) { -+ pw = getpwuid(getuid()); -+ if (pw != NULL) -+ home = pw->pw_dir; -+ } -+ -+ if (home == NULL) -+ return strdup("/etc/soft-token.rc"); -+ -+ if (asprintf(&fn, "%s/.soft-token.rc", home) < 0) -+ return NULL; -+ return fn; -+} -+ - CK_RV - C_Initialize(CK_VOID_PTR a) - { - CK_C_INITIALIZE_ARGS_PTR args = a; - size_t i; -+ char *fn; - - st_logf("Initialize\n"); - - OpenSSL_add_all_algorithms(); - ERR_load_crypto_strings(); - -- srandom(getpid() ^ time(NULL)); -- - for (i = 0; i < MAX_NUM_SESSION; i++) { - soft_token.state[i].session_handle = CK_INVALID_HANDLE; - soft_token.state[i].find.attributes = NULL; -@@ -850,31 +872,13 @@ C_Initialize(CK_VOID_PTR a) - st_logf("\tFlags\t%04x\n", (unsigned int)args->flags); - } - -- { -- char *fn = NULL, *home = NULL; -- -- if (getuid() == geteuid()) { -- fn = getenv("SOFTPKCS11RC"); -- if (fn) -- fn = strdup(fn); -- home = getenv("HOME"); -- } -- if (fn == NULL && home == NULL) { -- struct passwd *pw = getpwuid(getuid()); -- if(pw != NULL) -- home = pw->pw_dir; -- } -- if (fn == NULL) { -- if (home) -- asprintf(&fn, "%s/.soft-token.rc", home); -- else -- fn = strdup("/etc/soft-token.rc"); -- } -- -- read_conf_file(fn); -- free(fn); -- } -+ soft_token.next_session_handle = 0; - -+ fn = get_rcfilename(); -+ if (fn == NULL) -+ return CKR_DEVICE_MEMORY; -+ read_conf_file(fn); -+ free(fn); - return CKR_OK; - } - -@@ -1082,8 +1086,7 @@ C_OpenSession(CK_SLOT_ID slotID, - - soft_token.open_sessions++; - -- soft_token.state[i].session_handle = -- (CK_SESSION_HANDLE)(random() & 0xfffff); -+ soft_token.state[i].session_handle = soft_token.next_session_handle++; - *phSession = soft_token.state[i].session_handle; - - return CKR_OK; -@@ -1152,7 +1155,8 @@ C_Login(CK_SESSION_HANDLE hSession, - VERIFY_SESSION_HANDLE(hSession, NULL); - - if (pPin != NULL_PTR) { -- asprintf(&pin, "%.*s", (int)ulPinLen, pPin); -+ if (asprintf(&pin, "%.*s", (int)ulPinLen, pPin) < 0) -+ return CKR_DEVICE_MEMORY; - st_logf("type: %d password: %s\n", (int)userType, pin); - } - diff --git a/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch b/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch deleted file mode 100644 index 56bcd85..0000000 --- a/Fix-KDC-crash-when-logging-PKINIT-enctypes.patch +++ /dev/null @@ -1,31 +0,0 @@ -From 2f939727e531f04a24b687b9807b2e23599a2e4f Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 25 Sep 2019 12:57:56 -0400 -Subject: [PATCH] Fix KDC crash when logging PKINIT enctypes - -Commit a649279727490687d54becad91fde8cf7429d951 introduced a KDC crash -bug due to transposed strlcpy() arguments. Fix the argument order. - -This bug does not affect any MIT krb5 release, but affects the Fedora -krb5 packages due to backports. CVE-2019-14844 has been issued as a -result. - -ticket: 8772 -(cherry picked from commit 275c9a1aad36a1a7b56042f1a2c21c33e7d16eaf) ---- - src/kdc/kdc_util.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index 23ad6c584..698f18c1c 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -1080,7 +1080,7 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) - else - return krb5_enctype_to_name(ktype, FALSE, buf, buflen); - -- if (strlcpy(name, buf, buflen) >= buflen) -+ if (strlcpy(buf, name, buflen) >= buflen) - return ENOMEM; - return 0; - } diff --git a/Fix-LDAP-policy-enforcement-of-pw_expiration.patch b/Fix-LDAP-policy-enforcement-of-pw_expiration.patch deleted file mode 100644 index 45b0484..0000000 --- a/Fix-LDAP-policy-enforcement-of-pw_expiration.patch +++ /dev/null @@ -1,302 +0,0 @@ -From d62cb044abe57eda1216f9ab97f50bd178f1d495 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 17 Dec 2019 17:37:41 -0500 -Subject: [PATCH] Fix LDAP policy enforcement of pw_expiration - -In the LDAP backend, the change mask is used to determine what LDAP -attributes to update. As a result, password expiration was not set -from policy when running during addprinc, among other issues. -However, when the mask did not contain KADM5_PRINCIPAL, pw_expiration -would be applied regardless, which meant that (for instance) changing -the password would cause the password application to be applied. - -Remove the check for KADM5_PRINCIPAL, and fix the mask to contain -KADM5_PW_EXPIRATION where appropriate. Add a regression test to -t_kdb.py. - -[ghudson@mit.edu: also set KADM5_ATTRIBUTES for randkey and setkey -since they both unset KRB5_KDB_REQUIRES_PWCHANGE; edited comments and -commit message] - -ticket: 8861 (new) -tags: pullup -target_version: 1.17-next - -(cherry picked from commit 6b004dd5739bded71be4290c11e7ac3a816c7e09) ---- - src/lib/kadm5/srv/svr_principal.c | 92 +++++++++---------- - .../kdb/ldap/libkdb_ldap/ldap_principal2.c | 13 --- - src/tests/t_kdb.py | 17 ++++ - 3 files changed, 60 insertions(+), 62 deletions(-) - -diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c -index a1ecdbfc4..35bbf1218 100644 ---- a/src/lib/kadm5/srv/svr_principal.c -+++ b/src/lib/kadm5/srv/svr_principal.c -@@ -356,6 +356,11 @@ kadm5_create_principal_3(void *server_handle, - kdb = calloc(1, sizeof(*kdb)); - if (kdb == NULL) - return ENOMEM; -+ -+ /* In all cases the principal entry is new and key data is set; let the -+ * database provider know. */ -+ kdb->mask = mask | KADM5_KEY_DATA | KADM5_PRINCIPAL; -+ - memset(&adb, 0, sizeof(osa_princ_ent_rec)); - - /* -@@ -405,14 +410,12 @@ kadm5_create_principal_3(void *server_handle, - kdb->expiration = handle->params.expiration; - - kdb->pw_expiration = 0; -- if (have_polent) { -- if(polent.pw_max_life) -- kdb->pw_expiration = ts_incr(now, polent.pw_max_life); -- else -- kdb->pw_expiration = 0; -- } -- if ((mask & KADM5_PW_EXPIRATION)) -+ if (mask & KADM5_PW_EXPIRATION) { - kdb->pw_expiration = entry->pw_expiration; -+ } else if (have_polent && polent.pw_max_life) { -+ kdb->mask |= KADM5_PW_EXPIRATION; -+ kdb->pw_expiration = ts_incr(now, polent.pw_max_life); -+ } - - kdb->last_success = 0; - kdb->last_failed = 0; -@@ -503,9 +506,6 @@ kadm5_create_principal_3(void *server_handle, - adb.policy = entry->policy; - } - -- /* In all cases key and the principal data is set, let the database provider know */ -- kdb->mask = mask | KADM5_KEY_DATA | KADM5_PRINCIPAL ; -- - /* store the new db entry */ - ret = kdb_put_entry(handle, kdb, &adb); - -@@ -601,6 +601,9 @@ kadm5_modify_principal(void *server_handle, - if (ret) - return(ret); - -+ /* Let the mask propagate to the database provider. */ -+ kdb->mask = mask; -+ - /* - * This is pretty much the same as create ... - */ -@@ -616,11 +619,15 @@ kadm5_modify_principal(void *server_handle, - free(adb.policy); - adb.policy = strdup(entry->policy); - } -- if (have_pol) { -+ -+ if (mask & KADM5_PW_EXPIRATION) { -+ kdb->pw_expiration = entry->pw_expiration; -+ } else if (have_pol) { - /* set pw_max_life based on new policy */ -+ kdb->mask |= KADM5_PW_EXPIRATION; - if (pol.pw_max_life) { - ret = krb5_dbe_lookup_last_pwd_change(handle->context, kdb, -- &(kdb->pw_expiration)); -+ &kdb->pw_expiration); - if (ret) - goto done; - kdb->pw_expiration = ts_incr(kdb->pw_expiration, pol.pw_max_life); -@@ -642,8 +649,6 @@ kadm5_modify_principal(void *server_handle, - kdb->max_life = entry->max_life; - if ((mask & KADM5_PRINC_EXPIRE_TIME)) - kdb->expiration = entry->princ_expire_time; -- if (mask & KADM5_PW_EXPIRATION) -- kdb->pw_expiration = entry->pw_expiration; - if (mask & KADM5_MAX_RLIFE) - kdb->max_renewable_life = entry->max_renewable_life; - -@@ -682,9 +687,6 @@ kadm5_modify_principal(void *server_handle, - kdb->fail_auth_count = 0; - } - -- /* let the mask propagate to the database provider */ -- kdb->mask = mask; -- - ret = k5_kadm5_hook_modify(handle->context, handle->hook_handles, - KADM5_HOOK_STAGE_PRECOMMIT, entry, mask); - if (ret) -@@ -1362,6 +1364,11 @@ kadm5_chpass_principal_3(void *server_handle, - if ((ret = kdb_get_entry(handle, principal, &kdb, &adb))) - return(ret); - -+ /* We will always be changing the key data, attributes, auth failure count, -+ * and password expiration time. */ -+ kdb->mask = KADM5_KEY_DATA | KADM5_ATTRIBUTES | KADM5_FAIL_AUTH_COUNT | -+ KADM5_PW_EXPIRATION; -+ - ret = apply_keysalt_policy(handle, adb.policy, n_ks_tuple, ks_tuple, - &new_n_ks_tuple, &new_ks_tuple); - if (ret) -@@ -1407,6 +1414,7 @@ kadm5_chpass_principal_3(void *server_handle, - if (ret) - goto done; - -+ kdb->pw_expiration = 0; - if ((adb.aux_attributes & KADM5_POLICY)) { - /* the policy was loaded before */ - -@@ -1439,10 +1447,6 @@ kadm5_chpass_principal_3(void *server_handle, - - if (pol.pw_max_life) - kdb->pw_expiration = ts_incr(now, pol.pw_max_life); -- else -- kdb->pw_expiration = 0; -- } else { -- kdb->pw_expiration = 0; - } - - #ifdef USE_PASSWORD_SERVER -@@ -1481,11 +1485,6 @@ kadm5_chpass_principal_3(void *server_handle, - /* unlock principal on this KDC */ - kdb->fail_auth_count = 0; - -- /* key data and attributes changed, let the database provider know */ -- kdb->mask = KADM5_KEY_DATA | KADM5_ATTRIBUTES | -- KADM5_FAIL_AUTH_COUNT; -- /* | KADM5_CPW_FUNCTION */ -- - if (hist_added) - kdb->mask |= KADM5_KEY_HIST; - -@@ -1560,6 +1559,11 @@ kadm5_randkey_principal_3(void *server_handle, - if ((ret = kdb_get_entry(handle, principal, &kdb, &adb))) - return(ret); - -+ /* We will always be changing the key data, attributes, auth failure count, -+ * and password expiration time. */ -+ kdb->mask = KADM5_KEY_DATA | KADM5_ATTRIBUTES | KADM5_FAIL_AUTH_COUNT | -+ KADM5_PW_EXPIRATION; -+ - ret = apply_keysalt_policy(handle, adb.policy, n_ks_tuple, ks_tuple, - &new_n_ks_tuple, &new_ks_tuple); - if (ret) -@@ -1599,14 +1603,10 @@ kadm5_randkey_principal_3(void *server_handle, - if (ret) - goto done; - } -- if (have_pol) { -- if (pol.pw_max_life) -- kdb->pw_expiration = ts_incr(now, pol.pw_max_life); -- else -- kdb->pw_expiration = 0; -- } else { -- kdb->pw_expiration = 0; -- } -+ -+ kdb->pw_expiration = 0; -+ if (have_pol && pol.pw_max_life) -+ kdb->pw_expiration = ts_incr(now, pol.pw_max_life); - - ret = krb5_dbe_update_last_pwd_change(handle->context, kdb, now); - if (ret) -@@ -1624,10 +1624,6 @@ kadm5_randkey_principal_3(void *server_handle, - goto done; - } - -- /* key data changed, let the database provider know */ -- kdb->mask = KADM5_KEY_DATA | KADM5_FAIL_AUTH_COUNT; -- /* | KADM5_RANDKEY_USED */; -- - ret = k5_kadm5_hook_chpass(handle->context, handle->hook_handles, - KADM5_HOOK_STAGE_PRECOMMIT, principal, keepold, - new_n_ks_tuple, new_ks_tuple, NULL); -@@ -1763,6 +1759,11 @@ kadm5_setkey_principal_4(void *server_handle, krb5_principal principal, - if (ret) - return ret; - -+ /* We will always be changing the key data, attributes, auth failure count, -+ * and password expiration time. */ -+ kdb->mask = KADM5_KEY_DATA | KADM5_ATTRIBUTES | KADM5_FAIL_AUTH_COUNT | -+ KADM5_PW_EXPIRATION; -+ - if (kvno == 0) { - /* Pick the next kvno. */ - for (i = 0; i < kdb->n_key_data; i++) { -@@ -1864,14 +1865,10 @@ kadm5_setkey_principal_4(void *server_handle, krb5_principal principal, - if (ret) - goto done; - } -- if (have_pol) { -- if (pol.pw_max_life) -- kdb->pw_expiration = ts_incr(now, pol.pw_max_life); -- else -- kdb->pw_expiration = 0; -- } else { -- kdb->pw_expiration = 0; -- } -+ -+ kdb->pw_expiration = 0; -+ if (have_pol && pol.pw_max_life) -+ kdb->pw_expiration = ts_incr(now, pol.pw_max_life); - - ret = krb5_dbe_update_last_pwd_change(handle->context, kdb, now); - if (ret) -@@ -1880,9 +1877,6 @@ kadm5_setkey_principal_4(void *server_handle, krb5_principal principal, - /* Unlock principal on this KDC. */ - kdb->fail_auth_count = 0; - -- /* key data changed, let the database provider know */ -- kdb->mask = KADM5_KEY_DATA | KADM5_FAIL_AUTH_COUNT; -- - ret = kdb_put_entry(handle, kdb, &adb); - if (ret) - goto done; -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -index ee9c02814..fa0a2c683 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -@@ -1233,19 +1233,6 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, - goto cleanup; - } - -- if (!(entry->mask & KADM5_PRINCIPAL)) { -- memset(strval, 0, sizeof(strval)); -- if ((strval[0]=getstringtime(entry->pw_expiration)) == NULL) -- goto cleanup; -- if ((st=krb5_add_str_mem_ldap_mod(&mods, -- "krbpasswordexpiration", -- LDAP_MOD_REPLACE, strval)) != 0) { -- free (strval[0]); -- goto cleanup; -- } -- free (strval[0]); -- } -- - /* Update last password change whenever a new key is set */ - { - krb5_timestamp last_pw_changed; -diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py -index 7271fcbbd..d18f672c1 100755 ---- a/src/tests/t_kdb.py -+++ b/src/tests/t_kdb.py -@@ -494,6 +494,23 @@ else: - realm.run([kadminl, 'modprinc', '-pwexpire', '2040-02-03', 'user']) - realm.run([kadminl, 'getprinc', 'user'], expected_msg=' 2040\n') - -+# Regression test for #8861 (pw_expiration policy enforcement). -+mark('pw_expiration propogation') -+# Create a policy with a max life and verify its application. -+realm.run([kadminl, 'addpol', '-maxlife', '1s', 'pw_e']) -+realm.run([kadminl, 'addprinc', '-policy', 'pw_e', '-pw', 'password', -+ 'pwuser']) -+out = realm.run([kadminl, 'getprinc', 'pwuser'], -+ expected_msg='Password expiration date: ') -+if 'Password expiration date: [never]' in out: -+ fail('pw_expiration not applied at principal creation') -+# Unset the policy max life and verify its application during password -+# change. -+realm.run([kadminl, 'modpol', '-maxlife', '0', 'pw_e']) -+realm.run([kadminl, 'cpw', '-pw', 'password_', 'pwuser']) -+realm.run([kadminl, 'getprinc', 'pwuser'], -+ expected_msg='Password expiration date: [never]') -+ - realm.stop() - - # Briefly test dump and load. diff --git a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch b/Fix-config-realm-change-logic-in-FILE-remove_cred.patch deleted file mode 100644 index c662158..0000000 --- a/Fix-config-realm-change-logic-in-FILE-remove_cred.patch +++ /dev/null @@ -1,29 +0,0 @@ -From bde05bf227939691855c025ce3c79cda07093fa7 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 16 Apr 2019 10:47:35 -0400 -Subject: [PATCH] Fix config realm change logic in FILE remove_cred - -Use data_eq_string() to check the server realm, and do not check if -cred->server is NULL since it is not expected to be (and -k5_marshal_cred() would have already crashed if it were). - -ticket: 8792 -(cherry picked from commit e5367fcddd53dc4db0c1fd2279e91eda3791960a) ---- - src/lib/krb5/ccache/cc_file.c | 3 +-- - 1 file changed, 1 insertion(+), 2 deletions(-) - -diff --git a/src/lib/krb5/ccache/cc_file.c b/src/lib/krb5/ccache/cc_file.c -index 09da38fa9..a3f67766e 100644 ---- a/src/lib/krb5/ccache/cc_file.c -+++ b/src/lib/krb5/ccache/cc_file.c -@@ -1058,8 +1058,7 @@ delete_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor, - - /* For config entries, also change the realm so that other implementations - * won't match them. */ -- if (cred->server != NULL && cred->server->realm.length > 0 && -- strcmp(cred->server->realm.data, "X-CACHECONF:") == 0) -+ if (data_eq_string(cred->server->realm, "X-CACHECONF:")) - memcpy(cred->server->realm.data, "X-RMED-CONF:", 12); - - k5_marshal_cred(&overwrite, fcursor->version, cred); diff --git a/Fix-handling-of-invalid-CAMMAC-service-verifier.patch b/Fix-handling-of-invalid-CAMMAC-service-verifier.patch deleted file mode 100644 index bc285c2..0000000 --- a/Fix-handling-of-invalid-CAMMAC-service-verifier.patch +++ /dev/null @@ -1,30 +0,0 @@ -From 87d0a1364b9ddb4b9ed8dfaee3022172bfb879ba Mon Sep 17 00:00:00 2001 -From: Jeffrey Arbuckle -Date: Sat, 21 Dec 2019 22:59:20 -0500 -Subject: [PATCH] Fix handling of invalid CAMMAC service verifier - -In extract_cammacs(), avoid a null dereference if the CAMMAC service -verifier is invalid or the CAMMAC is empty. - -ticket: 8856 -tags: pullup -target_version: 1.17-next - -(cherry picked from commit 8451ff6ed57361de585a35f35a39c54dc48172c7) ---- - src/lib/krb5/krb/authdata.c | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/src/lib/krb5/krb/authdata.c b/src/lib/krb5/krb/authdata.c -index 3e7dfbe49..d3096e5a2 100644 ---- a/src/lib/krb5/krb/authdata.c -+++ b/src/lib/krb5/krb/authdata.c -@@ -557,6 +557,8 @@ extract_cammacs(krb5_context kcontext, krb5_authdata **cammacs, - if (ret && ret != KRB5KRB_AP_ERR_BAD_INTEGRITY) - goto cleanup; - ret = 0; -+ if (elements == NULL) -+ continue; - - /* Add the verified elements to list and free the container array. */ - for (n_elements = 0; elements[n_elements] != NULL; n_elements++); diff --git a/Fix-memory-leaks-in-soft-pkcs11-code.patch b/Fix-memory-leaks-in-soft-pkcs11-code.patch deleted file mode 100644 index acc2938..0000000 --- a/Fix-memory-leaks-in-soft-pkcs11-code.patch +++ /dev/null @@ -1,122 +0,0 @@ -From b0acd2918e673a60a88cfed9fe7da08fb7fc4987 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 5 Aug 2019 01:53:51 -0400 -Subject: [PATCH] Fix memory leaks in soft-pkcs11 code - -Fix leaks detected by asan in t_pkinit.py. Add a helper to free a -struct st_object and free objects in C_Finalize(). Duplicate the X509 -cert in add_certificate() instead of creating aliases so it can be -properly freed. Start the session handle counter at 1 so that -C_Finalize() won't confuse the first session handle with -CK_INVALID_HANDLE (defined to 0 in pkinit.h) and will properly clean -the session object. - -(cherry picked from commit 15bcaf8bcb4af25ff89820ad3bf23ad5a324e863) ---- - src/tests/softpkcs11/main.c | 44 +++++++++++++++++++++++++++++++++---- - 1 file changed, 40 insertions(+), 4 deletions(-) - -diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c -index 2d1448ca2..a4c3ae78e 100644 ---- a/src/tests/softpkcs11/main.c -+++ b/src/tests/softpkcs11/main.c -@@ -109,7 +109,7 @@ struct st_object { - X509 *cert; - EVP_PKEY *public_key; - struct { -- const char *file; -+ char *file; - EVP_PKEY *key; - X509 *cert; - } private_key; -@@ -343,6 +343,26 @@ print_attributes(const CK_ATTRIBUTE *attributes, - } - } - -+static void -+free_st_object(struct st_object *o) -+{ -+ int i; -+ -+ for (i = 0; i < o->num_attributes; i++) -+ free(o->attrs[i].attribute.pValue); -+ free(o->attrs); -+ if (o->type == STO_T_CERTIFICATE) { -+ X509_free(o->u.cert); -+ } else if (o->type == STO_T_PRIVATE_KEY) { -+ free(o->u.private_key.file); -+ EVP_PKEY_free(o->u.private_key.key); -+ X509_free(o->u.private_key.cert); -+ } else if (o->type == STO_T_PUBLIC_KEY) { -+ EVP_PKEY_free(o->u.public_key); -+ } -+ free(o); -+} -+ - static struct st_object * - add_st_object(void) - { -@@ -518,7 +538,11 @@ add_certificate(char *label, - goto out; - } - o->type = STO_T_CERTIFICATE; -- o->u.cert = cert; -+ o->u.cert = X509_dup(cert); -+ if (o->u.cert == NULL) { -+ ret = CKR_DEVICE_MEMORY; -+ goto out; -+ } - public_key = X509_get_pubkey(o->u.cert); - - switch (EVP_PKEY_base_id(public_key)) { -@@ -602,7 +626,11 @@ add_certificate(char *label, - o->u.private_key.file = strdup(private_key_file); - o->u.private_key.key = NULL; - -- o->u.private_key.cert = cert; -+ o->u.private_key.cert = X509_dup(cert); -+ if (o->u.private_key.cert == NULL) { -+ ret = CKR_DEVICE_MEMORY; -+ goto out; -+ } - - c = CKO_PRIVATE_KEY; - add_object_attribute(o, 0, CKA_CLASS, &c, sizeof(c)); -@@ -676,6 +704,7 @@ add_certificate(char *label, - free(serial_data); - free(issuer_data); - free(subject_data); -+ X509_free(cert); - - return ret; - } -@@ -872,7 +901,7 @@ C_Initialize(CK_VOID_PTR a) - st_logf("\tFlags\t%04x\n", (unsigned int)args->flags); - } - -- soft_token.next_session_handle = 0; -+ soft_token.next_session_handle = 1; - - fn = get_rcfilename(); - if (fn == NULL) -@@ -886,6 +915,7 @@ CK_RV - C_Finalize(CK_VOID_PTR args) - { - size_t i; -+ int j; - - st_logf("Finalize\n"); - -@@ -897,6 +927,12 @@ C_Finalize(CK_VOID_PTR args) - } - } - -+ for (j = 0; j < soft_token.object.num_objs; j++) -+ free_st_object(soft_token.object.objs[j]); -+ free(soft_token.object.objs); -+ soft_token.object.objs = NULL; -+ soft_token.object.num_objs = 0; -+ - return CKR_OK; - } - diff --git a/Fix-minor-errors-in-softpkcs11.patch b/Fix-minor-errors-in-softpkcs11.patch deleted file mode 100644 index 963faec..0000000 --- a/Fix-minor-errors-in-softpkcs11.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 343068058951e343179156e895c7483ab8194236 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 8 Nov 2019 14:28:56 -0500 -Subject: [PATCH] Fix minor errors in softpkcs11 - -Fix a printf type mismatch in attributes_match() reported by Coverity, -and a possible uninitizlied use of key_type in add_certificate() -reported by clang. - -[ghudson@mit.edu: squashed commits and rewrote commit message] - -(cherry picked from commit 560e48fee9a192ed4eb1b6cbd62c119087b53948) ---- - src/tests/softpkcs11/main.c | 7 ++++--- - 1 file changed, 4 insertions(+), 3 deletions(-) - -diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c -index a4c3ae78e..1cccdfb43 100644 ---- a/src/tests/softpkcs11/main.c -+++ b/src/tests/softpkcs11/main.c -@@ -261,7 +261,7 @@ attributes_match(const struct st_object *obj, - } - } - if (match == 0) { -- st_logf("type %d attribute have no match\n", attributes[i].type); -+ st_logf("type %lu attribute have no match\n", attributes[i].type); - return 0; - } - } -@@ -553,8 +553,9 @@ add_certificate(char *label, - key_type = CKK_DSA; - break; - default: -- /* XXX */ -- break; -+ st_logf("invalid key_type\n"); -+ ret = CKR_GENERAL_ERROR; -+ goto out; - } - - c = CKO_CERTIFICATE; diff --git a/Fix-potential-close-1-in-cc_file.c.patch b/Fix-potential-close-1-in-cc_file.c.patch deleted file mode 100644 index 5e7136c..0000000 --- a/Fix-potential-close-1-in-cc_file.c.patch +++ /dev/null @@ -1,30 +0,0 @@ -From 20e18b31bac004c13b7f2b5b1e67e80730481aea Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 18 Apr 2019 13:39:37 -0400 -Subject: [PATCH] Fix potential close(-1) in cc_file.c - -As part of error handling in d3b39a8bac6206b5ea78b0bf6a2958c1df0b0dd5, -an error path in delete_cred() may result in close(-1). While this -shouldn't be a prolblem in practice (just returning EBADF), it does -upset Coverity. - -ticket: 8792 -(cherry picked from commit 5ccfbaf2f0c8871d2f0ea87ad4b21cc33392ca2c) ---- - src/lib/krb5/ccache/cc_file.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/src/lib/krb5/ccache/cc_file.c b/src/lib/krb5/ccache/cc_file.c -index a3f67766e..bf58c1d45 100644 ---- a/src/lib/krb5/ccache/cc_file.c -+++ b/src/lib/krb5/ccache/cc_file.c -@@ -1122,7 +1122,8 @@ delete_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor, - } - - cleanup: -- close(fd); -+ if (fd >= 0) -+ close(fd); - zapfree(on_disk, expected.len); - k5_buf_free(&expected); - k5_buf_free(&overwrite); diff --git a/Fix-xdr_bytes-strict-aliasing-violations.patch b/Fix-xdr_bytes-strict-aliasing-violations.patch deleted file mode 100644 index 34082c0..0000000 --- a/Fix-xdr_bytes-strict-aliasing-violations.patch +++ /dev/null @@ -1,138 +0,0 @@ -From e48e04d955c809c6f7b4f9052294d407f0d93daa Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 10 Dec 2019 12:06:05 -0500 -Subject: [PATCH] Fix xdr_bytes() strict-aliasing violations - -When xdr_bytes() is used for a gss_buffer_desc object, a temporary -character pointer must be used for the data value to avoid a strict -aliasing violation. - -When xdr_bytes() is used for a krb5_keyblock object, a temporary -character pointer must also be used, even though the data pointer is -of type unsigned char *, to avoid a clang warning on macOS due to the -"#pragma pack" declaration in krb5.h. - -(cherry picked from commit 21b39d0196e3e0bb6b1bfbf5d60a0596cfc82e27) ---- - src/lib/kadm5/kadm_rpc_xdr.c | 8 +++++--- - src/lib/rpc/auth_gssapi_misc.c | 21 +++++++++++++-------- - src/lib/rpc/authgss_prot.c | 5 ++++- - 3 files changed, 22 insertions(+), 12 deletions(-) - -diff --git a/src/lib/kadm5/kadm_rpc_xdr.c b/src/lib/kadm5/kadm_rpc_xdr.c -index f22ea7f1f..8383e4e23 100644 ---- a/src/lib/kadm5/kadm_rpc_xdr.c -+++ b/src/lib/kadm5/kadm_rpc_xdr.c -@@ -1125,14 +1125,16 @@ xdr_krb5_salttype(XDR *xdrs, krb5_int32 *objp) - bool_t - xdr_krb5_keyblock(XDR *xdrs, krb5_keyblock *objp) - { -+ char *cp; -+ - /* XXX This only works because free_keyblock assumes ->contents - is allocated by malloc() */ -- - if(!xdr_krb5_enctype(xdrs, &objp->enctype)) - return FALSE; -- if(!xdr_bytes(xdrs, (char **) &objp->contents, (unsigned int *) -- &objp->length, ~0)) -+ cp = (char *)objp->contents; -+ if(!xdr_bytes(xdrs, &cp, &objp->length, ~0)) - return FALSE; -+ objp->contents = (uint8_t *)cp; - return TRUE; - } - -diff --git a/src/lib/rpc/auth_gssapi_misc.c b/src/lib/rpc/auth_gssapi_misc.c -index a05ea19eb..a60eb7f7c 100644 ---- a/src/lib/rpc/auth_gssapi_misc.c -+++ b/src/lib/rpc/auth_gssapi_misc.c -@@ -45,9 +45,11 @@ bool_t xdr_gss_buf( - bool_t result; - /* Fix type mismatches between APIs. */ - unsigned int length = buf->length; -- result = xdr_bytes(xdrs, (char **) &buf->value, &length, -+ char *cp = buf->value; -+ result = xdr_bytes(xdrs, &cp, &length, - (xdrs->x_op == XDR_DECODE && buf->value == NULL) - ? (unsigned int) -1 : (unsigned int) buf->length); -+ buf->value = cp; - buf->length = length; - return result; - } -@@ -204,6 +206,7 @@ bool_t auth_gssapi_wrap_data( - XDR temp_xdrs; - int conf_state; - unsigned int length; -+ char *cp; - - PRINTF(("gssapi_wrap_data: starting\n")); - -@@ -243,13 +246,13 @@ bool_t auth_gssapi_wrap_data( - - /* write the token */ - length = out_buf.length; -- if (! xdr_bytes(out_xdrs, (char **) &out_buf.value, -- (unsigned int *) &length, -- out_buf.length)) { -+ cp = out_buf.value; -+ if (! xdr_bytes(out_xdrs, &cp, &length, out_buf.length)) { - PRINTF(("gssapi_wrap_data: serializing encrypted data failed\n")); - XDR_DESTROY(&temp_xdrs); - return FALSE; - } -+ out_buf.value = cp; - - *major = gss_release_buffer(minor, &out_buf); - -@@ -272,6 +275,7 @@ bool_t auth_gssapi_unwrap_data( - uint32_t verf_seq_num; - int conf, qop; - unsigned int length; -+ char *cp; - - PRINTF(("gssapi_unwrap_data: starting\n")); - -@@ -280,14 +284,15 @@ bool_t auth_gssapi_unwrap_data( - - in_buf.value = NULL; - out_buf.value = NULL; -- if (! xdr_bytes(in_xdrs, (char **) &in_buf.value, -- &length, (unsigned int) -1)) { -+ cp = in_buf.value; -+ if (! xdr_bytes(in_xdrs, &cp, &length, (unsigned int) -1)) { - PRINTF(("gssapi_unwrap_data: deserializing encrypted data failed\n")); - temp_xdrs.x_op = XDR_FREE; -- (void)xdr_bytes(&temp_xdrs, (char **) &in_buf.value, &length, -- (unsigned int) -1); -+ (void)xdr_bytes(&temp_xdrs, &cp, &length, (unsigned int) -1); -+ in_buf.value = NULL; - return FALSE; - } -+ in_buf.value = cp; - in_buf.length = length; - - *major = gss_unseal(minor, context, &in_buf, &out_buf, &conf, -diff --git a/src/lib/rpc/authgss_prot.c b/src/lib/rpc/authgss_prot.c -index a5a587f90..9a48277b3 100644 ---- a/src/lib/rpc/authgss_prot.c -+++ b/src/lib/rpc/authgss_prot.c -@@ -50,6 +50,7 @@ xdr_rpc_gss_buf(XDR *xdrs, gss_buffer_t buf, u_int maxsize) - { - bool_t xdr_stat; - u_int tmplen; -+ char *cp; - - if (xdrs->x_op != XDR_DECODE) { - if (buf->length > UINT_MAX) -@@ -57,7 +58,9 @@ xdr_rpc_gss_buf(XDR *xdrs, gss_buffer_t buf, u_int maxsize) - else - tmplen = buf->length; - } -- xdr_stat = xdr_bytes(xdrs, (char **)&buf->value, &tmplen, maxsize); -+ cp = buf->value; -+ xdr_stat = xdr_bytes(xdrs, &cp, &tmplen, maxsize); -+ buf->value = cp; - - if (xdr_stat && xdrs->x_op == XDR_DECODE) - buf->length = tmplen; diff --git a/Implement-krb5_cc_remove_cred-for-remaining-types.patch b/Implement-krb5_cc_remove_cred-for-remaining-types.patch deleted file mode 100644 index 65ddcf7..0000000 --- a/Implement-krb5_cc_remove_cred-for-remaining-types.patch +++ /dev/null @@ -1,599 +0,0 @@ -From adeba65ff738184656bb9589e1e3ffb079d3adf0 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 1 Apr 2019 14:28:48 -0400 -Subject: [PATCH] Implement krb5_cc_remove_cred for remaining types - -Previously, only KCM and MSLA implemented credential removal. Add -support for FILE (and therefore DIR), MEMORY, and KEYRING. - -The FILE logic is similar Heimdal's implementation, with additional -logic for skipping removed creds during iteration. In addition to -setting endtime to 0 and changing the realm for config entries as -Heimdal does, we set authtime to -1 to make deleted entries -distinguishable from gssproxy encrypted creds and config entries. - -For MEMORY, leave behind empty list elements when removing a cred will -leave behind an empty list element, in case an iterator holds a -pointer to that element. - -[ghudson@mit.edu: edited commit message; made minor style and comment -changes; fixed memory leaks detected by asan] - -ticket: 8792 (new) -(cherry picked from commit d3b39a8bac6206b5ea78b0bf6a2958c1df0b0dd5) ---- - src/lib/krb5/ccache/cc_file.c | 177 ++++++++++++++++++++++++++++--- - src/lib/krb5/ccache/cc_keyring.c | 89 +++++++++++----- - src/lib/krb5/ccache/cc_memory.c | 36 +++++-- - src/lib/krb5/ccache/t_cc.c | 129 +++++++++++++++++++++- - 4 files changed, 381 insertions(+), 50 deletions(-) - -diff --git a/src/lib/krb5/ccache/cc_file.c b/src/lib/krb5/ccache/cc_file.c -index 9263a0054..09da38fa9 100644 ---- a/src/lib/krb5/ccache/cc_file.c -+++ b/src/lib/krb5/ccache/cc_file.c -@@ -744,6 +744,14 @@ cleanup: - return set_errmsg_filename(context, ret, data->filename); - } - -+/* Return true if cred is a removed entry (assuming that no legitimate cred -+ * entries will have authtime=-1 and endtime=0). */ -+static inline krb5_boolean -+cred_removed(krb5_creds *c) -+{ -+ return c->times.endtime == 0 && c->times.authtime == -1; -+} -+ - /* Get the next credential from the cache file. */ - static krb5_error_code KRB5_CALLCONV - fcc_next_cred(krb5_context context, krb5_ccache id, krb5_cc_cursor *cursor, -@@ -765,19 +773,30 @@ fcc_next_cred(krb5_context context, krb5_ccache id, krb5_cc_cursor *cursor, - goto cleanup; - file_locked = TRUE; - -- /* Load a marshalled cred into memory. */ -- ret = get_size(context, fcursor->fp, &maxsize); -- if (ret) -- goto cleanup; -- ret = load_cred(context, fcursor->fp, fcursor->version, maxsize, &buf); -- if (ret) -- goto cleanup; -- ret = k5_buf_status(&buf); -- if (ret) -- goto cleanup; -+ for (;;) { -+ /* Load a marshalled cred into memory. */ -+ ret = get_size(context, fcursor->fp, &maxsize); -+ if (ret) -+ goto cleanup; -+ ret = load_cred(context, fcursor->fp, fcursor->version, maxsize, &buf); -+ if (ret) -+ goto cleanup; -+ ret = k5_buf_status(&buf); -+ if (ret) -+ goto cleanup; - -- /* Unmarshal it from buf into creds. */ -- ret = k5_unmarshal_cred(buf.data, buf.len, fcursor->version, creds); -+ /* Unmarshal it from buf into creds. */ -+ ret = k5_unmarshal_cred(buf.data, buf.len, fcursor->version, creds); -+ if (ret) -+ goto cleanup; -+ -+ /* Keep going if this entry has been removed; otherwise stop. */ -+ if (!cred_removed(creds)) -+ break; -+ -+ k5_buf_truncate(&buf, 0); -+ krb5_free_cred_contents(context, creds); -+ } - - cleanup: - if (file_locked) -@@ -1002,12 +1021,142 @@ cleanup: - return set_errmsg_filename(context, ret ? ret : ret2, data->filename); - } - --/* Non-functional stub for removing a cred from the cache file. */ -+/* -+ * Overwrite cred in the ccache file with an entry that should not match any -+ * reasonable search. Deletion is not guaranteed. This method is originally -+ * from Heimdal, with the addition of setting authtime to -1. -+ */ -+static krb5_error_code -+delete_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor, -+ krb5_creds *cred) -+{ -+ krb5_error_code ret; -+ krb5_fcc_cursor *fcursor = *cursor; -+ fcc_data *data = cache->data; -+ struct k5buf expected = EMPTY_K5BUF, overwrite = EMPTY_K5BUF; -+ int fd = -1; -+ uint8_t *on_disk = NULL; -+ ssize_t rwret; -+ off_t start_offset; -+ -+ k5_buf_init_dynamic_zap(&expected); -+ k5_buf_init_dynamic_zap(&overwrite); -+ -+ /* Re-marshal cred to get its byte representation in the file. */ -+ k5_marshal_cred(&expected, fcursor->version, cred); -+ ret = k5_buf_status(&expected); -+ if (ret) -+ goto cleanup; -+ -+ /* -+ * Mark the cred expired so that it will be skipped over by any future -+ * match checks. Heimdal only sets endtime, but we also set authtime to -+ * distinguish from gssproxy's creds. -+ */ -+ cred->times.endtime = 0; -+ cred->times.authtime = -1; -+ -+ /* For config entries, also change the realm so that other implementations -+ * won't match them. */ -+ if (cred->server != NULL && cred->server->realm.length > 0 && -+ strcmp(cred->server->realm.data, "X-CACHECONF:") == 0) -+ memcpy(cred->server->realm.data, "X-RMED-CONF:", 12); -+ -+ k5_marshal_cred(&overwrite, fcursor->version, cred); -+ ret = k5_buf_status(&overwrite); -+ if (ret) -+ goto cleanup; -+ -+ if (expected.len != overwrite.len) { -+ ret = KRB5_CC_FORMAT; -+ goto cleanup; -+ } -+ -+ /* Get a non-O_APPEND handle to the raw file. */ -+ fd = open(data->filename, O_RDWR | O_BINARY | O_CLOEXEC); -+ if (fd == -1) { -+ ret = interpret_errno(context, errno); -+ goto cleanup; -+ } -+ -+ start_offset = ftell(fcursor->fp); -+ if (start_offset == -1) { -+ ret = interpret_errno(context, errno); -+ goto cleanup; -+ } -+ start_offset -= expected.len; -+ -+ /* Read the bytes at the entry to be overwritten. */ -+ if (lseek(fd, start_offset, SEEK_SET) == -1) { -+ ret = interpret_errno(context, errno); -+ goto cleanup; -+ } -+ on_disk = k5alloc(expected.len, &ret); -+ if (ret != 0) -+ goto cleanup; -+ rwret = read(fd, on_disk, expected.len); -+ if (rwret < 0) { -+ ret = interpret_errno(context, errno); -+ goto cleanup; -+ } else if ((size_t)rwret != expected.len) { -+ ret = KRB5_CC_FORMAT; -+ goto cleanup; -+ } -+ -+ /* -+ * If the bytes have changed, either someone else removed the same cred or -+ * the cache was reinitialized. Either way the cred is no longer present, -+ * so return successfully. -+ */ -+ if (memcmp(on_disk, expected.data, expected.len) != 0) -+ goto cleanup; -+ -+ /* Write out the altered entry. */ -+ if (lseek(fd, start_offset, SEEK_SET) == -1) { -+ ret = interpret_errno(context, errno); -+ goto cleanup; -+ } -+ rwret = write(fd, overwrite.data, overwrite.len); -+ if (rwret < 0) { -+ ret = interpret_errno(context, errno); -+ goto cleanup; -+ } -+ -+cleanup: -+ close(fd); -+ zapfree(on_disk, expected.len); -+ k5_buf_free(&expected); -+ k5_buf_free(&overwrite); -+ return ret; -+} -+ -+/* Remove the given creds from the ccache file. */ - static krb5_error_code KRB5_CALLCONV - fcc_remove_cred(krb5_context context, krb5_ccache cache, krb5_flags flags, - krb5_creds *creds) - { -- return KRB5_CC_NOSUPP; -+ krb5_error_code ret; -+ krb5_cc_cursor cursor; -+ krb5_creds cur; -+ -+ ret = krb5_cc_start_seq_get(context, cache, &cursor); -+ if (ret) -+ return ret; -+ -+ for (;;) { -+ ret = krb5_cc_next_cred(context, cache, &cursor, &cur); -+ if (ret) -+ break; -+ -+ if (krb5int_cc_creds_match_request(context, flags, creds, &cur)) -+ ret = delete_cred(context, cache, &cursor, &cur); -+ krb5_free_cred_contents(context, &cur); -+ if (ret) -+ break; -+ } -+ -+ krb5_cc_end_seq_get(context, cache, &cursor); -+ return (ret == KRB5_CC_END) ? 0 : ret; - } - - static krb5_error_code KRB5_CALLCONV -diff --git a/src/lib/krb5/ccache/cc_keyring.c b/src/lib/krb5/ccache/cc_keyring.c -index 8419f6ebf..98723fe2e 100644 ---- a/src/lib/krb5/ccache/cc_keyring.c -+++ b/src/lib/krb5/ccache/cc_keyring.c -@@ -1032,40 +1032,44 @@ krcc_next_cred(krb5_context context, krb5_ccache id, krb5_cc_cursor *cursor, - - memset(creds, 0, sizeof(krb5_creds)); - -- /* The cursor has the entire list of keys. (Note that we don't support -- * remove_cred.) */ -+ /* The cursor has the entire list of keys. */ - krcursor = *cursor; - if (krcursor == NULL) - return KRB5_CC_END; - -- /* If we're pointing past the end of the keys array, there are no more. */ -- if (krcursor->currkey >= krcursor->numkeys) -- return KRB5_CC_END; -+ while (krcursor->currkey < krcursor->numkeys) { -+ /* If we're pointing at the entry with the principal, or at the key -+ * with the time offsets, skip it. */ -+ if (krcursor->keys[krcursor->currkey] == krcursor->princ_id || -+ krcursor->keys[krcursor->currkey] == krcursor->offsets_id) { -+ krcursor->currkey++; -+ continue; -+ } - -- /* If we're pointing at the entry with the principal, or at the key -- * with the time offsets, skip it. */ -- while (krcursor->keys[krcursor->currkey] == krcursor->princ_id || -- krcursor->keys[krcursor->currkey] == krcursor->offsets_id) { -+ /* Read the key; the right size buffer will be allocated and -+ * returned. */ -+ psize = keyctl_read_alloc(krcursor->keys[krcursor->currkey], -+ &payload); -+ if (psize != -1) { -+ krcursor->currkey++; -+ -+ /* Unmarshal the cred using the file ccache version 4 format. */ -+ ret = k5_unmarshal_cred(payload, psize, 4, creds); -+ free(payload); -+ return ret; -+ } else if (errno != ENOKEY && errno != EACCES) { -+ DEBUG_PRINT(("Error reading key %d: %s\n", -+ krcursor->keys[krcursor->currkey], strerror(errno))); -+ return KRB5_FCC_NOFILE; -+ } -+ -+ /* The current key was unlinked, probably by a remove_cred call; move -+ * on to the next one. */ - krcursor->currkey++; -- /* Check if we have now reached the end */ -- if (krcursor->currkey >= krcursor->numkeys) -- return KRB5_CC_END; - } - -- /* Read the key; the right size buffer will be allocated and returned. */ -- psize = keyctl_read_alloc(krcursor->keys[krcursor->currkey], &payload); -- if (psize == -1) { -- DEBUG_PRINT(("Error reading key %d: %s\n", -- krcursor->keys[krcursor->currkey], -- strerror(errno))); -- return KRB5_FCC_NOFILE; -- } -- krcursor->currkey++; -- -- /* Unmarshal the credential using the file ccache version 4 format. */ -- ret = k5_unmarshal_cred(payload, psize, 4, creds); -- free(payload); -- return ret; -+ /* No more keys in keyring. */ -+ return KRB5_CC_END; - } - - /* Release an iteration cursor. */ -@@ -1248,12 +1252,41 @@ krcc_retrieve(krb5_context context, krb5_ccache id, - creds); - } - --/* Non-functional stub for removing a cred from the cache keyring. */ -+/* Remove a credential from the cache keyring. */ - static krb5_error_code KRB5_CALLCONV - krcc_remove_cred(krb5_context context, krb5_ccache cache, - krb5_flags flags, krb5_creds *creds) - { -- return KRB5_CC_NOSUPP; -+ krb5_error_code ret; -+ krcc_data *data = cache->data; -+ krb5_cc_cursor cursor; -+ krb5_creds c; -+ krcc_cursor krcursor; -+ key_serial_t key; -+ krb5_boolean match; -+ -+ ret = krcc_start_seq_get(context, cache, &cursor); -+ if (ret) -+ return ret; -+ -+ for (;;) { -+ ret = krcc_next_cred(context, cache, &cursor, &c); -+ if (ret) -+ break; -+ match = krb5int_cc_creds_match_request(context, flags, creds, &c); -+ krb5_free_cred_contents(context, &c); -+ if (match) { -+ krcursor = cursor; -+ key = krcursor->keys[krcursor->currkey - 1]; -+ if (keyctl_unlink(key, data->cache_id) == -1) { -+ ret = errno; -+ break; -+ } -+ } -+ } -+ -+ krcc_end_seq_get(context, cache, &cursor); -+ return (ret == KRB5_CC_END) ? 0 : ret; - } - - /* Set flags on the cache. (We don't care about any flags.) */ -diff --git a/src/lib/krb5/ccache/cc_memory.c b/src/lib/krb5/ccache/cc_memory.c -index 114ef6913..edf6fcc26 100644 ---- a/src/lib/krb5/ccache/cc_memory.c -+++ b/src/lib/krb5/ccache/cc_memory.c -@@ -405,14 +405,23 @@ krb5_mcc_next_cred(krb5_context context, krb5_ccache id, - */ - k5_cc_mutex_lock(context, &d->lock); - if (mcursor->generation != d->generation) { -- k5_cc_mutex_unlock(context, &d->lock); -- return KRB5_CC_END; -+ retval = KRB5_CC_END; -+ goto done; -+ } -+ -+ /* Skip over removed creds. */ -+ while (mcursor->next_link != NULL && mcursor->next_link->creds == NULL) -+ mcursor->next_link = mcursor->next_link->next; -+ if (mcursor->next_link == NULL) { -+ retval = KRB5_CC_END; -+ goto done; - } - - retval = k5_copy_creds_contents(context, mcursor->next_link->creds, creds); - if (retval == 0) - mcursor->next_link = mcursor->next_link->next; - -+done: - k5_cc_mutex_unlock(context, &d->lock); - return retval; - } -@@ -592,16 +601,31 @@ krb5_mcc_retrieve(krb5_context context, krb5_ccache id, krb5_flags whichfields, - } - - /* -- * Non-functional stub implementation for krb5_mcc_remove -+ * Modifies: -+ * the memory cache - * -- * Errors: -- * KRB5_CC_NOSUPP - not implemented -+ * Effects: -+ * Remove the given creds from the ccache. - */ - static krb5_error_code KRB5_CALLCONV - krb5_mcc_remove_cred(krb5_context context, krb5_ccache cache, krb5_flags flags, - krb5_creds *creds) - { -- return KRB5_CC_NOSUPP; -+ krb5_mcc_data *data = (krb5_mcc_data *)cache->data; -+ krb5_mcc_link *l; -+ -+ k5_cc_mutex_lock(context, &data->lock); -+ -+ for (l = data->link; l != NULL; l = l->next) { -+ if (l->creds != NULL && -+ krb5int_cc_creds_match_request(context, flags, creds, l->creds)) { -+ krb5_free_creds(context, l->creds); -+ l->creds = NULL; -+ } -+ } -+ -+ k5_cc_mutex_unlock(context, &data->lock); -+ return 0; - } - - -diff --git a/src/lib/krb5/ccache/t_cc.c b/src/lib/krb5/ccache/t_cc.c -index cd4569c4c..954f2f465 100644 ---- a/src/lib/krb5/ccache/t_cc.c -+++ b/src/lib/krb5/ccache/t_cc.c -@@ -36,7 +36,7 @@ - - #define KRB5_OK 0 - --krb5_creds test_creds; -+krb5_creds test_creds, test_creds2; - - int debug=0; - -@@ -144,6 +144,10 @@ init_test_cred(krb5_context context) - a->length = 2; - test_creds.authdata[1] = a; - -+ memcpy(&test_creds2, &test_creds, sizeof(test_creds)); -+ kret = krb5_build_principal(context, &test_creds2.server, sizeof(REALM), -+ REALM, "server-comp1", "server-comp3", NULL); -+ - cleanup: - if(kret) { - if (test_creds.client) { -@@ -170,6 +174,7 @@ free_test_cred(krb5_context context) - krb5_free_principal(context, test_creds.client); - - krb5_free_principal(context, test_creds.server); -+ krb5_free_principal(context, test_creds2.server); - - if(test_creds.authdata) { - krb5_free_authdata(context, test_creds.authdata); -@@ -199,6 +204,44 @@ free_test_cred(krb5_context context) - #define CHECK_FAIL(experr, kret, msg) \ - if (experr != kret) { CHECK(kret, msg);} - -+static void -+check_num_entries(krb5_context context, krb5_ccache cache, int expected, -+ unsigned linenum) -+{ -+ krb5_error_code ret; -+ krb5_cc_cursor cursor; -+ krb5_creds creds; -+ int count = 0; -+ -+ ret = krb5_cc_start_seq_get(context, cache, &cursor); -+ if (ret != 0) { -+ com_err("", ret, "(on line %d) - krb5_cc_start_seq_get", linenum); -+ fflush(stderr); -+ exit(1); -+ } -+ -+ while (1) { -+ ret = krb5_cc_next_cred(context, cache, &cursor, &creds); -+ if (ret) -+ break; -+ -+ count++; -+ krb5_free_cred_contents(context, &creds); -+ } -+ krb5_cc_end_seq_get(context, cache, &cursor); -+ if (ret != KRB5_CC_END) { -+ CHECK(ret, "counting entries in ccache"); -+ } -+ -+ if (count != expected) { -+ com_err("", KRB5_FCC_INTERNAL, -+ "(on line %d) - count didn't match (expected %d, got %d)", -+ linenum, expected, count); -+ fflush(stderr); -+ exit(1); -+ } -+} -+ - static void - cc_test(krb5_context context, const char *name, krb5_flags flags) - { -@@ -207,6 +250,7 @@ cc_test(krb5_context context, const char *name, krb5_flags flags) - krb5_error_code kret; - krb5_cc_cursor cursor; - krb5_principal tmp; -+ krb5_flags matchflags = KRB5_TC_MATCH_IS_SKEY; - - const char *c_name; - char newcache[300]; -@@ -311,9 +355,90 @@ cc_test(krb5_context context, const char *name, krb5_flags flags) - kret = krb5_cc_destroy(context, id2); - CHECK(kret, "destroy id2"); - -+ /* ----------------------------------------------------- */ -+ /* Test credential removal */ -+ kret = krb5_cc_resolve(context, name, &id); -+ CHECK(kret, "resolving for remove"); -+ -+ kret = krb5_cc_initialize(context, id, test_creds.client); -+ CHECK(kret, "initialize for remove"); -+ check_num_entries(context, id, 0, __LINE__); -+ -+ kret = krb5_cc_store_cred(context, id, &test_creds); -+ CHECK(kret, "store for remove (first pass)"); -+ check_num_entries(context, id, 1, __LINE__); /* 1 */ -+ -+ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds); -+ CHECK(kret, "removing credential (first pass)"); -+ check_num_entries(context, id, 0, __LINE__); /* empty */ -+ -+ kret = krb5_cc_store_cred(context, id, &test_creds); -+ CHECK(kret, "first store for remove (second pass)"); -+ check_num_entries(context, id, 1, __LINE__); /* 1 */ -+ -+ kret = krb5_cc_store_cred(context, id, &test_creds2); -+ CHECK(kret, "second store for remove (second pass)"); -+ check_num_entries(context, id, 2, __LINE__); /* 1, 2 */ -+ -+ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds2); -+ CHECK(kret, "first remove (second pass)"); -+ check_num_entries(context, id, 1, __LINE__); /* 1 */ -+ -+ kret = krb5_cc_store_cred(context, id, &test_creds2); -+ CHECK(kret, "third store for remove (second pass)"); -+ check_num_entries(context, id, 2, __LINE__); /* 1, 2 */ -+ -+ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds); -+ CHECK(kret, "second remove (second pass)"); -+ check_num_entries(context, id, 1, __LINE__); /* 2 */ -+ -+ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds2); -+ CHECK(kret, "third remove (second pass)"); -+ check_num_entries(context, id, 0, __LINE__); /* empty */ -+ -+ kret = krb5_cc_destroy(context, id); -+ CHECK(kret, "destruction for remove"); -+ -+ /* Test removal with iteration. */ -+ kret = krb5_cc_resolve(context, name, &id); -+ CHECK(kret, "resolving for remove-iter"); -+ -+ kret = krb5_cc_initialize(context, id, test_creds.client); -+ CHECK(kret, "initialize for remove-iter"); -+ -+ kret = krb5_cc_store_cred(context, id, &test_creds); -+ CHECK(kret, "first store for remove-iter"); -+ -+ kret = krb5_cc_store_cred(context, id, &test_creds2); -+ CHECK(kret, "second store for remove-iter"); -+ -+ kret = krb5_cc_start_seq_get(context, id, &cursor); -+ CHECK(kret, "start_seq_get for remove-iter"); -+ -+ kret = krb5_cc_remove_cred(context, id, matchflags, &test_creds); -+ CHECK(kret, "remove for remove-iter"); -+ -+ while (1) { -+ /* The removed credential may or may not be present in the cache - -+ * either behavior is technically correct. */ -+ kret = krb5_cc_next_cred(context, id, &cursor, &creds); -+ if (kret == KRB5_CC_END) -+ break; -+ CHECK(kret, "next_cred for remove-iter: %s"); -+ -+ CHECK(creds.times.endtime == 0, "no-lifetime cred"); -+ -+ krb5_free_cred_contents(context, &creds); -+ } -+ -+ kret = krb5_cc_end_seq_get(context, id, &cursor); -+ CHECK(kret, "end_seq_get for remove-iter"); -+ -+ kret = krb5_cc_destroy(context, id); -+ CHECK(kret, "destruction for remove-iter"); -+ - free(save_type); - free_test_cred(context); -- - } - - /* diff --git a/Improve-error-messages-from-kadmin-change_password.patch b/Improve-error-messages-from-kadmin-change_password.patch deleted file mode 100644 index aff1567..0000000 --- a/Improve-error-messages-from-kadmin-change_password.patch +++ /dev/null @@ -1,55 +0,0 @@ -From 69a09fc7c76f443f08c437043d689669d39f46ca Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 6 May 2019 13:13:16 -0400 -Subject: [PATCH] Improve error messages from kadmin change_password - -The checks for missing option arguments were dead code, because the -loop condition requires at least two remaining arguments. Instead -check for at least one argument with a leading "-", and check for too -many or too few arguments after the loop. Add an initial message for -unrecognized options. - -[ghudson@mit.edu: adjusted logic to improve mesages in more cases] - -(cherry picked from commit 13ba54002d362ebb09be464b4e7ec75050d1348f) ---- - src/kadmin/cli/kadmin.c | 12 ++++++++---- - 1 file changed, 8 insertions(+), 4 deletions(-) - -diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c -index cc74921bf..fe4cb493c 100644 ---- a/src/kadmin/cli/kadmin.c -+++ b/src/kadmin/cli/kadmin.c -@@ -797,11 +797,11 @@ kadmin_cpw(int argc, char *argv[]) - char **db_args = NULL; - int db_args_size = 0; - -- if (argc < 2) { -+ if (argc < 1) { - cpw_usage(NULL); - return; - } -- for (argv++, argc--; argc > 1; argc--, argv++) { -+ for (argv++, argc--; argc > 0 && **argv == '-'; argc--, argv++) { - if (!strcmp("-x", *argv)) { - argc--; - if (argc < 1) { -@@ -841,12 +841,16 @@ kadmin_cpw(int argc, char *argv[]) - goto cleanup; - } - } else { -+ com_err("change_password", 0, _("unrecognized option %s"), *argv); - cpw_usage(NULL); - goto cleanup; - } - } -- if (*argv == NULL) { -- com_err("change_password", 0, _("missing principal name")); -+ if (argc != 1) { -+ if (argc < 1) -+ com_err("change_password", 0, _("missing principal name")); -+ else -+ com_err("change_password", 0, _("too many arguments")); - cpw_usage(NULL); - goto cleanup; - } diff --git a/In-kpropd-debug-log-proper-ticket-enctype-names.patch b/In-kpropd-debug-log-proper-ticket-enctype-names.patch deleted file mode 100644 index dec823a..0000000 --- a/In-kpropd-debug-log-proper-ticket-enctype-names.patch +++ /dev/null @@ -1,28 +0,0 @@ -From bcd727fc66e9213e7b6ea4d22f781812033789ba Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 15 Jan 2019 13:41:16 -0500 -Subject: [PATCH] In kpropd, debug-log proper ticket enctype names - -This change replaces the last call of krb5_enctype_to_string() in our -sources with krb5_enctype_to_name(), ensuring that we log consistently -to users using readily discoverable strings. - -(cherry picked from commit 30e12a2ecdf7e2a034a91626a03b5c9909e4c68d) ---- - src/kprop/kpropd.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c -index 4cc035dc6..0c7bffa24 100644 ---- a/src/kprop/kpropd.c -+++ b/src/kprop/kpropd.c -@@ -1279,7 +1279,8 @@ kerberos_authenticate(krb5_context context, int fd, krb5_principal *clientp, - exit(1); - } - -- retval = krb5_enctype_to_string(*etype, etypebuf, sizeof(etypebuf)); -+ retval = krb5_enctype_to_name(*etype, FALSE, etypebuf, -+ sizeof(etypebuf)); - if (retval) { - com_err(progname, retval, _("while unparsing ticket etype")); - exit(1); diff --git a/In-rd_req_dec-always-log-non-permitted-enctypes.patch b/In-rd_req_dec-always-log-non-permitted-enctypes.patch deleted file mode 100644 index 148deb0..0000000 --- a/In-rd_req_dec-always-log-non-permitted-enctypes.patch +++ /dev/null @@ -1,54 +0,0 @@ -From 7710ba9b6d48ae82a2b2559131c6a8da802a4c0d Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 14 Jan 2019 17:14:42 -0500 -Subject: [PATCH] In rd_req_dec, always log non-permitted enctypes - -The buffer specified in negotiate_etype() is too small for use with -the AES enctypes when used with krb5_enctype_to_string(), so switch to -using krb5_enctype_to_name(). - -(cherry picked from commit bf75ebf583a51bf00005a96d17924818d19377be) ---- - src/lib/krb5/krb/rd_req_dec.c | 5 ++--- - src/tests/gssapi/t_enctypes.py | 5 +++-- - 2 files changed, 5 insertions(+), 5 deletions(-) - -diff --git a/src/lib/krb5/krb/rd_req_dec.c b/src/lib/krb5/krb/rd_req_dec.c -index 4cd429a11..e75192fee 100644 ---- a/src/lib/krb5/krb/rd_req_dec.c -+++ b/src/lib/krb5/krb/rd_req_dec.c -@@ -864,9 +864,8 @@ negotiate_etype(krb5_context context, - if (permitted == FALSE) { - char enctype_name[30]; - -- if (krb5_enctype_to_string(desired_etypes[i], -- enctype_name, -- sizeof(enctype_name)) == 0) -+ if (krb5_enctype_to_name(desired_etypes[i], FALSE, enctype_name, -+ sizeof(enctype_name)) == 0) - k5_setmsg(context, KRB5_NOPERM_ETYPE, - _("Encryption type %s not permitted"), enctype_name); - return KRB5_NOPERM_ETYPE; -diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py -index ee43ff028..5d9f80e04 100755 ---- a/src/tests/gssapi/t_enctypes.py -+++ b/src/tests/gssapi/t_enctypes.py -@@ -85,7 +85,8 @@ test('both aes128', 'aes128-cts', 'aes128-cts', - # If only the acceptor constrains the permitted session enctypes to - # aes128, subkey negotiation fails because the acceptor considers the - # aes256 session key to be non-permitted. --test_err('acc aes128', None, 'aes128-cts', 'Encryption type not permitted') -+test_err('acc aes128', None, 'aes128-cts', -+ 'Encryption type aes256-cts-hmac-sha1-96 not permitted') - - # If the initiator constrains the permitted session enctypes to des3, - # no acceptor subkey will be generated because we can't upgrade to a -@@ -128,7 +129,7 @@ test('upgrade init des3+rc4', 'des3 rc4', None, - # is only for the sake of the kernel, since we could upgrade to an - # aes128 subkey, but it's the current semantics.) - test_err('upgrade acc aes128', None, 'aes128-cts', -- 'Encryption type ArcFour with HMAC/md5 not permitted') -+ 'Encryption type arcfour-hmac not permitted') - - # If the acceptor permits rc4 but prefers aes128, it will negotiate an - # upgrade to aes128. diff --git a/Initialize-some-data-structure-magic-fields.patch b/Initialize-some-data-structure-magic-fields.patch deleted file mode 100644 index e392f10..0000000 --- a/Initialize-some-data-structure-magic-fields.patch +++ /dev/null @@ -1,55 +0,0 @@ -From 3f8434553e5bc3551c7be651de196caf98647cf3 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 2 May 2019 13:36:38 -0400 -Subject: [PATCH] Initialize some data structure magic fields - -Static analyzers may complain if they see a data structure copied with -an uninitialized field, even if the copy target won't use the field. -Add magic field initializers in three such places. - -[ghudson@mit.edu: rewrote commit message] - -(cherry picked from commit 551e88e76e537e45f6c80eadaefeb790994f83f9) ---- - src/lib/gssapi/krb5/util_cksum.c | 1 + - src/lib/krb5/krb/authdata.c | 8 ++------ - 2 files changed, 3 insertions(+), 6 deletions(-) - -diff --git a/src/lib/gssapi/krb5/util_cksum.c b/src/lib/gssapi/krb5/util_cksum.c -index cfd585ec7..a1770774e 100644 ---- a/src/lib/gssapi/krb5/util_cksum.c -+++ b/src/lib/gssapi/krb5/util_cksum.c -@@ -48,6 +48,7 @@ kg_checksum_channel_bindings(context, cb, cksum) - - cksum->checksum_type = CKSUMTYPE_RSA_MD5; - cksum->length = sumlen; -+ cksum->magic = KV5M_CHECKSUM; - - /* generate a buffer full of zeros if no cb specified */ - -diff --git a/src/lib/krb5/krb/authdata.c b/src/lib/krb5/krb/authdata.c -index 7fbcfab68..3e7dfbe49 100644 ---- a/src/lib/krb5/krb/authdata.c -+++ b/src/lib/krb5/krb/authdata.c -@@ -976,9 +976,7 @@ krb5_authdata_export_internal(krb5_context kcontext, - - *ptr = NULL; - -- name.length = strlen(module_name); -- name.data = (char *)module_name; -- -+ name = make_data((char *)module_name, strlen(module_name)); - module = k5_ad_find_module(kcontext, context, AD_USAGE_MASK, &name); - if (module == NULL) - return ENOENT; -@@ -1005,9 +1003,7 @@ krb5_authdata_free_internal(krb5_context kcontext, - krb5_data name; - struct _krb5_authdata_context_module *module; - -- name.length = strlen(module_name); -- name.data = (char *)module_name; -- -+ name = make_data((char *)module_name, strlen(module_name)); - module = k5_ad_find_module(kcontext, context, AD_USAGE_MASK, &name); - if (module == NULL) - return ENOENT; diff --git a/Log-unknown-enctypes-as-unsupported-in-KDC.patch b/Log-unknown-enctypes-as-unsupported-in-KDC.patch deleted file mode 100644 index e742826..0000000 --- a/Log-unknown-enctypes-as-unsupported-in-KDC.patch +++ /dev/null @@ -1,52 +0,0 @@ -From f4681ed7ec9f22fdbacc5c58a9f12ef567601267 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 27 Sep 2019 16:55:37 -0400 -Subject: [PATCH] Log unknown enctypes as unsupported in KDC - -Commit 8d8e68283b599e680f9fe45eff8af397e827bd6c logs both invalid and -deprecated enctypes as "DEPRECATED:". An invalid enctype might be too -old or marginal to be supported (like single-DES) or too new to be -recognized. For clarity, prefix invalid enctypes with "UNSUPPORTED:" -instead. - -ticket: 8773 -(cherry picked from commit 5ee99b0007f480f01f86340d1c30da51cc80da96) ---- - src/kdc/kdc_util.c | 18 ++++++++++-------- - 1 file changed, 10 insertions(+), 8 deletions(-) - -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index 698f18c1c..8700ec02c 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -1048,20 +1048,22 @@ void limit_string(char *name) - static krb5_error_code - enctype_name(krb5_enctype ktype, char *buf, size_t buflen) - { -- char *name; -+ const char *name, *prefix = ""; - size_t len; - - if (buflen == 0) - return EINVAL; - *buf = '\0'; /* ensure these are always valid C-strings */ - -- if (krb5int_c_deprecated_enctype(ktype)) { -- len = strlcpy(buf, "DEPRECATED:", buflen); -- if (len >= buflen) -- return ENOMEM; -- buflen -= len; -- buf += len; -- } -+ if (!krb5_c_valid_enctype(ktype)) -+ prefix = "UNSUPPORTED:"; -+ else if (krb5int_c_deprecated_enctype(ktype)) -+ prefix = "DEPRECATED:"; -+ len = strlcpy(buf, prefix, buflen); -+ if (len >= buflen) -+ return ENOMEM; -+ buflen -= len; -+ buf += len; - - /* rfc4556 recommends that clients wishing to indicate support for these - * pkinit algorithms include them in the etype field of the AS-REQ. */ diff --git a/Make-etype-names-in-KDC-logs-human-readable.patch b/Make-etype-names-in-KDC-logs-human-readable.patch deleted file mode 100644 index 451e554..0000000 --- a/Make-etype-names-in-KDC-logs-human-readable.patch +++ /dev/null @@ -1,296 +0,0 @@ -From 87e5a350db1c18a92427a2a7645cc53d5813672d Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 8 Jan 2019 17:42:35 -0500 -Subject: [PATCH] Make etype names in KDC logs human-readable - -Introduce enctype_name() as a wrapper over krb5_enctype_to_name for -converting between registered constants and names. Adjust signatures -and rewrite ktypes2str() and rep_etypes2str() to operate on dynamic -buffers. - -ticket: 8772 (new) -(cherry picked from commit a649279727490687d54becad91fde8cf7429d951) ---- - src/kdc/kdc_log.c | 42 +++++++-------- - src/kdc/kdc_util.c | 131 +++++++++++++++++++++++---------------------- - src/kdc/kdc_util.h | 6 +-- - 3 files changed, 90 insertions(+), 89 deletions(-) - -diff --git a/src/kdc/kdc_log.c b/src/kdc/kdc_log.c -index 4eec50373..b160ba21a 100644 ---- a/src/kdc/kdc_log.c -+++ b/src/kdc/kdc_log.c -@@ -65,7 +65,7 @@ log_as_req(krb5_context context, - { - const char *fromstring = 0; - char fromstringbuf[70]; -- char ktypestr[128]; -+ char *ktypestr = NULL; - const char *cname2 = cname ? cname : ""; - const char *sname2 = sname ? sname : ""; - -@@ -74,26 +74,29 @@ log_as_req(krb5_context context, - fromstringbuf, sizeof(fromstringbuf)); - if (!fromstring) - fromstring = ""; -- ktypes2str(ktypestr, sizeof(ktypestr), -- request->nktypes, request->ktype); -+ -+ ktypestr = ktypes2str(request->ktype, request->nktypes); - - if (status == NULL) { - /* success */ -- char rep_etypestr[128]; -- rep_etypes2str(rep_etypestr, sizeof(rep_etypestr), reply); -+ char *rep_etypestr = rep_etypes2str(reply); - krb5_klog_syslog(LOG_INFO, _("AS_REQ (%s) %s: ISSUE: authtime %u, %s, " - "%s for %s"), -- ktypestr, fromstring, (unsigned int)authtime, -- rep_etypestr, cname2, sname2); -+ ktypestr ? ktypestr : "", fromstring, -+ (unsigned int)authtime, -+ rep_etypestr ? rep_etypestr : "", cname2, sname2); -+ free(rep_etypestr); - } else { - /* fail */ - krb5_klog_syslog(LOG_INFO, _("AS_REQ (%s) %s: %s: %s for %s%s%s"), -- ktypestr, fromstring, status, -- cname2, sname2, emsg ? ", " : "", emsg ? emsg : ""); -+ ktypestr ? ktypestr : "", fromstring, status, cname2, -+ sname2, emsg ? ", " : "", emsg ? emsg : ""); - } - krb5_db_audit_as_req(context, request, - local_addr->address, remote_addr->address, - client, server, authtime, errcode); -+ -+ free(ktypestr); - } - - /* -@@ -122,10 +125,9 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from, - unsigned int c_flags, - const char *status, krb5_error_code errcode, const char *emsg) - { -- char ktypestr[128]; -+ char *ktypestr = NULL, *rep_etypestr = NULL; - const char *fromstring = 0; - char fromstringbuf[70]; -- char rep_etypestr[128]; - char *cname = NULL, *sname = NULL, *altcname = NULL; - char *logcname = NULL, *logsname = NULL, *logaltcname = NULL; - -@@ -134,11 +136,6 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from, - fromstringbuf, sizeof(fromstringbuf)); - if (!fromstring) - fromstring = ""; -- ktypes2str(ktypestr, sizeof(ktypestr), request->nktypes, request->ktype); -- if (!errcode) -- rep_etypes2str(rep_etypestr, sizeof(rep_etypestr), reply); -- else -- rep_etypestr[0] = 0; - - unparse_and_limit(ctx, cprinc, &cname); - logcname = (cname != NULL) ? cname : ""; -@@ -151,10 +148,14 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from, - name (useful), and doesn't log ktypestr (probably not - important). */ - if (errcode != KRB5KDC_ERR_SERVER_NOMATCH) { -+ ktypestr = ktypes2str(request->ktype, request->nktypes); -+ rep_etypestr = rep_etypes2str(reply); - krb5_klog_syslog(LOG_INFO, _("TGS_REQ (%s) %s: %s: authtime %u, %s%s " - "%s for %s%s%s"), -- ktypestr, fromstring, status, (unsigned int)authtime, -- rep_etypestr, !errcode ? "," : "", logcname, logsname, -+ ktypestr ? ktypestr : "", fromstring, status, -+ (unsigned int)authtime, -+ rep_etypestr ? rep_etypestr : "", -+ !errcode ? "," : "", logcname, logsname, - errcode ? ", " : "", errcode ? emsg : ""); - if (isflagset(c_flags, KRB5_KDB_FLAG_PROTOCOL_TRANSITION)) - krb5_klog_syslog(LOG_INFO, -@@ -171,9 +172,8 @@ log_tgs_req(krb5_context ctx, const krb5_fulladdr *from, - fromstring, status, (unsigned int)authtime, - logcname, logsname, logaltcname); - -- /* OpenSolaris: audit_krb5kdc_tgs_req(...) or -- audit_krb5kdc_tgs_req_2ndtktmm(...) */ -- -+ free(rep_etypestr); -+ free(ktypestr); - krb5_free_unparsed_name(ctx, cname); - krb5_free_unparsed_name(ctx, sname); - krb5_free_unparsed_name(ctx, altcname); -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index 0155c28c6..f5c581c82 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -1043,84 +1043,87 @@ void limit_string(char *name) - return; - } - --/* -- * L10_2 = log10(2**x), rounded up; log10(2) ~= 0.301. -- */ --#define L10_2(x) ((int)(((x * 301) + 999) / 1000)) -- --/* -- * Max length of sprintf("%ld") for an int of type T; includes leading -- * minus sign and terminating NUL. -- */ --#define D_LEN(t) (L10_2(sizeof(t) * CHAR_BIT) + 2) -- --void --ktypes2str(char *s, size_t len, int nktypes, krb5_enctype *ktype) -+/* Wrapper of krb5_enctype_to_name() to include the PKINIT types. */ -+static krb5_error_code -+enctype_name(krb5_enctype ktype, char *buf, size_t buflen) - { -- int i; -- char stmp[D_LEN(krb5_enctype) + 1]; -- char *p; -+ char *name; - -- if (nktypes < 0 -- || len < (sizeof(" etypes {...}") + D_LEN(int))) { -- *s = '\0'; -- return; -- } -+ if (buflen == 0) -+ return EINVAL; -+ *buf = '\0'; /* ensure these are always valid C-strings */ - -- snprintf(s, len, "%d etypes {", nktypes); -- for (i = 0; i < nktypes; i++) { -- snprintf(stmp, sizeof(stmp), "%s%ld", i ? " " : "", (long)ktype[i]); -- if (strlen(s) + strlen(stmp) + sizeof("}") > len) -- break; -- strlcat(s, stmp, len); -- } -- if (i < nktypes) { -- /* -- * We broke out of the loop. Try to truncate the list. -- */ -- p = s + strlen(s); -- while (p - s + sizeof("...}") > len) { -- while (p > s && *p != ' ' && *p != '{') -- *p-- = '\0'; -- if (p > s && *p == ' ') { -- *p-- = '\0'; -- continue; -- } -- } -- strlcat(s, "...", len); -- } -- strlcat(s, "}", len); -- return; -+ /* rfc4556 recommends that clients wishing to indicate support for these -+ * pkinit algorithms include them in the etype field of the AS-REQ. */ -+ if (ktype == ENCTYPE_DSA_SHA1_CMS) -+ name = "id-dsa-with-sha1-CmsOID"; -+ else if (ktype == ENCTYPE_MD5_RSA_CMS) -+ name = "md5WithRSAEncryption-CmsOID"; -+ else if (ktype == ENCTYPE_SHA1_RSA_CMS) -+ name = "sha-1WithRSAEncryption-CmsOID"; -+ else if (ktype == ENCTYPE_RC2_CBC_ENV) -+ name = "rc2-cbc-EnvOID"; -+ else if (ktype == ENCTYPE_RSA_ENV) -+ name = "rsaEncryption-EnvOID"; -+ else if (ktype == ENCTYPE_RSA_ES_OAEP_ENV) -+ name = "id-RSAES-OAEP-EnvOID"; -+ else if (ktype == ENCTYPE_DES3_CBC_ENV) -+ name = "des-ede3-cbc-EnvOID"; -+ else -+ return krb5_enctype_to_name(ktype, FALSE, buf, buflen); -+ -+ if (strlcpy(name, buf, buflen) >= buflen) -+ return ENOMEM; -+ return 0; - } - --void --rep_etypes2str(char *s, size_t len, krb5_kdc_rep *rep) -+char * -+ktypes2str(krb5_enctype *ktype, int nktypes) - { -- char stmp[sizeof("ses=") + D_LEN(krb5_enctype)]; -+ struct k5buf buf; -+ int i; -+ char name[64]; - -- if (len < (3 * D_LEN(krb5_enctype) -- + sizeof("etypes {rep= tkt= ses=}"))) { -- *s = '\0'; -- return; -+ if (nktypes < 0) -+ return NULL; -+ -+ k5_buf_init_dynamic(&buf); -+ k5_buf_add_fmt(&buf, "%d etypes {", nktypes); -+ for (i = 0; i < nktypes; i++) { -+ enctype_name(ktype[i], name, sizeof(name)); -+ k5_buf_add_fmt(&buf, "%s%s(%ld)", i ? ", " : "", name, (long)ktype[i]); - } -+ k5_buf_add(&buf, "}"); -+ return buf.data; -+} - -- snprintf(s, len, "etypes {rep=%ld", (long)rep->enc_part.enctype); -+char * -+rep_etypes2str(krb5_kdc_rep *rep) -+{ -+ struct k5buf buf; -+ char name[64]; -+ krb5_enctype etype; -+ -+ k5_buf_init_dynamic(&buf); -+ k5_buf_add(&buf, "etypes {rep="); -+ enctype_name(rep->enc_part.enctype, name, sizeof(name)); -+ k5_buf_add_fmt(&buf, "%s(%ld)", name, (long)rep->enc_part.enctype); - - if (rep->ticket != NULL) { -- snprintf(stmp, sizeof(stmp), -- " tkt=%ld", (long)rep->ticket->enc_part.enctype); -- strlcat(s, stmp, len); -+ etype = rep->ticket->enc_part.enctype; -+ enctype_name(etype, name, sizeof(name)); -+ k5_buf_add_fmt(&buf, ", tkt=%s(%ld)", name, (long)etype); - } - -- if (rep->ticket != NULL -- && rep->ticket->enc_part2 != NULL -- && rep->ticket->enc_part2->session != NULL) { -- snprintf(stmp, sizeof(stmp), " ses=%ld", -- (long)rep->ticket->enc_part2->session->enctype); -- strlcat(s, stmp, len); -+ if (rep->ticket != NULL && rep->ticket->enc_part2 != NULL && -+ rep->ticket->enc_part2->session != NULL) { -+ etype = rep->ticket->enc_part2->session->enctype; -+ enctype_name(etype, name, sizeof(name)); -+ k5_buf_add_fmt(&buf, ", ses=%s(%ld)", name, (long)etype); - } -- strlcat(s, "}", len); -- return; -+ -+ k5_buf_add(&buf, "}"); -+ return buf.data; - } - - static krb5_error_code -diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index 6ec645fc3..25077cbf5 100644 ---- a/src/kdc/kdc_util.h -+++ b/src/kdc/kdc_util.h -@@ -110,11 +110,9 @@ select_session_keytype (kdc_realm_t *kdc_active_realm, - - void limit_string (char *name); - --void --ktypes2str(char *s, size_t len, int nktypes, krb5_enctype *ktype); -+char *ktypes2str(krb5_enctype *ktype, int nktypes); - --void --rep_etypes2str(char *s, size_t len, krb5_kdc_rep *rep); -+char *rep_etypes2str(krb5_kdc_rep *rep); - - /* authind.c */ - krb5_boolean diff --git a/Mark-deprecated-enctypes-when-used.patch b/Mark-deprecated-enctypes-when-used.patch deleted file mode 100644 index 9f520d7..0000000 --- a/Mark-deprecated-enctypes-when-used.patch +++ /dev/null @@ -1,250 +0,0 @@ -From 8e3b86c1e7bdd12c649127a8a44e5a269b5b4453 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 10 Jan 2019 16:34:54 -0500 -Subject: [PATCH] Mark deprecated enctypes when used - -Preface ETYPE_DEPRECATED enctypes with "DEPRECATED:" in klist output, -KDC logs, and kadmin interactions. Also complain in krb5kdc when the -stash file has a deprecated enctype or a deprecated enctype is -requested with -k. - -ticket: 8773 (new) -(cherry picked from commit 8d8e68283b599e680f9fe45eff8af397e827bd6c) ---- - src/clients/klist/klist.c | 14 ++++++++++---- - src/kadmin/cli/kadmin.c | 6 +++++- - src/kdc/kdc_util.c | 9 +++++++++ - src/kdc/main.c | 19 +++++++++++++++++++ - src/tests/gssapi/t_enctypes.py | 15 +++++++++------ - src/tests/t_keyrollover.py | 8 +++++--- - src/tests/t_sesskeynego.py | 4 ++-- - 7 files changed, 59 insertions(+), 16 deletions(-) - -diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c -index 70adb54e8..8c307151a 100644 ---- a/src/clients/klist/klist.c -+++ b/src/clients/klist/klist.c -@@ -571,11 +571,17 @@ static char * - etype_string(krb5_enctype enctype) - { - static char buf[100]; -- krb5_error_code ret; -+ char *bp = buf; -+ size_t deplen, buflen = sizeof(buf); - -- ret = krb5_enctype_to_name(enctype, FALSE, buf, sizeof(buf)); -- if (ret) -- snprintf(buf, sizeof(buf), "etype %d", enctype); -+ if (krb5int_c_deprecated_enctype(enctype)) { -+ deplen = strlcpy(bp, "DEPRECATED:", buflen); -+ buflen -= deplen; -+ bp += deplen; -+ } -+ -+ if (krb5_enctype_to_name(enctype, FALSE, bp, buflen)) -+ snprintf(bp, buflen, "etype %d", enctype); - return buf; - } - -diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c -index ed581ee79..cc74921bf 100644 ---- a/src/kadmin/cli/kadmin.c -+++ b/src/kadmin/cli/kadmin.c -@@ -1451,12 +1451,16 @@ kadmin_getprinc(int argc, char *argv[]) - for (i = 0; i < dprinc.n_key_data; i++) { - krb5_key_data *key_data = &dprinc.key_data[i]; - char enctype[BUFSIZ], salttype[BUFSIZ]; -+ char *deprecated = ""; - - if (krb5_enctype_to_name(key_data->key_data_type[0], FALSE, - enctype, sizeof(enctype))) - snprintf(enctype, sizeof(enctype), _(""), - key_data->key_data_type[0]); -- printf("Key: vno %d, %s", key_data->key_data_kvno, enctype); -+ if (krb5int_c_deprecated_enctype(key_data->key_data_type[0])) -+ deprecated = "DEPRECATED:"; -+ printf("Key: vno %d, %s%s", key_data->key_data_kvno, deprecated, -+ enctype); - if (key_data->key_data_ver > 1 && - key_data->key_data_type[1] != KRB5_KDB_SALTTYPE_NORMAL) { - if (krb5_salttype_to_string(key_data->key_data_type[1], -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index f5c581c82..96c88edc1 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -1048,11 +1048,20 @@ static krb5_error_code - enctype_name(krb5_enctype ktype, char *buf, size_t buflen) - { - char *name; -+ size_t len; - - if (buflen == 0) - return EINVAL; - *buf = '\0'; /* ensure these are always valid C-strings */ - -+ if (krb5int_c_deprecated_enctype(ktype)) { -+ len = strlcpy(buf, "DEPRECATED:", buflen); -+ if (len >= buflen) -+ return ENOMEM; -+ buflen -= len; -+ buf += len; -+ } -+ - /* rfc4556 recommends that clients wishing to indicate support for these - * pkinit algorithms include them in the etype field of the AS-REQ. */ - if (ktype == ENCTYPE_DSA_SHA1_CMS) -diff --git a/src/kdc/main.c b/src/kdc/main.c -index 663fd6303..60092a0df 100644 ---- a/src/kdc/main.c -+++ b/src/kdc/main.c -@@ -210,12 +210,23 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm, - char *svalue = NULL; - const char *hierarchy[4]; - krb5_kvno mkvno = IGNORE_VNO; -+ char ename[32]; - - memset(rdp, 0, sizeof(kdc_realm_t)); - if (!realm) { - kret = EINVAL; - goto whoops; - } -+ -+ if (def_enctype != ENCTYPE_UNKNOWN && -+ krb5int_c_deprecated_enctype(def_enctype)) { -+ if (krb5_enctype_to_name(def_enctype, FALSE, ename, sizeof(ename))) -+ ename[0] = '\0'; -+ fprintf(stderr, -+ _("Requested master password enctype %s in %s is DEPRECATED!"), -+ ename, realm); -+ } -+ - hierarchy[0] = KRB5_CONF_REALMS; - hierarchy[1] = realm; - hierarchy[3] = NULL; -@@ -370,6 +381,14 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm, - goto whoops; - } - -+ if (krb5int_c_deprecated_enctype(rdp->realm_mkey.enctype)) { -+ if (krb5_enctype_to_name(rdp->realm_mkey.enctype, FALSE, ename, -+ sizeof(ename))) -+ ename[0] = '\0'; -+ fprintf(stderr, _("Stash file %s uses DEPRECATED enctype %s!"), -+ rdp->realm_stash, ename); -+ } -+ - if ((kret = krb5_db_fetch_mkey_list(rdp->realm_context, rdp->realm_mprinc, - &rdp->realm_mkey))) { - kdc_err(rdp->realm_context, kret, -diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py -index 5d9f80e04..ca3d32d21 100755 ---- a/src/tests/gssapi/t_enctypes.py -+++ b/src/tests/gssapi/t_enctypes.py -@@ -9,8 +9,11 @@ from k5test import * - aes256 = 'aes256-cts-hmac-sha1-96' - aes128 = 'aes128-cts-hmac-sha1-96' - des3 = 'des3-cbc-sha1' -+d_des3 = 'DEPRECATED:des3-cbc-sha1' - des3raw = 'des3-cbc-raw' -+d_des3raw = 'DEPRECATED:des3-cbc-raw' - rc4 = 'arcfour-hmac' -+d_rc4 = 'DEPRECATED:arcfour-hmac' - - # These tests make assumptions about the default enctype lists, so set - # them explicitly rather than relying on the library defaults. -@@ -92,7 +95,7 @@ test_err('acc aes128', None, 'aes128-cts', - # no acceptor subkey will be generated because we can't upgrade to a - # CFX enctype. - test('init des3', 'des3', None, -- tktenc=aes256, tktsession=des3, -+ tktenc=aes256, tktsession=d_des3, - proto='rfc1964', isubkey=des3raw, asubkey=None) - - # Force the ticket session key to be rc4, so we can test some subkey -@@ -103,7 +106,7 @@ realm.run([kadminl, 'setstr', realm.host_princ, 'session_enctypes', 'rc4']) - # [aes256 aes128 des3] and the acceptor should upgrade to an aes256 - # subkey. - test('upgrade noargs', None, None, -- tktenc=aes256, tktsession=rc4, -+ tktenc=aes256, tktsession=d_rc4, - proto='cfx', isubkey=rc4, asubkey=aes256) - - # If the initiator won't permit rc4 as a session key, it won't be able -@@ -113,14 +116,14 @@ test_err('upgrade init aes', 'aes', None, 'no support for encryption type') - # If the initiator permits rc4 but prefers aes128, it will send an - # upgrade list of [aes128] and the acceptor will upgrade to aes128. - test('upgrade init aes128+rc4', 'aes128-cts rc4', None, -- tktenc=aes256, tktsession=rc4, -+ tktenc=aes256, tktsession=d_rc4, - proto='cfx', isubkey=rc4, asubkey=aes128) - - # If the initiator permits rc4 but prefers des3, it will send an - # upgrade list of [des3], but the acceptor won't generate a subkey - # because des3 isn't a CFX enctype. - test('upgrade init des3+rc4', 'des3 rc4', None, -- tktenc=aes256, tktsession=rc4, -+ tktenc=aes256, tktsession=d_rc4, - proto='rfc1964', isubkey=rc4, asubkey=None) - - # If the acceptor permits only aes128, subkey negotiation will fail -@@ -134,14 +137,14 @@ test_err('upgrade acc aes128', None, 'aes128-cts', - # If the acceptor permits rc4 but prefers aes128, it will negotiate an - # upgrade to aes128. - test('upgrade acc aes128 rc4', None, 'aes128-cts rc4', -- tktenc=aes256, tktsession=rc4, -+ tktenc=aes256, tktsession=d_rc4, - proto='cfx', isubkey=rc4, asubkey=aes128) - - # In this test, the initiator and acceptor each prefer an AES enctype - # to rc4, but they can't agree on which one, so no subkey is - # generated. - test('upgrade mismatch', 'aes128-cts rc4', 'aes256-cts rc4', -- tktenc=aes256, tktsession=rc4, -+ tktenc=aes256, tktsession=d_rc4, - proto='rfc1964', isubkey=rc4, asubkey=None) - - success('gss_krb5_set_allowable_enctypes tests') -diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py -index 7c8d828f0..4af6804f2 100755 ---- a/src/tests/t_keyrollover.py -+++ b/src/tests/t_keyrollover.py -@@ -22,8 +22,9 @@ realm.run([kvno, princ1]) - realm.run([kadminl, 'purgekeys', realm.krbtgt_princ]) - # Make sure an old TGT fails after purging old TGS key. - realm.run([kvno, princ2], expected_code=1) --msg = 'krbtgt/%s@%s\n\tEtype (skey, tkt): des-cbc-crc, des-cbc-crc' % \ -- (realm.realm, realm.realm) -+ddes = "DEPRECATED:des-cbc-crc" -+msg = 'krbtgt/%s@%s\n\tEtype (skey, tkt): %s, %s' % \ -+ (realm.realm, realm.realm, ddes, ddes) - realm.run([klist, '-e'], expected_msg=msg) - - # Check that new key actually works. -@@ -48,7 +49,8 @@ realm.run([kadminl, 'cpw', '-randkey', '-keepold', '-e', 'aes256-cts', - realm.krbtgt_princ]) - realm.run([kadminl, 'modprinc', '-kvno', '1', realm.krbtgt_princ]) - out = realm.run([kadminl, 'getprinc', realm.krbtgt_princ]) --if 'vno 1, aes256' not in out or 'vno 1, des3' not in out: -+if 'vno 1, aes256-cts' not in out or \ -+ 'vno 1, DEPRECATED:des3-cbc-sha1' not in out: - fail('keyrollover: setup for TGS enctype test failed') - # Now present the DES3 ticket to the KDC and make sure it's rejected. - realm.run([kvno, realm.host_princ], expected_code=1) -diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py -index 448092387..da02f224a 100755 ---- a/src/tests/t_sesskeynego.py -+++ b/src/tests/t_sesskeynego.py -@@ -62,11 +62,11 @@ test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96') - # 3b: Negotiate rc4-hmac session key when principal only has aes256 long-term. - realm.run([kadminl, 'setstr', 'server', 'session_enctypes', - 'rc4-hmac,aes128-cts,aes256-cts']) --test_kvno(realm, 'arcfour-hmac', 'aes256-cts-hmac-sha1-96') -+test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') - - # 3c: Test des-cbc-crc default assumption. - realm.run([kadminl, 'delstr', 'server', 'session_enctypes']) --test_kvno(realm, 'des-cbc-crc', 'aes256-cts-hmac-sha1-96') -+test_kvno(realm, 'DEPRECATED:des-cbc-crc', 'aes256-cts-hmac-sha1-96') - realm.stop() - - # Last go: test that we can disable the des-cbc-crc assumption diff --git a/Mark-the-doc-kadm5-tex-files-as-historic.patch b/Mark-the-doc-kadm5-tex-files-as-historic.patch deleted file mode 100644 index 8ff592d..0000000 --- a/Mark-the-doc-kadm5-tex-files-as-historic.patch +++ /dev/null @@ -1,139 +0,0 @@ -From d8a20291fca962dfc88e396f2a60e41ede62be46 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 11 Apr 2019 18:33:04 -0400 -Subject: [PATCH] Mark the doc/kadm5 tex files as historic - -Remove rcsid.sty and the uses of the \rcsId macro as git does not -perform the keyword expansion necessary to make it work. Add comments -indicating the historic status of the kadm5 documentation. - -[ghudson@mit.edu: fix the tex files instead of marking them as -non-building] - -(cherry picked from commit e6047bdd6dec0d104417f9a1318bbafe022b81c1) ---- - doc/kadm5/adb-unit-test.tex | 7 ++++--- - doc/kadm5/api-funcspec.tex | 9 +++++---- - doc/kadm5/api-server-design.tex | 9 +++++---- - doc/kadm5/api-unit-test.tex | 7 ++++--- - doc/kadm5/rcsid.sty | 5 ----- - 5 files changed, 18 insertions(+), 19 deletions(-) - delete mode 100644 doc/kadm5/rcsid.sty - -diff --git a/doc/kadm5/adb-unit-test.tex b/doc/kadm5/adb-unit-test.tex -index d401342df..987af1a5e 100644 ---- a/doc/kadm5/adb-unit-test.tex -+++ b/doc/kadm5/adb-unit-test.tex -@@ -1,6 +1,7 @@ --\documentstyle[times,fullpage,rcsid]{article} -+% This document is included for historical purposes only, and does not -+% apply to krb5 today. - --\rcs$Id$ -+\documentstyle[times,fullpage]{article} - - %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% - %% Make _ actually generate an _, and allow line-breaking after it. -@@ -39,7 +40,7 @@ - %\newcommand{\Priority}[1]{} - - \title{OpenV*Secure Admin Database API\\ --Unit Test Description\footnote{\rcsId}} -+Unit Test Description} - \author{Jonathan I. Kamens} - - \begin{document} -diff --git a/doc/kadm5/api-funcspec.tex b/doc/kadm5/api-funcspec.tex -index c13090a51..76d2bb5d0 100644 ---- a/doc/kadm5/api-funcspec.tex -+++ b/doc/kadm5/api-funcspec.tex -@@ -1,4 +1,7 @@ --\documentstyle[12pt,fullpage,rcsid]{article} -+% This document is included for historical purposes only, and does not -+% apply to krb5 today. -+ -+\documentstyle[12pt,fullpage]{article} - - %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% - %% Make _ actually generate an _, and allow line-breaking after it. -@@ -7,15 +10,13 @@ - \def_{\underscore\penalty75\relax} - %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% - --\rcs$Id$ -- - \setlength{\parskip}{.7\baselineskip} - \setlength{\parindent}{0pt} - - \def\v#1{\verb+#1+} - - \title{Kerberos Administration System \\ -- KADM5 API Functional Specifications\thanks{\rcsId}} -+ KADM5 API Functional Specifications} - \author{Barry Jaspan} - - \begin{document} -diff --git a/doc/kadm5/api-server-design.tex b/doc/kadm5/api-server-design.tex -index 228e83113..94e05b877 100644 ---- a/doc/kadm5/api-server-design.tex -+++ b/doc/kadm5/api-server-design.tex -@@ -1,4 +1,7 @@ --\documentstyle[12pt,fullpage,rcsid]{article} -+% This document is included for historical purposes only, and does not -+% apply to krb5 today. -+ -+\documentstyle[12pt,fullpage]{article} - - %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% - %% Make _ actually generate an _, and allow line-breaking after it. -@@ -7,15 +10,13 @@ - \def_{\underscore\penalty75\relax} - %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% - --\rcs$Id$ -- - \setlength{\parskip}{.7\baselineskip} - \setlength{\parindent}{0pt} - - \def\v#1{\verb+#1+} - \def\k#1{K$_#1$} - --\title{KADM5 Library and Server \\ Implementation Design\thanks{\rcsId}} -+\title{KADM5 Library and Server \\ Implementation Design} - \author{Barry Jaspan} - - \begin{document} -diff --git a/doc/kadm5/api-unit-test.tex b/doc/kadm5/api-unit-test.tex -index 3e0eb503e..bfd6280bb 100644 ---- a/doc/kadm5/api-unit-test.tex -+++ b/doc/kadm5/api-unit-test.tex -@@ -1,6 +1,7 @@ --\documentstyle[times,fullpage,rcsid]{article} -+% This document is included for historical purposes only, and does not -+% apply to krb5 today. - --\rcs$Id$ -+\documentstyle[times,fullpage]{article} - - %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% - %% Make _ actually generate an _, and allow line-breaking after it. -@@ -41,7 +42,7 @@ - %\newcommand{\Priority}[1]{} - - \title{KADM5 Admin API\\ --Unit Test Description\footnote{\rcsId}} -+Unit Test Description} - \author{Jonathan I. Kamens} - - \begin{document} -diff --git a/doc/kadm5/rcsid.sty b/doc/kadm5/rcsid.sty -deleted file mode 100644 -index 3ad7826ff..000000000 ---- a/doc/kadm5/rcsid.sty -+++ /dev/null -@@ -1,5 +0,0 @@ --\def\rcs$#1: #2${\expandafter\def\csname rcs#1\endcsname{#2}} -- --% example usage: --% \rcs$Version$ --% Version \rcsVersion diff --git a/Modernize-example-enctypes-in-documentation.patch b/Modernize-example-enctypes-in-documentation.patch deleted file mode 100644 index 78ee5e6..0000000 --- a/Modernize-example-enctypes-in-documentation.patch +++ /dev/null @@ -1,232 +0,0 @@ -From b90cdec363eae38cb2ea40d40668e3fbc83edeb8 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 11 Apr 2019 18:25:41 -0400 -Subject: [PATCH] Modernize example enctypes in documentation - -ticket: 8805 (new) -(cherry picked from commit ccb4a3e4b35fa9ea63af0e98a42eba4aadb099e2) -[rharwood@redhat.com: release version conflict in man pages] ---- - doc/admin/admin_commands/kadmin_local.rst | 8 ++++---- - doc/admin/admin_commands/kdb5_util.rst | 10 +++++----- - doc/admin/database.rst | 2 +- - doc/admin/install_appl_srv.rst | 19 +++++++------------ - doc/admin/install_kdc.rst | 2 +- - src/man/kadmin.man | 10 +++++----- - src/man/kdb5_util.man | 10 +++++----- - .../kdb/ldap/libkdb_ldap/kerberos.ldif | 4 ++-- - .../kdb/ldap/libkdb_ldap/kerberos.schema | 4 ++-- - 9 files changed, 32 insertions(+), 37 deletions(-) - -diff --git a/doc/admin/admin_commands/kadmin_local.rst b/doc/admin/admin_commands/kadmin_local.rst -index 150da1fad..71aa894f6 100644 ---- a/doc/admin/admin_commands/kadmin_local.rst -+++ b/doc/admin/admin_commands/kadmin_local.rst -@@ -569,16 +569,16 @@ Examples:: - Principal: tlyu/admin@BLEEP.COM - Expiration date: [never] - Last password change: Mon Aug 12 14:16:47 EDT 1996 -- Password expiration date: [none] -+ Password expiration date: [never] - Maximum ticket life: 0 days 10:00:00 - Maximum renewable life: 7 days 00:00:00 - Last modified: Mon Aug 12 14:16:47 EDT 1996 (bjaspan/admin@BLEEP.COM) - Last successful authentication: [never] - Last failed authentication: [never] - Failed password attempts: 0 -- Number of keys: 2 -- Key: vno 1, des-cbc-crc -- Key: vno 1, des-cbc-crc:v4 -+ Number of keys: 1 -+ Key: vno 1, aes256-cts-hmac-sha384-192 -+ MKey: vno 1 - Attributes: - Policy: [none] - -diff --git a/doc/admin/admin_commands/kdb5_util.rst b/doc/admin/admin_commands/kdb5_util.rst -index 7dd54f797..444c58bcd 100644 ---- a/doc/admin/admin_commands/kdb5_util.rst -+++ b/doc/admin/admin_commands/kdb5_util.rst -@@ -476,17 +476,17 @@ Examples:: - $ kdb5_util tabdump -o keyinfo.txt keyinfo - $ cat keyinfo.txt - name keyindex kvno enctype salttype salt -+ K/M@EXAMPLE.COM 0 1 aes256-cts-hmac-sha384-192 normal -1 - foo@EXAMPLE.COM 0 1 aes128-cts-hmac-sha1-96 normal -1 - bar@EXAMPLE.COM 0 1 aes128-cts-hmac-sha1-96 normal -1 -- bar@EXAMPLE.COM 1 1 des-cbc-crc normal -1 - $ sqlite3 - sqlite> .mode tabs - sqlite> .import keyinfo.txt keyinfo -- sqlite> select * from keyinfo where enctype like 'des-cbc-%'; -- bar@EXAMPLE.COM 1 1 des-cbc-crc normal -1 -+ sqlite> select * from keyinfo where enctype like 'aes256-%'; -+ K/M@EXAMPLE.COM 1 1 aes256-cts-hmac-sha384-192 normal -1 - sqlite> .quit -- $ awk -F'\t' '$4 ~ /des-cbc-/ { print }' keyinfo.txt -- bar@EXAMPLE.COM 1 1 des-cbc-crc normal -1 -+ $ awk -F'\t' '$4 ~ /aes256-/ { print }' keyinfo.txt -+ K/M@EXAMPLE.COM 1 1 aes256-cts-hmac-sha384-192 normal -1 - - - ENVIRONMENT -diff --git a/doc/admin/database.rst b/doc/admin/database.rst -index 33895b857..cea60b009 100644 ---- a/doc/admin/database.rst -+++ b/doc/admin/database.rst -@@ -483,7 +483,7 @@ availability. To roll over the master key, follow these steps: - - $ kdb5_util list_mkeys - Master keys for Principal: K/M@KRBTEST.COM -- KVNO: 1, Enctype: des-cbc-crc, Active on: Wed Dec 31 19:00:00 EST 1969 * -+ KVNO: 1, Enctype: aes256-cts-hmac-sha384-192, Active on: Thu Jan 01 00:00:00 UTC 1970 * - - #. On the master KDC, run ``kdb5_util use_mkey 1`` to ensure that a - master key activation list is present in the database. This step -diff --git a/doc/admin/install_appl_srv.rst b/doc/admin/install_appl_srv.rst -index 6bae7248f..6b2d8e471 100644 ---- a/doc/admin/install_appl_srv.rst -+++ b/doc/admin/install_appl_srv.rst -@@ -44,18 +44,13 @@ pop, the administrator ``joeadmin`` would issue the command (on - ``trillium.mit.edu``):: - - trillium% kadmin -- kadmin5: ktadd host/trillium.mit.edu ftp/trillium.mit.edu -- pop/trillium.mit.edu -- kadmin: Entry for principal host/trillium.mit.edu@ATHENA.MIT.EDU with -- kvno 3, encryption type DES-CBC-CRC added to keytab -- FILE:/etc/krb5.keytab. -- kadmin: Entry for principal ftp/trillium.mit.edu@ATHENA.MIT.EDU with -- kvno 3, encryption type DES-CBC-CRC added to keytab -- FILE:/etc/krb5.keytab. -- kadmin: Entry for principal pop/trillium.mit.edu@ATHENA.MIT.EDU with -- kvno 3, encryption type DES-CBC-CRC added to keytab -- FILE:/etc/krb5.keytab. -- kadmin5: quit -+ Authenticating as principal root/admin@ATHENA.MIT.EDU with password. -+ Password for root/admin@ATHENA.MIT.EDU: -+ kadmin: ktadd host/trillium.mit.edu ftp/trillium.mit.edu pop/trillium.mit.edu -+ Entry for principal host/trillium.mit.edu@ATHENA.MIT.EDU with kvno 3, encryption type aes256-cts-hmac-sha384-192 added to keytab FILE:/etc/krb5.keytab. -+ kadmin: Entry for principal ftp/trillium.mit.edu@ATHENA.MIT.EDU with kvno 3, encryption type aes256-cts-hmac-sha384-192 added to keytab FILE:/etc/krb5.keytab. -+ kadmin: Entry for principal pop/trillium.mit.edu@ATHENA.MIT.EDU with kvno 3, encryption type aes256-cts-hmac-sha384-192 added to keytab FILE:/etc/krb5.keytab. -+ kadmin: quit - trillium% - - If you generate the keytab file on another host, you need to get a -diff --git a/doc/admin/install_kdc.rst b/doc/admin/install_kdc.rst -index 5d1e70ede..3bec59f96 100644 ---- a/doc/admin/install_kdc.rst -+++ b/doc/admin/install_kdc.rst -@@ -340,7 +340,7 @@ To extract a keytab directly on a replica KDC called - Entry for principal host/kerberos-1.mit.edu with kvno 2, encryption - type aes128-cts-hmac-sha1-96 added to keytab FILE:/etc/krb5.keytab. - Entry for principal host/kerberos-1.mit.edu with kvno 2, encryption -- type des3-cbc-sha1 added to keytab FILE:/etc/krb5.keytab. -+ type aes256-cts-hmac-sha384-192 added to keytab FILE:/etc/krb5.keytab. - Entry for principal host/kerberos-1.mit.edu with kvno 2, encryption - type arcfour-hmac added to keytab FILE:/etc/krb5.keytab. - -diff --git a/src/man/kadmin.man b/src/man/kadmin.man -index 3c4f013fb..44859a378 100644 ---- a/src/man/kadmin.man -+++ b/src/man/kadmin.man -@@ -1,6 +1,6 @@ - .\" Man page generated from reStructuredText. - . --.TH "KADMIN" "1" " " "1.17.1" "MIT Kerberos" -+.TH "KADMIN" "1" " " "1.18" "MIT Kerberos" - .SH NAME - kadmin \- Kerberos V5 database administration program - . -@@ -610,16 +610,16 @@ kadmin: getprinc tlyu/admin - Principal: tlyu/admin@BLEEP.COM - Expiration date: [never] - Last password change: Mon Aug 12 14:16:47 EDT 1996 --Password expiration date: [none] -+Password expiration date: [never] - Maximum ticket life: 0 days 10:00:00 - Maximum renewable life: 7 days 00:00:00 - Last modified: Mon Aug 12 14:16:47 EDT 1996 (bjaspan/admin@BLEEP.COM) - Last successful authentication: [never] - Last failed authentication: [never] - Failed password attempts: 0 --Number of keys: 2 --Key: vno 1, des\-cbc\-crc --Key: vno 1, des\-cbc\-crc:v4 -+Number of keys: 1 -+Key: vno 1, aes256\-cts\-hmac\-sha384\-192 -+MKey: vno 1 - Attributes: - Policy: [none] - -diff --git a/src/man/kdb5_util.man b/src/man/kdb5_util.man -index 9a36ef0df..46772a236 100644 ---- a/src/man/kdb5_util.man -+++ b/src/man/kdb5_util.man -@@ -529,17 +529,17 @@ Examples: - $ kdb5_util tabdump \-o keyinfo.txt keyinfo - $ cat keyinfo.txt - name keyindex kvno enctype salttype salt -+K/M@EXAMPLE.COM 0 1 aes256\-cts\-hmac\-sha384\-192 normal \-1 - foo@EXAMPLE.COM 0 1 aes128\-cts\-hmac\-sha1\-96 normal \-1 - bar@EXAMPLE.COM 0 1 aes128\-cts\-hmac\-sha1\-96 normal \-1 --bar@EXAMPLE.COM 1 1 des\-cbc\-crc normal \-1 - $ sqlite3 - sqlite> .mode tabs - sqlite> .import keyinfo.txt keyinfo --sqlite> select * from keyinfo where enctype like \(aqdes\-cbc\-%\(aq; --bar@EXAMPLE.COM 1 1 des\-cbc\-crc normal \-1 -+sqlite> select * from keyinfo where enctype like \(aqaes256\-%\(aq; -+K/M@EXAMPLE.COM 1 1 aes256\-cts\-hmac\-sha384\-192 normal \-1 - sqlite> .quit --$ awk \-F\(aq\et\(aq \(aq$4 ~ /des\-cbc\-/ { print }\(aq keyinfo.txt --bar@EXAMPLE.COM 1 1 des\-cbc\-crc normal \-1 -+$ awk \-F\(aq\et\(aq \(aq$4 ~ /aes256\-/ { print }\(aq keyinfo.txt -+K/M@EXAMPLE.COM 1 1 aes256\-cts\-hmac\-sha384\-192 normal \-1 - .ft P - .fi - .UNINDENT -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif b/src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif -index 13db48609..4224f0850 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif -+++ b/src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif -@@ -512,7 +512,7 @@ attributetypes: ( 2.16.840.1.113719.1.301.4.41.1 - - ##### Holds the default encryption/salt type combinations of principals for - ##### the Realm. Stores in the form of key:salt strings. --##### Example: des-cbc-crc:normal -+##### Example: aes256-cts-hmac-sha384-192:normal - - dn: cn=schema - changetype: modify -@@ -533,7 +533,7 @@ attributetypes: ( 2.16.840.1.113719.1.301.4.42.1 - ##### ONLYREALM - ##### SPECIAL - ##### AFS3 --##### Example: des-cbc-crc:normal -+##### Example: aes256-cts-hmac-sha384-192:normal - ##### - ##### This attribute obsoletes the krbSupportedEncTypes and krbSupportedSaltTypes - ##### attributes. -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema b/src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema -index 52036a178..171f66927 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema -+++ b/src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema -@@ -410,7 +410,7 @@ attributetype ( 2.16.840.1.113719.1.301.4.41.1 - ##### Holds the default encryption/salt type combinations of principals for - ##### the Realm. Stores in the form of key:salt strings. This will be - ##### subset of the supported encryption/salt types. --##### Example: des-cbc-crc:normal -+##### Example: aes256-cts-hmac-sha384-192:normal - - attributetype ( 2.16.840.1.113719.1.301.4.42.1 - NAME 'krbDefaultEncSaltTypes' -@@ -428,7 +428,7 @@ attributetype ( 2.16.840.1.113719.1.301.4.42.1 - ##### ONLYREALM - ##### SPECIAL - ##### AFS3 --##### Example: des-cbc-crc:normal -+##### Example: aes256-cts-hmac-sha384-192:normal - - attributetype ( 2.16.840.1.113719.1.301.4.43.1 - NAME 'krbSupportedEncSaltTypes' diff --git a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch b/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch deleted file mode 100644 index 9914759..0000000 --- a/Modernize-exit-path-in-gss_krb5int_copy_ccache.patch +++ /dev/null @@ -1,68 +0,0 @@ -From 762241d6dbcb7b90ecf6a7352553465c30fcab74 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 2 May 2019 14:32:33 -0400 -Subject: [PATCH] Modernize exit path in gss_krb5int_copy_ccache() - -Move to a single lock / single unlock paradigm, and eliminate some -dead code in the old error handling. - -(cherry picked from commit 1b89e3d8e949f52901bce74c9afc7a1a64099520) ---- - src/lib/gssapi/krb5/copy_ccache.c | 31 ++++++++++++------------------- - 1 file changed, 12 insertions(+), 19 deletions(-) - -diff --git a/src/lib/gssapi/krb5/copy_ccache.c b/src/lib/gssapi/krb5/copy_ccache.c -index 027ed4847..2b2806e70 100644 ---- a/src/lib/gssapi/krb5/copy_ccache.c -+++ b/src/lib/gssapi/krb5/copy_ccache.c -@@ -9,7 +9,7 @@ gss_krb5int_copy_ccache(OM_uint32 *minor_status, - { - krb5_gss_cred_id_t k5creds; - krb5_error_code code; -- krb5_context context; -+ krb5_context context = NULL; - krb5_ccache out_ccache; - - assert(value->length == sizeof(out_ccache)); -@@ -23,30 +23,23 @@ gss_krb5int_copy_ccache(OM_uint32 *minor_status, - k5creds = (krb5_gss_cred_id_t) *cred_handle; - k5_mutex_lock(&k5creds->lock); - if (k5creds->usage == GSS_C_ACCEPT) { -- k5_mutex_unlock(&k5creds->lock); -- *minor_status = (OM_uint32) G_BAD_USAGE; -- return(GSS_S_FAILURE); -+ code = G_BAD_USAGE; -+ goto cleanup; - } - - code = krb5_gss_init_context(&context); -- if (code) { -- k5_mutex_unlock(&k5creds->lock); -- *minor_status = code; -- return GSS_S_FAILURE; -- } -+ if (code) -+ goto cleanup; - - code = krb5_cc_copy_creds(context, k5creds->ccache, out_ccache); -- if (code) { -- k5_mutex_unlock(&k5creds->lock); -- *minor_status = code; -- save_error_info(*minor_status, context); -- krb5_free_context(context); -- return(GSS_S_FAILURE); -- } -+ -+cleanup: - k5_mutex_unlock(&k5creds->lock); - *minor_status = code; -- if (code) -- save_error_info(*minor_status, context); -- krb5_free_context(context); -+ if (context != NULL) { -+ if (code) -+ save_error_info(*minor_status, context); -+ krb5_free_context(context); -+ } - return code ? GSS_S_FAILURE : GSS_S_COMPLETE; - } diff --git a/Properly-size-ifdef-in-k5_cccol_lock.patch b/Properly-size-ifdef-in-k5_cccol_lock.patch deleted file mode 100644 index 1afa100..0000000 --- a/Properly-size-ifdef-in-k5_cccol_lock.patch +++ /dev/null @@ -1,33 +0,0 @@ -From c1b4612565658d64940ba4760e0b47afd21e718f Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 14 Feb 2019 11:50:35 -0500 -Subject: [PATCH] Properly size #ifdef in k5_cccol_lock() - -The cleanup code only could get executed in the USE_CCAPI_V3 case, so -move it inside that block. Reported by Coverity. - -(cherry picked from commit 444a15f9cf82b9a6c1bca3f20307f82fee91c228) ---- - src/lib/krb5/ccache/ccbase.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/lib/krb5/ccache/ccbase.c b/src/lib/krb5/ccache/ccbase.c -index 8198f2b9b..2702bef69 100644 ---- a/src/lib/krb5/ccache/ccbase.c -+++ b/src/lib/krb5/ccache/ccbase.c -@@ -511,7 +511,6 @@ krb5_cccol_lock(krb5_context context) - #endif - #ifdef USE_CCAPI_V3 - ret = krb5_stdccv3_context_lock(context); --#endif - if (ret) { - k5_cc_mutex_unlock(context, &krb5int_mcc_mutex); - k5_cc_mutex_unlock(context, &krb5int_cc_file_mutex); -@@ -519,6 +518,7 @@ krb5_cccol_lock(krb5_context context) - k5_cc_mutex_unlock(context, &cccol_lock); - return ret; - } -+#endif - k5_mutex_unlock(&cc_typelist_lock); - return ret; - } diff --git a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch b/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch deleted file mode 100644 index 09280f0..0000000 --- a/Remove-Kerberos-v4-support-vestiges-from-ccapi.patch +++ /dev/null @@ -1,1604 +0,0 @@ -From 34aa9b5889a48f05b4dec33d40e72e97390118a5 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 4 Apr 2019 14:37:38 -0400 -Subject: [PATCH] Remove Kerberos v4 support vestiges from ccapi - -(cherry picked from commit 51395dc956ce9eef27c0d6843561d3d3828b03cd) ---- - src/ccapi/common/cci_cred_union.c | 280 +------------------------ - src/ccapi/lib/ccapi_v2.c | 34 +-- - src/ccapi/lib/win/OldCC/ccapi.h | 20 -- - src/ccapi/server/ccs_ccache.c | 69 +----- - src/ccapi/test/test_ccapi_ccache.c | 223 +++----------------- - src/ccapi/test/test_ccapi_constants.c | 2 - - src/ccapi/test/test_ccapi_context.c | 3 - - src/ccapi/test/test_ccapi_v2.c | 89 -------- - src/include/CredentialsCache.h | 156 ++++---------- - src/include/CredentialsCache2.h | 26 +-- - src/lib/krb5/ccache/ccapi/stdcc.c | 2 - - src/lib/krb5/ccache/ccapi/stdcc_util.c | 8 +- - src/windows/kfwlogon/kfwlogon.h | 2 +- - src/windows/leashdll/leash-int.h | 2 +- - src/windows/lib/cacheapi.h | 53 +---- - 15 files changed, 98 insertions(+), 871 deletions(-) - -diff --git a/src/ccapi/common/cci_cred_union.c b/src/ccapi/common/cci_cred_union.c -index 4c8981610..424a93dab 100644 ---- a/src/ccapi/common/cci_cred_union.c -+++ b/src/ccapi/common/cci_cred_union.c -@@ -25,181 +25,6 @@ - - #include "cci_common.h" - --#ifdef TARGET_OS_MAC --#pragma mark - --#endif -- --/* ------------------------------------------------------------------------ */ -- --static cc_uint32 cci_credentials_v4_release (cc_credentials_v4_t *io_v4creds) --{ -- cc_int32 err = ccNoError; -- -- if (!io_v4creds) { err = ccErrBadParam; } -- -- if (!err) { -- memset (io_v4creds, 0, sizeof (*io_v4creds)); -- free (io_v4creds); -- } -- -- return err; --} -- --/* ------------------------------------------------------------------------ */ -- --static cc_uint32 cci_credentials_v4_read (cc_credentials_v4_t **out_v4creds, -- k5_ipc_stream io_stream) --{ -- cc_int32 err = ccNoError; -- cc_credentials_v4_t *v4creds = NULL; -- -- if (!io_stream ) { err = cci_check_error (ccErrBadParam); } -- if (!out_v4creds) { err = cci_check_error (ccErrBadParam); } -- -- if (!err) { -- v4creds = malloc (sizeof (*v4creds)); -- if (!v4creds) { err = cci_check_error (ccErrNoMem); } -- } -- -- if (!err) { -- err = krb5int_ipc_stream_read_uint32 (io_stream, &v4creds->version); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_read (io_stream, v4creds->principal, cc_v4_name_size); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_read (io_stream, v4creds->principal_instance, cc_v4_instance_size); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_read (io_stream, v4creds->service, cc_v4_name_size); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_read (io_stream, v4creds->service_instance, cc_v4_instance_size); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_read (io_stream, v4creds->realm, cc_v4_realm_size); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_read (io_stream, v4creds->session_key, cc_v4_key_size); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_read_int32 (io_stream, &v4creds->kvno); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_read_int32 (io_stream, &v4creds->string_to_key_type); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_read_time (io_stream, &v4creds->issue_date); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_read_int32 (io_stream, &v4creds->lifetime); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_read_uint32 (io_stream, &v4creds->address); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_read_int32 (io_stream, &v4creds->ticket_size); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_read (io_stream, v4creds->ticket, cc_v4_ticket_size); -- } -- -- if (!err) { -- *out_v4creds = v4creds; -- v4creds = NULL; -- } -- -- free (v4creds); -- -- return cci_check_error (err); --} -- --/* ------------------------------------------------------------------------ */ -- --static cc_uint32 cci_credentials_v4_write (cc_credentials_v4_t *in_v4creds, -- k5_ipc_stream io_stream) --{ -- cc_int32 err = ccNoError; -- -- if (!io_stream ) { err = cci_check_error (ccErrBadParam); } -- if (!in_v4creds) { err = cci_check_error (ccErrBadParam); } -- -- if (!err) { -- err = krb5int_ipc_stream_write_uint32 (io_stream, in_v4creds->version); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_write (io_stream, in_v4creds->principal, cc_v4_name_size); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_write (io_stream, in_v4creds->principal_instance, cc_v4_instance_size); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_write (io_stream, in_v4creds->service, cc_v4_name_size); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_write (io_stream, in_v4creds->service_instance, cc_v4_instance_size); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_write (io_stream, in_v4creds->realm, cc_v4_realm_size); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_write (io_stream, in_v4creds->session_key, cc_v4_key_size); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_write_int32 (io_stream, in_v4creds->kvno); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_write_int32 (io_stream, in_v4creds->string_to_key_type); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_write_time (io_stream, in_v4creds->issue_date); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_write_int32 (io_stream, in_v4creds->lifetime); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_write_uint32 (io_stream, in_v4creds->address); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_write_int32 (io_stream, in_v4creds->ticket_size); -- } -- -- if (!err) { -- err = krb5int_ipc_stream_write (io_stream, in_v4creds->ticket, cc_v4_ticket_size); -- } -- -- return cci_check_error (err); --} -- --#ifdef TARGET_OS_MAC --#pragma mark - --#endif -- - /* ------------------------------------------------------------------------ */ - - static cc_uint32 cci_cc_data_contents_release (cc_data *io_ccdata) -@@ -600,9 +425,7 @@ cc_uint32 cci_credentials_union_release (cc_credentials_union *io_cred_union) - if (!io_cred_union) { err = ccErrBadParam; } - - if (!err) { -- if (io_cred_union->version == cc_credentials_v4) { -- cci_credentials_v4_release (io_cred_union->credentials.credentials_v4); -- } else if (io_cred_union->version == cc_credentials_v5) { -+ if (io_cred_union->version == cc_credentials_v5) { - cci_credentials_v5_release (io_cred_union->credentials.credentials_v5); - } - free (io_cred_union); -@@ -632,11 +455,7 @@ cc_uint32 cci_credentials_union_read (cc_credentials_union **out_credentials_uni - } - - if (!err) { -- if (credentials_union->version == cc_credentials_v4) { -- err = cci_credentials_v4_read (&credentials_union->credentials.credentials_v4, -- io_stream); -- -- } else if (credentials_union->version == cc_credentials_v5) { -+ if (credentials_union->version == cc_credentials_v5) { - err = cci_credentials_v5_read (&credentials_union->credentials.credentials_v5, - io_stream); - -@@ -671,11 +490,7 @@ cc_uint32 cci_credentials_union_write (const cc_credentials_union *in_credential - } - - if (!err) { -- if (in_credentials_union->version == cc_credentials_v4) { -- err = cci_credentials_v4_write (in_credentials_union->credentials.credentials_v4, -- io_stream); -- -- } else if (in_credentials_union->version == cc_credentials_v5) { -+ if (in_credentials_union->version == cc_credentials_v5) { - err = cci_credentials_v5_write (in_credentials_union->credentials.credentials_v5, - io_stream); - -@@ -714,11 +529,7 @@ cc_uint32 cci_cred_union_release (cred_union *io_cred_union) - if (!io_cred_union) { err = ccErrBadParam; } - - if (!err) { -- if (io_cred_union->cred_type == CC_CRED_V4) { -- memset (io_cred_union->cred.pV4Cred, 0, sizeof (cc_credentials_v4_compat)); -- free (io_cred_union->cred.pV4Cred); -- -- } else if (io_cred_union->cred_type == CC_CRED_V5) { -+ if (io_cred_union->cred_type == CC_CRED_V5) { - free (io_cred_union->cred.pV5Cred->client); - free (io_cred_union->cred.pV5Cred->server); - cci_cc_data_contents_release (&io_cred_union->cred.pV5Cred->keyblock); -@@ -829,36 +640,7 @@ cc_uint32 cci_credentials_union_to_cred_union (const cc_credentials_union *in_c - } - - if (!err) { -- if (in_credentials_union->version == cc_credentials_v4) { -- cc_credentials_v4_compat *compat_v4creds = NULL; -- -- compat_v4creds = malloc (sizeof (*compat_v4creds)); -- if (!compat_v4creds) { err = cci_check_error (ccErrNoMem); } -- -- if (!err) { -- cc_credentials_v4_t *v4creds = in_credentials_union->credentials.credentials_v4; -- -- compat_cred_union->cred_type = CC_CRED_V4; -- compat_cred_union->cred.pV4Cred = compat_v4creds; -- -- compat_v4creds->kversion = v4creds->version; -- strncpy (compat_v4creds->principal, v4creds->principal, KRB_NAME_SZ+1); -- strncpy (compat_v4creds->principal_instance, v4creds->principal_instance, KRB_INSTANCE_SZ+1); -- strncpy (compat_v4creds->service, v4creds->service, KRB_NAME_SZ+1); -- strncpy (compat_v4creds->service_instance, v4creds->service_instance, KRB_INSTANCE_SZ+1); -- strncpy (compat_v4creds->realm, v4creds->realm, KRB_REALM_SZ+1); -- memcpy (compat_v4creds->session_key, v4creds->session_key, 8); -- compat_v4creds->kvno = v4creds->kvno; -- compat_v4creds->str_to_key = v4creds->string_to_key_type; -- compat_v4creds->issue_date = v4creds->issue_date; -- compat_v4creds->lifetime = v4creds->lifetime; -- compat_v4creds->address = v4creds->address; -- compat_v4creds->ticket_sz = v4creds->ticket_size; -- memcpy (compat_v4creds->ticket, v4creds->ticket, MAX_V4_CRED_LEN); -- compat_v4creds->oops = 0; -- } -- -- } else if (in_credentials_union->version == cc_credentials_v5) { -+ if (in_credentials_union->version == cc_credentials_v5) { - cc_credentials_v5_t *v5creds = in_credentials_union->credentials.credentials_v5; - cc_credentials_v5_compat *compat_v5creds = NULL; - -@@ -951,36 +733,7 @@ cc_uint32 cci_cred_union_to_credentials_union (const cred_union *in_cred_un - } - - if (!err) { -- if (in_cred_union->cred_type == CC_CRED_V4) { -- cc_credentials_v4_compat *compat_v4creds = in_cred_union->cred.pV4Cred; -- cc_credentials_v4_t *v4creds = NULL; -- -- if (!err) { -- v4creds = malloc (sizeof (*v4creds)); -- if (!v4creds) { err = cci_check_error (ccErrNoMem); } -- } -- -- if (!err) { -- creds_union->version = cc_credentials_v4; -- creds_union->credentials.credentials_v4 = v4creds; -- -- v4creds->version = compat_v4creds->kversion; -- strncpy (v4creds->principal, compat_v4creds->principal, KRB_NAME_SZ); -- strncpy (v4creds->principal_instance, compat_v4creds->principal_instance, KRB_INSTANCE_SZ); -- strncpy (v4creds->service, compat_v4creds->service, KRB_NAME_SZ); -- strncpy (v4creds->service_instance, compat_v4creds->service_instance, KRB_INSTANCE_SZ); -- strncpy (v4creds->realm, compat_v4creds->realm, KRB_REALM_SZ); -- memcpy (v4creds->session_key, compat_v4creds->session_key, 8); -- v4creds->kvno = compat_v4creds->kvno; -- v4creds->string_to_key_type = compat_v4creds->str_to_key; -- v4creds->issue_date = compat_v4creds->issue_date; -- v4creds->lifetime = compat_v4creds->lifetime; -- v4creds->address = compat_v4creds->address; -- v4creds->ticket_size = compat_v4creds->ticket_sz; -- memcpy (v4creds->ticket, compat_v4creds->ticket, MAX_V4_CRED_LEN); -- } -- -- } else if (in_cred_union->cred_type == CC_CRED_V5) { -+ if (in_cred_union->cred_type == CC_CRED_V5) { - cc_credentials_v5_compat *compat_v5creds = in_cred_union->cred.pV5Cred; - cc_credentials_v5_t *v5creds = NULL; - -@@ -1072,26 +825,7 @@ cc_uint32 cci_cred_union_compare_to_credentials_union (const cred_union - if (!out_equal ) { err = cci_check_error (ccErrBadParam); } - - if (!err) { -- if (in_cred_union_compat->cred_type == CC_CRED_V4 && -- in_credentials_union->version == cc_credentials_v4) { -- cc_credentials_v4_compat *old_creds_v4 = in_cred_union_compat->cred.pV4Cred; -- cc_credentials_v4_t *new_creds_v4 = in_credentials_union->credentials.credentials_v4; -- -- if (old_creds_v4 && new_creds_v4 && -- !strcmp (old_creds_v4->principal, -- new_creds_v4->principal) && -- !strcmp (old_creds_v4->principal_instance, -- new_creds_v4->principal_instance) && -- !strcmp (old_creds_v4->service, -- new_creds_v4->service) && -- !strcmp (old_creds_v4->service_instance, -- new_creds_v4->service_instance) && -- !strcmp (old_creds_v4->realm, new_creds_v4->realm) && -- (old_creds_v4->issue_date == (long) new_creds_v4->issue_date)) { -- equal = 1; -- } -- -- } else if (in_cred_union_compat->cred_type == CC_CRED_V5 && -+ if (in_cred_union_compat->cred_type == CC_CRED_V5 && - in_credentials_union->version == cc_credentials_v5) { - cc_credentials_v5_compat *old_creds_v5 = in_cred_union_compat->cred.pV5Cred; - cc_credentials_v5_t *new_creds_v5 = in_credentials_union->credentials.credentials_v5; -diff --git a/src/ccapi/lib/ccapi_v2.c b/src/ccapi/lib/ccapi_v2.c -index 8a831d796..ae9b790b0 100644 ---- a/src/ccapi/lib/ccapi_v2.c -+++ b/src/ccapi/lib/ccapi_v2.c -@@ -44,10 +44,7 @@ static cc_int32 cci_remap_version (cc_int32 in_v2_version, - if (!out_v3_version) { err = cci_check_error (ccErrBadParam); } - - if (!err) { -- if (in_v2_version == CC_CRED_V4) { -- *out_v3_version = cc_credentials_v4; -- -- } else if (in_v2_version == CC_CRED_V5) { -+ if (in_v2_version == CC_CRED_V5) { - *out_v3_version = cc_credentials_v5; - - } else { -@@ -450,10 +447,7 @@ cc_result cc_get_cred_version (apiCB *in_context, - } - - if (!err) { -- if (compat_version == cc_credentials_v4) { -- *out_version = CC_CRED_V4; -- -- } else if (compat_version == cc_credentials_v5) { -+ if (compat_version == cc_credentials_v5) { - *out_version = CC_CRED_V5; - - } else { -@@ -642,10 +636,6 @@ cc_result cc_seq_fetch_NCs_next (apiCB *in_context, - if (!out_ccache ) { err = cci_check_error (ccErrBadParam); } - if (!in_iterator) { err = cci_check_error (ccErrBadParam); } - -- /* CCache iterators need to return some ccaches twice (when v3 ccache has -- * two kinds of credentials). To do that, we return such ccaches twice -- * v4 first, then v5. */ -- - if (!err) { - err = cci_ccache_iterator_get_saved_ccache_name (iterator, - &saved_ccache_name); -@@ -674,25 +664,7 @@ cc_result cc_seq_fetch_NCs_next (apiCB *in_context, - } - - if (!err) { -- if (version == cc_credentials_v4_v5) { -- cc_string_t name = NULL; -- -- err = cci_ccache_set_compat_version (ccache, cc_credentials_v4); -- -- if (!err) { -- err = ccapi_ccache_get_name (ccache, &name); -- } -- -- if (!err) { -- err = cci_ccache_iterator_set_saved_ccache_name (iterator, -- name->data); -- } -- -- if (name) { ccapi_string_release (name); } -- -- } else { -- err = cci_ccache_set_compat_version (ccache, version); -- } -+ err = cci_ccache_set_compat_version (ccache, version); - } - } - } -diff --git a/src/ccapi/lib/win/OldCC/ccapi.h b/src/ccapi/lib/win/OldCC/ccapi.h -index 82512771a..4d6f3faaf 100644 ---- a/src/ccapi/lib/win/OldCC/ccapi.h -+++ b/src/ccapi/lib/win/OldCC/ccapi.h -@@ -80,7 +80,6 @@ enum __MIDL_ccapi_0003 - { KRB_NAME_SZ = 40, - KRB_INSTANCE_SZ = 40, - KRB_REALM_SZ = 40, -- MAX_V4_CRED_LEN = 1250 - } ; - typedef struct _NC_INFO - { -@@ -95,24 +94,6 @@ typedef struct _NC_INFO_LIST - /* [size_is] */ NC_INFO *info; - } NC_INFO_LIST; - --typedef struct _V4_CRED -- { -- CC_UCHAR kversion; -- CC_CHAR principal[ 41 ]; -- CC_CHAR principal_instance[ 41 ]; -- CC_CHAR service[ 41 ]; -- CC_CHAR service_instance[ 41 ]; -- CC_CHAR realm[ 41 ]; -- CC_UCHAR session_key[ 8 ]; -- CC_INT32 kvno; -- CC_INT32 str_to_key; -- CC_INT32 issue_date; -- CC_INT32 lifetime; -- CC_UINT32 address; -- CC_INT32 ticket_sz; -- CC_UCHAR ticket[ 1250 ]; -- } V4_CRED; -- - typedef struct _CC_DATA - { - CC_UINT32 type; -@@ -145,7 +126,6 @@ typedef struct _V5_CRED - - typedef /* [switch_type] */ union _CRED_PTR_UNION - { -- /* [case()] */ V4_CRED *pV4Cred; - /* [case()] */ V5_CRED *pV5Cred; - } CRED_PTR_UNION; - -diff --git a/src/ccapi/server/ccs_ccache.c b/src/ccapi/server/ccs_ccache.c -index 65c59e4be..645380a7b 100644 ---- a/src/ccapi/server/ccs_ccache.c -+++ b/src/ccapi/server/ccs_ccache.c -@@ -31,19 +31,16 @@ struct ccs_ccache_d { - ccs_lock_state_t lock_state; - cc_uint32 creds_version; - char *name; -- char *v4_principal; - char *v5_principal; - cc_time_t last_default_time; - cc_time_t last_changed_time; -- cc_uint32 kdc_time_offset_v4_valid; -- cc_time_t kdc_time_offset_v4; - cc_uint32 kdc_time_offset_v5_valid; - cc_time_t kdc_time_offset_v5; - ccs_credentials_list_t credentials; - ccs_callback_array_t change_callbacks; - }; - --struct ccs_ccache_d ccs_ccache_initializer = { NULL, NULL, 0, NULL, NULL, NULL, 0, 0, 0, 0, 0, 0, NULL, NULL }; -+struct ccs_ccache_d ccs_ccache_initializer = { NULL, NULL, 0, NULL, NULL, 0, 0, 0, 0, NULL, NULL }; - - /* ------------------------------------------------------------------------ */ - -@@ -88,11 +85,7 @@ cc_int32 ccs_ccache_new (ccs_ccache_t *out_ccache, - if (!err) { - ccache->creds_version = in_creds_version; - -- if (ccache->creds_version == cc_credentials_v4) { -- ccache->v4_principal = strdup (in_principal); -- if (!ccache->v4_principal) { err = cci_check_error (ccErrNoMem); } -- -- } else if (ccache->creds_version == cc_credentials_v5) { -+ if (ccache->creds_version == cc_credentials_v5) { - ccache->v5_principal = strdup (in_principal); - if (!ccache->v5_principal) { err = cci_check_error (ccErrNoMem); } - -@@ -147,7 +140,6 @@ cc_int32 ccs_ccache_reset (ccs_ccache_t io_ccache, - const char *in_principal) - { - cc_int32 err = ccNoError; -- char *v4_principal = NULL; - char *v5_principal = NULL; - ccs_credentials_list_t credentials = NULL; - -@@ -158,11 +150,7 @@ cc_int32 ccs_ccache_reset (ccs_ccache_t io_ccache, - if (!err) { - io_ccache->creds_version = in_creds_version; - -- if (io_ccache->creds_version == cc_credentials_v4) { -- v4_principal = strdup (in_principal); -- if (!v4_principal) { err = cci_check_error (ccErrNoMem); } -- -- } else if (io_ccache->creds_version == cc_credentials_v5) { -+ if (io_ccache->creds_version == cc_credentials_v5) { - v5_principal = strdup (in_principal); - if (!v5_principal) { err = cci_check_error (ccErrNoMem); } - -@@ -176,15 +164,9 @@ cc_int32 ccs_ccache_reset (ccs_ccache_t io_ccache, - } - - if (!err) { -- io_ccache->kdc_time_offset_v4 = 0; -- io_ccache->kdc_time_offset_v4_valid = 0; - io_ccache->kdc_time_offset_v5 = 0; - io_ccache->kdc_time_offset_v5_valid = 0; - -- if (io_ccache->v4_principal) { free (io_ccache->v4_principal); } -- io_ccache->v4_principal = v4_principal; -- v4_principal = NULL; /* take ownership */ -- - if (io_ccache->v5_principal) { free (io_ccache->v5_principal); } - io_ccache->v5_principal = v5_principal; - v5_principal = NULL; /* take ownership */ -@@ -196,7 +178,6 @@ cc_int32 ccs_ccache_reset (ccs_ccache_t io_ccache, - err = ccs_ccache_changed (io_ccache, io_cache_collection); - } - -- free (v4_principal); - free (v5_principal); - ccs_credentials_list_release (credentials); - -@@ -250,7 +231,6 @@ cc_int32 ccs_ccache_release (ccs_ccache_t io_ccache) - cci_identifier_release (io_ccache->identifier); - ccs_lock_state_release (io_ccache->lock_state); - free (io_ccache->name); -- free (io_ccache->v4_principal); - free (io_ccache->v5_principal); - ccs_credentials_list_release (io_ccache->credentials); - ccs_callback_array_release (io_ccache->change_callbacks); -@@ -607,15 +587,8 @@ static cc_int32 ccs_ccache_get_principal (ccs_ccache_t io_ccache, - err = krb5int_ipc_stream_read_uint32 (in_request_data, &version); - } - -- if (!err && version == cc_credentials_v4_v5) { -- err = cci_check_error (ccErrBadCredentialsVersion); -- } -- - if (!err) { -- if (version == cc_credentials_v4) { -- err = krb5int_ipc_stream_write_string (io_reply_data, io_ccache->v4_principal); -- -- } else if (version == cc_credentials_v5) { -+ if (version == cc_credentials_v5) { - err = krb5int_ipc_stream_write_string (io_reply_data, io_ccache->v5_principal); - - } else { -@@ -652,16 +625,7 @@ static cc_int32 ccs_ccache_set_principal (ccs_ccache_t io_ccache, - - if (!err) { - /* reset KDC time offsets because they are per-KDC */ -- if (version == cc_credentials_v4) { -- io_ccache->kdc_time_offset_v4 = 0; -- io_ccache->kdc_time_offset_v4_valid = 0; -- -- if (io_ccache->v4_principal) { free (io_ccache->v4_principal); } -- io_ccache->v4_principal = principal; -- principal = NULL; /* take ownership */ -- -- -- } else if (version == cc_credentials_v5) { -+ if (version == cc_credentials_v5) { - io_ccache->kdc_time_offset_v5 = 0; - io_ccache->kdc_time_offset_v5_valid = 0; - -@@ -998,14 +962,7 @@ static cc_int32 ccs_ccache_get_kdc_time_offset (ccs_ccache_t io_ccache - } - - if (!err) { -- if (cred_vers == cc_credentials_v4) { -- if (io_ccache->kdc_time_offset_v4_valid) { -- err = krb5int_ipc_stream_write_time (io_reply_data, io_ccache->kdc_time_offset_v4); -- } else { -- err = cci_check_error (ccErrTimeOffsetNotSet); -- } -- -- } else if (cred_vers == cc_credentials_v5) { -+ if (cred_vers == cc_credentials_v5) { - if (io_ccache->kdc_time_offset_v5_valid) { - err = krb5int_ipc_stream_write_time (io_reply_data, io_ccache->kdc_time_offset_v5); - } else { -@@ -1040,13 +997,7 @@ static cc_int32 ccs_ccache_set_kdc_time_offset (ccs_ccache_t io_ccache - } - - if (!err) { -- if (cred_vers == cc_credentials_v4) { -- err = krb5int_ipc_stream_read_time (in_request_data, &io_ccache->kdc_time_offset_v4); -- -- if (!err) { -- io_ccache->kdc_time_offset_v4_valid = 1; -- } -- } else if (cred_vers == cc_credentials_v5) { -+ if (cred_vers == cc_credentials_v5) { - err = krb5int_ipc_stream_read_time (in_request_data, &io_ccache->kdc_time_offset_v5); - - if (!err) { -@@ -1084,11 +1035,7 @@ static cc_int32 ccs_ccache_clear_kdc_time_offset (ccs_ccache_t io_ccac - } - - if (!err) { -- if (cred_vers == cc_credentials_v4) { -- io_ccache->kdc_time_offset_v4 = 0; -- io_ccache->kdc_time_offset_v4_valid = 0; -- -- } else if (cred_vers == cc_credentials_v5) { -+ if (cred_vers == cc_credentials_v5) { - io_ccache->kdc_time_offset_v5 = 0; - io_ccache->kdc_time_offset_v5_valid = 0; - -diff --git a/src/ccapi/test/test_ccapi_ccache.c b/src/ccapi/test/test_ccapi_ccache.c -index a0fd84af1..fe63e6710 100644 ---- a/src/ccapi/test/test_ccapi_ccache.c -+++ b/src/ccapi/test/test_ccapi_ccache.c -@@ -303,18 +303,6 @@ int check_cc_ccache_get_credentials_version(void) { - failure_count++; - } - -- // try it with added v4 creds -- if (!err) { -- err = cc_ccache_set_principal(ccache, cc_credentials_v4, "foo@BAR.ORG"); -- } -- if (!err) { -- check_once_cc_ccache_get_credentials_version(ccache, cc_credentials_v4_v5, ccNoError, "v5 with v4 creds added"); -- } -- else { -- log_error("cc_ccache_set_principal failed, can't complete test"); -- failure_count++; -- } -- - if (ccache) { - cc_ccache_destroy(ccache); - ccache = NULL; -@@ -322,35 +310,6 @@ int check_cc_ccache_get_credentials_version(void) { - - err = ccNoError; - -- // try one created with v4 creds -- if (!err) { -- err = cc_context_create_new_ccache(context, cc_credentials_v4, "foo@BAR.ORG", &ccache); -- } -- if (!err) { -- check_once_cc_ccache_get_credentials_version(ccache, cc_credentials_v4, ccNoError, "v4 creds"); -- } -- else { -- log_error("cc_context_create_new_ccache failed, can't complete test"); -- failure_count++; -- } -- -- // try it with added v5 creds -- if (!err) { -- err = cc_ccache_set_principal(ccache, cc_credentials_v5, "foo@BAR.ORG"); -- } -- if (!err) { -- check_once_cc_ccache_get_credentials_version(ccache, cc_credentials_v4_v5, ccNoError, "v4 with v5 creds added"); -- } -- else { -- log_error("cc_ccache_set_principal failed, can't complete test"); -- failure_count++; -- } -- -- if (ccache) { -- cc_ccache_destroy(ccache); -- ccache = NULL; -- } -- - if (context) { cc_context_release(context); } - - #endif /* cc_ccache_get_credentials_version */ -@@ -582,31 +541,13 @@ int check_cc_ccache_get_principal(void) { - log_error("cc_context_create_new_ccache failed, can't complete test"); - failure_count++; - } -- if (ccache) { -- cc_ccache_release(ccache); -- ccache = NULL; -- } - -- // try with krb4 principal -- if (!err) { -- err = cc_context_create_new_ccache(context, cc_credentials_v4, "foo.BAR@BAZ.ORG", &ccache); -- } -- if (!err) { -- check_once_cc_ccache_get_principal(ccache, cc_credentials_v4, "foo.BAR@BAZ.ORG", ccNoError, "trying to get krb4 princ for krb4 ccache"); -- } -- else { -- log_error("cc_context_create_new_ccache failed, can't complete test"); -- failure_count++; -- } -- -- // try with bad param -- if (!err) { -- // cc_ccache_t doesn't have any concept of the difference between a v4 and v5 principal -- check_once_cc_ccache_get_principal(ccache, cc_credentials_v4_v5, "foo.BAR@BAZ.ORG", -- ccErrBadCredentialsVersion, -- "passing cc_credentials_v4_v5 (shouldn't be allowed)"); -- check_once_cc_ccache_get_principal(ccache, cc_credentials_v5, NULL, ccErrBadParam, "passed null out param"); -- } -+ // try with bad param -+ if (!err) { -+ check_once_cc_ccache_get_principal(ccache, cc_credentials_v5, -+ NULL, ccErrBadParam, -+ "passed null out param"); -+ } - - if (ccache) { - cc_ccache_release(ccache); -@@ -643,99 +584,33 @@ int check_cc_ccache_set_principal(void) { - err = destroy_all_ccaches(context); - } - -- // bad params -- if (!err) { -- err = cc_context_create_new_ccache(context, cc_credentials_v5, "foo@BAZ.ORG", &ccache); -- } -- if (!err) { -- check_once_cc_ccache_set_principal(ccache, cc_credentials_v4_v5, "foo/BAZ@BAR.ORG", ccErrBadCredentialsVersion, "cc_credentials_v4_v5 (not allowed)"); -- check_once_cc_ccache_set_principal(ccache, cc_credentials_v5, NULL, ccErrBadParam, "NULL principal"); -- } -- else { -- log_error("cc_context_create_new_ccache failed, can't complete test"); -- failure_count++; -- } -- if (ccache) { -- cc_ccache_destroy(ccache); -- ccache = NULL; -- } -+ // replace v5 only ccache's principal -+ if (!err) { -+ err = cc_context_create_new_ccache(context, cc_credentials_v5, -+ "foo@BAZ.ORG", &ccache); -+ } -+ if (!err) { -+ check_once_cc_ccache_set_principal( -+ ccache, cc_credentials_v5, "foo/BAZ@BAR.ORG", ccNoError, -+ "replace v5 only ccache's principal (empty ccache)"); -+ } -+ else { -+ log_error( -+ "cc_context_create_new_ccache failed, can't complete test"); -+ failure_count++; -+ } - -+ // bad params -+ if (!err) { -+ check_once_cc_ccache_set_principal(ccache, cc_credentials_v5, -+ NULL, ccErrBadParam, -+ "NULL principal"); -+ } - -- // empty ccache -- -- // replace v5 only ccache's principal -- if (!err) { -- err = cc_context_create_new_ccache(context, cc_credentials_v5, "foo@BAZ.ORG", &ccache); -- } -- if (!err) { -- check_once_cc_ccache_set_principal(ccache, cc_credentials_v5, "foo/BAZ@BAR.ORG", ccNoError, "replace v5 only ccache's principal (empty ccache)"); -- } -- else { -- log_error("cc_context_create_new_ccache failed, can't complete test"); -- failure_count++; -- } -- if (ccache) { -- cc_ccache_destroy(ccache); -- ccache = NULL; -- } -- -- // add v4 principal to v5 only ccache -- if (!err) { -- err = cc_context_create_new_ccache(context, cc_credentials_v5, "foo@BAZ.ORG", &ccache); -- } -- if (!err) { -- check_once_cc_ccache_set_principal(ccache, cc_credentials_v4, "foo.BAZ@BAR.ORG", ccNoError, "add v4 principal to v5 only ccache (empty ccache)"); -- } -- else { -- log_error("cc_context_create_new_ccache failed, can't complete test"); -- failure_count++; -- } -- if (ccache) { -- cc_ccache_destroy(ccache); -- ccache = NULL; -- } -- -- // replace v4 only ccache's principal -- if (!err) { -- err = cc_context_create_new_ccache(context, cc_credentials_v4, "foo@BAZ.ORG", &ccache); -- } -- if (!err) { -- check_once_cc_ccache_set_principal(ccache, cc_credentials_v4, "foo.BAZ@BAR.ORG", ccNoError, "replace v4 only ccache's principal (empty ccache)"); -- } -- else { -- log_error("cc_context_create_new_ccache failed, can't complete test"); -- failure_count++; -- } -- if (ccache) { -- cc_ccache_destroy(ccache); -- ccache = NULL; -- } -- -- // add v5 principal to v4 only ccache -- if (!err) { -- err = cc_context_create_new_ccache(context, cc_credentials_v4, "foo@BAZ.ORG", &ccache); -- } -- if (!err) { -- check_once_cc_ccache_set_principal(ccache, cc_credentials_v5, "foo/BAZ@BAR.ORG", ccNoError, "add v5 principal to v4 only ccache (empty ccache)"); -- } -- else { -- log_error("cc_context_create_new_ccache failed, can't complete test"); -- failure_count++; -- } -- if (ccache) { -- cc_ccache_destroy(ccache); -- ccache = NULL; -- } -- -- // with credentials -- -- // replace v5 only ccache's principal -- -- // add v4 principal to v5 only ccache -- -- // replace v4 only ccache's principal -- -- // add v5 principal to v4 only ccache -+ if (ccache) { -+ cc_ccache_destroy(ccache); -+ ccache = NULL; -+ } - - if (context) { - err = destroy_all_ccaches(context); -@@ -847,21 +722,6 @@ int check_cc_ccache_store_credentials(void) { - - if (&creds_union) { release_v5_creds_union(&creds_union); } - -- // bad creds version -- if (!err) { -- err = new_v5_creds_union(&creds_union, "BAR.ORG"); -- } -- -- if (!err) { -- creds_union.version = cc_credentials_v4_v5; -- check_once_cc_ccache_store_credentials(ccache, &creds_union, ccErrBadCredentialsVersion, "v4_v5 creds (invalid) into a ccache with only v5 princ"); -- creds_union.version = cc_credentials_v4; -- check_once_cc_ccache_store_credentials(ccache, &creds_union, ccErrBadCredentialsVersion, "v4 creds into a ccache with only v5 princ"); -- creds_union.version = cc_credentials_v5; -- } -- -- if (&creds_union) { release_v5_creds_union(&creds_union); } -- - // non-existent ccache - if (ccache) { - err = cc_ccache_get_name(ccache, &name); -@@ -1809,21 +1669,10 @@ int check_cc_ccache_get_kdc_time_offset(void) { - err = cc_ccache_set_kdc_time_offset(ccache, cc_credentials_v5, time_offset); - } - if (!err) { -- check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v5, &time_offset, ccNoError, "offset set for v5 but not v4"); -+ check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v5, &time_offset, ccNoError, "offset set for v5"); - } -- if (!err) { -- check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v4, &time_offset, ccErrTimeOffsetNotSet, "asking for v4 offset when only v5 is set"); -- } -- if (!err) { -- err = cc_ccache_set_kdc_time_offset(ccache, cc_credentials_v4, time_offset); -- } -- if (!err) { -- check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v4, &time_offset, ccNoError, "asking for v4 offset when v4 and v5 are set"); -- } -- - - check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v5, NULL, ccErrBadParam, "NULL time_offset out param"); -- check_once_cc_ccache_get_kdc_time_offset(ccache, cc_credentials_v4_v5, &time_offset, ccErrBadCredentialsVersion, "v4_v5 creds_vers in param (invalid)"); - - if (ccache) { cc_ccache_release(ccache); } - -@@ -1900,9 +1749,6 @@ int check_cc_ccache_set_kdc_time_offset(void) { - } - - check_once_cc_ccache_set_kdc_time_offset(ccache, cc_credentials_v5, 0, ccNoError, "first time setting offset (v5)"); -- check_once_cc_ccache_set_kdc_time_offset(ccache, cc_credentials_v4, 0, ccNoError, "first time setting offset (v4)"); -- -- check_once_cc_ccache_set_kdc_time_offset(ccache, cc_credentials_v4_v5, 0, ccErrBadCredentialsVersion, "invalid creds_vers (v4_v5)"); - - if (ccache) { cc_ccache_release(ccache); } - -@@ -1978,15 +1824,10 @@ int check_cc_ccache_clear_kdc_time_offset(void) { - } - - check_once_cc_ccache_clear_kdc_time_offset(ccache, cc_credentials_v5, ccNoError, "clearing an offset that was never set (v5)"); -- check_once_cc_ccache_clear_kdc_time_offset(ccache, cc_credentials_v4, ccNoError, "clearing an offset that was never set (v4)"); - - err = cc_ccache_set_kdc_time_offset(ccache, cc_credentials_v5, 0); -- err = cc_ccache_set_kdc_time_offset(ccache, cc_credentials_v4, 0); - - check_once_cc_ccache_clear_kdc_time_offset(ccache, cc_credentials_v5, ccNoError, "clearing v5"); -- check_once_cc_ccache_clear_kdc_time_offset(ccache, cc_credentials_v4, ccNoError, "clearing v4"); -- -- check_once_cc_ccache_clear_kdc_time_offset(ccache, cc_credentials_v4_v5, ccErrBadCredentialsVersion, "bad in param creds vers (v4_v5)"); - - if (ccache) { cc_ccache_release(ccache); } - -diff --git a/src/ccapi/test/test_ccapi_constants.c b/src/ccapi/test/test_ccapi_constants.c -index 9f2aecbc2..57377262e 100644 ---- a/src/ccapi/test/test_ccapi_constants.c -+++ b/src/ccapi/test/test_ccapi_constants.c -@@ -46,9 +46,7 @@ int check_constants(void) { - - /* Credentials versions */ - -- check_int(cc_credentials_v4, 1); - check_int(cc_credentials_v5, 2); -- check_int(cc_credentials_v4_v5, (cc_credentials_v4 | cc_credentials_v5)); - - /* Lock types */ - -diff --git a/src/ccapi/test/test_ccapi_context.c b/src/ccapi/test/test_ccapi_context.c -index 09feebee5..2dc348ea0 100644 ---- a/src/ccapi/test/test_ccapi_context.c -+++ b/src/ccapi/test/test_ccapi_context.c -@@ -583,7 +583,6 @@ int check_cc_context_create_ccache(void) { - - // try bad parameters - err = check_once_cc_context_create_ccache(context, NULL, cc_credentials_v5, "foo@BAR.ORG", &ccache, ccErrBadParam, "NULL name"); // NULL name -- err = check_once_cc_context_create_ccache(context, "name", cc_credentials_v4_v5, "foo@BAR.ORG", &ccache, ccErrBadCredentialsVersion, "invalid creds_vers"); // invalid creds_vers - err = check_once_cc_context_create_ccache(context, "name", cc_credentials_v5, NULL, &ccache, ccErrBadParam, "NULL principal"); // NULL principal - err = check_once_cc_context_create_ccache(context, "name", cc_credentials_v5, "foo@BAR.ORG", NULL, ccErrBadParam, "NULL ccache"); // NULL ccache - } -@@ -681,7 +680,6 @@ int check_cc_context_create_default_ccache(void) { - } - - // try bad parameters -- err = check_once_cc_context_create_default_ccache(context, cc_credentials_v4_v5, "foo@BAR.ORG", &ccache, ccErrBadCredentialsVersion, "invalid creds_vers"); // invalid creds_vers - err = check_once_cc_context_create_default_ccache(context, cc_credentials_v5, NULL, &ccache, ccErrBadParam, "NULL principal"); // NULL principal - err = check_once_cc_context_create_default_ccache(context, cc_credentials_v5, "foo@BAR.ORG", NULL, ccErrBadParam, "NULL ccache"); // NULL ccache - } -@@ -773,7 +771,6 @@ int check_cc_context_create_new_ccache(void) { - if (ccache) { cc_ccache_release(ccache); } - - // try bad parameters -- err = check_once_cc_context_create_new_ccache(context, 1, cc_credentials_v4_v5, "foo@BAR.ORG", &ccache, ccErrBadCredentialsVersion, "invalid creds_vers"); // invalid creds_vers - err = check_once_cc_context_create_new_ccache(context, 1, cc_credentials_v5, NULL, &ccache, ccErrBadParam, "NULL principal"); // NULL principal - err = check_once_cc_context_create_new_ccache(context, 1, cc_credentials_v5, "foo@BAR.ORG", NULL, ccErrBadParam, "NULL ccache"); // NULL ccache - } -diff --git a/src/ccapi/test/test_ccapi_v2.c b/src/ccapi/test/test_ccapi_v2.c -index e0205ce46..c71bb45a8 100644 ---- a/src/ccapi/test/test_ccapi_v2.c -+++ b/src/ccapi/test/test_ccapi_v2.c -@@ -45,20 +45,6 @@ static int compare_v5_creds_unions_compat(const cred_union *a, const cred_union - a->cred.pV5Cred->starttime == b->cred.pV5Cred->starttime) { - retval = 0; - } -- } else if (a->cred_type == CC_CRED_V4) { -- if (!strcmp (a->cred.pV4Cred->principal, -- b->cred.pV4Cred->principal) && -- !strcmp (a->cred.pV4Cred->principal_instance, -- b->cred.pV4Cred->principal_instance) && -- !strcmp (a->cred.pV4Cred->service, -- b->cred.pV4Cred->service) && -- !strcmp (a->cred.pV4Cred->service_instance, -- b->cred.pV4Cred->service_instance) && -- !strcmp (a->cred.pV4Cred->realm, -- b->cred.pV4Cred->realm) && -- a->cred.pV4Cred->issue_date == b->cred.pV4Cred->issue_date) { -- retval = 0; -- } - } - } - -@@ -361,10 +347,6 @@ int check_cc_open(void) { - err = check_once_cc_open(context, name, CC_CRED_V5, &ccache, CC_NOERROR, NULL); - } - -- // check version -- if (!err) { -- err = check_once_cc_open(context, name, CC_CRED_V4, &ccache, CC_ERR_CRED_VERSION, NULL); -- } - // try bad parameters - err = check_once_cc_open(context, NULL, CC_CRED_V5, &ccache, CC_BAD_PARM, NULL); - err = check_once_cc_open(context, name, CC_CRED_V5, NULL, CC_BAD_PARM, NULL); -@@ -681,17 +663,6 @@ int check_cc_get_cred_version(void) { - - err = CC_NOERROR; - -- // try one created with v4 creds -- if (!err) { -- err = cc_create(context, name, "foo@BAR.ORG", CC_CRED_V4, 0, &ccache); -- } -- if (!err) { -- check_once_cc_get_cred_version(context, ccache, CC_CRED_V4, CC_NOERROR, "v4 creds"); -- } -- else { -- log_error("cc_context_create_new_ccache failed, can't complete test"); -- failure_count++; -- } - if (ccache) { - cc_destroy(context, &ccache); - ccache = NULL; -@@ -840,7 +811,6 @@ int check_cc_get_principal(void) { - apiCB *context = NULL; - ccache_p *ccache = NULL; - char *name_v5 = "TEST_CC_GET_PRINCIPAL_V5"; -- char *name_v4 = "TEST_CC_GET_PRINCIPAL_V4"; - - BEGIN_TEST("cc_get_principal"); - -@@ -866,18 +836,6 @@ int check_cc_get_principal(void) { - ccache = NULL; - } - -- // try with krb4 principal -- if (!err) { -- err = cc_create(context, name_v4, "foo.BAR@BAZ.ORG", CC_CRED_V4, 0, &ccache); -- } -- if (!err) { -- check_once_cc_get_principal(context, ccache, "foo.BAR@BAZ.ORG", CC_NOERROR, "trying to get krb4 princ for krb4 ccache"); -- } -- else { -- log_error("cc_create failed, can't complete test"); -- failure_count++; -- } -- - // try with bad param - if (!err) { - check_once_cc_get_principal(context, ccache, NULL, CC_BAD_PARM, "passed null out param"); -@@ -945,7 +903,6 @@ int check_cc_set_principal(void) { - apiCB *context = NULL; - ccache_p *ccache = NULL; - char *name_v5 = "TEST_CC_GET_PRINCIPAL_V5"; -- char *name_v4 = "TEST_CC_GET_PRINCIPAL_V4"; - - BEGIN_TEST("cc_set_principal"); - -@@ -972,37 +929,6 @@ int check_cc_set_principal(void) { - ccache = NULL; - } - -- // empty ccache -- -- // replace v5 ccache's principal -- if (!err) { -- err = cc_create(context, name_v5, "foo@BAZ.ORG", CC_CRED_V5, 0, &ccache); -- } -- if (!err) { -- check_once_cc_set_principal(context, ccache, CC_CRED_V5, "foo/BAZ@BAR.ORG", CC_NOERROR, "replace v5 only ccache's principal (empty ccache)"); -- check_once_cc_set_principal(context, ccache, CC_CRED_V4, "foo.BAZ@BAR.ORG", CC_ERR_CRED_VERSION, "replace v5 principal with v4"); -- } -- else { -- log_error("cc_create failed, can't complete test"); -- failure_count++; -- } -- if (ccache) { -- cc_destroy(context, &ccache); -- ccache = NULL; -- } -- -- // replace v4 ccache's principal -- if (!err) { -- err = cc_create(context, name_v4, "foo@BAZ.ORG", CC_CRED_V4, 0, &ccache); -- } -- if (!err) { -- check_once_cc_set_principal(context, ccache, CC_CRED_V4, "foo.BAZ@BAR.ORG", CC_NOERROR, "replace v4 only ccache's principal (empty ccache)"); -- check_once_cc_set_principal(context, ccache, CC_CRED_V5, "foo/BAZ@BAR.ORG", CC_ERR_CRED_VERSION, "replace v4 principal with v5"); -- } -- else { -- log_error("cc_create failed, can't complete test"); -- failure_count++; -- } - if (ccache) { - cc_destroy(context, &ccache); - ccache = NULL; -@@ -1102,21 +1028,6 @@ int check_cc_store(void) { - } - } - -- // bad creds version -- if (!err) { -- err = new_v5_creds_union_compat(&creds_union, "BAR.ORG"); -- -- if (!err) { -- creds_union.cred_type = CC_CRED_MAX; -- check_once_cc_store(context, ccache, creds_union, CC_ERR_CRED_VERSION, "CC_CRED_MAX (invalid) into a ccache with only v5 princ"); -- creds_union.cred_type = CC_CRED_V4; -- check_once_cc_store(context, ccache, creds_union, CC_ERR_CRED_VERSION, "v4 creds into a v5 ccache"); -- creds_union.cred_type = CC_CRED_V5; -- -- release_v5_creds_union_compat(&creds_union); -- } -- } -- - // non-existent ccache - if (ccache) { - err = cc_get_name(context, ccache, &name); -diff --git a/src/include/CredentialsCache.h b/src/include/CredentialsCache.h -index 54f71a1a0..c18159639 100644 ---- a/src/include/CredentialsCache.h -+++ b/src/include/CredentialsCache.h -@@ -104,19 +104,19 @@ extern "C" { - * \section introduction Introduction - * - * This is the specification for an API which provides Credentials Cache -- * services for both Kerberos v5 and v4. The idea behind this API is that -- * multiple Kerberos implementations can share a single collection of -- * credentials caches, mediated by this API specification. On the Mac OS -- * and Microsoft Windows platforms this will allow single-login, even when -- * more than one Kerberos shared library is in use on a particular system. -+ * services for Kerberos v5 (and previously v4). The idea behind this API is -+ * that multiple Kerberos implementations can share a single collection of -+ * credentials caches, mediated by this API specification. On the Mac OS and -+ * Microsoft Windows platforms this will allow single-login, even when more -+ * than one Kerberos shared library is in use on a particular system. - * - * Abstractly, a credentials cache collection contains one or more credentials - * caches, or ccaches. A ccache is uniquely identified by its name, which is - * a string internal to the API and not intended to be presented to users. - * The user presentable identifier of a ccache is its principal. - * -- * Unlike the previous versions of the API, version 3 of the API stores both -- * Kerberos v4 and v5 credentials in the same ccache. -+ * Unlike the previous versions of the API, version 3 of the API could store -+ * credentials for multiple Kerberos versions in the same ccache. - * - * At any given time, one ccache is the "default" ccache. The exact meaning - * of a default ccache is OS-specific; refer to implementation requirements -@@ -305,10 +305,9 @@ enum { - /*! - * Credentials versions - * -- * These constants are used in several places in the API to discern -- * between Kerberos v4 and Kerberos v5. Not all values are valid -- * inputs and outputs for all functions; function specifications -- * below detail the allowed values. -+ * These constants are used in several places in the API to discern Kerberos -+ * versions. Not all values are valid inputs and outputs for all functions; -+ * function specifications below detail the allowed values. - * - * Kerberos version constants will always be a bit-field, and can be - * tested as such; for example the following test will tell you if -@@ -317,9 +316,9 @@ enum { - * if ((ccacheVersion & cc_credentials_v5) != 0) - */ - enum cc_credential_versions { -- cc_credentials_v4 = 1, -+ /* cc_credentials_v4 = 1, */ - cc_credentials_v5 = 2, -- cc_credentials_v4_v5 = 3 -+ /* cc_credentials_v4_v5 = 3 */ - }; - - /*! -@@ -353,29 +352,6 @@ enum cc_lock_modes { - cc_lock_block = 1 - }; - --/*! -- * Sizes of fields in cc_credentials_v4_t. -- */ --enum { -- /* Make sure all of these are multiples of four (for alignment sanity) */ -- cc_v4_name_size = 40, -- cc_v4_instance_size = 40, -- cc_v4_realm_size = 40, -- cc_v4_ticket_size = 1254, -- cc_v4_key_size = 8 --}; -- --/*! -- * String to key type (Kerberos v4 only) -- */ --enum cc_string_to_key_type { -- cc_v4_stk_afs = 0, -- cc_v4_stk_des = 1, -- cc_v4_stk_columbia_special = 2, -- cc_v4_stk_krb5 = 3, -- cc_v4_stk_unknown = 4 --}; -- - /*!@}*/ - - /*! -@@ -482,15 +458,13 @@ typedef cc_ccache_iterator_d *cc_ccache_iterator_t; - * \defgroup cc_credentials_reference cc_credentials_t Overview - * @{ - * -- * The cc_credentials_t type is used to store a single set of -- * credentials for either Kerberos v4 or Kerberos v5. In addition -- * to its only function, release(), it contains a pointer to a -- * cc_credentials_union structure. A cc_credentials_union -+ * The cc_credentials_t type is used to store a single set of credentials for -+ * Kerberos v5. In addition to its only function, release(), it contains a -+ * pointer to a cc_credentials_union structure. A cc_credentials_union - * structure contains an integer of the enumerator type -- * cc_credentials_version, which is either #cc_credentials_v4 or -- * #cc_credentials_v5, and a pointer union, which contains either a -- * cc_credentials_v4_t pointer or a cc_credentials_v5_t pointer, -- * depending on the value in version. -+ * cc_credentials_version, which is #cc_credentials_v5, and a pointer union, -+ * which contains a cc_credentials_v5_t pointer, depending on the value in -+ * version. - * - * Variables of the type cc_credentials_t are allocated by the CCAPI - * implementation, and should be released with their release() -@@ -501,43 +475,6 @@ typedef cc_ccache_iterator_d *cc_ccache_iterator_t; - * For API functions see \ref cc_credentials_f. - */ - --/*! -- * If a cc_credentials_t variable is used to store Kerberos v4 -- * credentials, then credentials.credentials_v4 points to a v4 -- * credentials structure. This structure is similar to a -- * krb4 API CREDENTIALS structure. -- */ --struct cc_credentials_v4_t { -- cc_uint32 version; -- /*! A properly quoted string representation of the first component of the client principal */ -- char principal [cc_v4_name_size]; -- /*! A properly quoted string representation of the second component of the client principal */ -- char principal_instance [cc_v4_instance_size]; -- /*! A properly quoted string representation of the first component of the service principal */ -- char service [cc_v4_name_size]; -- /*! A properly quoted string representation of the second component of the service principal */ -- char service_instance [cc_v4_instance_size]; -- /*! A properly quoted string representation of the realm */ -- char realm [cc_v4_realm_size]; -- /*! Ticket session key */ -- unsigned char session_key [cc_v4_key_size]; -- /*! Key version number */ -- cc_int32 kvno; -- /*! String to key type used. See cc_string_to_key_type for valid values */ -- cc_int32 string_to_key_type; -- /*! Time when the ticket was issued */ -- cc_time_t issue_date; -- /*! Ticket lifetime in 5 minute units */ -- cc_int32 lifetime; -- /*! IPv4 address of the client the ticket was issued for */ -- cc_uint32 address; -- /*! Ticket size (no greater than cc_v4_ticket_size) */ -- cc_int32 ticket_size; -- /*! Ticket data */ -- unsigned char ticket [cc_v4_ticket_size]; --}; --typedef struct cc_credentials_v4_t cc_credentials_v4_t; -- - /*! - * The CCAPI data structure. This structure is similar to a krb5_data structure. - * In a v5 credentials structure, cc_data structures are used -@@ -602,8 +539,6 @@ struct cc_credentials_union { - cc_uint32 version; - /*! The credentials. */ - union { -- /*! If \a version is #cc_credentials_v4, a pointer to a cc_credentials_v4_t. */ -- cc_credentials_v4_t* credentials_v4; - /*! If \a version is #cc_credentials_v5, a pointer to a cc_credentials_v5_t. */ - cc_credentials_v5_t* credentials_v5; - } credentials; -@@ -781,13 +716,11 @@ struct cc_context_f { - * \return On success, #ccNoError. On failure, an error code representing the failure. - * \brief \b cc_context_create_ccache(): Create a new ccache. - * -- * Create a new credentials cache. The ccache is uniquely identified by its name. -- * The principal given is also associated with the ccache and the credentials -- * version specified. A NULL name is not allowed (and ccErrBadName is returned -- * if one is passed in). Only cc_credentials_v4 and cc_credentials_v5 are valid -- * input values for cred_vers. If you want to create a new ccache that will hold -- * both versions of credentials, call cc_context_create_ccache() with one version, -- * and then cc_ccache_set_principal() with the other version. -+ * Create a new credentials cache. The ccache is uniquely identified by -+ * its name. The principal given is also associated with the ccache and -+ * the credentials version specified. A NULL name is not allowed (and -+ * ccErrBadName is returned if one is passed in). Only cc_credentials_v5 -+ * can be an input value for cred_vers. - * - * If you want to create a new ccache (with a unique name), you should use - * cc_context_create_new_ccache() instead. If you want to create or reinitialize -@@ -814,10 +747,9 @@ struct cc_context_f { - * cc_context_get_default_ccache_name()); see the description of - * cc_context_get_default_ccache_name() for details. - * -- * The principal should be a C string containing an unparsed Kerberos principal -- * in the format of the appropriate Kerberos version, i.e. \verbatim foo.bar/@BAZ -- * \endverbatim for Kerberos v4 and \verbatim foo/bar/@BAZ \endverbatim -- * for Kerberos v5. -+ * The principal should be a C string containing an unparsed Kerberos -+ * principal in the format of the appropriate Kerberos version, -+ * i.e. \verbatim foo/bar/@BAZ \endverbatim for Kerberos v5. - */ - cc_int32 (*create_ccache) (cc_context_t in_context, - const char *in_name, -@@ -1014,14 +946,11 @@ struct cc_ccache_f { - * \return On success, #ccNoError. On failure, an error code representing the failure. - * \brief \b cc_ccache_get_credentials_version(): Get the credentials version of a ccache. - * -- * cc_ccache_get_credentials_version() returns one value of the enumerated type -- * cc_credentials_vers. The possible return values are #cc_credentials_v4 -- * (if ccache's v4 principal has been set), #cc_credentials_v5 -- * (if ccache's v5 principal has been set), or #cc_credentials_v4_v5 -- * (if both ccache's v4 and v5 principals have been set). A ccache's -- * principal is set with one of cc_context_create_ccache(), -- * cc_context_create_new_ccache(), cc_context_create_default_ccache(), or -- * cc_ccache_set_principal(). -+ * cc_ccache_get_credentials_version() returns one value of the enumerated -+ * type cc_credentials_vers. The return value is #cc_credentials_v5 (if -+ * ccache's v5 principal has been set). A ccache's principal is set with -+ * one of cc_context_create_ccache(), cc_context_create_new_ccache(), -+ * cc_context_create_default_ccache(), or cc_ccache_set_principal(). - */ - cc_int32 (*get_credentials_version) (cc_ccache_t in_ccache, - cc_uint32 *out_credentials_version); -@@ -1046,10 +975,7 @@ struct cc_ccache_f { - * - * Return the principal for the ccache that was set via cc_context_create_ccache(), - * cc_context_create_default_ccache(), cc_context_create_new_ccache(), or -- * cc_ccache_set_principal(). Principals for v4 and v5 are separate, but -- * should be kept synchronized for each ccache; they can be retrieved by -- * passing cc_credentials_v4 or cc_credentials_v5 in cred_vers. Passing -- * cc_credentials_v4_v5 will result in the error ccErrBadCredentialsVersion. -+ * cc_ccache_set_principal(). - */ - cc_int32 (*get_principal) (cc_ccache_t in_ccache, - cc_uint32 in_credentials_version, -@@ -1063,10 +989,7 @@ struct cc_ccache_f { - * \return On success, #ccNoError. On failure, an error code representing the failure. - * \brief \b cc_ccache_set_principal(): Set the principal of a ccache. - * -- * Set the a principal for ccache. The v4 and v5 principals can be set -- * independently, but they should always be kept equal, up to differences in -- * string representation between v4 and v5. Passing cc_credentials_v4_v5 in -- * cred_vers will result in the error ccErrBadCredentialsVersion. -+ * Set the a principal for ccache. - */ - cc_int32 (*set_principal) (cc_ccache_t io_ccache, - cc_uint32 in_credentials_version, -@@ -1083,12 +1006,13 @@ struct cc_ccache_f { - * See the description of the credentials types for the meaning of - * cc_credentials_union fields. - * -- * Before credentials of a specific credential type can be stored in a ccache, -- * the corresponding principal version has to be set. For example, before you can -- * store Kerberos v4 credentials in a ccache, the Kerberos v4 principal has to be set -- * either by cc_context_create_ccache(), cc_context_create_default_ccache(), -- * cc_context_create_new_ccache(), or cc_ccache_set_principal(); likewise for -- * Kerberos v5. Otherwise, ccErrBadCredentialsVersion is returned. -+ * Before credentials of a specific credential type can be stored in a -+ * ccache, the corresponding principal version has to be set. That is, -+ * before you can store Kerberos v5 credentials in a ccache, the Kerberos -+ * v5 principal has to be set either by cc_context_create_ccache(), -+ * cc_context_create_default_ccache(), cc_context_create_new_ccache(), or -+ * cc_ccache_set_principal(); otherwise, ccErrBadCredentialsVersion is -+ * returned. - */ - cc_int32 (*store_credentials) (cc_ccache_t io_ccache, - const cc_credentials_union *in_credentials_union); -diff --git a/src/include/CredentialsCache2.h b/src/include/CredentialsCache2.h -index b3b48996d..9e5a346ac 100644 ---- a/src/include/CredentialsCache2.h -+++ b/src/include/CredentialsCache2.h -@@ -85,36 +85,13 @@ typedef struct cc_credentials_v5_compat { - cc_data_compat** authdata; - } cc_credentials_v5_compat; - --enum { -- MAX_V4_CRED_LEN = 1250 --}; -- - enum { - KRB_NAME_SZ = 40, - KRB_INSTANCE_SZ = 40, - KRB_REALM_SZ = 40 - }; - --typedef struct cc_credentials_v4_compat { -- unsigned char kversion; -- char principal[KRB_NAME_SZ+1]; -- char principal_instance[KRB_INSTANCE_SZ+1]; -- char service[KRB_NAME_SZ+1]; -- char service_instance[KRB_INSTANCE_SZ+1]; -- char realm[KRB_REALM_SZ+1]; -- unsigned char session_key[8]; -- cc_int32 kvno; -- cc_int32 str_to_key; -- long issue_date; -- cc_int32 lifetime; -- cc_uint32 address; -- cc_int32 ticket_sz; -- unsigned char ticket[MAX_V4_CRED_LEN]; -- unsigned long oops; --} cc_credentials_v4_compat; -- - typedef union cred_ptr_union_compat { -- cc_credentials_v4_compat* pV4Cred; - cc_credentials_v5_compat* pV5Cred; - } cred_ptr_union_compat; - -@@ -135,7 +112,6 @@ typedef struct infoNC infoNC; - - /* Some old type names */ - --typedef cc_credentials_v4_compat V4Cred_type; - typedef cc_credentials_v5_compat cc_creds; - struct ccache_cit; - typedef struct ccache_cit ccache_cit; -@@ -166,7 +142,7 @@ enum { - - enum { - CC_CRED_UNKNOWN, -- CC_CRED_V4, -+ /* CC_CRED_V4, */ - CC_CRED_V5, - CC_CRED_MAX - }; -diff --git a/src/lib/krb5/ccache/ccapi/stdcc.c b/src/lib/krb5/ccache/ccapi/stdcc.c -index db69eebb4..cac61e45c 100644 ---- a/src/lib/krb5/ccache/ccapi/stdcc.c -+++ b/src/lib/krb5/ccache/ccapi/stdcc.c -@@ -589,7 +589,6 @@ krb5_stdccv3_next_cred (krb5_context context, - err = stdccv3_setup (context, ccapi_data); - } - -- /* Note: CCAPI v3 ccaches can contain both v4 and v5 creds */ - while (!err) { - err = cc_credentials_iterator_next (iterator, &credentials); - -@@ -836,7 +835,6 @@ krb5_stdccv3_remove (krb5_context context, - &iterator); - } - -- /* Note: CCAPI v3 ccaches can contain both v4 and v5 creds */ - while (!err && !found) { - cc_credentials_t credentials = NULL; - -diff --git a/src/lib/krb5/ccache/ccapi/stdcc_util.c b/src/lib/krb5/ccache/ccapi/stdcc_util.c -index 62d847c18..1f2a3865c 100644 ---- a/src/lib/krb5/ccache/ccapi/stdcc_util.c -+++ b/src/lib/krb5/ccache/ccapi/stdcc_util.c -@@ -521,9 +521,6 @@ cred_union_release (cc_credentials_union *in_cred_union) - - free (cv5); - -- } else if (in_cred_union->version == cc_credentials_v4 && -- in_cred_union->credentials.credentials_v4) { -- free (in_cred_union->credentials.credentials_v4); - } - free ((cc_credentials_union *) in_cred_union); - } -@@ -892,10 +889,7 @@ static void deep_free_cc_v5_creds (cc_creds* creds) - - static void deep_free_cc_creds (cred_union creds) - { -- if (creds.cred_type == CC_CRED_V4) { -- /* we shouldn't get this, of course */ -- free (creds.cred.pV4Cred); -- } else if (creds.cred_type == CC_CRED_V5) { -+ if (creds.cred_type == CC_CRED_V5) { - deep_free_cc_v5_creds (creds.cred.pV5Cred); - } - } -diff --git a/src/windows/kfwlogon/kfwlogon.h b/src/windows/kfwlogon/kfwlogon.h -index b2674573e..622d5665c 100644 ---- a/src/windows/kfwlogon/kfwlogon.h -+++ b/src/windows/kfwlogon/kfwlogon.h -@@ -94,7 +94,7 @@ typedef int cc_int32; - - enum { - CC_CRED_VUNKNOWN = 0, // For validation -- CC_CRED_V4 = 1, -+ /* CC_CRED_V4 = 1, */ - CC_CRED_V5 = 2, - CC_CRED_VMAX = 3 // For validation - }; -diff --git a/src/windows/leashdll/leash-int.h b/src/windows/leashdll/leash-int.h -index cb40c607c..bf6f6a08d 100644 ---- a/src/windows/leashdll/leash-int.h -+++ b/src/windows/leashdll/leash-int.h -@@ -182,7 +182,7 @@ typedef int cc_int32; - - enum { - CC_CRED_VUNKNOWN = 0, // For validation -- CC_CRED_V4 = 1, -+ /* CC_CRED_V4 = 1, */ - CC_CRED_V5 = 2, - CC_CRED_VMAX = 3 // For validation - }; -diff --git a/src/windows/lib/cacheapi.h b/src/windows/lib/cacheapi.h -index b30857810..9aab4a098 100644 ---- a/src/windows/lib/cacheapi.h -+++ b/src/windows/lib/cacheapi.h -@@ -126,52 +126,8 @@ typedef struct _cc_creds { - cc_data ** authdata; - } cc_creds; - --// begin V4 stuff --// use an enumerated type so all callers infer the same meaning --// these values are what krbv4win uses internally. --#define STK_AFS 0 --#define STK_DES 1 -- --// K4 uses a MAX_KTXT_LEN of 1250 to hold a ticket --// K95 uses 256 --// To be safe I'll use the larger number, but a factor of 5!!! --#define MAX_V4_CRED_LEN 1250 -- --// V4 Credentials -- --enum { -- KRB_NAME_SZ = 40, -- KRB_INSTANCE_SZ = 40, -- KRB_REALM_SZ = 40 --}; -- --typedef struct cc_V4credential { -- unsigned char kversion; -- char principal[KRB_NAME_SZ + 1]; -- char principal_instance[KRB_INSTANCE_SZ + 1]; -- char service[KRB_NAME_SZ + 1]; -- char service_instance[KRB_INSTANCE_SZ + 1]; -- char realm[KRB_REALM_SZ + 1]; -- unsigned char session_key[8]; -- cc_int32 kvno; // k95 used BYTE skvno -- cc_int32 str_to_key; // k4 infers dynamically, k95 stores -- long issue_date; // k95 called this issue_time -- cc_int32 lifetime; // k95 used LONG expiration_time -- cc_uint32 address; // IP Address of local host -- cc_int32 ticket_sz; // k95 used BYTE, k4 ktext uses int to hold up to 1250 -- unsigned char ticket[MAX_V4_CRED_LEN]; -- unsigned long oops; // zero to catch runaways --} V4Cred_type; -- --enum { -- CC_CRED_VUNKNOWN = 0, // For validation -- CC_CRED_V4 = 1, -- CC_CRED_V5 = 2, -- CC_CRED_VMAX = 3 // For validation --}; - - typedef union cred_ptr_union_type { -- V4Cred_type* pV4Cred; - cc_creds* pV5Cred; - } cred_ptr_union; - -@@ -223,16 +179,15 @@ cc_get_change_time( - ** create, open, close, destroy, get_principal, get_cred_version, & - ** lock_request - ** --** Multiple NCs are allowed within the main cache. Each has a Name --** and kerberos version # (V4 or V5). Caller gets "ccache_ptr"s for --** NCs. -+** Multiple NCs are allowed within the main cache. Each has a Name and -+** kerberos version # (V5). Caller gets "ccache_ptr"s for NCs. - */ - CCACHE_API - cc_create( - apiCB* cc_ctx, // > DLL's primary control structure - const char* name, // > name of cache to be [destroyed if exists, then] created - const char* principal, -- cc_int32 vers, // > ticket version (CC_CRED_V4 or CC_CRED_V5) -+ cc_int32 vers, // > ticket version (CC_CRED_V5) - cc_uint32 cc_flags, // > options - ccache_p** ccache_ptr // < NC control structure - ); -@@ -241,7 +196,7 @@ CCACHE_API - cc_open( - apiCB* cc_ctx, // > DLL's primary control structure - const char* name, // > name of pre-created cache -- cc_int32 vers, // > ticket version (CC_CRED_V4 or CC_CRED_V5) -+ cc_int32 vers, // > ticket version (CC_CRED_V5) - cc_uint32 cc_flags, // > options - ccache_p** ccache_ptr // < NC control structure - ); diff --git a/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch b/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch deleted file mode 100644 index b759047..0000000 --- a/Remove-PKINIT-draft-9-ASN.1-code-and-types.patch +++ /dev/null @@ -1,967 +0,0 @@ -From 044e7ea922800bfc17ba816780803b1d67622b7b Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 18 Jun 2019 11:40:48 -0400 -Subject: [PATCH] Remove PKINIT draft 9 ASN.1 code and types - -ticket: 8817 -(cherry picked from commit c82e21d8836d4cb4c6ac7047752c9f600cb1ce33) ---- - src/include/k5-int-pkinit.h | 74 -------------------------- - src/include/k5-int.h | 30 +---------- - src/lib/krb5/asn.1/asn1_k_encode.c | 81 ---------------------------- - src/lib/krb5/os/accessor.c | 7 --- - src/tests/asn.1/krb5_decode_test.c | 41 -------------- - src/tests/asn.1/krb5_encode_test.c | 40 -------------- - src/tests/asn.1/ktest.c | 85 ------------------------------ - src/tests/asn.1/ktest.h | 11 ---- - src/tests/asn.1/ktest_equal.c | 51 ------------------ - src/tests/asn.1/ktest_equal.h | 3 -- - src/tests/asn.1/pkinit_encode.out | 5 -- - src/tests/asn.1/pkinit_trval.out | 47 ----------------- - 12 files changed, 1 insertion(+), 474 deletions(-) - -diff --git a/src/include/k5-int-pkinit.h b/src/include/k5-int-pkinit.h -index 4622a629e..c23cfd304 100644 ---- a/src/include/k5-int-pkinit.h -+++ b/src/include/k5-int-pkinit.h -@@ -45,14 +45,6 @@ typedef struct _krb5_pk_authenticator { - krb5_data *freshnessToken; - } krb5_pk_authenticator; - --/* PKAuthenticator draft9 */ --typedef struct _krb5_pk_authenticator_draft9 { -- krb5_principal kdcName; -- krb5_int32 cusec; /* (0..999999) */ -- krb5_timestamp ctime; -- krb5_int32 nonce; /* (0..4294967295) */ --} krb5_pk_authenticator_draft9; -- - /* AlgorithmIdentifier */ - typedef struct _krb5_algorithm_identifier { - krb5_data algorithm; /* OID */ -@@ -74,12 +66,6 @@ typedef struct _krb5_auth_pack { - krb5_data **supportedKDFs; /* OIDs of KDFs; OPTIONAL */ - } krb5_auth_pack; - --/* AuthPack draft9 */ --typedef struct _krb5_auth_pack_draft9 { -- krb5_pk_authenticator_draft9 pkAuthenticator; -- krb5_subject_pk_info *clientPublicValue; /* Optional */ --} krb5_auth_pack_draft9; -- - /* ExternalPrincipalIdentifier */ - typedef struct _krb5_external_principal_identifier { - krb5_data subjectName; /* Optional */ -@@ -87,14 +73,6 @@ typedef struct _krb5_external_principal_identifier { - krb5_data subjectKeyIdentifier; /* Optional */ - } krb5_external_principal_identifier; - --/* PA-PK-AS-REQ (Draft 9 -- PA TYPE 14) */ --/* This has four fields, but we only care about the first and third for -- * encoding, and the only about the first for decoding. */ --typedef struct _krb5_pa_pk_as_req_draft9 { -- krb5_data signedAuthPack; -- krb5_data kdcCert; /* Optional */ --} krb5_pa_pk_as_req_draft9; -- - /* PA-PK-AS-REQ (rfc4556 -- PA TYPE 16) */ - typedef struct _krb5_pa_pk_as_req { - krb5_data signedAuthPack; -@@ -116,37 +94,12 @@ typedef struct _krb5_kdc_dh_key_info { - krb5_timestamp dhKeyExpiration; /* Optional */ - } krb5_kdc_dh_key_info; - --/* KDCDHKeyInfo draft9*/ --typedef struct _krb5_kdc_dh_key_info_draft9 { -- krb5_data subjectPublicKey; /* BIT STRING */ -- krb5_int32 nonce; /* (0..4294967295) */ --} krb5_kdc_dh_key_info_draft9; -- - /* ReplyKeyPack */ - typedef struct _krb5_reply_key_pack { - krb5_keyblock replyKey; - krb5_checksum asChecksum; - } krb5_reply_key_pack; - --/* ReplyKeyPack */ --typedef struct _krb5_reply_key_pack_draft9 { -- krb5_keyblock replyKey; -- krb5_int32 nonce; --} krb5_reply_key_pack_draft9; -- --/* PA-PK-AS-REP (Draft 9 -- PA TYPE 15) */ --typedef struct _krb5_pa_pk_as_rep_draft9 { -- enum krb5_pa_pk_as_rep_draft9_selection { -- choice_pa_pk_as_rep_draft9_UNKNOWN = -1, -- choice_pa_pk_as_rep_draft9_dhSignedData = 0, -- choice_pa_pk_as_rep_draft9_encKeyPack = 1 -- } choice; -- union krb5_pa_pk_as_rep_draft9_choices { -- krb5_data dhSignedData; -- krb5_data encKeyPack; -- } u; --} krb5_pa_pk_as_rep_draft9; -- - /* PA-PK-AS-REP (rfc4556 -- PA TYPE 17) */ - typedef struct _krb5_pa_pk_as_rep { - enum krb5_pa_pk_as_rep_selection { -@@ -186,34 +139,18 @@ typedef struct _krb5_pkinit_supp_pub_info { - krb5_error_code - encode_krb5_pa_pk_as_req(const krb5_pa_pk_as_req *rep, krb5_data **code); - --krb5_error_code --encode_krb5_pa_pk_as_req_draft9(const krb5_pa_pk_as_req_draft9 *rep, -- krb5_data **code); -- - krb5_error_code - encode_krb5_pa_pk_as_rep(const krb5_pa_pk_as_rep *rep, krb5_data **code); - --krb5_error_code --encode_krb5_pa_pk_as_rep_draft9(const krb5_pa_pk_as_rep_draft9 *rep, -- krb5_data **code); -- - krb5_error_code - encode_krb5_auth_pack(const krb5_auth_pack *rep, krb5_data **code); - --krb5_error_code --encode_krb5_auth_pack_draft9(const krb5_auth_pack_draft9 *rep, -- krb5_data **code); -- - krb5_error_code - encode_krb5_kdc_dh_key_info(const krb5_kdc_dh_key_info *rep, krb5_data **code); - - krb5_error_code - encode_krb5_reply_key_pack(const krb5_reply_key_pack *, krb5_data **code); - --krb5_error_code --encode_krb5_reply_key_pack_draft9(const krb5_reply_key_pack_draft9 *, -- krb5_data **code); -- - krb5_error_code - encode_krb5_td_trusted_certifiers(krb5_external_principal_identifier *const *, - krb5_data **code); -@@ -237,19 +174,12 @@ encode_krb5_pkinit_supp_pub_info(const krb5_pkinit_supp_pub_info *, - krb5_error_code - decode_krb5_pa_pk_as_req(const krb5_data *, krb5_pa_pk_as_req **); - --krb5_error_code --decode_krb5_pa_pk_as_req_draft9(const krb5_data *, -- krb5_pa_pk_as_req_draft9 **); -- - krb5_error_code - decode_krb5_pa_pk_as_rep(const krb5_data *, krb5_pa_pk_as_rep **); - - krb5_error_code - decode_krb5_auth_pack(const krb5_data *, krb5_auth_pack **); - --krb5_error_code --decode_krb5_auth_pack_draft9(const krb5_data *, krb5_auth_pack_draft9 **); -- - krb5_error_code - decode_krb5_kdc_dh_key_info(const krb5_data *, krb5_kdc_dh_key_info **); - -@@ -259,10 +189,6 @@ decode_krb5_principal_name(const krb5_data *, krb5_principal_data **); - krb5_error_code - decode_krb5_reply_key_pack(const krb5_data *, krb5_reply_key_pack **); - --krb5_error_code --decode_krb5_reply_key_pack_draft9(const krb5_data *, -- krb5_reply_key_pack_draft9 **); -- - krb5_error_code - decode_krb5_td_trusted_certifiers(const krb5_data *, - krb5_external_principal_identifier ***); -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 0857fd1cc..cb328785d 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -1836,7 +1836,7 @@ krb5int_random_string(krb5_context, char *string, unsigned int length); - /* To keep happy libraries which are (for now) accessing internal stuff */ - - /* Make sure to increment by one when changing the struct */ --#define KRB5INT_ACCESS_STRUCT_VERSION 22 -+#define KRB5INT_ACCESS_STRUCT_VERSION 23 - - typedef struct _krb5int_access { - krb5_error_code (*auth_con_get_subkey_enctype)(krb5_context, -@@ -1865,10 +1865,6 @@ typedef struct _krb5int_access { - krb5_error_code - (*encode_krb5_auth_pack)(const krb5_auth_pack *rep, krb5_data **code); - -- krb5_error_code -- (*encode_krb5_auth_pack_draft9)(const krb5_auth_pack_draft9 *rep, -- krb5_data **code); -- - krb5_error_code - (*encode_krb5_kdc_dh_key_info)(const krb5_kdc_dh_key_info *rep, - krb5_data **code); -@@ -1877,26 +1873,14 @@ typedef struct _krb5int_access { - (*encode_krb5_pa_pk_as_rep)(const krb5_pa_pk_as_rep *rep, - krb5_data **code); - -- krb5_error_code -- (*encode_krb5_pa_pk_as_rep_draft9)(const krb5_pa_pk_as_rep_draft9 *rep, -- krb5_data **code); -- - krb5_error_code - (*encode_krb5_pa_pk_as_req)(const krb5_pa_pk_as_req *rep, - krb5_data **code); - -- krb5_error_code -- (*encode_krb5_pa_pk_as_req_draft9)(const krb5_pa_pk_as_req_draft9 *rep, -- krb5_data **code); -- - krb5_error_code - (*encode_krb5_reply_key_pack)(const krb5_reply_key_pack *, - krb5_data **code); - -- krb5_error_code -- (*encode_krb5_reply_key_pack_draft9)(const krb5_reply_key_pack_draft9 *, -- krb5_data **code); -- - krb5_error_code - (*encode_krb5_td_dh_parameters)(krb5_algorithm_identifier *const *, - krb5_data **code); -@@ -1908,17 +1892,9 @@ typedef struct _krb5int_access { - krb5_error_code - (*decode_krb5_auth_pack)(const krb5_data *, krb5_auth_pack **); - -- krb5_error_code -- (*decode_krb5_auth_pack_draft9)(const krb5_data *, -- krb5_auth_pack_draft9 **); -- - krb5_error_code - (*decode_krb5_pa_pk_as_req)(const krb5_data *, krb5_pa_pk_as_req **); - -- krb5_error_code -- (*decode_krb5_pa_pk_as_req_draft9)(const krb5_data *, -- krb5_pa_pk_as_req_draft9 **); -- - krb5_error_code - (*decode_krb5_pa_pk_as_rep)(const krb5_data *, krb5_pa_pk_as_rep **); - -@@ -1931,10 +1907,6 @@ typedef struct _krb5int_access { - krb5_error_code - (*decode_krb5_reply_key_pack)(const krb5_data *, krb5_reply_key_pack **); - -- krb5_error_code -- (*decode_krb5_reply_key_pack_draft9)(const krb5_data *, -- krb5_reply_key_pack_draft9 **); -- - krb5_error_code - (*decode_krb5_td_dh_parameters)(const krb5_data *, - krb5_algorithm_identifier ***); -diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c -index 81a34bac9..a026ab390 100644 ---- a/src/lib/krb5/asn.1/asn1_k_encode.c -+++ b/src/lib/krb5/asn.1/asn1_k_encode.c -@@ -1446,19 +1446,6 @@ static const struct atype_info *pk_authenticator_fields[] = { - }; - DEFSEQTYPE(pk_authenticator, krb5_pk_authenticator, pk_authenticator_fields); - --DEFFIELD(pkauth9_0, krb5_pk_authenticator_draft9, kdcName, 0, principal); --DEFFIELD(pkauth9_1, krb5_pk_authenticator_draft9, kdcName, 1, -- realm_of_principal); --DEFFIELD(pkauth9_2, krb5_pk_authenticator_draft9, cusec, 2, int32); --DEFFIELD(pkauth9_3, krb5_pk_authenticator_draft9, ctime, 3, kerberos_time); --DEFFIELD(pkauth9_4, krb5_pk_authenticator_draft9, nonce, 4, int32); --static const struct atype_info *pk_authenticator_draft9_fields[] = { -- &k5_atype_pkauth9_0, &k5_atype_pkauth9_1, &k5_atype_pkauth9_2, -- &k5_atype_pkauth9_3, &k5_atype_pkauth9_4 --}; --DEFSEQTYPE(pk_authenticator_draft9, krb5_pk_authenticator_draft9, -- pk_authenticator_draft9_fields); -- - DEFCOUNTEDSTRINGTYPE(s_bitstring, char *, unsigned int, - k5_asn1_encode_bitstring, k5_asn1_decode_bitstring, - ASN1_BITSTRING); -@@ -1488,15 +1475,6 @@ static const struct atype_info *auth_pack_fields[] = { - }; - DEFSEQTYPE(auth_pack, krb5_auth_pack, auth_pack_fields); - --DEFFIELD(auth_pack9_0, krb5_auth_pack_draft9, pkAuthenticator, 0, -- pk_authenticator_draft9); --DEFFIELD(auth_pack9_1, krb5_auth_pack_draft9, clientPublicValue, 1, -- opt_subject_pk_info_ptr); --static const struct atype_info *auth_pack_draft9_fields[] = { -- &k5_atype_auth_pack9_0, &k5_atype_auth_pack9_1 --}; --DEFSEQTYPE(auth_pack_draft9, krb5_auth_pack_draft9, auth_pack_draft9_fields); -- - DEFFIELD_IMPLICIT(extprinc_0, krb5_external_principal_identifier, - subjectName, 0, opt_ostring_data); - DEFFIELD_IMPLICIT(extprinc_1, krb5_external_principal_identifier, -@@ -1529,29 +1507,6 @@ static const struct atype_info *pa_pk_as_req_fields[] = { - }; - DEFSEQTYPE(pa_pk_as_req, krb5_pa_pk_as_req, pa_pk_as_req_fields); - --/* -- * In draft-ietf-cat-kerberos-pk-init-09, this sequence has four fields, but we -- * only ever use the first and third. The fields are specified as explicitly -- * tagged, but our historical behavior is to pretend that they are wrapped in -- * IMPLICIT OCTET STRING (i.e., generate primitive context tags), and we don't -- * want to change that without interop testing. -- */ --DEFFIELD_IMPLICIT(pa_pk_as_req9_0, krb5_pa_pk_as_req_draft9, signedAuthPack, 0, -- ostring_data); --DEFFIELD_IMPLICIT(pa_pk_as_req9_2, krb5_pa_pk_as_req_draft9, kdcCert, 2, -- opt_ostring_data); --static const struct atype_info *pa_pk_as_req_draft9_fields[] = { -- &k5_atype_pa_pk_as_req9_0, &k5_atype_pa_pk_as_req9_2 --}; --DEFSEQTYPE(pa_pk_as_req_draft9, krb5_pa_pk_as_req_draft9, -- pa_pk_as_req_draft9_fields); --/* For decoding, we only care about the first field; we can ignore the rest. */ --static const struct atype_info *pa_pk_as_req_draft9_decode_fields[] = { -- &k5_atype_pa_pk_as_req9_0 --}; --DEFSEQTYPE(pa_pk_as_req_draft9_decode, krb5_pa_pk_as_req_draft9, -- pa_pk_as_req_draft9_decode_fields); -- - DEFFIELD_IMPLICIT(dh_rep_info_0, krb5_dh_rep_info, dhSignedData, 0, - ostring_data); - DEFFIELD(dh_rep_info_1, krb5_dh_rep_info, serverDHNonce, 1, opt_ostring_data); -@@ -1577,14 +1532,6 @@ static const struct atype_info *reply_key_pack_fields[] = { - }; - DEFSEQTYPE(reply_key_pack, krb5_reply_key_pack, reply_key_pack_fields); - --DEFFIELD(key_pack9_0, krb5_reply_key_pack_draft9, replyKey, 0, encryption_key); --DEFFIELD(key_pack9_1, krb5_reply_key_pack_draft9, nonce, 1, int32); --static const struct atype_info *reply_key_pack_draft9_fields[] = { -- &k5_atype_key_pack9_0, &k5_atype_key_pack9_1 --}; --DEFSEQTYPE(reply_key_pack_draft9, krb5_reply_key_pack_draft9, -- reply_key_pack_draft9_fields); -- - DEFCTAGGEDTYPE(pa_pk_as_rep_0, 0, dh_rep_info); - DEFCTAGGEDTYPE_IMPLICIT(pa_pk_as_rep_1, 1, ostring_data); - static const struct atype_info *pa_pk_as_rep_alternatives[] = { -@@ -1595,44 +1542,16 @@ DEFCHOICETYPE(pa_pk_as_rep_choice, union krb5_pa_pk_as_rep_choices, - DEFCOUNTEDTYPE_SIGNED(pa_pk_as_rep, krb5_pa_pk_as_rep, u, choice, - pa_pk_as_rep_choice); - --/* -- * draft-ietf-cat-kerberos-pk-init-09 specifies these alternatives as -- * explicitly tagged SignedData and EnvelopedData respectively, which means -- * they should have constructed context tags. However, our historical behavior -- * is to use primitive context tags, and we don't want to change that behavior -- * without interop testing. We have the encodings for each alternative in a -- * krb5_data object; pretend that they are wrapped in IMPLICIT OCTET STRING in -- * order to wrap them in primitive [0] and [1] tags. -- */ --DEFCTAGGEDTYPE_IMPLICIT(pa_pk_as_rep9_0, 0, ostring_data); --DEFCTAGGEDTYPE_IMPLICIT(pa_pk_as_rep9_1, 1, ostring_data); --static const struct atype_info *pa_pk_as_rep_draft9_alternatives[] = { -- &k5_atype_pa_pk_as_rep9_0, &k5_atype_pa_pk_as_rep9_1 --}; --DEFCHOICETYPE(pa_pk_as_rep_draft9_choice, -- union krb5_pa_pk_as_rep_draft9_choices, -- enum krb5_pa_pk_as_rep_draft9_selection, -- pa_pk_as_rep_draft9_alternatives); --DEFCOUNTEDTYPE_SIGNED(pa_pk_as_rep_draft9, krb5_pa_pk_as_rep_draft9, u, choice, -- pa_pk_as_rep_draft9_choice); -- - MAKE_ENCODER(encode_krb5_pa_pk_as_req, pa_pk_as_req); - MAKE_DECODER(decode_krb5_pa_pk_as_req, pa_pk_as_req); --MAKE_ENCODER(encode_krb5_pa_pk_as_req_draft9, pa_pk_as_req_draft9); --MAKE_DECODER(decode_krb5_pa_pk_as_req_draft9, pa_pk_as_req_draft9_decode); - MAKE_ENCODER(encode_krb5_pa_pk_as_rep, pa_pk_as_rep); - MAKE_DECODER(decode_krb5_pa_pk_as_rep, pa_pk_as_rep); --MAKE_ENCODER(encode_krb5_pa_pk_as_rep_draft9, pa_pk_as_rep_draft9); - MAKE_ENCODER(encode_krb5_auth_pack, auth_pack); - MAKE_DECODER(decode_krb5_auth_pack, auth_pack); --MAKE_ENCODER(encode_krb5_auth_pack_draft9, auth_pack_draft9); --MAKE_DECODER(decode_krb5_auth_pack_draft9, auth_pack_draft9); - MAKE_ENCODER(encode_krb5_kdc_dh_key_info, kdc_dh_key_info); - MAKE_DECODER(decode_krb5_kdc_dh_key_info, kdc_dh_key_info); - MAKE_ENCODER(encode_krb5_reply_key_pack, reply_key_pack); - MAKE_DECODER(decode_krb5_reply_key_pack, reply_key_pack); --MAKE_ENCODER(encode_krb5_reply_key_pack_draft9, reply_key_pack_draft9); --MAKE_DECODER(decode_krb5_reply_key_pack_draft9, reply_key_pack_draft9); - MAKE_ENCODER(encode_krb5_td_trusted_certifiers, - seqof_external_principal_identifier); - MAKE_DECODER(decode_krb5_td_trusted_certifiers, -diff --git a/src/lib/krb5/os/accessor.c b/src/lib/krb5/os/accessor.c -index d77f8c6b7..12a39a2ab 100644 ---- a/src/lib/krb5/os/accessor.c -+++ b/src/lib/krb5/os/accessor.c -@@ -80,25 +80,18 @@ krb5int_accessor(krb5int_access *internals, krb5_int32 version) - #define SC(FIELD, VAL) S(FIELD, 0) - #endif - SC (encode_krb5_pa_pk_as_req, encode_krb5_pa_pk_as_req), -- SC (encode_krb5_pa_pk_as_req_draft9, encode_krb5_pa_pk_as_req_draft9), - SC (encode_krb5_pa_pk_as_rep, encode_krb5_pa_pk_as_rep), -- SC (encode_krb5_pa_pk_as_rep_draft9, encode_krb5_pa_pk_as_rep_draft9), - SC (encode_krb5_auth_pack, encode_krb5_auth_pack), -- SC (encode_krb5_auth_pack_draft9, encode_krb5_auth_pack_draft9), - SC (encode_krb5_kdc_dh_key_info, encode_krb5_kdc_dh_key_info), - SC (encode_krb5_reply_key_pack, encode_krb5_reply_key_pack), -- SC (encode_krb5_reply_key_pack_draft9, encode_krb5_reply_key_pack_draft9), - SC (encode_krb5_td_trusted_certifiers, encode_krb5_td_trusted_certifiers), - SC (encode_krb5_td_dh_parameters, encode_krb5_td_dh_parameters), - SC (decode_krb5_pa_pk_as_req, decode_krb5_pa_pk_as_req), -- SC (decode_krb5_pa_pk_as_req_draft9, decode_krb5_pa_pk_as_req_draft9), - SC (decode_krb5_pa_pk_as_rep, decode_krb5_pa_pk_as_rep), - SC (decode_krb5_auth_pack, decode_krb5_auth_pack), -- SC (decode_krb5_auth_pack_draft9, decode_krb5_auth_pack_draft9), - SC (decode_krb5_kdc_dh_key_info, decode_krb5_kdc_dh_key_info), - SC (decode_krb5_principal_name, decode_krb5_principal_name), - SC (decode_krb5_reply_key_pack, decode_krb5_reply_key_pack), -- SC (decode_krb5_reply_key_pack_draft9, decode_krb5_reply_key_pack_draft9), - SC (decode_krb5_td_trusted_certifiers, decode_krb5_td_trusted_certifiers), - SC (decode_krb5_td_dh_parameters, decode_krb5_td_dh_parameters), - SC (encode_krb5_kdc_req_body, encode_krb5_kdc_req_body), -diff --git a/src/tests/asn.1/krb5_decode_test.c b/src/tests/asn.1/krb5_decode_test.c -index cbd99ba63..7a116b40d 100644 ---- a/src/tests/asn.1/krb5_decode_test.c -+++ b/src/tests/asn.1/krb5_decode_test.c -@@ -42,8 +42,6 @@ void krb5_ktest_free_enc_data(krb5_context context, krb5_enc_data *val); - #ifndef DISABLE_PKINIT - static int equal_principal(krb5_principal *ref, krb5_principal var); - static void ktest_free_auth_pack(krb5_context context, krb5_auth_pack *val); --static void ktest_free_auth_pack_draft9(krb5_context context, -- krb5_auth_pack_draft9 *val); - static void ktest_free_kdc_dh_key_info(krb5_context context, - krb5_kdc_dh_key_info *val); - static void ktest_free_pa_pk_as_req(krb5_context context, -@@ -52,8 +50,6 @@ static void ktest_free_pa_pk_as_rep(krb5_context context, - krb5_pa_pk_as_rep *val); - static void ktest_free_reply_key_pack(krb5_context context, - krb5_reply_key_pack *val); --static void ktest_free_reply_key_pack_draft9(krb5_context context, -- krb5_reply_key_pack_draft9 *val); - #endif - static void ktest_free_kkdcp_message(krb5_context context, - krb5_kkdcp_message *val); -@@ -1183,16 +1179,6 @@ int main(argc, argv) - ktest_empty_auth_pack(&ref); - } - -- /****************************************************************/ -- /* decode_krb5_auth_pack_draft9 */ -- { -- setup(krb5_auth_pack_draft9,ktest_make_sample_auth_pack_draft9); -- decode_run("krb5_auth_pack_draft9","","30 75 A0 4F 30 4D A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A2 05 02 03 01 E2 40 A3 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A4 03 02 01 2A A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61", -- acc.decode_krb5_auth_pack_draft9, -- ktest_equal_auth_pack_draft9,ktest_free_auth_pack_draft9); -- ktest_empty_auth_pack_draft9(&ref); -- } -- - /****************************************************************/ - /* decode_krb5_kdc_dh_key_info */ - { -@@ -1213,16 +1199,6 @@ int main(argc, argv) - ktest_empty_reply_key_pack(&ref); - } - -- /****************************************************************/ -- /* decode_krb5_reply_key_pack_draft9 */ -- { -- setup(krb5_reply_key_pack_draft9,ktest_make_sample_reply_key_pack_draft9); -- decode_run("krb5_reply_key_pack_draft9","","30 1A A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 03 02 01 2A", -- acc.decode_krb5_reply_key_pack_draft9, -- ktest_equal_reply_key_pack_draft9,ktest_free_reply_key_pack_draft9); -- ktest_empty_reply_key_pack_draft9(&ref); -- } -- - /****************************************************************/ - /* decode_krb5_principal_name */ - /* We have no encoder for this type (KerberosName from RFC 4556); the -@@ -1279,14 +1255,6 @@ ktest_free_auth_pack(krb5_context context, krb5_auth_pack *val) - free(val); - } - --static void --ktest_free_auth_pack_draft9(krb5_context context, krb5_auth_pack_draft9 *val) --{ -- if (val) -- ktest_empty_auth_pack_draft9(val); -- free(val); --} -- - static void - ktest_free_kdc_dh_key_info(krb5_context context, krb5_kdc_dh_key_info *val) - { -@@ -1319,15 +1287,6 @@ ktest_free_reply_key_pack(krb5_context context, krb5_reply_key_pack *val) - free(val); - } - --static void --ktest_free_reply_key_pack_draft9(krb5_context context, -- krb5_reply_key_pack_draft9 *val) --{ -- if (val) -- ktest_empty_reply_key_pack_draft9(val); -- free(val); --} -- - #endif /* not DISABLE_PKINIT */ - - static void -diff --git a/src/tests/asn.1/krb5_encode_test.c b/src/tests/asn.1/krb5_encode_test.c -index 3efbfb4c0..72c013468 100644 ---- a/src/tests/asn.1/krb5_encode_test.c -+++ b/src/tests/asn.1/krb5_encode_test.c -@@ -798,15 +798,6 @@ main(argc, argv) - ktest_empty_pa_pk_as_req(&req); - } - /****************************************************************/ -- /* encode_krb5_pa_pk_as_req_draft9 */ -- { -- krb5_pa_pk_as_req_draft9 req; -- ktest_make_sample_pa_pk_as_req_draft9(&req); -- encode_run(req, "pa_pk_as_req_draft9", "", -- acc.encode_krb5_pa_pk_as_req_draft9); -- ktest_empty_pa_pk_as_req_draft9(&req); -- } -- /****************************************************************/ - /* encode_krb5_pa_pk_as_rep */ - { - krb5_pa_pk_as_rep rep; -@@ -820,19 +811,6 @@ main(argc, argv) - ktest_empty_pa_pk_as_rep(&rep); - } - /****************************************************************/ -- /* encode_krb5_pa_pk_as_rep_draft9 */ -- { -- krb5_pa_pk_as_rep_draft9 rep; -- ktest_make_sample_pa_pk_as_rep_draft9_dhSignedData(&rep); -- encode_run(rep, "pa_pk_as_rep_draft9", "(dhSignedData)", -- acc.encode_krb5_pa_pk_as_rep_draft9); -- ktest_empty_pa_pk_as_rep_draft9(&rep); -- ktest_make_sample_pa_pk_as_rep_draft9_encKeyPack(&rep); -- encode_run(rep, "pa_pk_as_rep_draft9", "(encKeyPack)", -- acc.encode_krb5_pa_pk_as_rep_draft9); -- ktest_empty_pa_pk_as_rep_draft9(&rep); -- } -- /****************************************************************/ - /* encode_krb5_auth_pack */ - { - krb5_auth_pack pack; -@@ -841,15 +819,6 @@ main(argc, argv) - ktest_empty_auth_pack(&pack); - } - /****************************************************************/ -- /* encode_krb5_auth_pack_draft9_draft9 */ -- { -- krb5_auth_pack_draft9 pack; -- ktest_make_sample_auth_pack_draft9(&pack); -- encode_run(pack, "auth_pack_draft9", "", -- acc.encode_krb5_auth_pack_draft9); -- ktest_empty_auth_pack_draft9(&pack); -- } -- /****************************************************************/ - /* encode_krb5_kdc_dh_key_info */ - { - krb5_kdc_dh_key_info ki; -@@ -866,15 +835,6 @@ main(argc, argv) - ktest_empty_reply_key_pack(&pack); - } - /****************************************************************/ -- /* encode_krb5_reply_key_pack_draft9 */ -- { -- krb5_reply_key_pack_draft9 pack; -- ktest_make_sample_reply_key_pack_draft9(&pack); -- encode_run(pack, "reply_key_pack_draft9", "", -- acc.encode_krb5_reply_key_pack_draft9); -- ktest_empty_reply_key_pack_draft9(&pack); -- } -- /****************************************************************/ - /* encode_krb5_sp80056a_other_info */ - { - krb5_sp80056a_other_info info; -diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c -index 258377299..7bb698732 100644 ---- a/src/tests/asn.1/ktest.c -+++ b/src/tests/asn.1/ktest.c -@@ -729,15 +729,6 @@ ktest_make_sample_pk_authenticator(krb5_pk_authenticator *p) - ktest_make_sample_data(p->freshnessToken); - } - --static void --ktest_make_sample_pk_authenticator_draft9(krb5_pk_authenticator_draft9 *p) --{ -- ktest_make_sample_principal(&p->kdcName); -- p->cusec = SAMPLE_USEC; -- p->ctime = SAMPLE_TIME; -- p->nonce = SAMPLE_NONCE; --} -- - static void - ktest_make_sample_oid(krb5_data *p) - { -@@ -788,13 +779,6 @@ ktest_make_sample_pa_pk_as_req(krb5_pa_pk_as_req *p) - ktest_make_sample_data(&p->kdcPkId); - } - --void --ktest_make_sample_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *p) --{ -- ktest_make_sample_data(&p->signedAuthPack); -- ktest_make_sample_data(&p->kdcCert); --} -- - static void - ktest_make_sample_dh_rep_info(krb5_dh_rep_info *p) - { -@@ -818,20 +802,6 @@ ktest_make_sample_pa_pk_as_rep_encKeyPack(krb5_pa_pk_as_rep *p) - ktest_make_sample_data(&p->u.encKeyPack); - } - --void --ktest_make_sample_pa_pk_as_rep_draft9_dhSignedData(krb5_pa_pk_as_rep_draft9 *p) --{ -- p->choice = choice_pa_pk_as_rep_draft9_dhSignedData; -- ktest_make_sample_data(&p->u.dhSignedData); --} -- --void --ktest_make_sample_pa_pk_as_rep_draft9_encKeyPack(krb5_pa_pk_as_rep_draft9 *p) --{ -- p->choice = choice_pa_pk_as_rep_draft9_encKeyPack; -- ktest_make_sample_data(&p->u.encKeyPack); --} -- - void - ktest_make_sample_auth_pack(krb5_auth_pack *p) - { -@@ -851,14 +821,6 @@ ktest_make_sample_auth_pack(krb5_auth_pack *p) - p->supportedKDFs[1] = NULL; - } - --void --ktest_make_sample_auth_pack_draft9(krb5_auth_pack_draft9 *p) --{ -- ktest_make_sample_pk_authenticator_draft9(&p->pkAuthenticator); -- p->clientPublicValue = ealloc(sizeof(krb5_subject_pk_info)); -- ktest_make_sample_subject_pk_info(p->clientPublicValue); --} -- - void - ktest_make_sample_kdc_dh_key_info(krb5_kdc_dh_key_info *p) - { -@@ -874,13 +836,6 @@ ktest_make_sample_reply_key_pack(krb5_reply_key_pack *p) - ktest_make_sample_checksum(&p->asChecksum); - } - --void --ktest_make_sample_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *p) --{ -- ktest_make_sample_keyblock(&p->replyKey); -- p->nonce = SAMPLE_NONCE; --} -- - void - ktest_make_sample_sp80056a_other_info(krb5_sp80056a_other_info *p) - { -@@ -1717,12 +1672,6 @@ ktest_empty_pk_authenticator(krb5_pk_authenticator *p) - p->freshnessToken = NULL; - } - --static void --ktest_empty_pk_authenticator_draft9(krb5_pk_authenticator_draft9 *p) --{ -- ktest_destroy_principal(&p->kdcName); --} -- - static void - ktest_empty_subject_pk_info(krb5_subject_pk_info *p) - { -@@ -1754,13 +1703,6 @@ ktest_empty_pa_pk_as_req(krb5_pa_pk_as_req *p) - ktest_empty_data(&p->kdcPkId); - } - --void --ktest_empty_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *p) --{ -- ktest_empty_data(&p->signedAuthPack); -- ktest_empty_data(&p->kdcCert); --} -- - static void - ktest_empty_dh_rep_info(krb5_dh_rep_info *p) - { -@@ -1779,16 +1721,6 @@ ktest_empty_pa_pk_as_rep(krb5_pa_pk_as_rep *p) - p->choice = choice_pa_pk_as_rep_UNKNOWN; - } - --void --ktest_empty_pa_pk_as_rep_draft9(krb5_pa_pk_as_rep_draft9 *p) --{ -- if (p->choice == choice_pa_pk_as_rep_draft9_dhSignedData) -- ktest_empty_data(&p->u.dhSignedData); -- else if (p->choice == choice_pa_pk_as_rep_draft9_encKeyPack) -- ktest_empty_data(&p->u.encKeyPack); -- p->choice = choice_pa_pk_as_rep_draft9_UNKNOWN; --} -- - void - ktest_empty_auth_pack(krb5_auth_pack *p) - { -@@ -1820,17 +1752,6 @@ ktest_empty_auth_pack(krb5_auth_pack *p) - } - } - --void --ktest_empty_auth_pack_draft9(krb5_auth_pack_draft9 *p) --{ -- ktest_empty_pk_authenticator_draft9(&p->pkAuthenticator); -- if (p->clientPublicValue != NULL) { -- ktest_empty_subject_pk_info(p->clientPublicValue); -- free(p->clientPublicValue); -- p->clientPublicValue = NULL; -- } --} -- - void - ktest_empty_kdc_dh_key_info(krb5_kdc_dh_key_info *p) - { -@@ -1844,12 +1765,6 @@ ktest_empty_reply_key_pack(krb5_reply_key_pack *p) - ktest_empty_checksum(&p->asChecksum); - } - --void --ktest_empty_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *p) --{ -- ktest_empty_keyblock(&p->replyKey); --} -- - void ktest_empty_sp80056a_other_info(krb5_sp80056a_other_info *p) - { - ktest_empty_algorithm_identifier(&p->algorithm_identifier); -diff --git a/src/tests/asn.1/ktest.h b/src/tests/asn.1/ktest.h -index 1413cfae1..d9cc90a5c 100644 ---- a/src/tests/asn.1/ktest.h -+++ b/src/tests/asn.1/ktest.h -@@ -101,18 +101,11 @@ void ktest_make_maximal_pa_otp_req(krb5_pa_otp_req *p); - - #ifndef DISABLE_PKINIT - void ktest_make_sample_pa_pk_as_req(krb5_pa_pk_as_req *p); --void ktest_make_sample_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *p); - void ktest_make_sample_pa_pk_as_rep_dhInfo(krb5_pa_pk_as_rep *p); - void ktest_make_sample_pa_pk_as_rep_encKeyPack(krb5_pa_pk_as_rep *p); --void ktest_make_sample_pa_pk_as_rep_draft9_dhSignedData( -- krb5_pa_pk_as_rep_draft9 *p); --void ktest_make_sample_pa_pk_as_rep_draft9_encKeyPack( -- krb5_pa_pk_as_rep_draft9 *p); - void ktest_make_sample_auth_pack(krb5_auth_pack *p); --void ktest_make_sample_auth_pack_draft9(krb5_auth_pack_draft9 *p); - void ktest_make_sample_kdc_dh_key_info(krb5_kdc_dh_key_info *p); - void ktest_make_sample_reply_key_pack(krb5_reply_key_pack *p); --void ktest_make_sample_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *p); - void ktest_make_sample_sp80056a_other_info(krb5_sp80056a_other_info *p); - void ktest_make_sample_pkinit_supp_pub_info(krb5_pkinit_supp_pub_info *p); - #endif -@@ -197,14 +190,10 @@ void ktest_empty_pa_otp_req(krb5_pa_otp_req *p); - - #ifndef DISABLE_PKINIT - void ktest_empty_pa_pk_as_req(krb5_pa_pk_as_req *p); --void ktest_empty_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *p); - void ktest_empty_pa_pk_as_rep(krb5_pa_pk_as_rep *p); --void ktest_empty_pa_pk_as_rep_draft9(krb5_pa_pk_as_rep_draft9 *p); - void ktest_empty_auth_pack(krb5_auth_pack *p); --void ktest_empty_auth_pack_draft9(krb5_auth_pack_draft9 *p); - void ktest_empty_kdc_dh_key_info(krb5_kdc_dh_key_info *p); - void ktest_empty_reply_key_pack(krb5_reply_key_pack *p); --void ktest_empty_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *p); - void ktest_empty_sp80056a_other_info(krb5_sp80056a_other_info *p); - void ktest_empty_pkinit_supp_pub_info(krb5_pkinit_supp_pub_info *p); - #endif -diff --git a/src/tests/asn.1/ktest_equal.c b/src/tests/asn.1/ktest_equal.c -index 714cc4398..8a3911cdc 100644 ---- a/src/tests/asn.1/ktest_equal.c -+++ b/src/tests/asn.1/ktest_equal.c -@@ -876,20 +876,6 @@ ktest_equal_pk_authenticator(krb5_pk_authenticator *ref, - return p; - } - --static int --ktest_equal_pk_authenticator_draft9(krb5_pk_authenticator_draft9 *ref, -- krb5_pk_authenticator_draft9 *var) --{ -- int p = TRUE; -- if (ref == var) return TRUE; -- else if (ref == NULL || var == NULL) return FALSE; -- p = p && ptr_equal(kdcName, ktest_equal_principal_data); -- p = p && scalar_equal(cusec); -- p = p && scalar_equal(ctime); -- p = p && scalar_equal(nonce); -- return p; --} -- - static int - ktest_equal_subject_pk_info(krb5_subject_pk_info *ref, - krb5_subject_pk_info *var) -@@ -937,18 +923,6 @@ ktest_equal_pa_pk_as_req(krb5_pa_pk_as_req *ref, krb5_pa_pk_as_req *var) - return p; - } - --int --ktest_equal_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 *ref, -- krb5_pa_pk_as_req_draft9 *var) --{ -- int p = TRUE; -- if (ref == var) return TRUE; -- else if (ref == NULL || var == NULL) return FALSE; -- p = p && equal_str(signedAuthPack); -- p = p && equal_str(kdcCert); -- return p; --} -- - static int - ktest_equal_dh_rep_info(krb5_dh_rep_info *ref, krb5_dh_rep_info *var) - { -@@ -996,19 +970,6 @@ ktest_equal_auth_pack(krb5_auth_pack *ref, krb5_auth_pack *var) - return p; - } - --int --ktest_equal_auth_pack_draft9(krb5_auth_pack_draft9 *ref, -- krb5_auth_pack_draft9 *var) --{ -- int p = TRUE; -- if (ref == var) return TRUE; -- else if (ref == NULL || var == NULL) return FALSE; -- p = p && struct_equal(pkAuthenticator, -- ktest_equal_pk_authenticator_draft9); -- p = p && ptr_equal(clientPublicValue, ktest_equal_subject_pk_info); -- return p; --} -- - int - ktest_equal_kdc_dh_key_info(krb5_kdc_dh_key_info *ref, - krb5_kdc_dh_key_info *var) -@@ -1033,18 +994,6 @@ ktest_equal_reply_key_pack(krb5_reply_key_pack *ref, krb5_reply_key_pack *var) - return p; - } - --int --ktest_equal_reply_key_pack_draft9(krb5_reply_key_pack_draft9 *ref, -- krb5_reply_key_pack_draft9 *var) --{ -- int p = TRUE; -- if (ref == var) return TRUE; -- else if (ref == NULL || var == NULL) return FALSE; -- p = p && struct_equal(replyKey, ktest_equal_keyblock); -- p = p && scalar_equal(nonce); -- return p; --} -- - #endif /* not DISABLE_PKINIT */ - - int -diff --git a/src/tests/asn.1/ktest_equal.h b/src/tests/asn.1/ktest_equal.h -index cfa82ac6e..80a0d781a 100644 ---- a/src/tests/asn.1/ktest_equal.h -+++ b/src/tests/asn.1/ktest_equal.h -@@ -139,13 +139,10 @@ int ktest_equal_ldap_sequence_of_keys(ldap_seqof_key_data *ref, - - #ifndef DISABLE_PKINIT - generic(ktest_equal_pa_pk_as_req, krb5_pa_pk_as_req); --generic(ktest_equal_pa_pk_as_req_draft9, krb5_pa_pk_as_req_draft9); - generic(ktest_equal_pa_pk_as_rep, krb5_pa_pk_as_rep); - generic(ktest_equal_auth_pack, krb5_auth_pack); --generic(ktest_equal_auth_pack_draft9, krb5_auth_pack_draft9); - generic(ktest_equal_kdc_dh_key_info, krb5_kdc_dh_key_info); - generic(ktest_equal_reply_key_pack, krb5_reply_key_pack); --generic(ktest_equal_reply_key_pack_draft9, krb5_reply_key_pack_draft9); - #endif /* not DISABLE_PKINIT */ - - int ktest_equal_kkdcp_message(krb5_kkdcp_message *ref, -diff --git a/src/tests/asn.1/pkinit_encode.out b/src/tests/asn.1/pkinit_encode.out -index 55a60bbef..9bd08e159 100644 ---- a/src/tests/asn.1/pkinit_encode.out -+++ b/src/tests/asn.1/pkinit_encode.out -@@ -1,13 +1,8 @@ - encode_krb5_pa_pk_as_req: 30 38 80 08 6B 72 62 35 64 61 74 61 A1 22 30 20 30 1E 80 08 6B 72 62 35 64 61 74 61 81 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61 --encode_krb5_pa_pk_as_req_draft9: 30 14 80 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61 - encode_krb5_pa_pk_as_rep(dhInfo): A0 28 30 26 80 08 6B 72 62 35 64 61 74 61 A1 0A 04 08 6B 72 62 35 64 61 74 61 A2 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61 - encode_krb5_pa_pk_as_rep(encKeyPack): 81 08 6B 72 62 35 64 61 74 61 --encode_krb5_pa_pk_as_rep_draft9(dhSignedData): 80 08 6B 72 62 35 64 61 74 61 --encode_krb5_pa_pk_as_rep_draft9(encKeyPack): 81 08 6B 72 62 35 64 61 74 61 - encode_krb5_auth_pack: 30 81 9F A0 35 30 33 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61 --encode_krb5_auth_pack_draft9: 30 75 A0 4F 30 4D A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A2 05 02 03 01 E2 40 A3 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A4 03 02 01 2A A1 22 30 20 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 03 09 00 6B 72 62 35 64 61 74 61 - encode_krb5_kdc_dh_key_info: 30 25 A0 0B 03 09 00 6B 72 62 35 64 61 74 61 A1 03 02 01 2A A2 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A - encode_krb5_reply_key_pack: 30 26 A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34 --encode_krb5_reply_key_pack_draft9: 30 1A A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 03 02 01 2A - encode_krb5_sp80056a_other_info: 30 81 81 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A0 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A2 0A 04 08 6B 72 62 35 64 61 74 61 - encode_krb5_pkinit_supp_pub_info: 30 1D A0 03 02 01 14 A1 0A 04 08 6B 72 62 35 64 61 74 61 A2 0A 04 08 6B 72 62 35 64 61 74 61 -diff --git a/src/tests/asn.1/pkinit_trval.out b/src/tests/asn.1/pkinit_trval.out -index 9557188a8..3675fba38 100644 ---- a/src/tests/asn.1/pkinit_trval.out -+++ b/src/tests/asn.1/pkinit_trval.out -@@ -15,14 +15,6 @@ encode_krb5_pa_pk_as_req: - . [2] <8> - 6b 72 62 35 64 61 74 61 krb5data - --encode_krb5_pa_pk_as_req_draft9: -- --[Sequence/Sequence Of] --. [0] <8> -- 6b 72 62 35 64 61 74 61 krb5data --. [2] <8> -- 6b 72 62 35 64 61 74 61 krb5data -- - encode_krb5_pa_pk_as_rep(dhInfo): - - [CONT 0] -@@ -36,16 +28,6 @@ encode_krb5_pa_pk_as_rep(dhInfo): - - encode_krb5_pa_pk_as_rep(encKeyPack): - --[CONT 1] <8> -- 6b 72 62 35 64 61 74 61 krb5data -- --encode_krb5_pa_pk_as_rep_draft9(dhSignedData): -- --[CONT 0] <8> -- 6b 72 62 35 64 61 74 61 krb5data -- --encode_krb5_pa_pk_as_rep_draft9(encKeyPack): -- - [CONT 1] <8> - 6b 72 62 35 64 61 74 61 krb5data - -@@ -79,27 +61,6 @@ encode_krb5_auth_pack: - . . . [0] [Object Identifier] <8> - 6b 72 62 35 64 61 74 61 krb5data - --encode_krb5_auth_pack_draft9: -- --[Sequence/Sequence Of] --. [0] [Sequence/Sequence Of] --. . [0] [Sequence/Sequence Of] --. . . [0] [Integer] 1 --. . . [1] [Sequence/Sequence Of] --. . . . [General string] "hftsai" --. . . . [General string] "extra" --. . [1] [General string] "ATHENA.MIT.EDU" --. . [2] [Integer] 123456 --. . [3] [Generalized Time] "19940610060317Z" --. . [4] [Integer] 42 --. [1] [Sequence/Sequence Of] --. . [Sequence/Sequence Of] --. . . [Object Identifier] <9> -- 2a 86 48 86 f7 12 01 02 02 *.H...... --. . . [Octet String] "params" --. . [Bit String] <9> -- 00 6b 72 62 35 64 61 74 61 .krb5data -- - encode_krb5_kdc_dh_key_info: - - [Sequence/Sequence Of] -@@ -118,14 +79,6 @@ encode_krb5_reply_key_pack: - . . [0] [Integer] 1 - . . [1] [Octet String] "1234" - --encode_krb5_reply_key_pack_draft9: -- --[Sequence/Sequence Of] --. [0] [Sequence/Sequence Of] --. . [0] [Integer] 1 --. . [1] [Octet String] "12345678" --. [1] [Integer] 42 -- - encode_krb5_sp80056a_other_info: - - [Sequence/Sequence Of] diff --git a/Remove-PKINIT-draft-9-support.patch b/Remove-PKINIT-draft-9-support.patch deleted file mode 100644 index c5b45f2..0000000 --- a/Remove-PKINIT-draft-9-support.patch +++ /dev/null @@ -1,1712 +0,0 @@ -From b13b0e48470e03203afd4133e4be9c6471e2acb4 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 18 Jun 2019 13:06:44 -0400 -Subject: [PATCH] Remove PKINIT draft 9 support - -PKINIT draft 9 support is required to interoperate with Windows 2000, -Windows XP, and Windows Server 2003, all of which are well beyond -end-of-life. Remove it. - -ticket: 8817 (new) -(cherry picked from commit bb82690be39a033669388154964486e213d84e76) ---- - src/plugins/preauth/pkinit/pkinit.h | 9 - - src/plugins/preauth/pkinit/pkinit_accessor.c | 12 - - src/plugins/preauth/pkinit/pkinit_accessor.h | 6 - - src/plugins/preauth/pkinit/pkinit_clnt.c | 231 +++----- - src/plugins/preauth/pkinit/pkinit_crypto.h | 1 - - .../preauth/pkinit/pkinit_crypto_openssl.c | 219 ++----- - src/plugins/preauth/pkinit/pkinit_lib.c | 65 --- - src/plugins/preauth/pkinit/pkinit_srv.c | 543 ++++++------------ - src/plugins/preauth/pkinit/pkinit_trace.h | 4 - - src/tests/t_pkinit.py | 6 +- - 10 files changed, 282 insertions(+), 814 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h -index fe2ec0d31..b437fd53f 100644 ---- a/src/plugins/preauth/pkinit/pkinit.h -+++ b/src/plugins/preauth/pkinit/pkinit.h -@@ -213,7 +213,6 @@ struct _pkinit_req_context { - pkinit_identity_opts *idopts; - int do_identity_matching; - krb5_preauthtype pa_type; -- int rfc4556_kdc; - int rfc6112_kdc; - int identity_initialized; - int identity_prompted; -@@ -244,7 +243,6 @@ struct _pkinit_kdc_req_context { - int magic; - pkinit_req_crypto_context cryptoctx; - krb5_auth_pack *rcv_auth_pack; -- krb5_auth_pack_draft9 *rcv_auth_pack9; - krb5_preauthtype pa_type; - }; - typedef struct _pkinit_kdc_req_context *pkinit_kdc_req_context; -@@ -329,22 +327,15 @@ void pkinit_free_deferred_ids(pkinit_deferred_id *identities); - * initialization and free functions - */ - void init_krb5_pa_pk_as_req(krb5_pa_pk_as_req **in); --void init_krb5_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 **in); - void init_krb5_reply_key_pack(krb5_reply_key_pack **in); --void init_krb5_reply_key_pack_draft9(krb5_reply_key_pack_draft9 **in); - - void init_krb5_pa_pk_as_rep(krb5_pa_pk_as_rep **in); --void init_krb5_pa_pk_as_rep_draft9(krb5_pa_pk_as_rep_draft9 **in); - void init_krb5_subject_pk_info(krb5_subject_pk_info **in); - - void free_krb5_pa_pk_as_req(krb5_pa_pk_as_req **in); --void free_krb5_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 **in); - void free_krb5_reply_key_pack(krb5_reply_key_pack **in); --void free_krb5_reply_key_pack_draft9(krb5_reply_key_pack_draft9 **in); - void free_krb5_auth_pack(krb5_auth_pack **in); --void free_krb5_auth_pack_draft9(krb5_context, krb5_auth_pack_draft9 **in); - void free_krb5_pa_pk_as_rep(krb5_pa_pk_as_rep **in); --void free_krb5_pa_pk_as_rep_draft9(krb5_pa_pk_as_rep_draft9 **in); - void free_krb5_external_principal_identifier(krb5_external_principal_identifier ***in); - void free_krb5_algorithm_identifiers(krb5_algorithm_identifier ***in); - void free_krb5_algorithm_identifier(krb5_algorithm_identifier *in); -diff --git a/src/plugins/preauth/pkinit/pkinit_accessor.c b/src/plugins/preauth/pkinit/pkinit_accessor.c -index 6bae94969..0908f1b9b 100644 ---- a/src/plugins/preauth/pkinit/pkinit_accessor.c -+++ b/src/plugins/preauth/pkinit/pkinit_accessor.c -@@ -41,22 +41,15 @@ - krb5_error_code (*k5int_decode_##type)(const krb5_data *, type ***) - - DEF_FUNC_PTRS(krb5_auth_pack); --DEF_FUNC_PTRS(krb5_auth_pack_draft9); - DEF_FUNC_PTRS(krb5_kdc_dh_key_info); - DEF_FUNC_PTRS(krb5_pa_pk_as_rep); - DEF_FUNC_PTRS(krb5_pa_pk_as_req); --DEF_FUNC_PTRS(krb5_pa_pk_as_req_draft9); - DEF_FUNC_PTRS(krb5_reply_key_pack); --DEF_FUNC_PTRS(krb5_reply_key_pack_draft9); - - /* special cases... */ - krb5_error_code - (*k5int_decode_krb5_principal_name)(const krb5_data *, krb5_principal_data **); - --krb5_error_code --(*k5int_encode_krb5_pa_pk_as_rep_draft9)(const krb5_pa_pk_as_rep_draft9 *, -- krb5_data **code); -- - krb5_error_code - (*k5int_encode_krb5_td_dh_parameters)(krb5_algorithm_identifier *const *, - krb5_data **code); -@@ -101,21 +94,16 @@ pkinit_accessor_init(void) - k5int_decode_##type = k5int.decode_##type; - - SET_PTRS(krb5_auth_pack); -- SET_PTRS(krb5_auth_pack_draft9); - SET_PTRS(krb5_kdc_dh_key_info); - SET_PTRS(krb5_pa_pk_as_rep); - SET_PTRS(krb5_pa_pk_as_req); -- SET_PTRS(krb5_pa_pk_as_req_draft9); - SET_PTRS(krb5_reply_key_pack); -- SET_PTRS(krb5_reply_key_pack_draft9); - SET_PTRS(krb5_td_dh_parameters); - SET_PTRS(krb5_td_trusted_certifiers); - - /* special cases... */ - k5int_decode_krb5_principal_name = k5int.decode_krb5_principal_name; - k5int_encode_krb5_kdc_req_body = k5int.encode_krb5_kdc_req_body; -- k5int_encode_krb5_pa_pk_as_rep_draft9 = \ -- k5int.encode_krb5_pa_pk_as_rep_draft9; - k5int_krb5_free_kdc_req = k5int.free_kdc_req; - k5int_set_prompt_types = k5int.set_prompt_types; - return 0; -diff --git a/src/plugins/preauth/pkinit/pkinit_accessor.h b/src/plugins/preauth/pkinit/pkinit_accessor.h -index dcee3db53..e510ab624 100644 ---- a/src/plugins/preauth/pkinit/pkinit_accessor.h -+++ b/src/plugins/preauth/pkinit/pkinit_accessor.h -@@ -45,21 +45,15 @@ extern krb5_error_code (*k5int_encode_##type)(const type **, krb5_data **); \ - extern krb5_error_code (*k5int_decode_##type)(const krb5_data *, type ***) - - DEF_EXT_FUNC_PTRS(krb5_auth_pack); --DEF_EXT_FUNC_PTRS(krb5_auth_pack_draft9); - DEF_EXT_FUNC_PTRS(krb5_kdc_dh_key_info); - DEF_EXT_FUNC_PTRS(krb5_pa_pk_as_rep); - DEF_EXT_FUNC_PTRS(krb5_pa_pk_as_req); --DEF_EXT_FUNC_PTRS(krb5_pa_pk_as_req_draft9); - DEF_EXT_FUNC_PTRS(krb5_reply_key_pack); --DEF_EXT_FUNC_PTRS(krb5_reply_key_pack_draft9); - - /* special cases... */ - extern krb5_error_code (*k5int_decode_krb5_principal_name) - (const krb5_data *, krb5_principal_data **); - --extern krb5_error_code (*k5int_encode_krb5_pa_pk_as_rep_draft9) -- (const krb5_pa_pk_as_rep_draft9 *, krb5_data **code); -- - extern krb5_error_code (*k5int_encode_krb5_td_dh_parameters) - (krb5_algorithm_identifier *const *, krb5_data **code); - extern krb5_error_code (*k5int_decode_krb5_td_dh_parameters) -diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c -index 58400d555..1a642139a 100644 ---- a/src/plugins/preauth/pkinit/pkinit_clnt.c -+++ b/src/plugins/preauth/pkinit/pkinit_clnt.c -@@ -148,11 +148,7 @@ pa_pkinit_gen_req(krb5_context context, - goto cleanup; - } - -- /* -- * The most we'll return is two pa_data, normally just one. -- * We need to make room for the NULL terminator. -- */ -- return_pa_data = k5calloc(3, sizeof(*return_pa_data), &retval); -+ return_pa_data = k5calloc(2, sizeof(*return_pa_data), &retval); - if (return_pa_data == NULL) - goto cleanup; - -@@ -162,21 +158,11 @@ pa_pkinit_gen_req(krb5_context context, - - return_pa_data[0]->magic = KV5M_PA_DATA; - -- if (pa_type == KRB5_PADATA_PK_AS_REQ_OLD) -- return_pa_data[0]->pa_type = KRB5_PADATA_PK_AS_REP_OLD; -- else -- return_pa_data[0]->pa_type = pa_type; -+ return_pa_data[0]->pa_type = pa_type; - return_pa_data[0]->length = out_data->length; - return_pa_data[0]->contents = (krb5_octet *) out_data->data; - *out_data = empty_data(); - -- if (return_pa_data[0]->pa_type == KRB5_PADATA_PK_AS_REP_OLD) { -- return_pa_data[1] = k5alloc(sizeof(*return_pa_data[1]), &retval); -- if (return_pa_data[1] == NULL) -- goto cleanup; -- return_pa_data[1]->pa_type = KRB5_PADATA_AS_CHECKSUM; -- } -- - *out_padata = return_pa_data; - return_pa_data = NULL; - cb->disable_fallback(context, rock); -@@ -206,8 +192,6 @@ pkinit_as_req_create(krb5_context context, - krb5_data *coded_auth_pack = NULL; - krb5_auth_pack auth_pack; - krb5_pa_pk_as_req *req = NULL; -- krb5_auth_pack_draft9 auth_pack9; -- krb5_pa_pk_as_req_draft9 *req9 = NULL; - krb5_algorithm_identifier **cmstypes = NULL; - int protocol = reqctx->opts->dh_or_rsa; - unsigned char *dh_params = NULL, *dh_pubkey = NULL; -@@ -216,42 +200,25 @@ pkinit_as_req_create(krb5_context context, - pkiDebug("pkinit_as_req_create pa_type = %d\n", reqctx->pa_type); - - /* Create the authpack */ -- switch((int)reqctx->pa_type) { -- case KRB5_PADATA_PK_AS_REQ_OLD: -- protocol = RSA_PROTOCOL; -- memset(&auth_pack9, 0, sizeof(auth_pack9)); -- auth_pack9.pkAuthenticator.ctime = ctsec; -- auth_pack9.pkAuthenticator.cusec = cusec; -- auth_pack9.pkAuthenticator.nonce = nonce; -- auth_pack9.pkAuthenticator.kdcName = server; -- break; -- case KRB5_PADATA_PK_AS_REQ: -- memset(&info, 0, sizeof(info)); -- memset(&auth_pack, 0, sizeof(auth_pack)); -- auth_pack.pkAuthenticator.ctime = ctsec; -- auth_pack.pkAuthenticator.cusec = cusec; -- auth_pack.pkAuthenticator.nonce = nonce; -- auth_pack.pkAuthenticator.paChecksum = *cksum; -- if (!reqctx->opts->disable_freshness) -- auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token; -- auth_pack.clientDHNonce.length = 0; -- auth_pack.clientPublicValue = &info; -- auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; -+ memset(&info, 0, sizeof(info)); -+ memset(&auth_pack, 0, sizeof(auth_pack)); -+ auth_pack.pkAuthenticator.ctime = ctsec; -+ auth_pack.pkAuthenticator.cusec = cusec; -+ auth_pack.pkAuthenticator.nonce = nonce; -+ auth_pack.pkAuthenticator.paChecksum = *cksum; -+ if (!reqctx->opts->disable_freshness) -+ auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token; -+ auth_pack.clientDHNonce.length = 0; -+ auth_pack.clientPublicValue = &info; -+ auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; - -- /* add List of CMS algorithms */ -- retval = create_krb5_supportedCMSTypes(context, plgctx->cryptoctx, -- reqctx->cryptoctx, -- reqctx->idctx, &cmstypes); -- auth_pack.supportedCMSTypes = cmstypes; -- if (retval) -- goto cleanup; -- break; -- default: -- pkiDebug("as_req: unrecognized pa_type = %d\n", -- (int)reqctx->pa_type); -- retval = -1; -+ /* add List of CMS algorithms */ -+ retval = create_krb5_supportedCMSTypes(context, plgctx->cryptoctx, -+ reqctx->cryptoctx, -+ reqctx->idctx, &cmstypes); -+ auth_pack.supportedCMSTypes = cmstypes; -+ if (retval) - goto cleanup; -- } - - switch(protocol) { - case DH_PROTOCOL: -@@ -274,14 +241,7 @@ pkinit_as_req_create(krb5_context context, - case RSA_PROTOCOL: - TRACE_PKINIT_CLIENT_REQ_RSA(context); - pkiDebug("as_req: RSA key transport algorithm\n"); -- switch((int)reqctx->pa_type) { -- case KRB5_PADATA_PK_AS_REQ_OLD: -- auth_pack9.clientPublicValue = NULL; -- break; -- case KRB5_PADATA_PK_AS_REQ: -- auth_pack.clientPublicValue = NULL; -- break; -- } -+ auth_pack.clientPublicValue = NULL; - break; - default: - pkiDebug("as_req: unknown key transport protocol %d\n", -@@ -290,16 +250,7 @@ pkinit_as_req_create(krb5_context context, - goto cleanup; - } - -- /* Encode the authpack */ -- switch((int)reqctx->pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- retval = k5int_encode_krb5_auth_pack(&auth_pack, &coded_auth_pack); -- break; -- case KRB5_PADATA_PK_AS_REQ_OLD: -- retval = k5int_encode_krb5_auth_pack_draft9(&auth_pack9, -- &coded_auth_pack); -- break; -- } -+ retval = k5int_encode_krb5_auth_pack(&auth_pack, &coded_auth_pack); - if (retval) { - pkiDebug("failed to encode the AuthPack %d\n", retval); - goto cleanup; -@@ -311,60 +262,39 @@ pkinit_as_req_create(krb5_context context, - #endif - - /* create PKCS7 object from authpack */ -- switch((int)reqctx->pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- init_krb5_pa_pk_as_req(&req); -- if (req == NULL) { -- retval = ENOMEM; -- goto cleanup; -- } -- if (use_content_info(context, reqctx, client)) { -- retval = cms_contentinfo_create(context, plgctx->cryptoctx, -- reqctx->cryptoctx, reqctx->idctx, -- CMS_SIGN_CLIENT, -- (unsigned char *) -- coded_auth_pack->data, -- coded_auth_pack->length, -- (unsigned char **) -- &req->signedAuthPack.data, -- &req->signedAuthPack.length); -- } else { -- retval = cms_signeddata_create(context, plgctx->cryptoctx, -- reqctx->cryptoctx, reqctx->idctx, -- CMS_SIGN_CLIENT, 1, -- (unsigned char *) -- coded_auth_pack->data, -- coded_auth_pack->length, -- (unsigned char **) -- &req->signedAuthPack.data, -- &req->signedAuthPack.length); -- } --#ifdef DEBUG_ASN1 -- print_buffer_bin((unsigned char *)req->signedAuthPack.data, -- req->signedAuthPack.length, -- "/tmp/client_signed_data"); --#endif -- break; -- case KRB5_PADATA_PK_AS_REQ_OLD: -- init_krb5_pa_pk_as_req_draft9(&req9); -- if (req9 == NULL) { -- retval = ENOMEM; -- goto cleanup; -- } -+ init_krb5_pa_pk_as_req(&req); -+ if (req == NULL) { -+ retval = ENOMEM; -+ goto cleanup; -+ } -+ if (use_content_info(context, reqctx, client)) { -+ retval = cms_contentinfo_create(context, plgctx->cryptoctx, -+ reqctx->cryptoctx, reqctx->idctx, -+ CMS_SIGN_CLIENT, -+ (unsigned char *) -+ coded_auth_pack->data, -+ coded_auth_pack->length, -+ (unsigned char **) -+ &req->signedAuthPack.data, -+ &req->signedAuthPack.length); -+ } else { - retval = cms_signeddata_create(context, plgctx->cryptoctx, -- reqctx->cryptoctx, reqctx->idctx, CMS_SIGN_DRAFT9, 1, -- (unsigned char *)coded_auth_pack->data, -+ reqctx->cryptoctx, reqctx->idctx, -+ CMS_SIGN_CLIENT, 1, -+ (unsigned char *) -+ coded_auth_pack->data, - coded_auth_pack->length, - (unsigned char **) -- &req9->signedAuthPack.data, -- &req9->signedAuthPack.length); -- break; --#ifdef DEBUG_ASN1 -- print_buffer_bin((unsigned char *)req9->signedAuthPack.data, -- req9->signedAuthPack.length, -- "/tmp/client_signed_data_draft9"); --#endif -+ &req->signedAuthPack.data, -+ &req->signedAuthPack.length); - } -+ -+#ifdef DEBUG_ASN1 -+ print_buffer_bin((unsigned char *)req->signedAuthPack.data, -+ req->signedAuthPack.length, -+ "/tmp/client_signed_data"); -+#endif -+ - krb5_free_data(context, coded_auth_pack); - if (retval) { - pkiDebug("failed to create pkcs7 signed data\n"); -@@ -372,33 +302,21 @@ pkinit_as_req_create(krb5_context context, - } - - /* create a list of trusted CAs */ -- switch((int)reqctx->pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- retval = create_krb5_trustedCertifiers(context, plgctx->cryptoctx, -- reqctx->cryptoctx, reqctx->idctx, &req->trustedCertifiers); -- if (retval) -- goto cleanup; -- retval = create_issuerAndSerial(context, plgctx->cryptoctx, -- reqctx->cryptoctx, reqctx->idctx, -- (unsigned char **)&req->kdcPkId.data, -- &req->kdcPkId.length); -- if (retval) -- goto cleanup; -+ retval = create_krb5_trustedCertifiers(context, plgctx->cryptoctx, -+ reqctx->cryptoctx, reqctx->idctx, -+ &req->trustedCertifiers); -+ if (retval) -+ goto cleanup; -+ retval = create_issuerAndSerial(context, plgctx->cryptoctx, -+ reqctx->cryptoctx, reqctx->idctx, -+ (unsigned char **)&req->kdcPkId.data, -+ &req->kdcPkId.length); -+ if (retval) -+ goto cleanup; -+ -+ /* Encode the as-req */ -+ retval = k5int_encode_krb5_pa_pk_as_req(req, as_req); - -- /* Encode the as-req */ -- retval = k5int_encode_krb5_pa_pk_as_req(req, as_req); -- break; -- case KRB5_PADATA_PK_AS_REQ_OLD: -- retval = create_issuerAndSerial(context, plgctx->cryptoctx, -- reqctx->cryptoctx, reqctx->idctx, -- (unsigned char **)&req9->kdcCert.data, -- &req9->kdcCert.length); -- if (retval) -- goto cleanup; -- /* Encode the as-req */ -- retval = k5int_encode_krb5_pa_pk_as_req_draft9(req9, as_req); -- break; -- } - #ifdef DEBUG_ASN1 - if (!retval) - print_buffer_bin((unsigned char *)(*as_req)->data, (*as_req)->length, -@@ -410,7 +328,6 @@ cleanup: - free(dh_params); - free(dh_pubkey); - free_krb5_pa_pk_as_req(&req); -- free_krb5_pa_pk_as_req_draft9(&req9); - - pkiDebug("pkinit_as_req_create retval=%d\n", (int) retval); - -@@ -1165,31 +1082,13 @@ pkinit_client_process(krb5_context context, krb5_clpreauth_moddata moddata, - d = make_data(in_padata->contents, in_padata->length); - return krb5_copy_data(context, &d, &reqctx->freshness_token); - case KRB5_PADATA_PK_AS_REQ: -- reqctx->rfc4556_kdc = 1; - pkiDebug("processing KRB5_PADATA_PK_AS_REQ\n"); - processing_request = 1; - break; - - case KRB5_PADATA_PK_AS_REP: -- reqctx->rfc4556_kdc = 1; - pkiDebug("processing KRB5_PADATA_PK_AS_REP\n"); - break; -- case KRB5_PADATA_PK_AS_REP_OLD: -- case KRB5_PADATA_PK_AS_REQ_OLD: -- /* Don't fall back to draft9 code if the KDC supports RFC 4556. */ -- if (reqctx->rfc4556_kdc) { -- TRACE_PKINIT_CLIENT_NO_DRAFT9(context); -- return KRB5KDC_ERR_PREAUTH_FAILED; -- } -- if (in_padata->length == 0) { -- pkiDebug("processing KRB5_PADATA_PK_AS_REQ_OLD\n"); -- in_padata->pa_type = KRB5_PADATA_PK_AS_REQ_OLD; -- processing_request = 1; -- } else { -- pkiDebug("processing KRB5_PADATA_PK_AS_REP_OLD\n"); -- in_padata->pa_type = KRB5_PADATA_PK_AS_REP_OLD; -- } -- break; - default: - pkiDebug("unrecognized patype = %d for PKINIT\n", - in_padata->pa_type); -@@ -1363,8 +1262,6 @@ pkinit_client_get_flags(krb5_context kcontext, krb5_preauthtype patype) - static krb5_preauthtype supported_client_pa_types[] = { - KRB5_PADATA_PK_AS_REP, - KRB5_PADATA_PK_AS_REQ, -- KRB5_PADATA_PK_AS_REP_OLD, -- KRB5_PADATA_PK_AS_REQ_OLD, - KRB5_PADATA_PKINIT_KX, - KRB5_PADATA_AS_FRESHNESS, - 0 -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h -index 0acb731cd..8064a07d0 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto.h -+++ b/src/plugins/preauth/pkinit/pkinit_crypto.h -@@ -46,7 +46,6 @@ - */ - enum cms_msg_types { - CMS_SIGN_CLIENT, -- CMS_SIGN_DRAFT9, - CMS_SIGN_SERVER, - CMS_ENVEL_SERVER - }; -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 8aa2c5257..8c7fd0cca 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -1050,17 +1050,11 @@ create_contentinfo(krb5_context context, ASN1_OBJECT *oid, - if (p7->type == NULL) - goto oom; - -- if (OBJ_obj2nid(oid) == NID_pkcs7_data) { -- /* Draft 9 uses id-pkcs7-data for signed data. For this type OpenSSL -- * expects an octet string in d.data. */ -- p7->d.data = ostr; -- } else { -- p7->d.other = ASN1_TYPE_new(); -- if (p7->d.other == NULL) -- goto oom; -- p7->d.other->type = V_ASN1_OCTET_STRING; -- p7->d.other->value.octet_string = ostr; -- } -+ p7->d.other = ASN1_TYPE_new(); -+ if (p7->d.other == NULL) -+ goto oom; -+ p7->d.other->type = V_ASN1_OCTET_STRING; -+ p7->d.other->value.octet_string = ostr; - - *p7_out = p7; - return 0; -@@ -1249,43 +1243,37 @@ cms_signeddata_create(krb5_context context, - goto cleanup; - p7si->digest_enc_alg->parameter->type = V_ASN1_NULL; - -- if (cms_msg_type == CMS_SIGN_DRAFT9){ -- /* don't include signed attributes for pa-type 15 request */ -- abuf = data; -- alen = data_len; -- } else { -- /* add signed attributes */ -- /* compute sha1 digest over the EncapsulatedContentInfo */ -- ctx = EVP_MD_CTX_new(); -- if (ctx == NULL) -- goto cleanup; -- EVP_DigestInit_ex(ctx, EVP_sha1(), NULL); -- EVP_DigestUpdate(ctx, data, data_len); -- md_tmp = EVP_MD_CTX_md(ctx); -- EVP_DigestFinal_ex(ctx, md_data, &md_len); -- EVP_MD_CTX_free(ctx); -+ /* add signed attributes */ -+ /* compute sha1 digest over the EncapsulatedContentInfo */ -+ ctx = EVP_MD_CTX_new(); -+ if (ctx == NULL) -+ goto cleanup; -+ EVP_DigestInit_ex(ctx, EVP_sha1(), NULL); -+ EVP_DigestUpdate(ctx, data, data_len); -+ md_tmp = EVP_MD_CTX_md(ctx); -+ EVP_DigestFinal_ex(ctx, md_data, &md_len); -+ EVP_MD_CTX_free(ctx); - -- /* create a message digest attr */ -- digest_attr = ASN1_OCTET_STRING_new(); -- ASN1_OCTET_STRING_set(digest_attr, md_data, (int)md_len); -- PKCS7_add_signed_attribute(p7si, NID_pkcs9_messageDigest, -- V_ASN1_OCTET_STRING, (char *) digest_attr); -+ /* create a message digest attr */ -+ digest_attr = ASN1_OCTET_STRING_new(); -+ ASN1_OCTET_STRING_set(digest_attr, md_data, (int)md_len); -+ PKCS7_add_signed_attribute(p7si, NID_pkcs9_messageDigest, -+ V_ASN1_OCTET_STRING, (char *)digest_attr); - -- /* create a content-type attr */ -- oid_copy = OBJ_dup(oid); -- if (oid_copy == NULL) -- goto cleanup2; -- PKCS7_add_signed_attribute(p7si, NID_pkcs9_contentType, -- V_ASN1_OBJECT, oid_copy); -+ /* create a content-type attr */ -+ oid_copy = OBJ_dup(oid); -+ if (oid_copy == NULL) -+ goto cleanup2; -+ PKCS7_add_signed_attribute(p7si, NID_pkcs9_contentType, -+ V_ASN1_OBJECT, oid_copy); - -- /* create the signature over signed attributes. get DER encoded value */ -- /* This is the place where smartcard signature needs to be calculated */ -- sk = p7si->auth_attr; -- alen = ASN1_item_i2d((ASN1_VALUE *) sk, &abuf, -- ASN1_ITEM_rptr(PKCS7_ATTR_SIGN)); -- if (abuf == NULL) -- goto cleanup2; -- } /* signed attributes */ -+ /* create the signature over signed attributes. get DER encoded value */ -+ /* This is the place where smartcard signature needs to be calculated */ -+ sk = p7si->auth_attr; -+ alen = ASN1_item_i2d((ASN1_VALUE *)sk, &abuf, -+ ASN1_ITEM_rptr(PKCS7_ATTR_SIGN)); -+ if (abuf == NULL) -+ goto cleanup2; - - #ifndef WITHOUT_PKCS11 - /* Some tokens can only do RSAEncryption without sha1 hash */ -@@ -1301,11 +1289,7 @@ cms_signeddata_create(krb5_context context, - ctx = EVP_MD_CTX_new(); - if (ctx == NULL) - goto cleanup; -- /* if this is not draft9 request, include digest signed attribute */ -- if (cms_msg_type != CMS_SIGN_DRAFT9) -- EVP_DigestInit_ex(ctx, md_tmp, NULL); -- else -- EVP_DigestInit_ex(ctx, EVP_sha1(), NULL); -+ EVP_DigestInit_ex(ctx, md_tmp, NULL); - EVP_DigestUpdate(ctx, abuf, alen); - EVP_DigestFinal_ex(ctx, md_data2, &md_len2); - EVP_MD_CTX_free(ctx); -@@ -1349,8 +1333,7 @@ cms_signeddata_create(krb5_context context, - #ifdef DEBUG_SIG - print_buffer(sig, sig_len); - #endif -- if (cms_msg_type != CMS_SIGN_DRAFT9 ) -- free(abuf); -+ free(abuf); - if (retval) - goto cleanup2; - -@@ -1393,19 +1376,13 @@ cms_signeddata_create(krb5_context context, - print_buffer_bin(*signed_data, *signed_data_len, - "/tmp/client_pkcs7_signeddata"); - } else { -- if (cms_msg_type == CMS_SIGN_SERVER) { -- print_buffer_bin(*signed_data, *signed_data_len, -- "/tmp/kdc_pkcs7_signeddata"); -- } else { -- print_buffer_bin(*signed_data, *signed_data_len, -- "/tmp/draft9_pkcs7_signeddata"); -- } -+ print_buffer_bin(*signed_data, *signed_data_len, -+ "/tmp/kdc_pkcs7_signeddata"); - } - #endif - - cleanup2: - if (p7si) { -- if (cms_msg_type != CMS_SIGN_DRAFT9) - #ifndef WITHOUT_PKCS11 - if (id_cryptoctx->pkcs11_method == 1 && - id_cryptoctx->mech == CKM_RSA_PKCS) { -@@ -1692,15 +1669,13 @@ cms_signeddata_verify(krb5_context context, - #endif - } else { - /* retrieve verified certificate chain */ -- if (cms_msg_type == CMS_SIGN_CLIENT || cms_msg_type == CMS_SIGN_DRAFT9) -+ if (cms_msg_type == CMS_SIGN_CLIENT) - verified_chain = X509_STORE_CTX_get1_chain(cert_ctx); - } - X509_STORE_CTX_free(cert_ctx); - if (i <= 0) - goto cleanup; - out = BIO_new(BIO_s_mem()); -- if (cms_msg_type == CMS_SIGN_DRAFT9) -- flags |= CMS_NOATTR; - if (CMS_verify(cms, NULL, store, NULL, out, flags) == 0) { - unsigned long err = ERR_peek_error(); - switch(ERR_GET_REASON(err)) { -@@ -1717,21 +1692,6 @@ cms_signeddata_verify(krb5_context context, - } /* message was signed */ - if (!OBJ_cmp(etype, oid)) - valid_oid = 1; -- else if (cms_msg_type == CMS_SIGN_DRAFT9) { -- /* -- * Various implementations of the pa-type 15 request use -- * different OIDS. We check that the returned object -- * has any of the acceptable OIDs -- */ -- ASN1_OBJECT *client_oid = NULL, *server_oid = NULL, *rsa_oid = NULL; -- client_oid = pkinit_pkcs7type2oid(plgctx, CMS_SIGN_CLIENT); -- server_oid = pkinit_pkcs7type2oid(plgctx, CMS_SIGN_SERVER); -- rsa_oid = pkinit_pkcs7type2oid(plgctx, CMS_ENVEL_SERVER); -- if (!OBJ_cmp(etype, client_oid) || -- !OBJ_cmp(etype, server_oid) || -- !OBJ_cmp(etype, rsa_oid)) -- valid_oid = 1; -- } - - if (valid_oid) - pkiDebug("CMS Verification successful\n"); -@@ -1761,7 +1721,7 @@ cms_signeddata_verify(krb5_context context, - reqctx->received_cert = X509_dup(x); - - /* generate authorization data */ -- if (cms_msg_type == CMS_SIGN_CLIENT || cms_msg_type == CMS_SIGN_DRAFT9) { -+ if (cms_msg_type == CMS_SIGN_CLIENT) { - - if (authz_data == NULL || authz_data_len == NULL) - goto out; -@@ -1841,24 +1801,11 @@ cms_envelopeddata_create(krb5_context context, - int signed_data_len = 0, enc_data_len = 0, flags = PKCS7_BINARY; - STACK_OF(X509) *encerts = NULL; - const EVP_CIPHER *cipher = NULL; -- int cms_msg_type; -- -- /* create the PKCS7 SignedData portion of the PKCS7 EnvelopedData */ -- switch ((int)pa_type) { -- case KRB5_PADATA_PK_AS_REQ_OLD: -- case KRB5_PADATA_PK_AS_REP_OLD: -- cms_msg_type = CMS_SIGN_DRAFT9; -- break; -- case KRB5_PADATA_PK_AS_REQ: -- cms_msg_type = CMS_ENVEL_SERVER; -- break; -- default: -- goto cleanup; -- } - - retval = cms_signeddata_create(context, plgctx, reqctx, idctx, -- cms_msg_type, include_certchain, key_pack, key_pack_len, -- &signed_data, (unsigned int *)&signed_data_len); -+ CMS_ENVEL_SERVER, include_certchain, -+ key_pack, key_pack_len, &signed_data, -+ (unsigned int *)&signed_data_len); - if (retval) { - pkiDebug("failed to create pkcs7 signed data\n"); - goto cleanup; -@@ -1874,26 +1821,11 @@ cms_envelopeddata_create(krb5_context context, - - cipher = EVP_des_ede3_cbc(); - in = BIO_new(BIO_s_mem()); -- switch (pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- prepare_enc_data(signed_data, signed_data_len, &enc_data, -- &enc_data_len); -- retval = BIO_write(in, enc_data, enc_data_len); -- if (retval != enc_data_len) { -- pkiDebug("BIO_write only wrote %d\n", retval); -- goto cleanup; -- } -- break; -- case KRB5_PADATA_PK_AS_REP_OLD: -- case KRB5_PADATA_PK_AS_REQ_OLD: -- retval = BIO_write(in, signed_data, signed_data_len); -- if (retval != signed_data_len) { -- pkiDebug("BIO_write only wrote %d\n", retval); -- goto cleanup; -- } -- break; -- default: -- retval = -1; -+ prepare_enc_data(signed_data, signed_data_len, &enc_data, -+ &enc_data_len); -+ retval = BIO_write(in, enc_data, enc_data_len); -+ if (retval != enc_data_len) { -+ pkiDebug("BIO_write only wrote %d\n", retval); - goto cleanup; - } - -@@ -1902,20 +1834,7 @@ cms_envelopeddata_create(krb5_context context, - retval = oerr(context, 0, _("Failed to encrypt PKCS7 object")); - goto cleanup; - } -- switch (pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- p7->d.enveloped->enc_data->content_type = -- OBJ_nid2obj(NID_pkcs7_signed); -- break; -- case KRB5_PADATA_PK_AS_REP_OLD: -- case KRB5_PADATA_PK_AS_REQ_OLD: -- p7->d.enveloped->enc_data->content_type = -- OBJ_nid2obj(NID_pkcs7_data); -- break; -- break; -- break; -- break; -- } -+ p7->d.enveloped->enc_data->content_type = OBJ_nid2obj(NID_pkcs7_signed); - - *out_len = i2d_PKCS7(p7, NULL); - if (!*out_len || (p = *out = malloc(*out_len)) == NULL) { -@@ -1963,7 +1882,6 @@ cms_envelopeddata_verify(krb5_context context, - const unsigned char *p = enveloped_data; - unsigned int tmp_buf_len = 0, tmp_buf2_len = 0, vfy_buf_len = 0; - unsigned char *tmp_buf = NULL, *tmp_buf2 = NULL, *vfy_buf = NULL; -- int msg_type = 0; - - #ifdef DEBUG_ASN1 - print_buffer_bin(enveloped_data, enveloped_data_len, -@@ -1995,46 +1913,21 @@ cms_envelopeddata_verify(krb5_context context, - print_buffer_bin(tmp_buf, tmp_buf_len, "/tmp/client_enc_keypack"); - #endif - /* verify PKCS7 SignedData message */ -- switch (pa_type) { -- case KRB5_PADATA_PK_AS_REP: -- msg_type = CMS_ENVEL_SERVER; -- -- break; -- case KRB5_PADATA_PK_AS_REP_OLD: -- msg_type = CMS_SIGN_DRAFT9; -- break; -- default: -- pkiDebug("%s: unrecognized pa_type = %d\n", __FUNCTION__, pa_type); -- retval = KRB5KDC_ERR_PREAUTH_FAILED; -+ /* Wrap the signed data to make decoding easier in the verify routine. */ -+ retval = wrap_signeddata(tmp_buf, tmp_buf_len, &tmp_buf2, &tmp_buf2_len); -+ if (retval) { -+ pkiDebug("failed to encode signeddata\n"); - goto cleanup; - } -- /* -- * If this is the RFC style, wrap the signed data to make -- * decoding easier in the verify routine. -- * For draft9-compatible, we don't do anything because it -- * is already wrapped. -- */ -- if (msg_type == CMS_ENVEL_SERVER) { -- retval = wrap_signeddata(tmp_buf, tmp_buf_len, -- &tmp_buf2, &tmp_buf2_len); -- if (retval) { -- pkiDebug("failed to encode signeddata\n"); -- goto cleanup; -- } -- vfy_buf = tmp_buf2; -- vfy_buf_len = tmp_buf2_len; -- -- } else { -- vfy_buf = tmp_buf; -- vfy_buf_len = tmp_buf_len; -- } -+ vfy_buf = tmp_buf2; -+ vfy_buf_len = tmp_buf2_len; - - #ifdef DEBUG_ASN1 - print_buffer_bin(vfy_buf, vfy_buf_len, "/tmp/client_enc_keypack2"); - #endif - - retval = cms_signeddata_verify(context, plg_cryptoctx, req_cryptoctx, -- id_cryptoctx, msg_type, -+ id_cryptoctx, CMS_ENVEL_SERVER, - require_crl_checking, - vfy_buf, vfy_buf_len, - data, data_len, NULL, NULL, NULL); -@@ -3580,8 +3473,6 @@ pkinit_pkcs7type2oid(pkinit_plg_crypto_context cryptoctx, int pkcs7_type) - switch (pkcs7_type) { - case CMS_SIGN_CLIENT: - return cryptoctx->id_pkinit_authData; -- case CMS_SIGN_DRAFT9: -- return OBJ_nid2obj(NID_pkcs7_data); - case CMS_SIGN_SERVER: - return cryptoctx->id_pkinit_DHKeyData; - case CMS_ENVEL_SERVER: -diff --git a/src/plugins/preauth/pkinit/pkinit_lib.c b/src/plugins/preauth/pkinit/pkinit_lib.c -index d5858c424..bb2916bd5 100644 ---- a/src/plugins/preauth/pkinit/pkinit_lib.c -+++ b/src/plugins/preauth/pkinit/pkinit_lib.c -@@ -110,15 +110,6 @@ free_krb5_pa_pk_as_req(krb5_pa_pk_as_req **in) - free(*in); - } - --void --free_krb5_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 **in) --{ -- if (*in == NULL) return; -- free((*in)->signedAuthPack.data); -- free((*in)->kdcCert.data); -- free(*in); --} -- - void - free_krb5_reply_key_pack(krb5_reply_key_pack **in) - { -@@ -128,14 +119,6 @@ free_krb5_reply_key_pack(krb5_reply_key_pack **in) - free(*in); - } - --void --free_krb5_reply_key_pack_draft9(krb5_reply_key_pack_draft9 **in) --{ -- if (*in == NULL) return; -- free((*in)->replyKey.contents); -- free(*in); --} -- - void - free_krb5_auth_pack(krb5_auth_pack **in) - { -@@ -160,15 +143,6 @@ free_krb5_auth_pack(krb5_auth_pack **in) - free(*in); - } - --void --free_krb5_auth_pack_draft9(krb5_context context, -- krb5_auth_pack_draft9 **in) --{ -- if ((*in) == NULL) return; -- krb5_free_principal(context, (*in)->pkAuthenticator.kdcName); -- free(*in); --} -- - void - free_krb5_pa_pk_as_rep(krb5_pa_pk_as_rep **in) - { -@@ -187,14 +161,6 @@ free_krb5_pa_pk_as_rep(krb5_pa_pk_as_rep **in) - free(*in); - } - --void --free_krb5_pa_pk_as_rep_draft9(krb5_pa_pk_as_rep_draft9 **in) --{ -- if (*in == NULL) return; -- free((*in)->u.encKeyPack.data); -- free(*in); --} -- - void - free_krb5_external_principal_identifier(krb5_external_principal_identifier ***in) - { -@@ -261,17 +227,6 @@ init_krb5_pa_pk_as_req(krb5_pa_pk_as_req **in) - (*in)->kdcPkId.length = 0; - } - --void --init_krb5_pa_pk_as_req_draft9(krb5_pa_pk_as_req_draft9 **in) --{ -- (*in) = malloc(sizeof(krb5_pa_pk_as_req_draft9)); -- if ((*in) == NULL) return; -- (*in)->signedAuthPack.data = NULL; -- (*in)->signedAuthPack.length = 0; -- (*in)->kdcCert.data = NULL; -- (*in)->kdcCert.length = 0; --} -- - void - init_krb5_reply_key_pack(krb5_reply_key_pack **in) - { -@@ -283,15 +238,6 @@ init_krb5_reply_key_pack(krb5_reply_key_pack **in) - (*in)->asChecksum.length = 0; - } - --void --init_krb5_reply_key_pack_draft9(krb5_reply_key_pack_draft9 **in) --{ -- (*in) = malloc(sizeof(krb5_reply_key_pack_draft9)); -- if ((*in) == NULL) return; -- (*in)->replyKey.contents = NULL; -- (*in)->replyKey.length = 0; --} -- - void - init_krb5_pa_pk_as_rep(krb5_pa_pk_as_rep **in) - { -@@ -306,17 +252,6 @@ init_krb5_pa_pk_as_rep(krb5_pa_pk_as_rep **in) - (*in)->u.dh_Info.kdfID = NULL; - } - --void --init_krb5_pa_pk_as_rep_draft9(krb5_pa_pk_as_rep_draft9 **in) --{ -- (*in) = malloc(sizeof(krb5_pa_pk_as_rep_draft9)); -- if ((*in) == NULL) return; -- (*in)->u.dhSignedData.length = 0; -- (*in)->u.dhSignedData.data = NULL; -- (*in)->u.encKeyPack.length = 0; -- (*in)->u.encKeyPack.data = NULL; --} -- - void - init_krb5_subject_pk_info(krb5_subject_pk_info **in) - { -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index 6aa646cc6..c44be9c74 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -421,9 +421,7 @@ pkinit_server_verify_padata(krb5_context context, - krb5_error_code retval = 0; - krb5_data authp_data = {0, 0, NULL}, krb5_authz = {0, 0, NULL}; - krb5_pa_pk_as_req *reqp = NULL; -- krb5_pa_pk_as_req_draft9 *reqp9 = NULL; - krb5_auth_pack *auth_pack = NULL; -- krb5_auth_pack_draft9 *auth_pack9 = NULL; - pkinit_kdc_context plgctx = NULL; - pkinit_kdc_req_context reqctx = NULL; - krb5_checksum cksum = {0, 0, 0, NULL}; -@@ -464,58 +462,32 @@ pkinit_server_verify_padata(krb5_context context, - - PADATA_TO_KRB5DATA(data, &k5data); - -- switch ((int)data->pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- TRACE_PKINIT_SERVER_PADATA_VERIFY(context); -- retval = k5int_decode_krb5_pa_pk_as_req(&k5data, &reqp); -- if (retval) { -- pkiDebug("decode_krb5_pa_pk_as_req failed\n"); -- goto cleanup; -- } --#ifdef DEBUG_ASN1 -- print_buffer_bin(reqp->signedAuthPack.data, -- reqp->signedAuthPack.length, -- "/tmp/kdc_signed_data"); --#endif -- retval = cms_signeddata_verify(context, plgctx->cryptoctx, -- reqctx->cryptoctx, plgctx->idctx, CMS_SIGN_CLIENT, -- plgctx->opts->require_crl_checking, -- (unsigned char *) -- reqp->signedAuthPack.data, reqp->signedAuthPack.length, -- (unsigned char **)&authp_data.data, -- &authp_data.length, -- (unsigned char **)&krb5_authz.data, -- &krb5_authz.length, &is_signed); -- break; -- case KRB5_PADATA_PK_AS_REP_OLD: -- case KRB5_PADATA_PK_AS_REQ_OLD: -- TRACE_PKINIT_SERVER_PADATA_VERIFY_OLD(context); -- retval = k5int_decode_krb5_pa_pk_as_req_draft9(&k5data, &reqp9); -- if (retval) { -- pkiDebug("decode_krb5_pa_pk_as_req_draft9 failed\n"); -- goto cleanup; -- } --#ifdef DEBUG_ASN1 -- print_buffer_bin(reqp9->signedAuthPack.data, -- reqp9->signedAuthPack.length, -- "/tmp/kdc_signed_data_draft9"); --#endif -- -- retval = cms_signeddata_verify(context, plgctx->cryptoctx, -- reqctx->cryptoctx, plgctx->idctx, CMS_SIGN_DRAFT9, -- plgctx->opts->require_crl_checking, -- (unsigned char *) -- reqp9->signedAuthPack.data, reqp9->signedAuthPack.length, -- (unsigned char **)&authp_data.data, -- &authp_data.length, -- (unsigned char **)&krb5_authz.data, -- &krb5_authz.length, NULL); -- break; -- default: -+ if (data->pa_type != KRB5_PADATA_PK_AS_REQ) { - pkiDebug("unrecognized pa_type = %d\n", data->pa_type); - retval = EINVAL; - goto cleanup; - } -+ -+ TRACE_PKINIT_SERVER_PADATA_VERIFY(context); -+ retval = k5int_decode_krb5_pa_pk_as_req(&k5data, &reqp); -+ if (retval) { -+ pkiDebug("decode_krb5_pa_pk_as_req failed\n"); -+ goto cleanup; -+ } -+#ifdef DEBUG_ASN1 -+ print_buffer_bin(reqp->signedAuthPack.data, reqp->signedAuthPack.length, -+ "/tmp/kdc_signed_data"); -+#endif -+ retval = cms_signeddata_verify(context, plgctx->cryptoctx, -+ reqctx->cryptoctx, plgctx->idctx, -+ CMS_SIGN_CLIENT, -+ plgctx->opts->require_crl_checking, -+ (unsigned char *)reqp->signedAuthPack.data, -+ reqp->signedAuthPack.length, -+ (unsigned char **)&authp_data.data, -+ &authp_data.length, -+ (unsigned char **)&krb5_authz.data, -+ &krb5_authz.length, &is_signed); - if (retval) { - TRACE_PKINIT_SERVER_PADATA_VERIFY_FAIL(context); - goto cleanup; -@@ -541,118 +513,88 @@ pkinit_server_verify_padata(krb5_context context, - #endif - - OCTETDATA_TO_KRB5DATA(&authp_data, &k5data); -- switch ((int)data->pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- retval = k5int_decode_krb5_auth_pack(&k5data, &auth_pack); -+ retval = k5int_decode_krb5_auth_pack(&k5data, &auth_pack); -+ if (retval) { -+ pkiDebug("failed to decode krb5_auth_pack\n"); -+ goto cleanup; -+ } -+ -+ retval = krb5_check_clockskew(context, auth_pack->pkAuthenticator.ctime); -+ if (retval) -+ goto cleanup; -+ -+ /* check dh parameters */ -+ if (auth_pack->clientPublicValue != NULL) { -+ retval = server_check_dh(context, plgctx->cryptoctx, -+ reqctx->cryptoctx, plgctx->idctx, -+ &auth_pack->clientPublicValue->algorithm.parameters, -+ plgctx->opts->dh_min_bits); - if (retval) { -- pkiDebug("failed to decode krb5_auth_pack\n"); -+ pkiDebug("bad dh parameters\n"); - goto cleanup; - } -- -- retval = krb5_check_clockskew(context, -- auth_pack->pkAuthenticator.ctime); -- if (retval) -- goto cleanup; -- -- /* check dh parameters */ -- if (auth_pack->clientPublicValue != NULL) { -- retval = server_check_dh(context, plgctx->cryptoctx, -- reqctx->cryptoctx, plgctx->idctx, -- &auth_pack->clientPublicValue->algorithm.parameters, -- plgctx->opts->dh_min_bits); -- -- if (retval) { -- pkiDebug("bad dh parameters\n"); -- goto cleanup; -- } -- } else if (!is_signed) { -- /*Anonymous pkinit requires DH*/ -- retval = KRB5KDC_ERR_PREAUTH_FAILED; -- krb5_set_error_message(context, retval, -- _("Anonymous pkinit without DH public " -- "value not supported.")); -- goto cleanup; -- } -- der_req = cb->request_body(context, rock); -- retval = krb5_c_make_checksum(context, CKSUMTYPE_NIST_SHA, NULL, -- 0, der_req, &cksum); -- if (retval) { -- pkiDebug("unable to calculate AS REQ checksum\n"); -- goto cleanup; -- } -- if (cksum.length != auth_pack->pkAuthenticator.paChecksum.length || -- k5_bcmp(cksum.contents, -- auth_pack->pkAuthenticator.paChecksum.contents, -- cksum.length) != 0) { -- pkiDebug("failed to match the checksum\n"); -+ } else if (!is_signed) { -+ /*Anonymous pkinit requires DH*/ -+ retval = KRB5KDC_ERR_PREAUTH_FAILED; -+ krb5_set_error_message(context, retval, -+ _("Anonymous pkinit without DH public " -+ "value not supported.")); -+ goto cleanup; -+ } -+ der_req = cb->request_body(context, rock); -+ retval = krb5_c_make_checksum(context, CKSUMTYPE_NIST_SHA, NULL, 0, -+ der_req, &cksum); -+ if (retval) { -+ pkiDebug("unable to calculate AS REQ checksum\n"); -+ goto cleanup; -+ } -+ if (cksum.length != auth_pack->pkAuthenticator.paChecksum.length || -+ k5_bcmp(cksum.contents, auth_pack->pkAuthenticator.paChecksum.contents, -+ cksum.length) != 0) { -+ pkiDebug("failed to match the checksum\n"); - #ifdef DEBUG_CKSUM -- pkiDebug("calculating checksum on buf size (%d)\n", -- req_pkt->length); -- print_buffer(req_pkt->data, req_pkt->length); -- pkiDebug("received checksum type=%d size=%d ", -- auth_pack->pkAuthenticator.paChecksum.checksum_type, -+ pkiDebug("calculating checksum on buf size (%d)\n", req_pkt->length); -+ print_buffer(req_pkt->data, req_pkt->length); -+ pkiDebug("received checksum type=%d size=%d ", -+ auth_pack->pkAuthenticator.paChecksum.checksum_type, -+ auth_pack->pkAuthenticator.paChecksum.length); -+ print_buffer(auth_pack->pkAuthenticator.paChecksum.contents, - auth_pack->pkAuthenticator.paChecksum.length); -- print_buffer(auth_pack->pkAuthenticator.paChecksum.contents, -- auth_pack->pkAuthenticator.paChecksum.length); -- pkiDebug("expected checksum type=%d size=%d ", -- cksum.checksum_type, cksum.length); -- print_buffer(cksum.contents, cksum.length); -+ pkiDebug("expected checksum type=%d size=%d ", -+ cksum.checksum_type, cksum.length); -+ print_buffer(cksum.contents, cksum.length); - #endif - -- retval = KRB5KDC_ERR_PA_CHECKSUM_MUST_BE_INCLUDED; -- goto cleanup; -- } -- -- ftoken = auth_pack->pkAuthenticator.freshnessToken; -- if (ftoken != NULL) { -- retval = cb->check_freshness_token(context, rock, ftoken); -- if (retval) -- goto cleanup; -- valid_freshness_token = TRUE; -- } -- -- /* check if kdcPkId present and match KDC's subjectIdentifier */ -- if (reqp->kdcPkId.data != NULL) { -- int valid_kdcPkId = 0; -- retval = pkinit_check_kdc_pkid(context, plgctx->cryptoctx, -- reqctx->cryptoctx, plgctx->idctx, -- (unsigned char *)reqp->kdcPkId.data, -- reqp->kdcPkId.length, &valid_kdcPkId); -- if (retval) -- goto cleanup; -- if (!valid_kdcPkId) -- pkiDebug("kdcPkId in AS_REQ does not match KDC's cert" -- "RFC says to ignore and proceed\n"); -- -- } -- /* remember the decoded auth_pack for verify_padata routine */ -- reqctx->rcv_auth_pack = auth_pack; -- auth_pack = NULL; -- break; -- case KRB5_PADATA_PK_AS_REP_OLD: -- case KRB5_PADATA_PK_AS_REQ_OLD: -- retval = k5int_decode_krb5_auth_pack_draft9(&k5data, &auth_pack9); -- if (retval) { -- pkiDebug("failed to decode krb5_auth_pack_draft9\n"); -- goto cleanup; -- } -- if (auth_pack9->clientPublicValue != NULL) { -- retval = server_check_dh(context, plgctx->cryptoctx, -- reqctx->cryptoctx, plgctx->idctx, -- &auth_pack9->clientPublicValue->algorithm.parameters, -- plgctx->opts->dh_min_bits); -- -- if (retval) { -- pkiDebug("bad dh parameters\n"); -- goto cleanup; -- } -- } -- /* remember the decoded auth_pack for verify_padata routine */ -- reqctx->rcv_auth_pack9 = auth_pack9; -- auth_pack9 = NULL; -- break; -+ retval = KRB5KDC_ERR_PA_CHECKSUM_MUST_BE_INCLUDED; -+ goto cleanup; - } - -+ ftoken = auth_pack->pkAuthenticator.freshnessToken; -+ if (ftoken != NULL) { -+ retval = cb->check_freshness_token(context, rock, ftoken); -+ if (retval) -+ goto cleanup; -+ valid_freshness_token = TRUE; -+ } -+ -+ /* check if kdcPkId present and match KDC's subjectIdentifier */ -+ if (reqp->kdcPkId.data != NULL) { -+ int valid_kdcPkId = 0; -+ retval = pkinit_check_kdc_pkid(context, plgctx->cryptoctx, -+ reqctx->cryptoctx, plgctx->idctx, -+ (unsigned char *)reqp->kdcPkId.data, -+ reqp->kdcPkId.length, &valid_kdcPkId); -+ if (retval) -+ goto cleanup; -+ if (!valid_kdcPkId) { -+ pkiDebug("kdcPkId in AS_REQ does not match KDC's cert; " -+ "RFC says to ignore and proceed\n"); -+ } -+ } -+ /* remember the decoded auth_pack for verify_padata routine */ -+ reqctx->rcv_auth_pack = auth_pack; -+ auth_pack = NULL; -+ - if (is_signed) { - retval = check_log_freshness(context, plgctx, request, - valid_freshness_token); -@@ -682,21 +624,13 @@ cleanup: - pkiDebug("pkinit_create_edata failed\n"); - } - -- switch ((int)data->pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- free_krb5_pa_pk_as_req(&reqp); -- free(cksum.contents); -- break; -- case KRB5_PADATA_PK_AS_REP_OLD: -- case KRB5_PADATA_PK_AS_REQ_OLD: -- free_krb5_pa_pk_as_req_draft9(&reqp9); -- } -+ free_krb5_pa_pk_as_req(&reqp); -+ free(cksum.contents); - free(authp_data.data); - free(krb5_authz.data); - if (reqctx != NULL) - pkinit_fini_kdc_req_context(context, reqctx); - free_krb5_auth_pack(&auth_pack); -- free_krb5_auth_pack_draft9(context, &auth_pack9); - - (*respond)(arg, retval, modreq, e_data, NULL); - } -@@ -817,7 +751,6 @@ pkinit_server_return_padata(krb5_context context, - krb5_error_code retval = 0; - krb5_data scratch = {0, 0, NULL}; - krb5_pa_pk_as_req *reqp = NULL; -- krb5_pa_pk_as_req_draft9 *reqp9 = NULL; - int i = 0; - - unsigned char *subjectPublicKey = NULL; -@@ -828,21 +761,17 @@ pkinit_server_return_padata(krb5_context context, - krb5_kdc_dh_key_info dhkey_info; - krb5_data *encoded_dhkey_info = NULL; - krb5_pa_pk_as_rep *rep = NULL; -- krb5_pa_pk_as_rep_draft9 *rep9 = NULL; - krb5_data *out_data = NULL; - krb5_data secret; - - krb5_enctype enctype = -1; - - krb5_reply_key_pack *key_pack = NULL; -- krb5_reply_key_pack_draft9 *key_pack9 = NULL; - krb5_data *encoded_key_pack = NULL; - - pkinit_kdc_context plgctx; - pkinit_kdc_req_context reqctx; - -- int fixed_keypack = 0; -- - *send_pa = NULL; - if (padata->pa_type == KRB5_PADATA_PKINIT_KX) { - return return_pkinit_kx(context, request, reply, -@@ -886,29 +815,13 @@ pkinit_server_return_padata(krb5_context context, - goto cleanup; - } - -- switch((int)reqctx->pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- init_krb5_pa_pk_as_rep(&rep); -- if (rep == NULL) { -- retval = ENOMEM; -- goto cleanup; -- } -- /* let's assume it's RSA. we'll reset it to DH if needed */ -- rep->choice = choice_pa_pk_as_rep_encKeyPack; -- break; -- case KRB5_PADATA_PK_AS_REP_OLD: -- case KRB5_PADATA_PK_AS_REQ_OLD: -- init_krb5_pa_pk_as_rep_draft9(&rep9); -- if (rep9 == NULL) { -- retval = ENOMEM; -- goto cleanup; -- } -- rep9->choice = choice_pa_pk_as_rep_draft9_encKeyPack; -- break; -- default: -- retval = KRB5KDC_ERR_PREAUTH_FAILED; -+ init_krb5_pa_pk_as_rep(&rep); -+ if (rep == NULL) { -+ retval = ENOMEM; - goto cleanup; - } -+ /* let's assume it's RSA. we'll reset it to DH if needed */ -+ rep->choice = choice_pa_pk_as_rep_encKeyPack; - - if (reqctx->rcv_auth_pack != NULL && - reqctx->rcv_auth_pack->clientPublicValue != NULL) { -@@ -917,18 +830,7 @@ pkinit_server_return_padata(krb5_context context, - subjectPublicKey_len = - reqctx->rcv_auth_pack->clientPublicValue->subjectPublicKey.length; - rep->choice = choice_pa_pk_as_rep_dhInfo; -- } else if (reqctx->rcv_auth_pack9 != NULL && -- reqctx->rcv_auth_pack9->clientPublicValue != NULL) { -- subjectPublicKey = (unsigned char *) -- reqctx->rcv_auth_pack9->clientPublicValue->subjectPublicKey.data; -- subjectPublicKey_len = -- reqctx->rcv_auth_pack9->clientPublicValue->subjectPublicKey.length; -- rep9->choice = choice_pa_pk_as_rep_draft9_dhSignedData; -- } - -- /* if this DH, then process finish computing DH key */ -- if (rep != NULL && (rep->choice == choice_pa_pk_as_rep_dhInfo || -- rep->choice == choice_pa_pk_as_rep_draft9_dhSignedData)) { - pkiDebug("received DH key delivery AS REQ\n"); - retval = server_process_dh(context, plgctx->cryptoctx, - reqctx->cryptoctx, plgctx->idctx, subjectPublicKey, -@@ -938,10 +840,6 @@ pkinit_server_return_padata(krb5_context context, - pkiDebug("failed to process/create dh paramters\n"); - goto cleanup; - } -- } -- if ((rep9 != NULL && -- rep9->choice == choice_pa_pk_as_rep_draft9_dhSignedData) || -- (rep != NULL && rep->choice == choice_pa_pk_as_rep_dhInfo)) { - - /* - * This is DH, so don't generate the key until after we -@@ -966,36 +864,18 @@ pkinit_server_return_padata(krb5_context context, - "/tmp/kdc_dh_key_info"); - #endif - -- switch ((int)padata->pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- retval = cms_signeddata_create(context, plgctx->cryptoctx, -- reqctx->cryptoctx, plgctx->idctx, CMS_SIGN_SERVER, 1, -- (unsigned char *) -- encoded_dhkey_info->data, -- encoded_dhkey_info->length, -- (unsigned char **) -- &rep->u.dh_Info.dhSignedData.data, -- &rep->u.dh_Info.dhSignedData.length); -- if (retval) { -- pkiDebug("failed to create pkcs7 signed data\n"); -- goto cleanup; -- } -- break; -- case KRB5_PADATA_PK_AS_REP_OLD: -- case KRB5_PADATA_PK_AS_REQ_OLD: -- retval = cms_signeddata_create(context, plgctx->cryptoctx, -- reqctx->cryptoctx, plgctx->idctx, CMS_SIGN_DRAFT9, 1, -- (unsigned char *) -- encoded_dhkey_info->data, -- encoded_dhkey_info->length, -- (unsigned char **) -- &rep9->u.dhSignedData.data, -- &rep9->u.dhSignedData.length); -- if (retval) { -- pkiDebug("failed to create pkcs7 signed data\n"); -- goto cleanup; -- } -- break; -+ retval = cms_signeddata_create(context, plgctx->cryptoctx, -+ reqctx->cryptoctx, plgctx->idctx, -+ CMS_SIGN_SERVER, 1, -+ (unsigned char *) -+ encoded_dhkey_info->data, -+ encoded_dhkey_info->length, -+ (unsigned char **) -+ &rep->u.dh_Info.dhSignedData.data, -+ &rep->u.dh_Info.dhSignedData.length); -+ if (retval) { -+ pkiDebug("failed to create pkcs7 signed data\n"); -+ goto cleanup; - } - - } else { -@@ -1007,102 +887,49 @@ pkinit_server_return_padata(krb5_context context, - goto cleanup; - } - -- /* check if PA_TYPE of KRB5_PADATA_AS_CHECKSUM (132) is present which -- * means the client is requesting that a checksum is send back instead -- * of the nonce. -- */ -- for (i = 0; request->padata[i] != NULL; i++) { -- pkiDebug("%s: Checking pa_type 0x%08x\n", -- __FUNCTION__, request->padata[i]->pa_type); -- if (request->padata[i]->pa_type == KRB5_PADATA_AS_CHECKSUM) -- fixed_keypack = 1; -+ init_krb5_reply_key_pack(&key_pack); -+ if (key_pack == NULL) { -+ retval = ENOMEM; -+ goto cleanup; - } -- pkiDebug("%s: return checksum instead of nonce = %d\n", -- __FUNCTION__, fixed_keypack); - -- /* if this is an RFC reply or draft9 client requested a checksum -- * in the reply instead of the nonce, create an RFC-style keypack -- */ -- if ((int)padata->pa_type == KRB5_PADATA_PK_AS_REQ || fixed_keypack) { -- init_krb5_reply_key_pack(&key_pack); -- if (key_pack == NULL) { -- retval = ENOMEM; -- goto cleanup; -- } -- -- retval = krb5_c_make_checksum(context, 0, -- encrypting_key, KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, -- req_pkt, &key_pack->asChecksum); -- if (retval) { -- pkiDebug("unable to calculate AS REQ checksum\n"); -- goto cleanup; -- } -+ retval = krb5_c_make_checksum(context, 0, encrypting_key, -+ KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, -+ req_pkt, &key_pack->asChecksum); -+ if (retval) { -+ pkiDebug("unable to calculate AS REQ checksum\n"); -+ goto cleanup; -+ } - #ifdef DEBUG_CKSUM -- pkiDebug("calculating checksum on buf size = %d\n", req_pkt->length); -- print_buffer(req_pkt->data, req_pkt->length); -- pkiDebug("checksum size = %d\n", key_pack->asChecksum.length); -- print_buffer(key_pack->asChecksum.contents, -- key_pack->asChecksum.length); -- pkiDebug("encrypting key (%d)\n", encrypting_key->length); -- print_buffer(encrypting_key->contents, encrypting_key->length); -+ pkiDebug("calculating checksum on buf size = %d\n", req_pkt->length); -+ print_buffer(req_pkt->data, req_pkt->length); -+ pkiDebug("checksum size = %d\n", key_pack->asChecksum.length); -+ print_buffer(key_pack->asChecksum.contents, -+ key_pack->asChecksum.length); -+ pkiDebug("encrypting key (%d)\n", encrypting_key->length); -+ print_buffer(encrypting_key->contents, encrypting_key->length); - #endif - -- krb5_copy_keyblock_contents(context, encrypting_key, -- &key_pack->replyKey); -+ krb5_copy_keyblock_contents(context, encrypting_key, -+ &key_pack->replyKey); - -- retval = k5int_encode_krb5_reply_key_pack(key_pack, -- &encoded_key_pack); -- if (retval) { -- pkiDebug("failed to encode reply_key_pack\n"); -- goto cleanup; -- } -+ retval = k5int_encode_krb5_reply_key_pack(key_pack, -+ &encoded_key_pack); -+ if (retval) { -+ pkiDebug("failed to encode reply_key_pack\n"); -+ goto cleanup; - } - -- switch ((int)padata->pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- rep->choice = choice_pa_pk_as_rep_encKeyPack; -- retval = cms_envelopeddata_create(context, plgctx->cryptoctx, -- reqctx->cryptoctx, plgctx->idctx, padata->pa_type, 1, -- (unsigned char *) -- encoded_key_pack->data, -- encoded_key_pack->length, -- (unsigned char **) -- &rep->u.encKeyPack.data, -- &rep->u.encKeyPack.length); -- break; -- case KRB5_PADATA_PK_AS_REP_OLD: -- case KRB5_PADATA_PK_AS_REQ_OLD: -- /* if the request is from the broken draft9 client that -- * expects back a nonce, create it now -- */ -- if (!fixed_keypack) { -- init_krb5_reply_key_pack_draft9(&key_pack9); -- if (key_pack9 == NULL) { -- retval = ENOMEM; -- goto cleanup; -- } -- key_pack9->nonce = reqctx->rcv_auth_pack9->pkAuthenticator.nonce; -- krb5_copy_keyblock_contents(context, encrypting_key, -- &key_pack9->replyKey); -- -- retval = k5int_encode_krb5_reply_key_pack_draft9(key_pack9, -- &encoded_key_pack); -- if (retval) { -- pkiDebug("failed to encode reply_key_pack\n"); -- goto cleanup; -- } -- } -- -- rep9->choice = choice_pa_pk_as_rep_draft9_encKeyPack; -- retval = cms_envelopeddata_create(context, plgctx->cryptoctx, -- reqctx->cryptoctx, plgctx->idctx, padata->pa_type, 1, -- (unsigned char *) -- encoded_key_pack->data, -- encoded_key_pack->length, -- (unsigned char **) -- &rep9->u.encKeyPack.data, &rep9->u.encKeyPack.length); -- break; -- } -+ rep->choice = choice_pa_pk_as_rep_encKeyPack; -+ retval = cms_envelopeddata_create(context, plgctx->cryptoctx, -+ reqctx->cryptoctx, plgctx->idctx, -+ padata->pa_type, 1, -+ (unsigned char *) -+ encoded_key_pack->data, -+ encoded_key_pack->length, -+ (unsigned char **) -+ &rep->u.encKeyPack.data, -+ &rep->u.encKeyPack.length); - if (retval) { - pkiDebug("failed to create pkcs7 enveloped data: %s\n", - error_message(retval)); -@@ -1112,23 +939,12 @@ pkinit_server_return_padata(krb5_context context, - print_buffer_bin((unsigned char *)encoded_key_pack->data, - encoded_key_pack->length, - "/tmp/kdc_key_pack"); -- switch ((int)padata->pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- print_buffer_bin(rep->u.encKeyPack.data, -- rep->u.encKeyPack.length, -- "/tmp/kdc_enc_key_pack"); -- break; -- case KRB5_PADATA_PK_AS_REP_OLD: -- case KRB5_PADATA_PK_AS_REQ_OLD: -- print_buffer_bin(rep9->u.encKeyPack.data, -- rep9->u.encKeyPack.length, -- "/tmp/kdc_enc_key_pack"); -- break; -- } -+ print_buffer_bin(rep->u.encKeyPack.data, rep->u.encKeyPack.length, -+ "/tmp/kdc_enc_key_pack"); - #endif - } - -- if ((rep != NULL && rep->choice == choice_pa_pk_as_rep_dhInfo) && -+ if (rep->choice == choice_pa_pk_as_rep_dhInfo && - ((reqctx->rcv_auth_pack != NULL && - reqctx->rcv_auth_pack->supportedKDFs != NULL))) { - -@@ -1147,15 +963,7 @@ pkinit_server_return_padata(krb5_context context, - } - } - -- switch ((int)padata->pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- retval = k5int_encode_krb5_pa_pk_as_rep(rep, &out_data); -- break; -- case KRB5_PADATA_PK_AS_REP_OLD: -- case KRB5_PADATA_PK_AS_REQ_OLD: -- retval = k5int_encode_krb5_pa_pk_as_rep_draft9(rep9, &out_data); -- break; -- } -+ retval = k5int_encode_krb5_pa_pk_as_rep(rep, &out_data); - if (retval) { - pkiDebug("failed to encode AS_REP\n"); - goto cleanup; -@@ -1167,13 +975,11 @@ pkinit_server_return_padata(krb5_context context, - #endif - - /* If this is DH, we haven't computed the key yet, so do it now. */ -- if ((rep9 != NULL && -- rep9->choice == choice_pa_pk_as_rep_draft9_dhSignedData) || -- (rep != NULL && rep->choice == choice_pa_pk_as_rep_dhInfo)) { -+ if (rep->choice == choice_pa_pk_as_rep_dhInfo) { - -- /* If we're not doing draft 9, and mutually supported KDFs were found, -- * use the algorithm agility KDF. */ -- if (rep != NULL && rep->u.dh_Info.kdfID) { -+ /* If mutually supported KDFs were found, use the algorithm agility -+ * KDF. */ -+ if (rep->u.dh_Info.kdfID) { - secret.data = (char *)server_key; - secret.length = server_key_len; - -@@ -1209,15 +1015,7 @@ pkinit_server_return_padata(krb5_context context, - goto cleanup; - } - (*send_pa)->magic = KV5M_PA_DATA; -- switch ((int)padata->pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- (*send_pa)->pa_type = KRB5_PADATA_PK_AS_REP; -- break; -- case KRB5_PADATA_PK_AS_REQ_OLD: -- case KRB5_PADATA_PK_AS_REP_OLD: -- (*send_pa)->pa_type = KRB5_PADATA_PK_AS_REP_OLD; -- break; -- } -+ (*send_pa)->pa_type = KRB5_PADATA_PK_AS_REP; - (*send_pa)->length = out_data->length; - (*send_pa)->contents = (krb5_octet *) out_data->data; - -@@ -1231,23 +1029,9 @@ cleanup: - krb5_free_data(context, encoded_key_pack); - free(dh_pubkey); - free(server_key); -- -- switch ((int)padata->pa_type) { -- case KRB5_PADATA_PK_AS_REQ: -- free_krb5_pa_pk_as_req(&reqp); -- free_krb5_pa_pk_as_rep(&rep); -- free_krb5_reply_key_pack(&key_pack); -- break; -- case KRB5_PADATA_PK_AS_REP_OLD: -- case KRB5_PADATA_PK_AS_REQ_OLD: -- free_krb5_pa_pk_as_req_draft9(&reqp9); -- free_krb5_pa_pk_as_rep_draft9(&rep9); -- if (!fixed_keypack) -- free_krb5_reply_key_pack_draft9(&key_pack9); -- else -- free_krb5_reply_key_pack(&key_pack); -- break; -- } -+ free_krb5_pa_pk_as_req(&reqp); -+ free_krb5_pa_pk_as_rep(&rep); -+ free_krb5_reply_key_pack(&key_pack); - - if (retval) - pkiDebug("pkinit_verify_padata failure"); -@@ -1265,8 +1049,6 @@ pkinit_server_get_flags(krb5_context kcontext, krb5_preauthtype patype) - - static krb5_preauthtype supported_server_pa_types[] = { - KRB5_PADATA_PK_AS_REQ, -- KRB5_PADATA_PK_AS_REQ_OLD, -- KRB5_PADATA_PK_AS_REP_OLD, - KRB5_PADATA_PKINIT_KX, - 0 - }; -@@ -1796,7 +1578,6 @@ pkinit_init_kdc_req_context(krb5_context context, pkinit_kdc_req_context *ctx) - if (retval) - goto cleanup; - reqctx->rcv_auth_pack = NULL; -- reqctx->rcv_auth_pack9 = NULL; - - pkiDebug("%s: returning reqctx at %p\n", __FUNCTION__, reqctx); - *ctx = reqctx; -@@ -1822,8 +1603,6 @@ pkinit_fini_kdc_req_context(krb5_context context, void *ctx) - pkinit_fini_req_crypto(reqctx->cryptoctx); - if (reqctx->rcv_auth_pack != NULL) - free_krb5_auth_pack(&reqctx->rcv_auth_pack); -- if (reqctx->rcv_auth_pack9 != NULL) -- free_krb5_auth_pack_draft9(context, &reqctx->rcv_auth_pack9); - - free(reqctx); - } -diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h -index 4da735f80..bba3226bd 100644 ---- a/src/plugins/preauth/pkinit/pkinit_trace.h -+++ b/src/plugins/preauth/pkinit/pkinit_trace.h -@@ -49,8 +49,6 @@ - #define TRACE_PKINIT_CLIENT_KDF_OS2K(c, keyblock) \ - TRACE(c, "PKINIT client used octetstring2key to compute reply key " \ - "{keyblock}", keyblock) --#define TRACE_PKINIT_CLIENT_NO_DRAFT9(c) \ -- TRACE(c, "PKINIT client ignoring draft 9 offer from RFC 4556 KDC") - #define TRACE_PKINIT_CLIENT_NO_IDENTITY(c) \ - TRACE(c, "PKINIT client has no configured identity; giving up") - #define TRACE_PKINIT_CLIENT_REP_CHECKSUM_FAIL(c, expected, received) \ -@@ -115,8 +113,6 @@ - TRACE(c, "PKINIT server found no SAN in client cert") - #define TRACE_PKINIT_SERVER_PADATA_VERIFY(c) \ - TRACE(c, "PKINIT server verifying KRB5_PADATA_PK_AS_REQ") --#define TRACE_PKINIT_SERVER_PADATA_VERIFY_OLD(c) \ -- TRACE(c, "PKINIT server verifying KRB5_PADATA_PK_AS_REQ_OLD") - #define TRACE_PKINIT_SERVER_PADATA_VERIFY_FAIL(c) \ - TRACE(c, "PKINIT server failed to verify PA data") - #define TRACE_PKINIT_SERVER_RETURN_PADATA(c) \ -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index 1dadb1b96..93f0f2632 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -432,11 +432,9 @@ realm.kinit(realm.user_princ, - realm.klist(realm.user_princ) - realm.run([kvno, realm.host_princ]) - --# Supply the wrong PIN, and verify that we ignore the draft9 padata offer --# in the KDC method data after RFC 4556 PKINIT fails. -+# Supply the wrong PIN. - mark('PKCS11 identity, wrong PIN') --expected_trace = ('PKINIT client has no configured identity; giving up', -- 'PKINIT client ignoring draft 9 offer from RFC 4556 KDC') -+expected_trace = ('PKINIT client has no configured identity; giving up',) - realm.kinit(realm.user_princ, - flags=['-X', 'X509_user_identity=%s' % p11_identity], - password='wrong', expected_code=1, expected_trace=expected_trace) diff --git a/Remove-ccapi-related-comments-in-configure.ac.patch b/Remove-ccapi-related-comments-in-configure.ac.patch deleted file mode 100644 index 7aa672b..0000000 --- a/Remove-ccapi-related-comments-in-configure.ac.patch +++ /dev/null @@ -1,34 +0,0 @@ -From ac8df1b0977dd5aedfaeb3d10458aaf18cece29f Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 3 Apr 2019 16:01:22 -0400 -Subject: [PATCH] Remove ccapi-related comments in configure.ac - -These suggested ccapi is buildable on non-Windows, and empirically it -is not. - -(cherry picked from commit eb48b176bccf3634b9c82f588dce85125a5c4bd8) ---- - src/configure.in | 3 --- - 1 file changed, 3 deletions(-) - -diff --git a/src/configure.in b/src/configure.in -index 505dabb02..9d6825b78 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -1450,7 +1450,6 @@ V5_AC_OUTPUT_MAKEFILE(. - lib/crypto/crypto_tests - - lib/krb5 lib/krb5/error_tables lib/krb5/asn.1 lib/krb5/ccache --dnl lib/krb5/ccache/ccapi - lib/krb5/keytab lib/krb5/krb lib/krb5/rcache lib/krb5/os - lib/krb5/unicode - -@@ -1463,8 +1462,6 @@ dnl lib/krb5/ccache/ccapi - lib/krad - lib/apputils - --dnl ccapi ccapi/lib ccapi/lib/unix ccapi/server ccapi/server/unix ccapi/test -- - kdc kprop config-files build-tools man doc include - - plugins/certauth/test diff --git a/Remove-checksum-type-profile-variables.patch b/Remove-checksum-type-profile-variables.patch deleted file mode 100644 index a2a05c2..0000000 --- a/Remove-checksum-type-profile-variables.patch +++ /dev/null @@ -1,429 +0,0 @@ -From ee07471fa613fb68ddebc28577870e97cb5190cf Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 13 May 2019 14:19:57 -0400 -Subject: [PATCH] Remove checksum type profile variables - -Remove support for the krb5.conf relations ap_req_checksum_type, -kdc_req_checksum_type, and safe_checksum_type. These values were -useful for interoperating with very old KDCs, which should no longer -be deployed. - -Additionally, kdc_req_checksum_type was incorrectly documented as only -applying to single-DES keys; in practice it also worked for RC4. The -other two were not clearly documented, but safe_checksum_type did -allow use of hmac-md5-rc4 for any enctype, and ap_req_checksum_type -did not impose any limitations. - -[ghudson@mit.edu: edited commit message] - -ticket: 8804 (new) -(cherry picked from commit a5a140dc85201faf1ba3a687553058354722a1b4) -[rharwood@redhat.com: release version conflict in man pages] ---- - doc/admin/conf_files/krb5_conf.rst | 37 ------------ - src/include/k5-int.h | 6 -- - src/lib/krb5/krb/auth_con.c | 2 - - src/lib/krb5/krb/init_ctx.c | 13 ----- - src/lib/krb5/krb/send_tgs.c | 19 +------ - src/lib/krb5/krb/ser_ctx.c | 38 +------------ - src/lib/krb5/krb/t_copy_context.c | 6 -- - src/man/krb5.conf.man | 90 ++---------------------------- - 8 files changed, 7 insertions(+), 204 deletions(-) - -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index d1e1a222d..a3fb5d9f2 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -105,14 +105,6 @@ The libdefaults section may contain any of the following relations: - strong crypto. Users in affected environments should set this tag - to true until their infrastructure adopts stronger ciphers. - --**ap_req_checksum_type** -- An integer which specifies the type of AP-REQ checksum to use in -- authenticators. This variable should be unset so the appropriate -- checksum for the encryption key in use will be used. This can be -- set if backward compatibility requires a specific checksum type. -- See the **kdc_req_checksum_type** configuration option for the -- possible values and their meanings. -- - **canonicalize** - If this flag is set to true, initial ticket requests to the KDC - will request canonicalization of the client principal name, and -@@ -291,26 +283,6 @@ The libdefaults section may contain any of the following relations: - corrective factor is only used by the Kerberos library; it is not - used to change the system clock. The default value is 1. - --**kdc_req_checksum_type** -- An integer which specifies the type of checksum to use for the KDC -- requests, for compatibility with very old KDC implementations. -- This value is only used for DES keys; other keys use the preferred -- checksum type for those keys. -- -- The possible values and their meanings are as follows. -- -- ======== =============================== -- 1 CRC32 -- 2 RSA MD4 -- 3 RSA MD4 DES -- 4 DES CBC -- 7 RSA MD5 -- 8 RSA MD5 DES -- 9 NIST SHA -- 12 HMAC SHA1 DES3 -- -138 Microsoft MD5 HMAC checksum type -- ======== =============================== -- - **noaddresses** - If this flag is true, requests for initial tickets will not be - made with address restrictions set, allowing the tickets to be -@@ -359,15 +331,6 @@ The libdefaults section may contain any of the following relations: - (:ref:`duration` string.) Sets the default renewable lifetime - for initial ticket requests. The default value is 0. - --**safe_checksum_type** -- An integer which specifies the type of checksum to use for the -- KRB-SAFE requests. By default it is set to 8 (RSA MD5 DES). For -- compatibility with applications linked against DCE version 1.1 or -- earlier Kerberos libraries, use a value of 3 to use the RSA MD4 -- DES instead. This field is ignored when its value is incompatible -- with the session key type. See the **kdc_req_checksum_type** -- configuration option for the possible values and their meanings. -- - **spake_preauth_groups** - A whitespace or comma-separated list of words which specifies the - groups allowed for SPAKE preauthentication. The possible values -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 1e6a739e9..1a78fd7a9 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -182,7 +182,6 @@ typedef unsigned char u_char; - #define KRB5_CONF_ACL_FILE "acl_file" - #define KRB5_CONF_ADMIN_SERVER "admin_server" - #define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto" --#define KRB5_CONF_AP_REQ_CHECKSUM_TYPE "ap_req_checksum_type" - #define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local" - #define KRB5_CONF_AUTH_TO_LOCAL_NAMES "auth_to_local_names" - #define KRB5_CONF_CANONICALIZE "canonicalize" -@@ -241,7 +240,6 @@ typedef unsigned char u_char; - #define KRB5_CONF_KDC_LISTEN "kdc_listen" - #define KRB5_CONF_KDC_MAX_DGRAM_REPLY_SIZE "kdc_max_dgram_reply_size" - #define KRB5_CONF_KDC_PORTS "kdc_ports" --#define KRB5_CONF_KDC_REQ_CHECKSUM_TYPE "kdc_req_checksum_type" - #define KRB5_CONF_KDC_TCP_PORTS "kdc_tcp_ports" - #define KRB5_CONF_KDC_TCP_LISTEN "kdc_tcp_listen" - #define KRB5_CONF_KDC_TCP_LISTEN_BACKLOG "kdc_tcp_listen_backlog" -@@ -289,7 +287,6 @@ typedef unsigned char u_char; - #define KRB5_CONF_REJECT_BAD_TRANSIT "reject_bad_transit" - #define KRB5_CONF_RENEW_LIFETIME "renew_lifetime" - #define KRB5_CONF_RESTRICT_ANONYMOUS_TO_TGT "restrict_anonymous_to_tgt" --#define KRB5_CONF_SAFE_CHECKSUM_TYPE "safe_checksum_type" - #define KRB5_CONF_SUPPORTED_ENCTYPES "supported_enctypes" - #define KRB5_CONF_SPAKE_PREAUTH_INDICATOR "spake_preauth_indicator" - #define KRB5_CONF_SPAKE_PREAUTH_KDC_CHALLENGE "spake_preauth_kdc_challenge" -@@ -1185,9 +1182,6 @@ struct _krb5_context { - void *ser_ctx; - /* allowable clock skew */ - krb5_deltat clockskew; -- krb5_cksumtype kdc_req_sumtype; -- krb5_cksumtype default_ap_req_sumtype; -- krb5_cksumtype default_safe_sumtype; - krb5_flags kdc_default_options; - krb5_flags library_options; - krb5_boolean profile_secure; -diff --git a/src/lib/krb5/krb/auth_con.c b/src/lib/krb5/krb/auth_con.c -index c86a4af63..1dfce631c 100644 ---- a/src/lib/krb5/krb/auth_con.c -+++ b/src/lib/krb5/krb/auth_con.c -@@ -40,8 +40,6 @@ krb5_auth_con_init(krb5_context context, krb5_auth_context *auth_context) - (*auth_context)->auth_context_flags = - KRB5_AUTH_CONTEXT_DO_TIME | KRB5_AUTH_CONN_INITIALIZED; - -- (*auth_context)->req_cksumtype = context->default_ap_req_sumtype; -- (*auth_context)->safe_cksumtype = context->default_safe_sumtype; - (*auth_context)->checksum_func = NULL; - (*auth_context)->checksum_func_data = NULL; - (*auth_context)->negotiated_etype = ENCTYPE_NULL; -diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index d263d5cc5..37405728c 100644 ---- a/src/lib/krb5/krb/init_ctx.c -+++ b/src/lib/krb5/krb/init_ctx.c -@@ -258,19 +258,6 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, - get_integer(ctx, KRB5_CONF_CLOCKSKEW, DEFAULT_CLOCKSKEW, &tmp); - ctx->clockskew = tmp; - -- /* DCE 1.1 and below only support CKSUMTYPE_RSA_MD4 (2) */ -- /* DCE add kdc_req_checksum_type = 2 to krb5.conf */ -- get_integer(ctx, KRB5_CONF_KDC_REQ_CHECKSUM_TYPE, CKSUMTYPE_RSA_MD5, -- &tmp); -- ctx->kdc_req_sumtype = tmp; -- -- get_integer(ctx, KRB5_CONF_AP_REQ_CHECKSUM_TYPE, 0, &tmp); -- ctx->default_ap_req_sumtype = tmp; -- -- get_integer(ctx, KRB5_CONF_SAFE_CHECKSUM_TYPE, CKSUMTYPE_RSA_MD5_DES, -- &tmp); -- ctx->default_safe_sumtype = tmp; -- - get_integer(ctx, KRB5_CONF_KDC_DEFAULT_OPTIONS, KDC_OPT_RENEWABLE_OK, - &tmp); - ctx->kdc_default_options = tmp; -diff --git a/src/lib/krb5/krb/send_tgs.c b/src/lib/krb5/krb/send_tgs.c -index e43a5cc5b..3dda2fdaa 100644 ---- a/src/lib/krb5/krb/send_tgs.c -+++ b/src/lib/krb5/krb/send_tgs.c -@@ -53,7 +53,6 @@ tgs_construct_ap_req(krb5_context context, krb5_data *checksum_data, - krb5_creds *tgt, krb5_keyblock *subkey, - krb5_data **ap_req_asn1_out) - { -- krb5_cksumtype cksumtype; - krb5_error_code ret; - krb5_checksum checksum; - krb5_authenticator authent; -@@ -67,24 +66,8 @@ tgs_construct_ap_req(krb5_context context, krb5_data *checksum_data, - memset(&ap_req, 0, sizeof(ap_req)); - memset(&authent_enc, 0, sizeof(authent_enc)); - -- /* Determine the authenticator checksum type. */ -- switch (tgt->keyblock.enctype) { -- case ENCTYPE_DES_CBC_CRC: -- case ENCTYPE_DES_CBC_MD4: -- case ENCTYPE_DES_CBC_MD5: -- case ENCTYPE_ARCFOUR_HMAC: -- case ENCTYPE_ARCFOUR_HMAC_EXP: -- cksumtype = context->kdc_req_sumtype; -- break; -- default: -- ret = krb5int_c_mandatory_cksumtype(context, tgt->keyblock.enctype, -- &cksumtype); -- if (ret) -- goto cleanup; -- } -- - /* Generate checksum. */ -- ret = krb5_c_make_checksum(context, cksumtype, &tgt->keyblock, -+ ret = krb5_c_make_checksum(context, 0, &tgt->keyblock, - KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, checksum_data, - &checksum); - if (ret) -diff --git a/src/lib/krb5/krb/ser_ctx.c b/src/lib/krb5/krb/ser_ctx.c -index a9f50b239..39f656322 100644 ---- a/src/lib/krb5/krb/ser_ctx.c -+++ b/src/lib/krb5/krb/ser_ctx.c -@@ -124,9 +124,6 @@ krb5_context_size(krb5_context kcontext, krb5_pointer arg, size_t *sizep) - * krb5_int32 for n_tgs_etypes*sizeof(krb5_int32) - * nktypes*sizeof(krb5_int32) for tgs_etypes. - * krb5_int32 for clockskew -- * krb5_int32 for kdc_req_sumtype -- * krb5_int32 for ap_req_sumtype -- * krb5_int32 for safe_sumtype - * krb5_int32 for kdc_default_options - * krb5_int32 for library_options - * krb5_int32 for profile_secure -@@ -139,7 +136,7 @@ krb5_context_size(krb5_context kcontext, krb5_pointer arg, size_t *sizep) - kret = EINVAL; - if ((context = (krb5_context) arg)) { - /* Calculate base length */ -- required = (14 * sizeof(krb5_int32) + -+ required = (11 * sizeof(krb5_int32) + - (etypes_len(context->in_tkt_etypes) * sizeof(krb5_int32)) + - (etypes_len(context->tgs_etypes) * sizeof(krb5_int32))); - -@@ -255,24 +252,6 @@ krb5_context_externalize(krb5_context kcontext, krb5_pointer arg, krb5_octet **b - if (kret) - return (kret); - -- /* Now kdc_req_sumtype */ -- kret = krb5_ser_pack_int32((krb5_int32) context->kdc_req_sumtype, -- &bp, &remain); -- if (kret) -- return (kret); -- -- /* Now default ap_req_sumtype */ -- kret = krb5_ser_pack_int32((krb5_int32) context->default_ap_req_sumtype, -- &bp, &remain); -- if (kret) -- return (kret); -- -- /* Now default safe_sumtype */ -- kret = krb5_ser_pack_int32((krb5_int32) context->default_safe_sumtype, -- &bp, &remain); -- if (kret) -- return (kret); -- - /* Now kdc_default_options */ - kret = krb5_ser_pack_int32((krb5_int32) context->kdc_default_options, - &bp, &remain); -@@ -426,21 +405,6 @@ krb5_context_internalize(krb5_context kcontext, krb5_pointer *argp, krb5_octet * - goto cleanup; - context->clockskew = (krb5_deltat) ibuf; - -- /* kdc_req_sumtype */ -- if ((kret = krb5_ser_unpack_int32(&ibuf, &bp, &remain))) -- goto cleanup; -- context->kdc_req_sumtype = (krb5_cksumtype) ibuf; -- -- /* default ap_req_sumtype */ -- if ((kret = krb5_ser_unpack_int32(&ibuf, &bp, &remain))) -- goto cleanup; -- context->default_ap_req_sumtype = (krb5_cksumtype) ibuf; -- -- /* default_safe_sumtype */ -- if ((kret = krb5_ser_unpack_int32(&ibuf, &bp, &remain))) -- goto cleanup; -- context->default_safe_sumtype = (krb5_cksumtype) ibuf; -- - /* kdc_default_options */ - if ((kret = krb5_ser_unpack_int32(&ibuf, &bp, &remain))) - goto cleanup; -diff --git a/src/lib/krb5/krb/t_copy_context.c b/src/lib/krb5/krb/t_copy_context.c -index a6e48cd25..22be2198b 100644 ---- a/src/lib/krb5/krb/t_copy_context.c -+++ b/src/lib/krb5/krb/t_copy_context.c -@@ -77,9 +77,6 @@ check_context(krb5_context c, krb5_context r) - check(c->os_context.os_flags == r->os_context.os_flags); - compare_string(c->os_context.default_ccname, r->os_context.default_ccname); - check(c->clockskew == r->clockskew); -- check(c->kdc_req_sumtype == r->kdc_req_sumtype); -- check(c->default_ap_req_sumtype == r->default_ap_req_sumtype); -- check(c->default_safe_sumtype == r->default_safe_sumtype); - check(c->kdc_default_options == r->kdc_default_options); - check(c->library_options == r->library_options); - check(c->profile_secure == r->profile_secure); -@@ -136,9 +133,6 @@ main(int argc, char **argv) - check(krb5_cc_set_default_name(ctx, "defccname") == 0); - check(krb5_set_default_realm(ctx, "defrealm") == 0); - ctx->clockskew = 18; -- ctx->kdc_req_sumtype = CKSUMTYPE_NIST_SHA; -- ctx->default_ap_req_sumtype = CKSUMTYPE_HMAC_SHA1_96_AES128; -- ctx->default_safe_sumtype = CKSUMTYPE_HMAC_SHA1_96_AES256; - ctx->kdc_default_options = KDC_OPT_FORWARDABLE; - ctx->library_options = 0; - ctx->profile_secure = TRUE; -diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man -index 2a7af6aa4..433f38d71 100644 ---- a/src/man/krb5.conf.man -+++ b/src/man/krb5.conf.man -@@ -1,6 +1,6 @@ - .\" Man page generated from reStructuredText. - . --.TH "KRB5.CONF" "5" " " "1.17.1" "MIT Kerberos" -+.TH "KRB5.CONF" "5" " " "1.18" "MIT Kerberos" - .SH NAME - krb5.conf \- Kerberos configuration file - . -@@ -188,14 +188,6 @@ failures in existing Kerberos infrastructures that do not support - strong crypto. Users in affected environments should set this tag - to true until their infrastructure adopts stronger ciphers. - .TP --\fBap_req_checksum_type\fP --An integer which specifies the type of AP\-REQ checksum to use in --authenticators. This variable should be unset so the appropriate --checksum for the encryption key in use will be used. This can be --set if backward compatibility requires a specific checksum type. --See the \fBkdc_req_checksum_type\fP configuration option for the --possible values and their meanings. --.TP - \fBcanonicalize\fP - If this flag is set to true, initial ticket requests to the KDC - will request canonicalization of the client principal name, and -@@ -277,6 +269,10 @@ hostnames for use in service principal names. Setting this flag - to false can improve security by reducing reliance on DNS, but - means that short hostnames will not be canonicalized to - fully\-qualified hostnames. The default value is true. -+.sp -+If this option is set to \fBfallback\fP (new in release 1.18), DNS -+canonicalization will only be performed the server hostname is not -+found with the original name when requesting credentials. - .TP - \fBdns_lookup_kdc\fP - Indicate whether DNS SRV records should be used to locate the KDCs -@@ -370,73 +366,6 @@ requesting service tickets or authenticating to services. This - corrective factor is only used by the Kerberos library; it is not - used to change the system clock. The default value is 1. - .TP --\fBkdc_req_checksum_type\fP --An integer which specifies the type of checksum to use for the KDC --requests, for compatibility with very old KDC implementations. --This value is only used for DES keys; other keys use the preferred --checksum type for those keys. --.sp --The possible values and their meanings are as follows. --.TS --center; --|l|l|. --_ --T{ --1 --T} T{ --CRC32 --T} --_ --T{ --2 --T} T{ --RSA MD4 --T} --_ --T{ --3 --T} T{ --RSA MD4 DES --T} --_ --T{ --4 --T} T{ --DES CBC --T} --_ --T{ --7 --T} T{ --RSA MD5 --T} --_ --T{ --8 --T} T{ --RSA MD5 DES --T} --_ --T{ --9 --T} T{ --NIST SHA --T} --_ --T{ --12 --T} T{ --HMAC SHA1 DES3 --T} --_ --T{ --\-138 --T} T{ --Microsoft MD5 HMAC checksum type --T} --_ --.TE --.TP - \fBnoaddresses\fP - If this flag is true, requests for initial tickets will not be - made with address restrictions set, allowing the tickets to be -@@ -485,15 +414,6 @@ set. The default is not to search domain components. - (duration string.) Sets the default renewable lifetime - for initial ticket requests. The default value is 0. - .TP --\fBsafe_checksum_type\fP --An integer which specifies the type of checksum to use for the --KRB\-SAFE requests. By default it is set to 8 (RSA MD5 DES). For --compatibility with applications linked against DCE version 1.1 or --earlier Kerberos libraries, use a value of 3 to use the RSA MD4 --DES instead. This field is ignored when its value is incompatible --with the session key type. See the \fBkdc_req_checksum_type\fP --configuration option for the possible values and their meanings. --.TP - \fBspake_preauth_groups\fP - A whitespace or comma\-separated list of words which specifies the - groups allowed for SPAKE preauthentication. The possible values diff --git a/Remove-confvalidator-utility.patch b/Remove-confvalidator-utility.patch deleted file mode 100644 index cb7d58d..0000000 --- a/Remove-confvalidator-utility.patch +++ /dev/null @@ -1,430 +0,0 @@ -From 1df6ae50de14c8795af7f7aea7f54eede51fd206 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 3 Apr 2019 14:58:19 -0400 -Subject: [PATCH] Remove confvalidator utility - -This utility has not been maintained with encryption types and salt -changes, which suggests it is unused. - -(cherry picked from commit 482a366793d9338e9edb504b407d7704a4bb2f8f) ---- - src/util/confvalidator/README | 25 ---- - src/util/confvalidator/confparser.py | 144 ------------------- - src/util/confvalidator/rules.yml | 13 -- - src/util/confvalidator/validator.conf | 2 - - src/util/confvalidator/validator.py | 194 -------------------------- - 5 files changed, 378 deletions(-) - delete mode 100644 src/util/confvalidator/README - delete mode 100644 src/util/confvalidator/confparser.py - delete mode 100644 src/util/confvalidator/rules.yml - delete mode 100644 src/util/confvalidator/validator.conf - delete mode 100644 src/util/confvalidator/validator.py - -diff --git a/src/util/confvalidator/README b/src/util/confvalidator/README -deleted file mode 100644 -index 7bf7a106a..000000000 ---- a/src/util/confvalidator/README -+++ /dev/null -@@ -1,25 +0,0 @@ --validator.py is a command line tool for identifying invalid attributes, values and some formating problems in Kerberos configuration files. --The list of the valid attributes is created based on the “configuration variables” section in k5-int.h and user defined attributes from the rules file. -- --Usage: -- --validator.py path [-d defPath] [-r rulesPath] [-c validatorConfPath] -- --Options: -- --path – the path to the configuration file to validate -- ---d defPath – path to the k5-int.h file. Starting from the 1.7 release this header holds the profile attribute names in the form #define KRB5_CONF_xxx ”ZZZ”. -- ---r rulesPath - path the rules file in yaml format. It may be used to manage the list of the valid attributes and to define the additional validation rules. -- ---c validatorConfPath – the same as -r and -d options, but in validator configuration file format. -- --Example: -- --python validator.py src/config-files/krb5.conf -r rules.yml -d src/include/k5-int.h --or --python validator.py src/config-files/krb5.conf -c validator.conf -- --For more details please refer to the sample files validator.conf and rules.yml -- -diff --git a/src/util/confvalidator/confparser.py b/src/util/confvalidator/confparser.py -deleted file mode 100644 -index 2fea142a5..000000000 ---- a/src/util/confvalidator/confparser.py -+++ /dev/null -@@ -1,144 +0,0 @@ --''' --Created on Jan 31, 2010 -- --@author: tsitkova --''' --import re --import copy --import yaml -- --class ConfParser(object): -- def __init__(self, path): -- self.configuration = self._parse(path) -- -- def walk(self): -- for trio in self._walk(self.configuration): -- yield trio -- -- def _parse(self, path): -- comment_pattern = re.compile(r'(\s*[#].*)') -- section_pattern = re.compile(r'^\s*\[(?P
    \w+)\]\s+$') -- empty_pattern = re.compile(r'^\s*$') -- equalsign_pattern = re.compile(r'=') -- -- section = None -- parser_stack = list() -- result = dict() -- value = None -- f = open(path, 'r') -- for (ln,line) in enumerate(f): -- line = comment_pattern.sub('', line) -- line = equalsign_pattern.sub(' = ',line,count=1) -- if empty_pattern.match(line) is not None: -- continue -- m = section_pattern.match(line) -- if m is not None: -- section = m.group('section') -- value = dict() -- result[section] = value -- continue -- if section is None: -- msg = 'Failed to determine section for line #%i' % ln -- raise ValueError(msg) -- try: -- value = self._parseLine(value, line, parser_stack) -- except: -- print 'Error while parsing line %i: %s' % (ln+1, line) -- raise -- f.close() -- -- if len(parser_stack): -- raise 'Parsing error.' -- -- return result -- -- def _parseLine(self, value, content, stack): -- token_pattern = re.compile(r'(?P\S+)(?=\s+)') -- attr = None -- token_stack = list() -- -- for m in token_pattern.finditer(content): -- token = m.group('token') -- if not self._validate(token): -- raise ValueError('Invalid token %s' % token) -- if token == '=': -- if len(token_stack) == 0: -- raise ValueError('Failed to find attribute.') -- elif len(token_stack) == 1: -- attr = token_stack.pop() -- else: -- value[attr] = token_stack[:-1] -- attr = token_stack[-1] -- token_stack = list() -- elif token == '{': -- if attr is None: -- raise ValueError('Failed to find attribute.') -- stack.append((attr,value)) -- value = dict() -- elif token == '}': -- if len(stack) == 0: -- raise ValueError('Failed to parse: unbalanced braces') -- if len(token_stack): -- if attr is None: -- raise ValueError('Missing attribute') -- value[attr] = token_stack -- attr = None -- token_stack = list() -- (attr,parent_value) = stack.pop() -- parent_value[attr] = value -- value = parent_value -- else: -- token_stack.append(token) -- if len(token_stack): -- if attr is None: -- raise ValueError('Missing attribute') -- value[attr] = token_stack -- -- return value -- -- def _validate(self, token): -- result = True -- for s in ['{','}']: -- if s in token and s != token: -- result = False -- -- return result -- -- def _walk(self, parsedData, path='root'): -- dirs = list() -- av = list() -- for (key, value) in parsedData.iteritems(): -- if type(value) == dict: -- new_path = path + '.' + key -- for trio in self._walk(value, new_path): -- yield trio -- dirs.append(key) -- else: -- av.append((key,value)) -- yield (path, dirs, av) -- -- -- --class ConfParserTest(ConfParser): -- def __init__(self): -- self.conf_path = '../tests/krb5.conf' -- super(ConfParserTest, self).__init__(self.conf_path) -- -- def run_tests(self): -- self._test_walk() -- -- def _test_parse(self): -- result = self._parse(self.conf_path) -- print yaml.dump(result) -- -- def _test_walk(self): -- configuration = self._parse(self.conf_path) -- for (path,dirs,av) in self.walk(): -- print path,dirs,av -- -- -- -- --if __name__ == '__main__': -- tester = ConfParserTest() -- tester.run_tests() -diff --git a/src/util/confvalidator/rules.yml b/src/util/confvalidator/rules.yml -deleted file mode 100644 -index c6ccc89fe..000000000 ---- a/src/util/confvalidator/rules.yml -+++ /dev/null -@@ -1,13 +0,0 @@ --# Extend the list of the allowed enctypes and salts as needed --Types: -- supported_enctypes: -- '(aes256-cts-hmac-sha1-96|aes256-cts|aes128-cts-hmac-sha1-96|aes128-cts|des3-hmac-sha1|des3-cbc-raw|des3-cbc-sha1|des3-hmac-sha1|rc4-hmac|arcfour-hmac-md5)(:(normal|v4))?$' -- default_tgs_enctypes: -- '(aes256-cts-hmac-sha1-96|aes256-cts|aes128-cts-hmac-sha1-96|aes128-cts|des3-hmac-sha1|des3-cbc-raw|des3-cbc-sha1|des3-hmac-sha1|rc4-hmac|arcfour-hmac-md5)' -- default_tkt_enctypes: -- '(aes256-cts-hmac-sha1-96|aes256-cts|aes128-cts-hmac-sha1-96|aes128-cts|des3-hmac-sha1|des3-cbc-raw|des3-cbc-sha1|des3-hmac-sha1|rc4-hmac|arcfour-hmac-md5)' -- --# Add all valid profile attributes that are not listed in k5-int.h --Attributes: -- - logging -- - dbmodules -diff --git a/src/util/confvalidator/validator.conf b/src/util/confvalidator/validator.conf -deleted file mode 100644 -index 71e205c3b..000000000 ---- a/src/util/confvalidator/validator.conf -+++ /dev/null -@@ -1,2 +0,0 @@ --RulesPath=./rules.yml --HfilePath=../../include/k5-int.h -diff --git a/src/util/confvalidator/validator.py b/src/util/confvalidator/validator.py -deleted file mode 100644 -index d739bc091..000000000 ---- a/src/util/confvalidator/validator.py -+++ /dev/null -@@ -1,194 +0,0 @@ --''' --Created on Jan 25, 2010 -- --@author: tsitkova --''' --import os --import sys --import re --import yaml --from optparse import OptionParser --from confparser import ConfParser -- --class Rule(object): -- def __init__(self): -- pass -- -- def validate(self,node): -- (path,dirs,avs) = node -- -- --class Validator(object): -- def __init__(self, kerberosPath, confPath=None, rulesPath=None, hfilePath=None): -- self.parser = ConfParser(kerberosPath) -- if confPath is not None: -- content = self._readConfigFile(confPath) -- rulesPath = content['RulesPath'] -- hfilePath = content['HfilePath'] -- if rulesPath is not None and hfilePath is not None: -- self.rules = self._loadRules(rulesPath) -- self.validKeys = SupportedKeys(hfilePath).validKeys.union(self.rules['Attributes']) -- else: -- raise ValueError('Invalid arguments for validator: no path to rules and definition files') -- -- self._attribute_pattern = re.compile(r'^\w+$') -- self._lowercase_pattern = re.compile(r'[a-z]') -- -- def _readConfigFile(self,path): -- f = open(path) -- result = dict() -- for line in f: -- line = line.rstrip() -- fields = line.split('=') -- result[fields[0]] = fields[1] -- -- return result -- -- def _loadRules(self, path): -- f = open(path) -- rules = yaml.load(f) -- f.close() -- -- return rules -- -- def validate(self): -- typeInfo = self.rules['Types'] -- -- for node in self.parser.walk(): -- self._validateTypes(node, typeInfo) -- self._validateAttrubutes(node, self.validKeys) -- # self._validateRealm(node) -- -- -- def _validateTypes(self, node, typeInfo): -- (path, dirs, avs) = node -- for (key, value) in avs: -- valid_type_pattern = typeInfo.get(key) -- if valid_type_pattern is not None: -- for t in value: -- if re.match(valid_type_pattern, t) is None: -- print 'Wrong type %s for attribute %s.%s' % (t,path,key) -- -- def _validateAttrubutes(self, node, validKeys): -- (path, dirs, avs) = node -- attributes = list() -- for attr in dirs: -- if self._attribute_pattern.match(attr) is not None: -- attributes.append(attr) -- for (attr, value) in avs: -- if self._attribute_pattern.match(attr) is not None: -- attributes.append(attr) -- -- for attr in attributes: -- if attr not in validKeys: -- print 'Unrecognized attribute %s at %s' % (attr, path) -- --# def _validateRealm(self, node): --# (path, dirs, avs) = node --# if path == 'root.realms': --# for attr in dirs: --# if self._lowercase_pattern.search(attr) is not None: --# print 'Lower case letter in realm attribute: %s at %s' % (attr, path) -- --class SupportedKeys(object): -- def __init__(self, path): -- self.validKeys = self.getKeysFromHfile(path) -- -- def getKeysFromHfile(self, path): -- pattern = re.compile(r'^[#]define KRB5_CONF_\w+\s+["](\w+)["]') -- f = open(path) -- result = set() -- for l in f: -- l = l.rstrip() -- m = pattern.match(l) -- if m is not None: -- result.add(m.groups()[0]) -- f.close() -- -- return result -- -- --class ValidatorTest(Validator): -- def __init__(self): -- self.kerberosPath = '../tests/kdc1.conf' -- self.rulesPath = '../tests/rules.yml' -- self.hfilePath = '../tests/k5-int.h' -- self.confPath = '../tests/validator.conf' -- -- super(ValidatorTest, self).__init__(self.kerberosPath, -- rulesPath=self.rulesPath, -- hfilePath=self.hfilePath) -- -- def run_tests(self): -- self._test_validate() -- -- def _test__loadRules(self): -- result = self._loadRules(self.rulesPath) -- print result -- -- def _test_validate(self): -- self.validate() -- -- def _test__readConfigFile(self): -- result = self._readConfigFile(self.confPath) -- print result -- --class SupportedKeysTest(SupportedKeys): -- def __init__(self): -- self.path = '../tests/k5-int.h' -- -- def run_tests(self): -- self._test_getKeysFromHFile() -- -- def _test_getKeysFromHFile(self): -- result = set() -- krb5keys = self.getKeysFromHfile(self.path) -- for key in krb5keys: -- print key -- result.update(key) -- print len(krb5keys) -- -- return result -- --def _test(): -- tester = ValidatorTest() -- krb5keys = tester.run_tests() -- --if __name__ == '__main__': -- TEST = False -- if TEST: -- _test() -- sys.exit() -- -- -- usage = "\n\t%prog path [-d defPath] [-r rulesPath] [-c validatorConfPath]" -- description = 'Description: validates kerberos configuration file' -- parser = OptionParser(usage = usage, description = description) -- parser.add_option("-c", dest="confPath", -- help='path to validator config file') -- parser.add_option("-d", dest="hfilePath", -- help='path to h-file with attribute definition') -- parser.add_option("-r", dest="rulesPath", -- help='path to file with validation rules') -- (options, args) = parser.parse_args() -- -- if len(args) != 1 and len(sys.argv) <= 3: -- print '\n%s' % parser.get_usage() -- sys.exit() -- -- validator = None -- if options.confPath is not None: -- validator = Validator(args[0], confPath=options.confPath) -- elif options.hfilePath is not None and options.rulesPath is not None: -- validator = Validator(args[0], hfilePath=options.hfilePath, rulesPath=options.rulesPath) -- else: -- print '\nMust specify either configuration file or paths to rules and definitions files' -- print '%s' % parser.get_usage() -- sys.exit() -- -- validator.validate() -- -- -- -- -- diff --git a/Remove-dead-variable-def_kslist-from-two-files.patch b/Remove-dead-variable-def_kslist-from-two-files.patch deleted file mode 100644 index d9ba0dc..0000000 --- a/Remove-dead-variable-def_kslist-from-two-files.patch +++ /dev/null @@ -1,69 +0,0 @@ -From 5c9dce0ac1b8b6fcb048404e3830fd4619f4f1c5 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 2 May 2019 16:57:51 -0400 -Subject: [PATCH] Remove dead variable def_kslist from two files - -def_kslist was part of kdb5_create.c since its addition (commit -edf8b4d8a6a665c2aa150993cd813ea6c5cf12e1) and has always been -irrelevant since the rblock structure is fully initialized in -kdb5_create(). - -def_klist was copied into kdb5_ldap_realm.c (present in addition at -commit 42d9d6ab320ee3a661fe21472be542acd542d5be). The global rblock -structure (and therefore the initializer) was removed in commit -9c850f8b62784170a5e42315c1a9552ddcf4ca2b, leaving def_kslist -unreferenced. - -Remove def_kslist from both files, and remove the rblock initializer -from kdb5_create.c. - -[ghudson@mit.edu: edited commit message] - -(cherry picked from commit 6309f5e3508cd24151222b2cd095766283e205f2) ---- - src/kadmin/dbutil/kdb5_create.c | 12 +----------- - src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c | 1 - - 2 files changed, 1 insertion(+), 12 deletions(-) - -diff --git a/src/kadmin/dbutil/kdb5_create.c b/src/kadmin/dbutil/kdb5_create.c -index bc1b9195d..efdb8adb0 100644 ---- a/src/kadmin/dbutil/kdb5_create.c -+++ b/src/kadmin/dbutil/kdb5_create.c -@@ -66,8 +66,6 @@ enum ap_op { - TGT_KEY /* special handling for tgt key */ - }; - --krb5_key_salt_tuple def_kslist = { ENCTYPE_DES_CBC_CRC, KRB5_KDB_SALTTYPE_NORMAL }; -- - struct realm_info { - krb5_deltat max_life; - krb5_deltat max_rlife; -@@ -76,15 +74,7 @@ struct realm_info { - krb5_keyblock *key; - krb5_int32 nkslist; - krb5_key_salt_tuple *kslist; --} rblock = { /* XXX */ -- KRB5_KDB_MAX_LIFE, -- KRB5_KDB_MAX_RLIFE, -- KRB5_KDB_EXPIRATION, -- KRB5_KDB_DEF_FLAGS, -- (krb5_keyblock *) NULL, -- 1, -- &def_kslist --}; -+} rblock; - - struct iterate_args { - krb5_context ctx; -diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c -index 5a745e21d..c21d19981 100644 ---- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c -+++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c -@@ -91,7 +91,6 @@ - extern time_t get_date(char *); /* kadmin/cli/getdate.o */ - - char *yes = "yes\n"; /* \n to compare against result of fgets */ --krb5_key_salt_tuple def_kslist = {ENCTYPE_DES_CBC_CRC, KRB5_KDB_SALTTYPE_NORMAL}; - - krb5_data tgt_princ_entries[] = { - {0, KRB5_TGS_NAME_SIZE, KRB5_TGS_NAME}, diff --git a/Remove-doxygen-generated-HTML-output-for-ccapi.patch b/Remove-doxygen-generated-HTML-output-for-ccapi.patch deleted file mode 100644 index 3133482..0000000 --- a/Remove-doxygen-generated-HTML-output-for-ccapi.patch +++ /dev/null @@ -1,7653 +0,0 @@ -From a0c231f79b0b9c02120802cc5549c8576b5156bd Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 4 Apr 2019 14:15:58 -0400 -Subject: [PATCH] Remove doxygen-generated HTML output for ccapi - -(cherry picked from commit d4f90b750d6d81cc001f6b00266c82c1c916bbf4) ---- - doc/ccapi/Doxyfile | 281 ---- - doc/ccapi/ccache-api-v2.html | 1217 --------------- - doc/ccapi/html/doxygen.css | 310 ---- - doc/ccapi/html/doxygen.png | Bin 1281 -> 0 bytes - ...roup__cc__ccache__iterator__reference.html | 96 -- - .../html/group__cc__ccache__reference.html | 96 -- - .../html/group__cc__context__reference.html | 161 -- - ..._cc__credentials__iterator__reference.html | 133 -- - .../group__cc__credentials__reference.html | 197 --- - .../html/group__cc__string__reference.html | 96 -- - .../group__ccapi__constants__reference.html | 407 ----- - .../html/group__ccapi__types__reference.html | 138 -- - doc/ccapi/html/group__helper__macros.html | 1377 ----------------- - doc/ccapi/html/index.html | 85 - - doc/ccapi/html/structcc__ccache__d.html | 43 - - doc/ccapi/html/structcc__ccache__f.html | 722 --------- - .../html/structcc__ccache__iterator__d.html | 43 - - .../html/structcc__ccache__iterator__f.html | 117 -- - doc/ccapi/html/structcc__context__d.html | 43 - - doc/ccapi/html/structcc__context__f.html | 513 ------ - doc/ccapi/html/structcc__credentials__d.html | 67 - - doc/ccapi/html/structcc__credentials__f.html | 85 - - .../structcc__credentials__iterator__d.html | 43 - - .../structcc__credentials__iterator__f.html | 85 - - .../html/structcc__credentials__union.html | 118 -- - .../html/structcc__credentials__v4__t.html | 358 ----- - .../html/structcc__credentials__v5__t.html | 334 ---- - doc/ccapi/html/structcc__data.html | 94 -- - doc/ccapi/html/structcc__string__d.html | 67 - - doc/ccapi/html/structcc__string__f.html | 51 - - 30 files changed, 7377 deletions(-) - delete mode 100644 doc/ccapi/Doxyfile - delete mode 100755 doc/ccapi/ccache-api-v2.html - delete mode 100644 doc/ccapi/html/doxygen.css - delete mode 100644 doc/ccapi/html/doxygen.png - delete mode 100644 doc/ccapi/html/group__cc__ccache__iterator__reference.html - delete mode 100644 doc/ccapi/html/group__cc__ccache__reference.html - delete mode 100644 doc/ccapi/html/group__cc__context__reference.html - delete mode 100644 doc/ccapi/html/group__cc__credentials__iterator__reference.html - delete mode 100644 doc/ccapi/html/group__cc__credentials__reference.html - delete mode 100644 doc/ccapi/html/group__cc__string__reference.html - delete mode 100644 doc/ccapi/html/group__ccapi__constants__reference.html - delete mode 100644 doc/ccapi/html/group__ccapi__types__reference.html - delete mode 100644 doc/ccapi/html/group__helper__macros.html - delete mode 100644 doc/ccapi/html/index.html - delete mode 100644 doc/ccapi/html/structcc__ccache__d.html - delete mode 100644 doc/ccapi/html/structcc__ccache__f.html - delete mode 100644 doc/ccapi/html/structcc__ccache__iterator__d.html - delete mode 100644 doc/ccapi/html/structcc__ccache__iterator__f.html - delete mode 100644 doc/ccapi/html/structcc__context__d.html - delete mode 100644 doc/ccapi/html/structcc__context__f.html - delete mode 100644 doc/ccapi/html/structcc__credentials__d.html - delete mode 100644 doc/ccapi/html/structcc__credentials__f.html - delete mode 100644 doc/ccapi/html/structcc__credentials__iterator__d.html - delete mode 100644 doc/ccapi/html/structcc__credentials__iterator__f.html - delete mode 100644 doc/ccapi/html/structcc__credentials__union.html - delete mode 100644 doc/ccapi/html/structcc__credentials__v4__t.html - delete mode 100644 doc/ccapi/html/structcc__credentials__v5__t.html - delete mode 100644 doc/ccapi/html/structcc__data.html - delete mode 100644 doc/ccapi/html/structcc__string__d.html - delete mode 100644 doc/ccapi/html/structcc__string__f.html - -diff --git a/doc/ccapi/Doxyfile b/doc/ccapi/Doxyfile -deleted file mode 100644 -index 734c29c90..000000000 ---- a/doc/ccapi/Doxyfile -+++ /dev/null -@@ -1,281 +0,0 @@ --# Doxyfile 1.5.3 -- --#--------------------------------------------------------------------------- --# Project related configuration options --#--------------------------------------------------------------------------- --DOXYFILE_ENCODING = UTF-8 --PROJECT_NAME = "Credentials Cache API " --PROJECT_NUMBER = --OUTPUT_DIRECTORY = . --CREATE_SUBDIRS = NO --OUTPUT_LANGUAGE = English --BRIEF_MEMBER_DESC = YES --REPEAT_BRIEF = YES --ABBREVIATE_BRIEF = "The $name class " \ -- "The $name widget " \ -- "The $name file " \ -- is \ -- provides \ -- specifies \ -- contains \ -- represents \ -- a \ -- an \ -- the --ALWAYS_DETAILED_SEC = YES --INLINE_INHERITED_MEMB = NO --FULL_PATH_NAMES = NO --STRIP_FROM_PATH = --STRIP_FROM_INC_PATH = --SHORT_NAMES = NO --JAVADOC_AUTOBRIEF = NO --QT_AUTOBRIEF = NO --MULTILINE_CPP_IS_BRIEF = NO --DETAILS_AT_TOP = YES --INHERIT_DOCS = YES --SEPARATE_MEMBER_PAGES = NO --TAB_SIZE = 8 --ALIASES = --OPTIMIZE_OUTPUT_FOR_C = YES --OPTIMIZE_OUTPUT_JAVA = NO --BUILTIN_STL_SUPPORT = NO --CPP_CLI_SUPPORT = NO --DISTRIBUTE_GROUP_DOC = NO --SUBGROUPING = YES --#--------------------------------------------------------------------------- --# Build related configuration options --#--------------------------------------------------------------------------- --EXTRACT_ALL = YES --EXTRACT_PRIVATE = NO --EXTRACT_STATIC = NO --EXTRACT_LOCAL_CLASSES = NO --EXTRACT_LOCAL_METHODS = NO --EXTRACT_ANON_NSPACES = NO --HIDE_UNDOC_MEMBERS = NO --HIDE_UNDOC_CLASSES = NO --HIDE_FRIEND_COMPOUNDS = NO --HIDE_IN_BODY_DOCS = YES --INTERNAL_DOCS = NO --CASE_SENSE_NAMES = YES --HIDE_SCOPE_NAMES = YES --SHOW_INCLUDE_FILES = NO --INLINE_INFO = YES --SORT_MEMBER_DOCS = NO --SORT_BRIEF_DOCS = NO --SORT_BY_SCOPE_NAME = NO --GENERATE_TODOLIST = YES --GENERATE_TESTLIST = YES --GENERATE_BUGLIST = YES --GENERATE_DEPRECATEDLIST= YES --ENABLED_SECTIONS = --MAX_INITIALIZER_LINES = 30 --SHOW_USED_FILES = NO --SHOW_DIRECTORIES = NO --FILE_VERSION_FILTER = --#--------------------------------------------------------------------------- --# configuration options related to warning and progress messages --#--------------------------------------------------------------------------- --QUIET = NO --WARNINGS = YES --WARN_IF_UNDOCUMENTED = YES --WARN_IF_DOC_ERROR = YES --WARN_NO_PARAMDOC = YES --WARN_FORMAT = "$file:$line: $text " --WARN_LOGFILE = --#--------------------------------------------------------------------------- --# configuration options related to the input files --#--------------------------------------------------------------------------- --INPUT = ../../Sources/include/CredentialsCache.h --INPUT_ENCODING = UTF-8 --FILE_PATTERNS = *.c \ -- *.cc \ -- *.cxx \ -- *.cpp \ -- *.c++ \ -- *.d \ -- *.java \ -- *.ii \ -- *.ixx \ -- *.ipp \ -- *.i++ \ -- *.inl \ -- *.h \ -- *.hh \ -- *.hxx \ -- *.hpp \ -- *.h++ \ -- *.idl \ -- *.odl \ -- *.cs \ -- *.php \ -- *.php3 \ -- *.inc \ -- *.m \ -- *.mm \ -- *.dox \ -- *.py \ -- *.C \ -- *.CC \ -- *.C++ \ -- *.II \ -- *.I++ \ -- *.H \ -- *.HH \ -- *.H++ \ -- *.CS \ -- *.PHP \ -- *.PHP3 \ -- *.M \ -- *.MM \ -- *.PY --RECURSIVE = YES --EXCLUDE = --EXCLUDE_SYMLINKS = NO --EXCLUDE_PATTERNS = --EXCLUDE_SYMBOLS = --EXAMPLE_PATH = --EXAMPLE_PATTERNS = * --EXAMPLE_RECURSIVE = NO --IMAGE_PATH = --INPUT_FILTER = --FILTER_PATTERNS = --FILTER_SOURCE_FILES = NO --#--------------------------------------------------------------------------- --# configuration options related to source browsing --#--------------------------------------------------------------------------- --SOURCE_BROWSER = NO --INLINE_SOURCES = NO --STRIP_CODE_COMMENTS = YES --REFERENCED_BY_RELATION = YES --REFERENCES_RELATION = YES --REFERENCES_LINK_SOURCE = YES --USE_HTAGS = NO --VERBATIM_HEADERS = NO --#--------------------------------------------------------------------------- --# configuration options related to the alphabetical class index --#--------------------------------------------------------------------------- --ALPHABETICAL_INDEX = NO --COLS_IN_ALPHA_INDEX = 5 --IGNORE_PREFIX = --#--------------------------------------------------------------------------- --# configuration options related to the HTML output --#--------------------------------------------------------------------------- --GENERATE_HTML = YES --HTML_OUTPUT = html --HTML_FILE_EXTENSION = .html --HTML_HEADER = --HTML_FOOTER = --HTML_STYLESHEET = --HTML_ALIGN_MEMBERS = NO --GENERATE_HTMLHELP = NO --HTML_DYNAMIC_SECTIONS = NO --CHM_FILE = --HHC_LOCATION = --GENERATE_CHI = NO --BINARY_TOC = NO --TOC_EXPAND = NO --DISABLE_INDEX = YES --ENUM_VALUES_PER_LINE = 4 --GENERATE_TREEVIEW = NO --TREEVIEW_WIDTH = 250 --#--------------------------------------------------------------------------- --# configuration options related to the LaTeX output --#--------------------------------------------------------------------------- --GENERATE_LATEX = NO --LATEX_OUTPUT = latex --LATEX_CMD_NAME = latex --MAKEINDEX_CMD_NAME = makeindex --COMPACT_LATEX = NO --PAPER_TYPE = letter --EXTRA_PACKAGES = --LATEX_HEADER = --PDF_HYPERLINKS = YES --USE_PDFLATEX = YES --LATEX_BATCHMODE = NO --LATEX_HIDE_INDICES = NO --#--------------------------------------------------------------------------- --# configuration options related to the RTF output --#--------------------------------------------------------------------------- --GENERATE_RTF = YES --RTF_OUTPUT = rtf --COMPACT_RTF = YES --RTF_HYPERLINKS = YES --RTF_STYLESHEET_FILE = --RTF_EXTENSIONS_FILE = --#--------------------------------------------------------------------------- --# configuration options related to the man page output --#--------------------------------------------------------------------------- --GENERATE_MAN = NO --MAN_OUTPUT = man --MAN_EXTENSION = .3 --MAN_LINKS = NO --#--------------------------------------------------------------------------- --# configuration options related to the XML output --#--------------------------------------------------------------------------- --GENERATE_XML = NO --XML_OUTPUT = xml --XML_SCHEMA = --XML_DTD = --XML_PROGRAMLISTING = YES --#--------------------------------------------------------------------------- --# configuration options for the AutoGen Definitions output --#--------------------------------------------------------------------------- --GENERATE_AUTOGEN_DEF = NO --#--------------------------------------------------------------------------- --# configuration options related to the Perl module output --#--------------------------------------------------------------------------- --GENERATE_PERLMOD = NO --PERLMOD_LATEX = NO --PERLMOD_PRETTY = YES --PERLMOD_MAKEVAR_PREFIX = --#--------------------------------------------------------------------------- --# Configuration options related to the preprocessor --#--------------------------------------------------------------------------- --ENABLE_PREPROCESSING = YES --MACRO_EXPANSION = NO --EXPAND_ONLY_PREDEF = NO --SEARCH_INCLUDES = NO --INCLUDE_PATH = --INCLUDE_FILE_PATTERNS = --PREDEFINED = --EXPAND_AS_DEFINED = --SKIP_FUNCTION_MACROS = YES --#--------------------------------------------------------------------------- --# Configuration::additions related to external references --#--------------------------------------------------------------------------- --TAGFILES = --GENERATE_TAGFILE = --ALLEXTERNALS = NO --EXTERNAL_GROUPS = NO --PERL_PATH = /usr/bin/perl --#--------------------------------------------------------------------------- --# Configuration options related to the dot tool --#--------------------------------------------------------------------------- --CLASS_DIAGRAMS = NO --MSCGEN_PATH = /Volumes/Ragna-Blade/Developer/Doxygen/Doxygen.app/Contents/Resources/ --HIDE_UNDOC_RELATIONS = YES --HAVE_DOT = NO --CLASS_GRAPH = YES --COLLABORATION_GRAPH = YES --GROUP_GRAPHS = YES --UML_LOOK = NO --TEMPLATE_RELATIONS = NO --INCLUDE_GRAPH = YES --INCLUDED_BY_GRAPH = YES --CALL_GRAPH = NO --CALLER_GRAPH = NO --GRAPHICAL_HIERARCHY = YES --DIRECTORY_GRAPH = YES --DOT_IMAGE_FORMAT = png --DOT_PATH = --DOTFILE_DIRS = --DOT_GRAPH_MAX_NODES = 50 --MAX_DOT_GRAPH_DEPTH = 1000 --DOT_TRANSPARENT = NO --DOT_MULTI_TARGETS = NO --GENERATE_LEGEND = YES --DOT_CLEANUP = YES --#--------------------------------------------------------------------------- --# Configuration::additions related to the search engine --#--------------------------------------------------------------------------- --SEARCHENGINE = NO -diff --git a/doc/ccapi/ccache-api-v2.html b/doc/ccapi/ccache-api-v2.html -deleted file mode 100755 -index b8d3f06e5..000000000 ---- a/doc/ccapi/ccache-api-v2.html -+++ /dev/null -@@ -1,1217 +0,0 @@ -- -- -- -- Credentials Cache API v2 Specification -- -- --

    Credentials Cache API v2 Specification

    --

    This version of the API is deprecated.
    --Please refer to CCAPI version 3 or later for the current API.

    -- -- -- --

    --


    -- -- --

    Abstract

    -- --

    This is the specification for an API which provides Credentials --Cache services for both --Kerberos V5 and V4. --The idea behind this API is that multiple Kerberos implementations --can share a single Credentials Cache, mediated by this API --specification. On the Microsoft Windows platform this will allow --single-signon, even when more than one Kerberos DLL is in use on a --particular system. Ideally, this problem could be solved by --standardizing the Kerberos V5 API library interface. However, the --Kerberos API is complicated enough that this would be hard to --accomplish. Standardizing the interface for credentials cache access --is much simpler. This API has also been adopted in the MIT Kerberos --for the Macintosh implementation. -- --

    This specification has been revised to allow storage and --manipulation of both V4 and V5 tickets. A cache contains one or more --"Named Cache"s. It is assumed that V4 and V5 credentials would each --be stored in separate "Named Cache"s and not mixed in a single "Named --Cache". -- --

    Below, "NC" refers to "Named Cache".
    -- -- -- --

    --


    -- -- --

    Revision History/Notes

    -- --

    Original version (Draft Version 1)

    -- --

    1/27/96 by --Theodore Ts'o -- --

    Revision 2 (Draft Version 1)

    -- --

    970628 by Steve Rothwell --for the V4Cache Team (Paul Hill, Jenny Khuon, Jean Luker, Dave --Detlefs, Allan Bjorklund, & Steve Rothwell) -- --

    -- --

    Revision 3 (Draft Version 1)

    -- --

    970725 by Steve Rothwell after initial implementation and alpha --release. The term "credentials cache" was previously used to mean --both "the main cache" and individual "named cache"s within the main --cache. I have started using the term "NC" for "named cache" to make --the distinction clearer and to reduce the overloading of the word --"cache". -- --

    Changes made for revision 3 of this API:
    -- --
      --
    • Added cred version type to cc_create() & cc_open() -- --
    • New functions -- --
        --
      • cc_get_NC_info(), returns NC_info list for all NCs -- --
      • cc_free_NC_info(), frees NC_info list -- --
      • cc_get_cred_version(), returns version type of NC -- --
      • cc_get_name(), returns name of NC -- --
      • cc_free_name(), frees name aquired via cc_get_name() -- --
      • cc_seq_fetch_NCs(), iterate over all NCs --
      -- --
    • New return codes -- --
        --
      • CC_BAD_PARM -- --
      • CC_ERR_CACHE_ATTACH -- --
      • CC_ERR_CACHE_RELEASE -- --
      • CC_ERR_CACHE_FULL -- --
      • CC_ERR_CRED_VERSION --
      -- --
    • Modified functions -- --
        --
      • cc_create(), cc_open(), pass version type of NC -- --
      • cc_store(), cc_remove(), cc_ --
      -- --
    • New & Modified typedefs & data structures -- --
        --
      • cc_cred_vers { CC_CRED_VUNKNOWN, CC_CRED_V4, CC_CRED_V5 } -- --
      • cred_ptr_union : contains pointer to credentials (either V4 -- or V5) -- --
      • cred_union : contains version type and cred_ptr_union -- --
      • modified V4Cred_type -- --
      • enum StringToKey_Type { STK_AFS or STK_DES } -- --
      • copies of the maximum V4 string size indicators -- KRB_PRINCIPAL_SZ, KRB_SERVICE_SZ, KRB_INSTANCE_SZ, -- KRB_REALM_SZ, ADDR_SZ --
      --
    -- --

    Revision 4 (Draft Version 1)

    -- --

    970908 by Steve Rothwell to incorporate changes initiated by Ted --Tso. Further changes are expected in the comments for cc_create() and --cc_get_change_time(). -- --

    Revision 4a (Final Version 1)

    -- --

    980603 by Scott McGuire to --correct typographical errors, HTML errors, and minor clarifications. --Final API Version 1 spec. -- --

    Revision 5 (Draft Version 2)

    -- --

    990201 by Scott McGuire. -- --

      --
    • Increased API version number to 2. -- --
    • Added enum's defining version numbers. -- --
    • Changes to cc_initialize() to specify how to deal with -- different API version numbers. -- --
    • Added description of cc_int32 and cc_uint32 types. -- --
    • Change some cc_int32's to cc_uint32's. -- --
    • Changed way cc_create() will behave when called on an existing -- cache. -- --
    • Replaced cc_seq_fetch_NCs() with cc_seq_fetch_NCs_begin(), -- cc_seq_fetch_NCs_next(), and cc_seq_fetch_NCs_end(); -- --
    • Replaced cc_seq_fetch_creds() with cc_seq_fetch_creds_begin(), -- cc_seq_fetch_creds_next(), and cc_seq_fetch_creds_end(); -- --
    • Replaced enum type references in structs and function -- paramenters with cc_int32 references; -- --
    • Replaced int type references in function parameters with -- cc_int32; -- --
    • Added return type of cc_int32 to all functions; -- --
    • Removed #ifdef from cred_union structure; -- --
    • Constant definitions and changes to V4Cred_type structure; -- --
    • Removed incorrect const ccache_p * parameters from cc_store() -- and cc_remove_cred(); -- --
    • Added CC_NOERROR and CC_BAD_PARM as possible return codes from -- all functions (except no CC_BAD_PARM from cc_shutdown() ); -- --
    • Added CC_ERR_CRED_VERSION as possible return code from -- cc_open() and cc_create(); -- --
    • Moved infoNC structure definition up to be with rest of -- structure definitions; -- --
    • Changed "struct _infoNC" to "infoNC" in parameter type -- references. -- --
    • cc_free_principal() and cc_free_name() now take char ** -- instead of char * for final parameter. (This change was made -- between rev 4a and rev 5, but I'm re-emphasizing it here.) -- --
    • Added Implementation Notes section with requirement that all -- functions must be atomic and name requirements for Windows DLL's. -- --
    • Renamed "the proposed changes to this API are" section to -- "Ideas for Future Versions" -- but removed all items but one -- because they'd all been done. -- --
    • Removed most of the notes about differences with the Win NT/95 -- implementation of the API -- the differences have been reconciled. -- --
    • Removed unnecessary and inconsistent italicizing. --
    -- --

    Revsion 5a (Final Version 2)

    -- --

    990723 by Scott McGuire. -- --

      --
    • cc_create(): Removed text about "expected" form of name. -- Removed note about "the alpha version does not do this." -- --
    • cc_destroy(): Clarified that you do not need to call -- cc_close() on the cache_pointer after calling this function. -- --
    • Removed note about Windows cc_get_instance() and -- cc_set_instance() functions, they are no longer part of the -- Windows code! --
    -- --

    Ideas for Future Versions

    -- --
      --
    • Define Get/Set functions for all components of _cc_creds? -- (This will allow future changes to the data structure to be -- transparent to the caller. This also makes backward compatibility -- much easier to maintain.) --
    -- --


    -- -- --


    -- -- --

    Type definitions

    -- --
    // enums for API versions used in cc_initialize()
    --enum {
    --   CC_API_VER_1 = 1,
    --   CC_API_VER_2 = 2
    --};
    -- 
    --
    --// cc_int32 and cc_uint32 are not exactly defined in this API due
    --// to a lack of standard 32-bit integer size between platforms
    --// (although there is the C9X standard).
    --// However, we will place the following constraints:
    --//
    --// cc_int32 is a signed integer that is at least 32 bits wide.
    --// cc_uint32 is an unsigned integer that is at least 32 bits wide
    -- 
    --
    --typedef cc_int32 cc_time_t;  //see notes below
    --
    --typedef cc_uint32 cc_nc_flags;
    -- 
    -- 
    --
    --typedef struct opaque_dll_control_block_type* apiCB;
    --typedef struct opaque_ccache_pointer_type* ccache_p;
    --typedef struct opaque_credential_iterator_type* ccache_cit;
    -- 
    --// These really are intended to be opaque. All implementations of the cache API must have
    --// them but what they are is implementation specific. In the case of SGR's implementation,
    --// the cc_ctx returned available after a call to cc_initialize, is a CCache_ctx class object. The 
    --// code that normally calls the cc_initialize function is straight C, which means the calling
    --// application doesn't have a chance in hell of manipulating this directly. The API is designed
    --// so that it does not have to. It does have to pass the pointer to the class around, one reason 
    --// being so that the destructor can eventually be called.
    -- 
    -- 
    --
    --typedef struct _cc_data {
    --    cc_uint32            type;
    --    cc_uint32            length;
    --    unsigned char*      data;
    --} cc_data;
    -- 
    --
    --typedef struct _cc_creds {
    --    char*       client; /* client's principal identifier */
    --    char*       server; /* server's principal identifier */
    --    cc_data     keyblock;       /* session encryption key info */
    --    cc_time_t   authtime;
    --    cc_time_t   starttime;
    --    cc_time_t   endtime;
    --    cc_time_t   renew_till;
    --    cc_uint32    is_skey;        /* true if ticket is encrypted in
    --                                   another ticket's skey */
    --    cc_uint32    ticket_flags;   /* flags in ticket */
    --    cc_data**   addresses;      /* addrs in ticket */
    --    cc_data     ticket;         /* ticket string itself */
    --    cc_data     second_ticket;  /* second ticket, if related to
    --                                   ticket (via DUPLICATE-SKEY or
    --                                   ENC-TKT-IN-SKEY) */
    --    cc_data**   authdata;       /* authorization data */
    --} cc_creds;
    -- 
    -- 
    --// use an enumerated type so all callers infer the same meaning
    --// these values are what krbv4win uses internally.
    --
    --enum StringToKey_Type { STK_AFS = 0, STK_DES = 1 };
    -- 
    --enum { MAX_V4_CRED_LEN = 1250 };
    -- 
    -- 
    --// V4 Credentials
    --
    --enum {
    --  KRB_NAME_SZ = 40,
    --  KRB_INSTANCE_SZ = 40,
    --  KRB_REALM_SZ = 40
    --};
    -- 
    --typedef struct _V4credential {
    --    unsigned char              kversion;
    --    char                       principal[KRB_NAME_SZ+1];
    --    char                       principal_instance[KRB_INSTANCE_SZ+1];
    --    char                       service[KRB_NAME_SZ+1];
    --    char                       service_instance[KRB_INSTANCE_SZ+1];
    --    char                       realm[KRB_REALM_SZ+1];
    --    unsigned char              session_key[8];
    --    cc_int32                   kvno;                   // k95 used BYTE skvno
    --    cc_int32                   str_to_key;             // k4 infers dynamically, k95 stores; of type enum StringToKey_Type
    --    long                       issue_date;             // k95 called this issue_time
    --    cc_int32                   lifetime;               // k95 used LONG expiration_time
    --    cc_uint32                  address;                // IP Address of local host as an unsigned 32-bit integer
    --    cc_int32                   ticket_sz;              // k95 used BYTE, k4 ktext uses int to hold up to 1250
    --    unsigned char              ticket[MAX_V4_CRED_LEN];
    --    unsigned long              oops;                   // zero to catch runaways
    --} V4Cred_type;
    -- 
    --
    --enum cc_cred_vers {  
    --    CC_CRED_VUNKNOWN = 0,       // For validation
    --    CC_CRED_V4 = 1,
    --    CC_CRED_V5 = 2,
    --    CC_CRED_VMAX = 3            // For validation
    --};
    -- 
    --
    --typedef union cred_ptr_union_type {
    --    V4Cred_type* pV4Cred;
    --    cc_creds*    pV5Cred;
    --} cred_ptr_union;
    -- 
    --
    --typedef struct cred_union_type {
    --    cc_int32 cred_type;  // cc_cred_vers
    --    cred_ptr_union cred;
    --} cred_union;
    -- 
    --
    --typedef struct _infoNC {
    --        char*   name;
    --        char*   principal;
    --        cc_int32 vers;   // cc_cred_vers
    --} infoNC;
    -- --

    The cc_data structure

    -- --

    The cc_data structure is used to store the following elements: -- --

      --
    • keyblock -- --
    • addresses -- --
    • ticket (and second_ticket) -- --
    • authorization data --
    -- --

    For cc_creds.ticket and cc_creds.second_ticket, the cc_data.type --field MUST be zero. For the cc_creds.addresses, cc_creds.authdata, --and cc_data.keyblock, the cc_data.type field should be the address --type, authorization data type, and encryption type, as defined by the --Kerberos V5 protocol definition. -- --

    cc_time_t

    -- --

    The cc_time_t fields are used to represent time. The time must be --stored as the number of seconds since midnight GMT on January 1, --1970. -- --

    Principal names

    -- --

    Principal names are stored as C strings in this API. The C strings --may contain UTF-8 encoded strings for internationalization --purposes.
    -- -- --


    -- -- --

    Error Codes Definition

    -- --

    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    --

    0  --

    --

    CC_NOERROR  --

    --

    "Successful return"  --

    --

    1  --

    --

    CC_BADNAME  --

    --

    "Bad credential cache name format"  --

    --

    2  --

    --

    CC_NOTFOUD  --

    --

    "Matching credential not found"  --

    --

    3  --

    --

    CC_END  --

    --

    "End of credential cache reached"  --

    --

    4  --

    --

    CC_IO  --

    --

    "Credentials cache I/O operation failed"  --

    --

    5  --

    --

    CC_WRITE  --

    --

    "Error writing to credentials cache file"  --

    --

    6  --

    --

    CC_NOMEM  --

    --

    "No memory"  --

    --

    7  --

    --

    CC_FORMAT  --

    --

    "Corrupted credentials cache"  --

    --

    8  --

    --

    CC_LOCKED  --

    --

    "The credentials cache or NC is locked"  --

    --

    9  --

    --

    CC_BAD_API_VERSION  --

    --

    "Unsupported API version"  --

    --

    10  --

    --

    CC_NO_EXIST  --

    --

    "Credentials cache or NC does not exist"  --

    --

    11  --

    --

    CC_NOT_SUPP  --

    --

    "Function not supported"  --

    --

    12  --

    --

    CC_BAD_PARM  --

    --

    "Bad Paramter Passed"  --

    --

    13  --

    --

    CC_ERR_CACHE_ATTACH  --

    --

    "Failed to attach cache"  --

    --

    14  --

    --

    CC_ERR_CACHE_RELEASE  --

    --

    "Failed to release cache"  --

    --

    15  --

    --

    CC_ERR_CACHE_FULL  --

    --

    "Cache FULL"  --

    --

    16  --

    --

    CC_ERR_CRED_VERSION  --

    --

    "Wrong Cred Version"  --

    -- --

    --


    -- -- --

    Implementation Notes

    -- --

    All functions are atomic

    -- --

    All Credentials Cache API functions must be atomic. -- --

    Windows -- --

    DLLs should be named KrbCC16.dll and KrbCC32.dll. -- --

    --


    -- -- --

    Function definitions

    -- --

    -- --

    Main Cache Functions

    -- --

    -- -- --

    -- --

    cc_initialize

    -- --
    cc_int32 cc_initialize(apiCB** cc_ctx, cc_int32 api_version, cc_int32* api_supported, char** vendor)
    -- --

    This function performs any initialization required by the --API. It must be called before any other function in the --API is called. The cc_ctx returned by this function must be --passed to all other API functions as the first argument. -- --

    The application must pass in the maximum version number of the API --it supports in the api_version parameter. -- --

    If api_supported non-NULL, then cc_initialize will store --the maximum API version number supported by the library implementing --the API there. -- --

    If the version requested by api_version is not equal to the --version supported by the library, CC_BAD_API_VERSION will be returned --as the error code (along with the version the library does support in --api_supported) and cc_initialize should not allocate any --memory. -- --

    If the vendor is non-NULL, then cc_initialize will store a --pointer to a read/only C string which contains a string describing --the vendor which implemented the credentials cache API. -- --

    Possible error codes: CC_NOERROR, CC_NOMEM, CC_BAD_API_VERSION, --CC_BAD_PARM -- --


    -- -- -- --

    cc_shutdown

    -- --
    cc_int32 cc_shutdown(apiCB** cc_ctx)
    -- --

    This function performs any cleanup required by the API. --cc_ctx will be NULL on return. The application program must call --cc_initialize() again before making any credentials cache API --calls. -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM -- --


    -- -- -- --

    cc_get_change_time

    -- --
    cc_int32 cc_get_change_time(apiCB* cc_ctx, cc_time_t* time)
    -- --

    This function returns the time of the most recent change for the --entire cache. There is ONE timestamp maintained for the entire cache. --By maintaining a local copy the caller can deduce whether "something --changed" or not. -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_NOMEM, --CC_BAD_PARM -- --


    -- -- -- --

    cc_get_NC_info

    -- --
    cc_int32 cc_get_NC_info(apiCB* cc_ctx, infoNC*** ppNCi)
    -- --

    cc_get_NC_info() is a wrapper for cc_seq_fetch_NCs(), --cc_get_name() cc_get_cred_version(), and cc_get_principal(). It --returns all the information needed to uniquely identify each NC in --the cache (name and cred_version) and the associated principal. --Specifically it returns a null terminated list of pointers to infoNC --structs. Each infoNC struct contain a pointer to the NC's name, a --pointer to the the principal associated with the NC, and the version --number (as an enumerated type) of the credentials stored in this NC. -- --

    The ppNCi (the entire data structure) aquired by this routine --should be freed with cc_free_NC_info(). -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_NOMEM, --CC_BAD_PARM -- --


    -- -- -- --

    cc_open

    -- --
    cc_int32 cc_open(apiCB* cc_ctx, const char* name, cc_int32 cred_vers, cc_uint32 cc_flags,
    --                 ccache_p** ccache_pointer)
    -- --

    Opens an already exising NC identified by both name, and --cred_vers. It fills in the parameter **ccache_pointer with a --pointer to the NC. -- --

    The list of cache names, principals, and credentials versions may --be retrieved via cc_seq_fetch_NCs(), cc_get_name(), --cc_get_cred_version(), & cc_get_principal() OR via --cc_get_NC_info(). -- --

    Possible error codes: CC_NOERROR, CC_BADNAME, CC_NO_EXIST, --CC_NOMEM, CC_ERR_CRED_VERSION, CC_BAD_PARM -- --


    -- -- -- --

    cc_create

    -- --
    cc_int32 cc_create(apiCB* cc_ctx, const char* name, const char* principal,
    --                cc_int32 cred_vers, cc_uint32 cc_flags, ccache_p** ccache_pointer)
    -- --

    Create a new NC. The NC is uniquely identified by the combination --of it's name and the "cc_creds_vers" (i.e. which credentials version --it holds). The principal given is also associated with the NC. A NULL --name is not allowed (and CC_BADNAME should be returned if one --is passed in). If name is non-null and there is already a NC --named name, all credentials in the cache are removed, and --handle for the existing cache is returned. If there is already a NC --named name, all existing handles for this cache remain valid. The NC --is created with a primary principal specified by principal. -- --

    (Removed text about the "expected" form of the NC name.) -- --

    An NC is intended to hold credentials for a single principal in a --single realm, and for a single credentials version (i.e. V4 or V5). --The cache can contain credentials for other credential versions, --other realms, and even other principals, but each in a separate NC. --This rule will allow callers that can only handle a single principal --in a single realm to continue to work by dealing with only one NC. --Callers that can deal with multiple principals, multiple realms, --and/or multiple credentials versions can do so by dealing with --multiple NCs. By doing it this way, the callers that are able to --handle multiple principals, realms, and/or versions can do so without --interfering with "differently abled" code. -- --

    The list of cache names, principals, & cred_versions may be --retrieved via cc_get_NC_info(). -- --

    Possible error codes: CC_NOERROR, CC_BADNAME, CC_BAD_PARM, --CC_NO_EXIST, CC_NOMEM, CC_ERR_CRED_VERSION -- --


    -- -- -- --

    cc_close

    -- --
    cc_int32 cc_close(apiCB* cc_ctx, ccache_p** ccache_pointer)
    -- --

    Close the NC. The ccache_pointer related memory is --deallocated, and ccache_pointer is set to NULL before being returned --to caller. -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM -- --


    -- -- -- --

    cc_destroy

    -- --
    cc_int32 cc_destroy(apiCB* cc_ctx, ccache_p** ccache_pointer)
    -- --

    Destroy the NC pointed to by ccache_pointer. The --ccache_pointer related memory is deallocated, and --ccache_pointer is set to NULL before being returned to caller. The --caller does not need to call cc_close() on the cache_pointer --afterwards. -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM -- --


    -- -- -- --

    -- --

    cc_seq_fetch_NCs_begin

    -- --
    cc_int32 cc_seq_fetch_NCs_begin(apiCB* cc_ctx, ccache_cit** itNCs)
    -- --

    Used to allocate memory and initialize the iterator *itNCs. Use --cc_seq_fetch_NCs_end() to deallocate the memory used by *itNCs. -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM, --CC_NOMEM -- --

    -- --

    cc_seq_fetch_NCs_next

    -- --
    cc_int32 cc_seq_fetch_NCs_next(apiCB* cc_ctx, ccache_p** ccache_pointer, ccache_cit* itNCs)
    -- --

    Used to sequentially open every NC in the cache. -- --

    Ccache_pointer must be a pointer to a ccache_p*. The --ccache_pointer returned may be used to get information about the NC --by calling cc_get_name(), cc_get_cred_version(), and --cc_get_principal(). Ccache_pointer's returned must be freed via --cc_close() between calls to cc_seq_fetch_NCs_next(). -- --

    itNCs must be a pointer to a ccache_cit* variable provided by the --calling application and which is used by cc_seq_fetch_NCs_next() to --determine the next NC to return. It must have been initialized by --cc_seq_fetch_NCs_begin(). -- --

    If changes are made to the credentials cache while it iterator is --being used, it must return at least the intersection, and at most the --union, of the set of NC's that were in the cache when the iteration --began and the set of NC's that are in the cache when it ends. -- --

    When the last NC in the sequence is returned, the return code from --cc_seq_fetch_NCs_next() will be CC_END. -- --

    Possible error codes: CC_NOERROR, CC_END, CC_NO_EXIST. --CC_BAD_PARM, CC_NOMEM -- --

     

    -- --

    -- --

    cc_seq_fetch_NCs_end

    -- --
    cc_int32 cc_seq_fetch_NCs_end(apiCB* cc_ctx, ccache_cit** itNCs)
    -- --

    Deallocates the memory used by *itNCs, and sets *itNCs to NULL. -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM -- --

      -- --

    -- --

    NC Functions

    -- --

    -- -- --

    cc_get_name

    -- --
    cc_int32 cc_get_name(apiCB* cc_ctx, const ccache_p* ccache_pointer, char** name)
    -- --

    cc_get_name() returns the name of the NC indicated by --ccache_pointer. The name can be used in cc_open() or cc_create(). The --combination of the name and the credentials version uniqeuly identify --an NC. The returned name should be freed via cc_free_name(). -- --

    Possible error codes: CC_NOERROR, CC_NOMEM, CC_NO_EXIST, --CC_BAD_PARM -- --


    -- -- -- --

    cc_get_cred_version

    -- --
    cc_int32 cc_get_cred_version(apiCB* cc_ctx, const ccache_p* ccache_pointer, cc_int32* cred_vers)
    -- --

    cc_get_cred_version() returns one of the enumerated type --cc_cred_vers in cred_vers. The expected values are CC_CRED_V4, or --CC_CRED_V5. The combination of the name and the credentials version --uniquely identify an NC. -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM -- --


    -- -- -- --

    cc_set_principal

    -- --
    cc_int32 cc_set_principal(apiCB* cc_ctx, const ccache_p* ccache_pointer, const cc_int32 cred_vers,
    --                          const char* principal)
    -- --

    Set the primary principal for the NC indicated by ccache_pointer. --This is the complement to cc_get_principal(). -- --

    cred_vers is used as a double check. -- --

    principal points to a null terminated string that will be copied --into the NC. This new principal will be returned if you call --cc_get_principal() for this NC. -- --

    Possible error codes: CC_NOERROR, CC_NOMEM, CC_NO_EXIST, --CC_ERR_CRED_VERSION, CC_BAD_PARM
    -- --  -- --


    -- -- -- --

    cc_get_principal

    -- --
    cc_int32 cc_get_principal(apiCB* cc_ctx, const ccache_p* ccache_pointer, char** principal)
    -- --

    Return the primary principal for the NC that was set via --cc_create() or cc_set_principal(). The returned principal should be --freed via cc_free_principal() . -- --

    Possible error codes: CC_NOERROR, CC_NOMEM, CC_NO_EXIST, --CC_BAD_PARM
    -- -- -- --


    -- -- -- --

    cc_store

    -- --
    cc_int32 cc_store(apiCB* cc_ctx, ccache_p* ccache_pointer, const cred_union cred)
    -- --

    Store (make a copy of) cred in the NC indicated by --ccache_pointer. -- --

    A cred_union contains a cred_type indicator and a cred_ptr_union. --A cred_ptr_union can contain either a V4Cred_type pointer or a --cc_creds (V5 creds) pointer. Cred_type indicates which type of --pointer is in the cred_ptr_union. This also allows the API to --enforce the credentials version declared in cc_create() or cc_open(). -- -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_ERR_CACHE_FULL, --CC_ERR_CRED_VERSION, CC_BAD_PARM -- --


    -- -- -- --

    cc_remove_cred

    -- --
    cc_int32 cc_remove_cred(apiCB* cc_ctx, ccache_p* ccache_pointer, const cred_union cred)
    -- --

    Removes the credential cred from ccache_pointer. The --credentials in the NC indicated by ccache_pointer are searched to --find a matching credential. If found, that credential is removed from --the NC. The cred parameter is not modified and should be freed via --cc_free_creds(). It is legitimate to call this function during a --sequential fetch, and the deletion of a credential already returned --by cc_seq_fetch_creds() should not disturb sequence of credentials --returned by cc_seq_fetch_creds(). -- --

    Use of cred_union is the same as is explained in cc_store(). -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_NOTFOUND, --CC_ERR_CRED_VERSION, CC_BAD_PARM -- --


    -- -- -- --

    cc_seq_fetch_creds_begin

    -- --
    cc_int32 cc_seq_fetch_creds_begin(apiCB* cc_ctx, const ccache_p* ccache_pointer, ccache_cit** itCreds)
    -- --

    Allocates memory for and initializes *itCreds. This memory must be --deallocated using cc_seq_fetch_creds_end(). -- --

    Ccache_pointer must be a valid pointer to the NC containing the --creds to be returned by the iterator. -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM, --CC_NOMEM -- --

      -- --

    -- --

    cc_seq_fetch_creds_next

    -- --
    cc_int32 cc_seq_fetch_creds_next(apiCB* cc_ctx, cred_union** cred, ccache_cit* itCreds)
    -- --

    cc_seq_fetch_creds_next() is used to sequentially read every set --of credentials in an NC. The NC has been indicated in the call to --cc_seq_fetch_creds_begin(). -- --

    itCreds must be a pointer to a ccache_cit* variable provided by --the calling application and which is used by --cc_seq_fetch_creds_next() to determine the next cached credential to --return. The ccache_cit* variable must be initialized by calling --cc_seq_fetch_creds_begin(). -- --

    The credentials are filled into the cred_union pointed to by --creds. Note that the cred_union contains elements which are --dynamically allocated, so must be freed using cc_free_creds() between --calls to cc_seq_fetch_creds_next(). -- --

    If changes are made to the NC while it iterator is being used, it --must return at least the intersection, and at most the union, of the --set of credentials that were in the NC when the iteration began and --the set of credentials that are in the NC when it ends. -- --

    When the last credential in the sequence is returned, the return --code from cc_seq_fetch_creds_next() will be CC_END. -- --

    Possible error codes: CC_NOERROR, CC_END, CC_NO_EXIST, --CC_BAD_PARM, CC_NOMEM -- --

      -- --

    -- --

    cc_seq_fetch_creds_end

    -- --
    cc_int32 cc_seq_fetch_creds_end(apiCB* cc_ctx, ccache_cit** itCreds)
    -- --

    Deallocates memory used by *itCreds and sets *itCreds to NULL. -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM -- --


    -- -- -- --

    cc_lock_request

    -- --
    cc_int32 cc_lock_request(apiCB* cc_ctx, const ccache_p* ccache_pointer, cc_int32 lock_type)
    -- --
    --
    99/02/11 - smcguire -- --
    As of this date there is no locking in the Win NT/95 -- or Machintosh implementations. The description below may not be -- completely accurate as to how this function should be -- implemented. --
    -- --

    This function is currently NOT IMPLEMENTED. All functions attach --to the cache, take action, and detach from the cache before returning --to the caller. -- --

    This function will lock or unlock the NC based on the argument --value of lock_type: -- --

            CC_LOCK_UNLOCK  1       Unlock the NC
    --        CC_LOCK_READER  2       Lock the NC for reading
    --        CC_LOCK_WRITER  3       Lock the NC for writing
    -- 
    --        CC_LOCK_NOBLOCK 16      Don't block, but return an error code if
    --                                the request cannot be satisfied.
    -- 
    -- --

    Locking is done on a per-thread basis. At most one thread may have --the credentials locked for writing; if so, there must not be any --threads that have the credentials locked for reading. -- --

    Multiple threads may have the cache locked for reading, as long as --there is not a writer lock asserted on the cache. -- --

    If a thread has a cache locked for reading, that lock may be --upgraded to a writer lock by calling cc_lock_request() with a --lock_type of CC_LOCK_WRITER. If a thread has the cache locked for --reading or writing, a request to cc_lock_request() for a reader or --writer lock, respectively, is a no-op. If a thread does not have the --cache locked, and calls cc_lock_request() with a lock_type of --CC_LOCK_UNLOCK, this is also a no-op. -- --

    A request for CC_LOCK_READER and CC_LOCK_WRITER may be made --non-blocking by logical or'ing the value CC_LOCK_NOBLOCK. In that --case, if it is not possible to satisfy the lock request, the error --CC_LOCKED will be returned. -- --

      -- --

    -- --

    Liberation Functions

    -- --

    -- -- --

    cc_free_principal

    -- --
    cc_int32 cc_free_principal(apiCB* cc_ctx, char** principal)
    -- --

    This function frees the principal returned by --cc_get_principal() and sets *principal to NULL. -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM -- --


    -- -- -- --

    cc_free_name

    -- --
    cc_int32 cc_free_name(apiCB* cc_ctx, char** name)
    -- --

    This function frees the name returned by cc_get_name() and --sets *name to NULL. -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM -- --


    -- -- -- --

    cc_free_creds

    -- --
    cc_int32 cc_free_creds(apiCB* cc_ctx, cred_union** creds)
    -- --

    This function frees all storage associated with creds returned by --cc_seq_fetch_creds() and sets the creds pointer to NULL. -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM -- --


    -- -- -- --

    cc_free_NC_info

    -- --
    cc_int32 cc_free_NC_info(apiCB* cc_ctx, infoNC*** ppNCi)
    -- --

    This routine frees all storage aquired by cc_get_NC_info() and --sets ppNCi to NULL. -- --

    Possible error codes: CC_NOERROR, CC_NO_EXIST, CC_BAD_PARM -- -- -- -- -- -diff --git a/doc/ccapi/html/doxygen.css b/doc/ccapi/html/doxygen.css -deleted file mode 100644 -index 05615b2e6..000000000 ---- a/doc/ccapi/html/doxygen.css -+++ /dev/null -@@ -1,310 +0,0 @@ --BODY,H1,H2,H3,H4,H5,H6,P,CENTER,TD,TH,UL,DL,DIV { -- font-family: Geneva, Arial, Helvetica, sans-serif; --} --BODY,TD { -- font-size: 90%; --} --H1 { -- text-align: center; -- font-size: 160%; --} --H2 { -- font-size: 120%; --} --H3 { -- font-size: 100%; --} --CAPTION { font-weight: bold } --DIV.qindex { -- width: 100%; -- background-color: #e8eef2; -- border: 1px solid #84b0c7; -- text-align: center; -- margin: 2px; -- padding: 2px; -- line-height: 140%; --} --DIV.nav { -- width: 100%; -- background-color: #e8eef2; -- border: 1px solid #84b0c7; -- text-align: center; -- margin: 2px; -- padding: 2px; -- line-height: 140%; --} --DIV.navtab { -- background-color: #e8eef2; -- border: 1px solid #84b0c7; -- text-align: center; -- margin: 2px; -- margin-right: 15px; -- padding: 2px; --} --TD.navtab { -- font-size: 70%; --} --A.qindex { -- text-decoration: none; -- font-weight: bold; -- color: #1A419D; --} --A.qindex:visited { -- text-decoration: none; -- font-weight: bold; -- color: #1A419D --} --A.qindex:hover { -- text-decoration: none; -- background-color: #ddddff; --} --A.qindexHL { -- text-decoration: none; -- font-weight: bold; -- background-color: #6666cc; -- color: #ffffff; -- border: 1px double #9295C2; --} --A.qindexHL:hover { -- text-decoration: none; -- background-color: #6666cc; -- color: #ffffff; --} --A.qindexHL:visited { text-decoration: none; background-color: #6666cc; color: #ffffff } --A.el { text-decoration: none; font-weight: bold } --A.elRef { font-weight: bold } --A.code:link { text-decoration: none; font-weight: normal; color: #0000FF} --A.code:visited { text-decoration: none; font-weight: normal; color: #0000FF} --A.codeRef:link { font-weight: normal; color: #0000FF} --A.codeRef:visited { font-weight: normal; color: #0000FF} --A:hover { text-decoration: none; background-color: #f2f2ff } --DL.el { margin-left: -1cm } --.fragment { -- font-family: Fixed, monospace; -- font-size: 95%; --} --PRE.fragment { -- border: 1px solid #CCCCCC; -- background-color: #f5f5f5; -- margin-top: 4px; -- margin-bottom: 4px; -- margin-left: 2px; -- margin-right: 8px; -- padding-left: 6px; -- padding-right: 6px; -- padding-top: 4px; -- padding-bottom: 4px; --} --DIV.ah { background-color: black; font-weight: bold; color: #ffffff; margin-bottom: 3px; margin-top: 3px } --TD.md { background-color: #F4F4FB; font-weight: bold; } --TD.mdPrefix { -- background-color: #F4F4FB; -- color: #606060; -- font-size: 80%; --} --TD.mdname1 { background-color: #F4F4FB; font-weight: bold; color: #602020; } --TD.mdname { background-color: #F4F4FB; font-weight: bold; color: #602020; width: 600px; } --DIV.groupHeader { -- margin-left: 16px; -- margin-top: 12px; -- margin-bottom: 6px; -- font-weight: bold; --} --DIV.groupText { margin-left: 16px; font-style: italic; font-size: 90% } --BODY { -- background: white; -- color: black; -- margin-right: 20px; -- margin-left: 20px; --} --TD.indexkey { -- background-color: #e8eef2; -- font-weight: bold; -- padding-right : 10px; -- padding-top : 2px; -- padding-left : 10px; -- padding-bottom : 2px; -- margin-left : 0px; -- margin-right : 0px; -- margin-top : 2px; -- margin-bottom : 2px; -- border: 1px solid #CCCCCC; --} --TD.indexvalue { -- background-color: #e8eef2; -- font-style: italic; -- padding-right : 10px; -- padding-top : 2px; -- padding-left : 10px; -- padding-bottom : 2px; -- margin-left : 0px; -- margin-right : 0px; -- margin-top : 2px; -- margin-bottom : 2px; -- border: 1px solid #CCCCCC; --} --TR.memlist { -- background-color: #f0f0f0; --} --P.formulaDsp { text-align: center; } --IMG.formulaDsp { } --IMG.formulaInl { vertical-align: middle; } --SPAN.keyword { color: #008000 } --SPAN.keywordtype { color: #604020 } --SPAN.keywordflow { color: #e08000 } --SPAN.comment { color: #800000 } --SPAN.preprocessor { color: #806020 } --SPAN.stringliteral { color: #002080 } --SPAN.charliteral { color: #008080 } --.mdTable { -- border: 1px solid #868686; -- background-color: #F4F4FB; --} --.mdRow { -- padding: 8px 10px; --} --.mdescLeft { -- padding: 0px 8px 4px 8px; -- font-size: 80%; -- font-style: italic; -- background-color: #FAFAFA; -- border-top: 1px none #E0E0E0; -- border-right: 1px none #E0E0E0; -- border-bottom: 1px none #E0E0E0; -- border-left: 1px none #E0E0E0; -- margin: 0px; --} --.mdescRight { -- padding: 0px 8px 4px 8px; -- font-size: 80%; -- font-style: italic; -- background-color: #FAFAFA; -- border-top: 1px none #E0E0E0; -- border-right: 1px none #E0E0E0; -- border-bottom: 1px none #E0E0E0; -- border-left: 1px none #E0E0E0; -- margin: 0px; --} --.memItemLeft { -- padding: 1px 0px 0px 8px; -- margin: 4px; -- border-top-width: 1px; -- border-right-width: 1px; -- border-bottom-width: 1px; -- border-left-width: 1px; -- border-top-color: #E0E0E0; -- border-right-color: #E0E0E0; -- border-bottom-color: #E0E0E0; -- border-left-color: #E0E0E0; -- border-top-style: solid; -- border-right-style: none; -- border-bottom-style: none; -- border-left-style: none; -- background-color: #FAFAFA; -- font-size: 80%; --} --.memItemRight { -- padding: 1px 8px 0px 8px; -- margin: 4px; -- border-top-width: 1px; -- border-right-width: 1px; -- border-bottom-width: 1px; -- border-left-width: 1px; -- border-top-color: #E0E0E0; -- border-right-color: #E0E0E0; -- border-bottom-color: #E0E0E0; -- border-left-color: #E0E0E0; -- border-top-style: solid; -- border-right-style: none; -- border-bottom-style: none; -- border-left-style: none; -- background-color: #FAFAFA; -- font-size: 80%; --} --.memTemplItemLeft { -- padding: 1px 0px 0px 8px; -- margin: 4px; -- border-top-width: 1px; -- border-right-width: 1px; -- border-bottom-width: 1px; -- border-left-width: 1px; -- border-top-color: #E0E0E0; -- border-right-color: #E0E0E0; -- border-bottom-color: #E0E0E0; -- border-left-color: #E0E0E0; -- border-top-style: none; -- border-right-style: none; -- border-bottom-style: none; -- border-left-style: none; -- background-color: #FAFAFA; -- font-size: 80%; --} --.memTemplItemRight { -- padding: 1px 8px 0px 8px; -- margin: 4px; -- border-top-width: 1px; -- border-right-width: 1px; -- border-bottom-width: 1px; -- border-left-width: 1px; -- border-top-color: #E0E0E0; -- border-right-color: #E0E0E0; -- border-bottom-color: #E0E0E0; -- border-left-color: #E0E0E0; -- border-top-style: none; -- border-right-style: none; -- border-bottom-style: none; -- border-left-style: none; -- background-color: #FAFAFA; -- font-size: 80%; --} --.memTemplParams { -- padding: 1px 0px 0px 8px; -- margin: 4px; -- border-top-width: 1px; -- border-right-width: 1px; -- border-bottom-width: 1px; -- border-left-width: 1px; -- border-top-color: #E0E0E0; -- border-right-color: #E0E0E0; -- border-bottom-color: #E0E0E0; -- border-left-color: #E0E0E0; -- border-top-style: solid; -- border-right-style: none; -- border-bottom-style: none; -- border-left-style: none; -- color: #606060; -- background-color: #FAFAFA; -- font-size: 80%; --} --.search { color: #003399; -- font-weight: bold; --} --FORM.search { -- margin-bottom: 0px; -- margin-top: 0px; --} --INPUT.search { font-size: 75%; -- color: #000080; -- font-weight: normal; -- background-color: #e8eef2; --} --TD.tiny { font-size: 75%; --} --a { -- color: #1A41A8; --} --a:visited { -- color: #2A3798; --} --.dirtab { padding: 4px; -- border-collapse: collapse; -- border: 1px solid #84b0c7; --} --TH.dirtab { background: #e8eef2; -- font-weight: bold; --} --HR { height: 1px; -- border: none; -- border-top: 1px solid black; --} -- -diff --git a/doc/ccapi/html/doxygen.png b/doc/ccapi/html/doxygen.png -deleted file mode 100644 -index f0a274bbaffdd67f6d784c894d9cf28729db0e14..0000000000000000000000000000000000000000 -GIT binary patch -literal 0 -HcmV?d00001 - -literal 1281 -zcmaJ>ZA?>F7(Vx-ms?uoS`b@hdRtpo6o^%HU>M$hfGrBvQnk$LE?p^P!kn&ikhyq! -zX~V@&tPF5Qt@V?oTL96Bi%aRiwbe1)9DWQI#?)=HxS7QSw`J`5fAJ*eJbB;uNuKA& -zdERDo*{Y<(If(#(B$Lr#;nB(8Y#ia=ZCeW?JfPLuQY`=@cW$k}Rivq|vbxGrRq1Tl9;+(gNt?}UtVKM2`T5t1jLzuL@0UIs`S#vlhl4)^ -zLgSYrPj@$+`|j?eSbXTmiHGkWxV8V}BzNR?pl9k_s4pDu9vd5a_UzZEPk)}Ad{AV_ -zzddrjrh4=Imr`E06;LY{)YYt?o}L~H@7C}F^WB!Ra=v`Q0bj{>5&$66CWF>mf6vjP -z2N>RRY6ZYa=K`76>+|_)Xdwko+7wv}7cN|btOhWb(*{sta~6b?S8Omrxw}!4`NhGr -zZVpNqpu1@BE`QGWNTpEpcJVW5izu~2B^GlM?1(OPg)zwW;QcP@Ltcclm>XbJL9C|j -z=9!2?ua=uIlf0%AndzHsRC}IyTL$EhAee(fdKB`?27KeS^2M8M_7b~PiCFO&r5LC7 -z7gl1*a<8;SjNaw#h=843_AV9iZbWQOAp5YOC^&_F*9K0> -zB|6%IDb?aM#3viTxkLU4aXg&@+CkNTOnQ1iMP*^?b|^lJy$4C)Zk4isV!|RZ*XhXh -zw8q3$=*0LeGC!XI_Wc?dkT~3+*Gu%%yIqP+Wr3H$=&ROMQU6q}Ag^P~>c5vAEO;a- -z_dK-3PPeKar%)6$j~vI2#*-YH!1h6HYVtwCX5_wM`iF#UKz&&@9Oo5w3%XGYrX -zW>dY~)SG-((Yim%`InwgTvyRC?e=Wh^8KCao!R6Eg&TpVWUY1sN~4G}V?nFnEGo-; -zHZ_$eW9-GnC%^WS9b -z@p;-$oH#MtC0v>Q$HX%4^JdFdO$0cbv-W)Q -TtK}Eh@>>I#ipmV1>S*>q-hkC} - -diff --git a/doc/ccapi/html/group__cc__ccache__iterator__reference.html b/doc/ccapi/html/group__cc__ccache__iterator__reference.html -deleted file mode 100644 -index 2c8bfe27b..000000000 ---- a/doc/ccapi/html/group__cc__ccache__iterator__reference.html -+++ /dev/null -@@ -1,96 +0,0 @@ -- -- --Credentials Cache API : cc_ccache_iterator_t Overview -- -- -- -- --

    cc_ccache_iterator_t Overview


    Detailed Description

    --The cc_ccache_iterator_t type represents an iterator that iterates over a set of ccaches and returns them in all in some order. A new instance of this type can be obtained by calling cc_context_new_ccache_iterator().

    --For API function documentation see cc_ccache_iterator_f. --

    --

    Data Structures

    -- --

    Typedefs

    -- --

    Typedef Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_ccache_iterator_f cc_ccache_iterator_f
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_ccache_iterator_d cc_ccache_iterator_d
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef cc_ccache_iterator_d* cc_ccache_iterator_t
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/group__cc__ccache__reference.html b/doc/ccapi/html/group__cc__ccache__reference.html -deleted file mode 100644 -index ce47b73c6..000000000 ---- a/doc/ccapi/html/group__cc__ccache__reference.html -+++ /dev/null -@@ -1,96 +0,0 @@ -- -- --Credentials Cache API : cc_ccache_t Overview -- -- -- -- --

    cc_ccache_t Overview


    Detailed Description

    --The cc_ccache_t type represents a reference to a ccache. Callers can access a ccache and the credentials stored in it via a cc_ccache_t. A cc_ccache_t can be acquired via cc_context_open_ccache(), cc_context_open_default_ccache(), or cc_ccache_iterator_next().

    --For API function documentation see cc_ccache_f. --

    --

    Data Structures

    -- --

    Typedefs

    -- --

    Typedef Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_ccache_f cc_ccache_f
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_ccache_d cc_ccache_d
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef cc_ccache_d* cc_ccache_t
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/group__cc__context__reference.html b/doc/ccapi/html/group__cc__context__reference.html -deleted file mode 100644 -index cd7e6be3d..000000000 ---- a/doc/ccapi/html/group__cc__context__reference.html -+++ /dev/null -@@ -1,161 +0,0 @@ -- -- --Credentials Cache API : cc_context_t Overview -- -- -- -- --

    cc_context_t Overview


    Detailed Description

    --The cc_context_t type gives the caller access to a ccache collection. Before being able to call any functions in the CCache API, the caller needs to acquire an instance of cc_context_t by calling cc_initialize().

    --For API function documentation see cc_context_f. --

    --

    Data Structures

    -- --

    Typedefs

    -- --

    Functions

    -- --

    Typedef Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_context_f cc_context_f
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_context_d cc_context_d
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef cc_context_d* cc_context_t
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --


    Function Documentation

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    CCACHE_API cc_int32 cc_initialize cc_context_t out_context,
    cc_int32  in_version,
    cc_int32 out_supported_version,
    char const **  out_vendor
    --
    -- -- -- -- -- --
    --   -- -- --

    --Initialize a new cc_context. --

    --

    Parameters:
    -- -- -- -- -- --
    out_context on exit, a new context object. Must be free with cc_context_release().
    in_version the requested API version. This should be the maximum version the application supports.
    out_supported_version if non-NULL, on exit contains the maximum API version supported by the implementation.
    out_vendor if non-NULL, on exit contains a pointer to a read-only C string which contains a string describing the vendor which implemented the credentials cache API.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure. May return CCAPI v2 error CC_BAD_API_VERSION if ccapi_version_2 is passed in.
    --
    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/group__cc__credentials__iterator__reference.html b/doc/ccapi/html/group__cc__credentials__iterator__reference.html -deleted file mode 100644 -index 41ba42f86..000000000 ---- a/doc/ccapi/html/group__cc__credentials__iterator__reference.html -+++ /dev/null -@@ -1,133 +0,0 @@ -- -- --Credentials Cache API : cc_credentials_iterator_t -- -- -- -- --

    cc_credentials_iterator_t


    Detailed Description

    --The cc_credentials_iterator_t type represents an iterator that iterates over a set of credentials. A new instance of this type can be obtained by calling cc_ccache_new_credentials_iterator().

    --For API function documentation see cc_credentials_iterator_f. --

    --

    Data Structures

    -- --

    Typedefs

    -- --

    Variables

    -- --

    Typedef Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_credentials_iterator_f cc_credentials_iterator_f
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_credentials_iterator_d cc_credentials_iterator_d
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef cc_credentials_iterator_d* cc_credentials_iterator_t
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --


    Variable Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* clone)(cc_credentials_iterator_t in_credentials_iterator, cc_credentials_iterator_t *out_credentials_iterator) [inherited]
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_credentials_iterator_clone(): Make a copy of a credentials iterator. --

    --

    Parameters:
    -- -- -- --
    in_credentials_iterator a credentials iterator object.
    out_credentials_iterator on exit, a copy of in_credentials_iterator.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/group__cc__credentials__reference.html b/doc/ccapi/html/group__cc__credentials__reference.html -deleted file mode 100644 -index d083e6c07..000000000 ---- a/doc/ccapi/html/group__cc__credentials__reference.html -+++ /dev/null -@@ -1,197 +0,0 @@ -- -- --Credentials Cache API : cc_credentials_t Overview -- -- -- -- --

    cc_credentials_t Overview


    Detailed Description

    --The cc_credentials_t type is used to store a single set of credentials for either Kerberos v4 or Kerberos v5. In addition to its only function, release(), it contains a pointer to a cc_credentials_union structure. A cc_credentials_union structure contains an integer of the enumerator type cc_credentials_version, which is either cc_credentials_v4 or cc_credentials_v5, and a pointer union, which contains either a cc_credentials_v4_t pointer or a cc_credentials_v5_t pointer, depending on the value in version.

    --Variables of the type cc_credentials_t are allocated by the CCAPI implementation, and should be released with their release() function. API functions which receive credentials structures from the caller always accept cc_credentials_union, which is allocated by the caller, and accordingly disposed by the caller.

    --For API functions see cc_credentials_f. --

    --

    Data Structures

    -- --

    Typedefs

    -- --

    Typedef Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_credentials_v4_t cc_credentials_v4_t
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_data cc_data
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_credentials_v5_t cc_credentials_v5_t
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_credentials_union cc_credentials_union
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_credentials_f cc_credentials_f
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_credentials_d cc_credentials_d
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef cc_credentials_d* cc_credentials_t
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/group__cc__string__reference.html b/doc/ccapi/html/group__cc__string__reference.html -deleted file mode 100644 -index 9ce3b7195..000000000 ---- a/doc/ccapi/html/group__cc__string__reference.html -+++ /dev/null -@@ -1,96 +0,0 @@ -- -- --Credentials Cache API : cc_string_t Overview -- -- -- -- --

    cc_string_t Overview


    Detailed Description

    --The cc_string_t represents a C string returned by the API. It has a pointer to the string data and a release() function. This type is used for both principal names and ccache names returned by the API. Principal names may contain UTF-8 encoded strings for internationalization purposes.

    --For API function documentation see cc_string_f. --

    --

    Data Structures

    -- --

    Typedefs

    -- --

    Typedef Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_string_f cc_string_f
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef struct cc_string_d cc_string_d
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef cc_string_d* cc_string_t
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/group__ccapi__constants__reference.html b/doc/ccapi/html/group__ccapi__constants__reference.html -deleted file mode 100644 -index 87ec30b83..000000000 ---- a/doc/ccapi/html/group__ccapi__constants__reference.html -+++ /dev/null -@@ -1,407 +0,0 @@ -- -- --Credentials Cache API : Constants -- -- -- -- --

    Constants

    --

    --

    Enumerations

    -- --

    Enumeration Type Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    anonymous enum
    --
    -- -- -- -- -- --
    --   -- -- --

    --API version numbers

    --These constants are passed into cc_initialize() to indicate the version of the API the caller wants to use.

    --CCAPI v1 and v2 are deprecated and should not be used.

    Enumerator:
    -- -- -- -- -- -- -- -- --
    ccapi_version_2  --
    ccapi_version_3  --
    ccapi_version_4  --
    ccapi_version_5  --
    ccapi_version_6  --
    ccapi_version_7  --
    ccapi_version_max  --
    --
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    anonymous enum
    --
    -- -- -- -- -- --
    --   -- -- --

    --Error codes

    Enumerator:
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    ccNoError  --Success.
    ccIteratorEnd  --Iterator is done iterating.
    ccErrBadParam  --Bad parameter (NULL or invalid pointer where valid pointer expected).
    ccErrNoMem  --Not enough memory to complete the operation.
    ccErrInvalidContext  --Context is invalid (e.g., it was released).
    ccErrInvalidCCache  --CCache is invalid (e.g., it was released or destroyed).
    ccErrInvalidString  --String is invalid (e.g., it was released).
    ccErrInvalidCredentials  --Credentials are invalid (e.g., they were released), or they have a bad version.
    ccErrInvalidCCacheIterator  --CCache iterator is invalid (e.g., it was released).
    ccErrInvalidCredentialsIterator  --Credentials iterator is invalid (e.g., it was released).
    ccErrInvalidLock  --Lock is invalid (e.g., it was released).
    ccErrBadName  --Bad credential cache name format.
    ccErrBadCredentialsVersion  --Credentials version is invalid.
    ccErrBadAPIVersion  --Unsupported API version.
    ccErrContextLocked  --Context is already locked.
    ccErrContextUnlocked  --Context is not locked by the caller.
    ccErrCCacheLocked  --CCache is already locked.
    ccErrCCacheUnlocked  --CCache is not locked by the caller.
    ccErrBadLockType  --Bad lock type.
    ccErrNeverDefault  --CCache was never default.
    ccErrCredentialsNotFound  --Matching credentials not found in the ccache.
    ccErrCCacheNotFound  --Matching ccache not found in the collection.
    ccErrContextNotFound  --Matching cache collection not found.
    ccErrServerUnavailable  --CCacheServer is unavailable.
    ccErrServerInsecure  --CCacheServer has detected that it is running as the wrong user.
    ccErrServerCantBecomeUID  --CCacheServer failed to start running as the user.
    ccErrTimeOffsetNotSet  --KDC time offset not set for this ccache.
    ccErrBadInternalMessage  --The client and CCacheServer can't communicate (e.g., a version mismatch).
    ccErrNotImplemented  --API function not supported by this implementation.
    ccErrClientNotFound  --CCacheServer has no record of the caller's process (e.g., the server crashed).
    --
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    enum cc_credential_versions
    --
    -- -- -- -- -- --
    --   -- -- --

    --Credentials versions

    --These constants are used in several places in the API to discern between Kerberos v4 and Kerberos v5. Not all values are valid inputs and outputs for all functions; function specifications below detail the allowed values.

    --Kerberos version constants will always be a bit-field, and can be tested as such; for example the following test will tell you if a ccacheVersion includes v5 credentials:

    --if ((ccacheVersion & cc_credentials_v5) != 0)

    Enumerator:
    -- -- -- -- --
    cc_credentials_v4  --
    cc_credentials_v5  --
    cc_credentials_v4_v5  --
    --
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    enum cc_lock_types
    --
    -- -- -- -- -- --
    --   -- -- --

    --Lock types

    --These constants are used in the locking functions to describe the type of lock requested. Note that all CCAPI locks are advisory so only callers using the lock calls will be blocked by each other. This is because locking functions were introduced after the CCAPI came into common use and we did not want to break existing callers.

    Enumerator:
    -- -- -- -- -- --
    cc_lock_read  --
    cc_lock_write  --
    cc_lock_upgrade  --
    cc_lock_downgrade  --
    --
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    enum cc_lock_modes
    --
    -- -- -- -- -- --
    --   -- -- --

    --Locking Modes

    --These constants are used in the advisory locking functions to describe whether or not the lock function should block waiting for a lock or return an error immediately. For example, attempting to acquire a lock with a non-blocking call will result in an error if the lock cannot be acquired; otherwise, the call will block until the lock can be acquired.

    Enumerator:
    -- -- -- --
    cc_lock_noblock  --
    cc_lock_block  --
    --
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    anonymous enum
    --
    -- -- -- -- -- --
    --   -- -- --

    --Sizes of fields in cc_credentials_v4_t.

    Enumerator:
    -- -- -- -- -- -- --
    cc_v4_name_size  --
    cc_v4_instance_size  --
    cc_v4_realm_size  --
    cc_v4_ticket_size  --
    cc_v4_key_size  --
    --
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    enum cc_string_to_key_type
    --
    -- -- -- -- -- --
    --   -- -- --

    --String to key type (Kerberos v4 only)

    Enumerator:
    -- -- -- -- -- -- --
    cc_v4_stk_afs  --
    cc_v4_stk_des  --
    cc_v4_stk_columbia_special  --
    cc_v4_stk_krb5  --
    cc_v4_stk_unknown  --
    --
    --
    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/group__ccapi__types__reference.html b/doc/ccapi/html/group__ccapi__types__reference.html -deleted file mode 100644 -index 9c646b8d9..000000000 ---- a/doc/ccapi/html/group__ccapi__types__reference.html -+++ /dev/null -@@ -1,138 +0,0 @@ -- -- --Credentials Cache API : Basic Types -- -- -- -- --

    Basic Types

    --

    --

    Typedefs

    -- --

    Typedef Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef uint32_t cc_uint32
    --
    -- -- -- -- -- --
    --   -- -- --

    --Unsigned 32-bit integer type

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef int32_t cc_int32
    --
    -- -- -- -- -- --
    --   -- -- --

    --Signed 32-bit integer type

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef int64_t cc_int64
    --
    -- -- -- -- -- --
    --   -- -- --

    --Unsigned 64-bit integer type

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef uint64_t cc_uint64
    --
    -- -- -- -- -- --
    --   -- -- --

    --Signed 64-bit integer type

    --

    -- -- -- -- --
    -- -- -- -- --
    typedef cc_uint32 cc_time_t
    --
    -- -- -- -- -- --
    --   -- -- --

    --The cc_time_t type is used to represent a time in seconds. The time must be stored as the number of seconds since midnight GMT on January 1, 1970.

    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/group__helper__macros.html b/doc/ccapi/html/group__helper__macros.html -deleted file mode 100644 -index cf1c681dc..000000000 ---- a/doc/ccapi/html/group__helper__macros.html -+++ /dev/null -@@ -1,1377 +0,0 @@ -- -- --Credentials Cache API : CCAPI Function Helper Macros -- -- -- -- --

    CCAPI Function Helper Macros

    --

    --

    Defines

    --
      --
    • #define cc_context_release(context)   ((context) -> functions -> release (context)) --
    • #define cc_context_get_change_time(context, change_time)   ((context) -> functions -> get_change_time (context, change_time)) --
    • #define cc_context_get_default_ccache_name(context, name)   ((context) -> functions -> get_default_ccache_name (context, name)) --
    • #define cc_context_open_ccache(context, name, ccache)   ((context) -> functions -> open_ccache (context, name, ccache)) --
    • #define cc_context_open_default_ccache(context, ccache)   ((context) -> functions -> open_default_ccache (context, ccache)) --
    • #define cc_context_create_ccache(context, name, version, principal, ccache)   ((context) -> functions -> create_ccache (context, name, version, principal, ccache)) --
    • #define cc_context_create_default_ccache(context, version, principal, ccache)   ((context) -> functions -> create_default_ccache (context, version, principal, ccache)) --
    • #define cc_context_create_new_ccache(context, version, principal, ccache)   ((context) -> functions -> create_new_ccache (context, version, principal, ccache)) --
    • #define cc_context_new_ccache_iterator(context, iterator)   ((context) -> functions -> new_ccache_iterator (context, iterator)) --
    • #define cc_context_lock(context, type, block)   ((context) -> functions -> lock (context, type, block)) --
    • #define cc_context_unlock(context)   ((context) -> functions -> unlock (context)) --
    • #define cc_context_compare(context, compare_to, equal)   ((context) -> functions -> compare (context, compare_to, equal)) --
    • #define cc_context_wait_for_change(context)   ((context) -> functions -> wait_for_change (context)) --
    • #define cc_ccache_release(ccache)   ((ccache) -> functions -> release (ccache)) --
    • #define cc_ccache_destroy(ccache)   ((ccache) -> functions -> destroy (ccache)) --
    • #define cc_ccache_set_default(ccache)   ((ccache) -> functions -> set_default (ccache)) --
    • #define cc_ccache_get_credentials_version(ccache, version)   ((ccache) -> functions -> get_credentials_version (ccache, version)) --
    • #define cc_ccache_get_name(ccache, name)   ((ccache) -> functions -> get_name (ccache, name)) --
    • #define cc_ccache_get_principal(ccache, version, principal)   ((ccache) -> functions -> get_principal (ccache, version, principal)) --
    • #define cc_ccache_set_principal(ccache, version, principal)   ((ccache) -> functions -> set_principal (ccache, version, principal)) --
    • #define cc_ccache_store_credentials(ccache, credentials)   ((ccache) -> functions -> store_credentials (ccache, credentials)) --
    • #define cc_ccache_remove_credentials(ccache, credentials)   ((ccache) -> functions -> remove_credentials (ccache, credentials)) --
    • #define cc_ccache_new_credentials_iterator(ccache, iterator)   ((ccache) -> functions -> new_credentials_iterator (ccache, iterator)) --
    • #define cc_ccache_lock(ccache, type, block)   ((ccache) -> functions -> lock (ccache, type, block)) --
    • #define cc_ccache_unlock(ccache)   ((ccache) -> functions -> unlock (ccache)) --
    • #define cc_ccache_get_last_default_time(ccache, last_default_time)   ((ccache) -> functions -> get_last_default_time (ccache, last_default_time)) --
    • #define cc_ccache_get_change_time(ccache, change_time)   ((ccache) -> functions -> get_change_time (ccache, change_time)) --
    • #define cc_ccache_move(source, destination)   ((source) -> functions -> move (source, destination)) --
    • #define cc_ccache_compare(ccache, compare_to, equal)   ((ccache) -> functions -> compare (ccache, compare_to, equal)) --
    • #define cc_ccache_get_kdc_time_offset(ccache, version, time_offset)   ((ccache) -> functions -> get_kdc_time_offset (ccache, version, time_offset)) --
    • #define cc_ccache_set_kdc_time_offset(ccache, version, time_offset)   ((ccache) -> functions -> set_kdc_time_offset (ccache, version, time_offset)) --
    • #define cc_ccache_clear_kdc_time_offset(ccache, version)   ((ccache) -> functions -> clear_kdc_time_offset (ccache, version)) --
    • #define cc_ccache_wait_for_change(ccache)   ((ccache) -> functions -> wait_for_change (ccache)) --
    • #define cc_string_release(string)   ((string) -> functions -> release (string)) --
    • #define cc_credentials_release(credentials)   ((credentials) -> functions -> release (credentials)) --
    • #define cc_credentials_compare(credentials, compare_to, equal)   ((credentials) -> functions -> compare (credentials, compare_to, equal)) --
    • #define cc_ccache_iterator_release(iterator)   ((iterator) -> functions -> release (iterator)) --
    • #define cc_ccache_iterator_next(iterator, ccache)   ((iterator) -> functions -> next (iterator, ccache)) --
    • #define cc_ccache_iterator_clone(iterator, new_iterator)   ((iterator) -> functions -> clone (iterator, new_iterator)) --
    • #define cc_credentials_iterator_release(iterator)   ((iterator) -> functions -> release (iterator)) --
    • #define cc_credentials_iterator_next(iterator, credentials)   ((iterator) -> functions -> next (iterator, credentials)) --
    • #define cc_credentials_iterator_clone(iterator, new_iterator)   ((iterator) -> functions -> clone (iterator, new_iterator)) --
    --

    Define Documentation

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- --
    #define cc_context_release context   )    ((context) -> functions -> release (context))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_context_f release()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_context_get_change_time context,
    change_time   )    ((context) -> functions -> get_change_time (context, change_time))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_context_f get_change_time()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_context_get_default_ccache_name context,
    name   )    ((context) -> functions -> get_default_ccache_name (context, name))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_context_f get_default_ccache_name()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_context_open_ccache context,
    name,
    ccache   )    ((context) -> functions -> open_ccache (context, name, ccache))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_context_f open_ccache()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_context_open_default_ccache context,
    ccache   )    ((context) -> functions -> open_default_ccache (context, ccache))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_context_f open_default_ccache()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_context_create_ccache context,
    name,
    version,
    principal,
    ccache   )    ((context) -> functions -> create_ccache (context, name, version, principal, ccache))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_context_f create_ccache()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_context_create_default_ccache context,
    version,
    principal,
    ccache   )    ((context) -> functions -> create_default_ccache (context, version, principal, ccache))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_context_f create_default_ccache()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_context_create_new_ccache context,
    version,
    principal,
    ccache   )    ((context) -> functions -> create_new_ccache (context, version, principal, ccache))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_context_f create_new_ccache()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_context_new_ccache_iterator context,
    iterator   )    ((context) -> functions -> new_ccache_iterator (context, iterator))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_context_f new_ccache_iterator()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_context_lock context,
    type,
    block   )    ((context) -> functions -> lock (context, type, block))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_context_f lock()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- --
    #define cc_context_unlock context   )    ((context) -> functions -> unlock (context))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_context_f unlock()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_context_compare context,
    compare_to,
    equal   )    ((context) -> functions -> compare (context, compare_to, equal))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_context_f compare()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- --
    #define cc_context_wait_for_change context   )    ((context) -> functions -> wait_for_change (context))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_context_f wait_for_change()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_release ccache   )    ((ccache) -> functions -> release (ccache))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f release()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_destroy ccache   )    ((ccache) -> functions -> destroy (ccache))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f destroy()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_set_default ccache   )    ((ccache) -> functions -> set_default (ccache))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f set_default()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_get_credentials_version ccache,
    version   )    ((ccache) -> functions -> get_credentials_version (ccache, version))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f get_credentials_version()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_get_name ccache,
    name   )    ((ccache) -> functions -> get_name (ccache, name))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f get_name()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_get_principal ccache,
    version,
    principal   )    ((ccache) -> functions -> get_principal (ccache, version, principal))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f get_principal()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_set_principal ccache,
    version,
    principal   )    ((ccache) -> functions -> set_principal (ccache, version, principal))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f set_principal()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_store_credentials ccache,
    credentials   )    ((ccache) -> functions -> store_credentials (ccache, credentials))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f store_credentials()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_remove_credentials ccache,
    credentials   )    ((ccache) -> functions -> remove_credentials (ccache, credentials))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f remove_credentials()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_new_credentials_iterator ccache,
    iterator   )    ((ccache) -> functions -> new_credentials_iterator (ccache, iterator))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f new_credentials_iterator()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_lock ccache,
    type,
    block   )    ((ccache) -> functions -> lock (ccache, type, block))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f lock()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_unlock ccache   )    ((ccache) -> functions -> unlock (ccache))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f unlock()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_get_last_default_time ccache,
    last_default_time   )    ((ccache) -> functions -> get_last_default_time (ccache, last_default_time))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f get_last_default_time()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_get_change_time ccache,
    change_time   )    ((ccache) -> functions -> get_change_time (ccache, change_time))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f get_change_time()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_move source,
    destination   )    ((source) -> functions -> move (source, destination))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f move()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_compare ccache,
    compare_to,
    equal   )    ((ccache) -> functions -> compare (ccache, compare_to, equal))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f compare()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_get_kdc_time_offset ccache,
    version,
    time_offset   )    ((ccache) -> functions -> get_kdc_time_offset (ccache, version, time_offset))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f get_kdc_time_offset()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_set_kdc_time_offset ccache,
    version,
    time_offset   )    ((ccache) -> functions -> set_kdc_time_offset (ccache, version, time_offset))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f set_kdc_time_offset()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_clear_kdc_time_offset ccache,
    version   )    ((ccache) -> functions -> clear_kdc_time_offset (ccache, version))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f clear_kdc_time_offset()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_wait_for_change ccache   )    ((ccache) -> functions -> wait_for_change (ccache))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_f wait_for_change()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- --
    #define cc_string_release string   )    ((string) -> functions -> release (string))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_string_f release()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- --
    #define cc_credentials_release credentials   )    ((credentials) -> functions -> release (credentials))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_credentials_f release()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_credentials_compare credentials,
    compare_to,
    equal   )    ((credentials) -> functions -> compare (credentials, compare_to, equal))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_credentials_f compare()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_iterator_release iterator   )    ((iterator) -> functions -> release (iterator))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_iterator_f release()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_iterator_next iterator,
    ccache   )    ((iterator) -> functions -> next (iterator, ccache))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_iterator_f next()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_ccache_iterator_clone iterator,
    new_iterator   )    ((iterator) -> functions -> clone (iterator, new_iterator))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_ccache_iterator_f clone()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- --
    #define cc_credentials_iterator_release iterator   )    ((iterator) -> functions -> release (iterator))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_credentials_iterator_f release()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_credentials_iterator_next iterator,
    credentials   )    ((iterator) -> functions -> next (iterator, credentials))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_credentials_iterator_f next()

    --

    -- -- -- -- --
    -- -- -- -- -- -- -- -- -- -- -- -- --
    #define cc_credentials_iterator_clone iterator,
    new_iterator   )    ((iterator) -> functions -> clone (iterator, new_iterator))
    --
    -- -- -- -- -- --
    --   -- -- --

    --Helper macro for cc_credentials_iterator_f clone()

    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/index.html b/doc/ccapi/html/index.html -deleted file mode 100644 -index bf920052f..000000000 ---- a/doc/ccapi/html/index.html -+++ /dev/null -@@ -1,85 +0,0 @@ -- -- --Credentials Cache API : Credentials Cache API (CCAPI) Documentation -- -- -- -- --

    Credentials Cache API (CCAPI) Documentation

    --

    --

    --Table of Contents

    -- -- -- -- -- -- -- -- --

    --Introduction

    --This is the specification for an API which provides Credentials Cache services for both Kerberos v5 and v4. The idea behind this API is that multiple Kerberos implementations can share a single collection of credentials caches, mediated by this API specification. On the Mac OS and Microsoft Windows platforms this will allow single-login, even when more than one Kerberos shared library is in use on a particular system.

    --Abstractly, a credentials cache collection contains one or more credentials caches, or ccaches. A ccache is uniquely identified by its name, which is a string internal to the API and not intended to be presented to users. The user presentable identifier of a ccache is its principal.

    --Unlike the previous versions of the API, version 3 of the API stores both Kerberos v4 and v5 credentials in the same ccache.

    --At any given time, one ccache is the "default" ccache. The exact meaning of a default ccache is OS-specific; refer to implementation requirements for details.

    --Error Handling

    --All functions of the API return some of the error constants listed FIXME; the exact list of error constants returned by any API function is provided in the function descriptions below.

    --When returning an error constant other than ccNoError or ccIteratorEnd, API functions never modify any of the values passed in by reference.

    --Synchronization and Atomicity

    --Every function in the API is atomic. In order to make a series of calls atomic, callers should lock the ccache or cache collection they are working with to advise other callers not to modify that container. Note that advisory locks are per container so even if you have a read lock on the cache collection other callers can obtain write locks on ccaches in that cache collection.

    --Note that iterators do not iterate over ccaches and credentials atomically because locking ccaches and the cache collection over every iteration would degrade performance considerably under high load. However, iterators do guarantee a consistent view of items they are iterating over. Iterators will never return duplicate entries or skip entries when items are removed or added to the container they are iterating over.

    --An application can always lock a ccache or the cache collection to guarantee that other callers participating in the advisory locking system do not modify the ccache or cache collection.

    --Implementations should not use copy-on-write techniques to implement locks because those techniques imply that same parts of the ccache collection remain visible to some callers even though they are not present in the collection, which is a potential security risk. For example, a copy-on-write technique might make a copy of the entire collection when a read lock is acquired, so as to allow the owner of the lock to access the collection in an apparently unmodified state, while also allowing others to make modifications to the collection. However, this would also enable the owner of the lock to indefinitely (until the expiration time) use credentials that have actually been deleted from the collection.

    --Object Memory Management

    --The lifetime of an object returned by the API is until release() is called for it. Releasing one object has no effect on existence of any other object. For example, a ccache obtained within a context continue to exist when the context is released.

    --Every object returned by the API (cc_context_t, cc_ccache_t, cc_ccache_iterator_t, cc_credentials_t, cc_credentials_iterator_t, cc_string_t) is owned by the caller of the API, and it is the responsibility of the caller to call release() for every object to prevent memory leaks.

    --Opaque Types

    --All of the opaque high-level types in CCache API are implemented as structures of function pointers and private data. To perform some operation on a type, the caller of the API has to first obtain an instance of that type, and then call the appropriate function pointer from that instance. For example, to call get_change_time() on a cc_context_t, one would call cc_initialize() which creates a new cc_context_t and then call its get_change_time(), like this:

    --

     cc_context_t context;
    -- cc_int32 err = cc_initialize (&context, ccapi_version_3, nil, nil);
    -- if (err == ccNoError)
    -- time = context->functions->get_change_time (context)
    --

    --All API functions also have convenience preprocessor macros, which make the API seem completely function-based. For example, cc_context_get_change_time (context, time) is equivalent to context->functions->get_change_time (context, time). The convenience macros follow the following naming convention:

    --The API function some_function()

     cc_type_t an_object;
    -- result = an_object->functions->some_function (opaque_pointer, args)
    --

    --has an equivalent convenience macro of the form cc_type_some_function():

     cc_type_t an_object;
    -- result = cc_type_some_function (an_object, args)
    --

    --The specifications below include the names for both the functions and the convenience macros, in that order. For clarity, it is recommended that clients using the API use the convenience macros, but that is merely a stylistic choice.

    --Implementing the API in this manner allows us to extend and change the interface in the future, while preserving compatibility with older clients.

    --For example, consider the case when the signature or the semantics of a cc_ccache_t function is changed. The API version number is incremented. The library implementation contains both a function with the old signature and semantics and a function with the new signature and semantics. When a context is created, the API version number used in that context is stored in the context, and therefore it can be used whenever a ccache is created in that context. When a ccache is created in a context with the old API version number, the function pointer structure for the ccache is filled with pointers to functions implementing the old semantics; when a ccache is created in a context with the new API version number, the function pointer structure for the ccache is filled with poitners to functions implementing the new semantics.

    --Similarly, if a function is added to the API, the version number in the context can be used to decide whether to include the implementation of the new function in the appropriate function pointer structure or not.


    Generated on Tue Oct 2 17:16:05 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__ccache__d.html b/doc/ccapi/html/structcc__ccache__d.html -deleted file mode 100644 -index c19aa2b59..000000000 ---- a/doc/ccapi/html/structcc__ccache__d.html -+++ /dev/null -@@ -1,43 +0,0 @@ -- -- --Credentials Cache API : cc_ccache_d Struct Reference -- -- -- -- --

    cc_ccache_d Struct Reference
    -- --[cc_ccache_t Overview] --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    const cc_ccache_f* functions
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --


    Generated on Tue Oct 2 17:16:05 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__ccache__f.html b/doc/ccapi/html/structcc__ccache__f.html -deleted file mode 100644 -index ddab94ff9..000000000 ---- a/doc/ccapi/html/structcc__ccache__f.html -+++ /dev/null -@@ -1,722 +0,0 @@ -- -- --Credentials Cache API : cc_ccache_f Struct Reference -- -- -- -- --

    cc_ccache_f Struct Reference


    Detailed Description

    --Function pointer table for cc_ccache_t. For more information see cc_ccache_t Overview. --

    --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* release)(cc_ccache_t io_ccache)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_release(): Release memory associated with a cc_ccache_t object. --

    --

    Parameters:
    -- -- --
    io_ccache the ccache object to release.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    Note:
    Does not modify the ccache. If you wish to remove the ccache see cc_ccache_destroy().
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* destroy)(cc_ccache_t io_ccache)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_destroy(): Destroy a ccache. --

    --

    Parameters:
    -- -- --
    io_ccache the ccache object to destroy and release.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --Destroy the ccache referred to by io_ccache and releases memory associated with the io_ccache object. After this call io_ccache becomes invalid. If io_ccache was the default ccache, the next ccache in the cache collection (if any) becomes the new default.
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* set_default)(cc_ccache_t io_ccache)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_set_default(): Make a ccache the default ccache. --

    --

    Parameters:
    -- -- --
    io_ccache a ccache object to make the new default ccache.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* get_credentials_version)(cc_ccache_t in_ccache, cc_uint32 *out_credentials_version)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_get_credentials_version(): Get the credentials version of a ccache. --

    --

    Parameters:
    -- -- -- --
    in_ccache a ccache object.
    out_credentials_version on exit, the credentials version of in_ccache.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --cc_ccache_get_credentials_version() returns one value of the enumerated type cc_credentials_vers. The possible return values are cc_credentials_v4 (if ccache's v4 principal has been set), cc_credentials_v5 (if ccache's v5 principal has been set), or cc_credentials_v4_v5 (if both ccache's v4 and v5 principals have been set). A ccache's principal is set with one of cc_context_create_ccache(), cc_context_create_new_ccache(), cc_context_create_default_ccache(), or cc_ccache_set_principal().
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* get_name)(cc_ccache_t in_ccache, cc_string_t *out_name)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_get_name(): Get the name of a ccache. --

    --

    Parameters:
    -- -- -- --
    in_ccache a ccache object.
    out_name on exit, a cc_string_t representing the name of in_ccache. out_name must be released with cc_string_release().
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* get_principal)(cc_ccache_t in_ccache, cc_uint32 in_credentials_version, cc_string_t *out_principal)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_get_principal(): Get the principal of a ccache. --

    --

    Parameters:
    -- -- -- -- --
    in_ccache a ccache object.
    in_credentials_version the credentials version to get the principal for.
    out_principal on exit, a cc_string_t representing the principal of in_ccache. out_principal must be released with cc_string_release().
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --Return the principal for the ccache that was set via cc_context_create_ccache(), cc_context_create_default_ccache(), cc_context_create_new_ccache(), or cc_ccache_set_principal(). Principals for v4 and v5 are separate, but should be kept synchronized for each ccache; they can be retrieved by passing cc_credentials_v4 or cc_credentials_v5 in cred_vers. Passing cc_credentials_v4_v5 will result in the error ccErrBadCredentialsVersion.
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* set_principal)(cc_ccache_t io_ccache, cc_uint32 in_credentials_version, const char *in_principal)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_set_principal(): Set the principal of a ccache. --

    --

    Parameters:
    -- -- -- -- --
    in_ccache a ccache object.
    in_credentials_version the credentials version to set the principal for.
    in_principal a C string representing the new principal of in_ccache.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --Set the a principal for ccache. The v4 and v5 principals can be set independently, but they should always be kept equal, up to differences in string representation between v4 and v5. Passing cc_credentials_v4_v5 in cred_vers will result in the error ccErrBadCredentialsVersion.
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* store_credentials)(cc_ccache_t io_ccache, const cc_credentials_union *in_credentials_union)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_store_credentials(): Store credentials in a ccache. --

    --

    Parameters:
    -- -- -- --
    io_ccache a ccache object.
    in_credentials_union the credentials to store in io_ccache.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --Store a copy of credentials in the ccache.

    --See the description of the credentials types for the meaning of cc_credentials_union fields.

    --Before credentials of a specific credential type can be stored in a ccache, the corresponding principal version has to be set. For example, before you can store Kerberos v4 credentials in a ccache, the Kerberos v4 principal has to be set either by cc_context_create_ccache(), cc_context_create_default_ccache(), cc_context_create_new_ccache(), or cc_ccache_set_principal(); likewise for Kerberos v5. Otherwise, ccErrBadCredentialsVersion is returned.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* remove_credentials)(cc_ccache_t io_ccache, cc_credentials_t in_credentials)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_remove_credentials(): Remove credentials from a ccache. --

    --

    Parameters:
    -- -- -- --
    io_ccache a ccache object.
    in_credentials the credentials to remove from io_ccache.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --Removes credentials from a ccache. Note that credentials must be previously acquired from the CCache API; only exactly matching credentials will be removed. (This places the burden of determining exactly which credentials to remove on the caller, but ensures there is no ambigity about which credentials will be removed.) cc_credentials_t objects can be obtained by iterating over the ccache's credentials with cc_ccache_new_credentials_iterator().

    --If found, the credentials are removed from the ccache. The credentials parameter is not modified and should be freed by the caller. It is legitimate to call this function while an iterator is traversing the ccache, and the deletion of a credential already returned by cc_credentials_iterator_next() will not disturb sequence of credentials returned by cc_credentials_iterator_next().

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* new_credentials_iterator)(cc_ccache_t in_ccache, cc_credentials_iterator_t *out_credentials_iterator)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_new_credentials_iterator(): Iterate over credentials in a ccache. --

    --

    Parameters:
    -- -- -- --
    in_ccache a ccache object.
    out_credentials_iterator a credentials iterator for io_ccache.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --Allocates memory for iterator and initializes it. Successive calls to cc_credentials_iterator_next() will return credentials from the ccache.

    --If changes are made to the ccache while an iterator is being used on it, the iterator must return at least the intersection, and at most the union, of the set of credentials that were in the ccache when the iteration began and the set of credentials that are in the ccache when it ends.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* move)(cc_ccache_t io_source_ccache, cc_ccache_t io_destination_ccache)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_move(): Move the contents of one ccache into another, destroying the source. --

    --

    Parameters:
    -- -- -- --
    io_source_ccache a ccache object to move.
    io_destination_ccache a ccache object replace with the contents of io_source_ccache.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --cc_ccache_move() atomically copies the credentials, credential versions and principals from one ccache to another. On successful completion io_source_ccache will be released and the ccache it points to will be destroyed. Any credentials previously in io_destination_ccache will be replaced with credentials from io_source_ccache. The only part of io_destination_ccache which remains constant is the name. Any other callers referring to io_destination_ccache will suddenly see new data in it.

    --Typically cc_ccache_move() is used when the caller wishes to safely overwrite the contents of a ccache with new data which requires several steps to generate. cc_ccache_move() allows the caller to create a temporary ccache (which can be destroyed if any intermediate step fails) and the atomically copy the temporary cache into the destination.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* lock)(cc_ccache_t io_ccache, cc_uint32 in_lock_type, cc_uint32 in_block)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_lock(): Lock a ccache. --

    --

    Parameters:
    -- -- -- -- --
    io_ccache the ccache object for the ccache you wish to lock.
    in_lock_type the type of lock to obtain.
    in_block whether or not the function should block if the lock cannot be obtained immediately.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --Attempts to acquire an advisory lock for a ccache. Allowed values for lock_type are:

    --

      --
    • cc_lock_read: a read lock.
    • --
    • cc_lock_write: a write lock
    • --
    • cc_lock_upgrade: upgrade an already-obtained read lock to a write lock
    • --
    • cc_lock_downgrade: downgrade an already-obtained write lock to a read lock
    • --
    --If block is cc_lock_block, lock() will not return until the lock is acquired. If block is cc_lock_noblock, lock() will return immediately, either acquiring the lock and returning ccNoError, or failing to acquire the lock and returning an error explaining why.

    --To avoid having to deal with differences between thread semantics on different platforms, locks are granted per ccache, rather than per thread or per process. That means that different threads of execution have to acquire separate contexts in order to be able to synchronize with each other.

    --The lock should be unlocked by using cc_ccache_unlock().

    --

    Note:
    All locks are advisory. For example, callers which do not call cc_ccache_lock() and cc_ccache_unlock() will not be prevented from writing to the ccache when you have a read lock. This is because the CCAPI locking was added after the first release and thus adding mandatory locks would have changed the user experience and performance of existing applications.
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* unlock)(cc_ccache_t io_ccache)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_unlock(): Unlock a ccache. --

    --

    Parameters:
    -- -- --
    io_ccache a ccache object.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* get_last_default_time)(cc_ccache_t in_ccache, cc_time_t *out_last_default_time)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_get_change_time(): Get the last time a ccache was the default ccache. --

    --

    Parameters:
    -- -- -- --
    in_ccache a cache object.
    out_last_default_time on exit, the last time the ccache was default.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --This function returns the last time when the ccache was made the default ccache. This allows clients to sort the ccaches by how recently they were default, which is useful for user listing of ccaches. If the ccache was never default, ccErrNeverDefault is returned.
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* get_change_time)(cc_ccache_t in_ccache, cc_time_t *out_change_time)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_get_change_time(): Get the last time a ccache changed. --

    --

    Parameters:
    -- -- -- --
    in_ccache a cache object.
    out_change_time on exit, the last time the ccache changed.
    --
    --
    Returns:
    On success, ccNoError. If the ccache was never the default ccache, ccErrNeverDefault. Otherwise, an error code representing the failure.
    --This function returns the time of the most recent change made to a ccache. By maintaining a local copy the caller can deduce whether or not the ccache has been modified since the previous call to cc_ccache_get_change_time().

    --The time returned by cc_ccache_get_change_time() increases whenever:

    --

      --
    • a credential is stored
    • --
    • a credential is removed
    • --
    • a ccache principal is changed
    • --
    • the ccache becomes the default ccache
    • --
    • the ccache is no longer the default ccache
    • --
    --
    Note:
    In order to be able to compare two values returned by cc_ccache_get_change_time(), the caller must use the same ccache object to acquire them. Callers should maintain a single ccache object in memory for cc_ccache_get_change_time() calls rather than creating a new ccache object for every call.
    --
    See also:
    wait_for_change
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* compare)(cc_ccache_t in_ccache, cc_ccache_t in_compare_to_ccache, cc_uint32 *out_equal)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_compare(): Compare two ccache objects. --

    --

    Parameters:
    -- -- -- -- --
    in_ccache a ccache object.
    in_compare_to_ccache a ccache object to compare with in_ccache.
    out_equal on exit, whether or not the two ccaches refer to the same ccache.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* get_kdc_time_offset)(cc_ccache_t in_ccache, cc_uint32 in_credentials_version, cc_time_t *out_time_offset)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_get_kdc_time_offset(): Get the KDC time offset for credentials in a ccache. --

    --

    Parameters:
    -- -- -- -- --
    in_ccache a ccache object.
    in_credentials_version the credentials version to get the time offset for.
    out_time_offset on exit, the KDC time offset for in_ccache for credentials version in_credentials_version.
    --
    --
    Returns:
    On success, ccNoError if a time offset was obtained or ccErrTimeOffsetNotSet if a time offset has not been set. On failure, an error code representing the failure.
    --
    See also:
    set_kdc_time_offset, clear_kdc_time_offset
    --Sometimes the KDC and client's clocks get out of sync. cc_ccache_get_kdc_time_offset() returns the difference between the KDC and client's clocks at the time credentials were acquired. This offset allows callers to figure out how much time is left on a given credential even though the end_time is based on the KDC's clock not the client's clock.
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* set_kdc_time_offset)(cc_ccache_t io_ccache, cc_uint32 in_credentials_version, cc_time_t in_time_offset)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_set_kdc_time_offset(): Set the KDC time offset for credentials in a ccache. --

    --

    Parameters:
    -- -- -- -- --
    in_ccache a ccache object.
    in_credentials_version the credentials version to get the time offset for.
    in_time_offset the new KDC time offset for in_ccache for credentials version in_credentials_version.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    See also:
    get_kdc_time_offset, clear_kdc_time_offset
    --Sometimes the KDC and client's clocks get out of sync. cc_ccache_set_kdc_time_offset() sets the difference between the KDC and client's clocks at the time credentials were acquired. This offset allows callers to figure out how much time is left on a given credential even though the end_time is based on the KDC's clock not the client's clock.
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* clear_kdc_time_offset)(cc_ccache_t io_ccache, cc_uint32 in_credentials_version)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_clear_kdc_time_offset(): Clear the KDC time offset for credentials in a ccache. --

    --

    Parameters:
    -- -- -- --
    in_ccache a ccache object.
    in_credentials_version the credentials version to get the time offset for.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    See also:
    get_kdc_time_offset, set_kdc_time_offset
    --Sometimes the KDC and client's clocks get out of sync. cc_ccache_clear_kdc_time_offset() clears the difference between the KDC and client's clocks at the time credentials were acquired. This offset allows callers to figure out how much time is left on a given credential even though the end_time is based on the KDC's clock not the client's clock.
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* wait_for_change)(cc_ccache_t in_ccache)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_wait_for_change(): Wait for the next change to a ccache. --

    --

    Parameters:
    -- -- --
    in_ccache a ccache object.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --This function blocks until the next change is made to the ccache referenced by in_ccache. By repeatedly calling cc_ccache_wait_for_change() from a worker thread the caller can effectively receive callbacks whenever the ccache changes. This is considerably more efficient than polling with cc_ccache_get_change_time().

    --cc_ccache_wait_for_change() will return whenever:

    --

      --
    • a credential is stored
    • --
    • a credential is removed
    • --
    • the ccache principal is changed
    • --
    • the ccache becomes the default ccache
    • --
    • the ccache is no longer the default ccache
    • --
    --
    Note:
    In order to make sure that the caller doesn't miss any changes, cc_ccache_wait_for_change() always returns immediately after the first time it is called on a new ccache object. Callers must use the same ccache object for successive calls to cc_ccache_wait_for_change() rather than creating a new ccache object for every call.
    --
    See also:
    get_change_time
    --
    --


    Generated on Tue Oct 2 17:16:05 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__ccache__iterator__d.html b/doc/ccapi/html/structcc__ccache__iterator__d.html -deleted file mode 100644 -index 5e85ee2da..000000000 ---- a/doc/ccapi/html/structcc__ccache__iterator__d.html -+++ /dev/null -@@ -1,43 +0,0 @@ -- -- --Credentials Cache API : cc_ccache_iterator_d Struct Reference -- -- -- -- --

    cc_ccache_iterator_d Struct Reference
    -- --[cc_ccache_iterator_t Overview] --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    const cc_ccache_iterator_f* functions
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --


    Generated on Tue Oct 2 17:16:05 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__ccache__iterator__f.html b/doc/ccapi/html/structcc__ccache__iterator__f.html -deleted file mode 100644 -index 333aab8f4..000000000 ---- a/doc/ccapi/html/structcc__ccache__iterator__f.html -+++ /dev/null -@@ -1,117 +0,0 @@ -- -- --Credentials Cache API : cc_ccache_iterator_f Struct Reference -- -- -- -- --

    cc_ccache_iterator_f Struct Reference


    Detailed Description

    --Function pointer table for cc_ccache_iterator_t. For more information see cc_ccache_iterator_t Overview. --

    --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* release)(cc_ccache_iterator_t io_ccache_iterator)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_iterator_release(): Release memory associated with a cc_ccache_iterator_t object. --

    --

    Parameters:
    -- -- --
    io_ccache_iterator the ccache iterator object to release.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* next)(cc_ccache_iterator_t in_ccache_iterator, cc_ccache_t *out_ccache)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_iterator_next(): Get the next ccache in the cache collection. --

    --

    Parameters:
    -- -- -- --
    in_ccache_iterator a ccache iterator object.
    out_ccache on exit, the next ccache in the cache collection.
    --
    --
    Returns:
    On success, ccNoError if the next ccache in the cache collection was obtained or ccIteratorEnd if there are no more ccaches. On failure, an error code representing the failure.
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* clone)(cc_ccache_iterator_t in_ccache_iterator, cc_ccache_iterator_t *out_ccache_iterator)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_ccache_iterator_clone(): Make a copy of a ccache iterator. --

    --

    Parameters:
    -- -- -- --
    in_ccache_iterator a ccache iterator object.
    out_ccache_iterator on exit, a copy of in_ccache_iterator.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    --


    Generated on Tue Oct 2 17:16:05 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__context__d.html b/doc/ccapi/html/structcc__context__d.html -deleted file mode 100644 -index d3904a2a1..000000000 ---- a/doc/ccapi/html/structcc__context__d.html -+++ /dev/null -@@ -1,43 +0,0 @@ -- -- --Credentials Cache API : cc_context_d Struct Reference -- -- -- -- --

    cc_context_d Struct Reference
    -- --[cc_context_t Overview] --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    const cc_context_f* functions
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --


    Generated on Tue Oct 2 17:16:05 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__context__f.html b/doc/ccapi/html/structcc__context__f.html -deleted file mode 100644 -index fe310518a..000000000 ---- a/doc/ccapi/html/structcc__context__f.html -+++ /dev/null -@@ -1,513 +0,0 @@ -- -- --Credentials Cache API : cc_context_f Struct Reference -- -- -- -- --

    cc_context_f Struct Reference


    Detailed Description

    --Function pointer table for cc_context_t. For more information see cc_context_t Overview. --

    --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* release)(cc_context_t io_context)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_context_release(): Release memory associated with a cc_context_t. --

    --

    Parameters:
    -- -- --
    io_context the context object to free.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* get_change_time)(cc_context_t in_context, cc_time_t *out_time)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_context_get_change_time(): Get the last time the cache collection changed. --

    --

    Parameters:
    -- -- -- --
    in_context the context object for the cache collection to examine.
    out_time on exit, the time of the most recent change for the entire ccache collection.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --This function returns the time of the most recent change for the entire ccache collection. By maintaining a local copy the caller can deduce whether or not the ccache collection has been modified since the previous call to cc_context_get_change_time().

    --The time returned by cc_context_get_changed_time() increases whenever:

    --

      --
    • a ccache is created
    • --
    • a ccache is destroyed
    • --
    • a credential is stored
    • --
    • a credential is removed
    • --
    • a ccache principal is changed
    • --
    • the default ccache is changed
    • --
    --
    Note:
    In order to be able to compare two values returned by cc_context_get_change_time(), the caller must use the same context to acquire them. Callers should maintain a single context in memory for cc_context_get_change_time() calls rather than creating a new context for every call.
    --
    See also:
    wait_for_change
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* get_default_ccache_name)(cc_context_t in_context, cc_string_t *out_name)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_context_get_default_ccache_name(): Get the name of the default ccache. --

    --

    Parameters:
    -- -- -- --
    in_context the context object for the cache collection.
    out_name on exit, the name of the default ccache.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --This function returns the name of the default ccache. When the default ccache exists, its name is returned. If there are no ccaches in the collection, and thus there is no default ccache, the name that the default ccache should have is returned. The ccache with that name will be used as the default ccache by all processes which initialized Kerberos libraries before the ccache was created.

    --If there is no default ccache, and the client is creating a new ccache, it should be created with the default name. If there already is a default ccache, and the client wants to create a new ccache (as opposed to reusing an existing ccache), it should be created with any unique name; create_new_ccache() can be used to accomplish that more easily.

    --If the first ccache is created with a name other than the default name, then the processes already running will not notice the credentials stored in the new ccache, which is normally undesirable.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* open_ccache)(cc_context_t in_context, const char *in_name, cc_ccache_t *out_ccache)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_context_open_ccache(): Open a ccache. --

    --

    Parameters:
    -- -- -- -- --
    in_context the context object for the cache collection.
    in_name the name of the ccache to open.
    out_ccache on exit, a ccache object for the ccache
    --
    --
    Returns:
    On success, ccNoError. If no ccache named in_name exists, ccErrCCacheNotFound. On failure, an error code representing the failure.
    --Opens an already existing ccache identified by its name. It returns a reference to the ccache in out_ccache.

    --The list of all ccache names, principals, and credentials versions may be retrieved by calling cc_context_new_cache_iterator(), cc_ccache_get_name(), cc_ccache_get_principal(), and cc_ccache_get_cred_version().

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* open_default_ccache)(cc_context_t in_context, cc_ccache_t *out_ccache)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_context_open_default_ccache(): Open the default ccache. --

    --

    Parameters:
    -- -- -- --
    in_context the context object for the cache collection.
    out_ccache on exit, a ccache object for the default ccache
    --
    --
    Returns:
    On success, ccNoError. If no default ccache exists, ccErrCCacheNotFound. On failure, an error code representing the failure.
    --Opens the default ccache. It returns a reference to the ccache in *ccache.

    --This function performs the same function as calling cc_context_get_default_ccache_name followed by cc_context_open_ccache, but it performs it atomically.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* create_ccache)(cc_context_t in_context, const char *in_name, cc_uint32 in_cred_vers, const char *in_principal, cc_ccache_t *out_ccache)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_context_create_ccache(): Create a new ccache. --

    --

    Parameters:
    -- -- -- -- -- -- --
    in_context the context object for the cache collection.
    in_name the name of the new ccache to create
    in_cred_vers the version of the credentials the new ccache will hold
    in_principal the client principal of the credentials the new ccache will hold
    out_ccache on exit, a ccache object for the newly created ccache
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --Create a new credentials cache. The ccache is uniquely identified by its name. The principal given is also associated with the ccache and the credentials version specified. A NULL name is not allowed (and ccErrBadName is returned if one is passed in). Only cc_credentials_v4 and cc_credentials_v5 are valid input values for cred_vers. If you want to create a new ccache that will hold both versions of credentials, call cc_context_create_ccache() with one version, and then cc_ccache_set_principal() with the other version.

    --If you want to create a new ccache (with a unique name), you should use cc_context_create_new_ccache() instead. If you want to create or reinitialize the default cache, you should use cc_context_create_default_ccache().

    --If name is non-NULL and there is already a ccache named name:

    --

      --
    • the credentials in the ccache whose version is cred_vers are removed
    • --
    • the principal (of the existing ccache) associated with cred_vers is set to principal
    • --
    • a handle for the existing ccache is returned and all existing handles for the ccache remain valid
    • --
    --If no ccache named name already exists:

    --

      --
    • a new empty ccache is created
    • --
    • the principal of the new ccache associated with cred_vers is set to principal
    • --
    • a handle for the new ccache is returned
    • --
    --For a new ccache, the name should be any unique string. The name is not intended to be presented to users.

    --If the created ccache is the first ccache in the collection, it is made the default ccache. Note that normally it is undesirable to create the first ccache with a name different from the default ccache name (as returned by cc_context_get_default_ccache_name()); see the description of cc_context_get_default_ccache_name() for details.

    --The principal should be a C string containing an unparsed Kerberos principal in the format of the appropriate Kerberos version, i.e.

    foo.bar/@BAZ 
    --      * 
    for Kerberos v4 and
    foo/bar/@BAZ 
    for Kerberos v5.
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* create_default_ccache)(cc_context_t in_context, cc_uint32 in_cred_vers, const char *in_principal, cc_ccache_t *out_ccache)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_context_create_default_ccache(): Create a new default ccache. --

    --

    Parameters:
    -- -- -- -- -- --
    in_context the context object for the cache collection.
    in_cred_vers the version of the credentials the new default ccache will hold
    in_principal the client principal of the credentials the new default ccache will hold
    out_ccache on exit, a ccache object for the newly created default ccache
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --Create the default credentials cache. The behavior of this function is similar to that of cc_create_ccache(). If there is a default ccache (which is always the case except when there are no ccaches at all in the collection), it is initialized with the specified credentials version and principal, as per cc_create_ccache(); otherwise, a new ccache is created, and its name is the name returned by cc_context_get_default_ccache_name().
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* create_new_ccache)(cc_context_t in_context, cc_uint32 in_cred_vers, const char *in_principal, cc_ccache_t *out_ccache)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_context_create_new_ccache(): Create a new uniquely named ccache. --

    --

    Parameters:
    -- -- -- -- -- --
    in_context the context object for the cache collection.
    in_cred_vers the version of the credentials the new ccache will hold
    in_principal the client principal of the credentials the new ccache will hold
    out_ccache on exit, a ccache object for the newly created ccache
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --Create a new unique credentials cache. The behavior of this function is similar to that of cc_create_ccache(). If there are no ccaches, and therefore no default ccache, the new ccache is created with the default ccache name as would be returned by get_default_ccache_name(). If there are some ccaches, and therefore there is a default ccache, the new ccache is created with a new unique name. Clearly, this function never reinitializes a ccache, since it always uses a unique name.
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* new_ccache_iterator)(cc_context_t in_context, cc_ccache_iterator_t *out_iterator)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_context_new_ccache_iterator(): Get an iterator for the cache collection. --

    --

    Parameters:
    -- -- -- --
    in_context the context object for the cache collection.
    out_iterator on exit, a ccache iterator object for the ccache collection.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --Used to allocate memory and initialize iterator. Successive calls to iterator's next() function will return ccaches in the collection.

    --If changes are made to the collection while an iterator is being used on it, the iterator must return at least the intersection, and at most the union, of the set of ccaches that were present when the iteration began and the set of ccaches that are present when it ends.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* lock)(cc_context_t in_context, cc_uint32 in_lock_type, cc_uint32 in_block)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_context_lock(): Lock the cache collection. --

    --

    Parameters:
    -- -- -- -- --
    in_context the context object for the cache collection.
    in_lock_type the type of lock to obtain.
    in_block whether or not the function should block if the lock cannot be obtained immediately.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --Attempts to acquire an advisory lock for the ccache collection. Allowed values for lock_type are:

    --

      --
    • cc_lock_read: a read lock.
    • --
    • cc_lock_write: a write lock
    • --
    • cc_lock_upgrade: upgrade an already-obtained read lock to a write lock
    • --
    • cc_lock_downgrade: downgrade an already-obtained write lock to a read lock
    • --
    --If block is cc_lock_block, lock() will not return until the lock is acquired. If block is cc_lock_noblock, lock() will return immediately, either acquiring the lock and returning ccNoError, or failing to acquire the lock and returning an error explaining why.

    --Locks apply only to the list of ccaches, not the contents of those ccaches. To prevent callers participating in the advisory locking from changing the credentials in a cache you must also lock that ccache with cc_ccache_lock(). This is so that you can get the list of ccaches without preventing applications from simultaneously obtaining service tickets.

    --To avoid having to deal with differences between thread semantics on different platforms, locks are granted per context, rather than per thread or per process. That means that different threads of execution have to acquire separate contexts in order to be able to synchronize with each other.

    --The lock should be unlocked by using cc_context_unlock().

    --

    Note:
    All locks are advisory. For example, callers which do not call cc_context_lock() and cc_context_unlock() will not be prevented from writing to the cache collection when you have a read lock. This is because the CCAPI locking was added after the first release and thus adding mandatory locks would have changed the user experience and performance of existing applications.
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* unlock)(cc_context_t in_cc_context)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_context_unlock(): Unlock the cache collection. --

    --

    Parameters:
    -- -- --
    in_context the context object for the cache collection.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* compare)(cc_context_t in_cc_context, cc_context_t in_compare_to_context, cc_uint32 *out_equal)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_context_compare(): Compare two context objects. --

    --

    Parameters:
    -- -- -- -- --
    in_context a context object.
    in_compare_to_context a context object to compare with in_context.
    out_equal on exit, whether or not the two contexts refer to the same cache collection.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* wait_for_change)(cc_context_t in_cc_context)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_context_wait_for_change(): Wait for the next change in the cache collection. --

    --

    Parameters:
    -- -- --
    in_context a context object.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --This function blocks until the next change is made to the cache collection ccache collection. By repeatedly calling cc_context_wait_for_change() from a worker thread the caller can effectively receive callbacks whenever the cache collection changes. This is considerably more efficient than polling with cc_context_get_change_time().

    --cc_context_wait_for_change() will return whenever:

    --

      --
    • a ccache is created
    • --
    • a ccache is destroyed
    • --
    • a credential is stored
    • --
    • a credential is removed
    • --
    • a ccache principal is changed
    • --
    • the default ccache is changed
    • --
    --
    Note:
    In order to make sure that the caller doesn't miss any changes, cc_context_wait_for_change() always returns immediately after the first time it is called on a new context object. Callers must use the same context object for successive calls to cc_context_wait_for_change() rather than creating a new context for every call.
    --
    See also:
    get_change_time
    --
    --


    Generated on Tue Oct 2 17:16:05 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__credentials__d.html b/doc/ccapi/html/structcc__credentials__d.html -deleted file mode 100644 -index 8a13251e5..000000000 ---- a/doc/ccapi/html/structcc__credentials__d.html -+++ /dev/null -@@ -1,67 +0,0 @@ -- -- --Credentials Cache API : cc_credentials_d Struct Reference -- -- -- -- --

    cc_credentials_d Struct Reference
    -- --[cc_credentials_t Overview] --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    const cc_credentials_union* data
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    const cc_credentials_f* functions
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__credentials__f.html b/doc/ccapi/html/structcc__credentials__f.html -deleted file mode 100644 -index 91f4b3adb..000000000 ---- a/doc/ccapi/html/structcc__credentials__f.html -+++ /dev/null -@@ -1,85 +0,0 @@ -- -- --Credentials Cache API : cc_credentials_f Struct Reference -- -- -- -- --

    cc_credentials_f Struct Reference


    Detailed Description

    --Function pointer table for cc_credentials_t. For more information see cc_credentials_t Overview. --

    --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* release)(cc_credentials_t io_credentials)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_credentials_release(): Release memory associated with a cc_credentials_t object. --

    --

    Parameters:
    -- -- --
    io_credentials the credentials object to release.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* compare)(cc_credentials_t in_credentials, cc_credentials_t in_compare_to_credentials, cc_uint32 *out_equal)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_credentials_compare(): Compare two credentials objects. --

    --

    Parameters:
    -- -- -- -- --
    in_credentials a credentials object.
    in_compare_to_credentials a credentials object to compare with in_credentials.
    out_equal on exit, whether or not the two credentials objects refer to the same credentials in the cache collection.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__credentials__iterator__d.html b/doc/ccapi/html/structcc__credentials__iterator__d.html -deleted file mode 100644 -index 5682db0ed..000000000 ---- a/doc/ccapi/html/structcc__credentials__iterator__d.html -+++ /dev/null -@@ -1,43 +0,0 @@ -- -- --Credentials Cache API : cc_credentials_iterator_d Struct Reference -- -- -- -- --

    cc_credentials_iterator_d Struct Reference
    -- --[cc_credentials_iterator_t] --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    const cc_credentials_iterator_f* functions
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__credentials__iterator__f.html b/doc/ccapi/html/structcc__credentials__iterator__f.html -deleted file mode 100644 -index 66aec178a..000000000 ---- a/doc/ccapi/html/structcc__credentials__iterator__f.html -+++ /dev/null -@@ -1,85 +0,0 @@ -- -- --Credentials Cache API : cc_credentials_iterator_f Struct Reference -- -- -- -- --

    cc_credentials_iterator_f Struct Reference


    Detailed Description

    --Function pointer table for cc_credentials_iterator_t. For more information see cc_credentials_iterator_t. --

    --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* release)(cc_credentials_iterator_t io_credentials_iterator)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_credentials_iterator_release(): Release memory associated with a cc_credentials_iterator_t object. --

    --

    Parameters:
    -- -- --
    io_credentials_iterator the credentials iterator object to release.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* next)(cc_credentials_iterator_t in_credentials_iterator, cc_credentials_t *out_credentials)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_credentials_iterator_next(): Get the next credentials in the ccache. --

    --

    Parameters:
    -- -- -- --
    in_credentials_iterator a credentials iterator object.
    out_credentials on exit, the next credentials in the ccache.
    --
    --
    Returns:
    On success, ccNoError if the next credential in the ccache was obtained or ccIteratorEnd if there are no more credentials. On failure, an error code representing the failure.
    --
    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__credentials__union.html b/doc/ccapi/html/structcc__credentials__union.html -deleted file mode 100644 -index 6082346cc..000000000 ---- a/doc/ccapi/html/structcc__credentials__union.html -+++ /dev/null -@@ -1,118 +0,0 @@ -- -- --Credentials Cache API : cc_credentials_union Struct Reference -- -- -- -- --

    cc_credentials_union Struct Reference
    -- --[cc_credentials_t Overview] --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_uint32 version
    --
    -- -- -- -- -- --
    --   -- -- --

    --The credentials version of this credentials object.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_credentials_v4_t* credentials_v4
    --
    -- -- -- -- -- --
    --   -- -- --

    --If version is cc_credentials_v4, a pointer to a cc_credentials_v4_t.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_credentials_v5_t* credentials_v5
    --
    -- -- -- -- -- --
    --   -- -- --

    --If version is cc_credentials_v5, a pointer to a cc_credentials_v5_t.

    --

    -- -- -- -- --
    -- -- -- -- --
    union { ... } credentials
    --
    -- -- -- -- -- --
    --   -- -- --

    --The credentials.

    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__credentials__v4__t.html b/doc/ccapi/html/structcc__credentials__v4__t.html -deleted file mode 100644 -index 086e7fea7..000000000 ---- a/doc/ccapi/html/structcc__credentials__v4__t.html -+++ /dev/null -@@ -1,358 +0,0 @@ -- -- --Credentials Cache API : cc_credentials_v4_t Struct Reference -- -- -- -- --

    cc_credentials_v4_t Struct Reference
    -- --[cc_credentials_t Overview] --


    Detailed Description

    --If a cc_credentials_t variable is used to store Kerberos v4 credentials, then credentials.credentials_v4 points to a v4 credentials structure. This structure is similar to a krb4 API CREDENTIALS structure. --

    --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_uint32 version
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    char principal[cc_v4_name_size]
    --
    -- -- -- -- -- --
    --   -- -- --

    --A properly quoted string representation of the first component of the client principal

    --

    -- -- -- -- --
    -- -- -- -- --
    char principal_instance[cc_v4_instance_size]
    --
    -- -- -- -- -- --
    --   -- -- --

    --A properly quoted string representation of the second component of the client principal

    --

    -- -- -- -- --
    -- -- -- -- --
    char service[cc_v4_name_size]
    --
    -- -- -- -- -- --
    --   -- -- --

    --A properly quoted string representation of the first component of the service principal

    --

    -- -- -- -- --
    -- -- -- -- --
    char service_instance[cc_v4_instance_size]
    --
    -- -- -- -- -- --
    --   -- -- --

    --A properly quoted string representation of the second component of the service principal

    --

    -- -- -- -- --
    -- -- -- -- --
    char realm[cc_v4_realm_size]
    --
    -- -- -- -- -- --
    --   -- -- --

    --A properly quoted string representation of the realm

    --

    -- -- -- -- --
    -- -- -- -- --
    unsigned char session_key[cc_v4_key_size]
    --
    -- -- -- -- -- --
    --   -- -- --

    --Ticket session key

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32 kvno
    --
    -- -- -- -- -- --
    --   -- -- --

    --Key version number

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32 string_to_key_type
    --
    -- -- -- -- -- --
    --   -- -- --

    --String to key type used. See cc_string_to_key_type for valid values

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_time_t issue_date
    --
    -- -- -- -- -- --
    --   -- -- --

    --Time when the ticket was issued

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32 lifetime
    --
    -- -- -- -- -- --
    --   -- -- --

    --Ticket lifetime in 5 minute units

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_uint32 address
    --
    -- -- -- -- -- --
    --   -- -- --

    --IPv4 address of the client the ticket was issued for

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32 ticket_size
    --
    -- -- -- -- -- --
    --   -- -- --

    --Ticket size (no greater than cc_v4_ticket_size)

    --

    -- -- -- -- --
    -- -- -- -- --
    unsigned char ticket[cc_v4_ticket_size]
    --
    -- -- -- -- -- --
    --   -- -- --

    --Ticket data

    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__credentials__v5__t.html b/doc/ccapi/html/structcc__credentials__v5__t.html -deleted file mode 100644 -index ad0996281..000000000 ---- a/doc/ccapi/html/structcc__credentials__v5__t.html -+++ /dev/null -@@ -1,334 +0,0 @@ -- -- --Credentials Cache API : cc_credentials_v5_t Struct Reference -- -- -- -- --

    cc_credentials_v5_t Struct Reference
    -- --[cc_credentials_t Overview] --


    Detailed Description

    --If a cc_credentials_t variable is used to store Kerberos v5 c redentials, and then credentials.credentials_v5 points to a v5 credentials structure. This structure is similar to a krb5_creds structure. --

    --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    char* client
    --
    -- -- -- -- -- --
    --   -- -- --

    --A properly quoted string representation of the client principal.

    --

    -- -- -- -- --
    -- -- -- -- --
    char* server
    --
    -- -- -- -- -- --
    --   -- -- --

    --A properly quoted string representation of the service principal.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_data keyblock
    --
    -- -- -- -- -- --
    --   -- -- --

    --Session encryption key info.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_time_t authtime
    --
    -- -- -- -- -- --
    --   -- -- --

    --The time when the ticket was issued.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_time_t starttime
    --
    -- -- -- -- -- --
    --   -- -- --

    --The time when the ticket becomes valid.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_time_t endtime
    --
    -- -- -- -- -- --
    --   -- -- --

    --The time when the ticket expires.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_time_t renew_till
    --
    -- -- -- -- -- --
    --   -- -- --

    --The time when the ticket becomes no longer renewable (if renewable).

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_uint32 is_skey
    --
    -- -- -- -- -- --
    --   -- -- --

    --1 if the ticket is encrypted in another ticket's key, or 0 otherwise.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_uint32 ticket_flags
    --
    -- -- -- -- -- --
    --   -- -- --

    --Ticket flags, as defined by the Kerberos 5 API.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_data** addresses
    --
    -- -- -- -- -- --
    --   -- -- --

    --The the list of network addresses of hosts that are allowed to authenticate using this ticket.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_data ticket
    --
    -- -- -- -- -- --
    --   -- -- --

    --Ticket data.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_data second_ticket
    --
    -- -- -- -- -- --
    --   -- -- --

    --Second ticket data.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_data** authdata
    --
    -- -- -- -- -- --
    --   -- -- --

    --Authorization data.

    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__data.html b/doc/ccapi/html/structcc__data.html -deleted file mode 100644 -index 346f6a41d..000000000 ---- a/doc/ccapi/html/structcc__data.html -+++ /dev/null -@@ -1,94 +0,0 @@ -- -- --Credentials Cache API : cc_data Struct Reference -- -- -- -- --

    cc_data Struct Reference
    -- --[cc_credentials_t Overview] --


    Detailed Description

    --The CCAPI data structure. This structure is similar to a krb5_data structure. In a v5 credentials structure, cc_data structures are used to store tagged variable-length binary data. Specifically, for cc_credentials_v5.ticket and cc_credentials_v5.second_ticket, the cc_data.type field must be zero. For the cc_credentials_v5.addresses, cc_credentials_v5.authdata, and cc_credentials_v5.keyblock, the cc_data.type field should be the address type, authorization data type, and encryption type, as defined by the Kerberos v5 protocol definition. --

    --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_uint32 type
    --
    -- -- -- -- -- --
    --   -- -- --

    --The type of the data as defined by the krb5_data structure.

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_uint32 length
    --
    -- -- -- -- -- --
    --   -- -- --

    --The length of data.

    --

    -- -- -- -- --
    -- -- -- -- --
    void* data
    --
    -- -- -- -- -- --
    --   -- -- --

    --The data buffer.

    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__string__d.html b/doc/ccapi/html/structcc__string__d.html -deleted file mode 100644 -index b38286b3e..000000000 ---- a/doc/ccapi/html/structcc__string__d.html -+++ /dev/null -@@ -1,67 +0,0 @@ -- -- --Credentials Cache API : cc_string_d Struct Reference -- -- -- -- --

    cc_string_d Struct Reference
    -- --[cc_string_t Overview] --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    const char* data
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --

    -- -- -- -- --
    -- -- -- -- --
    const cc_string_f* functions
    --
    -- -- -- -- -- --
    --   -- -- --

    --

    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- -diff --git a/doc/ccapi/html/structcc__string__f.html b/doc/ccapi/html/structcc__string__f.html -deleted file mode 100644 -index d5f738f49..000000000 ---- a/doc/ccapi/html/structcc__string__f.html -+++ /dev/null -@@ -1,51 +0,0 @@ -- -- --Credentials Cache API : cc_string_f Struct Reference -- -- -- -- --

    cc_string_f Struct Reference


    Detailed Description

    --Function pointer table for cc_string_t. For more information see cc_string_t Overview. --

    --

    Data Fields

    -- --

    Field Documentation

    --

    -- -- -- -- --
    -- -- -- -- --
    cc_int32(* release)(cc_string_t io_string)
    --
    -- -- -- -- -- --
    --   -- -- --

    --cc_string_release(): Release memory associated with a cc_string_t object. --

    --

    Parameters:
    -- -- --
    io_string the string object to release.
    --
    --
    Returns:
    On success, ccNoError. On failure, an error code representing the failure.
    --
    --


    Generated on Tue Oct 2 17:16:06 2007 for Credentials Cache API by  -- --doxygen 1.4.6
    -- -- diff --git a/Remove-kadmin-RPC-support-for-setting-v4-key.patch b/Remove-kadmin-RPC-support-for-setting-v4-key.patch deleted file mode 100644 index 3a08ddc..0000000 --- a/Remove-kadmin-RPC-support-for-setting-v4-key.patch +++ /dev/null @@ -1,466 +0,0 @@ -From 620a45acc6ea6c01cce0474883011ed47cb35458 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 4 Apr 2019 16:14:46 -0400 -Subject: [PATCH] Remove kadmin RPC support for setting v4 key - -ticket: 8794 (new) -(cherry picked from commit 752187a441ed0f301f1a8adb1fea843080ac8c97) ---- - src/kadmin/server/kadm_rpc_svc.c | 7 -- - src/kadmin/server/ovsec_kadmd.c | 2 +- - src/kadmin/server/server_stubs.c | 50 --------- - src/lib/kadm5/admin.h | 3 - - src/lib/kadm5/admin_xdr.h | 1 - - src/lib/kadm5/clnt/Makefile.in | 2 +- - src/lib/kadm5/clnt/client_principal.c | 22 ---- - src/lib/kadm5/clnt/client_rpc.c | 8 -- - src/lib/kadm5/clnt/libkadm5clnt_mit.exports | 2 - - src/lib/kadm5/kadm_rpc.h | 16 +-- - src/lib/kadm5/kadm_rpc_xdr.c | 19 ---- - src/lib/kadm5/srv/Makefile.in | 2 +- - src/lib/kadm5/srv/libkadm5srv_mit.exports | 2 - - src/lib/kadm5/srv/svr_principal.c | 118 -------------------- - 14 files changed, 6 insertions(+), 248 deletions(-) - -diff --git a/src/kadmin/server/kadm_rpc_svc.c b/src/kadmin/server/kadm_rpc_svc.c -index 41fc88ac8..d343e2c25 100644 ---- a/src/kadmin/server/kadm_rpc_svc.c -+++ b/src/kadmin/server/kadm_rpc_svc.c -@@ -53,7 +53,6 @@ void kadm_1(rqstp, transp) - mpol_arg modify_policy_2_arg; - gpol_arg get_policy_2_arg; - setkey_arg setkey_principal_2_arg; -- setv4key_arg setv4key_principal_2_arg; - cprinc3_arg create_principal3_2_arg; - chpass3_arg chpass_principal3_2_arg; - chrand3_arg chrand_principal3_2_arg; -@@ -134,12 +133,6 @@ void kadm_1(rqstp, transp) - local = (bool_t (*)()) chpass_principal_2_svc; - break; - -- case SETV4KEY_PRINCIPAL: -- xdr_argument = xdr_setv4key_arg; -- xdr_result = xdr_generic_ret; -- local = (bool_t (*)()) setv4key_principal_2_svc; -- break; -- - case SETKEY_PRINCIPAL: - xdr_argument = xdr_setkey_arg; - xdr_result = xdr_generic_ret; -diff --git a/src/kadmin/server/ovsec_kadmd.c b/src/kadmin/server/ovsec_kadmd.c -index 6a6b21401..3737791b6 100644 ---- a/src/kadmin/server/ovsec_kadmd.c -+++ b/src/kadmin/server/ovsec_kadmd.c -@@ -227,7 +227,7 @@ log_badverf(gss_name_t client_name, gss_name_t server_name, - {14, "GET_PRINCS"}, - {15, "GET_POLS"}, - {16, "SETKEY_PRINCIPAL"}, -- {17, "SETV4KEY_PRINCIPAL"}, -+ /* 17 was "SETV4KEY_PRINCIPAL" */ - {18, "CREATE_PRINCIPAL3"}, - {19, "CHPASS_PRINCIPAL3"}, - {20, "CHRAND_PRINCIPAL3"}, -diff --git a/src/kadmin/server/server_stubs.c b/src/kadmin/server/server_stubs.c -index cfef97fec..d5a25e502 100644 ---- a/src/kadmin/server/server_stubs.c -+++ b/src/kadmin/server/server_stubs.c -@@ -893,56 +893,6 @@ exit_func: - return TRUE; - } - --bool_t --setv4key_principal_2_svc(setv4key_arg *arg, generic_ret *ret, -- struct svc_req *rqstp) --{ -- char *prime_arg = NULL; -- gss_buffer_desc client_name = GSS_C_EMPTY_BUFFER; -- gss_buffer_desc service_name = GSS_C_EMPTY_BUFFER; -- kadm5_server_handle_t handle; -- const char *errmsg = NULL; -- -- ret->code = stub_setup(arg->api_version, rqstp, arg->princ, &handle, -- &ret->api_version, &client_name, &service_name, -- &prime_arg); -- if (ret->code) -- goto exit_func; -- -- ret->code = check_lockdown_keys(handle, arg->princ); -- if (ret->code != KADM5_OK) { -- if (ret->code == KADM5_PROTECT_KEYS) { -- log_unauth("kadm5_setv4key_principal", prime_arg, &client_name, -- &service_name, rqstp); -- ret->code = KADM5_AUTH_SETKEY; -- } -- } else if (!(CHANGEPW_SERVICE(rqstp)) && -- stub_auth(handle, OP_SETKEY, arg->princ, NULL, NULL, NULL)) { -- ret->code = kadm5_setv4key_principal(handle, arg->princ, -- arg->keyblock); -- } else { -- log_unauth("kadm5_setv4key_principal", prime_arg, -- &client_name, &service_name, rqstp); -- ret->code = KADM5_AUTH_SETKEY; -- } -- -- if (ret->code != KADM5_AUTH_SETKEY) { -- if (ret->code != 0) -- errmsg = krb5_get_error_message(handle->context, ret->code); -- -- log_done("kadm5_setv4key_principal", prime_arg, errmsg, -- &client_name, &service_name, rqstp); -- -- if (errmsg != NULL) -- krb5_free_error_message(handle->context, errmsg); -- } -- --exit_func: -- stub_cleanup(handle, prime_arg, &client_name, &service_name); -- return TRUE; --} -- -- - bool_t - setkey_principal_2_svc(setkey_arg *arg, generic_ret *ret, - struct svc_req *rqstp) -diff --git a/src/lib/kadm5/admin.h b/src/lib/kadm5/admin.h -index b765148b3..7268be44e 100644 ---- a/src/lib/kadm5/admin.h -+++ b/src/lib/kadm5/admin.h -@@ -394,9 +394,6 @@ kadm5_ret_t kadm5_randkey_principal_3(void *server_handle, - krb5_key_salt_tuple *ks_tuple, - krb5_keyblock **keyblocks, - int *n_keys); --kadm5_ret_t kadm5_setv4key_principal(void *server_handle, -- krb5_principal principal, -- krb5_keyblock *keyblock); - - kadm5_ret_t kadm5_setkey_principal(void *server_handle, - krb5_principal principal, -diff --git a/src/lib/kadm5/admin_xdr.h b/src/lib/kadm5/admin_xdr.h -index 2d22611e7..9da98451e 100644 ---- a/src/lib/kadm5/admin_xdr.h -+++ b/src/lib/kadm5/admin_xdr.h -@@ -37,7 +37,6 @@ bool_t xdr_mprinc_arg(XDR *xdrs, mprinc_arg *objp); - bool_t xdr_rprinc_arg(XDR *xdrs, rprinc_arg *objp); - bool_t xdr_chpass_arg(XDR *xdrs, chpass_arg *objp); - bool_t xdr_chpass3_arg(XDR *xdrs, chpass3_arg *objp); --bool_t xdr_setv4key_arg(XDR *xdrs, setv4key_arg *objp); - bool_t xdr_setkey_arg(XDR *xdrs, setkey_arg *objp); - bool_t xdr_setkey3_arg(XDR *xdrs, setkey3_arg *objp); - bool_t xdr_setkey4_arg(XDR *xdrs, setkey4_arg *objp); -diff --git a/src/lib/kadm5/clnt/Makefile.in b/src/lib/kadm5/clnt/Makefile.in -index a180e85cd..2bc385afe 100644 ---- a/src/lib/kadm5/clnt/Makefile.in -+++ b/src/lib/kadm5/clnt/Makefile.in -@@ -3,7 +3,7 @@ BUILDTOP=$(REL)..$(S)..$(S).. - LOCALINCLUDES = -I$(BUILDTOP)/include/kadm5 - - LIBBASE=kadm5clnt_mit --LIBMAJOR=11 -+LIBMAJOR=12 - LIBMINOR=0 - STOBJLISTS=../OBJS.ST OBJS.ST - SHLIB_EXPDEPS=\ -diff --git a/src/lib/kadm5/clnt/client_principal.c b/src/lib/kadm5/clnt/client_principal.c -index 18714bf37..96d9d1932 100644 ---- a/src/lib/kadm5/clnt/client_principal.c -+++ b/src/lib/kadm5/clnt/client_principal.c -@@ -273,28 +273,6 @@ kadm5_chpass_principal_3(void *server_handle, - return r.code; - } - --kadm5_ret_t --kadm5_setv4key_principal(void *server_handle, -- krb5_principal princ, -- krb5_keyblock *keyblock) --{ -- setv4key_arg arg; -- generic_ret r = { 0, 0 }; -- kadm5_server_handle_t handle = server_handle; -- -- CHECK_HANDLE(server_handle); -- -- arg.princ = princ; -- arg.keyblock = keyblock; -- arg.api_version = handle->api_version; -- -- if(princ == NULL || keyblock == NULL) -- return EINVAL; -- if (setv4key_principal_2(&arg, &r, handle->clnt)) -- eret(); -- return r.code; --} -- - kadm5_ret_t - kadm5_setkey_principal(void *server_handle, - krb5_principal princ, -diff --git a/src/lib/kadm5/clnt/client_rpc.c b/src/lib/kadm5/clnt/client_rpc.c -index df5455fd8..d84d158b4 100644 ---- a/src/lib/kadm5/clnt/client_rpc.c -+++ b/src/lib/kadm5/clnt/client_rpc.c -@@ -84,14 +84,6 @@ chpass_principal3_2(chpass3_arg *argp, generic_ret *res, CLIENT *clnt) - (xdrproc_t)xdr_generic_ret, (caddr_t)res, TIMEOUT); - } - --enum clnt_stat --setv4key_principal_2(setv4key_arg *argp, generic_ret *res, CLIENT *clnt) --{ -- return clnt_call(clnt, SETV4KEY_PRINCIPAL, -- (xdrproc_t)xdr_setv4key_arg, (caddr_t)argp, -- (xdrproc_t)xdr_generic_ret, (caddr_t)res, TIMEOUT); --} -- - enum clnt_stat - setkey_principal_2(setkey_arg *argp, generic_ret *res, CLIENT *clnt) - { -diff --git a/src/lib/kadm5/clnt/libkadm5clnt_mit.exports b/src/lib/kadm5/clnt/libkadm5clnt_mit.exports -index f122b31ab..e41c8e4f7 100644 ---- a/src/lib/kadm5/clnt/libkadm5clnt_mit.exports -+++ b/src/lib/kadm5/clnt/libkadm5clnt_mit.exports -@@ -44,7 +44,6 @@ kadm5_set_string - kadm5_setkey_principal - kadm5_setkey_principal_3 - kadm5_setkey_principal_4 --kadm5_setv4key_principal - kadm5_unlock - krb5_aprof_finish - krb5_aprof_get_boolean -@@ -114,6 +113,5 @@ xdr_rprinc_arg - xdr_setkey3_arg - xdr_setkey4_arg - xdr_setkey_arg --xdr_setv4key_arg - xdr_ui_4 - kadm5_init_iprop -diff --git a/src/lib/kadm5/kadm_rpc.h b/src/lib/kadm5/kadm_rpc.h -index 8d7cf3b36..5099c6c14 100644 ---- a/src/lib/kadm5/kadm_rpc.h -+++ b/src/lib/kadm5/kadm_rpc.h -@@ -82,13 +82,6 @@ struct chpass3_arg { - }; - typedef struct chpass3_arg chpass3_arg; - --struct setv4key_arg { -- krb5_ui_4 api_version; -- krb5_principal princ; -- krb5_keyblock *keyblock; --}; --typedef struct setv4key_arg setv4key_arg; -- - struct setkey_arg { - krb5_ui_4 api_version; - krb5_principal princ; -@@ -322,11 +315,9 @@ extern enum clnt_stat setkey_principal_2(setkey_arg *, generic_ret *, - CLIENT *); - extern bool_t setkey_principal_2_svc(setkey_arg *, generic_ret *, - struct svc_req *); --#define SETV4KEY_PRINCIPAL 17 --extern enum clnt_stat setv4key_principal_2(setv4key_arg *, generic_ret *, -- CLIENT *); --extern bool_t setv4key_principal_2_svc(setv4key_arg *, generic_ret *, -- struct svc_req *); -+ -+/* 17 was SETV4KEY_PRINCIPAL (removed in 1.18). */ -+ - #define CREATE_PRINCIPAL3 18 - extern enum clnt_stat create_principal3_2(cprinc3_arg *, generic_ret *, - CLIENT *); -@@ -380,7 +371,6 @@ extern bool_t xdr_gprincs_arg (); - extern bool_t xdr_gprincs_ret (); - extern bool_t xdr_chpass_arg (); - extern bool_t xdr_chpass3_arg (); --extern bool_t xdr_setv4key_arg (); - extern bool_t xdr_setkey_arg (); - extern bool_t xdr_setkey3_arg (); - extern bool_t xdr_setkey4_arg (); -diff --git a/src/lib/kadm5/kadm_rpc_xdr.c b/src/lib/kadm5/kadm_rpc_xdr.c -index 2892d4147..745ee857e 100644 ---- a/src/lib/kadm5/kadm_rpc_xdr.c -+++ b/src/lib/kadm5/kadm_rpc_xdr.c -@@ -710,25 +710,6 @@ xdr_chpass3_arg(XDR *xdrs, chpass3_arg *objp) - return (TRUE); - } - --bool_t --xdr_setv4key_arg(XDR *xdrs, setv4key_arg *objp) --{ -- unsigned int n_keys = 1; -- -- if (!xdr_ui_4(xdrs, &objp->api_version)) { -- return (FALSE); -- } -- if (!xdr_krb5_principal(xdrs, &objp->princ)) { -- return (FALSE); -- } -- if (!xdr_array(xdrs, (caddr_t *) &objp->keyblock, -- &n_keys, ~0, -- sizeof(krb5_keyblock), xdr_krb5_keyblock)) { -- return (FALSE); -- } -- return (TRUE); --} -- - bool_t - xdr_setkey_arg(XDR *xdrs, setkey_arg *objp) - { -diff --git a/src/lib/kadm5/srv/Makefile.in b/src/lib/kadm5/srv/Makefile.in -index 617d65666..89e6097cf 100644 ---- a/src/lib/kadm5/srv/Makefile.in -+++ b/src/lib/kadm5/srv/Makefile.in -@@ -9,7 +9,7 @@ DEFINES = @HESIOD_DEFS@ - ##DOSLIBNAME = libkadm5srv.lib - - LIBBASE=kadm5srv_mit --LIBMAJOR=11 -+LIBMAJOR=12 - LIBMINOR=0 - STOBJLISTS=../OBJS.ST OBJS.ST - -diff --git a/src/lib/kadm5/srv/libkadm5srv_mit.exports b/src/lib/kadm5/srv/libkadm5srv_mit.exports -index 64ad5dd69..e3c04e690 100644 ---- a/src/lib/kadm5/srv/libkadm5srv_mit.exports -+++ b/src/lib/kadm5/srv/libkadm5srv_mit.exports -@@ -45,7 +45,6 @@ kadm5_set_string - kadm5_setkey_principal - kadm5_setkey_principal_3 - kadm5_setkey_principal_4 --kadm5_setv4key_principal - kadm5_unlock - kdb_delete_entry - kdb_free_entry -@@ -133,7 +132,6 @@ xdr_rprinc_arg - xdr_setkey3_arg - xdr_setkey4_arg - xdr_setkey_arg --xdr_setv4key_arg - xdr_sstring_arg - xdr_ui_4 - kadm5_init_iprop -diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c -index be0922101..a1ecdbfc4 100644 ---- a/src/lib/kadm5/srv/svr_principal.c -+++ b/src/lib/kadm5/srv/svr_principal.c -@@ -1649,124 +1649,6 @@ done: - return ret; - } - --/* -- * kadm5_setv4key_principal: -- * -- * Set only ONE key of the principal, removing all others. This key -- * must have the DES_CBC_CRC enctype and is entered as having the -- * krb4 salttype. This is to enable things like kadmind4 to work. -- */ --kadm5_ret_t --kadm5_setv4key_principal(void *server_handle, -- krb5_principal principal, -- krb5_keyblock *keyblock) --{ -- krb5_db_entry *kdb; -- osa_princ_ent_rec adb; -- krb5_timestamp now; -- kadm5_policy_ent_rec pol; -- krb5_keysalt keysalt; -- int i, kvno, ret; -- krb5_boolean have_pol = FALSE; -- kadm5_server_handle_t handle = server_handle; -- krb5_key_data tmp_key_data; -- krb5_keyblock *act_mkey; -- -- memset( &tmp_key_data, 0, sizeof(tmp_key_data)); -- -- CHECK_HANDLE(server_handle); -- -- krb5_clear_error_message(handle->context); -- -- if (principal == NULL || keyblock == NULL) -- return EINVAL; -- if (hist_princ && /* this will be NULL when initializing the databse */ -- ((krb5_principal_compare(handle->context, -- principal, hist_princ)) == TRUE)) -- return KADM5_PROTECT_PRINCIPAL; -- -- if (keyblock->enctype != ENCTYPE_DES_CBC_CRC) -- return KADM5_SETV4KEY_INVAL_ENCTYPE; -- -- if ((ret = kdb_get_entry(handle, principal, &kdb, &adb))) -- return(ret); -- -- for (kvno = 0, i=0; in_key_data; i++) -- if (kdb->key_data[i].key_data_kvno > kvno) -- kvno = kdb->key_data[i].key_data_kvno; -- -- if (kdb->key_data != NULL) -- cleanup_key_data(handle->context, kdb->n_key_data, kdb->key_data); -- -- kdb->key_data = calloc(1, sizeof(krb5_key_data)); -- if (kdb->key_data == NULL) -- return ENOMEM; -- kdb->n_key_data = 1; -- keysalt.type = KRB5_KDB_SALTTYPE_V4; -- /* XXX data.magic? */ -- keysalt.data.length = 0; -- keysalt.data.data = NULL; -- -- ret = kdb_get_active_mkey(handle, NULL, &act_mkey); -- if (ret) -- goto done; -- -- /* use tmp_key_data as temporary location and reallocate later */ -- ret = krb5_dbe_encrypt_key_data(handle->context, act_mkey, keyblock, -- &keysalt, kvno + 1, kdb->key_data); -- if (ret) { -- goto done; -- } -- -- kdb->attributes &= ~KRB5_KDB_REQUIRES_PWCHANGE; -- -- ret = krb5_timeofday(handle->context, &now); -- if (ret) -- goto done; -- -- if ((adb.aux_attributes & KADM5_POLICY)) { -- ret = get_policy(handle, adb.policy, &pol, &have_pol); -- if (ret) -- goto done; -- } -- if (have_pol) { -- if (pol.pw_max_life) -- kdb->pw_expiration = ts_incr(now, pol.pw_max_life); -- else -- kdb->pw_expiration = 0; -- } else { -- kdb->pw_expiration = 0; -- } -- -- ret = krb5_dbe_update_last_pwd_change(handle->context, kdb, now); -- if (ret) -- goto done; -- -- /* unlock principal on this KDC */ -- kdb->fail_auth_count = 0; -- -- /* key data changed, let the database provider know */ -- kdb->mask = KADM5_KEY_DATA | KADM5_FAIL_AUTH_COUNT; -- -- if ((ret = kdb_put_entry(handle, kdb, &adb))) -- goto done; -- -- ret = KADM5_OK; --done: -- for (i = 0; i < tmp_key_data.key_data_ver; i++) { -- if (tmp_key_data.key_data_contents[i]) { -- memset (tmp_key_data.key_data_contents[i], 0, tmp_key_data.key_data_length[i]); -- free (tmp_key_data.key_data_contents[i]); -- } -- } -- -- kdb_free_entry(handle, kdb, &adb); -- if (have_pol) -- kadm5_free_policy_ent(handle->lhandle, &pol); -- -- return ret; --} -- - kadm5_ret_t - kadm5_setkey_principal(void *server_handle, - krb5_principal principal, diff --git a/Remove-krb5int_c_combine_keys.patch b/Remove-krb5int_c_combine_keys.patch deleted file mode 100644 index e78c003..0000000 --- a/Remove-krb5int_c_combine_keys.patch +++ /dev/null @@ -1,479 +0,0 @@ -From 90c702467b0c4373758f235512c67f80f1998e02 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 18 Apr 2019 17:27:07 -0400 -Subject: [PATCH] Remove krb5int_c_combine_keys() - -This method of combining keys was specified by -draft-ietf-krb-wg-kerberos-sam for DES and 3DES enctypes, and is -otherwise unused. Remove it. - -[ghudson@mit.edu: rewrote commit message] - -ticket: 8812 -(cherry picked from commit 925a7df2f486aaa3ff137d2bcdf8ff57186638c6) -[rharwood@redhat.com: conflicts: .gitignore] ---- - src/include/k5-int.h | 7 - - src/lib/crypto/crypto_tests/Makefile.in | 12 +- - src/lib/crypto/crypto_tests/deps | 10 -- - src/lib/crypto/crypto_tests/t_combine.c | 62 ------- - src/lib/crypto/krb/Makefile.in | 3 - - src/lib/crypto/krb/combine_keys.c | 227 ------------------------ - src/lib/crypto/krb/deps | 13 -- - src/lib/crypto/libk5crypto.exports | 1 - - 8 files changed, 3 insertions(+), 332 deletions(-) - delete mode 100644 src/lib/crypto/crypto_tests/t_combine.c - delete mode 100644 src/lib/crypto/krb/combine_keys.c - -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 2bc59e636..0857fd1cc 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -673,13 +673,6 @@ zapfreedata(krb5_data *data) - } - } - --/* -- * Combine two keys (normally used by the hardware preauth mechanism) -- */ --krb5_error_code --krb5int_c_combine_keys(krb5_context context, krb5_keyblock *key1, -- krb5_keyblock *key2, krb5_keyblock *outkey); -- - void krb5int_c_free_keyblock(krb5_context, krb5_keyblock *key); - void krb5int_c_free_keyblock_contents(krb5_context, krb5_keyblock *); - krb5_error_code krb5int_c_init_keyblock(krb5_context, krb5_enctype enctype, -diff --git a/src/lib/crypto/crypto_tests/Makefile.in b/src/lib/crypto/crypto_tests/Makefile.in -index 09feeb50e..0295ee14f 100644 ---- a/src/lib/crypto/crypto_tests/Makefile.in -+++ b/src/lib/crypto/crypto_tests/Makefile.in -@@ -23,8 +23,7 @@ EXTRADEPSRCS=\ - $(srcdir)/t_short.c \ - $(srcdir)/t_str2key.c \ - $(srcdir)/t_derive.c \ -- $(srcdir)/t_fork.c \ -- $(srcdir)/t_combine.c -+ $(srcdir)/t_fork.c - - ##DOS##BUILDTOP = ..\..\.. - -@@ -33,8 +32,7 @@ check-unix: t_nfold t_encrypt t_decrypt t_prf t_prng t_cmac t_hmac \ - aes-test \ - camellia-test \ - t_mddriver4 t_mddriver \ -- t_cts t_sha2 t_short t_str2key t_derive t_fork t_cf2 \ -- t_combine -+ t_cts t_sha2 t_short t_str2key t_derive t_fork t_cf2 - $(RUN_TEST) ./t_nfold - $(RUN_TEST) ./t_encrypt - $(RUN_TEST) ./t_decrypt -@@ -59,7 +57,6 @@ check-unix: t_nfold t_encrypt t_decrypt t_prf t_prng t_cmac t_hmac \ - $(RUN_TEST) ./t_fork - $(RUN_TEST) ./t_cf2 <$(srcdir)/t_cf2.in >t_cf2.output - diff t_cf2.output $(srcdir)/t_cf2.expected -- $(RUN_TEST) ./t_combine - # $(RUN_TEST) ./t_pkcs5 - - t_nfold$(EXEEXT): t_nfold.$(OBJEXT) $(KRB5_BASE_DEPLIBS) -@@ -134,9 +131,6 @@ t_fork$(EXEEXT): t_fork.$(OBJEXT) $(KRB5_BASE_DEPLIBS) - t_cf2$(EXEEXT): t_cf2.$(OBJEXT) $(KRB5_BASE_DEPLIBS) - $(CC_LINK) -o $@ t_cf2.$(OBJEXT) $(KRB5_BASE_LIBS) - --t_combine$(EXEEXT): t_combine.$(OBJEXT) $(KRB5_BASE_DEPLIBS) -- $(CC_LINK) -o $@ t_combine.$(OBJEXT) $(KRB5_BASE_LIBS) -- - clean: - $(RM) t_nfold.o t_nfold t_encrypt t_encrypt.o \ - t_decrypt.o t_decrypt t_prng.o t_prng t_cmac.o t_cmac \ -@@ -149,7 +143,7 @@ clean: - t_str2key.o t_derive t_derive.o t_fork t_fork.o \ - t_mddriver$(EXEEXT) $(OUTPRE)t_mddriver.$(OBJEXT) \ - camellia-test camellia-test.o camellia-vt.txt \ -- t_cf2 t_cf2.o t_cf2.output t_combine.o t_combine -+ t_cf2 t_cf2.o t_cf2.output - - -$(RM) t_prng.output - -$(RM) t_prf.output -diff --git a/src/lib/crypto/crypto_tests/deps b/src/lib/crypto/crypto_tests/deps -index 19fef2582..0d10d4a1a 100644 ---- a/src/lib/crypto/crypto_tests/deps -+++ b/src/lib/crypto/crypto_tests/deps -@@ -226,13 +226,3 @@ $(OUTPRE)t_fork.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ - $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ - $(top_srcdir)/include/socket-utils.h t_fork.c --$(OUTPRE)t_combine.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ -- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h t_combine.c -diff --git a/src/lib/crypto/crypto_tests/t_combine.c b/src/lib/crypto/crypto_tests/t_combine.c -deleted file mode 100644 -index ba0622bcf..000000000 ---- a/src/lib/crypto/crypto_tests/t_combine.c -+++ /dev/null -@@ -1,62 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* lib/crypto/crypto_tests/t_combine.c - krb5int_c_combine_keys tests */ --/* -- * Copyright (C) 2014 by the Massachusetts Institute of Technology. -- * All rights reserved. -- * -- * Redistribution and use in source and binary forms, with or without -- * modification, are permitted provided that the following conditions -- * are met: -- * -- * * Redistributions of source code must retain the above copyright -- * notice, this list of conditions and the following disclaimer. -- * -- * * Redistributions in binary form must reproduce the above copyright -- * notice, this list of conditions and the following disclaimer in -- * the documentation and/or other materials provided with the -- * distribution. -- * -- * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -- * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -- * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -- * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -- * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -- * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -- * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -- * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -- * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -- * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -- * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -- * OF THE POSSIBILITY OF SUCH DAMAGE. -- */ -- --#include "k5-int.h" -- --unsigned char des3_key1[] = "\x10\xB6\x75\xD5\x5B\xD9\x6E\x73" -- "\xFD\x54\xB3\x3D\x37\x52\xC1\x2A\xF7\x43\x91\xFE\x1C\x02\x37\x13"; --unsigned char des3_key2[] = "\xC8\xDA\x3E\xA7\xB6\x64\xAE\x7A" -- "\xB5\x70\x2A\x29\xB3\xBF\x9B\xA8\x46\x7C\x5B\xA8\x8A\x46\x70\x10"; --unsigned char des3_result[] = "\x2F\x79\x97\x3E\x3E\xA4\x73\x1A" -- "\xB9\x3D\xEF\x5E\x7C\x29\xFB\x2A\x68\x86\x1F\xC1\x85\x0E\x79\x92"; -- --int --main(int argc, char **argv) --{ -- krb5_keyblock kb1, kb2, result; -- -- kb1.enctype = ENCTYPE_DES3_CBC_SHA1; -- kb1.contents = des3_key1; -- kb1.length = 24; -- kb2.enctype = ENCTYPE_DES3_CBC_SHA1; -- kb2.contents = des3_key2; -- kb2.length = 24; -- memset(&result, 0, sizeof(result)); -- if (krb5int_c_combine_keys(NULL, &kb1, &kb2, &result) != 0) -- abort(); -- if (result.enctype != ENCTYPE_DES3_CBC_SHA1 || result.length != 24 || -- memcmp(result.contents, des3_result, 24) != 0) -- abort(); -- krb5_free_keyblock_contents(NULL, &result); -- -- return 0; --} -diff --git a/src/lib/crypto/krb/Makefile.in b/src/lib/crypto/krb/Makefile.in -index c0e0b791b..536bacb6e 100644 ---- a/src/lib/crypto/krb/Makefile.in -+++ b/src/lib/crypto/krb/Makefile.in -@@ -22,7 +22,6 @@ STLIBOBJS=\ - cksumtypes.o \ - cmac.o \ - coll_proof_cksum.o \ -- combine_keys.o \ - crypto_length.o \ - crypto_libinit.o \ - default_state.o \ -@@ -84,7 +83,6 @@ OBJS=\ - $(OUTPRE)cksumtypes.$(OBJEXT) \ - $(OUTPRE)cmac.$(OBJEXT) \ - $(OUTPRE)coll_proof_cksum.$(OBJEXT) \ -- $(OUTPRE)combine_keys.$(OBJEXT) \ - $(OUTPRE)crypto_length.$(OBJEXT) \ - $(OUTPRE)crypto_libinit.$(OBJEXT) \ - $(OUTPRE)default_state.$(OBJEXT) \ -@@ -146,7 +144,6 @@ SRCS=\ - $(srcdir)/cksumtypes.c \ - $(srcdir)/cmac.c \ - $(srcdir)/coll_proof_cksum.c \ -- $(srcdir)/combine_keys.c \ - $(srcdir)/crypto_length.c \ - $(srcdir)/crypto_libinit.c \ - $(srcdir)/default_state.c \ -diff --git a/src/lib/crypto/krb/combine_keys.c b/src/lib/crypto/krb/combine_keys.c -deleted file mode 100644 -index c36434e17..000000000 ---- a/src/lib/crypto/krb/combine_keys.c -+++ /dev/null -@@ -1,227 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* Copyright (c) 2002 Naval Research Laboratory (NRL/CCS) */ --/* -- * Permission to use, copy, modify and distribute this software and its -- * documentation is hereby granted, provided that both the copyright -- * notice and this permission notice appear in all copies of the software, -- * derivative works or modified versions, and any portions thereof. -- * -- * NRL ALLOWS FREE USE OF THIS SOFTWARE IN ITS "AS IS" CONDITION AND -- * DISCLAIMS ANY LIABILITY OF ANY KIND FOR ANY DAMAGES WHATSOEVER -- * RESULTING FROM THE USE OF THIS SOFTWARE. -- */ -- --/* -- * Key combination function. -- * -- * If Key1 and Key2 are two keys to be combined, the algorithm to combine -- * them is as follows. -- * -- * Definitions: -- * -- * k-truncate is defined as truncating to the key size the input. -- * -- * DR is defined as the generate "random" data from a key -- * (defined in crypto draft) -- * -- * DK is defined as the key derivation function (krb5int_derive_key()) -- * -- * (note: | means "concatenate") -- * -- * Combine key algorithm: -- * -- * R1 = DR(Key1, n-fold(Key2)) [ Output is length of Key1 ] -- * R2 = DR(Key2, n-fold(Key1)) [ Output is length of Key2 ] -- * -- * rnd = n-fold(R1 | R2) [ Note: output size of nfold must be appropriately -- * sized for random-to-key function ] -- * tkey = random-to-key(rnd) -- * Combine-Key(Key1, Key2) = DK(tkey, CombineConstant) -- * -- * CombineConstant is defined as the byte string: -- * -- * { 0x63 0x6f 0x6d 0x62 0x69 0x6e 0x65 }, which corresponds to the -- * ASCII encoding of the string "combine" -- */ -- --#include "crypto_int.h" -- --static krb5_error_code dr(const struct krb5_enc_provider *enc, -- const krb5_keyblock *inkey, unsigned char *outdata, -- const krb5_data *in_constant); -- --/* -- * We only support this combine_keys algorithm for des and 3des keys. -- * Everything else should use the PRF defined in the crypto framework. -- * We don't implement that yet. -- */ -- --static krb5_boolean --enctype_ok(krb5_enctype e) --{ -- switch (e) { -- case ENCTYPE_DES3_CBC_SHA1: -- return TRUE; -- default: -- return FALSE; -- } --} -- --krb5_error_code --krb5int_c_combine_keys(krb5_context context, krb5_keyblock *key1, -- krb5_keyblock *key2, krb5_keyblock *outkey) --{ -- unsigned char *r1 = NULL, *r2 = NULL, *combined = NULL, *rnd = NULL; -- unsigned char *output = NULL; -- size_t keybytes, keylength; -- const struct krb5_enc_provider *enc; -- krb5_data input, randbits; -- krb5_keyblock tkeyblock; -- krb5_key tkey = NULL; -- krb5_error_code ret; -- const struct krb5_keytypes *ktp; -- krb5_boolean myalloc = FALSE; -- -- if (!enctype_ok(key1->enctype) || !enctype_ok(key2->enctype)) -- return KRB5_CRYPTO_INTERNAL; -- -- if (key1->length != key2->length || key1->enctype != key2->enctype) -- return KRB5_CRYPTO_INTERNAL; -- -- /* Find our encryption algorithm. */ -- ktp = find_enctype(key1->enctype); -- if (ktp == NULL) -- return KRB5_BAD_ENCTYPE; -- enc = ktp->enc; -- -- keybytes = enc->keybytes; -- keylength = enc->keylength; -- -- /* Allocate and set up buffers. */ -- r1 = k5alloc(keybytes, &ret); -- if (ret) -- goto cleanup; -- r2 = k5alloc(keybytes, &ret); -- if (ret) -- goto cleanup; -- rnd = k5alloc(keybytes, &ret); -- if (ret) -- goto cleanup; -- combined = k5calloc(2, keybytes, &ret); -- if (ret) -- goto cleanup; -- output = k5alloc(keylength, &ret); -- if (ret) -- goto cleanup; -- -- /* -- * Get R1 and R2 (by running the input keys through the DR algorithm. -- * Note this is most of derive-key, but not all. -- */ -- -- input.length = key2->length; -- input.data = (char *) key2->contents; -- ret = dr(enc, key1, r1, &input); -- if (ret) -- goto cleanup; -- -- input.length = key1->length; -- input.data = (char *) key1->contents; -- ret = dr(enc, key2, r2, &input); -- if (ret) -- goto cleanup; -- -- /* -- * Concatenate the two keys together, and then run them through -- * n-fold to reduce them to a length appropriate for the random-to-key -- * operation. Note here that krb5int_nfold() takes sizes in bits, hence -- * the multiply by 8. -- */ -- -- memcpy(combined, r1, keybytes); -- memcpy(combined + keybytes, r2, keybytes); -- -- krb5int_nfold((keybytes * 2) * 8, combined, keybytes * 8, rnd); -- -- /* -- * Run the "random" bits through random-to-key to produce a encryption -- * key. -- */ -- -- randbits.length = keybytes; -- randbits.data = (char *) rnd; -- tkeyblock.length = keylength; -- tkeyblock.contents = output; -- tkeyblock.enctype = key1->enctype; -- -- ret = (*ktp->rand2key)(&randbits, &tkeyblock); -- if (ret) -- goto cleanup; -- -- ret = krb5_k_create_key(NULL, &tkeyblock, &tkey); -- if (ret) -- goto cleanup; -- -- /* -- * Run through derive-key one more time to produce the final key. -- * Note that the input to derive-key is the ASCII string "combine". -- */ -- -- input.length = 7; -- input.data = "combine"; -- -- /* -- * Just FYI: _if_ we have space here in the key, then simply use it -- * without modification. But if the key is blank (no allocated storage) -- * then allocate some memory for it. This allows programs to use one of -- * the existing keys as the output key, _or_ pass in a blank keyblock -- * for us to allocate. It's easier for us to allocate it since we already -- * know the crypto library internals -- */ -- -- if (outkey->length == 0 || outkey->contents == NULL) { -- outkey->contents = k5alloc(keylength, &ret); -- if (ret) -- goto cleanup; -- outkey->length = keylength; -- outkey->enctype = key1->enctype; -- myalloc = TRUE; -- } -- -- ret = krb5int_derive_keyblock(enc, NULL, tkey, outkey, &input, -- DERIVE_RFC3961); -- if (ret) { -- if (myalloc) { -- free(outkey->contents); -- outkey->contents = NULL; -- } -- goto cleanup; -- } -- --cleanup: -- zapfree(r1, keybytes); -- zapfree(r2, keybytes); -- zapfree(rnd, keybytes); -- zapfree(combined, keybytes * 2); -- zapfree(output, keylength); -- krb5_k_free_key(NULL, tkey); -- return ret; --} -- --/* Our DR function, a simple wrapper around krb5int_derive_random(). */ --static krb5_error_code --dr(const struct krb5_enc_provider *enc, const krb5_keyblock *inkey, -- unsigned char *out, const krb5_data *in_constant) --{ -- krb5_data outdata = make_data(out, enc->keybytes); -- krb5_key key = NULL; -- krb5_error_code ret; -- -- ret = krb5_k_create_key(NULL, inkey, &key); -- if (ret != 0) -- return ret; -- ret = krb5int_derive_random(enc, NULL, key, &outdata, in_constant, -- DERIVE_RFC3961); -- krb5_k_free_key(NULL, key); -- return ret; --} -diff --git a/src/lib/crypto/krb/deps b/src/lib/crypto/krb/deps -index f9a740860..2f4af1906 100644 ---- a/src/lib/crypto/krb/deps -+++ b/src/lib/crypto/krb/deps -@@ -191,19 +191,6 @@ coll_proof_cksum.so coll_proof_cksum.po $(OUTPRE)coll_proof_cksum.$(OBJEXT): \ - $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ - $(top_srcdir)/include/socket-utils.h coll_proof_cksum.c \ - crypto_int.h --combine_keys.so combine_keys.po $(OUTPRE)combine_keys.$(OBJEXT): \ -- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ -- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h $(srcdir)/../builtin/crypto_mod.h \ -- $(srcdir)/../builtin/sha2/sha2.h $(top_srcdir)/include/k5-buf.h \ -- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h combine_keys.c \ -- crypto_int.h - crypto_length.so crypto_length.po $(OUTPRE)crypto_length.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports -index 63804299f..451d5e035 100644 ---- a/src/lib/crypto/libk5crypto.exports -+++ b/src/lib/crypto/libk5crypto.exports -@@ -58,7 +58,6 @@ krb5_c_prf_length - krb5int_c_mandatory_cksumtype - krb5_c_fx_cf2_simple - krb5int_c_weak_enctype --krb5int_c_combine_keys - krb5_encrypt_data - krb5int_c_copy_keyblock - krb5int_c_copy_keyblock_contents diff --git a/Remove-more-dead-code.patch b/Remove-more-dead-code.patch deleted file mode 100644 index b0f04ab..0000000 --- a/Remove-more-dead-code.patch +++ /dev/null @@ -1,276 +0,0 @@ -From e470fc217b19f6d958cc891910527e43651167a3 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 9 May 2019 14:07:24 -0400 -Subject: [PATCH] Remove more dead code - -(cherry picked from commit 0269810b1aec6c554fb746433f045d59fd34ab3a) ---- - src/clients/klist/klist.c | 5 --- - src/kadmin/dbutil/kdb5_mkey.c | 2 -- - src/kadmin/server/ipropd_svc.c | 4 --- - src/lib/gssapi/krb5/gssapi_krb5.c | 2 +- - src/lib/gssapi/krb5/k5sealv3.c | 5 ++- - src/lib/gssapi/krb5/k5sealv3iov.c | 5 ++- - src/lib/kdb/kdb_convert.c | 36 +++---------------- - .../kdb/ldap/ldap_util/kdb5_ldap_services.c | 4 --- - .../kdb/ldap/libkdb_ldap/ldap_create.c | 10 ------ - src/plugins/preauth/pkinit/pkinit_srv.c | 8 ----- - src/tests/hammer/kdc5_hammer.c | 4 +-- - 11 files changed, 10 insertions(+), 75 deletions(-) - -diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c -index 8c307151a..4261ac96c 100644 ---- a/src/clients/klist/klist.c -+++ b/src/clients/klist/klist.c -@@ -720,11 +720,6 @@ show_credential(krb5_creds *cred) - extra_field += 2; - } - -- if (extra_field > 3) { -- fputs("\n", stdout); -- extra_field = 0; -- } -- - if (show_flags) { - flags = flags_string(cred); - if (flags && *flags) { -diff --git a/src/kadmin/dbutil/kdb5_mkey.c b/src/kadmin/dbutil/kdb5_mkey.c -index 19796c202..aceb0a9b8 100644 ---- a/src/kadmin/dbutil/kdb5_mkey.c -+++ b/src/kadmin/dbutil/kdb5_mkey.c -@@ -1240,7 +1240,6 @@ kdb5_purge_mkeys(int argc, char *argv[]) - if (actkvno_entry == actkvno_list) { - /* remove from head */ - actkvno_list = actkvno_entry->next; -- prev_actkvno_entry = actkvno_list; - } else if (actkvno_entry->next == NULL) { - /* remove from tail */ - prev_actkvno_entry->next = NULL; -@@ -1263,7 +1262,6 @@ kdb5_purge_mkeys(int argc, char *argv[]) - if (mkey_aux_entry->mkey_kvno == args.kvnos[j].kvno) { - if (mkey_aux_entry == mkey_aux_list) { - mkey_aux_list = mkey_aux_entry->next; -- prev_mkey_aux_entry = mkey_aux_list; - } else if (mkey_aux_entry->next == NULL) { - prev_mkey_aux_entry->next = NULL; - } else { -diff --git a/src/kadmin/server/ipropd_svc.c b/src/kadmin/server/ipropd_svc.c -index dc9984c2c..56e9b90b2 100644 ---- a/src/kadmin/server/ipropd_svc.c -+++ b/src/kadmin/server/ipropd_svc.c -@@ -263,8 +263,6 @@ ipropx_resync(uint32_t vers, struct svc_req *rqstp) - int pret, fret; - FILE *p; - kadm5_server_handle_t handle = global_server_handle; -- OM_uint32 min_stat; -- gss_name_t name = NULL; - char *client_name = NULL, *service_name = NULL; - char *whoami = "iprop_full_resync_1"; - -@@ -440,8 +438,6 @@ out: - debprret(whoami, ret.ret, 0); - free(client_name); - free(service_name); -- if (name) -- gss_release_name(&min_stat, &name); - free(ubuf); - return (&ret); - } -diff --git a/src/lib/gssapi/krb5/gssapi_krb5.c b/src/lib/gssapi/krb5/gssapi_krb5.c -index 79b83e0c6..f09cda007 100644 ---- a/src/lib/gssapi/krb5/gssapi_krb5.c -+++ b/src/lib/gssapi/krb5/gssapi_krb5.c -@@ -780,7 +780,7 @@ krb5_gss_localname(OM_uint32 *minor, - localname->value = gssalloc_strdup(lname); - localname->length = strlen(lname); - -- return (code == 0) ? GSS_S_COMPLETE : GSS_S_FAILURE; -+ return GSS_S_COMPLETE; - } - - -diff --git a/src/lib/gssapi/krb5/k5sealv3.c b/src/lib/gssapi/krb5/k5sealv3.c -index 25d9f2711..3b4f8cb83 100644 ---- a/src/lib/gssapi/krb5/k5sealv3.c -+++ b/src/lib/gssapi/krb5/k5sealv3.c -@@ -145,9 +145,8 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, - /* TOK_ID */ - store_16_be(KG2_TOK_WRAP_MSG, outbuf); - /* flags */ -- outbuf[2] = (acceptor_flag -- | (conf_req_flag ? FLAG_WRAP_CONFIDENTIAL : 0) -- | (ctx->have_acceptor_subkey ? FLAG_ACCEPTOR_SUBKEY : 0)); -+ outbuf[2] = (acceptor_flag | FLAG_WRAP_CONFIDENTIAL | -+ (ctx->have_acceptor_subkey ? FLAG_ACCEPTOR_SUBKEY : 0)); - /* filler */ - outbuf[3] = 0xff; - /* EC */ -diff --git a/src/lib/gssapi/krb5/k5sealv3iov.c b/src/lib/gssapi/krb5/k5sealv3iov.c -index a73edb6a4..333ee124d 100644 ---- a/src/lib/gssapi/krb5/k5sealv3iov.c -+++ b/src/lib/gssapi/krb5/k5sealv3iov.c -@@ -144,9 +144,8 @@ gss_krb5int_make_seal_token_v3_iov(krb5_context context, - /* TOK_ID */ - store_16_be(KG2_TOK_WRAP_MSG, outbuf); - /* flags */ -- outbuf[2] = (acceptor_flag -- | (conf_req_flag ? FLAG_WRAP_CONFIDENTIAL : 0) -- | (ctx->have_acceptor_subkey ? FLAG_ACCEPTOR_SUBKEY : 0)); -+ outbuf[2] = (acceptor_flag | FLAG_WRAP_CONFIDENTIAL | -+ (ctx->have_acceptor_subkey ? FLAG_ACCEPTOR_SUBKEY : 0)); - /* filler */ - outbuf[3] = 0xFF; - /* EC */ -diff --git a/src/lib/kdb/kdb_convert.c b/src/lib/kdb/kdb_convert.c -index 76140732f..e1bf1919f 100644 ---- a/src/lib/kdb/kdb_convert.c -+++ b/src/lib/kdb/kdb_convert.c -@@ -305,8 +305,6 @@ ulog_conv_2logentry(krb5_context context, krb5_db_entry *entry, - krb5_error_code ret; - kdbe_attr_type_t *attr_types; - int kadm_data_yes; -- /* always exclude non-replicated attributes, for now */ -- krb5_boolean exclude_nra = TRUE; - - nattrs = tmpint = 0; - final = -1; -@@ -356,7 +354,8 @@ ulog_conv_2logentry(krb5_context context, krb5_db_entry *entry, - nattrs++; - } - } else { -- find_changed_attrs(curr, entry, exclude_nra, attr_types, &nattrs); -+ /* Always exclude non-replicated attributes for now. */ -+ find_changed_attrs(curr, entry, TRUE, attr_types, &nattrs); - krb5_db_free_principal(context, curr); - } - -@@ -402,31 +401,6 @@ ulog_conv_2logentry(krb5_context context, krb5_db_entry *entry, - } - break; - -- case AT_LAST_SUCCESS: -- if (!exclude_nra && entry->last_success >= 0) { -- ULOG_ENTRY_TYPE(update, ++final).av_type = AT_LAST_SUCCESS; -- ULOG_ENTRY(update, final).av_last_success = -- (uint32_t)entry->last_success; -- } -- break; -- -- case AT_LAST_FAILED: -- if (!exclude_nra && entry->last_failed >= 0) { -- ULOG_ENTRY_TYPE(update, ++final).av_type = AT_LAST_FAILED; -- ULOG_ENTRY(update, final).av_last_failed = -- (uint32_t)entry->last_failed; -- } -- break; -- -- case AT_FAIL_AUTH_COUNT: -- if (!exclude_nra) { -- ULOG_ENTRY_TYPE(update, ++final).av_type = -- AT_FAIL_AUTH_COUNT; -- ULOG_ENTRY(update, final).av_fail_auth_count = -- (uint32_t)entry->fail_auth_count; -- } -- break; -- - case AT_PRINC: - if (entry->princ->length > 0) { - ULOG_ENTRY_TYPE(update, ++final).av_type = AT_PRINC; -@@ -552,10 +526,8 @@ ulog_conv_2logentry(krb5_context context, krb5_db_entry *entry, - /* END CSTYLED */ - - case AT_LEN: -- if (entry->len >= 0) { -- ULOG_ENTRY_TYPE(update, ++final).av_type = AT_LEN; -- ULOG_ENTRY(update, final).av_len = (int16_t)entry->len; -- } -+ ULOG_ENTRY_TYPE(update, ++final).av_type = AT_LEN; -+ ULOG_ENTRY(update, final).av_len = (int16_t)entry->len; - break; - - default: -diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c -index ce038fc3d..0a95101ad 100644 ---- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c -+++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c -@@ -135,10 +135,6 @@ kdb5_ldap_stash_service_password(int argc, char **argv) - print_usage = TRUE; - goto cleanup; - } -- if (file_name == NULL) { -- com_err(me, ENOMEM, _("while setting service object password")); -- goto cleanup; -- } - } else { /* argc == 2 */ - service_object = strdup (argv[1]); - if (service_object == NULL) { -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c -index 1e6fffee5..5b57c799a 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c -@@ -56,7 +56,6 @@ krb5_ldap_create(krb5_context context, char *conf_section, char **db_args) - krb5_ldap_realm_params *rparams = NULL; - krb5_ldap_context *ldap_context=NULL; - krb5_boolean realm_obj_created = FALSE; -- krb5_boolean krbcontainer_obj_created = FALSE; - int mask = 0; - - /* Clear the global error string */ -@@ -121,15 +120,6 @@ krb5_ldap_create(krb5_context context, char *conf_section, char **db_args) - goto cleanup; - - cleanup: -- /* If the krbcontainer/realm creation is not complete, do the roll-back here */ -- if ((krbcontainer_obj_created) && (!realm_obj_created)) { -- int rc; -- rc = krb5_ldap_delete_krbcontainer(context, -- ldap_context->container_dn); -- k5_setmsg(context, rc, _("could not complete roll-back, error " -- "deleting Kerberos Container")); -- } -- - if (rparams) - krb5_ldap_free_realm_params(rparams); - -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index 27e6ef4d2..6aa646cc6 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -258,15 +258,7 @@ verify_client_san(krb5_context context, - } - pkiDebug("%s: no upn san match found\n", __FUNCTION__); - -- /* We found no match */ -- if (princs != NULL || upns != NULL) { -- *valid_san = 0; -- /* XXX ??? If there was one or more name in the cert, but -- * none matched the client name, then return mismatch? */ -- retval = KRB5KDC_ERR_CLIENT_NAME_MISMATCH; -- } - retval = 0; -- - out: - if (princs != NULL) { - for (i = 0; princs[i] != NULL; i++) -diff --git a/src/tests/hammer/kdc5_hammer.c b/src/tests/hammer/kdc5_hammer.c -index 086c21d1c..8220fd97b 100644 ---- a/src/tests/hammer/kdc5_hammer.c -+++ b/src/tests/hammer/kdc5_hammer.c -@@ -439,7 +439,6 @@ int get_tgt (context, p_client_str, p_client, ccache) - krb5_principal *p_client; - krb5_ccache ccache; - { -- char *cache_name = NULL; /* -f option */ - long lifetime = KRB5_DEFAULT_LIFE; /* -l option */ - krb5_error_code code; - krb5_creds my_creds; -@@ -464,8 +463,7 @@ int get_tgt (context, p_client_str, p_client, ccache) - - code = krb5_cc_initialize (context, ccache, *p_client); - if (code != 0) { -- com_err (prog, code, "when initializing cache %s", -- cache_name?cache_name:""); -+ com_err (prog, code, "when initializing cache"); - return(-1); - } - diff --git a/Remove-now-unused-checksum-functions.patch b/Remove-now-unused-checksum-functions.patch deleted file mode 100644 index 5a8dd90..0000000 --- a/Remove-now-unused-checksum-functions.patch +++ /dev/null @@ -1,335 +0,0 @@ -From e9cc0b8762266ed368cb50e7ba48d6196db54da5 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 28 Jun 2019 13:09:47 -0400 -Subject: [PATCH] Remove now-unused checksum functions - -fb2dada5eb89c4cd4e39dedd6dbb7dbd5e94f8b8 removed all call sites of -krb5int_cbc_checksum(), krb5int_confounder_verify(), and -krb5int_confounder_checksum(), but neglected the functions themselves. - -ticket: 8808 -(cherry picked from commit 2063ff09b384d466c15aca8970c01d074230c815) ---- - src/lib/crypto/krb/Makefile.in | 6 - - src/lib/crypto/krb/checksum_cbc.c | 41 ------ - src/lib/crypto/krb/checksum_confounder.c | 159 ----------------------- - src/lib/crypto/krb/crypto_int.h | 16 --- - src/lib/crypto/krb/deps | 26 ---- - 5 files changed, 248 deletions(-) - delete mode 100644 src/lib/crypto/krb/checksum_cbc.c - delete mode 100644 src/lib/crypto/krb/checksum_confounder.c - -diff --git a/src/lib/crypto/krb/Makefile.in b/src/lib/crypto/krb/Makefile.in -index b587f7e19..2b0c4163d 100644 ---- a/src/lib/crypto/krb/Makefile.in -+++ b/src/lib/crypto/krb/Makefile.in -@@ -10,8 +10,6 @@ STLIBOBJS=\ - aead.o \ - block_size.o \ - cf2.o \ -- checksum_cbc.o \ -- checksum_confounder.o \ - checksum_dk_cmac.o \ - checksum_dk_hmac.o \ - checksum_etm.o \ -@@ -70,8 +68,6 @@ OBJS=\ - $(OUTPRE)aead.$(OBJEXT) \ - $(OUTPRE)block_size.$(OBJEXT) \ - $(OUTPRE)cf2.$(OBJEXT) \ -- $(OUTPRE)checksum_cbc.$(OBJEXT) \ -- $(OUTPRE)checksum_confounder.$(OBJEXT) \ - $(OUTPRE)checksum_dk_cmac.$(OBJEXT) \ - $(OUTPRE)checksum_dk_hmac.$(OBJEXT) \ - $(OUTPRE)checksum_etm.$(OBJEXT) \ -@@ -130,8 +126,6 @@ SRCS=\ - $(srcdir)/aead.c \ - $(srcdir)/block_size.c \ - $(srcdir)/cf2.c \ -- $(srcdir)/checksum_cbc.c \ -- $(srcdir)/checksum_confounder.c \ - $(srcdir)/checksum_dk_cmac.c \ - $(srcdir)/checksum_dk_hmac.c \ - $(srcdir)/checksum_etm.c \ -diff --git a/src/lib/crypto/krb/checksum_cbc.c b/src/lib/crypto/krb/checksum_cbc.c -deleted file mode 100644 -index 48afeb0e5..000000000 ---- a/src/lib/crypto/krb/checksum_cbc.c -+++ /dev/null -@@ -1,41 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* lib/crypto/krb/checksum_cbc.c */ --/* -- * Copyright (C) 2009 by the Massachusetts Institute of Technology. -- * All rights reserved. -- * -- * Export of this software from the United States of America may -- * require a specific license from the United States Government. -- * It is the responsibility of any person or organization contemplating -- * export to obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of M.I.T. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. Furthermore if you modify this software you must label -- * your software as modified software and not distribute it in such a -- * fashion that it might be confused with the original M.I.T. software. -- * M.I.T. makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- */ -- --/* CBC checksum, which computes the ivec resulting from CBC encryption of the -- * input. */ -- --#include "crypto_int.h" -- --krb5_error_code --krb5int_cbc_checksum(const struct krb5_cksumtypes *ctp, -- krb5_key key, krb5_keyusage usage, -- const krb5_crypto_iov *data, size_t num_data, -- krb5_data *output) --{ -- if (ctp->enc->cbc_mac == NULL) -- return KRB5_CRYPTO_INTERNAL; -- return ctp->enc->cbc_mac(key, data, num_data, NULL, output); --} -diff --git a/src/lib/crypto/krb/checksum_confounder.c b/src/lib/crypto/krb/checksum_confounder.c -deleted file mode 100644 -index 34941562c..000000000 ---- a/src/lib/crypto/krb/checksum_confounder.c -+++ /dev/null -@@ -1,159 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* lib/crypto/krb/checksum_confounder.c */ --/* -- * Copyright (C) 2009 by the Massachusetts Institute of Technology. -- * All rights reserved. -- * -- * Export of this software from the United States of America may -- * require a specific license from the United States Government. -- * It is the responsibility of any person or organization contemplating -- * export to obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of M.I.T. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. Furthermore if you modify this software you must label -- * your software as modified software and not distribute it in such a -- * fashion that it might be confused with the original M.I.T. software. -- * M.I.T. makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- */ -- --/* -- * Confounder checksum implementation, using tokens of the form: -- * enc(xorkey, confounder | hash(confounder | data)) -- * where xorkey is the key XOR'd with 0xf0 bytes. -- */ -- --#include "crypto_int.h" -- --/* Derive a key by XOR with 0xF0 bytes. */ --static krb5_error_code --mk_xorkey(krb5_key origkey, krb5_key *xorkey) --{ -- krb5_error_code retval = 0; -- unsigned char *xorbytes; -- krb5_keyblock xorkeyblock; -- size_t i = 0; -- -- xorbytes = k5memdup(origkey->keyblock.contents, origkey->keyblock.length, -- &retval); -- if (xorbytes == NULL) -- return retval; -- for (i = 0; i < origkey->keyblock.length; i++) -- xorbytes[i] ^= 0xf0; -- -- /* Do a shallow copy here. */ -- xorkeyblock = origkey->keyblock; -- xorkeyblock.contents = xorbytes; -- -- retval = krb5_k_create_key(0, &xorkeyblock, xorkey); -- zapfree(xorbytes, origkey->keyblock.length); -- return retval; --} -- --krb5_error_code --krb5int_confounder_checksum(const struct krb5_cksumtypes *ctp, -- krb5_key key, krb5_keyusage usage, -- const krb5_crypto_iov *data, size_t num_data, -- krb5_data *output) --{ -- krb5_error_code ret; -- krb5_data conf, hashval; -- krb5_key xorkey = NULL; -- krb5_crypto_iov *hash_iov, iov; -- size_t blocksize = ctp->enc->block_size, hashsize = ctp->hash->hashsize; -- -- /* Partition the output buffer into confounder and hash. */ -- conf = make_data(output->data, blocksize); -- hashval = make_data(output->data + blocksize, hashsize); -- -- /* Create the confounder. */ -- ret = krb5_c_random_make_octets(NULL, &conf); -- if (ret != 0) -- return ret; -- -- ret = mk_xorkey(key, &xorkey); -- if (ret) -- return ret; -- -- /* Hash the confounder, then the input data. */ -- hash_iov = k5calloc(num_data + 1, sizeof(krb5_crypto_iov), &ret); -- if (hash_iov == NULL) -- goto cleanup; -- hash_iov[0].flags = KRB5_CRYPTO_TYPE_DATA; -- hash_iov[0].data = conf; -- memcpy(hash_iov + 1, data, num_data * sizeof(krb5_crypto_iov)); -- ret = ctp->hash->hash(hash_iov, num_data + 1, &hashval); -- if (ret != 0) -- goto cleanup; -- -- /* Confounder and hash are in output buffer; encrypt them in place. */ -- iov.flags = KRB5_CRYPTO_TYPE_DATA; -- iov.data = *output; -- ret = ctp->enc->encrypt(xorkey, NULL, &iov, 1); -- --cleanup: -- free(hash_iov); -- krb5_k_free_key(NULL, xorkey); -- return ret; --} -- --krb5_error_code krb5int_confounder_verify(const struct krb5_cksumtypes *ctp, -- krb5_key key, krb5_keyusage usage, -- const krb5_crypto_iov *data, -- size_t num_data, -- const krb5_data *input, -- krb5_boolean *valid) --{ -- krb5_error_code ret; -- unsigned char *plaintext = NULL; -- krb5_key xorkey = NULL; -- krb5_data computed = empty_data(); -- krb5_crypto_iov *hash_iov = NULL, iov; -- size_t blocksize = ctp->enc->block_size, hashsize = ctp->hash->hashsize; -- -- plaintext = k5memdup(input->data, input->length, &ret); -- if (plaintext == NULL) -- return ret; -- -- ret = mk_xorkey(key, &xorkey); -- if (ret != 0) -- goto cleanup; -- -- /* Decrypt the input checksum. */ -- iov.flags = KRB5_CRYPTO_TYPE_DATA; -- iov.data = make_data(plaintext, input->length); -- ret = ctp->enc->decrypt(xorkey, NULL, &iov, 1); -- if (ret != 0) -- goto cleanup; -- -- /* Hash the confounder, then the input data. */ -- hash_iov = k5calloc(num_data + 1, sizeof(krb5_crypto_iov), &ret); -- if (hash_iov == NULL) -- goto cleanup; -- hash_iov[0].flags = KRB5_CRYPTO_TYPE_DATA; -- hash_iov[0].data = make_data(plaintext, blocksize); -- memcpy(hash_iov + 1, data, num_data * sizeof(krb5_crypto_iov)); -- ret = alloc_data(&computed, hashsize); -- if (ret != 0) -- goto cleanup; -- ret = ctp->hash->hash(hash_iov, num_data + 1, &computed); -- if (ret != 0) -- goto cleanup; -- -- /* Compare the decrypted hash to the computed one. */ -- *valid = (k5_bcmp(plaintext + blocksize, computed.data, hashsize) == 0); -- --cleanup: -- zapfree(plaintext, input->length); -- zapfree(computed.data, hashsize); -- free(hash_iov); -- krb5_k_free_key(NULL, xorkey); -- return ret; --} -diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h -index 1b4324d71..5cc1f8e43 100644 ---- a/src/lib/crypto/krb/crypto_int.h -+++ b/src/lib/crypto/krb/crypto_int.h -@@ -299,11 +299,6 @@ krb5_error_code krb5int_unkeyed_checksum(const struct krb5_cksumtypes *ctp, - const krb5_crypto_iov *data, - size_t num_data, - krb5_data *output); --krb5_error_code krb5int_cbc_checksum(const struct krb5_cksumtypes *ctp, -- krb5_key key, krb5_keyusage usage, -- const krb5_crypto_iov *data, -- size_t num_data, -- krb5_data *output); - krb5_error_code krb5int_hmacmd5_checksum(const struct krb5_cksumtypes *ctp, - krb5_key key, krb5_keyusage usage, - const krb5_crypto_iov *data, -@@ -317,17 +312,6 @@ krb5_error_code krb5int_dk_cmac_checksum(const struct krb5_cksumtypes *ctp, - krb5_key key, krb5_keyusage usage, - const krb5_crypto_iov *data, - size_t num_data, krb5_data *output); --krb5_error_code krb5int_confounder_checksum(const struct krb5_cksumtypes *ctp, -- krb5_key key, krb5_keyusage usage, -- const krb5_crypto_iov *data, -- size_t num_data, -- krb5_data *output); --krb5_error_code krb5int_confounder_verify(const struct krb5_cksumtypes *ctp, -- krb5_key key, krb5_keyusage usage, -- const krb5_crypto_iov *data, -- size_t num_data, -- const krb5_data *input, -- krb5_boolean *valid); - krb5_error_code krb5int_etm_checksum(const struct krb5_cksumtypes *ctp, - krb5_key key, krb5_keyusage usage, - const krb5_crypto_iov *data, -diff --git a/src/lib/crypto/krb/deps b/src/lib/crypto/krb/deps -index 2f4af1906..883d12c56 100644 ---- a/src/lib/crypto/krb/deps -+++ b/src/lib/crypto/krb/deps -@@ -37,32 +37,6 @@ cf2.so cf2.po $(OUTPRE)cf2.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ - $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ - cf2.c crypto_int.h --checksum_cbc.so checksum_cbc.po $(OUTPRE)checksum_cbc.$(OBJEXT): \ -- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ -- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h $(srcdir)/../builtin/crypto_mod.h \ -- $(srcdir)/../builtin/sha2/sha2.h $(top_srcdir)/include/k5-buf.h \ -- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h checksum_cbc.c \ -- crypto_int.h --checksum_confounder.so checksum_confounder.po $(OUTPRE)checksum_confounder.$(OBJEXT): \ -- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ -- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h $(srcdir)/../builtin/crypto_mod.h \ -- $(srcdir)/../builtin/sha2/sha2.h $(top_srcdir)/include/k5-buf.h \ -- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h checksum_confounder.c \ -- crypto_int.h - checksum_dk_cmac.so checksum_dk_cmac.po $(OUTPRE)checksum_dk_cmac.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ diff --git a/Remove-null-check-in-krb5_gss_duplicate_name.patch b/Remove-null-check-in-krb5_gss_duplicate_name.patch deleted file mode 100644 index 4d65cbd..0000000 --- a/Remove-null-check-in-krb5_gss_duplicate_name.patch +++ /dev/null @@ -1,28 +0,0 @@ -From 61855503e579611b2bb2f322070c2e1e0ca36ce8 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 30 Aug 2019 11:19:52 -0400 -Subject: [PATCH] Remove null check in krb5_gss_duplicate_name() - -Within the krb5 mechanism, we require minor_status to be writable -without checking. Remove the null check in krb5_gss_duplicate_name() -to squash a forward-null defect. - -(cherry picked from commit 9fd7bc179f0bd74fc83c1edf0247dcfd87fc73e6) ---- - src/lib/gssapi/krb5/duplicate_name.c | 3 +-- - 1 file changed, 1 insertion(+), 2 deletions(-) - -diff --git a/src/lib/gssapi/krb5/duplicate_name.c b/src/lib/gssapi/krb5/duplicate_name.c -index b88d97d9d..ea53e9c0d 100644 ---- a/src/lib/gssapi/krb5/duplicate_name.c -+++ b/src/lib/gssapi/krb5/duplicate_name.c -@@ -34,8 +34,7 @@ krb5_gss_duplicate_name(OM_uint32 *minor_status, const gss_name_t input_name, - krb5_error_code code; - krb5_gss_name_t princ, outprinc; - -- if (minor_status) -- *minor_status = 0; -+ *minor_status = 0; - - code = krb5_gss_init_context(&context); - if (code) { diff --git a/Remove-ovsec_adm_export-dump-format-support.patch b/Remove-ovsec_adm_export-dump-format-support.patch deleted file mode 100644 index 466aea0..0000000 --- a/Remove-ovsec_adm_export-dump-format-support.patch +++ /dev/null @@ -1,386 +0,0 @@ -From e4c75d01bfdedfe77068a641e0053eef227dc22b Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 22 Jan 2019 18:34:58 -0500 -Subject: [PATCH] Remove ovsec_adm_export dump format support - -Dumping only suported single-DES principals. While importing still -functioned, it would only have been useful for extremely old (1.3-era) -KDCs. - -ticket: 8798 (new) -(cherry picked from commit 23b93fd48bc445005436c5be98a7269b599b1800) -[rharwood@redhat.com: release version conflict in man pages] ---- - doc/admin/admin_commands/kdb5_util.rst | 11 +-- - doc/admin/database.rst | 14 ---- - src/kadmin/dbutil/dump.c | 109 ++----------------------- - src/kadmin/dbutil/kdb5_util.c | 4 +- - src/man/kdb5_util.man | 13 +-- - src/tests/Makefile.in | 6 -- - src/tests/t_dump.py | 8 -- - 7 files changed, 13 insertions(+), 152 deletions(-) - -diff --git a/doc/admin/admin_commands/kdb5_util.rst b/doc/admin/admin_commands/kdb5_util.rst -index fee68261a..7dd54f797 100644 ---- a/doc/admin/admin_commands/kdb5_util.rst -+++ b/doc/admin/admin_commands/kdb5_util.rst -@@ -136,7 +136,7 @@ dump - - .. _kdb5_util_dump: - -- **dump** [**-b7**\|\ **-ov**\|\ **-r13**\|\ **-r18**] -+ **dump** [**-b7**\|\ **-r13**\|\ **-r18**] - [**-verbose**] [**-mkey_convert**] [**-new_mkey_file** - *mkey_file*] [**-rev**] [**-recurse**] [*filename* - [*principals*...]] -@@ -151,9 +151,6 @@ load_dump version 7". If filename is not specified, or is the string - load_dump version 4"). This was the dump format produced on - releases prior to 1.2.2. - --**-ov** -- causes the dump to be in "ovsec_adm_export" format. -- - **-r13** - causes the dump to be in the Kerberos 5 1.3 format ("kdb5_util - load_dump version 5"). This was the dump format produced on -@@ -204,7 +201,7 @@ load - - .. _kdb5_util_load: - -- **load** [**-b7**\|\ **-ov**\|\ **-r13**\|\ **-r18**] [**-hash**] -+ **load** [**-b7**\|\ **-r13**\|\ **-r18**] [**-hash**] - [**-verbose**] [**-update**] *filename* - - Loads a database dump from the named file into the named database. If -@@ -222,10 +219,6 @@ Options: - ("kdb5_util load_dump version 4"). This was the dump format - produced on releases prior to 1.2.2. - --**-ov** -- requires the database to be in "ovsec_adm_import" format. Must be -- used with the **-update** option. -- - **-r13** - requires the database to be in Kerberos 5 1.3 format ("kdb5_util - load_dump version 5"). This was the dump format produced on -diff --git a/doc/admin/database.rst b/doc/admin/database.rst -index d0be455f8..33895b857 100644 ---- a/doc/admin/database.rst -+++ b/doc/admin/database.rst -@@ -393,20 +393,6 @@ To dump a single principal and later load it, updating the database: - If the database file exists, and the *-update* flag was not - given, *kdb5_util* will overwrite the existing database. - --Using kdb5_util to upgrade a master KDC from krb5 1.1.x: -- --:: -- -- shell% kdb5_util dump old-kdb-dump -- shell% kdb5_util dump -ov old-kdb-dump.ov -- [Create a new KDC installation, using the old stash file/master password] -- shell% kdb5_util load old-kdb-dump -- shell% kdb5_util load -update old-kdb-dump.ov -- --The use of old-kdb-dump.ov for an extra dump and load is necessary --to preserve per-principal policy information, which is not included in --the default dump format of krb5 1.1.x. -- - .. note:: - - Using kdb5_util to dump and reload the principal database is -diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c -index 8301a33d0..19f2cc230 100644 ---- a/src/kadmin/dbutil/dump.c -+++ b/src/kadmin/dbutil/dump.c -@@ -484,83 +484,6 @@ dump_r1_11_policy(void *data, osa_policy_ent_t entry) - fprintf(arg->ofile, "\n"); - } - --static void --print_key_data(FILE *f, krb5_key_data *kd) --{ -- int c; -- -- fprintf(f, "%d\t%d\t", kd->key_data_type[0], kd->key_data_length[0]); -- for (c = 0; c < kd->key_data_length[0]; c++) -- fprintf(f, "%02x ", kd->key_data_contents[0][c]); --} -- --/* Output osa_adb_princ_ent data in a printable serialized format, suitable for -- * ovsec_adm_import consumption. */ --static krb5_error_code --dump_ov_princ(krb5_context context, krb5_db_entry *entry, const char *name, -- FILE *fp, krb5_boolean verbose, krb5_boolean omit_nra) --{ -- char *princstr; -- unsigned int x; -- int y, foundcrc; -- krb5_tl_data tl_data; -- osa_princ_ent_rec adb; -- XDR xdrs; -- krb5_key_data *key_data; -- -- tl_data.tl_data_type = KRB5_TL_KADM_DATA; -- if (krb5_dbe_lookup_tl_data(context, entry, &tl_data) || -- tl_data.tl_data_length == 0) -- return 0; -- -- memset(&adb, 0, sizeof(adb)); -- xdrmem_create(&xdrs, (caddr_t)tl_data.tl_data_contents, -- tl_data.tl_data_length, XDR_DECODE); -- if (!xdr_osa_princ_ent_rec(&xdrs, &adb)) { -- xdr_destroy(&xdrs); -- return KADM5_XDR_FAILURE; -- } -- xdr_destroy(&xdrs); -- -- krb5_unparse_name(context, entry->princ, &princstr); -- fprintf(fp, "princ\t%s\t", princstr); -- if (adb.policy == NULL) -- fputc('\t', fp); -- else -- fprintf(fp, "%s\t", adb.policy); -- fprintf(fp, "%lx\t%d\t%d\t%d", adb.aux_attributes, adb.old_key_len, -- adb.old_key_next, adb.admin_history_kvno); -- -- for (x = 0; x < adb.old_key_len; x++) { -- foundcrc = 0; -- for (y = 0; y < adb.old_keys[x].n_key_data; y++) { -- key_data = &adb.old_keys[x].key_data[y]; -- if (key_data->key_data_type[0] != ENCTYPE_DES_CBC_CRC) -- continue; -- if (foundcrc) { -- fprintf(stderr, _("Warning! Multiple DES-CBC-CRC keys for " -- "principal %s; skipping duplicates.\n"), -- princstr); -- continue; -- } -- foundcrc++; -- -- fputc('\t', fp); -- print_key_data(fp, key_data); -- } -- if (!foundcrc) { -- fprintf(stderr, _("Warning! No DES-CBC-CRC key for principal %s, " -- "cannot generate OV-compatible record; " -- "skipping\n"), princstr); -- } -- } -- -- fputc('\n', fp); -- free(princstr); -- xdr_free(xdr_osa_princ_ent_rec, &adb); -- return 0; --} -- - static krb5_error_code - dump_iterator(void *ptr, krb5_db_entry *entry) - { -@@ -1101,14 +1024,6 @@ process_k5beta7_record(krb5_context context, const char *fname, FILE *filep, - process_k5beta7_princ, process_k5beta7_policy); - } - --static int --process_ov_record(krb5_context context, const char *fname, FILE *filep, -- krb5_boolean verbose, int *linenop) --{ -- return process_tagged(context, fname, filep, verbose, linenop, -- process_ov_principal, process_k5beta7_policy); --} -- - static int - process_r1_8_record(krb5_context context, const char *fname, FILE *filep, - krb5_boolean verbose, int *linenop) -@@ -1135,16 +1050,6 @@ dump_version beta7_version = { - dump_k5beta7_policy, - process_k5beta7_record, - }; --dump_version ov_version = { -- "OpenV*Secure V1.0", -- "OpenV*Secure V1.0\t", -- 1, -- 0, -- 0, -- dump_ov_princ, -- dump_k5beta7_policy, -- process_ov_record --}; - dump_version r1_3_version = { - "Kerberos version 5 release 1.3", - "kdb5_util load_dump version 5\n", -@@ -1267,7 +1172,7 @@ current_dump_sno_in_ulog(krb5_context context, const char *ifile) - - /* - * usage is: -- * dump_db [-b7] [-ov] [-r13] [-r18] [-verbose] [-mkey_convert] -+ * dump_db [-b7] [-r13] [-r18] [-verbose] [-mkey_convert] - * [-new_mkey_file mkey_file] [-rev] [-recurse] - * [filename [principals...]] - */ -@@ -1302,7 +1207,8 @@ dump_db(int argc, char **argv) - if (!strcmp(argv[aindex], "-b7")) { - dump = &beta7_version; - } else if (!strcmp(argv[aindex], "-ov")) { -- dump = &ov_version; -+ fprintf(stderr, _("OV dump format not supported\n")); -+ goto error; - } else if (!strcmp(argv[aindex], "-r13")) { - dump = &r1_3_version; - } else if (!strcmp(argv[aindex], "-r18")) { -@@ -1515,8 +1421,7 @@ restore_dump(krb5_context context, char *dumpfile, FILE *f, - } - - /* -- * Usage: load_db [-ov] [-b7] [-r13] [-r18] [-verbose] [-update] [-hash] -- * filename -+ * Usage: load_db [-b7] [-r13] [-r18] [-verbose] [-update] [-hash] filename - */ - void - load_db(int argc, char **argv) -@@ -1540,7 +1445,8 @@ load_db(int argc, char **argv) - if (!strcmp(argv[aindex], "-b7")){ - load = &beta7_version; - } else if (!strcmp(argv[aindex], "-ov")) { -- load = &ov_version; -+ fprintf(stderr, _("OV dump format not supported\n")); -+ goto error; - } else if (!strcmp(argv[aindex], "-r13")) { - load = &r1_3_version; - } else if (!strcmp(argv[aindex], "-r18")){ -@@ -1605,9 +1511,6 @@ load_db(int argc, char **argv) - load = &r1_8_version; - } else if (strcmp(buf, r1_11_version.header) == 0) { - load = &r1_11_version; -- } else if (strncmp(buf, ov_version.header, -- strlen(ov_version.header)) == 0) { -- load = &ov_version; - } else { - fprintf(stderr, _("%s: dump header bad in %s\n"), progname, - dumpfile); -diff --git a/src/kadmin/dbutil/kdb5_util.c b/src/kadmin/dbutil/kdb5_util.c -index accc959e0..e73e2c68e 100644 ---- a/src/kadmin/dbutil/kdb5_util.c -+++ b/src/kadmin/dbutil/kdb5_util.c -@@ -85,10 +85,10 @@ void usage() - "\tcreate [-s]\n" - "\tdestroy [-f]\n" - "\tstash [-f keyfile]\n" -- "\tdump [-old|-ov|-b6|-b7|-r13|-r18] [-verbose]\n" -+ "\tdump [-old|-b6|-b7|-r13|-r18] [-verbose]\n" - "\t [-mkey_convert] [-new_mkey_file mkey_file]\n" - "\t [-rev] [-recurse] [filename [princs...]]\n" -- "\tload [-old|-ov|-b6|-b7|-r13|-r18] [-verbose] [-update] " -+ "\tload [-old|-b6|-b7|-r13|-r18] [-verbose] [-update] " - "filename\n" - "\tark [-e etype_list] principal\n" - "\tadd_mkey [-e etype] [-s]\n" -diff --git a/src/man/kdb5_util.man b/src/man/kdb5_util.man -index 9c48c32fb..9a36ef0df 100644 ---- a/src/man/kdb5_util.man -+++ b/src/man/kdb5_util.man -@@ -1,6 +1,6 @@ - .\" Man page generated from reStructuredText. - . --.TH "KDB5_UTIL" "8" " " "1.17.1" "MIT Kerberos" -+.TH "KDB5_UTIL" "8" " " "1.18" "MIT Kerberos" - .SH NAME - kdb5_util \- Kerberos database maintenance utility - . -@@ -136,7 +136,7 @@ kdc.conf(5)\&. - .SS dump - .INDENT 0.0 - .INDENT 3.5 --\fBdump\fP [\fB\-b7\fP|\fB\-ov\fP|\fB\-r13\fP|\fB\-r18\fP] -+\fBdump\fP [\fB\-b7\fP|\fB\-r13\fP|\fB\-r18\fP] - [\fB\-verbose\fP] [\fB\-mkey_convert\fP] [\fB\-new_mkey_file\fP - \fImkey_file\fP] [\fB\-rev\fP] [\fB\-recurse\fP] [\fIfilename\fP - [\fIprincipals\fP\&...]] -@@ -154,9 +154,6 @@ causes the dump to be in the Kerberos 5 Beta 7 format ("kdb5_util - load_dump version 4"). This was the dump format produced on - releases prior to 1.2.2. - .TP --\fB\-ov\fP --causes the dump to be in "ovsec_adm_export" format. --.TP - \fB\-r13\fP - causes the dump to be in the Kerberos 5 1.3 format ("kdb5_util - load_dump version 5"). This was the dump format produced on -@@ -203,7 +200,7 @@ doing a normal dump instead of a recursive traversal. - .SS load - .INDENT 0.0 - .INDENT 3.5 --\fBload\fP [\fB\-b7\fP|\fB\-ov\fP|\fB\-r13\fP|\fB\-r18\fP] [\fB\-hash\fP] -+\fBload\fP [\fB\-b7\fP|\fB\-r13\fP|\fB\-r18\fP] [\fB\-hash\fP] - [\fB\-verbose\fP] [\fB\-update\fP] \fIfilename\fP - .UNINDENT - .UNINDENT -@@ -224,10 +221,6 @@ requires the database to be in the Kerberos 5 Beta 7 format - ("kdb5_util load_dump version 4"). This was the dump format - produced on releases prior to 1.2.2. - .TP --\fB\-ov\fP --requires the database to be in "ovsec_adm_import" format. Must be --used with the \fB\-update\fP option. --.TP - \fB\-r13\fP - requires the database to be in Kerberos 5 1.3 format ("kdb5_util - load_dump version 5"). This was the dump format produced on -diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in -index e27617ee2..c96c5d6b7 100644 ---- a/src/tests/Makefile.in -+++ b/src/tests/Makefile.in -@@ -97,7 +97,6 @@ kdb_check: kdc.conf krb5.conf - $(RUN_DB_TEST) ../tests/create/kdb5_mkdums $(KTEST_OPTS) - $(RUN_DB_TEST) ../tests/verify/kdb5_verify $(KTEST_OPTS) - $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) dump $(TEST_DB).dump -- $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) dump -ov $(TEST_DB).ovdump - $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) destroy -f - @echo "====> NOTE!" - @echo "The following 'create' command is needed due to a change" -@@ -105,16 +104,11 @@ kdb_check: kdc.conf krb5.conf - @echo ==== - $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) create -W - $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) load $(TEST_DB).dump -- $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) load -update -ov $(TEST_DB).ovdump - $(RUN_DB_TEST) ../tests/verify/kdb5_verify $(KTEST_OPTS) - $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) dump $(TEST_DB).dump2 -- $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) dump -ov $(TEST_DB).ovdump2 - sort $(TEST_DB).dump > $(TEST_DB).sort - sort $(TEST_DB).dump2 > $(TEST_DB).sort2 -- sort $(TEST_DB).ovdump > $(TEST_DB).ovsort -- sort $(TEST_DB).ovdump2 > $(TEST_DB).ovsort2 - cmp $(TEST_DB).sort $(TEST_DB).sort2 -- cmp $(TEST_DB).ovsort $(TEST_DB).ovsort2 - $(RUN_DB_TEST) ../kadmin/dbutil/kdb5_util $(KADMIN_OPTS) destroy -f - $(RM) $(TEST_DB)* stash_file - -diff --git a/src/tests/t_dump.py b/src/tests/t_dump.py -index d803d5602..5d692df99 100755 ---- a/src/tests/t_dump.py -+++ b/src/tests/t_dump.py -@@ -73,7 +73,6 @@ for realm in multidb_realms(start_kdc=False): - srcdump_r18 = os.path.join(srcdumpdir, 'dump.r18') - srcdump_r13 = os.path.join(srcdumpdir, 'dump.r13') - srcdump_b7 = os.path.join(srcdumpdir, 'dump.b7') -- srcdump_ov = os.path.join(srcdumpdir, 'dump.ov') - - # Load a dump file from the source directory. - realm.run([kdb5_util, 'destroy', '-f']) -@@ -86,17 +85,10 @@ for realm in multidb_realms(start_kdc=False): - dump_compare(realm, ['-r18'], srcdump_r18) - dump_compare(realm, ['-r13'], srcdump_r13) - dump_compare(realm, ['-b7'], srcdump_b7) -- dump_compare(realm, ['-ov'], srcdump_ov) - - # Load each format of dump, check it, re-dump it, and compare. - load_dump_check_compare(realm, ['-r18'], srcdump_r18) - load_dump_check_compare(realm, ['-r13'], srcdump_r13) - load_dump_check_compare(realm, ['-b7'], srcdump_b7) - -- # Loading the last (-b7 format) dump won't have loaded the -- # per-principal kadm data. Load that incrementally with -ov. -- realm.run([kadminl, 'getprinc', 'user'], expected_msg='Policy: [none]') -- realm.run([kdb5_util, 'load', '-update', '-ov', srcdump_ov]) -- realm.run([kadminl, 'getprinc', 'user'], expected_msg='Policy: testpol') -- - success('Dump/load tests') diff --git a/Remove-srvtab-support.patch b/Remove-srvtab-support.patch deleted file mode 100644 index e175243..0000000 --- a/Remove-srvtab-support.patch +++ /dev/null @@ -1,1411 +0,0 @@ -From ecf80eb7a536c2d78812482d9c974120725ca609 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 9 Oct 2017 15:58:33 -0400 -Subject: [PATCH] Remove srvtab support - -Also change internal names from "srvtab" to "keytab" where the old -name was used. - -ticket: 8793 (new) -(cherry picked from commit a23e670b40f69b6be0024f8a60d2afaf7f7a005a) -[rharwood@redhat.com: release version conflict in man pages] ---- - doc/admin/admin_commands/ktutil.rst | 22 +- - doc/basic/keytab_def.rst | 6 +- - src/kadmin/ktutil/ktutil.c | 11 +- - src/kadmin/ktutil/ktutil.h | 4 - - src/kadmin/ktutil/ktutil_ct.ct | 4 +- - src/kadmin/ktutil/ktutil_funcs.c | 19 - - src/kadmin/testing/proto/krb5.conf.proto | 2 +- - src/kadmin/testing/scripts/env-setup.shin | 2 +- - src/kadmin/testing/scripts/init_db | 2 +- - .../testing/scripts/make-host-keytab.plin | 2 +- - .../testing/scripts/start_servers_local | 3 - - src/kprop/kprop.c | 10 +- - src/kprop/kpropd.c | 12 +- - src/lib/kadm5/unit-test/api.current/init.exp | 4 +- - src/lib/krb5/keytab/Makefile.in | 3 - - src/lib/krb5/keytab/deps | 11 - - src/lib/krb5/keytab/kt_srvtab.c | 435 ------------------ - src/lib/krb5/keytab/ktbase.c | 7 +- - src/lib/krb5/krb/in_tkt_sky.c | 6 +- - src/lib/krb5/libkrb5.exports | 1 - - src/lib/rpc/unit-test/Makefile.in | 6 +- - src/lib/rpc/unit-test/config/unix.exp | 2 +- - src/lib/rpc/unit-test/lib/helpers.exp | 4 +- - src/lib/rpc/unit-test/rpc_test_setup.sh | 6 +- - src/man/ktutil.man | 26 +- - src/tests/dejagnu/config/default.exp | 58 ++- - src/tests/dejagnu/krb-standalone/gssapi.exp | 8 +- - src/tests/dejagnu/krb-standalone/kadmin.exp | 48 +- - src/tests/dejagnu/krb-standalone/kprop.exp | 6 +- - src/tests/dejagnu/krb-standalone/sample.exp | 8 +- - src/tests/dejagnu/krb-standalone/simple.exp | 6 +- - .../dejagnu/krb-standalone/standalone.exp | 4 +- - src/tests/dejagnu/krb-standalone/tcp.exp | 5 - - 33 files changed, 86 insertions(+), 667 deletions(-) - delete mode 100644 src/lib/krb5/keytab/kt_srvtab.c - -diff --git a/doc/admin/admin_commands/ktutil.rst b/doc/admin/admin_commands/ktutil.rst -index 0dbc08f60..0897c7757 100644 ---- a/doc/admin/admin_commands/ktutil.rst -+++ b/doc/admin/admin_commands/ktutil.rst -@@ -13,8 +13,8 @@ DESCRIPTION - ----------- - - The ktutil command invokes a command interface from which an --administrator can read, write, or edit entries in a keytab or Kerberos --V4 srvtab file. -+administrator can read, write, or edit entries in a keytab. (Kerberos -+V4 srvtab files are no longer supported.) - - - COMMANDS -@@ -38,15 +38,6 @@ Read the Kerberos V5 keytab file *keytab* into the current keylist. - - Alias: **rkt** - --read_st --~~~~~~~ -- -- **read_st** *srvtab* -- --Read the Kerberos V4 srvtab file *srvtab* into the current keylist. -- --Alias: **rst** -- - write_kt - ~~~~~~~~ - -@@ -56,15 +47,6 @@ Write the current keylist into the Kerberos V5 keytab file *keytab*. - - Alias: **wkt** - --write_st --~~~~~~~~ -- -- **write_st** *srvtab* -- --Write the current keylist into the Kerberos V4 srvtab file *srvtab*. -- --Alias: **wst** -- - clear_list - ~~~~~~~~~~ - -diff --git a/doc/basic/keytab_def.rst b/doc/basic/keytab_def.rst -index 33ae67c6c..6c7fcc3b0 100644 ---- a/doc/basic/keytab_def.rst -+++ b/doc/basic/keytab_def.rst -@@ -12,10 +12,8 @@ credentials for client applications. - - Keytabs are named using the format *type*\ ``:``\ *value*. Usually - *type* is ``FILE`` and *value* is the absolute pathname of the file. --Other possible values for *type* are ``SRVTAB``, which indicates a --file in the deprecated Kerberos 4 srvtab format, and ``MEMORY``, which --indicates a temporary keytab stored in the memory of the current --process. -+The other possible value for *type* is ``MEMORY``, which indicates a -+temporary keytab stored in the memory of the current process. - - A keytab contains one or more entries, where each entry consists of a - timestamp (indicating when the entry was written to the keytab), a -diff --git a/src/kadmin/ktutil/ktutil.c b/src/kadmin/ktutil/ktutil.c -index 196f20786..92d7023a4 100644 ---- a/src/kadmin/ktutil/ktutil.c -+++ b/src/kadmin/ktutil/ktutil.c -@@ -98,15 +98,8 @@ void ktutil_read_v4(argc, argv) - int argc; - char *argv[]; - { -- krb5_error_code retval; -- -- if (argc != 2) { -- fprintf(stderr, _("%s: must specify the srvtab to read\n"), argv[0]); -- return; -- } -- retval = ktutil_read_srvtab(kcontext, argv[1], &ktlist); -- if (retval) -- com_err(argv[0], retval, _("while reading srvtab \"%s\""), argv[1]); -+ fprintf(stderr, _("%s: reading srvtabs is no longer supported\n"), -+ argv[0]); - } - - void ktutil_write_v5(argc, argv) -diff --git a/src/kadmin/ktutil/ktutil.h b/src/kadmin/ktutil/ktutil.h -index ddb754bae..acaf0239a 100644 ---- a/src/kadmin/ktutil/ktutil.h -+++ b/src/kadmin/ktutil/ktutil.h -@@ -50,10 +50,6 @@ krb5_error_code ktutil_write_keytab (krb5_context, - krb5_kt_list, - char *); - --krb5_error_code ktutil_read_srvtab (krb5_context, -- char *, -- krb5_kt_list *); -- - void ktutil_add_entry (int, char *[]); - - void ktutil_clear_list (int, char *[]); -diff --git a/src/kadmin/ktutil/ktutil_ct.ct b/src/kadmin/ktutil/ktutil_ct.ct -index 0c7ccb689..2061ef9d0 100644 ---- a/src/kadmin/ktutil/ktutil_ct.ct -+++ b/src/kadmin/ktutil/ktutil_ct.ct -@@ -32,13 +32,13 @@ request ktutil_clear_list, "Clear the current keylist.", - request ktutil_read_v5, "Read a krb5 keytab into the current keylist.", - read_kt, rkt; - --request ktutil_read_v4, "Read a krb4 srvtab into the current keylist.", -+request ktutil_read_v4, "Deprecated and removed.", - read_st, rst; - - request ktutil_write_v5, "Write the current keylist to a krb5 keytab.", - write_kt, wkt; - --request ktutil_write_v4, "Write the current keylist to a krb4 srvtab.", -+request ktutil_write_v4, "Deprecated and removed.", - write_st, wst; - - request ktutil_add_entry, "Add an entry to the current keylist.", -diff --git a/src/kadmin/ktutil/ktutil_funcs.c b/src/kadmin/ktutil/ktutil_funcs.c -index 6d119a2b6..e2e005d22 100644 ---- a/src/kadmin/ktutil/ktutil_funcs.c -+++ b/src/kadmin/ktutil/ktutil_funcs.c -@@ -368,22 +368,3 @@ krb5_error_code ktutil_write_keytab(context, list, name) - krb5_kt_close(context, kt); - return retval; - } -- --/* -- * Read in a named krb4 srvtab and append to list. Allocate new list -- * if needed. -- */ --krb5_error_code ktutil_read_srvtab(context, name, list) -- krb5_context context; -- char *name; -- krb5_kt_list *list; --{ -- char *ktname; -- krb5_error_code result; -- -- if (asprintf(&ktname, "SRVTAB:%s", name) < 0) -- return ENOMEM; -- result = ktutil_read_keytab(context, ktname, list); -- free(ktname); -- return result; --} -diff --git a/src/kadmin/testing/proto/krb5.conf.proto b/src/kadmin/testing/proto/krb5.conf.proto -index 00c442978..e710852d4 100644 ---- a/src/kadmin/testing/proto/krb5.conf.proto -+++ b/src/kadmin/testing/proto/krb5.conf.proto -@@ -1,6 +1,6 @@ - [libdefaults] - default_realm = __REALM__ -- default_keytab_name = FILE:__K5ROOT__/v5srvtab -+ default_keytab_name = FILE:__K5ROOT__/keytab - dns_fallback = no - plugin_base_dir = __PLUGIN_DIR__ - allow_weak_crypto = true -diff --git a/src/kadmin/testing/scripts/env-setup.shin b/src/kadmin/testing/scripts/env-setup.shin -index 273cf6954..8c29bb996 100755 ---- a/src/kadmin/testing/scripts/env-setup.shin -+++ b/src/kadmin/testing/scripts/env-setup.shin -@@ -79,7 +79,7 @@ export QUALNAME - - KRB5_CONFIG=$K5ROOT/krb5.conf; export KRB5_CONFIG - KRB5_KDC_PROFILE=$K5ROOT/kdc.conf; export KRB5_KDC_PROFILE --KRB5_KTNAME=$K5ROOT/ovsec_adm.srvtab; export KRB5_KTNAME -+KRB5_KTNAME=$K5ROOT/ovsec_adm.keytab; export KRB5_KTNAME - KRB5_CLIENT_KTNAME=$K5ROOT/client_keytab; export KRB5_CLIENT_KTNAME - KRB5CCNAME=$K5ROOT/krb5cc_unit-test; export KRB5CCNAME - -diff --git a/src/kadmin/testing/scripts/init_db b/src/kadmin/testing/scripts/init_db -index c41d290d1..2496be2ab 100755 ---- a/src/kadmin/testing/scripts/init_db -+++ b/src/kadmin/testing/scripts/init_db -@@ -216,7 +216,7 @@ changepw/kerberos@$REALM cil - - EOF - --eval $LOCAL_MAKE_KEYTAB -princ kadmin/admin -princ kadmin/changepw -princ ovsec_adm/admin -princ ovsec_adm/changepw $K5ROOT/ovsec_adm.srvtab $REDIRECT -+eval $LOCAL_MAKE_KEYTAB -princ kadmin/admin -princ kadmin/changepw -princ ovsec_adm/admin -princ ovsec_adm/changepw $K5ROOT/ovsec_adm.keytab $REDIRECT - - # Create $K5ROOT/setup.csh to make it easy to run other programs against - # the test db -diff --git a/src/kadmin/testing/scripts/make-host-keytab.plin b/src/kadmin/testing/scripts/make-host-keytab.plin -index dfe0b3a01..c77d61c70 100755 ---- a/src/kadmin/testing/scripts/make-host-keytab.plin -+++ b/src/kadmin/testing/scripts/make-host-keytab.plin -@@ -11,7 +11,7 @@ $usage = "Usage: $whoami [ -server server ] [ -princ principal ] - Default principals are host/hostname\@SECURE-TEST.OV.COM and - test/hostname\@SECURE-TEST.OV.COM. - If any principals are specified, the default principals are -- not added to the srvtab. -+ not added to the keytab. - The string \"xCANONHOSTx\" in a principal specification will be - replaced by the canonical host name of the local host."; - -diff --git a/src/kadmin/testing/scripts/start_servers_local b/src/kadmin/testing/scripts/start_servers_local -index f34444ee8..e502a6a0b 100755 ---- a/src/kadmin/testing/scripts/start_servers_local -+++ b/src/kadmin/testing/scripts/start_servers_local -@@ -96,9 +96,6 @@ x=$? - rm /tmp/start_servers_local$$ - if test $x != 0 ; then exit 1 ; fi - --# rm -f /etc/v5srvtab --# eval $LOCAL_MAKE_KEYTAB -princ host/xCANONHOSTx /etc/v5srvtab $REDIRECT -- - # run the servers (from the build tree) - - adm_start_file=/tmp/adm_server_start.$$ -diff --git a/src/kprop/kprop.c b/src/kprop/kprop.c -index b7fb63777..0b53aae7e 100644 ---- a/src/kprop/kprop.c -+++ b/src/kprop/kprop.c -@@ -49,7 +49,7 @@ static char *kprop_version = KPROP_PROT_VERSION; - - static char *progname = NULL; - static int debug = 0; --static char *srvtab = NULL; -+static char *keytab_path = NULL; - static char *replica_host; - static char *realm = NULL; - static char *def_realm = NULL; -@@ -83,7 +83,7 @@ static void update_last_prop_file(char *hostname, char *file_name); - static void usage() - { - fprintf(stderr, _("\nUsage: %s [-r realm] [-f file] [-d] [-P port] " -- "[-s srvtab] replica_host\n\n"), progname); -+ "[-s keytab] replica_host\n\n"), progname); - exit(1); - } - -@@ -140,7 +140,7 @@ parse_args(krb5_context context, int argc, char **argv) - port = optarg; - break; - case 's': -- srvtab = optarg; -+ keytab_path = optarg; - break; - default: - usage(); -@@ -191,8 +191,8 @@ get_tickets(krb5_context context) - exit(1); - } - -- if (srvtab != NULL) { -- retval = krb5_kt_resolve(context, srvtab, &keytab); -+ if (keytab_path != NULL) { -+ retval = krb5_kt_resolve(context, keytab_path, &keytab); - if (retval) { - com_err(progname, retval, _("while resolving keytab")); - exit(1); -diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c -index 0c7bffa24..e4aaf553c 100644 ---- a/src/kprop/kpropd.c -+++ b/src/kprop/kpropd.c -@@ -117,7 +117,7 @@ static kadm5_config_params params; - static char *progname; - static int debug = 0; - static int nodaemon = 0; --static char *srvtab = NULL; -+static char *keytab_path = NULL; - static int standalone = 0; - static const char *pid_file = NULL; - -@@ -168,7 +168,7 @@ static void - usage() - { - fprintf(stderr, -- _("\nUsage: %s [-r realm] [-s srvtab] [-dS] [-f replica_file]\n"), -+ _("\nUsage: %s [-r realm] [-s keytab] [-dS] [-f replica_file]\n"), - progname); - fprintf(stderr, _("\t[-F kerberos_db_file ] [-p kdb5_util_pathname]\n")); - fprintf(stderr, _("\t[-x db_args]* [-P port] [-a acl_file]\n")); -@@ -701,7 +701,7 @@ reinit: - iprop_svc_princstr); - } - retval = kadm5_init_with_skey(kpropd_context, iprop_svc_princstr, -- srvtab, -+ keytab_path, - master_svc_princstr, - ¶ms, - KADM5_STRUCT_VERSION, -@@ -1092,7 +1092,7 @@ parse_args(int argc, char **argv) - realm = optarg; - break; - case 's': -- srvtab = optarg; -+ keytab_path = optarg; - break; - case 'D': - nodaemon++; -@@ -1246,8 +1246,8 @@ kerberos_authenticate(krb5_context context, int fd, krb5_principal *clientp, - exit(1); - } - -- if (srvtab != NULL) { -- retval = krb5_kt_resolve(context, srvtab, &keytab); -+ if (keytab_path != NULL) { -+ retval = krb5_kt_resolve(context, keytab_path, &keytab); - if (retval) { - syslog(LOG_ERR, _("Error in krb5_kt_resolve: %s"), - error_message(retval)); -diff --git a/src/lib/kadm5/unit-test/api.current/init.exp b/src/lib/kadm5/unit-test/api.current/init.exp -index d9ae3fbd8..f78261376 100644 ---- a/src/lib/kadm5/unit-test/api.current/init.exp -+++ b/src/lib/kadm5/unit-test/api.current/init.exp -@@ -695,10 +695,10 @@ if {$RPC} { - test45_46 ovsec_adm/changepw - - # re-extract the keytab so it is right -- exec rm $env(K5ROOT)/ovsec_adm.srvtab -+ exec rm $env(K5ROOT)/ovsec_adm.keytab - exec $env(MAKE_KEYTAB) -princ ovsec_adm/admin -princ ovsec_adm/changepw \ - -princ kadmin/admin -princ kadmin/changepw \ -- $env(K5ROOT)/ovsec_adm.srvtab -+ $env(K5ROOT)/ovsec_adm.keytab - } - - return "" -diff --git a/src/lib/krb5/keytab/Makefile.in b/src/lib/krb5/keytab/Makefile.in -index 2a8fceb00..4621bf714 100644 ---- a/src/lib/krb5/keytab/Makefile.in -+++ b/src/lib/krb5/keytab/Makefile.in -@@ -14,7 +14,6 @@ STLIBOBJS= \ - ktfns.o \ - kt_file.o \ - kt_memory.o \ -- kt_srvtab.o \ - read_servi.o - - OBJS= \ -@@ -26,7 +25,6 @@ OBJS= \ - $(OUTPRE)ktfns.$(OBJEXT) \ - $(OUTPRE)kt_file.$(OBJEXT) \ - $(OUTPRE)kt_memory.$(OBJEXT) \ -- $(OUTPRE)kt_srvtab.$(OBJEXT) \ - $(OUTPRE)read_servi.$(OBJEXT) - - SRCS= \ -@@ -38,7 +36,6 @@ SRCS= \ - $(srcdir)/ktfns.c \ - $(srcdir)/kt_file.c \ - $(srcdir)/kt_memory.c \ -- $(srcdir)/kt_srvtab.c \ - $(srcdir)/read_servi.c - - EXTRADEPSRCS= \ -diff --git a/src/lib/krb5/keytab/deps b/src/lib/krb5/keytab/deps -index 4c98188ca..522cad0e8 100644 ---- a/src/lib/krb5/keytab/deps -+++ b/src/lib/krb5/keytab/deps -@@ -87,17 +87,6 @@ kt_memory.so kt_memory.po $(OUTPRE)kt_memory.$(OBJEXT): \ - $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ - $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ - kt-int.h kt_memory.c --kt_srvtab.so kt_srvtab.po $(OUTPRE)kt_srvtab.$(OBJEXT): \ -- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ -- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- kt_srvtab.c - read_servi.so read_servi.po $(OUTPRE)read_servi.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -diff --git a/src/lib/krb5/keytab/kt_srvtab.c b/src/lib/krb5/keytab/kt_srvtab.c -deleted file mode 100644 -index bbfaadfc2..000000000 ---- a/src/lib/krb5/keytab/kt_srvtab.c -+++ /dev/null -@@ -1,435 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* lib/krb5/keytab/kt_srvtab.c */ --/* -- * Copyright 1990,1991,2002,2007,2008 by the Massachusetts Institute of Technology. -- * All Rights Reserved. -- * -- * Export of this software from the United States of America may -- * require a specific license from the United States Government. -- * It is the responsibility of any person or organization contemplating -- * export to obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of M.I.T. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. Furthermore if you modify this software you must label -- * your software as modified software and not distribute it in such a -- * fashion that it might be confused with the original M.I.T. software. -- * M.I.T. makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- */ --/* -- * Copyright (c) Hewlett-Packard Company 1991 -- * Released to the Massachusetts Institute of Technology for inclusion -- * in the Kerberos source code distribution. -- * -- * Copyright 1990,1991 by the Massachusetts Institute of Technology. -- * All Rights Reserved. -- * -- * Export of this software from the United States of America may -- * require a specific license from the United States Government. -- * It is the responsibility of any person or organization contemplating -- * export to obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of M.I.T. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. Furthermore if you modify this software you must label -- * your software as modified software and not distribute it in such a -- * fashion that it might be confused with the original M.I.T. software. -- * M.I.T. makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- */ -- --#include "k5-int.h" --#include -- --#ifndef LEAN_CLIENT -- --/* -- * Constants -- */ -- --#define KRB5_KT_VNO_1 0x0501 /* krb v5, keytab version 1 (DCE compat) */ --#define KRB5_KT_VNO 0x0502 /* krb v5, keytab version 2 (standard) */ -- --#define KRB5_KT_DEFAULT_VNO KRB5_KT_VNO -- --/* -- * Types -- */ --typedef struct _krb5_ktsrvtab_data { -- char *name; /* Name of the file */ -- FILE *openf; /* open file, if any. */ --} krb5_ktsrvtab_data; -- --/* -- * Macros -- */ --#define KTPRIVATE(id) ((krb5_ktsrvtab_data *)(id)->data) --#define KTFILENAME(id) (((krb5_ktsrvtab_data *)(id)->data)->name) --#define KTFILEP(id) (((krb5_ktsrvtab_data *)(id)->data)->openf) -- --extern const struct _krb5_kt_ops krb5_kts_ops; -- --static krb5_error_code KRB5_CALLCONV --krb5_ktsrvtab_resolve(krb5_context, const char *, krb5_keytab *); -- --static krb5_error_code KRB5_CALLCONV --krb5_ktsrvtab_get_name(krb5_context, krb5_keytab, char *, unsigned int); -- --static krb5_error_code KRB5_CALLCONV --krb5_ktsrvtab_close(krb5_context, krb5_keytab); -- --static krb5_error_code KRB5_CALLCONV --krb5_ktsrvtab_get_entry(krb5_context, krb5_keytab, krb5_const_principal, -- krb5_kvno, krb5_enctype, krb5_keytab_entry *); -- --static krb5_error_code KRB5_CALLCONV --krb5_ktsrvtab_start_seq_get(krb5_context, krb5_keytab, krb5_kt_cursor *); -- --static krb5_error_code KRB5_CALLCONV --krb5_ktsrvtab_get_next(krb5_context, krb5_keytab, krb5_keytab_entry *, -- krb5_kt_cursor *); -- --static krb5_error_code KRB5_CALLCONV --krb5_ktsrvtab_end_get(krb5_context, krb5_keytab, krb5_kt_cursor *); -- --static krb5_error_code --krb5_ktsrvint_open(krb5_context, krb5_keytab); -- --static krb5_error_code --krb5_ktsrvint_close(krb5_context, krb5_keytab); -- --static krb5_error_code --krb5_ktsrvint_read_entry(krb5_context, krb5_keytab, krb5_keytab_entry *); -- --/* -- * This is an implementation specific resolver. It returns a keytab id -- * initialized with srvtab keytab routines. -- */ -- --static krb5_error_code KRB5_CALLCONV --krb5_ktsrvtab_resolve(krb5_context context, const char *name, krb5_keytab *id) --{ -- krb5_ktsrvtab_data *data; -- -- if ((*id = (krb5_keytab) malloc(sizeof(**id))) == NULL) -- return(ENOMEM); -- -- (*id)->ops = &krb5_kts_ops; -- data = (krb5_ktsrvtab_data *)malloc(sizeof(krb5_ktsrvtab_data)); -- if (data == NULL) { -- free(*id); -- return(ENOMEM); -- } -- -- data->name = strdup(name); -- if (data->name == NULL) { -- free(data); -- free(*id); -- return(ENOMEM); -- } -- -- data->openf = 0; -- -- (*id)->data = (krb5_pointer)data; -- (*id)->magic = KV5M_KEYTAB; -- return(0); --} -- --/* -- * "Close" a file-based keytab and invalidate the id. This means -- * free memory hidden in the structures. -- */ -- --krb5_error_code KRB5_CALLCONV --krb5_ktsrvtab_close(krb5_context context, krb5_keytab id) --/* -- * This routine is responsible for freeing all memory allocated -- * for this keytab. There are no system resources that need -- * to be freed nor are there any open files. -- * -- * This routine should undo anything done by krb5_ktsrvtab_resolve(). -- */ --{ -- free(KTFILENAME(id)); -- free(id->data); -- id->ops = 0; -- free(id); -- return (0); --} -- --/* -- * This is the get_entry routine for the file based keytab implementation. -- * It opens the keytab file, and either retrieves the entry or returns -- * an error. -- */ -- --krb5_error_code KRB5_CALLCONV --krb5_ktsrvtab_get_entry(krb5_context context, krb5_keytab id, krb5_const_principal principal, krb5_kvno kvno, krb5_enctype enctype, krb5_keytab_entry *entry) --{ -- krb5_keytab_entry best_entry, ent; -- krb5_error_code kerror = 0; -- int found_wrong_kvno = 0; -- -- /* Open the srvtab. */ -- if ((kerror = krb5_ktsrvint_open(context, id))) -- return(kerror); -- -- /* srvtab files only have DES_CBC_CRC keys. */ -- switch (enctype) { -- case ENCTYPE_DES_CBC_CRC: -- case ENCTYPE_DES_CBC_MD5: -- case ENCTYPE_DES_CBC_MD4: -- case ENCTYPE_DES_CBC_RAW: -- case IGNORE_ENCTYPE: -- break; -- default: -- return KRB5_KT_NOTFOUND; -- } -- -- best_entry.principal = 0; -- best_entry.vno = 0; -- best_entry.key.contents = 0; -- while ((kerror = krb5_ktsrvint_read_entry(context, id, &ent)) == 0) { -- ent.key.enctype = enctype; -- if (krb5_principal_compare(context, principal, ent.principal)) { -- if (kvno == IGNORE_VNO || ent.vno == IGNORE_VNO) { -- if (!best_entry.principal || (best_entry.vno < ent.vno)) { -- krb5_kt_free_entry(context, &best_entry); -- best_entry = ent; -- } -- } else { -- if (ent.vno == kvno) { -- best_entry = ent; -- break; -- } else { -- found_wrong_kvno = 1; -- } -- } -- } else { -- krb5_kt_free_entry(context, &ent); -- } -- } -- if (kerror == KRB5_KT_END) { -- if (best_entry.principal) -- kerror = 0; -- else if (found_wrong_kvno) -- kerror = KRB5_KT_KVNONOTFOUND; -- else -- kerror = KRB5_KT_NOTFOUND; -- } -- if (kerror) { -- (void) krb5_ktsrvint_close(context, id); -- krb5_kt_free_entry(context, &best_entry); -- return kerror; -- } -- if ((kerror = krb5_ktsrvint_close(context, id)) != 0) { -- krb5_kt_free_entry(context, &best_entry); -- return kerror; -- } -- *entry = best_entry; -- return 0; --} -- --/* -- * Get the name of the file containing a srvtab-based keytab. -- */ -- --krb5_error_code KRB5_CALLCONV --krb5_ktsrvtab_get_name(krb5_context context, krb5_keytab id, char *name, unsigned int len) --/* -- * This routine returns the name of the name of the file associated with -- * this srvtab-based keytab. The name is prefixed with PREFIX:, so that -- * trt will happen if the name is passed back to resolve. -- */ --{ -- int result; -- -- memset(name, 0, len); -- result = snprintf(name, len, "%s:%s", id->ops->prefix, KTFILENAME(id)); -- if (SNPRINTF_OVERFLOW(result, len)) -- return(KRB5_KT_NAME_TOOLONG); -- return(0); --} -- --/* -- * krb5_ktsrvtab_start_seq_get() -- */ -- --krb5_error_code KRB5_CALLCONV --krb5_ktsrvtab_start_seq_get(krb5_context context, krb5_keytab id, krb5_kt_cursor *cursorp) --{ -- krb5_error_code retval; -- long *fileoff; -- -- if ((retval = krb5_ktsrvint_open(context, id))) -- return retval; -- -- if (!(fileoff = (long *)malloc(sizeof(*fileoff)))) { -- krb5_ktsrvint_close(context, id); -- return ENOMEM; -- } -- *fileoff = ftell(KTFILEP(id)); -- *cursorp = (krb5_kt_cursor)fileoff; -- -- return 0; --} -- --/* -- * krb5_ktsrvtab_get_next() -- */ -- --krb5_error_code KRB5_CALLCONV --krb5_ktsrvtab_get_next(krb5_context context, krb5_keytab id, krb5_keytab_entry *entry, krb5_kt_cursor *cursor) --{ -- long *fileoff = (long *)*cursor; -- krb5_keytab_entry cur_entry; -- krb5_error_code kerror; -- -- if (fseek(KTFILEP(id), *fileoff, 0) == -1) -- return KRB5_KT_END; -- if ((kerror = krb5_ktsrvint_read_entry(context, id, &cur_entry))) -- return kerror; -- *fileoff = ftell(KTFILEP(id)); -- *entry = cur_entry; -- return 0; --} -- --/* -- * krb5_ktsrvtab_end_get() -- */ -- --krb5_error_code KRB5_CALLCONV --krb5_ktsrvtab_end_get(krb5_context context, krb5_keytab id, krb5_kt_cursor *cursor) --{ -- free(*cursor); -- return krb5_ktsrvint_close(context, id); --} -- --/* -- * krb5_kts_ops -- */ -- --const struct _krb5_kt_ops krb5_kts_ops = { -- 0, -- "SRVTAB", /* Prefix -- this string should not appear anywhere else! */ -- krb5_ktsrvtab_resolve, -- krb5_ktsrvtab_get_name, -- krb5_ktsrvtab_close, -- krb5_ktsrvtab_get_entry, -- krb5_ktsrvtab_start_seq_get, -- krb5_ktsrvtab_get_next, -- krb5_ktsrvtab_end_get, -- 0, -- 0, -- 0 --}; -- --/* formerly: lib/krb5/keytab/srvtab/kts_util.c */ -- --#include -- --/* The maximum sizes for V4 aname, realm, sname, and instance +1 */ --/* Taken from krb.h */ --#define ANAME_SZ 40 --#define REALM_SZ 40 --#define SNAME_SZ 40 --#define INST_SZ 40 -- --static krb5_error_code --read_field(FILE *fp, char *s, int len) --{ -- int c; -- -- while ((c = getc(fp)) != 0) { -- if (c == EOF || len <= 1) -- return KRB5_KT_END; -- *s = c; -- s++; -- len--; -- } -- *s = 0; -- return 0; --} -- --krb5_error_code --krb5_ktsrvint_open(krb5_context context, krb5_keytab id) --{ -- KTFILEP(id) = fopen(KTFILENAME(id), "rb"); -- if (!KTFILEP(id)) -- return errno; -- set_cloexec_file(KTFILEP(id)); -- return 0; --} -- --krb5_error_code --krb5_ktsrvint_close(krb5_context context, krb5_keytab id) --{ -- if (!KTFILEP(id)) -- return 0; -- (void) fclose(KTFILEP(id)); -- KTFILEP(id) = 0; -- return 0; --} -- --krb5_error_code --krb5_ktsrvint_read_entry(krb5_context context, krb5_keytab id, krb5_keytab_entry *ret_entry) --{ -- FILE *fp; -- char name[SNAME_SZ], instance[INST_SZ], realm[REALM_SZ]; -- unsigned char key[8]; -- int vno; -- krb5_error_code kerror; -- -- /* Read in an entry from the srvtab file. */ -- fp = KTFILEP(id); -- kerror = read_field(fp, name, sizeof(name)); -- if (kerror != 0) -- return kerror; -- kerror = read_field(fp, instance, sizeof(instance)); -- if (kerror != 0) -- return kerror; -- kerror = read_field(fp, realm, sizeof(realm)); -- if (kerror != 0) -- return kerror; -- vno = getc(fp); -- if (vno == EOF) -- return KRB5_KT_END; -- if (fread(key, 1, sizeof(key), fp) != sizeof(key)) -- return KRB5_KT_END; -- -- /* Fill in ret_entry with the data we read. Everything maps well -- * except for the timestamp, which we don't have a value for. For -- * now we just set it to 0. */ -- memset(ret_entry, 0, sizeof(*ret_entry)); -- ret_entry->magic = KV5M_KEYTAB_ENTRY; -- kerror = krb5_425_conv_principal(context, name, instance, realm, -- &ret_entry->principal); -- if (kerror != 0) -- return kerror; -- ret_entry->vno = vno; -- ret_entry->timestamp = 0; -- ret_entry->key.enctype = ENCTYPE_DES_CBC_CRC; -- ret_entry->key.magic = KV5M_KEYBLOCK; -- ret_entry->key.length = sizeof(key); -- ret_entry->key.contents = k5memdup(key, sizeof(key), &kerror); -- if (ret_entry->key.contents == NULL) { -- krb5_free_principal(context, ret_entry->principal); -- return kerror; -- } -- -- return 0; --} --#endif /* LEAN_CLIENT */ -diff --git a/src/lib/krb5/keytab/ktbase.c b/src/lib/krb5/keytab/ktbase.c -index 0d39b2940..25752245a 100644 ---- a/src/lib/krb5/keytab/ktbase.c -+++ b/src/lib/krb5/keytab/ktbase.c -@@ -55,20 +55,15 @@ - - extern const krb5_kt_ops krb5_ktf_ops; - extern const krb5_kt_ops krb5_ktf_writable_ops; --extern const krb5_kt_ops krb5_kts_ops; - extern const krb5_kt_ops krb5_mkt_ops; - - struct krb5_kt_typelist { - const krb5_kt_ops *ops; - const struct krb5_kt_typelist *next; - }; --const static struct krb5_kt_typelist krb5_kt_typelist_srvtab = { -- &krb5_kts_ops, -- NULL --}; - const static struct krb5_kt_typelist krb5_kt_typelist_memory = { - &krb5_mkt_ops, -- &krb5_kt_typelist_srvtab -+ NULL - }; - const static struct krb5_kt_typelist krb5_kt_typelist_wrfile = { - &krb5_ktf_writable_ops, -diff --git a/src/lib/krb5/krb/in_tkt_sky.c b/src/lib/krb5/krb/in_tkt_sky.c -index 7a8922623..342fe18dc 100644 ---- a/src/lib/krb5/krb/in_tkt_sky.c -+++ b/src/lib/krb5/krb/in_tkt_sky.c -@@ -56,9 +56,9 @@ get_as_key_skey(krb5_context context, krb5_principal client, - If addrs is non-NULL, it is used for the addresses requested. If it is - null, the system standard addresses are used. - -- If keyblock is NULL, an appropriate key for creds->client is retrieved -- from the system key store (e.g. /etc/srvtab). If keyblock is non-NULL, -- it is used as the decryption key. -+ If keyblock is NULL, an appropriate key for creds->client is retrieved from -+ the system key store (e.g. /etc/krb5.keytab). If keyblock is non-NULL, it -+ is used as the decryption key. - - A succesful call will place the ticket in the credentials cache ccache. - -diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports -index dfdb72daf..038e4de4b 100644 ---- a/src/lib/krb5/libkrb5.exports -+++ b/src/lib/krb5/libkrb5.exports -@@ -459,7 +459,6 @@ krb5_kt_resolve - krb5_kt_start_seq_get - krb5_ktf_ops - krb5_ktf_writable_ops --krb5_kts_ops - krb5_kuserok - krb5_lock_file - krb5_make_authdata_kdc_issued -diff --git a/src/lib/rpc/unit-test/Makefile.in b/src/lib/rpc/unit-test/Makefile.in -index 6f29e33c9..46f2f1d4b 100644 ---- a/src/lib/rpc/unit-test/Makefile.in -+++ b/src/lib/rpc/unit-test/Makefile.in -@@ -45,8 +45,8 @@ PASS=@PASS@ - unit-test-body: - $(RM) krb5cc_rpc_test_* - $(ENV_SETUP) $(VALGRIND) $(START_SERVERS) -- RPC_TEST_SRVTAB=/tmp/rpc_test_v5srvtab.$$$$ ; export RPC_TEST_SRVTAB ; \ -- trap "echo Failed, cleaning up... ; rm -f $$RPC_TEST_SRVTAB ; $(ENV_SETUP) $(STOP_SERVERS) ; trap '' 0 ; exit 1" 0 1 2 3 14 15 ; \ -+ RPC_TEST_KEYTAB=/tmp/rpc_test_keytab.$$$$ ; export RPC_TEST_KEYTAB ; \ -+ trap "echo Failed, cleaning up... ; rm -f $$RPC_TEST_KEYTAB ; $(ENV_SETUP) $(STOP_SERVERS) ; trap '' 0 ; exit 1" 0 1 2 3 14 15 ; \ - if $(ENV_SETUP) \ - $(RUNTEST) SERVER=./server CLIENT=./client \ - KINIT=$(BUILDTOP)/clients/kinit/kinit \ -@@ -55,7 +55,7 @@ unit-test-body: - PASS="$(PASS)" --tool rpc_test $(RUNTESTFLAGS) ; \ - then \ - echo Cleaning up... ; \ -- rm -f $$RPC_TEST_SRVTAB krb5cc_rpc_test_* ; \ -+ rm -f $$RPC_TEST_KEYTAB krb5cc_rpc_test_* ; \ - $(ENV_SETUP) $(STOP_SERVERS) ; \ - trap 0 ; exit 0 ; \ - else exit 1 ; fi -diff --git a/src/lib/rpc/unit-test/config/unix.exp b/src/lib/rpc/unit-test/config/unix.exp -index ba57b703e..ed179bbe3 100644 ---- a/src/lib/rpc/unit-test/config/unix.exp -+++ b/src/lib/rpc/unit-test/config/unix.exp -@@ -139,7 +139,7 @@ proc rpc_test_start { } { - - if [info exists server_pid] { rpc_test_exit } - -- set env(KRB5_KTNAME) FILE:$env(RPC_TEST_SRVTAB) -+ set env(KRB5_KTNAME) FILE:$env(RPC_TEST_KEYTAB) - - verbose "% $SERVER" 1 - set server_pid [spawn $SERVER $PROT] -diff --git a/src/lib/rpc/unit-test/lib/helpers.exp b/src/lib/rpc/unit-test/lib/helpers.exp -index a7f89f636..f08c73201 100644 ---- a/src/lib/rpc/unit-test/lib/helpers.exp -+++ b/src/lib/rpc/unit-test/lib/helpers.exp -@@ -121,8 +121,8 @@ proc setup_database {} { - if ![info exists CANON_HOST] { - set CANON_HOST $env(QUALNAME) - setup_database -- file delete $env(RPC_TEST_SRVTAB) -- exec $env(MAKE_KEYTAB) -princ "server/$CANON_HOST" $env(RPC_TEST_SRVTAB) -+ file delete $env(RPC_TEST_KEYTAB) -+ exec $env(MAKE_KEYTAB) -princ "server/$CANON_HOST" $env(RPC_TEST_KEYTAB) - } - - -diff --git a/src/lib/rpc/unit-test/rpc_test_setup.sh b/src/lib/rpc/unit-test/rpc_test_setup.sh -index d147a337e..d7df0eb2b 100755 ---- a/src/lib/rpc/unit-test/rpc_test_setup.sh -+++ b/src/lib/rpc/unit-test/rpc_test_setup.sh -@@ -1,7 +1,7 @@ - #!/bin/sh - # - # This script performs additional setup for the RPC unit test. It --# assumes that gmake has put TOP and RPC_TEST_SRVTAB into the -+# assumes that gmake has put TOP and RPC_TEST_KEYTAB into the - # environment. - # - # $Id$ -@@ -39,9 +39,9 @@ if test $? != 0 ; then - fi - rm /tmp/rpc_test_setup$$ - --rm -f $RPC_TEST_SRVTAB -+rm -f $RPC_TEST_KEYTAB - --eval $MAKE_KEYTAB -princ server/$CANON_HOST $RPC_TEST_SRVTAB $REDIRECT -+eval $MAKE_KEYTAB -princ server/$CANON_HOST $RPC_TEST_KEYTAB $REDIRECT - - # grep -s "$CANON_HOST SECURE-TEST.OV.COM" /etc/krb.realms - # if [ $? != 0 ]; then -diff --git a/src/man/ktutil.man b/src/man/ktutil.man -index 711a0ed2c..233329468 100644 ---- a/src/man/ktutil.man -+++ b/src/man/ktutil.man -@@ -1,6 +1,6 @@ - .\" Man page generated from reStructuredText. - . --.TH "KTUTIL" "1" " " "1.17.1" "MIT Kerberos" -+.TH "KTUTIL" "1" " " "1.18" "MIT Kerberos" - .SH NAME - ktutil \- Kerberos keytab file maintenance utility - . -@@ -36,8 +36,8 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]] - .SH DESCRIPTION - .sp - The ktutil command invokes a command interface from which an --administrator can read, write, or edit entries in a keytab or Kerberos --V4 srvtab file. -+administrator can read, write, or edit entries in a keytab. (Kerberos -+V4 srvtab files are no longer supported.) - .SH COMMANDS - .SS list - .INDENT 0.0 -@@ -59,16 +59,6 @@ Alias: \fBl\fP - Read the Kerberos V5 keytab file \fIkeytab\fP into the current keylist. - .sp - Alias: \fBrkt\fP --.SS read_st --.INDENT 0.0 --.INDENT 3.5 --\fBread_st\fP \fIsrvtab\fP --.UNINDENT --.UNINDENT --.sp --Read the Kerberos V4 srvtab file \fIsrvtab\fP into the current keylist. --.sp --Alias: \fBrst\fP - .SS write_kt - .INDENT 0.0 - .INDENT 3.5 -@@ -79,16 +69,6 @@ Alias: \fBrst\fP - Write the current keylist into the Kerberos V5 keytab file \fIkeytab\fP\&. - .sp - Alias: \fBwkt\fP --.SS write_st --.INDENT 0.0 --.INDENT 3.5 --\fBwrite_st\fP \fIsrvtab\fP --.UNINDENT --.UNINDENT --.sp --Write the current keylist into the Kerberos V4 srvtab file \fIsrvtab\fP\&. --.sp --Alias: \fBwst\fP - .SS clear_list - .INDENT 0.0 - .INDENT 3.5 -diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp -index d7b296516..ea9bedd45 100644 ---- a/src/tests/dejagnu/config/default.exp -+++ b/src/tests/dejagnu/config/default.exp -@@ -440,8 +440,8 @@ proc delete_db {} { - $tmppwd/kdc-db.ulog \ - $tmppwd/replica-db $tmppwd/replica-db.ok $tmppwd/replica-db.kadm5 $tmppwd/replica-db.kadm5.lock \ - $tmppwd/replica-db~ $tmppwd/replica-db~.ok $tmppwd/replica-db~.kadm5 $tmppwd/replica-db~.kadm5.lock -- # Creating a new database means we need a new srvtab. -- file delete $tmppwd/srvtab $tmppwd/cpw_srvtab -+ # Creating a new database means we need a new keytab. -+ file delete $tmppwd/keytab $tmppwd/cpw_keytab - } - - delete_db -@@ -1510,11 +1510,9 @@ proc start_kpropd {} { - - envstack_push - setup_kerberos_env replica -- spawn $KPROPD -S -d -t -P [expr 10 + $portbase] -s $tmppwd/srvtab -f $tmppwd/incoming-replica-datatrans -p $KDB5_UTIL -a $tmppwd/kpropd-acl -+ spawn $KPROPD -S -d -t -P [expr 10 + $portbase] -s $tmppwd/keytab -f $tmppwd/incoming-replica-datatrans -p $KDB5_UTIL -a $tmppwd/kpropd-acl - set kpropd_pid [exp_pid] - set kpropd_spawn_id $spawn_id --# send_user [list $KPROPD -S -d -P [expr 10 + $portbase] -s $tmppwd/srvtab -f $tmppwd/incoming-replica-datatrans -p $KDB5_UTIL -a $tmppwd/kpropd-acl]\n --# spawn_shell - envstack_pop - } - -@@ -1859,13 +1857,13 @@ proc add_random_key { kkey standalone } { - } - } - --# setup_srvtab --# Set up a srvtab file. start_kerberos_daemons and add_random_key -+# setup_keytab -+# Set up a keytab file. start_kerberos_daemons and add_random_key - # $id/$hostname must be called before this procedure. If the - # argument is non-zero, call pass at relevant points. Returns 1 on - # success, 0 on failure. If the id field is not provided, host is used. - --proc setup_srvtab { standalone {id host} } { -+proc setup_keytab { standalone {id host} } { - global REALMNAME - global KADMIN_LOCAL - global KEY -@@ -1874,17 +1872,17 @@ proc setup_srvtab { standalone {id host} } { - global spawn_id - global last_service - -- if {!$standalone && [file exists $tmppwd/srvtab] && $last_service == $id} { -+ if {!$standalone && [file exists $tmppwd/keytab] && $last_service == $id} { - return 1 - } - -- file delete $tmppwd/srvtab $tmppwd/srvtab.old -+ file delete $tmppwd/keytab $tmppwd/keytab.old - - if ![get_hostname] { - return 0 - } - -- file delete $hostname-new-srvtab -+ file delete $hostname-new-keytab - - envstack_push - setup_kerberos_env kdc -@@ -1892,40 +1890,40 @@ proc setup_srvtab { standalone {id host} } { - envstack_pop - expect_after { - -re "(.*)\r\nkadmin.local: " { -- fail "kadmin.local srvtab (unmatched output: $expect_out(1,string))" -+ fail "kadmin.local keytab (unmatched output: $expect_out(1,string))" - if {!$standalone} { -- file delete $tmppwd/srvtab -+ file delete $tmppwd/keytab - } - catch "expect_after" - return 0 - } - timeout { -- fail "kadmin.local srvtab" -+ fail "kadmin.local keytab" - if {!$standalone} { -- file delete $tmppwd/srvtab -+ file delete $tmppwd/keytab - } - catch "expect_after" - return 0 - } - eof { -- fail "kadmin.local srvtab" -+ fail "kadmin.local keytab" - if {!$standalone} { -- file delete $tmppwd/srvtab -+ file delete $tmppwd/keytab - } - catch "expect_after" - return 0 - } - } - expect "kadmin.local: " -- send "xst -k $hostname-new-srvtab $id/$hostname kiprop/$hostname\r" -- expect "xst -k $hostname-new-srvtab $id/$hostname kiprop/$hostname\r\n" -+ send "xst -k $hostname-new-keytab $id/$hostname kiprop/$hostname\r" -+ expect "xst -k $hostname-new-keytab $id/$hostname kiprop/$hostname\r\n" - expect { -- -re ".*Entry for principal $id/$hostname.* added to keytab WRFILE:$hostname-new-srvtab." { } -+ -re ".*Entry for principal $id/$hostname.* added to keytab WRFILE:$hostname-new-keytab." { } - -re "\r\nkadmin.local: " { - if {$standalone} { -- fail "kadmin.local srvtab" -+ fail "kadmin.local keytab" - } else { -- file delete $tmppwd/srvtab -+ file delete $tmppwd/keytab - } - catch expect_after - return 0 -@@ -1935,27 +1933,27 @@ proc setup_srvtab { standalone {id host} } { - send "quit\r" - expect eof - catch expect_after -- if ![check_exit_status "kadmin.local srvtab"] { -+ if ![check_exit_status "kadmin.local keytab"] { - if {!$standalone} { -- file delete $tmppwd/srvtab -+ file delete $tmppwd/keytab - } - return 0 - } - -- catch "exec mv -f $hostname-new-srvtab $tmppwd/srvtab" exec_output -+ catch "exec mv -f $hostname-new-keytab $tmppwd/keytab" exec_output - if ![string match "" $exec_output] { - verbose -log "$exec_output" -- perror "can't mv new srvtab" -+ perror "can't mv new keytab" - return 0 - } - - if {$standalone} { -- pass "kadmin.local srvtab" -+ pass "kadmin.local keytab" - } - -- # Make the srvtab file globally readable in case we are using a -- # root shell and the srvtab is NFS mounted. -- catch "exec chmod a+r $tmppwd/srvtab" -+ # Make the keytab file globally readable in case we are using a -+ # root shell and the keytab is NFS mounted. -+ catch "exec chmod a+r $tmppwd/keytab" - - # Remember what we just extracted - set last_service $id -diff --git a/src/tests/dejagnu/krb-standalone/gssapi.exp b/src/tests/dejagnu/krb-standalone/gssapi.exp -index 582e08719..e3357e769 100644 ---- a/src/tests/dejagnu/krb-standalone/gssapi.exp -+++ b/src/tests/dejagnu/krb-standalone/gssapi.exp -@@ -238,9 +238,9 @@ proc doit { } { - perror "failed to set up gssservice/$hostname key" - } - -- # Use kdb5_edit to create a srvtab entry for gssservice -- if ![setup_srvtab 0 gssservice] { -- perror "failed to set up gssservice srvtab" -+ # Use kdb5_edit to create a keytab entry for gssservice -+ if ![setup_keytab 0 gssservice] { -+ perror "failed to set up gssservice keytab" - } - - catch "exec rm -f $tmppwd/gss_tk_0 $tmppwd/gss_tk_1 $tmppwd/gss_tk_2 $tmppwd/gss_tk_3" -@@ -278,7 +278,7 @@ proc doit { } { - # - # set KRB5CCNAME and KRB5_KTNAME - # -- set env(KRB5_KTNAME) FILE:$tmppwd/srvtab -+ set env(KRB5_KTNAME) FILE:$tmppwd/keytab - verbose "KRB5_KTNAME=$env(KRB5_KTNAME)" - - # Now start the gss-server. -diff --git a/src/tests/dejagnu/krb-standalone/kadmin.exp b/src/tests/dejagnu/krb-standalone/kadmin.exp -index 33fc34a7b..36a345258 100644 ---- a/src/tests/dejagnu/krb-standalone/kadmin.exp -+++ b/src/tests/dejagnu/krb-standalone/kadmin.exp -@@ -457,62 +457,16 @@ proc kadmin_extract { instance name } { - expect -re "assword\[^\r\n\]*: *" { - send "adminpass$KEY\r" - } --# expect -re "kadmin: Entry for principal $name/$instance with kvno [0-9], encryption type .* added to keytab WRFILE:$tmppwd/keytab." - expect_after - expect eof - set k_stat [wait -i $spawn_id] - verbose "wait -i $spawn_id returned $k_stat (kadmin xst)" - catch "close -i $spawn_id" -- catch "exec rm -f $instance-new-srvtab" -+ catch "exec rm -f $instance-new-keytab" - pass "kadmin xst $instance $name" - return 1 - } - --#++ --# kadmin_extractv4 - Test extract service key in v4 format function of --# kadmin. --# --# Extracts service key for service name $name instance $instance in version --# 4 format. Returns 1 on success. --#-- --#proc kadmin_extractv4 { instance name } { --# global REALMNAME --# global KADMIN --# global KEY --# global spawn_id --# --# spawn $KADMIN -p krbtest/admin@$REALMNAME -q "xst4 $instance $name" --# expect_after { --# "Cannot contact any KDC" { --# fail "kadmin xst4 $instance $name lost KDC" --# catch "expect_after" --# return 0 --# } --# timeout { --# fail "kadmin xst4 $instance $name" --# catch "expect_after" --# return 0 --# } --# eof { --# fail "kadmin xst4 $instance $name" --# catch "expect_after" --# return 0 --# } --# } --# expect -re "assword\[^\r\n\]*: *" { --# send "adminpass$KEY\r" --# } --# expect "extracted entry $name to key table $instance-new-v4-srvtab" --# expect_after --# expect eof --# set k_stat [wait -i $spawn_id] --# verbose "wait -i $spawn_id returned $k_stat (kadmin xst4)" --# catch "close -i $spawn_id" --# catch "exec rm -f $instance-new-v4-srvtab" --# pass "kadmin xst4 $instance $name" --# return 1 --#} -- - #++ - # kadmin_delete - Test delete principal function of kadmin. - # -diff --git a/src/tests/dejagnu/krb-standalone/kprop.exp b/src/tests/dejagnu/krb-standalone/kprop.exp -index 2221a65e4..f71ee8638 100644 ---- a/src/tests/dejagnu/krb-standalone/kprop.exp -+++ b/src/tests/dejagnu/krb-standalone/kprop.exp -@@ -72,8 +72,8 @@ proc doit { } { - fail "kprop (host key)" - return - } -- if ![setup_srvtab 0] { -- fail "kprop (srvtab)" -+ if ![setup_keytab 0] { -+ fail "kprop (keytab)" - return - } - -@@ -99,7 +99,7 @@ proc doit { } { - sleep 1 - - # Try a propagation. -- spawn $KPROP -f $tmppwd/replica_datatrans -P [expr 10 + $portbase] -s $tmppwd/srvtab $hostname -+ spawn $KPROP -f $tmppwd/replica_datatrans -P [expr 10 + $portbase] -s $tmppwd/keytab $hostname - expect eof - set kprop_exit [check_exit_status "kprop (exit status)"] - # log output for debugging -diff --git a/src/tests/dejagnu/krb-standalone/sample.exp b/src/tests/dejagnu/krb-standalone/sample.exp -index 326f1848d..93a75f1d0 100644 ---- a/src/tests/dejagnu/krb-standalone/sample.exp -+++ b/src/tests/dejagnu/krb-standalone/sample.exp -@@ -42,7 +42,7 @@ proc start_sserver_daemon { inetd } { - # if inetd = 0, then we are running stand-alone - if !{$inetd} { - # Start the sserver -- spawn $SSERVER -p [expr 8 + $portbase] -S $tmppwd/srvtab -+ spawn $SSERVER -p [expr 8 + $portbase] -S $tmppwd/keytab - set sserver_pid [exp_pid] - set sserver_spawn_id $spawn_id - -@@ -52,7 +52,7 @@ proc start_sserver_daemon { inetd } { - sleep 2 - } else { - # Start the sserver -- spawn $T_INETD [expr 8 + $portbase] $SSERVER sserver -S $tmppwd/srvtab -+ spawn $T_INETD [expr 8 + $portbase] $SSERVER sserver -S $tmppwd/keytab - set sserver_pid [exp_pid] - set sserver_spawn_id $spawn_id - -@@ -166,8 +166,8 @@ proc doit { } { - return - } - -- # Use ksrvutil to create a srvtab entry for sample -- if ![setup_srvtab 1 sample] { -+ # Use ksrvutil to create a keytab entry for sample -+ if ![setup_keytab 1 sample] { - return - } - -diff --git a/src/tests/dejagnu/krb-standalone/simple.exp b/src/tests/dejagnu/krb-standalone/simple.exp -index fa749035f..d8b218248 100644 ---- a/src/tests/dejagnu/krb-standalone/simple.exp -+++ b/src/tests/dejagnu/krb-standalone/simple.exp -@@ -40,7 +40,7 @@ proc start_sim_server_daemon { } { - global portbase - - # Start the sim_server -- spawn $SIM_SERVER -p [expr 8 + $portbase] -S $tmppwd/srvtab -+ spawn $SIM_SERVER -p [expr 8 + $portbase] -S $tmppwd/keytab - set sim_server_pid [exp_pid] - set sim_server_spawn_id $spawn_id - -@@ -179,8 +179,8 @@ proc doit { } { - return - } - -- # Use ksrvutil to create a srvtab entry for sample -- if ![setup_srvtab 1 sample] { -+ # Use ksrvutil to create a keytab entry for sample -+ if ![setup_keytab 1 sample] { - return - } - -diff --git a/src/tests/dejagnu/krb-standalone/standalone.exp b/src/tests/dejagnu/krb-standalone/standalone.exp -index 5b5970fba..d284297e8 100644 ---- a/src/tests/dejagnu/krb-standalone/standalone.exp -+++ b/src/tests/dejagnu/krb-standalone/standalone.exp -@@ -166,8 +166,8 @@ proc doit { } { - verbose "wait -i $spawn_id returned $k_stat (kadmin addpol)" - catch "close -i $spawn_id" - -- # Use ksrvutil to create a srvtab entry. -- if ![setup_srvtab 1] { -+ # Use ksrvutil to create a keytab entry. -+ if ![setup_keytab 1] { - return - } - -diff --git a/src/tests/dejagnu/krb-standalone/tcp.exp b/src/tests/dejagnu/krb-standalone/tcp.exp -index db09b895e..df3195bb6 100644 ---- a/src/tests/dejagnu/krb-standalone/tcp.exp -+++ b/src/tests/dejagnu/krb-standalone/tcp.exp -@@ -33,11 +33,6 @@ proc doit { } { - return - } - -- # Use ksrvutil to create a srvtab entry. --# if ![setup_srvtab 1] { --# return --# } -- - # Use kinit to get a ticket. - if ![kinit krbtest/admin adminpass$KEY 1] { - return diff --git a/Remove-strerror-calls-from-k5_get_error.patch b/Remove-strerror-calls-from-k5_get_error.patch deleted file mode 100644 index a46ccdc..0000000 --- a/Remove-strerror-calls-from-k5_get_error.patch +++ /dev/null @@ -1,34 +0,0 @@ -From 128098be731775ecc2a5de6308868fae78059db9 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 6 Jun 2019 11:46:58 -0400 -Subject: [PATCH] Remove strerror() calls from k5_get_error() - -Coverity models strerror() as a function which cannot accept negative -values, even though it has defined behavior on all integers. -k5_get_error() contains code to call strerror_r() and strerror() if -its fptr global is unset, which isn't an expected case in practice. -To silence a large number of Coverity false positives, just return a -fixed string if fptr is null. - -(cherry picked from commit 2d400bea7a81a5a834a1be6ded439f18e0afa5ba) ---- - src/util/support/errors.c | 5 ++--- - 1 file changed, 2 insertions(+), 3 deletions(-) - -diff --git a/src/util/support/errors.c b/src/util/support/errors.c -index 70e1d59d0..f8bea07a3 100644 ---- a/src/util/support/errors.c -+++ b/src/util/support/errors.c -@@ -78,10 +78,9 @@ k5_get_error(struct errinfo *ep, long code) - - lock(); - if (fptr == NULL) { -+ /* Should be rare; fptr should be set whenever libkrb5 is loaded. */ - unlock(); -- if (strerror_r(code, buf, sizeof(buf)) == 0) -- return oom_check(strdup(buf)); -- return oom_check(strdup(strerror(code))); -+ return oom_check(strdup(_("Error code translation unavailable"))); - } - r = fptr(code); - #ifndef HAVE_COM_ERR_INTL diff --git a/Remove-support-for-no-flags-SAM-2-preauth.patch b/Remove-support-for-no-flags-SAM-2-preauth.patch deleted file mode 100644 index c7c1afb..0000000 --- a/Remove-support-for-no-flags-SAM-2-preauth.patch +++ /dev/null @@ -1,73 +0,0 @@ -From c00274de6de883d74ae231405b6ae5e1486712c9 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 17 Apr 2019 17:07:46 -0400 -Subject: [PATCH] Remove support for no-flags SAM-2 preauth - -When neither the send-encrypted-sad nor the use-sad-as-key flag is set -in the SAM-2 challenge, the protocol calls for the AS key to be -combined with the string-to-key of the SAD using a key combination -method which has only been implemented for DES and 3DES enctypes. -Rather than extending key combination, remove support for this case. - -[ghudson@mit.edu: rewrote commit message, added comment] - -ticket: 8812 (new) -(cherry picked from commit c30e0af224ef3716513744fd86aec3eeea90abf9) ---- - src/lib/krb5/krb/preauth_sam2.c | 40 +++++++++------------------------ - 1 file changed, 11 insertions(+), 29 deletions(-) - -diff --git a/src/lib/krb5/krb/preauth_sam2.c b/src/lib/krb5/krb/preauth_sam2.c -index c7484c47e..fda86bee2 100644 ---- a/src/lib/krb5/krb/preauth_sam2.c -+++ b/src/lib/krb5/krb/preauth_sam2.c -@@ -211,38 +211,20 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata, - /* Get encryption key to be used for checksum and sam_response */ - if (!(sc2b->sam_flags & KRB5_SAM_USE_SAD_AS_KEY)) { - /* Retain as_key from above gak_fct call. */ -- -- if (!(sc2b->sam_flags & KRB5_SAM_SEND_ENCRYPTED_SAD)) { -- /* as_key = combine_key (as_key, string_to_key(SAD)) */ -- krb5_keyblock tmp_kb; -- -- retval = krb5_c_string_to_key(context, sc2b->sam_etype, -- &response_data, salt, &tmp_kb); -- -- if (retval) { -- krb5_free_sam_challenge_2(context, sc2); -- krb5_free_sam_challenge_2_body(context, sc2b); -- if (defsalt.length) free(defsalt.data); -- return(retval); -- } -- -- /* This should be a call to the crypto library some day */ -- /* key types should already match the sam_etype */ -- retval = krb5int_c_combine_keys(context, &ctx->as_key, &tmp_kb, -- &ctx->as_key); -- -- if (retval) { -- krb5_free_sam_challenge_2(context, sc2); -- krb5_free_sam_challenge_2_body(context, sc2b); -- if (defsalt.length) free(defsalt.data); -- return(retval); -- } -- krb5_free_keyblock_contents(context, &tmp_kb); -- } -- - if (defsalt.length) - free(defsalt.data); - -+ if (!(sc2b->sam_flags & KRB5_SAM_SEND_ENCRYPTED_SAD)) { -+ /* -+ * If no flags are set, the protocol calls for us to combine the -+ * initial reply key with the SAD, using a method which is only -+ * specified for DES and 3DES enctypes. We no longer support this -+ * case. -+ */ -+ krb5_free_sam_challenge_2(context, sc2); -+ krb5_free_sam_challenge_2_body(context, sc2b); -+ return(KRB5_SAM_UNSUPPORTED); -+ } - } else { - /* as_key = string_to_key(SAD) */ - diff --git a/Remove-support-for-single-DES-and-CRC.patch b/Remove-support-for-single-DES-and-CRC.patch deleted file mode 100644 index 156e09a..0000000 --- a/Remove-support-for-single-DES-and-CRC.patch +++ /dev/null @@ -1,3340 +0,0 @@ -From e73ed142bd5baf15943069346202fe3b1a4d96d6 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 24 May 2019 13:12:03 -0400 -Subject: [PATCH] Remove support for single-DES and CRC - -Single-DES removal brings us closer to compliance with RFC 6649. -Single-DES was disabled by default starting in release 1.8, and -user-visible deprecation warnings were issued starting in release -1.17. - -ticket: 8808 -(cherry picked from commit fb2dada5eb89c4cd4e39dedd6dbb7dbd5e94f8b8) -[rharwood@redhat.com: .gitignore removal] -[rharwood@redhat.com: In this branch, supported_enctypes changes landed -first] ---- - doc/admin/advanced/retiring-des.rst | 5 + - doc/admin/conf_files/kdc_conf.rst | 17 +- - doc/admin/conf_files/krb5_conf.rst | 17 +- - doc/admin/enctypes.rst | 38 +- - doc/appdev/refs/macros/index.rst | 1 + - doc/conf.py | 4 +- - doc/mitK5features.rst | 2 +- - src/include/k5-int.h | 1 - - src/include/krb5/krb5.hin | 10 +- - src/include/win-mac.h | 12 - - src/kdc/kdc_util.c | 14 - - src/kdc/main.c | 6 - - src/kdc/realm_data.h | 1 - - src/lib/crypto/builtin/des/des_int.h | 1 - - .../crypto/builtin/enc_provider/Makefile.in | 3 - - src/lib/crypto/builtin/enc_provider/deps | 12 - - src/lib/crypto/builtin/enc_provider/des.c | 120 --- - .../crypto/builtin/hash_provider/Makefile.in | 7 +- - src/lib/crypto/builtin/hash_provider/deps | 13 - - .../crypto/builtin/hash_provider/hash_crc32.c | 56 -- - src/lib/crypto/krb/Makefile.in | 9 - - src/lib/crypto/krb/cksumtypes.c | 24 - - src/lib/crypto/krb/combine_keys.c | 3 - - src/lib/crypto/krb/crc32.c | 165 ----- - src/lib/crypto/krb/crypto_int.h | 16 - - src/lib/crypto/krb/default_state.c | 4 - - src/lib/crypto/krb/deps | 36 - - src/lib/crypto/krb/enc_old.c | 181 ----- - src/lib/crypto/krb/etypes.c | 46 -- - src/lib/crypto/krb/s2k_des.c | 691 ------------------ - src/lib/crypto/libk5crypto.exports | 1 - - .../crypto/openssl/enc_provider/Makefile.in | 3 - - src/lib/crypto/openssl/enc_provider/deps | 11 - - src/lib/crypto/openssl/enc_provider/des.c | 218 ------ - .../crypto/openssl/hash_provider/Makefile.in | 10 +- - src/lib/crypto/openssl/hash_provider/deps | 12 - - .../crypto/openssl/hash_provider/hash_crc32.c | 56 -- - src/lib/gssapi/krb5/accept_sec_context.c | 3 - - src/lib/gssapi/krb5/gssapiP_krb5.h | 20 +- - src/lib/gssapi/krb5/k5seal.c | 28 +- - src/lib/gssapi/krb5/k5sealiov.c | 20 - - src/lib/gssapi/krb5/k5unseal.c | 112 --- - src/lib/gssapi/krb5/k5unsealiov.c | 34 +- - src/lib/gssapi/krb5/util_crypt.c | 41 -- - src/lib/kadm5/kadm_rpc_xdr.c | 10 - - src/lib/krb5/ccache/cc_mslsa.c | 11 +- - src/lib/krb5/krb/auth_con.c | 23 +- - src/lib/krb5/krb/gic_keytab.c | 4 - - src/lib/krb5/krb/init_ctx.c | 9 - - src/lib/krb5/krb/mk_req_ext.c | 43 +- - src/lib/krb5/krb/s4u_creds.c | 3 - - src/lib/krb5/krb/ser_ctx.c | 2 +- - src/man/kdc.conf.man | 47 +- - src/man/krb5.conf.man | 6 +- - .../leash/htmlhelp/html/Encryption_Types.htm | 14 +- - 55 files changed, 75 insertions(+), 2181 deletions(-) - delete mode 100644 src/lib/crypto/builtin/enc_provider/des.c - delete mode 100644 src/lib/crypto/builtin/hash_provider/hash_crc32.c - delete mode 100644 src/lib/crypto/krb/crc32.c - delete mode 100644 src/lib/crypto/krb/enc_old.c - delete mode 100644 src/lib/crypto/krb/s2k_des.c - delete mode 100644 src/lib/crypto/openssl/enc_provider/des.c - delete mode 100644 src/lib/crypto/openssl/hash_provider/hash_crc32.c - -diff --git a/doc/admin/advanced/retiring-des.rst b/doc/admin/advanced/retiring-des.rst -index ebac95f24..4a964c15c 100644 ---- a/doc/admin/advanced/retiring-des.rst -+++ b/doc/admin/advanced/retiring-des.rst -@@ -22,6 +22,11 @@ However, deployments of krb5 using Kerberos databases created with older - versions of krb5 will not necessarily start using strong crypto for - ordinary operation without administrator intervention. - -+MIT krb5 began flagging deprecated encryption types with release 1.17, -+and removed DES (single-DES) support in release 1.18. As a -+consequence, a release prior to 1.18 is required to perform these -+migrations. -+ - Types of keys - ------------- - -diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst -index 7fbc8eb79..9759756a2 100644 ---- a/doc/admin/conf_files/kdc_conf.rst -+++ b/doc/admin/conf_files/kdc_conf.rst -@@ -381,13 +381,6 @@ The following tags may be specified in a [realms] subsection: - listed in **host_based_services**. ``no_host_referral = *`` will - disable referral processing altogether. - --**des_crc_session_supported** -- (Boolean value). If set to true, the KDC will assume that service -- principals support des-cbc-crc for session key enctype negotiation -- purposes. If **allow_weak_crypto** in :ref:`libdefaults` is -- false, or if des-cbc-crc is not a permitted enctype, then this -- variable has no effect. Defaults to true. New in release 1.11. -- - **reject_bad_transit** - (Boolean value.) If set to true, the KDC will check the list of - transited realms for cross-realm tickets against the transit path -@@ -850,13 +843,8 @@ Encryption types marked as "weak" are available for compatibility but - not recommended for use. - - ==================================================== ========================================================= --des-cbc-crc DES cbc mode with CRC-32 (weak) --des-cbc-md4 DES cbc mode with RSA-MD4 (weak) --des-cbc-md5 DES cbc mode with RSA-MD5 (weak) --des-cbc-raw DES cbc mode raw (weak) - des3-cbc-raw Triple DES cbc mode raw (weak) - des3-cbc-sha1 des3-hmac-sha1 des3-cbc-sha1-kd Triple DES cbc mode with HMAC/sha1 --des-hmac-sha1 DES with HMAC/sha1 (weak) - aes256-cts-hmac-sha1-96 aes256-cts aes256-sha1 AES-256 CTS mode with 96-bit SHA-1 HMAC - aes128-cts-hmac-sha1-96 aes128-cts aes128-sha1 AES-128 CTS mode with 96-bit SHA-1 HMAC - aes256-cts-hmac-sha384-192 aes256-sha2 AES-256 CTS mode with 192-bit SHA-384 HMAC -@@ -865,7 +853,6 @@ arcfour-hmac rc4-hmac arcfour-hmac-md5 RC4 with HMAC/MD5 - arcfour-hmac-exp rc4-hmac-exp arcfour-hmac-md5-exp Exportable RC4 with HMAC/MD5 (weak) - camellia256-cts-cmac camellia256-cts Camellia-256 CTS mode with CMAC - camellia128-cts-cmac camellia128-cts Camellia-128 CTS mode with CMAC --des The DES family: des-cbc-crc, des-cbc-md5, and des-cbc-md4 (weak) - des3 The triple DES family: des3-cbc-sha1 - aes The AES family: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, aes256-cts-hmac-sha384-192, and aes128-cts-hmac-sha256-128 - rc4 The RC4 family: arcfour-hmac -@@ -877,8 +864,8 @@ types for the variable in question. Types or families can be removed - from the current list by prefixing them with a minus sign ("-"). - Types or families can be prefixed with a plus sign ("+") for symmetry; - it has the same meaning as just listing the type or family. For --example, "``DEFAULT -des``" would be the default set of encryption --types with DES types removed, and "``des3 DEFAULT``" would be the -+example, "``DEFAULT -rc4``" would be the default set of encryption -+types with RC4 types removed, and "``des3 DEFAULT``" would be the - default set of encryption types with triple DES types moved to the - front. - -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index a3fb5d9f2..d5c498c89 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -100,10 +100,7 @@ The libdefaults section may contain any of the following relations: - in :ref:`Encryption_types` in :ref:`kdc.conf(5)`) will be filtered - out of the lists **default_tgs_enctypes**, - **default_tkt_enctypes**, and **permitted_enctypes**. The default -- value for this tag is false, which may cause authentication -- failures in existing Kerberos infrastructures that do not support -- strong crypto. Users in affected environments should set this tag -- to true until their infrastructure adopts stronger ciphers. -+ value for this tag is false. - - **canonicalize** - If this flag is set to true, initial ticket requests to the KDC -@@ -157,9 +154,7 @@ The libdefaults section may contain any of the following relations: - preference from highest to lowest. The list may be delimited with - commas or whitespace. See :ref:`Encryption_types` in - :ref:`kdc.conf(5)` for a list of the accepted values for this tag. -- The default value is |defetypes|, but single-DES encryption types -- will be implicitly removed from this list if the value of -- **allow_weak_crypto** is false. -+ The default value is |defetypes|. - - Do not set this unless required for specific backward - compatibility purposes; stale values of this setting can prevent -@@ -171,9 +166,7 @@ The libdefaults section may contain any of the following relations: - the client should request when making an AS-REQ, in order of - preference from highest to lowest. The format is the same as for - default_tgs_enctypes. The default value for this tag is -- |defetypes|, but single-DES encryption types will be implicitly -- removed from this list if the value of **allow_weak_crypto** is -- false. -+ |defetypes|. - - Do not set this unless required for specific backward - compatibility purposes; stale values of this setting can prevent -@@ -291,9 +284,7 @@ The libdefaults section may contain any of the following relations: - **permitted_enctypes** - Identifies all encryption types that are permitted for use in - session key encryption. The default value for this tag is -- |defetypes|, but single-DES encryption types will be implicitly -- removed from this list if the value of **allow_weak_crypto** is -- false. -+ |defetypes|. - - **plugin_base_dir** - If set, determines the base directory where krb5 plugins are -diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst -index 3cdfc92cf..84183a53c 100644 ---- a/doc/admin/enctypes.rst -+++ b/doc/admin/enctypes.rst -@@ -48,17 +48,12 @@ Session key selection - The KDC chooses the session key enctype by taking the intersection of - its **permitted_enctypes** list, the list of long-term keys for the - most recent kvno of the service, and the client's requested list of --enctypes. If **allow_weak_crypto** is true, all services are assumed --to support des-cbc-crc. -+enctypes. - --Starting in krb5-1.11, **des_crc_session_supported** in --:ref:`kdc.conf(5)` allows additional control over whether the KDC --issues des-cbc-crc session keys. -- --Also starting in krb5-1.11, it is possible to set a string attribute --on a service principal to control what session key enctypes the KDC --may issue for service tickets for that principal. See --:ref:`set_string` in :ref:`kadmin(1)` for details. -+Starting in krb5-1.11, it is possible to set a string attribute on a -+service principal to control what session key enctypes the KDC may -+issue for service tickets for that principal. See :ref:`set_string` -+in :ref:`kadmin(1)` for details. - - - Choosing enctypes for a service -@@ -86,11 +81,11 @@ affect how enctypes are chosen. - - **allow_weak_crypto** - defaults to *false* starting with krb5-1.8. When *false*, removes -- single-DES enctypes (and other weak enctypes) from -- **permitted_enctypes**, **default_tkt_enctypes**, and -- **default_tgs_enctypes**. Do not set this to *true* unless the -- use of weak enctypes is an acceptable risk for your environment -- and the weak enctypes are required for backward compatibility. -+ weak enctypes from **permitted_enctypes**, -+ **default_tkt_enctypes**, and **default_tgs_enctypes**. Do not -+ set this to *true* unless the use of weak enctypes is an -+ acceptable risk for your environment and the weak enctypes are -+ required for backward compatibility. - - **permitted_enctypes** - controls the set of enctypes that a service will accept as session -@@ -127,9 +122,9 @@ See :ref:`Encryption_types` for additional information about enctypes. - ========================== ===== ======== ======= - enctype weak? krb5 Windows - ========================== ===== ======== ======= --des-cbc-crc weak all >=2000 --des-cbc-md4 weak all ? --des-cbc-md5 weak all >=2000 -+des-cbc-crc weak <1.18 >=2000 -+des-cbc-md4 weak <1.18 ? -+des-cbc-md5 weak <1.18 >=2000 - des3-cbc-sha1 >=1.1 none - arcfour-hmac >=1.3 >=2000 - arcfour-hmac-exp weak >=1.3 >=2000 -@@ -141,6 +136,7 @@ camellia128-cts-cmac >=1.9 none - camellia256-cts-cmac >=1.9 none - ========================== ===== ======== ======= - --krb5 releases 1.8 and later disable the single-DES enctypes by --default. Microsoft Windows releases Windows 7 and later disable --single-DES enctypes by default. -+krb5 releases 1.18 and later do not support single-DES. krb5 releases -+1.8 and later disable the single-DES enctypes by default. Microsoft -+Windows releases Windows 7 and later disable single-DES enctypes by -+default. -diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst -index 47c6d4413..534795d15 100644 ---- a/doc/appdev/refs/macros/index.rst -+++ b/doc/appdev/refs/macros/index.rst -@@ -55,6 +55,7 @@ Public - ENCTYPE_DES3_CBC_RAW.rst - ENCTYPE_DES3_CBC_SHA.rst - ENCTYPE_DES3_CBC_SHA1.rst -+ ENCTYPE_DES3_CBC_SHA1.rst - ENCTYPE_DES_CBC_CRC.rst - ENCTYPE_DES_CBC_MD4.rst - ENCTYPE_DES_CBC_MD5.rst -diff --git a/doc/conf.py b/doc/conf.py -index 7c688d871..759367c21 100644 ---- a/doc/conf.py -+++ b/doc/conf.py -@@ -271,8 +271,8 @@ else: - rst_epilog += '.. |ckeytab| replace:: %s\n' % ckeytab - rst_epilog += ''' - .. |krb5conf| replace:: ``/etc/krb5.conf`` --.. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal`` --.. |defetypes| replace:: ``aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha384-192 aes128-cts-hmac-sha256-128 des3-cbc-sha1 arcfour-hmac-md5 camellia256-cts-cmac camellia128-cts-cmac des-cbc-crc des-cbc-md5 des-cbc-md4`` -+.. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal des3-cbc-sha1:normal arcfour-hmac-md5:normal`` -+.. |defetypes| replace:: ``aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha384-192 aes128-cts-hmac-sha256-128 des3-cbc-sha1 arcfour-hmac-md5 camellia256-cts-cmac camellia128-cts-cmac`` - .. |defmkey| replace:: ``aes256-cts-hmac-sha1-96`` - .. |copy| unicode:: U+000A9 - ''' -diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst -index 584f7b893..a19068e26 100644 ---- a/doc/mitK5features.rst -+++ b/doc/mitK5features.rst -@@ -37,7 +37,7 @@ Database backends: LDAP, DB2, LMDB - - krb4 support: Kerberos 5 release < 1.8 - --DES support: configurable (See :ref:`retiring-des`) -+DES support: Kerberos 5 release < 1.18 (See :ref:`retiring-des`) - - Interoperability - ---------------- -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 1a78fd7a9..e0c557554 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -200,7 +200,6 @@ typedef unsigned char u_char; - #define KRB5_CONF_DEFAULT_REALM "default_realm" - #define KRB5_CONF_DEFAULT_TGS_ENCTYPES "default_tgs_enctypes" - #define KRB5_CONF_DEFAULT_TKT_ENCTYPES "default_tkt_enctypes" --#define KRB5_CONF_DES_CRC_SESSION_SUPPORTED "des_crc_session_supported" - #define KRB5_CONF_DICT_FILE "dict_file" - #define KRB5_CONF_DISABLE "disable" - #define KRB5_CONF_DISABLE_ENCRYPTED_TIMESTAMP "disable_encrypted_timestamp" -diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 346e796a5..5f596d1fc 100644 ---- a/src/include/krb5/krb5.hin -+++ b/src/include/krb5/krb5.hin -@@ -422,13 +422,13 @@ typedef struct _krb5_crypto_iov { - - /* per Kerberos v5 protocol spec */ - #define ENCTYPE_NULL 0x0000 --#define ENCTYPE_DES_CBC_CRC 0x0001 /**< DES cbc mode with CRC-32 */ --#define ENCTYPE_DES_CBC_MD4 0x0002 /**< DES cbc mode with RSA-MD4 */ --#define ENCTYPE_DES_CBC_MD5 0x0003 /**< DES cbc mode with RSA-MD5 */ --#define ENCTYPE_DES_CBC_RAW 0x0004 /**< @deprecated DES cbc mode raw */ -+#define ENCTYPE_DES_CBC_CRC 0x0001 /**< @deprecated no longer supported */ -+#define ENCTYPE_DES_CBC_MD4 0x0002 /**< @deprecated no longer supported */ -+#define ENCTYPE_DES_CBC_MD5 0x0003 /**< @deprecated no longer supported */ -+#define ENCTYPE_DES_CBC_RAW 0x0004 /**< @deprecated no longer supported */ - #define ENCTYPE_DES3_CBC_SHA 0x0005 /**< @deprecated DES-3 cbc with SHA1 */ - #define ENCTYPE_DES3_CBC_RAW 0x0006 /**< @deprecated DES-3 cbc mode raw */ --#define ENCTYPE_DES_HMAC_SHA1 0x0008 /**< @deprecated */ -+#define ENCTYPE_DES_HMAC_SHA1 0x0008 /**< @deprecated no longer supported */ - /* PKINIT */ - #define ENCTYPE_DSA_SHA1_CMS 0x0009 /**< DSA with SHA1, CMS signature */ - #define ENCTYPE_MD5_RSA_CMS 0x000a /**< MD5 with RSA, CMS signature */ -diff --git a/src/include/win-mac.h b/src/include/win-mac.h -index c3744ed14..dc0f2a1ae 100644 ---- a/src/include/win-mac.h -+++ b/src/include/win-mac.h -@@ -176,18 +176,6 @@ typedef _W64 int ssize_t; - #define HAVE_STDLIB_H - #endif - --/* This controls which encryption routines libcrypto will provide */ --#define PROVIDE_DES_CBC_MD5 --#define PROVIDE_DES_CBC_CRC --#define PROVIDE_DES_CBC_RAW --#define PROVIDE_DES_CBC_CKSUM --#define PROVIDE_CRC32 --#define PROVIDE_RSA_MD4 --#define PROVIDE_RSA_MD5 --/* #define PROVIDE_DES3_CBC_SHA */ --/* #define PROVIDE_DES3_CBC_RAW */ --/* #define PROVIDE_NIST_SHA */ -- - /* Ugly. Microsoft, in stdc mode, doesn't support the low-level i/o - * routines directly. Rather, they only export the _ version. - * The following defines works around this problem. -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index f2741090e..df1ba6acf 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -991,17 +991,6 @@ dbentry_supports_enctype(kdc_realm_t *kdc_active_realm, krb5_db_entry *server, - free(etypes_str); - free(etypes); - -- /* If configured to, assume every server without a session_enctypes -- * attribute supports DES_CBC_CRC. */ -- if (kdc_active_realm->realm_assume_des_crc_sess && -- enctype == ENCTYPE_DES_CBC_CRC) -- return TRUE; -- -- /* Due to an ancient interop problem, assume nothing supports des-cbc-md5 -- * unless there's a session_enctypes explicitly saying that it does. */ -- if (enctype == ENCTYPE_DES_CBC_MD5) -- return FALSE; -- - /* Assume the server supports any enctype it has a long-term key for. */ - return !krb5_dbe_find_enctype(kdc_context, server, enctype, -1, 0, &datap); - } -@@ -1752,9 +1741,6 @@ krb5_boolean - enctype_requires_etype_info_2(krb5_enctype enctype) - { - switch(enctype) { -- case ENCTYPE_DES_CBC_CRC: -- case ENCTYPE_DES_CBC_MD4: -- case ENCTYPE_DES_CBC_MD5: - case ENCTYPE_DES3_CBC_SHA1: - case ENCTYPE_DES3_CBC_RAW: - case ENCTYPE_ARCFOUR_HMAC: -diff --git a/src/kdc/main.c b/src/kdc/main.c -index 1596c1c5b..8d4df4d6a 100644 ---- a/src/kdc/main.c -+++ b/src/kdc/main.c -@@ -307,12 +307,6 @@ init_realm(kdc_realm_t * rdp, krb5_pointer aprof, char *realm, - &rdp->realm_reject_bad_transit)) - rdp->realm_reject_bad_transit = TRUE; - -- /* Handle assume des-cbc-crc is supported for session keys */ -- hierarchy[2] = KRB5_CONF_DES_CRC_SESSION_SUPPORTED; -- if (krb5_aprof_get_boolean(aprof, hierarchy, TRUE, -- &rdp->realm_assume_des_crc_sess)) -- rdp->realm_assume_des_crc_sess = TRUE; -- - /* Handle ticket maximum life */ - hierarchy[2] = KRB5_CONF_MAX_LIFE; - if (krb5_aprof_get_deltat(aprof, hierarchy, TRUE, &rdp->realm_maxlife)) -diff --git a/src/kdc/realm_data.h b/src/kdc/realm_data.h -index 859daf159..8d698dcb8 100644 ---- a/src/kdc/realm_data.h -+++ b/src/kdc/realm_data.h -@@ -73,7 +73,6 @@ typedef struct __kdc_realm_data { - krb5_deltat realm_maxrlife; /* Maximum renewable life for realm */ - krb5_boolean realm_reject_bad_transit; /* Accept unverifiable transited_realm ? */ - krb5_boolean realm_restrict_anon; /* Anon to local TGT only */ -- krb5_boolean realm_assume_des_crc_sess; /* Assume princs support des-cbc-crc for session keys */ - } kdc_realm_t; - - struct server_handle { -diff --git a/src/lib/crypto/builtin/des/des_int.h b/src/lib/crypto/builtin/des/des_int.h -index 67e40a19c..f8dc6b296 100644 ---- a/src/lib/crypto/builtin/des/des_int.h -+++ b/src/lib/crypto/builtin/des/des_int.h -@@ -131,7 +131,6 @@ typedef struct mit_des_ran_key_seed { - /* the first byte of the key is already in the keyblock */ - - #define MIT_DES_BLOCK_LENGTH (8*sizeof(krb5_octet)) --#define MIT_DES_CBC_CRC_PAD_MINIMUM CRC32_CKSUM_LENGTH - /* This used to be 8*sizeof(krb5_octet) */ - #define MIT_DES_KEYSIZE 8 - -diff --git a/src/lib/crypto/builtin/enc_provider/Makefile.in b/src/lib/crypto/builtin/enc_provider/Makefile.in -index 4fd3311b4..3459e1d0e 100644 ---- a/src/lib/crypto/builtin/enc_provider/Makefile.in -+++ b/src/lib/crypto/builtin/enc_provider/Makefile.in -@@ -11,21 +11,18 @@ LOCALINCLUDES = -I$(srcdir)/../des \ - ##DOS##OBJFILE = ..\..\$(OUTPRE)enc_provider.lst - - STLIBOBJS= \ -- des.o \ - des3.o \ - rc4.o \ - aes.o \ - camellia.o - - OBJS= \ -- $(OUTPRE)des.$(OBJEXT) \ - $(OUTPRE)des3.$(OBJEXT) \ - $(OUTPRE)aes.$(OBJEXT) \ - $(OUTPRE)camellia.$(OBJEXT) \ - $(OUTPRE)rc4.$(OBJEXT) - - SRCS= \ -- $(srcdir)/des.c \ - $(srcdir)/des3.c \ - $(srcdir)/aes.c \ - $(srcdir)/camellia.c \ -diff --git a/src/lib/crypto/builtin/enc_provider/deps b/src/lib/crypto/builtin/enc_provider/deps -index 72e340766..7a3324c44 100644 ---- a/src/lib/crypto/builtin/enc_provider/deps -+++ b/src/lib/crypto/builtin/enc_provider/deps -@@ -1,18 +1,6 @@ - # - # Generated makefile dependencies follow. - # --des.so des.po $(OUTPRE)des.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ -- $(srcdir)/../aes/aes.h $(srcdir)/../crypto_mod.h $(srcdir)/../des/des_int.h \ -- $(srcdir)/../sha2/sha2.h $(top_srcdir)/include/k5-buf.h \ -- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h des.c - des3.so des3.po $(OUTPRE)des3.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ -diff --git a/src/lib/crypto/builtin/enc_provider/des.c b/src/lib/crypto/builtin/enc_provider/des.c -deleted file mode 100644 -index 30b8229f8..000000000 ---- a/src/lib/crypto/builtin/enc_provider/des.c -+++ /dev/null -@@ -1,120 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* -- * Copyright (C) 1998 by the FundsXpress, INC. -- * -- * All rights reserved. -- * -- * Export of this software from the United States of America may require -- * a specific license from the United States Government. It is the -- * responsibility of any person or organization contemplating export to -- * obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of FundsXpress. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. FundsXpress makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- * -- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR -- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED -- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. -- */ -- --#include "crypto_int.h" --#include "des_int.h" -- --static krb5_error_code --validate_and_schedule(krb5_key key, const krb5_data *ivec, -- const krb5_crypto_iov *data, size_t num_data, -- mit_des_key_schedule schedule) --{ -- if (key->keyblock.length != 8) -- return KRB5_BAD_KEYSIZE; -- if (iov_total_length(data, num_data, FALSE) % 8 != 0) -- return KRB5_BAD_MSIZE; -- if (ivec != NULL && ivec->length != 8) -- return KRB5_BAD_MSIZE; -- -- switch (mit_des_key_sched(key->keyblock.contents, schedule)) { -- case -1: -- return(KRB5DES_BAD_KEYPAR); -- case -2: -- return(KRB5DES_WEAK_KEY); -- } -- return 0; --} -- --static krb5_error_code --des_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, -- size_t num_data) --{ -- mit_des_key_schedule schedule; -- krb5_error_code err; -- -- err = validate_and_schedule(key, ivec, data, num_data, schedule); -- if (err) -- return err; -- -- krb5int_des_cbc_encrypt(data, num_data, schedule, -- ivec != NULL ? (unsigned char *) ivec->data : -- NULL); -- -- zap(schedule, sizeof(schedule)); -- return 0; --} -- --static krb5_error_code --des_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, -- size_t num_data) --{ -- mit_des_key_schedule schedule; -- krb5_error_code err; -- -- err = validate_and_schedule(key, ivec, data, num_data, schedule); -- if (err) -- return err; -- -- krb5int_des_cbc_decrypt(data, num_data, schedule, -- ivec != NULL ? (unsigned char *) ivec->data : -- NULL); -- -- zap(schedule, sizeof(schedule)); -- return 0; --} -- --static krb5_error_code --des_cbc_mac(krb5_key key, const krb5_crypto_iov *data, size_t num_data, -- const krb5_data *ivec, krb5_data *output) --{ -- mit_des_key_schedule schedule; -- krb5_error_code err; -- -- err = validate_and_schedule(key, ivec, data, num_data, schedule); -- if (err) -- return err; -- -- if (output->length != 8) -- return KRB5_CRYPTO_INTERNAL; -- -- krb5int_des_cbc_mac(data, num_data, schedule, -- ivec != NULL ? (unsigned char *) ivec->data : NULL, -- (unsigned char *) output->data); -- -- zap(schedule, sizeof(schedule)); -- return 0; --} -- --const struct krb5_enc_provider krb5int_enc_des = { -- 8, -- 7, 8, -- des_encrypt, -- des_decrypt, -- des_cbc_mac, -- krb5int_des_init_state, -- krb5int_default_free_state --}; -diff --git a/src/lib/crypto/builtin/hash_provider/Makefile.in b/src/lib/crypto/builtin/hash_provider/Makefile.in -index 2f587a497..ceebf9380 100644 ---- a/src/lib/crypto/builtin/hash_provider/Makefile.in -+++ b/src/lib/crypto/builtin/hash_provider/Makefile.in -@@ -8,20 +8,17 @@ LOCALINCLUDES = -I$(srcdir)/.. -I$(srcdir)/../../krb -I$(srcdir)/../md4 \ - ##DOS##OBJFILE = ..\..\$(OUTPRE)hash_provider.lst - - STLIBOBJS= \ -- hash_crc32.o \ - hash_md4.o \ - hash_md5.o \ - hash_sha1.o \ - hash_sha2.o - --OBJS= $(OUTPRE)hash_crc32.$(OBJEXT) \ -- $(OUTPRE)hash_md4.$(OBJEXT) \ -+OBJS= $(OUTPRE)hash_md4.$(OBJEXT) \ - $(OUTPRE)hash_md5.$(OBJEXT) \ - $(OUTPRE)hash_sha1.$(OBJEXT) \ - $(OUTPRE)hash_sha2.$(OBJEXT) - --SRCS= $(srcdir)/hash_crc32.c \ -- $(srcdir)/hash_md4.c \ -+SRCS= $(srcdir)/hash_md4.c \ - $(srcdir)/hash_md5.c \ - $(srcdir)/hash_sha1.c \ - $(srcdir)/hash_sha2.c -diff --git a/src/lib/crypto/builtin/hash_provider/deps b/src/lib/crypto/builtin/hash_provider/deps -index 18f89b383..fb65a44be 100644 ---- a/src/lib/crypto/builtin/hash_provider/deps -+++ b/src/lib/crypto/builtin/hash_provider/deps -@@ -1,19 +1,6 @@ - # - # Generated makefile dependencies follow. - # --hash_crc32.so hash_crc32.po $(OUTPRE)hash_crc32.$(OBJEXT): \ -- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ -- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(srcdir)/../aes/aes.h \ -- $(srcdir)/../crypto_mod.h $(srcdir)/../sha2/sha2.h \ -- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- hash_crc32.c - hash_md4.so hash_md4.po $(OUTPRE)hash_md4.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -diff --git a/src/lib/crypto/builtin/hash_provider/hash_crc32.c b/src/lib/crypto/builtin/hash_provider/hash_crc32.c -deleted file mode 100644 -index 1d0be5563..000000000 ---- a/src/lib/crypto/builtin/hash_provider/hash_crc32.c -+++ /dev/null -@@ -1,56 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* -- * Copyright (C) 1998 by the FundsXpress, INC. -- * -- * All rights reserved. -- * -- * Export of this software from the United States of America may require -- * a specific license from the United States Government. It is the -- * responsibility of any person or organization contemplating export to -- * obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of FundsXpress. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. FundsXpress makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- * -- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR -- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED -- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. -- */ -- --#include "crypto_int.h" -- --static krb5_error_code --k5_crc32_hash(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) --{ -- unsigned long c; -- unsigned int i; -- -- if (output->length != CRC32_CKSUM_LENGTH) -- return KRB5_CRYPTO_INTERNAL; -- -- c = 0; -- for (i = 0; i < num_data; i++) { -- const krb5_crypto_iov *iov = &data[i]; -- -- if (SIGN_IOV(iov)) -- mit_crc32(iov->data.data, iov->data.length, &c); -- } -- -- store_32_le(c, output->data); -- return 0; --} -- --const struct krb5_hash_provider krb5int_hash_crc32 = { -- "CRC32", -- CRC32_CKSUM_LENGTH, -- 1, -- k5_crc32_hash --}; -diff --git a/src/lib/crypto/krb/Makefile.in b/src/lib/crypto/krb/Makefile.in -index fc01a2ced..c0e0b791b 100644 ---- a/src/lib/crypto/krb/Makefile.in -+++ b/src/lib/crypto/krb/Makefile.in -@@ -23,7 +23,6 @@ STLIBOBJS=\ - cmac.o \ - coll_proof_cksum.o \ - combine_keys.o \ -- crc32.o \ - crypto_length.o \ - crypto_libinit.o \ - default_state.o \ -@@ -37,7 +36,6 @@ STLIBOBJS=\ - enc_dk_cmac.o \ - enc_dk_hmac.o \ - enc_etm.o \ -- enc_old.o \ - enc_raw.o \ - enc_rc4.o \ - etypes.o \ -@@ -61,7 +59,6 @@ STLIBOBJS=\ - prng.o \ - prng_$(PRNG_ALG).o \ - random_to_key.o \ -- s2k_des.o \ - s2k_pbkdf2.o \ - s2k_rc4.o \ - state.o \ -@@ -88,7 +85,6 @@ OBJS=\ - $(OUTPRE)cmac.$(OBJEXT) \ - $(OUTPRE)coll_proof_cksum.$(OBJEXT) \ - $(OUTPRE)combine_keys.$(OBJEXT) \ -- $(OUTPRE)crc32.$(OBJEXT) \ - $(OUTPRE)crypto_length.$(OBJEXT) \ - $(OUTPRE)crypto_libinit.$(OBJEXT) \ - $(OUTPRE)default_state.$(OBJEXT) \ -@@ -102,7 +98,6 @@ OBJS=\ - $(OUTPRE)enc_dk_cmac.$(OBJEXT) \ - $(OUTPRE)enc_dk_hmac.$(OBJEXT) \ - $(OUTPRE)enc_etm.$(OBJEXT) \ -- $(OUTPRE)enc_old.$(OBJEXT) \ - $(OUTPRE)enc_raw.$(OBJEXT) \ - $(OUTPRE)enc_rc4.$(OBJEXT) \ - $(OUTPRE)etypes.$(OBJEXT) \ -@@ -126,7 +121,6 @@ OBJS=\ - $(OUTPRE)prng.$(OBJEXT) \ - $(OUTPRE)prng_$(PRNG_ALG).$(OBJEXT) \ - $(OUTPRE)random_to_key.$(OBJEXT) \ -- $(OUTPRE)s2k_des.$(OBJEXT) \ - $(OUTPRE)s2k_pbkdf2.$(OBJEXT) \ - $(OUTPRE)s2k_rc4.$(OBJEXT) \ - $(OUTPRE)state.$(OBJEXT) \ -@@ -153,7 +147,6 @@ SRCS=\ - $(srcdir)/cmac.c \ - $(srcdir)/coll_proof_cksum.c \ - $(srcdir)/combine_keys.c \ -- $(srcdir)/crc32.c \ - $(srcdir)/crypto_length.c \ - $(srcdir)/crypto_libinit.c \ - $(srcdir)/default_state.c \ -@@ -167,7 +160,6 @@ SRCS=\ - $(srcdir)/enc_dk_cmac.c \ - $(srcdir)/enc_dk_hmac.c \ - $(srcdir)/enc_etm.c \ -- $(srcdir)/enc_old.c \ - $(srcdir)/enc_raw.c \ - $(srcdir)/enc_rc4.c \ - $(srcdir)/etypes.c \ -@@ -192,7 +184,6 @@ SRCS=\ - $(srcdir)/prng_$(PRNG_ALG).c \ - $(srcdir)/cf2.c \ - $(srcdir)/random_to_key.c \ -- $(srcdir)/s2k_des.c \ - $(srcdir)/s2k_pbkdf2.c \ - $(srcdir)/s2k_rc4.c \ - $(srcdir)/state.c \ -diff --git a/src/lib/crypto/krb/cksumtypes.c b/src/lib/crypto/krb/cksumtypes.c -index 85967f9aa..ecc2e08c9 100644 ---- a/src/lib/crypto/krb/cksumtypes.c -+++ b/src/lib/crypto/krb/cksumtypes.c -@@ -28,42 +28,18 @@ - #include "crypto_int.h" - - const struct krb5_cksumtypes krb5int_cksumtypes_list[] = { -- { CKSUMTYPE_CRC32, -- "crc32", { 0 }, "CRC-32", -- NULL, &krb5int_hash_crc32, -- krb5int_unkeyed_checksum, NULL, -- 4, 4, CKSUM_UNKEYED | CKSUM_NOT_COLL_PROOF }, -- - { CKSUMTYPE_RSA_MD4, - "md4", { 0 }, "RSA-MD4", - NULL, &krb5int_hash_md4, - krb5int_unkeyed_checksum, NULL, - 16, 16, CKSUM_UNKEYED }, - -- { CKSUMTYPE_RSA_MD4_DES, -- "md4-des", { 0 }, "RSA-MD4 with DES cbc mode", -- &krb5int_enc_des, &krb5int_hash_md4, -- krb5int_confounder_checksum, krb5int_confounder_verify, -- 24, 24, 0 }, -- -- { CKSUMTYPE_DESCBC, -- "des-cbc", { 0 }, "DES cbc mode", -- &krb5int_enc_des, NULL, -- krb5int_cbc_checksum, NULL, -- 8, 8, 0 }, -- - { CKSUMTYPE_RSA_MD5, - "md5", { 0 }, "RSA-MD5", - NULL, &krb5int_hash_md5, - krb5int_unkeyed_checksum, NULL, - 16, 16, CKSUM_UNKEYED }, - -- { CKSUMTYPE_RSA_MD5_DES, -- "md5-des", { 0 }, "RSA-MD5 with DES cbc mode", -- &krb5int_enc_des, &krb5int_hash_md5, -- krb5int_confounder_checksum, krb5int_confounder_verify, -- 24, 24, 0 }, -- - { CKSUMTYPE_NIST_SHA, - "sha", { 0 }, "NIST-SHA", - NULL, &krb5int_hash_sha1, -diff --git a/src/lib/crypto/krb/combine_keys.c b/src/lib/crypto/krb/combine_keys.c -index 90905c5ae..c36434e17 100644 ---- a/src/lib/crypto/krb/combine_keys.c -+++ b/src/lib/crypto/krb/combine_keys.c -@@ -60,9 +60,6 @@ static krb5_boolean - enctype_ok(krb5_enctype e) - { - switch (e) { -- case ENCTYPE_DES_CBC_CRC: -- case ENCTYPE_DES_CBC_MD4: -- case ENCTYPE_DES_CBC_MD5: - case ENCTYPE_DES3_CBC_SHA1: - return TRUE; - default: -diff --git a/src/lib/crypto/krb/crc32.c b/src/lib/crypto/krb/crc32.c -deleted file mode 100644 -index 11fe312da..000000000 ---- a/src/lib/crypto/krb/crc32.c -+++ /dev/null -@@ -1,165 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* lib/crypto/krb/crc32.c */ --/* -- * Copyright 1990, 2002 by the Massachusetts Institute of Technology. -- * All Rights Reserved. -- * -- * Export of this software from the United States of America may -- * require a specific license from the United States Government. -- * It is the responsibility of any person or organization contemplating -- * export to obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of M.I.T. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. Furthermore if you modify this software you must label -- * your software as modified software and not distribute it in such a -- * fashion that it might be confused with the original M.I.T. software. -- * M.I.T. makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- */ --/* -- * Copyright (C) 1986 Gary S. Brown. You may use this program, or -- * code or tables extracted from it, as desired without restriction. -- */ -- --/* -- * -- * CRC-32/AUTODIN-II routines -- */ -- --#include "crypto_int.h" -- --/* First, the polynomial itself and its table of feedback terms. The */ --/* polynomial is */ --/* X^32+X^26+X^23+X^22+X^16+X^12+X^11+X^10+X^8+X^7+X^5+X^4+X^2+X^1+X^0 */ --/* Note that we take it "backwards" and put the highest-order term in */ --/* the lowest-order bit. The X^32 term is "implied"; the LSB is the */ --/* X^31 term, etc. The X^0 term (usually shown as "+1") results in */ --/* the MSB being 1. */ -- --/* Note that the usual hardware shift register implementation, which */ --/* is what we're using (we're merely optimizing it by doing eight-bit */ --/* chunks at a time) shifts bits into the lowest-order term. In our */ --/* implementation, that means shifting towards the right. Why do we */ --/* do it this way? Because the calculated CRC must be transmitted in */ --/* order from highest-order term to lowest-order term. UARTs transmit */ --/* characters in order from LSB to MSB. By storing the CRC this way, */ --/* we hand it to the UART in the order low-byte to high-byte; the UART */ --/* sends each low-bit to hight-bit; and the result is transmission bit */ --/* by bit from highest- to lowest-order term without requiring any bit */ --/* shuffling on our part. Reception works similarly. */ -- --/* The feedback terms table consists of 256, 32-bit entries. Notes: */ --/* */ --/* 1. The table can be generated at runtime if desired; code to do so */ --/* is shown later. It might not be obvious, but the feedback */ --/* terms simply represent the results of eight shift/xor opera- */ --/* tions for all combinations of data and CRC register values. */ --/* */ --/* 2. The CRC accumulation logic is the same for all CRC polynomials, */ --/* be they sixteen or thirty-two bits wide. You simply choose the */ --/* appropriate table. Alternatively, because the table can be */ --/* generated at runtime, you can start by generating the table for */ --/* the polynomial in question and use exactly the same "updcrc", */ --/* if your application needn't simultaneously handle two CRC */ --/* polynomials. (Note, however, that XMODEM is strange.) */ --/* */ --/* 3. For 16-bit CRCs, the table entries need be only 16 bits wide; */ --/* of course, 32-bit entries work OK if the high 16 bits are zero. */ --/* */ --/* 4. The values must be right-shifted by eight bits by the "updcrc" */ --/* logic; the shift must be unsigned (bring in zeroes). On some */ --/* hardware you could probably optimize the shift in assembler by */ --/* using byte-swap instructions. */ -- --static u_long const crc_table[256] = { -- 0x00000000, 0x77073096, 0xee0e612c, 0x990951ba, -- 0x076dc419, 0x706af48f, 0xe963a535, 0x9e6495a3, -- 0x0edb8832, 0x79dcb8a4, 0xe0d5e91e, 0x97d2d988, -- 0x09b64c2b, 0x7eb17cbd, 0xe7b82d07, 0x90bf1d91, -- 0x1db71064, 0x6ab020f2, 0xf3b97148, 0x84be41de, -- 0x1adad47d, 0x6ddde4eb, 0xf4d4b551, 0x83d385c7, -- 0x136c9856, 0x646ba8c0, 0xfd62f97a, 0x8a65c9ec, -- 0x14015c4f, 0x63066cd9, 0xfa0f3d63, 0x8d080df5, -- 0x3b6e20c8, 0x4c69105e, 0xd56041e4, 0xa2677172, -- 0x3c03e4d1, 0x4b04d447, 0xd20d85fd, 0xa50ab56b, -- 0x35b5a8fa, 0x42b2986c, 0xdbbbc9d6, 0xacbcf940, -- 0x32d86ce3, 0x45df5c75, 0xdcd60dcf, 0xabd13d59, -- 0x26d930ac, 0x51de003a, 0xc8d75180, 0xbfd06116, -- 0x21b4f4b5, 0x56b3c423, 0xcfba9599, 0xb8bda50f, -- 0x2802b89e, 0x5f058808, 0xc60cd9b2, 0xb10be924, -- 0x2f6f7c87, 0x58684c11, 0xc1611dab, 0xb6662d3d, -- 0x76dc4190, 0x01db7106, 0x98d220bc, 0xefd5102a, -- 0x71b18589, 0x06b6b51f, 0x9fbfe4a5, 0xe8b8d433, -- 0x7807c9a2, 0x0f00f934, 0x9609a88e, 0xe10e9818, -- 0x7f6a0dbb, 0x086d3d2d, 0x91646c97, 0xe6635c01, -- 0x6b6b51f4, 0x1c6c6162, 0x856530d8, 0xf262004e, -- 0x6c0695ed, 0x1b01a57b, 0x8208f4c1, 0xf50fc457, -- 0x65b0d9c6, 0x12b7e950, 0x8bbeb8ea, 0xfcb9887c, -- 0x62dd1ddf, 0x15da2d49, 0x8cd37cf3, 0xfbd44c65, -- 0x4db26158, 0x3ab551ce, 0xa3bc0074, 0xd4bb30e2, -- 0x4adfa541, 0x3dd895d7, 0xa4d1c46d, 0xd3d6f4fb, -- 0x4369e96a, 0x346ed9fc, 0xad678846, 0xda60b8d0, -- 0x44042d73, 0x33031de5, 0xaa0a4c5f, 0xdd0d7cc9, -- 0x5005713c, 0x270241aa, 0xbe0b1010, 0xc90c2086, -- 0x5768b525, 0x206f85b3, 0xb966d409, 0xce61e49f, -- 0x5edef90e, 0x29d9c998, 0xb0d09822, 0xc7d7a8b4, -- 0x59b33d17, 0x2eb40d81, 0xb7bd5c3b, 0xc0ba6cad, -- 0xedb88320, 0x9abfb3b6, 0x03b6e20c, 0x74b1d29a, -- 0xead54739, 0x9dd277af, 0x04db2615, 0x73dc1683, -- 0xe3630b12, 0x94643b84, 0x0d6d6a3e, 0x7a6a5aa8, -- 0xe40ecf0b, 0x9309ff9d, 0x0a00ae27, 0x7d079eb1, -- 0xf00f9344, 0x8708a3d2, 0x1e01f268, 0x6906c2fe, -- 0xf762575d, 0x806567cb, 0x196c3671, 0x6e6b06e7, -- 0xfed41b76, 0x89d32be0, 0x10da7a5a, 0x67dd4acc, -- 0xf9b9df6f, 0x8ebeeff9, 0x17b7be43, 0x60b08ed5, -- 0xd6d6a3e8, 0xa1d1937e, 0x38d8c2c4, 0x4fdff252, -- 0xd1bb67f1, 0xa6bc5767, 0x3fb506dd, 0x48b2364b, -- 0xd80d2bda, 0xaf0a1b4c, 0x36034af6, 0x41047a60, -- 0xdf60efc3, 0xa867df55, 0x316e8eef, 0x4669be79, -- 0xcb61b38c, 0xbc66831a, 0x256fd2a0, 0x5268e236, -- 0xcc0c7795, 0xbb0b4703, 0x220216b9, 0x5505262f, -- 0xc5ba3bbe, 0xb2bd0b28, 0x2bb45a92, 0x5cb36a04, -- 0xc2d7ffa7, 0xb5d0cf31, 0x2cd99e8b, 0x5bdeae1d, -- 0x9b64c2b0, 0xec63f226, 0x756aa39c, 0x026d930a, -- 0x9c0906a9, 0xeb0e363f, 0x72076785, 0x05005713, -- 0x95bf4a82, 0xe2b87a14, 0x7bb12bae, 0x0cb61b38, -- 0x92d28e9b, 0xe5d5be0d, 0x7cdcefb7, 0x0bdbdf21, -- 0x86d3d2d4, 0xf1d4e242, 0x68ddb3f8, 0x1fda836e, -- 0x81be16cd, 0xf6b9265b, 0x6fb077e1, 0x18b74777, -- 0x88085ae6, 0xff0f6a70, 0x66063bca, 0x11010b5c, -- 0x8f659eff, 0xf862ae69, 0x616bffd3, 0x166ccf45, -- 0xa00ae278, 0xd70dd2ee, 0x4e048354, 0x3903b3c2, -- 0xa7672661, 0xd06016f7, 0x4969474d, 0x3e6e77db, -- 0xaed16a4a, 0xd9d65adc, 0x40df0b66, 0x37d83bf0, -- 0xa9bcae53, 0xdebb9ec5, 0x47b2cf7f, 0x30b5ffe9, -- 0xbdbdf21c, 0xcabac28a, 0x53b39330, 0x24b4a3a6, -- 0xbad03605, 0xcdd70693, 0x54de5729, 0x23d967bf, -- 0xb3667a2e, 0xc4614ab8, 0x5d681b02, 0x2a6f2b94, -- 0xb40bbe37, 0xc30c8ea1, 0x5a05df1b, 0x2d02ef8d --}; -- --void --mit_crc32(krb5_pointer in, size_t in_length, unsigned long *cksum) --{ -- u_char *data; -- u_long c = *cksum; -- int idx; -- size_t i; -- -- data = (u_char *)in; -- for (i = 0; i < in_length; i++) { -- idx = (int) (data[i] ^ c); -- idx &= 0xff; -- c >>= 8; -- c ^= crc_table[idx]; -- } -- -- *cksum = c; --} -diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h -index 6c1c77cac..b18d5e2e3 100644 ---- a/src/lib/crypto/krb/crypto_int.h -+++ b/src/lib/crypto/krb/crypto_int.h -@@ -180,8 +180,6 @@ extern const size_t krb5int_cksumtypes_length; - /*** Prototypes for enctype table functions ***/ - - /* Length */ --unsigned int krb5int_old_crypto_length(const struct krb5_keytypes *ktp, -- krb5_cryptotype type); - unsigned int krb5int_raw_crypto_length(const struct krb5_keytypes *ktp, - krb5_cryptotype type); - unsigned int krb5int_arcfour_crypto_length(const struct krb5_keytypes *ktp, -@@ -196,10 +194,6 @@ unsigned int krb5int_aes2_crypto_length(const struct krb5_keytypes *ktp, - krb5_cryptotype type); - - /* Encrypt */ --krb5_error_code krb5int_old_encrypt(const struct krb5_keytypes *ktp, -- krb5_key key, krb5_keyusage usage, -- const krb5_data *ivec, -- krb5_crypto_iov *data, size_t num_data); - krb5_error_code krb5int_raw_encrypt(const struct krb5_keytypes *ktp, - krb5_key key, krb5_keyusage usage, - const krb5_data *ivec, -@@ -224,10 +218,6 @@ krb5_error_code krb5int_etm_encrypt(const struct krb5_keytypes *ktp, - krb5_crypto_iov *data, size_t num_data); - - /* Decrypt */ --krb5_error_code krb5int_old_decrypt(const struct krb5_keytypes *ktp, -- krb5_key key, krb5_keyusage usage, -- const krb5_data *ivec, -- krb5_crypto_iov *data, size_t num_data); - krb5_error_code krb5int_raw_decrypt(const struct krb5_keytypes *ktp, - krb5_key key, krb5_keyusage usage, - const krb5_data *ivec, -@@ -388,10 +378,6 @@ krb5_error_code krb5int_cmac_checksum(const struct krb5_enc_provider *enc, - size_t num_data, - krb5_data *output); - --/* Compute a CRC-32 checksum. c is in-out to allow chaining; init to 0. */ --#define CRC32_CKSUM_LENGTH 4 --void mit_crc32(krb5_pointer in, size_t in_length, unsigned long *c); -- - /* Translate an RFC 3961 key usage to a Microsoft RC4 usage. */ - krb5_keyusage krb5int_arcfour_translate_usage(krb5_keyusage usage); - -@@ -455,7 +441,6 @@ void k5_iov_cursor_put(struct iov_cursor *cursor, unsigned char *block); - /* Modules must implement the k5_sha256() function prototyped in k5-int.h. */ - - /* Modules must implement the following enc_providers and hash_providers: */ --extern const struct krb5_enc_provider krb5int_enc_des; - extern const struct krb5_enc_provider krb5int_enc_des3; - extern const struct krb5_enc_provider krb5int_enc_arcfour; - extern const struct krb5_enc_provider krb5int_enc_aes128; -@@ -465,7 +450,6 @@ extern const struct krb5_enc_provider krb5int_enc_aes256_ctr; - extern const struct krb5_enc_provider krb5int_enc_camellia128; - extern const struct krb5_enc_provider krb5int_enc_camellia256; - --extern const struct krb5_hash_provider krb5int_hash_crc32; - extern const struct krb5_hash_provider krb5int_hash_md4; - extern const struct krb5_hash_provider krb5int_hash_md5; - extern const struct krb5_hash_provider krb5int_hash_sha1; -diff --git a/src/lib/crypto/krb/default_state.c b/src/lib/crypto/krb/default_state.c -index c7bfe323f..0757c8b02 100644 ---- a/src/lib/crypto/krb/default_state.c -+++ b/src/lib/crypto/krb/default_state.c -@@ -39,10 +39,6 @@ krb5int_des_init_state(const krb5_keyblock *key, krb5_keyusage usage, - if (alloc_data(state_out, 8)) - return ENOMEM; - -- /* des-cbc-crc uses the key as the initial ivec. */ -- if (key->enctype == ENCTYPE_DES_CBC_CRC) -- memcpy(state_out->data, key->contents, state_out->length); -- - return 0; - } - -diff --git a/src/lib/crypto/krb/deps b/src/lib/crypto/krb/deps -index 2a7f9b0ef..f9a740860 100644 ---- a/src/lib/crypto/krb/deps -+++ b/src/lib/crypto/krb/deps -@@ -204,18 +204,6 @@ combine_keys.so combine_keys.po $(OUTPRE)combine_keys.$(OBJEXT): \ - $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ - $(top_srcdir)/include/socket-utils.h combine_keys.c \ - crypto_int.h --crc32.so crc32.po $(OUTPRE)crc32.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \ -- $(srcdir)/../builtin/crypto_mod.h $(srcdir)/../builtin/sha2/sha2.h \ -- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- crc32.c crypto_int.h - crypto_length.so crypto_length.po $(OUTPRE)crypto_length.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -@@ -372,18 +360,6 @@ enc_etm.so enc_etm.po $(OUTPRE)enc_etm.$(OBJEXT): $(BUILDTOP)/include/autoconf.h - $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ - $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ - crypto_int.h enc_etm.c --enc_old.so enc_old.po $(OUTPRE)enc_old.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \ -- $(srcdir)/../builtin/crypto_mod.h $(srcdir)/../builtin/sha2/sha2.h \ -- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- crypto_int.h enc_old.c - enc_raw.so enc_raw.po $(OUTPRE)enc_raw.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \ -@@ -660,18 +636,6 @@ random_to_key.so random_to_key.po $(OUTPRE)random_to_key.$(OBJEXT): \ - $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ - $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ - $(top_srcdir)/include/socket-utils.h crypto_int.h random_to_key.c --s2k_des.so s2k_des.po $(OUTPRE)s2k_des.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \ -- $(srcdir)/../builtin/crypto_mod.h $(srcdir)/../builtin/sha2/sha2.h \ -- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- crypto_int.h s2k_des.c - s2k_pbkdf2.so s2k_pbkdf2.po $(OUTPRE)s2k_pbkdf2.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -diff --git a/src/lib/crypto/krb/enc_old.c b/src/lib/crypto/krb/enc_old.c -deleted file mode 100644 -index 1b02a5915..000000000 ---- a/src/lib/crypto/krb/enc_old.c -+++ /dev/null -@@ -1,181 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* lib/crypto/krb/enc_old.c */ --/* -- * Copyright 2008 by the Massachusetts Institute of Technology. -- * All Rights Reserved. -- * -- * Export of this software from the United States of America may -- * require a specific license from the United States Government. -- * It is the responsibility of any person or organization contemplating -- * export to obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of M.I.T. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. Furthermore if you modify this software you must label -- * your software as modified software and not distribute it in such a -- * fashion that it might be confused with the original M.I.T. software. -- * M.I.T. makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- */ -- --#include "crypto_int.h" -- --unsigned int --krb5int_old_crypto_length(const struct krb5_keytypes *ktp, -- krb5_cryptotype type) --{ -- switch (type) { -- case KRB5_CRYPTO_TYPE_HEADER: -- return ktp->enc->block_size + ktp->hash->hashsize; -- case KRB5_CRYPTO_TYPE_PADDING: -- return ktp->enc->block_size; -- case KRB5_CRYPTO_TYPE_TRAILER: -- return 0; -- case KRB5_CRYPTO_TYPE_CHECKSUM: -- return ktp->hash->hashsize; -- default: -- assert(0 && "invalid cryptotype passed to krb5int_old_crypto_length"); -- return 0; -- } --} -- --krb5_error_code --krb5int_old_encrypt(const struct krb5_keytypes *ktp, krb5_key key, -- krb5_keyusage usage, const krb5_data *ivec, -- krb5_crypto_iov *data, size_t num_data) --{ -- const struct krb5_enc_provider *enc = ktp->enc; -- const struct krb5_hash_provider *hash = ktp->hash; -- krb5_error_code ret; -- krb5_crypto_iov *header, *trailer, *padding; -- krb5_data checksum, confounder, crcivec = empty_data(); -- unsigned int plainlen, padsize; -- size_t i; -- -- /* E(Confounder | Checksum | Plaintext | Pad) */ -- -- plainlen = enc->block_size + hash->hashsize; -- for (i = 0; i < num_data; i++) { -- krb5_crypto_iov *iov = &data[i]; -- -- if (iov->flags == KRB5_CRYPTO_TYPE_DATA) -- plainlen += iov->data.length; -- } -- -- header = krb5int_c_locate_iov(data, num_data, KRB5_CRYPTO_TYPE_HEADER); -- if (header == NULL || -- header->data.length < enc->block_size + hash->hashsize) -- return KRB5_BAD_MSIZE; -- -- /* Trailer may be absent. */ -- trailer = krb5int_c_locate_iov(data, num_data, KRB5_CRYPTO_TYPE_TRAILER); -- if (trailer != NULL) -- trailer->data.length = 0; -- -- /* Check that the input data is correctly padded. */ -- padsize = krb5_roundup(plainlen, enc->block_size) - plainlen; -- padding = krb5int_c_locate_iov(data, num_data, KRB5_CRYPTO_TYPE_PADDING); -- if (padsize > 0 && (padding == NULL || padding->data.length < padsize)) -- return KRB5_BAD_MSIZE; -- if (padding) { -- padding->data.length = padsize; -- memset(padding->data.data, 0, padsize); -- } -- -- /* Generate a confounder in the header block. */ -- confounder = make_data(header->data.data, enc->block_size); -- ret = krb5_c_random_make_octets(0, &confounder); -- if (ret != 0) -- goto cleanup; -- checksum = make_data(header->data.data + enc->block_size, hash->hashsize); -- memset(checksum.data, 0, hash->hashsize); -- -- /* Checksum the plaintext with zeroed checksum and padding. */ -- ret = hash->hash(data, num_data, &checksum); -- if (ret != 0) -- goto cleanup; -- -- /* Use the key as the ivec for des-cbc-crc if none was provided. */ -- if (key->keyblock.enctype == ENCTYPE_DES_CBC_CRC && ivec == NULL) { -- ret = alloc_data(&crcivec, key->keyblock.length); -- if (ret != 0) -- goto cleanup; -- memcpy(crcivec.data, key->keyblock.contents, key->keyblock.length); -- ivec = &crcivec; -- } -- -- ret = enc->encrypt(key, ivec, data, num_data); -- if (ret != 0) -- goto cleanup; -- --cleanup: -- zapfree(crcivec.data, crcivec.length); -- return ret; --} -- --krb5_error_code --krb5int_old_decrypt(const struct krb5_keytypes *ktp, krb5_key key, -- krb5_keyusage usage, const krb5_data *ivec, -- krb5_crypto_iov *data, size_t num_data) --{ -- const struct krb5_enc_provider *enc = ktp->enc; -- const struct krb5_hash_provider *hash = ktp->hash; -- krb5_error_code ret; -- krb5_crypto_iov *header, *trailer; -- krb5_data checksum, crcivec = empty_data(); -- char *saved_checksum = NULL; -- -- /* Check that the input data is correctly padded. */ -- if (iov_total_length(data, num_data, FALSE) % enc->block_size != 0) -- return KRB5_BAD_MSIZE; -- -- header = krb5int_c_locate_iov(data, num_data, KRB5_CRYPTO_TYPE_HEADER); -- if (header == NULL || -- header->data.length != enc->block_size + hash->hashsize) -- return KRB5_BAD_MSIZE; -- -- trailer = krb5int_c_locate_iov(data, num_data, KRB5_CRYPTO_TYPE_TRAILER); -- if (trailer != NULL && trailer->data.length != 0) -- return KRB5_BAD_MSIZE; -- -- /* Use the key as the ivec for des-cbc-crc if none was provided. */ -- if (key->keyblock.enctype == ENCTYPE_DES_CBC_CRC && ivec == NULL) { -- ret = alloc_data(&crcivec, key->keyblock.length); -- memcpy(crcivec.data, key->keyblock.contents, key->keyblock.length); -- ivec = &crcivec; -- } -- -- /* Decrypt the ciphertext. */ -- ret = enc->decrypt(key, ivec, data, num_data); -- if (ret != 0) -- goto cleanup; -- -- /* Save the checksum, then zero it out in the plaintext. */ -- checksum = make_data(header->data.data + enc->block_size, hash->hashsize); -- saved_checksum = k5memdup(checksum.data, checksum.length, &ret); -- if (saved_checksum == NULL) -- goto cleanup; -- memset(checksum.data, 0, checksum.length); -- -- /* -- * Checksum the plaintext (with zeroed checksum field), storing the result -- * back into the plaintext field we just zeroed out. Then compare it to -- * the saved checksum. -- */ -- ret = hash->hash(data, num_data, &checksum); -- if (k5_bcmp(checksum.data, saved_checksum, checksum.length) != 0) { -- ret = KRB5KRB_AP_ERR_BAD_INTEGRITY; -- goto cleanup; -- } -- --cleanup: -- zapfree(crcivec.data, crcivec.length); -- zapfree(saved_checksum, hash->hashsize); -- return ret; --} -diff --git a/src/lib/crypto/krb/etypes.c b/src/lib/crypto/krb/etypes.c -index 8f44c37e7..fc278783b 100644 ---- a/src/lib/crypto/krb/etypes.c -+++ b/src/lib/crypto/krb/etypes.c -@@ -35,42 +35,6 @@ - - /* Deprecations come from RFC 6649 and RFC 8249. */ - const struct krb5_keytypes krb5int_enctypes_list[] = { -- { ENCTYPE_DES_CBC_CRC, -- "des-cbc-crc", { 0 }, "DES cbc mode with CRC-32", -- &krb5int_enc_des, &krb5int_hash_crc32, -- 16, -- krb5int_old_crypto_length, krb5int_old_encrypt, krb5int_old_decrypt, -- krb5int_des_string_to_key, k5_rand2key_des, -- krb5int_des_prf, -- CKSUMTYPE_RSA_MD5_DES, -- ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, -- { ENCTYPE_DES_CBC_MD4, -- "des-cbc-md4", { 0 }, "DES cbc mode with RSA-MD4", -- &krb5int_enc_des, &krb5int_hash_md4, -- 16, -- krb5int_old_crypto_length, krb5int_old_encrypt, krb5int_old_decrypt, -- krb5int_des_string_to_key, k5_rand2key_des, -- krb5int_des_prf, -- CKSUMTYPE_RSA_MD4_DES, -- ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, -- { ENCTYPE_DES_CBC_MD5, -- "des-cbc-md5", { "des" }, "DES cbc mode with RSA-MD5", -- &krb5int_enc_des, &krb5int_hash_md5, -- 16, -- krb5int_old_crypto_length, krb5int_old_encrypt, krb5int_old_decrypt, -- krb5int_des_string_to_key, k5_rand2key_des, -- krb5int_des_prf, -- CKSUMTYPE_RSA_MD5_DES, -- ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, -- { ENCTYPE_DES_CBC_RAW, -- "des-cbc-raw", { 0 }, "DES cbc mode raw", -- &krb5int_enc_des, NULL, -- 16, -- krb5int_raw_crypto_length, krb5int_raw_encrypt, krb5int_raw_decrypt, -- krb5int_des_string_to_key, k5_rand2key_des, -- krb5int_des_prf, -- 0, -- ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, - { ENCTYPE_DES3_CBC_RAW, - "des3-cbc-raw", { 0 }, "Triple DES cbc mode raw", - &krb5int_enc_des3, NULL, -@@ -92,16 +56,6 @@ const struct krb5_keytypes krb5int_enctypes_list[] = { - CKSUMTYPE_HMAC_SHA1_DES3, - ETYPE_DEPRECATED, 112 }, - -- { ENCTYPE_DES_HMAC_SHA1, -- "des-hmac-sha1", { 0 }, "DES with HMAC/sha1", -- &krb5int_enc_des, &krb5int_hash_sha1, -- 8, -- krb5int_dk_crypto_length, krb5int_dk_encrypt, krb5int_dk_decrypt, -- krb5int_dk_string_to_key, k5_rand2key_des, -- NULL, /*PRF*/ -- 0, -- ETYPE_WEAK | ETYPE_DEPRECATED, 56 }, -- - /* rc4-hmac uses a 128-bit key, but due to weaknesses in the RC4 cipher, we - * consider its strength degraded and assign it an SSF value of 64. */ - { ENCTYPE_ARCFOUR_HMAC, -diff --git a/src/lib/crypto/krb/s2k_des.c b/src/lib/crypto/krb/s2k_des.c -deleted file mode 100644 -index d5c29befc..000000000 ---- a/src/lib/crypto/krb/s2k_des.c -+++ /dev/null -@@ -1,691 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* -- * Copyright (C) 1998 by the FundsXpress, INC. -- * -- * All rights reserved. -- * -- * Export of this software from the United States of America may require -- * a specific license from the United States Government. It is the -- * responsibility of any person or organization contemplating export to -- * obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of FundsXpress. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. FundsXpress makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- * -- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR -- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED -- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. -- */ -- --/* -- * RFC 3961 and AFS string to key. These are not standard crypto primitives -- * (RFC 3961 string-to-key is implemented in OpenSSL for historical reasons but -- * it doesn't get weak keys right), so we have to implement them here. -- */ -- --#include --#include "crypto_int.h" -- --#undef min --#define min(a,b) ((a)>(b)?(b):(a)) -- --/* Compute a CBC checksum of in (with length len) using the specified key and -- * ivec. The result is written into out. */ --static krb5_error_code --des_cbc_mac(const unsigned char *keybits, const unsigned char *ivec, -- const unsigned char *in, size_t len, unsigned char *out) --{ -- krb5_error_code ret; -- krb5_keyblock kb; -- krb5_key key; -- krb5_crypto_iov iov[2]; -- unsigned char zero[8] = { 0, 0, 0, 0, 0, 0, 0, 0 }; -- krb5_data outd, ivecd; -- -- /* Make a key from keybits. */ -- kb.magic = KV5M_KEYBLOCK; -- kb.enctype = ENCTYPE_DES_CBC_CRC; -- kb.length = 8; -- kb.contents = (unsigned char *)keybits; -- ret = krb5_k_create_key(NULL, &kb, &key); -- if (ret) -- return ret; -- -- /* Make iovs for the input data, padding it out to the block size. */ -- iov[0].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[0].data = make_data((unsigned char *)in, len); -- iov[1].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[1].data = make_data(zero, krb5_roundup(len, 8) - len); -- -- /* Make krb5_data structures for the ivec and output. */ -- ivecd = make_data((unsigned char *)ivec, 8); -- outd = make_data(out, 8); -- -- /* Call the cbc_mac operation of the module's DES enc-provider. */ -- ret = krb5int_enc_des.cbc_mac(key, iov, 2, &ivecd, &outd); -- krb5_k_free_key(NULL, key); -- return ret; --} -- --/*** AFS string-to-key constants ***/ -- --/* Initial permutation */ --static const char IP[] = { -- 58,50,42,34,26,18,10, 2, -- 60,52,44,36,28,20,12, 4, -- 62,54,46,38,30,22,14, 6, -- 64,56,48,40,32,24,16, 8, -- 57,49,41,33,25,17, 9, 1, -- 59,51,43,35,27,19,11, 3, -- 61,53,45,37,29,21,13, 5, -- 63,55,47,39,31,23,15, 7, --}; -- --/* Final permutation, FP = IP^(-1) */ --static const char FP[] = { -- 40, 8,48,16,56,24,64,32, -- 39, 7,47,15,55,23,63,31, -- 38, 6,46,14,54,22,62,30, -- 37, 5,45,13,53,21,61,29, -- 36, 4,44,12,52,20,60,28, -- 35, 3,43,11,51,19,59,27, -- 34, 2,42,10,50,18,58,26, -- 33, 1,41, 9,49,17,57,25, --}; -- --/* -- * Permuted-choice 1 from the key bits to yield C and D. -- * Note that bits 8,16... are left out: They are intended for a parity check. -- */ --static const char PC1_C[] = { -- 57,49,41,33,25,17, 9, -- 1,58,50,42,34,26,18, -- 10, 2,59,51,43,35,27, -- 19,11, 3,60,52,44,36, --}; -- --static const char PC1_D[] = { -- 63,55,47,39,31,23,15, -- 7,62,54,46,38,30,22, -- 14, 6,61,53,45,37,29, -- 21,13, 5,28,20,12, 4, --}; -- --/* Sequence of shifts used for the key schedule */ --static const char shifts[] = { -- 1,1,2,2,2,2,2,2,1,2,2,2,2,2,2,1, --}; -- --/* Permuted-choice 2, to pick out the bits from the CD array that generate the -- * key schedule */ --static const char PC2_C[] = { -- 14,17,11,24, 1, 5, -- 3,28,15, 6,21,10, -- 23,19,12, 4,26, 8, -- 16, 7,27,20,13, 2, --}; -- --static const char PC2_D[] = { -- 41,52,31,37,47,55, -- 30,40,51,45,33,48, -- 44,49,39,56,34,53, -- 46,42,50,36,29,32, --}; -- --/* The E bit-selection table */ --static const char e[] = { -- 32, 1, 2, 3, 4, 5, -- 4, 5, 6, 7, 8, 9, -- 8, 9,10,11,12,13, -- 12,13,14,15,16,17, -- 16,17,18,19,20,21, -- 20,21,22,23,24,25, -- 24,25,26,27,28,29, -- 28,29,30,31,32, 1, --}; -- --/* P is a permutation on the selected combination of the current L and key. */ --static const char P[] = { -- 16, 7,20,21, -- 29,12,28,17, -- 1,15,23,26, -- 5,18,31,10, -- 2, 8,24,14, -- 32,27, 3, 9, -- 19,13,30, 6, -- 22,11, 4,25, --}; -- --/* -- * The 8 selection functions. -- * For some reason, they give a 0-origin -- * index, unlike everything else. -- */ --static const char S[8][64] = { -- {14, 4,13, 1, 2,15,11, 8, 3,10, 6,12, 5, 9, 0, 7, -- 0,15, 7, 4,14, 2,13, 1,10, 6,12,11, 9, 5, 3, 8, -- 4, 1,14, 8,13, 6, 2,11,15,12, 9, 7, 3,10, 5, 0, -- 15,12, 8, 2, 4, 9, 1, 7, 5,11, 3,14,10, 0, 6,13}, -- -- {15, 1, 8,14, 6,11, 3, 4, 9, 7, 2,13,12, 0, 5,10, -- 3,13, 4, 7,15, 2, 8,14,12, 0, 1,10, 6, 9,11, 5, -- 0,14, 7,11,10, 4,13, 1, 5, 8,12, 6, 9, 3, 2,15, -- 13, 8,10, 1, 3,15, 4, 2,11, 6, 7,12, 0, 5,14, 9}, -- -- {10, 0, 9,14, 6, 3,15, 5, 1,13,12, 7,11, 4, 2, 8, -- 13, 7, 0, 9, 3, 4, 6,10, 2, 8, 5,14,12,11,15, 1, -- 13, 6, 4, 9, 8,15, 3, 0,11, 1, 2,12, 5,10,14, 7, -- 1,10,13, 0, 6, 9, 8, 7, 4,15,14, 3,11, 5, 2,12}, -- -- { 7,13,14, 3, 0, 6, 9,10, 1, 2, 8, 5,11,12, 4,15, -- 13, 8,11, 5, 6,15, 0, 3, 4, 7, 2,12, 1,10,14, 9, -- 10, 6, 9, 0,12,11, 7,13,15, 1, 3,14, 5, 2, 8, 4, -- 3,15, 0, 6,10, 1,13, 8, 9, 4, 5,11,12, 7, 2,14}, -- -- { 2,12, 4, 1, 7,10,11, 6, 8, 5, 3,15,13, 0,14, 9, -- 14,11, 2,12, 4, 7,13, 1, 5, 0,15,10, 3, 9, 8, 6, -- 4, 2, 1,11,10,13, 7, 8,15, 9,12, 5, 6, 3, 0,14, -- 11, 8,12, 7, 1,14, 2,13, 6,15, 0, 9,10, 4, 5, 3}, -- -- {12, 1,10,15, 9, 2, 6, 8, 0,13, 3, 4,14, 7, 5,11, -- 10,15, 4, 2, 7,12, 9, 5, 6, 1,13,14, 0,11, 3, 8, -- 9,14,15, 5, 2, 8,12, 3, 7, 0, 4,10, 1,13,11, 6, -- 4, 3, 2,12, 9, 5,15,10,11,14, 1, 7, 6, 0, 8,13}, -- -- { 4,11, 2,14,15, 0, 8,13, 3,12, 9, 7, 5,10, 6, 1, -- 13, 0,11, 7, 4, 9, 1,10,14, 3, 5,12, 2,15, 8, 6, -- 1, 4,11,13,12, 3, 7,14,10,15, 6, 8, 0, 5, 9, 2, -- 6,11,13, 8, 1, 4,10, 7, 9, 5, 0,15,14, 2, 3,12}, -- -- {13, 2, 8, 4, 6,15,11, 1,10, 9, 3,14, 5, 0,12, 7, -- 1,15,13, 8,10, 3, 7, 4,12, 5, 6,11, 0,14, 9, 2, -- 7,11, 4, 1, 9,12,14, 2, 0, 6,10,13,15, 3, 5, 8, -- 2, 1,14, 7, 4,10, 8,13,15,12, 9, 0, 3, 5, 6,11}, --}; -- -- --/* Set up the key schedule from the key. */ --static void --afs_crypt_setkey(char *key, char *E, char (*KS)[48]) --{ -- int i, j, k, t; -- char C[28], D[28]; /* Used to calculate key schedule. */ -- -- /* -- * First, generate C and D by permuting -- * the key. The low order bit of each -- * 8-bit char is not used, so C and D are only 28 -- * bits apiece. -- */ -- for (i = 0; i < 28; i++) { -- C[i] = key[PC1_C[i] - 1]; -- D[i] = key[PC1_D[i] - 1]; -- } -- /* -- * To generate Ki, rotate C and D according -- * to schedule and pick up a permutation -- * using PC2. -- */ -- for (i = 0; i < 16; i++) { -- /* Rotate. */ -- for (k = 0; k < shifts[i]; k++) { -- t = C[0]; -- for (j = 0; j < 28 - 1; j++) -- C[j] = C[j + 1]; -- C[27] = t; -- t = D[0]; -- for (j = 0; j < 28 - 1; j++) -- D[j] = D[j + 1]; -- D[27] = t; -- } -- /* Get Ki. Note C and D are concatenated. */ -- for (j = 0; j < 24; j++) { -- KS[i][j] = C[PC2_C[j]-1]; -- KS[i][j+24] = D[PC2_D[j]-28-1]; -- } -- } -- -- memcpy(E, e, 48); --} -- --/* -- * The payoff: encrypt a block. -- */ -- --static void --afs_encrypt_block(char *block, char *E, char (*KS)[48]) --{ -- const long edflag = 0; -- int i, ii; -- int t, j, k; -- char tempL[32]; -- char f[32]; -- char L[64]; /* Current block divided into two halves */ -- char *const R = &L[32]; -- /* The combination of the key and the input, before selection. */ -- char preS[48]; -- -- /* First, permute the bits in the input. */ -- for (j = 0; j < 64; j++) -- L[j] = block[IP[j] - 1]; -- /* Perform an encryption operation 16 times. */ -- for (ii = 0; ii < 16; ii++) { -- /* Set direction. */ -- i = (edflag) ? 15 - ii : ii; -- /* Save the R array, which will be the new L. */ -- memcpy(tempL, R, 32); -- /* Expand R to 48 bits using the E selector; exclusive-or with the -- * current key bits. */ -- for (j = 0; j < 48; j++) -- preS[j] = R[E[j] - 1] ^ KS[i][j]; -- /* -- * The pre-select bits are now considered in 8 groups of 6 bits each. -- * The 8 selection functions map these 6-bit quantities into 4-bit -- * quantities and the results permuted to make an f(R, K). The -- * indexing into the selection functions is peculiar; it could be -- * simplified by rewriting the tables. -- */ -- for (j = 0; j < 8; j++) { -- t = 6 * j; -- k = S[j][(preS[t + 0] << 5) + -- (preS[t + 1] << 3) + -- (preS[t + 2] << 2) + -- (preS[t + 3] << 1) + -- (preS[t + 4] << 0) + -- (preS[t + 5] << 4)]; -- t = 4 * j; -- f[t + 0] = (k >> 3) & 1; -- f[t + 1] = (k >> 2) & 1; -- f[t + 2] = (k >> 1) & 1; -- f[t + 3] = (k >> 0) & 1; -- } -- /* The new R is L ^ f(R, K). The f here has to be permuted first, -- * though. */ -- for (j = 0; j < 32; j++) -- R[j] = L[j] ^ f[P[j] - 1]; -- /* Finally, the new L (the original R) is copied back. */ -- memcpy(L, tempL, 32); -- } -- /* The output L and R are reversed. */ -- for (j = 0; j < 32; j++) { -- t = L[j]; -- L[j] = R[j]; -- R[j] = t; -- } -- /* The final output gets the inverse permutation of the very original. */ -- for (j = 0; j < 64; j++) -- block[j] = L[FP[j] - 1]; --} -- --/* iobuf must be at least 16 bytes */ --static char * --afs_crypt(const char *pw, const char *salt, char *iobuf) --{ -- int i, j, c; -- int temp; -- char block[66]; -- char E[48]; -- char KS[16][48]; /* Key schedule, generated from key */ -- -- for (i = 0; i < 66; i++) -- block[i] = 0; -- for (i = 0; (c = *pw) != '\0' && i < 64; pw++){ -- for(j = 0; j < 7; j++, i++) -- block[i] = (c >> (6 - j)) & 01; -- i++; -- } -- -- afs_crypt_setkey(block, E, KS); -- -- for (i = 0; i < 66; i++) -- block[i] = 0; -- -- for (i = 0; i < 2; i++) { -- c = *salt++; -- iobuf[i] = c; -- if (c > 'Z') -- c -= 6; -- if (c > '9') -- c -= 7; -- c -= '.'; -- for (j = 0; j < 6; j++) { -- if ((c >> j) & 01) { -- temp = E[6 * i + j]; -- E[6 * i + j] = E[6 * i + j + 24]; -- E[6 * i + j + 24] = temp; -- } -- } -- } -- -- for (i = 0; i < 25; i++) -- afs_encrypt_block(block, E, KS); -- -- for (i = 0; i < 11; i++) { -- c = 0; -- for (j = 0; j < 6; j++) { -- c <<= 1; -- c |= block[6 * i + j]; -- } -- c += '.'; -- if (c > '9') -- c += 7; -- if (c > 'Z') -- c += 6; -- iobuf[i + 2] = c; -- } -- iobuf[i + 2] = 0; -- if (iobuf[1] == 0) -- iobuf[1] = iobuf[0]; -- return iobuf; --} -- --static krb5_error_code --afs_s2k_oneblock(const krb5_data *data, const krb5_data *salt, -- unsigned char *key_out) --{ -- unsigned int i; -- unsigned char password[9]; /* trailing nul for crypt() */ -- char afs_crypt_buf[16]; -- -- /* -- * Run afs_crypt and use the first eight returned bytes after the copy of -- * the (fixed) salt. -- * -- * Since the returned bytes are alphanumeric, the output is limited to -- * 2**48 possibilities; for each byte, only 64 possible values can be used. -- */ -- -- memset(password, 0, sizeof(password)); -- if (salt->length > 0) -- memcpy(password, salt->data, min(salt->length, 8)); -- for (i = 0; i < 8; i++) { -- if (isupper(password[i])) -- password[i] = tolower(password[i]); -- } -- for (i = 0; i < data->length; i++) -- password[i] ^= data->data[i]; -- for (i = 0; i < 8; i++) { -- if (password[i] == '\0') -- password[i] = 'X'; -- } -- password[8] = '\0'; -- /* Out-of-bounds salt characters are equivalent to a salt string -- * of "p1". */ -- strncpy((char *)key_out, -- (char *)afs_crypt((char *)password, "#~", afs_crypt_buf) + 2, 8); -- for (i = 0; i < 8; i++) -- key_out[i] <<= 1; -- /* Fix up key parity again. */ -- k5_des_fixup_key_parity(key_out); -- zap(password, sizeof(password)); -- return 0; --} -- --static krb5_error_code --afs_s2k_multiblock(const krb5_data *data, const krb5_data *salt, -- unsigned char *key_out) --{ -- krb5_error_code ret; -- unsigned char ivec[8], tkey[8], *password; -- size_t pw_len = salt->length + data->length; -- unsigned int i, j; -- -- /* Do a CBC checksum, twice, and use the result as the new key. */ -- -- password = malloc(pw_len); -- if (!password) -- return ENOMEM; -- -- if (data->length > 0) -- memcpy(password, data->data, data->length); -- for (i = data->length, j = 0; j < salt->length; i++, j++) { -- password[i] = salt->data[j]; -- if (isupper(password[i])) -- password[i] = tolower(password[i]); -- } -- -- memcpy(ivec, "kerberos", sizeof(ivec)); -- memcpy(tkey, ivec, sizeof(tkey)); -- k5_des_fixup_key_parity(tkey); -- ret = des_cbc_mac(tkey, ivec, password, pw_len, tkey); -- if (ret) -- goto cleanup; -- -- memcpy(ivec, tkey, sizeof(ivec)); -- k5_des_fixup_key_parity(tkey); -- ret = des_cbc_mac(tkey, ivec, password, pw_len, key_out); -- if (ret) -- goto cleanup; -- k5_des_fixup_key_parity(key_out); -- --cleanup: -- zapfree(password, pw_len); -- return ret; --} -- --static krb5_error_code --afs_s2k(const krb5_data *data, const krb5_data *salt, unsigned char *key_out) --{ -- if (data->length <= 8) -- return afs_s2k_oneblock(data, salt, key_out); -- else -- return afs_s2k_multiblock(data, salt, key_out); --} -- --static krb5_error_code --des_s2k(const krb5_data *pw, const krb5_data *salt, unsigned char *key_out) --{ -- union { -- /* 8 "forward" bytes, 8 "reverse" bytes */ -- unsigned char uc[16]; -- krb5_ui_4 ui[4]; -- } temp; -- unsigned int i; -- krb5_ui_4 x, y, z; -- unsigned char *p, *copy; -- size_t copylen; -- krb5_error_code ret; -- -- /* As long as the architecture is big-endian or little-endian, it -- doesn't matter which it is. Think of it as reversing the -- bytes, and also reversing the bits within each byte. But this -- current algorithm is dependent on having four 8-bit char values -- exactly overlay a 32-bit integral type. */ -- if (sizeof(temp.uc) != sizeof(temp.ui) -- || (unsigned char)~0 != 0xFF -- || (krb5_ui_4)~(krb5_ui_4)0 != 0xFFFFFFFF -- || (temp.uc[0] = 1, temp.uc[1] = 2, temp.uc[2] = 3, temp.uc[3] = 4, -- !(temp.ui[0] == 0x01020304 -- || temp.ui[0] == 0x04030201))) -- abort(); --#define FETCH4(VAR, IDX) VAR = temp.ui[IDX/4] --#define PUT4(VAR, IDX) temp.ui[IDX/4] = VAR -- -- copylen = pw->length + salt->length; -- /* Don't need NUL termination, at this point we're treating it as -- a byte array, not a string. */ -- copy = malloc(copylen); -- if (copy == NULL) -- return ENOMEM; -- if (pw->length > 0) -- memcpy(copy, pw->data, pw->length); -- if (salt->length > 0) -- memcpy(copy + pw->length, salt->data, salt->length); -- -- memset(&temp, 0, sizeof(temp)); -- p = temp.uc; -- /* Handle the fan-fold xor operation by splitting the data into -- forward and reverse sections, and combine them later, rather -- than having to do the reversal over and over again. */ -- for (i = 0; i < copylen; i++) { -- *p++ ^= copy[i]; -- if (p == temp.uc+16) { -- p = temp.uc; --#ifdef PRINT_TEST_VECTORS -- { -- int j; -- printf("after %d input bytes:\nforward block:\t", i+1); -- for (j = 0; j < 8; j++) -- printf(" %02x", temp.uc[j] & 0xff); -- printf("\nreverse block:\t"); -- for (j = 8; j < 16; j++) -- printf(" %02x", temp.uc[j] & 0xff); -- printf("\n"); -- } --#endif -- } -- } -- --#ifdef PRINT_TEST_VECTORS -- if (p != temp.uc) { -- int j; -- printf("at end, after %d input bytes:\nforward block:\t", i); -- for (j = 0; j < 8; j++) -- printf(" %02x", temp.uc[j] & 0xff); -- printf("\nreverse block:\t"); -- for (j = 8; j < 16; j++) -- printf(" %02x", temp.uc[j] & 0xff); -- printf("\n"); -- } --#endif --#define REVERSE(VAR) \ -- { \ -- krb5_ui_4 old = VAR, temp1 = 0; \ -- int j; \ -- for (j = 0; j < 32; j++) { \ -- temp1 = (temp1 << 1) | (old & 1); \ -- old >>= 1; \ -- } \ -- VAR = temp1; \ -- } -- -- FETCH4 (x, 8); -- FETCH4 (y, 12); -- /* Ignore high bits of each input byte. */ -- x &= 0x7F7F7F7F; -- y &= 0x7F7F7F7F; -- /* Reverse the bit strings -- after this, y is "before" x. */ -- REVERSE (x); -- REVERSE (y); --#ifdef PRINT_TEST_VECTORS -- { -- int j; -- union { unsigned char uc[4]; krb5_ui_4 ui; } t2; -- printf("after reversal, reversed block:\n\t\t"); -- t2.ui = y; -- for (j = 0; j < 4; j++) -- printf(" %02x", t2.uc[j] & 0xff); -- t2.ui = x; -- for (j = 0; j < 4; j++) -- printf(" %02x", t2.uc[j] & 0xff); -- printf("\n"); -- } --#endif -- /* Ignored bits are now at the bottom of each byte, where we'll -- * put the parity bits. Good. */ -- FETCH4 (z, 0); -- z &= 0x7F7F7F7F; -- /* Ignored bits for z are at the top of each byte; fix that. */ -- z <<= 1; -- /* Finish the fan-fold xor for these four bytes. */ -- z ^= y; -- PUT4 (z, 0); -- /* Now do the second four bytes. */ -- FETCH4 (z, 4); -- z &= 0x7F7F7F7F; -- /* Ignored bits for z are at the top of each byte; fix that. */ -- z <<= 1; -- /* Finish the fan-fold xor for these four bytes. */ -- z ^= x; -- PUT4 (z, 4); -- --#ifdef PRINT_TEST_VECTORS -- { -- int j; -- printf("after reversal, combined block:\n\t\t"); -- for (j = 0; j < 8; j++) -- printf(" %02x", temp.uc[j] & 0xff); -- printf("\n"); -- } --#endif -- --#define FIXUP(k) (k5_des_fixup_key_parity(k), \ -- k5_des_is_weak_key(k) ? (k[7] ^= 0xF0) : 0) -- -- /* Now temp.cb is the temporary key, with invalid parity. */ -- FIXUP(temp.uc); -- --#ifdef PRINT_TEST_VECTORS -- { -- int j; -- printf("after fixing parity and weak keys:\n\t\t"); -- for (j = 0; j < 8; j++) -- printf(" %02x", temp.uc[j] & 0xff); -- printf("\n"); -- } --#endif -- -- ret = des_cbc_mac(temp.uc, temp.uc, copy, copylen, temp.uc); -- if (ret) -- goto cleanup; -- --#ifdef PRINT_TEST_VECTORS -- { -- int j; -- printf("cbc checksum:\n\t\t"); -- for (j = 0; j < 8; j++) -- printf(" %02x", temp.uc[j] & 0xff); -- printf("\n"); -- } --#endif -- -- FIXUP(temp.uc); -- --#ifdef PRINT_TEST_VECTORS -- { -- int j; -- printf("after fixing parity and weak keys:\n\t\t"); -- for (j = 0; j < 8; j++) -- printf(" %02x", temp.uc[j] & 0xff); -- printf("\n"); -- } --#endif -- -- memcpy(key_out, temp.uc, 8); -- --cleanup: -- zap(&temp, sizeof(temp)); -- zapfree(copy, copylen); -- return ret; --} -- --krb5_error_code --krb5int_des_string_to_key(const struct krb5_keytypes *ktp, -- const krb5_data *string, const krb5_data *salt, -- const krb5_data *parm, krb5_keyblock *keyblock) --{ -- int type; -- -- if (parm != NULL) { -- if (parm->length != 1) -- return KRB5_ERR_BAD_S2K_PARAMS; -- type = parm->data[0]; -- if (type != 0 && type != 1) -- return KRB5_ERR_BAD_S2K_PARAMS; -- } else -- type = 0; -- -- /* Use AFS string to key if we were told to. */ -- if (type == 1) -- return afs_s2k(string, salt, keyblock->contents); -- -- return des_s2k(string, salt, keyblock->contents); --} -diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports -index 90afdf5f7..63804299f 100644 ---- a/src/lib/crypto/libk5crypto.exports -+++ b/src/lib/crypto/libk5crypto.exports -@@ -85,7 +85,6 @@ krb5_k_prf - krb5_k_reference_key - krb5_k_verify_checksum - krb5_k_verify_checksum_iov --mit_crc32 - krb5int_aes_encrypt - krb5int_aes_decrypt - krb5int_enc_des3 -diff --git a/src/lib/crypto/openssl/enc_provider/Makefile.in b/src/lib/crypto/openssl/enc_provider/Makefile.in -index b9e28c9cd..a9069d22d 100644 ---- a/src/lib/crypto/openssl/enc_provider/Makefile.in -+++ b/src/lib/crypto/openssl/enc_provider/Makefile.in -@@ -3,21 +3,18 @@ BUILDTOP=$(REL)..$(S)..$(S)..$(S).. - LOCALINCLUDES = -I$(srcdir)/../../krb -I$(srcdir)/.. - - STLIBOBJS= \ -- des.o \ - des3.o \ - rc4.o \ - aes.o \ - camellia.o - - OBJS= \ -- $(OUTPRE)des.$(OBJEXT) \ - $(OUTPRE)des3.$(OBJEXT) \ - $(OUTPRE)aes.$(OBJEXT) \ - $(OUTPRE)camellia.$(OBJEXT) \ - $(OUTPRE)rc4.$(OBJEXT) - - SRCS= \ -- $(srcdir)/des.c \ - $(srcdir)/des3.c \ - $(srcdir)/aes.c \ - $(srcdir)/camellia.c \ -diff --git a/src/lib/crypto/openssl/enc_provider/deps b/src/lib/crypto/openssl/enc_provider/deps -index 428fcf6f5..1c28cc842 100644 ---- a/src/lib/crypto/openssl/enc_provider/deps -+++ b/src/lib/crypto/openssl/enc_provider/deps -@@ -1,17 +1,6 @@ - # - # Generated makefile dependencies follow. - # --des.so des.po $(OUTPRE)des.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ -- $(srcdir)/../crypto_mod.h $(top_srcdir)/include/k5-buf.h \ -- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h des.c - des3.so des3.po $(OUTPRE)des3.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ -diff --git a/src/lib/crypto/openssl/enc_provider/des.c b/src/lib/crypto/openssl/enc_provider/des.c -deleted file mode 100644 -index a662db512..000000000 ---- a/src/lib/crypto/openssl/enc_provider/des.c -+++ /dev/null -@@ -1,218 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* lib/crypto/openssl/enc_provider/des.c */ --/* -- * Copyright (C) 2009 by the Massachusetts Institute of Technology. -- * All rights reserved. -- * -- * Export of this software from the United States of America may -- * require a specific license from the United States Government. -- * It is the responsibility of any person or organization contemplating -- * export to obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of M.I.T. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. Furthermore if you modify this software you must label -- * your software as modified software and not distribute it in such a -- * fashion that it might be confused with the original M.I.T. software. -- * M.I.T. makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- */ -- --/* -- * Copyright (C) 1998 by the FundsXpress, INC. -- * -- * All rights reserved. -- * -- * Export of this software from the United States of America may require -- * a specific license from the United States Government. It is the -- * responsibility of any person or organization contemplating export to -- * obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of FundsXpress. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. FundsXpress makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- * -- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR -- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED -- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. -- */ -- --#include "crypto_int.h" --#include --#include -- --#define DES_BLOCK_SIZE 8 --#define DES_KEY_SIZE 8 --#define DES_KEY_BYTES 7 -- --static krb5_error_code --validate(krb5_key key, const krb5_data *ivec, const krb5_crypto_iov *data, -- size_t num_data, krb5_boolean *empty) --{ -- size_t input_length = iov_total_length(data, num_data, FALSE); -- -- if (key->keyblock.length != DES_KEY_SIZE) -- return(KRB5_BAD_KEYSIZE); -- if ((input_length%DES_BLOCK_SIZE) != 0) -- return(KRB5_BAD_MSIZE); -- if (ivec && (ivec->length != 8)) -- return(KRB5_BAD_MSIZE); -- -- *empty = (input_length == 0); -- return 0; --} -- --static krb5_error_code --k5_des_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, -- size_t num_data) --{ -- int ret, olen = DES_BLOCK_SIZE; -- unsigned char iblock[DES_BLOCK_SIZE], oblock[DES_BLOCK_SIZE]; -- struct iov_cursor cursor; -- EVP_CIPHER_CTX *ctx; -- krb5_boolean empty; -- -- ret = validate(key, ivec, data, num_data, &empty); -- if (ret != 0 || empty) -- return ret; -- -- ctx = EVP_CIPHER_CTX_new(); -- if (ctx == NULL) -- return ENOMEM; -- -- ret = EVP_EncryptInit_ex(ctx, EVP_des_cbc(), NULL, -- key->keyblock.contents, (ivec && ivec->data) ? (unsigned char*)ivec->data : NULL); -- if (!ret) { -- EVP_CIPHER_CTX_free(ctx); -- return KRB5_CRYPTO_INTERNAL; -- } -- -- EVP_CIPHER_CTX_set_padding(ctx, 0); -- -- k5_iov_cursor_init(&cursor, data, num_data, DES_BLOCK_SIZE, FALSE); -- while (k5_iov_cursor_get(&cursor, iblock)) { -- ret = EVP_EncryptUpdate(ctx, oblock, &olen, iblock, DES_BLOCK_SIZE); -- if (!ret) -- break; -- k5_iov_cursor_put(&cursor, oblock); -- } -- -- if (ivec != NULL) -- memcpy(ivec->data, oblock, DES_BLOCK_SIZE); -- -- EVP_CIPHER_CTX_free(ctx); -- -- zap(iblock, sizeof(iblock)); -- zap(oblock, sizeof(oblock)); -- -- if (ret != 1) -- return KRB5_CRYPTO_INTERNAL; -- return 0; --} -- --static krb5_error_code --k5_des_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, -- size_t num_data) --{ -- int ret, olen = DES_BLOCK_SIZE; -- unsigned char iblock[DES_BLOCK_SIZE], oblock[DES_BLOCK_SIZE]; -- struct iov_cursor cursor; -- EVP_CIPHER_CTX *ctx; -- krb5_boolean empty; -- -- ret = validate(key, ivec, data, num_data, &empty); -- if (ret != 0 || empty) -- return ret; -- -- ctx = EVP_CIPHER_CTX_new(); -- if (ctx == NULL) -- return ENOMEM; -- -- ret = EVP_DecryptInit_ex(ctx, EVP_des_cbc(), NULL, -- key->keyblock.contents, -- (ivec) ? (unsigned char*)ivec->data : NULL); -- if (!ret) { -- EVP_CIPHER_CTX_free(ctx); -- return KRB5_CRYPTO_INTERNAL; -- } -- -- EVP_CIPHER_CTX_set_padding(ctx,0); -- -- k5_iov_cursor_init(&cursor, data, num_data, DES_BLOCK_SIZE, FALSE); -- while (k5_iov_cursor_get(&cursor, iblock)) { -- ret = EVP_DecryptUpdate(ctx, oblock, &olen, iblock, DES_BLOCK_SIZE); -- if (!ret) -- break; -- k5_iov_cursor_put(&cursor, oblock); -- } -- -- if (ivec != NULL) -- memcpy(ivec->data, iblock, DES_BLOCK_SIZE); -- -- EVP_CIPHER_CTX_free(ctx); -- -- zap(iblock, sizeof(iblock)); -- zap(oblock, sizeof(oblock)); -- -- if (ret != 1) -- return KRB5_CRYPTO_INTERNAL; -- return 0; --} -- --static krb5_error_code --k5_des_cbc_mac(krb5_key key, const krb5_crypto_iov *data, size_t num_data, -- const krb5_data *ivec, krb5_data *output) --{ -- int ret; -- struct iov_cursor cursor; -- DES_cblock blockY, blockB; -- DES_key_schedule sched; -- krb5_boolean empty; -- -- ret = validate(key, ivec, data, num_data, &empty); -- if (ret != 0) -- return ret; -- -- if (output->length != DES_BLOCK_SIZE) -- return KRB5_BAD_MSIZE; -- -- if (DES_set_key((DES_cblock *)key->keyblock.contents, &sched) != 0) -- return KRB5_CRYPTO_INTERNAL; -- -- if (ivec != NULL) -- memcpy(blockY, ivec->data, DES_BLOCK_SIZE); -- else -- memset(blockY, 0, DES_BLOCK_SIZE); -- -- k5_iov_cursor_init(&cursor, data, num_data, DES_BLOCK_SIZE, FALSE); -- while (k5_iov_cursor_get(&cursor, blockB)) { -- store_64_n(load_64_n(blockB) ^ load_64_n(blockY), blockB); -- DES_ecb_encrypt(&blockB, &blockY, &sched, 1); -- } -- -- memcpy(output->data, blockY, DES_BLOCK_SIZE); -- return 0; --} -- --const struct krb5_enc_provider krb5int_enc_des = { -- DES_BLOCK_SIZE, -- DES_KEY_BYTES, DES_KEY_SIZE, -- k5_des_encrypt, -- k5_des_decrypt, -- k5_des_cbc_mac, -- krb5int_des_init_state, -- krb5int_default_free_state --}; -diff --git a/src/lib/crypto/openssl/hash_provider/Makefile.in b/src/lib/crypto/openssl/hash_provider/Makefile.in -index 7762e20a5..f7245fbd1 100644 ---- a/src/lib/crypto/openssl/hash_provider/Makefile.in -+++ b/src/lib/crypto/openssl/hash_provider/Makefile.in -@@ -2,15 +2,11 @@ mydir=lib$(S)crypto$(S)openssl$(S)hash_provider - BUILDTOP=$(REL)..$(S)..$(S)..$(S).. - LOCALINCLUDES = -I$(srcdir)/../../krb -I$(srcdir)/.. - --STLIBOBJS= \ -- hash_crc32.o \ -- hash_evp.o -+STLIBOBJS= hash_evp.o - --OBJS= $(OUTPRE)hash_crc32.$(OBJEXT) \ -- $(OUTPRE)hash_evp.$(OBJEXT) -+OBJS= $(OUTPRE)hash_evp.$(OBJEXT) - --SRCS= $(srcdir)/hash_crc32.c \ -- $(srcdir)/hash_evp.c -+SRCS= $(srcdir)/hash_evp.c - - all-unix: all-libobjs - -diff --git a/src/lib/crypto/openssl/hash_provider/deps b/src/lib/crypto/openssl/hash_provider/deps -index 87dd02012..690574cab 100644 ---- a/src/lib/crypto/openssl/hash_provider/deps -+++ b/src/lib/crypto/openssl/hash_provider/deps -@@ -1,18 +1,6 @@ - # - # Generated makefile dependencies follow. - # --hash_crc32.so hash_crc32.po $(OUTPRE)hash_crc32.$(OBJEXT): \ -- $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ -- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(srcdir)/../crypto_mod.h \ -- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- hash_crc32.c - hash_evp.so hash_evp.po $(OUTPRE)hash_evp.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -diff --git a/src/lib/crypto/openssl/hash_provider/hash_crc32.c b/src/lib/crypto/openssl/hash_provider/hash_crc32.c -deleted file mode 100644 -index 4013843ed..000000000 ---- a/src/lib/crypto/openssl/hash_provider/hash_crc32.c -+++ /dev/null -@@ -1,56 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* -- * Copyright (C) 1998 by the FundsXpress, INC. -- * -- * All rights reserved. -- * -- * Export of this software from the United States of America may require -- * a specific license from the United States Government. It is the -- * responsibility of any person or organization contemplating export to -- * obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of FundsXpress. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. FundsXpress makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- * -- * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR -- * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED -- * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE. -- */ -- --#include "crypto_int.h" -- --static krb5_error_code --k5_crc32_hash(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) --{ -- unsigned long c; -- unsigned int i; -- -- if (output->length != CRC32_CKSUM_LENGTH) -- return(KRB5_CRYPTO_INTERNAL); -- -- c = 0; -- for (i = 0; i < num_data; i++) { -- const krb5_crypto_iov *iov = &data[i]; -- -- if (SIGN_IOV(iov)) -- mit_crc32(iov->data.data, iov->data.length, &c); -- } -- -- store_32_le(c, output->data); -- return(0); --} -- --const struct krb5_hash_provider krb5int_hash_crc32 = { -- "CRC32", -- CRC32_CKSUM_LENGTH, -- 1, -- k5_crc32_hash --}; -diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index 5baa6cecf..439ae6aeb 100644 ---- a/src/lib/gssapi/krb5/accept_sec_context.c -+++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -1011,9 +1011,6 @@ kg_accept_krb5(minor_status, context_handle, - } - - switch (negotiated_etype) { -- case ENCTYPE_DES_CBC_MD5: -- case ENCTYPE_DES_CBC_MD4: -- case ENCTYPE_DES_CBC_CRC: - case ENCTYPE_DES3_CBC_SHA1: - case ENCTYPE_ARCFOUR_HMAC: - case ENCTYPE_ARCFOUR_HMAC_EXP: -diff --git a/src/lib/gssapi/krb5/gssapiP_krb5.h b/src/lib/gssapi/krb5/gssapiP_krb5.h -index e92be88b4..2647434ba 100644 ---- a/src/lib/gssapi/krb5/gssapiP_krb5.h -+++ b/src/lib/gssapi/krb5/gssapiP_krb5.h -@@ -120,17 +120,17 @@ extern const gss_OID_set kg_all_mechs; - /* These are to be stored in little-endian order, i.e., des-mac is - stored as 02 00. */ - enum sgn_alg { -- SGN_ALG_DES_MAC_MD5 = 0x0000, -- SGN_ALG_MD2_5 = 0x0001, -- SGN_ALG_DES_MAC = 0x0002, -- SGN_ALG_3 = 0x0003, /* not published */ -+ /* SGN_ALG_DES_MAC_MD5 = 0x0000, */ -+ /* SGN_ALG_MD2_5 = 0x0001, */ -+ /* SGN_ALG_DES_MAC = 0x0002, */ -+ /* SGN_ALG_3 = 0x0003, /\* not published *\/ */ - SGN_ALG_HMAC_MD5 = 0x0011, /* microsoft w2k; */ - SGN_ALG_HMAC_SHA1_DES3_KD = 0x0004 - }; - enum seal_alg { - SEAL_ALG_NONE = 0xffff, -- SEAL_ALG_DES = 0x0000, -- SEAL_ALG_1 = 0x0001, /* not published */ -+ /* SEAL_ALG_DES = 0x0000, */ -+ /* SEAL_ALG_1 = 0x0001, /\* not published *\/ */ - SEAL_ALG_MICROSOFT_RC4 = 0x0010, /* microsoft w2k; */ - SEAL_ALG_DES3KD = 0x0002 - }; -@@ -147,12 +147,12 @@ enum seal_alg { - #define KG_USAGE_INITIATOR_SIGN 25 - - enum qop { -- GSS_KRB5_INTEG_C_QOP_MD5 = 0x0001, /* *partial* MD5 = "MD2.5" */ -- GSS_KRB5_INTEG_C_QOP_DES_MD5 = 0x0002, -- GSS_KRB5_INTEG_C_QOP_DES_MAC = 0x0003, -+ /* GSS_KRB5_INTEG_C_QOP_MD5 = 0x0001, */ -+ /* GSS_KRB5_INTEG_C_QOP_DES_MD5 = 0x0002, */ -+ /* GSS_KRB5_INTEG_C_QOP_DES_MAC = 0x0003, */ - GSS_KRB5_INTEG_C_QOP_HMAC_SHA1 = 0x0004, - GSS_KRB5_INTEG_C_QOP_MASK = 0x00ff, -- GSS_KRB5_CONF_C_QOP_DES = 0x0100, -+ /* GSS_KRB5_CONF_C_QOP_DES = 0x0100, */ - GSS_KRB5_CONF_C_QOP_DES3_KD = 0x0200, - GSS_KRB5_CONF_C_QOP_MASK = 0xff00 - }; -diff --git a/src/lib/gssapi/krb5/k5seal.c b/src/lib/gssapi/krb5/k5seal.c -index 4da531b58..d1cdce486 100644 ---- a/src/lib/gssapi/krb5/k5seal.c -+++ b/src/lib/gssapi/krb5/k5seal.c -@@ -71,7 +71,6 @@ make_seal_token_v1 (krb5_context context, - char *data_ptr; - krb5_data plaind; - krb5_checksum md5cksum; -- krb5_checksum cksum; - /* msglen contains the message length - * we are signing/encrypting. tmsglen - * contains the length of the message -@@ -137,12 +136,8 @@ make_seal_token_v1 (krb5_context context, - - /* pad the plaintext, encrypt if needed, and stick it in the token */ - -- /* initialize the the cksum */ -+ /* initialize the the checksum */ - switch (signalg) { -- case SGN_ALG_DES_MAC_MD5: -- case SGN_ALG_MD2_5: -- md5cksum.checksum_type = CKSUMTYPE_RSA_MD5; -- break; - case SGN_ALG_HMAC_SHA1_DES3_KD: - md5cksum.checksum_type = CKSUMTYPE_HMAC_SHA1_DES3; - break; -@@ -152,7 +147,6 @@ make_seal_token_v1 (krb5_context context, - sign_usage = 15; - break; - default: -- case SGN_ALG_DES_MAC: - abort (); - } - -@@ -203,26 +197,6 @@ make_seal_token_v1 (krb5_context context, - return(code); - } - switch(signalg) { -- case SGN_ALG_DES_MAC_MD5: -- case 3: -- -- code = kg_encrypt_inplace(context, seq, KG_USAGE_SEAL, -- (g_OID_equal(oid, gss_mech_krb5_old) ? -- seq->keyblock.contents : NULL), -- md5cksum.contents, 16); -- if (code) { -- krb5_free_checksum_contents(context, &md5cksum); -- xfree (plain); -- gssalloc_free(t); -- return code; -- } -- -- cksum.length = cksum_size; -- cksum.contents = md5cksum.contents + 16 - cksum.length; -- -- memcpy(ptr+14, cksum.contents, cksum.length); -- break; -- - case SGN_ALG_HMAC_SHA1_DES3_KD: - /* - * Using key derivation, the call to krb5_c_make_checksum -diff --git a/src/lib/gssapi/krb5/k5sealiov.c b/src/lib/gssapi/krb5/k5sealiov.c -index 88caa856f..9bb2ee109 100644 ---- a/src/lib/gssapi/krb5/k5sealiov.c -+++ b/src/lib/gssapi/krb5/k5sealiov.c -@@ -145,10 +145,6 @@ make_seal_token_v1_iov(krb5_context context, - - /* initialize the checksum */ - switch (ctx->signalg) { -- case SGN_ALG_DES_MAC_MD5: -- case SGN_ALG_MD2_5: -- md5cksum.checksum_type = CKSUMTYPE_RSA_MD5; -- break; - case SGN_ALG_HMAC_SHA1_DES3_KD: - md5cksum.checksum_type = CKSUMTYPE_HMAC_SHA1_DES3; - break; -@@ -158,7 +154,6 @@ make_seal_token_v1_iov(krb5_context context, - sign_usage = 15; - break; - default: -- case SGN_ALG_DES_MAC: - abort (); - } - -@@ -183,21 +178,6 @@ make_seal_token_v1_iov(krb5_context context, - goto cleanup; - - switch (ctx->signalg) { -- case SGN_ALG_DES_MAC_MD5: -- case SGN_ALG_3: -- code = kg_encrypt_inplace(context, ctx->seq, KG_USAGE_SEAL, -- (g_OID_equal(ctx->mech_used, -- gss_mech_krb5_old) ? -- ctx->seq->keyblock.contents : NULL), -- md5cksum.contents, 16); -- if (code != 0) -- goto cleanup; -- -- cksum.length = ctx->cksum_size; -- cksum.contents = md5cksum.contents + 16 - cksum.length; -- -- memcpy(ptr + 14, cksum.contents, cksum.length); -- break; - case SGN_ALG_HMAC_SHA1_DES3_KD: - assert(md5cksum.length == ctx->cksum_size); - memcpy(ptr + 14, md5cksum.contents, md5cksum.length); -diff --git a/src/lib/gssapi/krb5/k5unseal.c b/src/lib/gssapi/krb5/k5unseal.c -index 57720c2ea..9b183bc33 100644 ---- a/src/lib/gssapi/krb5/k5unseal.c -+++ b/src/lib/gssapi/krb5/k5unseal.c -@@ -76,7 +76,6 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, - int sealalg; - int bad_pad = 0; - gss_buffer_desc token; -- krb5_checksum cksum; - krb5_checksum md5cksum; - krb5_data plaind; - char *data_ptr; -@@ -132,7 +131,6 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, - but few enough that we can try them all. */ - - if ((ctx->sealalg == SEAL_ALG_NONE && signalg > 1) || -- (ctx->sealalg == SEAL_ALG_1 && signalg != SGN_ALG_3) || - (ctx->sealalg == SEAL_ALG_DES3KD && - signalg != SGN_ALG_HMAC_SHA1_DES3_KD)|| - (ctx->sealalg == SEAL_ALG_MICROSOFT_RC4 && -@@ -142,16 +140,11 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, - } - - switch (signalg) { -- case SGN_ALG_DES_MAC_MD5: -- case SGN_ALG_MD2_5: - case SGN_ALG_HMAC_MD5: - cksum_len = 8; - if (toktype != KG_TOK_SEAL_MSG) - sign_usage = 15; - break; -- case SGN_ALG_3: -- cksum_len = 16; -- break; - case SGN_ALG_HMAC_SHA1_DES3_KD: - cksum_len = 20; - break; -@@ -260,12 +253,6 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, - - /* initialize the the cksum */ - switch (signalg) { -- case SGN_ALG_DES_MAC_MD5: -- case SGN_ALG_MD2_5: -- case SGN_ALG_DES_MAC: -- case SGN_ALG_3: -- md5cksum.checksum_type = CKSUMTYPE_RSA_MD5; -- break; - case SGN_ALG_HMAC_MD5: - md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; - break; -@@ -282,105 +269,6 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, - md5cksum.length = sumlen; - - switch (signalg) { -- case SGN_ALG_DES_MAC_MD5: -- case SGN_ALG_3: -- /* compute the checksum of the message */ -- -- /* 8 = bytes of token body to be checksummed according to spec */ -- -- if (! (data_ptr = xmalloc(8 + plainlen))) { -- if (sealalg != 0xffff) -- xfree(plain); -- if (toktype == KG_TOK_SEAL_MSG) -- gssalloc_free(token.value); -- *minor_status = ENOMEM; -- return(GSS_S_FAILURE); -- } -- -- (void) memcpy(data_ptr, ptr-2, 8); -- -- (void) memcpy(data_ptr+8, plain, plainlen); -- -- plaind.length = 8 + plainlen; -- plaind.data = data_ptr; -- code = krb5_k_make_checksum(context, md5cksum.checksum_type, -- ctx->seq, sign_usage, -- &plaind, &md5cksum); -- xfree(data_ptr); -- -- if (code) { -- if (toktype == KG_TOK_SEAL_MSG) -- gssalloc_free(token.value); -- *minor_status = code; -- return(GSS_S_FAILURE); -- } -- -- code = kg_encrypt_inplace(context, ctx->seq, KG_USAGE_SEAL, -- (g_OID_equal(ctx->mech_used, -- gss_mech_krb5_old) ? -- ctx->seq->keyblock.contents : NULL), -- md5cksum.contents, 16); -- if (code) { -- krb5_free_checksum_contents(context, &md5cksum); -- if (toktype == KG_TOK_SEAL_MSG) -- gssalloc_free(token.value); -- *minor_status = code; -- return GSS_S_FAILURE; -- } -- -- if (signalg == 0) -- cksum.length = 8; -- else -- cksum.length = 16; -- cksum.contents = md5cksum.contents + 16 - cksum.length; -- -- code = k5_bcmp(cksum.contents, ptr + 14, cksum.length); -- break; -- -- case SGN_ALG_MD2_5: -- if (!ctx->seed_init && -- (code = kg_make_seed(context, ctx->subkey, ctx->seed))) { -- krb5_free_checksum_contents(context, &md5cksum); -- if (sealalg != 0xffff) -- xfree(plain); -- if (toktype == KG_TOK_SEAL_MSG) -- gssalloc_free(token.value); -- *minor_status = code; -- return GSS_S_FAILURE; -- } -- -- if (! (data_ptr = xmalloc(sizeof(ctx->seed) + 8 + plainlen))) { -- krb5_free_checksum_contents(context, &md5cksum); -- if (sealalg == 0) -- xfree(plain); -- if (toktype == KG_TOK_SEAL_MSG) -- gssalloc_free(token.value); -- *minor_status = ENOMEM; -- return(GSS_S_FAILURE); -- } -- (void) memcpy(data_ptr, ptr-2, 8); -- (void) memcpy(data_ptr+8, ctx->seed, sizeof(ctx->seed)); -- (void) memcpy(data_ptr+8+sizeof(ctx->seed), plain, plainlen); -- plaind.length = 8 + sizeof(ctx->seed) + plainlen; -- plaind.data = data_ptr; -- krb5_free_checksum_contents(context, &md5cksum); -- code = krb5_k_make_checksum(context, md5cksum.checksum_type, -- ctx->seq, sign_usage, -- &plaind, &md5cksum); -- xfree(data_ptr); -- -- if (code) { -- if (sealalg == 0) -- xfree(plain); -- if (toktype == KG_TOK_SEAL_MSG) -- gssalloc_free(token.value); -- *minor_status = code; -- return(GSS_S_FAILURE); -- } -- -- code = k5_bcmp(md5cksum.contents, ptr + 14, 8); -- /* Falls through to defective-token?? */ -- - default: - *minor_status = 0; - return(GSS_S_DEFECTIVE_TOKEN); -diff --git a/src/lib/gssapi/krb5/k5unsealiov.c b/src/lib/gssapi/krb5/k5unsealiov.c -index f15d2db69..85a9574f3 100644 ---- a/src/lib/gssapi/krb5/k5unsealiov.c -+++ b/src/lib/gssapi/krb5/k5unsealiov.c -@@ -44,7 +44,6 @@ kg_unseal_v1_iov(krb5_context context, - unsigned char *ptr; - int sealalg; - int signalg; -- krb5_checksum cksum; - krb5_checksum md5cksum; - size_t cksum_len = 0; - size_t conflen = 0; -@@ -54,8 +53,8 @@ kg_unseal_v1_iov(krb5_context context, - size_t sumlen; - krb5_keyusage sign_usage = KG_USAGE_SIGN; - -- md5cksum.length = cksum.length = 0; -- md5cksum.contents = cksum.contents = NULL; -+ md5cksum.length = 0; -+ md5cksum.contents = NULL; - - header = kg_locate_header_iov(iov, iov_count, toktype); - assert(header != NULL); -@@ -103,7 +102,6 @@ kg_unseal_v1_iov(krb5_context context, - } - - if ((ctx->sealalg == SEAL_ALG_NONE && signalg > 1) || -- (ctx->sealalg == SEAL_ALG_1 && signalg != SGN_ALG_3) || - (ctx->sealalg == SEAL_ALG_DES3KD && - signalg != SGN_ALG_HMAC_SHA1_DES3_KD)|| - (ctx->sealalg == SEAL_ALG_MICROSOFT_RC4 && -@@ -113,16 +111,11 @@ kg_unseal_v1_iov(krb5_context context, - } - - switch (signalg) { -- case SGN_ALG_DES_MAC_MD5: -- case SGN_ALG_MD2_5: - case SGN_ALG_HMAC_MD5: - cksum_len = 8; - if (toktype != KG_TOK_WRAP_MSG) - sign_usage = 15; - break; -- case SGN_ALG_3: -- cksum_len = 16; -- break; - case SGN_ALG_HMAC_SHA1_DES3_KD: - cksum_len = 20; - break; -@@ -189,12 +182,6 @@ kg_unseal_v1_iov(krb5_context context, - /* initialize the checksum */ - - switch (signalg) { -- case SGN_ALG_DES_MAC_MD5: -- case SGN_ALG_MD2_5: -- case SGN_ALG_DES_MAC: -- case SGN_ALG_3: -- md5cksum.checksum_type = CKSUMTYPE_RSA_MD5; -- break; - case SGN_ALG_HMAC_MD5: - md5cksum.checksum_type = CKSUMTYPE_HMAC_MD5_ARCFOUR; - break; -@@ -223,23 +210,6 @@ kg_unseal_v1_iov(krb5_context context, - } - - switch (signalg) { -- case SGN_ALG_DES_MAC_MD5: -- case SGN_ALG_3: -- code = kg_encrypt_inplace(context, ctx->seq, KG_USAGE_SEAL, -- (g_OID_equal(ctx->mech_used, -- gss_mech_krb5_old) ? -- ctx->seq->keyblock.contents : NULL), -- md5cksum.contents, 16); -- if (code != 0) { -- retval = GSS_S_FAILURE; -- goto cleanup; -- } -- -- cksum.length = cksum_len; -- cksum.contents = md5cksum.contents + 16 - cksum.length; -- -- code = k5_bcmp(cksum.contents, ptr + 14, cksum.length); -- break; - case SGN_ALG_HMAC_SHA1_DES3_KD: - case SGN_ALG_HMAC_MD5: - code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); -diff --git a/src/lib/gssapi/krb5/util_crypt.c b/src/lib/gssapi/krb5/util_crypt.c -index 0cebde12a..80954aff7 100644 ---- a/src/lib/gssapi/krb5/util_crypt.c -+++ b/src/lib/gssapi/krb5/util_crypt.c -@@ -74,27 +74,6 @@ kg_copy_keys(krb5_context context, krb5_gss_ctx_id_rec *ctx, krb5_key subkey) - return 0; - } - --static krb5_error_code --kg_derive_des_enc_key(krb5_context context, krb5_key subkey, krb5_key *out) --{ -- krb5_error_code code; -- krb5_keyblock *keyblock; -- unsigned int i; -- -- *out = NULL; -- -- code = krb5_k_key_keyblock(context, subkey, &keyblock); -- if (code != 0) -- return code; -- -- for (i = 0; i < keyblock->length; i++) -- keyblock->contents[i] ^= 0xF0; -- -- code = krb5_k_create_key(context, keyblock, out); -- krb5_free_keyblock(context, keyblock); -- return code; --} -- - krb5_error_code - kg_setup_keys(krb5_context context, krb5_gss_ctx_id_rec *ctx, krb5_key subkey, - krb5_cksumtype *cksumtype) -@@ -118,26 +97,6 @@ kg_setup_keys(krb5_context context, krb5_gss_ctx_id_rec *ctx, krb5_key subkey, - return code; - - switch (subkey->keyblock.enctype) { -- case ENCTYPE_DES_CBC_MD5: -- case ENCTYPE_DES_CBC_MD4: -- case ENCTYPE_DES_CBC_CRC: -- krb5_k_free_key(context, ctx->seq); -- code = krb5_k_create_key(context, &subkey->keyblock, &ctx->seq); -- if (code != 0) -- return code; -- -- krb5_k_free_key(context, ctx->enc); -- code = kg_derive_des_enc_key(context, subkey, &ctx->enc); -- if (code != 0) -- return code; -- -- ctx->enc->keyblock.enctype = ENCTYPE_DES_CBC_RAW; -- ctx->seq->keyblock.enctype = ENCTYPE_DES_CBC_RAW; -- ctx->signalg = SGN_ALG_DES_MAC_MD5; -- ctx->cksum_size = 8; -- ctx->sealalg = SEAL_ALG_DES; -- -- break; - case ENCTYPE_DES3_CBC_SHA1: - code = kg_copy_keys(context, ctx, subkey); - if (code != 0) -diff --git a/src/lib/kadm5/kadm_rpc_xdr.c b/src/lib/kadm5/kadm_rpc_xdr.c -index 745ee857e..f22ea7f1f 100644 ---- a/src/lib/kadm5/kadm_rpc_xdr.c -+++ b/src/lib/kadm5/kadm_rpc_xdr.c -@@ -1109,16 +1109,6 @@ xdr_krb5_octet(XDR *xdrs, krb5_octet *objp) - bool_t - xdr_krb5_enctype(XDR *xdrs, krb5_enctype *objp) - { -- /* -- * This used to be xdr_krb5_keytype, but keytypes and enctypes have -- * been merged into only enctypes. However, randkey_principal -- * already ensures that only a key of ENCTYPE_DES_CBC_CRC will be -- * returned to v1 clients, and ENCTYPE_DES_CBC_CRC has the same -- * value as KEYTYPE_DES used too, which is what all v1 clients -- * expect. Therefore, IMHO, just encoding whatever enctype we get -- * is safe. -- */ -- - if (!xdr_int32(xdrs, (int32_t *) objp)) - return (FALSE); - return (TRUE); -diff --git a/src/lib/krb5/ccache/cc_mslsa.c b/src/lib/krb5/ccache/cc_mslsa.c -index 0d00c86d4..4367322b7 100644 ---- a/src/lib/krb5/ccache/cc_mslsa.c -+++ b/src/lib/krb5/ccache/cc_mslsa.c -@@ -1103,13 +1103,14 @@ GetMSTGT(krb5_context context, HANDLE LogonHandle, ULONG PackageId, KERB_EXTERNA - } - - if (krb5_get_tgs_ktypes(context, NULL, &etype_list)) { -- ptr = etype_list = NULL; -- etype = ENCTYPE_DES_CBC_CRC; -- } else { -- ptr = etype_list + 1; -- etype = *etype_list; -+ /* No enctypes - nothing we can do. */ -+ bIsLsaError = TRUE; -+ goto cleanup; - } - -+ ptr = etype_list + 1; -+ etype = *etype_list; -+ - while ( etype ) { - // Try once more but this time specify the Encryption Type - // (This will not store the retrieved tickets in the LSA cache unless -diff --git a/src/lib/krb5/krb/auth_con.c b/src/lib/krb5/krb/auth_con.c -index 1dfce631c..aa90454f3 100644 ---- a/src/lib/krb5/krb/auth_con.c -+++ b/src/lib/krb5/krb/auth_con.c -@@ -313,28 +313,11 @@ krb5_auth_con_getremoteseqnumber(krb5_context context, krb5_auth_context auth_co - krb5_error_code KRB5_CALLCONV - krb5_auth_con_initivector(krb5_context context, krb5_auth_context auth_context) - { -- krb5_error_code ret; -- krb5_enctype enctype; -- - if (auth_context->key == NULL) - return EINVAL; -- ret = krb5_c_init_state(context, &auth_context->key->keyblock, -- KRB5_KEYUSAGE_KRB_PRIV_ENCPART, -- &auth_context->cstate); -- if (ret) -- return ret; -- -- /* -- * Historically we used a zero-filled buffer of the enctype block size. -- * This matches every existing enctype except RC4 (which has a block size -- * of 1) and des-cbc-crc (which uses the key instead of a zero-filled -- * buffer). Special-case des-cbc-crc to remain interoperable. -- */ -- enctype = krb5_k_key_enctype(context, auth_context->key); -- if (enctype == ENCTYPE_DES_CBC_CRC) -- zap(auth_context->cstate.data, auth_context->cstate.length); -- -- return 0; -+ return krb5_c_init_state(context, &auth_context->key->keyblock, -+ KRB5_KEYUSAGE_KRB_PRIV_ENCPART, -+ &auth_context->cstate); - } - - krb5_error_code -diff --git a/src/lib/krb5/krb/gic_keytab.c b/src/lib/krb5/krb/gic_keytab.c -index e82f42581..1d70cf46f 100644 ---- a/src/lib/krb5/krb/gic_keytab.c -+++ b/src/lib/krb5/krb/gic_keytab.c -@@ -130,10 +130,6 @@ lookup_etypes_for_keytab(krb5_context context, krb5_keytab keytab, - } - etypes = p; - etypes[count++] = etype; -- /* All DES key types work with des-cbc-crc, which is more likely to be -- * accepted by the KDC (since MIT KDCs refuse des-cbc-md5). */ -- if (etype == ENCTYPE_DES_CBC_MD5 || etype == ENCTYPE_DES_CBC_MD4) -- etypes[count++] = ENCTYPE_DES_CBC_CRC; - etypes[count] = 0; - } - if (ret != KRB5_KT_END) -diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index 37405728c..b597dda54 100644 ---- a/src/lib/krb5/krb/init_ctx.c -+++ b/src/lib/krb5/krb/init_ctx.c -@@ -56,17 +56,12 @@ - #include "brand.c" - #include "../krb5_libinit.h" - --/* The des-mdX entries are last for now, because it's easy to -- configure KDCs to issue TGTs with des-mdX keys and then not accept -- them. This'll be fixed, but for better compatibility, let's prefer -- des-crc for now. */ - static krb5_enctype default_enctype_list[] = { - ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, - ENCTYPE_AES256_CTS_HMAC_SHA384_192, ENCTYPE_AES128_CTS_HMAC_SHA256_128, - ENCTYPE_DES3_CBC_SHA1, - ENCTYPE_ARCFOUR_HMAC, - ENCTYPE_CAMELLIA128_CTS_CMAC, ENCTYPE_CAMELLIA256_CTS_CMAC, -- ENCTYPE_DES_CBC_CRC, ENCTYPE_DES_CBC_MD5, ENCTYPE_DES_CBC_MD4, - 0 - }; - -@@ -483,10 +478,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, - /* Set all enctypes in the default list. */ - for (i = 0; default_list[i]; i++) - mod_list(default_list[i], sel, weak, &list); -- } else if (strcasecmp(token, "des") == 0) { -- mod_list(ENCTYPE_DES_CBC_CRC, sel, weak, &list); -- mod_list(ENCTYPE_DES_CBC_MD5, sel, weak, &list); -- mod_list(ENCTYPE_DES_CBC_MD4, sel, weak, &list); - } else if (strcasecmp(token, "des3") == 0) { - mod_list(ENCTYPE_DES3_CBC_SHA1, sel, weak, &list); - } else if (strcasecmp(token, "aes") == 0) { -diff --git a/src/lib/krb5/krb/mk_req_ext.c b/src/lib/krb5/krb/mk_req_ext.c -index dce092781..9fc6a0e52 100644 ---- a/src/lib/krb5/krb/mk_req_ext.c -+++ b/src/lib/krb5/krb/mk_req_ext.c -@@ -82,36 +82,6 @@ generate_authenticator(krb5_context, - krb5_enctype *desired_etypes, - krb5_enctype tkt_enctype); - --/* Return the checksum type for the AP request, or 0 to use the enctype's -- * mandatory checksum. */ --static krb5_cksumtype --ap_req_cksum(krb5_context context, krb5_auth_context auth_context, -- krb5_enctype enctype) --{ -- /* Use the configured checksum type if one was set. */ -- if (auth_context->req_cksumtype) -- return auth_context->req_cksumtype; -- -- /* -- * Otherwise choose based on the enctype. For interoperability with very -- * old implementations, use unkeyed MD4 or MD5 checkums for DES enctypes. -- * (The authenticator checksum does not have to be keyed since it is -- * contained within an encrypted blob.) -- */ -- switch (enctype) { -- case ENCTYPE_DES_CBC_CRC: -- case ENCTYPE_DES_CBC_MD5: -- return CKSUMTYPE_RSA_MD5; -- break; -- case ENCTYPE_DES_CBC_MD4: -- return CKSUMTYPE_RSA_MD4; -- break; -- default: -- /* Use the mandatory checksum type for the enctype. */ -- return 0; -- } --} -- - krb5_error_code KRB5_CALLCONV - krb5_mk_req_extended(krb5_context context, krb5_auth_context *auth_context, - krb5_flags ap_req_options, krb5_data *in_data, -@@ -198,15 +168,10 @@ krb5_mk_req_extended(krb5_context context, krb5_auth_context *auth_context, - checksum.length = in_data->length; - checksum.contents = (krb5_octet *) in_data->data; - } else { -- krb5_enctype enctype = krb5_k_key_enctype(context, -- (*auth_context)->key); -- krb5_cksumtype cksumtype = ap_req_cksum(context, *auth_context, -- enctype); -- if ((retval = krb5_k_make_checksum(context, -- cksumtype, -- (*auth_context)->key, -- KRB5_KEYUSAGE_AP_REQ_AUTH_CKSUM, -- in_data, &checksum))) -+ retval = krb5_k_make_checksum(context, 0, (*auth_context)->key, -+ KRB5_KEYUSAGE_AP_REQ_AUTH_CKSUM, -+ in_data, &checksum); -+ if (retval) - goto cleanup_cksum; - } - checksump = &checksum; -diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c -index 614ed4190..d8015c64a 100644 ---- a/src/lib/krb5/krb/s4u_creds.c -+++ b/src/lib/krb5/krb/s4u_creds.c -@@ -341,9 +341,6 @@ verify_s4u2self_reply(krb5_context context, - assert(req_s4u_user != NULL); - - switch (subkey->enctype) { -- case ENCTYPE_DES_CBC_CRC: -- case ENCTYPE_DES_CBC_MD4: -- case ENCTYPE_DES_CBC_MD5: - case ENCTYPE_DES3_CBC_SHA1: - case ENCTYPE_DES3_CBC_RAW: - case ENCTYPE_ARCFOUR_HMAC: -diff --git a/src/lib/krb5/krb/ser_ctx.c b/src/lib/krb5/krb/ser_ctx.c -index 39f656322..55491428b 100644 ---- a/src/lib/krb5/krb/ser_ctx.c -+++ b/src/lib/krb5/krb/ser_ctx.c -@@ -400,7 +400,7 @@ krb5_context_internalize(krb5_context kcontext, krb5_pointer *argp, krb5_octet * - } else - context->tgs_etypes = NULL; - -- /* Allowable checksum */ -+ /* Allowable clockskew */ - if ((kret = krb5_ser_unpack_int32(&ibuf, &bp, &remain))) - goto cleanup; - context->clockskew = (krb5_deltat) ibuf; -diff --git a/src/man/kdc.conf.man b/src/man/kdc.conf.man -index fd4dbb2e2..527d5d697 100644 ---- a/src/man/kdc.conf.man -+++ b/src/man/kdc.conf.man -@@ -441,13 +441,6 @@ marks the server principal as host\-based or the service is also - listed in \fBhost_based_services\fP\&. \fBno_host_referral = *\fP will - disable referral processing altogether. - .TP --\fBdes_crc_session_supported\fP --(Boolean value). If set to true, the KDC will assume that service --principals support des\-cbc\-crc for session key enctype negotiation --purposes. If \fBallow_weak_crypto\fP in libdefaults is --false, or if des\-cbc\-crc is not a permitted enctype, then this --variable has no effect. Defaults to true. New in release 1.11. --.TP - \fBreject_bad_transit\fP - (Boolean value.) If set to true, the KDC will check the list of - transited realms for cross\-realm tickets against the transit path -@@ -970,30 +963,6 @@ center; - |l|l|. - _ - T{ --des\-cbc\-crc --T} T{ --DES cbc mode with CRC\-32 (weak) --T} --_ --T{ --des\-cbc\-md4 --T} T{ --DES cbc mode with RSA\-MD4 (weak) --T} --_ --T{ --des\-cbc\-md5 --T} T{ --DES cbc mode with RSA\-MD5 (weak) --T} --_ --T{ --des\-cbc\-raw --T} T{ --DES cbc mode raw (weak) --T} --_ --T{ - des3\-cbc\-raw - T} T{ - Triple DES cbc mode raw (weak) -@@ -1006,12 +975,6 @@ Triple DES cbc mode with HMAC/sha1 - T} - _ - T{ --des\-hmac\-sha1 --T} T{ --DES with HMAC/sha1 (weak) --T} --_ --T{ - aes256\-cts\-hmac\-sha1\-96 aes256\-cts aes256\-sha1 - T} T{ - AES\-256 CTS mode with 96\-bit SHA\-1 HMAC -@@ -1060,12 +1023,6 @@ Camellia\-128 CTS mode with CMAC - T} - _ - T{ --des --T} T{ --The DES family: des\-cbc\-crc, des\-cbc\-md5, and des\-cbc\-md4 (weak) --T} --_ --T{ - des3 - T} T{ - The triple DES family: des3\-cbc\-sha1 -@@ -1096,8 +1053,8 @@ types for the variable in question. Types or families can be removed - from the current list by prefixing them with a minus sign ("\-"). - Types or families can be prefixed with a plus sign ("+") for symmetry; - it has the same meaning as just listing the type or family. For --example, "\fBDEFAULT \-des\fP" would be the default set of encryption --types with DES types removed, and "\fBdes3 DEFAULT\fP" would be the -+example, "\fBDEFAULT \-rc4\fP" would be the default set of encryption -+types with RC4 types removed, and "\fBdes3 DEFAULT\fP" would be the - default set of encryption types with triple DES types moved to the - front. - .sp -diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man -index 433f38d71..4bc190e32 100644 ---- a/src/man/krb5.conf.man -+++ b/src/man/krb5.conf.man -@@ -240,7 +240,7 @@ the client should request when making a TGS\-REQ, in order of - preference from highest to lowest. The list may be delimited with - commas or whitespace. See Encryption_types in - kdc.conf(5) for a list of the accepted values for this tag. --The default value is \fBaes256\-cts\-hmac\-sha1\-96 aes128\-cts\-hmac\-sha1\-96 aes256\-cts\-hmac\-sha384\-192 aes128\-cts\-hmac\-sha256\-128 des3\-cbc\-sha1 arcfour\-hmac\-md5 camellia256\-cts\-cmac camellia128\-cts\-cmac des\-cbc\-crc des\-cbc\-md5 des\-cbc\-md4\fP, but single\-DES encryption types -+The default value is \fBaes256\-cts\-hmac\-sha1\-96 aes128\-cts\-hmac\-sha1\-96 aes256\-cts\-hmac\-sha384\-192 aes128\-cts\-hmac\-sha256\-128 des3\-cbc\-sha1 arcfour\-hmac\-md5 camellia256\-cts\-cmac camellia128\-cts\-cmac\fP, but weak encryption types - will be implicitly removed from this list if the value of - \fBallow_weak_crypto\fP is false. - .sp -@@ -254,7 +254,7 @@ Identifies the supported list of session key encryption types that - the client should request when making an AS\-REQ, in order of - preference from highest to lowest. The format is the same as for - default_tgs_enctypes. The default value for this tag is --\fBaes256\-cts\-hmac\-sha1\-96 aes128\-cts\-hmac\-sha1\-96 aes256\-cts\-hmac\-sha384\-192 aes128\-cts\-hmac\-sha256\-128 des3\-cbc\-sha1 arcfour\-hmac\-md5 camellia256\-cts\-cmac camellia128\-cts\-cmac des\-cbc\-crc des\-cbc\-md5 des\-cbc\-md4\fP, but single\-DES encryption types will be implicitly -+\fBaes256\-cts\-hmac\-sha1\-96 aes128\-cts\-hmac\-sha1\-96 aes256\-cts\-hmac\-sha384\-192 aes128\-cts\-hmac\-sha256\-128 des3\-cbc\-sha1 arcfour\-hmac\-md5 camellia256\-cts\-cmac camellia128\-cts\-cmac\fP, but weak encryption types will be implicitly - removed from this list if the value of \fBallow_weak_crypto\fP is - false. - .sp -@@ -374,7 +374,7 @@ used across NATs. The default value is true. - \fBpermitted_enctypes\fP - Identifies all encryption types that are permitted for use in - session key encryption. The default value for this tag is --\fBaes256\-cts\-hmac\-sha1\-96 aes128\-cts\-hmac\-sha1\-96 aes256\-cts\-hmac\-sha384\-192 aes128\-cts\-hmac\-sha256\-128 des3\-cbc\-sha1 arcfour\-hmac\-md5 camellia256\-cts\-cmac camellia128\-cts\-cmac des\-cbc\-crc des\-cbc\-md5 des\-cbc\-md4\fP, but single\-DES encryption types will be implicitly -+\fBaes256\-cts\-hmac\-sha1\-96 aes128\-cts\-hmac\-sha1\-96 aes256\-cts\-hmac\-sha384\-192 aes128\-cts\-hmac\-sha256\-128 des3\-cbc\-sha1 arcfour\-hmac\-md5 camellia256\-cts\-cmac camellia128\-cts\-cmac\fP, but weak encryption types will be implicitly - removed from this list if the value of \fBallow_weak_crypto\fP is - false. - .TP -diff --git a/src/windows/leash/htmlhelp/html/Encryption_Types.htm b/src/windows/leash/htmlhelp/html/Encryption_Types.htm -index aad42a389..1aebdd0b4 100644 ---- a/src/windows/leash/htmlhelp/html/Encryption_Types.htm -+++ b/src/windows/leash/htmlhelp/html/Encryption_Types.htm -@@ -79,18 +79,6 @@ will have an entry in the Encryption type column.
    - Description - - -- des- -- The DES (Data Encryption Standard) --family is a symmetric block cipher. It was designed to handle only --56-bit keys which is not enough for modern computing power. It is now --considered to be weak encryption.
      --
    • des-cbc-crc (weak)
    • --
    • des-cbc-md5 (weak)
    • --
    • des-cbc-md4 (weak)
    • -- --
    -- -- - des3- - The triple DES family improves on - the original DES (Data Encryption Standard) by using 3 separate 56-bit -@@ -106,7 +94,7 @@ keys. Some modes of 3DES are considered weak while others are strong - - aes - The AES Advanced Encryption Standard --family, like DES and 3DES, is a symmetric block cipher and was designed -+family, like 3DES, is a symmetric block cipher and was designed - to replace them. It can use multiple key sizes. Kerberos specifies use - for 256-bit and 128-bit keys. -
      diff --git a/Remove-the-v4-and-afs3-salt-types.patch b/Remove-the-v4-and-afs3-salt-types.patch deleted file mode 100644 index e135f2e..0000000 --- a/Remove-the-v4-and-afs3-salt-types.patch +++ /dev/null @@ -1,509 +0,0 @@ -From 111e528c68393435be41f71f22f41b7a04ccad1e Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 24 May 2019 13:11:44 -0400 -Subject: [PATCH] Remove the v4 and afs3 salt types - -In preparation for removing single-DES support, remove the v4 and afs3 -salt types. The afs3 salt type could only be used with single-DES -keys, and the v4 salt type was only useful for single-DES keys from -krb4 databases. - -[ghudson@mit.edu: wrote commit message] - -ticket: 8808 -(cherry picked from commit e0a35ff48c09a26ebb9aefd7e98855a84574b8be) -[rharwood@redhat.com: release version conflict in man pages] ---- - doc/admin/conf_files/kdc_conf.rst | 2 - - src/include/kdb.h | 4 +- - src/kadmin/testing/proto/kdc.conf.proto | 2 +- - src/kdc/kdc_preauth.c | 40 +++++-------------- - .../api.current/chpass-principal-v2.exp | 8 ++-- - .../api.current/get-principal-v2.exp | 4 +- - src/lib/kdb/kdb5.c | 4 -- - src/lib/kdb/kdb_cpw.c | 16 +------- - src/lib/krb5/krb/str_conv.c | 2 - - src/lib/krb5/krb/t_get_etype_info.py | 7 ---- - src/man/kdc.conf.man | 14 +------ - src/tests/dejagnu/config/default.exp | 17 -------- - src/tests/t_etype_info.py | 24 +---------- - src/tests/t_keytab.py | 5 --- - src/tests/t_renprinc.py | 2 +- - src/tests/t_salt.py | 26 +----------- - src/util/k5test.py | 11 ----- - 17 files changed, 24 insertions(+), 164 deletions(-) - -diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst -index 72f002d4d..7fbc8eb79 100644 ---- a/doc/admin/conf_files/kdc_conf.rst -+++ b/doc/admin/conf_files/kdc_conf.rst -@@ -919,10 +919,8 @@ follows: - - ================= ============================================ - normal default for Kerberos Version 5 --v4 the only type used by Kerberos Version 4 (no salt) - norealm same as the default, without using realm information - onlyrealm uses only realm information as the salt --afs3 AFS version 3, only used for compatibility with Kerberos 4 in AFS - special generate a random salt - ================= ============================================ - -diff --git a/src/include/kdb.h b/src/include/kdb.h -index 9812a35e6..7749cfc99 100644 ---- a/src/include/kdb.h -+++ b/src/include/kdb.h -@@ -73,11 +73,11 @@ - - /* Salt types */ - #define KRB5_KDB_SALTTYPE_NORMAL 0 --#define KRB5_KDB_SALTTYPE_V4 1 -+/* #define KRB5_KDB_SALTTYPE_V4 1 */ - #define KRB5_KDB_SALTTYPE_NOREALM 2 - #define KRB5_KDB_SALTTYPE_ONLYREALM 3 - #define KRB5_KDB_SALTTYPE_SPECIAL 4 --#define KRB5_KDB_SALTTYPE_AFS3 5 -+/* #define KRB5_KDB_SALTTYPE_AFS3 5 */ - #define KRB5_KDB_SALTTYPE_CERTHASH 6 - - /* Attributes */ -diff --git a/src/kadmin/testing/proto/kdc.conf.proto b/src/kadmin/testing/proto/kdc.conf.proto -index 61283ac77..45df78b91 100644 ---- a/src/kadmin/testing/proto/kdc.conf.proto -+++ b/src/kadmin/testing/proto/kdc.conf.proto -@@ -12,5 +12,5 @@ - kadmind_port = 1751 - kpasswd_port = 1752 - master_key_type = des3-hmac-sha1 -- supported_enctypes = des3-hmac-sha1:normal des-cbc-crc:normal des-cbc-crc:v4 des-cbc-md5:normal des-cbc-raw:normal -+ supported_enctypes = des3-hmac-sha1:normal des-cbc-crc:normal des-cbc-md5:normal des-cbc-raw:normal - } -diff --git a/src/kdc/kdc_preauth.c b/src/kdc/kdc_preauth.c -index caf133c14..508a5cf89 100644 ---- a/src/kdc/kdc_preauth.c -+++ b/src/kdc/kdc_preauth.c -@@ -781,8 +781,8 @@ add_etype_info(krb5_context context, krb5_kdcpreauth_rock rock, - return add_pa_data_element(pa_list, pa); - } - --/* Add PW-SALT or AFS3-SALT entries to pa_list as appropriate for the request -- * and client principal. */ -+/* Add PW-SALT entries to pa_list as appropriate for the request and client -+ * principal. */ - static krb5_error_code - add_pw_salt(krb5_context context, krb5_kdcpreauth_rock rock, - krb5_pa_data ***pa_list) -@@ -801,21 +801,13 @@ add_pw_salt(krb5_context context, krb5_kdcpreauth_rock rock, - if (ret) - return 0; - -- if (salttype == KRB5_KDB_SALTTYPE_AFS3) { -- ret = alloc_pa_data(KRB5_PADATA_AFS3_SALT, salt->length + 1, &pa); -- if (ret) -- goto cleanup; -- memcpy(pa->contents, salt->data, salt->length); -- pa->contents[salt->length] = '\0'; -- } else { -- /* Steal memory from salt to make the pa-data entry. */ -- ret = alloc_pa_data(KRB5_PADATA_PW_SALT, 0, &pa); -- if (ret) -- goto cleanup; -- pa->length = salt->length; -- pa->contents = (uint8_t *)salt->data; -- salt->data = NULL; -- } -+ /* Steal memory from salt to make the pa-data entry. */ -+ ret = alloc_pa_data(KRB5_PADATA_PW_SALT, 0, &pa); -+ if (ret) -+ goto cleanup; -+ pa->length = salt->length; -+ pa->contents = (uint8_t *)salt->data; -+ salt->data = NULL; - - /* add_pa_data_element() claims pa on success or failure. */ - ret = add_pa_data_element(pa_list, pa); -@@ -1545,20 +1537,6 @@ _make_etype_info_entry(krb5_context context, - &salttype, &salt); - if (retval) - goto cleanup; -- if (etype_info2 && salttype == KRB5_KDB_SALTTYPE_AFS3) { -- switch (etype) { -- case ENCTYPE_DES_CBC_CRC: -- case ENCTYPE_DES_CBC_MD4: -- case ENCTYPE_DES_CBC_MD5: -- retval = alloc_data(&entry->s2kparams, 1); -- if (retval) -- goto cleanup; -- entry->s2kparams.data[0] = 1; -- break; -- default: -- break; -- } -- } - - entry->length = salt->length; - entry->salt = (unsigned char *)salt->data; -diff --git a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp -index 8361fb085..db899a1dc 100644 ---- a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp -+++ b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp -@@ -18,8 +18,8 @@ proc test200 {} { - - # I'd like to specify a long list of keysalt tuples and make sure - # that chpass does the right thing, but we can only use those -- # enctypes that krbtgt has a key for: des-cbc-crc:normal and -- # des-cbc-crc:v4, according to the prototype kdc.conf. -+ # enctypes that krbtgt has a key for: des-cbc-crc:normal -+ # according to the prototype kdc.conf. - if {! [cmd [format { - kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ - $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -@@ -53,10 +53,10 @@ proc test200 {} { - } - - # XXX Perhaps I should actually check the key type returned. -- if {$num_keys == 3} { -+ if {$num_keys == 2} { - pass "$test" - } else { -- fail "$test: $num_keys keys, should be 3" -+ fail "$test: $num_keys keys, should be 2" - } - if { ! [cmd {kadm5_destroy $server_handle}]} { - perror "$test: unexpected failure in destroy" -diff --git a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp -index 86c45f49e..8526897ed 100644 ---- a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp -+++ b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp -@@ -143,8 +143,8 @@ proc test101_102 {rpc} { - } - - set failed 0 -- if {$num_keys != 3} { -- fail "$test: num_keys $num_keys should be 3" -+ if {$num_keys != 2} { -+ fail "$test: num_keys $num_keys should be 2" - set failed 1 - } - for {set i 0} {$i < $num_keys} {incr i} { -diff --git a/src/lib/kdb/kdb5.c b/src/lib/kdb/kdb5.c -index da5332217..b81a44312 100644 ---- a/src/lib/kdb/kdb5.c -+++ b/src/lib/kdb/kdb5.c -@@ -2312,15 +2312,11 @@ krb5_dbe_compute_salt(krb5_context context, const krb5_key_data *key, - if (retval) - return retval; - break; -- case KRB5_KDB_SALTTYPE_V4: -- sdata = empty_data(); -- break; - case KRB5_KDB_SALTTYPE_NOREALM: - retval = krb5_principal2salt_norealm(context, princ, &sdata); - if (retval) - return retval; - break; -- case KRB5_KDB_SALTTYPE_AFS3: - case KRB5_KDB_SALTTYPE_ONLYREALM: - return krb5_copy_data(context, &princ->realm, salt_out); - case KRB5_KDB_SALTTYPE_SPECIAL: -diff --git a/src/lib/kdb/kdb_cpw.c b/src/lib/kdb/kdb_cpw.c -index 03efc28ed..450860f47 100644 ---- a/src/lib/kdb/kdb_cpw.c -+++ b/src/lib/kdb/kdb_cpw.c -@@ -260,7 +260,6 @@ add_key_pwd(context, master_key, ks_tuple, ks_tuple_count, passwd, - krb5_keysalt key_salt; - krb5_keyblock key; - krb5_data pwd; -- krb5_data afs_params = string2data("\1"), *s2k_params; - int i, j; - krb5_key_data *kd_slot; - -@@ -268,7 +267,6 @@ add_key_pwd(context, master_key, ks_tuple, ks_tuple_count, passwd, - krb5_boolean similar; - - similar = 0; -- s2k_params = NULL; - - /* - * We could use krb5_keysalt_iterate to replace this loop, or use -@@ -316,18 +314,6 @@ add_key_pwd(context, master_key, ks_tuple, ks_tuple_count, passwd, - &key_salt.data))) - return(retval); - break; -- case KRB5_KDB_SALTTYPE_V4: -- key_salt.data.length = 0; -- key_salt.data.data = 0; -- break; -- case KRB5_KDB_SALTTYPE_AFS3: -- retval = krb5int_copy_data_contents(context, -- &db_entry->princ->realm, -- &key_salt.data); -- if (retval) -- return retval; -- s2k_params = &afs_params; -- break; - case KRB5_KDB_SALTTYPE_SPECIAL: - retval = make_random_salt(context, &key_salt); - if (retval) -@@ -342,7 +328,7 @@ add_key_pwd(context, master_key, ks_tuple, ks_tuple_count, passwd, - retval = krb5_c_string_to_key_with_params(context, - ks_tuple[i].ks_enctype, - &pwd, &key_salt.data, -- s2k_params, &key); -+ NULL, &key); - if (retval) { - free(key_salt.data.data); - return retval; -diff --git a/src/lib/krb5/krb/str_conv.c b/src/lib/krb5/krb/str_conv.c -index 3d057241b..c8421a8c1 100644 ---- a/src/lib/krb5/krb/str_conv.c -+++ b/src/lib/krb5/krb/str_conv.c -@@ -61,11 +61,9 @@ struct salttype_lookup_entry { - #include "kdb.h" - static const struct salttype_lookup_entry salttype_table[] = { - { KRB5_KDB_SALTTYPE_NORMAL, "normal" }, -- { KRB5_KDB_SALTTYPE_V4, "v4", }, - { KRB5_KDB_SALTTYPE_NOREALM, "norealm", }, - { KRB5_KDB_SALTTYPE_ONLYREALM, "onlyrealm", }, - { KRB5_KDB_SALTTYPE_SPECIAL, "special", }, -- { KRB5_KDB_SALTTYPE_AFS3, "afs3", }, - }; - static const int salttype_table_nents = sizeof(salttype_table)/ - sizeof(salttype_table[0]); -diff --git a/src/lib/krb5/krb/t_get_etype_info.py b/src/lib/krb5/krb/t_get_etype_info.py -index 7c400be86..3c9168591 100644 ---- a/src/lib/krb5/krb/t_get_etype_info.py -+++ b/src/lib/krb5/krb/t_get_etype_info.py -@@ -9,9 +9,6 @@ realm.run([kadminl, 'ank', '-nokey', '+preauth', 'pnokey']) - realm.run([kadminl, 'ank', '-e', 'aes256-cts:special', '-pw', 'pw', 'exp']) - realm.run([kadminl, 'ank', '-e', 'aes256-cts:special', '-pw', 'pw', '+preauth', - 'pexp']) --realm.run([kadminl, 'ank', '-e', 'des-cbc-crc:afs3', '-pw', 'pw', 'afs']) --realm.run([kadminl, 'ank', '-e', 'des-cbc-crc:afs3', '-pw', 'pw', '+preauth', -- 'pafs']) - - # Extract the explicit salt values from the database. - out = realm.run([kdb5_util, 'tabdump', 'keyinfo']) -@@ -56,8 +53,4 @@ realm.run(['./t_get_etype_info', 'exp'], - realm.run(['./t_get_etype_info', 'pexp'], - expected_msg='etype: aes256-cts\nsalt: ' + pexp_salt + '\n') - --msg = 'etype: des-cbc-crc\nsalt: KRBTEST.COM\ns2kparams: 01\n' --realm.run(['./t_get_etype_info', 'afs'], expected_msg=msg) --realm.run(['./t_get_etype_info', 'pafs'], expected_msg=msg) -- - success('krb5_get_etype_info() tests') -diff --git a/src/man/kdc.conf.man b/src/man/kdc.conf.man -index 959f00de5..fd4dbb2e2 100644 ---- a/src/man/kdc.conf.man -+++ b/src/man/kdc.conf.man -@@ -1,6 +1,6 @@ - .\" Man page generated from reStructuredText. - . --.TH "KDC.CONF" "5" " " "1.17.1" "MIT Kerberos" -+.TH "KDC.CONF" "5" " " "1.18" "MIT Kerberos" - .SH NAME - kdc.conf \- Kerberos V5 KDC configuration file - . -@@ -1149,12 +1149,6 @@ default for Kerberos Version 5 - T} - _ - T{ --v4 --T} T{ --the only type used by Kerberos Version 4 (no salt) --T} --_ --T{ - norealm - T} T{ - same as the default, without using realm information -@@ -1167,12 +1161,6 @@ uses only realm information as the salt - T} - _ - T{ --afs3 --T} T{ --AFS version 3, only used for compatibility with Kerberos 4 in AFS --T} --_ --T{ - special - T} T{ - generate a random salt -diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp -index ea9bedd45..c061d764e 100644 ---- a/src/tests/dejagnu/config/default.exp -+++ b/src/tests/dejagnu/config/default.exp -@@ -238,22 +238,6 @@ set passes { - {master_key_type=aes256-cts-hmac-sha1-96} - {dummy=[verbose -log "AES + DES enctypes, DES3 TGT"]} - } -- { -- des-v4 -- mode=udp -- des3_krbtgt=0 -- {supported_enctypes=des-cbc-crc:v4} -- {default_tkt_enctypes(client)=des-cbc-crc} -- {dummy=[verbose -log "DES TGT, DES-CRC enctype, V4 salt"]} -- } -- { -- des-md5-v4 -- mode=udp -- des3_krbtgt=0 -- {supported_enctypes=des-cbc-md5:v4 des-cbc-crc:v4} -- {default_tkt_enctypes(client)=des-cbc-md5 des-cbc-crc} -- {dummy=[verbose -log "DES TGT, DES-MD5 and -CRC enctypes, V4 salt"]} -- } - { - all-enctypes - mode=udp -@@ -356,7 +340,6 @@ set unused_passes { - aes128-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:norealm \ - des3-cbc-sha1:normal des3-cbc-sha1:none \ - des-cbc-md5:normal des-cbc-md4:normal des-cbc-crc:normal \ -- des-cbc-md5:v4 des-cbc-md4:v4 des-cbc-crc:v4 \ - } - {dummy=[verbose -log "DES3 TGT, default enctypes"]} - } -diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py -index 2026e7876..c21d054f1 100644 ---- a/src/tests/t_etype_info.py -+++ b/src/tests/t_etype_info.py -@@ -1,6 +1,6 @@ - from k5test import * - --supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac des-cbc-crc:afs3' -+supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac' - conf = {'libdefaults': {'allow_weak_crypto': 'true'}, - 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} - realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) -@@ -43,28 +43,6 @@ test_etinfo('preauthuser', 'rc4-hmac-exp des3 rc4 des-cbc-crc', - test_etinfo('preauthuser', 'rc4 aes256-cts', - ['error etype_info2 rc4-hmac KRBTEST.COMpreauthuser']) - --# AFS3 salt for DES enctypes is conveyed using s2kparams in --# PA-ETYPE-INFO2, not at all in PA-ETYPE-INFO, and with a special padata --# type instead of PA-PW-SALT. --test_etinfo('user', 'des-cbc-crc rc4', -- ['asrep etype_info2 des-cbc-crc KRBTEST.COM 01', -- 'asrep etype_info des-cbc-crc KRBTEST.COM', -- 'asrep afs3_salt KRBTEST.COM']) --test_etinfo('preauthuser', 'des-cbc-crc rc4', -- ['error etype_info2 des-cbc-crc KRBTEST.COM 01', -- 'error etype_info des-cbc-crc KRBTEST.COM']) -- --# DES keys can be used with other DES enctypes. The requested enctype --# shows up in the etype-info, not the database key enctype. --test_etinfo('user', 'des-cbc-md4 rc4', -- ['asrep etype_info2 des-cbc-md4 KRBTEST.COM 01', -- 'asrep etype_info des-cbc-md4 KRBTEST.COM', -- 'asrep afs3_salt KRBTEST.COM']) --test_etinfo('user', 'des-cbc-md5 rc4', -- ['asrep etype_info2 des KRBTEST.COM 01', -- 'asrep etype_info des KRBTEST.COM', -- 'asrep afs3_salt KRBTEST.COM']) -- - # If no keys are found matching the request enctypes, a - # preauth-required error can be generated with no etype-info at all - # (to allow for preauth mechs which don't depend on long-term keys). -diff --git a/src/tests/t_keytab.py b/src/tests/t_keytab.py -index 72e09daac..633f7c7ef 100755 ---- a/src/tests/t_keytab.py -+++ b/src/tests/t_keytab.py -@@ -155,9 +155,6 @@ realm.run([kadminl, 'ank', '-pw', 'pw', 'default']) - realm.run([kadminl, 'ank', '-e', 'aes256-cts:special', '-pw', 'pw', 'exp']) - realm.run([kadminl, 'ank', '-e', 'aes256-cts:special', '-pw', 'pw', '+preauth', - 'pexp']) --realm.run([kadminl, 'ank', '-e', 'des-cbc-crc:afs3', '-pw', 'pw', 'afs']) --realm.run([kadminl, 'ank', '-e', 'des-cbc-crc:afs3', '-pw', 'pw', '+preauth', -- 'pafs']) - - # Extract one of the explicit salt values from the database. - out = realm.run([kdb5_util, 'tabdump', 'keyinfo']) -@@ -187,8 +184,6 @@ test_addent(realm, 'default', '-f') - test_addent(realm, 'default', '-f -e aes128-cts') - test_addent(realm, 'exp', '-f') - test_addent(realm, 'pexp', '-f') --test_addent(realm, 'afs', '-f') --test_addent(realm, 'pafs', '-f') - - success('Keytab-related tests') - success('Keytab-related tests') -diff --git a/src/tests/t_renprinc.py b/src/tests/t_renprinc.py -index 46cbed441..3dbb3e77e 100755 ---- a/src/tests/t_renprinc.py -+++ b/src/tests/t_renprinc.py -@@ -25,7 +25,7 @@ from k5test import * - enctype = "aes128-cts" - - realm = K5Realm(create_host=False, create_user=False) --salttypes = ('normal', 'v4', 'norealm', 'onlyrealm') -+salttypes = ('normal', 'norealm', 'onlyrealm') - - # For a variety of salt types, test that we can rename a principal and - # still get tickets with the same password. -diff --git a/src/tests/t_salt.py b/src/tests/t_salt.py -index 278911a22..008efcb03 100755 ---- a/src/tests/t_salt.py -+++ b/src/tests/t_salt.py -@@ -15,13 +15,9 @@ def test_salt(realm, e1, salt, e2): - realm.run([kadminl, 'delprinc', 'user']) - - # Enctype/salt pairs chosen with non-default salt types. --# The enctypes are mostly arbitrary, though afs3 must only be used with des. --# We do not enforce that v4 salts must only be used with des, but it seems --# like a good idea. --salts = [('des-cbc-crc', 'afs3'), -- ('des3-cbc-sha1', 'norealm'), -+# The enctypes are mostly arbitrary. -+salts = [('des3-cbc-sha1', 'norealm'), - ('arcfour-hmac', 'onlyrealm'), -- ('des-cbc-crc', 'v4'), - ('aes128-cts-hmac-sha1-96', 'special')] - # These enctypes are chosen to cover the different string-to-key routines. - # Omit ":normal" from aes256 to check that salttype defaulting works. -@@ -56,22 +52,4 @@ dup_kstypes = ['arcfour-hmac-md5:normal,rc4-hmac:normal', - for ks in dup_kstypes: - test_dup(realm, ks) - --# Attempt to create a principal with a non-des enctype and the afs3 salt, --# verifying that the expected error is received and the principal creation --# fails. --def test_reject_afs3(realm, etype): -- query = 'ank -e ' + etype + ':afs3 -pw password princ1' -- realm.run([kadminl, 'ank', '-e', etype + ':afs3', '-pw', 'password', -- 'princ1'], expected_code=1, -- expected_msg='Invalid key generation parameters from KDC') -- realm.run([kadminl, 'getprinc', 'princ1'], expected_code=1, -- expected_msg='Principal does not exist') -- --# Verify that the afs3 salt is rejected for arcfour and pbkdf2 enctypes. --# We do not currently do any verification on the key-generation parameters --# for the triple-DES enctypes, so that test is commented out. --test_reject_afs3(realm, 'arcfour-hmac') --test_reject_afs3(realm, 'aes256-cts-hmac-sha1-96') --#test_reject_afs3(realm, 'des3-cbc-sha1') -- - success("Salt types") -diff --git a/src/util/k5test.py b/src/util/k5test.py -index 3aec1ef92..b6d93f1d8 100644 ---- a/src/util/k5test.py -+++ b/src/util/k5test.py -@@ -1246,17 +1246,6 @@ _passes = [ - # No special settings; exercises AES256. - ('default', None, None, None), - -- # Exercise a DES enctype and the v4 salt type. -- ('desv4', None, -- {'libdefaults': { -- 'default_tgs_enctypes': 'des-cbc-crc', -- 'default_tkt_enctypes': 'des-cbc-crc', -- 'permitted_enctypes': 'des-cbc-crc', -- 'allow_weak_crypto': 'true'}}, -- {'realms': {'$realm': { -- 'supported_enctypes': 'des-cbc-crc:v4', -- 'master_key_type': 'des-cbc-crc'}}}), -- - # Exercise the DES3 enctype. - ('des3', None, - {'libdefaults': { diff --git a/Set-a-more-modern-default-ksu-CMD_PATH.patch b/Set-a-more-modern-default-ksu-CMD_PATH.patch deleted file mode 100644 index 47defd5..0000000 --- a/Set-a-more-modern-default-ksu-CMD_PATH.patch +++ /dev/null @@ -1,26 +0,0 @@ -From 3d8b0bb1469295bd09f8ba81d3fb059a9ef372f2 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:32:09 -0400 -Subject: [PATCH] Set a more modern default ksu CMD_PATH - -ksu uses CMD_PATH to expand command names in .k5users. Include the /usr -tree and .../sbin variants. Drop nonstandard /local. - -ticket: 8807 (new) -(cherry picked from commit 9eb937a6e1f740d323221813e5da096d30bd68de) ---- - src/clients/ksu/Makefile.in | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/clients/ksu/Makefile.in b/src/clients/ksu/Makefile.in -index 5755bb58a..9d58f29b5 100644 ---- a/src/clients/ksu/Makefile.in -+++ b/src/clients/ksu/Makefile.in -@@ -1,6 +1,6 @@ - mydir=clients$(S)ksu - BUILDTOP=$(REL)..$(S).. --DEFINES = -DGET_TGT_VIA_PASSWD -DPRINC_LOOK_AHEAD -DCMD_PATH='"/bin /local/bin"' -+DEFINES = -DGET_TGT_VIA_PASSWD -DPRINC_LOOK_AHEAD -DCMD_PATH='"/usr/local/sbin /usr/local/bin /sbin /bin /usr/sbin /usr/bin"' - - KSU_LIBS=@KSU_LIBS@ - PAM_LIBS=@PAM_LIBS@ diff --git a/Simplify-SAM-2-as_key-handling.patch b/Simplify-SAM-2-as_key-handling.patch deleted file mode 100644 index 1930a5d..0000000 --- a/Simplify-SAM-2-as_key-handling.patch +++ /dev/null @@ -1,76 +0,0 @@ -From f7fb525d762ba42f62f1044f07f38a243980a2ba Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sun, 5 May 2019 18:53:27 -0400 -Subject: [PATCH] Simplify SAM-2 as_key handling - -The ctx->gak_fct() call in sam2_process() used an empty salt instead -of the default salt when the KDC did not supply an explicit salt. -This bug arose when commit bc096a77ffdab283d77c2e0fc1fdd15b9f77eb41 -changed the internal contracts around salts but did not adjust the -SAM-2 code. Commit e9aa891fcdb4c08d39902ab89afb268042b60c86 fixed the -resulting bug, but mistakenly did not adjust the gak_fct call to use -the correct salt. - -Later on, the code contains a redundant call to krb5_c_string_to_key() -in the non-USE_SAD_AS_KEY modes, replacing ctx->as_key. This call was -properly adjusted by commit e9aa891fcdb4c08d39902ab89afb268042b60c86, -so the improper gak_fct call did not manifest as a bug. - -Fix the gak_fct call to supply the correct salt, and remove the -redundant string_to_key operation. - -(cherry picked from commit d48670c51460e9a74b4f4a9966f85ca6f77c1d8b) ---- - src/lib/krb5/krb/preauth_sam2.c | 25 +++---------------------- - 1 file changed, 3 insertions(+), 22 deletions(-) - -diff --git a/src/lib/krb5/krb/preauth_sam2.c b/src/lib/krb5/krb/preauth_sam2.c -index 4c70021a9..c7484c47e 100644 ---- a/src/lib/krb5/krb/preauth_sam2.c -+++ b/src/lib/krb5/krb/preauth_sam2.c -@@ -95,7 +95,6 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata, - krb5_prompt kprompt; - krb5_prompt_type prompt_type; - krb5_data defsalt, *salt; -- struct gak_password *gakpw; - krb5_checksum **cksum; - krb5_data *scratch = NULL; - krb5_boolean valid_cksum = 0; -@@ -152,9 +151,8 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata, - - salt = ctx->default_salt ? NULL : &ctx->salt; - retval = ctx->gak_fct(context, request->client, sc2b->sam_etype, -- prompter, prompter_data, &ctx->salt, -- &ctx->s2kparams, &ctx->as_key, -- ctx->gak_data, ctx->rctx.items); -+ prompter, prompter_data, salt, &ctx->s2kparams, -+ &ctx->as_key, ctx->gak_data, ctx->rctx.items); - if (retval) { - krb5_free_sam_challenge_2(context, sc2); - krb5_free_sam_challenge_2_body(context, sc2b); -@@ -212,24 +210,7 @@ sam2_process(krb5_context context, krb5_clpreauth_moddata moddata, - - /* Get encryption key to be used for checksum and sam_response */ - if (!(sc2b->sam_flags & KRB5_SAM_USE_SAD_AS_KEY)) { -- /* as_key = string_to_key(password) */ -- -- if (ctx->as_key.length) { -- krb5_free_keyblock_contents(context, &ctx->as_key); -- ctx->as_key.length = 0; -- } -- -- /* generate a key using the supplied password */ -- gakpw = ctx->gak_data; -- retval = krb5_c_string_to_key(context, sc2b->sam_etype, -- gakpw->password, salt, &ctx->as_key); -- -- if (retval) { -- krb5_free_sam_challenge_2(context, sc2); -- krb5_free_sam_challenge_2_body(context, sc2b); -- if (defsalt.length) free(defsalt.data); -- return(retval); -- } -+ /* Retain as_key from above gak_fct call. */ - - if (!(sc2b->sam_flags & KRB5_SAM_SEND_ENCRYPTED_SAD)) { - /* as_key = combine_key (as_key, string_to_key(SAD)) */ diff --git a/Simplify-krb5_dbe_def_search_enctype.patch b/Simplify-krb5_dbe_def_search_enctype.patch deleted file mode 100644 index aefeeed..0000000 --- a/Simplify-krb5_dbe_def_search_enctype.patch +++ /dev/null @@ -1,162 +0,0 @@ -From a7cd60bc97b4d9b171eddae391cf9ecd84c58d31 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 22 Aug 2019 16:19:12 -0400 -Subject: [PATCH] Simplify krb5_dbe_def_search_enctype() - -Key data is now sorted in descending kvno order (since commit -44ad57d8d38efc944f64536354435f5b721c0ee0) and key enctypes can be -compared with a simple equality test (since single-DES support was -removed in commit fb2dada5eb89c4cd4e39dedd6dbb7dbd5e94f8b8). Use -these assumptions to simplify krb5_dbe_def_search_enctype(). - -The rewrite contains one probably-unnoticeable bugfix: if enctype, -salttype, and kvno are all given as -1 in a repeated search, yield all -key entries of permitted enctype, not just entries of the maximum -kvno. - -(cherry picked from commit fcfb0e47c995a7e9f956c3716be3175f44ad26e0) ---- - src/lib/kdb/kdb_default.c | 111 +++++++++++++++----------------------- - 1 file changed, 42 insertions(+), 69 deletions(-) - -diff --git a/src/lib/kdb/kdb_default.c b/src/lib/kdb/kdb_default.c -index a1021f13a..231a0d8b4 100644 ---- a/src/lib/kdb/kdb_default.c -+++ b/src/lib/kdb/kdb_default.c -@@ -37,94 +37,67 @@ - - - /* -- * Given a particular enctype and optional salttype and kvno, find the -- * most appropriate krb5_key_data entry of the database entry. -- * -- * If stype or kvno is negative, it is ignored. -- * If kvno is 0 get the key which is maxkvno for the princ and matches -- * the other attributes. -+ * Set *kd_out to the key data entry matching kvno, enctype, and salttype. If -+ * any of those three parameters are -1, ignore them. If kvno is 0, match only -+ * the highest kvno. Begin searching at the index *start and set *start to the -+ * index after the match. Do not return keys of non-permitted enctypes; return -+ * KRB5_KDB_NO_PERMITTED_KEY if the whole list was searched and only -+ * non-permitted matches were found. - */ - krb5_error_code --krb5_dbe_def_search_enctype(kcontext, dbentp, start, ktype, stype, kvno, kdatap) -- krb5_context kcontext; -- krb5_db_entry *dbentp; -- krb5_int32 *start; -- krb5_int32 ktype; -- krb5_int32 stype; -- krb5_int32 kvno; -- krb5_key_data **kdatap; -+krb5_dbe_def_search_enctype(krb5_context context, krb5_db_entry *ent, -+ krb5_int32 *start, krb5_int32 enctype, -+ krb5_int32 salttype, krb5_int32 kvno, -+ krb5_key_data **kd_out) - { -- int i, idx; -- int maxkvno; -- krb5_key_data *datap; -- krb5_error_code ret; -- krb5_boolean saw_non_permitted = FALSE; -+ krb5_key_data *kd; -+ krb5_int32 db_salttype; -+ krb5_boolean saw_non_permitted = FALSE; -+ int i; - -- ret = 0; -- if (ktype != -1 && !krb5_is_permitted_enctype(kcontext, ktype)) -+ *kd_out = NULL; -+ -+ if (enctype != -1 && !krb5_is_permitted_enctype(context, enctype)) - return KRB5_KDB_NO_PERMITTED_KEY; -+ if (ent->n_key_data == 0) -+ return KRB5_KDB_NO_MATCHING_KEY; - -- if (kvno == -1 && stype == -1 && ktype == -1) -- kvno = 0; -+ /* Match the highest kvno if kvno is 0. Key data is sorted in descending -+ * order of kvno. */ -+ if (kvno == 0) -+ kvno = ent->key_data[0].key_data_kvno; - -- if (kvno == 0) { -- /* Get the max key version */ -- for (i = 0; i < dbentp->n_key_data; i++) { -- if (kvno < dbentp->key_data[i].key_data_kvno) { -- kvno = dbentp->key_data[i].key_data_kvno; -- } -- } -- } -+ for (i = *start; i < ent->n_key_data; i++) { -+ kd = &ent->key_data[i]; -+ db_salttype = (kd->key_data_ver > 1) ? kd->key_data_type[1] : -+ KRB5_KDB_SALTTYPE_NORMAL; - -- maxkvno = -1; -- idx = -1; -- datap = (krb5_key_data *) NULL; -- for (i = *start; i < dbentp->n_key_data; i++) { -- krb5_boolean similar; -- krb5_int32 db_stype; -- -- ret = 0; -- if (dbentp->key_data[i].key_data_ver > 1) { -- db_stype = dbentp->key_data[i].key_data_type[1]; -- } else { -- db_stype = KRB5_KDB_SALTTYPE_NORMAL; -- } -- -- /* Match this entry against the arguments. */ -- if (ktype != -1) { -- ret = krb5_c_enctype_compare(kcontext, (krb5_enctype) ktype, -- dbentp->key_data[i].key_data_type[0], -- &similar); -- if (ret != 0 || !similar) -- continue; -- } -- if (stype >= 0 && db_stype != stype) -+ /* Match this entry against the arguments. Stop searching if we have -+ * passed the entries for the requested kvno. */ -+ if (enctype != -1 && kd->key_data_type[0] != enctype) - continue; -- if (kvno >= 0 && dbentp->key_data[i].key_data_kvno != kvno) -+ if (salttype >= 0 && db_salttype != salttype) -+ continue; -+ if (kvno >= 0 && kd->key_data_kvno < kvno) -+ break; -+ if (kvno >= 0 && kd->key_data_kvno != kvno) - continue; - - /* Filter out non-permitted enctypes. */ -- if (!krb5_is_permitted_enctype(kcontext, -- dbentp->key_data[i].key_data_type[0])) { -+ if (!krb5_is_permitted_enctype(context, kd->key_data_type[0])) { - saw_non_permitted = TRUE; - continue; - } - -- if (dbentp->key_data[i].key_data_kvno > maxkvno) { -- maxkvno = dbentp->key_data[i].key_data_kvno; -- datap = &dbentp->key_data[i]; -- idx = i; -- } -+ *start = i + 1; -+ *kd_out = kd; -+ return 0; - } -+ - /* If we scanned the whole set of keys and matched only non-permitted - * enctypes, indicate that. */ -- if (maxkvno < 0 && *start == 0 && saw_non_permitted) -- ret = KRB5_KDB_NO_PERMITTED_KEY; -- if (maxkvno < 0) -- return ret ? ret : KRB5_KDB_NO_MATCHING_KEY; -- *kdatap = datap; -- *start = idx+1; -- return 0; -+ return (*start == 0 && saw_non_permitted) ? KRB5_KDB_NO_PERMITTED_KEY : -+ KRB5_KDB_NO_MATCHING_KEY; - } - - /* diff --git a/Simply-OpenSSL-PKCS7-decryption-code.patch b/Simply-OpenSSL-PKCS7-decryption-code.patch deleted file mode 100644 index 4190846..0000000 --- a/Simply-OpenSSL-PKCS7-decryption-code.patch +++ /dev/null @@ -1,301 +0,0 @@ -From db62fe97a56f8f8476e3202a492d1c3d784d52b2 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 6 May 2019 13:13:06 -0400 -Subject: [PATCH] Simply OpenSSL PKCS7 decryption code - -Fold pkcs7_decrypt() and pkcs7_dataDecode() into a single function, -and make it output the plaintext rather than a BIO. - -[ghudson@mit.edu: continued a modernization of pkcs7_dataDecode() into -a larger refactoring] - -(cherry picked from commit 210356653a2f963ffe9a8a1b1627c64fb8ca7a3d) ---- - .../preauth/pkinit/pkinit_crypto_openssl.c | 213 ++++++------------ - 1 file changed, 63 insertions(+), 150 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 5ff81d8cf..8aa2c5257 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -81,12 +81,8 @@ static int openssl_callback (int, X509_STORE_CTX *); - static int openssl_callback_ignore_crls (int, X509_STORE_CTX *); - - static int pkcs7_decrypt --(krb5_context context, pkinit_identity_crypto_context id_cryptoctx, -- PKCS7 *p7, BIO *bio); -- --static BIO * pkcs7_dataDecode --(krb5_context context, pkinit_identity_crypto_context id_cryptoctx, -- PKCS7 *p7); -+(krb5_context context, pkinit_identity_crypto_context id_cryptoctx, PKCS7 *p7, -+ unsigned char **data_out, unsigned int *len_out); - - static ASN1_OBJECT * pkinit_pkcs7type2oid - (pkinit_plg_crypto_context plg_cryptoctx, int pkcs7_type); -@@ -1964,9 +1960,6 @@ cms_envelopeddata_verify(krb5_context context, - { - krb5_error_code retval = KRB5KDC_ERR_PREAUTH_FAILED; - PKCS7 *p7 = NULL; -- BIO *out = NULL; -- int i = 0; -- unsigned int size = 0; - const unsigned char *p = enveloped_data; - unsigned int tmp_buf_len = 0, tmp_buf2_len = 0, vfy_buf_len = 0; - unsigned char *tmp_buf = NULL, *tmp_buf2 = NULL, *vfy_buf = NULL; -@@ -1991,26 +1984,13 @@ cms_envelopeddata_verify(krb5_context context, - } - - /* decrypt received PKCS7 message */ -- out = BIO_new(BIO_s_mem()); -- if (pkcs7_decrypt(context, id_cryptoctx, p7, out)) { -+ if (pkcs7_decrypt(context, id_cryptoctx, p7, &tmp_buf, &tmp_buf_len)) { - pkiDebug("PKCS7 decryption successful\n"); - } else { - retval = oerr(context, 0, _("Failed to decrypt PKCS7 message")); - goto cleanup; - } - -- /* transfer the decoded PKCS7 SignedData message into a separate buffer */ -- for (;;) { -- if ((tmp_buf = realloc(tmp_buf, size + 1024 * 10)) == NULL) -- goto cleanup; -- i = BIO_read(out, &(tmp_buf[size]), 1024 * 10); -- if (i <= 0) -- break; -- else -- size += i; -- } -- tmp_buf_len = size; -- - #ifdef DEBUG_ASN1 - print_buffer_bin(tmp_buf, tmp_buf_len, "/tmp/client_enc_keypack"); - #endif -@@ -2072,8 +2052,6 @@ cleanup: - - if (p7 != NULL) - PKCS7_free(p7); -- if (out != NULL) -- BIO_free(out); - free(tmp_buf); - free(tmp_buf2); - -@@ -5714,39 +5692,6 @@ cleanup: - return retval; - } - --static int --pkcs7_decrypt(krb5_context context, -- pkinit_identity_crypto_context id_cryptoctx, -- PKCS7 *p7, -- BIO *data) --{ -- BIO *tmpmem = NULL; -- int retval = 0, i = 0; -- char buf[4096]; -- -- if(p7 == NULL) -- return 0; -- -- if(!PKCS7_type_is_enveloped(p7)) { -- pkiDebug("wrong pkcs7 content type\n"); -- return 0; -- } -- -- if(!(tmpmem = pkcs7_dataDecode(context, id_cryptoctx, p7))) { -- pkiDebug("unable to decrypt pkcs7 object\n"); -- return 0; -- } -- -- for(;;) { -- i = BIO_read(tmpmem, buf, sizeof(buf)); -- if (i <= 0) break; -- BIO_write(data, buf, i); -- BIO_free_all(tmpmem); -- return 1; -- } -- return retval; --} -- - krb5_error_code - pkinit_process_td_trusted_certifiers( - krb5_context context, -@@ -5827,118 +5772,86 @@ cleanup: - return retval; - } - --static BIO * --pkcs7_dataDecode(krb5_context context, -- pkinit_identity_crypto_context id_cryptoctx, -- PKCS7 *p7) -+/* Originally based on OpenSSL's PKCS7_dataDecode(), now modified to remove the -+ * use of BIO objects and to fit the PKINIT internal interfaces. */ -+static int -+pkcs7_decrypt(krb5_context context, -+ pkinit_identity_crypto_context id_cryptoctx, PKCS7 *p7, -+ unsigned char **data_out, unsigned int *len_out) - { -- unsigned int eklen=0, tkeylen=0; -- BIO *out=NULL,*etmp=NULL,*bio=NULL; -- unsigned char *ek=NULL, *tkey=NULL; -- ASN1_OCTET_STRING *data_body=NULL; -- const EVP_CIPHER *evp_cipher=NULL; -- EVP_CIPHER_CTX *evp_ctx=NULL; -- X509_ALGOR *enc_alg=NULL; -- STACK_OF(PKCS7_RECIP_INFO) *rsk=NULL; -- PKCS7_RECIP_INFO *ri=NULL; -+ krb5_error_code ret; -+ int ok = 0, plaintext_len = 0, final_len; -+ unsigned int keylen = 0, eklen = 0, blocksize; -+ unsigned char *ek = NULL, *tkey = NULL, *plaintext = NULL, *use_key; -+ ASN1_OCTET_STRING *data_body = p7->d.enveloped->enc_data->enc_data; -+ const EVP_CIPHER *evp_cipher; -+ EVP_CIPHER_CTX *evp_ctx = NULL; -+ X509_ALGOR *enc_alg = p7->d.enveloped->enc_data->algorithm; -+ STACK_OF(PKCS7_RECIP_INFO) *rsk = p7->d.enveloped->recipientinfo; -+ PKCS7_RECIP_INFO *ri = NULL; - -- p7->state=PKCS7_S_HEADER; -+ *data_out = NULL; -+ *len_out = 0; - -- rsk=p7->d.enveloped->recipientinfo; -- enc_alg=p7->d.enveloped->enc_data->algorithm; -- data_body=p7->d.enveloped->enc_data->enc_data; -- evp_cipher=EVP_get_cipherbyobj(enc_alg->algorithm); -- if (evp_cipher == NULL) { -- PKCS7err(PKCS7_F_PKCS7_DATADECODE,PKCS7_R_UNSUPPORTED_CIPHER_TYPE); -- goto cleanup; -- } -- -- if ((etmp=BIO_new(BIO_f_cipher())) == NULL) { -- PKCS7err(PKCS7_F_PKCS7_DATADECODE,ERR_R_BIO_LIB); -- goto cleanup; -- } -- -- /* It was encrypted, we need to decrypt the secret key -- * with the private key */ -+ p7->state = PKCS7_S_HEADER; - - /* RFC 4556 section 3.2.3.2 requires that there be exactly one - * recipientInfo. */ - if (sk_PKCS7_RECIP_INFO_num(rsk) != 1) { - pkiDebug("invalid number of EnvelopedData RecipientInfos\n"); -- goto cleanup; -+ return 0; - } -- - ri = sk_PKCS7_RECIP_INFO_value(rsk, 0); -- (void)pkinit_decode_data(context, id_cryptoctx, -- ASN1_STRING_get0_data(ri->enc_key), -- ASN1_STRING_length(ri->enc_key), &ek, &eklen); - -- evp_ctx=NULL; -- BIO_get_cipher_ctx(etmp,&evp_ctx); -- if (EVP_CipherInit_ex(evp_ctx,evp_cipher,NULL,NULL,NULL,0) <= 0) -+ evp_cipher = EVP_get_cipherbyobj(enc_alg->algorithm); -+ if (evp_cipher == NULL) - goto cleanup; -- if (EVP_CIPHER_asn1_to_param(evp_ctx,enc_alg->parameter) < 0) -+ keylen = EVP_CIPHER_key_length(evp_cipher); -+ blocksize = EVP_CIPHER_block_size(evp_cipher); -+ -+ evp_ctx = EVP_CIPHER_CTX_new(); -+ if (evp_ctx == NULL) -+ goto cleanup; -+ if (!EVP_DecryptInit(evp_ctx, evp_cipher, NULL, NULL) || -+ EVP_CIPHER_asn1_to_param(evp_ctx, enc_alg->parameter) <= 0) - goto cleanup; - - /* Generate a random symmetric key to avoid exposing timing data if RSA - * decryption fails the padding check. */ -- tkeylen = EVP_CIPHER_CTX_key_length(evp_ctx); -- tkey = OPENSSL_malloc(tkeylen); -- if (tkey == NULL) -- goto cleanup; -- if (EVP_CIPHER_CTX_rand_key(evp_ctx, tkey) <= 0) -- goto cleanup; -- if (ek == NULL) { -- ek = tkey; -- eklen = tkeylen; -- tkey = NULL; -- } -- -- if (eklen != (unsigned)EVP_CIPHER_CTX_key_length(evp_ctx)) { -- /* Some S/MIME clients don't use the same key -- * and effective key length. The key length is -- * determined by the size of the decrypted RSA key. -- */ -- if (!EVP_CIPHER_CTX_set_key_length(evp_ctx, (int)eklen)) { -- ek = tkey; -- eklen = tkeylen; -- tkey = NULL; -- } -- } -- if (EVP_CipherInit_ex(evp_ctx,NULL,NULL,ek,NULL,0) <= 0) -+ tkey = malloc(keylen); -+ if (tkey == NULL || !EVP_CIPHER_CTX_rand_key(evp_ctx, tkey)) - goto cleanup; - -- if (out == NULL) -- out=etmp; -- else -- BIO_push(out,etmp); -- etmp=NULL; -+ /* Decrypt the secret key with the private key. */ -+ ret = pkinit_decode_data(context, id_cryptoctx, -+ ASN1_STRING_get0_data(ri->enc_key), -+ ASN1_STRING_length(ri->enc_key), &ek, &eklen); -+ use_key = (ret || eklen != keylen) ? tkey : ek; - -- if (data_body->length > 0) -- bio = BIO_new_mem_buf(data_body->data, data_body->length); -- else { -- bio=BIO_new(BIO_s_mem()); -- BIO_set_mem_eof_return(bio,0); -- } -- BIO_push(out,bio); -- bio=NULL; -+ /* Allocate a plaintext buffer and decrypt data_body into it. */ -+ plaintext = malloc(data_body->length + blocksize); -+ if (plaintext == NULL) -+ goto cleanup; -+ if (!EVP_DecryptInit(evp_ctx, NULL, use_key, NULL)) -+ goto cleanup; -+ if (!EVP_DecryptUpdate(evp_ctx, plaintext, &plaintext_len, -+ data_body->data, data_body->length)) -+ goto cleanup; -+ if (!EVP_DecryptFinal(evp_ctx, plaintext + plaintext_len, &final_len)) -+ goto cleanup; -+ plaintext_len += final_len; - -- if (0) { -- cleanup: -- if (out != NULL) BIO_free_all(out); -- if (etmp != NULL) BIO_free_all(etmp); -- if (bio != NULL) BIO_free_all(bio); -- out=NULL; -- } -- if (ek != NULL) { -- OPENSSL_cleanse(ek, eklen); -- OPENSSL_free(ek); -- } -- if (tkey != NULL) { -- OPENSSL_cleanse(tkey, tkeylen); -- OPENSSL_free(tkey); -- } -- return(out); -+ *len_out = plaintext_len; -+ *data_out = plaintext; -+ plaintext = NULL; -+ ok = 1; -+ -+cleanup: -+ EVP_CIPHER_CTX_free(evp_ctx); -+ zapfree(plaintext, plaintext_len); -+ zapfree(ek, eklen); -+ zapfree(tkey, keylen); -+ return ok; - } - - #ifdef DEBUG_DH diff --git a/Skip-URI-tests-when-using-asan.patch b/Skip-URI-tests-when-using-asan.patch deleted file mode 100644 index 05d68db..0000000 --- a/Skip-URI-tests-when-using-asan.patch +++ /dev/null @@ -1,37 +0,0 @@ -From c58dbf05938b57a729d1b3811424866296f11998 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 3 Aug 2019 13:30:28 -0400 -Subject: [PATCH] Skip URI tests when using asan - -resolve_wrapper uses RTLD_DEEPBIND to load libresolv, triggering a -failure in the asan runtime. - -(cherry picked from commit dbcec74b277952adf6e49d087932d2d0ea5393d1) ---- - src/lib/krb5/os/Makefile.in | 10 +++++++--- - 1 file changed, 7 insertions(+), 3 deletions(-) - -diff --git a/src/lib/krb5/os/Makefile.in b/src/lib/krb5/os/Makefile.in -index 91b0486b8..f523a5ac8 100644 ---- a/src/lib/krb5/os/Makefile.in -+++ b/src/lib/krb5/os/Makefile.in -@@ -232,12 +232,16 @@ check-unix-locate: t_locate_kdc - echo 'Skipped t_locate_kdc test: OFFLINE' >> $(SKIPTESTS); \ - fi - -+ASAN = @ASAN@ - check-unix-uri: t_locate_kdc -- if [ $(HAVE_RESOLV_WRAPPER) = 1 ]; then \ -- $(RUNPYTEST) $(srcdir)/t_discover_uri.py $(PYTESTFLAGS); \ -- else \ -+ if [ $(HAVE_RESOLV_WRAPPER) = 0 ]; then \ - echo '*** WARNING: skipped t_discover_uri.py due to not using resolv_wrapper'; \ - echo 'Skipped URI discovery tests: resolv_wrapper 1.1.5 not found' >> $(SKIPTESTS); \ -+ elif [ $(ASAN) = yes ]; then \ -+ echo '*** Skipping URI discovery tests: resolv_wrapper is incompatible with asan'; \ -+ echo 'Skipped URI discovery tests: incompatible with asan' >> $(SKIPTESTS); \ -+ else \ -+ $(RUNPYTEST) $(srcdir)/t_discover_uri.py $(PYTESTFLAGS); \ - fi - - check-unix-trace: t_trace diff --git a/Squash-apparent-forward-null-in-clnttcp_create.patch b/Squash-apparent-forward-null-in-clnttcp_create.patch deleted file mode 100644 index fe55a52..0000000 --- a/Squash-apparent-forward-null-in-clnttcp_create.patch +++ /dev/null @@ -1,34 +0,0 @@ -From 566fa44c8f53b3c558791bef29d01fb6a02ff559 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 30 Aug 2019 11:16:58 -0400 -Subject: [PATCH] Squash apparent forward-null in clnttcp_create() - -clnttcp_create() only allows raddr to be NULL if *sockp is set. -Static analyzers cannot know this, so can report a forward null -defect. Add an raddr check before calling connect() to squash the -defect. - -[ghudson@mit.edu: rewrote commit message] - -(cherry picked from commit b2f688eedd4bcca525201ef9485749a8c20b808a) ---- - src/lib/rpc/clnt_tcp.c | 6 +++--- - 1 file changed, 3 insertions(+), 3 deletions(-) - -diff --git a/src/lib/rpc/clnt_tcp.c b/src/lib/rpc/clnt_tcp.c -index 87761906c..dbd62d0a7 100644 ---- a/src/lib/rpc/clnt_tcp.c -+++ b/src/lib/rpc/clnt_tcp.c -@@ -168,9 +168,9 @@ clnttcp_create( - if (*sockp < 0) { - *sockp = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP); - (void)bindresvport_sa(*sockp, NULL); -- if ((*sockp < 0) -- || (connect(*sockp, (struct sockaddr *)raddr, -- sizeof(*raddr)) < 0)) { -+ if (*sockp < 0 || raddr == NULL || -+ connect(*sockp, (struct sockaddr *)raddr, -+ sizeof(*raddr)) < 0) { - rpc_createerr.cf_stat = RPC_SYSTEMERROR; - rpc_createerr.cf_error.re_errno = errno; - (void)closesocket(*sockp); diff --git a/Support-389ds-s-lockout-model.patch b/Support-389ds-s-lockout-model.patch deleted file mode 100644 index b8f4d02..0000000 --- a/Support-389ds-s-lockout-model.patch +++ /dev/null @@ -1,63 +0,0 @@ -From a9c73bc1078dc6287a3838220ef1bd435273506e Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:47:44 -0400 -Subject: [PATCH] Support 389ds's lockout model - -Handle the attribute 'nsAccountLock' from Netscape derivatives. Based -on a patch by Nalin Dahyabhai and Simo Sorce. - -ticket: 5891 -(cherry picked from commit 6ad061e24eca41a61eebed61db39768bfa51a084) ---- - src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c | 18 ++++++++++++++++++ - .../kdb/ldap/libkdb_ldap/ldap_principal.c | 1 + - 2 files changed, 19 insertions(+) - -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c -index 5b9d1e9fa..2ade63719 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c -@@ -1420,6 +1420,7 @@ populate_krb5_db_entry(krb5_context context, krb5_ldap_context *ldap_context, - struct berval **ber_key_data = NULL, **ber_tl_data = NULL; - krb5_tl_data userinfo_tl_data = { NULL }, **endp, *tl; - osa_princ_ent_rec princ_ent; -+ char *is_login_disabled = NULL; - - memset(&princ_ent, 0, sizeof(princ_ent)); - -@@ -1653,6 +1654,23 @@ populate_krb5_db_entry(krb5_context context, krb5_ldap_context *ldap_context, - if (ret) - goto cleanup; - -+ /* -+ * 389ds and other Netscape directory server derivatives support an -+ * attribute "nsAccountLock" which functions similarly to eDirectory's -+ * "loginDisabled". When the user's account object is also a -+ * krbPrincipalAux object, the kdb entry should be treated as if -+ * DISALLOW_ALL_TIX has been set. -+ */ -+ ret = krb5_ldap_get_string(ld, ent, "nsAccountLock", &is_login_disabled, -+ &attr_present); -+ if (ret) -+ goto cleanup; -+ if (attr_present == TRUE) { -+ if (strcasecmp(is_login_disabled, "TRUE") == 0) -+ entry->attributes |= KRB5_KDB_DISALLOW_ALL_TIX; -+ free(is_login_disabled); -+ } -+ - ret = krb5_read_tkt_policy(context, ldap_context, entry, tktpolname); - if (ret) - goto cleanup; -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c -index d722dbfa6..a5180c73f 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal.c -@@ -54,6 +54,7 @@ char *principal_attributes[] = { "krbprincipalname", - "krbLastFailedAuth", - "krbLoginFailedCount", - "krbLastSuccessfulAuth", -+ "nsAccountLock", - "krbLastPwdChange", - "krbLastAdminUnlock", - "krbPrincipalAuthInd", diff --git a/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch b/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch deleted file mode 100644 index be73cc3..0000000 --- a/Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch +++ /dev/null @@ -1,85 +0,0 @@ -From 5e7c6ac2f9ee4dfe182f28c0801811910b63be1d Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 16 Apr 2019 14:16:39 -0400 -Subject: [PATCH] Update ASN.1 SAM tests to use a modern enctype - -(cherry picked from commit 3e94e53febc6d5636272f31ae9dba8e3babe9263) ---- - src/tests/asn.1/krb5_decode_test.c | 2 +- - src/tests/asn.1/ktest.c | 4 ++-- - src/tests/asn.1/reference_encode.out | 4 ++-- - src/tests/asn.1/trval_reference.out | 4 ++-- - 4 files changed, 7 insertions(+), 7 deletions(-) - -diff --git a/src/tests/asn.1/krb5_decode_test.c b/src/tests/asn.1/krb5_decode_test.c -index ee70fa4b9..cbd99ba63 100644 ---- a/src/tests/asn.1/krb5_decode_test.c -+++ b/src/tests/asn.1/krb5_decode_test.c -@@ -934,7 +934,7 @@ int main(argc, argv) - /* decode_sam_challenge_2_body */ - { - setup(krb5_sam_challenge_2_body,ktest_make_sample_sam_challenge_2_body); -- decode_run("sam_challenge_2_body","","30 64 A0 03 02 01 2A A1 07 03 05 00 80 00 00 00 A2 0B 04 09 74 79 70 65 20 6E 61 6D 65 A4 11 04 0F 63 68 61 6C 6C 65 6E 67 65 20 6C 61 62 65 6C A5 10 04 0E 63 68 61 6C 6C 65 6E 67 65 20 69 70 73 65 A6 16 04 14 72 65 73 70 6F 6E 73 65 5F 70 72 6F 6D 70 74 20 69 70 73 65 A8 05 02 03 54 32 10 A9 03 02 01 01",decode_krb5_sam_challenge_2_body,ktest_equal_sam_challenge_2_body,krb5_free_sam_challenge_2_body); -+ decode_run("sam_challenge_2_body","","30 64 A0 03 02 01 2A A1 07 03 05 00 80 00 00 00 A2 0B 04 09 74 79 70 65 20 6E 61 6D 65 A4 11 04 0F 63 68 61 6C 6C 65 6E 67 65 20 6C 61 62 65 6C A5 10 04 0E 63 68 61 6C 6C 65 6E 67 65 20 69 70 73 65 A6 16 04 14 72 65 73 70 6F 6E 73 65 5F 70 72 6F 6D 70 74 20 69 70 73 65 A8 05 02 03 54 32 10 A9 03 02 01 14",decode_krb5_sam_challenge_2_body,ktest_equal_sam_challenge_2_body,krb5_free_sam_challenge_2_body); - ktest_empty_sam_challenge_2_body(&ref); - - } -diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c -index 5bfdc5be2..6bf6e54ac 100644 ---- a/src/tests/asn.1/ktest.c -+++ b/src/tests/asn.1/ktest.c -@@ -507,7 +507,7 @@ ktest_make_sample_sam_challenge_2_body(krb5_sam_challenge_2_body *p) - krb5_data_parse(&p->sam_response_prompt, "response_prompt ipse"); - p->sam_pk_for_sad = empty_data(); - p->sam_nonce = 0x543210; -- p->sam_etype = ENCTYPE_DES_CBC_CRC; -+ p->sam_etype = ENCTYPE_AES256_CTS_HMAC_SHA384_192; - } - - void -@@ -518,7 +518,7 @@ ktest_make_sample_sam_response_2(krb5_sam_response_2 *p) - p->sam_flags = KRB5_SAM_USE_SAD_AS_KEY; /* KRB5_SAM_* values */ - krb5_data_parse(&p->sam_track_id, "track data"); - krb5_data_parse(&p->sam_enc_nonce_or_sad.ciphertext, "nonce or sad"); -- p->sam_enc_nonce_or_sad.enctype = ENCTYPE_DES_CBC_CRC; -+ p->sam_enc_nonce_or_sad.enctype = ENCTYPE_AES256_CTS_HMAC_SHA384_192; - p->sam_enc_nonce_or_sad.kvno = 3382; - p->sam_nonce = 0x543210; - } -diff --git a/src/tests/asn.1/reference_encode.out b/src/tests/asn.1/reference_encode.out -index a76deead2..80b18a2fb 100644 ---- a/src/tests/asn.1/reference_encode.out -+++ b/src/tests/asn.1/reference_encode.out -@@ -49,8 +49,8 @@ encode_krb5_enc_data: 30 23 A0 03 02 01 00 A1 03 02 01 05 A2 17 04 15 6B 72 62 4 - encode_krb5_enc_data(MSB-set kvno): 30 26 A0 03 02 01 00 A1 06 02 04 FF 00 00 00 A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65 - encode_krb5_enc_data(kvno=-1): 30 23 A0 03 02 01 00 A1 03 02 01 FF A2 17 04 15 6B 72 62 41 53 4E 2E 31 20 74 65 73 74 20 6D 65 73 73 61 67 65 - encode_krb5_sam_challenge_2: 30 22 A0 0D 30 0B 04 09 63 68 61 6C 6C 65 6E 67 65 A1 11 30 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34 --encode_krb5_sam_challenge_2_body: 30 64 A0 03 02 01 2A A1 07 03 05 00 80 00 00 00 A2 0B 04 09 74 79 70 65 20 6E 61 6D 65 A4 11 04 0F 63 68 61 6C 6C 65 6E 67 65 20 6C 61 62 65 6C A5 10 04 0E 63 68 61 6C 6C 65 6E 67 65 20 69 70 73 65 A6 16 04 14 72 65 73 70 6F 6E 73 65 5F 70 72 6F 6D 70 74 20 69 70 73 65 A8 05 02 03 54 32 10 A9 03 02 01 01 --encode_krb5_sam_response_2: 30 42 A0 03 02 01 2B A1 07 03 05 00 80 00 00 00 A2 0C 04 0A 74 72 61 63 6B 20 64 61 74 61 A3 1D 30 1B A0 03 02 01 01 A1 04 02 02 0D 36 A2 0E 04 0C 6E 6F 6E 63 65 20 6F 72 20 73 61 64 A4 05 02 03 54 32 10 -+encode_krb5_sam_challenge_2_body: 30 64 A0 03 02 01 2A A1 07 03 05 00 80 00 00 00 A2 0B 04 09 74 79 70 65 20 6E 61 6D 65 A4 11 04 0F 63 68 61 6C 6C 65 6E 67 65 20 6C 61 62 65 6C A5 10 04 0E 63 68 61 6C 6C 65 6E 67 65 20 69 70 73 65 A6 16 04 14 72 65 73 70 6F 6E 73 65 5F 70 72 6F 6D 70 74 20 69 70 73 65 A8 05 02 03 54 32 10 A9 03 02 01 14 -+encode_krb5_sam_response_2: 30 42 A0 03 02 01 2B A1 07 03 05 00 80 00 00 00 A2 0C 04 0A 74 72 61 63 6B 20 64 61 74 61 A3 1D 30 1B A0 03 02 01 14 A1 04 02 02 0D 36 A2 0E 04 0C 6E 6F 6E 63 65 20 6F 72 20 73 61 64 A4 05 02 03 54 32 10 - encode_krb5_enc_sam_response_enc_2: 30 1F A0 03 02 01 58 A1 18 04 16 65 6E 63 5F 73 61 6D 5F 72 65 73 70 6F 6E 73 65 5F 65 6E 63 5F 32 - encode_krb5_pa_for_user: 30 4B A0 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A2 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34 A3 0A 1B 08 6B 72 62 35 64 61 74 61 - encode_krb5_pa_s4u_x509_user: 30 68 A0 55 30 53 A0 06 02 04 00 CA 14 9A A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A2 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A3 12 04 10 70 61 5F 73 34 75 5F 78 35 30 39 5F 75 73 65 72 A4 07 03 05 00 80 00 00 00 A1 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34 -diff --git a/src/tests/asn.1/trval_reference.out b/src/tests/asn.1/trval_reference.out -index e5c715924..432fdcebb 100644 ---- a/src/tests/asn.1/trval_reference.out -+++ b/src/tests/asn.1/trval_reference.out -@@ -1180,7 +1180,7 @@ encode_krb5_sam_challenge_2_body: - . [5] [Octet String] "challenge ipse" - . [6] [Octet String] "response_prompt ipse" - . [8] [Integer] 5517840 --. [9] [Integer] 1 -+. [9] [Integer] 20 - - encode_krb5_sam_response_2: - -@@ -1189,7 +1189,7 @@ encode_krb5_sam_response_2: - . [1] [Bit String] 0x80000000 - . [2] [Octet String] "track data" - . [3] [Sequence/Sequence Of] --. . [0] [Integer] 1 -+. . [0] [Integer] 20 - . . [1] [Integer] 3382 - . . [2] [Octet String] "nonce or sad" - . [4] [Integer] 5517840 diff --git a/Update-default-krb5kdc-mkey-manual-entry-enctype.patch b/Update-default-krb5kdc-mkey-manual-entry-enctype.patch deleted file mode 100644 index 7954dcb..0000000 --- a/Update-default-krb5kdc-mkey-manual-entry-enctype.patch +++ /dev/null @@ -1,54 +0,0 @@ -From 04ce158f626a683d60914f464bac24a1bd5687e3 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 20 May 2019 16:52:57 -0400 -Subject: [PATCH] Update default krb5kdc mkey manual-entry enctype - -Change from the legacy des-cbc-crc to the default for kdb5_util and -kadmind, which is currently aes256-cts-hmac-sha1-96. - -(cherry picked from commit 512f5cde625253cba1e6f87e037a00ef88178882) ---- - doc/admin/admin_commands/krb5kdc.rst | 2 +- - src/kdc/main.c | 2 +- - src/man/krb5kdc.man | 2 +- - 3 files changed, 3 insertions(+), 3 deletions(-) - -diff --git a/doc/admin/admin_commands/krb5kdc.rst b/doc/admin/admin_commands/krb5kdc.rst -index 08d40cc0d..631a0de84 100644 ---- a/doc/admin/admin_commands/krb5kdc.rst -+++ b/doc/admin/admin_commands/krb5kdc.rst -@@ -41,7 +41,7 @@ LDAP database. - - The **-k** *keytype* option specifies the key type of the master key - to be entered manually as a password when **-m** is given; the default --is ``des-cbc-crc``. -+is |defmkey|. - - The **-M** *mkeyname* option specifies the principal name for the - master key in the database (usually ``K/M`` in the KDC's realm). -diff --git a/src/kdc/main.c b/src/kdc/main.c -index 60092a0df..04393772f 100644 ---- a/src/kdc/main.c -+++ b/src/kdc/main.c -@@ -777,7 +777,7 @@ initialize_realms(krb5_context kcontext, int argc, char **argv, - case 'm': /* manual type-in of master key */ - manual = TRUE; - if (menctype == ENCTYPE_UNKNOWN) -- menctype = ENCTYPE_DES_CBC_CRC; -+ menctype = DEFAULT_KDC_ENCTYPE; - break; - case 'M': /* master key name in DB */ - mkey_name = optarg; -diff --git a/src/man/krb5kdc.man b/src/man/krb5kdc.man -index 9c9b816b3..100f371c4 100644 ---- a/src/man/krb5kdc.man -+++ b/src/man/krb5kdc.man -@@ -61,7 +61,7 @@ LDAP database. - .sp - The \fB\-k\fP \fIkeytype\fP option specifies the key type of the master key - to be entered manually as a password when \fB\-m\fP is given; the default --is \fBdes\-cbc\-crc\fP\&. -+is \fBaes256\-cts\-hmac\-sha1\-96\fP\&. - .sp - The \fB\-M\fP \fImkeyname\fP option specifies the principal name for the - master key in the database (usually \fBK/M\fP in the KDC\(aqs realm). diff --git a/Update-test-suite-cert-message-digest-to-sha256.patch b/Update-test-suite-cert-message-digest-to-sha256.patch deleted file mode 100644 index ec7c9df..0000000 --- a/Update-test-suite-cert-message-digest-to-sha256.patch +++ /dev/null @@ -1,638 +0,0 @@ -From 8c38e6a1cef9bee050e42f591a530d077bb11f17 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 12 Nov 2019 13:38:59 -0500 -Subject: [PATCH] Update test suite cert message digest to sha256 - -Certain openssl configurations (such as Debian testing) will fail out -the sha1 certificates with errors like "ssl.SSLError: [SSL: -CA_MD_TOO_WEAK] ca md too weak (_ssl.c:3833)" or similar. Also update -the certs in question. - -(cherry picked from commit b1c258c6aab95198bdc340b86ca67cbd531464f8) ---- - src/tests/dejagnu/proxy-certs/ca.pem | 52 +++++----- - src/tests/dejagnu/proxy-certs/make-certs.sh | 2 +- - .../dejagnu/proxy-certs/proxy-badsig.pem | 96 +++++++++--------- - src/tests/dejagnu/proxy-certs/proxy-ideal.pem | 98 +++++++++---------- - .../dejagnu/proxy-certs/proxy-no-match.pem | 98 +++++++++---------- - src/tests/dejagnu/proxy-certs/proxy-san.pem | 98 +++++++++---------- - .../dejagnu/proxy-certs/proxy-subject.pem | 98 +++++++++---------- - 7 files changed, 271 insertions(+), 271 deletions(-) - -diff --git a/src/tests/dejagnu/proxy-certs/ca.pem b/src/tests/dejagnu/proxy-certs/ca.pem -index e0f8dc73c..ee24cba81 100644 ---- a/src/tests/dejagnu/proxy-certs/ca.pem -+++ b/src/tests/dejagnu/proxy-certs/ca.pem -@@ -1,28 +1,28 @@ - -----BEGIN CERTIFICATE----- --MIIEuzCCA6OgAwIBAgIBATANBgkqhkiG9w0BAQUFADCBmTELMAkGA1UEBhMCVVMx --FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcTCUNhbWJyaWRnZTEMMAoG --A1UEChMDTUlUMSIwIAYDVQQLExlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww --KgYDVQQDFCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x --NDA1MDIxOTA2MDhaFw0yNTA0MTQxOTA2MDhaMIGZMQswCQYDVQQGEwJVUzEWMBQG --A1UECBMNTWFzc2FjaHVzZXR0czESMBAGA1UEBxMJQ2FtYnJpZGdlMQwwCgYDVQQK --EwNNSVQxIjAgBgNVBAsTGUluc2VjdXJlIEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNV --BAMUI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlMIIBIjANBgkq --hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1zudnpN8FP7iLn1vgkyTSn/RQxXx1yt6 --zikHaMrVPjkjXPPUoCFpWS3eeI4aQFoj93L5MwZDmSxOflBAqLwV2AMAacrYnNPJ --IkHtbYKdVsvw9b4INTWqV9/DOODO7UowyMppmO35/pUXaLL+AjHjLw1/EhQ3ZYtq --fpAMOkf5TnS5GtqZFlrYgZKE8vTC8BxDKM7FYhWYz7kp/tG3S8O/RTnP7Nd+h1Yd --pmlHBGfuwIRIJz5xNw6KIcCy3Q0NNoKnh00WVwLmR+x11BGSkMjiZZkwJ5D0RObS --g13QD/itrGoV2gtPzjQgNPfTrjsMvyOWAAFrWVR3QLTxnnmXsqnXvwIDAQABo4IB --CjCCAQYwHQYDVR0OBBYEFHO5+DSYzq8rvQhUldyvn0y4AqlHMIHGBgNVHSMEgb4w --gbuAFHO5+DSYzq8rvQhUldyvn0y4AqlHoYGfpIGcMIGZMQswCQYDVQQGEwJVUzEW --MBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAGA1UEBxMJQ2FtYnJpZGdlMQwwCgYD --VQQKEwNNSVQxIjAgBgNVBAsTGUluc2VjdXJlIEtlcmJlcm9zIHRlc3QgQ0ExLDAq --BgNVBAMUI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlggEBMAsG --A1UdDwQEAwIB/jAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQAM --Mf4ptC6WoQBH3GoTfgBL0WlIeYeSFmLO7IaSjpK0FV6F/yF7iPFSXcpmu23m6USY --LRSxnAvxFTi+h1S5Za9O2Pjq88R9nHmesg4v8HJqOw4HpkDowYo2lumjIMfAutyR --MQUOujYJW1WyZ2PidN5M1exDeMgQN9nVjUCx/WKD9fnzOjOOR1Sc8Us2KpoyccIi --A+ABHubCvSO3cln0Sp7qjkssJScZtouzPu8FYiroTIR+1oSIKTpJiik1EptlsTea --L6fHTMHspFhZaiUJFHWTBAgn/dT+UkFntHdHGI6HWBThFVW05hKoarBA7N25W7FN --AHyfC0lKds4qFiBQkpdi -+MIIEuzCCA6OgAwIBAgIBATANBgkqhkiG9w0BAQsFADCBmTELMAkGA1UEBhMCVVMx -+FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG -+A1UECgwDTUlUMSIwIAYDVQQLDBlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww -+KgYDVQQDDCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x -+OTExMTIxODMwMzRaFw0zMDEwMjUxODMwMzRaMIGZMQswCQYDVQQGEwJVUzEWMBQG -+A1UECAwNTWFzc2FjaHVzZXR0czESMBAGA1UEBwwJQ2FtYnJpZGdlMQwwCgYDVQQK -+DANNSVQxIjAgBgNVBAsMGUluc2VjdXJlIEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNV -+BAMMI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlMIIBIjANBgkq -+hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA54HCeTTUe127pqjK8r28NGMw2r2x+hWK -+KayH5NmqOqnwnzRHkZE5UjkazQ/h97S6LZ6Yb8w3mJEyX1PdcNARDw2mbOPFk5N9 -+uXnBb6AZog7hh9wMe//g9a7PpKanfw69fSVgAr49TFFiLoKuyTgHiJOB7YgP0bTH -+EO4lLqusPQM16lRDSdoXg42udAh3uBY+QDs23snLSiB+9vt8gt6gXiaYb3BBOWs9 -+B3PKs374N9kOPsgcj+8kyR/M+q+RfK5biqS3ce/sxvPV0Kseh//1uJxlbQCwOiBd -+3TLWHLhW9F7rzEcvzn1Mfck35s0XDDRlGxRGGDy+ZCKmxf8Zu/8SwwIDAQABo4IB -+CjCCAQYwHQYDVR0OBBYEFPf/vJvFMCwrABeCC0sq7RGfYeIiMIHGBgNVHSMEgb4w -+gbuAFPf/vJvFMCwrABeCC0sq7RGfYeIioYGfpIGcMIGZMQswCQYDVQQGEwJVUzEW -+MBQGA1UECAwNTWFzc2FjaHVzZXR0czESMBAGA1UEBwwJQ2FtYnJpZGdlMQwwCgYD -+VQQKDANNSVQxIjAgBgNVBAsMGUluc2VjdXJlIEtlcmJlcm9zIHRlc3QgQ0ExLDAq -+BgNVBAMMI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlggEBMAsG -+A1UdDwQEAwIB/jAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBz -+q/t9amz4ahTFNc0v69NZrfCBgo7DWBHxXuE0Gov2/RBPwP/+Efrd4+1Tl5fSv6We -+N/cttEUTTM3Z7wtof3mkSQwkozwWpaHXm31St+0FbTuHNpN4i0Uae5lsO8/pTz/L -+VqsVLjGGpkZKP831BO9oJJbwUASNc2dpLs94pojlSlSZzf/u/T+k0wltgZexnQpU -+5IrdPIqteB32ym2XjZWSCS29jL3zoZ/y8UAPIOR/Zi77wNCehOuBx2bzc/P6RNLa -+CuuPMhDu8PPYVB3rfJInmF5wT5jQ9YX4UUb0qYXDRff5/l26fEjLHQSrA/iMqdIW -+dsDwkqTcy1lOjcP3xOMq - -----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/proxy-certs/make-certs.sh b/src/tests/dejagnu/proxy-certs/make-certs.sh -index 24ef91bde..7a40e2b98 100755 ---- a/src/tests/dejagnu/proxy-certs/make-certs.sh -+++ b/src/tests/dejagnu/proxy-certs/make-certs.sh -@@ -25,7 +25,7 @@ private_key = $PWD/privkey.pem - default_days = $DAYS - x509_extensions = exts_proxy - policy = proxyname --default_md = sha1 -+default_md = sha256 - unique_subject = no - email_in_dn = no - -diff --git a/src/tests/dejagnu/proxy-certs/proxy-badsig.pem b/src/tests/dejagnu/proxy-certs/proxy-badsig.pem -index 2b31f7d6a..40001d974 100644 ---- a/src/tests/dejagnu/proxy-certs/proxy-badsig.pem -+++ b/src/tests/dejagnu/proxy-certs/proxy-badsig.pem -@@ -1,56 +1,56 @@ - -----BEGIN RSA PRIVATE KEY----- --MIIEpQIBAAKCAQEA1zudnpN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPU --oCFpWS3eeI4aQFoj93L5MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4I --NTWqV9/DOODO7UowyMppmO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZ --FlrYgZKE8vTC8BxDKM7FYhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5x --Nw6KIcCy3Q0NNoKnh00WVwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtP --zjQgNPfTrjsMvyOWAAFrWVR3QLTxnnmXsqnXvwIDAQABAoIBAQCqvhpeMDXhGgoo --Q03wmfrGwPsrMv91aIK1hYrhMPdVs1JAbRYiKh8+pcq07FYa8udRaB4UwkVh/+oM --/nEs6niRsl/jjQ2l68TFrnNByroynvr6l9Q/EeGecF6Ygo7lY1OsFhcLQM5vjarS --XhxvdU/6hcRmfS8tGRpUaMWqfmpiN3YgJcgt8SoYhiwAYDTMJjNyWC61lO7IqNVR --4kntiM24sfAu1sdZynX8Gp2GrpNChapEuhilQ8RayjuStEYr2abcSIjfZFHQXN7o --TnjL+AQUzc/ZTXDGnIe9ZzZeFz8UCueeoN6KPxfrq9UUWRL6qt7gOIMdhYR6lFxt --6pj6kLhxAoGBAO5DTnTKDfCMY2/AsTzCJvMGSY0bT1rsdDxrpqjrbUSeMHV3s5Lm --vEPnnm+05FD/vi99+HZjHXAZFkhA3ubij2qWFPBnQ5YUoh17IW/Ae4bzY2uXikgL --tLZ+R+OrcGYQQlvPn//PLsxbfdk5vraqzm08kIX0T4o4Iz8ST5NFJ8hVAoGBAOdB --ahXr14563Cjeu0pSQ1nXoz3IXdnDwePXasYhxQHl8Ayk8qZS5pt7r07H3dqq6pvn --e09gZINJe47B9UhkR3H5bPyz/kujKS4zqo3Zlbryzm3V0BWqjNj+j8E2YuQKNQr+ --c480jn2FzwW66w0i3n4U4KUn1w2/iq5AnVzyNkPDAoGAWLYEsyU79XE/4K79DqM3 --P0r6/afKbw8U5B4syj4FzAOeBU6RNMPmGt5VNkBCtgnSdPpRFTsoDcG5cyN8GrkG --Lug8WZoJJwr9pT5gH6yqEX/zZ27f1J1PJpd0CsedLNMm8eonJ2arhPkXrVZ7tKV6 --AGAJa2agatUmAmi96hZYjpUCgYEA32abJEgsedEIhFb/GYI03ELryRCaUXfCA+gj --lvoihn3qE1z5qGGns4adyX5dPRQmBqxtvDXDg+zl9vg6i0+MkXdCqTD8tXcOnjp9 --RgFvmyVa9FI8beHPpQTuPNncWK3fpho/6pT8Hhi48LEsxwjrZWOnzQSaxQZH46Q6 --IQNAFt8CgYEAkflxXvA2/2naix+riaBzv5EVJB7ilbfWiWtq2LEAtwrQ5XNFjrtK --g45jKrZ/ezAzTfPa5Dwn4xcImd0MIavnJhDu2ATxMGB0GATLlDH2HZvU7UwKLpTW --6Hlol4yRcX4GSEOxJ2ZpWYNIOYH0yDf1qLJXs1j8Fi3zWRe+V1kff4w= -+MIIEpAIBAAKCAQEA54HCeTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRH -+kZE5UjkazQ/h97S6LZ6Yb8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wM -+e//g9a7PpKanfw69fSVgAr49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRD -+SdoXg42udAh3uBY+QDs23snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgc -+j+8kyR/M+q+RfK5biqS3ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcv -+zn1Mfck35s0XDDRlGxRGGDy+ZCKmxf8Zu/8SwwIDAQABAoIBAGxzOBQpsIReQ6Lu -+HaybP4hXEzLVfIOIBaJCJaMKaJl0tLkP95r0qiKfh7OahiPRMQpf6k8tHrpFApDv -+q6PGhMdFgLov9YWNqW7y37AYEwn86KAJcHvCQbM2AiXCwGJgGFqA4LpIPlT7JwBc -+zd6LddQALfSFMcvuYPbIaPi1CUnGy/AAyxGjUrc60KO57NbI+dHSTOwTHO1QjOz9 -+ESk4fb34beUuZQzR6s/s1N0k09GJyklLpAAblRs5M6w9IlAn781eRLUAHTafLm4b -+21J9k2Q2UaOofn0Cvh8ggyJMiYqAJ0CsRy5pJroEyboA51WU+8THNFkNtRX5SxY5 -+YY3xE7ECgYEA/qkq7BPMkr/SnBPm32G1Eux5eLVd65qbox0oTLodZbusuxutqXTp -+1MseDPQtHlrq6CQBizwElx//pdKnIiU9iBS/QkMR9CviitMTt+WrWRrM54/A4CJP -+AU2Jg7b2DmhW1ombHHiBZ1tWzyiv9zxrtwR8kmKqv9aTOuPn4l7jY5kCgYEA6Llr -+47pQjp/YhkBBvlriRwM9RXek++ythgsWvEswORaUalnaZ9gxZOKKas35GLDDuVyT -+RnEhIqVlTg9iz6x5fXRtm6VzQvy9yFLzPMnlwsiSnRNOfMVIETUTOhNgm45tYY8f -+lN5bcdY6k6VZ/g/N3zqddnxkjocrd6lAayjjIrsCgYEAyZLYAcPuQx6JM7fhIGIz -+tQXvZKeS7yITHbq/onQTPuqd4AEZpi9/w0r/v1srt4JZvGR7wF1CeOkAL56dYr69 -+hNB/T5DNTkvKZv6K9h5aUg6PsJ8uGXuus6ZPOi4BeAgI7IpBd/i+3TQEc7eOCZIO -+5PAtNqXY6D6NjajGbH2VWckCgYA2KRDmyrF8v86QT9v9BQGsLSDRTerjhk1L6MC9 -+yXHLl2mq5oZhrHqyU9aKzKywBlNGjDjqJ+HiQkO1SvdgBW+wtqvbkUGl0VQJjuR0 -+vTfvgOY+EAQwHWmMN6Hl3iSZjyf9kGV1K9p0P7saKV0sN1leHjIPJRvx35tKGeWY -+CsfxiQKBgQCVUvsX/HeWyc4bxxMuzw8JniUG2JftZqIC1haHEFNElASjt4hARM7Y -+X/dkpYPXOZaN+qfvP949rS1WPXRtwMjt7bYzm7MGbXW7OiGGY3LV2CuVmbXJupvr -+Usvi+YnpqKDY/miOYd+541NJm76AQTSgQ8K7XitX7Beddh1U9e17mg== - -----END RSA PRIVATE KEY----- - -----BEGIN CERTIFICATE----- --MIIE3TCCA8WgAwIBAgIBBTANBgkqhkiG9w0BAQUFADCBmTELMAkGA1UEBhMCVVMx --FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcTCUNhbWJyaWRnZTEMMAoG --A1UEChMDTUlUMSIwIAYDVQQLExlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww --KgYDVQQDFCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x --NDA1MDIxOTA2MDlaFw0yNTA0MTQxOTA2MDlaME8xCzAJBgNVBAYTAlVTMRYwFAYD --VQQIEw1NYXNzYWNodXNldHRzMRQwEgYDVQQKEwtLUkJURVNULkNPTTESMBAGA1UE --AxMJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1zud --npN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPUoCFpWS3eeI4aQFoj93L5 --MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4INTWqV9/DOODO7UowyMpp --mO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZFlrYgZKE8vTC8BxDKM7F --YhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5xNw6KIcCy3Q0NNoKnh00W --VwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtPzjQgNPfTrjsMvyOWAAFr --WVR3QLTxnnmXsqnXvwIDAQABo4IBdzCCAXMwHQYDVR0OBBYEFHO5+DSYzq8rvQhU --ldyvn0y4AqlHMIHGBgNVHSMEgb4wgbuAFHO5+DSYzq8rvQhUldyvn0y4AqlHoYGf --pIGcMIGZMQswCQYDVQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAG --A1UEBxMJQ2FtYnJpZGdlMQwwCgYDVQQKEwNNSVQxIjAgBgNVBAsTGUluc2VjdXJl --IEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNVBAMUI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5v -+MIIE3TCCA8WgAwIBAgIBBTANBgkqhkiG9w0BAQsFADCBmTELMAkGA1UEBhMCVVMx -+FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG -+A1UECgwDTUlUMSIwIAYDVQQLDBlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww -+KgYDVQQDDCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x -+OTExMTIxODMwMzRaFw0zMDEwMjUxODMwMzRaME8xCzAJBgNVBAYTAlVTMRYwFAYD -+VQQIDA1NYXNzYWNodXNldHRzMRQwEgYDVQQKDAtLUkJURVNULkNPTTESMBAGA1UE -+AwwJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA54HC -+eTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRHkZE5UjkazQ/h97S6LZ6Y -+b8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wMe//g9a7PpKanfw69fSVg -+Ar49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRDSdoXg42udAh3uBY+QDs2 -+3snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgcj+8kyR/M+q+RfK5biqS3 -+ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcvzn1Mfck35s0XDDRlGxRG -+GDy+ZCKmxf8Zu/8SwwIDAQABo4IBdzCCAXMwHQYDVR0OBBYEFPf/vJvFMCwrABeC -+C0sq7RGfYeIiMIHGBgNVHSMEgb4wgbuAFPf/vJvFMCwrABeCC0sq7RGfYeIioYGf -+pIGcMIGZMQswCQYDVQQGEwJVUzEWMBQGA1UECAwNTWFzc2FjaHVzZXR0czESMBAG -+A1UEBwwJQ2FtYnJpZGdlMQwwCgYDVQQKDANNSVQxIjAgBgNVBAsMGUluc2VjdXJl -+IEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNVBAMMI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5v - dCB1c2Ugb3RoZXJ3aXNlggEBMAsGA1UdDwQEAwID6DAMBgNVHRMBAf8EAjAAMFkG - A1UdEQRSMFCCFnByb3h5xaB1YmplY3TDhGx0w5FhbWWCE3Byb3h5U3ViamVjdEFs - dE5hbWWHBH8AAAGHEAAAAAAAAAAAAAAAAAAAAAGCCWxvY2FsaG9zdDATBgNVHSUE --DDAKBggrBgEFBQcDATANBgkqhkiG9w0BAQUFAAOCAQEAfTctgFjQSaevBi64q7yh --GNsK3PqeNEALZz4pSXRbOwm0E4RpYIS7uqg1C4zJ5Zbd4V/dOX7q+T/iBS7gErzS --rj21jH3Ggc92TmXzcFxMDCxLV0hO8xFkqg3P4sslJESOHxvEMTTf5s893yUb8vJ/ --DCvZXXRoRwPot9MFozkmcQcaTNunREWFvn4i4JXcMCSAfWTd+/VkpVsy69u3tj68 --7G2/K5nalvZikutEC+DyfyBuvDAoxIYzCi3VtQxCalW28Q5hzWV21QsvKTP5QBsh --RaU2r0O58lZPPvrOrtWQBCudUgsnoraVLrjJshEQ4z/ZAAAAAAAAAAAAAAAAAAAA -+DDAKBggrBgEFBQcDATANBgkqhkiG9w0BAQsFAAOCAQEAsMRJnxdbnpm5VlCFwNyU -+8ra1wCjj+ZH0POVCM4iXQ77bV6UBpcqlaQUvR7R/H1Bt5t3Cp0ycN/dy+RcXtj+5 -+FA84bRM767rsakxTEwjOjWw6GiK6bGjBfQ4F6Q97ELmiM0OZgmW8D56UHZxrI+o7 -+QrKWBpFf1UA8n/BmupHBtyW3gudtJS9a71u6lBRydPFqJ4l8YxHckbgPFceSRbRj -+x7E2pQVQ0p2nvG/NVyuC+2L29p81KAsG3vPzwOOfr1Tnpl1/B4R0+XEIy33KHpbz -+Ceyitz6k16fOVNxMI59W2OACPTQ/s99kygh+cARRPfEUAAAAAAAAAAAAAAAAAAAA - AA== - -----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/proxy-certs/proxy-ideal.pem b/src/tests/dejagnu/proxy-certs/proxy-ideal.pem -index 4588f7d4e..3bb09dc94 100644 ---- a/src/tests/dejagnu/proxy-certs/proxy-ideal.pem -+++ b/src/tests/dejagnu/proxy-certs/proxy-ideal.pem -@@ -1,56 +1,56 @@ - -----BEGIN RSA PRIVATE KEY----- --MIIEpQIBAAKCAQEA1zudnpN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPU --oCFpWS3eeI4aQFoj93L5MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4I --NTWqV9/DOODO7UowyMppmO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZ --FlrYgZKE8vTC8BxDKM7FYhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5x --Nw6KIcCy3Q0NNoKnh00WVwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtP --zjQgNPfTrjsMvyOWAAFrWVR3QLTxnnmXsqnXvwIDAQABAoIBAQCqvhpeMDXhGgoo --Q03wmfrGwPsrMv91aIK1hYrhMPdVs1JAbRYiKh8+pcq07FYa8udRaB4UwkVh/+oM --/nEs6niRsl/jjQ2l68TFrnNByroynvr6l9Q/EeGecF6Ygo7lY1OsFhcLQM5vjarS --XhxvdU/6hcRmfS8tGRpUaMWqfmpiN3YgJcgt8SoYhiwAYDTMJjNyWC61lO7IqNVR --4kntiM24sfAu1sdZynX8Gp2GrpNChapEuhilQ8RayjuStEYr2abcSIjfZFHQXN7o --TnjL+AQUzc/ZTXDGnIe9ZzZeFz8UCueeoN6KPxfrq9UUWRL6qt7gOIMdhYR6lFxt --6pj6kLhxAoGBAO5DTnTKDfCMY2/AsTzCJvMGSY0bT1rsdDxrpqjrbUSeMHV3s5Lm --vEPnnm+05FD/vi99+HZjHXAZFkhA3ubij2qWFPBnQ5YUoh17IW/Ae4bzY2uXikgL --tLZ+R+OrcGYQQlvPn//PLsxbfdk5vraqzm08kIX0T4o4Iz8ST5NFJ8hVAoGBAOdB --ahXr14563Cjeu0pSQ1nXoz3IXdnDwePXasYhxQHl8Ayk8qZS5pt7r07H3dqq6pvn --e09gZINJe47B9UhkR3H5bPyz/kujKS4zqo3Zlbryzm3V0BWqjNj+j8E2YuQKNQr+ --c480jn2FzwW66w0i3n4U4KUn1w2/iq5AnVzyNkPDAoGAWLYEsyU79XE/4K79DqM3 --P0r6/afKbw8U5B4syj4FzAOeBU6RNMPmGt5VNkBCtgnSdPpRFTsoDcG5cyN8GrkG --Lug8WZoJJwr9pT5gH6yqEX/zZ27f1J1PJpd0CsedLNMm8eonJ2arhPkXrVZ7tKV6 --AGAJa2agatUmAmi96hZYjpUCgYEA32abJEgsedEIhFb/GYI03ELryRCaUXfCA+gj --lvoihn3qE1z5qGGns4adyX5dPRQmBqxtvDXDg+zl9vg6i0+MkXdCqTD8tXcOnjp9 --RgFvmyVa9FI8beHPpQTuPNncWK3fpho/6pT8Hhi48LEsxwjrZWOnzQSaxQZH46Q6 --IQNAFt8CgYEAkflxXvA2/2naix+riaBzv5EVJB7ilbfWiWtq2LEAtwrQ5XNFjrtK --g45jKrZ/ezAzTfPa5Dwn4xcImd0MIavnJhDu2ATxMGB0GATLlDH2HZvU7UwKLpTW --6Hlol4yRcX4GSEOxJ2ZpWYNIOYH0yDf1qLJXs1j8Fi3zWRe+V1kff4w= -+MIIEpAIBAAKCAQEA54HCeTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRH -+kZE5UjkazQ/h97S6LZ6Yb8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wM -+e//g9a7PpKanfw69fSVgAr49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRD -+SdoXg42udAh3uBY+QDs23snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgc -+j+8kyR/M+q+RfK5biqS3ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcv -+zn1Mfck35s0XDDRlGxRGGDy+ZCKmxf8Zu/8SwwIDAQABAoIBAGxzOBQpsIReQ6Lu -+HaybP4hXEzLVfIOIBaJCJaMKaJl0tLkP95r0qiKfh7OahiPRMQpf6k8tHrpFApDv -+q6PGhMdFgLov9YWNqW7y37AYEwn86KAJcHvCQbM2AiXCwGJgGFqA4LpIPlT7JwBc -+zd6LddQALfSFMcvuYPbIaPi1CUnGy/AAyxGjUrc60KO57NbI+dHSTOwTHO1QjOz9 -+ESk4fb34beUuZQzR6s/s1N0k09GJyklLpAAblRs5M6w9IlAn781eRLUAHTafLm4b -+21J9k2Q2UaOofn0Cvh8ggyJMiYqAJ0CsRy5pJroEyboA51WU+8THNFkNtRX5SxY5 -+YY3xE7ECgYEA/qkq7BPMkr/SnBPm32G1Eux5eLVd65qbox0oTLodZbusuxutqXTp -+1MseDPQtHlrq6CQBizwElx//pdKnIiU9iBS/QkMR9CviitMTt+WrWRrM54/A4CJP -+AU2Jg7b2DmhW1ombHHiBZ1tWzyiv9zxrtwR8kmKqv9aTOuPn4l7jY5kCgYEA6Llr -+47pQjp/YhkBBvlriRwM9RXek++ythgsWvEswORaUalnaZ9gxZOKKas35GLDDuVyT -+RnEhIqVlTg9iz6x5fXRtm6VzQvy9yFLzPMnlwsiSnRNOfMVIETUTOhNgm45tYY8f -+lN5bcdY6k6VZ/g/N3zqddnxkjocrd6lAayjjIrsCgYEAyZLYAcPuQx6JM7fhIGIz -+tQXvZKeS7yITHbq/onQTPuqd4AEZpi9/w0r/v1srt4JZvGR7wF1CeOkAL56dYr69 -+hNB/T5DNTkvKZv6K9h5aUg6PsJ8uGXuus6ZPOi4BeAgI7IpBd/i+3TQEc7eOCZIO -+5PAtNqXY6D6NjajGbH2VWckCgYA2KRDmyrF8v86QT9v9BQGsLSDRTerjhk1L6MC9 -+yXHLl2mq5oZhrHqyU9aKzKywBlNGjDjqJ+HiQkO1SvdgBW+wtqvbkUGl0VQJjuR0 -+vTfvgOY+EAQwHWmMN6Hl3iSZjyf9kGV1K9p0P7saKV0sN1leHjIPJRvx35tKGeWY -+CsfxiQKBgQCVUvsX/HeWyc4bxxMuzw8JniUG2JftZqIC1haHEFNElASjt4hARM7Y -+X/dkpYPXOZaN+qfvP949rS1WPXRtwMjt7bYzm7MGbXW7OiGGY3LV2CuVmbXJupvr -+Usvi+YnpqKDY/miOYd+541NJm76AQTSgQ8K7XitX7Beddh1U9e17mg== - -----END RSA PRIVATE KEY----- - -----BEGIN CERTIFICATE----- --MIIE3TCCA8WgAwIBAgIBBTANBgkqhkiG9w0BAQUFADCBmTELMAkGA1UEBhMCVVMx --FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcTCUNhbWJyaWRnZTEMMAoG --A1UEChMDTUlUMSIwIAYDVQQLExlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww --KgYDVQQDFCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x --NDA1MDIxOTA2MDlaFw0yNTA0MTQxOTA2MDlaME8xCzAJBgNVBAYTAlVTMRYwFAYD --VQQIEw1NYXNzYWNodXNldHRzMRQwEgYDVQQKEwtLUkJURVNULkNPTTESMBAGA1UE --AxMJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1zud --npN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPUoCFpWS3eeI4aQFoj93L5 --MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4INTWqV9/DOODO7UowyMpp --mO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZFlrYgZKE8vTC8BxDKM7F --YhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5xNw6KIcCy3Q0NNoKnh00W --VwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtPzjQgNPfTrjsMvyOWAAFr --WVR3QLTxnnmXsqnXvwIDAQABo4IBdzCCAXMwHQYDVR0OBBYEFHO5+DSYzq8rvQhU --ldyvn0y4AqlHMIHGBgNVHSMEgb4wgbuAFHO5+DSYzq8rvQhUldyvn0y4AqlHoYGf --pIGcMIGZMQswCQYDVQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAG --A1UEBxMJQ2FtYnJpZGdlMQwwCgYDVQQKEwNNSVQxIjAgBgNVBAsTGUluc2VjdXJl --IEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNVBAMUI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5v -+MIIE3TCCA8WgAwIBAgIBBTANBgkqhkiG9w0BAQsFADCBmTELMAkGA1UEBhMCVVMx -+FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG -+A1UECgwDTUlUMSIwIAYDVQQLDBlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww -+KgYDVQQDDCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x -+OTExMTIxODMwMzRaFw0zMDEwMjUxODMwMzRaME8xCzAJBgNVBAYTAlVTMRYwFAYD -+VQQIDA1NYXNzYWNodXNldHRzMRQwEgYDVQQKDAtLUkJURVNULkNPTTESMBAGA1UE -+AwwJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA54HC -+eTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRHkZE5UjkazQ/h97S6LZ6Y -+b8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wMe//g9a7PpKanfw69fSVg -+Ar49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRDSdoXg42udAh3uBY+QDs2 -+3snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgcj+8kyR/M+q+RfK5biqS3 -+ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcvzn1Mfck35s0XDDRlGxRG -+GDy+ZCKmxf8Zu/8SwwIDAQABo4IBdzCCAXMwHQYDVR0OBBYEFPf/vJvFMCwrABeC -+C0sq7RGfYeIiMIHGBgNVHSMEgb4wgbuAFPf/vJvFMCwrABeCC0sq7RGfYeIioYGf -+pIGcMIGZMQswCQYDVQQGEwJVUzEWMBQGA1UECAwNTWFzc2FjaHVzZXR0czESMBAG -+A1UEBwwJQ2FtYnJpZGdlMQwwCgYDVQQKDANNSVQxIjAgBgNVBAsMGUluc2VjdXJl -+IEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNVBAMMI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5v - dCB1c2Ugb3RoZXJ3aXNlggEBMAsGA1UdDwQEAwID6DAMBgNVHRMBAf8EAjAAMFkG - A1UdEQRSMFCCFnByb3h5xaB1YmplY3TDhGx0w5FhbWWCE3Byb3h5U3ViamVjdEFs - dE5hbWWHBH8AAAGHEAAAAAAAAAAAAAAAAAAAAAGCCWxvY2FsaG9zdDATBgNVHSUE --DDAKBggrBgEFBQcDATANBgkqhkiG9w0BAQUFAAOCAQEAfTctgFjQSaevBi64q7yh --GNsK3PqeNEALZz4pSXRbOwm0E4RpYIS7uqg1C4zJ5Zbd4V/dOX7q+T/iBS7gErzS --rj21jH3Ggc92TmXzcFxMDCxLV0hO8xFkqg3P4sslJESOHxvEMTTf5s893yUb8vJ/ --DCvZXXRoRwPot9MFozkmcQcaTNunREWFvn4i4JXcMCSAfWTd+/VkpVsy69u3tj68 --7G2/K5nalvZikutEC+DyfyBuvDAoxIYzCi3VtQxCalW28Q5hzWV21QsvKTP5QBsh --RaU2r0O58lZPPvrOrtWQBCudUgsnoraVLrjJshEQ4z/ZA9fVtX2ndCSIoyWpWk01 --gQ== -+DDAKBggrBgEFBQcDATANBgkqhkiG9w0BAQsFAAOCAQEAsMRJnxdbnpm5VlCFwNyU -+8ra1wCjj+ZH0POVCM4iXQ77bV6UBpcqlaQUvR7R/H1Bt5t3Cp0ycN/dy+RcXtj+5 -+FA84bRM767rsakxTEwjOjWw6GiK6bGjBfQ4F6Q97ELmiM0OZgmW8D56UHZxrI+o7 -+QrKWBpFf1UA8n/BmupHBtyW3gudtJS9a71u6lBRydPFqJ4l8YxHckbgPFceSRbRj -+x7E2pQVQ0p2nvG/NVyuC+2L29p81KAsG3vPzwOOfr1Tnpl1/B4R0+XEIy33KHpbz -+Ceyitz6k16fOVNxMI59W2OACPTQ/s99kygh+cARRPfEUPjDcJpS1gRZ6kDKRh6Np -+ig== - -----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/proxy-certs/proxy-no-match.pem b/src/tests/dejagnu/proxy-certs/proxy-no-match.pem -index a97c1c77b..7464e40db 100644 ---- a/src/tests/dejagnu/proxy-certs/proxy-no-match.pem -+++ b/src/tests/dejagnu/proxy-certs/proxy-no-match.pem -@@ -1,54 +1,54 @@ - -----BEGIN RSA PRIVATE KEY----- --MIIEpQIBAAKCAQEA1zudnpN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPU --oCFpWS3eeI4aQFoj93L5MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4I --NTWqV9/DOODO7UowyMppmO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZ --FlrYgZKE8vTC8BxDKM7FYhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5x --Nw6KIcCy3Q0NNoKnh00WVwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtP --zjQgNPfTrjsMvyOWAAFrWVR3QLTxnnmXsqnXvwIDAQABAoIBAQCqvhpeMDXhGgoo --Q03wmfrGwPsrMv91aIK1hYrhMPdVs1JAbRYiKh8+pcq07FYa8udRaB4UwkVh/+oM --/nEs6niRsl/jjQ2l68TFrnNByroynvr6l9Q/EeGecF6Ygo7lY1OsFhcLQM5vjarS --XhxvdU/6hcRmfS8tGRpUaMWqfmpiN3YgJcgt8SoYhiwAYDTMJjNyWC61lO7IqNVR --4kntiM24sfAu1sdZynX8Gp2GrpNChapEuhilQ8RayjuStEYr2abcSIjfZFHQXN7o --TnjL+AQUzc/ZTXDGnIe9ZzZeFz8UCueeoN6KPxfrq9UUWRL6qt7gOIMdhYR6lFxt --6pj6kLhxAoGBAO5DTnTKDfCMY2/AsTzCJvMGSY0bT1rsdDxrpqjrbUSeMHV3s5Lm --vEPnnm+05FD/vi99+HZjHXAZFkhA3ubij2qWFPBnQ5YUoh17IW/Ae4bzY2uXikgL --tLZ+R+OrcGYQQlvPn//PLsxbfdk5vraqzm08kIX0T4o4Iz8ST5NFJ8hVAoGBAOdB --ahXr14563Cjeu0pSQ1nXoz3IXdnDwePXasYhxQHl8Ayk8qZS5pt7r07H3dqq6pvn --e09gZINJe47B9UhkR3H5bPyz/kujKS4zqo3Zlbryzm3V0BWqjNj+j8E2YuQKNQr+ --c480jn2FzwW66w0i3n4U4KUn1w2/iq5AnVzyNkPDAoGAWLYEsyU79XE/4K79DqM3 --P0r6/afKbw8U5B4syj4FzAOeBU6RNMPmGt5VNkBCtgnSdPpRFTsoDcG5cyN8GrkG --Lug8WZoJJwr9pT5gH6yqEX/zZ27f1J1PJpd0CsedLNMm8eonJ2arhPkXrVZ7tKV6 --AGAJa2agatUmAmi96hZYjpUCgYEA32abJEgsedEIhFb/GYI03ELryRCaUXfCA+gj --lvoihn3qE1z5qGGns4adyX5dPRQmBqxtvDXDg+zl9vg6i0+MkXdCqTD8tXcOnjp9 --RgFvmyVa9FI8beHPpQTuPNncWK3fpho/6pT8Hhi48LEsxwjrZWOnzQSaxQZH46Q6 --IQNAFt8CgYEAkflxXvA2/2naix+riaBzv5EVJB7ilbfWiWtq2LEAtwrQ5XNFjrtK --g45jKrZ/ezAzTfPa5Dwn4xcImd0MIavnJhDu2ATxMGB0GATLlDH2HZvU7UwKLpTW --6Hlol4yRcX4GSEOxJ2ZpWYNIOYH0yDf1qLJXs1j8Fi3zWRe+V1kff4w= -+MIIEpAIBAAKCAQEA54HCeTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRH -+kZE5UjkazQ/h97S6LZ6Yb8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wM -+e//g9a7PpKanfw69fSVgAr49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRD -+SdoXg42udAh3uBY+QDs23snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgc -+j+8kyR/M+q+RfK5biqS3ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcv -+zn1Mfck35s0XDDRlGxRGGDy+ZCKmxf8Zu/8SwwIDAQABAoIBAGxzOBQpsIReQ6Lu -+HaybP4hXEzLVfIOIBaJCJaMKaJl0tLkP95r0qiKfh7OahiPRMQpf6k8tHrpFApDv -+q6PGhMdFgLov9YWNqW7y37AYEwn86KAJcHvCQbM2AiXCwGJgGFqA4LpIPlT7JwBc -+zd6LddQALfSFMcvuYPbIaPi1CUnGy/AAyxGjUrc60KO57NbI+dHSTOwTHO1QjOz9 -+ESk4fb34beUuZQzR6s/s1N0k09GJyklLpAAblRs5M6w9IlAn781eRLUAHTafLm4b -+21J9k2Q2UaOofn0Cvh8ggyJMiYqAJ0CsRy5pJroEyboA51WU+8THNFkNtRX5SxY5 -+YY3xE7ECgYEA/qkq7BPMkr/SnBPm32G1Eux5eLVd65qbox0oTLodZbusuxutqXTp -+1MseDPQtHlrq6CQBizwElx//pdKnIiU9iBS/QkMR9CviitMTt+WrWRrM54/A4CJP -+AU2Jg7b2DmhW1ombHHiBZ1tWzyiv9zxrtwR8kmKqv9aTOuPn4l7jY5kCgYEA6Llr -+47pQjp/YhkBBvlriRwM9RXek++ythgsWvEswORaUalnaZ9gxZOKKas35GLDDuVyT -+RnEhIqVlTg9iz6x5fXRtm6VzQvy9yFLzPMnlwsiSnRNOfMVIETUTOhNgm45tYY8f -+lN5bcdY6k6VZ/g/N3zqddnxkjocrd6lAayjjIrsCgYEAyZLYAcPuQx6JM7fhIGIz -+tQXvZKeS7yITHbq/onQTPuqd4AEZpi9/w0r/v1srt4JZvGR7wF1CeOkAL56dYr69 -+hNB/T5DNTkvKZv6K9h5aUg6PsJ8uGXuus6ZPOi4BeAgI7IpBd/i+3TQEc7eOCZIO -+5PAtNqXY6D6NjajGbH2VWckCgYA2KRDmyrF8v86QT9v9BQGsLSDRTerjhk1L6MC9 -+yXHLl2mq5oZhrHqyU9aKzKywBlNGjDjqJ+HiQkO1SvdgBW+wtqvbkUGl0VQJjuR0 -+vTfvgOY+EAQwHWmMN6Hl3iSZjyf9kGV1K9p0P7saKV0sN1leHjIPJRvx35tKGeWY -+CsfxiQKBgQCVUvsX/HeWyc4bxxMuzw8JniUG2JftZqIC1haHEFNElASjt4hARM7Y -+X/dkpYPXOZaN+qfvP949rS1WPXRtwMjt7bYzm7MGbXW7OiGGY3LV2CuVmbXJupvr -+Usvi+YnpqKDY/miOYd+541NJm76AQTSgQ8K7XitX7Beddh1U9e17mg== - -----END RSA PRIVATE KEY----- - -----BEGIN CERTIFICATE----- --MIIEhzCCA2+gAwIBAgIBBDANBgkqhkiG9w0BAQUFADCBmTELMAkGA1UEBhMCVVMx --FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcTCUNhbWJyaWRnZTEMMAoG --A1UEChMDTUlUMSIwIAYDVQQLExlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww --KgYDVQQDFCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x --NDA1MDIxOTA2MDhaFw0yNTA0MTQxOTA2MDhaMFQxCzAJBgNVBAYTAlVTMRYwFAYD --VQQIEw1NYXNzYWNodXNldHRzMRQwEgYDVQQKEwtLUkJURVNULkNPTTEXMBUGA1UE --AxMOUFJPWFlpblN1YmplY3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB --AQDXO52ek3wU/uIufW+CTJNKf9FDFfHXK3rOKQdoytU+OSNc89SgIWlZLd54jhpA --WiP3cvkzBkOZLE5+UECovBXYAwBpytic08kiQe1tgp1Wy/D1vgg1NapX38M44M7t --SjDIymmY7fn+lRdosv4CMeMvDX8SFDdli2p+kAw6R/lOdLka2pkWWtiBkoTy9MLw --HEMozsViFZjPuSn+0bdLw79FOc/s136HVh2maUcEZ+7AhEgnPnE3DoohwLLdDQ02 --gqeHTRZXAuZH7HXUEZKQyOJlmTAnkPRE5tKDXdAP+K2sahXaC0/ONCA099OuOwy/ --I5YAAWtZVHdAtPGeeZeyqde/AgMBAAGjggEcMIIBGDAdBgNVHQ4EFgQUc7n4NJjO --ryu9CFSV3K+fTLgCqUcwgcYGA1UdIwSBvjCBu4AUc7n4NJjOryu9CFSV3K+fTLgC --qUehgZ+kgZwwgZkxCzAJBgNVBAYTAlVTMRYwFAYDVQQIEw1NYXNzYWNodXNldHRz --MRIwEAYDVQQHEwlDYW1icmlkZ2UxDDAKBgNVBAoTA01JVDEiMCAGA1UECxMZSW5z --ZWN1cmUgS2VyYmVyb3MgdGVzdCBDQTEsMCoGA1UEAxQjdGVzdCBzdWl0ZSBDQTsg -+MIIEhzCCA2+gAwIBAgIBBDANBgkqhkiG9w0BAQsFADCBmTELMAkGA1UEBhMCVVMx -+FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG -+A1UECgwDTUlUMSIwIAYDVQQLDBlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww -+KgYDVQQDDCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x -+OTExMTIxODMwMzRaFw0zMDEwMjUxODMwMzRaMFQxCzAJBgNVBAYTAlVTMRYwFAYD -+VQQIDA1NYXNzYWNodXNldHRzMRQwEgYDVQQKDAtLUkJURVNULkNPTTEXMBUGA1UE -+AwwOUFJPWFlpblN1YmplY3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB -+AQDngcJ5NNR7XbumqMryvbw0YzDavbH6FYoprIfk2ao6qfCfNEeRkTlSORrND+H3 -+tLotnphvzDeYkTJfU91w0BEPDaZs48WTk325ecFvoBmiDuGH3Ax7/+D1rs+kpqd/ -+Dr19JWACvj1MUWIugq7JOAeIk4HtiA/RtMcQ7iUuq6w9AzXqVENJ2heDja50CHe4 -+Fj5AOzbeyctKIH72+3yC3qBeJphvcEE5az0Hc8qzfvg32Q4+yByP7yTJH8z6r5F8 -+rluKpLdx7+zG89XQqx6H//W4nGVtALA6IF3dMtYcuFb0XuvMRy/OfUx9yTfmzRcM -+NGUbFEYYPL5kIqbF/xm7/xLDAgMBAAGjggEcMIIBGDAdBgNVHQ4EFgQU9/+8m8Uw -+LCsAF4ILSyrtEZ9h4iIwgcYGA1UdIwSBvjCBu4AU9/+8m8UwLCsAF4ILSyrtEZ9h -+4iKhgZ+kgZwwgZkxCzAJBgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNldHRz -+MRIwEAYDVQQHDAlDYW1icmlkZ2UxDDAKBgNVBAoMA01JVDEiMCAGA1UECwwZSW5z -+ZWN1cmUgS2VyYmVyb3MgdGVzdCBDQTEsMCoGA1UEAwwjdGVzdCBzdWl0ZSBDQTsg - ZG8gbm90IHVzZSBvdGhlcndpc2WCAQEwCwYDVR0PBAQDAgPoMAwGA1UdEwEB/wQC --MAAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwDQYJKoZIhvcNAQEFBQADggEBAMsP++r4 --vki0mBJg3POpp0i+H6zNMimoYLLtM5NvwXinfFuFQKbwLm8QWuHVifjfCYxMUm+l --iL5cS/bq+SUWGDmrlOhsuu4+aYaxgNiEyki5Rol6miSOHbfOhzX8yp0EBPpq08dg --SEdrTd/FIl4qgkkb1A4RJYZRErn/fbsyjJN66KIfSOXJuC8XMBf03Vw9f2rdrHJa --r5lVGvqa4wjO2MPq9vVK52VFrbU/zuyyCUtggyIOwGLGSY0Axtbci+IHToDBQes+ --6W4WwSUCssWfIZXQDLjFw1oRHnN43fXmX5vsVLi7YvOFHOAa1BDnDtCTZit26xVA --Mdic66hR2jHP0TE= -+MAAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwDQYJKoZIhvcNAQELBQADggEBAI0Ons8g -+6aXdZsKSmp1hbwNUvsY5GNl/QHVJIMQbe9zNVkW9Hp286fzkMar6peTB9MEnhzJ5 -+5mbJM9DkugzgJeG0+HwsSdjAQCOcG4jSQ3SaASETOo58LsaG/yssIaZiZdJBrzNb -+1D5fJVVpopZMZ/mKUNB/2ofUVGVBZCdfyOoIbVSkkm1UHJ9liLFK1ZNPDTX60613 -+YNl4BydTiXtEg+IOYgmFXuZj310dDZUMHuYdzAM5j+6i2JaIcK4PgDE+yG9Oj9N+ -+uKjj0iHWyoZW49y9Hq/oiMegi2X4XZBtbZlEUu4OkpBJ1QG0MTaz/vN94sHiLOzS -+81b7+2BMgHd51+E= - -----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/proxy-certs/proxy-san.pem b/src/tests/dejagnu/proxy-certs/proxy-san.pem -index ac8bbaa16..8eaeceece 100644 ---- a/src/tests/dejagnu/proxy-certs/proxy-san.pem -+++ b/src/tests/dejagnu/proxy-certs/proxy-san.pem -@@ -1,56 +1,56 @@ - -----BEGIN RSA PRIVATE KEY----- --MIIEpQIBAAKCAQEA1zudnpN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPU --oCFpWS3eeI4aQFoj93L5MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4I --NTWqV9/DOODO7UowyMppmO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZ --FlrYgZKE8vTC8BxDKM7FYhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5x --Nw6KIcCy3Q0NNoKnh00WVwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtP --zjQgNPfTrjsMvyOWAAFrWVR3QLTxnnmXsqnXvwIDAQABAoIBAQCqvhpeMDXhGgoo --Q03wmfrGwPsrMv91aIK1hYrhMPdVs1JAbRYiKh8+pcq07FYa8udRaB4UwkVh/+oM --/nEs6niRsl/jjQ2l68TFrnNByroynvr6l9Q/EeGecF6Ygo7lY1OsFhcLQM5vjarS --XhxvdU/6hcRmfS8tGRpUaMWqfmpiN3YgJcgt8SoYhiwAYDTMJjNyWC61lO7IqNVR --4kntiM24sfAu1sdZynX8Gp2GrpNChapEuhilQ8RayjuStEYr2abcSIjfZFHQXN7o --TnjL+AQUzc/ZTXDGnIe9ZzZeFz8UCueeoN6KPxfrq9UUWRL6qt7gOIMdhYR6lFxt --6pj6kLhxAoGBAO5DTnTKDfCMY2/AsTzCJvMGSY0bT1rsdDxrpqjrbUSeMHV3s5Lm --vEPnnm+05FD/vi99+HZjHXAZFkhA3ubij2qWFPBnQ5YUoh17IW/Ae4bzY2uXikgL --tLZ+R+OrcGYQQlvPn//PLsxbfdk5vraqzm08kIX0T4o4Iz8ST5NFJ8hVAoGBAOdB --ahXr14563Cjeu0pSQ1nXoz3IXdnDwePXasYhxQHl8Ayk8qZS5pt7r07H3dqq6pvn --e09gZINJe47B9UhkR3H5bPyz/kujKS4zqo3Zlbryzm3V0BWqjNj+j8E2YuQKNQr+ --c480jn2FzwW66w0i3n4U4KUn1w2/iq5AnVzyNkPDAoGAWLYEsyU79XE/4K79DqM3 --P0r6/afKbw8U5B4syj4FzAOeBU6RNMPmGt5VNkBCtgnSdPpRFTsoDcG5cyN8GrkG --Lug8WZoJJwr9pT5gH6yqEX/zZ27f1J1PJpd0CsedLNMm8eonJ2arhPkXrVZ7tKV6 --AGAJa2agatUmAmi96hZYjpUCgYEA32abJEgsedEIhFb/GYI03ELryRCaUXfCA+gj --lvoihn3qE1z5qGGns4adyX5dPRQmBqxtvDXDg+zl9vg6i0+MkXdCqTD8tXcOnjp9 --RgFvmyVa9FI8beHPpQTuPNncWK3fpho/6pT8Hhi48LEsxwjrZWOnzQSaxQZH46Q6 --IQNAFt8CgYEAkflxXvA2/2naix+riaBzv5EVJB7ilbfWiWtq2LEAtwrQ5XNFjrtK --g45jKrZ/ezAzTfPa5Dwn4xcImd0MIavnJhDu2ATxMGB0GATLlDH2HZvU7UwKLpTW --6Hlol4yRcX4GSEOxJ2ZpWYNIOYH0yDf1qLJXs1j8Fi3zWRe+V1kff4w= -+MIIEpAIBAAKCAQEA54HCeTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRH -+kZE5UjkazQ/h97S6LZ6Yb8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wM -+e//g9a7PpKanfw69fSVgAr49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRD -+SdoXg42udAh3uBY+QDs23snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgc -+j+8kyR/M+q+RfK5biqS3ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcv -+zn1Mfck35s0XDDRlGxRGGDy+ZCKmxf8Zu/8SwwIDAQABAoIBAGxzOBQpsIReQ6Lu -+HaybP4hXEzLVfIOIBaJCJaMKaJl0tLkP95r0qiKfh7OahiPRMQpf6k8tHrpFApDv -+q6PGhMdFgLov9YWNqW7y37AYEwn86KAJcHvCQbM2AiXCwGJgGFqA4LpIPlT7JwBc -+zd6LddQALfSFMcvuYPbIaPi1CUnGy/AAyxGjUrc60KO57NbI+dHSTOwTHO1QjOz9 -+ESk4fb34beUuZQzR6s/s1N0k09GJyklLpAAblRs5M6w9IlAn781eRLUAHTafLm4b -+21J9k2Q2UaOofn0Cvh8ggyJMiYqAJ0CsRy5pJroEyboA51WU+8THNFkNtRX5SxY5 -+YY3xE7ECgYEA/qkq7BPMkr/SnBPm32G1Eux5eLVd65qbox0oTLodZbusuxutqXTp -+1MseDPQtHlrq6CQBizwElx//pdKnIiU9iBS/QkMR9CviitMTt+WrWRrM54/A4CJP -+AU2Jg7b2DmhW1ombHHiBZ1tWzyiv9zxrtwR8kmKqv9aTOuPn4l7jY5kCgYEA6Llr -+47pQjp/YhkBBvlriRwM9RXek++ythgsWvEswORaUalnaZ9gxZOKKas35GLDDuVyT -+RnEhIqVlTg9iz6x5fXRtm6VzQvy9yFLzPMnlwsiSnRNOfMVIETUTOhNgm45tYY8f -+lN5bcdY6k6VZ/g/N3zqddnxkjocrd6lAayjjIrsCgYEAyZLYAcPuQx6JM7fhIGIz -+tQXvZKeS7yITHbq/onQTPuqd4AEZpi9/w0r/v1srt4JZvGR7wF1CeOkAL56dYr69 -+hNB/T5DNTkvKZv6K9h5aUg6PsJ8uGXuus6ZPOi4BeAgI7IpBd/i+3TQEc7eOCZIO -+5PAtNqXY6D6NjajGbH2VWckCgYA2KRDmyrF8v86QT9v9BQGsLSDRTerjhk1L6MC9 -+yXHLl2mq5oZhrHqyU9aKzKywBlNGjDjqJ+HiQkO1SvdgBW+wtqvbkUGl0VQJjuR0 -+vTfvgOY+EAQwHWmMN6Hl3iSZjyf9kGV1K9p0P7saKV0sN1leHjIPJRvx35tKGeWY -+CsfxiQKBgQCVUvsX/HeWyc4bxxMuzw8JniUG2JftZqIC1haHEFNElASjt4hARM7Y -+X/dkpYPXOZaN+qfvP949rS1WPXRtwMjt7bYzm7MGbXW7OiGGY3LV2CuVmbXJupvr -+Usvi+YnpqKDY/miOYd+541NJm76AQTSgQ8K7XitX7Beddh1U9e17mg== - -----END RSA PRIVATE KEY----- - -----BEGIN CERTIFICATE----- --MIIE4jCCA8qgAwIBAgIBAjANBgkqhkiG9w0BAQUFADCBmTELMAkGA1UEBhMCVVMx --FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcTCUNhbWJyaWRnZTEMMAoG --A1UEChMDTUlUMSIwIAYDVQQLExlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww --KgYDVQQDFCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x --NDA1MDIxOTA2MDhaFw0yNTA0MTQxOTA2MDhaMFQxCzAJBgNVBAYTAlVTMRYwFAYD --VQQIEw1NYXNzYWNodXNldHRzMRQwEgYDVQQKEwtLUkJURVNULkNPTTEXMBUGA1UE --AxMOUFJPWFlpblN1YmplY3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB --AQDXO52ek3wU/uIufW+CTJNKf9FDFfHXK3rOKQdoytU+OSNc89SgIWlZLd54jhpA --WiP3cvkzBkOZLE5+UECovBXYAwBpytic08kiQe1tgp1Wy/D1vgg1NapX38M44M7t --SjDIymmY7fn+lRdosv4CMeMvDX8SFDdli2p+kAw6R/lOdLka2pkWWtiBkoTy9MLw --HEMozsViFZjPuSn+0bdLw79FOc/s136HVh2maUcEZ+7AhEgnPnE3DoohwLLdDQ02 --gqeHTRZXAuZH7HXUEZKQyOJlmTAnkPRE5tKDXdAP+K2sahXaC0/ONCA099OuOwy/ --I5YAAWtZVHdAtPGeeZeyqde/AgMBAAGjggF3MIIBczAdBgNVHQ4EFgQUc7n4NJjO --ryu9CFSV3K+fTLgCqUcwgcYGA1UdIwSBvjCBu4AUc7n4NJjOryu9CFSV3K+fTLgC --qUehgZ+kgZwwgZkxCzAJBgNVBAYTAlVTMRYwFAYDVQQIEw1NYXNzYWNodXNldHRz --MRIwEAYDVQQHEwlDYW1icmlkZ2UxDDAKBgNVBAoTA01JVDEiMCAGA1UECxMZSW5z --ZWN1cmUgS2VyYmVyb3MgdGVzdCBDQTEsMCoGA1UEAxQjdGVzdCBzdWl0ZSBDQTsg -+MIIE4jCCA8qgAwIBAgIBAjANBgkqhkiG9w0BAQsFADCBmTELMAkGA1UEBhMCVVMx -+FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG -+A1UECgwDTUlUMSIwIAYDVQQLDBlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww -+KgYDVQQDDCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x -+OTExMTIxODMwMzRaFw0zMDEwMjUxODMwMzRaMFQxCzAJBgNVBAYTAlVTMRYwFAYD -+VQQIDA1NYXNzYWNodXNldHRzMRQwEgYDVQQKDAtLUkJURVNULkNPTTEXMBUGA1UE -+AwwOUFJPWFlpblN1YmplY3QwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB -+AQDngcJ5NNR7XbumqMryvbw0YzDavbH6FYoprIfk2ao6qfCfNEeRkTlSORrND+H3 -+tLotnphvzDeYkTJfU91w0BEPDaZs48WTk325ecFvoBmiDuGH3Ax7/+D1rs+kpqd/ -+Dr19JWACvj1MUWIugq7JOAeIk4HtiA/RtMcQ7iUuq6w9AzXqVENJ2heDja50CHe4 -+Fj5AOzbeyctKIH72+3yC3qBeJphvcEE5az0Hc8qzfvg32Q4+yByP7yTJH8z6r5F8 -+rluKpLdx7+zG89XQqx6H//W4nGVtALA6IF3dMtYcuFb0XuvMRy/OfUx9yTfmzRcM -+NGUbFEYYPL5kIqbF/xm7/xLDAgMBAAGjggF3MIIBczAdBgNVHQ4EFgQU9/+8m8Uw -+LCsAF4ILSyrtEZ9h4iIwgcYGA1UdIwSBvjCBu4AU9/+8m8UwLCsAF4ILSyrtEZ9h -+4iKhgZ+kgZwwgZkxCzAJBgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNldHRz -+MRIwEAYDVQQHDAlDYW1icmlkZ2UxDDAKBgNVBAoMA01JVDEiMCAGA1UECwwZSW5z -+ZWN1cmUgS2VyYmVyb3MgdGVzdCBDQTEsMCoGA1UEAwwjdGVzdCBzdWl0ZSBDQTsg - ZG8gbm90IHVzZSBvdGhlcndpc2WCAQEwCwYDVR0PBAQDAgPoMAwGA1UdEwEB/wQC - MAAwWQYDVR0RBFIwUIIWcHJveHnFoHViamVjdMOEbHTDkWFtZYITcHJveHlTdWJq - ZWN0QWx0TmFtZYcEfwAAAYcQAAAAAAAAAAAAAAAAAAAAAYIJbG9jYWxob3N0MBMG --A1UdJQQMMAoGCCsGAQUFBwMBMA0GCSqGSIb3DQEBBQUAA4IBAQAH6AWuyRLzMbKq --MUlyg9ZIar8p0Ms0/UEaa6Xm3/cfm6HSujtgcYlDN3M86Z3zWzWdTrOHsRr/YSG3 --H3YDhJToKqxcjgho+1xdBPm0xuFsJcypRqGj/mIaJSoa+wC2AdY1EdE+URsh87XC --SHYNbxAVo8qBHMjtROm6AKb2YusYqHnkT+U6nc4Pn9UnIzmu4wfoSB+X1vtY24TP --AtXNYQEG4BkgSrcsgoL+z/+wtZLU8QFk6JRO7Bedq711Oh/taEasZHjRAmnqC5TB --Ab2fnwWuoVZHqz2qydeywXUKrZlctuRVdjE++wOt9xuMPKFGo0PKDw/SymCe61Q8 --Nc/d2mhz -+A1UdJQQMMAoGCCsGAQUFBwMBMA0GCSqGSIb3DQEBCwUAA4IBAQDQI1/zeNAWvXAG -+CTJk+hFLNx7xzd28/vWGkumK60rSmLVLZNDlvfmNJZ/kd7d0YZFvZDvbzhugXigI -+5N54664XreRwXA7QkgD2laFd/Rzq+6NdhyMCno7V6j1VZUm6/FWgfYjfGEBvbGNv -+Ue50fyRSQBmFv3p87Av/Zc0OMjted0zOYUxUPH0OL+2e4BL/suo05Q5DZq+J8Dni -+7SJbDC0fp5mKVLQ500zIRwUF2y5TE4olBsYBoaMDxQl+HoG6XpzaVslTKXAvzFMk -+8beI2BmqUId1OSLa3TOKnbsK8K/MPnSnB5StINt1+ZtTjjV+dY3xB6ZC+G1Pl6Ta -+00C7EWul - -----END CERTIFICATE----- -diff --git a/src/tests/dejagnu/proxy-certs/proxy-subject.pem b/src/tests/dejagnu/proxy-certs/proxy-subject.pem -index e17918f2b..3846aece6 100644 ---- a/src/tests/dejagnu/proxy-certs/proxy-subject.pem -+++ b/src/tests/dejagnu/proxy-certs/proxy-subject.pem -@@ -1,54 +1,54 @@ - -----BEGIN RSA PRIVATE KEY----- --MIIEpQIBAAKCAQEA1zudnpN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPU --oCFpWS3eeI4aQFoj93L5MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4I --NTWqV9/DOODO7UowyMppmO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZ --FlrYgZKE8vTC8BxDKM7FYhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5x --Nw6KIcCy3Q0NNoKnh00WVwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtP --zjQgNPfTrjsMvyOWAAFrWVR3QLTxnnmXsqnXvwIDAQABAoIBAQCqvhpeMDXhGgoo --Q03wmfrGwPsrMv91aIK1hYrhMPdVs1JAbRYiKh8+pcq07FYa8udRaB4UwkVh/+oM --/nEs6niRsl/jjQ2l68TFrnNByroynvr6l9Q/EeGecF6Ygo7lY1OsFhcLQM5vjarS --XhxvdU/6hcRmfS8tGRpUaMWqfmpiN3YgJcgt8SoYhiwAYDTMJjNyWC61lO7IqNVR --4kntiM24sfAu1sdZynX8Gp2GrpNChapEuhilQ8RayjuStEYr2abcSIjfZFHQXN7o --TnjL+AQUzc/ZTXDGnIe9ZzZeFz8UCueeoN6KPxfrq9UUWRL6qt7gOIMdhYR6lFxt --6pj6kLhxAoGBAO5DTnTKDfCMY2/AsTzCJvMGSY0bT1rsdDxrpqjrbUSeMHV3s5Lm --vEPnnm+05FD/vi99+HZjHXAZFkhA3ubij2qWFPBnQ5YUoh17IW/Ae4bzY2uXikgL --tLZ+R+OrcGYQQlvPn//PLsxbfdk5vraqzm08kIX0T4o4Iz8ST5NFJ8hVAoGBAOdB --ahXr14563Cjeu0pSQ1nXoz3IXdnDwePXasYhxQHl8Ayk8qZS5pt7r07H3dqq6pvn --e09gZINJe47B9UhkR3H5bPyz/kujKS4zqo3Zlbryzm3V0BWqjNj+j8E2YuQKNQr+ --c480jn2FzwW66w0i3n4U4KUn1w2/iq5AnVzyNkPDAoGAWLYEsyU79XE/4K79DqM3 --P0r6/afKbw8U5B4syj4FzAOeBU6RNMPmGt5VNkBCtgnSdPpRFTsoDcG5cyN8GrkG --Lug8WZoJJwr9pT5gH6yqEX/zZ27f1J1PJpd0CsedLNMm8eonJ2arhPkXrVZ7tKV6 --AGAJa2agatUmAmi96hZYjpUCgYEA32abJEgsedEIhFb/GYI03ELryRCaUXfCA+gj --lvoihn3qE1z5qGGns4adyX5dPRQmBqxtvDXDg+zl9vg6i0+MkXdCqTD8tXcOnjp9 --RgFvmyVa9FI8beHPpQTuPNncWK3fpho/6pT8Hhi48LEsxwjrZWOnzQSaxQZH46Q6 --IQNAFt8CgYEAkflxXvA2/2naix+riaBzv5EVJB7ilbfWiWtq2LEAtwrQ5XNFjrtK --g45jKrZ/ezAzTfPa5Dwn4xcImd0MIavnJhDu2ATxMGB0GATLlDH2HZvU7UwKLpTW --6Hlol4yRcX4GSEOxJ2ZpWYNIOYH0yDf1qLJXs1j8Fi3zWRe+V1kff4w= -+MIIEpAIBAAKCAQEA54HCeTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRH -+kZE5UjkazQ/h97S6LZ6Yb8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wM -+e//g9a7PpKanfw69fSVgAr49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRD -+SdoXg42udAh3uBY+QDs23snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgc -+j+8kyR/M+q+RfK5biqS3ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcv -+zn1Mfck35s0XDDRlGxRGGDy+ZCKmxf8Zu/8SwwIDAQABAoIBAGxzOBQpsIReQ6Lu -+HaybP4hXEzLVfIOIBaJCJaMKaJl0tLkP95r0qiKfh7OahiPRMQpf6k8tHrpFApDv -+q6PGhMdFgLov9YWNqW7y37AYEwn86KAJcHvCQbM2AiXCwGJgGFqA4LpIPlT7JwBc -+zd6LddQALfSFMcvuYPbIaPi1CUnGy/AAyxGjUrc60KO57NbI+dHSTOwTHO1QjOz9 -+ESk4fb34beUuZQzR6s/s1N0k09GJyklLpAAblRs5M6w9IlAn781eRLUAHTafLm4b -+21J9k2Q2UaOofn0Cvh8ggyJMiYqAJ0CsRy5pJroEyboA51WU+8THNFkNtRX5SxY5 -+YY3xE7ECgYEA/qkq7BPMkr/SnBPm32G1Eux5eLVd65qbox0oTLodZbusuxutqXTp -+1MseDPQtHlrq6CQBizwElx//pdKnIiU9iBS/QkMR9CviitMTt+WrWRrM54/A4CJP -+AU2Jg7b2DmhW1ombHHiBZ1tWzyiv9zxrtwR8kmKqv9aTOuPn4l7jY5kCgYEA6Llr -+47pQjp/YhkBBvlriRwM9RXek++ythgsWvEswORaUalnaZ9gxZOKKas35GLDDuVyT -+RnEhIqVlTg9iz6x5fXRtm6VzQvy9yFLzPMnlwsiSnRNOfMVIETUTOhNgm45tYY8f -+lN5bcdY6k6VZ/g/N3zqddnxkjocrd6lAayjjIrsCgYEAyZLYAcPuQx6JM7fhIGIz -+tQXvZKeS7yITHbq/onQTPuqd4AEZpi9/w0r/v1srt4JZvGR7wF1CeOkAL56dYr69 -+hNB/T5DNTkvKZv6K9h5aUg6PsJ8uGXuus6ZPOi4BeAgI7IpBd/i+3TQEc7eOCZIO -+5PAtNqXY6D6NjajGbH2VWckCgYA2KRDmyrF8v86QT9v9BQGsLSDRTerjhk1L6MC9 -+yXHLl2mq5oZhrHqyU9aKzKywBlNGjDjqJ+HiQkO1SvdgBW+wtqvbkUGl0VQJjuR0 -+vTfvgOY+EAQwHWmMN6Hl3iSZjyf9kGV1K9p0P7saKV0sN1leHjIPJRvx35tKGeWY -+CsfxiQKBgQCVUvsX/HeWyc4bxxMuzw8JniUG2JftZqIC1haHEFNElASjt4hARM7Y -+X/dkpYPXOZaN+qfvP949rS1WPXRtwMjt7bYzm7MGbXW7OiGGY3LV2CuVmbXJupvr -+Usvi+YnpqKDY/miOYd+541NJm76AQTSgQ8K7XitX7Beddh1U9e17mg== - -----END RSA PRIVATE KEY----- - -----BEGIN CERTIFICATE----- --MIIEgjCCA2qgAwIBAgIBAzANBgkqhkiG9w0BAQUFADCBmTELMAkGA1UEBhMCVVMx --FjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcTCUNhbWJyaWRnZTEMMAoG --A1UEChMDTUlUMSIwIAYDVQQLExlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww --KgYDVQQDFCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x --NDA1MDIxOTA2MDhaFw0yNTA0MTQxOTA2MDhaME8xCzAJBgNVBAYTAlVTMRYwFAYD --VQQIEw1NYXNzYWNodXNldHRzMRQwEgYDVQQKEwtLUkJURVNULkNPTTESMBAGA1UE --AxMJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1zud --npN8FP7iLn1vgkyTSn/RQxXx1yt6zikHaMrVPjkjXPPUoCFpWS3eeI4aQFoj93L5 --MwZDmSxOflBAqLwV2AMAacrYnNPJIkHtbYKdVsvw9b4INTWqV9/DOODO7UowyMpp --mO35/pUXaLL+AjHjLw1/EhQ3ZYtqfpAMOkf5TnS5GtqZFlrYgZKE8vTC8BxDKM7F --YhWYz7kp/tG3S8O/RTnP7Nd+h1YdpmlHBGfuwIRIJz5xNw6KIcCy3Q0NNoKnh00W --VwLmR+x11BGSkMjiZZkwJ5D0RObSg13QD/itrGoV2gtPzjQgNPfTrjsMvyOWAAFr --WVR3QLTxnnmXsqnXvwIDAQABo4IBHDCCARgwHQYDVR0OBBYEFHO5+DSYzq8rvQhU --ldyvn0y4AqlHMIHGBgNVHSMEgb4wgbuAFHO5+DSYzq8rvQhUldyvn0y4AqlHoYGf --pIGcMIGZMQswCQYDVQQGEwJVUzEWMBQGA1UECBMNTWFzc2FjaHVzZXR0czESMBAG --A1UEBxMJQ2FtYnJpZGdlMQwwCgYDVQQKEwNNSVQxIjAgBgNVBAsTGUluc2VjdXJl --IEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNVBAMUI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5v -+MIIEgjCCA2qgAwIBAgIBAzANBgkqhkiG9w0BAQsFADCBmTELMAkGA1UEBhMCVVMx -+FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG -+A1UECgwDTUlUMSIwIAYDVQQLDBlJbnNlY3VyZSBLZXJiZXJvcyB0ZXN0IENBMSww -+KgYDVQQDDCN0ZXN0IHN1aXRlIENBOyBkbyBub3QgdXNlIG90aGVyd2lzZTAeFw0x -+OTExMTIxODMwMzRaFw0zMDEwMjUxODMwMzRaME8xCzAJBgNVBAYTAlVTMRYwFAYD -+VQQIDA1NYXNzYWNodXNldHRzMRQwEgYDVQQKDAtLUkJURVNULkNPTTESMBAGA1UE -+AwwJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA54HC -+eTTUe127pqjK8r28NGMw2r2x+hWKKayH5NmqOqnwnzRHkZE5UjkazQ/h97S6LZ6Y -+b8w3mJEyX1PdcNARDw2mbOPFk5N9uXnBb6AZog7hh9wMe//g9a7PpKanfw69fSVg -+Ar49TFFiLoKuyTgHiJOB7YgP0bTHEO4lLqusPQM16lRDSdoXg42udAh3uBY+QDs2 -+3snLSiB+9vt8gt6gXiaYb3BBOWs9B3PKs374N9kOPsgcj+8kyR/M+q+RfK5biqS3 -+ce/sxvPV0Kseh//1uJxlbQCwOiBd3TLWHLhW9F7rzEcvzn1Mfck35s0XDDRlGxRG -+GDy+ZCKmxf8Zu/8SwwIDAQABo4IBHDCCARgwHQYDVR0OBBYEFPf/vJvFMCwrABeC -+C0sq7RGfYeIiMIHGBgNVHSMEgb4wgbuAFPf/vJvFMCwrABeCC0sq7RGfYeIioYGf -+pIGcMIGZMQswCQYDVQQGEwJVUzEWMBQGA1UECAwNTWFzc2FjaHVzZXR0czESMBAG -+A1UEBwwJQ2FtYnJpZGdlMQwwCgYDVQQKDANNSVQxIjAgBgNVBAsMGUluc2VjdXJl -+IEtlcmJlcm9zIHRlc3QgQ0ExLDAqBgNVBAMMI3Rlc3Qgc3VpdGUgQ0E7IGRvIG5v - dCB1c2Ugb3RoZXJ3aXNlggEBMAsGA1UdDwQEAwID6DAMBgNVHRMBAf8EAjAAMBMG --A1UdJQQMMAoGCCsGAQUFBwMBMA0GCSqGSIb3DQEBBQUAA4IBAQCzGPT+QOrl9mbJ --nsGlPlLUOF+PYz0a/9V/iznlofxwCXiRi2ryMpLFbjLeOvjLJ3UzyNKtmEeudTBM --yfR4i8tb9WA7Oh0BjK1+kD4688bAUXiIDhueKBjonmPvMd9kq3MDd4vDLkcZk6R4 --4IcbdwhzSBmnJH8ha2J82XShPpRq5CZNR9+vTyFwGdGWdPDjTMiXoXAmpRemcEgO --iO4Gxvcrg/Z06Ys3eLze7QHNMAEwXhC4rUR34j5I2zgU7CEhff3AktLmnKVa8go8 --4BJT/n3XGB+3gdAEihQmgCEZetHH+YxAR0Ppn3ty7fpAlOnbRJqpeu6TMN8x/lL8 --c6JtDWRG -+A1UdJQQMMAoGCCsGAQUFBwMBMA0GCSqGSIb3DQEBCwUAA4IBAQBdg7Gk/RqQpTfD -+vyFB1GPWRcLYpYW4GQh3e/dcesmwjwT8Nsd4Mzq9mA9TzJIXwffUQ8de85L5+9Oh -+k4yiwRS3vDCP0fr+GZMpBqkBVunJIHQnm+RWxT42+0kBxxmO/fqp5ztND8gGBLiW -+QPHb+mSCFgmgwnRuW+UI3TZ965oZfd2oRjjHjr51cgxcXndqnNws/kakMpxSM+KT -++ICHNz5og79nC7zpVqu0Cd56stPXbrFeU+bnN5UT9sOZNOYstWZmS8u+ddDuJwhS -+ijJZgtQNOIuBfD2TLfDmg/QfLeh5hhgBVyXC5o8g6KEtjPgm+44OF3vNZeuwVPaf -+L58YyPcO - -----END CERTIFICATE----- diff --git a/Update-test-suite-to-avoid-single-DES-enctypes.patch b/Update-test-suite-to-avoid-single-DES-enctypes.patch deleted file mode 100644 index 042bc1b..0000000 --- a/Update-test-suite-to-avoid-single-DES-enctypes.patch +++ /dev/null @@ -1,2328 +0,0 @@ -From 99077dd3855832912df7563086cd615ba430e440 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 24 May 2019 13:11:55 -0400 -Subject: [PATCH] Update test suite to avoid single-DES enctypes - -Remove the CRC exercise code, since CRC is DES-only. - -ticket: 8808 -(cherry picked from commit 50588db5d26e81f3d564d1f69435af34ae80d9b2) ---- - src/kadmin/testing/proto/kdc.conf.proto | 2 +- - src/kadmin/testing/util/tcl_kadm5.c | 2 - - src/lib/crypto/crypto_tests/CRC.pm | 156 ---------- - src/lib/crypto/crypto_tests/Makefile.in | 31 +- - src/lib/crypto/crypto_tests/crc.pl | 111 ------- - src/lib/crypto/crypto_tests/deps | 24 -- - src/lib/crypto/crypto_tests/t_cf2.expected | 1 - - src/lib/crypto/crypto_tests/t_cf2.in | 5 - - src/lib/crypto/crypto_tests/t_cksum.c | 160 ---------- - src/lib/crypto/crypto_tests/t_cksums.c | 8 +- - src/lib/crypto/crypto_tests/t_combine.c | 18 -- - src/lib/crypto/crypto_tests/t_crc.c | 148 ---------- - src/lib/crypto/crypto_tests/t_decrypt.c | 148 ---------- - src/lib/crypto/crypto_tests/t_encrypt.c | 3 - - src/lib/crypto/crypto_tests/t_short.c | 3 - - src/lib/crypto/crypto_tests/t_str2key.c | 274 ------------------ - src/lib/crypto/crypto_tests/vectors.c | 3 +- - .../api.current/chpass-principal-v2.exp | 8 +- - .../api.current/get-principal-v2.exp | 4 +- - .../api.current/randkey-principal-v2.exp | 11 +- - src/lib/kadm5/unit-test/setkey-test.c | 6 +- - src/lib/krb5/keytab/t_keytab.c | 40 +-- - src/lib/krb5/krb/t_etypes.c | 67 +---- - src/lib/krb5/krb/t_ser.c | 2 +- - src/lib/krb5/os/t_trace.c | 2 +- - src/lib/krb5/os/t_trace.ref | 2 +- - src/tests/asn.1/ktest.c | 2 +- - src/tests/asn.1/pkinit_encode.out | 2 +- - src/tests/asn.1/pkinit_trval.out | 2 +- - src/tests/dejagnu/config/default.exp | 226 ++------------- - src/tests/gssapi/t_invalid.c | 20 +- - src/tests/gssapi/t_pcontok.c | 17 +- - src/tests/gssapi/t_prf.c | 7 - - src/tests/t_etype_info.py | 4 +- - src/tests/t_keyrollover.py | 6 +- - src/tests/t_salt.py | 2 +- - src/tests/t_sesskeynego.py | 18 +- - src/util/k5test.py | 2 +- - 38 files changed, 88 insertions(+), 1459 deletions(-) - delete mode 100644 src/lib/crypto/crypto_tests/CRC.pm - delete mode 100644 src/lib/crypto/crypto_tests/crc.pl - delete mode 100644 src/lib/crypto/crypto_tests/t_cksum.c - delete mode 100644 src/lib/crypto/crypto_tests/t_crc.c - -diff --git a/src/kadmin/testing/proto/kdc.conf.proto b/src/kadmin/testing/proto/kdc.conf.proto -index 45df78b91..8a4b87de1 100644 ---- a/src/kadmin/testing/proto/kdc.conf.proto -+++ b/src/kadmin/testing/proto/kdc.conf.proto -@@ -12,5 +12,5 @@ - kadmind_port = 1751 - kpasswd_port = 1752 - master_key_type = des3-hmac-sha1 -- supported_enctypes = des3-hmac-sha1:normal des-cbc-crc:normal des-cbc-md5:normal des-cbc-raw:normal -+ supported_enctypes = des3-hmac-sha1:normal aes256-cts:normal aes128-cts:normal aes256-sha2:normal aes128-sha2:normal - } -diff --git a/src/kadmin/testing/util/tcl_kadm5.c b/src/kadmin/testing/util/tcl_kadm5.c -index 9dde579ef..4d3114b11 100644 ---- a/src/kadmin/testing/util/tcl_kadm5.c -+++ b/src/kadmin/testing/util/tcl_kadm5.c -@@ -1514,8 +1514,6 @@ static Tcl_DString *unparse_keytype(krb5_enctype enctype) - switch (enctype) { - /* XXX is this right? */ - case ENCTYPE_NULL: Tcl_DStringAppend(str, "ENCTYPE_NULL", -1); break; -- case ENCTYPE_DES_CBC_CRC: -- Tcl_DStringAppend(str, "ENCTYPE_DES_CBC_CRC", -1); break; - default: - sprintf(buf, "UNKNOWN KEYTYPE (0x%x)", enctype); - Tcl_DStringAppend(str, buf, -1); -diff --git a/src/lib/crypto/crypto_tests/CRC.pm b/src/lib/crypto/crypto_tests/CRC.pm -deleted file mode 100644 -index ee2ab2ae8..000000000 ---- a/src/lib/crypto/crypto_tests/CRC.pm -+++ /dev/null -@@ -1,156 +0,0 @@ --# Copyright 2002 by the Massachusetts Institute of Technology. --# All Rights Reserved. --# --# Export of this software from the United States of America may --# require a specific license from the United States Government. --# It is the responsibility of any person or organization contemplating --# export to obtain such a license before exporting. --# --# WITHIN THAT CONSTRAINT, permission to use, copy, modify, and --# distribute this software and its documentation for any purpose and --# without fee is hereby granted, provided that the above copyright --# notice appear in all copies and that both that copyright notice and --# this permission notice appear in supporting documentation, and that --# the name of M.I.T. not be used in advertising or publicity pertaining --# to distribution of the software without specific, written prior --# permission. Furthermore if you modify this software you must label --# your software as modified software and not distribute it in such a --# fashion that it might be confused with the original M.I.T. software. --# M.I.T. makes no representations about the suitability of --# this software for any purpose. It is provided "as is" without express --# or implied warranty. -- --package CRC; -- --# CRC: implement a CRC using the Poly package (yes this is slow) --# --# message M(x) = m_0 * x^0 + m_1 * x^1 + ... + m_(k-1) * x^(k-1) --# generator P(x) = p_0 * x^0 + p_1 * x^1 + ... + p_n * x^n --# remainder R(x) = r_0 * x^0 + r_1 * x^1 + ... + r_(n-1) * x^(n-1) --# --# R(x) = (x^n * M(x)) % P(x) --# --# Note that if F(x) = x^n * M(x) + R(x), then F(x) = 0 mod P(x) . --# --# In MIT Kerberos 5, R(x) is taken as the CRC, as opposed to what --# ISO 3309 does. --# --# ISO 3309 adds a precomplement and a postcomplement. --# --# The ISO 3309 postcomplement is of the form --# --# A(x) = x^0 + x^1 + ... + x^(n-1) . --# --# The ISO 3309 precomplement is of the form --# --# B(x) = x^k * A(x) . --# --# The ISO 3309 FCS is then --# --# (x^n * M(x)) % P(x) + B(x) % P(x) + A(x) , --# --# which is equivalent to --# --# (x^n * M(x) + B(x)) % P(x) + A(x) . --# --# In ISO 3309, the transmitted frame is --# --# F'(x) = x^n * M(x) + R(x) + R'(x) + A(x) , --# --# where --# --# R'(x) = B(x) % P(x) . --# --# Note that this means that if a new remainder is computed over the --# frame F'(x) (treating F'(x) as the new M(x)), it will be equal to a --# constant. --# --# F'(x) = 0 + R'(x) + A(x) mod P(x) , --# --# then --# --# (F'(x) + x^k * A(x)) * x^n --# --# = ((R'(x) + A(x)) + x^k * A(x)) * x^n mod P(x) --# --# = (x^k * A(x) + A(x) + x^k * A(x)) * x^n mod P(x) --# --# = (0 + A(x)) * x^n mod P(x) --# --# Note that (A(x) * x^n) % P(x) is a constant, and that this result --# depends on B(x) being x^k * A(x). -- --use Carp; --use Poly; -- --sub new { -- my $self = shift; -- my $class = ref($self) || $self; -- my %args = @_; -- $self = {bitsendian => "little"}; -- bless $self, $class; -- $self->setpoly($args{"Poly"}) if exists $args{"Poly"}; -- $self->bitsendian($args{"bitsendian"}) -- if exists $args{"bitsendian"}; -- $self->{precomp} = $args{precomp} if exists $args{precomp}; -- $self->{postcomp} = $args{postcomp} if exists $args{postcomp}; -- return $self; --} -- --sub setpoly { -- my $self = shift; -- my($arg) = @_; -- croak "need a polynomial" if !$arg->isa("Poly"); -- $self->{Poly} = $arg; -- return $self; --} -- --sub crc { -- my $self = shift; -- my $msg = Poly->new(@_); -- my($order, $r, $precomp); -- $order = $self->{Poly}->order; -- # B(x) = x^k * precomp -- $precomp = $self->{precomp} ? -- $self->{precomp} * Poly->powers2poly(scalar(@_)) : Poly->new; -- # R(x) = (x^n * M(x)) % P(x) -- $r = ($msg * Poly->powers2poly($order)) % $self->{Poly}; -- # B(x) % P(x) -- $r += $precomp % $self->{Poly}; -- $r += $self->{postcomp} if exists $self->{postcomp}; -- return $r; --} -- --# endianness of bits of each octet --# --# Note that the message is always treated as being sent in big-endian --# octet order. --# --# Usually, the message will be treated as bits being little-endian, --# since that is the common case for serial implementations that --# present data in octets; e.g., most UARTs shift octets onto the line --# in little-endian order, and protocols such as ISO 3309, V.42, --# etc. treat individual octets as being sent LSB-first. -- --sub bitsendian { -- my $self = shift; -- my($arg) = @_; -- croak "bad bit endianness" if $arg !~ /big|little/; -- $self->{bitsendian} = $arg; -- return $self; --} -- --sub crcstring { -- my $self = shift; -- my($arg) = @_; -- my($packstr, @m); -- { -- $packstr = "B*", last if $self->{bitsendian} =~ /big/; -- $packstr = "b*", last if $self->{bitsendian} =~ /little/; -- croak "bad bit endianness"; -- }; -- @m = split //, unpack $packstr, $arg; -- return $self->crc(@m); --} -- --1; -diff --git a/src/lib/crypto/crypto_tests/Makefile.in b/src/lib/crypto/crypto_tests/Makefile.in -index c5eba1b10..09feeb50e 100644 ---- a/src/lib/crypto/crypto_tests/Makefile.in -+++ b/src/lib/crypto/crypto_tests/Makefile.in -@@ -16,9 +16,7 @@ EXTRADEPSRCS=\ - $(srcdir)/aes-test.c \ - $(srcdir)/camellia-test.c \ - $(srcdir)/t_cf2.c \ -- $(srcdir)/t_cksum.c \ - $(srcdir)/t_cksums.c \ -- $(srcdir)/t_crc.c \ - $(srcdir)/t_mddriver.c \ - $(srcdir)/t_kperf.c \ - $(srcdir)/t_sha2.c \ -@@ -30,15 +28,12 @@ EXTRADEPSRCS=\ - - ##DOS##BUILDTOP = ..\..\.. - --# NOTE: The t_cksum known checksum values are primarily for regression --# testing. They are not derived a priori, but are known to produce --# checksums that interoperate. - check-unix: t_nfold t_encrypt t_decrypt t_prf t_prng t_cmac t_hmac \ -- t_cksum4 t_cksum5 t_cksums \ -+ t_cksums \ - aes-test \ - camellia-test \ - t_mddriver4 t_mddriver \ -- t_crc t_cts t_sha2 t_short t_str2key t_derive t_fork t_cf2 \ -+ t_cts t_sha2 t_short t_str2key t_derive t_fork t_cf2 \ - t_combine - $(RUN_TEST) ./t_nfold - $(RUN_TEST) ./t_encrypt -@@ -47,10 +42,7 @@ check-unix: t_nfold t_encrypt t_decrypt t_prf t_prng t_cmac t_hmac \ - $(RUN_TEST) ./t_cmac - $(RUN_TEST) ./t_hmac - $(RUN_TEST) ./t_prf -- $(RUN_TEST) ./t_cksum4 "this is a test" e3f76a07f3401e3536b43a3f54226c39422c35682c354835 -- $(RUN_TEST) ./t_cksum5 "this is a test" e3f76a07f3401e351143ee6f4c09be1edb4264d55015db53 - $(RUN_TEST) ./t_cksums -- $(RUN_TEST) ./t_crc - $(RUN_TEST) ./t_cts - $(RUN_TEST) ./aes-test -k > vk.txt - cmp vk.txt $(srcdir)/expect-vk.txt -@@ -109,24 +101,9 @@ t_short$(EXEEXT): t_short.$(OBJEXT) $(KRB5_BASE_DEPLIBS) - $(CC_LINK) -o $@ t_short.$(OBJEXT) \ - $(KRB5_BASE_LIBS) - --t_cksum4.o: $(srcdir)/t_cksum.c -- $(CC) -DMD=4 $(ALL_CFLAGS) -o t_cksum4.o -c $(srcdir)/t_cksum.c -- --t_cksum5.o: $(srcdir)/t_cksum.c -- $(CC) -DMD=5 $(ALL_CFLAGS) -o t_cksum5.o -c $(srcdir)/t_cksum.c -- --t_cksum4: t_cksum4.o $(CRYTPO_DEPLIB) -- $(CC_LINK) -o t_cksum4 t_cksum4.o $(KRB5_BASE_LIBS) -- --t_cksum5: t_cksum5.o $(CRYPTO_DEPLIB) -- $(CC_LINK) -o t_cksum5 t_cksum5.o $(KRB5_BASE_LIBS) -- - t_cksums: t_cksums.o $(CRYTPO_DEPLIB) - $(CC_LINK) -o t_cksums t_cksums.o -lkrb5 $(KRB5_BASE_LIBS) - --t_crc: t_crc.o $(KRB5_BASE_DEPLIBS) -- $(CC_LINK) -o $@ t_crc.o $(KRB5_BASE_LIBS) -- - aes-test: aes-test.$(OBJEXT) $(KRB5_BASE_DEPLIBS) - $(CC_LINK) -o aes-test aes-test.$(OBJEXT) $(KRB5_BASE_LIBS) - -@@ -165,9 +142,9 @@ clean: - t_decrypt.o t_decrypt t_prng.o t_prng t_cmac.o t_cmac \ - t_hmac.o t_hmac t_pkcs5.o t_pkcs5 pbkdf2.o t_prf t_prf.o \ - aes-test.o aes-test vt.txt vk.txt kresults.out \ -- t_crc.o t_crc t_cts.o t_cts \ -+ t_cts.o t_cts \ - t_mddriver4.o t_mddriver4 t_mddriver.o t_mddriver \ -- t_cksum4 t_cksum4.o t_cksum5 t_cksum5.o t_cksums t_cksums.o \ -+ t_cksums t_cksums.o \ - t_kperf.o t_kperf t_sha2.o t_sha2 t_short t_short.o t_str2key \ - t_str2key.o t_derive t_derive.o t_fork t_fork.o \ - t_mddriver$(EXEEXT) $(OUTPRE)t_mddriver.$(OBJEXT) \ -diff --git a/src/lib/crypto/crypto_tests/crc.pl b/src/lib/crypto/crypto_tests/crc.pl -deleted file mode 100644 -index b21b6b15d..000000000 ---- a/src/lib/crypto/crypto_tests/crc.pl -+++ /dev/null -@@ -1,111 +0,0 @@ --# Copyright 2002 by the Massachusetts Institute of Technology. --# All Rights Reserved. --# --# Export of this software from the United States of America may --# require a specific license from the United States Government. --# It is the responsibility of any person or organization contemplating --# export to obtain such a license before exporting. --# --# WITHIN THAT CONSTRAINT, permission to use, copy, modify, and --# distribute this software and its documentation for any purpose and --# without fee is hereby granted, provided that the above copyright --# notice appear in all copies and that both that copyright notice and --# this permission notice appear in supporting documentation, and that --# the name of M.I.T. not be used in advertising or publicity pertaining --# to distribution of the software without specific, written prior --# permission. Furthermore if you modify this software you must label --# your software as modified software and not distribute it in such a --# fashion that it might be confused with the original M.I.T. software. --# M.I.T. makes no representations about the suitability of --# this software for any purpose. It is provided "as is" without express --# or implied warranty. -- --use CRC; -- --print "*** crudely testing polynomial functions ***\n"; -- --$x = Poly->new(1,1,1,1); --$y = Poly->new(1,1); --print "x = @{[$x->pretty]}\ny = @{[$y->pretty]}\n"; --$q = $x / $y; --$r = $x % $y; --print $x->pretty, " = (", $y->pretty , ") * (", $q->pretty, -- ") + ", $r->pretty, "\n"; --$q = $y / $x; --$r = $y % $x; --print "y / x = @{[$q->pretty]}\ny % x = @{[$r->pretty]}\n"; -- --# ISO 3309 32-bit FCS polynomial --$fcs32 = Poly->powers2poly(32,26,23,22,16,12,11,10,8,7,5,4,2,1,0); --print "fcs32 = ", $fcs32->pretty, "\n"; -- --$crc = CRC->new(Poly => $fcs32, bitsendian => "little"); -- --print "\n"; -- --print "*** little endian, no complementation ***\n"; --for ($i = 0; $i < 256; $i++) { -- $r = $crc->crcstring(pack "C", $i); -- printf ("%02x: ", $i) if !($i % 8); -- print ($r->revhex, ($i % 8 == 7) ? "\n" : " "); --} -- --print "\n"; -- --print "*** little endian, 4 bits, no complementation ***\n"; --for ($i = 0; $i < 16; $i++) { -- @m = (split //, unpack "b*", pack "C", $i)[0..3]; -- $r = $crc->crc(@m); -- printf ("%02x: ", $i) if !($i % 8); -- print ($r->revhex, ($i % 8 == 7) ? "\n" : " "); --} -- --print "\n"; -- --print "*** test vectors for t_crc.c, little endian ***\n"; --for ($i = 1; $i <= 4; $i *=2) { -- for ($j = 0; $j < $i * 8; $j++) { -- @m = split //, unpack "b*", pack "V", 1 << $j; -- splice @m, $i * 8; -- $r = $crc->crc(@m); -- $m = unpack "H*", pack "b*", join("", @m); -- print "{HEX, \"$m\", 0x", $r->revhex, "},\n"; -- } --} --@m = ("foo", "test0123456789", -- "MASSACHVSETTS INSTITVTE OF TECHNOLOGY"); --foreach $m (@m) { -- $r = $crc->crcstring($m); -- print "{STR, \"$m\", 0x", $r->revhex, "},\n"; --} --__END__ -- --print "*** big endian, no complementation ***\n"; --for ($i = 0; $i < 256; $i++) { -- $r = $crc->crcstring(pack "C", $i); -- printf ("%02x: ", $i) if !($i % 8); -- print ($r->hex, ($i % 8 == 7) ? "\n" : " "); --} -- --# all ones polynomial of order 31 --$ones = Poly->new((1) x 32); -- --print "*** big endian, ISO-3309 style\n"; --$crc = CRC->new(Poly => $fcs32, -- bitsendian => "little", -- precomp => $ones, -- postcomp => $ones); --for ($i = 0; $i < 256; $i++) { -- $r = $crc->crcstring(pack "C", $i); -- print ($r->hex, ($i % 8 == 7) ? "\n" : " "); --} -- --for ($i = 0; $i < 0; $i++) { -- $x = Poly->new((1) x 32, (0) x $i); -- $y = Poly->new((1) x 32); -- $f = ($x % $fcs32) + $y; -- $r = (($f + $x) * Poly->powers2poly(32)) % $fcs32; -- @out = @$r; -- unshift @out, 0 while @out < 32; -- print @out, "\n"; --} -diff --git a/src/lib/crypto/crypto_tests/deps b/src/lib/crypto/crypto_tests/deps -index 5d94a593d..19fef2582 100644 ---- a/src/lib/crypto/crypto_tests/deps -+++ b/src/lib/crypto/crypto_tests/deps -@@ -140,17 +140,6 @@ $(OUTPRE)camellia-test.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(top_srcdir)/include/socket-utils.h camellia-test.c - $(OUTPRE)t_cf2.$(OBJEXT): $(BUILDTOP)/include/krb5/krb5.h \ - $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h t_cf2.c --$(OUTPRE)t_cksum.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ -- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- t_cksum.c - $(OUTPRE)t_cksums.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ -@@ -161,19 +150,6 @@ $(OUTPRE)t_cksums.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ - $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ - $(top_srcdir)/include/socket-utils.h t_cksums.c --$(OUTPRE)t_crc.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \ -- $(srcdir)/../builtin/crypto_mod.h $(srcdir)/../builtin/sha2/sha2.h \ -- $(srcdir)/../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ -- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-hex.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- t_crc.c - $(OUTPRE)t_mddriver.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../builtin/aes/aes.h \ -diff --git a/src/lib/crypto/crypto_tests/t_cf2.expected b/src/lib/crypto/crypto_tests/t_cf2.expected -index 11a24b800..f8251a16c 100644 ---- a/src/lib/crypto/crypto_tests/t_cf2.expected -+++ b/src/lib/crypto/crypto_tests/t_cf2.expected -@@ -1,6 +1,5 @@ - 97df97e4b798b29eb31ed7280287a92a - 4d6ca4e629785c1f01baf55e2e548566b9617ae3a96868c337cb93b5e72b1c7b --43bae3738c9467e6 - e58f9eb643862c13ad38e529313462a7f73e62834fe54a01 - 24d7f6b6bae4e5c00d2082c5ebab3672 - edd02a39d2dbde31611c16e610be062c -diff --git a/src/lib/crypto/crypto_tests/t_cf2.in b/src/lib/crypto/crypto_tests/t_cf2.in -index e62ead7d8..73e2f8fbc 100644 ---- a/src/lib/crypto/crypto_tests/t_cf2.in -+++ b/src/lib/crypto/crypto_tests/t_cf2.in -@@ -8,11 +8,6 @@ key1 - key2 - a - b --1 --key1 --key2 --a --b - 16 - key1 - key2 -diff --git a/src/lib/crypto/crypto_tests/t_cksum.c b/src/lib/crypto/crypto_tests/t_cksum.c -deleted file mode 100644 -index 0edaeb850..000000000 ---- a/src/lib/crypto/crypto_tests/t_cksum.c -+++ /dev/null -@@ -1,160 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* lib/crypto/crypto_tests/t_cksum.c */ --/* -- * Copyright 1995 by the Massachusetts Institute of Technology. -- * All Rights Reserved. -- * -- * Export of this software from the United States of America may -- * require a specific license from the United States Government. -- * It is the responsibility of any person or organization contemplating -- * export to obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of M.I.T. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. Furthermore if you modify this software you must label -- * your software as modified software and not distribute it in such a -- * fashion that it might be confused with the original M.I.T. software. -- * M.I.T. makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- */ -- --/* Test checksum and checksum compatability for rsa-md[4,5]-des. */ -- --#include "k5-int.h" --#include "k5-hex.h" -- --#define MD5_K5BETA_COMPAT --#define MD4_K5BETA_COMPAT -- --#if MD == 4 --#define CKTYPE CKSUMTYPE_RSA_MD4_DES --#endif -- --#if MD == 5 --#define CKTYPE CKSUMTYPE_RSA_MD5_DES --#endif -- --static void --print_checksum(char *text, int number, char *message, krb5_checksum *checksum) --{ -- unsigned int i; -- -- printf("%s MD%d checksum(\"%s\") = ", text, number, message); -- for (i=0; ilength; i++) -- printf("%02x", (unsigned char) checksum->contents[i]); -- printf("\n"); --} -- --/* -- * Test the checksum verification of Old Style (tm) and correct RSA-MD[4,5]-DES -- * checksums. -- */ -- --krb5_octet testkey[8] = { 0x45, 0x01, 0x49, 0x61, 0x58, 0x19, 0x1a, 0x3d }; -- --int --main(argc, argv) -- int argc; -- char **argv; --{ -- int msgindex; -- size_t len; -- krb5_boolean valid; -- krb5_keyblock keyblock; -- krb5_key key; -- krb5_error_code kret=0; -- krb5_data plaintext; -- krb5_checksum checksum, knowncksum; -- -- /* this is a terrible seed, but that's ok for the test. */ -- -- plaintext.length = 8; -- plaintext.data = (char *) testkey; -- -- krb5_c_random_seed(/* XXX */ 0, &plaintext); -- -- keyblock.enctype = ENCTYPE_DES_CBC_CRC; -- keyblock.length = sizeof(testkey); -- keyblock.contents = testkey; -- -- krb5_k_create_key(NULL, &keyblock, &key); -- -- for (msgindex = 1; msgindex + 1 < argc; msgindex += 2) { -- plaintext.length = strlen(argv[msgindex]); -- plaintext.data = argv[msgindex]; -- -- /* Create a checksum. */ -- kret = krb5_k_make_checksum(NULL, CKTYPE, key, 0, &plaintext, -- &checksum); -- if (kret != 0) { -- printf("krb5_calculate_checksum choked with %d\n", kret); -- break; -- } -- print_checksum("correct", MD, argv[msgindex], &checksum); -- -- /* Verify it. */ -- kret = krb5_k_verify_checksum(NULL, key, 0, &plaintext, &checksum, -- &valid); -- if (kret != 0) { -- printf("verify on new checksum choked with %d\n", kret); -- break; -- } -- if (!valid) { -- printf("verify on new checksum failed\n"); -- kret = 1; -- break; -- } -- printf("Verify succeeded for \"%s\"\n", argv[msgindex]); -- -- /* Corrupt the checksum and see if it still verifies. */ -- checksum.contents[0]++; -- kret = krb5_k_verify_checksum(NULL, key, 0, &plaintext, &checksum, -- &valid); -- if (kret != 0) { -- printf("verify on new checksum choked with %d\n", kret); -- break; -- } -- if (valid) { -- printf("verify on new checksum succeeded, but shouldn't have\n"); -- kret = 1; -- break; -- } -- printf("Verify of bad checksum OK for \"%s\"\n", argv[msgindex]); -- free(checksum.contents); -- -- /* Verify a known-good checksum for this plaintext. */ -- kret = k5_hex_decode(argv[msgindex + 1], &knowncksum.contents, &len); -- if (kret) { -- printf("k5_hex_decode failed\n"); -- break; -- } -- knowncksum.length = len; -- knowncksum.checksum_type = CKTYPE; -- knowncksum.magic = KV5M_CHECKSUM; -- kret = krb5_k_verify_checksum(NULL, key, 0, &plaintext, &knowncksum, -- &valid); -- if (kret != 0) { -- printf("verify on known checksum choked with %d\n", kret); -- break; -- } -- if (!valid) { -- printf("verify on known checksum failed\n"); -- kret = 1; -- break; -- } -- printf("Verify on known checksum succeeded\n"); -- free(knowncksum.contents); -- } -- if (!kret) -- printf("%d tests passed successfully for MD%d checksum\n", (argc-1)/2, MD); -- -- krb5_k_free_key(NULL, key); -- -- return(kret); --} -diff --git a/src/lib/crypto/crypto_tests/t_cksums.c b/src/lib/crypto/crypto_tests/t_cksums.c -index 5afc90ed8..4da14ea43 100644 ---- a/src/lib/crypto/crypto_tests/t_cksums.c -+++ b/src/lib/crypto/crypto_tests/t_cksums.c -@@ -27,7 +27,7 @@ - /* - * This harness tests checksum results against known values. With the -v flag, - * results for all tests are displayed. This harness only works for -- * deterministic checksums; for rsa-md4-des and rsa-md5-des, see t_cksum.c. -+ * deterministic checksums. - */ - - #include "k5-int.h" -@@ -40,12 +40,6 @@ struct test { - krb5_data keybits; - krb5_data cksum; - } test_cases[] = { -- { -- { KV5M_DATA, 3, "abc" }, -- CKSUMTYPE_CRC32, 0, 0, { KV5M_DATA, 0, "" }, -- { KV5M_DATA, 4, -- "\xD0\x98\x65\xCA" } -- }, - { - { KV5M_DATA, 3, "one" }, - CKSUMTYPE_RSA_MD4, 0, 0, { KV5M_DATA, 0, "" }, -diff --git a/src/lib/crypto/crypto_tests/t_combine.c b/src/lib/crypto/crypto_tests/t_combine.c -index 89219c762..ba0622bcf 100644 ---- a/src/lib/crypto/crypto_tests/t_combine.c -+++ b/src/lib/crypto/crypto_tests/t_combine.c -@@ -32,10 +32,6 @@ - - #include "k5-int.h" - --unsigned char des_key1[] = "\x04\x86\xCD\x97\x61\xDF\xD6\x29"; --unsigned char des_key2[] = "\x1A\x54\x9B\x7F\xDC\x20\x83\x0E"; --unsigned char des_result[] = "\xC2\x13\x01\x52\x89\x26\xC4\xF7"; -- - unsigned char des3_key1[] = "\x10\xB6\x75\xD5\x5B\xD9\x6E\x73" - "\xFD\x54\xB3\x3D\x37\x52\xC1\x2A\xF7\x43\x91\xFE\x1C\x02\x37\x13"; - unsigned char des3_key2[] = "\xC8\xDA\x3E\xA7\xB6\x64\xAE\x7A" -@@ -48,20 +44,6 @@ main(int argc, char **argv) - { - krb5_keyblock kb1, kb2, result; - -- kb1.enctype = ENCTYPE_DES_CBC_CRC; -- kb1.contents = des_key1; -- kb1.length = 8; -- kb2.enctype = ENCTYPE_DES_CBC_CRC; -- kb2.contents = des_key2; -- kb2.length = 8; -- memset(&result, 0, sizeof(result)); -- if (krb5int_c_combine_keys(NULL, &kb1, &kb2, &result) != 0) -- abort(); -- if (result.enctype != ENCTYPE_DES_CBC_CRC || result.length != 8 || -- memcmp(result.contents, des_result, 8) != 0) -- abort(); -- krb5_free_keyblock_contents(NULL, &result); -- - kb1.enctype = ENCTYPE_DES3_CBC_SHA1; - kb1.contents = des3_key1; - kb1.length = 24; -diff --git a/src/lib/crypto/crypto_tests/t_crc.c b/src/lib/crypto/crypto_tests/t_crc.c -deleted file mode 100644 -index 8cd1d36cb..000000000 ---- a/src/lib/crypto/crypto_tests/t_crc.c -+++ /dev/null -@@ -1,148 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* lib/crypto/crypto_tests/t_crc.c */ --/* -- * Copyright 2002,2005 by the Massachusetts Institute of Technology. -- * All Rights Reserved. -- * -- * Export of this software from the United States of America may -- * require a specific license from the United States Government. -- * It is the responsibility of any person or organization contemplating -- * export to obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of M.I.T. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. Furthermore if you modify this software you must label -- * your software as modified software and not distribute it in such a -- * fashion that it might be confused with the original M.I.T. software. -- * M.I.T. makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- */ -- --/* -- * Sanity checks for CRC32. -- */ --#include --#include --#include --#include --#include --#include --#include "crypto_int.h" -- --#define HEX 1 --#define STR 2 --struct crc_trial { -- int type; -- char *data; -- unsigned long sum; --}; -- --struct crc_trial trials[] = { -- {HEX, "01", 0x77073096}, -- {HEX, "02", 0xee0e612c}, -- {HEX, "04", 0x076dc419}, -- {HEX, "08", 0x0edb8832}, -- {HEX, "10", 0x1db71064}, -- {HEX, "20", 0x3b6e20c8}, -- {HEX, "40", 0x76dc4190}, -- {HEX, "80", 0xedb88320}, -- {HEX, "0100", 0x191b3141}, -- {HEX, "0200", 0x32366282}, -- {HEX, "0400", 0x646cc504}, -- {HEX, "0800", 0xc8d98a08}, -- {HEX, "1000", 0x4ac21251}, -- {HEX, "2000", 0x958424a2}, -- {HEX, "4000", 0xf0794f05}, -- {HEX, "8000", 0x3b83984b}, -- {HEX, "0001", 0x77073096}, -- {HEX, "0002", 0xee0e612c}, -- {HEX, "0004", 0x076dc419}, -- {HEX, "0008", 0x0edb8832}, -- {HEX, "0010", 0x1db71064}, -- {HEX, "0020", 0x3b6e20c8}, -- {HEX, "0040", 0x76dc4190}, -- {HEX, "0080", 0xedb88320}, -- {HEX, "01000000", 0xb8bc6765}, -- {HEX, "02000000", 0xaa09c88b}, -- {HEX, "04000000", 0x8f629757}, -- {HEX, "08000000", 0xc5b428ef}, -- {HEX, "10000000", 0x5019579f}, -- {HEX, "20000000", 0xa032af3e}, -- {HEX, "40000000", 0x9b14583d}, -- {HEX, "80000000", 0xed59b63b}, -- {HEX, "00010000", 0x01c26a37}, -- {HEX, "00020000", 0x0384d46e}, -- {HEX, "00040000", 0x0709a8dc}, -- {HEX, "00080000", 0x0e1351b8}, -- {HEX, "00100000", 0x1c26a370}, -- {HEX, "00200000", 0x384d46e0}, -- {HEX, "00400000", 0x709a8dc0}, -- {HEX, "00800000", 0xe1351b80}, -- {HEX, "00000100", 0x191b3141}, -- {HEX, "00000200", 0x32366282}, -- {HEX, "00000400", 0x646cc504}, -- {HEX, "00000800", 0xc8d98a08}, -- {HEX, "00001000", 0x4ac21251}, -- {HEX, "00002000", 0x958424a2}, -- {HEX, "00004000", 0xf0794f05}, -- {HEX, "00008000", 0x3b83984b}, -- {HEX, "00000001", 0x77073096}, -- {HEX, "00000002", 0xee0e612c}, -- {HEX, "00000004", 0x076dc419}, -- {HEX, "00000008", 0x0edb8832}, -- {HEX, "00000010", 0x1db71064}, -- {HEX, "00000020", 0x3b6e20c8}, -- {HEX, "00000040", 0x76dc4190}, -- {HEX, "00000080", 0xedb88320}, -- {STR, "foo", 0x7332bc33}, -- {STR, "test0123456789", 0xb83e88d6}, -- {STR, "MASSACHVSETTS INSTITVTE OF TECHNOLOGY", 0xe34180f7} --}; -- --#define NTRIALS (sizeof(trials) / sizeof(trials[0])) -- -- --int --main(void) --{ -- unsigned int i; -- struct crc_trial trial; -- uint8_t *bytes; -- size_t len; -- unsigned long cksum; -- char *typestr; -- -- for (i = 0; i < NTRIALS; i++) { -- trial = trials[i]; -- switch (trial.type) { -- case STR: -- len = strlen(trial.data); -- typestr = "STR"; -- cksum = 0; -- mit_crc32(trial.data, len, &cksum); -- break; -- case HEX: -- typestr = "HEX"; -- if (k5_hex_decode(trial.data, &bytes, &len) != 0) -- abort(); -- cksum = 0; -- mit_crc32(bytes, len, &cksum); -- free(bytes); -- break; -- default: -- typestr = "BOGUS"; -- fprintf(stderr, "bad trial type %d\n", trial.type); -- exit(1); -- } -- printf("%s: %s \"%s\" = 0x%08lx\n", -- (trial.sum == cksum) ? "OK" : "***BAD***", -- typestr, trial.data, cksum); -- } -- exit(0); --} -diff --git a/src/lib/crypto/crypto_tests/t_decrypt.c b/src/lib/crypto/crypto_tests/t_decrypt.c -index 4ae0256cc..a40a85500 100644 ---- a/src/lib/crypto/crypto_tests/t_decrypt.c -+++ b/src/lib/crypto/crypto_tests/t_decrypt.c -@@ -39,151 +39,6 @@ struct test { - krb5_data keybits; - krb5_data ciphertext; - } test_cases[] = { -- { -- ENCTYPE_DES_CBC_CRC, -- { KV5M_DATA, 0, "" }, 0, -- { KV5M_DATA, 8, -- "\x45\xE6\x08\x7C\xDF\x13\x8F\xB5" }, -- { KV5M_DATA, 16, -- "\x28\xF6\xB0\x9A\x01\x2B\xCC\xF7\x2F\xB0\x51\x22\xB2\x83\x9E\x6E" } -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- { KV5M_DATA, 1, "1" }, 1, -- { KV5M_DATA, 8, -- "\x92\xA7\x15\x58\x10\x58\x6B\x2F" }, -- { KV5M_DATA, 16, -- "\xB4\xC8\x71\xC2\xF3\xE7\xBF\x76\x05\xEF\xD6\x2F\x2E\xEE\xC2\x05" } -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- { KV5M_DATA, 9, "9 bytesss" }, 2, -- { KV5M_DATA, 8, -- "\xA4\xB9\x51\x4A\x61\x64\x64\x23" }, -- { KV5M_DATA, 24, -- "\x5F\x14\xC3\x51\x78\xD3\x3D\x7C\xDE\x0E\xC1\x69\xC6\x23\xCC\x83" -- "\x21\xB7\xB8\xBD\x34\xEA\x7E\xFE" } -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- { KV5M_DATA, 13, "13 bytes byte", }, 3, -- { KV5M_DATA, 8, -- "\x2F\x16\xA2\xA7\xFD\xB0\x57\x68" }, -- { KV5M_DATA, 32, -- "\x0B\x58\x8E\x38\xD9\x71\x43\x3C\x9D\x86\xD8\xBA\xEB\xF6\x3E\x4C" -- "\x1A\x01\x66\x6E\x76\xD8\xA5\x4A\x32\x93\xF7\x26\x79\xED\x88\xC9" } -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- { KV5M_DATA, 30, "30 bytes bytes bytes bytes byt", }, 4, -- { KV5M_DATA, 8, -- "\xBC\x8F\x70\xFD\x20\x97\xD6\x7C" }, -- { KV5M_DATA, 48, -- "\x38\xD6\x32\xD2\xC2\x0A\x7C\x2E\xA2\x50\xFC\x8E\xCE\x42\x93\x8E" -- "\x92\xA9\xF5\xD3\x02\x50\x26\x65\xC1\xA3\x37\x29\xC1\x05\x0D\xC2" -- "\x05\x62\x98\xFB\xFB\x16\x82\xCE\xEB\x65\xE5\x92\x04\xFD\xA7\xDF" } -- }, -- -- { -- ENCTYPE_DES_CBC_MD4, -- { KV5M_DATA, 0, "", }, 0, -- { KV5M_DATA, 8, -- "\x13\xEF\x45\xD0\xD6\xD9\xA1\x5D" }, -- { KV5M_DATA, 24, -- "\x1F\xB2\x02\xBF\x07\xAF\x30\x47\xFB\x78\x01\xE5\x88\x56\x86\x86" -- "\xBA\x63\xD7\x8B\xE3\xE8\x7D\xC7" } -- }, -- { -- ENCTYPE_DES_CBC_MD4, -- { KV5M_DATA, 1, "1", }, 1, -- { KV5M_DATA, 8, -- "\x64\x68\x86\x54\xDC\x26\x9E\x67" }, -- { KV5M_DATA, 32, -- "\x1F\x6C\xB9\xCE\xCB\x73\xF7\x55\xAB\xFD\xB3\xD5\x65\xBD\x31\xD5" -- "\xA2\xE6\x4B\xFE\x44\xC4\x91\xE2\x0E\xEB\xE5\xBD\x20\xE4\xD2\xA9" } -- }, -- { -- ENCTYPE_DES_CBC_MD4, -- { KV5M_DATA, 9, "9 bytesss", }, 2, -- { KV5M_DATA, 8, -- "\x68\x04\xFB\x26\xDF\x8A\x4C\x32" }, -- { KV5M_DATA, 40, -- "\x08\xA5\x3D\x62\xFE\xC3\x33\x8A\xD1\xD2\x18\xE6\x0D\xBD\xD3\xB2" -- "\x12\x94\x06\x79\xD1\x25\xE0\x62\x1B\x3B\xAB\x46\x80\xCE\x03\x67" -- "\x6A\x2C\x42\x0E\x9B\xE7\x84\xEB" } -- }, -- { -- ENCTYPE_DES_CBC_MD4, -- { KV5M_DATA, 13, "13 bytes byte", }, 3, -- { KV5M_DATA, 8, -- "\x23\x4A\x43\x6E\xC7\x2F\xA8\x0B" }, -- { KV5M_DATA, 40, -- "\x17\xCD\x45\xE1\x4F\xF0\x6B\x28\x40\xA6\x03\x6E\x9A\xA7\xA4\x14" -- "\x4E\x29\x76\x81\x44\xA0\xC1\x82\x7D\x8C\x4B\xC7\xC9\x90\x6E\x72" -- "\xCD\x4D\xC3\x28\xF6\x64\x8C\x99" } -- }, -- { -- ENCTYPE_DES_CBC_MD4, -- { KV5M_DATA, 30, "30 bytes bytes bytes bytes byt", }, 4, -- { KV5M_DATA, 8, -- "\x1F\xD5\xF7\x43\x34\xC4\xFB\x8C" }, -- { KV5M_DATA, 56, -- "\x51\x13\x4C\xD8\x95\x1E\x9D\x57\xC0\xA3\x60\x53\xE0\x4C\xE0\x3E" -- "\xCB\x84\x22\x48\x8F\xDD\xC5\xC0\x74\xC4\xD8\x5E\x60\xA2\xAE\x42" -- "\x3C\x3C\x70\x12\x01\x31\x4F\x36\x2C\xB0\x74\x48\x09\x16\x79\xC6" -- "\xA4\x96\xC1\x1D\x7B\x93\xC7\x1B" } -- }, -- -- { -- ENCTYPE_DES_CBC_MD5, -- { KV5M_DATA, 0, "", }, 0, -- { KV5M_DATA, 8, -- "\x4A\x54\x5E\x0B\xF7\xA2\x26\x31" }, -- { KV5M_DATA, 24, -- "\x78\x4C\xD8\x15\x91\xA0\x34\xBE\x82\x55\x6F\x56\xDC\xA3\x22\x4B" -- "\x62\xD9\x95\x6F\xA9\x0B\x1B\x93" } -- }, -- { -- ENCTYPE_DES_CBC_MD5, -- { KV5M_DATA, 1, "1", }, 1, -- { KV5M_DATA, 8, -- "\xD5\x80\x4A\x26\x9D\xC4\xE6\x45" }, -- { KV5M_DATA, 32, -- "\xFF\xA2\x5C\x7B\xE2\x87\x59\x6B\xFE\x58\x12\x6E\x90\xAA\xA0\xF1" -- "\x2D\x9A\x82\xA0\xD8\x6D\xF6\xD5\xF9\x07\x4B\x6B\x39\x9E\x7F\xF1" } -- }, -- { -- ENCTYPE_DES_CBC_MD5, -- { KV5M_DATA, 9, "9 bytesss", }, 2, -- { KV5M_DATA, 8, -- "\xC8\x31\x2F\x7F\x83\xEA\x46\x40" }, -- { KV5M_DATA, 40, -- "\xE7\x85\x03\x37\xF2\xCC\x5E\x3F\x35\xCE\x3D\x69\xE2\xC3\x29\x86" -- "\x38\xA7\xAA\x44\xB8\x78\x03\x1E\x39\x85\x1E\x47\xC1\x5B\x5D\x0E" -- "\xE7\xE7\xAC\x54\xDE\x11\x1D\x80" } -- }, -- { -- ENCTYPE_DES_CBC_MD5, -- { KV5M_DATA, 13, "13 bytes byte", }, 3, -- { KV5M_DATA, 8, -- "\x7F\xDA\x3E\x62\xAD\x8A\xF1\x8C" }, -- { KV5M_DATA, 40, -- "\xD7\xA8\x03\x2E\x19\x99\x4C\x92\x87\x77\x50\x65\x95\xFB\xDA\x98" -- "\x83\x15\x8A\x85\x14\x54\x8E\x29\x6E\x91\x1C\x29\xF4\x65\xC6\x72" -- "\x36\x60\x00\x55\x8B\xFC\x2E\x88" } -- }, -- { -- ENCTYPE_DES_CBC_MD5, -- { KV5M_DATA, 30, "30 bytes bytes bytes bytes byt", }, 4, -- { KV5M_DATA, 8, -- "\xD3\xD6\x83\x29\x70\xA7\x37\x52" }, -- { KV5M_DATA, 56, -- "\x8A\x48\x16\x6A\x4C\x6F\xEA\xE6\x07\xA8\xCF\x68\xB3\x81\xC0\x75" -- "\x5E\x40\x2B\x19\xDB\xC0\xF8\x1A\x7D\x7C\xA1\x9A\x25\xE0\x52\x23" -- "\xF6\x06\x44\x09\xBF\x5A\x4F\x50\xAC\xD8\x26\x63\x9F\xFA\x76\x73" -- "\xFD\x32\x4E\xC1\x9E\x42\x95\x02" } -- }, -- - { - ENCTYPE_DES3_CBC_SHA1, - { KV5M_DATA, 0, "", }, 0, -@@ -669,9 +524,6 @@ printhex(const char *head, void *data, size_t len) - - static krb5_enctype - enctypes[] = { -- ENCTYPE_DES_CBC_CRC, -- ENCTYPE_DES_CBC_MD4, -- ENCTYPE_DES_CBC_MD5, - ENCTYPE_DES3_CBC_SHA1, - ENCTYPE_ARCFOUR_HMAC, - ENCTYPE_ARCFOUR_HMAC_EXP, -diff --git a/src/lib/crypto/crypto_tests/t_encrypt.c b/src/lib/crypto/crypto_tests/t_encrypt.c -index 4afbddedb..bd9b94691 100644 ---- a/src/lib/crypto/crypto_tests/t_encrypt.c -+++ b/src/lib/crypto/crypto_tests/t_encrypt.c -@@ -37,9 +37,6 @@ - - /* What enctypes should we test?*/ - krb5_enctype interesting_enctypes[] = { -- ENCTYPE_DES_CBC_CRC, -- ENCTYPE_DES_CBC_MD4, -- ENCTYPE_DES_CBC_MD5, - ENCTYPE_DES3_CBC_SHA1, - ENCTYPE_ARCFOUR_HMAC, - ENCTYPE_ARCFOUR_HMAC_EXP, -diff --git a/src/lib/crypto/crypto_tests/t_short.c b/src/lib/crypto/crypto_tests/t_short.c -index 40fa2821f..d4c2b97df 100644 ---- a/src/lib/crypto/crypto_tests/t_short.c -+++ b/src/lib/crypto/crypto_tests/t_short.c -@@ -34,9 +34,6 @@ - #include "k5-int.h" - - krb5_enctype interesting_enctypes[] = { -- ENCTYPE_DES_CBC_CRC, -- ENCTYPE_DES_CBC_MD4, -- ENCTYPE_DES_CBC_MD5, - ENCTYPE_DES3_CBC_SHA1, - ENCTYPE_ARCFOUR_HMAC, - ENCTYPE_ARCFOUR_HMAC_EXP, -diff --git a/src/lib/crypto/crypto_tests/t_str2key.c b/src/lib/crypto/crypto_tests/t_str2key.c -index 27896e61e..cdb1acc6d 100644 ---- a/src/lib/crypto/crypto_tests/t_str2key.c -+++ b/src/lib/crypto/crypto_tests/t_str2key.c -@@ -35,280 +35,6 @@ struct test { - krb5_error_code expected_err; - krb5_boolean allow_weak; - } test_cases[] = { -- /* AFS string-to-key tests from old t_afss2k.c. */ -- { -- ENCTYPE_DES_CBC_CRC, -- "", -- { KV5M_DATA, 15, "Sodium Chloride" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xA4\xD0\xD0\x9B\x86\x92\xB0\xC2" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "M", -- { KV5M_DATA, 15, "Sodium Chloride" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xF1\xF2\x9E\xAB\xD0\xEF\xDF\x73" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My", -- { KV5M_DATA, 15, "Sodium Chloride" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xD6\x85\x61\xC4\xF2\x94\xF4\xA1" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My ", -- { KV5M_DATA, 15, "Sodium Chloride" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xD0\xE3\xA7\x83\x94\x61\xE0\xD0" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My P", -- { KV5M_DATA, 15, "Sodium Chloride" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xD5\x62\xCD\x94\x61\xCB\x97\xDF" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My Pa", -- { KV5M_DATA, 15, "Sodium Chloride" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\x9E\xA2\xA2\xEC\xA8\x8C\x6B\x8F" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My Pas", -- { KV5M_DATA, 15, "Sodium Chloride" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xE3\x91\x6D\xD3\x85\xF1\x67\xC4" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My Pass", -- { KV5M_DATA, 15, "Sodium Chloride" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xF4\xC4\x73\xC8\x8A\xE9\x94\x6D" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My Passw", -- { KV5M_DATA, 15, "Sodium Chloride" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xA1\x9E\xB3\xAD\x6B\xE3\xAB\xD9" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My Passwo", -- { KV5M_DATA, 15, "Sodium Chloride" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xAD\xA1\xCE\x10\x37\x83\xA7\x8C" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My Passwor", -- { KV5M_DATA, 15, "Sodium Chloride" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xD3\x01\xD0\xF7\x3E\x7A\x49\x0B" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My Password", -- { KV5M_DATA, 15, "Sodium Chloride" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xB6\x2A\x4A\xEC\x9D\x4C\x68\xDF" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "", -- { KV5M_DATA, 4, "NaCl" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\x61\xEF\xE6\x83\xE5\x8A\x6B\x98" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "M", -- { KV5M_DATA, 4, "NaCl" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\x68\xCD\x68\xAD\xC4\x86\xCD\xE5" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My", -- { KV5M_DATA, 4, "NaCl" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\x83\xA1\xC8\x86\x8F\x67\xD0\x62" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My ", -- { KV5M_DATA, 4, "NaCl" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\x9E\xC7\x8F\xA4\xA4\xB3\xE0\xD5" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My P", -- { KV5M_DATA, 4, "NaCl" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xD9\x92\x86\x8F\x9D\x8C\x85\xE6" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My Pa", -- { KV5M_DATA, 4, "NaCl" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xDA\xF2\x92\x83\xF4\x9B\xA7\xAD" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My Pas", -- { KV5M_DATA, 4, "NaCl" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\x91\xCD\xAD\xEF\x86\xDF\xD3\xA2" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My Pass", -- { KV5M_DATA, 4, "NaCl" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\x73\xD3\x67\x68\x8F\x6E\xE3\x73" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My Passw", -- { KV5M_DATA, 4, "NaCl" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xC4\x61\x85\x9D\xAD\xF4\xDC\xB0" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My Passwo", -- { KV5M_DATA, 4, "NaCl" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\xE9\x02\x83\x16\x2C\xEC\xE0\x08" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My Passwor", -- { KV5M_DATA, 4, "NaCl" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\x61\xC8\x26\x29\xD9\x73\x6E\xB6" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "My Password", -- { KV5M_DATA, 4, "NaCl" }, -- { KV5M_DATA, 1, "\1" }, -- { KV5M_DATA, 8, "\x8C\xA8\x9E\xC4\xA8\xDC\x31\x73" }, -- 0, -- FALSE -- }, -- -- /* Test vectors from RFC 3961 appendix A.2. */ -- { -- ENCTYPE_DES_CBC_CRC, -- "password", -- { KV5M_DATA, 21, "ATHENA.MIT.EDUraeburn" }, -- { KV5M_DATA, 1, "\0" }, -- { KV5M_DATA, 8, "\xCB\xC2\x2F\xAE\x23\x52\x98\xE3" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "potatoe", -- { KV5M_DATA, 19, "WHITEHOUSE.GOVdanny" }, -- { KV5M_DATA, 1, "\0" }, -- { KV5M_DATA, 8, "\xDF\x3D\x32\xA7\x4F\xD9\x2A\x01" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "\xF0\x9D\x84\x9E", -- { KV5M_DATA, 18, "EXAMPLE.COMpianist" }, -- { KV5M_DATA, 1, "\0" }, -- { KV5M_DATA, 8, "\x4F\xFB\x26\xBA\xB0\xCD\x94\x13" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "\xC3\x9F", -- { KV5M_DATA, 23, "ATHENA.MIT.EDUJuri\xC5\xA1\x69\xC4\x87" }, -- { KV5M_DATA, 1, "\0" }, -- { KV5M_DATA, 8, "\x62\xC8\x1A\x52\x32\xB5\xE6\x9D" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "11119999", -- { KV5M_DATA, 8, "AAAAAAAA" }, -- { KV5M_DATA, 1, "\0" }, -- { KV5M_DATA, 8, "\x98\x40\x54\xd0\xf1\xa7\x3e\x31" }, -- 0, -- FALSE -- }, -- { -- ENCTYPE_DES_CBC_CRC, -- "NNNN6666", -- { KV5M_DATA, 8, "FFFFAAAA" }, -- { KV5M_DATA, 1, "\0" }, -- { KV5M_DATA, 8, "\xC4\xBF\x6B\x25\xAD\xF7\xA4\xF8" }, -- 0, -- FALSE -- }, -- - /* Test vectors from RFC 3961 appendix A.4. */ - { - ENCTYPE_DES3_CBC_SHA1, -diff --git a/src/lib/crypto/crypto_tests/vectors.c b/src/lib/crypto/crypto_tests/vectors.c -index c1a765732..bcf5c9106 100644 ---- a/src/lib/crypto/crypto_tests/vectors.c -+++ b/src/lib/crypto/crypto_tests/vectors.c -@@ -30,7 +30,8 @@ - * - * N.B.: Doesn't compile -- this file uses some routines internal to our - * crypto library which are declared "static" and thus aren't accessible -- * without modifying the other sources. -+ * without modifying the other sources. Additionally, some ciphers have been -+ * removed. - */ - - #include -diff --git a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp -index db899a1dc..740425c69 100644 ---- a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp -+++ b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp -@@ -18,8 +18,8 @@ proc test200 {} { - - # I'd like to specify a long list of keysalt tuples and make sure - # that chpass does the right thing, but we can only use those -- # enctypes that krbtgt has a key for: des-cbc-crc:normal -- # according to the prototype kdc.conf. -+ # enctypes that krbtgt has a key for: the AES enctypes, according to -+ # the prototype kdc.conf. - if {! [cmd [format { - kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ - $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -@@ -53,10 +53,10 @@ proc test200 {} { - } - - # XXX Perhaps I should actually check the key type returned. -- if {$num_keys == 2} { -+ if {$num_keys == 5} { - pass "$test" - } else { -- fail "$test: $num_keys keys, should be 2" -+ fail "$test: $num_keys keys, should be 5" - } - if { ! [cmd {kadm5_destroy $server_handle}]} { - perror "$test: unexpected failure in destroy" -diff --git a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp -index 8526897ed..3ea1ba29b 100644 ---- a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp -+++ b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp -@@ -143,8 +143,8 @@ proc test101_102 {rpc} { - } - - set failed 0 -- if {$num_keys != 2} { -- fail "$test: num_keys $num_keys should be 2" -+ if {$num_keys != 5} { -+ fail "$test: num_keys $num_keys should be 5" - set failed 1 - } - for {set i 0} {$i < $num_keys} {incr i} { -diff --git a/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp -index ee652cbd3..2925c1c43 100644 ---- a/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp -+++ b/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp -@@ -16,10 +16,9 @@ proc test100 {} { - return - } - -- # I'd like to specify a long list of keysalt tuples and make sure -- # that randkey does the right thing, but we can only use those -- # enctypes that krbtgt has a key for: des-cbc-crc:normal and -- # des-cbc-crc:v4, according to the prototype kdc.conf. -+ # I'd like to specify a long list of keysalt tuples and make sure that -+ # randkey does the right thing, but we can only use those enctypes that -+ # krbtgt has a key for: 3DES and AES, according to the prototype kdc.conf. - if {! [cmd [format { - kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ - $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -@@ -47,10 +46,10 @@ proc test100 {} { - } - - # XXX Perhaps I should actually check the key type returned. -- if {$num_keys == 2} { -+ if {$num_keys == 5} { - pass "$test" - } else { -- fail "$test: $num_keys keys, should be 2" -+ fail "$test: $num_keys keys, should be 5" - } - if { ! [cmd {kadm5_destroy $server_handle}]} { - perror "$test: unexpected failure in destroy" -diff --git a/src/lib/kadm5/unit-test/setkey-test.c b/src/lib/kadm5/unit-test/setkey-test.c -index fa2392f81..8e7df96e9 100644 ---- a/src/lib/kadm5/unit-test/setkey-test.c -+++ b/src/lib/kadm5/unit-test/setkey-test.c -@@ -19,15 +19,15 @@ need a random number generator - #endif /* no random */ - - krb5_keyblock test1[] = { -- {0, ENCTYPE_DES_CBC_CRC, 0, 0}, -+ {0, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0, 0}, - {-1}, - }; - krb5_keyblock test2[] = { -- {0, ENCTYPE_DES_CBC_CRC, 0, 0}, -+ {0, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0, 0}, - {-1}, - }; - krb5_keyblock test3[] = { -- {0, ENCTYPE_DES_CBC_CRC, 0, 0}, -+ {0, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0, 0}, - {-1}, - }; - -diff --git a/src/lib/krb5/keytab/t_keytab.c b/src/lib/krb5/keytab/t_keytab.c -index c845596d6..ea4ce6819 100644 ---- a/src/lib/krb5/keytab/t_keytab.c -+++ b/src/lib/krb5/keytab/t_keytab.c -@@ -96,6 +96,8 @@ kt_test(krb5_context context, const char *name) - krb5_principal princ; - krb5_kt_cursor cursor, cursor2; - int cnt; -+ krb5_enctype e1 = ENCTYPE_AES128_CTS_HMAC_SHA256_128, -+ e2 = ENCTYPE_AES256_CTS_HMAC_SHA384_192; - - kret = krb5_kt_resolve(context, name, &kt); - CHECK(kret, "resolve"); -@@ -139,9 +141,9 @@ kt_test(krb5_context context, const char *name) - /* =================== Add entries to keytab ================= */ - /* - * Add the following for this principal -- * enctype 1, kvno 1, key = "1" -- * enctype 2, kvno 1, key = "1" -- * enctype 1, kvno 2, key = "2" -+ * enctype e1, kvno 1, key = "1" -+ * enctype e2, kvno 1, key = "1" -+ * enctype e1, kvno 2, key = "2" - */ - memset(&kent, 0, sizeof(kent)); - kent.magic = KV5M_KEYTAB_ENTRY; -@@ -149,7 +151,7 @@ kt_test(krb5_context context, const char *name) - kent.timestamp = 327689; - kent.vno = 1; - kent.key.magic = KV5M_KEYBLOCK; -- kent.key.enctype = 1; -+ kent.key.enctype = e1; - kent.key.length = 1; - kent.key.contents = (krb5_octet *) "1"; - -@@ -157,11 +159,11 @@ kt_test(krb5_context context, const char *name) - kret = krb5_kt_add_entry(context, kt, &kent); - CHECK(kret, "Adding initial entry"); - -- kent.key.enctype = 2; -+ kent.key.enctype = e2; - kret = krb5_kt_add_entry(context, kt, &kent); - CHECK(kret, "Adding second entry"); - -- kent.key.enctype = 1; -+ kent.key.enctype = e1; - kent.vno = 2; - kent.key.contents = (krb5_octet *) "2"; - kret = krb5_kt_add_entry(context, kt, &kent); -@@ -183,7 +185,7 @@ kt_test(krb5_context context, const char *name) - cnt = 0; - while((kret = krb5_kt_next_entry(context, kt, &kent, &cursor)) == 0) { - if(((kent.vno != 1) && (kent.vno != 2)) || -- ((kent.key.enctype != 1) && (kent.key.enctype != 2)) || -+ ((kent.key.enctype != e1) && (kent.key.enctype != e2)) || - (kent.key.length != 1) || - (kent.key.contents[0] != kent.vno +'0')) { - fprintf(stderr, "Error in read contents\n"); -@@ -231,7 +233,7 @@ kt_test(krb5_context context, const char *name) - /* Ensure a valid answer - we did not specify an enctype or kvno */ - if (!krb5_principal_compare(context, princ, kent.principal) || - ((kent.vno != 1) && (kent.vno != 2)) || -- ((kent.key.enctype != 1) && (kent.key.enctype != 2)) || -+ ((kent.key.enctype != e1) && (kent.key.enctype != e2)) || - (kent.key.length != 1) || - (kent.key.contents[0] != kent.vno +'0')) { - fprintf(stderr, "Retrieved principal does not check\n"); -@@ -243,12 +245,12 @@ kt_test(krb5_context context, const char *name) - /* Try to lookup a specific enctype - but unspecified kvno - should give - * max kvno - */ -- kret = krb5_kt_get_entry(context, kt, princ, 0, 1, &kent); -+ kret = krb5_kt_get_entry(context, kt, princ, 0, e1, &kent); - CHECK(kret, "looking up principal"); - - /* Ensure a valid answer - we did specified an enctype */ - if (!krb5_principal_compare(context, princ, kent.principal) || -- (kent.vno != 2) || (kent.key.enctype != 1) || -+ (kent.vno != 2) || (kent.key.enctype != e1) || - (kent.key.length != 1) || - (kent.key.contents[0] != kent.vno +'0')) { - fprintf(stderr, "Retrieved principal does not check\n"); -@@ -266,7 +268,7 @@ kt_test(krb5_context context, const char *name) - - /* Ensure a valid answer - we did not specify a kvno */ - if (!krb5_principal_compare(context, princ, kent.principal) || -- (kent.vno != 2) || (kent.key.enctype != 1) || -+ (kent.vno != 2) || (kent.key.enctype != e1) || - (kent.key.length != 1) || - (kent.key.contents[0] != kent.vno +'0')) { - fprintf(stderr, "Retrieved principal does not check\n"); -@@ -281,11 +283,11 @@ kt_test(krb5_context context, const char *name) - - /* Try to lookup specified enctype and kvno */ - -- kret = krb5_kt_get_entry(context, kt, princ, 1, 1, &kent); -+ kret = krb5_kt_get_entry(context, kt, princ, 1, e1, &kent); - CHECK(kret, "looking up principal"); - - if (!krb5_principal_compare(context, princ, kent.principal) || -- (kent.vno != 1) || (kent.key.enctype != 1) || -+ (kent.vno != 1) || (kent.key.enctype != e1) || - (kent.key.length != 1) || - (kent.key.contents[0] != kent.vno +'0')) { - fprintf(stderr, "Retrieved principal does not check\n"); -@@ -334,7 +336,7 @@ kt_test(krb5_context context, const char *name) - - /* Try to lookup specified enctype and kvno - that does not exist*/ - -- kret = krb5_kt_get_entry(context, kt, princ, 3, 1, &kent); -+ kret = krb5_kt_get_entry(context, kt, princ, 3, e1, &kent); - CHECK_ERR(kret, KRB5_KT_KVNONOTFOUND, - "looking up specific principal, kvno, enctype"); - -@@ -347,12 +349,12 @@ kt_test(krb5_context context, const char *name) - kret = krb5_parse_name(context, "test/test2@TEST.MIT.EDU", &princ); - CHECK(kret, "parsing principal"); - -- kret = krb5_kt_get_entry(context, kt, princ, 0, 1, &kent); -+ kret = krb5_kt_get_entry(context, kt, princ, 0, e1, &kent); - CHECK(kret, "looking up principal"); - -- /* Ensure a valid answer - we are looking for max(kvno) and enc=1 */ -+ /* Ensure a valid answer - we are looking for max(kvno) and enc=e1 */ - if (!krb5_principal_compare(context, princ, kent.principal) || -- (kent.vno != 2) || (kent.key.enctype != 1) || -+ (kent.vno != 2) || (kent.key.enctype != e1) || - (kent.key.length != 1) || - (kent.key.contents[0] != kent.vno +'0')) { - fprintf(stderr, "Retrieved principal does not check\n"); -@@ -368,12 +370,12 @@ kt_test(krb5_context context, const char *name) - krb5_free_keytab_entry_contents(context, &kent); - /* And ensure gone */ - -- kret = krb5_kt_get_entry(context, kt, princ, 0, 1, &kent); -+ kret = krb5_kt_get_entry(context, kt, princ, 0, e1, &kent); - CHECK(kret, "looking up principal"); - - /* Ensure a valid answer - kvno should now be 1 - we deleted 2 */ - if (!krb5_principal_compare(context, princ, kent.principal) || -- (kent.vno != 1) || (kent.key.enctype != 1) || -+ (kent.vno != 1) || (kent.key.enctype != e1) || - (kent.key.length != 1) || - (kent.key.contents[0] != kent.vno +'0')) { - fprintf(stderr, "Delete principal check failed\n"); -diff --git a/src/lib/krb5/krb/t_etypes.c b/src/lib/krb5/krb/t_etypes.c -index 317637684..f609e938a 100644 ---- a/src/lib/krb5/krb/t_etypes.c -+++ b/src/lib/krb5/krb/t_etypes.c -@@ -36,20 +36,6 @@ static struct { - krb5_error_code expected_err_noweak; - krb5_error_code expected_err_weak; - } tests[] = { -- /* Empty string, unused default list */ -- { "", -- { ENCTYPE_DES_CBC_CRC, 0 }, -- { 0 }, -- { 0 }, -- 0, 0 -- }, -- /* Single weak enctype */ -- { "des-cbc-md4", -- { 0 }, -- { 0 }, -- { ENCTYPE_DES_CBC_MD4, 0 }, -- 0, 0 -- }, - /* Single non-weak enctype */ - { "aes128-cts-hmac-sha1-96", - { 0 }, -@@ -57,35 +43,11 @@ static struct { - { ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0 }, - 0, 0 - }, -- /* Two enctypes, one an alias, one weak */ -- { "rc4-hmac des-cbc-md5", -- { 0 }, -- { ENCTYPE_ARCFOUR_HMAC, 0 }, -- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_DES_CBC_MD5, 0 }, -- 0, 0 -- }, -- /* Three enctypes, all weak, case variation, funky separators */ -- { " deS-HMac-shA1 , arCFour-hmaC-mD5-exp\tdeS3-Cbc-RAw\n", -- { 0 }, -- { 0 }, -- { ENCTYPE_DES_HMAC_SHA1, ENCTYPE_ARCFOUR_HMAC_EXP, -- ENCTYPE_DES3_CBC_RAW, 0 }, -- 0, 0 -- }, -- /* Default set with enctypes added (one weak in each pair) */ -- { "DEFAULT des-cbc-raw +des3-hmac-sha1", -- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_ARCFOUR_HMAC_EXP, 0 }, -- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_DES3_CBC_SHA1, 0 }, -- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_ARCFOUR_HMAC_EXP, -- ENCTYPE_DES_CBC_RAW, ENCTYPE_DES3_CBC_SHA1, 0 }, -- 0, 0 -- }, - /* Default set with enctypes removed */ - { "default -aes128-cts -des-hmac-sha1", -- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, -- ENCTYPE_DES_CBC_MD5, ENCTYPE_DES_HMAC_SHA1, 0 }, -+ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0 }, -+ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, - { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, -- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_DES_CBC_MD5, 0 }, - 0, 0 - }, - /* Family followed by enctype */ -@@ -105,31 +67,22 @@ static struct { - { ENCTYPE_CAMELLIA128_CTS_CMAC, 0 }, - { ENCTYPE_CAMELLIA128_CTS_CMAC, 0 } - }, -- /* Enctype followed by two families */ -- { "+rc4-hmAC des3 +des", -- { 0 }, -- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_DES3_CBC_SHA1, 0 }, -- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_DES3_CBC_SHA1, ENCTYPE_DES_CBC_CRC, -- ENCTYPE_DES_CBC_MD5, ENCTYPE_DES_CBC_MD4 }, -- 0, 0 -- }, - /* Default set with family added and enctype removed */ - { "DEFAULT +aes -arcfour-hmac-md5", -- { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_DES3_CBC_SHA1, ENCTYPE_DES_CBC_CRC, 0 }, -+ { ENCTYPE_ARCFOUR_HMAC, ENCTYPE_DES3_CBC_SHA1, 0 }, - { ENCTYPE_DES3_CBC_SHA1, ENCTYPE_AES256_CTS_HMAC_SHA1_96, - ENCTYPE_AES128_CTS_HMAC_SHA1_96, ENCTYPE_AES256_CTS_HMAC_SHA384_192, - ENCTYPE_AES128_CTS_HMAC_SHA256_128, 0 }, -- { ENCTYPE_DES3_CBC_SHA1, ENCTYPE_DES_CBC_CRC, -+ { ENCTYPE_DES3_CBC_SHA1, - ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, - ENCTYPE_AES256_CTS_HMAC_SHA384_192, ENCTYPE_AES128_CTS_HMAC_SHA256_128, - 0 }, - 0, 0 - }, - /* Default set with families removed and enctypes added (one redundant) */ -- { "DEFAULT -des -des3 rc4-hmac rc4-hmac-exp", -+ { "DEFAULT -des3 rc4-hmac rc4-hmac-exp", - { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, -- ENCTYPE_DES3_CBC_SHA1, ENCTYPE_ARCFOUR_HMAC, -- ENCTYPE_DES_CBC_CRC, ENCTYPE_DES_CBC_MD5, ENCTYPE_DES_CBC_MD4, 0 }, -+ ENCTYPE_DES3_CBC_SHA1, ENCTYPE_ARCFOUR_HMAC, 0 }, - { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, - ENCTYPE_ARCFOUR_HMAC, 0 }, - { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_AES128_CTS_HMAC_SHA1_96, -@@ -158,17 +111,17 @@ static struct { - }, - /* Test krb5_set_default_in_tkt_ktypes */ - { NULL, -- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_DES_CBC_CRC, 0 }, - { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, -- { ENCTYPE_AES256_CTS_HMAC_SHA1_96, ENCTYPE_DES_CBC_CRC, 0 }, -+ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, -+ { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, - 0, 0 - }, - /* Should get KRB5_CONFIG_ETYPE_NOSUPP if app-provided list has no strong - * enctypes and allow_weak_crypto=false. */ - { NULL, -- { ENCTYPE_DES_CBC_CRC, 0 }, -+ { ENCTYPE_ARCFOUR_HMAC_EXP, 0 }, - { 0 }, -- { ENCTYPE_DES_CBC_CRC, 0 }, -+ { ENCTYPE_ARCFOUR_HMAC_EXP, 0 }, - KRB5_CONFIG_ETYPE_NOSUPP, 0 - }, - /* Should get EINVAL if app provides an empty list. */ -diff --git a/src/lib/krb5/krb/t_ser.c b/src/lib/krb5/krb/t_ser.c -index 1d6cceaa2..f1a8c2553 100644 ---- a/src/lib/krb5/krb/t_ser.c -+++ b/src/lib/krb5/krb/t_ser.c -@@ -272,7 +272,7 @@ ser_acontext_test(krb5_context kcontext, int verbose) - KV5M_AUTH_CONTEXT))) { - memset(&ukeyblock, 0, sizeof(ukeyblock)); - memset(keydata, 0, sizeof(keydata)); -- ukeyblock.enctype = ENCTYPE_DES_CBC_MD5; -+ ukeyblock.enctype = ENCTYPE_AES128_CTS_HMAC_SHA256_128; - ukeyblock.length = sizeof(keydata); - ukeyblock.contents = keydata; - keydata[0] = 0xde; -diff --git a/src/lib/krb5/os/t_trace.c b/src/lib/krb5/os/t_trace.c -index 5aea68e8d..10ba8d0ac 100644 ---- a/src/lib/krb5/os/t_trace.c -+++ b/src/lib/krb5/os/t_trace.c -@@ -204,7 +204,7 @@ main (int argc, char *argv[]) - padatap = NULL; - - TRACE(ctx, "krb5_enctype, display shortest name of enctype: {etype}", -- ENCTYPE_DES_CBC_CRC); -+ ENCTYPE_AES128_CTS_HMAC_SHA1_96); - TRACE(ctx, "krb5_enctype *, display list of enctypes: {etypes}", enctypes); - TRACE(ctx, "krb5_enctype *, display list of enctypes: {etypes}", NULL); - -diff --git a/src/lib/krb5/os/t_trace.ref b/src/lib/krb5/os/t_trace.ref -index bd5d9b6b6..044a66999 100644 ---- a/src/lib/krb5/os/t_trace.ref -+++ b/src/lib/krb5/os/t_trace.ref -@@ -40,7 +40,7 @@ int, krb5_principal type: NT 4 style name and SID - int, krb5_principal type: ? - krb5_pa_data **, display list of padata type numbers: PA-PW-SALT (3), 0 - krb5_pa_data **, display list of padata type numbers: (empty) --krb5_enctype, display shortest name of enctype: des-cbc-crc -+krb5_enctype, display shortest name of enctype: aes128-cts - krb5_enctype *, display list of enctypes: 5, rc4-hmac-exp, 511 - krb5_enctype *, display list of enctypes: (empty) - krb5_ccache, display type:name: FILE:/path/to/ccache -diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c -index 6bf6e54ac..258377299 100644 ---- a/src/tests/asn.1/ktest.c -+++ b/src/tests/asn.1/ktest.c -@@ -893,7 +893,7 @@ ktest_make_sample_sp80056a_other_info(krb5_sp80056a_other_info *p) - void - ktest_make_sample_pkinit_supp_pub_info(krb5_pkinit_supp_pub_info *p) - { -- p->enctype = ENCTYPE_DES_CBC_CRC; -+ p->enctype = ENCTYPE_AES256_CTS_HMAC_SHA384_192; - ktest_make_sample_data(&p->as_req); - ktest_make_sample_data(&p->pk_as_rep); - } -diff --git a/src/tests/asn.1/pkinit_encode.out b/src/tests/asn.1/pkinit_encode.out -index 3b0f7190a..55a60bbef 100644 ---- a/src/tests/asn.1/pkinit_encode.out -+++ b/src/tests/asn.1/pkinit_encode.out -@@ -10,4 +10,4 @@ encode_krb5_kdc_dh_key_info: 30 25 A0 0B 03 09 00 6B 72 62 35 64 61 74 61 A1 03 - encode_krb5_reply_key_pack: 30 26 A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34 - encode_krb5_reply_key_pack_draft9: 30 1A A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 03 02 01 2A - encode_krb5_sp80056a_other_info: 30 81 81 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A0 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A2 0A 04 08 6B 72 62 35 64 61 74 61 --encode_krb5_pkinit_supp_pub_info: 30 1D A0 03 02 01 01 A1 0A 04 08 6B 72 62 35 64 61 74 61 A2 0A 04 08 6B 72 62 35 64 61 74 61 -+encode_krb5_pkinit_supp_pub_info: 30 1D A0 03 02 01 14 A1 0A 04 08 6B 72 62 35 64 61 74 61 A2 0A 04 08 6B 72 62 35 64 61 74 61 -diff --git a/src/tests/asn.1/pkinit_trval.out b/src/tests/asn.1/pkinit_trval.out -index f9edbe154..9557188a8 100644 ---- a/src/tests/asn.1/pkinit_trval.out -+++ b/src/tests/asn.1/pkinit_trval.out -@@ -145,6 +145,6 @@ encode_krb5_sp80056a_other_info: - encode_krb5_pkinit_supp_pub_info: - - [Sequence/Sequence Of] --. [0] [Integer] 1 -+. [0] [Integer] 20 - . [1] [Octet String] "krb5data" - . [2] [Octet String] "krb5data" -diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp -index c061d764e..e8adee234 100644 ---- a/src/tests/dejagnu/config/default.exp -+++ b/src/tests/dejagnu/config/default.exp -@@ -16,21 +16,6 @@ set stty_init {erase \^h kill \^u} - set env(TERM) dumb - - set des3_krbtgt 0 --set tgt_support_desmd5 0 -- --# The names of the individual passes must be unique; lots of things --# depend on it. The PASSES variable may not contain comments; only --# small pieces get evaluated, so comments will do strange things. -- --# Most of the purpose of using multiple passes is to exercise the --# dependency of various bugs on configuration file settings, --# particularly with regards to encryption types. -- --# The des.no-kdc-md5 pass will fail if the KDC does not constrain --# session key enctypes to those in its permitted_enctypes list. It --# works by assuming enctype similarity, thus allowing the client to --# request a des-cbc-md4 session key. Since only des-cbc-crc is in the --# KDC's permitted_enctypes list, the TGT will be unusable. - - if { [string length $VALGRIND] } { - rename spawn valgrind_aux_spawn -@@ -111,47 +96,21 @@ if { $PRIOCNTL_HACK } { - } - } - --# The des.des3-tgt.no-kdc-des3 pass will fail if the KDC doesn't --# constrain ticket key enctypes to those in permitted_enctypes. It --# does this by not putting des3 in the permitted_enctypes, while --# creating a TGT princpal that has a des3 key as well as a des key. -+# The names of the individual passes must be unique; lots of things -+# depend on it. The PASSES variable may not contain comments; only -+# small pieces get evaluated, so comments will do strange things. - --# XXX -- master_key_type is fragile w.r.t. permitted_enctypes; it is --# possible to configure things such that you have a master_key_type --# that is not permitted, and the error message used to be cryptic. -+# Most of the purpose of using multiple passes is to exercise the -+# dependency of various bugs on configuration file settings, -+# particularly with regards to encryption types. - - set passes { -- { -- des -- mode=udp -- des3_krbtgt=0 -- {supported_enctypes=des-cbc-crc:normal} -- {dummy=[verbose -log "DES TGT, DES enctype"]} -- } -- { -- des.des3tgt -- mode=udp -- des3_krbtgt=1 -- {supported_enctypes=des-cbc-crc:normal} -- {dummy=[verbose -log "DES3 TGT, DES enctype"]} -- } - { - des3 - mode=udp - des3_krbtgt=1 -- {supported_enctypes=des3-cbc-sha1:normal des-cbc-crc:normal} -- {dummy=[verbose -log "DES3 TGT, DES3 + DES enctypes"]} -- } -- { -- aes-des -- mode=udp -- des3_krbtgt=0 -- {supported_enctypes=aes256-cts-hmac-sha1-96:normal des-cbc-crc:normal} -- {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96 des-cbc-crc} -- {permitted_enctypes(client)=aes256-cts-hmac-sha1-96 des-cbc-crc} -- {permitted_enctypes(server)=aes256-cts-hmac-sha1-96 des-cbc-crc} -- {master_key_type=aes256-cts-hmac-sha1-96} -- {dummy=[verbose -log "AES + DES enctypes"]} -+ {supported_enctypes=des3-cbc-sha1:normal} -+ {dummy=[verbose -log "DES3 TGT, DES3 enctype"]} - } - { - aes-only -@@ -220,10 +179,10 @@ set passes { - aes-des3 - mode=udp - des3_krbtgt=0 -- {supported_enctypes=aes256-cts-hmac-sha1-96:normal des3-cbc-sha1:normal des-cbc-crc:normal} -- {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96 des3-cbc-sha1 des-cbc-crc} -- {permitted_enctypes(client)=aes256-cts-hmac-sha1-96 des3-cbc-sha1 des-cbc-crc} -- {permitted_enctypes(server)=aes256-cts-hmac-sha1-96 des3-cbc-sha1 des-cbc-crc} -+ {supported_enctypes=aes256-cts-hmac-sha1-96:normal des3-cbc-sha1:normal} -+ {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} -+ {permitted_enctypes(client)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} -+ {permitted_enctypes(server)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} - {master_key_type=aes256-cts-hmac-sha1-96} - {dummy=[verbose -log "AES + DES3 + DES enctypes"]} - } -@@ -231,12 +190,12 @@ set passes { - aes-des3tgt - mode=udp - des3_krbtgt=1 -- {supported_enctypes=aes256-cts-hmac-sha1-96:normal des3-cbc-sha1:normal des-cbc-crc:normal} -- {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96 des3-cbc-sha1 des-cbc-crc} -- {permitted_enctypes(client)=aes256-cts-hmac-sha1-96 des3-cbc-sha1 des-cbc-crc} -- {permitted_enctypes(server)=aes256-cts-hmac-sha1-96 des3-cbc-sha1 des-cbc-crc} -+ {supported_enctypes=aes256-cts-hmac-sha1-96:normal des3-cbc-sha1:normal} -+ {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} -+ {permitted_enctypes(client)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} -+ {permitted_enctypes(server)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} - {master_key_type=aes256-cts-hmac-sha1-96} -- {dummy=[verbose -log "AES + DES enctypes, DES3 TGT"]} -+ {dummy=[verbose -log "AES enctypes, DES3 TGT"]} - } - { - all-enctypes -@@ -248,115 +207,8 @@ set passes { - {allow_weak_crypto(server)=false} - {dummy=[verbose -log "all default enctypes"]} - } -- { -- des.no-kdc-md5 -- mode=udp -- des3_krbtgt=0 -- tgt_support_desmd5=0 -- {permitted_enctypes(kdc)=des-cbc-crc} -- {default_tgs_enctypes(client)=des-cbc-md5 des-cbc-md4 des-cbc-crc} -- {default_tkt_enctypes(client)=des-cbc-md5 des-cbc-md4 des-cbc-crc} -- {supported_enctypes=des-cbc-crc:normal} -- {master_key_type=des-cbc-crc} -- {dummy=[verbose -log \ -- "DES TGT, KDC permitting only des-cbc-crc"]} -- } -- { -- des.des3-tgt.no-kdc-des3 -- mode=udp -- tgt_support_desmd5=0 -- {permitted_enctypes(kdc)=des-cbc-crc} -- {default_tgs_enctypes(client)=des-cbc-crc} -- {default_tkt_enctypes(client)=des-cbc-crc} -- {supported_enctypes=des3-cbc-sha1:normal des-cbc-crc:normal} -- {master_key_type=des-cbc-crc} -- {dummy=[verbose -log \ -- "DES3 TGT, KDC permitting only des-cbc-crc"]} -- } - } - --# des.md5-tgt is set as unused, since it won't trigger the error case --# if SUPPORT_DESMD5 isn't honored. -- --# The des.md5-tgt pass will fail if enctype similarity is inconsisent; --# between 1.0.x and 1.1, the decrypt functions became more strict --# about matching enctypes, while the KDB retrieval functions didn't --# coerce the enctype to match what was requested. It works by setting --# SUPPORT_DESMD5 on the TGT principal, forcing an enctype of --# des-cbc-md5 on the TGT key. Since the database only contains a --# des-cbc-crc key, the decrypt will fail if enctypes are not coerced. -- --# des.no-kdc-md5.client-md4-skey is retained in unsed_passes, even --# though des.no-kdc-md5 is roughly equivalent, since the associated --# comment needs additional investigation at some point re the kadmin --# client. -- --# The des.no-kdc-md5.client-md4-skey will fail on TGS requests due to --# the KDC issuing session keys that it won't accept. It will also --# fail for a kadmin client, but for different reasons, since the kadm5 --# library does some curious filtering of enctypes, and also uses --# get_in_tkt() rather than get_init_creds(); the former does an --# intersection of the enctypes provided by the caller and those listed --# in the config file! -- --set unused_passes { -- { -- des.md5-tgt -- des3_krbtgt=0 -- tgt_support_desmd5=1 -- supported_enctypes=des-cbc-crc:normal -- {permitted_enctypes(kdc)=des-cbc-md5 des-cbc-md4 des-cbc-crc} -- {permitted_enctypes(client)=des-cbc-md5 des-cbc-md4 des-cbc-crc} -- {dummy=[verbose -log "DES TGT, SUPPORTS_DESMD5"]} -- } -- { -- des.md5-tgt.no-kdc-md5 -- des3_krbtgt=0 -- tgt_support_desmd5=1 -- {permitted_enctypes(kdc)=des-cbc-crc} -- {default_tgs_enctypes(client)=des-cbc-crc} -- {default_tkt_enctypes(client)=des-cbc-crc} -- {supported_enctypes=des-cbc-crc:normal} -- {master_key_type=des-cbc-crc} -- {dummy=[verbose -log \ -- "DES TGT, SUPPORTS_DESMD5, KDC permitting only des-cbc-crc"]} -- } -- { -- des.no-kdc-md5.client-md4-skey -- des3_krbtgt=0 -- {permitted_enctypes(kdc)=des-cbc-crc} -- {permitted_enctypes(client)=des-cbc-crc des-cbc-md4} -- {default_tgs_enctypes(client)=des-cbc-crc des-cbc-md4} -- {default_tkt_enctypes(client)=des-cbc-md4} -- {supported_enctypes=des-cbc-crc:normal} -- {dummy=[verbose -log \ -- "DES TGT, DES enctype, KDC permitting only des-cbc-crc, client requests des-cbc-md4 session key"]} -- } -- { -- all-enctypes -- des3_krbtgt=1 -- {supported_enctypes=\ -- aes256-cts-hmac-sha1-96:normal aes256-cts-hmac-sha1-96:norealm \ -- aes128-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:norealm \ -- des3-cbc-sha1:normal des3-cbc-sha1:none \ -- des-cbc-md5:normal des-cbc-md4:normal des-cbc-crc:normal \ -- } -- {dummy=[verbose -log "DES3 TGT, default enctypes"]} -- } -- { -- aes-tcp -- mode=tcp -- des3_krbtgt=0 -- {supported_enctypes=aes256-cts-hmac-sha1-96:normal} -- {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96} -- {permitted_enctypes(client)=aes256-cts-hmac-sha1-96} -- {permitted_enctypes(server)=aes256-cts-hmac-sha1-96} -- {master_key_type=aes256-cts-hmac-sha1-96} -- {dummy=[verbose -log "AES via TCP"]} -- } --} --# {supported_enctypes=des-cbc-md5:normal des-cbc-crc:normal twofish256-hmac-sha1:normal } -- - # This shouldn't be necessary on dejagnu-1.4 and later, but 1.3 seems - # to need it because its runtest.exp doesn't deal with PASS at all. - if [info exists PASS] { -@@ -1095,7 +947,7 @@ proc setup_kerberos_db { standalone } { - global REALMNAME KDB5_UTIL KADMIN_LOCAL KEY - global tmppwd hostname - global spawn_id -- global des3_krbtgt tgt_support_desmd5 -+ global des3_krbtgt - global multipass_name last_passname_db - - set failall 0 -@@ -1334,48 +1186,6 @@ proc setup_kerberos_db { standalone } { - } - } - } -- if $tgt_support_desmd5 { -- # Make TGT support des-cbc-md5 -- set test "kadmin.local TGT to SUPPORT_DESMD5" -- set body { -- if $failall { -- break -- } -- spawn $KADMIN_LOCAL -r $REALMNAME -- verbose "starting $test" -- expect_after $def_exp_after -- -- expect "kadmin.local: " -- send "modprinc +support_desmd5 krbtgt/$REALMNAME@$REALMNAME\r" -- # It echos... -- expect "modprinc +support_desmd5 krbtgt/$REALMNAME@$REALMNAME\r" -- expect { -- "Principal \"krbtgt/$REALMNAME@$REALMNAME\" modified.\r\n" { } -- } -- expect "kadmin.local: " -- send "quit\r" -- expect eof -- catch expect_after -- if ![check_exit_status kadmin_local] { -- break -- } -- } -- set ret [catch $body] -- catch "expect eof" -- catch expect_after -- if $ret { -- set failall 1 -- if $standalone { -- fail $test -- } else { -- delete_db -- } -- } else { -- if $standalone { -- pass $test -- } -- } -- } - envstack_pop - - # create the admin database lock file -diff --git a/src/tests/gssapi/t_invalid.c b/src/tests/gssapi/t_invalid.c -index 2a332a8ae..9876a11e6 100644 ---- a/src/tests/gssapi/t_invalid.c -+++ b/src/tests/gssapi/t_invalid.c -@@ -84,17 +84,6 @@ struct test { - size_t toklen; - const char *token; - } tests[] = { -- { -- ENCTYPE_DES_CBC_CRC, ENCTYPE_DES_CBC_RAW, -- SEAL_ALG_DES, SGN_ALG_DES_MAC_MD5, 8, -- 8, -- "\x26\xEC\xBA\xB6\xFE\xBA\x91\xCE", -- 53, -- "\x60\x33\x06\x09\x2A\x86\x48\x86\xF7\x12\x01\x02\x02\x02\x01\x00" -- "\x00\x00\x00\xFF\xFF\xF0\x0B\x90\x7B\xC4\xFC\xEB\xF4\x84\x9C\x5A" -- "\xA8\x56\x41\x3E\xE1\x62\xEE\x38\xD1\x34\x9A\xE3\xFB\xC9\xFD\x0A" -- "\xDC\x83\xE1\x4A\xE4" -- }, - { - ENCTYPE_DES3_CBC_SHA1, ENCTYPE_DES3_CBC_RAW, - SEAL_ALG_DES3KD, SGN_ALG_HMAC_SHA1_DES3_KD, 20, -@@ -160,8 +149,6 @@ make_fake_context(const struct test *test) - gss_union_ctx_id_t uctx; - krb5_gss_ctx_id_t kgctx; - krb5_keyblock kb; -- unsigned char encbuf[8]; -- size_t i; - - kgctx = calloc(1, sizeof(*kgctx)); - if (kgctx == NULL) -@@ -184,11 +171,6 @@ make_fake_context(const struct test *test) - if (krb5_k_create_key(NULL, &kb, &kgctx->seq) != 0) - abort(); - -- if (kb.enctype == ENCTYPE_DES_CBC_RAW) { -- for (i = 0; i < 8; i++) -- encbuf[i] = kb.contents[i] ^ 0xF0; -- kb.contents = encbuf; -- } - if (krb5_k_create_key(NULL, &kb, &kgctx->enc) != 0) - abort(); - -@@ -248,7 +230,7 @@ test_bogus_1964_token(gss_ctx_id_t ctx) - gss_iov_buffer_desc iov; - - store_16_be(KG_TOK_SIGN_MSG, tokbuf); -- store_16_le(SGN_ALG_DES_MAC_MD5, tokbuf + 2); -+ store_16_le(SGN_ALG_HMAC_MD5, tokbuf + 2); - store_16_le(SEAL_ALG_NONE, tokbuf + 4); - store_16_le(0xFFFF, tokbuf + 6); - memset(tokbuf + 8, 0, 16); -diff --git a/src/tests/gssapi/t_pcontok.c b/src/tests/gssapi/t_pcontok.c -index c40ea434c..7368f752f 100644 ---- a/src/tests/gssapi/t_pcontok.c -+++ b/src/tests/gssapi/t_pcontok.c -@@ -43,7 +43,6 @@ - #include "k5-int.h" - #include "common.h" - --#define SGN_ALG_DES_MAC_MD5 0x00 - #define SGN_ALG_HMAC_SHA1_DES3_KD 0x04 - #define SGN_ALG_HMAC_MD5 0x11 - -@@ -78,11 +77,7 @@ make_delete_token(gss_krb5_lucid_context_v1_t *lctx, gss_buffer_desc *out) - ret = krb5_k_create_key(context, &seqkb, &seq); - check_k5err(context, "krb5_k_create_key", ret); - -- if (signalg == SGN_ALG_DES_MAC_MD5) { -- cktype = CKSUMTYPE_RSA_MD5; -- cksize = 8; -- ckusage = 0; -- } else if (signalg == SGN_ALG_HMAC_SHA1_DES3_KD) { -+ if (signalg == SGN_ALG_HMAC_SHA1_DES3_KD) { - cktype = CKSUMTYPE_HMAC_SHA1_DES3; - cksize = 20; - ckusage = 23; -@@ -122,15 +117,7 @@ make_delete_token(gss_krb5_lucid_context_v1_t *lctx, gss_buffer_desc *out) - d = make_data(ptr - 8, 8); - ret = krb5_k_make_checksum(context, cktype, seq, ckusage, &d, &cksum); - check_k5err(context, "krb5_k_make_checksum", ret); -- if (signalg == SGN_ALG_DES_MAC_MD5) { -- iov.flags = KRB5_CRYPTO_TYPE_DATA; -- iov.data = make_data(cksum.contents, 16); -- ret = krb5_k_encrypt_iov(context, seq, 0, NULL, &iov, 1); -- check_k5err(context, "krb5_k_encrypt_iov", ret); -- memcpy(ptr + 8, cksum.contents + 8, 8); -- } else { -- memcpy(ptr + 8, cksum.contents, cksize); -- } -+ memcpy(ptr + 8, cksum.contents, cksize); - - /* Create the sequence number (8 bytes). */ - iov.flags = KRB5_CRYPTO_TYPE_DATA; -diff --git a/src/tests/gssapi/t_prf.c b/src/tests/gssapi/t_prf.c -index 6a698ce0f..f71774cdc 100644 ---- a/src/tests/gssapi/t_prf.c -+++ b/src/tests/gssapi/t_prf.c -@@ -41,13 +41,6 @@ static struct { - const char *key2; - const char *out2; - } tests[] = { -- { ENCTYPE_DES_CBC_CRC, -- "E607FE9DABB57AE0", -- "803C4121379FC4B87CE413B67707C4632EBED2C6D6B7" -- "2A55E878836E35E21600D915D590DED5B6D77BB30A1F", -- "54758316B6257A75", -- "279E4105F7ADC9BD6EF28ABE31D89B442FE0058388BA" -- "33264ACB5729562DC637950F6BD144B654BE7700B2D6" }, - { ENCTYPE_DES3_CBC_SHA1, - "70378A19CD64134580C27C0115D6B34A1CF2FEECEF9886A2", - "9F8D127C520BB826BFF3E0FE5EF352389C17E0C073D9" -diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py -index c21d054f1..2a052fc17 100644 ---- a/src/tests/t_etype_info.py -+++ b/src/tests/t_etype_info.py -@@ -24,7 +24,7 @@ def test_etinfo(princ, enctypes, expected_lines): - # With no newer enctypes in the request, PA-ETYPE-INFO2, - # PA-ETYPE-INFO, and PA-PW-SALT appear in the AS-REP, each listing one - # key for the most preferred matching enctype. --test_etinfo('user', 'rc4-hmac-exp des3 rc4 des-cbc-crc', -+test_etinfo('user', 'rc4-hmac-exp des3 rc4', - ['asrep etype_info2 des3-cbc-sha1 KRBTEST.COMuser', - 'asrep etype_info des3-cbc-sha1 KRBTEST.COMuser', - 'asrep pw_salt KRBTEST.COMuser']) -@@ -37,7 +37,7 @@ test_etinfo('user', 'rc4 aes256-cts', - - # In preauth-required errors, PA-PW-SALT does not appear, but the same - # etype-info2 values are expected. --test_etinfo('preauthuser', 'rc4-hmac-exp des3 rc4 des-cbc-crc', -+test_etinfo('preauthuser', 'rc4-hmac-exp des3 rc4', - ['error etype_info2 des3-cbc-sha1 KRBTEST.COMpreauthuser', - 'error etype_info des3-cbc-sha1 KRBTEST.COMpreauthuser']) - test_etinfo('preauthuser', 'rc4 aes256-cts', -diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py -index 4af6804f2..2c825a692 100755 ---- a/src/tests/t_keyrollover.py -+++ b/src/tests/t_keyrollover.py -@@ -2,7 +2,7 @@ from k5test import * - - rollover_krb5_conf = {'libdefaults': {'allow_weak_crypto': 'true'}} - --realm = K5Realm(krbtgt_keysalt='des-cbc-crc:normal', -+realm = K5Realm(krbtgt_keysalt='aes128-cts-hmac-sha256-128:normal', - krb5_conf=rollover_krb5_conf) - - princ1 = 'host/test1@%s' % (realm.realm,) -@@ -22,9 +22,9 @@ realm.run([kvno, princ1]) - realm.run([kadminl, 'purgekeys', realm.krbtgt_princ]) - # Make sure an old TGT fails after purging old TGS key. - realm.run([kvno, princ2], expected_code=1) --ddes = "DEPRECATED:des-cbc-crc" -+et = "aes128-cts-hmac-sha256-128" - msg = 'krbtgt/%s@%s\n\tEtype (skey, tkt): %s, %s' % \ -- (realm.realm, realm.realm, ddes, ddes) -+ (realm.realm, realm.realm, et, et) - realm.run([klist, '-e'], expected_msg=msg) - - # Check that new key actually works. -diff --git a/src/tests/t_salt.py b/src/tests/t_salt.py -index 008efcb03..65084bbf3 100755 ---- a/src/tests/t_salt.py -+++ b/src/tests/t_salt.py -@@ -22,7 +22,7 @@ salts = [('des3-cbc-sha1', 'norealm'), - # These enctypes are chosen to cover the different string-to-key routines. - # Omit ":normal" from aes256 to check that salttype defaulting works. - second_kstypes = ['aes256-cts-hmac-sha1-96', 'arcfour-hmac:normal', -- 'des3-cbc-sha1:normal', 'des-cbc-crc:normal'] -+ 'des3-cbc-sha1:normal'] - - # Test using different salt types in a principal's key list. - # Parameters from one key in the list must not leak over to later ones. -diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py -index da02f224a..621b27156 100755 ---- a/src/tests/t_sesskeynego.py -+++ b/src/tests/t_sesskeynego.py -@@ -23,13 +23,7 @@ conf2 = {'libdefaults': {'default_tgs_enctypes': 'aes256-cts,aes128-cts'}} - conf3 = {'libdefaults': { - 'allow_weak_crypto': 'true', - 'default_tkt_enctypes': 'aes128-cts', -- 'default_tgs_enctypes': 'rc4-hmac,aes128-cts,des-cbc-crc'}} --conf4 = {'libdefaults': { -- 'allow_weak_crypto': 'true', -- 'default_tkt_enctypes': 'aes256-cts', -- 'default_tgs_enctypes': 'des-cbc-crc,rc4-hmac,aes256-cts'}, -- 'realms': {'$realm': {'des_crc_session_supported': 'false'}}} -- -+ 'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}} - # Test with client request and session_enctypes preferring aes128, but - # aes256 long-term key. - realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False) -@@ -63,16 +57,6 @@ test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96') - realm.run([kadminl, 'setstr', 'server', 'session_enctypes', - 'rc4-hmac,aes128-cts,aes256-cts']) - test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') -- --# 3c: Test des-cbc-crc default assumption. --realm.run([kadminl, 'delstr', 'server', 'session_enctypes']) --test_kvno(realm, 'DEPRECATED:des-cbc-crc', 'aes256-cts-hmac-sha1-96') --realm.stop() -- --# Last go: test that we can disable the des-cbc-crc assumption --realm = K5Realm(krb5_conf=conf4, get_creds=False) --realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server']) --test_kvno(realm, 'aes256-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96') - realm.stop() - - success('sesskeynego') -diff --git a/src/util/k5test.py b/src/util/k5test.py -index b6d93f1d8..da2782e15 100644 ---- a/src/util/k5test.py -+++ b/src/util/k5test.py -@@ -1307,7 +1307,7 @@ _passes = [ - 'master_key_type': 'aes256-sha2'}}}), - - # Test a setup with modern principal keys but an old TGT key. -- ('aes256.destgt', 'des-cbc-crc:normal', -+ ('aes256.destgt', 'arcfour-hmac:normal', - {'libdefaults': {'allow_weak_crypto': 'true'}}, - None) - ] diff --git a/Use-backported-version-of-OpenSSL-3-KDF-interface.patch b/Use-backported-version-of-OpenSSL-3-KDF-interface.patch index 28bd9f9..d0f57c8 100644 --- a/Use-backported-version-of-OpenSSL-3-KDF-interface.patch +++ b/Use-backported-version-of-OpenSSL-3-KDF-interface.patch @@ -1,19 +1,19 @@ -From bdb78f9d3fbf9abccec9b41709bb0131e9ec28d6 Mon Sep 17 00:00:00 2001 +From 9d887898571744f5ea0a523c7fba9d86d9cf8588 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 15 Nov 2019 20:05:16 +0000 Subject: [PATCH] Use backported version of OpenSSL-3 KDF interface --- - src/configure.in | 4 + + src/configure.ac | 4 + src/lib/crypto/krb/derive.c | 356 +++++++++++++----- .../preauth/pkinit/pkinit_crypto_openssl.c | 257 ++++++++----- 3 files changed, 428 insertions(+), 189 deletions(-) -diff --git a/src/configure.in b/src/configure.in -index 1df6f18fc..3bd5e683d 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -269,6 +269,10 @@ AC_SUBST(CRYPTO_IMPL) +diff --git a/src/configure.ac b/src/configure.ac +index d4e4da525..29be532cb 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -282,6 +282,10 @@ AC_SUBST(CRYPTO_IMPL) AC_SUBST(CRYPTO_IMPL_CFLAGS) AC_SUBST(CRYPTO_IMPL_LIBS) diff --git a/Use-imported-soft-pkcs11-for-tests.patch b/Use-imported-soft-pkcs11-for-tests.patch deleted file mode 100644 index 96dd953..0000000 --- a/Use-imported-soft-pkcs11-for-tests.patch +++ /dev/null @@ -1,471 +0,0 @@ -From 923cafe924fa08c1b35ca11d5473a255d629592d Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 20 Jun 2019 13:41:57 -0400 -Subject: [PATCH] Use imported soft-pkcs11 for tests - -Update the soft-pkcs11 code for OpenSSL 1.1, fix some warnings, -integrate it into the build system, and use it for the PKINIT tests. - -(cherry picked from commit e5ef7b69765353ea62ad8712a229ed4e90a8fe17) ---- - src/configure.in | 1 + - src/tests/Makefile.in | 2 +- - src/tests/softpkcs11/Makefile.in | 21 ++++ - src/tests/softpkcs11/deps | 6 ++ - src/tests/softpkcs11/main.c | 124 +++++++++++++++++------- - src/tests/softpkcs11/softpkcs11.exports | 39 ++++++++ - src/tests/t_pkinit.py | 18 +--- - 7 files changed, 162 insertions(+), 49 deletions(-) - create mode 100644 src/tests/softpkcs11/Makefile.in - create mode 100644 src/tests/softpkcs11/deps - create mode 100644 src/tests/softpkcs11/softpkcs11.exports - -diff --git a/src/configure.in b/src/configure.in -index 3e3b95e49..1df6f18fc 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -1086,6 +1086,7 @@ int i = 1; - fi - if test "$k5_cv_openssl_version_okay" = yes && (test "$enable_pkinit" = yes || test "$enable_pkinit" = try); then - K5_GEN_MAKEFILE(plugins/preauth/pkinit) -+ K5_GEN_MAKEFILE(tests/softpkcs11) - PKINIT=yes - AC_CHECK_LIB(crypto, CMS_get0_content, [AC_DEFINE([HAVE_OPENSSL_CMS], 1, [Define if OpenSSL supports cms.])]) - elif test "$k5_cv_openssl_version_okay" = no && test "$enable_pkinit" = yes; then -diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in -index d2a37c616..8fa44fb59 100644 ---- a/src/tests/Makefile.in -+++ b/src/tests/Makefile.in -@@ -1,7 +1,7 @@ - mydir=tests - BUILDTOP=$(REL).. - SUBDIRS = resolve asn.1 create hammer verify gssapi dejagnu shlib \ -- gss-threads misc threads -+ gss-threads misc threads softpkcs11 - - RUN_DB_TEST = $(RUN_SETUP) KRB5_KDC_PROFILE=kdc.conf KRB5_CONFIG=krb5.conf \ - LC_ALL=C $(VALGRIND) -diff --git a/src/tests/softpkcs11/Makefile.in b/src/tests/softpkcs11/Makefile.in -new file mode 100644 -index 000000000..e89678154 ---- /dev/null -+++ b/src/tests/softpkcs11/Makefile.in -@@ -0,0 +1,21 @@ -+mydir=tests$(S)softpkcs11 -+BUILDTOP=$(REL)..$(S).. -+ -+LOCALINCLUDES = -I$(top_srcdir)/plugins/preauth/pkinit -+ -+LIBBASE=softpkcs11 -+LIBMAJOR=0 -+LIBMINOR=0 -+ -+SHLIB_EXPLIBS=$(SUPPORT_LIB) -lcrypto -+SHLIB_EXPDEPS=$(SUPPORT_DEPLIB) -+ -+STLIBOBJS=main.o -+ -+SRCS=$(srcdir)/main.c -+ -+all-unix: all-libs -+clean-unix:: clean-libs clean-libobjs -+ -+@libnover_frag@ -+@libobj_frag@ -diff --git a/src/tests/softpkcs11/deps b/src/tests/softpkcs11/deps -new file mode 100644 -index 000000000..1e82d9572 ---- /dev/null -+++ b/src/tests/softpkcs11/deps -@@ -0,0 +1,6 @@ -+# -+# Generated makefile dependencies follow. -+# -+main.so main.po $(OUTPRE)main.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -+ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-thread.h \ -+ $(top_srcdir)/plugins/preauth/pkinit/pkcs11.h main.c -diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c -index 2acec5169..5255323d3 100644 ---- a/src/tests/softpkcs11/main.c -+++ b/src/tests/softpkcs11/main.c -@@ -1,3 +1,4 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ - /* - * Copyright (c) 2004-2006, Stockholms universitet - * (Stockholm University, Stockholm Sweden) -@@ -31,7 +32,57 @@ - * POSSIBILITY OF SUCH DAMAGE. - */ - --#include "locl.h" -+#include "k5-platform.h" -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+ -+#include -+ -+#if OPENSSL_VERSION_NUMBER < 0x10100000L -+#define EVP_PKEY_get0_RSA(key) ((key)->pkey.rsa) -+#define RSA_PKCS1_OpenSSL RSA_PKCS1_SSLeay -+#define RSA_get0_key compat_rsa_get0_key -+static void -+compat_rsa_get0_key(const RSA *rsa, const BIGNUM **n, const BIGNUM **e, -+ const BIGNUM **d) -+{ -+ if (n != NULL) -+ *n = rsa->n; -+ if (e != NULL) -+ *e = rsa->e; -+ if (d != NULL) -+ *d = rsa->d; -+} -+#endif -+ -+#define OPENSSL_ASN1_MALLOC_ENCODE(T, B, BL, S, R) \ -+ { \ -+ unsigned char *p; \ -+ (BL) = i2d_##T((S), NULL); \ -+ if ((BL) <= 0) { \ -+ (R) = EINVAL; \ -+ } else { \ -+ (B) = malloc((BL)); \ -+ if ((B) == NULL) { \ -+ (R) = ENOMEM; \ -+ } else { \ -+ p = (B); \ -+ (R) = 0; \ -+ (BL) = i2d_##T((S), &p); \ -+ if ((BL) <= 0) { \ -+ free((B)); \ -+ (R) = EINVAL; \ -+ } \ -+ } \ -+ } \ -+ } - - /* RCSID("$Id: main.c,v 1.24 2006/01/11 12:42:53 lha Exp $"); */ - -@@ -124,7 +175,7 @@ st_logf(const char *fmt, ...) - } - - static void --snprintf_fill(char *str, size_t size, char fillchar, const char *fmt, ...) -+snprintf_fill(char *str, int size, char fillchar, const char *fmt, ...) - { - int len; - va_list ap; -@@ -141,19 +192,19 @@ snprintf_fill(char *str, size_t size, char fillchar, const char *fmt, ...) - #endif - - #define VERIFY_SESSION_HANDLE(s, state) \ --{ \ -- CK_RV ret; \ -- ret = verify_session_handle(s, state); \ -- if (ret != CKR_OK) { \ -- /* return CKR_OK */; \ -- } \ --} -+ { \ -+ CK_RV vshret; \ -+ vshret = verify_session_handle(s, state); \ -+ if (vshret != CKR_OK) { \ -+ /* return CKR_OK */; \ -+ } \ -+ } - - static CK_RV - verify_session_handle(CK_SESSION_HANDLE hSession, - struct session_state **state) - { -- int i; -+ size_t i; - - for (i = 0; i < MAX_NUM_SESSION; i++){ - if (soft_token.state[i].session_handle == hSession) -@@ -361,16 +412,20 @@ add_pubkey_info(struct st_object *o, CK_KEY_TYPE key_type, EVP_PKEY *key) - CK_ULONG modulus_bits = 0; - CK_BYTE *exponent = NULL; - size_t exponent_len = 0; -+ RSA *rsa; -+ const BIGNUM *n, *e; - -- modulus_bits = BN_num_bits(key->pkey.rsa->n); -+ rsa = EVP_PKEY_get0_RSA(key); -+ RSA_get0_key(rsa, &n, &e, NULL); -+ modulus_bits = BN_num_bits(n); - -- modulus_len = BN_num_bytes(key->pkey.rsa->n); -+ modulus_len = BN_num_bytes(n); - modulus = malloc(modulus_len); -- BN_bn2bin(key->pkey.rsa->n, modulus); -+ BN_bn2bin(n, modulus); - -- exponent_len = BN_num_bytes(key->pkey.rsa->e); -+ exponent_len = BN_num_bytes(e); - exponent = malloc(exponent_len); -- BN_bn2bin(key->pkey.rsa->e, exponent); -+ BN_bn2bin(e, exponent); - - add_object_attribute(o, 0, CKA_MODULUS, modulus, modulus_len); - add_object_attribute(o, 0, CKA_MODULUS_BITS, -@@ -378,7 +433,7 @@ add_pubkey_info(struct st_object *o, CK_KEY_TYPE key_type, EVP_PKEY *key) - add_object_attribute(o, 0, CKA_PUBLIC_EXPONENT, - exponent, exponent_len); - -- RSA_set_method(key->pkey.rsa, RSA_PKCS1_SSLeay()); -+ RSA_set_method(rsa, RSA_PKCS1_OpenSSL()); - - free(modulus); - free(exponent); -@@ -474,7 +529,7 @@ add_certificate(char *label, - o->u.cert = cert; - public_key = X509_get_pubkey(o->u.cert); - -- switch (EVP_PKEY_type(public_key->type)) { -+ switch (EVP_PKEY_base_id(public_key)) { - case EVP_PKEY_RSA: - key_type = CKK_RSA; - break; -@@ -604,8 +659,8 @@ add_certificate(char *label, - /* XXX verify keytype */ - - if (key_type == CKK_RSA) -- RSA_set_method(o->u.private_key.key->pkey.rsa, -- RSA_PKCS1_SSLeay()); -+ RSA_set_method(EVP_PKEY_get0_RSA(o->u.private_key.key), -+ RSA_PKCS1_OpenSSL()); - - if (X509_check_private_key(cert, o->u.private_key.key) != 1) { - EVP_PKEY_free(o->u.private_key.key); -@@ -755,8 +810,9 @@ CK_RV - C_Initialize(CK_VOID_PTR a) - { - CK_C_INITIALIZE_ARGS_PTR args = a; -+ size_t i; -+ - st_logf("Initialize\n"); -- int i; - - OpenSSL_add_all_algorithms(); - ERR_load_crypto_strings(); -@@ -825,7 +881,7 @@ C_Initialize(CK_VOID_PTR a) - CK_RV - C_Finalize(CK_VOID_PTR args) - { -- int i; -+ size_t i; - - st_logf("Finalize\n"); - -@@ -1008,7 +1064,7 @@ C_OpenSession(CK_SLOT_ID slotID, - CK_NOTIFY Notify, - CK_SESSION_HANDLE_PTR phSession) - { -- int i; -+ size_t i; - - st_logf("OpenSession: slot: %d\n", (int)slotID); - -@@ -1050,7 +1106,7 @@ C_CloseSession(CK_SESSION_HANDLE hSession) - CK_RV - C_CloseAllSessions(CK_SLOT_ID slotID) - { -- int i; -+ size_t i; - - st_logf("CloseAllSessions\n"); - -@@ -1127,7 +1183,8 @@ C_Login(CK_SESSION_HANDLE hSession, - } - - /* XXX check keytype */ -- RSA_set_method(o->u.private_key.key->pkey.rsa, RSA_PKCS1_SSLeay()); -+ RSA_set_method(EVP_PKEY_get0_RSA(o->u.private_key.key), -+ RSA_PKCS1_OpenSSL()); - - if (X509_check_private_key(o->u.private_key.cert, o->u.private_key.key) != 1) { - EVP_PKEY_free(o->u.private_key.key); -@@ -1226,7 +1283,6 @@ C_FindObjectsInit(CK_SESSION_HANDLE hSession, - } - if (ulCount) { - CK_ULONG i; -- size_t len; - - print_attributes(pTemplate, ulCount); - -@@ -1415,7 +1471,7 @@ C_Encrypt(CK_SESSION_HANDLE hSession, - return CKR_ARGUMENTS_BAD; - } - -- rsa = o->u.public_key->pkey.rsa; -+ rsa = EVP_PKEY_get0_RSA(o->u.public_key); - - if (rsa == NULL) - return CKR_ARGUMENTS_BAD; -@@ -1445,7 +1501,7 @@ C_Encrypt(CK_SESSION_HANDLE hSession, - goto out; - } - -- if (buffer_len + padding_len < ulDataLen) { -+ if ((CK_ULONG)buffer_len + padding_len < ulDataLen) { - ret = CKR_ARGUMENTS_BAD; - goto out; - } -@@ -1566,7 +1622,7 @@ C_Decrypt(CK_SESSION_HANDLE hSession, - return CKR_ARGUMENTS_BAD; - } - -- rsa = o->u.private_key.key->pkey.rsa; -+ rsa = EVP_PKEY_get0_RSA(o->u.private_key.key); - - if (rsa == NULL) - return CKR_ARGUMENTS_BAD; -@@ -1596,7 +1652,7 @@ C_Decrypt(CK_SESSION_HANDLE hSession, - goto out; - } - -- if (buffer_len + padding_len < ulEncryptedDataLen) { -+ if ((CK_ULONG)buffer_len + padding_len < ulEncryptedDataLen) { - ret = CKR_ARGUMENTS_BAD; - goto out; - } -@@ -1725,7 +1781,7 @@ C_Sign(CK_SESSION_HANDLE hSession, - return CKR_ARGUMENTS_BAD; - } - -- rsa = o->u.private_key.key->pkey.rsa; -+ rsa = EVP_PKEY_get0_RSA(o->u.private_key.key); - - if (rsa == NULL) - return CKR_ARGUMENTS_BAD; -@@ -1754,7 +1810,7 @@ C_Sign(CK_SESSION_HANDLE hSession, - goto out; - } - -- if (buffer_len < ulDataLen + padding_len) { -+ if ((CK_ULONG)buffer_len < ulDataLen + padding_len) { - ret = CKR_ARGUMENTS_BAD; - goto out; - } -@@ -1872,7 +1928,7 @@ C_Verify(CK_SESSION_HANDLE hSession, - return CKR_ARGUMENTS_BAD; - } - -- rsa = o->u.public_key->pkey.rsa; -+ rsa = EVP_PKEY_get0_RSA(o->u.public_key); - - if (rsa == NULL) - return CKR_ARGUMENTS_BAD; -@@ -1900,7 +1956,7 @@ C_Verify(CK_SESSION_HANDLE hSession, - goto out; - } - -- if (buffer_len < ulDataLen) { -+ if ((CK_ULONG)buffer_len < ulDataLen) { - ret = CKR_ARGUMENTS_BAD; - goto out; - } -@@ -1926,7 +1982,7 @@ C_Verify(CK_SESSION_HANDLE hSession, - if (len > buffer_len) - abort(); - -- if (len != ulSignatureLen) { -+ if ((CK_ULONG)len != ulSignatureLen) { - ret = CKR_GENERAL_ERROR; - goto out; - } -diff --git a/src/tests/softpkcs11/softpkcs11.exports b/src/tests/softpkcs11/softpkcs11.exports -new file mode 100644 -index 000000000..aa7284511 ---- /dev/null -+++ b/src/tests/softpkcs11/softpkcs11.exports -@@ -0,0 +1,39 @@ -+C_CloseAllSessions -+C_CloseSession -+C_Decrypt -+C_DecryptFinal -+C_DecryptInit -+C_DecryptUpdate -+C_DigestInit -+C_Encrypt -+C_EncryptFinal -+C_EncryptInit -+C_EncryptUpdate -+C_Finalize -+C_FindObjects -+C_FindObjectsFinal -+C_FindObjectsInit -+C_GenerateRandom -+C_GetAttributeValue -+C_GetFunctionList -+C_GetInfo -+C_GetMechanismInfo -+C_GetMechanismList -+C_GetObjectSize -+C_GetSessionInfo -+C_GetSlotInfo -+C_GetSlotList -+C_GetTokenInfo -+C_Initialize -+C_InitToken -+C_Login -+C_Logout -+C_OpenSession -+C_Sign -+C_SignFinal -+C_SignInit -+C_SignUpdate -+C_Verify -+C_VerifyFinal -+C_VerifyInit -+C_VerifyUpdate -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index 93f0f2632..69daf4987 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -4,14 +4,7 @@ from k5test import * - if not os.path.exists(os.path.join(plugins, 'preauth', 'pkinit.so')): - skip_rest('PKINIT tests', 'PKINIT module not built') - --# Check if soft-pkcs11.so is available. --try: -- import ctypes -- lib = ctypes.LibraryLoader(ctypes.CDLL).LoadLibrary('soft-pkcs11.so') -- del lib -- have_soft_pkcs11 = True --except: -- have_soft_pkcs11 = False -+soft_pkcs11 = os.path.join(buildtop, 'tests', 'softpkcs11', 'softpkcs11.so') - - # Construct a krb5.conf fragment configuring pkinit. - certs = os.path.join(srctop, 'tests', 'dejagnu', 'pkinit-certs') -@@ -69,9 +62,9 @@ p12_upn2_identity = 'PKCS12:%s' % user_upn2_p12 - p12_upn3_identity = 'PKCS12:%s' % user_upn3_p12 - p12_generic_identity = 'PKCS12:%s' % generic_p12 - p12_enc_identity = 'PKCS12:%s' % user_enc_p12 --p11_identity = 'PKCS11:soft-pkcs11.so' --p11_token_identity = ('PKCS11:module_name=soft-pkcs11.so:' -- 'slotid=1:token=SoftToken (token)') -+p11_identity = 'PKCS11:' + soft_pkcs11 -+p11_token_identity = ('PKCS11:module_name=' + soft_pkcs11 + -+ ':slotid=1:token=SoftToken (token)') - - # Start a realm with the test kdb module for the following UPN SAN tests. - realm = K5Realm(krb5_conf=pkinit_krb5_conf, kdc_conf=alias_kdc_conf, -@@ -398,9 +391,6 @@ realm.klist(realm.user_princ) - realm.kinit(realm.user_princ, flags=['-X', 'X509_user_identity=,'], - expected_code=1, expected_msg='Preauthentication failed while') - --if not have_soft_pkcs11: -- skip_rest('PKINIT PKCS11 tests', 'soft-pkcs11.so not found') -- - softpkcs11rc = os.path.join(os.getcwd(), 'testdir', 'soft-pkcs11.rc') - realm.env['SOFTPKCS11RC'] = softpkcs11rc - diff --git a/Use-secure_getenv-where-appropriate.patch b/Use-secure_getenv-where-appropriate.patch deleted file mode 100644 index d8f5832..0000000 --- a/Use-secure_getenv-where-appropriate.patch +++ /dev/null @@ -1,240 +0,0 @@ -From a41dc78bd3a879870eece3bf0a7c66196c90e7e8 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 24 Apr 2019 16:19:50 -0400 -Subject: [PATCH] Use secure_getenv() where appropriate - -ticket: 8800 -(cherry picked from commit d439e370b70f7af4ed2da9c692a3be7dcf7b4ac6) ---- - src/lib/kadm5/alt_prof.c | 2 +- - src/lib/krb5/ccache/ccselect_k5identity.c | 2 +- - src/lib/krb5/os/ccdefname.c | 2 +- - src/lib/krb5/os/expand_path.c | 2 +- - src/lib/krb5/os/init_os_ctx.c | 6 +++--- - src/lib/krb5/os/ktdefname.c | 4 ++-- - src/lib/krb5/os/trace.c | 2 +- - src/lib/krb5/rcache/rc_base.c | 4 ++-- - src/lib/krb5/rcache/rc_io.c | 4 ++-- - src/plugins/preauth/pkinit/pkinit_identity.c | 13 ++++--------- - src/plugins/tls/k5tls/openssl.c | 2 +- - src/util/profile/prof_file.c | 2 +- - 12 files changed, 20 insertions(+), 25 deletions(-) - -diff --git a/src/lib/kadm5/alt_prof.c b/src/lib/kadm5/alt_prof.c -index 3f6b53651..5531a10fb 100644 ---- a/src/lib/kadm5/alt_prof.c -+++ b/src/lib/kadm5/alt_prof.c -@@ -73,7 +73,7 @@ krb5_aprof_init(char *fname, char *envname, krb5_pointer *acontextp) - ret = krb5_get_default_config_files(&filenames); - if (ret) - return ret; -- if (envname == NULL || (kdc_config = getenv(envname)) == NULL) -+ if (envname == NULL || (kdc_config = secure_getenv(envname)) == NULL) - kdc_config = fname; - k5_buf_init_dynamic(&buf); - if (kdc_config) -diff --git a/src/lib/krb5/ccache/ccselect_k5identity.c b/src/lib/krb5/ccache/ccselect_k5identity.c -index bee541658..b2dbf8a09 100644 ---- a/src/lib/krb5/ccache/ccselect_k5identity.c -+++ b/src/lib/krb5/ccache/ccselect_k5identity.c -@@ -135,7 +135,7 @@ get_homedir(krb5_context context) - struct passwd pwx, *pwd; - - if (!context->profile_secure) -- homedir = getenv("HOME"); -+ homedir = secure_getenv("HOME"); - - if (homedir == NULL) { - if (k5_getpwuid_r(geteuid(), &pwx, pwbuf, sizeof(pwbuf), &pwd) != 0) -diff --git a/src/lib/krb5/os/ccdefname.c b/src/lib/krb5/os/ccdefname.c -index e5cb3e44c..233173d35 100644 ---- a/src/lib/krb5/os/ccdefname.c -+++ b/src/lib/krb5/os/ccdefname.c -@@ -300,7 +300,7 @@ krb5_cc_default_name(krb5_context context) - return os_ctx->default_ccname; - - /* Try the environment variable first. */ -- envstr = getenv(KRB5_ENV_CCNAME); -+ envstr = secure_getenv(KRB5_ENV_CCNAME); - if (envstr != NULL) { - os_ctx->default_ccname = strdup(envstr); - return os_ctx->default_ccname; -diff --git a/src/lib/krb5/os/expand_path.c b/src/lib/krb5/os/expand_path.c -index 61fb23459..4ce466c19 100644 ---- a/src/lib/krb5/os/expand_path.c -+++ b/src/lib/krb5/os/expand_path.c -@@ -280,7 +280,7 @@ expand_temp_folder(krb5_context context, PTYPE param, const char *postfix, - const char *p = NULL; - - if (context == NULL || !context->profile_secure) -- p = getenv("TMPDIR"); -+ p = secure_getenv("TMPDIR"); - *ret = strdup((p != NULL) ? p : "/tmp"); - if (*ret == NULL) - return ENOMEM; -diff --git a/src/lib/krb5/os/init_os_ctx.c b/src/lib/krb5/os/init_os_ctx.c -index 09809b932..3aa86f4ad 100644 ---- a/src/lib/krb5/os/init_os_ctx.c -+++ b/src/lib/krb5/os/init_os_ctx.c -@@ -243,7 +243,7 @@ os_get_default_config_files(profile_filespec_t **pfiles, krb5_boolean secure) - char *name = 0; - - if (!secure) { -- char *env = getenv("KRB5_CONFIG"); -+ char *env = secure_getenv("KRB5_CONFIG"); - if (env) { - name = strdup(env); - if (!name) return ENOMEM; -@@ -298,7 +298,7 @@ os_get_default_config_files(profile_filespec_t **pfiles, krb5_boolean secure) - if (secure) { - filepath = DEFAULT_SECURE_PROFILE_PATH; - } else { -- filepath = getenv("KRB5_CONFIG"); -+ filepath = secure_getenv("KRB5_CONFIG"); - if (!filepath) filepath = DEFAULT_PROFILE_PATH; - } - -@@ -344,7 +344,7 @@ add_kdc_config_file(profile_filespec_t **pfiles) - size_t count = 0; - profile_filespec_t *newfiles; - -- file = getenv(KDC_PROFILE_ENV); -+ file = secure_getenv(KDC_PROFILE_ENV); - if (file == NULL) - file = DEFAULT_KDC_PROFILE; - -diff --git a/src/lib/krb5/os/ktdefname.c b/src/lib/krb5/os/ktdefname.c -index ffbd14d51..fbe4e98b4 100644 ---- a/src/lib/krb5/os/ktdefname.c -+++ b/src/lib/krb5/os/ktdefname.c -@@ -42,7 +42,7 @@ kt_default_name(krb5_context context, char **name_out) - *name_out = strdup(krb5_overridekeyname); - return (*name_out == NULL) ? ENOMEM : 0; - } else if (context->profile_secure == FALSE && -- (str = getenv("KRB5_KTNAME")) != NULL) { -+ (str = secure_getenv("KRB5_KTNAME")) != NULL) { - *name_out = strdup(str); - return (*name_out == NULL) ? ENOMEM : 0; - } else if (profile_get_string(context->profile, KRB5_CONF_LIBDEFAULTS, -@@ -63,7 +63,7 @@ k5_kt_client_default_name(krb5_context context, char **name_out) - char *str; - - if (context->profile_secure == FALSE && -- (str = getenv("KRB5_CLIENT_KTNAME")) != NULL) { -+ (str = secure_getenv("KRB5_CLIENT_KTNAME")) != NULL) { - *name_out = strdup(str); - return (*name_out == NULL) ? ENOMEM : 0; - } else if (profile_get_string(context->profile, KRB5_CONF_LIBDEFAULTS, -diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c -index 40a9e7b10..85dbfeb47 100644 ---- a/src/lib/krb5/os/trace.c -+++ b/src/lib/krb5/os/trace.c -@@ -389,7 +389,7 @@ k5_init_trace(krb5_context context) - { - const char *filename; - -- filename = getenv("KRB5_TRACE"); -+ filename = secure_getenv("KRB5_TRACE"); - if (filename) - (void) krb5_set_trace_filename(context, filename); - } -diff --git a/src/lib/krb5/rcache/rc_base.c b/src/lib/krb5/rcache/rc_base.c -index 373ac3046..9fa46432d 100644 ---- a/src/lib/krb5/rcache/rc_base.c -+++ b/src/lib/krb5/rcache/rc_base.c -@@ -107,7 +107,7 @@ char * - krb5_rc_default_type(krb5_context context) - { - char *s; -- if ((s = getenv("KRB5RCACHETYPE"))) -+ if ((s = secure_getenv("KRB5RCACHETYPE"))) - return s; - else - return "dfl"; -@@ -117,7 +117,7 @@ char * - krb5_rc_default_name(krb5_context context) - { - char *s; -- if ((s = getenv("KRB5RCACHENAME"))) -+ if ((s = secure_getenv("KRB5RCACHENAME"))) - return s; - else - return (char *) 0; -diff --git a/src/lib/krb5/rcache/rc_io.c b/src/lib/krb5/rcache/rc_io.c -index 35fa14a1f..1800460b2 100644 ---- a/src/lib/krb5/rcache/rc_io.c -+++ b/src/lib/krb5/rcache/rc_io.c -@@ -48,13 +48,13 @@ getdir(void) - { - char *dir; - -- if (!(dir = getenv("KRB5RCACHEDIR"))) { -+ if (!(dir = secure_getenv("KRB5RCACHEDIR"))) { - #if defined(_WIN32) - if (!(dir = getenv("TEMP"))) - if (!(dir = getenv("TMP"))) - dir = "C:"; - #else -- if (!(dir = getenv("TMPDIR"))) { -+ if (!(dir = secure_getenv("TMPDIR"))) { - #ifdef RCTMPDIR - dir = RCTMPDIR; - #else -diff --git a/src/plugins/preauth/pkinit/pkinit_identity.c b/src/plugins/preauth/pkinit/pkinit_identity.c -index 8cd3fc640..b89c5d015 100644 ---- a/src/plugins/preauth/pkinit/pkinit_identity.c -+++ b/src/plugins/preauth/pkinit/pkinit_identity.c -@@ -29,15 +29,9 @@ - * SUCH DAMAGES. - */ - --#include --#include --#include --#include --#include --#include --#include -- - #include "pkinit.h" -+#include -+#include - - static void - free_list(char **list) -@@ -430,7 +424,8 @@ process_option_identity(krb5_context context, - switch (idtype) { - case IDTYPE_ENVVAR: - return process_option_identity(context, plg_cryptoctx, req_cryptoctx, -- idopts, id_cryptoctx, getenv(residual)); -+ idopts, id_cryptoctx, -+ secure_getenv(residual)); - break; - case IDTYPE_FILE: - retval = parse_fs_options(context, idopts, residual); -diff --git a/src/plugins/tls/k5tls/openssl.c b/src/plugins/tls/k5tls/openssl.c -index 822632c90..76a43b3cd 100644 ---- a/src/plugins/tls/k5tls/openssl.c -+++ b/src/plugins/tls/k5tls/openssl.c -@@ -399,7 +399,7 @@ load_anchor(SSL_CTX *ctx, const char *location) - } else if (strncmp(location, "DIR:", 4) == 0) { - return load_anchor_dir(store, location + 4); - } else if (strncmp(location, "ENV:", 4) == 0) { -- envloc = getenv(location + 4); -+ envloc = secure_getenv(location + 4); - if (envloc == NULL) - return ENOENT; - return load_anchor(ctx, envloc); -diff --git a/src/util/profile/prof_file.c b/src/util/profile/prof_file.c -index 0dcb6b543..79f9500f6 100644 ---- a/src/util/profile/prof_file.c -+++ b/src/util/profile/prof_file.c -@@ -183,7 +183,7 @@ errcode_t profile_open_file(const_profile_filespec_t filespec, - prf->magic = PROF_MAGIC_FILE; - - if (filespec[0] == '~' && filespec[1] == '/') { -- home_env = getenv("HOME"); -+ home_env = secure_getenv("HOME"); - #ifdef HAVE_PWD_H - if (home_env == NULL) { - uid_t uid; diff --git a/krb5-1.15-beta1-buildconf.patch b/krb5-1.15-beta1-buildconf.patch index e074e10..5ad5500 100644 --- a/krb5-1.15-beta1-buildconf.patch +++ b/krb5-1.15-beta1-buildconf.patch @@ -1,4 +1,4 @@ -From ab2b67102127e448cc1a266fbbe2c738a1a3a158 Mon Sep 17 00:00:00 2001 +From e07920163e88a538e73b4d72db26b74c951b8256 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] krb5-1.15-beta1-buildconf.patch diff --git a/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index 89b9e2f..58a7118 100644 --- a/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From c874aa2c7ec16203c0be91e9e789b21221689de2 Mon Sep 17 00:00:00 2001 +From ad14cab8d35e6c7edee196708ce5b5516b9bb1f8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] krb5-1.17post6 FIPS with PRNG and RADIUS and MD4 @@ -541,7 +541,7 @@ index 00734a13b..a3ce22b70 100644 vt->name = "spake"; vt->pa_type_list = pa_types; diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c -index 59e88409e..1b3e569e9 100644 +index 88c964ce1..c7df0392f 100644 --- a/src/plugins/preauth/spake/spake_kdc.c +++ b/src/plugins/preauth/spake/spake_kdc.c @@ -41,6 +41,8 @@ @@ -553,7 +553,7 @@ index 59e88409e..1b3e569e9 100644 /* * The SPAKE kdcpreauth module uses a secure cookie containing the following * concatenated fields (all integer fields are big-endian): -@@ -578,6 +580,10 @@ kdcpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, +@@ -571,6 +573,10 @@ kdcpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, if (maj_ver != 1) return KRB5_PLUGIN_VER_NOTSUPP; diff --git a/Remove-3des-support.patch b/krb5-1.18-beta1-Remove-3des-support.patch similarity index 99% rename from Remove-3des-support.patch rename to krb5-1.18-beta1-Remove-3des-support.patch index dd68008..1b88923 100644 --- a/Remove-3des-support.patch +++ b/krb5-1.18-beta1-Remove-3des-support.patch @@ -1,25 +1,22 @@ -From 98db8d2582b72fb75023c43c5bee435be960247f Mon Sep 17 00:00:00 2001 +From d042a0d6ea28c70e87ae342255a0af2bab631ec1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 -Subject: [PATCH] Remove 3des support +Subject: [PATCH] krb5-1.18-beta1-Remove-3des-support Completely remove support for all DES3 enctypes (des3-cbc-raw, des3-hmac-sha1, des3-cbc-sha1-kd). Update all tests and documentation to user other enctypes. Mark the 3DES enctypes UNSUPPORTED and retain their constants. - -(cherry picked from commit 57a8a84e035000b515ca9efd56e5cbe1568b95e7) -[rharwood@redhat.com: supported enctypes docs landed first] --- doc/admin/advanced/retiring-des.rst | 11 + doc/admin/conf_files/kdc_conf.rst | 7 +- doc/admin/enctypes.rst | 13 +- doc/admin/troubleshoot.rst | 9 +- doc/appdev/refs/macros/index.rst | 1 - - doc/conf.py | 4 +- + doc/conf.py | 2 +- doc/mitK5features.rst | 2 +- src/Makefile.in | 4 +- - src/configure.in | 1 - + src/configure.ac | 1 - src/include/krb5/krb5.hin | 10 +- src/kadmin/testing/proto/kdc.conf.proto | 4 +- src/kdc/kdc_util.c | 4 - @@ -107,7 +104,7 @@ their constants. src/tests/t_salt.py | 5 +- src/util/k5test.py | 10 - .../leash/htmlhelp/html/Encryption_Types.htm | 13 - - 96 files changed, 164 insertions(+), 4838 deletions(-) + 96 files changed, 163 insertions(+), 4837 deletions(-) delete mode 100644 src/lib/crypto/builtin/des/ISSUES delete mode 100644 src/lib/crypto/builtin/des/Makefile.in delete mode 100644 src/lib/crypto/builtin/des/d3_aead.c @@ -245,7 +242,7 @@ index 6a0c7f89b..263fc9c97 100644 .. _err_cert_chain_cert_expired: diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst -index 534795d15..9542611ea 100644 +index 68debe714..788d094bf 100644 --- a/doc/appdev/refs/macros/index.rst +++ b/doc/appdev/refs/macros/index.rst @@ -36,7 +36,6 @@ Public @@ -257,22 +254,20 @@ index 534795d15..9542611ea 100644 CKSUMTYPE_NIST_SHA.rst CKSUMTYPE_RSA_MD4.rst diff --git a/doc/conf.py b/doc/conf.py -index 759367c21..37eda67fa 100644 +index fc5662767..37eda67fa 100644 --- a/doc/conf.py +++ b/doc/conf.py -@@ -271,8 +271,8 @@ else: - rst_epilog += '.. |ckeytab| replace:: %s\n' % ckeytab +@@ -272,7 +272,7 @@ else: rst_epilog += ''' .. |krb5conf| replace:: ``/etc/krb5.conf`` --.. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal des3-cbc-sha1:normal arcfour-hmac-md5:normal`` + .. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal`` -.. |defetypes| replace:: ``aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha384-192 aes128-cts-hmac-sha256-128 des3-cbc-sha1 arcfour-hmac-md5 camellia256-cts-cmac camellia128-cts-cmac`` -+.. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal`` +.. |defetypes| replace:: ``aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha384-192 aes128-cts-hmac-sha256-128 arcfour-hmac-md5 camellia256-cts-cmac camellia128-cts-cmac`` .. |defmkey| replace:: ``aes256-cts-hmac-sha1-96`` .. |copy| unicode:: U+000A9 ''' diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst -index a19068e26..5bfdc3936 100644 +index d58c71898..8655e257d 100644 --- a/doc/mitK5features.rst +++ b/doc/mitK5features.rst @@ -37,7 +37,7 @@ Database backends: LDAP, DB2, LMDB @@ -285,10 +280,10 @@ index a19068e26..5bfdc3936 100644 Interoperability ---------------- diff --git a/src/Makefile.in b/src/Makefile.in -index 91a5f4bf8..0197e5b6d 100644 +index 56c7a4e6f..70db82a30 100644 --- a/src/Makefile.in +++ b/src/Makefile.in -@@ -129,7 +129,7 @@ WINMAKEFILES=Makefile \ +@@ -130,7 +130,7 @@ WINMAKEFILES=Makefile \ lib\Makefile lib\crypto\Makefile lib\crypto\krb\Makefile \ lib\crypto\builtin\Makefile lib\crypto\builtin\aes\Makefile \ lib\crypto\builtin\enc_provider\Makefile \ @@ -297,7 +292,7 @@ index 91a5f4bf8..0197e5b6d 100644 lib\crypto\builtin\camellia\Makefile lib\crypto\builtin\md4\Makefile \ lib\crypto\builtin\hash_provider\Makefile \ lib\crypto\builtin\sha2\Makefile lib\crypto\builtin\sha1\Makefile \ -@@ -201,8 +201,6 @@ WINMAKEFILES=Makefile \ +@@ -202,8 +202,6 @@ WINMAKEFILES=Makefile \ ##DOS## $(WCONFIG) config < $@.in > $@ ##DOS##lib\crypto\builtin\enc_provider\Makefile: lib\crypto\builtin\enc_provider\Makefile.in $(MKFDEP) ##DOS## $(WCONFIG) config < $@.in > $@ @@ -306,11 +301,11 @@ index 91a5f4bf8..0197e5b6d 100644 ##DOS##lib\crypto\builtin\md5\Makefile: lib\crypto\builtin\md5\Makefile.in $(MKFDEP) ##DOS## $(WCONFIG) config < $@.in > $@ ##DOS##lib\crypto\builtin\camellia\Makefile: lib\crypto\builtin\camellia\Makefile.in $(MKFDEP) -diff --git a/src/configure.in b/src/configure.in -index 9d6825b78..3e3b95e49 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -1443,7 +1443,6 @@ V5_AC_OUTPUT_MAKEFILE(. +diff --git a/src/configure.ac b/src/configure.ac +index 440a22bd9..d4e4da525 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -1481,7 +1481,6 @@ V5_AC_OUTPUT_MAKEFILE(. lib/crypto lib/crypto/krb lib/crypto/$CRYPTO_IMPL lib/crypto/$CRYPTO_IMPL/enc_provider lib/crypto/$CRYPTO_IMPL/hash_provider @@ -319,7 +314,7 @@ index 9d6825b78..3e3b95e49 100644 lib/crypto/$CRYPTO_IMPL/sha1 lib/crypto/$CRYPTO_IMPL/sha2 lib/crypto/$CRYPTO_IMPL/aes lib/crypto/$CRYPTO_IMPL/camellia diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 5f596d1fc..9a05ce32d 100644 +index d1f5661bf..26a3b6ec8 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin @@ -426,8 +426,8 @@ typedef struct _krb5_crypto_iov { @@ -368,10 +363,10 @@ index 8a4b87de1..d7f1d076b 100644 + supported_enctypes = aes256-cts:normal aes128-cts:normal aes256-sha2:normal aes128-sha2:normal } diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index df1ba6acf..23ad6c584 100644 +index d0fd5d7e1..050672840 100644 --- a/src/kdc/kdc_util.c +++ b/src/kdc/kdc_util.c -@@ -1077,8 +1077,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) +@@ -1103,8 +1103,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) name = "rsaEncryption-EnvOID"; else if (ktype == ENCTYPE_RSA_ES_OAEP_ENV) name = "id-RSAES-OAEP-EnvOID"; @@ -380,7 +375,7 @@ index df1ba6acf..23ad6c584 100644 else return krb5_enctype_to_name(ktype, FALSE, buf, buflen); -@@ -1741,8 +1739,6 @@ krb5_boolean +@@ -1839,8 +1837,6 @@ krb5_boolean enctype_requires_etype_info_2(krb5_enctype enctype) { switch(enctype) { @@ -4551,10 +4546,10 @@ index cdb1acc6d..ef4c4a7d3 100644 { ENCTYPE_AES128_CTS_HMAC_SHA1_96, diff --git a/src/lib/crypto/krb/Makefile.in b/src/lib/crypto/krb/Makefile.in -index 536bacb6e..b587f7e19 100644 +index b74e6f7cc..2b0c4163d 100644 --- a/src/lib/crypto/krb/Makefile.in +++ b/src/lib/crypto/krb/Makefile.in -@@ -52,7 +52,6 @@ STLIBOBJS=\ +@@ -50,7 +50,6 @@ STLIBOBJS=\ prf.o \ prf_aes2.o \ prf_cmac.o \ @@ -4562,7 +4557,7 @@ index 536bacb6e..b587f7e19 100644 prf_dk.o \ prf_rc4.o \ prng.o \ -@@ -113,7 +112,6 @@ OBJS=\ +@@ -109,7 +108,6 @@ OBJS=\ $(OUTPRE)prf.$(OBJEXT) \ $(OUTPRE)prf_aes2.$(OBJEXT) \ $(OUTPRE)prf_cmac.$(OBJEXT) \ @@ -4570,7 +4565,7 @@ index 536bacb6e..b587f7e19 100644 $(OUTPRE)prf_dk.$(OBJEXT) \ $(OUTPRE)prf_rc4.$(OBJEXT) \ $(OUTPRE)prng.$(OBJEXT) \ -@@ -174,7 +172,6 @@ SRCS=\ +@@ -168,7 +166,6 @@ SRCS=\ $(srcdir)/prf.c \ $(srcdir)/prf_aes2.c \ $(srcdir)/prf_cmac.c \ @@ -4596,7 +4591,7 @@ index ecc2e08c9..f5fbe8a2a 100644 "hmac-md5-rc4", { "hmac-md5-enc", "hmac-md5-earcfour" }, "Microsoft HMAC MD5", diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h -index b18d5e2e3..1b4324d71 100644 +index ba693f8a4..5cc1f8e43 100644 --- a/src/lib/crypto/krb/crypto_int.h +++ b/src/lib/crypto/krb/crypto_int.h @@ -276,10 +276,6 @@ krb5_error_code krb5int_aes2_string_to_key(const struct krb5_keytypes *enc, @@ -4610,7 +4605,7 @@ index b18d5e2e3..1b4324d71 100644 /* Pseudo-random function */ krb5_error_code krb5int_des_prf(const struct krb5_keytypes *ktp, -@@ -384,11 +380,6 @@ krb5_keyusage krb5int_arcfour_translate_usage(krb5_keyusage usage); +@@ -368,11 +364,6 @@ krb5_keyusage krb5int_arcfour_translate_usage(krb5_keyusage usage); /* Ensure library initialization has occurred. */ int krb5int_crypto_init(void); @@ -4622,7 +4617,7 @@ index b18d5e2e3..1b4324d71 100644 /* Default state cleanup handler (used by module enc providers). */ void krb5int_default_free_state(krb5_data *state); -@@ -441,7 +432,6 @@ void k5_iov_cursor_put(struct iov_cursor *cursor, unsigned char *block); +@@ -425,7 +416,6 @@ void k5_iov_cursor_put(struct iov_cursor *cursor, unsigned char *block); /* Modules must implement the k5_sha256() function prototyped in k5-int.h. */ /* Modules must implement the following enc_providers and hash_providers: */ @@ -4630,7 +4625,7 @@ index b18d5e2e3..1b4324d71 100644 extern const struct krb5_enc_provider krb5int_enc_arcfour; extern const struct krb5_enc_provider krb5int_enc_aes128; extern const struct krb5_enc_provider krb5int_enc_aes256; -@@ -458,12 +448,6 @@ extern const struct krb5_hash_provider krb5int_hash_sha384; +@@ -442,12 +432,6 @@ extern const struct krb5_hash_provider krb5int_hash_sha384; /* Modules must implement the following functions. */ @@ -5196,10 +5191,10 @@ index 1c439c2cd..000000000 - krb5int_default_free_state -}; diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index 439ae6aeb..d8e0f93a1 100644 +index c821cc830..c5bddb1e8 100644 --- a/src/lib/gssapi/krb5/accept_sec_context.c +++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -1011,7 +1011,6 @@ kg_accept_krb5(minor_status, context_handle, +@@ -1010,7 +1010,6 @@ kg_accept_krb5(minor_status, context_handle, } switch (negotiated_etype) { @@ -5208,7 +5203,7 @@ index 439ae6aeb..d8e0f93a1 100644 case ENCTYPE_ARCFOUR_HMAC_EXP: /* RFC 4121 accidentally omits RC4-HMAC-EXP as a "not-newer" diff --git a/src/lib/gssapi/krb5/gssapiP_krb5.h b/src/lib/gssapi/krb5/gssapiP_krb5.h -index 2647434ba..1cdd23cc8 100644 +index 2e2c775d6..f5b0fede6 100644 --- a/src/lib/gssapi/krb5/gssapiP_krb5.h +++ b/src/lib/gssapi/krb5/gssapiP_krb5.h @@ -125,14 +125,14 @@ enum sgn_alg { @@ -5626,7 +5621,7 @@ index 2925c1c43..2f76c8b43 100644 if { ! [cmd {kadm5_destroy $server_handle}]} { perror "$test: unexpected failure in destroy" diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index b597dda54..ed52987a0 100644 +index 0fad90389..316c2b40b 100644 --- a/src/lib/krb5/krb/init_ctx.c +++ b/src/lib/krb5/krb/init_ctx.c @@ -59,7 +59,6 @@ @@ -5637,7 +5632,7 @@ index b597dda54..ed52987a0 100644 ENCTYPE_ARCFOUR_HMAC, ENCTYPE_CAMELLIA128_CTS_CMAC, ENCTYPE_CAMELLIA256_CTS_CMAC, 0 -@@ -478,8 +477,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, +@@ -479,8 +478,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, /* Set all enctypes in the default list. */ for (i = 0; default_list[i]; i++) mod_list(default_list[i], sel, weak, &list); @@ -5647,10 +5642,10 @@ index b597dda54..ed52987a0 100644 mod_list(ENCTYPE_AES256_CTS_HMAC_SHA1_96, sel, weak, &list); mod_list(ENCTYPE_AES128_CTS_HMAC_SHA1_96, sel, weak, &list); diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c -index d8015c64a..005cfd468 100644 +index 8202fe9d3..731281938 100644 --- a/src/lib/krb5/krb/s4u_creds.c +++ b/src/lib/krb5/krb/s4u_creds.c -@@ -341,8 +341,6 @@ verify_s4u2self_reply(krb5_context context, +@@ -287,8 +287,6 @@ verify_s4u2self_reply(krb5_context context, assert(req_s4u_user != NULL); switch (subkey->enctype) { @@ -5660,10 +5655,10 @@ index d8015c64a..005cfd468 100644 case ENCTYPE_ARCFOUR_HMAC_EXP : not_newer = TRUE; diff --git a/src/lib/krb5/krb/t_copy_context.c b/src/lib/krb5/krb/t_copy_context.c -index 22be2198b..d489b78f9 100644 +index 2970a8cea..fb82daf19 100644 --- a/src/lib/krb5/krb/t_copy_context.c +++ b/src/lib/krb5/krb/t_copy_context.c -@@ -114,7 +114,7 @@ main(int argc, char **argv) +@@ -113,7 +113,7 @@ main(int argc, char **argv) { krb5_context ctx, ctx2; krb5_plugin_initvt_fn *mods; @@ -5773,7 +5768,7 @@ index 044a66999..98fb14f3f 100644 krb5_ccache, display type:name: FILE:/path/to/ccache krb5_keytab, display name: FILE:/etc/krb5.keytab diff --git a/src/plugins/preauth/pkinit/pkcs11.h b/src/plugins/preauth/pkinit/pkcs11.h -index 28ded4a89..47f4727bd 100644 +index e3d284631..586661bb7 100644 --- a/src/plugins/preauth/pkinit/pkcs11.h +++ b/src/plugins/preauth/pkinit/pkcs11.h @@ -339,9 +339,9 @@ typedef unsigned long ck_key_type_t; @@ -5966,7 +5961,7 @@ index 2279202d3..96b0307d7 100644 /* initial key, w, x, y, T, S, K */ "8846F7EAEE8FB117AD06BDD830B7586C", diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp -index e8adee234..30a2c0967 100644 +index c24651737..9ef2af745 100644 --- a/src/tests/dejagnu/config/default.exp +++ b/src/tests/dejagnu/config/default.exp @@ -15,8 +15,6 @@ set timeout 100 @@ -6045,7 +6040,7 @@ index e8adee234..30a2c0967 100644 {allow_weak_crypto(kdc)=false} {allow_weak_crypto(replica)=false} {allow_weak_crypto(client)=false} -@@ -947,7 +912,6 @@ proc setup_kerberos_db { standalone } { +@@ -962,7 +927,6 @@ proc setup_kerberos_db { standalone } { global REALMNAME KDB5_UTIL KADMIN_LOCAL KEY global tmppwd hostname global spawn_id @@ -6053,7 +6048,7 @@ index e8adee234..30a2c0967 100644 global multipass_name last_passname_db set failall 0 -@@ -1144,48 +1108,6 @@ proc setup_kerberos_db { standalone } { +@@ -1159,48 +1123,6 @@ proc setup_kerberos_db { standalone } { } } @@ -6261,7 +6256,7 @@ index f71774cdc..d1857c433 100644 "3BB3AE288C12B3B9D06B208A4151B3B6", "9AEA11A3BCF3C53F1F91F5A0BA2132E2501ADF5F3C28" diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py -index d98974b36..84153d9cf 100644 +index 9b41bc0c1..5e6d31302 100644 --- a/src/tests/t_authdata.py +++ b/src/tests/t_authdata.py @@ -172,7 +172,7 @@ realm.run([kvno, 'restricted']) @@ -6424,10 +6419,10 @@ index 65084bbf3..55ca89745 100755 # Test using different salt types in a principal's key list. # Parameters from one key in the list must not leak over to later ones. diff --git a/src/util/k5test.py b/src/util/k5test.py -index da2782e15..feb6df7a0 100644 +index e3614d735..94ab1e71e 100644 --- a/src/util/k5test.py +++ b/src/util/k5test.py -@@ -1246,16 +1246,6 @@ _passes = [ +@@ -1297,16 +1297,6 @@ _passes = [ # No special settings; exercises AES256. ('default', None, None, None), diff --git a/krb5-1.17-beta1-selinux-label.patch b/krb5-1.18-beta1-selinux-label.patch similarity index 92% rename from krb5-1.17-beta1-selinux-label.patch rename to krb5-1.18-beta1-selinux-label.patch index c82350f..cce5f21 100644 --- a/krb5-1.17-beta1-selinux-label.patch +++ b/krb5-1.18-beta1-selinux-label.patch @@ -1,7 +1,7 @@ -From b50a43ef1f09694298ec043104a59082d6f37c8c Mon Sep 17 00:00:00 2001 +From 49a03b8bff8399b9259b51da1e034f67878bfad4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 -Subject: [PATCH] krb5-1.17-beta1-selinux-label.patch +Subject: [PATCH] krb5-1.18-beta1-selinux-label.patch SELinux bases access to files on the domain of the requesting process, the operation being performed, and the context applied to the file. @@ -36,10 +36,10 @@ The selabel APIs for looking up the context should be thread-safe (per Red Hat #273081), so switching to using them instead of matchpathcon(), which we used earlier, is some improvement. --- - src/aclocal.m4 | 49 +++ + src/aclocal.m4 | 48 +++ src/build-tools/krb5-config.in | 3 +- src/config/pre.in | 3 +- - src/configure.in | 2 + + src/configure.ac | 2 + src/include/k5-int.h | 1 + src/include/k5-label.h | 32 ++ src/include/krb5/krb5.hin | 6 + @@ -51,7 +51,6 @@ which we used earlier, is some improvement. src/lib/krb5/ccache/cc_dir.c | 26 +- src/lib/krb5/keytab/kt_file.c | 4 +- src/lib/krb5/os/trace.c | 2 +- - src/lib/krb5/rcache/rc_dfl.c | 13 + src/plugins/kdb/db2/adb_openclose.c | 2 +- src/plugins/kdb/db2/kdb_db2.c | 4 +- src/plugins/kdb/db2/libdb2/btree/bt_open.c | 3 +- @@ -61,12 +60,12 @@ which we used earlier, is some improvement. src/util/profile/prof_file.c | 3 +- src/util/support/Makefile.in | 3 +- src/util/support/selinux.c | 406 ++++++++++++++++++ - 25 files changed, 587 insertions(+), 21 deletions(-) + 24 files changed, 573 insertions(+), 21 deletions(-) create mode 100644 src/include/k5-label.h create mode 100644 src/util/support/selinux.c diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 340546d80..a7afec09e 100644 +index 830203683..6796fec53 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 @@ -89,6 +89,7 @@ AC_SUBST_FILE(libnodeps_frag) @@ -77,7 +76,7 @@ index 340546d80..a7afec09e 100644 KRB5_LIB_PARAMS KRB5_AC_INITFINI KRB5_AC_ENABLE_THREADS -@@ -1764,3 +1765,51 @@ AC_SUBST(PAM_LIBS) +@@ -1743,4 +1744,51 @@ AC_SUBST(PAM_LIBS) AC_SUBST(PAM_MAN) AC_SUBST(NON_PAM_MAN) ])dnl @@ -100,7 +99,7 @@ index 340546d80..a7afec09e 100644 + AC_MSG_ERROR([Unable to locate selinux/selinux.h.]) + fi + fi -+ + + LIBS= + unset ac_cv_func_setfscreatecon + AC_CHECK_FUNCS(setfscreatecon selabel_open) @@ -171,11 +170,11 @@ index ce87e21ca..917357df9 100644 KDB5_LIBS = $(KDB5_LIB) $(GSSRPC_LIBS) GSS_LIBS = $(GSS_KRB5_LIB) # needs fixing if ever used on macOS! -diff --git a/src/configure.in b/src/configure.in -index cd8ccabcd..feae21c3e 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -1354,6 +1354,8 @@ AC_PATH_PROG(GROFF, groff) +diff --git a/src/configure.ac b/src/configure.ac +index d1f576124..440a22bd9 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -1392,6 +1392,8 @@ AC_PATH_PROG(GROFF, groff) KRB5_WITH_PAM @@ -185,7 +184,7 @@ index cd8ccabcd..feae21c3e 100644 if test "${localedir+set}" != set; then localedir='$(datadir)/locale' diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 652242207..8f9329c59 100644 +index 9616b24bf..0d9af3d95 100644 --- a/src/include/k5-int.h +++ b/src/include/k5-int.h @@ -128,6 +128,7 @@ typedef unsigned char u_char; @@ -235,7 +234,7 @@ index 000000000..dfaaa847c +#endif +#endif diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index c40a6cca8..3ff86d7ff 100644 +index d48685357..d1f5661bf 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin @@ -87,6 +87,12 @@ @@ -252,7 +251,7 @@ index c40a6cca8..3ff86d7ff 100644 #include diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c -index c9574c6e1..8301a33d0 100644 +index 301e3476d..19f2cc230 100644 --- a/src/kadmin/dbutil/dump.c +++ b/src/kadmin/dbutil/dump.c @@ -148,12 +148,21 @@ create_ofile(char *ofile, char **tmpname) @@ -287,10 +286,10 @@ index c9574c6e1..8301a33d0 100644 com_err(progname, errno, _("while creating 'ok' file, '%s'"), file_ok); goto cleanup; diff --git a/src/kdc/main.c b/src/kdc/main.c -index 408c723f5..663fd6303 100644 +index fdcd694d7..1ede4bf2f 100644 --- a/src/kdc/main.c +++ b/src/kdc/main.c -@@ -858,7 +858,7 @@ write_pid_file(const char *path) +@@ -872,7 +872,7 @@ write_pid_file(const char *path) FILE *file; unsigned long pid; @@ -300,10 +299,10 @@ index 408c723f5..663fd6303 100644 return errno; pid = (unsigned long) getpid(); diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c -index 68323dd0f..4cc035dc6 100644 +index 5622d56e1..356e3e0e6 100644 --- a/src/kprop/kpropd.c +++ b/src/kprop/kpropd.c -@@ -488,6 +488,9 @@ doit(int fd) +@@ -487,6 +487,9 @@ doit(int fd) krb5_enctype etype; int database_fd; char host[INET6_ADDRSTRLEN + 1]; @@ -313,7 +312,7 @@ index 68323dd0f..4cc035dc6 100644 signal_wrapper(SIGALRM, alarm_handler); alarm(params.iprop_resync_timeout); -@@ -543,9 +546,15 @@ doit(int fd) +@@ -542,9 +545,15 @@ doit(int fd) free(name); exit(1); } @@ -365,7 +364,7 @@ index 2659a2501..e9b95fce5 100644 retval = errno; goto cleanup; diff --git a/src/lib/krb5/ccache/cc_dir.c b/src/lib/krb5/ccache/cc_dir.c -index bba64e516..73f0fe62d 100644 +index 7b100a0ec..5683a0433 100644 --- a/src/lib/krb5/ccache/cc_dir.c +++ b/src/lib/krb5/ccache/cc_dir.c @@ -183,10 +183,19 @@ write_primary_file(const char *primary_path, const char *contents) @@ -415,10 +414,10 @@ index bba64e516..73f0fe62d 100644 _("Credential cache directory %s does not exist"), dirname); diff --git a/src/lib/krb5/keytab/kt_file.c b/src/lib/krb5/keytab/kt_file.c -index 89cb68680..21c80d419 100644 +index 021c94398..aaf573439 100644 --- a/src/lib/krb5/keytab/kt_file.c +++ b/src/lib/krb5/keytab/kt_file.c -@@ -1024,14 +1024,14 @@ krb5_ktfileint_open(krb5_context context, krb5_keytab id, int mode) +@@ -735,14 +735,14 @@ krb5_ktfileint_open(krb5_context context, krb5_keytab id, int mode) KTCHECKLOCK(id); errno = 0; @@ -436,7 +435,7 @@ index 89cb68680..21c80d419 100644 goto report_errno; writevno = 1; diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c -index 4fff8f38c..40a9e7b10 100644 +index 2a03ae980..85dbfeb47 100644 --- a/src/lib/krb5/os/trace.c +++ b/src/lib/krb5/os/trace.c @@ -458,7 +458,7 @@ krb5_set_trace_filename(krb5_context context, const char *filename) @@ -448,38 +447,6 @@ index 4fff8f38c..40a9e7b10 100644 if (*fd == -1) { free(fd); return errno; -diff --git a/src/lib/krb5/rcache/rc_dfl.c b/src/lib/krb5/rcache/rc_dfl.c -index 1e0cb22c9..f5e93b1ab 100644 ---- a/src/lib/krb5/rcache/rc_dfl.c -+++ b/src/lib/krb5/rcache/rc_dfl.c -@@ -793,6 +793,9 @@ krb5_rc_dfl_expunge_locked(krb5_context context, krb5_rcache id) - krb5_error_code retval = 0; - krb5_rcache tmp; - krb5_deltat lifespan = t->lifespan; /* save original lifespan */ -+#ifdef USE_SELINUX -+ void *selabel; -+#endif - - if (! t->recovering) { - name = t->name; -@@ -814,7 +817,17 @@ krb5_rc_dfl_expunge_locked(krb5_context context, krb5_rcache id) - retval = krb5_rc_resolve(context, tmp, 0); - if (retval) - goto cleanup; -+#ifdef USE_SELINUX -+ if (t->d.fn != NULL) -+ selabel = krb5int_push_fscreatecon_for(t->d.fn); -+ else -+ selabel = NULL; -+#endif - retval = krb5_rc_initialize(context, tmp, lifespan); -+#ifdef USE_SELINUX -+ if (selabel != NULL) -+ krb5int_pop_fscreatecon(selabel); -+#endif - if (retval) - goto cleanup; - for (q = t->a; q; q = q->na) { diff --git a/src/plugins/kdb/db2/adb_openclose.c b/src/plugins/kdb/db2/adb_openclose.c index 7db30a33b..2b9d01921 100644 --- a/src/plugins/kdb/db2/adb_openclose.c @@ -573,10 +540,10 @@ index d8b26e701..b0daa7c02 100644 if (fname != NULL && fcntl(rfd, F_SETFD, 1) == -1) { diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c -index 1ed72afe9..ce038fc3d 100644 +index b92cb58c7..0a95101ad 100644 --- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c +++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c -@@ -194,7 +194,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv) +@@ -190,7 +190,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv) /* set password in the file */ old_mode = umask(0177); @@ -585,7 +552,7 @@ index 1ed72afe9..ce038fc3d 100644 if (pfile == NULL) { com_err(me, errno, _("Failed to open file %s: %s"), file_name, strerror (errno)); -@@ -235,6 +235,9 @@ kdb5_ldap_stash_service_password(int argc, char **argv) +@@ -231,6 +231,9 @@ kdb5_ldap_stash_service_password(int argc, char **argv) * Delete the existing entry and add the new entry */ FILE *newfile; @@ -595,7 +562,7 @@ index 1ed72afe9..ce038fc3d 100644 mode_t omask; -@@ -246,7 +249,13 @@ kdb5_ldap_stash_service_password(int argc, char **argv) +@@ -242,7 +245,13 @@ kdb5_ldap_stash_service_password(int argc, char **argv) } omask = umask(077); @@ -610,7 +577,7 @@ index 1ed72afe9..ce038fc3d 100644 if (newfile == NULL) { com_err(me, errno, _("Error creating file %s"), tmp_file); diff --git a/src/util/profile/prof_file.c b/src/util/profile/prof_file.c -index 24e41fb80..0dcb6b543 100644 +index aa951df05..79f9500f6 100644 --- a/src/util/profile/prof_file.c +++ b/src/util/profile/prof_file.c @@ -33,6 +33,7 @@ @@ -631,10 +598,10 @@ index 24e41fb80..0dcb6b543 100644 retval = errno; if (retval == 0) diff --git a/src/util/support/Makefile.in b/src/util/support/Makefile.in -index db7b030b8..321672bcb 100644 +index 86d5a950a..1052d53a1 100644 --- a/src/util/support/Makefile.in +++ b/src/util/support/Makefile.in -@@ -69,6 +69,7 @@ IPC_SYMS= \ +@@ -74,6 +74,7 @@ IPC_SYMS= \ STLIBOBJS= \ threads.o \ @@ -642,7 +609,7 @@ index db7b030b8..321672bcb 100644 init-addrinfo.o \ plugins.o \ errors.o \ -@@ -160,7 +161,7 @@ SRCS=\ +@@ -168,7 +169,7 @@ SRCS=\ SHLIB_EXPDEPS = # Add -lm if dumping thread stats, for sqrt. diff --git a/krb5-1.12.1-pam.patch b/krb5-1.18beta1-pam.patch similarity index 96% rename from krb5-1.12.1-pam.patch rename to krb5-1.18beta1-pam.patch index 2ce2a57..c785c7c 100644 --- a/krb5-1.12.1-pam.patch +++ b/krb5-1.18beta1-pam.patch @@ -1,7 +1,7 @@ -From 5e2837a56bb6bb1fbaf371377dbffa35aa81b3f1 Mon Sep 17 00:00:00 2001 +From 9d77eb513f95821f01f12e233e16d4ce50da7d23 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 -Subject: [PATCH] krb5-1.12.1-pam.patch +Subject: [PATCH] krb5-1.18beta1-pam.patch Modify ksu so that it performs account and session management on behalf of the target user account, mimicking the action of regular su. The default @@ -17,24 +17,25 @@ Originally RT#5939, though it's changed since then to perform the account and session management before dropping privileges, and to apply on top of changes we're proposing for how it handles cache collections. --- - src/aclocal.m4 | 67 +++++++ + src/aclocal.m4 | 69 +++++++ src/clients/ksu/Makefile.in | 8 +- src/clients/ksu/main.c | 88 +++++++- src/clients/ksu/pam.c | 389 ++++++++++++++++++++++++++++++++++++ src/clients/ksu/pam.h | 57 ++++++ - src/configure.in | 2 + - 6 files changed, 608 insertions(+), 3 deletions(-) + src/configure.ac | 2 + + 6 files changed, 610 insertions(+), 3 deletions(-) create mode 100644 src/clients/ksu/pam.c create mode 100644 src/clients/ksu/pam.h diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 3752d9bd5..340546d80 100644 +index 2394f7e33..830203683 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -1697,3 +1697,70 @@ AC_DEFUN(KRB5_AC_PERSISTENT_KEYRING,[ - ])) +@@ -1675,3 +1675,72 @@ if test "$with_ldap" = yes; then + OPENLDAP_PLUGIN=yes + fi ])dnl - dnl ++dnl +dnl +dnl Use PAM instead of local crypt() compare for checking local passwords, +dnl and perform PAM account, session management, and password-changing where @@ -102,12 +103,13 @@ index 3752d9bd5..340546d80 100644 +AC_SUBST(PAM_MAN) +AC_SUBST(NON_PAM_MAN) +])dnl ++ diff --git a/src/clients/ksu/Makefile.in b/src/clients/ksu/Makefile.in -index b2fcbf240..5755bb58a 100644 +index 8b4edce4d..9d58f29b5 100644 --- a/src/clients/ksu/Makefile.in +++ b/src/clients/ksu/Makefile.in @@ -3,12 +3,14 @@ BUILDTOP=$(REL)..$(S).. - DEFINES = -DGET_TGT_VIA_PASSWD -DPRINC_LOOK_AHEAD -DCMD_PATH='"/bin /local/bin"' + DEFINES = -DGET_TGT_VIA_PASSWD -DPRINC_LOOK_AHEAD -DCMD_PATH='"/usr/local/sbin /usr/local/bin /sbin /bin /usr/sbin /usr/bin"' KSU_LIBS=@KSU_LIBS@ +PAM_LIBS=@PAM_LIBS@ @@ -141,7 +143,7 @@ index b2fcbf240..5755bb58a 100644 clean: $(RM) ksu diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c -index d9596d948..ec06788bc 100644 +index 4f03dd8ed..21a4d02bb 100644 --- a/src/clients/ksu/main.c +++ b/src/clients/ksu/main.c @@ -26,6 +26,7 @@ @@ -171,7 +173,7 @@ index d9596d948..ec06788bc 100644 /***********/ #define KS_TEMPORARY_CACHE "MEMORY:_ksu" -@@ -528,6 +534,23 @@ main (argc, argv) +@@ -535,6 +541,23 @@ main (argc, argv) prog_name,target_user,client_name, source_user,ontty()); @@ -195,7 +197,7 @@ index d9596d948..ec06788bc 100644 /* Run authorization as target.*/ if (krb5_seteuid(target_uid)) { com_err(prog_name, errno, _("while switching to target for " -@@ -588,6 +611,24 @@ main (argc, argv) +@@ -595,6 +618,24 @@ main (argc, argv) exit(1); } @@ -220,7 +222,7 @@ index d9596d948..ec06788bc 100644 } if( some_rest_copy){ -@@ -645,6 +686,30 @@ main (argc, argv) +@@ -652,6 +693,30 @@ main (argc, argv) exit(1); } @@ -251,7 +253,7 @@ index d9596d948..ec06788bc 100644 /* set permissions */ if (setgid(target_pwd->pw_gid) < 0) { perror("ksu: setgid"); -@@ -742,7 +807,7 @@ main (argc, argv) +@@ -749,7 +814,7 @@ main (argc, argv) fprintf(stderr, "program to be execed %s\n",params[0]); } @@ -260,7 +262,7 @@ index d9596d948..ec06788bc 100644 execv(params[0], params); com_err(prog_name, errno, _("while trying to execv %s"), params[0]); sweep_up(ksu_context, cc_target); -@@ -772,16 +837,35 @@ main (argc, argv) +@@ -779,16 +844,35 @@ main (argc, argv) if (ret_pid == -1) { com_err(prog_name, errno, _("while calling waitpid")); } @@ -755,11 +757,11 @@ index 000000000..0ab76569c +int appl_pam_cred_init(void); +void appl_pam_cleanup(void); +#endif -diff --git a/src/configure.in b/src/configure.in -index 36df71fa9..cd8ccabcd 100644 ---- a/src/configure.in -+++ b/src/configure.in -@@ -1352,6 +1352,8 @@ AC_SUBST([VERTO_VERSION]) +diff --git a/src/configure.ac b/src/configure.ac +index 234f4281c..d1f576124 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -1390,6 +1390,8 @@ AC_SUBST([VERTO_VERSION]) AC_PATH_PROG(GROFF, groff) diff --git a/krb5-1.3.1-dns.patch b/krb5-1.3.1-dns.patch index ec0e306..2ae1f8e 100644 --- a/krb5-1.3.1-dns.patch +++ b/krb5-1.3.1-dns.patch @@ -1,4 +1,4 @@ -From 35cd8e40a35ce4546eaffada2f401a7f0f6a83b3 Mon Sep 17 00:00:00 2001 +From fe90cb8f915e7f43899437e5e2d9a3aebf23ed82 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] krb5-1.3.1-dns.patch @@ -9,10 +9,10 @@ We want to be able to use --with-netlib and --enable-dns at the same time. 1 file changed, 1 insertion(+) diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index a7afec09e..db18226ed 100644 +index 6796fec53..c4358988a 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -726,6 +726,7 @@ AC_HELP_STRING([--with-netlib=LIBS], use user defined resolver library), +@@ -724,6 +724,7 @@ AC_HELP_STRING([--with-netlib=LIBS], use user defined resolver library), LIBS="$LIBS $withval" AC_MSG_RESULT("netlib will use \'$withval\'") fi diff --git a/krb5-1.9-debuginfo.patch b/krb5-1.9-debuginfo.patch index a5046d0..adb6219 100644 --- a/krb5-1.9-debuginfo.patch +++ b/krb5-1.9-debuginfo.patch @@ -1,4 +1,4 @@ -From e0391c7071741e6d59025d8b4a26119f2998d90c Mon Sep 17 00:00:00 2001 +From c26cf6cc3507ba63cb458094b9237ad2231ca5eb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] krb5-1.9-debuginfo.patch diff --git a/krb5.spec b/krb5.spec index c7f4735..9ea18f5 100644 --- a/krb5.spec +++ b/krb5.spec @@ -9,16 +9,16 @@ %global configured_default_ccache_name KEYRING:persistent:%%{uid} # leave empty or set to e.g., -beta2 -%global prerelease %{nil} +%global prerelease -beta1 # Should be in form 5.0, 6.1, etc. -%global kdbversion 7.0 +%global kdbversion 8.0 Summary: The Kerberos network authentication system Name: krb5 -Version: 1.17.1 +Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 5%{?dist} +Release: 0.beta1.1%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -42,85 +42,14 @@ Source39: krb5-krb5kdc.conf # Carry this locally until it's available in a packaged form. Source100: noport.c -Patch26: krb5-1.12.1-pam.patch -Patch27: krb5-1.17-beta1-selinux-label.patch +Patch1: krb5-1.18beta1-pam.patch +Patch2: krb5-1.18-beta1-selinux-label.patch Patch30: krb5-1.15-beta1-buildconf.patch Patch31: krb5-1.3.1-dns.patch Patch34: krb5-1.9-debuginfo.patch -Patch90: Add-tests-for-KCM-ccache-type.patch -Patch92: Address-some-optimized-out-memset-calls.patch -Patch94: Avoid-allocating-a-register-in-zap-assembly.patch -Patch95: In-rd_req_dec-always-log-non-permitted-enctypes.patch -Patch96: In-kpropd-debug-log-proper-ticket-enctype-names.patch -Patch97: Add-function-and-enctype-flag-for-deprecations.patch -Patch98: Make-etype-names-in-KDC-logs-human-readable.patch -Patch99: Mark-deprecated-enctypes-when-used.patch -Patch100: Properly-size-ifdef-in-k5_cccol_lock.patch -Patch104: Clarify-header-comment-for-krb5_cc_start_seq_get.patch -Patch105: Implement-krb5_cc_remove_cred-for-remaining-types.patch -Patch106: Remove-srvtab-support.patch -Patch107: Remove-kadmin-RPC-support-for-setting-v4-key.patch -Patch108: Remove-ccapi-related-comments-in-configure.ac.patch -Patch109: Remove-doxygen-generated-HTML-output-for-ccapi.patch -Patch110: Remove-Kerberos-v4-support-vestiges-from-ccapi.patch -Patch111: Fix-config-realm-change-logic-in-FILE-remove_cred.patch -Patch112: Remove-confvalidator-utility.patch -Patch113: Remove-ovsec_adm_export-dump-format-support.patch -Patch114: Fix-potential-close-1-in-cc_file.c.patch -Patch115: Check-more-errors-in-OpenSSL-crypto-backend.patch -Patch116: Clear-forwardable-flag-instead-of-denying-request.patch -Patch117: Add-dns_canonicalize_hostname-fallback-support.patch -Patch118: Use-secure_getenv-where-appropriate.patch -Patch119: Initialize-some-data-structure-magic-fields.patch -Patch121: Modernize-exit-path-in-gss_krb5int_copy_ccache.patch -Patch122: Simplify-SAM-2-as_key-handling.patch -Patch123: Avoid-alignment-warnings-in-openssl-rc4.c.patch -Patch124: Simply-OpenSSL-PKCS7-decryption-code.patch -Patch125: Improve-error-messages-from-kadmin-change_password.patch -Patch126: Remove-more-dead-code.patch -Patch128: Remove-checksum-type-profile-variables.patch -Patch129: Remove-dead-variable-def_kslist-from-two-files.patch -Patch130: Mark-the-doc-kadm5-tex-files-as-historic.patch -Patch131: Modernize-example-enctypes-in-documentation.patch -Patch132: Update-ASN.1-SAM-tests-to-use-a-modern-enctype.patch -Patch133: Update-default-krb5kdc-mkey-manual-entry-enctype.patch -Patch134: Support-389ds-s-lockout-model.patch -Patch135: Add-missing-newlines-to-deprecation-warnings.patch -Patch136: Set-a-more-modern-default-ksu-CMD_PATH.patch -Patch137: Remove-the-v4-and-afs3-salt-types.patch -Patch138: Update-test-suite-to-avoid-single-DES-enctypes.patch -Patch139: Remove-support-for-single-DES-and-CRC.patch -Patch140: Display-unsupported-enctype-names.patch -Patch142: Add-zapfreedata-convenience-function.patch -Patch143: Remove-support-for-no-flags-SAM-2-preauth.patch -Patch144: Remove-krb5int_c_combine_keys.patch -Patch147: Remove-strerror-calls-from-k5_get_error.patch -Patch148: Remove-PKINIT-draft-9-support.patch -Patch149: Remove-PKINIT-draft-9-ASN.1-code-and-types.patch -Patch150: Remove-3des-support.patch -Patch151: Remove-now-unused-checksum-functions.patch -Patch152: Don-t-error-on-invalid-enctypes-in-keytab.patch -Patch153: Filter-enctypes-in-gss_set_allowable_enctypes.patch -Patch154: Add-soft-pkcs11-source-code.patch -Patch155: Use-imported-soft-pkcs11-for-tests.patch -Patch156: Fix-Coverity-defects-in-soft-pkcs11-test-code.patch -Patch157: Skip-URI-tests-when-using-asan.patch -Patch158: Fix-memory-leaks-in-soft-pkcs11-code.patch -Patch162: Simplify-krb5_dbe_def_search_enctype.patch -Patch163: Squash-apparent-forward-null-in-clnttcp_create.patch -Patch164: Remove-null-check-in-krb5_gss_duplicate_name.patch -Patch165: Fix-KDC-crash-when-logging-PKINIT-enctypes.patch -Patch166: Log-unknown-enctypes-as-unsupported-in-KDC.patch -Patch167: Fix-minor-errors-in-softpkcs11.patch -Patch168: Update-test-suite-cert-message-digest-to-sha256.patch +Patch35: krb5-1.18-beta1-Remove-3des-support.patch Patch169: Use-backported-version-of-OpenSSL-3-KDF-interface.patch Patch170: krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch -Patch171: Don-t-warn-in-kadmin-when-no-policy-is-specified.patch -Patch172: Allow-client-canonicalization-in-non-krbtgt-AS-REP.patch -Patch173: Do-not-always-canonicalize-enterprise-principals.patch -Patch174: Fix-xdr_bytes-strict-aliasing-violations.patch -Patch175: Fix-handling-of-invalid-CAMMAC-service-verifier.patch -Patch176: Fix-LDAP-policy-enforcement-of-pw_expiration.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -694,6 +623,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Jan 10 2020 Robbie Harwood - 1.18-0beta1.1 +- New upstream beta release - 1.18-beta1 + * Wed Jan 08 2020 Robbie Harwood - 1.17.1-5 - Fix LDAP policy enforcement of pw_expiration - Fix handling of invalid CAMMAC service verifier diff --git a/sources b/sources index 01f775d..3b304f6 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.17.1.tar.gz) = e0c3dc0a6554ab3105ac32f3f01519f56064500213aa743816235d83250abc1db9a9ca38a2ba93a938d562b4af135a013017ce96346d6742bca0c812b842ceef -SHA512 (krb5-1.17.1.tar.gz.asc) = 9665c0b83cc5e8fafbb7f47c383c6bf00e498befa305ab7ed8b867ff6f54a09b6b1f3b7a7f007ceb6dfbc1ebfb797be21cb97ac51c1c8fc8e956d83ce30aa7b1 +SHA512 (krb5-1.18-beta1.tar.gz) = e9e622350c9d07bca573d1e416a7277377e85c0f3eab605d3f551f96c5ddc7eb21e8ef2cfadddbac7d9da99a204d738fd22939cfb23d7fcc8166e8ae35a679a4 +SHA512 (krb5-1.18-beta1.tar.gz.asc) = b8542e317db89d11ad29bba9bc55f4d294e649b0e8c28b37dde398fed64fa3da394af262225ebefda5e5f3224ba108df21af460837e72a4349ae7e6469e21e43 From b3d5b8f7197a348981e2ba8f9a406d11c11cecde Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Wed, 29 Jan 2020 07:50:49 +0000 Subject: [PATCH 147/304] - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 9ea18f5..ffb7285 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 0.beta1.1%{?dist} +Release: 0.beta1.1%{?dist}.1 # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz @@ -623,6 +623,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Jan 29 2020 Fedora Release Engineering - 1.18-0.beta1.1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild + * Fri Jan 10 2020 Robbie Harwood - 1.18-0beta1.1 - New upstream beta release - 1.18-beta1 From 8fb4697062c46f1ab5c143714efd5c48cf53156d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 31 Jan 2020 20:31:53 +0000 Subject: [PATCH 148/304] New upstream beta release - 1.18-beta2 Adjust naming convention for downstream patches --- .gitignore | 2 + ...ownstream-Adjust-build-configuration.patch | 6 +- ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 6 +- ...ch => downstream-Remove-3des-support.patch | 65 +++++++++---------- ...ch => downstream-SELinux-integration.patch | 6 +- ...ackported-version-of-OpenSSL-3-KDF-i.patch | 6 +- ...ownstream-fix-debuginfo-with-y.tab.c.patch | 6 +- ...ch => downstream-ksu-pam-integration.patch | 6 +- ...s.patch => downstream-netlib-and-dns.patch | 6 +- krb5.spec | 31 ++++----- sources | 4 +- 11 files changed, 80 insertions(+), 64 deletions(-) rename krb5-1.15-beta1-buildconf.patch => downstream-Adjust-build-configuration.patch (95%) rename krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch => downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch (99%) rename krb5-1.18-beta1-Remove-3des-support.patch => downstream-Remove-3des-support.patch (99%) rename krb5-1.18-beta1-selinux-label.patch => downstream-SELinux-integration.patch (99%) rename Use-backported-version-of-OpenSSL-3-KDF-interface.patch => downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch (99%) rename krb5-1.9-debuginfo.patch => downstream-fix-debuginfo-with-y.tab.c.patch (90%) rename krb5-1.18beta1-pam.patch => downstream-ksu-pam-integration.patch (99%) rename krb5-1.3.1-dns.patch => downstream-netlib-and-dns.patch (80%) diff --git a/.gitignore b/.gitignore index 9c30463..1b6f6a6 100644 --- a/.gitignore +++ b/.gitignore @@ -179,3 +179,5 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.17.1.tar.gz.asc /krb5-1.18-beta1.tar.gz /krb5-1.18-beta1.tar.gz.asc +/krb5-1.18-beta2.tar.gz +/krb5-1.18-beta2.tar.gz.asc diff --git a/krb5-1.15-beta1-buildconf.patch b/downstream-Adjust-build-configuration.patch similarity index 95% rename from krb5-1.15-beta1-buildconf.patch rename to downstream-Adjust-build-configuration.patch index 5ad5500..6fecd56 100644 --- a/krb5-1.15-beta1-buildconf.patch +++ b/downstream-Adjust-build-configuration.patch @@ -1,13 +1,15 @@ -From e07920163e88a538e73b4d72db26b74c951b8256 Mon Sep 17 00:00:00 2001 +From 74e18ba4575ed2fbf67dd57c3712f01ecba76932 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 -Subject: [PATCH] krb5-1.15-beta1-buildconf.patch +Subject: [PATCH] [downstream] Adjust build configuration Build binaries in this package as RELRO PIEs, libraries as partial RELRO, and install shared libraries with the execute bit set on them. Prune out the -L/usr/lib* and PIE flags where they might leak out and affect apps which just want to link with the libraries. FIXME: needs to check and not just assume that the compiler supports using these flags. + +Last-updated: krb5-1.15-beta1 --- src/build-tools/krb5-config.in | 7 +++++++ src/config/pre.in | 2 +- diff --git a/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch similarity index 99% rename from krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch rename to downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index 58a7118..f0219e3 100644 --- a/krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,7 +1,7 @@ -From ad14cab8d35e6c7edee196708ce5b5516b9bb1f8 Mon Sep 17 00:00:00 2001 +From 494658b52c8aebd7d31d51faa4eb498b6e6843ed Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 -Subject: [PATCH] krb5-1.17post6 FIPS with PRNG and RADIUS and MD4 +Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 NB: Use openssl's PRNG in FIPS mode and taint within krad. @@ -16,6 +16,8 @@ locks), but not for any ciphers we care about - which is to say that AES is fine. Shame about SPAKE though. post6 restores MD4 (and therefore keygen-only RC4). + +Last-updated: krb5-1.17 --- src/lib/crypto/krb/prng.c | 11 ++++- .../crypto/openssl/enc_provider/camellia.c | 6 +++ diff --git a/krb5-1.18-beta1-Remove-3des-support.patch b/downstream-Remove-3des-support.patch similarity index 99% rename from krb5-1.18-beta1-Remove-3des-support.patch rename to downstream-Remove-3des-support.patch index 1b88923..001b2d3 100644 --- a/krb5-1.18-beta1-Remove-3des-support.patch +++ b/downstream-Remove-3des-support.patch @@ -1,12 +1,14 @@ -From d042a0d6ea28c70e87ae342255a0af2bab631ec1 Mon Sep 17 00:00:00 2001 +From 0153147f716b8f8710fd307df54908267779c3a4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 -Subject: [PATCH] krb5-1.18-beta1-Remove-3des-support +Subject: [PATCH] [downstream] Remove 3des support Completely remove support for all DES3 enctypes (des3-cbc-raw, des3-hmac-sha1, des3-cbc-sha1-kd). Update all tests and documentation to user other enctypes. Mark the 3DES enctypes UNSUPPORTED and retain their constants. + +Last-updated: 1.18-beta2 --- doc/admin/advanced/retiring-des.rst | 11 + doc/admin/conf_files/kdc_conf.rst | 7 +- @@ -102,9 +104,9 @@ their constants. src/tests/t_keyrollover.py | 8 +- src/tests/t_mkey.py | 35 -- src/tests/t_salt.py | 5 +- - src/util/k5test.py | 10 - + src/util/k5test.py | 7 - .../leash/htmlhelp/html/Encryption_Types.htm | 13 - - 96 files changed, 163 insertions(+), 4837 deletions(-) + 96 files changed, 163 insertions(+), 4834 deletions(-) delete mode 100644 src/lib/crypto/builtin/des/ISSUES delete mode 100644 src/lib/crypto/builtin/des/Makefile.in delete mode 100644 src/lib/crypto/builtin/des/d3_aead.c @@ -194,10 +196,10 @@ index 9759756a2..cf8a12547 100644 While **aes128-cts** and **aes256-cts** are supported for all Kerberos diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst -index 84183a53c..b3fdc7c8b 100644 +index caf6d9267..65b55cdb9 100644 --- a/doc/admin/enctypes.rst +++ b/doc/admin/enctypes.rst -@@ -125,7 +125,7 @@ enctype weak? krb5 Windows +@@ -129,7 +129,7 @@ enctype weak? krb5 Windows des-cbc-crc weak <1.18 >=2000 des-cbc-md4 weak <1.18 ? des-cbc-md5 weak <1.18 >=2000 @@ -206,7 +208,7 @@ index 84183a53c..b3fdc7c8b 100644 arcfour-hmac >=1.3 >=2000 arcfour-hmac-exp weak >=1.3 >=2000 aes128-cts-hmac-sha1-96 >=1.3 >=Vista -@@ -136,7 +136,10 @@ camellia128-cts-cmac >=1.9 none +@@ -140,7 +140,10 @@ camellia128-cts-cmac >=1.9 none camellia256-cts-cmac >=1.9 none ========================== ===== ======== ======= @@ -267,7 +269,7 @@ index fc5662767..37eda67fa 100644 .. |copy| unicode:: U+000A9 ''' diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst -index d58c71898..8655e257d 100644 +index a7e55f206..77c095c75 100644 --- a/doc/mitK5features.rst +++ b/doc/mitK5features.rst @@ -37,7 +37,7 @@ Database backends: LDAP, DB2, LMDB @@ -363,7 +365,7 @@ index 8a4b87de1..d7f1d076b 100644 + supported_enctypes = aes256-cts:normal aes128-cts:normal aes256-sha2:normal aes128-sha2:normal } diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index d0fd5d7e1..050672840 100644 +index 221bde1dd..b8d292021 100644 --- a/src/kdc/kdc_util.c +++ b/src/kdc/kdc_util.c @@ -1103,8 +1103,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) @@ -375,7 +377,7 @@ index d0fd5d7e1..050672840 100644 else return krb5_enctype_to_name(ktype, FALSE, buf, buflen); -@@ -1839,8 +1837,6 @@ krb5_boolean +@@ -1841,8 +1839,6 @@ krb5_boolean enctype_requires_etype_info_2(krb5_enctype enctype) { switch(enctype) { @@ -5621,7 +5623,7 @@ index 2925c1c43..2f76c8b43 100644 if { ! [cmd {kadm5_destroy $server_handle}]} { perror "$test: unexpected failure in destroy" diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index 0fad90389..316c2b40b 100644 +index e7d67cca4..9a4741fa6 100644 --- a/src/lib/krb5/krb/init_ctx.c +++ b/src/lib/krb5/krb/init_ctx.c @@ -59,7 +59,6 @@ @@ -5642,7 +5644,7 @@ index 0fad90389..316c2b40b 100644 mod_list(ENCTYPE_AES256_CTS_HMAC_SHA1_96, sel, weak, &list); mod_list(ENCTYPE_AES128_CTS_HMAC_SHA1_96, sel, weak, &list); diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c -index 8202fe9d3..731281938 100644 +index 504eb557f..fc5c886d6 100644 --- a/src/lib/krb5/krb/s4u_creds.c +++ b/src/lib/krb5/krb/s4u_creds.c @@ -287,8 +287,6 @@ verify_s4u2self_reply(krb5_context context, @@ -5961,7 +5963,7 @@ index 2279202d3..96b0307d7 100644 /* initial key, w, x, y, T, S, K */ "8846F7EAEE8FB117AD06BDD830B7586C", diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp -index c24651737..9ef2af745 100644 +index b047ef1f7..4d8c917cd 100644 --- a/src/tests/dejagnu/config/default.exp +++ b/src/tests/dejagnu/config/default.exp @@ -15,8 +15,6 @@ set timeout 100 @@ -5999,7 +6001,7 @@ index c24651737..9ef2af745 100644 {supported_enctypes=aes256-sha2:normal} {permitted_enctypes(kdc)=aes256-sha2} {permitted_enctypes(replica)=aes256-sha2} -@@ -154,7 +143,6 @@ set passes { +@@ -146,7 +135,6 @@ set passes { { camellia-only mode=udp @@ -6007,7 +6009,7 @@ index c24651737..9ef2af745 100644 {supported_enctypes=camellia256-cts:normal} {permitted_enctypes(kdc)=camellia256-cts} {permitted_enctypes(replica)=camellia256-cts} -@@ -175,32 +163,9 @@ set passes { +@@ -159,32 +147,9 @@ set passes { {master_key_type=camellia256-cts} {dummy=[verbose -log "Camellia-256 enctype"]} } @@ -6040,7 +6042,7 @@ index c24651737..9ef2af745 100644 {allow_weak_crypto(kdc)=false} {allow_weak_crypto(replica)=false} {allow_weak_crypto(client)=false} -@@ -962,7 +927,6 @@ proc setup_kerberos_db { standalone } { +@@ -946,7 +911,6 @@ proc setup_kerberos_db { standalone } { global REALMNAME KDB5_UTIL KADMIN_LOCAL KEY global tmppwd hostname global spawn_id @@ -6048,7 +6050,7 @@ index c24651737..9ef2af745 100644 global multipass_name last_passname_db set failall 0 -@@ -1159,48 +1123,6 @@ proc setup_kerberos_db { standalone } { +@@ -1143,48 +1107,6 @@ proc setup_kerberos_db { standalone } { } } @@ -6111,7 +6113,7 @@ index f71ee8638..8c08cf42f 100644 # Delete any db, ulog files delete_db diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py -index ca3d32d21..96d0e7330 100755 +index 7494d7fcd..2f95d8996 100755 --- a/src/tests/gssapi/t_enctypes.py +++ b/src/tests/gssapi/t_enctypes.py @@ -1,24 +1,17 @@ @@ -6137,14 +6139,14 @@ index ca3d32d21..96d0e7330 100755 # These tests make assumptions about the default enctype lists, so set # them explicitly rather than relying on the library defaults. --enctypes='aes des3 rc4' -supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal' -+enctypes='aes rc4' +-conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4'}, +supp='aes256-cts:normal aes128-cts:normal rc4-hmac:normal' - conf = {'libdefaults': { - 'default_tgs_enctypes': enctypes, - 'default_tkt_enctypes': enctypes, -@@ -91,19 +84,12 @@ test('both aes128', 'aes128-cts', 'aes128-cts', ++conf = {'libdefaults': {'permitted_enctypes': 'aes rc4'}, + 'realms': {'$realm': {'supported_enctypes': supp}}} + realm = K5Realm(krb5_conf=conf) + shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save')) +@@ -87,19 +80,12 @@ test('both aes128', 'aes128-cts', 'aes128-cts', test_err('acc aes128', None, 'aes128-cts', 'Encryption type aes256-cts-hmac-sha1-96 not permitted') @@ -6165,7 +6167,7 @@ index ca3d32d21..96d0e7330 100755 # subkey. test('upgrade noargs', None, None, tktenc=aes256, tktsession=d_rc4, -@@ -119,13 +105,6 @@ test('upgrade init aes128+rc4', 'aes128-cts rc4', None, +@@ -115,13 +101,6 @@ test('upgrade init aes128+rc4', 'aes128-cts rc4', None, tktenc=aes256, tktsession=d_rc4, proto='cfx', isubkey=rc4, asubkey=aes128) @@ -6256,7 +6258,7 @@ index f71774cdc..d1857c433 100644 "3BB3AE288C12B3B9D06B208A4151B3B6", "9AEA11A3BCF3C53F1F91F5A0BA2132E2501ADF5F3C28" diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py -index 9b41bc0c1..5e6d31302 100644 +index 378174a2e..3153ebca3 100644 --- a/src/tests/t_authdata.py +++ b/src/tests/t_authdata.py @@ -172,7 +172,7 @@ realm.run([kvno, 'restricted']) @@ -6419,26 +6421,23 @@ index 65084bbf3..55ca89745 100755 # Test using different salt types in a principal's key list. # Parameters from one key in the list must not leak over to later ones. diff --git a/src/util/k5test.py b/src/util/k5test.py -index e3614d735..94ab1e71e 100644 +index 442a4e4f7..eea92275d 100644 --- a/src/util/k5test.py +++ b/src/util/k5test.py -@@ -1297,16 +1297,6 @@ _passes = [ +@@ -1299,13 +1299,6 @@ _passes = [ # No special settings; exercises AES256. ('default', None, None, None), - # Exercise the DES3 enctype. - ('des3', None, -- {'libdefaults': { -- 'default_tgs_enctypes': 'des3', -- 'default_tkt_enctypes': 'des3', -- 'permitted_enctypes': 'des3'}}, +- {'libdefaults': {'permitted_enctypes': 'des3'}}, - {'realms': {'$realm': { - 'supported_enctypes': 'des3-cbc-sha1:normal', - 'master_key_type': 'des3-cbc-sha1'}}}), - # Exercise the arcfour enctype. ('arcfour', None, - {'libdefaults': { + {'libdefaults': {'permitted_enctypes': 'rc4'}}, diff --git a/src/windows/leash/htmlhelp/html/Encryption_Types.htm b/src/windows/leash/htmlhelp/html/Encryption_Types.htm index 1aebdd0b4..c38eefd2b 100644 --- a/src/windows/leash/htmlhelp/html/Encryption_Types.htm diff --git a/krb5-1.18-beta1-selinux-label.patch b/downstream-SELinux-integration.patch similarity index 99% rename from krb5-1.18-beta1-selinux-label.patch rename to downstream-SELinux-integration.patch index cce5f21..52d4607 100644 --- a/krb5-1.18-beta1-selinux-label.patch +++ b/downstream-SELinux-integration.patch @@ -1,7 +1,7 @@ -From 49a03b8bff8399b9259b51da1e034f67878bfad4 Mon Sep 17 00:00:00 2001 +From bbdfaec5156307c791804c6eb5ed8c2eefff1318 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 -Subject: [PATCH] krb5-1.18-beta1-selinux-label.patch +Subject: [PATCH] [downstream] SELinux integration SELinux bases access to files on the domain of the requesting process, the operation being performed, and the context applied to the file. @@ -35,6 +35,8 @@ stomp all over us. The selabel APIs for looking up the context should be thread-safe (per Red Hat #273081), so switching to using them instead of matchpathcon(), which we used earlier, is some improvement. + +Last-updated: krb5-1.18-beta1 --- src/aclocal.m4 | 48 +++ src/build-tools/krb5-config.in | 3 +- diff --git a/Use-backported-version-of-OpenSSL-3-KDF-interface.patch b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch similarity index 99% rename from Use-backported-version-of-OpenSSL-3-KDF-interface.patch rename to downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch index d0f57c8..4a2bfd3 100644 --- a/Use-backported-version-of-OpenSSL-3-KDF-interface.patch +++ b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch @@ -1,8 +1,10 @@ -From 9d887898571744f5ea0a523c7fba9d86d9cf8588 Mon Sep 17 00:00:00 2001 +From 6015b8b21da26d4b2845ffad8fee3442402ea709 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 15 Nov 2019 20:05:16 +0000 -Subject: [PATCH] Use backported version of OpenSSL-3 KDF interface +Subject: [PATCH] [downstream] Use backported version of OpenSSL-3 KDF + interface +Last-updated: krb5-1.17 --- src/configure.ac | 4 + src/lib/crypto/krb/derive.c | 356 +++++++++++++----- diff --git a/krb5-1.9-debuginfo.patch b/downstream-fix-debuginfo-with-y.tab.c.patch similarity index 90% rename from krb5-1.9-debuginfo.patch rename to downstream-fix-debuginfo-with-y.tab.c.patch index adb6219..daa2da5 100644 --- a/krb5-1.9-debuginfo.patch +++ b/downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,11 +1,13 @@ -From c26cf6cc3507ba63cb458094b9237ad2231ca5eb Mon Sep 17 00:00:00 2001 +From c0eb69736c57f791802ba9d2ce8a2c987bb538ba Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 -Subject: [PATCH] krb5-1.9-debuginfo.patch +Subject: [PATCH] [downstream] fix debuginfo with y.tab.c We want to keep these y.tab.c files around because the debuginfo points to them. It would be more elegant at the end to use symbolic links, but that could mess up people working in the tree on other things. + +Last-updated: krb5-1.9 --- src/kadmin/cli/Makefile.in | 5 +++++ src/plugins/kdb/ldap/ldap_util/Makefile.in | 2 +- diff --git a/krb5-1.18beta1-pam.patch b/downstream-ksu-pam-integration.patch similarity index 99% rename from krb5-1.18beta1-pam.patch rename to downstream-ksu-pam-integration.patch index c785c7c..98838df 100644 --- a/krb5-1.18beta1-pam.patch +++ b/downstream-ksu-pam-integration.patch @@ -1,7 +1,7 @@ -From 9d77eb513f95821f01f12e233e16d4ce50da7d23 Mon Sep 17 00:00:00 2001 +From f59ec1fb55c13b0b0da413930d84a7c73019ed2b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 -Subject: [PATCH] krb5-1.18beta1-pam.patch +Subject: [PATCH] [downstream] ksu pam integration Modify ksu so that it performs account and session management on behalf of the target user account, mimicking the action of regular su. The default @@ -16,6 +16,8 @@ When enabled, ksu gains a dependency on libpam. Originally RT#5939, though it's changed since then to perform the account and session management before dropping privileges, and to apply on top of changes we're proposing for how it handles cache collections. + +Last-updated: krb5-1.18-beta1 --- src/aclocal.m4 | 69 +++++++ src/clients/ksu/Makefile.in | 8 +- diff --git a/krb5-1.3.1-dns.patch b/downstream-netlib-and-dns.patch similarity index 80% rename from krb5-1.3.1-dns.patch rename to downstream-netlib-and-dns.patch index 2ae1f8e..284c164 100644 --- a/krb5-1.3.1-dns.patch +++ b/downstream-netlib-and-dns.patch @@ -1,9 +1,11 @@ -From fe90cb8f915e7f43899437e5e2d9a3aebf23ed82 Mon Sep 17 00:00:00 2001 +From 080082e5a62475fa10da0f9476cac69231f13de0 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 -Subject: [PATCH] krb5-1.3.1-dns.patch +Subject: [PATCH] [downstream] netlib and dns We want to be able to use --with-netlib and --enable-dns at the same time. + +Last-updated: krb5-1.3.1 --- src/aclocal.m4 | 1 + 1 file changed, 1 insertion(+) diff --git a/krb5.spec b/krb5.spec index ffb7285..b2454fc 100644 --- a/krb5.spec +++ b/krb5.spec @@ -9,7 +9,7 @@ %global configured_default_ccache_name KEYRING:persistent:%%{uid} # leave empty or set to e.g., -beta2 -%global prerelease -beta1 +%global prerelease -beta2 # Should be in form 5.0, 6.1, etc. %global kdbversion 8.0 @@ -18,11 +18,11 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 0.beta1.1%{?dist}.1 +Release: 0.beta2.1%{?dist} # rharwood has trust path to signing key and verifies on check-in -Source0: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz -Source1: https://web.mit.edu/kerberos/dist/krb5/1.17/krb5-%{version}%{prerelease}.tar.gz.asc +Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz +Source1: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz.asc # Numbering is a relic of old init systems etc. It's easiest to just leave. Source2: kprop.service @@ -42,14 +42,14 @@ Source39: krb5-krb5kdc.conf # Carry this locally until it's available in a packaged form. Source100: noport.c -Patch1: krb5-1.18beta1-pam.patch -Patch2: krb5-1.18-beta1-selinux-label.patch -Patch30: krb5-1.15-beta1-buildconf.patch -Patch31: krb5-1.3.1-dns.patch -Patch34: krb5-1.9-debuginfo.patch -Patch35: krb5-1.18-beta1-Remove-3des-support.patch -Patch169: Use-backported-version-of-OpenSSL-3-KDF-interface.patch -Patch170: krb5-1.17post6-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +Patch0: downstream-ksu-pam-integration.patch +Patch1: downstream-SELinux-integration.patch +Patch2: downstream-Adjust-build-configuration.patch +Patch3: downstream-netlib-and-dns.patch +Patch4: downstream-fix-debuginfo-with-y.tab.c.patch +Patch5: downstream-Remove-3des-support.patch +Patch6: downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch +Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -623,10 +623,11 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog -* Wed Jan 29 2020 Fedora Release Engineering - 1.18-0.beta1.1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild +* Fri Jan 31 2020 Robbie Harwood - 1.18-0.beta2.1 +- New upstream beta release - 1.18-beta2 +- Adjust naming convention for downstream patches -* Fri Jan 10 2020 Robbie Harwood - 1.18-0beta1.1 +* Fri Jan 10 2020 Robbie Harwood - 1.18-0.beta1.1 - New upstream beta release - 1.18-beta1 * Wed Jan 08 2020 Robbie Harwood - 1.17.1-5 diff --git a/sources b/sources index 3b304f6..56ba25c 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.18-beta1.tar.gz) = e9e622350c9d07bca573d1e416a7277377e85c0f3eab605d3f551f96c5ddc7eb21e8ef2cfadddbac7d9da99a204d738fd22939cfb23d7fcc8166e8ae35a679a4 -SHA512 (krb5-1.18-beta1.tar.gz.asc) = b8542e317db89d11ad29bba9bc55f4d294e649b0e8c28b37dde398fed64fa3da394af262225ebefda5e5f3224ba108df21af460837e72a4349ae7e6469e21e43 +SHA512 (krb5-1.18-beta2.tar.gz) = 1805c56dd6bde929aeaaf82fe20a3485daef5b2730bd74b92e3351b63d99f96c8523d43c5814b1e65b5c293252df7a70e9584530f49734ccad433d4c6c5a392e +SHA512 (krb5-1.18-beta2.tar.gz.asc) = f437c43e7295365f5dc561b66ec67b90b30c2300ca2c89b2bf0570ad8aa2df4f78f160d0026f3e21b36898d74b5434ce55819d8bdf9b4a535c814cedfdb294b2 From edfb00e0013485d25cf4e3edaa0f4e28d57eb831 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 6 Feb 2020 10:17:38 -0500 Subject: [PATCH 149/304] Put KDB authdata first --- Put-KDB-authdata-first.patch | 44 ++++++ ...at-PAC-is-the-first-authdata-element.patch | 147 ++++++++++++++++++ krb5.spec | 7 +- 3 files changed, 197 insertions(+), 1 deletion(-) create mode 100644 Put-KDB-authdata-first.patch create mode 100644 Test-that-PAC-is-the-first-authdata-element.patch diff --git a/Put-KDB-authdata-first.patch b/Put-KDB-authdata-first.patch new file mode 100644 index 0000000..d8c1c9c --- /dev/null +++ b/Put-KDB-authdata-first.patch @@ -0,0 +1,44 @@ +From 1678270de3fda699114122447b1f06b08fb4e53e Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Sat, 1 Feb 2020 16:13:30 +0100 +Subject: [PATCH] Put KDB authdata first + +Windows services, as well as some versions of Samba, may refuse +tickets if the PAC is not in the first AD-IF-RELEVANT container. In +fetch_kdb_authdata(), change the merge order so that authdata from the +KDB module appears first. + +[ghudson@mit.edu: added comment and clarified commit message] + +ticket: 8872 (new) +tags: pullup +target_version: 1.18 +target_version: 1.17-next + +(cherry picked from commit 331fa4bdd34263ea20667a0f51338cb84357fdaa) +--- + src/kdc/kdc_authdata.c | 9 ++++++--- + 1 file changed, 6 insertions(+), 3 deletions(-) + +diff --git a/src/kdc/kdc_authdata.c b/src/kdc/kdc_authdata.c +index a18e4b4be..1ebe87246 100644 +--- a/src/kdc/kdc_authdata.c ++++ b/src/kdc/kdc_authdata.c +@@ -372,11 +372,14 @@ fetch_kdb_authdata(krb5_context context, unsigned int flags, + if (ret) + return (ret == KRB5_PLUGIN_OP_NOTSUPP) ? 0 : ret; + +- /* Add the KDB authdata to the ticket, without copying or filtering. */ +- ret = merge_authdata(context, db_authdata, +- &enc_tkt_reply->authorization_data, FALSE, FALSE); ++ /* Put the KDB authdata first in the ticket. A successful merge places the ++ * combined list in db_authdata and releases the old ticket authdata. */ ++ ret = merge_authdata(context, enc_tkt_reply->authorization_data, ++ &db_authdata, FALSE, FALSE); + if (ret) + krb5_free_authdata(context, db_authdata); ++ else ++ enc_tkt_reply->authorization_data = db_authdata; + return ret; + } + diff --git a/Test-that-PAC-is-the-first-authdata-element.patch b/Test-that-PAC-is-the-first-authdata-element.patch new file mode 100644 index 0000000..acda89e --- /dev/null +++ b/Test-that-PAC-is-the-first-authdata-element.patch @@ -0,0 +1,147 @@ +From a3b82f95570e39c8689f5ce1bbcc80ad99483323 Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Sat, 1 Feb 2020 13:21:39 +0100 +Subject: [PATCH] Test that PAC is the first authdata element + +In the test KDB module, set the PAC as the first authdata element. In +adata.c, add PAC service verification and verify that a PAC does not +appear in authdata elements after the first. + +[ghudson@mit.edu: minor style changes; edited commit message] + +ticket: 8872 +(cherry picked from commit d40d7c8ee8d7fb547e45c545365b21a818050130) +--- + src/plugins/kdb/test/kdb_test.c | 7 +++-- + src/tests/adata.c | 54 ++++++++++++++++++++++++++++----- + 2 files changed, 51 insertions(+), 10 deletions(-) + +diff --git a/src/plugins/kdb/test/kdb_test.c b/src/plugins/kdb/test/kdb_test.c +index d95a7fa5d..1936cb0e4 100644 +--- a/src/plugins/kdb/test/kdb_test.c ++++ b/src/plugins/kdb/test/kdb_test.c +@@ -897,10 +897,11 @@ test_sign_authdata(krb5_context context, unsigned int flags, + test_ad->contents = (uint8_t *)estrdup("db-authdata-test"); + test_ad->length = strlen((char *)test_ad->contents); + +- /* Assemble the authdata into a one-element or two-element list. */ ++ /* Assemble the authdata into a one-element or two-element list. ++ * The PAC must be the first element. */ + list = ealloc(3 * sizeof(*list)); +- list[0] = test_ad; +- list[1] = pac_ad; ++ list[0] = (pac_ad != NULL) ? pac_ad : test_ad; ++ list[1] = (pac_ad != NULL) ? test_ad : NULL; + list[2] = NULL; + *signed_auth_data = list; + +diff --git a/src/tests/adata.c b/src/tests/adata.c +index d3bd08e30..3869aec1d 100644 +--- a/src/tests/adata.c ++++ b/src/tests/adata.c +@@ -56,7 +56,8 @@ + static krb5_context ctx; + + static void display_authdata_list(krb5_authdata **list, krb5_keyblock *skey, +- krb5_keyblock *tktkey, char prefix_byte); ++ krb5_keyblock *tktkey, char prefix_byte, ++ krb5_boolean pac_expected); + + static void + check(krb5_error_code code) +@@ -206,7 +207,7 @@ display_binary_or_ascii(krb5_authdata *ad) + * must be the ticket session key. */ + static void + display_authdata(krb5_authdata *ad, krb5_keyblock *skey, krb5_keyblock *tktkey, +- int prefix_byte) ++ int prefix_byte, krb5_boolean pac_expected) + { + krb5_authdata **inner_ad; + +@@ -214,13 +215,18 @@ display_authdata(krb5_authdata *ad, krb5_keyblock *skey, krb5_keyblock *tktkey, + ad->ad_type == KRB5_AUTHDATA_MANDATORY_FOR_KDC || + ad->ad_type == KRB5_AUTHDATA_KDC_ISSUED || + ad->ad_type == KRB5_AUTHDATA_CAMMAC) { ++ if (ad->ad_type != KRB5_AUTHDATA_IF_RELEVANT) ++ pac_expected = FALSE; + /* Decode and display the contents. */ + inner_ad = get_container_contents(ad, skey, tktkey); +- display_authdata_list(inner_ad, skey, tktkey, get_prefix_byte(ad)); ++ display_authdata_list(inner_ad, skey, tktkey, get_prefix_byte(ad), ++ pac_expected); + krb5_free_authdata(ctx, inner_ad); + return; + } + ++ assert(!pac_expected || ad->ad_type == KRB5_AUTHDATA_WIN2K_PAC); ++ + printf("%c", prefix_byte); + printf("%d: ", (int)ad->ad_type); + +@@ -233,12 +239,43 @@ display_authdata(krb5_authdata *ad, krb5_keyblock *skey, krb5_keyblock *tktkey, + + static void + display_authdata_list(krb5_authdata **list, krb5_keyblock *skey, +- krb5_keyblock *tktkey, char prefix_byte) ++ krb5_keyblock *tktkey, char prefix_byte, ++ krb5_boolean pac_expected) + { + if (list == NULL) + return; +- for (; *list != NULL; list++) +- display_authdata(*list, skey, tktkey, prefix_byte); ++ /* Only expect a PAC in the first element, if at all. */ ++ for (; *list != NULL; list++) { ++ display_authdata(*list, skey, tktkey, prefix_byte, pac_expected); ++ pac_expected = FALSE; ++ } ++} ++ ++/* If a PAC is present in enc_part2, verify its service signature with key and ++ * set *has_pac to true. */ ++static void ++check_pac(krb5_context context, krb5_enc_tkt_part *enc_part2, ++ const krb5_keyblock *key, krb5_boolean *has_pac) ++{ ++ krb5_authdata **authdata; ++ krb5_pac pac; ++ ++ *has_pac = FALSE; ++ ++ check(krb5_find_authdata(context, enc_part2->authorization_data, NULL, ++ KRB5_AUTHDATA_WIN2K_PAC, &authdata)); ++ if (authdata == NULL) ++ return; ++ ++ assert(authdata[1] == NULL); ++ check(krb5_pac_parse(context, authdata[0]->contents, authdata[0]->length, ++ &pac)); ++ krb5_free_authdata(context, authdata); ++ ++ check(krb5_pac_verify(context, pac, enc_part2->times.authtime, ++ enc_part2->client, key, NULL)); ++ krb5_pac_free(context, pac); ++ *has_pac = TRUE; + } + + int +@@ -252,6 +289,7 @@ main(int argc, char **argv) + krb5_ticket *ticket; + krb5_authdata **req_authdata = NULL, *ad; + krb5_keytab_entry ktent; ++ krb5_boolean with_pac; + size_t count; + int c; + +@@ -311,8 +349,10 @@ main(int argc, char **argv) + ticket->enc_part.enctype, &ktent)); + check(krb5_decrypt_tkt_part(ctx, &ktent.key, ticket)); + ++ check_pac(ctx, ticket->enc_part2, &ktent.key, &with_pac); + display_authdata_list(ticket->enc_part2->authorization_data, +- ticket->enc_part2->session, &ktent.key, ' '); ++ ticket->enc_part2->session, &ktent.key, ' ', ++ with_pac); + + while (count > 0) { + free(req_authdata[--count]->contents); diff --git a/krb5.spec b/krb5.spec index b2454fc..73216f6 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 0.beta2.1%{?dist} +Release: 0.beta2.2%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -50,6 +50,8 @@ Patch4: downstream-fix-debuginfo-with-y.tab.c.patch Patch5: downstream-Remove-3des-support.patch Patch6: downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +Patch8: Put-KDB-authdata-first.patch +Patch9: Test-that-PAC-is-the-first-authdata-element.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -623,6 +625,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Feb 06 2020 Robbie Harwood - 1.18-0.beta2.2 +- Put KDB authdata first + * Fri Jan 31 2020 Robbie Harwood - 1.18-0.beta2.1 - New upstream beta release - 1.18-beta2 - Adjust naming convention for downstream patches From dd3e136188bd2c37d9aa0f8eb0f21d98127e6fab Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 7 Feb 2020 10:59:57 -0500 Subject: [PATCH 150/304] Don't assume OpenSSL failures are memory errors --- ...e-OpenSSL-failures-are-memory-errors.patch | 44 +++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 49 insertions(+), 1 deletion(-) create mode 100644 Don-t-assume-OpenSSL-failures-are-memory-errors.patch diff --git a/Don-t-assume-OpenSSL-failures-are-memory-errors.patch b/Don-t-assume-OpenSSL-failures-are-memory-errors.patch new file mode 100644 index 0000000..151e523 --- /dev/null +++ b/Don-t-assume-OpenSSL-failures-are-memory-errors.patch @@ -0,0 +1,44 @@ +From 4951953618e5b53a571c4d1e4fcb5e6b14fbe004 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 5 Feb 2020 12:56:00 -0500 +Subject: [PATCH] Don't assume OpenSSL failures are memory errors + +More recent versions of OpenSSL can fail for other reasons. Indicate +a crypto-related error occurred rather than a memory error to aid +debugging. + +ticket: 8873 (new) +tags: pullup +target_version: 1.18 +target_version: 1.17-next + +(cherry picked from commit bf9b2134ceddd6c727362be894b1c95c297a0f17) +--- + src/lib/crypto/openssl/hash_provider/hash_evp.c | 2 +- + src/lib/crypto/openssl/sha256.c | 2 +- + 2 files changed, 2 insertions(+), 2 deletions(-) + +diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c +index 915da9dbe..feb5eda99 100644 +--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c ++++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c +@@ -63,7 +63,7 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, + } + ok = ok && EVP_DigestFinal_ex(ctx, (uint8_t *)output->data, NULL); + EVP_MD_CTX_free(ctx); +- return ok ? 0 : ENOMEM; ++ return ok ? 0 : KRB5_CRYPTO_INTERNAL; + } + + static krb5_error_code +diff --git a/src/lib/crypto/openssl/sha256.c b/src/lib/crypto/openssl/sha256.c +index 0edd8b7ba..f9dfc8539 100644 +--- a/src/lib/crypto/openssl/sha256.c ++++ b/src/lib/crypto/openssl/sha256.c +@@ -48,5 +48,5 @@ k5_sha256(const krb5_data *in, size_t n, uint8_t out[K5_SHA256_HASHLEN]) + ok = ok && EVP_DigestUpdate(ctx, in[i].data, in[i].length); + ok = ok && EVP_DigestFinal_ex(ctx, out, NULL); + EVP_MD_CTX_free(ctx); +- return ok ? 0 : ENOMEM; ++ return ok ? 0 : KRB5_CRYPTO_INTERNAL; + } diff --git a/krb5.spec b/krb5.spec index 73216f6..aa68ebf 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 0.beta2.2%{?dist} +Release: 0.beta2.3%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -52,6 +52,7 @@ Patch6: downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch Patch8: Put-KDB-authdata-first.patch Patch9: Test-that-PAC-is-the-first-authdata-element.patch +Patch10: Don-t-assume-OpenSSL-failures-are-memory-errors.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -625,6 +626,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Feb 07 2020 Robbie Harwood - 1.18-0.beta2.3 +- Don't assume OpenSSL failures are memory errors + * Thu Feb 06 2020 Robbie Harwood - 1.18-0.beta2.2 - Put KDB authdata first From f287f939a9f12f91c63142fc1aa12c7163c0f43b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 12 Feb 2020 22:29:13 +0000 Subject: [PATCH 151/304] New upstream version (1.18) --- .gitignore | 2 + ...e-OpenSSL-failures-are-memory-errors.patch | 44 ------ Put-KDB-authdata-first.patch | 44 ------ ...at-PAC-is-the-first-authdata-element.patch | 147 ------------------ downstream-Adjust-build-configuration.patch | 2 +- ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 4 +- downstream-Remove-3des-support.patch | 4 +- downstream-SELinux-integration.patch | 2 +- ...ackported-version-of-OpenSSL-3-KDF-i.patch | 2 +- downstream-fix-debuginfo-with-y.tab.c.patch | 2 +- downstream-ksu-pam-integration.patch | 2 +- downstream-netlib-and-dns.patch | 2 +- krb5.spec | 10 +- sources | 4 +- 14 files changed, 19 insertions(+), 252 deletions(-) delete mode 100644 Don-t-assume-OpenSSL-failures-are-memory-errors.patch delete mode 100644 Put-KDB-authdata-first.patch delete mode 100644 Test-that-PAC-is-the-first-authdata-element.patch diff --git a/.gitignore b/.gitignore index 1b6f6a6..88fde60 100644 --- a/.gitignore +++ b/.gitignore @@ -181,3 +181,5 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.18-beta1.tar.gz.asc /krb5-1.18-beta2.tar.gz /krb5-1.18-beta2.tar.gz.asc +/krb5-1.18.tar.gz +/krb5-1.18.tar.gz.asc diff --git a/Don-t-assume-OpenSSL-failures-are-memory-errors.patch b/Don-t-assume-OpenSSL-failures-are-memory-errors.patch deleted file mode 100644 index 151e523..0000000 --- a/Don-t-assume-OpenSSL-failures-are-memory-errors.patch +++ /dev/null @@ -1,44 +0,0 @@ -From 4951953618e5b53a571c4d1e4fcb5e6b14fbe004 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 5 Feb 2020 12:56:00 -0500 -Subject: [PATCH] Don't assume OpenSSL failures are memory errors - -More recent versions of OpenSSL can fail for other reasons. Indicate -a crypto-related error occurred rather than a memory error to aid -debugging. - -ticket: 8873 (new) -tags: pullup -target_version: 1.18 -target_version: 1.17-next - -(cherry picked from commit bf9b2134ceddd6c727362be894b1c95c297a0f17) ---- - src/lib/crypto/openssl/hash_provider/hash_evp.c | 2 +- - src/lib/crypto/openssl/sha256.c | 2 +- - 2 files changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c -index 915da9dbe..feb5eda99 100644 ---- a/src/lib/crypto/openssl/hash_provider/hash_evp.c -+++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c -@@ -63,7 +63,7 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, - } - ok = ok && EVP_DigestFinal_ex(ctx, (uint8_t *)output->data, NULL); - EVP_MD_CTX_free(ctx); -- return ok ? 0 : ENOMEM; -+ return ok ? 0 : KRB5_CRYPTO_INTERNAL; - } - - static krb5_error_code -diff --git a/src/lib/crypto/openssl/sha256.c b/src/lib/crypto/openssl/sha256.c -index 0edd8b7ba..f9dfc8539 100644 ---- a/src/lib/crypto/openssl/sha256.c -+++ b/src/lib/crypto/openssl/sha256.c -@@ -48,5 +48,5 @@ k5_sha256(const krb5_data *in, size_t n, uint8_t out[K5_SHA256_HASHLEN]) - ok = ok && EVP_DigestUpdate(ctx, in[i].data, in[i].length); - ok = ok && EVP_DigestFinal_ex(ctx, out, NULL); - EVP_MD_CTX_free(ctx); -- return ok ? 0 : ENOMEM; -+ return ok ? 0 : KRB5_CRYPTO_INTERNAL; - } diff --git a/Put-KDB-authdata-first.patch b/Put-KDB-authdata-first.patch deleted file mode 100644 index d8c1c9c..0000000 --- a/Put-KDB-authdata-first.patch +++ /dev/null @@ -1,44 +0,0 @@ -From 1678270de3fda699114122447b1f06b08fb4e53e Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Sat, 1 Feb 2020 16:13:30 +0100 -Subject: [PATCH] Put KDB authdata first - -Windows services, as well as some versions of Samba, may refuse -tickets if the PAC is not in the first AD-IF-RELEVANT container. In -fetch_kdb_authdata(), change the merge order so that authdata from the -KDB module appears first. - -[ghudson@mit.edu: added comment and clarified commit message] - -ticket: 8872 (new) -tags: pullup -target_version: 1.18 -target_version: 1.17-next - -(cherry picked from commit 331fa4bdd34263ea20667a0f51338cb84357fdaa) ---- - src/kdc/kdc_authdata.c | 9 ++++++--- - 1 file changed, 6 insertions(+), 3 deletions(-) - -diff --git a/src/kdc/kdc_authdata.c b/src/kdc/kdc_authdata.c -index a18e4b4be..1ebe87246 100644 ---- a/src/kdc/kdc_authdata.c -+++ b/src/kdc/kdc_authdata.c -@@ -372,11 +372,14 @@ fetch_kdb_authdata(krb5_context context, unsigned int flags, - if (ret) - return (ret == KRB5_PLUGIN_OP_NOTSUPP) ? 0 : ret; - -- /* Add the KDB authdata to the ticket, without copying or filtering. */ -- ret = merge_authdata(context, db_authdata, -- &enc_tkt_reply->authorization_data, FALSE, FALSE); -+ /* Put the KDB authdata first in the ticket. A successful merge places the -+ * combined list in db_authdata and releases the old ticket authdata. */ -+ ret = merge_authdata(context, enc_tkt_reply->authorization_data, -+ &db_authdata, FALSE, FALSE); - if (ret) - krb5_free_authdata(context, db_authdata); -+ else -+ enc_tkt_reply->authorization_data = db_authdata; - return ret; - } - diff --git a/Test-that-PAC-is-the-first-authdata-element.patch b/Test-that-PAC-is-the-first-authdata-element.patch deleted file mode 100644 index acda89e..0000000 --- a/Test-that-PAC-is-the-first-authdata-element.patch +++ /dev/null @@ -1,147 +0,0 @@ -From a3b82f95570e39c8689f5ce1bbcc80ad99483323 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Sat, 1 Feb 2020 13:21:39 +0100 -Subject: [PATCH] Test that PAC is the first authdata element - -In the test KDB module, set the PAC as the first authdata element. In -adata.c, add PAC service verification and verify that a PAC does not -appear in authdata elements after the first. - -[ghudson@mit.edu: minor style changes; edited commit message] - -ticket: 8872 -(cherry picked from commit d40d7c8ee8d7fb547e45c545365b21a818050130) ---- - src/plugins/kdb/test/kdb_test.c | 7 +++-- - src/tests/adata.c | 54 ++++++++++++++++++++++++++++----- - 2 files changed, 51 insertions(+), 10 deletions(-) - -diff --git a/src/plugins/kdb/test/kdb_test.c b/src/plugins/kdb/test/kdb_test.c -index d95a7fa5d..1936cb0e4 100644 ---- a/src/plugins/kdb/test/kdb_test.c -+++ b/src/plugins/kdb/test/kdb_test.c -@@ -897,10 +897,11 @@ test_sign_authdata(krb5_context context, unsigned int flags, - test_ad->contents = (uint8_t *)estrdup("db-authdata-test"); - test_ad->length = strlen((char *)test_ad->contents); - -- /* Assemble the authdata into a one-element or two-element list. */ -+ /* Assemble the authdata into a one-element or two-element list. -+ * The PAC must be the first element. */ - list = ealloc(3 * sizeof(*list)); -- list[0] = test_ad; -- list[1] = pac_ad; -+ list[0] = (pac_ad != NULL) ? pac_ad : test_ad; -+ list[1] = (pac_ad != NULL) ? test_ad : NULL; - list[2] = NULL; - *signed_auth_data = list; - -diff --git a/src/tests/adata.c b/src/tests/adata.c -index d3bd08e30..3869aec1d 100644 ---- a/src/tests/adata.c -+++ b/src/tests/adata.c -@@ -56,7 +56,8 @@ - static krb5_context ctx; - - static void display_authdata_list(krb5_authdata **list, krb5_keyblock *skey, -- krb5_keyblock *tktkey, char prefix_byte); -+ krb5_keyblock *tktkey, char prefix_byte, -+ krb5_boolean pac_expected); - - static void - check(krb5_error_code code) -@@ -206,7 +207,7 @@ display_binary_or_ascii(krb5_authdata *ad) - * must be the ticket session key. */ - static void - display_authdata(krb5_authdata *ad, krb5_keyblock *skey, krb5_keyblock *tktkey, -- int prefix_byte) -+ int prefix_byte, krb5_boolean pac_expected) - { - krb5_authdata **inner_ad; - -@@ -214,13 +215,18 @@ display_authdata(krb5_authdata *ad, krb5_keyblock *skey, krb5_keyblock *tktkey, - ad->ad_type == KRB5_AUTHDATA_MANDATORY_FOR_KDC || - ad->ad_type == KRB5_AUTHDATA_KDC_ISSUED || - ad->ad_type == KRB5_AUTHDATA_CAMMAC) { -+ if (ad->ad_type != KRB5_AUTHDATA_IF_RELEVANT) -+ pac_expected = FALSE; - /* Decode and display the contents. */ - inner_ad = get_container_contents(ad, skey, tktkey); -- display_authdata_list(inner_ad, skey, tktkey, get_prefix_byte(ad)); -+ display_authdata_list(inner_ad, skey, tktkey, get_prefix_byte(ad), -+ pac_expected); - krb5_free_authdata(ctx, inner_ad); - return; - } - -+ assert(!pac_expected || ad->ad_type == KRB5_AUTHDATA_WIN2K_PAC); -+ - printf("%c", prefix_byte); - printf("%d: ", (int)ad->ad_type); - -@@ -233,12 +239,43 @@ display_authdata(krb5_authdata *ad, krb5_keyblock *skey, krb5_keyblock *tktkey, - - static void - display_authdata_list(krb5_authdata **list, krb5_keyblock *skey, -- krb5_keyblock *tktkey, char prefix_byte) -+ krb5_keyblock *tktkey, char prefix_byte, -+ krb5_boolean pac_expected) - { - if (list == NULL) - return; -- for (; *list != NULL; list++) -- display_authdata(*list, skey, tktkey, prefix_byte); -+ /* Only expect a PAC in the first element, if at all. */ -+ for (; *list != NULL; list++) { -+ display_authdata(*list, skey, tktkey, prefix_byte, pac_expected); -+ pac_expected = FALSE; -+ } -+} -+ -+/* If a PAC is present in enc_part2, verify its service signature with key and -+ * set *has_pac to true. */ -+static void -+check_pac(krb5_context context, krb5_enc_tkt_part *enc_part2, -+ const krb5_keyblock *key, krb5_boolean *has_pac) -+{ -+ krb5_authdata **authdata; -+ krb5_pac pac; -+ -+ *has_pac = FALSE; -+ -+ check(krb5_find_authdata(context, enc_part2->authorization_data, NULL, -+ KRB5_AUTHDATA_WIN2K_PAC, &authdata)); -+ if (authdata == NULL) -+ return; -+ -+ assert(authdata[1] == NULL); -+ check(krb5_pac_parse(context, authdata[0]->contents, authdata[0]->length, -+ &pac)); -+ krb5_free_authdata(context, authdata); -+ -+ check(krb5_pac_verify(context, pac, enc_part2->times.authtime, -+ enc_part2->client, key, NULL)); -+ krb5_pac_free(context, pac); -+ *has_pac = TRUE; - } - - int -@@ -252,6 +289,7 @@ main(int argc, char **argv) - krb5_ticket *ticket; - krb5_authdata **req_authdata = NULL, *ad; - krb5_keytab_entry ktent; -+ krb5_boolean with_pac; - size_t count; - int c; - -@@ -311,8 +349,10 @@ main(int argc, char **argv) - ticket->enc_part.enctype, &ktent)); - check(krb5_decrypt_tkt_part(ctx, &ktent.key, ticket)); - -+ check_pac(ctx, ticket->enc_part2, &ktent.key, &with_pac); - display_authdata_list(ticket->enc_part2->authorization_data, -- ticket->enc_part2->session, &ktent.key, ' '); -+ ticket->enc_part2->session, &ktent.key, ' ', -+ with_pac); - - while (count > 0) { - free(req_authdata[--count]->contents); diff --git a/downstream-Adjust-build-configuration.patch b/downstream-Adjust-build-configuration.patch index 6fecd56..68ecf50 100644 --- a/downstream-Adjust-build-configuration.patch +++ b/downstream-Adjust-build-configuration.patch @@ -1,4 +1,4 @@ -From 74e18ba4575ed2fbf67dd57c3712f01ecba76932 Mon Sep 17 00:00:00 2001 +From cbfe13d5f0de6e2a3deab2ba0dacda8c952476ab Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] [downstream] Adjust build configuration diff --git a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index f0219e3..573d222 100644 --- a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From 494658b52c8aebd7d31d51faa4eb498b6e6843ed Mon Sep 17 00:00:00 2001 +From 5978878bcee5ec39e4357f408470d39e9540d2bf Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 @@ -129,7 +129,7 @@ index a65d57b7a..6ccaca94a 100644 * The cipher state here is a saved pointer to a struct arcfour_state * object, rather than a flat byte array as in most enc providers. The diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c -index 957ed8d9c..915da9dbe 100644 +index 1e0fb8fc3..feb5eda99 100644 --- a/src/lib/crypto/openssl/hash_provider/hash_evp.c +++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c @@ -49,6 +49,11 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, diff --git a/downstream-Remove-3des-support.patch b/downstream-Remove-3des-support.patch index 001b2d3..4f14733 100644 --- a/downstream-Remove-3des-support.patch +++ b/downstream-Remove-3des-support.patch @@ -1,4 +1,4 @@ -From 0153147f716b8f8710fd307df54908267779c3a4 Mon Sep 17 00:00:00 2001 +From 7dda569170c3f6ab08a9373572b4bc90481eeaf7 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] [downstream] Remove 3des support @@ -269,7 +269,7 @@ index fc5662767..37eda67fa 100644 .. |copy| unicode:: U+000A9 ''' diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst -index a7e55f206..77c095c75 100644 +index 513ecfd1b..05243f47b 100644 --- a/doc/mitK5features.rst +++ b/doc/mitK5features.rst @@ -37,7 +37,7 @@ Database backends: LDAP, DB2, LMDB diff --git a/downstream-SELinux-integration.patch b/downstream-SELinux-integration.patch index 52d4607..e40bd1a 100644 --- a/downstream-SELinux-integration.patch +++ b/downstream-SELinux-integration.patch @@ -1,4 +1,4 @@ -From bbdfaec5156307c791804c6eb5ed8c2eefff1318 Mon Sep 17 00:00:00 2001 +From 4a215a206d1d5af69ea9fbf1e78001971ab18be2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] [downstream] SELinux integration diff --git a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch index 4a2bfd3..b796692 100644 --- a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch +++ b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch @@ -1,4 +1,4 @@ -From 6015b8b21da26d4b2845ffad8fee3442402ea709 Mon Sep 17 00:00:00 2001 +From 0a53577ebb24f0f9b05d769b34bdd4ef2ee2a629 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 15 Nov 2019 20:05:16 +0000 Subject: [PATCH] [downstream] Use backported version of OpenSSL-3 KDF diff --git a/downstream-fix-debuginfo-with-y.tab.c.patch b/downstream-fix-debuginfo-with-y.tab.c.patch index daa2da5..e8e1870 100644 --- a/downstream-fix-debuginfo-with-y.tab.c.patch +++ b/downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,4 +1,4 @@ -From c0eb69736c57f791802ba9d2ce8a2c987bb538ba Mon Sep 17 00:00:00 2001 +From ed161c3f3cb642d025f0fee6d4af6f56bba711e9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] [downstream] fix debuginfo with y.tab.c diff --git a/downstream-ksu-pam-integration.patch b/downstream-ksu-pam-integration.patch index 98838df..4532601 100644 --- a/downstream-ksu-pam-integration.patch +++ b/downstream-ksu-pam-integration.patch @@ -1,4 +1,4 @@ -From f59ec1fb55c13b0b0da413930d84a7c73019ed2b Mon Sep 17 00:00:00 2001 +From 9a082e1e02ae4efd2404d0672d38b3d4eb2d6660 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] [downstream] ksu pam integration diff --git a/downstream-netlib-and-dns.patch b/downstream-netlib-and-dns.patch index 284c164..ba04deb 100644 --- a/downstream-netlib-and-dns.patch +++ b/downstream-netlib-and-dns.patch @@ -1,4 +1,4 @@ -From 080082e5a62475fa10da0f9476cac69231f13de0 Mon Sep 17 00:00:00 2001 +From 40553473b674dfbb6328389b6b39ebe3218ed597 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] [downstream] netlib and dns diff --git a/krb5.spec b/krb5.spec index aa68ebf..45b6ee3 100644 --- a/krb5.spec +++ b/krb5.spec @@ -9,7 +9,7 @@ %global configured_default_ccache_name KEYRING:persistent:%%{uid} # leave empty or set to e.g., -beta2 -%global prerelease -beta2 +%global prerelease %{nil} # Should be in form 5.0, 6.1, etc. %global kdbversion 8.0 @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 0.beta2.3%{?dist} +Release: 1 # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -50,9 +50,6 @@ Patch4: downstream-fix-debuginfo-with-y.tab.c.patch Patch5: downstream-Remove-3des-support.patch Patch6: downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch -Patch8: Put-KDB-authdata-first.patch -Patch9: Test-that-PAC-is-the-first-authdata-element.patch -Patch10: Don-t-assume-OpenSSL-failures-are-memory-errors.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -626,6 +623,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Feb 12 2020 Robbie Harwood - 1.18-1 +- New upstream version (1.18) + * Fri Feb 07 2020 Robbie Harwood - 1.18-0.beta2.3 - Don't assume OpenSSL failures are memory errors diff --git a/sources b/sources index 56ba25c..d851b71 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.18-beta2.tar.gz) = 1805c56dd6bde929aeaaf82fe20a3485daef5b2730bd74b92e3351b63d99f96c8523d43c5814b1e65b5c293252df7a70e9584530f49734ccad433d4c6c5a392e -SHA512 (krb5-1.18-beta2.tar.gz.asc) = f437c43e7295365f5dc561b66ec67b90b30c2300ca2c89b2bf0570ad8aa2df4f78f160d0026f3e21b36898d74b5434ce55819d8bdf9b4a535c814cedfdb294b2 +SHA512 (krb5-1.18.tar.gz) = 36a01ea310b4b3d0a3d209b641739575239e1ca5e93b3de99cb1fec83e82f9a70ad0761dd6eb77cda5c18c53044ab80168b00725642a0c2dfde0e492c42af6a9 +SHA512 (krb5-1.18.tar.gz.asc) = a9399a0e98a810b0c1c9e47c280edec329018714d60b3be228d125ea6e9d1548030940ca29ffd92a424675b02922a8509ed6ffec30d42da6c0d505d84c5aba63 From 48a220a102dc41bdeb423abc2de650585716232d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 12 Feb 2020 17:47:03 -0500 Subject: [PATCH 152/304] Fix missing dist --- krb5.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 45b6ee3..43bb589 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1 +Release: 1%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz From 3b6955d99e3c9ab351147b8c0d14a904a7bcffb8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 21 Feb 2020 13:16:49 -0500 Subject: [PATCH 153/304] Fix AS-REQ checking of KDB-modified indicators --- ...-checking-of-KDB-modified-indicators.patch | 189 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 194 insertions(+), 1 deletion(-) create mode 100644 Fix-AS-REQ-checking-of-KDB-modified-indicators.patch diff --git a/Fix-AS-REQ-checking-of-KDB-modified-indicators.patch b/Fix-AS-REQ-checking-of-KDB-modified-indicators.patch new file mode 100644 index 0000000..1655c38 --- /dev/null +++ b/Fix-AS-REQ-checking-of-KDB-modified-indicators.patch @@ -0,0 +1,189 @@ +From 744154b19c8000965e5a5de51d5dbef0794958be Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 19 Feb 2020 15:36:38 -0500 +Subject: [PATCH] Fix AS-REQ checking of KDB-modified indicators + +Commit 7196c03f18f14695abeb5ae4923004469b172f0f (ticket 8823) gave the +KDB the ability to modify auth indicators, but it happens after the +asserted indicators are checked against the server principal +requirements. In finish_process_as_req(), move the call to +check_indicators() after the call to handle_authdata() so that the +final indicator list is checked. + +For the test case, add string attribute functionality to the test KDB +module, and fix a bug where test_get_principal() would return failure +if a principal has no keys. Also add a test case for AS-REQ +enforcement of normally asserted auth indicators. + +ticket: 8876 (new) +tags: pullup +target_version: 1.18-next + +(cherry picked from commit 109e30ce22c20f18b8233119f274935bdf573886) +--- + src/kdc/do_as_req.c | 14 +++++------ + src/plugins/kdb/test/kdb_test.c | 42 +++++++++++++++++++++++++++++++-- + src/tests/t_authdata.py | 11 +++++++++ + 3 files changed, 58 insertions(+), 9 deletions(-) + +diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c +index 87dd7e993..9ae7b0a5e 100644 +--- a/src/kdc/do_as_req.c ++++ b/src/kdc/do_as_req.c +@@ -211,13 +211,6 @@ finish_process_as_req(struct as_req_state *state, krb5_error_code errcode) + + au_state->stage = ENCR_REP; + +- errcode = check_indicators(kdc_context, state->server, +- state->auth_indicators); +- if (errcode) { +- state->status = "HIGHER_AUTHENTICATION_REQUIRED"; +- goto egress; +- } +- + state->ticket_reply.enc_part2 = &state->enc_tkt_reply; + + errcode = check_kdcpolicy_as(kdc_context, state->request, state->client, +@@ -301,6 +294,13 @@ finish_process_as_req(struct as_req_state *state, krb5_error_code errcode) + goto egress; + } + ++ errcode = check_indicators(kdc_context, state->server, ++ state->auth_indicators); ++ if (errcode) { ++ state->status = "HIGHER_AUTHENTICATION_REQUIRED"; ++ goto egress; ++ } ++ + errcode = krb5_encrypt_tkt_part(kdc_context, &state->server_keyblock, + &state->ticket_reply); + if (errcode) +diff --git a/src/plugins/kdb/test/kdb_test.c b/src/plugins/kdb/test/kdb_test.c +index 1936cb0e4..95a6062e2 100644 +--- a/src/plugins/kdb/test/kdb_test.c ++++ b/src/plugins/kdb/test/kdb_test.c +@@ -54,6 +54,8 @@ + * # Initial number is kvno; defaults to 1. + * keys = 3 aes256-cts aes128-cts:normal + * keys = 2 rc4-hmac ++ * strings = key1:value1 ++ * strings = key2:value2 + * } + * } + * delegation = { +@@ -282,6 +284,33 @@ make_keys(char **strings, const char *princstr, const krb5_data *realm, + ent->n_key_data = nkeys; + } + ++static void ++make_strings(char **stringattrs, krb5_db_entry *ent) ++{ ++ struct k5buf buf; ++ char **p; ++ const char *str, *sep; ++ krb5_tl_data *tl; ++ ++ k5_buf_init_dynamic(&buf); ++ for (p = stringattrs; *p != NULL; p++) { ++ str = *p; ++ sep = strchr(str, ':'); ++ assert(sep != NULL); ++ k5_buf_add_len(&buf, str, sep - str); ++ k5_buf_add_len(&buf, "\0", 1); ++ k5_buf_add_len(&buf, sep + 1, strlen(sep + 1) + 1); ++ } ++ assert(buf.data != NULL); ++ ++ tl = ealloc(sizeof(*ent->tl_data)); ++ tl->tl_data_next = NULL; ++ tl->tl_data_type = KRB5_TL_STRING_ATTRS; ++ tl->tl_data_length = buf.len; ++ tl->tl_data_contents = buf.data; ++ ent->tl_data = tl; ++} ++ + static krb5_error_code + test_init() + { +@@ -339,7 +368,8 @@ test_get_principal(krb5_context context, krb5_const_principal search_for, + krb5_principal princ = NULL, tgtprinc; + krb5_principal_data empty_princ = { KV5M_PRINCIPAL }; + testhandle h = context->dal_handle->db_context; +- char *search_name = NULL, *canon = NULL, *flagstr, **names, **key_strings; ++ char *search_name = NULL, *canon = NULL, *flagstr; ++ char **names, **key_strings, **stringattrs; + const char *ename; + krb5_db_entry *ent; + +@@ -415,7 +445,7 @@ test_get_principal(krb5_context context, krb5_const_principal search_for, + ent->pw_expiration = get_time(h, "princs", ename, "pwexpiration"); + + /* Leave last_success, last_failed, fail_auth_count zeroed. */ +- /* Leave tl_data and e_data empty. */ ++ /* Leave e_data empty. */ + + set_names(h, "princs", ename, "keys"); + ret = profile_get_values(h->profile, h->names, &key_strings); +@@ -424,11 +454,19 @@ test_get_principal(krb5_context context, krb5_const_principal search_for, + profile_free_list(key_strings); + } + ++ set_names(h, "princs", ename, "strings"); ++ ret = profile_get_values(h->profile, h->names, &stringattrs); ++ if (ret != PROF_NO_RELATION) { ++ make_strings(stringattrs, ent); ++ profile_free_list(stringattrs); ++ } ++ + /* We must include mod-princ data or kadm5_get_principal() won't work and + * we can't extract keys with kadmin.local. */ + check(krb5_dbe_update_mod_princ_data(context, ent, 0, &empty_princ)); + + *entry = ent; ++ ret = 0; + + cleanup: + krb5_free_unparsed_name(context, search_name); +diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py +index 3153ebca3..4fbdbec05 100644 +--- a/src/tests/t_authdata.py ++++ b/src/tests/t_authdata.py +@@ -158,6 +158,8 @@ realm.run(['./adata', realm.host_princ], expected_msg='+97: [indcl]') + mark('auth indicator enforcement') + realm.addprinc('restricted') + realm.run([kadminl, 'setstr', 'restricted', 'require_auth', 'superstrong']) ++realm.kinit(realm.user_princ, password('user'), ['-S', 'restricted'], ++ expected_code=1, expected_msg='KDC policy rejects request') + realm.run([kvno, 'restricted'], expected_code=1, + expected_msg='KDC policy rejects request') + realm.run([kadminl, 'setstr', 'restricted', 'require_auth', 'indcl']) +@@ -194,6 +196,8 @@ testprincs = {'krbtgt/KRBTEST.COM': {'keys': 'aes128-cts'}, + 'krbtgt/FOREIGN': {'keys': 'aes128-cts'}, + 'user': {'keys': 'aes128-cts', 'flags': '+preauth'}, + 'user2': {'keys': 'aes128-cts', 'flags': '+preauth'}, ++ 'rservice': {'keys': 'aes128-cts', ++ 'strings': 'require_auth:strong'}, + 'service/1': {'keys': 'aes128-cts', + 'flags': '+ok_to_auth_as_delegate'}, + 'service/2': {'keys': 'aes128-cts'}, +@@ -208,6 +212,7 @@ usercache = 'FILE:' + os.path.join(realm.testdir, 'usercache') + realm.extract_keytab(realm.krbtgt_princ, realm.keytab) + realm.extract_keytab('krbtgt/FOREIGN', realm.keytab) + realm.extract_keytab(realm.user_princ, realm.keytab) ++realm.extract_keytab('ruser', realm.keytab) + realm.extract_keytab('service/1', realm.keytab) + realm.extract_keytab('service/2', realm.keytab) + realm.extract_keytab('noauthdata', realm.keytab) +@@ -252,6 +257,12 @@ if ' -2: self_ad' not in out or ' -2: proxy_ad' not in out: + realm.kinit(realm.user_princ, None, ['-k', '-X', 'indicators=dummy dbincr1']) + realm.run(['./adata', realm.krbtgt_princ], expected_msg='+97: [dbincr2]') + realm.run(['./adata', 'service/1'], expected_msg='+97: [dbincr3]') ++realm.kinit(realm.user_princ, None, ++ ['-k', '-X', 'indicators=strong', '-S', 'rservice']) ++# Test enforcement of altered indicators during AS request. ++realm.kinit(realm.user_princ, None, ++ ['-k', '-X', 'indicators=strong dbincr1', '-S', 'rservice'], ++ expected_code=1) + + # Test that KDB module authdata is included in an AS request, by + # default or with an explicit PAC request. diff --git a/krb5.spec b/krb5.spec index 43bb589..1eb325d 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1%{?dist} +Release: 2%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -50,6 +50,7 @@ Patch4: downstream-fix-debuginfo-with-y.tab.c.patch Patch5: downstream-Remove-3des-support.patch Patch6: downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +Patch8: Fix-AS-REQ-checking-of-KDB-modified-indicators.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -623,6 +624,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Feb 21 2020 Robbie Harwood - 1.18-2 +- Fix AS-REQ checking of KDB-modified indicators + * Wed Feb 12 2020 Robbie Harwood - 1.18-1 - New upstream version (1.18) From 0ecf7a0e65459c3f4a0171739eb4e072f11448e2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 27 Feb 2020 16:13:51 -0500 Subject: [PATCH 154/304] Allow certauth modules to set hw-authent flag --- ...tauth-modules-to-set-hw-authent-flag.patch | 241 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 246 insertions(+), 1 deletion(-) create mode 100644 Allow-certauth-modules-to-set-hw-authent-flag.patch diff --git a/Allow-certauth-modules-to-set-hw-authent-flag.patch b/Allow-certauth-modules-to-set-hw-authent-flag.patch new file mode 100644 index 0000000..c1266c9 --- /dev/null +++ b/Allow-certauth-modules-to-set-hw-authent-flag.patch @@ -0,0 +1,241 @@ +From 745aa16c41305da1a3f288bf06e551f56cb04594 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 24 Feb 2020 15:58:59 -0500 +Subject: [PATCH] Allow certauth modules to set hw-authent flag + +In PKINIT, if a certauth module returns KRB5_CERTAUTH_HWAUTH from its +authorize method, set the hw-authent flag in the ticket. + +ticket: 8879 (new) +(cherry picked from commit 50fb43b4a2d97ce2cd53e1ced30e8e8224fede70) +--- + doc/plugindev/certauth.rst | 7 +++++-- + src/include/krb5/certauth_plugin.h | 9 ++++++--- + src/lib/krb5/error_tables/k5e1_err.et | 1 + + src/plugins/certauth/test/Makefile.in | 4 ++-- + src/plugins/certauth/test/main.c | 11 +++++++++-- + src/plugins/preauth/pkinit/pkinit_srv.c | 24 ++++++++++++++++-------- + src/tests/t_certauth.py | 13 +++++++++++++ + 7 files changed, 52 insertions(+), 17 deletions(-) + +diff --git a/doc/plugindev/certauth.rst b/doc/plugindev/certauth.rst +index 8a7f7c5eb..3b715f738 100644 +--- a/doc/plugindev/certauth.rst ++++ b/doc/plugindev/certauth.rst +@@ -15,8 +15,11 @@ principal. **authorize** receives the DER-encoded certificate, the + requested client principal, and a pointer to the client's + krb5_db_entry (for modules that link against libkdb5). It returns the + authorization status and optionally outputs a list of authentication +-indicator strings to be added to the ticket. A module must use its +-own internal or library-provided ASN.1 certificate decoder. ++indicator strings to be added to the ticket. Beginning in release ++1.19, the authorize method can request that the hardware ++authentication bit be set in the ticket by returning ++**KRB5_CERTAUTH_HWAUTH**. A module must use its own internal or ++library-provided ASN.1 certificate decoder. + + A module can optionally create and destroy module data with the + **init** and **fini** methods. Module data objects last for the +diff --git a/src/include/krb5/certauth_plugin.h b/src/include/krb5/certauth_plugin.h +index 3074790f8..3466cf345 100644 +--- a/src/include/krb5/certauth_plugin.h ++++ b/src/include/krb5/certauth_plugin.h +@@ -85,14 +85,17 @@ typedef void + (*krb5_certauth_fini_fn)(krb5_context context, krb5_certauth_moddata moddata); + + /* +- * Mandatory: +- * Return 0 if the DER-encoded cert is authorized for PKINIT authentication by +- * princ; otherwise return one of the following error codes: ++ * Mandatory: return 0 or KRB5_CERTAUTH_HWAUTH if the DER-encoded cert is ++ * authorized for PKINIT authentication by princ; otherwise return one of the ++ * following error codes: + * - KRB5KDC_ERR_CLIENT_NAME_MISMATCH - incorrect SAN value + * - KRB5KDC_ERR_INCONSISTENT_KEY_PURPOSE - incorrect EKU + * - KRB5KDC_ERR_CERTIFICATE_MISMATCH - other extension error + * - KRB5_PLUGIN_NO_HANDLE - the module has no opinion about cert + * ++ * Returning KRB5_CERTAUTH_HWAUTH will cause the hw-authent flag to be set in ++ * the issued ticket (new in release 1.19). ++ * + * - opts is used by built-in modules to receive internal data, and must be + * ignored by other modules. + * - db_entry receives the client principal database entry, and can be ignored +diff --git a/src/lib/krb5/error_tables/k5e1_err.et b/src/lib/krb5/error_tables/k5e1_err.et +index ade5caecf..abd9f3bfe 100644 +--- a/src/lib/krb5/error_tables/k5e1_err.et ++++ b/src/lib/krb5/error_tables/k5e1_err.et +@@ -42,4 +42,5 @@ error_code KRB5_KCM_MALFORMED_REPLY, "Malformed reply from KCM daemon" + error_code KRB5_KCM_RPC_ERROR, "Mach RPC error communicating with KCM daemon" + error_code KRB5_KCM_REPLY_TOO_BIG, "KCM daemon reply too big" + error_code KRB5_KCM_NO_SERVER, "No KCM server found" ++error_code KRB5_CERTAUTH_HWAUTH, "Authorize and set hw-authent ticket flag" + end +diff --git a/src/plugins/certauth/test/Makefile.in b/src/plugins/certauth/test/Makefile.in +index d3524084c..e94c13845 100644 +--- a/src/plugins/certauth/test/Makefile.in ++++ b/src/plugins/certauth/test/Makefile.in +@@ -5,8 +5,8 @@ LIBBASE=certauth_test + LIBMAJOR=0 + LIBMINOR=0 + RELDIR=../plugins/certauth/test +-SHLIB_EXPDEPS=$(KRB5_BASE_DEPLIBS) +-SHLIB_EXPLIBS=$(KRB5_BASE_LIBS) ++SHLIB_EXPDEPS=$(KDB5_DEPLIBS) $(KRB5_BASE_DEPLIBS) ++SHLIB_EXPLIBS=$(KDB5_LIBS) $(KRB5_BASE_LIBS) + + STLIBOBJS=main.o + +diff --git a/src/plugins/certauth/test/main.c b/src/plugins/certauth/test/main.c +index 77641230c..d4633b8cd 100644 +--- a/src/plugins/certauth/test/main.c ++++ b/src/plugins/certauth/test/main.c +@@ -31,6 +31,7 @@ + */ + + #include ++#include + #include "krb5/certauth_plugin.h" + + struct krb5_certauth_moddata_st { +@@ -131,7 +132,8 @@ has_cn(krb5_context context, const uint8_t *cert, size_t cert_len, + + /* + * Test module 2 returns OK if princ matches the CN part of the subject name, +- * and returns indicators of the module name and princ. ++ * and returns indicators of the module name and princ. If the "hwauth" string ++ * attribute is set on db_entry, it returns KRB5_CERTAUTH_HWAUTH. + */ + static krb5_error_code + test2_authorize(krb5_context context, krb5_certauth_moddata moddata, +@@ -141,7 +143,7 @@ test2_authorize(krb5_context context, krb5_certauth_moddata moddata, + char ***authinds_out) + { + krb5_error_code ret; +- char *name = NULL, **ais = NULL; ++ char *name = NULL, *strval = NULL, **ais = NULL; + + *authinds_out = NULL; + +@@ -167,6 +169,11 @@ test2_authorize(krb5_context context, krb5_certauth_moddata moddata, + + ais = NULL; + ++ ret = krb5_dbe_get_string(context, (krb5_db_entry *)db_entry, "hwauth", ++ &strval); ++ ret = (strval != NULL) ? KRB5_CERTAUTH_HWAUTH : 0; ++ krb5_dbe_free_string(context, strval); ++ + cleanup: + krb5_free_unparsed_name(context, name); + return ret; +diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c +index feca11806..3ae56c064 100644 +--- a/src/plugins/preauth/pkinit/pkinit_srv.c ++++ b/src/plugins/preauth/pkinit/pkinit_srv.c +@@ -320,12 +320,12 @@ static krb5_error_code + authorize_cert(krb5_context context, certauth_handle *certauth_modules, + pkinit_kdc_context plgctx, pkinit_kdc_req_context reqctx, + krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, +- krb5_principal client) ++ krb5_principal client, krb5_boolean *hwauth_out) + { + krb5_error_code ret; + certauth_handle h; + struct certauth_req_opts opts; +- krb5_boolean accepted = FALSE; ++ krb5_boolean accepted = FALSE, hwauth = FALSE; + uint8_t *cert; + size_t i, cert_len; + void *db_ent = NULL; +@@ -347,9 +347,10 @@ authorize_cert(krb5_context context, certauth_handle *certauth_modules, + + /* + * Check the certificate against each certauth module. For the certificate +- * to be authorized at least one module must return 0, and no module can an +- * error code other than KRB5_PLUGIN_NO_HANDLE (pass). Add indicators from +- * modules that return 0 or pass. ++ * to be authorized at least one module must return 0 or ++ * KRB5_CERTAUTH_HWAUTH, and no module can return an error code other than ++ * KRB5_PLUGIN_NO_HANDLE (pass). Add indicators from modules that return 0 ++ * or pass. + */ + ret = KRB5_PLUGIN_NO_HANDLE; + for (i = 0; certauth_modules != NULL && certauth_modules[i] != NULL; i++) { +@@ -359,6 +360,8 @@ authorize_cert(krb5_context context, certauth_handle *certauth_modules, + &opts, db_ent, &ais); + if (ret == 0) + accepted = TRUE; ++ else if (ret == KRB5_CERTAUTH_HWAUTH) ++ accepted = hwauth = TRUE; + else if (ret != KRB5_PLUGIN_NO_HANDLE) + goto cleanup; + +@@ -374,6 +377,7 @@ authorize_cert(krb5_context context, certauth_handle *certauth_modules, + } + } + ++ *hwauth_out = hwauth; + ret = accepted ? 0 : KRB5KDC_ERR_CLIENT_NAME_MISMATCH; + + cleanup: +@@ -430,7 +434,7 @@ pkinit_server_verify_padata(krb5_context context, + int is_signed = 1; + krb5_pa_data **e_data = NULL; + krb5_kdcpreauth_modreq modreq = NULL; +- krb5_boolean valid_freshness_token = FALSE; ++ krb5_boolean valid_freshness_token = FALSE, hwauth = FALSE; + char **sp; + + pkiDebug("pkinit_verify_padata: entered!\n"); +@@ -494,7 +498,7 @@ pkinit_server_verify_padata(krb5_context context, + } + if (is_signed) { + retval = authorize_cert(context, moddata->certauth_modules, plgctx, +- reqctx, cb, rock, request->client); ++ reqctx, cb, rock, request->client, &hwauth); + if (retval) + goto cleanup; + +@@ -613,6 +617,8 @@ pkinit_server_verify_padata(krb5_context context, + + /* remember to set the PREAUTH flag in the reply */ + enc_tkt_reply->flags |= TKT_FLG_PRE_AUTH; ++ if (hwauth) ++ enc_tkt_reply->flags |= TKT_FLG_HW_AUTH; + modreq = (krb5_kdcpreauth_modreq)reqctx; + reqctx = NULL; + +@@ -1044,7 +1050,9 @@ pkinit_server_get_flags(krb5_context kcontext, krb5_preauthtype patype) + { + if (patype == KRB5_PADATA_PKINIT_KX) + return PA_INFO; +- return PA_SUFFICIENT | PA_REPLACES_KEY | PA_TYPED_E_DATA; ++ /* PKINIT does not normally set the hw-authent ticket flag, but a ++ * certauth module can cause it to do so. */ ++ return PA_SUFFICIENT | PA_REPLACES_KEY | PA_TYPED_E_DATA | PA_HARDWARE; + } + + static krb5_preauthtype supported_server_pa_types[] = { +diff --git a/src/tests/t_certauth.py b/src/tests/t_certauth.py +index 9c7094525..0fe0fdb4a 100644 +--- a/src/tests/t_certauth.py ++++ b/src/tests/t_certauth.py +@@ -43,4 +43,17 @@ out = realm.kinit("user2@KRBTEST.COM", + expected_code=1, + expected_msg='kinit: Certificate mismatch') + ++# Test the KRB5_CERTAUTH_HWAUTH return code. ++mark('hw-authent flag tests') ++# First test +requires_hwauth without causing the hw-authent ticket ++# flag to be set. This currently results in a preauth loop. ++realm.run([kadminl, 'modprinc', '+requires_hwauth', realm.user_princ]) ++realm.kinit(realm.user_princ, ++ flags=['-X', 'X509_user_identity=%s' % file_identity], ++ expected_code=1, expected_msg='Looping detected') ++# Cause the test2 module to return KRB5_CERTAUTH_HWAUTH and try again. ++realm.run([kadminl, 'setstr', realm.user_princ, 'hwauth', 'x']) ++realm.kinit(realm.user_princ, ++ flags=['-X', 'X509_user_identity=%s' % file_identity]) ++ + success("certauth tests") diff --git a/krb5.spec b/krb5.spec index 1eb325d..45feb1a 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 2%{?dist} +Release: 3%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -51,6 +51,7 @@ Patch5: downstream-Remove-3des-support.patch Patch6: downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch Patch8: Fix-AS-REQ-checking-of-KDB-modified-indicators.patch +Patch9: Allow-certauth-modules-to-set-hw-authent-flag.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -624,6 +625,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Feb 27 2020 Robbie Harwood - 1.18-3 +- Allow certauth modules to set hw-authent flag + * Fri Feb 21 2020 Robbie Harwood - 1.18-2 - Fix AS-REQ checking of KDB-modified indicators From 812c07a94f1ff6f28272a5080110b7d4e4562830 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 28 Feb 2020 13:35:47 -0500 Subject: [PATCH 155/304] Allow deletion of require_auth with LDAP KDB --- ...letion-of-require_auth-with-LDAP-KDB.patch | 160 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 165 insertions(+), 1 deletion(-) create mode 100644 Allow-deletion-of-require_auth-with-LDAP-KDB.patch diff --git a/Allow-deletion-of-require_auth-with-LDAP-KDB.patch b/Allow-deletion-of-require_auth-with-LDAP-KDB.patch new file mode 100644 index 0000000..58ef195 --- /dev/null +++ b/Allow-deletion-of-require_auth-with-LDAP-KDB.patch @@ -0,0 +1,160 @@ +From 59eea8a1977c6039069b3826e5e651582a33fc25 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 25 Feb 2020 11:32:09 -0500 +Subject: [PATCH] Allow deletion of require_auth with LDAP KDB + +In update_ldap_mod_auth_ind(), if there is no string attribute value +for require_auth, check for krbPrincipalAuthInd attributes that might +need to be removed. (This will only work if the entry is loaded and +then modified, but that is the normal case for an existing entry.) + +Move the update_ldap_mod_auth_ind() call inside the tl-data +conditional (which should perhaps be a check for KADM5_TL_DATA in the +mask instead). A modification which did not intend to update tl-data +should not remove the krbPrincipalAuthInd attributes. + +Change get_int_from_tl_data() to to zero its output so that it can't +leave a garbage value behind if it returns 0 (as it does if no +KDB_TL_USER_INFO tl-data is present). + +Based on a patch by Glenn Machin. + +ticket: 8877 +tags: pullup +target_version: 1.18-next +target_version: 1.17-next + +(cherry picked from commit 6d9da7bb216f96cbdd731aa894714bd84213a9d0) +--- + src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c | 2 ++ + .../kdb/ldap/libkdb_ldap/ldap_principal2.c | 31 ++++++++++++------- + src/tests/t_kdb.py | 26 +++++++++++++++- + 3 files changed, 47 insertions(+), 12 deletions(-) + +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c +index ec7f32511..6bc20593f 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c ++++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c +@@ -721,6 +721,8 @@ get_int_from_tl_data(krb5_context context, krb5_db_entry *entry, int type, + void *ptr; + int *intptr; + ++ *intval = 0; ++ + tl_data.tl_data_type = KDB_TL_USER_INFO; + ret = krb5_dbe_lookup_tl_data(context, entry, &tl_data); + if (ret || tl_data.tl_data_length == 0) +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c +index 1d0726707..8d97a29b6 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c ++++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c +@@ -627,12 +627,22 @@ update_ldap_mod_auth_ind(krb5_context context, krb5_db_entry *entry, + char *auth_ind = NULL; + char *strval[10] = { 0 }; + char *ai, *ai_save = NULL; +- int sv_num = sizeof(strval) / sizeof(*strval); ++ int mask, sv_num = sizeof(strval) / sizeof(*strval); + + ret = krb5_dbe_get_string(context, entry, KRB5_KDB_SK_REQUIRE_AUTH, + &auth_ind); +- if (ret || auth_ind == NULL) +- goto cleanup; ++ if (ret) ++ return ret; ++ if (auth_ind == NULL) { ++ /* If we know krbPrincipalAuthInd attributes are present from loading ++ * the entry, delete them. */ ++ ret = krb5_get_attributes_mask(context, entry, &mask); ++ if (!ret && (mask & KDB_AUTH_IND_ATTR)) { ++ return krb5_add_str_mem_ldap_mod(mods, "krbPrincipalAuthInd", ++ LDAP_MOD_DELETE, NULL); ++ } ++ return 0; ++ } + + ai = strtok_r(auth_ind, " ", &ai_save); + while (ai != NULL && i < sv_num) { +@@ -642,8 +652,6 @@ update_ldap_mod_auth_ind(krb5_context context, krb5_db_entry *entry, + + ret = krb5_add_str_mem_ldap_mod(mods, "krbPrincipalAuthInd", + LDAP_MOD_REPLACE, strval); +- +-cleanup: + krb5_dbe_free_string(context, auth_ind); + return ret; + } +@@ -1251,18 +1259,19 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, + + } /* Modify Key data ends here */ + +- /* Auth indicators will also be stored in krbExtraData when processing +- * tl_data. */ +- st = update_ldap_mod_auth_ind(context, entry, &mods); +- if (st != 0) +- goto cleanup; +- + /* Set tl_data */ + if (entry->tl_data != NULL) { + int count = 0; + struct berval **ber_tl_data = NULL; + krb5_tl_data *ptr; + krb5_timestamp unlock_time; ++ ++ /* Normalize required auth indicators, but also store them as string ++ * attributes within krbExtraData. */ ++ st = update_ldap_mod_auth_ind(context, entry, &mods); ++ if (st != 0) ++ goto cleanup; ++ + for (ptr = entry->tl_data; ptr != NULL; ptr = ptr->tl_data_next) { + if (ptr->tl_data_type == KRB5_TL_LAST_PWD_CHANGE + #ifdef SECURID +diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py +index 03ee70f47..caa7e9d8f 100755 +--- a/src/tests/t_kdb.py ++++ b/src/tests/t_kdb.py +@@ -319,19 +319,43 @@ realm.klist(realm.user_princ, realm.host_princ) + + mark('LDAP auth indicator') + +-# Test auth indicator support ++# Test require_auth normalization. + realm.addprinc('authind', password('authind')) + realm.run([kadminl, 'setstr', 'authind', 'require_auth', 'otp radius']) + ++# Check that krbPrincipalAuthInd attributes are set when the string ++# attribute it set. + out = ldap_search('(krbPrincipalName=authind*)') + if 'krbPrincipalAuthInd: otp' not in out: + fail('Expected krbPrincipalAuthInd value not in output') + if 'krbPrincipalAuthInd: radius' not in out: + fail('Expected krbPrincipalAuthInd value not in output') + ++# Check that the string attribute still appears when the principal is ++# loaded. + realm.run([kadminl, 'getstrs', 'authind'], + expected_msg='require_auth: otp radius') + ++# Modify the LDAP attributes and check that the change is reflected in ++# the string attribute. ++ldap_modify('dn: krbPrincipalName=authind@KRBTEST.COM,cn=t1,cn=krb5\n' ++ 'changetype: modify\n' ++ 'replace: krbPrincipalAuthInd\n' ++ 'krbPrincipalAuthInd: radius\n' ++ 'krbPrincipalAuthInd: pkinit\n') ++realm.run([kadminl, 'getstrs', 'authind'], ++ expected_msg='require_auth: radius pkinit') ++ ++# Regression test for #8877: remove the string attribute and check ++# that it is reflected in the LDAP attributes and by getstrs. ++realm.run([kadminl, 'delstr', 'authind', 'require_auth']) ++out = ldap_search('(krbPrincipalName=authind*)') ++if 'krbPrincipalAuthInd' in out: ++ fail('krbPrincipalAuthInd attribute still present after delstr') ++out = realm.run([kadminl, 'getstrs', 'authind']) ++if 'require_auth' in out: ++ fail('require_auth string attribute still visible after delstr') ++ + mark('LDAP service principal aliases') + + # Test service principal aliases. diff --git a/krb5.spec b/krb5.spec index 45feb1a..1114076 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 3%{?dist} +Release: 4%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -52,6 +52,7 @@ Patch6: downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch Patch8: Fix-AS-REQ-checking-of-KDB-modified-indicators.patch Patch9: Allow-certauth-modules-to-set-hw-authent-flag.patch +Patch10: Allow-deletion-of-require_auth-with-LDAP-KDB.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -625,6 +626,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Feb 28 2020 Robbie Harwood - 1.18-4 +- Allow deletion of require_auth with LDAP KDB + * Thu Feb 27 2020 Robbie Harwood - 1.18-3 - Allow certauth modules to set hw-authent flag From f6c62d5e63b5177fa453fe83e6e46f0485eab1b2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 3 Mar 2020 12:34:50 -0500 Subject: [PATCH 156/304] Refresh manually acquired creds from client keytab --- ...ly-acquired-creds-from-client-keytab.patch | 78 +++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 83 insertions(+), 1 deletion(-) create mode 100644 Refresh-manually-acquired-creds-from-client-keytab.patch diff --git a/Refresh-manually-acquired-creds-from-client-keytab.patch b/Refresh-manually-acquired-creds-from-client-keytab.patch new file mode 100644 index 0000000..fe2588f --- /dev/null +++ b/Refresh-manually-acquired-creds-from-client-keytab.patch @@ -0,0 +1,78 @@ +From e67aca9a77d78efa798237b43e177caf9e79f64a Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 26 Feb 2020 18:27:17 -0500 +Subject: [PATCH] Refresh manually acquired creds from client keytab + +If a client keytab is present but credentials are acquired manually, +the credentials would not be refreshed because no refresh_time config +var is set in the cache. Change kg_cred_time_to_refresh() to attempt +a refresh from the client keytab on any credentials which will expire +in the next 30 seconds. + +[ghudson@mit.edu: adjused code and added test case] + +ticket: 7976 +(cherry picked from commit 729896467e3c77904666019d6cbbda583ae49b95) +--- + src/lib/gssapi/krb5/acquire_cred.c | 14 +++++++++++--- + src/tests/gssapi/t_client_keytab.py | 18 ++++++++++++++++++ + 2 files changed, 29 insertions(+), 3 deletions(-) + +diff --git a/src/lib/gssapi/krb5/acquire_cred.c b/src/lib/gssapi/krb5/acquire_cred.c +index acc1868f8..4062f4741 100644 +--- a/src/lib/gssapi/krb5/acquire_cred.c ++++ b/src/lib/gssapi/krb5/acquire_cred.c +@@ -557,15 +557,23 @@ set_refresh_time(krb5_context context, krb5_ccache ccache, + krb5_boolean + kg_cred_time_to_refresh(krb5_context context, krb5_gss_cred_id_rec *cred) + { +- krb5_timestamp now; ++ krb5_timestamp now, soon; + + if (krb5_timeofday(context, &now)) + return FALSE; ++ soon = ts_incr(now, 30); + if (cred->refresh_time != 0 && !ts_after(cred->refresh_time, now)) { +- set_refresh_time(context, cred->ccache, +- ts_incr(cred->refresh_time, 30)); ++ set_refresh_time(context, cred->ccache, soon); + return TRUE; + } ++ ++ /* If the creds will expire soon, try to refresh even if they weren't ++ * acquired with a client keytab. */ ++ if (ts_after(soon, cred->expire)) { ++ set_refresh_time(context, cred->ccache, soon); ++ return TRUE; ++ } ++ + return FALSE; + } + +diff --git a/src/tests/gssapi/t_client_keytab.py b/src/tests/gssapi/t_client_keytab.py +index e474a27c7..7847b3ecd 100755 +--- a/src/tests/gssapi/t_client_keytab.py ++++ b/src/tests/gssapi/t_client_keytab.py +@@ -124,4 +124,22 @@ realm.kinit(realm.user_princ, password('user')) + realm.run(['./t_ccselect', phost], env=bad_cktname, + expected_msg=realm.user_princ) + ++mark('refresh of manually acquired creds') ++ ++# Test 17: no name/ccache specified, manually acquired creds which ++# will expire soon. Verify that creds are refreshed using the current ++# client name, with refresh_time set in the refreshed ccache. ++realm.kinit('bob', password('bob'), ['-l', '15s']) ++realm.run(['./t_ccselect', phost], expected_msg='bob') ++realm.run([klist, '-C'], expected_msg='refresh_time = ') ++ ++# Test 18: no name/ccache specified, manually acquired creds with a ++# client principal not present in the client keytab. A refresh is ++# attempted but fails, and an expired ticket error results. ++realm.kinit(realm.admin_princ, password('admin'), ['-l', '-1s']) ++msgs = ('Getting initial credentials for user/admin@KRBTEST.COM', ++ '/Matching credential not found') ++realm.run(['./t_ccselect', phost], expected_code=1, ++ expected_msg='Ticket expired', expected_trace=msgs) ++ + success('Client keytab tests') diff --git a/krb5.spec b/krb5.spec index 1114076..55a9f87 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 4%{?dist} +Release: 5%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -53,6 +53,7 @@ Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch Patch8: Fix-AS-REQ-checking-of-KDB-modified-indicators.patch Patch9: Allow-certauth-modules-to-set-hw-authent-flag.patch Patch10: Allow-deletion-of-require_auth-with-LDAP-KDB.patch +Patch11: Refresh-manually-acquired-creds-from-client-keytab.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -626,6 +627,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Mar 03 2020 Robbie Harwood - 1.18-5 +- Refresh manually acquired creds from client keytab + * Fri Feb 28 2020 Robbie Harwood - 1.18-4 - Allow deletion of require_auth with LDAP KDB From bef2ba57a2f0a3afde0e5dee73355570e472cbd1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 9 Mar 2020 15:26:46 -0400 Subject: [PATCH 157/304] Update for new rpmlint shenanigans --- krb5.rpmlintrc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/krb5.rpmlintrc b/krb5.rpmlintrc index ad8e989..e1d2f0b 100644 --- a/krb5.rpmlintrc +++ b/krb5.rpmlintrc @@ -1,5 +1,4 @@ addFilter(r'spelling-error .* en_US (unencrypted)') -addFilter(r'Source3: krb5-1.17-pdfs.tar') addFilter(r'hidden-file-or-dir /usr/share/man/man5/.k5identity.5.gz') addFilter(r'non-standard-dir-in-var kerberos') addFilter(r'explicit-lib-dependency libverto-module-base') @@ -12,3 +11,4 @@ addFilter(r'/usr/bin/ksu') addFilter(r'no-documentation') addFilter(r'invalid-directory-reference .*pkgconfig') addFilter(r'incoherent-logrotate-file /etc/logrotate.d/k') +addFilter(r'library-not-linked-against-libc') From bea8330f52b6e342ae1bab996bb8fd1f10ecce23 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 17 Mar 2020 15:26:56 -0400 Subject: [PATCH 158/304] Document client keytab usage --- Document-client-keytab-usage.patch | 62 ++++++++++++++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 67 insertions(+), 1 deletion(-) create mode 100644 Document-client-keytab-usage.patch diff --git a/Document-client-keytab-usage.patch b/Document-client-keytab-usage.patch new file mode 100644 index 0000000..800522f --- /dev/null +++ b/Document-client-keytab-usage.patch @@ -0,0 +1,62 @@ +From 90a4102f334ce0c655492de9248c3c60ffbd0449 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 16 Mar 2020 18:14:30 -0400 +Subject: [PATCH] Document client keytab usage + +ticket: 8886 (new) +tags: pullup +target_version: 1.18-next + +(cherry picked from commit 366c64897d55c86cdc616d2d1cf4617ff8a07a99) +--- + doc/admin/appl_servers.rst | 37 +++++++++++++++++++++++++++++++++++++ + 1 file changed, 37 insertions(+) + +diff --git a/doc/admin/appl_servers.rst b/doc/admin/appl_servers.rst +index fee49f027..5232db9af 100644 +--- a/doc/admin/appl_servers.rst ++++ b/doc/admin/appl_servers.rst +@@ -60,6 +60,43 @@ To remove a principal from an existing keytab, use the kadmin + :end-before: _ktremove_end: + + ++Using a keytab to acquire client credentials ++~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ++ ++While keytabs are ordinarily used to accept credentials from clients, ++they can also be used to acquire initial credentials, allowing one ++service to authenticate to another. ++ ++To manually obtain credentials using a keytab, use the :ref:`kinit(1)` ++**-k** option, together with the **-t** option if the keytab is not in ++the default location. ++ ++Beginning with release 1.11, GSSAPI applications can be configured to ++automatically obtain initial credentials from a keytab as needed. The ++recommended configuration is as follows: ++ ++#. Create a keytab containing a single entry for the desired client ++ identity. ++ ++#. Place the keytab in a location readable by the service, and set the ++ **KRB5_CLIENT_KTNAME** environment variable to its filename. ++ Alternatively, use the **default_client_keytab_name** profile ++ variable in :ref:`libdefaults`, or use the default location of ++ |ckeytab|. ++ ++#. Set **KRB5CCNAME** to a filename writable by the service, which ++ will not be used for any other purpose. Do not manually obtain ++ credentials at this location. (Another credential cache type ++ besides **FILE** can be used if desired, as long the cache will not ++ conflict with another use. A **MEMORY** cache can be used if the ++ service runs as a long-lived process. See :ref:`ccache_definition` ++ for details.) ++ ++#. Start the service. When it authenticates using GSSAPI, it will ++ automatically obtain credentials from the client keytab into the ++ specified credential cache, and refresh them before they expire. ++ ++ + Clock Skew + ---------- + diff --git a/krb5.spec b/krb5.spec index 55a9f87..29f33ed 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 5%{?dist} +Release: 6%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -54,6 +54,7 @@ Patch8: Fix-AS-REQ-checking-of-KDB-modified-indicators.patch Patch9: Allow-certauth-modules-to-set-hw-authent-flag.patch Patch10: Allow-deletion-of-require_auth-with-LDAP-KDB.patch Patch11: Refresh-manually-acquired-creds-from-client-keytab.patch +Patch12: Document-client-keytab-usage.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -627,6 +628,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Mar 17 2020 Robbie Harwood - 1.18-6 +- Document client keytab usage + * Tue Mar 03 2020 Robbie Harwood - 1.18-5 - Refresh manually acquired creds from client keytab From 5c9732a54546bf8c9551e31dec78fb83d75ba9d6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 20 Mar 2020 16:16:55 +0000 Subject: [PATCH 159/304] Add maximum openssl version in preparation for openssl 3 --- krb5.spec | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/krb5.spec b/krb5.spec index 29f33ed..51ef2ae 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 6%{?dist} +Release: 7%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -78,9 +78,12 @@ BuildRequires: hostname BuildRequires: iproute BuildRequires: libverto-devel BuildRequires: openldap-devel -BuildRequires: openssl-devel >= 1:1.1.1d-4 BuildRequires: lmdb-devel +# Need KDFs. This is the backported version +BuildRequires: openssl-devel >= 1:1.1.1d-4 +BuildRequires: openssl-devel < 1:3.0.0 + %ifarch %{ix86} x86_64 BuildRequires: yasm %endif @@ -113,6 +116,7 @@ to install this package. %package libs Summary: The non-admin shared libraries used by Kerberos 5 Requires: openssl-libs >= 1:1.1.1d-4 +Requires: openssl-libs < 1:3.0.0 Requires: coreutils, gawk, grep, sed Requires: keyutils-libs >= 1.5.8 Requires: /etc/crypto-policies/back-ends/krb5.config @@ -628,6 +632,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Mar 20 2020 Robbie Harwood - 1.18-7 +- Add maximum openssl version in preparation for openssl 3 + * Tue Mar 17 2020 Robbie Harwood - 1.18-6 - Document client keytab usage From dd7e9481aa7c23d20b14ba3f788376f19c11bb02 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 26 Mar 2020 10:20:02 -0400 Subject: [PATCH 160/304] Add finalization safety check to com_err --- ...finalization-safety-check-to-com_err.patch | 53 +++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 58 insertions(+), 1 deletion(-) create mode 100644 Add-finalization-safety-check-to-com_err.patch diff --git a/Add-finalization-safety-check-to-com_err.patch b/Add-finalization-safety-check-to-com_err.patch new file mode 100644 index 0000000..0fcb8cc --- /dev/null +++ b/Add-finalization-safety-check-to-com_err.patch @@ -0,0 +1,53 @@ +From 7d375a59fb36cc5ef8dd87895b83e9dfccc57058 Mon Sep 17 00:00:00 2001 +From: Jiri Sasek +Date: Fri, 13 Mar 2020 19:02:58 +0100 +Subject: [PATCH] Add finalization safety check to com_err + +If the linker erroneously runs the libkrb5 finalizer after the +libcom_err finalizer, the consequent remove_error_table() calls could +crash due to accessing a destroyed mutex or an invalid et_list +pointer. Add an unsynchronized check on finalized in +remove_error_table(), and set et_list to null in com_err_terminate() +after destroying the list. + +[ghudson@mit.edu: minimized code hanges; rewrote comment and commit +message] + +ticket: 8890 (new) +(cherry picked from commit 9d654aa05e26bbf22f140abde3436afeff2fdf8d) +--- + src/util/et/error_message.c | 7 ++++++- + 1 file changed, 6 insertions(+), 1 deletion(-) + +diff --git a/src/util/et/error_message.c b/src/util/et/error_message.c +index d7069a9df..7dc02a34e 100644 +--- a/src/util/et/error_message.c ++++ b/src/util/et/error_message.c +@@ -26,7 +26,7 @@ + + static struct et_list *et_list; + static k5_mutex_t et_list_lock = K5_MUTEX_PARTIAL_INITIALIZER; +-static int terminated = 0; /* for debugging shlib fini sequence errors */ ++static int terminated = 0; /* for safety and finalization debugging */ + + MAKE_INIT_FUNCTION(com_err_initialize); + MAKE_FINI_FUNCTION(com_err_terminate); +@@ -69,6 +69,7 @@ void com_err_terminate(void) + enext = e->next; + free(e); + } ++ et_list = NULL; + k5_mutex_unlock(&et_list_lock); + k5_mutex_destroy(&et_list_lock); + terminated = 1; +@@ -280,6 +281,10 @@ remove_error_table(const struct error_table *et) + { + struct et_list **ep, *e; + ++ /* Safety check in case libraries are finalized in the wrong order. */ ++ if (terminated) ++ return ENOENT; ++ + if (CALL_INIT_FUNCTION(com_err_initialize)) + return 0; + k5_mutex_lock(&et_list_lock); diff --git a/krb5.spec b/krb5.spec index 51ef2ae..6e2698b 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 7%{?dist} +Release: 8%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -55,6 +55,7 @@ Patch9: Allow-certauth-modules-to-set-hw-authent-flag.patch Patch10: Allow-deletion-of-require_auth-with-LDAP-KDB.patch Patch11: Refresh-manually-acquired-creds-from-client-keytab.patch Patch12: Document-client-keytab-usage.patch +Patch13: Add-finalization-safety-check-to-com_err.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -632,6 +633,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Mar 26 2020 Robbie Harwood - 1.18-8 +- Add finalization safety check to com_err + * Fri Mar 20 2020 Robbie Harwood - 1.18-7 - Add maximum openssl version in preparation for openssl 3 From 4e7e5fe69b3cad7cf7d4ec4ef1af77dd73fb3f6f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 26 Mar 2020 16:01:18 -0400 Subject: [PATCH 161/304] Eliminate redundant PKINIT responder invocation --- ...edundant-PKINIT-responder-invocation.patch | 93 +++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 98 insertions(+), 1 deletion(-) create mode 100644 Eliminate-redundant-PKINIT-responder-invocation.patch diff --git a/Eliminate-redundant-PKINIT-responder-invocation.patch b/Eliminate-redundant-PKINIT-responder-invocation.patch new file mode 100644 index 0000000..ea973b7 --- /dev/null +++ b/Eliminate-redundant-PKINIT-responder-invocation.patch @@ -0,0 +1,93 @@ +From b5793f8024320aaa7a85ca39cdc03bf99773bf11 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 23 Mar 2020 19:10:03 -0400 +Subject: [PATCH] Eliminate redundant PKINIT responder invocation + +In pkinit_client_prep_questions(), only act if the input padata type +is KRB5_PADATA_PK_AS_REQ. Otherwise we will ask questions again when +the KDC issues a ticket. + +Commit 7621d2f9a87214327ca3b2594e34dc7cea84596b (ticket 8242) +unintentionally changed the behavior of pkinit_load_fs_cert_and_key(), +causing pkinit_client_prep_questions() to do nothing on its first +call. Restore the original behavior of returning 0 when prompting is +deferred. + +Modify the existing "FILE identity, password on key (responder)" +PKINIT test to check that the responder is only invoked once. + +ticket: 8885 +(cherry picked from commit f1286842ce7b9e507a4ce0a47f44ab361a98be63) +--- + src/plugins/preauth/pkinit/pkinit_clnt.c | 5 +++++ + src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 13 +++++++------ + src/tests/t_pkinit.py | 11 +++++++---- + 3 files changed, 19 insertions(+), 10 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c +index 2f0431991..9b991ffe0 100644 +--- a/src/plugins/preauth/pkinit/pkinit_clnt.c ++++ b/src/plugins/preauth/pkinit/pkinit_clnt.c +@@ -897,6 +897,11 @@ pkinit_client_prep_questions(krb5_context context, + k5_json_object jval = NULL; + k5_json_number jflag = NULL; + ++ /* Don't ask questions for the informational padata items or when the ++ * ticket is issued. */ ++ if (pa_data->pa_type != KRB5_PADATA_PK_AS_REQ) ++ return 0; ++ + if (!reqctx->identity_initialized) { + pkinit_client_profile(context, plgctx, reqctx, cb, rock, + &request->server->realm); +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index dd718c2be..dbb054378 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -4362,17 +4362,18 @@ pkinit_load_fs_cert_and_key(krb5_context context, + + /* Load the certificate. */ + retval = get_cert(certname, &x); +- if (retval != 0 || x == NULL) { +- retval = oerr(context, 0, _("Cannot read certificate file '%s'"), ++ if (retval) { ++ retval = oerr(context, retval, _("Cannot read certificate file '%s'"), + certname); +- goto cleanup; + } ++ if (retval || x == NULL) ++ goto cleanup; + /* Load the key. */ + retval = get_key(context, id_cryptoctx, keyname, fsname, &y, password); +- if (retval != 0 || y == NULL) { +- retval = oerr(context, 0, _("Cannot read key file '%s'"), fsname); ++ if (retval) ++ retval = oerr(context, retval, _("Cannot read key file '%s'"), fsname); ++ if (retval || y == NULL) + goto cleanup; +- } + + id_cryptoctx->creds[cindex] = malloc(sizeof(struct _pkinit_cred_info)); + if (id_cryptoctx->creds[cindex] == NULL) { +diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py +index 69daf4987..ecd450e8a 100755 +--- a/src/tests/t_pkinit.py ++++ b/src/tests/t_pkinit.py +@@ -248,10 +248,13 @@ realm.run(['./adata', realm.host_princ], + # supplied by the responder. + # Supply the response in raw form. + mark('FILE identity, password on key (responder)') +-realm.run(['./responder', '-x', 'pkinit={"%s": 0}' % file_enc_identity, +- '-r', 'pkinit={"%s": "encrypted"}' % file_enc_identity, +- '-X', 'X509_user_identity=%s' % file_enc_identity, +- realm.user_princ]) ++out = realm.run(['./responder', '-x', 'pkinit={"%s": 0}' % file_enc_identity, ++ '-r', 'pkinit={"%s": "encrypted"}' % file_enc_identity, ++ '-X', 'X509_user_identity=%s' % file_enc_identity, ++ realm.user_princ]) ++# Regression test for #8885 (password question asked twice). ++if out.count('OK: ') != 1: ++ fail('Wrong number of responder calls') + # Supply the response through the convenience API. + realm.run(['./responder', '-X', 'X509_user_identity=%s' % file_enc_identity, + '-p', '%s=%s' % (file_enc_identity, 'encrypted'), realm.user_princ]) diff --git a/krb5.spec b/krb5.spec index 6e2698b..a87f08c 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 8%{?dist} +Release: 9%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -56,6 +56,7 @@ Patch10: Allow-deletion-of-require_auth-with-LDAP-KDB.patch Patch11: Refresh-manually-acquired-creds-from-client-keytab.patch Patch12: Document-client-keytab-usage.patch Patch13: Add-finalization-safety-check-to-com_err.patch +Patch14: Eliminate-redundant-PKINIT-responder-invocation.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -633,6 +634,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Mar 26 2020 Robbie Harwood - 1.18-9 +- Eliminate redundant PKINIT responder invocation + * Thu Mar 26 2020 Robbie Harwood - 1.18-8 - Add finalization safety check to com_err From c262ec69f6436125b0421ab6fd6ebed6215ce92c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 1 Apr 2020 14:24:49 -0400 Subject: [PATCH 162/304] Correctly import "service@" GSS host-based name --- ...y-import-service-GSS-host-based-name.patch | 52 +++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 57 insertions(+), 1 deletion(-) create mode 100644 Correctly-import-service-GSS-host-based-name.patch diff --git a/Correctly-import-service-GSS-host-based-name.patch b/Correctly-import-service-GSS-host-based-name.patch new file mode 100644 index 0000000..683b2d9 --- /dev/null +++ b/Correctly-import-service-GSS-host-based-name.patch @@ -0,0 +1,52 @@ +From 53b7be87de77b09f44b4ced1d4e85f520c9ce71a Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 30 Mar 2020 15:26:02 -0400 +Subject: [PATCH] Correctly import "service@" GSS host-based name + +The intended way to specify only a service in a GSS host-based name is +to omit the "@" separator. Some applications include the separator +but no hostname, and this happened to yield wildcard hostname behavior +prior to commit 996353767fe8afa7f67a3b5b465e4d70e18bad7c when +shortname qualification was added. To restore this behavior, check in +parse_hostbased() that at least one character is present after the "@" +separator before copying the hostname. Add a test case to t_gssapi.py. + +ticket: 8892 +tags: pullup +target_version: 1.18-next + +(cherry picked from commit a2f047af0400ba8080dc26033fae2b17534501e2) +--- + src/lib/gssapi/krb5/import_name.c | 4 ++-- + src/tests/gssapi/t_gssapi.py | 3 +++ + 2 files changed, 5 insertions(+), 2 deletions(-) + +diff --git a/src/lib/gssapi/krb5/import_name.c b/src/lib/gssapi/krb5/import_name.c +index da2ab1423..21023dd76 100644 +--- a/src/lib/gssapi/krb5/import_name.c ++++ b/src/lib/gssapi/krb5/import_name.c +@@ -102,8 +102,8 @@ parse_hostbased(const char *str, size_t len, + memcpy(service, str, servicelen); + service[servicelen] = '\0'; + +- /* If present, copy the hostname. */ +- if (at != NULL) { ++ /* Copy the hostname if present (at least one character after '@'). */ ++ if (len - servicelen > 1) { + hostlen = len - servicelen - 1; + host = malloc(hostlen + 1); + if (host == NULL) { +diff --git a/src/tests/gssapi/t_gssapi.py b/src/tests/gssapi/t_gssapi.py +index 54d5cf549..ecf982604 100755 +--- a/src/tests/gssapi/t_gssapi.py ++++ b/src/tests/gssapi/t_gssapi.py +@@ -47,6 +47,9 @@ realm.run(['./t_accname', 'p:service2/calvin', 'h:service2'], + expected_msg='service2/calvin') + realm.run(['./t_accname', 'p:service2/calvin', 'h:service1'], expected_code=1, + expected_msg=' found in keytab but does not match server principal') ++# Regression test for #8892 (trailing @ in name). ++realm.run(['./t_accname', 'p:service1/andrew', 'h:service1@'], ++ expected_msg='service1/abraham') + + # Test with acceptor name containing service and host. Use the + # client's un-canonicalized hostname as acceptor input to mirror what diff --git a/krb5.spec b/krb5.spec index a87f08c..37bd530 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 9%{?dist} +Release: 10%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -57,6 +57,7 @@ Patch11: Refresh-manually-acquired-creds-from-client-keytab.patch Patch12: Document-client-keytab-usage.patch Patch13: Add-finalization-safety-check-to-com_err.patch Patch14: Eliminate-redundant-PKINIT-responder-invocation.patch +Patch15: Correctly-import-service-GSS-host-based-name.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -634,6 +635,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Apr 01 2020 Robbie Harwood - 1.18-10 +- Correctly import "service@" GSS host-based name + * Thu Mar 26 2020 Robbie Harwood - 1.18-9 - Eliminate redundant PKINIT responder invocation From 9f3201c4bcbfcc39f47176ae489d361765774fb3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 2 Apr 2020 14:03:07 -0400 Subject: [PATCH 163/304] Do expiration warnings for all init_creds APIs --- ...ion-warnings-for-all-init_creds-APIs.patch | 425 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 430 insertions(+), 1 deletion(-) create mode 100644 Do-expiration-warnings-for-all-init_creds-APIs.patch diff --git a/Do-expiration-warnings-for-all-init_creds-APIs.patch b/Do-expiration-warnings-for-all-init_creds-APIs.patch new file mode 100644 index 0000000..d94f11d --- /dev/null +++ b/Do-expiration-warnings-for-all-init_creds-APIs.patch @@ -0,0 +1,425 @@ +From 9d452dc135ba0fad9470f096938a5dbfbacdbbe1 Mon Sep 17 00:00:00 2001 +From: Sumit Bose +Date: Fri, 28 Feb 2020 10:11:49 +0100 +Subject: [PATCH] Do expiration warnings for all init_creds APIs + +Move the password expiration warning code from gic_pwd.c to +get_in_tkt.c. Call it from init_creds_step_reply() on successful +completion. + +[ghudson@mit.edu: added test case; simplified doc comment; moved call +site to init_creds_step_reply(); rewrote commit message] + +ticket: 8893 (new) +(cherry picked from commit e1efb890f7ac31b32c68ab816ef118dbfb5a8c7e) +--- + src/include/krb5/krb5.hin | 9 ++- + src/lib/krb5/krb/get_in_tkt.c | 112 ++++++++++++++++++++++++++++++ + src/lib/krb5/krb/gic_pwd.c | 110 ----------------------------- + src/lib/krb5/krb/t_expire_warn.c | 47 +++++++++---- + src/lib/krb5/krb/t_expire_warn.py | 22 ++++-- + 5 files changed, 165 insertions(+), 135 deletions(-) + +diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin +index 26a3b6ec8..36300ea53 100644 +--- a/src/include/krb5/krb5.hin ++++ b/src/include/krb5/krb5.hin +@@ -7174,11 +7174,10 @@ typedef void + * + * Set a callback to receive password and account expiration times. + * +- * This option only applies to krb5_get_init_creds_password(). @a cb will be +- * invoked if and only if credentials are successfully acquired. The callback +- * will receive the @a context from the krb5_get_init_creds_password() call and +- * the @a data argument supplied with this API. The remaining arguments should +- * be interpreted as follows: ++ * @a cb will be invoked if and only if credentials are successfully acquired. ++ * The callback will receive the @a context from the calling function and the ++ * @a data argument supplied with this API. The remaining arguments should be ++ * interpreted as follows: + * + * If @a is_last_req is true, then the KDC reply contained last-req entries + * which unambiguously indicated the password expiration, account expiration, +diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c +index 870df62a1..cc0f70e83 100644 +--- a/src/lib/krb5/krb/get_in_tkt.c ++++ b/src/lib/krb5/krb/get_in_tkt.c +@@ -1482,6 +1482,116 @@ accept_method_data(krb5_context context, krb5_init_creds_context ctx) + ctx->method_padata); + } + ++/* Return the password expiry time indicated by enc_part2. Set *is_last_req ++ * if the information came from a last_req value. */ ++static void ++get_expiry_times(krb5_enc_kdc_rep_part *enc_part2, krb5_timestamp *pw_exp, ++ krb5_timestamp *acct_exp, krb5_boolean *is_last_req) ++{ ++ krb5_last_req_entry **last_req; ++ krb5_int32 lr_type; ++ ++ *pw_exp = 0; ++ *acct_exp = 0; ++ *is_last_req = FALSE; ++ ++ /* Look for last-req entries for password or account expiration. */ ++ if (enc_part2->last_req) { ++ for (last_req = enc_part2->last_req; *last_req; last_req++) { ++ lr_type = (*last_req)->lr_type; ++ if (lr_type == KRB5_LRQ_ALL_PW_EXPTIME || ++ lr_type == KRB5_LRQ_ONE_PW_EXPTIME) { ++ *is_last_req = TRUE; ++ *pw_exp = (*last_req)->value; ++ } else if (lr_type == KRB5_LRQ_ALL_ACCT_EXPTIME || ++ lr_type == KRB5_LRQ_ONE_ACCT_EXPTIME) { ++ *is_last_req = TRUE; ++ *acct_exp = (*last_req)->value; ++ } ++ } ++ } ++ ++ /* If we didn't find any, use the ambiguous key_exp field. */ ++ if (*is_last_req == FALSE) ++ *pw_exp = enc_part2->key_exp; ++} ++ ++/* ++ * Send an appropriate warning prompter if as_reply indicates that the password ++ * is going to expire soon. If an expire callback was provided, use that ++ * instead. ++ */ ++static void ++warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, ++ krb5_prompter_fct prompter, void *data, ++ const char *in_tkt_service, krb5_kdc_rep *as_reply) ++{ ++ krb5_error_code ret; ++ krb5_expire_callback_func expire_cb; ++ void *expire_data; ++ krb5_timestamp pw_exp, acct_exp, now; ++ krb5_boolean is_last_req; ++ krb5_deltat delta; ++ char ts[256], banner[1024]; ++ ++ if (as_reply == NULL || as_reply->enc_part2 == NULL) ++ return; ++ ++ get_expiry_times(as_reply->enc_part2, &pw_exp, &acct_exp, &is_last_req); ++ ++ k5_gic_opt_get_expire_cb(options, &expire_cb, &expire_data); ++ if (expire_cb != NULL) { ++ /* Invoke the expire callback and don't send prompter warnings. */ ++ (*expire_cb)(context, expire_data, pw_exp, acct_exp, is_last_req); ++ return; ++ } ++ ++ /* Don't warn if no password expiry value was sent. */ ++ if (pw_exp == 0) ++ return; ++ ++ /* Don't warn if the password is being changed. */ ++ if (in_tkt_service && strcmp(in_tkt_service, "kadmin/changepw") == 0) ++ return; ++ ++ /* ++ * If the expiry time came from a last_req field, assume the KDC wants us ++ * to warn. Otherwise, warn only if the expiry time is less than a week ++ * from now. ++ */ ++ ret = krb5_timeofday(context, &now); ++ if (ret != 0) ++ return; ++ if (!is_last_req && ++ (ts_after(now, pw_exp) || ts_delta(pw_exp, now) > 7 * 24 * 60 * 60)) ++ return; ++ ++ if (!prompter) ++ return; ++ ++ ret = krb5_timestamp_to_string(pw_exp, ts, sizeof(ts)); ++ if (ret != 0) ++ return; ++ ++ delta = ts_delta(pw_exp, now); ++ if (delta < 3600) { ++ snprintf(banner, sizeof(banner), ++ _("Warning: Your password will expire in less than one hour " ++ "on %s"), ts); ++ } else if (delta < 86400 * 2) { ++ snprintf(banner, sizeof(banner), ++ _("Warning: Your password will expire in %d hour%s on %s"), ++ delta / 3600, delta < 7200 ? "" : "s", ts); ++ } else { ++ snprintf(banner, sizeof(banner), ++ _("Warning: Your password will expire in %d days on %s"), ++ delta / 86400, ts); ++ } ++ ++ /* PROMPTER_INVOCATION */ ++ (*prompter)(context, data, 0, banner, 0, 0); ++} ++ + static krb5_error_code + init_creds_step_reply(krb5_context context, + krb5_init_creds_context ctx, +@@ -1693,6 +1803,8 @@ init_creds_step_reply(krb5_context context, + + /* success */ + ctx->complete = TRUE; ++ warn_pw_expiry(context, ctx->opt, ctx->prompter, ctx->prompter_data, ++ ctx->in_tkt_service, ctx->reply); + + cleanup: + krb5_free_pa_data(context, kdc_padata); +diff --git a/src/lib/krb5/krb/gic_pwd.c b/src/lib/krb5/krb/gic_pwd.c +index 14ce23ba4..54e0a8ebe 100644 +--- a/src/lib/krb5/krb/gic_pwd.c ++++ b/src/lib/krb5/krb/gic_pwd.c +@@ -133,113 +133,6 @@ krb5_init_creds_set_password(krb5_context context, + return 0; + } + +-/* Return the password expiry time indicated by enc_part2. Set *is_last_req +- * if the information came from a last_req value. */ +-static void +-get_expiry_times(krb5_enc_kdc_rep_part *enc_part2, krb5_timestamp *pw_exp, +- krb5_timestamp *acct_exp, krb5_boolean *is_last_req) +-{ +- krb5_last_req_entry **last_req; +- krb5_int32 lr_type; +- +- *pw_exp = 0; +- *acct_exp = 0; +- *is_last_req = FALSE; +- +- /* Look for last-req entries for password or account expiration. */ +- if (enc_part2->last_req) { +- for (last_req = enc_part2->last_req; *last_req; last_req++) { +- lr_type = (*last_req)->lr_type; +- if (lr_type == KRB5_LRQ_ALL_PW_EXPTIME || +- lr_type == KRB5_LRQ_ONE_PW_EXPTIME) { +- *is_last_req = TRUE; +- *pw_exp = (*last_req)->value; +- } else if (lr_type == KRB5_LRQ_ALL_ACCT_EXPTIME || +- lr_type == KRB5_LRQ_ONE_ACCT_EXPTIME) { +- *is_last_req = TRUE; +- *acct_exp = (*last_req)->value; +- } +- } +- } +- +- /* If we didn't find any, use the ambiguous key_exp field. */ +- if (*is_last_req == FALSE) +- *pw_exp = enc_part2->key_exp; +-} +- +-/* +- * Send an appropriate warning prompter if as_reply indicates that the password +- * is going to expire soon. If an expire callback was provided, use that +- * instead. +- */ +-static void +-warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, +- krb5_prompter_fct prompter, void *data, +- const char *in_tkt_service, krb5_kdc_rep *as_reply) +-{ +- krb5_error_code ret; +- krb5_expire_callback_func expire_cb; +- void *expire_data; +- krb5_timestamp pw_exp, acct_exp, now; +- krb5_boolean is_last_req; +- krb5_deltat delta; +- char ts[256], banner[1024]; +- +- get_expiry_times(as_reply->enc_part2, &pw_exp, &acct_exp, &is_last_req); +- +- k5_gic_opt_get_expire_cb(options, &expire_cb, &expire_data); +- if (expire_cb != NULL) { +- /* Invoke the expire callback and don't send prompter warnings. */ +- (*expire_cb)(context, expire_data, pw_exp, acct_exp, is_last_req); +- return; +- } +- +- /* Don't warn if no password expiry value was sent. */ +- if (pw_exp == 0) +- return; +- +- /* Don't warn if the password is being changed. */ +- if (in_tkt_service && strcmp(in_tkt_service, "kadmin/changepw") == 0) +- return; +- +- /* +- * If the expiry time came from a last_req field, assume the KDC wants us +- * to warn. Otherwise, warn only if the expiry time is less than a week +- * from now. +- */ +- ret = krb5_timeofday(context, &now); +- if (ret != 0) +- return; +- if (!is_last_req && +- (ts_after(now, pw_exp) || ts_delta(pw_exp, now) > 7 * 24 * 60 * 60)) +- return; +- +- if (!prompter) +- return; +- +- ret = krb5_timestamp_to_string(pw_exp, ts, sizeof(ts)); +- if (ret != 0) +- return; +- +- delta = ts_delta(pw_exp, now); +- if (delta < 3600) { +- snprintf(banner, sizeof(banner), +- _("Warning: Your password will expire in less than one hour " +- "on %s"), ts); +- } else if (delta < 86400*2) { +- snprintf(banner, sizeof(banner), +- _("Warning: Your password will expire in %d hour%s on %s"), +- delta / 3600, delta < 7200 ? "" : "s", ts); +- } else { +- snprintf(banner, sizeof(banner), +- _("Warning: Your password will expire in %d days on %s"), +- delta / 86400, ts); +- } +- +- /* PROMPTER_INVOCATION */ +- (*prompter)(context, data, 0, banner, 0, 0); +-} +- + /* + * Create a temporary options structure for getting a kadmin/changepw ticket, + * based on the appplication-specified options. Propagate all application +@@ -496,9 +389,6 @@ krb5_get_init_creds_password(krb5_context context, + goto cleanup; + + cleanup: +- if (ret == 0) +- warn_pw_expiry(context, options, prompter, data, in_tkt_service, +- as_reply); + free(chpw_opts); + zapfree(gakpw.storage.data, gakpw.storage.length); + memset(pw0array, 0, sizeof(pw0array)); +diff --git a/src/lib/krb5/krb/t_expire_warn.c b/src/lib/krb5/krb/t_expire_warn.c +index 1e59acba1..dc8dc8fb3 100644 +--- a/src/lib/krb5/krb/t_expire_warn.c ++++ b/src/lib/krb5/krb/t_expire_warn.c +@@ -28,6 +28,13 @@ + + static int exp_dummy, prompt_dummy; + ++static void ++check(krb5_error_code code) ++{ ++ if (code != 0) ++ abort(); ++} ++ + static krb5_error_code + prompter_cb(krb5_context ctx, void *data, const char *name, + const char *banner, int num_prompts, krb5_prompt prompts[]) +@@ -52,36 +59,48 @@ int + main(int argc, char **argv) + { + krb5_context ctx; ++ krb5_init_creds_context icctx; + krb5_get_init_creds_opt *opt; + char *user, *password, *service = NULL; +- krb5_boolean use_cb; ++ krb5_boolean use_cb, stepwise; + krb5_principal client; + krb5_creds creds; + +- if (argc < 4) { +- fprintf(stderr, "Usage: %s username password {1|0} [service]\n", ++ if (argc < 5) { ++ fprintf(stderr, "Usage: %s username password {1|0} {1|0} [service]\n", + argv[0]); + return 1; + } + user = argv[1]; + password = argv[2]; + use_cb = atoi(argv[3]); +- if (argc >= 5) +- service = argv[4]; ++ stepwise = atoi(argv[4]); ++ if (argc >= 6) ++ service = argv[5]; + +- assert(krb5_init_context(&ctx) == 0); +- assert(krb5_get_init_creds_opt_alloc(ctx, &opt) == 0); ++ check(krb5_init_context(&ctx)); ++ check(krb5_get_init_creds_opt_alloc(ctx, &opt)); + if (use_cb) { +- assert(krb5_get_init_creds_opt_set_expire_callback(ctx, opt, expire_cb, +- &exp_dummy) == 0); ++ check(krb5_get_init_creds_opt_set_expire_callback(ctx, opt, expire_cb, ++ &exp_dummy)); ++ } ++ check(krb5_parse_name(ctx, user, &client)); ++ if (stepwise) { ++ check(krb5_init_creds_init(ctx, client, prompter_cb, &prompt_dummy, 0, ++ opt, &icctx)); ++ krb5_init_creds_set_password(ctx, icctx, password); ++ if (service != NULL) ++ check(krb5_init_creds_set_service(ctx, icctx, service)); ++ check(krb5_init_creds_get(ctx, icctx)); ++ krb5_init_creds_free(ctx, icctx); ++ } else { ++ check(krb5_get_init_creds_password(ctx, &creds, client, password, ++ prompter_cb, &prompt_dummy, 0, ++ service, opt)); ++ krb5_free_cred_contents(ctx, &creds); + } +- assert(krb5_parse_name(ctx, user, &client) == 0); +- assert(krb5_get_init_creds_password(ctx, &creds, client, password, +- prompter_cb, &prompt_dummy, 0, service, +- opt) == 0); + krb5_get_init_creds_opt_free(ctx, opt); + krb5_free_principal(ctx, client); +- krb5_free_cred_contents(ctx, &creds); + krb5_free_context(ctx); + return 0; + } +diff --git a/src/lib/krb5/krb/t_expire_warn.py b/src/lib/krb5/krb/t_expire_warn.py +index 781f2728a..e163cc7e4 100755 +--- a/src/lib/krb5/krb/t_expire_warn.py ++++ b/src/lib/krb5/krb/t_expire_warn.py +@@ -34,23 +34,33 @@ realm.run([kadminl, 'addprinc', '-pw', 'pass', '-pwexpire', '12 hours', + realm.run([kadminl, 'addprinc', '-pw', 'pass', '-pwexpire', '3 days', 'days']) + + # Check for expected prompter warnings when no expire callback is used. +-output = realm.run(['./t_expire_warn', 'noexpire', 'pass', '0']) ++output = realm.run(['./t_expire_warn', 'noexpire', 'pass', '0', '0']) + if output: + fail('Unexpected output for noexpire') +-realm.run(['./t_expire_warn', 'minutes', 'pass', '0'], ++realm.run(['./t_expire_warn', 'minutes', 'pass', '0', '0'], + expected_msg=' less than one hour on ') +-realm.run(['./t_expire_warn', 'hours', 'pass', '0'], expected_msg=' hours on ') +-realm.run(['./t_expire_warn', 'days', 'pass', '0'], expected_msg=' days on ') ++realm.run(['./t_expire_warn', 'hours', 'pass', '0', '0'], ++ expected_msg=' hours on ') ++realm.run(['./t_expire_warn', 'days', 'pass', '0', '0'], ++ expected_msg=' days on ') ++# Try one case with the stepwise interface. ++realm.run(['./t_expire_warn', 'days', 'pass', '0', '1'], ++ expected_msg=' days on ') + + # Check for expected expire callback behavior. These tests are + # carefully agnostic about whether the KDC supports last_req fields, + # and could be made more specific if last_req support is added. +-output = realm.run(['./t_expire_warn', 'noexpire', 'pass', '1']) ++output = realm.run(['./t_expire_warn', 'noexpire', 'pass', '1', '0']) + if 'password_expiration = 0\n' not in output or \ + 'account_expiration = 0\n' not in output or \ + 'is_last_req = ' not in output: + fail('Expected callback output not seen for noexpire') +-output = realm.run(['./t_expire_warn', 'days', 'pass', '1']) ++output = realm.run(['./t_expire_warn', 'days', 'pass', '1', '0']) ++if 'password_expiration = ' not in output or \ ++ 'password_expiration = 0\n' in output: ++ fail('Expected non-zero password expiration not seen for days') ++# Try one case with the stepwise interface. ++output = realm.run(['./t_expire_warn', 'days', 'pass', '1', '1']) + if 'password_expiration = ' not in output or \ + 'password_expiration = 0\n' in output: + fail('Expected non-zero password expiration not seen for days') diff --git a/krb5.spec b/krb5.spec index 37bd530..9c9022c 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 10%{?dist} +Release: 11%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -58,6 +58,7 @@ Patch12: Document-client-keytab-usage.patch Patch13: Add-finalization-safety-check-to-com_err.patch Patch14: Eliminate-redundant-PKINIT-responder-invocation.patch Patch15: Correctly-import-service-GSS-host-based-name.patch +Patch16: Do-expiration-warnings-for-all-init_creds-APIs.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -635,6 +636,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Apr 02 2020 Robbie Harwood - 1.18-11 +- Do expiration warnings for all init_creds APIs + * Wed Apr 01 2020 Robbie Harwood - 1.18-10 - Correctly import "service@" GSS host-based name From 66ec722479d8af429db1ae3ca974f578be799b19 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 7 Apr 2020 15:51:54 -0400 Subject: [PATCH 164/304] Make ksu honor KRB5CCNAME again --- Make-ksu-honor-KRB5CCNAME-again.patch | 79 +++++++++++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 84 insertions(+), 1 deletion(-) create mode 100644 Make-ksu-honor-KRB5CCNAME-again.patch diff --git a/Make-ksu-honor-KRB5CCNAME-again.patch b/Make-ksu-honor-KRB5CCNAME-again.patch new file mode 100644 index 0000000..19f05ae --- /dev/null +++ b/Make-ksu-honor-KRB5CCNAME-again.patch @@ -0,0 +1,79 @@ +From 59f2a9dd6a83a3721cdffe852343d96ffaa5c18a Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 6 Apr 2020 20:45:10 -0400 +Subject: [PATCH] Make ksu honor KRB5CCNAME again + +Commit d439e370b70f7af4ed2da9c692a3be7dcf7b4ac6 (ticket 8800) caused +ksu to ignore KRB5CCNAME from the environment. ksu uses euid +switching to access the source cache, and should honor KRB5CCNAME to +find the ccache to potentially authorize the su operation. + +Add a helper function init_ksu_context() to create the ksu context, +with explicit code to honor KRB5CCNAME using +krb5_cc_set_default_name(). + +ticket: 8895 +tags: pullup +target_version: 1.18-next + +(cherry picked from commit f040a3ac73947312e1b08c76f75f3389ffb4ba75) +--- + src/clients/ksu/main.c | 31 ++++++++++++++++++++++++++++++- + 1 file changed, 30 insertions(+), 1 deletion(-) + +diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c +index 21a4d02bb..508242e0e 100644 +--- a/src/clients/ksu/main.c ++++ b/src/clients/ksu/main.c +@@ -54,6 +54,7 @@ int force_fork = 0; + static int set_env_var (char *, char *); + static void sweep_up (krb5_context, krb5_ccache); + static char * ontty (void); ++static krb5_error_code init_ksu_context(krb5_context *); + static krb5_error_code set_ccname_env(krb5_context, krb5_ccache); + static void print_status( const char *fmt, ...) + #if __GNUC__ > 2 || (__GNUC__ == 2 && __GNUC_MINOR__ >= 7) +@@ -135,7 +136,7 @@ main (argc, argv) + + unsetenv ("KRB5_CONFIG"); + +- retval = krb5_init_secure_context(&ksu_context); ++ retval = init_ksu_context(&ksu_context); + if (retval) { + com_err(argv[0], retval, _("while initializing krb5")); + exit(1); +@@ -878,6 +879,34 @@ main (argc, argv) + } + } + ++static krb5_error_code ++init_ksu_context(krb5_context *context_out) ++{ ++ krb5_error_code retval; ++ const char *env_ccname; ++ krb5_context context; ++ ++ *context_out = NULL; ++ ++ retval = krb5_init_secure_context(&context); ++ if (retval) ++ return retval; ++ ++ /* We want to obey KRB5CCNAME in this context even though this is a setuid ++ * program. (It will only be used when operating as the real uid.) */ ++ env_ccname = getenv(KRB5_ENV_CCNAME); ++ if (env_ccname != NULL) { ++ retval = krb5_cc_set_default_name(context, env_ccname); ++ if (retval) { ++ krb5_free_context(context); ++ return retval; ++ } ++ } ++ ++ *context_out = context; ++ return 0; ++} ++ + /* Set KRB5CCNAME in the environment to point to ccache. Print an error + * message on failure. */ + static krb5_error_code diff --git a/krb5.spec b/krb5.spec index 9c9022c..6913a3b 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 11%{?dist} +Release: 12%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -59,6 +59,7 @@ Patch13: Add-finalization-safety-check-to-com_err.patch Patch14: Eliminate-redundant-PKINIT-responder-invocation.patch Patch15: Correctly-import-service-GSS-host-based-name.patch Patch16: Do-expiration-warnings-for-all-init_creds-APIs.patch +Patch17: Make-ksu-honor-KRB5CCNAME-again.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -636,6 +637,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Apr 07 2020 Robbie Harwood - 1.18-12 +- Make ksu honor KRB5CCNAME again + * Thu Apr 02 2020 Robbie Harwood - 1.18-11 - Do expiration warnings for all init_creds APIs From 7fca7fd076a59b106c637913678a7752808bf89f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 14 Apr 2020 15:45:43 -0400 Subject: [PATCH 165/304] New upstream version (1.18.1) --- ...finalization-safety-check-to-com_err.patch | 2 +- ...tauth-modules-to-set-hw-authent-flag.patch | 2 +- ...letion-of-require_auth-with-LDAP-KDB.patch | 160 --------------- ...y-import-service-GSS-host-based-name.patch | 2 +- ...ion-warnings-for-all-init_creds-APIs.patch | 4 +- Document-client-keytab-usage.patch | 62 ------ ...edundant-PKINIT-responder-invocation.patch | 2 +- ...-checking-of-KDB-modified-indicators.patch | 189 ------------------ Make-ksu-honor-KRB5CCNAME-again.patch | 79 -------- ...ly-acquired-creds-from-client-keytab.patch | 2 +- downstream-Adjust-build-configuration.patch | 2 +- ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 2 +- downstream-Remove-3des-support.patch | 16 +- downstream-SELinux-integration.patch | 6 +- ...ackported-version-of-OpenSSL-3-KDF-i.patch | 2 +- downstream-fix-debuginfo-with-y.tab.c.patch | 2 +- downstream-ksu-pam-integration.patch | 14 +- downstream-netlib-and-dns.patch | 2 +- krb5.spec | 11 +- 19 files changed, 35 insertions(+), 526 deletions(-) delete mode 100644 Allow-deletion-of-require_auth-with-LDAP-KDB.patch delete mode 100644 Document-client-keytab-usage.patch delete mode 100644 Fix-AS-REQ-checking-of-KDB-modified-indicators.patch delete mode 100644 Make-ksu-honor-KRB5CCNAME-again.patch diff --git a/Add-finalization-safety-check-to-com_err.patch b/Add-finalization-safety-check-to-com_err.patch index 0fcb8cc..0dc7663 100644 --- a/Add-finalization-safety-check-to-com_err.patch +++ b/Add-finalization-safety-check-to-com_err.patch @@ -1,4 +1,4 @@ -From 7d375a59fb36cc5ef8dd87895b83e9dfccc57058 Mon Sep 17 00:00:00 2001 +From c7a37d3e87132864ebc44710baf1d50a69682b5c Mon Sep 17 00:00:00 2001 From: Jiri Sasek Date: Fri, 13 Mar 2020 19:02:58 +0100 Subject: [PATCH] Add finalization safety check to com_err diff --git a/Allow-certauth-modules-to-set-hw-authent-flag.patch b/Allow-certauth-modules-to-set-hw-authent-flag.patch index c1266c9..6fdb430 100644 --- a/Allow-certauth-modules-to-set-hw-authent-flag.patch +++ b/Allow-certauth-modules-to-set-hw-authent-flag.patch @@ -1,4 +1,4 @@ -From 745aa16c41305da1a3f288bf06e551f56cb04594 Mon Sep 17 00:00:00 2001 +From d23b2ed4f06fa77cd021814834dd1391ef6f452f Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 24 Feb 2020 15:58:59 -0500 Subject: [PATCH] Allow certauth modules to set hw-authent flag diff --git a/Allow-deletion-of-require_auth-with-LDAP-KDB.patch b/Allow-deletion-of-require_auth-with-LDAP-KDB.patch deleted file mode 100644 index 58ef195..0000000 --- a/Allow-deletion-of-require_auth-with-LDAP-KDB.patch +++ /dev/null @@ -1,160 +0,0 @@ -From 59eea8a1977c6039069b3826e5e651582a33fc25 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 25 Feb 2020 11:32:09 -0500 -Subject: [PATCH] Allow deletion of require_auth with LDAP KDB - -In update_ldap_mod_auth_ind(), if there is no string attribute value -for require_auth, check for krbPrincipalAuthInd attributes that might -need to be removed. (This will only work if the entry is loaded and -then modified, but that is the normal case for an existing entry.) - -Move the update_ldap_mod_auth_ind() call inside the tl-data -conditional (which should perhaps be a check for KADM5_TL_DATA in the -mask instead). A modification which did not intend to update tl-data -should not remove the krbPrincipalAuthInd attributes. - -Change get_int_from_tl_data() to to zero its output so that it can't -leave a garbage value behind if it returns 0 (as it does if no -KDB_TL_USER_INFO tl-data is present). - -Based on a patch by Glenn Machin. - -ticket: 8877 -tags: pullup -target_version: 1.18-next -target_version: 1.17-next - -(cherry picked from commit 6d9da7bb216f96cbdd731aa894714bd84213a9d0) ---- - src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c | 2 ++ - .../kdb/ldap/libkdb_ldap/ldap_principal2.c | 31 ++++++++++++------- - src/tests/t_kdb.py | 26 +++++++++++++++- - 3 files changed, 47 insertions(+), 12 deletions(-) - -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c -index ec7f32511..6bc20593f 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_misc.c -@@ -721,6 +721,8 @@ get_int_from_tl_data(krb5_context context, krb5_db_entry *entry, int type, - void *ptr; - int *intptr; - -+ *intval = 0; -+ - tl_data.tl_data_type = KDB_TL_USER_INFO; - ret = krb5_dbe_lookup_tl_data(context, entry, &tl_data); - if (ret || tl_data.tl_data_length == 0) -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -index 1d0726707..8d97a29b6 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c -@@ -627,12 +627,22 @@ update_ldap_mod_auth_ind(krb5_context context, krb5_db_entry *entry, - char *auth_ind = NULL; - char *strval[10] = { 0 }; - char *ai, *ai_save = NULL; -- int sv_num = sizeof(strval) / sizeof(*strval); -+ int mask, sv_num = sizeof(strval) / sizeof(*strval); - - ret = krb5_dbe_get_string(context, entry, KRB5_KDB_SK_REQUIRE_AUTH, - &auth_ind); -- if (ret || auth_ind == NULL) -- goto cleanup; -+ if (ret) -+ return ret; -+ if (auth_ind == NULL) { -+ /* If we know krbPrincipalAuthInd attributes are present from loading -+ * the entry, delete them. */ -+ ret = krb5_get_attributes_mask(context, entry, &mask); -+ if (!ret && (mask & KDB_AUTH_IND_ATTR)) { -+ return krb5_add_str_mem_ldap_mod(mods, "krbPrincipalAuthInd", -+ LDAP_MOD_DELETE, NULL); -+ } -+ return 0; -+ } - - ai = strtok_r(auth_ind, " ", &ai_save); - while (ai != NULL && i < sv_num) { -@@ -642,8 +652,6 @@ update_ldap_mod_auth_ind(krb5_context context, krb5_db_entry *entry, - - ret = krb5_add_str_mem_ldap_mod(mods, "krbPrincipalAuthInd", - LDAP_MOD_REPLACE, strval); -- --cleanup: - krb5_dbe_free_string(context, auth_ind); - return ret; - } -@@ -1251,18 +1259,19 @@ krb5_ldap_put_principal(krb5_context context, krb5_db_entry *entry, - - } /* Modify Key data ends here */ - -- /* Auth indicators will also be stored in krbExtraData when processing -- * tl_data. */ -- st = update_ldap_mod_auth_ind(context, entry, &mods); -- if (st != 0) -- goto cleanup; -- - /* Set tl_data */ - if (entry->tl_data != NULL) { - int count = 0; - struct berval **ber_tl_data = NULL; - krb5_tl_data *ptr; - krb5_timestamp unlock_time; -+ -+ /* Normalize required auth indicators, but also store them as string -+ * attributes within krbExtraData. */ -+ st = update_ldap_mod_auth_ind(context, entry, &mods); -+ if (st != 0) -+ goto cleanup; -+ - for (ptr = entry->tl_data; ptr != NULL; ptr = ptr->tl_data_next) { - if (ptr->tl_data_type == KRB5_TL_LAST_PWD_CHANGE - #ifdef SECURID -diff --git a/src/tests/t_kdb.py b/src/tests/t_kdb.py -index 03ee70f47..caa7e9d8f 100755 ---- a/src/tests/t_kdb.py -+++ b/src/tests/t_kdb.py -@@ -319,19 +319,43 @@ realm.klist(realm.user_princ, realm.host_princ) - - mark('LDAP auth indicator') - --# Test auth indicator support -+# Test require_auth normalization. - realm.addprinc('authind', password('authind')) - realm.run([kadminl, 'setstr', 'authind', 'require_auth', 'otp radius']) - -+# Check that krbPrincipalAuthInd attributes are set when the string -+# attribute it set. - out = ldap_search('(krbPrincipalName=authind*)') - if 'krbPrincipalAuthInd: otp' not in out: - fail('Expected krbPrincipalAuthInd value not in output') - if 'krbPrincipalAuthInd: radius' not in out: - fail('Expected krbPrincipalAuthInd value not in output') - -+# Check that the string attribute still appears when the principal is -+# loaded. - realm.run([kadminl, 'getstrs', 'authind'], - expected_msg='require_auth: otp radius') - -+# Modify the LDAP attributes and check that the change is reflected in -+# the string attribute. -+ldap_modify('dn: krbPrincipalName=authind@KRBTEST.COM,cn=t1,cn=krb5\n' -+ 'changetype: modify\n' -+ 'replace: krbPrincipalAuthInd\n' -+ 'krbPrincipalAuthInd: radius\n' -+ 'krbPrincipalAuthInd: pkinit\n') -+realm.run([kadminl, 'getstrs', 'authind'], -+ expected_msg='require_auth: radius pkinit') -+ -+# Regression test for #8877: remove the string attribute and check -+# that it is reflected in the LDAP attributes and by getstrs. -+realm.run([kadminl, 'delstr', 'authind', 'require_auth']) -+out = ldap_search('(krbPrincipalName=authind*)') -+if 'krbPrincipalAuthInd' in out: -+ fail('krbPrincipalAuthInd attribute still present after delstr') -+out = realm.run([kadminl, 'getstrs', 'authind']) -+if 'require_auth' in out: -+ fail('require_auth string attribute still visible after delstr') -+ - mark('LDAP service principal aliases') - - # Test service principal aliases. diff --git a/Correctly-import-service-GSS-host-based-name.patch b/Correctly-import-service-GSS-host-based-name.patch index 683b2d9..523ebaf 100644 --- a/Correctly-import-service-GSS-host-based-name.patch +++ b/Correctly-import-service-GSS-host-based-name.patch @@ -1,4 +1,4 @@ -From 53b7be87de77b09f44b4ced1d4e85f520c9ce71a Mon Sep 17 00:00:00 2001 +From dd4364d76925ce1fe21c2ab995554d6af3a2ea12 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 30 Mar 2020 15:26:02 -0400 Subject: [PATCH] Correctly import "service@" GSS host-based name diff --git a/Do-expiration-warnings-for-all-init_creds-APIs.patch b/Do-expiration-warnings-for-all-init_creds-APIs.patch index d94f11d..3dbe1f5 100644 --- a/Do-expiration-warnings-for-all-init_creds-APIs.patch +++ b/Do-expiration-warnings-for-all-init_creds-APIs.patch @@ -1,4 +1,4 @@ -From 9d452dc135ba0fad9470f096938a5dbfbacdbbe1 Mon Sep 17 00:00:00 2001 +From c136cfe050d203c910624573a33247fde2889b09 Mon Sep 17 00:00:00 2001 From: Sumit Bose Date: Fri, 28 Feb 2020 10:11:49 +0100 Subject: [PATCH] Do expiration warnings for all init_creds APIs @@ -21,7 +21,7 @@ ticket: 8893 (new) 5 files changed, 165 insertions(+), 135 deletions(-) diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 26a3b6ec8..36300ea53 100644 +index 6355e6540..f8269fb17 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin @@ -7174,11 +7174,10 @@ typedef void diff --git a/Document-client-keytab-usage.patch b/Document-client-keytab-usage.patch deleted file mode 100644 index 800522f..0000000 --- a/Document-client-keytab-usage.patch +++ /dev/null @@ -1,62 +0,0 @@ -From 90a4102f334ce0c655492de9248c3c60ffbd0449 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 16 Mar 2020 18:14:30 -0400 -Subject: [PATCH] Document client keytab usage - -ticket: 8886 (new) -tags: pullup -target_version: 1.18-next - -(cherry picked from commit 366c64897d55c86cdc616d2d1cf4617ff8a07a99) ---- - doc/admin/appl_servers.rst | 37 +++++++++++++++++++++++++++++++++++++ - 1 file changed, 37 insertions(+) - -diff --git a/doc/admin/appl_servers.rst b/doc/admin/appl_servers.rst -index fee49f027..5232db9af 100644 ---- a/doc/admin/appl_servers.rst -+++ b/doc/admin/appl_servers.rst -@@ -60,6 +60,43 @@ To remove a principal from an existing keytab, use the kadmin - :end-before: _ktremove_end: - - -+Using a keytab to acquire client credentials -+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -+ -+While keytabs are ordinarily used to accept credentials from clients, -+they can also be used to acquire initial credentials, allowing one -+service to authenticate to another. -+ -+To manually obtain credentials using a keytab, use the :ref:`kinit(1)` -+**-k** option, together with the **-t** option if the keytab is not in -+the default location. -+ -+Beginning with release 1.11, GSSAPI applications can be configured to -+automatically obtain initial credentials from a keytab as needed. The -+recommended configuration is as follows: -+ -+#. Create a keytab containing a single entry for the desired client -+ identity. -+ -+#. Place the keytab in a location readable by the service, and set the -+ **KRB5_CLIENT_KTNAME** environment variable to its filename. -+ Alternatively, use the **default_client_keytab_name** profile -+ variable in :ref:`libdefaults`, or use the default location of -+ |ckeytab|. -+ -+#. Set **KRB5CCNAME** to a filename writable by the service, which -+ will not be used for any other purpose. Do not manually obtain -+ credentials at this location. (Another credential cache type -+ besides **FILE** can be used if desired, as long the cache will not -+ conflict with another use. A **MEMORY** cache can be used if the -+ service runs as a long-lived process. See :ref:`ccache_definition` -+ for details.) -+ -+#. Start the service. When it authenticates using GSSAPI, it will -+ automatically obtain credentials from the client keytab into the -+ specified credential cache, and refresh them before they expire. -+ -+ - Clock Skew - ---------- - diff --git a/Eliminate-redundant-PKINIT-responder-invocation.patch b/Eliminate-redundant-PKINIT-responder-invocation.patch index ea973b7..92bc1ab 100644 --- a/Eliminate-redundant-PKINIT-responder-invocation.patch +++ b/Eliminate-redundant-PKINIT-responder-invocation.patch @@ -1,4 +1,4 @@ -From b5793f8024320aaa7a85ca39cdc03bf99773bf11 Mon Sep 17 00:00:00 2001 +From 4a05805eb39ba088c07f782fb52a6538ec3f2db6 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 23 Mar 2020 19:10:03 -0400 Subject: [PATCH] Eliminate redundant PKINIT responder invocation diff --git a/Fix-AS-REQ-checking-of-KDB-modified-indicators.patch b/Fix-AS-REQ-checking-of-KDB-modified-indicators.patch deleted file mode 100644 index 1655c38..0000000 --- a/Fix-AS-REQ-checking-of-KDB-modified-indicators.patch +++ /dev/null @@ -1,189 +0,0 @@ -From 744154b19c8000965e5a5de51d5dbef0794958be Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 19 Feb 2020 15:36:38 -0500 -Subject: [PATCH] Fix AS-REQ checking of KDB-modified indicators - -Commit 7196c03f18f14695abeb5ae4923004469b172f0f (ticket 8823) gave the -KDB the ability to modify auth indicators, but it happens after the -asserted indicators are checked against the server principal -requirements. In finish_process_as_req(), move the call to -check_indicators() after the call to handle_authdata() so that the -final indicator list is checked. - -For the test case, add string attribute functionality to the test KDB -module, and fix a bug where test_get_principal() would return failure -if a principal has no keys. Also add a test case for AS-REQ -enforcement of normally asserted auth indicators. - -ticket: 8876 (new) -tags: pullup -target_version: 1.18-next - -(cherry picked from commit 109e30ce22c20f18b8233119f274935bdf573886) ---- - src/kdc/do_as_req.c | 14 +++++------ - src/plugins/kdb/test/kdb_test.c | 42 +++++++++++++++++++++++++++++++-- - src/tests/t_authdata.py | 11 +++++++++ - 3 files changed, 58 insertions(+), 9 deletions(-) - -diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c -index 87dd7e993..9ae7b0a5e 100644 ---- a/src/kdc/do_as_req.c -+++ b/src/kdc/do_as_req.c -@@ -211,13 +211,6 @@ finish_process_as_req(struct as_req_state *state, krb5_error_code errcode) - - au_state->stage = ENCR_REP; - -- errcode = check_indicators(kdc_context, state->server, -- state->auth_indicators); -- if (errcode) { -- state->status = "HIGHER_AUTHENTICATION_REQUIRED"; -- goto egress; -- } -- - state->ticket_reply.enc_part2 = &state->enc_tkt_reply; - - errcode = check_kdcpolicy_as(kdc_context, state->request, state->client, -@@ -301,6 +294,13 @@ finish_process_as_req(struct as_req_state *state, krb5_error_code errcode) - goto egress; - } - -+ errcode = check_indicators(kdc_context, state->server, -+ state->auth_indicators); -+ if (errcode) { -+ state->status = "HIGHER_AUTHENTICATION_REQUIRED"; -+ goto egress; -+ } -+ - errcode = krb5_encrypt_tkt_part(kdc_context, &state->server_keyblock, - &state->ticket_reply); - if (errcode) -diff --git a/src/plugins/kdb/test/kdb_test.c b/src/plugins/kdb/test/kdb_test.c -index 1936cb0e4..95a6062e2 100644 ---- a/src/plugins/kdb/test/kdb_test.c -+++ b/src/plugins/kdb/test/kdb_test.c -@@ -54,6 +54,8 @@ - * # Initial number is kvno; defaults to 1. - * keys = 3 aes256-cts aes128-cts:normal - * keys = 2 rc4-hmac -+ * strings = key1:value1 -+ * strings = key2:value2 - * } - * } - * delegation = { -@@ -282,6 +284,33 @@ make_keys(char **strings, const char *princstr, const krb5_data *realm, - ent->n_key_data = nkeys; - } - -+static void -+make_strings(char **stringattrs, krb5_db_entry *ent) -+{ -+ struct k5buf buf; -+ char **p; -+ const char *str, *sep; -+ krb5_tl_data *tl; -+ -+ k5_buf_init_dynamic(&buf); -+ for (p = stringattrs; *p != NULL; p++) { -+ str = *p; -+ sep = strchr(str, ':'); -+ assert(sep != NULL); -+ k5_buf_add_len(&buf, str, sep - str); -+ k5_buf_add_len(&buf, "\0", 1); -+ k5_buf_add_len(&buf, sep + 1, strlen(sep + 1) + 1); -+ } -+ assert(buf.data != NULL); -+ -+ tl = ealloc(sizeof(*ent->tl_data)); -+ tl->tl_data_next = NULL; -+ tl->tl_data_type = KRB5_TL_STRING_ATTRS; -+ tl->tl_data_length = buf.len; -+ tl->tl_data_contents = buf.data; -+ ent->tl_data = tl; -+} -+ - static krb5_error_code - test_init() - { -@@ -339,7 +368,8 @@ test_get_principal(krb5_context context, krb5_const_principal search_for, - krb5_principal princ = NULL, tgtprinc; - krb5_principal_data empty_princ = { KV5M_PRINCIPAL }; - testhandle h = context->dal_handle->db_context; -- char *search_name = NULL, *canon = NULL, *flagstr, **names, **key_strings; -+ char *search_name = NULL, *canon = NULL, *flagstr; -+ char **names, **key_strings, **stringattrs; - const char *ename; - krb5_db_entry *ent; - -@@ -415,7 +445,7 @@ test_get_principal(krb5_context context, krb5_const_principal search_for, - ent->pw_expiration = get_time(h, "princs", ename, "pwexpiration"); - - /* Leave last_success, last_failed, fail_auth_count zeroed. */ -- /* Leave tl_data and e_data empty. */ -+ /* Leave e_data empty. */ - - set_names(h, "princs", ename, "keys"); - ret = profile_get_values(h->profile, h->names, &key_strings); -@@ -424,11 +454,19 @@ test_get_principal(krb5_context context, krb5_const_principal search_for, - profile_free_list(key_strings); - } - -+ set_names(h, "princs", ename, "strings"); -+ ret = profile_get_values(h->profile, h->names, &stringattrs); -+ if (ret != PROF_NO_RELATION) { -+ make_strings(stringattrs, ent); -+ profile_free_list(stringattrs); -+ } -+ - /* We must include mod-princ data or kadm5_get_principal() won't work and - * we can't extract keys with kadmin.local. */ - check(krb5_dbe_update_mod_princ_data(context, ent, 0, &empty_princ)); - - *entry = ent; -+ ret = 0; - - cleanup: - krb5_free_unparsed_name(context, search_name); -diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py -index 3153ebca3..4fbdbec05 100644 ---- a/src/tests/t_authdata.py -+++ b/src/tests/t_authdata.py -@@ -158,6 +158,8 @@ realm.run(['./adata', realm.host_princ], expected_msg='+97: [indcl]') - mark('auth indicator enforcement') - realm.addprinc('restricted') - realm.run([kadminl, 'setstr', 'restricted', 'require_auth', 'superstrong']) -+realm.kinit(realm.user_princ, password('user'), ['-S', 'restricted'], -+ expected_code=1, expected_msg='KDC policy rejects request') - realm.run([kvno, 'restricted'], expected_code=1, - expected_msg='KDC policy rejects request') - realm.run([kadminl, 'setstr', 'restricted', 'require_auth', 'indcl']) -@@ -194,6 +196,8 @@ testprincs = {'krbtgt/KRBTEST.COM': {'keys': 'aes128-cts'}, - 'krbtgt/FOREIGN': {'keys': 'aes128-cts'}, - 'user': {'keys': 'aes128-cts', 'flags': '+preauth'}, - 'user2': {'keys': 'aes128-cts', 'flags': '+preauth'}, -+ 'rservice': {'keys': 'aes128-cts', -+ 'strings': 'require_auth:strong'}, - 'service/1': {'keys': 'aes128-cts', - 'flags': '+ok_to_auth_as_delegate'}, - 'service/2': {'keys': 'aes128-cts'}, -@@ -208,6 +212,7 @@ usercache = 'FILE:' + os.path.join(realm.testdir, 'usercache') - realm.extract_keytab(realm.krbtgt_princ, realm.keytab) - realm.extract_keytab('krbtgt/FOREIGN', realm.keytab) - realm.extract_keytab(realm.user_princ, realm.keytab) -+realm.extract_keytab('ruser', realm.keytab) - realm.extract_keytab('service/1', realm.keytab) - realm.extract_keytab('service/2', realm.keytab) - realm.extract_keytab('noauthdata', realm.keytab) -@@ -252,6 +257,12 @@ if ' -2: self_ad' not in out or ' -2: proxy_ad' not in out: - realm.kinit(realm.user_princ, None, ['-k', '-X', 'indicators=dummy dbincr1']) - realm.run(['./adata', realm.krbtgt_princ], expected_msg='+97: [dbincr2]') - realm.run(['./adata', 'service/1'], expected_msg='+97: [dbincr3]') -+realm.kinit(realm.user_princ, None, -+ ['-k', '-X', 'indicators=strong', '-S', 'rservice']) -+# Test enforcement of altered indicators during AS request. -+realm.kinit(realm.user_princ, None, -+ ['-k', '-X', 'indicators=strong dbincr1', '-S', 'rservice'], -+ expected_code=1) - - # Test that KDB module authdata is included in an AS request, by - # default or with an explicit PAC request. diff --git a/Make-ksu-honor-KRB5CCNAME-again.patch b/Make-ksu-honor-KRB5CCNAME-again.patch deleted file mode 100644 index 19f05ae..0000000 --- a/Make-ksu-honor-KRB5CCNAME-again.patch +++ /dev/null @@ -1,79 +0,0 @@ -From 59f2a9dd6a83a3721cdffe852343d96ffaa5c18a Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 6 Apr 2020 20:45:10 -0400 -Subject: [PATCH] Make ksu honor KRB5CCNAME again - -Commit d439e370b70f7af4ed2da9c692a3be7dcf7b4ac6 (ticket 8800) caused -ksu to ignore KRB5CCNAME from the environment. ksu uses euid -switching to access the source cache, and should honor KRB5CCNAME to -find the ccache to potentially authorize the su operation. - -Add a helper function init_ksu_context() to create the ksu context, -with explicit code to honor KRB5CCNAME using -krb5_cc_set_default_name(). - -ticket: 8895 -tags: pullup -target_version: 1.18-next - -(cherry picked from commit f040a3ac73947312e1b08c76f75f3389ffb4ba75) ---- - src/clients/ksu/main.c | 31 ++++++++++++++++++++++++++++++- - 1 file changed, 30 insertions(+), 1 deletion(-) - -diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c -index 21a4d02bb..508242e0e 100644 ---- a/src/clients/ksu/main.c -+++ b/src/clients/ksu/main.c -@@ -54,6 +54,7 @@ int force_fork = 0; - static int set_env_var (char *, char *); - static void sweep_up (krb5_context, krb5_ccache); - static char * ontty (void); -+static krb5_error_code init_ksu_context(krb5_context *); - static krb5_error_code set_ccname_env(krb5_context, krb5_ccache); - static void print_status( const char *fmt, ...) - #if __GNUC__ > 2 || (__GNUC__ == 2 && __GNUC_MINOR__ >= 7) -@@ -135,7 +136,7 @@ main (argc, argv) - - unsetenv ("KRB5_CONFIG"); - -- retval = krb5_init_secure_context(&ksu_context); -+ retval = init_ksu_context(&ksu_context); - if (retval) { - com_err(argv[0], retval, _("while initializing krb5")); - exit(1); -@@ -878,6 +879,34 @@ main (argc, argv) - } - } - -+static krb5_error_code -+init_ksu_context(krb5_context *context_out) -+{ -+ krb5_error_code retval; -+ const char *env_ccname; -+ krb5_context context; -+ -+ *context_out = NULL; -+ -+ retval = krb5_init_secure_context(&context); -+ if (retval) -+ return retval; -+ -+ /* We want to obey KRB5CCNAME in this context even though this is a setuid -+ * program. (It will only be used when operating as the real uid.) */ -+ env_ccname = getenv(KRB5_ENV_CCNAME); -+ if (env_ccname != NULL) { -+ retval = krb5_cc_set_default_name(context, env_ccname); -+ if (retval) { -+ krb5_free_context(context); -+ return retval; -+ } -+ } -+ -+ *context_out = context; -+ return 0; -+} -+ - /* Set KRB5CCNAME in the environment to point to ccache. Print an error - * message on failure. */ - static krb5_error_code diff --git a/Refresh-manually-acquired-creds-from-client-keytab.patch b/Refresh-manually-acquired-creds-from-client-keytab.patch index fe2588f..cb20c44 100644 --- a/Refresh-manually-acquired-creds-from-client-keytab.patch +++ b/Refresh-manually-acquired-creds-from-client-keytab.patch @@ -1,4 +1,4 @@ -From e67aca9a77d78efa798237b43e177caf9e79f64a Mon Sep 17 00:00:00 2001 +From 685aada9eae420cb5156ca7b71c2c7614c0b6e2c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 26 Feb 2020 18:27:17 -0500 Subject: [PATCH] Refresh manually acquired creds from client keytab diff --git a/downstream-Adjust-build-configuration.patch b/downstream-Adjust-build-configuration.patch index 68ecf50..f15a4a2 100644 --- a/downstream-Adjust-build-configuration.patch +++ b/downstream-Adjust-build-configuration.patch @@ -1,4 +1,4 @@ -From cbfe13d5f0de6e2a3deab2ba0dacda8c952476ab Mon Sep 17 00:00:00 2001 +From 92508996ed4c69fa6f5cf855fdf10f34cfa07ec9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] [downstream] Adjust build configuration diff --git a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index 573d222..e6a0a64 100644 --- a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From 5978878bcee5ec39e4357f408470d39e9540d2bf Mon Sep 17 00:00:00 2001 +From a721df13d09b5fdad32de15e6aa973b732727aa9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 diff --git a/downstream-Remove-3des-support.patch b/downstream-Remove-3des-support.patch index 4f14733..01d9338 100644 --- a/downstream-Remove-3des-support.patch +++ b/downstream-Remove-3des-support.patch @@ -1,4 +1,4 @@ -From 7dda569170c3f6ab08a9373572b4bc90481eeaf7 Mon Sep 17 00:00:00 2001 +From e9cd83237b54e2f6010a063f523217b0a442ecbf Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] [downstream] Remove 3des support @@ -256,7 +256,7 @@ index 68debe714..788d094bf 100644 CKSUMTYPE_NIST_SHA.rst CKSUMTYPE_RSA_MD4.rst diff --git a/doc/conf.py b/doc/conf.py -index fc5662767..37eda67fa 100644 +index c32b2882a..5eeafc30f 100644 --- a/doc/conf.py +++ b/doc/conf.py @@ -272,7 +272,7 @@ else: @@ -269,7 +269,7 @@ index fc5662767..37eda67fa 100644 .. |copy| unicode:: U+000A9 ''' diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst -index 513ecfd1b..05243f47b 100644 +index 5d286b6ee..f4594ed13 100644 --- a/doc/mitK5features.rst +++ b/doc/mitK5features.rst @@ -37,7 +37,7 @@ Database backends: LDAP, DB2, LMDB @@ -316,7 +316,7 @@ index 440a22bd9..d4e4da525 100644 lib/crypto/$CRYPTO_IMPL/sha1 lib/crypto/$CRYPTO_IMPL/sha2 lib/crypto/$CRYPTO_IMPL/aes lib/crypto/$CRYPTO_IMPL/camellia diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index d1f5661bf..26a3b6ec8 100644 +index e9435c693..6355e6540 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin @@ -426,8 +426,8 @@ typedef struct _krb5_crypto_iov { @@ -365,7 +365,7 @@ index 8a4b87de1..d7f1d076b 100644 + supported_enctypes = aes256-cts:normal aes128-cts:normal aes256-sha2:normal aes128-sha2:normal } diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index 221bde1dd..b8d292021 100644 +index e5898ea63..973976fd9 100644 --- a/src/kdc/kdc_util.c +++ b/src/kdc/kdc_util.c @@ -1103,8 +1103,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) @@ -377,7 +377,7 @@ index 221bde1dd..b8d292021 100644 else return krb5_enctype_to_name(ktype, FALSE, buf, buflen); -@@ -1841,8 +1839,6 @@ krb5_boolean +@@ -1826,8 +1824,6 @@ krb5_boolean enctype_requires_etype_info_2(krb5_enctype enctype) { switch(enctype) { @@ -6258,10 +6258,10 @@ index f71774cdc..d1857c433 100644 "3BB3AE288C12B3B9D06B208A4151B3B6", "9AEA11A3BCF3C53F1F91F5A0BA2132E2501ADF5F3C28" diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py -index 378174a2e..3153ebca3 100644 +index c589adf2a..4fbdbec05 100644 --- a/src/tests/t_authdata.py +++ b/src/tests/t_authdata.py -@@ -172,7 +172,7 @@ realm.run([kvno, 'restricted']) +@@ -174,7 +174,7 @@ realm.run([kvno, 'restricted']) # preferred krbtgt enctype changes. mark('#8139 regression test') realm.kinit(realm.user_princ, password('user'), ['-f']) diff --git a/downstream-SELinux-integration.patch b/downstream-SELinux-integration.patch index e40bd1a..3d3bd08 100644 --- a/downstream-SELinux-integration.patch +++ b/downstream-SELinux-integration.patch @@ -1,4 +1,4 @@ -From 4a215a206d1d5af69ea9fbf1e78001971ab18be2 Mon Sep 17 00:00:00 2001 +From 0f8851a23a7b6fa0e195e01d0475e9e55707adf2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] [downstream] SELinux integration @@ -236,7 +236,7 @@ index 000000000..dfaaa847c +#endif +#endif diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index d48685357..d1f5661bf 100644 +index 79761f6d2..e9435c693 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin @@ -87,6 +87,12 @@ @@ -437,7 +437,7 @@ index 021c94398..aaf573439 100644 goto report_errno; writevno = 1; diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c -index 2a03ae980..85dbfeb47 100644 +index 7073459f0..e9b99f4ca 100644 --- a/src/lib/krb5/os/trace.c +++ b/src/lib/krb5/os/trace.c @@ -458,7 +458,7 @@ krb5_set_trace_filename(krb5_context context, const char *filename) diff --git a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch index b796692..478fd82 100644 --- a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch +++ b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch @@ -1,4 +1,4 @@ -From 0a53577ebb24f0f9b05d769b34bdd4ef2ee2a629 Mon Sep 17 00:00:00 2001 +From 3f5875cf859271bca62f07aee6f663787972def9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 15 Nov 2019 20:05:16 +0000 Subject: [PATCH] [downstream] Use backported version of OpenSSL-3 KDF diff --git a/downstream-fix-debuginfo-with-y.tab.c.patch b/downstream-fix-debuginfo-with-y.tab.c.patch index e8e1870..167fcaf 100644 --- a/downstream-fix-debuginfo-with-y.tab.c.patch +++ b/downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,4 +1,4 @@ -From ed161c3f3cb642d025f0fee6d4af6f56bba711e9 Mon Sep 17 00:00:00 2001 +From f4002f246332695d8ea12ec803139fcac18fbba2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] [downstream] fix debuginfo with y.tab.c diff --git a/downstream-ksu-pam-integration.patch b/downstream-ksu-pam-integration.patch index 4532601..220363b 100644 --- a/downstream-ksu-pam-integration.patch +++ b/downstream-ksu-pam-integration.patch @@ -1,4 +1,4 @@ -From 9a082e1e02ae4efd2404d0672d38b3d4eb2d6660 Mon Sep 17 00:00:00 2001 +From a7322a84657752c886c317a6994a9fc7a4a70ca5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] [downstream] ksu pam integration @@ -145,7 +145,7 @@ index 8b4edce4d..9d58f29b5 100644 clean: $(RM) ksu diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c -index 4f03dd8ed..21a4d02bb 100644 +index 57c349200..508242e0e 100644 --- a/src/clients/ksu/main.c +++ b/src/clients/ksu/main.c @@ -26,6 +26,7 @@ @@ -175,7 +175,7 @@ index 4f03dd8ed..21a4d02bb 100644 /***********/ #define KS_TEMPORARY_CACHE "MEMORY:_ksu" -@@ -535,6 +541,23 @@ main (argc, argv) +@@ -536,6 +542,23 @@ main (argc, argv) prog_name,target_user,client_name, source_user,ontty()); @@ -199,7 +199,7 @@ index 4f03dd8ed..21a4d02bb 100644 /* Run authorization as target.*/ if (krb5_seteuid(target_uid)) { com_err(prog_name, errno, _("while switching to target for " -@@ -595,6 +618,24 @@ main (argc, argv) +@@ -596,6 +619,24 @@ main (argc, argv) exit(1); } @@ -224,7 +224,7 @@ index 4f03dd8ed..21a4d02bb 100644 } if( some_rest_copy){ -@@ -652,6 +693,30 @@ main (argc, argv) +@@ -653,6 +694,30 @@ main (argc, argv) exit(1); } @@ -255,7 +255,7 @@ index 4f03dd8ed..21a4d02bb 100644 /* set permissions */ if (setgid(target_pwd->pw_gid) < 0) { perror("ksu: setgid"); -@@ -749,7 +814,7 @@ main (argc, argv) +@@ -750,7 +815,7 @@ main (argc, argv) fprintf(stderr, "program to be execed %s\n",params[0]); } @@ -264,7 +264,7 @@ index 4f03dd8ed..21a4d02bb 100644 execv(params[0], params); com_err(prog_name, errno, _("while trying to execv %s"), params[0]); sweep_up(ksu_context, cc_target); -@@ -779,16 +844,35 @@ main (argc, argv) +@@ -780,16 +845,35 @@ main (argc, argv) if (ret_pid == -1) { com_err(prog_name, errno, _("while calling waitpid")); } diff --git a/downstream-netlib-and-dns.patch b/downstream-netlib-and-dns.patch index ba04deb..d7ceab1 100644 --- a/downstream-netlib-and-dns.patch +++ b/downstream-netlib-and-dns.patch @@ -1,4 +1,4 @@ -From 40553473b674dfbb6328389b6b39ebe3218ed597 Mon Sep 17 00:00:00 2001 +From 355dd481511af4d517ee540854f95a6fb12116a9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] [downstream] netlib and dns diff --git a/krb5.spec b/krb5.spec index 6913a3b..37089cc 100644 --- a/krb5.spec +++ b/krb5.spec @@ -16,9 +16,9 @@ Summary: The Kerberos network authentication system Name: krb5 -Version: 1.18 +Version: 1.18.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 12%{?dist} +Release: 1%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -50,16 +50,12 @@ Patch4: downstream-fix-debuginfo-with-y.tab.c.patch Patch5: downstream-Remove-3des-support.patch Patch6: downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch -Patch8: Fix-AS-REQ-checking-of-KDB-modified-indicators.patch Patch9: Allow-certauth-modules-to-set-hw-authent-flag.patch -Patch10: Allow-deletion-of-require_auth-with-LDAP-KDB.patch Patch11: Refresh-manually-acquired-creds-from-client-keytab.patch -Patch12: Document-client-keytab-usage.patch Patch13: Add-finalization-safety-check-to-com_err.patch Patch14: Eliminate-redundant-PKINIT-responder-invocation.patch Patch15: Correctly-import-service-GSS-host-based-name.patch Patch16: Do-expiration-warnings-for-all-init_creds-APIs.patch -Patch17: Make-ksu-honor-KRB5CCNAME-again.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -637,6 +633,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Apr 14 2020 Robbie Harwood - 1.18.1-1 +- New upstream version (1.18.1) + * Tue Apr 07 2020 Robbie Harwood - 1.18-12 - Make ksu honor KRB5CCNAME again From 46d8c677aef7d66f4270be9084f89b71fe0ae565 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 14 Apr 2020 15:50:03 -0400 Subject: [PATCH 166/304] It usually helps if I commit the sources file --- .gitignore | 2 ++ sources | 4 ++-- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 88fde60..5de4b79 100644 --- a/.gitignore +++ b/.gitignore @@ -183,3 +183,5 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.18-beta2.tar.gz.asc /krb5-1.18.tar.gz /krb5-1.18.tar.gz.asc +/krb5-1.18.1.tar.gz +/krb5-1.18.1.tar.gz.asc diff --git a/sources b/sources index d851b71..a2aa017 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.18.tar.gz) = 36a01ea310b4b3d0a3d209b641739575239e1ca5e93b3de99cb1fec83e82f9a70ad0761dd6eb77cda5c18c53044ab80168b00725642a0c2dfde0e492c42af6a9 -SHA512 (krb5-1.18.tar.gz.asc) = a9399a0e98a810b0c1c9e47c280edec329018714d60b3be228d125ea6e9d1548030940ca29ffd92a424675b02922a8509ed6ffec30d42da6c0d505d84c5aba63 +SHA512 (krb5-1.18.1.tar.gz) = c96c9ed676c8ccb9b65d17bb1d982c266228c75030a2d8fd5d7952ee8cdf362a22d202e93018d1011a5e7bd9a9fabe69aa1578d1d2e4839a78b9916d8b8019ce +SHA512 (krb5-1.18.1.tar.gz.asc) = e7db98b9f053de793763af734a7b8de81702156d12dfeb7295032c2416a43406840960fb8d16efb6cad911c1cb047da1f6fe17c88289aad28983b5d531f47908 From 19d5d2e504feee8022564d27832956218146d392 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 28 Apr 2020 13:12:21 -0400 Subject: [PATCH 167/304] Pass gss_localname() through SPNEGO --- Pass-gss_localname-through-SPNEGO.patch | 58 +++++++++++++++++++++++++ krb5.spec | 18 ++++---- 2 files changed, 68 insertions(+), 8 deletions(-) create mode 100644 Pass-gss_localname-through-SPNEGO.patch diff --git a/Pass-gss_localname-through-SPNEGO.patch b/Pass-gss_localname-through-SPNEGO.patch new file mode 100644 index 0000000..37aef38 --- /dev/null +++ b/Pass-gss_localname-through-SPNEGO.patch @@ -0,0 +1,58 @@ +From 646212314a580a8cdffdacda9cb3c8f806471b08 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sun, 26 Apr 2020 19:55:54 -0400 +Subject: [PATCH] Pass gss_localname() through SPNEGO + +ticket: 8897 (new) +(cherry picked from commit f7b8a6432bd289bdc528017be122305f95b8e285) +--- + src/lib/gssapi/spnego/gssapiP_spnego.h | 8 ++++++++ + src/lib/gssapi/spnego/spnego_mech.c | 9 ++++++++- + 2 files changed, 16 insertions(+), 1 deletion(-) + +diff --git a/src/lib/gssapi/spnego/gssapiP_spnego.h b/src/lib/gssapi/spnego/gssapiP_spnego.h +index a93763314..066ec736f 100644 +--- a/src/lib/gssapi/spnego/gssapiP_spnego.h ++++ b/src/lib/gssapi/spnego/gssapiP_spnego.h +@@ -357,6 +357,14 @@ OM_uint32 KRB5_CALLCONV spnego_gss_wrap_size_limit + OM_uint32 *max_input_size + ); + ++OM_uint32 KRB5_CALLCONV spnego_gss_localname ++( ++ OM_uint32 *minor_status, ++ const gss_name_t pname, ++ const gss_const_OID mech_type, ++ gss_buffer_t localname ++); ++ + OM_uint32 KRB5_CALLCONV spnego_gss_get_mic + ( + OM_uint32 *minor_status, +diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/spnego/spnego_mech.c +index 8e0c3a348..8d36a05e8 100644 +--- a/src/lib/gssapi/spnego/spnego_mech.c ++++ b/src/lib/gssapi/spnego/spnego_mech.c +@@ -237,7 +237,7 @@ static struct gss_config spnego_mechanism = + spnego_gss_inquire_context, /* gss_inquire_context */ + NULL, /* gss_internal_release_oid */ + spnego_gss_wrap_size_limit, /* gss_wrap_size_limit */ +- NULL, /* gssd_pname_to_uid */ ++ spnego_gss_localname, + NULL, /* gss_userok */ + NULL, /* gss_export_name */ + spnego_gss_duplicate_name, /* gss_duplicate_name */ +@@ -2371,6 +2371,13 @@ spnego_gss_wrap_size_limit( + return (ret); + } + ++OM_uint32 KRB5_CALLCONV ++spnego_gss_localname(OM_uint32 *minor_status, const gss_name_t pname, ++ const gss_const_OID mech_type, gss_buffer_t localname) ++{ ++ return gss_localname(minor_status, pname, GSS_C_NO_OID, localname); ++} ++ + OM_uint32 KRB5_CALLCONV + spnego_gss_get_mic( + OM_uint32 *minor_status, diff --git a/krb5.spec b/krb5.spec index 37089cc..03bfa71 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1%{?dist} +Release: 3%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -56,6 +56,7 @@ Patch13: Add-finalization-safety-check-to-com_err.patch Patch14: Eliminate-redundant-PKINIT-responder-invocation.patch Patch15: Correctly-import-service-GSS-host-based-name.patch Patch16: Do-expiration-warnings-for-all-init_creds-APIs.patch +Patch17: Pass-gss_localname-through-SPNEGO.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -80,18 +81,13 @@ BuildRequires: iproute BuildRequires: libverto-devel BuildRequires: openldap-devel BuildRequires: lmdb-devel +BuildRequires: nss_wrapper +BuildRequires: socket_wrapper # Need KDFs. This is the backported version BuildRequires: openssl-devel >= 1:1.1.1d-4 BuildRequires: openssl-devel < 1:3.0.0 -%ifarch %{ix86} x86_64 -BuildRequires: yasm -%endif - -BuildRequires: nss_wrapper -BuildRequires: socket_wrapper - %description Kerberos V5 is a trusted-third-party network authentication system, which can improve your network's security by eliminating the insecure @@ -633,6 +629,12 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Apr 28 2020 Robbie Harwood - 1.18.1-3 +- Pass gss_localname() through SPNEGO + +* Tue Apr 14 2020 Robbie Harwood - 1.18-1.1 +- Drop yasm requirement since we don't use builtin crypto + * Tue Apr 14 2020 Robbie Harwood - 1.18.1-1 - New upstream version (1.18.1) From a9ccd6fd5703d21eecd044c5b984daa5a2441770 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 8 May 2020 14:14:22 -0400 Subject: [PATCH 168/304] Omit KDC indicator check for S4U2Self requests --- ...ndicator-check-for-S4U2Self-requests.patch | 48 +++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 53 insertions(+), 1 deletion(-) create mode 100644 Omit-KDC-indicator-check-for-S4U2Self-requests.patch diff --git a/Omit-KDC-indicator-check-for-S4U2Self-requests.patch b/Omit-KDC-indicator-check-for-S4U2Self-requests.patch new file mode 100644 index 0000000..b1b1908 --- /dev/null +++ b/Omit-KDC-indicator-check-for-S4U2Self-requests.patch @@ -0,0 +1,48 @@ +From 442f1fa5b2e4034954a51048414cc0863b914379 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 6 May 2020 16:03:13 -0400 +Subject: [PATCH] Omit KDC indicator check for S4U2Self requests + +As there was no initial ticket exchange from the client for an +S4U2Self request, the auth indicator check is inapplicable (and would +always fail if any auth indicators are required). + +ticket: 8902 (new) +(cherry picked from commit 183631fbf72351c2d5fc7d60b2d9fc4d09fe7465) +--- + src/kdc/do_tgs_req.c | 14 +++++++------- + 1 file changed, 7 insertions(+), 7 deletions(-) + +diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c +index 241f34e2a..463a9c0dd 100644 +--- a/src/kdc/do_tgs_req.c ++++ b/src/kdc/do_tgs_req.c +@@ -392,8 +392,8 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, + } + authtime = subject_tkt->times.authtime; + +- /* Extract auth indicators from the subject ticket, except for S4U2Self +- * requests (where the client didn't authenticate). */ ++ /* Extract and check auth indicators from the subject ticket, except for ++ * S4U2Self requests (where the client didn't authenticate). */ + if (s4u_x509_user == NULL) { + errcode = get_auth_indicators(kdc_context, subject_tkt, local_tgt, + &local_tgt_key, &auth_indicators); +@@ -401,12 +401,12 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, + status = "GET_AUTH_INDICATORS"; + goto cleanup; + } +- } + +- errcode = check_indicators(kdc_context, server, auth_indicators); +- if (errcode) { +- status = "HIGHER_AUTHENTICATION_REQUIRED"; +- goto cleanup; ++ errcode = check_indicators(kdc_context, server, auth_indicators); ++ if (errcode) { ++ status = "HIGHER_AUTHENTICATION_REQUIRED"; ++ goto cleanup; ++ } + } + + if (is_referral) diff --git a/krb5.spec b/krb5.spec index 03bfa71..23dcee4 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 3%{?dist} +Release: 4%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -57,6 +57,7 @@ Patch14: Eliminate-redundant-PKINIT-responder-invocation.patch Patch15: Correctly-import-service-GSS-host-based-name.patch Patch16: Do-expiration-warnings-for-all-init_creds-APIs.patch Patch17: Pass-gss_localname-through-SPNEGO.patch +Patch18: Omit-KDC-indicator-check-for-S4U2Self-requests.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -629,6 +630,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri May 08 2020 Robbie Harwood - 1.18.1-4 +- Omit KDC indicator check for S4U2Self requests + * Tue Apr 28 2020 Robbie Harwood - 1.18.1-3 - Pass gss_localname() through SPNEGO From 0963a62bc3cce5c44f51352e905aecf069ecac45 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 18 May 2020 14:02:44 -0400 Subject: [PATCH 169/304] Fix typo ("in in") in the ksu man page --- Fix-typo-in-in-in-the-ksu-man-page.patch | 37 ++++++++++++++++++++++++ krb5.spec | 6 +++- 2 files changed, 42 insertions(+), 1 deletion(-) create mode 100644 Fix-typo-in-in-in-the-ksu-man-page.patch diff --git a/Fix-typo-in-in-in-the-ksu-man-page.patch b/Fix-typo-in-in-in-the-ksu-man-page.patch new file mode 100644 index 0000000..2a93038 --- /dev/null +++ b/Fix-typo-in-in-in-the-ksu-man-page.patch @@ -0,0 +1,37 @@ +From 5eed1579142640363302f27e41abb354461d3030 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 14 May 2020 15:01:18 -0400 +Subject: [PATCH] Fix typo ("in in") in the ksu man page + +(cherry picked from commit 1011841acdc1020f308ef4f569c6622f279d8c3f) +--- + doc/user/user_commands/ksu.rst | 2 +- + src/man/ksu.man | 2 +- + 2 files changed, 2 insertions(+), 2 deletions(-) + +diff --git a/doc/user/user_commands/ksu.rst b/doc/user/user_commands/ksu.rst +index 8d6c7ef79..933738229 100644 +--- a/doc/user/user_commands/ksu.rst ++++ b/doc/user/user_commands/ksu.rst +@@ -155,7 +155,7 @@ wrong password is typed in, ksu fails. + .. note:: + + During authentication, only the tickets that could be +- obtained without providing a password are cached in in the ++ obtained without providing a password are cached in the + source cache. + + +diff --git a/src/man/ksu.man b/src/man/ksu.man +index 6660e0937..9c8cf75ff 100644 +--- a/src/man/ksu.man ++++ b/src/man/ksu.man +@@ -176,7 +176,7 @@ wrong password is typed in, ksu fails. + .INDENT 0.0 + .INDENT 3.5 + During authentication, only the tickets that could be +-obtained without providing a password are cached in in the ++obtained without providing a password are cached in the + source cache. + .UNINDENT + .UNINDENT diff --git a/krb5.spec b/krb5.spec index 23dcee4..9622f8f 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 4%{?dist} +Release: 5%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -58,6 +58,7 @@ Patch15: Correctly-import-service-GSS-host-based-name.patch Patch16: Do-expiration-warnings-for-all-init_creds-APIs.patch Patch17: Pass-gss_localname-through-SPNEGO.patch Patch18: Omit-KDC-indicator-check-for-S4U2Self-requests.patch +Patch19: Fix-typo-in-in-in-the-ksu-man-page.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -630,6 +631,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon May 18 2020 Robbie Harwood - 1.18.1-5 +- Fix typo ("in in") in the ksu man page + * Fri May 08 2020 Robbie Harwood - 1.18.1-4 - Omit KDC indicator check for S4U2Self requests From d370e2a431a42b1fa46c89275def24e844697326 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 22 May 2020 13:28:09 -0400 Subject: [PATCH 170/304] Fix SPNEGO acceptor mech filtering --- Fix-SPNEGO-acceptor-mech-filtering.patch | 32 ++++++++++++++++++++++++ krb5.spec | 6 ++++- 2 files changed, 37 insertions(+), 1 deletion(-) create mode 100644 Fix-SPNEGO-acceptor-mech-filtering.patch diff --git a/Fix-SPNEGO-acceptor-mech-filtering.patch b/Fix-SPNEGO-acceptor-mech-filtering.patch new file mode 100644 index 0000000..3f07637 --- /dev/null +++ b/Fix-SPNEGO-acceptor-mech-filtering.patch @@ -0,0 +1,32 @@ +From b8a19522f0169be3b4a2f539e28c89755cd85d6f Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 21 May 2020 14:15:25 -0400 +Subject: [PATCH] Fix SPNEGO acceptor mech filtering + +Commit c2ca2f26eaf817a6a7ed42257c380437ab802bd9 (ticket 8851) +accidentally changed the SPNEGO acceptor code to filter mechanisms by +the obtainability of initiator credentials rather than acceptor +credentials, when the default acceptor credential is used. + +ticket: 8908 (new) +tags: pullup +target_version: 1.18-next + +(cherry picked from commit e25918cb9efd7361aa78d2d96cd097dd34fdf35d) +--- + src/lib/gssapi/spnego/spnego_mech.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/spnego/spnego_mech.c +index 8d36a05e8..255db6e30 100644 +--- a/src/lib/gssapi/spnego/spnego_mech.c ++++ b/src/lib/gssapi/spnego/spnego_mech.c +@@ -1379,7 +1379,7 @@ acc_ctx_new(OM_uint32 *minor_status, + goto cleanup; + } + +- ret = get_negotiable_mechs(minor_status, sc, spcred, GSS_C_INITIATE); ++ ret = get_negotiable_mechs(minor_status, sc, spcred, GSS_C_ACCEPT); + if (ret != GSS_S_COMPLETE) { + *return_token = NO_TOKEN_SEND; + goto cleanup; diff --git a/krb5.spec b/krb5.spec index 9622f8f..fe42e76 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.1 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 5%{?dist} +Release: 6%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -59,6 +59,7 @@ Patch16: Do-expiration-warnings-for-all-init_creds-APIs.patch Patch17: Pass-gss_localname-through-SPNEGO.patch Patch18: Omit-KDC-indicator-check-for-S4U2Self-requests.patch Patch19: Fix-typo-in-in-in-the-ksu-man-page.patch +Patch20: Fix-SPNEGO-acceptor-mech-filtering.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -631,6 +632,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri May 22 2020 Robbie Harwood - 1.18.1-6 +- Fix SPNEGO acceptor mech filtering + * Mon May 18 2020 Robbie Harwood - 1.18.1-5 - Fix typo ("in in") in the ksu man page From 102adf5edf477b0cd64bd208064b1c9680343750 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 22 May 2020 14:22:05 -0400 Subject: [PATCH 171/304] New upstream release (1.18.2) --- .gitignore | 2 ++ ...finalization-safety-check-to-com_err.patch | 2 +- ...tauth-modules-to-set-hw-authent-flag.patch | 2 +- ...y-import-service-GSS-host-based-name.patch | 2 +- ...ion-warnings-for-all-init_creds-APIs.patch | 2 +- ...edundant-PKINIT-responder-invocation.patch | 2 +- Fix-SPNEGO-acceptor-mech-filtering.patch | 32 ------------------- Fix-typo-in-in-in-the-ksu-man-page.patch | 4 +-- ...ndicator-check-for-S4U2Self-requests.patch | 2 +- Pass-gss_localname-through-SPNEGO.patch | 4 +-- ...ly-acquired-creds-from-client-keytab.patch | 2 +- downstream-Adjust-build-configuration.patch | 2 +- ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 2 +- downstream-Remove-3des-support.patch | 4 +-- downstream-SELinux-integration.patch | 2 +- ...ackported-version-of-OpenSSL-3-KDF-i.patch | 2 +- downstream-fix-debuginfo-with-y.tab.c.patch | 2 +- downstream-ksu-pam-integration.patch | 2 +- downstream-netlib-and-dns.patch | 2 +- krb5.spec | 8 +++-- sources | 4 +-- 21 files changed, 29 insertions(+), 57 deletions(-) delete mode 100644 Fix-SPNEGO-acceptor-mech-filtering.patch diff --git a/.gitignore b/.gitignore index 5de4b79..ecff9ea 100644 --- a/.gitignore +++ b/.gitignore @@ -185,3 +185,5 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.18.tar.gz.asc /krb5-1.18.1.tar.gz /krb5-1.18.1.tar.gz.asc +/krb5-1.18.2.tar.gz +/krb5-1.18.2.tar.gz.asc diff --git a/Add-finalization-safety-check-to-com_err.patch b/Add-finalization-safety-check-to-com_err.patch index 0dc7663..531bbf5 100644 --- a/Add-finalization-safety-check-to-com_err.patch +++ b/Add-finalization-safety-check-to-com_err.patch @@ -1,4 +1,4 @@ -From c7a37d3e87132864ebc44710baf1d50a69682b5c Mon Sep 17 00:00:00 2001 +From 9b28e9bbadb775cf790092bc0b0fe9f6c880d215 Mon Sep 17 00:00:00 2001 From: Jiri Sasek Date: Fri, 13 Mar 2020 19:02:58 +0100 Subject: [PATCH] Add finalization safety check to com_err diff --git a/Allow-certauth-modules-to-set-hw-authent-flag.patch b/Allow-certauth-modules-to-set-hw-authent-flag.patch index 6fdb430..ebadb9b 100644 --- a/Allow-certauth-modules-to-set-hw-authent-flag.patch +++ b/Allow-certauth-modules-to-set-hw-authent-flag.patch @@ -1,4 +1,4 @@ -From d23b2ed4f06fa77cd021814834dd1391ef6f452f Mon Sep 17 00:00:00 2001 +From 5413039348c612716fb5e33347814b7608778646 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 24 Feb 2020 15:58:59 -0500 Subject: [PATCH] Allow certauth modules to set hw-authent flag diff --git a/Correctly-import-service-GSS-host-based-name.patch b/Correctly-import-service-GSS-host-based-name.patch index 523ebaf..754bc89 100644 --- a/Correctly-import-service-GSS-host-based-name.patch +++ b/Correctly-import-service-GSS-host-based-name.patch @@ -1,4 +1,4 @@ -From dd4364d76925ce1fe21c2ab995554d6af3a2ea12 Mon Sep 17 00:00:00 2001 +From e8c6f76079bac021e30e89e12b547cc73f71ec36 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 30 Mar 2020 15:26:02 -0400 Subject: [PATCH] Correctly import "service@" GSS host-based name diff --git a/Do-expiration-warnings-for-all-init_creds-APIs.patch b/Do-expiration-warnings-for-all-init_creds-APIs.patch index 3dbe1f5..24062a0 100644 --- a/Do-expiration-warnings-for-all-init_creds-APIs.patch +++ b/Do-expiration-warnings-for-all-init_creds-APIs.patch @@ -1,4 +1,4 @@ -From c136cfe050d203c910624573a33247fde2889b09 Mon Sep 17 00:00:00 2001 +From 0083381a1dc008c6a1a437393045f82ec06423f8 Mon Sep 17 00:00:00 2001 From: Sumit Bose Date: Fri, 28 Feb 2020 10:11:49 +0100 Subject: [PATCH] Do expiration warnings for all init_creds APIs diff --git a/Eliminate-redundant-PKINIT-responder-invocation.patch b/Eliminate-redundant-PKINIT-responder-invocation.patch index 92bc1ab..4234ffd 100644 --- a/Eliminate-redundant-PKINIT-responder-invocation.patch +++ b/Eliminate-redundant-PKINIT-responder-invocation.patch @@ -1,4 +1,4 @@ -From 4a05805eb39ba088c07f782fb52a6538ec3f2db6 Mon Sep 17 00:00:00 2001 +From 43d09ed10d495e78c786f5468455f16a63a99532 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 23 Mar 2020 19:10:03 -0400 Subject: [PATCH] Eliminate redundant PKINIT responder invocation diff --git a/Fix-SPNEGO-acceptor-mech-filtering.patch b/Fix-SPNEGO-acceptor-mech-filtering.patch deleted file mode 100644 index 3f07637..0000000 --- a/Fix-SPNEGO-acceptor-mech-filtering.patch +++ /dev/null @@ -1,32 +0,0 @@ -From b8a19522f0169be3b4a2f539e28c89755cd85d6f Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 21 May 2020 14:15:25 -0400 -Subject: [PATCH] Fix SPNEGO acceptor mech filtering - -Commit c2ca2f26eaf817a6a7ed42257c380437ab802bd9 (ticket 8851) -accidentally changed the SPNEGO acceptor code to filter mechanisms by -the obtainability of initiator credentials rather than acceptor -credentials, when the default acceptor credential is used. - -ticket: 8908 (new) -tags: pullup -target_version: 1.18-next - -(cherry picked from commit e25918cb9efd7361aa78d2d96cd097dd34fdf35d) ---- - src/lib/gssapi/spnego/spnego_mech.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/spnego/spnego_mech.c -index 8d36a05e8..255db6e30 100644 ---- a/src/lib/gssapi/spnego/spnego_mech.c -+++ b/src/lib/gssapi/spnego/spnego_mech.c -@@ -1379,7 +1379,7 @@ acc_ctx_new(OM_uint32 *minor_status, - goto cleanup; - } - -- ret = get_negotiable_mechs(minor_status, sc, spcred, GSS_C_INITIATE); -+ ret = get_negotiable_mechs(minor_status, sc, spcred, GSS_C_ACCEPT); - if (ret != GSS_S_COMPLETE) { - *return_token = NO_TOKEN_SEND; - goto cleanup; diff --git a/Fix-typo-in-in-in-the-ksu-man-page.patch b/Fix-typo-in-in-in-the-ksu-man-page.patch index 2a93038..5196a90 100644 --- a/Fix-typo-in-in-in-the-ksu-man-page.patch +++ b/Fix-typo-in-in-in-the-ksu-man-page.patch @@ -1,4 +1,4 @@ -From 5eed1579142640363302f27e41abb354461d3030 Mon Sep 17 00:00:00 2001 +From 8de669742ae4190542741f0dc61119a6a0dad666 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 May 2020 15:01:18 -0400 Subject: [PATCH] Fix typo ("in in") in the ksu man page @@ -23,7 +23,7 @@ index 8d6c7ef79..933738229 100644 diff --git a/src/man/ksu.man b/src/man/ksu.man -index 6660e0937..9c8cf75ff 100644 +index 81e34815d..8d4c6a359 100644 --- a/src/man/ksu.man +++ b/src/man/ksu.man @@ -176,7 +176,7 @@ wrong password is typed in, ksu fails. diff --git a/Omit-KDC-indicator-check-for-S4U2Self-requests.patch b/Omit-KDC-indicator-check-for-S4U2Self-requests.patch index b1b1908..6ca7931 100644 --- a/Omit-KDC-indicator-check-for-S4U2Self-requests.patch +++ b/Omit-KDC-indicator-check-for-S4U2Self-requests.patch @@ -1,4 +1,4 @@ -From 442f1fa5b2e4034954a51048414cc0863b914379 Mon Sep 17 00:00:00 2001 +From 6d132f1019b2f1b6f54bae25ed0ea9122c87a190 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 6 May 2020 16:03:13 -0400 Subject: [PATCH] Omit KDC indicator check for S4U2Self requests diff --git a/Pass-gss_localname-through-SPNEGO.patch b/Pass-gss_localname-through-SPNEGO.patch index 37aef38..eff3733 100644 --- a/Pass-gss_localname-through-SPNEGO.patch +++ b/Pass-gss_localname-through-SPNEGO.patch @@ -1,4 +1,4 @@ -From 646212314a580a8cdffdacda9cb3c8f806471b08 Mon Sep 17 00:00:00 2001 +From dce745bbdf95ddfa733bc306c57afe5fcab74479 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 26 Apr 2020 19:55:54 -0400 Subject: [PATCH] Pass gss_localname() through SPNEGO @@ -30,7 +30,7 @@ index a93763314..066ec736f 100644 ( OM_uint32 *minor_status, diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/spnego/spnego_mech.c -index 8e0c3a348..8d36a05e8 100644 +index ec0bae6a4..594fc5894 100644 --- a/src/lib/gssapi/spnego/spnego_mech.c +++ b/src/lib/gssapi/spnego/spnego_mech.c @@ -237,7 +237,7 @@ static struct gss_config spnego_mechanism = diff --git a/Refresh-manually-acquired-creds-from-client-keytab.patch b/Refresh-manually-acquired-creds-from-client-keytab.patch index cb20c44..d67d9b4 100644 --- a/Refresh-manually-acquired-creds-from-client-keytab.patch +++ b/Refresh-manually-acquired-creds-from-client-keytab.patch @@ -1,4 +1,4 @@ -From 685aada9eae420cb5156ca7b71c2c7614c0b6e2c Mon Sep 17 00:00:00 2001 +From 13e085a996ac53484fa308f3ef7a2b66c05ccdfa Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 26 Feb 2020 18:27:17 -0500 Subject: [PATCH] Refresh manually acquired creds from client keytab diff --git a/downstream-Adjust-build-configuration.patch b/downstream-Adjust-build-configuration.patch index f15a4a2..47f6c31 100644 --- a/downstream-Adjust-build-configuration.patch +++ b/downstream-Adjust-build-configuration.patch @@ -1,4 +1,4 @@ -From 92508996ed4c69fa6f5cf855fdf10f34cfa07ec9 Mon Sep 17 00:00:00 2001 +From 30ece66508c8e10f704cd2860dfd421ebee15897 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] [downstream] Adjust build configuration diff --git a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index e6a0a64..b304c47 100644 --- a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From a721df13d09b5fdad32de15e6aa973b732727aa9 Mon Sep 17 00:00:00 2001 +From 15056939ae1e52b9c0b4e0f4ac59772b0d942647 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 diff --git a/downstream-Remove-3des-support.patch b/downstream-Remove-3des-support.patch index 01d9338..570762d 100644 --- a/downstream-Remove-3des-support.patch +++ b/downstream-Remove-3des-support.patch @@ -1,4 +1,4 @@ -From e9cd83237b54e2f6010a063f523217b0a442ecbf Mon Sep 17 00:00:00 2001 +From c920b585b8400ef44684c673c54264657195f3ce Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] [downstream] Remove 3des support @@ -365,7 +365,7 @@ index 8a4b87de1..d7f1d076b 100644 + supported_enctypes = aes256-cts:normal aes128-cts:normal aes256-sha2:normal aes128-sha2:normal } diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index e5898ea63..973976fd9 100644 +index ba0ce0b71..e3352f9cc 100644 --- a/src/kdc/kdc_util.c +++ b/src/kdc/kdc_util.c @@ -1103,8 +1103,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) diff --git a/downstream-SELinux-integration.patch b/downstream-SELinux-integration.patch index 3d3bd08..e5322af 100644 --- a/downstream-SELinux-integration.patch +++ b/downstream-SELinux-integration.patch @@ -1,4 +1,4 @@ -From 0f8851a23a7b6fa0e195e01d0475e9e55707adf2 Mon Sep 17 00:00:00 2001 +From f8c70f6190a0573e2aca0b40964cf3b1a73ca8bb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] [downstream] SELinux integration diff --git a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch index 478fd82..56565b1 100644 --- a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch +++ b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch @@ -1,4 +1,4 @@ -From 3f5875cf859271bca62f07aee6f663787972def9 Mon Sep 17 00:00:00 2001 +From 040dd62418b918adc993b9cc3e1e80fc232286c4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 15 Nov 2019 20:05:16 +0000 Subject: [PATCH] [downstream] Use backported version of OpenSSL-3 KDF diff --git a/downstream-fix-debuginfo-with-y.tab.c.patch b/downstream-fix-debuginfo-with-y.tab.c.patch index 167fcaf..33f61c5 100644 --- a/downstream-fix-debuginfo-with-y.tab.c.patch +++ b/downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,4 +1,4 @@ -From f4002f246332695d8ea12ec803139fcac18fbba2 Mon Sep 17 00:00:00 2001 +From c6e103db0eb02c31a13b8cbcbae296c473074991 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] [downstream] fix debuginfo with y.tab.c diff --git a/downstream-ksu-pam-integration.patch b/downstream-ksu-pam-integration.patch index 220363b..e81f2c1 100644 --- a/downstream-ksu-pam-integration.patch +++ b/downstream-ksu-pam-integration.patch @@ -1,4 +1,4 @@ -From a7322a84657752c886c317a6994a9fc7a4a70ca5 Mon Sep 17 00:00:00 2001 +From 9feb7298b90d3e6a34821fce7315757c0bf81c9e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] [downstream] ksu pam integration diff --git a/downstream-netlib-and-dns.patch b/downstream-netlib-and-dns.patch index d7ceab1..05bddc4 100644 --- a/downstream-netlib-and-dns.patch +++ b/downstream-netlib-and-dns.patch @@ -1,4 +1,4 @@ -From 355dd481511af4d517ee540854f95a6fb12116a9 Mon Sep 17 00:00:00 2001 +From 4254bee1b97edeb0848efce635bcf1b56306f968 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] [downstream] netlib and dns diff --git a/krb5.spec b/krb5.spec index fe42e76..eb99d26 100644 --- a/krb5.spec +++ b/krb5.spec @@ -16,9 +16,9 @@ Summary: The Kerberos network authentication system Name: krb5 -Version: 1.18.1 +Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 6%{?dist} +Release: 1%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -59,7 +59,6 @@ Patch16: Do-expiration-warnings-for-all-init_creds-APIs.patch Patch17: Pass-gss_localname-through-SPNEGO.patch Patch18: Omit-KDC-indicator-check-for-S4U2Self-requests.patch Patch19: Fix-typo-in-in-in-the-ksu-man-page.patch -Patch20: Fix-SPNEGO-acceptor-mech-filtering.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -632,6 +631,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri May 22 2020 Robbie Harwood - 1.18.2-1 +- New upstream release (1.18.2) + * Fri May 22 2020 Robbie Harwood - 1.18.1-6 - Fix SPNEGO acceptor mech filtering diff --git a/sources b/sources index a2aa017..c61d805 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.18.1.tar.gz) = c96c9ed676c8ccb9b65d17bb1d982c266228c75030a2d8fd5d7952ee8cdf362a22d202e93018d1011a5e7bd9a9fabe69aa1578d1d2e4839a78b9916d8b8019ce -SHA512 (krb5-1.18.1.tar.gz.asc) = e7db98b9f053de793763af734a7b8de81702156d12dfeb7295032c2416a43406840960fb8d16efb6cad911c1cb047da1f6fe17c88289aad28983b5d531f47908 +SHA512 (krb5-1.18.2.tar.gz) = 7cbb1b28e677fea3e0794e93951f3caaa2c49bb1175dd187951e72a466cc69d96c3b833d838000fe911c1a437d96a558e550f27c53a8b332fb9dfc7cbb7ec44c +SHA512 (krb5-1.18.2.tar.gz.asc) = 70775a06104b4d792d278da2efa92e94ddacb4ea319bfe2b253f5afcfec27f3bc5ddd12560294a265e3cf3d4fc74bcbfc3f5eeff8634d66c00d67e18dc93a74a From dec02b8411e735e47b6513a84b99f43a5ab5adc4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 May 2020 14:34:53 -0400 Subject: [PATCH 172/304] Pass channel bindings through SPNEGO --- Pass-channel-bindings-through-SPNEGO.patch | 256 +++++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 261 insertions(+), 1 deletion(-) create mode 100644 Pass-channel-bindings-through-SPNEGO.patch diff --git a/Pass-channel-bindings-through-SPNEGO.patch b/Pass-channel-bindings-through-SPNEGO.patch new file mode 100644 index 0000000..0137f0c --- /dev/null +++ b/Pass-channel-bindings-through-SPNEGO.patch @@ -0,0 +1,256 @@ +From dd82ae2d390c4de1b8a7737a918d80d6829366dd Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Tue, 28 Apr 2020 18:15:55 +0200 +Subject: [PATCH] Pass channel bindings through SPNEGO + +ticket: 8907 (new) +(cherry picked from commit d16325a24c34ec9a5f6fb4910987f162e0d4d9cd) +--- + src/lib/gssapi/spnego/gssapiP_negoex.h | 8 ++--- + src/lib/gssapi/spnego/negoex_ctx.c | 34 +++++++++++---------- + src/lib/gssapi/spnego/spnego_mech.c | 41 +++++++++++++------------- + 3 files changed, 43 insertions(+), 40 deletions(-) + +diff --git a/src/lib/gssapi/spnego/gssapiP_negoex.h b/src/lib/gssapi/spnego/gssapiP_negoex.h +index 44b08f523..489ab7c42 100644 +--- a/src/lib/gssapi/spnego/gssapiP_negoex.h ++++ b/src/lib/gssapi/spnego/gssapiP_negoex.h +@@ -201,10 +201,10 @@ negoex_restrict_auth_schemes(spnego_gss_ctx_id_t ctx, + OM_uint32 + negoex_init(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, + gss_name_t target_name, OM_uint32 req_flags, OM_uint32 time_req, +- gss_buffer_t input_token, gss_buffer_t output_token, +- OM_uint32 *time_rec); ++ gss_buffer_t input_token, gss_channel_bindings_t bindings, ++ gss_buffer_t output_token, OM_uint32 *time_rec); + + OM_uint32 + negoex_accept(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, +- gss_buffer_t input_token, gss_buffer_t output_token, +- OM_uint32 *time_rec); ++ gss_buffer_t input_token, gss_channel_bindings_t bindings, ++ gss_buffer_t output_token, OM_uint32 *time_rec); +diff --git a/src/lib/gssapi/spnego/negoex_ctx.c b/src/lib/gssapi/spnego/negoex_ctx.c +index 18d9d4147..8848ee4db 100644 +--- a/src/lib/gssapi/spnego/negoex_ctx.c ++++ b/src/lib/gssapi/spnego/negoex_ctx.c +@@ -276,7 +276,8 @@ static OM_uint32 + mech_init(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, + gss_name_t target, OM_uint32 req_flags, OM_uint32 time_req, + struct negoex_message *messages, size_t nmessages, +- gss_buffer_t output_token, OM_uint32 *time_rec) ++ gss_channel_bindings_t bindings, gss_buffer_t output_token, ++ OM_uint32 *time_rec) + { + OM_uint32 major, first_major = 0, first_minor = 0; + struct negoex_auth_mech *mech = NULL; +@@ -316,10 +317,9 @@ mech_init(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, + mech = K5_TAILQ_FIRST(&ctx->negoex_mechs); + + major = gss_init_sec_context(minor, cred, &mech->mech_context, target, +- mech->oid, req_flags, time_req, +- GSS_C_NO_CHANNEL_BINDINGS, input_token, +- &ctx->actual_mech, output_token, +- &ctx->ctx_flags, time_rec); ++ mech->oid, req_flags, time_req, bindings, ++ input_token, &ctx->actual_mech, ++ output_token, &ctx->ctx_flags, time_rec); + + if (major == GSS_S_COMPLETE) + mech->complete = 1; +@@ -351,7 +351,8 @@ mech_init(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, + static OM_uint32 + mech_accept(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, + gss_cred_id_t cred, struct negoex_message *messages, +- size_t nmessages, gss_buffer_t output_token, OM_uint32 *time_rec) ++ size_t nmessages, gss_channel_bindings_t bindings, ++ gss_buffer_t output_token, OM_uint32 *time_rec) + { + OM_uint32 major, tmpmin; + struct negoex_auth_mech *mech; +@@ -395,10 +396,10 @@ mech_accept(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, + gss_release_cred(&tmpmin, &ctx->deleg_cred); + + major = gss_accept_sec_context(minor, &mech->mech_context, cred, +- &msg->token, GSS_C_NO_CHANNEL_BINDINGS, +- &ctx->internal_name, &ctx->actual_mech, +- output_token, &ctx->ctx_flags, +- time_rec, &ctx->deleg_cred); ++ &msg->token, bindings, &ctx->internal_name, ++ &ctx->actual_mech, output_token, ++ &ctx->ctx_flags, time_rec, ++ &ctx->deleg_cred); + + if (major == GSS_S_COMPLETE) + mech->complete = 1; +@@ -609,8 +610,8 @@ make_output_token(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, + OM_uint32 + negoex_init(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, + gss_name_t target_name, OM_uint32 req_flags, OM_uint32 time_req, +- gss_buffer_t input_token, gss_buffer_t output_token, +- OM_uint32 *time_rec) ++ gss_buffer_t input_token, gss_channel_bindings_t bindings, ++ gss_buffer_t output_token, OM_uint32 *time_rec) + { + OM_uint32 major, tmpmin; + gss_buffer_desc mech_output_token = GSS_C_EMPTY_BUFFER; +@@ -663,7 +664,8 @@ negoex_init(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, + /* Process the input token and/or produce an output token. This may prune + * the mech list, but on success there will be at least one mech entry. */ + major = mech_init(minor, ctx, cred, target_name, req_flags, time_req, +- messages, nmessages, &mech_output_token, time_rec); ++ messages, nmessages, bindings, &mech_output_token, ++ time_rec); + if (major != GSS_S_COMPLETE) + goto cleanup; + assert(!K5_TAILQ_EMPTY(&ctx->negoex_mechs)); +@@ -701,8 +703,8 @@ cleanup: + + OM_uint32 + negoex_accept(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, +- gss_buffer_t input_token, gss_buffer_t output_token, +- OM_uint32 *time_rec) ++ gss_buffer_t input_token, gss_channel_bindings_t bindings, ++ gss_buffer_t output_token, OM_uint32 *time_rec) + { + OM_uint32 major, tmpmin; + gss_buffer_desc mech_output_token = GSS_C_EMPTY_BUFFER; +@@ -754,7 +756,7 @@ negoex_accept(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, + * prune the list to a single mech. Continue on error if an output token + * is generated, so that we send the token to the initiator. + */ +- major = mech_accept(minor, ctx, cred, messages, nmessages, ++ major = mech_accept(minor, ctx, cred, messages, nmessages, bindings, + &mech_output_token, time_rec); + if (major != GSS_S_COMPLETE && mech_output_token.length == 0) + goto cleanup; +diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/spnego/spnego_mech.c +index 594fc5894..4cf011143 100644 +--- a/src/lib/gssapi/spnego/spnego_mech.c ++++ b/src/lib/gssapi/spnego/spnego_mech.c +@@ -130,6 +130,7 @@ init_ctx_reselect(OM_uint32 *, spnego_gss_ctx_id_t, OM_uint32, + static OM_uint32 + init_ctx_call_init(OM_uint32 *, spnego_gss_ctx_id_t, spnego_gss_cred_id_t, + OM_uint32, gss_name_t, OM_uint32, OM_uint32, gss_buffer_t, ++ gss_channel_bindings_t, + gss_buffer_t, OM_uint32 *, send_token_flag *); + + static OM_uint32 +@@ -144,8 +145,8 @@ acc_ctx_vfy_oid(OM_uint32 *, spnego_gss_ctx_id_t, gss_OID, + OM_uint32 *, send_token_flag *); + static OM_uint32 + acc_ctx_call_acc(OM_uint32 *, spnego_gss_ctx_id_t, spnego_gss_cred_id_t, +- gss_buffer_t, gss_buffer_t, OM_uint32 *, OM_uint32 *, +- send_token_flag *); ++ gss_buffer_t, gss_channel_bindings_t, gss_buffer_t, ++ OM_uint32 *, OM_uint32 *, send_token_flag *); + + static gss_OID + negotiate_mech(spnego_gss_ctx_id_t, gss_OID_set, OM_uint32 *); +@@ -905,6 +906,7 @@ init_ctx_call_init(OM_uint32 *minor_status, + OM_uint32 req_flags, + OM_uint32 time_req, + gss_buffer_t mechtok_in, ++ gss_channel_bindings_t bindings, + gss_buffer_t mechtok_out, + OM_uint32 *time_rec, + send_token_flag *send_token) +@@ -921,15 +923,14 @@ init_ctx_call_init(OM_uint32 *minor_status, + if (gss_oid_equal(sc->internal_mech, &negoex_mech)) { + ret = negoex_init(minor_status, sc, mcred, target_name, + mech_req_flags, time_req, mechtok_in, +- mechtok_out, time_rec); ++ bindings, mechtok_out, time_rec); + } else { + ret = gss_init_sec_context(minor_status, mcred, + &sc->ctx_handle, target_name, + sc->internal_mech, mech_req_flags, +- time_req, GSS_C_NO_CHANNEL_BINDINGS, +- mechtok_in, &sc->actual_mech, +- mechtok_out, &sc->ctx_flags, +- time_rec); ++ time_req, bindings, mechtok_in, ++ &sc->actual_mech, mechtok_out, ++ &sc->ctx_flags, time_rec); + } + + /* Bail out if the acceptor gave us an error token but the mech didn't +@@ -981,8 +982,8 @@ init_ctx_call_init(OM_uint32 *minor_status, + gss_delete_sec_context(&tmpmin, &sc->ctx_handle, GSS_C_NO_BUFFER); + tmpret = init_ctx_call_init(&tmpmin, sc, spcred, acc_negState, + target_name, req_flags, time_req, +- mechtok_in, mechtok_out, time_rec, +- send_token); ++ mechtok_in, bindings, mechtok_out, ++ time_rec, send_token); + if (HARD_ERROR(tmpret)) + goto fail; + *minor_status = tmpmin; +@@ -1004,7 +1005,7 @@ spnego_gss_init_sec_context( + gss_OID mech_type, + OM_uint32 req_flags, + OM_uint32 time_req, +- gss_channel_bindings_t input_chan_bindings, ++ gss_channel_bindings_t bindings, + gss_buffer_t input_token, + gss_OID *actual_mech, + gss_buffer_t output_token, +@@ -1084,8 +1085,8 @@ spnego_gss_init_sec_context( + if (!spnego_ctx->mech_complete) { + ret = init_ctx_call_init(minor_status, spnego_ctx, spcred, + acc_negState, target_name, req_flags, +- time_req, mechtok_in, &mechtok_out, +- time_rec, &send_token); ++ time_req, mechtok_in, bindings, ++ &mechtok_out, time_rec, &send_token); + if (ret != GSS_S_COMPLETE) + goto cleanup; + +@@ -1542,8 +1543,9 @@ cleanup: + static OM_uint32 + acc_ctx_call_acc(OM_uint32 *minor_status, spnego_gss_ctx_id_t sc, + spnego_gss_cred_id_t spcred, gss_buffer_t mechtok_in, +- gss_buffer_t mechtok_out, OM_uint32 *time_rec, +- OM_uint32 *negState, send_token_flag *tokflag) ++ gss_channel_bindings_t bindings, gss_buffer_t mechtok_out, ++ OM_uint32 *time_rec, OM_uint32 *negState, ++ send_token_flag *tokflag) + { + OM_uint32 ret, tmpmin; + gss_OID_desc mechoid; +@@ -1568,13 +1570,12 @@ acc_ctx_call_acc(OM_uint32 *minor_status, spnego_gss_ctx_id_t sc, + mcred = (spcred == NULL) ? GSS_C_NO_CREDENTIAL : spcred->mcred; + if (negoex) { + ret = negoex_accept(minor_status, sc, mcred, mechtok_in, +- mechtok_out, time_rec); ++ bindings, mechtok_out, time_rec); + } else { + (void) gss_release_name(&tmpmin, &sc->internal_name); + (void) gss_release_cred(&tmpmin, &sc->deleg_cred); + ret = gss_accept_sec_context(minor_status, &sc->ctx_handle, +- mcred, mechtok_in, +- GSS_C_NO_CHANNEL_BINDINGS, ++ mcred, mechtok_in, bindings, + &sc->internal_name, + &sc->actual_mech, mechtok_out, + &sc->ctx_flags, time_rec, +@@ -1620,7 +1621,7 @@ spnego_gss_accept_sec_context( + gss_ctx_id_t *context_handle, + gss_cred_id_t verifier_cred_handle, + gss_buffer_t input_token, +- gss_channel_bindings_t input_chan_bindings, ++ gss_channel_bindings_t bindings, + gss_name_t *src_name, + gss_OID *mech_type, + gss_buffer_t output_token, +@@ -1734,8 +1735,8 @@ spnego_gss_accept_sec_context( + */ + if (negState != REQUEST_MIC && mechtok_in != GSS_C_NO_BUFFER) { + ret = acc_ctx_call_acc(minor_status, sc, spcred, mechtok_in, +- &mechtok_out, time_rec, &negState, +- &return_token); ++ bindings, &mechtok_out, time_rec, ++ &negState, &return_token); + } + + /* Step 3: process or generate the MIC, if the negotiated mech is diff --git a/krb5.spec b/krb5.spec index eb99d26..4aef2f9 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1%{?dist} +Release: 2%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -59,6 +59,7 @@ Patch16: Do-expiration-warnings-for-all-init_creds-APIs.patch Patch17: Pass-gss_localname-through-SPNEGO.patch Patch18: Omit-KDC-indicator-check-for-S4U2Self-requests.patch Patch19: Fix-typo-in-in-in-the-ksu-man-page.patch +Patch20: Pass-channel-bindings-through-SPNEGO.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -631,6 +632,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue May 26 2020 Robbie Harwood - 1.18.2-2 +- Pass channel bindings through SPNEGO + * Fri May 22 2020 Robbie Harwood - 1.18.2-1 - New upstream release (1.18.2) From 331a9df349e7de9845311387da39592b952aa5e1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 May 2020 21:47:51 +0000 Subject: [PATCH 173/304] dns_canonicalize_hostname = fallback --- krb5.conf | 1 + krb5.spec | 5 ++++- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/krb5.conf b/krb5.conf index c45f388..4f0d898 100644 --- a/krb5.conf +++ b/krb5.conf @@ -15,6 +15,7 @@ includedir /etc/krb5.conf.d/ rdns = false pkinit_anchors = FILE:/etc/pki/tls/certs/ca-bundle.crt spake_preauth_groups = edwards25519 + dns_canonicalize_hostname = fallback # default_realm = EXAMPLE.COM [realms] diff --git a/krb5.spec b/krb5.spec index 4aef2f9..ccd17ed 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 2%{?dist} +Release: 3%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -632,6 +632,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue May 26 2020 Robbie Harwood - 1.18.2-3 +- dns_canonicalize_hostname = fallback + * Tue May 26 2020 Robbie Harwood - 1.18.2-2 - Pass channel bindings through SPNEGO From 883355750aaa600491502d2d3659303ed7cbb3ac Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Sat, 30 May 2020 12:01:58 -0400 Subject: [PATCH 174/304] Default dns_canonicalize_hostname to "fallback" --- ...ns_canonicalize_hostname-to-fallback.patch | 371 ++++++++++++ Remove-resolver-test-utility.patch | 547 ++++++++++++++++++ krb5.spec | 7 +- 3 files changed, 924 insertions(+), 1 deletion(-) create mode 100644 Default-dns_canonicalize_hostname-to-fallback.patch create mode 100644 Remove-resolver-test-utility.patch diff --git a/Default-dns_canonicalize_hostname-to-fallback.patch b/Default-dns_canonicalize_hostname-to-fallback.patch new file mode 100644 index 0000000..2e34e13 --- /dev/null +++ b/Default-dns_canonicalize_hostname-to-fallback.patch @@ -0,0 +1,371 @@ +From 1e72ba5c1b74d5b78f84c5884d06e979830aeb53 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 27 May 2020 18:48:35 -0400 +Subject: [PATCH] Default dns_canonicalize_hostname to "fallback" + +This change should mitigate some of the pain caused by the rdns=true +default (generally associated with unwanted PTR records that cannot +easily be changed), with a minimum of fallout. + +Update the documentation and tests accordingly. In test environments, +disable qualify_shortname and use the uncanonicalized system hostname +(lowercased) to match the initial sn2princ result. + +ticket: 8911 (new) +--- + doc/admin/appl_servers.rst | 14 +++--- + doc/admin/conf_files/krb5_conf.rst | 9 ++-- + doc/admin/princ_dns.rst | 44 +++++++++++-------- + src/kadmin/testing/proto/krb5.conf.proto | 8 ++-- + src/kadmin/testing/scripts/env-setup.shin | 4 +- + src/kadmin/testing/scripts/init_db | 3 +- + src/kadmin/testing/scripts/start_servers | 3 +- + .../testing/scripts/start_servers_local | 2 +- + .../kadm5/unit-test/api.current/init-v2.exp | 6 +-- + src/lib/krb5/krb/init_ctx.c | 2 +- + src/tests/dejagnu/config/default.exp | 5 +-- + src/tests/t_sn2princ.py | 5 ++- + src/util/k5test.py | 25 +++-------- + 13 files changed, 58 insertions(+), 72 deletions(-) + +diff --git a/doc/admin/appl_servers.rst b/doc/admin/appl_servers.rst +index 5232db9af..afdf30297 100644 +--- a/doc/admin/appl_servers.rst ++++ b/doc/admin/appl_servers.rst +@@ -115,14 +115,12 @@ Getting DNS information correct + ------------------------------- + + Several aspects of Kerberos rely on name service. When a hostname is +-used to name a service, the Kerberos library canonicalizes the +-hostname using forward and reverse name resolution. (The reverse name +-resolution step can be turned off using the **rdns** variable in +-:ref:`libdefaults`.) The result of this canonicalization must match +-the principal entry in the host's keytab, or authentication will fail. +- +-Each host's canonical name must be the fully-qualified host name +-(including the domain), and each host's IP address must ++used to name a service, clients may canonicalize the hostname using ++forward and possibly reverse name resolution. The result of this ++canonicalization must match the principal entry in the host's keytab, ++or authentication will fail. To work with all client canonicalization ++configurations, each host's canonical name must be the fully-qualified ++host name (including the domain), and each host's IP address must + reverse-resolve to the canonical name. + + Configuration of hostnames varies by operating system. On the +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index 1d2aa7f68..a7e7a29d1 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -188,11 +188,10 @@ The libdefaults section may contain any of the following relations: + hostnames for use in service principal names. Setting this flag + to false can improve security by reducing reliance on DNS, but + means that short hostnames will not be canonicalized to +- fully-qualified hostnames. The default value is true. +- +- If this option is set to ``fallback`` (new in release 1.18), DNS +- canonicalization will only be performed the server hostname is not +- found with the original name when requesting credentials. ++ fully-qualified hostnames. If this option is set to ``fallback`` (new ++ in release 1.18), DNS canonicalization will only be performed the ++ server hostname is not found with the original name when ++ requesting credentials. The default value is ``fallback``. + + **dns_lookup_kdc** + Indicate whether DNS SRV records should be used to locate the KDCs +diff --git a/doc/admin/princ_dns.rst b/doc/admin/princ_dns.rst +index e1d823f27..32a269afc 100644 +--- a/doc/admin/princ_dns.rst ++++ b/doc/admin/princ_dns.rst +@@ -31,27 +31,35 @@ based on rotating ``CNAME`` records in DNS. + Service principal canonicalization + ---------------------------------- + +-MIT Kerberos clients currently always do forward resolution (looking +-up the IPv4 and possibly IPv6 addresses using ``getaddrinfo()``) of +-the hostname part of a host-based service principal to canonicalize +-the hostname. They obtain the "canonical" name of the host when doing +-so. By default, MIT Kerberos clients will also then do reverse DNS +-resolution (looking up the hostname associated with the IPv4 or IPv6 +-address using ``getnameinfo()``) of the hostname. Using the +-:ref:`krb5.conf(5)` setting:: ++In the MIT krb5 client library, canonicalization of host-based service ++principals is controlled by the **dns_canonicalize_hostname**, ++**rnds**, and **qualify_shortname** variables in :ref:`libdefaults`. + +- [libdefaults] +- rdns = false ++If **dns_canonicalize_hostname** is set to ``true`` (the default value ++before release 1.19), the client performs forward resolution by ++looking up the IPv4 and/or IPv6 addresses of the hostname using ++``getaddrinfo()``. This process will typically add a domain suffix to ++the hostname if needed, and follow CNAME records in the DNS. If ++**rdns** is also set to ``true`` (the default), the client will then ++perform a reverse lookup of the first returned Internet address using ++``getnameinfo()``, finding the name associated with the PTR record. + +-will disable reverse DNS lookup on clients. The default setting is +-"true". ++If **dns_canonicalize_hostname** is set to ``false``, the hostname is ++not canonicalized using DNS. If the hostname has only one component ++(i.e. it contains no "." characters), the host's primary DNS search ++domain will be appended, if there is one. The **qualify_shortname** ++variable can be used to override or disable this suffix. ++ ++If **dns_canonicalize_hostname** is set to ``fallback`` (the default ++value in release 1.19 and later), the hostname is initially treated ++according to the rules for ``dns_canonicalize_hostname=false``. If a ++ticket request fails because the service principal is unknown, it the ++hostname will be canonicalized according to the rules for ++``dns_canonicalize_hostname=true`` and the request will be retried. ++ ++In all cases, the hostname is converted to lowercase, and any trailing ++dot is removed. + +-Operating system bugs may prevent a setting of ``rdns = false`` from +-disabling reverse DNS lookup. Some versions of GNU libc have a bug in +-``getaddrinfo()`` that cause them to look up ``PTR`` records even when +-not required. MIT Kerberos releases krb5-1.10.2 and newer have a +-workaround for this problem, as does the krb5-1.9.x series as of +-release krb5-1.9.4. + + + Reverse DNS mismatches +diff --git a/src/kadmin/testing/proto/krb5.conf.proto b/src/kadmin/testing/proto/krb5.conf.proto +index e710852d4..c0af716a5 100644 +--- a/src/kadmin/testing/proto/krb5.conf.proto ++++ b/src/kadmin/testing/proto/krb5.conf.proto +@@ -2,19 +2,19 @@ + default_realm = __REALM__ + default_keytab_name = FILE:__K5ROOT__/keytab + dns_fallback = no ++ qualify_shortname = "" + plugin_base_dir = __PLUGIN_DIR__ + allow_weak_crypto = true + + [realms] + __REALM__ = { +- kdc = __KDCHOST__:1750 +- admin_server = __KDCHOST__:1751 ++ kdc = __HOSTNAME__:1750 ++ admin_server = __HOSTNAME__:1751 + database_module = foobar_db2_module_blah + } + + [domain_realm] +- __LOCALHOST__ = __REALM__ +- __KDCHOST__ = __REALM__ ++ __HOSTNAME__ = __REALM__ + + [logging] + admin_server = FILE:__K5ROOT__/syslog +diff --git a/src/kadmin/testing/scripts/env-setup.shin b/src/kadmin/testing/scripts/env-setup.shin +index 969c5340c..88f8ad1aa 100755 +--- a/src/kadmin/testing/scripts/env-setup.shin ++++ b/src/kadmin/testing/scripts/env-setup.shin +@@ -71,8 +71,8 @@ BSDDB_DUMP=$TESTDIR/util/bsddb_dump; export BSDDB_DUMP + CLNTTCL=$TESTDIR/util/kadm5_clnt_tcl; export CLNTTCL + SRVTCL=$TESTDIR/util/kadm5_srv_tcl; export SRVTCL + +-QUALNAME=`$BUILDTOP/tests/resolve/resolve -q | tr '[A-Z]' '[a-z]'` +-export QUALNAME ++HOSTNAME=`hostname | tr '[A-Z]' '[a-z]'` ++export HOSTNAME + + KRB5_CONFIG=$K5ROOT/krb5.conf; export KRB5_CONFIG + KRB5_KDC_PROFILE=$K5ROOT/kdc.conf; export KRB5_KDC_PROFILE +diff --git a/src/kadmin/testing/scripts/init_db b/src/kadmin/testing/scripts/init_db +index e65826c96..216f62793 100755 +--- a/src/kadmin/testing/scripts/init_db ++++ b/src/kadmin/testing/scripts/init_db +@@ -79,8 +79,7 @@ fi + # done + + sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ +- -e "s/__KDCHOST__/$QUALNAME/g" \ +- -e "s/__LOCALHOST__/$QUALNAME/g" \ ++ -e "s/__HOSTNAME__/$HOSTNAME/g" \ + -e "s#__MODDIR__#$MODDIR#g" \ + < $STESTDIR/proto/krb5.conf.proto > $K5ROOT/krb5.conf + sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ +diff --git a/src/kadmin/testing/scripts/start_servers b/src/kadmin/testing/scripts/start_servers +index f23df0682..05519e4ee 100755 +--- a/src/kadmin/testing/scripts/start_servers ++++ b/src/kadmin/testing/scripts/start_servers +@@ -36,8 +36,7 @@ if [ $local = 0 ]; then + + # Fix up the local krb5.conf to point to the remote + sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ +- -e "s/__KDCHOST__/$hostname/g" \ +- -e "s/__LOCALHOST__/$QUALNAME/g" \ ++ -e "s/__HOSTNAME__/$HOSTNAME/g" \ + -e "s#__MODDIR__#$TOP/../plugins/kdb#g"\ + -e "s#__PLUGIN_DIR__#$TOP/../plugins#g"\ + < $STESTDIR/proto/krb5.conf.proto > $K5ROOT/krb5.conf +diff --git a/src/kadmin/testing/scripts/start_servers_local b/src/kadmin/testing/scripts/start_servers_local +index 998ef9164..858e88031 100755 +--- a/src/kadmin/testing/scripts/start_servers_local ++++ b/src/kadmin/testing/scripts/start_servers_local +@@ -79,7 +79,7 @@ cat - > /tmp/start_servers_local$$ <<\EOF + if { [catch { + source $env(STOP)/testing/tcl/util.t + set r $env(REALM) +- set q $env(QUALNAME) ++ set q $env(HOSTNAME) + puts stdout [kadm5_init $env(SRVTCL) mrroot null \ + [config_params {KADM5_CONFIG_REALM} $r] \ + $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 server_handle] +diff --git a/src/lib/kadm5/unit-test/api.current/init-v2.exp b/src/lib/kadm5/unit-test/api.current/init-v2.exp +index 7a353d4e9..47764c212 100644 +--- a/src/lib/kadm5/unit-test/api.current/init-v2.exp ++++ b/src/lib/kadm5/unit-test/api.current/init-v2.exp +@@ -3,18 +3,14 @@ load_lib lib.t + api_exit + api_start + +-if ![info exists RESOLVE] { +- set RESOLVE [findfile $objdir/../../../tests/resolve/resolve] +-} + proc get_hostname { } { +- global RESOLVE + global hostname + + if {[info exists hostname]} { + return 1 + } + +- catch "exec $RESOLVE -q >myname" exec_output ++ catch "exec hostname >myname" exec_output + if ![string match "" $exec_output] { + send_log "$exec_output\n" + verbose $exec_output +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index 9a4741fa6..0b8ae6714 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -237,7 +237,7 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + ctx->enforce_ok_as_delegate = tmp; + + retval = get_tristate(ctx, KRB5_CONF_DNS_CANONICALIZE_HOSTNAME, "fallback", +- CANONHOST_FALLBACK, 1, &tmp); ++ CANONHOST_FALLBACK, CANONHOST_FALLBACK, &tmp); + if (retval) + goto cleanup; + ctx->dns_canonicalize_hostname = tmp; +diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp +index 4d8c917cd..1e7777f1e 100644 +--- a/src/tests/dejagnu/config/default.exp ++++ b/src/tests/dejagnu/config/default.exp +@@ -268,7 +268,6 @@ foreach i { + {KTUTIL $objdir/../../kadmin/ktutil/ktutil} + {KLIST $objdir/../../clients/klist/klist} + {KDESTROY $objdir/../../clients/kdestroy/kdestroy} +- {RESOLVE $objdir/../resolve/resolve} + {T_INETD $objdir/t_inetd} + {KPROPLOG $objdir/../../kprop/kproplog} + {KPASSWD $objdir/../../clients/kpasswd/kpasswd} +@@ -462,7 +461,6 @@ proc setup_runtime_env { } { + # 0 on failure. + + proc get_hostname { } { +- global RESOLVE + global hostname + global tmppwd + +@@ -472,7 +470,7 @@ proc get_hostname { } { + + envstack_push + setup_runtime_env +- catch "exec $RESOLVE -q >$tmppwd/hostname" exec_output ++ catch "exec hostname >$tmppwd/hostname" exec_output + envstack_pop + if ![string match "" $exec_output] { + verbose -log $exec_output +@@ -710,6 +708,7 @@ proc setup_krb5_conf { {type client} } { + puts $conffile "\[libdefaults\]" + puts $conffile " default_realm = $REALMNAME" + puts $conffile " dns_lookup_kdc = false" ++ puts $conffile " qualify_shortname = \"\"" + if [info exists allow_weak_crypto($type)] { + puts $conffile " allow_weak_crypto = $allow_weak_crypto($type)" + } else { +diff --git a/src/tests/t_sn2princ.py b/src/tests/t_sn2princ.py +index 26dcb91c2..f3e187286 100755 +--- a/src/tests/t_sn2princ.py ++++ b/src/tests/t_sn2princ.py +@@ -2,7 +2,8 @@ from k5test import * + + offline = (len(args) > 0 and args[0] != "no") + +-conf = {'domain_realm': {'kerberos.org': 'R1', ++conf = {'libdefaults': {'dns_canonicalize_hostname': 'true'}, ++ 'domain_realm': {'kerberos.org': 'R1', + 'example.com': 'R2', + 'mit.edu': 'R3'}} + no_rdns_conf = {'libdefaults': {'rdns': 'false'}} +@@ -28,7 +29,7 @@ def testbase(host, nametype, princhost, princrealm, env=None): + fail('Expected %s, got %s' % (expected, out)) + + def test(host, princhost, princrealm): +- # Test with the host-based name type in the default environment. ++ # Test with the host-based name type with canonicalization enabled. + testbase(host, 'srv-hst', princhost, princrealm) + + def testnc(host, princhost, princrealm): +diff --git a/src/util/k5test.py b/src/util/k5test.py +index eea92275d..5196cfa43 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -193,7 +193,10 @@ Scripts may use the following functions and variables: + + * plugins: The plugin directory in the build tree (absolute path). + +-* hostname: This machine's fully-qualified domain name. ++* hostname: The local hostname as it will initially appear in ++ krb5_sname_to_principal() results. (Shortname qualification is ++ turned off in the test environment to make this value easy to ++ discover from Python.) + + * null_input: A file opened to read /dev/null. + +@@ -525,23 +528,6 @@ def _find_srctop(): + return os.path.abspath(root) + + +-# Return the local hostname as it will be canonicalized by +-# krb5_sname_to_principal. We can't simply use socket.getfqdn() +-# because it explicitly prefers results containing periods and +-# krb5_sname_to_principal doesn't care. +-def _get_hostname(): +- hostname = socket.gethostname() +- try: +- ai = socket.getaddrinfo(hostname, None, 0, 0, 0, socket.AI_CANONNAME) +- except socket.gaierror as e: +- fail('Local hostname "%s" does not resolve: %s.' % (hostname, e[1])) +- (family, socktype, proto, canonname, sockaddr) = ai[0] +- try: +- name = socket.getnameinfo(sockaddr, socket.NI_NAMEREQD) +- except socket.gaierror: +- return canonname.lower() +- return name[0].lower() +- + # Parse command line arguments, setting global option variables. Also + # sets the global variable args to the positional arguments, which may + # be used by the test script. +@@ -1263,6 +1249,7 @@ _default_krb5_conf = { + 'libdefaults': { + 'default_realm': '$realm', + 'dns_lookup_kdc': 'false', ++ 'qualify_shortname': '', + 'plugin_base_dir': '$plugins'}, + 'realms': {'$realm': { + 'kdc': '$hostname:$port0', +@@ -1356,7 +1343,7 @@ buildtop = _find_buildtop() + srctop = _find_srctop() + plugins = os.path.join(buildtop, 'plugins') + runenv = _import_runenv() +-hostname = _get_hostname() ++hostname = socket.gethostname().lower() + null_input = open(os.devnull, 'r') + + # A DB pass is a tuple of: name, kdc_conf. diff --git a/Remove-resolver-test-utility.patch b/Remove-resolver-test-utility.patch new file mode 100644 index 0000000..444f99a --- /dev/null +++ b/Remove-resolver-test-utility.patch @@ -0,0 +1,547 @@ +From 621cf6c98d74b025a0ca190cd279756596709ef9 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 28 May 2020 18:41:02 -0400 +Subject: [PATCH] Remove resolver test utility + +tests/resolve is no longer used after the previous commit. + +[rharwood@redhat.com: .gitignore] +--- + src/configure.ac | 5 +- + src/tests/Makefile.in | 4 +- + src/tests/resolve/Makefile.in | 28 --- + src/tests/resolve/addrinfo-test.c | 306 ------------------------- + src/tests/resolve/deps | 14 -- + src/tests/resolve/fake-addrinfo-test.c | 3 - + src/tests/resolve/resolve.c | 115 ---------- + 7 files changed, 4 insertions(+), 471 deletions(-) + delete mode 100644 src/tests/resolve/Makefile.in + delete mode 100644 src/tests/resolve/addrinfo-test.c + delete mode 100644 src/tests/resolve/deps + delete mode 100644 src/tests/resolve/fake-addrinfo-test.c + delete mode 100644 src/tests/resolve/resolve.c + +diff --git a/src/configure.ac b/src/configure.ac +index 29be532cb..2a756d6b5 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -1542,7 +1542,6 @@ V5_AC_OUTPUT_MAKEFILE(. + appl/simple appl/simple/client appl/simple/server + appl/gss-sample appl/user_user + +- tests tests/resolve tests/asn.1 tests/create tests/hammer +- tests/verify tests/gssapi tests/dejagnu tests/threads tests/shlib +- tests/gss-threads tests/misc ++ tests tests/asn.1 tests/create tests/hammer tests/verify tests/gssapi ++ tests/dejagnu tests/threads tests/shlib tests/gss-threads tests/misc + ) +diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in +index 3f88f1713..6b7749129 100644 +--- a/src/tests/Makefile.in ++++ b/src/tests/Makefile.in +@@ -1,7 +1,7 @@ + mydir=tests + BUILDTOP=$(REL).. +-SUBDIRS = resolve asn.1 create hammer verify gssapi dejagnu shlib \ +- gss-threads misc threads softpkcs11 ++SUBDIRS = asn.1 create hammer verify gssapi dejagnu shlib gss-threads misc \ ++ threads softpkcs11 + + RUN_DB_TEST = $(RUN_SETUP) KRB5_KDC_PROFILE=kdc.conf KRB5_CONFIG=krb5.conf \ + GSS_MECH_CONFIG=mech.conf LC_ALL=C $(VALGRIND) +diff --git a/src/tests/resolve/Makefile.in b/src/tests/resolve/Makefile.in +deleted file mode 100644 +index 1f5954089..000000000 +--- a/src/tests/resolve/Makefile.in ++++ /dev/null +@@ -1,28 +0,0 @@ +-mydir=tests$(S)resolve +-BUILDTOP=$(REL)..$(S).. +- +-OBJS=resolve.o addrinfo-test.o fake-addrinfo-test.o +-SRCS=$(srcdir)/resolve.c $(srcdir)/addrinfo-test.c \ +- $(srcdir)/fake-addrinfo-test.c +- +-all: resolve addrinfo-test fake-addrinfo-test +- +-resolve: resolve.o +- $(CC_LINK) -o $@ resolve.o $(SUPPORT_LIB) $(LIBS) +- +-addrinfo-test: addrinfo-test.o +- $(CC_LINK) -o $@ addrinfo-test.o $(SUPPORT_LIB) $(LIBS) +- +-fake-addrinfo-test: fake-addrinfo-test.o +- $(CC_LINK) -o $@ fake-addrinfo-test.o $(SUPPORT_LIB) $(LIBS) +- +-check: resolve addrinfo-test fake-addrinfo-test +- $(RUN_TEST) ./resolve +- $(RUN_TEST) ./addrinfo-test -p telnet +- $(RUN_TEST) ./fake-addrinfo-test -p telnet +- +-install: +- +-clean: +- $(RM) resolve addrinfo-test fake-addrinfo-test +- +diff --git a/src/tests/resolve/addrinfo-test.c b/src/tests/resolve/addrinfo-test.c +deleted file mode 100644 +index e77640b62..000000000 +--- a/src/tests/resolve/addrinfo-test.c ++++ /dev/null +@@ -1,306 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* tests/resolve/addrinfo-test.c */ +-/* +- * Copyright 2004 by the Massachusetts Institute of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* +- * A simple program to test the functionality of the getaddrinfo function. +- * +- * Usage: +- * addrinfo-test [-t|-u|-R|-I] [-d|-s|-r] [-p port] [-P] [hostname] +- * +- * When invoked with no arguments, NULL is used for the node name, +- * which (at least with a non-null "port") means a socket address +- * is desired that can be used with connect() or bind() (depending +- * on whether "-P" is given). +- */ +- +-#include +-#include +-#include +-#include +-#include /* needed for IPPROTO_* on NetBSD */ +-#ifdef USE_FAKE_ADDRINFO +-#include "fake-addrinfo.h" +-#endif +- +-static const char *protoname (int p) { +- static char buf[30]; +- +-#define X(N) if (p == IPPROTO_ ## N) return #N +- +- X(TCP); +- X(UDP); +- X(ICMP); +-#ifdef IPPROTO_IPV6 +- X(IPV6); +-#endif +-#ifdef IPPROTO_GRE +- X(GRE); +-#endif +-#ifdef IPPROTO_NONE +- X(NONE); +-#endif +- X(RAW); +-#ifdef IPPROTO_COMP +- X(COMP); +-#endif +- +- snprintf(buf, sizeof(buf), " %-2d", p); +- return buf; +-} +- +-static const char *socktypename (int t) { +- static char buf[30]; +- switch (t) { +- case SOCK_DGRAM: return "DGRAM"; +- case SOCK_STREAM: return "STREAM"; +- case SOCK_RAW: return "RAW"; +- case SOCK_RDM: return "RDM"; +- case SOCK_SEQPACKET: return "SEQPACKET"; +- } +- snprintf(buf, sizeof(buf), " %-2d", t); +- return buf; +-} +- +-static char *whoami; +- +-static void usage () { +- fprintf(stderr, +- "usage:\n" +- "\t%s [ options ] [host]\n" +- "options:\n" +- "\t-t\tspecify protocol IPPROTO_TCP\n" +- "\t-u\tspecify protocol IPPROTO_UDP\n" +- "\t-R\tspecify protocol IPPROTO_RAW\n" +- "\t-I\tspecify protocol IPPROTO_ICMP\n" +- "\n" +- "\t-d\tspecify socket type SOCK_DGRAM\n" +- "\t-s\tspecify socket type SOCK_STREAM\n" +- "\t-r\tspecify socket type SOCK_RAW\n" +- "\n" +- "\t-4\tspecify address family AF_INET\n" +-#ifdef AF_INET6 +- "\t-6\tspecify address family AF_INET6\n" +-#endif +- "\n" +- "\t-p P\tspecify port P (service name or port number)\n" +- "\t-N\thostname is numeric, skip DNS query\n" +- "\t-n\tservice/port is numeric (sets AI_NUMERICSERV)\n" +- "\t-P\tset AI_PASSIVE\n" +- "\n" +- "default: protocol 0, socket type 0, address family 0, null port\n" +- , +- whoami); +- /* [ -t | -u | -R | -I ] [ -d | -s | -r ] [ -p port ] */ +- exit (1); +-} +- +-static const char *familyname (int f) { +- static char buf[30]; +- switch (f) { +- default: +- snprintf(buf, sizeof(buf), "AF %d", f); +- return buf; +- case AF_INET: return "AF_INET"; +-#ifdef AF_INET6 +- case AF_INET6: return "AF_INET6"; +-#endif +- } +-} +- +-#define eaistr(X) (X == EAI_SYSTEM ? strerror(errno) : gai_strerror(X)) +- +-int main (int argc, char *argv[]) +-{ +- struct addrinfo *ap, *ap2; +- int err, numerichost = 0, numericserv = 0; +- char *hname, *port = 0, *sep; +- struct addrinfo hints; +- +- whoami = strrchr(argv[0], '/'); +- if (whoami == 0) +- whoami = argv[0]; +- else +- whoami = whoami+1; +- +- memset(&hints, 0, sizeof(hints)); +- hints.ai_flags = 0; +- hints.ai_socktype = 0; +- +- hname = 0; +- hints.ai_family = 0; +- +- if (argc == 1) +- usage (); +- +- while (++argv, --argc > 0) { +- char *arg; +- arg = *argv; +- +- if (*arg != '-') +- hname = arg; +- else if (arg[1] == 0 || arg[2] != 0) +- usage (); +- else +- switch (arg[1]) { +- case 'u': +- hints.ai_protocol = IPPROTO_UDP; +- break; +- case 't': +- hints.ai_protocol = IPPROTO_TCP; +- break; +- case 'R': +- hints.ai_protocol = IPPROTO_RAW; +- break; +- case 'I': +- hints.ai_protocol = IPPROTO_ICMP; +- break; +- case 'd': +- hints.ai_socktype = SOCK_DGRAM; +- break; +- case 's': +- hints.ai_socktype = SOCK_STREAM; +- break; +- case 'r': +- hints.ai_socktype = SOCK_RAW; +- break; +- case 'p': +- if (argv[1] == 0 || argv[1][0] == 0 || argv[1][0] == '-') +- usage (); +- port = argv[1]; +- argc--, argv++; +- break; +- case '4': +- hints.ai_family = AF_INET; +- break; +-#ifdef AF_INET6 +- case '6': +- hints.ai_family = AF_INET6; +- break; +-#endif +- case 'N': +- numerichost = 1; +- break; +- case 'n': +- numericserv = 1; +- break; +- case 'P': +- hints.ai_flags |= AI_PASSIVE; +- break; +- default: +- usage (); +- } +- } +- +- if (hname && !numerichost) +- hints.ai_flags |= AI_CANONNAME; +- if (numerichost) { +-#ifdef AI_NUMERICHOST +- hints.ai_flags |= AI_NUMERICHOST; +-#else +- fprintf(stderr, "AI_NUMERICHOST not defined on this platform\n"); +- exit(1); +-#endif +- } +- if (numericserv) { +-#ifdef AI_NUMERICSERV +- hints.ai_flags |= AI_NUMERICSERV; +-#else +- fprintf(stderr, "AI_NUMERICSERV not defined on this platform\n"); +- exit(1); +-#endif +- } +- +- printf("getaddrinfo(hostname %s, service %s,\n" +- " hints { ", +- hname ? hname : "(null)", port ? port : "(null)"); +- sep = ""; +-#define Z(FLAG) if (hints.ai_flags & AI_##FLAG) printf("%s%s", sep, #FLAG), sep = "|" +- Z(CANONNAME); +- Z(PASSIVE); +-#ifdef AI_NUMERICHOST +- Z(NUMERICHOST); +-#endif +-#ifdef AI_NUMERICSERV +- Z(NUMERICSERV); +-#endif +- if (sep[0] == 0) +- printf ("no-flags"); +- if (hints.ai_family) +- printf(" %s", familyname(hints.ai_family)); +- if (hints.ai_socktype) +- printf(" SOCK_%s", socktypename(hints.ai_socktype)); +- if (hints.ai_protocol) +- printf(" IPPROTO_%s", protoname(hints.ai_protocol)); +- printf(" }):\n"); +- +- err = getaddrinfo(hname, port, &hints, &ap); +- if (err) { +- printf("\terror => %s\n", eaistr(err)); +- return 1; +- } +- +- for (ap2 = ap; ap2; ap2 = ap2->ai_next) { +- char hbuf[NI_MAXHOST], pbuf[NI_MAXSERV]; +- /* If we don't do this, even AIX's own getnameinfo will reject +- the sockaddr structures. The sa_len field doesn't get set +- either, on AIX, but getnameinfo won't complain. */ +- if (ap2->ai_addr->sa_family == 0) { +- printf("BAD: sa_family zero! fixing...\n"); +- ap2->ai_addr->sa_family = ap2->ai_family; +- } else if (ap2->ai_addr->sa_family != ap2->ai_family) { +- printf("BAD: sa_family != ai_family! fixing...\n"); +- ap2->ai_addr->sa_family = ap2->ai_family; +- } +- if (getnameinfo(ap2->ai_addr, ap2->ai_addrlen, hbuf, sizeof(hbuf), +- pbuf, sizeof(pbuf), NI_NUMERICHOST | NI_NUMERICSERV)) { +- strlcpy(hbuf, "...", sizeof(hbuf)); +- strlcpy(pbuf, "...", sizeof(pbuf)); +- } +- printf("%p:\n" +- "\tfamily = %s\tproto = %-4s\tsocktype = %s\n", +- (void *) ap2, familyname(ap2->ai_family), +- protoname (ap2->ai_protocol), +- socktypename (ap2->ai_socktype)); +- if (ap2->ai_canonname) { +- if (ap2->ai_canonname[0]) +- printf("\tcanonname = %s\n", ap2->ai_canonname); +- else +- printf("BAD: ai_canonname is set but empty!\n"); +- } else if (ap2 == ap && (hints.ai_flags & AI_CANONNAME)) { +- printf("BAD: first ai_canonname is null!\n"); +- } +- printf("\taddr = %-28s\tport = %s\n", hbuf, pbuf); +- +- err = getnameinfo(ap2->ai_addr, ap2->ai_addrlen, hbuf, sizeof (hbuf), +- pbuf, sizeof(pbuf), NI_NAMEREQD); +- if (err) +- printf("\tgetnameinfo(NI_NAMEREQD): %s\n", eaistr(err)); +- else +- printf("\tgetnameinfo => %s, %s\n", hbuf, pbuf); +- } +- freeaddrinfo(ap); +- return 0; +-} +diff --git a/src/tests/resolve/deps b/src/tests/resolve/deps +deleted file mode 100644 +index 762d9adab..000000000 +--- a/src/tests/resolve/deps ++++ /dev/null +@@ -1,14 +0,0 @@ +-# +-# Generated makefile dependencies follow. +-# +-$(OUTPRE)resolve.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-thread.h \ +- resolve.c +-$(OUTPRE)addrinfo-test.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-thread.h \ +- addrinfo-test.c +-$(OUTPRE)fake-addrinfo-test.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(top_srcdir)/include/fake-addrinfo.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h addrinfo-test.c \ +- fake-addrinfo-test.c +diff --git a/src/tests/resolve/fake-addrinfo-test.c b/src/tests/resolve/fake-addrinfo-test.c +deleted file mode 100644 +index 86365a5ba..000000000 +--- a/src/tests/resolve/fake-addrinfo-test.c ++++ /dev/null +@@ -1,3 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-#define USE_FAKE_ADDRINFO +-#include "addrinfo-test.c" +diff --git a/src/tests/resolve/resolve.c b/src/tests/resolve/resolve.c +deleted file mode 100644 +index ea0239113..000000000 +--- a/src/tests/resolve/resolve.c ++++ /dev/null +@@ -1,115 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* tests/resolve/resolve.c */ +-/* +- * Copyright 1995 by the Massachusetts Institute of Technology. +- * All Rights Reserved. +- * +- * Export of this software from the United States of America may +- * require a specific license from the United States Government. +- * It is the responsibility of any person or organization contemplating +- * export to obtain such a license before exporting. +- * +- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and +- * distribute this software and its documentation for any purpose and +- * without fee is hereby granted, provided that the above copyright +- * notice appear in all copies and that both that copyright notice and +- * this permission notice appear in supporting documentation, and that +- * the name of M.I.T. not be used in advertising or publicity pertaining +- * to distribution of the software without specific, written prior +- * permission. Furthermore if you modify this software you must label +- * your software as modified software and not distribute it in such a +- * fashion that it might be confused with the original M.I.T. software. +- * M.I.T. makes no representations about the suitability of +- * this software for any purpose. It is provided "as is" without express +- * or implied warranty. +- */ +- +-/* +- * A simple program to test the functionality of the resolver library. +- * It simply will try to get the IP address of the host, and then look +- * up the name from the address. If the resulting name does not contain the +- * domain name, then the resolve library is broken. +- * +- * Warning: It is possible to fool this program into thinking everything is +- * alright by a clever use of /etc/hosts - but this is better than nothing. +- * +- * Usage: +- * resolve [hostname] +- * +- * When invoked with no arguments, gethostname is used for the local host. +- * +- */ +- +-/* This program tests the resolve library and sees if it is broken... */ +- +-#include "k5-platform.h" +-#include +-#include +-#include +-#include +-#ifdef HAVE_SYS_PARAM_H +-#include +-#endif +- +-int +-main(int argc, char **argv) +-{ +- struct addrinfo *ai = NULL, hint; +- char myname[MAXHOSTNAMELEN + 1], namebuf[NI_MAXHOST], abuf[256]; +- const char *addrstr; +- int err, quiet = 0; +- +- argc--; argv++; +- while (argc) { +- if ((strcmp(*argv, "--quiet") == 0) || +- (strcmp(*argv, "-q") == 0)) { +- quiet++; +- } else +- break; +- argc--; argv++; +- } +- +- if (argc >= 1) { +- strlcpy(myname, *argv, sizeof(myname)); +- } else { +- if(gethostname(myname, MAXHOSTNAMELEN)) { +- perror("gethostname failure"); +- exit(1); +- } +- } +- +- myname[MAXHOSTNAMELEN] = '\0'; /* for safety */ +- +- /* Look up the address... */ +- if (!quiet) +- printf("Hostname: %s\n", myname); +- +- memset(&hint, 0, sizeof(hint)); +- hint.ai_flags = AI_CANONNAME; +- err = getaddrinfo(myname, 0, &hint, &ai); +- if (err) { +- fprintf(stderr, +- "Could not look up address for hostname '%s' - fatal\n", +- myname); +- exit(2); +- } +- +- if (!quiet) { +- addrstr = inet_ntop(ai->ai_family, ai->ai_addr, abuf, sizeof(abuf)); +- if (addrstr != NULL) +- printf("Host address: %s\n", addrstr); +- } +- +- err = getnameinfo(ai->ai_addr, ai->ai_addrlen, namebuf, sizeof(namebuf), +- NULL, 0, NI_NAMEREQD); +- if (err && !quiet) +- fprintf(stderr, "Error looking up IP address\n"); +- +- printf("%s%s\n", quiet ? "" : "FQDN: ", err ? ai->ai_canonname : namebuf); +- +- if (!quiet) +- printf("Resolve library appears to have passed the test\n"); +- +- freeaddrinfo(ai); +- return 0; +-} diff --git a/krb5.spec b/krb5.spec index ccd17ed..264ff0f 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 3%{?dist} +Release: 4%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -60,6 +60,8 @@ Patch17: Pass-gss_localname-through-SPNEGO.patch Patch18: Omit-KDC-indicator-check-for-S4U2Self-requests.patch Patch19: Fix-typo-in-in-in-the-ksu-man-page.patch Patch20: Pass-channel-bindings-through-SPNEGO.patch +Patch21: Default-dns_canonicalize_hostname-to-fallback.patch +Patch22: Remove-resolver-test-utility.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -632,6 +634,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Sat May 30 2020 Robbie Harwood - 1.18.2-4 +- Default dns_canonicalize_hostname to "fallback" + * Tue May 26 2020 Robbie Harwood - 1.18.2-3 - dns_canonicalize_hostname = fallback From 49849de3293936c6c1869f459ca3456c8804a06f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Sat, 30 May 2020 12:38:04 -0400 Subject: [PATCH 175/304] Replace gssrpc tests with a Python script --- ...ns_canonicalize_hostname-to-fallback.patch | 2 +- Remove-resolver-test-utility.patch | 6 +- ...ce-gssrpc-tests-with-a-Python-script.patch | 861 ++++++++++++++++++ krb5.spec | 10 +- 4 files changed, 872 insertions(+), 7 deletions(-) create mode 100644 Replace-gssrpc-tests-with-a-Python-script.patch diff --git a/Default-dns_canonicalize_hostname-to-fallback.patch b/Default-dns_canonicalize_hostname-to-fallback.patch index 2e34e13..b252354 100644 --- a/Default-dns_canonicalize_hostname-to-fallback.patch +++ b/Default-dns_canonicalize_hostname-to-fallback.patch @@ -1,4 +1,4 @@ -From 1e72ba5c1b74d5b78f84c5884d06e979830aeb53 Mon Sep 17 00:00:00 2001 +From d003b4aa8dce14967725d6607c54ceb884b3647c Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 27 May 2020 18:48:35 -0400 Subject: [PATCH] Default dns_canonicalize_hostname to "fallback" diff --git a/Remove-resolver-test-utility.patch b/Remove-resolver-test-utility.patch index 444f99a..95055df 100644 --- a/Remove-resolver-test-utility.patch +++ b/Remove-resolver-test-utility.patch @@ -1,4 +1,4 @@ -From 621cf6c98d74b025a0ca190cd279756596709ef9 Mon Sep 17 00:00:00 2001 +From c21bb26abc4799298726124d73f0c968430a87bd Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 28 May 2020 18:41:02 -0400 Subject: [PATCH] Remove resolver test utility @@ -22,10 +22,10 @@ tests/resolve is no longer used after the previous commit. delete mode 100644 src/tests/resolve/resolve.c diff --git a/src/configure.ac b/src/configure.ac -index 29be532cb..2a756d6b5 100644 +index aafc462f9..00b5ea4c5 100644 --- a/src/configure.ac +++ b/src/configure.ac -@@ -1542,7 +1542,6 @@ V5_AC_OUTPUT_MAKEFILE(. +@@ -1540,7 +1540,6 @@ V5_AC_OUTPUT_MAKEFILE(. appl/simple appl/simple/client appl/simple/server appl/gss-sample appl/user_user diff --git a/Replace-gssrpc-tests-with-a-Python-script.patch b/Replace-gssrpc-tests-with-a-Python-script.patch new file mode 100644 index 0000000..5632455 --- /dev/null +++ b/Replace-gssrpc-tests-with-a-Python-script.patch @@ -0,0 +1,861 @@ +From 5af211200d6c2ac82872435556f5b39edcaba541 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sat, 15 Feb 2020 20:34:23 -0500 +Subject: [PATCH] Replace gssrpc tests with a Python script + +Replace the dejagnu RPC test framework with a short Python script to +do the same tests as fullrun.exp and gsserr.exp. Modify the server +test program to facilitate use by k5test.py. + +expire.exp, together with a comment in the client test program, was +designed to test a libdb2 btree bug via the gssrpc server-side +authentication code. That code was subsequently changed not to use +libdb2, before it was merged into the main krb5 tree (in revision 1.23 +of svc_auth_gssapi.c, according to the changelog removed in commit +2a43d772be1e45faa8e488d436b6e867371563fb). Remove the comment and do +not replace that test sequence. + +[rharwood@redhat.com: .gitignore] +--- + src/configure.ac | 2 - + src/lib/rpc/unit-test/Makefile.in | 36 +-- + src/lib/rpc/unit-test/client.c | 26 --- + src/lib/rpc/unit-test/config/unix.exp | 176 -------------- + src/lib/rpc/unit-test/lib/helpers.exp | 234 ------------------- + src/lib/rpc/unit-test/rpc_test.0/expire.exp | 49 ---- + src/lib/rpc/unit-test/rpc_test.0/fullrun.exp | 91 -------- + src/lib/rpc/unit-test/rpc_test.0/gsserr.exp | 30 --- + src/lib/rpc/unit-test/server.c | 13 +- + src/lib/rpc/unit-test/t_rpc.py | 29 +++ + 10 files changed, 41 insertions(+), 645 deletions(-) + delete mode 100644 src/lib/rpc/unit-test/config/unix.exp + delete mode 100644 src/lib/rpc/unit-test/lib/helpers.exp + delete mode 100644 src/lib/rpc/unit-test/rpc_test.0/expire.exp + delete mode 100644 src/lib/rpc/unit-test/rpc_test.0/fullrun.exp + delete mode 100644 src/lib/rpc/unit-test/rpc_test.0/gsserr.exp + create mode 100644 src/lib/rpc/unit-test/t_rpc.py + +diff --git a/src/configure.ac b/src/configure.ac +index 29be532cb..aafc462f9 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -1102,8 +1102,6 @@ extern void endrpcent();], + AC_MSG_RESULT($k5_cv_type_endrpcent) + AC_DEFINE_UNQUOTED(ENDRPCENT_TYPE, $k5_cv_type_endrpcent, [Define as return type of endrpcent]) + K5_GEN_FILE(include/gssrpc/types.h:include/gssrpc/types.hin) +-PASS=tcp +-AC_SUBST(PASS) + + # for pkinit + AC_ARG_ENABLE([pkinit], +diff --git a/src/lib/rpc/unit-test/Makefile.in b/src/lib/rpc/unit-test/Makefile.in +index 0b6e5203d..309ae2b21 100644 +--- a/src/lib/rpc/unit-test/Makefile.in ++++ b/src/lib/rpc/unit-test/Makefile.in +@@ -16,10 +16,6 @@ server: server.o rpc_test_svc.o $(GSSRPC_DEPLIBS) $(KRB5_BASE_DEPLIBS) + + client.o server.o: rpc_test.h + +-runenv.exp: Makefile +- $(RUN_SETUP); for i in $(RUN_VARS); do \ +- eval echo "set env\($$i\) \$$$$i"; done > runenv.exp +- + # If rpc_test.h and rpc_test_*.c do not work on your system, you can + # try using rpcgen by uncommenting these lines (be sure to uncomment + # then in the generated not Makefile.in). +@@ -34,37 +30,9 @@ runenv.exp: Makefile + # rm -f rpc_test.h rpc_test_clnt.c rpc_test_svc.c + # + +-check unit-test: unit-test-@DO_TEST@ +- +-unit-test-: +- @echo "+++" +- @echo "+++ WARNING: lib/rpc unit tests not run." +- @echo "+++ Either tcl, runtest, or Perl is unavailable." +- @echo "+++" +- @echo 'Skipped rpc tests: runtest or Perl not found' >> $(SKIPTESTS) +- +-unit-test-ok: unit-test-body +- +-PASS=@PASS@ +-unit-test-body: runenv.sh runenv.exp +- $(RM) krb5cc_rpc_test_* +- $(ENV_SETUP) $(VALGRIND) $(START_SERVERS) +- RPC_TEST_KEYTAB=/tmp/rpc_test_keytab.$$$$ ; export RPC_TEST_KEYTAB ; \ +- trap "echo Failed, cleaning up... ; rm -f $$RPC_TEST_KEYTAB ; $(ENV_SETUP) $(STOP_SERVERS) ; trap '' 0 ; exit 1" 0 1 2 3 14 15 ; \ +- if $(ENV_SETUP) \ +- $(RUNTEST) SERVER=./server CLIENT=./client \ +- KINIT=$(BUILDTOP)/clients/kinit/kinit \ +- KDESTROY=$(BUILDTOP)/clients/kdestroy/kdestroy \ +- PRIOCNTL_HACK=@PRIOCNTL_HACK@ VALGRIND="$(VALGRIND)" \ +- PASS="$(PASS)" --tool rpc_test $(RUNTESTFLAGS) ; \ +- then \ +- echo Cleaning up... ; \ +- rm -f $$RPC_TEST_KEYTAB krb5cc_rpc_test_* ; \ +- $(ENV_SETUP) $(STOP_SERVERS) ; \ +- trap 0 ; exit 0 ; \ +- else exit 1 ; fi ++check-pytests: ++ $(RUNPYTEST) $(srcdir)/t_rpc.py $(PYTESTFLAGS) + + clean: + $(RM) server client +- $(RM) dbg.log rpc_test.log rpc_test.sum runenv.exp + +diff --git a/src/lib/rpc/unit-test/client.c b/src/lib/rpc/unit-test/client.c +index 5edde49df..c9a812bc5 100644 +--- a/src/lib/rpc/unit-test/client.c ++++ b/src/lib/rpc/unit-test/client.c +@@ -231,32 +231,6 @@ main(argc, argv) + else + gssrpc_xdr_free(xdr_wrapstring, echo_resp); + +- /* +- * Test fix for secure-rpc/586, part 1: btree keys must be +- * unique. Create another context from the same credentials; it +- * should have the same expiration time and will cause the server +- * to abort if the clients are not differentiated. +- * +- * Test fix for secure-rpc/586, part 2: btree keys cannot be +- * mutated in place. To test this: a second client, *with a +- * later expiration time*, must be run. The second client should +- * destroy itself *after* the first one; if the key-mutating bug +- * is not fixed, the second client_data will be in the btree +- * before the first, but its key will be larger; thus, when the +- * first client calls AUTH_DESTROY, the server won't find it in +- * the btree and call abort. +- * +- * For unknown reasons, running just a second client didn't +- * tickle the bug; the btree code seemed to guess which node to +- * look at first. Running a total of three clients does ticket +- * the bug. Thus, the full test sequence looks like this: +- * +- * kinit -l 20m user && client server test@ddn 200 +- * sleep 1 +- * kini -l 30m user && client server test@ddn 300 +- * sleep 1 +- * kinit -l 40m user && client server test@ddn 400 +- */ + if (! auth_once) { + tmp_auth = clnt->cl_auth; + clnt->cl_auth = auth_gssapi_create_default(clnt, target); +diff --git a/src/lib/rpc/unit-test/config/unix.exp b/src/lib/rpc/unit-test/config/unix.exp +deleted file mode 100644 +index 18da62be4..000000000 +--- a/src/lib/rpc/unit-test/config/unix.exp ++++ /dev/null +@@ -1,176 +0,0 @@ +-# +-# $Id$ +-# +- +-source runenv.exp +- +-set kill /bin/kill +-set sleep /bin/sleep +-set kinit $KINIT +-set kdestroy $KDESTROY +- +-set hostname [exec hostname] +- +-# Hack around Solaris 9 kernel race condition that causes last output +-# from a pty to get dropped. +-if { $PRIOCNTL_HACK } { +- catch {exec priocntl -s -c FX -m 30 -p 30 -i pid [getpid]} +- rename spawn oldspawn +- proc spawn { args } { +- upvar 1 spawn_id spawn_id +- set newargs {} +- set inflags 1 +- set eatnext 0 +- foreach arg $args { +- if { $arg == "-ignore" \ +- || $arg == "-open" \ +- || $arg == "-leaveopen" } { +- lappend newargs $arg +- set eatnext 1 +- continue +- } +- if [string match "-*" $arg] { +- lappend newargs $arg +- continue +- } +- if { $eatnext } { +- set eatnext 0 +- lappend newargs $arg +- continue +- } +- if { $inflags } { +- set inflags 0 +- set newargs [concat $newargs {priocntl -e -c FX -p 0}] +- } +- lappend newargs $arg +- } +- set pid [eval oldspawn $newargs] +- return $pid +- } +-} +- +-if { [string length $VALGRIND] } { +- rename spawn valgrind_aux_spawn +- proc spawn { args } { +- global VALGRIND +- upvar 1 spawn_id spawn_id +- set newargs {} +- set inflags 1 +- set eatnext 0 +- foreach arg $args { +- if { $arg == "-ignore" \ +- || $arg == "-open" \ +- || $arg == "-leaveopen" } { +- lappend newargs $arg +- set eatnext 1 +- continue +- } +- if [string match "-*" $arg] { +- lappend newargs $arg +- continue +- } +- if { $eatnext } { +- set eatnext 0 +- lappend newargs $arg +- continue +- } +- if { $inflags } { +- set inflags 0 +- # Only run valgrind for local programs, not +- # system ones. +-#&&![string match "/bin/sh" $arg] sh is used to start kadmind! +- if [string match "/" [string index $arg 0]]&&![string match "/bin/ls" $arg]&&![regexp {/kshd$} $arg] { +- set newargs [concat $newargs $VALGRIND] +- } elseif [string match "." [string index $arg 0]] { +- set newargs [concat $newargs $VALGRIND] +- } +- } +- lappend newargs $arg +- } +- set pid [eval valgrind_aux_spawn $newargs] +- return $pid +- } +-} +- +-# this will initialize the database and keytab +-load_lib "helpers.exp" +- +-proc rpc_test_version {} { +- global CLIENT +- global SERVER +- +- clone_output "$CLIENT version " +- clone_output "$SERVER version " +-} +- +-proc rpc_test_load {} { +- # +-} +- +-# rpc_test_exit -- clean up and exit +-proc rpc_test_exit {} { +- global server_id +- global server_pid +- global server_started +- global kill +- +- if {[catch { +- expect { +- -i $server_id +- eof { +- fail "server exited!" +- verbose $expect_out(buffer) 1 +- } +- timeout { pass "server survived" } +- } +- } tmp]} { +- fail "server exited! (expect failed)" +- } +-} +- +-# +-# rpc_test_start -- start the rpc_test server running +-# +-proc rpc_test_start { } { +- global SERVER PROT +- global server_id +- global server_pid +- global server_started +- global server_port +- global env +- +- if [info exists server_pid] { rpc_test_exit } +- +- set env(KRB5_KTNAME) FILE:$env(RPC_TEST_KEYTAB) +- +- verbose "% $SERVER" 1 +- set server_pid [spawn $SERVER $PROT] +- set server_id $spawn_id +- set server_started 1 +- set server_port -1 +- +- unset env(KRB5_KTNAME) +- +- set timeout 30 +- +- expect { +- -re "port: (\[0-9\]*)\r\n" { +- set server_port $expect_out(1,string) +- } +- "running" { } +- eof { +- send_error "server exited!" +- verbose $expect_out(buffer) 1 +- } +- timeout { +- send_error "server didn't start in $timeout seconds" +- verbose $expect_out(buffer) 1 +- } +- } +- +-} +- +-set MULTIPASS { +- {tcp PROT=-t dummy=[rpc_test_start]} +- {udp PROT=-u dummy=[rpc_test_start]} +-} +diff --git a/src/lib/rpc/unit-test/lib/helpers.exp b/src/lib/rpc/unit-test/lib/helpers.exp +deleted file mode 100644 +index eb2797c53..000000000 +--- a/src/lib/rpc/unit-test/lib/helpers.exp ++++ /dev/null +@@ -1,234 +0,0 @@ +-if {[info commands exp_version] != {}} { +- set exp_version_4 [regexp {^4} [exp_version]] +-} else { +- set exp_version_4 [regexp {^4} [expect_version]] +-} +- +-# Backward compatibility until we're using expect 5 everywhere +-if {$exp_version_4} { +- global wait_error_index wait_errno_index wait_status_index +- set wait_error_index 0 +- set wait_errno_index 1 +- set wait_status_index 1 +-} else { +- set wait_error_index 2 +- set wait_errno_index 3 +- set wait_status_index 3 +-} +- +-proc set_from_env {varname default_value} { +- global env +- upvar $varname v +- +- if [info exists env($varname)] { +- set v $env($varname) +- } else { +- set v $default_value +- } +-} +-proc expect_tcl_prompt {} { +- global kadmin_tcl_spawn_id +- expect { +- -i $kadmin_tcl_spawn_id +- -re "^% $" { } +- -re . { perror "unexpected output {$expect_out(buffer)} from subprocess, expecting tcl prompt" } +- timeout { perror "timeout waiting for tcl prompt" } +- eof { perror "eof from subprocess when expecting tcl prompt" } +- } +-} +-proc send_tcl_cmd_await_echo {cmd} { +- global kadmin_tcl_spawn_id +- send -i $kadmin_tcl_spawn_id "$cmd\n" +- expect { +- -i $kadmin_tcl_spawn_id +- -ex "$cmd\r\n" { } +- timeout { perror "timeout waiting for tcl subprocess to echo input" } +- eof { perror "eof waiting for tcl subprocess to echo input" } +- } +-} +-proc expect_kadm_ok {} { +- global kadmin_tcl_spawn_id +- expect { +- -i $kadmin_tcl_spawn_id +- -re "^OK KADM5_OK \[^\n\]*\n" {} +- -re "^ERROR \[^\n\]*\n" { perror "kadmin tcl subprocess reported unexpected error" } +- -re "^marshall_new_creds: \[^\n\]*\n" { exp_continue } +- -re "^gssapi_\[^\n\]*\n" { exp_continue } +- -re "^\r?\n" { exp_continue } +- eof { perror "kadmin tcl subprocess died" } +- default { perror "didn't get ok back" } +- } +-} +-proc setup_database {} { +- global env spawn_id kadmin_tcl_spawn_id TESTDIR CANON_HOST +- +- # XXXXX +- set_from_env TOP {/x/x/x/x/x} +- send_user "TOP=$TOP\n" +- +- set_from_env TESTDIR $env(TOP)/testing +- set_from_env CLNTTCL $TESTDIR/util/kadm5_clnt_tcl +- set_from_env TCLUTIL $TESTDIR/tcl/util.t +- set env(TCLUTIL) $TCLUTIL +- set env(PATH) "$TOP/install/admin:$env(PATH)" +- +- # $VERBOSE ? +- +- if [info exists spawn_id] { set x $spawn_id } +- spawn $CLNTTCL +- set kadmin_tcl_spawn_id $spawn_id +- if [info exists x] { set spawn_id $x } +- +- expect_tcl_prompt +- # tcl 8.4 for some reason screws up autodetection of output EOL +- # translation. Work around it for now. +- send_tcl_cmd_await_echo "if { \[info commands fconfigure\] != \"\" } { fconfigure stdout -translation lf }" +- expect_tcl_prompt +- send_tcl_cmd_await_echo "source {$TCLUTIL}" +- expect_tcl_prompt +- send_tcl_cmd_await_echo "set h {$CANON_HOST}" +- expect { +- -ex "$CANON_HOST\r\n" { } +- timeout { perror "timeout waiting for subprocess" } +- eof { perror "eof from subprocess" } +- } +- expect_tcl_prompt +- +- send_tcl_cmd_await_echo {kadm5_init admin admin $KADM5_ADMIN_SERVICE null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 server_handle} +- expect_kadm_ok +- expect "^% " +- send_tcl_cmd_await_echo {kadm5_create_principal $server_handle [simple_principal server/$h] {KADM5_PRINCIPAL} admin} +- expect_kadm_ok +- expect "^% " +- send_tcl_cmd_await_echo {kadm5_randkey_principal $server_handle server/$h key null} +- expect_kadm_ok +- expect "^% " +- send_tcl_cmd_await_echo {kadm5_create_principal $server_handle [simple_principal notserver/$h] {KADM5_PRINCIPAL} admin} +- expect_kadm_ok +- expect "^% " +- send_tcl_cmd_await_echo {kadm5_randkey_principal $server_handle notserver/$h key null} +- expect_kadm_ok +- expect "^% " +- send_tcl_cmd_await_echo {kadm5_destroy $server_handle} +- expect_kadm_ok +- expect "^% " +- wait -nowait -i $spawn_id +- close -i $spawn_id +-} +- +-if ![info exists CANON_HOST] { +- set CANON_HOST $env(QUALNAME) +- setup_database +- file delete $env(RPC_TEST_KEYTAB) +- exec $env(TOP)/cli/kadmin -p admin -w admin ktadd -k $env(RPC_TEST_KEYTAB) server/$CANON_HOST +-} +- +- +-proc kinit {princ pass lifetime} { +- global kinit +- global wait_error_index wait_errno_index wait_status_index +- +- spawn -noecho $kinit -5 -l $lifetime $princ +- expect { +- -re "Password for $princ.*: " { send "$pass\n"; expect eof } +- timeout { perror "Timeout waiting for kinit"; close } +- eof +- } +- +- set ret [wait] +- if {[lindex $ret $wait_error_index] == -1} { +- perror \ +- "wait(kinit $princ) returned error [lindex $ret $wait_errno_index]" +- } else { +- if {[lindex $ret $wait_status_index] != 0} { +- perror \ +- "kinit $princ failed with [lindex $ret $wait_status_index]" +- } +- } +-} +- +-proc flush_server {} { +- global server_id +- global expect_out +- +- verbose "flushing server output" 1 +- +- while {1} { +- set timeout 5 +- +- expect { +- -i $server_id +- -re "^.+$" { +- verbose "server output: $expect_out(buffer)" +- } +- timeout { break } +- } +- } +-} +- +-proc start_client {testname ccname user password lifetime count +- {target ""}} { +- global env CLIENT PROT hostname server_port spawn_id verbose +- +- if {$target == ""} { +- set target "server@$hostname" +- } +- +- set env(KRB5CCNAME) FILE:[pwd]/krb5cc_rpc_test_$ccname +- kinit $user $password $lifetime +- +- if {$verbose > 0} { +- spawn $CLIENT -a 1 -s 1 -m 1 $PROT $hostname $server_port $target $count +- } else { +- spawn $CLIENT $PROT $hostname $server_port $target $count +- } +- +- verbose "$testname: client $ccname started" +- +- unset env(KRB5CCNAME) +-} +- +-proc eof_client {testname ccname id status} { +- verbose "$testname: eof'ing for client $ccname" 1 +- +- expect { +- -i $id +- -re "^marshall_new_creds\[^\n\]*\n" { exp_continue } +- -re "^gssapi_\[^\n\]*\n" { exp_continue } +- -re "^\r?\n" { exp_continue } +- eof { verbose $expect_out(buffer) 1 } +- timeout { +- fail "$testname: timeout waiting for client $ccname to exit" +- } +- } +- wait_client $testname $ccname $id $status +-} +- +- +-proc wait_client {testname ccname id status} { +- global env +- global kill +- global kdestroy +- global wait_error_index wait_errno_index wait_status_index +- +- verbose "$testname: waiting for client $ccname" 1 +- +- set ret [wait -i $id] +- if {[lindex $ret $wait_error_index] == -1} { +- fail \ +- "$testname: wait $ccname returned error [lindex $ret $wait_errno_index]" +- } else { +- if {[lindex $ret $wait_status_index] == $status} { +- pass "$testname: client $ccname" +- } else { +- fail "$testname: client $ccname: unexpected return status [lindex $ret $wait_status_index], should be $status." +- } +- } +- +- set env(KRB5CCNAME) FILE:[pwd]/krb5cc_rpc_test_$ccname +- if {[catch "exec $kdestroy -5"] != 0} { +- perror "$testname: cannot destroy client $ccname ccache" +- } +- +- unset env(KRB5CCNAME) +-} +diff --git a/src/lib/rpc/unit-test/rpc_test.0/expire.exp b/src/lib/rpc/unit-test/rpc_test.0/expire.exp +deleted file mode 100644 +index e19cca0ef..000000000 +--- a/src/lib/rpc/unit-test/rpc_test.0/expire.exp ++++ /dev/null +@@ -1,49 +0,0 @@ +-set timeout 40 +- +-load_lib "helpers.exp" +- +-global server_started +- +-proc expired {} { +- global spawn_id server_id +- +- start_client expired expired testuser notathena -1m 100 +- eof_client expired expired $spawn_id 2 +- +- expect { +- -i $server_id +- -re "rpc_test server: Authen.*failed:.*credential.*expired" { pass "expired" } +- timeout { fail "expired: timeout waiting for expired creds error" } +- } +- +- flush_server +-} +- +-# This test doesn't work after #6948, because the client won't try to +-# authenticate using an expired TGT. +-#if { $server_started } {expired } +- +-proc overlap {} { +- global spawn_id +- +- start_client expire 1 testuser notathena 20m 100 +- set client1_id $spawn_id +- flush_server +- +- start_client expire 2 testuser notathena 40m 300 +- set client2_id $spawn_id +- flush_server +- +- start_client expire 3 testuser notathena 60m 500 +- set client3_id $spawn_id +- flush_server +- +- eof_client expire 1 $client1_id 0 +- eof_client expire 2 $client2_id 0 +- eof_client expire 3 $client3_id 0 +- +- flush_server +-} +-if { $server_started } {overlap} +- +- +diff --git a/src/lib/rpc/unit-test/rpc_test.0/fullrun.exp b/src/lib/rpc/unit-test/rpc_test.0/fullrun.exp +deleted file mode 100644 +index 73083de1f..000000000 +--- a/src/lib/rpc/unit-test/rpc_test.0/fullrun.exp ++++ /dev/null +@@ -1,91 +0,0 @@ +-set timeout 120 +- +-load_lib "helpers.exp" +- +-global spawn_id +-global server_id +-global server_started +- +-if { !$server_started } {return} +- +-# Start the client and do a full run +-start_client "full run" fullrun testuser notathena 8h 1026 +-set client_id $spawn_id +- +-# +-# test: did we get 11 dots? +-# +-verbose "Starting RPC echo test. This will take about 50 seconds.\n" +- +-set ver_line "rpc_test server: bad verifier\[^\r\n\]*\[\r\n]+" +- +-set dots 0 +-set server_lines 0 +-while {1} { +- expect { +- -i $server_id +- -re $ver_line { +- verbose "Got line from server." +- incr server_lines +- } +- default { +- exp_continue +- } +- +- -i $client_id +- . { +- incr dots +- verbose "$expect_out(buffer)" 1 +- if ($dots==11) { break } +- } +- eof { +- # +- # test: was the exit status right? +- # +- wait_client "full run" fullrun $client_id 0 +- break +- } +- +- timeout { +- verbose "Timeout waiting for dot\n" 1 +- fail "full run: timeout waiting for dot" +- break +- } +- } +-} +-if {$dots==11} { +- pass "fullrun: echo test" +-} else { +- fail "fullrun: echo test: expected 11 dots, got $dots" +-} +- +-# +-# test: server logged four bad verifiers? +-# +-verbose "full run: checking server output" +- +-# Small timeout, since the server should have already printed everything +-set timeout 5 +- +-while {$server_lines < 4} { +- expect { +- -i $server_id +- -re $ver_line { +- incr server_lines +- } +- -re ".+\r\n" { +- verbose "Unexpected server output: $expect_out(buffer)" +- } +- default { +- break +- } +- } +-} +- +-if {$server_lines == 4} { +- pass "fullrun: bad verifiers" +-} else { +- fail "fullrun: expected four bad verifiers, got $server_lines" +-} +- +-flush_server +diff --git a/src/lib/rpc/unit-test/rpc_test.0/gsserr.exp b/src/lib/rpc/unit-test/rpc_test.0/gsserr.exp +deleted file mode 100644 +index 005971989..000000000 +--- a/src/lib/rpc/unit-test/rpc_test.0/gsserr.exp ++++ /dev/null +@@ -1,30 +0,0 @@ +-set timeout 30 +- +-load_lib "helpers.exp" +- +-global spawn_id +-global server_id +-global server_started +-global hostname +- +-if { !$server_started } {return} +- +-start_client "gss err" gsserr testuser notathena 8h 1026 notserver@$hostname +- +-eof_client "gss err" gsserr $spawn_id 2 +- +-# +-# test: server logged an authentication attempted failed? +-# +-verbose "gss err: checking server output" +- +-expect { +- -i $server_id +- -re "rpc_test server: Authent.*failed: .* not found in keytab" { +- pass "gss err: server logged auth error" +- } +- eof { fail "gss err: server exited" } +- timeout { fail "gss err: timeout waiting for server output" } +-} +- +-flush_server +diff --git a/src/lib/rpc/unit-test/server.c b/src/lib/rpc/unit-test/server.c +index 13e99bb06..c3bbcbf8c 100644 +--- a/src/lib/rpc/unit-test/server.c ++++ b/src/lib/rpc/unit-test/server.c +@@ -37,7 +37,7 @@ static void rpc_test_badverf(gss_name_t client, gss_name_t server, + caddr_t data); + + #ifndef SERVICE_NAME +-#define SERVICE_NAME "server" ++#define SERVICE_NAME "host" + #endif + + static void usage() +@@ -120,7 +120,6 @@ main(int argc, char **argv) + prot == IPPROTO_TCP ? "tcp" : "udp"); + exit(1); + } +- printf("port: %d\n", (int)transp->xp_port); + + if (svcauth_gssapi_set_names(names, 0) == FALSE) { + fprintf(stderr, "unable to set gssapi names\n"); +@@ -144,6 +143,8 @@ main(int argc, char **argv) + signal(SIGTERM, handlesig); + #endif + printf("running\n"); ++ printf("port: %d\n", (int)transp->xp_port); ++ fflush(stdout); + + svc_run(); + fprintf(stderr, "svc_run returned"); +@@ -177,6 +178,7 @@ static void rpc_test_badverf(gss_name_t client, gss_name_t server, + inet_ntoa(rqst->rq_xprt->xp_raddr.sin_addr), + ntohs(rqst->rq_xprt->xp_raddr.sin_port), + (int) server_name.length, (char *) server_name.value); ++ fflush(stdout); + + (void) gss_release_buffer(&minor_stat, &client_name); + (void) gss_release_buffer(&minor_stat, &server_name); +@@ -211,6 +213,7 @@ void rpc_test_badauth(OM_uint32 major, OM_uint32 minor, + printf("rpc_test server: Authentication attempt failed: %s", a); + log_badauth_display_status(major, minor); + printf("\n"); ++ fflush(stdout); + } + + void log_miscerr(struct svc_req *rqst, struct rpc_msg *msg, +@@ -220,6 +223,7 @@ void log_miscerr(struct svc_req *rqst, struct rpc_msg *msg, + + a = inet_ntoa(rqst->rq_xprt->xp_raddr.sin_addr); + printf("Miscellaneous RPC error: %s, %s\n", a, error); ++ fflush(stdout); + } + + void log_badauth_display_status(OM_uint32 major, OM_uint32 minor) +@@ -243,10 +247,12 @@ void log_badauth_display_status_1(OM_uint32 code, int type, int rec) + log_badauth_display_status_1(gssstat,GSS_C_GSS_CODE,1); + log_badauth_display_status_1(minor_stat, + GSS_C_MECH_CODE, 1); +- } else ++ } else { + printf("GSS-API authentication error %.*s: " + "recursive failure!\n", (int) msg.length, + (char *)msg.value); ++ } ++ fflush(stdout); + return; + } + +@@ -256,4 +262,5 @@ void log_badauth_display_status_1(OM_uint32 code, int type, int rec) + if (!msg_ctx) + break; + } ++ fflush(stdout); + } +diff --git a/src/lib/rpc/unit-test/t_rpc.py b/src/lib/rpc/unit-test/t_rpc.py +new file mode 100644 +index 000000000..4e565d25c +--- /dev/null ++++ b/src/lib/rpc/unit-test/t_rpc.py +@@ -0,0 +1,29 @@ ++import re ++ ++from k5test import * ++ ++realm = K5Realm() ++ ++server = realm.start_server(['./server', '-t'], 'running') ++line = server.stdout.readline() ++portstr = re.match(r'^port: (\d+)$', line).group(1) ++ ++realm.run(['./client', '-t', hostname, portstr, 'host@' + hostname, '1026'], ++ expected_msg='...........') ++ ++for i in range(4): ++ line = server.stdout.readline() ++ if 'rpc_test server: bad verifier from user@KRBTEST.COM at ' not in line: ++ fail('unexpected server message: ' + line) ++ output(line) ++ ++realm.addprinc('nokey/' + hostname) ++ ++realm.run(['./client', '-t', hostname, portstr, 'nokey@' + hostname, '1026'], ++ expected_code=2) ++ ++line = server.stdout.readline() ++if 'rpc_test server: Authentication attempt failed: ' not in line: ++ fail('unexpected server message: ' + line) ++ ++success('gssrpc auth_gssapi tests') diff --git a/krb5.spec b/krb5.spec index 264ff0f..3c2201e 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 4%{?dist} +Release: 5%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -60,8 +60,9 @@ Patch17: Pass-gss_localname-through-SPNEGO.patch Patch18: Omit-KDC-indicator-check-for-S4U2Self-requests.patch Patch19: Fix-typo-in-in-in-the-ksu-man-page.patch Patch20: Pass-channel-bindings-through-SPNEGO.patch -Patch21: Default-dns_canonicalize_hostname-to-fallback.patch -Patch22: Remove-resolver-test-utility.patch +Patch21: Replace-gssrpc-tests-with-a-Python-script.patch +Patch22: Default-dns_canonicalize_hostname-to-fallback.patch +Patch23: Remove-resolver-test-utility.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -634,6 +635,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Sat May 30 2020 Robbie Harwood - 1.18.2-5 +- Replace gssrpc tests with a Python script + * Sat May 30 2020 Robbie Harwood - 1.18.2-4 - Default dns_canonicalize_hostname to "fallback" From 3c4e18f2f31ae7d1bfd5a7721a067c3d21bea99c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 8 Jun 2020 16:01:55 -0400 Subject: [PATCH 176/304] Omit PA_FOR_USER if we can't compute its checksum --- ...SER-if-we-can-t-compute-its-checksum.patch | 34 +++++++++++++++++++ krb5.spec | 6 +++- 2 files changed, 39 insertions(+), 1 deletion(-) create mode 100644 Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch diff --git a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch new file mode 100644 index 0000000..0d6b9e9 --- /dev/null +++ b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch @@ -0,0 +1,34 @@ +From 086de78292b8ae89aba8a72926831124da44205d Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Sat, 6 Jun 2020 11:03:37 +0200 +Subject: [PATCH] Omit PA_FOR_USER if we can't compute its checksum + +OpenSSL in FIPS mode will refuse to perform hmac-md5. Omit the legacy +PA_FOR_USER element in this case rather than failing out. + +[ghudson@mit.edu: minor code and comment edits; wrote commit message] + +ticket: 8912 (new) +(cherry picked from commit 03f122bdb22cfa53c7d855ed929c9541e56365e0) +--- + src/lib/krb5/krb/s4u_creds.c | 7 +++++++ + 1 file changed, 7 insertions(+) + +diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c +index fc5c886d6..d8f486dc6 100644 +--- a/src/lib/krb5/krb/s4u_creds.c ++++ b/src/lib/krb5/krb/s4u_creds.c +@@ -534,6 +534,13 @@ krb5_get_self_cred_from_kdc(krb5_context context, + if (s4u_user.user_id.user != NULL && s4u_user.user_id.user->length) { + code = build_pa_for_user(context, tgtptr, &s4u_user.user_id, + &in_padata[1]); ++ /* ++ * If we couldn't compute the hmac-md5 checksum, send only the ++ * KRB5_PADATA_S4U_X509_USER; this will still work against modern ++ * Windows and MIT KDCs. ++ */ ++ if (code == KRB5_CRYPTO_INTERNAL) ++ code = 0; + if (code != 0) { + krb5_free_pa_data(context, in_padata); + goto cleanup; diff --git a/krb5.spec b/krb5.spec index 3c2201e..f485b6b 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 5%{?dist} +Release: 6%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -63,6 +63,7 @@ Patch20: Pass-channel-bindings-through-SPNEGO.patch Patch21: Replace-gssrpc-tests-with-a-Python-script.patch Patch22: Default-dns_canonicalize_hostname-to-fallback.patch Patch23: Remove-resolver-test-utility.patch +Patch24: Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -635,6 +636,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jun 08 2020 Robbie Harwood - 1.18.2-6 +- Omit PA_FOR_USER if we can't compute its checksum + * Sat May 30 2020 Robbie Harwood - 1.18.2-5 - Replace gssrpc tests with a Python script From feaafc07b2c53c9d7306e1d7987cfae76b843776 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 8 Jun 2020 22:00:22 +0000 Subject: [PATCH 177/304] Fix test suite by removing wrapper workarounds --- krb5.spec | 40 ++++++-------------- noport.c | 111 ------------------------------------------------------ 2 files changed, 11 insertions(+), 140 deletions(-) delete mode 100644 noport.c diff --git a/krb5.spec b/krb5.spec index f485b6b..0bd0d21 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 6%{?dist} +Release: 7%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -39,9 +39,6 @@ Source33: krb5kdc.logrotate Source34: kadmind.logrotate Source39: krb5-krb5kdc.conf -# Carry this locally until it's available in a packaged form. -Source100: noport.c - Patch0: downstream-ksu-pam-integration.patch Patch1: downstream-SELinux-integration.patch Patch2: downstream-Adjust-build-configuration.patch @@ -68,7 +65,7 @@ Patch24: Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch License: MIT URL: https://web.mit.edu/kerberos/www/ BuildRequires: autoconf, bison, cmake, flex, gawk, gettext, pkgconfig, sed -BuildRequires: gcc +BuildRequires: gcc, gcc-c++ BuildRequires: libcom_err-devel, libedit-devel, libss-devel BuildRequires: gzip, ncurses-devel BuildRequires: python3-sphinx @@ -88,8 +85,7 @@ BuildRequires: iproute BuildRequires: libverto-devel BuildRequires: openldap-devel BuildRequires: lmdb-devel -BuildRequires: nss_wrapper -BuildRequires: socket_wrapper +BuildRequires: python3-pyrad # Need KDFs. This is the backported version BuildRequires: openssl-devel >= 1:1.1.1d-4 @@ -295,34 +291,17 @@ sphinx-build -a -b man -t pathsubs doc build-man sphinx-build -a -b html -t pathsubs doc build-html rm -fr build-html/_sources -# We need to cut off any access to locally-running nameservers, too. -%{__cc} -fPIC -shared -o noport.so -Wall -Wextra %{SOURCE100} - %check -mkdir nss_wrapper - -# Set things up to use the test wrappers. -export NSS_WRAPPER_HOSTNAME=test.example.com -export NSS_WRAPPER_HOSTS="$PWD/nss_wrapper/fakehosts" -echo "127.0.0.1 $NSS_WRAPPER_HOSTNAME localhost" > $NSS_WRAPPER_HOSTS -export NOPORT='53,111' -export SOCKET_WRAPPER_DIR="$PWD/sockets" ; mkdir -p $SOCKET_WRAPPER_DIR -export LD_PRELOAD="$PWD/noport.so:libnss_wrapper.so:libsocket_wrapper.so" +pushd src # ugh. COPR doesn't expose the keyring, so try to cope. KEYCTL=keyctl keyctl list @u &>/dev/null || KEYCTL=: -# Run the test suite. We can't actually run the whole thing in the build -# system, but we can at least run more than we used to. The build system may -# give us a revoked session keyring, so run affected tests with a new one. -make -C src runenv.py -: make -C src check TMPDIR=%{_tmppath} -$KEYCTL session - make -C src/lib check TMPDIR=%{_tmppath} OFFLINE=yes -make -C src/kdc check TMPDIR=%{_tmppath} -$KEYCTL session - make -C src/appl check TMPDIR=%{_tmppath} -make -C src/clients check TMPDIR=%{_tmppath} -$KEYCTL session - make -C src/util check TMPDIR=%{_tmppath} +# The build system may give us a revoked session keyring, so run affected +# tests with a new one. +$KEYCTL session - make check OFFLINE=yes TMPDIR=%{_tmppath} +popd %install [ "$RPM_BUILD_ROOT" != '/' ] && rm -rf -- "$RPM_BUILD_ROOT" @@ -636,6 +615,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jun 08 2020 Robbie Harwood - 1.18.2-7 +- Fix test suite by removing wrapper workarounds + * Mon Jun 08 2020 Robbie Harwood - 1.18.2-6 - Omit PA_FOR_USER if we can't compute its checksum diff --git a/noport.c b/noport.c deleted file mode 100644 index 22088eb..0000000 --- a/noport.c +++ /dev/null @@ -1,111 +0,0 @@ -#define _GNU_SOURCE -#include -#include -#include -#include -#include -#include - -static int -port_is_okay(unsigned short port) -{ - char *p, *q; - long l; - - p = getenv("NOPORT"); - while ((p != NULL) && (*p != '\0')) { - l = strtol(p, &q, 10); - if ((q == NULL) || (q == p)) { - break; - } - if ((*q == '\0') || (*q == ',')) { - if (port == l) { - errno = ECONNREFUSED; - return -1; - } - } - p = q; - p += strspn(p, ","); - } - return 0; -} - -int -connect(int sockfd, const struct sockaddr *addr, socklen_t addrlen) -{ - unsigned short port; - static int (*next_connect)(int, const struct sockaddr *, socklen_t); - - if (next_connect == NULL) { - next_connect = dlsym(RTLD_NEXT, "connect"); - if (next_connect == NULL) { - errno = ENOSYS; - return -1; - } - } - - if (getenv("NOPORT") == NULL) { - return next_connect(sockfd, addr, addrlen); - } - - switch (addr->sa_family) { - case AF_INET: - port = ntohs(((struct sockaddr_in *)addr)->sin_port); - if (port_is_okay(port) != 0) { - return -1; - } - break; - case AF_INET6: - port = ntohs(((struct sockaddr_in6 *)addr)->sin6_port); - if (port_is_okay(port) != 0) { - return -1; - } - break; - default: - break; - } - return next_connect(sockfd, addr, addrlen); -} - -ssize_t -sendto(int sockfd, const void *buf, size_t len, int flags, - const struct sockaddr *dest_addr, socklen_t addrlen) -{ - unsigned short port; - static int (*next_sendto)(int, const void *, size_t, int, - const struct sockaddr *, socklen_t); - - if (next_sendto == NULL) { - next_sendto = dlsym(RTLD_NEXT, "sendto"); - if (next_sendto == NULL) { - errno = ENOSYS; - return -1; - } - } - - if (getenv("NOPORT") == NULL) { - return next_sendto(sockfd, buf, len, flags, dest_addr, addrlen); - } - - if (dest_addr != NULL) { - switch (dest_addr->sa_family) { - case AF_INET: - port = ((struct sockaddr_in *)dest_addr)->sin_port; - port = ntohs(port); - if (port_is_okay(port) != 0) { - return -1; - } - break; - case AF_INET6: - port = ((struct sockaddr_in6 *)dest_addr)->sin6_port; - port = ntohs(port); - if (port_is_okay(port) != 0) { - return -1; - } - break; - default: - break; - } - } - return next_sendto(sockfd, buf, len, flags, dest_addr, addrlen); -} From e326a52474f26ee9445725271425cc06563e7ff3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 15 Jun 2020 16:57:30 -0400 Subject: [PATCH 178/304] Match Heimdal behavior for channel bindings --- Add-channel-bindings-tests.patch | 419 +++++++++++++++ ...client_aware_channel_bindings-option.patch | 264 ++++++++++ ...ns_canonicalize_hostname-to-fallback.patch | 2 +- Implement-GSS_C_CHANNEL_BOUND_FLAG.patch | 91 ++++ ...ment-KERB_AP_OPTIONS_CBT-server-side.patch | 102 ++++ Improve-negoex_parse_token-code-hygiene.patch | 30 ++ ...SER-if-we-can-t-compute-its-checksum.patch | 2 +- Pass-channel-bindings-through-SPNEGO.patch | 2 +- Refactor-krb5-GSS-checksum-handling.patch | 479 ++++++++++++++++++ Remove-resolver-test-utility.patch | 2 +- ...ce-gssrpc-tests-with-a-Python-script.patch | 2 +- krb5.spec | 13 +- 12 files changed, 1401 insertions(+), 7 deletions(-) create mode 100644 Add-channel-bindings-tests.patch create mode 100644 Add-client_aware_channel_bindings-option.patch create mode 100644 Implement-GSS_C_CHANNEL_BOUND_FLAG.patch create mode 100644 Implement-KERB_AP_OPTIONS_CBT-server-side.patch create mode 100644 Improve-negoex_parse_token-code-hygiene.patch create mode 100644 Refactor-krb5-GSS-checksum-handling.patch diff --git a/Add-channel-bindings-tests.patch b/Add-channel-bindings-tests.patch new file mode 100644 index 0000000..b758c79 --- /dev/null +++ b/Add-channel-bindings-tests.patch @@ -0,0 +1,419 @@ +From 3e92520c1417f22447751cd9172d5ab30c2e0ad8 Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Fri, 20 Mar 2020 00:17:28 +0100 +Subject: [PATCH] Add channel bindings tests + +[ghudson@mit.edu: adjusted test program to output channel-bound state +instead of optionally enforcing it; adjusted tests to check program +output; split out tests into separate Python script; made cosmetic +changes] + +ticket: 8900 +(cherry picked from commit b0b21b6d25b06f3e2b365dfe9dd4c99b3d43bf57) +[rharwood@redhat.com: .gitignore] +--- + src/plugins/gssapi/negoextest/main.c | 18 +++++ + src/tests/gssapi/Makefile.in | 49 ++++++------ + src/tests/gssapi/common.c | 25 ++++-- + src/tests/gssapi/common.h | 9 +++ + src/tests/gssapi/deps | 4 + + src/tests/gssapi/t_bindings.c | 111 +++++++++++++++++++++++++++ + src/tests/gssapi/t_bindings.py | 43 +++++++++++ + src/tests/gssapi/t_negoex.py | 7 ++ + 8 files changed, 237 insertions(+), 29 deletions(-) + create mode 100644 src/tests/gssapi/t_bindings.c + create mode 100644 src/tests/gssapi/t_bindings.py + +diff --git a/src/plugins/gssapi/negoextest/main.c b/src/plugins/gssapi/negoextest/main.c +index 6c340f41b..72fc5273a 100644 +--- a/src/plugins/gssapi/negoextest/main.c ++++ b/src/plugins/gssapi/negoextest/main.c +@@ -57,6 +57,15 @@ gss_init_sec_context(OM_uint32 *minor_status, + const char *envstr; + uint8_t hops, mech_last_octet; + ++ envstr = getenv("GSS_INIT_BINDING"); ++ if (envstr != NULL) { ++ assert(strlen(envstr) > 0); ++ assert(input_chan_bindings != GSS_C_NO_CHANNEL_BINDINGS); ++ assert(strlen(envstr) == input_chan_bindings->application_data.length); ++ assert(strcmp((char *)input_chan_bindings->application_data.value, ++ envstr) == 0); ++ } ++ + if (input_token == GSS_C_NO_BUFFER || input_token->length == 0) { + envstr = getenv("HOPS"); + hops = (envstr != NULL) ? atoi(envstr) : 1; +@@ -112,6 +121,15 @@ gss_accept_sec_context(OM_uint32 *minor_status, gss_ctx_id_t *context_handle, + uint8_t hops, mech_last_octet; + const char *envstr; + ++ envstr = getenv("GSS_ACCEPT_BINDING"); ++ if (envstr != NULL) { ++ assert(strlen(envstr) > 0); ++ assert(input_chan_bindings != GSS_C_NO_CHANNEL_BINDINGS); ++ assert(strlen(envstr) == input_chan_bindings->application_data.length); ++ assert(strcmp((char *)input_chan_bindings->application_data.value, ++ envstr) == 0); ++ } ++ + /* + * The unwrapped token sits at the end and is just one byte giving the + * remaining number of hops. The final octet of the mech encoding should +diff --git a/src/tests/gssapi/Makefile.in b/src/tests/gssapi/Makefile.in +index 5cc1e0f58..68c132b79 100644 +--- a/src/tests/gssapi/Makefile.in ++++ b/src/tests/gssapi/Makefile.in +@@ -9,33 +9,33 @@ LOCALINCLUDES = -I$(srcdir)/../../lib/gssapi/mechglue \ + -I../../lib/gssapi/generic + + SRCS= $(srcdir)/ccinit.c $(srcdir)/ccrefresh.c $(srcdir)/common.c \ +- $(srcdir)/t_accname.c $(srcdir)/t_add_cred.c $(srcdir)/t_ccselect.c \ +- $(srcdir)/t_ciflags.c $(srcdir)/t_context.c $(srcdir)/t_credstore.c \ +- $(srcdir)/t_enctypes.c $(srcdir)/t_err.c $(srcdir)/t_export_cred.c \ +- $(srcdir)/t_export_name.c $(srcdir)/t_gssexts.c \ +- $(srcdir)/t_imp_cred.c $(srcdir)/t_imp_name.c $(srcdir)/t_invalid.c \ +- $(srcdir)/t_inq_cred.c $(srcdir)/t_inq_ctx.c \ ++ $(srcdir)/t_accname.c $(srcdir)/t_add_cred.c $(srcdir)/t_bindings.c \ ++ $(srcdir)/t_ccselect.c $(srcdir)/t_ciflags.c $(srcdir)/t_context.c \ ++ $(srcdir)/t_credstore.c $(srcdir)/t_enctypes.c $(srcdir)/t_err.c \ ++ $(srcdir)/t_export_cred.c $(srcdir)/t_export_name.c \ ++ $(srcdir)/t_gssexts.c $(srcdir)/t_imp_cred.c $(srcdir)/t_imp_name.c \ ++ $(srcdir)/t_invalid.c $(srcdir)/t_inq_cred.c $(srcdir)/t_inq_ctx.c \ + $(srcdir)/t_inq_mechs_name.c $(srcdir)/t_iov.c \ + $(srcdir)/t_lifetime.c $(srcdir)/t_namingexts.c $(srcdir)/t_oid.c \ + $(srcdir)/t_pcontok.c $(srcdir)/t_prf.c $(srcdir)/t_s4u.c \ + $(srcdir)/t_s4u2proxy_krb5.c $(srcdir)/t_saslname.c \ + $(srcdir)/t_spnego.c $(srcdir)/t_srcattrs.c + +-OBJS= ccinit.o ccrefresh.o common.o t_accname.o t_add_cred.o t_ccselect.o \ +- t_ciflags.o t_context.o t_credstore.o t_enctypes.o t_err.o \ +- t_export_cred.o t_export_name.o t_gssexts.o t_imp_cred.o t_imp_name.o \ +- t_invalid.o t_inq_cred.o t_inq_ctx.o t_inq_mechs_name.o t_iov.o \ +- t_lifetime.o t_namingexts.o t_oid.o t_pcontok.o t_prf.o t_s4u.o \ +- t_s4u2proxy_krb5.o t_saslname.o t_spnego.o t_srcattrs.o ++OBJS= ccinit.o ccrefresh.o common.o t_accname.o t_add_cred.o t_bindings.o \ ++ t_ccselect.o t_ciflags.o t_context.o t_credstore.o t_enctypes.o \ ++ t_err.o t_export_cred.o t_export_name.o t_gssexts.o t_imp_cred.o \ ++ t_imp_name.o t_invalid.o t_inq_cred.o t_inq_ctx.o t_inq_mechs_name.o \ ++ t_iov.o t_lifetime.o t_namingexts.o t_oid.o t_pcontok.o t_prf.o \ ++ t_s4u.o t_s4u2proxy_krb5.o t_saslname.o t_spnego.o t_srcattrs.o + + COMMON_DEPS= common.o $(GSS_DEPLIBS) $(KRB5_BASE_DEPLIBS) + COMMON_LIBS= common.o $(GSS_LIBS) $(KRB5_BASE_LIBS) + +-all: ccinit ccrefresh t_accname t_add_cred t_ccselect t_ciflags t_context \ +- t_credstore t_enctypes t_err t_export_cred t_export_name t_gssexts \ +- t_imp_cred t_imp_name t_invalid t_inq_cred t_inq_ctx t_inq_mechs_name \ +- t_iov t_lifetime t_namingexts t_oid t_pcontok t_prf t_s4u \ +- t_s4u2proxy_krb5 t_saslname t_spnego t_srcattrs ++all: ccinit ccrefresh t_accname t_add_cred t_bindings t_ccselect t_ciflags \ ++ t_context t_credstore t_enctypes t_err t_export_cred t_export_name \ ++ t_gssexts t_imp_cred t_imp_name t_invalid t_inq_cred t_inq_ctx \ ++ t_inq_mechs_name t_iov t_lifetime t_namingexts t_oid t_pcontok t_prf \ ++ t_s4u t_s4u2proxy_krb5 t_saslname t_spnego t_srcattrs + + check-unix: t_oid + $(RUN_TEST) ./t_invalid +@@ -43,11 +43,12 @@ check-unix: t_oid + $(RUN_TEST) ./t_prf + $(RUN_TEST) ./t_imp_name + +-check-pytests: ccinit ccrefresh t_accname t_add_cred t_ccselect t_ciflags \ +- t_context t_credstore t_enctypes t_err t_export_cred t_export_name \ +- t_imp_cred t_inq_cred t_inq_ctx t_inq_mechs_name t_iov t_lifetime \ +- t_pcontok t_s4u t_s4u2proxy_krb5 t_spnego t_srcattrs ++check-pytests: ccinit ccrefresh t_accname t_add_cred t_bindings t_ccselect \ ++ t_ciflags t_context t_credstore t_enctypes t_err t_export_cred \ ++ t_export_name t_imp_cred t_inq_cred t_inq_ctx t_inq_mechs_name t_iov \ ++ t_lifetime t_pcontok t_s4u t_s4u2proxy_krb5 t_spnego t_srcattrs + $(RUNPYTEST) $(srcdir)/t_gssapi.py $(PYTESTFLAGS) ++ $(RUNPYTEST) $(srcdir)/t_bindings.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_ccselect.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_client_keytab.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_enctypes.py $(PYTESTFLAGS) +@@ -64,6 +65,8 @@ t_accname: t_accname.o $(COMMON_DEPS) + $(CC_LINK) -o $@ t_accname.o $(COMMON_LIBS) + t_add_cred: t_add_cred.o $(COMMON_DEPS) + $(CC_LINK) -o $@ t_add_cred.o $(COMMON_LIBS) ++t_bindings: t_bindings.o $(COMMON_DEPS) ++ $(CC_LINK) -o $@ t_bindings.o $(COMMON_LIBS) + t_ccselect: t_ccselect.o $(COMMON_DEPS) + $(CC_LINK) -o $@ t_ccselect.o $(COMMON_LIBS) + t_ciflags: t_ciflags.o $(COMMON_DEPS) +@@ -118,8 +121,8 @@ t_srcattrs: t_srcattrs.o $(COMMON_DEPS) + $(CC_LINK) -o $@ t_srcattrs.o $(COMMON_LIBS) + + clean: +- $(RM) ccinit ccrefresh t_accname t_add_cred t_ccselect t_ciflags +- $(RM) t_context t_credstore t_enctypes t_err t_export_cred ++ $(RM) ccinit ccrefresh t_accname t_add_cred t_bindings t_ccselect ++ $(RM) t_ciflags t_context t_credstore t_enctypes t_err t_export_cred + $(RM) t_export_name t_gssexts t_imp_cred t_imp_name t_invalid + $(RM) t_inq_cred t_inq_ctx t_inq_mechs_name t_iov t_lifetime + $(RM) t_namingexts t_oid t_pcontok t_prf t_s4u t_s4u2proxy_krb5 +diff --git a/src/tests/gssapi/common.c b/src/tests/gssapi/common.c +index 83e9d9bb8..7ba72f7b2 100644 +--- a/src/tests/gssapi/common.c ++++ b/src/tests/gssapi/common.c +@@ -115,6 +115,20 @@ establish_contexts(gss_OID imech, gss_cred_id_t icred, gss_cred_id_t acred, + gss_name_t tname, OM_uint32 flags, gss_ctx_id_t *ictx, + gss_ctx_id_t *actx, gss_name_t *src_name, gss_OID *amech, + gss_cred_id_t *deleg_cred) ++{ ++ return establish_contexts_ex(imech, icred, acred, tname, flags, ictx, actx, ++ GSS_C_NO_CHANNEL_BINDINGS, ++ GSS_C_NO_CHANNEL_BINDINGS, NULL, src_name, ++ amech, deleg_cred); ++} ++ ++void ++establish_contexts_ex(gss_OID imech, gss_cred_id_t icred, gss_cred_id_t acred, ++ gss_name_t tname, OM_uint32 flags, gss_ctx_id_t *ictx, ++ gss_ctx_id_t *actx, gss_channel_bindings_t icb, ++ gss_channel_bindings_t acb, OM_uint32 *aret_flags, ++ gss_name_t *src_name, gss_OID *amech, ++ gss_cred_id_t *deleg_cred) + { + OM_uint32 minor, imaj, amaj; + gss_buffer_desc itok, atok; +@@ -126,17 +140,16 @@ establish_contexts(gss_OID imech, gss_cred_id_t icred, gss_cred_id_t acred, + for (;;) { + (void)gss_release_buffer(&minor, &itok); + imaj = gss_init_sec_context(&minor, icred, ictx, tname, imech, flags, +- GSS_C_INDEFINITE, +- GSS_C_NO_CHANNEL_BINDINGS, &atok, NULL, +- &itok, NULL, NULL); ++ GSS_C_INDEFINITE, icb, &atok, NULL, &itok, ++ NULL, NULL); + check_gsserr("gss_init_sec_context", imaj, minor); + if (amaj == GSS_S_COMPLETE) + break; + + (void)gss_release_buffer(&minor, &atok); +- amaj = gss_accept_sec_context(&minor, actx, acred, &itok, +- GSS_C_NO_CHANNEL_BINDINGS, src_name, +- amech, &atok, NULL, NULL, deleg_cred); ++ amaj = gss_accept_sec_context(&minor, actx, acred, &itok, acb, ++ src_name, amech, &atok, aret_flags, NULL, ++ deleg_cred); + check_gsserr("gss_accept_sec_context", amaj, minor); + (void)gss_release_buffer(&minor, &itok); + if (imaj == GSS_S_COMPLETE) +diff --git a/src/tests/gssapi/common.h b/src/tests/gssapi/common.h +index ae11b51d4..a5c8f87e6 100644 +--- a/src/tests/gssapi/common.h ++++ b/src/tests/gssapi/common.h +@@ -62,6 +62,15 @@ void establish_contexts(gss_OID imech, gss_cred_id_t icred, + gss_name_t *src_name, gss_OID *amech, + gss_cred_id_t *deleg_cred); + ++/* Establish contexts with channel bindings. */ ++void establish_contexts_ex(gss_OID imech, gss_cred_id_t icred, ++ gss_cred_id_t acred, gss_name_t tname, ++ OM_uint32 flags, gss_ctx_id_t *ictx, ++ gss_ctx_id_t *actx, gss_channel_bindings_t icb, ++ gss_channel_bindings_t acb, OM_uint32 *aret_flags, ++ gss_name_t *src_name, gss_OID *amech, ++ gss_cred_id_t *deleg_cred); ++ + /* Export *cred to a token, then release *cred and replace it by re-importing + * the token. */ + void export_import_cred(gss_cred_id_t *cred); +diff --git a/src/tests/gssapi/deps b/src/tests/gssapi/deps +index acd0e96f8..73e4d9a74 100644 +--- a/src/tests/gssapi/deps ++++ b/src/tests/gssapi/deps +@@ -33,6 +33,10 @@ $(OUTPRE)t_add_cred.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ + $(BUILDTOP)/include/gssapi/gssapi_ext.h $(BUILDTOP)/include/gssapi/gssapi_krb5.h \ + $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h \ + common.h t_add_cred.c ++$(OUTPRE)t_bindings.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ ++ $(BUILDTOP)/include/gssapi/gssapi_ext.h $(BUILDTOP)/include/gssapi/gssapi_krb5.h \ ++ $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h \ ++ common.h t_bindings.c + $(OUTPRE)t_ccselect.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ + $(BUILDTOP)/include/gssapi/gssapi_ext.h $(BUILDTOP)/include/gssapi/gssapi_krb5.h \ + $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h \ +diff --git a/src/tests/gssapi/t_bindings.c b/src/tests/gssapi/t_bindings.c +new file mode 100644 +index 000000000..e8906715b +--- /dev/null ++++ b/src/tests/gssapi/t_bindings.c +@@ -0,0 +1,111 @@ ++/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ ++/* ++ * Copyright (C) 2020 by Red Hat, Inc. ++ * All rights reserved. ++ * ++ * Redistribution and use in source and binary forms, with or without ++ * modification, are permitted provided that the following conditions ++ * are met: ++ * ++ * * Redistributions of source code must retain the above copyright ++ * notice, this list of conditions and the following disclaimer. ++ * ++ * * Redistributions in binary form must reproduce the above copyright ++ * notice, this list of conditions and the following disclaimer in ++ * the documentation and/or other materials provided with the ++ * distribution. ++ * ++ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ++ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT ++ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS ++ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ++ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, ++ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES ++ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) ++ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, ++ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ++ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED ++ * OF THE POSSIBILITY OF SUCH DAMAGE. ++ */ ++ ++#include ++#include ++#include ++ ++#include "common.h" ++ ++/* ++ * Establish contexts (without and with GSS_C_DCE_STYLE) with the default ++ * initiator name, a specified principal name as target name, initiator ++ * bindings, and acceptor bindings. If any call is unsuccessful, display an ++ * error message. Output "yes" or "no" to indicate whether the contexts were ++ * reported as channel-bound on the acceptor. Exit with status 0 if all ++ * operations are successful, or 1 if not. ++ * ++ * Usage: ./t_bindings [-s] targetname icb acb ++ * ++ * An icb or abc value of "-" will not specify channel bindings. ++ */ ++ ++int ++main(int argc, char *argv[]) ++{ ++ OM_uint32 minor, flags1, flags2; ++ gss_name_t target_name; ++ gss_ctx_id_t ictx, actx; ++ struct gss_channel_bindings_struct icb_data = {0}, acb_data = {0}; ++ gss_channel_bindings_t icb = GSS_C_NO_CHANNEL_BINDINGS; ++ gss_channel_bindings_t acb = GSS_C_NO_CHANNEL_BINDINGS; ++ gss_OID_desc *mech; ++ ++ argv++; ++ argc--; ++ if (*argv != NULL && strcmp(*argv, "-s") == 0) { ++ mech = &mech_spnego; ++ argv++; ++ argc--; ++ } else { ++ mech = &mech_krb5; ++ } ++ ++ if (argc != 3) { ++ fprintf(stderr, "Usage: t_bindings [-s] targetname icb acb\n"); ++ return 1; ++ } ++ ++ target_name = import_name(argv[0]); ++ ++ if (strcmp(argv[1], "-") != 0) { ++ icb_data.application_data.length = strlen(argv[1]); ++ icb_data.application_data.value = argv[1]; ++ icb = &icb_data; ++ } ++ ++ if (strcmp(argv[2], "-") != 0) { ++ acb_data.application_data.length = strlen(argv[2]); ++ acb_data.application_data.value = argv[2]; ++ acb = &acb_data; ++ } ++ ++ establish_contexts_ex(mech, GSS_C_NO_CREDENTIAL, GSS_C_NO_CREDENTIAL, ++ target_name, 0, &ictx, &actx, icb, acb, &flags1, ++ NULL, NULL, NULL); ++ ++ /* Try again with GSS_C_DCE_STYLE */ ++ (void)gss_delete_sec_context(&minor, &ictx, NULL); ++ (void)gss_delete_sec_context(&minor, &actx, NULL); ++ ++ establish_contexts_ex(mech, GSS_C_NO_CREDENTIAL, GSS_C_NO_CREDENTIAL, ++ target_name, GSS_C_DCE_STYLE, &ictx, &actx, icb, acb, ++ &flags2, NULL, NULL, NULL); ++ assert((flags1 & GSS_C_CHANNEL_BOUND_FLAG) == ++ (flags2 & GSS_C_CHANNEL_BOUND_FLAG)); ++ printf("%s\n", (flags1 & GSS_C_CHANNEL_BOUND_FLAG) ? "yes" : "no"); ++ ++ (void)gss_delete_sec_context(&minor, &ictx, NULL); ++ (void)gss_delete_sec_context(&minor, &actx, NULL); ++ (void)gss_release_name(&minor, &target_name); ++ ++ return 0; ++} +diff --git a/src/tests/gssapi/t_bindings.py b/src/tests/gssapi/t_bindings.py +new file mode 100644 +index 000000000..f377977b6 +--- /dev/null ++++ b/src/tests/gssapi/t_bindings.py +@@ -0,0 +1,43 @@ ++from k5test import * ++ ++realm = K5Realm() ++server = 'p:' + realm.host_princ ++ ++mark('krb5 channel bindings') ++realm.run(['./t_bindings', server, '-', '-'], expected_msg='no') ++realm.run(['./t_bindings', server, 'a', '-'], expected_msg='no') ++realm.run(['./t_bindings', server, 'a', 'a'], expected_msg='yes') ++realm.run(['./t_bindings', server, '-', 'a'], expected_msg='no') ++realm.run(['./t_bindings', server, 'a', 'x'], ++ expected_code=1, expected_msg='Incorrect channel bindings') ++ ++mark('SPNEGO channel bindings') ++realm.run(['./t_bindings', '-s', server, '-', '-'], expected_msg='no') ++realm.run(['./t_bindings', '-s', server, 'a', '-'], expected_msg='no') ++realm.run(['./t_bindings', '-s', server, 'a', 'a'], expected_msg='yes') ++realm.run(['./t_bindings', '-s', server, '-', 'a'], expected_msg='no') ++realm.run(['./t_bindings', '-s', server, 'a', 'x'], ++ expected_code=1, expected_msg='Incorrect channel bindings') ++ ++client_aware_conf = {'libdefaults': {'client_aware_channel_bindings': 'true'}} ++e = realm.special_env('cb_aware', False, krb5_conf=client_aware_conf) ++ ++mark('krb5 client_aware_channel_bindings') ++realm.run(['./t_bindings', server, '-', '-'], env=e, expected_msg='no') ++realm.run(['./t_bindings', server, 'a', '-'], env=e, expected_msg='no') ++realm.run(['./t_bindings', server, 'a', 'a'], env=e, expected_msg='yes') ++realm.run(['./t_bindings', server, '-', 'a'], env=e, ++ expected_code=1, expected_msg='Incorrect channel bindings') ++realm.run(['./t_bindings', server, 'a', 'x'], env=e, ++ expected_code=1, expected_msg='Incorrect channel bindings') ++ ++mark('SPNEGO client_aware_channel_bindings') ++realm.run(['./t_bindings', '-s', server, '-', '-'], env=e, expected_msg='no') ++realm.run(['./t_bindings', '-s', server, 'a', '-'], env=e, expected_msg='no') ++realm.run(['./t_bindings', '-s', server, 'a', 'a'], env=e, expected_msg='yes') ++realm.run(['./t_bindings', '-s', server, '-', 'a'], env=e, ++ expected_code=1, expected_msg='Incorrect channel bindings') ++realm.run(['./t_bindings', '-s', server, 'a', 'x'], env=e, ++ expected_code=1, expected_msg='Incorrect channel bindings') ++ ++success('channel bindings tests') +diff --git a/src/tests/gssapi/t_negoex.py b/src/tests/gssapi/t_negoex.py +index 88470d2fa..a218899c4 100644 +--- a/src/tests/gssapi/t_negoex.py ++++ b/src/tests/gssapi/t_negoex.py +@@ -139,4 +139,11 @@ msgs = ('sending [3]AP_REQUEST', 'sending [7]CHALLENGE', 'sending [8]VERIFY', + 'sending [11]CHALLENGE', 'sending [12]VERIFY', 'sending [13]VERIFY') + test({'HOPS': '4', 'KEY': 'accept-always'}, expected_trace=()) + ++mark('channel bindings') ++e = realm.env.copy() ++e.update({'HOPS': '1', 'GSS_INIT_BINDING': 'a', 'GSS_ACCEPT_BINDING': 'b'}) ++# The test mech will verify that the bindings are communicated to the ++# mech, but does not set the channel-bound flag. ++realm.run(['./t_bindings', '-s', 'h:host', 'a', 'b'], env=e, expected_msg='no') ++ + success('NegoEx tests') diff --git a/Add-client_aware_channel_bindings-option.patch b/Add-client_aware_channel_bindings-option.patch new file mode 100644 index 0000000..012ce8d --- /dev/null +++ b/Add-client_aware_channel_bindings-option.patch @@ -0,0 +1,264 @@ +From 2a08fe3d2d1972df4ffe37d4bb64b161889ff988 Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Tue, 10 Mar 2020 13:13:17 +0100 +Subject: [PATCH] Add client_aware_channel_bindings option + +Add client support for KERB_AP_OPTIONS_CBT in the form of a profile +option "client_aware_gss_bindings". Adjust the make_etype_list() +helper so that enctype negotiation and AP_OPTIONS can be included in +the same IF-RELEVANT wrapper. + +[ghudson@mit.edu: refactored; edited documentation; wrote commit +message] + +ticket: 8900 +(cherry picked from commit 225e6ef7f021cd1a8ef2a054af0ca58b7288fd81) +--- + doc/admin/conf_files/krb5_conf.rst | 6 + + src/include/k5-int.h | 1 + + src/lib/krb5/krb/mk_req_ext.c | 177 +++++++++++++++-------------- + 3 files changed, 98 insertions(+), 86 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index a7e7a29d1..7f2879640 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -382,6 +382,12 @@ The libdefaults section may contain any of the following relations: + credentials will fail if the client machine does not have a + keytab. The default value is false. + ++**client_aware_channel_bindings** ++ If this flag is true, then all application protocol authentication ++ requests will be flagged to indicate that the application supports ++ channel bindings when operating over a secure channel. The ++ default value is false. ++ + .. _realms: + + [realms] +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 0d9af3d95..eb18a4cd6 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -299,6 +299,7 @@ typedef unsigned char u_char; + #define KRB5_CONF_V4_INSTANCE_CONVERT "v4_instance_convert" + #define KRB5_CONF_V4_REALM "v4_realm" + #define KRB5_CONF_VERIFY_AP_REQ_NOFAIL "verify_ap_req_nofail" ++#define KRB5_CONF_CLIENT_AWARE_GSS_BINDINGS "client_aware_channel_bindings" + + /* Cache configuration variables */ + #define KRB5_CC_CONF_FAST_AVAIL "fast_avail" +diff --git a/src/lib/krb5/krb/mk_req_ext.c b/src/lib/krb5/krb/mk_req_ext.c +index 9fc6a0e52..08504860c 100644 +--- a/src/lib/krb5/krb/mk_req_ext.c ++++ b/src/lib/krb5/krb/mk_req_ext.c +@@ -68,10 +68,9 @@ + */ + + static krb5_error_code +-make_etype_list(krb5_context context, +- krb5_enctype *desired_etypes, +- krb5_enctype tkt_enctype, +- krb5_authdata ***authdata); ++make_ap_authdata(krb5_context context, krb5_enctype *desired_enctypes, ++ krb5_enctype tkt_enctype, krb5_boolean client_aware_cb, ++ krb5_authdata ***authdata_out); + + static krb5_error_code + generate_authenticator(krb5_context, +@@ -263,7 +262,8 @@ generate_authenticator(krb5_context context, krb5_authenticator *authent, + krb5_enctype tkt_enctype) + { + krb5_error_code retval; +- krb5_authdata **ext_authdata = NULL; ++ krb5_authdata **ext_authdata = NULL, **ap_authdata, **combined; ++ int client_aware_cb; + + authent->client = client; + authent->checksum = cksum; +@@ -297,99 +297,104 @@ generate_authenticator(krb5_context context, krb5_authenticator *authent, + krb5_free_authdata(context, ext_authdata); + } + +- /* Only send EtypeList if we prefer another enctype to tkt_enctype */ +- if (desired_etypes != NULL && desired_etypes[0] != tkt_enctype) { +- TRACE_MK_REQ_ETYPES(context, desired_etypes); +- retval = make_etype_list(context, desired_etypes, tkt_enctype, +- &authent->authorization_data); ++ retval = profile_get_boolean(context->profile, KRB5_CONF_LIBDEFAULTS, ++ KRB5_CONF_CLIENT_AWARE_GSS_BINDINGS, NULL, ++ FALSE, &client_aware_cb); ++ if (retval) ++ return retval; ++ ++ /* Add etype negotiation or channel-binding awareness authdata to the ++ * front, if appropriate. */ ++ retval = make_ap_authdata(context, desired_etypes, tkt_enctype, ++ client_aware_cb, &ap_authdata); ++ if (retval) ++ return retval; ++ if (ap_authdata != NULL) { ++ retval = krb5_merge_authdata(context, ap_authdata, ++ authent->authorization_data, &combined); ++ krb5_free_authdata(context, ap_authdata); + if (retval) + return retval; ++ krb5_free_authdata(context, authent->authorization_data); ++ authent->authorization_data = combined; + } + + return(krb5_us_timeofday(context, &authent->ctime, &authent->cusec)); + } + +-/* RFC 4537 */ ++/* Set *out to a DER-encoded RFC 4537 etype list, or to NULL if no etype list ++ * should be sent. */ + static krb5_error_code +-make_etype_list(krb5_context context, +- krb5_enctype *desired_etypes, +- krb5_enctype tkt_enctype, +- krb5_authdata ***authdata) ++make_etype_list(krb5_context context, krb5_enctype *desired_enctypes, ++ krb5_enctype tkt_enctype, krb5_data **out) + { +- krb5_error_code code; +- krb5_etype_list etypes; +- krb5_data *enc_etype_list; +- krb5_data *ad_if_relevant; +- krb5_authdata *etype_adata[2], etype_adatum, **adata; +- int i; ++ krb5_etype_list etlist; ++ int count; + +- etypes.etypes = desired_etypes; ++ *out = NULL; + +- for (etypes.length = 0; +- etypes.etypes[etypes.length] != ENCTYPE_NULL; +- etypes.length++) +- { +- /* +- * RFC 4537: +- * +- * If the enctype of the ticket session key is included in the enctype +- * list sent by the client, it SHOULD be the last on the list; +- */ +- if (etypes.length && etypes.etypes[etypes.length - 1] == tkt_enctype) ++ /* Only send a list if we prefer another enctype to tkt_enctype. */ ++ if (desired_enctypes == NULL || desired_enctypes[0] == tkt_enctype) ++ return 0; ++ ++ /* Count elements of desired_etypes, stopping at tkt_enctypes if present. ++ * (Per RFC 4537, it must be the last option if it is included.) */ ++ for (count = 0; desired_enctypes[count] != ENCTYPE_NULL; count++) { ++ if (count > 0 && desired_enctypes[count - 1] == tkt_enctype) + break; + } + +- code = encode_krb5_etype_list(&etypes, &enc_etype_list); +- if (code) { +- return code; +- } +- +- etype_adatum.magic = KV5M_AUTHDATA; +- etype_adatum.ad_type = KRB5_AUTHDATA_ETYPE_NEGOTIATION; +- etype_adatum.length = enc_etype_list->length; +- etype_adatum.contents = (krb5_octet *)enc_etype_list->data; +- +- etype_adata[0] = &etype_adatum; +- etype_adata[1] = NULL; +- +- /* Wrap in AD-IF-RELEVANT container */ +- code = encode_krb5_authdata(etype_adata, &ad_if_relevant); +- if (code) { +- krb5_free_data(context, enc_etype_list); +- return code; +- } +- +- krb5_free_data(context, enc_etype_list); +- +- adata = *authdata; +- if (adata == NULL) { +- adata = (krb5_authdata **)calloc(2, sizeof(krb5_authdata *)); +- i = 0; +- } else { +- for (i = 0; adata[i] != NULL; i++) +- ; +- +- adata = (krb5_authdata **)realloc(*authdata, +- (i + 2) * sizeof(krb5_authdata *)); +- } +- if (adata == NULL) { +- krb5_free_data(context, ad_if_relevant); +- return ENOMEM; +- } +- *authdata = adata; +- +- adata[i] = (krb5_authdata *)malloc(sizeof(krb5_authdata)); +- if (adata[i] == NULL) { +- krb5_free_data(context, ad_if_relevant); +- return ENOMEM; +- } +- adata[i]->magic = KV5M_AUTHDATA; +- adata[i]->ad_type = KRB5_AUTHDATA_IF_RELEVANT; +- adata[i]->length = ad_if_relevant->length; +- adata[i]->contents = (krb5_octet *)ad_if_relevant->data; +- free(ad_if_relevant); /* contents owned by adata[i] */ +- +- adata[i + 1] = NULL; +- +- return 0; ++ etlist.etypes = desired_enctypes; ++ etlist.length = count; ++ return encode_krb5_etype_list(&etlist, out); ++} ++ ++/* Set *authdata_out to appropriate authenticator authdata for the request, ++ * encoded in a single AD_IF_RELEVANT element. */ ++static krb5_error_code ++make_ap_authdata(krb5_context context, krb5_enctype *desired_enctypes, ++ krb5_enctype tkt_enctype, krb5_boolean client_aware_cb, ++ krb5_authdata ***authdata_out) ++{ ++ krb5_error_code ret; ++ krb5_authdata etypes_ad, flags_ad, *list[3]; ++ krb5_data *der_etypes = NULL; ++ size_t count = 0; ++ uint8_t flagbuf[4]; ++ const uint32_t KERB_AP_OPTIONS_CBT = 0x4000; ++ ++ *authdata_out = NULL; ++ ++ /* Include an ETYPE_NEGOTIATION element if appropriate. */ ++ ret = make_etype_list(context, desired_enctypes, tkt_enctype, &der_etypes); ++ if (ret) ++ goto cleanup; ++ if (der_etypes != NULL) { ++ etypes_ad.magic = KV5M_AUTHDATA; ++ etypes_ad.ad_type = KRB5_AUTHDATA_ETYPE_NEGOTIATION; ++ etypes_ad.length = der_etypes->length; ++ etypes_ad.contents = (uint8_t *)der_etypes->data; ++ list[count++] = &etypes_ad; ++ } ++ ++ /* Include an AP_OPTIONS element if the CBT flag is configured. */ ++ if (client_aware_cb != 0) { ++ store_32_le(KERB_AP_OPTIONS_CBT, flagbuf); ++ flags_ad.magic = KV5M_AUTHDATA; ++ flags_ad.ad_type = KRB5_AUTHDATA_AP_OPTIONS; ++ flags_ad.length = 4; ++ flags_ad.contents = flagbuf; ++ list[count++] = &flags_ad; ++ } ++ ++ if (count > 0) { ++ list[count] = NULL; ++ ret = krb5_encode_authdata_container(context, ++ KRB5_AUTHDATA_IF_RELEVANT, ++ list, authdata_out); ++ } ++ ++cleanup: ++ krb5_free_data(context, der_etypes); ++ return ret; + } diff --git a/Default-dns_canonicalize_hostname-to-fallback.patch b/Default-dns_canonicalize_hostname-to-fallback.patch index b252354..ef80329 100644 --- a/Default-dns_canonicalize_hostname-to-fallback.patch +++ b/Default-dns_canonicalize_hostname-to-fallback.patch @@ -1,4 +1,4 @@ -From d003b4aa8dce14967725d6607c54ceb884b3647c Mon Sep 17 00:00:00 2001 +From 07179e38e5ee72e82ebc77a1c8d73e34905268b7 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 27 May 2020 18:48:35 -0400 Subject: [PATCH] Default dns_canonicalize_hostname to "fallback" diff --git a/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch b/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch new file mode 100644 index 0000000..649caa4 --- /dev/null +++ b/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch @@ -0,0 +1,91 @@ +From 3ea1d6296ced3a998e79356f9be212e4c5e6a5d5 Mon Sep 17 00:00:00 2001 +From: Alexander Scheel +Date: Wed, 5 Jul 2017 11:38:30 -0400 +Subject: [PATCH] Implement GSS_C_CHANNEL_BOUND_FLAG + +Define a new channel-bound GSS return flag, and set it in the krb5 +mech if the initiator sent channel bindings matching the acceptor's. +Do not error out if the acceptor specifies channel bindings and the +initiator does not send them. + +[ghudson@mit.edu: simplified code changes; fleshed out commit message] + +[iboukris: cherry-picked from another PR and reduced in scope] + +ticket: 8899 (new) +(cherry picked from commit 429a31146083fac21958631c2af572b08ec91022) +--- + src/lib/gssapi/generic/gssapi_ext.h | 2 ++ + src/lib/gssapi/krb5/accept_sec_context.c | 18 +++++++++++++----- + 2 files changed, 15 insertions(+), 5 deletions(-) + +diff --git a/src/lib/gssapi/generic/gssapi_ext.h b/src/lib/gssapi/generic/gssapi_ext.h +index 218456e44..c675e8ebb 100644 +--- a/src/lib/gssapi/generic/gssapi_ext.h ++++ b/src/lib/gssapi/generic/gssapi_ext.h +@@ -595,6 +595,8 @@ gss_store_cred_into( + * attribute (along with any applicable RFC 5587 attributes). + */ + ++#define GSS_C_CHANNEL_BOUND_FLAG 2048 /* 0x00000800 */ ++ + OM_uint32 KRB5_CALLCONV + gssspi_query_meta_data( + OM_uint32 *minor_status, +diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c +index 70dd7fc0c..9d3e2f4fe 100644 +--- a/src/lib/gssapi/krb5/accept_sec_context.c ++++ b/src/lib/gssapi/krb5/accept_sec_context.c +@@ -427,6 +427,9 @@ kg_process_extension(krb5_context context, + GSS_C_SEQUENCE_FLAG | GSS_C_DCE_STYLE | \ + GSS_C_IDENTIFY_FLAG | GSS_C_EXTENDED_ERROR_FLAG) + ++/* A zero-value channel binding, for comparison */ ++static const uint8_t null_cb[CB_MD5_LEN]; ++ + /* + * The krb5 GSS mech appropriates the authenticator checksum field from RFC + * 4120 to store structured data instead of a checksum, indicated with checksum +@@ -435,9 +438,10 @@ kg_process_extension(krb5_context context, + * + * Interpret the checksum. Read delegated creds into *deleg_out if it is not + * NULL. Set *flags_out to the allowed subset of token flags, plus +- * GSS_C_DELEG_FLAG if a delegated credential was present. Process any +- * extensions found using exts. On error, set *code_out to a krb5_error code +- * for use as a minor status value. ++ * GSS_C_DELEG_FLAG if a delegated credential was present and ++ * GSS_C_CHANNEL_BOUND_FLAG if matching channel bindings are present. Process ++ * any extensions found using exts. On error, set *code_out to a krb5_error ++ * code for use as a minor status value. + */ + static OM_uint32 + process_checksum(OM_uint32 *minor_status, krb5_context context, +@@ -450,7 +454,7 @@ process_checksum(OM_uint32 *minor_status, krb5_context context, + krb5_error_code code = 0; + OM_uint32 status, option_id, token_flags; + size_t cb_len, option_len; +- krb5_boolean valid; ++ krb5_boolean valid, token_cb_present = FALSE, cb_match = FALSE; + krb5_key subkey; + krb5_data option, empty = empty_data(); + krb5_checksum cb_cksum; +@@ -516,7 +520,9 @@ process_checksum(OM_uint32 *minor_status, krb5_context context, + goto fail; + } + assert(cb_cksum.length == cb_len); +- if (k5_bcmp(token_cb, cb_cksum.contents, cb_len) != 0) { ++ token_cb_present = (k5_bcmp(token_cb, null_cb, cb_len) != 0); ++ cb_match = (k5_bcmp(token_cb, cb_cksum.contents, cb_len) == 0); ++ if (token_cb_present && !cb_match) { + status = GSS_S_BAD_BINDINGS; + goto fail; + } +@@ -525,6 +531,8 @@ process_checksum(OM_uint32 *minor_status, krb5_context context, + /* Read the token flags and accept some of them as context flags. */ + token_flags = k5_input_get_uint32_le(&in); + *flags_out = token_flags & INITIATOR_FLAGS; ++ if (cb_match) ++ *flags_out |= GSS_C_CHANNEL_BOUND_FLAG; + + /* Read the delegated credential if present. */ + if (in.len >= 4 && (token_flags & GSS_C_DELEG_FLAG)) { diff --git a/Implement-KERB_AP_OPTIONS_CBT-server-side.patch b/Implement-KERB_AP_OPTIONS_CBT-server-side.patch new file mode 100644 index 0000000..41cf5f0 --- /dev/null +++ b/Implement-KERB_AP_OPTIONS_CBT-server-side.patch @@ -0,0 +1,102 @@ +From 6407bf087fe53088d91efd09df736e979cd4e8db Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Mon, 9 Mar 2020 16:04:21 +0100 +Subject: [PATCH] Implement KERB_AP_OPTIONS_CBT (server side) + +Add server support for Microsoft's KERB_AP_OPTIONS_CBT as described in +MS-KILE. If the client includes the AP option in the authenticator +authdata and the server passed channel bindings, require the bindings +to match. + +[ghudson@mit.edu: refactored to put more logic in the helper function; +added a comment; clarified commit message] + +ticket: 8900 (new) +(cherry picked from commit 4f7c77b64a048ca5e3199b26b31493698c777a9c) +--- + src/include/krb5/krb5.hin | 1 + + src/lib/gssapi/krb5/accept_sec_context.c | 45 +++++++++++++++++++++++- + 2 files changed, 45 insertions(+), 1 deletion(-) + +diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin +index f8269fb17..9264bede1 100644 +--- a/src/include/krb5/krb5.hin ++++ b/src/include/krb5/krb5.hin +@@ -1915,6 +1915,7 @@ krb5_verify_checksum(krb5_context context, krb5_cksumtype ctype, + #define KRB5_AUTHDATA_SIGNTICKET 512 /**< formerly 142 in krb5 1.8 */ + #define KRB5_AUTHDATA_FX_ARMOR 71 + #define KRB5_AUTHDATA_AUTH_INDICATOR 97 ++#define KRB5_AUTHDATA_AP_OPTIONS 143 + /** @} */ /* end of KRB5_AUTHDATA group */ + + /* password change constants */ +diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c +index 9d3e2f4fe..175a24c4e 100644 +--- a/src/lib/gssapi/krb5/accept_sec_context.c ++++ b/src/lib/gssapi/krb5/accept_sec_context.c +@@ -430,6 +430,32 @@ kg_process_extension(krb5_context context, + /* A zero-value channel binding, for comparison */ + static const uint8_t null_cb[CB_MD5_LEN]; + ++/* Look for AP_OPTIONS in authdata. If present and the options include ++ * KERB_AP_OPTIONS_CBT, set *cbt_out to true. */ ++static krb5_error_code ++check_cbt(krb5_context context, krb5_authdata **authdata, ++ krb5_boolean *cbt_out) ++{ ++ krb5_error_code code; ++ uint32_t ad_ap_options; ++ const uint32_t KERB_AP_OPTIONS_CBT = 0x4000; ++ ++ *cbt_out = FALSE; ++ ++ code = krb5_find_authdata(context, NULL, authdata, ++ KRB5_AUTHDATA_AP_OPTIONS, &authdata); ++ if (code || authdata == NULL) ++ return code; ++ if (authdata[1] != NULL || authdata[0]->length != 4) ++ return KRB5KRB_AP_ERR_MSG_TYPE; ++ ++ ad_ap_options = load_32_le(authdata[0]->contents); ++ if (ad_ap_options & KERB_AP_OPTIONS_CBT) ++ *cbt_out = TRUE; ++ ++ return 0; ++} ++ + /* + * The krb5 GSS mech appropriates the authenticator checksum field from RFC + * 4120 to store structured data instead of a checksum, indicated with checksum +@@ -454,7 +480,7 @@ process_checksum(OM_uint32 *minor_status, krb5_context context, + krb5_error_code code = 0; + OM_uint32 status, option_id, token_flags; + size_t cb_len, option_len; +- krb5_boolean valid, token_cb_present = FALSE, cb_match = FALSE; ++ krb5_boolean valid, client_cbt, token_cb_present = FALSE, cb_match = FALSE; + krb5_key subkey; + krb5_data option, empty = empty_data(); + krb5_checksum cb_cksum; +@@ -582,6 +608,23 @@ process_checksum(OM_uint32 *minor_status, krb5_context context, + } + } + ++ /* ++ * If the client asserts the KERB_AP_OPTIONS_CBT flag (from MS-KILE) in the ++ * authenticator authdata, and the acceptor passed channel bindings, ++ * require matching channel bindings from the client. The intent is to ++ * prevent an authenticator generated for use outside of a TLS channel from ++ * being used inside of one. ++ */ ++ code = check_cbt(context, authenticator->authorization_data, &client_cbt); ++ if (code) { ++ status = GSS_S_FAILURE; ++ goto fail; ++ } ++ if (client_cbt && acceptor_cb != GSS_C_NO_CHANNEL_BINDINGS && !cb_match) { ++ status = GSS_S_BAD_BINDINGS; ++ goto fail; ++ } ++ + status = GSS_S_COMPLETE; + + fail: diff --git a/Improve-negoex_parse_token-code-hygiene.patch b/Improve-negoex_parse_token-code-hygiene.patch new file mode 100644 index 0000000..f6b42a6 --- /dev/null +++ b/Improve-negoex_parse_token-code-hygiene.patch @@ -0,0 +1,30 @@ +From c726a72c68244129eb08b840b92144acfa776573 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 9 Jun 2020 16:23:37 -0400 +Subject: [PATCH] Improve negoex_parse_token() code hygiene + +If the while loop in negoex_parse_token() runs for zero iterations, +major will be used initialized. Currently this cannot happen, but +only because both of the call sites check for zero-length tokens. +Initialize major for safety. + +[ghudson@mit.edu: rewrote commit message] + +(cherry picked from commit 4f91b6f8fa6fe1de662b3fdac0d59b7758ec642a) +--- + src/lib/gssapi/spnego/negoex_util.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/lib/gssapi/spnego/negoex_util.c b/src/lib/gssapi/spnego/negoex_util.c +index 700368456..99580fd79 100644 +--- a/src/lib/gssapi/spnego/negoex_util.c ++++ b/src/lib/gssapi/spnego/negoex_util.c +@@ -454,7 +454,7 @@ negoex_parse_token(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, + gss_const_buffer_t token, + struct negoex_message **messages_out, size_t *count_out) + { +- OM_uint32 major; ++ OM_uint32 major = GSS_S_COMPLETE; + size_t count = 0; + struct k5input in; + struct negoex_message *messages = NULL, *newptr; diff --git a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch index 0d6b9e9..d0db74b 100644 --- a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch +++ b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch @@ -1,4 +1,4 @@ -From 086de78292b8ae89aba8a72926831124da44205d Mon Sep 17 00:00:00 2001 +From c36e826c70cb5b3bff8bd4371d47884cea30b3f4 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Sat, 6 Jun 2020 11:03:37 +0200 Subject: [PATCH] Omit PA_FOR_USER if we can't compute its checksum diff --git a/Pass-channel-bindings-through-SPNEGO.patch b/Pass-channel-bindings-through-SPNEGO.patch index 0137f0c..5ab5c07 100644 --- a/Pass-channel-bindings-through-SPNEGO.patch +++ b/Pass-channel-bindings-through-SPNEGO.patch @@ -1,4 +1,4 @@ -From dd82ae2d390c4de1b8a7737a918d80d6829366dd Mon Sep 17 00:00:00 2001 +From ee79bd43005245d3e5a2d3ec6d61146945e77717 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 28 Apr 2020 18:15:55 +0200 Subject: [PATCH] Pass channel bindings through SPNEGO diff --git a/Refactor-krb5-GSS-checksum-handling.patch b/Refactor-krb5-GSS-checksum-handling.patch new file mode 100644 index 0000000..392d929 --- /dev/null +++ b/Refactor-krb5-GSS-checksum-handling.patch @@ -0,0 +1,479 @@ +From a34b7c50e62c19f80d39ece6a72017dac781df64 Mon Sep 17 00:00:00 2001 +From: Alexander Scheel +Date: Fri, 30 Jun 2017 16:03:01 -0400 +Subject: [PATCH] Refactor krb5 GSS checksum handling + +Separate out checksum handling from kg_accept_krb5() into a new helper +process_checksum(). + +[ghudson@mit.edu: simplified checksum processing and made it use +k5-input.h instead of TREAD_ macros; moved more flag handling into +helper] + +[iboukris: adjusted helper function arguments, allowing access to the +full authenticator for subsequent changes] + +(cherry picked from commit 64d56233f9816a2a93f6e8d3030c8ed6ce397735) +[rharwood@redhat.com: problem with typo fix commit, I think] +--- + src/lib/gssapi/krb5/accept_sec_context.c | 383 +++++++++++------------ + 1 file changed, 179 insertions(+), 204 deletions(-) + +diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c +index c5bddb1e8..70dd7fc0c 100644 +--- a/src/lib/gssapi/krb5/accept_sec_context.c ++++ b/src/lib/gssapi/krb5/accept_sec_context.c +@@ -98,6 +98,7 @@ + */ + + #include "k5-int.h" ++#include "k5-input.h" + #include "gssapiP_krb5.h" + #ifdef HAVE_MEMORY_H + #include +@@ -413,6 +414,174 @@ kg_process_extension(krb5_context context, + return code; + } + ++/* The length of the MD5 channel bindings in an 0x8003 checksum */ ++#define CB_MD5_LEN 16 ++ ++/* The minimum length of an 0x8003 checksum value (4-byte channel bindings ++ * length, 16-byte channel bindings, 4-byte flags) */ ++#define MIN_8003_LEN (4 + CB_MD5_LEN + 4) ++ ++/* The flags we accept from the initiator's authenticator checksum. */ ++#define INITIATOR_FLAGS (GSS_C_INTEG_FLAG | GSS_C_CONF_FLAG | \ ++ GSS_C_MUTUAL_FLAG | GSS_C_REPLAY_FLAG | \ ++ GSS_C_SEQUENCE_FLAG | GSS_C_DCE_STYLE | \ ++ GSS_C_IDENTIFY_FLAG | GSS_C_EXTENDED_ERROR_FLAG) ++ ++/* ++ * The krb5 GSS mech appropriates the authenticator checksum field from RFC ++ * 4120 to store structured data instead of a checksum, indicated with checksum ++ * type 0x8003 (see RFC 4121 section 4.1.1). Some implementations instead send ++ * no checksum, or a regular checksum over empty data. ++ * ++ * Interpret the checksum. Read delegated creds into *deleg_out if it is not ++ * NULL. Set *flags_out to the allowed subset of token flags, plus ++ * GSS_C_DELEG_FLAG if a delegated credential was present. Process any ++ * extensions found using exts. On error, set *code_out to a krb5_error code ++ * for use as a minor status value. ++ */ ++static OM_uint32 ++process_checksum(OM_uint32 *minor_status, krb5_context context, ++ gss_channel_bindings_t acceptor_cb, ++ krb5_auth_context auth_context, krb5_flags ap_req_options, ++ krb5_authenticator *authenticator, krb5_gss_ctx_ext_t exts, ++ krb5_gss_cred_id_t *deleg_out, krb5_ui_4 *flags_out, ++ krb5_error_code *code_out) ++{ ++ krb5_error_code code = 0; ++ OM_uint32 status, option_id, token_flags; ++ size_t cb_len, option_len; ++ krb5_boolean valid; ++ krb5_key subkey; ++ krb5_data option, empty = empty_data(); ++ krb5_checksum cb_cksum; ++ const uint8_t *token_cb, *option_bytes; ++ struct k5input in; ++ const krb5_checksum *cksum = authenticator->checksum; ++ ++ cb_cksum.contents = NULL; ++ ++ if (cksum == NULL) { ++ /* ++ * Some SMB client implementations use handcrafted GSSAPI code that ++ * does not provide a checksum. MS-KILE documents that the Microsoft ++ * implementation considers a missing checksum acceptable; the server ++ * assumes all flags are unset in this case, and does not check channel ++ * bindings. ++ */ ++ *flags_out = 0; ++ } else if (cksum->checksum_type != CKSUMTYPE_KG_CB) { ++ /* Samba sends a regular checksum. */ ++ code = krb5_auth_con_getkey_k(context, auth_context, &subkey); ++ if (code) { ++ status = GSS_S_FAILURE; ++ goto fail; ++ } ++ ++ /* Verifying the checksum ensures that this authenticator wasn't ++ * replayed from one with a checksum over actual data. */ ++ code = krb5_k_verify_checksum(context, subkey, ++ KRB5_KEYUSAGE_AP_REQ_AUTH_CKSUM, &empty, ++ cksum, &valid); ++ krb5_k_free_key(context, subkey); ++ if (code || !valid) { ++ status = GSS_S_BAD_SIG; ++ goto fail; ++ } ++ ++ /* Use ap_options from the request to guess the mutual flag. */ ++ *flags_out = GSS_C_REPLAY_FLAG | GSS_C_SEQUENCE_FLAG; ++ if (ap_req_options & AP_OPTS_MUTUAL_REQUIRED) ++ *flags_out |= GSS_C_MUTUAL_FLAG; ++ } else { ++ /* The checksum must contain at least a fixed 24-byte part. */ ++ if (cksum->length < MIN_8003_LEN) { ++ status = GSS_S_BAD_BINDINGS; ++ goto fail; ++ } ++ ++ k5_input_init(&in, cksum->contents, cksum->length); ++ cb_len = k5_input_get_uint32_le(&in); ++ if (cb_len != CB_MD5_LEN) { ++ code = KG_BAD_LENGTH; ++ status = GSS_S_FAILURE; ++ goto fail; ++ } ++ ++ token_cb = k5_input_get_bytes(&in, cb_len); ++ if (acceptor_cb != GSS_C_NO_CHANNEL_BINDINGS) { ++ code = kg_checksum_channel_bindings(context, acceptor_cb, ++ &cb_cksum); ++ if (code) { ++ status = GSS_S_BAD_BINDINGS; ++ goto fail; ++ } ++ assert(cb_cksum.length == cb_len); ++ if (k5_bcmp(token_cb, cb_cksum.contents, cb_len) != 0) { ++ status = GSS_S_BAD_BINDINGS; ++ goto fail; ++ } ++ } ++ ++ /* Read the token flags and accept some of them as context flags. */ ++ token_flags = k5_input_get_uint32_le(&in); ++ *flags_out = token_flags & INITIATOR_FLAGS; ++ ++ /* Read the delegated credential if present. */ ++ if (in.len >= 4 && (token_flags & GSS_C_DELEG_FLAG)) { ++ option_id = k5_input_get_uint16_le(&in); ++ option_len = k5_input_get_uint16_le(&in); ++ option_bytes = k5_input_get_bytes(&in, option_len); ++ option = make_data((uint8_t *)option_bytes, option_len); ++ if (in.status) { ++ code = KG_BAD_LENGTH; ++ status = GSS_S_FAILURE; ++ goto fail; ++ } ++ if (option_id != KRB5_GSS_FOR_CREDS_OPTION) { ++ status = GSS_S_FAILURE; ++ goto fail; ++ } ++ ++ /* Store the delegated credential. */ ++ code = rd_and_store_for_creds(context, auth_context, &option, ++ deleg_out); ++ if (code) { ++ status = GSS_S_FAILURE; ++ goto fail; ++ } ++ *flags_out |= GSS_C_DELEG_FLAG; ++ } ++ ++ /* Process any extensions at the end of the checksum. Extensions use ++ * 4-byte big-endian tag and length instead of 2-byte little-endian. */ ++ while (in.len > 0) { ++ option_id = k5_input_get_uint32_be(&in); ++ option_len = k5_input_get_uint32_be(&in); ++ option_bytes = k5_input_get_bytes(&in, option_len); ++ option = make_data((uint8_t *)option_bytes, option_len); ++ if (in.status) { ++ code = KG_BAD_LENGTH; ++ status = GSS_S_FAILURE; ++ goto fail; ++ } ++ ++ code = kg_process_extension(context, auth_context, option_id, ++ &option, exts); ++ if (code) { ++ status = GSS_S_FAILURE; ++ goto fail; ++ } ++ } ++ } ++ ++ status = GSS_S_COMPLETE; ++ ++fail: ++ free(cb_cksum.contents); ++ *code_out = code; ++ return status; ++} ++ + static OM_uint32 + kg_accept_krb5(minor_status, context_handle, + verifier_cred_handle, input_token, +@@ -433,17 +602,13 @@ kg_accept_krb5(minor_status, context_handle, + krb5_gss_ctx_ext_t exts; + { + krb5_context context; +- unsigned char *ptr, *ptr2; ++ unsigned char *ptr; + char *sptr; +- OM_uint32 tmp; +- size_t md5len; + krb5_gss_cred_id_t cred = 0; + krb5_data ap_rep, ap_req; +- unsigned int i; + krb5_error_code code; + krb5_address addr, *paddr; + krb5_authenticator *authdat = 0; +- krb5_checksum reqcksum; + krb5_gss_name_t name = NULL; + krb5_ui_4 gss_flags = 0; + krb5_gss_ctx_id_rec *ctx = NULL; +@@ -451,8 +616,6 @@ kg_accept_krb5(minor_status, context_handle, + gss_buffer_desc token; + krb5_auth_context auth_context = NULL; + krb5_ticket * ticket = NULL; +- int option_id; +- krb5_data option; + const gss_OID_desc *mech_used = NULL; + OM_uint32 major_status = GSS_S_FAILURE; + OM_uint32 tmp_minor_status; +@@ -463,7 +626,6 @@ kg_accept_krb5(minor_status, context_handle, + krb5int_access kaccess; + int cred_rcache = 0; + int no_encap = 0; +- int token_deleg_flag = 0; + krb5_flags ap_req_options = 0; + krb5_enctype negotiated_etype; + krb5_authdata_context ad_context = NULL; +@@ -489,7 +651,6 @@ kg_accept_krb5(minor_status, context_handle, + output_token->length = 0; + output_token->value = NULL; + token.value = 0; +- reqcksum.contents = 0; + ap_req.data = 0; + ap_rep.data = 0; + +@@ -654,195 +815,16 @@ kg_accept_krb5(minor_status, context_handle, + + krb5_auth_con_getauthenticator(context, auth_context, &authdat); + +- if (authdat->checksum == NULL) { +- /* +- * Some SMB client implementations use handcrafted GSSAPI code that +- * does not provide a checksum. MS-KILE documents that the Microsoft +- * implementation considers a missing checksum acceptable; the server +- * assumes all flags are unset in this case, and does not check channel +- * bindings. +- */ +- gss_flags = 0; +- } else if (authdat->checksum->checksum_type != CKSUMTYPE_KG_CB) { +- /* Samba does not send 0x8003 GSS-API checksums */ +- krb5_boolean valid; +- krb5_key subkey; +- krb5_data zero; ++ major_status = process_checksum(minor_status, context, input_chan_bindings, ++ auth_context, ap_req_options, ++ authdat, exts, ++ delegated_cred_handle ? &deleg_cred : NULL, ++ &gss_flags, &code); + +- code = krb5_auth_con_getkey_k(context, auth_context, &subkey); +- if (code) { +- major_status = GSS_S_FAILURE; +- goto fail; +- } ++ if (major_status != GSS_S_COMPLETE) ++ goto fail; + +- zero.length = 0; +- zero.data = ""; +- +- code = krb5_k_verify_checksum(context, +- subkey, +- KRB5_KEYUSAGE_AP_REQ_AUTH_CKSUM, +- &zero, +- authdat->checksum, +- &valid); +- krb5_k_free_key(context, subkey); +- if (code || !valid) { +- major_status = GSS_S_BAD_SIG; +- goto fail; +- } +- +- /* Use ap_options from the request to guess the mutual flag. */ +- gss_flags = GSS_C_REPLAY_FLAG | GSS_C_SEQUENCE_FLAG; +- if (ap_req_options & AP_OPTS_MUTUAL_REQUIRED) +- gss_flags |= GSS_C_MUTUAL_FLAG; +- } else { +- /* gss krb5 v1 */ +- +- /* stash this now, for later. */ +- code = krb5_c_checksum_length(context, CKSUMTYPE_RSA_MD5, &md5len); +- if (code) { +- major_status = GSS_S_FAILURE; +- goto fail; +- } +- +- /* verify that the checksum is correct */ +- +- /* +- The checksum may be either exactly 24 bytes, in which case +- no options are specified, or greater than 24 bytes, in which case +- one or more options are specified. Currently, the only valid +- option is KRB5_GSS_FOR_CREDS_OPTION ( = 1 ). +- */ +- +- if ((authdat->checksum->checksum_type != CKSUMTYPE_KG_CB) || +- (authdat->checksum->length < 24)) { +- code = 0; +- major_status = GSS_S_BAD_BINDINGS; +- goto fail; +- } +- +- ptr = (unsigned char *) authdat->checksum->contents; +- +- TREAD_INT(ptr, tmp, 0); +- +- if (tmp != md5len) { +- code = KG_BAD_LENGTH; +- major_status = GSS_S_FAILURE; +- goto fail; +- } +- +- /* +- The following section of code attempts to implement the +- optional channel binding facility as described in RFC2743. +- +- Since this facility is optional channel binding may or may +- not have been provided by either the client or the server. +- +- If the server has specified input_chan_bindings equal to +- GSS_C_NO_CHANNEL_BINDINGS then we skip the check. If +- the server does provide channel bindings then we compute +- a checksum and compare against those provided by the +- client. */ +- +- if ((code = kg_checksum_channel_bindings(context, +- input_chan_bindings, +- &reqcksum))) { +- major_status = GSS_S_BAD_BINDINGS; +- goto fail; +- } +- +- /* Always read the clients bindings - eventhough we might ignore them */ +- TREAD_STR(ptr, ptr2, reqcksum.length); +- +- if (input_chan_bindings != GSS_C_NO_CHANNEL_BINDINGS ) { +- if (memcmp(ptr2, reqcksum.contents, reqcksum.length) != 0) { +- xfree(reqcksum.contents); +- reqcksum.contents = 0; +- code = 0; +- major_status = GSS_S_BAD_BINDINGS; +- goto fail; +- } +- +- } +- +- xfree(reqcksum.contents); +- reqcksum.contents = 0; +- +- /* Read the token flags. Remember if GSS_C_DELEG_FLAG was set, but +- * mask it out until we actually read a delegated credential. */ +- TREAD_INT(ptr, gss_flags, 0); +- token_deleg_flag = (gss_flags & GSS_C_DELEG_FLAG); +- gss_flags &= ~GSS_C_DELEG_FLAG; +- +- /* if the checksum length > 24, there are options to process */ +- +- i = authdat->checksum->length - 24; +- if (i && token_deleg_flag) { +- if (i >= 4) { +- TREAD_INT16(ptr, option_id, 0); +- TREAD_INT16(ptr, option.length, 0); +- i -= 4; +- +- if (i < option.length) { +- code = KG_BAD_LENGTH; +- major_status = GSS_S_FAILURE; +- goto fail; +- } +- +- /* have to use ptr2, since option.data is wrong type and +- macro uses ptr as both lvalue and rvalue */ +- +- TREAD_STR(ptr, ptr2, option.length); +- option.data = (char *) ptr2; +- +- i -= option.length; +- +- if (option_id != KRB5_GSS_FOR_CREDS_OPTION) { +- major_status = GSS_S_FAILURE; +- goto fail; +- } +- +- /* store the delegated credential */ +- +- code = rd_and_store_for_creds(context, auth_context, &option, +- (delegated_cred_handle) ? +- &deleg_cred : NULL); +- if (code) { +- major_status = GSS_S_FAILURE; +- goto fail; +- } +- +- gss_flags |= GSS_C_DELEG_FLAG; +- } /* if i >= 4 */ +- /* ignore any additional trailing data, for now */ +- } +- while (i > 0) { +- /* Process Type-Length-Data options */ +- if (i < 8) { +- code = KG_BAD_LENGTH; +- major_status = GSS_S_FAILURE; +- goto fail; +- } +- TREAD_INT(ptr, option_id, 1); +- TREAD_INT(ptr, option.length, 1); +- i -= 8; +- if (i < option.length) { +- code = KG_BAD_LENGTH; +- major_status = GSS_S_FAILURE; +- goto fail; +- } +- TREAD_STR(ptr, ptr2, option.length); +- option.data = (char *)ptr2; +- +- i -= option.length; +- +- code = kg_process_extension(context, auth_context, +- option_id, &option, exts); +- if (code != 0) { +- major_status = GSS_S_FAILURE; +- goto fail; +- } +- } +- } ++ major_status = GSS_S_FAILURE; + + if (exts->iakerb.conv && !exts->iakerb.verified) { + major_status = GSS_S_BAD_SIG; +@@ -869,12 +851,7 @@ kg_accept_krb5(minor_status, context_handle, + ctx->mech_used = (gss_OID) mech_used; + ctx->auth_context = auth_context; + ctx->initiate = 0; +- ctx->gss_flags = (GSS_C_TRANS_FLAG | +- ((gss_flags) & (GSS_C_INTEG_FLAG | GSS_C_CONF_FLAG | +- GSS_C_MUTUAL_FLAG | GSS_C_REPLAY_FLAG | +- GSS_C_SEQUENCE_FLAG | GSS_C_DELEG_FLAG | +- GSS_C_DCE_STYLE | GSS_C_IDENTIFY_FLAG | +- GSS_C_EXTENDED_ERROR_FLAG))); ++ ctx->gss_flags = gss_flags | GSS_C_TRANS_FLAG; + ctx->seed_init = 0; + ctx->cred_rcache = cred_rcache; + +@@ -1161,8 +1138,6 @@ fail: + + krb5_auth_con_free(context, auth_context); + } +- if (reqcksum.contents) +- xfree(reqcksum.contents); + if (ap_rep.data) + krb5_free_data_contents(context, &ap_rep); + if (major_status == GSS_S_COMPLETE || diff --git a/Remove-resolver-test-utility.patch b/Remove-resolver-test-utility.patch index 95055df..6602185 100644 --- a/Remove-resolver-test-utility.patch +++ b/Remove-resolver-test-utility.patch @@ -1,4 +1,4 @@ -From c21bb26abc4799298726124d73f0c968430a87bd Mon Sep 17 00:00:00 2001 +From 85bb5fe5a11708b78e9f0bd3a3b34999b6c888a7 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 28 May 2020 18:41:02 -0400 Subject: [PATCH] Remove resolver test utility diff --git a/Replace-gssrpc-tests-with-a-Python-script.patch b/Replace-gssrpc-tests-with-a-Python-script.patch index 5632455..17fee61 100644 --- a/Replace-gssrpc-tests-with-a-Python-script.patch +++ b/Replace-gssrpc-tests-with-a-Python-script.patch @@ -1,4 +1,4 @@ -From 5af211200d6c2ac82872435556f5b39edcaba541 Mon Sep 17 00:00:00 2001 +From a12fc355a034e5b1d23bdb23db9735d4eaa396d8 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 15 Feb 2020 20:34:23 -0500 Subject: [PATCH] Replace gssrpc tests with a Python script diff --git a/krb5.spec b/krb5.spec index 0bd0d21..5d1ebda 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 7%{?dist} +Release: 8%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -56,11 +56,17 @@ Patch16: Do-expiration-warnings-for-all-init_creds-APIs.patch Patch17: Pass-gss_localname-through-SPNEGO.patch Patch18: Omit-KDC-indicator-check-for-S4U2Self-requests.patch Patch19: Fix-typo-in-in-in-the-ksu-man-page.patch -Patch20: Pass-channel-bindings-through-SPNEGO.patch Patch21: Replace-gssrpc-tests-with-a-Python-script.patch Patch22: Default-dns_canonicalize_hostname-to-fallback.patch Patch23: Remove-resolver-test-utility.patch Patch24: Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch +Patch25: Improve-negoex_parse_token-code-hygiene.patch +Patch26: Refactor-krb5-GSS-checksum-handling.patch +Patch27: Implement-GSS_C_CHANNEL_BOUND_FLAG.patch +Patch28: Implement-KERB_AP_OPTIONS_CBT-server-side.patch +Patch29: Add-client_aware_channel_bindings-option.patch +Patch30: Pass-channel-bindings-through-SPNEGO.patch +Patch31: Add-channel-bindings-tests.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -615,6 +621,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jun 15 2020 Robbie Harwood - 1.18.2-8 +- Match Heimdal behavior for channel bindings + * Mon Jun 08 2020 Robbie Harwood - 1.18.2-7 - Fix test suite by removing wrapper workarounds From 80e06352b841fd4e06cd36118154566561fdfb77 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 15 Jun 2020 17:27:59 -0400 Subject: [PATCH 179/304] Use two queues for concurrent t_otp.py daemons --- ...eues-for-concurrent-t_otp.py-daemons.patch | 41 +++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 46 insertions(+), 1 deletion(-) create mode 100644 Use-two-queues-for-concurrent-t_otp.py-daemons.patch diff --git a/Use-two-queues-for-concurrent-t_otp.py-daemons.patch b/Use-two-queues-for-concurrent-t_otp.py-daemons.patch new file mode 100644 index 0000000..33da6f5 --- /dev/null +++ b/Use-two-queues-for-concurrent-t_otp.py-daemons.patch @@ -0,0 +1,41 @@ +From 8e08f01d73ddca1b828788710ec6bb3e0354727a Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 4 Mar 2020 17:18:51 -0500 +Subject: [PATCH] Use two queues for concurrent t_otp.py daemons + +t_otp.py occasionally fails during the #8708 regression test, reading +a true answer instead of the expected false answer during the first +verify() call. Most likely the daemons are writing their answers to +the shared queue out of order. Use a separate queue for the second +daemon to ensure correct correlation of results. + +(cherry picked from commit c03f67eefec05db19e84e889fab7c25904929633) +--- + src/tests/t_otp.py | 7 ++++--- + 1 file changed, 4 insertions(+), 3 deletions(-) + +diff --git a/src/tests/t_otp.py b/src/tests/t_otp.py +index cba871a0f..c3b820a41 100755 +--- a/src/tests/t_otp.py ++++ b/src/tests/t_otp.py +@@ -256,16 +256,17 @@ verify(daemon, queue, True, realm.user_princ, 'accept') + ## tokens configured, with the first rejecting and the second + ## accepting. With the bug, the KDC incorrectly rejects the request + ## and then performs invalid memory accesses, most likely crashing. ++queue2 = Queue() + daemon1 = UDPRadiusDaemon(args=(server_addr, secret_file, 'accept1', queue)) +-daemon2 = UnixRadiusDaemon(args=(socket_file, None, 'accept2', queue)) ++daemon2 = UnixRadiusDaemon(args=(socket_file, None, 'accept2', queue2)) + daemon1.start() + queue.get() + daemon2.start() +-queue.get() ++queue2.get() + oconf = '[' + otpconfig_1('udp') + ', ' + otpconfig_1('unix') + ']' + realm.run([kadminl, 'setstr', realm.user_princ, 'otp', oconf]) + realm.kinit(realm.user_princ, 'accept2', flags=flags) + verify(daemon1, queue, False, realm.user_princ.split('@')[0], 'accept2') +-verify(daemon2, queue, True, realm.user_princ, 'accept2') ++verify(daemon2, queue2, True, realm.user_princ, 'accept2') + + success('OTP tests') diff --git a/krb5.spec b/krb5.spec index 5d1ebda..b3e9dfa 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 8%{?dist} +Release: 9%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -67,6 +67,7 @@ Patch28: Implement-KERB_AP_OPTIONS_CBT-server-side.patch Patch29: Add-client_aware_channel_bindings-option.patch Patch30: Pass-channel-bindings-through-SPNEGO.patch Patch31: Add-channel-bindings-tests.patch +Patch32: Use-two-queues-for-concurrent-t_otp.py-daemons.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -621,6 +622,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jun 15 2020 Robbie Harwood - 1.18.2-9 +- Use two queues for concurrent t_otp.py daemons + * Mon Jun 15 2020 Robbie Harwood - 1.18.2-8 - Match Heimdal behavior for channel bindings From f15271f04d938b5a0b71e0d7c1e967bcf8baa621 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 8 Jul 2020 20:10:01 +0000 Subject: [PATCH 180/304] Set qualify_shortname empty in default configuration Resolves: #1852041 --- krb5.conf | 1 + krb5.spec | 6 +++++- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/krb5.conf b/krb5.conf index 4f0d898..5e474d1 100644 --- a/krb5.conf +++ b/krb5.conf @@ -16,6 +16,7 @@ includedir /etc/krb5.conf.d/ pkinit_anchors = FILE:/etc/pki/tls/certs/ca-bundle.crt spake_preauth_groups = edwards25519 dns_canonicalize_hostname = fallback + qualify_shortname = "" # default_realm = EXAMPLE.COM [realms] diff --git a/krb5.spec b/krb5.spec index b3e9dfa..18792f8 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 9%{?dist} +Release: 10%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -622,6 +622,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Jul 08 2020 Robbie Harwood - 1.18.2-10 +- Set qualify_shortname empty in default configuration +- Resolves: #1852041 + * Mon Jun 15 2020 Robbie Harwood - 1.18.2-9 - Use two queues for concurrent t_otp.py daemons From da1e8dbb3fb80bafd44da5d823d38ac574c07e69 Mon Sep 17 00:00:00 2001 From: Tom Stellard Date: Mon, 13 Jul 2020 20:32:39 +0000 Subject: [PATCH 181/304] Use make macros https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro --- krb5.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 18792f8..3a67ce4 100644 --- a/krb5.spec +++ b/krb5.spec @@ -391,7 +391,7 @@ install -pdm 755 $RPM_BUILD_ROOT/%{_libdir}/krb5/plugins/kdb install -pdm 755 $RPM_BUILD_ROOT/%{_libdir}/krb5/plugins/authdata # The rest of the binaries, headers, libraries, and docs. -make -C src DESTDIR=$RPM_BUILD_ROOT EXAMPLEDIR=%{libsdocdir}/examples install +%make_install -C src EXAMPLEDIR=%{libsdocdir}/examples # Munge krb5-config yet again. This is totally wrong for 64-bit, but chunks # of the buildconf patch already conspire to strip out /usr/ from the From b1b925635d7bbaa915961f9ae7e8c2535e591125 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 15 Jul 2020 16:30:20 -0400 Subject: [PATCH 182/304] Ignore bad enctypes in krb5_string_to_keysalts() --- ...-enctypes-in-krb5_string_to_keysalts.patch | 31 +++++++++++++++++++ krb5.spec | 6 +++- 2 files changed, 36 insertions(+), 1 deletion(-) create mode 100644 Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch diff --git a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch new file mode 100644 index 0000000..9b80631 --- /dev/null +++ b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch @@ -0,0 +1,31 @@ +From f9c314847c999727679a9e8ad4fb565001e47fd2 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 15 Jul 2020 15:42:20 -0400 +Subject: [PATCH] Ignore bad enctypes in krb5_string_to_keysalts() + +Fixes a problem where the presence of legacy/unrecognized keysalts in +supported_enctypes would prevent the kadmin programs from starting. + +(cherry picked from commit 860b411d441e4a486f6714762605c42997b8946a) +--- + src/lib/kadm5/str_conv.c | 7 ++++--- + 1 file changed, 4 insertions(+), 3 deletions(-) + +diff --git a/src/lib/kadm5/str_conv.c b/src/lib/kadm5/str_conv.c +index 7cf51d316..0abfa845c 100644 +--- a/src/lib/kadm5/str_conv.c ++++ b/src/lib/kadm5/str_conv.c +@@ -340,9 +340,10 @@ krb5_string_to_keysalts(const char *string, const char *tupleseps, + while ((ksp = strtok_r(p, tseps, &tlasts)) != NULL) { + /* Pass a null pointer to subsequent calls to strtok_r(). */ + p = NULL; +- ret = string_to_keysalt(ksp, ksaltseps, &etype, &stype); +- if (ret) +- goto cleanup; ++ ++ /* Discard unrecognized keysalts. */ ++ if (string_to_keysalt(ksp, ksaltseps, &etype, &stype)) ++ continue; + + /* Ignore duplicate keysalts if caller asks. */ + if (!dups && krb5_keysalt_is_present(ksalts, nksalts, etype, stype)) diff --git a/krb5.spec b/krb5.spec index 3a67ce4..013c443 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 10%{?dist} +Release: 11%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -68,6 +68,7 @@ Patch29: Add-client_aware_channel_bindings-option.patch Patch30: Pass-channel-bindings-through-SPNEGO.patch Patch31: Add-channel-bindings-tests.patch Patch32: Use-two-queues-for-concurrent-t_otp.py-daemons.patch +Patch33: Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -622,6 +623,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Jul 15 2020 Robbie Harwood - 1.18.2-11 +- Ignore bad enctypes in krb5_string_to_keysalts() + * Wed Jul 08 2020 Robbie Harwood - 1.18.2-10 - Set qualify_shortname empty in default configuration - Resolves: #1852041 From 86ecb1b3d2f99d190e82d342366400434fdc5e98 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 22 Jul 2020 17:28:11 -0400 Subject: [PATCH 183/304] Ignore bad enctypes in krb5_string_to_keysalts() Allow gss_unwrap_iov() of unpadded RC4 tokens --- ...ss_unwrap_iov-of-unpadded-RC4-tokens.patch | 49 +++++++++++++++++++ ...-enctypes-in-krb5_string_to_keysalts.patch | 14 ++++-- krb5.spec | 9 +++- 3 files changed, 66 insertions(+), 6 deletions(-) create mode 100644 Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch diff --git a/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch b/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch new file mode 100644 index 0000000..4698963 --- /dev/null +++ b/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch @@ -0,0 +1,49 @@ +From bedbb5ee1ad821b91f00d30361985e6863c0e6ba Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sat, 11 Jul 2020 21:57:30 -0400 +Subject: [PATCH] Allow gss_unwrap_iov() of unpadded RC4 tokens + +Windows Remote Management, when used with an RC4 session key, appears +to generate GSS wrap tokens with no padding instead of the expected +one byte (RFC 4757 section 7.3). These tokens cannot be decoded with +gss_unwrap() or a STREAM buffer (even with Microsoft SSPI), but SSPI +allows them to be decoded using explicit IOVs with either a +zero-length padding buffer or no padding buffer. Allow these cases to +work in kg_fixup_padding_iov(). (It is already possible to make this +work with HEADER | DATA | DATA, but only by +accident--kg_fixup_padding_iov() doesn't find a data buffer because +kg_locate_iov() only looks for singleton buffers, so it exits early.) + +ticket: 8926 (new) +tags: pullup +target_version: 1.18-next + +(cherry picked from commit 3f204ddd567715ef360b4bb0b32961b6a9877f9d) +--- + src/lib/gssapi/krb5/util_crypt.c | 9 +++------ + 1 file changed, 3 insertions(+), 6 deletions(-) + +diff --git a/src/lib/gssapi/krb5/util_crypt.c b/src/lib/gssapi/krb5/util_crypt.c +index f7d3e92c4..d6c71aeb8 100644 +--- a/src/lib/gssapi/krb5/util_crypt.c ++++ b/src/lib/gssapi/krb5/util_crypt.c +@@ -638,16 +638,13 @@ kg_fixup_padding_iov(OM_uint32 *minor_status, gss_iov_buffer_desc *iov, + data = kg_locate_iov(iov, iov_count, GSS_IOV_BUFFER_TYPE_DATA); + padding = kg_locate_iov(iov, iov_count, GSS_IOV_BUFFER_TYPE_PADDING); + +- if (data == NULL) { ++ /* Do nothing if padding is absent or empty, to allow unwrapping of WinRM ++ * unpadded RC4 tokens using an explicit IOV array. */ ++ if (data == NULL || padding == NULL || padding->buffer.length == 0) { + *minor_status = 0; + return GSS_S_COMPLETE; + } + +- if (padding == NULL || padding->buffer.length == 0) { +- *minor_status = EINVAL; +- return GSS_S_FAILURE; +- } +- + p = (unsigned char *)padding->buffer.value; + padlength = p[padding->buffer.length - 1]; + diff --git a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch index 9b80631..2bdd0a3 100644 --- a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch +++ b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch @@ -1,4 +1,4 @@ -From f9c314847c999727679a9e8ad4fb565001e47fd2 Mon Sep 17 00:00:00 2001 +From 3f873868fb08b77da2d30e164a0ef6c71c17c607 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 15 Jul 2020 15:42:20 -0400 Subject: [PATCH] Ignore bad enctypes in krb5_string_to_keysalts() @@ -6,13 +6,19 @@ Subject: [PATCH] Ignore bad enctypes in krb5_string_to_keysalts() Fixes a problem where the presence of legacy/unrecognized keysalts in supported_enctypes would prevent the kadmin programs from starting. -(cherry picked from commit 860b411d441e4a486f6714762605c42997b8946a) +[ghudson@mit.edu: ideally we would put a warning in the kadmind log, +but that is difficult to do when the parsing is done inside a library. +Even adding a trace log is difficult because the kadm5 str_conv +functions do not accept contexts.] + +ticket: 8929 (new) +(cherry picked from commit be5396ada0e8dabd68bd0aceb733cfca39a609bc) --- src/lib/kadm5/str_conv.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/src/lib/kadm5/str_conv.c b/src/lib/kadm5/str_conv.c -index 7cf51d316..0abfa845c 100644 +index 7cf51d316..798295606 100644 --- a/src/lib/kadm5/str_conv.c +++ b/src/lib/kadm5/str_conv.c @@ -340,9 +340,10 @@ krb5_string_to_keysalts(const char *string, const char *tupleseps, @@ -24,7 +30,7 @@ index 7cf51d316..0abfa845c 100644 - goto cleanup; + + /* Discard unrecognized keysalts. */ -+ if (string_to_keysalt(ksp, ksaltseps, &etype, &stype)) ++ if (string_to_keysalt(ksp, ksaltseps, &etype, &stype) != 0) + continue; /* Ignore duplicate keysalts if caller asks. */ diff --git a/krb5.spec b/krb5.spec index 013c443..2596330 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 11%{?dist} +Release: 12%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -68,7 +68,8 @@ Patch29: Add-client_aware_channel_bindings-option.patch Patch30: Pass-channel-bindings-through-SPNEGO.patch Patch31: Add-channel-bindings-tests.patch Patch32: Use-two-queues-for-concurrent-t_otp.py-daemons.patch -Patch33: Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch +Patch33: Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch +Patch34: Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -623,6 +624,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Jul 22 2020 Robbie Harwood - 1.18.2-12 +- Ignore bad enctypes in krb5_string_to_keysalts() +- Allow gss_unwrap_iov() of unpadded RC4 tokens + * Wed Jul 15 2020 Robbie Harwood - 1.18.2-11 - Ignore bad enctypes in krb5_string_to_keysalts() From d314641a26de22a916c21aeff590e54d69be7ccf Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Tue, 28 Jul 2020 03:39:56 +0000 Subject: [PATCH 184/304] - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 2596330..8e6cb4e 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 12%{?dist} +Release: 13%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -624,6 +624,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Jul 28 2020 Fedora Release Engineering - 1.18.2-13 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + * Wed Jul 22 2020 Robbie Harwood - 1.18.2-12 - Ignore bad enctypes in krb5_string_to_keysalts() - Allow gss_unwrap_iov() of unpadded RC4 tokens From 710f626f12ede3d343fe5dc32214b8d2afea9099 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 31 Jul 2020 13:31:53 -0400 Subject: [PATCH 185/304] Revert qualify_shortname changes --- Add-channel-bindings-tests.patch | 2 +- ...client_aware_channel_bindings-option.patch | 6 +- ...ss_unwrap_iov-of-unpadded-RC4-tokens.patch | 2 +- ...ns_canonicalize_hostname-to-fallback.patch | 371 ------------------ ...-enctypes-in-krb5_string_to_keysalts.patch | 2 +- Implement-GSS_C_CHANNEL_BOUND_FLAG.patch | 2 +- ...ment-KERB_AP_OPTIONS_CBT-server-side.patch | 2 +- Improve-negoex_parse_token-code-hygiene.patch | 2 +- ...SER-if-we-can-t-compute-its-checksum.patch | 2 +- Pass-channel-bindings-through-SPNEGO.patch | 2 +- Refactor-krb5-GSS-checksum-handling.patch | 2 +- Remove-resolver-test-utility.patch | 2 +- ...eues-for-concurrent-t_otp.py-daemons.patch | 2 +- krb5.spec | 6 +- 14 files changed, 18 insertions(+), 387 deletions(-) delete mode 100644 Default-dns_canonicalize_hostname-to-fallback.patch diff --git a/Add-channel-bindings-tests.patch b/Add-channel-bindings-tests.patch index b758c79..a152fa2 100644 --- a/Add-channel-bindings-tests.patch +++ b/Add-channel-bindings-tests.patch @@ -1,4 +1,4 @@ -From 3e92520c1417f22447751cd9172d5ab30c2e0ad8 Mon Sep 17 00:00:00 2001 +From 5f98c9d9ff16f3760ac26304cfdb87bf53bc8628 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Fri, 20 Mar 2020 00:17:28 +0100 Subject: [PATCH] Add channel bindings tests diff --git a/Add-client_aware_channel_bindings-option.patch b/Add-client_aware_channel_bindings-option.patch index 012ce8d..e8b5374 100644 --- a/Add-client_aware_channel_bindings-option.patch +++ b/Add-client_aware_channel_bindings-option.patch @@ -1,4 +1,4 @@ -From 2a08fe3d2d1972df4ffe37d4bb64b161889ff988 Mon Sep 17 00:00:00 2001 +From bb7425941f5d84a53e30721c20fbfc714157f082 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 10 Mar 2020 13:13:17 +0100 Subject: [PATCH] Add client_aware_channel_bindings option @@ -20,10 +20,10 @@ ticket: 8900 3 files changed, 98 insertions(+), 86 deletions(-) diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index a7e7a29d1..7f2879640 100644 +index 1d2aa7f68..1d8ffc1e4 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst -@@ -382,6 +382,12 @@ The libdefaults section may contain any of the following relations: +@@ -383,6 +383,12 @@ The libdefaults section may contain any of the following relations: credentials will fail if the client machine does not have a keytab. The default value is false. diff --git a/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch b/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch index 4698963..716fa8a 100644 --- a/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch +++ b/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch @@ -1,4 +1,4 @@ -From bedbb5ee1ad821b91f00d30361985e6863c0e6ba Mon Sep 17 00:00:00 2001 +From 297857dec4f82a802caa734670b57f0a18d942e2 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 11 Jul 2020 21:57:30 -0400 Subject: [PATCH] Allow gss_unwrap_iov() of unpadded RC4 tokens diff --git a/Default-dns_canonicalize_hostname-to-fallback.patch b/Default-dns_canonicalize_hostname-to-fallback.patch deleted file mode 100644 index ef80329..0000000 --- a/Default-dns_canonicalize_hostname-to-fallback.patch +++ /dev/null @@ -1,371 +0,0 @@ -From 07179e38e5ee72e82ebc77a1c8d73e34905268b7 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 27 May 2020 18:48:35 -0400 -Subject: [PATCH] Default dns_canonicalize_hostname to "fallback" - -This change should mitigate some of the pain caused by the rdns=true -default (generally associated with unwanted PTR records that cannot -easily be changed), with a minimum of fallout. - -Update the documentation and tests accordingly. In test environments, -disable qualify_shortname and use the uncanonicalized system hostname -(lowercased) to match the initial sn2princ result. - -ticket: 8911 (new) ---- - doc/admin/appl_servers.rst | 14 +++--- - doc/admin/conf_files/krb5_conf.rst | 9 ++-- - doc/admin/princ_dns.rst | 44 +++++++++++-------- - src/kadmin/testing/proto/krb5.conf.proto | 8 ++-- - src/kadmin/testing/scripts/env-setup.shin | 4 +- - src/kadmin/testing/scripts/init_db | 3 +- - src/kadmin/testing/scripts/start_servers | 3 +- - .../testing/scripts/start_servers_local | 2 +- - .../kadm5/unit-test/api.current/init-v2.exp | 6 +-- - src/lib/krb5/krb/init_ctx.c | 2 +- - src/tests/dejagnu/config/default.exp | 5 +-- - src/tests/t_sn2princ.py | 5 ++- - src/util/k5test.py | 25 +++-------- - 13 files changed, 58 insertions(+), 72 deletions(-) - -diff --git a/doc/admin/appl_servers.rst b/doc/admin/appl_servers.rst -index 5232db9af..afdf30297 100644 ---- a/doc/admin/appl_servers.rst -+++ b/doc/admin/appl_servers.rst -@@ -115,14 +115,12 @@ Getting DNS information correct - ------------------------------- - - Several aspects of Kerberos rely on name service. When a hostname is --used to name a service, the Kerberos library canonicalizes the --hostname using forward and reverse name resolution. (The reverse name --resolution step can be turned off using the **rdns** variable in --:ref:`libdefaults`.) The result of this canonicalization must match --the principal entry in the host's keytab, or authentication will fail. -- --Each host's canonical name must be the fully-qualified host name --(including the domain), and each host's IP address must -+used to name a service, clients may canonicalize the hostname using -+forward and possibly reverse name resolution. The result of this -+canonicalization must match the principal entry in the host's keytab, -+or authentication will fail. To work with all client canonicalization -+configurations, each host's canonical name must be the fully-qualified -+host name (including the domain), and each host's IP address must - reverse-resolve to the canonical name. - - Configuration of hostnames varies by operating system. On the -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 1d2aa7f68..a7e7a29d1 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -188,11 +188,10 @@ The libdefaults section may contain any of the following relations: - hostnames for use in service principal names. Setting this flag - to false can improve security by reducing reliance on DNS, but - means that short hostnames will not be canonicalized to -- fully-qualified hostnames. The default value is true. -- -- If this option is set to ``fallback`` (new in release 1.18), DNS -- canonicalization will only be performed the server hostname is not -- found with the original name when requesting credentials. -+ fully-qualified hostnames. If this option is set to ``fallback`` (new -+ in release 1.18), DNS canonicalization will only be performed the -+ server hostname is not found with the original name when -+ requesting credentials. The default value is ``fallback``. - - **dns_lookup_kdc** - Indicate whether DNS SRV records should be used to locate the KDCs -diff --git a/doc/admin/princ_dns.rst b/doc/admin/princ_dns.rst -index e1d823f27..32a269afc 100644 ---- a/doc/admin/princ_dns.rst -+++ b/doc/admin/princ_dns.rst -@@ -31,27 +31,35 @@ based on rotating ``CNAME`` records in DNS. - Service principal canonicalization - ---------------------------------- - --MIT Kerberos clients currently always do forward resolution (looking --up the IPv4 and possibly IPv6 addresses using ``getaddrinfo()``) of --the hostname part of a host-based service principal to canonicalize --the hostname. They obtain the "canonical" name of the host when doing --so. By default, MIT Kerberos clients will also then do reverse DNS --resolution (looking up the hostname associated with the IPv4 or IPv6 --address using ``getnameinfo()``) of the hostname. Using the --:ref:`krb5.conf(5)` setting:: -+In the MIT krb5 client library, canonicalization of host-based service -+principals is controlled by the **dns_canonicalize_hostname**, -+**rnds**, and **qualify_shortname** variables in :ref:`libdefaults`. - -- [libdefaults] -- rdns = false -+If **dns_canonicalize_hostname** is set to ``true`` (the default value -+before release 1.19), the client performs forward resolution by -+looking up the IPv4 and/or IPv6 addresses of the hostname using -+``getaddrinfo()``. This process will typically add a domain suffix to -+the hostname if needed, and follow CNAME records in the DNS. If -+**rdns** is also set to ``true`` (the default), the client will then -+perform a reverse lookup of the first returned Internet address using -+``getnameinfo()``, finding the name associated with the PTR record. - --will disable reverse DNS lookup on clients. The default setting is --"true". -+If **dns_canonicalize_hostname** is set to ``false``, the hostname is -+not canonicalized using DNS. If the hostname has only one component -+(i.e. it contains no "." characters), the host's primary DNS search -+domain will be appended, if there is one. The **qualify_shortname** -+variable can be used to override or disable this suffix. -+ -+If **dns_canonicalize_hostname** is set to ``fallback`` (the default -+value in release 1.19 and later), the hostname is initially treated -+according to the rules for ``dns_canonicalize_hostname=false``. If a -+ticket request fails because the service principal is unknown, it the -+hostname will be canonicalized according to the rules for -+``dns_canonicalize_hostname=true`` and the request will be retried. -+ -+In all cases, the hostname is converted to lowercase, and any trailing -+dot is removed. - --Operating system bugs may prevent a setting of ``rdns = false`` from --disabling reverse DNS lookup. Some versions of GNU libc have a bug in --``getaddrinfo()`` that cause them to look up ``PTR`` records even when --not required. MIT Kerberos releases krb5-1.10.2 and newer have a --workaround for this problem, as does the krb5-1.9.x series as of --release krb5-1.9.4. - - - Reverse DNS mismatches -diff --git a/src/kadmin/testing/proto/krb5.conf.proto b/src/kadmin/testing/proto/krb5.conf.proto -index e710852d4..c0af716a5 100644 ---- a/src/kadmin/testing/proto/krb5.conf.proto -+++ b/src/kadmin/testing/proto/krb5.conf.proto -@@ -2,19 +2,19 @@ - default_realm = __REALM__ - default_keytab_name = FILE:__K5ROOT__/keytab - dns_fallback = no -+ qualify_shortname = "" - plugin_base_dir = __PLUGIN_DIR__ - allow_weak_crypto = true - - [realms] - __REALM__ = { -- kdc = __KDCHOST__:1750 -- admin_server = __KDCHOST__:1751 -+ kdc = __HOSTNAME__:1750 -+ admin_server = __HOSTNAME__:1751 - database_module = foobar_db2_module_blah - } - - [domain_realm] -- __LOCALHOST__ = __REALM__ -- __KDCHOST__ = __REALM__ -+ __HOSTNAME__ = __REALM__ - - [logging] - admin_server = FILE:__K5ROOT__/syslog -diff --git a/src/kadmin/testing/scripts/env-setup.shin b/src/kadmin/testing/scripts/env-setup.shin -index 969c5340c..88f8ad1aa 100755 ---- a/src/kadmin/testing/scripts/env-setup.shin -+++ b/src/kadmin/testing/scripts/env-setup.shin -@@ -71,8 +71,8 @@ BSDDB_DUMP=$TESTDIR/util/bsddb_dump; export BSDDB_DUMP - CLNTTCL=$TESTDIR/util/kadm5_clnt_tcl; export CLNTTCL - SRVTCL=$TESTDIR/util/kadm5_srv_tcl; export SRVTCL - --QUALNAME=`$BUILDTOP/tests/resolve/resolve -q | tr '[A-Z]' '[a-z]'` --export QUALNAME -+HOSTNAME=`hostname | tr '[A-Z]' '[a-z]'` -+export HOSTNAME - - KRB5_CONFIG=$K5ROOT/krb5.conf; export KRB5_CONFIG - KRB5_KDC_PROFILE=$K5ROOT/kdc.conf; export KRB5_KDC_PROFILE -diff --git a/src/kadmin/testing/scripts/init_db b/src/kadmin/testing/scripts/init_db -index e65826c96..216f62793 100755 ---- a/src/kadmin/testing/scripts/init_db -+++ b/src/kadmin/testing/scripts/init_db -@@ -79,8 +79,7 @@ fi - # done - - sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ -- -e "s/__KDCHOST__/$QUALNAME/g" \ -- -e "s/__LOCALHOST__/$QUALNAME/g" \ -+ -e "s/__HOSTNAME__/$HOSTNAME/g" \ - -e "s#__MODDIR__#$MODDIR#g" \ - < $STESTDIR/proto/krb5.conf.proto > $K5ROOT/krb5.conf - sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ -diff --git a/src/kadmin/testing/scripts/start_servers b/src/kadmin/testing/scripts/start_servers -index f23df0682..05519e4ee 100755 ---- a/src/kadmin/testing/scripts/start_servers -+++ b/src/kadmin/testing/scripts/start_servers -@@ -36,8 +36,7 @@ if [ $local = 0 ]; then - - # Fix up the local krb5.conf to point to the remote - sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ -- -e "s/__KDCHOST__/$hostname/g" \ -- -e "s/__LOCALHOST__/$QUALNAME/g" \ -+ -e "s/__HOSTNAME__/$HOSTNAME/g" \ - -e "s#__MODDIR__#$TOP/../plugins/kdb#g"\ - -e "s#__PLUGIN_DIR__#$TOP/../plugins#g"\ - < $STESTDIR/proto/krb5.conf.proto > $K5ROOT/krb5.conf -diff --git a/src/kadmin/testing/scripts/start_servers_local b/src/kadmin/testing/scripts/start_servers_local -index 998ef9164..858e88031 100755 ---- a/src/kadmin/testing/scripts/start_servers_local -+++ b/src/kadmin/testing/scripts/start_servers_local -@@ -79,7 +79,7 @@ cat - > /tmp/start_servers_local$$ <<\EOF - if { [catch { - source $env(STOP)/testing/tcl/util.t - set r $env(REALM) -- set q $env(QUALNAME) -+ set q $env(HOSTNAME) - puts stdout [kadm5_init $env(SRVTCL) mrroot null \ - [config_params {KADM5_CONFIG_REALM} $r] \ - $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 server_handle] -diff --git a/src/lib/kadm5/unit-test/api.current/init-v2.exp b/src/lib/kadm5/unit-test/api.current/init-v2.exp -index 7a353d4e9..47764c212 100644 ---- a/src/lib/kadm5/unit-test/api.current/init-v2.exp -+++ b/src/lib/kadm5/unit-test/api.current/init-v2.exp -@@ -3,18 +3,14 @@ load_lib lib.t - api_exit - api_start - --if ![info exists RESOLVE] { -- set RESOLVE [findfile $objdir/../../../tests/resolve/resolve] --} - proc get_hostname { } { -- global RESOLVE - global hostname - - if {[info exists hostname]} { - return 1 - } - -- catch "exec $RESOLVE -q >myname" exec_output -+ catch "exec hostname >myname" exec_output - if ![string match "" $exec_output] { - send_log "$exec_output\n" - verbose $exec_output -diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index 9a4741fa6..0b8ae6714 100644 ---- a/src/lib/krb5/krb/init_ctx.c -+++ b/src/lib/krb5/krb/init_ctx.c -@@ -237,7 +237,7 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, - ctx->enforce_ok_as_delegate = tmp; - - retval = get_tristate(ctx, KRB5_CONF_DNS_CANONICALIZE_HOSTNAME, "fallback", -- CANONHOST_FALLBACK, 1, &tmp); -+ CANONHOST_FALLBACK, CANONHOST_FALLBACK, &tmp); - if (retval) - goto cleanup; - ctx->dns_canonicalize_hostname = tmp; -diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp -index 4d8c917cd..1e7777f1e 100644 ---- a/src/tests/dejagnu/config/default.exp -+++ b/src/tests/dejagnu/config/default.exp -@@ -268,7 +268,6 @@ foreach i { - {KTUTIL $objdir/../../kadmin/ktutil/ktutil} - {KLIST $objdir/../../clients/klist/klist} - {KDESTROY $objdir/../../clients/kdestroy/kdestroy} -- {RESOLVE $objdir/../resolve/resolve} - {T_INETD $objdir/t_inetd} - {KPROPLOG $objdir/../../kprop/kproplog} - {KPASSWD $objdir/../../clients/kpasswd/kpasswd} -@@ -462,7 +461,6 @@ proc setup_runtime_env { } { - # 0 on failure. - - proc get_hostname { } { -- global RESOLVE - global hostname - global tmppwd - -@@ -472,7 +470,7 @@ proc get_hostname { } { - - envstack_push - setup_runtime_env -- catch "exec $RESOLVE -q >$tmppwd/hostname" exec_output -+ catch "exec hostname >$tmppwd/hostname" exec_output - envstack_pop - if ![string match "" $exec_output] { - verbose -log $exec_output -@@ -710,6 +708,7 @@ proc setup_krb5_conf { {type client} } { - puts $conffile "\[libdefaults\]" - puts $conffile " default_realm = $REALMNAME" - puts $conffile " dns_lookup_kdc = false" -+ puts $conffile " qualify_shortname = \"\"" - if [info exists allow_weak_crypto($type)] { - puts $conffile " allow_weak_crypto = $allow_weak_crypto($type)" - } else { -diff --git a/src/tests/t_sn2princ.py b/src/tests/t_sn2princ.py -index 26dcb91c2..f3e187286 100755 ---- a/src/tests/t_sn2princ.py -+++ b/src/tests/t_sn2princ.py -@@ -2,7 +2,8 @@ from k5test import * - - offline = (len(args) > 0 and args[0] != "no") - --conf = {'domain_realm': {'kerberos.org': 'R1', -+conf = {'libdefaults': {'dns_canonicalize_hostname': 'true'}, -+ 'domain_realm': {'kerberos.org': 'R1', - 'example.com': 'R2', - 'mit.edu': 'R3'}} - no_rdns_conf = {'libdefaults': {'rdns': 'false'}} -@@ -28,7 +29,7 @@ def testbase(host, nametype, princhost, princrealm, env=None): - fail('Expected %s, got %s' % (expected, out)) - - def test(host, princhost, princrealm): -- # Test with the host-based name type in the default environment. -+ # Test with the host-based name type with canonicalization enabled. - testbase(host, 'srv-hst', princhost, princrealm) - - def testnc(host, princhost, princrealm): -diff --git a/src/util/k5test.py b/src/util/k5test.py -index eea92275d..5196cfa43 100644 ---- a/src/util/k5test.py -+++ b/src/util/k5test.py -@@ -193,7 +193,10 @@ Scripts may use the following functions and variables: - - * plugins: The plugin directory in the build tree (absolute path). - --* hostname: This machine's fully-qualified domain name. -+* hostname: The local hostname as it will initially appear in -+ krb5_sname_to_principal() results. (Shortname qualification is -+ turned off in the test environment to make this value easy to -+ discover from Python.) - - * null_input: A file opened to read /dev/null. - -@@ -525,23 +528,6 @@ def _find_srctop(): - return os.path.abspath(root) - - --# Return the local hostname as it will be canonicalized by --# krb5_sname_to_principal. We can't simply use socket.getfqdn() --# because it explicitly prefers results containing periods and --# krb5_sname_to_principal doesn't care. --def _get_hostname(): -- hostname = socket.gethostname() -- try: -- ai = socket.getaddrinfo(hostname, None, 0, 0, 0, socket.AI_CANONNAME) -- except socket.gaierror as e: -- fail('Local hostname "%s" does not resolve: %s.' % (hostname, e[1])) -- (family, socktype, proto, canonname, sockaddr) = ai[0] -- try: -- name = socket.getnameinfo(sockaddr, socket.NI_NAMEREQD) -- except socket.gaierror: -- return canonname.lower() -- return name[0].lower() -- - # Parse command line arguments, setting global option variables. Also - # sets the global variable args to the positional arguments, which may - # be used by the test script. -@@ -1263,6 +1249,7 @@ _default_krb5_conf = { - 'libdefaults': { - 'default_realm': '$realm', - 'dns_lookup_kdc': 'false', -+ 'qualify_shortname': '', - 'plugin_base_dir': '$plugins'}, - 'realms': {'$realm': { - 'kdc': '$hostname:$port0', -@@ -1356,7 +1343,7 @@ buildtop = _find_buildtop() - srctop = _find_srctop() - plugins = os.path.join(buildtop, 'plugins') - runenv = _import_runenv() --hostname = _get_hostname() -+hostname = socket.gethostname().lower() - null_input = open(os.devnull, 'r') - - # A DB pass is a tuple of: name, kdc_conf. diff --git a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch index 2bdd0a3..b91c81b 100644 --- a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch +++ b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch @@ -1,4 +1,4 @@ -From 3f873868fb08b77da2d30e164a0ef6c71c17c607 Mon Sep 17 00:00:00 2001 +From 63b526ffbdd932dffd5bc1d4a2b3ef6300208fb8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 15 Jul 2020 15:42:20 -0400 Subject: [PATCH] Ignore bad enctypes in krb5_string_to_keysalts() diff --git a/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch b/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch index 649caa4..5a1cad7 100644 --- a/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch +++ b/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch @@ -1,4 +1,4 @@ -From 3ea1d6296ced3a998e79356f9be212e4c5e6a5d5 Mon Sep 17 00:00:00 2001 +From bfc91774e1bf67b544d38abe10b41cdb76e30d8c Mon Sep 17 00:00:00 2001 From: Alexander Scheel Date: Wed, 5 Jul 2017 11:38:30 -0400 Subject: [PATCH] Implement GSS_C_CHANNEL_BOUND_FLAG diff --git a/Implement-KERB_AP_OPTIONS_CBT-server-side.patch b/Implement-KERB_AP_OPTIONS_CBT-server-side.patch index 41cf5f0..7757547 100644 --- a/Implement-KERB_AP_OPTIONS_CBT-server-side.patch +++ b/Implement-KERB_AP_OPTIONS_CBT-server-side.patch @@ -1,4 +1,4 @@ -From 6407bf087fe53088d91efd09df736e979cd4e8db Mon Sep 17 00:00:00 2001 +From 49e5ab0f11287dd2fd87de02abf14e63e5040c5b Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Mon, 9 Mar 2020 16:04:21 +0100 Subject: [PATCH] Implement KERB_AP_OPTIONS_CBT (server side) diff --git a/Improve-negoex_parse_token-code-hygiene.patch b/Improve-negoex_parse_token-code-hygiene.patch index f6b42a6..fd16725 100644 --- a/Improve-negoex_parse_token-code-hygiene.patch +++ b/Improve-negoex_parse_token-code-hygiene.patch @@ -1,4 +1,4 @@ -From c726a72c68244129eb08b840b92144acfa776573 Mon Sep 17 00:00:00 2001 +From 409a8920e13cd14fec8533c1ff864de92d292178 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 9 Jun 2020 16:23:37 -0400 Subject: [PATCH] Improve negoex_parse_token() code hygiene diff --git a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch index d0db74b..2514e20 100644 --- a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch +++ b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch @@ -1,4 +1,4 @@ -From c36e826c70cb5b3bff8bd4371d47884cea30b3f4 Mon Sep 17 00:00:00 2001 +From 911f19b661cb13373ad3de4fb92015beb3647de7 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Sat, 6 Jun 2020 11:03:37 +0200 Subject: [PATCH] Omit PA_FOR_USER if we can't compute its checksum diff --git a/Pass-channel-bindings-through-SPNEGO.patch b/Pass-channel-bindings-through-SPNEGO.patch index 5ab5c07..1dff308 100644 --- a/Pass-channel-bindings-through-SPNEGO.patch +++ b/Pass-channel-bindings-through-SPNEGO.patch @@ -1,4 +1,4 @@ -From ee79bd43005245d3e5a2d3ec6d61146945e77717 Mon Sep 17 00:00:00 2001 +From 20ec2ee13c34bfae03d62662b25f2f7708d1a418 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 28 Apr 2020 18:15:55 +0200 Subject: [PATCH] Pass channel bindings through SPNEGO diff --git a/Refactor-krb5-GSS-checksum-handling.patch b/Refactor-krb5-GSS-checksum-handling.patch index 392d929..6e41865 100644 --- a/Refactor-krb5-GSS-checksum-handling.patch +++ b/Refactor-krb5-GSS-checksum-handling.patch @@ -1,4 +1,4 @@ -From a34b7c50e62c19f80d39ece6a72017dac781df64 Mon Sep 17 00:00:00 2001 +From 5037c0fe698ad00a8e8f53fdcfc3d3b1c3537aba Mon Sep 17 00:00:00 2001 From: Alexander Scheel Date: Fri, 30 Jun 2017 16:03:01 -0400 Subject: [PATCH] Refactor krb5 GSS checksum handling diff --git a/Remove-resolver-test-utility.patch b/Remove-resolver-test-utility.patch index 6602185..d70f078 100644 --- a/Remove-resolver-test-utility.patch +++ b/Remove-resolver-test-utility.patch @@ -1,4 +1,4 @@ -From 85bb5fe5a11708b78e9f0bd3a3b34999b6c888a7 Mon Sep 17 00:00:00 2001 +From 3eb685873f5390a3af518ac86e99f6863750ada3 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 28 May 2020 18:41:02 -0400 Subject: [PATCH] Remove resolver test utility diff --git a/Use-two-queues-for-concurrent-t_otp.py-daemons.patch b/Use-two-queues-for-concurrent-t_otp.py-daemons.patch index 33da6f5..7a66d35 100644 --- a/Use-two-queues-for-concurrent-t_otp.py-daemons.patch +++ b/Use-two-queues-for-concurrent-t_otp.py-daemons.patch @@ -1,4 +1,4 @@ -From 8e08f01d73ddca1b828788710ec6bb3e0354727a Mon Sep 17 00:00:00 2001 +From ccc6e0fae1fc000e10e51ffa45cc59674038714a Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 4 Mar 2020 17:18:51 -0500 Subject: [PATCH] Use two queues for concurrent t_otp.py daemons diff --git a/krb5.spec b/krb5.spec index 8e6cb4e..6d25581 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 13%{?dist} +Release: 14%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -57,7 +57,6 @@ Patch17: Pass-gss_localname-through-SPNEGO.patch Patch18: Omit-KDC-indicator-check-for-S4U2Self-requests.patch Patch19: Fix-typo-in-in-in-the-ksu-man-page.patch Patch21: Replace-gssrpc-tests-with-a-Python-script.patch -Patch22: Default-dns_canonicalize_hostname-to-fallback.patch Patch23: Remove-resolver-test-utility.patch Patch24: Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch Patch25: Improve-negoex_parse_token-code-hygiene.patch @@ -624,6 +623,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Jul 31 2020 Robbie Harwood - 1.18.2-14 +- Revert qualify_shortname changes + * Tue Jul 28 2020 Fedora Release Engineering - 1.18.2-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild From d0cfa344c7bb9bd1cd31606d7a1c6978c3e7f30d Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 1 Aug 2020 03:47:16 +0000 Subject: [PATCH 186/304] - Second attempt - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- krb5.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 6d25581..9ce8b31 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 14%{?dist} +Release: 15%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -623,6 +623,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Sat Aug 01 2020 Fedora Release Engineering - 1.18.2-15 +- Second attempt - Rebuilt for + https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + * Fri Jul 31 2020 Robbie Harwood - 1.18.2-14 - Revert qualify_shortname changes From 8be525213668ed9f1b144e6fe4beaee4d135c1a2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 3 Aug 2020 19:30:15 +0000 Subject: [PATCH 187/304] Disable tests on s390x Resolves: #1863952 --- krb5.spec | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 9ce8b31..c5818f4 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 15%{?dist} +Release: 16%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -300,6 +300,12 @@ sphinx-build -a -b html -t pathsubs doc build-html rm -fr build-html/_sources %check + +# There are 0 test machines for this architecture, very few builders, and +# they're not very well provisioned / maintained. I can't support it. +# Patches welcome, but there's nothing I can do - it fails more than half the +# time for no discernable reason. +%ifnarch s390x pushd src # ugh. COPR doesn't expose the keyring, so try to cope. @@ -310,6 +316,7 @@ keyctl list @u &>/dev/null || KEYCTL=: # tests with a new one. $KEYCTL session - make check OFFLINE=yes TMPDIR=%{_tmppath} popd +%endif %install [ "$RPM_BUILD_ROOT" != '/' ] && rm -rf -- "$RPM_BUILD_ROOT" @@ -623,6 +630,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Aug 03 2020 Robbie Harwood - 1.18.2-16 +- Disable tests on s390x +- Resolves: #1863952 + * Sat Aug 01 2020 Fedora Release Engineering - 1.18.2-15 - Second attempt - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild From 4530bb6de9f097108be1cc64007685e68c7d3844 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 3 Aug 2020 15:39:37 -0400 Subject: [PATCH 188/304] Revert qualify_shortname removal --- Add-channel-bindings-tests.patch | 2 +- ...client_aware_channel_bindings-option.patch | 6 +- ...ss_unwrap_iov-of-unpadded-RC4-tokens.patch | 2 +- ...ns_canonicalize_hostname-to-fallback.patch | 371 ++++++++++++++++++ ...-enctypes-in-krb5_string_to_keysalts.patch | 2 +- Implement-GSS_C_CHANNEL_BOUND_FLAG.patch | 2 +- ...ment-KERB_AP_OPTIONS_CBT-server-side.patch | 2 +- Improve-negoex_parse_token-code-hygiene.patch | 2 +- ...SER-if-we-can-t-compute-its-checksum.patch | 2 +- Pass-channel-bindings-through-SPNEGO.patch | 2 +- Refactor-krb5-GSS-checksum-handling.patch | 2 +- Remove-resolver-test-utility.patch | 2 +- ...eues-for-concurrent-t_otp.py-daemons.patch | 2 +- krb5.spec | 6 +- 14 files changed, 390 insertions(+), 15 deletions(-) create mode 100644 Default-dns_canonicalize_hostname-to-fallback.patch diff --git a/Add-channel-bindings-tests.patch b/Add-channel-bindings-tests.patch index a152fa2..b758c79 100644 --- a/Add-channel-bindings-tests.patch +++ b/Add-channel-bindings-tests.patch @@ -1,4 +1,4 @@ -From 5f98c9d9ff16f3760ac26304cfdb87bf53bc8628 Mon Sep 17 00:00:00 2001 +From 3e92520c1417f22447751cd9172d5ab30c2e0ad8 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Fri, 20 Mar 2020 00:17:28 +0100 Subject: [PATCH] Add channel bindings tests diff --git a/Add-client_aware_channel_bindings-option.patch b/Add-client_aware_channel_bindings-option.patch index e8b5374..012ce8d 100644 --- a/Add-client_aware_channel_bindings-option.patch +++ b/Add-client_aware_channel_bindings-option.patch @@ -1,4 +1,4 @@ -From bb7425941f5d84a53e30721c20fbfc714157f082 Mon Sep 17 00:00:00 2001 +From 2a08fe3d2d1972df4ffe37d4bb64b161889ff988 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 10 Mar 2020 13:13:17 +0100 Subject: [PATCH] Add client_aware_channel_bindings option @@ -20,10 +20,10 @@ ticket: 8900 3 files changed, 98 insertions(+), 86 deletions(-) diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 1d2aa7f68..1d8ffc1e4 100644 +index a7e7a29d1..7f2879640 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst -@@ -383,6 +383,12 @@ The libdefaults section may contain any of the following relations: +@@ -382,6 +382,12 @@ The libdefaults section may contain any of the following relations: credentials will fail if the client machine does not have a keytab. The default value is false. diff --git a/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch b/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch index 716fa8a..4698963 100644 --- a/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch +++ b/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch @@ -1,4 +1,4 @@ -From 297857dec4f82a802caa734670b57f0a18d942e2 Mon Sep 17 00:00:00 2001 +From bedbb5ee1ad821b91f00d30361985e6863c0e6ba Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 11 Jul 2020 21:57:30 -0400 Subject: [PATCH] Allow gss_unwrap_iov() of unpadded RC4 tokens diff --git a/Default-dns_canonicalize_hostname-to-fallback.patch b/Default-dns_canonicalize_hostname-to-fallback.patch new file mode 100644 index 0000000..ef80329 --- /dev/null +++ b/Default-dns_canonicalize_hostname-to-fallback.patch @@ -0,0 +1,371 @@ +From 07179e38e5ee72e82ebc77a1c8d73e34905268b7 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 27 May 2020 18:48:35 -0400 +Subject: [PATCH] Default dns_canonicalize_hostname to "fallback" + +This change should mitigate some of the pain caused by the rdns=true +default (generally associated with unwanted PTR records that cannot +easily be changed), with a minimum of fallout. + +Update the documentation and tests accordingly. In test environments, +disable qualify_shortname and use the uncanonicalized system hostname +(lowercased) to match the initial sn2princ result. + +ticket: 8911 (new) +--- + doc/admin/appl_servers.rst | 14 +++--- + doc/admin/conf_files/krb5_conf.rst | 9 ++-- + doc/admin/princ_dns.rst | 44 +++++++++++-------- + src/kadmin/testing/proto/krb5.conf.proto | 8 ++-- + src/kadmin/testing/scripts/env-setup.shin | 4 +- + src/kadmin/testing/scripts/init_db | 3 +- + src/kadmin/testing/scripts/start_servers | 3 +- + .../testing/scripts/start_servers_local | 2 +- + .../kadm5/unit-test/api.current/init-v2.exp | 6 +-- + src/lib/krb5/krb/init_ctx.c | 2 +- + src/tests/dejagnu/config/default.exp | 5 +-- + src/tests/t_sn2princ.py | 5 ++- + src/util/k5test.py | 25 +++-------- + 13 files changed, 58 insertions(+), 72 deletions(-) + +diff --git a/doc/admin/appl_servers.rst b/doc/admin/appl_servers.rst +index 5232db9af..afdf30297 100644 +--- a/doc/admin/appl_servers.rst ++++ b/doc/admin/appl_servers.rst +@@ -115,14 +115,12 @@ Getting DNS information correct + ------------------------------- + + Several aspects of Kerberos rely on name service. When a hostname is +-used to name a service, the Kerberos library canonicalizes the +-hostname using forward and reverse name resolution. (The reverse name +-resolution step can be turned off using the **rdns** variable in +-:ref:`libdefaults`.) The result of this canonicalization must match +-the principal entry in the host's keytab, or authentication will fail. +- +-Each host's canonical name must be the fully-qualified host name +-(including the domain), and each host's IP address must ++used to name a service, clients may canonicalize the hostname using ++forward and possibly reverse name resolution. The result of this ++canonicalization must match the principal entry in the host's keytab, ++or authentication will fail. To work with all client canonicalization ++configurations, each host's canonical name must be the fully-qualified ++host name (including the domain), and each host's IP address must + reverse-resolve to the canonical name. + + Configuration of hostnames varies by operating system. On the +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index 1d2aa7f68..a7e7a29d1 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -188,11 +188,10 @@ The libdefaults section may contain any of the following relations: + hostnames for use in service principal names. Setting this flag + to false can improve security by reducing reliance on DNS, but + means that short hostnames will not be canonicalized to +- fully-qualified hostnames. The default value is true. +- +- If this option is set to ``fallback`` (new in release 1.18), DNS +- canonicalization will only be performed the server hostname is not +- found with the original name when requesting credentials. ++ fully-qualified hostnames. If this option is set to ``fallback`` (new ++ in release 1.18), DNS canonicalization will only be performed the ++ server hostname is not found with the original name when ++ requesting credentials. The default value is ``fallback``. + + **dns_lookup_kdc** + Indicate whether DNS SRV records should be used to locate the KDCs +diff --git a/doc/admin/princ_dns.rst b/doc/admin/princ_dns.rst +index e1d823f27..32a269afc 100644 +--- a/doc/admin/princ_dns.rst ++++ b/doc/admin/princ_dns.rst +@@ -31,27 +31,35 @@ based on rotating ``CNAME`` records in DNS. + Service principal canonicalization + ---------------------------------- + +-MIT Kerberos clients currently always do forward resolution (looking +-up the IPv4 and possibly IPv6 addresses using ``getaddrinfo()``) of +-the hostname part of a host-based service principal to canonicalize +-the hostname. They obtain the "canonical" name of the host when doing +-so. By default, MIT Kerberos clients will also then do reverse DNS +-resolution (looking up the hostname associated with the IPv4 or IPv6 +-address using ``getnameinfo()``) of the hostname. Using the +-:ref:`krb5.conf(5)` setting:: ++In the MIT krb5 client library, canonicalization of host-based service ++principals is controlled by the **dns_canonicalize_hostname**, ++**rnds**, and **qualify_shortname** variables in :ref:`libdefaults`. + +- [libdefaults] +- rdns = false ++If **dns_canonicalize_hostname** is set to ``true`` (the default value ++before release 1.19), the client performs forward resolution by ++looking up the IPv4 and/or IPv6 addresses of the hostname using ++``getaddrinfo()``. This process will typically add a domain suffix to ++the hostname if needed, and follow CNAME records in the DNS. If ++**rdns** is also set to ``true`` (the default), the client will then ++perform a reverse lookup of the first returned Internet address using ++``getnameinfo()``, finding the name associated with the PTR record. + +-will disable reverse DNS lookup on clients. The default setting is +-"true". ++If **dns_canonicalize_hostname** is set to ``false``, the hostname is ++not canonicalized using DNS. If the hostname has only one component ++(i.e. it contains no "." characters), the host's primary DNS search ++domain will be appended, if there is one. The **qualify_shortname** ++variable can be used to override or disable this suffix. ++ ++If **dns_canonicalize_hostname** is set to ``fallback`` (the default ++value in release 1.19 and later), the hostname is initially treated ++according to the rules for ``dns_canonicalize_hostname=false``. If a ++ticket request fails because the service principal is unknown, it the ++hostname will be canonicalized according to the rules for ++``dns_canonicalize_hostname=true`` and the request will be retried. ++ ++In all cases, the hostname is converted to lowercase, and any trailing ++dot is removed. + +-Operating system bugs may prevent a setting of ``rdns = false`` from +-disabling reverse DNS lookup. Some versions of GNU libc have a bug in +-``getaddrinfo()`` that cause them to look up ``PTR`` records even when +-not required. MIT Kerberos releases krb5-1.10.2 and newer have a +-workaround for this problem, as does the krb5-1.9.x series as of +-release krb5-1.9.4. + + + Reverse DNS mismatches +diff --git a/src/kadmin/testing/proto/krb5.conf.proto b/src/kadmin/testing/proto/krb5.conf.proto +index e710852d4..c0af716a5 100644 +--- a/src/kadmin/testing/proto/krb5.conf.proto ++++ b/src/kadmin/testing/proto/krb5.conf.proto +@@ -2,19 +2,19 @@ + default_realm = __REALM__ + default_keytab_name = FILE:__K5ROOT__/keytab + dns_fallback = no ++ qualify_shortname = "" + plugin_base_dir = __PLUGIN_DIR__ + allow_weak_crypto = true + + [realms] + __REALM__ = { +- kdc = __KDCHOST__:1750 +- admin_server = __KDCHOST__:1751 ++ kdc = __HOSTNAME__:1750 ++ admin_server = __HOSTNAME__:1751 + database_module = foobar_db2_module_blah + } + + [domain_realm] +- __LOCALHOST__ = __REALM__ +- __KDCHOST__ = __REALM__ ++ __HOSTNAME__ = __REALM__ + + [logging] + admin_server = FILE:__K5ROOT__/syslog +diff --git a/src/kadmin/testing/scripts/env-setup.shin b/src/kadmin/testing/scripts/env-setup.shin +index 969c5340c..88f8ad1aa 100755 +--- a/src/kadmin/testing/scripts/env-setup.shin ++++ b/src/kadmin/testing/scripts/env-setup.shin +@@ -71,8 +71,8 @@ BSDDB_DUMP=$TESTDIR/util/bsddb_dump; export BSDDB_DUMP + CLNTTCL=$TESTDIR/util/kadm5_clnt_tcl; export CLNTTCL + SRVTCL=$TESTDIR/util/kadm5_srv_tcl; export SRVTCL + +-QUALNAME=`$BUILDTOP/tests/resolve/resolve -q | tr '[A-Z]' '[a-z]'` +-export QUALNAME ++HOSTNAME=`hostname | tr '[A-Z]' '[a-z]'` ++export HOSTNAME + + KRB5_CONFIG=$K5ROOT/krb5.conf; export KRB5_CONFIG + KRB5_KDC_PROFILE=$K5ROOT/kdc.conf; export KRB5_KDC_PROFILE +diff --git a/src/kadmin/testing/scripts/init_db b/src/kadmin/testing/scripts/init_db +index e65826c96..216f62793 100755 +--- a/src/kadmin/testing/scripts/init_db ++++ b/src/kadmin/testing/scripts/init_db +@@ -79,8 +79,7 @@ fi + # done + + sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ +- -e "s/__KDCHOST__/$QUALNAME/g" \ +- -e "s/__LOCALHOST__/$QUALNAME/g" \ ++ -e "s/__HOSTNAME__/$HOSTNAME/g" \ + -e "s#__MODDIR__#$MODDIR#g" \ + < $STESTDIR/proto/krb5.conf.proto > $K5ROOT/krb5.conf + sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ +diff --git a/src/kadmin/testing/scripts/start_servers b/src/kadmin/testing/scripts/start_servers +index f23df0682..05519e4ee 100755 +--- a/src/kadmin/testing/scripts/start_servers ++++ b/src/kadmin/testing/scripts/start_servers +@@ -36,8 +36,7 @@ if [ $local = 0 ]; then + + # Fix up the local krb5.conf to point to the remote + sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ +- -e "s/__KDCHOST__/$hostname/g" \ +- -e "s/__LOCALHOST__/$QUALNAME/g" \ ++ -e "s/__HOSTNAME__/$HOSTNAME/g" \ + -e "s#__MODDIR__#$TOP/../plugins/kdb#g"\ + -e "s#__PLUGIN_DIR__#$TOP/../plugins#g"\ + < $STESTDIR/proto/krb5.conf.proto > $K5ROOT/krb5.conf +diff --git a/src/kadmin/testing/scripts/start_servers_local b/src/kadmin/testing/scripts/start_servers_local +index 998ef9164..858e88031 100755 +--- a/src/kadmin/testing/scripts/start_servers_local ++++ b/src/kadmin/testing/scripts/start_servers_local +@@ -79,7 +79,7 @@ cat - > /tmp/start_servers_local$$ <<\EOF + if { [catch { + source $env(STOP)/testing/tcl/util.t + set r $env(REALM) +- set q $env(QUALNAME) ++ set q $env(HOSTNAME) + puts stdout [kadm5_init $env(SRVTCL) mrroot null \ + [config_params {KADM5_CONFIG_REALM} $r] \ + $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 server_handle] +diff --git a/src/lib/kadm5/unit-test/api.current/init-v2.exp b/src/lib/kadm5/unit-test/api.current/init-v2.exp +index 7a353d4e9..47764c212 100644 +--- a/src/lib/kadm5/unit-test/api.current/init-v2.exp ++++ b/src/lib/kadm5/unit-test/api.current/init-v2.exp +@@ -3,18 +3,14 @@ load_lib lib.t + api_exit + api_start + +-if ![info exists RESOLVE] { +- set RESOLVE [findfile $objdir/../../../tests/resolve/resolve] +-} + proc get_hostname { } { +- global RESOLVE + global hostname + + if {[info exists hostname]} { + return 1 + } + +- catch "exec $RESOLVE -q >myname" exec_output ++ catch "exec hostname >myname" exec_output + if ![string match "" $exec_output] { + send_log "$exec_output\n" + verbose $exec_output +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index 9a4741fa6..0b8ae6714 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -237,7 +237,7 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + ctx->enforce_ok_as_delegate = tmp; + + retval = get_tristate(ctx, KRB5_CONF_DNS_CANONICALIZE_HOSTNAME, "fallback", +- CANONHOST_FALLBACK, 1, &tmp); ++ CANONHOST_FALLBACK, CANONHOST_FALLBACK, &tmp); + if (retval) + goto cleanup; + ctx->dns_canonicalize_hostname = tmp; +diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp +index 4d8c917cd..1e7777f1e 100644 +--- a/src/tests/dejagnu/config/default.exp ++++ b/src/tests/dejagnu/config/default.exp +@@ -268,7 +268,6 @@ foreach i { + {KTUTIL $objdir/../../kadmin/ktutil/ktutil} + {KLIST $objdir/../../clients/klist/klist} + {KDESTROY $objdir/../../clients/kdestroy/kdestroy} +- {RESOLVE $objdir/../resolve/resolve} + {T_INETD $objdir/t_inetd} + {KPROPLOG $objdir/../../kprop/kproplog} + {KPASSWD $objdir/../../clients/kpasswd/kpasswd} +@@ -462,7 +461,6 @@ proc setup_runtime_env { } { + # 0 on failure. + + proc get_hostname { } { +- global RESOLVE + global hostname + global tmppwd + +@@ -472,7 +470,7 @@ proc get_hostname { } { + + envstack_push + setup_runtime_env +- catch "exec $RESOLVE -q >$tmppwd/hostname" exec_output ++ catch "exec hostname >$tmppwd/hostname" exec_output + envstack_pop + if ![string match "" $exec_output] { + verbose -log $exec_output +@@ -710,6 +708,7 @@ proc setup_krb5_conf { {type client} } { + puts $conffile "\[libdefaults\]" + puts $conffile " default_realm = $REALMNAME" + puts $conffile " dns_lookup_kdc = false" ++ puts $conffile " qualify_shortname = \"\"" + if [info exists allow_weak_crypto($type)] { + puts $conffile " allow_weak_crypto = $allow_weak_crypto($type)" + } else { +diff --git a/src/tests/t_sn2princ.py b/src/tests/t_sn2princ.py +index 26dcb91c2..f3e187286 100755 +--- a/src/tests/t_sn2princ.py ++++ b/src/tests/t_sn2princ.py +@@ -2,7 +2,8 @@ from k5test import * + + offline = (len(args) > 0 and args[0] != "no") + +-conf = {'domain_realm': {'kerberos.org': 'R1', ++conf = {'libdefaults': {'dns_canonicalize_hostname': 'true'}, ++ 'domain_realm': {'kerberos.org': 'R1', + 'example.com': 'R2', + 'mit.edu': 'R3'}} + no_rdns_conf = {'libdefaults': {'rdns': 'false'}} +@@ -28,7 +29,7 @@ def testbase(host, nametype, princhost, princrealm, env=None): + fail('Expected %s, got %s' % (expected, out)) + + def test(host, princhost, princrealm): +- # Test with the host-based name type in the default environment. ++ # Test with the host-based name type with canonicalization enabled. + testbase(host, 'srv-hst', princhost, princrealm) + + def testnc(host, princhost, princrealm): +diff --git a/src/util/k5test.py b/src/util/k5test.py +index eea92275d..5196cfa43 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -193,7 +193,10 @@ Scripts may use the following functions and variables: + + * plugins: The plugin directory in the build tree (absolute path). + +-* hostname: This machine's fully-qualified domain name. ++* hostname: The local hostname as it will initially appear in ++ krb5_sname_to_principal() results. (Shortname qualification is ++ turned off in the test environment to make this value easy to ++ discover from Python.) + + * null_input: A file opened to read /dev/null. + +@@ -525,23 +528,6 @@ def _find_srctop(): + return os.path.abspath(root) + + +-# Return the local hostname as it will be canonicalized by +-# krb5_sname_to_principal. We can't simply use socket.getfqdn() +-# because it explicitly prefers results containing periods and +-# krb5_sname_to_principal doesn't care. +-def _get_hostname(): +- hostname = socket.gethostname() +- try: +- ai = socket.getaddrinfo(hostname, None, 0, 0, 0, socket.AI_CANONNAME) +- except socket.gaierror as e: +- fail('Local hostname "%s" does not resolve: %s.' % (hostname, e[1])) +- (family, socktype, proto, canonname, sockaddr) = ai[0] +- try: +- name = socket.getnameinfo(sockaddr, socket.NI_NAMEREQD) +- except socket.gaierror: +- return canonname.lower() +- return name[0].lower() +- + # Parse command line arguments, setting global option variables. Also + # sets the global variable args to the positional arguments, which may + # be used by the test script. +@@ -1263,6 +1249,7 @@ _default_krb5_conf = { + 'libdefaults': { + 'default_realm': '$realm', + 'dns_lookup_kdc': 'false', ++ 'qualify_shortname': '', + 'plugin_base_dir': '$plugins'}, + 'realms': {'$realm': { + 'kdc': '$hostname:$port0', +@@ -1356,7 +1343,7 @@ buildtop = _find_buildtop() + srctop = _find_srctop() + plugins = os.path.join(buildtop, 'plugins') + runenv = _import_runenv() +-hostname = _get_hostname() ++hostname = socket.gethostname().lower() + null_input = open(os.devnull, 'r') + + # A DB pass is a tuple of: name, kdc_conf. diff --git a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch index b91c81b..2bdd0a3 100644 --- a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch +++ b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch @@ -1,4 +1,4 @@ -From 63b526ffbdd932dffd5bc1d4a2b3ef6300208fb8 Mon Sep 17 00:00:00 2001 +From 3f873868fb08b77da2d30e164a0ef6c71c17c607 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 15 Jul 2020 15:42:20 -0400 Subject: [PATCH] Ignore bad enctypes in krb5_string_to_keysalts() diff --git a/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch b/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch index 5a1cad7..649caa4 100644 --- a/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch +++ b/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch @@ -1,4 +1,4 @@ -From bfc91774e1bf67b544d38abe10b41cdb76e30d8c Mon Sep 17 00:00:00 2001 +From 3ea1d6296ced3a998e79356f9be212e4c5e6a5d5 Mon Sep 17 00:00:00 2001 From: Alexander Scheel Date: Wed, 5 Jul 2017 11:38:30 -0400 Subject: [PATCH] Implement GSS_C_CHANNEL_BOUND_FLAG diff --git a/Implement-KERB_AP_OPTIONS_CBT-server-side.patch b/Implement-KERB_AP_OPTIONS_CBT-server-side.patch index 7757547..41cf5f0 100644 --- a/Implement-KERB_AP_OPTIONS_CBT-server-side.patch +++ b/Implement-KERB_AP_OPTIONS_CBT-server-side.patch @@ -1,4 +1,4 @@ -From 49e5ab0f11287dd2fd87de02abf14e63e5040c5b Mon Sep 17 00:00:00 2001 +From 6407bf087fe53088d91efd09df736e979cd4e8db Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Mon, 9 Mar 2020 16:04:21 +0100 Subject: [PATCH] Implement KERB_AP_OPTIONS_CBT (server side) diff --git a/Improve-negoex_parse_token-code-hygiene.patch b/Improve-negoex_parse_token-code-hygiene.patch index fd16725..f6b42a6 100644 --- a/Improve-negoex_parse_token-code-hygiene.patch +++ b/Improve-negoex_parse_token-code-hygiene.patch @@ -1,4 +1,4 @@ -From 409a8920e13cd14fec8533c1ff864de92d292178 Mon Sep 17 00:00:00 2001 +From c726a72c68244129eb08b840b92144acfa776573 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 9 Jun 2020 16:23:37 -0400 Subject: [PATCH] Improve negoex_parse_token() code hygiene diff --git a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch index 2514e20..d0db74b 100644 --- a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch +++ b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch @@ -1,4 +1,4 @@ -From 911f19b661cb13373ad3de4fb92015beb3647de7 Mon Sep 17 00:00:00 2001 +From c36e826c70cb5b3bff8bd4371d47884cea30b3f4 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Sat, 6 Jun 2020 11:03:37 +0200 Subject: [PATCH] Omit PA_FOR_USER if we can't compute its checksum diff --git a/Pass-channel-bindings-through-SPNEGO.patch b/Pass-channel-bindings-through-SPNEGO.patch index 1dff308..5ab5c07 100644 --- a/Pass-channel-bindings-through-SPNEGO.patch +++ b/Pass-channel-bindings-through-SPNEGO.patch @@ -1,4 +1,4 @@ -From 20ec2ee13c34bfae03d62662b25f2f7708d1a418 Mon Sep 17 00:00:00 2001 +From ee79bd43005245d3e5a2d3ec6d61146945e77717 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 28 Apr 2020 18:15:55 +0200 Subject: [PATCH] Pass channel bindings through SPNEGO diff --git a/Refactor-krb5-GSS-checksum-handling.patch b/Refactor-krb5-GSS-checksum-handling.patch index 6e41865..392d929 100644 --- a/Refactor-krb5-GSS-checksum-handling.patch +++ b/Refactor-krb5-GSS-checksum-handling.patch @@ -1,4 +1,4 @@ -From 5037c0fe698ad00a8e8f53fdcfc3d3b1c3537aba Mon Sep 17 00:00:00 2001 +From a34b7c50e62c19f80d39ece6a72017dac781df64 Mon Sep 17 00:00:00 2001 From: Alexander Scheel Date: Fri, 30 Jun 2017 16:03:01 -0400 Subject: [PATCH] Refactor krb5 GSS checksum handling diff --git a/Remove-resolver-test-utility.patch b/Remove-resolver-test-utility.patch index d70f078..6602185 100644 --- a/Remove-resolver-test-utility.patch +++ b/Remove-resolver-test-utility.patch @@ -1,4 +1,4 @@ -From 3eb685873f5390a3af518ac86e99f6863750ada3 Mon Sep 17 00:00:00 2001 +From 85bb5fe5a11708b78e9f0bd3a3b34999b6c888a7 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 28 May 2020 18:41:02 -0400 Subject: [PATCH] Remove resolver test utility diff --git a/Use-two-queues-for-concurrent-t_otp.py-daemons.patch b/Use-two-queues-for-concurrent-t_otp.py-daemons.patch index 7a66d35..33da6f5 100644 --- a/Use-two-queues-for-concurrent-t_otp.py-daemons.patch +++ b/Use-two-queues-for-concurrent-t_otp.py-daemons.patch @@ -1,4 +1,4 @@ -From ccc6e0fae1fc000e10e51ffa45cc59674038714a Mon Sep 17 00:00:00 2001 +From 8e08f01d73ddca1b828788710ec6bb3e0354727a Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 4 Mar 2020 17:18:51 -0500 Subject: [PATCH] Use two queues for concurrent t_otp.py daemons diff --git a/krb5.spec b/krb5.spec index c5818f4..4a61316 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 16%{?dist} +Release: 17%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -57,6 +57,7 @@ Patch17: Pass-gss_localname-through-SPNEGO.patch Patch18: Omit-KDC-indicator-check-for-S4U2Self-requests.patch Patch19: Fix-typo-in-in-in-the-ksu-man-page.patch Patch21: Replace-gssrpc-tests-with-a-Python-script.patch +Patch22: Default-dns_canonicalize_hostname-to-fallback.patch Patch23: Remove-resolver-test-utility.patch Patch24: Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch Patch25: Improve-negoex_parse_token-code-hygiene.patch @@ -630,6 +631,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Aug 03 2020 Robbie Harwood - 1.18.2-17 +- Revert qualify_shortname removal + * Mon Aug 03 2020 Robbie Harwood - 1.18.2-16 - Disable tests on s390x - Resolves: #1863952 From 2091f2939975551a5bfbe8b53ee5d74fa588f03e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 4 Aug 2020 14:24:08 -0400 Subject: [PATCH 189/304] Fix leak in KERB_AP_OPTIONS_CBT server support --- ...n-KERB_AP_OPTIONS_CBT-server-support.patch | 59 +++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 64 insertions(+), 1 deletion(-) create mode 100644 Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch diff --git a/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch b/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch new file mode 100644 index 0000000..54f2550 --- /dev/null +++ b/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch @@ -0,0 +1,59 @@ +From 044e2209586fd1935d9a637df76d52f48c4f3e6e Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 24 Jul 2020 16:05:24 -0400 +Subject: [PATCH] Fix leak in KERB_AP_OPTIONS_CBT server support + +In check_cbt(), use a local variable to hold the retrieved authdata +list, and free it before returning. + +ticket: 8900 +(cherry picked from commit bf2ddff13c178e0c291f8fb382b040080d159e4f) +--- + src/lib/gssapi/krb5/accept_sec_context.c | 23 +++++++++++++---------- + 1 file changed, 13 insertions(+), 10 deletions(-) + +diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c +index 175a24c4e..3d5b84b15 100644 +--- a/src/lib/gssapi/krb5/accept_sec_context.c ++++ b/src/lib/gssapi/krb5/accept_sec_context.c +@@ -433,27 +433,30 @@ static const uint8_t null_cb[CB_MD5_LEN]; + /* Look for AP_OPTIONS in authdata. If present and the options include + * KERB_AP_OPTIONS_CBT, set *cbt_out to true. */ + static krb5_error_code +-check_cbt(krb5_context context, krb5_authdata **authdata, ++check_cbt(krb5_context context, krb5_authdata *const *authdata, + krb5_boolean *cbt_out) + { + krb5_error_code code; ++ krb5_authdata **ad; + uint32_t ad_ap_options; + const uint32_t KERB_AP_OPTIONS_CBT = 0x4000; + + *cbt_out = FALSE; + + code = krb5_find_authdata(context, NULL, authdata, +- KRB5_AUTHDATA_AP_OPTIONS, &authdata); +- if (code || authdata == NULL) ++ KRB5_AUTHDATA_AP_OPTIONS, &ad); ++ if (code || ad == NULL) + return code; +- if (authdata[1] != NULL || authdata[0]->length != 4) +- return KRB5KRB_AP_ERR_MSG_TYPE; ++ if (ad[1] != NULL || ad[0]->length != 4) { ++ code = KRB5KRB_AP_ERR_MSG_TYPE; ++ } else { ++ ad_ap_options = load_32_le(ad[0]->contents); ++ if (ad_ap_options & KERB_AP_OPTIONS_CBT) ++ *cbt_out = TRUE; ++ } + +- ad_ap_options = load_32_le(authdata[0]->contents); +- if (ad_ap_options & KERB_AP_OPTIONS_CBT) +- *cbt_out = TRUE; +- +- return 0; ++ krb5_free_authdata(context, ad); ++ return code; + } + + /* diff --git a/krb5.spec b/krb5.spec index 4a61316..7199f35 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 17%{?dist} +Release: 18%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -70,6 +70,7 @@ Patch31: Add-channel-bindings-tests.patch Patch32: Use-two-queues-for-concurrent-t_otp.py-daemons.patch Patch33: Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch Patch34: Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch +Patch35: Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -631,6 +632,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Aug 04 2020 Robbie Harwood - 1.18.2-18 +- Fix leak in KERB_AP_OPTIONS_CBT server support + * Mon Aug 03 2020 Robbie Harwood - 1.18.2-17 - Revert qualify_shortname removal From c59e4a1c673512e66b4f5cfe53a1c64f7dd6b635 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 7 Aug 2020 19:03:02 -0400 Subject: [PATCH 190/304] Expand dns_canonicalize_hostname=fallback support --- ...-S4U2Proxy-requests-by-second-ticket.patch | 327 +++++ ...ate-hostbased-principals-in-new-KDBs.patch | 195 +++ ...s_canonicalize_host-fallback-support.patch | 1190 +++++++++++++++++ Prevent-deletion-of-K-M.patch | 45 + ...or-cache-checking-in-TGS-client-code.patch | 188 +++ Try-kadmin-admin-first-in-libkadm5clnt.patch | 159 +++ krb5.spec | 11 +- 7 files changed, 2114 insertions(+), 1 deletion(-) create mode 100644 Cache-S4U2Proxy-requests-by-second-ticket.patch create mode 100644 Don-t-create-hostbased-principals-in-new-KDBs.patch create mode 100644 Expand-dns_canonicalize_host-fallback-support.patch create mode 100644 Prevent-deletion-of-K-M.patch create mode 100644 Refactor-cache-checking-in-TGS-client-code.patch create mode 100644 Try-kadmin-admin-first-in-libkadm5clnt.patch diff --git a/Cache-S4U2Proxy-requests-by-second-ticket.patch b/Cache-S4U2Proxy-requests-by-second-ticket.patch new file mode 100644 index 0000000..01532bf --- /dev/null +++ b/Cache-S4U2Proxy-requests-by-second-ticket.patch @@ -0,0 +1,327 @@ +From 158ce9222351216507da39d7bb4233469603e647 Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Tue, 21 Jul 2020 00:40:06 +0200 +Subject: [PATCH] Cache S4U2Proxy requests by second ticket + +krb5_get_credentials() does not know the client principal for an +S4U2Proxy request until the end, because it is in the encrypted part +of the evidence ticket. However, we can check the cache by second +ticket, since all S4U2Proxy requests in a cache will generally be made +with the same evidence ticket. + +In the ccache types, allow mcreds->client and mcreds->server to be +NULL (as Heimdal does) to ignore them for the purpose of matching. In +krb5int_construct_matching_creds(), set mcreds->client to NULL for +S4U2Proxy requests. Add a cache check to +k5_get_proxy_cred_from_kdc(), and remove the cache check from +krb5_get_credentials_for_proxy() and the krb5 mech's +get_credentials(). + +In get_proxy_cred_from_kdc(), fix a bug where cross-realm S4U2Proxy +would cache the evidence ticket used in the final request, rather than +the original evidence ticket. + +[ghudson@mit.edu: debugged cache check and cross-realm caching; +switched from new flag to null matching cred principals; wrote commit +message] + +ticket: 8931 (new) +(cherry picked from commit 148b317e1eb5df28dad96679cb4b8a07c62d4786) +--- + src/lib/gssapi/krb5/init_sec_context.c | 61 ++++++++++++-------------- + src/lib/krb5/ccache/cc_retr.c | 13 +++--- + src/lib/krb5/ccache/ccapi/stdcc_util.c | 30 ++++++------- + src/lib/krb5/ccache/ccfns.c | 3 +- + src/lib/krb5/krb/get_creds.c | 5 +++ + src/lib/krb5/krb/s4u_creds.c | 58 ++++++++++++------------ + src/tests/s4u2proxy.c | 3 ++ + 7 files changed, 88 insertions(+), 85 deletions(-) + +diff --git a/src/lib/gssapi/krb5/init_sec_context.c b/src/lib/gssapi/krb5/init_sec_context.c +index 3f77157c9..823656037 100644 +--- a/src/lib/gssapi/krb5/init_sec_context.c ++++ b/src/lib/gssapi/krb5/init_sec_context.c +@@ -165,44 +165,37 @@ static krb5_error_code get_credentials(context, cred, server, now, + goto cleanup; + } + +- /* +- * For IAKERB or constrained delegation, only check the cache in this step. +- * For IAKERB we will ask the server to make any necessary TGS requests; +- * for constrained delegation we will adjust in_creds and make an S4U2Proxy +- * request below if the cache lookup fails. +- */ +- if (cred->impersonator != NULL || cred->iakerb_mech) ++ /* Try constrained delegation if we have proxy credentials. */ ++ if (cred->impersonator != NULL) { ++ /* If we are trying to get a ticket to ourselves, we should use the ++ * the evidence ticket directly from cache. */ ++ if (krb5_principal_compare(context, cred->impersonator, ++ server->princ)) { ++ flags |= KRB5_GC_CACHED; ++ } else { ++ memset(&mcreds, 0, sizeof(mcreds)); ++ mcreds.magic = KV5M_CREDS; ++ mcreds.server = cred->impersonator; ++ mcreds.client = cred->name->princ; ++ code = krb5_cc_retrieve_cred(context, cred->ccache, ++ KRB5_TC_MATCH_AUTHDATA, &mcreds, ++ &evidence_creds); ++ if (code) ++ goto cleanup; ++ ++ in_creds.client = cred->impersonator; ++ in_creds.second_ticket = evidence_creds.ticket; ++ flags = KRB5_GC_CANONICALIZE | KRB5_GC_CONSTRAINED_DELEGATION; ++ } ++ } ++ ++ /* For IAKERB, only check the cache in this step. We will ask the server ++ * to make any necessary TGS requests. */ ++ if (cred->iakerb_mech) + flags |= KRB5_GC_CACHED; + + code = krb5_get_credentials(context, flags, cred->ccache, + &in_creds, &result_creds); +- +- /* +- * Try constrained delegation if we have proxy credentials, unless +- * we are trying to get a ticket to ourselves (in which case we could +- * just use the evidence ticket directly from cache). +- */ +- if (code == KRB5_CC_NOTFOUND && cred->impersonator != NULL && +- !cred->iakerb_mech && +- !krb5_principal_compare(context, cred->impersonator, server->princ)) { +- +- memset(&mcreds, 0, sizeof(mcreds)); +- mcreds.magic = KV5M_CREDS; +- mcreds.server = cred->impersonator; +- mcreds.client = cred->name->princ; +- code = krb5_cc_retrieve_cred(context, cred->ccache, +- KRB5_TC_MATCH_AUTHDATA, &mcreds, +- &evidence_creds); +- if (code) +- goto cleanup; +- +- in_creds.client = cred->impersonator; +- in_creds.second_ticket = evidence_creds.ticket; +- flags = KRB5_GC_CANONICALIZE | KRB5_GC_CONSTRAINED_DELEGATION; +- code = krb5_get_credentials(context, flags, cred->ccache, +- &in_creds, &result_creds); +- } +- + if (code) + goto cleanup; + +diff --git a/src/lib/krb5/ccache/cc_retr.c b/src/lib/krb5/ccache/cc_retr.c +index 2c50c9cce..4328b7d6f 100644 +--- a/src/lib/krb5/ccache/cc_retr.c ++++ b/src/lib/krb5/ccache/cc_retr.c +@@ -58,15 +58,14 @@ static krb5_boolean + princs_match(krb5_context context, krb5_flags whichfields, + const krb5_creds *mcreds, const krb5_creds *creds) + { +- krb5_principal_data princ; +- +- if (!krb5_principal_compare(context, mcreds->client, creds->client)) ++ if (mcreds->client != NULL && ++ !krb5_principal_compare(context, mcreds->client, creds->client)) + return FALSE; ++ if (mcreds->server == NULL) ++ return TRUE; + if (whichfields & KRB5_TC_MATCH_SRV_NAMEONLY) { +- /* Ignore the server realm. */ +- princ = *mcreds->server; +- princ.realm = creds->server->realm; +- return krb5_principal_compare(context, &princ, creds->server); ++ return krb5_principal_compare_any_realm(context, mcreds->server, ++ creds->server); + } else { + return krb5_principal_compare(context, mcreds->server, creds->server); + } +diff --git a/src/lib/krb5/ccache/ccapi/stdcc_util.c b/src/lib/krb5/ccache/ccapi/stdcc_util.c +index 1f2a3865c..58aa81165 100644 +--- a/src/lib/krb5/ccache/ccapi/stdcc_util.c ++++ b/src/lib/krb5/ccache/ccapi/stdcc_util.c +@@ -945,8 +945,13 @@ standard_fields_match(context, mcreds, creds) + krb5_context context; + const krb5_creds *mcreds, *creds; + { +- return (krb5_principal_compare(context, mcreds->client,creds->client) && +- krb5_principal_compare(context, mcreds->server,creds->server)); ++ if (mcreds->client != NULL && ++ !krb5_principal_compare(context, mcreds->client, creds->client)) ++ return FALSE; ++ if (mcreds->server != NULL && ++ !krb5_principal_compare(context, mcreds->server,creds->server)) ++ return FALSE; ++ return TRUE; + } + + /* only match the server name portion, not the server realm portion */ +@@ -956,19 +961,14 @@ srvname_match(context, mcreds, creds) + krb5_context context; + const krb5_creds *mcreds, *creds; + { +- krb5_boolean retval; +- krb5_principal_data p1, p2; +- +- retval = krb5_principal_compare(context, mcreds->client,creds->client); +- if (retval != TRUE) +- return retval; +- /* +- * Hack to ignore the server realm for the purposes of the compare. +- */ +- p1 = *mcreds->server; +- p2 = *creds->server; +- p1.realm = p2.realm; +- return krb5_principal_compare(context, &p1, &p2); ++ if (mcreds->client != NULL && ++ !krb5_principal_compare(context, mcreds->client, creds->client)) ++ return FALSE; ++ if (mcreds->server != NULL && ++ !krb5_principal_compare_any_realm(context, mcreds->server, ++ creds->server)) ++ return FALSE; ++ return TRUE; + } + + +diff --git a/src/lib/krb5/ccache/ccfns.c b/src/lib/krb5/ccache/ccfns.c +index 62a6983d8..59982b752 100644 +--- a/src/lib/krb5/ccache/ccfns.c ++++ b/src/lib/krb5/ccache/ccfns.c +@@ -96,7 +96,8 @@ krb5_cc_retrieve_cred(krb5_context context, krb5_ccache cache, + TRACE_CC_RETRIEVE(context, cache, mcreds, ret); + if (ret != KRB5_CC_NOTFOUND) + return ret; +- if (!krb5_is_referral_realm(&mcreds->server->realm)) ++ if (mcreds->client == NULL || mcreds->server == NULL || ++ !krb5_is_referral_realm(&mcreds->server->realm)) + return ret; + + /* +diff --git a/src/lib/krb5/krb/get_creds.c b/src/lib/krb5/krb/get_creds.c +index dc0aef667..b3f01be9b 100644 +--- a/src/lib/krb5/krb/get_creds.c ++++ b/src/lib/krb5/krb/get_creds.c +@@ -102,6 +102,11 @@ krb5int_construct_matching_creds(krb5_context context, krb5_flags options, + return KRB5_NO_2ND_TKT; + } + ++ /* For S4U2Proxy requests we don't know the impersonated client in this ++ * API, but matching against the second ticket is good enough. */ ++ if (options & KRB5_GC_CONSTRAINED_DELEGATION) ++ mcreds->client = NULL; ++ + return 0; + } + +diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c +index 07c7a98be..d44f939f8 100644 +--- a/src/lib/krb5/krb/s4u_creds.c ++++ b/src/lib/krb5/krb/s4u_creds.c +@@ -1122,6 +1122,13 @@ get_proxy_cred_from_kdc(krb5_context context, krb5_flags options, + code = KRB5KRB_AP_WRONG_PRINC; + goto cleanup; + } ++ ++ /* Put the original evidence ticket in the output creds. */ ++ krb5_free_data_contents(context, &tkt->second_ticket); ++ code = krb5int_copy_data_contents(context, &in_creds->second_ticket, ++ &tkt->second_ticket); ++ if (code) ++ goto cleanup; + } + + /* Note the authdata we asked for in the output creds. */ +@@ -1148,11 +1155,33 @@ k5_get_proxy_cred_from_kdc(krb5_context context, krb5_flags options, + { + krb5_error_code code; + krb5_const_principal canonprinc; +- krb5_creds copy, *creds; ++ krb5_creds mcreds, copy, *creds, *ncreds; ++ krb5_flags fields; + struct canonprinc iter = { in_creds->server, .no_hostrealm = TRUE }; + + *out_creds = NULL; + ++ code = krb5int_construct_matching_creds(context, options, in_creds, ++ &mcreds, &fields); ++ if (code != 0) ++ return code; ++ ++ ncreds = calloc(1, sizeof(*ncreds)); ++ if (ncreds == NULL) ++ return ENOMEM; ++ ncreds->magic = KV5M_CRED; ++ ++ code = krb5_cc_retrieve_cred(context, ccache, fields, &mcreds, ncreds); ++ if (code) { ++ free(ncreds); ++ } else { ++ *out_creds = ncreds; ++ } ++ ++ if ((code != KRB5_CC_NOTFOUND && code != KRB5_CC_NOT_KTYPE) || ++ options & KRB5_GC_CACHED) ++ return code; ++ + copy = *in_creds; + while ((code = k5_canonprinc(context, &iter, &canonprinc)) == 0 && + canonprinc != NULL) { +@@ -1198,9 +1227,6 @@ krb5_get_credentials_for_proxy(krb5_context context, + krb5_creds **out_creds) + { + krb5_error_code code; +- krb5_creds mcreds; +- krb5_creds *ncreds = NULL; +- krb5_flags fields; + krb5_data *evidence_tkt_data = NULL; + krb5_creds s4u_creds; + +@@ -1222,30 +1248,6 @@ krb5_get_credentials_for_proxy(krb5_context context, + goto cleanup; + } + +- code = krb5int_construct_matching_creds(context, options, in_creds, +- &mcreds, &fields); +- if (code != 0) +- goto cleanup; +- +- ncreds = calloc(1, sizeof(*ncreds)); +- if (ncreds == NULL) { +- code = ENOMEM; +- goto cleanup; +- } +- ncreds->magic = KV5M_CRED; +- +- code = krb5_cc_retrieve_cred(context, ccache, fields, &mcreds, ncreds); +- if (code != 0) { +- free(ncreds); +- ncreds = in_creds; +- } else { +- *out_creds = ncreds; +- } +- +- if ((code != KRB5_CC_NOTFOUND && code != KRB5_CC_NOT_KTYPE) +- || options & KRB5_GC_CACHED) +- goto cleanup; +- + code = encode_krb5_ticket(evidence_tkt, &evidence_tkt_data); + if (code != 0) + goto cleanup; +diff --git a/src/tests/s4u2proxy.c b/src/tests/s4u2proxy.c +index 4adf6aca5..3786bad2c 100644 +--- a/src/tests/s4u2proxy.c ++++ b/src/tests/s4u2proxy.c +@@ -124,6 +124,9 @@ main(int argc, char **argv) + KRB5_GC_CANONICALIZE, defcc, + &mcred, ev_ticket, &new_cred)); + ++ assert(data_eq(new_cred->second_ticket, ev_cred.ticket)); ++ assert(new_cred->second_ticket.length != 0); ++ + /* Store the new cred in the default ccache. */ + check(krb5_cc_store_cred(context, defcc, new_cred)); + diff --git a/Don-t-create-hostbased-principals-in-new-KDBs.patch b/Don-t-create-hostbased-principals-in-new-KDBs.patch new file mode 100644 index 0000000..867eb4a --- /dev/null +++ b/Don-t-create-hostbased-principals-in-new-KDBs.patch @@ -0,0 +1,195 @@ +From 71070a0f0fa6424cfb37aef7c4ec43e99380a6aa Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 30 Jul 2020 12:14:27 -0400 +Subject: [PATCH] Don't create hostbased principals in new KDBs + +Unix-like platforms do not provide a simple method to find the +fully-qualified local hostname as the machine is expected to appear to +other hosts. Canonicalizing the gethostname() result with +getaddrinfo() usually works, but potentially uses DNS. Now that +dns_canonicalize_hostname=true is no longer the default, KDB creation +would generally create the wrong host-based principals. + +kadmin/hostname is unnecessary because the client software can also +use kadmin/admin, and kiprop/hostname is one of several principals +that must be created for incremental propagation. + +ticket: 8935 (new) +(cherry picked from commit ac2b693d0ec464e0bcda4953acd79f201169f396) +--- + src/kadmin/dbutil/kadm5_create.c | 52 ++----------------- + .../kdb/ldap/ldap_util/kdb5_ldap_realm.c | 35 +------------ + src/tests/dejagnu/krb-standalone/kadmin.exp | 7 +-- + src/tests/t_iprop.py | 1 + + src/tests/t_kadmin_acl.py | 1 + + 5 files changed, 12 insertions(+), 84 deletions(-) + +diff --git a/src/kadmin/dbutil/kadm5_create.c b/src/kadmin/dbutil/kadm5_create.c +index 4f254a387..42b45aa2d 100644 +--- a/src/kadmin/dbutil/kadm5_create.c ++++ b/src/kadmin/dbutil/kadm5_create.c +@@ -139,60 +139,18 @@ int kadm5_create_magic_princs(kadm5_config_params *params, + static int add_admin_princs(void *handle, krb5_context context, char *realm) + { + krb5_error_code ret = 0; +- char *service_name = 0, *kiprop_name = 0, *canonhost = 0; +- char localname[MAXHOSTNAMELEN]; +- +- if (gethostname(localname, MAXHOSTNAMELEN)) { +- ret = errno; +- perror("gethostname"); +- goto clean_and_exit; +- } +- ret = krb5_expand_hostname(context, localname, &canonhost); +- if (ret) { +- com_err(progname, ret, _("while canonicalizing local hostname")); +- goto clean_and_exit; +- } +- if (asprintf(&service_name, "kadmin/%s", canonhost) < 0) { +- ret = ENOMEM; +- fprintf(stderr, _("Out of memory\n")); +- goto clean_and_exit; +- } +- if (asprintf(&kiprop_name, "kiprop/%s", canonhost) < 0) { +- ret = ENOMEM; +- fprintf(stderr, _("Out of memory\n")); +- goto clean_and_exit; +- } +- +- if ((ret = add_admin_princ(handle, context, +- service_name, realm, +- KRB5_KDB_DISALLOW_TGT_BASED | +- KRB5_KDB_LOCKDOWN_KEYS, +- ADMIN_LIFETIME))) +- goto clean_and_exit; + + if ((ret = add_admin_princ(handle, context, + KADM5_ADMIN_SERVICE, realm, + KRB5_KDB_DISALLOW_TGT_BASED | + KRB5_KDB_LOCKDOWN_KEYS, + ADMIN_LIFETIME))) +- goto clean_and_exit; ++ return ret; + +- if ((ret = add_admin_princ(handle, context, +- KADM5_CHANGEPW_SERVICE, realm, +- KRB5_KDB_DISALLOW_TGT_BASED | +- KRB5_KDB_PWCHANGE_SERVICE | +- KRB5_KDB_LOCKDOWN_KEYS, +- CHANGEPW_LIFETIME))) +- goto clean_and_exit; +- +- ret = add_admin_princ(handle, context, kiprop_name, realm, 0, 0); +- +-clean_and_exit: +- krb5_free_string(context, canonhost); +- free(service_name); +- free(kiprop_name); +- +- return ret; ++ return add_admin_princ(handle, context, KADM5_CHANGEPW_SERVICE, realm, ++ KRB5_KDB_DISALLOW_TGT_BASED | ++ KRB5_KDB_PWCHANGE_SERVICE | KRB5_KDB_LOCKDOWN_KEYS, ++ CHANGEPW_LIFETIME); + } + + /* +diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c +index c21d19981..ae1afd4a9 100644 +--- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c ++++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c +@@ -307,29 +307,6 @@ create_fixed_special(krb5_context context, struct realm_info *rinfo, + + } + +-/* Create a special principal using one specified component and the +- * canonicalized local hostname. */ +-static krb5_error_code +-create_hostbased_special(krb5_context context, struct realm_info *rinfo, +- krb5_keyblock *mkey, const char *comp1) +-{ +- krb5_error_code ret; +- krb5_principal princ = NULL; +- +- ret = krb5_sname_to_principal(context, NULL, comp1, KRB5_NT_SRV_HST, +- &princ); +- if (ret) +- goto cleanup; +- ret = krb5_set_principal_realm(context, princ, global_params.realm); +- if (ret) +- goto cleanup; +- ret = kdb_ldap_create_principal(context, princ, TGT_KEY, rinfo, mkey); +- +-cleanup: +- krb5_free_principal(context, princ); +- return ret; +-} +- + /* Create all special principals for the realm. */ + static krb5_error_code + create_special_princs(krb5_context context, krb5_principal master_princ, +@@ -360,20 +337,10 @@ create_special_princs(krb5_context context, krb5_principal master_princ, + if (ret) + return ret; + +- /* Create kadmin/admin and kadmin/. */ ++ /* Create kadmin/admin. */ + rblock.max_life = ADMIN_LIFETIME; + rblock.flags = KRB5_KDB_DISALLOW_TGT_BASED; + ret = create_fixed_special(context, &rblock, mkey, "kadmin", "admin"); +- if (ret) +- return ret; +- ret = create_hostbased_special(context, &rblock, mkey, "kadmin"); +- if (ret) +- return ret; +- +- /* Create kiprop/. */ +- rblock.max_life = global_params.max_life; +- rblock.flags = 0; +- ret = create_hostbased_special(context, &rblock, mkey, "kiprop"); + if (ret) + return ret; + +diff --git a/src/tests/dejagnu/krb-standalone/kadmin.exp b/src/tests/dejagnu/krb-standalone/kadmin.exp +index 36a345258..fa50a61fb 100644 +--- a/src/tests/dejagnu/krb-standalone/kadmin.exp ++++ b/src/tests/dejagnu/krb-standalone/kadmin.exp +@@ -1098,10 +1098,11 @@ proc kadmin_test { } { + return + } + +- # test fallback to kadmin/admin +- if {![kadmin_delete_locked_down kadmin/$hostname] \ ++ # test fallback to kadmin/hostname ++ if {![kadmin_add_rnd kadmin/$hostname] \ ++ || ![kadmin_delete_locked_down kadmin/admin] \ + || ![kadmin_list] \ +- || ![kadmin_add_rnd kadmin/$hostname -allow_tgs_req] \ ++ || ![kadmin_add_rnd kadmin/admin -allow_tgs_req] \ + || ![kadmin_list]} { + return + } +diff --git a/src/tests/t_iprop.py b/src/tests/t_iprop.py +index 371f3a22b..3bb0fd2e9 100755 +--- a/src/tests/t_iprop.py ++++ b/src/tests/t_iprop.py +@@ -188,6 +188,7 @@ for realm in multidb_realms(kdc_conf=conf, create_user=False, + + # Create the principal used to authenticate kpropd to kadmind. + kiprop_princ = 'kiprop/' + hostname ++ realm.addprinc(kiprop_princ) + realm.extract_keytab(kiprop_princ, realm.keytab) + + # Create the initial replica databases. +diff --git a/src/tests/t_kadmin_acl.py b/src/tests/t_kadmin_acl.py +index 16faf0a9d..31a7fb871 100755 +--- a/src/tests/t_kadmin_acl.py ++++ b/src/tests/t_kadmin_acl.py +@@ -331,6 +331,7 @@ realm.run([kadmin, '-c', realm.ccache, 'cpw', '-randkey', '-e', 'aes256-cts', + # Test authentication to kadmin/hostname. + mark('authentication to kadmin/hostname') + kadmin_hostname = 'kadmin/' + hostname ++realm.addprinc(kadmin_hostname) + realm.run([kadminl, 'delprinc', 'kadmin/admin']) + msgs = ('Getting initial credentials for user/admin@KRBTEST.COM', + 'Setting initial creds service to kadmin/admin', diff --git a/Expand-dns_canonicalize_host-fallback-support.patch b/Expand-dns_canonicalize_host-fallback-support.patch new file mode 100644 index 0000000..eb82a81 --- /dev/null +++ b/Expand-dns_canonicalize_host-fallback-support.patch @@ -0,0 +1,1190 @@ +From c0e732f79dc5ea0c2066120bfe7ae8f6df82bf82 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 17 Jul 2020 22:57:45 -0400 +Subject: [PATCH] Expand dns_canonicalize_host=fallback support + +In krb5_sname_to_principal(), when using fallback, defer realm lookup +and any kind of hostname canonicalization until use. Add a +lightweight iterator k5_canonprinc() to yield the one or two possible +candidates for a principal. In the iterator, don't yield the same +hostname part twice. + +Add fallback processing to the stepwise TGS state machine, and remove +it from krb5_get_credentials(). Add fallback processing to +k5_get_proxy_cred_from_kdc(). + +Add fallback processing to krb5_init_creds_set_keytab(), and use the +principal we find in the keytab as the request client principal. +Defer restart_init_creds_loop() to the first step call so that server +principal is built using the correct realm. + +Add fallback processing to krb5_rd_req(). + +ticket: 8930 (new) +(cherry picked from commit 3fcc365a6f049730b3f47168f7112c03997c5c0b) +--- + src/include/k5-trace.h | 4 +- + src/kprop/kprop_util.c | 26 ++-- + src/lib/krb5/krb/deps | 41 +++--- + src/lib/krb5/krb/get_creds.c | 151 ++++++++++----------- + src/lib/krb5/krb/get_in_tkt.c | 7 +- + src/lib/krb5/krb/gic_keytab.c | 29 +++- + src/lib/krb5/krb/init_creds_ctx.h | 1 + + src/lib/krb5/krb/rd_req_dec.c | 36 ++++- + src/lib/krb5/krb/s4u_creds.c | 62 ++++++--- + src/lib/krb5/os/os-proto.h | 30 +++++ + src/lib/krb5/os/sn2princ.c | 215 +++++++++++++++++++++--------- + src/tests/icred.c | 39 ++++-- + src/tests/t_sn2princ.py | 65 ++++++--- + 13 files changed, 465 insertions(+), 241 deletions(-) + +diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h +index 1da53dbb1..5a120f1a0 100644 +--- a/src/include/k5-trace.h ++++ b/src/include/k5-trace.h +@@ -229,8 +229,8 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); + salt, s2kparams) + #define TRACE_INIT_CREDS_IDENTIFIED_REALM(c, realm) \ + TRACE(c, "Identified realm of client principal as {data}", realm) +-#define TRACE_INIT_CREDS_KEYTAB_LOOKUP(c, etypes) \ +- TRACE(c, "Looked up etypes in keytab: {etypes}", etypes) ++#define TRACE_INIT_CREDS_KEYTAB_LOOKUP(c, princ, etypes) \ ++ TRACE(c, "Found entries for {princ} in keytab: {etypes}", princ, etypes) + #define TRACE_INIT_CREDS_KEYTAB_LOOKUP_FAILED(c, code) \ + TRACE(c, "Couldn't lookup etypes in keytab: {kerr}", code) + #define TRACE_INIT_CREDS_PREAUTH(c) \ +diff --git a/src/kprop/kprop_util.c b/src/kprop/kprop_util.c +index c32d174b9..c2b2e8764 100644 +--- a/src/kprop/kprop_util.c ++++ b/src/kprop/kprop_util.c +@@ -73,26 +73,22 @@ sn2princ_realm(krb5_context context, const char *hostname, const char *sname, + const char *realm, krb5_principal *princ_out) + { + krb5_error_code ret; +- char *canonhost, localname[MAXHOSTNAMELEN]; ++ krb5_principal princ; + + *princ_out = NULL; + assert(sname != NULL && realm != NULL); + +- /* If hostname is NULL, use the local hostname. */ +- if (hostname == NULL) { +- if (gethostname(localname, MAXHOSTNAMELEN) != 0) +- return SOCKET_ERRNO; +- hostname = localname; +- } +- +- ret = krb5_expand_hostname(context, hostname, &canonhost); ++ ret = krb5_sname_to_principal(context, hostname, sname, KRB5_NT_SRV_HST, ++ &princ); + if (ret) + return ret; + +- ret = krb5_build_principal(context, princ_out, strlen(realm), realm, sname, +- canonhost, (char *)NULL); +- krb5_free_string(context, canonhost); +- if (!ret) +- (*princ_out)->type = KRB5_NT_SRV_HST; +- return ret; ++ ret = krb5_set_principal_realm(context, princ, realm); ++ if (ret) { ++ krb5_free_principal(context, princ); ++ return ret; ++ } ++ ++ *princ_out = princ; ++ return 0; + } +diff --git a/src/lib/krb5/krb/deps b/src/lib/krb5/krb/deps +index 439ca0272..6ac68bc19 100644 +--- a/src/lib/krb5/krb/deps ++++ b/src/lib/krb5/krb/deps +@@ -499,12 +499,13 @@ get_in_tkt.so get_in_tkt.po $(OUTPRE)get_in_tkt.$(OBJEXT): \ + gic_keytab.so gic_keytab.po $(OUTPRE)gic_keytab.$(OBJEXT): \ + $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ + $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-json.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ ++ $(COM_ERR_DEPS) $(srcdir)/../os/os-proto.h $(top_srcdir)/include/k5-buf.h \ ++ $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ ++ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ ++ $(top_srcdir)/include/k5-json.h $(top_srcdir)/include/k5-platform.h \ ++ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ ++ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ ++ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/locate_plugin.h \ + $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ + $(top_srcdir)/include/socket-utils.h gic_keytab.c init_creds_ctx.h \ + int-proto.h +@@ -940,13 +941,14 @@ rd_req.so rd_req.po $(OUTPRE)rd_req.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ + rd_req_dec.so rd_req_dec.po $(OUTPRE)rd_req_dec.$(OBJEXT): \ + $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ + $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(srcdir)/../rcache/memrcache.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/k5-utf8.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ ++ $(COM_ERR_DEPS) $(srcdir)/../os/os-proto.h $(srcdir)/../rcache/memrcache.h \ ++ $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ ++ $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ ++ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ ++ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ ++ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/k5-utf8.h \ ++ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ ++ $(top_srcdir)/include/krb5/locate_plugin.h $(top_srcdir)/include/krb5/plugin.h \ + $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ + auth_con.h authdata.h int-proto.h rd_req_dec.c + rd_safe.so rd_safe.po $(OUTPRE)rd_safe.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +@@ -997,12 +999,13 @@ s4u_authdata.so s4u_authdata.po $(OUTPRE)s4u_authdata.$(OBJEXT): \ + s4u_creds.so s4u_creds.po $(OUTPRE)s4u_creds.$(OBJEXT): \ + $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ + $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ ++ $(COM_ERR_DEPS) $(srcdir)/../os/os-proto.h $(top_srcdir)/include/k5-buf.h \ ++ $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ ++ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ ++ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ ++ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ ++ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ ++ $(top_srcdir)/include/krb5/locate_plugin.h $(top_srcdir)/include/krb5/plugin.h \ + $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ + int-proto.h s4u_creds.c + sendauth.so sendauth.po $(OUTPRE)sendauth.$(OBJEXT): \ +diff --git a/src/lib/krb5/krb/get_creds.c b/src/lib/krb5/krb/get_creds.c +index e0a3b5cd8..dc0aef667 100644 +--- a/src/lib/krb5/krb/get_creds.c ++++ b/src/lib/krb5/krb/get_creds.c +@@ -119,7 +119,7 @@ krb5int_construct_matching_creds(krb5_context context, krb5_flags options, + * generate the next request. If it's time to advance to another state, any of + * the three functions can make a tail call to begin_ to do so. + * +- * The overall process is as follows: ++ * The general process is as follows: + * 1. Get a TGT for the service principal's realm (STATE_GET_TGT). + * 2. Make one or more referrals queries (STATE_REFERRALS). + * 3. In some cases, get a TGT for the fallback realm (STATE_GET_TGT again). +@@ -129,6 +129,9 @@ krb5int_construct_matching_creds(krb5_context context, krb5_flags options, + * getting_tgt_for field in the context keeps track of what state we will go to + * after successfully obtaining the TGT, and the end_get_tgt() function + * advances to the proper next state. ++ * ++ * If fallback DNS canonicalization is in use, the process can be repeated a ++ * second time for the second server principal canonicalization candidate. + */ + + enum state { +@@ -153,6 +156,8 @@ struct _krb5_tkt_creds_context { + krb5_flags req_options; /* Caller-requested KRB5_GC_* options */ + krb5_flags req_kdcopt; /* Caller-requested options as KDC options */ + krb5_authdata **authdata; /* Caller-requested authdata */ ++ struct canonprinc iter; /* Iterator over canonicalized server princs */ ++ krb5_boolean referral_req; /* Server initially contained referral realm */ + + /* The following fields are used in multiple steps. */ + krb5_creds *cur_tgt; /* TGT to be used for next query */ +@@ -484,7 +489,7 @@ try_fallback(krb5_context context, krb5_tkt_creds_context ctx) + + /* If the request used a specified realm, make a non-referral request to + * that realm (in case it's a KDC which rejects KDC_OPT_CANONICALIZE). */ +- if (!krb5_is_referral_realm(&ctx->req_server->realm)) ++ if (!ctx->referral_req) + return begin_non_referral(context, ctx); + + if (ctx->server->length < 2) { +@@ -1015,10 +1020,13 @@ check_cache(krb5_context context, krb5_tkt_creds_context ctx) + krb5_error_code code; + krb5_creds mcreds; + krb5_flags fields; ++ krb5_creds req_in_creds; + +- /* Perform the cache lookup. */ ++ /* Check the cache for the originally requested server principal. */ ++ req_in_creds = *ctx->in_creds; ++ req_in_creds.server = ctx->req_server; + code = krb5int_construct_matching_creds(context, ctx->req_options, +- ctx->in_creds, &mcreds, &fields); ++ &req_in_creds, &mcreds, &fields); + if (code) + return code; + code = cache_get(context, ctx->ccache, fields, &mcreds, &ctx->reply_creds); +@@ -1044,12 +1052,9 @@ begin(krb5_context context, krb5_tkt_creds_context ctx) + { + krb5_error_code code; + +- code = check_cache(context, ctx); +- if (code != 0 || ctx->state == STATE_COMPLETE) +- return code; +- + /* If the server realm is unspecified, start with the client realm. */ +- if (krb5_is_referral_realm(&ctx->server->realm)) { ++ ctx->referral_req = krb5_is_referral_realm(&ctx->server->realm); ++ if (ctx->referral_req) { + krb5_free_data_contents(context, &ctx->server->realm); + code = krb5int_copy_data_contents(context, &ctx->client->realm, + &ctx->server->realm); +@@ -1072,6 +1077,7 @@ krb5_tkt_creds_init(krb5_context context, krb5_ccache ccache, + { + krb5_error_code code; + krb5_tkt_creds_context ctx = NULL; ++ krb5_const_principal canonprinc; + + TRACE_TKT_CREDS(context, in_creds, ccache); + ctx = k5alloc(sizeof(*ctx), &code); +@@ -1089,14 +1095,28 @@ krb5_tkt_creds_init(krb5_context context, krb5_ccache ccache, + + ctx->state = STATE_BEGIN; + ++ /* Copy the matching cred so we can modify it. Steal the copy of the ++ * service principal name to remember the original request server. */ + code = krb5_copy_creds(context, in_creds, &ctx->in_creds); + if (code != 0) + goto cleanup; +- ctx->client = ctx->in_creds->client; +- ctx->server = ctx->in_creds->server; +- code = krb5_copy_principal(context, ctx->server, &ctx->req_server); ++ ctx->req_server = ctx->in_creds->server; ++ ctx->in_creds->server = NULL; ++ ++ /* Get the first canonicalization candidate for the requested server. */ ++ ctx->iter.princ = ctx->req_server; ++ ++ code = k5_canonprinc(context, &ctx->iter, &canonprinc); ++ if (code == 0 && canonprinc == NULL) ++ code = KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN; + if (code != 0) + goto cleanup; ++ code = krb5_copy_principal(context, canonprinc, &ctx->in_creds->server); ++ if (code != 0) ++ goto cleanup; ++ ++ ctx->client = ctx->in_creds->client; ++ ctx->server = ctx->in_creds->server; + code = krb5_cc_dup(context, ccache, &ctx->ccache); + if (code != 0) + goto cleanup; +@@ -1138,6 +1158,7 @@ krb5_tkt_creds_free(krb5_context context, krb5_tkt_creds_context ctx) + return; + krb5int_fast_free_state(context, ctx->fast_state); + krb5_free_creds(context, ctx->in_creds); ++ free_canonprinc(&ctx->iter); + krb5_cc_close(context, ctx->ccache); + krb5_free_principal(context, ctx->req_server); + krb5_free_authdata(context, ctx->authdata); +@@ -1195,6 +1216,7 @@ krb5_tkt_creds_step(krb5_context context, krb5_tkt_creds_context ctx, + { + krb5_error_code code; + krb5_boolean no_input = (in == NULL || in->length == 0); ++ krb5_const_principal canonprinc; + + *out = empty_data(); + *realm = empty_data(); +@@ -1206,6 +1228,12 @@ krb5_tkt_creds_step(krb5_context context, krb5_tkt_creds_context ctx, + ctx->state == STATE_COMPLETE) + return EINVAL; + ++ if (ctx->state == STATE_BEGIN) { ++ code = check_cache(context, ctx); ++ if (code != 0 || ctx->state == STATE_COMPLETE) ++ return code; ++ } ++ + ctx->caller_out = out; + ctx->caller_realm = realm; + ctx->caller_flags = flags; +@@ -1218,37 +1246,32 @@ krb5_tkt_creds_step(krb5_context context, krb5_tkt_creds_context ctx, + } + + if (ctx->state == STATE_BEGIN) +- return begin(context, ctx); ++ code = begin(context, ctx); + else if (ctx->state == STATE_GET_TGT) +- return step_get_tgt(context, ctx); ++ code = step_get_tgt(context, ctx); + else if (ctx->state == STATE_GET_TGT_OFFPATH) +- return step_get_tgt_offpath(context, ctx); ++ code = step_get_tgt_offpath(context, ctx); + else if (ctx->state == STATE_REFERRALS) +- return step_referrals(context, ctx); ++ code = step_referrals(context, ctx); + else if (ctx->state == STATE_NON_REFERRAL) +- return step_non_referral(context, ctx); ++ code = step_non_referral(context, ctx); + else +- return EINVAL; +-} ++ code = EINVAL; + +-static krb5_error_code +-try_get_creds(krb5_context context, krb5_flags options, krb5_ccache ccache, +- krb5_creds *in_creds, krb5_creds *creds_out) +-{ +- krb5_error_code code; +- krb5_tkt_creds_context ctx = NULL; ++ /* Terminate on success or most errors. */ ++ if (code != KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN) ++ return code; + +- code = krb5_tkt_creds_init(context, ccache, in_creds, options, &ctx); ++ /* Restart with the next server principal canonicalization candidate. */ ++ code = k5_canonprinc(context, &ctx->iter, &canonprinc); + if (code) +- goto cleanup; +- code = krb5_tkt_creds_get(context, ctx); +- if (code) +- goto cleanup; +- code = krb5_tkt_creds_get_creds(context, ctx, creds_out); +- +-cleanup: +- krb5_tkt_creds_free(context, ctx); +- return code; ++ return code; ++ if (canonprinc == NULL) ++ return KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN; ++ krb5_free_principal(context, ctx->in_creds->server); ++ code = krb5_copy_principal(context, canonprinc, &ctx->in_creds->server); ++ ctx->server = ctx->in_creds->server; ++ return begin(context, ctx); + } + + krb5_error_code KRB5_CALLCONV +@@ -1258,10 +1281,7 @@ krb5_get_credentials(krb5_context context, krb5_flags options, + { + krb5_error_code code; + krb5_creds *ncreds = NULL; +- krb5_creds canon_creds, store_creds; +- krb5_principal_data canon_server; +- krb5_data canon_components[2]; +- char *hostname = NULL, *canon_hostname = NULL; ++ krb5_tkt_creds_context ctx = NULL; + + *out_creds = NULL; + +@@ -1277,59 +1297,22 @@ krb5_get_credentials(krb5_context context, krb5_flags options, + if (ncreds == NULL) + goto cleanup; + +- code = try_get_creds(context, options, ccache, in_creds, ncreds); +- if (!code) { +- *out_creds = ncreds; +- return 0; +- } +- +- /* Possibly try again with the canonicalized hostname, if the server is +- * host-based and we are configured for fallback canonicalization. */ +- if (code != KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN) ++ /* Make and execute a krb5_tkt_creds context to get the credential. */ ++ code = krb5_tkt_creds_init(context, ccache, in_creds, options, &ctx); ++ if (code != 0) + goto cleanup; +- if (context->dns_canonicalize_hostname != CANONHOST_FALLBACK) ++ code = krb5_tkt_creds_get(context, ctx); ++ if (code != 0) + goto cleanup; +- if (in_creds->server->type != KRB5_NT_SRV_HST || +- in_creds->server->length != 2) ++ code = krb5_tkt_creds_get_creds(context, ctx, ncreds); ++ if (code != 0) + goto cleanup; + +- hostname = k5memdup0(in_creds->server->data[1].data, +- in_creds->server->data[1].length, &code); +- if (hostname == NULL) +- goto cleanup; +- code = k5_expand_hostname(context, hostname, TRUE, &canon_hostname); +- if (code) +- goto cleanup; +- +- TRACE_GET_CREDS_FALLBACK(context, canon_hostname); +- +- /* Make shallow copies of in_creds and its server to alter the hostname. */ +- canon_components[0] = in_creds->server->data[0]; +- canon_components[1] = string2data(canon_hostname); +- canon_server = *in_creds->server; +- canon_server.data = canon_components; +- canon_creds = *in_creds; +- canon_creds.server = &canon_server; +- +- code = try_get_creds(context, options | KRB5_GC_NO_STORE, ccache, +- &canon_creds, ncreds); +- if (code) +- goto cleanup; +- +- if (!(options & KRB5_GC_NO_STORE)) { +- /* Store the creds under the originally requested server name. The +- * ccache layer will also store them under the ticket server name. */ +- store_creds = *ncreds; +- store_creds.server = in_creds->server; +- (void)krb5_cc_store_cred(context, ccache, &store_creds); +- } +- + *out_creds = ncreds; + ncreds = NULL; + + cleanup: +- free(hostname); +- free(canon_hostname); + krb5_free_creds(context, ncreds); ++ krb5_tkt_creds_free(context, ctx); + return code; + } +diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c +index cc0f70e83..09c4b8495 100644 +--- a/src/lib/krb5/krb/get_in_tkt.c ++++ b/src/lib/krb5/krb/get_in_tkt.c +@@ -1051,9 +1051,6 @@ krb5_init_creds_init(krb5_context context, + ctx->request->kdc_options |= KDC_OPT_REQUEST_ANONYMOUS; + ctx->request->client->type = KRB5_NT_WELLKNOWN; + } +- code = restart_init_creds_loop(context, ctx, FALSE); +- if (code) +- goto cleanup; + + *pctx = ctx; + ctx = NULL; +@@ -1859,6 +1856,10 @@ krb5_init_creds_step(krb5_context context, + } + if (code != 0 || ctx->complete) + goto cleanup; ++ } else { ++ code = restart_init_creds_loop(context, ctx, FALSE); ++ if (code) ++ goto cleanup; + } + + code = init_creds_step_request(context, ctx, out); +diff --git a/src/lib/krb5/krb/gic_keytab.c b/src/lib/krb5/krb/gic_keytab.c +index 1d70cf46f..b2b4ac904 100644 +--- a/src/lib/krb5/krb/gic_keytab.c ++++ b/src/lib/krb5/krb/gic_keytab.c +@@ -27,6 +27,7 @@ + + #include "k5-int.h" + #include "int-proto.h" ++#include "os-proto.h" + #include "init_creds_ctx.h" + + static krb5_error_code +@@ -85,7 +86,8 @@ get_as_key_keytab(krb5_context context, + /* Return the list of etypes available for client in keytab. */ + static krb5_error_code + lookup_etypes_for_keytab(krb5_context context, krb5_keytab keytab, +- krb5_principal client, krb5_enctype **etypes_out) ++ krb5_const_principal client, ++ krb5_enctype **etypes_out) + { + krb5_kt_cursor cursor; + krb5_keytab_entry entry; +@@ -182,18 +184,37 @@ krb5_init_creds_set_keytab(krb5_context context, + { + krb5_enctype *etype_list; + krb5_error_code ret; ++ struct canonprinc iter = { ctx->request->client, .subst_defrealm = TRUE }; ++ krb5_const_principal canonprinc; ++ krb5_principal copy; + char *name; + + ctx->gak_fct = get_as_key_keytab; + ctx->gak_data = keytab; + +- ret = lookup_etypes_for_keytab(context, keytab, ctx->request->client, +- &etype_list); ++ /* We may be authenticating as a host-based principal. If so, look for ++ * each canonicalization candidate in the keytab. */ ++ while ((ret = k5_canonprinc(context, &iter, &canonprinc)) == 0 && ++ canonprinc != NULL) { ++ ret = lookup_etypes_for_keytab(context, keytab, canonprinc, ++ &etype_list); ++ if (ret || etype_list != NULL) ++ break; ++ } ++ if (!ret && canonprinc != NULL) { ++ /* Authenticate as the principal we found in the keytab. */ ++ ret = krb5_copy_principal(context, canonprinc, ©); ++ if (!ret) { ++ krb5_free_principal(context, ctx->request->client); ++ ctx->request->client = copy; ++ } ++ } ++ free_canonprinc(&iter); + if (ret) { + TRACE_INIT_CREDS_KEYTAB_LOOKUP_FAILED(context, ret); + return 0; + } +- TRACE_INIT_CREDS_KEYTAB_LOOKUP(context, etype_list); ++ TRACE_INIT_CREDS_KEYTAB_LOOKUP(context, ctx->request->client, etype_list); + + /* Error out if we have no keys for the client principal. */ + if (etype_list == NULL) { +diff --git a/src/lib/krb5/krb/init_creds_ctx.h b/src/lib/krb5/krb/init_creds_ctx.h +index 5bd67a1d8..17d55dd7c 100644 +--- a/src/lib/krb5/krb/init_creds_ctx.h ++++ b/src/lib/krb5/krb/init_creds_ctx.h +@@ -22,6 +22,7 @@ struct _krb5_init_creds_context { + krb5_get_init_creds_opt opt_storage; + krb5_boolean identify_realm; + const krb5_data *subject_cert; ++ krb5_principal keytab_princ; + char *in_tkt_service; + krb5_prompter_fct prompter; + void *prompter_data; +diff --git a/src/lib/krb5/krb/rd_req_dec.c b/src/lib/krb5/krb/rd_req_dec.c +index bc7fac455..013ca905c 100644 +--- a/src/lib/krb5/krb/rd_req_dec.c ++++ b/src/lib/krb5/krb/rd_req_dec.c +@@ -33,6 +33,7 @@ + #include "auth_con.h" + #include "authdata.h" + #include "int-proto.h" ++#include "os-proto.h" + + /* + * essentially the same as krb_rd_req, but uses a decoded AP_REQ as +@@ -351,9 +352,9 @@ try_one_princ(krb5_context context, const krb5_ap_req *req, + * Store the decrypting key in *keyblock_out if it is not NULL. + */ + static krb5_error_code +-decrypt_ticket(krb5_context context, const krb5_ap_req *req, +- krb5_const_principal server, krb5_keytab keytab, +- krb5_keyblock *keyblock_out) ++decrypt_try_server(krb5_context context, const krb5_ap_req *req, ++ krb5_const_principal server, krb5_keytab keytab, ++ krb5_keyblock *keyblock_out) + { + krb5_error_code ret; + krb5_keytab_entry ent; +@@ -441,6 +442,35 @@ decrypt_ticket(krb5_context context, const krb5_ap_req *req, + #endif /* LEAN_CLIENT */ + } + ++static krb5_error_code ++decrypt_ticket(krb5_context context, const krb5_ap_req *req, ++ krb5_const_principal server, krb5_keytab keytab, ++ krb5_keyblock *keyblock_out) ++{ ++ krb5_error_code ret, dret = 0; ++ struct canonprinc iter = { server, .no_hostrealm = TRUE }; ++ krb5_const_principal canonprinc; ++ ++ /* Don't try to canonicalize if we're going to ignore the hostname, or if ++ * server is null or has a wildcard hostname. */ ++ if (context->ignore_acceptor_hostname || server == NULL || ++ (server->length == 2 && server->data[1].length == 0)) ++ return decrypt_try_server(context, req, server, keytab, keyblock_out); ++ ++ /* Try each canonicalization candidate for server. If they all fail, ++ * return the error from the last attempt. */ ++ while ((ret = k5_canonprinc(context, &iter, &canonprinc)) == 0 && ++ canonprinc != NULL) { ++ dret = decrypt_try_server(context, req, canonprinc, keytab, ++ keyblock_out); ++ /* Only continue if we found no keytab entries matching canonprinc. */ ++ if (dret != KRB5KRB_AP_ERR_NOKEY) ++ break; ++ } ++ free_canonprinc(&iter); ++ return (ret != 0) ? ret : dret; ++} ++ + static krb5_error_code + rd_req_decoded_opt(krb5_context context, krb5_auth_context *auth_context, + const krb5_ap_req *req, krb5_const_principal server, +diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c +index d8f486dc6..07c7a98be 100644 +--- a/src/lib/krb5/krb/s4u_creds.c ++++ b/src/lib/krb5/krb/s4u_creds.c +@@ -26,6 +26,7 @@ + + #include "k5-int.h" + #include "int-proto.h" ++#include "os-proto.h" + + /* Convert ticket flags to necessary KDC options */ + #define FLAGS2OPTS(flags) (flags & KDC_TKT_COMMON_MASK) +@@ -984,10 +985,10 @@ get_target_realm_proxy_tgt(krb5_context context, const krb5_data *realm, + return 0; + } + +-krb5_error_code +-k5_get_proxy_cred_from_kdc(krb5_context context, krb5_flags options, +- krb5_ccache ccache, krb5_creds *in_creds, +- krb5_creds **out_creds) ++static krb5_error_code ++get_proxy_cred_from_kdc(krb5_context context, krb5_flags options, ++ krb5_ccache ccache, krb5_creds *in_creds, ++ krb5_creds **out_creds) + { + krb5_error_code code; + krb5_flags flags, req_kdcopt = 0; +@@ -1123,22 +1124,11 @@ k5_get_proxy_cred_from_kdc(krb5_context context, krb5_flags options, + } + } + +- if (!krb5_principal_compare(context, in_creds->server, tkt->server)) { +- krb5_free_principal(context, tkt->server); +- tkt->server = NULL; +- code = krb5_copy_principal(context, in_creds->server, &tkt->server); +- if (code) +- goto cleanup; +- } +- + /* Note the authdata we asked for in the output creds. */ + code = krb5_copy_authdata(context, in_creds->authdata, &tkt->authdata); + if (code) + goto cleanup; + +- if (!(options & KRB5_GC_NO_STORE)) +- (void)krb5_cc_store_cred(context, ccache, tkt); +- + *out_creds = tkt; + tkt = NULL; + +@@ -1151,6 +1141,48 @@ cleanup: + return code; + } + ++krb5_error_code ++k5_get_proxy_cred_from_kdc(krb5_context context, krb5_flags options, ++ krb5_ccache ccache, krb5_creds *in_creds, ++ krb5_creds **out_creds) ++{ ++ krb5_error_code code; ++ krb5_const_principal canonprinc; ++ krb5_creds copy, *creds; ++ struct canonprinc iter = { in_creds->server, .no_hostrealm = TRUE }; ++ ++ *out_creds = NULL; ++ ++ copy = *in_creds; ++ while ((code = k5_canonprinc(context, &iter, &canonprinc)) == 0 && ++ canonprinc != NULL) { ++ copy.server = (krb5_principal)canonprinc; ++ code = get_proxy_cred_from_kdc(context, options, ccache, ©, ++ &creds); ++ if (code != KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN) ++ break; ++ } ++ if (!code && canonprinc == NULL) ++ code = KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN; ++ free_canonprinc(&iter); ++ if (code) ++ return code; ++ ++ krb5_free_principal(context, creds->server); ++ creds->server = NULL; ++ code = krb5_copy_principal(context, in_creds->server, &creds->server); ++ if (code) { ++ krb5_free_creds(context, creds); ++ return code; ++ } ++ ++ if (!(options & KRB5_GC_NO_STORE)) ++ (void)krb5_cc_store_cred(context, ccache, creds); ++ ++ *out_creds = creds; ++ return 0; ++} ++ + /* + * Exported API for constrained delegation (S4U2Proxy). + * +diff --git a/src/lib/krb5/os/os-proto.h b/src/lib/krb5/os/os-proto.h +index a16a34b74..f1aa60a3e 100644 +--- a/src/lib/krb5/os/os-proto.h ++++ b/src/lib/krb5/os/os-proto.h +@@ -83,6 +83,36 @@ struct sendto_callback_info { + void *data; + }; + ++/* ++ * Initialize with all zeros except for princ. Set no_hostrealm to disable ++ * host-to-realm lookup, which ordinarily happens after canonicalizing the host ++ * part. Set subst_defrealm to substitute the default realm for the referral ++ * realm after realm lookup (this has no effect if no_hostrealm is set). Free ++ * with free_canonprinc() when done. ++ */ ++struct canonprinc { ++ krb5_const_principal princ; ++ krb5_boolean no_hostrealm; ++ krb5_boolean subst_defrealm; ++ int step; ++ char *canonhost; ++ char *realm; ++ krb5_principal_data copy; ++ krb5_data components[2]; ++}; ++ ++/* Yield one or two candidate canonical principal names for iter, then NULL. ++ * Output names are valid for one iteration and must not be freed. */ ++krb5_error_code k5_canonprinc(krb5_context context, struct canonprinc *iter, ++ krb5_const_principal *princ_out); ++ ++static inline void ++free_canonprinc(struct canonprinc *iter) ++{ ++ free(iter->canonhost); ++ free(iter->realm); ++} ++ + krb5_error_code k5_expand_hostname(krb5_context context, const char *host, + krb5_boolean is_fallback, + char **canonhost_out); +diff --git a/src/lib/krb5/os/sn2princ.c b/src/lib/krb5/os/sn2princ.c +index a51761d0c..8b7214189 100644 +--- a/src/lib/krb5/os/sn2princ.c ++++ b/src/lib/krb5/os/sn2princ.c +@@ -85,22 +85,18 @@ qualify_shortname(krb5_context context, const char *host) + return fqdn; + } + +-krb5_error_code +-k5_expand_hostname(krb5_context context, const char *host, +- krb5_boolean is_fallback, char **canonhost_out) ++static krb5_error_code ++expand_hostname(krb5_context context, const char *host, krb5_boolean use_dns, ++ char **canonhost_out) + { + struct addrinfo *ai = NULL, hint; + char namebuf[NI_MAXHOST], *qualified = NULL, *copy, *p; + int err; + const char *canonhost; +- krb5_boolean use_dns; + + *canonhost_out = NULL; + + canonhost = host; +- use_dns = (context->dns_canonicalize_hostname == CANONHOST_TRUE || +- (is_fallback && +- context->dns_canonicalize_hostname == CANONHOST_FALLBACK)); + if (use_dns) { + /* Try a forward lookup of the hostname. */ + memset(&hint, 0, sizeof(hint)); +@@ -161,21 +157,135 @@ krb5_error_code KRB5_CALLCONV + krb5_expand_hostname(krb5_context context, const char *host, + char **canonhost_out) + { +- return k5_expand_hostname(context, host, FALSE, canonhost_out); ++ int use_dns = (context->dns_canonicalize_hostname == CANONHOST_TRUE); ++ ++ return expand_hostname(context, host, use_dns, canonhost_out); + } + +-/* If hostname appears to have a :port or :instance trailer (used in MSSQLSvc +- * principals), return a pointer to the separator. Otherwise return NULL. */ +-static const char * +-find_trailer(const char *hostname) ++/* Split data into hostname and trailer (:port or :instance). Trailers are ++ * used in MSSQLSvc principals. */ ++static void ++split_trailer(const krb5_data *data, krb5_data *host, krb5_data *trailer) + { +- const char *p = strchr(hostname, ':'); ++ char *p = memchr(data->data, ':', data->length); ++ unsigned int tlen = (p == NULL) ? 0 : data->length - (p - data->data); + +- /* Look for a single colon followed by one or more characters. An IPv6 +- * address will have more than one colon, so don't accept that. */ +- if (p == NULL || p[1] == '\0' || strchr(p + 1, ':') != NULL) +- return NULL; +- return p; ++ /* Make sure we have a single colon followed by one or more characters. An ++ * IPv6 address will have more than one colon, so don't accept that. */ ++ if (p == NULL || tlen == 1 || memchr(p + 1, ':', tlen - 1) != NULL) { ++ *host = *data; ++ *trailer = empty_data(); ++ } else { ++ *host = make_data(data->data, p - data->data); ++ *trailer = make_data(p, tlen); ++ } ++} ++ ++static krb5_error_code ++canonicalize_princ(krb5_context context, struct canonprinc *iter, ++ krb5_boolean use_dns, krb5_const_principal *princ_out) ++{ ++ krb5_error_code ret; ++ krb5_data host, trailer; ++ char *hostname = NULL, *canonhost = NULL, *combined = NULL; ++ char **hrealms = NULL; ++ ++ *princ_out = NULL; ++ ++ assert(iter->princ->length == 2); ++ split_trailer(&iter->princ->data[1], &host, &trailer); ++ ++ hostname = k5memdup0(host.data, host.length, &ret); ++ if (hostname == NULL) ++ goto cleanup; ++ ++ if (iter->princ->type == KRB5_NT_SRV_HST) { ++ /* Expand the hostname with or without DNS as specified. */ ++ ret = expand_hostname(context, hostname, use_dns, &canonhost); ++ if (ret) ++ goto cleanup; ++ } else { ++ canonhost = strdup(hostname); ++ if (canonhost == NULL) { ++ ret = ENOMEM; ++ goto cleanup; ++ } ++ } ++ ++ /* Add the trailer to the expanded hostname. */ ++ if (asprintf(&combined, "%s%.*s", canonhost, ++ trailer.length, trailer.data) < 0) { ++ combined = NULL; ++ ret = ENOMEM; ++ goto cleanup; ++ } ++ ++ /* Don't yield the same host part twice. */ ++ if (iter->canonhost != NULL && strcmp(iter->canonhost, combined) == 0) ++ goto cleanup; ++ ++ free(iter->canonhost); ++ iter->canonhost = combined; ++ combined = NULL; ++ ++ /* If the realm is unknown, look up the realm of the expanded hostname. */ ++ if (iter->princ->realm.length == 0 && !iter->no_hostrealm) { ++ ret = krb5_get_host_realm(context, canonhost, &hrealms); ++ if (ret) ++ goto cleanup; ++ if (hrealms[0] == NULL) { ++ ret = KRB5_ERR_HOST_REALM_UNKNOWN; ++ goto cleanup; ++ } ++ free(iter->realm); ++ if (*hrealms[0] == '\0' && iter->subst_defrealm) { ++ ret = krb5_get_default_realm(context, &iter->realm); ++ if (ret) ++ goto cleanup; ++ } else { ++ iter->realm = strdup(hrealms[0]); ++ if (iter->realm == NULL) { ++ ret = ENOMEM; ++ goto cleanup; ++ } ++ } ++ } ++ ++ iter->copy = *iter->princ; ++ if (iter->realm != NULL) ++ iter->copy.realm = string2data(iter->realm); ++ iter->components[0] = iter->princ->data[0]; ++ iter->components[1] = string2data(iter->canonhost); ++ iter->copy.data = iter->components; ++ *princ_out = &iter->copy; ++ ++cleanup: ++ free(hostname); ++ free(canonhost); ++ free(combined); ++ krb5_free_host_realm(context, hrealms); ++ return ret; ++} ++ ++krb5_error_code ++k5_canonprinc(krb5_context context, struct canonprinc *iter, ++ krb5_const_principal *princ_out) ++{ ++ int step = ++iter->step; ++ ++ *princ_out = NULL; ++ ++ /* If we're not doing fallback, the input principal is canonical. */ ++ if (context->dns_canonicalize_hostname != CANONHOST_FALLBACK || ++ iter->princ->type != KRB5_NT_SRV_HST || iter->princ->length != 2) { ++ *princ_out = (step == 1) ? iter->princ : NULL; ++ return 0; ++ } ++ ++ /* Canonicalize without DNS at step 1, with DNS at step 2. */ ++ if (step > 2) ++ return 0; ++ return canonicalize_princ(context, iter, step == 2, princ_out); + } + + krb5_error_code KRB5_CALLCONV +@@ -185,9 +295,10 @@ krb5_sname_to_principal(krb5_context context, const char *hostname, + { + krb5_error_code ret; + krb5_principal princ; +- const char *realm, *trailer; +- char **hrealms = NULL, *canonhost = NULL, *hostonly = NULL, *concat = NULL; ++ krb5_const_principal cprinc; ++ krb5_boolean use_dns; + char localname[MAXHOSTNAMELEN]; ++ struct canonprinc iter = { NULL }; + + *princ_out = NULL; + +@@ -205,54 +316,26 @@ krb5_sname_to_principal(krb5_context context, const char *hostname, + if (sname == NULL) + sname = "host"; + +- /* If there is a trailer, remove it for now. */ +- trailer = find_trailer(hostname); +- if (trailer != NULL) { +- hostonly = k5memdup0(hostname, trailer - hostname, &ret); +- if (hostonly == NULL) +- goto cleanup; +- hostname = hostonly; +- } +- +- /* Canonicalize the hostname if appropriate. */ +- if (type == KRB5_NT_SRV_HST) { +- ret = krb5_expand_hostname(context, hostname, &canonhost); +- if (ret) +- goto cleanup; +- hostname = canonhost; +- } +- +- /* Find the realm of the host. */ +- ret = krb5_get_host_realm(context, hostname, &hrealms); ++ /* Build an initial principal with what we have. */ ++ ret = krb5_build_principal(context, &princ, 0, KRB5_REFERRAL_REALM, ++ sname, hostname, (char *)NULL); + if (ret) +- goto cleanup; +- if (hrealms[0] == NULL) { +- ret = KRB5_ERR_HOST_REALM_UNKNOWN; +- goto cleanup; +- } +- realm = hrealms[0]; +- +- /* If there was a trailer, put it back on the end. */ +- if (trailer != NULL) { +- if (asprintf(&concat, "%s%s", hostname, trailer) < 0) { +- ret = ENOMEM; +- goto cleanup; +- } +- hostname = concat; +- } +- +- ret = krb5_build_principal(context, &princ, strlen(realm), realm, sname, +- hostname, (char *)NULL); +- if (ret) +- goto cleanup; +- ++ return ret; + princ->type = type; +- *princ_out = princ; + +-cleanup: +- free(hostonly); +- free(canonhost); +- free(concat); +- krb5_free_host_realm(context, hrealms); ++ if (type == KRB5_NT_SRV_HST && ++ context->dns_canonicalize_hostname == CANONHOST_FALLBACK) { ++ /* Delay canonicalization and realm lookup until use. */ ++ *princ_out = princ; ++ return 0; ++ } ++ ++ use_dns = (context->dns_canonicalize_hostname == CANONHOST_TRUE); ++ iter.princ = princ; ++ ret = canonicalize_princ(context, &iter, use_dns, &cprinc); ++ if (!ret) ++ ret = krb5_copy_principal(context, cprinc, princ_out); ++ free_canonprinc(&iter); ++ krb5_free_principal(context, princ); + return ret; + } +diff --git a/src/tests/icred.c b/src/tests/icred.c +index 55f929cd7..d6ce1d5d3 100644 +--- a/src/tests/icred.c ++++ b/src/tests/icred.c +@@ -30,10 +30,7 @@ + * OF THE POSSIBILITY OF SUCH DAMAGE. + */ + +-/* +- * This program exercises the init_creds APIs in ways kinit doesn't. Right now +- * it is very simplistic, but it can be extended as needed. +- */ ++/* This program exercises the init_creds APIs in ways kinit doesn't. */ + + #include "k5-platform.h" + #include +@@ -56,10 +53,11 @@ check(krb5_error_code code) + int + main(int argc, char **argv) + { +- const char *princstr, *password; ++ const char *ktname = NULL, *sname = NULL, *princstr, *password; + krb5_principal client; + krb5_init_creds_context icc; + krb5_get_init_creds_opt *opt; ++ krb5_keytab keytab = NULL; + krb5_creds creds; + krb5_boolean stepwise = FALSE; + krb5_preauthtype ptypes[64]; +@@ -69,8 +67,11 @@ main(int argc, char **argv) + check(krb5_init_context(&ctx)); + check(krb5_get_init_creds_opt_alloc(ctx, &opt)); + +- while ((c = getopt(argc, argv, "so:X:")) != -1) { ++ while ((c = getopt(argc, argv, "k:so:S:X:")) != -1) { + switch (c) { ++ case 'k': ++ ktname = optarg; ++ break; + case 's': + stepwise = TRUE; + break; +@@ -78,6 +79,9 @@ main(int argc, char **argv) + assert(nptypes < 64); + ptypes[nptypes++] = atoi(optarg); + break; ++ case 'S': ++ sname = optarg; ++ break; + case 'X': + val = strchr(optarg, '='); + if (val != NULL) +@@ -93,12 +97,20 @@ main(int argc, char **argv) + + argc -= optind; + argv += optind; +- if (argc != 2) ++ if (argc != 1 && argc != 2) + abort(); + princstr = argv[0]; + password = argv[1]; + +- check(krb5_parse_name(ctx, princstr, &client)); ++ if (sname != NULL) { ++ check(krb5_sname_to_principal(ctx, princstr, sname, KRB5_NT_SRV_HST, ++ &client)); ++ } else { ++ check(krb5_parse_name(ctx, princstr, &client)); ++ } ++ ++ if (ktname != NULL) ++ check(krb5_kt_resolve(ctx, ktname, &keytab)); + + if (nptypes > 0) + krb5_get_init_creds_opt_set_preauth_list(opt, ptypes, nptypes); +@@ -106,9 +118,16 @@ main(int argc, char **argv) + if (stepwise) { + /* Use the stepwise interface. */ + check(krb5_init_creds_init(ctx, client, NULL, NULL, 0, NULL, &icc)); +- check(krb5_init_creds_set_password(ctx, icc, password)); ++ if (keytab != NULL) ++ check(krb5_init_creds_set_keytab(ctx, icc, keytab)); ++ if (password != NULL) ++ check(krb5_init_creds_set_password(ctx, icc, password)); + check(krb5_init_creds_get(ctx, icc)); + krb5_init_creds_free(ctx, icc); ++ } else if (keytab != NULL) { ++ check(krb5_get_init_creds_keytab(ctx, &creds, client, keytab, 0, NULL, ++ opt)); ++ krb5_free_cred_contents(ctx, &creds); + } else { + /* Use the traditional one-shot interface. */ + check(krb5_get_init_creds_password(ctx, &creds, client, password, NULL, +@@ -116,6 +135,8 @@ main(int argc, char **argv) + krb5_free_cred_contents(ctx, &creds); + } + ++ if (keytab != NULL) ++ krb5_kt_close(ctx, keytab); + krb5_get_init_creds_opt_free(ctx, opt); + krb5_free_principal(ctx, client); + krb5_free_context(ctx); +diff --git a/src/tests/t_sn2princ.py b/src/tests/t_sn2princ.py +index f3e187286..493fba219 100755 +--- a/src/tests/t_sn2princ.py ++++ b/src/tests/t_sn2princ.py +@@ -85,28 +85,9 @@ if offline: + oname = 'ptr-mismatch.kerberos.org' + fname = 'www.kerberos.org' + +-# Test fallback canonicalization krb5_sname_to_principal() results +-# (same as dns_canonicalize_hostname=false). ++# Test fallback canonicalization krb5_sname_to_principal() results. + mark('dns_canonicalize_host=fallback') +-testfc(oname, oname, 'R1') +- +-# Test fallback canonicalization in krb5_get_credentials(). +-oprinc = 'host/' + oname +-fprinc = 'host/' + fname +-shutil.copy(realm.ccache, realm.ccache + '.save') +-realm.addprinc(fprinc) +-# oprinc doesn't exist, so we get the canonicalized fprinc as a fallback. +-msgs = ('Falling back to canonicalized server hostname ' + fname,) +-realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon, +- expected_msg=fprinc, expected_trace=msgs) +-realm.addprinc(oprinc) +-# oprinc now exists, but we still get the fprinc ticket from the cache. +-realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon, +- expected_msg=fprinc) +-# Without the cached result, we sould get oprinc in preference to fprinc. +-os.rename(realm.ccache + '.save', realm.ccache) +-realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon, +- expected_msg=oprinc) ++testfc(oname, oname, '') + + # Verify forward resolution before testing for it. + try: +@@ -118,6 +99,48 @@ if canonname.lower() != fname: + skip_rest('sn2princ tests', + '%s forward resolves to %s, not %s' % (oname, canonname, fname)) + ++# Test fallback canonicalization in krb5_get_credentials(). ++oprinc = 'host/' + oname ++fprinc = 'host/' + fname ++shutil.copy(realm.ccache, realm.ccache + '.save') ++# Test that we only try fprinc once if we enter it as input. ++out, trace = realm.run(['./gcred', 'srv-hst', fprinc + '@'], ++ env=fallback_canon, expected_code=1, return_trace=True) ++msg = 'Requesting tickets for %s@R1, referrals on' % fprinc ++if trace.count(msg) != 1: ++ fail('Expected one try for %s' % fprinc) ++# Create fprinc, and verify that we get it as the canonicalized ++# fallback for oprinc. ++realm.addprinc(fprinc) ++msgs = ('Getting credentials user@R1 -> %s@ using' % oprinc, ++ 'Requesting tickets for %s@R1' % oprinc, ++ 'Requesting tickets for %s@R1' % fprinc, ++ 'Received creds for desired service %s@R1' % fprinc) ++realm.run(['./gcred', 'srv-hst', oprinc + '@'], env=fallback_canon, ++ expected_msg=fprinc, expected_trace=msgs) ++realm.addprinc(oprinc) ++# oprinc now exists, but we still get the fprinc ticket from the cache. ++realm.run(['./gcred', 'srv-hst', oprinc + '@'], env=fallback_canon, ++ expected_msg=fprinc) ++# Without the cached result, we sould get oprinc in preference to fprinc. ++os.rename(realm.ccache + '.save', realm.ccache) ++realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon, ++ expected_msg=oprinc) ++ ++# Test fallback canonicalization for krb5_rd_req(). ++realm.run([kadminl, 'ktadd', fprinc]) ++msgs = ('Decrypted AP-REQ with server principal %s@R1' % fprinc, ++ 'AP-REQ ticket: user@R1 -> %s@R1' % fprinc) ++realm.run(['./rdreq', fprinc, oprinc + '@'], env=fallback_canon, ++ expected_trace=msgs) ++ ++# Test fallback canonicalization for getting initial creds with a keytab. ++msgs = ('Getting initial credentials for %s@' % oprinc, ++ 'Found entries for %s@R1 in keytab' % fprinc, ++ 'Retrieving %s@R1 from ' % fprinc) ++realm.run(['./icred', '-k', realm.keytab, '-S', 'host', oname], ++ env=fallback_canon, expected_trace=msgs) ++ + # Test forward-only canonicalization (rdns=false). + mark('rdns=false') + testnr(oname, fname, 'R1') diff --git a/Prevent-deletion-of-K-M.patch b/Prevent-deletion-of-K-M.patch new file mode 100644 index 0000000..5e2c117 --- /dev/null +++ b/Prevent-deletion-of-K-M.patch @@ -0,0 +1,45 @@ +From 7986adf30dffdd16fec43f261a2fa1384e0b8b90 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sat, 13 Jun 2020 21:55:54 -0400 +Subject: [PATCH] Prevent deletion of K/M + +In libkadm5srv, do not allow deletion of the master key principal, as +it is very difficult to recover a KDB after doing so. + +ticket: 8913 +(cherry picked from commit 94b936a1bf0a8c67809597c5ea5400d8994d5dd8) +--- + src/lib/kadm5/srv/svr_principal.c | 4 ++++ + src/tests/t_kadmin_acl.py | 6 ++++++ + 2 files changed, 10 insertions(+) + +diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c +index 53ecbe1bc..c2412df31 100644 +--- a/src/lib/kadm5/srv/svr_principal.c ++++ b/src/lib/kadm5/srv/svr_principal.c +@@ -537,6 +537,10 @@ kadm5_delete_principal(void *server_handle, krb5_principal principal) + if (principal == NULL) + return EINVAL; + ++ /* Deleting K/M is mostly unrecoverable, so don't allow it. */ ++ if (krb5_principal_compare(handle->context, principal, master_princ)) ++ return KADM5_PROTECT_PRINCIPAL; ++ + if ((ret = kdb_get_entry(handle, principal, &kdb, &adb))) + return(ret); + ret = k5_kadm5_hook_remove(handle->context, handle->hook_handles, +diff --git a/src/tests/t_kadmin_acl.py b/src/tests/t_kadmin_acl.py +index 86eb59729..8946e8cc4 100755 +--- a/src/tests/t_kadmin_acl.py ++++ b/src/tests/t_kadmin_acl.py +@@ -328,4 +328,10 @@ realm.run([kadmin, '-c', realm.ccache, 'cpw', '-randkey', 'none'], + realm.run([kadmin, '-c', realm.ccache, 'cpw', '-randkey', '-e', 'aes256-cts', + 'none'], expected_code=1, expected_msg=msg) + ++# Test operations disallowed at the libkadm5 layer. ++realm.run([kadminl, 'delprinc', 'K/M'], ++ expected_code=1, expected_msg='Cannot change protected principal') ++realm.run([kadminl, 'cpw', '-pw', 'pw', 'kadmin/history'], ++ expected_code=1, expected_msg='Cannot change protected principal') ++ + success('kadmin ACL enforcement') diff --git a/Refactor-cache-checking-in-TGS-client-code.patch b/Refactor-cache-checking-in-TGS-client-code.patch new file mode 100644 index 0000000..86315ec --- /dev/null +++ b/Refactor-cache-checking-in-TGS-client-code.patch @@ -0,0 +1,188 @@ +From 0cffa5904341460353fa7f99b5aa514fc27a10eb Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 23 Jul 2020 01:52:43 -0400 +Subject: [PATCH] Refactor cache checking in TGS client code + +(cherry picked from commit 8f2f0a2e8f65c4b39883129967301e3a8986218b) +--- + src/lib/krb5/krb/get_creds.c | 86 +++++++++++++++++++++--------------- + src/lib/krb5/krb/int-proto.h | 6 +-- + src/lib/krb5/krb/s4u_creds.c | 21 +-------- + 3 files changed, 55 insertions(+), 58 deletions(-) + +diff --git a/src/lib/krb5/krb/get_creds.c b/src/lib/krb5/krb/get_creds.c +index b3f01be9b..32401bcb1 100644 +--- a/src/lib/krb5/krb/get_creds.c ++++ b/src/lib/krb5/krb/get_creds.c +@@ -48,10 +48,10 @@ + * and options. The fields of *mcreds will be aliased to the fields + * of in_creds, so the contents of *mcreds should not be freed. + */ +-krb5_error_code +-krb5int_construct_matching_creds(krb5_context context, krb5_flags options, +- krb5_creds *in_creds, krb5_creds *mcreds, +- krb5_flags *fields) ++static krb5_error_code ++construct_matching_creds(krb5_context context, krb5_flags options, ++ krb5_creds *in_creds, krb5_creds *mcreds, ++ krb5_flags *fields) + { + if (!in_creds || !in_creds->server || !in_creds->client) + return EINVAL; +@@ -110,6 +110,50 @@ krb5int_construct_matching_creds(krb5_context context, krb5_flags options, + return 0; + } + ++/* Simple wrapper around krb5_cc_retrieve_cred which allocates the result ++ * container. */ ++static krb5_error_code ++cache_get(krb5_context context, krb5_ccache ccache, krb5_flags flags, ++ krb5_creds *in_creds, krb5_creds **out_creds) ++{ ++ krb5_error_code code; ++ krb5_creds *creds; ++ ++ *out_creds = NULL; ++ ++ creds = malloc(sizeof(*creds)); ++ if (creds == NULL) ++ return ENOMEM; ++ ++ code = krb5_cc_retrieve_cred(context, ccache, flags, in_creds, creds); ++ if (code != 0) { ++ free(creds); ++ return code; ++ } ++ ++ *out_creds = creds; ++ return 0; ++} ++ ++krb5_error_code ++k5_get_cached_cred(krb5_context context, krb5_flags options, ++ krb5_ccache ccache, krb5_creds *in_creds, ++ krb5_creds **creds_out) ++{ ++ krb5_error_code code; ++ krb5_creds mcreds; ++ krb5_flags fields; ++ ++ *creds_out = NULL; ++ ++ code = construct_matching_creds(context, options, in_creds, ++ &mcreds, &fields); ++ if (code) ++ return code; ++ ++ return cache_get(context, ccache, fields, &mcreds, creds_out); ++} ++ + /* + * krb5_tkt_creds_step() is implemented using a tail call style. Every + * begin_*, step_*, or *_request function is responsible for returning an +@@ -235,31 +279,6 @@ cleanup: + return code; + } + +-/* Simple wrapper around krb5_cc_retrieve_cred which allocates the result +- * container. */ +-static krb5_error_code +-cache_get(krb5_context context, krb5_ccache ccache, krb5_flags flags, +- krb5_creds *in_creds, krb5_creds **out_creds) +-{ +- krb5_error_code code; +- krb5_creds *creds; +- +- *out_creds = NULL; +- +- creds = malloc(sizeof(*creds)); +- if (creds == NULL) +- return ENOMEM; +- +- code = krb5_cc_retrieve_cred(context, ccache, flags, in_creds, creds); +- if (code != 0) { +- free(creds); +- return code; +- } +- +- *out_creds = creds; +- return 0; +-} +- + /* + * Set up the request given by ctx->tgs_in_creds, using ctx->cur_tgt. KDC + * options for the requests are determined by ctx->cur_tgt->ticket_flags and +@@ -1023,18 +1042,13 @@ static krb5_error_code + check_cache(krb5_context context, krb5_tkt_creds_context ctx) + { + krb5_error_code code; +- krb5_creds mcreds; +- krb5_flags fields; + krb5_creds req_in_creds; + + /* Check the cache for the originally requested server principal. */ + req_in_creds = *ctx->in_creds; + req_in_creds.server = ctx->req_server; +- code = krb5int_construct_matching_creds(context, ctx->req_options, +- &req_in_creds, &mcreds, &fields); +- if (code) +- return code; +- code = cache_get(context, ctx->ccache, fields, &mcreds, &ctx->reply_creds); ++ code = k5_get_cached_cred(context, ctx->req_options, ctx->ccache, ++ &req_in_creds, &ctx->reply_creds); + if (code == 0) { + ctx->state = STATE_COMPLETE; + return 0; +diff --git a/src/lib/krb5/krb/int-proto.h b/src/lib/krb5/krb/int-proto.h +index fe61bebf5..5211044dc 100644 +--- a/src/lib/krb5/krb/int-proto.h ++++ b/src/lib/krb5/krb/int-proto.h +@@ -79,9 +79,9 @@ clpreauth_otp_initvt(krb5_context context, int maj_ver, int min_ver, + krb5_plugin_vtable vtable); + + krb5_error_code +-krb5int_construct_matching_creds(krb5_context context, krb5_flags options, +- krb5_creds *in_creds, krb5_creds *mcreds, +- krb5_flags *fields); ++k5_get_cached_cred(krb5_context context, krb5_flags options, ++ krb5_ccache ccache, krb5_creds *in_creds, ++ krb5_creds **creds_out); + + #define IS_TGS_PRINC(p) ((p)->length == 2 && \ + data_eq_string((p)->data[0], KRB5_TGS_NAME)) +diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c +index d44f939f8..eadb37cd0 100644 +--- a/src/lib/krb5/krb/s4u_creds.c ++++ b/src/lib/krb5/krb/s4u_creds.c +@@ -1155,29 +1155,12 @@ k5_get_proxy_cred_from_kdc(krb5_context context, krb5_flags options, + { + krb5_error_code code; + krb5_const_principal canonprinc; +- krb5_creds mcreds, copy, *creds, *ncreds; +- krb5_flags fields; ++ krb5_creds copy, *creds; + struct canonprinc iter = { in_creds->server, .no_hostrealm = TRUE }; + + *out_creds = NULL; + +- code = krb5int_construct_matching_creds(context, options, in_creds, +- &mcreds, &fields); +- if (code != 0) +- return code; +- +- ncreds = calloc(1, sizeof(*ncreds)); +- if (ncreds == NULL) +- return ENOMEM; +- ncreds->magic = KV5M_CRED; +- +- code = krb5_cc_retrieve_cred(context, ccache, fields, &mcreds, ncreds); +- if (code) { +- free(ncreds); +- } else { +- *out_creds = ncreds; +- } +- ++ code = k5_get_cached_cred(context, options, ccache, in_creds, out_creds); + if ((code != KRB5_CC_NOTFOUND && code != KRB5_CC_NOT_KTYPE) || + options & KRB5_GC_CACHED) + return code; diff --git a/Try-kadmin-admin-first-in-libkadm5clnt.patch b/Try-kadmin-admin-first-in-libkadm5clnt.patch new file mode 100644 index 0000000..6249ff5 --- /dev/null +++ b/Try-kadmin-admin-first-in-libkadm5clnt.patch @@ -0,0 +1,159 @@ +From fae915ea7f2734cfd9ef3d5952f25638e675bb7c Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 27 Jul 2020 01:19:01 -0400 +Subject: [PATCH] Try kadmin/admin first in libkadm5clnt + +The MIT krb5 kadmin protocol originally used kadmin/admin as the +service principal. Commits 493f0da5fbf92b0ac2f10e887706d1964d8a15e8 +and 5cfaec38a8e8f1c4b76228ba0a252987af797ca4 changed it to use +kadmin/hostname preferentially, with kadmin/admin as a fallback, for +interoperability with the Solaris SEAM administrative protocol. + +Change the preference order so that kadmin/admin is tried first, with +kadmin/hostname as a fallback. + +ticket: 8934 (new) +(cherry picked from commit 1d282badfbd6098e3db9d50d22d565c2ec3c8c47) +--- + doc/admin/admin_commands/kadmin_local.rst | 14 ++++++------ + doc/admin/database.rst | 10 ++++----- + src/lib/kadm5/clnt/client_init.c | 26 +++++++++-------------- + src/tests/t_kadmin_acl.py | 14 ++++++++++++ + 4 files changed, 36 insertions(+), 28 deletions(-) + +diff --git a/doc/admin/admin_commands/kadmin_local.rst b/doc/admin/admin_commands/kadmin_local.rst +index fafa61365..33cf3a9cb 100644 +--- a/doc/admin/admin_commands/kadmin_local.rst ++++ b/doc/admin/admin_commands/kadmin_local.rst +@@ -44,9 +44,9 @@ Kerberos principals, password policies, and service key tables + (keytabs). + + The remote kadmin client uses Kerberos to authenticate to kadmind +-using the service principal ``kadmin/ADMINHOST`` (where *ADMINHOST* is +-the fully-qualified hostname of the admin server) or ``kadmin/admin``. +-If the credentials cache contains a ticket for one of these ++using the service principal ``kadmin/admin`` or ``kadmin/ADMINHOST`` ++(where *ADMINHOST* is the fully-qualified hostname of the admin ++server). If the credentials cache contains a ticket for one of these + principals, and the **-c** credentials_cache option is specified, that + ticket is used to authenticate to kadmind. Otherwise, the **-p** and + **-k** options are used to specify the client Kerberos principal name +@@ -100,10 +100,10 @@ OPTIONS + fully anonymous operation. + + **-c** *credentials_cache* +- Use *credentials_cache* as the credentials cache. The +- cache should contain a service ticket for the ``kadmin/ADMINHOST`` +- (where *ADMINHOST* is the fully-qualified hostname of the admin +- server) or ``kadmin/admin`` service; it can be acquired with the ++ Use *credentials_cache* as the credentials cache. The cache ++ should contain a service ticket for the ``kadmin/admin`` or ++ ``kadmin/ADMINHOST`` (where *ADMINHOST* is the fully-qualified ++ hostname of the admin server) service; it can be acquired with the + :ref:`kinit(1)` program. If this option is not specified, kadmin + requests a new service ticket from the KDC, and stores it in its + own temporary ccache. +diff --git a/doc/admin/database.rst b/doc/admin/database.rst +index e62cef7a7..ca19a362a 100644 +--- a/doc/admin/database.rst ++++ b/doc/admin/database.rst +@@ -26,8 +26,8 @@ local filesystem (or through LDAP). kadmin.local is necessary to set + up enough of the database to be able to use the remote version. + + kadmin can authenticate to the admin server using the service +-principal ``kadmin/HOST`` (where *HOST* is the hostname of the admin +-server) or ``kadmin/admin``. If the credentials cache contains a ++principal ``kadmin/admin`` or ``kadmin/HOST`` (where *HOST* is the ++hostname of the admin server). If the credentials cache contains a + ticket for either service principal and the **-c** ccache option is + specified, that ticket is used to authenticate to KADM5. Otherwise, + the **-p** and **-k** options are used to specify the client Kerberos +@@ -811,9 +811,9 @@ Both master and replica sides must have a principal named + ``kiprop/hostname`` (where *hostname* is the lowercase, + fully-qualified, canonical name for the host) registered in the + Kerberos database, and have keys for that principal stored in the +-default keytab file (|keytab|). In release 1.13, the +-``kiprop/hostname`` principal is created automatically for the master +-KDC, but it must still be created for replica KDCs. ++default keytab file (|keytab|). The ``kiprop/hostname`` principal may ++have been created automatically for the master KDC, but it must always ++be created for replica KDCs. + + On the master KDC side, the ``kiprop/hostname`` principal must be + listed in the kadmind ACL file :ref:`kadm5.acl(5)`, and given the +diff --git a/src/lib/kadm5/clnt/client_init.c b/src/lib/kadm5/clnt/client_init.c +index aa08918e2..8d43ab97a 100644 +--- a/src/lib/kadm5/clnt/client_init.c ++++ b/src/lib/kadm5/clnt/client_init.c +@@ -372,22 +372,10 @@ get_init_creds(kadm5_server_handle_t handle, krb5_principal client, + { + kadm5_ret_t code; + krb5_ccache ccache = NULL; +- char svcname[BUFSIZ]; ++ char *svcname, svcbuf[BUFSIZ]; + + *server_out = NULL; + +- /* NULL svcname means use host-based. */ +- if (svcname_in == NULL) { +- code = kadm5_get_admin_service_name(handle->context, +- handle->params.realm, +- svcname, sizeof(svcname)); +- if (code) +- goto error; +- } else { +- strncpy(svcname, svcname_in, sizeof(svcname)); +- svcname[sizeof(svcname)-1] = '\0'; +- } +- + /* + * Acquire a service ticket for svcname@realm for client, using password + * pass (which could be NULL), and create a ccache to store them in. If +@@ -423,13 +411,19 @@ get_init_creds(kadm5_server_handle_t handle, krb5_principal client, + } + handle->lhandle->cache_name = handle->cache_name; + ++ svcname = (svcname_in != NULL) ? svcname_in : KADM5_ADMIN_SERVICE; + code = gic_iter(handle, init_type, ccache, client, pass, svcname, realm, + server_out); + if ((code == KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN + || code == KRB5_CC_NOTFOUND) && svcname_in == NULL) { +- /* Retry with old host-independent service principal. */ +- code = gic_iter(handle, init_type, ccache, client, pass, +- KADM5_ADMIN_SERVICE, realm, server_out); ++ /* Retry with host-based service principal. */ ++ code = kadm5_get_admin_service_name(handle->context, ++ handle->params.realm, ++ svcbuf, sizeof(svcbuf)); ++ if (code) ++ goto error; ++ code = gic_iter(handle, init_type, ccache, client, pass, svcbuf, realm, ++ server_out); + } + /* Improved error messages */ + if (code == KRB5KRB_AP_ERR_BAD_INTEGRITY) code = KADM5_BAD_PASSWORD; +diff --git a/src/tests/t_kadmin_acl.py b/src/tests/t_kadmin_acl.py +index 8946e8cc4..16faf0a9d 100755 +--- a/src/tests/t_kadmin_acl.py ++++ b/src/tests/t_kadmin_acl.py +@@ -328,6 +328,20 @@ realm.run([kadmin, '-c', realm.ccache, 'cpw', '-randkey', 'none'], + realm.run([kadmin, '-c', realm.ccache, 'cpw', '-randkey', '-e', 'aes256-cts', + 'none'], expected_code=1, expected_msg=msg) + ++# Test authentication to kadmin/hostname. ++mark('authentication to kadmin/hostname') ++kadmin_hostname = 'kadmin/' + hostname ++realm.run([kadminl, 'delprinc', 'kadmin/admin']) ++msgs = ('Getting initial credentials for user/admin@KRBTEST.COM', ++ 'Setting initial creds service to kadmin/admin', ++ '/Server not found in Kerberos database', ++ 'Getting initial credentials for user/admin@KRBTEST.COM', ++ 'Setting initial creds service to ' + kadmin_hostname, ++ 'Decrypted AS reply') ++realm.run([kadmin, '-p', 'user/admin', 'listprincs'], expected_code=1, ++ expected_msg="Operation requires ``list'' privilege", ++ input=password('user/admin'), expected_trace=msgs) ++ + # Test operations disallowed at the libkadm5 layer. + realm.run([kadminl, 'delprinc', 'K/M'], + expected_code=1, expected_msg='Cannot change protected principal') diff --git a/krb5.spec b/krb5.spec index 7199f35..081299e 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 18%{?dist} +Release: 19%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -71,6 +71,12 @@ Patch32: Use-two-queues-for-concurrent-t_otp.py-daemons.patch Patch33: Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch Patch34: Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch Patch35: Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch +Patch36: Prevent-deletion-of-K-M.patch +Patch37: Try-kadmin-admin-first-in-libkadm5clnt.patch +Patch38: Don-t-create-hostbased-principals-in-new-KDBs.patch +Patch39: Expand-dns_canonicalize_host-fallback-support.patch +Patch40: Cache-S4U2Proxy-requests-by-second-ticket.patch +Patch41: Refactor-cache-checking-in-TGS-client-code.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -632,6 +638,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Aug 07 2020 Robbie Harwood - 1.18.2-19 +- Expand dns_canonicalize_hostname=fallback support + * Tue Aug 04 2020 Robbie Harwood - 1.18.2-18 - Fix leak in KERB_AP_OPTIONS_CBT server support From cd0b1d6ba6cfd96da3b09731a33b40d190751a09 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 13 Aug 2020 09:50:45 -0400 Subject: [PATCH 191/304] Temporarily dns_canonicalize_hostname=fallback changes Hopefully unbreak IPA while we debug further --- ...-S4U2Proxy-requests-by-second-ticket.patch | 327 ----- ...ate-hostbased-principals-in-new-KDBs.patch | 195 --- ...s_canonicalize_host-fallback-support.patch | 1190 ----------------- Prevent-deletion-of-K-M.patch | 45 - ...or-cache-checking-in-TGS-client-code.patch | 188 --- Try-kadmin-admin-first-in-libkadm5clnt.patch | 159 --- krb5.spec | 12 +- 7 files changed, 5 insertions(+), 2111 deletions(-) delete mode 100644 Cache-S4U2Proxy-requests-by-second-ticket.patch delete mode 100644 Don-t-create-hostbased-principals-in-new-KDBs.patch delete mode 100644 Expand-dns_canonicalize_host-fallback-support.patch delete mode 100644 Prevent-deletion-of-K-M.patch delete mode 100644 Refactor-cache-checking-in-TGS-client-code.patch delete mode 100644 Try-kadmin-admin-first-in-libkadm5clnt.patch diff --git a/Cache-S4U2Proxy-requests-by-second-ticket.patch b/Cache-S4U2Proxy-requests-by-second-ticket.patch deleted file mode 100644 index 01532bf..0000000 --- a/Cache-S4U2Proxy-requests-by-second-ticket.patch +++ /dev/null @@ -1,327 +0,0 @@ -From 158ce9222351216507da39d7bb4233469603e647 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Tue, 21 Jul 2020 00:40:06 +0200 -Subject: [PATCH] Cache S4U2Proxy requests by second ticket - -krb5_get_credentials() does not know the client principal for an -S4U2Proxy request until the end, because it is in the encrypted part -of the evidence ticket. However, we can check the cache by second -ticket, since all S4U2Proxy requests in a cache will generally be made -with the same evidence ticket. - -In the ccache types, allow mcreds->client and mcreds->server to be -NULL (as Heimdal does) to ignore them for the purpose of matching. In -krb5int_construct_matching_creds(), set mcreds->client to NULL for -S4U2Proxy requests. Add a cache check to -k5_get_proxy_cred_from_kdc(), and remove the cache check from -krb5_get_credentials_for_proxy() and the krb5 mech's -get_credentials(). - -In get_proxy_cred_from_kdc(), fix a bug where cross-realm S4U2Proxy -would cache the evidence ticket used in the final request, rather than -the original evidence ticket. - -[ghudson@mit.edu: debugged cache check and cross-realm caching; -switched from new flag to null matching cred principals; wrote commit -message] - -ticket: 8931 (new) -(cherry picked from commit 148b317e1eb5df28dad96679cb4b8a07c62d4786) ---- - src/lib/gssapi/krb5/init_sec_context.c | 61 ++++++++++++-------------- - src/lib/krb5/ccache/cc_retr.c | 13 +++--- - src/lib/krb5/ccache/ccapi/stdcc_util.c | 30 ++++++------- - src/lib/krb5/ccache/ccfns.c | 3 +- - src/lib/krb5/krb/get_creds.c | 5 +++ - src/lib/krb5/krb/s4u_creds.c | 58 ++++++++++++------------ - src/tests/s4u2proxy.c | 3 ++ - 7 files changed, 88 insertions(+), 85 deletions(-) - -diff --git a/src/lib/gssapi/krb5/init_sec_context.c b/src/lib/gssapi/krb5/init_sec_context.c -index 3f77157c9..823656037 100644 ---- a/src/lib/gssapi/krb5/init_sec_context.c -+++ b/src/lib/gssapi/krb5/init_sec_context.c -@@ -165,44 +165,37 @@ static krb5_error_code get_credentials(context, cred, server, now, - goto cleanup; - } - -- /* -- * For IAKERB or constrained delegation, only check the cache in this step. -- * For IAKERB we will ask the server to make any necessary TGS requests; -- * for constrained delegation we will adjust in_creds and make an S4U2Proxy -- * request below if the cache lookup fails. -- */ -- if (cred->impersonator != NULL || cred->iakerb_mech) -+ /* Try constrained delegation if we have proxy credentials. */ -+ if (cred->impersonator != NULL) { -+ /* If we are trying to get a ticket to ourselves, we should use the -+ * the evidence ticket directly from cache. */ -+ if (krb5_principal_compare(context, cred->impersonator, -+ server->princ)) { -+ flags |= KRB5_GC_CACHED; -+ } else { -+ memset(&mcreds, 0, sizeof(mcreds)); -+ mcreds.magic = KV5M_CREDS; -+ mcreds.server = cred->impersonator; -+ mcreds.client = cred->name->princ; -+ code = krb5_cc_retrieve_cred(context, cred->ccache, -+ KRB5_TC_MATCH_AUTHDATA, &mcreds, -+ &evidence_creds); -+ if (code) -+ goto cleanup; -+ -+ in_creds.client = cred->impersonator; -+ in_creds.second_ticket = evidence_creds.ticket; -+ flags = KRB5_GC_CANONICALIZE | KRB5_GC_CONSTRAINED_DELEGATION; -+ } -+ } -+ -+ /* For IAKERB, only check the cache in this step. We will ask the server -+ * to make any necessary TGS requests. */ -+ if (cred->iakerb_mech) - flags |= KRB5_GC_CACHED; - - code = krb5_get_credentials(context, flags, cred->ccache, - &in_creds, &result_creds); -- -- /* -- * Try constrained delegation if we have proxy credentials, unless -- * we are trying to get a ticket to ourselves (in which case we could -- * just use the evidence ticket directly from cache). -- */ -- if (code == KRB5_CC_NOTFOUND && cred->impersonator != NULL && -- !cred->iakerb_mech && -- !krb5_principal_compare(context, cred->impersonator, server->princ)) { -- -- memset(&mcreds, 0, sizeof(mcreds)); -- mcreds.magic = KV5M_CREDS; -- mcreds.server = cred->impersonator; -- mcreds.client = cred->name->princ; -- code = krb5_cc_retrieve_cred(context, cred->ccache, -- KRB5_TC_MATCH_AUTHDATA, &mcreds, -- &evidence_creds); -- if (code) -- goto cleanup; -- -- in_creds.client = cred->impersonator; -- in_creds.second_ticket = evidence_creds.ticket; -- flags = KRB5_GC_CANONICALIZE | KRB5_GC_CONSTRAINED_DELEGATION; -- code = krb5_get_credentials(context, flags, cred->ccache, -- &in_creds, &result_creds); -- } -- - if (code) - goto cleanup; - -diff --git a/src/lib/krb5/ccache/cc_retr.c b/src/lib/krb5/ccache/cc_retr.c -index 2c50c9cce..4328b7d6f 100644 ---- a/src/lib/krb5/ccache/cc_retr.c -+++ b/src/lib/krb5/ccache/cc_retr.c -@@ -58,15 +58,14 @@ static krb5_boolean - princs_match(krb5_context context, krb5_flags whichfields, - const krb5_creds *mcreds, const krb5_creds *creds) - { -- krb5_principal_data princ; -- -- if (!krb5_principal_compare(context, mcreds->client, creds->client)) -+ if (mcreds->client != NULL && -+ !krb5_principal_compare(context, mcreds->client, creds->client)) - return FALSE; -+ if (mcreds->server == NULL) -+ return TRUE; - if (whichfields & KRB5_TC_MATCH_SRV_NAMEONLY) { -- /* Ignore the server realm. */ -- princ = *mcreds->server; -- princ.realm = creds->server->realm; -- return krb5_principal_compare(context, &princ, creds->server); -+ return krb5_principal_compare_any_realm(context, mcreds->server, -+ creds->server); - } else { - return krb5_principal_compare(context, mcreds->server, creds->server); - } -diff --git a/src/lib/krb5/ccache/ccapi/stdcc_util.c b/src/lib/krb5/ccache/ccapi/stdcc_util.c -index 1f2a3865c..58aa81165 100644 ---- a/src/lib/krb5/ccache/ccapi/stdcc_util.c -+++ b/src/lib/krb5/ccache/ccapi/stdcc_util.c -@@ -945,8 +945,13 @@ standard_fields_match(context, mcreds, creds) - krb5_context context; - const krb5_creds *mcreds, *creds; - { -- return (krb5_principal_compare(context, mcreds->client,creds->client) && -- krb5_principal_compare(context, mcreds->server,creds->server)); -+ if (mcreds->client != NULL && -+ !krb5_principal_compare(context, mcreds->client, creds->client)) -+ return FALSE; -+ if (mcreds->server != NULL && -+ !krb5_principal_compare(context, mcreds->server,creds->server)) -+ return FALSE; -+ return TRUE; - } - - /* only match the server name portion, not the server realm portion */ -@@ -956,19 +961,14 @@ srvname_match(context, mcreds, creds) - krb5_context context; - const krb5_creds *mcreds, *creds; - { -- krb5_boolean retval; -- krb5_principal_data p1, p2; -- -- retval = krb5_principal_compare(context, mcreds->client,creds->client); -- if (retval != TRUE) -- return retval; -- /* -- * Hack to ignore the server realm for the purposes of the compare. -- */ -- p1 = *mcreds->server; -- p2 = *creds->server; -- p1.realm = p2.realm; -- return krb5_principal_compare(context, &p1, &p2); -+ if (mcreds->client != NULL && -+ !krb5_principal_compare(context, mcreds->client, creds->client)) -+ return FALSE; -+ if (mcreds->server != NULL && -+ !krb5_principal_compare_any_realm(context, mcreds->server, -+ creds->server)) -+ return FALSE; -+ return TRUE; - } - - -diff --git a/src/lib/krb5/ccache/ccfns.c b/src/lib/krb5/ccache/ccfns.c -index 62a6983d8..59982b752 100644 ---- a/src/lib/krb5/ccache/ccfns.c -+++ b/src/lib/krb5/ccache/ccfns.c -@@ -96,7 +96,8 @@ krb5_cc_retrieve_cred(krb5_context context, krb5_ccache cache, - TRACE_CC_RETRIEVE(context, cache, mcreds, ret); - if (ret != KRB5_CC_NOTFOUND) - return ret; -- if (!krb5_is_referral_realm(&mcreds->server->realm)) -+ if (mcreds->client == NULL || mcreds->server == NULL || -+ !krb5_is_referral_realm(&mcreds->server->realm)) - return ret; - - /* -diff --git a/src/lib/krb5/krb/get_creds.c b/src/lib/krb5/krb/get_creds.c -index dc0aef667..b3f01be9b 100644 ---- a/src/lib/krb5/krb/get_creds.c -+++ b/src/lib/krb5/krb/get_creds.c -@@ -102,6 +102,11 @@ krb5int_construct_matching_creds(krb5_context context, krb5_flags options, - return KRB5_NO_2ND_TKT; - } - -+ /* For S4U2Proxy requests we don't know the impersonated client in this -+ * API, but matching against the second ticket is good enough. */ -+ if (options & KRB5_GC_CONSTRAINED_DELEGATION) -+ mcreds->client = NULL; -+ - return 0; - } - -diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c -index 07c7a98be..d44f939f8 100644 ---- a/src/lib/krb5/krb/s4u_creds.c -+++ b/src/lib/krb5/krb/s4u_creds.c -@@ -1122,6 +1122,13 @@ get_proxy_cred_from_kdc(krb5_context context, krb5_flags options, - code = KRB5KRB_AP_WRONG_PRINC; - goto cleanup; - } -+ -+ /* Put the original evidence ticket in the output creds. */ -+ krb5_free_data_contents(context, &tkt->second_ticket); -+ code = krb5int_copy_data_contents(context, &in_creds->second_ticket, -+ &tkt->second_ticket); -+ if (code) -+ goto cleanup; - } - - /* Note the authdata we asked for in the output creds. */ -@@ -1148,11 +1155,33 @@ k5_get_proxy_cred_from_kdc(krb5_context context, krb5_flags options, - { - krb5_error_code code; - krb5_const_principal canonprinc; -- krb5_creds copy, *creds; -+ krb5_creds mcreds, copy, *creds, *ncreds; -+ krb5_flags fields; - struct canonprinc iter = { in_creds->server, .no_hostrealm = TRUE }; - - *out_creds = NULL; - -+ code = krb5int_construct_matching_creds(context, options, in_creds, -+ &mcreds, &fields); -+ if (code != 0) -+ return code; -+ -+ ncreds = calloc(1, sizeof(*ncreds)); -+ if (ncreds == NULL) -+ return ENOMEM; -+ ncreds->magic = KV5M_CRED; -+ -+ code = krb5_cc_retrieve_cred(context, ccache, fields, &mcreds, ncreds); -+ if (code) { -+ free(ncreds); -+ } else { -+ *out_creds = ncreds; -+ } -+ -+ if ((code != KRB5_CC_NOTFOUND && code != KRB5_CC_NOT_KTYPE) || -+ options & KRB5_GC_CACHED) -+ return code; -+ - copy = *in_creds; - while ((code = k5_canonprinc(context, &iter, &canonprinc)) == 0 && - canonprinc != NULL) { -@@ -1198,9 +1227,6 @@ krb5_get_credentials_for_proxy(krb5_context context, - krb5_creds **out_creds) - { - krb5_error_code code; -- krb5_creds mcreds; -- krb5_creds *ncreds = NULL; -- krb5_flags fields; - krb5_data *evidence_tkt_data = NULL; - krb5_creds s4u_creds; - -@@ -1222,30 +1248,6 @@ krb5_get_credentials_for_proxy(krb5_context context, - goto cleanup; - } - -- code = krb5int_construct_matching_creds(context, options, in_creds, -- &mcreds, &fields); -- if (code != 0) -- goto cleanup; -- -- ncreds = calloc(1, sizeof(*ncreds)); -- if (ncreds == NULL) { -- code = ENOMEM; -- goto cleanup; -- } -- ncreds->magic = KV5M_CRED; -- -- code = krb5_cc_retrieve_cred(context, ccache, fields, &mcreds, ncreds); -- if (code != 0) { -- free(ncreds); -- ncreds = in_creds; -- } else { -- *out_creds = ncreds; -- } -- -- if ((code != KRB5_CC_NOTFOUND && code != KRB5_CC_NOT_KTYPE) -- || options & KRB5_GC_CACHED) -- goto cleanup; -- - code = encode_krb5_ticket(evidence_tkt, &evidence_tkt_data); - if (code != 0) - goto cleanup; -diff --git a/src/tests/s4u2proxy.c b/src/tests/s4u2proxy.c -index 4adf6aca5..3786bad2c 100644 ---- a/src/tests/s4u2proxy.c -+++ b/src/tests/s4u2proxy.c -@@ -124,6 +124,9 @@ main(int argc, char **argv) - KRB5_GC_CANONICALIZE, defcc, - &mcred, ev_ticket, &new_cred)); - -+ assert(data_eq(new_cred->second_ticket, ev_cred.ticket)); -+ assert(new_cred->second_ticket.length != 0); -+ - /* Store the new cred in the default ccache. */ - check(krb5_cc_store_cred(context, defcc, new_cred)); - diff --git a/Don-t-create-hostbased-principals-in-new-KDBs.patch b/Don-t-create-hostbased-principals-in-new-KDBs.patch deleted file mode 100644 index 867eb4a..0000000 --- a/Don-t-create-hostbased-principals-in-new-KDBs.patch +++ /dev/null @@ -1,195 +0,0 @@ -From 71070a0f0fa6424cfb37aef7c4ec43e99380a6aa Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 30 Jul 2020 12:14:27 -0400 -Subject: [PATCH] Don't create hostbased principals in new KDBs - -Unix-like platforms do not provide a simple method to find the -fully-qualified local hostname as the machine is expected to appear to -other hosts. Canonicalizing the gethostname() result with -getaddrinfo() usually works, but potentially uses DNS. Now that -dns_canonicalize_hostname=true is no longer the default, KDB creation -would generally create the wrong host-based principals. - -kadmin/hostname is unnecessary because the client software can also -use kadmin/admin, and kiprop/hostname is one of several principals -that must be created for incremental propagation. - -ticket: 8935 (new) -(cherry picked from commit ac2b693d0ec464e0bcda4953acd79f201169f396) ---- - src/kadmin/dbutil/kadm5_create.c | 52 ++----------------- - .../kdb/ldap/ldap_util/kdb5_ldap_realm.c | 35 +------------ - src/tests/dejagnu/krb-standalone/kadmin.exp | 7 +-- - src/tests/t_iprop.py | 1 + - src/tests/t_kadmin_acl.py | 1 + - 5 files changed, 12 insertions(+), 84 deletions(-) - -diff --git a/src/kadmin/dbutil/kadm5_create.c b/src/kadmin/dbutil/kadm5_create.c -index 4f254a387..42b45aa2d 100644 ---- a/src/kadmin/dbutil/kadm5_create.c -+++ b/src/kadmin/dbutil/kadm5_create.c -@@ -139,60 +139,18 @@ int kadm5_create_magic_princs(kadm5_config_params *params, - static int add_admin_princs(void *handle, krb5_context context, char *realm) - { - krb5_error_code ret = 0; -- char *service_name = 0, *kiprop_name = 0, *canonhost = 0; -- char localname[MAXHOSTNAMELEN]; -- -- if (gethostname(localname, MAXHOSTNAMELEN)) { -- ret = errno; -- perror("gethostname"); -- goto clean_and_exit; -- } -- ret = krb5_expand_hostname(context, localname, &canonhost); -- if (ret) { -- com_err(progname, ret, _("while canonicalizing local hostname")); -- goto clean_and_exit; -- } -- if (asprintf(&service_name, "kadmin/%s", canonhost) < 0) { -- ret = ENOMEM; -- fprintf(stderr, _("Out of memory\n")); -- goto clean_and_exit; -- } -- if (asprintf(&kiprop_name, "kiprop/%s", canonhost) < 0) { -- ret = ENOMEM; -- fprintf(stderr, _("Out of memory\n")); -- goto clean_and_exit; -- } -- -- if ((ret = add_admin_princ(handle, context, -- service_name, realm, -- KRB5_KDB_DISALLOW_TGT_BASED | -- KRB5_KDB_LOCKDOWN_KEYS, -- ADMIN_LIFETIME))) -- goto clean_and_exit; - - if ((ret = add_admin_princ(handle, context, - KADM5_ADMIN_SERVICE, realm, - KRB5_KDB_DISALLOW_TGT_BASED | - KRB5_KDB_LOCKDOWN_KEYS, - ADMIN_LIFETIME))) -- goto clean_and_exit; -+ return ret; - -- if ((ret = add_admin_princ(handle, context, -- KADM5_CHANGEPW_SERVICE, realm, -- KRB5_KDB_DISALLOW_TGT_BASED | -- KRB5_KDB_PWCHANGE_SERVICE | -- KRB5_KDB_LOCKDOWN_KEYS, -- CHANGEPW_LIFETIME))) -- goto clean_and_exit; -- -- ret = add_admin_princ(handle, context, kiprop_name, realm, 0, 0); -- --clean_and_exit: -- krb5_free_string(context, canonhost); -- free(service_name); -- free(kiprop_name); -- -- return ret; -+ return add_admin_princ(handle, context, KADM5_CHANGEPW_SERVICE, realm, -+ KRB5_KDB_DISALLOW_TGT_BASED | -+ KRB5_KDB_PWCHANGE_SERVICE | KRB5_KDB_LOCKDOWN_KEYS, -+ CHANGEPW_LIFETIME); - } - - /* -diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c -index c21d19981..ae1afd4a9 100644 ---- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c -+++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c -@@ -307,29 +307,6 @@ create_fixed_special(krb5_context context, struct realm_info *rinfo, - - } - --/* Create a special principal using one specified component and the -- * canonicalized local hostname. */ --static krb5_error_code --create_hostbased_special(krb5_context context, struct realm_info *rinfo, -- krb5_keyblock *mkey, const char *comp1) --{ -- krb5_error_code ret; -- krb5_principal princ = NULL; -- -- ret = krb5_sname_to_principal(context, NULL, comp1, KRB5_NT_SRV_HST, -- &princ); -- if (ret) -- goto cleanup; -- ret = krb5_set_principal_realm(context, princ, global_params.realm); -- if (ret) -- goto cleanup; -- ret = kdb_ldap_create_principal(context, princ, TGT_KEY, rinfo, mkey); -- --cleanup: -- krb5_free_principal(context, princ); -- return ret; --} -- - /* Create all special principals for the realm. */ - static krb5_error_code - create_special_princs(krb5_context context, krb5_principal master_princ, -@@ -360,20 +337,10 @@ create_special_princs(krb5_context context, krb5_principal master_princ, - if (ret) - return ret; - -- /* Create kadmin/admin and kadmin/. */ -+ /* Create kadmin/admin. */ - rblock.max_life = ADMIN_LIFETIME; - rblock.flags = KRB5_KDB_DISALLOW_TGT_BASED; - ret = create_fixed_special(context, &rblock, mkey, "kadmin", "admin"); -- if (ret) -- return ret; -- ret = create_hostbased_special(context, &rblock, mkey, "kadmin"); -- if (ret) -- return ret; -- -- /* Create kiprop/. */ -- rblock.max_life = global_params.max_life; -- rblock.flags = 0; -- ret = create_hostbased_special(context, &rblock, mkey, "kiprop"); - if (ret) - return ret; - -diff --git a/src/tests/dejagnu/krb-standalone/kadmin.exp b/src/tests/dejagnu/krb-standalone/kadmin.exp -index 36a345258..fa50a61fb 100644 ---- a/src/tests/dejagnu/krb-standalone/kadmin.exp -+++ b/src/tests/dejagnu/krb-standalone/kadmin.exp -@@ -1098,10 +1098,11 @@ proc kadmin_test { } { - return - } - -- # test fallback to kadmin/admin -- if {![kadmin_delete_locked_down kadmin/$hostname] \ -+ # test fallback to kadmin/hostname -+ if {![kadmin_add_rnd kadmin/$hostname] \ -+ || ![kadmin_delete_locked_down kadmin/admin] \ - || ![kadmin_list] \ -- || ![kadmin_add_rnd kadmin/$hostname -allow_tgs_req] \ -+ || ![kadmin_add_rnd kadmin/admin -allow_tgs_req] \ - || ![kadmin_list]} { - return - } -diff --git a/src/tests/t_iprop.py b/src/tests/t_iprop.py -index 371f3a22b..3bb0fd2e9 100755 ---- a/src/tests/t_iprop.py -+++ b/src/tests/t_iprop.py -@@ -188,6 +188,7 @@ for realm in multidb_realms(kdc_conf=conf, create_user=False, - - # Create the principal used to authenticate kpropd to kadmind. - kiprop_princ = 'kiprop/' + hostname -+ realm.addprinc(kiprop_princ) - realm.extract_keytab(kiprop_princ, realm.keytab) - - # Create the initial replica databases. -diff --git a/src/tests/t_kadmin_acl.py b/src/tests/t_kadmin_acl.py -index 16faf0a9d..31a7fb871 100755 ---- a/src/tests/t_kadmin_acl.py -+++ b/src/tests/t_kadmin_acl.py -@@ -331,6 +331,7 @@ realm.run([kadmin, '-c', realm.ccache, 'cpw', '-randkey', '-e', 'aes256-cts', - # Test authentication to kadmin/hostname. - mark('authentication to kadmin/hostname') - kadmin_hostname = 'kadmin/' + hostname -+realm.addprinc(kadmin_hostname) - realm.run([kadminl, 'delprinc', 'kadmin/admin']) - msgs = ('Getting initial credentials for user/admin@KRBTEST.COM', - 'Setting initial creds service to kadmin/admin', diff --git a/Expand-dns_canonicalize_host-fallback-support.patch b/Expand-dns_canonicalize_host-fallback-support.patch deleted file mode 100644 index eb82a81..0000000 --- a/Expand-dns_canonicalize_host-fallback-support.patch +++ /dev/null @@ -1,1190 +0,0 @@ -From c0e732f79dc5ea0c2066120bfe7ae8f6df82bf82 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 17 Jul 2020 22:57:45 -0400 -Subject: [PATCH] Expand dns_canonicalize_host=fallback support - -In krb5_sname_to_principal(), when using fallback, defer realm lookup -and any kind of hostname canonicalization until use. Add a -lightweight iterator k5_canonprinc() to yield the one or two possible -candidates for a principal. In the iterator, don't yield the same -hostname part twice. - -Add fallback processing to the stepwise TGS state machine, and remove -it from krb5_get_credentials(). Add fallback processing to -k5_get_proxy_cred_from_kdc(). - -Add fallback processing to krb5_init_creds_set_keytab(), and use the -principal we find in the keytab as the request client principal. -Defer restart_init_creds_loop() to the first step call so that server -principal is built using the correct realm. - -Add fallback processing to krb5_rd_req(). - -ticket: 8930 (new) -(cherry picked from commit 3fcc365a6f049730b3f47168f7112c03997c5c0b) ---- - src/include/k5-trace.h | 4 +- - src/kprop/kprop_util.c | 26 ++-- - src/lib/krb5/krb/deps | 41 +++--- - src/lib/krb5/krb/get_creds.c | 151 ++++++++++----------- - src/lib/krb5/krb/get_in_tkt.c | 7 +- - src/lib/krb5/krb/gic_keytab.c | 29 +++- - src/lib/krb5/krb/init_creds_ctx.h | 1 + - src/lib/krb5/krb/rd_req_dec.c | 36 ++++- - src/lib/krb5/krb/s4u_creds.c | 62 ++++++--- - src/lib/krb5/os/os-proto.h | 30 +++++ - src/lib/krb5/os/sn2princ.c | 215 +++++++++++++++++++++--------- - src/tests/icred.c | 39 ++++-- - src/tests/t_sn2princ.py | 65 ++++++--- - 13 files changed, 465 insertions(+), 241 deletions(-) - -diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h -index 1da53dbb1..5a120f1a0 100644 ---- a/src/include/k5-trace.h -+++ b/src/include/k5-trace.h -@@ -229,8 +229,8 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); - salt, s2kparams) - #define TRACE_INIT_CREDS_IDENTIFIED_REALM(c, realm) \ - TRACE(c, "Identified realm of client principal as {data}", realm) --#define TRACE_INIT_CREDS_KEYTAB_LOOKUP(c, etypes) \ -- TRACE(c, "Looked up etypes in keytab: {etypes}", etypes) -+#define TRACE_INIT_CREDS_KEYTAB_LOOKUP(c, princ, etypes) \ -+ TRACE(c, "Found entries for {princ} in keytab: {etypes}", princ, etypes) - #define TRACE_INIT_CREDS_KEYTAB_LOOKUP_FAILED(c, code) \ - TRACE(c, "Couldn't lookup etypes in keytab: {kerr}", code) - #define TRACE_INIT_CREDS_PREAUTH(c) \ -diff --git a/src/kprop/kprop_util.c b/src/kprop/kprop_util.c -index c32d174b9..c2b2e8764 100644 ---- a/src/kprop/kprop_util.c -+++ b/src/kprop/kprop_util.c -@@ -73,26 +73,22 @@ sn2princ_realm(krb5_context context, const char *hostname, const char *sname, - const char *realm, krb5_principal *princ_out) - { - krb5_error_code ret; -- char *canonhost, localname[MAXHOSTNAMELEN]; -+ krb5_principal princ; - - *princ_out = NULL; - assert(sname != NULL && realm != NULL); - -- /* If hostname is NULL, use the local hostname. */ -- if (hostname == NULL) { -- if (gethostname(localname, MAXHOSTNAMELEN) != 0) -- return SOCKET_ERRNO; -- hostname = localname; -- } -- -- ret = krb5_expand_hostname(context, hostname, &canonhost); -+ ret = krb5_sname_to_principal(context, hostname, sname, KRB5_NT_SRV_HST, -+ &princ); - if (ret) - return ret; - -- ret = krb5_build_principal(context, princ_out, strlen(realm), realm, sname, -- canonhost, (char *)NULL); -- krb5_free_string(context, canonhost); -- if (!ret) -- (*princ_out)->type = KRB5_NT_SRV_HST; -- return ret; -+ ret = krb5_set_principal_realm(context, princ, realm); -+ if (ret) { -+ krb5_free_principal(context, princ); -+ return ret; -+ } -+ -+ *princ_out = princ; -+ return 0; - } -diff --git a/src/lib/krb5/krb/deps b/src/lib/krb5/krb/deps -index 439ca0272..6ac68bc19 100644 ---- a/src/lib/krb5/krb/deps -+++ b/src/lib/krb5/krb/deps -@@ -499,12 +499,13 @@ get_in_tkt.so get_in_tkt.po $(OUTPRE)get_in_tkt.$(OBJEXT): \ - gic_keytab.so gic_keytab.po $(OUTPRE)gic_keytab.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-json.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -+ $(COM_ERR_DEPS) $(srcdir)/../os/os-proto.h $(top_srcdir)/include/k5-buf.h \ -+ $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -+ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -+ $(top_srcdir)/include/k5-json.h $(top_srcdir)/include/k5-platform.h \ -+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -+ $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/locate_plugin.h \ - $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ - $(top_srcdir)/include/socket-utils.h gic_keytab.c init_creds_ctx.h \ - int-proto.h -@@ -940,13 +941,14 @@ rd_req.so rd_req.po $(OUTPRE)rd_req.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - rd_req_dec.so rd_req_dec.po $(OUTPRE)rd_req_dec.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(srcdir)/../rcache/memrcache.h $(top_srcdir)/include/k5-buf.h \ -- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/k5-utf8.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -+ $(COM_ERR_DEPS) $(srcdir)/../os/os-proto.h $(srcdir)/../rcache/memrcache.h \ -+ $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -+ $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -+ $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -+ $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -+ $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/k5-utf8.h \ -+ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -+ $(top_srcdir)/include/krb5/locate_plugin.h $(top_srcdir)/include/krb5/plugin.h \ - $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ - auth_con.h authdata.h int-proto.h rd_req_dec.c - rd_safe.so rd_safe.po $(OUTPRE)rd_safe.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -@@ -997,12 +999,13 @@ s4u_authdata.so s4u_authdata.po $(OUTPRE)s4u_authdata.$(OBJEXT): \ - s4u_creds.so s4u_creds.po $(OUTPRE)s4u_creds.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -+ $(COM_ERR_DEPS) $(srcdir)/../os/os-proto.h $(top_srcdir)/include/k5-buf.h \ -+ $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -+ $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -+ $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -+ $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -+ $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -+ $(top_srcdir)/include/krb5/locate_plugin.h $(top_srcdir)/include/krb5/plugin.h \ - $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ - int-proto.h s4u_creds.c - sendauth.so sendauth.po $(OUTPRE)sendauth.$(OBJEXT): \ -diff --git a/src/lib/krb5/krb/get_creds.c b/src/lib/krb5/krb/get_creds.c -index e0a3b5cd8..dc0aef667 100644 ---- a/src/lib/krb5/krb/get_creds.c -+++ b/src/lib/krb5/krb/get_creds.c -@@ -119,7 +119,7 @@ krb5int_construct_matching_creds(krb5_context context, krb5_flags options, - * generate the next request. If it's time to advance to another state, any of - * the three functions can make a tail call to begin_ to do so. - * -- * The overall process is as follows: -+ * The general process is as follows: - * 1. Get a TGT for the service principal's realm (STATE_GET_TGT). - * 2. Make one or more referrals queries (STATE_REFERRALS). - * 3. In some cases, get a TGT for the fallback realm (STATE_GET_TGT again). -@@ -129,6 +129,9 @@ krb5int_construct_matching_creds(krb5_context context, krb5_flags options, - * getting_tgt_for field in the context keeps track of what state we will go to - * after successfully obtaining the TGT, and the end_get_tgt() function - * advances to the proper next state. -+ * -+ * If fallback DNS canonicalization is in use, the process can be repeated a -+ * second time for the second server principal canonicalization candidate. - */ - - enum state { -@@ -153,6 +156,8 @@ struct _krb5_tkt_creds_context { - krb5_flags req_options; /* Caller-requested KRB5_GC_* options */ - krb5_flags req_kdcopt; /* Caller-requested options as KDC options */ - krb5_authdata **authdata; /* Caller-requested authdata */ -+ struct canonprinc iter; /* Iterator over canonicalized server princs */ -+ krb5_boolean referral_req; /* Server initially contained referral realm */ - - /* The following fields are used in multiple steps. */ - krb5_creds *cur_tgt; /* TGT to be used for next query */ -@@ -484,7 +489,7 @@ try_fallback(krb5_context context, krb5_tkt_creds_context ctx) - - /* If the request used a specified realm, make a non-referral request to - * that realm (in case it's a KDC which rejects KDC_OPT_CANONICALIZE). */ -- if (!krb5_is_referral_realm(&ctx->req_server->realm)) -+ if (!ctx->referral_req) - return begin_non_referral(context, ctx); - - if (ctx->server->length < 2) { -@@ -1015,10 +1020,13 @@ check_cache(krb5_context context, krb5_tkt_creds_context ctx) - krb5_error_code code; - krb5_creds mcreds; - krb5_flags fields; -+ krb5_creds req_in_creds; - -- /* Perform the cache lookup. */ -+ /* Check the cache for the originally requested server principal. */ -+ req_in_creds = *ctx->in_creds; -+ req_in_creds.server = ctx->req_server; - code = krb5int_construct_matching_creds(context, ctx->req_options, -- ctx->in_creds, &mcreds, &fields); -+ &req_in_creds, &mcreds, &fields); - if (code) - return code; - code = cache_get(context, ctx->ccache, fields, &mcreds, &ctx->reply_creds); -@@ -1044,12 +1052,9 @@ begin(krb5_context context, krb5_tkt_creds_context ctx) - { - krb5_error_code code; - -- code = check_cache(context, ctx); -- if (code != 0 || ctx->state == STATE_COMPLETE) -- return code; -- - /* If the server realm is unspecified, start with the client realm. */ -- if (krb5_is_referral_realm(&ctx->server->realm)) { -+ ctx->referral_req = krb5_is_referral_realm(&ctx->server->realm); -+ if (ctx->referral_req) { - krb5_free_data_contents(context, &ctx->server->realm); - code = krb5int_copy_data_contents(context, &ctx->client->realm, - &ctx->server->realm); -@@ -1072,6 +1077,7 @@ krb5_tkt_creds_init(krb5_context context, krb5_ccache ccache, - { - krb5_error_code code; - krb5_tkt_creds_context ctx = NULL; -+ krb5_const_principal canonprinc; - - TRACE_TKT_CREDS(context, in_creds, ccache); - ctx = k5alloc(sizeof(*ctx), &code); -@@ -1089,14 +1095,28 @@ krb5_tkt_creds_init(krb5_context context, krb5_ccache ccache, - - ctx->state = STATE_BEGIN; - -+ /* Copy the matching cred so we can modify it. Steal the copy of the -+ * service principal name to remember the original request server. */ - code = krb5_copy_creds(context, in_creds, &ctx->in_creds); - if (code != 0) - goto cleanup; -- ctx->client = ctx->in_creds->client; -- ctx->server = ctx->in_creds->server; -- code = krb5_copy_principal(context, ctx->server, &ctx->req_server); -+ ctx->req_server = ctx->in_creds->server; -+ ctx->in_creds->server = NULL; -+ -+ /* Get the first canonicalization candidate for the requested server. */ -+ ctx->iter.princ = ctx->req_server; -+ -+ code = k5_canonprinc(context, &ctx->iter, &canonprinc); -+ if (code == 0 && canonprinc == NULL) -+ code = KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN; - if (code != 0) - goto cleanup; -+ code = krb5_copy_principal(context, canonprinc, &ctx->in_creds->server); -+ if (code != 0) -+ goto cleanup; -+ -+ ctx->client = ctx->in_creds->client; -+ ctx->server = ctx->in_creds->server; - code = krb5_cc_dup(context, ccache, &ctx->ccache); - if (code != 0) - goto cleanup; -@@ -1138,6 +1158,7 @@ krb5_tkt_creds_free(krb5_context context, krb5_tkt_creds_context ctx) - return; - krb5int_fast_free_state(context, ctx->fast_state); - krb5_free_creds(context, ctx->in_creds); -+ free_canonprinc(&ctx->iter); - krb5_cc_close(context, ctx->ccache); - krb5_free_principal(context, ctx->req_server); - krb5_free_authdata(context, ctx->authdata); -@@ -1195,6 +1216,7 @@ krb5_tkt_creds_step(krb5_context context, krb5_tkt_creds_context ctx, - { - krb5_error_code code; - krb5_boolean no_input = (in == NULL || in->length == 0); -+ krb5_const_principal canonprinc; - - *out = empty_data(); - *realm = empty_data(); -@@ -1206,6 +1228,12 @@ krb5_tkt_creds_step(krb5_context context, krb5_tkt_creds_context ctx, - ctx->state == STATE_COMPLETE) - return EINVAL; - -+ if (ctx->state == STATE_BEGIN) { -+ code = check_cache(context, ctx); -+ if (code != 0 || ctx->state == STATE_COMPLETE) -+ return code; -+ } -+ - ctx->caller_out = out; - ctx->caller_realm = realm; - ctx->caller_flags = flags; -@@ -1218,37 +1246,32 @@ krb5_tkt_creds_step(krb5_context context, krb5_tkt_creds_context ctx, - } - - if (ctx->state == STATE_BEGIN) -- return begin(context, ctx); -+ code = begin(context, ctx); - else if (ctx->state == STATE_GET_TGT) -- return step_get_tgt(context, ctx); -+ code = step_get_tgt(context, ctx); - else if (ctx->state == STATE_GET_TGT_OFFPATH) -- return step_get_tgt_offpath(context, ctx); -+ code = step_get_tgt_offpath(context, ctx); - else if (ctx->state == STATE_REFERRALS) -- return step_referrals(context, ctx); -+ code = step_referrals(context, ctx); - else if (ctx->state == STATE_NON_REFERRAL) -- return step_non_referral(context, ctx); -+ code = step_non_referral(context, ctx); - else -- return EINVAL; --} -+ code = EINVAL; - --static krb5_error_code --try_get_creds(krb5_context context, krb5_flags options, krb5_ccache ccache, -- krb5_creds *in_creds, krb5_creds *creds_out) --{ -- krb5_error_code code; -- krb5_tkt_creds_context ctx = NULL; -+ /* Terminate on success or most errors. */ -+ if (code != KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN) -+ return code; - -- code = krb5_tkt_creds_init(context, ccache, in_creds, options, &ctx); -+ /* Restart with the next server principal canonicalization candidate. */ -+ code = k5_canonprinc(context, &ctx->iter, &canonprinc); - if (code) -- goto cleanup; -- code = krb5_tkt_creds_get(context, ctx); -- if (code) -- goto cleanup; -- code = krb5_tkt_creds_get_creds(context, ctx, creds_out); -- --cleanup: -- krb5_tkt_creds_free(context, ctx); -- return code; -+ return code; -+ if (canonprinc == NULL) -+ return KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN; -+ krb5_free_principal(context, ctx->in_creds->server); -+ code = krb5_copy_principal(context, canonprinc, &ctx->in_creds->server); -+ ctx->server = ctx->in_creds->server; -+ return begin(context, ctx); - } - - krb5_error_code KRB5_CALLCONV -@@ -1258,10 +1281,7 @@ krb5_get_credentials(krb5_context context, krb5_flags options, - { - krb5_error_code code; - krb5_creds *ncreds = NULL; -- krb5_creds canon_creds, store_creds; -- krb5_principal_data canon_server; -- krb5_data canon_components[2]; -- char *hostname = NULL, *canon_hostname = NULL; -+ krb5_tkt_creds_context ctx = NULL; - - *out_creds = NULL; - -@@ -1277,59 +1297,22 @@ krb5_get_credentials(krb5_context context, krb5_flags options, - if (ncreds == NULL) - goto cleanup; - -- code = try_get_creds(context, options, ccache, in_creds, ncreds); -- if (!code) { -- *out_creds = ncreds; -- return 0; -- } -- -- /* Possibly try again with the canonicalized hostname, if the server is -- * host-based and we are configured for fallback canonicalization. */ -- if (code != KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN) -+ /* Make and execute a krb5_tkt_creds context to get the credential. */ -+ code = krb5_tkt_creds_init(context, ccache, in_creds, options, &ctx); -+ if (code != 0) - goto cleanup; -- if (context->dns_canonicalize_hostname != CANONHOST_FALLBACK) -+ code = krb5_tkt_creds_get(context, ctx); -+ if (code != 0) - goto cleanup; -- if (in_creds->server->type != KRB5_NT_SRV_HST || -- in_creds->server->length != 2) -+ code = krb5_tkt_creds_get_creds(context, ctx, ncreds); -+ if (code != 0) - goto cleanup; - -- hostname = k5memdup0(in_creds->server->data[1].data, -- in_creds->server->data[1].length, &code); -- if (hostname == NULL) -- goto cleanup; -- code = k5_expand_hostname(context, hostname, TRUE, &canon_hostname); -- if (code) -- goto cleanup; -- -- TRACE_GET_CREDS_FALLBACK(context, canon_hostname); -- -- /* Make shallow copies of in_creds and its server to alter the hostname. */ -- canon_components[0] = in_creds->server->data[0]; -- canon_components[1] = string2data(canon_hostname); -- canon_server = *in_creds->server; -- canon_server.data = canon_components; -- canon_creds = *in_creds; -- canon_creds.server = &canon_server; -- -- code = try_get_creds(context, options | KRB5_GC_NO_STORE, ccache, -- &canon_creds, ncreds); -- if (code) -- goto cleanup; -- -- if (!(options & KRB5_GC_NO_STORE)) { -- /* Store the creds under the originally requested server name. The -- * ccache layer will also store them under the ticket server name. */ -- store_creds = *ncreds; -- store_creds.server = in_creds->server; -- (void)krb5_cc_store_cred(context, ccache, &store_creds); -- } -- - *out_creds = ncreds; - ncreds = NULL; - - cleanup: -- free(hostname); -- free(canon_hostname); - krb5_free_creds(context, ncreds); -+ krb5_tkt_creds_free(context, ctx); - return code; - } -diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c -index cc0f70e83..09c4b8495 100644 ---- a/src/lib/krb5/krb/get_in_tkt.c -+++ b/src/lib/krb5/krb/get_in_tkt.c -@@ -1051,9 +1051,6 @@ krb5_init_creds_init(krb5_context context, - ctx->request->kdc_options |= KDC_OPT_REQUEST_ANONYMOUS; - ctx->request->client->type = KRB5_NT_WELLKNOWN; - } -- code = restart_init_creds_loop(context, ctx, FALSE); -- if (code) -- goto cleanup; - - *pctx = ctx; - ctx = NULL; -@@ -1859,6 +1856,10 @@ krb5_init_creds_step(krb5_context context, - } - if (code != 0 || ctx->complete) - goto cleanup; -+ } else { -+ code = restart_init_creds_loop(context, ctx, FALSE); -+ if (code) -+ goto cleanup; - } - - code = init_creds_step_request(context, ctx, out); -diff --git a/src/lib/krb5/krb/gic_keytab.c b/src/lib/krb5/krb/gic_keytab.c -index 1d70cf46f..b2b4ac904 100644 ---- a/src/lib/krb5/krb/gic_keytab.c -+++ b/src/lib/krb5/krb/gic_keytab.c -@@ -27,6 +27,7 @@ - - #include "k5-int.h" - #include "int-proto.h" -+#include "os-proto.h" - #include "init_creds_ctx.h" - - static krb5_error_code -@@ -85,7 +86,8 @@ get_as_key_keytab(krb5_context context, - /* Return the list of etypes available for client in keytab. */ - static krb5_error_code - lookup_etypes_for_keytab(krb5_context context, krb5_keytab keytab, -- krb5_principal client, krb5_enctype **etypes_out) -+ krb5_const_principal client, -+ krb5_enctype **etypes_out) - { - krb5_kt_cursor cursor; - krb5_keytab_entry entry; -@@ -182,18 +184,37 @@ krb5_init_creds_set_keytab(krb5_context context, - { - krb5_enctype *etype_list; - krb5_error_code ret; -+ struct canonprinc iter = { ctx->request->client, .subst_defrealm = TRUE }; -+ krb5_const_principal canonprinc; -+ krb5_principal copy; - char *name; - - ctx->gak_fct = get_as_key_keytab; - ctx->gak_data = keytab; - -- ret = lookup_etypes_for_keytab(context, keytab, ctx->request->client, -- &etype_list); -+ /* We may be authenticating as a host-based principal. If so, look for -+ * each canonicalization candidate in the keytab. */ -+ while ((ret = k5_canonprinc(context, &iter, &canonprinc)) == 0 && -+ canonprinc != NULL) { -+ ret = lookup_etypes_for_keytab(context, keytab, canonprinc, -+ &etype_list); -+ if (ret || etype_list != NULL) -+ break; -+ } -+ if (!ret && canonprinc != NULL) { -+ /* Authenticate as the principal we found in the keytab. */ -+ ret = krb5_copy_principal(context, canonprinc, ©); -+ if (!ret) { -+ krb5_free_principal(context, ctx->request->client); -+ ctx->request->client = copy; -+ } -+ } -+ free_canonprinc(&iter); - if (ret) { - TRACE_INIT_CREDS_KEYTAB_LOOKUP_FAILED(context, ret); - return 0; - } -- TRACE_INIT_CREDS_KEYTAB_LOOKUP(context, etype_list); -+ TRACE_INIT_CREDS_KEYTAB_LOOKUP(context, ctx->request->client, etype_list); - - /* Error out if we have no keys for the client principal. */ - if (etype_list == NULL) { -diff --git a/src/lib/krb5/krb/init_creds_ctx.h b/src/lib/krb5/krb/init_creds_ctx.h -index 5bd67a1d8..17d55dd7c 100644 ---- a/src/lib/krb5/krb/init_creds_ctx.h -+++ b/src/lib/krb5/krb/init_creds_ctx.h -@@ -22,6 +22,7 @@ struct _krb5_init_creds_context { - krb5_get_init_creds_opt opt_storage; - krb5_boolean identify_realm; - const krb5_data *subject_cert; -+ krb5_principal keytab_princ; - char *in_tkt_service; - krb5_prompter_fct prompter; - void *prompter_data; -diff --git a/src/lib/krb5/krb/rd_req_dec.c b/src/lib/krb5/krb/rd_req_dec.c -index bc7fac455..013ca905c 100644 ---- a/src/lib/krb5/krb/rd_req_dec.c -+++ b/src/lib/krb5/krb/rd_req_dec.c -@@ -33,6 +33,7 @@ - #include "auth_con.h" - #include "authdata.h" - #include "int-proto.h" -+#include "os-proto.h" - - /* - * essentially the same as krb_rd_req, but uses a decoded AP_REQ as -@@ -351,9 +352,9 @@ try_one_princ(krb5_context context, const krb5_ap_req *req, - * Store the decrypting key in *keyblock_out if it is not NULL. - */ - static krb5_error_code --decrypt_ticket(krb5_context context, const krb5_ap_req *req, -- krb5_const_principal server, krb5_keytab keytab, -- krb5_keyblock *keyblock_out) -+decrypt_try_server(krb5_context context, const krb5_ap_req *req, -+ krb5_const_principal server, krb5_keytab keytab, -+ krb5_keyblock *keyblock_out) - { - krb5_error_code ret; - krb5_keytab_entry ent; -@@ -441,6 +442,35 @@ decrypt_ticket(krb5_context context, const krb5_ap_req *req, - #endif /* LEAN_CLIENT */ - } - -+static krb5_error_code -+decrypt_ticket(krb5_context context, const krb5_ap_req *req, -+ krb5_const_principal server, krb5_keytab keytab, -+ krb5_keyblock *keyblock_out) -+{ -+ krb5_error_code ret, dret = 0; -+ struct canonprinc iter = { server, .no_hostrealm = TRUE }; -+ krb5_const_principal canonprinc; -+ -+ /* Don't try to canonicalize if we're going to ignore the hostname, or if -+ * server is null or has a wildcard hostname. */ -+ if (context->ignore_acceptor_hostname || server == NULL || -+ (server->length == 2 && server->data[1].length == 0)) -+ return decrypt_try_server(context, req, server, keytab, keyblock_out); -+ -+ /* Try each canonicalization candidate for server. If they all fail, -+ * return the error from the last attempt. */ -+ while ((ret = k5_canonprinc(context, &iter, &canonprinc)) == 0 && -+ canonprinc != NULL) { -+ dret = decrypt_try_server(context, req, canonprinc, keytab, -+ keyblock_out); -+ /* Only continue if we found no keytab entries matching canonprinc. */ -+ if (dret != KRB5KRB_AP_ERR_NOKEY) -+ break; -+ } -+ free_canonprinc(&iter); -+ return (ret != 0) ? ret : dret; -+} -+ - static krb5_error_code - rd_req_decoded_opt(krb5_context context, krb5_auth_context *auth_context, - const krb5_ap_req *req, krb5_const_principal server, -diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c -index d8f486dc6..07c7a98be 100644 ---- a/src/lib/krb5/krb/s4u_creds.c -+++ b/src/lib/krb5/krb/s4u_creds.c -@@ -26,6 +26,7 @@ - - #include "k5-int.h" - #include "int-proto.h" -+#include "os-proto.h" - - /* Convert ticket flags to necessary KDC options */ - #define FLAGS2OPTS(flags) (flags & KDC_TKT_COMMON_MASK) -@@ -984,10 +985,10 @@ get_target_realm_proxy_tgt(krb5_context context, const krb5_data *realm, - return 0; - } - --krb5_error_code --k5_get_proxy_cred_from_kdc(krb5_context context, krb5_flags options, -- krb5_ccache ccache, krb5_creds *in_creds, -- krb5_creds **out_creds) -+static krb5_error_code -+get_proxy_cred_from_kdc(krb5_context context, krb5_flags options, -+ krb5_ccache ccache, krb5_creds *in_creds, -+ krb5_creds **out_creds) - { - krb5_error_code code; - krb5_flags flags, req_kdcopt = 0; -@@ -1123,22 +1124,11 @@ k5_get_proxy_cred_from_kdc(krb5_context context, krb5_flags options, - } - } - -- if (!krb5_principal_compare(context, in_creds->server, tkt->server)) { -- krb5_free_principal(context, tkt->server); -- tkt->server = NULL; -- code = krb5_copy_principal(context, in_creds->server, &tkt->server); -- if (code) -- goto cleanup; -- } -- - /* Note the authdata we asked for in the output creds. */ - code = krb5_copy_authdata(context, in_creds->authdata, &tkt->authdata); - if (code) - goto cleanup; - -- if (!(options & KRB5_GC_NO_STORE)) -- (void)krb5_cc_store_cred(context, ccache, tkt); -- - *out_creds = tkt; - tkt = NULL; - -@@ -1151,6 +1141,48 @@ cleanup: - return code; - } - -+krb5_error_code -+k5_get_proxy_cred_from_kdc(krb5_context context, krb5_flags options, -+ krb5_ccache ccache, krb5_creds *in_creds, -+ krb5_creds **out_creds) -+{ -+ krb5_error_code code; -+ krb5_const_principal canonprinc; -+ krb5_creds copy, *creds; -+ struct canonprinc iter = { in_creds->server, .no_hostrealm = TRUE }; -+ -+ *out_creds = NULL; -+ -+ copy = *in_creds; -+ while ((code = k5_canonprinc(context, &iter, &canonprinc)) == 0 && -+ canonprinc != NULL) { -+ copy.server = (krb5_principal)canonprinc; -+ code = get_proxy_cred_from_kdc(context, options, ccache, ©, -+ &creds); -+ if (code != KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN) -+ break; -+ } -+ if (!code && canonprinc == NULL) -+ code = KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN; -+ free_canonprinc(&iter); -+ if (code) -+ return code; -+ -+ krb5_free_principal(context, creds->server); -+ creds->server = NULL; -+ code = krb5_copy_principal(context, in_creds->server, &creds->server); -+ if (code) { -+ krb5_free_creds(context, creds); -+ return code; -+ } -+ -+ if (!(options & KRB5_GC_NO_STORE)) -+ (void)krb5_cc_store_cred(context, ccache, creds); -+ -+ *out_creds = creds; -+ return 0; -+} -+ - /* - * Exported API for constrained delegation (S4U2Proxy). - * -diff --git a/src/lib/krb5/os/os-proto.h b/src/lib/krb5/os/os-proto.h -index a16a34b74..f1aa60a3e 100644 ---- a/src/lib/krb5/os/os-proto.h -+++ b/src/lib/krb5/os/os-proto.h -@@ -83,6 +83,36 @@ struct sendto_callback_info { - void *data; - }; - -+/* -+ * Initialize with all zeros except for princ. Set no_hostrealm to disable -+ * host-to-realm lookup, which ordinarily happens after canonicalizing the host -+ * part. Set subst_defrealm to substitute the default realm for the referral -+ * realm after realm lookup (this has no effect if no_hostrealm is set). Free -+ * with free_canonprinc() when done. -+ */ -+struct canonprinc { -+ krb5_const_principal princ; -+ krb5_boolean no_hostrealm; -+ krb5_boolean subst_defrealm; -+ int step; -+ char *canonhost; -+ char *realm; -+ krb5_principal_data copy; -+ krb5_data components[2]; -+}; -+ -+/* Yield one or two candidate canonical principal names for iter, then NULL. -+ * Output names are valid for one iteration and must not be freed. */ -+krb5_error_code k5_canonprinc(krb5_context context, struct canonprinc *iter, -+ krb5_const_principal *princ_out); -+ -+static inline void -+free_canonprinc(struct canonprinc *iter) -+{ -+ free(iter->canonhost); -+ free(iter->realm); -+} -+ - krb5_error_code k5_expand_hostname(krb5_context context, const char *host, - krb5_boolean is_fallback, - char **canonhost_out); -diff --git a/src/lib/krb5/os/sn2princ.c b/src/lib/krb5/os/sn2princ.c -index a51761d0c..8b7214189 100644 ---- a/src/lib/krb5/os/sn2princ.c -+++ b/src/lib/krb5/os/sn2princ.c -@@ -85,22 +85,18 @@ qualify_shortname(krb5_context context, const char *host) - return fqdn; - } - --krb5_error_code --k5_expand_hostname(krb5_context context, const char *host, -- krb5_boolean is_fallback, char **canonhost_out) -+static krb5_error_code -+expand_hostname(krb5_context context, const char *host, krb5_boolean use_dns, -+ char **canonhost_out) - { - struct addrinfo *ai = NULL, hint; - char namebuf[NI_MAXHOST], *qualified = NULL, *copy, *p; - int err; - const char *canonhost; -- krb5_boolean use_dns; - - *canonhost_out = NULL; - - canonhost = host; -- use_dns = (context->dns_canonicalize_hostname == CANONHOST_TRUE || -- (is_fallback && -- context->dns_canonicalize_hostname == CANONHOST_FALLBACK)); - if (use_dns) { - /* Try a forward lookup of the hostname. */ - memset(&hint, 0, sizeof(hint)); -@@ -161,21 +157,135 @@ krb5_error_code KRB5_CALLCONV - krb5_expand_hostname(krb5_context context, const char *host, - char **canonhost_out) - { -- return k5_expand_hostname(context, host, FALSE, canonhost_out); -+ int use_dns = (context->dns_canonicalize_hostname == CANONHOST_TRUE); -+ -+ return expand_hostname(context, host, use_dns, canonhost_out); - } - --/* If hostname appears to have a :port or :instance trailer (used in MSSQLSvc -- * principals), return a pointer to the separator. Otherwise return NULL. */ --static const char * --find_trailer(const char *hostname) -+/* Split data into hostname and trailer (:port or :instance). Trailers are -+ * used in MSSQLSvc principals. */ -+static void -+split_trailer(const krb5_data *data, krb5_data *host, krb5_data *trailer) - { -- const char *p = strchr(hostname, ':'); -+ char *p = memchr(data->data, ':', data->length); -+ unsigned int tlen = (p == NULL) ? 0 : data->length - (p - data->data); - -- /* Look for a single colon followed by one or more characters. An IPv6 -- * address will have more than one colon, so don't accept that. */ -- if (p == NULL || p[1] == '\0' || strchr(p + 1, ':') != NULL) -- return NULL; -- return p; -+ /* Make sure we have a single colon followed by one or more characters. An -+ * IPv6 address will have more than one colon, so don't accept that. */ -+ if (p == NULL || tlen == 1 || memchr(p + 1, ':', tlen - 1) != NULL) { -+ *host = *data; -+ *trailer = empty_data(); -+ } else { -+ *host = make_data(data->data, p - data->data); -+ *trailer = make_data(p, tlen); -+ } -+} -+ -+static krb5_error_code -+canonicalize_princ(krb5_context context, struct canonprinc *iter, -+ krb5_boolean use_dns, krb5_const_principal *princ_out) -+{ -+ krb5_error_code ret; -+ krb5_data host, trailer; -+ char *hostname = NULL, *canonhost = NULL, *combined = NULL; -+ char **hrealms = NULL; -+ -+ *princ_out = NULL; -+ -+ assert(iter->princ->length == 2); -+ split_trailer(&iter->princ->data[1], &host, &trailer); -+ -+ hostname = k5memdup0(host.data, host.length, &ret); -+ if (hostname == NULL) -+ goto cleanup; -+ -+ if (iter->princ->type == KRB5_NT_SRV_HST) { -+ /* Expand the hostname with or without DNS as specified. */ -+ ret = expand_hostname(context, hostname, use_dns, &canonhost); -+ if (ret) -+ goto cleanup; -+ } else { -+ canonhost = strdup(hostname); -+ if (canonhost == NULL) { -+ ret = ENOMEM; -+ goto cleanup; -+ } -+ } -+ -+ /* Add the trailer to the expanded hostname. */ -+ if (asprintf(&combined, "%s%.*s", canonhost, -+ trailer.length, trailer.data) < 0) { -+ combined = NULL; -+ ret = ENOMEM; -+ goto cleanup; -+ } -+ -+ /* Don't yield the same host part twice. */ -+ if (iter->canonhost != NULL && strcmp(iter->canonhost, combined) == 0) -+ goto cleanup; -+ -+ free(iter->canonhost); -+ iter->canonhost = combined; -+ combined = NULL; -+ -+ /* If the realm is unknown, look up the realm of the expanded hostname. */ -+ if (iter->princ->realm.length == 0 && !iter->no_hostrealm) { -+ ret = krb5_get_host_realm(context, canonhost, &hrealms); -+ if (ret) -+ goto cleanup; -+ if (hrealms[0] == NULL) { -+ ret = KRB5_ERR_HOST_REALM_UNKNOWN; -+ goto cleanup; -+ } -+ free(iter->realm); -+ if (*hrealms[0] == '\0' && iter->subst_defrealm) { -+ ret = krb5_get_default_realm(context, &iter->realm); -+ if (ret) -+ goto cleanup; -+ } else { -+ iter->realm = strdup(hrealms[0]); -+ if (iter->realm == NULL) { -+ ret = ENOMEM; -+ goto cleanup; -+ } -+ } -+ } -+ -+ iter->copy = *iter->princ; -+ if (iter->realm != NULL) -+ iter->copy.realm = string2data(iter->realm); -+ iter->components[0] = iter->princ->data[0]; -+ iter->components[1] = string2data(iter->canonhost); -+ iter->copy.data = iter->components; -+ *princ_out = &iter->copy; -+ -+cleanup: -+ free(hostname); -+ free(canonhost); -+ free(combined); -+ krb5_free_host_realm(context, hrealms); -+ return ret; -+} -+ -+krb5_error_code -+k5_canonprinc(krb5_context context, struct canonprinc *iter, -+ krb5_const_principal *princ_out) -+{ -+ int step = ++iter->step; -+ -+ *princ_out = NULL; -+ -+ /* If we're not doing fallback, the input principal is canonical. */ -+ if (context->dns_canonicalize_hostname != CANONHOST_FALLBACK || -+ iter->princ->type != KRB5_NT_SRV_HST || iter->princ->length != 2) { -+ *princ_out = (step == 1) ? iter->princ : NULL; -+ return 0; -+ } -+ -+ /* Canonicalize without DNS at step 1, with DNS at step 2. */ -+ if (step > 2) -+ return 0; -+ return canonicalize_princ(context, iter, step == 2, princ_out); - } - - krb5_error_code KRB5_CALLCONV -@@ -185,9 +295,10 @@ krb5_sname_to_principal(krb5_context context, const char *hostname, - { - krb5_error_code ret; - krb5_principal princ; -- const char *realm, *trailer; -- char **hrealms = NULL, *canonhost = NULL, *hostonly = NULL, *concat = NULL; -+ krb5_const_principal cprinc; -+ krb5_boolean use_dns; - char localname[MAXHOSTNAMELEN]; -+ struct canonprinc iter = { NULL }; - - *princ_out = NULL; - -@@ -205,54 +316,26 @@ krb5_sname_to_principal(krb5_context context, const char *hostname, - if (sname == NULL) - sname = "host"; - -- /* If there is a trailer, remove it for now. */ -- trailer = find_trailer(hostname); -- if (trailer != NULL) { -- hostonly = k5memdup0(hostname, trailer - hostname, &ret); -- if (hostonly == NULL) -- goto cleanup; -- hostname = hostonly; -- } -- -- /* Canonicalize the hostname if appropriate. */ -- if (type == KRB5_NT_SRV_HST) { -- ret = krb5_expand_hostname(context, hostname, &canonhost); -- if (ret) -- goto cleanup; -- hostname = canonhost; -- } -- -- /* Find the realm of the host. */ -- ret = krb5_get_host_realm(context, hostname, &hrealms); -+ /* Build an initial principal with what we have. */ -+ ret = krb5_build_principal(context, &princ, 0, KRB5_REFERRAL_REALM, -+ sname, hostname, (char *)NULL); - if (ret) -- goto cleanup; -- if (hrealms[0] == NULL) { -- ret = KRB5_ERR_HOST_REALM_UNKNOWN; -- goto cleanup; -- } -- realm = hrealms[0]; -- -- /* If there was a trailer, put it back on the end. */ -- if (trailer != NULL) { -- if (asprintf(&concat, "%s%s", hostname, trailer) < 0) { -- ret = ENOMEM; -- goto cleanup; -- } -- hostname = concat; -- } -- -- ret = krb5_build_principal(context, &princ, strlen(realm), realm, sname, -- hostname, (char *)NULL); -- if (ret) -- goto cleanup; -- -+ return ret; - princ->type = type; -- *princ_out = princ; - --cleanup: -- free(hostonly); -- free(canonhost); -- free(concat); -- krb5_free_host_realm(context, hrealms); -+ if (type == KRB5_NT_SRV_HST && -+ context->dns_canonicalize_hostname == CANONHOST_FALLBACK) { -+ /* Delay canonicalization and realm lookup until use. */ -+ *princ_out = princ; -+ return 0; -+ } -+ -+ use_dns = (context->dns_canonicalize_hostname == CANONHOST_TRUE); -+ iter.princ = princ; -+ ret = canonicalize_princ(context, &iter, use_dns, &cprinc); -+ if (!ret) -+ ret = krb5_copy_principal(context, cprinc, princ_out); -+ free_canonprinc(&iter); -+ krb5_free_principal(context, princ); - return ret; - } -diff --git a/src/tests/icred.c b/src/tests/icred.c -index 55f929cd7..d6ce1d5d3 100644 ---- a/src/tests/icred.c -+++ b/src/tests/icred.c -@@ -30,10 +30,7 @@ - * OF THE POSSIBILITY OF SUCH DAMAGE. - */ - --/* -- * This program exercises the init_creds APIs in ways kinit doesn't. Right now -- * it is very simplistic, but it can be extended as needed. -- */ -+/* This program exercises the init_creds APIs in ways kinit doesn't. */ - - #include "k5-platform.h" - #include -@@ -56,10 +53,11 @@ check(krb5_error_code code) - int - main(int argc, char **argv) - { -- const char *princstr, *password; -+ const char *ktname = NULL, *sname = NULL, *princstr, *password; - krb5_principal client; - krb5_init_creds_context icc; - krb5_get_init_creds_opt *opt; -+ krb5_keytab keytab = NULL; - krb5_creds creds; - krb5_boolean stepwise = FALSE; - krb5_preauthtype ptypes[64]; -@@ -69,8 +67,11 @@ main(int argc, char **argv) - check(krb5_init_context(&ctx)); - check(krb5_get_init_creds_opt_alloc(ctx, &opt)); - -- while ((c = getopt(argc, argv, "so:X:")) != -1) { -+ while ((c = getopt(argc, argv, "k:so:S:X:")) != -1) { - switch (c) { -+ case 'k': -+ ktname = optarg; -+ break; - case 's': - stepwise = TRUE; - break; -@@ -78,6 +79,9 @@ main(int argc, char **argv) - assert(nptypes < 64); - ptypes[nptypes++] = atoi(optarg); - break; -+ case 'S': -+ sname = optarg; -+ break; - case 'X': - val = strchr(optarg, '='); - if (val != NULL) -@@ -93,12 +97,20 @@ main(int argc, char **argv) - - argc -= optind; - argv += optind; -- if (argc != 2) -+ if (argc != 1 && argc != 2) - abort(); - princstr = argv[0]; - password = argv[1]; - -- check(krb5_parse_name(ctx, princstr, &client)); -+ if (sname != NULL) { -+ check(krb5_sname_to_principal(ctx, princstr, sname, KRB5_NT_SRV_HST, -+ &client)); -+ } else { -+ check(krb5_parse_name(ctx, princstr, &client)); -+ } -+ -+ if (ktname != NULL) -+ check(krb5_kt_resolve(ctx, ktname, &keytab)); - - if (nptypes > 0) - krb5_get_init_creds_opt_set_preauth_list(opt, ptypes, nptypes); -@@ -106,9 +118,16 @@ main(int argc, char **argv) - if (stepwise) { - /* Use the stepwise interface. */ - check(krb5_init_creds_init(ctx, client, NULL, NULL, 0, NULL, &icc)); -- check(krb5_init_creds_set_password(ctx, icc, password)); -+ if (keytab != NULL) -+ check(krb5_init_creds_set_keytab(ctx, icc, keytab)); -+ if (password != NULL) -+ check(krb5_init_creds_set_password(ctx, icc, password)); - check(krb5_init_creds_get(ctx, icc)); - krb5_init_creds_free(ctx, icc); -+ } else if (keytab != NULL) { -+ check(krb5_get_init_creds_keytab(ctx, &creds, client, keytab, 0, NULL, -+ opt)); -+ krb5_free_cred_contents(ctx, &creds); - } else { - /* Use the traditional one-shot interface. */ - check(krb5_get_init_creds_password(ctx, &creds, client, password, NULL, -@@ -116,6 +135,8 @@ main(int argc, char **argv) - krb5_free_cred_contents(ctx, &creds); - } - -+ if (keytab != NULL) -+ krb5_kt_close(ctx, keytab); - krb5_get_init_creds_opt_free(ctx, opt); - krb5_free_principal(ctx, client); - krb5_free_context(ctx); -diff --git a/src/tests/t_sn2princ.py b/src/tests/t_sn2princ.py -index f3e187286..493fba219 100755 ---- a/src/tests/t_sn2princ.py -+++ b/src/tests/t_sn2princ.py -@@ -85,28 +85,9 @@ if offline: - oname = 'ptr-mismatch.kerberos.org' - fname = 'www.kerberos.org' - --# Test fallback canonicalization krb5_sname_to_principal() results --# (same as dns_canonicalize_hostname=false). -+# Test fallback canonicalization krb5_sname_to_principal() results. - mark('dns_canonicalize_host=fallback') --testfc(oname, oname, 'R1') -- --# Test fallback canonicalization in krb5_get_credentials(). --oprinc = 'host/' + oname --fprinc = 'host/' + fname --shutil.copy(realm.ccache, realm.ccache + '.save') --realm.addprinc(fprinc) --# oprinc doesn't exist, so we get the canonicalized fprinc as a fallback. --msgs = ('Falling back to canonicalized server hostname ' + fname,) --realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon, -- expected_msg=fprinc, expected_trace=msgs) --realm.addprinc(oprinc) --# oprinc now exists, but we still get the fprinc ticket from the cache. --realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon, -- expected_msg=fprinc) --# Without the cached result, we sould get oprinc in preference to fprinc. --os.rename(realm.ccache + '.save', realm.ccache) --realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon, -- expected_msg=oprinc) -+testfc(oname, oname, '') - - # Verify forward resolution before testing for it. - try: -@@ -118,6 +99,48 @@ if canonname.lower() != fname: - skip_rest('sn2princ tests', - '%s forward resolves to %s, not %s' % (oname, canonname, fname)) - -+# Test fallback canonicalization in krb5_get_credentials(). -+oprinc = 'host/' + oname -+fprinc = 'host/' + fname -+shutil.copy(realm.ccache, realm.ccache + '.save') -+# Test that we only try fprinc once if we enter it as input. -+out, trace = realm.run(['./gcred', 'srv-hst', fprinc + '@'], -+ env=fallback_canon, expected_code=1, return_trace=True) -+msg = 'Requesting tickets for %s@R1, referrals on' % fprinc -+if trace.count(msg) != 1: -+ fail('Expected one try for %s' % fprinc) -+# Create fprinc, and verify that we get it as the canonicalized -+# fallback for oprinc. -+realm.addprinc(fprinc) -+msgs = ('Getting credentials user@R1 -> %s@ using' % oprinc, -+ 'Requesting tickets for %s@R1' % oprinc, -+ 'Requesting tickets for %s@R1' % fprinc, -+ 'Received creds for desired service %s@R1' % fprinc) -+realm.run(['./gcred', 'srv-hst', oprinc + '@'], env=fallback_canon, -+ expected_msg=fprinc, expected_trace=msgs) -+realm.addprinc(oprinc) -+# oprinc now exists, but we still get the fprinc ticket from the cache. -+realm.run(['./gcred', 'srv-hst', oprinc + '@'], env=fallback_canon, -+ expected_msg=fprinc) -+# Without the cached result, we sould get oprinc in preference to fprinc. -+os.rename(realm.ccache + '.save', realm.ccache) -+realm.run(['./gcred', 'srv-hst', oprinc], env=fallback_canon, -+ expected_msg=oprinc) -+ -+# Test fallback canonicalization for krb5_rd_req(). -+realm.run([kadminl, 'ktadd', fprinc]) -+msgs = ('Decrypted AP-REQ with server principal %s@R1' % fprinc, -+ 'AP-REQ ticket: user@R1 -> %s@R1' % fprinc) -+realm.run(['./rdreq', fprinc, oprinc + '@'], env=fallback_canon, -+ expected_trace=msgs) -+ -+# Test fallback canonicalization for getting initial creds with a keytab. -+msgs = ('Getting initial credentials for %s@' % oprinc, -+ 'Found entries for %s@R1 in keytab' % fprinc, -+ 'Retrieving %s@R1 from ' % fprinc) -+realm.run(['./icred', '-k', realm.keytab, '-S', 'host', oname], -+ env=fallback_canon, expected_trace=msgs) -+ - # Test forward-only canonicalization (rdns=false). - mark('rdns=false') - testnr(oname, fname, 'R1') diff --git a/Prevent-deletion-of-K-M.patch b/Prevent-deletion-of-K-M.patch deleted file mode 100644 index 5e2c117..0000000 --- a/Prevent-deletion-of-K-M.patch +++ /dev/null @@ -1,45 +0,0 @@ -From 7986adf30dffdd16fec43f261a2fa1384e0b8b90 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 13 Jun 2020 21:55:54 -0400 -Subject: [PATCH] Prevent deletion of K/M - -In libkadm5srv, do not allow deletion of the master key principal, as -it is very difficult to recover a KDB after doing so. - -ticket: 8913 -(cherry picked from commit 94b936a1bf0a8c67809597c5ea5400d8994d5dd8) ---- - src/lib/kadm5/srv/svr_principal.c | 4 ++++ - src/tests/t_kadmin_acl.py | 6 ++++++ - 2 files changed, 10 insertions(+) - -diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c -index 53ecbe1bc..c2412df31 100644 ---- a/src/lib/kadm5/srv/svr_principal.c -+++ b/src/lib/kadm5/srv/svr_principal.c -@@ -537,6 +537,10 @@ kadm5_delete_principal(void *server_handle, krb5_principal principal) - if (principal == NULL) - return EINVAL; - -+ /* Deleting K/M is mostly unrecoverable, so don't allow it. */ -+ if (krb5_principal_compare(handle->context, principal, master_princ)) -+ return KADM5_PROTECT_PRINCIPAL; -+ - if ((ret = kdb_get_entry(handle, principal, &kdb, &adb))) - return(ret); - ret = k5_kadm5_hook_remove(handle->context, handle->hook_handles, -diff --git a/src/tests/t_kadmin_acl.py b/src/tests/t_kadmin_acl.py -index 86eb59729..8946e8cc4 100755 ---- a/src/tests/t_kadmin_acl.py -+++ b/src/tests/t_kadmin_acl.py -@@ -328,4 +328,10 @@ realm.run([kadmin, '-c', realm.ccache, 'cpw', '-randkey', 'none'], - realm.run([kadmin, '-c', realm.ccache, 'cpw', '-randkey', '-e', 'aes256-cts', - 'none'], expected_code=1, expected_msg=msg) - -+# Test operations disallowed at the libkadm5 layer. -+realm.run([kadminl, 'delprinc', 'K/M'], -+ expected_code=1, expected_msg='Cannot change protected principal') -+realm.run([kadminl, 'cpw', '-pw', 'pw', 'kadmin/history'], -+ expected_code=1, expected_msg='Cannot change protected principal') -+ - success('kadmin ACL enforcement') diff --git a/Refactor-cache-checking-in-TGS-client-code.patch b/Refactor-cache-checking-in-TGS-client-code.patch deleted file mode 100644 index 86315ec..0000000 --- a/Refactor-cache-checking-in-TGS-client-code.patch +++ /dev/null @@ -1,188 +0,0 @@ -From 0cffa5904341460353fa7f99b5aa514fc27a10eb Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 23 Jul 2020 01:52:43 -0400 -Subject: [PATCH] Refactor cache checking in TGS client code - -(cherry picked from commit 8f2f0a2e8f65c4b39883129967301e3a8986218b) ---- - src/lib/krb5/krb/get_creds.c | 86 +++++++++++++++++++++--------------- - src/lib/krb5/krb/int-proto.h | 6 +-- - src/lib/krb5/krb/s4u_creds.c | 21 +-------- - 3 files changed, 55 insertions(+), 58 deletions(-) - -diff --git a/src/lib/krb5/krb/get_creds.c b/src/lib/krb5/krb/get_creds.c -index b3f01be9b..32401bcb1 100644 ---- a/src/lib/krb5/krb/get_creds.c -+++ b/src/lib/krb5/krb/get_creds.c -@@ -48,10 +48,10 @@ - * and options. The fields of *mcreds will be aliased to the fields - * of in_creds, so the contents of *mcreds should not be freed. - */ --krb5_error_code --krb5int_construct_matching_creds(krb5_context context, krb5_flags options, -- krb5_creds *in_creds, krb5_creds *mcreds, -- krb5_flags *fields) -+static krb5_error_code -+construct_matching_creds(krb5_context context, krb5_flags options, -+ krb5_creds *in_creds, krb5_creds *mcreds, -+ krb5_flags *fields) - { - if (!in_creds || !in_creds->server || !in_creds->client) - return EINVAL; -@@ -110,6 +110,50 @@ krb5int_construct_matching_creds(krb5_context context, krb5_flags options, - return 0; - } - -+/* Simple wrapper around krb5_cc_retrieve_cred which allocates the result -+ * container. */ -+static krb5_error_code -+cache_get(krb5_context context, krb5_ccache ccache, krb5_flags flags, -+ krb5_creds *in_creds, krb5_creds **out_creds) -+{ -+ krb5_error_code code; -+ krb5_creds *creds; -+ -+ *out_creds = NULL; -+ -+ creds = malloc(sizeof(*creds)); -+ if (creds == NULL) -+ return ENOMEM; -+ -+ code = krb5_cc_retrieve_cred(context, ccache, flags, in_creds, creds); -+ if (code != 0) { -+ free(creds); -+ return code; -+ } -+ -+ *out_creds = creds; -+ return 0; -+} -+ -+krb5_error_code -+k5_get_cached_cred(krb5_context context, krb5_flags options, -+ krb5_ccache ccache, krb5_creds *in_creds, -+ krb5_creds **creds_out) -+{ -+ krb5_error_code code; -+ krb5_creds mcreds; -+ krb5_flags fields; -+ -+ *creds_out = NULL; -+ -+ code = construct_matching_creds(context, options, in_creds, -+ &mcreds, &fields); -+ if (code) -+ return code; -+ -+ return cache_get(context, ccache, fields, &mcreds, creds_out); -+} -+ - /* - * krb5_tkt_creds_step() is implemented using a tail call style. Every - * begin_*, step_*, or *_request function is responsible for returning an -@@ -235,31 +279,6 @@ cleanup: - return code; - } - --/* Simple wrapper around krb5_cc_retrieve_cred which allocates the result -- * container. */ --static krb5_error_code --cache_get(krb5_context context, krb5_ccache ccache, krb5_flags flags, -- krb5_creds *in_creds, krb5_creds **out_creds) --{ -- krb5_error_code code; -- krb5_creds *creds; -- -- *out_creds = NULL; -- -- creds = malloc(sizeof(*creds)); -- if (creds == NULL) -- return ENOMEM; -- -- code = krb5_cc_retrieve_cred(context, ccache, flags, in_creds, creds); -- if (code != 0) { -- free(creds); -- return code; -- } -- -- *out_creds = creds; -- return 0; --} -- - /* - * Set up the request given by ctx->tgs_in_creds, using ctx->cur_tgt. KDC - * options for the requests are determined by ctx->cur_tgt->ticket_flags and -@@ -1023,18 +1042,13 @@ static krb5_error_code - check_cache(krb5_context context, krb5_tkt_creds_context ctx) - { - krb5_error_code code; -- krb5_creds mcreds; -- krb5_flags fields; - krb5_creds req_in_creds; - - /* Check the cache for the originally requested server principal. */ - req_in_creds = *ctx->in_creds; - req_in_creds.server = ctx->req_server; -- code = krb5int_construct_matching_creds(context, ctx->req_options, -- &req_in_creds, &mcreds, &fields); -- if (code) -- return code; -- code = cache_get(context, ctx->ccache, fields, &mcreds, &ctx->reply_creds); -+ code = k5_get_cached_cred(context, ctx->req_options, ctx->ccache, -+ &req_in_creds, &ctx->reply_creds); - if (code == 0) { - ctx->state = STATE_COMPLETE; - return 0; -diff --git a/src/lib/krb5/krb/int-proto.h b/src/lib/krb5/krb/int-proto.h -index fe61bebf5..5211044dc 100644 ---- a/src/lib/krb5/krb/int-proto.h -+++ b/src/lib/krb5/krb/int-proto.h -@@ -79,9 +79,9 @@ clpreauth_otp_initvt(krb5_context context, int maj_ver, int min_ver, - krb5_plugin_vtable vtable); - - krb5_error_code --krb5int_construct_matching_creds(krb5_context context, krb5_flags options, -- krb5_creds *in_creds, krb5_creds *mcreds, -- krb5_flags *fields); -+k5_get_cached_cred(krb5_context context, krb5_flags options, -+ krb5_ccache ccache, krb5_creds *in_creds, -+ krb5_creds **creds_out); - - #define IS_TGS_PRINC(p) ((p)->length == 2 && \ - data_eq_string((p)->data[0], KRB5_TGS_NAME)) -diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c -index d44f939f8..eadb37cd0 100644 ---- a/src/lib/krb5/krb/s4u_creds.c -+++ b/src/lib/krb5/krb/s4u_creds.c -@@ -1155,29 +1155,12 @@ k5_get_proxy_cred_from_kdc(krb5_context context, krb5_flags options, - { - krb5_error_code code; - krb5_const_principal canonprinc; -- krb5_creds mcreds, copy, *creds, *ncreds; -- krb5_flags fields; -+ krb5_creds copy, *creds; - struct canonprinc iter = { in_creds->server, .no_hostrealm = TRUE }; - - *out_creds = NULL; - -- code = krb5int_construct_matching_creds(context, options, in_creds, -- &mcreds, &fields); -- if (code != 0) -- return code; -- -- ncreds = calloc(1, sizeof(*ncreds)); -- if (ncreds == NULL) -- return ENOMEM; -- ncreds->magic = KV5M_CRED; -- -- code = krb5_cc_retrieve_cred(context, ccache, fields, &mcreds, ncreds); -- if (code) { -- free(ncreds); -- } else { -- *out_creds = ncreds; -- } -- -+ code = k5_get_cached_cred(context, options, ccache, in_creds, out_creds); - if ((code != KRB5_CC_NOTFOUND && code != KRB5_CC_NOT_KTYPE) || - options & KRB5_GC_CACHED) - return code; diff --git a/Try-kadmin-admin-first-in-libkadm5clnt.patch b/Try-kadmin-admin-first-in-libkadm5clnt.patch deleted file mode 100644 index 6249ff5..0000000 --- a/Try-kadmin-admin-first-in-libkadm5clnt.patch +++ /dev/null @@ -1,159 +0,0 @@ -From fae915ea7f2734cfd9ef3d5952f25638e675bb7c Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 27 Jul 2020 01:19:01 -0400 -Subject: [PATCH] Try kadmin/admin first in libkadm5clnt - -The MIT krb5 kadmin protocol originally used kadmin/admin as the -service principal. Commits 493f0da5fbf92b0ac2f10e887706d1964d8a15e8 -and 5cfaec38a8e8f1c4b76228ba0a252987af797ca4 changed it to use -kadmin/hostname preferentially, with kadmin/admin as a fallback, for -interoperability with the Solaris SEAM administrative protocol. - -Change the preference order so that kadmin/admin is tried first, with -kadmin/hostname as a fallback. - -ticket: 8934 (new) -(cherry picked from commit 1d282badfbd6098e3db9d50d22d565c2ec3c8c47) ---- - doc/admin/admin_commands/kadmin_local.rst | 14 ++++++------ - doc/admin/database.rst | 10 ++++----- - src/lib/kadm5/clnt/client_init.c | 26 +++++++++-------------- - src/tests/t_kadmin_acl.py | 14 ++++++++++++ - 4 files changed, 36 insertions(+), 28 deletions(-) - -diff --git a/doc/admin/admin_commands/kadmin_local.rst b/doc/admin/admin_commands/kadmin_local.rst -index fafa61365..33cf3a9cb 100644 ---- a/doc/admin/admin_commands/kadmin_local.rst -+++ b/doc/admin/admin_commands/kadmin_local.rst -@@ -44,9 +44,9 @@ Kerberos principals, password policies, and service key tables - (keytabs). - - The remote kadmin client uses Kerberos to authenticate to kadmind --using the service principal ``kadmin/ADMINHOST`` (where *ADMINHOST* is --the fully-qualified hostname of the admin server) or ``kadmin/admin``. --If the credentials cache contains a ticket for one of these -+using the service principal ``kadmin/admin`` or ``kadmin/ADMINHOST`` -+(where *ADMINHOST* is the fully-qualified hostname of the admin -+server). If the credentials cache contains a ticket for one of these - principals, and the **-c** credentials_cache option is specified, that - ticket is used to authenticate to kadmind. Otherwise, the **-p** and - **-k** options are used to specify the client Kerberos principal name -@@ -100,10 +100,10 @@ OPTIONS - fully anonymous operation. - - **-c** *credentials_cache* -- Use *credentials_cache* as the credentials cache. The -- cache should contain a service ticket for the ``kadmin/ADMINHOST`` -- (where *ADMINHOST* is the fully-qualified hostname of the admin -- server) or ``kadmin/admin`` service; it can be acquired with the -+ Use *credentials_cache* as the credentials cache. The cache -+ should contain a service ticket for the ``kadmin/admin`` or -+ ``kadmin/ADMINHOST`` (where *ADMINHOST* is the fully-qualified -+ hostname of the admin server) service; it can be acquired with the - :ref:`kinit(1)` program. If this option is not specified, kadmin - requests a new service ticket from the KDC, and stores it in its - own temporary ccache. -diff --git a/doc/admin/database.rst b/doc/admin/database.rst -index e62cef7a7..ca19a362a 100644 ---- a/doc/admin/database.rst -+++ b/doc/admin/database.rst -@@ -26,8 +26,8 @@ local filesystem (or through LDAP). kadmin.local is necessary to set - up enough of the database to be able to use the remote version. - - kadmin can authenticate to the admin server using the service --principal ``kadmin/HOST`` (where *HOST* is the hostname of the admin --server) or ``kadmin/admin``. If the credentials cache contains a -+principal ``kadmin/admin`` or ``kadmin/HOST`` (where *HOST* is the -+hostname of the admin server). If the credentials cache contains a - ticket for either service principal and the **-c** ccache option is - specified, that ticket is used to authenticate to KADM5. Otherwise, - the **-p** and **-k** options are used to specify the client Kerberos -@@ -811,9 +811,9 @@ Both master and replica sides must have a principal named - ``kiprop/hostname`` (where *hostname* is the lowercase, - fully-qualified, canonical name for the host) registered in the - Kerberos database, and have keys for that principal stored in the --default keytab file (|keytab|). In release 1.13, the --``kiprop/hostname`` principal is created automatically for the master --KDC, but it must still be created for replica KDCs. -+default keytab file (|keytab|). The ``kiprop/hostname`` principal may -+have been created automatically for the master KDC, but it must always -+be created for replica KDCs. - - On the master KDC side, the ``kiprop/hostname`` principal must be - listed in the kadmind ACL file :ref:`kadm5.acl(5)`, and given the -diff --git a/src/lib/kadm5/clnt/client_init.c b/src/lib/kadm5/clnt/client_init.c -index aa08918e2..8d43ab97a 100644 ---- a/src/lib/kadm5/clnt/client_init.c -+++ b/src/lib/kadm5/clnt/client_init.c -@@ -372,22 +372,10 @@ get_init_creds(kadm5_server_handle_t handle, krb5_principal client, - { - kadm5_ret_t code; - krb5_ccache ccache = NULL; -- char svcname[BUFSIZ]; -+ char *svcname, svcbuf[BUFSIZ]; - - *server_out = NULL; - -- /* NULL svcname means use host-based. */ -- if (svcname_in == NULL) { -- code = kadm5_get_admin_service_name(handle->context, -- handle->params.realm, -- svcname, sizeof(svcname)); -- if (code) -- goto error; -- } else { -- strncpy(svcname, svcname_in, sizeof(svcname)); -- svcname[sizeof(svcname)-1] = '\0'; -- } -- - /* - * Acquire a service ticket for svcname@realm for client, using password - * pass (which could be NULL), and create a ccache to store them in. If -@@ -423,13 +411,19 @@ get_init_creds(kadm5_server_handle_t handle, krb5_principal client, - } - handle->lhandle->cache_name = handle->cache_name; - -+ svcname = (svcname_in != NULL) ? svcname_in : KADM5_ADMIN_SERVICE; - code = gic_iter(handle, init_type, ccache, client, pass, svcname, realm, - server_out); - if ((code == KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN - || code == KRB5_CC_NOTFOUND) && svcname_in == NULL) { -- /* Retry with old host-independent service principal. */ -- code = gic_iter(handle, init_type, ccache, client, pass, -- KADM5_ADMIN_SERVICE, realm, server_out); -+ /* Retry with host-based service principal. */ -+ code = kadm5_get_admin_service_name(handle->context, -+ handle->params.realm, -+ svcbuf, sizeof(svcbuf)); -+ if (code) -+ goto error; -+ code = gic_iter(handle, init_type, ccache, client, pass, svcbuf, realm, -+ server_out); - } - /* Improved error messages */ - if (code == KRB5KRB_AP_ERR_BAD_INTEGRITY) code = KADM5_BAD_PASSWORD; -diff --git a/src/tests/t_kadmin_acl.py b/src/tests/t_kadmin_acl.py -index 8946e8cc4..16faf0a9d 100755 ---- a/src/tests/t_kadmin_acl.py -+++ b/src/tests/t_kadmin_acl.py -@@ -328,6 +328,20 @@ realm.run([kadmin, '-c', realm.ccache, 'cpw', '-randkey', 'none'], - realm.run([kadmin, '-c', realm.ccache, 'cpw', '-randkey', '-e', 'aes256-cts', - 'none'], expected_code=1, expected_msg=msg) - -+# Test authentication to kadmin/hostname. -+mark('authentication to kadmin/hostname') -+kadmin_hostname = 'kadmin/' + hostname -+realm.run([kadminl, 'delprinc', 'kadmin/admin']) -+msgs = ('Getting initial credentials for user/admin@KRBTEST.COM', -+ 'Setting initial creds service to kadmin/admin', -+ '/Server not found in Kerberos database', -+ 'Getting initial credentials for user/admin@KRBTEST.COM', -+ 'Setting initial creds service to ' + kadmin_hostname, -+ 'Decrypted AS reply') -+realm.run([kadmin, '-p', 'user/admin', 'listprincs'], expected_code=1, -+ expected_msg="Operation requires ``list'' privilege", -+ input=password('user/admin'), expected_trace=msgs) -+ - # Test operations disallowed at the libkadm5 layer. - realm.run([kadminl, 'delprinc', 'K/M'], - expected_code=1, expected_msg='Cannot change protected principal') diff --git a/krb5.spec b/krb5.spec index 081299e..6005972 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 19%{?dist} +Release: 20%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -71,12 +71,6 @@ Patch32: Use-two-queues-for-concurrent-t_otp.py-daemons.patch Patch33: Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch Patch34: Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch Patch35: Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch -Patch36: Prevent-deletion-of-K-M.patch -Patch37: Try-kadmin-admin-first-in-libkadm5clnt.patch -Patch38: Don-t-create-hostbased-principals-in-new-KDBs.patch -Patch39: Expand-dns_canonicalize_host-fallback-support.patch -Patch40: Cache-S4U2Proxy-requests-by-second-ticket.patch -Patch41: Refactor-cache-checking-in-TGS-client-code.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -638,6 +632,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Aug 13 2020 Robbie Harwood - 1.18.2-20 +- Temporarily dns_canonicalize_hostname=fallback changes +- Hopefully unbreak IPA while we debug further + * Fri Aug 07 2020 Robbie Harwood - 1.18.2-19 - Expand dns_canonicalize_hostname=fallback support From 10033285885949d4349fcb5dd826f201230bb372 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 28 Aug 2020 16:23:22 +0000 Subject: [PATCH 192/304] Mark crypto-polices snippet as missingok Resolves: #1868379 --- krb5.spec | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/krb5.spec b/krb5.spec index 6005972..0e5d23c 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 20%{?dist} +Release: 21%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -578,7 +578,7 @@ exit 0 %dir /etc/gss/mech.d %dir /etc/krb5.conf.d %config(noreplace) /etc/krb5.conf -%config(noreplace) /etc/krb5.conf.d/crypto-policies +%config(noreplace,missingok) /etc/krb5.conf.d/crypto-policies /%{_mandir}/man5/.k5identity.5* /%{_mandir}/man5/.k5login.5* /%{_mandir}/man5/k5identity.5* @@ -632,6 +632,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Aug 28 2020 Robbie Harwood - 1.18.2-21 +- Mark crypto-polices snippet as missingok +- Resolves: #1868379 + * Thu Aug 13 2020 Robbie Harwood - 1.18.2-20 - Temporarily dns_canonicalize_hostname=fallback changes - Hopefully unbreak IPA while we debug further From d7334ebf68fab49402c648d80416aad7bafc7b65 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 9 Sep 2020 17:47:18 -0400 Subject: [PATCH 193/304] Fix input length checking in SPNEGO DER decoding --- ...ngth-checking-in-SPNEGO-DER-decoding.patch | 58 +++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 63 insertions(+), 1 deletion(-) create mode 100644 Fix-input-length-checking-in-SPNEGO-DER-decoding.patch diff --git a/Fix-input-length-checking-in-SPNEGO-DER-decoding.patch b/Fix-input-length-checking-in-SPNEGO-DER-decoding.patch new file mode 100644 index 0000000..4bad883 --- /dev/null +++ b/Fix-input-length-checking-in-SPNEGO-DER-decoding.patch @@ -0,0 +1,58 @@ +From 9504dd4de49938e4cdd56ce6df635b76eaf37e96 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 28 Jul 2020 12:58:26 -0400 +Subject: [PATCH] Fix input length checking in SPNEGO DER decoding + +In get_mech_set(), check the length before reading the first byte, and +decrease the length by the tag byte when reading and verifying the +sequence length. + +In get_req_flags(), check the length before reading the first byte, +and check the context tag length after decoding it. + +ticket: 8933 (new) +tags: pullup +target_version: 1.18-next +target_version: 1.17-next + +(cherry picked from commit 64f4b75a22212681ca293f8f09ddd24b0244d5b4) +--- + src/lib/gssapi/spnego/spnego_mech.c | 10 +++++----- + 1 file changed, 5 insertions(+), 5 deletions(-) + +diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/spnego/spnego_mech.c +index 4cf011143..13c351620 100644 +--- a/src/lib/gssapi/spnego/spnego_mech.c ++++ b/src/lib/gssapi/spnego/spnego_mech.c +@@ -3462,14 +3462,14 @@ get_mech_set(OM_uint32 *minor_status, unsigned char **buff_in, + unsigned char *start; + int i; + +- if (**buff_in != SEQUENCE_OF) ++ if (buff_length < 1 || **buff_in != SEQUENCE_OF) + return (NULL); + + start = *buff_in; + (*buff_in)++; + +- length = gssint_get_der_length(buff_in, buff_length, &bytes); +- if (length < 0 || buff_length - bytes < (unsigned int)length) ++ length = gssint_get_der_length(buff_in, buff_length - 1, &bytes); ++ if (length < 0 || buff_length - 1 - bytes < (unsigned int)length) + return NULL; + + major_status = gss_create_empty_oid_set(minor_status, +@@ -3549,11 +3549,11 @@ get_req_flags(unsigned char **buff_in, OM_uint32 bodysize, + { + unsigned int len; + +- if (**buff_in != (CONTEXT | 0x01)) ++ if (bodysize < 1 || **buff_in != (CONTEXT | 0x01)) + return (0); + + if (g_get_tag_and_length(buff_in, (CONTEXT | 0x01), +- bodysize, &len) < 0) ++ bodysize, &len) < 0 || len != 4) + return GSS_S_DEFECTIVE_TOKEN; + + if (*(*buff_in)++ != BIT_STRING) diff --git a/krb5.spec b/krb5.spec index 0e5d23c..a1faa71 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 21%{?dist} +Release: 22%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -71,6 +71,7 @@ Patch32: Use-two-queues-for-concurrent-t_otp.py-daemons.patch Patch33: Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch Patch34: Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch Patch35: Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch +Patch36: Fix-input-length-checking-in-SPNEGO-DER-decoding.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -632,6 +633,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Sep 09 2020 Robbie Harwood - 1.18.2-22 +- Fix input length checking in SPNEGO DER decoding + * Fri Aug 28 2020 Robbie Harwood - 1.18.2-21 - Mark crypto-polices snippet as missingok - Resolves: #1868379 From c06ba2920a13ff8ff5cb2b24d48a0c52306a36a6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 10 Sep 2020 14:22:32 +0000 Subject: [PATCH 194/304] Use `systemctl reload` to HUP the KDC during logrotate Resolves: #1877692 --- kadmind.logrotate | 2 +- krb5.spec | 6 +++++- krb5kdc.logrotate | 2 +- 3 files changed, 7 insertions(+), 3 deletions(-) diff --git a/kadmind.logrotate b/kadmind.logrotate index 52a66c4..f00aa4d 100644 --- a/kadmind.logrotate +++ b/kadmind.logrotate @@ -4,6 +4,6 @@ monthly rotate 12 postrotate - /bin/kill -HUP `cat /var/run/kadmind.pid 2>/dev/null` 2> /dev/null || true + systemctl reload kadmin.service || true endscript } diff --git a/krb5.spec b/krb5.spec index a1faa71..4ffc992 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 22%{?dist} +Release: 23%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -633,6 +633,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Sep 10 2020 Robbie Harwood - 1.18.2-23 +- Use `systemctl reload` to HUP the KDC during logrotate +- Resolves: #1877692 + * Wed Sep 09 2020 Robbie Harwood - 1.18.2-22 - Fix input length checking in SPNEGO DER decoding diff --git a/krb5kdc.logrotate b/krb5kdc.logrotate index 1100ed3..cfc4539 100644 --- a/krb5kdc.logrotate +++ b/krb5kdc.logrotate @@ -4,6 +4,6 @@ monthly rotate 12 postrotate - /bin/kill -HUP `cat /var/run/krb5kdc.pid 2>/dev/null` 2> /dev/null || true + systemctl reload krb5kdc.service || true endscript } From 501e2980728bcbd0c757fd9bb2b6274342420d2a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 2 Oct 2020 16:36:12 -0400 Subject: [PATCH 195/304] Add md5 override to krad --- Add-channel-bindings-tests.patch | 2 +- ...client_aware_channel_bindings-option.patch | 6 +- ...finalization-safety-check-to-com_err.patch | 2 +- ...tauth-modules-to-set-hw-authent-flag.patch | 2 +- ...ss_unwrap_iov-of-unpadded-RC4-tokens.patch | 2 +- ...y-import-service-GSS-host-based-name.patch | 2 +- ...ns_canonicalize_hostname-to-fallback.patch | 4 +- ...ion-warnings-for-all-init_creds-APIs.patch | 2 +- ...edundant-PKINIT-responder-invocation.patch | 2 +- ...ngth-checking-in-SPNEGO-DER-decoding.patch | 2 +- ...n-KERB_AP_OPTIONS_CBT-server-support.patch | 2 +- Fix-typo-in-in-in-the-ksu-man-page.patch | 2 +- ...-enctypes-in-krb5_string_to_keysalts.patch | 2 +- Implement-GSS_C_CHANNEL_BOUND_FLAG.patch | 2 +- ...ment-KERB_AP_OPTIONS_CBT-server-side.patch | 2 +- Improve-negoex_parse_token-code-hygiene.patch | 2 +- ...ndicator-check-for-S4U2Self-requests.patch | 2 +- ...SER-if-we-can-t-compute-its-checksum.patch | 2 +- Pass-channel-bindings-through-SPNEGO.patch | 2 +- Pass-gss_localname-through-SPNEGO.patch | 2 +- Refactor-krb5-GSS-checksum-handling.patch | 2 +- ...ly-acquired-creds-from-client-keytab.patch | 2 +- Remove-resolver-test-utility.patch | 2 +- ...ce-gssrpc-tests-with-a-Python-script.patch | 2 +- ...eues-for-concurrent-t_otp.py-daemons.patch | 2 +- ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 136 +++++++++++------- krb5.spec | 5 +- 27 files changed, 117 insertions(+), 80 deletions(-) diff --git a/Add-channel-bindings-tests.patch b/Add-channel-bindings-tests.patch index b758c79..2eb0f1c 100644 --- a/Add-channel-bindings-tests.patch +++ b/Add-channel-bindings-tests.patch @@ -1,4 +1,4 @@ -From 3e92520c1417f22447751cd9172d5ab30c2e0ad8 Mon Sep 17 00:00:00 2001 +From 6d36ea6fcfe281a8ce73fc5aa5c133f435d93fa4 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Fri, 20 Mar 2020 00:17:28 +0100 Subject: [PATCH] Add channel bindings tests diff --git a/Add-client_aware_channel_bindings-option.patch b/Add-client_aware_channel_bindings-option.patch index 012ce8d..bd3bcba 100644 --- a/Add-client_aware_channel_bindings-option.patch +++ b/Add-client_aware_channel_bindings-option.patch @@ -1,4 +1,4 @@ -From 2a08fe3d2d1972df4ffe37d4bb64b161889ff988 Mon Sep 17 00:00:00 2001 +From 46ec975eb8f33b6d42c440758fc0deb826f87313 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 10 Mar 2020 13:13:17 +0100 Subject: [PATCH] Add client_aware_channel_bindings option @@ -20,10 +20,10 @@ ticket: 8900 3 files changed, 98 insertions(+), 86 deletions(-) diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index a7e7a29d1..7f2879640 100644 +index 38f450367..da5ad00f2 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst -@@ -382,6 +382,12 @@ The libdefaults section may contain any of the following relations: +@@ -388,6 +388,12 @@ The libdefaults section may contain any of the following relations: credentials will fail if the client machine does not have a keytab. The default value is false. diff --git a/Add-finalization-safety-check-to-com_err.patch b/Add-finalization-safety-check-to-com_err.patch index 531bbf5..a7ebd53 100644 --- a/Add-finalization-safety-check-to-com_err.patch +++ b/Add-finalization-safety-check-to-com_err.patch @@ -1,4 +1,4 @@ -From 9b28e9bbadb775cf790092bc0b0fe9f6c880d215 Mon Sep 17 00:00:00 2001 +From 96a36ef54aecb48b71c1ae0cc85b83ef644c3bd0 Mon Sep 17 00:00:00 2001 From: Jiri Sasek Date: Fri, 13 Mar 2020 19:02:58 +0100 Subject: [PATCH] Add finalization safety check to com_err diff --git a/Allow-certauth-modules-to-set-hw-authent-flag.patch b/Allow-certauth-modules-to-set-hw-authent-flag.patch index ebadb9b..94ff5dd 100644 --- a/Allow-certauth-modules-to-set-hw-authent-flag.patch +++ b/Allow-certauth-modules-to-set-hw-authent-flag.patch @@ -1,4 +1,4 @@ -From 5413039348c612716fb5e33347814b7608778646 Mon Sep 17 00:00:00 2001 +From 5b62f6f6a960e5a428a39a3e83e0a16dba5a914a Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 24 Feb 2020 15:58:59 -0500 Subject: [PATCH] Allow certauth modules to set hw-authent flag diff --git a/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch b/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch index 4698963..3824646 100644 --- a/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch +++ b/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch @@ -1,4 +1,4 @@ -From bedbb5ee1ad821b91f00d30361985e6863c0e6ba Mon Sep 17 00:00:00 2001 +From 594c9d225f470e73a46dd2a85c5e50571e90598c Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 11 Jul 2020 21:57:30 -0400 Subject: [PATCH] Allow gss_unwrap_iov() of unpadded RC4 tokens diff --git a/Correctly-import-service-GSS-host-based-name.patch b/Correctly-import-service-GSS-host-based-name.patch index 754bc89..f56aed4 100644 --- a/Correctly-import-service-GSS-host-based-name.patch +++ b/Correctly-import-service-GSS-host-based-name.patch @@ -1,4 +1,4 @@ -From e8c6f76079bac021e30e89e12b547cc73f71ec36 Mon Sep 17 00:00:00 2001 +From f56afbeb7848322f3208edd55f2c12a9e32127f0 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 30 Mar 2020 15:26:02 -0400 Subject: [PATCH] Correctly import "service@" GSS host-based name diff --git a/Default-dns_canonicalize_hostname-to-fallback.patch b/Default-dns_canonicalize_hostname-to-fallback.patch index ef80329..1c46562 100644 --- a/Default-dns_canonicalize_hostname-to-fallback.patch +++ b/Default-dns_canonicalize_hostname-to-fallback.patch @@ -1,4 +1,4 @@ -From 07179e38e5ee72e82ebc77a1c8d73e34905268b7 Mon Sep 17 00:00:00 2001 +From c3d2c3bcafe0ac87d9cbbf37f1488ad642627fc3 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 27 May 2020 18:48:35 -0400 Subject: [PATCH] Default dns_canonicalize_hostname to "fallback" @@ -54,7 +54,7 @@ index 5232db9af..afdf30297 100644 Configuration of hostnames varies by operating system. On the diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 1d2aa7f68..a7e7a29d1 100644 +index 3a8b9cf47..38f450367 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst @@ -188,11 +188,10 @@ The libdefaults section may contain any of the following relations: diff --git a/Do-expiration-warnings-for-all-init_creds-APIs.patch b/Do-expiration-warnings-for-all-init_creds-APIs.patch index 24062a0..4f642f4 100644 --- a/Do-expiration-warnings-for-all-init_creds-APIs.patch +++ b/Do-expiration-warnings-for-all-init_creds-APIs.patch @@ -1,4 +1,4 @@ -From 0083381a1dc008c6a1a437393045f82ec06423f8 Mon Sep 17 00:00:00 2001 +From 51a9f8e7498591b22558a7a61d42a821030f9c4e Mon Sep 17 00:00:00 2001 From: Sumit Bose Date: Fri, 28 Feb 2020 10:11:49 +0100 Subject: [PATCH] Do expiration warnings for all init_creds APIs diff --git a/Eliminate-redundant-PKINIT-responder-invocation.patch b/Eliminate-redundant-PKINIT-responder-invocation.patch index 4234ffd..48e6e89 100644 --- a/Eliminate-redundant-PKINIT-responder-invocation.patch +++ b/Eliminate-redundant-PKINIT-responder-invocation.patch @@ -1,4 +1,4 @@ -From 43d09ed10d495e78c786f5468455f16a63a99532 Mon Sep 17 00:00:00 2001 +From b27a2f1f330afed53b034a66031f9a801b4568b7 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 23 Mar 2020 19:10:03 -0400 Subject: [PATCH] Eliminate redundant PKINIT responder invocation diff --git a/Fix-input-length-checking-in-SPNEGO-DER-decoding.patch b/Fix-input-length-checking-in-SPNEGO-DER-decoding.patch index 4bad883..ae01c8d 100644 --- a/Fix-input-length-checking-in-SPNEGO-DER-decoding.patch +++ b/Fix-input-length-checking-in-SPNEGO-DER-decoding.patch @@ -1,4 +1,4 @@ -From 9504dd4de49938e4cdd56ce6df635b76eaf37e96 Mon Sep 17 00:00:00 2001 +From 5b42970afea248889fd3350448a40045d467ff3f Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 28 Jul 2020 12:58:26 -0400 Subject: [PATCH] Fix input length checking in SPNEGO DER decoding diff --git a/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch b/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch index 54f2550..c5ec79a 100644 --- a/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch +++ b/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch @@ -1,4 +1,4 @@ -From 044e2209586fd1935d9a637df76d52f48c4f3e6e Mon Sep 17 00:00:00 2001 +From ff47523d7d812fba24106f416aafa5d1f2c433a2 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 24 Jul 2020 16:05:24 -0400 Subject: [PATCH] Fix leak in KERB_AP_OPTIONS_CBT server support diff --git a/Fix-typo-in-in-in-the-ksu-man-page.patch b/Fix-typo-in-in-in-the-ksu-man-page.patch index 5196a90..040355c 100644 --- a/Fix-typo-in-in-in-the-ksu-man-page.patch +++ b/Fix-typo-in-in-in-the-ksu-man-page.patch @@ -1,4 +1,4 @@ -From 8de669742ae4190542741f0dc61119a6a0dad666 Mon Sep 17 00:00:00 2001 +From bf8567ed95991628f198e88403e30f78e2d74e15 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 May 2020 15:01:18 -0400 Subject: [PATCH] Fix typo ("in in") in the ksu man page diff --git a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch index 2bdd0a3..14e27a9 100644 --- a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch +++ b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch @@ -1,4 +1,4 @@ -From 3f873868fb08b77da2d30e164a0ef6c71c17c607 Mon Sep 17 00:00:00 2001 +From e74f9424e47ab914c46e549fc5a2cbdf2615ef93 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 15 Jul 2020 15:42:20 -0400 Subject: [PATCH] Ignore bad enctypes in krb5_string_to_keysalts() diff --git a/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch b/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch index 649caa4..2b41b6b 100644 --- a/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch +++ b/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch @@ -1,4 +1,4 @@ -From 3ea1d6296ced3a998e79356f9be212e4c5e6a5d5 Mon Sep 17 00:00:00 2001 +From 651b9b8084ecff5553b7ef6ee723ce7c4438a9d8 Mon Sep 17 00:00:00 2001 From: Alexander Scheel Date: Wed, 5 Jul 2017 11:38:30 -0400 Subject: [PATCH] Implement GSS_C_CHANNEL_BOUND_FLAG diff --git a/Implement-KERB_AP_OPTIONS_CBT-server-side.patch b/Implement-KERB_AP_OPTIONS_CBT-server-side.patch index 41cf5f0..eadc695 100644 --- a/Implement-KERB_AP_OPTIONS_CBT-server-side.patch +++ b/Implement-KERB_AP_OPTIONS_CBT-server-side.patch @@ -1,4 +1,4 @@ -From 6407bf087fe53088d91efd09df736e979cd4e8db Mon Sep 17 00:00:00 2001 +From bc89c6c720c4170d43010fead23550b80499c32a Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Mon, 9 Mar 2020 16:04:21 +0100 Subject: [PATCH] Implement KERB_AP_OPTIONS_CBT (server side) diff --git a/Improve-negoex_parse_token-code-hygiene.patch b/Improve-negoex_parse_token-code-hygiene.patch index f6b42a6..a58c2e6 100644 --- a/Improve-negoex_parse_token-code-hygiene.patch +++ b/Improve-negoex_parse_token-code-hygiene.patch @@ -1,4 +1,4 @@ -From c726a72c68244129eb08b840b92144acfa776573 Mon Sep 17 00:00:00 2001 +From 4c96c8fef146337b7d3c0ebb4118a18818dd1f4e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 9 Jun 2020 16:23:37 -0400 Subject: [PATCH] Improve negoex_parse_token() code hygiene diff --git a/Omit-KDC-indicator-check-for-S4U2Self-requests.patch b/Omit-KDC-indicator-check-for-S4U2Self-requests.patch index 6ca7931..d5eacc1 100644 --- a/Omit-KDC-indicator-check-for-S4U2Self-requests.patch +++ b/Omit-KDC-indicator-check-for-S4U2Self-requests.patch @@ -1,4 +1,4 @@ -From 6d132f1019b2f1b6f54bae25ed0ea9122c87a190 Mon Sep 17 00:00:00 2001 +From f0ac5c1efef5401f669dc176e62c09b0b01fa2d0 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 6 May 2020 16:03:13 -0400 Subject: [PATCH] Omit KDC indicator check for S4U2Self requests diff --git a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch index d0db74b..8e1c248 100644 --- a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch +++ b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch @@ -1,4 +1,4 @@ -From c36e826c70cb5b3bff8bd4371d47884cea30b3f4 Mon Sep 17 00:00:00 2001 +From 5251097c927f476fe83ffe544b73fd2d785aaf2a Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Sat, 6 Jun 2020 11:03:37 +0200 Subject: [PATCH] Omit PA_FOR_USER if we can't compute its checksum diff --git a/Pass-channel-bindings-through-SPNEGO.patch b/Pass-channel-bindings-through-SPNEGO.patch index 5ab5c07..0e307c3 100644 --- a/Pass-channel-bindings-through-SPNEGO.patch +++ b/Pass-channel-bindings-through-SPNEGO.patch @@ -1,4 +1,4 @@ -From ee79bd43005245d3e5a2d3ec6d61146945e77717 Mon Sep 17 00:00:00 2001 +From 17d9b74328f247de5f9d820ae008726632d11d2a Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 28 Apr 2020 18:15:55 +0200 Subject: [PATCH] Pass channel bindings through SPNEGO diff --git a/Pass-gss_localname-through-SPNEGO.patch b/Pass-gss_localname-through-SPNEGO.patch index eff3733..e641a91 100644 --- a/Pass-gss_localname-through-SPNEGO.patch +++ b/Pass-gss_localname-through-SPNEGO.patch @@ -1,4 +1,4 @@ -From dce745bbdf95ddfa733bc306c57afe5fcab74479 Mon Sep 17 00:00:00 2001 +From cec820485e8b854fe3ee42d0a67a77e7ad20595e Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 26 Apr 2020 19:55:54 -0400 Subject: [PATCH] Pass gss_localname() through SPNEGO diff --git a/Refactor-krb5-GSS-checksum-handling.patch b/Refactor-krb5-GSS-checksum-handling.patch index 392d929..c80426b 100644 --- a/Refactor-krb5-GSS-checksum-handling.patch +++ b/Refactor-krb5-GSS-checksum-handling.patch @@ -1,4 +1,4 @@ -From a34b7c50e62c19f80d39ece6a72017dac781df64 Mon Sep 17 00:00:00 2001 +From c90cef2ebfbefc595798dd5dbb805575e1be0fbf Mon Sep 17 00:00:00 2001 From: Alexander Scheel Date: Fri, 30 Jun 2017 16:03:01 -0400 Subject: [PATCH] Refactor krb5 GSS checksum handling diff --git a/Refresh-manually-acquired-creds-from-client-keytab.patch b/Refresh-manually-acquired-creds-from-client-keytab.patch index d67d9b4..ff28434 100644 --- a/Refresh-manually-acquired-creds-from-client-keytab.patch +++ b/Refresh-manually-acquired-creds-from-client-keytab.patch @@ -1,4 +1,4 @@ -From 13e085a996ac53484fa308f3ef7a2b66c05ccdfa Mon Sep 17 00:00:00 2001 +From 7316aaa0e9249a88e919f2596d881f78970548bc Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 26 Feb 2020 18:27:17 -0500 Subject: [PATCH] Refresh manually acquired creds from client keytab diff --git a/Remove-resolver-test-utility.patch b/Remove-resolver-test-utility.patch index 6602185..e5dd78d 100644 --- a/Remove-resolver-test-utility.patch +++ b/Remove-resolver-test-utility.patch @@ -1,4 +1,4 @@ -From 85bb5fe5a11708b78e9f0bd3a3b34999b6c888a7 Mon Sep 17 00:00:00 2001 +From 3e75969e0c0a52ec3ca8195200fcdadaa63b324f Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 28 May 2020 18:41:02 -0400 Subject: [PATCH] Remove resolver test utility diff --git a/Replace-gssrpc-tests-with-a-Python-script.patch b/Replace-gssrpc-tests-with-a-Python-script.patch index 17fee61..ced6543 100644 --- a/Replace-gssrpc-tests-with-a-Python-script.patch +++ b/Replace-gssrpc-tests-with-a-Python-script.patch @@ -1,4 +1,4 @@ -From a12fc355a034e5b1d23bdb23db9735d4eaa396d8 Mon Sep 17 00:00:00 2001 +From 404cc1152880a567fc27bb7c691a1a732692bbf9 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 15 Feb 2020 20:34:23 -0500 Subject: [PATCH] Replace gssrpc tests with a Python script diff --git a/Use-two-queues-for-concurrent-t_otp.py-daemons.patch b/Use-two-queues-for-concurrent-t_otp.py-daemons.patch index 33da6f5..4e81cd0 100644 --- a/Use-two-queues-for-concurrent-t_otp.py-daemons.patch +++ b/Use-two-queues-for-concurrent-t_otp.py-daemons.patch @@ -1,4 +1,4 @@ -From 8e08f01d73ddca1b828788710ec6bb3e0354727a Mon Sep 17 00:00:00 2001 +From 3e0d464f55320b393e32285f31710c24758a9101 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 4 Mar 2020 17:18:51 -0500 Subject: [PATCH] Use two queues for concurrent t_otp.py daemons diff --git a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index b304c47..08b78b1 100644 --- a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From 15056939ae1e52b9c0b4e0f4ac59772b0d942647 Mon Sep 17 00:00:00 2001 +From bf8521bfaa4a4d54f6eb94f785c68942f4afa055 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 @@ -17,24 +17,44 @@ AES is fine. Shame about SPAKE though. post6 restores MD4 (and therefore keygen-only RC4). +post7 restores MD5 and adds radius_md5_fips_override. + Last-updated: krb5-1.17 --- + doc/admin/conf_files/krb5_conf.rst | 6 +++ src/lib/crypto/krb/prng.c | 11 ++++- .../crypto/openssl/enc_provider/camellia.c | 6 +++ src/lib/crypto/openssl/enc_provider/rc4.c | 13 +++++- .../crypto/openssl/hash_provider/hash_evp.c | 12 +++++ src/lib/crypto/openssl/hmac.c | 6 ++- - src/lib/krad/attr.c | 45 ++++++++++++++----- - src/lib/krad/attrset.c | 5 ++- - src/lib/krad/internal.h | 13 +++++- - src/lib/krad/packet.c | 22 ++++----- - src/lib/krad/remote.c | 10 ++++- + src/lib/krad/attr.c | 46 ++++++++++++++----- + src/lib/krad/attrset.c | 5 +- + src/lib/krad/internal.h | 28 ++++++++++- + src/lib/krad/packet.c | 22 +++++---- + src/lib/krad/remote.c | 10 +++- src/lib/krad/t_attr.c | 3 +- src/lib/krad/t_attrset.c | 4 +- src/plugins/preauth/spake/spake_client.c | 6 +++ src/plugins/preauth/spake/spake_kdc.c | 6 +++ - 14 files changed, 129 insertions(+), 33 deletions(-) + 15 files changed, 151 insertions(+), 33 deletions(-) +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index 1d2aa7f68..3a8b9cf47 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -331,6 +331,12 @@ The libdefaults section may contain any of the following relations: + qualification of shortnames, set this relation to the empty string + with ``qualify_shortname = ""``. (New in release 1.18.) + ++**radius_md5_fips_override** ++ Downstream-only option to enable use of MD5 in RADIUS ++ communication (libkrad). This allows for local (or protected ++ tunnel) communication with a RADIUS server that doesn't use krad ++ (e.g., freeradius) while in FIPS mode. ++ + **rdns** + If this flag is true, reverse name lookup will be used in addition + to forward name lookup to canonicalizing hostnames for use in diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c index cb9ca9b98..f0e9984ca 100644 --- a/src/lib/crypto/krb/prng.c @@ -129,15 +149,15 @@ index a65d57b7a..6ccaca94a 100644 * The cipher state here is a saved pointer to a struct arcfour_state * object, rather than a flat byte array as in most enc providers. The diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c -index 1e0fb8fc3..feb5eda99 100644 +index 1e0fb8fc3..2eb5139c0 100644 --- a/src/lib/crypto/openssl/hash_provider/hash_evp.c +++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c @@ -49,6 +49,11 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, if (ctx == NULL) return ENOMEM; -+ if (type == EVP_md4()) { -+ /* See comment below in hash_md4(). */ ++ if (type == EVP_md4() || type == EVP_md5()) { ++ /* See comments below in hash_md4() and hash_md5(). */ + EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_NON_FIPS_ALLOW); + } + @@ -159,8 +179,8 @@ index 1e0fb8fc3..feb5eda99 100644 static krb5_error_code hash_md5(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) { -+ if (FIPS_mode()) -+ return KRB5_CRYPTO_INTERNAL; ++ /* MD5 is needed in FIPS mode for communication with RADIUS servers. This ++ * is gated in libkrad by libdefaults->radius_md5_fips_override. */ return hash_evp(EVP_md5(), data, num_data, output); } @@ -182,18 +202,10 @@ index 7dc59dcc0..769a50c00 100644 else if (!strncmp(hash->hash_name, "MD4", 3)) return EVP_md4(); diff --git a/src/lib/krad/attr.c b/src/lib/krad/attr.c -index 9c13d9d75..275327e67 100644 +index 9c13d9d75..42d354a3b 100644 --- a/src/lib/krad/attr.c +++ b/src/lib/krad/attr.c -@@ -30,6 +30,7 @@ - #include - #include "internal.h" - -+#include - #include - - /* RFC 2865 */ -@@ -38,7 +39,8 @@ +@@ -38,7 +38,8 @@ typedef krb5_error_code (*attribute_transform_fn)(krb5_context ctx, const char *secret, const unsigned char *auth, const krb5_data *in, @@ -203,7 +215,7 @@ index 9c13d9d75..275327e67 100644 typedef struct { const char *name; -@@ -51,12 +53,14 @@ typedef struct { +@@ -51,12 +52,14 @@ typedef struct { static krb5_error_code user_password_encode(krb5_context ctx, const char *secret, const unsigned char *auth, const krb5_data *in, @@ -220,7 +232,7 @@ index 9c13d9d75..275327e67 100644 static const attribute_record attributes[UCHAR_MAX] = { {"User-Name", 1, MAX_ATTRSIZE, NULL, NULL}, -@@ -128,7 +132,8 @@ static const attribute_record attributes[UCHAR_MAX] = { +@@ -128,7 +131,8 @@ static const attribute_record attributes[UCHAR_MAX] = { static krb5_error_code user_password_encode(krb5_context ctx, const char *secret, const unsigned char *auth, const krb5_data *in, @@ -230,20 +242,21 @@ index 9c13d9d75..275327e67 100644 { const unsigned char *indx; krb5_error_code retval; -@@ -154,8 +159,14 @@ user_password_encode(krb5_context ctx, const char *secret, +@@ -154,8 +158,15 @@ user_password_encode(krb5_context ctx, const char *secret, for (blck = 0, indx = auth; blck * BLOCKSIZE < len; blck++) { memcpy(tmp.data + seclen, indx, BLOCKSIZE); - retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &tmp, - &sum); -+ if (FIPS_mode()) { ++ if (kr_use_fips(ctx)) { + /* Skip encryption here. Taint so that we won't pass it out of + * the machine by accident. */ + *is_fips = TRUE; + sum.contents = calloc(1, BLOCKSIZE); -+ } else ++ } else { + retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &tmp, + &sum); ++ } if (retval != 0) { zap(tmp.data, tmp.length); zap(outbuf, len); @@ -257,24 +270,25 @@ index 9c13d9d75..275327e67 100644 { const unsigned char *indx; krb5_error_code retval; -@@ -204,8 +216,14 @@ user_password_decode(krb5_context ctx, const char *secret, +@@ -204,8 +216,15 @@ user_password_decode(krb5_context ctx, const char *secret, for (blck = 0, indx = auth; blck * BLOCKSIZE < in->length; blck++) { memcpy(tmp.data + seclen, indx, BLOCKSIZE); - retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, - &tmp, &sum); -+ if (FIPS_mode()) { ++ if (kr_use_fips(ctx)) { + /* Skip encryption here. Taint so that we won't pass it out of + * the machine by accident. */ + *is_fips = TRUE; + sum.contents = calloc(1, BLOCKSIZE); -+ } else ++ } else { + retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, + &tmp, &sum); ++ } if (retval != 0) { zap(tmp.data, tmp.length); zap(outbuf, in->length); -@@ -248,7 +266,7 @@ krb5_error_code +@@ -248,7 +267,7 @@ krb5_error_code kr_attr_encode(krb5_context ctx, const char *secret, const unsigned char *auth, krad_attr type, const krb5_data *in, unsigned char outbuf[MAX_ATTRSIZE], @@ -283,7 +297,7 @@ index 9c13d9d75..275327e67 100644 { krb5_error_code retval; -@@ -265,7 +283,8 @@ kr_attr_encode(krb5_context ctx, const char *secret, +@@ -265,7 +284,8 @@ kr_attr_encode(krb5_context ctx, const char *secret, return 0; } @@ -293,7 +307,7 @@ index 9c13d9d75..275327e67 100644 } krb5_error_code -@@ -274,6 +293,7 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, +@@ -274,6 +294,7 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen) { krb5_error_code retval; @@ -301,7 +315,7 @@ index 9c13d9d75..275327e67 100644 retval = kr_attr_valid(type, in); if (retval != 0) -@@ -288,7 +308,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, +@@ -288,7 +309,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, return 0; } @@ -335,10 +349,19 @@ index 03c613716..d89982a13 100644 return retval; diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h -index 996a89372..a53ce31ce 100644 +index 996a89372..312dc8258 100644 --- a/src/lib/krad/internal.h +++ b/src/lib/krad/internal.h -@@ -49,6 +49,13 @@ +@@ -39,6 +39,8 @@ + #include + #include + ++#include ++ + #ifndef UCHAR_MAX + #define UCHAR_MAX 255 + #endif +@@ -49,6 +51,13 @@ typedef struct krad_remote_st krad_remote; @@ -352,7 +375,7 @@ index 996a89372..a53ce31ce 100644 /* Validate constraints of an attribute. */ krb5_error_code kr_attr_valid(krad_attr type, const krb5_data *data); -@@ -57,7 +64,8 @@ kr_attr_valid(krad_attr type, const krb5_data *data); +@@ -57,7 +66,8 @@ kr_attr_valid(krad_attr type, const krb5_data *data); krb5_error_code kr_attr_encode(krb5_context ctx, const char *secret, const unsigned char *auth, krad_attr type, const krb5_data *in, @@ -362,7 +385,7 @@ index 996a89372..a53ce31ce 100644 /* Decode an attribute. */ krb5_error_code -@@ -69,7 +77,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, +@@ -69,7 +79,8 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, krb5_error_code kr_attrset_encode(const krad_attrset *set, const char *secret, const unsigned char *auth, @@ -372,19 +395,29 @@ index 996a89372..a53ce31ce 100644 /* Decode attributes from a buffer. */ krb5_error_code +@@ -152,4 +163,17 @@ gai_error_code(int err) + } + } + ++static inline krb5_boolean ++kr_use_fips(krb5_context ctx) ++{ ++ int val = 0; ++ ++ if (!FIPS_mode()) ++ return 0; ++ ++ profile_get_boolean(ctx->profile, "libdefaults", ++ "radius_md5_fips_override", NULL, 0, &val); ++ return !val; ++} ++ + #endif /* INTERNAL_H_ */ diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c -index c597174b6..794ac84c4 100644 +index c597174b6..fc2d24800 100644 --- a/src/lib/krad/packet.c +++ b/src/lib/krad/packet.c -@@ -32,6 +32,7 @@ - #include - - #include -+#include - - typedef unsigned char uchar; - -@@ -53,12 +54,6 @@ typedef unsigned char uchar; +@@ -53,12 +53,6 @@ typedef unsigned char uchar; #define pkt_auth(p) ((uchar *)offset(&(p)->pkt, OFFSET_AUTH)) #define pkt_attr(p) ((unsigned char *)offset(&(p)->pkt, OFFSET_ATTR)) @@ -397,19 +430,20 @@ index c597174b6..794ac84c4 100644 typedef struct { uchar x[(UCHAR_MAX + 1) / 8]; } idmap; -@@ -187,8 +182,13 @@ auth_generate_response(krb5_context ctx, const char *secret, +@@ -187,8 +181,14 @@ auth_generate_response(krb5_context ctx, const char *secret, memcpy(data.data + response->pkt.length, secret, strlen(secret)); /* Hash it. */ - retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &data, - &hash); -+ if (FIPS_mode()) { ++ if (kr_use_fips(ctx)) { + /* This checksum does very little security-wise anyway, so don't + * taint. */ + hash.contents = calloc(1, AUTH_FIELD_SIZE); -+ } else ++ } else { + retval = krb5_c_make_checksum(ctx, CKSUMTYPE_RSA_MD5, NULL, 0, &data, + &hash); ++ } free(data.data); if (retval != 0) return retval; diff --git a/krb5.spec b/krb5.spec index 4ffc992..8f389f4 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 23%{?dist} +Release: 24%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -633,6 +633,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Oct 02 2020 Robbie Harwood - 1.18.2-24 +- Add md5 override to krad + * Thu Sep 10 2020 Robbie Harwood - 1.18.2-23 - Use `systemctl reload` to HUP the KDC during logrotate - Resolves: #1877692 From 96c0dcc1c7983803070610543e5c443d4e575316 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 15 Oct 2020 16:18:06 -0400 Subject: [PATCH 196/304] Unify kvno option documentation --- ...e-kvno-options-from-Heimdal-kgetcred.patch | 404 ++++++++++++++++++ Unify-kvno-option-documentation.patch | 185 ++++++++ krb5.spec | 7 +- 3 files changed, 595 insertions(+), 1 deletion(-) create mode 100644 Add-three-kvno-options-from-Heimdal-kgetcred.patch create mode 100644 Unify-kvno-option-documentation.patch diff --git a/Add-three-kvno-options-from-Heimdal-kgetcred.patch b/Add-three-kvno-options-from-Heimdal-kgetcred.patch new file mode 100644 index 0000000..40a6318 --- /dev/null +++ b/Add-three-kvno-options-from-Heimdal-kgetcred.patch @@ -0,0 +1,404 @@ +From 538d787aa7c10894cc0426f54db0d8248efcf7c9 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 17 Jun 2020 20:48:38 -0400 +Subject: [PATCH] Add three kvno options from Heimdal kgetcred + +Add the flags --cached-only and --no-store, which pass the +corresponding options to krb5_get_credentials(). Add the option +--out-cache to write the retrieved credentials to a specified output +cache. + +Add a Python test script for kvno command-line options, including +tests for the new options. + +ticket: 8917 (new) +(cherry picked from commit 876bab8418d7dd134c9d9db812ee2118d5ad58f0) +--- + doc/user/user_commands/kvno.rst | 13 ++++ + src/clients/kvno/Makefile.in | 3 + + src/clients/kvno/kvno.c | 115 +++++++++++++++++++++++--------- + src/clients/kvno/t_kvno.py | 75 +++++++++++++++++++++ + src/man/kvno.man | 13 ++++ + 5 files changed, 187 insertions(+), 32 deletions(-) + create mode 100644 src/clients/kvno/t_kvno.py + +diff --git a/doc/user/user_commands/kvno.rst b/doc/user/user_commands/kvno.rst +index 3892f0ca5..718313576 100644 +--- a/doc/user/user_commands/kvno.rst ++++ b/doc/user/user_commands/kvno.rst +@@ -74,6 +74,19 @@ OPTIONS + client principal with the X.509 certificate in *cert_file*. The + certificate file must be in PEM format. + ++**--cached-only** ++ Only retrieve credentials already present in the cache, not from ++ the KDC. ++ ++**--no-store** ++ Do not store retrieved credentials in the cache. If ++ **--out-cache** is also specified, credentials will still be ++ stored into the output credential cache. ++ ++**--out-cache** *ccache* ++ Initialize *ccache* and store all retrieved credentials into it. ++ Do not store acquired credentials in the input cache. ++ + **--u2u** *ccache* + Requests a user-to-user ticket. *ccache* must contain a local + krbtgt ticket for the server principal. The reported version +diff --git a/src/clients/kvno/Makefile.in b/src/clients/kvno/Makefile.in +index 1c3f79392..5ba877271 100644 +--- a/src/clients/kvno/Makefile.in ++++ b/src/clients/kvno/Makefile.in +@@ -26,6 +26,9 @@ kvno: kvno.o $(KRB5_BASE_DEPLIBS) + ##WIN32## link $(EXE_LINKOPTS) /out:$@ $** + ##WIN32## $(_VC_MANIFEST_EMBED_EXE) + ++check-pytests: kvno ++ $(RUNPYTEST) $(srcdir)/t_kvno.py $(PYTESTFLAGS) ++ + clean-unix:: + $(RM) kvno.o kvno + +diff --git a/src/clients/kvno/kvno.c b/src/clients/kvno/kvno.c +index 2472c0cfe..9d85864f6 100644 +--- a/src/clients/kvno/kvno.c ++++ b/src/clients/kvno/kvno.c +@@ -44,14 +44,17 @@ xusage() + fprintf(stderr, _("usage: %s [-C] [-u] [-c ccache] [-e etype]\n"), prog); + fprintf(stderr, _("\t[-k keytab] [-S sname] [{-I | -U} for_user | " + "[-F cert_file] [-P]]\n")); +- fprintf(stderr, _("\t[--u2u ccache] service1 service2 ...\n")); ++ fprintf(stderr, _("\t[--cached-only] [--no-store] [--out-cache ccache] " ++ "[--u2u ccache]\n")); ++ fprintf(stderr, _("\tservice1 service2 ...\n")); + exit(1); + } + + static void do_v5_kvno(int argc, char *argv[], char *ccachestr, char *etypestr, +- char *keytab_name, char *sname, int canon, int unknown, +- char *for_user, int for_user_enterprise, +- char *for_user_cert_file, int proxy, ++ char *keytab_name, char *sname, int cached_only, ++ int canon, int no_store, int unknown, char *for_user, ++ int for_user_enterprise, char *for_user_cert_file, ++ int proxy, const char *out_ccname, + const char *u2u_ccname); + + #include +@@ -61,18 +64,21 @@ static void extended_com_err_fn(const char *myprog, errcode_t code, + int + main(int argc, char *argv[]) + { +- enum { OPTION_U2U = 256 }; +- struct option lopts[] = { +- { "u2u", 1, NULL, OPTION_U2U }, +- { NULL, 0, NULL, 0 } +- }; ++ enum { OPTION_U2U = 256, OPTION_OUT_CACHE = 257 }; + const char *shopts = "uCc:e:hk:qPS:I:U:F:"; + int option; + char *etypestr = NULL, *ccachestr = NULL, *keytab_name = NULL; + char *sname = NULL, *for_user = NULL, *u2u_ccname = NULL; +- char *for_user_cert_file = NULL; ++ char *for_user_cert_file = NULL, *out_ccname = NULL; + int canon = 0, unknown = 0, proxy = 0, for_user_enterprise = 0; +- int impersonate = 0; ++ int impersonate = 0, cached_only = 0, no_store = 0; ++ struct option lopts[] = { ++ { "cached-only", 0, &cached_only, 1 }, ++ { "no-store", 0, &no_store, 1 }, ++ { "out-cache", 1, NULL, OPTION_OUT_CACHE }, ++ { "u2u", 1, NULL, OPTION_U2U }, ++ { NULL, 0, NULL, 0 } ++ }; + + setlocale(LC_ALL, ""); + set_com_err_hook(extended_com_err_fn); +@@ -135,6 +141,12 @@ main(int argc, char *argv[]) + case OPTION_U2U: + u2u_ccname = optarg; + break; ++ case OPTION_OUT_CACHE: ++ out_ccname = optarg; ++ break; ++ case 0: ++ /* If this option set a flag, do nothing else now. */ ++ break; + default: + xusage(); + break; +@@ -159,8 +171,9 @@ main(int argc, char *argv[]) + xusage(); + + do_v5_kvno(argc - optind, argv + optind, ccachestr, etypestr, keytab_name, +- sname, canon, unknown, for_user, for_user_enterprise, +- for_user_cert_file, proxy, u2u_ccname); ++ sname, cached_only, canon, no_store, unknown, for_user, ++ for_user_enterprise, for_user_cert_file, proxy, out_ccname, ++ u2u_ccname); + return 0; + } + +@@ -274,14 +287,16 @@ static krb5_error_code + kvno(const char *name, krb5_ccache ccache, krb5_principal me, + krb5_enctype etype, krb5_keytab keytab, const char *sname, + krb5_flags options, int unknown, krb5_principal for_user_princ, +- krb5_data *for_user_cert, int proxy, krb5_data *u2u_ticket) ++ krb5_data *for_user_cert, int proxy, krb5_data *u2u_ticket, ++ krb5_creds **creds_out) + { + krb5_error_code ret; + krb5_principal server = NULL; + krb5_ticket *ticket = NULL; +- krb5_creds in_creds, *out_creds = NULL; ++ krb5_creds in_creds, *creds = NULL; + char *princ = NULL; + ++ *creds_out = NULL; + memset(&in_creds, 0, sizeof(in_creds)); + + if (sname != NULL) { +@@ -321,13 +336,12 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, + in_creds.client = for_user_princ; + in_creds.server = me; + ret = krb5_get_credentials_for_user(context, options, ccache, +- &in_creds, for_user_cert, +- &out_creds); ++ &in_creds, for_user_cert, &creds); + } else { + in_creds.client = me; + in_creds.server = server; + ret = krb5_get_credentials(context, options, ccache, &in_creds, +- &out_creds); ++ &creds); + } + + if (ret) { +@@ -336,7 +350,7 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, + } + + /* We need a native ticket. */ +- ret = krb5_decode_ticket(&out_creds->ticket, &ticket); ++ ret = krb5_decode_ticket(&creds->ticket, &ticket); + if (ret) { + com_err(prog, ret, _("while decoding ticket for %s"), princ); + goto cleanup; +@@ -362,15 +376,15 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, + } + + if (proxy) { +- in_creds.client = out_creds->client; +- out_creds->client = NULL; +- krb5_free_creds(context, out_creds); +- out_creds = NULL; ++ in_creds.client = creds->client; ++ creds->client = NULL; ++ krb5_free_creds(context, creds); ++ creds = NULL; + in_creds.server = server; + + ret = krb5_get_credentials_for_proxy(context, KRB5_GC_CANONICALIZE, + ccache, &in_creds, ticket, +- &out_creds); ++ &creds); + krb5_free_principal(context, in_creds.client); + if (ret) { + com_err(prog, ret, _("%s: constrained delegation failed"), +@@ -379,10 +393,13 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, + } + } + ++ *creds_out = creds; ++ creds = NULL; ++ + cleanup: + krb5_free_principal(context, server); + krb5_free_ticket(context, ticket); +- krb5_free_creds(context, out_creds); ++ krb5_free_creds(context, creds); + krb5_free_unparsed_name(context, princ); + return ret; + } +@@ -428,19 +445,28 @@ cleanup: + + static void + do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, +- char *keytab_name, char *sname, int canon, int unknown, +- char *for_user, int for_user_enterprise, +- char *for_user_cert_file, int proxy, const char *u2u_ccname) ++ char *keytab_name, char *sname, int cached_only, int canon, ++ int no_store, int unknown, char *for_user, int for_user_enterprise, ++ char *for_user_cert_file, int proxy, const char *out_ccname, ++ const char *u2u_ccname) + { + krb5_error_code ret; +- int i, errors, flags; ++ int i, errors, flags, initialized = 0; + krb5_enctype etype; +- krb5_ccache ccache; ++ krb5_ccache ccache, out_ccache = NULL; + krb5_principal me; + krb5_keytab keytab = NULL; + krb5_principal for_user_princ = NULL; +- krb5_flags options = canon ? KRB5_GC_CANONICALIZE : 0; ++ krb5_flags options = 0; + krb5_data cert_data = empty_data(), *user_cert = NULL, *u2u_ticket = NULL; ++ krb5_creds *creds; ++ ++ if (canon) ++ options |= KRB5_GC_CANONICALIZE; ++ if (cached_only) ++ options |= KRB5_GC_CACHED; ++ if (no_store || out_ccname != NULL) ++ options |= KRB5_GC_NO_STORE; + + ret = krb5_init_context(&context); + if (ret) { +@@ -467,6 +493,14 @@ do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, + exit(1); + } + ++ if (out_ccname != NULL) { ++ ret = krb5_cc_resolve(context, out_ccname, &out_ccache); ++ if (ret) { ++ com_err(prog, ret, _("while resolving output ccache")); ++ exit(1); ++ } ++ } ++ + if (keytab_name != NULL) { + ret = krb5_kt_resolve(context, keytab_name, &keytab); + if (ret) { +@@ -513,8 +547,25 @@ do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, + errors = 0; + for (i = 0; i < count; i++) { + if (kvno(names[i], ccache, me, etype, keytab, sname, options, unknown, +- for_user_princ, user_cert, proxy, u2u_ticket) != 0) ++ for_user_princ, user_cert, proxy, u2u_ticket, &creds) != 0) { + errors++; ++ } else if (out_ccache != NULL) { ++ if (!initialized) { ++ ret = krb5_cc_initialize(context, out_ccache, creds->client); ++ if (ret) { ++ com_err(prog, ret, _("while initializing output ccache")); ++ exit(1); ++ } ++ initialized = 1; ++ } ++ ret = krb5_cc_store_cred(context, out_ccache, creds); ++ if (ret) { ++ com_err(prog, ret, _("while storing creds in output ccache")); ++ exit(1); ++ } ++ } ++ ++ krb5_free_creds(context, creds); + } + + if (keytab != NULL) +diff --git a/src/clients/kvno/t_kvno.py b/src/clients/kvno/t_kvno.py +new file mode 100644 +index 000000000..e98b90e8a +--- /dev/null ++++ b/src/clients/kvno/t_kvno.py +@@ -0,0 +1,75 @@ ++from k5test import * ++ ++realm = K5Realm() ++ ++def check_cache(ccache, expected_services): ++ # Fetch the klist output and skip past the header. ++ lines = realm.run([klist, '-c', ccache]).splitlines() ++ lines = lines[4:] ++ ++ # For each line not beginning with an indent, match against the ++ # expected service principals. ++ svcs = {x: True for x in expected_services} ++ for l in lines: ++ if not l.startswith('\t'): ++ svcprinc = l.split()[4] ++ if svcprinc in svcs: ++ del svcs[svcprinc] ++ else: ++ fail('unexpected service princ ' + svcprinc) ++ ++ if svcs: ++ fail('services not found in klist output: ' + ' '.join(svcs.keys())) ++ ++ ++mark('no options') ++realm.run([kvno, realm.user_princ], expected_msg='user@KRBTEST.COM: kvno = 1') ++check_cache(realm.ccache, [realm.krbtgt_princ, realm.user_princ]) ++ ++mark('-e') ++msgs = ('etypes requested in TGS request: camellia128-cts', ++ '/KDC has no support for encryption type') ++realm.run([kvno, '-e', 'camellia128-cts', realm.host_princ], ++ expected_code=1, expected_trace=msgs) ++ ++mark('--cached-only') ++realm.run([kvno, '--cached-only', realm.user_princ], expected_msg='kvno = 1') ++realm.run([kvno, '--cached-only', realm.host_princ], ++ expected_code=1, expected_msg='Matching credential not found') ++check_cache(realm.ccache, [realm.krbtgt_princ, realm.user_princ]) ++ ++mark('--no-store') ++realm.run([kvno, '--no-store', realm.host_princ], expected_msg='kvno = 1') ++check_cache(realm.ccache, [realm.krbtgt_princ, realm.user_princ]) ++ ++mark('--out-cache') # and multiple services ++out_ccache = os.path.join(realm.testdir, 'ccache.out') ++realm.run([kvno, '--out-cache', out_ccache, ++ realm.host_princ, realm.admin_princ]) ++check_cache(realm.ccache, [realm.krbtgt_princ, realm.user_princ]) ++check_cache(out_ccache, [realm.host_princ, realm.admin_princ]) ++ ++mark('--out-cache --cached-only') # tests out-cache overwriting, and -q ++realm.run([kvno, '--out-cache', out_ccache, '--cached-only', realm.host_princ], ++ expected_code=1, expected_msg='Matching credential not found') ++out = realm.run([kvno, '-q', '--out-cache', out_ccache, '--cached-only', ++ realm.user_princ]) ++if out: ++ fail('unexpected kvno output with -q') ++check_cache(out_ccache, [realm.user_princ]) ++ ++mark('-U') # and -c ++svc_ccache = os.path.join(realm.testdir, 'ccache.svc') ++realm.run([kinit, '-k', '-c', svc_ccache, realm.host_princ]) ++realm.run([kvno, '-c', svc_ccache, '-U', 'user', realm.host_princ]) ++realm.run([klist, '-c', svc_ccache], expected_msg='for client user@') ++realm.run([kvno, '-c', svc_ccache, '-U', 'user', '--out-cache', out_ccache, ++ realm.host_princ]) ++out = realm.run([klist, '-c', out_ccache]) ++if ('Default principal: user@KRBTEST.COM' not in out): ++ fail('wrong default principal in klist output') ++ ++# More S4U options are tested in tests/gssapi/t_s4u.py. ++# --u2u is tested in tests/t_u2u.py. ++ ++success('kvno tests') +diff --git a/src/man/kvno.man b/src/man/kvno.man +index 005a2ec97..b9f6739eb 100644 +--- a/src/man/kvno.man ++++ b/src/man/kvno.man +@@ -95,6 +95,19 @@ Specifies that protocol transition is to be used, identifying the + client principal with the X.509 certificate in \fIcert_file\fP\&. The + certificate file must be in PEM format. + .TP ++\fB\-\-cached\-only\fP ++Only retrieve credentials already present in the cache, not from ++the KDC. ++.TP ++\fB\-\-no\-store\fP ++Do not store retrieved credentials in the cache. If ++\fB\-\-out\-cache\fP is also specified, credentials will still be ++stored into the output credential cache. ++.TP ++\fB\-\-out\-cache\fP \fIccache\fP ++Initialize \fIccache\fP and store all retrieved credentials into it. ++Do not store acquired credentials in the input cache. ++.TP + \fB\-\-u2u\fP \fIccache\fP + Requests a user\-to\-user ticket. \fIccache\fP must contain a local + krbtgt ticket for the server principal. The reported version diff --git a/Unify-kvno-option-documentation.patch b/Unify-kvno-option-documentation.patch new file mode 100644 index 0000000..b6f5e01 --- /dev/null +++ b/Unify-kvno-option-documentation.patch @@ -0,0 +1,185 @@ +From 52e3695cc5ef00766e12adfe8ed276c2885e71bb Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 20 Aug 2020 17:49:29 -0400 +Subject: [PATCH] Unify kvno option documentation + +Add missing kvno options to the kvno.rst synopsis and option +descriptions, and to the kvno usage message. Remove mention of '-h' +(help text), from kvno.rst as it is an implicit option. Note that the +three new caching options were added in release 1.19. + +Indicate the two exclusions (-u/-S and --u2u with the S4U2Self options) +and dependency (-P on S4U2Self) where they are missing. + +Switch xusage() to print only a single localized string, rather than +running each line of output through localization separately. + +Leave kvno -C undocumented for now, as the semantics of +KRB5_GC_CANONICALIZE are minimally useful and likely to change. + +[ghudson@mit.edu: edited documentation and commit message] + +ticket: 7476 +tags: pullup +target_version: 1.18-next + +(cherry picked from commit becd1ad6830b526d08ddaf5b2b6f213154c6446c) +--- + doc/user/user_commands/kvno.rst | 24 +++++++++++++----------- + src/clients/kvno/kvno.c | 15 +++++++++------ + src/man/kvno.man | 24 +++++++++++++----------- + 3 files changed, 35 insertions(+), 28 deletions(-) + +diff --git a/doc/user/user_commands/kvno.rst b/doc/user/user_commands/kvno.rst +index 718313576..65c44e1c0 100644 +--- a/doc/user/user_commands/kvno.rst ++++ b/doc/user/user_commands/kvno.rst +@@ -10,13 +10,9 @@ SYNOPSIS + [**-c** *ccache*] + [**-e** *etype*] + [**-q**] +-[**-h**] ++[**-u** | **-S** *sname*] + [**-P**] +-[**-S** *sname*] +-[**-I** *for_user*] +-[**-U** *for_user*] +-[**-F** *cert_file*] +-[**--u2u** *ccache*] ++[[{**-F** *cert_file* | {**-I** | **-U**} *for_user*} [**-P**]] | **--u2u** *ccache*] + *service1 service2* ... + + +@@ -39,13 +35,18 @@ OPTIONS + of all the services named on the command line. This is useful in + certain backward compatibility situations. + ++**-k** *keytab* ++ Decrypt the acquired tickets using *keytab* to confirm their ++ validity. ++ + **-q** + Suppress printing output when successful. If a service ticket + cannot be obtained, an error message will still be printed and + kvno will exit with nonzero status. + +-**-h** +- Prints a usage statement and exits. ++**-u** ++ Use the unknown name type in requested service principal names. ++ This option Cannot be used with *-S*. + + **-P** + Specifies that the *service1 service2* ... arguments are to be +@@ -76,16 +77,17 @@ OPTIONS + + **--cached-only** + Only retrieve credentials already present in the cache, not from +- the KDC. ++ the KDC. (Added in release 1.19.) + + **--no-store** + Do not store retrieved credentials in the cache. If + **--out-cache** is also specified, credentials will still be +- stored into the output credential cache. ++ stored into the output credential cache. (Added in release 1.19.) + + **--out-cache** *ccache* + Initialize *ccache* and store all retrieved credentials into it. +- Do not store acquired credentials in the input cache. ++ Do not store acquired credentials in the input cache. (Added in ++ release 1.19.) + + **--u2u** *ccache* + Requests a user-to-user ticket. *ccache* must contain a local +diff --git a/src/clients/kvno/kvno.c b/src/clients/kvno/kvno.c +index 9d85864f6..c5f6bf700 100644 +--- a/src/clients/kvno/kvno.c ++++ b/src/clients/kvno/kvno.c +@@ -38,15 +38,18 @@ + static char *prog; + static int quiet = 0; + ++#define XUSAGE_BREAK "\n\t" ++ + static void + xusage() + { +- fprintf(stderr, _("usage: %s [-C] [-u] [-c ccache] [-e etype]\n"), prog); +- fprintf(stderr, _("\t[-k keytab] [-S sname] [{-I | -U} for_user | " +- "[-F cert_file] [-P]]\n")); +- fprintf(stderr, _("\t[--cached-only] [--no-store] [--out-cache ccache] " +- "[--u2u ccache]\n")); +- fprintf(stderr, _("\tservice1 service2 ...\n")); ++ fprintf(stderr, _("usage: %s [-c ccache] [-e etype] [-k keytab] [-q] " ++ "[-u | -S sname]" XUSAGE_BREAK ++ "[[{-F cert_file | {-I | -U} for_user} [-P]] | " ++ "--u2u ccache]" XUSAGE_BREAK ++ "[--cached-only] [--no-store] [--out-cache] " ++ "service1 service2 ...\n"), ++ prog); + exit(1); + } + +diff --git a/src/man/kvno.man b/src/man/kvno.man +index b9f6739eb..22318324d 100644 +--- a/src/man/kvno.man ++++ b/src/man/kvno.man +@@ -36,13 +36,9 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]] + [\fB\-c\fP \fIccache\fP] + [\fB\-e\fP \fIetype\fP] + [\fB\-q\fP] +-[\fB\-h\fP] ++[\fB\-u\fP | \fB\-S\fP \fIsname\fP] + [\fB\-P\fP] +-[\fB\-S\fP \fIsname\fP] +-[\fB\-I\fP \fIfor_user\fP] +-[\fB\-U\fP \fIfor_user\fP] +-[\fB\-F\fP \fIcert_file\fP] +-[\fB\-\-u2u\fP \fIccache\fP] ++[[{\fB\-F\fP \fIcert_file\fP | {\fB\-I\fP | \fB\-U\fP} \fIfor_user\fP} [\fB\-P\fP]] | \fB\-\-u2u\fP \fIccache\fP] + \fIservice1 service2\fP ... + .SH DESCRIPTION + .sp +@@ -60,13 +56,18 @@ Specifies the enctype which will be requested for the session key + of all the services named on the command line. This is useful in + certain backward compatibility situations. + .TP ++\fB\-k\fP \fIkeytab\fP ++Decrypt the acquired tickets using \fIkeytab\fP to confirm their ++validity. ++.TP + \fB\-q\fP + Suppress printing output when successful. If a service ticket + cannot be obtained, an error message will still be printed and + kvno will exit with nonzero status. + .TP +-\fB\-h\fP +-Prints a usage statement and exits. ++\fB\-u\fP ++Use the unknown name type in requested service principal names. ++This option Cannot be used with \fI\-S\fP\&. + .TP + \fB\-P\fP + Specifies that the \fIservice1 service2\fP ... arguments are to be +@@ -97,16 +98,17 @@ certificate file must be in PEM format. + .TP + \fB\-\-cached\-only\fP + Only retrieve credentials already present in the cache, not from +-the KDC. ++the KDC. (Added in release 1.19.) + .TP + \fB\-\-no\-store\fP + Do not store retrieved credentials in the cache. If + \fB\-\-out\-cache\fP is also specified, credentials will still be +-stored into the output credential cache. ++stored into the output credential cache. (Added in release 1.19.) + .TP + \fB\-\-out\-cache\fP \fIccache\fP + Initialize \fIccache\fP and store all retrieved credentials into it. +-Do not store acquired credentials in the input cache. ++Do not store acquired credentials in the input cache. (Added in ++release 1.19.) + .TP + \fB\-\-u2u\fP \fIccache\fP + Requests a user\-to\-user ticket. \fIccache\fP must contain a local diff --git a/krb5.spec b/krb5.spec index 8f389f4..63c329b 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 24%{?dist} +Release: 25%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -72,6 +72,8 @@ Patch33: Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch Patch34: Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch Patch35: Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch Patch36: Fix-input-length-checking-in-SPNEGO-DER-decoding.patch +Patch37: Add-three-kvno-options-from-Heimdal-kgetcred.patch +Patch38: Unify-kvno-option-documentation.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -633,6 +635,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Oct 15 2020 Robbie Harwood - 1.18.2-25 +- Unify kvno option documentation + * Fri Oct 02 2020 Robbie Harwood - 1.18.2-24 - Add md5 override to krad From da77b5dcf895220ddab32b41a1060f0db598ecff Mon Sep 17 00:00:00 2001 From: Tomas Mraz Date: Mon, 19 Oct 2020 11:25:53 +0200 Subject: [PATCH 197/304] Drop unnecessary conflict with openssl-libs >= 3.0.0 The requirement unnecessarily prevents temporary coexistence of krb5-libs with new openssl library where the old openssl library is coming from openssl1.1 compat package. --- krb5.spec | 1 - 1 file changed, 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 63c329b..42d0e0f 100644 --- a/krb5.spec +++ b/krb5.spec @@ -129,7 +129,6 @@ to install this package. %package libs Summary: The non-admin shared libraries used by Kerberos 5 Requires: openssl-libs >= 1:1.1.1d-4 -Requires: openssl-libs < 1:3.0.0 Requires: coreutils, gawk, grep, sed Requires: keyutils-libs >= 1.5.8 Requires: /etc/crypto-policies/back-ends/krb5.config From 7c8b50fca590f640747ce2a39d57c2ebb4376e7a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 21 Oct 2020 11:24:24 -0400 Subject: [PATCH 198/304] Cross-realm s4u fixes for samba (#1836630) --- ...t-KDC-alias-helper-function-contract.patch | 80 +++++ ...ases-when-matching-U2U-second-ticket.patch | 65 ++++ ...-KDC-alias-checking-for-S4U-requests.patch | 124 +++++++ Minimize-usage-of-tgs_server-in-KDC.patch | 316 +++++++++++++++++ ...KDC-authdata-list-management-helpers.patch | 335 ++++++++++++++++++ krb5.spec | 10 +- 6 files changed, 929 insertions(+), 1 deletion(-) create mode 100644 Adjust-KDC-alias-helper-function-contract.patch create mode 100644 Allow-aliases-when-matching-U2U-second-ticket.patch create mode 100644 Improve-KDC-alias-checking-for-S4U-requests.patch create mode 100644 Minimize-usage-of-tgs_server-in-KDC.patch create mode 100644 Refactor-KDC-authdata-list-management-helpers.patch diff --git a/Adjust-KDC-alias-helper-function-contract.patch b/Adjust-KDC-alias-helper-function-contract.patch new file mode 100644 index 0000000..7b7c62b --- /dev/null +++ b/Adjust-KDC-alias-helper-function-contract.patch @@ -0,0 +1,80 @@ +From 758f5031fe9d6c1e3eb33818bc6d57cf8b4a3a72 Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Tue, 22 Sep 2020 01:11:39 +0300 +Subject: [PATCH] Adjust KDC alias helper function contract + +Change the name of is_client_alias() to is_client_db_alias(), and +change the contract so that the already-canonical principal name comes +from a DB entry (which is less flexible, but clearer since DB entries +always contain canonical principal names). Make the function +available outside of kdc_util.c. + +[ghudson@mit.edu: clarified commit message] + +(cherry picked from commit 9fb5f572dd6ce808b234cb60a573eac48136d7ca) +--- + src/kdc/kdc_util.c | 14 +++++++------- + src/kdc/kdc_util.h | 4 ++++ + 2 files changed, 11 insertions(+), 7 deletions(-) + +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index dcb2df8dc..6330387d0 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1463,10 +1463,10 @@ cleanup: + return code; + } + +-/* Return true if princ canonicalizes to the same principal as canon. */ +-static krb5_boolean +-is_client_alias(krb5_context context, krb5_const_principal canon, +- krb5_const_principal princ) ++/* Return true if princ canonicalizes to the same principal as entry's. */ ++krb5_boolean ++is_client_db_alias(krb5_context context, const krb5_db_entry *entry, ++ krb5_const_principal princ) + { + krb5_error_code ret; + krb5_db_entry *self; +@@ -1475,7 +1475,7 @@ is_client_alias(krb5_context context, krb5_const_principal canon, + ret = krb5_db_get_principal(context, princ, + KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY, &self); + if (!ret) { +- is_self = krb5_principal_compare(context, canon, self->princ); ++ is_self = krb5_principal_compare(context, entry->princ, self->princ); + krb5_db_free_principal(context, self); + } + +@@ -1535,7 +1535,7 @@ kdc_process_s4u2self_req(kdc_realm_t *kdc_active_realm, + + /* If the server is local, check that the request is for self. */ + if (!isflagset(c_flags, KRB5_KDB_FLAG_ISSUING_REFERRAL) && +- !is_client_alias(kdc_context, server->princ, client_princ)) { ++ !is_client_db_alias(kdc_context, server, client_princ)) { + *status = "INVALID_S4U2SELF_REQUEST_SERVER_MISMATCH"; + return KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN; /* match Windows error */ + } +@@ -1728,7 +1728,7 @@ kdc_process_s4u2proxy_req(kdc_realm_t *kdc_active_realm, unsigned int flags, + } + + client_princ = *stkt_authdata_client; +- } else if (!is_client_alias(kdc_context, server->princ, server_princ)) { ++ } else if (!is_client_db_alias(kdc_context, server, server_princ)) { + *status = "EVIDENCE_TICKET_MISMATCH"; + return KRB5KDC_ERR_SERVER_NOMATCH; + } +diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h +index 384b21ad2..2c9d8cf69 100644 +--- a/src/kdc/kdc_util.h ++++ b/src/kdc/kdc_util.h +@@ -344,6 +344,10 @@ log_tgs_badtrans(krb5_context ctx, krb5_principal cprinc, + void + log_tgs_alt_tgt(krb5_context context, krb5_principal p); + ++krb5_boolean ++is_client_db_alias(krb5_context context, const krb5_db_entry *entry, ++ krb5_const_principal princ); ++ + /* FAST*/ + enum krb5_fast_kdc_flags { + KRB5_FAST_REPLY_KEY_USED = 0x1, diff --git a/Allow-aliases-when-matching-U2U-second-ticket.patch b/Allow-aliases-when-matching-U2U-second-ticket.patch new file mode 100644 index 0000000..8622ff8 --- /dev/null +++ b/Allow-aliases-when-matching-U2U-second-ticket.patch @@ -0,0 +1,65 @@ +From ccc5b9663e229f20421c01836aa5ecb06f1f2a48 Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Tue, 22 Sep 2020 01:17:11 +0300 +Subject: [PATCH] Allow aliases when matching U2U second ticket + +In process_tgs_req() when verifying the user-to-user second ticket, +compare the canonical names of the request server and the second +ticket client. + +[ghudson@mit.edu: expanded commit message; trimmed tests] + +ticket: 8951 (new) +(cherry picked from commit afc494ef9418e6be7fbb887364efa6606b10034a) +--- + src/kdc/do_tgs_req.c | 2 +- + src/tests/t_u2u.py | 25 +++++++++++++++++++++++++ + 2 files changed, 26 insertions(+), 1 deletion(-) + +diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c +index 463a9c0dd..74cd19e96 100644 +--- a/src/kdc/do_tgs_req.c ++++ b/src/kdc/do_tgs_req.c +@@ -666,7 +666,7 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, + */ + krb5_enc_tkt_part *t2enc = request->second_ticket[st_idx]->enc_part2; + krb5_principal client2 = t2enc->client; +- if (!krb5_principal_compare(kdc_context, request->server, client2)) { ++ if (!is_client_db_alias(kdc_context, server, client2)) { + altcprinc = client2; + errcode = KRB5KDC_ERR_SERVER_NOMATCH; + status = "2ND_TKT_MISMATCH"; +diff --git a/src/tests/t_u2u.py b/src/tests/t_u2u.py +index 1ca6ac87e..4b8a82a2f 100644 +--- a/src/tests/t_u2u.py ++++ b/src/tests/t_u2u.py +@@ -32,4 +32,29 @@ realm.run([kvno, '--u2u', realm.ccache, realm.user_princ]) + + realm.run([klist]) + ++realm.stop() ++ ++# Load the test KDB module to test aliases ++testprincs = {'krbtgt/KRBTEST.COM': {'keys': 'aes128-cts'}, ++ 'user': {'keys': 'aes128-cts', 'flags': '+preauth'}, ++ 'WIN10': {'keys': 'aes128-cts'}} ++kdcconf = {'realms': {'$realm': {'database_module': 'test'}}, ++ 'dbmodules': {'test': {'db_library': 'test', ++ 'princs': testprincs, ++ 'alias': {'HOST/win10': 'WIN10'}}}} ++ ++realm = K5Realm(kdc_conf=kdcconf, create_kdb=False) ++realm.start_kdc() ++ ++# Create a second user principal and get tickets for it. ++u2u_ccache = 'FILE:' + os.path.join(realm.testdir, 'ccu2u') ++realm.extract_keytab('WIN10', realm.keytab) ++realm.kinit('WIN10', None, ['-k', '-c', u2u_ccache]) ++ ++realm.extract_keytab(realm.user_princ, realm.keytab) ++realm.kinit(realm.user_princ, None, ['-k']) ++ ++realm.run([kvno, '--u2u', u2u_ccache, 'HOST/win10'], expected_msg='kvno = 0') ++realm.run([kvno, '--u2u', u2u_ccache, 'WIN10'], expected_msg='kvno = 0') ++ + success('user-to-user tests') diff --git a/Improve-KDC-alias-checking-for-S4U-requests.patch b/Improve-KDC-alias-checking-for-S4U-requests.patch new file mode 100644 index 0000000..3dbb119 --- /dev/null +++ b/Improve-KDC-alias-checking-for-S4U-requests.patch @@ -0,0 +1,124 @@ +From ed87237cdd70f72b309960a294a2bed26cef1579 Mon Sep 17 00:00:00 2001 +From: Isaac Boukris +Date: Fri, 4 Sep 2020 14:05:50 +0300 +Subject: [PATCH] Improve KDC alias checking for S4U requests + +When processing an S4U2Self request, check for DB aliases when +matching the TGT client against the request server. When processing +an S4U2Proxy request, check for DB aliases when matching the TGT +client against the evidence ticket server. + +[ghudson@mit.edu: minor edits; rewrote commit message] + +ticket: 8946 (new) +(cherry picked from commit 05deeebfc096970b5d9aa67a48b14106cf1b9b56) +--- + src/kdc/kdc_util.c | 74 ++++++++++++++++------------------------------ + 1 file changed, 25 insertions(+), 49 deletions(-) + +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index e3352f9cc..dcb2df8dc 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1463,6 +1463,25 @@ cleanup: + return code; + } + ++/* Return true if princ canonicalizes to the same principal as canon. */ ++static krb5_boolean ++is_client_alias(krb5_context context, krb5_const_principal canon, ++ krb5_const_principal princ) ++{ ++ krb5_error_code ret; ++ krb5_db_entry *self; ++ krb5_boolean is_self = FALSE; ++ ++ ret = krb5_db_get_principal(context, princ, ++ KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY, &self); ++ if (!ret) { ++ is_self = krb5_principal_compare(context, canon, self->princ); ++ krb5_db_free_principal(context, self); ++ } ++ ++ return is_self; ++} ++ + /* + * Protocol transition (S4U2Self) + */ +@@ -1481,7 +1500,6 @@ kdc_process_s4u2self_req(kdc_realm_t *kdc_active_realm, + { + krb5_error_code code; + krb5_pa_data *pa_data; +- int flags; + krb5_db_entry *princ; + krb5_s4u_userid *id; + +@@ -1515,51 +1533,11 @@ kdc_process_s4u2self_req(kdc_realm_t *kdc_active_realm, + } + id = &(*s4u_x509_user)->user_id; + +- /* +- * We need to compare the client name in the TGT with the requested +- * server name. Supporting server name aliases without assuming a +- * global name service makes this difficult to do. +- * +- * The comparison below handles the following cases (note that the +- * term "principal name" below excludes the realm). +- * +- * (1) The requested service is a host-based service with two name +- * components, in which case we assume the principal name to +- * contain sufficient qualifying information. The realm is +- * ignored for the purpose of comparison. +- * +- * (2) The requested service name is an enterprise principal name: +- * the service principal name is compared with the unparsed +- * form of the client name (including its realm). +- * +- * (3) The requested service is some other name type: an exact +- * match is required. +- * +- * An alternative would be to look up the server once again with +- * FLAG_CANONICALIZE | FLAG_CLIENT_REFERRALS_ONLY set, do an exact +- * match between the returned name and client_princ. However, this +- * assumes that the client set FLAG_CANONICALIZE when requesting +- * the TGT and that we have a global name service. +- */ +- flags = 0; +- switch (krb5_princ_type(kdc_context, request->server)) { +- case KRB5_NT_SRV_HST: /* (1) */ +- if (krb5_princ_size(kdc_context, request->server) == 2) +- flags |= KRB5_PRINCIPAL_COMPARE_IGNORE_REALM; +- break; +- case KRB5_NT_ENTERPRISE_PRINCIPAL: /* (2) */ +- flags |= KRB5_PRINCIPAL_COMPARE_ENTERPRISE; +- break; +- default: /* (3) */ +- break; +- } +- +- if (!krb5_principal_compare_flags(kdc_context, +- request->server, +- client_princ, +- flags)) { +- *status = "INVALID_S4U2SELF_REQUEST"; +- return KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN; /* match Windows error code */ ++ /* If the server is local, check that the request is for self. */ ++ if (!isflagset(c_flags, KRB5_KDB_FLAG_ISSUING_REFERRAL) && ++ !is_client_alias(kdc_context, server->princ, client_princ)) { ++ *status = "INVALID_S4U2SELF_REQUEST_SERVER_MISMATCH"; ++ return KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN; /* match Windows error */ + } + + /* +@@ -1750,9 +1728,7 @@ kdc_process_s4u2proxy_req(kdc_realm_t *kdc_active_realm, unsigned int flags, + } + + client_princ = *stkt_authdata_client; +- } else if (!krb5_principal_compare(kdc_context, +- server->princ, /* after canon */ +- server_princ)) { ++ } else if (!is_client_alias(kdc_context, server->princ, server_princ)) { + *status = "EVIDENCE_TICKET_MISMATCH"; + return KRB5KDC_ERR_SERVER_NOMATCH; + } diff --git a/Minimize-usage-of-tgs_server-in-KDC.patch b/Minimize-usage-of-tgs_server-in-KDC.patch new file mode 100644 index 0000000..7a2a031 --- /dev/null +++ b/Minimize-usage-of-tgs_server-in-KDC.patch @@ -0,0 +1,316 @@ +From 604135b5ad6bf954491413243eb305b82fec1c06 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 25 Sep 2020 11:12:34 -0400 +Subject: [PATCH] Minimize usage of tgs_server in KDC + +Where possible, use the realm of the request server principal +(canonicalized via KDB lookup, if available) in preference to +tgs_server. This change facilitates alias realm support and potential +future support for serving multiple realms from the same KDB. + +S4U2Self local user testing currently uses the uncanonicalized request +realm after this change, which will require attention for alias realm +support. + +FAST armor ticket checking is unaffected by this change (it still +compares against tgs_server). This check poses no issue for realm +aliases, as both tgs_server and the armor ticket server should have +canonical realms, but it will require attention for multi-realm KDB +support. + +Remove is_local_principal() as it is no longer used. Add an +is_local_tgs_principal() helper and shorten is_cross_tgs_principal(). + +Move the header ticket lineage check from kdc_process_tgs_req() to +process_tgs_req(), where we have the canonical request server name and +a more natural indication of whether the request was an S4U2Self +request. + +(cherry picked from commit 90fedf8188fc47aa5a476a969af34671555df389) +--- + src/kdc/do_as_req.c | 21 ++++++-------- + src/kdc/do_tgs_req.c | 16 ++++++++--- + src/kdc/kdc_util.c | 68 ++++++++++---------------------------------- + src/kdc/kdc_util.h | 3 +- + src/kdc/tgs_policy.c | 16 ++++++----- + 5 files changed, 46 insertions(+), 78 deletions(-) + +diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c +index 9ae7b0a5e..e243f50be 100644 +--- a/src/kdc/do_as_req.c ++++ b/src/kdc/do_as_req.c +@@ -620,18 +620,6 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, + } + state->rock.client = state->client; + +- /* +- * If the backend returned a principal that is not in the local +- * realm, then we need to refer the client to that realm. +- */ +- if (!is_local_principal(kdc_active_realm, state->client->princ)) { +- /* Entry is a referral to another realm */ +- state->status = "REFERRAL"; +- au_state->cl_realm = &state->client->princ->realm; +- errcode = KRB5KDC_ERR_WRONG_REALM; +- goto errout; +- } +- + au_state->stage = SRVC_PRINC; + + s_flags = 0; +@@ -651,6 +639,15 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, + goto errout; + } + ++ /* If the KDB module returned a different realm for the client and server, ++ * we need to issue a client realm referral. */ ++ if (!data_eq(state->server->princ->realm, state->client->princ->realm)) { ++ state->status = "REFERRAL"; ++ au_state->cl_realm = &state->client->princ->realm; ++ errcode = KRB5KDC_ERR_WRONG_REALM; ++ goto errout; ++ } ++ + errcode = get_local_tgt(kdc_context, &state->request->server->realm, + state->server, &state->local_tgt, + &state->local_tgt_storage, &state->local_tgt_key); +diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c +index 74cd19e96..72525a462 100644 +--- a/src/kdc/do_tgs_req.c ++++ b/src/kdc/do_tgs_req.c +@@ -268,7 +268,7 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, + goto cleanup; + } + +- if (!is_local_principal(kdc_active_realm, header_ticket->server)) ++ if (!data_eq(header_server->princ->realm, sprinc->realm)) + setflag(c_flags, KRB5_KDB_FLAG_CROSS_REALM); + if (is_referral) + setflag(c_flags, KRB5_KDB_FLAG_ISSUING_REFERRAL); +@@ -295,6 +295,15 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, + au_state->s4u2self_user = NULL; + } + ++ /* Aside from cross-realm S4U2Self requests, do not accept header tickets ++ * for local users issued by foreign realms. */ ++ if (s4u_x509_user == NULL && data_eq(cprinc->realm, sprinc->realm) && ++ isflagset(c_flags, KRB5_KDB_FLAG_CROSS_REALM)) { ++ krb5_klog_syslog(LOG_INFO, _("PROCESS_TGS: failed lineage check")); ++ retval = KRB5KDC_ERR_POLICY; ++ goto cleanup; ++ } ++ + if (errcode) + goto cleanup; + +@@ -583,13 +592,12 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, + + /* + * Only add the realm of the presented tgt to the transited list if +- * it is different than the local realm (cross-realm) and it is different ++ * it is different than the server realm (cross-realm) and it is different + * than the realm of the client (since the realm of the client is already + * implicitly part of the transited list and should not be explicitly + * listed). + */ +- /* realm compare is like strcmp, but knows how to deal with these args */ +- if (krb5_realm_compare(kdc_context, header_ticket->server, tgs_server) || ++ if (!isflagset(c_flags, KRB5_KDB_FLAG_CROSS_REALM) || + krb5_realm_compare(kdc_context, header_ticket->server, + enc_tkt_reply.client)) { + /* tgt issued by local realm or issued by realm of client */ +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index a4a05b9fa..a631b498d 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -78,12 +78,6 @@ static krb5_error_code find_server_key(krb5_context, + krb5_kvno, krb5_keyblock **, + krb5_kvno *); + +-krb5_boolean +-is_local_principal(kdc_realm_t *kdc_active_realm, krb5_const_principal princ1) +-{ +- return krb5_realm_compare(kdc_context, princ1, tgs_server); +-} +- + /* + * Returns TRUE if the kerberos principal is the name of a Kerberos ticket + * service. +@@ -104,13 +98,16 @@ krb5_is_tgs_principal(krb5_const_principal principal) + krb5_boolean + is_cross_tgs_principal(krb5_const_principal principal) + { +- if (!krb5_is_tgs_principal(principal)) +- return FALSE; +- if (!data_eq(*krb5_princ_component(kdc_context, principal, 1), +- *krb5_princ_realm(kdc_context, principal))) +- return TRUE; +- else +- return FALSE; ++ return krb5_is_tgs_principal(principal) && ++ !data_eq(principal->data[1], principal->realm); ++} ++ ++/* Return true if princ is the name of a local TGS for any realm. */ ++krb5_boolean ++is_local_tgs_principal(krb5_const_principal principal) ++{ ++ return krb5_is_tgs_principal(principal) && ++ data_eq(principal->data[1], principal->realm); + } + + /* +@@ -143,17 +140,6 @@ comp_cksum(krb5_context kcontext, krb5_data *source, krb5_ticket *ticket, + return(0); + } + +-/* Return true if padata contains an entry of either S4U2Self type. */ +-static inline krb5_boolean +-has_s4u2self_padata(krb5_pa_data **padata) +-{ +- if (krb5int_find_pa_data(NULL, padata, KRB5_PADATA_FOR_USER) != NULL) +- return TRUE; +- if (krb5int_find_pa_data(NULL, padata, KRB5_PADATA_S4U_X509_USER) != NULL) +- return TRUE; +- return FALSE; +-} +- + /* If a header ticket is decrypted, *ticket_out is filled in even on error. */ + krb5_error_code + kdc_process_tgs_req(kdc_realm_t *kdc_active_realm, +@@ -170,7 +156,6 @@ kdc_process_tgs_req(kdc_realm_t *kdc_active_realm, + krb5_authdata **authdata = NULL; + krb5_data scratch1; + krb5_data * scratch = NULL; +- krb5_boolean foreign_server = FALSE; + krb5_auth_context auth_context = NULL; + krb5_authenticator * authenticator = NULL; + krb5_checksum * his_cksum = NULL; +@@ -199,19 +184,6 @@ kdc_process_tgs_req(kdc_realm_t *kdc_active_realm, + goto cleanup; + } + +- /* If the "server" principal in the ticket is not something +- in the local realm, then we must refuse to service the request +- if the client claims to be from the local realm. +- +- If we don't do this, then some other realm's nasty KDC can +- claim to be authenticating a client from our realm, and we'll +- give out tickets concurring with it! +- +- we set a flag here for checking below. +- */ +- foreign_server = !is_local_principal(kdc_active_realm, +- apreq->ticket->server); +- + if ((retval = krb5_auth_con_init(kdc_context, &auth_context))) + goto cleanup; + +@@ -265,15 +237,6 @@ kdc_process_tgs_req(kdc_realm_t *kdc_active_realm, + goto cleanup_authenticator; + } + +- /* make sure the client is of proper lineage (see above) */ +- if (foreign_server && !has_s4u2self_padata(request->padata) && +- is_local_principal(kdc_active_realm, ticket->enc_part2->client)) { +- /* someone in a foreign realm claiming to be local */ +- krb5_klog_syslog(LOG_INFO, _("PROCESS_TGS: failed lineage check")); +- retval = KRB5KDC_ERR_POLICY; +- goto cleanup_authenticator; +- } +- + /* + * Check application checksum vs. tgs request + * +@@ -591,12 +554,12 @@ int + check_anon(kdc_realm_t *kdc_active_realm, + krb5_principal client, krb5_principal server) + { +- /* If restrict_anon is set, reject requests from anonymous to principals +- * other than the local TGT. */ ++ /* If restrict_anon is set, reject requests from anonymous clients to ++ * server principals other than local TGTs. */ + if (kdc_active_realm->realm_restrict_anon && + krb5_principal_compare_any_realm(kdc_context, client, + krb5_anonymous_principal()) && +- !krb5_principal_compare(kdc_context, server, tgs_server)) ++ !is_local_tgs_principal(server)) + return -1; + return 0; + } +@@ -1527,7 +1490,7 @@ kdc_process_s4u2self_req(kdc_realm_t *kdc_active_realm, + /* + * Do not attempt to lookup principals in foreign realms. + */ +- if (is_local_principal(kdc_active_realm, id->user)) { ++ if (data_eq(server->princ->realm, id->user->realm)) { + krb5_db_entry no_server; + krb5_pa_data **e_data = NULL; + +@@ -1663,8 +1626,7 @@ kdc_process_s4u2proxy_req(kdc_realm_t *kdc_active_realm, unsigned int flags, + */ + if (isflagset(flags, KRB5_KDB_FLAG_ISSUING_REFERRAL) || + !is_cross_tgs_principal(server->princ) || +- !krb5_principal_compare_any_realm(kdc_context, server->princ, +- tgs_server) || ++ !data_eq(server->princ->data[1], proxy->princ->realm) || + !krb5_principal_compare(kdc_context, client_princ, server_princ)) { + *status = "XREALM_EVIDENCE_TICKET_MISMATCH"; + return KRB5KDC_ERR_BADOPTION; +diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h +index 42b7ee208..c730409ae 100644 +--- a/src/kdc/kdc_util.h ++++ b/src/kdc/kdc_util.h +@@ -37,10 +37,9 @@ + #include "reqstate.h" + + krb5_error_code check_hot_list (krb5_ticket *); +-krb5_boolean is_local_principal(kdc_realm_t *kdc_active_realm, +- krb5_const_principal princ1); + krb5_boolean krb5_is_tgs_principal (krb5_const_principal); + krb5_boolean is_cross_tgs_principal(krb5_const_principal); ++krb5_boolean is_local_tgs_principal(krb5_const_principal); + krb5_error_code + add_to_transited (krb5_data *, + krb5_data *, +diff --git a/src/kdc/tgs_policy.c b/src/kdc/tgs_policy.c +index 554345ba5..59d60ca25 100644 +--- a/src/kdc/tgs_policy.c ++++ b/src/kdc/tgs_policy.c +@@ -251,19 +251,21 @@ check_tgs_s4u2proxy(kdc_realm_t *kdc_active_realm, + } + + static int +-check_tgs_u2u(kdc_realm_t *kdc_active_realm, +- krb5_kdc_req *req, const char **status) ++check_tgs_u2u(kdc_realm_t *kdc_active_realm, krb5_kdc_req *req, ++ krb5_const_principal server_princ, const char **status) + { ++ krb5_const_principal second_server_princ; ++ + if (req->kdc_options & KDC_OPT_ENC_TKT_IN_SKEY) { + /* Check that second ticket is in request. */ + if (!req->second_ticket || !req->second_ticket[0]) { + *status = "NO_2ND_TKT"; + return KDC_ERR_BADOPTION; + } +- /* Check that second ticket is a TGT. */ +- if (!krb5_principal_compare(kdc_context, +- req->second_ticket[0]->server, +- tgs_server)) { ++ /* Check that second ticket is a TGT to the server realm. */ ++ second_server_princ = req->second_ticket[0]->server; ++ if (!is_local_tgs_principal(second_server_princ) || ++ !data_eq(second_server_princ->data[1], server_princ->realm)) { + *status = "2ND_TKT_NOT_TGS"; + return KDC_ERR_POLICY; + } +@@ -352,7 +354,7 @@ validate_tgs_request(kdc_realm_t *kdc_active_realm, + return(KRB_AP_ERR_REPEAT); + } + +- errcode = check_tgs_u2u(kdc_active_realm, request, status); ++ errcode = check_tgs_u2u(kdc_active_realm, request, server->princ, status); + if (errcode != 0) + return errcode; + diff --git a/Refactor-KDC-authdata-list-management-helpers.patch b/Refactor-KDC-authdata-list-management-helpers.patch new file mode 100644 index 0000000..00aed49 --- /dev/null +++ b/Refactor-KDC-authdata-list-management-helpers.patch @@ -0,0 +1,335 @@ +From 9335481c00cd15170adec244ccff0a00a014bbab Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 5 Feb 2020 18:46:11 -0500 +Subject: [PATCH] Refactor KDC authdata list management helpers + +Remove the unused concat_authorization_data(). Split merge_authdata() +into two helpers, one to destructively merge without filtering and one +to add copied elements while filtering out KDC-only authdata types. +Remove context parameters where they aren't needed (taking advantage +of knowledge that some libkrb5 functions don't use their context +parameters). + +(cherry picked from commit b2190fdc253de6024001e0f1ff9fe56c31042bb7) +--- + src/kdc/kdc_authdata.c | 138 +++++++++++++++++++---------------------- + src/kdc/kdc_util.c | 50 --------------- + src/kdc/kdc_util.h | 5 -- + 3 files changed, 64 insertions(+), 129 deletions(-) + +diff --git a/src/kdc/kdc_authdata.c b/src/kdc/kdc_authdata.c +index 1ebe87246..010922c27 100644 +--- a/src/kdc/kdc_authdata.c ++++ b/src/kdc/kdc_authdata.c +@@ -108,7 +108,7 @@ unload_authdata_plugins(krb5_context context) + /* Return true if authdata should be filtered when copying from untrusted + * authdata. If desired_type is non-zero, look only for that type. */ + static krb5_boolean +-is_kdc_issued_authdatum(krb5_context context, krb5_authdata *authdata, ++is_kdc_issued_authdatum(krb5_authdata *authdata, + krb5_authdatatype desired_type) + { + krb5_boolean result = FALSE; +@@ -117,7 +117,7 @@ is_kdc_issued_authdatum(krb5_context context, krb5_authdata *authdata, + krb5_authdatatype *ad_types, *containee_types = NULL; + + if (authdata->ad_type == KRB5_AUTHDATA_IF_RELEVANT) { +- if (krb5int_get_authdata_containee_types(context, authdata, &count, ++ if (krb5int_get_authdata_containee_types(NULL, authdata, &count, + &containee_types) != 0) + goto cleanup; + ad_types = containee_types; +@@ -152,7 +152,7 @@ cleanup: + /* Return true if authdata contains any elements which should only come from + * the KDC. If desired_type is non-zero, look only for that type. */ + static krb5_boolean +-has_kdc_issued_authdata(krb5_context context, krb5_authdata **authdata, ++has_kdc_issued_authdata(krb5_authdata **authdata, + krb5_authdatatype desired_type) + { + int i; +@@ -160,7 +160,7 @@ has_kdc_issued_authdata(krb5_context context, krb5_authdata **authdata, + if (authdata == NULL) + return FALSE; + for (i = 0; authdata[i] != NULL; i++) { +- if (is_kdc_issued_authdatum(context, authdata[i], desired_type)) ++ if (is_kdc_issued_authdatum(authdata[i], desired_type)) + return TRUE; + } + return FALSE; +@@ -181,66 +181,71 @@ has_mandatory_for_kdc_authdata(krb5_context context, krb5_authdata **authdata) + return FALSE; + } + +-/* +- * Add the elements of in_authdata to out_authdata. If copy is false, +- * in_authdata is invalid on successful return. If ignore_kdc_issued is true, +- * KDC-issued authdata is not copied. +- */ ++/* Add elements from *new_elements to *existing_list, reallocating as ++ * necessary. On success, release *new_elements and set it to NULL. */ + static krb5_error_code +-merge_authdata(krb5_context context, krb5_authdata **in_authdata, +- krb5_authdata ***out_authdata, krb5_boolean copy, +- krb5_boolean ignore_kdc_issued) ++merge_authdata(krb5_authdata ***existing_list, krb5_authdata ***new_elements) + { +- krb5_error_code ret; +- size_t i, j, nadata = 0; +- krb5_authdata **in_copy = NULL, **authdata = *out_authdata; ++ size_t count = 0, ncount = 0; ++ krb5_authdata **list = *existing_list, **nlist = *new_elements; + +- if (in_authdata == NULL || in_authdata[0] == NULL) ++ if (nlist == NULL) + return 0; + +- if (authdata != NULL) { +- for (nadata = 0; authdata[nadata] != NULL; nadata++) +- ; +- } ++ for (count = 0; list != NULL && list[count] != NULL; count++); ++ for (ncount = 0; nlist[ncount] != NULL; ncount++); + +- for (i = 0; in_authdata[i] != NULL; i++) +- ; +- +- if (copy) { +- ret = krb5_copy_authdata(context, in_authdata, &in_copy); +- if (ret) +- return ret; +- in_authdata = in_copy; +- } +- +- authdata = realloc(authdata, (nadata + i + 1) * sizeof(krb5_authdata *)); +- if (authdata == NULL) { +- krb5_free_authdata(context, in_copy); ++ list = realloc(list, (count + ncount + 1) * sizeof(*list)); ++ if (list == NULL) + return ENOMEM; ++ ++ memcpy(list + count, nlist, ncount * sizeof(*nlist)); ++ list[count + ncount] = NULL; ++ free(nlist); ++ ++ if (list[0] == NULL) { ++ free(list); ++ list = NULL; + } + +- for (i = 0, j = 0; in_authdata[i] != NULL; i++) { +- if (ignore_kdc_issued && +- is_kdc_issued_authdatum(context, in_authdata[i], 0)) { +- free(in_authdata[i]->contents); +- free(in_authdata[i]); ++ *new_elements = NULL; ++ *existing_list = list; ++ return 0; ++} ++ ++/* Add a copy of new_elements to *existing_list, omitting KDC-issued ++ * authdata. */ ++static krb5_error_code ++add_filtered_authdata(krb5_authdata ***existing_list, ++ krb5_authdata **new_elements) ++{ ++ krb5_error_code ret; ++ krb5_authdata **copy; ++ size_t i, j; ++ ++ if (new_elements == NULL) ++ return 0; ++ ++ ret = krb5_copy_authdata(NULL, new_elements, ©); ++ if (ret) ++ return ret; ++ ++ /* Remove KDC-issued elements from copy. */ ++ j = 0; ++ for (i = 0; copy[i] != NULL; i++) { ++ if (is_kdc_issued_authdatum(copy[i], 0)) { ++ free(copy[i]->contents); ++ free(copy[i]); + } else { +- authdata[nadata + j++] = in_authdata[i]; ++ copy[j++] = copy[i]; + } + } ++ copy[j] = NULL; + +- authdata[nadata + j] = NULL; +- +- free(in_authdata); +- +- if (authdata[0] == NULL) { +- free(authdata); +- authdata = NULL; +- } +- +- *out_authdata = authdata; +- +- return 0; ++ /* Destructively merge the filtered copy into existing_list. */ ++ ret = merge_authdata(existing_list, ©); ++ krb5_free_authdata(NULL, copy); ++ return ret; + } + + /* Copy TGS-REQ authorization data into the ticket authdata. */ +@@ -289,10 +294,7 @@ copy_request_authdata(krb5_context context, krb5_keyblock *client_key, + goto cleanup; + } + +- /* Add a copy of the requested authdata to the ticket, ignoring KDC-issued +- * types. */ +- ret = merge_authdata(context, req->unenc_authdata, tkt_authdata, TRUE, +- TRUE); ++ ret = add_filtered_authdata(tkt_authdata, req->unenc_authdata); + + cleanup: + free(plaintext.data); +@@ -307,9 +309,7 @@ copy_tgt_authdata(krb5_context context, krb5_kdc_req *request, + if (has_mandatory_for_kdc_authdata(context, tgt_authdata)) + return KRB5KDC_ERR_POLICY; + +- /* Add a copy of the TGT authdata to the ticket, ignoring KDC-issued +- * types. */ +- return merge_authdata(context, tgt_authdata, tkt_authdata, TRUE, TRUE); ++ return add_filtered_authdata(tkt_authdata, tgt_authdata); + } + + /* Fetch authorization data from KDB module. */ +@@ -374,8 +374,7 @@ fetch_kdb_authdata(krb5_context context, unsigned int flags, + + /* Put the KDB authdata first in the ticket. A successful merge places the + * combined list in db_authdata and releases the old ticket authdata. */ +- ret = merge_authdata(context, enc_tkt_reply->authorization_data, +- &db_authdata, FALSE, FALSE); ++ ret = merge_authdata(&db_authdata, &enc_tkt_reply->authorization_data); + if (ret) + krb5_free_authdata(context, db_authdata); + else +@@ -404,8 +403,7 @@ make_signedpath_data(krb5_context context, krb5_const_principal client, + return ret; + + for (i = 0, j = 0; authdata[i] != NULL; i++) { +- if (is_kdc_issued_authdatum(context, authdata[i], +- KRB5_AUTHDATA_SIGNTICKET)) ++ if (is_kdc_issued_authdatum(authdata[i], KRB5_AUTHDATA_SIGNTICKET)) + continue; + + sign_authdata[j++] = authdata[i]; +@@ -635,12 +633,8 @@ make_signedpath(krb5_context context, krb5_const_principal for_user_princ, + if (ret) + goto cleanup; + +- /* Add the authdata to the ticket, without copying or filtering. */ +- ret = merge_authdata(context, if_relevant, +- &enc_tkt_reply->authorization_data, FALSE, FALSE); +- if (ret) +- goto cleanup; +- if_relevant = NULL; /* merge_authdata() freed */ ++ /* Add the signedpath authdata to the ticket. */ ++ ret = merge_authdata(&enc_tkt_reply->authorization_data, &if_relevant); + + cleanup: + free(sp.delegated); +@@ -665,7 +659,7 @@ free_deleg_path(krb5_context context, krb5_principal *deleg_path) + static krb5_boolean + has_pac(krb5_context context, krb5_authdata **authdata) + { +- return has_kdc_issued_authdata(context, authdata, KRB5_AUTHDATA_WIN2K_PAC); ++ return has_kdc_issued_authdata(authdata, KRB5_AUTHDATA_WIN2K_PAC); + } + + /* Verify AD-SIGNTICKET authdata if we need to, and insert an AD-SIGNEDPATH +@@ -746,11 +740,7 @@ add_auth_indicators(krb5_context context, krb5_data *const *auth_indicators, + goto cleanup; + + /* Add the wrapped authdata to the ticket, without copying or filtering. */ +- ret = merge_authdata(context, cammac, &enc_tkt_reply->authorization_data, +- FALSE, FALSE); +- if (ret) +- goto cleanup; +- cammac = NULL; /* merge_authdata() freed */ ++ ret = merge_authdata(&enc_tkt_reply->authorization_data, &cammac); + + cleanup: + krb5_free_data(context, der_indicators); +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index 6330387d0..a4a05b9fa 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -78,56 +78,6 @@ static krb5_error_code find_server_key(krb5_context, + krb5_kvno, krb5_keyblock **, + krb5_kvno *); + +-/* +- * concatenate first two authdata arrays, returning an allocated replacement. +- * The replacement should be freed with krb5_free_authdata(). +- */ +-krb5_error_code +-concat_authorization_data(krb5_context context, +- krb5_authdata **first, krb5_authdata **second, +- krb5_authdata ***output) +-{ +- int i, j; +- krb5_authdata **ptr, **retdata; +- +- /* count up the entries */ +- i = 0; +- if (first) +- for (ptr = first; *ptr; ptr++) +- i++; +- if (second) +- for (ptr = second; *ptr; ptr++) +- i++; +- +- retdata = (krb5_authdata **)malloc((i+1)*sizeof(*retdata)); +- if (!retdata) +- return ENOMEM; +- retdata[i] = 0; /* null-terminated array */ +- for (i = 0, j = 0, ptr = first; j < 2 ; ptr = second, j++) +- while (ptr && *ptr) { +- /* now walk & copy */ +- retdata[i] = (krb5_authdata *)malloc(sizeof(*retdata[i])); +- if (!retdata[i]) { +- krb5_free_authdata(context, retdata); +- return ENOMEM; +- } +- *retdata[i] = **ptr; +- if (!(retdata[i]->contents = +- (krb5_octet *)malloc(retdata[i]->length))) { +- free(retdata[i]); +- retdata[i] = 0; +- krb5_free_authdata(context, retdata); +- return ENOMEM; +- } +- memcpy(retdata[i]->contents, (*ptr)->contents, retdata[i]->length); +- +- ptr++; +- i++; +- } +- *output = retdata; +- return 0; +-} +- + krb5_boolean + is_local_principal(kdc_realm_t *kdc_active_realm, krb5_const_principal princ1) + { +diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h +index 2c9d8cf69..42b7ee208 100644 +--- a/src/kdc/kdc_util.h ++++ b/src/kdc/kdc_util.h +@@ -52,11 +52,6 @@ compress_transited (krb5_data *, + krb5_principal, + krb5_data *); + krb5_error_code +-concat_authorization_data (krb5_context, +- krb5_authdata **, +- krb5_authdata **, +- krb5_authdata ***); +-krb5_error_code + fetch_last_req_info (krb5_db_entry *, krb5_last_req_entry ***); + + krb5_error_code diff --git a/krb5.spec b/krb5.spec index 42d0e0f..9cdd23b 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 25%{?dist} +Release: 26%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -74,6 +74,11 @@ Patch35: Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch Patch36: Fix-input-length-checking-in-SPNEGO-DER-decoding.patch Patch37: Add-three-kvno-options-from-Heimdal-kgetcred.patch Patch38: Unify-kvno-option-documentation.patch +Patch39: Improve-KDC-alias-checking-for-S4U-requests.patch +Patch40: Adjust-KDC-alias-helper-function-contract.patch +Patch41: Allow-aliases-when-matching-U2U-second-ticket.patch +Patch42: Refactor-KDC-authdata-list-management-helpers.patch +Patch43: Minimize-usage-of-tgs_server-in-KDC.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -634,6 +639,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Oct 21 2020 Robbie Harwood - 1.18.2-26 +- Cross-realm s4u fixes for samba (#1836630) + * Thu Oct 15 2020 Robbie Harwood - 1.18.2-25 - Unify kvno option documentation From fced14e78a1904328080fdc7ac61f12cacacac1c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 21 Oct 2020 11:49:22 -0400 Subject: [PATCH 199/304] Fix build of previous --- ...d-passing-DB-entry-structures-in-KDC.patch | 298 ++++++++++++++++++ Minimize-usage-of-tgs_server-in-KDC.patch | 16 +- krb5.spec | 8 +- 3 files changed, 312 insertions(+), 10 deletions(-) create mode 100644 Avoid-passing-DB-entry-structures-in-KDC.patch diff --git a/Avoid-passing-DB-entry-structures-in-KDC.patch b/Avoid-passing-DB-entry-structures-in-KDC.patch new file mode 100644 index 0000000..e5cff1a --- /dev/null +++ b/Avoid-passing-DB-entry-structures-in-KDC.patch @@ -0,0 +1,298 @@ +From dd8b146093d4bdf8a7d0c0eb8156b62d090448d7 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 30 Sep 2020 02:12:00 -0400 +Subject: [PATCH] Avoid passing DB entry structures in KDC + +When validating AS or TGS requests, pass pointers to DB entry +structures, not the structures themselves. + +(cherry picked from commit 7ccc08a889b40693b2ce7f108f2cdda51bc04bff) +--- + src/kdc/do_as_req.c | 4 ++-- + src/kdc/do_tgs_req.c | 2 +- + src/kdc/kdc_util.c | 34 +++++++++++++++++----------------- + src/kdc/kdc_util.h | 6 +++--- + src/kdc/tgs_policy.c | 35 ++++++++++++++++++----------------- + 5 files changed, 41 insertions(+), 40 deletions(-) + +diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c +index 9ae7b0a5e..c2dfea9b8 100644 +--- a/src/kdc/do_as_req.c ++++ b/src/kdc/do_as_req.c +@@ -663,8 +663,8 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, + au_state->stage = VALIDATE_POL; + + if ((errcode = validate_as_request(kdc_active_realm, +- state->request, *state->client, +- *state->server, state->kdc_time, ++ state->request, state->client, ++ state->server, state->kdc_time, + &state->status, &state->e_data))) { + errcode += ERROR_TABLE_BASE_krb5; + goto errout; +diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c +index 74cd19e96..d345797c4 100644 +--- a/src/kdc/do_tgs_req.c ++++ b/src/kdc/do_tgs_req.c +@@ -260,7 +260,7 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, + goto cleanup; + + if ((retval = validate_tgs_request(kdc_active_realm, +- request, *server, header_ticket, ++ request, server, header_ticket, + kdc_time, &status, &e_data))) { + if (retval == KDC_ERR_POLICY || retval == KDC_ERR_BADOPTION) + au_state->violation = PROT_CONSTRAINT; +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index a4a05b9fa..b2042862a 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -612,8 +612,8 @@ check_anon(kdc_realm_t *kdc_active_realm, + KDC_OPT_ENC_TKT_IN_SKEY | KDC_OPT_CNAME_IN_ADDL_TKT) + int + validate_as_request(kdc_realm_t *kdc_active_realm, +- krb5_kdc_req *request, krb5_db_entry client, +- krb5_db_entry server, krb5_timestamp kdc_time, ++ krb5_kdc_req *request, krb5_db_entry *client, ++ krb5_db_entry *server, krb5_timestamp kdc_time, + const char **status, krb5_pa_data ***e_data) + { + krb5_error_code ret; +@@ -627,7 +627,7 @@ validate_as_request(kdc_realm_t *kdc_active_realm, + } + + /* The client must not be expired */ +- if (client.expiration && ts_after(kdc_time, client.expiration)) { ++ if (client->expiration && ts_after(kdc_time, client->expiration)) { + *status = "CLIENT EXPIRED"; + if (vague_errors) + return(KRB_ERR_GENERIC); +@@ -637,8 +637,8 @@ validate_as_request(kdc_realm_t *kdc_active_realm, + + /* The client's password must not be expired, unless the server is + a KRB5_KDC_PWCHANGE_SERVICE. */ +- if (client.pw_expiration && ts_after(kdc_time, client.pw_expiration) && +- !isflagset(server.attributes, KRB5_KDB_PWCHANGE_SERVICE)) { ++ if (client->pw_expiration && ts_after(kdc_time, client->pw_expiration) && ++ !isflagset(server->attributes, KRB5_KDB_PWCHANGE_SERVICE)) { + *status = "CLIENT KEY EXPIRED"; + if (vague_errors) + return(KRB_ERR_GENERIC); +@@ -647,7 +647,7 @@ validate_as_request(kdc_realm_t *kdc_active_realm, + } + + /* The server must not be expired */ +- if (server.expiration && ts_after(kdc_time, server.expiration)) { ++ if (server->expiration && ts_after(kdc_time, server->expiration)) { + *status = "SERVICE EXPIRED"; + return(KDC_ERR_SERVICE_EXP); + } +@@ -656,8 +656,8 @@ validate_as_request(kdc_realm_t *kdc_active_realm, + * If the client requires password changing, then only allow the + * pwchange service. + */ +- if (isflagset(client.attributes, KRB5_KDB_REQUIRES_PWCHANGE) && +- !isflagset(server.attributes, KRB5_KDB_PWCHANGE_SERVICE)) { ++ if (isflagset(client->attributes, KRB5_KDB_REQUIRES_PWCHANGE) && ++ !isflagset(server->attributes, KRB5_KDB_PWCHANGE_SERVICE)) { + *status = "REQUIRED PWCHANGE"; + return(KDC_ERR_KEY_EXP); + } +@@ -665,37 +665,37 @@ validate_as_request(kdc_realm_t *kdc_active_realm, + /* Client and server must allow postdating tickets */ + if ((isflagset(request->kdc_options, KDC_OPT_ALLOW_POSTDATE) || + isflagset(request->kdc_options, KDC_OPT_POSTDATED)) && +- (isflagset(client.attributes, KRB5_KDB_DISALLOW_POSTDATED) || +- isflagset(server.attributes, KRB5_KDB_DISALLOW_POSTDATED))) { ++ (isflagset(client->attributes, KRB5_KDB_DISALLOW_POSTDATED) || ++ isflagset(server->attributes, KRB5_KDB_DISALLOW_POSTDATED))) { + *status = "POSTDATE NOT ALLOWED"; + return(KDC_ERR_CANNOT_POSTDATE); + } + + /* Check to see if client is locked out */ +- if (isflagset(client.attributes, KRB5_KDB_DISALLOW_ALL_TIX)) { ++ if (isflagset(client->attributes, KRB5_KDB_DISALLOW_ALL_TIX)) { + *status = "CLIENT LOCKED OUT"; + return(KDC_ERR_CLIENT_REVOKED); + } + + /* Check to see if server is locked out */ +- if (isflagset(server.attributes, KRB5_KDB_DISALLOW_ALL_TIX)) { ++ if (isflagset(server->attributes, KRB5_KDB_DISALLOW_ALL_TIX)) { + *status = "SERVICE LOCKED OUT"; + return(KDC_ERR_S_PRINCIPAL_UNKNOWN); + } + + /* Check to see if server is allowed to be a service */ +- if (isflagset(server.attributes, KRB5_KDB_DISALLOW_SVR)) { ++ if (isflagset(server->attributes, KRB5_KDB_DISALLOW_SVR)) { + *status = "SERVICE NOT ALLOWED"; + return(KDC_ERR_MUST_USE_USER2USER); + } + +- if (check_anon(kdc_active_realm, client.princ, request->server) != 0) { ++ if (check_anon(kdc_active_realm, client->princ, request->server) != 0) { + *status = "ANONYMOUS NOT ALLOWED"; + return(KDC_ERR_POLICY); + } + + /* Perform KDB module policy checks. */ +- ret = krb5_db_check_policy_as(kdc_context, request, &client, &server, ++ ret = krb5_db_check_policy_as(kdc_context, request, client, server, + kdc_time, status, e_data); + if (ret && ret != KRB5_PLUGIN_OP_NOTSUPP) + return errcode_to_protocol(ret); +@@ -1568,8 +1568,8 @@ kdc_process_s4u2self_req(kdc_realm_t *kdc_active_realm, + princ->pw_expiration = 0; + clear(princ->attributes, KRB5_KDB_REQUIRES_PWCHANGE); + +- code = validate_as_request(kdc_active_realm, request, *princ, +- no_server, kdc_time, status, &e_data); ++ code = validate_as_request(kdc_active_realm, request, princ, ++ &no_server, kdc_time, status, &e_data); + if (code) { + krb5_db_free_principal(kdc_context, princ); + krb5_free_pa_data(kdc_context, e_data); +diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h +index 42b7ee208..04007a8f5 100644 +--- a/src/kdc/kdc_util.h ++++ b/src/kdc/kdc_util.h +@@ -76,12 +76,12 @@ get_local_tgt(krb5_context context, const krb5_data *realm, + krb5_db_entry **storage_out, krb5_keyblock *kb_out); + + int +-validate_as_request (kdc_realm_t *, krb5_kdc_req *, krb5_db_entry, +- krb5_db_entry, krb5_timestamp, ++validate_as_request (kdc_realm_t *, krb5_kdc_req *, krb5_db_entry *, ++ krb5_db_entry *, krb5_timestamp, + const char **, krb5_pa_data ***); + + int +-validate_tgs_request (kdc_realm_t *, krb5_kdc_req *, krb5_db_entry, ++validate_tgs_request (kdc_realm_t *, krb5_kdc_req *, krb5_db_entry *, + krb5_ticket *, krb5_timestamp, + const char **, krb5_pa_data ***); + +diff --git a/src/kdc/tgs_policy.c b/src/kdc/tgs_policy.c +index 554345ba5..3f4fa8499 100644 +--- a/src/kdc/tgs_policy.c ++++ b/src/kdc/tgs_policy.c +@@ -48,7 +48,7 @@ struct tgsflagrule { + }; + + /* Service principal TGS policy checking functions */ +-typedef int (check_tgs_svc_pol_fn)(krb5_kdc_req *, krb5_db_entry, ++typedef int (check_tgs_svc_pol_fn)(krb5_kdc_req *, krb5_db_entry *, + krb5_ticket *, krb5_timestamp, + const char **); + +@@ -110,7 +110,7 @@ static const struct tgsflagrule svcdenyrules[] = { + * A service principal can forbid some TGS-REQ options. + */ + static int +-check_tgs_svc_deny_opts(krb5_kdc_req *req, krb5_db_entry server, ++check_tgs_svc_deny_opts(krb5_kdc_req *req, krb5_db_entry *server, + krb5_ticket *tkt, krb5_timestamp kdc_time, + const char **status) + { +@@ -122,7 +122,7 @@ check_tgs_svc_deny_opts(krb5_kdc_req *req, krb5_db_entry server, + r = &svcdenyrules[i]; + if (!(r->reqflags & req->kdc_options)) + continue; +- if (r->checkflag & server.attributes) { ++ if (r->checkflag & server->attributes) { + *status = r->status; + return r->err; + } +@@ -134,20 +134,20 @@ check_tgs_svc_deny_opts(krb5_kdc_req *req, krb5_db_entry server, + * A service principal can deny all TGS-REQs for it. + */ + static int +-check_tgs_svc_deny_all(krb5_kdc_req *req, krb5_db_entry server, ++check_tgs_svc_deny_all(krb5_kdc_req *req, krb5_db_entry *server, + krb5_ticket *tkt, krb5_timestamp kdc_time, + const char **status) + { +- if (server.attributes & KRB5_KDB_DISALLOW_ALL_TIX) { ++ if (server->attributes & KRB5_KDB_DISALLOW_ALL_TIX) { + *status = "SERVER LOCKED OUT"; + return KDC_ERR_S_PRINCIPAL_UNKNOWN; + } +- if ((server.attributes & KRB5_KDB_DISALLOW_SVR) && ++ if ((server->attributes & KRB5_KDB_DISALLOW_SVR) && + !(req->kdc_options & KDC_OPT_ENC_TKT_IN_SKEY)) { + *status = "SERVER NOT ALLOWED"; + return KDC_ERR_MUST_USE_USER2USER; + } +- if (server.attributes & KRB5_KDB_DISALLOW_TGT_BASED) { ++ if (server->attributes & KRB5_KDB_DISALLOW_TGT_BASED) { + if (krb5_is_tgs_principal(tkt->server)) { + *status = "TGT BASED NOT ALLOWED"; + return KDC_ERR_POLICY; +@@ -160,17 +160,17 @@ check_tgs_svc_deny_all(krb5_kdc_req *req, krb5_db_entry server, + * A service principal can require certain TGT flags. + */ + static int +-check_tgs_svc_reqd_flags(krb5_kdc_req *req, krb5_db_entry server, ++check_tgs_svc_reqd_flags(krb5_kdc_req *req, krb5_db_entry *server, + krb5_ticket *tkt, + krb5_timestamp kdc_time, const char **status) + { +- if (server.attributes & KRB5_KDB_REQUIRES_HW_AUTH) { ++ if (server->attributes & KRB5_KDB_REQUIRES_HW_AUTH) { + if (!(tkt->enc_part2->flags & TKT_FLG_HW_AUTH)) { + *status = "NO HW PREAUTH"; + return KRB_ERR_GENERIC; + } + } +- if (server.attributes & KRB5_KDB_REQUIRES_PRE_AUTH) { ++ if (server->attributes & KRB5_KDB_REQUIRES_PRE_AUTH) { + if (!(tkt->enc_part2->flags & TKT_FLG_PRE_AUTH)) { + *status = "NO PREAUTH"; + return KRB_ERR_GENERIC; +@@ -180,10 +180,10 @@ check_tgs_svc_reqd_flags(krb5_kdc_req *req, krb5_db_entry server, + } + + static int +-check_tgs_svc_time(krb5_kdc_req *req, krb5_db_entry server, krb5_ticket *tkt, ++check_tgs_svc_time(krb5_kdc_req *req, krb5_db_entry *server, krb5_ticket *tkt, + krb5_timestamp kdc_time, const char **status) + { +- if (server.expiration && ts_after(kdc_time, server.expiration)) { ++ if (server->expiration && ts_after(kdc_time, server->expiration)) { + *status = "SERVICE EXPIRED"; + return KDC_ERR_SERVICE_EXP; + } +@@ -191,8 +191,9 @@ check_tgs_svc_time(krb5_kdc_req *req, krb5_db_entry server, krb5_ticket *tkt, + } + + static int +-check_tgs_svc_policy(krb5_kdc_req *req, krb5_db_entry server, krb5_ticket *tkt, +- krb5_timestamp kdc_time, const char **status) ++check_tgs_svc_policy(krb5_kdc_req *req, krb5_db_entry *server, ++ krb5_ticket *tkt, krb5_timestamp kdc_time, ++ const char **status) + { + int errcode; + size_t i; +@@ -317,7 +318,7 @@ check_tgs_tgt(kdc_realm_t *kdc_active_realm, krb5_kdc_req *req, + + int + validate_tgs_request(kdc_realm_t *kdc_active_realm, +- krb5_kdc_req *request, krb5_db_entry server, ++ krb5_kdc_req *request, krb5_db_entry *server, + krb5_ticket *ticket, krb5_timestamp kdc_time, + const char **status, krb5_pa_data ***e_data) + { +@@ -367,8 +368,8 @@ validate_tgs_request(kdc_realm_t *kdc_active_realm, + } + + /* Perform KDB module policy checks. */ +- ret = krb5_db_check_policy_tgs(kdc_context, request, &server, +- ticket, status, e_data); ++ ret = krb5_db_check_policy_tgs(kdc_context, request, server, ticket, ++ status, e_data); + if (ret && ret != KRB5_PLUGIN_OP_NOTSUPP) + return errcode_to_protocol(ret); + diff --git a/Minimize-usage-of-tgs_server-in-KDC.patch b/Minimize-usage-of-tgs_server-in-KDC.patch index 7a2a031..f08458e 100644 --- a/Minimize-usage-of-tgs_server-in-KDC.patch +++ b/Minimize-usage-of-tgs_server-in-KDC.patch @@ -1,4 +1,4 @@ -From 604135b5ad6bf954491413243eb305b82fec1c06 Mon Sep 17 00:00:00 2001 +From 5e79319edf3836d12dbc710ec1e2dd4405c9df35 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 25 Sep 2020 11:12:34 -0400 Subject: [PATCH] Minimize usage of tgs_server in KDC @@ -36,7 +36,7 @@ request. 5 files changed, 46 insertions(+), 78 deletions(-) diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c -index 9ae7b0a5e..e243f50be 100644 +index c2dfea9b8..e0ac33649 100644 --- a/src/kdc/do_as_req.c +++ b/src/kdc/do_as_req.c @@ -620,18 +620,6 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, @@ -75,7 +75,7 @@ index 9ae7b0a5e..e243f50be 100644 state->server, &state->local_tgt, &state->local_tgt_storage, &state->local_tgt_key); diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c -index 74cd19e96..72525a462 100644 +index d345797c4..8ea418e43 100644 --- a/src/kdc/do_tgs_req.c +++ b/src/kdc/do_tgs_req.c @@ -268,7 +268,7 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, @@ -120,7 +120,7 @@ index 74cd19e96..72525a462 100644 enc_tkt_reply.client)) { /* tgt issued by local realm or issued by realm of client */ diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index a4a05b9fa..a631b498d 100644 +index b2042862a..e0b65a87c 100644 --- a/src/kdc/kdc_util.c +++ b/src/kdc/kdc_util.c @@ -78,12 +78,6 @@ static krb5_error_code find_server_key(krb5_context, @@ -258,7 +258,7 @@ index a4a05b9fa..a631b498d 100644 *status = "XREALM_EVIDENCE_TICKET_MISMATCH"; return KRB5KDC_ERR_BADOPTION; diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index 42b7ee208..c730409ae 100644 +index 04007a8f5..a6bac4388 100644 --- a/src/kdc/kdc_util.h +++ b/src/kdc/kdc_util.h @@ -37,10 +37,9 @@ @@ -274,10 +274,10 @@ index 42b7ee208..c730409ae 100644 add_to_transited (krb5_data *, krb5_data *, diff --git a/src/kdc/tgs_policy.c b/src/kdc/tgs_policy.c -index 554345ba5..59d60ca25 100644 +index 3f4fa8499..a5a00f0cc 100644 --- a/src/kdc/tgs_policy.c +++ b/src/kdc/tgs_policy.c -@@ -251,19 +251,21 @@ check_tgs_s4u2proxy(kdc_realm_t *kdc_active_realm, +@@ -252,19 +252,21 @@ check_tgs_s4u2proxy(kdc_realm_t *kdc_active_realm, } static int @@ -305,7 +305,7 @@ index 554345ba5..59d60ca25 100644 *status = "2ND_TKT_NOT_TGS"; return KDC_ERR_POLICY; } -@@ -352,7 +354,7 @@ validate_tgs_request(kdc_realm_t *kdc_active_realm, +@@ -353,7 +355,7 @@ validate_tgs_request(kdc_realm_t *kdc_active_realm, return(KRB_AP_ERR_REPEAT); } diff --git a/krb5.spec b/krb5.spec index 9cdd23b..30396a5 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 26%{?dist} +Release: 27%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -78,7 +78,8 @@ Patch39: Improve-KDC-alias-checking-for-S4U-requests.patch Patch40: Adjust-KDC-alias-helper-function-contract.patch Patch41: Allow-aliases-when-matching-U2U-second-ticket.patch Patch42: Refactor-KDC-authdata-list-management-helpers.patch -Patch43: Minimize-usage-of-tgs_server-in-KDC.patch +Patch43: Avoid-passing-DB-entry-structures-in-KDC.patch +Patch44: Minimize-usage-of-tgs_server-in-KDC.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -639,6 +640,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Oct 21 2020 Robbie Harwood - 1.18.2-27 +- Fix build of previous + * Wed Oct 21 2020 Robbie Harwood - 1.18.2-26 - Cross-realm s4u fixes for samba (#1836630) From bfdc7c0b7be1f33f451a173fb1155450fbe25690 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 23 Oct 2020 10:25:37 -0400 Subject: [PATCH 200/304] Fix minor static analysis defects --- Fix-minor-static-analysis-defects.patch | 106 ++++++++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 111 insertions(+), 1 deletion(-) create mode 100644 Fix-minor-static-analysis-defects.patch diff --git a/Fix-minor-static-analysis-defects.patch b/Fix-minor-static-analysis-defects.patch new file mode 100644 index 0000000..653bce1 --- /dev/null +++ b/Fix-minor-static-analysis-defects.patch @@ -0,0 +1,106 @@ +From c3d96fca46cb2cc3ee9f4c2e2a4ed98bad3e310a Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 15 Oct 2020 18:15:29 -0400 +Subject: [PATCH] Fix minor static analysis defects + +Remove an unused variable in krb5_ldap_create(). Handle the return +value from krb5_dbe_get_string() in the certauth test plugin module. +Handle the return value from k5_expand_path_tokens() in +k5_rc_default(). Remove dead assignments in +krb5_get_credentials_for_user() and kg_accept_krb5(). + +[ghudson@mit.edu: squashed and edited commit message; simplified +k5_rc_default() change] + +(cherry picked from commit b27461141810fddd299764928649148c5d0e99f3) +--- + src/lib/gssapi/krb5/accept_sec_context.c | 4 +--- + src/lib/krb5/krb/s4u_creds.c | 1 - + src/lib/krb5/rcache/rc_base.c | 2 ++ + src/plugins/certauth/test/main.c | 3 +++ + src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c | 4 ---- + 5 files changed, 6 insertions(+), 8 deletions(-) + +diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c +index 3d5b84b15..e2c5e2b59 100644 +--- a/src/lib/gssapi/krb5/accept_sec_context.c ++++ b/src/lib/gssapi/krb5/accept_sec_context.c +@@ -671,7 +671,7 @@ kg_accept_krb5(minor_status, context_handle, + krb5_auth_context auth_context = NULL; + krb5_ticket * ticket = NULL; + const gss_OID_desc *mech_used = NULL; +- OM_uint32 major_status = GSS_S_FAILURE; ++ OM_uint32 major_status; + OM_uint32 tmp_minor_status; + krb5_error krb_error_data; + krb5_data scratch; +@@ -878,8 +878,6 @@ kg_accept_krb5(minor_status, context_handle, + if (major_status != GSS_S_COMPLETE) + goto fail; + +- major_status = GSS_S_FAILURE; +- + if (exts->iakerb.conv && !exts->iakerb.verified) { + major_status = GSS_S_BAD_SIG; + goto fail; +diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c +index d8f486dc6..35a8843e5 100644 +--- a/src/lib/krb5/krb/s4u_creds.c ++++ b/src/lib/krb5/krb/s4u_creds.c +@@ -714,7 +714,6 @@ krb5_get_credentials_for_user(krb5_context context, krb5_flags options, + } else if (code != KRB5_CC_NOTFOUND && code != KRB5_CC_NOT_KTYPE) { + goto cleanup; + } +- code = 0; + } + + /* Note the authdata we asked for in the output creds. */ +diff --git a/src/lib/krb5/rcache/rc_base.c b/src/lib/krb5/rcache/rc_base.c +index 5f456d1f3..f9a482318 100644 +--- a/src/lib/krb5/rcache/rc_base.c ++++ b/src/lib/krb5/rcache/rc_base.c +@@ -56,6 +56,8 @@ k5_rc_default(krb5_context context, krb5_rcache *rc_out) + &profstr) == 0 && profstr != NULL) { + ret = k5_expand_path_tokens(context, profstr, &rcname); + profile_release_string(profstr); ++ if (ret) ++ return ret; + ret = k5_rc_resolve(context, rcname, rc_out); + free(rcname); + return ret; +diff --git a/src/plugins/certauth/test/main.c b/src/plugins/certauth/test/main.c +index d4633b8cd..7e7a3ef4c 100644 +--- a/src/plugins/certauth/test/main.c ++++ b/src/plugins/certauth/test/main.c +@@ -171,6 +171,9 @@ test2_authorize(krb5_context context, krb5_certauth_moddata moddata, + + ret = krb5_dbe_get_string(context, (krb5_db_entry *)db_entry, "hwauth", + &strval); ++ if (ret) ++ goto cleanup; ++ + ret = (strval != NULL) ? KRB5_CERTAUTH_HWAUTH : 0; + krb5_dbe_free_string(context, strval); + +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c +index 5b57c799a..2d6605666 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c ++++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c +@@ -55,7 +55,6 @@ krb5_ldap_create(krb5_context context, char *conf_section, char **db_args) + krb5_error_code status = 0; + krb5_ldap_realm_params *rparams = NULL; + krb5_ldap_context *ldap_context=NULL; +- krb5_boolean realm_obj_created = FALSE; + int mask = 0; + + /* Clear the global error string */ +@@ -109,9 +108,6 @@ krb5_ldap_create(krb5_context context, char *conf_section, char **db_args) + if ((status = krb5_ldap_create_realm(context, rparams, mask))) + goto cleanup; + +- /* We just created the Realm container. Here starts our transaction tracking */ +- realm_obj_created = TRUE; +- + /* verify realm object */ + if ((status = krb5_ldap_read_realm_params(context, + rparams->realm_name, diff --git a/krb5.spec b/krb5.spec index 30396a5..3cc61cf 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 27%{?dist} +Release: 28%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -80,6 +80,7 @@ Patch41: Allow-aliases-when-matching-U2U-second-ticket.patch Patch42: Refactor-KDC-authdata-list-management-helpers.patch Patch43: Avoid-passing-DB-entry-structures-in-KDC.patch Patch44: Minimize-usage-of-tgs_server-in-KDC.patch +Patch45: Fix-minor-static-analysis-defects.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -640,6 +641,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Oct 23 2020 Robbie Harwood - 1.18.2-28 +- Fix minor static analysis defects + * Wed Oct 21 2020 Robbie Harwood - 1.18.2-27 - Fix build of previous From d2da394f6768fee0f055e022ccbf4c011586bd93 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 5 Nov 2020 12:09:39 -0500 Subject: [PATCH 201/304] Add recursion limit for ASN.1 indefinite lengths (CVE-2020-28196) --- ...n-limit-for-ASN.1-indefinite-lengths.patch | 97 +++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 102 insertions(+), 1 deletion(-) create mode 100644 Add-recursion-limit-for-ASN.1-indefinite-lengths.patch diff --git a/Add-recursion-limit-for-ASN.1-indefinite-lengths.patch b/Add-recursion-limit-for-ASN.1-indefinite-lengths.patch new file mode 100644 index 0000000..bc1229c --- /dev/null +++ b/Add-recursion-limit-for-ASN.1-indefinite-lengths.patch @@ -0,0 +1,97 @@ +From b7aca8b57422cdc67a2d2bff385f09646ca037bc Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sat, 31 Oct 2020 17:07:05 -0400 +Subject: [PATCH] Add recursion limit for ASN.1 indefinite lengths + +The libkrb5 ASN.1 decoder supports BER indefinite lengths. It +computes the tag length using recursion; the lack of a recursion limit +allows an attacker to overrun the stack and cause the process to +crash. Reported by Demi Obenour. + +CVE-2020-28196: + +In MIT krb5 releases 1.11 and later, an unauthenticated attacker can +cause a denial of service for any client or server to which it can +send an ASN.1-encoded Kerberos message of sufficient length. + +ticket: 8959 (new) +tags: pullup +target_version: 1.18-next +target_version: 1.17-next + +(cherry picked from commit 57415dda6cf04e73ffc3723be518eddfae599bfd) +--- + src/lib/krb5/asn.1/asn1_encode.c | 16 +++++++++------- + 1 file changed, 9 insertions(+), 7 deletions(-) + +diff --git a/src/lib/krb5/asn.1/asn1_encode.c b/src/lib/krb5/asn.1/asn1_encode.c +index a160cf4fe..cd6b879f7 100644 +--- a/src/lib/krb5/asn.1/asn1_encode.c ++++ b/src/lib/krb5/asn.1/asn1_encode.c +@@ -356,7 +356,7 @@ make_tag(asn1buf *buf, const taginfo *t, size_t len) + static krb5_error_code + get_tag(const uint8_t *asn1, size_t len, taginfo *tag_out, + const uint8_t **contents_out, size_t *clen_out, +- const uint8_t **remainder_out, size_t *rlen_out) ++ const uint8_t **remainder_out, size_t *rlen_out, int recursion) + { + krb5_error_code ret; + uint8_t o; +@@ -394,9 +394,11 @@ get_tag(const uint8_t *asn1, size_t len, taginfo *tag_out, + /* Indefinite form (should not be present in DER, but we accept it). */ + if (tag_out->construction != CONSTRUCTED) + return ASN1_MISMATCH_INDEF; ++ if (recursion >= 32) ++ return ASN1_OVERFLOW; + p = asn1; + while (!(len >= 2 && p[0] == 0 && p[1] == 0)) { +- ret = get_tag(p, len, &t, &c, &clen, &p, &len); ++ ret = get_tag(p, len, &t, &c, &clen, &p, &len, recursion + 1); + if (ret) + return ret; + } +@@ -613,7 +615,7 @@ split_der(asn1buf *buf, uint8_t *const *der, size_t len, taginfo *tag_out) + const uint8_t *contents, *remainder; + size_t clen, rlen; + +- ret = get_tag(*der, len, tag_out, &contents, &clen, &remainder, &rlen); ++ ret = get_tag(*der, len, tag_out, &contents, &clen, &remainder, &rlen, 0); + if (ret) + return ret; + if (rlen != 0) +@@ -1199,7 +1201,7 @@ decode_atype(const taginfo *t, const uint8_t *asn1, size_t len, + const uint8_t *rem; + size_t rlen; + if (!tag->implicit) { +- ret = get_tag(asn1, len, &inner_tag, &asn1, &len, &rem, &rlen); ++ ret = get_tag(asn1, len, &inner_tag, &asn1, &len, &rem, &rlen, 0); + if (ret) + return ret; + /* Note: we don't check rlen (it should be 0). */ +@@ -1420,7 +1422,7 @@ decode_sequence(const uint8_t *asn1, size_t len, const struct seq_info *seq, + for (i = 0; i < seq->n_fields; i++) { + if (len == 0) + break; +- ret = get_tag(asn1, len, &t, &contents, &clen, &asn1, &len); ++ ret = get_tag(asn1, len, &t, &contents, &clen, &asn1, &len, 0); + if (ret) + goto error; + /* +@@ -1478,7 +1480,7 @@ decode_sequence_of(const uint8_t *asn1, size_t len, + *seq_out = NULL; + *count_out = 0; + while (len > 0) { +- ret = get_tag(asn1, len, &t, &contents, &clen, &asn1, &len); ++ ret = get_tag(asn1, len, &t, &contents, &clen, &asn1, &len, 0); + if (ret) + goto error; + if (!check_atype_tag(elemtype, &t)) { +@@ -1584,7 +1586,7 @@ k5_asn1_full_decode(const krb5_data *code, const struct atype_info *a, + + *retrep = NULL; + ret = get_tag((uint8_t *)code->data, code->length, &t, &contents, +- &clen, &remainder, &rlen); ++ &clen, &remainder, &rlen, 0); + if (ret) + return ret; + /* rlen should be 0, but we don't check it (and due to padding in diff --git a/krb5.spec b/krb5.spec index 3cc61cf..dd4152d 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 28%{?dist} +Release: 29%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -81,6 +81,7 @@ Patch42: Refactor-KDC-authdata-list-management-helpers.patch Patch43: Avoid-passing-DB-entry-structures-in-KDC.patch Patch44: Minimize-usage-of-tgs_server-in-KDC.patch Patch45: Fix-minor-static-analysis-defects.patch +Patch46: Add-recursion-limit-for-ASN.1-indefinite-lengths.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -641,6 +642,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Nov 05 2020 Robbie Harwood - 1.18.2-29 +- Add recursion limit for ASN.1 indefinite lengths (CVE-2020-28196) + * Fri Oct 23 2020 Robbie Harwood - 1.18.2-28 - Fix minor static analysis defects From ec1ab43ca2ba22fbe7db5ad5bf2ba3800c31262a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 17 Nov 2020 17:27:37 +0000 Subject: [PATCH 202/304] Migrate /var/run to /run, an exercise in pointlessness Resolves: #1898410 --- kadmin.service | 4 ++-- krb5-krb5kdc.conf | 2 +- krb5.spec | 16 +++++----------- krb5kdc.service | 4 ++-- 4 files changed, 10 insertions(+), 16 deletions(-) diff --git a/kadmin.service b/kadmin.service index f1677c6..daa08b1 100644 --- a/kadmin.service +++ b/kadmin.service @@ -6,9 +6,9 @@ AssertPathExists=!/var/kerberos/krb5kdc/kpropd.acl [Service] Type=forking -PIDFile=/var/run/kadmind.pid +PIDFile=/run/kadmind.pid EnvironmentFile=-/etc/sysconfig/kadmin -ExecStart=/usr/sbin/kadmind -P /var/run/kadmind.pid $KADMIND_ARGS +ExecStart=/usr/sbin/kadmind -P /run/kadmind.pid $KADMIND_ARGS ExecReload=/bin/kill -HUP $MAINPID [Install] diff --git a/krb5-krb5kdc.conf b/krb5-krb5kdc.conf index eadeb51..5160b28 100644 --- a/krb5-krb5kdc.conf +++ b/krb5-krb5kdc.conf @@ -1 +1 @@ -d /var/run/krb5kdc 0755 root root +d /run/krb5kdc 0755 root root diff --git a/krb5.spec b/krb5.spec index dd4152d..e133875 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.2 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 29%{?dist} +Release: 30%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -258,9 +258,6 @@ sed -i -e s,7778,`expr "$PORT" + 1`,g $cfg source %{_libdir}/tclConfig.sh pushd src -# Set this so that configure will have a value even if the current version of -# autoconf doesn't set one. -export runstatedir=%{_localstatedir}/run # Work out the CFLAGS and CPPFLAGS which we intend to use. INCLUDES=-I%{_includedir}/et CFLAGS="`echo $RPM_OPT_FLAGS $DEFINES $INCLUDES -fPIC -fno-strict-aliasing -fstack-protector-all`" @@ -296,13 +293,6 @@ CPPFLAGS="`echo $DEFINES $INCLUDES`" make popd -# Sanity check the KDC_RUN_DIR. -configured_kdcrundir=`grep KDC_RUN_DIR src/include/osconf.h | awk '{print $NF}'` -configured_kdcrundir=`eval echo $configured_kdcrundir` -if test "$configured_kdcrundir" != %{_localstatedir}/run/krb5kdc ; then - exit 1 -fi - # Build the docs. make -C src/doc paths.py version.py cp src/doc/paths.py doc/ @@ -642,6 +632,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Nov 17 2020 Robbie Harwood - 1.18.2-30 +- Migrate /var/run to /run, an exercise in pointlessness +- Resolves: #1898410 + * Thu Nov 05 2020 Robbie Harwood - 1.18.2-29 - Add recursion limit for ASN.1 indefinite lengths (CVE-2020-28196) diff --git a/krb5kdc.service b/krb5kdc.service index 806b062..40e23d6 100644 --- a/krb5kdc.service +++ b/krb5kdc.service @@ -5,9 +5,9 @@ After=syslog.target network.target network-online.target [Service] Type=forking -PIDFile=/var/run/krb5kdc.pid +PIDFile=/run/krb5kdc.pid EnvironmentFile=-/etc/sysconfig/krb5kdc -ExecStart=/usr/sbin/krb5kdc -P /var/run/krb5kdc.pid $KRB5KDC_ARGS +ExecStart=/usr/sbin/krb5kdc -P /run/krb5kdc.pid $KRB5KDC_ARGS ExecReload=/bin/kill -HUP $MAINPID [Install] From 015255764a8b2e22bcb29b8abd0813344c423da1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 17 Nov 2020 12:50:36 -0500 Subject: [PATCH 203/304] Sigh, date fix --- krb5.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index e133875..6223d52 100644 --- a/krb5.spec +++ b/krb5.spec @@ -632,7 +632,7 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog -* Thu Nov 17 2020 Robbie Harwood - 1.18.2-30 +* Tue Nov 17 2020 Robbie Harwood - 1.18.2-30 - Migrate /var/run to /run, an exercise in pointlessness - Resolves: #1898410 From 5facc9df4d7293dfdfe2767f46cdcdbdf51a0977 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 18 Nov 2020 18:16:20 +0000 Subject: [PATCH 204/304] New upstream version (1.18.3) --- .gitignore | 2 + Add-channel-bindings-tests.patch | 68 ++++--- ...client_aware_channel_bindings-option.patch | 2 +- ...finalization-safety-check-to-com_err.patch | 2 +- ...n-limit-for-ASN.1-indefinite-lengths.patch | 97 --------- ...e-kvno-options-from-Heimdal-kgetcred.patch | 54 ++--- ...t-KDC-alias-helper-function-contract.patch | 2 +- ...ases-when-matching-U2U-second-ticket.patch | 2 +- ...tauth-modules-to-set-hw-authent-flag.patch | 2 +- ...ss_unwrap_iov-of-unpadded-RC4-tokens.patch | 49 ----- ...d-passing-DB-entry-structures-in-KDC.patch | 2 +- ...y-import-service-GSS-host-based-name.patch | 2 +- ...ns_canonicalize_hostname-to-fallback.patch | 2 +- ...ion-warnings-for-all-init_creds-APIs.patch | 2 +- ...edundant-PKINIT-responder-invocation.patch | 93 --------- ...ngth-checking-in-SPNEGO-DER-decoding.patch | 58 ------ ...n-KERB_AP_OPTIONS_CBT-server-support.patch | 2 +- Fix-minor-static-analysis-defects.patch | 2 +- Fix-typo-in-in-in-the-ksu-man-page.patch | 4 +- ...-enctypes-in-krb5_string_to_keysalts.patch | 2 +- Implement-GSS_C_CHANNEL_BOUND_FLAG.patch | 2 +- ...ment-KERB_AP_OPTIONS_CBT-server-side.patch | 2 +- ...-KDC-alias-checking-for-S4U-requests.patch | 2 +- Improve-negoex_parse_token-code-hygiene.patch | 2 +- Minimize-usage-of-tgs_server-in-KDC.patch | 2 +- ...ndicator-check-for-S4U2Self-requests.patch | 2 +- ...SER-if-we-can-t-compute-its-checksum.patch | 2 +- Pass-channel-bindings-through-SPNEGO.patch | 22 +-- Pass-gss_localname-through-SPNEGO.patch | 6 +- ...KDC-authdata-list-management-helpers.patch | 2 +- Refactor-krb5-GSS-checksum-handling.patch | 2 +- ...ly-acquired-creds-from-client-keytab.patch | 2 +- Remove-resolver-test-utility.patch | 2 +- ...ce-gssrpc-tests-with-a-Python-script.patch | 2 +- Unify-kvno-option-documentation.patch | 185 ------------------ ...eues-for-concurrent-t_otp.py-daemons.patch | 2 +- downstream-Adjust-build-configuration.patch | 2 +- ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 2 +- downstream-Remove-3des-support.patch | 4 +- downstream-SELinux-integration.patch | 12 +- ...ackported-version-of-OpenSSL-3-KDF-i.patch | 2 +- downstream-fix-debuginfo-with-y.tab.c.patch | 2 +- downstream-ksu-pam-integration.patch | 6 +- downstream-netlib-and-dns.patch | 6 +- krb5.spec | 12 +- sources | 4 +- 46 files changed, 133 insertions(+), 607 deletions(-) delete mode 100644 Add-recursion-limit-for-ASN.1-indefinite-lengths.patch delete mode 100644 Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch delete mode 100644 Eliminate-redundant-PKINIT-responder-invocation.patch delete mode 100644 Fix-input-length-checking-in-SPNEGO-DER-decoding.patch delete mode 100644 Unify-kvno-option-documentation.patch diff --git a/.gitignore b/.gitignore index ecff9ea..35b6d60 100644 --- a/.gitignore +++ b/.gitignore @@ -187,3 +187,5 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.18.1.tar.gz.asc /krb5-1.18.2.tar.gz /krb5-1.18.2.tar.gz.asc +/krb5-1.18.3.tar.gz +/krb5-1.18.3.tar.gz.asc diff --git a/Add-channel-bindings-tests.patch b/Add-channel-bindings-tests.patch index 2eb0f1c..99c2da2 100644 --- a/Add-channel-bindings-tests.patch +++ b/Add-channel-bindings-tests.patch @@ -1,4 +1,4 @@ -From 6d36ea6fcfe281a8ce73fc5aa5c133f435d93fa4 Mon Sep 17 00:00:00 2001 +From 2c8494a1b89d69da9de46ca2cb17f9e8f12eb9b5 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Fri, 20 Mar 2020 00:17:28 +0100 Subject: [PATCH] Add channel bindings tests @@ -10,17 +10,18 @@ changes] ticket: 8900 (cherry picked from commit b0b21b6d25b06f3e2b365dfe9dd4c99b3d43bf57) -[rharwood@redhat.com: .gitignore] +[rharwood@redhat.com: slush around upstream not backporting reload, +gitignore] --- src/plugins/gssapi/negoextest/main.c | 18 +++++ - src/tests/gssapi/Makefile.in | 49 ++++++------ + src/tests/gssapi/Makefile.in | 57 +++++++------- src/tests/gssapi/common.c | 25 ++++-- src/tests/gssapi/common.h | 9 +++ src/tests/gssapi/deps | 4 + src/tests/gssapi/t_bindings.c | 111 +++++++++++++++++++++++++++ src/tests/gssapi/t_bindings.py | 43 +++++++++++ src/tests/gssapi/t_negoex.py | 7 ++ - 8 files changed, 237 insertions(+), 29 deletions(-) + 8 files changed, 242 insertions(+), 32 deletions(-) create mode 100644 src/tests/gssapi/t_bindings.c create mode 100644 src/tests/gssapi/t_bindings.py @@ -61,23 +62,25 @@ index 6c340f41b..72fc5273a 100644 * The unwrapped token sits at the end and is just one byte giving the * remaining number of hops. The final octet of the mech encoding should diff --git a/src/tests/gssapi/Makefile.in b/src/tests/gssapi/Makefile.in -index 5cc1e0f58..68c132b79 100644 +index 22a2f9480..cf7bcf451 100644 --- a/src/tests/gssapi/Makefile.in +++ b/src/tests/gssapi/Makefile.in -@@ -9,33 +9,33 @@ LOCALINCLUDES = -I$(srcdir)/../../lib/gssapi/mechglue \ +@@ -8,34 +8,36 @@ LOCALINCLUDES = -I$(srcdir)/../../lib/gssapi/mechglue \ + -I$(srcdir)/../../lib/gssapi/generic -I../../lib/gssapi/krb5 \ -I../../lib/gssapi/generic - SRCS= $(srcdir)/ccinit.c $(srcdir)/ccrefresh.c $(srcdir)/common.c \ +-SRCS= $(srcdir)/ccinit.c $(srcdir)/ccrefresh.c $(srcdir)/common.c $(srcdir)/reload.c \ - $(srcdir)/t_accname.c $(srcdir)/t_add_cred.c $(srcdir)/t_ccselect.c \ - $(srcdir)/t_ciflags.c $(srcdir)/t_context.c $(srcdir)/t_credstore.c \ - $(srcdir)/t_enctypes.c $(srcdir)/t_err.c $(srcdir)/t_export_cred.c \ - $(srcdir)/t_export_name.c $(srcdir)/t_gssexts.c \ - $(srcdir)/t_imp_cred.c $(srcdir)/t_imp_name.c $(srcdir)/t_invalid.c \ - $(srcdir)/t_inq_cred.c $(srcdir)/t_inq_ctx.c \ -+ $(srcdir)/t_accname.c $(srcdir)/t_add_cred.c $(srcdir)/t_bindings.c \ -+ $(srcdir)/t_ccselect.c $(srcdir)/t_ciflags.c $(srcdir)/t_context.c \ -+ $(srcdir)/t_credstore.c $(srcdir)/t_enctypes.c $(srcdir)/t_err.c \ -+ $(srcdir)/t_export_cred.c $(srcdir)/t_export_name.c \ ++SRCS= $(srcdir)/ccinit.c $(srcdir)/ccrefresh.c $(srcdir)/common.c \ ++ $(srcdir)/reload.c $(srcdir)/t_accname.c $(srcdir)/t_add_cred.c \ ++ $(srcdir)/t_bindings.c $(srcdir)/t_ccselect.c $(srcdir)/t_ciflags.c \ ++ $(srcdir)/t_context.c $(srcdir)/t_credstore.c $(srcdir)/t_enctypes.c \ ++ $(srcdir)/t_err.c $(srcdir)/t_export_cred.c $(srcdir)/t_export_name.c \ + $(srcdir)/t_gssexts.c $(srcdir)/t_imp_cred.c $(srcdir)/t_imp_name.c \ + $(srcdir)/t_invalid.c $(srcdir)/t_inq_cred.c $(srcdir)/t_inq_ctx.c \ $(srcdir)/t_inq_mechs_name.c $(srcdir)/t_iov.c \ @@ -86,18 +89,20 @@ index 5cc1e0f58..68c132b79 100644 $(srcdir)/t_s4u2proxy_krb5.c $(srcdir)/t_saslname.c \ $(srcdir)/t_spnego.c $(srcdir)/t_srcattrs.c --OBJS= ccinit.o ccrefresh.o common.o t_accname.o t_add_cred.o t_ccselect.o \ +-OBJS= ccinit.o ccrefresh.o common.o reload.o t_accname.o t_add_cred.o t_ccselect.o \ - t_ciflags.o t_context.o t_credstore.o t_enctypes.o t_err.o \ - t_export_cred.o t_export_name.o t_gssexts.o t_imp_cred.o t_imp_name.o \ - t_invalid.o t_inq_cred.o t_inq_ctx.o t_inq_mechs_name.o t_iov.o \ - t_lifetime.o t_namingexts.o t_oid.o t_pcontok.o t_prf.o t_s4u.o \ - t_s4u2proxy_krb5.o t_saslname.o t_spnego.o t_srcattrs.o -+OBJS= ccinit.o ccrefresh.o common.o t_accname.o t_add_cred.o t_bindings.o \ -+ t_ccselect.o t_ciflags.o t_context.o t_credstore.o t_enctypes.o \ -+ t_err.o t_export_cred.o t_export_name.o t_gssexts.o t_imp_cred.o \ -+ t_imp_name.o t_invalid.o t_inq_cred.o t_inq_ctx.o t_inq_mechs_name.o \ -+ t_iov.o t_lifetime.o t_namingexts.o t_oid.o t_pcontok.o t_prf.o \ -+ t_s4u.o t_s4u2proxy_krb5.o t_saslname.o t_spnego.o t_srcattrs.o ++ ++OBJS= ccinit.o ccrefresh.o common.o reload.o t_accname.o t_add_cred.o \ ++ t_bindings.o t_ccselect.o t_ciflags.o t_context.o t_credstore.o \ ++ t_enctypes.o t_err.o t_export_cred.o t_export_name.o t_gssexts.o \ ++ t_imp_cred.o t_imp_name.o t_invalid.o t_inq_cred.o t_inq_ctx.o \ ++ t_inq_mechs_name.o t_iov.o t_lifetime.o t_namingexts.o t_oid.o \ ++ t_pcontok.o t_prf.o t_s4u.o t_s4u2proxy_krb5.o t_saslname.o \ ++ t_spnego.o t_srcattrs.o COMMON_DEPS= common.o $(GSS_DEPLIBS) $(KRB5_BASE_DEPLIBS) COMMON_LIBS= common.o $(GSS_LIBS) $(KRB5_BASE_LIBS) @@ -113,11 +118,11 @@ index 5cc1e0f58..68c132b79 100644 + t_inq_mechs_name t_iov t_lifetime t_namingexts t_oid t_pcontok t_prf \ + t_s4u t_s4u2proxy_krb5 t_saslname t_spnego t_srcattrs - check-unix: t_oid + check-unix: t_oid reload $(RUN_TEST) ./t_invalid -@@ -43,11 +43,12 @@ check-unix: t_oid - $(RUN_TEST) ./t_prf +@@ -44,11 +46,12 @@ check-unix: t_oid reload $(RUN_TEST) ./t_imp_name + if [ -r $(TOPLIBD)/libgssapi_krb5.so ]; then $(RUN_TEST) ./reload; fi -check-pytests: ccinit ccrefresh t_accname t_add_cred t_ccselect t_ciflags \ - t_context t_credstore t_enctypes t_err t_export_cred t_export_name \ @@ -132,7 +137,7 @@ index 5cc1e0f58..68c132b79 100644 $(RUNPYTEST) $(srcdir)/t_ccselect.py $(PYTESTFLAGS) $(RUNPYTEST) $(srcdir)/t_client_keytab.py $(PYTESTFLAGS) $(RUNPYTEST) $(srcdir)/t_enctypes.py $(PYTESTFLAGS) -@@ -64,6 +65,8 @@ t_accname: t_accname.o $(COMMON_DEPS) +@@ -67,6 +70,8 @@ t_accname: t_accname.o $(COMMON_DEPS) $(CC_LINK) -o $@ t_accname.o $(COMMON_LIBS) t_add_cred: t_add_cred.o $(COMMON_DEPS) $(CC_LINK) -o $@ t_add_cred.o $(COMMON_LIBS) @@ -141,17 +146,20 @@ index 5cc1e0f58..68c132b79 100644 t_ccselect: t_ccselect.o $(COMMON_DEPS) $(CC_LINK) -o $@ t_ccselect.o $(COMMON_LIBS) t_ciflags: t_ciflags.o $(COMMON_DEPS) -@@ -118,8 +121,8 @@ t_srcattrs: t_srcattrs.o $(COMMON_DEPS) +@@ -121,9 +126,9 @@ t_srcattrs: t_srcattrs.o $(COMMON_DEPS) $(CC_LINK) -o $@ t_srcattrs.o $(COMMON_LIBS) clean: -- $(RM) ccinit ccrefresh t_accname t_add_cred t_ccselect t_ciflags +- $(RM) ccinit ccrefresh reload t_accname t_add_cred t_ccselect t_ciflags - $(RM) t_context t_credstore t_enctypes t_err t_export_cred -+ $(RM) ccinit ccrefresh t_accname t_add_cred t_bindings t_ccselect -+ $(RM) t_ciflags t_context t_credstore t_enctypes t_err t_export_cred - $(RM) t_export_name t_gssexts t_imp_cred t_imp_name t_invalid - $(RM) t_inq_cred t_inq_ctx t_inq_mechs_name t_iov t_lifetime +- $(RM) t_export_name t_gssexts t_imp_cred t_imp_name t_invalid +- $(RM) t_inq_cred t_inq_ctx t_inq_mechs_name t_iov t_lifetime ++ $(RM) ccinit ccrefresh reload t_accname t_add_cred t_bindings ++ $(RM) t_ccselect t_ciflags t_context t_credstore t_enctypes t_err ++ $(RM) t_export_cred t_export_name t_gssexts t_imp_cred t_imp_name ++ $(RM) t_invalid t_inq_cred t_inq_ctx t_inq_mechs_name t_iov t_lifetime $(RM) t_namingexts t_oid t_pcontok t_prf t_s4u t_s4u2proxy_krb5 + $(RM) t_saslname t_spnego t_srcattrs diff --git a/src/tests/gssapi/common.c b/src/tests/gssapi/common.c index 83e9d9bb8..7ba72f7b2 100644 --- a/src/tests/gssapi/common.c @@ -221,10 +229,10 @@ index ae11b51d4..a5c8f87e6 100644 * the token. */ void export_import_cred(gss_cred_id_t *cred); diff --git a/src/tests/gssapi/deps b/src/tests/gssapi/deps -index acd0e96f8..73e4d9a74 100644 +index 55586de53..ca1d6e22a 100644 --- a/src/tests/gssapi/deps +++ b/src/tests/gssapi/deps -@@ -33,6 +33,10 @@ $(OUTPRE)t_add_cred.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ +@@ -35,6 +35,10 @@ $(OUTPRE)t_add_cred.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ $(BUILDTOP)/include/gssapi/gssapi_ext.h $(BUILDTOP)/include/gssapi/gssapi_krb5.h \ $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h \ common.h t_add_cred.c diff --git a/Add-client_aware_channel_bindings-option.patch b/Add-client_aware_channel_bindings-option.patch index bd3bcba..142e1d9 100644 --- a/Add-client_aware_channel_bindings-option.patch +++ b/Add-client_aware_channel_bindings-option.patch @@ -1,4 +1,4 @@ -From 46ec975eb8f33b6d42c440758fc0deb826f87313 Mon Sep 17 00:00:00 2001 +From 849bb23d0044b2ff315608784c0f96b81feb472f Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 10 Mar 2020 13:13:17 +0100 Subject: [PATCH] Add client_aware_channel_bindings option diff --git a/Add-finalization-safety-check-to-com_err.patch b/Add-finalization-safety-check-to-com_err.patch index a7ebd53..9411b15 100644 --- a/Add-finalization-safety-check-to-com_err.patch +++ b/Add-finalization-safety-check-to-com_err.patch @@ -1,4 +1,4 @@ -From 96a36ef54aecb48b71c1ae0cc85b83ef644c3bd0 Mon Sep 17 00:00:00 2001 +From 73f1db69f99462b5109a5dd4e1a9476667bd3715 Mon Sep 17 00:00:00 2001 From: Jiri Sasek Date: Fri, 13 Mar 2020 19:02:58 +0100 Subject: [PATCH] Add finalization safety check to com_err diff --git a/Add-recursion-limit-for-ASN.1-indefinite-lengths.patch b/Add-recursion-limit-for-ASN.1-indefinite-lengths.patch deleted file mode 100644 index bc1229c..0000000 --- a/Add-recursion-limit-for-ASN.1-indefinite-lengths.patch +++ /dev/null @@ -1,97 +0,0 @@ -From b7aca8b57422cdc67a2d2bff385f09646ca037bc Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 31 Oct 2020 17:07:05 -0400 -Subject: [PATCH] Add recursion limit for ASN.1 indefinite lengths - -The libkrb5 ASN.1 decoder supports BER indefinite lengths. It -computes the tag length using recursion; the lack of a recursion limit -allows an attacker to overrun the stack and cause the process to -crash. Reported by Demi Obenour. - -CVE-2020-28196: - -In MIT krb5 releases 1.11 and later, an unauthenticated attacker can -cause a denial of service for any client or server to which it can -send an ASN.1-encoded Kerberos message of sufficient length. - -ticket: 8959 (new) -tags: pullup -target_version: 1.18-next -target_version: 1.17-next - -(cherry picked from commit 57415dda6cf04e73ffc3723be518eddfae599bfd) ---- - src/lib/krb5/asn.1/asn1_encode.c | 16 +++++++++------- - 1 file changed, 9 insertions(+), 7 deletions(-) - -diff --git a/src/lib/krb5/asn.1/asn1_encode.c b/src/lib/krb5/asn.1/asn1_encode.c -index a160cf4fe..cd6b879f7 100644 ---- a/src/lib/krb5/asn.1/asn1_encode.c -+++ b/src/lib/krb5/asn.1/asn1_encode.c -@@ -356,7 +356,7 @@ make_tag(asn1buf *buf, const taginfo *t, size_t len) - static krb5_error_code - get_tag(const uint8_t *asn1, size_t len, taginfo *tag_out, - const uint8_t **contents_out, size_t *clen_out, -- const uint8_t **remainder_out, size_t *rlen_out) -+ const uint8_t **remainder_out, size_t *rlen_out, int recursion) - { - krb5_error_code ret; - uint8_t o; -@@ -394,9 +394,11 @@ get_tag(const uint8_t *asn1, size_t len, taginfo *tag_out, - /* Indefinite form (should not be present in DER, but we accept it). */ - if (tag_out->construction != CONSTRUCTED) - return ASN1_MISMATCH_INDEF; -+ if (recursion >= 32) -+ return ASN1_OVERFLOW; - p = asn1; - while (!(len >= 2 && p[0] == 0 && p[1] == 0)) { -- ret = get_tag(p, len, &t, &c, &clen, &p, &len); -+ ret = get_tag(p, len, &t, &c, &clen, &p, &len, recursion + 1); - if (ret) - return ret; - } -@@ -613,7 +615,7 @@ split_der(asn1buf *buf, uint8_t *const *der, size_t len, taginfo *tag_out) - const uint8_t *contents, *remainder; - size_t clen, rlen; - -- ret = get_tag(*der, len, tag_out, &contents, &clen, &remainder, &rlen); -+ ret = get_tag(*der, len, tag_out, &contents, &clen, &remainder, &rlen, 0); - if (ret) - return ret; - if (rlen != 0) -@@ -1199,7 +1201,7 @@ decode_atype(const taginfo *t, const uint8_t *asn1, size_t len, - const uint8_t *rem; - size_t rlen; - if (!tag->implicit) { -- ret = get_tag(asn1, len, &inner_tag, &asn1, &len, &rem, &rlen); -+ ret = get_tag(asn1, len, &inner_tag, &asn1, &len, &rem, &rlen, 0); - if (ret) - return ret; - /* Note: we don't check rlen (it should be 0). */ -@@ -1420,7 +1422,7 @@ decode_sequence(const uint8_t *asn1, size_t len, const struct seq_info *seq, - for (i = 0; i < seq->n_fields; i++) { - if (len == 0) - break; -- ret = get_tag(asn1, len, &t, &contents, &clen, &asn1, &len); -+ ret = get_tag(asn1, len, &t, &contents, &clen, &asn1, &len, 0); - if (ret) - goto error; - /* -@@ -1478,7 +1480,7 @@ decode_sequence_of(const uint8_t *asn1, size_t len, - *seq_out = NULL; - *count_out = 0; - while (len > 0) { -- ret = get_tag(asn1, len, &t, &contents, &clen, &asn1, &len); -+ ret = get_tag(asn1, len, &t, &contents, &clen, &asn1, &len, 0); - if (ret) - goto error; - if (!check_atype_tag(elemtype, &t)) { -@@ -1584,7 +1586,7 @@ k5_asn1_full_decode(const krb5_data *code, const struct atype_info *a, - - *retrep = NULL; - ret = get_tag((uint8_t *)code->data, code->length, &t, &contents, -- &clen, &remainder, &rlen); -+ &clen, &remainder, &rlen, 0); - if (ret) - return ret; - /* rlen should be 0, but we don't check it (and due to padding in diff --git a/Add-three-kvno-options-from-Heimdal-kgetcred.patch b/Add-three-kvno-options-from-Heimdal-kgetcred.patch index 40a6318..9cb1386 100644 --- a/Add-three-kvno-options-from-Heimdal-kgetcred.patch +++ b/Add-three-kvno-options-from-Heimdal-kgetcred.patch @@ -1,4 +1,4 @@ -From 538d787aa7c10894cc0426f54db0d8248efcf7c9 Mon Sep 17 00:00:00 2001 +From ba21ad84f7c8317a595ded1e657c7985fa4b90e1 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 17 Jun 2020 20:48:38 -0400 Subject: [PATCH] Add three kvno options from Heimdal kgetcred @@ -13,20 +13,21 @@ tests for the new options. ticket: 8917 (new) (cherry picked from commit 876bab8418d7dd134c9d9db812ee2118d5ad58f0) +[rharwood@redhat.com: slush around option unification] --- doc/user/user_commands/kvno.rst | 13 ++++ src/clients/kvno/Makefile.in | 3 + - src/clients/kvno/kvno.c | 115 +++++++++++++++++++++++--------- + src/clients/kvno/kvno.c | 113 +++++++++++++++++++++++--------- src/clients/kvno/t_kvno.py | 75 +++++++++++++++++++++ src/man/kvno.man | 13 ++++ - 5 files changed, 187 insertions(+), 32 deletions(-) + 5 files changed, 185 insertions(+), 32 deletions(-) create mode 100644 src/clients/kvno/t_kvno.py diff --git a/doc/user/user_commands/kvno.rst b/doc/user/user_commands/kvno.rst -index 3892f0ca5..718313576 100644 +index 53e569651..6fd8577a5 100644 --- a/doc/user/user_commands/kvno.rst +++ b/doc/user/user_commands/kvno.rst -@@ -74,6 +74,19 @@ OPTIONS +@@ -75,6 +75,19 @@ OPTIONS client principal with the X.509 certificate in *cert_file*. The certificate file must be in PEM format. @@ -61,17 +62,16 @@ index 1c3f79392..5ba877271 100644 $(RM) kvno.o kvno diff --git a/src/clients/kvno/kvno.c b/src/clients/kvno/kvno.c -index 2472c0cfe..9d85864f6 100644 +index 8edd97361..55e7dd0ce 100644 --- a/src/clients/kvno/kvno.c +++ b/src/clients/kvno/kvno.c -@@ -44,14 +44,17 @@ xusage() - fprintf(stderr, _("usage: %s [-C] [-u] [-c ccache] [-e etype]\n"), prog); - fprintf(stderr, _("\t[-k keytab] [-S sname] [{-I | -U} for_user | " - "[-F cert_file] [-P]]\n")); -- fprintf(stderr, _("\t[--u2u ccache] service1 service2 ...\n")); -+ fprintf(stderr, _("\t[--cached-only] [--no-store] [--out-cache ccache] " -+ "[--u2u ccache]\n")); -+ fprintf(stderr, _("\tservice1 service2 ...\n")); +@@ -47,15 +47,16 @@ xusage() + "[-u | -S sname]" XUSAGE_BREAK + "[[{-F cert_file | {-I | -U} for_user} [-P]] | " + "--u2u ccache]" XUSAGE_BREAK ++ "[--cached-only] [--no-store] [--out-cache] " + "service1 service2 ...\n"), +- prog); exit(1); } @@ -86,7 +86,7 @@ index 2472c0cfe..9d85864f6 100644 const char *u2u_ccname); #include -@@ -61,18 +64,21 @@ static void extended_com_err_fn(const char *myprog, errcode_t code, +@@ -65,18 +66,21 @@ static void extended_com_err_fn(const char *myprog, errcode_t code, int main(int argc, char *argv[]) { @@ -115,7 +115,7 @@ index 2472c0cfe..9d85864f6 100644 setlocale(LC_ALL, ""); set_com_err_hook(extended_com_err_fn); -@@ -135,6 +141,12 @@ main(int argc, char *argv[]) +@@ -139,6 +143,12 @@ main(int argc, char *argv[]) case OPTION_U2U: u2u_ccname = optarg; break; @@ -128,7 +128,7 @@ index 2472c0cfe..9d85864f6 100644 default: xusage(); break; -@@ -159,8 +171,9 @@ main(int argc, char *argv[]) +@@ -163,8 +173,9 @@ main(int argc, char *argv[]) xusage(); do_v5_kvno(argc - optind, argv + optind, ccachestr, etypestr, keytab_name, @@ -140,7 +140,7 @@ index 2472c0cfe..9d85864f6 100644 return 0; } -@@ -274,14 +287,16 @@ static krb5_error_code +@@ -278,14 +289,16 @@ static krb5_error_code kvno(const char *name, krb5_ccache ccache, krb5_principal me, krb5_enctype etype, krb5_keytab keytab, const char *sname, krb5_flags options, int unknown, krb5_principal for_user_princ, @@ -159,7 +159,7 @@ index 2472c0cfe..9d85864f6 100644 memset(&in_creds, 0, sizeof(in_creds)); if (sname != NULL) { -@@ -321,13 +336,12 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, +@@ -325,13 +338,12 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, in_creds.client = for_user_princ; in_creds.server = me; ret = krb5_get_credentials_for_user(context, options, ccache, @@ -175,7 +175,7 @@ index 2472c0cfe..9d85864f6 100644 } if (ret) { -@@ -336,7 +350,7 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, +@@ -340,7 +352,7 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, } /* We need a native ticket. */ @@ -184,7 +184,7 @@ index 2472c0cfe..9d85864f6 100644 if (ret) { com_err(prog, ret, _("while decoding ticket for %s"), princ); goto cleanup; -@@ -362,15 +376,15 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, +@@ -366,15 +378,15 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, } if (proxy) { @@ -205,7 +205,7 @@ index 2472c0cfe..9d85864f6 100644 krb5_free_principal(context, in_creds.client); if (ret) { com_err(prog, ret, _("%s: constrained delegation failed"), -@@ -379,10 +393,13 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, +@@ -383,10 +395,13 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, } } @@ -220,7 +220,7 @@ index 2472c0cfe..9d85864f6 100644 krb5_free_unparsed_name(context, princ); return ret; } -@@ -428,19 +445,28 @@ cleanup: +@@ -432,19 +447,28 @@ cleanup: static void do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, @@ -255,7 +255,7 @@ index 2472c0cfe..9d85864f6 100644 ret = krb5_init_context(&context); if (ret) { -@@ -467,6 +493,14 @@ do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, +@@ -471,6 +495,14 @@ do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, exit(1); } @@ -270,7 +270,7 @@ index 2472c0cfe..9d85864f6 100644 if (keytab_name != NULL) { ret = krb5_kt_resolve(context, keytab_name, &keytab); if (ret) { -@@ -513,8 +547,25 @@ do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, +@@ -517,8 +549,25 @@ do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, errors = 0; for (i = 0; i < count; i++) { if (kvno(names[i], ccache, me, etype, keytab, sname, options, unknown, @@ -379,10 +379,10 @@ index 000000000..e98b90e8a + +success('kvno tests') diff --git a/src/man/kvno.man b/src/man/kvno.man -index 005a2ec97..b9f6739eb 100644 +index 9eb9e1852..7c9565bdb 100644 --- a/src/man/kvno.man +++ b/src/man/kvno.man -@@ -95,6 +95,19 @@ Specifies that protocol transition is to be used, identifying the +@@ -96,6 +96,19 @@ Specifies that protocol transition is to be used, identifying the client principal with the X.509 certificate in \fIcert_file\fP\&. The certificate file must be in PEM format. .TP diff --git a/Adjust-KDC-alias-helper-function-contract.patch b/Adjust-KDC-alias-helper-function-contract.patch index 7b7c62b..0046bb4 100644 --- a/Adjust-KDC-alias-helper-function-contract.patch +++ b/Adjust-KDC-alias-helper-function-contract.patch @@ -1,4 +1,4 @@ -From 758f5031fe9d6c1e3eb33818bc6d57cf8b4a3a72 Mon Sep 17 00:00:00 2001 +From cf853d10b13dca77acd08d1387e94527994f9ef5 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 22 Sep 2020 01:11:39 +0300 Subject: [PATCH] Adjust KDC alias helper function contract diff --git a/Allow-aliases-when-matching-U2U-second-ticket.patch b/Allow-aliases-when-matching-U2U-second-ticket.patch index 8622ff8..07519e1 100644 --- a/Allow-aliases-when-matching-U2U-second-ticket.patch +++ b/Allow-aliases-when-matching-U2U-second-ticket.patch @@ -1,4 +1,4 @@ -From ccc5b9663e229f20421c01836aa5ecb06f1f2a48 Mon Sep 17 00:00:00 2001 +From 5a9b4d190906a8b11a7e1f707d1ea1930ce2fd31 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 22 Sep 2020 01:17:11 +0300 Subject: [PATCH] Allow aliases when matching U2U second ticket diff --git a/Allow-certauth-modules-to-set-hw-authent-flag.patch b/Allow-certauth-modules-to-set-hw-authent-flag.patch index 94ff5dd..0c155e7 100644 --- a/Allow-certauth-modules-to-set-hw-authent-flag.patch +++ b/Allow-certauth-modules-to-set-hw-authent-flag.patch @@ -1,4 +1,4 @@ -From 5b62f6f6a960e5a428a39a3e83e0a16dba5a914a Mon Sep 17 00:00:00 2001 +From c18034484eadb0f32cef384197d1185aa50c3adb Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 24 Feb 2020 15:58:59 -0500 Subject: [PATCH] Allow certauth modules to set hw-authent flag diff --git a/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch b/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch deleted file mode 100644 index 3824646..0000000 --- a/Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch +++ /dev/null @@ -1,49 +0,0 @@ -From 594c9d225f470e73a46dd2a85c5e50571e90598c Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 11 Jul 2020 21:57:30 -0400 -Subject: [PATCH] Allow gss_unwrap_iov() of unpadded RC4 tokens - -Windows Remote Management, when used with an RC4 session key, appears -to generate GSS wrap tokens with no padding instead of the expected -one byte (RFC 4757 section 7.3). These tokens cannot be decoded with -gss_unwrap() or a STREAM buffer (even with Microsoft SSPI), but SSPI -allows them to be decoded using explicit IOVs with either a -zero-length padding buffer or no padding buffer. Allow these cases to -work in kg_fixup_padding_iov(). (It is already possible to make this -work with HEADER | DATA | DATA, but only by -accident--kg_fixup_padding_iov() doesn't find a data buffer because -kg_locate_iov() only looks for singleton buffers, so it exits early.) - -ticket: 8926 (new) -tags: pullup -target_version: 1.18-next - -(cherry picked from commit 3f204ddd567715ef360b4bb0b32961b6a9877f9d) ---- - src/lib/gssapi/krb5/util_crypt.c | 9 +++------ - 1 file changed, 3 insertions(+), 6 deletions(-) - -diff --git a/src/lib/gssapi/krb5/util_crypt.c b/src/lib/gssapi/krb5/util_crypt.c -index f7d3e92c4..d6c71aeb8 100644 ---- a/src/lib/gssapi/krb5/util_crypt.c -+++ b/src/lib/gssapi/krb5/util_crypt.c -@@ -638,16 +638,13 @@ kg_fixup_padding_iov(OM_uint32 *minor_status, gss_iov_buffer_desc *iov, - data = kg_locate_iov(iov, iov_count, GSS_IOV_BUFFER_TYPE_DATA); - padding = kg_locate_iov(iov, iov_count, GSS_IOV_BUFFER_TYPE_PADDING); - -- if (data == NULL) { -+ /* Do nothing if padding is absent or empty, to allow unwrapping of WinRM -+ * unpadded RC4 tokens using an explicit IOV array. */ -+ if (data == NULL || padding == NULL || padding->buffer.length == 0) { - *minor_status = 0; - return GSS_S_COMPLETE; - } - -- if (padding == NULL || padding->buffer.length == 0) { -- *minor_status = EINVAL; -- return GSS_S_FAILURE; -- } -- - p = (unsigned char *)padding->buffer.value; - padlength = p[padding->buffer.length - 1]; - diff --git a/Avoid-passing-DB-entry-structures-in-KDC.patch b/Avoid-passing-DB-entry-structures-in-KDC.patch index e5cff1a..aeb20ad 100644 --- a/Avoid-passing-DB-entry-structures-in-KDC.patch +++ b/Avoid-passing-DB-entry-structures-in-KDC.patch @@ -1,4 +1,4 @@ -From dd8b146093d4bdf8a7d0c0eb8156b62d090448d7 Mon Sep 17 00:00:00 2001 +From f5987c71188138626030eef62145a126a84b62fb Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 30 Sep 2020 02:12:00 -0400 Subject: [PATCH] Avoid passing DB entry structures in KDC diff --git a/Correctly-import-service-GSS-host-based-name.patch b/Correctly-import-service-GSS-host-based-name.patch index f56aed4..e56648b 100644 --- a/Correctly-import-service-GSS-host-based-name.patch +++ b/Correctly-import-service-GSS-host-based-name.patch @@ -1,4 +1,4 @@ -From f56afbeb7848322f3208edd55f2c12a9e32127f0 Mon Sep 17 00:00:00 2001 +From 24c5e1ad937505a03628547ed7a5c6060a2b0ff2 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 30 Mar 2020 15:26:02 -0400 Subject: [PATCH] Correctly import "service@" GSS host-based name diff --git a/Default-dns_canonicalize_hostname-to-fallback.patch b/Default-dns_canonicalize_hostname-to-fallback.patch index 1c46562..3669432 100644 --- a/Default-dns_canonicalize_hostname-to-fallback.patch +++ b/Default-dns_canonicalize_hostname-to-fallback.patch @@ -1,4 +1,4 @@ -From c3d2c3bcafe0ac87d9cbbf37f1488ad642627fc3 Mon Sep 17 00:00:00 2001 +From 6bdab27ef3dfcefb8426f2ea4e06bbdbd1141b16 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 27 May 2020 18:48:35 -0400 Subject: [PATCH] Default dns_canonicalize_hostname to "fallback" diff --git a/Do-expiration-warnings-for-all-init_creds-APIs.patch b/Do-expiration-warnings-for-all-init_creds-APIs.patch index 4f642f4..374068f 100644 --- a/Do-expiration-warnings-for-all-init_creds-APIs.patch +++ b/Do-expiration-warnings-for-all-init_creds-APIs.patch @@ -1,4 +1,4 @@ -From 51a9f8e7498591b22558a7a61d42a821030f9c4e Mon Sep 17 00:00:00 2001 +From c7abf942c66b2ba543cf412f12562e9bb8ee260a Mon Sep 17 00:00:00 2001 From: Sumit Bose Date: Fri, 28 Feb 2020 10:11:49 +0100 Subject: [PATCH] Do expiration warnings for all init_creds APIs diff --git a/Eliminate-redundant-PKINIT-responder-invocation.patch b/Eliminate-redundant-PKINIT-responder-invocation.patch deleted file mode 100644 index 48e6e89..0000000 --- a/Eliminate-redundant-PKINIT-responder-invocation.patch +++ /dev/null @@ -1,93 +0,0 @@ -From b27a2f1f330afed53b034a66031f9a801b4568b7 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 23 Mar 2020 19:10:03 -0400 -Subject: [PATCH] Eliminate redundant PKINIT responder invocation - -In pkinit_client_prep_questions(), only act if the input padata type -is KRB5_PADATA_PK_AS_REQ. Otherwise we will ask questions again when -the KDC issues a ticket. - -Commit 7621d2f9a87214327ca3b2594e34dc7cea84596b (ticket 8242) -unintentionally changed the behavior of pkinit_load_fs_cert_and_key(), -causing pkinit_client_prep_questions() to do nothing on its first -call. Restore the original behavior of returning 0 when prompting is -deferred. - -Modify the existing "FILE identity, password on key (responder)" -PKINIT test to check that the responder is only invoked once. - -ticket: 8885 -(cherry picked from commit f1286842ce7b9e507a4ce0a47f44ab361a98be63) ---- - src/plugins/preauth/pkinit/pkinit_clnt.c | 5 +++++ - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 13 +++++++------ - src/tests/t_pkinit.py | 11 +++++++---- - 3 files changed, 19 insertions(+), 10 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c -index 2f0431991..9b991ffe0 100644 ---- a/src/plugins/preauth/pkinit/pkinit_clnt.c -+++ b/src/plugins/preauth/pkinit/pkinit_clnt.c -@@ -897,6 +897,11 @@ pkinit_client_prep_questions(krb5_context context, - k5_json_object jval = NULL; - k5_json_number jflag = NULL; - -+ /* Don't ask questions for the informational padata items or when the -+ * ticket is issued. */ -+ if (pa_data->pa_type != KRB5_PADATA_PK_AS_REQ) -+ return 0; -+ - if (!reqctx->identity_initialized) { - pkinit_client_profile(context, plgctx, reqctx, cb, rock, - &request->server->realm); -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index dd718c2be..dbb054378 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -4362,17 +4362,18 @@ pkinit_load_fs_cert_and_key(krb5_context context, - - /* Load the certificate. */ - retval = get_cert(certname, &x); -- if (retval != 0 || x == NULL) { -- retval = oerr(context, 0, _("Cannot read certificate file '%s'"), -+ if (retval) { -+ retval = oerr(context, retval, _("Cannot read certificate file '%s'"), - certname); -- goto cleanup; - } -+ if (retval || x == NULL) -+ goto cleanup; - /* Load the key. */ - retval = get_key(context, id_cryptoctx, keyname, fsname, &y, password); -- if (retval != 0 || y == NULL) { -- retval = oerr(context, 0, _("Cannot read key file '%s'"), fsname); -+ if (retval) -+ retval = oerr(context, retval, _("Cannot read key file '%s'"), fsname); -+ if (retval || y == NULL) - goto cleanup; -- } - - id_cryptoctx->creds[cindex] = malloc(sizeof(struct _pkinit_cred_info)); - if (id_cryptoctx->creds[cindex] == NULL) { -diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py -index 69daf4987..ecd450e8a 100755 ---- a/src/tests/t_pkinit.py -+++ b/src/tests/t_pkinit.py -@@ -248,10 +248,13 @@ realm.run(['./adata', realm.host_princ], - # supplied by the responder. - # Supply the response in raw form. - mark('FILE identity, password on key (responder)') --realm.run(['./responder', '-x', 'pkinit={"%s": 0}' % file_enc_identity, -- '-r', 'pkinit={"%s": "encrypted"}' % file_enc_identity, -- '-X', 'X509_user_identity=%s' % file_enc_identity, -- realm.user_princ]) -+out = realm.run(['./responder', '-x', 'pkinit={"%s": 0}' % file_enc_identity, -+ '-r', 'pkinit={"%s": "encrypted"}' % file_enc_identity, -+ '-X', 'X509_user_identity=%s' % file_enc_identity, -+ realm.user_princ]) -+# Regression test for #8885 (password question asked twice). -+if out.count('OK: ') != 1: -+ fail('Wrong number of responder calls') - # Supply the response through the convenience API. - realm.run(['./responder', '-X', 'X509_user_identity=%s' % file_enc_identity, - '-p', '%s=%s' % (file_enc_identity, 'encrypted'), realm.user_princ]) diff --git a/Fix-input-length-checking-in-SPNEGO-DER-decoding.patch b/Fix-input-length-checking-in-SPNEGO-DER-decoding.patch deleted file mode 100644 index ae01c8d..0000000 --- a/Fix-input-length-checking-in-SPNEGO-DER-decoding.patch +++ /dev/null @@ -1,58 +0,0 @@ -From 5b42970afea248889fd3350448a40045d467ff3f Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 28 Jul 2020 12:58:26 -0400 -Subject: [PATCH] Fix input length checking in SPNEGO DER decoding - -In get_mech_set(), check the length before reading the first byte, and -decrease the length by the tag byte when reading and verifying the -sequence length. - -In get_req_flags(), check the length before reading the first byte, -and check the context tag length after decoding it. - -ticket: 8933 (new) -tags: pullup -target_version: 1.18-next -target_version: 1.17-next - -(cherry picked from commit 64f4b75a22212681ca293f8f09ddd24b0244d5b4) ---- - src/lib/gssapi/spnego/spnego_mech.c | 10 +++++----- - 1 file changed, 5 insertions(+), 5 deletions(-) - -diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/spnego/spnego_mech.c -index 4cf011143..13c351620 100644 ---- a/src/lib/gssapi/spnego/spnego_mech.c -+++ b/src/lib/gssapi/spnego/spnego_mech.c -@@ -3462,14 +3462,14 @@ get_mech_set(OM_uint32 *minor_status, unsigned char **buff_in, - unsigned char *start; - int i; - -- if (**buff_in != SEQUENCE_OF) -+ if (buff_length < 1 || **buff_in != SEQUENCE_OF) - return (NULL); - - start = *buff_in; - (*buff_in)++; - -- length = gssint_get_der_length(buff_in, buff_length, &bytes); -- if (length < 0 || buff_length - bytes < (unsigned int)length) -+ length = gssint_get_der_length(buff_in, buff_length - 1, &bytes); -+ if (length < 0 || buff_length - 1 - bytes < (unsigned int)length) - return NULL; - - major_status = gss_create_empty_oid_set(minor_status, -@@ -3549,11 +3549,11 @@ get_req_flags(unsigned char **buff_in, OM_uint32 bodysize, - { - unsigned int len; - -- if (**buff_in != (CONTEXT | 0x01)) -+ if (bodysize < 1 || **buff_in != (CONTEXT | 0x01)) - return (0); - - if (g_get_tag_and_length(buff_in, (CONTEXT | 0x01), -- bodysize, &len) < 0) -+ bodysize, &len) < 0 || len != 4) - return GSS_S_DEFECTIVE_TOKEN; - - if (*(*buff_in)++ != BIT_STRING) diff --git a/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch b/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch index c5ec79a..90bbcab 100644 --- a/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch +++ b/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch @@ -1,4 +1,4 @@ -From ff47523d7d812fba24106f416aafa5d1f2c433a2 Mon Sep 17 00:00:00 2001 +From 4b2176eaad00630890abe4b458cbc31f05b2b9c0 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 24 Jul 2020 16:05:24 -0400 Subject: [PATCH] Fix leak in KERB_AP_OPTIONS_CBT server support diff --git a/Fix-minor-static-analysis-defects.patch b/Fix-minor-static-analysis-defects.patch index 653bce1..644df97 100644 --- a/Fix-minor-static-analysis-defects.patch +++ b/Fix-minor-static-analysis-defects.patch @@ -1,4 +1,4 @@ -From c3d96fca46cb2cc3ee9f4c2e2a4ed98bad3e310a Mon Sep 17 00:00:00 2001 +From ae153c1dbb91782e1c8d5e80be9e133766eb81fd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 15 Oct 2020 18:15:29 -0400 Subject: [PATCH] Fix minor static analysis defects diff --git a/Fix-typo-in-in-in-the-ksu-man-page.patch b/Fix-typo-in-in-in-the-ksu-man-page.patch index 040355c..a6c1f5c 100644 --- a/Fix-typo-in-in-in-the-ksu-man-page.patch +++ b/Fix-typo-in-in-in-the-ksu-man-page.patch @@ -1,4 +1,4 @@ -From bf8567ed95991628f198e88403e30f78e2d74e15 Mon Sep 17 00:00:00 2001 +From 5399eaea6c5e00c4e96fa5507aa50dd643337194 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 May 2020 15:01:18 -0400 Subject: [PATCH] Fix typo ("in in") in the ksu man page @@ -23,7 +23,7 @@ index 8d6c7ef79..933738229 100644 diff --git a/src/man/ksu.man b/src/man/ksu.man -index 81e34815d..8d4c6a359 100644 +index a1972518c..b07a4b05d 100644 --- a/src/man/ksu.man +++ b/src/man/ksu.man @@ -176,7 +176,7 @@ wrong password is typed in, ksu fails. diff --git a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch index 14e27a9..01edf16 100644 --- a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch +++ b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch @@ -1,4 +1,4 @@ -From e74f9424e47ab914c46e549fc5a2cbdf2615ef93 Mon Sep 17 00:00:00 2001 +From 6931f8ed0fd8c9f634e1e48f1e8926022610fc3f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 15 Jul 2020 15:42:20 -0400 Subject: [PATCH] Ignore bad enctypes in krb5_string_to_keysalts() diff --git a/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch b/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch index 2b41b6b..d93a3f8 100644 --- a/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch +++ b/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch @@ -1,4 +1,4 @@ -From 651b9b8084ecff5553b7ef6ee723ce7c4438a9d8 Mon Sep 17 00:00:00 2001 +From 40093f65c58ab78a050860ce41560595aa8ecf7e Mon Sep 17 00:00:00 2001 From: Alexander Scheel Date: Wed, 5 Jul 2017 11:38:30 -0400 Subject: [PATCH] Implement GSS_C_CHANNEL_BOUND_FLAG diff --git a/Implement-KERB_AP_OPTIONS_CBT-server-side.patch b/Implement-KERB_AP_OPTIONS_CBT-server-side.patch index eadc695..a43ae8b 100644 --- a/Implement-KERB_AP_OPTIONS_CBT-server-side.patch +++ b/Implement-KERB_AP_OPTIONS_CBT-server-side.patch @@ -1,4 +1,4 @@ -From bc89c6c720c4170d43010fead23550b80499c32a Mon Sep 17 00:00:00 2001 +From 2250babfa6fc6590d50fc9c9beb267ba280ff685 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Mon, 9 Mar 2020 16:04:21 +0100 Subject: [PATCH] Implement KERB_AP_OPTIONS_CBT (server side) diff --git a/Improve-KDC-alias-checking-for-S4U-requests.patch b/Improve-KDC-alias-checking-for-S4U-requests.patch index 3dbb119..d58ffa5 100644 --- a/Improve-KDC-alias-checking-for-S4U-requests.patch +++ b/Improve-KDC-alias-checking-for-S4U-requests.patch @@ -1,4 +1,4 @@ -From ed87237cdd70f72b309960a294a2bed26cef1579 Mon Sep 17 00:00:00 2001 +From ec23f914a4be4f4ce5a8960ea72f0f45f7c8cf59 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Fri, 4 Sep 2020 14:05:50 +0300 Subject: [PATCH] Improve KDC alias checking for S4U requests diff --git a/Improve-negoex_parse_token-code-hygiene.patch b/Improve-negoex_parse_token-code-hygiene.patch index a58c2e6..ef9bf2b 100644 --- a/Improve-negoex_parse_token-code-hygiene.patch +++ b/Improve-negoex_parse_token-code-hygiene.patch @@ -1,4 +1,4 @@ -From 4c96c8fef146337b7d3c0ebb4118a18818dd1f4e Mon Sep 17 00:00:00 2001 +From d604359e2f0bce65f08d0d805e0795e29287109c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 9 Jun 2020 16:23:37 -0400 Subject: [PATCH] Improve negoex_parse_token() code hygiene diff --git a/Minimize-usage-of-tgs_server-in-KDC.patch b/Minimize-usage-of-tgs_server-in-KDC.patch index f08458e..3e3c740 100644 --- a/Minimize-usage-of-tgs_server-in-KDC.patch +++ b/Minimize-usage-of-tgs_server-in-KDC.patch @@ -1,4 +1,4 @@ -From 5e79319edf3836d12dbc710ec1e2dd4405c9df35 Mon Sep 17 00:00:00 2001 +From 62f5a8c4ef97f0f0f3ceddff8e0a768c5f3b544e Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 25 Sep 2020 11:12:34 -0400 Subject: [PATCH] Minimize usage of tgs_server in KDC diff --git a/Omit-KDC-indicator-check-for-S4U2Self-requests.patch b/Omit-KDC-indicator-check-for-S4U2Self-requests.patch index d5eacc1..782974b 100644 --- a/Omit-KDC-indicator-check-for-S4U2Self-requests.patch +++ b/Omit-KDC-indicator-check-for-S4U2Self-requests.patch @@ -1,4 +1,4 @@ -From f0ac5c1efef5401f669dc176e62c09b0b01fa2d0 Mon Sep 17 00:00:00 2001 +From a9144f5238b91949f32355f5ab88e2ade734eb06 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 6 May 2020 16:03:13 -0400 Subject: [PATCH] Omit KDC indicator check for S4U2Self requests diff --git a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch index 8e1c248..bc4ed52 100644 --- a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch +++ b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch @@ -1,4 +1,4 @@ -From 5251097c927f476fe83ffe544b73fd2d785aaf2a Mon Sep 17 00:00:00 2001 +From 8fc932c8f75e4332aa7dc6c4862cb881308b6813 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Sat, 6 Jun 2020 11:03:37 +0200 Subject: [PATCH] Omit PA_FOR_USER if we can't compute its checksum diff --git a/Pass-channel-bindings-through-SPNEGO.patch b/Pass-channel-bindings-through-SPNEGO.patch index 0e307c3..e376472 100644 --- a/Pass-channel-bindings-through-SPNEGO.patch +++ b/Pass-channel-bindings-through-SPNEGO.patch @@ -1,4 +1,4 @@ -From 17d9b74328f247de5f9d820ae008726632d11d2a Mon Sep 17 00:00:00 2001 +From 19ef4a378a8fe483e82b1b4f979a7ffcb264325e Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 28 Apr 2020 18:15:55 +0200 Subject: [PATCH] Pass channel bindings through SPNEGO @@ -125,7 +125,7 @@ index 18d9d4147..8848ee4db 100644 if (major != GSS_S_COMPLETE && mech_output_token.length == 0) goto cleanup; diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/spnego/spnego_mech.c -index 594fc5894..4cf011143 100644 +index f4a042478..2327cd927 100644 --- a/src/lib/gssapi/spnego/spnego_mech.c +++ b/src/lib/gssapi/spnego/spnego_mech.c @@ -130,6 +130,7 @@ init_ctx_reselect(OM_uint32 *, spnego_gss_ctx_id_t, OM_uint32, @@ -147,7 +147,7 @@ index 594fc5894..4cf011143 100644 static gss_OID negotiate_mech(spnego_gss_ctx_id_t, gss_OID_set, OM_uint32 *); -@@ -905,6 +906,7 @@ init_ctx_call_init(OM_uint32 *minor_status, +@@ -906,6 +907,7 @@ init_ctx_call_init(OM_uint32 *minor_status, OM_uint32 req_flags, OM_uint32 time_req, gss_buffer_t mechtok_in, @@ -155,7 +155,7 @@ index 594fc5894..4cf011143 100644 gss_buffer_t mechtok_out, OM_uint32 *time_rec, send_token_flag *send_token) -@@ -921,15 +923,14 @@ init_ctx_call_init(OM_uint32 *minor_status, +@@ -922,15 +924,14 @@ init_ctx_call_init(OM_uint32 *minor_status, if (gss_oid_equal(sc->internal_mech, &negoex_mech)) { ret = negoex_init(minor_status, sc, mcred, target_name, mech_req_flags, time_req, mechtok_in, @@ -175,7 +175,7 @@ index 594fc5894..4cf011143 100644 } /* Bail out if the acceptor gave us an error token but the mech didn't -@@ -981,8 +982,8 @@ init_ctx_call_init(OM_uint32 *minor_status, +@@ -982,8 +983,8 @@ init_ctx_call_init(OM_uint32 *minor_status, gss_delete_sec_context(&tmpmin, &sc->ctx_handle, GSS_C_NO_BUFFER); tmpret = init_ctx_call_init(&tmpmin, sc, spcred, acc_negState, target_name, req_flags, time_req, @@ -186,7 +186,7 @@ index 594fc5894..4cf011143 100644 if (HARD_ERROR(tmpret)) goto fail; *minor_status = tmpmin; -@@ -1004,7 +1005,7 @@ spnego_gss_init_sec_context( +@@ -1005,7 +1006,7 @@ spnego_gss_init_sec_context( gss_OID mech_type, OM_uint32 req_flags, OM_uint32 time_req, @@ -195,7 +195,7 @@ index 594fc5894..4cf011143 100644 gss_buffer_t input_token, gss_OID *actual_mech, gss_buffer_t output_token, -@@ -1084,8 +1085,8 @@ spnego_gss_init_sec_context( +@@ -1085,8 +1086,8 @@ spnego_gss_init_sec_context( if (!spnego_ctx->mech_complete) { ret = init_ctx_call_init(minor_status, spnego_ctx, spcred, acc_negState, target_name, req_flags, @@ -206,7 +206,7 @@ index 594fc5894..4cf011143 100644 if (ret != GSS_S_COMPLETE) goto cleanup; -@@ -1542,8 +1543,9 @@ cleanup: +@@ -1543,8 +1544,9 @@ cleanup: static OM_uint32 acc_ctx_call_acc(OM_uint32 *minor_status, spnego_gss_ctx_id_t sc, spnego_gss_cred_id_t spcred, gss_buffer_t mechtok_in, @@ -218,7 +218,7 @@ index 594fc5894..4cf011143 100644 { OM_uint32 ret, tmpmin; gss_OID_desc mechoid; -@@ -1568,13 +1570,12 @@ acc_ctx_call_acc(OM_uint32 *minor_status, spnego_gss_ctx_id_t sc, +@@ -1569,13 +1571,12 @@ acc_ctx_call_acc(OM_uint32 *minor_status, spnego_gss_ctx_id_t sc, mcred = (spcred == NULL) ? GSS_C_NO_CREDENTIAL : spcred->mcred; if (negoex) { ret = negoex_accept(minor_status, sc, mcred, mechtok_in, @@ -234,7 +234,7 @@ index 594fc5894..4cf011143 100644 &sc->internal_name, &sc->actual_mech, mechtok_out, &sc->ctx_flags, time_rec, -@@ -1620,7 +1621,7 @@ spnego_gss_accept_sec_context( +@@ -1621,7 +1622,7 @@ spnego_gss_accept_sec_context( gss_ctx_id_t *context_handle, gss_cred_id_t verifier_cred_handle, gss_buffer_t input_token, @@ -243,7 +243,7 @@ index 594fc5894..4cf011143 100644 gss_name_t *src_name, gss_OID *mech_type, gss_buffer_t output_token, -@@ -1734,8 +1735,8 @@ spnego_gss_accept_sec_context( +@@ -1735,8 +1736,8 @@ spnego_gss_accept_sec_context( */ if (negState != REQUEST_MIC && mechtok_in != GSS_C_NO_BUFFER) { ret = acc_ctx_call_acc(minor_status, sc, spcred, mechtok_in, diff --git a/Pass-gss_localname-through-SPNEGO.patch b/Pass-gss_localname-through-SPNEGO.patch index e641a91..bbf703c 100644 --- a/Pass-gss_localname-through-SPNEGO.patch +++ b/Pass-gss_localname-through-SPNEGO.patch @@ -1,4 +1,4 @@ -From cec820485e8b854fe3ee42d0a67a77e7ad20595e Mon Sep 17 00:00:00 2001 +From fb89e83451519aed051bb129f3cf9cc34cde702f Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 26 Apr 2020 19:55:54 -0400 Subject: [PATCH] Pass gss_localname() through SPNEGO @@ -30,7 +30,7 @@ index a93763314..066ec736f 100644 ( OM_uint32 *minor_status, diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/spnego/spnego_mech.c -index ec0bae6a4..594fc5894 100644 +index b3010c201..f4a042478 100644 --- a/src/lib/gssapi/spnego/spnego_mech.c +++ b/src/lib/gssapi/spnego/spnego_mech.c @@ -237,7 +237,7 @@ static struct gss_config spnego_mechanism = @@ -42,7 +42,7 @@ index ec0bae6a4..594fc5894 100644 NULL, /* gss_userok */ NULL, /* gss_export_name */ spnego_gss_duplicate_name, /* gss_duplicate_name */ -@@ -2371,6 +2371,13 @@ spnego_gss_wrap_size_limit( +@@ -2372,6 +2372,13 @@ spnego_gss_wrap_size_limit( return (ret); } diff --git a/Refactor-KDC-authdata-list-management-helpers.patch b/Refactor-KDC-authdata-list-management-helpers.patch index 00aed49..f60e0af 100644 --- a/Refactor-KDC-authdata-list-management-helpers.patch +++ b/Refactor-KDC-authdata-list-management-helpers.patch @@ -1,4 +1,4 @@ -From 9335481c00cd15170adec244ccff0a00a014bbab Mon Sep 17 00:00:00 2001 +From 227828eb22ff0383f76b918899a03e1c7c97a7c0 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 5 Feb 2020 18:46:11 -0500 Subject: [PATCH] Refactor KDC authdata list management helpers diff --git a/Refactor-krb5-GSS-checksum-handling.patch b/Refactor-krb5-GSS-checksum-handling.patch index c80426b..a0bb217 100644 --- a/Refactor-krb5-GSS-checksum-handling.patch +++ b/Refactor-krb5-GSS-checksum-handling.patch @@ -1,4 +1,4 @@ -From c90cef2ebfbefc595798dd5dbb805575e1be0fbf Mon Sep 17 00:00:00 2001 +From 544c37e2928f2585708e36f77a6b0baa52c3c541 Mon Sep 17 00:00:00 2001 From: Alexander Scheel Date: Fri, 30 Jun 2017 16:03:01 -0400 Subject: [PATCH] Refactor krb5 GSS checksum handling diff --git a/Refresh-manually-acquired-creds-from-client-keytab.patch b/Refresh-manually-acquired-creds-from-client-keytab.patch index ff28434..dc50194 100644 --- a/Refresh-manually-acquired-creds-from-client-keytab.patch +++ b/Refresh-manually-acquired-creds-from-client-keytab.patch @@ -1,4 +1,4 @@ -From 7316aaa0e9249a88e919f2596d881f78970548bc Mon Sep 17 00:00:00 2001 +From e1762f16fe4d900903c5395cc3268f9b78835100 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 26 Feb 2020 18:27:17 -0500 Subject: [PATCH] Refresh manually acquired creds from client keytab diff --git a/Remove-resolver-test-utility.patch b/Remove-resolver-test-utility.patch index e5dd78d..e765069 100644 --- a/Remove-resolver-test-utility.patch +++ b/Remove-resolver-test-utility.patch @@ -1,4 +1,4 @@ -From 3e75969e0c0a52ec3ca8195200fcdadaa63b324f Mon Sep 17 00:00:00 2001 +From 8a2cd84c047ef7500dc8149ed6ace8e9fa631cad Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 28 May 2020 18:41:02 -0400 Subject: [PATCH] Remove resolver test utility diff --git a/Replace-gssrpc-tests-with-a-Python-script.patch b/Replace-gssrpc-tests-with-a-Python-script.patch index ced6543..fc8fe87 100644 --- a/Replace-gssrpc-tests-with-a-Python-script.patch +++ b/Replace-gssrpc-tests-with-a-Python-script.patch @@ -1,4 +1,4 @@ -From 404cc1152880a567fc27bb7c691a1a732692bbf9 Mon Sep 17 00:00:00 2001 +From e2ad633616a3f4db91bbd332d778df93e4bdb652 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 15 Feb 2020 20:34:23 -0500 Subject: [PATCH] Replace gssrpc tests with a Python script diff --git a/Unify-kvno-option-documentation.patch b/Unify-kvno-option-documentation.patch deleted file mode 100644 index b6f5e01..0000000 --- a/Unify-kvno-option-documentation.patch +++ /dev/null @@ -1,185 +0,0 @@ -From 52e3695cc5ef00766e12adfe8ed276c2885e71bb Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 20 Aug 2020 17:49:29 -0400 -Subject: [PATCH] Unify kvno option documentation - -Add missing kvno options to the kvno.rst synopsis and option -descriptions, and to the kvno usage message. Remove mention of '-h' -(help text), from kvno.rst as it is an implicit option. Note that the -three new caching options were added in release 1.19. - -Indicate the two exclusions (-u/-S and --u2u with the S4U2Self options) -and dependency (-P on S4U2Self) where they are missing. - -Switch xusage() to print only a single localized string, rather than -running each line of output through localization separately. - -Leave kvno -C undocumented for now, as the semantics of -KRB5_GC_CANONICALIZE are minimally useful and likely to change. - -[ghudson@mit.edu: edited documentation and commit message] - -ticket: 7476 -tags: pullup -target_version: 1.18-next - -(cherry picked from commit becd1ad6830b526d08ddaf5b2b6f213154c6446c) ---- - doc/user/user_commands/kvno.rst | 24 +++++++++++++----------- - src/clients/kvno/kvno.c | 15 +++++++++------ - src/man/kvno.man | 24 +++++++++++++----------- - 3 files changed, 35 insertions(+), 28 deletions(-) - -diff --git a/doc/user/user_commands/kvno.rst b/doc/user/user_commands/kvno.rst -index 718313576..65c44e1c0 100644 ---- a/doc/user/user_commands/kvno.rst -+++ b/doc/user/user_commands/kvno.rst -@@ -10,13 +10,9 @@ SYNOPSIS - [**-c** *ccache*] - [**-e** *etype*] - [**-q**] --[**-h**] -+[**-u** | **-S** *sname*] - [**-P**] --[**-S** *sname*] --[**-I** *for_user*] --[**-U** *for_user*] --[**-F** *cert_file*] --[**--u2u** *ccache*] -+[[{**-F** *cert_file* | {**-I** | **-U**} *for_user*} [**-P**]] | **--u2u** *ccache*] - *service1 service2* ... - - -@@ -39,13 +35,18 @@ OPTIONS - of all the services named on the command line. This is useful in - certain backward compatibility situations. - -+**-k** *keytab* -+ Decrypt the acquired tickets using *keytab* to confirm their -+ validity. -+ - **-q** - Suppress printing output when successful. If a service ticket - cannot be obtained, an error message will still be printed and - kvno will exit with nonzero status. - --**-h** -- Prints a usage statement and exits. -+**-u** -+ Use the unknown name type in requested service principal names. -+ This option Cannot be used with *-S*. - - **-P** - Specifies that the *service1 service2* ... arguments are to be -@@ -76,16 +77,17 @@ OPTIONS - - **--cached-only** - Only retrieve credentials already present in the cache, not from -- the KDC. -+ the KDC. (Added in release 1.19.) - - **--no-store** - Do not store retrieved credentials in the cache. If - **--out-cache** is also specified, credentials will still be -- stored into the output credential cache. -+ stored into the output credential cache. (Added in release 1.19.) - - **--out-cache** *ccache* - Initialize *ccache* and store all retrieved credentials into it. -- Do not store acquired credentials in the input cache. -+ Do not store acquired credentials in the input cache. (Added in -+ release 1.19.) - - **--u2u** *ccache* - Requests a user-to-user ticket. *ccache* must contain a local -diff --git a/src/clients/kvno/kvno.c b/src/clients/kvno/kvno.c -index 9d85864f6..c5f6bf700 100644 ---- a/src/clients/kvno/kvno.c -+++ b/src/clients/kvno/kvno.c -@@ -38,15 +38,18 @@ - static char *prog; - static int quiet = 0; - -+#define XUSAGE_BREAK "\n\t" -+ - static void - xusage() - { -- fprintf(stderr, _("usage: %s [-C] [-u] [-c ccache] [-e etype]\n"), prog); -- fprintf(stderr, _("\t[-k keytab] [-S sname] [{-I | -U} for_user | " -- "[-F cert_file] [-P]]\n")); -- fprintf(stderr, _("\t[--cached-only] [--no-store] [--out-cache ccache] " -- "[--u2u ccache]\n")); -- fprintf(stderr, _("\tservice1 service2 ...\n")); -+ fprintf(stderr, _("usage: %s [-c ccache] [-e etype] [-k keytab] [-q] " -+ "[-u | -S sname]" XUSAGE_BREAK -+ "[[{-F cert_file | {-I | -U} for_user} [-P]] | " -+ "--u2u ccache]" XUSAGE_BREAK -+ "[--cached-only] [--no-store] [--out-cache] " -+ "service1 service2 ...\n"), -+ prog); - exit(1); - } - -diff --git a/src/man/kvno.man b/src/man/kvno.man -index b9f6739eb..22318324d 100644 ---- a/src/man/kvno.man -+++ b/src/man/kvno.man -@@ -36,13 +36,9 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]] - [\fB\-c\fP \fIccache\fP] - [\fB\-e\fP \fIetype\fP] - [\fB\-q\fP] --[\fB\-h\fP] -+[\fB\-u\fP | \fB\-S\fP \fIsname\fP] - [\fB\-P\fP] --[\fB\-S\fP \fIsname\fP] --[\fB\-I\fP \fIfor_user\fP] --[\fB\-U\fP \fIfor_user\fP] --[\fB\-F\fP \fIcert_file\fP] --[\fB\-\-u2u\fP \fIccache\fP] -+[[{\fB\-F\fP \fIcert_file\fP | {\fB\-I\fP | \fB\-U\fP} \fIfor_user\fP} [\fB\-P\fP]] | \fB\-\-u2u\fP \fIccache\fP] - \fIservice1 service2\fP ... - .SH DESCRIPTION - .sp -@@ -60,13 +56,18 @@ Specifies the enctype which will be requested for the session key - of all the services named on the command line. This is useful in - certain backward compatibility situations. - .TP -+\fB\-k\fP \fIkeytab\fP -+Decrypt the acquired tickets using \fIkeytab\fP to confirm their -+validity. -+.TP - \fB\-q\fP - Suppress printing output when successful. If a service ticket - cannot be obtained, an error message will still be printed and - kvno will exit with nonzero status. - .TP --\fB\-h\fP --Prints a usage statement and exits. -+\fB\-u\fP -+Use the unknown name type in requested service principal names. -+This option Cannot be used with \fI\-S\fP\&. - .TP - \fB\-P\fP - Specifies that the \fIservice1 service2\fP ... arguments are to be -@@ -97,16 +98,17 @@ certificate file must be in PEM format. - .TP - \fB\-\-cached\-only\fP - Only retrieve credentials already present in the cache, not from --the KDC. -+the KDC. (Added in release 1.19.) - .TP - \fB\-\-no\-store\fP - Do not store retrieved credentials in the cache. If - \fB\-\-out\-cache\fP is also specified, credentials will still be --stored into the output credential cache. -+stored into the output credential cache. (Added in release 1.19.) - .TP - \fB\-\-out\-cache\fP \fIccache\fP - Initialize \fIccache\fP and store all retrieved credentials into it. --Do not store acquired credentials in the input cache. -+Do not store acquired credentials in the input cache. (Added in -+release 1.19.) - .TP - \fB\-\-u2u\fP \fIccache\fP - Requests a user\-to\-user ticket. \fIccache\fP must contain a local diff --git a/Use-two-queues-for-concurrent-t_otp.py-daemons.patch b/Use-two-queues-for-concurrent-t_otp.py-daemons.patch index 4e81cd0..88c2364 100644 --- a/Use-two-queues-for-concurrent-t_otp.py-daemons.patch +++ b/Use-two-queues-for-concurrent-t_otp.py-daemons.patch @@ -1,4 +1,4 @@ -From 3e0d464f55320b393e32285f31710c24758a9101 Mon Sep 17 00:00:00 2001 +From e12c670bceb08413f797ecd643675a4a80dac824 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 4 Mar 2020 17:18:51 -0500 Subject: [PATCH] Use two queues for concurrent t_otp.py daemons diff --git a/downstream-Adjust-build-configuration.patch b/downstream-Adjust-build-configuration.patch index 47f6c31..62000c1 100644 --- a/downstream-Adjust-build-configuration.patch +++ b/downstream-Adjust-build-configuration.patch @@ -1,4 +1,4 @@ -From 30ece66508c8e10f704cd2860dfd421ebee15897 Mon Sep 17 00:00:00 2001 +From c06693e5a17daf0fd585e608e8bfd1eb3eef447c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:45:26 -0400 Subject: [PATCH] [downstream] Adjust build configuration diff --git a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index 08b78b1..310e1ac 100644 --- a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From bf8521bfaa4a4d54f6eb94f785c68942f4afa055 Mon Sep 17 00:00:00 2001 +From a983f32cfd2ec3f0571db347426835e8fc7c8464 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 diff --git a/downstream-Remove-3des-support.patch b/downstream-Remove-3des-support.patch index 570762d..e060f4e 100644 --- a/downstream-Remove-3des-support.patch +++ b/downstream-Remove-3des-support.patch @@ -1,4 +1,4 @@ -From c920b585b8400ef44684c673c54264657195f3ce Mon Sep 17 00:00:00 2001 +From 603a735ba52b50541520e53b031be47817de2fd5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] [downstream] Remove 3des support @@ -5552,7 +5552,7 @@ index 85a9574f3..3ce2a90ce 100644 code = 0; retval = GSS_S_BAD_SIG; diff --git a/src/lib/gssapi/krb5/util_crypt.c b/src/lib/gssapi/krb5/util_crypt.c -index 80954aff7..f7d3e92c4 100644 +index ddb0af8fc..d6c71aeb8 100644 --- a/src/lib/gssapi/krb5/util_crypt.c +++ b/src/lib/gssapi/krb5/util_crypt.c @@ -97,17 +97,6 @@ kg_setup_keys(krb5_context context, krb5_gss_ctx_id_rec *ctx, krb5_key subkey, diff --git a/downstream-SELinux-integration.patch b/downstream-SELinux-integration.patch index e5322af..4574a19 100644 --- a/downstream-SELinux-integration.patch +++ b/downstream-SELinux-integration.patch @@ -1,4 +1,4 @@ -From f8c70f6190a0573e2aca0b40964cf3b1a73ca8bb Mon Sep 17 00:00:00 2001 +From 2c4d04d1da4dbb1a312db965f3392d7d0bc67a17 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] [downstream] SELinux integration @@ -67,10 +67,10 @@ Last-updated: krb5-1.18-beta1 create mode 100644 src/util/support/selinux.c diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 830203683..6796fec53 100644 +index 59621e3e7..398eca7e4 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -89,6 +89,7 @@ AC_SUBST_FILE(libnodeps_frag) +@@ -85,6 +85,7 @@ AC_SUBST_FILE(libnodeps_frag) dnl KRB5_AC_PRAGMA_WEAK_REF WITH_LDAP @@ -78,7 +78,7 @@ index 830203683..6796fec53 100644 KRB5_LIB_PARAMS KRB5_AC_INITFINI KRB5_AC_ENABLE_THREADS -@@ -1743,4 +1744,51 @@ AC_SUBST(PAM_LIBS) +@@ -1739,4 +1740,51 @@ AC_SUBST(PAM_LIBS) AC_SUBST(PAM_MAN) AC_SUBST(NON_PAM_MAN) ])dnl @@ -253,7 +253,7 @@ index 79761f6d2..e9435c693 100644 #include diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c -index 301e3476d..19f2cc230 100644 +index ff2f25050..e3457622a 100644 --- a/src/kadmin/dbutil/dump.c +++ b/src/kadmin/dbutil/dump.c @@ -148,12 +148,21 @@ create_ofile(char *ofile, char **tmpname) @@ -288,7 +288,7 @@ index 301e3476d..19f2cc230 100644 com_err(progname, errno, _("while creating 'ok' file, '%s'"), file_ok); goto cleanup; diff --git a/src/kdc/main.c b/src/kdc/main.c -index fdcd694d7..1ede4bf2f 100644 +index 38d76b3b1..eb6966f2d 100644 --- a/src/kdc/main.c +++ b/src/kdc/main.c @@ -872,7 +872,7 @@ write_pid_file(const char *path) diff --git a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch index 56565b1..2e41026 100644 --- a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch +++ b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch @@ -1,4 +1,4 @@ -From 040dd62418b918adc993b9cc3e1e80fc232286c4 Mon Sep 17 00:00:00 2001 +From b1eeb9caf1e1fec23d92f163086ec168fbaf74e5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 15 Nov 2019 20:05:16 +0000 Subject: [PATCH] [downstream] Use backported version of OpenSSL-3 KDF diff --git a/downstream-fix-debuginfo-with-y.tab.c.patch b/downstream-fix-debuginfo-with-y.tab.c.patch index 33f61c5..7600f5d 100644 --- a/downstream-fix-debuginfo-with-y.tab.c.patch +++ b/downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,4 +1,4 @@ -From c6e103db0eb02c31a13b8cbcbae296c473074991 Mon Sep 17 00:00:00 2001 +From 126569bf428c546b938b9fec5b12851f09d61c94 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] [downstream] fix debuginfo with y.tab.c diff --git a/downstream-ksu-pam-integration.patch b/downstream-ksu-pam-integration.patch index e81f2c1..be0e02f 100644 --- a/downstream-ksu-pam-integration.patch +++ b/downstream-ksu-pam-integration.patch @@ -1,4 +1,4 @@ -From 9feb7298b90d3e6a34821fce7315757c0bf81c9e Mon Sep 17 00:00:00 2001 +From a5a642c33a2f57d24c1cfa8ca3e286418206ab55 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] [downstream] ksu pam integration @@ -30,10 +30,10 @@ Last-updated: krb5-1.18-beta1 create mode 100644 src/clients/ksu/pam.h diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 2394f7e33..830203683 100644 +index 8709a7f5d..59621e3e7 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -1675,3 +1675,72 @@ if test "$with_ldap" = yes; then +@@ -1671,3 +1671,72 @@ if test "$with_ldap" = yes; then OPENLDAP_PLUGIN=yes fi ])dnl diff --git a/downstream-netlib-and-dns.patch b/downstream-netlib-and-dns.patch index 05bddc4..156870b 100644 --- a/downstream-netlib-and-dns.patch +++ b/downstream-netlib-and-dns.patch @@ -1,4 +1,4 @@ -From 4254bee1b97edeb0848efce635bcf1b56306f968 Mon Sep 17 00:00:00 2001 +From 23bce0aef64454bf808b9885967b04abafcf7917 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] [downstream] netlib and dns @@ -11,10 +11,10 @@ Last-updated: krb5-1.3.1 1 file changed, 1 insertion(+) diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 6796fec53..c4358988a 100644 +index 398eca7e4..7ef2db56b 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -724,6 +724,7 @@ AC_HELP_STRING([--with-netlib=LIBS], use user defined resolver library), +@@ -720,6 +720,7 @@ AC_HELP_STRING([--with-netlib=LIBS], use user defined resolver library), LIBS="$LIBS $withval" AC_MSG_RESULT("netlib will use \'$withval\'") fi diff --git a/krb5.spec b/krb5.spec index 6223d52..6d2244a 100644 --- a/krb5.spec +++ b/krb5.spec @@ -16,9 +16,9 @@ Summary: The Kerberos network authentication system Name: krb5 -Version: 1.18.2 +Version: 1.18.3 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 30%{?dist} +Release: 1%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -50,7 +50,6 @@ Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch Patch9: Allow-certauth-modules-to-set-hw-authent-flag.patch Patch11: Refresh-manually-acquired-creds-from-client-keytab.patch Patch13: Add-finalization-safety-check-to-com_err.patch -Patch14: Eliminate-redundant-PKINIT-responder-invocation.patch Patch15: Correctly-import-service-GSS-host-based-name.patch Patch16: Do-expiration-warnings-for-all-init_creds-APIs.patch Patch17: Pass-gss_localname-through-SPNEGO.patch @@ -68,12 +67,9 @@ Patch29: Add-client_aware_channel_bindings-option.patch Patch30: Pass-channel-bindings-through-SPNEGO.patch Patch31: Add-channel-bindings-tests.patch Patch32: Use-two-queues-for-concurrent-t_otp.py-daemons.patch -Patch33: Allow-gss_unwrap_iov-of-unpadded-RC4-tokens.patch Patch34: Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch Patch35: Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch -Patch36: Fix-input-length-checking-in-SPNEGO-DER-decoding.patch Patch37: Add-three-kvno-options-from-Heimdal-kgetcred.patch -Patch38: Unify-kvno-option-documentation.patch Patch39: Improve-KDC-alias-checking-for-S4U-requests.patch Patch40: Adjust-KDC-alias-helper-function-contract.patch Patch41: Allow-aliases-when-matching-U2U-second-ticket.patch @@ -81,7 +77,6 @@ Patch42: Refactor-KDC-authdata-list-management-helpers.patch Patch43: Avoid-passing-DB-entry-structures-in-KDC.patch Patch44: Minimize-usage-of-tgs_server-in-KDC.patch Patch45: Fix-minor-static-analysis-defects.patch -Patch46: Add-recursion-limit-for-ASN.1-indefinite-lengths.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -632,6 +627,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Nov 18 2020 Robbie Harwood - 1.18.3-1 +- New upstream version (1.18.3) + * Tue Nov 17 2020 Robbie Harwood - 1.18.2-30 - Migrate /var/run to /run, an exercise in pointlessness - Resolves: #1898410 diff --git a/sources b/sources index c61d805..6ed904d 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.18.2.tar.gz) = 7cbb1b28e677fea3e0794e93951f3caaa2c49bb1175dd187951e72a466cc69d96c3b833d838000fe911c1a437d96a558e550f27c53a8b332fb9dfc7cbb7ec44c -SHA512 (krb5-1.18.2.tar.gz.asc) = 70775a06104b4d792d278da2efa92e94ddacb4ea319bfe2b253f5afcfec27f3bc5ddd12560294a265e3cf3d4fc74bcbfc3f5eeff8634d66c00d67e18dc93a74a +SHA512 (krb5-1.18.3.tar.gz) = cf0bf6cf8f622fa085954e6da998d952cf64dc7ccc319972ed81ea0542089cabf2d0e8243df84da01ad6f40584768ca2f02d108630c6741fa7b3d7d98c887c01 +SHA512 (krb5-1.18.3.tar.gz.asc) = 7c5a83e13d00910d895d545ed63310ebec48c90c29846dd54e48048f710360e8306778729b636baa091a4e9048998ff6d4dfe37f88dd6292540d55678c961a30 From dc8775d11d7134f84024545f21b4561a6bd8dccf Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 18 Nov 2020 13:33:37 -0500 Subject: [PATCH 205/304] Fix build failure in -1 --- ...e-kvno-options-from-Heimdal-kgetcred.patch | 34 +++++++++---------- ...t-KDC-alias-helper-function-contract.patch | 2 +- ...ases-when-matching-U2U-second-ticket.patch | 2 +- ...d-passing-DB-entry-structures-in-KDC.patch | 2 +- Fix-minor-static-analysis-defects.patch | 2 +- ...-KDC-alias-checking-for-S4U-requests.patch | 2 +- Minimize-usage-of-tgs_server-in-KDC.patch | 2 +- ...KDC-authdata-list-management-helpers.patch | 2 +- krb5.spec | 5 ++- 9 files changed, 28 insertions(+), 25 deletions(-) diff --git a/Add-three-kvno-options-from-Heimdal-kgetcred.patch b/Add-three-kvno-options-from-Heimdal-kgetcred.patch index 9cb1386..1f6452f 100644 --- a/Add-three-kvno-options-from-Heimdal-kgetcred.patch +++ b/Add-three-kvno-options-from-Heimdal-kgetcred.patch @@ -1,4 +1,4 @@ -From ba21ad84f7c8317a595ded1e657c7985fa4b90e1 Mon Sep 17 00:00:00 2001 +From 4da87d7fe288f3f7087dca8396d42abfd958b8e4 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 17 Jun 2020 20:48:38 -0400 Subject: [PATCH] Add three kvno options from Heimdal kgetcred @@ -17,10 +17,10 @@ ticket: 8917 (new) --- doc/user/user_commands/kvno.rst | 13 ++++ src/clients/kvno/Makefile.in | 3 + - src/clients/kvno/kvno.c | 113 +++++++++++++++++++++++--------- + src/clients/kvno/kvno.c | 112 +++++++++++++++++++++++--------- src/clients/kvno/t_kvno.py | 75 +++++++++++++++++++++ src/man/kvno.man | 13 ++++ - 5 files changed, 185 insertions(+), 32 deletions(-) + 5 files changed, 185 insertions(+), 31 deletions(-) create mode 100644 src/clients/kvno/t_kvno.py diff --git a/doc/user/user_commands/kvno.rst b/doc/user/user_commands/kvno.rst @@ -62,16 +62,16 @@ index 1c3f79392..5ba877271 100644 $(RM) kvno.o kvno diff --git a/src/clients/kvno/kvno.c b/src/clients/kvno/kvno.c -index 8edd97361..55e7dd0ce 100644 +index 8edd97361..c5f6bf700 100644 --- a/src/clients/kvno/kvno.c +++ b/src/clients/kvno/kvno.c -@@ -47,15 +47,16 @@ xusage() +@@ -47,15 +47,17 @@ xusage() "[-u | -S sname]" XUSAGE_BREAK "[[{-F cert_file | {-I | -U} for_user} [-P]] | " "--u2u ccache]" XUSAGE_BREAK + "[--cached-only] [--no-store] [--out-cache] " "service1 service2 ...\n"), -- prog); + prog); exit(1); } @@ -86,7 +86,7 @@ index 8edd97361..55e7dd0ce 100644 const char *u2u_ccname); #include -@@ -65,18 +66,21 @@ static void extended_com_err_fn(const char *myprog, errcode_t code, +@@ -65,18 +67,21 @@ static void extended_com_err_fn(const char *myprog, errcode_t code, int main(int argc, char *argv[]) { @@ -115,7 +115,7 @@ index 8edd97361..55e7dd0ce 100644 setlocale(LC_ALL, ""); set_com_err_hook(extended_com_err_fn); -@@ -139,6 +143,12 @@ main(int argc, char *argv[]) +@@ -139,6 +144,12 @@ main(int argc, char *argv[]) case OPTION_U2U: u2u_ccname = optarg; break; @@ -128,7 +128,7 @@ index 8edd97361..55e7dd0ce 100644 default: xusage(); break; -@@ -163,8 +173,9 @@ main(int argc, char *argv[]) +@@ -163,8 +174,9 @@ main(int argc, char *argv[]) xusage(); do_v5_kvno(argc - optind, argv + optind, ccachestr, etypestr, keytab_name, @@ -140,7 +140,7 @@ index 8edd97361..55e7dd0ce 100644 return 0; } -@@ -278,14 +289,16 @@ static krb5_error_code +@@ -278,14 +290,16 @@ static krb5_error_code kvno(const char *name, krb5_ccache ccache, krb5_principal me, krb5_enctype etype, krb5_keytab keytab, const char *sname, krb5_flags options, int unknown, krb5_principal for_user_princ, @@ -159,7 +159,7 @@ index 8edd97361..55e7dd0ce 100644 memset(&in_creds, 0, sizeof(in_creds)); if (sname != NULL) { -@@ -325,13 +338,12 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, +@@ -325,13 +339,12 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, in_creds.client = for_user_princ; in_creds.server = me; ret = krb5_get_credentials_for_user(context, options, ccache, @@ -175,7 +175,7 @@ index 8edd97361..55e7dd0ce 100644 } if (ret) { -@@ -340,7 +352,7 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, +@@ -340,7 +353,7 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, } /* We need a native ticket. */ @@ -184,7 +184,7 @@ index 8edd97361..55e7dd0ce 100644 if (ret) { com_err(prog, ret, _("while decoding ticket for %s"), princ); goto cleanup; -@@ -366,15 +378,15 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, +@@ -366,15 +379,15 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, } if (proxy) { @@ -205,7 +205,7 @@ index 8edd97361..55e7dd0ce 100644 krb5_free_principal(context, in_creds.client); if (ret) { com_err(prog, ret, _("%s: constrained delegation failed"), -@@ -383,10 +395,13 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, +@@ -383,10 +396,13 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, } } @@ -220,7 +220,7 @@ index 8edd97361..55e7dd0ce 100644 krb5_free_unparsed_name(context, princ); return ret; } -@@ -432,19 +447,28 @@ cleanup: +@@ -432,19 +448,28 @@ cleanup: static void do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, @@ -255,7 +255,7 @@ index 8edd97361..55e7dd0ce 100644 ret = krb5_init_context(&context); if (ret) { -@@ -471,6 +495,14 @@ do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, +@@ -471,6 +496,14 @@ do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, exit(1); } @@ -270,7 +270,7 @@ index 8edd97361..55e7dd0ce 100644 if (keytab_name != NULL) { ret = krb5_kt_resolve(context, keytab_name, &keytab); if (ret) { -@@ -517,8 +549,25 @@ do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, +@@ -517,8 +550,25 @@ do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, errors = 0; for (i = 0; i < count; i++) { if (kvno(names[i], ccache, me, etype, keytab, sname, options, unknown, diff --git a/Adjust-KDC-alias-helper-function-contract.patch b/Adjust-KDC-alias-helper-function-contract.patch index 0046bb4..13f4cb7 100644 --- a/Adjust-KDC-alias-helper-function-contract.patch +++ b/Adjust-KDC-alias-helper-function-contract.patch @@ -1,4 +1,4 @@ -From cf853d10b13dca77acd08d1387e94527994f9ef5 Mon Sep 17 00:00:00 2001 +From 833dfff1a11da3b1b9cf45a2bb09f17efa49cdba Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 22 Sep 2020 01:11:39 +0300 Subject: [PATCH] Adjust KDC alias helper function contract diff --git a/Allow-aliases-when-matching-U2U-second-ticket.patch b/Allow-aliases-when-matching-U2U-second-ticket.patch index 07519e1..523402f 100644 --- a/Allow-aliases-when-matching-U2U-second-ticket.patch +++ b/Allow-aliases-when-matching-U2U-second-ticket.patch @@ -1,4 +1,4 @@ -From 5a9b4d190906a8b11a7e1f707d1ea1930ce2fd31 Mon Sep 17 00:00:00 2001 +From e976a70ff23e600a76d1c3134f9c2f80753b6679 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 22 Sep 2020 01:17:11 +0300 Subject: [PATCH] Allow aliases when matching U2U second ticket diff --git a/Avoid-passing-DB-entry-structures-in-KDC.patch b/Avoid-passing-DB-entry-structures-in-KDC.patch index aeb20ad..23f96e3 100644 --- a/Avoid-passing-DB-entry-structures-in-KDC.patch +++ b/Avoid-passing-DB-entry-structures-in-KDC.patch @@ -1,4 +1,4 @@ -From f5987c71188138626030eef62145a126a84b62fb Mon Sep 17 00:00:00 2001 +From e0fc680b2fb51513993c4cdaa2c25b292f57a073 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 30 Sep 2020 02:12:00 -0400 Subject: [PATCH] Avoid passing DB entry structures in KDC diff --git a/Fix-minor-static-analysis-defects.patch b/Fix-minor-static-analysis-defects.patch index 644df97..b94b48c 100644 --- a/Fix-minor-static-analysis-defects.patch +++ b/Fix-minor-static-analysis-defects.patch @@ -1,4 +1,4 @@ -From ae153c1dbb91782e1c8d5e80be9e133766eb81fd Mon Sep 17 00:00:00 2001 +From 0de060366a1b75df47189f5cc0a7a92685cbe1d7 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 15 Oct 2020 18:15:29 -0400 Subject: [PATCH] Fix minor static analysis defects diff --git a/Improve-KDC-alias-checking-for-S4U-requests.patch b/Improve-KDC-alias-checking-for-S4U-requests.patch index d58ffa5..76b0bf9 100644 --- a/Improve-KDC-alias-checking-for-S4U-requests.patch +++ b/Improve-KDC-alias-checking-for-S4U-requests.patch @@ -1,4 +1,4 @@ -From ec23f914a4be4f4ce5a8960ea72f0f45f7c8cf59 Mon Sep 17 00:00:00 2001 +From dc03b33af17f2014baaa29412a1787cbcb140a62 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Fri, 4 Sep 2020 14:05:50 +0300 Subject: [PATCH] Improve KDC alias checking for S4U requests diff --git a/Minimize-usage-of-tgs_server-in-KDC.patch b/Minimize-usage-of-tgs_server-in-KDC.patch index 3e3c740..5199395 100644 --- a/Minimize-usage-of-tgs_server-in-KDC.patch +++ b/Minimize-usage-of-tgs_server-in-KDC.patch @@ -1,4 +1,4 @@ -From 62f5a8c4ef97f0f0f3ceddff8e0a768c5f3b544e Mon Sep 17 00:00:00 2001 +From ce60c549887a7732a6079d6e7111eb645f279781 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 25 Sep 2020 11:12:34 -0400 Subject: [PATCH] Minimize usage of tgs_server in KDC diff --git a/Refactor-KDC-authdata-list-management-helpers.patch b/Refactor-KDC-authdata-list-management-helpers.patch index f60e0af..495dbda 100644 --- a/Refactor-KDC-authdata-list-management-helpers.patch +++ b/Refactor-KDC-authdata-list-management-helpers.patch @@ -1,4 +1,4 @@ -From 227828eb22ff0383f76b918899a03e1c7c97a7c0 Mon Sep 17 00:00:00 2001 +From 00245d789edc6cf6263540d7c9d7ee45bbac58ce Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 5 Feb 2020 18:46:11 -0500 Subject: [PATCH] Refactor KDC authdata list management helpers diff --git a/krb5.spec b/krb5.spec index 6d2244a..8372f70 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.3 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 1%{?dist} +Release: 2%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -627,6 +627,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Nov 18 2020 Robbie Harwood - 1.18.3-2 +- Fix build failure in -1 + * Wed Nov 18 2020 Robbie Harwood - 1.18.3-1 - New upstream version (1.18.3) From ab7a2a35c2846faa89c58d48498208f495b1f6be Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 20 Nov 2020 11:43:18 -0500 Subject: [PATCH 206/304] Upstream executable shared libraries patch --- Add-channel-bindings-tests.patch | 2 +- ...client_aware_channel_bindings-option.patch | 2 +- ...finalization-safety-check-to-com_err.patch | 2 +- ...e-kvno-options-from-Heimdal-kgetcred.patch | 2 +- ...t-KDC-alias-helper-function-contract.patch | 2 +- ...ases-when-matching-U2U-second-ticket.patch | 2 +- ...tauth-modules-to-set-hw-authent-flag.patch | 2 +- ...d-passing-DB-entry-structures-in-KDC.patch | 2 +- ...y-import-service-GSS-host-based-name.patch | 2 +- ...ns_canonicalize_hostname-to-fallback.patch | 2 +- ...ion-warnings-for-all-init_creds-APIs.patch | 2 +- ...n-KERB_AP_OPTIONS_CBT-server-support.patch | 2 +- Fix-minor-static-analysis-defects.patch | 2 +- Fix-typo-in-in-in-the-ksu-man-page.patch | 2 +- ...-enctypes-in-krb5_string_to_keysalts.patch | 2 +- Implement-GSS_C_CHANNEL_BOUND_FLAG.patch | 2 +- ...ment-KERB_AP_OPTIONS_CBT-server-side.patch | 2 +- ...-KDC-alias-checking-for-S4U-requests.patch | 2 +- Improve-negoex_parse_token-code-hygiene.patch | 2 +- Install-shared-libraries-as-executable.patch | 42 +++++++++++ Minimize-usage-of-tgs_server-in-KDC.patch | 2 +- ...ndicator-check-for-S4U2Self-requests.patch | 2 +- ...SER-if-we-can-t-compute-its-checksum.patch | 2 +- Pass-channel-bindings-through-SPNEGO.patch | 2 +- Pass-gss_localname-through-SPNEGO.patch | 2 +- ...KDC-authdata-list-management-helpers.patch | 2 +- Refactor-krb5-GSS-checksum-handling.patch | 2 +- ...ly-acquired-creds-from-client-keytab.patch | 2 +- Remove-resolver-test-utility.patch | 2 +- ...ce-gssrpc-tests-with-a-Python-script.patch | 2 +- ...eues-for-concurrent-t_otp.py-daemons.patch | 2 +- downstream-Adjust-build-configuration.patch | 72 ------------------- ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 2 +- downstream-Remove-3des-support.patch | 2 +- ...ackported-version-of-OpenSSL-3-KDF-i.patch | 2 +- downstream-fix-debuginfo-with-y.tab.c.patch | 2 +- downstream-netlib-and-dns.patch | 2 +- krb5.spec | 7 +- 38 files changed, 82 insertions(+), 109 deletions(-) create mode 100644 Install-shared-libraries-as-executable.patch delete mode 100644 downstream-Adjust-build-configuration.patch diff --git a/Add-channel-bindings-tests.patch b/Add-channel-bindings-tests.patch index 99c2da2..caf14f6 100644 --- a/Add-channel-bindings-tests.patch +++ b/Add-channel-bindings-tests.patch @@ -1,4 +1,4 @@ -From 2c8494a1b89d69da9de46ca2cb17f9e8f12eb9b5 Mon Sep 17 00:00:00 2001 +From b9ca222798a52ef3a28185ed44f3dfe19579d8fc Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Fri, 20 Mar 2020 00:17:28 +0100 Subject: [PATCH] Add channel bindings tests diff --git a/Add-client_aware_channel_bindings-option.patch b/Add-client_aware_channel_bindings-option.patch index 142e1d9..20ecd30 100644 --- a/Add-client_aware_channel_bindings-option.patch +++ b/Add-client_aware_channel_bindings-option.patch @@ -1,4 +1,4 @@ -From 849bb23d0044b2ff315608784c0f96b81feb472f Mon Sep 17 00:00:00 2001 +From 032c7f496c9b327752dda33bf85e74c66d3a93cf Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 10 Mar 2020 13:13:17 +0100 Subject: [PATCH] Add client_aware_channel_bindings option diff --git a/Add-finalization-safety-check-to-com_err.patch b/Add-finalization-safety-check-to-com_err.patch index 9411b15..d717bcc 100644 --- a/Add-finalization-safety-check-to-com_err.patch +++ b/Add-finalization-safety-check-to-com_err.patch @@ -1,4 +1,4 @@ -From 73f1db69f99462b5109a5dd4e1a9476667bd3715 Mon Sep 17 00:00:00 2001 +From 903fc418db4f5819c507cb0d42c0d4a12217c22f Mon Sep 17 00:00:00 2001 From: Jiri Sasek Date: Fri, 13 Mar 2020 19:02:58 +0100 Subject: [PATCH] Add finalization safety check to com_err diff --git a/Add-three-kvno-options-from-Heimdal-kgetcred.patch b/Add-three-kvno-options-from-Heimdal-kgetcred.patch index 1f6452f..a68394c 100644 --- a/Add-three-kvno-options-from-Heimdal-kgetcred.patch +++ b/Add-three-kvno-options-from-Heimdal-kgetcred.patch @@ -1,4 +1,4 @@ -From 4da87d7fe288f3f7087dca8396d42abfd958b8e4 Mon Sep 17 00:00:00 2001 +From ea2ad3330aa39ef4e62d8856ea7e8eed2843b3f2 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 17 Jun 2020 20:48:38 -0400 Subject: [PATCH] Add three kvno options from Heimdal kgetcred diff --git a/Adjust-KDC-alias-helper-function-contract.patch b/Adjust-KDC-alias-helper-function-contract.patch index 13f4cb7..b7ce64e 100644 --- a/Adjust-KDC-alias-helper-function-contract.patch +++ b/Adjust-KDC-alias-helper-function-contract.patch @@ -1,4 +1,4 @@ -From 833dfff1a11da3b1b9cf45a2bb09f17efa49cdba Mon Sep 17 00:00:00 2001 +From d27cef7eb6f099fb1ec4e2d49625aee0d8dc1007 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 22 Sep 2020 01:11:39 +0300 Subject: [PATCH] Adjust KDC alias helper function contract diff --git a/Allow-aliases-when-matching-U2U-second-ticket.patch b/Allow-aliases-when-matching-U2U-second-ticket.patch index 523402f..38ed3cc 100644 --- a/Allow-aliases-when-matching-U2U-second-ticket.patch +++ b/Allow-aliases-when-matching-U2U-second-ticket.patch @@ -1,4 +1,4 @@ -From e976a70ff23e600a76d1c3134f9c2f80753b6679 Mon Sep 17 00:00:00 2001 +From 69e45f51b466219bde15b11c8539ea3841281f2b Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 22 Sep 2020 01:17:11 +0300 Subject: [PATCH] Allow aliases when matching U2U second ticket diff --git a/Allow-certauth-modules-to-set-hw-authent-flag.patch b/Allow-certauth-modules-to-set-hw-authent-flag.patch index 0c155e7..3be71e7 100644 --- a/Allow-certauth-modules-to-set-hw-authent-flag.patch +++ b/Allow-certauth-modules-to-set-hw-authent-flag.patch @@ -1,4 +1,4 @@ -From c18034484eadb0f32cef384197d1185aa50c3adb Mon Sep 17 00:00:00 2001 +From b581e106c65957f48ee088d9243b985d3e9a0be8 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 24 Feb 2020 15:58:59 -0500 Subject: [PATCH] Allow certauth modules to set hw-authent flag diff --git a/Avoid-passing-DB-entry-structures-in-KDC.patch b/Avoid-passing-DB-entry-structures-in-KDC.patch index 23f96e3..0d6a8be 100644 --- a/Avoid-passing-DB-entry-structures-in-KDC.patch +++ b/Avoid-passing-DB-entry-structures-in-KDC.patch @@ -1,4 +1,4 @@ -From e0fc680b2fb51513993c4cdaa2c25b292f57a073 Mon Sep 17 00:00:00 2001 +From aad7ffc2cdc5b1c55a5967612730daa2f493fa6e Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 30 Sep 2020 02:12:00 -0400 Subject: [PATCH] Avoid passing DB entry structures in KDC diff --git a/Correctly-import-service-GSS-host-based-name.patch b/Correctly-import-service-GSS-host-based-name.patch index e56648b..0c6d0e7 100644 --- a/Correctly-import-service-GSS-host-based-name.patch +++ b/Correctly-import-service-GSS-host-based-name.patch @@ -1,4 +1,4 @@ -From 24c5e1ad937505a03628547ed7a5c6060a2b0ff2 Mon Sep 17 00:00:00 2001 +From 5a0900dc3f0ce7569db2ed6d14da3f97b47bd120 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 30 Mar 2020 15:26:02 -0400 Subject: [PATCH] Correctly import "service@" GSS host-based name diff --git a/Default-dns_canonicalize_hostname-to-fallback.patch b/Default-dns_canonicalize_hostname-to-fallback.patch index 3669432..99b9bbb 100644 --- a/Default-dns_canonicalize_hostname-to-fallback.patch +++ b/Default-dns_canonicalize_hostname-to-fallback.patch @@ -1,4 +1,4 @@ -From 6bdab27ef3dfcefb8426f2ea4e06bbdbd1141b16 Mon Sep 17 00:00:00 2001 +From bec1b3601b15397df07b3464959da92915eb45b5 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 27 May 2020 18:48:35 -0400 Subject: [PATCH] Default dns_canonicalize_hostname to "fallback" diff --git a/Do-expiration-warnings-for-all-init_creds-APIs.patch b/Do-expiration-warnings-for-all-init_creds-APIs.patch index 374068f..0dc7528 100644 --- a/Do-expiration-warnings-for-all-init_creds-APIs.patch +++ b/Do-expiration-warnings-for-all-init_creds-APIs.patch @@ -1,4 +1,4 @@ -From c7abf942c66b2ba543cf412f12562e9bb8ee260a Mon Sep 17 00:00:00 2001 +From 4369b03968131b005acbafd043465899da50e1dc Mon Sep 17 00:00:00 2001 From: Sumit Bose Date: Fri, 28 Feb 2020 10:11:49 +0100 Subject: [PATCH] Do expiration warnings for all init_creds APIs diff --git a/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch b/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch index 90bbcab..ad0dd7a 100644 --- a/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch +++ b/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch @@ -1,4 +1,4 @@ -From 4b2176eaad00630890abe4b458cbc31f05b2b9c0 Mon Sep 17 00:00:00 2001 +From 5106d0b7ea10d1faa21f6dfb542a46eb74e78d40 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 24 Jul 2020 16:05:24 -0400 Subject: [PATCH] Fix leak in KERB_AP_OPTIONS_CBT server support diff --git a/Fix-minor-static-analysis-defects.patch b/Fix-minor-static-analysis-defects.patch index b94b48c..c136b7f 100644 --- a/Fix-minor-static-analysis-defects.patch +++ b/Fix-minor-static-analysis-defects.patch @@ -1,4 +1,4 @@ -From 0de060366a1b75df47189f5cc0a7a92685cbe1d7 Mon Sep 17 00:00:00 2001 +From a33dc1cfb0ebecb67cc7f38258303492a552cb73 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 15 Oct 2020 18:15:29 -0400 Subject: [PATCH] Fix minor static analysis defects diff --git a/Fix-typo-in-in-in-the-ksu-man-page.patch b/Fix-typo-in-in-in-the-ksu-man-page.patch index a6c1f5c..922aa29 100644 --- a/Fix-typo-in-in-in-the-ksu-man-page.patch +++ b/Fix-typo-in-in-in-the-ksu-man-page.patch @@ -1,4 +1,4 @@ -From 5399eaea6c5e00c4e96fa5507aa50dd643337194 Mon Sep 17 00:00:00 2001 +From 5952a06a594c4dc0f20f7ba2854b25f76734aa27 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 May 2020 15:01:18 -0400 Subject: [PATCH] Fix typo ("in in") in the ksu man page diff --git a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch index 01edf16..aaab2d3 100644 --- a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch +++ b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch @@ -1,4 +1,4 @@ -From 6931f8ed0fd8c9f634e1e48f1e8926022610fc3f Mon Sep 17 00:00:00 2001 +From cc572c5b6f8a3269c24c0f21f5799e60014635fb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 15 Jul 2020 15:42:20 -0400 Subject: [PATCH] Ignore bad enctypes in krb5_string_to_keysalts() diff --git a/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch b/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch index d93a3f8..b5180b2 100644 --- a/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch +++ b/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch @@ -1,4 +1,4 @@ -From 40093f65c58ab78a050860ce41560595aa8ecf7e Mon Sep 17 00:00:00 2001 +From e0a702b6e5f0665cca88723f7b17ff90ea218e45 Mon Sep 17 00:00:00 2001 From: Alexander Scheel Date: Wed, 5 Jul 2017 11:38:30 -0400 Subject: [PATCH] Implement GSS_C_CHANNEL_BOUND_FLAG diff --git a/Implement-KERB_AP_OPTIONS_CBT-server-side.patch b/Implement-KERB_AP_OPTIONS_CBT-server-side.patch index a43ae8b..458901d 100644 --- a/Implement-KERB_AP_OPTIONS_CBT-server-side.patch +++ b/Implement-KERB_AP_OPTIONS_CBT-server-side.patch @@ -1,4 +1,4 @@ -From 2250babfa6fc6590d50fc9c9beb267ba280ff685 Mon Sep 17 00:00:00 2001 +From 323329d9033f32f49266921910124fe4f2a9124c Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Mon, 9 Mar 2020 16:04:21 +0100 Subject: [PATCH] Implement KERB_AP_OPTIONS_CBT (server side) diff --git a/Improve-KDC-alias-checking-for-S4U-requests.patch b/Improve-KDC-alias-checking-for-S4U-requests.patch index 76b0bf9..69745de 100644 --- a/Improve-KDC-alias-checking-for-S4U-requests.patch +++ b/Improve-KDC-alias-checking-for-S4U-requests.patch @@ -1,4 +1,4 @@ -From dc03b33af17f2014baaa29412a1787cbcb140a62 Mon Sep 17 00:00:00 2001 +From d80afa1396c3a6605338e4eaaf5bc44f8ad3eacc Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Fri, 4 Sep 2020 14:05:50 +0300 Subject: [PATCH] Improve KDC alias checking for S4U requests diff --git a/Improve-negoex_parse_token-code-hygiene.patch b/Improve-negoex_parse_token-code-hygiene.patch index ef9bf2b..d2b94aa 100644 --- a/Improve-negoex_parse_token-code-hygiene.patch +++ b/Improve-negoex_parse_token-code-hygiene.patch @@ -1,4 +1,4 @@ -From d604359e2f0bce65f08d0d805e0795e29287109c Mon Sep 17 00:00:00 2001 +From 9596a341d99e3af1438ad215ed0fb5496cb59ff0 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 9 Jun 2020 16:23:37 -0400 Subject: [PATCH] Improve negoex_parse_token() code hygiene diff --git a/Install-shared-libraries-as-executable.patch b/Install-shared-libraries-as-executable.patch new file mode 100644 index 0000000..b8adf3d --- /dev/null +++ b/Install-shared-libraries-as-executable.patch @@ -0,0 +1,42 @@ +From b3c6667d7f98cf0347642c7927618fd40cd6f904 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 23 Aug 2016 16:45:26 -0400 +Subject: [PATCH] Install shared libraries as executable + +RPM expects this behavior, and systems with contrary policies (like +Debian) address permissions at the packaging layer. Most other build +systems appear to install shared libraries as executable. + +[ghudson@mit.edu: edited commit message] + +ticket: 8965 (new) +(cherry picked from commit 1bc5f76d2e7013b8771e3bd9960c82642ba0b467) +--- + src/config/shlib.conf | 7 ++++--- + 1 file changed, 4 insertions(+), 3 deletions(-) + +diff --git a/src/config/shlib.conf b/src/config/shlib.conf +index 3e4af6c02..75b7cc3af 100644 +--- a/src/config/shlib.conf ++++ b/src/config/shlib.conf +@@ -22,8 +22,10 @@ SHLIBVEXT=.so.v-nobuild + SHLIBSEXT=.so.s-nobuild + # Most systems support profiled libraries. + PFLIBEXT=_p.a +-# Most systems install shared libs as mode 644, etc. while hpux wants 755 +-INSTALL_SHLIB='$(INSTALL_DATA)' ++# Install libraries executable. Some systems (e.g., RPM-based ones) require ++# this for package dependency generation, while others are ambivalent or will ++# strip it during packaging. ++INSTALL_SHLIB='$(INSTALL)' + # Most systems use the same objects for shared libraries and dynamically + # loadable objects. + DYNOBJEXT='$(SHLIBEXT)' +@@ -118,7 +120,6 @@ alpha*-dec-osf*) + # -O +dpv should display any routines eliminated as unused, but -b + # apparently turns that off + *-*-hpux*) +- INSTALL_SHLIB='$(INSTALL)' + case $host_cpu in + hppa*) + SHLIBEXT=.sl diff --git a/Minimize-usage-of-tgs_server-in-KDC.patch b/Minimize-usage-of-tgs_server-in-KDC.patch index 5199395..01608e8 100644 --- a/Minimize-usage-of-tgs_server-in-KDC.patch +++ b/Minimize-usage-of-tgs_server-in-KDC.patch @@ -1,4 +1,4 @@ -From ce60c549887a7732a6079d6e7111eb645f279781 Mon Sep 17 00:00:00 2001 +From 6e82fd67034eef7f99b901f417782a3786a02069 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 25 Sep 2020 11:12:34 -0400 Subject: [PATCH] Minimize usage of tgs_server in KDC diff --git a/Omit-KDC-indicator-check-for-S4U2Self-requests.patch b/Omit-KDC-indicator-check-for-S4U2Self-requests.patch index 782974b..9e25d54 100644 --- a/Omit-KDC-indicator-check-for-S4U2Self-requests.patch +++ b/Omit-KDC-indicator-check-for-S4U2Self-requests.patch @@ -1,4 +1,4 @@ -From a9144f5238b91949f32355f5ab88e2ade734eb06 Mon Sep 17 00:00:00 2001 +From cd99c7829a43074cec8afe5c7021778a5a2ebd31 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 6 May 2020 16:03:13 -0400 Subject: [PATCH] Omit KDC indicator check for S4U2Self requests diff --git a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch index bc4ed52..5fd221e 100644 --- a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch +++ b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch @@ -1,4 +1,4 @@ -From 8fc932c8f75e4332aa7dc6c4862cb881308b6813 Mon Sep 17 00:00:00 2001 +From 6b81d2d9913d91a4cc48d04f123fc71cc1022432 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Sat, 6 Jun 2020 11:03:37 +0200 Subject: [PATCH] Omit PA_FOR_USER if we can't compute its checksum diff --git a/Pass-channel-bindings-through-SPNEGO.patch b/Pass-channel-bindings-through-SPNEGO.patch index e376472..1b3c130 100644 --- a/Pass-channel-bindings-through-SPNEGO.patch +++ b/Pass-channel-bindings-through-SPNEGO.patch @@ -1,4 +1,4 @@ -From 19ef4a378a8fe483e82b1b4f979a7ffcb264325e Mon Sep 17 00:00:00 2001 +From a5588aae21d44f5a6eed4bdfeae992a709b92959 Mon Sep 17 00:00:00 2001 From: Isaac Boukris Date: Tue, 28 Apr 2020 18:15:55 +0200 Subject: [PATCH] Pass channel bindings through SPNEGO diff --git a/Pass-gss_localname-through-SPNEGO.patch b/Pass-gss_localname-through-SPNEGO.patch index bbf703c..1aad597 100644 --- a/Pass-gss_localname-through-SPNEGO.patch +++ b/Pass-gss_localname-through-SPNEGO.patch @@ -1,4 +1,4 @@ -From fb89e83451519aed051bb129f3cf9cc34cde702f Mon Sep 17 00:00:00 2001 +From 723f4c746293f064a32961ad77b57f901dd54a67 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sun, 26 Apr 2020 19:55:54 -0400 Subject: [PATCH] Pass gss_localname() through SPNEGO diff --git a/Refactor-KDC-authdata-list-management-helpers.patch b/Refactor-KDC-authdata-list-management-helpers.patch index 495dbda..69ef109 100644 --- a/Refactor-KDC-authdata-list-management-helpers.patch +++ b/Refactor-KDC-authdata-list-management-helpers.patch @@ -1,4 +1,4 @@ -From 00245d789edc6cf6263540d7c9d7ee45bbac58ce Mon Sep 17 00:00:00 2001 +From 17093468190706e241d2a6ef2bb5607be7021640 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 5 Feb 2020 18:46:11 -0500 Subject: [PATCH] Refactor KDC authdata list management helpers diff --git a/Refactor-krb5-GSS-checksum-handling.patch b/Refactor-krb5-GSS-checksum-handling.patch index a0bb217..62f36c3 100644 --- a/Refactor-krb5-GSS-checksum-handling.patch +++ b/Refactor-krb5-GSS-checksum-handling.patch @@ -1,4 +1,4 @@ -From 544c37e2928f2585708e36f77a6b0baa52c3c541 Mon Sep 17 00:00:00 2001 +From 8412a1611290da9705730c9e473a5b122c55e9fd Mon Sep 17 00:00:00 2001 From: Alexander Scheel Date: Fri, 30 Jun 2017 16:03:01 -0400 Subject: [PATCH] Refactor krb5 GSS checksum handling diff --git a/Refresh-manually-acquired-creds-from-client-keytab.patch b/Refresh-manually-acquired-creds-from-client-keytab.patch index dc50194..61e1fa4 100644 --- a/Refresh-manually-acquired-creds-from-client-keytab.patch +++ b/Refresh-manually-acquired-creds-from-client-keytab.patch @@ -1,4 +1,4 @@ -From e1762f16fe4d900903c5395cc3268f9b78835100 Mon Sep 17 00:00:00 2001 +From 43fe1f948059ad79d95dbf41f2206de65238d892 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 26 Feb 2020 18:27:17 -0500 Subject: [PATCH] Refresh manually acquired creds from client keytab diff --git a/Remove-resolver-test-utility.patch b/Remove-resolver-test-utility.patch index e765069..77fea7a 100644 --- a/Remove-resolver-test-utility.patch +++ b/Remove-resolver-test-utility.patch @@ -1,4 +1,4 @@ -From 8a2cd84c047ef7500dc8149ed6ace8e9fa631cad Mon Sep 17 00:00:00 2001 +From 6d2dbd0378c92ea13363f2536ab0062bdfda076e Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 28 May 2020 18:41:02 -0400 Subject: [PATCH] Remove resolver test utility diff --git a/Replace-gssrpc-tests-with-a-Python-script.patch b/Replace-gssrpc-tests-with-a-Python-script.patch index fc8fe87..3481a87 100644 --- a/Replace-gssrpc-tests-with-a-Python-script.patch +++ b/Replace-gssrpc-tests-with-a-Python-script.patch @@ -1,4 +1,4 @@ -From e2ad633616a3f4db91bbd332d778df93e4bdb652 Mon Sep 17 00:00:00 2001 +From 1de586b414104a447a50ffb6f81c2f57ed3d3a34 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Sat, 15 Feb 2020 20:34:23 -0500 Subject: [PATCH] Replace gssrpc tests with a Python script diff --git a/Use-two-queues-for-concurrent-t_otp.py-daemons.patch b/Use-two-queues-for-concurrent-t_otp.py-daemons.patch index 88c2364..80093f3 100644 --- a/Use-two-queues-for-concurrent-t_otp.py-daemons.patch +++ b/Use-two-queues-for-concurrent-t_otp.py-daemons.patch @@ -1,4 +1,4 @@ -From e12c670bceb08413f797ecd643675a4a80dac824 Mon Sep 17 00:00:00 2001 +From 35d041e432ea6d4611b232cc9bb72a36552eda27 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 4 Mar 2020 17:18:51 -0500 Subject: [PATCH] Use two queues for concurrent t_otp.py daemons diff --git a/downstream-Adjust-build-configuration.patch b/downstream-Adjust-build-configuration.patch deleted file mode 100644 index 62000c1..0000000 --- a/downstream-Adjust-build-configuration.patch +++ /dev/null @@ -1,72 +0,0 @@ -From c06693e5a17daf0fd585e608e8bfd1eb3eef447c Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:45:26 -0400 -Subject: [PATCH] [downstream] Adjust build configuration - -Build binaries in this package as RELRO PIEs, libraries as partial RELRO, -and install shared libraries with the execute bit set on them. Prune out -the -L/usr/lib* and PIE flags where they might leak out and affect -apps which just want to link with the libraries. FIXME: needs to check and -not just assume that the compiler supports using these flags. - -Last-updated: krb5-1.15-beta1 ---- - src/build-tools/krb5-config.in | 7 +++++++ - src/config/pre.in | 2 +- - src/config/shlib.conf | 5 +++-- - 3 files changed, 11 insertions(+), 3 deletions(-) - -diff --git a/src/build-tools/krb5-config.in b/src/build-tools/krb5-config.in -index c17cb5eb5..1891dea99 100755 ---- a/src/build-tools/krb5-config.in -+++ b/src/build-tools/krb5-config.in -@@ -226,6 +226,13 @@ if test -n "$do_libs"; then - -e 's#\$(PTHREAD_CFLAGS)#'"$PTHREAD_CFLAGS"'#' \ - -e 's#\$(CFLAGS)##'` - -+ if test `dirname $libdir` = /usr ; then -+ lib_flags=`echo $lib_flags | sed -e "s#-L$libdir##" -e "s#$RPATH_FLAG$libdir##"` -+ fi -+ lib_flags=`echo $lib_flags | sed -e "s#-fPIE##g" -e "s#-pie##g"` -+ lib_flags=`echo $lib_flags | sed -e "s#-Wl,-z,relro##g"` -+ lib_flags=`echo $lib_flags | sed -e "s#-Wl,-z,now##g"` -+ - if test $library = 'kdb'; then - lib_flags="$lib_flags -lkdb5 $KDB5_DB_LIB" - library=krb5 -diff --git a/src/config/pre.in b/src/config/pre.in -index 917357df9..a8540ae2a 100644 ---- a/src/config/pre.in -+++ b/src/config/pre.in -@@ -185,7 +185,7 @@ INSTALL_PROGRAM=@INSTALL_PROGRAM@ $(INSTALL_STRIP) - INSTALL_SCRIPT=@INSTALL_PROGRAM@ - INSTALL_DATA=@INSTALL_DATA@ - INSTALL_SHLIB=@INSTALL_SHLIB@ --INSTALL_SETUID=$(INSTALL) $(INSTALL_STRIP) -m 4755 -o root -+INSTALL_SETUID=$(INSTALL) $(INSTALL_STRIP) -m 4755 - ## This is needed because autoconf will sometimes define @exec_prefix@ to be - ## ${prefix}. - prefix=@prefix@ -diff --git a/src/config/shlib.conf b/src/config/shlib.conf -index 3e4af6c02..2b20c3fda 100644 ---- a/src/config/shlib.conf -+++ b/src/config/shlib.conf -@@ -423,7 +423,7 @@ mips-*-netbsd*) - # Linux ld doesn't default to stuffing the SONAME field... - # Use objdump -x to examine the fields of the library - # UNDEF_CHECK is suppressed by --enable-asan -- LDCOMBINE='$(CC) -shared -fPIC -Wl,-h,$(LIBPREFIX)$(LIBBASE)$(SHLIBSEXT) $(UNDEF_CHECK)' -+ LDCOMBINE='$(CC) -shared -fPIC -Wl,-h,$(LIBPREFIX)$(LIBBASE)$(SHLIBSEXT) $(UNDEF_CHECK) -Wl,-z,relro -Wl,--warn-shared-textrel' - UNDEF_CHECK='-Wl,--no-undefined' - # $(EXPORT_CHECK) runs export-check.pl when in maintainer mode. - LDCOMBINE_TAIL='-Wl,--version-script binutils.versions $(EXPORT_CHECK)' -@@ -435,7 +435,8 @@ mips-*-netbsd*) - SHLIB_EXPFLAGS='$(SHLIB_RPATH_FLAGS) $(SHLIB_DIRS) $(SHLIB_EXPLIBS)' - PROFFLAGS=-pg - PROG_RPATH_FLAGS='$(RPATH_FLAG)$(PROG_RPATH)' -- CC_LINK_SHARED='$(CC) $(PROG_LIBPATH) $(PROG_RPATH_FLAGS) $(CFLAGS) $(LDFLAGS)' -+ CC_LINK_SHARED='$(CC) $(PROG_LIBPATH) $(PROG_RPATH_FLAGS) $(CFLAGS) -pie -Wl,-z,relro -Wl,-z,now $(LDFLAGS)' -+ INSTALL_SHLIB='${INSTALL} -m755' - CC_LINK_STATIC='$(CC) $(PROG_LIBPATH) $(CFLAGS) $(LDFLAGS)' - CXX_LINK_SHARED='$(CXX) $(PROG_LIBPATH) $(PROG_RPATH_FLAGS) $(CXXFLAGS) $(LDFLAGS)' - CXX_LINK_STATIC='$(CXX) $(PROG_LIBPATH) $(CXXFLAGS) $(LDFLAGS)' diff --git a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index 310e1ac..3d0cd46 100644 --- a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From a983f32cfd2ec3f0571db347426835e8fc7c8464 Mon Sep 17 00:00:00 2001 +From 3a83d2b4c2a3eea5dde8de883ee9b41630a6a487 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 diff --git a/downstream-Remove-3des-support.patch b/downstream-Remove-3des-support.patch index e060f4e..ae4124f 100644 --- a/downstream-Remove-3des-support.patch +++ b/downstream-Remove-3des-support.patch @@ -1,4 +1,4 @@ -From 603a735ba52b50541520e53b031be47817de2fd5 Mon Sep 17 00:00:00 2001 +From 0ef71d2bef3efcb38b20fc8b3050944286ada726 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] [downstream] Remove 3des support diff --git a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch index 2e41026..149bb0a 100644 --- a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch +++ b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch @@ -1,4 +1,4 @@ -From b1eeb9caf1e1fec23d92f163086ec168fbaf74e5 Mon Sep 17 00:00:00 2001 +From a89e833a2ae26197a0edf864bb9274d776003c60 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 15 Nov 2019 20:05:16 +0000 Subject: [PATCH] [downstream] Use backported version of OpenSSL-3 KDF diff --git a/downstream-fix-debuginfo-with-y.tab.c.patch b/downstream-fix-debuginfo-with-y.tab.c.patch index 7600f5d..13072cf 100644 --- a/downstream-fix-debuginfo-with-y.tab.c.patch +++ b/downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,4 +1,4 @@ -From 126569bf428c546b938b9fec5b12851f09d61c94 Mon Sep 17 00:00:00 2001 +From 0f98db9b00fa2ce685f841db18fff641f8eaa904 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] [downstream] fix debuginfo with y.tab.c diff --git a/downstream-netlib-and-dns.patch b/downstream-netlib-and-dns.patch index 156870b..682e3df 100644 --- a/downstream-netlib-and-dns.patch +++ b/downstream-netlib-and-dns.patch @@ -1,4 +1,4 @@ -From 23bce0aef64454bf808b9885967b04abafcf7917 Mon Sep 17 00:00:00 2001 +From 29f58a8059cb73ca586514b57458b2b17e091f36 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] [downstream] netlib and dns diff --git a/krb5.spec b/krb5.spec index 8372f70..fbd52c3 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.3 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 2%{?dist} +Release: 3%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -41,7 +41,6 @@ Source39: krb5-krb5kdc.conf Patch0: downstream-ksu-pam-integration.patch Patch1: downstream-SELinux-integration.patch -Patch2: downstream-Adjust-build-configuration.patch Patch3: downstream-netlib-and-dns.patch Patch4: downstream-fix-debuginfo-with-y.tab.c.patch Patch5: downstream-Remove-3des-support.patch @@ -77,6 +76,7 @@ Patch42: Refactor-KDC-authdata-list-management-helpers.patch Patch43: Avoid-passing-DB-entry-structures-in-KDC.patch Patch44: Minimize-usage-of-tgs_server-in-KDC.patch Patch45: Fix-minor-static-analysis-defects.patch +Patch46: Install-shared-libraries-as-executable.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -627,6 +627,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Nov 20 2020 Robbie Harwood - 1.18.3-3 +- Upstream executable shared libraries patch + * Wed Nov 18 2020 Robbie Harwood - 1.18.3-2 - Fix build failure in -1 From b783a5421cf5820f19f2e3aeb999ad24de39747e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 24 Nov 2020 12:55:33 -0500 Subject: [PATCH 207/304] Document -k option in kvno(1) synopsis --- Document-k-option-in-kvno-1-synopsis.patch | 38 ++++++++++++++++++++++ krb5.spec | 6 +++- 2 files changed, 43 insertions(+), 1 deletion(-) create mode 100644 Document-k-option-in-kvno-1-synopsis.patch diff --git a/Document-k-option-in-kvno-1-synopsis.patch b/Document-k-option-in-kvno-1-synopsis.patch new file mode 100644 index 0000000..21f8100 --- /dev/null +++ b/Document-k-option-in-kvno-1-synopsis.patch @@ -0,0 +1,38 @@ +From 588d964f59356373353dfd31d4fdcba95e508385 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 24 Nov 2020 12:52:02 -0500 +Subject: [PATCH] Document -k option in kvno(1) synopsis + +becd1ad6830b526d08ddaf5b2b6f213154c6446c attempted to unify the +synopsis, option descriptions, and xusage(), but missed one option. + +(cherry picked from commit d81e76d9ddab9e880bcf54eabf07119af91d28c7) +--- + doc/user/user_commands/kvno.rst | 1 + + src/man/kvno.man | 1 + + 2 files changed, 2 insertions(+) + +diff --git a/doc/user/user_commands/kvno.rst b/doc/user/user_commands/kvno.rst +index 6fd8577a5..1e273e26e 100644 +--- a/doc/user/user_commands/kvno.rst ++++ b/doc/user/user_commands/kvno.rst +@@ -9,6 +9,7 @@ SYNOPSIS + **kvno** + [**-c** *ccache*] + [**-e** *etype*] ++[**-k** *keytab*] + [**-q**] + [**-u** | **-S** *sname*] + [**-P**] +diff --git a/src/man/kvno.man b/src/man/kvno.man +index 7c9565bdb..dc9847e99 100644 +--- a/src/man/kvno.man ++++ b/src/man/kvno.man +@@ -35,6 +35,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]] + \fBkvno\fP + [\fB\-c\fP \fIccache\fP] + [\fB\-e\fP \fIetype\fP] ++[\fB\-k\fP \fIkeytab\fP] + [\fB\-q\fP] + [\fB\-u\fP | \fB\-S\fP \fIsname\fP] + [\fB\-P\fP] diff --git a/krb5.spec b/krb5.spec index fbd52c3..2248930 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.3 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 3%{?dist} +Release: 4%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -77,6 +77,7 @@ Patch43: Avoid-passing-DB-entry-structures-in-KDC.patch Patch44: Minimize-usage-of-tgs_server-in-KDC.patch Patch45: Fix-minor-static-analysis-defects.patch Patch46: Install-shared-libraries-as-executable.patch +Patch47: Document-k-option-in-kvno-1-synopsis.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -627,6 +628,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Nov 24 2020 Robbie Harwood - 1.18.3-4 +- Document -k option in kvno(1) synopsis + * Fri Nov 20 2020 Robbie Harwood - 1.18.3-3 - Upstream executable shared libraries patch From ed80b0806210e307f19d26668b0de154927b48a4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 1 Dec 2020 14:37:26 -0500 Subject: [PATCH 208/304] Add make to BuildRequires Drop cmake since we don't use it for anything --- krb5.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 2248930..5ec582b 100644 --- a/krb5.spec +++ b/krb5.spec @@ -81,7 +81,7 @@ Patch47: Document-k-option-in-kvno-1-synopsis.patch License: MIT URL: https://web.mit.edu/kerberos/www/ -BuildRequires: autoconf, bison, cmake, flex, gawk, gettext, pkgconfig, sed +BuildRequires: autoconf, bison, make, flex, gawk, gettext, pkgconfig, sed BuildRequires: gcc, gcc-c++ BuildRequires: libcom_err-devel, libedit-devel, libss-devel BuildRequires: gzip, ncurses-devel From 58924baeb41832d67570d81c009af6723ef62cc2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 16 Dec 2020 11:12:22 -0500 Subject: [PATCH 209/304] Fix runstatedir configuration Why couldn't systemd just leave it alone? Partially reverts ec1ab43ca2ba22fbe7db5ad5bf2ba3800c31262a . --- krb5.spec | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 5ec582b..a465681 100644 --- a/krb5.spec +++ b/krb5.spec @@ -18,7 +18,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.18.3 # for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 4%{?dist} +Release: 5%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz @@ -254,6 +254,9 @@ sed -i -e s,7778,`expr "$PORT" + 1`,g $cfg source %{_libdir}/tclConfig.sh pushd src +# Set this so that configure will have a value - upstream defaults it from +# localstatedir, which is wrong for us. +export runstatedir=/run # Work out the CFLAGS and CPPFLAGS which we intend to use. INCLUDES=-I%{_includedir}/et CFLAGS="`echo $RPM_OPT_FLAGS $DEFINES $INCLUDES -fPIC -fno-strict-aliasing -fstack-protector-all`" @@ -289,6 +292,14 @@ CPPFLAGS="`echo $DEFINES $INCLUDES`" make popd +# Sanity check the KDC_RUN_DIR. +configured_dir=`grep KDC_RUN_DIR src/include/osconf.h | awk '{print $NF}'` +configured_dir=`eval echo $configured_dir` +if test "$configured_dir" != /run/krb5kdc ; then + echo Failed to configure KDC_RUN_DIR. + exit 1 +fi + # Build the docs. make -C src/doc paths.py version.py cp src/doc/paths.py doc/ @@ -628,6 +639,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Dec 16 2020 Robbie Harwood - 1.18.3-5 +- Fix runstatedir configuration +- Why couldn't systemd just leave it alone? + * Tue Nov 24 2020 Robbie Harwood - 1.18.3-4 - Document -k option in kvno(1) synopsis From 0da55d61754318f0a4bbf6903b86314706892ff8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 16 Dec 2020 16:06:50 +0000 Subject: [PATCH 210/304] New upstream version (1.19-beta1) --- .gitignore | 2 + Add-channel-bindings-tests.patch | 427 --------- ...client_aware_channel_bindings-option.patch | 264 ------ ...finalization-safety-check-to-com_err.patch | 53 -- ...e-kvno-options-from-Heimdal-kgetcred.patch | 404 -------- ...t-KDC-alias-helper-function-contract.patch | 80 -- ...ases-when-matching-U2U-second-ticket.patch | 65 -- ...tauth-modules-to-set-hw-authent-flag.patch | 241 ----- ...d-passing-DB-entry-structures-in-KDC.patch | 298 ------ ...y-import-service-GSS-host-based-name.patch | 52 -- ...ns_canonicalize_hostname-to-fallback.patch | 371 -------- ...ion-warnings-for-all-init_creds-APIs.patch | 425 --------- Document-k-option-in-kvno-1-synopsis.patch | 6 +- ...n-KERB_AP_OPTIONS_CBT-server-support.patch | 59 -- Fix-minor-static-analysis-defects.patch | 106 --- Fix-typo-in-in-in-the-ksu-man-page.patch | 37 - ...-enctypes-in-krb5_string_to_keysalts.patch | 37 - Implement-GSS_C_CHANNEL_BOUND_FLAG.patch | 91 -- ...ment-KERB_AP_OPTIONS_CBT-server-side.patch | 102 --- ...-KDC-alias-checking-for-S4U-requests.patch | 124 --- Improve-negoex_parse_token-code-hygiene.patch | 30 - Install-shared-libraries-as-executable.patch | 42 - Minimize-usage-of-tgs_server-in-KDC.patch | 316 ------- ...ndicator-check-for-S4U2Self-requests.patch | 48 - ...SER-if-we-can-t-compute-its-checksum.patch | 34 - Pass-channel-bindings-through-SPNEGO.patch | 256 ------ Pass-gss_localname-through-SPNEGO.patch | 58 -- ...KDC-authdata-list-management-helpers.patch | 335 ------- Refactor-krb5-GSS-checksum-handling.patch | 479 ---------- ...ly-acquired-creds-from-client-keytab.patch | 78 -- Remove-resolver-test-utility.patch | 547 ----------- ...ce-gssrpc-tests-with-a-Python-script.patch | 861 ------------------ ...eues-for-concurrent-t_otp.py-daemons.patch | 41 - ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 12 +- downstream-Remove-3des-support.patch | 209 ++--- downstream-SELinux-integration.patch | 28 +- ...ackported-version-of-OpenSSL-3-KDF-i.patch | 6 +- downstream-fix-debuginfo-with-y.tab.c.patch | 2 +- downstream-ksu-pam-integration.patch | 14 +- downstream-netlib-and-dns.patch | 6 +- krb5.spec | 69 +- sources | 4 +- 42 files changed, 162 insertions(+), 6557 deletions(-) delete mode 100644 Add-channel-bindings-tests.patch delete mode 100644 Add-client_aware_channel_bindings-option.patch delete mode 100644 Add-finalization-safety-check-to-com_err.patch delete mode 100644 Add-three-kvno-options-from-Heimdal-kgetcred.patch delete mode 100644 Adjust-KDC-alias-helper-function-contract.patch delete mode 100644 Allow-aliases-when-matching-U2U-second-ticket.patch delete mode 100644 Allow-certauth-modules-to-set-hw-authent-flag.patch delete mode 100644 Avoid-passing-DB-entry-structures-in-KDC.patch delete mode 100644 Correctly-import-service-GSS-host-based-name.patch delete mode 100644 Default-dns_canonicalize_hostname-to-fallback.patch delete mode 100644 Do-expiration-warnings-for-all-init_creds-APIs.patch delete mode 100644 Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch delete mode 100644 Fix-minor-static-analysis-defects.patch delete mode 100644 Fix-typo-in-in-in-the-ksu-man-page.patch delete mode 100644 Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch delete mode 100644 Implement-GSS_C_CHANNEL_BOUND_FLAG.patch delete mode 100644 Implement-KERB_AP_OPTIONS_CBT-server-side.patch delete mode 100644 Improve-KDC-alias-checking-for-S4U-requests.patch delete mode 100644 Improve-negoex_parse_token-code-hygiene.patch delete mode 100644 Install-shared-libraries-as-executable.patch delete mode 100644 Minimize-usage-of-tgs_server-in-KDC.patch delete mode 100644 Omit-KDC-indicator-check-for-S4U2Self-requests.patch delete mode 100644 Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch delete mode 100644 Pass-channel-bindings-through-SPNEGO.patch delete mode 100644 Pass-gss_localname-through-SPNEGO.patch delete mode 100644 Refactor-KDC-authdata-list-management-helpers.patch delete mode 100644 Refactor-krb5-GSS-checksum-handling.patch delete mode 100644 Refresh-manually-acquired-creds-from-client-keytab.patch delete mode 100644 Remove-resolver-test-utility.patch delete mode 100644 Replace-gssrpc-tests-with-a-Python-script.patch delete mode 100644 Use-two-queues-for-concurrent-t_otp.py-daemons.patch diff --git a/.gitignore b/.gitignore index 35b6d60..258cd98 100644 --- a/.gitignore +++ b/.gitignore @@ -189,3 +189,5 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.18.2.tar.gz.asc /krb5-1.18.3.tar.gz /krb5-1.18.3.tar.gz.asc +/krb5-1.19-beta1.tar.gz +/krb5-1.19-beta1.tar.gz.asc diff --git a/Add-channel-bindings-tests.patch b/Add-channel-bindings-tests.patch deleted file mode 100644 index caf14f6..0000000 --- a/Add-channel-bindings-tests.patch +++ /dev/null @@ -1,427 +0,0 @@ -From b9ca222798a52ef3a28185ed44f3dfe19579d8fc Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Fri, 20 Mar 2020 00:17:28 +0100 -Subject: [PATCH] Add channel bindings tests - -[ghudson@mit.edu: adjusted test program to output channel-bound state -instead of optionally enforcing it; adjusted tests to check program -output; split out tests into separate Python script; made cosmetic -changes] - -ticket: 8900 -(cherry picked from commit b0b21b6d25b06f3e2b365dfe9dd4c99b3d43bf57) -[rharwood@redhat.com: slush around upstream not backporting reload, -gitignore] ---- - src/plugins/gssapi/negoextest/main.c | 18 +++++ - src/tests/gssapi/Makefile.in | 57 +++++++------- - src/tests/gssapi/common.c | 25 ++++-- - src/tests/gssapi/common.h | 9 +++ - src/tests/gssapi/deps | 4 + - src/tests/gssapi/t_bindings.c | 111 +++++++++++++++++++++++++++ - src/tests/gssapi/t_bindings.py | 43 +++++++++++ - src/tests/gssapi/t_negoex.py | 7 ++ - 8 files changed, 242 insertions(+), 32 deletions(-) - create mode 100644 src/tests/gssapi/t_bindings.c - create mode 100644 src/tests/gssapi/t_bindings.py - -diff --git a/src/plugins/gssapi/negoextest/main.c b/src/plugins/gssapi/negoextest/main.c -index 6c340f41b..72fc5273a 100644 ---- a/src/plugins/gssapi/negoextest/main.c -+++ b/src/plugins/gssapi/negoextest/main.c -@@ -57,6 +57,15 @@ gss_init_sec_context(OM_uint32 *minor_status, - const char *envstr; - uint8_t hops, mech_last_octet; - -+ envstr = getenv("GSS_INIT_BINDING"); -+ if (envstr != NULL) { -+ assert(strlen(envstr) > 0); -+ assert(input_chan_bindings != GSS_C_NO_CHANNEL_BINDINGS); -+ assert(strlen(envstr) == input_chan_bindings->application_data.length); -+ assert(strcmp((char *)input_chan_bindings->application_data.value, -+ envstr) == 0); -+ } -+ - if (input_token == GSS_C_NO_BUFFER || input_token->length == 0) { - envstr = getenv("HOPS"); - hops = (envstr != NULL) ? atoi(envstr) : 1; -@@ -112,6 +121,15 @@ gss_accept_sec_context(OM_uint32 *minor_status, gss_ctx_id_t *context_handle, - uint8_t hops, mech_last_octet; - const char *envstr; - -+ envstr = getenv("GSS_ACCEPT_BINDING"); -+ if (envstr != NULL) { -+ assert(strlen(envstr) > 0); -+ assert(input_chan_bindings != GSS_C_NO_CHANNEL_BINDINGS); -+ assert(strlen(envstr) == input_chan_bindings->application_data.length); -+ assert(strcmp((char *)input_chan_bindings->application_data.value, -+ envstr) == 0); -+ } -+ - /* - * The unwrapped token sits at the end and is just one byte giving the - * remaining number of hops. The final octet of the mech encoding should -diff --git a/src/tests/gssapi/Makefile.in b/src/tests/gssapi/Makefile.in -index 22a2f9480..cf7bcf451 100644 ---- a/src/tests/gssapi/Makefile.in -+++ b/src/tests/gssapi/Makefile.in -@@ -8,34 +8,36 @@ LOCALINCLUDES = -I$(srcdir)/../../lib/gssapi/mechglue \ - -I$(srcdir)/../../lib/gssapi/generic -I../../lib/gssapi/krb5 \ - -I../../lib/gssapi/generic - --SRCS= $(srcdir)/ccinit.c $(srcdir)/ccrefresh.c $(srcdir)/common.c $(srcdir)/reload.c \ -- $(srcdir)/t_accname.c $(srcdir)/t_add_cred.c $(srcdir)/t_ccselect.c \ -- $(srcdir)/t_ciflags.c $(srcdir)/t_context.c $(srcdir)/t_credstore.c \ -- $(srcdir)/t_enctypes.c $(srcdir)/t_err.c $(srcdir)/t_export_cred.c \ -- $(srcdir)/t_export_name.c $(srcdir)/t_gssexts.c \ -- $(srcdir)/t_imp_cred.c $(srcdir)/t_imp_name.c $(srcdir)/t_invalid.c \ -- $(srcdir)/t_inq_cred.c $(srcdir)/t_inq_ctx.c \ -+SRCS= $(srcdir)/ccinit.c $(srcdir)/ccrefresh.c $(srcdir)/common.c \ -+ $(srcdir)/reload.c $(srcdir)/t_accname.c $(srcdir)/t_add_cred.c \ -+ $(srcdir)/t_bindings.c $(srcdir)/t_ccselect.c $(srcdir)/t_ciflags.c \ -+ $(srcdir)/t_context.c $(srcdir)/t_credstore.c $(srcdir)/t_enctypes.c \ -+ $(srcdir)/t_err.c $(srcdir)/t_export_cred.c $(srcdir)/t_export_name.c \ -+ $(srcdir)/t_gssexts.c $(srcdir)/t_imp_cred.c $(srcdir)/t_imp_name.c \ -+ $(srcdir)/t_invalid.c $(srcdir)/t_inq_cred.c $(srcdir)/t_inq_ctx.c \ - $(srcdir)/t_inq_mechs_name.c $(srcdir)/t_iov.c \ - $(srcdir)/t_lifetime.c $(srcdir)/t_namingexts.c $(srcdir)/t_oid.c \ - $(srcdir)/t_pcontok.c $(srcdir)/t_prf.c $(srcdir)/t_s4u.c \ - $(srcdir)/t_s4u2proxy_krb5.c $(srcdir)/t_saslname.c \ - $(srcdir)/t_spnego.c $(srcdir)/t_srcattrs.c - --OBJS= ccinit.o ccrefresh.o common.o reload.o t_accname.o t_add_cred.o t_ccselect.o \ -- t_ciflags.o t_context.o t_credstore.o t_enctypes.o t_err.o \ -- t_export_cred.o t_export_name.o t_gssexts.o t_imp_cred.o t_imp_name.o \ -- t_invalid.o t_inq_cred.o t_inq_ctx.o t_inq_mechs_name.o t_iov.o \ -- t_lifetime.o t_namingexts.o t_oid.o t_pcontok.o t_prf.o t_s4u.o \ -- t_s4u2proxy_krb5.o t_saslname.o t_spnego.o t_srcattrs.o -+ -+OBJS= ccinit.o ccrefresh.o common.o reload.o t_accname.o t_add_cred.o \ -+ t_bindings.o t_ccselect.o t_ciflags.o t_context.o t_credstore.o \ -+ t_enctypes.o t_err.o t_export_cred.o t_export_name.o t_gssexts.o \ -+ t_imp_cred.o t_imp_name.o t_invalid.o t_inq_cred.o t_inq_ctx.o \ -+ t_inq_mechs_name.o t_iov.o t_lifetime.o t_namingexts.o t_oid.o \ -+ t_pcontok.o t_prf.o t_s4u.o t_s4u2proxy_krb5.o t_saslname.o \ -+ t_spnego.o t_srcattrs.o - - COMMON_DEPS= common.o $(GSS_DEPLIBS) $(KRB5_BASE_DEPLIBS) - COMMON_LIBS= common.o $(GSS_LIBS) $(KRB5_BASE_LIBS) - --all: ccinit ccrefresh t_accname t_add_cred t_ccselect t_ciflags t_context \ -- t_credstore t_enctypes t_err t_export_cred t_export_name t_gssexts \ -- t_imp_cred t_imp_name t_invalid t_inq_cred t_inq_ctx t_inq_mechs_name \ -- t_iov t_lifetime t_namingexts t_oid t_pcontok t_prf t_s4u \ -- t_s4u2proxy_krb5 t_saslname t_spnego t_srcattrs -+all: ccinit ccrefresh t_accname t_add_cred t_bindings t_ccselect t_ciflags \ -+ t_context t_credstore t_enctypes t_err t_export_cred t_export_name \ -+ t_gssexts t_imp_cred t_imp_name t_invalid t_inq_cred t_inq_ctx \ -+ t_inq_mechs_name t_iov t_lifetime t_namingexts t_oid t_pcontok t_prf \ -+ t_s4u t_s4u2proxy_krb5 t_saslname t_spnego t_srcattrs - - check-unix: t_oid reload - $(RUN_TEST) ./t_invalid -@@ -44,11 +46,12 @@ check-unix: t_oid reload - $(RUN_TEST) ./t_imp_name - if [ -r $(TOPLIBD)/libgssapi_krb5.so ]; then $(RUN_TEST) ./reload; fi - --check-pytests: ccinit ccrefresh t_accname t_add_cred t_ccselect t_ciflags \ -- t_context t_credstore t_enctypes t_err t_export_cred t_export_name \ -- t_imp_cred t_inq_cred t_inq_ctx t_inq_mechs_name t_iov t_lifetime \ -- t_pcontok t_s4u t_s4u2proxy_krb5 t_spnego t_srcattrs -+check-pytests: ccinit ccrefresh t_accname t_add_cred t_bindings t_ccselect \ -+ t_ciflags t_context t_credstore t_enctypes t_err t_export_cred \ -+ t_export_name t_imp_cred t_inq_cred t_inq_ctx t_inq_mechs_name t_iov \ -+ t_lifetime t_pcontok t_s4u t_s4u2proxy_krb5 t_spnego t_srcattrs - $(RUNPYTEST) $(srcdir)/t_gssapi.py $(PYTESTFLAGS) -+ $(RUNPYTEST) $(srcdir)/t_bindings.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_ccselect.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_client_keytab.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_enctypes.py $(PYTESTFLAGS) -@@ -67,6 +70,8 @@ t_accname: t_accname.o $(COMMON_DEPS) - $(CC_LINK) -o $@ t_accname.o $(COMMON_LIBS) - t_add_cred: t_add_cred.o $(COMMON_DEPS) - $(CC_LINK) -o $@ t_add_cred.o $(COMMON_LIBS) -+t_bindings: t_bindings.o $(COMMON_DEPS) -+ $(CC_LINK) -o $@ t_bindings.o $(COMMON_LIBS) - t_ccselect: t_ccselect.o $(COMMON_DEPS) - $(CC_LINK) -o $@ t_ccselect.o $(COMMON_LIBS) - t_ciflags: t_ciflags.o $(COMMON_DEPS) -@@ -121,9 +126,9 @@ t_srcattrs: t_srcattrs.o $(COMMON_DEPS) - $(CC_LINK) -o $@ t_srcattrs.o $(COMMON_LIBS) - - clean: -- $(RM) ccinit ccrefresh reload t_accname t_add_cred t_ccselect t_ciflags -- $(RM) t_context t_credstore t_enctypes t_err t_export_cred -- $(RM) t_export_name t_gssexts t_imp_cred t_imp_name t_invalid -- $(RM) t_inq_cred t_inq_ctx t_inq_mechs_name t_iov t_lifetime -+ $(RM) ccinit ccrefresh reload t_accname t_add_cred t_bindings -+ $(RM) t_ccselect t_ciflags t_context t_credstore t_enctypes t_err -+ $(RM) t_export_cred t_export_name t_gssexts t_imp_cred t_imp_name -+ $(RM) t_invalid t_inq_cred t_inq_ctx t_inq_mechs_name t_iov t_lifetime - $(RM) t_namingexts t_oid t_pcontok t_prf t_s4u t_s4u2proxy_krb5 - $(RM) t_saslname t_spnego t_srcattrs -diff --git a/src/tests/gssapi/common.c b/src/tests/gssapi/common.c -index 83e9d9bb8..7ba72f7b2 100644 ---- a/src/tests/gssapi/common.c -+++ b/src/tests/gssapi/common.c -@@ -115,6 +115,20 @@ establish_contexts(gss_OID imech, gss_cred_id_t icred, gss_cred_id_t acred, - gss_name_t tname, OM_uint32 flags, gss_ctx_id_t *ictx, - gss_ctx_id_t *actx, gss_name_t *src_name, gss_OID *amech, - gss_cred_id_t *deleg_cred) -+{ -+ return establish_contexts_ex(imech, icred, acred, tname, flags, ictx, actx, -+ GSS_C_NO_CHANNEL_BINDINGS, -+ GSS_C_NO_CHANNEL_BINDINGS, NULL, src_name, -+ amech, deleg_cred); -+} -+ -+void -+establish_contexts_ex(gss_OID imech, gss_cred_id_t icred, gss_cred_id_t acred, -+ gss_name_t tname, OM_uint32 flags, gss_ctx_id_t *ictx, -+ gss_ctx_id_t *actx, gss_channel_bindings_t icb, -+ gss_channel_bindings_t acb, OM_uint32 *aret_flags, -+ gss_name_t *src_name, gss_OID *amech, -+ gss_cred_id_t *deleg_cred) - { - OM_uint32 minor, imaj, amaj; - gss_buffer_desc itok, atok; -@@ -126,17 +140,16 @@ establish_contexts(gss_OID imech, gss_cred_id_t icred, gss_cred_id_t acred, - for (;;) { - (void)gss_release_buffer(&minor, &itok); - imaj = gss_init_sec_context(&minor, icred, ictx, tname, imech, flags, -- GSS_C_INDEFINITE, -- GSS_C_NO_CHANNEL_BINDINGS, &atok, NULL, -- &itok, NULL, NULL); -+ GSS_C_INDEFINITE, icb, &atok, NULL, &itok, -+ NULL, NULL); - check_gsserr("gss_init_sec_context", imaj, minor); - if (amaj == GSS_S_COMPLETE) - break; - - (void)gss_release_buffer(&minor, &atok); -- amaj = gss_accept_sec_context(&minor, actx, acred, &itok, -- GSS_C_NO_CHANNEL_BINDINGS, src_name, -- amech, &atok, NULL, NULL, deleg_cred); -+ amaj = gss_accept_sec_context(&minor, actx, acred, &itok, acb, -+ src_name, amech, &atok, aret_flags, NULL, -+ deleg_cred); - check_gsserr("gss_accept_sec_context", amaj, minor); - (void)gss_release_buffer(&minor, &itok); - if (imaj == GSS_S_COMPLETE) -diff --git a/src/tests/gssapi/common.h b/src/tests/gssapi/common.h -index ae11b51d4..a5c8f87e6 100644 ---- a/src/tests/gssapi/common.h -+++ b/src/tests/gssapi/common.h -@@ -62,6 +62,15 @@ void establish_contexts(gss_OID imech, gss_cred_id_t icred, - gss_name_t *src_name, gss_OID *amech, - gss_cred_id_t *deleg_cred); - -+/* Establish contexts with channel bindings. */ -+void establish_contexts_ex(gss_OID imech, gss_cred_id_t icred, -+ gss_cred_id_t acred, gss_name_t tname, -+ OM_uint32 flags, gss_ctx_id_t *ictx, -+ gss_ctx_id_t *actx, gss_channel_bindings_t icb, -+ gss_channel_bindings_t acb, OM_uint32 *aret_flags, -+ gss_name_t *src_name, gss_OID *amech, -+ gss_cred_id_t *deleg_cred); -+ - /* Export *cred to a token, then release *cred and replace it by re-importing - * the token. */ - void export_import_cred(gss_cred_id_t *cred); -diff --git a/src/tests/gssapi/deps b/src/tests/gssapi/deps -index 55586de53..ca1d6e22a 100644 ---- a/src/tests/gssapi/deps -+++ b/src/tests/gssapi/deps -@@ -35,6 +35,10 @@ $(OUTPRE)t_add_cred.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ - $(BUILDTOP)/include/gssapi/gssapi_ext.h $(BUILDTOP)/include/gssapi/gssapi_krb5.h \ - $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h \ - common.h t_add_cred.c -+$(OUTPRE)t_bindings.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ -+ $(BUILDTOP)/include/gssapi/gssapi_ext.h $(BUILDTOP)/include/gssapi/gssapi_krb5.h \ -+ $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h \ -+ common.h t_bindings.c - $(OUTPRE)t_ccselect.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ - $(BUILDTOP)/include/gssapi/gssapi_ext.h $(BUILDTOP)/include/gssapi/gssapi_krb5.h \ - $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/krb5.h \ -diff --git a/src/tests/gssapi/t_bindings.c b/src/tests/gssapi/t_bindings.c -new file mode 100644 -index 000000000..e8906715b ---- /dev/null -+++ b/src/tests/gssapi/t_bindings.c -@@ -0,0 +1,111 @@ -+/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -+/* -+ * Copyright (C) 2020 by Red Hat, Inc. -+ * All rights reserved. -+ * -+ * Redistribution and use in source and binary forms, with or without -+ * modification, are permitted provided that the following conditions -+ * are met: -+ * -+ * * Redistributions of source code must retain the above copyright -+ * notice, this list of conditions and the following disclaimer. -+ * -+ * * Redistributions in binary form must reproduce the above copyright -+ * notice, this list of conditions and the following disclaimer in -+ * the documentation and/or other materials provided with the -+ * distribution. -+ * -+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS -+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT -+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS -+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE -+ * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, -+ * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES -+ * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR -+ * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) -+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, -+ * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) -+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED -+ * OF THE POSSIBILITY OF SUCH DAMAGE. -+ */ -+ -+#include -+#include -+#include -+ -+#include "common.h" -+ -+/* -+ * Establish contexts (without and with GSS_C_DCE_STYLE) with the default -+ * initiator name, a specified principal name as target name, initiator -+ * bindings, and acceptor bindings. If any call is unsuccessful, display an -+ * error message. Output "yes" or "no" to indicate whether the contexts were -+ * reported as channel-bound on the acceptor. Exit with status 0 if all -+ * operations are successful, or 1 if not. -+ * -+ * Usage: ./t_bindings [-s] targetname icb acb -+ * -+ * An icb or abc value of "-" will not specify channel bindings. -+ */ -+ -+int -+main(int argc, char *argv[]) -+{ -+ OM_uint32 minor, flags1, flags2; -+ gss_name_t target_name; -+ gss_ctx_id_t ictx, actx; -+ struct gss_channel_bindings_struct icb_data = {0}, acb_data = {0}; -+ gss_channel_bindings_t icb = GSS_C_NO_CHANNEL_BINDINGS; -+ gss_channel_bindings_t acb = GSS_C_NO_CHANNEL_BINDINGS; -+ gss_OID_desc *mech; -+ -+ argv++; -+ argc--; -+ if (*argv != NULL && strcmp(*argv, "-s") == 0) { -+ mech = &mech_spnego; -+ argv++; -+ argc--; -+ } else { -+ mech = &mech_krb5; -+ } -+ -+ if (argc != 3) { -+ fprintf(stderr, "Usage: t_bindings [-s] targetname icb acb\n"); -+ return 1; -+ } -+ -+ target_name = import_name(argv[0]); -+ -+ if (strcmp(argv[1], "-") != 0) { -+ icb_data.application_data.length = strlen(argv[1]); -+ icb_data.application_data.value = argv[1]; -+ icb = &icb_data; -+ } -+ -+ if (strcmp(argv[2], "-") != 0) { -+ acb_data.application_data.length = strlen(argv[2]); -+ acb_data.application_data.value = argv[2]; -+ acb = &acb_data; -+ } -+ -+ establish_contexts_ex(mech, GSS_C_NO_CREDENTIAL, GSS_C_NO_CREDENTIAL, -+ target_name, 0, &ictx, &actx, icb, acb, &flags1, -+ NULL, NULL, NULL); -+ -+ /* Try again with GSS_C_DCE_STYLE */ -+ (void)gss_delete_sec_context(&minor, &ictx, NULL); -+ (void)gss_delete_sec_context(&minor, &actx, NULL); -+ -+ establish_contexts_ex(mech, GSS_C_NO_CREDENTIAL, GSS_C_NO_CREDENTIAL, -+ target_name, GSS_C_DCE_STYLE, &ictx, &actx, icb, acb, -+ &flags2, NULL, NULL, NULL); -+ assert((flags1 & GSS_C_CHANNEL_BOUND_FLAG) == -+ (flags2 & GSS_C_CHANNEL_BOUND_FLAG)); -+ printf("%s\n", (flags1 & GSS_C_CHANNEL_BOUND_FLAG) ? "yes" : "no"); -+ -+ (void)gss_delete_sec_context(&minor, &ictx, NULL); -+ (void)gss_delete_sec_context(&minor, &actx, NULL); -+ (void)gss_release_name(&minor, &target_name); -+ -+ return 0; -+} -diff --git a/src/tests/gssapi/t_bindings.py b/src/tests/gssapi/t_bindings.py -new file mode 100644 -index 000000000..f377977b6 ---- /dev/null -+++ b/src/tests/gssapi/t_bindings.py -@@ -0,0 +1,43 @@ -+from k5test import * -+ -+realm = K5Realm() -+server = 'p:' + realm.host_princ -+ -+mark('krb5 channel bindings') -+realm.run(['./t_bindings', server, '-', '-'], expected_msg='no') -+realm.run(['./t_bindings', server, 'a', '-'], expected_msg='no') -+realm.run(['./t_bindings', server, 'a', 'a'], expected_msg='yes') -+realm.run(['./t_bindings', server, '-', 'a'], expected_msg='no') -+realm.run(['./t_bindings', server, 'a', 'x'], -+ expected_code=1, expected_msg='Incorrect channel bindings') -+ -+mark('SPNEGO channel bindings') -+realm.run(['./t_bindings', '-s', server, '-', '-'], expected_msg='no') -+realm.run(['./t_bindings', '-s', server, 'a', '-'], expected_msg='no') -+realm.run(['./t_bindings', '-s', server, 'a', 'a'], expected_msg='yes') -+realm.run(['./t_bindings', '-s', server, '-', 'a'], expected_msg='no') -+realm.run(['./t_bindings', '-s', server, 'a', 'x'], -+ expected_code=1, expected_msg='Incorrect channel bindings') -+ -+client_aware_conf = {'libdefaults': {'client_aware_channel_bindings': 'true'}} -+e = realm.special_env('cb_aware', False, krb5_conf=client_aware_conf) -+ -+mark('krb5 client_aware_channel_bindings') -+realm.run(['./t_bindings', server, '-', '-'], env=e, expected_msg='no') -+realm.run(['./t_bindings', server, 'a', '-'], env=e, expected_msg='no') -+realm.run(['./t_bindings', server, 'a', 'a'], env=e, expected_msg='yes') -+realm.run(['./t_bindings', server, '-', 'a'], env=e, -+ expected_code=1, expected_msg='Incorrect channel bindings') -+realm.run(['./t_bindings', server, 'a', 'x'], env=e, -+ expected_code=1, expected_msg='Incorrect channel bindings') -+ -+mark('SPNEGO client_aware_channel_bindings') -+realm.run(['./t_bindings', '-s', server, '-', '-'], env=e, expected_msg='no') -+realm.run(['./t_bindings', '-s', server, 'a', '-'], env=e, expected_msg='no') -+realm.run(['./t_bindings', '-s', server, 'a', 'a'], env=e, expected_msg='yes') -+realm.run(['./t_bindings', '-s', server, '-', 'a'], env=e, -+ expected_code=1, expected_msg='Incorrect channel bindings') -+realm.run(['./t_bindings', '-s', server, 'a', 'x'], env=e, -+ expected_code=1, expected_msg='Incorrect channel bindings') -+ -+success('channel bindings tests') -diff --git a/src/tests/gssapi/t_negoex.py b/src/tests/gssapi/t_negoex.py -index 88470d2fa..a218899c4 100644 ---- a/src/tests/gssapi/t_negoex.py -+++ b/src/tests/gssapi/t_negoex.py -@@ -139,4 +139,11 @@ msgs = ('sending [3]AP_REQUEST', 'sending [7]CHALLENGE', 'sending [8]VERIFY', - 'sending [11]CHALLENGE', 'sending [12]VERIFY', 'sending [13]VERIFY') - test({'HOPS': '4', 'KEY': 'accept-always'}, expected_trace=()) - -+mark('channel bindings') -+e = realm.env.copy() -+e.update({'HOPS': '1', 'GSS_INIT_BINDING': 'a', 'GSS_ACCEPT_BINDING': 'b'}) -+# The test mech will verify that the bindings are communicated to the -+# mech, but does not set the channel-bound flag. -+realm.run(['./t_bindings', '-s', 'h:host', 'a', 'b'], env=e, expected_msg='no') -+ - success('NegoEx tests') diff --git a/Add-client_aware_channel_bindings-option.patch b/Add-client_aware_channel_bindings-option.patch deleted file mode 100644 index 20ecd30..0000000 --- a/Add-client_aware_channel_bindings-option.patch +++ /dev/null @@ -1,264 +0,0 @@ -From 032c7f496c9b327752dda33bf85e74c66d3a93cf Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Tue, 10 Mar 2020 13:13:17 +0100 -Subject: [PATCH] Add client_aware_channel_bindings option - -Add client support for KERB_AP_OPTIONS_CBT in the form of a profile -option "client_aware_gss_bindings". Adjust the make_etype_list() -helper so that enctype negotiation and AP_OPTIONS can be included in -the same IF-RELEVANT wrapper. - -[ghudson@mit.edu: refactored; edited documentation; wrote commit -message] - -ticket: 8900 -(cherry picked from commit 225e6ef7f021cd1a8ef2a054af0ca58b7288fd81) ---- - doc/admin/conf_files/krb5_conf.rst | 6 + - src/include/k5-int.h | 1 + - src/lib/krb5/krb/mk_req_ext.c | 177 +++++++++++++++-------------- - 3 files changed, 98 insertions(+), 86 deletions(-) - -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 38f450367..da5ad00f2 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -388,6 +388,12 @@ The libdefaults section may contain any of the following relations: - credentials will fail if the client machine does not have a - keytab. The default value is false. - -+**client_aware_channel_bindings** -+ If this flag is true, then all application protocol authentication -+ requests will be flagged to indicate that the application supports -+ channel bindings when operating over a secure channel. The -+ default value is false. -+ - .. _realms: - - [realms] -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 0d9af3d95..eb18a4cd6 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -299,6 +299,7 @@ typedef unsigned char u_char; - #define KRB5_CONF_V4_INSTANCE_CONVERT "v4_instance_convert" - #define KRB5_CONF_V4_REALM "v4_realm" - #define KRB5_CONF_VERIFY_AP_REQ_NOFAIL "verify_ap_req_nofail" -+#define KRB5_CONF_CLIENT_AWARE_GSS_BINDINGS "client_aware_channel_bindings" - - /* Cache configuration variables */ - #define KRB5_CC_CONF_FAST_AVAIL "fast_avail" -diff --git a/src/lib/krb5/krb/mk_req_ext.c b/src/lib/krb5/krb/mk_req_ext.c -index 9fc6a0e52..08504860c 100644 ---- a/src/lib/krb5/krb/mk_req_ext.c -+++ b/src/lib/krb5/krb/mk_req_ext.c -@@ -68,10 +68,9 @@ - */ - - static krb5_error_code --make_etype_list(krb5_context context, -- krb5_enctype *desired_etypes, -- krb5_enctype tkt_enctype, -- krb5_authdata ***authdata); -+make_ap_authdata(krb5_context context, krb5_enctype *desired_enctypes, -+ krb5_enctype tkt_enctype, krb5_boolean client_aware_cb, -+ krb5_authdata ***authdata_out); - - static krb5_error_code - generate_authenticator(krb5_context, -@@ -263,7 +262,8 @@ generate_authenticator(krb5_context context, krb5_authenticator *authent, - krb5_enctype tkt_enctype) - { - krb5_error_code retval; -- krb5_authdata **ext_authdata = NULL; -+ krb5_authdata **ext_authdata = NULL, **ap_authdata, **combined; -+ int client_aware_cb; - - authent->client = client; - authent->checksum = cksum; -@@ -297,99 +297,104 @@ generate_authenticator(krb5_context context, krb5_authenticator *authent, - krb5_free_authdata(context, ext_authdata); - } - -- /* Only send EtypeList if we prefer another enctype to tkt_enctype */ -- if (desired_etypes != NULL && desired_etypes[0] != tkt_enctype) { -- TRACE_MK_REQ_ETYPES(context, desired_etypes); -- retval = make_etype_list(context, desired_etypes, tkt_enctype, -- &authent->authorization_data); -+ retval = profile_get_boolean(context->profile, KRB5_CONF_LIBDEFAULTS, -+ KRB5_CONF_CLIENT_AWARE_GSS_BINDINGS, NULL, -+ FALSE, &client_aware_cb); -+ if (retval) -+ return retval; -+ -+ /* Add etype negotiation or channel-binding awareness authdata to the -+ * front, if appropriate. */ -+ retval = make_ap_authdata(context, desired_etypes, tkt_enctype, -+ client_aware_cb, &ap_authdata); -+ if (retval) -+ return retval; -+ if (ap_authdata != NULL) { -+ retval = krb5_merge_authdata(context, ap_authdata, -+ authent->authorization_data, &combined); -+ krb5_free_authdata(context, ap_authdata); - if (retval) - return retval; -+ krb5_free_authdata(context, authent->authorization_data); -+ authent->authorization_data = combined; - } - - return(krb5_us_timeofday(context, &authent->ctime, &authent->cusec)); - } - --/* RFC 4537 */ -+/* Set *out to a DER-encoded RFC 4537 etype list, or to NULL if no etype list -+ * should be sent. */ - static krb5_error_code --make_etype_list(krb5_context context, -- krb5_enctype *desired_etypes, -- krb5_enctype tkt_enctype, -- krb5_authdata ***authdata) -+make_etype_list(krb5_context context, krb5_enctype *desired_enctypes, -+ krb5_enctype tkt_enctype, krb5_data **out) - { -- krb5_error_code code; -- krb5_etype_list etypes; -- krb5_data *enc_etype_list; -- krb5_data *ad_if_relevant; -- krb5_authdata *etype_adata[2], etype_adatum, **adata; -- int i; -+ krb5_etype_list etlist; -+ int count; - -- etypes.etypes = desired_etypes; -+ *out = NULL; - -- for (etypes.length = 0; -- etypes.etypes[etypes.length] != ENCTYPE_NULL; -- etypes.length++) -- { -- /* -- * RFC 4537: -- * -- * If the enctype of the ticket session key is included in the enctype -- * list sent by the client, it SHOULD be the last on the list; -- */ -- if (etypes.length && etypes.etypes[etypes.length - 1] == tkt_enctype) -+ /* Only send a list if we prefer another enctype to tkt_enctype. */ -+ if (desired_enctypes == NULL || desired_enctypes[0] == tkt_enctype) -+ return 0; -+ -+ /* Count elements of desired_etypes, stopping at tkt_enctypes if present. -+ * (Per RFC 4537, it must be the last option if it is included.) */ -+ for (count = 0; desired_enctypes[count] != ENCTYPE_NULL; count++) { -+ if (count > 0 && desired_enctypes[count - 1] == tkt_enctype) - break; - } - -- code = encode_krb5_etype_list(&etypes, &enc_etype_list); -- if (code) { -- return code; -- } -- -- etype_adatum.magic = KV5M_AUTHDATA; -- etype_adatum.ad_type = KRB5_AUTHDATA_ETYPE_NEGOTIATION; -- etype_adatum.length = enc_etype_list->length; -- etype_adatum.contents = (krb5_octet *)enc_etype_list->data; -- -- etype_adata[0] = &etype_adatum; -- etype_adata[1] = NULL; -- -- /* Wrap in AD-IF-RELEVANT container */ -- code = encode_krb5_authdata(etype_adata, &ad_if_relevant); -- if (code) { -- krb5_free_data(context, enc_etype_list); -- return code; -- } -- -- krb5_free_data(context, enc_etype_list); -- -- adata = *authdata; -- if (adata == NULL) { -- adata = (krb5_authdata **)calloc(2, sizeof(krb5_authdata *)); -- i = 0; -- } else { -- for (i = 0; adata[i] != NULL; i++) -- ; -- -- adata = (krb5_authdata **)realloc(*authdata, -- (i + 2) * sizeof(krb5_authdata *)); -- } -- if (adata == NULL) { -- krb5_free_data(context, ad_if_relevant); -- return ENOMEM; -- } -- *authdata = adata; -- -- adata[i] = (krb5_authdata *)malloc(sizeof(krb5_authdata)); -- if (adata[i] == NULL) { -- krb5_free_data(context, ad_if_relevant); -- return ENOMEM; -- } -- adata[i]->magic = KV5M_AUTHDATA; -- adata[i]->ad_type = KRB5_AUTHDATA_IF_RELEVANT; -- adata[i]->length = ad_if_relevant->length; -- adata[i]->contents = (krb5_octet *)ad_if_relevant->data; -- free(ad_if_relevant); /* contents owned by adata[i] */ -- -- adata[i + 1] = NULL; -- -- return 0; -+ etlist.etypes = desired_enctypes; -+ etlist.length = count; -+ return encode_krb5_etype_list(&etlist, out); -+} -+ -+/* Set *authdata_out to appropriate authenticator authdata for the request, -+ * encoded in a single AD_IF_RELEVANT element. */ -+static krb5_error_code -+make_ap_authdata(krb5_context context, krb5_enctype *desired_enctypes, -+ krb5_enctype tkt_enctype, krb5_boolean client_aware_cb, -+ krb5_authdata ***authdata_out) -+{ -+ krb5_error_code ret; -+ krb5_authdata etypes_ad, flags_ad, *list[3]; -+ krb5_data *der_etypes = NULL; -+ size_t count = 0; -+ uint8_t flagbuf[4]; -+ const uint32_t KERB_AP_OPTIONS_CBT = 0x4000; -+ -+ *authdata_out = NULL; -+ -+ /* Include an ETYPE_NEGOTIATION element if appropriate. */ -+ ret = make_etype_list(context, desired_enctypes, tkt_enctype, &der_etypes); -+ if (ret) -+ goto cleanup; -+ if (der_etypes != NULL) { -+ etypes_ad.magic = KV5M_AUTHDATA; -+ etypes_ad.ad_type = KRB5_AUTHDATA_ETYPE_NEGOTIATION; -+ etypes_ad.length = der_etypes->length; -+ etypes_ad.contents = (uint8_t *)der_etypes->data; -+ list[count++] = &etypes_ad; -+ } -+ -+ /* Include an AP_OPTIONS element if the CBT flag is configured. */ -+ if (client_aware_cb != 0) { -+ store_32_le(KERB_AP_OPTIONS_CBT, flagbuf); -+ flags_ad.magic = KV5M_AUTHDATA; -+ flags_ad.ad_type = KRB5_AUTHDATA_AP_OPTIONS; -+ flags_ad.length = 4; -+ flags_ad.contents = flagbuf; -+ list[count++] = &flags_ad; -+ } -+ -+ if (count > 0) { -+ list[count] = NULL; -+ ret = krb5_encode_authdata_container(context, -+ KRB5_AUTHDATA_IF_RELEVANT, -+ list, authdata_out); -+ } -+ -+cleanup: -+ krb5_free_data(context, der_etypes); -+ return ret; - } diff --git a/Add-finalization-safety-check-to-com_err.patch b/Add-finalization-safety-check-to-com_err.patch deleted file mode 100644 index d717bcc..0000000 --- a/Add-finalization-safety-check-to-com_err.patch +++ /dev/null @@ -1,53 +0,0 @@ -From 903fc418db4f5819c507cb0d42c0d4a12217c22f Mon Sep 17 00:00:00 2001 -From: Jiri Sasek -Date: Fri, 13 Mar 2020 19:02:58 +0100 -Subject: [PATCH] Add finalization safety check to com_err - -If the linker erroneously runs the libkrb5 finalizer after the -libcom_err finalizer, the consequent remove_error_table() calls could -crash due to accessing a destroyed mutex or an invalid et_list -pointer. Add an unsynchronized check on finalized in -remove_error_table(), and set et_list to null in com_err_terminate() -after destroying the list. - -[ghudson@mit.edu: minimized code hanges; rewrote comment and commit -message] - -ticket: 8890 (new) -(cherry picked from commit 9d654aa05e26bbf22f140abde3436afeff2fdf8d) ---- - src/util/et/error_message.c | 7 ++++++- - 1 file changed, 6 insertions(+), 1 deletion(-) - -diff --git a/src/util/et/error_message.c b/src/util/et/error_message.c -index d7069a9df..7dc02a34e 100644 ---- a/src/util/et/error_message.c -+++ b/src/util/et/error_message.c -@@ -26,7 +26,7 @@ - - static struct et_list *et_list; - static k5_mutex_t et_list_lock = K5_MUTEX_PARTIAL_INITIALIZER; --static int terminated = 0; /* for debugging shlib fini sequence errors */ -+static int terminated = 0; /* for safety and finalization debugging */ - - MAKE_INIT_FUNCTION(com_err_initialize); - MAKE_FINI_FUNCTION(com_err_terminate); -@@ -69,6 +69,7 @@ void com_err_terminate(void) - enext = e->next; - free(e); - } -+ et_list = NULL; - k5_mutex_unlock(&et_list_lock); - k5_mutex_destroy(&et_list_lock); - terminated = 1; -@@ -280,6 +281,10 @@ remove_error_table(const struct error_table *et) - { - struct et_list **ep, *e; - -+ /* Safety check in case libraries are finalized in the wrong order. */ -+ if (terminated) -+ return ENOENT; -+ - if (CALL_INIT_FUNCTION(com_err_initialize)) - return 0; - k5_mutex_lock(&et_list_lock); diff --git a/Add-three-kvno-options-from-Heimdal-kgetcred.patch b/Add-three-kvno-options-from-Heimdal-kgetcred.patch deleted file mode 100644 index a68394c..0000000 --- a/Add-three-kvno-options-from-Heimdal-kgetcred.patch +++ /dev/null @@ -1,404 +0,0 @@ -From ea2ad3330aa39ef4e62d8856ea7e8eed2843b3f2 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 17 Jun 2020 20:48:38 -0400 -Subject: [PATCH] Add three kvno options from Heimdal kgetcred - -Add the flags --cached-only and --no-store, which pass the -corresponding options to krb5_get_credentials(). Add the option ---out-cache to write the retrieved credentials to a specified output -cache. - -Add a Python test script for kvno command-line options, including -tests for the new options. - -ticket: 8917 (new) -(cherry picked from commit 876bab8418d7dd134c9d9db812ee2118d5ad58f0) -[rharwood@redhat.com: slush around option unification] ---- - doc/user/user_commands/kvno.rst | 13 ++++ - src/clients/kvno/Makefile.in | 3 + - src/clients/kvno/kvno.c | 112 +++++++++++++++++++++++--------- - src/clients/kvno/t_kvno.py | 75 +++++++++++++++++++++ - src/man/kvno.man | 13 ++++ - 5 files changed, 185 insertions(+), 31 deletions(-) - create mode 100644 src/clients/kvno/t_kvno.py - -diff --git a/doc/user/user_commands/kvno.rst b/doc/user/user_commands/kvno.rst -index 53e569651..6fd8577a5 100644 ---- a/doc/user/user_commands/kvno.rst -+++ b/doc/user/user_commands/kvno.rst -@@ -75,6 +75,19 @@ OPTIONS - client principal with the X.509 certificate in *cert_file*. The - certificate file must be in PEM format. - -+**--cached-only** -+ Only retrieve credentials already present in the cache, not from -+ the KDC. -+ -+**--no-store** -+ Do not store retrieved credentials in the cache. If -+ **--out-cache** is also specified, credentials will still be -+ stored into the output credential cache. -+ -+**--out-cache** *ccache* -+ Initialize *ccache* and store all retrieved credentials into it. -+ Do not store acquired credentials in the input cache. -+ - **--u2u** *ccache* - Requests a user-to-user ticket. *ccache* must contain a local - krbtgt ticket for the server principal. The reported version -diff --git a/src/clients/kvno/Makefile.in b/src/clients/kvno/Makefile.in -index 1c3f79392..5ba877271 100644 ---- a/src/clients/kvno/Makefile.in -+++ b/src/clients/kvno/Makefile.in -@@ -26,6 +26,9 @@ kvno: kvno.o $(KRB5_BASE_DEPLIBS) - ##WIN32## link $(EXE_LINKOPTS) /out:$@ $** - ##WIN32## $(_VC_MANIFEST_EMBED_EXE) - -+check-pytests: kvno -+ $(RUNPYTEST) $(srcdir)/t_kvno.py $(PYTESTFLAGS) -+ - clean-unix:: - $(RM) kvno.o kvno - -diff --git a/src/clients/kvno/kvno.c b/src/clients/kvno/kvno.c -index 8edd97361..c5f6bf700 100644 ---- a/src/clients/kvno/kvno.c -+++ b/src/clients/kvno/kvno.c -@@ -47,15 +47,17 @@ xusage() - "[-u | -S sname]" XUSAGE_BREAK - "[[{-F cert_file | {-I | -U} for_user} [-P]] | " - "--u2u ccache]" XUSAGE_BREAK -+ "[--cached-only] [--no-store] [--out-cache] " - "service1 service2 ...\n"), - prog); - exit(1); - } - - static void do_v5_kvno(int argc, char *argv[], char *ccachestr, char *etypestr, -- char *keytab_name, char *sname, int canon, int unknown, -- char *for_user, int for_user_enterprise, -- char *for_user_cert_file, int proxy, -+ char *keytab_name, char *sname, int cached_only, -+ int canon, int no_store, int unknown, char *for_user, -+ int for_user_enterprise, char *for_user_cert_file, -+ int proxy, const char *out_ccname, - const char *u2u_ccname); - - #include -@@ -65,18 +67,21 @@ static void extended_com_err_fn(const char *myprog, errcode_t code, - int - main(int argc, char *argv[]) - { -- enum { OPTION_U2U = 256 }; -- struct option lopts[] = { -- { "u2u", 1, NULL, OPTION_U2U }, -- { NULL, 0, NULL, 0 } -- }; -+ enum { OPTION_U2U = 256, OPTION_OUT_CACHE = 257 }; - const char *shopts = "uCc:e:hk:qPS:I:U:F:"; - int option; - char *etypestr = NULL, *ccachestr = NULL, *keytab_name = NULL; - char *sname = NULL, *for_user = NULL, *u2u_ccname = NULL; -- char *for_user_cert_file = NULL; -+ char *for_user_cert_file = NULL, *out_ccname = NULL; - int canon = 0, unknown = 0, proxy = 0, for_user_enterprise = 0; -- int impersonate = 0; -+ int impersonate = 0, cached_only = 0, no_store = 0; -+ struct option lopts[] = { -+ { "cached-only", 0, &cached_only, 1 }, -+ { "no-store", 0, &no_store, 1 }, -+ { "out-cache", 1, NULL, OPTION_OUT_CACHE }, -+ { "u2u", 1, NULL, OPTION_U2U }, -+ { NULL, 0, NULL, 0 } -+ }; - - setlocale(LC_ALL, ""); - set_com_err_hook(extended_com_err_fn); -@@ -139,6 +144,12 @@ main(int argc, char *argv[]) - case OPTION_U2U: - u2u_ccname = optarg; - break; -+ case OPTION_OUT_CACHE: -+ out_ccname = optarg; -+ break; -+ case 0: -+ /* If this option set a flag, do nothing else now. */ -+ break; - default: - xusage(); - break; -@@ -163,8 +174,9 @@ main(int argc, char *argv[]) - xusage(); - - do_v5_kvno(argc - optind, argv + optind, ccachestr, etypestr, keytab_name, -- sname, canon, unknown, for_user, for_user_enterprise, -- for_user_cert_file, proxy, u2u_ccname); -+ sname, cached_only, canon, no_store, unknown, for_user, -+ for_user_enterprise, for_user_cert_file, proxy, out_ccname, -+ u2u_ccname); - return 0; - } - -@@ -278,14 +290,16 @@ static krb5_error_code - kvno(const char *name, krb5_ccache ccache, krb5_principal me, - krb5_enctype etype, krb5_keytab keytab, const char *sname, - krb5_flags options, int unknown, krb5_principal for_user_princ, -- krb5_data *for_user_cert, int proxy, krb5_data *u2u_ticket) -+ krb5_data *for_user_cert, int proxy, krb5_data *u2u_ticket, -+ krb5_creds **creds_out) - { - krb5_error_code ret; - krb5_principal server = NULL; - krb5_ticket *ticket = NULL; -- krb5_creds in_creds, *out_creds = NULL; -+ krb5_creds in_creds, *creds = NULL; - char *princ = NULL; - -+ *creds_out = NULL; - memset(&in_creds, 0, sizeof(in_creds)); - - if (sname != NULL) { -@@ -325,13 +339,12 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, - in_creds.client = for_user_princ; - in_creds.server = me; - ret = krb5_get_credentials_for_user(context, options, ccache, -- &in_creds, for_user_cert, -- &out_creds); -+ &in_creds, for_user_cert, &creds); - } else { - in_creds.client = me; - in_creds.server = server; - ret = krb5_get_credentials(context, options, ccache, &in_creds, -- &out_creds); -+ &creds); - } - - if (ret) { -@@ -340,7 +353,7 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, - } - - /* We need a native ticket. */ -- ret = krb5_decode_ticket(&out_creds->ticket, &ticket); -+ ret = krb5_decode_ticket(&creds->ticket, &ticket); - if (ret) { - com_err(prog, ret, _("while decoding ticket for %s"), princ); - goto cleanup; -@@ -366,15 +379,15 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, - } - - if (proxy) { -- in_creds.client = out_creds->client; -- out_creds->client = NULL; -- krb5_free_creds(context, out_creds); -- out_creds = NULL; -+ in_creds.client = creds->client; -+ creds->client = NULL; -+ krb5_free_creds(context, creds); -+ creds = NULL; - in_creds.server = server; - - ret = krb5_get_credentials_for_proxy(context, KRB5_GC_CANONICALIZE, - ccache, &in_creds, ticket, -- &out_creds); -+ &creds); - krb5_free_principal(context, in_creds.client); - if (ret) { - com_err(prog, ret, _("%s: constrained delegation failed"), -@@ -383,10 +396,13 @@ kvno(const char *name, krb5_ccache ccache, krb5_principal me, - } - } - -+ *creds_out = creds; -+ creds = NULL; -+ - cleanup: - krb5_free_principal(context, server); - krb5_free_ticket(context, ticket); -- krb5_free_creds(context, out_creds); -+ krb5_free_creds(context, creds); - krb5_free_unparsed_name(context, princ); - return ret; - } -@@ -432,19 +448,28 @@ cleanup: - - static void - do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, -- char *keytab_name, char *sname, int canon, int unknown, -- char *for_user, int for_user_enterprise, -- char *for_user_cert_file, int proxy, const char *u2u_ccname) -+ char *keytab_name, char *sname, int cached_only, int canon, -+ int no_store, int unknown, char *for_user, int for_user_enterprise, -+ char *for_user_cert_file, int proxy, const char *out_ccname, -+ const char *u2u_ccname) - { - krb5_error_code ret; -- int i, errors, flags; -+ int i, errors, flags, initialized = 0; - krb5_enctype etype; -- krb5_ccache ccache; -+ krb5_ccache ccache, out_ccache = NULL; - krb5_principal me; - krb5_keytab keytab = NULL; - krb5_principal for_user_princ = NULL; -- krb5_flags options = canon ? KRB5_GC_CANONICALIZE : 0; -+ krb5_flags options = 0; - krb5_data cert_data = empty_data(), *user_cert = NULL, *u2u_ticket = NULL; -+ krb5_creds *creds; -+ -+ if (canon) -+ options |= KRB5_GC_CANONICALIZE; -+ if (cached_only) -+ options |= KRB5_GC_CACHED; -+ if (no_store || out_ccname != NULL) -+ options |= KRB5_GC_NO_STORE; - - ret = krb5_init_context(&context); - if (ret) { -@@ -471,6 +496,14 @@ do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, - exit(1); - } - -+ if (out_ccname != NULL) { -+ ret = krb5_cc_resolve(context, out_ccname, &out_ccache); -+ if (ret) { -+ com_err(prog, ret, _("while resolving output ccache")); -+ exit(1); -+ } -+ } -+ - if (keytab_name != NULL) { - ret = krb5_kt_resolve(context, keytab_name, &keytab); - if (ret) { -@@ -517,8 +550,25 @@ do_v5_kvno(int count, char *names[], char * ccachestr, char *etypestr, - errors = 0; - for (i = 0; i < count; i++) { - if (kvno(names[i], ccache, me, etype, keytab, sname, options, unknown, -- for_user_princ, user_cert, proxy, u2u_ticket) != 0) -+ for_user_princ, user_cert, proxy, u2u_ticket, &creds) != 0) { - errors++; -+ } else if (out_ccache != NULL) { -+ if (!initialized) { -+ ret = krb5_cc_initialize(context, out_ccache, creds->client); -+ if (ret) { -+ com_err(prog, ret, _("while initializing output ccache")); -+ exit(1); -+ } -+ initialized = 1; -+ } -+ ret = krb5_cc_store_cred(context, out_ccache, creds); -+ if (ret) { -+ com_err(prog, ret, _("while storing creds in output ccache")); -+ exit(1); -+ } -+ } -+ -+ krb5_free_creds(context, creds); - } - - if (keytab != NULL) -diff --git a/src/clients/kvno/t_kvno.py b/src/clients/kvno/t_kvno.py -new file mode 100644 -index 000000000..e98b90e8a ---- /dev/null -+++ b/src/clients/kvno/t_kvno.py -@@ -0,0 +1,75 @@ -+from k5test import * -+ -+realm = K5Realm() -+ -+def check_cache(ccache, expected_services): -+ # Fetch the klist output and skip past the header. -+ lines = realm.run([klist, '-c', ccache]).splitlines() -+ lines = lines[4:] -+ -+ # For each line not beginning with an indent, match against the -+ # expected service principals. -+ svcs = {x: True for x in expected_services} -+ for l in lines: -+ if not l.startswith('\t'): -+ svcprinc = l.split()[4] -+ if svcprinc in svcs: -+ del svcs[svcprinc] -+ else: -+ fail('unexpected service princ ' + svcprinc) -+ -+ if svcs: -+ fail('services not found in klist output: ' + ' '.join(svcs.keys())) -+ -+ -+mark('no options') -+realm.run([kvno, realm.user_princ], expected_msg='user@KRBTEST.COM: kvno = 1') -+check_cache(realm.ccache, [realm.krbtgt_princ, realm.user_princ]) -+ -+mark('-e') -+msgs = ('etypes requested in TGS request: camellia128-cts', -+ '/KDC has no support for encryption type') -+realm.run([kvno, '-e', 'camellia128-cts', realm.host_princ], -+ expected_code=1, expected_trace=msgs) -+ -+mark('--cached-only') -+realm.run([kvno, '--cached-only', realm.user_princ], expected_msg='kvno = 1') -+realm.run([kvno, '--cached-only', realm.host_princ], -+ expected_code=1, expected_msg='Matching credential not found') -+check_cache(realm.ccache, [realm.krbtgt_princ, realm.user_princ]) -+ -+mark('--no-store') -+realm.run([kvno, '--no-store', realm.host_princ], expected_msg='kvno = 1') -+check_cache(realm.ccache, [realm.krbtgt_princ, realm.user_princ]) -+ -+mark('--out-cache') # and multiple services -+out_ccache = os.path.join(realm.testdir, 'ccache.out') -+realm.run([kvno, '--out-cache', out_ccache, -+ realm.host_princ, realm.admin_princ]) -+check_cache(realm.ccache, [realm.krbtgt_princ, realm.user_princ]) -+check_cache(out_ccache, [realm.host_princ, realm.admin_princ]) -+ -+mark('--out-cache --cached-only') # tests out-cache overwriting, and -q -+realm.run([kvno, '--out-cache', out_ccache, '--cached-only', realm.host_princ], -+ expected_code=1, expected_msg='Matching credential not found') -+out = realm.run([kvno, '-q', '--out-cache', out_ccache, '--cached-only', -+ realm.user_princ]) -+if out: -+ fail('unexpected kvno output with -q') -+check_cache(out_ccache, [realm.user_princ]) -+ -+mark('-U') # and -c -+svc_ccache = os.path.join(realm.testdir, 'ccache.svc') -+realm.run([kinit, '-k', '-c', svc_ccache, realm.host_princ]) -+realm.run([kvno, '-c', svc_ccache, '-U', 'user', realm.host_princ]) -+realm.run([klist, '-c', svc_ccache], expected_msg='for client user@') -+realm.run([kvno, '-c', svc_ccache, '-U', 'user', '--out-cache', out_ccache, -+ realm.host_princ]) -+out = realm.run([klist, '-c', out_ccache]) -+if ('Default principal: user@KRBTEST.COM' not in out): -+ fail('wrong default principal in klist output') -+ -+# More S4U options are tested in tests/gssapi/t_s4u.py. -+# --u2u is tested in tests/t_u2u.py. -+ -+success('kvno tests') -diff --git a/src/man/kvno.man b/src/man/kvno.man -index 9eb9e1852..7c9565bdb 100644 ---- a/src/man/kvno.man -+++ b/src/man/kvno.man -@@ -96,6 +96,19 @@ Specifies that protocol transition is to be used, identifying the - client principal with the X.509 certificate in \fIcert_file\fP\&. The - certificate file must be in PEM format. - .TP -+\fB\-\-cached\-only\fP -+Only retrieve credentials already present in the cache, not from -+the KDC. -+.TP -+\fB\-\-no\-store\fP -+Do not store retrieved credentials in the cache. If -+\fB\-\-out\-cache\fP is also specified, credentials will still be -+stored into the output credential cache. -+.TP -+\fB\-\-out\-cache\fP \fIccache\fP -+Initialize \fIccache\fP and store all retrieved credentials into it. -+Do not store acquired credentials in the input cache. -+.TP - \fB\-\-u2u\fP \fIccache\fP - Requests a user\-to\-user ticket. \fIccache\fP must contain a local - krbtgt ticket for the server principal. The reported version diff --git a/Adjust-KDC-alias-helper-function-contract.patch b/Adjust-KDC-alias-helper-function-contract.patch deleted file mode 100644 index b7ce64e..0000000 --- a/Adjust-KDC-alias-helper-function-contract.patch +++ /dev/null @@ -1,80 +0,0 @@ -From d27cef7eb6f099fb1ec4e2d49625aee0d8dc1007 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Tue, 22 Sep 2020 01:11:39 +0300 -Subject: [PATCH] Adjust KDC alias helper function contract - -Change the name of is_client_alias() to is_client_db_alias(), and -change the contract so that the already-canonical principal name comes -from a DB entry (which is less flexible, but clearer since DB entries -always contain canonical principal names). Make the function -available outside of kdc_util.c. - -[ghudson@mit.edu: clarified commit message] - -(cherry picked from commit 9fb5f572dd6ce808b234cb60a573eac48136d7ca) ---- - src/kdc/kdc_util.c | 14 +++++++------- - src/kdc/kdc_util.h | 4 ++++ - 2 files changed, 11 insertions(+), 7 deletions(-) - -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index dcb2df8dc..6330387d0 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -1463,10 +1463,10 @@ cleanup: - return code; - } - --/* Return true if princ canonicalizes to the same principal as canon. */ --static krb5_boolean --is_client_alias(krb5_context context, krb5_const_principal canon, -- krb5_const_principal princ) -+/* Return true if princ canonicalizes to the same principal as entry's. */ -+krb5_boolean -+is_client_db_alias(krb5_context context, const krb5_db_entry *entry, -+ krb5_const_principal princ) - { - krb5_error_code ret; - krb5_db_entry *self; -@@ -1475,7 +1475,7 @@ is_client_alias(krb5_context context, krb5_const_principal canon, - ret = krb5_db_get_principal(context, princ, - KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY, &self); - if (!ret) { -- is_self = krb5_principal_compare(context, canon, self->princ); -+ is_self = krb5_principal_compare(context, entry->princ, self->princ); - krb5_db_free_principal(context, self); - } - -@@ -1535,7 +1535,7 @@ kdc_process_s4u2self_req(kdc_realm_t *kdc_active_realm, - - /* If the server is local, check that the request is for self. */ - if (!isflagset(c_flags, KRB5_KDB_FLAG_ISSUING_REFERRAL) && -- !is_client_alias(kdc_context, server->princ, client_princ)) { -+ !is_client_db_alias(kdc_context, server, client_princ)) { - *status = "INVALID_S4U2SELF_REQUEST_SERVER_MISMATCH"; - return KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN; /* match Windows error */ - } -@@ -1728,7 +1728,7 @@ kdc_process_s4u2proxy_req(kdc_realm_t *kdc_active_realm, unsigned int flags, - } - - client_princ = *stkt_authdata_client; -- } else if (!is_client_alias(kdc_context, server->princ, server_princ)) { -+ } else if (!is_client_db_alias(kdc_context, server, server_princ)) { - *status = "EVIDENCE_TICKET_MISMATCH"; - return KRB5KDC_ERR_SERVER_NOMATCH; - } -diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index 384b21ad2..2c9d8cf69 100644 ---- a/src/kdc/kdc_util.h -+++ b/src/kdc/kdc_util.h -@@ -344,6 +344,10 @@ log_tgs_badtrans(krb5_context ctx, krb5_principal cprinc, - void - log_tgs_alt_tgt(krb5_context context, krb5_principal p); - -+krb5_boolean -+is_client_db_alias(krb5_context context, const krb5_db_entry *entry, -+ krb5_const_principal princ); -+ - /* FAST*/ - enum krb5_fast_kdc_flags { - KRB5_FAST_REPLY_KEY_USED = 0x1, diff --git a/Allow-aliases-when-matching-U2U-second-ticket.patch b/Allow-aliases-when-matching-U2U-second-ticket.patch deleted file mode 100644 index 38ed3cc..0000000 --- a/Allow-aliases-when-matching-U2U-second-ticket.patch +++ /dev/null @@ -1,65 +0,0 @@ -From 69e45f51b466219bde15b11c8539ea3841281f2b Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Tue, 22 Sep 2020 01:17:11 +0300 -Subject: [PATCH] Allow aliases when matching U2U second ticket - -In process_tgs_req() when verifying the user-to-user second ticket, -compare the canonical names of the request server and the second -ticket client. - -[ghudson@mit.edu: expanded commit message; trimmed tests] - -ticket: 8951 (new) -(cherry picked from commit afc494ef9418e6be7fbb887364efa6606b10034a) ---- - src/kdc/do_tgs_req.c | 2 +- - src/tests/t_u2u.py | 25 +++++++++++++++++++++++++ - 2 files changed, 26 insertions(+), 1 deletion(-) - -diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c -index 463a9c0dd..74cd19e96 100644 ---- a/src/kdc/do_tgs_req.c -+++ b/src/kdc/do_tgs_req.c -@@ -666,7 +666,7 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, - */ - krb5_enc_tkt_part *t2enc = request->second_ticket[st_idx]->enc_part2; - krb5_principal client2 = t2enc->client; -- if (!krb5_principal_compare(kdc_context, request->server, client2)) { -+ if (!is_client_db_alias(kdc_context, server, client2)) { - altcprinc = client2; - errcode = KRB5KDC_ERR_SERVER_NOMATCH; - status = "2ND_TKT_MISMATCH"; -diff --git a/src/tests/t_u2u.py b/src/tests/t_u2u.py -index 1ca6ac87e..4b8a82a2f 100644 ---- a/src/tests/t_u2u.py -+++ b/src/tests/t_u2u.py -@@ -32,4 +32,29 @@ realm.run([kvno, '--u2u', realm.ccache, realm.user_princ]) - - realm.run([klist]) - -+realm.stop() -+ -+# Load the test KDB module to test aliases -+testprincs = {'krbtgt/KRBTEST.COM': {'keys': 'aes128-cts'}, -+ 'user': {'keys': 'aes128-cts', 'flags': '+preauth'}, -+ 'WIN10': {'keys': 'aes128-cts'}} -+kdcconf = {'realms': {'$realm': {'database_module': 'test'}}, -+ 'dbmodules': {'test': {'db_library': 'test', -+ 'princs': testprincs, -+ 'alias': {'HOST/win10': 'WIN10'}}}} -+ -+realm = K5Realm(kdc_conf=kdcconf, create_kdb=False) -+realm.start_kdc() -+ -+# Create a second user principal and get tickets for it. -+u2u_ccache = 'FILE:' + os.path.join(realm.testdir, 'ccu2u') -+realm.extract_keytab('WIN10', realm.keytab) -+realm.kinit('WIN10', None, ['-k', '-c', u2u_ccache]) -+ -+realm.extract_keytab(realm.user_princ, realm.keytab) -+realm.kinit(realm.user_princ, None, ['-k']) -+ -+realm.run([kvno, '--u2u', u2u_ccache, 'HOST/win10'], expected_msg='kvno = 0') -+realm.run([kvno, '--u2u', u2u_ccache, 'WIN10'], expected_msg='kvno = 0') -+ - success('user-to-user tests') diff --git a/Allow-certauth-modules-to-set-hw-authent-flag.patch b/Allow-certauth-modules-to-set-hw-authent-flag.patch deleted file mode 100644 index 3be71e7..0000000 --- a/Allow-certauth-modules-to-set-hw-authent-flag.patch +++ /dev/null @@ -1,241 +0,0 @@ -From b581e106c65957f48ee088d9243b985d3e9a0be8 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 24 Feb 2020 15:58:59 -0500 -Subject: [PATCH] Allow certauth modules to set hw-authent flag - -In PKINIT, if a certauth module returns KRB5_CERTAUTH_HWAUTH from its -authorize method, set the hw-authent flag in the ticket. - -ticket: 8879 (new) -(cherry picked from commit 50fb43b4a2d97ce2cd53e1ced30e8e8224fede70) ---- - doc/plugindev/certauth.rst | 7 +++++-- - src/include/krb5/certauth_plugin.h | 9 ++++++--- - src/lib/krb5/error_tables/k5e1_err.et | 1 + - src/plugins/certauth/test/Makefile.in | 4 ++-- - src/plugins/certauth/test/main.c | 11 +++++++++-- - src/plugins/preauth/pkinit/pkinit_srv.c | 24 ++++++++++++++++-------- - src/tests/t_certauth.py | 13 +++++++++++++ - 7 files changed, 52 insertions(+), 17 deletions(-) - -diff --git a/doc/plugindev/certauth.rst b/doc/plugindev/certauth.rst -index 8a7f7c5eb..3b715f738 100644 ---- a/doc/plugindev/certauth.rst -+++ b/doc/plugindev/certauth.rst -@@ -15,8 +15,11 @@ principal. **authorize** receives the DER-encoded certificate, the - requested client principal, and a pointer to the client's - krb5_db_entry (for modules that link against libkdb5). It returns the - authorization status and optionally outputs a list of authentication --indicator strings to be added to the ticket. A module must use its --own internal or library-provided ASN.1 certificate decoder. -+indicator strings to be added to the ticket. Beginning in release -+1.19, the authorize method can request that the hardware -+authentication bit be set in the ticket by returning -+**KRB5_CERTAUTH_HWAUTH**. A module must use its own internal or -+library-provided ASN.1 certificate decoder. - - A module can optionally create and destroy module data with the - **init** and **fini** methods. Module data objects last for the -diff --git a/src/include/krb5/certauth_plugin.h b/src/include/krb5/certauth_plugin.h -index 3074790f8..3466cf345 100644 ---- a/src/include/krb5/certauth_plugin.h -+++ b/src/include/krb5/certauth_plugin.h -@@ -85,14 +85,17 @@ typedef void - (*krb5_certauth_fini_fn)(krb5_context context, krb5_certauth_moddata moddata); - - /* -- * Mandatory: -- * Return 0 if the DER-encoded cert is authorized for PKINIT authentication by -- * princ; otherwise return one of the following error codes: -+ * Mandatory: return 0 or KRB5_CERTAUTH_HWAUTH if the DER-encoded cert is -+ * authorized for PKINIT authentication by princ; otherwise return one of the -+ * following error codes: - * - KRB5KDC_ERR_CLIENT_NAME_MISMATCH - incorrect SAN value - * - KRB5KDC_ERR_INCONSISTENT_KEY_PURPOSE - incorrect EKU - * - KRB5KDC_ERR_CERTIFICATE_MISMATCH - other extension error - * - KRB5_PLUGIN_NO_HANDLE - the module has no opinion about cert - * -+ * Returning KRB5_CERTAUTH_HWAUTH will cause the hw-authent flag to be set in -+ * the issued ticket (new in release 1.19). -+ * - * - opts is used by built-in modules to receive internal data, and must be - * ignored by other modules. - * - db_entry receives the client principal database entry, and can be ignored -diff --git a/src/lib/krb5/error_tables/k5e1_err.et b/src/lib/krb5/error_tables/k5e1_err.et -index ade5caecf..abd9f3bfe 100644 ---- a/src/lib/krb5/error_tables/k5e1_err.et -+++ b/src/lib/krb5/error_tables/k5e1_err.et -@@ -42,4 +42,5 @@ error_code KRB5_KCM_MALFORMED_REPLY, "Malformed reply from KCM daemon" - error_code KRB5_KCM_RPC_ERROR, "Mach RPC error communicating with KCM daemon" - error_code KRB5_KCM_REPLY_TOO_BIG, "KCM daemon reply too big" - error_code KRB5_KCM_NO_SERVER, "No KCM server found" -+error_code KRB5_CERTAUTH_HWAUTH, "Authorize and set hw-authent ticket flag" - end -diff --git a/src/plugins/certauth/test/Makefile.in b/src/plugins/certauth/test/Makefile.in -index d3524084c..e94c13845 100644 ---- a/src/plugins/certauth/test/Makefile.in -+++ b/src/plugins/certauth/test/Makefile.in -@@ -5,8 +5,8 @@ LIBBASE=certauth_test - LIBMAJOR=0 - LIBMINOR=0 - RELDIR=../plugins/certauth/test --SHLIB_EXPDEPS=$(KRB5_BASE_DEPLIBS) --SHLIB_EXPLIBS=$(KRB5_BASE_LIBS) -+SHLIB_EXPDEPS=$(KDB5_DEPLIBS) $(KRB5_BASE_DEPLIBS) -+SHLIB_EXPLIBS=$(KDB5_LIBS) $(KRB5_BASE_LIBS) - - STLIBOBJS=main.o - -diff --git a/src/plugins/certauth/test/main.c b/src/plugins/certauth/test/main.c -index 77641230c..d4633b8cd 100644 ---- a/src/plugins/certauth/test/main.c -+++ b/src/plugins/certauth/test/main.c -@@ -31,6 +31,7 @@ - */ - - #include -+#include - #include "krb5/certauth_plugin.h" - - struct krb5_certauth_moddata_st { -@@ -131,7 +132,8 @@ has_cn(krb5_context context, const uint8_t *cert, size_t cert_len, - - /* - * Test module 2 returns OK if princ matches the CN part of the subject name, -- * and returns indicators of the module name and princ. -+ * and returns indicators of the module name and princ. If the "hwauth" string -+ * attribute is set on db_entry, it returns KRB5_CERTAUTH_HWAUTH. - */ - static krb5_error_code - test2_authorize(krb5_context context, krb5_certauth_moddata moddata, -@@ -141,7 +143,7 @@ test2_authorize(krb5_context context, krb5_certauth_moddata moddata, - char ***authinds_out) - { - krb5_error_code ret; -- char *name = NULL, **ais = NULL; -+ char *name = NULL, *strval = NULL, **ais = NULL; - - *authinds_out = NULL; - -@@ -167,6 +169,11 @@ test2_authorize(krb5_context context, krb5_certauth_moddata moddata, - - ais = NULL; - -+ ret = krb5_dbe_get_string(context, (krb5_db_entry *)db_entry, "hwauth", -+ &strval); -+ ret = (strval != NULL) ? KRB5_CERTAUTH_HWAUTH : 0; -+ krb5_dbe_free_string(context, strval); -+ - cleanup: - krb5_free_unparsed_name(context, name); - return ret; -diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c -index feca11806..3ae56c064 100644 ---- a/src/plugins/preauth/pkinit/pkinit_srv.c -+++ b/src/plugins/preauth/pkinit/pkinit_srv.c -@@ -320,12 +320,12 @@ static krb5_error_code - authorize_cert(krb5_context context, certauth_handle *certauth_modules, - pkinit_kdc_context plgctx, pkinit_kdc_req_context reqctx, - krb5_kdcpreauth_callbacks cb, krb5_kdcpreauth_rock rock, -- krb5_principal client) -+ krb5_principal client, krb5_boolean *hwauth_out) - { - krb5_error_code ret; - certauth_handle h; - struct certauth_req_opts opts; -- krb5_boolean accepted = FALSE; -+ krb5_boolean accepted = FALSE, hwauth = FALSE; - uint8_t *cert; - size_t i, cert_len; - void *db_ent = NULL; -@@ -347,9 +347,10 @@ authorize_cert(krb5_context context, certauth_handle *certauth_modules, - - /* - * Check the certificate against each certauth module. For the certificate -- * to be authorized at least one module must return 0, and no module can an -- * error code other than KRB5_PLUGIN_NO_HANDLE (pass). Add indicators from -- * modules that return 0 or pass. -+ * to be authorized at least one module must return 0 or -+ * KRB5_CERTAUTH_HWAUTH, and no module can return an error code other than -+ * KRB5_PLUGIN_NO_HANDLE (pass). Add indicators from modules that return 0 -+ * or pass. - */ - ret = KRB5_PLUGIN_NO_HANDLE; - for (i = 0; certauth_modules != NULL && certauth_modules[i] != NULL; i++) { -@@ -359,6 +360,8 @@ authorize_cert(krb5_context context, certauth_handle *certauth_modules, - &opts, db_ent, &ais); - if (ret == 0) - accepted = TRUE; -+ else if (ret == KRB5_CERTAUTH_HWAUTH) -+ accepted = hwauth = TRUE; - else if (ret != KRB5_PLUGIN_NO_HANDLE) - goto cleanup; - -@@ -374,6 +377,7 @@ authorize_cert(krb5_context context, certauth_handle *certauth_modules, - } - } - -+ *hwauth_out = hwauth; - ret = accepted ? 0 : KRB5KDC_ERR_CLIENT_NAME_MISMATCH; - - cleanup: -@@ -430,7 +434,7 @@ pkinit_server_verify_padata(krb5_context context, - int is_signed = 1; - krb5_pa_data **e_data = NULL; - krb5_kdcpreauth_modreq modreq = NULL; -- krb5_boolean valid_freshness_token = FALSE; -+ krb5_boolean valid_freshness_token = FALSE, hwauth = FALSE; - char **sp; - - pkiDebug("pkinit_verify_padata: entered!\n"); -@@ -494,7 +498,7 @@ pkinit_server_verify_padata(krb5_context context, - } - if (is_signed) { - retval = authorize_cert(context, moddata->certauth_modules, plgctx, -- reqctx, cb, rock, request->client); -+ reqctx, cb, rock, request->client, &hwauth); - if (retval) - goto cleanup; - -@@ -613,6 +617,8 @@ pkinit_server_verify_padata(krb5_context context, - - /* remember to set the PREAUTH flag in the reply */ - enc_tkt_reply->flags |= TKT_FLG_PRE_AUTH; -+ if (hwauth) -+ enc_tkt_reply->flags |= TKT_FLG_HW_AUTH; - modreq = (krb5_kdcpreauth_modreq)reqctx; - reqctx = NULL; - -@@ -1044,7 +1050,9 @@ pkinit_server_get_flags(krb5_context kcontext, krb5_preauthtype patype) - { - if (patype == KRB5_PADATA_PKINIT_KX) - return PA_INFO; -- return PA_SUFFICIENT | PA_REPLACES_KEY | PA_TYPED_E_DATA; -+ /* PKINIT does not normally set the hw-authent ticket flag, but a -+ * certauth module can cause it to do so. */ -+ return PA_SUFFICIENT | PA_REPLACES_KEY | PA_TYPED_E_DATA | PA_HARDWARE; - } - - static krb5_preauthtype supported_server_pa_types[] = { -diff --git a/src/tests/t_certauth.py b/src/tests/t_certauth.py -index 9c7094525..0fe0fdb4a 100644 ---- a/src/tests/t_certauth.py -+++ b/src/tests/t_certauth.py -@@ -43,4 +43,17 @@ out = realm.kinit("user2@KRBTEST.COM", - expected_code=1, - expected_msg='kinit: Certificate mismatch') - -+# Test the KRB5_CERTAUTH_HWAUTH return code. -+mark('hw-authent flag tests') -+# First test +requires_hwauth without causing the hw-authent ticket -+# flag to be set. This currently results in a preauth loop. -+realm.run([kadminl, 'modprinc', '+requires_hwauth', realm.user_princ]) -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % file_identity], -+ expected_code=1, expected_msg='Looping detected') -+# Cause the test2 module to return KRB5_CERTAUTH_HWAUTH and try again. -+realm.run([kadminl, 'setstr', realm.user_princ, 'hwauth', 'x']) -+realm.kinit(realm.user_princ, -+ flags=['-X', 'X509_user_identity=%s' % file_identity]) -+ - success("certauth tests") diff --git a/Avoid-passing-DB-entry-structures-in-KDC.patch b/Avoid-passing-DB-entry-structures-in-KDC.patch deleted file mode 100644 index 0d6a8be..0000000 --- a/Avoid-passing-DB-entry-structures-in-KDC.patch +++ /dev/null @@ -1,298 +0,0 @@ -From aad7ffc2cdc5b1c55a5967612730daa2f493fa6e Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 30 Sep 2020 02:12:00 -0400 -Subject: [PATCH] Avoid passing DB entry structures in KDC - -When validating AS or TGS requests, pass pointers to DB entry -structures, not the structures themselves. - -(cherry picked from commit 7ccc08a889b40693b2ce7f108f2cdda51bc04bff) ---- - src/kdc/do_as_req.c | 4 ++-- - src/kdc/do_tgs_req.c | 2 +- - src/kdc/kdc_util.c | 34 +++++++++++++++++----------------- - src/kdc/kdc_util.h | 6 +++--- - src/kdc/tgs_policy.c | 35 ++++++++++++++++++----------------- - 5 files changed, 41 insertions(+), 40 deletions(-) - -diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c -index 9ae7b0a5e..c2dfea9b8 100644 ---- a/src/kdc/do_as_req.c -+++ b/src/kdc/do_as_req.c -@@ -663,8 +663,8 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, - au_state->stage = VALIDATE_POL; - - if ((errcode = validate_as_request(kdc_active_realm, -- state->request, *state->client, -- *state->server, state->kdc_time, -+ state->request, state->client, -+ state->server, state->kdc_time, - &state->status, &state->e_data))) { - errcode += ERROR_TABLE_BASE_krb5; - goto errout; -diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c -index 74cd19e96..d345797c4 100644 ---- a/src/kdc/do_tgs_req.c -+++ b/src/kdc/do_tgs_req.c -@@ -260,7 +260,7 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, - goto cleanup; - - if ((retval = validate_tgs_request(kdc_active_realm, -- request, *server, header_ticket, -+ request, server, header_ticket, - kdc_time, &status, &e_data))) { - if (retval == KDC_ERR_POLICY || retval == KDC_ERR_BADOPTION) - au_state->violation = PROT_CONSTRAINT; -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index a4a05b9fa..b2042862a 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -612,8 +612,8 @@ check_anon(kdc_realm_t *kdc_active_realm, - KDC_OPT_ENC_TKT_IN_SKEY | KDC_OPT_CNAME_IN_ADDL_TKT) - int - validate_as_request(kdc_realm_t *kdc_active_realm, -- krb5_kdc_req *request, krb5_db_entry client, -- krb5_db_entry server, krb5_timestamp kdc_time, -+ krb5_kdc_req *request, krb5_db_entry *client, -+ krb5_db_entry *server, krb5_timestamp kdc_time, - const char **status, krb5_pa_data ***e_data) - { - krb5_error_code ret; -@@ -627,7 +627,7 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - } - - /* The client must not be expired */ -- if (client.expiration && ts_after(kdc_time, client.expiration)) { -+ if (client->expiration && ts_after(kdc_time, client->expiration)) { - *status = "CLIENT EXPIRED"; - if (vague_errors) - return(KRB_ERR_GENERIC); -@@ -637,8 +637,8 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - - /* The client's password must not be expired, unless the server is - a KRB5_KDC_PWCHANGE_SERVICE. */ -- if (client.pw_expiration && ts_after(kdc_time, client.pw_expiration) && -- !isflagset(server.attributes, KRB5_KDB_PWCHANGE_SERVICE)) { -+ if (client->pw_expiration && ts_after(kdc_time, client->pw_expiration) && -+ !isflagset(server->attributes, KRB5_KDB_PWCHANGE_SERVICE)) { - *status = "CLIENT KEY EXPIRED"; - if (vague_errors) - return(KRB_ERR_GENERIC); -@@ -647,7 +647,7 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - } - - /* The server must not be expired */ -- if (server.expiration && ts_after(kdc_time, server.expiration)) { -+ if (server->expiration && ts_after(kdc_time, server->expiration)) { - *status = "SERVICE EXPIRED"; - return(KDC_ERR_SERVICE_EXP); - } -@@ -656,8 +656,8 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - * If the client requires password changing, then only allow the - * pwchange service. - */ -- if (isflagset(client.attributes, KRB5_KDB_REQUIRES_PWCHANGE) && -- !isflagset(server.attributes, KRB5_KDB_PWCHANGE_SERVICE)) { -+ if (isflagset(client->attributes, KRB5_KDB_REQUIRES_PWCHANGE) && -+ !isflagset(server->attributes, KRB5_KDB_PWCHANGE_SERVICE)) { - *status = "REQUIRED PWCHANGE"; - return(KDC_ERR_KEY_EXP); - } -@@ -665,37 +665,37 @@ validate_as_request(kdc_realm_t *kdc_active_realm, - /* Client and server must allow postdating tickets */ - if ((isflagset(request->kdc_options, KDC_OPT_ALLOW_POSTDATE) || - isflagset(request->kdc_options, KDC_OPT_POSTDATED)) && -- (isflagset(client.attributes, KRB5_KDB_DISALLOW_POSTDATED) || -- isflagset(server.attributes, KRB5_KDB_DISALLOW_POSTDATED))) { -+ (isflagset(client->attributes, KRB5_KDB_DISALLOW_POSTDATED) || -+ isflagset(server->attributes, KRB5_KDB_DISALLOW_POSTDATED))) { - *status = "POSTDATE NOT ALLOWED"; - return(KDC_ERR_CANNOT_POSTDATE); - } - - /* Check to see if client is locked out */ -- if (isflagset(client.attributes, KRB5_KDB_DISALLOW_ALL_TIX)) { -+ if (isflagset(client->attributes, KRB5_KDB_DISALLOW_ALL_TIX)) { - *status = "CLIENT LOCKED OUT"; - return(KDC_ERR_CLIENT_REVOKED); - } - - /* Check to see if server is locked out */ -- if (isflagset(server.attributes, KRB5_KDB_DISALLOW_ALL_TIX)) { -+ if (isflagset(server->attributes, KRB5_KDB_DISALLOW_ALL_TIX)) { - *status = "SERVICE LOCKED OUT"; - return(KDC_ERR_S_PRINCIPAL_UNKNOWN); - } - - /* Check to see if server is allowed to be a service */ -- if (isflagset(server.attributes, KRB5_KDB_DISALLOW_SVR)) { -+ if (isflagset(server->attributes, KRB5_KDB_DISALLOW_SVR)) { - *status = "SERVICE NOT ALLOWED"; - return(KDC_ERR_MUST_USE_USER2USER); - } - -- if (check_anon(kdc_active_realm, client.princ, request->server) != 0) { -+ if (check_anon(kdc_active_realm, client->princ, request->server) != 0) { - *status = "ANONYMOUS NOT ALLOWED"; - return(KDC_ERR_POLICY); - } - - /* Perform KDB module policy checks. */ -- ret = krb5_db_check_policy_as(kdc_context, request, &client, &server, -+ ret = krb5_db_check_policy_as(kdc_context, request, client, server, - kdc_time, status, e_data); - if (ret && ret != KRB5_PLUGIN_OP_NOTSUPP) - return errcode_to_protocol(ret); -@@ -1568,8 +1568,8 @@ kdc_process_s4u2self_req(kdc_realm_t *kdc_active_realm, - princ->pw_expiration = 0; - clear(princ->attributes, KRB5_KDB_REQUIRES_PWCHANGE); - -- code = validate_as_request(kdc_active_realm, request, *princ, -- no_server, kdc_time, status, &e_data); -+ code = validate_as_request(kdc_active_realm, request, princ, -+ &no_server, kdc_time, status, &e_data); - if (code) { - krb5_db_free_principal(kdc_context, princ); - krb5_free_pa_data(kdc_context, e_data); -diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index 42b7ee208..04007a8f5 100644 ---- a/src/kdc/kdc_util.h -+++ b/src/kdc/kdc_util.h -@@ -76,12 +76,12 @@ get_local_tgt(krb5_context context, const krb5_data *realm, - krb5_db_entry **storage_out, krb5_keyblock *kb_out); - - int --validate_as_request (kdc_realm_t *, krb5_kdc_req *, krb5_db_entry, -- krb5_db_entry, krb5_timestamp, -+validate_as_request (kdc_realm_t *, krb5_kdc_req *, krb5_db_entry *, -+ krb5_db_entry *, krb5_timestamp, - const char **, krb5_pa_data ***); - - int --validate_tgs_request (kdc_realm_t *, krb5_kdc_req *, krb5_db_entry, -+validate_tgs_request (kdc_realm_t *, krb5_kdc_req *, krb5_db_entry *, - krb5_ticket *, krb5_timestamp, - const char **, krb5_pa_data ***); - -diff --git a/src/kdc/tgs_policy.c b/src/kdc/tgs_policy.c -index 554345ba5..3f4fa8499 100644 ---- a/src/kdc/tgs_policy.c -+++ b/src/kdc/tgs_policy.c -@@ -48,7 +48,7 @@ struct tgsflagrule { - }; - - /* Service principal TGS policy checking functions */ --typedef int (check_tgs_svc_pol_fn)(krb5_kdc_req *, krb5_db_entry, -+typedef int (check_tgs_svc_pol_fn)(krb5_kdc_req *, krb5_db_entry *, - krb5_ticket *, krb5_timestamp, - const char **); - -@@ -110,7 +110,7 @@ static const struct tgsflagrule svcdenyrules[] = { - * A service principal can forbid some TGS-REQ options. - */ - static int --check_tgs_svc_deny_opts(krb5_kdc_req *req, krb5_db_entry server, -+check_tgs_svc_deny_opts(krb5_kdc_req *req, krb5_db_entry *server, - krb5_ticket *tkt, krb5_timestamp kdc_time, - const char **status) - { -@@ -122,7 +122,7 @@ check_tgs_svc_deny_opts(krb5_kdc_req *req, krb5_db_entry server, - r = &svcdenyrules[i]; - if (!(r->reqflags & req->kdc_options)) - continue; -- if (r->checkflag & server.attributes) { -+ if (r->checkflag & server->attributes) { - *status = r->status; - return r->err; - } -@@ -134,20 +134,20 @@ check_tgs_svc_deny_opts(krb5_kdc_req *req, krb5_db_entry server, - * A service principal can deny all TGS-REQs for it. - */ - static int --check_tgs_svc_deny_all(krb5_kdc_req *req, krb5_db_entry server, -+check_tgs_svc_deny_all(krb5_kdc_req *req, krb5_db_entry *server, - krb5_ticket *tkt, krb5_timestamp kdc_time, - const char **status) - { -- if (server.attributes & KRB5_KDB_DISALLOW_ALL_TIX) { -+ if (server->attributes & KRB5_KDB_DISALLOW_ALL_TIX) { - *status = "SERVER LOCKED OUT"; - return KDC_ERR_S_PRINCIPAL_UNKNOWN; - } -- if ((server.attributes & KRB5_KDB_DISALLOW_SVR) && -+ if ((server->attributes & KRB5_KDB_DISALLOW_SVR) && - !(req->kdc_options & KDC_OPT_ENC_TKT_IN_SKEY)) { - *status = "SERVER NOT ALLOWED"; - return KDC_ERR_MUST_USE_USER2USER; - } -- if (server.attributes & KRB5_KDB_DISALLOW_TGT_BASED) { -+ if (server->attributes & KRB5_KDB_DISALLOW_TGT_BASED) { - if (krb5_is_tgs_principal(tkt->server)) { - *status = "TGT BASED NOT ALLOWED"; - return KDC_ERR_POLICY; -@@ -160,17 +160,17 @@ check_tgs_svc_deny_all(krb5_kdc_req *req, krb5_db_entry server, - * A service principal can require certain TGT flags. - */ - static int --check_tgs_svc_reqd_flags(krb5_kdc_req *req, krb5_db_entry server, -+check_tgs_svc_reqd_flags(krb5_kdc_req *req, krb5_db_entry *server, - krb5_ticket *tkt, - krb5_timestamp kdc_time, const char **status) - { -- if (server.attributes & KRB5_KDB_REQUIRES_HW_AUTH) { -+ if (server->attributes & KRB5_KDB_REQUIRES_HW_AUTH) { - if (!(tkt->enc_part2->flags & TKT_FLG_HW_AUTH)) { - *status = "NO HW PREAUTH"; - return KRB_ERR_GENERIC; - } - } -- if (server.attributes & KRB5_KDB_REQUIRES_PRE_AUTH) { -+ if (server->attributes & KRB5_KDB_REQUIRES_PRE_AUTH) { - if (!(tkt->enc_part2->flags & TKT_FLG_PRE_AUTH)) { - *status = "NO PREAUTH"; - return KRB_ERR_GENERIC; -@@ -180,10 +180,10 @@ check_tgs_svc_reqd_flags(krb5_kdc_req *req, krb5_db_entry server, - } - - static int --check_tgs_svc_time(krb5_kdc_req *req, krb5_db_entry server, krb5_ticket *tkt, -+check_tgs_svc_time(krb5_kdc_req *req, krb5_db_entry *server, krb5_ticket *tkt, - krb5_timestamp kdc_time, const char **status) - { -- if (server.expiration && ts_after(kdc_time, server.expiration)) { -+ if (server->expiration && ts_after(kdc_time, server->expiration)) { - *status = "SERVICE EXPIRED"; - return KDC_ERR_SERVICE_EXP; - } -@@ -191,8 +191,9 @@ check_tgs_svc_time(krb5_kdc_req *req, krb5_db_entry server, krb5_ticket *tkt, - } - - static int --check_tgs_svc_policy(krb5_kdc_req *req, krb5_db_entry server, krb5_ticket *tkt, -- krb5_timestamp kdc_time, const char **status) -+check_tgs_svc_policy(krb5_kdc_req *req, krb5_db_entry *server, -+ krb5_ticket *tkt, krb5_timestamp kdc_time, -+ const char **status) - { - int errcode; - size_t i; -@@ -317,7 +318,7 @@ check_tgs_tgt(kdc_realm_t *kdc_active_realm, krb5_kdc_req *req, - - int - validate_tgs_request(kdc_realm_t *kdc_active_realm, -- krb5_kdc_req *request, krb5_db_entry server, -+ krb5_kdc_req *request, krb5_db_entry *server, - krb5_ticket *ticket, krb5_timestamp kdc_time, - const char **status, krb5_pa_data ***e_data) - { -@@ -367,8 +368,8 @@ validate_tgs_request(kdc_realm_t *kdc_active_realm, - } - - /* Perform KDB module policy checks. */ -- ret = krb5_db_check_policy_tgs(kdc_context, request, &server, -- ticket, status, e_data); -+ ret = krb5_db_check_policy_tgs(kdc_context, request, server, ticket, -+ status, e_data); - if (ret && ret != KRB5_PLUGIN_OP_NOTSUPP) - return errcode_to_protocol(ret); - diff --git a/Correctly-import-service-GSS-host-based-name.patch b/Correctly-import-service-GSS-host-based-name.patch deleted file mode 100644 index 0c6d0e7..0000000 --- a/Correctly-import-service-GSS-host-based-name.patch +++ /dev/null @@ -1,52 +0,0 @@ -From 5a0900dc3f0ce7569db2ed6d14da3f97b47bd120 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 30 Mar 2020 15:26:02 -0400 -Subject: [PATCH] Correctly import "service@" GSS host-based name - -The intended way to specify only a service in a GSS host-based name is -to omit the "@" separator. Some applications include the separator -but no hostname, and this happened to yield wildcard hostname behavior -prior to commit 996353767fe8afa7f67a3b5b465e4d70e18bad7c when -shortname qualification was added. To restore this behavior, check in -parse_hostbased() that at least one character is present after the "@" -separator before copying the hostname. Add a test case to t_gssapi.py. - -ticket: 8892 -tags: pullup -target_version: 1.18-next - -(cherry picked from commit a2f047af0400ba8080dc26033fae2b17534501e2) ---- - src/lib/gssapi/krb5/import_name.c | 4 ++-- - src/tests/gssapi/t_gssapi.py | 3 +++ - 2 files changed, 5 insertions(+), 2 deletions(-) - -diff --git a/src/lib/gssapi/krb5/import_name.c b/src/lib/gssapi/krb5/import_name.c -index da2ab1423..21023dd76 100644 ---- a/src/lib/gssapi/krb5/import_name.c -+++ b/src/lib/gssapi/krb5/import_name.c -@@ -102,8 +102,8 @@ parse_hostbased(const char *str, size_t len, - memcpy(service, str, servicelen); - service[servicelen] = '\0'; - -- /* If present, copy the hostname. */ -- if (at != NULL) { -+ /* Copy the hostname if present (at least one character after '@'). */ -+ if (len - servicelen > 1) { - hostlen = len - servicelen - 1; - host = malloc(hostlen + 1); - if (host == NULL) { -diff --git a/src/tests/gssapi/t_gssapi.py b/src/tests/gssapi/t_gssapi.py -index 54d5cf549..ecf982604 100755 ---- a/src/tests/gssapi/t_gssapi.py -+++ b/src/tests/gssapi/t_gssapi.py -@@ -47,6 +47,9 @@ realm.run(['./t_accname', 'p:service2/calvin', 'h:service2'], - expected_msg='service2/calvin') - realm.run(['./t_accname', 'p:service2/calvin', 'h:service1'], expected_code=1, - expected_msg=' found in keytab but does not match server principal') -+# Regression test for #8892 (trailing @ in name). -+realm.run(['./t_accname', 'p:service1/andrew', 'h:service1@'], -+ expected_msg='service1/abraham') - - # Test with acceptor name containing service and host. Use the - # client's un-canonicalized hostname as acceptor input to mirror what diff --git a/Default-dns_canonicalize_hostname-to-fallback.patch b/Default-dns_canonicalize_hostname-to-fallback.patch deleted file mode 100644 index 99b9bbb..0000000 --- a/Default-dns_canonicalize_hostname-to-fallback.patch +++ /dev/null @@ -1,371 +0,0 @@ -From bec1b3601b15397df07b3464959da92915eb45b5 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 27 May 2020 18:48:35 -0400 -Subject: [PATCH] Default dns_canonicalize_hostname to "fallback" - -This change should mitigate some of the pain caused by the rdns=true -default (generally associated with unwanted PTR records that cannot -easily be changed), with a minimum of fallout. - -Update the documentation and tests accordingly. In test environments, -disable qualify_shortname and use the uncanonicalized system hostname -(lowercased) to match the initial sn2princ result. - -ticket: 8911 (new) ---- - doc/admin/appl_servers.rst | 14 +++--- - doc/admin/conf_files/krb5_conf.rst | 9 ++-- - doc/admin/princ_dns.rst | 44 +++++++++++-------- - src/kadmin/testing/proto/krb5.conf.proto | 8 ++-- - src/kadmin/testing/scripts/env-setup.shin | 4 +- - src/kadmin/testing/scripts/init_db | 3 +- - src/kadmin/testing/scripts/start_servers | 3 +- - .../testing/scripts/start_servers_local | 2 +- - .../kadm5/unit-test/api.current/init-v2.exp | 6 +-- - src/lib/krb5/krb/init_ctx.c | 2 +- - src/tests/dejagnu/config/default.exp | 5 +-- - src/tests/t_sn2princ.py | 5 ++- - src/util/k5test.py | 25 +++-------- - 13 files changed, 58 insertions(+), 72 deletions(-) - -diff --git a/doc/admin/appl_servers.rst b/doc/admin/appl_servers.rst -index 5232db9af..afdf30297 100644 ---- a/doc/admin/appl_servers.rst -+++ b/doc/admin/appl_servers.rst -@@ -115,14 +115,12 @@ Getting DNS information correct - ------------------------------- - - Several aspects of Kerberos rely on name service. When a hostname is --used to name a service, the Kerberos library canonicalizes the --hostname using forward and reverse name resolution. (The reverse name --resolution step can be turned off using the **rdns** variable in --:ref:`libdefaults`.) The result of this canonicalization must match --the principal entry in the host's keytab, or authentication will fail. -- --Each host's canonical name must be the fully-qualified host name --(including the domain), and each host's IP address must -+used to name a service, clients may canonicalize the hostname using -+forward and possibly reverse name resolution. The result of this -+canonicalization must match the principal entry in the host's keytab, -+or authentication will fail. To work with all client canonicalization -+configurations, each host's canonical name must be the fully-qualified -+host name (including the domain), and each host's IP address must - reverse-resolve to the canonical name. - - Configuration of hostnames varies by operating system. On the -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 3a8b9cf47..38f450367 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -188,11 +188,10 @@ The libdefaults section may contain any of the following relations: - hostnames for use in service principal names. Setting this flag - to false can improve security by reducing reliance on DNS, but - means that short hostnames will not be canonicalized to -- fully-qualified hostnames. The default value is true. -- -- If this option is set to ``fallback`` (new in release 1.18), DNS -- canonicalization will only be performed the server hostname is not -- found with the original name when requesting credentials. -+ fully-qualified hostnames. If this option is set to ``fallback`` (new -+ in release 1.18), DNS canonicalization will only be performed the -+ server hostname is not found with the original name when -+ requesting credentials. The default value is ``fallback``. - - **dns_lookup_kdc** - Indicate whether DNS SRV records should be used to locate the KDCs -diff --git a/doc/admin/princ_dns.rst b/doc/admin/princ_dns.rst -index e1d823f27..32a269afc 100644 ---- a/doc/admin/princ_dns.rst -+++ b/doc/admin/princ_dns.rst -@@ -31,27 +31,35 @@ based on rotating ``CNAME`` records in DNS. - Service principal canonicalization - ---------------------------------- - --MIT Kerberos clients currently always do forward resolution (looking --up the IPv4 and possibly IPv6 addresses using ``getaddrinfo()``) of --the hostname part of a host-based service principal to canonicalize --the hostname. They obtain the "canonical" name of the host when doing --so. By default, MIT Kerberos clients will also then do reverse DNS --resolution (looking up the hostname associated with the IPv4 or IPv6 --address using ``getnameinfo()``) of the hostname. Using the --:ref:`krb5.conf(5)` setting:: -+In the MIT krb5 client library, canonicalization of host-based service -+principals is controlled by the **dns_canonicalize_hostname**, -+**rnds**, and **qualify_shortname** variables in :ref:`libdefaults`. - -- [libdefaults] -- rdns = false -+If **dns_canonicalize_hostname** is set to ``true`` (the default value -+before release 1.19), the client performs forward resolution by -+looking up the IPv4 and/or IPv6 addresses of the hostname using -+``getaddrinfo()``. This process will typically add a domain suffix to -+the hostname if needed, and follow CNAME records in the DNS. If -+**rdns** is also set to ``true`` (the default), the client will then -+perform a reverse lookup of the first returned Internet address using -+``getnameinfo()``, finding the name associated with the PTR record. - --will disable reverse DNS lookup on clients. The default setting is --"true". -+If **dns_canonicalize_hostname** is set to ``false``, the hostname is -+not canonicalized using DNS. If the hostname has only one component -+(i.e. it contains no "." characters), the host's primary DNS search -+domain will be appended, if there is one. The **qualify_shortname** -+variable can be used to override or disable this suffix. -+ -+If **dns_canonicalize_hostname** is set to ``fallback`` (the default -+value in release 1.19 and later), the hostname is initially treated -+according to the rules for ``dns_canonicalize_hostname=false``. If a -+ticket request fails because the service principal is unknown, it the -+hostname will be canonicalized according to the rules for -+``dns_canonicalize_hostname=true`` and the request will be retried. -+ -+In all cases, the hostname is converted to lowercase, and any trailing -+dot is removed. - --Operating system bugs may prevent a setting of ``rdns = false`` from --disabling reverse DNS lookup. Some versions of GNU libc have a bug in --``getaddrinfo()`` that cause them to look up ``PTR`` records even when --not required. MIT Kerberos releases krb5-1.10.2 and newer have a --workaround for this problem, as does the krb5-1.9.x series as of --release krb5-1.9.4. - - - Reverse DNS mismatches -diff --git a/src/kadmin/testing/proto/krb5.conf.proto b/src/kadmin/testing/proto/krb5.conf.proto -index e710852d4..c0af716a5 100644 ---- a/src/kadmin/testing/proto/krb5.conf.proto -+++ b/src/kadmin/testing/proto/krb5.conf.proto -@@ -2,19 +2,19 @@ - default_realm = __REALM__ - default_keytab_name = FILE:__K5ROOT__/keytab - dns_fallback = no -+ qualify_shortname = "" - plugin_base_dir = __PLUGIN_DIR__ - allow_weak_crypto = true - - [realms] - __REALM__ = { -- kdc = __KDCHOST__:1750 -- admin_server = __KDCHOST__:1751 -+ kdc = __HOSTNAME__:1750 -+ admin_server = __HOSTNAME__:1751 - database_module = foobar_db2_module_blah - } - - [domain_realm] -- __LOCALHOST__ = __REALM__ -- __KDCHOST__ = __REALM__ -+ __HOSTNAME__ = __REALM__ - - [logging] - admin_server = FILE:__K5ROOT__/syslog -diff --git a/src/kadmin/testing/scripts/env-setup.shin b/src/kadmin/testing/scripts/env-setup.shin -index 969c5340c..88f8ad1aa 100755 ---- a/src/kadmin/testing/scripts/env-setup.shin -+++ b/src/kadmin/testing/scripts/env-setup.shin -@@ -71,8 +71,8 @@ BSDDB_DUMP=$TESTDIR/util/bsddb_dump; export BSDDB_DUMP - CLNTTCL=$TESTDIR/util/kadm5_clnt_tcl; export CLNTTCL - SRVTCL=$TESTDIR/util/kadm5_srv_tcl; export SRVTCL - --QUALNAME=`$BUILDTOP/tests/resolve/resolve -q | tr '[A-Z]' '[a-z]'` --export QUALNAME -+HOSTNAME=`hostname | tr '[A-Z]' '[a-z]'` -+export HOSTNAME - - KRB5_CONFIG=$K5ROOT/krb5.conf; export KRB5_CONFIG - KRB5_KDC_PROFILE=$K5ROOT/kdc.conf; export KRB5_KDC_PROFILE -diff --git a/src/kadmin/testing/scripts/init_db b/src/kadmin/testing/scripts/init_db -index e65826c96..216f62793 100755 ---- a/src/kadmin/testing/scripts/init_db -+++ b/src/kadmin/testing/scripts/init_db -@@ -79,8 +79,7 @@ fi - # done - - sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ -- -e "s/__KDCHOST__/$QUALNAME/g" \ -- -e "s/__LOCALHOST__/$QUALNAME/g" \ -+ -e "s/__HOSTNAME__/$HOSTNAME/g" \ - -e "s#__MODDIR__#$MODDIR#g" \ - < $STESTDIR/proto/krb5.conf.proto > $K5ROOT/krb5.conf - sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ -diff --git a/src/kadmin/testing/scripts/start_servers b/src/kadmin/testing/scripts/start_servers -index f23df0682..05519e4ee 100755 ---- a/src/kadmin/testing/scripts/start_servers -+++ b/src/kadmin/testing/scripts/start_servers -@@ -36,8 +36,7 @@ if [ $local = 0 ]; then - - # Fix up the local krb5.conf to point to the remote - sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ -- -e "s/__KDCHOST__/$hostname/g" \ -- -e "s/__LOCALHOST__/$QUALNAME/g" \ -+ -e "s/__HOSTNAME__/$HOSTNAME/g" \ - -e "s#__MODDIR__#$TOP/../plugins/kdb#g"\ - -e "s#__PLUGIN_DIR__#$TOP/../plugins#g"\ - < $STESTDIR/proto/krb5.conf.proto > $K5ROOT/krb5.conf -diff --git a/src/kadmin/testing/scripts/start_servers_local b/src/kadmin/testing/scripts/start_servers_local -index 998ef9164..858e88031 100755 ---- a/src/kadmin/testing/scripts/start_servers_local -+++ b/src/kadmin/testing/scripts/start_servers_local -@@ -79,7 +79,7 @@ cat - > /tmp/start_servers_local$$ <<\EOF - if { [catch { - source $env(STOP)/testing/tcl/util.t - set r $env(REALM) -- set q $env(QUALNAME) -+ set q $env(HOSTNAME) - puts stdout [kadm5_init $env(SRVTCL) mrroot null \ - [config_params {KADM5_CONFIG_REALM} $r] \ - $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 server_handle] -diff --git a/src/lib/kadm5/unit-test/api.current/init-v2.exp b/src/lib/kadm5/unit-test/api.current/init-v2.exp -index 7a353d4e9..47764c212 100644 ---- a/src/lib/kadm5/unit-test/api.current/init-v2.exp -+++ b/src/lib/kadm5/unit-test/api.current/init-v2.exp -@@ -3,18 +3,14 @@ load_lib lib.t - api_exit - api_start - --if ![info exists RESOLVE] { -- set RESOLVE [findfile $objdir/../../../tests/resolve/resolve] --} - proc get_hostname { } { -- global RESOLVE - global hostname - - if {[info exists hostname]} { - return 1 - } - -- catch "exec $RESOLVE -q >myname" exec_output -+ catch "exec hostname >myname" exec_output - if ![string match "" $exec_output] { - send_log "$exec_output\n" - verbose $exec_output -diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index 9a4741fa6..0b8ae6714 100644 ---- a/src/lib/krb5/krb/init_ctx.c -+++ b/src/lib/krb5/krb/init_ctx.c -@@ -237,7 +237,7 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, - ctx->enforce_ok_as_delegate = tmp; - - retval = get_tristate(ctx, KRB5_CONF_DNS_CANONICALIZE_HOSTNAME, "fallback", -- CANONHOST_FALLBACK, 1, &tmp); -+ CANONHOST_FALLBACK, CANONHOST_FALLBACK, &tmp); - if (retval) - goto cleanup; - ctx->dns_canonicalize_hostname = tmp; -diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp -index 4d8c917cd..1e7777f1e 100644 ---- a/src/tests/dejagnu/config/default.exp -+++ b/src/tests/dejagnu/config/default.exp -@@ -268,7 +268,6 @@ foreach i { - {KTUTIL $objdir/../../kadmin/ktutil/ktutil} - {KLIST $objdir/../../clients/klist/klist} - {KDESTROY $objdir/../../clients/kdestroy/kdestroy} -- {RESOLVE $objdir/../resolve/resolve} - {T_INETD $objdir/t_inetd} - {KPROPLOG $objdir/../../kprop/kproplog} - {KPASSWD $objdir/../../clients/kpasswd/kpasswd} -@@ -462,7 +461,6 @@ proc setup_runtime_env { } { - # 0 on failure. - - proc get_hostname { } { -- global RESOLVE - global hostname - global tmppwd - -@@ -472,7 +470,7 @@ proc get_hostname { } { - - envstack_push - setup_runtime_env -- catch "exec $RESOLVE -q >$tmppwd/hostname" exec_output -+ catch "exec hostname >$tmppwd/hostname" exec_output - envstack_pop - if ![string match "" $exec_output] { - verbose -log $exec_output -@@ -710,6 +708,7 @@ proc setup_krb5_conf { {type client} } { - puts $conffile "\[libdefaults\]" - puts $conffile " default_realm = $REALMNAME" - puts $conffile " dns_lookup_kdc = false" -+ puts $conffile " qualify_shortname = \"\"" - if [info exists allow_weak_crypto($type)] { - puts $conffile " allow_weak_crypto = $allow_weak_crypto($type)" - } else { -diff --git a/src/tests/t_sn2princ.py b/src/tests/t_sn2princ.py -index 26dcb91c2..f3e187286 100755 ---- a/src/tests/t_sn2princ.py -+++ b/src/tests/t_sn2princ.py -@@ -2,7 +2,8 @@ from k5test import * - - offline = (len(args) > 0 and args[0] != "no") - --conf = {'domain_realm': {'kerberos.org': 'R1', -+conf = {'libdefaults': {'dns_canonicalize_hostname': 'true'}, -+ 'domain_realm': {'kerberos.org': 'R1', - 'example.com': 'R2', - 'mit.edu': 'R3'}} - no_rdns_conf = {'libdefaults': {'rdns': 'false'}} -@@ -28,7 +29,7 @@ def testbase(host, nametype, princhost, princrealm, env=None): - fail('Expected %s, got %s' % (expected, out)) - - def test(host, princhost, princrealm): -- # Test with the host-based name type in the default environment. -+ # Test with the host-based name type with canonicalization enabled. - testbase(host, 'srv-hst', princhost, princrealm) - - def testnc(host, princhost, princrealm): -diff --git a/src/util/k5test.py b/src/util/k5test.py -index eea92275d..5196cfa43 100644 ---- a/src/util/k5test.py -+++ b/src/util/k5test.py -@@ -193,7 +193,10 @@ Scripts may use the following functions and variables: - - * plugins: The plugin directory in the build tree (absolute path). - --* hostname: This machine's fully-qualified domain name. -+* hostname: The local hostname as it will initially appear in -+ krb5_sname_to_principal() results. (Shortname qualification is -+ turned off in the test environment to make this value easy to -+ discover from Python.) - - * null_input: A file opened to read /dev/null. - -@@ -525,23 +528,6 @@ def _find_srctop(): - return os.path.abspath(root) - - --# Return the local hostname as it will be canonicalized by --# krb5_sname_to_principal. We can't simply use socket.getfqdn() --# because it explicitly prefers results containing periods and --# krb5_sname_to_principal doesn't care. --def _get_hostname(): -- hostname = socket.gethostname() -- try: -- ai = socket.getaddrinfo(hostname, None, 0, 0, 0, socket.AI_CANONNAME) -- except socket.gaierror as e: -- fail('Local hostname "%s" does not resolve: %s.' % (hostname, e[1])) -- (family, socktype, proto, canonname, sockaddr) = ai[0] -- try: -- name = socket.getnameinfo(sockaddr, socket.NI_NAMEREQD) -- except socket.gaierror: -- return canonname.lower() -- return name[0].lower() -- - # Parse command line arguments, setting global option variables. Also - # sets the global variable args to the positional arguments, which may - # be used by the test script. -@@ -1263,6 +1249,7 @@ _default_krb5_conf = { - 'libdefaults': { - 'default_realm': '$realm', - 'dns_lookup_kdc': 'false', -+ 'qualify_shortname': '', - 'plugin_base_dir': '$plugins'}, - 'realms': {'$realm': { - 'kdc': '$hostname:$port0', -@@ -1356,7 +1343,7 @@ buildtop = _find_buildtop() - srctop = _find_srctop() - plugins = os.path.join(buildtop, 'plugins') - runenv = _import_runenv() --hostname = _get_hostname() -+hostname = socket.gethostname().lower() - null_input = open(os.devnull, 'r') - - # A DB pass is a tuple of: name, kdc_conf. diff --git a/Do-expiration-warnings-for-all-init_creds-APIs.patch b/Do-expiration-warnings-for-all-init_creds-APIs.patch deleted file mode 100644 index 0dc7528..0000000 --- a/Do-expiration-warnings-for-all-init_creds-APIs.patch +++ /dev/null @@ -1,425 +0,0 @@ -From 4369b03968131b005acbafd043465899da50e1dc Mon Sep 17 00:00:00 2001 -From: Sumit Bose -Date: Fri, 28 Feb 2020 10:11:49 +0100 -Subject: [PATCH] Do expiration warnings for all init_creds APIs - -Move the password expiration warning code from gic_pwd.c to -get_in_tkt.c. Call it from init_creds_step_reply() on successful -completion. - -[ghudson@mit.edu: added test case; simplified doc comment; moved call -site to init_creds_step_reply(); rewrote commit message] - -ticket: 8893 (new) -(cherry picked from commit e1efb890f7ac31b32c68ab816ef118dbfb5a8c7e) ---- - src/include/krb5/krb5.hin | 9 ++- - src/lib/krb5/krb/get_in_tkt.c | 112 ++++++++++++++++++++++++++++++ - src/lib/krb5/krb/gic_pwd.c | 110 ----------------------------- - src/lib/krb5/krb/t_expire_warn.c | 47 +++++++++---- - src/lib/krb5/krb/t_expire_warn.py | 22 ++++-- - 5 files changed, 165 insertions(+), 135 deletions(-) - -diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 6355e6540..f8269fb17 100644 ---- a/src/include/krb5/krb5.hin -+++ b/src/include/krb5/krb5.hin -@@ -7174,11 +7174,10 @@ typedef void - * - * Set a callback to receive password and account expiration times. - * -- * This option only applies to krb5_get_init_creds_password(). @a cb will be -- * invoked if and only if credentials are successfully acquired. The callback -- * will receive the @a context from the krb5_get_init_creds_password() call and -- * the @a data argument supplied with this API. The remaining arguments should -- * be interpreted as follows: -+ * @a cb will be invoked if and only if credentials are successfully acquired. -+ * The callback will receive the @a context from the calling function and the -+ * @a data argument supplied with this API. The remaining arguments should be -+ * interpreted as follows: - * - * If @a is_last_req is true, then the KDC reply contained last-req entries - * which unambiguously indicated the password expiration, account expiration, -diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c -index 870df62a1..cc0f70e83 100644 ---- a/src/lib/krb5/krb/get_in_tkt.c -+++ b/src/lib/krb5/krb/get_in_tkt.c -@@ -1482,6 +1482,116 @@ accept_method_data(krb5_context context, krb5_init_creds_context ctx) - ctx->method_padata); - } - -+/* Return the password expiry time indicated by enc_part2. Set *is_last_req -+ * if the information came from a last_req value. */ -+static void -+get_expiry_times(krb5_enc_kdc_rep_part *enc_part2, krb5_timestamp *pw_exp, -+ krb5_timestamp *acct_exp, krb5_boolean *is_last_req) -+{ -+ krb5_last_req_entry **last_req; -+ krb5_int32 lr_type; -+ -+ *pw_exp = 0; -+ *acct_exp = 0; -+ *is_last_req = FALSE; -+ -+ /* Look for last-req entries for password or account expiration. */ -+ if (enc_part2->last_req) { -+ for (last_req = enc_part2->last_req; *last_req; last_req++) { -+ lr_type = (*last_req)->lr_type; -+ if (lr_type == KRB5_LRQ_ALL_PW_EXPTIME || -+ lr_type == KRB5_LRQ_ONE_PW_EXPTIME) { -+ *is_last_req = TRUE; -+ *pw_exp = (*last_req)->value; -+ } else if (lr_type == KRB5_LRQ_ALL_ACCT_EXPTIME || -+ lr_type == KRB5_LRQ_ONE_ACCT_EXPTIME) { -+ *is_last_req = TRUE; -+ *acct_exp = (*last_req)->value; -+ } -+ } -+ } -+ -+ /* If we didn't find any, use the ambiguous key_exp field. */ -+ if (*is_last_req == FALSE) -+ *pw_exp = enc_part2->key_exp; -+} -+ -+/* -+ * Send an appropriate warning prompter if as_reply indicates that the password -+ * is going to expire soon. If an expire callback was provided, use that -+ * instead. -+ */ -+static void -+warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, -+ krb5_prompter_fct prompter, void *data, -+ const char *in_tkt_service, krb5_kdc_rep *as_reply) -+{ -+ krb5_error_code ret; -+ krb5_expire_callback_func expire_cb; -+ void *expire_data; -+ krb5_timestamp pw_exp, acct_exp, now; -+ krb5_boolean is_last_req; -+ krb5_deltat delta; -+ char ts[256], banner[1024]; -+ -+ if (as_reply == NULL || as_reply->enc_part2 == NULL) -+ return; -+ -+ get_expiry_times(as_reply->enc_part2, &pw_exp, &acct_exp, &is_last_req); -+ -+ k5_gic_opt_get_expire_cb(options, &expire_cb, &expire_data); -+ if (expire_cb != NULL) { -+ /* Invoke the expire callback and don't send prompter warnings. */ -+ (*expire_cb)(context, expire_data, pw_exp, acct_exp, is_last_req); -+ return; -+ } -+ -+ /* Don't warn if no password expiry value was sent. */ -+ if (pw_exp == 0) -+ return; -+ -+ /* Don't warn if the password is being changed. */ -+ if (in_tkt_service && strcmp(in_tkt_service, "kadmin/changepw") == 0) -+ return; -+ -+ /* -+ * If the expiry time came from a last_req field, assume the KDC wants us -+ * to warn. Otherwise, warn only if the expiry time is less than a week -+ * from now. -+ */ -+ ret = krb5_timeofday(context, &now); -+ if (ret != 0) -+ return; -+ if (!is_last_req && -+ (ts_after(now, pw_exp) || ts_delta(pw_exp, now) > 7 * 24 * 60 * 60)) -+ return; -+ -+ if (!prompter) -+ return; -+ -+ ret = krb5_timestamp_to_string(pw_exp, ts, sizeof(ts)); -+ if (ret != 0) -+ return; -+ -+ delta = ts_delta(pw_exp, now); -+ if (delta < 3600) { -+ snprintf(banner, sizeof(banner), -+ _("Warning: Your password will expire in less than one hour " -+ "on %s"), ts); -+ } else if (delta < 86400 * 2) { -+ snprintf(banner, sizeof(banner), -+ _("Warning: Your password will expire in %d hour%s on %s"), -+ delta / 3600, delta < 7200 ? "" : "s", ts); -+ } else { -+ snprintf(banner, sizeof(banner), -+ _("Warning: Your password will expire in %d days on %s"), -+ delta / 86400, ts); -+ } -+ -+ /* PROMPTER_INVOCATION */ -+ (*prompter)(context, data, 0, banner, 0, 0); -+} -+ - static krb5_error_code - init_creds_step_reply(krb5_context context, - krb5_init_creds_context ctx, -@@ -1693,6 +1803,8 @@ init_creds_step_reply(krb5_context context, - - /* success */ - ctx->complete = TRUE; -+ warn_pw_expiry(context, ctx->opt, ctx->prompter, ctx->prompter_data, -+ ctx->in_tkt_service, ctx->reply); - - cleanup: - krb5_free_pa_data(context, kdc_padata); -diff --git a/src/lib/krb5/krb/gic_pwd.c b/src/lib/krb5/krb/gic_pwd.c -index 14ce23ba4..54e0a8ebe 100644 ---- a/src/lib/krb5/krb/gic_pwd.c -+++ b/src/lib/krb5/krb/gic_pwd.c -@@ -133,113 +133,6 @@ krb5_init_creds_set_password(krb5_context context, - return 0; - } - --/* Return the password expiry time indicated by enc_part2. Set *is_last_req -- * if the information came from a last_req value. */ --static void --get_expiry_times(krb5_enc_kdc_rep_part *enc_part2, krb5_timestamp *pw_exp, -- krb5_timestamp *acct_exp, krb5_boolean *is_last_req) --{ -- krb5_last_req_entry **last_req; -- krb5_int32 lr_type; -- -- *pw_exp = 0; -- *acct_exp = 0; -- *is_last_req = FALSE; -- -- /* Look for last-req entries for password or account expiration. */ -- if (enc_part2->last_req) { -- for (last_req = enc_part2->last_req; *last_req; last_req++) { -- lr_type = (*last_req)->lr_type; -- if (lr_type == KRB5_LRQ_ALL_PW_EXPTIME || -- lr_type == KRB5_LRQ_ONE_PW_EXPTIME) { -- *is_last_req = TRUE; -- *pw_exp = (*last_req)->value; -- } else if (lr_type == KRB5_LRQ_ALL_ACCT_EXPTIME || -- lr_type == KRB5_LRQ_ONE_ACCT_EXPTIME) { -- *is_last_req = TRUE; -- *acct_exp = (*last_req)->value; -- } -- } -- } -- -- /* If we didn't find any, use the ambiguous key_exp field. */ -- if (*is_last_req == FALSE) -- *pw_exp = enc_part2->key_exp; --} -- --/* -- * Send an appropriate warning prompter if as_reply indicates that the password -- * is going to expire soon. If an expire callback was provided, use that -- * instead. -- */ --static void --warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, -- krb5_prompter_fct prompter, void *data, -- const char *in_tkt_service, krb5_kdc_rep *as_reply) --{ -- krb5_error_code ret; -- krb5_expire_callback_func expire_cb; -- void *expire_data; -- krb5_timestamp pw_exp, acct_exp, now; -- krb5_boolean is_last_req; -- krb5_deltat delta; -- char ts[256], banner[1024]; -- -- get_expiry_times(as_reply->enc_part2, &pw_exp, &acct_exp, &is_last_req); -- -- k5_gic_opt_get_expire_cb(options, &expire_cb, &expire_data); -- if (expire_cb != NULL) { -- /* Invoke the expire callback and don't send prompter warnings. */ -- (*expire_cb)(context, expire_data, pw_exp, acct_exp, is_last_req); -- return; -- } -- -- /* Don't warn if no password expiry value was sent. */ -- if (pw_exp == 0) -- return; -- -- /* Don't warn if the password is being changed. */ -- if (in_tkt_service && strcmp(in_tkt_service, "kadmin/changepw") == 0) -- return; -- -- /* -- * If the expiry time came from a last_req field, assume the KDC wants us -- * to warn. Otherwise, warn only if the expiry time is less than a week -- * from now. -- */ -- ret = krb5_timeofday(context, &now); -- if (ret != 0) -- return; -- if (!is_last_req && -- (ts_after(now, pw_exp) || ts_delta(pw_exp, now) > 7 * 24 * 60 * 60)) -- return; -- -- if (!prompter) -- return; -- -- ret = krb5_timestamp_to_string(pw_exp, ts, sizeof(ts)); -- if (ret != 0) -- return; -- -- delta = ts_delta(pw_exp, now); -- if (delta < 3600) { -- snprintf(banner, sizeof(banner), -- _("Warning: Your password will expire in less than one hour " -- "on %s"), ts); -- } else if (delta < 86400*2) { -- snprintf(banner, sizeof(banner), -- _("Warning: Your password will expire in %d hour%s on %s"), -- delta / 3600, delta < 7200 ? "" : "s", ts); -- } else { -- snprintf(banner, sizeof(banner), -- _("Warning: Your password will expire in %d days on %s"), -- delta / 86400, ts); -- } -- -- /* PROMPTER_INVOCATION */ -- (*prompter)(context, data, 0, banner, 0, 0); --} -- - /* - * Create a temporary options structure for getting a kadmin/changepw ticket, - * based on the appplication-specified options. Propagate all application -@@ -496,9 +389,6 @@ krb5_get_init_creds_password(krb5_context context, - goto cleanup; - - cleanup: -- if (ret == 0) -- warn_pw_expiry(context, options, prompter, data, in_tkt_service, -- as_reply); - free(chpw_opts); - zapfree(gakpw.storage.data, gakpw.storage.length); - memset(pw0array, 0, sizeof(pw0array)); -diff --git a/src/lib/krb5/krb/t_expire_warn.c b/src/lib/krb5/krb/t_expire_warn.c -index 1e59acba1..dc8dc8fb3 100644 ---- a/src/lib/krb5/krb/t_expire_warn.c -+++ b/src/lib/krb5/krb/t_expire_warn.c -@@ -28,6 +28,13 @@ - - static int exp_dummy, prompt_dummy; - -+static void -+check(krb5_error_code code) -+{ -+ if (code != 0) -+ abort(); -+} -+ - static krb5_error_code - prompter_cb(krb5_context ctx, void *data, const char *name, - const char *banner, int num_prompts, krb5_prompt prompts[]) -@@ -52,36 +59,48 @@ int - main(int argc, char **argv) - { - krb5_context ctx; -+ krb5_init_creds_context icctx; - krb5_get_init_creds_opt *opt; - char *user, *password, *service = NULL; -- krb5_boolean use_cb; -+ krb5_boolean use_cb, stepwise; - krb5_principal client; - krb5_creds creds; - -- if (argc < 4) { -- fprintf(stderr, "Usage: %s username password {1|0} [service]\n", -+ if (argc < 5) { -+ fprintf(stderr, "Usage: %s username password {1|0} {1|0} [service]\n", - argv[0]); - return 1; - } - user = argv[1]; - password = argv[2]; - use_cb = atoi(argv[3]); -- if (argc >= 5) -- service = argv[4]; -+ stepwise = atoi(argv[4]); -+ if (argc >= 6) -+ service = argv[5]; - -- assert(krb5_init_context(&ctx) == 0); -- assert(krb5_get_init_creds_opt_alloc(ctx, &opt) == 0); -+ check(krb5_init_context(&ctx)); -+ check(krb5_get_init_creds_opt_alloc(ctx, &opt)); - if (use_cb) { -- assert(krb5_get_init_creds_opt_set_expire_callback(ctx, opt, expire_cb, -- &exp_dummy) == 0); -+ check(krb5_get_init_creds_opt_set_expire_callback(ctx, opt, expire_cb, -+ &exp_dummy)); -+ } -+ check(krb5_parse_name(ctx, user, &client)); -+ if (stepwise) { -+ check(krb5_init_creds_init(ctx, client, prompter_cb, &prompt_dummy, 0, -+ opt, &icctx)); -+ krb5_init_creds_set_password(ctx, icctx, password); -+ if (service != NULL) -+ check(krb5_init_creds_set_service(ctx, icctx, service)); -+ check(krb5_init_creds_get(ctx, icctx)); -+ krb5_init_creds_free(ctx, icctx); -+ } else { -+ check(krb5_get_init_creds_password(ctx, &creds, client, password, -+ prompter_cb, &prompt_dummy, 0, -+ service, opt)); -+ krb5_free_cred_contents(ctx, &creds); - } -- assert(krb5_parse_name(ctx, user, &client) == 0); -- assert(krb5_get_init_creds_password(ctx, &creds, client, password, -- prompter_cb, &prompt_dummy, 0, service, -- opt) == 0); - krb5_get_init_creds_opt_free(ctx, opt); - krb5_free_principal(ctx, client); -- krb5_free_cred_contents(ctx, &creds); - krb5_free_context(ctx); - return 0; - } -diff --git a/src/lib/krb5/krb/t_expire_warn.py b/src/lib/krb5/krb/t_expire_warn.py -index 781f2728a..e163cc7e4 100755 ---- a/src/lib/krb5/krb/t_expire_warn.py -+++ b/src/lib/krb5/krb/t_expire_warn.py -@@ -34,23 +34,33 @@ realm.run([kadminl, 'addprinc', '-pw', 'pass', '-pwexpire', '12 hours', - realm.run([kadminl, 'addprinc', '-pw', 'pass', '-pwexpire', '3 days', 'days']) - - # Check for expected prompter warnings when no expire callback is used. --output = realm.run(['./t_expire_warn', 'noexpire', 'pass', '0']) -+output = realm.run(['./t_expire_warn', 'noexpire', 'pass', '0', '0']) - if output: - fail('Unexpected output for noexpire') --realm.run(['./t_expire_warn', 'minutes', 'pass', '0'], -+realm.run(['./t_expire_warn', 'minutes', 'pass', '0', '0'], - expected_msg=' less than one hour on ') --realm.run(['./t_expire_warn', 'hours', 'pass', '0'], expected_msg=' hours on ') --realm.run(['./t_expire_warn', 'days', 'pass', '0'], expected_msg=' days on ') -+realm.run(['./t_expire_warn', 'hours', 'pass', '0', '0'], -+ expected_msg=' hours on ') -+realm.run(['./t_expire_warn', 'days', 'pass', '0', '0'], -+ expected_msg=' days on ') -+# Try one case with the stepwise interface. -+realm.run(['./t_expire_warn', 'days', 'pass', '0', '1'], -+ expected_msg=' days on ') - - # Check for expected expire callback behavior. These tests are - # carefully agnostic about whether the KDC supports last_req fields, - # and could be made more specific if last_req support is added. --output = realm.run(['./t_expire_warn', 'noexpire', 'pass', '1']) -+output = realm.run(['./t_expire_warn', 'noexpire', 'pass', '1', '0']) - if 'password_expiration = 0\n' not in output or \ - 'account_expiration = 0\n' not in output or \ - 'is_last_req = ' not in output: - fail('Expected callback output not seen for noexpire') --output = realm.run(['./t_expire_warn', 'days', 'pass', '1']) -+output = realm.run(['./t_expire_warn', 'days', 'pass', '1', '0']) -+if 'password_expiration = ' not in output or \ -+ 'password_expiration = 0\n' in output: -+ fail('Expected non-zero password expiration not seen for days') -+# Try one case with the stepwise interface. -+output = realm.run(['./t_expire_warn', 'days', 'pass', '1', '1']) - if 'password_expiration = ' not in output or \ - 'password_expiration = 0\n' in output: - fail('Expected non-zero password expiration not seen for days') diff --git a/Document-k-option-in-kvno-1-synopsis.patch b/Document-k-option-in-kvno-1-synopsis.patch index 21f8100..28323f4 100644 --- a/Document-k-option-in-kvno-1-synopsis.patch +++ b/Document-k-option-in-kvno-1-synopsis.patch @@ -1,4 +1,4 @@ -From 588d964f59356373353dfd31d4fdcba95e508385 Mon Sep 17 00:00:00 2001 +From b401a1127f27f8cd564e32411f799648a8fd5481 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 24 Nov 2020 12:52:02 -0500 Subject: [PATCH] Document -k option in kvno(1) synopsis @@ -13,7 +13,7 @@ synopsis, option descriptions, and xusage(), but missed one option. 2 files changed, 2 insertions(+) diff --git a/doc/user/user_commands/kvno.rst b/doc/user/user_commands/kvno.rst -index 6fd8577a5..1e273e26e 100644 +index 65c44e1c0..93a5132b2 100644 --- a/doc/user/user_commands/kvno.rst +++ b/doc/user/user_commands/kvno.rst @@ -9,6 +9,7 @@ SYNOPSIS @@ -25,7 +25,7 @@ index 6fd8577a5..1e273e26e 100644 [**-u** | **-S** *sname*] [**-P**] diff --git a/src/man/kvno.man b/src/man/kvno.man -index 7c9565bdb..dc9847e99 100644 +index 953d168e6..ebdd6e8ca 100644 --- a/src/man/kvno.man +++ b/src/man/kvno.man @@ -35,6 +35,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]] diff --git a/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch b/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch deleted file mode 100644 index ad0dd7a..0000000 --- a/Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch +++ /dev/null @@ -1,59 +0,0 @@ -From 5106d0b7ea10d1faa21f6dfb542a46eb74e78d40 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 24 Jul 2020 16:05:24 -0400 -Subject: [PATCH] Fix leak in KERB_AP_OPTIONS_CBT server support - -In check_cbt(), use a local variable to hold the retrieved authdata -list, and free it before returning. - -ticket: 8900 -(cherry picked from commit bf2ddff13c178e0c291f8fb382b040080d159e4f) ---- - src/lib/gssapi/krb5/accept_sec_context.c | 23 +++++++++++++---------- - 1 file changed, 13 insertions(+), 10 deletions(-) - -diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index 175a24c4e..3d5b84b15 100644 ---- a/src/lib/gssapi/krb5/accept_sec_context.c -+++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -433,27 +433,30 @@ static const uint8_t null_cb[CB_MD5_LEN]; - /* Look for AP_OPTIONS in authdata. If present and the options include - * KERB_AP_OPTIONS_CBT, set *cbt_out to true. */ - static krb5_error_code --check_cbt(krb5_context context, krb5_authdata **authdata, -+check_cbt(krb5_context context, krb5_authdata *const *authdata, - krb5_boolean *cbt_out) - { - krb5_error_code code; -+ krb5_authdata **ad; - uint32_t ad_ap_options; - const uint32_t KERB_AP_OPTIONS_CBT = 0x4000; - - *cbt_out = FALSE; - - code = krb5_find_authdata(context, NULL, authdata, -- KRB5_AUTHDATA_AP_OPTIONS, &authdata); -- if (code || authdata == NULL) -+ KRB5_AUTHDATA_AP_OPTIONS, &ad); -+ if (code || ad == NULL) - return code; -- if (authdata[1] != NULL || authdata[0]->length != 4) -- return KRB5KRB_AP_ERR_MSG_TYPE; -+ if (ad[1] != NULL || ad[0]->length != 4) { -+ code = KRB5KRB_AP_ERR_MSG_TYPE; -+ } else { -+ ad_ap_options = load_32_le(ad[0]->contents); -+ if (ad_ap_options & KERB_AP_OPTIONS_CBT) -+ *cbt_out = TRUE; -+ } - -- ad_ap_options = load_32_le(authdata[0]->contents); -- if (ad_ap_options & KERB_AP_OPTIONS_CBT) -- *cbt_out = TRUE; -- -- return 0; -+ krb5_free_authdata(context, ad); -+ return code; - } - - /* diff --git a/Fix-minor-static-analysis-defects.patch b/Fix-minor-static-analysis-defects.patch deleted file mode 100644 index c136b7f..0000000 --- a/Fix-minor-static-analysis-defects.patch +++ /dev/null @@ -1,106 +0,0 @@ -From a33dc1cfb0ebecb67cc7f38258303492a552cb73 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 15 Oct 2020 18:15:29 -0400 -Subject: [PATCH] Fix minor static analysis defects - -Remove an unused variable in krb5_ldap_create(). Handle the return -value from krb5_dbe_get_string() in the certauth test plugin module. -Handle the return value from k5_expand_path_tokens() in -k5_rc_default(). Remove dead assignments in -krb5_get_credentials_for_user() and kg_accept_krb5(). - -[ghudson@mit.edu: squashed and edited commit message; simplified -k5_rc_default() change] - -(cherry picked from commit b27461141810fddd299764928649148c5d0e99f3) ---- - src/lib/gssapi/krb5/accept_sec_context.c | 4 +--- - src/lib/krb5/krb/s4u_creds.c | 1 - - src/lib/krb5/rcache/rc_base.c | 2 ++ - src/plugins/certauth/test/main.c | 3 +++ - src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c | 4 ---- - 5 files changed, 6 insertions(+), 8 deletions(-) - -diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index 3d5b84b15..e2c5e2b59 100644 ---- a/src/lib/gssapi/krb5/accept_sec_context.c -+++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -671,7 +671,7 @@ kg_accept_krb5(minor_status, context_handle, - krb5_auth_context auth_context = NULL; - krb5_ticket * ticket = NULL; - const gss_OID_desc *mech_used = NULL; -- OM_uint32 major_status = GSS_S_FAILURE; -+ OM_uint32 major_status; - OM_uint32 tmp_minor_status; - krb5_error krb_error_data; - krb5_data scratch; -@@ -878,8 +878,6 @@ kg_accept_krb5(minor_status, context_handle, - if (major_status != GSS_S_COMPLETE) - goto fail; - -- major_status = GSS_S_FAILURE; -- - if (exts->iakerb.conv && !exts->iakerb.verified) { - major_status = GSS_S_BAD_SIG; - goto fail; -diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c -index d8f486dc6..35a8843e5 100644 ---- a/src/lib/krb5/krb/s4u_creds.c -+++ b/src/lib/krb5/krb/s4u_creds.c -@@ -714,7 +714,6 @@ krb5_get_credentials_for_user(krb5_context context, krb5_flags options, - } else if (code != KRB5_CC_NOTFOUND && code != KRB5_CC_NOT_KTYPE) { - goto cleanup; - } -- code = 0; - } - - /* Note the authdata we asked for in the output creds. */ -diff --git a/src/lib/krb5/rcache/rc_base.c b/src/lib/krb5/rcache/rc_base.c -index 5f456d1f3..f9a482318 100644 ---- a/src/lib/krb5/rcache/rc_base.c -+++ b/src/lib/krb5/rcache/rc_base.c -@@ -56,6 +56,8 @@ k5_rc_default(krb5_context context, krb5_rcache *rc_out) - &profstr) == 0 && profstr != NULL) { - ret = k5_expand_path_tokens(context, profstr, &rcname); - profile_release_string(profstr); -+ if (ret) -+ return ret; - ret = k5_rc_resolve(context, rcname, rc_out); - free(rcname); - return ret; -diff --git a/src/plugins/certauth/test/main.c b/src/plugins/certauth/test/main.c -index d4633b8cd..7e7a3ef4c 100644 ---- a/src/plugins/certauth/test/main.c -+++ b/src/plugins/certauth/test/main.c -@@ -171,6 +171,9 @@ test2_authorize(krb5_context context, krb5_certauth_moddata moddata, - - ret = krb5_dbe_get_string(context, (krb5_db_entry *)db_entry, "hwauth", - &strval); -+ if (ret) -+ goto cleanup; -+ - ret = (strval != NULL) ? KRB5_CERTAUTH_HWAUTH : 0; - krb5_dbe_free_string(context, strval); - -diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c -index 5b57c799a..2d6605666 100644 ---- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c -+++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_create.c -@@ -55,7 +55,6 @@ krb5_ldap_create(krb5_context context, char *conf_section, char **db_args) - krb5_error_code status = 0; - krb5_ldap_realm_params *rparams = NULL; - krb5_ldap_context *ldap_context=NULL; -- krb5_boolean realm_obj_created = FALSE; - int mask = 0; - - /* Clear the global error string */ -@@ -109,9 +108,6 @@ krb5_ldap_create(krb5_context context, char *conf_section, char **db_args) - if ((status = krb5_ldap_create_realm(context, rparams, mask))) - goto cleanup; - -- /* We just created the Realm container. Here starts our transaction tracking */ -- realm_obj_created = TRUE; -- - /* verify realm object */ - if ((status = krb5_ldap_read_realm_params(context, - rparams->realm_name, diff --git a/Fix-typo-in-in-in-the-ksu-man-page.patch b/Fix-typo-in-in-in-the-ksu-man-page.patch deleted file mode 100644 index 922aa29..0000000 --- a/Fix-typo-in-in-in-the-ksu-man-page.patch +++ /dev/null @@ -1,37 +0,0 @@ -From 5952a06a594c4dc0f20f7ba2854b25f76734aa27 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 14 May 2020 15:01:18 -0400 -Subject: [PATCH] Fix typo ("in in") in the ksu man page - -(cherry picked from commit 1011841acdc1020f308ef4f569c6622f279d8c3f) ---- - doc/user/user_commands/ksu.rst | 2 +- - src/man/ksu.man | 2 +- - 2 files changed, 2 insertions(+), 2 deletions(-) - -diff --git a/doc/user/user_commands/ksu.rst b/doc/user/user_commands/ksu.rst -index 8d6c7ef79..933738229 100644 ---- a/doc/user/user_commands/ksu.rst -+++ b/doc/user/user_commands/ksu.rst -@@ -155,7 +155,7 @@ wrong password is typed in, ksu fails. - .. note:: - - During authentication, only the tickets that could be -- obtained without providing a password are cached in in the -+ obtained without providing a password are cached in the - source cache. - - -diff --git a/src/man/ksu.man b/src/man/ksu.man -index a1972518c..b07a4b05d 100644 ---- a/src/man/ksu.man -+++ b/src/man/ksu.man -@@ -176,7 +176,7 @@ wrong password is typed in, ksu fails. - .INDENT 0.0 - .INDENT 3.5 - During authentication, only the tickets that could be --obtained without providing a password are cached in in the -+obtained without providing a password are cached in the - source cache. - .UNINDENT - .UNINDENT diff --git a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch b/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch deleted file mode 100644 index aaab2d3..0000000 --- a/Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch +++ /dev/null @@ -1,37 +0,0 @@ -From cc572c5b6f8a3269c24c0f21f5799e60014635fb Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 15 Jul 2020 15:42:20 -0400 -Subject: [PATCH] Ignore bad enctypes in krb5_string_to_keysalts() - -Fixes a problem where the presence of legacy/unrecognized keysalts in -supported_enctypes would prevent the kadmin programs from starting. - -[ghudson@mit.edu: ideally we would put a warning in the kadmind log, -but that is difficult to do when the parsing is done inside a library. -Even adding a trace log is difficult because the kadm5 str_conv -functions do not accept contexts.] - -ticket: 8929 (new) -(cherry picked from commit be5396ada0e8dabd68bd0aceb733cfca39a609bc) ---- - src/lib/kadm5/str_conv.c | 7 ++++--- - 1 file changed, 4 insertions(+), 3 deletions(-) - -diff --git a/src/lib/kadm5/str_conv.c b/src/lib/kadm5/str_conv.c -index 7cf51d316..798295606 100644 ---- a/src/lib/kadm5/str_conv.c -+++ b/src/lib/kadm5/str_conv.c -@@ -340,9 +340,10 @@ krb5_string_to_keysalts(const char *string, const char *tupleseps, - while ((ksp = strtok_r(p, tseps, &tlasts)) != NULL) { - /* Pass a null pointer to subsequent calls to strtok_r(). */ - p = NULL; -- ret = string_to_keysalt(ksp, ksaltseps, &etype, &stype); -- if (ret) -- goto cleanup; -+ -+ /* Discard unrecognized keysalts. */ -+ if (string_to_keysalt(ksp, ksaltseps, &etype, &stype) != 0) -+ continue; - - /* Ignore duplicate keysalts if caller asks. */ - if (!dups && krb5_keysalt_is_present(ksalts, nksalts, etype, stype)) diff --git a/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch b/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch deleted file mode 100644 index b5180b2..0000000 --- a/Implement-GSS_C_CHANNEL_BOUND_FLAG.patch +++ /dev/null @@ -1,91 +0,0 @@ -From e0a702b6e5f0665cca88723f7b17ff90ea218e45 Mon Sep 17 00:00:00 2001 -From: Alexander Scheel -Date: Wed, 5 Jul 2017 11:38:30 -0400 -Subject: [PATCH] Implement GSS_C_CHANNEL_BOUND_FLAG - -Define a new channel-bound GSS return flag, and set it in the krb5 -mech if the initiator sent channel bindings matching the acceptor's. -Do not error out if the acceptor specifies channel bindings and the -initiator does not send them. - -[ghudson@mit.edu: simplified code changes; fleshed out commit message] - -[iboukris: cherry-picked from another PR and reduced in scope] - -ticket: 8899 (new) -(cherry picked from commit 429a31146083fac21958631c2af572b08ec91022) ---- - src/lib/gssapi/generic/gssapi_ext.h | 2 ++ - src/lib/gssapi/krb5/accept_sec_context.c | 18 +++++++++++++----- - 2 files changed, 15 insertions(+), 5 deletions(-) - -diff --git a/src/lib/gssapi/generic/gssapi_ext.h b/src/lib/gssapi/generic/gssapi_ext.h -index 218456e44..c675e8ebb 100644 ---- a/src/lib/gssapi/generic/gssapi_ext.h -+++ b/src/lib/gssapi/generic/gssapi_ext.h -@@ -595,6 +595,8 @@ gss_store_cred_into( - * attribute (along with any applicable RFC 5587 attributes). - */ - -+#define GSS_C_CHANNEL_BOUND_FLAG 2048 /* 0x00000800 */ -+ - OM_uint32 KRB5_CALLCONV - gssspi_query_meta_data( - OM_uint32 *minor_status, -diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index 70dd7fc0c..9d3e2f4fe 100644 ---- a/src/lib/gssapi/krb5/accept_sec_context.c -+++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -427,6 +427,9 @@ kg_process_extension(krb5_context context, - GSS_C_SEQUENCE_FLAG | GSS_C_DCE_STYLE | \ - GSS_C_IDENTIFY_FLAG | GSS_C_EXTENDED_ERROR_FLAG) - -+/* A zero-value channel binding, for comparison */ -+static const uint8_t null_cb[CB_MD5_LEN]; -+ - /* - * The krb5 GSS mech appropriates the authenticator checksum field from RFC - * 4120 to store structured data instead of a checksum, indicated with checksum -@@ -435,9 +438,10 @@ kg_process_extension(krb5_context context, - * - * Interpret the checksum. Read delegated creds into *deleg_out if it is not - * NULL. Set *flags_out to the allowed subset of token flags, plus -- * GSS_C_DELEG_FLAG if a delegated credential was present. Process any -- * extensions found using exts. On error, set *code_out to a krb5_error code -- * for use as a minor status value. -+ * GSS_C_DELEG_FLAG if a delegated credential was present and -+ * GSS_C_CHANNEL_BOUND_FLAG if matching channel bindings are present. Process -+ * any extensions found using exts. On error, set *code_out to a krb5_error -+ * code for use as a minor status value. - */ - static OM_uint32 - process_checksum(OM_uint32 *minor_status, krb5_context context, -@@ -450,7 +454,7 @@ process_checksum(OM_uint32 *minor_status, krb5_context context, - krb5_error_code code = 0; - OM_uint32 status, option_id, token_flags; - size_t cb_len, option_len; -- krb5_boolean valid; -+ krb5_boolean valid, token_cb_present = FALSE, cb_match = FALSE; - krb5_key subkey; - krb5_data option, empty = empty_data(); - krb5_checksum cb_cksum; -@@ -516,7 +520,9 @@ process_checksum(OM_uint32 *minor_status, krb5_context context, - goto fail; - } - assert(cb_cksum.length == cb_len); -- if (k5_bcmp(token_cb, cb_cksum.contents, cb_len) != 0) { -+ token_cb_present = (k5_bcmp(token_cb, null_cb, cb_len) != 0); -+ cb_match = (k5_bcmp(token_cb, cb_cksum.contents, cb_len) == 0); -+ if (token_cb_present && !cb_match) { - status = GSS_S_BAD_BINDINGS; - goto fail; - } -@@ -525,6 +531,8 @@ process_checksum(OM_uint32 *minor_status, krb5_context context, - /* Read the token flags and accept some of them as context flags. */ - token_flags = k5_input_get_uint32_le(&in); - *flags_out = token_flags & INITIATOR_FLAGS; -+ if (cb_match) -+ *flags_out |= GSS_C_CHANNEL_BOUND_FLAG; - - /* Read the delegated credential if present. */ - if (in.len >= 4 && (token_flags & GSS_C_DELEG_FLAG)) { diff --git a/Implement-KERB_AP_OPTIONS_CBT-server-side.patch b/Implement-KERB_AP_OPTIONS_CBT-server-side.patch deleted file mode 100644 index 458901d..0000000 --- a/Implement-KERB_AP_OPTIONS_CBT-server-side.patch +++ /dev/null @@ -1,102 +0,0 @@ -From 323329d9033f32f49266921910124fe4f2a9124c Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Mon, 9 Mar 2020 16:04:21 +0100 -Subject: [PATCH] Implement KERB_AP_OPTIONS_CBT (server side) - -Add server support for Microsoft's KERB_AP_OPTIONS_CBT as described in -MS-KILE. If the client includes the AP option in the authenticator -authdata and the server passed channel bindings, require the bindings -to match. - -[ghudson@mit.edu: refactored to put more logic in the helper function; -added a comment; clarified commit message] - -ticket: 8900 (new) -(cherry picked from commit 4f7c77b64a048ca5e3199b26b31493698c777a9c) ---- - src/include/krb5/krb5.hin | 1 + - src/lib/gssapi/krb5/accept_sec_context.c | 45 +++++++++++++++++++++++- - 2 files changed, 45 insertions(+), 1 deletion(-) - -diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index f8269fb17..9264bede1 100644 ---- a/src/include/krb5/krb5.hin -+++ b/src/include/krb5/krb5.hin -@@ -1915,6 +1915,7 @@ krb5_verify_checksum(krb5_context context, krb5_cksumtype ctype, - #define KRB5_AUTHDATA_SIGNTICKET 512 /**< formerly 142 in krb5 1.8 */ - #define KRB5_AUTHDATA_FX_ARMOR 71 - #define KRB5_AUTHDATA_AUTH_INDICATOR 97 -+#define KRB5_AUTHDATA_AP_OPTIONS 143 - /** @} */ /* end of KRB5_AUTHDATA group */ - - /* password change constants */ -diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index 9d3e2f4fe..175a24c4e 100644 ---- a/src/lib/gssapi/krb5/accept_sec_context.c -+++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -430,6 +430,32 @@ kg_process_extension(krb5_context context, - /* A zero-value channel binding, for comparison */ - static const uint8_t null_cb[CB_MD5_LEN]; - -+/* Look for AP_OPTIONS in authdata. If present and the options include -+ * KERB_AP_OPTIONS_CBT, set *cbt_out to true. */ -+static krb5_error_code -+check_cbt(krb5_context context, krb5_authdata **authdata, -+ krb5_boolean *cbt_out) -+{ -+ krb5_error_code code; -+ uint32_t ad_ap_options; -+ const uint32_t KERB_AP_OPTIONS_CBT = 0x4000; -+ -+ *cbt_out = FALSE; -+ -+ code = krb5_find_authdata(context, NULL, authdata, -+ KRB5_AUTHDATA_AP_OPTIONS, &authdata); -+ if (code || authdata == NULL) -+ return code; -+ if (authdata[1] != NULL || authdata[0]->length != 4) -+ return KRB5KRB_AP_ERR_MSG_TYPE; -+ -+ ad_ap_options = load_32_le(authdata[0]->contents); -+ if (ad_ap_options & KERB_AP_OPTIONS_CBT) -+ *cbt_out = TRUE; -+ -+ return 0; -+} -+ - /* - * The krb5 GSS mech appropriates the authenticator checksum field from RFC - * 4120 to store structured data instead of a checksum, indicated with checksum -@@ -454,7 +480,7 @@ process_checksum(OM_uint32 *minor_status, krb5_context context, - krb5_error_code code = 0; - OM_uint32 status, option_id, token_flags; - size_t cb_len, option_len; -- krb5_boolean valid, token_cb_present = FALSE, cb_match = FALSE; -+ krb5_boolean valid, client_cbt, token_cb_present = FALSE, cb_match = FALSE; - krb5_key subkey; - krb5_data option, empty = empty_data(); - krb5_checksum cb_cksum; -@@ -582,6 +608,23 @@ process_checksum(OM_uint32 *minor_status, krb5_context context, - } - } - -+ /* -+ * If the client asserts the KERB_AP_OPTIONS_CBT flag (from MS-KILE) in the -+ * authenticator authdata, and the acceptor passed channel bindings, -+ * require matching channel bindings from the client. The intent is to -+ * prevent an authenticator generated for use outside of a TLS channel from -+ * being used inside of one. -+ */ -+ code = check_cbt(context, authenticator->authorization_data, &client_cbt); -+ if (code) { -+ status = GSS_S_FAILURE; -+ goto fail; -+ } -+ if (client_cbt && acceptor_cb != GSS_C_NO_CHANNEL_BINDINGS && !cb_match) { -+ status = GSS_S_BAD_BINDINGS; -+ goto fail; -+ } -+ - status = GSS_S_COMPLETE; - - fail: diff --git a/Improve-KDC-alias-checking-for-S4U-requests.patch b/Improve-KDC-alias-checking-for-S4U-requests.patch deleted file mode 100644 index 69745de..0000000 --- a/Improve-KDC-alias-checking-for-S4U-requests.patch +++ /dev/null @@ -1,124 +0,0 @@ -From d80afa1396c3a6605338e4eaaf5bc44f8ad3eacc Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Fri, 4 Sep 2020 14:05:50 +0300 -Subject: [PATCH] Improve KDC alias checking for S4U requests - -When processing an S4U2Self request, check for DB aliases when -matching the TGT client against the request server. When processing -an S4U2Proxy request, check for DB aliases when matching the TGT -client against the evidence ticket server. - -[ghudson@mit.edu: minor edits; rewrote commit message] - -ticket: 8946 (new) -(cherry picked from commit 05deeebfc096970b5d9aa67a48b14106cf1b9b56) ---- - src/kdc/kdc_util.c | 74 ++++++++++++++++------------------------------ - 1 file changed, 25 insertions(+), 49 deletions(-) - -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index e3352f9cc..dcb2df8dc 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -1463,6 +1463,25 @@ cleanup: - return code; - } - -+/* Return true if princ canonicalizes to the same principal as canon. */ -+static krb5_boolean -+is_client_alias(krb5_context context, krb5_const_principal canon, -+ krb5_const_principal princ) -+{ -+ krb5_error_code ret; -+ krb5_db_entry *self; -+ krb5_boolean is_self = FALSE; -+ -+ ret = krb5_db_get_principal(context, princ, -+ KRB5_KDB_FLAG_CLIENT_REFERRALS_ONLY, &self); -+ if (!ret) { -+ is_self = krb5_principal_compare(context, canon, self->princ); -+ krb5_db_free_principal(context, self); -+ } -+ -+ return is_self; -+} -+ - /* - * Protocol transition (S4U2Self) - */ -@@ -1481,7 +1500,6 @@ kdc_process_s4u2self_req(kdc_realm_t *kdc_active_realm, - { - krb5_error_code code; - krb5_pa_data *pa_data; -- int flags; - krb5_db_entry *princ; - krb5_s4u_userid *id; - -@@ -1515,51 +1533,11 @@ kdc_process_s4u2self_req(kdc_realm_t *kdc_active_realm, - } - id = &(*s4u_x509_user)->user_id; - -- /* -- * We need to compare the client name in the TGT with the requested -- * server name. Supporting server name aliases without assuming a -- * global name service makes this difficult to do. -- * -- * The comparison below handles the following cases (note that the -- * term "principal name" below excludes the realm). -- * -- * (1) The requested service is a host-based service with two name -- * components, in which case we assume the principal name to -- * contain sufficient qualifying information. The realm is -- * ignored for the purpose of comparison. -- * -- * (2) The requested service name is an enterprise principal name: -- * the service principal name is compared with the unparsed -- * form of the client name (including its realm). -- * -- * (3) The requested service is some other name type: an exact -- * match is required. -- * -- * An alternative would be to look up the server once again with -- * FLAG_CANONICALIZE | FLAG_CLIENT_REFERRALS_ONLY set, do an exact -- * match between the returned name and client_princ. However, this -- * assumes that the client set FLAG_CANONICALIZE when requesting -- * the TGT and that we have a global name service. -- */ -- flags = 0; -- switch (krb5_princ_type(kdc_context, request->server)) { -- case KRB5_NT_SRV_HST: /* (1) */ -- if (krb5_princ_size(kdc_context, request->server) == 2) -- flags |= KRB5_PRINCIPAL_COMPARE_IGNORE_REALM; -- break; -- case KRB5_NT_ENTERPRISE_PRINCIPAL: /* (2) */ -- flags |= KRB5_PRINCIPAL_COMPARE_ENTERPRISE; -- break; -- default: /* (3) */ -- break; -- } -- -- if (!krb5_principal_compare_flags(kdc_context, -- request->server, -- client_princ, -- flags)) { -- *status = "INVALID_S4U2SELF_REQUEST"; -- return KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN; /* match Windows error code */ -+ /* If the server is local, check that the request is for self. */ -+ if (!isflagset(c_flags, KRB5_KDB_FLAG_ISSUING_REFERRAL) && -+ !is_client_alias(kdc_context, server->princ, client_princ)) { -+ *status = "INVALID_S4U2SELF_REQUEST_SERVER_MISMATCH"; -+ return KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN; /* match Windows error */ - } - - /* -@@ -1750,9 +1728,7 @@ kdc_process_s4u2proxy_req(kdc_realm_t *kdc_active_realm, unsigned int flags, - } - - client_princ = *stkt_authdata_client; -- } else if (!krb5_principal_compare(kdc_context, -- server->princ, /* after canon */ -- server_princ)) { -+ } else if (!is_client_alias(kdc_context, server->princ, server_princ)) { - *status = "EVIDENCE_TICKET_MISMATCH"; - return KRB5KDC_ERR_SERVER_NOMATCH; - } diff --git a/Improve-negoex_parse_token-code-hygiene.patch b/Improve-negoex_parse_token-code-hygiene.patch deleted file mode 100644 index d2b94aa..0000000 --- a/Improve-negoex_parse_token-code-hygiene.patch +++ /dev/null @@ -1,30 +0,0 @@ -From 9596a341d99e3af1438ad215ed0fb5496cb59ff0 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 9 Jun 2020 16:23:37 -0400 -Subject: [PATCH] Improve negoex_parse_token() code hygiene - -If the while loop in negoex_parse_token() runs for zero iterations, -major will be used initialized. Currently this cannot happen, but -only because both of the call sites check for zero-length tokens. -Initialize major for safety. - -[ghudson@mit.edu: rewrote commit message] - -(cherry picked from commit 4f91b6f8fa6fe1de662b3fdac0d59b7758ec642a) ---- - src/lib/gssapi/spnego/negoex_util.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/lib/gssapi/spnego/negoex_util.c b/src/lib/gssapi/spnego/negoex_util.c -index 700368456..99580fd79 100644 ---- a/src/lib/gssapi/spnego/negoex_util.c -+++ b/src/lib/gssapi/spnego/negoex_util.c -@@ -454,7 +454,7 @@ negoex_parse_token(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, - gss_const_buffer_t token, - struct negoex_message **messages_out, size_t *count_out) - { -- OM_uint32 major; -+ OM_uint32 major = GSS_S_COMPLETE; - size_t count = 0; - struct k5input in; - struct negoex_message *messages = NULL, *newptr; diff --git a/Install-shared-libraries-as-executable.patch b/Install-shared-libraries-as-executable.patch deleted file mode 100644 index b8adf3d..0000000 --- a/Install-shared-libraries-as-executable.patch +++ /dev/null @@ -1,42 +0,0 @@ -From b3c6667d7f98cf0347642c7927618fd40cd6f904 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:45:26 -0400 -Subject: [PATCH] Install shared libraries as executable - -RPM expects this behavior, and systems with contrary policies (like -Debian) address permissions at the packaging layer. Most other build -systems appear to install shared libraries as executable. - -[ghudson@mit.edu: edited commit message] - -ticket: 8965 (new) -(cherry picked from commit 1bc5f76d2e7013b8771e3bd9960c82642ba0b467) ---- - src/config/shlib.conf | 7 ++++--- - 1 file changed, 4 insertions(+), 3 deletions(-) - -diff --git a/src/config/shlib.conf b/src/config/shlib.conf -index 3e4af6c02..75b7cc3af 100644 ---- a/src/config/shlib.conf -+++ b/src/config/shlib.conf -@@ -22,8 +22,10 @@ SHLIBVEXT=.so.v-nobuild - SHLIBSEXT=.so.s-nobuild - # Most systems support profiled libraries. - PFLIBEXT=_p.a --# Most systems install shared libs as mode 644, etc. while hpux wants 755 --INSTALL_SHLIB='$(INSTALL_DATA)' -+# Install libraries executable. Some systems (e.g., RPM-based ones) require -+# this for package dependency generation, while others are ambivalent or will -+# strip it during packaging. -+INSTALL_SHLIB='$(INSTALL)' - # Most systems use the same objects for shared libraries and dynamically - # loadable objects. - DYNOBJEXT='$(SHLIBEXT)' -@@ -118,7 +120,6 @@ alpha*-dec-osf*) - # -O +dpv should display any routines eliminated as unused, but -b - # apparently turns that off - *-*-hpux*) -- INSTALL_SHLIB='$(INSTALL)' - case $host_cpu in - hppa*) - SHLIBEXT=.sl diff --git a/Minimize-usage-of-tgs_server-in-KDC.patch b/Minimize-usage-of-tgs_server-in-KDC.patch deleted file mode 100644 index 01608e8..0000000 --- a/Minimize-usage-of-tgs_server-in-KDC.patch +++ /dev/null @@ -1,316 +0,0 @@ -From 6e82fd67034eef7f99b901f417782a3786a02069 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 25 Sep 2020 11:12:34 -0400 -Subject: [PATCH] Minimize usage of tgs_server in KDC - -Where possible, use the realm of the request server principal -(canonicalized via KDB lookup, if available) in preference to -tgs_server. This change facilitates alias realm support and potential -future support for serving multiple realms from the same KDB. - -S4U2Self local user testing currently uses the uncanonicalized request -realm after this change, which will require attention for alias realm -support. - -FAST armor ticket checking is unaffected by this change (it still -compares against tgs_server). This check poses no issue for realm -aliases, as both tgs_server and the armor ticket server should have -canonical realms, but it will require attention for multi-realm KDB -support. - -Remove is_local_principal() as it is no longer used. Add an -is_local_tgs_principal() helper and shorten is_cross_tgs_principal(). - -Move the header ticket lineage check from kdc_process_tgs_req() to -process_tgs_req(), where we have the canonical request server name and -a more natural indication of whether the request was an S4U2Self -request. - -(cherry picked from commit 90fedf8188fc47aa5a476a969af34671555df389) ---- - src/kdc/do_as_req.c | 21 ++++++-------- - src/kdc/do_tgs_req.c | 16 ++++++++--- - src/kdc/kdc_util.c | 68 ++++++++++---------------------------------- - src/kdc/kdc_util.h | 3 +- - src/kdc/tgs_policy.c | 16 ++++++----- - 5 files changed, 46 insertions(+), 78 deletions(-) - -diff --git a/src/kdc/do_as_req.c b/src/kdc/do_as_req.c -index c2dfea9b8..e0ac33649 100644 ---- a/src/kdc/do_as_req.c -+++ b/src/kdc/do_as_req.c -@@ -620,18 +620,6 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, - } - state->rock.client = state->client; - -- /* -- * If the backend returned a principal that is not in the local -- * realm, then we need to refer the client to that realm. -- */ -- if (!is_local_principal(kdc_active_realm, state->client->princ)) { -- /* Entry is a referral to another realm */ -- state->status = "REFERRAL"; -- au_state->cl_realm = &state->client->princ->realm; -- errcode = KRB5KDC_ERR_WRONG_REALM; -- goto errout; -- } -- - au_state->stage = SRVC_PRINC; - - s_flags = 0; -@@ -651,6 +639,15 @@ process_as_req(krb5_kdc_req *request, krb5_data *req_pkt, - goto errout; - } - -+ /* If the KDB module returned a different realm for the client and server, -+ * we need to issue a client realm referral. */ -+ if (!data_eq(state->server->princ->realm, state->client->princ->realm)) { -+ state->status = "REFERRAL"; -+ au_state->cl_realm = &state->client->princ->realm; -+ errcode = KRB5KDC_ERR_WRONG_REALM; -+ goto errout; -+ } -+ - errcode = get_local_tgt(kdc_context, &state->request->server->realm, - state->server, &state->local_tgt, - &state->local_tgt_storage, &state->local_tgt_key); -diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c -index d345797c4..8ea418e43 100644 ---- a/src/kdc/do_tgs_req.c -+++ b/src/kdc/do_tgs_req.c -@@ -268,7 +268,7 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, - goto cleanup; - } - -- if (!is_local_principal(kdc_active_realm, header_ticket->server)) -+ if (!data_eq(header_server->princ->realm, sprinc->realm)) - setflag(c_flags, KRB5_KDB_FLAG_CROSS_REALM); - if (is_referral) - setflag(c_flags, KRB5_KDB_FLAG_ISSUING_REFERRAL); -@@ -295,6 +295,15 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, - au_state->s4u2self_user = NULL; - } - -+ /* Aside from cross-realm S4U2Self requests, do not accept header tickets -+ * for local users issued by foreign realms. */ -+ if (s4u_x509_user == NULL && data_eq(cprinc->realm, sprinc->realm) && -+ isflagset(c_flags, KRB5_KDB_FLAG_CROSS_REALM)) { -+ krb5_klog_syslog(LOG_INFO, _("PROCESS_TGS: failed lineage check")); -+ retval = KRB5KDC_ERR_POLICY; -+ goto cleanup; -+ } -+ - if (errcode) - goto cleanup; - -@@ -583,13 +592,12 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, - - /* - * Only add the realm of the presented tgt to the transited list if -- * it is different than the local realm (cross-realm) and it is different -+ * it is different than the server realm (cross-realm) and it is different - * than the realm of the client (since the realm of the client is already - * implicitly part of the transited list and should not be explicitly - * listed). - */ -- /* realm compare is like strcmp, but knows how to deal with these args */ -- if (krb5_realm_compare(kdc_context, header_ticket->server, tgs_server) || -+ if (!isflagset(c_flags, KRB5_KDB_FLAG_CROSS_REALM) || - krb5_realm_compare(kdc_context, header_ticket->server, - enc_tkt_reply.client)) { - /* tgt issued by local realm or issued by realm of client */ -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index b2042862a..e0b65a87c 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -78,12 +78,6 @@ static krb5_error_code find_server_key(krb5_context, - krb5_kvno, krb5_keyblock **, - krb5_kvno *); - --krb5_boolean --is_local_principal(kdc_realm_t *kdc_active_realm, krb5_const_principal princ1) --{ -- return krb5_realm_compare(kdc_context, princ1, tgs_server); --} -- - /* - * Returns TRUE if the kerberos principal is the name of a Kerberos ticket - * service. -@@ -104,13 +98,16 @@ krb5_is_tgs_principal(krb5_const_principal principal) - krb5_boolean - is_cross_tgs_principal(krb5_const_principal principal) - { -- if (!krb5_is_tgs_principal(principal)) -- return FALSE; -- if (!data_eq(*krb5_princ_component(kdc_context, principal, 1), -- *krb5_princ_realm(kdc_context, principal))) -- return TRUE; -- else -- return FALSE; -+ return krb5_is_tgs_principal(principal) && -+ !data_eq(principal->data[1], principal->realm); -+} -+ -+/* Return true if princ is the name of a local TGS for any realm. */ -+krb5_boolean -+is_local_tgs_principal(krb5_const_principal principal) -+{ -+ return krb5_is_tgs_principal(principal) && -+ data_eq(principal->data[1], principal->realm); - } - - /* -@@ -143,17 +140,6 @@ comp_cksum(krb5_context kcontext, krb5_data *source, krb5_ticket *ticket, - return(0); - } - --/* Return true if padata contains an entry of either S4U2Self type. */ --static inline krb5_boolean --has_s4u2self_padata(krb5_pa_data **padata) --{ -- if (krb5int_find_pa_data(NULL, padata, KRB5_PADATA_FOR_USER) != NULL) -- return TRUE; -- if (krb5int_find_pa_data(NULL, padata, KRB5_PADATA_S4U_X509_USER) != NULL) -- return TRUE; -- return FALSE; --} -- - /* If a header ticket is decrypted, *ticket_out is filled in even on error. */ - krb5_error_code - kdc_process_tgs_req(kdc_realm_t *kdc_active_realm, -@@ -170,7 +156,6 @@ kdc_process_tgs_req(kdc_realm_t *kdc_active_realm, - krb5_authdata **authdata = NULL; - krb5_data scratch1; - krb5_data * scratch = NULL; -- krb5_boolean foreign_server = FALSE; - krb5_auth_context auth_context = NULL; - krb5_authenticator * authenticator = NULL; - krb5_checksum * his_cksum = NULL; -@@ -199,19 +184,6 @@ kdc_process_tgs_req(kdc_realm_t *kdc_active_realm, - goto cleanup; - } - -- /* If the "server" principal in the ticket is not something -- in the local realm, then we must refuse to service the request -- if the client claims to be from the local realm. -- -- If we don't do this, then some other realm's nasty KDC can -- claim to be authenticating a client from our realm, and we'll -- give out tickets concurring with it! -- -- we set a flag here for checking below. -- */ -- foreign_server = !is_local_principal(kdc_active_realm, -- apreq->ticket->server); -- - if ((retval = krb5_auth_con_init(kdc_context, &auth_context))) - goto cleanup; - -@@ -265,15 +237,6 @@ kdc_process_tgs_req(kdc_realm_t *kdc_active_realm, - goto cleanup_authenticator; - } - -- /* make sure the client is of proper lineage (see above) */ -- if (foreign_server && !has_s4u2self_padata(request->padata) && -- is_local_principal(kdc_active_realm, ticket->enc_part2->client)) { -- /* someone in a foreign realm claiming to be local */ -- krb5_klog_syslog(LOG_INFO, _("PROCESS_TGS: failed lineage check")); -- retval = KRB5KDC_ERR_POLICY; -- goto cleanup_authenticator; -- } -- - /* - * Check application checksum vs. tgs request - * -@@ -591,12 +554,12 @@ int - check_anon(kdc_realm_t *kdc_active_realm, - krb5_principal client, krb5_principal server) - { -- /* If restrict_anon is set, reject requests from anonymous to principals -- * other than the local TGT. */ -+ /* If restrict_anon is set, reject requests from anonymous clients to -+ * server principals other than local TGTs. */ - if (kdc_active_realm->realm_restrict_anon && - krb5_principal_compare_any_realm(kdc_context, client, - krb5_anonymous_principal()) && -- !krb5_principal_compare(kdc_context, server, tgs_server)) -+ !is_local_tgs_principal(server)) - return -1; - return 0; - } -@@ -1527,7 +1490,7 @@ kdc_process_s4u2self_req(kdc_realm_t *kdc_active_realm, - /* - * Do not attempt to lookup principals in foreign realms. - */ -- if (is_local_principal(kdc_active_realm, id->user)) { -+ if (data_eq(server->princ->realm, id->user->realm)) { - krb5_db_entry no_server; - krb5_pa_data **e_data = NULL; - -@@ -1663,8 +1626,7 @@ kdc_process_s4u2proxy_req(kdc_realm_t *kdc_active_realm, unsigned int flags, - */ - if (isflagset(flags, KRB5_KDB_FLAG_ISSUING_REFERRAL) || - !is_cross_tgs_principal(server->princ) || -- !krb5_principal_compare_any_realm(kdc_context, server->princ, -- tgs_server) || -+ !data_eq(server->princ->data[1], proxy->princ->realm) || - !krb5_principal_compare(kdc_context, client_princ, server_princ)) { - *status = "XREALM_EVIDENCE_TICKET_MISMATCH"; - return KRB5KDC_ERR_BADOPTION; -diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index 04007a8f5..a6bac4388 100644 ---- a/src/kdc/kdc_util.h -+++ b/src/kdc/kdc_util.h -@@ -37,10 +37,9 @@ - #include "reqstate.h" - - krb5_error_code check_hot_list (krb5_ticket *); --krb5_boolean is_local_principal(kdc_realm_t *kdc_active_realm, -- krb5_const_principal princ1); - krb5_boolean krb5_is_tgs_principal (krb5_const_principal); - krb5_boolean is_cross_tgs_principal(krb5_const_principal); -+krb5_boolean is_local_tgs_principal(krb5_const_principal); - krb5_error_code - add_to_transited (krb5_data *, - krb5_data *, -diff --git a/src/kdc/tgs_policy.c b/src/kdc/tgs_policy.c -index 3f4fa8499..a5a00f0cc 100644 ---- a/src/kdc/tgs_policy.c -+++ b/src/kdc/tgs_policy.c -@@ -252,19 +252,21 @@ check_tgs_s4u2proxy(kdc_realm_t *kdc_active_realm, - } - - static int --check_tgs_u2u(kdc_realm_t *kdc_active_realm, -- krb5_kdc_req *req, const char **status) -+check_tgs_u2u(kdc_realm_t *kdc_active_realm, krb5_kdc_req *req, -+ krb5_const_principal server_princ, const char **status) - { -+ krb5_const_principal second_server_princ; -+ - if (req->kdc_options & KDC_OPT_ENC_TKT_IN_SKEY) { - /* Check that second ticket is in request. */ - if (!req->second_ticket || !req->second_ticket[0]) { - *status = "NO_2ND_TKT"; - return KDC_ERR_BADOPTION; - } -- /* Check that second ticket is a TGT. */ -- if (!krb5_principal_compare(kdc_context, -- req->second_ticket[0]->server, -- tgs_server)) { -+ /* Check that second ticket is a TGT to the server realm. */ -+ second_server_princ = req->second_ticket[0]->server; -+ if (!is_local_tgs_principal(second_server_princ) || -+ !data_eq(second_server_princ->data[1], server_princ->realm)) { - *status = "2ND_TKT_NOT_TGS"; - return KDC_ERR_POLICY; - } -@@ -353,7 +355,7 @@ validate_tgs_request(kdc_realm_t *kdc_active_realm, - return(KRB_AP_ERR_REPEAT); - } - -- errcode = check_tgs_u2u(kdc_active_realm, request, status); -+ errcode = check_tgs_u2u(kdc_active_realm, request, server->princ, status); - if (errcode != 0) - return errcode; - diff --git a/Omit-KDC-indicator-check-for-S4U2Self-requests.patch b/Omit-KDC-indicator-check-for-S4U2Self-requests.patch deleted file mode 100644 index 9e25d54..0000000 --- a/Omit-KDC-indicator-check-for-S4U2Self-requests.patch +++ /dev/null @@ -1,48 +0,0 @@ -From cd99c7829a43074cec8afe5c7021778a5a2ebd31 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 6 May 2020 16:03:13 -0400 -Subject: [PATCH] Omit KDC indicator check for S4U2Self requests - -As there was no initial ticket exchange from the client for an -S4U2Self request, the auth indicator check is inapplicable (and would -always fail if any auth indicators are required). - -ticket: 8902 (new) -(cherry picked from commit 183631fbf72351c2d5fc7d60b2d9fc4d09fe7465) ---- - src/kdc/do_tgs_req.c | 14 +++++++------- - 1 file changed, 7 insertions(+), 7 deletions(-) - -diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c -index 241f34e2a..463a9c0dd 100644 ---- a/src/kdc/do_tgs_req.c -+++ b/src/kdc/do_tgs_req.c -@@ -392,8 +392,8 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, - } - authtime = subject_tkt->times.authtime; - -- /* Extract auth indicators from the subject ticket, except for S4U2Self -- * requests (where the client didn't authenticate). */ -+ /* Extract and check auth indicators from the subject ticket, except for -+ * S4U2Self requests (where the client didn't authenticate). */ - if (s4u_x509_user == NULL) { - errcode = get_auth_indicators(kdc_context, subject_tkt, local_tgt, - &local_tgt_key, &auth_indicators); -@@ -401,12 +401,12 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, - status = "GET_AUTH_INDICATORS"; - goto cleanup; - } -- } - -- errcode = check_indicators(kdc_context, server, auth_indicators); -- if (errcode) { -- status = "HIGHER_AUTHENTICATION_REQUIRED"; -- goto cleanup; -+ errcode = check_indicators(kdc_context, server, auth_indicators); -+ if (errcode) { -+ status = "HIGHER_AUTHENTICATION_REQUIRED"; -+ goto cleanup; -+ } - } - - if (is_referral) diff --git a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch b/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch deleted file mode 100644 index 5fd221e..0000000 --- a/Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch +++ /dev/null @@ -1,34 +0,0 @@ -From 6b81d2d9913d91a4cc48d04f123fc71cc1022432 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Sat, 6 Jun 2020 11:03:37 +0200 -Subject: [PATCH] Omit PA_FOR_USER if we can't compute its checksum - -OpenSSL in FIPS mode will refuse to perform hmac-md5. Omit the legacy -PA_FOR_USER element in this case rather than failing out. - -[ghudson@mit.edu: minor code and comment edits; wrote commit message] - -ticket: 8912 (new) -(cherry picked from commit 03f122bdb22cfa53c7d855ed929c9541e56365e0) ---- - src/lib/krb5/krb/s4u_creds.c | 7 +++++++ - 1 file changed, 7 insertions(+) - -diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c -index fc5c886d6..d8f486dc6 100644 ---- a/src/lib/krb5/krb/s4u_creds.c -+++ b/src/lib/krb5/krb/s4u_creds.c -@@ -534,6 +534,13 @@ krb5_get_self_cred_from_kdc(krb5_context context, - if (s4u_user.user_id.user != NULL && s4u_user.user_id.user->length) { - code = build_pa_for_user(context, tgtptr, &s4u_user.user_id, - &in_padata[1]); -+ /* -+ * If we couldn't compute the hmac-md5 checksum, send only the -+ * KRB5_PADATA_S4U_X509_USER; this will still work against modern -+ * Windows and MIT KDCs. -+ */ -+ if (code == KRB5_CRYPTO_INTERNAL) -+ code = 0; - if (code != 0) { - krb5_free_pa_data(context, in_padata); - goto cleanup; diff --git a/Pass-channel-bindings-through-SPNEGO.patch b/Pass-channel-bindings-through-SPNEGO.patch deleted file mode 100644 index 1b3c130..0000000 --- a/Pass-channel-bindings-through-SPNEGO.patch +++ /dev/null @@ -1,256 +0,0 @@ -From a5588aae21d44f5a6eed4bdfeae992a709b92959 Mon Sep 17 00:00:00 2001 -From: Isaac Boukris -Date: Tue, 28 Apr 2020 18:15:55 +0200 -Subject: [PATCH] Pass channel bindings through SPNEGO - -ticket: 8907 (new) -(cherry picked from commit d16325a24c34ec9a5f6fb4910987f162e0d4d9cd) ---- - src/lib/gssapi/spnego/gssapiP_negoex.h | 8 ++--- - src/lib/gssapi/spnego/negoex_ctx.c | 34 +++++++++++---------- - src/lib/gssapi/spnego/spnego_mech.c | 41 +++++++++++++------------- - 3 files changed, 43 insertions(+), 40 deletions(-) - -diff --git a/src/lib/gssapi/spnego/gssapiP_negoex.h b/src/lib/gssapi/spnego/gssapiP_negoex.h -index 44b08f523..489ab7c42 100644 ---- a/src/lib/gssapi/spnego/gssapiP_negoex.h -+++ b/src/lib/gssapi/spnego/gssapiP_negoex.h -@@ -201,10 +201,10 @@ negoex_restrict_auth_schemes(spnego_gss_ctx_id_t ctx, - OM_uint32 - negoex_init(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, - gss_name_t target_name, OM_uint32 req_flags, OM_uint32 time_req, -- gss_buffer_t input_token, gss_buffer_t output_token, -- OM_uint32 *time_rec); -+ gss_buffer_t input_token, gss_channel_bindings_t bindings, -+ gss_buffer_t output_token, OM_uint32 *time_rec); - - OM_uint32 - negoex_accept(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, -- gss_buffer_t input_token, gss_buffer_t output_token, -- OM_uint32 *time_rec); -+ gss_buffer_t input_token, gss_channel_bindings_t bindings, -+ gss_buffer_t output_token, OM_uint32 *time_rec); -diff --git a/src/lib/gssapi/spnego/negoex_ctx.c b/src/lib/gssapi/spnego/negoex_ctx.c -index 18d9d4147..8848ee4db 100644 ---- a/src/lib/gssapi/spnego/negoex_ctx.c -+++ b/src/lib/gssapi/spnego/negoex_ctx.c -@@ -276,7 +276,8 @@ static OM_uint32 - mech_init(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, - gss_name_t target, OM_uint32 req_flags, OM_uint32 time_req, - struct negoex_message *messages, size_t nmessages, -- gss_buffer_t output_token, OM_uint32 *time_rec) -+ gss_channel_bindings_t bindings, gss_buffer_t output_token, -+ OM_uint32 *time_rec) - { - OM_uint32 major, first_major = 0, first_minor = 0; - struct negoex_auth_mech *mech = NULL; -@@ -316,10 +317,9 @@ mech_init(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, - mech = K5_TAILQ_FIRST(&ctx->negoex_mechs); - - major = gss_init_sec_context(minor, cred, &mech->mech_context, target, -- mech->oid, req_flags, time_req, -- GSS_C_NO_CHANNEL_BINDINGS, input_token, -- &ctx->actual_mech, output_token, -- &ctx->ctx_flags, time_rec); -+ mech->oid, req_flags, time_req, bindings, -+ input_token, &ctx->actual_mech, -+ output_token, &ctx->ctx_flags, time_rec); - - if (major == GSS_S_COMPLETE) - mech->complete = 1; -@@ -351,7 +351,8 @@ mech_init(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, - static OM_uint32 - mech_accept(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, - gss_cred_id_t cred, struct negoex_message *messages, -- size_t nmessages, gss_buffer_t output_token, OM_uint32 *time_rec) -+ size_t nmessages, gss_channel_bindings_t bindings, -+ gss_buffer_t output_token, OM_uint32 *time_rec) - { - OM_uint32 major, tmpmin; - struct negoex_auth_mech *mech; -@@ -395,10 +396,10 @@ mech_accept(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, - gss_release_cred(&tmpmin, &ctx->deleg_cred); - - major = gss_accept_sec_context(minor, &mech->mech_context, cred, -- &msg->token, GSS_C_NO_CHANNEL_BINDINGS, -- &ctx->internal_name, &ctx->actual_mech, -- output_token, &ctx->ctx_flags, -- time_rec, &ctx->deleg_cred); -+ &msg->token, bindings, &ctx->internal_name, -+ &ctx->actual_mech, output_token, -+ &ctx->ctx_flags, time_rec, -+ &ctx->deleg_cred); - - if (major == GSS_S_COMPLETE) - mech->complete = 1; -@@ -609,8 +610,8 @@ make_output_token(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, - OM_uint32 - negoex_init(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, - gss_name_t target_name, OM_uint32 req_flags, OM_uint32 time_req, -- gss_buffer_t input_token, gss_buffer_t output_token, -- OM_uint32 *time_rec) -+ gss_buffer_t input_token, gss_channel_bindings_t bindings, -+ gss_buffer_t output_token, OM_uint32 *time_rec) - { - OM_uint32 major, tmpmin; - gss_buffer_desc mech_output_token = GSS_C_EMPTY_BUFFER; -@@ -663,7 +664,8 @@ negoex_init(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, - /* Process the input token and/or produce an output token. This may prune - * the mech list, but on success there will be at least one mech entry. */ - major = mech_init(minor, ctx, cred, target_name, req_flags, time_req, -- messages, nmessages, &mech_output_token, time_rec); -+ messages, nmessages, bindings, &mech_output_token, -+ time_rec); - if (major != GSS_S_COMPLETE) - goto cleanup; - assert(!K5_TAILQ_EMPTY(&ctx->negoex_mechs)); -@@ -701,8 +703,8 @@ cleanup: - - OM_uint32 - negoex_accept(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, -- gss_buffer_t input_token, gss_buffer_t output_token, -- OM_uint32 *time_rec) -+ gss_buffer_t input_token, gss_channel_bindings_t bindings, -+ gss_buffer_t output_token, OM_uint32 *time_rec) - { - OM_uint32 major, tmpmin; - gss_buffer_desc mech_output_token = GSS_C_EMPTY_BUFFER; -@@ -754,7 +756,7 @@ negoex_accept(OM_uint32 *minor, spnego_gss_ctx_id_t ctx, gss_cred_id_t cred, - * prune the list to a single mech. Continue on error if an output token - * is generated, so that we send the token to the initiator. - */ -- major = mech_accept(minor, ctx, cred, messages, nmessages, -+ major = mech_accept(minor, ctx, cred, messages, nmessages, bindings, - &mech_output_token, time_rec); - if (major != GSS_S_COMPLETE && mech_output_token.length == 0) - goto cleanup; -diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/spnego/spnego_mech.c -index f4a042478..2327cd927 100644 ---- a/src/lib/gssapi/spnego/spnego_mech.c -+++ b/src/lib/gssapi/spnego/spnego_mech.c -@@ -130,6 +130,7 @@ init_ctx_reselect(OM_uint32 *, spnego_gss_ctx_id_t, OM_uint32, - static OM_uint32 - init_ctx_call_init(OM_uint32 *, spnego_gss_ctx_id_t, spnego_gss_cred_id_t, - OM_uint32, gss_name_t, OM_uint32, OM_uint32, gss_buffer_t, -+ gss_channel_bindings_t, - gss_buffer_t, OM_uint32 *, send_token_flag *); - - static OM_uint32 -@@ -144,8 +145,8 @@ acc_ctx_vfy_oid(OM_uint32 *, spnego_gss_ctx_id_t, gss_OID, - OM_uint32 *, send_token_flag *); - static OM_uint32 - acc_ctx_call_acc(OM_uint32 *, spnego_gss_ctx_id_t, spnego_gss_cred_id_t, -- gss_buffer_t, gss_buffer_t, OM_uint32 *, OM_uint32 *, -- send_token_flag *); -+ gss_buffer_t, gss_channel_bindings_t, gss_buffer_t, -+ OM_uint32 *, OM_uint32 *, send_token_flag *); - - static gss_OID - negotiate_mech(spnego_gss_ctx_id_t, gss_OID_set, OM_uint32 *); -@@ -906,6 +907,7 @@ init_ctx_call_init(OM_uint32 *minor_status, - OM_uint32 req_flags, - OM_uint32 time_req, - gss_buffer_t mechtok_in, -+ gss_channel_bindings_t bindings, - gss_buffer_t mechtok_out, - OM_uint32 *time_rec, - send_token_flag *send_token) -@@ -922,15 +924,14 @@ init_ctx_call_init(OM_uint32 *minor_status, - if (gss_oid_equal(sc->internal_mech, &negoex_mech)) { - ret = negoex_init(minor_status, sc, mcred, target_name, - mech_req_flags, time_req, mechtok_in, -- mechtok_out, time_rec); -+ bindings, mechtok_out, time_rec); - } else { - ret = gss_init_sec_context(minor_status, mcred, - &sc->ctx_handle, target_name, - sc->internal_mech, mech_req_flags, -- time_req, GSS_C_NO_CHANNEL_BINDINGS, -- mechtok_in, &sc->actual_mech, -- mechtok_out, &sc->ctx_flags, -- time_rec); -+ time_req, bindings, mechtok_in, -+ &sc->actual_mech, mechtok_out, -+ &sc->ctx_flags, time_rec); - } - - /* Bail out if the acceptor gave us an error token but the mech didn't -@@ -982,8 +983,8 @@ init_ctx_call_init(OM_uint32 *minor_status, - gss_delete_sec_context(&tmpmin, &sc->ctx_handle, GSS_C_NO_BUFFER); - tmpret = init_ctx_call_init(&tmpmin, sc, spcred, acc_negState, - target_name, req_flags, time_req, -- mechtok_in, mechtok_out, time_rec, -- send_token); -+ mechtok_in, bindings, mechtok_out, -+ time_rec, send_token); - if (HARD_ERROR(tmpret)) - goto fail; - *minor_status = tmpmin; -@@ -1005,7 +1006,7 @@ spnego_gss_init_sec_context( - gss_OID mech_type, - OM_uint32 req_flags, - OM_uint32 time_req, -- gss_channel_bindings_t input_chan_bindings, -+ gss_channel_bindings_t bindings, - gss_buffer_t input_token, - gss_OID *actual_mech, - gss_buffer_t output_token, -@@ -1085,8 +1086,8 @@ spnego_gss_init_sec_context( - if (!spnego_ctx->mech_complete) { - ret = init_ctx_call_init(minor_status, spnego_ctx, spcred, - acc_negState, target_name, req_flags, -- time_req, mechtok_in, &mechtok_out, -- time_rec, &send_token); -+ time_req, mechtok_in, bindings, -+ &mechtok_out, time_rec, &send_token); - if (ret != GSS_S_COMPLETE) - goto cleanup; - -@@ -1543,8 +1544,9 @@ cleanup: - static OM_uint32 - acc_ctx_call_acc(OM_uint32 *minor_status, spnego_gss_ctx_id_t sc, - spnego_gss_cred_id_t spcred, gss_buffer_t mechtok_in, -- gss_buffer_t mechtok_out, OM_uint32 *time_rec, -- OM_uint32 *negState, send_token_flag *tokflag) -+ gss_channel_bindings_t bindings, gss_buffer_t mechtok_out, -+ OM_uint32 *time_rec, OM_uint32 *negState, -+ send_token_flag *tokflag) - { - OM_uint32 ret, tmpmin; - gss_OID_desc mechoid; -@@ -1569,13 +1571,12 @@ acc_ctx_call_acc(OM_uint32 *minor_status, spnego_gss_ctx_id_t sc, - mcred = (spcred == NULL) ? GSS_C_NO_CREDENTIAL : spcred->mcred; - if (negoex) { - ret = negoex_accept(minor_status, sc, mcred, mechtok_in, -- mechtok_out, time_rec); -+ bindings, mechtok_out, time_rec); - } else { - (void) gss_release_name(&tmpmin, &sc->internal_name); - (void) gss_release_cred(&tmpmin, &sc->deleg_cred); - ret = gss_accept_sec_context(minor_status, &sc->ctx_handle, -- mcred, mechtok_in, -- GSS_C_NO_CHANNEL_BINDINGS, -+ mcred, mechtok_in, bindings, - &sc->internal_name, - &sc->actual_mech, mechtok_out, - &sc->ctx_flags, time_rec, -@@ -1621,7 +1622,7 @@ spnego_gss_accept_sec_context( - gss_ctx_id_t *context_handle, - gss_cred_id_t verifier_cred_handle, - gss_buffer_t input_token, -- gss_channel_bindings_t input_chan_bindings, -+ gss_channel_bindings_t bindings, - gss_name_t *src_name, - gss_OID *mech_type, - gss_buffer_t output_token, -@@ -1735,8 +1736,8 @@ spnego_gss_accept_sec_context( - */ - if (negState != REQUEST_MIC && mechtok_in != GSS_C_NO_BUFFER) { - ret = acc_ctx_call_acc(minor_status, sc, spcred, mechtok_in, -- &mechtok_out, time_rec, &negState, -- &return_token); -+ bindings, &mechtok_out, time_rec, -+ &negState, &return_token); - } - - /* Step 3: process or generate the MIC, if the negotiated mech is diff --git a/Pass-gss_localname-through-SPNEGO.patch b/Pass-gss_localname-through-SPNEGO.patch deleted file mode 100644 index 1aad597..0000000 --- a/Pass-gss_localname-through-SPNEGO.patch +++ /dev/null @@ -1,58 +0,0 @@ -From 723f4c746293f064a32961ad77b57f901dd54a67 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sun, 26 Apr 2020 19:55:54 -0400 -Subject: [PATCH] Pass gss_localname() through SPNEGO - -ticket: 8897 (new) -(cherry picked from commit f7b8a6432bd289bdc528017be122305f95b8e285) ---- - src/lib/gssapi/spnego/gssapiP_spnego.h | 8 ++++++++ - src/lib/gssapi/spnego/spnego_mech.c | 9 ++++++++- - 2 files changed, 16 insertions(+), 1 deletion(-) - -diff --git a/src/lib/gssapi/spnego/gssapiP_spnego.h b/src/lib/gssapi/spnego/gssapiP_spnego.h -index a93763314..066ec736f 100644 ---- a/src/lib/gssapi/spnego/gssapiP_spnego.h -+++ b/src/lib/gssapi/spnego/gssapiP_spnego.h -@@ -357,6 +357,14 @@ OM_uint32 KRB5_CALLCONV spnego_gss_wrap_size_limit - OM_uint32 *max_input_size - ); - -+OM_uint32 KRB5_CALLCONV spnego_gss_localname -+( -+ OM_uint32 *minor_status, -+ const gss_name_t pname, -+ const gss_const_OID mech_type, -+ gss_buffer_t localname -+); -+ - OM_uint32 KRB5_CALLCONV spnego_gss_get_mic - ( - OM_uint32 *minor_status, -diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/spnego/spnego_mech.c -index b3010c201..f4a042478 100644 ---- a/src/lib/gssapi/spnego/spnego_mech.c -+++ b/src/lib/gssapi/spnego/spnego_mech.c -@@ -237,7 +237,7 @@ static struct gss_config spnego_mechanism = - spnego_gss_inquire_context, /* gss_inquire_context */ - NULL, /* gss_internal_release_oid */ - spnego_gss_wrap_size_limit, /* gss_wrap_size_limit */ -- NULL, /* gssd_pname_to_uid */ -+ spnego_gss_localname, - NULL, /* gss_userok */ - NULL, /* gss_export_name */ - spnego_gss_duplicate_name, /* gss_duplicate_name */ -@@ -2372,6 +2372,13 @@ spnego_gss_wrap_size_limit( - return (ret); - } - -+OM_uint32 KRB5_CALLCONV -+spnego_gss_localname(OM_uint32 *minor_status, const gss_name_t pname, -+ const gss_const_OID mech_type, gss_buffer_t localname) -+{ -+ return gss_localname(minor_status, pname, GSS_C_NO_OID, localname); -+} -+ - OM_uint32 KRB5_CALLCONV - spnego_gss_get_mic( - OM_uint32 *minor_status, diff --git a/Refactor-KDC-authdata-list-management-helpers.patch b/Refactor-KDC-authdata-list-management-helpers.patch deleted file mode 100644 index 69ef109..0000000 --- a/Refactor-KDC-authdata-list-management-helpers.patch +++ /dev/null @@ -1,335 +0,0 @@ -From 17093468190706e241d2a6ef2bb5607be7021640 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 5 Feb 2020 18:46:11 -0500 -Subject: [PATCH] Refactor KDC authdata list management helpers - -Remove the unused concat_authorization_data(). Split merge_authdata() -into two helpers, one to destructively merge without filtering and one -to add copied elements while filtering out KDC-only authdata types. -Remove context parameters where they aren't needed (taking advantage -of knowledge that some libkrb5 functions don't use their context -parameters). - -(cherry picked from commit b2190fdc253de6024001e0f1ff9fe56c31042bb7) ---- - src/kdc/kdc_authdata.c | 138 +++++++++++++++++++---------------------- - src/kdc/kdc_util.c | 50 --------------- - src/kdc/kdc_util.h | 5 -- - 3 files changed, 64 insertions(+), 129 deletions(-) - -diff --git a/src/kdc/kdc_authdata.c b/src/kdc/kdc_authdata.c -index 1ebe87246..010922c27 100644 ---- a/src/kdc/kdc_authdata.c -+++ b/src/kdc/kdc_authdata.c -@@ -108,7 +108,7 @@ unload_authdata_plugins(krb5_context context) - /* Return true if authdata should be filtered when copying from untrusted - * authdata. If desired_type is non-zero, look only for that type. */ - static krb5_boolean --is_kdc_issued_authdatum(krb5_context context, krb5_authdata *authdata, -+is_kdc_issued_authdatum(krb5_authdata *authdata, - krb5_authdatatype desired_type) - { - krb5_boolean result = FALSE; -@@ -117,7 +117,7 @@ is_kdc_issued_authdatum(krb5_context context, krb5_authdata *authdata, - krb5_authdatatype *ad_types, *containee_types = NULL; - - if (authdata->ad_type == KRB5_AUTHDATA_IF_RELEVANT) { -- if (krb5int_get_authdata_containee_types(context, authdata, &count, -+ if (krb5int_get_authdata_containee_types(NULL, authdata, &count, - &containee_types) != 0) - goto cleanup; - ad_types = containee_types; -@@ -152,7 +152,7 @@ cleanup: - /* Return true if authdata contains any elements which should only come from - * the KDC. If desired_type is non-zero, look only for that type. */ - static krb5_boolean --has_kdc_issued_authdata(krb5_context context, krb5_authdata **authdata, -+has_kdc_issued_authdata(krb5_authdata **authdata, - krb5_authdatatype desired_type) - { - int i; -@@ -160,7 +160,7 @@ has_kdc_issued_authdata(krb5_context context, krb5_authdata **authdata, - if (authdata == NULL) - return FALSE; - for (i = 0; authdata[i] != NULL; i++) { -- if (is_kdc_issued_authdatum(context, authdata[i], desired_type)) -+ if (is_kdc_issued_authdatum(authdata[i], desired_type)) - return TRUE; - } - return FALSE; -@@ -181,66 +181,71 @@ has_mandatory_for_kdc_authdata(krb5_context context, krb5_authdata **authdata) - return FALSE; - } - --/* -- * Add the elements of in_authdata to out_authdata. If copy is false, -- * in_authdata is invalid on successful return. If ignore_kdc_issued is true, -- * KDC-issued authdata is not copied. -- */ -+/* Add elements from *new_elements to *existing_list, reallocating as -+ * necessary. On success, release *new_elements and set it to NULL. */ - static krb5_error_code --merge_authdata(krb5_context context, krb5_authdata **in_authdata, -- krb5_authdata ***out_authdata, krb5_boolean copy, -- krb5_boolean ignore_kdc_issued) -+merge_authdata(krb5_authdata ***existing_list, krb5_authdata ***new_elements) - { -- krb5_error_code ret; -- size_t i, j, nadata = 0; -- krb5_authdata **in_copy = NULL, **authdata = *out_authdata; -+ size_t count = 0, ncount = 0; -+ krb5_authdata **list = *existing_list, **nlist = *new_elements; - -- if (in_authdata == NULL || in_authdata[0] == NULL) -+ if (nlist == NULL) - return 0; - -- if (authdata != NULL) { -- for (nadata = 0; authdata[nadata] != NULL; nadata++) -- ; -- } -+ for (count = 0; list != NULL && list[count] != NULL; count++); -+ for (ncount = 0; nlist[ncount] != NULL; ncount++); - -- for (i = 0; in_authdata[i] != NULL; i++) -- ; -- -- if (copy) { -- ret = krb5_copy_authdata(context, in_authdata, &in_copy); -- if (ret) -- return ret; -- in_authdata = in_copy; -- } -- -- authdata = realloc(authdata, (nadata + i + 1) * sizeof(krb5_authdata *)); -- if (authdata == NULL) { -- krb5_free_authdata(context, in_copy); -+ list = realloc(list, (count + ncount + 1) * sizeof(*list)); -+ if (list == NULL) - return ENOMEM; -+ -+ memcpy(list + count, nlist, ncount * sizeof(*nlist)); -+ list[count + ncount] = NULL; -+ free(nlist); -+ -+ if (list[0] == NULL) { -+ free(list); -+ list = NULL; - } - -- for (i = 0, j = 0; in_authdata[i] != NULL; i++) { -- if (ignore_kdc_issued && -- is_kdc_issued_authdatum(context, in_authdata[i], 0)) { -- free(in_authdata[i]->contents); -- free(in_authdata[i]); -+ *new_elements = NULL; -+ *existing_list = list; -+ return 0; -+} -+ -+/* Add a copy of new_elements to *existing_list, omitting KDC-issued -+ * authdata. */ -+static krb5_error_code -+add_filtered_authdata(krb5_authdata ***existing_list, -+ krb5_authdata **new_elements) -+{ -+ krb5_error_code ret; -+ krb5_authdata **copy; -+ size_t i, j; -+ -+ if (new_elements == NULL) -+ return 0; -+ -+ ret = krb5_copy_authdata(NULL, new_elements, ©); -+ if (ret) -+ return ret; -+ -+ /* Remove KDC-issued elements from copy. */ -+ j = 0; -+ for (i = 0; copy[i] != NULL; i++) { -+ if (is_kdc_issued_authdatum(copy[i], 0)) { -+ free(copy[i]->contents); -+ free(copy[i]); - } else { -- authdata[nadata + j++] = in_authdata[i]; -+ copy[j++] = copy[i]; - } - } -+ copy[j] = NULL; - -- authdata[nadata + j] = NULL; -- -- free(in_authdata); -- -- if (authdata[0] == NULL) { -- free(authdata); -- authdata = NULL; -- } -- -- *out_authdata = authdata; -- -- return 0; -+ /* Destructively merge the filtered copy into existing_list. */ -+ ret = merge_authdata(existing_list, ©); -+ krb5_free_authdata(NULL, copy); -+ return ret; - } - - /* Copy TGS-REQ authorization data into the ticket authdata. */ -@@ -289,10 +294,7 @@ copy_request_authdata(krb5_context context, krb5_keyblock *client_key, - goto cleanup; - } - -- /* Add a copy of the requested authdata to the ticket, ignoring KDC-issued -- * types. */ -- ret = merge_authdata(context, req->unenc_authdata, tkt_authdata, TRUE, -- TRUE); -+ ret = add_filtered_authdata(tkt_authdata, req->unenc_authdata); - - cleanup: - free(plaintext.data); -@@ -307,9 +309,7 @@ copy_tgt_authdata(krb5_context context, krb5_kdc_req *request, - if (has_mandatory_for_kdc_authdata(context, tgt_authdata)) - return KRB5KDC_ERR_POLICY; - -- /* Add a copy of the TGT authdata to the ticket, ignoring KDC-issued -- * types. */ -- return merge_authdata(context, tgt_authdata, tkt_authdata, TRUE, TRUE); -+ return add_filtered_authdata(tkt_authdata, tgt_authdata); - } - - /* Fetch authorization data from KDB module. */ -@@ -374,8 +374,7 @@ fetch_kdb_authdata(krb5_context context, unsigned int flags, - - /* Put the KDB authdata first in the ticket. A successful merge places the - * combined list in db_authdata and releases the old ticket authdata. */ -- ret = merge_authdata(context, enc_tkt_reply->authorization_data, -- &db_authdata, FALSE, FALSE); -+ ret = merge_authdata(&db_authdata, &enc_tkt_reply->authorization_data); - if (ret) - krb5_free_authdata(context, db_authdata); - else -@@ -404,8 +403,7 @@ make_signedpath_data(krb5_context context, krb5_const_principal client, - return ret; - - for (i = 0, j = 0; authdata[i] != NULL; i++) { -- if (is_kdc_issued_authdatum(context, authdata[i], -- KRB5_AUTHDATA_SIGNTICKET)) -+ if (is_kdc_issued_authdatum(authdata[i], KRB5_AUTHDATA_SIGNTICKET)) - continue; - - sign_authdata[j++] = authdata[i]; -@@ -635,12 +633,8 @@ make_signedpath(krb5_context context, krb5_const_principal for_user_princ, - if (ret) - goto cleanup; - -- /* Add the authdata to the ticket, without copying or filtering. */ -- ret = merge_authdata(context, if_relevant, -- &enc_tkt_reply->authorization_data, FALSE, FALSE); -- if (ret) -- goto cleanup; -- if_relevant = NULL; /* merge_authdata() freed */ -+ /* Add the signedpath authdata to the ticket. */ -+ ret = merge_authdata(&enc_tkt_reply->authorization_data, &if_relevant); - - cleanup: - free(sp.delegated); -@@ -665,7 +659,7 @@ free_deleg_path(krb5_context context, krb5_principal *deleg_path) - static krb5_boolean - has_pac(krb5_context context, krb5_authdata **authdata) - { -- return has_kdc_issued_authdata(context, authdata, KRB5_AUTHDATA_WIN2K_PAC); -+ return has_kdc_issued_authdata(authdata, KRB5_AUTHDATA_WIN2K_PAC); - } - - /* Verify AD-SIGNTICKET authdata if we need to, and insert an AD-SIGNEDPATH -@@ -746,11 +740,7 @@ add_auth_indicators(krb5_context context, krb5_data *const *auth_indicators, - goto cleanup; - - /* Add the wrapped authdata to the ticket, without copying or filtering. */ -- ret = merge_authdata(context, cammac, &enc_tkt_reply->authorization_data, -- FALSE, FALSE); -- if (ret) -- goto cleanup; -- cammac = NULL; /* merge_authdata() freed */ -+ ret = merge_authdata(&enc_tkt_reply->authorization_data, &cammac); - - cleanup: - krb5_free_data(context, der_indicators); -diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index 6330387d0..a4a05b9fa 100644 ---- a/src/kdc/kdc_util.c -+++ b/src/kdc/kdc_util.c -@@ -78,56 +78,6 @@ static krb5_error_code find_server_key(krb5_context, - krb5_kvno, krb5_keyblock **, - krb5_kvno *); - --/* -- * concatenate first two authdata arrays, returning an allocated replacement. -- * The replacement should be freed with krb5_free_authdata(). -- */ --krb5_error_code --concat_authorization_data(krb5_context context, -- krb5_authdata **first, krb5_authdata **second, -- krb5_authdata ***output) --{ -- int i, j; -- krb5_authdata **ptr, **retdata; -- -- /* count up the entries */ -- i = 0; -- if (first) -- for (ptr = first; *ptr; ptr++) -- i++; -- if (second) -- for (ptr = second; *ptr; ptr++) -- i++; -- -- retdata = (krb5_authdata **)malloc((i+1)*sizeof(*retdata)); -- if (!retdata) -- return ENOMEM; -- retdata[i] = 0; /* null-terminated array */ -- for (i = 0, j = 0, ptr = first; j < 2 ; ptr = second, j++) -- while (ptr && *ptr) { -- /* now walk & copy */ -- retdata[i] = (krb5_authdata *)malloc(sizeof(*retdata[i])); -- if (!retdata[i]) { -- krb5_free_authdata(context, retdata); -- return ENOMEM; -- } -- *retdata[i] = **ptr; -- if (!(retdata[i]->contents = -- (krb5_octet *)malloc(retdata[i]->length))) { -- free(retdata[i]); -- retdata[i] = 0; -- krb5_free_authdata(context, retdata); -- return ENOMEM; -- } -- memcpy(retdata[i]->contents, (*ptr)->contents, retdata[i]->length); -- -- ptr++; -- i++; -- } -- *output = retdata; -- return 0; --} -- - krb5_boolean - is_local_principal(kdc_realm_t *kdc_active_realm, krb5_const_principal princ1) - { -diff --git a/src/kdc/kdc_util.h b/src/kdc/kdc_util.h -index 2c9d8cf69..42b7ee208 100644 ---- a/src/kdc/kdc_util.h -+++ b/src/kdc/kdc_util.h -@@ -52,11 +52,6 @@ compress_transited (krb5_data *, - krb5_principal, - krb5_data *); - krb5_error_code --concat_authorization_data (krb5_context, -- krb5_authdata **, -- krb5_authdata **, -- krb5_authdata ***); --krb5_error_code - fetch_last_req_info (krb5_db_entry *, krb5_last_req_entry ***); - - krb5_error_code diff --git a/Refactor-krb5-GSS-checksum-handling.patch b/Refactor-krb5-GSS-checksum-handling.patch deleted file mode 100644 index 62f36c3..0000000 --- a/Refactor-krb5-GSS-checksum-handling.patch +++ /dev/null @@ -1,479 +0,0 @@ -From 8412a1611290da9705730c9e473a5b122c55e9fd Mon Sep 17 00:00:00 2001 -From: Alexander Scheel -Date: Fri, 30 Jun 2017 16:03:01 -0400 -Subject: [PATCH] Refactor krb5 GSS checksum handling - -Separate out checksum handling from kg_accept_krb5() into a new helper -process_checksum(). - -[ghudson@mit.edu: simplified checksum processing and made it use -k5-input.h instead of TREAD_ macros; moved more flag handling into -helper] - -[iboukris: adjusted helper function arguments, allowing access to the -full authenticator for subsequent changes] - -(cherry picked from commit 64d56233f9816a2a93f6e8d3030c8ed6ce397735) -[rharwood@redhat.com: problem with typo fix commit, I think] ---- - src/lib/gssapi/krb5/accept_sec_context.c | 383 +++++++++++------------ - 1 file changed, 179 insertions(+), 204 deletions(-) - -diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index c5bddb1e8..70dd7fc0c 100644 ---- a/src/lib/gssapi/krb5/accept_sec_context.c -+++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -98,6 +98,7 @@ - */ - - #include "k5-int.h" -+#include "k5-input.h" - #include "gssapiP_krb5.h" - #ifdef HAVE_MEMORY_H - #include -@@ -413,6 +414,174 @@ kg_process_extension(krb5_context context, - return code; - } - -+/* The length of the MD5 channel bindings in an 0x8003 checksum */ -+#define CB_MD5_LEN 16 -+ -+/* The minimum length of an 0x8003 checksum value (4-byte channel bindings -+ * length, 16-byte channel bindings, 4-byte flags) */ -+#define MIN_8003_LEN (4 + CB_MD5_LEN + 4) -+ -+/* The flags we accept from the initiator's authenticator checksum. */ -+#define INITIATOR_FLAGS (GSS_C_INTEG_FLAG | GSS_C_CONF_FLAG | \ -+ GSS_C_MUTUAL_FLAG | GSS_C_REPLAY_FLAG | \ -+ GSS_C_SEQUENCE_FLAG | GSS_C_DCE_STYLE | \ -+ GSS_C_IDENTIFY_FLAG | GSS_C_EXTENDED_ERROR_FLAG) -+ -+/* -+ * The krb5 GSS mech appropriates the authenticator checksum field from RFC -+ * 4120 to store structured data instead of a checksum, indicated with checksum -+ * type 0x8003 (see RFC 4121 section 4.1.1). Some implementations instead send -+ * no checksum, or a regular checksum over empty data. -+ * -+ * Interpret the checksum. Read delegated creds into *deleg_out if it is not -+ * NULL. Set *flags_out to the allowed subset of token flags, plus -+ * GSS_C_DELEG_FLAG if a delegated credential was present. Process any -+ * extensions found using exts. On error, set *code_out to a krb5_error code -+ * for use as a minor status value. -+ */ -+static OM_uint32 -+process_checksum(OM_uint32 *minor_status, krb5_context context, -+ gss_channel_bindings_t acceptor_cb, -+ krb5_auth_context auth_context, krb5_flags ap_req_options, -+ krb5_authenticator *authenticator, krb5_gss_ctx_ext_t exts, -+ krb5_gss_cred_id_t *deleg_out, krb5_ui_4 *flags_out, -+ krb5_error_code *code_out) -+{ -+ krb5_error_code code = 0; -+ OM_uint32 status, option_id, token_flags; -+ size_t cb_len, option_len; -+ krb5_boolean valid; -+ krb5_key subkey; -+ krb5_data option, empty = empty_data(); -+ krb5_checksum cb_cksum; -+ const uint8_t *token_cb, *option_bytes; -+ struct k5input in; -+ const krb5_checksum *cksum = authenticator->checksum; -+ -+ cb_cksum.contents = NULL; -+ -+ if (cksum == NULL) { -+ /* -+ * Some SMB client implementations use handcrafted GSSAPI code that -+ * does not provide a checksum. MS-KILE documents that the Microsoft -+ * implementation considers a missing checksum acceptable; the server -+ * assumes all flags are unset in this case, and does not check channel -+ * bindings. -+ */ -+ *flags_out = 0; -+ } else if (cksum->checksum_type != CKSUMTYPE_KG_CB) { -+ /* Samba sends a regular checksum. */ -+ code = krb5_auth_con_getkey_k(context, auth_context, &subkey); -+ if (code) { -+ status = GSS_S_FAILURE; -+ goto fail; -+ } -+ -+ /* Verifying the checksum ensures that this authenticator wasn't -+ * replayed from one with a checksum over actual data. */ -+ code = krb5_k_verify_checksum(context, subkey, -+ KRB5_KEYUSAGE_AP_REQ_AUTH_CKSUM, &empty, -+ cksum, &valid); -+ krb5_k_free_key(context, subkey); -+ if (code || !valid) { -+ status = GSS_S_BAD_SIG; -+ goto fail; -+ } -+ -+ /* Use ap_options from the request to guess the mutual flag. */ -+ *flags_out = GSS_C_REPLAY_FLAG | GSS_C_SEQUENCE_FLAG; -+ if (ap_req_options & AP_OPTS_MUTUAL_REQUIRED) -+ *flags_out |= GSS_C_MUTUAL_FLAG; -+ } else { -+ /* The checksum must contain at least a fixed 24-byte part. */ -+ if (cksum->length < MIN_8003_LEN) { -+ status = GSS_S_BAD_BINDINGS; -+ goto fail; -+ } -+ -+ k5_input_init(&in, cksum->contents, cksum->length); -+ cb_len = k5_input_get_uint32_le(&in); -+ if (cb_len != CB_MD5_LEN) { -+ code = KG_BAD_LENGTH; -+ status = GSS_S_FAILURE; -+ goto fail; -+ } -+ -+ token_cb = k5_input_get_bytes(&in, cb_len); -+ if (acceptor_cb != GSS_C_NO_CHANNEL_BINDINGS) { -+ code = kg_checksum_channel_bindings(context, acceptor_cb, -+ &cb_cksum); -+ if (code) { -+ status = GSS_S_BAD_BINDINGS; -+ goto fail; -+ } -+ assert(cb_cksum.length == cb_len); -+ if (k5_bcmp(token_cb, cb_cksum.contents, cb_len) != 0) { -+ status = GSS_S_BAD_BINDINGS; -+ goto fail; -+ } -+ } -+ -+ /* Read the token flags and accept some of them as context flags. */ -+ token_flags = k5_input_get_uint32_le(&in); -+ *flags_out = token_flags & INITIATOR_FLAGS; -+ -+ /* Read the delegated credential if present. */ -+ if (in.len >= 4 && (token_flags & GSS_C_DELEG_FLAG)) { -+ option_id = k5_input_get_uint16_le(&in); -+ option_len = k5_input_get_uint16_le(&in); -+ option_bytes = k5_input_get_bytes(&in, option_len); -+ option = make_data((uint8_t *)option_bytes, option_len); -+ if (in.status) { -+ code = KG_BAD_LENGTH; -+ status = GSS_S_FAILURE; -+ goto fail; -+ } -+ if (option_id != KRB5_GSS_FOR_CREDS_OPTION) { -+ status = GSS_S_FAILURE; -+ goto fail; -+ } -+ -+ /* Store the delegated credential. */ -+ code = rd_and_store_for_creds(context, auth_context, &option, -+ deleg_out); -+ if (code) { -+ status = GSS_S_FAILURE; -+ goto fail; -+ } -+ *flags_out |= GSS_C_DELEG_FLAG; -+ } -+ -+ /* Process any extensions at the end of the checksum. Extensions use -+ * 4-byte big-endian tag and length instead of 2-byte little-endian. */ -+ while (in.len > 0) { -+ option_id = k5_input_get_uint32_be(&in); -+ option_len = k5_input_get_uint32_be(&in); -+ option_bytes = k5_input_get_bytes(&in, option_len); -+ option = make_data((uint8_t *)option_bytes, option_len); -+ if (in.status) { -+ code = KG_BAD_LENGTH; -+ status = GSS_S_FAILURE; -+ goto fail; -+ } -+ -+ code = kg_process_extension(context, auth_context, option_id, -+ &option, exts); -+ if (code) { -+ status = GSS_S_FAILURE; -+ goto fail; -+ } -+ } -+ } -+ -+ status = GSS_S_COMPLETE; -+ -+fail: -+ free(cb_cksum.contents); -+ *code_out = code; -+ return status; -+} -+ - static OM_uint32 - kg_accept_krb5(minor_status, context_handle, - verifier_cred_handle, input_token, -@@ -433,17 +602,13 @@ kg_accept_krb5(minor_status, context_handle, - krb5_gss_ctx_ext_t exts; - { - krb5_context context; -- unsigned char *ptr, *ptr2; -+ unsigned char *ptr; - char *sptr; -- OM_uint32 tmp; -- size_t md5len; - krb5_gss_cred_id_t cred = 0; - krb5_data ap_rep, ap_req; -- unsigned int i; - krb5_error_code code; - krb5_address addr, *paddr; - krb5_authenticator *authdat = 0; -- krb5_checksum reqcksum; - krb5_gss_name_t name = NULL; - krb5_ui_4 gss_flags = 0; - krb5_gss_ctx_id_rec *ctx = NULL; -@@ -451,8 +616,6 @@ kg_accept_krb5(minor_status, context_handle, - gss_buffer_desc token; - krb5_auth_context auth_context = NULL; - krb5_ticket * ticket = NULL; -- int option_id; -- krb5_data option; - const gss_OID_desc *mech_used = NULL; - OM_uint32 major_status = GSS_S_FAILURE; - OM_uint32 tmp_minor_status; -@@ -463,7 +626,6 @@ kg_accept_krb5(minor_status, context_handle, - krb5int_access kaccess; - int cred_rcache = 0; - int no_encap = 0; -- int token_deleg_flag = 0; - krb5_flags ap_req_options = 0; - krb5_enctype negotiated_etype; - krb5_authdata_context ad_context = NULL; -@@ -489,7 +651,6 @@ kg_accept_krb5(minor_status, context_handle, - output_token->length = 0; - output_token->value = NULL; - token.value = 0; -- reqcksum.contents = 0; - ap_req.data = 0; - ap_rep.data = 0; - -@@ -654,195 +815,16 @@ kg_accept_krb5(minor_status, context_handle, - - krb5_auth_con_getauthenticator(context, auth_context, &authdat); - -- if (authdat->checksum == NULL) { -- /* -- * Some SMB client implementations use handcrafted GSSAPI code that -- * does not provide a checksum. MS-KILE documents that the Microsoft -- * implementation considers a missing checksum acceptable; the server -- * assumes all flags are unset in this case, and does not check channel -- * bindings. -- */ -- gss_flags = 0; -- } else if (authdat->checksum->checksum_type != CKSUMTYPE_KG_CB) { -- /* Samba does not send 0x8003 GSS-API checksums */ -- krb5_boolean valid; -- krb5_key subkey; -- krb5_data zero; -+ major_status = process_checksum(minor_status, context, input_chan_bindings, -+ auth_context, ap_req_options, -+ authdat, exts, -+ delegated_cred_handle ? &deleg_cred : NULL, -+ &gss_flags, &code); - -- code = krb5_auth_con_getkey_k(context, auth_context, &subkey); -- if (code) { -- major_status = GSS_S_FAILURE; -- goto fail; -- } -+ if (major_status != GSS_S_COMPLETE) -+ goto fail; - -- zero.length = 0; -- zero.data = ""; -- -- code = krb5_k_verify_checksum(context, -- subkey, -- KRB5_KEYUSAGE_AP_REQ_AUTH_CKSUM, -- &zero, -- authdat->checksum, -- &valid); -- krb5_k_free_key(context, subkey); -- if (code || !valid) { -- major_status = GSS_S_BAD_SIG; -- goto fail; -- } -- -- /* Use ap_options from the request to guess the mutual flag. */ -- gss_flags = GSS_C_REPLAY_FLAG | GSS_C_SEQUENCE_FLAG; -- if (ap_req_options & AP_OPTS_MUTUAL_REQUIRED) -- gss_flags |= GSS_C_MUTUAL_FLAG; -- } else { -- /* gss krb5 v1 */ -- -- /* stash this now, for later. */ -- code = krb5_c_checksum_length(context, CKSUMTYPE_RSA_MD5, &md5len); -- if (code) { -- major_status = GSS_S_FAILURE; -- goto fail; -- } -- -- /* verify that the checksum is correct */ -- -- /* -- The checksum may be either exactly 24 bytes, in which case -- no options are specified, or greater than 24 bytes, in which case -- one or more options are specified. Currently, the only valid -- option is KRB5_GSS_FOR_CREDS_OPTION ( = 1 ). -- */ -- -- if ((authdat->checksum->checksum_type != CKSUMTYPE_KG_CB) || -- (authdat->checksum->length < 24)) { -- code = 0; -- major_status = GSS_S_BAD_BINDINGS; -- goto fail; -- } -- -- ptr = (unsigned char *) authdat->checksum->contents; -- -- TREAD_INT(ptr, tmp, 0); -- -- if (tmp != md5len) { -- code = KG_BAD_LENGTH; -- major_status = GSS_S_FAILURE; -- goto fail; -- } -- -- /* -- The following section of code attempts to implement the -- optional channel binding facility as described in RFC2743. -- -- Since this facility is optional channel binding may or may -- not have been provided by either the client or the server. -- -- If the server has specified input_chan_bindings equal to -- GSS_C_NO_CHANNEL_BINDINGS then we skip the check. If -- the server does provide channel bindings then we compute -- a checksum and compare against those provided by the -- client. */ -- -- if ((code = kg_checksum_channel_bindings(context, -- input_chan_bindings, -- &reqcksum))) { -- major_status = GSS_S_BAD_BINDINGS; -- goto fail; -- } -- -- /* Always read the clients bindings - eventhough we might ignore them */ -- TREAD_STR(ptr, ptr2, reqcksum.length); -- -- if (input_chan_bindings != GSS_C_NO_CHANNEL_BINDINGS ) { -- if (memcmp(ptr2, reqcksum.contents, reqcksum.length) != 0) { -- xfree(reqcksum.contents); -- reqcksum.contents = 0; -- code = 0; -- major_status = GSS_S_BAD_BINDINGS; -- goto fail; -- } -- -- } -- -- xfree(reqcksum.contents); -- reqcksum.contents = 0; -- -- /* Read the token flags. Remember if GSS_C_DELEG_FLAG was set, but -- * mask it out until we actually read a delegated credential. */ -- TREAD_INT(ptr, gss_flags, 0); -- token_deleg_flag = (gss_flags & GSS_C_DELEG_FLAG); -- gss_flags &= ~GSS_C_DELEG_FLAG; -- -- /* if the checksum length > 24, there are options to process */ -- -- i = authdat->checksum->length - 24; -- if (i && token_deleg_flag) { -- if (i >= 4) { -- TREAD_INT16(ptr, option_id, 0); -- TREAD_INT16(ptr, option.length, 0); -- i -= 4; -- -- if (i < option.length) { -- code = KG_BAD_LENGTH; -- major_status = GSS_S_FAILURE; -- goto fail; -- } -- -- /* have to use ptr2, since option.data is wrong type and -- macro uses ptr as both lvalue and rvalue */ -- -- TREAD_STR(ptr, ptr2, option.length); -- option.data = (char *) ptr2; -- -- i -= option.length; -- -- if (option_id != KRB5_GSS_FOR_CREDS_OPTION) { -- major_status = GSS_S_FAILURE; -- goto fail; -- } -- -- /* store the delegated credential */ -- -- code = rd_and_store_for_creds(context, auth_context, &option, -- (delegated_cred_handle) ? -- &deleg_cred : NULL); -- if (code) { -- major_status = GSS_S_FAILURE; -- goto fail; -- } -- -- gss_flags |= GSS_C_DELEG_FLAG; -- } /* if i >= 4 */ -- /* ignore any additional trailing data, for now */ -- } -- while (i > 0) { -- /* Process Type-Length-Data options */ -- if (i < 8) { -- code = KG_BAD_LENGTH; -- major_status = GSS_S_FAILURE; -- goto fail; -- } -- TREAD_INT(ptr, option_id, 1); -- TREAD_INT(ptr, option.length, 1); -- i -= 8; -- if (i < option.length) { -- code = KG_BAD_LENGTH; -- major_status = GSS_S_FAILURE; -- goto fail; -- } -- TREAD_STR(ptr, ptr2, option.length); -- option.data = (char *)ptr2; -- -- i -= option.length; -- -- code = kg_process_extension(context, auth_context, -- option_id, &option, exts); -- if (code != 0) { -- major_status = GSS_S_FAILURE; -- goto fail; -- } -- } -- } -+ major_status = GSS_S_FAILURE; - - if (exts->iakerb.conv && !exts->iakerb.verified) { - major_status = GSS_S_BAD_SIG; -@@ -869,12 +851,7 @@ kg_accept_krb5(minor_status, context_handle, - ctx->mech_used = (gss_OID) mech_used; - ctx->auth_context = auth_context; - ctx->initiate = 0; -- ctx->gss_flags = (GSS_C_TRANS_FLAG | -- ((gss_flags) & (GSS_C_INTEG_FLAG | GSS_C_CONF_FLAG | -- GSS_C_MUTUAL_FLAG | GSS_C_REPLAY_FLAG | -- GSS_C_SEQUENCE_FLAG | GSS_C_DELEG_FLAG | -- GSS_C_DCE_STYLE | GSS_C_IDENTIFY_FLAG | -- GSS_C_EXTENDED_ERROR_FLAG))); -+ ctx->gss_flags = gss_flags | GSS_C_TRANS_FLAG; - ctx->seed_init = 0; - ctx->cred_rcache = cred_rcache; - -@@ -1161,8 +1138,6 @@ fail: - - krb5_auth_con_free(context, auth_context); - } -- if (reqcksum.contents) -- xfree(reqcksum.contents); - if (ap_rep.data) - krb5_free_data_contents(context, &ap_rep); - if (major_status == GSS_S_COMPLETE || diff --git a/Refresh-manually-acquired-creds-from-client-keytab.patch b/Refresh-manually-acquired-creds-from-client-keytab.patch deleted file mode 100644 index 61e1fa4..0000000 --- a/Refresh-manually-acquired-creds-from-client-keytab.patch +++ /dev/null @@ -1,78 +0,0 @@ -From 43fe1f948059ad79d95dbf41f2206de65238d892 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 26 Feb 2020 18:27:17 -0500 -Subject: [PATCH] Refresh manually acquired creds from client keytab - -If a client keytab is present but credentials are acquired manually, -the credentials would not be refreshed because no refresh_time config -var is set in the cache. Change kg_cred_time_to_refresh() to attempt -a refresh from the client keytab on any credentials which will expire -in the next 30 seconds. - -[ghudson@mit.edu: adjused code and added test case] - -ticket: 7976 -(cherry picked from commit 729896467e3c77904666019d6cbbda583ae49b95) ---- - src/lib/gssapi/krb5/acquire_cred.c | 14 +++++++++++--- - src/tests/gssapi/t_client_keytab.py | 18 ++++++++++++++++++ - 2 files changed, 29 insertions(+), 3 deletions(-) - -diff --git a/src/lib/gssapi/krb5/acquire_cred.c b/src/lib/gssapi/krb5/acquire_cred.c -index acc1868f8..4062f4741 100644 ---- a/src/lib/gssapi/krb5/acquire_cred.c -+++ b/src/lib/gssapi/krb5/acquire_cred.c -@@ -557,15 +557,23 @@ set_refresh_time(krb5_context context, krb5_ccache ccache, - krb5_boolean - kg_cred_time_to_refresh(krb5_context context, krb5_gss_cred_id_rec *cred) - { -- krb5_timestamp now; -+ krb5_timestamp now, soon; - - if (krb5_timeofday(context, &now)) - return FALSE; -+ soon = ts_incr(now, 30); - if (cred->refresh_time != 0 && !ts_after(cred->refresh_time, now)) { -- set_refresh_time(context, cred->ccache, -- ts_incr(cred->refresh_time, 30)); -+ set_refresh_time(context, cred->ccache, soon); - return TRUE; - } -+ -+ /* If the creds will expire soon, try to refresh even if they weren't -+ * acquired with a client keytab. */ -+ if (ts_after(soon, cred->expire)) { -+ set_refresh_time(context, cred->ccache, soon); -+ return TRUE; -+ } -+ - return FALSE; - } - -diff --git a/src/tests/gssapi/t_client_keytab.py b/src/tests/gssapi/t_client_keytab.py -index e474a27c7..7847b3ecd 100755 ---- a/src/tests/gssapi/t_client_keytab.py -+++ b/src/tests/gssapi/t_client_keytab.py -@@ -124,4 +124,22 @@ realm.kinit(realm.user_princ, password('user')) - realm.run(['./t_ccselect', phost], env=bad_cktname, - expected_msg=realm.user_princ) - -+mark('refresh of manually acquired creds') -+ -+# Test 17: no name/ccache specified, manually acquired creds which -+# will expire soon. Verify that creds are refreshed using the current -+# client name, with refresh_time set in the refreshed ccache. -+realm.kinit('bob', password('bob'), ['-l', '15s']) -+realm.run(['./t_ccselect', phost], expected_msg='bob') -+realm.run([klist, '-C'], expected_msg='refresh_time = ') -+ -+# Test 18: no name/ccache specified, manually acquired creds with a -+# client principal not present in the client keytab. A refresh is -+# attempted but fails, and an expired ticket error results. -+realm.kinit(realm.admin_princ, password('admin'), ['-l', '-1s']) -+msgs = ('Getting initial credentials for user/admin@KRBTEST.COM', -+ '/Matching credential not found') -+realm.run(['./t_ccselect', phost], expected_code=1, -+ expected_msg='Ticket expired', expected_trace=msgs) -+ - success('Client keytab tests') diff --git a/Remove-resolver-test-utility.patch b/Remove-resolver-test-utility.patch deleted file mode 100644 index 77fea7a..0000000 --- a/Remove-resolver-test-utility.patch +++ /dev/null @@ -1,547 +0,0 @@ -From 6d2dbd0378c92ea13363f2536ab0062bdfda076e Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 28 May 2020 18:41:02 -0400 -Subject: [PATCH] Remove resolver test utility - -tests/resolve is no longer used after the previous commit. - -[rharwood@redhat.com: .gitignore] ---- - src/configure.ac | 5 +- - src/tests/Makefile.in | 4 +- - src/tests/resolve/Makefile.in | 28 --- - src/tests/resolve/addrinfo-test.c | 306 ------------------------- - src/tests/resolve/deps | 14 -- - src/tests/resolve/fake-addrinfo-test.c | 3 - - src/tests/resolve/resolve.c | 115 ---------- - 7 files changed, 4 insertions(+), 471 deletions(-) - delete mode 100644 src/tests/resolve/Makefile.in - delete mode 100644 src/tests/resolve/addrinfo-test.c - delete mode 100644 src/tests/resolve/deps - delete mode 100644 src/tests/resolve/fake-addrinfo-test.c - delete mode 100644 src/tests/resolve/resolve.c - -diff --git a/src/configure.ac b/src/configure.ac -index aafc462f9..00b5ea4c5 100644 ---- a/src/configure.ac -+++ b/src/configure.ac -@@ -1540,7 +1540,6 @@ V5_AC_OUTPUT_MAKEFILE(. - appl/simple appl/simple/client appl/simple/server - appl/gss-sample appl/user_user - -- tests tests/resolve tests/asn.1 tests/create tests/hammer -- tests/verify tests/gssapi tests/dejagnu tests/threads tests/shlib -- tests/gss-threads tests/misc -+ tests tests/asn.1 tests/create tests/hammer tests/verify tests/gssapi -+ tests/dejagnu tests/threads tests/shlib tests/gss-threads tests/misc - ) -diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in -index 3f88f1713..6b7749129 100644 ---- a/src/tests/Makefile.in -+++ b/src/tests/Makefile.in -@@ -1,7 +1,7 @@ - mydir=tests - BUILDTOP=$(REL).. --SUBDIRS = resolve asn.1 create hammer verify gssapi dejagnu shlib \ -- gss-threads misc threads softpkcs11 -+SUBDIRS = asn.1 create hammer verify gssapi dejagnu shlib gss-threads misc \ -+ threads softpkcs11 - - RUN_DB_TEST = $(RUN_SETUP) KRB5_KDC_PROFILE=kdc.conf KRB5_CONFIG=krb5.conf \ - GSS_MECH_CONFIG=mech.conf LC_ALL=C $(VALGRIND) -diff --git a/src/tests/resolve/Makefile.in b/src/tests/resolve/Makefile.in -deleted file mode 100644 -index 1f5954089..000000000 ---- a/src/tests/resolve/Makefile.in -+++ /dev/null -@@ -1,28 +0,0 @@ --mydir=tests$(S)resolve --BUILDTOP=$(REL)..$(S).. -- --OBJS=resolve.o addrinfo-test.o fake-addrinfo-test.o --SRCS=$(srcdir)/resolve.c $(srcdir)/addrinfo-test.c \ -- $(srcdir)/fake-addrinfo-test.c -- --all: resolve addrinfo-test fake-addrinfo-test -- --resolve: resolve.o -- $(CC_LINK) -o $@ resolve.o $(SUPPORT_LIB) $(LIBS) -- --addrinfo-test: addrinfo-test.o -- $(CC_LINK) -o $@ addrinfo-test.o $(SUPPORT_LIB) $(LIBS) -- --fake-addrinfo-test: fake-addrinfo-test.o -- $(CC_LINK) -o $@ fake-addrinfo-test.o $(SUPPORT_LIB) $(LIBS) -- --check: resolve addrinfo-test fake-addrinfo-test -- $(RUN_TEST) ./resolve -- $(RUN_TEST) ./addrinfo-test -p telnet -- $(RUN_TEST) ./fake-addrinfo-test -p telnet -- --install: -- --clean: -- $(RM) resolve addrinfo-test fake-addrinfo-test -- -diff --git a/src/tests/resolve/addrinfo-test.c b/src/tests/resolve/addrinfo-test.c -deleted file mode 100644 -index e77640b62..000000000 ---- a/src/tests/resolve/addrinfo-test.c -+++ /dev/null -@@ -1,306 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* tests/resolve/addrinfo-test.c */ --/* -- * Copyright 2004 by the Massachusetts Institute of Technology. -- * All Rights Reserved. -- * -- * Export of this software from the United States of America may -- * require a specific license from the United States Government. -- * It is the responsibility of any person or organization contemplating -- * export to obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of M.I.T. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. Furthermore if you modify this software you must label -- * your software as modified software and not distribute it in such a -- * fashion that it might be confused with the original M.I.T. software. -- * M.I.T. makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- */ -- --/* -- * A simple program to test the functionality of the getaddrinfo function. -- * -- * Usage: -- * addrinfo-test [-t|-u|-R|-I] [-d|-s|-r] [-p port] [-P] [hostname] -- * -- * When invoked with no arguments, NULL is used for the node name, -- * which (at least with a non-null "port") means a socket address -- * is desired that can be used with connect() or bind() (depending -- * on whether "-P" is given). -- */ -- --#include --#include --#include --#include --#include /* needed for IPPROTO_* on NetBSD */ --#ifdef USE_FAKE_ADDRINFO --#include "fake-addrinfo.h" --#endif -- --static const char *protoname (int p) { -- static char buf[30]; -- --#define X(N) if (p == IPPROTO_ ## N) return #N -- -- X(TCP); -- X(UDP); -- X(ICMP); --#ifdef IPPROTO_IPV6 -- X(IPV6); --#endif --#ifdef IPPROTO_GRE -- X(GRE); --#endif --#ifdef IPPROTO_NONE -- X(NONE); --#endif -- X(RAW); --#ifdef IPPROTO_COMP -- X(COMP); --#endif -- -- snprintf(buf, sizeof(buf), " %-2d", p); -- return buf; --} -- --static const char *socktypename (int t) { -- static char buf[30]; -- switch (t) { -- case SOCK_DGRAM: return "DGRAM"; -- case SOCK_STREAM: return "STREAM"; -- case SOCK_RAW: return "RAW"; -- case SOCK_RDM: return "RDM"; -- case SOCK_SEQPACKET: return "SEQPACKET"; -- } -- snprintf(buf, sizeof(buf), " %-2d", t); -- return buf; --} -- --static char *whoami; -- --static void usage () { -- fprintf(stderr, -- "usage:\n" -- "\t%s [ options ] [host]\n" -- "options:\n" -- "\t-t\tspecify protocol IPPROTO_TCP\n" -- "\t-u\tspecify protocol IPPROTO_UDP\n" -- "\t-R\tspecify protocol IPPROTO_RAW\n" -- "\t-I\tspecify protocol IPPROTO_ICMP\n" -- "\n" -- "\t-d\tspecify socket type SOCK_DGRAM\n" -- "\t-s\tspecify socket type SOCK_STREAM\n" -- "\t-r\tspecify socket type SOCK_RAW\n" -- "\n" -- "\t-4\tspecify address family AF_INET\n" --#ifdef AF_INET6 -- "\t-6\tspecify address family AF_INET6\n" --#endif -- "\n" -- "\t-p P\tspecify port P (service name or port number)\n" -- "\t-N\thostname is numeric, skip DNS query\n" -- "\t-n\tservice/port is numeric (sets AI_NUMERICSERV)\n" -- "\t-P\tset AI_PASSIVE\n" -- "\n" -- "default: protocol 0, socket type 0, address family 0, null port\n" -- , -- whoami); -- /* [ -t | -u | -R | -I ] [ -d | -s | -r ] [ -p port ] */ -- exit (1); --} -- --static const char *familyname (int f) { -- static char buf[30]; -- switch (f) { -- default: -- snprintf(buf, sizeof(buf), "AF %d", f); -- return buf; -- case AF_INET: return "AF_INET"; --#ifdef AF_INET6 -- case AF_INET6: return "AF_INET6"; --#endif -- } --} -- --#define eaistr(X) (X == EAI_SYSTEM ? strerror(errno) : gai_strerror(X)) -- --int main (int argc, char *argv[]) --{ -- struct addrinfo *ap, *ap2; -- int err, numerichost = 0, numericserv = 0; -- char *hname, *port = 0, *sep; -- struct addrinfo hints; -- -- whoami = strrchr(argv[0], '/'); -- if (whoami == 0) -- whoami = argv[0]; -- else -- whoami = whoami+1; -- -- memset(&hints, 0, sizeof(hints)); -- hints.ai_flags = 0; -- hints.ai_socktype = 0; -- -- hname = 0; -- hints.ai_family = 0; -- -- if (argc == 1) -- usage (); -- -- while (++argv, --argc > 0) { -- char *arg; -- arg = *argv; -- -- if (*arg != '-') -- hname = arg; -- else if (arg[1] == 0 || arg[2] != 0) -- usage (); -- else -- switch (arg[1]) { -- case 'u': -- hints.ai_protocol = IPPROTO_UDP; -- break; -- case 't': -- hints.ai_protocol = IPPROTO_TCP; -- break; -- case 'R': -- hints.ai_protocol = IPPROTO_RAW; -- break; -- case 'I': -- hints.ai_protocol = IPPROTO_ICMP; -- break; -- case 'd': -- hints.ai_socktype = SOCK_DGRAM; -- break; -- case 's': -- hints.ai_socktype = SOCK_STREAM; -- break; -- case 'r': -- hints.ai_socktype = SOCK_RAW; -- break; -- case 'p': -- if (argv[1] == 0 || argv[1][0] == 0 || argv[1][0] == '-') -- usage (); -- port = argv[1]; -- argc--, argv++; -- break; -- case '4': -- hints.ai_family = AF_INET; -- break; --#ifdef AF_INET6 -- case '6': -- hints.ai_family = AF_INET6; -- break; --#endif -- case 'N': -- numerichost = 1; -- break; -- case 'n': -- numericserv = 1; -- break; -- case 'P': -- hints.ai_flags |= AI_PASSIVE; -- break; -- default: -- usage (); -- } -- } -- -- if (hname && !numerichost) -- hints.ai_flags |= AI_CANONNAME; -- if (numerichost) { --#ifdef AI_NUMERICHOST -- hints.ai_flags |= AI_NUMERICHOST; --#else -- fprintf(stderr, "AI_NUMERICHOST not defined on this platform\n"); -- exit(1); --#endif -- } -- if (numericserv) { --#ifdef AI_NUMERICSERV -- hints.ai_flags |= AI_NUMERICSERV; --#else -- fprintf(stderr, "AI_NUMERICSERV not defined on this platform\n"); -- exit(1); --#endif -- } -- -- printf("getaddrinfo(hostname %s, service %s,\n" -- " hints { ", -- hname ? hname : "(null)", port ? port : "(null)"); -- sep = ""; --#define Z(FLAG) if (hints.ai_flags & AI_##FLAG) printf("%s%s", sep, #FLAG), sep = "|" -- Z(CANONNAME); -- Z(PASSIVE); --#ifdef AI_NUMERICHOST -- Z(NUMERICHOST); --#endif --#ifdef AI_NUMERICSERV -- Z(NUMERICSERV); --#endif -- if (sep[0] == 0) -- printf ("no-flags"); -- if (hints.ai_family) -- printf(" %s", familyname(hints.ai_family)); -- if (hints.ai_socktype) -- printf(" SOCK_%s", socktypename(hints.ai_socktype)); -- if (hints.ai_protocol) -- printf(" IPPROTO_%s", protoname(hints.ai_protocol)); -- printf(" }):\n"); -- -- err = getaddrinfo(hname, port, &hints, &ap); -- if (err) { -- printf("\terror => %s\n", eaistr(err)); -- return 1; -- } -- -- for (ap2 = ap; ap2; ap2 = ap2->ai_next) { -- char hbuf[NI_MAXHOST], pbuf[NI_MAXSERV]; -- /* If we don't do this, even AIX's own getnameinfo will reject -- the sockaddr structures. The sa_len field doesn't get set -- either, on AIX, but getnameinfo won't complain. */ -- if (ap2->ai_addr->sa_family == 0) { -- printf("BAD: sa_family zero! fixing...\n"); -- ap2->ai_addr->sa_family = ap2->ai_family; -- } else if (ap2->ai_addr->sa_family != ap2->ai_family) { -- printf("BAD: sa_family != ai_family! fixing...\n"); -- ap2->ai_addr->sa_family = ap2->ai_family; -- } -- if (getnameinfo(ap2->ai_addr, ap2->ai_addrlen, hbuf, sizeof(hbuf), -- pbuf, sizeof(pbuf), NI_NUMERICHOST | NI_NUMERICSERV)) { -- strlcpy(hbuf, "...", sizeof(hbuf)); -- strlcpy(pbuf, "...", sizeof(pbuf)); -- } -- printf("%p:\n" -- "\tfamily = %s\tproto = %-4s\tsocktype = %s\n", -- (void *) ap2, familyname(ap2->ai_family), -- protoname (ap2->ai_protocol), -- socktypename (ap2->ai_socktype)); -- if (ap2->ai_canonname) { -- if (ap2->ai_canonname[0]) -- printf("\tcanonname = %s\n", ap2->ai_canonname); -- else -- printf("BAD: ai_canonname is set but empty!\n"); -- } else if (ap2 == ap && (hints.ai_flags & AI_CANONNAME)) { -- printf("BAD: first ai_canonname is null!\n"); -- } -- printf("\taddr = %-28s\tport = %s\n", hbuf, pbuf); -- -- err = getnameinfo(ap2->ai_addr, ap2->ai_addrlen, hbuf, sizeof (hbuf), -- pbuf, sizeof(pbuf), NI_NAMEREQD); -- if (err) -- printf("\tgetnameinfo(NI_NAMEREQD): %s\n", eaistr(err)); -- else -- printf("\tgetnameinfo => %s, %s\n", hbuf, pbuf); -- } -- freeaddrinfo(ap); -- return 0; --} -diff --git a/src/tests/resolve/deps b/src/tests/resolve/deps -deleted file mode 100644 -index 762d9adab..000000000 ---- a/src/tests/resolve/deps -+++ /dev/null -@@ -1,14 +0,0 @@ --# --# Generated makefile dependencies follow. --# --$(OUTPRE)resolve.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-thread.h \ -- resolve.c --$(OUTPRE)addrinfo-test.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-thread.h \ -- addrinfo-test.c --$(OUTPRE)fake-addrinfo-test.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(top_srcdir)/include/fake-addrinfo.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h addrinfo-test.c \ -- fake-addrinfo-test.c -diff --git a/src/tests/resolve/fake-addrinfo-test.c b/src/tests/resolve/fake-addrinfo-test.c -deleted file mode 100644 -index 86365a5ba..000000000 ---- a/src/tests/resolve/fake-addrinfo-test.c -+++ /dev/null -@@ -1,3 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --#define USE_FAKE_ADDRINFO --#include "addrinfo-test.c" -diff --git a/src/tests/resolve/resolve.c b/src/tests/resolve/resolve.c -deleted file mode 100644 -index ea0239113..000000000 ---- a/src/tests/resolve/resolve.c -+++ /dev/null -@@ -1,115 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* tests/resolve/resolve.c */ --/* -- * Copyright 1995 by the Massachusetts Institute of Technology. -- * All Rights Reserved. -- * -- * Export of this software from the United States of America may -- * require a specific license from the United States Government. -- * It is the responsibility of any person or organization contemplating -- * export to obtain such a license before exporting. -- * -- * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and -- * distribute this software and its documentation for any purpose and -- * without fee is hereby granted, provided that the above copyright -- * notice appear in all copies and that both that copyright notice and -- * this permission notice appear in supporting documentation, and that -- * the name of M.I.T. not be used in advertising or publicity pertaining -- * to distribution of the software without specific, written prior -- * permission. Furthermore if you modify this software you must label -- * your software as modified software and not distribute it in such a -- * fashion that it might be confused with the original M.I.T. software. -- * M.I.T. makes no representations about the suitability of -- * this software for any purpose. It is provided "as is" without express -- * or implied warranty. -- */ -- --/* -- * A simple program to test the functionality of the resolver library. -- * It simply will try to get the IP address of the host, and then look -- * up the name from the address. If the resulting name does not contain the -- * domain name, then the resolve library is broken. -- * -- * Warning: It is possible to fool this program into thinking everything is -- * alright by a clever use of /etc/hosts - but this is better than nothing. -- * -- * Usage: -- * resolve [hostname] -- * -- * When invoked with no arguments, gethostname is used for the local host. -- * -- */ -- --/* This program tests the resolve library and sees if it is broken... */ -- --#include "k5-platform.h" --#include --#include --#include --#include --#ifdef HAVE_SYS_PARAM_H --#include --#endif -- --int --main(int argc, char **argv) --{ -- struct addrinfo *ai = NULL, hint; -- char myname[MAXHOSTNAMELEN + 1], namebuf[NI_MAXHOST], abuf[256]; -- const char *addrstr; -- int err, quiet = 0; -- -- argc--; argv++; -- while (argc) { -- if ((strcmp(*argv, "--quiet") == 0) || -- (strcmp(*argv, "-q") == 0)) { -- quiet++; -- } else -- break; -- argc--; argv++; -- } -- -- if (argc >= 1) { -- strlcpy(myname, *argv, sizeof(myname)); -- } else { -- if(gethostname(myname, MAXHOSTNAMELEN)) { -- perror("gethostname failure"); -- exit(1); -- } -- } -- -- myname[MAXHOSTNAMELEN] = '\0'; /* for safety */ -- -- /* Look up the address... */ -- if (!quiet) -- printf("Hostname: %s\n", myname); -- -- memset(&hint, 0, sizeof(hint)); -- hint.ai_flags = AI_CANONNAME; -- err = getaddrinfo(myname, 0, &hint, &ai); -- if (err) { -- fprintf(stderr, -- "Could not look up address for hostname '%s' - fatal\n", -- myname); -- exit(2); -- } -- -- if (!quiet) { -- addrstr = inet_ntop(ai->ai_family, ai->ai_addr, abuf, sizeof(abuf)); -- if (addrstr != NULL) -- printf("Host address: %s\n", addrstr); -- } -- -- err = getnameinfo(ai->ai_addr, ai->ai_addrlen, namebuf, sizeof(namebuf), -- NULL, 0, NI_NAMEREQD); -- if (err && !quiet) -- fprintf(stderr, "Error looking up IP address\n"); -- -- printf("%s%s\n", quiet ? "" : "FQDN: ", err ? ai->ai_canonname : namebuf); -- -- if (!quiet) -- printf("Resolve library appears to have passed the test\n"); -- -- freeaddrinfo(ai); -- return 0; --} diff --git a/Replace-gssrpc-tests-with-a-Python-script.patch b/Replace-gssrpc-tests-with-a-Python-script.patch deleted file mode 100644 index 3481a87..0000000 --- a/Replace-gssrpc-tests-with-a-Python-script.patch +++ /dev/null @@ -1,861 +0,0 @@ -From 1de586b414104a447a50ffb6f81c2f57ed3d3a34 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sat, 15 Feb 2020 20:34:23 -0500 -Subject: [PATCH] Replace gssrpc tests with a Python script - -Replace the dejagnu RPC test framework with a short Python script to -do the same tests as fullrun.exp and gsserr.exp. Modify the server -test program to facilitate use by k5test.py. - -expire.exp, together with a comment in the client test program, was -designed to test a libdb2 btree bug via the gssrpc server-side -authentication code. That code was subsequently changed not to use -libdb2, before it was merged into the main krb5 tree (in revision 1.23 -of svc_auth_gssapi.c, according to the changelog removed in commit -2a43d772be1e45faa8e488d436b6e867371563fb). Remove the comment and do -not replace that test sequence. - -[rharwood@redhat.com: .gitignore] ---- - src/configure.ac | 2 - - src/lib/rpc/unit-test/Makefile.in | 36 +-- - src/lib/rpc/unit-test/client.c | 26 --- - src/lib/rpc/unit-test/config/unix.exp | 176 -------------- - src/lib/rpc/unit-test/lib/helpers.exp | 234 ------------------- - src/lib/rpc/unit-test/rpc_test.0/expire.exp | 49 ---- - src/lib/rpc/unit-test/rpc_test.0/fullrun.exp | 91 -------- - src/lib/rpc/unit-test/rpc_test.0/gsserr.exp | 30 --- - src/lib/rpc/unit-test/server.c | 13 +- - src/lib/rpc/unit-test/t_rpc.py | 29 +++ - 10 files changed, 41 insertions(+), 645 deletions(-) - delete mode 100644 src/lib/rpc/unit-test/config/unix.exp - delete mode 100644 src/lib/rpc/unit-test/lib/helpers.exp - delete mode 100644 src/lib/rpc/unit-test/rpc_test.0/expire.exp - delete mode 100644 src/lib/rpc/unit-test/rpc_test.0/fullrun.exp - delete mode 100644 src/lib/rpc/unit-test/rpc_test.0/gsserr.exp - create mode 100644 src/lib/rpc/unit-test/t_rpc.py - -diff --git a/src/configure.ac b/src/configure.ac -index 29be532cb..aafc462f9 100644 ---- a/src/configure.ac -+++ b/src/configure.ac -@@ -1102,8 +1102,6 @@ extern void endrpcent();], - AC_MSG_RESULT($k5_cv_type_endrpcent) - AC_DEFINE_UNQUOTED(ENDRPCENT_TYPE, $k5_cv_type_endrpcent, [Define as return type of endrpcent]) - K5_GEN_FILE(include/gssrpc/types.h:include/gssrpc/types.hin) --PASS=tcp --AC_SUBST(PASS) - - # for pkinit - AC_ARG_ENABLE([pkinit], -diff --git a/src/lib/rpc/unit-test/Makefile.in b/src/lib/rpc/unit-test/Makefile.in -index 0b6e5203d..309ae2b21 100644 ---- a/src/lib/rpc/unit-test/Makefile.in -+++ b/src/lib/rpc/unit-test/Makefile.in -@@ -16,10 +16,6 @@ server: server.o rpc_test_svc.o $(GSSRPC_DEPLIBS) $(KRB5_BASE_DEPLIBS) - - client.o server.o: rpc_test.h - --runenv.exp: Makefile -- $(RUN_SETUP); for i in $(RUN_VARS); do \ -- eval echo "set env\($$i\) \$$$$i"; done > runenv.exp -- - # If rpc_test.h and rpc_test_*.c do not work on your system, you can - # try using rpcgen by uncommenting these lines (be sure to uncomment - # then in the generated not Makefile.in). -@@ -34,37 +30,9 @@ runenv.exp: Makefile - # rm -f rpc_test.h rpc_test_clnt.c rpc_test_svc.c - # - --check unit-test: unit-test-@DO_TEST@ -- --unit-test-: -- @echo "+++" -- @echo "+++ WARNING: lib/rpc unit tests not run." -- @echo "+++ Either tcl, runtest, or Perl is unavailable." -- @echo "+++" -- @echo 'Skipped rpc tests: runtest or Perl not found' >> $(SKIPTESTS) -- --unit-test-ok: unit-test-body -- --PASS=@PASS@ --unit-test-body: runenv.sh runenv.exp -- $(RM) krb5cc_rpc_test_* -- $(ENV_SETUP) $(VALGRIND) $(START_SERVERS) -- RPC_TEST_KEYTAB=/tmp/rpc_test_keytab.$$$$ ; export RPC_TEST_KEYTAB ; \ -- trap "echo Failed, cleaning up... ; rm -f $$RPC_TEST_KEYTAB ; $(ENV_SETUP) $(STOP_SERVERS) ; trap '' 0 ; exit 1" 0 1 2 3 14 15 ; \ -- if $(ENV_SETUP) \ -- $(RUNTEST) SERVER=./server CLIENT=./client \ -- KINIT=$(BUILDTOP)/clients/kinit/kinit \ -- KDESTROY=$(BUILDTOP)/clients/kdestroy/kdestroy \ -- PRIOCNTL_HACK=@PRIOCNTL_HACK@ VALGRIND="$(VALGRIND)" \ -- PASS="$(PASS)" --tool rpc_test $(RUNTESTFLAGS) ; \ -- then \ -- echo Cleaning up... ; \ -- rm -f $$RPC_TEST_KEYTAB krb5cc_rpc_test_* ; \ -- $(ENV_SETUP) $(STOP_SERVERS) ; \ -- trap 0 ; exit 0 ; \ -- else exit 1 ; fi -+check-pytests: -+ $(RUNPYTEST) $(srcdir)/t_rpc.py $(PYTESTFLAGS) - - clean: - $(RM) server client -- $(RM) dbg.log rpc_test.log rpc_test.sum runenv.exp - -diff --git a/src/lib/rpc/unit-test/client.c b/src/lib/rpc/unit-test/client.c -index 5edde49df..c9a812bc5 100644 ---- a/src/lib/rpc/unit-test/client.c -+++ b/src/lib/rpc/unit-test/client.c -@@ -231,32 +231,6 @@ main(argc, argv) - else - gssrpc_xdr_free(xdr_wrapstring, echo_resp); - -- /* -- * Test fix for secure-rpc/586, part 1: btree keys must be -- * unique. Create another context from the same credentials; it -- * should have the same expiration time and will cause the server -- * to abort if the clients are not differentiated. -- * -- * Test fix for secure-rpc/586, part 2: btree keys cannot be -- * mutated in place. To test this: a second client, *with a -- * later expiration time*, must be run. The second client should -- * destroy itself *after* the first one; if the key-mutating bug -- * is not fixed, the second client_data will be in the btree -- * before the first, but its key will be larger; thus, when the -- * first client calls AUTH_DESTROY, the server won't find it in -- * the btree and call abort. -- * -- * For unknown reasons, running just a second client didn't -- * tickle the bug; the btree code seemed to guess which node to -- * look at first. Running a total of three clients does ticket -- * the bug. Thus, the full test sequence looks like this: -- * -- * kinit -l 20m user && client server test@ddn 200 -- * sleep 1 -- * kini -l 30m user && client server test@ddn 300 -- * sleep 1 -- * kinit -l 40m user && client server test@ddn 400 -- */ - if (! auth_once) { - tmp_auth = clnt->cl_auth; - clnt->cl_auth = auth_gssapi_create_default(clnt, target); -diff --git a/src/lib/rpc/unit-test/config/unix.exp b/src/lib/rpc/unit-test/config/unix.exp -deleted file mode 100644 -index 18da62be4..000000000 ---- a/src/lib/rpc/unit-test/config/unix.exp -+++ /dev/null -@@ -1,176 +0,0 @@ --# --# $Id$ --# -- --source runenv.exp -- --set kill /bin/kill --set sleep /bin/sleep --set kinit $KINIT --set kdestroy $KDESTROY -- --set hostname [exec hostname] -- --# Hack around Solaris 9 kernel race condition that causes last output --# from a pty to get dropped. --if { $PRIOCNTL_HACK } { -- catch {exec priocntl -s -c FX -m 30 -p 30 -i pid [getpid]} -- rename spawn oldspawn -- proc spawn { args } { -- upvar 1 spawn_id spawn_id -- set newargs {} -- set inflags 1 -- set eatnext 0 -- foreach arg $args { -- if { $arg == "-ignore" \ -- || $arg == "-open" \ -- || $arg == "-leaveopen" } { -- lappend newargs $arg -- set eatnext 1 -- continue -- } -- if [string match "-*" $arg] { -- lappend newargs $arg -- continue -- } -- if { $eatnext } { -- set eatnext 0 -- lappend newargs $arg -- continue -- } -- if { $inflags } { -- set inflags 0 -- set newargs [concat $newargs {priocntl -e -c FX -p 0}] -- } -- lappend newargs $arg -- } -- set pid [eval oldspawn $newargs] -- return $pid -- } --} -- --if { [string length $VALGRIND] } { -- rename spawn valgrind_aux_spawn -- proc spawn { args } { -- global VALGRIND -- upvar 1 spawn_id spawn_id -- set newargs {} -- set inflags 1 -- set eatnext 0 -- foreach arg $args { -- if { $arg == "-ignore" \ -- || $arg == "-open" \ -- || $arg == "-leaveopen" } { -- lappend newargs $arg -- set eatnext 1 -- continue -- } -- if [string match "-*" $arg] { -- lappend newargs $arg -- continue -- } -- if { $eatnext } { -- set eatnext 0 -- lappend newargs $arg -- continue -- } -- if { $inflags } { -- set inflags 0 -- # Only run valgrind for local programs, not -- # system ones. --#&&![string match "/bin/sh" $arg] sh is used to start kadmind! -- if [string match "/" [string index $arg 0]]&&![string match "/bin/ls" $arg]&&![regexp {/kshd$} $arg] { -- set newargs [concat $newargs $VALGRIND] -- } elseif [string match "." [string index $arg 0]] { -- set newargs [concat $newargs $VALGRIND] -- } -- } -- lappend newargs $arg -- } -- set pid [eval valgrind_aux_spawn $newargs] -- return $pid -- } --} -- --# this will initialize the database and keytab --load_lib "helpers.exp" -- --proc rpc_test_version {} { -- global CLIENT -- global SERVER -- -- clone_output "$CLIENT version " -- clone_output "$SERVER version " --} -- --proc rpc_test_load {} { -- # --} -- --# rpc_test_exit -- clean up and exit --proc rpc_test_exit {} { -- global server_id -- global server_pid -- global server_started -- global kill -- -- if {[catch { -- expect { -- -i $server_id -- eof { -- fail "server exited!" -- verbose $expect_out(buffer) 1 -- } -- timeout { pass "server survived" } -- } -- } tmp]} { -- fail "server exited! (expect failed)" -- } --} -- --# --# rpc_test_start -- start the rpc_test server running --# --proc rpc_test_start { } { -- global SERVER PROT -- global server_id -- global server_pid -- global server_started -- global server_port -- global env -- -- if [info exists server_pid] { rpc_test_exit } -- -- set env(KRB5_KTNAME) FILE:$env(RPC_TEST_KEYTAB) -- -- verbose "% $SERVER" 1 -- set server_pid [spawn $SERVER $PROT] -- set server_id $spawn_id -- set server_started 1 -- set server_port -1 -- -- unset env(KRB5_KTNAME) -- -- set timeout 30 -- -- expect { -- -re "port: (\[0-9\]*)\r\n" { -- set server_port $expect_out(1,string) -- } -- "running" { } -- eof { -- send_error "server exited!" -- verbose $expect_out(buffer) 1 -- } -- timeout { -- send_error "server didn't start in $timeout seconds" -- verbose $expect_out(buffer) 1 -- } -- } -- --} -- --set MULTIPASS { -- {tcp PROT=-t dummy=[rpc_test_start]} -- {udp PROT=-u dummy=[rpc_test_start]} --} -diff --git a/src/lib/rpc/unit-test/lib/helpers.exp b/src/lib/rpc/unit-test/lib/helpers.exp -deleted file mode 100644 -index eb2797c53..000000000 ---- a/src/lib/rpc/unit-test/lib/helpers.exp -+++ /dev/null -@@ -1,234 +0,0 @@ --if {[info commands exp_version] != {}} { -- set exp_version_4 [regexp {^4} [exp_version]] --} else { -- set exp_version_4 [regexp {^4} [expect_version]] --} -- --# Backward compatibility until we're using expect 5 everywhere --if {$exp_version_4} { -- global wait_error_index wait_errno_index wait_status_index -- set wait_error_index 0 -- set wait_errno_index 1 -- set wait_status_index 1 --} else { -- set wait_error_index 2 -- set wait_errno_index 3 -- set wait_status_index 3 --} -- --proc set_from_env {varname default_value} { -- global env -- upvar $varname v -- -- if [info exists env($varname)] { -- set v $env($varname) -- } else { -- set v $default_value -- } --} --proc expect_tcl_prompt {} { -- global kadmin_tcl_spawn_id -- expect { -- -i $kadmin_tcl_spawn_id -- -re "^% $" { } -- -re . { perror "unexpected output {$expect_out(buffer)} from subprocess, expecting tcl prompt" } -- timeout { perror "timeout waiting for tcl prompt" } -- eof { perror "eof from subprocess when expecting tcl prompt" } -- } --} --proc send_tcl_cmd_await_echo {cmd} { -- global kadmin_tcl_spawn_id -- send -i $kadmin_tcl_spawn_id "$cmd\n" -- expect { -- -i $kadmin_tcl_spawn_id -- -ex "$cmd\r\n" { } -- timeout { perror "timeout waiting for tcl subprocess to echo input" } -- eof { perror "eof waiting for tcl subprocess to echo input" } -- } --} --proc expect_kadm_ok {} { -- global kadmin_tcl_spawn_id -- expect { -- -i $kadmin_tcl_spawn_id -- -re "^OK KADM5_OK \[^\n\]*\n" {} -- -re "^ERROR \[^\n\]*\n" { perror "kadmin tcl subprocess reported unexpected error" } -- -re "^marshall_new_creds: \[^\n\]*\n" { exp_continue } -- -re "^gssapi_\[^\n\]*\n" { exp_continue } -- -re "^\r?\n" { exp_continue } -- eof { perror "kadmin tcl subprocess died" } -- default { perror "didn't get ok back" } -- } --} --proc setup_database {} { -- global env spawn_id kadmin_tcl_spawn_id TESTDIR CANON_HOST -- -- # XXXXX -- set_from_env TOP {/x/x/x/x/x} -- send_user "TOP=$TOP\n" -- -- set_from_env TESTDIR $env(TOP)/testing -- set_from_env CLNTTCL $TESTDIR/util/kadm5_clnt_tcl -- set_from_env TCLUTIL $TESTDIR/tcl/util.t -- set env(TCLUTIL) $TCLUTIL -- set env(PATH) "$TOP/install/admin:$env(PATH)" -- -- # $VERBOSE ? -- -- if [info exists spawn_id] { set x $spawn_id } -- spawn $CLNTTCL -- set kadmin_tcl_spawn_id $spawn_id -- if [info exists x] { set spawn_id $x } -- -- expect_tcl_prompt -- # tcl 8.4 for some reason screws up autodetection of output EOL -- # translation. Work around it for now. -- send_tcl_cmd_await_echo "if { \[info commands fconfigure\] != \"\" } { fconfigure stdout -translation lf }" -- expect_tcl_prompt -- send_tcl_cmd_await_echo "source {$TCLUTIL}" -- expect_tcl_prompt -- send_tcl_cmd_await_echo "set h {$CANON_HOST}" -- expect { -- -ex "$CANON_HOST\r\n" { } -- timeout { perror "timeout waiting for subprocess" } -- eof { perror "eof from subprocess" } -- } -- expect_tcl_prompt -- -- send_tcl_cmd_await_echo {kadm5_init admin admin $KADM5_ADMIN_SERVICE null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 server_handle} -- expect_kadm_ok -- expect "^% " -- send_tcl_cmd_await_echo {kadm5_create_principal $server_handle [simple_principal server/$h] {KADM5_PRINCIPAL} admin} -- expect_kadm_ok -- expect "^% " -- send_tcl_cmd_await_echo {kadm5_randkey_principal $server_handle server/$h key null} -- expect_kadm_ok -- expect "^% " -- send_tcl_cmd_await_echo {kadm5_create_principal $server_handle [simple_principal notserver/$h] {KADM5_PRINCIPAL} admin} -- expect_kadm_ok -- expect "^% " -- send_tcl_cmd_await_echo {kadm5_randkey_principal $server_handle notserver/$h key null} -- expect_kadm_ok -- expect "^% " -- send_tcl_cmd_await_echo {kadm5_destroy $server_handle} -- expect_kadm_ok -- expect "^% " -- wait -nowait -i $spawn_id -- close -i $spawn_id --} -- --if ![info exists CANON_HOST] { -- set CANON_HOST $env(QUALNAME) -- setup_database -- file delete $env(RPC_TEST_KEYTAB) -- exec $env(TOP)/cli/kadmin -p admin -w admin ktadd -k $env(RPC_TEST_KEYTAB) server/$CANON_HOST --} -- -- --proc kinit {princ pass lifetime} { -- global kinit -- global wait_error_index wait_errno_index wait_status_index -- -- spawn -noecho $kinit -5 -l $lifetime $princ -- expect { -- -re "Password for $princ.*: " { send "$pass\n"; expect eof } -- timeout { perror "Timeout waiting for kinit"; close } -- eof -- } -- -- set ret [wait] -- if {[lindex $ret $wait_error_index] == -1} { -- perror \ -- "wait(kinit $princ) returned error [lindex $ret $wait_errno_index]" -- } else { -- if {[lindex $ret $wait_status_index] != 0} { -- perror \ -- "kinit $princ failed with [lindex $ret $wait_status_index]" -- } -- } --} -- --proc flush_server {} { -- global server_id -- global expect_out -- -- verbose "flushing server output" 1 -- -- while {1} { -- set timeout 5 -- -- expect { -- -i $server_id -- -re "^.+$" { -- verbose "server output: $expect_out(buffer)" -- } -- timeout { break } -- } -- } --} -- --proc start_client {testname ccname user password lifetime count -- {target ""}} { -- global env CLIENT PROT hostname server_port spawn_id verbose -- -- if {$target == ""} { -- set target "server@$hostname" -- } -- -- set env(KRB5CCNAME) FILE:[pwd]/krb5cc_rpc_test_$ccname -- kinit $user $password $lifetime -- -- if {$verbose > 0} { -- spawn $CLIENT -a 1 -s 1 -m 1 $PROT $hostname $server_port $target $count -- } else { -- spawn $CLIENT $PROT $hostname $server_port $target $count -- } -- -- verbose "$testname: client $ccname started" -- -- unset env(KRB5CCNAME) --} -- --proc eof_client {testname ccname id status} { -- verbose "$testname: eof'ing for client $ccname" 1 -- -- expect { -- -i $id -- -re "^marshall_new_creds\[^\n\]*\n" { exp_continue } -- -re "^gssapi_\[^\n\]*\n" { exp_continue } -- -re "^\r?\n" { exp_continue } -- eof { verbose $expect_out(buffer) 1 } -- timeout { -- fail "$testname: timeout waiting for client $ccname to exit" -- } -- } -- wait_client $testname $ccname $id $status --} -- -- --proc wait_client {testname ccname id status} { -- global env -- global kill -- global kdestroy -- global wait_error_index wait_errno_index wait_status_index -- -- verbose "$testname: waiting for client $ccname" 1 -- -- set ret [wait -i $id] -- if {[lindex $ret $wait_error_index] == -1} { -- fail \ -- "$testname: wait $ccname returned error [lindex $ret $wait_errno_index]" -- } else { -- if {[lindex $ret $wait_status_index] == $status} { -- pass "$testname: client $ccname" -- } else { -- fail "$testname: client $ccname: unexpected return status [lindex $ret $wait_status_index], should be $status." -- } -- } -- -- set env(KRB5CCNAME) FILE:[pwd]/krb5cc_rpc_test_$ccname -- if {[catch "exec $kdestroy -5"] != 0} { -- perror "$testname: cannot destroy client $ccname ccache" -- } -- -- unset env(KRB5CCNAME) --} -diff --git a/src/lib/rpc/unit-test/rpc_test.0/expire.exp b/src/lib/rpc/unit-test/rpc_test.0/expire.exp -deleted file mode 100644 -index e19cca0ef..000000000 ---- a/src/lib/rpc/unit-test/rpc_test.0/expire.exp -+++ /dev/null -@@ -1,49 +0,0 @@ --set timeout 40 -- --load_lib "helpers.exp" -- --global server_started -- --proc expired {} { -- global spawn_id server_id -- -- start_client expired expired testuser notathena -1m 100 -- eof_client expired expired $spawn_id 2 -- -- expect { -- -i $server_id -- -re "rpc_test server: Authen.*failed:.*credential.*expired" { pass "expired" } -- timeout { fail "expired: timeout waiting for expired creds error" } -- } -- -- flush_server --} -- --# This test doesn't work after #6948, because the client won't try to --# authenticate using an expired TGT. --#if { $server_started } {expired } -- --proc overlap {} { -- global spawn_id -- -- start_client expire 1 testuser notathena 20m 100 -- set client1_id $spawn_id -- flush_server -- -- start_client expire 2 testuser notathena 40m 300 -- set client2_id $spawn_id -- flush_server -- -- start_client expire 3 testuser notathena 60m 500 -- set client3_id $spawn_id -- flush_server -- -- eof_client expire 1 $client1_id 0 -- eof_client expire 2 $client2_id 0 -- eof_client expire 3 $client3_id 0 -- -- flush_server --} --if { $server_started } {overlap} -- -- -diff --git a/src/lib/rpc/unit-test/rpc_test.0/fullrun.exp b/src/lib/rpc/unit-test/rpc_test.0/fullrun.exp -deleted file mode 100644 -index 73083de1f..000000000 ---- a/src/lib/rpc/unit-test/rpc_test.0/fullrun.exp -+++ /dev/null -@@ -1,91 +0,0 @@ --set timeout 120 -- --load_lib "helpers.exp" -- --global spawn_id --global server_id --global server_started -- --if { !$server_started } {return} -- --# Start the client and do a full run --start_client "full run" fullrun testuser notathena 8h 1026 --set client_id $spawn_id -- --# --# test: did we get 11 dots? --# --verbose "Starting RPC echo test. This will take about 50 seconds.\n" -- --set ver_line "rpc_test server: bad verifier\[^\r\n\]*\[\r\n]+" -- --set dots 0 --set server_lines 0 --while {1} { -- expect { -- -i $server_id -- -re $ver_line { -- verbose "Got line from server." -- incr server_lines -- } -- default { -- exp_continue -- } -- -- -i $client_id -- . { -- incr dots -- verbose "$expect_out(buffer)" 1 -- if ($dots==11) { break } -- } -- eof { -- # -- # test: was the exit status right? -- # -- wait_client "full run" fullrun $client_id 0 -- break -- } -- -- timeout { -- verbose "Timeout waiting for dot\n" 1 -- fail "full run: timeout waiting for dot" -- break -- } -- } --} --if {$dots==11} { -- pass "fullrun: echo test" --} else { -- fail "fullrun: echo test: expected 11 dots, got $dots" --} -- --# --# test: server logged four bad verifiers? --# --verbose "full run: checking server output" -- --# Small timeout, since the server should have already printed everything --set timeout 5 -- --while {$server_lines < 4} { -- expect { -- -i $server_id -- -re $ver_line { -- incr server_lines -- } -- -re ".+\r\n" { -- verbose "Unexpected server output: $expect_out(buffer)" -- } -- default { -- break -- } -- } --} -- --if {$server_lines == 4} { -- pass "fullrun: bad verifiers" --} else { -- fail "fullrun: expected four bad verifiers, got $server_lines" --} -- --flush_server -diff --git a/src/lib/rpc/unit-test/rpc_test.0/gsserr.exp b/src/lib/rpc/unit-test/rpc_test.0/gsserr.exp -deleted file mode 100644 -index 005971989..000000000 ---- a/src/lib/rpc/unit-test/rpc_test.0/gsserr.exp -+++ /dev/null -@@ -1,30 +0,0 @@ --set timeout 30 -- --load_lib "helpers.exp" -- --global spawn_id --global server_id --global server_started --global hostname -- --if { !$server_started } {return} -- --start_client "gss err" gsserr testuser notathena 8h 1026 notserver@$hostname -- --eof_client "gss err" gsserr $spawn_id 2 -- --# --# test: server logged an authentication attempted failed? --# --verbose "gss err: checking server output" -- --expect { -- -i $server_id -- -re "rpc_test server: Authent.*failed: .* not found in keytab" { -- pass "gss err: server logged auth error" -- } -- eof { fail "gss err: server exited" } -- timeout { fail "gss err: timeout waiting for server output" } --} -- --flush_server -diff --git a/src/lib/rpc/unit-test/server.c b/src/lib/rpc/unit-test/server.c -index 13e99bb06..c3bbcbf8c 100644 ---- a/src/lib/rpc/unit-test/server.c -+++ b/src/lib/rpc/unit-test/server.c -@@ -37,7 +37,7 @@ static void rpc_test_badverf(gss_name_t client, gss_name_t server, - caddr_t data); - - #ifndef SERVICE_NAME --#define SERVICE_NAME "server" -+#define SERVICE_NAME "host" - #endif - - static void usage() -@@ -120,7 +120,6 @@ main(int argc, char **argv) - prot == IPPROTO_TCP ? "tcp" : "udp"); - exit(1); - } -- printf("port: %d\n", (int)transp->xp_port); - - if (svcauth_gssapi_set_names(names, 0) == FALSE) { - fprintf(stderr, "unable to set gssapi names\n"); -@@ -144,6 +143,8 @@ main(int argc, char **argv) - signal(SIGTERM, handlesig); - #endif - printf("running\n"); -+ printf("port: %d\n", (int)transp->xp_port); -+ fflush(stdout); - - svc_run(); - fprintf(stderr, "svc_run returned"); -@@ -177,6 +178,7 @@ static void rpc_test_badverf(gss_name_t client, gss_name_t server, - inet_ntoa(rqst->rq_xprt->xp_raddr.sin_addr), - ntohs(rqst->rq_xprt->xp_raddr.sin_port), - (int) server_name.length, (char *) server_name.value); -+ fflush(stdout); - - (void) gss_release_buffer(&minor_stat, &client_name); - (void) gss_release_buffer(&minor_stat, &server_name); -@@ -211,6 +213,7 @@ void rpc_test_badauth(OM_uint32 major, OM_uint32 minor, - printf("rpc_test server: Authentication attempt failed: %s", a); - log_badauth_display_status(major, minor); - printf("\n"); -+ fflush(stdout); - } - - void log_miscerr(struct svc_req *rqst, struct rpc_msg *msg, -@@ -220,6 +223,7 @@ void log_miscerr(struct svc_req *rqst, struct rpc_msg *msg, - - a = inet_ntoa(rqst->rq_xprt->xp_raddr.sin_addr); - printf("Miscellaneous RPC error: %s, %s\n", a, error); -+ fflush(stdout); - } - - void log_badauth_display_status(OM_uint32 major, OM_uint32 minor) -@@ -243,10 +247,12 @@ void log_badauth_display_status_1(OM_uint32 code, int type, int rec) - log_badauth_display_status_1(gssstat,GSS_C_GSS_CODE,1); - log_badauth_display_status_1(minor_stat, - GSS_C_MECH_CODE, 1); -- } else -+ } else { - printf("GSS-API authentication error %.*s: " - "recursive failure!\n", (int) msg.length, - (char *)msg.value); -+ } -+ fflush(stdout); - return; - } - -@@ -256,4 +262,5 @@ void log_badauth_display_status_1(OM_uint32 code, int type, int rec) - if (!msg_ctx) - break; - } -+ fflush(stdout); - } -diff --git a/src/lib/rpc/unit-test/t_rpc.py b/src/lib/rpc/unit-test/t_rpc.py -new file mode 100644 -index 000000000..4e565d25c ---- /dev/null -+++ b/src/lib/rpc/unit-test/t_rpc.py -@@ -0,0 +1,29 @@ -+import re -+ -+from k5test import * -+ -+realm = K5Realm() -+ -+server = realm.start_server(['./server', '-t'], 'running') -+line = server.stdout.readline() -+portstr = re.match(r'^port: (\d+)$', line).group(1) -+ -+realm.run(['./client', '-t', hostname, portstr, 'host@' + hostname, '1026'], -+ expected_msg='...........') -+ -+for i in range(4): -+ line = server.stdout.readline() -+ if 'rpc_test server: bad verifier from user@KRBTEST.COM at ' not in line: -+ fail('unexpected server message: ' + line) -+ output(line) -+ -+realm.addprinc('nokey/' + hostname) -+ -+realm.run(['./client', '-t', hostname, portstr, 'nokey@' + hostname, '1026'], -+ expected_code=2) -+ -+line = server.stdout.readline() -+if 'rpc_test server: Authentication attempt failed: ' not in line: -+ fail('unexpected server message: ' + line) -+ -+success('gssrpc auth_gssapi tests') diff --git a/Use-two-queues-for-concurrent-t_otp.py-daemons.patch b/Use-two-queues-for-concurrent-t_otp.py-daemons.patch deleted file mode 100644 index 80093f3..0000000 --- a/Use-two-queues-for-concurrent-t_otp.py-daemons.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 35d041e432ea6d4611b232cc9bb72a36552eda27 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 4 Mar 2020 17:18:51 -0500 -Subject: [PATCH] Use two queues for concurrent t_otp.py daemons - -t_otp.py occasionally fails during the #8708 regression test, reading -a true answer instead of the expected false answer during the first -verify() call. Most likely the daemons are writing their answers to -the shared queue out of order. Use a separate queue for the second -daemon to ensure correct correlation of results. - -(cherry picked from commit c03f67eefec05db19e84e889fab7c25904929633) ---- - src/tests/t_otp.py | 7 ++++--- - 1 file changed, 4 insertions(+), 3 deletions(-) - -diff --git a/src/tests/t_otp.py b/src/tests/t_otp.py -index cba871a0f..c3b820a41 100755 ---- a/src/tests/t_otp.py -+++ b/src/tests/t_otp.py -@@ -256,16 +256,17 @@ verify(daemon, queue, True, realm.user_princ, 'accept') - ## tokens configured, with the first rejecting and the second - ## accepting. With the bug, the KDC incorrectly rejects the request - ## and then performs invalid memory accesses, most likely crashing. -+queue2 = Queue() - daemon1 = UDPRadiusDaemon(args=(server_addr, secret_file, 'accept1', queue)) --daemon2 = UnixRadiusDaemon(args=(socket_file, None, 'accept2', queue)) -+daemon2 = UnixRadiusDaemon(args=(socket_file, None, 'accept2', queue2)) - daemon1.start() - queue.get() - daemon2.start() --queue.get() -+queue2.get() - oconf = '[' + otpconfig_1('udp') + ', ' + otpconfig_1('unix') + ']' - realm.run([kadminl, 'setstr', realm.user_princ, 'otp', oconf]) - realm.kinit(realm.user_princ, 'accept2', flags=flags) - verify(daemon1, queue, False, realm.user_princ.split('@')[0], 'accept2') --verify(daemon2, queue, True, realm.user_princ, 'accept2') -+verify(daemon2, queue2, True, realm.user_princ, 'accept2') - - success('OTP tests') diff --git a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index 3d0cd46..6d74df5 100644 --- a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From 3a83d2b4c2a3eea5dde8de883ee9b41630a6a487 Mon Sep 17 00:00:00 2001 +From 146967416993f66c3ba32cbf3881e43e7bc1ed1c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 @@ -39,10 +39,10 @@ Last-updated: krb5-1.17 15 files changed, 151 insertions(+), 33 deletions(-) diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 1d2aa7f68..3a8b9cf47 100644 +index e4e2443ed..af3df5871 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst -@@ -331,6 +331,12 @@ The libdefaults section may contain any of the following relations: +@@ -330,6 +330,12 @@ The libdefaults section may contain any of the following relations: qualification of shortnames, set this relation to the empty string with ``qualify_shortname = ""``. (New in release 1.18.) @@ -111,7 +111,7 @@ index 2da691329..f79679a0b 100644 state->data = (void *) malloc(16); if (state->data == NULL) diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c -index a65d57b7a..6ccaca94a 100644 +index bc87c6f42..9bf407899 100644 --- a/src/lib/crypto/openssl/enc_provider/rc4.c +++ b/src/lib/crypto/openssl/enc_provider/rc4.c @@ -66,6 +66,9 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, @@ -349,7 +349,7 @@ index 03c613716..d89982a13 100644 return retval; diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h -index 996a89372..312dc8258 100644 +index 0143d155a..223ffd730 100644 --- a/src/lib/krad/internal.h +++ b/src/lib/krad/internal.h @@ -39,6 +39,8 @@ @@ -475,7 +475,7 @@ index c597174b6..fc2d24800 100644 } diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c -index 437f7e91a..0f90443ce 100644 +index c96a9b4ee..eca432424 100644 --- a/src/lib/krad/remote.c +++ b/src/lib/krad/remote.c @@ -263,7 +263,7 @@ on_io_write(krad_remote *rr) diff --git a/downstream-Remove-3des-support.patch b/downstream-Remove-3des-support.patch index ae4124f..1bf529e 100644 --- a/downstream-Remove-3des-support.patch +++ b/downstream-Remove-3des-support.patch @@ -1,4 +1,4 @@ -From 0ef71d2bef3efcb38b20fc8b3050944286ada726 Mon Sep 17 00:00:00 2001 +From 3af536f114e1c1b33b1579f9f16bbb3f497d4a1d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] [downstream] Remove 3des support @@ -8,11 +8,11 @@ des3-hmac-sha1, des3-cbc-sha1-kd). Update all tests and documentation to user other enctypes. Mark the 3DES enctypes UNSUPPORTED and retain their constants. -Last-updated: 1.18-beta2 +Last-updated: 1.19-beta1 --- doc/admin/advanced/retiring-des.rst | 11 + doc/admin/conf_files/kdc_conf.rst | 7 +- - doc/admin/enctypes.rst | 13 +- + doc/admin/enctypes.rst | 10 +- doc/admin/troubleshoot.rst | 9 +- doc/appdev/refs/macros/index.rst | 1 - doc/conf.py | 2 +- @@ -28,7 +28,7 @@ Last-updated: 1.18-beta2 src/lib/crypto/builtin/des/Makefile.in | 80 ---- src/lib/crypto/builtin/des/d3_aead.c | 133 ------ src/lib/crypto/builtin/des/d3_kysched.c | 51 --- - src/lib/crypto/builtin/des/deps | 148 ------- + src/lib/crypto/builtin/des/deps | 150 ------- src/lib/crypto/builtin/des/des_int.h | 285 ------------- src/lib/crypto/builtin/des/des_keys.c | 40 -- src/lib/crypto/builtin/des/destest.c | 240 ----------- @@ -45,7 +45,7 @@ Last-updated: 1.18-beta2 src/lib/crypto/builtin/des/t_verify.c | 395 ------------------ src/lib/crypto/builtin/des/weak_key.c | 86 ---- .../crypto/builtin/enc_provider/Makefile.in | 6 +- - src/lib/crypto/builtin/enc_provider/deps | 12 - + src/lib/crypto/builtin/enc_provider/deps | 13 - src/lib/crypto/builtin/enc_provider/des3.c | 105 ----- src/lib/crypto/crypto_tests/t_cf2.expected | 1 - src/lib/crypto/crypto_tests/t_cf2.in | 5 - @@ -83,7 +83,6 @@ Last-updated: 1.18-beta2 .../api.current/randkey-principal-v2.exp | 4 +- src/lib/krb5/krb/init_ctx.c | 3 - src/lib/krb5/krb/s4u_creds.c | 2 - - src/lib/krb5/krb/t_copy_context.c | 2 +- src/lib/krb5/krb/t_etypes.c | 48 +-- src/lib/krb5/os/t_trace.c | 4 +- src/lib/krb5/os/t_trace.ref | 2 +- @@ -106,7 +105,7 @@ Last-updated: 1.18-beta2 src/tests/t_salt.py | 5 +- src/util/k5test.py | 7 - .../leash/htmlhelp/html/Encryption_Types.htm | 13 - - 96 files changed, 163 insertions(+), 4834 deletions(-) + 95 files changed, 160 insertions(+), 4835 deletions(-) delete mode 100644 src/lib/crypto/builtin/des/ISSUES delete mode 100644 src/lib/crypto/builtin/des/Makefile.in delete mode 100644 src/lib/crypto/builtin/des/d3_aead.c @@ -135,7 +134,7 @@ Last-updated: 1.18-beta2 delete mode 100644 src/lib/crypto/openssl/enc_provider/des3.c diff --git a/doc/admin/advanced/retiring-des.rst b/doc/admin/advanced/retiring-des.rst -index 4a964c15c..cb6258d77 100644 +index 38f76d3f4..d5e3c30c0 100644 --- a/doc/admin/advanced/retiring-des.rst +++ b/doc/admin/advanced/retiring-des.rst @@ -10,6 +10,13 @@ ability have rendered DES vulnerable to brute force attacks on its 56-bit @@ -164,19 +163,19 @@ index 4a964c15c..cb6258d77 100644 ------------- diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst -index 9759756a2..cf8a12547 100644 +index 1dc958d62..3a72aabef 100644 --- a/doc/admin/conf_files/kdc_conf.rst +++ b/doc/admin/conf_files/kdc_conf.rst -@@ -843,8 +843,6 @@ Encryption types marked as "weak" are available for compatibility but - not recommended for use. +@@ -848,8 +848,6 @@ Encryption types marked as "weak" and "deprecated" are available for + compatibility but not recommended for use. ==================================================== ========================================================= -des3-cbc-raw Triple DES cbc mode raw (weak) --des3-cbc-sha1 des3-hmac-sha1 des3-cbc-sha1-kd Triple DES cbc mode with HMAC/sha1 +-des3-cbc-sha1 des3-hmac-sha1 des3-cbc-sha1-kd Triple DES cbc mode with HMAC/sha1 (deprecated) aes256-cts-hmac-sha1-96 aes256-cts aes256-sha1 AES-256 CTS mode with 96-bit SHA-1 HMAC aes128-cts-hmac-sha1-96 aes128-cts aes128-sha1 AES-128 CTS mode with 96-bit SHA-1 HMAC aes256-cts-hmac-sha384-192 aes256-sha2 AES-256 CTS mode with 192-bit SHA-384 HMAC -@@ -853,7 +851,6 @@ arcfour-hmac rc4-hmac arcfour-hmac-md5 RC4 with HMAC/MD5 +@@ -858,7 +856,6 @@ arcfour-hmac rc4-hmac arcfour-hmac-md5 RC4 with HMAC/MD5 (deprecat arcfour-hmac-exp rc4-hmac-exp arcfour-hmac-md5-exp Exportable RC4 with HMAC/MD5 (weak) camellia256-cts-cmac camellia256-cts Camellia-256 CTS mode with CMAC camellia128-cts-cmac camellia128-cts Camellia-128 CTS mode with CMAC @@ -184,7 +183,7 @@ index 9759756a2..cf8a12547 100644 aes The AES family: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, aes256-cts-hmac-sha384-192, and aes128-cts-hmac-sha256-128 rc4 The RC4 family: arcfour-hmac camellia The Camellia family: camellia256-cts-cmac and camellia128-cts-cmac -@@ -865,8 +862,8 @@ from the current list by prefixing them with a minus sign ("-"). +@@ -870,8 +867,8 @@ from the current list by prefixing them with a minus sign ("-"). Types or families can be prefixed with a plus sign ("+") for symmetry; it has the same meaning as just listing the type or family. For example, "``DEFAULT -rc4``" would be the default set of encryption @@ -196,35 +195,35 @@ index 9759756a2..cf8a12547 100644 While **aes128-cts** and **aes256-cts** are supported for all Kerberos diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst -index caf6d9267..65b55cdb9 100644 +index 047185afb..b08d954d9 100644 --- a/doc/admin/enctypes.rst +++ b/doc/admin/enctypes.rst -@@ -129,7 +129,7 @@ enctype weak? krb5 Windows - des-cbc-crc weak <1.18 >=2000 - des-cbc-md4 weak <1.18 ? - des-cbc-md5 weak <1.18 >=2000 --des3-cbc-sha1 >=1.1 none -+des3-cbc-sha1 <1.18 none - arcfour-hmac >=1.3 >=2000 - arcfour-hmac-exp weak >=1.3 >=2000 - aes128-cts-hmac-sha1-96 >=1.3 >=Vista -@@ -140,7 +140,10 @@ camellia128-cts-cmac >=1.9 none - camellia256-cts-cmac >=1.9 none - ========================== ===== ======== ======= - --krb5 releases 1.18 and later do not support single-DES. krb5 releases --1.8 and later disable the single-DES enctypes by default. Microsoft --Windows releases Windows 7 and later disable single-DES enctypes by --default. -+krb5 releases 1.8 and later disable the single-DES enctypes by -+default. Microsoft Windows releases Windows 7 and later disable -+single-DES enctypes by default. +@@ -129,7 +129,7 @@ enctype weak? krb5 Windows + des-cbc-crc weak <1.18 >=2000 + des-cbc-md4 weak <1.18 ? + des-cbc-md5 weak <1.18 >=2000 +-des3-cbc-sha1 deprecated >=1.1 none ++des3-cbc-sha1 deprecated <1.18 none + arcfour-hmac deprecated >=1.3 >=2000 + arcfour-hmac-exp weak >=1.3 >=2000 + aes128-cts-hmac-sha1-96 >=1.3 >=Vista +@@ -148,9 +148,11 @@ default. + krb5 releases 1.17 and later flag deprecated encryption types + (including ``des3-cbc-sha1`` and ``arcfour-hmac``) in KDC logs and + kadmin output. krb5 release 1.19 issues a warning during initial +-authentication if ``des3-cbc-sha1`` is used. Future releases will +-disable ``des3-cbc-sha1`` by default and eventually remove support for +-it. ++authentication if ``des3-cbc-sha1`` is used. + +krb5 releases 1.18 and later remove single-DES and 3DES +(downstream-only patch) enctype support. Microsoft Windows never +supported 3DES. + + + Migrating away from older encryption types diff --git a/doc/admin/troubleshoot.rst b/doc/admin/troubleshoot.rst -index 6a0c7f89b..263fc9c97 100644 +index ade5e1f87..e4dc54f7e 100644 --- a/doc/admin/troubleshoot.rst +++ b/doc/admin/troubleshoot.rst @@ -73,11 +73,10 @@ credential verification failed: KDC has no support for encryption type @@ -244,7 +243,7 @@ index 6a0c7f89b..263fc9c97 100644 .. _err_cert_chain_cert_expired: diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst -index 68debe714..788d094bf 100644 +index cebb6644c..4d51e795c 100644 --- a/doc/appdev/refs/macros/index.rst +++ b/doc/appdev/refs/macros/index.rst @@ -36,7 +36,6 @@ Public @@ -256,10 +255,10 @@ index 68debe714..788d094bf 100644 CKSUMTYPE_NIST_SHA.rst CKSUMTYPE_RSA_MD4.rst diff --git a/doc/conf.py b/doc/conf.py -index c32b2882a..5eeafc30f 100644 +index 9226b8e01..19cf38326 100644 --- a/doc/conf.py +++ b/doc/conf.py -@@ -272,7 +272,7 @@ else: +@@ -271,7 +271,7 @@ else: rst_epilog += ''' .. |krb5conf| replace:: ``/etc/krb5.conf`` .. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal`` @@ -269,7 +268,7 @@ index c32b2882a..5eeafc30f 100644 .. |copy| unicode:: U+000A9 ''' diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst -index 5d286b6ee..f4594ed13 100644 +index 4954bb3aa..92ce2a772 100644 --- a/doc/mitK5features.rst +++ b/doc/mitK5features.rst @@ -37,7 +37,7 @@ Database backends: LDAP, DB2, LMDB @@ -282,7 +281,7 @@ index 5d286b6ee..f4594ed13 100644 Interoperability ---------------- diff --git a/src/Makefile.in b/src/Makefile.in -index 56c7a4e6f..70db82a30 100644 +index f9270aba2..c958da60f 100644 --- a/src/Makefile.in +++ b/src/Makefile.in @@ -130,7 +130,7 @@ WINMAKEFILES=Makefile \ @@ -304,10 +303,10 @@ index 56c7a4e6f..70db82a30 100644 ##DOS## $(WCONFIG) config < $@.in > $@ ##DOS##lib\crypto\builtin\camellia\Makefile: lib\crypto\builtin\camellia\Makefile.in $(MKFDEP) diff --git a/src/configure.ac b/src/configure.ac -index 440a22bd9..d4e4da525 100644 +index bd151ca26..27c2383d7 100644 --- a/src/configure.ac +++ b/src/configure.ac -@@ -1481,7 +1481,6 @@ V5_AC_OUTPUT_MAKEFILE(. +@@ -1480,7 +1480,6 @@ V5_AC_OUTPUT_MAKEFILE(. lib/crypto lib/crypto/krb lib/crypto/$CRYPTO_IMPL lib/crypto/$CRYPTO_IMPL/enc_provider lib/crypto/$CRYPTO_IMPL/hash_provider @@ -316,7 +315,7 @@ index 440a22bd9..d4e4da525 100644 lib/crypto/$CRYPTO_IMPL/sha1 lib/crypto/$CRYPTO_IMPL/sha2 lib/crypto/$CRYPTO_IMPL/aes lib/crypto/$CRYPTO_IMPL/camellia diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index e9435c693..6355e6540 100644 +index db80063eb..63e67a2ba 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin @@ -426,8 +426,8 @@ typedef struct _krb5_crypto_iov { @@ -365,10 +364,10 @@ index 8a4b87de1..d7f1d076b 100644 + supported_enctypes = aes256-cts:normal aes128-cts:normal aes256-sha2:normal aes128-sha2:normal } diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index ba0ce0b71..e3352f9cc 100644 +index 60f30c4f4..c65375aef 100644 --- a/src/kdc/kdc_util.c +++ b/src/kdc/kdc_util.c -@@ -1103,8 +1103,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) +@@ -1017,8 +1017,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) name = "rsaEncryption-EnvOID"; else if (ktype == ENCTYPE_RSA_ES_OAEP_ENV) name = "id-RSAES-OAEP-EnvOID"; @@ -377,7 +376,7 @@ index ba0ce0b71..e3352f9cc 100644 else return krb5_enctype_to_name(ktype, FALSE, buf, buflen); -@@ -1826,8 +1824,6 @@ krb5_boolean +@@ -1605,8 +1603,6 @@ krb5_boolean enctype_requires_etype_info_2(krb5_enctype enctype) { switch(enctype) { @@ -470,7 +469,7 @@ index 157891103..000000000 -const? diff --git a/src/lib/crypto/builtin/des/Makefile.in b/src/lib/crypto/builtin/des/Makefile.in deleted file mode 100644 -index ed25dab7c..000000000 +index 54b329d0f..000000000 --- a/src/lib/crypto/builtin/des/Makefile.in +++ /dev/null @@ -1,80 +0,0 @@ @@ -527,7 +526,7 @@ index ed25dab7c..000000000 -verify$(EXEEXT): t_verify.$(OBJEXT) $(TOBJS) f_parity.$(OBJEXT) \ - $(COM_ERR_DEPLIB) $(SUPPORT_DEPLIB) - $(CC_LINK) -o $@ t_verify.$(OBJEXT) $(TOBJS) f_parity.$(OBJEXT) \ -- -lcom_err $(SUPPORT_LIB) +- $(COM_ERR_LIB) $(SUPPORT_LIB) - -destest$(EXEEXT): destest.$(OBJEXT) $(TOBJS) $(SUPPORT_DEPLIB) - $(CC_LINK) -o $@ destest.$(OBJEXT) $(TOBJS) $(SUPPORT_LIB) @@ -752,17 +751,18 @@ index ebd1050b1..000000000 -} diff --git a/src/lib/crypto/builtin/des/deps b/src/lib/crypto/builtin/des/deps deleted file mode 100644 -index df2a31dac..000000000 +index a1db1f36e..000000000 --- a/src/lib/crypto/builtin/des/deps +++ /dev/null -@@ -1,148 +0,0 @@ +@@ -1,150 +0,0 @@ -# -# Generated makefile dependencies follow. -# -d3_aead.so d3_aead.po $(OUTPRE)d3_aead.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ -- $(srcdir)/../aes/aes.h $(srcdir)/../crypto_mod.h $(srcdir)/../sha2/sha2.h \ +- $(srcdir)/../aes/aes.h $(srcdir)/../aes/brg_types.h \ +- $(srcdir)/../crypto_mod.h $(srcdir)/../sha2/sha2.h \ - $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ - $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ - $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ @@ -786,19 +786,20 @@ index df2a31dac..000000000 - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ - $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(srcdir)/../aes/aes.h \ -- $(srcdir)/../crypto_mod.h $(srcdir)/../sha2/sha2.h \ -- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- des_int.h des_keys.c +- $(srcdir)/../aes/brg_types.h $(srcdir)/../crypto_mod.h \ +- $(srcdir)/../sha2/sha2.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h des_keys.c -f_aead.so f_aead.po $(OUTPRE)f_aead.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ -- $(srcdir)/../aes/aes.h $(srcdir)/../crypto_mod.h $(srcdir)/../sha2/sha2.h \ +- $(srcdir)/../aes/aes.h $(srcdir)/../aes/brg_types.h \ +- $(srcdir)/../crypto_mod.h $(srcdir)/../sha2/sha2.h \ - $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ - $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ - $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ @@ -1489,7 +1490,7 @@ index 52114304e..000000000 -} diff --git a/src/lib/crypto/builtin/des/doc/libdes.doc b/src/lib/crypto/builtin/des/doc/libdes.doc deleted file mode 100644 -index 19c03c1d3..000000000 +index 6e9431ed2..000000000 --- a/src/lib/crypto/builtin/des/doc/libdes.doc +++ /dev/null @@ -1,208 +0,0 @@ @@ -1644,7 +1645,7 @@ index 19c03c1d3..000000000 - by "*key", then after getting a new key, call the des_set_key() - routine when needed. - -- No meaningfull value is returned. Void is not used for compatibility +- No meaningful value is returned. Void is not used for compatibility - with other compilers. - - @@ -3625,7 +3626,7 @@ index 7ff34eedc..000000000 -1C587F1C13924FEF 305532286D6F295A 63FAC0D034D9F793 diff --git a/src/lib/crypto/builtin/des/t_verify.c b/src/lib/crypto/builtin/des/t_verify.c deleted file mode 100644 -index f4332f5c0..000000000 +index 4a19933ca..000000000 --- a/src/lib/crypto/builtin/des/t_verify.c +++ /dev/null @@ -1,395 +0,0 @@ @@ -3956,7 +3957,7 @@ index f4332f5c0..000000000 - printf("%02x ",cipher_text[j]); - printf("\n\n"); - if ( memcmp((char *)cipher_text, (char *)checksum, 8) ) { -- printf("verify: error in CBC cheksum\n"); +- printf("verify: error in CBC checksum\n"); - exit(-1); - } - else @@ -4150,17 +4151,18 @@ index 3459e1d0e..af6276b96 100644 $(srcdir)/camellia.c \ $(srcdir)/rc4.c diff --git a/src/lib/crypto/builtin/enc_provider/deps b/src/lib/crypto/builtin/enc_provider/deps -index 7a3324c44..c1201cc1a 100644 +index ea4ffecd8..061289a91 100644 --- a/src/lib/crypto/builtin/enc_provider/deps +++ b/src/lib/crypto/builtin/enc_provider/deps -@@ -1,18 +1,6 @@ +@@ -1,19 +1,6 @@ # # Generated makefile dependencies follow. # -des3.so des3.po $(OUTPRE)des3.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ -- $(srcdir)/../aes/aes.h $(srcdir)/../crypto_mod.h $(srcdir)/../des/des_int.h \ +- $(srcdir)/../aes/aes.h $(srcdir)/../aes/brg_types.h \ +- $(srcdir)/../crypto_mod.h $(srcdir)/../des/des_int.h \ - $(srcdir)/../sha2/sha2.h $(top_srcdir)/include/k5-buf.h \ - $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ - $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ @@ -4311,7 +4313,7 @@ index 73e2f8fbc..c4d23b506 100644 key1 key2 diff --git a/src/lib/crypto/crypto_tests/t_cksums.c b/src/lib/crypto/crypto_tests/t_cksums.c -index 4da14ea43..84408fb68 100644 +index 8297fcbf5..3063d12ec 100644 --- a/src/lib/crypto/crypto_tests/t_cksums.c +++ b/src/lib/crypto/crypto_tests/t_cksums.c @@ -59,16 +59,6 @@ struct test { @@ -4593,7 +4595,7 @@ index ecc2e08c9..f5fbe8a2a 100644 "hmac-md5-rc4", { "hmac-md5-enc", "hmac-md5-earcfour" }, "Microsoft HMAC MD5", diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h -index ba693f8a4..5cc1f8e43 100644 +index 19f808749..4bc430c7a 100644 --- a/src/lib/crypto/krb/crypto_int.h +++ b/src/lib/crypto/krb/crypto_int.h @@ -276,10 +276,6 @@ krb5_error_code krb5int_aes2_string_to_key(const struct krb5_keytypes *enc, @@ -4814,7 +4816,7 @@ index 157462526..863090beb 100644 - return 0; -} diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports -index 451d5e035..9db181381 100644 +index d6cc1b423..f44cb9170 100644 --- a/src/lib/crypto/libk5crypto.exports +++ b/src/lib/crypto/libk5crypto.exports @@ -86,7 +86,6 @@ krb5_k_verify_checksum @@ -5193,10 +5195,10 @@ index 1c439c2cd..000000000 - krb5int_default_free_state -}; diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index c821cc830..c5bddb1e8 100644 +index 636ee303f..e2c5e2b59 100644 --- a/src/lib/gssapi/krb5/accept_sec_context.c +++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -1010,7 +1010,6 @@ kg_accept_krb5(minor_status, context_handle, +@@ -1039,7 +1039,6 @@ kg_accept_krb5(minor_status, context_handle, } switch (negotiated_etype) { @@ -5205,7 +5207,7 @@ index c821cc830..c5bddb1e8 100644 case ENCTYPE_ARCFOUR_HMAC_EXP: /* RFC 4121 accidentally omits RC4-HMAC-EXP as a "not-newer" diff --git a/src/lib/gssapi/krb5/gssapiP_krb5.h b/src/lib/gssapi/krb5/gssapiP_krb5.h -index 2e2c775d6..f5b0fede6 100644 +index a7e0e63ec..3bacdcd35 100644 --- a/src/lib/gssapi/krb5/gssapiP_krb5.h +++ b/src/lib/gssapi/krb5/gssapiP_krb5.h @@ -125,14 +125,14 @@ enum sgn_alg { @@ -5552,7 +5554,7 @@ index 85a9574f3..3ce2a90ce 100644 code = 0; retval = GSS_S_BAD_SIG; diff --git a/src/lib/gssapi/krb5/util_crypt.c b/src/lib/gssapi/krb5/util_crypt.c -index ddb0af8fc..d6c71aeb8 100644 +index 84f194988..32150f5e3 100644 --- a/src/lib/gssapi/krb5/util_crypt.c +++ b/src/lib/gssapi/krb5/util_crypt.c @@ -97,17 +97,6 @@ kg_setup_keys(krb5_context context, krb5_gss_ctx_id_rec *ctx, krb5_key subkey, @@ -5623,7 +5625,7 @@ index 2925c1c43..2f76c8b43 100644 if { ! [cmd {kadm5_destroy $server_handle}]} { perror "$test: unexpected failure in destroy" diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index e7d67cca4..9a4741fa6 100644 +index 21d5cb1ca..a8ba6fc5b 100644 --- a/src/lib/krb5/krb/init_ctx.c +++ b/src/lib/krb5/krb/init_ctx.c @@ -59,7 +59,6 @@ @@ -5634,7 +5636,7 @@ index e7d67cca4..9a4741fa6 100644 ENCTYPE_ARCFOUR_HMAC, ENCTYPE_CAMELLIA128_CTS_CMAC, ENCTYPE_CAMELLIA256_CTS_CMAC, 0 -@@ -479,8 +478,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, +@@ -456,8 +455,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, /* Set all enctypes in the default list. */ for (i = 0; default_list[i]; i++) mod_list(default_list[i], sel, weak, &list); @@ -5644,10 +5646,10 @@ index e7d67cca4..9a4741fa6 100644 mod_list(ENCTYPE_AES256_CTS_HMAC_SHA1_96, sel, weak, &list); mod_list(ENCTYPE_AES128_CTS_HMAC_SHA1_96, sel, weak, &list); diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c -index 504eb557f..fc5c886d6 100644 +index 44d113e7c..966278578 100644 --- a/src/lib/krb5/krb/s4u_creds.c +++ b/src/lib/krb5/krb/s4u_creds.c -@@ -287,8 +287,6 @@ verify_s4u2self_reply(krb5_context context, +@@ -288,8 +288,6 @@ verify_s4u2self_reply(krb5_context context, assert(req_s4u_user != NULL); switch (subkey->enctype) { @@ -5656,21 +5658,8 @@ index 504eb557f..fc5c886d6 100644 case ENCTYPE_ARCFOUR_HMAC: case ENCTYPE_ARCFOUR_HMAC_EXP : not_newer = TRUE; -diff --git a/src/lib/krb5/krb/t_copy_context.c b/src/lib/krb5/krb/t_copy_context.c -index 2970a8cea..fb82daf19 100644 ---- a/src/lib/krb5/krb/t_copy_context.c -+++ b/src/lib/krb5/krb/t_copy_context.c -@@ -113,7 +113,7 @@ main(int argc, char **argv) - { - krb5_context ctx, ctx2; - krb5_plugin_initvt_fn *mods; -- const krb5_enctype etypes1[] = { ENCTYPE_DES3_CBC_SHA1, 0 }; -+ const krb5_enctype etypes1[] = { ENCTYPE_AES128_CTS_HMAC_SHA256_128, 0 }; - const krb5_enctype etypes2[] = { ENCTYPE_AES128_CTS_HMAC_SHA1_96, - ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }; - krb5_prompt_type ptypes[] = { KRB5_PROMPT_TYPE_PASSWORD }; diff --git a/src/lib/krb5/krb/t_etypes.c b/src/lib/krb5/krb/t_etypes.c -index f609e938a..248ffea90 100644 +index 90c9f626c..935aca12f 100644 --- a/src/lib/krb5/krb/t_etypes.c +++ b/src/lib/krb5/krb/t_etypes.c @@ -50,17 +50,6 @@ static struct { @@ -5787,7 +5776,7 @@ index e3d284631..586661bb7 100644 #define CKK_CAST3 (0x17) #define CKK_CAST128 (0x18) diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c -index 1a642139a..2f0431991 100644 +index 2817cc213..a385da7c3 100644 --- a/src/plugins/preauth/pkinit/pkinit_clnt.c +++ b/src/plugins/preauth/pkinit/pkinit_clnt.c @@ -212,14 +212,6 @@ pkinit_as_req_create(krb5_context context, @@ -5806,7 +5795,7 @@ index 1a642139a..2f0431991 100644 case DH_PROTOCOL: TRACE_PKINIT_CLIENT_REQ_DH(context); diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h -index 8064a07d0..a291889b0 100644 +index 77d5c61fe..1f9868351 100644 --- a/src/plugins/preauth/pkinit/pkinit_crypto.h +++ b/src/plugins/preauth/pkinit/pkinit_crypto.h @@ -380,18 +380,6 @@ krb5_error_code server_process_dh @@ -5829,10 +5818,10 @@ index 8064a07d0..a291889b0 100644 * this functions takes in crypto specific representation of * trustedCertifiers and creates a list of diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 8c7fd0cca..52976895b 100644 +index d7d1593f4..0a67c44ef 100644 --- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -5487,44 +5487,6 @@ cleanup: +@@ -5488,44 +5488,6 @@ cleanup: return retval; } @@ -5963,7 +5952,7 @@ index 2279202d3..96b0307d7 100644 /* initial key, w, x, y, T, S, K */ "8846F7EAEE8FB117AD06BDD830B7586C", diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp -index b047ef1f7..4d8c917cd 100644 +index 619fcce48..0a2ed723d 100644 --- a/src/tests/dejagnu/config/default.exp +++ b/src/tests/dejagnu/config/default.exp @@ -15,8 +15,6 @@ set timeout 100 @@ -6042,7 +6031,7 @@ index b047ef1f7..4d8c917cd 100644 {allow_weak_crypto(kdc)=false} {allow_weak_crypto(replica)=false} {allow_weak_crypto(client)=false} -@@ -946,7 +911,6 @@ proc setup_kerberos_db { standalone } { +@@ -945,7 +910,6 @@ proc setup_kerberos_db { standalone } { global REALMNAME KDB5_UTIL KADMIN_LOCAL KEY global tmppwd hostname global spawn_id @@ -6050,7 +6039,7 @@ index b047ef1f7..4d8c917cd 100644 global multipass_name last_passname_db set failall 0 -@@ -1143,48 +1107,6 @@ proc setup_kerberos_db { standalone } { +@@ -1142,48 +1106,6 @@ proc setup_kerberos_db { standalone } { } } @@ -6100,7 +6089,7 @@ index b047ef1f7..4d8c917cd 100644 # create the admin database lock file diff --git a/src/tests/dejagnu/krb-standalone/kprop.exp b/src/tests/dejagnu/krb-standalone/kprop.exp -index f71ee8638..8c08cf42f 100644 +index 661e3fd9a..2b8f60045 100644 --- a/src/tests/dejagnu/krb-standalone/kprop.exp +++ b/src/tests/dejagnu/krb-standalone/kprop.exp @@ -54,7 +54,7 @@ proc doit { } { @@ -6258,7 +6247,7 @@ index f71774cdc..d1857c433 100644 "3BB3AE288C12B3B9D06B208A4151B3B6", "9AEA11A3BCF3C53F1F91F5A0BA2132E2501ADF5F3C28" diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py -index c589adf2a..4fbdbec05 100644 +index 3fa957ad2..2e01f46bc 100644 --- a/src/tests/t_authdata.py +++ b/src/tests/t_authdata.py @@ -174,7 +174,7 @@ realm.run([kvno, 'restricted']) @@ -6271,7 +6260,7 @@ index c589adf2a..4fbdbec05 100644 realm.run(['./forward']) realm.run([kvno, realm.host_princ]) diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py -index 2a052fc17..ace0edc3c 100644 +index c982508d8..96e90a69d 100644 --- a/src/tests/t_etype_info.py +++ b/src/tests/t_etype_info.py @@ -1,6 +1,6 @@ @@ -6282,7 +6271,7 @@ index 2a052fc17..ace0edc3c 100644 conf = {'libdefaults': {'allow_weak_crypto': 'true'}, 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) -@@ -24,9 +24,9 @@ def test_etinfo(princ, enctypes, expected_lines): +@@ -26,9 +26,9 @@ def test_etinfo(princ, enctypes, expected_lines): # With no newer enctypes in the request, PA-ETYPE-INFO2, # PA-ETYPE-INFO, and PA-PW-SALT appear in the AS-REP, each listing one # key for the most preferred matching enctype. @@ -6295,7 +6284,7 @@ index 2a052fc17..ace0edc3c 100644 'asrep pw_salt KRBTEST.COMuser']) # With a newer enctype in the request (even if it is not the most -@@ -37,9 +37,9 @@ test_etinfo('user', 'rc4 aes256-cts', +@@ -39,9 +39,9 @@ test_etinfo('user', 'rc4 aes256-cts', # In preauth-required errors, PA-PW-SALT does not appear, but the same # etype-info2 values are expected. @@ -6308,7 +6297,7 @@ index 2a052fc17..ace0edc3c 100644 test_etinfo('preauthuser', 'rc4 aes256-cts', ['error etype_info2 rc4-hmac KRBTEST.COMpreauthuser']) -@@ -48,8 +48,8 @@ test_etinfo('preauthuser', 'rc4 aes256-cts', +@@ -50,8 +50,8 @@ test_etinfo('preauthuser', 'rc4 aes256-cts', # (to allow for preauth mechs which don't depend on long-term keys). # An AS-REP cannot be generated without preauth as there is no reply # key. @@ -6348,7 +6337,7 @@ index 2c825a692..f29e0d550 100755 realm.stop() diff --git a/src/tests/t_mkey.py b/src/tests/t_mkey.py -index 99273c907..f84041ca4 100755 +index 32f4070bc..da0ed1831 100755 --- a/src/tests/t_mkey.py +++ b/src/tests/t_mkey.py @@ -7,7 +7,6 @@ import struct @@ -6421,10 +6410,10 @@ index 65084bbf3..55ca89745 100755 # Test using different salt types in a principal's key list. # Parameters from one key in the list must not leak over to later ones. diff --git a/src/util/k5test.py b/src/util/k5test.py -index 442a4e4f7..eea92275d 100644 +index 10f6b0a25..d234a5667 100644 --- a/src/util/k5test.py +++ b/src/util/k5test.py -@@ -1299,13 +1299,6 @@ _passes = [ +@@ -1277,13 +1277,6 @@ _passes = [ # No special settings; exercises AES256. ('default', None, None, None), diff --git a/downstream-SELinux-integration.patch b/downstream-SELinux-integration.patch index 4574a19..96cf861 100644 --- a/downstream-SELinux-integration.patch +++ b/downstream-SELinux-integration.patch @@ -1,4 +1,4 @@ -From 2c4d04d1da4dbb1a312db965f3392d7d0bc67a17 Mon Sep 17 00:00:00 2001 +From 289615de0c73969574e3d48611deda66989c36c0 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] [downstream] SELinux integration @@ -67,7 +67,7 @@ Last-updated: krb5-1.18-beta1 create mode 100644 src/util/support/selinux.c diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 59621e3e7..398eca7e4 100644 +index ca9fcf664..5afb96e58 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 @@ -85,6 +85,7 @@ AC_SUBST_FILE(libnodeps_frag) @@ -78,7 +78,7 @@ index 59621e3e7..398eca7e4 100644 KRB5_LIB_PARAMS KRB5_AC_INITFINI KRB5_AC_ENABLE_THREADS -@@ -1739,4 +1740,51 @@ AC_SUBST(PAM_LIBS) +@@ -1745,4 +1746,51 @@ AC_SUBST(PAM_LIBS) AC_SUBST(PAM_MAN) AC_SUBST(NON_PAM_MAN) ])dnl @@ -131,7 +131,7 @@ index 59621e3e7..398eca7e4 100644 +AC_SUBST(SELINUX_LIBS) +])dnl diff --git a/src/build-tools/krb5-config.in b/src/build-tools/krb5-config.in -index f6184da3f..c17cb5eb5 100755 +index 9f96a8719..120922ac3 100755 --- a/src/build-tools/krb5-config.in +++ b/src/build-tools/krb5-config.in @@ -41,6 +41,7 @@ DL_LIB='@DL_LIB@' @@ -152,7 +152,7 @@ index f6184da3f..c17cb5eb5 100755 echo $lib_flags diff --git a/src/config/pre.in b/src/config/pre.in -index ce87e21ca..917357df9 100644 +index 7b3a583cc..0c51e6966 100644 --- a/src/config/pre.in +++ b/src/config/pre.in @@ -177,6 +177,7 @@ LD = $(PURE) @LD@ @@ -173,10 +173,10 @@ index ce87e21ca..917357df9 100644 GSS_LIBS = $(GSS_KRB5_LIB) # needs fixing if ever used on macOS! diff --git a/src/configure.ac b/src/configure.ac -index d1f576124..440a22bd9 100644 +index fdaba0ce7..bd151ca26 100644 --- a/src/configure.ac +++ b/src/configure.ac -@@ -1392,6 +1392,8 @@ AC_PATH_PROG(GROFF, groff) +@@ -1391,6 +1391,8 @@ AC_PATH_PROG(GROFF, groff) KRB5_WITH_PAM @@ -186,7 +186,7 @@ index d1f576124..440a22bd9 100644 if test "${localedir+set}" != set; then localedir='$(datadir)/locale' diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 9616b24bf..0d9af3d95 100644 +index b3e346991..93d3a1f97 100644 --- a/src/include/k5-int.h +++ b/src/include/k5-int.h @@ -128,6 +128,7 @@ typedef unsigned char u_char; @@ -236,7 +236,7 @@ index 000000000..dfaaa847c +#endif +#endif diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 79761f6d2..e9435c693 100644 +index 045334a08..db80063eb 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin @@ -87,6 +87,12 @@ @@ -288,7 +288,7 @@ index ff2f25050..e3457622a 100644 com_err(progname, errno, _("while creating 'ok' file, '%s'"), file_ok); goto cleanup; diff --git a/src/kdc/main.c b/src/kdc/main.c -index 38d76b3b1..eb6966f2d 100644 +index 27aa10da0..b5916b147 100644 --- a/src/kdc/main.c +++ b/src/kdc/main.c @@ -872,7 +872,7 @@ write_pid_file(const char *path) @@ -301,7 +301,7 @@ index 38d76b3b1..eb6966f2d 100644 return errno; pid = (unsigned long) getpid(); diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c -index 5622d56e1..356e3e0e6 100644 +index 874ba1305..9d6378cc0 100644 --- a/src/kprop/kpropd.c +++ b/src/kprop/kpropd.c @@ -487,6 +487,9 @@ doit(int fd) @@ -416,7 +416,7 @@ index 7b100a0ec..5683a0433 100644 _("Credential cache directory %s does not exist"), dirname); diff --git a/src/lib/krb5/keytab/kt_file.c b/src/lib/krb5/keytab/kt_file.c -index 021c94398..aaf573439 100644 +index e510211fc..f3ea28c8e 100644 --- a/src/lib/krb5/keytab/kt_file.c +++ b/src/lib/krb5/keytab/kt_file.c @@ -735,14 +735,14 @@ krb5_ktfileint_open(krb5_context context, krb5_keytab id, int mode) @@ -463,7 +463,7 @@ index 7db30a33b..2b9d01921 100644 * maybe someone took away write permission so we could only * get shared locks? diff --git a/src/plugins/kdb/db2/kdb_db2.c b/src/plugins/kdb/db2/kdb_db2.c -index 5106a5c99..e481e8121 100644 +index 1a476b586..b40bb2240 100644 --- a/src/plugins/kdb/db2/kdb_db2.c +++ b/src/plugins/kdb/db2/kdb_db2.c @@ -694,8 +694,8 @@ ctx_create_db(krb5_context context, krb5_db2_context *dbc) @@ -542,7 +542,7 @@ index d8b26e701..b0daa7c02 100644 if (fname != NULL && fcntl(rfd, F_SETFD, 1) == -1) { diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c -index b92cb58c7..0a95101ad 100644 +index e87688d66..30f7c00ab 100644 --- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c +++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c @@ -190,7 +190,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv) diff --git a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch index 149bb0a..9ede1d4 100644 --- a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch +++ b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch @@ -1,4 +1,4 @@ -From a89e833a2ae26197a0edf864bb9274d776003c60 Mon Sep 17 00:00:00 2001 +From 7b22d94779ff340db5f9f25cf7b55aeb365091e1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 15 Nov 2019 20:05:16 +0000 Subject: [PATCH] [downstream] Use backported version of OpenSSL-3 KDF @@ -12,7 +12,7 @@ Last-updated: krb5-1.17 3 files changed, 428 insertions(+), 189 deletions(-) diff --git a/src/configure.ac b/src/configure.ac -index d4e4da525..29be532cb 100644 +index 27c2383d7..d3e022274 100644 --- a/src/configure.ac +++ b/src/configure.ac @@ -282,6 +282,10 @@ AC_SUBST(CRYPTO_IMPL) @@ -441,7 +441,7 @@ index 6707a7308..915a173dd 100644 return k5_sp800_108_counter_hmac(hash, inkey, outrnd, in_constant, &empty); diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 52976895b..dd718c2be 100644 +index 0a67c44ef..dbb054378 100644 --- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c @@ -38,6 +38,13 @@ diff --git a/downstream-fix-debuginfo-with-y.tab.c.patch b/downstream-fix-debuginfo-with-y.tab.c.patch index 13072cf..c31c013 100644 --- a/downstream-fix-debuginfo-with-y.tab.c.patch +++ b/downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,4 +1,4 @@ -From 0f98db9b00fa2ce685f841db18fff641f8eaa904 Mon Sep 17 00:00:00 2001 +From 27614a4fd889525fbd1ca5cb45c20c64a4f9568c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] [downstream] fix debuginfo with y.tab.c diff --git a/downstream-ksu-pam-integration.patch b/downstream-ksu-pam-integration.patch index be0e02f..050f195 100644 --- a/downstream-ksu-pam-integration.patch +++ b/downstream-ksu-pam-integration.patch @@ -1,4 +1,4 @@ -From a5a642c33a2f57d24c1cfa8ca3e286418206ab55 Mon Sep 17 00:00:00 2001 +From f7749ad59d75c2da64f4e9defdbfbc0c1e345bfb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] [downstream] ksu pam integration @@ -30,10 +30,10 @@ Last-updated: krb5-1.18-beta1 create mode 100644 src/clients/ksu/pam.h diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 8709a7f5d..59621e3e7 100644 +index 024d6370c..ca9fcf664 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -1671,3 +1671,72 @@ if test "$with_ldap" = yes; then +@@ -1677,3 +1677,72 @@ if test "$with_ldap" = yes; then OPENLDAP_PLUGIN=yes fi ])dnl @@ -145,11 +145,11 @@ index 8b4edce4d..9d58f29b5 100644 clean: $(RM) ksu diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c -index 57c349200..508242e0e 100644 +index af1286172..931f05404 100644 --- a/src/clients/ksu/main.c +++ b/src/clients/ksu/main.c @@ -26,6 +26,7 @@ - * KSU was writen by: Ari Medvinsky, ari@isi.edu + * KSU was written by: Ari Medvinsky, ari@isi.edu */ +#include "autoconf.h" @@ -760,10 +760,10 @@ index 000000000..0ab76569c +void appl_pam_cleanup(void); +#endif diff --git a/src/configure.ac b/src/configure.ac -index 234f4281c..d1f576124 100644 +index 49814922f..fdaba0ce7 100644 --- a/src/configure.ac +++ b/src/configure.ac -@@ -1390,6 +1390,8 @@ AC_SUBST([VERTO_VERSION]) +@@ -1389,6 +1389,8 @@ AC_SUBST([VERTO_VERSION]) AC_PATH_PROG(GROFF, groff) diff --git a/downstream-netlib-and-dns.patch b/downstream-netlib-and-dns.patch index 682e3df..17f1c00 100644 --- a/downstream-netlib-and-dns.patch +++ b/downstream-netlib-and-dns.patch @@ -1,4 +1,4 @@ -From 29f58a8059cb73ca586514b57458b2b17e091f36 Mon Sep 17 00:00:00 2001 +From df80ded9756b0637ab7cca706e1520f3f372c2e2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] [downstream] netlib and dns @@ -11,10 +11,10 @@ Last-updated: krb5-1.3.1 1 file changed, 1 insertion(+) diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 398eca7e4..7ef2db56b 100644 +index 5afb96e58..4a4d460e3 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -720,6 +720,7 @@ AC_HELP_STRING([--with-netlib=LIBS], use user defined resolver library), +@@ -718,6 +718,7 @@ AC_HELP_STRING([--with-netlib=LIBS], use user defined resolver library), LIBS="$LIBS $withval" AC_MSG_RESULT("netlib will use \'$withval\'") fi diff --git a/krb5.spec b/krb5.spec index a465681..604f84c 100644 --- a/krb5.spec +++ b/krb5.spec @@ -1,5 +1,3 @@ -%global WITH_DIRSRV 1 - # Set this so that find-lang.sh will recognize the .po files. %global gettext_domain mit-krb5 # Guess where the -libs subpackage's docs are going to go. @@ -8,21 +6,24 @@ %global configure_default_ccache_name 1 %global configured_default_ccache_name KEYRING:persistent:%%{uid} -# leave empty or set to e.g., -beta2 -%global prerelease %{nil} +# either beta1 or % { nil } +%global prerelease beta1 +%if %{defined prerelease} +%global dashpre -%{prerelease} +%global zdpd 0.%{prerelease}. +%endif # Should be in form 5.0, 6.1, etc. %global kdbversion 8.0 Summary: The Kerberos network authentication system Name: krb5 -Version: 1.18.3 -# for prerelease, should be e.g., 0.% {prerelease}.1% { ?dist } (without spaces) -Release: 5%{?dist} +Version: 1.19 +Release: %{?zdpd}2%{?dist} # rharwood has trust path to signing key and verifies on check-in -Source0: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz -Source1: https://web.mit.edu/kerberos/dist/krb5/1.18/krb5-%{version}%{prerelease}.tar.gz.asc +Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz +Source1: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz.asc # Numbering is a relic of old init systems etc. It's easiest to just leave. Source2: kprop.service @@ -46,37 +47,6 @@ Patch4: downstream-fix-debuginfo-with-y.tab.c.patch Patch5: downstream-Remove-3des-support.patch Patch6: downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch -Patch9: Allow-certauth-modules-to-set-hw-authent-flag.patch -Patch11: Refresh-manually-acquired-creds-from-client-keytab.patch -Patch13: Add-finalization-safety-check-to-com_err.patch -Patch15: Correctly-import-service-GSS-host-based-name.patch -Patch16: Do-expiration-warnings-for-all-init_creds-APIs.patch -Patch17: Pass-gss_localname-through-SPNEGO.patch -Patch18: Omit-KDC-indicator-check-for-S4U2Self-requests.patch -Patch19: Fix-typo-in-in-in-the-ksu-man-page.patch -Patch21: Replace-gssrpc-tests-with-a-Python-script.patch -Patch22: Default-dns_canonicalize_hostname-to-fallback.patch -Patch23: Remove-resolver-test-utility.patch -Patch24: Omit-PA_FOR_USER-if-we-can-t-compute-its-checksum.patch -Patch25: Improve-negoex_parse_token-code-hygiene.patch -Patch26: Refactor-krb5-GSS-checksum-handling.patch -Patch27: Implement-GSS_C_CHANNEL_BOUND_FLAG.patch -Patch28: Implement-KERB_AP_OPTIONS_CBT-server-side.patch -Patch29: Add-client_aware_channel_bindings-option.patch -Patch30: Pass-channel-bindings-through-SPNEGO.patch -Patch31: Add-channel-bindings-tests.patch -Patch32: Use-two-queues-for-concurrent-t_otp.py-daemons.patch -Patch34: Ignore-bad-enctypes-in-krb5_string_to_keysalts.patch -Patch35: Fix-leak-in-KERB_AP_OPTIONS_CBT-server-support.patch -Patch37: Add-three-kvno-options-from-Heimdal-kgetcred.patch -Patch39: Improve-KDC-alias-checking-for-S4U-requests.patch -Patch40: Adjust-KDC-alias-helper-function-contract.patch -Patch41: Allow-aliases-when-matching-U2U-second-ticket.patch -Patch42: Refactor-KDC-authdata-list-management-helpers.patch -Patch43: Avoid-passing-DB-entry-structures-in-KDC.patch -Patch44: Minimize-usage-of-tgs_server-in-KDC.patch -Patch45: Fix-minor-static-analysis-defects.patch -Patch46: Install-shared-libraries-as-executable.patch Patch47: Document-k-option-in-kvno-1-synopsis.patch License: MIT @@ -211,7 +181,7 @@ contains only the libkadm5clnt and libkadm5serv shared objects. This interface is not considered stable. %prep -%autosetup -S git -n %{name}-%{version}%{prerelease} +%autosetup -S git -n %{name}-%{version}%{?dashpre} ln NOTICE LICENSE # Generate an FDS-compatible LDIF file. @@ -276,9 +246,7 @@ CPPFLAGS="`echo $DEFINES $INCLUDES`" --with-tcl \ --enable-dns-for-realm \ --with-ldap \ -%if %{WITH_DIRSRV} --with-dirsrv-account-locking \ -%endif --enable-pkinit \ --with-crypto-impl=openssl \ --with-tls-impl=openssl \ @@ -317,13 +285,17 @@ rm -fr build-html/_sources %ifnarch s390x pushd src -# ugh. COPR doesn't expose the keyring, so try to cope. -KEYCTL=keyctl -keyctl list @u &>/dev/null || KEYCTL=: +# ugh. COPR doesn't work right with the tests. I suspect keyring issues, but +# can't actually debug, so... +%if 0%{?copr_username:1} +%global keyctl : +%else +%global keyctl keyctl +%endif # The build system may give us a revoked session keyring, so run affected # tests with a new one. -$KEYCTL session - make check OFFLINE=yes TMPDIR=%{_tmppath} +%{keyctl} session - make check OFFLINE=yes TMPDIR=%{_tmppath} popd %endif @@ -639,6 +611,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Dec 16 2020 Robbie Harwood - 1.19-0.beta1.2 +- New upstream version (1.19-beta1) + * Wed Dec 16 2020 Robbie Harwood - 1.18.3-5 - Fix runstatedir configuration - Why couldn't systemd just leave it alone? diff --git a/sources b/sources index 6ed904d..c36c920 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.18.3.tar.gz) = cf0bf6cf8f622fa085954e6da998d952cf64dc7ccc319972ed81ea0542089cabf2d0e8243df84da01ad6f40584768ca2f02d108630c6741fa7b3d7d98c887c01 -SHA512 (krb5-1.18.3.tar.gz.asc) = 7c5a83e13d00910d895d545ed63310ebec48c90c29846dd54e48048f710360e8306778729b636baa091a4e9048998ff6d4dfe37f88dd6292540d55678c961a30 +SHA512 (krb5-1.19-beta1.tar.gz) = 3538a13a38c20d6b5fee0fba474bc49a12434b184de409f829e7b6e5c76ad2fc105fc27f2574a93c3cd9fe9ccf3d5d98f6cd3bdd13a089bb3485e0c3974417de +SHA512 (krb5-1.19-beta1.tar.gz.asc) = cfa793f83f0adaba87f2fe242b0796ed8732de898501d51b745d57a55d98966b337e68f29ec0ae233b15613baca70f2c56f742e467d310e157e3b49b59ad9c5f From 9fb5239517e1095421fd19cb964949a1f5594988 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 12 Jan 2021 12:44:13 -0500 Subject: [PATCH 211/304] New upstream version (1.19-beta2) --- .gitignore | 2 + Document-k-option-in-kvno-1-synopsis.patch | 38 ------------------- ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 4 +- downstream-Remove-3des-support.patch | 22 +++++------ downstream-SELinux-integration.patch | 10 ++--- ...ackported-version-of-OpenSSL-3-KDF-i.patch | 4 +- downstream-fix-debuginfo-with-y.tab.c.patch | 2 +- downstream-ksu-pam-integration.patch | 4 +- downstream-netlib-and-dns.patch | 2 +- krb5.spec | 8 ++-- sources | 4 +- 11 files changed, 33 insertions(+), 67 deletions(-) delete mode 100644 Document-k-option-in-kvno-1-synopsis.patch diff --git a/.gitignore b/.gitignore index 258cd98..c686550 100644 --- a/.gitignore +++ b/.gitignore @@ -191,3 +191,5 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.18.3.tar.gz.asc /krb5-1.19-beta1.tar.gz /krb5-1.19-beta1.tar.gz.asc +/krb5-1.19-beta2.tar.gz +/krb5-1.19-beta2.tar.gz.asc diff --git a/Document-k-option-in-kvno-1-synopsis.patch b/Document-k-option-in-kvno-1-synopsis.patch deleted file mode 100644 index 28323f4..0000000 --- a/Document-k-option-in-kvno-1-synopsis.patch +++ /dev/null @@ -1,38 +0,0 @@ -From b401a1127f27f8cd564e32411f799648a8fd5481 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 24 Nov 2020 12:52:02 -0500 -Subject: [PATCH] Document -k option in kvno(1) synopsis - -becd1ad6830b526d08ddaf5b2b6f213154c6446c attempted to unify the -synopsis, option descriptions, and xusage(), but missed one option. - -(cherry picked from commit d81e76d9ddab9e880bcf54eabf07119af91d28c7) ---- - doc/user/user_commands/kvno.rst | 1 + - src/man/kvno.man | 1 + - 2 files changed, 2 insertions(+) - -diff --git a/doc/user/user_commands/kvno.rst b/doc/user/user_commands/kvno.rst -index 65c44e1c0..93a5132b2 100644 ---- a/doc/user/user_commands/kvno.rst -+++ b/doc/user/user_commands/kvno.rst -@@ -9,6 +9,7 @@ SYNOPSIS - **kvno** - [**-c** *ccache*] - [**-e** *etype*] -+[**-k** *keytab*] - [**-q**] - [**-u** | **-S** *sname*] - [**-P**] -diff --git a/src/man/kvno.man b/src/man/kvno.man -index 953d168e6..ebdd6e8ca 100644 ---- a/src/man/kvno.man -+++ b/src/man/kvno.man -@@ -35,6 +35,7 @@ level margin: \\n[rst2man-indent\\n[rst2man-indent-level]] - \fBkvno\fP - [\fB\-c\fP \fIccache\fP] - [\fB\-e\fP \fIetype\fP] -+[\fB\-k\fP \fIkeytab\fP] - [\fB\-q\fP] - [\fB\-u\fP | \fB\-S\fP \fIsname\fP] - [\fB\-P\fP] diff --git a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index 6d74df5..8ca2534 100644 --- a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From 146967416993f66c3ba32cbf3881e43e7bc1ed1c Mon Sep 17 00:00:00 2001 +From 836fdca1ac4bb58498551e1afe8ca6e55d41902d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 @@ -39,7 +39,7 @@ Last-updated: krb5-1.17 15 files changed, 151 insertions(+), 33 deletions(-) diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index e4e2443ed..af3df5871 100644 +index cb17a8485..29ddca3a4 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst @@ -330,6 +330,12 @@ The libdefaults section may contain any of the following relations: diff --git a/downstream-Remove-3des-support.patch b/downstream-Remove-3des-support.patch index 1bf529e..046a1be 100644 --- a/downstream-Remove-3des-support.patch +++ b/downstream-Remove-3des-support.patch @@ -1,4 +1,4 @@ -From 3af536f114e1c1b33b1579f9f16bbb3f497d4a1d Mon Sep 17 00:00:00 2001 +From 329c97793a3e96e79f618bc54914ec89a9e99828 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] [downstream] Remove 3des support @@ -255,7 +255,7 @@ index cebb6644c..4d51e795c 100644 CKSUMTYPE_NIST_SHA.rst CKSUMTYPE_RSA_MD4.rst diff --git a/doc/conf.py b/doc/conf.py -index 9226b8e01..19cf38326 100644 +index 543202bf4..4fb6aae14 100644 --- a/doc/conf.py +++ b/doc/conf.py @@ -271,7 +271,7 @@ else: @@ -281,7 +281,7 @@ index 4954bb3aa..92ce2a772 100644 Interoperability ---------------- diff --git a/src/Makefile.in b/src/Makefile.in -index f9270aba2..c958da60f 100644 +index 7d2507ef8..c16715ac7 100644 --- a/src/Makefile.in +++ b/src/Makefile.in @@ -130,7 +130,7 @@ WINMAKEFILES=Makefile \ @@ -303,7 +303,7 @@ index f9270aba2..c958da60f 100644 ##DOS## $(WCONFIG) config < $@.in > $@ ##DOS##lib\crypto\builtin\camellia\Makefile: lib\crypto\builtin\camellia\Makefile.in $(MKFDEP) diff --git a/src/configure.ac b/src/configure.ac -index bd151ca26..27c2383d7 100644 +index dd2cad3ee..3e1052db7 100644 --- a/src/configure.ac +++ b/src/configure.ac @@ -1480,7 +1480,6 @@ V5_AC_OUTPUT_MAKEFILE(. @@ -5195,7 +5195,7 @@ index 1c439c2cd..000000000 - krb5int_default_free_state -}; diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index 636ee303f..e2c5e2b59 100644 +index 75f071c3e..fcf2c2152 100644 --- a/src/lib/gssapi/krb5/accept_sec_context.c +++ b/src/lib/gssapi/krb5/accept_sec_context.c @@ -1039,7 +1039,6 @@ kg_accept_krb5(minor_status, context_handle, @@ -5625,7 +5625,7 @@ index 2925c1c43..2f76c8b43 100644 if { ! [cmd {kadm5_destroy $server_handle}]} { perror "$test: unexpected failure in destroy" diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index 21d5cb1ca..a8ba6fc5b 100644 +index be31eb31e..d2b70acad 100644 --- a/src/lib/krb5/krb/init_ctx.c +++ b/src/lib/krb5/krb/init_ctx.c @@ -59,7 +59,6 @@ @@ -5952,7 +5952,7 @@ index 2279202d3..96b0307d7 100644 /* initial key, w, x, y, T, S, K */ "8846F7EAEE8FB117AD06BDD830B7586C", diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp -index 619fcce48..0a2ed723d 100644 +index 85bbf478a..302dee74c 100644 --- a/src/tests/dejagnu/config/default.exp +++ b/src/tests/dejagnu/config/default.exp @@ -15,8 +15,6 @@ set timeout 100 @@ -6031,7 +6031,7 @@ index 619fcce48..0a2ed723d 100644 {allow_weak_crypto(kdc)=false} {allow_weak_crypto(replica)=false} {allow_weak_crypto(client)=false} -@@ -945,7 +910,6 @@ proc setup_kerberos_db { standalone } { +@@ -946,7 +911,6 @@ proc setup_kerberos_db { standalone } { global REALMNAME KDB5_UTIL KADMIN_LOCAL KEY global tmppwd hostname global spawn_id @@ -6039,7 +6039,7 @@ index 619fcce48..0a2ed723d 100644 global multipass_name last_passname_db set failall 0 -@@ -1142,48 +1106,6 @@ proc setup_kerberos_db { standalone } { +@@ -1143,48 +1107,6 @@ proc setup_kerberos_db { standalone } { } } @@ -6410,10 +6410,10 @@ index 65084bbf3..55ca89745 100755 # Test using different salt types in a principal's key list. # Parameters from one key in the list must not leak over to later ones. diff --git a/src/util/k5test.py b/src/util/k5test.py -index 10f6b0a25..d234a5667 100644 +index 6afe4b92c..789b0f4b9 100644 --- a/src/util/k5test.py +++ b/src/util/k5test.py -@@ -1277,13 +1277,6 @@ _passes = [ +@@ -1278,13 +1278,6 @@ _passes = [ # No special settings; exercises AES256. ('default', None, None, None), diff --git a/downstream-SELinux-integration.patch b/downstream-SELinux-integration.patch index 96cf861..7c134eb 100644 --- a/downstream-SELinux-integration.patch +++ b/downstream-SELinux-integration.patch @@ -1,4 +1,4 @@ -From 289615de0c73969574e3d48611deda66989c36c0 Mon Sep 17 00:00:00 2001 +From 1de6ec4cb5b2a1b7b88680ae0f72551a3b5178e6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] [downstream] SELinux integration @@ -152,7 +152,7 @@ index 9f96a8719..120922ac3 100755 echo $lib_flags diff --git a/src/config/pre.in b/src/config/pre.in -index 7b3a583cc..0c51e6966 100644 +index 3752174c7..0d2068575 100644 --- a/src/config/pre.in +++ b/src/config/pre.in @@ -177,6 +177,7 @@ LD = $(PURE) @LD@ @@ -163,7 +163,7 @@ index 7b3a583cc..0c51e6966 100644 INSTALL=@INSTALL@ INSTALL_STRIP= -@@ -402,7 +403,7 @@ SUPPORT_LIB = -l$(SUPPORT_LIBNAME) +@@ -403,7 +404,7 @@ SUPPORT_LIB = -l$(SUPPORT_LIBNAME) # HESIOD_LIBS is -lhesiod... HESIOD_LIBS = @HESIOD_LIBS@ @@ -173,7 +173,7 @@ index 7b3a583cc..0c51e6966 100644 GSS_LIBS = $(GSS_KRB5_LIB) # needs fixing if ever used on macOS! diff --git a/src/configure.ac b/src/configure.ac -index fdaba0ce7..bd151ca26 100644 +index 693f76a81..dd2cad3ee 100644 --- a/src/configure.ac +++ b/src/configure.ac @@ -1391,6 +1391,8 @@ AC_PATH_PROG(GROFF, groff) @@ -186,7 +186,7 @@ index fdaba0ce7..bd151ca26 100644 if test "${localedir+set}" != set; then localedir='$(datadir)/locale' diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index b3e346991..93d3a1f97 100644 +index cf524252f..efb523689 100644 --- a/src/include/k5-int.h +++ b/src/include/k5-int.h @@ -128,6 +128,7 @@ typedef unsigned char u_char; diff --git a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch index 9ede1d4..cb35de1 100644 --- a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch +++ b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch @@ -1,4 +1,4 @@ -From 7b22d94779ff340db5f9f25cf7b55aeb365091e1 Mon Sep 17 00:00:00 2001 +From 120e84b63c322c227fb8c6ee8a2f56f47d3e57f5 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 15 Nov 2019 20:05:16 +0000 Subject: [PATCH] [downstream] Use backported version of OpenSSL-3 KDF @@ -12,7 +12,7 @@ Last-updated: krb5-1.17 3 files changed, 428 insertions(+), 189 deletions(-) diff --git a/src/configure.ac b/src/configure.ac -index 27c2383d7..d3e022274 100644 +index 3e1052db7..ea708491b 100644 --- a/src/configure.ac +++ b/src/configure.ac @@ -282,6 +282,10 @@ AC_SUBST(CRYPTO_IMPL) diff --git a/downstream-fix-debuginfo-with-y.tab.c.patch b/downstream-fix-debuginfo-with-y.tab.c.patch index c31c013..96c21ac 100644 --- a/downstream-fix-debuginfo-with-y.tab.c.patch +++ b/downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,4 +1,4 @@ -From 27614a4fd889525fbd1ca5cb45c20c64a4f9568c Mon Sep 17 00:00:00 2001 +From db57bb9939da544af242c054d10e69a022558b4e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] [downstream] fix debuginfo with y.tab.c diff --git a/downstream-ksu-pam-integration.patch b/downstream-ksu-pam-integration.patch index 050f195..15b9b35 100644 --- a/downstream-ksu-pam-integration.patch +++ b/downstream-ksu-pam-integration.patch @@ -1,4 +1,4 @@ -From f7749ad59d75c2da64f4e9defdbfbc0c1e345bfb Mon Sep 17 00:00:00 2001 +From 25f948637140fb6aade80f99d9e7e096250135cd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] [downstream] ksu pam integration @@ -760,7 +760,7 @@ index 000000000..0ab76569c +void appl_pam_cleanup(void); +#endif diff --git a/src/configure.ac b/src/configure.ac -index 49814922f..fdaba0ce7 100644 +index 4eb080784..693f76a81 100644 --- a/src/configure.ac +++ b/src/configure.ac @@ -1389,6 +1389,8 @@ AC_SUBST([VERTO_VERSION]) diff --git a/downstream-netlib-and-dns.patch b/downstream-netlib-and-dns.patch index 17f1c00..4141da9 100644 --- a/downstream-netlib-and-dns.patch +++ b/downstream-netlib-and-dns.patch @@ -1,4 +1,4 @@ -From df80ded9756b0637ab7cca706e1520f3f372c2e2 Mon Sep 17 00:00:00 2001 +From 26a01204b4cb424e6f9cf4190f7290b0665f6f74 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] [downstream] netlib and dns diff --git a/krb5.spec b/krb5.spec index 604f84c..fcf894d 100644 --- a/krb5.spec +++ b/krb5.spec @@ -7,7 +7,7 @@ %global configured_default_ccache_name KEYRING:persistent:%%{uid} # either beta1 or % { nil } -%global prerelease beta1 +%global prerelease beta2 %if %{defined prerelease} %global dashpre -%{prerelease} %global zdpd 0.%{prerelease}. @@ -19,7 +19,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19 -Release: %{?zdpd}2%{?dist} +Release: %{?zdpd}1%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -47,7 +47,6 @@ Patch4: downstream-fix-debuginfo-with-y.tab.c.patch Patch5: downstream-Remove-3des-support.patch Patch6: downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch -Patch47: Document-k-option-in-kvno-1-synopsis.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -611,6 +610,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Jan 12 2021 Robbie Harwood - 1.19-1 +- New upstream version (1.19-beta2) + * Wed Dec 16 2020 Robbie Harwood - 1.19-0.beta1.2 - New upstream version (1.19-beta1) diff --git a/sources b/sources index c36c920..5daa433 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.19-beta1.tar.gz) = 3538a13a38c20d6b5fee0fba474bc49a12434b184de409f829e7b6e5c76ad2fc105fc27f2574a93c3cd9fe9ccf3d5d98f6cd3bdd13a089bb3485e0c3974417de -SHA512 (krb5-1.19-beta1.tar.gz.asc) = cfa793f83f0adaba87f2fe242b0796ed8732de898501d51b745d57a55d98966b337e68f29ec0ae233b15613baca70f2c56f742e467d310e157e3b49b59ad9c5f +SHA512 (krb5-1.19-beta2.tar.gz) = 2864a40c44575a9482d33165bc39e76f6bb476bdcc5bc87c9864f562925638118a236a788da870567d0f83df9aacb5f79145993f38f95cec1fa5b080f2561169 +SHA512 (krb5-1.19-beta2.tar.gz.asc) = fd17198c934907811abebd47b70f6c30e68aa5800f6dde90568241db1413da34557c689af66757e47d94e08d261573f0b1ee56929947f6dcc9fcbb9dcdd2e903 From b23f8f62150248278c63669cd663c6ef25dc66fe Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Tue, 26 Jan 2021 16:06:22 +0000 Subject: [PATCH 212/304] - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index fcf894d..063f1b1 100644 --- a/krb5.spec +++ b/krb5.spec @@ -19,7 +19,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19 -Release: %{?zdpd}1%{?dist} +Release: %{?zdpd}1%{?dist}.1 # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -610,6 +610,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Jan 26 2021 Fedora Release Engineering - 1.19-0.beta2.1.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + * Tue Jan 12 2021 Robbie Harwood - 1.19-1 - New upstream version (1.19-beta2) From 327ebd0b263aa5adaafd83851b8dd9953f984c01 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 27 Jan 2021 19:44:26 +0000 Subject: [PATCH 213/304] Cope with new autotools behavior wrt runstatedir --- krb5.spec | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/krb5.spec b/krb5.spec index 063f1b1..62b763c 100644 --- a/krb5.spec +++ b/krb5.spec @@ -19,7 +19,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19 -Release: %{?zdpd}1%{?dist}.1 +Release: %{?zdpd}1%{?dist}.2 # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -223,9 +223,6 @@ sed -i -e s,7778,`expr "$PORT" + 1`,g $cfg source %{_libdir}/tclConfig.sh pushd src -# Set this so that configure will have a value - upstream defaults it from -# localstatedir, which is wrong for us. -export runstatedir=/run # Work out the CFLAGS and CPPFLAGS which we intend to use. INCLUDES=-I%{_includedir}/et CFLAGS="`echo $RPM_OPT_FLAGS $DEFINES $INCLUDES -fPIC -fno-strict-aliasing -fstack-protector-all`" @@ -236,6 +233,7 @@ CPPFLAGS="`echo $DEFINES $INCLUDES`" CPPFLAGS="$CPPFLAGS" \ SS_LIB="-lss" \ --enable-shared \ + --runstatedir=/run \ --localstatedir=%{_var}/kerberos \ --disable-rpath \ --without-krb5-config \ @@ -610,6 +608,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Jan 27 2021 Robbie Harwood - 1.19.0.beta2.1.2 +- Cope with new autotools behavior wrt runstatedir + * Tue Jan 26 2021 Fedora Release Engineering - 1.19-0.beta2.1.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild From ef09340be020c9841b9ab2fb0fca0adae163942a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 28 Jan 2021 10:56:02 -0500 Subject: [PATCH 214/304] Add APIs for marshalling credentials --- Add-APIs-for-marshalling-credentials.patch | 220 +++++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 225 insertions(+), 1 deletion(-) create mode 100644 Add-APIs-for-marshalling-credentials.patch diff --git a/Add-APIs-for-marshalling-credentials.patch b/Add-APIs-for-marshalling-credentials.patch new file mode 100644 index 0000000..39b3455 --- /dev/null +++ b/Add-APIs-for-marshalling-credentials.patch @@ -0,0 +1,220 @@ +From fd3ffdf173173e08abfe9ba78922f63723541c54 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 14 Jan 2021 18:13:09 -0500 +Subject: [PATCH] Add APIs for marshalling credentials + +Faciliate KCM daemon implementations by providing functions to +deserialize and reserialize credentials in the FILE v4 format. + +[ghudson@mit.edu: minor editorial changes] + +ticket: 8980 (new) +(cherry picked from commit 18ea3bd2fca55b789b7de9c663624bc11d348fa6) +--- + doc/appdev/refs/api/index.rst | 2 ++ + src/include/krb5/krb5.hin | 36 ++++++++++++++++++++++ + src/lib/krb5/ccache/ccmarshal.c | 53 +++++++++++++++++++++++++++++++++ + src/lib/krb5/ccache/t_marshal.c | 15 +++++++++- + src/lib/krb5/libkrb5.exports | 2 ++ + src/lib/krb5_32.def | 4 +++ + 6 files changed, 111 insertions(+), 1 deletion(-) + +diff --git a/doc/appdev/refs/api/index.rst b/doc/appdev/refs/api/index.rst +index 727d9b492..9e03fd386 100644 +--- a/doc/appdev/refs/api/index.rst ++++ b/doc/appdev/refs/api/index.rst +@@ -232,6 +232,7 @@ Rarely used public interfaces + krb5_kt_remove_entry.rst + krb5_kt_start_seq_get.rst + krb5_make_authdata_kdc_issued.rst ++ krb5_marshal_credentials.rst + krb5_merge_authdata.rst + krb5_mk_1cred.rst + krb5_mk_error.rst +@@ -285,6 +286,7 @@ Rarely used public interfaces + krb5_tkt_creds_get_times.rst + krb5_tkt_creds_init.rst + krb5_tkt_creds_step.rst ++ krb5_unmarshal_credentials.rst + krb5_verify_init_creds.rst + krb5_verify_init_creds_opt_init.rst + krb5_verify_init_creds_opt_set_ap_req_nofail.rst +diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin +index 63e67a2ba..c26dde535 100644 +--- a/src/include/krb5/krb5.hin ++++ b/src/include/krb5/krb5.hin +@@ -3125,6 +3125,42 @@ krb5_get_credentials(krb5_context context, krb5_flags options, + krb5_ccache ccache, krb5_creds *in_creds, + krb5_creds **out_creds); + ++/** ++ * Serialize a @c krb5_creds object. ++ * ++ * @param [in] context Library context ++ * @param [in] creds The credentials object to serialize ++ * @param [out] data_out The serialized credentials ++ * ++ * Serialize @a creds in the format used by the FILE ccache format (vesion 4) ++ * and KCM ccache protocol. ++ * ++ * Use krb5_free_data() to free @a data_out when it is no longer needed. ++ * ++ * @retval 0 Success; otherwise - Kerberos error codes ++ */ ++krb5_error_code KRB5_CALLCONV ++krb5_marshal_credentials(krb5_context context, krb5_creds *in_creds, ++ krb5_data **data_out); ++ ++/** ++ * Deserialize a @c krb5_creds object. ++ * ++ * @param [in] context Library context ++ * @param [in] data The serialized credentials ++ * @param [out] creds_out The resulting creds object ++ * ++ * Deserialize @a data to credentials in the format used by the FILE ccache ++ * format (vesion 4) and KCM ccache protocol. ++ * ++ * Use krb5_free_creds() to free @a creds_out when it is no longer needed. ++ * ++ * @retval 0 Success; otherwise - Kerberos error codes ++ */ ++krb5_error_code KRB5_CALLCONV ++krb5_unmarshal_credentials(krb5_context context, const krb5_data *data, ++ krb5_creds **creds_out); ++ + /** @deprecated Replaced by krb5_get_validated_creds. */ + krb5_error_code KRB5_CALLCONV + krb5_get_credentials_validate(krb5_context context, krb5_flags options, +diff --git a/src/lib/krb5/ccache/ccmarshal.c b/src/lib/krb5/ccache/ccmarshal.c +index ae634ccab..ab284e721 100644 +--- a/src/lib/krb5/ccache/ccmarshal.c ++++ b/src/lib/krb5/ccache/ccmarshal.c +@@ -515,3 +515,56 @@ k5_marshal_mcred(struct k5buf *buf, krb5_creds *mcred) + if (mcred->second_ticket.length > 0) + put_data(buf, version, &mcred->second_ticket); + } ++ ++krb5_error_code KRB5_CALLCONV ++krb5_marshal_credentials(krb5_context context, krb5_creds *in_creds, ++ krb5_data **data_out) ++{ ++ krb5_error_code ret; ++ krb5_data *data; ++ struct k5buf buf; ++ ++ *data_out = NULL; ++ ++ data = k5alloc(sizeof(krb5_data), &ret); ++ if (ret) ++ return ret; ++ ++ k5_buf_init_dynamic(&buf); ++ k5_marshal_cred(&buf, 4, in_creds); ++ ++ ret = k5_buf_status(&buf); ++ if (ret) { ++ free(data); ++ return ret; ++ } ++ ++ /* Steal payload from buf. */ ++ *data = make_data(buf.data, buf.len); ++ *data_out = data; ++ return 0; ++} ++ ++krb5_error_code KRB5_CALLCONV ++krb5_unmarshal_credentials(krb5_context context, const krb5_data *data, ++ krb5_creds **creds_out) ++{ ++ krb5_error_code ret; ++ krb5_creds *creds; ++ ++ *creds_out = NULL; ++ ++ creds = k5alloc(sizeof(krb5_creds), &ret); ++ if (ret) ++ return ret; ++ ++ ret = k5_unmarshal_cred((unsigned char *)data->data, data->length, 4, ++ creds); ++ if (ret) { ++ free(creds); ++ return ret; ++ } ++ ++ *creds_out = creds; ++ return 0; ++} +diff --git a/src/lib/krb5/ccache/t_marshal.c b/src/lib/krb5/ccache/t_marshal.c +index bd0284afa..96e0931a2 100644 +--- a/src/lib/krb5/ccache/t_marshal.c ++++ b/src/lib/krb5/ccache/t_marshal.c +@@ -268,13 +268,14 @@ main(int argc, char **argv) + krb5_context context; + krb5_ccache cache; + krb5_principal princ; +- krb5_creds cred1, cred2; ++ krb5_creds cred1, cred2, *alloc_cred; + krb5_cc_cursor cursor; + const char *filename; + char *ccname, filebuf[256]; + int version, fd; + const struct test *t; + struct k5buf buf; ++ krb5_data ser_data, *alloc_data; + + if (argc != 2) + abort(); +@@ -285,6 +286,18 @@ main(int argc, char **argv) + if (krb5_init_context(&context) != 0) + abort(); + ++ /* Test public functions for unmarshalling and marshalling. */ ++ ser_data = make_data((char *)tests[3].cred1, tests[3].cred1len); ++ if (krb5_unmarshal_credentials(context, &ser_data, &alloc_cred) != 0) ++ abort(); ++ verify_cred1(alloc_cred); ++ if (krb5_marshal_credentials(context, alloc_cred, &alloc_data) != 0) ++ abort(); ++ assert(alloc_data->length == tests[3].cred1len); ++ assert(memcmp(tests[3].cred1, alloc_data->data, alloc_data->length) == 0); ++ krb5_free_data(context, alloc_data); ++ krb5_free_creds(context, alloc_cred); ++ + for (version = FIRST_VERSION; version <= 4; version++) { + t = &tests[version - 1]; + +diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports +index 72652f2ce..9de0fcdb3 100644 +--- a/src/lib/krb5/libkrb5.exports ++++ b/src/lib/krb5/libkrb5.exports +@@ -489,6 +489,7 @@ krb5_lock_file + krb5_make_authdata_kdc_issued + krb5_make_full_ipaddr + krb5_make_fulladdr ++krb5_marshal_credentials + krb5_mcc_ops + krb5_merge_authdata + krb5_mk_1cred +@@ -591,6 +592,7 @@ krb5_timeofday + krb5_timestamp_to_sfstring + krb5_timestamp_to_string + krb5_unlock_file ++krb5_unmarshal_credentials + krb5_unpack_full_ipaddr + krb5_unparse_name + krb5_unparse_name_ext +diff --git a/src/lib/krb5_32.def b/src/lib/krb5_32.def +index 4953907aa..60b8dd311 100644 +--- a/src/lib/krb5_32.def ++++ b/src/lib/krb5_32.def +@@ -503,3 +503,7 @@ EXPORTS + ; new in 1.19 + k5_cc_store_primary_cred @470 ; PRIVATE + k5_kt_have_match @471 ; PRIVATE GSSAPI ++ ++; new in 1.20 ++ krb5_marshal_credentials @472 ++ krb5_unmarshal_credentials @473 diff --git a/krb5.spec b/krb5.spec index 62b763c..75e83f7 100644 --- a/krb5.spec +++ b/krb5.spec @@ -19,7 +19,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19 -Release: %{?zdpd}1%{?dist}.2 +Release: %{?zdpd}2%{?dist}.2 # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -47,6 +47,7 @@ Patch4: downstream-fix-debuginfo-with-y.tab.c.patch Patch5: downstream-Remove-3des-support.patch Patch6: downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +Patch8: Add-APIs-for-marshalling-credentials.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -608,6 +609,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jan 28 2021 Robbie Harwood - 1.19-2 +- Add APIs for marshalling credentials + * Wed Jan 27 2021 Robbie Harwood - 1.19.0.beta2.1.2 - Cope with new autotools behavior wrt runstatedir From 54bf131a4adaf8bb87e989b0087d48d18dc5f82d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 28 Jan 2021 16:16:22 +0000 Subject: [PATCH 215/304] Fix up weird mass rebuild versioning --- krb5.spec | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/krb5.spec b/krb5.spec index 75e83f7..73bda4a 100644 --- a/krb5.spec +++ b/krb5.spec @@ -19,7 +19,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19 -Release: %{?zdpd}2%{?dist}.2 +Release: %{?zdpd}3%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -609,10 +609,13 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog -* Thu Jan 28 2021 Robbie Harwood - 1.19-2 +* Thu Jan 28 2021 Robbie Harwood - 1.19-0.beta2.3 +- Fix up weird mass rebuild versioning + +* Thu Jan 28 2021 Robbie Harwood - 1.19-0.beta2.2.2 - Add APIs for marshalling credentials -* Wed Jan 27 2021 Robbie Harwood - 1.19.0.beta2.1.2 +* Wed Jan 27 2021 Robbie Harwood - 1.19-0.beta2.1.2 - Cope with new autotools behavior wrt runstatedir * Tue Jan 26 2021 Fedora Release Engineering - 1.19-0.beta2.1.1 From 042ca4af99e6c40f648d3e0738dc6a23b418dd07 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 28 Jan 2021 16:37:37 +0000 Subject: [PATCH 216/304] Require krb5-pkinit from krb5-{server,workstation} --- krb5.spec | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 73bda4a..87f00ec 100644 --- a/krb5.spec +++ b/krb5.spec @@ -19,7 +19,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19 -Release: %{?zdpd}3%{?dist} +Release: %{?zdpd}4%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -115,6 +115,7 @@ Kerberos, you need to install this package. %package server Summary: The KDC and related programs for Kerberos 5 Requires: %{name}-libs%{?_isa} = %{version}-%{release} +Requires: %{name}-pkinit%{?_isa} = %{version}-%{release} Requires(post): systemd-units Requires(preun): systemd-units Requires(postun): systemd-units @@ -151,6 +152,7 @@ realm, you need to install this package. %package workstation Summary: Kerberos 5 programs for use on workstations Requires: %{name}-libs%{?_isa} = %{version}-%{release} +Requires: %{name}-pkinit%{?_isa} = %{version}-%{release} Requires: libkadm5%{?_isa} = %{version}-%{release} %description workstation @@ -609,6 +611,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jan 28 2021 Robbie Harwood - 1.19-0.beta2.4 +- Require krb5-pkinit from krb5-{server,workstation} + * Thu Jan 28 2021 Robbie Harwood - 1.19-0.beta2.3 - Fix up weird mass rebuild versioning From 0dd40e4ff052566efcaa5425c4cb56bd5d23d56f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 28 Jan 2021 13:18:14 -0500 Subject: [PATCH 217/304] Support host-based GSS initiator names --- ...canonicalization-helper-to-k5test.py.patch | 84 +++ Support-host-based-GSS-initiator-names.patch | 578 ++++++++++++++++++ krb5.spec | 7 +- 3 files changed, 668 insertions(+), 1 deletion(-) create mode 100644 Add-hostname-canonicalization-helper-to-k5test.py.patch create mode 100644 Support-host-based-GSS-initiator-names.patch diff --git a/Add-hostname-canonicalization-helper-to-k5test.py.patch b/Add-hostname-canonicalization-helper-to-k5test.py.patch new file mode 100644 index 0000000..93d3963 --- /dev/null +++ b/Add-hostname-canonicalization-helper-to-k5test.py.patch @@ -0,0 +1,84 @@ +From 3204462c480484845513f2d7f323e367efde62cd Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 15 Jan 2021 14:43:34 -0500 +Subject: [PATCH] Add hostname canonicalization helper to k5test.py + +To facilitate fallback tests, add a canonicalize_hostname() function +to k5test.py which works similarly to krb5_expand_hostname(). Use it +in t_gssapi.py for the recently-added acceptor name fallback test. + +(cherry picked from commit 225fffe4e912772acea3a01d45bafb60bfb80948) +--- + src/tests/gssapi/t_gssapi.py | 11 +++-------- + src/util/k5test.py | 22 ++++++++++++++++++++++ + 2 files changed, 25 insertions(+), 8 deletions(-) + +diff --git a/src/tests/gssapi/t_gssapi.py b/src/tests/gssapi/t_gssapi.py +index 1af6f31c2..e22cec427 100755 +--- a/src/tests/gssapi/t_gssapi.py ++++ b/src/tests/gssapi/t_gssapi.py +@@ -8,7 +8,7 @@ for realm in multipass_realms(): + realm.run(['./t_iov', '-s', 'p:' + realm.host_princ]) + realm.run(['./t_pcontok', 'p:' + realm.host_princ]) + +-realm = K5Realm(krb5_conf={'libdefaults': {'rdns': 'false'}}) ++realm = K5Realm() + + # Test gss_add_cred(). + realm.run(['./t_add_cred']) +@@ -62,13 +62,8 @@ realm.run(['./t_accname', 'p:host/-nomatch-', + expected_msg=' not found in keytab') + + # If possible, test with an acceptor name requiring fallback to match +-# against a keytab entry. Forward-canonicalize the hostname, relying +-# on the rdns=false realm setting. +-try: +- ai = socket.getaddrinfo(hostname, None, 0, 0, 0, socket.AI_CANONNAME) +- (family, socktype, proto, canonname, sockaddr) = ai[0] +-except socket.gaierror: +- canonname = hostname ++# against a keytab entry. ++canonname = canonicalize_hostname(hostname) + if canonname != hostname: + os.rename(realm.keytab, realm.keytab + '.save') + canonprinc = 'host/' + canonname +diff --git a/src/util/k5test.py b/src/util/k5test.py +index 789b0f4b9..251d11a9d 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -155,6 +155,10 @@ Scripts may use the following functions and variables: + * password(name): Return a weakly random password based on name. The + password will be consistent across calls with the same name. + ++* canonicalize_hostname(name, rdns=True): Return the DNS ++ canonicalization of name, optionally using reverse DNS. On error, ++ return name converted to lowercase. ++ + * stop_daemon(proc): Stop a daemon process started with + realm.start_server() or realm.start_in_inetd(). Only necessary if + the port needs to be reused; daemon processes will be stopped +@@ -458,6 +462,24 @@ def password(name): + return name + str(os.getpid()) + + ++def canonicalize_hostname(name, rdns=True): ++ """Canonicalize name using DNS, optionally with reverse DNS.""" ++ try: ++ ai = socket.getaddrinfo(name, None, 0, 0, 0, socket.AI_CANONNAME) ++ except socket.gaierror as e: ++ return name.lower() ++ (family, socktype, proto, canonname, sockaddr) = ai[0] ++ ++ if not rdns: ++ return canonname.lower() ++ ++ try: ++ rname = socket.getnameinfo(sockaddr, socket.NI_NAMEREQD) ++ except socket.gaierror: ++ return canonname.lower() ++ return rname[0].lower() ++ ++ + # Exit handler which ensures processes are cleaned up and, on failure, + # prints messages to help developers debug the problem. + def _onexit(): diff --git a/Support-host-based-GSS-initiator-names.patch b/Support-host-based-GSS-initiator-names.patch new file mode 100644 index 0000000..f04609f --- /dev/null +++ b/Support-host-based-GSS-initiator-names.patch @@ -0,0 +1,578 @@ +From 067e3a509442d81d1a31dd4bcbcc190f55369cc9 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 15 Jan 2021 13:51:34 -0500 +Subject: [PATCH] Support host-based GSS initiator names + +When checking if we can get initial credentials in the GSS krb5 mech, +use krb5_kt_have_match() to support fallback iteration. When scanning +the ccache or getting initial credentials, rewrite cred->name->princ +to the canonical client name. When a name check is necessary (such as +when the caller specifies both a name and ccache), use a new internal +API k5_sname_compare() to support fallback iteration. Add fallback +iteration to krb5_cc_cache_match() to allow host-based names to be +canonicalized against the cache collection. + +Create and store the matching principal for acceptor names in +acquire_accept_cred() so that it isn't affected by changes in +cred->name->princ during acquire_init_cred(). + +ticket: 8978 (new) +(cherry picked from commit c374ab40dd059a5938ffc0440d87457ac5da3a46) +--- + src/include/k5-int.h | 9 +++ + src/include/k5-trace.h | 3 + + src/lib/gssapi/krb5/accept_sec_context.c | 15 +--- + src/lib/gssapi/krb5/acquire_cred.c | 89 ++++++++++++++---------- + src/lib/gssapi/krb5/gssapiP_krb5.h | 1 + + src/lib/gssapi/krb5/rel_cred.c | 1 + + src/lib/krb5/ccache/cccursor.c | 57 +++++++++++---- + src/lib/krb5/libkrb5.exports | 1 + + src/lib/krb5/os/sn2princ.c | 23 +++++- + src/lib/krb5_32.def | 1 + + src/tests/gssapi/t_client_keytab.py | 44 ++++++++++++ + src/tests/gssapi/t_credstore.py | 32 +++++++++ + 12 files changed, 214 insertions(+), 62 deletions(-) + +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index efb523689..46f2ce2d3 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -2411,4 +2411,13 @@ void k5_change_error_message_code(krb5_context ctx, krb5_error_code oldcode, + #define k5_prependmsg krb5_prepend_error_message + #define k5_wrapmsg krb5_wrap_error_message + ++/* ++ * Like krb5_principal_compare(), but with canonicalization of sname if ++ * fallback is enabled. This function should be avoided if multiple matches ++ * are required, since repeated canonicalization is inefficient. ++ */ ++krb5_boolean ++k5_sname_compare(krb5_context context, krb5_const_principal sname, ++ krb5_const_principal princ); ++ + #endif /* _KRB5_INT_H */ +diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h +index b3e039dc8..79b5a7a85 100644 +--- a/src/include/k5-trace.h ++++ b/src/include/k5-trace.h +@@ -105,6 +105,9 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); + + #endif /* DISABLE_TRACING */ + ++#define TRACE_CC_CACHE_MATCH(c, princ, ret) \ ++ TRACE(c, "Matching {princ} in collection with result: {kerr}", \ ++ princ, ret) + #define TRACE_CC_DESTROY(c, cache) \ + TRACE(c, "Destroying ccache {ccache}", cache) + #define TRACE_CC_GEN_NEW(c, cache) \ +diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c +index fcf2c2152..a1d7e0d96 100644 +--- a/src/lib/gssapi/krb5/accept_sec_context.c ++++ b/src/lib/gssapi/krb5/accept_sec_context.c +@@ -683,7 +683,6 @@ kg_accept_krb5(minor_status, context_handle, + krb5_flags ap_req_options = 0; + krb5_enctype negotiated_etype; + krb5_authdata_context ad_context = NULL; +- krb5_principal accprinc = NULL; + krb5_ap_req *request = NULL; + + code = krb5int_accessor (&kaccess, KRB5INT_ACCESS_VERSION); +@@ -849,17 +848,9 @@ kg_accept_krb5(minor_status, context_handle, + } + } + +- if (!cred->default_identity) { +- if ((code = kg_acceptor_princ(context, cred->name, &accprinc))) { +- major_status = GSS_S_FAILURE; +- goto fail; +- } +- } +- +- code = krb5_rd_req_decoded(context, &auth_context, request, accprinc, +- cred->keytab, &ap_req_options, NULL); +- +- krb5_free_principal(context, accprinc); ++ code = krb5_rd_req_decoded(context, &auth_context, request, ++ cred->acceptor_mprinc, cred->keytab, ++ &ap_req_options, NULL); + if (code) { + major_status = GSS_S_FAILURE; + goto fail; +diff --git a/src/lib/gssapi/krb5/acquire_cred.c b/src/lib/gssapi/krb5/acquire_cred.c +index 632ee7def..e226a0269 100644 +--- a/src/lib/gssapi/krb5/acquire_cred.c ++++ b/src/lib/gssapi/krb5/acquire_cred.c +@@ -123,11 +123,11 @@ gss_krb5int_register_acceptor_identity(OM_uint32 *minor_status, + /* Try to verify that keytab contains at least one entry for name. Return 0 if + * it does, KRB5_KT_NOTFOUND if it doesn't, or another error as appropriate. */ + static krb5_error_code +-check_keytab(krb5_context context, krb5_keytab kt, krb5_gss_name_t name) ++check_keytab(krb5_context context, krb5_keytab kt, krb5_gss_name_t name, ++ krb5_principal mprinc) + { + krb5_error_code code; + krb5_keytab_entry ent; +- krb5_principal accprinc = NULL; + char *princname; + + if (name->service == NULL) { +@@ -141,21 +141,15 @@ check_keytab(krb5_context context, krb5_keytab kt, krb5_gss_name_t name) + if (kt->ops->start_seq_get == NULL) + return 0; + +- /* Get the partial principal for the acceptor name. */ +- code = kg_acceptor_princ(context, name, &accprinc); +- if (code) +- return code; +- +- /* Scan the keytab for host-based entries matching accprinc. */ +- code = k5_kt_have_match(context, kt, accprinc); ++ /* Scan the keytab for host-based entries matching mprinc. */ ++ code = k5_kt_have_match(context, kt, mprinc); + if (code == KRB5_KT_NOTFOUND) { +- if (krb5_unparse_name(context, accprinc, &princname) == 0) { ++ if (krb5_unparse_name(context, mprinc, &princname) == 0) { + k5_setmsg(context, code, _("No key table entry found matching %s"), + princname); + free(princname); + } + } +- krb5_free_principal(context, accprinc); + return code; + } + +@@ -202,8 +196,14 @@ acquire_accept_cred(krb5_context context, OM_uint32 *minor_status, + } + + if (cred->name != NULL) { ++ code = kg_acceptor_princ(context, cred->name, &cred->acceptor_mprinc); ++ if (code) { ++ major = GSS_S_FAILURE; ++ goto cleanup; ++ } ++ + /* Make sure we have keys matching the desired name in the keytab. */ +- code = check_keytab(context, kt, cred->name); ++ code = check_keytab(context, kt, cred->name, cred->acceptor_mprinc); + if (code) { + if (code == KRB5_KT_NOTFOUND) { + k5_change_error_message_code(context, code, KG_KEYTAB_NOMATCH); +@@ -324,7 +324,6 @@ static krb5_boolean + can_get_initial_creds(krb5_context context, krb5_gss_cred_id_rec *cred) + { + krb5_error_code code; +- krb5_keytab_entry entry; + + if (cred->password != NULL) + return TRUE; +@@ -336,20 +335,21 @@ can_get_initial_creds(krb5_context context, krb5_gss_cred_id_rec *cred) + if (cred->name == NULL) + return !krb5_kt_have_content(context, cred->client_keytab); + +- /* Check if we have a keytab key for the client principal. */ +- code = krb5_kt_get_entry(context, cred->client_keytab, cred->name->princ, +- 0, 0, &entry); +- if (code) { +- krb5_clear_error_message(context); +- return FALSE; +- } +- krb5_free_keytab_entry_contents(context, &entry); +- return TRUE; ++ /* ++ * Check if we have a keytab key for the client principal. This is a bit ++ * more permissive than we really want because krb5_kt_have_match() ++ * supports wildcarding and obeys ignore_acceptor_hostname, but that should ++ * generally be harmless. ++ */ ++ code = k5_kt_have_match(context, cred->client_keytab, cred->name->princ); ++ return code == 0; + } + +-/* Scan cred->ccache for name, expiry time, impersonator, refresh time. */ ++/* Scan cred->ccache for name, expiry time, impersonator, refresh time. If ++ * check_name is true, verify the cache name against the credential name. */ + static krb5_error_code +-scan_ccache(krb5_context context, krb5_gss_cred_id_rec *cred) ++scan_ccache(krb5_context context, krb5_gss_cred_id_rec *cred, ++ krb5_boolean check_name) + { + krb5_error_code code; + krb5_ccache ccache = cred->ccache; +@@ -365,23 +365,31 @@ scan_ccache(krb5_context context, krb5_gss_cred_id_rec *cred) + if (code) + return code; + +- /* Credentials cache principal must match the initiator name. */ + code = krb5_cc_get_principal(context, ccache, &ccache_princ); + if (code != 0) + goto cleanup; +- if (cred->name != NULL && +- !krb5_principal_compare(context, ccache_princ, cred->name->princ)) { +- code = KG_CCACHE_NOMATCH; +- goto cleanup; +- } + +- /* Save the ccache principal as the credential name if not already set. */ +- if (!cred->name) { ++ if (cred->name == NULL) { ++ /* Save the ccache principal as the credential name. */ + code = kg_init_name(context, ccache_princ, NULL, NULL, NULL, + KG_INIT_NAME_NO_COPY, &cred->name); + if (code) + goto cleanup; + ccache_princ = NULL; ++ } else { ++ /* Check against the desired name if needed. */ ++ if (check_name) { ++ if (!k5_sname_compare(context, cred->name->princ, ccache_princ)) { ++ code = KG_CCACHE_NOMATCH; ++ goto cleanup; ++ } ++ } ++ ++ /* Replace the credential name principal with the canonical client ++ * principal, retaining acceptor_mprinc if set. */ ++ krb5_free_principal(context, cred->name->princ); ++ cred->name->princ = ccache_princ; ++ ccache_princ = NULL; + } + + assert(cred->name->princ != NULL); +@@ -447,7 +455,7 @@ get_cache_for_name(krb5_context context, krb5_gss_cred_id_rec *cred) + assert(cred->name != NULL && cred->ccache == NULL); + #ifdef USE_LEASH + code = get_ccache_leash(context, cred->name->princ, &cred->ccache); +- return code ? code : scan_ccache(context, cred); ++ return code ? code : scan_ccache(context, cred, TRUE); + #else + /* Check first whether we can acquire tickets, to avoid overwriting the + * extended error message from krb5_cc_cache_match. */ +@@ -456,7 +464,7 @@ get_cache_for_name(krb5_context context, krb5_gss_cred_id_rec *cred) + /* Look for an existing cache for the client principal. */ + code = krb5_cc_cache_match(context, cred->name->princ, &cred->ccache); + if (code == 0) +- return scan_ccache(context, cred); ++ return scan_ccache(context, cred, FALSE); + if (code != KRB5_CC_NOTFOUND || !can_get) + return code; + krb5_clear_error_message(context); +@@ -633,6 +641,13 @@ get_initial_cred(krb5_context context, const struct verify_params *verify, + kg_cred_set_initial_refresh(context, cred, &creds.times); + cred->have_tgt = TRUE; + cred->expire = creds.times.endtime; ++ ++ /* Steal the canonical client principal name from creds and save it in the ++ * credential name, retaining acceptor_mprinc if set. */ ++ krb5_free_principal(context, cred->name->princ); ++ cred->name->princ = creds.client; ++ creds.client = NULL; ++ + krb5_free_cred_contents(context, &creds); + cleanup: + krb5_get_init_creds_opt_free(context, opt); +@@ -721,7 +736,7 @@ acquire_init_cred(krb5_context context, OM_uint32 *minor_status, + + if (cred->ccache != NULL) { + /* The caller specified a ccache; check what's in it. */ +- code = scan_ccache(context, cred); ++ code = scan_ccache(context, cred, TRUE); + if (code == KRB5_FCC_NOFILE) { + /* See if we can get initial creds. If the caller didn't specify + * a name, pick one from the client keytab. */ +@@ -984,7 +999,7 @@ kg_cred_resolve(OM_uint32 *minor_status, krb5_context context, + } + } + if (cred->ccache != NULL) { +- code = scan_ccache(context, cred); ++ code = scan_ccache(context, cred, FALSE); + if (code) + goto kerr; + } +@@ -996,7 +1011,7 @@ kg_cred_resolve(OM_uint32 *minor_status, krb5_context context, + code = krb5int_cc_default(context, &cred->ccache); + if (code) + goto kerr; +- code = scan_ccache(context, cred); ++ code = scan_ccache(context, cred, FALSE); + if (code == KRB5_FCC_NOFILE) { + /* Default ccache doesn't exist; fall through to client keytab. */ + krb5_cc_close(context, cred->ccache); +diff --git a/src/lib/gssapi/krb5/gssapiP_krb5.h b/src/lib/gssapi/krb5/gssapiP_krb5.h +index 3bacdcd35..fd7abbd77 100644 +--- a/src/lib/gssapi/krb5/gssapiP_krb5.h ++++ b/src/lib/gssapi/krb5/gssapiP_krb5.h +@@ -175,6 +175,7 @@ typedef struct _krb5_gss_cred_id_rec { + /* name/type of credential */ + gss_cred_usage_t usage; + krb5_gss_name_t name; ++ krb5_principal acceptor_mprinc; + krb5_principal impersonator; + unsigned int default_identity : 1; + unsigned int iakerb_mech : 1; +diff --git a/src/lib/gssapi/krb5/rel_cred.c b/src/lib/gssapi/krb5/rel_cred.c +index a9515daf7..0da6c1b95 100644 +--- a/src/lib/gssapi/krb5/rel_cred.c ++++ b/src/lib/gssapi/krb5/rel_cred.c +@@ -72,6 +72,7 @@ krb5_gss_release_cred(minor_status, cred_handle) + if (cred->name) + kg_release_name(context, &cred->name); + ++ krb5_free_principal(context, cred->acceptor_mprinc); + krb5_free_principal(context, cred->impersonator); + + if (cred->req_enctypes) +diff --git a/src/lib/krb5/ccache/cccursor.c b/src/lib/krb5/ccache/cccursor.c +index 8f5872116..760216d05 100644 +--- a/src/lib/krb5/ccache/cccursor.c ++++ b/src/lib/krb5/ccache/cccursor.c +@@ -30,6 +30,7 @@ + + #include "cc-int.h" + #include "../krb/int-proto.h" ++#include "../os/os-proto.h" + + #include + +@@ -141,18 +142,18 @@ krb5_cccol_cursor_free(krb5_context context, + return 0; + } + +-krb5_error_code KRB5_CALLCONV +-krb5_cc_cache_match(krb5_context context, krb5_principal client, +- krb5_ccache *cache_out) ++static krb5_error_code ++match_caches(krb5_context context, krb5_const_principal client, ++ krb5_ccache *cache_out) + { + krb5_error_code ret; + krb5_cccol_cursor cursor; + krb5_ccache cache = NULL; + krb5_principal princ; +- char *name; + krb5_boolean eq; + + *cache_out = NULL; ++ + ret = krb5_cccol_cursor_new(context, &cursor); + if (ret) + return ret; +@@ -169,20 +170,52 @@ krb5_cc_cache_match(krb5_context context, krb5_principal client, + krb5_cc_close(context, cache); + } + krb5_cccol_cursor_free(context, &cursor); ++ + if (ret) + return ret; +- if (cache == NULL) { +- ret = krb5_unparse_name(context, client, &name); +- if (ret == 0) { +- k5_setmsg(context, KRB5_CC_NOTFOUND, ++ if (cache == NULL) ++ return KRB5_CC_NOTFOUND; ++ ++ *cache_out = cache; ++ return 0; ++} ++ ++krb5_error_code KRB5_CALLCONV ++krb5_cc_cache_match(krb5_context context, krb5_principal client, ++ krb5_ccache *cache_out) ++{ ++ krb5_error_code ret; ++ struct canonprinc iter = { client, .subst_defrealm = TRUE }; ++ krb5_const_principal canonprinc = NULL; ++ krb5_ccache cache = NULL; ++ char *name; ++ ++ *cache_out = NULL; ++ ++ while ((ret = k5_canonprinc(context, &iter, &canonprinc)) == 0 && ++ canonprinc != NULL) { ++ ret = match_caches(context, canonprinc, &cache); ++ if (ret != KRB5_CC_NOTFOUND) ++ break; ++ } ++ free_canonprinc(&iter); ++ ++ if (ret == 0 && canonprinc == NULL) { ++ ret = KRB5_CC_NOTFOUND; ++ if (krb5_unparse_name(context, client, &name) == 0) { ++ k5_setmsg(context, ret, + _("Can't find client principal %s in cache collection"), + name); + krb5_free_unparsed_name(context, name); + } +- ret = KRB5_CC_NOTFOUND; +- } else +- *cache_out = cache; +- return ret; ++ } ++ ++ TRACE_CC_CACHE_MATCH(context, client, ret); ++ if (ret) ++ return ret; ++ ++ *cache_out = cache; ++ return 0; + } + + /* Store the error state for code from context into errsave, but only if code +diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports +index 9de0fcdb3..25141dfc5 100644 +--- a/src/lib/krb5/libkrb5.exports ++++ b/src/lib/krb5/libkrb5.exports +@@ -181,6 +181,7 @@ k5_size_authdata_context + k5_size_context + k5_size_keyblock + k5_size_principal ++k5_sname_compare + k5_unmarshal_cred + k5_unmarshal_princ + k5_unwrap_cammac_svc +diff --git a/src/lib/krb5/os/sn2princ.c b/src/lib/krb5/os/sn2princ.c +index 8b7214189..c99b7da17 100644 +--- a/src/lib/krb5/os/sn2princ.c ++++ b/src/lib/krb5/os/sn2princ.c +@@ -277,7 +277,8 @@ k5_canonprinc(krb5_context context, struct canonprinc *iter, + + /* If we're not doing fallback, the input principal is canonical. */ + if (context->dns_canonicalize_hostname != CANONHOST_FALLBACK || +- iter->princ->type != KRB5_NT_SRV_HST || iter->princ->length != 2) { ++ iter->princ->type != KRB5_NT_SRV_HST || iter->princ->length != 2 || ++ iter->princ->data[1].length == 0) { + *princ_out = (step == 1) ? iter->princ : NULL; + return 0; + } +@@ -288,6 +289,26 @@ k5_canonprinc(krb5_context context, struct canonprinc *iter, + return canonicalize_princ(context, iter, step == 2, princ_out); + } + ++krb5_boolean ++k5_sname_compare(krb5_context context, krb5_const_principal sname, ++ krb5_const_principal princ) ++{ ++ krb5_error_code ret; ++ struct canonprinc iter = { sname, .subst_defrealm = TRUE }; ++ krb5_const_principal canonprinc = NULL; ++ krb5_boolean match = FALSE; ++ ++ while ((ret = k5_canonprinc(context, &iter, &canonprinc)) == 0 && ++ canonprinc != NULL) { ++ if (krb5_principal_compare(context, canonprinc, princ)) { ++ match = TRUE; ++ break; ++ } ++ } ++ free_canonprinc(&iter); ++ return match; ++} ++ + krb5_error_code KRB5_CALLCONV + krb5_sname_to_principal(krb5_context context, const char *hostname, + const char *sname, krb5_int32 type, +diff --git a/src/lib/krb5_32.def b/src/lib/krb5_32.def +index 60b8dd311..cf690dbe4 100644 +--- a/src/lib/krb5_32.def ++++ b/src/lib/krb5_32.def +@@ -507,3 +507,4 @@ EXPORTS + ; new in 1.20 + krb5_marshal_credentials @472 + krb5_unmarshal_credentials @473 ++ k5_sname_compare @474 ; PRIVATE GSSAPI +diff --git a/src/tests/gssapi/t_client_keytab.py b/src/tests/gssapi/t_client_keytab.py +index 7847b3ecd..9a61d53b8 100755 +--- a/src/tests/gssapi/t_client_keytab.py ++++ b/src/tests/gssapi/t_client_keytab.py +@@ -141,5 +141,49 @@ msgs = ('Getting initial credentials for user/admin@KRBTEST.COM', + '/Matching credential not found') + realm.run(['./t_ccselect', phost], expected_code=1, + expected_msg='Ticket expired', expected_trace=msgs) ++realm.run([kdestroy, '-A']) ++ ++# Test 19: host-based initiator name ++mark('host-based initiator name') ++hsvc = 'h:svc@' + hostname ++svcprinc = 'svc/%s@%s' % (hostname, realm.realm) ++realm.addprinc(svcprinc) ++realm.extract_keytab(svcprinc, realm.client_keytab) ++# On the first run we match against the keytab while getting tickets, ++# substituting the default realm. ++msgs = ('/Can\'t find client principal svc/%s@ in' % hostname, ++ 'Getting initial credentials for svc/%s@' % hostname, ++ 'Found entries for %s in keytab' % svcprinc, ++ 'Retrieving %s from FILE:%s' % (svcprinc, realm.client_keytab), ++ 'Storing %s -> %s in' % (svcprinc, realm.krbtgt_princ), ++ 'Retrieving %s -> %s from' % (svcprinc, realm.krbtgt_princ), ++ 'authenticator for %s -> %s' % (svcprinc, realm.host_princ)) ++realm.run(['./t_ccselect', phost, hsvc], expected_trace=msgs) ++# On the second run we match against the collection. ++msgs = ('Matching svc/%s@ in collection with result: 0' % hostname, ++ 'Getting credentials %s -> %s' % (svcprinc, realm.host_princ), ++ 'authenticator for %s -> %s' % (svcprinc, realm.host_princ)) ++realm.run(['./t_ccselect', phost, hsvc], expected_trace=msgs) ++realm.run([kdestroy, '-A']) ++ ++# Test 20: host-based initiator name with fallback ++mark('host-based fallback initiator name') ++canonname = canonicalize_hostname(hostname) ++if canonname != hostname: ++ hfsvc = 'h:fsvc@' + hostname ++ canonprinc = 'fsvc/%s@%s' % (canonname, realm.realm) ++ realm.addprinc(canonprinc) ++ realm.extract_keytab(canonprinc, realm.client_keytab) ++ msgs = ('/Can\'t find client principal fsvc/%s@ in' % hostname, ++ 'Found entries for %s in keytab' % canonprinc, ++ 'authenticator for %s -> %s' % (canonprinc, realm.host_princ)) ++ realm.run(['./t_ccselect', phost, hfsvc], expected_trace=msgs) ++ msgs = ('Matching fsvc/%s@ in collection with result: 0' % hostname, ++ 'Getting credentials %s -> %s' % (canonprinc, realm.host_princ)) ++ realm.run(['./t_ccselect', phost, hfsvc], expected_trace=msgs) ++ realm.run([kdestroy, '-A']) ++else: ++ skipped('GSS initiator name fallback test', ++ '%s does not canonicalize to a different name' % hostname) + + success('Client keytab tests') +diff --git a/src/tests/gssapi/t_credstore.py b/src/tests/gssapi/t_credstore.py +index c11975bf5..9be57bb82 100644 +--- a/src/tests/gssapi/t_credstore.py ++++ b/src/tests/gssapi/t_credstore.py +@@ -15,6 +15,38 @@ msgs = ('Storing %s -> %s in %s' % (service_cs, realm.krbtgt_princ, + realm.run(['./t_credstore', '-s', 'p:' + service_cs, 'ccache', storagecache, + 'keytab', servicekeytab], expected_trace=msgs) + ++mark('matching') ++scc = 'FILE:' + os.path.join(realm.testdir, 'service_cache') ++realm.kinit(realm.host_princ, flags=['-k', '-c', scc]) ++realm.run(['./t_credstore', '-i', 'p:' + realm.host_princ, 'ccache', scc]) ++realm.run(['./t_credstore', '-i', 'h:host', 'ccache', scc]) ++realm.run(['./t_credstore', '-i', 'h:host@' + hostname, 'ccache', scc]) ++realm.run(['./t_credstore', '-i', 'p:wrong', 'ccache', scc], ++ expected_code=1, expected_msg='does not match desired name') ++realm.run(['./t_credstore', '-i', 'h:host@-nomatch-', 'ccache', scc], ++ expected_code=1, expected_msg='does not match desired name') ++realm.run(['./t_credstore', '-i', 'h:svc', 'ccache', scc], ++ expected_code=1, expected_msg='does not match desired name') ++ ++mark('matching (fallback)') ++canonname = canonicalize_hostname(hostname) ++if canonname != hostname: ++ canonprinc = 'host/%s@%s' % (canonname, realm.realm) ++ realm.addprinc(canonprinc) ++ realm.extract_keytab(canonprinc, realm.keytab) ++ realm.kinit(canonprinc, flags=['-k', '-c', scc]) ++ realm.run(['./t_credstore', '-i', 'h:host', 'ccache', scc]) ++ realm.run(['./t_credstore', '-i', 'h:host@' + hostname, 'ccache', scc]) ++ realm.run(['./t_credstore', '-i', 'h:host@' + canonname, 'ccache', scc]) ++ realm.run(['./t_credstore', '-i', 'p:' + canonprinc, 'ccache', scc]) ++ realm.run(['./t_credstore', '-i', 'p:' + realm.host_princ, 'ccache', scc], ++ expected_code=1, expected_msg='does not match desired name') ++ realm.run(['./t_credstore', '-i', 'h:host@-nomatch-', 'ccache', scc], ++ expected_code=1, expected_msg='does not match desired name') ++else: ++ skipped('fallback matching test', ++ '%s does not canonicalize to a different name' % hostname) ++ + mark('rcache') + # t_credstore -r should produce a replay error normally, but not with + # rcache set to "none:". diff --git a/krb5.spec b/krb5.spec index 87f00ec..8994c9c 100644 --- a/krb5.spec +++ b/krb5.spec @@ -19,7 +19,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19 -Release: %{?zdpd}4%{?dist} +Release: %{?zdpd}5%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -48,6 +48,8 @@ Patch5: downstream-Remove-3des-support.patch Patch6: downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch Patch8: Add-APIs-for-marshalling-credentials.patch +Patch9: Add-hostname-canonicalization-helper-to-k5test.py.patch +Patch10: Support-host-based-GSS-initiator-names.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -611,6 +613,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jan 28 2021 Robbie Harwood - 1.19-5 +- Support host-based GSS initiator names + * Thu Jan 28 2021 Robbie Harwood - 1.19-0.beta2.4 - Require krb5-pkinit from krb5-{server,workstation} From 105082cb422bee964b8feb51f39771c9d0425c34 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 1 Feb 2021 15:58:49 -0500 Subject: [PATCH 218/304] Hoist and add an option for disabling %check --- krb5.spec | 44 ++++++++++++++++++++++++++++---------------- 1 file changed, 28 insertions(+), 16 deletions(-) diff --git a/krb5.spec b/krb5.spec index 8994c9c..8be82d9 100644 --- a/krb5.spec +++ b/krb5.spec @@ -1,3 +1,27 @@ +%bcond_without check +%if %{without check} +%global skipcheck 1 +%endif + +# COPR doesn't work right with the tests. I suspect keyring issues, +# but can't actually debug, so... +%if 0%{?copr_username:1} +%global skipcheck 1 +%endif + +# There are 0 test machines for this architecture, very few builders, and +# they're not very well provisioned / maintained. I can't support it. +# Patches welcome, but there's nothing I can do - it fails more than half the +# for "infrastructure issues" that I can't hope to debug. +%ifarch s390x +%global skipcheck 1 +%endif + +# RHEL runs upstream's test suite in a separate pass after build. +%if 0%{?rhel} +%global skipcheck 1 +%endif + # Set this so that find-lang.sh will recognize the .po files. %global gettext_domain mit-krb5 # Guess where the -libs subpackage's docs are going to go. @@ -278,26 +302,14 @@ sphinx-build -a -b man -t pathsubs doc build-man sphinx-build -a -b html -t pathsubs doc build-html rm -fr build-html/_sources -%check - -# There are 0 test machines for this architecture, very few builders, and -# they're not very well provisioned / maintained. I can't support it. -# Patches welcome, but there's nothing I can do - it fails more than half the -# time for no discernable reason. -%ifnarch s390x -pushd src - -# ugh. COPR doesn't work right with the tests. I suspect keyring issues, but -# can't actually debug, so... -%if 0%{?copr_username:1} -%global keyctl : +%if 0%{?skipcheck} %else -%global keyctl keyctl -%endif +%check +pushd src # The build system may give us a revoked session keyring, so run affected # tests with a new one. -%{keyctl} session - make check OFFLINE=yes TMPDIR=%{_tmppath} +keyctl session - make check OFFLINE=yes TMPDIR=%{_tmppath} popd %endif From d5839d05119d47fad99e688c0a54d295c6e30024 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Feb 2021 10:24:01 -0500 Subject: [PATCH 219/304] New upstream version (1.19) --- .gitignore | 2 ++ Add-APIs-for-marshalling-credentials.patch | 2 +- ...me-canonicalization-helper-to-k5test.py.patch | 2 +- Support-host-based-GSS-initiator-names.patch | 2 +- ...tream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 2 +- downstream-Remove-3des-support.patch | 2 +- downstream-SELinux-integration.patch | 2 +- ...e-backported-version-of-OpenSSL-3-KDF-i.patch | 2 +- downstream-fix-debuginfo-with-y.tab.c.patch | 2 +- downstream-ksu-pam-integration.patch | 2 +- downstream-netlib-and-dns.patch | 2 +- krb5.spec | 16 +++++++++------- sources | 4 ++-- 13 files changed, 23 insertions(+), 19 deletions(-) diff --git a/.gitignore b/.gitignore index c686550..591c859 100644 --- a/.gitignore +++ b/.gitignore @@ -193,3 +193,5 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.19-beta1.tar.gz.asc /krb5-1.19-beta2.tar.gz /krb5-1.19-beta2.tar.gz.asc +/krb5-1.19.tar.gz +/krb5-1.19.tar.gz.asc diff --git a/Add-APIs-for-marshalling-credentials.patch b/Add-APIs-for-marshalling-credentials.patch index 39b3455..4c963d3 100644 --- a/Add-APIs-for-marshalling-credentials.patch +++ b/Add-APIs-for-marshalling-credentials.patch @@ -1,4 +1,4 @@ -From fd3ffdf173173e08abfe9ba78922f63723541c54 Mon Sep 17 00:00:00 2001 +From 057b45609fa457f2247df93b163f31723fd18077 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Jan 2021 18:13:09 -0500 Subject: [PATCH] Add APIs for marshalling credentials diff --git a/Add-hostname-canonicalization-helper-to-k5test.py.patch b/Add-hostname-canonicalization-helper-to-k5test.py.patch index 93d3963..83697cd 100644 --- a/Add-hostname-canonicalization-helper-to-k5test.py.patch +++ b/Add-hostname-canonicalization-helper-to-k5test.py.patch @@ -1,4 +1,4 @@ -From 3204462c480484845513f2d7f323e367efde62cd Mon Sep 17 00:00:00 2001 +From 1d7b365e670f19beae319fde2abf1de0601a2a34 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 15 Jan 2021 14:43:34 -0500 Subject: [PATCH] Add hostname canonicalization helper to k5test.py diff --git a/Support-host-based-GSS-initiator-names.patch b/Support-host-based-GSS-initiator-names.patch index f04609f..a9ca98d 100644 --- a/Support-host-based-GSS-initiator-names.patch +++ b/Support-host-based-GSS-initiator-names.patch @@ -1,4 +1,4 @@ -From 067e3a509442d81d1a31dd4bcbcc190f55369cc9 Mon Sep 17 00:00:00 2001 +From c1df10d60512e1697ef18b343c237c6a96baf62c Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 15 Jan 2021 13:51:34 -0500 Subject: [PATCH] Support host-based GSS initiator names diff --git a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index 8ca2534..ed61cf0 100644 --- a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From 836fdca1ac4bb58498551e1afe8ca6e55d41902d Mon Sep 17 00:00:00 2001 +From b57c3a8fbeb0e83c9faa63ac49c5ed58971aa934 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 diff --git a/downstream-Remove-3des-support.patch b/downstream-Remove-3des-support.patch index 046a1be..efb79d0 100644 --- a/downstream-Remove-3des-support.patch +++ b/downstream-Remove-3des-support.patch @@ -1,4 +1,4 @@ -From 329c97793a3e96e79f618bc54914ec89a9e99828 Mon Sep 17 00:00:00 2001 +From 5ff60c965583977ee4a4f98555973f9920fc79cd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] [downstream] Remove 3des support diff --git a/downstream-SELinux-integration.patch b/downstream-SELinux-integration.patch index 7c134eb..d68bd92 100644 --- a/downstream-SELinux-integration.patch +++ b/downstream-SELinux-integration.patch @@ -1,4 +1,4 @@ -From 1de6ec4cb5b2a1b7b88680ae0f72551a3b5178e6 Mon Sep 17 00:00:00 2001 +From 99e57d4cbf0eb060162b7038d6e7b202d2716784 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] [downstream] SELinux integration diff --git a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch index cb35de1..9ba0821 100644 --- a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch +++ b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch @@ -1,4 +1,4 @@ -From 120e84b63c322c227fb8c6ee8a2f56f47d3e57f5 Mon Sep 17 00:00:00 2001 +From 387ae61e2b6384eba692e777cc1bcc3d34bfa8c6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 15 Nov 2019 20:05:16 +0000 Subject: [PATCH] [downstream] Use backported version of OpenSSL-3 KDF diff --git a/downstream-fix-debuginfo-with-y.tab.c.patch b/downstream-fix-debuginfo-with-y.tab.c.patch index 96c21ac..d40aef7 100644 --- a/downstream-fix-debuginfo-with-y.tab.c.patch +++ b/downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,4 +1,4 @@ -From db57bb9939da544af242c054d10e69a022558b4e Mon Sep 17 00:00:00 2001 +From 83899829c5e26b98f0c9d124d1e56e7b84c75c02 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] [downstream] fix debuginfo with y.tab.c diff --git a/downstream-ksu-pam-integration.patch b/downstream-ksu-pam-integration.patch index 15b9b35..7da5ccf 100644 --- a/downstream-ksu-pam-integration.patch +++ b/downstream-ksu-pam-integration.patch @@ -1,4 +1,4 @@ -From 25f948637140fb6aade80f99d9e7e096250135cd Mon Sep 17 00:00:00 2001 +From 07d19a2c4f369a7a524c919c5a453e702967b530 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] [downstream] ksu pam integration diff --git a/downstream-netlib-and-dns.patch b/downstream-netlib-and-dns.patch index 4141da9..7b17912 100644 --- a/downstream-netlib-and-dns.patch +++ b/downstream-netlib-and-dns.patch @@ -1,4 +1,4 @@ -From 26a01204b4cb424e6f9cf4190f7290b0665f6f74 Mon Sep 17 00:00:00 2001 +From ea8156d348a533cc4418903ee351121366872c17 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] [downstream] netlib and dns diff --git a/krb5.spec b/krb5.spec index 8be82d9..7f08af2 100644 --- a/krb5.spec +++ b/krb5.spec @@ -30,8 +30,7 @@ %global configure_default_ccache_name 1 %global configured_default_ccache_name KEYRING:persistent:%%{uid} -# either beta1 or % { nil } -%global prerelease beta2 +# for prereleases, % global prerelease beta1 %if %{defined prerelease} %global dashpre -%{prerelease} %global zdpd 0.%{prerelease}. @@ -43,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19 -Release: %{?zdpd}5%{?dist} +Release: %{?zdpd}1%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -209,7 +208,7 @@ contains only the libkadm5clnt and libkadm5serv shared objects. This interface is not considered stable. %prep -%autosetup -S git -n %{name}-%{version}%{?dashpre} +%autosetup -S git_am -n %{name}-%{version}%{?dashpre} ln NOTICE LICENSE # Generate an FDS-compatible LDIF file. @@ -282,8 +281,8 @@ CPPFLAGS="`echo $DEFINES $INCLUDES`" --with-prng-alg=os \ --with-lmdb \ || (cat config.log; exit 1) -# Now build it. -make +# Build fast, but get better errors if we fail +make %{?_smp_mflags} || make -j1 popd # Sanity check the KDC_RUN_DIR. @@ -625,7 +624,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog -* Thu Jan 28 2021 Robbie Harwood - 1.19-5 +* Tue Feb 02 2021 Robbie Harwood - 1.19-1 +- New upstream version (1.19) + +* Thu Jan 28 2021 Robbie Harwood - 1.19-0.beta2.5 - Support host-based GSS initiator names * Thu Jan 28 2021 Robbie Harwood - 1.19-0.beta2.4 diff --git a/sources b/sources index 5daa433..dec9e28 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.19-beta2.tar.gz) = 2864a40c44575a9482d33165bc39e76f6bb476bdcc5bc87c9864f562925638118a236a788da870567d0f83df9aacb5f79145993f38f95cec1fa5b080f2561169 -SHA512 (krb5-1.19-beta2.tar.gz.asc) = fd17198c934907811abebd47b70f6c30e68aa5800f6dde90568241db1413da34557c689af66757e47d94e08d261573f0b1ee56929947f6dcc9fcbb9dcdd2e903 +SHA512 (krb5-1.19.tar.gz) = 99d4e75ff69bffc85698177b48ca430a7a9f077c3b6c4a422ed410b264f9a762a97db5d7e0764812e2530975f1c6c12031a5dabea1154bc01a26470e3ea960a9 +SHA512 (krb5-1.19.tar.gz.asc) = b5ee91d91f4fd727cdc61502753d679e9a87361b4c6f5db377ddf9fa1ae42447b8f46fc1c271e2253e88fb96a84fda88393003195076c16eb90506c1d7df731e From 90bc2e25b3235fd9b561f9b857f78fec988c62ad Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 5 Feb 2021 15:33:20 -0500 Subject: [PATCH 220/304] Cope with autoconf rollback --- krb5.spec | 3 +++ 1 file changed, 3 insertions(+) diff --git a/krb5.spec b/krb5.spec index 7f08af2..aaf18d0 100644 --- a/krb5.spec +++ b/krb5.spec @@ -251,6 +251,9 @@ sed -i -e s,7778,`expr "$PORT" + 1`,g $cfg source %{_libdir}/tclConfig.sh pushd src +# This should be safe to remove once we have autoconf >= 2.70 +export runstatedir=/run + # Work out the CFLAGS and CPPFLAGS which we intend to use. INCLUDES=-I%{_includedir}/et CFLAGS="`echo $RPM_OPT_FLAGS $DEFINES $INCLUDES -fPIC -fno-strict-aliasing -fstack-protector-all`" From 35a4aa7b99d1eb139f4ae0e0fe87b17ada77a999 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 5 Feb 2021 20:39:13 +0000 Subject: [PATCH 221/304] No code change; just coping with reverted autoconf --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index aaf18d0..f61e44a 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19 -Release: %{?zdpd}1%{?dist} +Release: %{?zdpd}2%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -627,6 +627,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Feb 05 2021 Robbie Harwood - 1.19-2 +- No code change; just coping with reverted autoconf + * Tue Feb 02 2021 Robbie Harwood - 1.19-1 - New upstream version (1.19) From d3ac4cf9b013e2eac320177fe64d420cc8f4d74b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 15 Feb 2021 15:54:54 -0500 Subject: [PATCH 222/304] Hoist the KDC_RUN_DIR check --- krb5.spec | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/krb5.spec b/krb5.spec index f61e44a..96be371 100644 --- a/krb5.spec +++ b/krb5.spec @@ -284,18 +284,22 @@ CPPFLAGS="`echo $DEFINES $INCLUDES`" --with-prng-alg=os \ --with-lmdb \ || (cat config.log; exit 1) -# Build fast, but get better errors if we fail -make %{?_smp_mflags} || make -j1 -popd # Sanity check the KDC_RUN_DIR. -configured_dir=`grep KDC_RUN_DIR src/include/osconf.h | awk '{print $NF}'` +pushd include +make osconf.h +popd +configured_dir=`grep KDC_RUN_DIR include/osconf.h | awk '{print $NF}'` configured_dir=`eval echo $configured_dir` if test "$configured_dir" != /run/krb5kdc ; then echo Failed to configure KDC_RUN_DIR. exit 1 fi +# Build fast, but get better errors if we fail +make %{?_smp_mflags} || make -j1 +popd + # Build the docs. make -C src/doc paths.py version.py cp src/doc/paths.py doc/ From 00a0ac8abc1516c2580646b92b554939a5e01075 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 17 Feb 2021 16:12:41 -0500 Subject: [PATCH 223/304] Restore krb5_set_default_tgs_ktypes() --- Restore-krb5_set_default_tgs_ktypes.patch | 54 +++++++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 59 insertions(+), 1 deletion(-) create mode 100644 Restore-krb5_set_default_tgs_ktypes.patch diff --git a/Restore-krb5_set_default_tgs_ktypes.patch b/Restore-krb5_set_default_tgs_ktypes.patch new file mode 100644 index 0000000..742e302 --- /dev/null +++ b/Restore-krb5_set_default_tgs_ktypes.patch @@ -0,0 +1,54 @@ +From faa975dd74df535960bf8f82990f352d022a12a5 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 12 Feb 2021 15:11:25 -0500 +Subject: [PATCH] Restore krb5_set_default_tgs_ktypes() + +Samba only uses the correct name (krb5_set_default_tgs_enctypes) if it +cannot find the old one in the library, so removing the name causes a +linker error for existing builds. + +(cherry picked from commit 17ee97788611f8f8f4a6bd69968a9499f4db2215) + +ticket: 8985 +version_fixed: 1.19.1 + +(cherry picked from commit 3e36b25712d940a8e325abc407143634365b51d0) +--- + src/lib/krb5/krb/init_ctx.c | 11 +++++++++++ + src/lib/krb5/libkrb5.exports | 1 + + 2 files changed, 12 insertions(+) + +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index d2b70acad..bfa99d9eb 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -375,6 +375,17 @@ krb5_set_default_tgs_enctypes(krb5_context context, const krb5_enctype *etypes) + return 0; + } + ++/* Old name for above function. This is not a public API, but Samba (as of ++ * 2021-02-12) uses this name if it finds it in the library. */ ++krb5_error_code ++krb5_set_default_tgs_ktypes(krb5_context context, const krb5_enctype *etypes); ++ ++krb5_error_code ++krb5_set_default_tgs_ktypes(krb5_context context, const krb5_enctype *etypes) ++{ ++ return krb5_set_default_tgs_enctypes(context, etypes); ++} ++ + /* + * Add etype to, or remove etype from, the zero-terminated list *list_ptr, + * reallocating if the list size changes. Filter out weak enctypes if +diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports +index 25141dfc5..df6e2ffbe 100644 +--- a/src/lib/krb5/libkrb5.exports ++++ b/src/lib/krb5/libkrb5.exports +@@ -567,6 +567,7 @@ krb5_set_config_files + krb5_set_debugging_time + krb5_set_default_realm + krb5_set_default_tgs_enctypes ++krb5_set_default_tgs_ktypes + krb5_set_error_message + krb5_set_password + krb5_set_password_using_ccache diff --git a/krb5.spec b/krb5.spec index 96be371..a2f4234 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19 -Release: %{?zdpd}2%{?dist} +Release: %{?zdpd}3%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -73,6 +73,7 @@ Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch Patch8: Add-APIs-for-marshalling-credentials.patch Patch9: Add-hostname-canonicalization-helper-to-k5test.py.patch Patch10: Support-host-based-GSS-initiator-names.patch +Patch11: Restore-krb5_set_default_tgs_ktypes.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -631,6 +632,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Feb 17 2021 Robbie Harwood - 1.19-3 +- Restore krb5_set_default_tgs_ktypes() + * Fri Feb 05 2021 Robbie Harwood - 1.19-2 - No code change; just coping with reverted autoconf From 3faaf11da73e25d6685931f23f28e55a26fe1bd3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 18 Feb 2021 16:51:47 -0500 Subject: [PATCH 224/304] New upstream version (1.19.1) --- Add-APIs-for-marshalling-credentials.patch | 6 +-- ...canonicalization-helper-to-k5test.py.patch | 2 +- Restore-krb5_set_default_tgs_ktypes.patch | 54 ------------------- Support-host-based-GSS-initiator-names.patch | 4 +- ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 4 +- downstream-Remove-3des-support.patch | 10 ++-- downstream-SELinux-integration.patch | 12 ++--- ...ackported-version-of-OpenSSL-3-KDF-i.patch | 4 +- downstream-fix-debuginfo-with-y.tab.c.patch | 2 +- downstream-ksu-pam-integration.patch | 2 +- downstream-netlib-and-dns.patch | 2 +- krb5.spec | 8 +-- 12 files changed, 29 insertions(+), 81 deletions(-) delete mode 100644 Restore-krb5_set_default_tgs_ktypes.patch diff --git a/Add-APIs-for-marshalling-credentials.patch b/Add-APIs-for-marshalling-credentials.patch index 4c963d3..105f358 100644 --- a/Add-APIs-for-marshalling-credentials.patch +++ b/Add-APIs-for-marshalling-credentials.patch @@ -1,4 +1,4 @@ -From 057b45609fa457f2247df93b163f31723fd18077 Mon Sep 17 00:00:00 2001 +From 4505316756e42db02b6dabe0a6b075fe52852371 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Jan 2021 18:13:09 -0500 Subject: [PATCH] Add APIs for marshalling credentials @@ -187,7 +187,7 @@ index bd0284afa..96e0931a2 100644 t = &tests[version - 1]; diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports -index 72652f2ce..9de0fcdb3 100644 +index 2d9d56530..adbfa332b 100644 --- a/src/lib/krb5/libkrb5.exports +++ b/src/lib/krb5/libkrb5.exports @@ -489,6 +489,7 @@ krb5_lock_file @@ -198,7 +198,7 @@ index 72652f2ce..9de0fcdb3 100644 krb5_mcc_ops krb5_merge_authdata krb5_mk_1cred -@@ -591,6 +592,7 @@ krb5_timeofday +@@ -592,6 +593,7 @@ krb5_timeofday krb5_timestamp_to_sfstring krb5_timestamp_to_string krb5_unlock_file diff --git a/Add-hostname-canonicalization-helper-to-k5test.py.patch b/Add-hostname-canonicalization-helper-to-k5test.py.patch index 83697cd..501984f 100644 --- a/Add-hostname-canonicalization-helper-to-k5test.py.patch +++ b/Add-hostname-canonicalization-helper-to-k5test.py.patch @@ -1,4 +1,4 @@ -From 1d7b365e670f19beae319fde2abf1de0601a2a34 Mon Sep 17 00:00:00 2001 +From d898d94cef8e1a8772a91cd3a62255c33f109636 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 15 Jan 2021 14:43:34 -0500 Subject: [PATCH] Add hostname canonicalization helper to k5test.py diff --git a/Restore-krb5_set_default_tgs_ktypes.patch b/Restore-krb5_set_default_tgs_ktypes.patch deleted file mode 100644 index 742e302..0000000 --- a/Restore-krb5_set_default_tgs_ktypes.patch +++ /dev/null @@ -1,54 +0,0 @@ -From faa975dd74df535960bf8f82990f352d022a12a5 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 12 Feb 2021 15:11:25 -0500 -Subject: [PATCH] Restore krb5_set_default_tgs_ktypes() - -Samba only uses the correct name (krb5_set_default_tgs_enctypes) if it -cannot find the old one in the library, so removing the name causes a -linker error for existing builds. - -(cherry picked from commit 17ee97788611f8f8f4a6bd69968a9499f4db2215) - -ticket: 8985 -version_fixed: 1.19.1 - -(cherry picked from commit 3e36b25712d940a8e325abc407143634365b51d0) ---- - src/lib/krb5/krb/init_ctx.c | 11 +++++++++++ - src/lib/krb5/libkrb5.exports | 1 + - 2 files changed, 12 insertions(+) - -diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index d2b70acad..bfa99d9eb 100644 ---- a/src/lib/krb5/krb/init_ctx.c -+++ b/src/lib/krb5/krb/init_ctx.c -@@ -375,6 +375,17 @@ krb5_set_default_tgs_enctypes(krb5_context context, const krb5_enctype *etypes) - return 0; - } - -+/* Old name for above function. This is not a public API, but Samba (as of -+ * 2021-02-12) uses this name if it finds it in the library. */ -+krb5_error_code -+krb5_set_default_tgs_ktypes(krb5_context context, const krb5_enctype *etypes); -+ -+krb5_error_code -+krb5_set_default_tgs_ktypes(krb5_context context, const krb5_enctype *etypes) -+{ -+ return krb5_set_default_tgs_enctypes(context, etypes); -+} -+ - /* - * Add etype to, or remove etype from, the zero-terminated list *list_ptr, - * reallocating if the list size changes. Filter out weak enctypes if -diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports -index 25141dfc5..df6e2ffbe 100644 ---- a/src/lib/krb5/libkrb5.exports -+++ b/src/lib/krb5/libkrb5.exports -@@ -567,6 +567,7 @@ krb5_set_config_files - krb5_set_debugging_time - krb5_set_default_realm - krb5_set_default_tgs_enctypes -+krb5_set_default_tgs_ktypes - krb5_set_error_message - krb5_set_password - krb5_set_password_using_ccache diff --git a/Support-host-based-GSS-initiator-names.patch b/Support-host-based-GSS-initiator-names.patch index a9ca98d..ebcae16 100644 --- a/Support-host-based-GSS-initiator-names.patch +++ b/Support-host-based-GSS-initiator-names.patch @@ -1,4 +1,4 @@ -From c1df10d60512e1697ef18b343c237c6a96baf62c Mon Sep 17 00:00:00 2001 +From 8c57937f3ca793fe3f8fdd636be0bc11c24069bc Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 15 Jan 2021 13:51:34 -0500 Subject: [PATCH] Support host-based GSS initiator names @@ -418,7 +418,7 @@ index 8f5872116..760216d05 100644 /* Store the error state for code from context into errsave, but only if code diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports -index 9de0fcdb3..25141dfc5 100644 +index adbfa332b..df6e2ffbe 100644 --- a/src/lib/krb5/libkrb5.exports +++ b/src/lib/krb5/libkrb5.exports @@ -181,6 +181,7 @@ k5_size_authdata_context diff --git a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index ed61cf0..047a59e 100644 --- a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From b57c3a8fbeb0e83c9faa63ac49c5ed58971aa934 Mon Sep 17 00:00:00 2001 +From 4a62aeae7b747cd289548949f940525365fe0947 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 @@ -39,7 +39,7 @@ Last-updated: krb5-1.17 15 files changed, 151 insertions(+), 33 deletions(-) diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index cb17a8485..29ddca3a4 100644 +index 675175955..adba8238d 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst @@ -330,6 +330,12 @@ The libdefaults section may contain any of the following relations: diff --git a/downstream-Remove-3des-support.patch b/downstream-Remove-3des-support.patch index efb79d0..2bc2479 100644 --- a/downstream-Remove-3des-support.patch +++ b/downstream-Remove-3des-support.patch @@ -1,4 +1,4 @@ -From 5ff60c965583977ee4a4f98555973f9920fc79cd Mon Sep 17 00:00:00 2001 +From fef4e551d3d2dcb55e58cc182304254c36aa8949 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] [downstream] Remove 3des support @@ -5625,7 +5625,7 @@ index 2925c1c43..2f76c8b43 100644 if { ! [cmd {kadm5_destroy $server_handle}]} { perror "$test: unexpected failure in destroy" diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index be31eb31e..d2b70acad 100644 +index aa35baa3c..bfa99d9eb 100644 --- a/src/lib/krb5/krb/init_ctx.c +++ b/src/lib/krb5/krb/init_ctx.c @@ -59,7 +59,6 @@ @@ -5636,7 +5636,7 @@ index be31eb31e..d2b70acad 100644 ENCTYPE_ARCFOUR_HMAC, ENCTYPE_CAMELLIA128_CTS_CMAC, ENCTYPE_CAMELLIA256_CTS_CMAC, 0 -@@ -456,8 +455,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, +@@ -467,8 +466,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, /* Set all enctypes in the default list. */ for (i = 0; default_list[i]; i++) mod_list(default_list[i], sel, weak, &list); @@ -5818,10 +5818,10 @@ index 77d5c61fe..1f9868351 100644 * this functions takes in crypto specific representation of * trustedCertifiers and creates a list of diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index d7d1593f4..0a67c44ef 100644 +index e5940a513..e1153344e 100644 --- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -5488,44 +5488,6 @@ cleanup: +@@ -5486,44 +5486,6 @@ cleanup: return retval; } diff --git a/downstream-SELinux-integration.patch b/downstream-SELinux-integration.patch index d68bd92..0ba8b6c 100644 --- a/downstream-SELinux-integration.patch +++ b/downstream-SELinux-integration.patch @@ -1,4 +1,4 @@ -From 99e57d4cbf0eb060162b7038d6e7b202d2716784 Mon Sep 17 00:00:00 2001 +From e787771b618a344d45ac515927e914602f48946f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] [downstream] SELinux integration @@ -131,7 +131,7 @@ index ca9fcf664..5afb96e58 100644 +AC_SUBST(SELINUX_LIBS) +])dnl diff --git a/src/build-tools/krb5-config.in b/src/build-tools/krb5-config.in -index 9f96a8719..120922ac3 100755 +index dead0dddc..fef3e054f 100755 --- a/src/build-tools/krb5-config.in +++ b/src/build-tools/krb5-config.in @@ -41,6 +41,7 @@ DL_LIB='@DL_LIB@' @@ -142,7 +142,7 @@ index 9f96a8719..120922ac3 100755 LIBS='@LIBS@' GEN_LIB=@GEN_LIB@ -@@ -255,7 +256,7 @@ if test -n "$do_libs"; then +@@ -254,7 +255,7 @@ if test -n "$do_libs"; then fi # If we ever support a flag to generate output suitable for static @@ -253,7 +253,7 @@ index 045334a08..db80063eb 100644 #include diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c -index ff2f25050..e3457622a 100644 +index 634ba4a8b..cea7939f4 100644 --- a/src/kadmin/dbutil/dump.c +++ b/src/kadmin/dbutil/dump.c @@ -148,12 +148,21 @@ create_ofile(char *ofile, char **tmpname) @@ -288,7 +288,7 @@ index ff2f25050..e3457622a 100644 com_err(progname, errno, _("while creating 'ok' file, '%s'"), file_ok); goto cleanup; diff --git a/src/kdc/main.c b/src/kdc/main.c -index 27aa10da0..b5916b147 100644 +index 3be6dcb07..24d441e16 100644 --- a/src/kdc/main.c +++ b/src/kdc/main.c @@ -872,7 +872,7 @@ write_pid_file(const char *path) @@ -301,7 +301,7 @@ index 27aa10da0..b5916b147 100644 return errno; pid = (unsigned long) getpid(); diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c -index 874ba1305..9d6378cc0 100644 +index 498ca599a..c6b8efc28 100644 --- a/src/kprop/kpropd.c +++ b/src/kprop/kpropd.c @@ -487,6 +487,9 @@ doit(int fd) diff --git a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch index 9ba0821..84551d1 100644 --- a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch +++ b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch @@ -1,4 +1,4 @@ -From 387ae61e2b6384eba692e777cc1bcc3d34bfa8c6 Mon Sep 17 00:00:00 2001 +From 687bb26cb0877fa5497e90f7d325de42b456da2a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 15 Nov 2019 20:05:16 +0000 Subject: [PATCH] [downstream] Use backported version of OpenSSL-3 KDF @@ -441,7 +441,7 @@ index 6707a7308..915a173dd 100644 return k5_sp800_108_counter_hmac(hash, inkey, outrnd, in_constant, &empty); diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 0a67c44ef..dbb054378 100644 +index e1153344e..911e74fd9 100644 --- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c @@ -38,6 +38,13 @@ diff --git a/downstream-fix-debuginfo-with-y.tab.c.patch b/downstream-fix-debuginfo-with-y.tab.c.patch index d40aef7..172a093 100644 --- a/downstream-fix-debuginfo-with-y.tab.c.patch +++ b/downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,4 +1,4 @@ -From 83899829c5e26b98f0c9d124d1e56e7b84c75c02 Mon Sep 17 00:00:00 2001 +From d5ea86ef491feb38f12e6aa53b7579ac02675df6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] [downstream] fix debuginfo with y.tab.c diff --git a/downstream-ksu-pam-integration.patch b/downstream-ksu-pam-integration.patch index 7da5ccf..7490bf2 100644 --- a/downstream-ksu-pam-integration.patch +++ b/downstream-ksu-pam-integration.patch @@ -1,4 +1,4 @@ -From 07d19a2c4f369a7a524c919c5a453e702967b530 Mon Sep 17 00:00:00 2001 +From 90ba715be48c2e1b6c7ca53cb1d75f3af2c388d6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] [downstream] ksu pam integration diff --git a/downstream-netlib-and-dns.patch b/downstream-netlib-and-dns.patch index 7b17912..de4f9bf 100644 --- a/downstream-netlib-and-dns.patch +++ b/downstream-netlib-and-dns.patch @@ -1,4 +1,4 @@ -From ea8156d348a533cc4418903ee351121366872c17 Mon Sep 17 00:00:00 2001 +From ad123366e5fb2694cf6d9f4f292a001a761b78fa Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] [downstream] netlib and dns diff --git a/krb5.spec b/krb5.spec index a2f4234..a3454d6 100644 --- a/krb5.spec +++ b/krb5.spec @@ -41,8 +41,8 @@ Summary: The Kerberos network authentication system Name: krb5 -Version: 1.19 -Release: %{?zdpd}3%{?dist} +Version: 1.19.1 +Release: %{?zdpd}1%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -73,7 +73,6 @@ Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch Patch8: Add-APIs-for-marshalling-credentials.patch Patch9: Add-hostname-canonicalization-helper-to-k5test.py.patch Patch10: Support-host-based-GSS-initiator-names.patch -Patch11: Restore-krb5_set_default_tgs_ktypes.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -632,6 +631,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Feb 18 2021 Robbie Harwood - 1.19.1-1 +- New upstream version (1.19.1) + * Wed Feb 17 2021 Robbie Harwood - 1.19-3 - Restore krb5_set_default_tgs_ktypes() From ab3f34f0e757af2367b8c31b9bd42feae03d0e48 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 18 Feb 2021 16:52:28 -0500 Subject: [PATCH 225/304] ... including the sources this time --- .gitignore | 2 ++ sources | 4 ++-- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 591c859..01d1000 100644 --- a/.gitignore +++ b/.gitignore @@ -195,3 +195,5 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.19-beta2.tar.gz.asc /krb5-1.19.tar.gz /krb5-1.19.tar.gz.asc +/krb5-1.19.1.tar.gz +/krb5-1.19.1.tar.gz.asc diff --git a/sources b/sources index dec9e28..e74f7db 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.19.tar.gz) = 99d4e75ff69bffc85698177b48ca430a7a9f077c3b6c4a422ed410b264f9a762a97db5d7e0764812e2530975f1c6c12031a5dabea1154bc01a26470e3ea960a9 -SHA512 (krb5-1.19.tar.gz.asc) = b5ee91d91f4fd727cdc61502753d679e9a87361b4c6f5db377ddf9fa1ae42447b8f46fc1c271e2253e88fb96a84fda88393003195076c16eb90506c1d7df731e +SHA512 (krb5-1.19.1.tar.gz) = 36bf33802119ada4650a8f69f1daca95aaf882dc96bfa7061f0340a5decd588c31fc10108ddadf1042934e0e2c3bbd975deec565b0a7f0fc2baf8b8cc6d97491 +SHA512 (krb5-1.19.1.tar.gz.asc) = 078924730ce441630b4ac553a76ba0ebacb09b67dd057a53e3cf42185dd80bf423e875bddd306e4e91873797a9c013a7b0cae66134976abdea2c9752028e66c7 From d20ec5d3bca4e811bdef8add432140143a60be10 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 1 Mar 2021 21:27:49 +0000 Subject: [PATCH 226/304] Make test dependencies contingent on skipcheck; no code changes --- krb5.spec | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index a3454d6..25549d0 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}1%{?dist} +Release: %{?zdpd}2%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -89,6 +89,8 @@ BuildRequires: systemd-units # For autosetup BuildRequires: git +%if 0%{?skipcheck} +%else # For the test framework. BuildRequires: perl-interpreter, dejagnu, tcl-devel, python3 BuildRequires: net-tools, rpcbind @@ -98,6 +100,7 @@ BuildRequires: libverto-devel BuildRequires: openldap-devel BuildRequires: lmdb-devel BuildRequires: python3-pyrad +%endif # Need KDFs. This is the backported version BuildRequires: openssl-devel >= 1:1.1.1d-4 @@ -631,6 +634,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Mar 01 2021 Robbie Harwood - 1.19.1-2 +- Make test dependencies contingent on skipcheck; no code changes + * Thu Feb 18 2021 Robbie Harwood - 1.19.1-1 - New upstream version (1.19.1) From 1c03da79deb8ed96af1eed5beacd2db24c4212a6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 1 Mar 2021 21:46:01 +0000 Subject: [PATCH 227/304] Further test dependency fixes; no code changes --- krb5.spec | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) diff --git a/krb5.spec b/krb5.spec index 25549d0..e50cefd 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}2%{?dist} +Release: %{?zdpd}3%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -80,25 +80,26 @@ BuildRequires: autoconf, bison, make, flex, gawk, gettext, pkgconfig, sed BuildRequires: gcc, gcc-c++ BuildRequires: libcom_err-devel, libedit-devel, libss-devel BuildRequires: gzip, ncurses-devel -BuildRequires: python3-sphinx +BuildRequires: python3, python3-sphinx BuildRequires: keyutils, keyutils-libs-devel >= 1.5.8 BuildRequires: libselinux-devel BuildRequires: pam-devel BuildRequires: systemd-units +BuildRequires: tcl-devel +BuildRequires: libverto-devel +BuildRequires: openldap-devel +BuildRequires: lmdb-devel +BuildRequires: perl-interpreter # For autosetup BuildRequires: git %if 0%{?skipcheck} %else -# For the test framework. -BuildRequires: perl-interpreter, dejagnu, tcl-devel, python3 +BuildRequires: dejagnu BuildRequires: net-tools, rpcbind BuildRequires: hostname BuildRequires: iproute -BuildRequires: libverto-devel -BuildRequires: openldap-devel -BuildRequires: lmdb-devel BuildRequires: python3-pyrad %endif @@ -634,6 +635,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Mar 01 2021 Robbie Harwood - 1.19.1-3 +- Further test dependency fixes; no code changes + * Mon Mar 01 2021 Robbie Harwood - 1.19.1-2 - Make test dependencies contingent on skipcheck; no code changes From cf3e70c97c326c331315b0eeb1e2694732e700e6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= Date: Tue, 2 Mar 2021 16:13:34 +0100 Subject: [PATCH 228/304] Rebuilt for updated systemd-rpm-macros See https://pagure.io/fesco/issue/2583. --- krb5.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index e50cefd..81f9a94 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}3%{?dist} +Release: %{?zdpd}3%{?dist}.1 # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -635,6 +635,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek - 1.19.1-3.1 +- Rebuilt for updated systemd-rpm-macros + See https://pagure.io/fesco/issue/2583. + * Mon Mar 01 2021 Robbie Harwood - 1.19.1-3 - Further test dependency fixes; no code changes From d67d35a3c66a7c210b347191a78a158172ff0330 Mon Sep 17 00:00:00 2001 From: Filip Dvorak Date: Mon, 29 Mar 2021 15:21:43 +0000 Subject: [PATCH 229/304] Update tests/inplace-upgrade-sanity-test/runtest.sh --- tests/inplace-upgrade-sanity-test/runtest.sh | 115 ++++++++++++++----- 1 file changed, 89 insertions(+), 26 deletions(-) diff --git a/tests/inplace-upgrade-sanity-test/runtest.sh b/tests/inplace-upgrade-sanity-test/runtest.sh index cdd4744..7454540 100755 --- a/tests/inplace-upgrade-sanity-test/runtest.sh +++ b/tests/inplace-upgrade-sanity-test/runtest.sh @@ -36,15 +36,10 @@ PACKAGES="krb5-libs krb5-server krb5-workstation openssh" TEST_ENTROPY_SOURCE=${TEST_ENTROPY_SOURCE:-no} echo TEST_ENTROPY_SOURCE=$TEST_ENTROPY_SOURCE -hostnamectl set-hostname test.fedora.com - -host_ip=`hostname -I | awk '{print$1}'` -echo "$host_ip test.fedora.com" >> /etc/hosts - -krb5REALM1='ZMRAZ.COM' -krb5REALM2='PKIS.NET' +krb5REALM1='TEST1.REDHAT.COM' +krb5REALM2='TEST2.REDHAT.COM' krb5HostName=`hostname` -krb5DomainName='fedora.com' +krb5DomainName=`hostname -d` krb5User='alice' krb5UserPass='alice' krb5UserKrbPass='aaa' @@ -58,6 +53,8 @@ krb5confdir="/etc/krb5.conf.d" krb5kdcconf="/var/kerberos/krb5kdc/kdc.conf" krb5kadmacl="/var/kerberos/krb5kdc/kadm5.acl" + + rlJournalStart rlPhaseStartSetup for pkg in $PACKAGES; do @@ -65,6 +62,8 @@ rlJournalStart done rlRun "TmpDir=\$(mktemp -d)" rlRun "pushd $TmpDir" + echo "-----/etc/krb5.conf----"; cat /etc/krb5.conf + echo "-----/var/kerberos/krb5kdc/kdc.conf-----"; cat /var/kerberos/krb5kdc/kdc.conf rlPhaseEnd # Run this part on OLD and in "normal" mode @@ -73,9 +72,19 @@ rlJournalStart # Stop and backup rlRun "rlServiceStop kadmin krb5kdc" rlRun "rm -f /var/kerberos/krb5kdc/principal* /var/kerberos/krb5kdc/.k5*" - rlFileBackup $krb5conf /var/kerberos/krb5kdc /etc/sysconfig/{kadmin,krb5kdc} + rlFileBackup $krb5conf /var/kerberos/krb5kdc /etc/sysconfig/{kadmin,krb5kdc} /etc/hosts + rlFileBackup --clean /root/.k5login [ -e /etc/krb5.keytab ] && rlFileBackup /etc/krb5.keytab [ -e $krb5confdir ] && rlFileBackup $krb5confdir + # Make sure IPv4 is used for ssh connection + if ! grep `hostname` /etc/hosts; then + DEF_DEV=`ip route |grep default |awk '{print $5}'` + echo DEF_DEV=$DEF_DEV + DEF_IP=`ip -o -4 addr show dev $DEF_DEV |awk '{print $4}' |grep -v '/32' |sed 's|/.*||'` + echo DEF_IP=$DEF_IP + rlRun "echo '$DEF_IP `hostname`' >>/etc/hosts" + grep `hostname` /etc/hosts + fi # Basic setup of KDC and krb5.conf if rlIsRHEL 6; then rlRun "sed -i \"s/EXAMPLE.COM/$krb5REALM1/\" $krb5conf" @@ -99,28 +108,59 @@ rlJournalStart dict_file = /usr/share/dict/words admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal - } +} _EOF - rlIsRHEL 6 || rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal/\" /var/kerberos/krb5kdc/kdc.conf" + + +if rlIsRHEL '7'; then + rlLog "Modify supported_enctypes for RHEL-7." + rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal/\" /var/kerberos/krb5kdc/kdc.conf" + # Remove 3DES and DES cipher suite from kdc.conf - Fedora 31 + # Fedora 31 - krb5 will be removing support for DES, 3DES, and crc-32 entirely + # they will not be allowed in session keys or long-term keys. (BZ#1670398) + # https://fedoraproject.org/wiki/Changes/krb5_crypto_modernization +elif rlIsFedora '>=31';then + rlLog "Modify supported_enctypes for Fedora >=31. Remove *DES ciphers." + rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal/\" /var/kerberos/krb5kdc/kdc.conf" +elif rlIsRHEL '8' && [ `rpm -q --qf '%{VERSION}' krb5-server | cut -d"." -f2` -lt 18 ];then + rlLog "Modify supported_enctypes for RHEL-8." + rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal/\" /var/kerberos/krb5kdc/kdc.conf" +else + #RHEL-8 Bug 1802334 - [Rebase] krb5: rebase to 1.18: + #- Removal of *DES encryption types + #https://bugzilla.redhat.com/show_bug.cgi?id=1802334 + rlLog "Modify supported_enctypes for RHEL-8 with krb-1.18. Remove *DES ciphers." + rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal/\" /var/kerberos/krb5kdc/kdc.conf" +fi rlRun "sed -i \"s/\[realms\]/[realms]\n $krb5REALM2 = {\n kdc = $krb5HostName\n admin_server = $krb5HostName\n }/\" $krb5conf" - cat >> $krb5conf << _EOF + cat >> $krb5conf << _EOF [capaths] $krb5REALM1 = { $krb5REALM2 = . } _EOF - # Test the entropy source (not relevant for RHEL6) + # BZ#1394908: Test the entropy source (not relevant for RHEL6) if ! rlIsRHEL 6 && [[ $TEST_ENTROPY_SOURCE == 'yes' ]]; then - rlLog "The source of entropy will be tested as well" + rlLog "BZ#1394908: The source of entropy will be tested as well" + # Check number of audit rules + number_rules=$(auditctl -l | grep -v "No rules" | wc -l) + if [[ ${number_rules} -ne 0 ]];then + truncate -s0 /var/log/audit/audit.log + rlRun "auditctl -D" 0 "Delete previous audit rules" + fi START_DATE=`date +%H:%M:%S` echo START_DATE=$START_DATE sleep 1 rlRun "auditctl -w /dev/random -p rwxa -k RAND" auditctl -l - sleep 1 + sleep 5 rlRun "ausearch -i -k RAND -ts $START_DATE" fi + + echo "-----/etc/krb5.conf----"; cat /etc/krb5.conf + echo "-----/var/kerberos/krb5kdc/kdc.conf-----"; cat /var/kerberos/krb5kdc/kdc.conf + # Create the realm databases rlRun "rngd -r /dev/urandom" rlRun "kdb5_util create -s -r $krb5REALM1 -P $krb5KDCPass" @@ -145,12 +185,12 @@ _EOF rlRun "kadmin.local -r $krb5REALM2 -q \"addprinc -randkey host/$krb5HostName\"" rlRun "kadmin.local -r $krb5REALM2 -q \"addprinc -pw $krb5KDCPass krbtgt/$krb5REALM1@$krb5REALM2\"" rlRun "kadmin.local -r $krb5REALM2 -q \"addprinc -pw $krb5KDCPass krbtgt/$krb5REALM2@$krb5REALM1\"" - # Create test system user + # Create test system user [ $krb5User != "root" ] && rlRun "useradd $krb5User" rlRun "echo $krb5UserPass | passwd --stdin $krb5User" rlPhaseEnd fi - + rlPhaseStartTest "Daemon start and log file test" # Make sure there is enough entropy and start recording of the logs rlRun "rngd -r /dev/urandom" @@ -190,6 +230,10 @@ _EOF echo "/var/log/kadmind.log:" tail -n 100 /var/log/kadmind.log fi + + #add 'list' privilege for root/master + sed -i -e '$a*/master@EXAMPLE.COM *' /var/kerberos/krb5kdc/kadm5.acl + # Restart daemon auto start if rlIsRHEL 6; then rlRun "service krb5kdc restart" @@ -204,11 +248,21 @@ _EOF fi rlRun "echo $krb5UserKrbPass |kinit $krb5User && klist" rlRun "kdestroy" - rlRun "kadmin -p root/master -w rrr -q ''" + rlRun "kadmin -p root/master -w rrr -q 'getprincs'" rlAssertGrep "AS_REQ.*$krb5User@$krb5REALM1.*krbtgt/$krb5REALM1@$krb5REALM1" krb5kdc.log.record - cat krb5kdc.log.record - rlAssertGrep "Request: kadm5_init.*root/master@$krb5REALM1.*service=kadmin/`hostname`@$krb5REALM1" kadmind.log.record - cat kadmind.log.record + +#The principal related to kadmin are not created with hostname (kadmin/hostname@REALM) during creating krb5 DB +#RHEL9 constains only kadmin/admin@REALM - this change was intentional - Don't create hostbased principals in new KDBs +#https://krbdev.mit.edu/rt/Ticket/Display.html?id=8935 + if rlIsRHEL 9 || rlIsFedora '>=33';then + kadmin_princ="Request: kadm5_init.*root/master@$krb5REALM1.*service=kadmin/admin@$krb5REALM1" + else + kadmin_princ="Request: kadm5_init.*root/master@$krb5REALM1.*service=kadmin/.*`hostname`@$krb5REALM1" + fi + rlAssertGrep "${kadmin_princ}" kadmind.log.record + #rlAssertGrep "Request: kadm5_init.*root\/master@$krb5REALM1.*service=kadmin\/(admin|.*`hostname`)@$krb5REALM1" kadmind.log.record -E + echo "***krb5kdc.log.record***" && cat krb5kdc.log.record + echo "***kadmind.log.record***" && cat kadmind.log.record # Stop log recording kill $KADMIND_LOG_PID kill $KRB5KDC_LOG_PID @@ -238,6 +292,13 @@ _EOF cat klist.log rlAssertGrep "host/`hostname`@$krb5REALM1" klist.log rlRun "kdestroy" + #BZ1841488-sshd cannot write into reply cache (/var/tmp/krb5_0.rcache2) due to security context + #The problem is that this file had security context: system_u:object_r:kadmind_tmp_t:s0. + #This is a problem when the ssh via krb5-GSSAPI is used because sshd service cannot write into this file. + if rlIsRHEL '>=8.3' || rlIsFedora '>=32'; then + rlLog "BZ1841488-sshd cannot write into reply cache (/var/tmp/krb5_0.rcache2) due to security context" + rlRun "sesearch -s sshd_t -t kadmind_tmp_t -c file -p write --allow | grep ^allow" + fi rlPhaseEnd rlPhaseStartTest "Basic kadmin and kpasswd test" @@ -279,13 +340,14 @@ _EOF rlRun "kdestroy" rlPhaseEnd - # Test the entropy source (not relevant for RHEL6) + # BZ#1394908: Test the entropy source (not relevant for RHEL6) if ! rlIsRHEL 6 && [[ $TEST_ENTROPY_SOURCE == 'yes' ]]; then - rlPhaseStartTest "Enable faster getrandom-based entropy system" + rlPhaseStartTest "BZ#1394908: Enable faster getrandom-based entropy system" echo START_DATE=$START_DATE auditctl -l + sleep 5 rlRun "ausearch -i -k RAND -ts $START_DATE" - rlRun "ausearch -i -k RAND -ts $START_DATE |grep comm= |grep -v 'comm=rngd'" 1 + rlRun "ausearch -i -k RAND -ts $START_DATE |grep comm= | grep -v comm=auditctl |grep -v 'comm=rngd'" 1 rlRun "auditctl -D" rlPhaseEnd fi @@ -299,10 +361,11 @@ _EOF [ $krb5User != "root" ] && rlRun "userdel -r -f $krb5User" rlPhaseEnd fi - + rlPhaseStartCleanup + rlRun "kdestroy -A" rlRun "popd" rlRun "rm -r $TmpDir" rlPhaseEnd rlJournalPrintText -rlJournalEnd +rlJournalEnd \ No newline at end of file From 002bf4053e28673f9a0d4e1c2638d91f18ba0fbd Mon Sep 17 00:00:00 2001 From: Filip Dvorak Date: Tue, 30 Mar 2021 08:29:53 +0000 Subject: [PATCH 230/304] Update tests/inplace-upgrade-sanity-test/Makefile Added setools-console package into Makefile. --- tests/inplace-upgrade-sanity-test/Makefile | 1 + 1 file changed, 1 insertion(+) diff --git a/tests/inplace-upgrade-sanity-test/Makefile b/tests/inplace-upgrade-sanity-test/Makefile index ccd8818..cfff69d 100644 --- a/tests/inplace-upgrade-sanity-test/Makefile +++ b/tests/inplace-upgrade-sanity-test/Makefile @@ -55,6 +55,7 @@ $(METADATA): Makefile @echo "TestTime: 20m" >> $(METADATA) @echo "RunFor: krb5" >> $(METADATA) @echo "Requires: expect krb5-server krb5-workstation openssh-clients openssh-server rng-tools" >> $(METADATA) + @echo "Requires: setools-console" >> $(METADATA) @echo "Priority: Normal" >> $(METADATA) @echo "License: GPLv2" >> $(METADATA) @echo "Confidential: no" >> $(METADATA) From 7ef49093167675c758482592a713ed540d97a011 Mon Sep 17 00:00:00 2001 From: Miroslav Vadkerti Date: Mon, 29 Mar 2021 10:30:49 +0200 Subject: [PATCH 231/304] Onboard krb5 to downstream gating Because krb5 is auto-synced via DistroBaker, we need to add downstream gating configuration in Fedora. Signed-off-by: Miroslav Vadkerti --- gating.yaml | 6 ++++++ 1 file changed, 6 insertions(+) create mode 100644 gating.yaml diff --git a/gating.yaml b/gating.yaml new file mode 100644 index 0000000..5588d06 --- /dev/null +++ b/gating.yaml @@ -0,0 +1,6 @@ + --- !Policy + product_versions: + - rhel-9 + decision_context: osci_compose_gate + rules: + - !PassingTestCaseRule {test_case_name: baseos-ci.brew-build.tier1.functional} From c183c8de7d1fe4c492feae96a12bae5b426a2e6a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 3 Mar 2021 16:23:34 -0500 Subject: [PATCH 232/304] Fix the mess the mass rebuild made of Release --- krb5.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 81f9a94..e21080b 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}3%{?dist}.1 +Release: %{?zdpd}4%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz From 1c2362203efef27ede12cd70d9e746eb4fe5ef19 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 3 May 2021 17:50:44 -0400 Subject: [PATCH 233/304] Add rpminspect configuration --- rpminspect.yaml | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 rpminspect.yaml diff --git a/rpminspect.yaml b/rpminspect.yaml new file mode 100644 index 0000000..a31a5e3 --- /dev/null +++ b/rpminspect.yaml @@ -0,0 +1,17 @@ +--- +inspections: + # https://bugzilla.redhat.com/show_bug.cgi?id=1956479 + badfuncs: off + + # Not a Java package + javabytecode: off + + # I need to be able to *add* functions, and also we export internal + # functions that are not considered part of our ABI. + abidiff: off + + # These just flag when things change "too much" + changedfiles: off + filesize: off + patches: off + upstream: off From e9fb111a119250ea761f3f3a3059cca72bd71d76 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 4 May 2021 15:02:53 -0400 Subject: [PATCH 234/304] Suppress static analyzer warning in FIPS override --- Add-APIs-for-marshalling-credentials.patch | 2 +- ...hostname-canonicalization-helper-to-k5test.py.patch | 2 +- Support-host-based-GSS-initiator-names.patch | 2 +- downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 10 ++++++---- krb5.spec | 5 ++++- 5 files changed, 13 insertions(+), 8 deletions(-) diff --git a/Add-APIs-for-marshalling-credentials.patch b/Add-APIs-for-marshalling-credentials.patch index 105f358..da613e9 100644 --- a/Add-APIs-for-marshalling-credentials.patch +++ b/Add-APIs-for-marshalling-credentials.patch @@ -1,4 +1,4 @@ -From 4505316756e42db02b6dabe0a6b075fe52852371 Mon Sep 17 00:00:00 2001 +From c1fe1c8fa3df7f50c7e28d52263d0d24afb4b3a1 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Jan 2021 18:13:09 -0500 Subject: [PATCH] Add APIs for marshalling credentials diff --git a/Add-hostname-canonicalization-helper-to-k5test.py.patch b/Add-hostname-canonicalization-helper-to-k5test.py.patch index 501984f..75c3e87 100644 --- a/Add-hostname-canonicalization-helper-to-k5test.py.patch +++ b/Add-hostname-canonicalization-helper-to-k5test.py.patch @@ -1,4 +1,4 @@ -From d898d94cef8e1a8772a91cd3a62255c33f109636 Mon Sep 17 00:00:00 2001 +From 3e78bc5d48513fe38f3bc4228b12abcdc0733ee2 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 15 Jan 2021 14:43:34 -0500 Subject: [PATCH] Add hostname canonicalization helper to k5test.py diff --git a/Support-host-based-GSS-initiator-names.patch b/Support-host-based-GSS-initiator-names.patch index ebcae16..25b074f 100644 --- a/Support-host-based-GSS-initiator-names.patch +++ b/Support-host-based-GSS-initiator-names.patch @@ -1,4 +1,4 @@ -From 8c57937f3ca793fe3f8fdd636be0bc11c24069bc Mon Sep 17 00:00:00 2001 +From 3133e5e24e94bf060e23a4d97cbdf74e934d010f Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 15 Jan 2021 13:51:34 -0500 Subject: [PATCH] Support host-based GSS initiator names diff --git a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index 047a59e..d48b1cd 100644 --- a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From 4a62aeae7b747cd289548949f940525365fe0947 Mon Sep 17 00:00:00 2001 +From 852e9efad17e3ef6ea54f91044a279bb34020ecf Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 @@ -19,6 +19,8 @@ post6 restores MD4 (and therefore keygen-only RC4). post7 restores MD5 and adds radius_md5_fips_override. +post8 silences a static analyzer warning. + Last-updated: krb5-1.17 --- doc/admin/conf_files/krb5_conf.rst | 6 +++ @@ -349,7 +351,7 @@ index 03c613716..d89982a13 100644 return retval; diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h -index 0143d155a..223ffd730 100644 +index 0143d155a..57672982f 100644 --- a/src/lib/krad/internal.h +++ b/src/lib/krad/internal.h @@ -39,6 +39,8 @@ @@ -407,8 +409,8 @@ index 0143d155a..223ffd730 100644 + if (!FIPS_mode()) + return 0; + -+ profile_get_boolean(ctx->profile, "libdefaults", -+ "radius_md5_fips_override", NULL, 0, &val); ++ (void)profile_get_boolean(ctx->profile, "libdefaults", ++ "radius_md5_fips_override", NULL, 0, &val); + return !val; +} + diff --git a/krb5.spec b/krb5.spec index e21080b..c4a407e 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}4%{?dist} +Release: %{?zdpd}5%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -635,6 +635,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue May 04 2021 Robbie Harwood - 1.19.1-5 +- Suppress static analyzer warning in FIPS override + * Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek - 1.19.1-3.1 - Rebuilt for updated systemd-rpm-macros See https://pagure.io/fesco/issue/2583. From 69e05d5e39b3a10e453a6cf72c646cd6c2876ea8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 4 May 2021 15:21:05 -0400 Subject: [PATCH 235/304] Remove broken gating file Currently the gating file prevents building: rharwood@eesha:~/krb5.fedora/rawhide$ fedpkg build Could not execute build: Found a gating.yaml file in your repo with additional Greenwave policies, but it is not valid. Please fix the file or skip this check using the option --skip-remote-rules-validation. Error response from Greenwave: YAML Parser Error: mapping values are not allowed here in "", line 2, column 18: product_versions: ^ rharwood@eesha:~/krb5.fedora/rawhide$ Patches to add it back will be considered if and only if they don't break the build. --- gating.yaml | 6 ------ 1 file changed, 6 deletions(-) delete mode 100644 gating.yaml diff --git a/gating.yaml b/gating.yaml deleted file mode 100644 index 5588d06..0000000 --- a/gating.yaml +++ /dev/null @@ -1,6 +0,0 @@ - --- !Policy - product_versions: - - rhel-9 - decision_context: osci_compose_gate - rules: - - !PassingTestCaseRule {test_case_name: baseos-ci.brew-build.tier1.functional} From 904d264a4145af06e7524b1b6a6e75a8e01d3b38 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 20 May 2021 13:48:19 -0400 Subject: [PATCH 236/304] Add KCM_OP_GET_CRED_LIST and KCM_OP_RETRIEVE support --- ...P_GET_CRED_LIST-for-faster-iteration.patch | 358 ++++++++++++++++++ Use-KCM_OP_RETRIEVE-in-KCM-client.patch | 235 ++++++++++++ krb5.spec | 7 +- 3 files changed, 599 insertions(+), 1 deletion(-) create mode 100644 Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch create mode 100644 Use-KCM_OP_RETRIEVE-in-KCM-client.patch diff --git a/Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch b/Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch new file mode 100644 index 0000000..237de35 --- /dev/null +++ b/Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch @@ -0,0 +1,358 @@ +From dc92022ad26cec8085a852dec6aeba310fa7a751 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Pavel=20B=C5=99ezina?= +Date: Thu, 11 Feb 2021 15:33:10 +0100 +Subject: [PATCH] Add KCM_OP_GET_CRED_LIST for faster iteration + +For large caches, one IPC operation per credential dominates the cost +of iteration. Instead transfer the whole list of credentials to the +client in one IPC operation. + +Add optional support for the new opcode to the test KCM server to +allow testing of the main and fallback code paths. + +[ghudson@mit.edu: fixed memory leaks and potential memory errors; +adjusted code style and comments; rewrote commit message; added +kcmserver.py support and tests] + +ticket: 8990 (new) +(cherry picked from commit 81bdb47d8ded390263d8ee48f71d5c312b4f1736) +--- + src/include/kcm.h | 12 ++- + src/lib/krb5/ccache/cc_kcm.c | 144 ++++++++++++++++++++++++++++++++--- + src/tests/kcmserver.py | 28 ++++++- + src/tests/t_ccache.py | 10 ++- + 4 files changed, 175 insertions(+), 19 deletions(-) + +diff --git a/src/include/kcm.h b/src/include/kcm.h +index 5ea1447cd..e4140c3a0 100644 +--- a/src/include/kcm.h ++++ b/src/include/kcm.h +@@ -51,9 +51,9 @@ + * + * All replies begin with a 32-bit big-endian reply code. + * +- * Parameters are appended to the request or reply with no delimiters. Flags +- * and time offsets are stored as 32-bit big-endian integers. Names are +- * marshalled as zero-terminated strings. Principals and credentials are ++ * Parameters are appended to the request or reply with no delimiters. Flags, ++ * time offsets, and lengths are stored as 32-bit big-endian integers. Names ++ * are marshalled as zero-terminated strings. Principals and credentials are + * marshalled in the v4 FILE ccache format. UUIDs are 16 bytes. UUID lists + * are not delimited, so nothing can come after them. + */ +@@ -89,7 +89,11 @@ typedef enum kcm_opcode { + KCM_OP_HAVE_NTLM_CRED, + KCM_OP_DEL_NTLM_CRED, + KCM_OP_DO_NTLM_AUTH, +- KCM_OP_GET_NTLM_USER_LIST ++ KCM_OP_GET_NTLM_USER_LIST, ++ ++ /* MIT extensions */ ++ KCM_OP_MIT_EXTENSION_BASE = 13000, ++ KCM_OP_GET_CRED_LIST, /* (name) -> (count, count*{len, cred}) */ + } kcm_opcode; + + #endif /* KCM_H */ +diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c +index 9093f894d..772928e4d 100644 +--- a/src/lib/krb5/ccache/cc_kcm.c ++++ b/src/lib/krb5/ccache/cc_kcm.c +@@ -61,6 +61,17 @@ struct uuid_list { + size_t pos; + }; + ++struct cred_list { ++ krb5_creds *creds; ++ size_t count; ++ size_t pos; ++}; ++ ++struct kcm_cursor { ++ struct uuid_list *uuids; ++ struct cred_list *creds; ++}; ++ + struct kcmio { + SOCKET fd; + #ifdef __APPLE__ +@@ -489,6 +500,69 @@ free_uuid_list(struct uuid_list *uuids) + free(uuids); + } + ++static void ++free_cred_list(struct cred_list *list) ++{ ++ size_t i; ++ ++ if (list == NULL) ++ return; ++ ++ /* Creds are transferred to the caller as list->pos is incremented, so we ++ * can start freeing there. */ ++ for (i = list->pos; i < list->count; i++) ++ krb5_free_cred_contents(NULL, &list->creds[i]); ++ free(list->creds); ++ free(list); ++} ++ ++/* Fetch a cred list from req->reply. */ ++static krb5_error_code ++kcmreq_get_cred_list(struct kcmreq *req, struct cred_list **creds_out) ++{ ++ struct cred_list *list; ++ const unsigned char *data; ++ krb5_error_code ret = 0; ++ size_t count, len, i; ++ ++ *creds_out = NULL; ++ ++ /* Check a rough bound on the count to prevent very large allocations. */ ++ count = k5_input_get_uint32_be(&req->reply); ++ if (count > req->reply.len / 4) ++ return KRB5_KCM_MALFORMED_REPLY; ++ ++ list = malloc(sizeof(*list)); ++ if (list == NULL) ++ return ENOMEM; ++ ++ list->creds = NULL; ++ list->count = count; ++ list->pos = 0; ++ list->creds = k5calloc(count, sizeof(*list->creds), &ret); ++ if (list->creds == NULL) { ++ free(list); ++ return ret; ++ } ++ ++ for (i = 0; i < count; i++) { ++ len = k5_input_get_uint32_be(&req->reply); ++ data = k5_input_get_bytes(&req->reply, len); ++ if (data == NULL) ++ break; ++ ret = k5_unmarshal_cred(data, len, 4, &list->creds[i]); ++ if (ret) ++ break; ++ } ++ if (i < count) { ++ free_cred_list(list); ++ return (ret == ENOMEM) ? ENOMEM : KRB5_KCM_MALFORMED_REPLY; ++ } ++ ++ *creds_out = list; ++ return 0; ++} ++ + static void + kcmreq_free(struct kcmreq *req) + { +@@ -753,33 +827,53 @@ kcm_start_seq_get(krb5_context context, krb5_ccache cache, + { + krb5_error_code ret; + struct kcmreq req = EMPTY_KCMREQ; +- struct uuid_list *uuids; ++ struct uuid_list *uuids = NULL; ++ struct cred_list *creds = NULL; ++ struct kcm_cursor *cursor; + + *cursor_out = NULL; + + get_kdc_offset(context, cache); + +- kcmreq_init(&req, KCM_OP_GET_CRED_UUID_LIST, cache); ++ kcmreq_init(&req, KCM_OP_GET_CRED_LIST, cache); + ret = cache_call(context, cache, &req); +- if (ret) ++ if (ret == 0) { ++ /* GET_CRED_LIST is available. */ ++ ret = kcmreq_get_cred_list(&req, &creds); ++ if (ret) ++ goto cleanup; ++ } else if (ret == KRB5_FCC_INTERNAL) { ++ /* Fall back to GET_CRED_UUID_LIST. */ ++ kcmreq_free(&req); ++ kcmreq_init(&req, KCM_OP_GET_CRED_UUID_LIST, cache); ++ ret = cache_call(context, cache, &req); ++ if (ret) ++ goto cleanup; ++ ret = kcmreq_get_uuid_list(&req, &uuids); ++ if (ret) ++ goto cleanup; ++ } else { + goto cleanup; +- ret = kcmreq_get_uuid_list(&req, &uuids); +- if (ret) ++ } ++ ++ cursor = k5alloc(sizeof(*cursor), &ret); ++ if (cursor == NULL) + goto cleanup; +- *cursor_out = (krb5_cc_cursor)uuids; ++ cursor->uuids = uuids; ++ cursor->creds = creds; ++ *cursor_out = (krb5_cc_cursor)cursor; + + cleanup: + kcmreq_free(&req); + return ret; + } + +-static krb5_error_code KRB5_CALLCONV +-kcm_next_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor, +- krb5_creds *cred_out) ++static krb5_error_code ++next_cred_by_uuid(krb5_context context, krb5_ccache cache, ++ struct uuid_list *uuids, krb5_creds *cred_out) + { + krb5_error_code ret; + struct kcmreq req; +- struct uuid_list *uuids = (struct uuid_list *)*cursor; + + memset(cred_out, 0, sizeof(*cred_out)); + +@@ -797,11 +891,39 @@ kcm_next_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor, + return map_invalid(ret); + } + ++static krb5_error_code KRB5_CALLCONV ++kcm_next_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor, ++ krb5_creds *cred_out) ++{ ++ struct kcm_cursor *c = (struct kcm_cursor *)*cursor; ++ struct cred_list *list; ++ ++ if (c->uuids != NULL) ++ return next_cred_by_uuid(context, cache, c->uuids, cred_out); ++ ++ list = c->creds; ++ if (list->pos >= list->count) ++ return KRB5_CC_END; ++ ++ /* Transfer memory ownership of one cred to the caller. */ ++ *cred_out = list->creds[list->pos]; ++ memset(&list->creds[list->pos], 0, sizeof(*list->creds)); ++ list->pos++; ++ ++ return 0; ++} ++ + static krb5_error_code KRB5_CALLCONV + kcm_end_seq_get(krb5_context context, krb5_ccache cache, + krb5_cc_cursor *cursor) + { +- free_uuid_list((struct uuid_list *)*cursor); ++ struct kcm_cursor *c = *cursor; ++ ++ if (c == NULL) ++ return 0; ++ free_uuid_list(c->uuids); ++ free_cred_list(c->creds); ++ free(c); + *cursor = NULL; + return 0; + } +diff --git a/src/tests/kcmserver.py b/src/tests/kcmserver.py +index 57432e5a7..8c5e66ff1 100644 +--- a/src/tests/kcmserver.py ++++ b/src/tests/kcmserver.py +@@ -23,6 +23,7 @@ + # traceback.print_exception(etype, value, tb, file=f) + # sys.excepthook = ehook + ++import optparse + import select + import socket + import struct +@@ -49,12 +50,14 @@ class KCMOpcodes(object): + SET_DEFAULT_CACHE = 21 + GET_KDC_OFFSET = 22 + SET_KDC_OFFSET = 23 ++ GET_CRED_LIST = 13001 + + + class KRB5Errors(object): + KRB5_CC_END = -1765328242 + KRB5_CC_NOSUPP = -1765328137 + KRB5_FCC_NOFILE = -1765328189 ++ KRB5_FCC_INTERNAL = -1765328188 + + + def make_uuid(): +@@ -183,6 +186,14 @@ def op_set_kdc_offset(argbytes): + return 0, b'' + + ++def op_get_cred_list(argbytes): ++ name, rest = unmarshal_name(argbytes) ++ cache = get_cache(name) ++ creds = [cache.creds[u] for u in cache.cred_uuids] ++ return 0, (struct.pack('>L', len(creds)) + ++ b''.join(struct.pack('>L', len(c)) + c for c in creds)) ++ ++ + ophandlers = { + KCMOpcodes.GEN_NEW : op_gen_new, + KCMOpcodes.INITIALIZE : op_initialize, +@@ -197,7 +208,8 @@ ophandlers = { + KCMOpcodes.GET_DEFAULT_CACHE : op_get_default_cache, + KCMOpcodes.SET_DEFAULT_CACHE : op_set_default_cache, + KCMOpcodes.GET_KDC_OFFSET : op_get_kdc_offset, +- KCMOpcodes.SET_KDC_OFFSET : op_set_kdc_offset ++ KCMOpcodes.SET_KDC_OFFSET : op_set_kdc_offset, ++ KCMOpcodes.GET_CRED_LIST : op_get_cred_list + } + + # Read and respond to a request from the socket s. +@@ -215,7 +227,11 @@ def service_request(s): + + majver, minver, op = struct.unpack('>BBH', req[:4]) + argbytes = req[4:] +- code, payload = ophandlers[op](argbytes) ++ ++ if op in ophandlers: ++ code, payload = ophandlers[op](argbytes) ++ else: ++ code, payload = KRB5Errors.KRB5_FCC_INTERNAL, b'' + + # The KCM response is the code (4 bytes) and the response payload. + # The Heimdal IPC response is the length of the KCM response (4 +@@ -226,9 +242,15 @@ def service_request(s): + s.sendall(hipc_response) + return True + ++parser = optparse.OptionParser() ++parser.add_option('-c', '--credlist', action='store_true', dest='credlist', ++ default=False, help='Support KCM_OP_GET_CRED_LIST') ++(options, args) = parser.parse_args() ++if not options.credlist: ++ del ophandlers[KCMOpcodes.GET_CRED_LIST] + + server = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM) +-server.bind(sys.argv[1]) ++server.bind(args[0]) + server.listen(5) + select_input = [server,] + sys.stderr.write('starting...\n') +diff --git a/src/tests/t_ccache.py b/src/tests/t_ccache.py +index 66804afa5..90040fb7b 100755 +--- a/src/tests/t_ccache.py ++++ b/src/tests/t_ccache.py +@@ -125,10 +125,18 @@ def collection_test(realm, ccname): + + + collection_test(realm, 'DIR:' + os.path.join(realm.testdir, 'cc')) ++ ++# Test KCM without and with GET_CRED_LIST support. + kcmserver_path = os.path.join(srctop, 'tests', 'kcmserver.py') +-realm.start_server([sys.executable, kcmserver_path, kcm_socket_path], ++kcmd = realm.start_server([sys.executable, kcmserver_path, kcm_socket_path], ++ 'starting...') ++collection_test(realm, 'KCM:') ++stop_daemon(kcmd) ++os.remove(kcm_socket_path) ++realm.start_server([sys.executable, kcmserver_path, '-c', kcm_socket_path], + 'starting...') + collection_test(realm, 'KCM:') ++ + if test_keyring: + def cleanup_keyring(anchor, name): + out = realm.run(['keyctl', 'list', anchor]) diff --git a/Use-KCM_OP_RETRIEVE-in-KCM-client.patch b/Use-KCM_OP_RETRIEVE-in-KCM-client.patch new file mode 100644 index 0000000..22c6593 --- /dev/null +++ b/Use-KCM_OP_RETRIEVE-in-KCM-client.patch @@ -0,0 +1,235 @@ +From 04a810c642245947d5f32a498ed7b1a6f9a11006 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 26 Mar 2021 23:38:54 -0400 +Subject: [PATCH] Use KCM_OP_RETRIEVE in KCM client + +In kcm_retrieve(), try KCM_OP_RETRIEVE. Fall back to iteration if the +server doesn't implement it, or if we can an answer incompatible with +KRB5_TC_SUPPORTED_KTYPES. + +In kcmserver.py, implement partial decoding for creds and cred tags so +that we can do a basic principal name match. + +ticket: 8997 (new) +(cherry picked from commit 795ebba8c039be172ab93cd41105c73ffdba0fdb) +--- + src/include/kcm.h | 2 +- + src/lib/krb5/ccache/cc_kcm.c | 52 +++++++++++++++++++++++++++++++++--- + src/tests/kcmserver.py | 44 +++++++++++++++++++++++++++--- + src/tests/t_ccache.py | 11 +++++--- + 4 files changed, 99 insertions(+), 10 deletions(-) + +diff --git a/src/include/kcm.h b/src/include/kcm.h +index e4140c3a0..5a3e55ce6 100644 +--- a/src/include/kcm.h ++++ b/src/include/kcm.h +@@ -68,7 +68,7 @@ typedef enum kcm_opcode { + KCM_OP_INITIALIZE, /* (name, princ) -> () */ + KCM_OP_DESTROY, /* (name) -> () */ + KCM_OP_STORE, /* (name, cred) -> () */ +- KCM_OP_RETRIEVE, ++ KCM_OP_RETRIEVE, /* (name, flags, credtag) -> (cred) */ + KCM_OP_GET_PRINCIPAL, /* (name) -> (princ) */ + KCM_OP_GET_CRED_UUID_LIST, /* (name) -> (uuid, ...) */ + KCM_OP_GET_CRED_BY_UUID, /* (name, uuid) -> (cred) */ +diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c +index 772928e4d..80f8bf631 100644 +--- a/src/lib/krb5/ccache/cc_kcm.c ++++ b/src/lib/krb5/ccache/cc_kcm.c +@@ -792,9 +792,55 @@ static krb5_error_code KRB5_CALLCONV + kcm_retrieve(krb5_context context, krb5_ccache cache, krb5_flags flags, + krb5_creds *mcred, krb5_creds *cred_out) + { +- /* There is a KCM opcode for retrieving creds, but Heimdal's client doesn't +- * use it. It causes the KCM daemon to actually make a TGS request. */ +- return k5_cc_retrieve_cred_default(context, cache, flags, mcred, cred_out); ++ krb5_error_code ret; ++ struct kcmreq req = EMPTY_KCMREQ; ++ krb5_creds cred; ++ krb5_enctype *enctypes = NULL; ++ ++ memset(&cred, 0, sizeof(cred)); ++ ++ /* Include KCM_GC_CACHED in flags to prevent Heimdal's sssd from making a ++ * TGS request itself. */ ++ kcmreq_init(&req, KCM_OP_RETRIEVE, cache); ++ k5_buf_add_uint32_be(&req.reqbuf, map_tcflags(flags) | KCM_GC_CACHED); ++ k5_marshal_mcred(&req.reqbuf, mcred); ++ ret = cache_call(context, cache, &req); ++ ++ /* Fall back to iteration if the server does not support retrieval. */ ++ if (ret == KRB5_FCC_INTERNAL || ret == KRB5_CC_IO) { ++ ret = k5_cc_retrieve_cred_default(context, cache, flags, mcred, ++ cred_out); ++ goto cleanup; ++ } ++ if (ret) ++ goto cleanup; ++ ++ ret = k5_unmarshal_cred(req.reply.ptr, req.reply.len, 4, &cred); ++ if (ret) ++ goto cleanup; ++ ++ /* In rare cases we might retrieve a credential with a session key this ++ * context can't support, in which case we must retry using iteration. */ ++ if (flags & KRB5_TC_SUPPORTED_KTYPES) { ++ ret = krb5_get_tgs_ktypes(context, cred.server, &enctypes); ++ if (ret) ++ goto cleanup; ++ if (!k5_etypes_contains(enctypes, cred.keyblock.enctype)) { ++ ret = k5_cc_retrieve_cred_default(context, cache, flags, mcred, ++ cred_out); ++ goto cleanup; ++ } ++ } ++ ++ *cred_out = cred; ++ memset(&cred, 0, sizeof(cred)); ++ ++cleanup: ++ kcmreq_free(&req); ++ krb5_free_cred_contents(context, &cred); ++ free(enctypes); ++ /* Heimdal's KCM returns KRB5_CC_END if no cred is found. */ ++ return (ret == KRB5_CC_END) ? KRB5_CC_NOTFOUND : map_invalid(ret); + } + + static krb5_error_code KRB5_CALLCONV +diff --git a/src/tests/kcmserver.py b/src/tests/kcmserver.py +index 8c5e66ff1..25e6f2bbe 100644 +--- a/src/tests/kcmserver.py ++++ b/src/tests/kcmserver.py +@@ -40,6 +40,7 @@ class KCMOpcodes(object): + INITIALIZE = 4 + DESTROY = 5 + STORE = 6 ++ RETRIEVE = 7 + GET_PRINCIPAL = 8 + GET_CRED_UUID_LIST = 9 + GET_CRED_BY_UUID = 10 +@@ -54,6 +55,7 @@ class KCMOpcodes(object): + + + class KRB5Errors(object): ++ KRB5_CC_NOTFOUND = -1765328243 + KRB5_CC_END = -1765328242 + KRB5_CC_NOSUPP = -1765328137 + KRB5_FCC_NOFILE = -1765328189 +@@ -86,11 +88,29 @@ def get_cache(name): + return cache + + ++def unpack_data(argbytes): ++ dlen, = struct.unpack('>L', argbytes[:4]) ++ return argbytes[4:dlen+4], argbytes[dlen+4:] ++ ++ + def unmarshal_name(argbytes): + offset = argbytes.find(b'\0') + return argbytes[0:offset], argbytes[offset+1:] + + ++def unmarshal_princ(argbytes): ++ # Ignore the type at argbytes[0:4]. ++ ncomps, = struct.unpack('>L', argbytes[4:8]) ++ realm, rest = unpack_data(argbytes[8:]) ++ comps = [] ++ for i in range(ncomps): ++ comp, rest = unpack_data(rest) ++ comps.append(comp) ++ # Asssume no quoting is needed. ++ princ = b'/'.join(comps) + b'@' + realm ++ return princ, rest ++ ++ + def op_gen_new(argbytes): + # Does not actually check for uniqueness. + global next_unique +@@ -126,6 +146,22 @@ def op_store(argbytes): + return 0, b'' + + ++def op_retrieve(argbytes): ++ name, rest = unmarshal_name(argbytes) ++ # Ignore the flags at rest[0:4] and the header at rest[4:8]. ++ # Assume there are client and server creds in the tag and match ++ # only against them. ++ cprinc, rest = unmarshal_princ(rest[8:]) ++ sprinc, rest = unmarshal_princ(rest) ++ cache = get_cache(name) ++ for cred in (cache.creds[u] for u in cache.cred_uuids): ++ cred_cprinc, rest = unmarshal_princ(cred) ++ cred_sprinc, rest = unmarshal_princ(rest) ++ if cred_cprinc == cprinc and cred_sprinc == sprinc: ++ return 0, cred ++ return KRB5Errors.KRB5_CC_NOTFOUND, b'' ++ ++ + def op_get_principal(argbytes): + name, rest = unmarshal_name(argbytes) + cache = get_cache(name) +@@ -199,6 +235,7 @@ ophandlers = { + KCMOpcodes.INITIALIZE : op_initialize, + KCMOpcodes.DESTROY : op_destroy, + KCMOpcodes.STORE : op_store, ++ KCMOpcodes.RETRIEVE : op_retrieve, + KCMOpcodes.GET_PRINCIPAL : op_get_principal, + KCMOpcodes.GET_CRED_UUID_LIST : op_get_cred_uuid_list, + KCMOpcodes.GET_CRED_BY_UUID : op_get_cred_by_uuid, +@@ -243,10 +280,11 @@ def service_request(s): + return True + + parser = optparse.OptionParser() +-parser.add_option('-c', '--credlist', action='store_true', dest='credlist', +- default=False, help='Support KCM_OP_GET_CRED_LIST') ++parser.add_option('-f', '--fallback', action='store_true', dest='fallback', ++ default=False, help='Do not support RETRIEVE/GET_CRED_LIST') + (options, args) = parser.parse_args() +-if not options.credlist: ++if options.fallback: ++ del ophandlers[KCMOpcodes.RETRIEVE] + del ophandlers[KCMOpcodes.GET_CRED_LIST] + + server = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM) +diff --git a/src/tests/t_ccache.py b/src/tests/t_ccache.py +index 90040fb7b..6ea9fb969 100755 +--- a/src/tests/t_ccache.py ++++ b/src/tests/t_ccache.py +@@ -25,7 +25,7 @@ from k5test import * + kcm_socket_path = os.path.join(os.getcwd(), 'testdir', 'kcm') + conf = {'libdefaults': {'kcm_socket': kcm_socket_path, + 'kcm_mach_service': '-'}} +-realm = K5Realm(create_host=False, krb5_conf=conf) ++realm = K5Realm(krb5_conf=conf) + + keyctl = which('keyctl') + out = realm.run([klist, '-c', 'KEYRING:process:abcd'], expected_code=1) +@@ -71,6 +71,11 @@ def collection_test(realm, ccname): + realm.kinit('alice', password('alice')) + realm.run([klist], expected_msg='Default principal: alice@') + realm.run([klist, '-A', '-s']) ++ realm.run([kvno, realm.host_princ], expected_msg = 'kvno = 1') ++ realm.run([kvno, realm.host_princ], expected_msg = 'kvno = 1') ++ out = realm.run([klist]) ++ if out.count(realm.host_princ) != 1: ++ fail('Wrong number of service tickets in cache') + realm.run([kdestroy]) + output = realm.run([klist], expected_code=1) + if 'No credentials cache' not in output and 'not found' not in output: +@@ -126,14 +131,14 @@ def collection_test(realm, ccname): + + collection_test(realm, 'DIR:' + os.path.join(realm.testdir, 'cc')) + +-# Test KCM without and with GET_CRED_LIST support. ++# Test KCM with and without RETRIEVE and GET_CRED_LIST support. + kcmserver_path = os.path.join(srctop, 'tests', 'kcmserver.py') + kcmd = realm.start_server([sys.executable, kcmserver_path, kcm_socket_path], + 'starting...') + collection_test(realm, 'KCM:') + stop_daemon(kcmd) + os.remove(kcm_socket_path) +-realm.start_server([sys.executable, kcmserver_path, '-c', kcm_socket_path], ++realm.start_server([sys.executable, kcmserver_path, '-f', kcm_socket_path], + 'starting...') + collection_test(realm, 'KCM:') + diff --git a/krb5.spec b/krb5.spec index c4a407e..ac83dce 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}5%{?dist} +Release: %{?zdpd}6%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -73,6 +73,8 @@ Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch Patch8: Add-APIs-for-marshalling-credentials.patch Patch9: Add-hostname-canonicalization-helper-to-k5test.py.patch Patch10: Support-host-based-GSS-initiator-names.patch +Patch11: Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch +Patch12: Use-KCM_OP_RETRIEVE-in-KCM-client.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -635,6 +637,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu May 20 2021 Robbie Harwood - 1.19.1-6 +- Add KCM_OP_GET_CRED_LIST and KCM_OP_RETRIEVE support + * Tue May 04 2021 Robbie Harwood - 1.19.1-5 - Suppress static analyzer warning in FIPS override From c4150c67d14ea9272ae0bca9eca2bcbf5b349dc4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 20 May 2021 13:59:15 -0400 Subject: [PATCH 237/304] Fix context for previous backport --- ...CM-flag-transmission-for-remove_cred.patch | 103 ++++++++++++++++++ Use-KCM_OP_RETRIEVE-in-KCM-client.patch | 10 +- krb5.spec | 8 +- 3 files changed, 114 insertions(+), 7 deletions(-) create mode 100644 Fix-KCM-flag-transmission-for-remove_cred.patch diff --git a/Fix-KCM-flag-transmission-for-remove_cred.patch b/Fix-KCM-flag-transmission-for-remove_cred.patch new file mode 100644 index 0000000..0542bfa --- /dev/null +++ b/Fix-KCM-flag-transmission-for-remove_cred.patch @@ -0,0 +1,103 @@ +From 1f160bee7ee2c6242fa2625b9f3e8fc211cec6c4 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 29 Mar 2021 14:32:56 -0400 +Subject: [PATCH] Fix KCM flag transmission for remove_cred + +MIT krb5 uses low bits for KRB5_TC flags, while Heimdal uses high bits +so that the same flag word can also hold KRB5_GC flags. Add a mapping +function and send the Heimdal flag values when performing a +remove_cred operation. + +ticket: 8995 +(cherry picked from commit 11a82cf424f9c905bb73680c64524f087090d4ef) +--- + src/include/kcm.h | 19 +++++++++++++++++++ + src/lib/krb5/ccache/cc_kcm.c | 36 +++++++++++++++++++++++++++++++++++- + 2 files changed, 54 insertions(+), 1 deletion(-) + +diff --git a/src/include/kcm.h b/src/include/kcm.h +index e4140c3a0..9b66f1cbd 100644 +--- a/src/include/kcm.h ++++ b/src/include/kcm.h +@@ -56,8 +56,27 @@ + * are marshalled as zero-terminated strings. Principals and credentials are + * marshalled in the v4 FILE ccache format. UUIDs are 16 bytes. UUID lists + * are not delimited, so nothing can come after them. ++ * ++ * Flag words must use Heimdal flag values, which are not the same as MIT krb5 ++ * values for KRB5_GC and KRB5_TC constants. The same flag word may contain ++ * both kinds of flags in Heimdal, but not in MIT krb5. Defines for the ++ * applicable Heimdal flag values are given below using KCM_GC and KCM_TC ++ * prefixes. + */ + ++#define KCM_GC_CACHED (1U << 0) ++ ++#define KCM_TC_DONT_MATCH_REALM (1U << 31) ++#define KCM_TC_MATCH_KEYTYPE (1U << 30) ++#define KCM_TC_MATCH_SRV_NAMEONLY (1U << 29) ++#define KCM_TC_MATCH_FLAGS_EXACT (1U << 28) ++#define KCM_TC_MATCH_FLAGS (1U << 27) ++#define KCM_TC_MATCH_TIMES_EXACT (1U << 26) ++#define KCM_TC_MATCH_TIMES (1U << 25) ++#define KCM_TC_MATCH_AUTHDATA (1U << 24) ++#define KCM_TC_MATCH_2ND_TKT (1U << 23) ++#define KCM_TC_MATCH_IS_SKEY (1U << 22) ++ + /* Opcodes without comments are currently unused in the MIT client + * implementation. */ + typedef enum kcm_opcode { +diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c +index 772928e4d..1f81a2190 100644 +--- a/src/lib/krb5/ccache/cc_kcm.c ++++ b/src/lib/krb5/ccache/cc_kcm.c +@@ -110,6 +110,40 @@ map_invalid(krb5_error_code code) + KRB5_KCM_MALFORMED_REPLY : code; + } + ++/* ++ * Map an MIT krb5 KRB5_TC flag word to the equivalent Heimdal flag word. Note ++ * that there is no MIT krb5 equivalent for Heimdal's KRB5_TC_DONT_MATCH_REALM ++ * (which is like KRB5_TC_MATCH_SRV_NAMEONLY but also applies to the client ++ * principal) and no Heimdal equivalent for MIT krb5's KRB5_TC_SUPPORTED_KTYPES ++ * (which matches against enctypes from the krb5_context rather than the ++ * matching cred). ++ */ ++static inline krb5_flags ++map_tcflags(krb5_flags mitflags) ++{ ++ krb5_flags heimflags = 0; ++ ++ if (mitflags & KRB5_TC_MATCH_TIMES) ++ heimflags |= KCM_TC_MATCH_TIMES; ++ if (mitflags & KRB5_TC_MATCH_IS_SKEY) ++ heimflags |= KCM_TC_MATCH_IS_SKEY; ++ if (mitflags & KRB5_TC_MATCH_FLAGS) ++ heimflags |= KCM_TC_MATCH_FLAGS; ++ if (mitflags & KRB5_TC_MATCH_TIMES_EXACT) ++ heimflags |= KCM_TC_MATCH_TIMES_EXACT; ++ if (mitflags & KRB5_TC_MATCH_FLAGS_EXACT) ++ heimflags |= KCM_TC_MATCH_FLAGS_EXACT; ++ if (mitflags & KRB5_TC_MATCH_AUTHDATA) ++ heimflags |= KCM_TC_MATCH_AUTHDATA; ++ if (mitflags & KRB5_TC_MATCH_SRV_NAMEONLY) ++ heimflags |= KCM_TC_MATCH_SRV_NAMEONLY; ++ if (mitflags & KRB5_TC_MATCH_2ND_TKT) ++ heimflags |= KCM_TC_MATCH_2ND_TKT; ++ if (mitflags & KRB5_TC_MATCH_KTYPE) ++ heimflags |= KCM_TC_MATCH_KEYTYPE; ++ return heimflags; ++} ++ + /* Begin a request for the given opcode. If cache is non-null, supply the + * cache name as a request parameter. */ + static void +@@ -936,7 +970,7 @@ kcm_remove_cred(krb5_context context, krb5_ccache cache, krb5_flags flags, + struct kcmreq req; + + kcmreq_init(&req, KCM_OP_REMOVE_CRED, cache); +- k5_buf_add_uint32_be(&req.reqbuf, flags); ++ k5_buf_add_uint32_be(&req.reqbuf, map_tcflags(flags)); + k5_marshal_mcred(&req.reqbuf, mcred); + ret = cache_call(context, cache, &req); + kcmreq_free(&req); diff --git a/Use-KCM_OP_RETRIEVE-in-KCM-client.patch b/Use-KCM_OP_RETRIEVE-in-KCM-client.patch index 22c6593..c0abcf3 100644 --- a/Use-KCM_OP_RETRIEVE-in-KCM-client.patch +++ b/Use-KCM_OP_RETRIEVE-in-KCM-client.patch @@ -1,4 +1,4 @@ -From 04a810c642245947d5f32a498ed7b1a6f9a11006 Mon Sep 17 00:00:00 2001 +From 8f073717c0373bcd4d13e338273449f00325b00c Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 26 Mar 2021 23:38:54 -0400 Subject: [PATCH] Use KCM_OP_RETRIEVE in KCM client @@ -20,10 +20,10 @@ ticket: 8997 (new) 4 files changed, 99 insertions(+), 10 deletions(-) diff --git a/src/include/kcm.h b/src/include/kcm.h -index e4140c3a0..5a3e55ce6 100644 +index 9b66f1cbd..85c20d345 100644 --- a/src/include/kcm.h +++ b/src/include/kcm.h -@@ -68,7 +68,7 @@ typedef enum kcm_opcode { +@@ -87,7 +87,7 @@ typedef enum kcm_opcode { KCM_OP_INITIALIZE, /* (name, princ) -> () */ KCM_OP_DESTROY, /* (name) -> () */ KCM_OP_STORE, /* (name, cred) -> () */ @@ -33,10 +33,10 @@ index e4140c3a0..5a3e55ce6 100644 KCM_OP_GET_CRED_UUID_LIST, /* (name) -> (uuid, ...) */ KCM_OP_GET_CRED_BY_UUID, /* (name, uuid) -> (cred) */ diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c -index 772928e4d..80f8bf631 100644 +index 1f81a2190..ef77ac216 100644 --- a/src/lib/krb5/ccache/cc_kcm.c +++ b/src/lib/krb5/ccache/cc_kcm.c -@@ -792,9 +792,55 @@ static krb5_error_code KRB5_CALLCONV +@@ -826,9 +826,55 @@ static krb5_error_code KRB5_CALLCONV kcm_retrieve(krb5_context context, krb5_ccache cache, krb5_flags flags, krb5_creds *mcred, krb5_creds *cred_out) { diff --git a/krb5.spec b/krb5.spec index ac83dce..d571916 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}6%{?dist} +Release: %{?zdpd}7%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -74,7 +74,8 @@ Patch8: Add-APIs-for-marshalling-credentials.patch Patch9: Add-hostname-canonicalization-helper-to-k5test.py.patch Patch10: Support-host-based-GSS-initiator-names.patch Patch11: Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch -Patch12: Use-KCM_OP_RETRIEVE-in-KCM-client.patch +Patch12: Fix-KCM-flag-transmission-for-remove_cred.patch +Patch13: Use-KCM_OP_RETRIEVE-in-KCM-client.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -637,6 +638,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu May 20 2021 Robbie Harwood - 1.19.1-7 +- Fix context for previous backport + * Thu May 20 2021 Robbie Harwood - 1.19.1-6 - Add KCM_OP_GET_CRED_LIST and KCM_OP_RETRIEVE support From 72e80d67ef87e136c3d5dd7b1e0323f968769096 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 20 May 2021 17:26:12 -0400 Subject: [PATCH 238/304] Add all the sssd-kcm workarounds --- ...P_GET_CRED_LIST-for-faster-iteration.patch | 2 +- ...CM-flag-transmission-for-remove_cred.patch | 2 +- Fix-KCM-retrieval-support-for-sssd.patch | 62 +++++++++++++++++++ ...teration-fallback-work-with-sssd-kcm.patch | 26 ++++++++ Use-KCM_OP_RETRIEVE-in-KCM-client.patch | 4 +- krb5.spec | 9 ++- 6 files changed, 99 insertions(+), 6 deletions(-) create mode 100644 Fix-KCM-retrieval-support-for-sssd.patch create mode 100644 Make-KCM-iteration-fallback-work-with-sssd-kcm.patch diff --git a/Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch b/Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch index 237de35..060b039 100644 --- a/Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch +++ b/Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch @@ -1,4 +1,4 @@ -From dc92022ad26cec8085a852dec6aeba310fa7a751 Mon Sep 17 00:00:00 2001 +From a0ee8b02e56c65e5dcd569caed0e151cef004ef4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Pavel=20B=C5=99ezina?= Date: Thu, 11 Feb 2021 15:33:10 +0100 Subject: [PATCH] Add KCM_OP_GET_CRED_LIST for faster iteration diff --git a/Fix-KCM-flag-transmission-for-remove_cred.patch b/Fix-KCM-flag-transmission-for-remove_cred.patch index 0542bfa..951be10 100644 --- a/Fix-KCM-flag-transmission-for-remove_cred.patch +++ b/Fix-KCM-flag-transmission-for-remove_cred.patch @@ -1,4 +1,4 @@ -From 1f160bee7ee2c6242fa2625b9f3e8fc211cec6c4 Mon Sep 17 00:00:00 2001 +From 04f0de4420508161ce439f262f2761ff51a07ab0 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 29 Mar 2021 14:32:56 -0400 Subject: [PATCH] Fix KCM flag transmission for remove_cred diff --git a/Fix-KCM-retrieval-support-for-sssd.patch b/Fix-KCM-retrieval-support-for-sssd.patch new file mode 100644 index 0000000..5fb7c2b --- /dev/null +++ b/Fix-KCM-retrieval-support-for-sssd.patch @@ -0,0 +1,62 @@ +From a5b2cff51808cd86fe8195e7ac074ecd25c3344d Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 11 May 2021 14:04:07 -0400 +Subject: [PATCH] Fix KCM retrieval support for sssd + +Commit 795ebba8c039be172ab93cd41105c73ffdba0fdb added a retrieval +handler using KCM_OP_RETRIEVE, falling back on the same error codes as +the previous KCM_OP_GET_CRED_LIST support. But sssd (as of 2.4) +returns KRB5_CC_NOSUPP instead of KRB5_CC_IO if it recognizes an +opcode but does not implement it. Add a helper function to recognize +all known unsupported-opcode error codes, and use it in kcm_retrieve() +and kcm_start_seq_get(). + +ticket: 8997 +(cherry picked from commit da103e36e13f3c846bcddbe38dd518a21e5260a0) +--- + src/lib/krb5/ccache/cc_kcm.c | 18 ++++++++++++++++-- + 1 file changed, 16 insertions(+), 2 deletions(-) + +diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c +index 23fcf13ea..18505cd3d 100644 +--- a/src/lib/krb5/ccache/cc_kcm.c ++++ b/src/lib/krb5/ccache/cc_kcm.c +@@ -144,6 +144,20 @@ map_tcflags(krb5_flags mitflags) + return heimflags; + } + ++/* ++ * Return true if code could indicate an unsupported operation. Heimdal's KCM ++ * returns KRB5_FCC_INTERNAL. sssd's KCM daemon (as of sssd 2.4) returns ++ * KRB5_CC_NO_SUPP if it recognizes the operation but does not implement it, ++ * and KRB5_CC_IO if it doesn't recognize the operation (which is unfortunate ++ * since it could also indicate a communication failure). ++ */ ++static krb5_boolean ++unsupported_op_error(krb5_error_code code) ++{ ++ return code == KRB5_FCC_INTERNAL || code == KRB5_CC_IO || ++ code == KRB5_CC_NOSUPP; ++} ++ + /* Begin a request for the given opcode. If cache is non-null, supply the + * cache name as a request parameter. */ + static void +@@ -841,7 +855,7 @@ kcm_retrieve(krb5_context context, krb5_ccache cache, krb5_flags flags, + ret = cache_call(context, cache, &req); + + /* Fall back to iteration if the server does not support retrieval. */ +- if (ret == KRB5_FCC_INTERNAL || ret == KRB5_CC_IO) { ++ if (unsupported_op_error(ret)) { + ret = k5_cc_retrieve_cred_default(context, cache, flags, mcred, + cred_out); + goto cleanup; +@@ -922,7 +936,7 @@ kcm_start_seq_get(krb5_context context, krb5_ccache cache, + ret = kcmreq_get_cred_list(&req, &creds); + if (ret) + goto cleanup; +- } else if (ret == KRB5_FCC_INTERNAL || ret == KRB5_CC_IO) { ++ } else if (unsupported_op_error(ret)) { + /* Fall back to GET_CRED_UUID_LIST. */ + kcmreq_free(&req); + kcmreq_init(&req, KCM_OP_GET_CRED_UUID_LIST, cache); diff --git a/Make-KCM-iteration-fallback-work-with-sssd-kcm.patch b/Make-KCM-iteration-fallback-work-with-sssd-kcm.patch new file mode 100644 index 0000000..5fa3106 --- /dev/null +++ b/Make-KCM-iteration-fallback-work-with-sssd-kcm.patch @@ -0,0 +1,26 @@ +From 2dbca7e14c945d6394e0e05f285a068dcd541295 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Pavel=20B=C5=99ezina?= +Date: Tue, 30 Mar 2021 14:35:28 +0200 +Subject: [PATCH] Make KCM iteration fallback work with sssd-kcm + +sssd-kcm returns KRB5_CC_IO if the operation code is not known. + +ticket: 8990 +(cherry picked from commit 06afae820a44c1dc96ad88a0b16c3e50bc938b2a) +--- + src/lib/krb5/ccache/cc_kcm.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c +index 1f81a2190..46705f1da 100644 +--- a/src/lib/krb5/ccache/cc_kcm.c ++++ b/src/lib/krb5/ccache/cc_kcm.c +@@ -876,7 +876,7 @@ kcm_start_seq_get(krb5_context context, krb5_ccache cache, + ret = kcmreq_get_cred_list(&req, &creds); + if (ret) + goto cleanup; +- } else if (ret == KRB5_FCC_INTERNAL) { ++ } else if (ret == KRB5_FCC_INTERNAL || ret == KRB5_CC_IO) { + /* Fall back to GET_CRED_UUID_LIST. */ + kcmreq_free(&req); + kcmreq_init(&req, KCM_OP_GET_CRED_UUID_LIST, cache); diff --git a/Use-KCM_OP_RETRIEVE-in-KCM-client.patch b/Use-KCM_OP_RETRIEVE-in-KCM-client.patch index c0abcf3..401b363 100644 --- a/Use-KCM_OP_RETRIEVE-in-KCM-client.patch +++ b/Use-KCM_OP_RETRIEVE-in-KCM-client.patch @@ -1,4 +1,4 @@ -From 8f073717c0373bcd4d13e338273449f00325b00c Mon Sep 17 00:00:00 2001 +From c56d4b87de0f30a38dc61d374ad225d02d581eb3 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 26 Mar 2021 23:38:54 -0400 Subject: [PATCH] Use KCM_OP_RETRIEVE in KCM client @@ -33,7 +33,7 @@ index 9b66f1cbd..85c20d345 100644 KCM_OP_GET_CRED_UUID_LIST, /* (name) -> (uuid, ...) */ KCM_OP_GET_CRED_BY_UUID, /* (name, uuid) -> (cred) */ diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c -index 1f81a2190..ef77ac216 100644 +index 46705f1da..23fcf13ea 100644 --- a/src/lib/krb5/ccache/cc_kcm.c +++ b/src/lib/krb5/ccache/cc_kcm.c @@ -826,9 +826,55 @@ static krb5_error_code KRB5_CALLCONV diff --git a/krb5.spec b/krb5.spec index d571916..cbe0580 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}7%{?dist} +Release: %{?zdpd}8%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -75,7 +75,9 @@ Patch9: Add-hostname-canonicalization-helper-to-k5test.py.patch Patch10: Support-host-based-GSS-initiator-names.patch Patch11: Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch Patch12: Fix-KCM-flag-transmission-for-remove_cred.patch -Patch13: Use-KCM_OP_RETRIEVE-in-KCM-client.patch +Patch13: Make-KCM-iteration-fallback-work-with-sssd-kcm.patch +Patch14: Use-KCM_OP_RETRIEVE-in-KCM-client.patch +Patch15: Fix-KCM-retrieval-support-for-sssd.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -638,6 +640,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu May 20 2021 Robbie Harwood - 1.19.1-8 +- Add all the sssd-kcm workarounds + * Thu May 20 2021 Robbie Harwood - 1.19.1-7 - Fix context for previous backport From 65a1e5607c56c0d73208c1afd138c2e46695ba9b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 2 Jun 2021 12:09:09 -0400 Subject: [PATCH 239/304] Fix doc build for Sphinx 4.0 --- Fix-doc-build-for-Sphinx-4.0.patch | 152 +++++++++++++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 157 insertions(+), 1 deletion(-) create mode 100644 Fix-doc-build-for-Sphinx-4.0.patch diff --git a/Fix-doc-build-for-Sphinx-4.0.patch b/Fix-doc-build-for-Sphinx-4.0.patch new file mode 100644 index 0000000..ae3972c --- /dev/null +++ b/Fix-doc-build-for-Sphinx-4.0.patch @@ -0,0 +1,152 @@ +From 0bf023bdbb8335f48a6a4dcf8bd5dac9c2cd7fb6 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 26 May 2021 15:08:28 -0400 +Subject: [PATCH] Fix doc build for Sphinx 4.0 + +Use app.add_css_file() to register krb5.css if possible (it was added +in Sphinx 1.8), since the old name app.add_stylesheet() was removed in +Sphinx 4.0. + +Use the highlight directive instead of the highlightlang directive, +which was removed in Sphinx 4.0. + +Remove two duplicate table of contents entries to fix warnings. + +In the Github Actions configuration, add a second doc build using the +newest version of Sphinx. + +ticket: 9006 +tags: pullup +target_version: 1.19-next + +(cherry picked from commit 3fa40a32e22cb9de91fa1d18deddcba446515855) +--- + .github/workflows/doc.yml | 16 +++++++++++++++- + doc/appdev/refs/macros/index.rst | 1 - + doc/appdev/refs/types/index.rst | 1 - + doc/appdev/refs/types/krb5_int32.rst | 2 +- + doc/appdev/refs/types/krb5_ui_4.rst | 2 +- + doc/conf.py | 9 ++++++++- + doc/tools/define_document.tmpl | 2 +- + doc/tools/type_document.tmpl | 2 +- + 8 files changed, 27 insertions(+), 8 deletions(-) + +diff --git a/.github/workflows/doc.yml b/.github/workflows/doc.yml +index 292df4cfe..75f467cde 100644 +--- a/.github/workflows/doc.yml ++++ b/.github/workflows/doc.yml +@@ -5,7 +5,7 @@ on: + pull_request: {paths: [doc/**, src/doc/*, src/include/krb5/krb5.hin, .github/workflows/doc.yml]} + + jobs: +- doc: ++ doc-older-sphinx: + runs-on: ubuntu-18.04 + steps: + - name: Checkout repository +@@ -19,6 +19,20 @@ jobs: + run: | + cd src/doc + make -f Makefile.in SPHINX_ARGS=-W htmlsrc ++ doc-newest-sphinx: ++ runs-on: ubuntu-18.04 ++ steps: ++ - name: Checkout repository ++ uses: actions/checkout@v1 ++ - name: Linux setup ++ run: | ++ sudo apt-get update -qq ++ sudo apt-get install -y doxygen python3-lxml python3-pip ++ pip3 install Cheetah3 sphinx ++ - name: Build documentation ++ run: | ++ cd src/doc ++ make -f Makefile.in SPHINX_ARGS=-W htmlsrc + - name: Upload HTML + uses: actions/upload-artifact@v2 + with: +diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst +index 4d51e795c..0cb2e81bd 100644 +--- a/doc/appdev/refs/macros/index.rst ++++ b/doc/appdev/refs/macros/index.rst +@@ -54,7 +54,6 @@ Public + ENCTYPE_DES3_CBC_RAW.rst + ENCTYPE_DES3_CBC_SHA.rst + ENCTYPE_DES3_CBC_SHA1.rst +- ENCTYPE_DES3_CBC_SHA1.rst + ENCTYPE_DES_CBC_CRC.rst + ENCTYPE_DES_CBC_MD4.rst + ENCTYPE_DES_CBC_MD5.rst +diff --git a/doc/appdev/refs/types/index.rst b/doc/appdev/refs/types/index.rst +index dc414cfde..d8d2a8f3c 100644 +--- a/doc/appdev/refs/types/index.rst ++++ b/doc/appdev/refs/types/index.rst +@@ -62,7 +62,6 @@ Public + krb5_preauthtype.rst + krb5_principal.rst + krb5_principal_data.rst +- krb5_const_principal.rst + krb5_prompt.rst + krb5_prompt_type.rst + krb5_prompter_fct.rst +diff --git a/doc/appdev/refs/types/krb5_int32.rst b/doc/appdev/refs/types/krb5_int32.rst +index 2bc914b3c..28baafa38 100644 +--- a/doc/appdev/refs/types/krb5_int32.rst ++++ b/doc/appdev/refs/types/krb5_int32.rst +@@ -1,4 +1,4 @@ +-.. highlightlang:: c ++.. highlight:: c + + .. _krb5-int32-struct: + +diff --git a/doc/appdev/refs/types/krb5_ui_4.rst b/doc/appdev/refs/types/krb5_ui_4.rst +index de79bafe1..73eb38cf4 100644 +--- a/doc/appdev/refs/types/krb5_ui_4.rst ++++ b/doc/appdev/refs/types/krb5_ui_4.rst +@@ -1,4 +1,4 @@ +-.. highlightlang:: c ++.. highlight:: c + + .. _krb5-ui4-struct: + +diff --git a/doc/conf.py b/doc/conf.py +index 4fb6aae14..a876fd633 100644 +--- a/doc/conf.py ++++ b/doc/conf.py +@@ -98,8 +98,15 @@ pygments_style = 'sphinx' + + # -- Options for HTML output --------------------------------------------------- + ++# When we can rely on Sphinx 1.8 (released Sep 2018) we can just set: ++# html_css_files = ['kerb.css'] ++# But in the meantime, we add this file using either a way that works ++# after 1.8 or a way that works before 4.0. + def setup(app): +- app.add_stylesheet('kerb.css') ++ if callable(getattr(app, 'add_css_file', None)): ++ app.add_css_file('kerb.css') ++ else: ++ app.add_stylesheet('kerb.css') + + # The theme to use for HTML and HTML Help pages. See the documentation for + # a list of builtin themes. +diff --git a/doc/tools/define_document.tmpl b/doc/tools/define_document.tmpl +index ca56d866c..8e74dc302 100644 +--- a/doc/tools/define_document.tmpl ++++ b/doc/tools/define_document.tmpl +@@ -1,4 +1,4 @@ +-.. highlightlang:: c ++.. highlight:: c + + .. $composite.macro_reference($composite.name): + +diff --git a/doc/tools/type_document.tmpl b/doc/tools/type_document.tmpl +index 5987fa762..11aafb818 100644 +--- a/doc/tools/type_document.tmpl ++++ b/doc/tools/type_document.tmpl +@@ -1,4 +1,4 @@ +-.. highlightlang:: c ++.. highlight:: c + + .. $composite.struct_reference($composite.name): + diff --git a/krb5.spec b/krb5.spec index cbe0580..b59f39c 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}8%{?dist} +Release: %{?zdpd}9%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -78,6 +78,7 @@ Patch12: Fix-KCM-flag-transmission-for-remove_cred.patch Patch13: Make-KCM-iteration-fallback-work-with-sssd-kcm.patch Patch14: Use-KCM_OP_RETRIEVE-in-KCM-client.patch Patch15: Fix-KCM-retrieval-support-for-sssd.patch +Patch16: Fix-doc-build-for-Sphinx-4.0.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -640,6 +641,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Jun 02 2021 Robbie Harwood - 1.19.1-9 +- Fix doc build for Sphinx 4.0 + * Thu May 20 2021 Robbie Harwood - 1.19.1-8 - Add all the sssd-kcm workarounds From 4df0096f2013dc5bc9fad459ddc18e83ac4da4c2 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 9 Jun 2021 10:55:13 -0400 Subject: [PATCH 240/304] Fix three canonicalization cases for fallback --- ...ith-keytab-to-defer-canonicalization.patch | 60 + ...in-k-with-fallback-or-referral-realm.patch | 64 + ...incipal-realm-canonicalization-cases.patch | 96 + ...dejagnu-kadmin-tests-to-Python-tests.patch | 1750 +++++++++++++++++ krb5.spec | 9 +- 5 files changed, 1978 insertions(+), 1 deletion(-) create mode 100644 Allow-kinit-with-keytab-to-defer-canonicalization.patch create mode 100644 Fix-kadmin-k-with-fallback-or-referral-realm.patch create mode 100644 Fix-some-principal-realm-canonicalization-cases.patch create mode 100644 Move-some-dejagnu-kadmin-tests-to-Python-tests.patch diff --git a/Allow-kinit-with-keytab-to-defer-canonicalization.patch b/Allow-kinit-with-keytab-to-defer-canonicalization.patch new file mode 100644 index 0000000..9315f66 --- /dev/null +++ b/Allow-kinit-with-keytab-to-defer-canonicalization.patch @@ -0,0 +1,60 @@ +From 090c7319652466339e3e6482bdd1b5a294638dff Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 3 Jun 2021 16:03:07 -0400 +Subject: [PATCH] Allow kinit with keytab to defer canonicalization + +[ghudson@mit.edu: added tests] + +ticket: 9012 (new) +(cherry picked from commit 5e6a6efc5df689d9fb8730d0227167ffbb6ece0e) +--- + src/clients/kinit/kinit.c | 11 ----------- + src/tests/t_keytab.py | 13 +++++++++++++ + 2 files changed, 13 insertions(+), 11 deletions(-) + +diff --git a/src/clients/kinit/kinit.c b/src/clients/kinit/kinit.c +index d1f5d74c3..5a6d7237c 100644 +--- a/src/clients/kinit/kinit.c ++++ b/src/clients/kinit/kinit.c +@@ -510,17 +510,6 @@ k5_begin(struct k_opts *opts, struct k5_data *k5) + _("when creating default server principal name")); + goto cleanup; + } +- if (k5->me->realm.data[0] == 0) { +- ret = krb5_unparse_name(k5->ctx, k5->me, &k5->name); +- if (ret == 0) { +- com_err(progname, KRB5_ERR_HOST_REALM_UNKNOWN, +- _("(principal %s)"), k5->name); +- } else { +- com_err(progname, KRB5_ERR_HOST_REALM_UNKNOWN, +- _("for local services")); +- } +- goto cleanup; +- } + } else if (k5->out_cc != NULL) { + /* If the output ccache is initialized, use its principal. */ + if (krb5_cc_get_principal(k5->ctx, k5->out_cc, &princ) == 0) +diff --git a/src/tests/t_keytab.py b/src/tests/t_keytab.py +index 850375c92..a9adebb26 100755 +--- a/src/tests/t_keytab.py ++++ b/src/tests/t_keytab.py +@@ -41,6 +41,19 @@ realm.kinit(realm.user_princ, flags=['-i'], + expected_msg='keytab specified, forcing -k') + realm.klist(realm.user_princ) + ++# Test default principal for -k. This operation requires ++# canonicalization against the keytab in krb5_get_init_creds_keytab() ++# as the krb5_sname_to_principal() result won't have a realm. Try ++# with and without without fallback processing since the code paths ++# are different. ++mark('default principal for -k') ++realm.run([kinit, '-k']) ++realm.klist(realm.host_princ) ++no_canon_conf = {'libdefaults': {'dns_canonicalize_hostname': 'false'}} ++no_canon = realm.special_env('no_canon', False, krb5_conf=no_canon_conf) ++realm.run([kinit, '-k'], env=no_canon) ++realm.klist(realm.host_princ) ++ + # Test extracting keys with multiple key versions present. + mark('multi-kvno extract') + os.remove(realm.keytab) diff --git a/Fix-kadmin-k-with-fallback-or-referral-realm.patch b/Fix-kadmin-k-with-fallback-or-referral-realm.patch new file mode 100644 index 0000000..3e03da1 --- /dev/null +++ b/Fix-kadmin-k-with-fallback-or-referral-realm.patch @@ -0,0 +1,64 @@ +From cd8ff035f5b4720a8fc457355726f7bd0eab5eaa Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 7 Jun 2021 15:00:41 -0400 +Subject: [PATCH] Fix kadmin -k with fallback or referral realm + +kadmin -k produces a client principal name with +krb5_sname_to_principal(), but it gets converted to a string and back +due to the signature of kadm5_init_with_skey(), which loses track of +the name type, so no canonicalization is performed. + +In libkadm5clnt initialization, recognize the important subset of this +case--an empty realm indicates either fallback processing or the +referral realm--and restore the host-based name type so that the +client principal can be canonicalized against the keytab. + +ticket: 9013 (new) +(cherry picked from commit dcb79089276624d7ddf44e08d35bd6d7d7e557d2) +--- + src/lib/kadm5/clnt/client_init.c | 7 +++++++ + src/tests/t_kadmin.py | 12 ++++++++++++ + 2 files changed, 19 insertions(+) + +diff --git a/src/lib/kadm5/clnt/client_init.c b/src/lib/kadm5/clnt/client_init.c +index aa1223bb3..0aaca701f 100644 +--- a/src/lib/kadm5/clnt/client_init.c ++++ b/src/lib/kadm5/clnt/client_init.c +@@ -221,9 +221,16 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, + return KADM5_MISSING_KRB5_CONF_PARAMS; + } + ++ /* ++ * Parse the client name. If it has an empty realm, it is almost certainly ++ * a host-based principal using DNS fallback processing or the referral ++ * realm, so give it the appropriate name type for canonicalization. ++ */ + code = krb5_parse_name(handle->context, client_name, &client); + if (code) + goto error; ++ if (init_type == INIT_SKEY && client->realm.length == 0) ++ client->type = KRB5_NT_SRV_HST; + + /* + * Get credentials. Also does some fallbacks in case kadmin/fqdn +diff --git a/src/tests/t_kadmin.py b/src/tests/t_kadmin.py +index fe6a3cc2e..98453d92e 100644 +--- a/src/tests/t_kadmin.py ++++ b/src/tests/t_kadmin.py +@@ -51,4 +51,16 @@ for i in range(200): + realm.run_kadmin(['addprinc', '-randkey', 'foo%d' % i]) + realm.run_kadmin(['listprincs'], expected_msg='foo199') + ++# Test kadmin -k with the default principal, with and without ++# fallback. This operation requires canonicalization against the ++# keytab in krb5_get_init_creds_keytab() as the ++# krb5_sname_to_principal() result won't have a realm. Try with and ++# without without fallback processing since the code paths are ++# different. ++mark('kadmin -k') ++realm.run([kadmin, '-k', 'getprinc', realm.host_princ]) ++no_canon_conf = {'libdefaults': {'dns_canonicalize_hostname': 'false'}} ++no_canon = realm.special_env('no_canon', False, krb5_conf=no_canon_conf) ++realm.run([kadmin, '-k', 'getprinc', realm.host_princ], env=no_canon) ++ + success('kadmin and kpasswd tests') diff --git a/Fix-some-principal-realm-canonicalization-cases.patch b/Fix-some-principal-realm-canonicalization-cases.patch new file mode 100644 index 0000000..2c6c915 --- /dev/null +++ b/Fix-some-principal-realm-canonicalization-cases.patch @@ -0,0 +1,96 @@ +From 5ae9bc98f23aeaa2ce17debe5a9b0cf1130e54ed Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 7 Jun 2021 13:27:29 -0400 +Subject: [PATCH] Fix some principal realm canonicalization cases + +The no_hostrealm and subst_defrealm flags in struct canonprinc were +only applied when dns_canonicalize_hostname=fallback; in the other +cases, the initial krb5_sname_to_principal() result is treated as +canonical. For no_hostrealm this limitation doesn't currently matter, +because all uses pass a principal with no realm as input. However, +subst_defrealm is used to convert the referral realm to the default +realm in krb5_get_init_creds_keytab(), krb5_cc_cache_match(), and +gss_acquire_cred() when it needs to check the desired name against a +specified ccache. + +In k5_canonprinc(), if the input principal is a +krb5_sname_to_principal() result and fallback isn't in effect, apply +subst_defrealm. Document in os-proto.h that no_hostrealm doesn't +remove an existing realm and that krb5_sname_to_principal() may +already have looked one up. + +ticket: 9011 (new) +(cherry picked from commit c077d0c6430c4ac163443aacc03d14d206a4cbb8) +--- + src/lib/krb5/os/os-proto.h | 13 +++++++++---- + src/lib/krb5/os/sn2princ.c | 24 +++++++++++++++++++++--- + 2 files changed, 30 insertions(+), 7 deletions(-) + +diff --git a/src/lib/krb5/os/os-proto.h b/src/lib/krb5/os/os-proto.h +index 7d5e7978f..a985f2aec 100644 +--- a/src/lib/krb5/os/os-proto.h ++++ b/src/lib/krb5/os/os-proto.h +@@ -85,10 +85,15 @@ struct sendto_callback_info { + + /* + * Initialize with all zeros except for princ. Set no_hostrealm to disable +- * host-to-realm lookup, which ordinarily happens after canonicalizing the host +- * part. Set subst_defrealm to substitute the default realm for the referral +- * realm after realm lookup (this has no effect if no_hostrealm is set). Free +- * with free_canonprinc() when done. ++ * host-to-realm lookup, which ordinarily happens during fallback processing ++ * after canonicalizing the host part. Set subst_defrealm to substitute the ++ * default realm for the referral realm after realm lookup. Do not set both ++ * flags. Free with free_canonprinc() when done. ++ * ++ * no_hostrealm only applies if fallback processing is in use ++ * (dns_canonicalize_hostname = fallback). It will not remove the realm if ++ * krb5_sname_to_principal() already canonicalized the hostname and looked up a ++ * realm. subst_defrealm applies whether or not fallback processing is in use. + */ + struct canonprinc { + krb5_const_principal princ; +diff --git a/src/lib/krb5/os/sn2princ.c b/src/lib/krb5/os/sn2princ.c +index c99b7da17..93c155932 100644 +--- a/src/lib/krb5/os/sn2princ.c ++++ b/src/lib/krb5/os/sn2princ.c +@@ -271,18 +271,36 @@ krb5_error_code + k5_canonprinc(krb5_context context, struct canonprinc *iter, + krb5_const_principal *princ_out) + { ++ krb5_error_code ret; + int step = ++iter->step; + + *princ_out = NULL; + +- /* If we're not doing fallback, the input principal is canonical. */ +- if (context->dns_canonicalize_hostname != CANONHOST_FALLBACK || +- iter->princ->type != KRB5_NT_SRV_HST || iter->princ->length != 2 || ++ /* If the hostname isn't from krb5_sname_to_principal(), the input ++ * principal is canonical. */ ++ if (iter->princ->type != KRB5_NT_SRV_HST || iter->princ->length != 2 || + iter->princ->data[1].length == 0) { + *princ_out = (step == 1) ? iter->princ : NULL; + return 0; + } + ++ /* If we're not doing fallback, the hostname is canonical, but we may need ++ * to substitute the default realm. */ ++ if (context->dns_canonicalize_hostname != CANONHOST_FALLBACK) { ++ if (step > 1) ++ return 0; ++ iter->copy = *iter->princ; ++ if (iter->subst_defrealm && iter->copy.realm.length == 0) { ++ ret = krb5_get_default_realm(context, &iter->realm); ++ if (ret) ++ return ret; ++ iter->copy = *iter->princ; ++ iter->copy.realm = string2data(iter->realm); ++ } ++ *princ_out = &iter->copy; ++ return 0; ++ } ++ + /* Canonicalize without DNS at step 1, with DNS at step 2. */ + if (step > 2) + return 0; diff --git a/Move-some-dejagnu-kadmin-tests-to-Python-tests.patch b/Move-some-dejagnu-kadmin-tests-to-Python-tests.patch new file mode 100644 index 0000000..9334c19 --- /dev/null +++ b/Move-some-dejagnu-kadmin-tests-to-Python-tests.patch @@ -0,0 +1,1750 @@ +From 9b3d8b9c395bf1a889ea6d6439dc3543c680480d Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 22 Apr 2021 15:51:36 -0400 +Subject: [PATCH] Move some dejagnu kadmin tests to Python tests + +Remove the dejagnu scripts kadmin.exp, pwchange.exp, and pwhist.exp. + +Add a new Python test script t_kadmin.py for the miscellaneous kadmin +tests from kadmin.exp. + +In t_changepw.py, use modprinc +needchange for one of the kinit +password change tests to gain the same coverage as pwchange.exp had, +and add the "password changes are usable by kinit" tests from +kadmin.exp. + +In t_policy.py, add the ticket 929 regression tests from kadmin.exp +and the ticket 2841 regression tests from pwhist.exp. + +(cherry picked from commit 8027531caf6911bb07bf13de087da0e6bef5a348) +--- + src/tests/Makefile.in | 1 + + src/tests/dejagnu/krb-standalone/kadmin.exp | 1133 ----------------- + src/tests/dejagnu/krb-standalone/pwchange.exp | 145 --- + src/tests/dejagnu/krb-standalone/pwhist.exp | 217 ---- + src/tests/t_changepw.py | 34 +- + src/tests/t_kadmin.py | 54 + + src/tests/t_policy.py | 62 + + 7 files changed, 143 insertions(+), 1503 deletions(-) + delete mode 100644 src/tests/dejagnu/krb-standalone/kadmin.exp + delete mode 100644 src/tests/dejagnu/krb-standalone/pwchange.exp + delete mode 100644 src/tests/dejagnu/krb-standalone/pwhist.exp + create mode 100644 src/tests/t_kadmin.py + +diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in +index 6b7749129..ab416cc5f 100644 +--- a/src/tests/Makefile.in ++++ b/src/tests/Makefile.in +@@ -147,6 +147,7 @@ check-pytests: unlockiter s4u2self + $(RUNPYTEST) $(srcdir)/t_referral.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_skew.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_keytab.py $(PYTESTFLAGS) ++ $(RUNPYTEST) $(srcdir)/t_kadmin.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_kadmin_acl.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_kadmin_parsing.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_kdb.py $(PYTESTFLAGS) +diff --git a/src/tests/dejagnu/krb-standalone/kadmin.exp b/src/tests/dejagnu/krb-standalone/kadmin.exp +deleted file mode 100644 +index fa50a61fb..000000000 +--- a/src/tests/dejagnu/krb-standalone/kadmin.exp ++++ /dev/null +@@ -1,1133 +0,0 @@ +-# Kerberos kadmin test. +-# This is a DejaGnu test script. +-# This script tests Kerberos kadmin5 using kadmin.local as verification. +- +-#++ +-# kadmin_add - Test add new v5 principal function of kadmin. +-# +-# Adds principal $pname with password $password. Returns 1 on success. +-#-- +-proc kadmin_add { pname password } { +- global REALMNAME +- global KADMIN +- global KADMIN_LOCAL +- global KEY +- global spawn_id +- global tmppwd +- +- set good 0 +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "ank $pname" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin add $pname lost KDC" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin add $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin add $pname" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*:" { +- send "adminpass$KEY\r" +- } +- expect "Enter password for principal \"$pname@$REALMNAME\":" { send "$password\r" } +- expect "Re-enter password for principal \"$pname@$REALMNAME\":" { send "$password\r" } +- expect "Principal \"$pname@$REALMNAME\" created." { set good 1 } +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin add)" +- catch "close -i $spawn_id" +- if { $good == 1 } { +- # +- # use kadmin.local to verify that a principal was created and that its +- # salt types are 0 (normal). +- # +- envstack_push +- setup_kerberos_env kdc +- spawn $KADMIN_LOCAL -r $REALMNAME +- envstack_pop +- expect_after { +- -i $spawn_id +- timeout { +- fail "kadmin add $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin add $pname" +- catch "expect_after" +- return 0 +- } +- } +- set good 0 +- expect "kadmin.local: " { send "getprinc $pname\r" } +- expect "Principal: $pname@$REALMNAME" { set good 1 } +- expect "Expiration date:" { verbose "got expiration date" } +- expect "Last password change:" { verbose "got last pwchange" } +- expect "Password expiration date:" { verbose "got pwexpire date" } +- expect "Maximum ticket life:" { verbose "got max life" } +- expect "Maximum renewable life:" { verbose "got max rlife" } +- expect "Last modified:" { verbose "got last modified" } +- expect "Last successful authentication:" { verbose "last succ auth" } +- expect "Last failed authentication:" { verbose "last pw failed" } +- expect "Failed password attempts:" { verbose "num failed attempts" } +- expect "Number of keys:" { verbose "num keys"} +- expect { +- "Key: " { verbose "Key listed" +- exp_continue +- } +- "Attributes:" { verbose "attributes" } +- } +- expect "kadmin.local: " { send "q\r" } +- +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin.local show)" +- catch "close -i $spawn_id" +- if { $good == 1 } { +- pass "kadmin add $pname" +- return 1 +- } +- else { +- fail "kadmin add $pname" +- return 0 +- } +- } +- else { +- fail "kadmin add $pname" +- return 0 +- } +-} +- +-#++ +-# kadmin_add_rnd - Test add new v5 principal with random key function. +-# +-# Adds principal $pname with random key. Returns 1 on success. +-#-- +-proc kadmin_add_rnd { pname { flags "" } } { +- global REALMNAME +- global KADMIN +- global KADMIN_LOCAL +- global KEY +- global spawn_id +- global tmppwd +- +- set good 0 +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "ank -randkey $flags $pname" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin add rnd $pname lost KDC" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin add_rnd $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin add_rnd $pname" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*: *" { +- send "adminpass$KEY\r" +- } +- expect "Principal \"$pname@$REALMNAME\" created." { set good 1 } +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin add_rnd)" +- catch "close -i $spawn_id" +- if { $good == 1 } { +- # +- # use kadmin.local to verify that a principal was created and that its +- # salt types are 0 (normal). +- # +- envstack_push +- setup_kerberos_env kdc +- spawn $KADMIN_LOCAL -r $REALMNAME +- envstack_pop +- expect_after { +- -i $spawn_id +- timeout { +- fail "kadmin add_rnd $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin add_rnd $pname" +- catch "expect_after" +- return 0 +- } +- } +- set good 0 +- expect "kadmin.local:" { send "getprinc $pname\r" } +- expect "Principal: $pname@$REALMNAME" { set good 1 } +- expect "kadmin.local:" { send "q\r" } +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin.local show)" +- catch "close -i $spawn_id" +- if { $good == 1 } { +- pass "kadmin add_rnd $pname" +- return 1 +- } +- else { +- fail "kadmin add_rnd $pname" +- return 0 +- } +- } +- else { +- fail "kadmin add_rnd $pname" +- return 0 +- } +-} +- +-#++ +-# kadmin_show - Test show principal function of kadmin. +-# +-# Retrieves entry for $pname. Returns 1 on success. +-#-- +-proc kadmin_show { pname } { +- global REALMNAME +- global KADMIN +- global KEY +- global spawn_id +- +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "get_principal $pname" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin show $pname lost KDC" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin show $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin show $pname" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*: *" +- send "adminpass$KEY\r" +- expect -re "\r.*Principal: $pname@$REALMNAME.*Key: .*Attributes:.*Policy: .*\r" +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin show)" +- catch "close -i $spawn_id" +- pass "kadmin show $pname" +- return 1 +-} +- +-#++ +-# kadmin_cpw - Test change password function of kadmin +-# +-# Change password of $pname to $password. Returns 1 on success. +-#-- +-proc kadmin_cpw { pname password } { +- global REALMNAME +- global KADMIN +- global KEY +- global spawn_id +- +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "cpw $pname" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin cpw $pname lost KDC" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin cpw $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin cpw $pname" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*: *" { +- send "adminpass$KEY\r" +- } +- +- expect "Enter password for principal \"$pname@$REALMNAME\":" { send "$password\r" } +- expect "Re-enter password for principal \"$pname@$REALMNAME\":" { send "$password\r" } +- # When in doubt, jam one of these in there. +- expect "\r" +- expect "Password for \"$pname@$REALMNAME\" changed." +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin cpw)" +- catch "close -i $spawn_id" +- pass "kadmin cpw $pname" +- return 1 +-} +- +-#++ +-# kadmin_cpw_rnd - Test change random key function of kadmin. +-# +-# Changes principal $pname's key to a new random key. Returns 1 on success. +-#-- +-proc kadmin_cpw_rnd { pname } { +- global REALMNAME +- global KADMIN +- global KEY +- global spawn_id +- +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "cpw -randkey $pname" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin cpw_rnd $pname lost KDC" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin cpw_rnd $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin cpw_rnd $pname" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*: *" { +- send "adminpass$KEY\r" +- } +- # When in doubt, jam one of these in there. +- expect "\r" +- expect "Key for \"$pname@$REALMNAME\" randomized." +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin cpw_rnd)" +- catch "close -i $spawn_id" +- pass "kadmin cpw_rnd $pname" +- return 1 +-} +- +-#++ +-# kadmin_modify - Test modify principal function of kadmin. +-# +-# Modifies principal $pname with flags $flags. Returns 1 on success. +-#-- +-proc kadmin_modify { pname flags } { +- global REALMNAME +- global KADMIN +- global KEY +- global spawn_id +- +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "modprinc $flags $pname" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin modify $pname ($flags) lost KDC" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin modify $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin modify $pname" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*: *" +- send "adminpass$KEY\r" +- # When in doubt, jam one of these in there. +- expect "\r" +- expect "Principal \"$pname@$REALMNAME\" modified." +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin modify)" +- catch "close -i $spawn_id" +- pass "kadmin modify $pname" +- return 1 +-} +- +- +-#++ +-# kadmin_list - Test list database function of kadmin. +-# +-# Lists the database and verifies that output matches regular expression +-# "(.*@$REALMNAME)*". Returns 1 on success. +-#-- +-proc kadmin_list { } { +- global REALMNAME +- global KADMIN +- global KEY +- global spawn_id +- +- # "*" would match everything +- # "*n" should match a few like kadmin/admin but see ticket 5667 +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "get_principals *n" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin ldb lost KDC" +- catch "expect_after" +- return 0 +- } +- "Communication failure" { +- fail "kadmin ldb got RPC error" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin ldb" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin ldb" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*: *" { +- send "adminpass$KEY\r" +- } +- expect -re "\(.*@$REALMNAME\r\n\)+" +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin list)" +- catch "close -i $spawn_id" +- pass "kadmin ldb" +- return 1 +-} +- +-#++ +-# kadmin_extract - Test extract service key function of kadmin. +-# +-# Extracts service key for service name $name instance $instance. Returns +-# 1 on success. +-#-- +-proc kadmin_extract { instance name } { +- global REALMNAME +- global KADMIN +- global KEY +- global spawn_id +- global tmppwd +- +- catch "exec rm -f $tmppwd/keytab" +- +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "xst -k $tmppwd/keytab $name/$instance" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin xst $instance $name lost KDC" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin xst $instance $name" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin xst $instance $name" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*: *" { +- send "adminpass$KEY\r" +- } +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin xst)" +- catch "close -i $spawn_id" +- catch "exec rm -f $instance-new-keytab" +- pass "kadmin xst $instance $name" +- return 1 +-} +- +-#++ +-# kadmin_delete - Test delete principal function of kadmin. +-# +-# Deletes principal $pname. Returns 1 on success. +-#-- +-proc kadmin_delete { pname } { +- global REALMNAME +- global KADMIN +- global KADMIN_LOCAL +- global KEY +- global spawn_id +- global tmppwd +- +- set good 0 +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "delprinc -force $pname" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin_delete $pname lost KDC" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin delprinc $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin delprinc $pname" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*: *" { +- send "adminpass$KEY\r" +- } +- expect "Principal \"$pname@$REALMNAME\" deleted." { set good 1 } +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin delprinc)" +- catch "close -i $spawn_id" +- if { $good == 1 } { +- # +- # use kadmin.local to verify that the old principal is not present. +- # +- envstack_push +- setup_kerberos_env kdc +- spawn $KADMIN_LOCAL -r $REALMNAME +- envstack_pop +- expect_after { +- -i $spawn_id +- timeout { +- fail "kadmin delprinc $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin delprinc $pname" +- catch "expect_after" +- return 0 +- } +- } +- set good 0 +- expect "kadmin.local: " { send "getprinc $pname\r" } +- expect "Principal does not exist while retrieving \"$pname@$REALMNAME\"." { set good 1 } +- expect "kadmin.local: " { send "quit\r" } +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin.local show)" +- catch "close -i $spawn_id" +- if { $good == 1 } { +- pass "kadmin delprinc $pname" +- return 1 +- } +- else { +- fail "kadmin delprinc $pname" +- return 0 +- } +- } +- else { +- fail "kadmin delprinc $pname" +- return 0 +- } +-} +- +-#++ +-# kadmin_delete - Test delete principal function of kadmin. +-# +-# Deletes principal $pname. Returns 1 on success. +-#-- +-proc kadmin_delete_locked_down { pname } { +- global REALMNAME +- global KADMIN +- global KADMIN_LOCAL +- global KEY +- global spawn_id +- global tmppwd +- +- # +- # First test that we fail, then unlock and retry +- # +- +- set good 0 +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "delprinc -force $pname" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin_delete $pname lost KDC" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin delprinc $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin delprinc $pname" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*: *" { +- send "adminpass$KEY\r" +- } +- expect "delete_principal: Operation requires ``delete'' privilege while deleting principal \"$pname@$REALMNAME\"" { set good 1 } +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin delprinc)" +- catch "close -i $spawn_id" +- if { $good == 1 } { +- # +- # use kadmin.local to remove lockdown. +- # +- envstack_push +- setup_kerberos_env kdc +- spawn $KADMIN_LOCAL -r $REALMNAME +- envstack_pop +- expect_after { +- -i $spawn_id +- timeout { +- fail "kadmin delprinc $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin delprinc $pname" +- catch "expect_after" +- return 0 +- } +- } +- set good 0 +- expect "kadmin.local: " { send "modprinc -lockdown_keys $pname\r" } +- expect "Principal \"$pname@$REALMNAME\" modified." { set good 1 } +- expect "kadmin.local: " { send "quit\r" } +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin.local show)" +- catch "close -i $spawn_id" +- if { $good == 1 } { +- set good 0 +- if {[kadmin_delete $pname]} { set good 1 } +- } +- if { $good == 1 } { +- pass "kadmin delprinc $pname" +- return 1 +- } +- else { +- fail "kadmin delprinc $pname" +- return 0 +- } +- } +- else { +- fail "kadmin delprinc $pname" +- return 0 +- } +-} +- +-#++ +-# kpasswd_cpw - Test password changing using kpasswd. +-# +-# Change $princ's password from $opw to $npw. Returns 1 on success. +-#-- +-proc kpasswd_cpw { princ opw npw } { +- global KPASSWD +- global REALMNAME +- +- spawn $KPASSWD $princ +- expect_after { +- timeout { +- fail "kpasswd $princ $npw" +-# catch "expect_after" +- return 0 +- } +- eof { +- fail "kpasswd $princ $npw" +-# catch "expect_after" +- return 0 +- } +- } +- +-# expect "Changing password for $princ." +-# expect "Old password:" { send "$opw\r" } +-# expect "New password:" { send "$npw\r" } +-# expect "New password (again):" { send "$npw\r" } +- expect "Password for $princ@$REALMNAME:" { send "$opw\r" } +- expect "Enter new password:" { send "$npw\r" } +- expect "Enter it again:" { send "$npw\r" } +-# expect "Kerberos password changed." +- expect "Password changed." +- expect_after +- expect eof +- +- if ![check_exit_status "kpasswd"] { +- fail "kpasswd $princ $npw" +- return 0 +- } +- pass "kpasswd $princ $npw" +- return 1 +-} +- +-#++ +-# kadmin_addpol - Test add new policy function of kadmin. +-# +-# Adds policy $pname. Returns 1 on success. +-#-- +-proc kadmin_addpol { pname } { +- global REALMNAME +- global KADMIN +- global KADMIN_LOCAL +- global KEY +- global spawn_id +- global tmppwd +- +- set good 0 +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "addpol $pname" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin addpol $pname lost KDC" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin addpol $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin addpol $pname" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*: *" { +- send "adminpass$KEY\r" +- } +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin addpol)" +- catch "close -i $spawn_id" +- # +- # use kadmin.local to verify that a policy was created +- # +- envstack_push +- setup_kerberos_env kdc +- spawn $KADMIN_LOCAL -r $REALMNAME +- envstack_pop +- expect_after { +- -i $spawn_id +- timeout { +- fail "kadmin addpol $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin addpol $pname" +- catch "expect_after" +- return 0 +- } +- } +- set good 0 +- expect "kadmin.local: " { send "getpol $pname\r" } +- expect "Policy: $pname" { set good 1 } +- expect "Maximum password life:" { verbose "got max pw life" } +- expect "Minimum password life:" { verbose "got min pw life" } +- expect "Minimum password length:" { verbose "got min pw length" } +- expect "Minimum number of password character classes:" { +- verbose "got min pw character classes" } +- expect "Number of old keys kept:" { verbose "got num old keys kept" } +- expect "kadmin.local: " { send "q\r" } +- +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin.local showpol)" +- catch "close -i $spawn_id" +- if { $good == 1 } { +- pass "kadmin addpol $pname" +- return 1 +- } +- else { +- fail "kadmin addpol $pname" +- return 0 +- } +-} +- +-#++ +-# kadmin_delpol - Test delete policy function of kadmin. +-# +-# Deletes policy $pname. Returns 1 on success. +-#-- +-proc kadmin_delpol { pname } { +- global REALMNAME +- global KADMIN +- global KADMIN_LOCAL +- global KEY +- global spawn_id +- global tmppwd +- +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "delpol -force $pname" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin_delpol $pname lost KDC" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin delpol $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin delpol $pname" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*: *" { +- send "adminpass$KEY\r" +- } +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin delpol)" +- catch "close -i $spawn_id" +- # +- # use kadmin.local to verify that the old policy is not present. +- # +- envstack_push +- setup_kerberos_env kdc +- spawn $KADMIN_LOCAL -r $REALMNAME +- envstack_pop +- expect_after { +- -i $spawn_id +- timeout { +- fail "kadmin delpol $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin delpol $pname" +- catch "expect_after" +- return 0 +- } +- } +- set good 0 +- expect "kadmin.local: " { send "getpol $pname\r" } +- expect "Policy does not exist while retrieving policy \"$pname\"." { +- set good 1 +- } +- expect "kadmin.local: " { send "quit\r" } +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin.local showpol)" +- catch "close -i $spawn_id" +- if { $good == 1 } { +- pass "kadmin delpol $pname" +- return 1 +- } +- else { +- fail "kadmin delpol $pname" +- return 0 +- } +-} +- +-#++ +-# kadmin_listpols - Test list policy database function of kadmin. +-# +-# Lists the policies. Returns 1 on success. +-#-- +-proc kadmin_listpols { } { +- global REALMNAME +- global KADMIN +- global KEY +- global spawn_id +- +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "get_policies *" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin lpols lost KDC" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin lpols" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin lpols" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*: *" { +- send "adminpass$KEY\r" +- } +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin listpols)" +- catch "close -i $spawn_id" +- pass "kadmin lpols" +- return 1 +-} +- +-#++ +-# kadmin_modpol - Test modify policy function of kadmin. +-# +-# Modifies policy $pname with flags $flags. Returns 1 on success. +-#-- +-proc kadmin_modpol { pname flags } { +- global REALMNAME +- global KADMIN +- global KEY +- global spawn_id +- +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "modpol $flags $pname" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin modpol $pname ($flags) lost KDC" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin modpol $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin modpol $pname" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*: *" +- send "adminpass$KEY\r" +- # When in doubt, jam one of these in there. +- expect "\r" +- # Sadly, kadmin doesn't print a confirmation message for policy operations. +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin modpol)" +- catch "close -i $spawn_id" +- pass "kadmin modpol $pname" +- return 1 +-} +- +-#++ +-# kadmin_showpol - Test show policy function of kadmin. +-# +-# Retrieves entry for $pname. Returns 1 on success. +-#-- +-proc kadmin_showpol { pname } { +- global REALMNAME +- global KADMIN +- global KEY +- global spawn_id +- +- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "get_policy $pname" +- expect_after { +- "Cannot contact any KDC" { +- fail "kadmin showpol $pname lost KDC" +- catch "expect_after" +- return 0 +- } +- timeout { +- fail "kadmin showpol $pname" +- catch "expect_after" +- return 0 +- } +- eof { +- fail "kadmin showpol $pname" +- catch "expect_after" +- return 0 +- } +- } +- expect -re "assword\[^\r\n\]*: *" +- send "adminpass$KEY\r" +- expect -re "\r.*Policy: $pname.*Number of old keys kept: .*\r" +- expect_after +- expect eof +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin showpol)" +- catch "close -i $spawn_id" +- pass "kadmin showpol $pname" +- return 1 +-} +- +-#++ +-# kdestroy +-#-- +-proc kdestroy { } { +- global KDESTROY +- +- spawn $KDESTROY -5 +- if ![check_exit_status "kdestroy"] { +- return 0 +- } +- return 1 +-} +- +-# Wrap the tests in a procedure, so that we can kill the daemons if +-# we get some sort of error. +- +-proc kadmin_test { } { +- global hostname +- +- # Start up the kerberos and kadmind daemons +- if {![start_kerberos_daemons 0] } { +- return +- } +- +- # Test basic kadmin functions. +- if {![kadmin_add v5principal/instance1 v5principal] \ +- || ![kadmin_addpol standardpol] \ +- || ![kadmin_showpol standardpol] \ +- || ![kadmin_listpols] \ +- || ![kadmin_modpol standardpol "-minlength 5"] \ +- || ![kadmin_add v4principal/instance2 v4principal] \ +- || ![kadmin_add_rnd v5random] \ +- || ![kadmin_show v5principal/instance1] \ +- || ![kadmin_show v4principal/instance2] \ +- || ![kadmin_show v5random] \ +- || ![kadmin_cpw v5principal/instance1 faroutman] \ +- || ![kadmin_cpw v4principal/instance2 honkydory] \ +- || ![kadmin_cpw_rnd v5random] \ +- || ![kadmin_modify v5random -allow_tix] \ +- || ![kadmin_modify v5random +allow_tix] \ +- || ![kadmin_modify v5random "-policy standardpol"] \ +- || ![kadmin_list] \ +- || ![kadmin_extract instance1 v5principal] \ +- || ![kadmin_delete v5random] \ +- || ![kadmin_delete v4principal/instance2] \ +- || ![kadmin_delete v5principal/instance1] \ +- || ![kadmin_delpol standardpol]} { +- return +- } +- +-# You cannot extract a v4 key... +-# || ![kadmin_extractv4 instance2 v4principal] \ +- +- # now test kpasswd +- if {![kadmin_add testprinc/instance thisisatest] \ +- || ![kpasswd_cpw testprinc/instance thisisatest anothertest] \ +- || ![kpasswd_cpw testprinc/instance anothertest goredsox] \ +- || ![kadmin_delete testprinc/instance]} { +- return +- } +- +- # now test that we can kinit with principals/passwords. +- # We defer kdestroying until after kpasswd at least once to test FAST automatic use in kpasswd +- if {![kadmin_add testprinc1/instance thisisatest] \ +- || ![kinit testprinc1/instance thisisatest 0] \ +- || ![kpasswd_cpw testprinc1/instance thisisatest anothertest] \ +- || ![kdestroy] \ +- || ![kinit testprinc1/instance anothertest 0] \ +- || ![kdestroy] \ +- || ![kpasswd_cpw testprinc1/instance anothertest goredsox] \ +- || ![kinit testprinc1/instance goredsox 0] \ +- || ![kdestroy] \ +- || ![kadmin_cpw testprinc1/instance betterwork] \ +- || ![kinit testprinc1/instance betterwork 0] \ +- || ![kdestroy] \ +- || ![kadmin_delete testprinc1/instance]} { +- return +- } +- +- # now test modify changes. +- if {![kadmin_add testuser longtestpw] \ +- || ![kinit testuser longtestpw 0] \ +- || ![kdestroy] \ +- || ![kadmin_modify testuser "-maxlife \"2500 seconds\""] \ +- || ![kinit testuser longtestpw 0] \ +- || ![kdestroy] \ +- || ![kadmin_delete testuser]} { +- return +- } +- +- # now test that reducing the history number doesn't make kadmind vulnerable. +- if {![kadmin_addpol crashpol] \ +- || ![kadmin_modpol crashpol "-history 5"] \ +- || ![kadmin_add crash first] \ +- || ![kadmin_modify crash "-policy crashpol"] \ +- || ![kadmin_cpw crash second] \ +- || ![kadmin_cpw crash third] \ +- || ![kadmin_cpw crash fourth] \ +- || ![kadmin_modpol crashpol "-history 3"] \ +- || ![kadmin_cpw crash fifth] \ +- || ![kadmin_delete crash] \ +- || ![kadmin_delpol crashpol]} { +- return +- } +- +- # test retrieval of large number of principals +- # bug [2877] +- for { set i 0 } { $i < 200 } { incr i } { +- if { ![kadmin_add "foo$i" foopass] } { +- return +- } +- } +- +- if { ![kadmin_list] } { +- return +- } +- +- # test fallback to kadmin/hostname +- if {![kadmin_add_rnd kadmin/$hostname] \ +- || ![kadmin_delete_locked_down kadmin/admin] \ +- || ![kadmin_list] \ +- || ![kadmin_add_rnd kadmin/admin -allow_tgs_req] \ +- || ![kadmin_list]} { +- return +- } +- +- verbose "kadmin_test succeeded" +-} +- +-run_once kadmin { +- # Set up the kerberos database. +- if {![get_hostname] \ +- || ![setup_kerberos_files] \ +- || ![setup_kerberos_env] \ +- || ![setup_kerberos_db 0]} { +- return +- } +- +- # Run the test. +- set status [catch kadmin_test msg] +- +- # Shut down the kerberos daemons and the rsh daemon. +- stop_kerberos_daemons +- +- if { $status != 0 } { +- send_error "ERROR: error in kadmin.exp\n" +- send_error "$msg\n" +- exit 1 +- } +-} +diff --git a/src/tests/dejagnu/krb-standalone/pwchange.exp b/src/tests/dejagnu/krb-standalone/pwchange.exp +deleted file mode 100644 +index 010e8344a..000000000 +--- a/src/tests/dejagnu/krb-standalone/pwchange.exp ++++ /dev/null +@@ -1,145 +0,0 @@ +-# Password-changing Kerberos test. +-# This is a DejaGnu test script. +- +-# We are about to start up a couple of daemon processes. We do all +-# the rest of the tests inside a proc, so that we can easily kill the +-# processes when the procedure ends. +- +-proc kinit_expecting_pwchange { name pass newpass } { +- global REALMNAME +- global KINIT +- global spawn_id +- +- # Use kinit to get a ticket. +- # +- # For now always get forwardable tickets. Later when we need to make +- # tests that distinguish between forwardable tickets and otherwise +- # we should but another option to this proc. --proven +- # +- spawn $KINIT -5 -f $name@$REALMNAME +- expect { +- "Password for $name@$REALMNAME:" { +- verbose "kinit started" +- } +- timeout { +- fail "kinit" +- return 0 +- } +- eof { +- fail "kinit" +- return 0 +- } +- } +- send "$pass\r" +- expect { +- "Enter new password: " { } +- timeout { +- fail "kinit (new password prompt)" +- return 0 +- } +- eof { +- fail "kinit (new password prompt)" +- return 0 +- } +- } +- send "$newpass\r" +- expect { +- " again: " { } +- timeout { +- fail "kinit (new password prompt2)" +- return 0 +- } +- eof { +- fail "kinit (new password prompt2)" +- return 0 +- } +- } +- send "$newpass\r" +- expect eof +- if ![check_exit_status kinit] { +- return 0 +- } +- +- return 1 +-} +- +-proc doit { } { +- global REALMNAME +- global KLIST +- global KDESTROY +- global KEY +- global KADMIN_LOCAL +- global KTUTIL +- global hostname +- global tmppwd +- global spawn_id +- global supported_enctypes +- global KRBIV +- global portbase +- global mode +- +- # Start up the kerberos and kadmind daemons. +- if ![start_kerberos_daemons 0] { +- return +- } +- +- # Use kadmin to add a key. +- if ![add_kerberos_key pwchanger 0] { +- return +- } +- +- setup_kerberos_env kdc +- spawn $KADMIN_LOCAL -q "modprinc +needchange pwchanger" +- catch expect_after +- expect { +- timeout { +- fail "kadmin.local modprinc +needchange" +- } +- eof { +- pass "kadmin.local modprinc +needchange" +- } +- } +- set k_stat [wait -i $spawn_id] +- verbose "wait -i $spawn_id returned $k_stat (kadmin modprinc +needchange)" +- catch "close -i $spawn_id" +- +- setup_kerberos_env client +- if ![kinit_expecting_pwchange pwchanger pwchanger$KEY floople] { +- return +- } +- pass "kinit (password change)" +- if ![kinit pwchanger floople 0] { +- return +- } +- pass "kinit (new password)" +- +- # Destroy the ticket. +- spawn $KDESTROY -5 +- if ![check_exit_status "kdestroy"] { +- return +- } +- pass "kdestroy" +-} +- +-run_once pwchange { +- # Set up the Kerberos files and environment. +- if {![get_hostname] || ![setup_kerberos_files] || ![setup_kerberos_env]} { +- return +- } +- +- # Initialize the Kerberos database. The argument tells +- # setup_kerberos_db that it is being called from here. +- if ![setup_kerberos_db 0] { +- return +- } +- +- set status [catch doit msg] +- +- stop_kerberos_daemons +- +- if { $status != 0 } { +- send_error "ERROR: error in pwchange.exp\n" +- send_error "$msg\n" +- exit 1 +- } +-} +diff --git a/src/tests/dejagnu/krb-standalone/pwhist.exp b/src/tests/dejagnu/krb-standalone/pwhist.exp +deleted file mode 100644 +index ed7a3771a..000000000 +--- a/src/tests/dejagnu/krb-standalone/pwhist.exp ++++ /dev/null +@@ -1,217 +0,0 @@ +-# password history tests +- +-# one *non-interactive* kadmin.local request +-proc onerq { rq pname str {flags ""} } { +- global REALMNAME +- global KADMIN_LOCAL +- +- spawn $KADMIN_LOCAL -r $REALMNAME -q "$rq $flags $pname" +- expect_after { +- timeout { +- verbose "kadmin.local $rq $flags $pname timed out" +- catch expect_after +- kill [exp_pid] +- close +- expect eof +- wait +- return 0 +- } eof { +- verbose "kadmin.local $rq $flags $pname got EOF" +- catch expect_after +- wait +- return 0 +- } +- } +- expect $str +- expect_after +- expect eof +- wait +- return 1 +-} +- +-proc addprinc { pname pw } { +- global REALMNAME +- +- return [onerq addprinc $pname \ +- "Principal \"$pname@$REALMNAME\" created." "-pw $pw"] +-} +- +-proc delprinc { pname } { +- global REALMNAME +- return [onerq delprinc $pname \ +- "Principal \"$pname@$REALMNAME\" deleted." "-force"] +-} +- +-proc cpw { pname pw } { +- global REALMNAME +- +- return [onerq cpw $pname \ +- "Password for \"$pname@$REALMNAME\" changed." "-pw $pw"] +-} +- +-proc modprinc { pname flags } { +- global REALMNAME +- +- return [onerq modprinc $pname \ +- "Principal \"$pname@$REALMNAME\" modified." $flags] +-} +- +-proc addpol { pname } { +- if ![onerq addpol $pname ""] { +- return 0 +- } +- return [onerq getpol $pname "Policy: $pname"] +-} +- +-proc delpol { pname } { +- onerq delpol $pname "" -force +- return [onerq getpol $pname \ +- "Policy does not exist while retrieving policy \"$pname\"."] +-} +- +-proc modpol { pname flags } { +- return [onerq modpol $pname "" $flags] +-} +- +-# Mandatory command must return true. +-# Issues a break in its parent on failure. +-proc mustrun { cmd } { +- if ![eval $cmd] { +- perror "mandatory command failed: $cmd" +- uplevel break +- } +-} +- +-# Fail test if command fails. +-# Issues a break in its parent on failure. +-proc chkpass { cmd } { +- upvar test test +- if ![eval $cmd] { +- verbose "unexpected failure: $cmd" +- fail $test +- uplevel break +- } +-} +- +-# Fail test if command succeeds. +-# Issues a break in its parent on failure. +-proc chkfail { cmd } { +- upvar test test +- if [eval $cmd] { +- verbose "unexpected success: $cmd" +- fail $test +- uplevel break +- } +-} +- +-# wrapper to run command (actually usually sequence of commands) +-# +-# If any part of CMD throws an exception, set failall, otherwise pass. +-# If failall is already true, report unresolved. +-proc wraptest { test cmd } { +- upvar failall failall +- if $failall { +- unresolved $test +- return +- } +- if [catch $cmd] { +- set failall 1 +- } else { +- pass $test +- } +-} +- +-run_once pwhist { +- # Set up the kerberos database. +- if {![get_hostname] \ +- || ![setup_kerberos_files] \ +- || ![setup_kerberos_env kdc] \ +- || ![setup_kerberos_db 0]} { +- return +- } +- +- set failall 0 +- wraptest "nkeys=1, nhist=3" { +- mustrun { addpol crashpol } +- mustrun { modpol crashpol "-history 3"} +- mustrun { addprinc crash 1111 } +- mustrun { modprinc crash "-policy crashpol" } +- chkpass { cpw crash 2222 } +- chkfail { cpw crash 2222 } +- chkfail { cpw crash 1111 } +- } +- verbose {old_keys [ 1111 ->[] ]} +- +- # The following will result in reading/writing past array bounds if +- # add_to_history() is not patched. +- # +- # NOTE: A pass from this test does not mean the bug isn't present; +- # check with Purify, valgrind, etc. +- wraptest "array bounds ok on nkeys=1, nhist 3->2" { +- mustrun { modpol crashpol "-history 2" } +- chkpass { cpw crash 3333 } +- } +- verbose {old_keys [ ->2222 ]} +- +- wraptest "verify nhist=2" { +- mustrun { delprinc crash } +- mustrun { addprinc crash 1111 } +- mustrun { modprinc crash "-policy crashpol" } +- chkpass { cpw crash 2222 } +- chkfail { cpw crash 2222 } +- chkfail { cpw crash 1111 } +- } +- verbose {old_keys [ ->1111 ]} +- +- # The following will fail if growing the history array causes an extra +- # key to be lost due to failure to shift entries. +- wraptest "grow nhist 2->3" { +- mustrun { modpol crashpol "-history 3" } +- chkpass { cpw crash 3333 } +- chkfail { cpw crash 3333 } +- chkfail { cpw crash 2222 } +- chkfail { cpw crash 1111 } +- } +- verbose {old_keys [ 2222 ->1111 ]} +- +- wraptest "grow nhist 3->4" { +- mustrun { modpol crashpol "-history 4" } +- chkfail { cpw crash 3333 } +- chkfail { cpw crash 2222 } +- chkfail { cpw crash 1111 } +- chkpass { cpw crash 4444 } +- chkfail { cpw crash 3333 } +- chkfail { cpw crash 2222 } +- chkfail { cpw crash 1111 } +- } +- verbose {old_keys [ 2222 3333 ->1111 ]} +- wraptest "shrink nhist 4->3" { +- mustrun { modpol crashpol "-history 3" } +- chkfail { cpw crash 4444 } +- chkfail { cpw crash 3333 } +- chkfail { cpw crash 2222 } +- chkfail { cpw crash 1111 } +- chkpass { cpw crash 5555 } +- } +- verbose {old_keys [ 4444 ->3333 ]} +- wraptest "verify nhist=3" { +- chkfail { cpw crash 5555 } +- chkfail { cpw crash 4444 } +- chkfail { cpw crash 3333 } +- chkpass { cpw crash 2222 } +- } +- verbose {old_keys [ ->4444 5555 ]} +- wraptest "shrink nhist 3->2" { +- mustrun { modpol crashpol "-history 2" } +- chkfail { cpw crash 2222 } +- chkfail { cpw crash 5555 } +- chkfail { cpw crash 4444 } +- chkpass { cpw crash 3333 } +- } +- verbose {old_keys [ ->2222 ]} +- +- delprinc crash +- delpol crashpol +- +- stop_kerberos_daemons +-} +diff --git a/src/tests/t_changepw.py b/src/tests/t_changepw.py +index 573bdbd49..bf8e3a9eb 100755 +--- a/src/tests/t_changepw.py ++++ b/src/tests/t_changepw.py +@@ -1,23 +1,24 @@ + from k5test import * + +-# This file is intended to cover any password-changing mechanism. For +-# now it only contains a regression test for #7868. +- + realm = K5Realm(create_host=False, get_creds=False, start_kadmind=True) ++realm.prep_kadmin() + + # Mark a principal as expired and change its password through kinit. ++mark('password change via kinit') + realm.run([kadminl, 'modprinc', '-pwexpire', '1 day ago', 'user']) + pwinput = password('user') + '\nabcd\nabcd\n' + realm.run([kinit, realm.user_princ], input=pwinput) + +-# Do the same thing with FAST, with tracing turned on. +-realm.run([kadminl, 'modprinc', '-pwexpire', '1 day ago', 'user']) ++# Regression test for #7868 (preauth options ignored when ++# krb5_get_init_creds_password() initiates a password change). This ++# time use the REQUIRES_PWCHANGE bit instead of the password ++# expiration time. ++mark('password change via kinit with FAST') ++realm.run([kadminl, 'modprinc', '+needchange', 'user']) + pwinput = 'abcd\nefgh\nefgh\n' + out, trace = realm.run([kinit, '-T', realm.ccache, realm.user_princ], + input=pwinput, return_trace=True) +- +-# Read the trace and check that FAST was used when getting the +-# kadmin/changepw ticket. ++# Check that FAST was used when getting the kadmin/changepw ticket. + getting_changepw = fast_used_for_changepw = False + for line in trace.splitlines(): + if 'Getting initial credentials for user@' in line: +@@ -29,4 +30,21 @@ for line in trace.splitlines(): + if not fast_used_for_changepw: + fail('FAST was not used to get kadmin/changepw ticket') + ++# Test that passwords specified via kadmin and kpasswd are usable with ++# kinit. ++mark('password change usability by kinit') ++realm.run([kadminl, 'addprinc', '-pw', 'pw1', 'testprinc']) ++# Run kpasswd with an active cache to exercise automatic FAST use. ++realm.kinit('testprinc', 'pw1') ++realm.run([kpasswd, 'testprinc'], input='pw1\npw2\npw2\n') ++realm.kinit('testprinc', 'pw2') ++realm.run([kdestroy]) ++realm.run([kpasswd, 'testprinc'], input='pw2\npw3\npw3\n') ++realm.kinit('testprinc', 'pw3') ++realm.run([kdestroy]) ++realm.run_kadmin(['cpw', '-pw', 'pw4', 'testprinc']) ++realm.kinit('testprinc', 'pw4') ++realm.run([kdestroy]) ++realm.run([kadminl, 'delprinc', 'testprinc']) ++ + success('Password change tests') +diff --git a/src/tests/t_kadmin.py b/src/tests/t_kadmin.py +new file mode 100644 +index 000000000..fe6a3cc2e +--- /dev/null ++++ b/src/tests/t_kadmin.py +@@ -0,0 +1,54 @@ ++from k5test import * ++ ++realm = K5Realm(start_kadmind=True) ++ ++# Create a principal. Test -q option and keyboard entry of the admin ++# password and principal password. Verify creation with kadmin.local. ++realm.run([kadmin, '-q', 'addprinc princ/pw'], ++ input=password('admin') + '\npw1\npw1\n') ++realm.run([kadminl, 'getprinc', 'princ/pw'], ++ expected_msg='Principal: princ/pw@KRBTEST.COM') ++ ++# Run the remaining tests with a cache for efficiency. ++realm.prep_kadmin() ++ ++realm.run_kadmin(['addpol', 'standardpol']) ++realm.run_kadmin(['listpols'], expected_msg='standardpol') ++realm.run_kadmin(['modpol', '-minlength', '5', 'standardpol']) ++realm.run_kadmin(['getpol', 'standardpol'], ++ expected_msg='Minimum password length: 5') ++ ++realm.run_kadmin(['addprinc', '-randkey', 'princ/random']) ++realm.run([kadminl, 'getprinc', 'princ/random'], ++ expected_msg='Principal: princ/random@KRBTEST.COM') ++ ++realm.run_kadmin(['cpw', 'princ/pw'], input='newpw\nnewpw\n') ++realm.run_kadmin(['cpw', '-randkey', 'princ/random']) ++ ++realm.run_kadmin(['modprinc', '-allow_tix', 'princ/random']) ++realm.run_kadmin(['modprinc', '+allow_tix', 'princ/random']) ++realm.run_kadmin(['modprinc', '-policy', 'standardpol', 'princ/random']) ++ ++realm.run_kadmin(['listprincs'], expected_msg='princ/random@KRBTEST.COM') ++ ++realm.run_kadmin(['ktadd', 'princ/pw']) ++ ++realm.run_kadmin(['delprinc', 'princ/random']) ++realm.run([kadminl, 'getprinc', 'princ/random'], expected_code=1, ++ expected_msg='Principal does not exist') ++realm.run_kadmin(['delprinc', 'princ/pw']) ++realm.run([kadminl, 'getprinc', 'princ/pw'], expected_code=1, ++ expected_msg='Principal does not exist') ++ ++realm.run_kadmin(['delpol', 'standardpol']) ++realm.run([kadminl, 'getpol', 'standardpol'], expected_code=1, ++ expected_msg='Policy does not exist') ++ ++# Regression test for #2877 (fixed-sized GSSRPC buffers can't ++# accomodate large listprinc results). ++mark('large listprincs result') ++for i in range(200): ++ realm.run_kadmin(['addprinc', '-randkey', 'foo%d' % i]) ++realm.run_kadmin(['listprincs'], expected_msg='foo199') ++ ++success('kadmin and kpasswd tests') +diff --git a/src/tests/t_policy.py b/src/tests/t_policy.py +index 5a0c06b86..2bb4f5f18 100755 +--- a/src/tests/t_policy.py ++++ b/src/tests/t_policy.py +@@ -25,6 +25,68 @@ realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser'], expected_code=1, + realm.run([kadminl, 'cpw', '-pw', '3rdpassword', 'pwuser']) + realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser']) + ++# Regression test for #929 (kadmind crash with more historical ++# passwords in a principal entry than current policy history setting). ++mark('password history (policy value reduced below current array size)') ++realm.run([kadminl, 'addpol', '-history', '5', 'histpol']) ++realm.addprinc('histprinc', 'first') ++realm.run([kadminl, 'modprinc', '-policy', 'histpol', 'histprinc']) ++realm.run([kadminl, 'cpw', '-pw', 'second', 'histprinc']) ++realm.run([kadminl, 'cpw', '-pw', 'third', 'histprinc']) ++realm.run([kadminl, 'cpw', '-pw', 'fourth', 'histprinc']) ++realm.run([kadminl, 'modpol', '-history', '3', 'histpol']) ++realm.run([kadminl, 'cpw', '-pw', 'fifth', 'histprinc']) ++realm.run([kadminl, 'delprinc', 'histprinc']) ++ ++# Regression test for #2841 (heap buffer overflow when policy history ++# value is reduced to match the number of historical passwords for a ++# principal). ++mark('password history (policy value reduced to current array size)') ++def histfail(*pwlist): ++ for pw in pwlist: ++ realm.run([kadminl, 'cpw', '-pw', pw, 'histprinc'], expected_code=1, ++ expected_msg='Cannot reuse password') ++realm.run([kadminl, 'modpol', '-history', '3', 'histpol']) ++realm.addprinc('histprinc', '1111') ++realm.run([kadminl, 'modprinc', '-policy', 'histpol', 'histprinc']) ++realm.run([kadminl, 'cpw', '-pw', '2222', 'histprinc']) ++histfail('2222', '1111') ++realm.run([kadminl, 'modpol', '-history', '2', 'histpol']) ++realm.run([kadminl, 'cpw', '-pw', '3333', 'histprinc']) ++ ++# Test that the history array is properly resized if the policy ++# history value is increased after the array is filled. ++mark('password history (policy value increase)') ++realm.run([kadminl, 'delprinc', 'histprinc']) ++realm.addprinc('histprinc', '1111') ++realm.run([kadminl, 'modprinc', '-policy', 'histpol', 'histprinc']) ++realm.run([kadminl, 'cpw', '-pw', '2222', 'histprinc']) ++histfail('2222', '1111') ++realm.run([kadminl, 'cpw', '-pw', '2222', 'histprinc'], expected_code=1, ++ expected_msg='Cannot reuse password') ++realm.run([kadminl, 'cpw', '-pw', '1111', 'histprinc'], expected_code=1, ++ expected_msg='Cannot reuse password') ++realm.run([kadminl, 'modpol', '-history', '3', 'histpol']) ++realm.run([kadminl, 'cpw', '-pw', '3333', 'histprinc']) ++histfail('3333', '2222', '1111') ++realm.run([kadminl, 'modpol', '-history', '4', 'histpol']) ++histfail('3333', '2222', '1111') ++realm.run([kadminl, 'cpw', '-pw', '4444', 'histprinc']) ++histfail('4444', '3333', '2222', '1111') ++ ++# Test that when the policy history value is reduced, all currently ++# known old passwords still fail until the next password change, after ++# which the new number of old passwords fails (but no more). ++mark('password history (policy value reduction)') ++realm.run([kadminl, 'modpol', '-history', '3', 'histpol']) ++histfail('4444', '3333', '2222', '1111') ++realm.run([kadminl, 'cpw', '-pw', '5555', 'histprinc']) ++histfail('5555', '3333', '3333') ++realm.run([kadminl, 'cpw', '-pw', '2222', 'histprinc']) ++realm.run([kadminl, 'modpol', '-history', '2', 'histpol']) ++histfail('2222', '5555', '4444') ++realm.run([kadminl, 'cpw', '-pw', '3333', 'histprinc']) ++ + # Test references to nonexistent policies. + mark('nonexistent policy references') + realm.run([kadminl, 'addprinc', '-randkey', '-policy', 'newpol', 'newuser']) diff --git a/krb5.spec b/krb5.spec index b59f39c..25d282e 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}9%{?dist} +Release: %{?zdpd}10%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -79,6 +79,10 @@ Patch13: Make-KCM-iteration-fallback-work-with-sssd-kcm.patch Patch14: Use-KCM_OP_RETRIEVE-in-KCM-client.patch Patch15: Fix-KCM-retrieval-support-for-sssd.patch Patch16: Fix-doc-build-for-Sphinx-4.0.patch +Patch17: Move-some-dejagnu-kadmin-tests-to-Python-tests.patch +Patch18: Fix-some-principal-realm-canonicalization-cases.patch +Patch19: Allow-kinit-with-keytab-to-defer-canonicalization.patch +Patch20: Fix-kadmin-k-with-fallback-or-referral-realm.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -641,6 +645,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Jun 09 2021 Robbie Harwood - 1.19.1-10 +- Fix three canonicalization cases for fallback + * Wed Jun 02 2021 Robbie Harwood - 1.19.1-9 - Fix doc build for Sphinx 4.0 From 91bbbda93f828542274c82abc8288af0cfbba6fe Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 21 Jun 2021 13:16:44 -0400 Subject: [PATCH 241/304] Add the backward-compatible parts of openssl3 support --- Fix-k5tls-module-for-OpenSSL-3.patch | 57 ++ ...pkcs11-build-issues-with-openssl-3.0.patch | 551 ++++++++++++++++++ ...ecated-OpenSSL-calls-from-softpkcs11.patch | 149 +++++ krb5.spec | 8 +- 4 files changed, 764 insertions(+), 1 deletion(-) create mode 100644 Fix-k5tls-module-for-OpenSSL-3.patch create mode 100644 Fix-softpkcs11-build-issues-with-openssl-3.0.patch create mode 100644 Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch diff --git a/Fix-k5tls-module-for-OpenSSL-3.patch b/Fix-k5tls-module-for-OpenSSL-3.patch new file mode 100644 index 0000000..fd425b8 --- /dev/null +++ b/Fix-k5tls-module-for-OpenSSL-3.patch @@ -0,0 +1,57 @@ +From 201e38845e9f70234bcaa9ba7c25b28e38169b0a Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Sat, 29 May 2021 12:05:49 -0400 +Subject: [PATCH] Fix k5tls module for OpenSSL 3 + +Starting in OpenSSL 3, connection termination without a close_notify +alert causes SSL_read() to return SSL_ERROR_SSL instead of +SSL_ERROR_SYSCALL. OpenSSL 3 also provides a new option +SSL_OP_IGNORE_UNEXPECTED_EOF which allows an application to explicitly +ignore possible truncation attacks and receive SSL_ERROR_ZERO_RETURN +instead. + +Remove the call to SSL_CTX_get_options() since SSL_CTX_set_options() +doesn't clear existing options. + +[ghudson@mit.edu: edited commit message and comment] + +(cherry picked from commit aa9b4a2a64046afd2fab7cb49c346295874a5fb6) +--- + src/plugins/tls/k5tls/openssl.c | 17 ++++++++++++++--- + 1 file changed, 14 insertions(+), 3 deletions(-) + +diff --git a/src/plugins/tls/k5tls/openssl.c b/src/plugins/tls/k5tls/openssl.c +index 76a43b3cd..99fda7ffc 100644 +--- a/src/plugins/tls/k5tls/openssl.c ++++ b/src/plugins/tls/k5tls/openssl.c +@@ -433,7 +433,7 @@ setup(krb5_context context, SOCKET fd, const char *servername, + char **anchors, k5_tls_handle *handle_out) + { + int e; +- long options; ++ long options = SSL_OP_NO_SSLv2; + SSL_CTX *ctx = NULL; + SSL *ssl = NULL; + k5_tls_handle handle = NULL; +@@ -448,8 +448,19 @@ setup(krb5_context context, SOCKET fd, const char *servername, + ctx = SSL_CTX_new(SSLv23_client_method()); + if (ctx == NULL) + goto error; +- options = SSL_CTX_get_options(ctx); +- SSL_CTX_set_options(ctx, options | SSL_OP_NO_SSLv2); ++ ++#ifdef SSL_OP_IGNORE_UNEXPECTED_EOF ++ /* ++ * For OpenSSL 3 and later, mark close_notify alerts as optional. We don't ++ * need to worry about truncation attacks because the protocols this module ++ * is used with (Kerberos and change-password) receive a single ++ * length-delimited message from the server. For prior versions of OpenSSL ++ * we check for SSL_ERROR_SYSCALL when reading instead (this error changes ++ * to SSL_ERROR_SSL in OpenSSL 3). ++ */ ++ options |= SSL_OP_IGNORE_UNEXPECTED_EOF; ++#endif ++ SSL_CTX_set_options(ctx, options); + + SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, verify_callback); + X509_STORE_set_flags(SSL_CTX_get_cert_store(ctx), 0); diff --git a/Fix-softpkcs11-build-issues-with-openssl-3.0.patch b/Fix-softpkcs11-build-issues-with-openssl-3.0.patch new file mode 100644 index 0000000..d7a0a5c --- /dev/null +++ b/Fix-softpkcs11-build-issues-with-openssl-3.0.patch @@ -0,0 +1,551 @@ +From a86b780ef275b35e8dc1e6d1886ec8e8d941f7c4 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Sat, 15 May 2021 17:35:25 -0400 +Subject: [PATCH] Fix softpkcs11 build issues with openssl 3.0 + +EVP_PKEY_get0_RSA() has been modified to have const return type. Remove +its usages in favor of the EVP_PKEY interface. Also remove calls to +RSA_blinding_off(), which we don't need and would require a non-const +object. Similarly, remove RSA_set_method() calls that set a pre-existing +default. + +Since softpkcs11 doesn't link against krb5 and can't use zap(), allocate +buffers with OPENSSL_malloc() so can use OPENSSL_clear_free(). + +Move several argument validation checks to the top of their functions. + +Fix some incorrect/inconsistent log messages. + +(cherry picked from commit 00de1aad7b3647b91017c7009b0bc65cd0c8b2e0) +--- + src/tests/softpkcs11/main.c | 360 ++++++++++++++---------------------- + 1 file changed, 141 insertions(+), 219 deletions(-) + +diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c +index 1cccdfb43..caa537b68 100644 +--- a/src/tests/softpkcs11/main.c ++++ b/src/tests/softpkcs11/main.c +@@ -375,10 +375,9 @@ add_st_object(void) + return NULL; + soft_token.object.objs = objs; + +- o = malloc(sizeof(*o)); ++ o = calloc(1, sizeof(*o)); + if (o == NULL) + return NULL; +- memset(o, 0, sizeof(*o)); + o->attrs = NULL; + o->num_attributes = 0; + o->object_handle = soft_token.object.num_objs; +@@ -424,7 +423,7 @@ add_pubkey_info(struct st_object *o, CK_KEY_TYPE key_type, EVP_PKEY *key) + CK_ULONG modulus_bits = 0; + CK_BYTE *exponent = NULL; + size_t exponent_len = 0; +- RSA *rsa; ++ const RSA *rsa; + const BIGNUM *n, *e; + + rsa = EVP_PKEY_get0_RSA(key); +@@ -445,8 +444,6 @@ add_pubkey_info(struct st_object *o, CK_KEY_TYPE key_type, EVP_PKEY *key) + add_object_attribute(o, 0, CKA_PUBLIC_EXPONENT, + exponent, exponent_len); + +- RSA_set_method(rsa, RSA_PKCS1_OpenSSL()); +- + free(modulus); + free(exponent); + } +@@ -679,10 +676,6 @@ add_certificate(char *label, + } else { + /* XXX verify keytype */ + +- if (key_type == CKK_RSA) +- RSA_set_method(EVP_PKEY_get0_RSA(o->u.private_key.key), +- RSA_PKCS1_OpenSSL()); +- + if (X509_check_private_key(cert, o->u.private_key.key) != 1) { + EVP_PKEY_free(o->u.private_key.key); + o->u.private_key.key = NULL; +@@ -695,7 +688,7 @@ add_certificate(char *label, + } + + ret = CKR_OK; +- out: ++out: + if (ret != CKR_OK) { + st_logf("something went wrong when adding cert!\n"); + +@@ -1224,8 +1217,6 @@ C_Login(CK_SESSION_HANDLE hSession, + } + + /* XXX check keytype */ +- RSA_set_method(EVP_PKEY_get0_RSA(o->u.private_key.key), +- RSA_PKCS1_OpenSSL()); + + if (X509_check_private_key(o->u.private_key.cert, o->u.private_key.key) != 1) { + EVP_PKEY_free(o->u.private_key.key); +@@ -1495,8 +1486,9 @@ C_Encrypt(CK_SESSION_HANDLE hSession, + struct st_object *o; + void *buffer = NULL; + CK_RV ret; +- RSA *rsa; +- int padding, len, buffer_len, padding_len; ++ size_t buffer_len = 0; ++ int padding; ++ EVP_PKEY_CTX *ctx = NULL; + + st_logf("Encrypt\n"); + +@@ -1512,70 +1504,58 @@ C_Encrypt(CK_SESSION_HANDLE hSession, + return CKR_ARGUMENTS_BAD; + } + +- rsa = EVP_PKEY_get0_RSA(o->u.public_key); +- +- if (rsa == NULL) +- return CKR_ARGUMENTS_BAD; +- +- RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ +- +- buffer_len = RSA_size(rsa); +- +- buffer = malloc(buffer_len); +- if (buffer == NULL) { +- ret = CKR_DEVICE_MEMORY; +- goto out; +- } +- +- ret = CKR_OK; +- switch(state->encrypt_mechanism->mechanism) { +- case CKM_RSA_PKCS: +- padding = RSA_PKCS1_PADDING; +- padding_len = RSA_PKCS1_PADDING_SIZE; +- break; +- case CKM_RSA_X_509: +- padding = RSA_NO_PADDING; +- padding_len = 0; +- break; +- default: +- ret = CKR_FUNCTION_NOT_SUPPORTED; +- goto out; +- } +- +- if ((CK_ULONG)buffer_len + padding_len < ulDataLen) { +- ret = CKR_ARGUMENTS_BAD; +- goto out; +- } +- + if (pulEncryptedDataLen == NULL) { + st_logf("pulEncryptedDataLen NULL\n"); + ret = CKR_ARGUMENTS_BAD; + goto out; + } + +- if (pData == NULL_PTR) { ++ if (pData == NULL) { + st_logf("data NULL\n"); + ret = CKR_ARGUMENTS_BAD; + goto out; + } + +- len = RSA_public_encrypt(ulDataLen, pData, buffer, rsa, padding); +- if (len <= 0) { ++ switch(state->encrypt_mechanism->mechanism) { ++ case CKM_RSA_PKCS: ++ padding = RSA_PKCS1_PADDING; ++ break; ++ case CKM_RSA_X_509: ++ padding = RSA_NO_PADDING; ++ break; ++ default: ++ ret = CKR_FUNCTION_NOT_SUPPORTED; ++ goto out; ++ } ++ ++ ctx = EVP_PKEY_CTX_new(o->u.public_key, NULL); ++ if (ctx == NULL || EVP_PKEY_encrypt_init(ctx) <= 0 || ++ EVP_PKEY_CTX_set_rsa_padding(ctx, padding) <= 0 || ++ EVP_PKEY_encrypt(ctx, NULL, &buffer_len, pData, ulDataLen) <= 0) { + ret = CKR_DEVICE_ERROR; + goto out; + } +- if (len > buffer_len) +- abort(); + +- if (pEncryptedData != NULL_PTR) +- memcpy(pEncryptedData, buffer, len); +- *pulEncryptedDataLen = len; +- +- out: +- if (buffer) { +- memset(buffer, 0, buffer_len); +- free(buffer); ++ buffer = OPENSSL_malloc(buffer_len); ++ if (buffer == NULL) { ++ ret = CKR_DEVICE_MEMORY; ++ goto out; + } ++ ++ if (EVP_PKEY_encrypt(ctx, buffer, &buffer_len, pData, ulDataLen) <= 0) { ++ ret = CKR_DEVICE_ERROR; ++ goto out; ++ } ++ st_logf("Encrypt done\n"); ++ ++ if (pEncryptedData != NULL) ++ memcpy(pEncryptedData, buffer, buffer_len); ++ *pulEncryptedDataLen = buffer_len; ++ ++ ret = CKR_OK; ++out: ++ OPENSSL_clear_free(buffer, buffer_len); ++ EVP_PKEY_CTX_free(ctx); + return ret; + } + +@@ -1646,8 +1626,9 @@ C_Decrypt(CK_SESSION_HANDLE hSession, + struct st_object *o; + void *buffer = NULL; + CK_RV ret; +- RSA *rsa; +- int padding, len, buffer_len, padding_len; ++ size_t buffer_len = 0; ++ int padding; ++ EVP_PKEY_CTX *ctx = NULL; + + st_logf("Decrypt\n"); + +@@ -1663,41 +1644,6 @@ C_Decrypt(CK_SESSION_HANDLE hSession, + return CKR_ARGUMENTS_BAD; + } + +- rsa = EVP_PKEY_get0_RSA(o->u.private_key.key); +- +- if (rsa == NULL) +- return CKR_ARGUMENTS_BAD; +- +- RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ +- +- buffer_len = RSA_size(rsa); +- +- buffer = malloc(buffer_len); +- if (buffer == NULL) { +- ret = CKR_DEVICE_MEMORY; +- goto out; +- } +- +- ret = CKR_OK; +- switch(state->decrypt_mechanism->mechanism) { +- case CKM_RSA_PKCS: +- padding = RSA_PKCS1_PADDING; +- padding_len = RSA_PKCS1_PADDING_SIZE; +- break; +- case CKM_RSA_X_509: +- padding = RSA_NO_PADDING; +- padding_len = 0; +- break; +- default: +- ret = CKR_FUNCTION_NOT_SUPPORTED; +- goto out; +- } +- +- if ((CK_ULONG)buffer_len + padding_len < ulEncryptedDataLen) { +- ret = CKR_ARGUMENTS_BAD; +- goto out; +- } +- + if (pulDataLen == NULL) { + st_logf("pulDataLen NULL\n"); + ret = CKR_ARGUMENTS_BAD; +@@ -1710,24 +1656,48 @@ C_Decrypt(CK_SESSION_HANDLE hSession, + goto out; + } + +- len = RSA_private_decrypt(ulEncryptedDataLen, pEncryptedData, buffer, +- rsa, padding); +- if (len <= 0) { ++ switch(state->decrypt_mechanism->mechanism) { ++ case CKM_RSA_PKCS: ++ padding = RSA_PKCS1_PADDING; ++ break; ++ case CKM_RSA_X_509: ++ padding = RSA_NO_PADDING; ++ break; ++ default: ++ ret = CKR_FUNCTION_NOT_SUPPORTED; ++ goto out; ++ } ++ ++ ctx = EVP_PKEY_CTX_new(o->u.private_key.key, NULL); ++ if (ctx == NULL || EVP_PKEY_decrypt_init(ctx) <= 0 || ++ EVP_PKEY_CTX_set_rsa_padding(ctx, padding) <= 0 || ++ EVP_PKEY_decrypt(ctx, NULL, &buffer_len, pEncryptedData, ++ ulEncryptedDataLen) <= 0) { + ret = CKR_DEVICE_ERROR; + goto out; + } +- if (len > buffer_len) +- abort(); ++ ++ buffer = OPENSSL_malloc(buffer_len); ++ if (buffer == NULL) { ++ ret = CKR_DEVICE_MEMORY; ++ goto out; ++ } ++ ++ if (EVP_PKEY_decrypt(ctx, buffer, &buffer_len, pEncryptedData, ++ ulEncryptedDataLen) <= 0) { ++ ret = CKR_DEVICE_ERROR; ++ goto out; ++ } ++ st_logf("Decrypt done\n"); + + if (pData != NULL_PTR) +- memcpy(pData, buffer, len); +- *pulDataLen = len; ++ memcpy(pData, buffer, buffer_len); ++ *pulDataLen = buffer_len; + +- out: +- if (buffer) { +- memset(buffer, 0, buffer_len); +- free(buffer); +- } ++ ret = CKR_OK; ++out: ++ OPENSSL_clear_free(buffer, buffer_len); ++ EVP_PKEY_CTX_free(ctx); + return ret; + } + +@@ -1806,8 +1776,9 @@ C_Sign(CK_SESSION_HANDLE hSession, + struct st_object *o; + void *buffer = NULL; + CK_RV ret; +- RSA *rsa; +- int padding, len, buffer_len, padding_len; ++ int padding; ++ size_t buffer_len = 0; ++ EVP_PKEY_CTX *ctx = NULL; + + st_logf("Sign\n"); + VERIFY_SESSION_HANDLE(hSession, &state); +@@ -1822,40 +1793,6 @@ C_Sign(CK_SESSION_HANDLE hSession, + return CKR_ARGUMENTS_BAD; + } + +- rsa = EVP_PKEY_get0_RSA(o->u.private_key.key); +- +- if (rsa == NULL) +- return CKR_ARGUMENTS_BAD; +- +- RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ +- +- buffer_len = RSA_size(rsa); +- +- buffer = malloc(buffer_len); +- if (buffer == NULL) { +- ret = CKR_DEVICE_MEMORY; +- goto out; +- } +- +- switch(state->sign_mechanism->mechanism) { +- case CKM_RSA_PKCS: +- padding = RSA_PKCS1_PADDING; +- padding_len = RSA_PKCS1_PADDING_SIZE; +- break; +- case CKM_RSA_X_509: +- padding = RSA_NO_PADDING; +- padding_len = 0; +- break; +- default: +- ret = CKR_FUNCTION_NOT_SUPPORTED; +- goto out; +- } +- +- if ((CK_ULONG)buffer_len < ulDataLen + padding_len) { +- ret = CKR_ARGUMENTS_BAD; +- goto out; +- } +- + if (pulSignatureLen == NULL) { + st_logf("signature len NULL\n"); + ret = CKR_ARGUMENTS_BAD; +@@ -1868,26 +1805,46 @@ C_Sign(CK_SESSION_HANDLE hSession, + goto out; + } + +- len = RSA_private_encrypt(ulDataLen, pData, buffer, rsa, padding); +- st_logf("private encrypt done\n"); +- if (len <= 0) { ++ switch(state->sign_mechanism->mechanism) { ++ case CKM_RSA_PKCS: ++ padding = RSA_PKCS1_PADDING; ++ break; ++ case CKM_RSA_X_509: ++ padding = RSA_NO_PADDING; ++ break; ++ default: ++ ret = CKR_FUNCTION_NOT_SUPPORTED; ++ goto out; ++ } ++ ++ ctx = EVP_PKEY_CTX_new(o->u.private_key.key, NULL); ++ if (ctx == NULL || EVP_PKEY_sign_init(ctx) <= 0 || ++ EVP_PKEY_CTX_set_rsa_padding(ctx, padding) <= 0 || ++ EVP_PKEY_sign(ctx, NULL, &buffer_len, pData, ulDataLen) <= 0) { + ret = CKR_DEVICE_ERROR; + goto out; + } +- if (len > buffer_len) +- abort(); + +- if (pSignature != NULL_PTR) +- memcpy(pSignature, buffer, len); +- *pulSignatureLen = len; ++ buffer = OPENSSL_malloc(buffer_len); ++ if (buffer == NULL) { ++ ret = CKR_DEVICE_MEMORY; ++ goto out; ++ } ++ ++ if (EVP_PKEY_sign(ctx, buffer, &buffer_len, pData, ulDataLen) <= 0) { ++ ret = CKR_DEVICE_ERROR; ++ goto out; ++ } ++ st_logf("Sign done\n"); ++ ++ if (pSignature != NULL) ++ memcpy(pSignature, buffer, buffer_len); ++ *pulSignatureLen = buffer_len; + + ret = CKR_OK; +- +- out: +- if (buffer) { +- memset(buffer, 0, buffer_len); +- free(buffer); +- } ++out: ++ OPENSSL_clear_free(buffer, buffer_len); ++ EVP_PKEY_CTX_free(ctx); + return ret; + } + +@@ -1951,10 +1908,9 @@ C_Verify(CK_SESSION_HANDLE hSession, + { + struct session_state *state; + struct st_object *o; +- void *buffer = NULL; + CK_RV ret; +- RSA *rsa; +- int padding, len, buffer_len; ++ int padding; ++ EVP_PKEY_CTX *ctx = NULL; + + st_logf("Verify\n"); + VERIFY_SESSION_HANDLE(hSession, &state); +@@ -1969,39 +1925,6 @@ C_Verify(CK_SESSION_HANDLE hSession, + return CKR_ARGUMENTS_BAD; + } + +- rsa = EVP_PKEY_get0_RSA(o->u.public_key); +- +- if (rsa == NULL) +- return CKR_ARGUMENTS_BAD; +- +- RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ +- +- buffer_len = RSA_size(rsa); +- +- buffer = malloc(buffer_len); +- if (buffer == NULL) { +- ret = CKR_DEVICE_MEMORY; +- goto out; +- } +- +- ret = CKR_OK; +- switch(state->verify_mechanism->mechanism) { +- case CKM_RSA_PKCS: +- padding = RSA_PKCS1_PADDING; +- break; +- case CKM_RSA_X_509: +- padding = RSA_NO_PADDING; +- break; +- default: +- ret = CKR_FUNCTION_NOT_SUPPORTED; +- goto out; +- } +- +- if ((CK_ULONG)buffer_len < ulDataLen) { +- ret = CKR_ARGUMENTS_BAD; +- goto out; +- } +- + if (pSignature == NULL) { + st_logf("signature NULL\n"); + ret = CKR_ARGUMENTS_BAD; +@@ -2014,34 +1937,34 @@ C_Verify(CK_SESSION_HANDLE hSession, + goto out; + } + +- len = RSA_public_decrypt(ulDataLen, pData, buffer, rsa, padding); +- st_logf("private encrypt done\n"); +- if (len <= 0) { ++ switch(state->verify_mechanism->mechanism) { ++ case CKM_RSA_PKCS: ++ padding = RSA_PKCS1_PADDING; ++ break; ++ case CKM_RSA_X_509: ++ padding = RSA_NO_PADDING; ++ break; ++ default: ++ ret = CKR_FUNCTION_NOT_SUPPORTED; ++ goto out; ++ } ++ ++ ctx = EVP_PKEY_CTX_new(o->u.public_key, NULL); ++ if (ctx == NULL || EVP_PKEY_verify_init(ctx) <= 0 || ++ EVP_PKEY_CTX_set_rsa_padding(ctx, padding) <= 0 || ++ EVP_PKEY_verify(ctx, pSignature, ulSignatureLen, pData, ++ ulDataLen) <= 0) { + ret = CKR_DEVICE_ERROR; + goto out; + } +- if (len > buffer_len) +- abort(); ++ st_logf("Verify done\n"); + +- if ((CK_ULONG)len != ulSignatureLen) { +- ret = CKR_GENERAL_ERROR; +- goto out; +- } +- +- if (memcmp(pSignature, buffer, len) != 0) { +- ret = CKR_GENERAL_ERROR; +- goto out; +- } +- +- out: +- if (buffer) { +- memset(buffer, 0, buffer_len); +- free(buffer); +- } ++ ret = CKR_OK; ++out: ++ EVP_PKEY_CTX_free(ctx); + return ret; + } + +- + CK_RV + C_VerifyUpdate(CK_SESSION_HANDLE hSession, + CK_BYTE_PTR pPart, +@@ -2072,7 +1995,6 @@ C_GenerateRandom(CK_SESSION_HANDLE hSession, + return CKR_FUNCTION_NOT_SUPPORTED; + } + +- + CK_FUNCTION_LIST funcs = { + { 2, 11 }, + C_Initialize, diff --git a/Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch b/Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch new file mode 100644 index 0000000..23f21a5 --- /dev/null +++ b/Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch @@ -0,0 +1,149 @@ +From 5072bfdfaddae762680d0f9d97afa6dbf8274760 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Sat, 15 May 2021 18:04:58 -0400 +Subject: [PATCH] Remove deprecated OpenSSL calls from softpkcs11 + +Rewrite add_pubkey_info() in terms of the EVP_PKEY interface. In this +process, fix its unchecked allocations and fail fast for non-RSA keys. + +(cherry picked from commit d6bf42279675100e3e4fe7c6e08eef74d49624cb) +--- + src/configure.ac | 1 + + src/tests/softpkcs11/main.c | 106 ++++++++++++++++++++++++------------ + 2 files changed, 72 insertions(+), 35 deletions(-) + +diff --git a/src/configure.ac b/src/configure.ac +index ea708491b..477819091 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -1118,6 +1118,7 @@ int i = 1; + ])], k5_cv_openssl_version_okay=yes, k5_cv_openssl_version_okay=no)]) + old_LIBS="$LIBS" + AC_CHECK_LIB(crypto, PKCS7_get_signer_info) ++ AC_CHECK_FUNCS(EVP_PKEY_get_bn_param) + LIBS="$old_LIBS" + fi + if test "$k5_cv_openssl_version_okay" = yes && (test "$enable_pkinit" = yes || test "$enable_pkinit" = try); then +diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c +index caa537b68..86b4ef711 100644 +--- a/src/tests/softpkcs11/main.c ++++ b/src/tests/softpkcs11/main.c +@@ -413,47 +413,83 @@ add_object_attribute(struct st_object *o, + return CKR_OK; + } + ++#ifdef HAVE_EVP_PKEY_GET_BN_PARAM ++ ++/* Declare owner pointers since EVP_PKEY_get_bn_param() gives us copies. */ ++#define DECLARE_BIGNUM(name) BIGNUM *name = NULL ++#define RELEASE_BIGNUM(bn) BN_clear_free(bn) + static CK_RV +-add_pubkey_info(struct st_object *o, CK_KEY_TYPE key_type, EVP_PKEY *key) ++get_bignums(EVP_PKEY *key, BIGNUM **n, BIGNUM **e) + { +- switch (key_type) { +- case CKK_RSA: { +- CK_BYTE *modulus = NULL; +- size_t modulus_len = 0; +- CK_ULONG modulus_bits = 0; +- CK_BYTE *exponent = NULL; +- size_t exponent_len = 0; +- const RSA *rsa; +- const BIGNUM *n, *e; ++ if (EVP_PKEY_get_bn_param(key, "n", n) == 0 || ++ EVP_PKEY_get_bn_param(key, "e", e) == 0) ++ return CKR_DEVICE_ERROR; + +- rsa = EVP_PKEY_get0_RSA(key); +- RSA_get0_key(rsa, &n, &e, NULL); +- modulus_bits = BN_num_bits(n); +- +- modulus_len = BN_num_bytes(n); +- modulus = malloc(modulus_len); +- BN_bn2bin(n, modulus); +- +- exponent_len = BN_num_bytes(e); +- exponent = malloc(exponent_len); +- BN_bn2bin(e, exponent); +- +- add_object_attribute(o, 0, CKA_MODULUS, modulus, modulus_len); +- add_object_attribute(o, 0, CKA_MODULUS_BITS, +- &modulus_bits, sizeof(modulus_bits)); +- add_object_attribute(o, 0, CKA_PUBLIC_EXPONENT, +- exponent, exponent_len); +- +- free(modulus); +- free(exponent); +- } +- default: +- /* XXX */ +- break; +- } + return CKR_OK; + } + ++#else ++ ++/* Declare const pointers since the old API gives us aliases. */ ++#define DECLARE_BIGNUM(name) const BIGNUM *name ++#define RELEASE_BIGNUM(bn) ++static CK_RV ++get_bignums(EVP_PKEY *key, const BIGNUM **n, const BIGNUM **e) ++{ ++ const RSA *rsa; ++ ++ rsa = EVP_PKEY_get0_RSA(key); ++ RSA_get0_key(rsa, n, e, NULL); ++ ++ return CKR_OK; ++} ++ ++#endif ++ ++static CK_RV ++add_pubkey_info(struct st_object *o, CK_KEY_TYPE key_type, EVP_PKEY *key) ++{ ++ CK_BYTE *modulus = NULL, *exponent = 0; ++ size_t modulus_len = 0, exponent_len = 0; ++ CK_ULONG modulus_bits = 0; ++ CK_RV ret; ++ DECLARE_BIGNUM(n); ++ DECLARE_BIGNUM(e); ++ ++ if (key_type != CKK_RSA) ++ abort(); ++ ++ ret = get_bignums(key, &n, &e); ++ if (ret != CKR_OK) ++ goto done; ++ ++ modulus_bits = BN_num_bits(n); ++ modulus_len = BN_num_bytes(n); ++ exponent_len = BN_num_bytes(e); ++ ++ modulus = malloc(modulus_len); ++ exponent = malloc(exponent_len); ++ if (modulus == NULL || exponent == NULL) { ++ ret = CKR_DEVICE_MEMORY; ++ goto done; ++ } ++ ++ BN_bn2bin(n, modulus); ++ BN_bn2bin(e, exponent); ++ ++ add_object_attribute(o, 0, CKA_MODULUS, modulus, modulus_len); ++ add_object_attribute(o, 0, CKA_MODULUS_BITS, &modulus_bits, ++ sizeof(modulus_bits)); ++ add_object_attribute(o, 0, CKA_PUBLIC_EXPONENT, exponent, exponent_len); ++ ++ ret = CKR_OK; ++done: ++ free(modulus); ++ free(exponent); ++ RELEASE_BIGNUM(n); ++ RELEASE_BIGNUM(e); ++ return ret; ++} + + static int + pem_callback(char *buf, int num, int w, void *key) diff --git a/krb5.spec b/krb5.spec index 25d282e..6d2a5cb 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}10%{?dist} +Release: %{?zdpd}11%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -83,6 +83,9 @@ Patch17: Move-some-dejagnu-kadmin-tests-to-Python-tests.patch Patch18: Fix-some-principal-realm-canonicalization-cases.patch Patch19: Allow-kinit-with-keytab-to-defer-canonicalization.patch Patch20: Fix-kadmin-k-with-fallback-or-referral-realm.patch +Patch21: Fix-softpkcs11-build-issues-with-openssl-3.0.patch +Patch22: Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch +Patch23: Fix-k5tls-module-for-OpenSSL-3.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -645,6 +648,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jun 21 2021 Robbie Harwood - 1.19.1-11 +- Add the backward-compatible parts of openssl3 support + * Wed Jun 09 2021 Robbie Harwood - 1.19.1-10 - Fix three canonicalization cases for fallback From c5044b07415e379cca8437a8a3c1d0fa00cabb13 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 28 Jun 2021 17:50:46 -0400 Subject: [PATCH 242/304] MEMORY locking fix and static analysis pullup --- ...context-after-failed-open-in-libkdb5.patch | 35 + ...aks-on-error-in-kadm5-init-functions.patch | 664 ++++++++++++++++++ Use-asan-in-one-of-the-CI-builds.patch | 22 + ...king-in-MEMORY-krb5_cc_get_principal.patch | 47 ++ krb5.spec | 9 +- 5 files changed, 776 insertions(+), 1 deletion(-) create mode 100644 Clean-up-context-after-failed-open-in-libkdb5.patch create mode 100644 Fix-leaks-on-error-in-kadm5-init-functions.patch create mode 100644 Use-asan-in-one-of-the-CI-builds.patch create mode 100644 Using-locking-in-MEMORY-krb5_cc_get_principal.patch diff --git a/Clean-up-context-after-failed-open-in-libkdb5.patch b/Clean-up-context-after-failed-open-in-libkdb5.patch new file mode 100644 index 0000000..a892a14 --- /dev/null +++ b/Clean-up-context-after-failed-open-in-libkdb5.patch @@ -0,0 +1,35 @@ +From 78c03a9b5ef3e3f894bea11c89e575b9bb4d1b0f Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 23 Jun 2021 16:57:39 -0400 +Subject: [PATCH] Clean up context after failed open in libkdb5 + +If krb5_db_open() or krb5_db_create() fails, release the dal_handle, +as the caller is unlikely to call krb5_db_close() after a failure. + +(cherry picked from commit 849b7056e703bd3724d909263769ce190db59acc) +--- + src/lib/kdb/kdb5.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/src/lib/kdb/kdb5.c b/src/lib/kdb/kdb5.c +index 47e9b31a7..11e2430c4 100644 +--- a/src/lib/kdb/kdb5.c ++++ b/src/lib/kdb/kdb5.c +@@ -675,6 +675,8 @@ krb5_db_open(krb5_context kcontext, char **db_args, int mode) + return status; + status = v->init_module(kcontext, section, db_args, mode); + free(section); ++ if (status) ++ (void)krb5_db_fini(kcontext); + return status; + } + +@@ -702,6 +704,8 @@ krb5_db_create(krb5_context kcontext, char **db_args) + return status; + status = v->create(kcontext, section, db_args); + free(section); ++ if (status) ++ (void)krb5_db_fini(kcontext); + return status; + } + diff --git a/Fix-leaks-on-error-in-kadm5-init-functions.patch b/Fix-leaks-on-error-in-kadm5-init-functions.patch new file mode 100644 index 0000000..ef12052 --- /dev/null +++ b/Fix-leaks-on-error-in-kadm5-init-functions.patch @@ -0,0 +1,664 @@ +From 6b2f7995ab23cffcababe537d57540236f99f0e3 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 23 Jun 2021 16:53:16 -0400 +Subject: [PATCH] Fix leaks on error in kadm5 init functions + +In the GENERIC_CHECK_HANDLE function, separate out the +version-checking logic so we can call it in the init functions before +allocating resources. + +In the client and server library initialization functions, use a +single exit path after argument validation, and share the destruction +code with kadm5_destroy() via a helper. + +(cherry picked from commit 552d7b7626450f963b8e37345c472420c842402c) +--- + src/lib/kadm5/admin_internal.h | 39 ++++--- + src/lib/kadm5/clnt/client_init.c | 174 +++++++++++----------------- + src/lib/kadm5/srv/server_init.c | 191 ++++++++++--------------------- + 3 files changed, 145 insertions(+), 259 deletions(-) + +diff --git a/src/lib/kadm5/admin_internal.h b/src/lib/kadm5/admin_internal.h +index faf8e9c36..9be53883a 100644 +--- a/src/lib/kadm5/admin_internal.h ++++ b/src/lib/kadm5/admin_internal.h +@@ -11,29 +11,32 @@ + + #define KADM5_SERVER_HANDLE_MAGIC 0x12345800 + +-#define GENERIC_CHECK_HANDLE(handle, old_api_version, new_api_version) \ ++#define CHECK_VERSIONS(struct_version, api_version, old_api_err, new_api_err) \ + { \ +- kadm5_server_handle_t srvr = \ +- (kadm5_server_handle_t) handle; \ +- \ +- if (! srvr) \ +- return KADM5_BAD_SERVER_HANDLE; \ +- if (srvr->magic_number != KADM5_SERVER_HANDLE_MAGIC) \ +- return KADM5_BAD_SERVER_HANDLE; \ +- if ((srvr->struct_version & KADM5_MASK_BITS) != \ +- KADM5_STRUCT_VERSION_MASK) \ ++ if ((struct_version & KADM5_MASK_BITS) != KADM5_STRUCT_VERSION_MASK) \ + return KADM5_BAD_STRUCT_VERSION; \ +- if (srvr->struct_version < KADM5_STRUCT_VERSION_1) \ ++ if (struct_version < KADM5_STRUCT_VERSION_1) \ + return KADM5_OLD_STRUCT_VERSION; \ +- if (srvr->struct_version > KADM5_STRUCT_VERSION_1) \ ++ if (struct_version > KADM5_STRUCT_VERSION_1) \ + return KADM5_NEW_STRUCT_VERSION; \ +- if ((srvr->api_version & KADM5_MASK_BITS) != \ +- KADM5_API_VERSION_MASK) \ ++ if ((api_version & KADM5_MASK_BITS) != KADM5_API_VERSION_MASK) \ + return KADM5_BAD_API_VERSION; \ +- if (srvr->api_version < KADM5_API_VERSION_2) \ +- return old_api_version; \ +- if (srvr->api_version > KADM5_API_VERSION_4) \ +- return new_api_version; \ ++ if (api_version < KADM5_API_VERSION_2) \ ++ return old_api_err; \ ++ if (api_version > KADM5_API_VERSION_4) \ ++ return new_api_err; \ ++ } ++ ++#define GENERIC_CHECK_HANDLE(handle, old_api_err, new_api_err) \ ++ { \ ++ kadm5_server_handle_t srvr = handle; \ ++ \ ++ if (srvr == NULL) \ ++ return KADM5_BAD_SERVER_HANDLE; \ ++ if (srvr->magic_number != KADM5_SERVER_HANDLE_MAGIC) \ ++ return KADM5_BAD_SERVER_HANDLE; \ ++ CHECK_VERSIONS(srvr->struct_version, srvr->api_version, \ ++ old_api_err, new_api_err); \ + } + + /* +diff --git a/src/lib/kadm5/clnt/client_init.c b/src/lib/kadm5/clnt/client_init.c +index 0aaca701f..75614bb19 100644 +--- a/src/lib/kadm5/clnt/client_init.c ++++ b/src/lib/kadm5/clnt/client_init.c +@@ -138,6 +138,36 @@ kadm5_init_with_skey(krb5_context context, char *client_name, + server_handle); + } + ++static kadm5_ret_t ++free_handle(kadm5_server_handle_t handle) ++{ ++ kadm5_ret_t ret = 0; ++ OM_uint32 minor_stat; ++ krb5_ccache ccache; ++ ++ if (handle == NULL) ++ return 0; ++ ++ if (handle->destroy_cache && handle->cache_name != NULL) { ++ ret = krb5_cc_resolve(handle->context, handle->cache_name, &ccache); ++ if (!ret) ++ ret = krb5_cc_destroy(handle->context, ccache); ++ } ++ free(handle->cache_name); ++ (void)gss_release_cred(&minor_stat, &handle->cred); ++ if (handle->clnt != NULL && handle->clnt->cl_auth != NULL) ++ AUTH_DESTROY(handle->clnt->cl_auth); ++ if (handle->clnt != NULL) ++ clnt_destroy(handle->clnt); ++ if (handle->client_socket != -1) ++ close(handle->client_socket); ++ free(handle->lhandle); ++ kadm5_free_config_params(handle->context, &handle->params); ++ free(handle); ++ ++ return ret; ++} ++ + static kadm5_ret_t + init_any(krb5_context context, char *client_name, enum init_type init_type, + char *pass, krb5_ccache ccache_in, char *service_name, +@@ -145,36 +175,34 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, + krb5_ui_4 api_version, char **db_args, void **server_handle) + { + int fd = -1; +- OM_uint32 minor_stat; + krb5_boolean iprop_enable; + int port; + rpcprog_t rpc_prog; + rpcvers_t rpc_vers; +- krb5_ccache ccache; + krb5_principal client = NULL, server = NULL; + struct timeval timeout; + +- kadm5_server_handle_t handle; ++ kadm5_server_handle_t handle = NULL; + kadm5_config_params params_local; + +- int code = 0; ++ krb5_error_code code; + generic_ret r = { 0, 0 }; + + initialize_ovk_error_table(); + initialize_ovku_error_table(); + +- if (! server_handle) { ++ if (server_handle == NULL || client_name == NULL) + return EINVAL; +- } + +- if (! (handle = malloc(sizeof(*handle)))) { +- return ENOMEM; +- } +- memset(handle, 0, sizeof(*handle)); +- if (! (handle->lhandle = malloc(sizeof(*handle)))) { +- free(handle); +- return ENOMEM; +- } ++ CHECK_VERSIONS(struct_version, api_version, KADM5_OLD_LIB_API_VERSION, ++ KADM5_NEW_LIB_API_VERSION); ++ ++ handle = k5alloc(sizeof(*handle), &code); ++ if (handle == NULL) ++ goto cleanup; ++ handle->lhandle = k5alloc(sizeof(*handle), &code); ++ if (handle->lhandle == NULL) ++ goto cleanup; + + handle->magic_number = KADM5_SERVER_HANDLE_MAGIC; + handle->struct_version = struct_version; +@@ -192,33 +220,20 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, + + handle->context = context; + +- if(client_name == NULL) { +- free(handle); +- return EINVAL; +- } +- +- /* +- * Verify the version numbers before proceeding; we can't use +- * CHECK_HANDLE because not all fields are set yet. +- */ +- GENERIC_CHECK_HANDLE(handle, KADM5_OLD_LIB_API_VERSION, +- KADM5_NEW_LIB_API_VERSION); +- + memset(¶ms_local, 0, sizeof(params_local)); + +- if ((code = kadm5_get_config_params(handle->context, 0, +- params_in, &handle->params))) { +- free(handle); +- return(code); +- } ++ code = kadm5_get_config_params(handle->context, 0, params_in, ++ &handle->params); ++ if (code) ++ goto cleanup; + + #define REQUIRED_PARAMS (KADM5_CONFIG_REALM | \ + KADM5_CONFIG_ADMIN_SERVER | \ + KADM5_CONFIG_KADMIND_PORT) + + if ((handle->params.mask & REQUIRED_PARAMS) != REQUIRED_PARAMS) { +- free(handle); +- return KADM5_MISSING_KRB5_CONF_PARAMS; ++ code = KADM5_MISSING_KRB5_CONF_PARAMS; ++ goto cleanup; + } + + /* +@@ -228,7 +243,7 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, + */ + code = krb5_parse_name(handle->context, client_name, &client); + if (code) +- goto error; ++ goto cleanup; + if (init_type == INIT_SKEY && client->realm.length == 0) + client->type = KRB5_NT_SRV_HST; + +@@ -239,7 +254,7 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, + code = get_init_creds(handle, client, init_type, pass, ccache_in, + service_name, handle->params.realm, &server); + if (code) +- goto error; ++ goto cleanup; + + /* If the service_name and client_name are iprop-centric, use the iprop + * port and RPC identifiers. */ +@@ -258,7 +273,7 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, + + code = connect_to_server(handle->params.admin_server, port, &fd); + if (code) +- goto error; ++ goto cleanup; + + handle->clnt = clnttcp_create(NULL, rpc_prog, rpc_vers, &fd, 0, 0); + if (handle->clnt == NULL) { +@@ -266,7 +281,7 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, + #ifdef DEBUG + clnt_pcreateerror("clnttcp_create"); + #endif +- goto error; ++ goto cleanup; + } + + /* Set a one-hour timeout. */ +@@ -278,10 +293,6 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, + handle->lhandle->clnt = handle->clnt; + handle->lhandle->client_socket = fd; + +- /* now that handle->clnt is set, we can check the handle */ +- if ((code = _kadm5_check_handle((void *) handle))) +- goto error; +- + /* + * The RPC connection is open; establish the GSS-API + * authentication context. +@@ -289,7 +300,7 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, + code = setup_gss(handle, params_in, + (init_type == INIT_CREDS) ? client : NULL, server); + if (code) +- goto error; ++ goto cleanup; + + /* + * Bypass the remainder of the code and return straight away +@@ -297,7 +308,8 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, + */ + if (iprop_enable) { + code = 0; +- *server_handle = (void *) handle; ++ *server_handle = handle; ++ handle = NULL; + goto cleanup; + } + +@@ -306,7 +318,7 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, + #ifdef DEBUG + clnt_perror(handle->clnt, "init_2 null resp"); + #endif +- goto error; ++ goto cleanup; + } + /* Drop down to v3 wire protocol if server does not support v4 */ + if (r.code == KADM5_NEW_SERVER_API_VERSION && +@@ -315,7 +327,7 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, + memset(&r, 0, sizeof(generic_ret)); + if (init_2(&handle->api_version, &r, handle->clnt)) { + code = KADM5_RPC_ERROR; +- goto error; ++ goto cleanup; + } + } + /* Drop down to v2 wire protocol if server does not support v3 */ +@@ -325,47 +337,21 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, + memset(&r, 0, sizeof(generic_ret)); + if (init_2(&handle->api_version, &r, handle->clnt)) { + code = KADM5_RPC_ERROR; +- goto error; ++ goto cleanup; + } + } + if (r.code) { + code = r.code; +- goto error; ++ goto cleanup; + } + +- *server_handle = (void *) handle; +- +- goto cleanup; +- +-error: +- /* +- * Note that it is illegal for this code to execute if "handle" +- * has not been allocated and initialized. I.e., don't use "goto +- * error" before the block of code at the top of the function +- * that allocates and initializes "handle". +- */ +- if (handle->destroy_cache && handle->cache_name) { +- if (krb5_cc_resolve(handle->context, +- handle->cache_name, &ccache) == 0) +- (void) krb5_cc_destroy (handle->context, ccache); +- } +- if (handle->cache_name) +- free(handle->cache_name); +- (void)gss_release_cred(&minor_stat, &handle->cred); +- if(handle->clnt && handle->clnt->cl_auth) +- AUTH_DESTROY(handle->clnt->cl_auth); +- if(handle->clnt) +- clnt_destroy(handle->clnt); +- if (fd != -1) +- close(fd); +- free(handle->lhandle); +- kadm5_free_config_params(handle->context, &handle->params); ++ *server_handle = handle; ++ handle = NULL; + + cleanup: +- krb5_free_principal(handle->context, client); +- krb5_free_principal(handle->context, server); +- if (code) +- free(handle); ++ krb5_free_principal(context, client); ++ krb5_free_principal(context, server); ++ (void)free_handle(handle); + + return code; + } +@@ -695,38 +681,8 @@ rpc_auth(kadm5_server_handle_t handle, kadm5_config_params *params_in, + kadm5_ret_t + kadm5_destroy(void *server_handle) + { +- OM_uint32 minor_stat; +- krb5_ccache ccache = NULL; +- int code = KADM5_OK; +- kadm5_server_handle_t handle = +- (kadm5_server_handle_t) server_handle; +- + CHECK_HANDLE(server_handle); +- +- if (handle->destroy_cache && handle->cache_name) { +- if ((code = krb5_cc_resolve(handle->context, +- handle->cache_name, &ccache)) == 0) +- code = krb5_cc_destroy (handle->context, ccache); +- } +- if (handle->cache_name) +- free(handle->cache_name); +- if (handle->cred) +- (void)gss_release_cred(&minor_stat, &handle->cred); +- if (handle->clnt && handle->clnt->cl_auth) +- AUTH_DESTROY(handle->clnt->cl_auth); +- if (handle->clnt) +- clnt_destroy(handle->clnt); +- if (handle->client_socket != -1) +- close(handle->client_socket); +- if (handle->lhandle) +- free (handle->lhandle); +- +- kadm5_free_config_params(handle->context, &handle->params); +- +- handle->magic_number = 0; +- free(handle); +- +- return code; ++ return free_handle(server_handle); + } + /* not supported on client */ + kadm5_ret_t kadm5_lock(void *server_handle) +diff --git a/src/lib/kadm5/srv/server_init.c b/src/lib/kadm5/srv/server_init.c +index 3adc4b57d..2c0d51efd 100644 +--- a/src/lib/kadm5/srv/server_init.c ++++ b/src/lib/kadm5/srv/server_init.c +@@ -19,23 +19,6 @@ + #include "osconf.h" + #include "iprop_hdr.h" + +-/* +- * Function check_handle +- * +- * Purpose: Check a server handle and return a com_err code if it is +- * invalid or 0 if it is valid. +- * +- * Arguments: +- * +- * handle The server handle. +- */ +- +-static int check_handle(void *handle) +-{ +- CHECK_HANDLE(handle); +- return 0; +-} +- + static int dup_db_args(kadm5_server_handle_t handle, char **db_args) + { + int count = 0; +@@ -84,6 +67,23 @@ static void free_db_args(kadm5_server_handle_t handle) + } + } + ++static void ++free_handle(kadm5_server_handle_t handle) ++{ ++ if (handle == NULL) ++ return; ++ ++ destroy_pwqual(handle); ++ k5_kadm5_hook_free_handles(handle->context, handle->hook_handles); ++ ulog_fini(handle->context); ++ krb5_db_fini(handle->context); ++ krb5_free_principal(handle->context, handle->current_caller); ++ kadm5_free_config_params(handle->context, &handle->params); ++ free(handle->lhandle); ++ free_db_args(handle); ++ free(handle); ++} ++ + kadm5_ret_t kadm5_init_with_password(krb5_context context, char *client_name, + char *pass, char *service_name, + kadm5_config_params *params, +@@ -163,8 +163,8 @@ kadm5_ret_t kadm5_init(krb5_context context, char *client_name, char *pass, + char **db_args, + void **server_handle) + { +- int ret; +- kadm5_server_handle_t handle; ++ krb5_error_code ret; ++ kadm5_server_handle_t handle = NULL; + kadm5_config_params params_local; /* for v1 compat */ + + if (! server_handle) +@@ -173,17 +173,17 @@ kadm5_ret_t kadm5_init(krb5_context context, char *client_name, char *pass, + if (! client_name) + return EINVAL; + +- if (! (handle = (kadm5_server_handle_t) malloc(sizeof *handle))) +- return ENOMEM; +- memset(handle, 0, sizeof(*handle)); ++ CHECK_VERSIONS(struct_version, api_version, KADM5_OLD_SERVER_API_VERSION, ++ KADM5_NEW_SERVER_API_VERSION); ++ ++ handle = k5alloc(sizeof(*handle), &ret); ++ if (handle == NULL) ++ goto cleanup; ++ handle->context = context; + + ret = dup_db_args(handle, db_args); +- if (ret) { +- free(handle); +- return ret; +- } +- +- handle->context = context; ++ if (ret) ++ goto cleanup; + + initialize_ovk_error_table(); + initialize_ovku_error_table(); +@@ -192,13 +192,6 @@ kadm5_ret_t kadm5_init(krb5_context context, char *client_name, char *pass, + handle->struct_version = struct_version; + handle->api_version = api_version; + +- /* +- * Verify the version numbers before proceeding; we can't use +- * CHECK_HANDLE because not all fields are set yet. +- */ +- GENERIC_CHECK_HANDLE(handle, KADM5_OLD_SERVER_API_VERSION, +- KADM5_NEW_SERVER_API_VERSION); +- + /* + * Acquire relevant profile entries. Merge values + * in params_in with values from profile, based on +@@ -208,11 +201,8 @@ kadm5_ret_t kadm5_init(krb5_context context, char *client_name, char *pass, + + ret = kadm5_get_config_params(handle->context, 1, params_in, + &handle->params); +- if (ret) { +- free_db_args(handle); +- free(handle); +- return(ret); +- } ++ if (ret) ++ goto cleanup; + + #define REQUIRED_PARAMS (KADM5_CONFIG_REALM | KADM5_CONFIG_DBNAME | \ + KADM5_CONFIG_ENCTYPE | \ +@@ -226,132 +216,69 @@ kadm5_ret_t kadm5_init(krb5_context context, char *client_name, char *pass, + KADM5_CONFIG_IPROP_PORT) + + if ((handle->params.mask & REQUIRED_PARAMS) != REQUIRED_PARAMS) { +- kadm5_free_config_params(handle->context, &handle->params); +- free_db_args(handle); +- free(handle); +- return KADM5_MISSING_CONF_PARAMS; ++ ret = KADM5_MISSING_CONF_PARAMS; ++ goto cleanup; + } + if ((handle->params.mask & KADM5_CONFIG_IPROP_ENABLED) == KADM5_CONFIG_IPROP_ENABLED + && handle->params.iprop_enabled) { + if ((handle->params.mask & IPROP_REQUIRED_PARAMS) != IPROP_REQUIRED_PARAMS) { +- kadm5_free_config_params(handle->context, &handle->params); +- free_db_args(handle); +- free(handle); +- return KADM5_MISSING_CONF_PARAMS; ++ ret = KADM5_MISSING_CONF_PARAMS; ++ goto cleanup; + } + } + + ret = krb5_set_default_realm(handle->context, handle->params.realm); +- if (ret) { +- kadm5_free_config_params(handle->context, &handle->params); +- free_db_args(handle); +- free(handle); +- return ret; +- } ++ if (ret) ++ goto cleanup; + + ret = krb5_db_open(handle->context, db_args, + KRB5_KDB_OPEN_RW | KRB5_KDB_SRV_TYPE_ADMIN); +- if (ret) { +- kadm5_free_config_params(handle->context, &handle->params); +- free_db_args(handle); +- free(handle); +- return(ret); +- } ++ if (ret) ++ goto cleanup; + +- if ((ret = krb5_parse_name(handle->context, client_name, +- &handle->current_caller))) { +- kadm5_free_config_params(handle->context, &handle->params); +- krb5_db_fini(handle->context); +- free_db_args(handle); +- free(handle); +- return ret; +- } ++ ret = krb5_parse_name(handle->context, client_name, ++ &handle->current_caller); ++ if (ret) ++ goto cleanup; + +- if (! (handle->lhandle = malloc(sizeof(*handle)))) { +- kadm5_free_config_params(handle->context, &handle->params); +- krb5_db_fini(handle->context); +- free_db_args(handle); +- free(handle); +- return ENOMEM; +- } ++ handle->lhandle = k5alloc(sizeof(*handle), &ret); ++ if (handle->lhandle == NULL) ++ goto cleanup; + *handle->lhandle = *handle; + handle->lhandle->api_version = KADM5_API_VERSION_4; + handle->lhandle->struct_version = KADM5_STRUCT_VERSION; + handle->lhandle->lhandle = handle->lhandle; + +- /* can't check the handle until current_caller is set */ +- ret = check_handle((void *) handle); +- if (ret) { +- kadm5_free_config_params(handle->context, &handle->params); +- free_db_args(handle); +- free(handle); +- return ret; +- } +- + ret = kdb_init_master(handle, handle->params.realm, + (handle->params.mask & KADM5_CONFIG_MKEY_FROM_KBD) + && handle->params.mkey_from_kbd); +- if (ret) { +- kadm5_free_config_params(handle->context, &handle->params); +- krb5_db_fini(handle->context); +- free_db_args(handle); +- free(handle); +- return ret; +- } ++ if (ret) ++ goto cleanup; + + ret = kdb_init_hist(handle, handle->params.realm); +- if (ret) { +- kadm5_free_config_params(handle->context, &handle->params); +- krb5_db_fini(handle->context); +- free_db_args(handle); +- free(handle); +- return ret; +- } ++ if (ret) ++ goto cleanup; + + ret = k5_kadm5_hook_load(context,&handle->hook_handles); +- if (ret) { +- kadm5_free_config_params(handle->context, &handle->params); +- krb5_db_fini(handle->context); +- krb5_free_principal(handle->context, handle->current_caller); +- free_db_args(handle); +- free(handle); +- return ret; +- } ++ if (ret) ++ goto cleanup; + + ret = init_pwqual(handle); +- if (ret) { +- kadm5_free_config_params(handle->context, &handle->params); +- k5_kadm5_hook_free_handles(context, handle->hook_handles); +- krb5_db_fini(handle->context); +- krb5_free_principal(handle->context, handle->current_caller); +- free_db_args(handle); +- free(handle); +- return ret; +- } ++ if (ret) ++ goto cleanup; + +- *server_handle = (void *) handle; ++ *server_handle = handle; ++ handle = NULL; + +- return KADM5_OK; ++cleanup: ++ free_handle(handle); ++ return ret; + } + + kadm5_ret_t kadm5_destroy(void *server_handle) + { +- kadm5_server_handle_t handle = server_handle; +- + CHECK_HANDLE(server_handle); +- +- destroy_pwqual(handle); +- +- k5_kadm5_hook_free_handles(handle->context, handle->hook_handles); +- ulog_fini(handle->context); +- krb5_db_fini(handle->context); +- krb5_free_principal(handle->context, handle->current_caller); +- kadm5_free_config_params(handle->context, &handle->params); +- handle->magic_number = 0; +- free(handle->lhandle); +- free_db_args(handle); +- free(handle); +- ++ free_handle(server_handle); + return KADM5_OK; + } + diff --git a/Use-asan-in-one-of-the-CI-builds.patch b/Use-asan-in-one-of-the-CI-builds.patch new file mode 100644 index 0000000..e6b1e86 --- /dev/null +++ b/Use-asan-in-one-of-the-CI-builds.patch @@ -0,0 +1,22 @@ +From 5457242ca6742ace42f1f7dbe37208752c6f26f4 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 21 Jun 2021 19:15:26 -0400 +Subject: [PATCH] Use asan in one of the CI builds + +(cherry picked from commit 7368354bcd0b58480a88b1fb81e63bd6aae7edf2) +--- + .github/workflows/build.yml | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml +index 8d1042b7b..06a35b7b9 100644 +--- a/.github/workflows/build.yml ++++ b/.github/workflows/build.yml +@@ -17,6 +17,7 @@ jobs: + os: ubuntu-18.04 + compiler: clang + makevars: CPPFLAGS=-Werror ++ configureopts: --enable-asan + - name: linux-clang-openssl + os: ubuntu-18.04 + compiler: clang diff --git a/Using-locking-in-MEMORY-krb5_cc_get_principal.patch b/Using-locking-in-MEMORY-krb5_cc_get_principal.patch new file mode 100644 index 0000000..2ae1967 --- /dev/null +++ b/Using-locking-in-MEMORY-krb5_cc_get_principal.patch @@ -0,0 +1,47 @@ +From d9a6607d47ff6449d1cad2a9a5b4d3b9b2768ddd Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sun, 20 Jun 2021 19:24:07 -0400 +Subject: [PATCH] Using locking in MEMORY krb5_cc_get_principal() + +Without locking, the principal pointer could be freed out from under +krb5_copy_principal() by another thread calling krb5_cc_initialize() +or krb5_cc_destroy(). + +ticket: 9014 (new) +tags: pullup +target_version: 1.19-next +target_version: 1.18-next + +(cherry picked from commit 1848447291c68e21311f441b0458ae53471d00d3) +--- + src/lib/krb5/ccache/cc_memory.c | 17 +++++++++++------ + 1 file changed, 11 insertions(+), 6 deletions(-) + +diff --git a/src/lib/krb5/ccache/cc_memory.c b/src/lib/krb5/ccache/cc_memory.c +index 610091a25..e4c795d25 100644 +--- a/src/lib/krb5/ccache/cc_memory.c ++++ b/src/lib/krb5/ccache/cc_memory.c +@@ -575,12 +575,17 @@ krb5_mcc_get_name (krb5_context context, krb5_ccache id) + krb5_error_code KRB5_CALLCONV + krb5_mcc_get_principal(krb5_context context, krb5_ccache id, krb5_principal *princ) + { +- krb5_mcc_data *ptr = (krb5_mcc_data *)id->data; +- if (!ptr->prin) { +- *princ = 0L; +- return KRB5_FCC_NOFILE; +- } +- return krb5_copy_principal(context, ptr->prin, princ); ++ krb5_error_code ret; ++ krb5_mcc_data *d = id->data; ++ ++ *princ = NULL; ++ k5_cc_mutex_lock(context, &d->lock); ++ if (d->prin == NULL) ++ ret = KRB5_FCC_NOFILE; ++ else ++ ret = krb5_copy_principal(context, d->prin, princ); ++ k5_cc_mutex_unlock(context, &d->lock); ++ return ret; + } + + krb5_error_code KRB5_CALLCONV diff --git a/krb5.spec b/krb5.spec index 6d2a5cb..6f8a7c8 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}11%{?dist} +Release: %{?zdpd}12%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -86,6 +86,10 @@ Patch20: Fix-kadmin-k-with-fallback-or-referral-realm.patch Patch21: Fix-softpkcs11-build-issues-with-openssl-3.0.patch Patch22: Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch Patch23: Fix-k5tls-module-for-OpenSSL-3.patch +Patch24: Fix-leaks-on-error-in-kadm5-init-functions.patch +Patch25: Clean-up-context-after-failed-open-in-libkdb5.patch +Patch26: Use-asan-in-one-of-the-CI-builds.patch +Patch27: Using-locking-in-MEMORY-krb5_cc_get_principal.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -648,6 +652,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jun 28 2021 Robbie Harwood - 1.19.1-12 +- MEMORY locking fix and static analysis pullup + * Mon Jun 21 2021 Robbie Harwood - 1.19.1-11 - Add the backward-compatible parts of openssl3 support From af96dc0c6c08934825f02525af71ad889d9f3042 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 1 Jul 2021 13:17:47 -0400 Subject: [PATCH 243/304] Fix use-after-free during krad remote_shutdown() --- ...up-gssapi_krb5-ccache-name-functions.patch | 193 ++++++++++++++++++ ...ter-free-during-krad-remote_shutdown.patch | 38 ++++ krb5.spec | 7 +- 3 files changed, 237 insertions(+), 1 deletion(-) create mode 100644 Clean-up-gssapi_krb5-ccache-name-functions.patch create mode 100644 Fix-use-after-free-during-krad-remote_shutdown.patch diff --git a/Clean-up-gssapi_krb5-ccache-name-functions.patch b/Clean-up-gssapi_krb5-ccache-name-functions.patch new file mode 100644 index 0000000..32f3fc4 --- /dev/null +++ b/Clean-up-gssapi_krb5-ccache-name-functions.patch @@ -0,0 +1,193 @@ +From 8285f21d40e30477436128ae2c28403cd5575074 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 26 May 2021 18:22:10 -0400 +Subject: [PATCH] Clean up gssapi_krb5 ccache name functions + +Modernize kg_get_ccache_name() and kg_get_ccache_name(). Drop +unnecessary use of const in kg_get_ccache_name() so that its return +value can be properly freed. Fixes some static analyzer false +positives. + +(cherry picked from commit f573f7f8ee5269103a0492d6521a3242c5ffb63b) +--- + src/lib/gssapi/krb5/gssapiP_krb5.h | 3 +- + src/lib/gssapi/krb5/gssapi_krb5.c | 47 ++++++++-------------- + src/lib/gssapi/krb5/set_ccache.c | 64 ++++++++++++------------------ + 3 files changed, 42 insertions(+), 72 deletions(-) + +diff --git a/src/lib/gssapi/krb5/gssapiP_krb5.h b/src/lib/gssapi/krb5/gssapiP_krb5.h +index fd7abbd77..88d41130a 100644 +--- a/src/lib/gssapi/krb5/gssapiP_krb5.h ++++ b/src/lib/gssapi/krb5/gssapiP_krb5.h +@@ -380,8 +380,7 @@ OM_uint32 kg_sync_ccache_name (krb5_context context, OM_uint32 *minor_status); + OM_uint32 kg_caller_provided_ccache_name (OM_uint32 *minor_status, + int *out_caller_provided_name); + +-OM_uint32 kg_get_ccache_name (OM_uint32 *minor_status, +- const char **out_name); ++OM_uint32 kg_get_ccache_name (OM_uint32 *minor_status, char **out_name); + + OM_uint32 kg_set_ccache_name (OM_uint32 *minor_status, + const char *name); +diff --git a/src/lib/gssapi/krb5/gssapi_krb5.c b/src/lib/gssapi/krb5/gssapi_krb5.c +index 46aa9b7a5..9915a8bb5 100644 +--- a/src/lib/gssapi/krb5/gssapi_krb5.c ++++ b/src/lib/gssapi/krb5/gssapi_krb5.c +@@ -253,46 +253,31 @@ kg_caller_provided_ccache_name (OM_uint32 *minor_status, + } + + OM_uint32 +-kg_get_ccache_name (OM_uint32 *minor_status, const char **out_name) ++kg_get_ccache_name(OM_uint32 *minor_status, char **out_name) + { +- const char *name = NULL; +- OM_uint32 err = 0; + char *kg_ccache_name; ++ const char *def_name; ++ OM_uint32 err; ++ krb5_context context; ++ ++ *out_name = NULL; + + kg_ccache_name = k5_getspecific(K5_KEY_GSS_KRB5_CCACHE_NAME); +- + if (kg_ccache_name != NULL) { +- name = strdup(kg_ccache_name); +- if (name == NULL) +- err = ENOMEM; ++ *out_name = strdup(kg_ccache_name); ++ err = (*out_name == NULL) ? ENOMEM : 0; + } else { +- krb5_context context = NULL; +- +- /* Reset the context default ccache (see text above), and then +- retrieve it. */ ++ /* Use the default ccache name. */ + err = krb5_gss_init_context(&context); +- if (!err) +- err = krb5_cc_set_default_name (context, NULL); +- if (!err) { +- name = krb5_cc_default_name(context); +- if (name) { +- name = strdup(name); +- if (name == NULL) +- err = ENOMEM; +- } +- } +- if (err && context) +- save_error_info(err, context); +- if (context) +- krb5_free_context(context); +- } +- +- if (!err) { +- if (out_name) { +- *out_name = name; +- } ++ if (err) ++ goto cleanup; ++ def_name = krb5_cc_default_name(context); ++ *out_name = (def_name != NULL) ? strdup(def_name) : NULL; ++ err = (*out_name == NULL) ? ENOMEM : 0; ++ krb5_free_context(context); + } + ++cleanup: + *minor_status = err; + return (*minor_status == 0) ? GSS_S_COMPLETE : GSS_S_FAILURE; + } +diff --git a/src/lib/gssapi/krb5/set_ccache.c b/src/lib/gssapi/krb5/set_ccache.c +index 8acf3ec90..91c3462be 100644 +--- a/src/lib/gssapi/krb5/set_ccache.c ++++ b/src/lib/gssapi/krb5/set_ccache.c +@@ -26,7 +26,7 @@ + + /* + * Set ccache name used by gssapi, and optionally obtain old ccache +- * name. Caller should not free returned name. ++ * name. Caller must not free returned name. + */ + + #include +@@ -38,11 +38,9 @@ gss_krb5int_ccache_name(OM_uint32 *minor_status, + const gss_OID desired_object, + const gss_buffer_t value) + { +- char *old_name = NULL; + OM_uint32 err = 0; +- OM_uint32 minor = 0; +- char *gss_out_name; + struct krb5_gss_ccache_name_req *req; ++ char *old_name, *cur_name = NULL; + + err = gss_krb5int_initialize_library(); + if (err) { +@@ -57,45 +55,33 @@ gss_krb5int_ccache_name(OM_uint32 *minor_status, + + req = (struct krb5_gss_ccache_name_req *)value->value; + +- gss_out_name = k5_getspecific(K5_KEY_GSS_KRB5_SET_CCACHE_OLD_NAME); ++ /* Our job is simple if the caller doesn't want the current name. */ ++ if (req->out_name == NULL) ++ return kg_set_ccache_name(minor_status, req->name); + +- if (req->out_name) { +- const char *tmp_name = NULL; ++ /* Fetch the current name and change it. */ ++ kg_get_ccache_name(&err, &cur_name); ++ if (err) ++ goto cleanup; ++ kg_set_ccache_name(&err, req->name); ++ if (err) ++ goto cleanup; + +- if (!err) { +- kg_get_ccache_name (&err, &tmp_name); +- } +- if (!err) { +- old_name = gss_out_name; +- gss_out_name = (char *)tmp_name; +- } +- } +- /* If out_name was NULL, we keep the same gss_out_name value, and +- don't free up any storage (leave old_name NULL). */ ++ /* Store the current name in a thread-specific variable. Free that ++ * variable's previous contents. */ ++ old_name = k5_getspecific(K5_KEY_GSS_KRB5_SET_CCACHE_OLD_NAME); ++ err = k5_setspecific(K5_KEY_GSS_KRB5_SET_CCACHE_OLD_NAME, cur_name); ++ if (err) ++ goto cleanup; ++ free(old_name); + +- if (!err) +- kg_set_ccache_name (&err, req->name); +- +- minor = k5_setspecific(K5_KEY_GSS_KRB5_SET_CCACHE_OLD_NAME, gss_out_name); +- if (minor) { +- /* Um. Now what? */ +- if (err == 0) { +- err = minor; +- } +- free(gss_out_name); +- gss_out_name = NULL; +- } +- +- if (!err) { +- if (req->out_name) { +- *(req->out_name) = gss_out_name; +- } +- } +- +- if (old_name != NULL) { +- free (old_name); +- } ++ /* Give the caller an alias to the stored value. */ ++ *req->out_name = cur_name; ++ cur_name = NULL; ++ err = 0; + ++cleanup: ++ free(cur_name); + *minor_status = err; + return (*minor_status == 0) ? GSS_S_COMPLETE : GSS_S_FAILURE; + } diff --git a/Fix-use-after-free-during-krad-remote_shutdown.patch b/Fix-use-after-free-during-krad-remote_shutdown.patch new file mode 100644 index 0000000..fb9c56d --- /dev/null +++ b/Fix-use-after-free-during-krad-remote_shutdown.patch @@ -0,0 +1,38 @@ +From bcd7b5e8aa0d325e9b178d9be3459759d39b631e Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Sat, 29 May 2021 13:25:59 -0400 +Subject: [PATCH] Fix use-after-free during krad remote_shutdown() + +Since elements of the queue can be removed on out-of-memory errors, +the correct call is K5_TAILQ_FOREACH_SAFE, not K5_TAILQ_FOREACH. +Reported by Coverity. + +ticket: 9015 (new) +tags: pullup +target_version: 1.19-next +target_version: 1.18-next + +(cherry picked from commit 8c88defb16b34937d5b72b4832c854ce2dbe32d1) +--- + src/lib/krad/remote.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c +index eca432424..7b5804b1d 100644 +--- a/src/lib/krad/remote.c ++++ b/src/lib/krad/remote.c +@@ -220,12 +220,12 @@ static void + remote_shutdown(krad_remote *rr) + { + krb5_error_code retval; +- request *r; ++ request *r, *next; + + remote_disconnect(rr); + + /* Start timers for all unsent packets. */ +- K5_TAILQ_FOREACH(r, &rr->list, list) { ++ K5_TAILQ_FOREACH_SAFE(r, &rr->list, list, next) { + if (r->timer == NULL) { + retval = request_start_timer(r, rr->vctx); + if (retval != 0) diff --git a/krb5.spec b/krb5.spec index 6f8a7c8..f1f9360 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}12%{?dist} +Release: %{?zdpd}13%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -90,6 +90,8 @@ Patch24: Fix-leaks-on-error-in-kadm5-init-functions.patch Patch25: Clean-up-context-after-failed-open-in-libkdb5.patch Patch26: Use-asan-in-one-of-the-CI-builds.patch Patch27: Using-locking-in-MEMORY-krb5_cc_get_principal.patch +Patch28: Fix-use-after-free-during-krad-remote_shutdown.patch +Patch29: Clean-up-gssapi_krb5-ccache-name-functions.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -652,6 +654,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jul 01 2021 Robbie Harwood - 1.19.1-13 +- Fix use-after-free during krad remote_shutdown() + * Mon Jun 28 2021 Robbie Harwood - 1.19.1-12 - MEMORY locking fix and static analysis pullup From 6a2eeb966621c96be097712e190a22cc63bcba7c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 12 Jul 2021 13:11:12 -0400 Subject: [PATCH 244/304] Fix KDC null deref on bad encrypted challenge (CVE-2021-36222) --- ...ull-deref-on-bad-encrypted-challenge.patch | 113 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 118 insertions(+), 1 deletion(-) create mode 100644 Fix-KDC-null-deref-on-bad-encrypted-challenge.patch diff --git a/Fix-KDC-null-deref-on-bad-encrypted-challenge.patch b/Fix-KDC-null-deref-on-bad-encrypted-challenge.patch new file mode 100644 index 0000000..4a7c7ae --- /dev/null +++ b/Fix-KDC-null-deref-on-bad-encrypted-challenge.patch @@ -0,0 +1,113 @@ +From 791211b00a53b394376d096c881b725ee739a936 Mon Sep 17 00:00:00 2001 +From: Joseph Sutton +Date: Wed, 7 Jul 2021 11:47:44 +1200 +Subject: [PATCH] Fix KDC null deref on bad encrypted challenge + +The function ec_verify() in src/kdc/kdc_preauth_ec.c contains a check +to avoid further processing if the armor key is NULL. However, this +check is bypassed by a call to k5memdup0() which overwrites retval +with 0 if the allocation succeeds. If the armor key is NULL, a call +to krb5_c_fx_cf2_simple() will then dereference it, resulting in a +crash. Add a check before the k5memdup0() call to avoid overwriting +retval. + +CVE-2021-36222: + +In MIT krb5 releases 1.16 and later, an unauthenticated attacker can +cause a null dereference in the KDC by sending a request containing a +PA-ENCRYPTED-CHALLENGE padata element without using FAST. + +[ghudson@mit.edu: trimmed patch; added test case; edited commit +message] + +ticket: 9007 (new) +tags: pullup +target_version: 1.19-next +target_version: 1.18-next + +(cherry picked from commit fc98f520caefff2e5ee9a0026fdf5109944b3562) +--- + src/kdc/kdc_preauth_ec.c | 3 ++- + src/tests/Makefile.in | 1 + + src/tests/t_cve-2021-36222.py | 46 +++++++++++++++++++++++++++++++++++ + 3 files changed, 49 insertions(+), 1 deletion(-) + create mode 100644 src/tests/t_cve-2021-36222.py + +diff --git a/src/kdc/kdc_preauth_ec.c b/src/kdc/kdc_preauth_ec.c +index 7e636b3f9..43a9902cc 100644 +--- a/src/kdc/kdc_preauth_ec.c ++++ b/src/kdc/kdc_preauth_ec.c +@@ -87,7 +87,8 @@ ec_verify(krb5_context context, krb5_data *req_pkt, krb5_kdc_req *request, + } + + /* Check for a configured FAST ec auth indicator. */ +- realmstr = k5memdup0(realm.data, realm.length, &retval); ++ if (retval == 0) ++ realmstr = k5memdup0(realm.data, realm.length, &retval); + if (realmstr != NULL) + retval = profile_get_string(context->profile, KRB5_CONF_REALMS, + realmstr, +diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in +index ab416cc5f..20f27d748 100644 +--- a/src/tests/Makefile.in ++++ b/src/tests/Makefile.in +@@ -159,6 +159,7 @@ check-pytests: unlockiter s4u2self + $(RUNPYTEST) $(srcdir)/t_cve-2012-1015.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_cve-2013-1416.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/t_cve-2013-1417.py $(PYTESTFLAGS) ++ $(RUNPYTEST) $(srcdir)/t_cve-2021-36222.py $(PYTESTFLAGS) + $(RM) au.log + $(RUNPYTEST) $(srcdir)/t_audit.py $(PYTESTFLAGS) + $(RUNPYTEST) $(srcdir)/jsonwalker.py -d $(srcdir)/au_dict.json \ +diff --git a/src/tests/t_cve-2021-36222.py b/src/tests/t_cve-2021-36222.py +new file mode 100644 +index 000000000..57e04993b +--- /dev/null ++++ b/src/tests/t_cve-2021-36222.py +@@ -0,0 +1,46 @@ ++import socket ++from k5test import * ++ ++realm = K5Realm() ++ ++# CVE-2021-36222 KDC null dereference on encrypted challenge preauth ++# without FAST ++ ++s = socket.socket(socket.AF_INET, socket.SOCK_DGRAM) ++a = (hostname, realm.portbase) ++ ++m = ('6A81A0' '30819D' # [APPLICATION 10] SEQUENCE ++ 'A103' '0201' '05' # [1] pvno = 5 ++ 'A203' '0201' '0A' # [2] msg-type = 10 ++ 'A30E' '300C' # [3] padata = SEQUENCE OF ++ '300A' # SEQUENCE ++ 'A104' '0202' '008A' # [1] padata-type = PA-ENCRYPTED-CHALLENGE ++ 'A202' '0400' # [2] padata-value = "" ++ 'A48180' '307E' # [4] req-body = SEQUENCE ++ 'A007' '0305' '0000000000' # [0] kdc-options = 0 ++ 'A120' '301E' # [1] cname = SEQUENCE ++ 'A003' '0201' '01' # [0] name-type = NT-PRINCIPAL ++ 'A117' '3015' # [1] name-string = SEQUENCE-OF ++ '1B06' '6B7262746774' # krbtgt ++ '1B0B' '4B5242544553542E434F4D' ++ # KRBTEST.COM ++ 'A20D' '1B0B' '4B5242544553542E434F4D' ++ # [2] realm = KRBTEST.COM ++ 'A320' '301E' # [3] sname = SEQUENCE ++ 'A003' '0201' '01' # [0] name-type = NT-PRINCIPAL ++ 'A117' '3015' # [1] name-string = SEQUENCE-OF ++ '1B06' '6B7262746774' # krbtgt ++ '1B0B' '4B5242544553542E434F4D' ++ # KRBTEST.COM ++ 'A511' '180F' '31393934303631303036303331375A' ++ # [5] till = 19940610060317Z ++ 'A703' '0201' '00' # [7] nonce = 0 ++ 'A808' '3006' # [8] etype = SEQUENCE OF ++ '020112' '020111') # aes256-cts aes128-cts ++ ++s.sendto(bytes.fromhex(m), a) ++ ++# Make sure kinit still works. ++realm.kinit(realm.user_princ, password('user')) ++ ++success('CVE-2021-36222 regression test') diff --git a/krb5.spec b/krb5.spec index f1f9360..48ff4fb 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}13%{?dist} +Release: %{?zdpd}14%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -92,6 +92,7 @@ Patch26: Use-asan-in-one-of-the-CI-builds.patch Patch27: Using-locking-in-MEMORY-krb5_cc_get_principal.patch Patch28: Fix-use-after-free-during-krad-remote_shutdown.patch Patch29: Clean-up-gssapi_krb5-ccache-name-functions.patch +Patch30: Fix-KDC-null-deref-on-bad-encrypted-challenge.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -654,6 +655,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jul 12 2021 Robbie Harwood - 1.19.1-14 +- Fix KDC null deref on bad encrypted challenge (CVE-2021-36222) + * Thu Jul 01 2021 Robbie Harwood - 1.19.1-13 - Fix use-after-free during krad remote_shutdown() From 2484569caa84eada42a9de64783cc56e89e1515d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 21 Jul 2021 12:44:26 -0400 Subject: [PATCH 245/304] Fix defcred leak in krb5 gss_inquire_cred() --- ...efcred-leak-in-krb5-gss_inquire_cred.patch | 85 +++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 90 insertions(+), 1 deletion(-) create mode 100644 Fix-defcred-leak-in-krb5-gss_inquire_cred.patch diff --git a/Fix-defcred-leak-in-krb5-gss_inquire_cred.patch b/Fix-defcred-leak-in-krb5-gss_inquire_cred.patch new file mode 100644 index 0000000..9b11bc7 --- /dev/null +++ b/Fix-defcred-leak-in-krb5-gss_inquire_cred.patch @@ -0,0 +1,85 @@ +From 7e6cdffd47559be61a8c26c4ed3c500c536d5368 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 16 Jul 2021 13:39:39 -0400 +Subject: [PATCH] Fix defcred leak in krb5 gss_inquire_cred() +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Commit 1cd2821c19b2b95e39d5fc2f451a035585a40fa5 altered the memory +management of krb5_gss_inquire_cred(), introducing defcred to act as +an owner pointer when the function must acquire a default credential. +The commit neglected to update the code to release the default cred +along the successful path. The old code does not trigger because +cred_handle is now reassigned, so the default credential is leaked. + +Unify the success and failure cleanup for this function so that +defcred is properly released on success. + +Reported by Pavel Březina. + +ticket: 9016 +tags: pullup +target_version: 1.19-next +target_version: 1.18-next + +(cherry picked from commit 593e16448e1af23eef74689afe06a7bcc86e79c7) +--- + src/lib/gssapi/krb5/inq_cred.c | 16 ++++++---------- + 1 file changed, 6 insertions(+), 10 deletions(-) + +diff --git a/src/lib/gssapi/krb5/inq_cred.c b/src/lib/gssapi/krb5/inq_cred.c +index a8f254110..bb63b726c 100644 +--- a/src/lib/gssapi/krb5/inq_cred.c ++++ b/src/lib/gssapi/krb5/inq_cred.c +@@ -127,7 +127,7 @@ krb5_gss_inquire_cred(minor_status, cred_handle, name, lifetime_ret, + if ((code = krb5_timeofday(context, &now))) { + *minor_status = code; + ret = GSS_S_FAILURE; +- goto fail; ++ goto cleanup; + } + + if (cred->expire != 0) { +@@ -158,7 +158,7 @@ krb5_gss_inquire_cred(minor_status, cred_handle, name, lifetime_ret, + *minor_status = code; + save_error_info(*minor_status, context); + ret = GSS_S_FAILURE; +- goto fail; ++ goto cleanup; + } + } + +@@ -174,7 +174,7 @@ krb5_gss_inquire_cred(minor_status, cred_handle, name, lifetime_ret, + if (ret_name) + kg_release_name(context, &ret_name); + /* *minor_status set above */ +- goto fail; ++ goto cleanup; + } + } + +@@ -190,20 +190,16 @@ krb5_gss_inquire_cred(minor_status, cred_handle, name, lifetime_ret, + + if (cred_usage) + *cred_usage = cred->usage; +- k5_mutex_unlock(&cred->lock); + + if (mechanisms) { + *mechanisms = mechs; + mechs = GSS_C_NO_OID_SET; + } + +- if (cred_handle == GSS_C_NO_CREDENTIAL) +- krb5_gss_release_cred(minor_status, (gss_cred_id_t *)&cred); +- +- krb5_free_context(context); + *minor_status = 0; +- return((lifetime == 0)?GSS_S_CREDENTIALS_EXPIRED:GSS_S_COMPLETE); +-fail: ++ ret = (lifetime == 0) ? GSS_S_CREDENTIALS_EXPIRED : GSS_S_COMPLETE; ++ ++cleanup: + k5_mutex_unlock(&cred->lock); + krb5_gss_release_cred(&tmpmin, &defcred); + krb5_free_context(context); diff --git a/krb5.spec b/krb5.spec index 48ff4fb..d27bf68 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.1 -Release: %{?zdpd}14%{?dist} +Release: %{?zdpd}15%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -93,6 +93,7 @@ Patch27: Using-locking-in-MEMORY-krb5_cc_get_principal.patch Patch28: Fix-use-after-free-during-krad-remote_shutdown.patch Patch29: Clean-up-gssapi_krb5-ccache-name-functions.patch Patch30: Fix-KDC-null-deref-on-bad-encrypted-challenge.patch +Patch31: Fix-defcred-leak-in-krb5-gss_inquire_cred.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -655,6 +656,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Jul 21 2021 Robbie Harwood - 1.19.1-15 +- Fix defcred leak in krb5 gss_inquire_cred() + * Mon Jul 12 2021 Robbie Harwood - 1.19.1-14 - Fix KDC null deref on bad encrypted challenge (CVE-2021-36222) From c4016b4e4cb2510246b6bbe186acd5784592e9ff Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 26 Jul 2021 14:49:39 -0400 Subject: [PATCH 246/304] New upstream version (1.19.2) --- Add-APIs-for-marshalling-credentials.patch | 2 +- ...P_GET_CRED_LIST-for-faster-iteration.patch | 2 +- ...canonicalization-helper-to-k5test.py.patch | 2 +- ...ith-keytab-to-defer-canonicalization.patch | 2 +- ...context-after-failed-open-in-libkdb5.patch | 2 +- ...up-gssapi_krb5-ccache-name-functions.patch | 2 +- ...CM-flag-transmission-for-remove_cred.patch | 2 +- Fix-KCM-retrieval-support-for-sssd.patch | 2 +- ...ull-deref-on-bad-encrypted-challenge.patch | 113 ------------- ...efcred-leak-in-krb5-gss_inquire_cred.patch | 85 ---------- Fix-doc-build-for-Sphinx-4.0.patch | 152 ------------------ Fix-k5tls-module-for-OpenSSL-3.patch | 2 +- ...in-k-with-fallback-or-referral-realm.patch | 2 +- ...aks-on-error-in-kadm5-init-functions.patch | 2 +- ...pkcs11-build-issues-with-openssl-3.0.patch | 2 +- ...incipal-realm-canonicalization-cases.patch | 2 +- ...ter-free-during-krad-remote_shutdown.patch | 38 ----- ...teration-fallback-work-with-sssd-kcm.patch | 2 +- ...dejagnu-kadmin-tests-to-Python-tests.patch | 4 +- ...ecated-OpenSSL-calls-from-softpkcs11.patch | 2 +- Support-host-based-GSS-initiator-names.patch | 2 +- Use-KCM_OP_RETRIEVE-in-KCM-client.patch | 2 +- Use-asan-in-one-of-the-CI-builds.patch | 2 +- ...king-in-MEMORY-krb5_cc_get_principal.patch | 47 ------ ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 4 +- downstream-Remove-3des-support.patch | 10 +- downstream-SELinux-integration.patch | 2 +- ...ackported-version-of-OpenSSL-3-KDF-i.patch | 2 +- downstream-fix-debuginfo-with-y.tab.c.patch | 2 +- downstream-ksu-pam-integration.patch | 2 +- downstream-netlib-and-dns.patch | 2 +- krb5.spec | 12 +- 32 files changed, 37 insertions(+), 474 deletions(-) delete mode 100644 Fix-KDC-null-deref-on-bad-encrypted-challenge.patch delete mode 100644 Fix-defcred-leak-in-krb5-gss_inquire_cred.patch delete mode 100644 Fix-doc-build-for-Sphinx-4.0.patch delete mode 100644 Fix-use-after-free-during-krad-remote_shutdown.patch delete mode 100644 Using-locking-in-MEMORY-krb5_cc_get_principal.patch diff --git a/Add-APIs-for-marshalling-credentials.patch b/Add-APIs-for-marshalling-credentials.patch index da613e9..8578721 100644 --- a/Add-APIs-for-marshalling-credentials.patch +++ b/Add-APIs-for-marshalling-credentials.patch @@ -1,4 +1,4 @@ -From c1fe1c8fa3df7f50c7e28d52263d0d24afb4b3a1 Mon Sep 17 00:00:00 2001 +From 3a99832252755cf7e5fef2bd824459cea3eb823e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 14 Jan 2021 18:13:09 -0500 Subject: [PATCH] Add APIs for marshalling credentials diff --git a/Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch b/Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch index 060b039..455e3e0 100644 --- a/Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch +++ b/Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch @@ -1,4 +1,4 @@ -From a0ee8b02e56c65e5dcd569caed0e151cef004ef4 Mon Sep 17 00:00:00 2001 +From 8772d8f47b7460a0eef48366881483fd9b3acfd3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Pavel=20B=C5=99ezina?= Date: Thu, 11 Feb 2021 15:33:10 +0100 Subject: [PATCH] Add KCM_OP_GET_CRED_LIST for faster iteration diff --git a/Add-hostname-canonicalization-helper-to-k5test.py.patch b/Add-hostname-canonicalization-helper-to-k5test.py.patch index 75c3e87..58179a2 100644 --- a/Add-hostname-canonicalization-helper-to-k5test.py.patch +++ b/Add-hostname-canonicalization-helper-to-k5test.py.patch @@ -1,4 +1,4 @@ -From 3e78bc5d48513fe38f3bc4228b12abcdc0733ee2 Mon Sep 17 00:00:00 2001 +From e88f0319427cee7245fb05c97a25473297c9d2d6 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 15 Jan 2021 14:43:34 -0500 Subject: [PATCH] Add hostname canonicalization helper to k5test.py diff --git a/Allow-kinit-with-keytab-to-defer-canonicalization.patch b/Allow-kinit-with-keytab-to-defer-canonicalization.patch index 9315f66..eee7d1d 100644 --- a/Allow-kinit-with-keytab-to-defer-canonicalization.patch +++ b/Allow-kinit-with-keytab-to-defer-canonicalization.patch @@ -1,4 +1,4 @@ -From 090c7319652466339e3e6482bdd1b5a294638dff Mon Sep 17 00:00:00 2001 +From fb4d9fa851b1d0d3375556d1cdc1fce72176df1e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 3 Jun 2021 16:03:07 -0400 Subject: [PATCH] Allow kinit with keytab to defer canonicalization diff --git a/Clean-up-context-after-failed-open-in-libkdb5.patch b/Clean-up-context-after-failed-open-in-libkdb5.patch index a892a14..fca6a71 100644 --- a/Clean-up-context-after-failed-open-in-libkdb5.patch +++ b/Clean-up-context-after-failed-open-in-libkdb5.patch @@ -1,4 +1,4 @@ -From 78c03a9b5ef3e3f894bea11c89e575b9bb4d1b0f Mon Sep 17 00:00:00 2001 +From 95547c12b39e62df55cef05cae890302834b7f98 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 23 Jun 2021 16:57:39 -0400 Subject: [PATCH] Clean up context after failed open in libkdb5 diff --git a/Clean-up-gssapi_krb5-ccache-name-functions.patch b/Clean-up-gssapi_krb5-ccache-name-functions.patch index 32f3fc4..207f186 100644 --- a/Clean-up-gssapi_krb5-ccache-name-functions.patch +++ b/Clean-up-gssapi_krb5-ccache-name-functions.patch @@ -1,4 +1,4 @@ -From 8285f21d40e30477436128ae2c28403cd5575074 Mon Sep 17 00:00:00 2001 +From 5e5ea8e8345c8b2f3254b0d346b8e0de0df3a696 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 26 May 2021 18:22:10 -0400 Subject: [PATCH] Clean up gssapi_krb5 ccache name functions diff --git a/Fix-KCM-flag-transmission-for-remove_cred.patch b/Fix-KCM-flag-transmission-for-remove_cred.patch index 951be10..77c383e 100644 --- a/Fix-KCM-flag-transmission-for-remove_cred.patch +++ b/Fix-KCM-flag-transmission-for-remove_cred.patch @@ -1,4 +1,4 @@ -From 04f0de4420508161ce439f262f2761ff51a07ab0 Mon Sep 17 00:00:00 2001 +From 1528c264d0e1eebff34132c01f4f770f01f1d1c2 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 29 Mar 2021 14:32:56 -0400 Subject: [PATCH] Fix KCM flag transmission for remove_cred diff --git a/Fix-KCM-retrieval-support-for-sssd.patch b/Fix-KCM-retrieval-support-for-sssd.patch index 5fb7c2b..9c09507 100644 --- a/Fix-KCM-retrieval-support-for-sssd.patch +++ b/Fix-KCM-retrieval-support-for-sssd.patch @@ -1,4 +1,4 @@ -From a5b2cff51808cd86fe8195e7ac074ecd25c3344d Mon Sep 17 00:00:00 2001 +From 43be8fba5301d08fc4d5ddef14f8ae3d9655b0ba Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 11 May 2021 14:04:07 -0400 Subject: [PATCH] Fix KCM retrieval support for sssd diff --git a/Fix-KDC-null-deref-on-bad-encrypted-challenge.patch b/Fix-KDC-null-deref-on-bad-encrypted-challenge.patch deleted file mode 100644 index 4a7c7ae..0000000 --- a/Fix-KDC-null-deref-on-bad-encrypted-challenge.patch +++ /dev/null @@ -1,113 +0,0 @@ -From 791211b00a53b394376d096c881b725ee739a936 Mon Sep 17 00:00:00 2001 -From: Joseph Sutton -Date: Wed, 7 Jul 2021 11:47:44 +1200 -Subject: [PATCH] Fix KDC null deref on bad encrypted challenge - -The function ec_verify() in src/kdc/kdc_preauth_ec.c contains a check -to avoid further processing if the armor key is NULL. However, this -check is bypassed by a call to k5memdup0() which overwrites retval -with 0 if the allocation succeeds. If the armor key is NULL, a call -to krb5_c_fx_cf2_simple() will then dereference it, resulting in a -crash. Add a check before the k5memdup0() call to avoid overwriting -retval. - -CVE-2021-36222: - -In MIT krb5 releases 1.16 and later, an unauthenticated attacker can -cause a null dereference in the KDC by sending a request containing a -PA-ENCRYPTED-CHALLENGE padata element without using FAST. - -[ghudson@mit.edu: trimmed patch; added test case; edited commit -message] - -ticket: 9007 (new) -tags: pullup -target_version: 1.19-next -target_version: 1.18-next - -(cherry picked from commit fc98f520caefff2e5ee9a0026fdf5109944b3562) ---- - src/kdc/kdc_preauth_ec.c | 3 ++- - src/tests/Makefile.in | 1 + - src/tests/t_cve-2021-36222.py | 46 +++++++++++++++++++++++++++++++++++ - 3 files changed, 49 insertions(+), 1 deletion(-) - create mode 100644 src/tests/t_cve-2021-36222.py - -diff --git a/src/kdc/kdc_preauth_ec.c b/src/kdc/kdc_preauth_ec.c -index 7e636b3f9..43a9902cc 100644 ---- a/src/kdc/kdc_preauth_ec.c -+++ b/src/kdc/kdc_preauth_ec.c -@@ -87,7 +87,8 @@ ec_verify(krb5_context context, krb5_data *req_pkt, krb5_kdc_req *request, - } - - /* Check for a configured FAST ec auth indicator. */ -- realmstr = k5memdup0(realm.data, realm.length, &retval); -+ if (retval == 0) -+ realmstr = k5memdup0(realm.data, realm.length, &retval); - if (realmstr != NULL) - retval = profile_get_string(context->profile, KRB5_CONF_REALMS, - realmstr, -diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in -index ab416cc5f..20f27d748 100644 ---- a/src/tests/Makefile.in -+++ b/src/tests/Makefile.in -@@ -159,6 +159,7 @@ check-pytests: unlockiter s4u2self - $(RUNPYTEST) $(srcdir)/t_cve-2012-1015.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_cve-2013-1416.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_cve-2013-1417.py $(PYTESTFLAGS) -+ $(RUNPYTEST) $(srcdir)/t_cve-2021-36222.py $(PYTESTFLAGS) - $(RM) au.log - $(RUNPYTEST) $(srcdir)/t_audit.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/jsonwalker.py -d $(srcdir)/au_dict.json \ -diff --git a/src/tests/t_cve-2021-36222.py b/src/tests/t_cve-2021-36222.py -new file mode 100644 -index 000000000..57e04993b ---- /dev/null -+++ b/src/tests/t_cve-2021-36222.py -@@ -0,0 +1,46 @@ -+import socket -+from k5test import * -+ -+realm = K5Realm() -+ -+# CVE-2021-36222 KDC null dereference on encrypted challenge preauth -+# without FAST -+ -+s = socket.socket(socket.AF_INET, socket.SOCK_DGRAM) -+a = (hostname, realm.portbase) -+ -+m = ('6A81A0' '30819D' # [APPLICATION 10] SEQUENCE -+ 'A103' '0201' '05' # [1] pvno = 5 -+ 'A203' '0201' '0A' # [2] msg-type = 10 -+ 'A30E' '300C' # [3] padata = SEQUENCE OF -+ '300A' # SEQUENCE -+ 'A104' '0202' '008A' # [1] padata-type = PA-ENCRYPTED-CHALLENGE -+ 'A202' '0400' # [2] padata-value = "" -+ 'A48180' '307E' # [4] req-body = SEQUENCE -+ 'A007' '0305' '0000000000' # [0] kdc-options = 0 -+ 'A120' '301E' # [1] cname = SEQUENCE -+ 'A003' '0201' '01' # [0] name-type = NT-PRINCIPAL -+ 'A117' '3015' # [1] name-string = SEQUENCE-OF -+ '1B06' '6B7262746774' # krbtgt -+ '1B0B' '4B5242544553542E434F4D' -+ # KRBTEST.COM -+ 'A20D' '1B0B' '4B5242544553542E434F4D' -+ # [2] realm = KRBTEST.COM -+ 'A320' '301E' # [3] sname = SEQUENCE -+ 'A003' '0201' '01' # [0] name-type = NT-PRINCIPAL -+ 'A117' '3015' # [1] name-string = SEQUENCE-OF -+ '1B06' '6B7262746774' # krbtgt -+ '1B0B' '4B5242544553542E434F4D' -+ # KRBTEST.COM -+ 'A511' '180F' '31393934303631303036303331375A' -+ # [5] till = 19940610060317Z -+ 'A703' '0201' '00' # [7] nonce = 0 -+ 'A808' '3006' # [8] etype = SEQUENCE OF -+ '020112' '020111') # aes256-cts aes128-cts -+ -+s.sendto(bytes.fromhex(m), a) -+ -+# Make sure kinit still works. -+realm.kinit(realm.user_princ, password('user')) -+ -+success('CVE-2021-36222 regression test') diff --git a/Fix-defcred-leak-in-krb5-gss_inquire_cred.patch b/Fix-defcred-leak-in-krb5-gss_inquire_cred.patch deleted file mode 100644 index 9b11bc7..0000000 --- a/Fix-defcred-leak-in-krb5-gss_inquire_cred.patch +++ /dev/null @@ -1,85 +0,0 @@ -From 7e6cdffd47559be61a8c26c4ed3c500c536d5368 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 16 Jul 2021 13:39:39 -0400 -Subject: [PATCH] Fix defcred leak in krb5 gss_inquire_cred() -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Commit 1cd2821c19b2b95e39d5fc2f451a035585a40fa5 altered the memory -management of krb5_gss_inquire_cred(), introducing defcred to act as -an owner pointer when the function must acquire a default credential. -The commit neglected to update the code to release the default cred -along the successful path. The old code does not trigger because -cred_handle is now reassigned, so the default credential is leaked. - -Unify the success and failure cleanup for this function so that -defcred is properly released on success. - -Reported by Pavel Březina. - -ticket: 9016 -tags: pullup -target_version: 1.19-next -target_version: 1.18-next - -(cherry picked from commit 593e16448e1af23eef74689afe06a7bcc86e79c7) ---- - src/lib/gssapi/krb5/inq_cred.c | 16 ++++++---------- - 1 file changed, 6 insertions(+), 10 deletions(-) - -diff --git a/src/lib/gssapi/krb5/inq_cred.c b/src/lib/gssapi/krb5/inq_cred.c -index a8f254110..bb63b726c 100644 ---- a/src/lib/gssapi/krb5/inq_cred.c -+++ b/src/lib/gssapi/krb5/inq_cred.c -@@ -127,7 +127,7 @@ krb5_gss_inquire_cred(minor_status, cred_handle, name, lifetime_ret, - if ((code = krb5_timeofday(context, &now))) { - *minor_status = code; - ret = GSS_S_FAILURE; -- goto fail; -+ goto cleanup; - } - - if (cred->expire != 0) { -@@ -158,7 +158,7 @@ krb5_gss_inquire_cred(minor_status, cred_handle, name, lifetime_ret, - *minor_status = code; - save_error_info(*minor_status, context); - ret = GSS_S_FAILURE; -- goto fail; -+ goto cleanup; - } - } - -@@ -174,7 +174,7 @@ krb5_gss_inquire_cred(minor_status, cred_handle, name, lifetime_ret, - if (ret_name) - kg_release_name(context, &ret_name); - /* *minor_status set above */ -- goto fail; -+ goto cleanup; - } - } - -@@ -190,20 +190,16 @@ krb5_gss_inquire_cred(minor_status, cred_handle, name, lifetime_ret, - - if (cred_usage) - *cred_usage = cred->usage; -- k5_mutex_unlock(&cred->lock); - - if (mechanisms) { - *mechanisms = mechs; - mechs = GSS_C_NO_OID_SET; - } - -- if (cred_handle == GSS_C_NO_CREDENTIAL) -- krb5_gss_release_cred(minor_status, (gss_cred_id_t *)&cred); -- -- krb5_free_context(context); - *minor_status = 0; -- return((lifetime == 0)?GSS_S_CREDENTIALS_EXPIRED:GSS_S_COMPLETE); --fail: -+ ret = (lifetime == 0) ? GSS_S_CREDENTIALS_EXPIRED : GSS_S_COMPLETE; -+ -+cleanup: - k5_mutex_unlock(&cred->lock); - krb5_gss_release_cred(&tmpmin, &defcred); - krb5_free_context(context); diff --git a/Fix-doc-build-for-Sphinx-4.0.patch b/Fix-doc-build-for-Sphinx-4.0.patch deleted file mode 100644 index ae3972c..0000000 --- a/Fix-doc-build-for-Sphinx-4.0.patch +++ /dev/null @@ -1,152 +0,0 @@ -From 0bf023bdbb8335f48a6a4dcf8bd5dac9c2cd7fb6 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 26 May 2021 15:08:28 -0400 -Subject: [PATCH] Fix doc build for Sphinx 4.0 - -Use app.add_css_file() to register krb5.css if possible (it was added -in Sphinx 1.8), since the old name app.add_stylesheet() was removed in -Sphinx 4.0. - -Use the highlight directive instead of the highlightlang directive, -which was removed in Sphinx 4.0. - -Remove two duplicate table of contents entries to fix warnings. - -In the Github Actions configuration, add a second doc build using the -newest version of Sphinx. - -ticket: 9006 -tags: pullup -target_version: 1.19-next - -(cherry picked from commit 3fa40a32e22cb9de91fa1d18deddcba446515855) ---- - .github/workflows/doc.yml | 16 +++++++++++++++- - doc/appdev/refs/macros/index.rst | 1 - - doc/appdev/refs/types/index.rst | 1 - - doc/appdev/refs/types/krb5_int32.rst | 2 +- - doc/appdev/refs/types/krb5_ui_4.rst | 2 +- - doc/conf.py | 9 ++++++++- - doc/tools/define_document.tmpl | 2 +- - doc/tools/type_document.tmpl | 2 +- - 8 files changed, 27 insertions(+), 8 deletions(-) - -diff --git a/.github/workflows/doc.yml b/.github/workflows/doc.yml -index 292df4cfe..75f467cde 100644 ---- a/.github/workflows/doc.yml -+++ b/.github/workflows/doc.yml -@@ -5,7 +5,7 @@ on: - pull_request: {paths: [doc/**, src/doc/*, src/include/krb5/krb5.hin, .github/workflows/doc.yml]} - - jobs: -- doc: -+ doc-older-sphinx: - runs-on: ubuntu-18.04 - steps: - - name: Checkout repository -@@ -19,6 +19,20 @@ jobs: - run: | - cd src/doc - make -f Makefile.in SPHINX_ARGS=-W htmlsrc -+ doc-newest-sphinx: -+ runs-on: ubuntu-18.04 -+ steps: -+ - name: Checkout repository -+ uses: actions/checkout@v1 -+ - name: Linux setup -+ run: | -+ sudo apt-get update -qq -+ sudo apt-get install -y doxygen python3-lxml python3-pip -+ pip3 install Cheetah3 sphinx -+ - name: Build documentation -+ run: | -+ cd src/doc -+ make -f Makefile.in SPHINX_ARGS=-W htmlsrc - - name: Upload HTML - uses: actions/upload-artifact@v2 - with: -diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst -index 4d51e795c..0cb2e81bd 100644 ---- a/doc/appdev/refs/macros/index.rst -+++ b/doc/appdev/refs/macros/index.rst -@@ -54,7 +54,6 @@ Public - ENCTYPE_DES3_CBC_RAW.rst - ENCTYPE_DES3_CBC_SHA.rst - ENCTYPE_DES3_CBC_SHA1.rst -- ENCTYPE_DES3_CBC_SHA1.rst - ENCTYPE_DES_CBC_CRC.rst - ENCTYPE_DES_CBC_MD4.rst - ENCTYPE_DES_CBC_MD5.rst -diff --git a/doc/appdev/refs/types/index.rst b/doc/appdev/refs/types/index.rst -index dc414cfde..d8d2a8f3c 100644 ---- a/doc/appdev/refs/types/index.rst -+++ b/doc/appdev/refs/types/index.rst -@@ -62,7 +62,6 @@ Public - krb5_preauthtype.rst - krb5_principal.rst - krb5_principal_data.rst -- krb5_const_principal.rst - krb5_prompt.rst - krb5_prompt_type.rst - krb5_prompter_fct.rst -diff --git a/doc/appdev/refs/types/krb5_int32.rst b/doc/appdev/refs/types/krb5_int32.rst -index 2bc914b3c..28baafa38 100644 ---- a/doc/appdev/refs/types/krb5_int32.rst -+++ b/doc/appdev/refs/types/krb5_int32.rst -@@ -1,4 +1,4 @@ --.. highlightlang:: c -+.. highlight:: c - - .. _krb5-int32-struct: - -diff --git a/doc/appdev/refs/types/krb5_ui_4.rst b/doc/appdev/refs/types/krb5_ui_4.rst -index de79bafe1..73eb38cf4 100644 ---- a/doc/appdev/refs/types/krb5_ui_4.rst -+++ b/doc/appdev/refs/types/krb5_ui_4.rst -@@ -1,4 +1,4 @@ --.. highlightlang:: c -+.. highlight:: c - - .. _krb5-ui4-struct: - -diff --git a/doc/conf.py b/doc/conf.py -index 4fb6aae14..a876fd633 100644 ---- a/doc/conf.py -+++ b/doc/conf.py -@@ -98,8 +98,15 @@ pygments_style = 'sphinx' - - # -- Options for HTML output --------------------------------------------------- - -+# When we can rely on Sphinx 1.8 (released Sep 2018) we can just set: -+# html_css_files = ['kerb.css'] -+# But in the meantime, we add this file using either a way that works -+# after 1.8 or a way that works before 4.0. - def setup(app): -- app.add_stylesheet('kerb.css') -+ if callable(getattr(app, 'add_css_file', None)): -+ app.add_css_file('kerb.css') -+ else: -+ app.add_stylesheet('kerb.css') - - # The theme to use for HTML and HTML Help pages. See the documentation for - # a list of builtin themes. -diff --git a/doc/tools/define_document.tmpl b/doc/tools/define_document.tmpl -index ca56d866c..8e74dc302 100644 ---- a/doc/tools/define_document.tmpl -+++ b/doc/tools/define_document.tmpl -@@ -1,4 +1,4 @@ --.. highlightlang:: c -+.. highlight:: c - - .. $composite.macro_reference($composite.name): - -diff --git a/doc/tools/type_document.tmpl b/doc/tools/type_document.tmpl -index 5987fa762..11aafb818 100644 ---- a/doc/tools/type_document.tmpl -+++ b/doc/tools/type_document.tmpl -@@ -1,4 +1,4 @@ --.. highlightlang:: c -+.. highlight:: c - - .. $composite.struct_reference($composite.name): - diff --git a/Fix-k5tls-module-for-OpenSSL-3.patch b/Fix-k5tls-module-for-OpenSSL-3.patch index fd425b8..f53a23c 100644 --- a/Fix-k5tls-module-for-OpenSSL-3.patch +++ b/Fix-k5tls-module-for-OpenSSL-3.patch @@ -1,4 +1,4 @@ -From 201e38845e9f70234bcaa9ba7c25b28e38169b0a Mon Sep 17 00:00:00 2001 +From 7e4429640f69acdd5d4f9caa655c011d8bd736f0 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Sat, 29 May 2021 12:05:49 -0400 Subject: [PATCH] Fix k5tls module for OpenSSL 3 diff --git a/Fix-kadmin-k-with-fallback-or-referral-realm.patch b/Fix-kadmin-k-with-fallback-or-referral-realm.patch index 3e03da1..a5162e7 100644 --- a/Fix-kadmin-k-with-fallback-or-referral-realm.patch +++ b/Fix-kadmin-k-with-fallback-or-referral-realm.patch @@ -1,4 +1,4 @@ -From cd8ff035f5b4720a8fc457355726f7bd0eab5eaa Mon Sep 17 00:00:00 2001 +From 2d2bb9a14613b3283dabdd40c3ee28e5b680cf93 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 7 Jun 2021 15:00:41 -0400 Subject: [PATCH] Fix kadmin -k with fallback or referral realm diff --git a/Fix-leaks-on-error-in-kadm5-init-functions.patch b/Fix-leaks-on-error-in-kadm5-init-functions.patch index ef12052..bdacecb 100644 --- a/Fix-leaks-on-error-in-kadm5-init-functions.patch +++ b/Fix-leaks-on-error-in-kadm5-init-functions.patch @@ -1,4 +1,4 @@ -From 6b2f7995ab23cffcababe537d57540236f99f0e3 Mon Sep 17 00:00:00 2001 +From a14e0fd3c1d00ba625e6d9eb72829f31527c6ad8 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Wed, 23 Jun 2021 16:53:16 -0400 Subject: [PATCH] Fix leaks on error in kadm5 init functions diff --git a/Fix-softpkcs11-build-issues-with-openssl-3.0.patch b/Fix-softpkcs11-build-issues-with-openssl-3.0.patch index d7a0a5c..184c1bf 100644 --- a/Fix-softpkcs11-build-issues-with-openssl-3.0.patch +++ b/Fix-softpkcs11-build-issues-with-openssl-3.0.patch @@ -1,4 +1,4 @@ -From a86b780ef275b35e8dc1e6d1886ec8e8d941f7c4 Mon Sep 17 00:00:00 2001 +From 391379bff864751262dbcedb897f2c2dd394345f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Sat, 15 May 2021 17:35:25 -0400 Subject: [PATCH] Fix softpkcs11 build issues with openssl 3.0 diff --git a/Fix-some-principal-realm-canonicalization-cases.patch b/Fix-some-principal-realm-canonicalization-cases.patch index 2c6c915..81fde7f 100644 --- a/Fix-some-principal-realm-canonicalization-cases.patch +++ b/Fix-some-principal-realm-canonicalization-cases.patch @@ -1,4 +1,4 @@ -From 5ae9bc98f23aeaa2ce17debe5a9b0cf1130e54ed Mon Sep 17 00:00:00 2001 +From 0779309f52f4c05bb1f01f638261ef1b8ca82488 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 7 Jun 2021 13:27:29 -0400 Subject: [PATCH] Fix some principal realm canonicalization cases diff --git a/Fix-use-after-free-during-krad-remote_shutdown.patch b/Fix-use-after-free-during-krad-remote_shutdown.patch deleted file mode 100644 index fb9c56d..0000000 --- a/Fix-use-after-free-during-krad-remote_shutdown.patch +++ /dev/null @@ -1,38 +0,0 @@ -From bcd7b5e8aa0d325e9b178d9be3459759d39b631e Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Sat, 29 May 2021 13:25:59 -0400 -Subject: [PATCH] Fix use-after-free during krad remote_shutdown() - -Since elements of the queue can be removed on out-of-memory errors, -the correct call is K5_TAILQ_FOREACH_SAFE, not K5_TAILQ_FOREACH. -Reported by Coverity. - -ticket: 9015 (new) -tags: pullup -target_version: 1.19-next -target_version: 1.18-next - -(cherry picked from commit 8c88defb16b34937d5b72b4832c854ce2dbe32d1) ---- - src/lib/krad/remote.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c -index eca432424..7b5804b1d 100644 ---- a/src/lib/krad/remote.c -+++ b/src/lib/krad/remote.c -@@ -220,12 +220,12 @@ static void - remote_shutdown(krad_remote *rr) - { - krb5_error_code retval; -- request *r; -+ request *r, *next; - - remote_disconnect(rr); - - /* Start timers for all unsent packets. */ -- K5_TAILQ_FOREACH(r, &rr->list, list) { -+ K5_TAILQ_FOREACH_SAFE(r, &rr->list, list, next) { - if (r->timer == NULL) { - retval = request_start_timer(r, rr->vctx); - if (retval != 0) diff --git a/Make-KCM-iteration-fallback-work-with-sssd-kcm.patch b/Make-KCM-iteration-fallback-work-with-sssd-kcm.patch index 5fa3106..a0e28a9 100644 --- a/Make-KCM-iteration-fallback-work-with-sssd-kcm.patch +++ b/Make-KCM-iteration-fallback-work-with-sssd-kcm.patch @@ -1,4 +1,4 @@ -From 2dbca7e14c945d6394e0e05f285a068dcd541295 Mon Sep 17 00:00:00 2001 +From 32ee800fa31d3bbda660bb9270f9aa20718ab202 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Pavel=20B=C5=99ezina?= Date: Tue, 30 Mar 2021 14:35:28 +0200 Subject: [PATCH] Make KCM iteration fallback work with sssd-kcm diff --git a/Move-some-dejagnu-kadmin-tests-to-Python-tests.patch b/Move-some-dejagnu-kadmin-tests-to-Python-tests.patch index 9334c19..1c97190 100644 --- a/Move-some-dejagnu-kadmin-tests-to-Python-tests.patch +++ b/Move-some-dejagnu-kadmin-tests-to-Python-tests.patch @@ -1,4 +1,4 @@ -From 9b3d8b9c395bf1a889ea6d6439dc3543c680480d Mon Sep 17 00:00:00 2001 +From 2fd38805a159020722395e79213540d9bcfa6c71 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Thu, 22 Apr 2021 15:51:36 -0400 Subject: [PATCH] Move some dejagnu kadmin tests to Python tests @@ -32,7 +32,7 @@ and the ticket 2841 regression tests from pwhist.exp. create mode 100644 src/tests/t_kadmin.py diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in -index 6b7749129..ab416cc5f 100644 +index fd714eedb..20f27d748 100644 --- a/src/tests/Makefile.in +++ b/src/tests/Makefile.in @@ -147,6 +147,7 @@ check-pytests: unlockiter s4u2self diff --git a/Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch b/Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch index 23f21a5..429cf4d 100644 --- a/Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch +++ b/Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch @@ -1,4 +1,4 @@ -From 5072bfdfaddae762680d0f9d97afa6dbf8274760 Mon Sep 17 00:00:00 2001 +From 0a2778833d2f04a29fe9d7122913abe42299044a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Sat, 15 May 2021 18:04:58 -0400 Subject: [PATCH] Remove deprecated OpenSSL calls from softpkcs11 diff --git a/Support-host-based-GSS-initiator-names.patch b/Support-host-based-GSS-initiator-names.patch index 25b074f..cd7450c 100644 --- a/Support-host-based-GSS-initiator-names.patch +++ b/Support-host-based-GSS-initiator-names.patch @@ -1,4 +1,4 @@ -From 3133e5e24e94bf060e23a4d97cbdf74e934d010f Mon Sep 17 00:00:00 2001 +From 818a777822658d44ce647fe975011a5ea25e8250 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 15 Jan 2021 13:51:34 -0500 Subject: [PATCH] Support host-based GSS initiator names diff --git a/Use-KCM_OP_RETRIEVE-in-KCM-client.patch b/Use-KCM_OP_RETRIEVE-in-KCM-client.patch index 401b363..2af5676 100644 --- a/Use-KCM_OP_RETRIEVE-in-KCM-client.patch +++ b/Use-KCM_OP_RETRIEVE-in-KCM-client.patch @@ -1,4 +1,4 @@ -From c56d4b87de0f30a38dc61d374ad225d02d581eb3 Mon Sep 17 00:00:00 2001 +From 336f744403baa5dfaffcc5bd226fdd8f14a0200b Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Fri, 26 Mar 2021 23:38:54 -0400 Subject: [PATCH] Use KCM_OP_RETRIEVE in KCM client diff --git a/Use-asan-in-one-of-the-CI-builds.patch b/Use-asan-in-one-of-the-CI-builds.patch index e6b1e86..4964d2f 100644 --- a/Use-asan-in-one-of-the-CI-builds.patch +++ b/Use-asan-in-one-of-the-CI-builds.patch @@ -1,4 +1,4 @@ -From 5457242ca6742ace42f1f7dbe37208752c6f26f4 Mon Sep 17 00:00:00 2001 +From 37e1fe755c6e976253a7f40ec7a9e740e4329789 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Mon, 21 Jun 2021 19:15:26 -0400 Subject: [PATCH] Use asan in one of the CI builds diff --git a/Using-locking-in-MEMORY-krb5_cc_get_principal.patch b/Using-locking-in-MEMORY-krb5_cc_get_principal.patch deleted file mode 100644 index 2ae1967..0000000 --- a/Using-locking-in-MEMORY-krb5_cc_get_principal.patch +++ /dev/null @@ -1,47 +0,0 @@ -From d9a6607d47ff6449d1cad2a9a5b4d3b9b2768ddd Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Sun, 20 Jun 2021 19:24:07 -0400 -Subject: [PATCH] Using locking in MEMORY krb5_cc_get_principal() - -Without locking, the principal pointer could be freed out from under -krb5_copy_principal() by another thread calling krb5_cc_initialize() -or krb5_cc_destroy(). - -ticket: 9014 (new) -tags: pullup -target_version: 1.19-next -target_version: 1.18-next - -(cherry picked from commit 1848447291c68e21311f441b0458ae53471d00d3) ---- - src/lib/krb5/ccache/cc_memory.c | 17 +++++++++++------ - 1 file changed, 11 insertions(+), 6 deletions(-) - -diff --git a/src/lib/krb5/ccache/cc_memory.c b/src/lib/krb5/ccache/cc_memory.c -index 610091a25..e4c795d25 100644 ---- a/src/lib/krb5/ccache/cc_memory.c -+++ b/src/lib/krb5/ccache/cc_memory.c -@@ -575,12 +575,17 @@ krb5_mcc_get_name (krb5_context context, krb5_ccache id) - krb5_error_code KRB5_CALLCONV - krb5_mcc_get_principal(krb5_context context, krb5_ccache id, krb5_principal *princ) - { -- krb5_mcc_data *ptr = (krb5_mcc_data *)id->data; -- if (!ptr->prin) { -- *princ = 0L; -- return KRB5_FCC_NOFILE; -- } -- return krb5_copy_principal(context, ptr->prin, princ); -+ krb5_error_code ret; -+ krb5_mcc_data *d = id->data; -+ -+ *princ = NULL; -+ k5_cc_mutex_lock(context, &d->lock); -+ if (d->prin == NULL) -+ ret = KRB5_FCC_NOFILE; -+ else -+ ret = krb5_copy_principal(context, d->prin, princ); -+ k5_cc_mutex_unlock(context, &d->lock); -+ return ret; - } - - krb5_error_code KRB5_CALLCONV diff --git a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index d48b1cd..553dec9 100644 --- a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From 852e9efad17e3ef6ea54f91044a279bb34020ecf Mon Sep 17 00:00:00 2001 +From 91e1d43858d90f59f5d9f45987cfca02c3175feb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 @@ -477,7 +477,7 @@ index c597174b6..fc2d24800 100644 } diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c -index c96a9b4ee..eca432424 100644 +index a938665f6..7b5804b1d 100644 --- a/src/lib/krad/remote.c +++ b/src/lib/krad/remote.c @@ -263,7 +263,7 @@ on_io_write(krad_remote *rr) diff --git a/downstream-Remove-3des-support.patch b/downstream-Remove-3des-support.patch index 2bc2479..9c29cdd 100644 --- a/downstream-Remove-3des-support.patch +++ b/downstream-Remove-3des-support.patch @@ -1,4 +1,4 @@ -From fef4e551d3d2dcb55e58cc182304254c36aa8949 Mon Sep 17 00:00:00 2001 +From defa8816e26ab9f5a8f0b61e7bebad67175c433e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] [downstream] Remove 3des support @@ -195,7 +195,7 @@ index 1dc958d62..3a72aabef 100644 While **aes128-cts** and **aes256-cts** are supported for all Kerberos diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst -index 047185afb..b08d954d9 100644 +index 694922c0d..c4d5499d3 100644 --- a/doc/admin/enctypes.rst +++ b/doc/admin/enctypes.rst @@ -129,7 +129,7 @@ enctype weak? krb5 Windows @@ -243,7 +243,7 @@ index ade5e1f87..e4dc54f7e 100644 .. _err_cert_chain_cert_expired: diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst -index cebb6644c..4d51e795c 100644 +index 5542d9850..0cb2e81bd 100644 --- a/doc/appdev/refs/macros/index.rst +++ b/doc/appdev/refs/macros/index.rst @@ -36,7 +36,6 @@ Public @@ -255,10 +255,10 @@ index cebb6644c..4d51e795c 100644 CKSUMTYPE_NIST_SHA.rst CKSUMTYPE_RSA_MD4.rst diff --git a/doc/conf.py b/doc/conf.py -index 543202bf4..4fb6aae14 100644 +index 14158ae81..a876fd633 100644 --- a/doc/conf.py +++ b/doc/conf.py -@@ -271,7 +271,7 @@ else: +@@ -278,7 +278,7 @@ else: rst_epilog += ''' .. |krb5conf| replace:: ``/etc/krb5.conf`` .. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal`` diff --git a/downstream-SELinux-integration.patch b/downstream-SELinux-integration.patch index 0ba8b6c..48b058b 100644 --- a/downstream-SELinux-integration.patch +++ b/downstream-SELinux-integration.patch @@ -1,4 +1,4 @@ -From e787771b618a344d45ac515927e914602f48946f Mon Sep 17 00:00:00 2001 +From 97966ffaac6bf9f2e09ac33a16b15794b31d51de Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] [downstream] SELinux integration diff --git a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch index 84551d1..4a9f664 100644 --- a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch +++ b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch @@ -1,4 +1,4 @@ -From 687bb26cb0877fa5497e90f7d325de42b456da2a Mon Sep 17 00:00:00 2001 +From 86d606e33439fd0511c5154be7f32b0df2c72e54 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 15 Nov 2019 20:05:16 +0000 Subject: [PATCH] [downstream] Use backported version of OpenSSL-3 KDF diff --git a/downstream-fix-debuginfo-with-y.tab.c.patch b/downstream-fix-debuginfo-with-y.tab.c.patch index 172a093..494152c 100644 --- a/downstream-fix-debuginfo-with-y.tab.c.patch +++ b/downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,4 +1,4 @@ -From d5ea86ef491feb38f12e6aa53b7579ac02675df6 Mon Sep 17 00:00:00 2001 +From 98b50683165089bf7bd9d91f953abbd79a8b1b08 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] [downstream] fix debuginfo with y.tab.c diff --git a/downstream-ksu-pam-integration.patch b/downstream-ksu-pam-integration.patch index 7490bf2..bebe946 100644 --- a/downstream-ksu-pam-integration.patch +++ b/downstream-ksu-pam-integration.patch @@ -1,4 +1,4 @@ -From 90ba715be48c2e1b6c7ca53cb1d75f3af2c388d6 Mon Sep 17 00:00:00 2001 +From 659b3b4a654b879ce84ad8fb4621dde5ae693385 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] [downstream] ksu pam integration diff --git a/downstream-netlib-and-dns.patch b/downstream-netlib-and-dns.patch index de4f9bf..d3ae129 100644 --- a/downstream-netlib-and-dns.patch +++ b/downstream-netlib-and-dns.patch @@ -1,4 +1,4 @@ -From ad123366e5fb2694cf6d9f4f292a001a761b78fa Mon Sep 17 00:00:00 2001 +From 2d7e197fa88dccd3ca051f9f7cb97937c35c55a8 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:46:21 -0400 Subject: [PATCH] [downstream] netlib and dns diff --git a/krb5.spec b/krb5.spec index d27bf68..930a581 100644 --- a/krb5.spec +++ b/krb5.spec @@ -41,8 +41,8 @@ Summary: The Kerberos network authentication system Name: krb5 -Version: 1.19.1 -Release: %{?zdpd}15%{?dist} +Version: 1.19.2 +Release: %{?zdpd}1%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -78,7 +78,6 @@ Patch12: Fix-KCM-flag-transmission-for-remove_cred.patch Patch13: Make-KCM-iteration-fallback-work-with-sssd-kcm.patch Patch14: Use-KCM_OP_RETRIEVE-in-KCM-client.patch Patch15: Fix-KCM-retrieval-support-for-sssd.patch -Patch16: Fix-doc-build-for-Sphinx-4.0.patch Patch17: Move-some-dejagnu-kadmin-tests-to-Python-tests.patch Patch18: Fix-some-principal-realm-canonicalization-cases.patch Patch19: Allow-kinit-with-keytab-to-defer-canonicalization.patch @@ -89,11 +88,7 @@ Patch23: Fix-k5tls-module-for-OpenSSL-3.patch Patch24: Fix-leaks-on-error-in-kadm5-init-functions.patch Patch25: Clean-up-context-after-failed-open-in-libkdb5.patch Patch26: Use-asan-in-one-of-the-CI-builds.patch -Patch27: Using-locking-in-MEMORY-krb5_cc_get_principal.patch -Patch28: Fix-use-after-free-during-krad-remote_shutdown.patch Patch29: Clean-up-gssapi_krb5-ccache-name-functions.patch -Patch30: Fix-KDC-null-deref-on-bad-encrypted-challenge.patch -Patch31: Fix-defcred-leak-in-krb5-gss_inquire_cred.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -656,6 +651,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Mon Jul 26 2021 Robbie Harwood - 1.19.2-1 +- New upstream version (1.19.2) + * Wed Jul 21 2021 Robbie Harwood - 1.19.1-15 - Fix defcred leak in krb5 gss_inquire_cred() From 03e8c698378c01b1c18019b35288f005fd4be69d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 26 Jul 2021 14:50:12 -0400 Subject: [PATCH 247/304] Add sources --- .gitignore | 2 ++ sources | 4 ++-- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 01d1000..c3c3cb9 100644 --- a/.gitignore +++ b/.gitignore @@ -197,3 +197,5 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.19.tar.gz.asc /krb5-1.19.1.tar.gz /krb5-1.19.1.tar.gz.asc +/krb5-1.19.2.tar.gz +/krb5-1.19.2.tar.gz.asc diff --git a/sources b/sources index e74f7db..16c7a8d 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.19.1.tar.gz) = 36bf33802119ada4650a8f69f1daca95aaf882dc96bfa7061f0340a5decd588c31fc10108ddadf1042934e0e2c3bbd975deec565b0a7f0fc2baf8b8cc6d97491 -SHA512 (krb5-1.19.1.tar.gz.asc) = 078924730ce441630b4ac553a76ba0ebacb09b67dd057a53e3cf42185dd80bf423e875bddd306e4e91873797a9c013a7b0cae66134976abdea2c9752028e66c7 +SHA512 (krb5-1.19.2.tar.gz) = b90d6ed0e1e8a87eb5cb2c36d88b823a6a6caabf85e5d419adb8a930f7eea09a5f8491464e7e454cca7ba88be09d19415962fe0036ad2e31fc584f9fc0bbd470 +SHA512 (krb5-1.19.2.tar.gz.asc) = 87c4d096dbb6821401125b8f8a315ce1aac029744ba9670a4f8a2a680e6dd5798e1c6d5d2b68b17fd9a4b3b9c6ff111cd1dcac42f934d48fb20381b3765e0f64 From ca196a9d6b85240361be460c4bcd731286919a54 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 19 Aug 2021 12:29:56 -0400 Subject: [PATCH 248/304] Fix KDC null deref on TGS inner body null server (CVE-2021-37750) --- ...-deref-on-TGS-inner-body-null-server.patch | 45 +++++++++++++++++++ krb5.spec | 6 ++- 2 files changed, 50 insertions(+), 1 deletion(-) create mode 100644 Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch diff --git a/Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch b/Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch new file mode 100644 index 0000000..24b9d95 --- /dev/null +++ b/Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch @@ -0,0 +1,45 @@ +From bb8fa495d00ccd931eec87a01b8920636cf7903e Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 3 Aug 2021 01:15:27 -0400 +Subject: [PATCH] Fix KDC null deref on TGS inner body null server + +After the KDC decodes a FAST inner body, it does not check for a null +server. Prior to commit 39548a5b17bbda9eeb63625a201cfd19b9de1c5b this +would typically result in an error from krb5_unparse_name(), but with +the addition of get_local_tgt() it results in a null dereference. Add +a null check. + +Reported by Joseph Sutton of Catalyst. + +CVE-2021-37750: + +In MIT krb5 releases 1.14 and later, an authenticated attacker can +cause a null dereference in the KDC by sending a FAST TGS request with +no server field. + +ticket: 9008 (new) +tags: pullup +target_version: 1.19-next +target_version: 1.18-next + +(cherry picked from commit d775c95af7606a51bf79547a94fa52ddd1cb7f49) +--- + src/kdc/do_tgs_req.c | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c +index 6d244ffd4..39a504ca1 100644 +--- a/src/kdc/do_tgs_req.c ++++ b/src/kdc/do_tgs_req.c +@@ -207,6 +207,11 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, + status = "FIND_FAST"; + goto cleanup; + } ++ if (sprinc == NULL) { ++ status = "NULL_SERVER"; ++ errcode = KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN; ++ goto cleanup; ++ } + + errcode = get_local_tgt(kdc_context, &sprinc->realm, header_server, + &local_tgt, &local_tgt_storage, &local_tgt_key); diff --git a/krb5.spec b/krb5.spec index 930a581..37c3b90 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}1%{?dist} +Release: %{?zdpd}2%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -89,6 +89,7 @@ Patch24: Fix-leaks-on-error-in-kadm5-init-functions.patch Patch25: Clean-up-context-after-failed-open-in-libkdb5.patch Patch26: Use-asan-in-one-of-the-CI-builds.patch Patch29: Clean-up-gssapi_krb5-ccache-name-functions.patch +Patch30: Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -651,6 +652,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Aug 19 2021 Robbie Harwood - 1.19.2-2 +- Fix KDC null deref on TGS inner body null server (CVE-2021-37750) + * Mon Jul 26 2021 Robbie Harwood - 1.19.2-1 - New upstream version (1.19.2) From 91c904e5dff1a257fe4f04a32271ac52e9cb6043 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 24 Aug 2021 17:13:22 +0000 Subject: [PATCH 249/304] Remove -specs= from krb5-config output --- krb5.spec | 16 +++++++--------- 1 file changed, 7 insertions(+), 9 deletions(-) diff --git a/krb5.spec b/krb5.spec index 37c3b90..97aaf81 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}2%{?dist} +Release: %{?zdpd}3%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -428,14 +428,9 @@ install -pdm 755 $RPM_BUILD_ROOT/%{_libdir}/krb5/plugins/authdata # list of link flags, and it helps prevent file conflicts on multilib systems. sed -r -i -e 's|^libdir=/usr/lib(64)?$|libdir=/usr/lib|g' $RPM_BUILD_ROOT%{_bindir}/krb5-config -# Temporay workaround for krb5-config reading too much from LDFLAGS. -# Upstream: http://krbdev.mit.edu/rt/Ticket/Display.html?id=8159 -sed -r -i -e "s/-specs=\/.+?\/redhat-hardened-ld//g" $RPM_BUILD_ROOT%{_bindir}/krb5-config - -if [[ "$(< $RPM_BUILD_ROOT%{_bindir}/krb5-config )" == *redhat-hardened-ld* ]] ; then - printf '# redhat-hardened-ld for krb5-config failed' 1>&2 - exit 1 -fi +# Workaround krb5-config reading too much from LDFLAGS. +# https://bugzilla.redhat.com/show_bug.cgi?id=1997021 +sed -i -e "s/-specs=[^ ]*//g" $RPM_BUILD_ROOT%{_bindir}/krb5-config # Install processed man pages. for section in 1 5 8 ; do @@ -652,6 +647,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Aug 24 2021 Robbie Harwood - 1.19.2-3 +- Remove -specs= from krb5-config output + * Thu Aug 19 2021 Robbie Harwood - 1.19.2-2 - Fix KDC null deref on TGS inner body null server (CVE-2021-37750) From 70255ea5b0b01697348072a05daa776297ecd9a7 Mon Sep 17 00:00:00 2001 From: Sahana Prasad Date: Tue, 14 Sep 2021 19:05:45 +0200 Subject: [PATCH 250/304] Rebuilt with OpenSSL 3.0.0 --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 97aaf81..82c7d8a 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}3%{?dist} +Release: %{?zdpd}3%{?dist}.1 # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -647,6 +647,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Sep 14 2021 Sahana Prasad - 1.19.2-3.1 +- Rebuilt with OpenSSL 3.0.0 + * Tue Aug 24 2021 Robbie Harwood - 1.19.2-3 - Remove -specs= from krb5-config output From ad88d4fd50a31f6cfe4de56d387f1a6f1aa5468c Mon Sep 17 00:00:00 2001 From: Antonio Torres Date: Fri, 3 Dec 2021 11:25:46 +0100 Subject: [PATCH 251/304] Add patches to support OpenSSL 3.0.0 Signed-off-by: Antonio Torres --- ...detection-of-the-OpenSSL-3-KDF-inter.patch | 25 + Fix-k5tls-module-for-OpenSSL-3.patch | 3 +- ...pkcs11-build-issues-with-openssl-3.0.patch | 3 +- Handle-OpenSSL-3-s-providers.patch | 301 + Remove-TCL-based-libkadm5-API-tests.patch | 18229 ++++++++++++++++ ...ecated-OpenSSL-calls-from-softpkcs11.patch | 7 +- ...KDF-and-KRB5KDF-for-deriving-long-te.patch | 482 + ...SSL-s-SSKDF-in-PKINIT-when-available.patch | 408 + downstream-Remove-3des-support.patch | 68 +- krb5.spec | 25 +- 10 files changed, 19474 insertions(+), 77 deletions(-) create mode 100644 Add-buildsystem-detection-of-the-OpenSSL-3-KDF-inter.patch create mode 100644 Handle-OpenSSL-3-s-providers.patch create mode 100644 Remove-TCL-based-libkadm5-API-tests.patch create mode 100644 Use-OpenSSL-s-KBKDF-and-KRB5KDF-for-deriving-long-te.patch create mode 100644 Use-OpenSSL-s-SSKDF-in-PKINIT-when-available.patch diff --git a/Add-buildsystem-detection-of-the-OpenSSL-3-KDF-inter.patch b/Add-buildsystem-detection-of-the-OpenSSL-3-KDF-inter.patch new file mode 100644 index 0000000..269a457 --- /dev/null +++ b/Add-buildsystem-detection-of-the-OpenSSL-3-KDF-inter.patch @@ -0,0 +1,25 @@ +From 2f039fc910022c9569fe6941a194f0b26bd6c894 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 20 Sep 2019 16:11:29 -0400 +Subject: [PATCH] Add buildsystem detection of the OpenSSL-3 KDF interface + +(cherry picked from commit a3e03dfd40928c4615bd9b8546eac0c104377850) +--- + src/configure.ac | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/src/configure.ac b/src/configure.ac +index eb6307468..9c2e816fe 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -282,6 +282,10 @@ AC_SUBST(CRYPTO_IMPL) + AC_SUBST(CRYPTO_IMPL_CFLAGS) + AC_SUBST(CRYPTO_IMPL_LIBS) + ++if test "$CRYPTO_IMPL" = openssl; then ++ AC_CHECK_FUNCS(EVP_KDF_fetch) ++fi ++ + AC_ARG_WITH([prng-alg], + AC_HELP_STRING([--with-prng-alg=ALG], [use specified PRNG algorithm. @<:@fortuna@:>@]), + [PRNG_ALG=$withval diff --git a/Fix-k5tls-module-for-OpenSSL-3.patch b/Fix-k5tls-module-for-OpenSSL-3.patch index f53a23c..a2b9e34 100644 --- a/Fix-k5tls-module-for-OpenSSL-3.patch +++ b/Fix-k5tls-module-for-OpenSSL-3.patch @@ -1,4 +1,4 @@ -From 7e4429640f69acdd5d4f9caa655c011d8bd736f0 Mon Sep 17 00:00:00 2001 +From 51938a8b731740299fe47d132b8840edba4141bc Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Sat, 29 May 2021 12:05:49 -0400 Subject: [PATCH] Fix k5tls module for OpenSSL 3 @@ -16,6 +16,7 @@ doesn't clear existing options. [ghudson@mit.edu: edited commit message and comment] (cherry picked from commit aa9b4a2a64046afd2fab7cb49c346295874a5fb6) +(cherry picked from commit 201e38845e9f70234bcaa9ba7c25b28e38169b0a) --- src/plugins/tls/k5tls/openssl.c | 17 ++++++++++++++--- 1 file changed, 14 insertions(+), 3 deletions(-) diff --git a/Fix-softpkcs11-build-issues-with-openssl-3.0.patch b/Fix-softpkcs11-build-issues-with-openssl-3.0.patch index 184c1bf..ba5a8b5 100644 --- a/Fix-softpkcs11-build-issues-with-openssl-3.0.patch +++ b/Fix-softpkcs11-build-issues-with-openssl-3.0.patch @@ -1,4 +1,4 @@ -From 391379bff864751262dbcedb897f2c2dd394345f Mon Sep 17 00:00:00 2001 +From f85a818fe1a7438db7e1ea579818da67e0be017d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Sat, 15 May 2021 17:35:25 -0400 Subject: [PATCH] Fix softpkcs11 build issues with openssl 3.0 @@ -17,6 +17,7 @@ Move several argument validation checks to the top of their functions. Fix some incorrect/inconsistent log messages. (cherry picked from commit 00de1aad7b3647b91017c7009b0bc65cd0c8b2e0) +(cherry picked from commit a86b780ef275b35e8dc1e6d1886ec8e8d941f7c4) --- src/tests/softpkcs11/main.c | 360 ++++++++++++++---------------------- 1 file changed, 141 insertions(+), 219 deletions(-) diff --git a/Handle-OpenSSL-3-s-providers.patch b/Handle-OpenSSL-3-s-providers.patch new file mode 100644 index 0000000..d7b0d90 --- /dev/null +++ b/Handle-OpenSSL-3-s-providers.patch @@ -0,0 +1,301 @@ +From e3f3d31a3db23f6c8437cd0efe45f67a7f4fc6aa Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Sat, 15 May 2021 21:18:06 -0400 +Subject: [PATCH] Handle OpenSSL 3's providers + +OpenSSL 3 compartmentalizes what algorithms it uses, which for us means +another hoop to jump through to use dubious cryptography. (Right now, +we need to load "legacy" in order to access MD4 and RC4.) + +Use our normal initializer logic to set up providers both in the OpenSSL +provider an the PKINIT plugin. Since DT_FINI is too late, release them +using atexit() as OpenSSL does. + +(cherry picked from commit bea5a703a06da1f1ab56821b77a2d3661cb0dda4) +[rharwood@redhat.com: work around des3 removal and rc4 fips changes] +--- + src/configure.ac | 1 + + src/lib/crypto/openssl/enc_provider/aes.c | 16 ++++++ + .../crypto/openssl/enc_provider/camellia.c | 16 ++++++ + src/lib/crypto/openssl/enc_provider/rc4.c | 4 ++ + .../crypto/openssl/hash_provider/hash_evp.c | 5 ++ + src/lib/crypto/openssl/init.c | 53 +++++++++++++++++++ + src/plugins/preauth/pkinit/Makefile.in | 1 + + .../preauth/pkinit/pkinit_crypto_openssl.c | 33 ++++++++++-- + 8 files changed, 126 insertions(+), 3 deletions(-) + +diff --git a/src/configure.ac b/src/configure.ac +index 9c2e816fe..20066918b 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -284,6 +284,7 @@ AC_SUBST(CRYPTO_IMPL_LIBS) + + if test "$CRYPTO_IMPL" = openssl; then + AC_CHECK_FUNCS(EVP_KDF_fetch) ++ AC_CHECK_FUNCS(OSSL_PROVIDER_load) + fi + + AC_ARG_WITH([prng-alg], +diff --git a/src/lib/crypto/openssl/enc_provider/aes.c b/src/lib/crypto/openssl/enc_provider/aes.c +index 6b4622fe9..31c90a69d 100644 +--- a/src/lib/crypto/openssl/enc_provider/aes.c ++++ b/src/lib/crypto/openssl/enc_provider/aes.c +@@ -68,6 +68,10 @@ cbc_enc(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx; + struct iov_cursor cursor; + ++ ret = krb5int_crypto_init(); ++ if (ret) ++ return ret; ++ + ctx = EVP_CIPHER_CTX_new(); + if (ctx == NULL) + return ENOMEM; +@@ -102,6 +106,10 @@ cbc_decr(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx; + struct iov_cursor cursor; + ++ ret = krb5int_crypto_init(); ++ if (ret) ++ return ret; ++ + ctx = EVP_CIPHER_CTX_new(); + if (ctx == NULL) + return ENOMEM; +@@ -137,6 +145,10 @@ cts_encr(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + struct iov_cursor cursor; + AES_KEY enck; + ++ ret = krb5int_crypto_init(); ++ if (ret) ++ return ret; ++ + memset(iv_cts,0,sizeof(iv_cts)); + if (ivec && ivec->data){ + if (ivec->length != sizeof(iv_cts)) +@@ -190,6 +202,10 @@ cts_decr(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + struct iov_cursor cursor; + AES_KEY deck; + ++ ret = krb5int_crypto_init(); ++ if (ret) ++ return ret; ++ + memset(iv_cts,0,sizeof(iv_cts)); + if (ivec && ivec->data){ + if (ivec->length != sizeof(iv_cts)) +diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c +index f79679a0b..7cc7fc6fb 100644 +--- a/src/lib/crypto/openssl/enc_provider/camellia.c ++++ b/src/lib/crypto/openssl/enc_provider/camellia.c +@@ -92,6 +92,10 @@ cbc_enc(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx; + struct iov_cursor cursor; + ++ ret = krb5int_crypto_init(); ++ if (ret) ++ return ret; ++ + ctx = EVP_CIPHER_CTX_new(); + if (ctx == NULL) + return ENOMEM; +@@ -126,6 +130,10 @@ cbc_decr(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx; + struct iov_cursor cursor; + ++ ret = krb5int_crypto_init(); ++ if (ret) ++ return ret; ++ + ctx = EVP_CIPHER_CTX_new(); + if (ctx == NULL) + return ENOMEM; +@@ -161,6 +169,10 @@ cts_encr(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + struct iov_cursor cursor; + CAMELLIA_KEY enck; + ++ ret = krb5int_crypto_init(); ++ if (ret) ++ return ret; ++ + memset(iv_cts,0,sizeof(iv_cts)); + if (ivec && ivec->data){ + if (ivec->length != sizeof(iv_cts)) +@@ -214,6 +226,10 @@ cts_decr(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, + struct iov_cursor cursor; + CAMELLIA_KEY deck; + ++ ret = krb5int_crypto_init(); ++ if (ret) ++ return ret; ++ + memset(iv_cts,0,sizeof(iv_cts)); + if (ivec && ivec->data){ + if (ivec->length != sizeof(iv_cts)) +diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c +index 9bf407899..a10cb5192 100644 +--- a/src/lib/crypto/openssl/enc_provider/rc4.c ++++ b/src/lib/crypto/openssl/enc_provider/rc4.c +@@ -66,6 +66,10 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, + EVP_CIPHER_CTX *ctx = NULL; + struct arcfour_state *arcstate; + ++ ret = krb5int_crypto_init(); ++ if (ret) ++ return ret; ++ + if (FIPS_mode()) + return KRB5_CRYPTO_INTERNAL; + +diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c +index 2eb5139c0..09d7b3896 100644 +--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c ++++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c +@@ -41,6 +41,11 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, + const krb5_data *d; + size_t i; + int ok; ++ krb5_error_code ret; ++ ++ ret = krb5int_crypto_init(); ++ if (ret) ++ return ret; + + if (output->length != (unsigned int)EVP_MD_size(type)) + return KRB5_CRYPTO_INTERNAL; +diff --git a/src/lib/crypto/openssl/init.c b/src/lib/crypto/openssl/init.c +index 1139bce53..f72dbfe81 100644 +--- a/src/lib/crypto/openssl/init.c ++++ b/src/lib/crypto/openssl/init.c +@@ -26,12 +26,65 @@ + + #include "crypto_int.h" + ++#ifdef HAVE_OSSL_PROVIDER_LOAD ++ ++/* ++ * Starting in OpenSSL 3, algorithms are grouped into containers called ++ * "providers", not all of which are loaded by default. At time of writing, ++ * we need MD4 and RC4 from the legacy provider. Oddly, 3DES is not in ++ * legacy. ++ */ ++ ++#include ++ ++static OSSL_PROVIDER *legacy_provider = NULL; ++static OSSL_PROVIDER *default_provider = NULL; ++ ++static void ++unload_providers(void) ++{ ++ if (default_provider != NULL) ++ (void)OSSL_PROVIDER_unload(default_provider); ++ if (legacy_provider != NULL) ++ (void)OSSL_PROVIDER_unload(legacy_provider); ++ default_provider = NULL; ++ legacy_provider = NULL; ++} ++ ++int ++krb5int_crypto_impl_init(void) ++{ ++ legacy_provider = OSSL_PROVIDER_load(NULL, "legacy"); ++ default_provider = OSSL_PROVIDER_load(NULL, "default"); ++ ++ /* ++ * Someone might build openssl without the legacy provider. They will ++ * have a bad time, but some things will still work. I don't know think ++ * this configuration is worth supporting. ++ */ ++ if (legacy_provider == NULL || default_provider == NULL) ++ abort(); ++ ++ /* ++ * If we attempt to do this with our normal LIBFINIFUNC logic (DT_FINI), ++ * OpenSSL will have cleaned itself up by the time we're invoked. OpenSSL ++ * registers its cleanup (OPENSSL_cleanup) with atexit() - do the same and ++ * we'll be higher on the stack. ++ */ ++ atexit(unload_providers); ++ return 0; ++} ++ ++#else /* !HAVE_OSSL_PROVIDER_LOAD */ ++ + int + krb5int_crypto_impl_init(void) + { + return 0; + } + ++#endif ++ + void + krb5int_crypto_impl_cleanup(void) + { +diff --git a/src/plugins/preauth/pkinit/Makefile.in b/src/plugins/preauth/pkinit/Makefile.in +index 15ca0eb48..d20fb18a8 100644 +--- a/src/plugins/preauth/pkinit/Makefile.in ++++ b/src/plugins/preauth/pkinit/Makefile.in +@@ -5,6 +5,7 @@ MODULE_INSTALL_DIR = $(KRB5_PA_MODULE_DIR) + LIBBASE=pkinit + LIBMAJOR=0 + LIBMINOR=0 ++LIBINITFUNC=pkinit_openssl_init + RELDIR=../plugins/preauth/pkinit + # Depends on libk5crypto and libkrb5 + SHLIB_EXPDEPS = \ +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 350c2118a..42e5c581d 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -44,6 +44,13 @@ + #include + #endif + ++#ifdef HAVE_OSSL_PROVIDER_LOAD ++#include ++ ++static OSSL_PROVIDER *legacy_provider = NULL; ++static OSSL_PROVIDER *default_provider = NULL; ++#endif ++ + static krb5_error_code pkinit_init_pkinit_oids(pkinit_plg_crypto_context ); + static void pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ); + +@@ -2937,12 +2944,32 @@ cleanup: + return retval; + } + ++/* pkinit_openssl_init() and unload_providers() are largely duplicated from ++ * lib/crypto/openssl/init.c - see explanations there. */ ++static void ++unload_providers(void) ++{ ++ if (default_provider != NULL) ++ (void)OSSL_PROVIDER_unload(default_provider); ++ if (legacy_provider != NULL) ++ (void)OSSL_PROVIDER_unload(legacy_provider); ++ default_provider = NULL; ++ legacy_provider = NULL; ++} ++ + int + pkinit_openssl_init() + { +- /* Initialize OpenSSL. */ +- ERR_load_crypto_strings(); +- OpenSSL_add_all_algorithms(); ++#ifdef HAVE_OSSL_PROVIDER_LOAD ++ legacy_provider = OSSL_PROVIDER_load(NULL, "legacy"); ++ default_provider = OSSL_PROVIDER_load(NULL, "default"); ++ ++ if (legacy_provider == NULL || default_provider == NULL) ++ abort(); ++ ++ atexit(unload_providers); ++#endif ++ + return 0; + } + diff --git a/Remove-TCL-based-libkadm5-API-tests.patch b/Remove-TCL-based-libkadm5-API-tests.patch new file mode 100644 index 0000000..7819198 --- /dev/null +++ b/Remove-TCL-based-libkadm5-API-tests.patch @@ -0,0 +1,18229 @@ +From ddb189ff95350afc0e3e063016a0f0dd5213dc4c Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 16 Apr 2021 10:24:04 -0400 +Subject: [PATCH] Remove TCL-based libkadm5 API tests + +[antorres@redhat.com: remove diff for .gitignore] +--- + .gitignore | 20 - + doc/kadm5/api-unit-test.tex | 2680 ----------------- + src/config/pre.in | 18 +- + src/configure.ac | 31 +- + src/kadmin/Makefile.in | 2 +- + src/kadmin/testing/Makefile.in | 8 - + src/kadmin/testing/deps | 1 - + src/kadmin/testing/proto/kdc.conf.proto | 16 - + src/kadmin/testing/proto/krb5.conf.proto | 32 - + src/kadmin/testing/proto/ovsec_adm.dict | 3 - + src/kadmin/testing/scripts/Makefile.in | 18 - + src/kadmin/testing/scripts/deps | 1 - + src/kadmin/testing/scripts/env-setup.shin | 104 - + src/kadmin/testing/scripts/init_db | 229 -- + src/kadmin/testing/scripts/start_servers | 69 - + .../testing/scripts/start_servers_local | 157 - + src/kadmin/testing/scripts/stop_servers | 60 - + src/kadmin/testing/scripts/stop_servers_local | 44 - + src/kadmin/testing/tcl/util.t | 58 - + src/kadmin/testing/util/Makefile.in | 42 - + src/kadmin/testing/util/bsddb_dump.c | 65 - + src/kadmin/testing/util/deps | 16 - + src/kadmin/testing/util/tcl_kadm5.c | 2566 ---------------- + src/kadmin/testing/util/tcl_kadm5.h | 3 - + src/kadmin/testing/util/tcl_kadm5_syntax | 57 - + src/kadmin/testing/util/tcl_krb5_hash.c | 167 - + src/kadmin/testing/util/test.c | 38 - + src/lib/kadm5/Makefile.in | 3 +- + src/lib/kadm5/unit-test/Makefile.in | 143 - + src/lib/kadm5/unit-test/api.2/crte-policy.exp | 927 ------ + src/lib/kadm5/unit-test/api.2/get-policy.exp | 199 -- + src/lib/kadm5/unit-test/api.2/mod-policy.exp | 675 ----- + .../api.current/chpass-principal-v2.exp | 68 - + .../api.current/chpass-principal.exp | 176 -- + .../unit-test/api.current/crte-policy.exp | 927 ------ + .../unit-test/api.current/crte-principal.exp | 1336 -------- + .../kadm5/unit-test/api.current/destroy.exp | 203 -- + .../unit-test/api.current/dlte-policy.exp | 208 -- + .../unit-test/api.current/dlte-principal.exp | 253 -- + .../unit-test/api.current/get-policy.exp | 199 -- + .../api.current/get-principal-v2.exp | 250 -- + .../unit-test/api.current/get-principal.exp | 346 --- + .../kadm5/unit-test/api.current/init-v2.exp | 506 ---- + src/lib/kadm5/unit-test/api.current/init.exp | 699 ----- + .../unit-test/api.current/mod-policy.exp | 711 ----- + .../api.current/mod-principal-v2.exp | 115 - + .../unit-test/api.current/mod-principal.exp | 1606 ---------- + .../api.current/randkey-principal-v2.exp | 61 - + .../api.current/randkey-principal.exp | 297 -- + src/lib/kadm5/unit-test/config/unix.exp | 222 -- + src/lib/kadm5/unit-test/deps | 86 - + src/lib/kadm5/unit-test/destroy-test.c | 48 - + src/lib/kadm5/unit-test/diff-files/destroy-1 | 2 - + src/lib/kadm5/unit-test/diff-files/no-diffs | 2 - + src/lib/kadm5/unit-test/handle-test.c | 140 - + src/lib/kadm5/unit-test/init-test.c | 39 - + src/lib/kadm5/unit-test/iter-test.c | 51 - + src/lib/kadm5/unit-test/lib/lib.t | 306 -- + src/lib/kadm5/unit-test/lock-test.c | 105 - + src/lib/kadm5/unit-test/randkey-test.c | 42 - + src/lib/kadm5/unit-test/setkey-test.c | 246 -- + src/lib/kadm5/unit-test/site.exp | 2 - + 62 files changed, 7 insertions(+), 17697 deletions(-) + delete mode 100644 doc/kadm5/api-unit-test.tex + delete mode 100644 src/kadmin/testing/Makefile.in + delete mode 100644 src/kadmin/testing/deps + delete mode 100644 src/kadmin/testing/proto/kdc.conf.proto + delete mode 100644 src/kadmin/testing/proto/krb5.conf.proto + delete mode 100644 src/kadmin/testing/proto/ovsec_adm.dict + delete mode 100644 src/kadmin/testing/scripts/Makefile.in + delete mode 100644 src/kadmin/testing/scripts/deps + delete mode 100755 src/kadmin/testing/scripts/env-setup.shin + delete mode 100755 src/kadmin/testing/scripts/init_db + delete mode 100755 src/kadmin/testing/scripts/start_servers + delete mode 100755 src/kadmin/testing/scripts/start_servers_local + delete mode 100755 src/kadmin/testing/scripts/stop_servers + delete mode 100755 src/kadmin/testing/scripts/stop_servers_local + delete mode 100644 src/kadmin/testing/tcl/util.t + delete mode 100644 src/kadmin/testing/util/Makefile.in + delete mode 100644 src/kadmin/testing/util/bsddb_dump.c + delete mode 100644 src/kadmin/testing/util/deps + delete mode 100644 src/kadmin/testing/util/tcl_kadm5.c + delete mode 100644 src/kadmin/testing/util/tcl_kadm5.h + delete mode 100644 src/kadmin/testing/util/tcl_kadm5_syntax + delete mode 100644 src/kadmin/testing/util/tcl_krb5_hash.c + delete mode 100644 src/kadmin/testing/util/test.c + delete mode 100644 src/lib/kadm5/unit-test/Makefile.in + delete mode 100644 src/lib/kadm5/unit-test/api.2/crte-policy.exp + delete mode 100644 src/lib/kadm5/unit-test/api.2/get-policy.exp + delete mode 100644 src/lib/kadm5/unit-test/api.2/mod-policy.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/chpass-principal.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/crte-policy.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/crte-principal.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/destroy.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/dlte-policy.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/dlte-principal.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/get-policy.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/get-principal-v2.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/get-principal.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/init-v2.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/init.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/mod-policy.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/mod-principal-v2.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/mod-principal.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp + delete mode 100644 src/lib/kadm5/unit-test/api.current/randkey-principal.exp + delete mode 100644 src/lib/kadm5/unit-test/config/unix.exp + delete mode 100644 src/lib/kadm5/unit-test/deps + delete mode 100644 src/lib/kadm5/unit-test/destroy-test.c + delete mode 100644 src/lib/kadm5/unit-test/diff-files/destroy-1 + delete mode 100644 src/lib/kadm5/unit-test/diff-files/no-diffs + delete mode 100644 src/lib/kadm5/unit-test/handle-test.c + delete mode 100644 src/lib/kadm5/unit-test/init-test.c + delete mode 100644 src/lib/kadm5/unit-test/iter-test.c + delete mode 100644 src/lib/kadm5/unit-test/lib/lib.t + delete mode 100644 src/lib/kadm5/unit-test/lock-test.c + delete mode 100644 src/lib/kadm5/unit-test/randkey-test.c + delete mode 100644 src/lib/kadm5/unit-test/setkey-test.c + delete mode 100644 src/lib/kadm5/unit-test/site.exp + +diff --git a/doc/kadm5/api-unit-test.tex b/doc/kadm5/api-unit-test.tex +deleted file mode 100644 +index 014242037..000000000 +--- a/doc/kadm5/api-unit-test.tex ++++ /dev/null +@@ -1,2680 +0,0 @@ +-% This document is included for historical purposes only, and does not +-% apply to krb5 today. +- +-\documentstyle[times,fullpage]{article} +- +-%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% +-%% Make _ actually generate an _, and allow line-breaking after it. +-\let\underscore=\_ +-\catcode`_=13 +-\def_{\underscore\penalty75\relax} +-%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% +- +-\newcommand{\test}[1]{\begin{description} +-\setlength{\itemsep}{0pt} +-#1 +-\end{description} +- +-} +- +-\newcommand{\numtest}[2]{\begin{description} +-\setlength{\itemsep}{0pt} +-\Number{#1} +-#2 +-\end{description} +- +-} +- +-\newcommand{\Number}[1]{\item[Number:] #1} +-\newcommand{\Reason}[1]{\item[Reason:] #1} +-\newcommand{\Expected}[1]{\item[Expected:] #1} +-\newcommand{\Conditions}[1]{\item[Conditions:] #1} +-\newcommand{\Priority}[1]{\item[Priority:] #1} +-\newcommand{\Status}[1]{\item[Status:] #1} +-\newcommand{\Vtwonote}[1]{\item[V2 note:] #1} +-\newcommand{\Version}[1]{\item[Version:] #1} +-\newcommand{\Call}[1]{} +-%\newcommand{\Call}[1]{\item[Call:] #1} +-%\newcommand{\Number}[1]{} +-%\newcommand{\Reason}[1]{} +-%\newcommand{\Expected}[1]{} +-%\newcommand{\Conditions}[1]{} +-%\newcommand{\Priority}[1]{} +- +-\title{KADM5 Admin API\\ +-Unit Test Description} +-\author{Jonathan I. Kamens} +- +-\begin{document} +- +-\maketitle +- +-%\tableofcontents +- +-\section{Introduction} +- +-The following is a description of a black-box unit test of the KADM5 +-API. Each API function is listed, followed by the tests that should be +-performed on it. +- +-The tests described here are based on the ``Kerberos Administration +-System KADM5 API Functional Specifications'', revision 1.68. This +-document was originally written based on the OpenVision API functional +-specifications, version 1.41, dated August 18, 1994, and many +-indications of the original version remain. +- +-All tests which test for success should verify, using some means other +-than the return value of the function being tested, that the requested +-operation was successfully performed. For example: for init, test +-that other operations can be performed after init; for destroy, test +-that other operations can't be performed after destroy; for modify +-functions, verify that all modifications to the database which should +-have taken place did, and that the new, modified data is in effect; +-for get operations, verify that the data retrieved is the data that +-should actually be in the database. +- +-The tests would be better if they compared the actual contents of the +-database before and after each test, rather than relying on the KADM5 +-API to report the results of changes. +- +-Similarly, all tests which test for failure should verify that the +-no component of the requested operation took place. For example: if +-init fails, other operations should not work. If a modify fails, all +-data in the database should be the same as it was before the attempt +-to modify, and the old data should still be what is enforced. +-Furthermore, tests which test for failure should verify that the +-failure code returned is correct for the specific failure condition +-tested. +- +-Most of the tests listed below should be run twice -- once locally on +-the server after linking against the server API library, and once +-talking to the server via authenticated Sun RPC after linking against +-the client API library. Tests which should only be run locally or via +-RPC are labelled with a ``local'' or ``RPC''. +- +-Furthermore, in addition to the tests labelled below, a test should be +-implemented to verify that a client can't perform operations on the +-server through the client API library when it's linked against +-standard Sun RPC instead of OpenV*Secure's authenticated Sun RPC. +-This will require a client with a modified version of ovsec_kadm_init +-which doesn't call auth_gssapi_create. This client should call this +-modified ovsec_kadm_init and then call some other admin API function, +-specifying arguments to both functions that would work if the +-authenticated Sun RPC had been used, but shouldn't if authentication +-wasn't used. The test should verify that the API function call after +-the init doesn't succeed. +- +-There is also another test to see if all the API functions handle getting an +-invalid server handle correctly. This is not done as part of the tests that +-are run through the TCL program cause the TCL program has no way of +-invalidating a server handle. So there is a program that calls init and +-changes the handle magic number, and then attempts to call each API function +-with the corrupted server handle. +- +-A number of tests have been added or changed to correspond with KADM5 +-API version 2. Tests which are only performed against the newer +-version specify the version number in the test description. +- +-\section{ovsec_kadm_init} +- +-\numtest{1}{ +-\Reason{An empty string realm is rejected.} +-\Status{Implemented} +-\Vtwonote{The empty string is now passed as the realm field of the +-parameters structure.} +-} +- +-\numtest{2}{ +-\Reason{A realm containing invalid characters is rejected.} +-\Status{Implemented} +-\Vtwonote{The invalid character is now passed as the realm field of the +-parameters structure.} +-} +- +-\numtest{2.5}{ +-\Reason{A non-existent realm is rejected.} +-\Status{Implemented} +-\Vtwonote{The non-existent realm is now passed as the realm field of the +-parameters structure.} +-} +- +-\numtest{3}{ +-\Reason{A bad service name representing an existing principal +- (different from the client principal) is rejected.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{4}{ +-\Reason{A bad service name representing a non-existent +- principal is rejected.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{5}{ +-\Reason{A bad service name identical to the (existing) client +- name is rejected.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{6}{ +-\Reason{A null password causes password prompting.} +-\Status{Implemented} +-} +- +-\numtest{7}{ +-\Reason{An empty-string causes password prompting} +-\Status{Implemented} +-} +- +-\numtest{8}{ +-\Reason{An incorrect password which is the password of another +- user is rejected.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{9}{ +-\Reason{An incorrect password which isn't the password of any +- user is rejected.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{10}{ +-\Reason{A null client_name is rejected.} +-\Status{Implemented} +-} +- +-% Empty string client name is legal. +-%\numtest{11}{ +-%\Reason{An empty-string client_name is rejected.} +-%} +- +-\numtest{12}{ +-\Reason{A client_name referring to a non-existent principal in +- the default realm is rejected.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{13}{ +-\Reason{A client_name referring to a non-existent principal +- with the local realm specified explicitly is rejected.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{14}{ +-\Reason{A client_name referring to a non-existent principal in +- a nonexistent realm is rejected.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{15}{ +-\Reason{A client_name referring to an existing principal in a +- nonexistent realm is rejected.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{16}{ +-\Reason{Valid invocation.} +-\Status{Implemented} +-} +- +-\numtest{17}{ +-\Reason{Valid invocation (explicit client realm).} +-\Status{Implemented} +-} +- +-\numtest{18}{ +-\Reason{Valid invocation (CHANGEPW_SERVICE).} +-\Status{Implemented} +-} +- +-\numtest{19}{ +-\Reason{Valid invocation (explicit service realm).} +-\Status{Implemented} +-\Vtwonote{The explicit realm is now passed as the realm field of the +-configuration parameters.} +-} +- +-\numtest{20}{ +-\Reason{Valid invocation (database access allowed after init).} +-\Status{Implemented} +-} +- +-%\numtest{21}{ +-%\Reason{Init fails when called twice in a row.} +-%\Status{Implemented} +-%} +- +-\numtest{22}{ +-\Reason{A null password causes master-key prompting.} +-\Conditions{local} +-\Status{Implemented} +-\Vtwonote{Obsolete.} +-} +- +-\numtest{22.5}{ +-\Reason{A empty string password causes master-key prompting.} +-\Conditions{local} +-\Status{Implemented} +-\Vtwonote{Obsolete.} +-} +- +-%\numtest{23}{ +-%\Reason{A non-null password causes reading from the kstash.} +-%\Conditions{local} +-%\Status{Implemented} +-%} +- +-\numtest{24}{ +-\Reason{Null service name is ignored in local invocation.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{25}{ +-\Reason{Non-null service name is ignored in local invocation.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-%\numtest{26}{ +-%\Reason{Can't do ``get'' operation before calling init.} +-%\Status{Implemented} +-%} +- +-%\numtest{27}{ +-%\Reason{Can't do ``add'' operation before calling init.} +-%\Status{Implemented} +-%} +- +-%\numtest{28}{ +-%\Reason{Can't do ``modify'' operation before calling init.} +-%\Status{Implemented} +-%} +- +-%\numtest{29}{ +-%\Reason{Can't do ``delete'' operation before calling init.} +-%\Status{Implemented} +-%} +- +-\numtest{30}{ +-\Reason{Can init after failed init attempt.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{31}{ +-\Priority{High} +-\Reason{Return BAD_STRUCT_VERSION when the mask bits are set to invalid values} +-\Status{Implemented} +-} +- +-\numtest{32}{ +-\Priority{High} +-\Reason{Return BAD_STRUCT_VERSION when the mask bits are not set} +-\Status{Implemented} +-} +- +-\numtest{33}{ +-\Priority{High} +-\Reason{Return OLD_STRUCT_VERSION when attempting to use an old/unsupported +- structure version} +-\Status{Implemented} +-} +- +-\numtest{34}{ +-\Priority{High} +-\Reason{Return NEW_STRUCT_VERSION when attempting to use a newer version of +- of the structure then what is supported} +-\Status{Implemented} +-} +- +-\numtest{35}{ +-\Priority{High} +-\Reason{Return BAD_API_VERSION when the mask bits are set to invalid values} +-\Status{Implemented} +-} +- +-\numtest{36}{ +-\Priority{High} +-\Reason{Return BAD_API_VERSION when the mask bits are not set} +-\Status{Implemented} +-} +- +-\numtest{37}{ +-\Priority{High} +-\Reason{Return OLD_LIB_API_VERSION when using an old/unsuppored +- api version number} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{38}{ +-\Priority{High} +-\Reason{Return OLD_SERVER_API_VERSION attempting to use an +- old/unsupported api version number} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{39}{ +-\Priority{High} +-\Reason{Return NEW_LIB_API_VERSION when using a newer api +- version number then supported} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{40}{ +-\Priority{High} +-\Reason{Return NEW_SERVER_API_VERSION when using a newer api version +- number then supported} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{41}{ +-\Priority{High} +-\Reason{Return BAD_XXX_VERSION when the API and the structure +- version numbers are reversed} +-\Status{Implemented} +-} +- +-\numtest{42}{ +-\Priority{High} +-\Reason{Succeeds when using valid api and struct version numbers and masks} +-\Status{Implemented} +-} +- +-\numtest{43}{ +-\Priority{Low} +-\Reason{Returns two different server handle when called twice with same info} +-} +- +-\numtest{44}{ +-\Priority{Low} +-\Reason{Returns two different server handles when called twice with +- different info} +-} +- +-\numtest{45}{ +-\Priority{Bug fix, secure-install/3390} +-\Reason{Returns SECURE_PRINC_MISSING when ADMIN_SERVICE does not +-exist.} +-\Status{Implemented} +-} +- +-\numtest{46}{ +-\Priority{Bug fix, secure-install/3390} +-\Reason{Returns SECURE_PRINC_MISSING when CHANGEPW_SERVICE does not +-exist.} +-\Status{Implemented} +-} +- +-\numtest{100}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the profile field of the configuration parameters, if +-set.} +-\Status{Implemented} +-} +- +-\numtest{101}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the kadmind_port field of the configuration parameters, +-if set.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{102}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the admin_server field of the configuration parameters, +-if set with only an admin server name.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{102.5}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the admin_server field of the configuration parameters, +-if set with a host name and port number.} +-\Conditions{RPC} +-} +- +-\numtest{103}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the dbname field of the configuration parameters, if +-set.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{104}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the admin_dbname field of the configuration parameters, if +-set.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{105}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the admin_lockfile field of the configuration parameters, if +-set.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{106}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the mkey_from_kbd field of the configuration parameters, if +-set.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{107}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the stash_file field of the configuration parameters, if +-set.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{108}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the mkey_name field of the configuration parameters, if +-set.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{109}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the max_life field of the configuration parameters, if +-set.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{110}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the max_rlife field of the configuration parameters, if +-set.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{111}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the expiration field of the configuration parameters, if +-set.} +-\Status{Implemented} +-\Conditions{local} +-} +- +-\numtest{112}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the flags field of the configuration parameters, if +-set.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{113}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Obeys the keysalts and num_keysalts field of the configuration +-parameters, if set.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{114}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Returns KADM5_BAD_SERVER_PARAMS if any client-only parameters +-are specified to server-side init.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{115}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Returns KADM5_BAD_CLIENT_PARAMS if any client-only parameters +-are specified to server-side init.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{116}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Two calls to init with clients having different privileges +-succeeds, and both clients maintain their correct privileges.} +-\Priority{Bug fix} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{117}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{The max_life field defaults to value specified in the API +-Functional Specification when kdc.conf is unreadable.} +-\Priority{Bug fix, krb5-admin/18} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{150}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{init_with_creds works when given an open ccache with a valid +-credential for ADMIN_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{151}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{init_with_creds works when given an open ccache with a valid +-credential for CHANGEPW_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{152}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{init_with_creds fails with KRB5_FCC_NOFILE (was +- KADM5_GSS_ERROR) when given an open +-ccache with no credentials.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{153}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{init_with_creds fails with KRB5_CC_NOTFOUND (was +- KADM5_GSS_ERROR) when given an open +-ccache without credentials for ADMIN_SERVICE or CHANGEPW_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{154}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{If the KRB5_KDC_PROFILE environment variable is set to a filename +-that does not exist, init fails with ENOENT.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\section{ovsec_kadm_destroy} +- +-\numtest{1}{ +-\Reason{Valid invocation.} +-\Status{Implemented} +-} +- +-%\numtest{2}{ +-%\Reason{Valid invocation (``get'' not allowed after destroy).} +-%\Status{Implemented} +-%} +- +-%\numtest{3}{ +-%\Reason{Valid invocation (``add'' not allowed after destroy).} +-%\Status{Implemented} +-%} +- +-%\numtest{4}{ +-%\Reason{Valid invocation (``modify'' not allowed after destroy).} +-%\Status{Implemented} +-%} +- +-%\numtest{5}{ +-%\Reason{Valid invocation (``delete'' not allowed after destroy).} +-%\Status{Implemented} +-%} +- +-%\numtest{6}{ +-%\Reason{Fails if database not initialized.} +-%\Status{Implemented} +-%} +- +-%\numtest{7}{ +-%\Reason{Fails if invoked twice in a row.} +-%\Status{Implemented} +-%} +- +-\numtest{8}{ +-\Reason{Database can be reinitialized after destroy.} +-\Status{Implemented} +-} +- +-\numtest{9}{ +-\Priority{High} +-\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} +-\Status{Implemented} +-} +- +-\numtest{10}{ +-\Priority{Low} +-\Reason{Connects to correct server when multiple handles exist} +-\Conditions{client} +-} +- +-\section{ovsec_kadm_create_principal} +- +-%In the tests below, ``getu'' refers to a user who has only ``get'' access, +-%''addu'' refers to a user who has only ``add'' access, ``modifyu'' refers to +-%a user who has only ``modify'' access, and ``deleteu'' refers to a user +-%who has only ``delete'' access. ``amu'' refers to a user with ``add'' and +-%''modify'' access. ``new_princ'' refers to a principal entry structure +-%filled in as follows: +-% +-% krb5_parse_name("newuser", \&new_princ.principal); +-% krb5_timeofday(\&new_princ.princ_expire_time); +-% new_princ.princ_expire_time += 130; +-% krb5_timeofday(\&new_princ.last_pwd_change); +-% new_princ.last_pwd_change += 140; +-% krb5_timeofday(\&new_princ.pw_expiration); +-% new_princ.pw_expiration += 150; +-% new_princ.max_life = 160; +-% krb5_parse_name("usera", \&new_princ.mod_name); +-% krb5_timeofday(\&new_princ.mod_date); +-% new_princ.mod_date += 170; +-% new_princ.attributes = 0xabcdabcd; +-% new_princ.kvno = 180; +-% new_princ.mkvno = 190; +-% new_princ.policy = null; +-% new_princ.aux_attributes = 0xdeadbeef; +-% +-%The offsets of 130 through 190 above are used to ensure that the +-%fields are all known to be different from each other, so that +-%accidentally switched fields can be detected. Some of the fields in +-%this structure may be changed by the tests, but they should clean up +-%after themselves. +- +-%\numtest{1}{ +-%\Reason{Fails if database not initialized.} +-%\Status{Implemented} +-%} +- +-\numtest{2}{ +-\Reason{Fails on null princ argument.} +-\Status{Implemented} +-} +- +-\numtest{3}{ +-\Reason{Fails on null password argument.} +-\Status{Implemented} +-} +- +-\numtest{4}{ +-\Reason{Fails on empty-string password argument.} +-\Status{Implemented} +-} +- +-\numtest{5}{ +-\Reason{Fails when mask contains undefined bit.} +-\Status{Implemented} +-} +- +-\numtest{6}{ +-\Reason{Fails when mask contains LAST_PWD_CHANGE bit.} +-\Status{Implemented} +-} +- +-\numtest{7}{ +-\Reason{Fails when mask contains MOD_TIME bit.} +-\Status{Implemented} +-} +- +-\numtest{8}{ +-\Reason{Fails when mask contains MOD_NAME bit.} +-\Status{Implemented} +-} +- +-\numtest{9}{ +-\Reason{Fails when mask contains MKVNO bit.} +-\Status{Implemented} +-} +- +-\numtest{10}{ +-\Reason{Fails when mask contains AUX_ATTRIBUTES bit.} +-\Status{Implemented} +-} +- +-\numtest{11}{ +-\Reason{Fails when mask contains POLICY_CLR bit.} +-\Status{Implemented} +-} +- +-\numtest{12}{ +-\Reason{Fails for caller with no access bits.} +-\Status{Implemented} +-} +- +-\numtest{13}{ +-\Reason{Fails when caller has ``get'' access and not ``add''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{14}{ +-\Reason{Fails when caller has ``modify'' access and not ``add''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{15}{ +-\Reason{Fails when caller has ``delete'' access and not ``add''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{16}{ +-\Reason{Fails when caller connected with CHANGEPW_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{17}{ +-\Reason{Fails on attempt to create existing principal.} +-\Status{Implemented} +-} +- +-\numtest{18}{ +-\Reason{Fails when password is too short.} +-\Status{Implemented} +-} +- +-\numtest{19}{ +-\Reason{Fails when password has too few classes.} +-\Status{Implemented} +-} +- +-\numtest{20}{ +-\Reason{Fails when password is in dictionary.} +-\Status{Implemented} +-} +- +-\numtest{21}{ +-\Reason{Nonexistent policy is rejected.} +-\Status{Implemented} +-} +- +-\numtest{22}{ +-\Reason{Fails on invalid principal name.} +-\Status{Implemented} +-} +- +-\numtest{23}{ +-\Reason{Valid invocation.} +-\Status{Implemented} +-} +- +-\numtest{24}{ +-\Reason{Succeeds when caller has ``add'' access and another one.} +-\Status{Implemented} +-} +- +-%\numtest{25}{ +-%\Reason{Fails when password is too short, when override_qual is true.} +-%} +- +-%\numtest{26}{ +-%\Reason{Fails when password has too few classes, when +-% override_qual is true.} +-%} +- +-%\numtest{27}{ +-%\Reason{Fails when password is in dictionary, when override_qual is +-% true.} +-%} +- +-\numtest{28}{ +-\Reason{Succeeds when assigning policy.} +-\Status{Implemented} +-} +- +-\numtest{29}{ +-\Priority{High} +-\Reason{Allows 0 (never) for princ_expire_time.} +-\Status{Implemented} +-} +- +-\numtest{30}{ +-\Reason{Allows 0 (never) for pw_expiration when there's no policy.} +-\Status{Implemented} +-} +- +-\numtest{31}{ +-\Reason{Allows 0 (never) for pw_expiration when there's a policy with +- 0 for pw_max_life.} +-\Status{Implemented} +-} +- +-\numtest{32}{ +-\Reason{Accepts 0 (never) for pw_expiration when there's a policy with +- non-zero pw_max_life, and sets pw_expiration to zero.} +-\Status{Implemented} +-} +- +-\numtest{33}{ +-\Reason{Accepts and sets non-zero pw_expiration when no policy.} +-\Status{Implemented} +-} +- +-\numtest{34}{ +-\Reason{Accepts and sets non-zero pw_expiration when there's a policy +- with zero pw_max_life.} +-\Status{Implemented} +-} +- +-\numtest{35}{ +-\Reason{Accepts and sets non-zero pw_expiration when there's a policy +- with pw_max_life later than the specified pw_expiration.} +-\Status{Implemented} +-} +- +-\numtest{36}{ +-\Reason{Accepts and sets non-zero pw_expiration greater than now_pw_max_life.} +-\Status{Implemented} +-} +- +-\numtest{37}{ +-\Priority{High} +-\Reason{Sets pw_expiration to 0 (never) if there's no policy and no +- specified pw_expiration.} +-\Status{Implemented} +-} +- +-\numtest{38}{ +-\Priority{High} +-\Reason{Sets pw_expiration to 0 (never) if it isn't specified and the +- policy has a 0 (never) pw_max_life.} +-\Status{Implemented} +-} +- +-\numtest{39}{ +-\Priority{High} +-\Reason{Sets pw_expiration to now + pw_max_life if it isn't specified +- and the policy has a non-zero pw_max_life.} +-\Status{Implemented} +-} +- +-\numtest{40}{ +-\Priority{High} +-\Reason{Allows 0 (forever) for max_life.} +-\Status{Implemented} +-} +- +-\numtest{41}{ +-\Priority{High} +-\Reason{Doesn't modify or free mod_name on success.} +-} +- +-\numtest{42}{ +-\Priority{High} +-\Reason{Doesn't modify or free mod_name on failure.} +-} +- +-\numtest{43}{ +-\Priority{High} +-\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} +-\Status{Implemented} +-} +- +-\numtest{44}{ +-\Priority{Low} +-\Reason{Connects to correct server when multiple handles exist} +-\Conditions{RPC} +-} +- +- +-\section{ovsec_kadm_delete_principal} +- +-%\numtest{1}{ +-%\Reason{Fails if database not initialized.} +-%\Status{Implemented} +-%} +- +-\numtest{2}{ +-\Reason{Fails on null principal.} +-\Status{Implemented} +-} +- +-% Empty string principal is legal. +-%\numtest{3}{ +-%\Reason{Fails on empty-string principal.} +-%} +- +-% There is not invalid principal names +-%\numtest{4}{ +-%\Reason{Fails on invalid principal name.} +-%} +- +-\numtest{5}{ +-\Priority{High} +-\Reason{Fails on nonexistent principal.} +-\Status{Implemented} +-} +- +-\numtest{6}{ +-\Priority{High} +-\Reason{Fails when caller connected with CHANGEPW_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{7}{ +-\Priority{High} +-\Reason{Fails if caller has ``add'' access and not ``delete''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{8}{ +-\Priority{High} +-\Reason{Fails if caller has ``modify'' access and not ``delete''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{9}{ +-\Priority{High} +-\Reason{Fails if caller has ``get'' access and not ``delete''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{10}{ +-\Priority{High} +-\Reason{Fails if caller has no access bits.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{11}{ +-\Priority{High} +-\Reason{Valid invocation.} +-\Status{Implemented} +-} +- +-\numtest{12}{ +-\Priority{High} +-\Reason{Valid invocation (on principal with policy).} +-\Status{Implemented} +-} +- +-\numtest{13}{ +-\Priority{High} +-\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} +-\Status{Implemented} +-} +- +-\numtest{14}{ +-\Priority{Low} +-\Reason{Connects to correct server when multiple handles exist} +-\Conditions{RPC} +-} +- +- +-\section{ovsec_kadm_modify_principal} +- +-%\numtest{1}{ +-%\Reason{Fails if database not initialized.} +-%\Status{Implemented} +-%} +- +-\numtest{2}{ +-\Priority{High} +-\Reason{Fails if user connected with CHANGEPW_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{3}{ +-\Reason{Fails on mask with undefined bit set.} +-\Status{Implemented} +-} +- +-\numtest{4}{ +-\Reason{Fails on mask with PRINCIPAL set.} +-\Status{Implemented} +-} +- +-\numtest{5}{ +-\Priority{High} +-\Reason{Fails on mask with LAST_PWD_CHANGE set.} +-\Status{Implemented} +-} +- +-\numtest{6}{ +-\Reason{Fails on mask with MOD_TIME set.} +-\Status{Implemented} +-} +- +-\numtest{7}{ +-\Reason{Fails on mask with MOD_NAME set.} +-\Status{Implemented} +-} +- +-\numtest{8}{ +-\Reason{Fails on mask with MKVNO set.} +-\Status{Implemented} +-} +- +-\numtest{9}{ +-\Priority{High} +-\Reason{Fails on mask with AUX_ATTRIBUTES set.} +-\Status{Implemented} +-} +- +-\numtest{10}{ +-\Reason{Fails on nonexistent principal.} +-\Status{Implemented} +-} +- +-\numtest{11}{ +-\Priority{High} +-\Reason{Fails for user with no access bits.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{12}{ +-\Priority{High} +-\Reason{Fails for user with ``get'' access.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{13}{ +-\Priority{High} +-\Reason{Fails for user with ``add'' access.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{14}{ +-\Priority{High} +-\Reason{Fails for user with ``delete'' access.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{15}{ +-\Priority{High} +-\Reason{Succeeds for user with ``modify'' access.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{16}{ +-\Reason{Succeeds for user with ``modify'' and another access.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{17}{ +-\Priority{High} +-\Reason{Fails when nonexistent policy is specified.} +-\Status{Implemented} +-} +- +-\numtest{18}{ +-\Priority{High} +-\Reason{Succeeds when existent policy is specified.} +-\Status{Implemented} +-} +- +-\numtest{19}{ +-\Reason{Updates policy count when setting policy from none.} +-\Status{Implemented} +-} +- +-\numtest{20}{ +-\Reason{Updates policy count when clearing policy from set.} +-\Status{Implemented} +-} +- +-\numtest{21}{ +-\Reason{Updates policy count when setting policy from other policy.} +-\Status{Implemented} +-} +- +-\numtest{21.5}{ +-\Reason{Policy reference count remains unchanged when policy is +- changed to itself.} +-\Status{Implemented.} +-} +- +-\numtest{22}{ +-\Reason{Allows 0 (never) for pw_expiration when there's no policy.} +-\Status{Implemented} +-} +- +-\numtest{23}{ +-\Reason{Allows 0 (never) for pw_expiration when there's a policy with +- 0 for pw_max_life.} +-\Status{Implemented} +-} +- +-\numtest{24}{ +-\Reason{Accepts 0 (never) for pw_expiration when there's a policy with +- non-zero pw_max_life, but actually sets pw_expiration to +- last_pwd_change + pw_max_life.} +-\Status{Implemented} +-} +- +-\numtest{25}{ +-\Reason{Accepts and sets non-zero pw_expiration when no policy.} +-\Status{Implemented} +-} +- +-\numtest{26}{ +-\Reason{Accepts and sets non-zero pw_expiration when there's a policy +- with zero pw_max_life.} +-\Status{Implemented} +-} +- +-\numtest{27}{ +-\Reason{Accepts and sets non-zero pw_expiration when there's a policy +- with pw_max_life later than the specified pw_expiration.} +-\Status{Implemented} +-} +- +-\numtest{28}{ +-\Reason{Accepts non-zero pw_expiration and limits it to last_pwd_change + +- pw_max_life when it's later than last_pwd_change + non-zero +- pw_max_life in policy.} +-\Status{Implemented} +-} +- +-\numtest{29}{ +-\Priority{High} +-\Reason{Sets pw_expiration to 0 (never) when a policy is cleared and +-no pw_expiration is specified.} +-\Status{Implemented} +-} +- +-\numtest{30}{ +-\Priority{High} +-\Reason{Sets pw_expiration to 0 (never) if it isn't specified and the +- new policy has a 0 (never) pw_max_life.} +-\Status{Implemented} +-} +- +-\numtest{31}{ +-\Priority{High} +-\Reason{Sets pw_expiration to now + pw_max_life if it isn't specified +- and the new policy has a non-zero pw_max_life.} +-\Status{Implemented} +-} +- +-\numtest{32}{ +-\Priority{High} +-\Reason{Accepts princ_expire_time change.} +-\Status{Implemented} +-} +- +- +- +-\numtest{33}{ +-\Priority{High} +-\Reason{Accepts attributes change.} +-\Status{Implemented} +-} +- +-\numtest{33.25}{ +-\Priority{High} +-\Reason{Accepts attributes change (KRB5_KDB_REQUIRES_PW_CHANGE).} +-\Status{Implemented} +-} +- +-\numtest{33.5}{ +-\Priority{High} +-\Reason{Accepts attributes change (KRB5_DISALLOW_TGT_BASE).} +-\Status{Implemented} +-} +- +-\numtest{33.75}{ +-\Priority{High} +-\Reason{Accepts attributes change (KRB5_PW_CHANGE_SERVICE).} +-\Status{Implemented} +-} +- +-\numtest{34}{ +-\Priority{High} +-\Reason{Accepts max_life change.} +-\Status{Implemented} +-} +- +-\numtest{35}{ +-\Priority{High} +-\Reason{Accepts kvno change.} +-\Status{Implemented} +-} +- +-\numtest{36}{ +-\Reason{Behaves correctly when policy is set to the same as it was +- before.} +-\Status{Implemented} +-} +- +-\numtest{37}{ +-\Reason{Behaves properly when POLICY_CLR is specified and there was no +- policy before.} +-\Status{Implemented} +-} +- +-\numtest{38}{ +-\Priority{High} +-\Reason{Accepts 0 (never) for princ_expire_time.} +-\Status{Implemented} +-} +- +-\numtest{39}{ +-\Priority{High} +-\Reason{Accepts 0 for max_life.} +-\Status{Implemented} +-} +- +-\numtest{40}{ +-\Reason{Rejects null principal argument.} +-\Status{Implemented} +-} +- +-\numtest{41}{ +-\Priority{High} +-\Reason{Doesn't modify or free mod_name on success.} +-} +- +-\numtest{42}{ +-\Priority{High} +-\Reason{Doesn't modify or free mod_name on failure.} +-} +- +-\numtest{43}{ +-\Priority{High} +-\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} +-\Status{Implemented} +-} +- +-\numtest{44}{ +-\Priority{Low} +-\Reason{Connects to correct server when multiple handles exist} +-\Conditions{RPC} +-} +- +-\numtest{100}{ +-\Version{KADM5_API_VERSION_2} +-\Priority{bug-fix} +-\Reason{Accepts max_rlife change.} +-\Status{Implemented} +-} +- +-\numtest{101}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Rejects last_success change.} +-\Status{Implemented} +-} +- +-\numtest{102}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Rejects last_failed change.} +-\Status{Implemented} +-} +- +-\numtest{103}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Rejects fail_auth_count change.} +-\Status{Implemented} +-} +- +-\numtest{103.5}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Rejects key_data change.} +-\Status{Implemented} +-} +- +-\numtest{104}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Accepts tl_data change when all types are greater than 256.} +-\Status{Implemented} +-} +- +-\numtest{105}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Returns KADM5_BAD_TL_TYPE when given tl_data with a type less +-than 256.} +-\Status{Implemented} +-} +- +-\section{ovsec_kadm_rename_principal} +- +-%\numtest{1}{ +-%\Reason{Fails if database not initialized.} +-%\Status{Implemented} +-%} +- +-\numtest{2}{ +-\Priority{High} +-\Reason{Fails if user connected with CHANGEPW_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{3}{ +-\Priority{High} +-\Reason{Fails for user with no access bits.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{4}{ +-\Reason{Fails for user with ``modify'' access and not ``add'' or +-``delete''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{5}{ +-\Reason{Fails for user with ``get'' access and not ``add'' or +-``delete''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{6}{ +-\Reason{Fails for user with ``modify'' and ``add'' but not ``delete''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{7}{ +-\Reason{Fails for user with ``modify'' and ``delete'' but not ``add''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{8}{ +-\Reason{Fails for user with ``get'' and ``add'' but not ``delete''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{9}{ +-\Reason{Fails for user with ``get'' and ``delete'' but not ``add.''} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{10}{ +-\Reason{Fails for user with ``modify'', ``get'' and ``add'', but not +- ``delete''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{11}{ +-\Reason{Fails for user with ``modify'', ``get'' and ``delete'', but +- not ``add''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{12}{ +-\Priority{High} +-\Reason{Fails for user with ``add'' but not ``delete''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{13}{ +-\Priority{High} +-\Reason{Fails for user with ``delete'' but not ``add''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{14}{ +-\Priority{High} +-\Reason{Succeeds for user with ``add'' and ``delete'', when that user +-has non-name-based salt.} +-\Status{Implemented} +-} +- +-\numtest{15}{ +-\Priority{High} +-\Reason{Fails if target principal name exists.} +-\Status{Implemented} +-} +- +-\numtest{16}{ +-\Priority{High} +-\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} +-\Status{Implemented} +-} +- +-\numtest{17}{ +-\Priority{Low} +-\Reason{Connects to correct server when multiple handles exist} +-\Conditions{RPC} +-} +- +-\numtest{18}{ +-\Priority{bug fix} +-\Reason{Returns NO_RENAME_SALT when asked to rename a principal whose +-salt depends on the principal name.} +-\Status{Implemented} +-} +- +-\section{ovsec_kadm_chpass_principal} +-\label{ovseckadmchpassprincipal} +- +-\subsection{Quality/history enforcement tests} +- +-This section lists a series of tests which will be run a number of +-times, with various parameter settings (e.g., which access bits user +-has, whether user connected with ADMIN_SERVICE or CHANGEPW_SERVICE, +-etc.). The table following the +-list of tests gives the various parameter settings under which the +-tests should be run, as well which should succeed and which should +-fail for each choice of parameter settings. +- +-\subsubsection{List of tests} +- +-The test number of each of these tests is an offset from the base +-given in the table below. +- +-\numtest{1}{ +-\Priority{High} +-\Reason{With history setting of 1, change password to itself.} +-} +- +-\numtest{2}{ +-\Reason{With history setting of 2 but no password changes since +- principal creation, change password to itself.} +-} +- +-\numtest{3}{ +-\Reason{With history setting of 2 and one password change since +- principal creation, change password to itself +- and directly previous password.} +-} +- +-\numtest{4}{ +-\Priority{High} +-\Reason{With a history setting of 3 and no password changes, +- change password to itself.} +-} +- +-\numtest{5}{ +-\Priority{High} +-\Reason{With a history setting of 3 and 1 password change, +- change password to itself or previous password.} +-} +- +-\numtest{6}{ +-\Priority{High} +-\Reason{With a history setting of 3 and 2 password changes, +- change password to itself and the two previous passwords.} +-} +- +-\numtest{7}{ +-\Priority{High} +-\Reason{Change to previously unused password when now - +- last_pwd_change $<$ pw_min_life.} +-} +- +-\numtest{8}{ +-\Priority{High} +-\Reason{Change to previously unused password that doesn't contain enough +- character classes.} +-} +- +-\numtest{9}{ +-\Priority{High} +-\Reason{Change to previously unused password that's too short.} +-} +- +-\numtest{10}{ +-\Priority{High} +-\Reason{Change to previously unused password that's in the dictionary.} +-} +- +-\subsubsection{List of parameter settings} +- +-In the table below, ``7 passes'' means that test 7 above passes and +-the rest of the tests fail. +- +-\begin{tabular}{llllll} +-Base & Modify access? & Own password? & Service & Pass/Fail \\ \hline +-0 & No & Yes & ADMIN & all fail \\ +-20 & No & Yes & CHANGEPW & all fail \\ +-40 & No & No & ADMIN & all fail \\ +-60 & No & No & CHANGEPW & all fail \\ +-80 & Yes & Yes & ADMIN & 7 passes \\ +-100 & Yes & Yes & CHANGEPW & all fail \\ +-120 & Yes & No & ADMIN & 7 passes \\ +-140 & Yes & No & CHANGEPW & all fail \\ +-\end{tabular} +- +-\subsection{Other quality/history tests} +- +-\numtest{161}{ +-\Priority{High} +-\Reason{With history of 1, can change password to anything other than +- itself that doesn't conflict with other quality +- rules.} +-} +- +-\numtest{162}{ +-\Reason{With history of 2 and 2 password changes, can change password +- to original password.} +-} +- +-\numtest{163}{ +-\Priority{High} +-\Reason{With history of 3 and 3 password changes, can change password +- to original password.} +-} +- +-\numtest{164}{ +-\Priority{High} +-\Reason{Can change password when now - last_pwd_change $>$ pw_min_life.} +-} +- +-\numtest{165}{ +-\Priority{High} +-\Reason{Can change password when it contains exactly the number of +- classes required by the policy.} +-} +- +-\numtest{166}{ +-\Priority{High} +-\Reason{Can change password when it is exactly the length required by +- the policy.} +-} +- +-\numtest{167}{ +-\Priority{High} +-\Reason{Can change password to a word that isn't in the dictionary.} +-} +- +- +-\subsection{Other tests} +- +-%\numtest{168}{ +-%\Reason{Fails if database not initialized.} +-%} +- +-\numtest{169}{ +-\Reason{Fails for non-existent principal.} +-} +- +-\numtest{170}{ +-\Reason{Fails for null password.} +-} +- +-\numtest{171}{ +-\Priority{High} +-\Reason{Fails for empty-string password.} +-} +- +-\numtest{172}{ +-\Priority{High} +-\Reason{Pw_expiration is set to now + max_pw_life if policy exists and +- has non-zero max_pw_life.} +-} +- +-\numtest{173}{ +-\Priority{High} +-\Reason{Pw_expiration is set to 0 if policy exists and has zero +- max_pw_life.} +-} +- +-\numtest{174}{ +-\Priority{High} +-\Reason{Pw_expiration is set to 0 if no policy.} +-} +- +-\numtest{175}{ +-\Priority{High} +-\Reason{KRB5_KDC_REQUIRES_PWCHANGE bit is cleared when password is +- successfully changed.} +-} +- +-\numtest{176}{ +-\Priority{High} +-\Reason{Fails for user with no access bits, on other's password.} +-} +- +-\numtest{177}{ +-\Priority{High} +-\Reason{Fails for user with ``get'' but not ``modify'' access, on +- other's password.} +-} +- +-\numtest{178}{ +-\Reason{Fails for user with ``delete'' but not ``modify'' access, on +- other's password.} +-} +- +-\numtest{179}{ +-\Reason{Fails for user with ``add'' but not ``modify'' access, on +- other's password.} +-} +- +-\numtest{180}{ +-\Reason{Succeeds for user with ``get'' and ``modify'' access, on +- other's password.} +-\Status{Implemented} +-} +- +-\numtest{180.5}{ +-\Priority{High} +-\Reason{Succeeds for user with ``modify'' but not ``get'' access, on +- other's password.} +-\Conditions{RPC} +-\Status{Implemented} +-} +-\numtest{180.625}{ +-\Priority{High} +-\Reason{Fails for user with modify when connecting with CHANGEPW_SERVICE on +- others password} +-\Conditions{RPC} +-\Status{Implemented} +-} +-\numtest{180.75}{ +-\Priority{High} +-\Reason{Fails for user with modify when connecting with CHANGEPW_SERVICE +- on other's password which has expired} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-%\numtest{181}{ +-%\Reason{Password that would succeed if override_qual were false fails +-% if override_qual is true.} +-%\Expected{Returns CANNOT_OVERRIDE.} +-%} +- +-\numtest{182}{ +-\Priority{High} +-\Reason{Can not change key of ovsec_adm/history principal.} +-\Status{Implemented} +-} +- +-\numtest{183}{ +-\Priority{High} +-\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} +-\Status{Implemented} +-} +- +-\numtest{184}{ +-\Priority{Low} +-\Reason{Connects to correct server when multiple handles exist} +-\Conditions{RPC} +-} +- +-\numtest{200}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Creates a key for the principal for each unique encryption +-type/salt type in use.} +-\Status{Implemented} +-} +- +-\section{ovsec_kadm_chpass_principal_util} +- +-Rerun all the tests listed for ovsec_kadm_chpass_principal above in +-Section \ref{ovseckadmchpassprincipal}. Verify that they succeed +-and fail in the same circumstances. Also verify that in each failure +-case, the error message returned in msg_ret is as specified in the +-functional specification. +- +-Also, run the following additional tests. +- +-\numtest{1}{ +-\Reason{Null msg_ret is rejected.} +-} +- +-\numtest{2}{ +-\Priority{High} +-\Reason{New password is put into pw_ret, when it's prompted for.} +-} +- +-\numtest{3}{ +-\Priority{High} +-Reason{New password is put into pw_ret, when it's supplied by the +- caller.} +-} +- +-\numtest{4}{ +-\Priority{High} +-\Reason{Successful invocation when pw_ret is null.} +-} +- +- +- +-\section{ovsec_kadm_randkey_principal} +- +-\subsection{TOOSOON enforcement tests} +- +-This test should be run a number of times, as indicated in the table +-following it. The table also indicates the expected result of each +-run of the test. +- +-\test{ +-\Reason{Change key when now - last_pwd_change $<$ pw_min_life.} +-} +- +-\subsubsection{List of parameter settings} +- +-\begin{tabular}{llllll} +-Number & Modify Access? & Own Key? & Service & Pass/Fail & Implemented? \\ \hline +-1 & No & Yes & ADMIN & fail & Yes \\ +-3 & No & Yes & CHANGEPW & fail & Yes \\ +-5 & No & No & ADMIN & fail \\ +-7 & No & No & CHANGEPW & fail \\ +-9 & Yes & Yes & ADMIN & pass \\ +-11 & Yes & Yes & CHANGEPW & fail \\ +-13 & Yes & No & ADMIN & pass & Yes \\ +-15 & Yes & No & CHANGEPW & fail & Yes \\ +-\end{tabular} +- +-\subsection{Other tests} +- +-\numtest{17}{ +-\Reason{Fails if database not initialized.} +-} +- +-\numtest{18}{ +-\Reason{Fails for non-existent principal.} +-} +- +-\numtest{19}{ +-\Reason{Fails for null keyblock pointer.} +-} +- +-\numtest{20}{ +-\Priority{High} +-\Reason{Pw_expiration is set to now + max_pw_life if policy exists and +- has non-zero max_pw_life.} +-} +- +-\numtest{21}{ +-\Priority{High} +-\Reason{Pw_expiration is set to 0 if policy exists and has zero +- max_pw_life.} +-} +- +-\numtest{22}{ +-\Priority{High} +-\Reason{Pw_expiration is set to 0 if no policy.} +-} +- +-\numtest{23}{ +-\Priority{High} +-\Reason{KRB5_KDC_REQUIRES_PWCHANGE bit is cleared when key is +- successfully changed.} +-} +- +-\numtest{24}{ +-\Priority{High} +-\Reason{Fails for user with no access bits, on other's password.} +-} +- +-\numtest{25}{ +-\Priority{High} +-\Reason{Fails for user with ``get'' but not ``modify'' access, on +- other's password.} +-\Vtwonote{Change-password instead of modify access.} +-} +- +-\numtest{26}{ +-\Reason{Fails for user with ``delete'' but not ``modify'' access, on +- other's password.} +-\Vtwonote{Change-password instead of modify access.} +-} +- +-\numtest{27}{ +-\Reason{Fails for user with ``add'' but not ``modify'' access, on +- other's password.} +-\Vtwonote{Change-password instead of modify access.} +-} +- +-\numtest{28}{ +-\Reason{Succeeds for user with ``get'' and ``modify'' access, on +- other's password.} +-\Status{Implemented} +-\Vtwonote{Change-password instead of modify access.} +-} +- +-\numtest{28.25}{ +-\Priority{High} +-\Reason{Fails for user with get and modify access on others password +- When conneceted with CHANGEPW_SERVICE} +-\Status{Implemented} +-\Vtwonote{Change-password instead of modify access.} +-} +- +-\numtest{28.5}{ +-\Priority{High} +-\Reason{Succeeds for user with ``modify'' but not ``get'' access, on +- other's password.} +-\Status{Implemented} +-\Vtwonote{Change-password instead of modify access.} +-} +- +-\numtest{29}{ +-\Reason{The new key that's assigned is truly random. XXX not sure how +- to test this.} +-} +- +-\numtest{30}{ +-\Reason{Succeeds for own key, no other access bits when connecting with CHANGEPW service} +-\Status{Implemented} +-} +-\numtest{31}{ +-\Reason{Succeeds for own key, no other access bits when connecting with ADMIM service} +-\Status{Implemented} +-} +- +-\numtest{32}{ +-\Reason{Cannot change ovsec_adm/history key} +-\Status{Implemented} +-} +- +-\numtest{33}{ +-\Priority{High} +-\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} +-\Status{Implemented} +-} +- +-\numtest{34}{ +-\Priority{Low} +-\Reason{Connects to correct server when multiple handles exist} +-\Conditions{RPC} +-} +- +-\numtest{100}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{Returns a key for each unique encryption type specified in the +-keysalts.} +-} +- +-\section{ovsec_kadm_get_principal} +- +-\numtest{1}{ +-\Reason{Fails for null ent.} +-\Status{Implemented} +-} +- +-\numtest{2}{ +-\Reason{Fails for non-existent principal.} +-\Status{Implemented} +-} +- +-\numtest{3}{ +-\Priority{High} +-\Reason{Fails for user with no access bits, retrieving other principal.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{4}{ +-\Priority{High} +-\Reason{Fails for user with ``add'' but not ``get'', getting principal +- other than his own, using ADMIN_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{5}{ +-\Reason{Fails for user with ``modify'' but not ``get'', getting +- principal other than his own, using ADMIN_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{6}{ +-\Reason{Fails for user with ``delete'' but not ``get'', getting +- principal other than his own, using ADMIN_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{7}{ +-\Reason{Fails for user with ``delete'' but not ``get'', getting +- principal other than his own, using CHANGEPW_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{8}{ +-\Priority{High} +-\Reason{Fails for user with ``get'', getting principal other than his +- own, using CHANGEPW_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{9}{ +-\Priority{High} +-\Reason{Succeeds for user without ``get'', retrieving self, using +- ADMIN_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{10}{ +-\Reason{Succeeds for user without ``get'', retrieving self, using +- CHANGEPW_SERVICE.} +-\Status{Implemented} +-} +- +-\numtest{11}{ +-\Reason{Succeeds for user with ``get'', retrieving self, using +- ADMIN_SERVICE.} +-\Status{Implemented} +-} +- +-\numtest{12}{ +-\Reason{Succeeds for user with ``get'', retrieving self, using +- CHANGEPW_SERVICE.} +-\Status{Implemented} +-} +- +-\numtest{13}{ +-\Priority{High} +-\Reason{Succeeds for user with ``get'', retrieving other user, using +- ADMIN_SERVICE.} +-\Status{Implemented} +-} +- +-\numtest{14}{ +-\Reason{Succeeds for user with ``get'' and ``modify'', retrieving +- other principal, using ADMIN_SERVICE.} +-\Status{Implemented} +-} +- +-\numtest{15}{ +-\Priority{High} +-\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} +-\Status{Implemented} +-} +- +-\numtest{16}{ +-\Priority{Low} +-\Reason{Connects to correct server when multiple handles exist} +-\Conditions{RPC} +-} +- +-\numtest{100}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{If KADM5_PRINCIPAL_NORMAL_MASK is specified, the key_data and +-tl_data fields are NULL/zero.} +-\Status{Implemented} +-} +- +-\numtest{101}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{If KADM5_KEY_DATA is specified, the key_data fields contain +-data but the contents are all NULL.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{102}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{If KADM5_KEY_DATA is specified, the key_data fields contain +-data and the contents are all non-NULL.} +-\Conditions{local} +-\Status{Implemented} +-} +- +-\numtest{103}{ +-\Version{KADM5_API_VERSION_2} +-\Reason{If KADM5_TL_DATA is specified, the tl_data field contains the +-correct tl_data and no entries whose type is less than 256.} +-\Status{Implemented} +-} +- +- +-\section{ovsec_kadm_create_policy} +- +-\numtest{1}{ +-\Reason{Fails for mask with undefined bit set.} +-\Status{Implemented - untested} +-} +- +-\numtest{2}{ +-\Priority{High} +-\Reason{Fails if caller connected with CHANGEPW_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{3}{ +-\Reason{Fails for mask without POLICY bit set.} +-\Status{Implemented - untested} +-} +- +-\numtest{4}{ +-\Reason{Fails for mask with REF_COUNT bit set.} +-\Status{Implemented} +-} +- +-\numtest{5}{ +-\Reason{Fails for invalid policy name.} +-\Status{Implemented - untested} +-} +- +-\numtest{6}{ +-\Priority{High} +-\Reason{Fails for existing policy name.} +-\Status{Implemented} +-} +- +-\numtest{7}{ +-\Reason{Fails for null policy name.} +-\Status{Implemented - untested} +-} +- +-\numtest{8}{ +-\Priority{High} +-\Reason{Fails for empty-string policy name.} +-\Status{Implemented} +-} +- +-\numtest{9}{ +-\Priority{High} +-\Reason{Accepts 0 for pw_min_life.} +-\Status{Implemented} +-} +- +-\numtest{10}{ +-\Priority{High} +-\Reason{Accepts non-zero for pw_min_life.} +-\Status{Implemented} +-} +- +-\numtest{11}{ +-\Priority{High} +-\Reason{Accepts 0 for pw_max_life.} +-\Status{Implemented} +-} +- +-\numtest{12}{ +-\Priority{High} +-\Reason{Accepts non-zero for pw_max_life.} +-\Status{Implemented} +-} +- +-\numtest{13}{ +-\Priority{High} +-\Reason{Rejects 0 for pw_min_length.} +-\Status{Implemented} +-} +- +-\numtest{14}{ +-\Priority{High} +-\Reason{Accepts non-zero for pw_min_length.} +-\Status{Implemented} +-} +- +-\numtest{15}{ +-\Priority{High} +-\Reason{Rejects 0 for pw_min_classes.} +-\Status{Implemented} +-} +- +-\numtest{16}{ +-\Priority{High} +-\Reason{Accepts 1 for pw_min_classes.} +-\Status{Implemented} +-} +- +-\numtest{17}{ +-\Priority{High} +-\Reason{Accepts 4 for pw_min_classes.} +-\Status{Implemented} +-} +- +-\numtest{18}{ +-\Priority{High} +-\Reason{Rejects 5 for pw_min_classes.} +-\Status{Implemented} +-} +- +-\numtest{19}{ +-\Priority{High} +-\Reason{Rejects 0 for pw_history_num.} +-\Status{Implemented} +-} +- +-\numtest{20}{ +-\Priority{High} +-\Reason{Accepts 1 for pw_history_num.} +-\Status{Implemented} +-} +- +-\numtest{21}{ +-\Priority{High} +-\Reason{Accepts 10 for pw_history_num.} +-\Status{Implemented} +-} +- +-\numtest{21.5}{ +-\Reason{Rejects 11 for pw_history_num.} +-\Status{Implemented - untested} +-} +- +-\numtest{22}{ +-\Priority{High} +-\Reason{Fails for user with no access bits.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{23}{ +-\Priority{High} +-\Reason{Fails for user with ``get'' but not ``add''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{24}{ +-\Reason{Fails for user with ``modify'' but not ``add.''} +-\Conditions{RPC} +-\Status{Implemented - untested} +-} +- +-\numtest{25}{ +-\Reason{Fails for user with ``delete'' but not ``add.''} +-\Conditions{RPC} +-\Status{Implemented - untested} +-} +- +-\numtest{26}{ +-\Priority{High} +-\Reason{Succeeds for user with ``add.''} +-\Status{Implemented} +-} +- +-\numtest{27}{ +-\Reason{Succeeds for user with ``get'' and ``add.''} +-\Status{Implemented - untested} +-} +- +-\numtest{28}{ +-\Reason{Rejects null policy argument.} +-\Status{Implemented - untested} +-} +- +-\numtest{29}{ +-\Reason{Rejects pw_min_life greater than pw_max_life.} +-} +- +-\numtest{30}{ +-\Priority{High} +-\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} +-\Status{Implemented} +-} +- +-\numtest{31}{ +-\Priority{Low} +-\Reason{Connects to correct server when multiple handles exist} +-\Conditions{RPC} +-} +- +- +-\section{ovsec_kadm_delete_policy} +- +-\numtest{1}{ +-\Reason{Fails for null policy name.} +-} +- +-\numtest{2}{ +-\Priority{High} +-\Reason{Fails for empty-string policy name.} +-\Status{Implemented} +-} +- +-\numtest{3}{ +-\Reason{Fails for non-existent policy name.} +-} +- +-\numtest{4}{ +-\Reason{Fails for bad policy name.} +-} +- +-\numtest{5}{ +-\Priority{High} +-\Reason{Fails if caller connected with CHANGEPW_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{6}{ +-\Priority{High} +-\Reason{Fails for user with no access bits.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{7}{ +-\Priority{High} +-\Reason{Fails for user with ``add'' but not ``delete''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{8}{ +-\Reason{Fails for user with ``modify'' but not ``delete''.} +-\Conditions{RPC} +-} +- +-\numtest{9}{ +-\Reason{Fails for user with ``get'' but not ``delete.''} +-\Conditions{RPC} +-} +- +-\numtest{10}{ +-\Priority{High} +-\Reason{Succeeds for user with only ``delete''.} +-\Status{Implemented} +-} +- +-\numtest{11}{ +-\Reason{Succeeds for user with ``delete'' and ``add''.} +-} +- +-\numtest{12}{ +-\Priority{High} +-\Reason{Fails for policy with non-zero reference count.} +-\Status{Implemented} +-} +- +-\numtest{13}{ +-\Priority{High} +-\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} +-\Status{Implemented} +-} +- +-\numtest{14}{ +-\Priority{Low} +-\Reason{Connects to correct server when multiple handles exist} +-\Conditions{RPC} +-} +- +- +-\section{ovsec_kadm_modify_policy} +- +-\numtest{1}{ +-\Reason{Fails for mask with undefined bit set.} +-\Conditions{RPC} +-} +- +-\numtest{2}{ +-\Priority{High} +-\Reason{Fails if caller connected with CHANGEPW_SERVICE.} +-\Status{Implemented} +-} +- +-\numtest{3}{ +-\Reason{Fails for mask with POLICY bit set.} +-} +- +-\numtest{4}{ +-\Reason{Fails for mask with REF_COUNT bit set.} +-\Status{Implemented} +-} +- +-\numtest{5}{ +-\Reason{Fails for invalid policy name.} +-} +- +-\numtest{6}{ +-\Reason{Fails for non-existent policy name.} +-} +- +-\numtest{7}{ +-\Reason{Fails for null policy name.} +-} +- +-\numtest{8}{ +-\Priority{High} +-\Reason{Fails for empty-string policy name.} +-\Status{Implemented} +-} +- +-\numtest{9}{ +-\Priority{High} +-\Reason{Accepts 0 for pw_min_life.} +-\Status{Implemented} +-} +- +-\numtest{10}{ +-\Priority{High} +-\Reason{Accepts non-zero for pw_min_life.} +-\Status{Implemented} +-} +- +-\numtest{11}{ +-\Priority{High} +-\Reason{Accepts 0 for pw_max_life.} +-\Status{Implemented} +-} +- +-\numtest{12}{ +-\Priority{High} +-\Reason{Accepts non-zero for pw_max_life.} +-\Status{Implemented} +-} +- +-\numtest{13}{ +-\Priority{High} +-\Reason{Accepts 0 for pw_min_length.} +-\Status{Implemented} +-} +- +-\numtest{14}{ +-\Priority{High} +-\Reason{Accepts non-zero for pw_min_length.} +-\Status{Implemented} +-} +- +-\numtest{15}{ +-\Priority{High} +-\Reason{Rejects 0 for pw_min_classes.} +-\Status{Implemented} +-} +- +-\numtest{16}{ +-\Priority{High} +-\Reason{Accepts 1 for pw_min_classes.} +-\Status{Implemented} +-} +- +-\numtest{17}{ +-\Priority{High} +-\Reason{Accepts 4 for pw_min_classes.} +-\Status{Implemented} +-} +- +-\numtest{18}{ +-\Priority{High} +-\Reason{Rejects 5 for pw_min_classes.} +-\Status{Implemented} +-} +- +-\numtest{19}{ +-\Priority{High} +-\Reason{Rejects 0 for pw_history_num.} +-\Status{Implemented} +-} +- +-\numtest{20}{ +-\Priority{High} +-\Reason{Accepts 1 for pw_history_num.} +-\Status{Implemented} +-} +- +-\numtest{21}{ +-\Priority{High} +-\Reason{Accepts 10 for pw_history_num.} +-\Status{Implemented} +-} +- +-\numtest{22}{ +-\Priority{High} +-\Reason{Fails for user with no access bits.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{23}{ +-\Priority{High} +-\Reason{Fails for user with ``get'' but not ``modify''.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{24}{ +-\Reason{Fails for user with ``add'' but not ``modify.''} +-\Conditions{RPC} +-} +- +-\numtest{25}{ +-\Reason{Fails for user with ``delete'' but not ``modify.''} +-\Conditions{RPC} +-} +- +-\numtest{26}{ +-\Priority{High} +-\Reason{Succeeds for user with ``modify.''} +-\Status{Implemented} +-} +- +-\numtest{27}{ +-\Reason{Succeeds for user with ``get'' and ``modify.''} +-} +- +-\numtest{28}{ +-\Reason{Rejects null policy argument.} +-} +- +-\numtest{29}{ +-\Reason{Rejects change which makes pw_min_life greater than +- pw_max_life.} +-} +- +-\numtest{30}{ +-\Priority{High} +-\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} +-\Status{Implemented} +-} +- +-\numtest{31}{ +-\Priority{Low} +-\Reason{Connects to correct server when multiple handles exist} +-\Conditions{RPC} +-} +- +-\section{ovsec_kadm_get_policy} +- +-\numtest{1}{ +-\Reason{Fails for null policy.} +-} +- +-\numtest{2}{ +-\Reason{Fails for invalid policy name.} +-} +- +-\numtest{3}{ +-\Priority{High} +-\Reason{Fails for empty-string policy name.} +-\Status{Implemented} +-} +- +-\numtest{4}{ +-\Reason{Fails for non-existent policy name.} +-} +- +-\numtest{5}{ +-\Reason{Fails for null ent.} +-} +- +-\numtest{6}{ +-\Priority{High} +-\Reason{Fails for user with no access bits trying to get other's +- policy, using ADMIN_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{7}{ +-\Priority{High} +-\Reason{Fails for user with ``add'' but not ``get'' trying to get +- other's policy, using ADMIN_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{8}{ +-\Reason{Fails for user with ``modify'' but not ``get'' trying to get +- other's policy, using ADMIN_SERVICE.} +-\Conditions{RPC} +-} +- +-\numtest{9}{ +-\Reason{Fails for user with ``delete'' but not ``get'' trying to get +- other's policy, using ADMIN_SERVICE.} +-\Conditions{RPC} +-} +- +-\numtest{10}{ +-\Reason{Fails for user with ``delete'' but not ``get'' trying to get +- other's policy, using CHANGEPW_SERVICE.} +-\Conditions{RPC} +-} +- +-\numtest{11}{ +-\Priority{High} +-\Reason{Succeeds for user with only ``get'', trying to get own policy, +- using ADMIN_SERVICE.} +-\Status{Implemented} +-} +- +-\numtest{12}{ +-\Priority{High} +-\Reason{Succeeds for user with only ``get'', trying to get own policy, +- using CHANGEPW_SERVICE.} +-\Status{Implemented} +-} +- +-\numtest{13}{ +-\Reason{Succeeds for user with ``add'' and ``get'', trying to get own +- policy, using ADMIN_SERVICE.} +-} +- +-\numtest{14}{ +-\Reason{Succeeds for user with ``add'' and ``get'', trying to get own +- policy, using CHANGEPW_SERVICE.} +-} +- +-\numtest{15}{ +-\Reason{Succeeds for user without ``get'', trying to get own policy, +- using ADMIN_SERVICE.} +-} +- +-\numtest{16}{ +-\Priority{High} +-\Reason{Succeeds for user without ``get'', trying to get own policy, +- using CHANGEPW_SERVICE.} +-\Status{Implemented} +-} +- +-\numtest{17}{ +-\Priority{High} +-\Reason{Succeeds for user with ``get'', trying to get other's policy, +- using ADMIN_SERVICE.} +-\Status{Implemented} +-} +- +-\numtest{18}{ +-\Priority{High} +-\Reason{Fails for user with ``get'', trying to get other's policy, +- using CHANGEPW_SERVICE.} +-\Conditions{RPC} +-\Status{Implemented} +-} +- +-\numtest{19}{ +-\Reason{Succeeds for user with ``modify'' and ``get'', trying to get +- other's policy, using ADMIN_SERVICE.} +-} +- +-\numtest{20}{ +-\Reason{Fails for user with ``modify'' and ``get'', trying to get +- other's policy, using CHANGEPW_SERVICE.} +-} +- +-\numtest{21}{ +-\Priority{High} +-\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} +-\Status{Implemented} +-} +- +-\numtest{22}{ +-\Priority{Low} +-\Reason{Connects to correct server when multiple handles exist} +-\Conditions{RPC} +-} +- +- +-\section{ovsec_kadm_free_principal_ent} +- +-In addition to the tests listed here, a memory-leak detector such as +-TestCenter, Purify or dbmalloc should be used to verify that the +-memory freed by this function is really freed. +- +-\numtest{1}{ +-\Reason{Null princ succeeds.} +-} +- +-\numtest{2}{ +-\Reason{Non-null princ succeeds.} +-} +- +- +-\section{ovsec_kadm_free_policy_ent} +- +-In addition to the tests listed here, a memory-leak detector such as +-TestCenter, Purify or dbmalloc should be used to verify that the +-memory freed by this function is really freed. +- +-\numtest{1}{ +-\Reason{Null policy succeeds.} +-} +- +-\numtest{2}{ +-\Reason{Non-null policy succeeds.} +-} +- +- +- +-\section{ovsec_kadm_get_privs} +- +-\numtest{1}{ +-\Reason{Fails for null pointer argument.} +-} +- +-This test should be run with the 16 possible combinations of access +-bits (since there are 4 access bits, there are $2^4 = 16$ possible +-combinations of them): +- +-\numtest{2}{ +-\Priority{High} +-\Reason{Returns correct bit mask for access bits of user.} +-\Conditions{RPC} +-} +- +-This test should be run locally: +- +-\numtest{3}{ +-\Priority{High} +-\Reason{Returns 0x0f.} +-\Conditions{local} +-} +- +-\end{document} +diff --git a/src/config/pre.in b/src/config/pre.in +index 3752174c7..b2d17b077 100644 +--- a/src/config/pre.in ++++ b/src/config/pre.in +@@ -228,16 +228,8 @@ KRB5_INCSUBDIRS = \ + $(KRB5_INCDIR)/gssapi \ + $(KRB5_INCDIR)/gssrpc + +-# +-# Macros used by the KADM5 (OV-based) unit test system. +-# XXX check which of these are actually used! +-# + SKIPTESTS = $(BUILDTOP)/skiptests +-TESTDIR = $(BUILDTOP)/kadmin/testing +-STESTDIR = $(top_srcdir)/kadmin/testing +-ENV_SETUP = $(TESTDIR)/scripts/env-setup.sh +-CLNTTCL = $(TESTDIR)/util/kadm5_clnt_tcl +-SRVTCL = $(TESTDIR)/util/kadm5_srv_tcl ++ + # Dejagnu variables. + # We have to set the host with --host so that setup_xfail will work. + # If we don't set it, then the host type used is "native", which +@@ -249,14 +241,6 @@ RUNTEST = runtest $(DEJAFLAGS) + RUNPYTEST = PYTHONPATH=$(top_srcdir)/util VALGRIND="$(VALGRIND)" \ + $(PYTHON) + +-START_SERVERS = $(STESTDIR)/scripts/start_servers $(TEST_SERVER) $(TEST_PATH) +-START_SERVERS_LOCAL = $(STESTDIR)/scripts/start_servers_local +- +-STOP_SERVERS = $(STESTDIR)/scripts/stop_servers $(TEST_SERVER) $(TEST_PATH) +-STOP_SERVERS_LOCAL = $(STESTDIR)/scripts/stop_servers_local +-# +-# End of macros for the KADM5 unit test system. +-# + + transform = @program_transform_name@ + +diff --git a/src/configure.ac b/src/configure.ac +index 61778dcd0..4f16fee45 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -991,33 +991,9 @@ ath_compat= + AC_ARG_ENABLE([athena], + [ --enable-athena build with MIT Project Athena configuration], + ath_compat=compat,) +-# The following are tests for the presence of programs required for +-# kadmin testing. +-AC_CHECK_PROG(have_RUNTEST,runtest,runtest) +-AC_CHECK_PROG(have_PERL,perl,perl) +-if test "$have_PERL" = perl -a "$have_RUNTEST" = runtest -a "$TCL_LIBS" != ""; then +- DO_TEST=ok +-fi +-AC_SUBST(DO_TEST) +- +-# The following are substituted into kadmin/testing/scripts/env-setup.sh +-RBUILD=`pwd` +-AC_SUBST(RBUILD) +-case "$srcdir" in +-/*) S_TOP=$srcdir ;; +-*) S_TOP=`pwd`/$srcdir ;; +-esac +-AC_SUBST(S_TOP) +-AC_PATH_PROG(EXPECT,expect) +-# For kadmin/testing/util/Makefile.in +-if test "$TCL_LIBS" != "" ; then +- DO_ALL=tcl +-fi +-AC_SUBST(DO_ALL) ++ + KRB5_AC_PRIOCNTL_HACK +-K5_GEN_FILE(kadmin/testing/scripts/env-setup.sh:kadmin/testing/scripts/env-setup.shin) +-# for lib/kadm5 +-AC_CHECK_PROG(RUNTEST,runtest,runtest) ++ + AC_CHECK_PROG(PERL,perl,perl) + + # lib/gssapi +@@ -1552,7 +1528,7 @@ V5_AC_OUTPUT_MAKEFILE(. + + lib/rpc lib/rpc/unit-test + +- lib/kadm5 lib/kadm5/clnt lib/kadm5/srv lib/kadm5/unit-test ++ lib/kadm5 lib/kadm5/clnt lib/kadm5/srv + lib/krad + lib/apputils + +@@ -1588,7 +1564,6 @@ V5_AC_OUTPUT_MAKEFILE(. + clients/kdestroy clients/kpasswd clients/ksu clients/kswitch + + kadmin kadmin/cli kadmin/dbutil kadmin/ktutil kadmin/server +- kadmin/testing kadmin/testing/scripts kadmin/testing/util + + appl + appl/sample appl/sample/sclient appl/sample/sserver +diff --git a/src/kadmin/Makefile.in b/src/kadmin/Makefile.in +index f4061f4f7..87cfa43fd 100644 +--- a/src/kadmin/Makefile.in ++++ b/src/kadmin/Makefile.in +@@ -1,6 +1,6 @@ + mydir=kadmin + BUILDTOP=$(REL).. +-SUBDIRS = cli dbutil ktutil server testing ++SUBDIRS = cli dbutil ktutil server + + all: + +diff --git a/src/kadmin/testing/Makefile.in b/src/kadmin/testing/Makefile.in +deleted file mode 100644 +index 5b803cb23..000000000 +--- a/src/kadmin/testing/Makefile.in ++++ /dev/null +@@ -1,8 +0,0 @@ +-mydir=kadmin$(S)testing +-BUILDTOP=$(REL)..$(S).. +-SUBDIRS = scripts util +- +-all: +- +-clean: +- -$(RM) -r krb5-test-root admin_* init-* *.rcache2 ovsec-* +diff --git a/src/kadmin/testing/deps b/src/kadmin/testing/deps +deleted file mode 100644 +index 2feac3c9d..000000000 +--- a/src/kadmin/testing/deps ++++ /dev/null +@@ -1 +0,0 @@ +-# No dependencies here. +diff --git a/src/kadmin/testing/proto/kdc.conf.proto b/src/kadmin/testing/proto/kdc.conf.proto +deleted file mode 100644 +index 8a4b87de1..000000000 +--- a/src/kadmin/testing/proto/kdc.conf.proto ++++ /dev/null +@@ -1,16 +0,0 @@ +-[kdcdefaults] +- kdc_listen = 1750 +- kdc_tcp_listen = 1750 +- +-[realms] +- __REALM__ = { +- profile = __K5ROOT__/krb5.conf +- database_name = __K5ROOT__/kdb5 +- key_stash_file = __K5ROOT__/.k5.__REALM__ +- acl_file = __K5ROOT__/ovsec_adm.acl +- dict_file = __K5ROOT__/ovsec_adm.dict +- kadmind_port = 1751 +- kpasswd_port = 1752 +- master_key_type = des3-hmac-sha1 +- supported_enctypes = des3-hmac-sha1:normal aes256-cts:normal aes128-cts:normal aes256-sha2:normal aes128-sha2:normal +- } +diff --git a/src/kadmin/testing/proto/krb5.conf.proto b/src/kadmin/testing/proto/krb5.conf.proto +deleted file mode 100644 +index a1c57119c..000000000 +--- a/src/kadmin/testing/proto/krb5.conf.proto ++++ /dev/null +@@ -1,32 +0,0 @@ +-[libdefaults] +- default_realm = __REALM__ +- default_keytab_name = FILE:__K5ROOT__/keytab +- dns_fallback = no +- dns_canonicalize_hostname = fallback +- qualify_shortname = "" +- plugin_base_dir = __PLUGIN_DIR__ +- allow_weak_crypto = true +- +-[realms] +- __REALM__ = { +- kdc = __HOSTNAME__:1750 +- admin_server = __HOSTNAME__:1751 +- database_module = foobar_db2_module_blah +- } +- +-[domain_realm] +- __HOSTNAME__ = __REALM__ +- +-[logging] +- admin_server = FILE:__K5ROOT__/syslog +- kdc = FILE:__K5ROOT__/syslog +- default = FILE:__K5ROOT__/syslog +- +- +-# THIS SHOULD BE IN KDC.CONF INSTEAD! +-[dbmodules] +- db_module_dir = __MODDIR__ +- foobar_db2_module_blah = { +- db_library = db2 +- database_name = __K5ROOT__/kdb5 +- } +diff --git a/src/kadmin/testing/proto/ovsec_adm.dict b/src/kadmin/testing/proto/ovsec_adm.dict +deleted file mode 100644 +index b54e3a85e..000000000 +--- a/src/kadmin/testing/proto/ovsec_adm.dict ++++ /dev/null +@@ -1,3 +0,0 @@ +-Abyssinia +-Discordianism +-foo +diff --git a/src/kadmin/testing/scripts/Makefile.in b/src/kadmin/testing/scripts/Makefile.in +deleted file mode 100644 +index 635930511..000000000 +--- a/src/kadmin/testing/scripts/Makefile.in ++++ /dev/null +@@ -1,18 +0,0 @@ +-mydir=kadmin$(S)testing$(S)scripts +-BUILDTOP=$(REL)..$(S)..$(S).. +- +-all: env-setup.sh runenv.sh $(GEN_SCRIPTS) +- +-# Should only rebuild env_setup.sh here (use CONFIG_FILES=), but the weird krb5 +-# makefile post-processing is unconditional and would trash the makefile. +-env-setup.sh: env-setup.stamp +-env-setup.stamp: $(srcdir)/env-setup.shin $(BUILDTOP)/config.status \ +- Makefile +- (cd $(BUILDTOP) && \ +- CONFIG_FILES=$(mydir)/env-setup.sh:$(mydir)/env-setup.shin $(SHELL) \ +- config.status) +- chmod +x env-setup.sh +- touch env-setup.stamp +- +-clean: +- -rm -f env-setup.sh env-setup.stamp +diff --git a/src/kadmin/testing/scripts/deps b/src/kadmin/testing/scripts/deps +deleted file mode 100644 +index 2feac3c9d..000000000 +--- a/src/kadmin/testing/scripts/deps ++++ /dev/null +@@ -1 +0,0 @@ +-# No dependencies here. +diff --git a/src/kadmin/testing/scripts/env-setup.shin b/src/kadmin/testing/scripts/env-setup.shin +deleted file mode 100755 +index 88f8ad1aa..000000000 +--- a/src/kadmin/testing/scripts/env-setup.shin ++++ /dev/null +@@ -1,104 +0,0 @@ +-#!/bin/sh +-# +-# The KADM5 unit tests were developed to work under gmake. As a +-# result, they expect to inherit a number of environment variables. +-# Rather than rewrite the tests, we simply use this script as an +-# execution wrapper that sets all the necessary environment variables +-# before running the program specified on its command line. +-# +-# The variable settings all came from OV's config.mk. +-# +-# Usage: env-setup.sh +-# +- +-TOP=@RBUILD@/kadmin +-STOP=@S_TOP@/kadmin +-export TOP +-export STOP +-# These two may be needed in case $libdir references them. +-prefix=@prefix@ +-exec_prefix=@exec_prefix@ +-libdir=@libdir@ ; eval "libdir=$libdir"; export libdir +- +-# The shared library run time setup +-TOPLIBD=@RBUILD@/lib +-PROG_LIBPATH=-L@RBUILD@/lib +-BUILDTOP=@RBUILD@ +-# XXX kludge! +-PROG_RPATH=@RBUILD@/lib +-# This converts $(TOPLIBD) to $TOPLIBD +-cat > /tmp/env_setup$$ <<\EOF +-@KRB5_RUN_ENV@ +-EOF +- +-foo=`sed -e 's/(//g' -e 's/)//g' -e 's/\\\$\\\$/\$/g' /tmp/env_setup$$` +-eval $foo +-export @KRB5_RUN_VARS@ +- +-# This will get put in setup.csh for convenience +-KRB5_RUN_ENV_CSH=`eval echo "$foo" | \ +- sed -e 's/\([^=]*\)=\(.*\)/setenv \1 \2/g'` +-export KRB5_RUN_ENV_CSH +-rm /tmp/env_setup$$ +- +-TESTDIR=$TOP/testing; export TESTDIR +-STESTDIR=$STOP/testing; export STESTDIR +-if [ "$K5ROOT" = "" ]; then +- K5ROOT="`cd $TESTDIR; pwd`/krb5-test-root" +- export K5ROOT +-fi +- +-# If $VERBOSE_TEST is non-null, enter verbose mode. Set $VERBOSE to +-# true or false so its exit status identifies the mode. +-if test x$VERBOSE_TEST = x; then +- VERBOSE=false +-else +- VERBOSE=true +-fi +-export VERBOSE +- +-REALM=SECURE-TEST.OV.COM; export REALM +- +-if test x$EXPECT = x; then +- EXPECT=@EXPECT@; export EXPECT +-fi +- +-COMPARE_DUMP=$TESTDIR/scripts/compare_dump.pl; export COMPARE_DUMP +-INITDB=$STESTDIR/scripts/init_db; export INITDB +-SIMPLE_DUMP=$TESTDIR/scripts/simple_dump.pl; export SIMPLE_DUMP +-TCLUTIL=$STESTDIR/tcl/util.t; export TCLUTIL +-BSDDB_DUMP=$TESTDIR/util/bsddb_dump; export BSDDB_DUMP +-CLNTTCL=$TESTDIR/util/kadm5_clnt_tcl; export CLNTTCL +-SRVTCL=$TESTDIR/util/kadm5_srv_tcl; export SRVTCL +- +-HOSTNAME=`hostname | tr '[A-Z]' '[a-z]'` +-export HOSTNAME +- +-KRB5_CONFIG=$K5ROOT/krb5.conf; export KRB5_CONFIG +-KRB5_KDC_PROFILE=$K5ROOT/kdc.conf; export KRB5_KDC_PROFILE +-KRB5_KTNAME=$K5ROOT/ovsec_adm.keytab; export KRB5_KTNAME +-KRB5_CLIENT_KTNAME=$K5ROOT/client_keytab; export KRB5_CLIENT_KTNAME +-KRB5CCNAME=$K5ROOT/krb5cc_unit-test; export KRB5CCNAME +-GSS_MECH_CONFIG=$K5ROOT/mech.conf; export GSS_MECH_CONFIG +- +-# Make sure we don't get confused by translated messages +-# or localized times. +-LC_ALL=C; export LC_ALL +- +-if [ "x$PS_ALL" = "x" ]; then +- if ps auxww >/dev/null 2>&1; then +- PS_ALL="ps auxww" +- PS_PID="ps uwwp" +- elif ps -ef >/dev/null 2>&1; then +- PS_ALL="ps -ef" +- PS_PID="ps -fp" +- else +- PS_ALL="ps auxww" +- PS_PID="ps uwwp" +- echo "WARNING! Cannot auto-detect ps type, assuming BSD." +- fi +- +- export PS_ALL PS_PID +-fi +- +-exec ${1+"$@"} +diff --git a/src/kadmin/testing/scripts/init_db b/src/kadmin/testing/scripts/init_db +deleted file mode 100755 +index 216f62793..000000000 +--- a/src/kadmin/testing/scripts/init_db ++++ /dev/null +@@ -1,229 +0,0 @@ +-#!/bin/sh +- +-if $VERBOSE; then +- REDIRECT= +-else +- REDIRECT='>/dev/null' +-fi +- +-# Requires that $K5ROOT, /etc/krb.conf, and .k5.$REALM be world-writeable. +- +-if [ "$TOP" = "" ]; then +- echo "init_db: Environment variable \$TOP must point to top of build tree" 1>&2 +- exit 1 +-fi +- +-if [ "$STOP" = "" ]; then +- echo "init_db: Environment variable \$STOP must point to top of source tree" 1>&2 +- exit 1 +-fi +- +-if [ "$libdir" = "" ]; then +- echo "init_db: Environment variable \$libdir must point to library install directory" 1>&2 +- exit 1 +-fi +- +-IROOT=$TOP/.. +-ADMIN=$TOP/dbutil +-BIN=$IROOT/bin +-ETC=$IROOT/etc +-MODDIR=$TOP/../plugins/kdb +-SBIN=$TOP/keytab:$TOP/server +-DUMMY=${REALM=SECURE-TEST.OV.COM}; export REALM +- +-. ./runenv.sh +- +-if [ ! -d $MODDIR ]; then +- echo "+++" 1>&2 +- echo "+++ Error! $MODDIR does not exist!" 1>&2 +- echo "+++ The MODDIR variable should point to the directory in which" 1>&2 +- echo "+++ database modules have been installed for testing." 1>&2 +- echo "+++" 1>&2 +- exit 1 +-fi +- +-DUMMY=${TESTDIR=$TOP/testing}; export TESTDIR +-DUMMY=${STESTDIR=$STOP/testing} +-DUMMY=${SRVTCL=$TESTDIR/util/kadm5_srv_tcl}; export SRVTCL +-DUMMY=${TCLUTIL=$STESTDIR/tcl/util.t}; export TCLUTIL +- +-PATH=$ADMIN:$BIN:$ETC:$SBIN:$PATH; export PATH +- +-if [ ! -x $SRVTCL ]; then +- echo "+++" 1>&2 +- echo "+++ Error! $SRVTCL does not exist!" 1>&2 +- echo "+++ It was probably not compiled because TCL was not available. If you" 1>&2 +- echo "+++ now have TCL installed, cd into that directory, re-run configure" 1>&2 +- echo "+++ with the --with-tcl option, and then re-run make." 1>&2 +- echo "+++" 1>&2 +- +- exit 1 +-fi +- +-rm -rf $K5ROOT/* +-if [ -d $K5ROOT ]; then +- true +-else +- mkdir $K5ROOT +-fi +- +-# touch $K5ROOT/syslog +-# for pid in `$PS_ALL | awk '/syslogd/ && !/awk/ {print $2}'` ; do +-# case "$pid" in +-# xxx) ;; +-# *) +-# if $VERBOSE; then $PS_PID$pid | grep -v COMMAND; fi +-# kill -1 $pid +-# ;; +-# esac +-# done +- +-sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ +- -e "s/__HOSTNAME__/$HOSTNAME/g" \ +- -e "s#__MODDIR__#$MODDIR#g" \ +- < $STESTDIR/proto/krb5.conf.proto > $K5ROOT/krb5.conf +-sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ +- < $STESTDIR/proto/kdc.conf.proto > $K5ROOT/kdc.conf +- +-eval kdb5_util -r $REALM create -W -P mrroot -s $REDIRECT || exit 1 +- +-cp $STESTDIR/proto/ovsec_adm.dict $K5ROOT/ovsec_adm.dict +- +-cat - > /tmp/init_db$$ <<\EOF +-source $env(TCLUTIL) +-set r $env(REALM) +-if {[info exists env(USER)]} { +- set whoami $env(USER) +-} else { +- set whoami [exec whoami] +-} +- +-set cmds { +- {kadm5_init $env(SRVTCL) mrroot null \ +- [config_params {KADM5_CONFIG_REALM} $r] $KADM5_STRUCT_VERSION \ +- $KADM5_API_VERSION_3 server_handle} +- +- {kadm5_create_policy $server_handle "test-pol 0 10000 8 2 3 0 2 90 180" \ +- {KADM5_POLICY KADM5_PW_MIN_LENGTH KADM5_PW_MIN_CLASSES KADM5_PW_MAX_LIFE KADM5_PW_HISTORY_NUM KADM5_PW_MAX_FAILURE KADM5_PW_FAILURE_COUNT_INTERVAL KADM5_PW_LOCKOUT_DURATION}} +- {kadm5_create_policy $server_handle "once-a-min 10 0 0 0 0 0 0 0 0" \ +- {KADM5_POLICY KADM5_PW_MIN_LIFE}} +- {kadm5_create_policy $server_handle "dict-only 0 0 0 0 0 0 0 0 0" \ +- {KADM5_POLICY}} +- {kadm5_create_policy $server_handle [simple_policy test-pol-nopw] \ +- {KADM5_POLICY}} +- +- {kadm5_create_principal $server_handle \ +- [simple_principal testuser@$r] {KADM5_PRINCIPAL} notathena} +- {kadm5_create_principal $server_handle \ +- [simple_principal test1@$r] {KADM5_PRINCIPAL} test1} +- {kadm5_create_principal $server_handle \ +- [simple_principal test2@$r] {KADM5_PRINCIPAL} test2} +- {kadm5_create_principal $server_handle \ +- [simple_principal test3@$r] {KADM5_PRINCIPAL} test3} +- {kadm5_create_principal $server_handle \ +- [simple_principal admin@$r] {KADM5_PRINCIPAL} admin} +- {kadm5_create_principal $server_handle \ +- [simple_principal admin/get@$r] {KADM5_PRINCIPAL} admin} +- {kadm5_create_principal $server_handle \ +- [simple_principal admin/modify@$r] {KADM5_PRINCIPAL} admin} +- {kadm5_create_principal $server_handle \ +- [simple_principal admin/delete@$r] {KADM5_PRINCIPAL} admin} +- {kadm5_create_principal $server_handle \ +- [simple_principal admin/add@$r] {KADM5_PRINCIPAL} admin} +- {kadm5_create_principal $server_handle \ +- [simple_principal admin/none@$r] {KADM5_PRINCIPAL} admin} +- {kadm5_create_principal $server_handle \ +- [simple_principal admin/rename@$r] {KADM5_PRINCIPAL} admin} +- {kadm5_create_principal $server_handle \ +- [simple_principal admin/mod-add@$r] {KADM5_PRINCIPAL} admin} +- {kadm5_create_principal $server_handle \ +- [simple_principal admin/mod-delete@$r] {KADM5_PRINCIPAL} \ +- admin} +- {kadm5_create_principal $server_handle \ +- [simple_principal admin/get-add@$r] {KADM5_PRINCIPAL} admin} +- {kadm5_create_principal $server_handle \ +- [simple_principal admin/get-delete@$r] {KADM5_PRINCIPAL} \ +- admin} +- {kadm5_create_principal $server_handle \ +- [simple_principal admin/get-mod@$r] {KADM5_PRINCIPAL} admin} +- {kadm5_create_principal $server_handle \ +- [simple_principal admin/no-add@$r] {KADM5_PRINCIPAL} admin} +- {kadm5_create_principal $server_handle \ +- [simple_principal admin/no-delete@$r] {KADM5_PRINCIPAL} admin} +- {kadm5_create_principal $server_handle \ +- [princ_w_pol pol1@$r test-pol] {KADM5_PRINCIPAL \ +- KADM5_POLICY} pol111111} +- {kadm5_create_principal $server_handle \ +- [princ_w_pol pol2@$r once-a-min] {KADM5_PRINCIPAL \ +- KADM5_POLICY} pol222222} +- {kadm5_create_principal $server_handle \ +- [princ_w_pol pol3@$r dict-only] {KADM5_PRINCIPAL \ +- KADM5_POLICY} pol333333} +- {kadm5_create_principal $server_handle \ +- [princ_w_pol admin/get-pol@$r test-pol-nopw] \ +- {KADM5_PRINCIPAL KADM5_POLICY} StupidAdmin} +- {kadm5_create_principal $server_handle \ +- [princ_w_pol admin/pol@$r test-pol-nopw] {KADM5_PRINCIPAL \ +- KADM5_POLICY} StupidAdmin} +- +- {kadm5_create_principal $server_handle \ +- [simple_principal changepw/kerberos] \ +- {KADM5_PRINCIPAL} {XXX THIS IS WRONG}} +- +- {kadm5_create_principal $server_handle \ +- [simple_principal $whoami] \ +- {KADM5_PRINCIPAL} $whoami} +- +- {kadm5_create_principal $server_handle \ +- [simple_principal testkeys@$r] {KADM5_PRINCIPAL} testkeys} +- +- {kadm5_destroy $server_handle} +-} +- +-foreach cmd $cmds { +- if {[catch $cmd output]} { +- puts stderr "Error! Command: $cmd\nError: $output" +- exit 1 +- } else { +- puts stdout $output +- } +-} +-EOF +-eval "$SRVTCL < /tmp/init_db$$ $REDIRECT" +-rm /tmp/init_db$$ +- +-if [ $? -ne 0 ]; then +- echo "Error in $SRVTCL!" 1>&2 +- exit 1 +-fi +- +-cat > $K5ROOT/ovsec_adm.acl < $K5ROOT/setup.csh <&2 +- exit 1 +- fi +- +- local=0 +- hostname=$1 +- if [ $# = 1 ]; then +- rempath=`sh -c "cd $TOP && pwd"` +- else +- rempath=$2 +- fi +-fi +- +-if [ $local = 0 ]; then +- +- # Fix up the local krb5.conf to point to the remote +- sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ +- -e "s/__HOSTNAME__/$HOSTNAME/g" \ +- -e "s#__MODDIR__#$TOP/../plugins/kdb#g"\ +- -e "s#__PLUGIN_DIR__#$TOP/../plugins#g"\ +- < $STESTDIR/proto/krb5.conf.proto > $K5ROOT/krb5.conf +- +-# Using /usr/ucb/rsh and getting rid of "-k $REALM" until we get +-# around to fixing the fact that Kerberos rsh doesn't strip out "-k +-# REALM" when falling back. +- +- START_SERVERS_LOCAL=`echo $START_SERVERS_LOCAL|sed "s%$TOP%$rempath%"` +- CMD="$RSH_CMD $hostname -n \ +- \"sh -c 'VERBOSE_TEST=$VERBOSE_TEST TOP=$rempath \ +- $rempath/testing/scripts/env-setup.sh \ +- $START_SERVERS_LOCAL $rempath'\"" +- +- if $VERBOSE; then +- echo "+++" +- echo "+++ Begin execution of start_servers_local on $hostname" +- echo "+++" +- echo $CMD +- fi +- eval $CMD +- if $VERBOSE; then +- echo "+++" +- echo "+++ End execution of start_servers_local on $hostname" +- echo "+++" +- fi +-else +- $START_SERVERS_LOCAL +-fi +- +diff --git a/src/kadmin/testing/scripts/start_servers_local b/src/kadmin/testing/scripts/start_servers_local +deleted file mode 100755 +index 858e88031..000000000 +--- a/src/kadmin/testing/scripts/start_servers_local ++++ /dev/null +@@ -1,157 +0,0 @@ +-#!/bin/sh +- +-DUMMY=${TESTDIR=$TOP/testing} +-DUMMY=${STESTDIR=$STOP/testing} +-DUMMY=${INITDB=$STESTDIR/scripts/init_db} +-DUMMY=${SRVTCL=$TESTDIR/util/kadm5_srv_tcl}; export SRVTCL +-DUMMY=${STOP_SERVERS_LOCAL=$STESTDIR/scripts/stop_servers_local} +-DUMMY=${KRB5RCACHEDIR=$TESTDIR} ; export KRB5RCACHEDIR +- +-. ./runenv.sh +- +-if [ -d /usr/tmp ]; then +- usrtmp=/usr/tmp +-else +- usrtmp=/var/tmp +-fi +- +-$STOP_SERVERS_LOCAL -start_servers +- +-if $VERBOSE; then +- REDIRECT= +-else +- REDIRECT='>/dev/null' +-fi +- +-while :; do +- case $1 in +- -keysalt) +- shift +- if [ $# -gt 0 ]; then +- keysalts="$keysalts $1" +- else +- break +- fi +- ;; +- -kdcport) +- shift +- if [ $# -gt 0 ]; then +- kdcport=$1 +- else +- break +- fi +- ;; +- *) +- break +- ;; +- esac +- shift +-done +- +-if [ $# -gt 1 ]; then +- echo "Usage: $0 [-kdcport port] [-keysalts tuple] ... [top]" 1>&2 +- exit 1 +-elif [ $# = 1 ]; then +- TOP=$1 +- export TOP +-fi +- +-# create a fresh db +- +-$INITDB "$keysalts" || exit 1 +- +-# Post-process the config files based on our arguments +-if [ "$keysalts" != "" ]; then +- sedcmd="s/\([ ]*supported_enctypes =\).*/\1 $keysalts/" +- sed -e "$sedcmd" < $K5ROOT/kdc.conf > $K5ROOT/kdc.conf.new +- mv $K5ROOT/kdc.conf.new $K5ROOT/kdc.conf +-fi +-if [ "$kdcport" != "" ] ; then +- sedcmd="s/\(kdc_ports = .*\)[ ]*/\1, $kdcport/" +- sed -e "$sedcmd" < $K5ROOT/kdc.conf > $K5ROOT/kdc.conf.new +- mv $K5ROOT/kdc.conf.new $K5ROOT/kdc.conf +-fi +- +-# allow admin to krlogin as root (for cleanup) +-DUMMY=${REALM=SECURE-TEST.OV.COM}; export REALM +- +-cat - > /tmp/start_servers_local$$ <<\EOF +-if { [catch { +- source $env(STOP)/testing/tcl/util.t +- set r $env(REALM) +- set q $env(HOSTNAME) +- puts stdout [kadm5_init $env(SRVTCL) mrroot null \ +- [config_params {KADM5_CONFIG_REALM} $r] \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 server_handle] +- puts stdout [kadm5_create_principal $server_handle \ +- [simple_principal host/$q@$r] {KADM5_PRINCIPAL} notathena] +- puts stdout [kadm5_destroy $server_handle] +-} err]} { +- puts stderr "initialization error: $err" +- exit 1 +-} +-exit 0 +-EOF +-eval "$SRVTCL < /tmp/start_servers_local$$ $REDIRECT" +-x=$? +-rm /tmp/start_servers_local$$ +-if test $x != 0 ; then exit 1 ; fi +- +-# run the servers (from the build tree) +- +-adm_start_file=/tmp/adm_server_start.$$ +-kdc_start_file=/tmp/kdc_server_start.$$ +- +-rm -f $kdc_start_file +- +-if test "x$USER" = x ; then +- USER=$LOGNAME ; export USER +-fi +- +-kdc_args="-R dfl:kdc_rcache.$USER" +- +-(trap "" 2; $TOP/../kdc/krb5kdc $kdc_args; touch $kdc_start_file) \ +- < /dev/null > $usrtmp/kdc-log.$USER 2>&1 & +- +-s=1 +-max_s=60 +-sofar_s=0 +-timewait_s=300 +- +-ovadm_args=-W +- +-rm -f $adm_start_file +- +-(sleep 1; $TOP/server/kadmind $ovadm_args; \ +- touch $adm_start_file) < /dev/null > $usrtmp/kadm-log.$USER 2>&1 & +- +-# wait until they start +- +-while [ $sofar_s -le $max_s ]; do +- if $VERBOSE; then +- echo "Sleeping for $s seconds to allow servers" \ +- "to start..." +- fi +- +- sofar_s=`expr $sofar_s + $s` +- +- sleep $s +- +- if [ -f $adm_start_file -a -f $kdc_start_file ]; then +- break +- fi +-done +- +-if [ $sofar_s -gt $max_s ]; then +- echo "Admin server or KDC failed to start after $sofar_s" \ +- "seconds." 1>&2 +- if [ ! -f $adm_start_file ]; then +- echo " No admin server start file $adm_start_file." 1>&2 +- fi +- if [ ! -f $kdc_start_file ]; then +- echo " No KDC start file $adm_start_file." 1>&2 +- fi +- exit 1 +-fi +- +-rm -f $kdc_start_file $adm_start_file +diff --git a/src/kadmin/testing/scripts/stop_servers b/src/kadmin/testing/scripts/stop_servers +deleted file mode 100755 +index b7f8384ca..000000000 +--- a/src/kadmin/testing/scripts/stop_servers ++++ /dev/null +@@ -1,60 +0,0 @@ +-#!/bin/sh +-# +-# Usage: stop_servers [hostname [path]] +-# +-# This script turns a host into a OpenV*Secure primary server for the +-# realm SECURE-TEST.OV.COM. If no arguments are specified, +-# the local host is affected. Otherwise, the host hostname is +-# affected; the path argument is the top of the Secure install tree on +-# that host, and if it is not specified the current canonical value of +-# TOP is used. +- +-DUMMY=${TESTDIR=$TOP/testing} +-DUMMY=${STESTDIR=$STOP/testing} +-DUMMY=${STOP_SERVERS_LOCAL=$STESTDIR/scripts/stop_servers_local} +-# This'll be wrong sometimes +-DUMMY=${RSH_CMD=rsh} +- +-local=1 +- +-if [ $# -gt 0 ]; then +- if [ $# != 1 -a $# != 2 ]; then +- echo "Usage: $0 [hostname [path]]" 1>&2 +- exit 1 +- fi +- +- local=0 +- hostname=$1 +- if [ $# = 1 ]; then +- rempath=`sh -c "cd $TOP && pwd"` +- else +- rempath=$2 +- fi +-fi +- +-if [ $local = 0 ]; then +- if $VERBOSE; then +- echo "+++ Stopping servers on remote host $hostname..." +- fi +- +- STOP_SERVERS_LOCAL=`echo $STOP_SERVERS_LOCAL | sed "s%$TOP%$rempath%"` +- CMD="$RSH_CMD $hostname -n \ +- \"sh -c 'VERBOSE_TEST=$VERBOSE_TEST TOP=$rempath \ +- $rempath/testing/scripts/env-setup.sh \ +- $STOP_SERVERS_LOCAL $rempath'\"" +- +- if $VERBOSE; then +- echo "+++" +- echo "+++ Begin execution of stop_servers_local on $hostname" +- echo "+++" +- echo $CMD +- fi +- eval $CMD +- if $VERBOSE; then +- echo "+++" +- echo "+++ End execution of stop_servers_local on $hostname" +- echo "+++" +- fi +-else +- $STOP_SERVERS_LOCAL +-fi +diff --git a/src/kadmin/testing/scripts/stop_servers_local b/src/kadmin/testing/scripts/stop_servers_local +deleted file mode 100755 +index 24a9de7b3..000000000 +--- a/src/kadmin/testing/scripts/stop_servers_local ++++ /dev/null +@@ -1,44 +0,0 @@ +-#!/bin/sh +- +-DUMMY=${TESTDIR=$TOP/testing} +-DUMMY=${KRB5RCACHEDIR=$TESTDIR} +- +-while [ $# -gt 0 ] ; do +- case $1 in +- -start_servers) +- start_servers=$1 +- ;; +- *) +- TOP=$1 +- export TOP +- ;; +- esac +- shift +-done +- +-# kill any running servers. +- +-if $VERBOSE; then echo "Killing servers:"; fi +- +-for pid in xxx \ +- `$PS_ALL | grep krb5kdc | grep -v grep | awk '{print $2}'` \ +- `$PS_ALL | grep kadmind | grep -v grep | awk '{print $2}'` \ +- ; do +- case "$pid" in +- xxx) +- ;; +- *) +- if $VERBOSE; then $PS_PID$pid | grep -v COMMAND; fi +- kill $pid +- ;; +- esac +-done +- +-# Destroy the kdc replay cache so we don't lose if we try to run the +-# KDC as another unix user. +-if test "x$USER" = x ; then +- USER=$LOGNAME +-fi +-rm -f $KRB5RCACHEDIR/krb5kdc_rcache.$USER +- +-exit 0 +diff --git a/src/kadmin/testing/tcl/util.t b/src/kadmin/testing/tcl/util.t +deleted file mode 100644 +index 6751f89e6..000000000 +--- a/src/kadmin/testing/tcl/util.t ++++ /dev/null +@@ -1,58 +0,0 @@ +-proc simple_principal {name} { +- return "{$name} 0 0 0 0 {$name} 0 0 0 0 null 0" +-} +- +-proc princ_w_pol {name policy} { +- return "{$name} 0 0 0 0 {$name} 0 0 0 0 {$policy} 0" +-} +- +-proc simple_policy {name} { +- return "{$name} 0 0 0 0 0 0 0 0 0" +-} +- +-proc config_params {masks values} { +- if {[llength $masks] != [llength $values]} { +- error "config_params: length of mask and values differ" +- } +- +- set params [list $masks 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 {}] +- for {set i 0} {$i < [llength $masks]} {incr i} { +- set mask [lindex $masks $i] +- set value [lindex $values $i] +- switch -glob -- $mask { +- "KADM5_CONFIG_REALM" {set params [lreplace $params 1 1 $value]} +- "KADM5_CONFIG_KADMIND_PORT" { +- set params [lreplace $params 2 2 $value]} +- "KADM5_CONFIG_ADMIN_SERVER" { +- set params [lreplace $params 3 3 $value]} +- "KADM5_CONFIG_DBNAME" {set params [lreplace $params 4 4 $value]} +- "KADM5_CONFIG_ADBNAME" {set params [lreplace $params 5 5 $value]} +- "KADM5_CONFIG_ADB_LOCKFILE" { +- set params [lreplace $params 6 6 $value]} +- "KADM5_CONFIG_ACL_FILE" {set params [lreplace $params 8 8 $value]} +- "KADM5_CONFIG_DICT_FILE" { +- set params [lreplace $params 9 9 $value]} +- "KADM5_CONFIG_MKEY_FROM_KBD" { +- set params [lreplace $params 10 10 $value]} +- "KADM5_CONFIG_STASH_FILE" { +- set params [lreplace $params 11 11 $value]} +- "KADM5_CONFIG_MKEY_NAME" { +- set params [lreplace $params 12 12 $value]} +- "KADM5_CONFIG_ENCTYPE" {set params [lreplace $params 13 13 $value]} +- "KADM5_CONFIG_MAX_LIFE" { +- set params [lreplace $params 14 14 $value]} +- "KADM5_CONFIG_MAX_RLIFE" { +- set params [lreplace $params 15 15 $value]} +- "KADM5_CONFIG_EXPIRATION" { +- set params [lreplace $params 16 16 $value]} +- "KADM5_CONFIG_FLAGS" {set params [lreplace $params 17 17 $value]} +- "KADM5_CONFIG_ENCTYPES" { +- set params [lreplace $params 18 19 [llength $value] $value]} +- "*" {error "config_params: unknown mask $mask"} +- } +- } +- return $params +-} +- +- +- +diff --git a/src/kadmin/testing/util/Makefile.in b/src/kadmin/testing/util/Makefile.in +deleted file mode 100644 +index 7785c742e..000000000 +--- a/src/kadmin/testing/util/Makefile.in ++++ /dev/null +@@ -1,42 +0,0 @@ +-mydir=kadmin$(S)testing$(S)util +-BUILDTOP=$(REL)..$(S)..$(S).. +-LOCALINCLUDES = $(TCL_INCLUDES) -I$(BUILDTOP)/lib/kdb/ +-# Force Tcl headers to use stdarg.h, because krb5 does too, and if +-# Tcl uses varargs.h it'll just mess things up. +-DEFINES= -DHAS_STDARG +-KRB5_PTHREAD_LIB=$(THREAD_LINKOPTS) +- +-PROG_LIBPATH=-L$(TOPLIBD) $(TCL_LIBPATH) +-PROG_RPATH=$(KRB5_LIBDIR)$(TCL_RPATH) +- +-SRCS = $(srcdir)/tcl_kadm5.c $(srcdir)/test.c +-OBJS = tcl_kadm5.o test.o +- +-CLNTPROG= kadm5_clnt_tcl +-SRVPROG = kadm5_srv_tcl +- +-DO_ALL=@DO_ALL@ +- +-all: all-$(DO_ALL) +- +-all-: +- @echo "+++" +- @echo "+++ WARNING: Tcl not available. The kadm5 tests will not be run." +- @echo "+++" +- @echo 'Skipped kadm5 tests: Tcl not found' >> $(SKIPTESTS) +- +-all-tcl: $(CLNTPROG) $(SRVPROG) +- +-$(SRVPROG): $(OBJS) $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIBS) +- $(CC_LINK) -o $(SRVPROG) $(OBJS) $(TCL_MAYBE_RPATH) \ +- $(KADMSRV_LIBS) $(KRB5_PTHREAD_LIB) $(KRB5_BASE_LIBS) $(TCL_LIBS) +- +-$(CLNTPROG): $(OBJS) $(KADMCLNT_DEPLIBS) $(KRB5_BASE_DEPLIBS) +- $(CC_LINK) -o $(CLNTPROG) $(OBJS) $(TCL_MAYBE_RPATH) \ +- $(KRB5_PTHREAD_LIB) $(KADMCLNT_LIBS) $(KRB5_BASE_LIBS) $(TCL_LIBS) +- +-bsddb_dump: bsddb_dump.o +- $(CC_LINK) -o bsddb_dump bsddb_dump.o $(KADMSRV_LIBS) +- +-clean: +- $(RM) $(CLNTPROG) $(SRVPROG) +diff --git a/src/kadmin/testing/util/bsddb_dump.c b/src/kadmin/testing/util/bsddb_dump.c +deleted file mode 100644 +index 5dbe7ae9c..000000000 +--- a/src/kadmin/testing/util/bsddb_dump.c ++++ /dev/null +@@ -1,65 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * $Id$ +- */ +- +-#include +-#include +-#include +-#include +- +-main(int argc, char *argv[]) +-{ +- char *file; +- DB *db; +- DBT dbkey, dbdata; +- int code, i; +- +- HASHINFO info; +- +- info.hash = NULL; +- info.bsize = 256; +- info.ffactor = 8; +- info.nelem = 25000; +- info.lorder = 0; +- +- if (argc != 2) { +- fprintf(stderr, "usage: argv[0] dbfile\n"); +- exit(2); +- } +- +- file = argv[1]; +- +- if((db = dbopen(file, O_RDWR, 0666, DB_HASH, &info)) == NULL) { +- perror("Opening db file"); +- exit(1); +- } +- +- if ((code = (*db->seq)(db, &dbkey, &dbdata, R_FIRST)) == -1) { +- perror("starting db iteration"); +- exit(1); +- } +- +- while (code == 0) { +- for (i=0; iseq)(db, &dbkey, &dbdata, R_NEXT); +- } +- +- if (code == -1) { +- perror("during db iteration"); +- exit(1); +- } +- +- if ((*db->close)(db) == -1) { +- perror("closing db"); +- exit(1); +- } +- +- exit(0); +-} +diff --git a/src/kadmin/testing/util/deps b/src/kadmin/testing/util/deps +deleted file mode 100644 +index ca828a85c..000000000 +--- a/src/kadmin/testing/util/deps ++++ /dev/null +@@ -1,16 +0,0 @@ +-# +-# Generated makefile dependencies follow. +-# +-$(OUTPRE)tcl_kadm5.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/gssapi/gssapi.h $(BUILDTOP)/include/gssrpc/types.h \ +- $(BUILDTOP)/include/kadm5/admin.h $(BUILDTOP)/include/kadm5/chpass_util_strings.h \ +- $(BUILDTOP)/include/kadm5/kadm_err.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/lib/kdb/adb_err.h $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ +- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ +- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ +- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ +- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ +- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/kdb.h \ +- $(top_srcdir)/include/krb5.h tcl_kadm5.c tcl_kadm5.h +-$(OUTPRE)test.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- tcl_kadm5.h test.c +diff --git a/src/kadmin/testing/util/tcl_kadm5.c b/src/kadmin/testing/util/tcl_kadm5.c +deleted file mode 100644 +index 864a929c8..000000000 +--- a/src/kadmin/testing/util/tcl_kadm5.c ++++ /dev/null +@@ -1,2566 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-#include "autoconf.h" +-#include +-#include +-#if HAVE_TCL_H +-#include +-#elif HAVE_TCL_TCL_H +-#include +-#endif +-#define USE_KADM5_API_VERSION 2 +-#include +-#include +-#include +-#include +-#include +-#include "tcl_kadm5.h" +- +-struct flagval { +- char *name; +- krb5_flags val; +-}; +- +-/* XXX This should probably be in the hash table like server_handle */ +-static krb5_context context; +- +-static struct flagval krb5_flags_array[] = { +- {"KRB5_KDB_DISALLOW_POSTDATED", KRB5_KDB_DISALLOW_POSTDATED}, +- {"KRB5_KDB_DISALLOW_FORWARDABLE", KRB5_KDB_DISALLOW_FORWARDABLE}, +- {"KRB5_KDB_DISALLOW_TGT_BASED", KRB5_KDB_DISALLOW_TGT_BASED}, +- {"KRB5_KDB_DISALLOW_RENEWABLE", KRB5_KDB_DISALLOW_RENEWABLE}, +- {"KRB5_KDB_DISALLOW_PROXIABLE", KRB5_KDB_DISALLOW_PROXIABLE}, +- {"KRB5_KDB_DISALLOW_DUP_SKEY", KRB5_KDB_DISALLOW_DUP_SKEY}, +- {"KRB5_KDB_DISALLOW_ALL_TIX", KRB5_KDB_DISALLOW_ALL_TIX}, +- {"KRB5_KDB_REQUIRES_PRE_AUTH", KRB5_KDB_REQUIRES_PRE_AUTH}, +- {"KRB5_KDB_REQUIRES_HW_AUTH", KRB5_KDB_REQUIRES_HW_AUTH}, +- {"KRB5_KDB_REQUIRES_PWCHANGE", KRB5_KDB_REQUIRES_PWCHANGE}, +- {"KRB5_KDB_DISALLOW_SVR", KRB5_KDB_DISALLOW_SVR}, +- {"KRB5_KDB_PWCHANGE_SERVICE", KRB5_KDB_PWCHANGE_SERVICE} +-}; +- +-static struct flagval aux_attributes[] = { +- {"KADM5_POLICY", KADM5_POLICY} +-}; +- +-static struct flagval principal_mask_flags[] = { +- {"KADM5_PRINCIPAL", KADM5_PRINCIPAL}, +- {"KADM5_PRINC_EXPIRE_TIME", KADM5_PRINC_EXPIRE_TIME}, +- {"KADM5_PW_EXPIRATION", KADM5_PW_EXPIRATION}, +- {"KADM5_LAST_PWD_CHANGE", KADM5_LAST_PWD_CHANGE}, +- {"KADM5_ATTRIBUTES", KADM5_ATTRIBUTES}, +- {"KADM5_MAX_LIFE", KADM5_MAX_LIFE}, +- {"KADM5_MOD_TIME", KADM5_MOD_TIME}, +- {"KADM5_MOD_NAME", KADM5_MOD_NAME}, +- {"KADM5_KVNO", KADM5_KVNO}, +- {"KADM5_MKVNO", KADM5_MKVNO}, +- {"KADM5_AUX_ATTRIBUTES", KADM5_AUX_ATTRIBUTES}, +- {"KADM5_POLICY", KADM5_POLICY}, +- {"KADM5_POLICY_CLR", KADM5_POLICY_CLR}, +- {"KADM5_MAX_RLIFE", KADM5_MAX_RLIFE}, +- {"KADM5_LAST_SUCCESS", KADM5_LAST_SUCCESS}, +- {"KADM5_LAST_FAILED", KADM5_LAST_FAILED}, +- {"KADM5_FAIL_AUTH_COUNT", KADM5_FAIL_AUTH_COUNT}, +- {"KADM5_KEY_DATA", KADM5_KEY_DATA}, +- {"KADM5_TL_DATA", KADM5_TL_DATA}, +- {"KADM5_PRINCIPAL_NORMAL_MASK", KADM5_PRINCIPAL_NORMAL_MASK} +-}; +- +-static struct flagval policy_mask_flags[] = { +- {"KADM5_POLICY", KADM5_POLICY}, +- {"KADM5_PW_MAX_LIFE", KADM5_PW_MAX_LIFE}, +- {"KADM5_PW_MIN_LIFE", KADM5_PW_MIN_LIFE}, +- {"KADM5_PW_MIN_LENGTH", KADM5_PW_MIN_LENGTH}, +- {"KADM5_PW_MIN_CLASSES", KADM5_PW_MIN_CLASSES}, +- {"KADM5_PW_HISTORY_NUM", KADM5_PW_HISTORY_NUM}, +- {"KADM5_REF_COUNT", KADM5_REF_COUNT}, +- {"KADM5_PW_MAX_FAILURE", KADM5_PW_MAX_FAILURE}, +- {"KADM5_PW_FAILURE_COUNT_INTERVAL", KADM5_PW_FAILURE_COUNT_INTERVAL}, +- {"KADM5_PW_LOCKOUT_DURATION", KADM5_PW_LOCKOUT_DURATION}, +-}; +- +-static struct flagval config_mask_flags[] = { +- {"KADM5_CONFIG_REALM", KADM5_CONFIG_REALM}, +- {"KADM5_CONFIG_DBNAME", KADM5_CONFIG_DBNAME}, +- {"KADM5_CONFIG_MKEY_NAME", KADM5_CONFIG_MKEY_NAME}, +- {"KADM5_CONFIG_MAX_LIFE", KADM5_CONFIG_MAX_LIFE}, +- {"KADM5_CONFIG_MAX_RLIFE", KADM5_CONFIG_MAX_RLIFE}, +- {"KADM5_CONFIG_EXPIRATION", KADM5_CONFIG_EXPIRATION}, +- {"KADM5_CONFIG_FLAGS", KADM5_CONFIG_FLAGS}, +- {"KADM5_CONFIG_STASH_FILE", KADM5_CONFIG_STASH_FILE}, +- {"KADM5_CONFIG_ENCTYPE", KADM5_CONFIG_ENCTYPE}, +- {"KADM5_CONFIG_ADBNAME", KADM5_CONFIG_ADBNAME}, +- {"KADM5_CONFIG_ADB_LOCKFILE", KADM5_CONFIG_ADB_LOCKFILE}, +- {"KADM5_CONFIG_ACL_FILE", KADM5_CONFIG_ACL_FILE}, +- {"KADM5_CONFIG_KADMIND_PORT", KADM5_CONFIG_KADMIND_PORT}, +- {"KADM5_CONFIG_ENCTYPES", KADM5_CONFIG_ENCTYPES}, +- {"KADM5_CONFIG_ADMIN_SERVER", KADM5_CONFIG_ADMIN_SERVER}, +- {"KADM5_CONFIG_DICT_FILE", KADM5_CONFIG_DICT_FILE}, +- {"KADM5_CONFIG_MKEY_FROM_KBD", KADM5_CONFIG_MKEY_FROM_KBD}, +-}; +- +-static struct flagval priv_flags[] = { +- {"KADM5_PRIV_GET", KADM5_PRIV_GET}, +- {"KADM5_PRIV_ADD", KADM5_PRIV_ADD}, +- {"KADM5_PRIV_MODIFY", KADM5_PRIV_MODIFY}, +- {"KADM5_PRIV_DELETE", KADM5_PRIV_DELETE} +-}; +- +- +-static char *arg_error = "wrong # args"; +- +-static Tcl_HashTable *struct_table = 0; +- +-static int put_server_handle(Tcl_Interp *interp, void *handle, char **name) +-{ +- int i = 1, newPtr = 0; +- static char buf[20]; +- Tcl_HashEntry *entry; +- +- if (! struct_table) { +- if (! (struct_table = +- malloc(sizeof(*struct_table)))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- Tcl_InitHashTable(struct_table, TCL_STRING_KEYS); +- } +- +- do { +- sprintf(buf, "kadm5_handle%d", i); +- entry = Tcl_CreateHashEntry(struct_table, buf, &newPtr); +- i++; +- } while (! newPtr); +- +- Tcl_SetHashValue(entry, handle); +- +- *name = buf; +- +- return TCL_OK; +-} +- +-static int get_server_handle(Tcl_Interp *interp, const char *name, +- void **handle) +-{ +- Tcl_HashEntry *entry; +- +- if(!strcasecmp(name, "null")) +- *handle = 0; +- else { +- if (! (struct_table && +- (entry = Tcl_FindHashEntry(struct_table, name)))) { +- Tcl_AppendResult(interp, "unknown server handle ", name, 0); +- return TCL_ERROR; +- } +- *handle = (void *) Tcl_GetHashValue(entry); +- } +- return TCL_OK; +-} +- +-static int remove_server_handle(Tcl_Interp *interp, const char *name) +-{ +- Tcl_HashEntry *entry; +- +- if (! (struct_table && +- (entry = Tcl_FindHashEntry(struct_table, name)))) { +- Tcl_AppendResult(interp, "unknown server handle ", name, 0); +- return TCL_ERROR; +- } +- +- Tcl_SetHashValue(entry, NULL); +- return TCL_OK; +-} +- +-#define GET_HANDLE(num_args, ignored) \ +- void *server_handle; \ +- const char *whoami = argv[0]; \ +- argv++, argc--; \ +- if (argc != num_args + 1) { \ +- Tcl_AppendResult(interp, whoami, ": ", arg_error, 0); \ +- return TCL_ERROR; \ +- } \ +- { \ +- int ltcl_ret; \ +- if ((ltcl_ret = get_server_handle(interp, argv[0], &server_handle)) \ +- != TCL_OK) { \ +- return ltcl_ret; \ +- } \ +- } \ +- argv++, argc--; +- +-static Tcl_HashTable *create_flag_table(struct flagval *flags, int size) +-{ +- Tcl_HashTable *table; +- Tcl_HashEntry *entry; +- int i; +- +- if (! (table = (Tcl_HashTable *) malloc(sizeof(Tcl_HashTable)))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- +- Tcl_InitHashTable(table, TCL_STRING_KEYS); +- +- for (i = 0; i < size; i++) { +- int newPtr; +- +- if (! (entry = Tcl_CreateHashEntry(table, flags[i].name, &newPtr))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- +- Tcl_SetHashValue(entry, &flags[i].val); +- } +- +- return table; +-} +- +- +-static Tcl_DString *unparse_str(char *in_str) +-{ +- Tcl_DString *str; +- +- if (! (str = malloc(sizeof(*str)))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- +- Tcl_DStringInit(str); +- +- if (! in_str) { +- Tcl_DStringAppend(str, "null", -1); +- } +- else { +- Tcl_DStringAppend(str, in_str, -1); +- } +- +- return str; +-} +- +- +- +-static int parse_str(Tcl_Interp *interp, const char *in_str, char **out_str) +-{ +- if (! in_str) { +- *out_str = 0; +- } +- else if (! strcasecmp(in_str, "null")) { +- *out_str = 0; +- } +- else { +- *out_str = (char *) in_str; +- } +- return TCL_OK; +-} +- +- +-static void set_ok(Tcl_Interp *interp, char *string) +-{ +- Tcl_SetResult(interp, "OK", TCL_STATIC); +- Tcl_AppendElement(interp, "KADM5_OK"); +- Tcl_AppendElement(interp, string); +-} +- +- +- +-static Tcl_DString *unparse_err(kadm5_ret_t code) +-{ +- char *code_string; +- const char *error_string; +- Tcl_DString *dstring; +- +- switch (code) { +- case KADM5_FAILURE: code_string = "KADM5_FAILURE"; break; +- case KADM5_AUTH_GET: code_string = "KADM5_AUTH_GET"; break; +- case KADM5_AUTH_ADD: code_string = "KADM5_AUTH_ADD"; break; +- case KADM5_AUTH_MODIFY: +- code_string = "KADM5_AUTH_MODIFY"; break; +- case KADM5_AUTH_DELETE: +- code_string = "KADM5_AUTH_DELETE"; break; +- case KADM5_AUTH_INSUFFICIENT: +- code_string = "KADM5_AUTH_INSUFFICIENT"; break; +- case KADM5_BAD_DB: code_string = "KADM5_BAD_DB"; break; +- case KADM5_DUP: code_string = "KADM5_DUP"; break; +- case KADM5_RPC_ERROR: code_string = "KADM5_RPC_ERROR"; break; +- case KADM5_NO_SRV: code_string = "KADM5_NO_SRV"; break; +- case KADM5_BAD_HIST_KEY: +- code_string = "KADM5_BAD_HIST_KEY"; break; +- case KADM5_NOT_INIT: code_string = "KADM5_NOT_INIT"; break; +- case KADM5_INIT: code_string = "KADM5_INIT"; break; +- case KADM5_BAD_PASSWORD: +- code_string = "KADM5_BAD_PASSWORD"; break; +- case KADM5_UNK_PRINC: code_string = "KADM5_UNK_PRINC"; break; +- case KADM5_UNK_POLICY: code_string = "KADM5_UNK_POLICY"; break; +- case KADM5_BAD_MASK: code_string = "KADM5_BAD_MASK"; break; +- case KADM5_BAD_CLASS: code_string = "KADM5_BAD_CLASS"; break; +- case KADM5_BAD_LENGTH: code_string = "KADM5_BAD_LENGTH"; break; +- case KADM5_BAD_POLICY: code_string = "KADM5_BAD_POLICY"; break; +- case KADM5_BAD_HISTORY: code_string = "KADM5_BAD_HISTORY"; break; +- case KADM5_BAD_PRINCIPAL: +- code_string = "KADM5_BAD_PRINCIPAL"; break; +- case KADM5_BAD_AUX_ATTR: +- code_string = "KADM5_BAD_AUX_ATTR"; break; +- case KADM5_PASS_Q_TOOSHORT: +- code_string = "KADM5_PASS_Q_TOOSHORT"; break; +- case KADM5_PASS_Q_CLASS: +- code_string = "KADM5_PASS_Q_CLASS"; break; +- case KADM5_PASS_Q_DICT: +- code_string = "KADM5_PASS_Q_DICT"; break; +- case KADM5_PASS_REUSE: code_string = "KADM5_PASS_REUSE"; break; +- case KADM5_PASS_TOOSOON: +- code_string = "KADM5_PASS_TOOSOON"; break; +- case KADM5_POLICY_REF: +- code_string = "KADM5_POLICY_REF"; break; +- case KADM5_PROTECT_PRINCIPAL: +- code_string = "KADM5_PROTECT_PRINCIPAL"; break; +- case KADM5_BAD_SERVER_HANDLE: +- code_string = "KADM5_BAD_SERVER_HANDLE"; break; +- case KADM5_BAD_STRUCT_VERSION: +- code_string = "KADM5_BAD_STRUCT_VERSION"; break; +- case KADM5_OLD_STRUCT_VERSION: +- code_string = "KADM5_OLD_STRUCT_VERSION"; break; +- case KADM5_NEW_STRUCT_VERSION: +- code_string = "KADM5_NEW_STRUCT_VERSION"; break; +- case KADM5_BAD_API_VERSION: +- code_string = "KADM5_BAD_API_VERSION"; break; +- case KADM5_OLD_LIB_API_VERSION: +- code_string = "KADM5_OLD_LIB_API_VERSION"; break; +- case KADM5_OLD_SERVER_API_VERSION: +- code_string = "KADM5_OLD_SERVER_API_VERSION"; break; +- case KADM5_NEW_LIB_API_VERSION: +- code_string = "KADM5_NEW_LIB_API_VERSION"; break; +- case KADM5_NEW_SERVER_API_VERSION: +- code_string = "KADM5_NEW_SERVER_API_VERSION"; break; +- case KADM5_SECURE_PRINC_MISSING: +- code_string = "KADM5_SECURE_PRINC_MISSING"; break; +- case KADM5_NO_RENAME_SALT: +- code_string = "KADM5_NO_RENAME_SALT"; break; +- case KADM5_BAD_CLIENT_PARAMS: +- code_string = "KADM5_BAD_CLIENT_PARAMS"; break; +- case KADM5_BAD_SERVER_PARAMS: +- code_string = "KADM5_BAD_SERVER_PARAMS"; break; +- case KADM5_AUTH_LIST: +- code_string = "KADM5_AUTH_LIST"; break; +- case KADM5_AUTH_CHANGEPW: +- code_string = "KADM5_AUTH_CHANGEPW"; break; +- case KADM5_GSS_ERROR: code_string = "KADM5_GSS_ERROR"; break; +- case KADM5_BAD_TL_TYPE: code_string = "KADM5_BAD_TL_TYPE"; break; +- case KADM5_MISSING_CONF_PARAMS: +- code_string = "KADM5_MISSING_CONF_PARAMS"; break; +- case KADM5_BAD_SERVER_NAME: +- code_string = "KADM5_BAD_SERVER_NAME"; break; +- case KADM5_MISSING_KRB5_CONF_PARAMS: +- code_string = "KADM5_MISSING_KRB5_CONF_PARAMS"; break; +- case KADM5_XDR_FAILURE: code_string = "KADM5_XDR_FAILURE"; break; +- case KADM5_CANT_RESOLVE: code_string = "KADM5_CANT_RESOLVE"; break; +- +- +- case OSA_ADB_DUP: code_string = "OSA_ADB_DUP"; break; +- case OSA_ADB_NOENT: code_string = "ENOENT"; break; +- case OSA_ADB_DBINIT: code_string = "OSA_ADB_DBINIT"; break; +- case OSA_ADB_BAD_POLICY: code_string = "Bad policy name"; break; +- case OSA_ADB_BAD_PRINC: code_string = "Bad principal name"; break; +- case OSA_ADB_BAD_DB: code_string = "Invalid database."; break; +- case OSA_ADB_XDR_FAILURE: code_string = "OSA_ADB_XDR_FAILURE"; break; +- case OSA_ADB_BADLOCKMODE: code_string = "OSA_ADB_BADLOCKMODE"; break; +- case OSA_ADB_CANTLOCK_DB: code_string = "OSA_ADB_CANTLOCK_DB"; break; +- case OSA_ADB_NOTLOCKED: code_string = "OSA_ADB_NOTLOCKED"; break; +- case OSA_ADB_NOLOCKFILE: code_string = "OSA_ADB_NOLOCKFILE"; break; +- case OSA_ADB_NOEXCL_PERM: code_string = "OSA_ADB_NOEXCL_PERM"; break; +- +- case KRB5_KDB_INUSE: code_string = "KRB5_KDB_INUSE"; break; +- case KRB5_KDB_UK_SERROR: code_string = "KRB5_KDB_UK_SERROR"; break; +- case KRB5_KDB_UK_RERROR: code_string = "KRB5_KDB_UK_RERROR"; break; +- case KRB5_KDB_UNAUTH: code_string = "KRB5_KDB_UNAUTH"; break; +- case KRB5_KDB_NOENTRY: code_string = "KRB5_KDB_NOENTRY"; break; +- case KRB5_KDB_ILL_WILDCARD: code_string = "KRB5_KDB_ILL_WILDCARD"; break; +- case KRB5_KDB_DB_INUSE: code_string = "KRB5_KDB_DB_INUSE"; break; +- case KRB5_KDB_DB_CHANGED: code_string = "KRB5_KDB_DB_CHANGED"; break; +- case KRB5_KDB_TRUNCATED_RECORD: +- code_string = "KRB5_KDB_TRUNCATED_RECORD"; break; +- case KRB5_KDB_RECURSIVELOCK: +- code_string = "KRB5_KDB_RECURSIVELOCK"; break; +- case KRB5_KDB_NOTLOCKED: code_string = "KRB5_KDB_NOTLOCKED"; break; +- case KRB5_KDB_BADLOCKMODE: code_string = "KRB5_KDB_BADLOCKMODE"; break; +- case KRB5_KDB_DBNOTINITED: code_string = "KRB5_KDB_DBNOTINITED"; break; +- case KRB5_KDB_DBINITED: code_string = "KRB5_KDB_DBINITED"; break; +- case KRB5_KDB_ILLDIRECTION: code_string = "KRB5_KDB_ILLDIRECTION"; break; +- case KRB5_KDB_NOMASTERKEY: code_string = "KRB5_KDB_NOMASTERKEY"; break; +- case KRB5_KDB_BADMASTERKEY: code_string = "KRB5_KDB_BADMASTERKEY"; break; +- case KRB5_KDB_INVALIDKEYSIZE: +- code_string = "KRB5_KDB_INVALIDKEYSIZE"; break; +- case KRB5_KDB_CANTREAD_STORED: +- code_string = "KRB5_KDB_CANTREAD_STORED"; break; +- case KRB5_KDB_BADSTORED_MKEY: +- code_string = "KRB5_KDB_BADSTORED_MKEY"; break; +- case KRB5_KDB_CANTLOCK_DB: code_string = "KRB5_KDB_CANTLOCK_DB"; break; +- case KRB5_KDB_DB_CORRUPT: code_string = "KRB5_KDB_DB_CORRUPT"; break; +- +- case KRB5_PARSE_ILLCHAR: code_string = "KRB5_PARSE_ILLCHAR"; break; +- case KRB5_PARSE_MALFORMED: code_string = "KRB5_PARSE_MALFORMED"; break; +- case KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN: code_string = "KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN"; break; +- case KRB5_REALM_UNKNOWN: code_string = "KRB5_REALM_UNKNOWN"; break; +- case KRB5_KDC_UNREACH: code_string = "KRB5_KDC_UNREACH"; break; +- case KRB5_KDCREP_MODIFIED: code_string = "KRB5_KDCREP_MODIFIED"; break; +- case KRB5KRB_AP_ERR_BAD_INTEGRITY: code_string = "KRB5KRB_AP_ERR_BAD_INTEGRITY"; break; +- case KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN: code_string = "KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN"; break; +- case KRB5_CONFIG_BADFORMAT: code_string = "KRB5_CONFIG_BADFORMAT"; break; +- +- case KRB5_CC_NOTFOUND: code_string = "KRB5_CC_NOTFOUND"; break; +- case KRB5_FCC_NOFILE: code_string = "KRB5_FCC_NOFILE"; break; +- +- case EINVAL: code_string = "EINVAL"; break; +- case ENOENT: code_string = "ENOENT"; break; +- +- default: +- fprintf(stderr, "**** CODE %ld (%s) ***\n", (long) code, +- error_message (code)); +- code_string = "UNKNOWN"; +- break; +- } +- +- error_string = error_message(code); +- +- if (! (dstring = (Tcl_DString *) malloc(sizeof(Tcl_DString)))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX Do we really want to exit? Ok if this is */ +- /* just a test program, but what about if it gets */ +- /* used for other things later? */ +- } +- +- Tcl_DStringInit(dstring); +- +- if (! (Tcl_DStringAppendElement(dstring, "ERROR") && +- Tcl_DStringAppendElement(dstring, code_string) && +- Tcl_DStringAppendElement(dstring, error_string))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- +- return dstring; +-} +- +- +- +-static void stash_error(Tcl_Interp *interp, krb5_error_code code) +-{ +- Tcl_DString *dstring = unparse_err(code); +- Tcl_DStringResult(interp, dstring); +- Tcl_DStringFree(dstring); +- free(dstring); +-} +- +-static Tcl_DString *unparse_key_data(krb5_key_data *key_data, int n_key_data) +-{ +- Tcl_DString *str; +- char buf[2048]; +- int i, j; +- +- if (! (str = malloc(sizeof(*str)))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- +- Tcl_DStringInit(str); +- for (i = 0; i < n_key_data; i++) { +- krb5_key_data *key = &key_data[i]; +- +- Tcl_DStringStartSublist(str); +- sprintf(buf, "%d", key->key_data_type[0]); +- Tcl_DStringAppendElement(str, buf); +- sprintf(buf, "%d", key->key_data_ver > 1 ? +- key->key_data_type[1] : -1); +- Tcl_DStringAppendElement(str, buf); +- if (key->key_data_contents[0]) { +- sprintf(buf, "0x"); +- for (j = 0; j < key->key_data_length[0]; j++) { +- sprintf(buf + 2*(j+1), "%02x", +- key->key_data_contents[0][j]); +- } +- } else *buf = '\0'; +- Tcl_DStringAppendElement(str, buf); +- Tcl_DStringEndSublist(str); +- } +- +- return str; +-} +- +-static Tcl_DString *unparse_tl_data(krb5_tl_data *tl_data, int n_tl_data) +-{ +- Tcl_DString *str; +- char buf[2048]; +- +- if (! (str = malloc(sizeof(*str)))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- +- Tcl_DStringInit(str); +- Tcl_DStringStartSublist(str); +- for (; tl_data; tl_data = tl_data->tl_data_next) { +- Tcl_DStringStartSublist(str); +- sprintf(buf, "%d", tl_data->tl_data_type); +- Tcl_DStringAppendElement(str, buf); +- sprintf(buf, "%d", tl_data->tl_data_length); +- Tcl_DStringAppendElement(str, buf); +- Tcl_DStringAppend(str, " ", 1); +- Tcl_DStringAppend(str, (char *) tl_data->tl_data_contents, +- tl_data->tl_data_length); +- Tcl_DStringEndSublist(str); +- } +- Tcl_DStringEndSublist(str); +- +- return str; +-} +- +-static Tcl_DString *unparse_flags(struct flagval *array, int size, +- krb5_int32 flags) +-{ +- int i; +- Tcl_DString *str; +- +- if (! (str = malloc(sizeof(*str)))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- +- Tcl_DStringInit(str); +- +- for (i = 0; i < size; i++) { +- if (flags & array[i].val) { +- Tcl_DStringAppendElement(str, array[i].name); +- } +- } +- +- return str; +-} +- +- +-static int parse_flags(Tcl_Interp *interp, Tcl_HashTable *table, +- struct flagval *array, int size, const char *str, +- krb5_flags *flags) +-{ +- int tmp, argc, i, retcode = TCL_OK; +- const char **argv; +- Tcl_HashEntry *entry; +- +- if (Tcl_GetInt(interp, str, &tmp) == TCL_OK) { +- *flags = tmp; +- return TCL_OK; +- } +- Tcl_ResetResult(interp); +- +- if (Tcl_SplitList(interp, str, &argc, &argv) != TCL_OK) { +- return TCL_ERROR; +- } +- +- if (! table) { +- table = create_flag_table(array, size); +- } +- +- *flags = 0; +- +- for (i = 0; i < argc; i++) { +- if (! (entry = Tcl_FindHashEntry(table, argv[i]))) { +- Tcl_AppendResult(interp, "unknown krb5 flag ", argv[i], 0); +- retcode = TCL_ERROR; +- break; +- } +- *flags |= *(krb5_flags *) Tcl_GetHashValue(entry); +- } +- +- Tcl_Free((char *) argv); +- return(retcode); +-} +- +-static Tcl_DString *unparse_privs(krb5_flags flags) +-{ +- return unparse_flags(priv_flags, sizeof(priv_flags) / +- sizeof(struct flagval), flags); +-} +- +- +-static Tcl_DString *unparse_krb5_flags(krb5_flags flags) +-{ +- return unparse_flags(krb5_flags_array, sizeof(krb5_flags_array) / +- sizeof(struct flagval), flags); +-} +- +-static int parse_krb5_flags(Tcl_Interp *interp, const char *str, +- krb5_flags *flags) +-{ +- krb5_flags tmp; +- static Tcl_HashTable *table = 0; +- int tcl_ret; +- +- if ((tcl_ret = parse_flags(interp, table, krb5_flags_array, +- sizeof(krb5_flags_array) / +- sizeof(struct flagval), +- str, &tmp)) != TCL_OK) { +- return tcl_ret; +- } +- +- *flags = tmp; +- return TCL_OK; +-} +- +-static Tcl_DString *unparse_aux_attributes(krb5_int32 flags) +-{ +- return unparse_flags(aux_attributes, sizeof(aux_attributes) / +- sizeof(struct flagval), flags); +-} +- +- +-static int parse_aux_attributes(Tcl_Interp *interp, const char *str, +- long *flags) +-{ +- krb5_flags tmp; +- static Tcl_HashTable *table = 0; +- int tcl_ret; +- +- if ((tcl_ret = parse_flags(interp, table, aux_attributes, +- sizeof(aux_attributes) / +- sizeof(struct flagval), +- str, &tmp)) != TCL_OK) { +- return tcl_ret; +- } +- +- *flags = tmp; +- return TCL_OK; +-} +- +-static int parse_principal_mask(Tcl_Interp *interp, const char *str, +- krb5_int32 *flags) +-{ +- krb5_flags tmp; +- static Tcl_HashTable *table = 0; +- int tcl_ret; +- +- if ((tcl_ret = parse_flags(interp, table, principal_mask_flags, +- sizeof(principal_mask_flags) / +- sizeof(struct flagval), +- str, &tmp)) != TCL_OK) { +- return tcl_ret; +- } +- +- *flags = tmp; +- return TCL_OK; +-} +- +-static int parse_policy_mask(Tcl_Interp *interp, const char *str, +- krb5_int32 *flags) +-{ +- krb5_flags tmp; +- static Tcl_HashTable *table = 0; +- int tcl_ret; +- +- if ((tcl_ret = parse_flags(interp, table, policy_mask_flags, +- sizeof(policy_mask_flags) / +- sizeof(struct flagval), +- str, &tmp)) != TCL_OK) { +- return tcl_ret; +- } +- +- *flags = tmp; +- return TCL_OK; +-} +- +- +-static Tcl_DString *unparse_principal_ent(kadm5_principal_ent_t princ, +- krb5_int32 mask) +-{ +- Tcl_DString *str, *tmp_dstring; +- char *tmp; +- char buf[20]; +- krb5_error_code krb5_ret; +- +- if (! (str = malloc(sizeof(*str)))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- +- Tcl_DStringInit(str); +- +- tmp = 0; /* It looks to me from looking at the library source */ +- /* code for krb5_parse_name that the pointer passed into */ +- /* it should be initialized to 0 if I want it do be */ +- /* allocated automatically. */ +- if (mask & KADM5_PRINCIPAL) { +- krb5_ret = krb5_unparse_name(context, princ->principal, &tmp); +- if (krb5_ret) { +- /* XXX Do we want to return an error? Not sure. */ +- Tcl_DStringAppendElement(str, "[unparsable principal]"); +- } +- else { +- Tcl_DStringAppendElement(str, tmp); +- free(tmp); +- } +- } else +- Tcl_DStringAppendElement(str, "null"); +- +- sprintf(buf, "%u", (unsigned int)princ->princ_expire_time); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%u", (unsigned int)princ->last_pwd_change); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%u", (unsigned int)princ->pw_expiration); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%d", princ->max_life); +- Tcl_DStringAppendElement(str, buf); +- +- tmp = 0; +- if (mask & KADM5_MOD_NAME) { +- if ((krb5_ret = krb5_unparse_name(context, princ->mod_name, &tmp))) { +- /* XXX */ +- Tcl_DStringAppendElement(str, "[unparsable principal]"); +- } +- else { +- Tcl_DStringAppendElement(str, tmp); +- free(tmp); +- } +- } else +- Tcl_DStringAppendElement(str, "null"); +- +- sprintf(buf, "%u", (unsigned int)princ->mod_date); +- Tcl_DStringAppendElement(str, buf); +- +- if (mask & KADM5_ATTRIBUTES) { +- tmp_dstring = unparse_krb5_flags(princ->attributes); +- Tcl_DStringAppendElement(str, tmp_dstring->string); +- Tcl_DStringFree(tmp_dstring); +- free(tmp_dstring); +- } else +- Tcl_DStringAppendElement(str, "null"); +- +- sprintf(buf, "%d", princ->kvno); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%d", princ->mkvno); +- Tcl_DStringAppendElement(str, buf); +- +- /* XXX This may be dangerous, because the contents of the policy */ +- /* field are undefined if the POLICY bit isn't set. However, I */ +- /* think it's a bug for the field not to be null in that case */ +- /* anyway, so we should assume that it will be null so that we'll */ +- /* catch it if it isn't. */ +- +- tmp_dstring = unparse_str(princ->policy); +- Tcl_DStringAppendElement(str, tmp_dstring->string); +- Tcl_DStringFree(tmp_dstring); +- free(tmp_dstring); +- +- tmp_dstring = unparse_aux_attributes(princ->aux_attributes); +- Tcl_DStringAppendElement(str, tmp_dstring->string); +- Tcl_DStringFree(tmp_dstring); +- free(tmp_dstring); +- +- sprintf(buf, "%d", princ->max_renewable_life); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%u", (unsigned int)princ->last_success); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%u", (unsigned int)princ->last_failed); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%d", princ->fail_auth_count); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%d", princ->n_key_data); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%d", princ->n_tl_data); +- Tcl_DStringAppendElement(str, buf); +- +- tmp_dstring = unparse_key_data(princ->key_data, princ->n_key_data); +- Tcl_DStringAppendElement(str, tmp_dstring->string); +- Tcl_DStringFree(tmp_dstring); +- free(tmp_dstring); +- +- tmp_dstring = unparse_tl_data(princ->tl_data, princ->n_tl_data); +- Tcl_DStringAppendElement(str, tmp_dstring->string); +- Tcl_DStringFree(tmp_dstring); +- free(tmp_dstring); +- +- return str; +-} +- +-static int parse_keysalts(Tcl_Interp *interp, const char *list, +- krb5_key_salt_tuple **keysalts, +- int num_keysalts) +-{ +- const char **argv, **argv1 = NULL; +- int i, tmp, argc, argc1, retcode; +- +- *keysalts = NULL; +- if (list == NULL) +- return TCL_OK; +- +- if ((retcode = Tcl_SplitList(interp, list, &argc, &argv)) != TCL_OK) { +- return retcode; +- } +- if (argc != num_keysalts) { +- Tcl_SetResult(interp, "wrong number of keysalts", TCL_STATIC); +- retcode = TCL_ERROR; +- goto finished; +- } +- *keysalts = (krb5_key_salt_tuple *) +- malloc(sizeof(krb5_key_salt_tuple)*num_keysalts); +- for (i = 0; i < num_keysalts; i++) { +- if ((retcode = Tcl_SplitList(interp, argv[i], &argc1, &argv1)) != +- TCL_OK) { +- goto finished; +- } +- if (argc1 != 2) { +- Tcl_SetResult(interp, "wrong # of fields in keysalt", TCL_STATIC); +- retcode = TCL_ERROR; +- goto finished; +- } +- /* XXX this used to be argv1[1] too! */ +- if ((retcode = Tcl_GetInt(interp, argv1[0], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing ks_enctype"); +- retcode = TCL_ERROR; +- goto finished; +- } +- (*keysalts)[i].ks_enctype = tmp; +- if ((retcode = Tcl_GetInt(interp, argv1[1], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing ks_salttype"); +- goto finished; +- } +- (*keysalts)[i].ks_salttype = tmp; +- +- Tcl_Free((char *) argv1); +- argv1 = NULL; +- } +- +-finished: +- if (argv1) { +- Tcl_Free((char *) argv1); +- } +- Tcl_Free((char *) argv); +- return retcode; +-} +- +-static int parse_key_data(Tcl_Interp *interp, const char *list, +- krb5_key_data **key_data, +- int n_key_data) +-{ +- const char **argv = NULL; +- int argc, retcode; +- +- *key_data = NULL; +- if (list == NULL) { +- if (n_key_data != 0) { +- Tcl_SetResult(interp, "wrong number of key_datas", TCL_STATIC); +- retcode = TCL_ERROR; +- goto finished; +- } else +- return TCL_OK; +- } +- +- if ((retcode = Tcl_SplitList(interp, list, &argc, &argv)) != TCL_OK) { +- return retcode; +- } +- if (argc != n_key_data) { +- Tcl_SetResult(interp, "wrong number of key_datas", TCL_STATIC); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- if (argc != 0) { +- Tcl_SetResult(interp, "cannot parse key_data yet", TCL_STATIC); +- retcode = TCL_ERROR; +- goto finished; +- } +- +-finished: +- Tcl_Free((char *) argv); +- return retcode; +-} +- +-static int parse_tl_data(Tcl_Interp *interp, const char *list, +- krb5_tl_data **tlp, +- int n_tl_data) +-{ +- krb5_tl_data *tl, *tl2; +- const char **argv = NULL, **argv1 = NULL; +- int i, tmp, argc, argc1, retcode; +- +- *tlp = NULL; +- if (list == NULL) { +- if (n_tl_data != 0) { +- Tcl_SetResult(interp, "wrong number of tl_datas", TCL_STATIC); +- retcode = TCL_ERROR; +- goto finished; +- } else +- return TCL_OK; +- } +- +- if ((retcode = Tcl_SplitList(interp, list, &argc, &argv)) != TCL_OK) { +- return retcode; +- } +- if (argc != n_tl_data) { +- Tcl_SetResult(interp, "wrong number of tl_datas", TCL_STATIC); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- tl = tl2 = NULL; +- for (i = 0; i < n_tl_data; i++) { +- tl2 = (krb5_tl_data *) malloc(sizeof(krb5_tl_data)); +- memset(tl2, 0, sizeof(krb5_tl_data)); +- tl2->tl_data_next = tl; +- tl = tl2; +- } +- tl2 = tl; +- +- for (i = 0; i < n_tl_data; i++) { +- if ((retcode = Tcl_SplitList(interp, argv[i], &argc1, &argv1)) != +- TCL_OK) { +- goto finished; +- } +- if (argc1 != 3) { +- Tcl_SetResult(interp, "wrong # of fields in tl_data", TCL_STATIC); +- retcode = TCL_ERROR; +- goto finished; +- } +- if ((retcode = Tcl_GetInt(interp, argv1[0], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing tl_data_type"); +- retcode = TCL_ERROR; +- goto finished; +- } +- tl->tl_data_type = tmp; +- if ((retcode = Tcl_GetInt(interp, argv1[1], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing tl_data_length"); +- retcode = TCL_ERROR; +- goto finished; +- } +- tl->tl_data_length = tmp; +- if (tl->tl_data_length != strlen(argv1[2])) { +- Tcl_SetResult(interp, "length != string length", TCL_STATIC); +- retcode = TCL_ERROR; +- goto finished; +- } +- tl->tl_data_contents = (krb5_octet *) strdup(argv1[2]); +- +- Tcl_Free((char *) argv1); +- argv1 = NULL; +- tl = tl->tl_data_next; +- } +- if (tl != NULL) { +- Tcl_SetResult(interp, "tl is not NULL!", TCL_STATIC); +- retcode = TCL_ERROR; +- goto finished; +- } +- *tlp = tl2; +- +-finished: +- if (argv1) { +- Tcl_Free((char *) argv1); +- } +- Tcl_Free((char *) argv); +- return retcode; +-} +- +-static int parse_config_params(Tcl_Interp *interp, char *list, +- kadm5_config_params *params) +-{ +- static Tcl_HashTable *table = 0; +- const char **argv = NULL; +- int tmp, argc, retcode; +- +- memset(params, 0, sizeof(kadm5_config_params)); +- if (list == NULL) +- return TCL_OK; +- +- if ((retcode = Tcl_SplitList(interp, list, &argc, &argv)) != TCL_OK) { +- return retcode; +- } +- +- if (argc != 20) { +- Tcl_SetResult(interp, "wrong # args in config params structure", +- TCL_STATIC); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- if ((retcode = parse_flags(interp, table, config_mask_flags, +- sizeof(config_mask_flags) / +- sizeof(struct flagval), +- argv[0], &tmp)) != TCL_OK) { +- goto finished; +- } +- params->mask = tmp; +- +- if ((retcode = parse_str(interp, argv[1], ¶ms->realm)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing realm name"); +- retcode = TCL_ERROR; +- goto finished; +- } +- if ((retcode = Tcl_GetInt(interp, argv[2], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing kadmind_port"); +- retcode = TCL_ERROR; +- goto finished; +- } +- params->kadmind_port = tmp; +- if ((retcode = parse_str(interp, argv[3], ¶ms->admin_server)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing profile name"); +- retcode = TCL_ERROR; +- goto finished; +- } +- if ((retcode = parse_str(interp, argv[4], ¶ms->dbname)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing profile name"); +- retcode = TCL_ERROR; +- goto finished; +- } +- /* Ignore argv[5], which used to set the admin_dbname field. */ +- /* Ignore argv[6], which used to set the admin_lockfile field. */ +- /* Ignore argv[7], which used to set the admin_keytab field. */ +- if ((retcode = parse_str(interp, argv[8], ¶ms->acl_file)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing acl_file name"); +- retcode = TCL_ERROR; +- goto finished; +- } +- if ((retcode = parse_str(interp, argv[9], ¶ms->dict_file)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing dict_file name"); +- retcode = TCL_ERROR; +- goto finished; +- } +- if ((retcode = Tcl_GetInt(interp, argv[10], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing mkey_from_kbd"); +- retcode = TCL_ERROR; +- goto finished; +- } +- params->mkey_from_kbd = tmp; +- if ((retcode = parse_str(interp, argv[11], ¶ms->stash_file)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing stash_file name"); +- retcode = TCL_ERROR; +- goto finished; +- } +- if ((retcode = parse_str(interp, argv[12], ¶ms->mkey_name)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing mkey_name name"); +- retcode = TCL_ERROR; +- goto finished; +- } +- if ((retcode = Tcl_GetInt(interp, argv[13], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing enctype"); +- retcode = TCL_ERROR; +- goto finished; +- } +- params->enctype = tmp; +- if ((retcode = Tcl_GetInt(interp, argv[14], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing max_life"); +- retcode = TCL_ERROR; +- goto finished; +- } +- params->max_life = tmp; +- if ((retcode = Tcl_GetInt(interp, argv[15], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing max_rlife"); +- retcode = TCL_ERROR; +- goto finished; +- } +- params->max_rlife = tmp; +- if ((retcode = Tcl_GetInt(interp, argv[16], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing expiration"); +- retcode = TCL_ERROR; +- goto finished; +- } +- params->expiration = tmp; +- if ((retcode = parse_krb5_flags(interp, argv[17], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing flags"); +- retcode = TCL_ERROR; +- goto finished; +- } +- params->flags = tmp; +- if ((retcode = Tcl_GetInt(interp, argv[18], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing num_keysalts"); +- retcode = TCL_ERROR; +- goto finished; +- } +- params->num_keysalts = tmp; +- if ((retcode = parse_keysalts(interp, argv[19], ¶ms->keysalts, +- params->num_keysalts)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing keysalts"); +- retcode = TCL_ERROR; +- goto finished; +- } +- +-finished: +- return retcode; +-} +- +-static int parse_principal_ent(Tcl_Interp *interp, char *list, +- kadm5_principal_ent_t *out_princ) +-{ +- kadm5_principal_ent_t princ = 0; +- krb5_error_code krb5_ret; +- int tcl_ret; +- int argc; +- const char **argv; +- int tmp; +- int retcode = TCL_OK; +- +- if ((tcl_ret = Tcl_SplitList(interp, list, &argc, &argv)) != TCL_OK) { +- return tcl_ret; +- } +- +- if (argc != 12 && argc != 20) { +- Tcl_SetResult(interp, "wrong # args in principal structure", +- TCL_STATIC); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- if (! (princ = malloc(sizeof *princ))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- memset(princ, 0, sizeof(*princ)); +- +- if ((krb5_ret = krb5_parse_name(context, argv[0], &princ->principal)) != 0) { +- stash_error(interp, krb5_ret); +- Tcl_AppendElement(interp, "while parsing principal"); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- /* +- * All of the numerical values parsed here are parsed into an +- * "int" and then assigned into the structure in case the actual +- * width of the field in the Kerberos structure is different from +- * the width of an integer. +- */ +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[1], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing princ_expire_time"); +- retcode = TCL_ERROR; +- goto finished; +- } +- princ->princ_expire_time = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[2], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing last_pwd_change"); +- retcode = TCL_ERROR; +- goto finished; +- } +- princ->last_pwd_change = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[3], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing pw_expiration"); +- retcode = TCL_ERROR; +- goto finished; +- } +- princ->pw_expiration = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[4], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing max_life"); +- retcode = TCL_ERROR; +- goto finished; +- } +- princ->max_life = tmp; +- +- if ((krb5_ret = krb5_parse_name(context, argv[5], &princ->mod_name)) != 0) { +- stash_error(interp, krb5_ret); +- Tcl_AppendElement(interp, "while parsing mod_name"); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[6], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing mod_date"); +- retcode = TCL_ERROR; +- goto finished; +- } +- princ->mod_date = tmp; +- +- if ((tcl_ret = parse_krb5_flags(interp, argv[7], &princ->attributes)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing attributes"); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[8], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing kvno"); +- retcode = TCL_ERROR; +- goto finished; +- } +- princ->kvno = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[9], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing mkvno"); +- retcode = TCL_ERROR; +- goto finished; +- } +- princ->mkvno = tmp; +- +- if ((tcl_ret = parse_str(interp, argv[10], &princ->policy)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing policy"); +- retcode = TCL_ERROR; +- goto finished; +- } +- if(princ->policy != NULL) { +- if(!(princ->policy = strdup(princ->policy))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); +- } +- } +- +- if ((tcl_ret = parse_aux_attributes(interp, argv[11], +- &princ->aux_attributes)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing aux_attributes"); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- if (argc == 12) goto finished; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[12], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing max_renewable_life"); +- retcode = TCL_ERROR; +- goto finished; +- } +- princ->max_renewable_life = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[13], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing last_success"); +- retcode = TCL_ERROR; +- goto finished; +- } +- princ->last_success = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[14], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing last_failed"); +- retcode = TCL_ERROR; +- goto finished; +- } +- princ->last_failed = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[15], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing fail_auth_count"); +- retcode = TCL_ERROR; +- goto finished; +- } +- princ->fail_auth_count = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[16], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing n_key_data"); +- retcode = TCL_ERROR; +- goto finished; +- } +- princ->n_key_data = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[17], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing n_tl_data"); +- retcode = TCL_ERROR; +- goto finished; +- } +- princ->n_tl_data = tmp; +- +- if ((tcl_ret = parse_key_data(interp, argv[18], +- &princ->key_data, +- princ->n_key_data)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing key_data"); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- if ((tcl_ret = parse_tl_data(interp, argv[19], +- &princ->tl_data, +- princ->n_tl_data)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing tl_data"); +- retcode = TCL_ERROR; +- goto finished; +- } +- princ->n_tl_data = tmp; +- +-finished: +- Tcl_Free((char *) argv); +- *out_princ = princ; +- return retcode; +-} +- +- +-static void free_principal_ent(kadm5_principal_ent_t *princ) +-{ +- krb5_free_principal(context, (*princ)->principal); +- krb5_free_principal(context, (*princ)->mod_name); +- free((*princ)->policy); +- free(*princ); +- *princ = 0; +-} +- +-static Tcl_DString *unparse_policy_ent(kadm5_policy_ent_t policy) +-{ +- Tcl_DString *str, *tmp_dstring; +- char buf[20]; +- +- if (! (str = malloc(sizeof(*str)))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- +- Tcl_DStringInit(str); +- +- tmp_dstring = unparse_str(policy->policy); +- Tcl_DStringAppendElement(str, tmp_dstring->string); +- Tcl_DStringFree(tmp_dstring); +- free(tmp_dstring); +- +- sprintf(buf, "%ld", policy->pw_min_life); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%ld", policy->pw_max_life); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%ld", policy->pw_min_length); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%ld", policy->pw_min_classes); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%ld", policy->pw_history_num); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%ld", policy->policy_refcnt); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%d", policy->pw_max_fail); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%d", policy->pw_failcnt_interval); +- Tcl_DStringAppendElement(str, buf); +- +- sprintf(buf, "%d", policy->pw_lockout_duration); +- Tcl_DStringAppendElement(str, buf); +- +- return str; +-} +- +- +- +-static int parse_policy_ent(Tcl_Interp *interp, char *list, +- kadm5_policy_ent_t *out_policy) +-{ +- kadm5_policy_ent_t policy = 0; +- int tcl_ret; +- int argc; +- const char **argv; +- int tmp; +- int retcode = TCL_OK; +- +- if ((tcl_ret = Tcl_SplitList(interp, list, &argc, &argv)) != TCL_OK) { +- return tcl_ret; +- } +- +- if (argc != 7 && argc != 10) { +- Tcl_SetResult(interp, "wrong # args in policy structure", TCL_STATIC); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- if (! (policy = malloc(sizeof *policy))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- +- if ((tcl_ret = parse_str(interp, argv[0], &policy->policy)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing policy name"); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- if(policy->policy != NULL) { +- if (! (policy->policy = strdup(policy->policy))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- } +- +- /* +- * All of the numerical values parsed here are parsed into an +- * "int" and then assigned into the structure in case the actual +- * width of the field in the Kerberos structure is different from +- * the width of an integer. +- */ +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[1], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing pw_min_life"); +- retcode = TCL_ERROR; +- goto finished; +- } +- policy->pw_min_life = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[2], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing pw_max_life"); +- retcode = TCL_ERROR; +- goto finished; +- } +- policy->pw_max_life = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[3], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing pw_min_length"); +- retcode = TCL_ERROR; +- goto finished; +- } +- policy->pw_min_length = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[4], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing pw_min_classes"); +- retcode = TCL_ERROR; +- goto finished; +- } +- policy->pw_min_classes = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[5], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing pw_history_num"); +- retcode = TCL_ERROR; +- goto finished; +- } +- policy->pw_history_num = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[6], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing policy_refcnt"); +- retcode = TCL_ERROR; +- goto finished; +- } +- policy->policy_refcnt = tmp; +- +- if (argc == 7) goto finished; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[7], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing pw_max_fail"); +- retcode = TCL_ERROR; +- goto finished; +- } +- policy->pw_max_fail = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[8], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing pw_failcnt_interval"); +- retcode = TCL_ERROR; +- goto finished; +- } +- policy->pw_failcnt_interval = tmp; +- +- if ((tcl_ret = Tcl_GetInt(interp, argv[9], &tmp)) +- != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing pw_lockout_duration"); +- retcode = TCL_ERROR; +- goto finished; +- } +- policy->pw_lockout_duration = tmp; +- +-finished: +- Tcl_Free((char *) argv); +- *out_policy = policy; +- return retcode; +-} +- +- +-static void free_policy_ent(kadm5_policy_ent_t *policy) +-{ +- free((*policy)->policy); +- free(*policy); +- *policy = 0; +-} +- +-static Tcl_DString *unparse_keytype(krb5_enctype enctype) +-{ +- Tcl_DString *str; +- char buf[50]; +- +- if (! (str = malloc(sizeof(*str)))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- +- Tcl_DStringInit(str); +- +- switch (enctype) { +- /* XXX is this right? */ +- case ENCTYPE_NULL: Tcl_DStringAppend(str, "ENCTYPE_NULL", -1); break; +- default: +- sprintf(buf, "UNKNOWN KEYTYPE (0x%x)", enctype); +- Tcl_DStringAppend(str, buf, -1); +- break; +- } +- +- return str; +-} +- +- +-static Tcl_DString *unparse_keyblocks(krb5_keyblock *keyblocks, int num_keys) +-{ +- Tcl_DString *str; +- Tcl_DString *keytype; +- unsigned int i; +- int j; +- +- if (! (str = malloc(sizeof(*str)))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- +- Tcl_DStringInit(str); +- +- for (j = 0; j < num_keys; j++) { +- krb5_keyblock *keyblock = &keyblocks[j]; +- +- Tcl_DStringStartSublist(str); +- +- keytype = unparse_keytype(keyblock->enctype); +- Tcl_DStringAppendElement(str, keytype->string); +- Tcl_DStringFree(keytype); +- free(keytype); +- if (keyblock->length == 0) { +- Tcl_DStringAppendElement(str, "0x00"); +- } +- else { +- Tcl_DStringAppendElement(str, "0x"); +- for (i = 0; i < keyblock->length; i++) { +- char buf[3]; +- sprintf(buf, "%02x", (int) keyblock->contents[i]); +- Tcl_DStringAppend(str, buf, -1); +- } +- } +- +- Tcl_DStringEndSublist(str); +- } +- +- +- return str; +-} +- +-enum init_type { INIT_NONE, INIT_PASS, INIT_CREDS }; +- +-static int _tcl_kadm5_init_any(enum init_type init_type, ClientData clientData, +- Tcl_Interp *interp, int argc, const char *argv[]) +-{ +- kadm5_ret_t ret; +- char *client_name, *pass, *service_name; +- int tcl_ret; +- krb5_ui_4 struct_version, api_version; +- const char *handle_var; +- void *server_handle; +- char *handle_name, *params_str; +- const char *whoami = argv[0]; +- kadm5_config_params params; +- +- argv++, argc--; +- +- kadm5_init_krb5_context(&context); +- +- if (argc != 7) { +- Tcl_AppendResult(interp, whoami, ": ", arg_error, 0); +- return TCL_ERROR; +- } +- +- if (((tcl_ret = parse_str(interp, argv[0], &client_name)) != TCL_OK) || +- ((tcl_ret = parse_str(interp, argv[1], &pass)) != TCL_OK) || +- ((tcl_ret = parse_str(interp, argv[2], &service_name)) != TCL_OK) || +- ((tcl_ret = parse_str(interp, argv[3], ¶ms_str)) != TCL_OK) || +- ((tcl_ret = parse_config_params(interp, params_str, ¶ms)) +- != TCL_OK) || +- ((tcl_ret = Tcl_GetInt(interp, argv[4], (int *) &struct_version)) != +- TCL_OK) || +- ((tcl_ret = Tcl_GetInt(interp, argv[5], (int *) &api_version)) != +- TCL_OK)) { +- return tcl_ret; +- } +- +- handle_var = argv[6]; +- +- if (! (handle_var && *handle_var)) { +- Tcl_SetResult(interp, "must specify server handle variable name", +- TCL_STATIC); +- return TCL_ERROR; +- } +- +- if (init_type == INIT_CREDS) { +- krb5_ccache cc; +- +- if (pass == NULL) { +- if ((ret = krb5_cc_default(context, &cc))) { +- stash_error(interp, ret); +- return TCL_ERROR; +- } +- } else { +- if ((ret = krb5_cc_resolve(context, pass, &cc))) { +- stash_error(interp, ret); +- return TCL_ERROR; +- } +- } +- +- ret = kadm5_init_with_creds(context, client_name, cc, service_name, +- ¶ms, struct_version, +- api_version, NULL, &server_handle); +- +- (void) krb5_cc_close(context, cc); +- } else +- ret = kadm5_init(context, client_name, pass, service_name, ¶ms, +- struct_version, api_version, NULL, &server_handle); +- +- /* The string fields of params are aliases into argv[3], but +- * params.keysalts is allocated, so clean it up. */ +- free(params.keysalts); +- +- if (ret != KADM5_OK) { +- stash_error(interp, ret); +- return TCL_ERROR; +- } +- +- if ((tcl_ret = put_server_handle(interp, server_handle, &handle_name)) +- != TCL_OK) { +- return tcl_ret; +- } +- +- if (! Tcl_SetVar(interp, handle_var, handle_name, TCL_LEAVE_ERR_MSG)) { +- return TCL_ERROR; +- } +- +- set_ok(interp, "KADM5 API initialized."); +- return TCL_OK; +-} +- +-static int tcl_kadm5_init(ClientData clientData, Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- return _tcl_kadm5_init_any(INIT_PASS, clientData, interp, argc, argv); +-} +- +-static int tcl_kadm5_init_with_creds(ClientData clientData, Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- return _tcl_kadm5_init_any(INIT_CREDS, clientData, interp, argc, argv); +-} +- +-static int tcl_kadm5_destroy(ClientData clientData, Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- kadm5_ret_t ret; +- int tcl_ret; +- +- GET_HANDLE(0, 0); +- +- ret = kadm5_destroy(server_handle); +- +- if (ret != KADM5_OK) { +- stash_error(interp, ret); +- return TCL_ERROR; +- } +- +- if ((tcl_ret = remove_server_handle(interp, argv[-1])) != TCL_OK) { +- return tcl_ret; +- } +- +- set_ok(interp, "KADM5 API deinitialized."); +- return TCL_OK; +-} +- +-static int tcl_kadm5_create_principal(ClientData clientData, +- Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- int tcl_ret; +- kadm5_ret_t ret; +- int retcode = TCL_OK; +- char *princ_string; +- kadm5_principal_ent_t princ = 0; +- krb5_int32 mask; +- char *pw; +-#ifdef OVERRIDE +- int override_qual; +-#endif +- +- GET_HANDLE(3, 0); +- +- if ((tcl_ret = parse_str(interp, argv[0], &princ_string)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing principal"); +- return tcl_ret; +- } +- +- if (princ_string && +- ((tcl_ret = parse_principal_ent(interp, princ_string, &princ)) +- != TCL_OK)) { +- return tcl_ret; +- } +- +- if ((tcl_ret = parse_principal_mask(interp, argv[1], &mask)) != TCL_OK) { +- retcode = tcl_ret; +- goto finished; +- } +- +- if ((tcl_ret = parse_str(interp, argv[2], &pw)) != TCL_OK) { +- retcode = tcl_ret; +- goto finished; +- } +-#ifdef OVERRIDE +- if ((tcl_ret = Tcl_GetBoolean(interp, argv[3], &override_qual)) != +- TCL_OK) { +- retcode = tcl_ret; +- goto finished; +- } +-#endif +- +-#ifdef OVERRIDE +- ret = kadm5_create_principal(server_handle, princ, mask, pw, +- override_qual); +-#else +- ret = kadm5_create_principal(server_handle, princ, mask, pw); +-#endif +- +- if (ret != KADM5_OK) { +- stash_error(interp, ret); +- retcode = TCL_ERROR; +- goto finished; +- } +- else { +- set_ok(interp, "Principal created."); +- } +- +-finished: +- if (princ) { +- free_principal_ent(&princ); +- } +- return retcode; +-} +- +- +- +-static int tcl_kadm5_delete_principal(ClientData clientData, +- Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- krb5_principal princ; +- krb5_error_code krb5_ret; +- kadm5_ret_t ret; +- int tcl_ret; +- char *name; +- +- GET_HANDLE(1, 0); +- +- if((tcl_ret = parse_str(interp, argv[0], &name)) != TCL_OK) +- return tcl_ret; +- if(name != NULL) { +- if ((krb5_ret = krb5_parse_name(context, name, &princ))) { +- stash_error(interp, krb5_ret); +- Tcl_AppendElement(interp, "while parsing principal"); +- return TCL_ERROR; +- } +- } else princ = NULL; +- ret = kadm5_delete_principal(server_handle, princ); +- +- if(princ != NULL) +- krb5_free_principal(context, princ); +- +- if (ret != KADM5_OK) { +- stash_error(interp, ret); +- return TCL_ERROR; +- } +- else { +- set_ok(interp, "Principal deleted."); +- return TCL_OK; +- } +-} +- +- +- +-static int tcl_kadm5_modify_principal(ClientData clientData, +- Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- char *princ_string; +- kadm5_principal_ent_t princ = 0; +- int tcl_ret; +- krb5_int32 mask; +- int retcode = TCL_OK; +- kadm5_ret_t ret; +- +- GET_HANDLE(2, 0); +- +- if ((tcl_ret = parse_str(interp, argv[0], &princ_string)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing principal"); +- return tcl_ret; +- } +- +- if (princ_string && +- ((tcl_ret = parse_principal_ent(interp, princ_string, &princ)) +- != TCL_OK)) { +- return tcl_ret; +- } +- +- if ((tcl_ret = parse_principal_mask(interp, argv[1], &mask)) != TCL_OK) { +- retcode = TCL_ERROR; +- goto finished; +- } +- +- ret = kadm5_modify_principal(server_handle, princ, mask); +- +- if (ret != KADM5_OK) { +- stash_error(interp, ret); +- retcode = TCL_ERROR; +- } +- else { +- set_ok(interp, "Principal modified."); +- } +- +-finished: +- if (princ) { +- free_principal_ent(&princ); +- } +- return retcode; +-} +- +- +-static int tcl_kadm5_rename_principal(ClientData clientData, +- Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- krb5_principal source, target; +- krb5_error_code krb5_ret; +- kadm5_ret_t ret; +- int retcode = TCL_OK; +- +- GET_HANDLE(2, 0); +- +- if ((krb5_ret = krb5_parse_name(context, argv[0], &source)) != 0) { +- stash_error(interp, krb5_ret); +- Tcl_AppendElement(interp, "while parsing source"); +- return TCL_ERROR; +- } +- +- if ((krb5_ret = krb5_parse_name(context, argv[1], &target)) != 0) { +- stash_error(interp, krb5_ret); +- Tcl_AppendElement(interp, "while parsing target"); +- krb5_free_principal(context, source); +- return TCL_ERROR; +- } +- +- ret = kadm5_rename_principal(server_handle, source, target); +- +- if (ret == KADM5_OK) { +- set_ok(interp, "Principal renamed."); +- } +- else { +- stash_error(interp, ret); +- retcode = TCL_ERROR; +- } +- +- krb5_free_principal(context, source); +- krb5_free_principal(context, target); +- return retcode; +-} +- +- +- +-static int tcl_kadm5_chpass_principal(ClientData clientData, +- Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- krb5_principal princ; +- char *pw; +-#ifdef OVERRIDE +- int override_qual; +-#endif +- krb5_error_code krb5_ret; +- int retcode = TCL_OK; +- kadm5_ret_t ret; +- +- GET_HANDLE(2, 0); +- +- if ((krb5_ret = krb5_parse_name(context, argv[0], &princ)) != 0) { +- stash_error(interp, krb5_ret); +- Tcl_AppendElement(interp, "while parsing principal name"); +- return TCL_ERROR; +- } +- +- if (parse_str(interp, argv[1], &pw) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing password"); +- retcode = TCL_ERROR; +- goto finished; +- } +- +-#ifdef OVERRIDE +- if (Tcl_GetBoolean(interp, argv[2], &override_qual) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing override_qual"); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- ret = kadm5_chpass_principal(server_handle, +- princ, pw, override_qual); +-#else +- ret = kadm5_chpass_principal(server_handle, princ, pw); +-#endif +- +- if (ret == KADM5_OK) { +- set_ok(interp, "Password changed."); +- goto finished; +- } +- else { +- stash_error(interp, ret); +- retcode = TCL_ERROR; +- } +- +-finished: +- krb5_free_principal(context, princ); +- return retcode; +-} +- +- +- +-static int tcl_kadm5_chpass_principal_util(ClientData clientData, +- Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- krb5_principal princ; +- char *new_pw; +-#ifdef OVERRIDE +- int override_qual; +-#endif +- char *pw_ret, *pw_ret_var; +- char msg_ret[1024], *msg_ret_var; +- krb5_error_code krb5_ret; +- kadm5_ret_t ret; +- int retcode = TCL_OK; +- +- GET_HANDLE(4, 0); +- +- if ((krb5_ret = krb5_parse_name(context, argv[0], &princ)) != 0) { +- stash_error(interp, krb5_ret); +- Tcl_AppendElement(interp, "while parsing principal name"); +- return TCL_ERROR; +- } +- +- if (parse_str(interp, argv[1], &new_pw) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing new password"); +- retcode = TCL_ERROR; +- goto finished; +- } +-#ifdef OVERRIDE +- if (Tcl_GetBoolean(interp, argv[2], &override_qual) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing override_qual"); +- retcode = TCL_ERROR; +- goto finished; +- } +-#endif +- if (parse_str(interp, argv[3], &pw_ret_var) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing pw_ret variable name"); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- if (parse_str(interp, argv[4], &msg_ret_var) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing msg_ret variable name"); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- ret = kadm5_chpass_principal_util(server_handle, princ, new_pw, +-#ifdef OVERRIDE +- override_qual, +-#endif +- pw_ret_var ? &pw_ret : 0, +- msg_ret_var ? msg_ret : 0, +- msg_ret_var ? sizeof(msg_ret) : 0); +- +- if (ret == KADM5_OK) { +- if (pw_ret_var && +- (! Tcl_SetVar(interp, pw_ret_var, pw_ret, +- TCL_LEAVE_ERR_MSG))) { +- Tcl_AppendElement(interp, "while setting pw_ret variable"); +- retcode = TCL_ERROR; +- goto finished; +- } +- if (msg_ret_var && +- (! Tcl_SetVar(interp, msg_ret_var, msg_ret, +- TCL_LEAVE_ERR_MSG))) { +- Tcl_AppendElement(interp, +- "while setting msg_ret variable"); +- retcode = TCL_ERROR; +- goto finished; +- } +- set_ok(interp, "Password changed."); +- } +- else { +- stash_error(interp, ret); +- retcode = TCL_ERROR; +- } +- +-finished: +- krb5_free_principal(context, princ); +- return retcode; +-} +- +- +- +-static int tcl_kadm5_randkey_principal(ClientData clientData, +- Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- krb5_principal princ; +- krb5_keyblock *keyblocks; +- int num_keys; +- char *keyblock_var, *num_var, buf[50]; +- Tcl_DString *keyblock_dstring = 0; +- krb5_error_code krb5_ret; +- kadm5_ret_t ret; +- int retcode = TCL_OK; +- +- GET_HANDLE(3, 0); +- +- if ((krb5_ret = krb5_parse_name(context, argv[0], &princ)) != 0) { +- stash_error(interp, krb5_ret); +- Tcl_AppendElement(interp, "while parsing principal name"); +- return TCL_ERROR; +- } +- +- if (parse_str(interp, argv[1], &keyblock_var) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing keyblock variable name"); +- retcode = TCL_ERROR; +- goto finished; +- } +- if (parse_str(interp, argv[2], &num_var) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing keyblock variable name"); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- ret = kadm5_randkey_principal(server_handle, +- princ, keyblock_var ? &keyblocks : 0, +- &num_keys); +- +- if (ret == KADM5_OK) { +- if (keyblock_var) { +- keyblock_dstring = unparse_keyblocks(keyblocks, num_keys); +- if (! Tcl_SetVar(interp, keyblock_var, +- keyblock_dstring->string, +- TCL_LEAVE_ERR_MSG)) { +- Tcl_AppendElement(interp, +- "while setting keyblock variable"); +- retcode = TCL_ERROR; +- goto finished; +- } +- } +- if (num_var) { +- sprintf(buf, "%d", num_keys); +- if (! Tcl_SetVar(interp, num_var, buf, +- TCL_LEAVE_ERR_MSG)) { +- Tcl_AppendElement(interp, +- "while setting num_keys variable"); +- } +- } +- set_ok(interp, "Key randomized."); +- } +- else { +- stash_error(interp, ret); +- retcode = TCL_ERROR; +- } +- +-finished: +- krb5_free_principal(context, princ); +- if (keyblock_dstring) { +- Tcl_DStringFree(keyblock_dstring); +- free(keyblock_dstring); +- } +- return retcode; +-} +- +- +- +-static int tcl_kadm5_get_principal(ClientData clientData, Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- krb5_principal princ; +- kadm5_principal_ent_rec ent; +- Tcl_DString *ent_dstring = 0; +- char *ent_var; +- char *name; +- krb5_error_code krb5_ret; +- int tcl_ret; +- kadm5_ret_t ret = -1; +- krb5_int32 mask; +- int retcode = TCL_OK; +- +- GET_HANDLE(3, 1); +- +- if((tcl_ret = parse_str(interp, argv[0], &name)) != TCL_OK) +- return tcl_ret; +- if(name != NULL) { +- if ((krb5_ret = krb5_parse_name(context, name, &princ)) != 0) { +- stash_error(interp, krb5_ret); +- Tcl_AppendElement(interp, "while parsing principal name"); +- return TCL_ERROR; +- } +- } else princ = NULL; +- +- if ((tcl_ret = parse_str(interp, argv[1], &ent_var)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing entry variable name"); +- retcode = TCL_ERROR; +- goto finished; +- } +- if ((tcl_ret = parse_principal_mask(interp, argv[2], &mask)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing principal mask"); +- retcode = TCL_ERROR; +- goto finished; +- } +- +- ret = kadm5_get_principal(server_handle, princ, ent_var ? &ent : 0, +- mask); +- +- if (ret == KADM5_OK) { +- if (ent_var) { +- ent_dstring = unparse_principal_ent(&ent, mask); +- if (! Tcl_SetVar(interp, ent_var, ent_dstring->string, +- TCL_LEAVE_ERR_MSG)) { +- Tcl_AppendElement(interp, +- "while setting entry variable"); +- retcode = TCL_ERROR; +- goto finished; +- } +- set_ok(interp, "Principal retrieved."); +- } +- } +- else { +- stash_error(interp, ret); +- retcode = TCL_ERROR; +- } +- +-finished: +- if (ent_dstring) { +- Tcl_DStringFree(ent_dstring); +- free(ent_dstring); +- } +- if(princ != NULL) +- krb5_free_principal(context, princ); +- if (ret == KADM5_OK && ent_var && +- (ret = kadm5_free_principal_ent(server_handle, &ent)) && +- (retcode == TCL_OK)) { +- stash_error(interp, ret); +- retcode = TCL_ERROR; +- } +- return retcode; +-} +- +-static int tcl_kadm5_create_policy(ClientData clientData, Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- int tcl_ret; +- kadm5_ret_t ret; +- int retcode = TCL_OK; +- char *policy_string; +- kadm5_policy_ent_t policy = 0; +- krb5_int32 mask; +- +- GET_HANDLE(2, 0); +- +- if ((tcl_ret = parse_str(interp, argv[0], &policy_string)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing policy"); +- return tcl_ret; +- } +- +- if (policy_string && +- ((tcl_ret = parse_policy_ent(interp, policy_string, &policy)) +- != TCL_OK)) { +- return tcl_ret; +- } +- +- if ((tcl_ret = parse_policy_mask(interp, argv[1], &mask)) != TCL_OK) { +- retcode = tcl_ret; +- goto finished; +- } +- +- ret = kadm5_create_policy(server_handle, policy, mask); +- +- if (ret != KADM5_OK) { +- stash_error(interp, ret); +- retcode = TCL_ERROR; +- goto finished; +- } +- else { +- set_ok(interp, "Policy created."); +- } +- +-finished: +- if (policy) { +- free_policy_ent(&policy); +- } +- return retcode; +-} +- +- +- +-static int tcl_kadm5_delete_policy(ClientData clientData, Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- kadm5_ret_t ret; +- char *policy; +- +- GET_HANDLE(1, 0); +- +- if (parse_str(interp, argv[0], &policy) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing policy name"); +- return TCL_ERROR; +- } +- +- ret = kadm5_delete_policy(server_handle, policy); +- +- if (ret != KADM5_OK) { +- stash_error(interp, ret); +- return TCL_ERROR; +- } +- else { +- set_ok(interp, "Policy deleted."); +- return TCL_OK; +- } +-} +- +- +- +-static int tcl_kadm5_modify_policy(ClientData clientData, Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- char *policy_string; +- kadm5_policy_ent_t policy = 0; +- int tcl_ret; +- krb5_int32 mask; +- int retcode = TCL_OK; +- kadm5_ret_t ret; +- +- GET_HANDLE(2, 0); +- +- if ((tcl_ret = parse_str(interp, argv[0], &policy_string)) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing policy"); +- return tcl_ret; +- } +- +- if (policy_string && +- ((tcl_ret = parse_policy_ent(interp, policy_string, &policy)) +- != TCL_OK)) { +- return tcl_ret; +- } +- +- if ((tcl_ret = parse_policy_mask(interp, argv[1], &mask)) != TCL_OK) { +- retcode = TCL_ERROR; +- goto finished; +- } +- +- ret = kadm5_modify_policy(server_handle, policy, mask); +- +- if (ret != KADM5_OK) { +- stash_error(interp, ret); +- retcode = TCL_ERROR; +- } +- else { +- set_ok(interp, "Policy modified."); +- } +- +-finished: +- if (policy) { +- free_policy_ent(&policy); +- } +- return retcode; +-} +- +- +-static int tcl_kadm5_get_policy(ClientData clientData, Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- kadm5_policy_ent_rec ent; +- Tcl_DString *ent_dstring = 0; +- char *policy; +- char *ent_var; +- kadm5_ret_t ret; +- int retcode = TCL_OK; +- +- GET_HANDLE(2, 1); +- +- if (parse_str(interp, argv[0], &policy) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing policy name"); +- return TCL_ERROR; +- } +- +- if (parse_str(interp, argv[1], &ent_var) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing entry variable name"); +- return TCL_ERROR; +- } +- +- ret = kadm5_get_policy(server_handle, policy, ent_var ? &ent : 0); +- +- if (ret == KADM5_OK) { +- if (ent_var) { +- ent_dstring = unparse_policy_ent(&ent); +- if (! Tcl_SetVar(interp, ent_var, ent_dstring->string, +- TCL_LEAVE_ERR_MSG)) { +- Tcl_AppendElement(interp, +- "while setting entry variable"); +- retcode = TCL_ERROR; +- goto finished; +- } +- set_ok(interp, "Policy retrieved."); +- } +- } +- else { +- stash_error(interp, ret); +- retcode = TCL_ERROR; +- } +- +-finished: +- if (ent_dstring) { +- Tcl_DStringFree(ent_dstring); +- free(ent_dstring); +- } +- if (ent_var && ret == KADM5_OK && +- (ret = kadm5_free_policy_ent(server_handle, &ent)) && +- (retcode == TCL_OK)) { +- stash_error(interp, ret); +- retcode = TCL_ERROR; +- } +- return retcode; +-} +- +- +- +-static int tcl_kadm5_free_principal_ent(ClientData clientData, +- Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- char *ent_name; +- kadm5_principal_ent_t ent; +- kadm5_ret_t ret; +- +- GET_HANDLE(1, 0); +- +- if (parse_str(interp, argv[0], &ent_name) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing entry name"); +- return TCL_ERROR; +- } +- +- if ((! ent_name) && +- (ret = kadm5_free_principal_ent(server_handle, 0))) { +- stash_error(interp, ret); +- return TCL_ERROR; +- } +- else { +- Tcl_HashEntry *entry; +- +- if (strncmp(ent_name, "principal", sizeof("principal")-1)) { +- Tcl_AppendResult(interp, "invalid principal handle \"", +- ent_name, "\"", 0); +- return TCL_ERROR; +- } +- if (! struct_table) { +- if (! (struct_table = malloc(sizeof(*struct_table)))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- Tcl_InitHashTable(struct_table, TCL_STRING_KEYS); +- } +- +- if (! (entry = Tcl_FindHashEntry(struct_table, ent_name))) { +- Tcl_AppendResult(interp, "principal handle \"", ent_name, +- "\" not found", 0); +- return TCL_ERROR; +- } +- +- ent = (kadm5_principal_ent_t) Tcl_GetHashValue(entry); +- +- ret = kadm5_free_principal_ent(server_handle, ent); +- if (ret != KADM5_OK) { +- stash_error(interp, ret); +- return TCL_ERROR; +- } +- Tcl_DeleteHashEntry(entry); +- } +- set_ok(interp, "Principal freed."); +- return TCL_OK; +-} +- +- +-static int tcl_kadm5_free_policy_ent(ClientData clientData, +- Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- char *ent_name; +- kadm5_policy_ent_t ent; +- kadm5_ret_t ret; +- +- GET_HANDLE(1, 0); +- +- if (parse_str(interp, argv[0], &ent_name) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing entry name"); +- return TCL_ERROR; +- } +- +- if ((! ent_name) && +- (ret = kadm5_free_policy_ent(server_handle, 0))) { +- stash_error(interp, ret); +- return TCL_ERROR; +- } +- else { +- Tcl_HashEntry *entry; +- +- if (strncmp(ent_name, "policy", sizeof("policy")-1)) { +- Tcl_AppendResult(interp, "invalid principal handle \"", +- ent_name, "\"", 0); +- return TCL_ERROR; +- } +- if (! struct_table) { +- if (! (struct_table = malloc(sizeof(*struct_table)))) { +- fprintf(stderr, "Out of memory!\n"); +- exit(1); /* XXX */ +- } +- Tcl_InitHashTable(struct_table, TCL_STRING_KEYS); +- } +- +- if (! (entry = Tcl_FindHashEntry(struct_table, ent_name))) { +- Tcl_AppendResult(interp, "policy handle \"", ent_name, +- "\" not found", 0); +- return TCL_ERROR; +- } +- +- ent = (kadm5_policy_ent_t) Tcl_GetHashValue(entry); +- +- if ((ret = kadm5_free_policy_ent(server_handle, ent)) != KADM5_OK) { +- stash_error(interp, ret); +- return TCL_ERROR; +- } +- Tcl_DeleteHashEntry(entry); +- } +- set_ok(interp, "Policy freed."); +- return TCL_OK; +-} +- +- +-static int tcl_kadm5_get_privs(ClientData clientData, Tcl_Interp *interp, +- int argc, const char *argv[]) +-{ +- const char *set_ret; +- kadm5_ret_t ret; +- char *priv_var; +- long privs; +- +- GET_HANDLE(1, 0); +- +- if (parse_str(interp, argv[0], &priv_var) != TCL_OK) { +- Tcl_AppendElement(interp, "while parsing privs variable name"); +- return TCL_ERROR; +- } +- +- ret = kadm5_get_privs(server_handle, priv_var ? &privs : 0); +- +- if (ret == KADM5_OK) { +- if (priv_var) { +- Tcl_DString *str = unparse_privs(privs); +- set_ret = Tcl_SetVar(interp, priv_var, str->string, +- TCL_LEAVE_ERR_MSG); +- Tcl_DStringFree(str); +- free(str); +- if (! set_ret) { +- Tcl_AppendElement(interp, "while setting priv variable"); +- return TCL_ERROR; +- } +- } +- set_ok(interp, "Privileges retrieved."); +- return TCL_OK; +- } +- else { +- stash_error(interp, ret); +- return TCL_ERROR; +- } +-} +- +- +-void Tcl_kadm5_init(Tcl_Interp *interp) +-{ +- char buf[20]; +- +- Tcl_SetVar(interp, "KADM5_ADMIN_SERVICE", +- KADM5_ADMIN_SERVICE, TCL_GLOBAL_ONLY); +- Tcl_SetVar(interp, "KADM5_CHANGEPW_SERVICE", +- KADM5_CHANGEPW_SERVICE, TCL_GLOBAL_ONLY); +- (void) sprintf(buf, "%d", KADM5_STRUCT_VERSION); +- Tcl_SetVar(interp, "KADM5_STRUCT_VERSION", buf, TCL_GLOBAL_ONLY); +- (void) sprintf(buf, "%d", KADM5_API_VERSION_2); +- Tcl_SetVar(interp, "KADM5_API_VERSION_2", buf, TCL_GLOBAL_ONLY); +- (void) sprintf(buf, "%d", KADM5_API_VERSION_3); +- Tcl_SetVar(interp, "KADM5_API_VERSION_3", buf, TCL_GLOBAL_ONLY); +- (void) sprintf(buf, "%d", KADM5_API_VERSION_4); +- Tcl_SetVar(interp, "KADM5_API_VERSION_4", buf, TCL_GLOBAL_ONLY); +- (void) sprintf(buf, "%d", KADM5_API_VERSION_MASK); +- Tcl_SetVar(interp, "KADM5_API_VERSION_MASK", buf, TCL_GLOBAL_ONLY); +- (void) sprintf(buf, "%d", KADM5_STRUCT_VERSION_MASK); +- Tcl_SetVar(interp, "KADM5_STRUCT_VERSION_MASK", buf, +- TCL_GLOBAL_ONLY); +- +- Tcl_CreateCommand(interp, "kadm5_init", tcl_kadm5_init, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_init_with_creds", +- tcl_kadm5_init_with_creds, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_destroy", tcl_kadm5_destroy, 0, +- 0); +- Tcl_CreateCommand(interp, "kadm5_create_principal", +- tcl_kadm5_create_principal, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_delete_principal", +- tcl_kadm5_delete_principal, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_modify_principal", +- tcl_kadm5_modify_principal, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_rename_principal", +- tcl_kadm5_rename_principal, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_chpass_principal", +- tcl_kadm5_chpass_principal, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_chpass_principal_util", +- tcl_kadm5_chpass_principal_util, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_randkey_principal", +- tcl_kadm5_randkey_principal, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_get_principal", +- tcl_kadm5_get_principal, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_create_policy", +- tcl_kadm5_create_policy, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_delete_policy", +- tcl_kadm5_delete_policy, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_modify_policy", +- tcl_kadm5_modify_policy, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_get_policy", +- tcl_kadm5_get_policy, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_free_principal_ent", +- tcl_kadm5_free_principal_ent, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_free_policy_ent", +- tcl_kadm5_free_policy_ent, 0, 0); +- Tcl_CreateCommand(interp, "kadm5_get_privs", +- tcl_kadm5_get_privs, 0, 0); +-} +diff --git a/src/kadmin/testing/util/tcl_kadm5.h b/src/kadmin/testing/util/tcl_kadm5.h +deleted file mode 100644 +index 1f91a11a1..000000000 +--- a/src/kadmin/testing/util/tcl_kadm5.h ++++ /dev/null +@@ -1,3 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +- +-void Tcl_kadm5_init(Tcl_Interp *interp); +diff --git a/src/kadmin/testing/util/tcl_kadm5_syntax b/src/kadmin/testing/util/tcl_kadm5_syntax +deleted file mode 100644 +index 5f16e58e0..000000000 +--- a/src/kadmin/testing/util/tcl_kadm5_syntax ++++ /dev/null +@@ -1,57 +0,0 @@ +-Here's a brief summary of the syntax of the tcl versions of the +-kadm5 functions: +- +-string Can be a string or "null" which will turn into a null pointer +-principal_ent A 12-field list in the order of the principal_ent +- structure: {string number number number number string +- number mask number number string mask} +- It can also be "null", like a string, to indicate that +- a null structure pointer should be used. +-mask Either a number, representing the actual value of the +- mask, or a sequence of symbols in a list. Example: +- {PRINCIPAL ATTRIBUTES} is a valid principal mask. +-boolean "1", "0", "true", "false", etc. +-varname The name of a Tcl variable, or "null" to not assign. +-policy_ent Similar to principal_ent, but with seven fields, +- instead of 12. The first is a string, and the rest +- are numbers. +- +-init +- client_name:string pass:string service_name:string +- realm:string struct_version:int api_version:int +- server_handle_ret:varname +-destroy +- server_handle:string +-create_principal +- server_handle:string principal:principal_ent +- mask:principal_mask password:string +-delete_principal +- server_handle:string name:string +-modify_principal +- server_handle:string principal_principal_ent +- mask:principal_mask +-rename_principal +- server_handle:string source:string target:string +-chpass_principal +- server_handle:string name:string password:string +-chpass_principal_util +- server_handle:string name:string password:string +- pw_ret:varname msg_ret:varname +-randkey_principal +- server_handle:string name:string keyblock_var:varname +-get_principal [-struct] +- server_handle:string name:string princ_var:varname +-create_policy +- server_handle:string policy:policy_ent mask:policy_mask +-delete_policy +- server_handle:string name:string +-modify_policy +- server_handle:string policy:policy_ent mask:policy_mask +-get_policy [-struct] +- server_handle:string name:string policy_var:varname +-free_principal_ent +- server_handle:string handle:string +-free_policy_ent +- server_handle:string handle:string +-get_privs +- server_handle:string privs:priv_var +diff --git a/src/kadmin/testing/util/tcl_krb5_hash.c b/src/kadmin/testing/util/tcl_krb5_hash.c +deleted file mode 100644 +index 35c6bb0b3..000000000 +--- a/src/kadmin/testing/util/tcl_krb5_hash.c ++++ /dev/null +@@ -1,167 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-/* +- * All of the TCL krb5 functions which return (or place into output +- * variables) structures or pointers to structures that can't be +- * represented as tcl native types, do so by returning a handle for +- * the appropriate structure. The handle is a string of the form +- * "type$id", where "type" is the type of datum represented by the +- * handle and "id" is a unique identifier for it. This handle can +- * then be used later by the caller to refer to the object, and +- * internally to retrieve the actually datum from the appropriate hash +- * table. +- * +- * The functions in this file do four things: +- * +- * 1) Given a pointer to a datum and a string representing the type of +- * datum to which the pointer refers, create a new handle for the +- * datum, store the datum in the hash table using the new handle as +- * its key, and return the new handle. +- * +- * 2) Given a handle, locate and return the appropriate hash table +- * datum. +- * +- * 3) Given a handle, look through a table of types and unparse +- * functions to figure out what function to call to get a string +- * representation of the datum, call it with the appropriate pointer +- * (obtained from the hash table) as an argument, and return the +- * resulting string as the unparsed form of the datum. +- * +- * 4) Given a handle, remove that handle and its associated datum from +- * the hash table (but don't free it -- it's assumed to have already +- * been freed by the caller). +- */ +- +-#if HAVE_TCL_H +-#include +-#elif HAVE_TCL_TCL_H +-#include +-#endif +-#include +- +-#define SEP_STR "$" +- +-static char *memory_error = "out of memory"; +- +-/* +- * Right now, we're only using one hash table. However, at some point +- * in the future, we might decide to use a separate hash table for +- * every type. Therefore, I'm putting this function in as an +- * abstraction so it's the only thing we'll have to change if we +- * decide to do that. +- * +- * Also, this function allows us to put in just one place the code for +- * checking to make sure that the hash table exists and initializing +- * it if it doesn't. +- */ +- +-static TclHashTable *get_hash_table(Tcl_Interp *interp, +- char *type) +-{ +- static Tcl_HashTable *hash_table = 0; +- +- if (! hash_table) { +- if (! (hash_table = malloc(sizeof(*hash_table)))) { +- Tcl_SetResult(interp, memory_error, TCL_STATIC); +- return 0; +- } +- Tcl_InitHashTable(hash_table, TCL_STRING_KEYS); +- } +- return hash_table; +-} +- +-#define MAX_ID 999999999 +-#define ID_BUF_SIZE 10 +- +-static Tcl_HashEntry *get_new_handle(Tcl_Interp *interp, +- char *type) +-{ +- static unsigned long int id_counter = 0; +- Tcl_DString *handle; +- char int_buf[ID_BUF_SIZE]; +- +- if (! (handle = malloc(sizeof(*handle)))) { +- Tcl_SetResult(interp, memory_error, TCL_STATIC); +- return 0; +- } +- Tcl_DStringInit(handle); +- +- assert(id_counter <= MAX_ID); +- +- sprintf(int_buf, "%d", id_counter++); +- +- Tcl_DStringAppend(handle, type, -1); +- Tcl_DStringAppend(handle, SEP_STR, -1); +- Tcl_DStringAppend(handle, int_buf, -1); +- +- return handle; +-} +- +- +-Tcl_DString *tcl_krb5_create_object(Tcl_Interp *interp, +- char *type, +- ClientData datum) +-{ +- Tcl_HashTable *table; +- Tcl_DString *handle; +- Tcl_HashEntry *entry; +- int entry_created = 0; +- +- if (! (table = get_hash_table(interp, type))) { +- return 0; +- } +- +- if (! (handle = get_new_handle(interp, type))) { +- return 0; +- } +- +- if (! (entry = Tcl_CreateHashEntry(table, handle, &entry_created))) { +- Tcl_SetResult(interp, "error creating hash entry", TCL_STATIC); +- Tcl_DStringFree(handle); +- return TCL_ERROR; +- } +- +- assert(entry_created); +- +- Tcl_SetHashValue(entry, datum); +- +- return handle; +-} +- +-ClientData tcl_krb5_get_object(Tcl_Interp *interp, +- char *handle) +-{ +- char *myhandle, *id_ptr; +- Tcl_HashTable *table; +- Tcl_HashEntry *entry; +- +- if (! (myhandle = strdup(handle))) { +- Tcl_SetResult(interp, memory_error, TCL_STATIC); +- return 0; +- } +- +- if (! (id_ptr = index(myhandle, *SEP_STR))) { +- free(myhandle); +- Tcl_ResetResult(interp); +- Tcl_AppendResult(interp, "malformatted handle \"", handle, +- "\"", 0); +- return 0; +- } +- +- *id_ptr = '\0'; +- +- if (! (table = get_hash_table(interp, myhandle))) { +- free(myhandle); +- return 0; +- } +- +- free(myhandle); +- +- if (! (entry = Tcl_FindHashEntry(table, handle))) { +- Tcl_ResetResult(interp); +- Tcl_AppendResult(interp, "no object corresponding to handle \"", +- handle, "\"", 0); +- return 0; +- } +- +- return(Tcl_GetHashValue(entry)); +-} +diff --git a/src/kadmin/testing/util/test.c b/src/kadmin/testing/util/test.c +deleted file mode 100644 +index 37e49d680..000000000 +--- a/src/kadmin/testing/util/test.c ++++ /dev/null +@@ -1,38 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-#include "autoconf.h" +-#if HAVE_TCL_H +-#include +-#elif HAVE_TCL_TCL_H +-#include +-#endif +-#include "tcl_kadm5.h" +- +-#define _TCL_MAIN ((TCL_MAJOR_VERSION * 100 + TCL_MINOR_VERSION) >= 704) +- +-#if _TCL_MAIN +-int +-main(argc, argv) +- int argc; /* Number of command-line arguments. */ +- char **argv; /* Values of command-line arguments. */ +-{ +- Tcl_Main(argc, argv, Tcl_AppInit); +- return 0; /* Needed only to prevent compiler warning. */ +-} +-#else +-/* +- * The following variable is a special hack that allows applications +- * to be linked using the procedure "main" from the Tcl library. The +- * variable generates a reference to "main", which causes main to +- * be brought in from the library (and all of Tcl with it). +- */ +- +-extern int main(); +-int *tclDummyMainPtr = (int *) main; +-#endif +- +-int Tcl_AppInit(Tcl_Interp *interp) +-{ +- Tcl_kadm5_init(interp); +- +- return(TCL_OK); +-} +diff --git a/src/lib/kadm5/Makefile.in b/src/lib/kadm5/Makefile.in +index f94c0a7da..3ff71c42b 100644 +--- a/src/lib/kadm5/Makefile.in ++++ b/src/lib/kadm5/Makefile.in +@@ -1,6 +1,6 @@ + mydir=lib$(S)kadm5 + BUILDTOP=$(REL)..$(S).. +-SUBDIRS = clnt srv unit-test ++SUBDIRS = clnt srv + + ##DOSBUILDTOP = ..\.. + +@@ -98,6 +98,7 @@ generate-files-mac-prerecurse: includes + check-windows: + + clean-unix:: clean-libobjs ++ $(RM) t_kadm5clnt t_kadm5srv t_kadm5.o + + clean-windows:: + +diff --git a/src/lib/kadm5/unit-test/Makefile.in b/src/lib/kadm5/unit-test/Makefile.in +deleted file mode 100644 +index 68fa097ff..000000000 +--- a/src/lib/kadm5/unit-test/Makefile.in ++++ /dev/null +@@ -1,143 +0,0 @@ +-mydir=lib$(S)kadm5$(S)unit-test +-BUILDTOP=$(REL)..$(S)..$(S).. +-KDB_DEP_LIB=$(DL_LIB) $(THREAD_LINKOPTS) +- +-SRCS= init-test.c destroy-test.c handle-test.c iter-test.c setkey-test.c \ +- randkey-test.c lock-test.c +- +-# +-# The client-side test programs. +-# +- +-init-test: init-test.o $(KADMCLNT_DEPLIBS) $(KRB5_BASE_DEPLIBS) +- $(CC_LINK) -o init-test init-test.o \ +- $(KADMCLNT_LIBS) $(KRB5_BASE_LIBS) +- +-destroy-test: destroy-test.o $(KADMCLNT_DEPLIBS) $(KRB5_BASE_DEPLIBS) +- $(CC_LINK) -o destroy-test destroy-test.o \ +- $(KADMCLNT_LIBS) $(KRB5_BASE_LIBS) +- +-client-handle-test: client-handle-test.o $(KADMCLNT_DEPLIBS) $(KRB5_BASE_DEPLIBS) +- $(CC_LINK) -o client-handle-test client-handle-test.o \ +- $(KADMCLNT_LIBS) $(KRB5_BASE_LIBS) +- +-client-handle-test.o: handle-test.c +- $(CC) $(ALL_CFLAGS) -DCLIENT_TEST -o client-handle-test.o -c $(srcdir)/handle-test.c +- +-client-iter-test: iter-test.o $(KADMLCNT_DEPLIBS) $(KRB5_BASE_DEPLIBS) +- $(CC_LINK) -o client-iter-test iter-test.o \ +- $(KADMCLNT_LIBS) $(KRB5_BASE_LIBS) +- +-client-setkey-test: setkey-test.o $(KADMCLNT_DEPLIBS) $(KRB5_BASE_DEPLIBS) +- $(CC_LINK) -o client-setkey-test setkey-test.o \ +- $(KADMCLNT_LIBS) $(KRB5_BASE_LIBS) +- +-# +-# The server-side test programs. +-# +- +-randkey-test: randkey-test.o $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIBS) +- $(CC_LINK) -o randkey-test randkey-test.o \ +- $(KADMSRV_LIBS) $(KDB_DEP_LIB) $(KRB5_BASE_LIBS) +- +-server-handle-test: handle-test.o $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIBS) +- $(CC_LINK) -o server-handle-test handle-test.o \ +- $(KADMSRV_LIBS) $(KDB_DEP_LIB) $(KRB5_BASE_LIBS) +- +-lock-test: lock-test.o $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIBS) +- $(CC_LINK) -o lock-test lock-test.o \ +- $(KADMSRV_LIBS) $(KDB_DEP_LIB) $(KRB5_BASE_LIBS) +- +-server-iter-test: iter-test.o $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIBS) +- $(CC_LINK) -o server-iter-test iter-test.o \ +- $(KADMSRV_LIBS) $(KDB_DEP_LIB) $(KRB5_BASE_LIBS) +- +-server-setkey-test: setkey-test.o $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIBS) +- $(CC_LINK) -o server-setkey-test setkey-test.o \ +- $(KADMSRV_LIBS) $(KDB_DEP_LIB) $(KRB5_BASE_LIBS) +- +-runenv.exp: Makefile +- $(RUN_SETUP); for i in $(RUN_VARS); do \ +- eval echo "set env\($$i\) \$$$$i"; done > runenv.exp +- +-# +-# The unit-test targets +-# +- +-check: check-@DO_TEST@ +- +-check-: +- @echo "+++" +- @echo "+++ WARNING: lib/kadm5 unit tests not run." +- @echo "+++ Either tcl, runtest, or Perl is unavailable." +- @echo "+++" +- +-check-ok unit-test: unit-test-client unit-test-server +- +-unit-test-client: unit-test-client-setup unit-test-client-body \ +- unit-test-client-cleanup +- +-unit-test-server: unit-test-server-setup unit-test-server-body \ +- unit-test-server-cleanup +- +-test-randkey: randkey-test +- $(ENV_SETUP) $(VALGRIND) ./randkey-test +- +-test-handle-server: server-handle-test +- $(ENV_SETUP) $(VALGRIND) ./server-handle-test +- +-test-handle-client: client-handle-test +- $(ENV_SETUP) $(VALGRIND) ./client-handle-test +- +-test-noauth: init-test +- $(ENV_SETUP) $(VALGRIND) ./init-test +- +-test-destroy: destroy-test +- $(ENV_SETUP) $(VALGRIND) ./destroy-test +- +-test-setkey-client: client-setkey-test +- $(ENV_SETUP) $(VALGRIND) ./client-setkey-test testkeys admin admin +- +-unit-test-client-setup: runenv.sh +- $(ENV_SETUP) $(VALGRIND) $(START_SERVERS) +- +-unit-test-client-cleanup: +- $(ENV_SETUP) $(STOP_SERVERS) +- +-unit-test-server-setup: runenv.sh +- $(ENV_SETUP) $(VALGRIND) $(START_SERVERS_LOCAL) +- +-unit-test-server-cleanup: +- $(ENV_SETUP) $(STOP_SERVERS_LOCAL) +- +-unit-test-client-body: site.exp test-noauth test-destroy test-handle-client \ +- test-setkey-client runenv.exp +- $(ENV_SETUP) $(RUNTEST) --tool api RPC=1 API=$(CLNTTCL) \ +- KINIT=$(BUILDTOP)/clients/kinit/kinit \ +- KDESTROY=$(BUILDTOP)/clients/kdestroy/kdestroy \ +- KADMIN_LOCAL=$(BUILDTOP)/kadmin/cli/kadmin.local \ +- PRIOCNTL_HACK=@PRIOCNTL_HACK@ VALGRIND="$(VALGRIND)" \ +- $(RUNTESTFLAGS) +- -mv api.log capi.log +- -mv api.sum capi.sum +- +-unit-test-server-body: site.exp test-handle-server lock-test +- $(ENV_SETUP) $(RUNTEST) --tool api RPC=0 API=$(SRVTCL) \ +- LOCKTEST=./lock-test \ +- KADMIN_LOCAL=$(BUILDTOP)/kadmin/cli/kadmin.local \ +- PRIOCNTL_HACK=@PRIOCNTL_HACK@ VALGRIND="$(VALGRIND)" \ +- $(RUNTESTFLAGS) +- -mv api.log sapi.log +- -mv api.sum sapi.sum +- +-clean: +- $(RM) init-test client_init.o init-test.o +- $(RM) destroy-test destroy-test.o +- $(RM) client-handle-test handle-test.o client-handle-test.o +- $(RM) client-iter-test iter-test.o +- $(RM) randkey-test randkey-test.o +- $(RM) server-handle-test handle-test.o +- $(RM) lock-test lock-test.o +- $(RM) server-iter-test iter-test.o +- $(RM) server-setkey-test client-setkey-test setkey-test.o +- $(RM) *.log *.plog *.sum *.psum unit-test-log.* runenv.exp +diff --git a/src/lib/kadm5/unit-test/api.2/crte-policy.exp b/src/lib/kadm5/unit-test/api.2/crte-policy.exp +deleted file mode 100644 +index 4902ea59f..000000000 +--- a/src/lib/kadm5/unit-test/api.2/crte-policy.exp ++++ /dev/null +@@ -1,927 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-# Description: (1) Fails for mask with undefined bit set. +-# 01/24/94: pshuang: untried. +-test "create-policy 1" +-proc test1 {} { +- global test +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete policy \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- 0xF01000 +- } $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test1 +- +-# Description: (2) Fails if caller connected with CHANGEPW_SERVICE. +-test "create-policy 2" +-proc test2 {} { +- global test +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy"; +- return +- } +-} +-if {$RPC} { test2 } +- +-# Description: (3) Fails for mask without POLICY bit set. +-# 01/24/94: pshuang: untried. +-test "create-policy 3" +-proc test3 {} { +- global test +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete policy \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- 0x000000 +- } $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test3 +- +-# Description: (5) Fails for invalid policy name. +-# 01/24/94: pshuang: untried. +-test "create-policy 5" +-proc test5 {} { +- global test +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/"] \ +- {KADM5_POLICY} +- } $test] "BAD_POLICY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test5 +- +-# Description: (6) Fails for existing policy name. +-test "create-policy 6" +-proc test6 {} { +- global test +-# set prms_id 777 +-# setup_xfail {*-*-*} $prms_id +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test { +- kadm5_create_policy $server_handle [simple_policy test-pol] \ +- {KADM5_POLICY} +- } "DUP" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test6 +- +-# Description: (7) Fails for null policy name. +-# 01/24/94: pshuang: untried. +-test "create-policy 7" +-proc test7 {} { +- global test +-# set prms_id 1977 +-# setup_xfail {*-*-*} $prms_id +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test { +- kadm5_create_policy $server_handle [simple_policy null] \ +- {KADM5_POLICY} +- } "EINVAL" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test7 +- +-# Description: (8) Fails for empty-string policy name. +-test "create-policy 8" +-proc test8 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test { +- kadm5_create_policy $server_handle [simple_policy ""] \ +- {KADM5_POLICY} +- } "BAD_POLICY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test8 +- +-# Description: (9) Accepts 0 for pw_min_life. +-test "create-policy 9" +-proc test9 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY KADM5_PW_MIN_LIFE} +- } $test]]} { +- fail "$test: create failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 1\n" +- expect { +- -re "0\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test9 +- +-# Description: (10) Accepts non-zero for pw_min_life. +-test "create-policy 10" +-proc test10 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_create_policy $server_handle {"%s/a" 32 0 0 0 0 0 } \ +- {KADM5_POLICY KADM5_PW_MIN_LIFE} +- } $test]]} { +- fail "$test" +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retreuve policy" +- return +- } +- send "lindex \$policy 1\n" +- expect { +- -re "32\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test10 +- +-# Description: (11) Accepts 0 for pw_max_life. +-test "create-policy 11" +-proc test11 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY KADM5_PW_MAX_LIFE} +- } $test]]} { +- fail "$test" +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retreuve policy" +- return +- } +- send "lindex \$policy 2\n" +- expect { +- -re "0\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test11 +- +-# Description: (12) Accepts non-zero for pw_max_life. +-test "create-policy 12" +-proc test12 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_policy $server_handle {"%s/a" 0 32 0 0 0 0 } \ +- {KADM5_POLICY KADM5_PW_MAX_LIFE} +- } $test]]} { +- fail "$test" +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retreuve policy" +- return +- } +- send "lindex \$policy 2\n" +- expect { +- -re "32\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test12 +- +-# Description: (13) Rejects 0 for pw_min_length. +-test "create-policy 13" +-proc test13 {} { +- global test +- global prompt +- +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY KADM5_PW_MIN_LENGTH} +- } $test] "BAD_LENGTH" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test13 +- +-# Description: (14) Accepts non-zero for pw_min_length. +-test "create-policy 14" +-proc test14 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_policy $server_handle {"%s/a" 0 0 8 0 0 0 } \ +- {KADM5_POLICY KADM5_PW_MIN_LENGTH} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retreuve policy" +- return +- } +- send "lindex \$policy 3\n" +- expect { +- -re "8\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test14 +- +-# Description: (15) Rejects 0 for pw_min_classes. +-test "create-policy 15" +-proc test15 {} { +- global test +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY KADM5_PW_MIN_CLASSES} +- } $test] "BAD_CLASS" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test15 +- +-# Description: (16) Accepts 1 for pw_min_classes. +-test "create-policy 16" +-proc test16 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_policy $server_handle {"%s/a" 0 0 0 1 0 0 } \ +- {KADM5_POLICY KADM5_PW_MIN_CLASSES} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retreuve policy" +- return +- } +- send "lindex \$policy 4\n" +- expect { +- -re "1\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test16 +- +-# Description: (17) Accepts 4 for pw_min_classes. +-test "create-policy 17" +-proc test17 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_policy $server_handle {"%s/a" 0 0 0 5 0 0} \ +- {KADM5_POLICY KADM5_PW_MIN_CLASSES} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retreuve policy" +- return +- } +- send "lindex \$policy 4\n" +- expect { +- -re "5\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test17 +- +-# Description: (18) Rejects 5 for pw_min_classes. +-test "create-policy 18" +-proc test18 {} { +- global test +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle {"%s/a" 0 0 0 6 0 0} \ +- {KADM5_POLICY KADM5_PW_MIN_CLASSES} +- } $test] "BAD_CLASS" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test18 +- +-# Description: (19) Rejects 0 for pw_history_num. +-test "create-policy 19" +-proc test19 {} { +- global test +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY KADM5_PW_HISTORY_NUM} +- } $test] "BAD_HISTORY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test19 +- +-# Description: (20) Accepts 1 for pw_history_num. +-test "create-policy 20" +-proc test20 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_policy $server_handle {"%s/a" 0 0 0 0 1 0} \ +- {KADM5_POLICY KADM5_PW_HISTORY_NUM} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retreuve policy" +- return +- } +- send "lindex \$policy 5\n" +- expect { +- -re "1\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test20 +- +-# Description: (21) Accepts 10 for pw_history_num. +-test "create-policy 21" +-proc test21 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_policy $server_handle {"%s/a" 0 0 0 0 10 0} \ +- {KADM5_POLICY KADM5_PW_HISTORY_NUM} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 5\n" +- expect { +- -re "10\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test21 +- +-# Description: (22) Fails for user with no access bits. +-test "create-policy 22" +-proc test22 {} { +- global test +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} test22 +- +-# Description: (23) Fails for user with "get" but not "add". +-test "create-policy 23" +-proc test23 {} { +- global test +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} test23 +- +-# Description: (24) Fails for user with "modify" but not "add". +-# 01/24/94: pshuang: untried. +-test "create-policy 24" +-proc test24 {} { +- global test +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} test24 +- +-# Description: (25) Fails for user with "delete" but not "add". +-# 01/24/94: pshuang: untried. +-test "create-policy 25" +-proc test25 {} { +- global test +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} test25 +- +-# Description: Succeeds for user with "add". +-test "create-policy 26" +-proc test26 {} { +- global test +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test26 +- +-# Description: Succeeds for user with "get" and "add". +-# 01/24/94: pshuang: untried. +-test "create-policy 27" +-proc test27 {} { +- global test +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/get-add admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test27 +- +-# Description: (28) Rejects null policy argument. +-# 01/24/94: pshuang: untried. +-test "create-policy 28" +-proc test28 {} { +- global test +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test { +- kadm5_create_policy $server_handle null {KADM5_POLICY} +- } "EINVAL" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test28 +- +-test "create-policy 30" +-proc test30 {} { +- global test +- one_line_fail_test [format { +- kadm5_create_policy null [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] "BAD_SERVER_HANDLE" +-} +-test30 +- +-return "" +diff --git a/src/lib/kadm5/unit-test/api.2/get-policy.exp b/src/lib/kadm5/unit-test/api.2/get-policy.exp +deleted file mode 100644 +index 83aef80e8..000000000 +--- a/src/lib/kadm5/unit-test/api.2/get-policy.exp ++++ /dev/null +@@ -1,199 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-test "get-policy 3" +-proc test3 {} { +- global test +-# set prms_id 744 +-# setup_xfail {*-*-*} $prms_id +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test {kadm5_get_policy $server_handle "" p} "BAD_POLICY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test3 +- +-test "get-policy 6" +-proc test6 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test {kadm5_get_policy $server_handle test-pol p} \ +- "AUTH_GET" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if { $RPC } test6 +- +-test "get-policy 7" +-proc test7 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test {kadm5_get_policy $server_handle test-pol p} \ +- "AUTH_GET" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if { $RPC } test7 +- +-test "get-policy 11" +-proc test11 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/get-pol StupidAdmin $KADM5_ADMIN_SERVICE \ +- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test {kadm5_get_policy $server_handle test-pol p} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test11 +- +-test "get-policy 12" +-proc test12 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/get-pol StupidAdmin \ +- $KADM5_CHANGEPW_SERVICE null $KADM5_STRUCT_VERSION \ +- $KADM5_API_VERSION_2 server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test \ +- {kadm5_get_policy $server_handle test-pol-nopw p} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test12 +- +-test "get-policy 15" +-proc test15 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/pol StupidAdmin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test \ +- {kadm5_get_policy $server_handle test-pol-nopw p} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test15 +- +-test "get-policy 16" +-proc test16 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/pol StupidAdmin $KADM5_CHANGEPW_SERVICE \ +- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test \ +- {kadm5_get_policy $server_handle test-pol-nopw p} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test16 +- +-test "get-policy 17" +-proc test17 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test {kadm5_get_policy $server_handle test-pol p} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test17 +- +-test "get-policy 18" +-proc test18 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test {kadm5_get_policy $server_handle test-pol p} \ +- "AUTH_GET" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if { $RPC } test18 +- +-test "get-policy 21" +-proc test21 {} { +- global test +- +- one_line_fail_test {kadm5_get_policy null "pol1" p} "BAD_SERVER_HANDLE" +-} +-test21 +diff --git a/src/lib/kadm5/unit-test/api.2/mod-policy.exp b/src/lib/kadm5/unit-test/api.2/mod-policy.exp +deleted file mode 100644 +index 904edca8a..000000000 +--- a/src/lib/kadm5/unit-test/api.2/mod-policy.exp ++++ /dev/null +@@ -1,675 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-test "modify-policy 2" +-proc test2 {} { +- global test +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MAX_LIFE} +- } $test] "AUTH_MODIFY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test2 } +- +-test "modify-policy 8" +-proc test8 {} { +- global test +-# set prms_id 744 +-# setup_xfail {*-*-*} $prms_id +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test { +- kadm5_modify_policy $server_handle [simple_policy ""] \ +- {KADM5_PW_MAX_LIFE} +- } "BAD_POLICY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test8 +- +-test "modify-policy 9" +-proc test9 {} { +- global test +- global prompt +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MIN_LIFE} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 1\n" +- expect { +- -re "0\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test9 +- +-test "modify-policy 10" +-proc test10 {} { +- global test +- global prompt +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle {"%s/a" 32 0 0 0 0 0} \ +- {KADM5_PW_MIN_LIFE} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 1\n" +- expect { +- -re "32\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test10 +- +- +-test "modify-policy 11" +-proc test11 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MAX_LIFE} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 2\n" +- expect { +- -re "0\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test11 +- +-test "modify-policy 12" +-proc test12 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 32 0 0 0 0} \ +- {KADM5_PW_MAX_LIFE} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 2\n" +- expect { +- -re "32\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test12 +- +-test "modify-policy 13" +-proc test13 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MIN_LENGTH} +- } $test] "BAD_LENGTH" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test13 +- +-test "modify-policy 14" +-proc test14 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 8 0 0 0} \ +- {KADM5_PW_MIN_LENGTH} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 3\n" +- expect { +- -re "8\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test14 +- +-test "modify-policy 15" +-proc test15 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MIN_CLASSES} +- } $test] "BAD_CLASS" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test15 +- +-test "modify-policy 16" +-proc test16 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 1 0 0} \ +- {KADM5_PW_MIN_CLASSES} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 4\n" +- expect { +- -re "1\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test16 +- +-test "modify-policy 17" +-proc test17 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 5 0 0} \ +- {KADM5_PW_MIN_CLASSES} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 4\n" +- expect { +- -re "5\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test17 +- +-test "modify-policy 18" +-proc test18 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 6 0 0} \ +- {KADM5_PW_MIN_CLASSES} +- } $test] "BAD_CLASS" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test18 +- +-test "modify-policy 19" +-proc test19 {} { +- global test +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_HISTORY_NUM} +- } $test] "BAD_HISTORY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test19 +- +-test "modify-policy 20" +-proc test20 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 0 1 0} \ +- {KADM5_PW_HISTORY_NUM} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 5\n" +- expect { +- -re "1\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test20 +- +-test "modify-policy 21" +-proc test21 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 0 10 0} \ +- {KADM5_PW_HISTORY_NUM} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 5\n" +- expect { +- -re "10\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test21 +- +-test "modify-policy 22" +-proc test22 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MAX_LIFE} +- } $test] "AUTH_MODIFY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} test22 +- +-test "modify-policy 23" +-proc test23 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MAX_LIFE} +- } $test] "AUTH_MODIFY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} test23 +- +-test "modify-policy 26" +-proc test26 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MAX_LIFE} +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test26 +- +-test "modify-policy 30" +-proc test30 {} { +- global test +- +- one_line_fail_test [format { +- kadm5_modify_policy null [simple_policy "%s/a"] \ +- {KADM5_PW_MAX_LIFE} +- } $test] "BAD_SERVER_HANDLE" +-} +-test30 +- +-return "" +diff --git a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp +deleted file mode 100644 +index 740425c69..000000000 +--- a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp ++++ /dev/null +@@ -1,68 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-test "chpass-principal 200" +-proc test200 {} { +- global test prompt +- +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [create_principal "$test/a"]} { +- error_and_restart "$test: creating principal" +- return +- } +- +- # I'd like to specify a long list of keysalt tuples and make sure +- # that chpass does the right thing, but we can only use those +- # enctypes that krbtgt has a key for: the AES enctypes, according to +- # the prototype kdc.conf. +- if {! [cmd [format { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_chpass_principal $server_handle "%s/a" newpassword +- } $test]]} { +- perror "$test: unexpected failure in chpass_principal" +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" p \ +- {KADM5_PRINCIPAL_NORMAL_MASK KADM5_KEY_DATA} +- } $test]]} { +- perror "$test: unexpected failure in get_principal" +- } +- send "lindex \$p 16\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" { set num_keys $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting num_keys" +- return +- } +- eof { +- error_and_restart "$test: eof getting num_keys" +- return +- } +- } +- +- # XXX Perhaps I should actually check the key type returned. +- if {$num_keys == 5} { +- pass "$test" +- } else { +- fail "$test: $num_keys keys, should be 5" +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test200 +- +-return "" +diff --git a/src/lib/kadm5/unit-test/api.current/chpass-principal.exp b/src/lib/kadm5/unit-test/api.current/chpass-principal.exp +deleted file mode 100644 +index 47a19dc20..000000000 +--- a/src/lib/kadm5/unit-test/api.current/chpass-principal.exp ++++ /dev/null +@@ -1,176 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-test "chpass-principal 180" +-proc test180 {} { +- global test +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [create_principal_pol "$test/a" once-a-min]} { +- error_and_restart "$test: creating principal" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_chpass_principal $server_handle "%s/a" FoobarBax +- } $test] +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if { $RPC } { test180 } +- +-test "chpass-principal 180.5" +-proc test1805 {} { +- global test +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [create_principal_pol "$test/a" once-a-min]} { +- error_and_restart "$test: creating principal" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_chpass_principal $server_handle "%s/a" FoobarBax +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if { $RPC } { test1805 } +- +-# +-# admin with changepw service tickets try to change other principals +-# password, fails with AUTH error +-test "chpass-principal 180.625" +-proc test180625 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_chpass_principal $server_handle "%s/a" password +- } $test] "AUTH" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test180625 } +- +-test "chpass-principal 180.75" +-proc test18075 {} { +- global test +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [create_principal_pol "$test/a" once-a-min]} { +- error_and_restart "$test: creating principal" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_chpass_principal $server_handle "%s/a" Foobar +- } $test] "AUTH_CHANGEPW" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if { $RPC } { test18075 } +- +-test "chpass-principal 182" +-proc test182 {} { +- global test +- +- if { ! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test { +- kadm5_chpass_principal $server_handle kadmin/history password +- } "PROTECT" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test182 +- +-test "chpass-principal 183" +-proc test183 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if { ! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_chpass_principal null "%s/a" password +- } $test] "BAD_SERVER_HANDLE" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test183 +- +-return "" +diff --git a/src/lib/kadm5/unit-test/api.current/crte-policy.exp b/src/lib/kadm5/unit-test/api.current/crte-policy.exp +deleted file mode 100644 +index 7e1eda63f..000000000 +--- a/src/lib/kadm5/unit-test/api.current/crte-policy.exp ++++ /dev/null +@@ -1,927 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-# Description: (1) Fails for mask with undefined bit set. +-# 01/24/94: pshuang: untried. +-test "create-policy 1" +-proc test1 {} { +- global test +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete policy \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- 0xF01000 +- } $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test1 +- +-# Description: (2) Fails if caller connected with CHANGEPW_SERVICE. +-test "create-policy 2" +-proc test2 {} { +- global test +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy"; +- return +- } +-} +-if {$RPC} { test2 } +- +-# Description: (3) Fails for mask without POLICY bit set. +-# 01/24/94: pshuang: untried. +-test "create-policy 3" +-proc test3 {} { +- global test +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete policy \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- 0x000000 +- } $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test3 +- +-# Description: (5) Fails for invalid policy name. +-# 01/24/94: pshuang: untried. +-test "create-policy 5" +-proc test5 {} { +- global test +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/"] \ +- {KADM5_POLICY} +- } $test] "BAD_POLICY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test5 +- +-# Description: (6) Fails for existing policy name. +-test "create-policy 6" +-proc test6 {} { +- global test +-# set prms_id 777 +-# setup_xfail {*-*-*} $prms_id +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test { +- kadm5_create_policy $server_handle [simple_policy test-pol] \ +- {KADM5_POLICY} +- } "DUP" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test6 +- +-# Description: (7) Fails for null policy name. +-# 01/24/94: pshuang: untried. +-test "create-policy 7" +-proc test7 {} { +- global test +-# set prms_id 1977 +-# setup_xfail {*-*-*} $prms_id +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test { +- kadm5_create_policy $server_handle [simple_policy null] \ +- {KADM5_POLICY} +- } "EINVAL" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test7 +- +-# Description: (8) Fails for empty-string policy name. +-test "create-policy 8" +-proc test8 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test { +- kadm5_create_policy $server_handle [simple_policy ""] \ +- {KADM5_POLICY} +- } "BAD_POLICY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test8 +- +-# Description: (9) Accepts 0 for pw_min_life. +-test "create-policy 9" +-proc test9 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY KADM5_PW_MIN_LIFE} +- } $test]]} { +- fail "$test: create failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 1\n" +- expect { +- -re "0\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test9 +- +-# Description: (10) Accepts non-zero for pw_min_life. +-test "create-policy 10" +-proc test10 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_create_policy $server_handle {"%s/a" 32 0 0 0 0 0 } \ +- {KADM5_POLICY KADM5_PW_MIN_LIFE} +- } $test]]} { +- fail "$test" +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retreuve policy" +- return +- } +- send "lindex \$policy 1\n" +- expect { +- -re "32\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test10 +- +-# Description: (11) Accepts 0 for pw_max_life. +-test "create-policy 11" +-proc test11 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY KADM5_PW_MAX_LIFE} +- } $test]]} { +- fail "$test" +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retreuve policy" +- return +- } +- send "lindex \$policy 2\n" +- expect { +- -re "0\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test11 +- +-# Description: (12) Accepts non-zero for pw_max_life. +-test "create-policy 12" +-proc test12 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_policy $server_handle {"%s/a" 0 32 0 0 0 0 } \ +- {KADM5_POLICY KADM5_PW_MAX_LIFE} +- } $test]]} { +- fail "$test" +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retreuve policy" +- return +- } +- send "lindex \$policy 2\n" +- expect { +- -re "32\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test12 +- +-# Description: (13) Rejects 0 for pw_min_length. +-test "create-policy 13" +-proc test13 {} { +- global test +- global prompt +- +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY KADM5_PW_MIN_LENGTH} +- } $test] "BAD_LENGTH" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test13 +- +-# Description: (14) Accepts non-zero for pw_min_length. +-test "create-policy 14" +-proc test14 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_policy $server_handle {"%s/a" 0 0 8 0 0 0 } \ +- {KADM5_POLICY KADM5_PW_MIN_LENGTH} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retreuve policy" +- return +- } +- send "lindex \$policy 3\n" +- expect { +- -re "8\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test14 +- +-# Description: (15) Rejects 0 for pw_min_classes. +-test "create-policy 15" +-proc test15 {} { +- global test +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY KADM5_PW_MIN_CLASSES} +- } $test] "BAD_CLASS" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test15 +- +-# Description: (16) Accepts 1 for pw_min_classes. +-test "create-policy 16" +-proc test16 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_policy $server_handle {"%s/a" 0 0 0 1 0 0 } \ +- {KADM5_POLICY KADM5_PW_MIN_CLASSES} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retreuve policy" +- return +- } +- send "lindex \$policy 4\n" +- expect { +- -re "1\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test16 +- +-# Description: (17) Accepts 4 for pw_min_classes. +-test "create-policy 17" +-proc test17 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_policy $server_handle {"%s/a" 0 0 0 5 0 0} \ +- {KADM5_POLICY KADM5_PW_MIN_CLASSES} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retreuve policy" +- return +- } +- send "lindex \$policy 4\n" +- expect { +- -re "5\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test17 +- +-# Description: (18) Rejects 5 for pw_min_classes. +-test "create-policy 18" +-proc test18 {} { +- global test +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle {"%s/a" 0 0 0 6 0 0} \ +- {KADM5_POLICY KADM5_PW_MIN_CLASSES} +- } $test] "BAD_CLASS" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test18 +- +-# Description: (19) Rejects 0 for pw_history_num. +-test "create-policy 19" +-proc test19 {} { +- global test +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY KADM5_PW_HISTORY_NUM} +- } $test] "BAD_HISTORY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test19 +- +-# Description: (20) Accepts 1 for pw_history_num. +-test "create-policy 20" +-proc test20 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_policy $server_handle {"%s/a" 0 0 0 0 1 0} \ +- {KADM5_POLICY KADM5_PW_HISTORY_NUM} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retreuve policy" +- return +- } +- send "lindex \$policy 5\n" +- expect { +- -re "1\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test20 +- +-# Description: (21) Accepts 10 for pw_history_num. +-test "create-policy 21" +-proc test21 {} { +- global test +- global prompt +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_policy $server_handle {"%s/a" 0 0 0 0 10 0} \ +- {KADM5_POLICY KADM5_PW_HISTORY_NUM} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 5\n" +- expect { +- -re "10\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test21 +- +-# Description: (22) Fails for user with no access bits. +-test "create-policy 22" +-proc test22 {} { +- global test +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} test22 +- +-# Description: (23) Fails for user with "get" but not "add". +-test "create-policy 23" +-proc test23 {} { +- global test +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} test23 +- +-# Description: (24) Fails for user with "modify" but not "add". +-# 01/24/94: pshuang: untried. +-test "create-policy 24" +-proc test24 {} { +- global test +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} test24 +- +-# Description: (25) Fails for user with "delete" but not "add". +-# 01/24/94: pshuang: untried. +-test "create-policy 25" +-proc test25 {} { +- global test +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} test25 +- +-# Description: Succeeds for user with "add". +-test "create-policy 26" +-proc test26 {} { +- global test +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test26 +- +-# Description: Succeeds for user with "get" and "add". +-# 01/24/94: pshuang: untried. +-test "create-policy 27" +-proc test27 {} { +- global test +- +- if {! (( ! [policy_exists "$test/a"]) || +- [delete_policy "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/get-add admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test27 +- +-# Description: (28) Rejects null policy argument. +-# 01/24/94: pshuang: untried. +-test "create-policy 28" +-proc test28 {} { +- global test +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test { +- kadm5_create_policy $server_handle null {KADM5_POLICY} +- } "EINVAL" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test28 +- +-test "create-policy 30" +-proc test30 {} { +- global test +- one_line_fail_test [format { +- kadm5_create_policy null [simple_policy "%s/a"] \ +- {KADM5_POLICY} +- } $test] "BAD_SERVER_HANDLE" +-} +-test30 +- +-return "" +diff --git a/src/lib/kadm5/unit-test/api.current/crte-principal.exp b/src/lib/kadm5/unit-test/api.current/crte-principal.exp +deleted file mode 100644 +index d6d6809ec..000000000 +--- a/src/lib/kadm5/unit-test/api.current/crte-principal.exp ++++ /dev/null +@@ -1,1336 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-#test "create-principal 1" +-# +-#proc test1 {} { +-# global test +-# begin_dump +-# one_line_fail_test [format { +-# kadm5_create_principal $server_handle \ +-# [simple_principal "%s/a"] {KADM5_PRINCIPAL} "%s/a" +-# } $test $test] "NOT_INIT" +-# end_dump_compare "no-diffs" +-#} +-#test1 +- +-# v2 create-principal 3 test, to avoid name conflict +-test "create-principal 1" +-proc test1 {} { +- global test +-# set prms_id 777 +-# setup_xfail {*-*-*} $prms_id +- begin_dump +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} null +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test1 +- +-test "create-principal 2" +- +-proc test2 {} { +- global test +- begin_dump +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test { +- kadm5_create_principal $server_handle null \ +- {KADM5_PRINCIPAL} testpass +- } "EINVAL" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test2 +- +-test "create-principal 4" +-proc test4 {} { +- global test +- +- begin_dump +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} "" +- } $test] "_Q_TOOSHORT" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test4 +- +-test "create-principal 5" +-proc test5 {} { +- global test +- begin_dump +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle \ +- [simple_principal "%s/a"] {0x100001} "%s/a" +- } $test $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test5 +- +-test "create-principal 6" +-proc test6 {} { +- global test +- begin_dump +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_LAST_PWD_CHANGE} "%s/a" +- } $test $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test6 +- +-test "create-principal 7" +-proc test7 {} { +- global test +- begin_dump +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_MOD_TIME} "%s/a" +- } $test $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test7 +- +-test "create-principal 8" +-proc test8 {} { +- global test +- begin_dump +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_MOD_NAME} "%s/a" +- } $test $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test8 +- +-test "create-principal 9" +-proc test9 {} { +- global test +- begin_dump +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_MKVNO} "%s/a" +- } $test $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test9 +- +-test "create-principal 10" +-proc test10 {} { +- global test +- begin_dump +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_AUX_ATTRIBUTES} "%s/a" +- } $test $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test10 +- +-test "create-principal 11" +-proc test11 {} { +- global test +- begin_dump +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_POLICY_CLR} "%s/a" +- } $test $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test11 +- +-test "create-principal 12" +-proc test12 {} { +- global test +- begin_dump +- if {! [cmd { +- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} testpass +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +- +-} +-if {$RPC} { test12 } +- +-test "create-principal 13" +-proc test13 {} { +- global test +- begin_dump +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} testpass +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-if {$RPC} { test13 } +- +-test "create-principal 14" +-proc test14 {} { +- global test +- begin_dump +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} testpass +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-if {$RPC} { test14 } +- +-test "create-principal 15" +-proc test15 {} { +- global test +- begin_dump +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} testpass +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-if {$RPC} { test15 } +- +-test "create-principal 16" +-proc test16 {} { +- global test +- begin_dump +- if {! [cmd { +- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} testpass +- } $test] "AUTH_ADD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-if {$RPC} { test16 } +- +-test "create-principal 17" +-proc test17 {} { +- global test +- +- begin_dump +- if {! (( [principal_exists "$test/a"]) || [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} testpass +- } $test] "DUP" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test17 +- +-test "create-principal 18" +-proc test18 {} { +- global test +- +- begin_dump +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle \ +- [princ_w_pol "%s/a" test-pol] \ +- {KADM5_PRINCIPAL KADM5_POLICY} tP +- } $test] "_Q_TOOSHORT" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test18 +- +-test "create-principal 19" +-proc test19 {} { +- global test +- +- begin_dump +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle \ +- [princ_w_pol "%s/a" test-pol] \ +- {KADM5_PRINCIPAL KADM5_POLICY} testpassword +- } $test] "_Q_CLASS" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test19 +- +-test "create-principal 20" +-proc test20 {} { +- global test +- +- begin_dump +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_create_principal $server_handle \ +- [princ_w_pol "%s/a" test-pol] \ +- {KADM5_PRINCIPAL KADM5_POLICY} Abyssinia +- } $test] "_Q_DICT" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test20 +- +-test "create-principal 21" +-proc test21 {} { +- global test +- +- begin_dump +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_create_principal $server_handle \ +- [princ_w_pol "%s/a" non-existant-pol] \ +- {KADM5_PRINCIPAL KADM5_POLICY} NotinTheDictionary +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- end_dump_compare "no-diffs" +-} +-test21 +- +-test "create-principal 23" +-proc test23 {} { +- global test +- +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} NotinTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- one_line_succeed_test \ +- [format {kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK} $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test23 +- +-test "create-principal 24" +-proc test24 {} { +- global test +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/rename admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} NotinTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- one_line_succeed_test \ +- [format {kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK} $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test24 } +- +- +-test "create-principal 28" +-proc test28 {} { +- global test +- global prompt +- +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- +- if {! [cmd [format { +- kadm5_create_principal $server_handle \ +- [princ_w_pol "%s/a" test-pol] \ +- {KADM5_PRINCIPAL KADM5_POLICY} NotinTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- fail "$test: can not retrieve principal" +- return +- } +- send "lindex \$principal 10\n" +- expect { +- -re "test-pol.*$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test28 +- +-test "create-principal 29" +-proc test29 {} { +- global test +- global prompt +- +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL KADM5_PRINC_EXPIRE_TIME} \ +- inTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- fail "$test: can not retrieve principal" +- return; +- } +- send "lindex \$principal 1\n" +- expect { +- -re "0.*$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test29 +- +-test "create-principal 30" +-proc test30 {} { +- global test +- global prompt +- +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL KADM5_PW_EXPIRATION} \ +- NotinTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- fail "$test: can not retrieve principal" +- return; +- } +- send "lindex \$principal 3\n" +- expect { +- -re "0.*$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test30 +- +-test "create-principal 31" +-proc test31 {} { +- global test +- global prompt +- +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle \ +- [princ_w_pol "%s/a" test-pol-nopw] \ +- {KADM5_PRINCIPAL KADM5_POLICY \ +- KADM5_PW_EXPIRATION} NotinTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- fail "$test: can not retrieve principal" +- return; +- } +- send "lindex \$principal 3\n" +- expect { +- -re "0.*$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test31 +- +-test "create-principal 32" +-proc test32 {} { +- global test +- global prompt +- +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle \ +- [princ_w_pol "%s/a" test-pol] \ +- {KADM5_PRINCIPAL KADM5_POLICY \ +- KADM5_PW_EXPIRATION} NotinTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- fail "$test: can not retrieve principal" +- return; +- } +- if { ! [cmd {kadm5_get_policy $server_handle test-pol policy}]} { +- error_and_restart "$test: cannot retrieve policy" +- return +- } +- +- send "lindex \$principal 6\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set mod_date $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting mod_date" +- return +- } +- eof { +- error_and_restart "$test: eof getting mod_date" +- return +- } +- } +- +- send "lindex \$principal 3\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_expire $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting pw_expire" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_expire" +- return +- } +- } +- +- send "lindex \$policy 2\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_max_life $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting pw_max_life" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_max_life" +- return +- } +- } +- if { $pw_expire != 0 } { +- fail "$test: pw_expire $pw_expire should be 0" +- return +- } else { +- pass "$test" +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test32 +- +-test "create-principal 33" +-proc test33 {} { +- global test +- global prompt +- +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle \ +- {"%s/a" 0 0 1234 0 null 0 0 0 0 null 0} \ +- {KADM5_PRINCIPAL KADM5_PW_EXPIRATION} \ +- NotinTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- fail "$test: can not retrieve principal" +- return; +- } +- send "lindex \$principal 3\n" +- expect { +- -re "1234.*$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test33 +- +-test "create-principal 34" +-proc test34 {} { +- global test +- global prompt +- +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle \ +- { "%s/a" 0 0 1234 0 null 0 0 0 0 test-pol-nopw 0} \ +- {KADM5_PRINCIPAL KADM5_POLICY \ +- KADM5_PW_EXPIRATION} NotinTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- fail "$test: can not retrieve principal" +- return; +- } +- send "lindex \$principal 3\n" +- expect { +- -re "1234.*$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test34 +- +-test "create-principal 35" +-proc test35 {} { +- global test +- global prompt +- +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle \ +- {"%s/a" 0 0 1234 0 null 0 0 0 0 test-pol 0} \ +- {KADM5_PRINCIPAL KADM5_POLICY \ +- KADM5_PW_EXPIRATION} NotinTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- fail "$test: can not retrieve principal" +- return; +- } +- send "lindex \$principal 3\n" +- expect { +- -re "1234.*$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test35 +- +-test "create-principal 36" +-proc test36 {} { +- global test +- global prompt +- +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle \ +- {"%s/a" 0 0 999999999 0 null 0 0 0 0 test-pol 0} \ +- {KADM5_PRINCIPAL KADM5_POLICY \ +- KADM5_PW_EXPIRATION} NotinTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- fail "$test: can not retrieve principal" +- return; +- } +- if { ! [cmd {kadm5_get_policy $server_handle test-pol policy} ]} { +- error_and_restart "$test: cannot retrieve policy" +- return +- } +- +- send "lindex \$principal 6\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set mod_date $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting mod_date" +- return +- } +- eof { +- error_and_restart "$test: eof getting mod_date" +- return +- } +- } +- +- send "lindex \$principal 3\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_expire $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting pw_expire" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_expire" +- return +- } +- } +- +- send "lindex \$policy 2\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_max_life $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting pw_max_life" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_max_life" +- return +- } +- } +- if { $pw_expire != 999999999 } { +- fail "$test: pw_expire is wrong" +- return +- } else { +- pass "$test" +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test36 +- +-test "create-principal 37" +-proc test37 {} { +- global test +- global prompt +- +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} NotinTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- fail "$test: can not retrieve principal" +- return; +- } +- send "lindex \$principal 3\n" +- expect { +- -re "0.*$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test37 +- +-test "create-principal 38" +-proc test38 {} { +- global test +- global prompt +- +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle [princ_w_pol "%s/a" \ +- test-pol-nopw] {KADM5_PRINCIPAL KADM5_POLICY} \ +- NotinTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- fail "$test: can not retrieve principal" +- return; +- } +- send "lindex \$principal 3\n" +- expect { +- -re "0.*$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test38 +- +-test "create-principal 39" +-proc test39 {} { +- global test +- global prompt +- +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle [princ_w_pol "%s/a" \ +- test-pol] {KADM5_PRINCIPAL KADM5_POLICY} \ +- NotinTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if { ! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: cannot not retrieve principal" +- return +- } +- if { ! [cmd {kadm5_get_policy $server_handle test-pol policy}]} { +- error_and_restart "$test: cannot retrieve policy" +- return +- } +- send "lindex \$principal 6\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set mod_date $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting mod_date" +- return +- } +- eof { +- error_and_restart "$test: eof getting mod_date" +- return +- } +- } +- +- send "lindex \$principal 3\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_expire $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting pw_expire" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_expire" +- return +- } +- } +- +- send "lindex \$policy 2\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_max_life $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting pw_max_life" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_max_life" +- return +- } +- } +- if { [expr "$mod_date + $pw_max_life - $pw_expire"] > 5 } { +- fail "$test: pw_expire is wrong" +- return +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test39 +- +-test "create-principal 40" +-proc test40 {} { +- global test +- global prompt +- +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL KADM5_PW_EXPIRATION} \ +- NotinTheDictionary +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- fail "$test: can not retrieve principal" +- return; +- } +- send "lindex \$principal 4\n" +- expect { +- -re "0.*$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test40 +- +-test "create-principal 43" +-proc test43 {} { +- global test +- one_line_fail_test [format { +- kadm5_create_principal null \ +- [simple_principal "%s/a"] {KADM5_PRINCIPAL} "%s/a" +- } $test $test] "BAD_SERVER_HANDLE" +-} +-test43 +- +-return "" +diff --git a/src/lib/kadm5/unit-test/api.current/destroy.exp b/src/lib/kadm5/unit-test/api.current/destroy.exp +deleted file mode 100644 +index a3e2bfc59..000000000 +--- a/src/lib/kadm5/unit-test/api.current/destroy.exp ++++ /dev/null +@@ -1,203 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-test "destroy 1" +- +-proc test1 {} { +- global test +- begin_dump +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test {kadm5_destroy $server_handle} +- end_dump_compare "no-diffs" +-} +-test1 +- +-#test "destroy 2" +-# +-#proc test2 {} { +-# global test +-# begin_dump +-# if {! [cmd { +-# kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +-# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +-# server_handle +-# }]} { +-# perror "$test: unexpected failure on init" +-# return +-# } +-# if {! [cmd {kadm5_destroy $server_handle}]} { +-# error_and_restart "$test: couldn't close database" +-# return +-# } +-# one_line_fail_test \ +-# {kadm5_get_principal $server_handle admin principal} \ +-# "NOT_INIT" +-# end_dump_compare "no-diffs" +-#} +-#test2 +- +-#test "destroy 3" +-#proc test3 {} { +-# global test +-# +-# begin_dump +-# if {! (( ! [principal_exists "$test/a"]) || [delete_principal "$test/a"])} { +-# error_and_restart "$test couldn't delete principal \"$test/a\"" +-# return +-# } +-# if {! [cmd { +-# kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +-# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +-# server_handle +-# }]} { +-# perror "$test: unexpected failure on init" +-# return +-# } +-# if {! [cmd {kadm5_destroy $server_handle}]} { +-# error_and_restart "$test: couldn't close database" +-# return +-# } +-# one_line_fail_test [format { +-# kadm5_create_principal $server_handle \ +-# [simple_principal "%s/a"] {KADM5_PRINCIPAL} "%s/a" +-# } $test $test] "NOT_INIT" +-# end_dump_compare "no-diffs" +-#} +-#test3 +- +-#test "destroy 4" +-#proc test4 {} { +-# global test prompt +-# +-# if {! (([principal_exists "$test/a"]) || [create_principal "$test/a"])} { +-# error_and_restart "$test: couldn't create principal \"$test/a\"" +-# return +-# } +-# begin_dump +-# if {! ([cmd { +-# kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +-# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +-# server_handle +-# }] && +-# [cmd [format { +-# kadm5_get_principal $server_handle "%s/a" principal +-# } $test]])} { +-# error_and_restart "$test: error getting principal" +-# return; +-# } +-# if {! [cmd {kadm5_destroy $server_handle}]} { +-# error_and_restart "$test: couldn't close database" +-# return +-# } +-# one_line_fail_test [format { +-# kadm5_modify_principal $server_handle \ +-# {"%s/a" 0 0 0 0 0 0 0 %d 0 0 0} {KADM5_KVNO} +-# } $test "77"] "NOT_INIT" +-# end_dump_compare "no-diffs" +-#} +-#test4 +- +-#test "destroy 5" +-# +-#proc test5 {} { +-# global test +-# +-# if {! ([principal_exists "$test/a"] || [create_principal "$test/a"])} { +-# error_and_restart "$test: couldn't create principal \"$test/a\"" +-# return +-# } +-# begin_dump +-# if {! [cmd { +-# kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +-# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +-# server_handle +-# }]} { +-# perror "$test: unexpected failure on init" +-# return +-# } +-# if {! [cmd {kadm5_destroy $server_handle}]} { +-# error_and_restart "$test: couldn't close database" +-# return +-# } +-# one_line_fail_test [format { +-# kadm5_delete_principal $server_handle "%s/a" +-# } $test] "NOT_INIT" +-# end_dump_compare "no-diffs" +-#} +-#test5 +- +-#test "destroy 6" +-# +-#proc test6 {} { +-# global test +-# begin_dump +-# one_line_fail_test {kadm5_destroy $server_handle} "NOT_INIT" +-# end_dump_compare "no-diffs" +-#} +-#test6 +- +- +-#test "destroy 7" +-# +-#proc test7 {} { +-# global test +-# begin_dump +-# if {! [cmd { +-# kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +-# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +-# server_handle +-# }]} { +-# perror "$test: unexpected failure in init" +-# return +-# } +-# if {! [cmd {kadm5_destroy $server_handle}]} { +-# error_and_restart "$test: couldn't close database" +-# } +-# one_line_fail_test {kadm5_destroy $server_handle} "NOT_INIT" +-# end_dump_compare "no-diffs" +-#} +-#test7 +- +-test "destroy 8" +-proc test8 {} { +- global test +- begin_dump +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close database" +- } +- one_line_succeed_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close database" +- } +- end_dump_compare "no-diffs" +-} +-test8 +- +-test "destroy 9" +-proc test9 {} { +- global test +- one_line_fail_test {kadm5_destroy null} "BAD_SERVER_HANDLE" +-} +-test9 +- +-return "" +diff --git a/src/lib/kadm5/unit-test/api.current/dlte-policy.exp b/src/lib/kadm5/unit-test/api.current/dlte-policy.exp +deleted file mode 100644 +index ad2863d0f..000000000 +--- a/src/lib/kadm5/unit-test/api.current/dlte-policy.exp ++++ /dev/null +@@ -1,208 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-test "delete-policy 2" +-proc test2 {} { +- global test +-# set prms_id 744 +-# setup_xfail {*-*-*} $prms_id +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test \ +- {kadm5_delete_policy $server_handle ""} "BAD_POL" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test2 +- +-test "delete-policy 5" +-proc test5 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_delete_policy $server_handle "%s/a" +- } $test] "AUTH_DELETE" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if ${RPC} test5 +- +-test "delete-policy 6" +-proc test6 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_delete_policy $server_handle "%s/a" +- } $test] "AUTH_DELETE" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if ${RPC} test6 +- +-test "delete-policy 7" +-proc test7 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_delete_policy $server_handle "%s/a" +- } $test] "AUTH_DELETE" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} test7 +- +-test "delete-policy 10" +-proc test10 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_delete_policy $server_handle "%s/a" +- } $test]]} { +- fail "$test" +- return +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- if { [policy_exists "$test/a"]} { +- fail "$test" +- return +- } +-} +-test10 +- +-test "delete-policy 12" +-proc test12 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle [princ_w_pol "%s/a" \ +- "%s/a"] {KADM5_PRINCIPAL KADM5_POLICY} \ +- NotinTheDictionary +- } $test $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- if {! [cmd { +- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_delete_policy $server_handle "%s/a" +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test12 +- +-test "delete-policy 13" +-proc test13 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- one_line_fail_test [format { +- kadm5_delete_policy null "%s/a" +- } $test] "BAD_SERVER_HANDLE" +-} +-test13 +- +-return "" +diff --git a/src/lib/kadm5/unit-test/api.current/dlte-principal.exp b/src/lib/kadm5/unit-test/api.current/dlte-principal.exp +deleted file mode 100644 +index 660468534..000000000 +--- a/src/lib/kadm5/unit-test/api.current/dlte-principal.exp ++++ /dev/null +@@ -1,253 +0,0 @@ +-load_lib lib.t +- +-api_exit +-api_start +- +-#test "delete-principal 1" +-#proc test1 {} { +-# global test +-# one_line_fail_test [format { +-# kadm5_delete_principal $server_handle "%s/a" +-# } $test] "NOT_INIT" +-#} +-#test1 +- +-test "delete-principal 2" +-proc test2 {} { +- global test +- +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test \ +- {kadm5_delete_principal $server_handle null} "EINVAL" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: unexpected failure in destroy" +- return +- } +-} +-test2 +- +-test "delete-principal 5" +-proc test5 {} { +- global test +- +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_delete_principal $server_handle "%s/a" +- } $test] "UNK_PRINC" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test5 +- +-test "delete-principal 6" +-proc test6 {} { +- global test +- +- if {! (( [principal_exists "$test/a"]) || +- [create_principal_pol "$test/a" test-pol])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/delete admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_delete_principal $server_handle "%s/a" +- } $test] "AUTH_DELETE" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test6 } +- +- +-test "delete-principal 7" +-proc test7 {} { +- global test +- +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_delete_principal $server_handle "%s/a" +- } $test] "AUTH_DELETE" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test7 } +- +- +-test "delete-principal 8" +-proc test8 {} { +- global test +- +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_delete_principal $server_handle "%s/a" +- } $test] "AUTH_DELETE" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test8 } +- +-test "delete-principal 9" +-proc test9 {} { +- global test +- +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_delete_principal $server_handle "%s/a" +- } $test] "AUTH_DELETE" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test9 } +- +-test "delete-principal 10" +-proc test10 {} { +- global test +- +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_delete_principal $server_handle "%s/a" +- } $test] "AUTH_DELETE" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test10 } +- +-test "delete-principal 11" +-proc test11 {} { +- global test +- +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_delete_principal $server_handle "%s/a" +- } $test]]} { +- fail "$test: delete failed" +- return; +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- if { [principal_exists "$test/a"] } { +- fail "$test" +- return +- } +-} +-test11 +- +-test "delete-principal 13" +-proc test13 {} { +- global test +- one_line_fail_test [format { +- kadm5_delete_principal null "%s/a" +- } $test] "BAD_SERVER_HANDLE" +-} +-test13 +- +-return "" +- +- +- +- +- +diff --git a/src/lib/kadm5/unit-test/api.current/get-policy.exp b/src/lib/kadm5/unit-test/api.current/get-policy.exp +deleted file mode 100644 +index c15ef0ca2..000000000 +--- a/src/lib/kadm5/unit-test/api.current/get-policy.exp ++++ /dev/null +@@ -1,199 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-test "get-policy 3" +-proc test3 {} { +- global test +-# set prms_id 744 +-# setup_xfail {*-*-*} $prms_id +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test {kadm5_get_policy $server_handle "" p} "BAD_POLICY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test3 +- +-test "get-policy 6" +-proc test6 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test {kadm5_get_policy $server_handle test-pol p} \ +- "AUTH_GET" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if { $RPC } test6 +- +-test "get-policy 7" +-proc test7 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test {kadm5_get_policy $server_handle test-pol p} \ +- "AUTH_GET" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if { $RPC } test7 +- +-test "get-policy 11" +-proc test11 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/get-pol StupidAdmin $KADM5_ADMIN_SERVICE \ +- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test {kadm5_get_policy $server_handle test-pol p} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test11 +- +-test "get-policy 12" +-proc test12 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/get-pol StupidAdmin \ +- $KADM5_CHANGEPW_SERVICE null $KADM5_STRUCT_VERSION \ +- $KADM5_API_VERSION_3 server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test \ +- {kadm5_get_policy $server_handle test-pol-nopw p} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test12 +- +-test "get-policy 15" +-proc test15 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/pol StupidAdmin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test \ +- {kadm5_get_policy $server_handle test-pol-nopw p} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test15 +- +-test "get-policy 16" +-proc test16 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/pol StupidAdmin $KADM5_CHANGEPW_SERVICE \ +- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test \ +- {kadm5_get_policy $server_handle test-pol-nopw p} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test16 +- +-test "get-policy 17" +-proc test17 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test {kadm5_get_policy $server_handle test-pol p} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test17 +- +-test "get-policy 18" +-proc test18 {} { +- global test +- +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test {kadm5_get_policy $server_handle test-pol p} \ +- "AUTH_GET" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if { $RPC } test18 +- +-test "get-policy 21" +-proc test21 {} { +- global test +- +- one_line_fail_test {kadm5_get_policy null "pol1" p} "BAD_SERVER_HANDLE" +-} +-test21 +diff --git a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp +deleted file mode 100644 +index 3ea1ba29b..000000000 +--- a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp ++++ /dev/null +@@ -1,250 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-test "get-principal 100" +-proc test100 {} { +- global test prompt +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd { +- kadm5_get_principal $server_handle testuser p \ +- {KADM5_PRINCIPAL_NORMAL_MASK} +- }]} { +- perror "$test: unexpected failure in get_principal" +- } +- send "lindex \$p 16\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" { set num_keys $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting num_keys" +- return +- } +- eof { +- error_and_restart "$test: eof getting num_keys" +- return +- } +- } +- send "lindex \$p 17\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" { set num_tl $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting num_tl" +- return +- } +- eof { +- error_and_restart "$test: eof getting num_tl" +- return +- } +- } +- send "lindex \$p 18\n" +- expect { +- -re "({.*})\n$prompt" {set key_data $expect_out(1,string) } +- -re "\n$prompt" { set key_data {} } +- timeout { +- error_and_restart "$test: timeout getting key_data" +- return +- } +- eof { +- error_and_restart "$test: eof getting key_data" +- return +- } +- } +- send "lindex \$p 19\n" +- expect { +- -re "({.*})\n$prompt" {set tl_data $expect_out(1,string) } +- -re "\n$prompt" { set tl_data {} } +- timeout { +- error_and_restart "$test: timeout getting tl_data" +- return +- } +- eof { +- error_and_restart "$test: eof getting tl_data" +- return +- } +- } +- +- set failed 0 +- if {$num_keys != 0} { +- fail "$test: num_keys $num_keys should be 0" +- set failed 1 +- } +- if {$num_tl != 0} { +- fail "$test: num_tl $num_tl should be 0" +- set failed 1 +- } +- if {$key_data != {}} { +- fail "$test: key_data $key_data should be {}" +- set failed 1 +- } +- if {$tl_data != "{}"} { +- fail "$test: tl_data $tl_data should be empty" +- set failed 1 +- } +- if {$failed == 0} { +- pass "$test" +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test100 +- +-proc test101_102 {rpc} { +- global test prompt +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd { +- kadm5_get_principal $server_handle testuser p \ +- {KADM5_PRINCIPAL_NORMAL_MASK KADM5_KEY_DATA} +- }]} { +- perror "$test: unexpected failure in get_principal" +- } +- send "lindex \$p 16\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" { set num_keys $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting num_keys" +- return +- } +- eof { +- error_and_restart "$test: eof getting num_keys" +- return +- } +- } +- send "lindex \$p 18\n" +- expect { +- -re "({.*})\n$prompt" {set key_data $expect_out(1,string) } +- -re "\n$prompt" { set key_data {} } +- timeout { +- error_and_restart "$test: timeout getting key_data" +- return +- } +- eof { +- error_and_restart "$test: eof getting key_data" +- return +- } +- } +- +- set failed 0 +- if {$num_keys != 5} { +- fail "$test: num_keys $num_keys should be 5" +- set failed 1 +- } +- for {set i 0} {$i < $num_keys} {incr i} { +- set key "[lindex [lindex $key_data $i] 2]" +- if {($rpc && [string compare $key ""] != 0) || +- ((! $rpc) && [string compare $key ""] == 0)} { +- fail "$test: key_data $key is wrong" +- set failed 1 +- +- } +- } +- if {$failed == 0} { pass "$test" } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test "get-principal 101" +-if {$RPC} {test101_102 $RPC} +-test "get-principal 102" +-if {! $RPC} {test101_102 $RPC} +- +-test "get-principal 103" +-proc test103 {} { +- global test prompt +- +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- +- if { ! [cmd [format { +- kadm5_modify_principal $server_handle \ +- "{%s/a} 0 0 0 0 {%s/a} 0 0 0 0 null 0 0 0 0 0 0 1 {} {{999 6 foobar}}" \ +- {KADM5_TL_DATA} +- } $test $test]]} { +- fail "$test: cannot set TL_DATA" +- return +- } +- +- if {! [cmd [format { +- kadm5_get_principal $server_handle {%s/a} p \ +- {KADM5_PRINCIPAL_NORMAL_MASK KADM5_TL_DATA} +- } $test]]} { +- perror "$test: unexpected failure in get_principal" +- } +- send "lindex \$p 17\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" { set num_tl $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting num_tl" +- return +- } +- eof { +- error_and_restart "$test: eof getting num_tl" +- return +- } +- } +- send "lindex \$p 19\n" +- expect { +- -re "({.*})\n$prompt" {set tl_data $expect_out(1,string) } +- -re "\n$prompt" { set tl_data {} } +- timeout { +- error_and_restart "$test: timeout getting tl_data" +- return +- } +- eof { +- error_and_restart "$test: eof getting tl_data" +- return +- } +- } +- +- if {$num_tl == 0} { +- fail "$test: num_tl $num_tl should not be 0" +- } elseif {$tl_data == "{{999 6 foobar}}"} { +- pass "$test" +- } else { +- fail "$test: tl_data $tl_data should be {{999 6 foobar}}" +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test103 +- +-return "" +- +- +- +- +diff --git a/src/lib/kadm5/unit-test/api.current/get-principal.exp b/src/lib/kadm5/unit-test/api.current/get-principal.exp +deleted file mode 100644 +index a33fdfe8c..000000000 +--- a/src/lib/kadm5/unit-test/api.current/get-principal.exp ++++ /dev/null +@@ -1,346 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-test "get-principal 1" +-proc test1 {} { +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test \ +- {kadm5_get_principal $server_handle null p KADM5_PRINCIPAL_NORMAL_MASK} "EINVAL" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test1 +- +-test "get-principal 2" +-proc test2 {} { +- global test +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK +- } $test] "UNK_PRINC" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test2 +- +-test "get-principal 3" +-proc test3 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK +- } $test] "AUTH_GET" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test3 } +- +-test "get-principal 4" +-proc test4 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK +- } $test] "AUTH_GET" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test4 } +- +-test "get-principal 5" +-proc test5 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK +- } $test] "AUTH_GET" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test5 } +- +-test "get-principal 6" +-proc test6 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK +- } $test] "AUTH_GET" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test6 } +- +-test "get-principal 7" +-proc test7 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/delete admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK +- } $test] "AUTH_GET" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test7 } +- +- +-test "get-principal 8" +-proc test8 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK +- } $test] "AUTH_GET" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test8 } +- +- +-test "get-principal 9" +-proc test9 {} { +- global test +- if {! [cmd { +- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test \ +- {kadm5_get_principal $server_handle admin/none p KADM5_PRINCIPAL_NORMAL_MASK} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test9 +- +-test "get-principal 10" +-proc test10 {} { +- global test +- if {! [cmd { +- kadm5_init admin/none admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test \ +- {kadm5_get_principal $server_handle admin/none p KADM5_PRINCIPAL_NORMAL_MASK} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test10 +- +-test "get-principal 11" +-proc test11 {} { +- global test +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test {kadm5_get_principal $server_handle admin/get p KADM5_PRINCIPAL_NORMAL_MASK} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test11 +- +-test "get-principal 12" +-proc test12 {} { +- global test +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test {kadm5_get_principal $server_handle admin/get p KADM5_PRINCIPAL_NORMAL_MASK} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test12 +- +-test "get-principal 13" +-proc test13 {} { +- global test +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test {kadm5_get_principal $server_handle admin/add p KADM5_PRINCIPAL_NORMAL_MASK} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test13 +- +-test "get-principal 14" +-proc test14 {} { +- global test +- if {! [cmd { +- kadm5_init admin/get-mod admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test {kadm5_get_principal $server_handle admin/add p KADM5_PRINCIPAL_NORMAL_MASK} +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test14 +- +-test "get-principal 15" +-proc test15 {} { +- one_line_fail_test \ +- {kadm5_get_principal null "admin" p KADM5_PRINCIPAL_NORMAL_MASK} "BAD_SERVER_HANDLE" +-} +-test15 +- +-return "" +- +- +- +- +diff --git a/src/lib/kadm5/unit-test/api.current/init-v2.exp b/src/lib/kadm5/unit-test/api.current/init-v2.exp +deleted file mode 100644 +index 47764c212..000000000 +--- a/src/lib/kadm5/unit-test/api.current/init-v2.exp ++++ /dev/null +@@ -1,506 +0,0 @@ +-load_lib lib.t +- +-api_exit +-api_start +- +-proc get_hostname { } { +- global hostname +- +- if {[info exists hostname]} { +- return 1 +- } +- +- catch "exec hostname >myname" exec_output +- if ![string match "" $exec_output] { +- send_log "$exec_output\n" +- verbose $exec_output +- send_error "ERROR: can't get hostname\n" +- return 0 +- } +- set file [open myname r] +- if { [ gets $file hostname ] == -1 } { +- send_error "ERROR: no output from hostname\n" +- return 0 +- } +- close $file +- catch "exec rm -f myname" exec_output +- +- set hostname [string tolower $hostname] +- verbose "hostname: $hostname" +- +- return 1 +-} +- +- +-test "init 101" +-proc test101 {} { +- global test +- global hostname +- +- get_hostname +- tcl_cmd "set hostname $hostname" +- +- # XXX Fix to work with a remote TEST_SERVER. For now, make sure +- # it fails in that case. +- one_line_succeed_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ +- [config_params {KADM5_CONFIG_ADMIN_SERVER KADM5_CONFIG_KADMIND_PORT} [list $hostname 1751]] \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ +- [config_params {KADM5_CONFIG_ADMIN_SERVER KADM5_CONFIG_KADMIND_PORT} [list $hostname 4]] \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } "RPC_ERROR" +-} +-if {$RPC} test101 +- +-test "init 102" +-proc test102 {} { +- global test +- +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ +- [config_params {KADM5_CONFIG_ADMIN_SERVER} does.not.exist] \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } "CANT_RESOLVE" +-} +-if {$RPC} test102 +- +-test "init 103" +-proc test103 {} { +- global test +- +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ +- [config_params {KADM5_CONFIG_DBNAME} /does-not-exist] \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } "ENOENT" +-} +-#if {! $RPC} test103 +-if {! $RPC} { +- send_user "UNTESTED: test103: test needs updating for DAL changes (see MIT RT ticket 3202)\n" +- untested "test103: test needs updating for DAL changes (see MIT RT ticket 3202)" +-} +- +- +-test "init 106" +-proc test106 {} { +- global test prompt +- +- set prompting 0 +- send [string trim { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ +- [config_params {KADM5_CONFIG_MKEY_FROM_KBD} 1] \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }] +- send "\n" +- expect { +- -re "\n\[^\n\]+:\[^\n\]*$" { set prompting 1} +- -re "\nOK .*$prompt$" { fail "$test: premature success" } +- -re "\nERROR .*$prompt$" { fail "$test: premature failure" } +- timeout { fail "$test: timeout" } +- eof { fail "$test: eof" } +- } +- if {$prompting} { +- one_line_succeed_test mrroot +- } +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close database" +- } +-} +-if {! $RPC} test106 +- +-test "init 107" +-proc test107 {} { +- global test +- +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ +- [config_params {KADM5_CONFIG_STASH_FILE} /does-not-exist] \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } "KDB_CANTREAD_STORED" +-} +-if {! $RPC} test107 +- +-test "init 108" +-proc test108 {} { +- global test +- +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ +- [config_params {KADM5_CONFIG_MKEY_NAME} does/not/exist] \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } "KRB5_KDB_CANTREAD_STORED" +-} +-if {! $RPC} test108 +- +-test "init 109-113" +-proc test109 {} { +- global test prompt +- +- delete_principal "$test/a" +- +- # I'd like to specify flags explicitly and check them, as in the +- # following config_params, but tcl gets mighty confused if I do and +- # I have no idea why. +-# [config_params {KADM5_CONFIG_MAX_LIFE KADM5_CONFIG_MAX_RLIFE KADM5_CONFIG_EXPIRATION KADM5_CONFIG_FLAGS KADM5_CONFIG_ENCTYPES} {10 20 30 KRB5_KDB_DISALLOW_TGT_BASED {}} ] +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ +- [config_params {KADM5_CONFIG_MAX_LIFE KADM5_CONFIG_MAX_RLIFE KADM5_CONFIG_EXPIRATION KADM5_CONFIG_ENCTYPES} {10 20 30 {}} ] \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- fail "$test: cannot init with max_life" +- return +- } +- if {! [cmd [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} testpass +- } $test]]} { +- fail "$test: can not create principal" +- return; +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" p \ +- {KADM5_PRINCIPAL_NORMAL_MASK KADM5_KEY_DATA} +- } $test]]} { +- fail "$test: can not get principal" +- return; +- } +- send "puts \$p\n" +- expect { +- -re "$prompt" { } +- timeout { +- error_and_restart "$test: timeout getting prompt" +- return +- } +- eof { +- error_and_restart "$test: eof getting prompt" +- return +- } +- } +- send "lindex \$p 4\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set max_life $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting max_life" +- return +- } +- eof { +- error_and_restart "$test: eof getting max_life" +- return +- } +- } +- send "lindex \$p 12\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set max_rlife $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting max_rlife" +- return +- } +- eof { +- error_and_restart "$test: eof getting max_rlife" +- return +- } +- } +- send "lindex \$p 1\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set expiration $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting expiration" +- return +- } +- eof { +- error_and_restart "$test: eof getting expiration" +- return +- } +- } +- send "lindex \$p 7\n" +- expect { +- -re "(\[A-Z_\]*)\n$prompt" {set flags $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting flags" +- return +- } +- eof { +- error_and_restart "$test: eof getting flags" +- return +- } +- } +- # This sorta worries me. Since the test is setting ENCTYPES to +- # nothing, the principal has no keys. That means that nothing is +- # printed for the keys in the correct case; but it feels too +- # likely that nothing will be printed in the case of some problem. +- send "lindex \$p 18\n" +- expect { +- -re "({.*})\n$prompt" {set key_data $expect_out(1,string) } +- -re "\n$prompt" { set key_data {} } +- timeout { +- error_and_restart "$test: timeout getting flags" +- return +- } +- eof { +- error_and_restart "$test: eof getting flags" +- return +- } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +- if {$max_life == 10} { +- pass "$test" +- } else { +- fail "$test: $max_life is not 10" +- } +- if {$max_rlife == 20} { +- pass "$test" +- } else { +- fail "$test: $max_rlife is not 20" +- } +- if {$expiration == 30} { +- pass "$test" +- } else { +- fail "$test: $expiration is not 30" +- } +- if {$flags == ""} { +- pass "$test" +- } else { +- fail "$test: flags $flags are wrong" +- } +- if {$key_data == {}} { +- pass "$test" +- } else { +- fail "$test: key_data $key_data is wrong" +- } +-} +-if {! $RPC} test109 +- +-test "init 116" +-proc test116 {} { +- global test +- +- delete_principal "$test/a" +- +- if {! [cmd {kadm5_init admin/get-add admin $KADM5_ADMIN_SERVICE \ +- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- get_add_handle}]} { +- error_and_restart "$test: couldn't init with admin/get-add" +- } +- +- if {! [cmd {kadm5_init admin/mod-delete admin $KADM5_ADMIN_SERVICE \ +- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- mod_delete_handle}]} { +- error_and_restart "$test: couldn't init with admin/get-add" +- } +- +- one_line_succeed_test { +- kadm5_get_principal $get_add_handle testuser p \ +- KADM5_PRINCIPAL_NORMAL_MASK +- } +- one_line_succeed_test [format { +- kadm5_create_principal $get_add_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} testpass +- } $test] +- one_line_fail_test { +- kadm5_modify_principal $get_add_handle [simple_principal testuser] \ +- {KADM5_PRINC_EXPIRE_TIME} +- } "AUTH_MODIFY" +- one_line_fail_test { +- kadm5_delete_principal $get_add_handle testuser +- } "AUTH_DELETE" +- +- one_line_fail_test { +- kadm5_get_principal $mod_delete_handle testuser p \ +- KADM5_PRINCIPAL_NORMAL_MASK +- } "AUTH_GET" +- one_line_fail_test [format { +- kadm5_create_principal $mod_delete_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} testpass +- } $test] "AUTH_ADD" +- one_line_succeed_test { +- kadm5_modify_principal $mod_delete_handle [simple_principal testuser] \ +- {KADM5_PRINC_EXPIRE_TIME} +- } +- one_line_succeed_test [format { +- kadm5_delete_principal $mod_delete_handle "%s/a" +- } $test] +- +- if {! [cmd {kadm5_destroy $get_add_handle}]} { +- error_and_restart "$test: couldn't close get_add_handle" +- } +- if {! [cmd {kadm5_destroy $mod_delete_handle}]} { +- error_and_restart "$test: couldn't close mod_delete_handle" +- } +-} +-if {$RPC} test116 +- +-test "init 117" +-proc test117 {} { +- global test env prompt +- +- if {[catch "exec grep max_life $env(KRB5_KDC_PROFILE)"] != 1} { +- warning \ +- "$test: max_life in $env(KRB5_KDC_PROFILE), cannot perform test" +- return +- } +- +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- fail "$test: unexpected failure in init" +- return +- } +- +- if {! [cmd [format { +- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} "%s/a" +- } $test $test]]} { +- perror "$test: unexpected failure creating principal" +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_MAX_LIFE +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 4\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set max_life $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting max_life" +- return +- } +- eof { +- error_and_restart "$test: eof getting max_life" +- return +- } +- } +- +- if {$max_life == 86400} { +- pass "$test" +- } else { +- fail "$test: max_life $max_life should be 86400" +- } +- +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close server_handle" +- } +-} +-test117 +- +-send "puts \$KADM5_ADMIN_SERVICE\n" +-expect { +- -re "(\[a-zA-Z/@\]+)\n$prompt" { +- set KADM5_ADMIN_SERVICE $expect_out(1,string) +- } +- default { +- error_and_restart "$test: timeout/eof getting admin_service" +- return +- } +-} +- +-send "puts \$KADM5_CHANGEPW_SERVICE\n" +-expect { +- -re "(\[a-zA-Z/@\]+)\n$prompt" { +- set KADM5_CHANGEPW_SERVICE $expect_out(1,string) +- } +- default { +- error_and_restart "$test: timeout/eof getting changepw_service" +- return +- } +-} +- +-test "init 150" +-proc test150 {} { +- global test KADM5_ADMIN_SERVICE +- +- kdestroy +- kinit testuser notathena "-S $KADM5_ADMIN_SERVICE" +- one_line_succeed_test { +- kadm5_init_with_creds testuser null $KADM5_ADMIN_SERVICE \ +- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } +- kdestroy +-} +-if {$RPC} test150 +- +-test "init 151" +-proc test151 {} { +- global test KADM5_CHANGEPW_SERVICE +- +- kdestroy +- kinit testuser notathena "-S $KADM5_CHANGEPW_SERVICE" +- one_line_succeed_test { +- kadm5_init_with_creds testuser null $KADM5_CHANGEPW_SERVICE \ +- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } +- kdestroy +-} +-if {$RPC} test151 +- +-test "init 152" +-proc test152 {} { +- global test KADM5_ADMIN_SERVICE +- +- kdestroy +- one_line_fail_test { +- kadm5_init_with_creds testuser null $KADM5_ADMIN_SERVICE \ +- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } "KRB5_FCC_NOFILE" +-} +-if {$RPC} test152 +- +-test "init 153" +-proc test153 {} { +- global test KADM5_ADMIN_SERVICE +- +- kinit testuser notathena +- one_line_fail_test { +- kadm5_init_with_creds testuser null $KADM5_ADMIN_SERVICE \ +- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } "KRB5_CC_NOTFOUND" +-} +-if {$RPC} test153 +- +-test "init 154" +-proc test154 {} { +- global test env +- +- set orig $env(KRB5_KDC_PROFILE) +- set env(KRB5_KDC_PROFILE) /does-not-exist +- api_exit; api_start +- set env(KRB5_KDC_PROFILE) $orig +- +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } "ENOENT" +- +- api_exit; lib_start_api +-} +-if {0 && ! $RPC} test154 +- +-return "" +diff --git a/src/lib/kadm5/unit-test/api.current/init.exp b/src/lib/kadm5/unit-test/api.current/init.exp +deleted file mode 100644 +index 8390b9cfa..000000000 +--- a/src/lib/kadm5/unit-test/api.current/init.exp ++++ /dev/null +@@ -1,699 +0,0 @@ +-load_lib lib.t +- +-# Assumptions: +-# +-# Principal "admin" exists, with "get", "add", "modify" and "delete" +-# access bits and password "admin". +-# The string "not-the-password" isn't the password of any user in the database. +-# Database master password is "mrroot". +- +-api_exit +-api_start +-test "init 1" +- +-one_line_fail_test_nochk \ +- {kadm5_init admin admin $KADM5_ADMIN_SERVICE \ +- [config_params {KADM5_CONFIG_REALM} {""}] \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 server_handle} +- +-test "init 2" +- +-one_line_fail_test_nochk \ +- {kadm5_init admin admin $KADM5_ADMIN_SERVICE \ +- [config_params {KADM5_CONFIG_REALM} {@}] \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 server_handle} +- +-test "init 2.5" +- +-one_line_fail_test_nochk \ +- {kadm5_init admin admin $KADM5_ADMIN_SERVICE \ +- [config_params {KADM5_CONFIG_REALM} {BAD.REALM}] \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 server_handle} +- +-test "init 3" +- +-proc test3 {} { +- global test +- if {! ([principal_exists "$test/a"] || [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- one_line_fail_test_nochk [format { +- kadm5_init admin admin "%s/a" null $KADM5_STRUCT_VERSION \ +- $KADM5_API_VERSION_3 server_handle +- } $test] +-} +-if {$RPC} { test3 } +- +-test "init 4" +- +-proc test4 {} { +- global test +- if {! ((! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- +- one_line_fail_test_nochk [format { +- kadm5_init admin admin "%s/a" null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } $test] +-} +-if {$RPC} { test4 } +- +-test "init 5" +- +-if {$RPC} { +- one_line_fail_test_nochk { +- kadm5_init admin admin admin null $KADM5_STRUCT_VERSION \ +- $KADM5_API_VERSION_3 server_handle +- } +-} +- +-test "init 6" +- +-proc test6 {} { +- global test +- +- send "kadm5_init admin null \$KADM5_ADMIN_SERVICE null \$KADM5_STRUCT_VERSION \$KADM5_API_VERSION_3 server_handle\n" +- +- expect { +- -re "assword\[^\r\n\]*:" { } +- eof { +- fail "$test: eof instead of password prompt" +- api_exit +- api_start +- return +- } +- timeout { +- fail "$test: timeout instead of password prompt" +- return +- } +- } +- one_line_succeed_test "admin" +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close database" +- } +-} +-if { $RPC } { test6 } +- +-test "init 8" +- +-proc test8 {} { +- global test +- if {! ([principal_exists "$test/a"] || [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- one_line_fail_test_nochk [format { +- kadm5_init "%s/a" admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } $test] +-} +-if {$RPC} { test8 } +- +-test "init 9" +- +-if {$RPC} { +- global test +- one_line_fail_test_nochk { +- kadm5_init admin not-the-password $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } +-} +- +-test "init 10" +- +-proc test10 {} { +- global test +-# set prms_id 562 +-# setup_xfail {*-*-*} $prms_id +- one_line_fail_test_nochk { +- kadm5_init null admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } +-} +-test10 +- +-#test "init 11" +-# +-#proc test11 {} { +-# global test +-# set prms_id 563 +-# setup_xfail {*-*-*} $prms_id +-# one_line_fail_test_nochk { +-# kadm5_init "" admin $KADM5_ADMIN_SERVICE null \ +-# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +-# server_handle +-# } +-#} +-#test11 +- +-test "init 12" +- +-proc test12 {} { +- global test +- one_line_fail_test_nochk [format { +- kadm5_init "%s/a" admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } $test] +-} +-if {$RPC} { test12 } +- +-test "init 13" +- +-proc test13 {} { +- global test +- one_line_fail_test_nochk [format { +- kadm5_init "%s/a@SECURE-TEST.OV.COM" admin \ +- $KADM5_ADMIN_SERVICE null $KADM5_STRUCT_VERSION \ +- $KADM5_API_VERSION_3 server_handle +- } $test] +-} +-if {$RPC} { test13 } +- +-test "init 14" +- +-proc test14 {} { +- global test +- one_line_fail_test_nochk [format { +- kadm5_init "%s/a@BAD.REALM" admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } $test] +-} +-if {$RPC} { test14 } +- +-test "init 15" +- +-if {$RPC} { +- one_line_fail_test_nochk { +- kadm5_init admin@BAD.REALM admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } +-} +- +-test "init 16" +- +-proc test16 {} { +- global test +- one_line_succeed_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close database" +- } +-} +-test16 +- +-test "init 17" +- +-proc test17 {} { +- global test +- one_line_succeed_test { +- kadm5_init admin@SECURE-TEST.OV.COM admin \ +- $KADM5_ADMIN_SERVICE null $KADM5_STRUCT_VERSION \ +- $KADM5_API_VERSION_3 server_handle +- } +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close database" +- } +-} +-test17 +- +-test "init 18" +- +-proc test18 {} { +- global test +- one_line_succeed_test { +- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close database" +- } +-} +-test18 +- +-test "init 19" +- +-proc test19 {} { +- global test +- one_line_succeed_test { +- kadm5_init admin@SECURE-TEST.OV.COM admin \ +- $KADM5_ADMIN_SERVICE \ +- [config_params {KADM5_CONFIG_REALM} {SECURE-TEST.OV.COM}] \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close database" +- } +-} +-test19 +- +-test "init 20" +- +-proc test20 {} { +- global test +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- error_and_restart "$test: couldn't init database" +- return +- } +- one_line_succeed_test \ +- {kadm5_get_principal $server_handle admin principal KADM5_PRINCIPAL_NORMAL_MASK} +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close database" +- } +-} +-test20 +- +-#test "init 21" +-# +-#proc test21 {} { +-# global test +-# if {! [cmd { +-# kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ +-# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +-# server_handle +-# }]} { +-# error_and_restart "$test: couldn't init database" +-# return +-# } +-# one_line_fail_test_nochk { +-# kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +-# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +-# server_handle +-# } +-# if {! [cmd {kadm5_destroy $server_handle}]} { +-# error_and_restart "$test: couldn't close database" +-# } +-#} +-#test21 +- +- +-# proc test22 {} { +-# global test prompt +-# set prompting 0 +-# send [string trim { +-# kadm5_init admin null null null $KADM5_STRUCT_VERSION \ +-# $KADM5_API_VERSION_3 server_handle +-# }] +-# send "\n" +-# expect { +-# -re ":$" { set prompting 1} +-# -re "\nOK .*$prompt$" { fail "$test: premature success" } +-# -re "\nERROR .*$prompt$" { fail "$test: premature failure" } +-# timeout { fail "$test: timeout" } +-# eof { fail "$test: eof" } +-# } +-# if {$prompting} { +-# one_line_succeed_test mrroot +-# } +-# if {! [cmd {kadm5_destroy $server_handle}]} { +-# error_and_restart "$test: couldn't close database" +-# } +-# } +-# if {! $RPC} { test22 } +-# +-# test "init 22.5" +-# proc test225 {} { +-# global test prompt +-# set prompting 0 +-# send [string trim { +-# kadm5_init admin null null null $KADM5_STRUCT_VERSION \ +-# $KADM5_API_VERSION_3 server_handle +-# }] +-# send "\n" +-# expect { +-# -re ":$" { set prompting 1} +-# -re "\nOK .*$prompt$" { fail "$test: premature success" } +-# -re "\nERROR .*$prompt$" { fail "$test: premature failure" } +-# timeout { fail "$test: timeout" } +-# eof { fail "$test: eof" } +-# } +-# if {$prompting} { +-# one_line_succeed_test mrroot +-# } +-# if {! [cmd {kadm5_destroy $server_handle}]} { +-# error_and_restart "$test: couldn't close database" +-# } +-# } +-# if {! $RPC} { test225 } +- +-test "init 23" +- +-proc test23 {} { +- global test +- one_line_succeed_test { +- kadm5_init admin not-the-password $KADM5_ADMIN_SERVICE \ +- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close database" +- } +-} +-if {! $RPC} { test23 } +- +-test "init 24" +- +-proc test24 {} { +- global test +- one_line_succeed_test { +- kadm5_init admin admin null null $KADM5_STRUCT_VERSION \ +- $KADM5_API_VERSION_3 server_handle +- } +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close database" +- } +-} +-if {! $RPC} { test24 } +- +-test "init 25" +- +-proc test25 {} { +- global test +- one_line_succeed_test { +- kadm5_init admin admin foobar null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close database" +- } +-} +-if {! $RPC} { test25 } +- +-test "init 26" +- +-#proc test26 {} { +-# global test +-# +-# api_exit +-# api_start +-# one_line_fail_test_nochk { +-# kadm5_get_principal $server_handle admin principal +-# } +-#} +-#test26 +- +-#test "init 27" +-# +-#proc test27 {} { +-# global test +-# +-# if {! ((! [principal_exists "$test/a"]) || [delete_principal "$test/a"])} { +-# error_and_restart "$test: couldn't delete principal \"$test/a\"" +-# return +-# } +-# begin_dump +-# if {[cmd [format { +-# kadm5_create_principal $server_handle [simple_principal \ +-# "%s/a"] {KADM5_PRINCIPAL} "%s/a" +-# } $test $test]]} { +-# fail "$test: unexpected success in add" +-# return +-# } +-# end_dump_compare "no-diffs" +-#} +-#test27 +- +-#test "init 28" +-# +-#proc test28 {} { +-# global test prompt +-# +-# if {! ([principal_exists "$test/a"] || [create_principal "$test/a"])} { +-# error_and_restart "$test: couldn't create principal \"$test/a\"" +-# return +-# } +-# begin_dump +-# if {! ([cmd { +-# kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +-# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +-# server_handle +-# }] && [cmd [format { +-# kadm5_get_principal $server_handle "%s/a" principal +-# } $test]])} { +-# error_and_restart "$test: error getting principal" +-# return; +-# } +-# send "lindex \$principal 8\n" +-# expect { +-# -re "\n(\[0-9\]+).*$prompt$" {set kvno $expect_out(1,string) } +-# timeout { +-# error_and_restart "$test: timeout getting principal kvno" +-# return +-# } +-# eof { +-# error_and_restart "$test: eof getting principal kvno" +-# return +-# } +-# } +-# api_exit +-# api_start +-# set new_kvno [expr "$kvno + 1"] +-# if {[cmd [format { +-# kadm5_modify_principal $server_handle \ +-# {"%s/a" 0 0 0 0 0 0 0 %d 0 0 0} {KADM5_KVNO} +-# } $test $new_kvno]]} { +-# fail "$test: unexpected success in modify" +-# return; +-# } +-# end_dump_compare "no-diffs" +-#} +-#test28 +- +-#test "init 29" +-# +-#proc test29 {} { +-# global test +-# +-# if {! ([principal_exists "$test/a"] || [create_principal "$test/a"])} { +-# error_and_restart "$test: couldn't create principal \"$test/a\"" +-# return +-# } +-# begin_dump +-# if {[cmd [format { +-# kadm5_delete_principal $server_handle "%s/a" +-# } $test]]} { +-# fail "$test: unexpected success in delete" +-# return +-# } +-# end_dump_compare "no-diffs" +-#} +-#test29 +- +-test "init 30" +-proc test30 {} { +- global test +- if {[cmd { +- kadm5_init admin foobar $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- error_and_restart "$test: unexpected success" +- return +- } +- one_line_succeed_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close database" +- } +-} +-if ${RPC} { test30 } +- +-test "init 31" +-proc test31 {} { +- global test +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $bad_struct_version_mask $KADM5_API_VERSION_3 \ +- server_handle +- } "BAD_STRUCT_VERSION" +-} +-test31 +- +-test "init 32" +-proc test32 {} { +- global test +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $no_struct_version_mask $KADM5_API_VERSION_3 \ +- server_handle +- } "BAD_STRUCT_VERSION" +-} +-test32 +- +-test "init 33" +-proc test33 {} { +- global test +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $old_struct_version $KADM5_API_VERSION_3 \ +- server_handle +- } "OLD_STRUCT_VERSION" +-} +-test33 +- +-test "init 34" +-proc test34 {} { +- global test +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $new_struct_version $KADM5_API_VERSION_3 \ +- server_handle +- } "NEW_STRUCT_VERSION" +-} +-test34 +- +-test "init 35" +-proc test35 {} { +- global test +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $bad_api_version_mask \ +- server_handle +- } "BAD_API_VERSION" +-} +-test35 +- +-test "init 36" +-proc test36 {} { +- global test +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $no_api_version_mask \ +- server_handle +- } "BAD_API_VERSION" +-} +-test36 +- +-test "init 37" +-proc test37 {} { +- global test +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $old_api_version \ +- server_handle +- } "OLD_LIB_API_VERSION" +-} +-if { $RPC } test37 +- +-test "init 38" +-proc test38 {} { +- global test +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $old_api_version \ +- server_handle +- } "OLD_SERVER_API_VERSION" +-} +-if { ! $RPC } test38 +- +-test "init 39" +-proc test39 {} { +- global test +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $new_api_version \ +- server_handle +- } "NEW_LIB_API_VERSION" +-} +-if { $RPC } test39 +- +-test "init 40" +-proc test40 {} { +- global test +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $new_api_version \ +- server_handle +- } "NEW_SERVER_API_VERSION" +-} +-if { ! $RPC } test40 +- +-test "init 41" +-proc test41 {} { +- global test +- one_line_fail_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_API_VERSION_3 $KADM5_STRUCT_VERSION \ +- server_handle +- } "BAD_" +-} +-test41 +- +-test "init 42" +-proc test42 {} { +- global test +- one_line_succeed_test { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } +- if {! [cmd {kadm5_destroy $server_handle}]} { +- error_and_restart "$test: couldn't close database" +- } +-} +-test42 +- +- +-proc test45_46 {service} { +- global test kadmin_local env +- +- spawn $kadmin_local -q "delprinc -force $service" +- expect { +- -re "Principal .* deleted." {} +- default { +- perror "kadmin.local delprinc failed\n"; +- } +- } +- expect eof +- wait +- +- one_line_fail_test [concat {kadm5_init admin admin } \ +- $service \ +- { null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle}] "SECURE_PRINC_MISSING" +- +- # this leaves the keytab with an incorrect entry +- spawn $kadmin_local -q "ank -randkey $service" +- expect eof +- wait +- +- # restart the api so it gets a new ccache +- api_exit +- api_start +-} +- +-if {$RPC} { +- test "init 45" +- +- test45_46 kadmin/admin +- +- test "init 46" +- +- test45_46 kadmin/changepw +-} +- +-return "" +- +diff --git a/src/lib/kadm5/unit-test/api.current/mod-policy.exp b/src/lib/kadm5/unit-test/api.current/mod-policy.exp +deleted file mode 100644 +index 1bf00b524..000000000 +--- a/src/lib/kadm5/unit-test/api.current/mod-policy.exp ++++ /dev/null +@@ -1,711 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-test "modify-policy 2" +-proc test2 {} { +- global test +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MAX_LIFE} +- } $test] "AUTH_MODIFY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test2 } +- +-test "modify-policy 8" +-proc test8 {} { +- global test +-# set prms_id 744 +-# setup_xfail {*-*-*} $prms_id +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test { +- kadm5_modify_policy $server_handle [simple_policy ""] \ +- {KADM5_PW_MAX_LIFE} +- } "BAD_POLICY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test8 +- +-test "modify-policy 9" +-proc test9 {} { +- global test +- global prompt +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MIN_LIFE} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 1\n" +- expect { +- -re "0\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test9 +- +-test "modify-policy 10" +-proc test10 {} { +- global test +- global prompt +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle {"%s/a" 32 0 0 0 0 0 0 0 0} \ +- {KADM5_PW_MIN_LIFE} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 1\n" +- expect { +- -re "32\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test10 +- +- +-test "modify-policy 11" +-proc test11 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MAX_LIFE} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 2\n" +- expect { +- -re "0\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test11 +- +-test "modify-policy 12" +-proc test12 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 32 0 0 0 0 0 0 0} \ +- {KADM5_PW_MAX_LIFE} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 2\n" +- expect { +- -re "32\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test12 +- +-test "modify-policy 13" +-proc test13 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MIN_LENGTH} +- } $test] "BAD_LENGTH" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test13 +- +-test "modify-policy 14" +-proc test14 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 8 0 0 0 0 0 0} \ +- {KADM5_PW_MIN_LENGTH} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 3\n" +- expect { +- -re "8\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test14 +- +-test "modify-policy 15" +-proc test15 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MIN_CLASSES} +- } $test] "BAD_CLASS" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test15 +- +-test "modify-policy 16" +-proc test16 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 1 0 0 0 0 0} \ +- {KADM5_PW_MIN_CLASSES} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 4\n" +- expect { +- -re "1\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test16 +- +-test "modify-policy 17" +-proc test17 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a"])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 5 0 0 0 0 0} \ +- {KADM5_PW_MIN_CLASSES} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 4\n" +- expect { +- -re "5\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test17 +- +-test "modify-policy 18" +-proc test18 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 6 0 0 0 0 0} \ +- {KADM5_PW_MIN_CLASSES} +- } $test] "BAD_CLASS" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test18 +- +-test "modify-policy 19" +-proc test19 {} { +- global test +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_HISTORY_NUM} +- } $test] "BAD_HISTORY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test19 +- +-test "modify-policy 20" +-proc test20 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 0 1 0 0 0 0} \ +- {KADM5_PW_HISTORY_NUM} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 5\n" +- expect { +- -re "1\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test20 +- +-test "modify-policy 21" +-proc test21 {} { +- global test +- global prompt +- +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 0 10 0 0 0 0} \ +- {KADM5_PW_HISTORY_NUM} +- } $test]]} { +- fail $test +- return +- } +- if {! [cmd [format { +- kadm5_get_policy $server_handle "%s/a" policy +- } $test]]} { +- fail "$test: can not retrieve policy" +- return +- } +- send "lindex \$policy 5\n" +- expect { +- -re "10\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test21 +- +-test "modify-policy 22" +-proc test22 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MAX_LIFE} +- } $test] "AUTH_MODIFY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} test22 +- +-test "modify-policy 23" +-proc test23 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MAX_LIFE} +- } $test] "AUTH_MODIFY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} test23 +- +-test "modify-policy 26" +-proc test26 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ +- {KADM5_PW_MAX_LIFE} +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test26 +- +-test "modify-policy 30" +-proc test30 {} { +- global test +- +- one_line_fail_test [format { +- kadm5_modify_policy null [simple_policy "%s/a"] \ +- {KADM5_PW_MAX_LIFE} +- } $test] "BAD_SERVER_HANDLE" +-} +-test30 +- +-test "modify-policy 31" +-proc test31 {} { +- global test +- if {! (( [policy_exists "$test/a"]) || +- [create_policy "$test/a" ])} { +- error_and_restart "$test: couldn't create policy \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 0 0 0 2 0 0} \ +- {KADM5_PW_MAX_FAILURE} +- } $test] +- one_line_succeed_test [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 1 0 0 0 90 0} \ +- {KADM5_PW_FAILURE_COUNT_INTERVAL} +- } $test] +- one_line_succeed_test [format { +- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 1 0 0 0 0 180} \ +- {KADM5_PW_LOCKOUT_DURATION} +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test31 +- +-return "" +diff --git a/src/lib/kadm5/unit-test/api.current/mod-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/mod-principal-v2.exp +deleted file mode 100644 +index 4abbeb52d..000000000 +--- a/src/lib/kadm5/unit-test/api.current/mod-principal-v2.exp ++++ /dev/null +@@ -1,115 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-test "modify-principal 100-105" +-proc test100_104 {} { +- global test +- global prompt +- +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- +- set origtest "$test" +- +- test "modify-principal 100" +- one_line_succeed_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_MAX_RLIFE} +- } $origtest] +- +- test "modify-principal 101" +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_LAST_SUCCESS} +- } $origtest] "BAD_MASK" +- +- test "modify-principal 102" +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_LAST_FAILED} +- } $origtest] "BAD_MASK" +- +-# This is now permitted to reset lockout count +-# test "modify-principal 103" +-# one_line_fail_test [format { +-# kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +-# {KADM5_FAIL_AUTH_COUNT} +-# } $origtest] "BAD_MASK" +- +- test "modify-principal 103.5" +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_KEY_DATA} +- } $origtest] "BAD_MASK" +- +- test "modify-principal 105" +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle \ +- "{%s/a} 0 0 0 0 {%s/a} 0 0 0 0 null 0 0 0 0 0 0 1 {} {{1 1 x}}" \ +- {KADM5_TL_DATA} +- } $origtest $origtest] "BAD_TL_TYPE" +- +- test "modify-principal 100,104" +- if { ! [cmd [format { +- kadm5_modify_principal $server_handle \ +- "{%s/a} 0 0 0 0 {%s/a} 0 0 0 0 null 0 88 0 0 0 0 1 {} {{990 6 foobar}}" \ +- {KADM5_MAX_RLIFE KADM5_TL_DATA} +- } $origtest $origtest]]} { +- fail "$test: cannot set MAX_RLIFE or TL_DATA" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal {KADM5_PRINCIPAL_NORMAL_MASK KADM5_TL_DATA} +- } $origtest]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 12\n" +- expect { +- -re "(\[0-9\]+)\n$prompt$" {set rlife $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting rlife" +- return +- } +- eof { +- error_and_restart "$test: eof getting rlife" +- return +- } +- } +- send "lindex \$principal 19\n" +- expect { +- -re "\(\{.*\}\)\n$prompt$" {set tl $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting tl_data" +- return +- } +- eof { +- error_and_restart "$test: eof getting tl_data" +- return +- } +- } +- if {($rlife == 88) && ($tl == "{{990 6 foobar}}")} { +- pass "$test" +- } else { +- fail "$test: $rlife should be 88, $tl should be {{990 6 foobar}}" +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test100_104 +diff --git a/src/lib/kadm5/unit-test/api.current/mod-principal.exp b/src/lib/kadm5/unit-test/api.current/mod-principal.exp +deleted file mode 100644 +index ac9f96845..000000000 +--- a/src/lib/kadm5/unit-test/api.current/mod-principal.exp ++++ /dev/null +@@ -1,1606 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-#test "modify-principal 1" +-#proc test1 {} { +-# global test +-# one_line_fail_test [format { +-# kadm5_modify_principal $server_handle [simple_principal \ +-# "%s/a"] {KADM5_PW_EXPIRATION} +-# } $test] "NOT_INIT" +-#} +-#test1 +- +-test "modify-principal 2" +-proc test2 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINC_EXPIRE_TIME} +- } $test] "AUTH_MODIFY" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test2 } +- +-test "modify-principal 4" +-proc test4 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINCIPAL} +- } $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test4 +- +- +-test "modify-principal 5" +-proc test5 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_LAST_PWD_CHANGE} +- } $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test5 +- +-test "modify-principal 6" +-proc test6 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_MOD_TIME} +- } $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test6 +- +-test "modify-principal 7" +-proc test7 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_MOD_NAME} +- } $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test7 +- +-test "modify-principal 8" +-proc test8 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_MKVNO} +- } $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test8 +- +-test "modify-principal 9" +-proc test9 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_AUX_ATTRIBUTES} +- } $test] "BAD_MASK" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test9 +- +-test "modify-principal 10" +-proc test10 {} { +- global test +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINC_EXPIRE_TIME} +- } $test] "UNK_PRINC" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test10 +- +-test "modify-principal 11" +-proc test11 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINC_EXPIRE_TIME} +- } $test] "AUTH_MOD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if { $RPC } { test11 } +- +-test "modify-principal 12" +-proc test12 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINC_EXPIRE_TIME} +- } $test] "AUTH_MOD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if { $RPC } { test12 } +- +-test "modify-principal 13" +-proc test13 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINC_EXPIRE_TIME} +- } $test] "AUTH_MOD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if { $RPC } { test13 } +- +-test "modify-principal 14" +-proc test14 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINC_EXPIRE_TIME} +- } $test] "AUTH_MOD" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if { $RPC } { test14 } +- +-test "modify-principal 15" +-proc test15 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINC_EXPIRE_TIME} +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test15 +- +-test "modify-principal 17" +-proc test17 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_modify_principal $server_handle [princ_w_pol "%s/a" \ +- no-policy] {KADM5_POLICY} +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test17 +- +-test "modify-principal 21.5" +-proc test21.5 {} { +- global test +- global prompt +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if { !( [create_principal_pol "$test/a" "test-pol"])} { +- error_and_restart "$test: could not create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd {kadm5_get_policy $server_handle test-pol old_p1}]} { +- perror "$test: unexpected failure on get policy" +- return +- } +- if {! [cmd [format { +- kadm5_modify_principal $server_handle [princ_w_pol "%s/a" \ +- test-pol] {KADM5_POLICY} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$old_p1 6\n" +- expect { +- -re "(\[0-9\]+)\n$prompt$" {set old_p1_ref $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting principal kvno (second time)" +- return +- } +- eof { +- error_and_restart "$test: eof getting principal kvno (second time)" +- return +- } +- } +- +- if { ! [cmd {kadm5_get_policy $server_handle test-pol new_p1}]} { +- perror "$test: unexpected failure on get policy" +- return +- } +- +- send "lindex \$new_p1 6\n" +- expect { +- -re "(\[0-9\]+)\n$prompt$" {set new_p1_ref $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting principal kvno (second time)" +- return +- } +- eof { +- error_and_restart "$test: eof getting principal kvno (second time)" +- return +- } +- } +- +- if {$old_p1_ref != $new_p1_ref} { +- fail "$test: policy reference count changed ($old_p1_ref to $new_p1_ref)" +- return +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test21.5 +- +-test "modify-principal 22" +-proc test22 {} { +- global test +- global prompt +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PW_EXPIRATION} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 3\n" +- expect { +- -re "0\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test22 +- +-test "modify-principal 23" +-proc test23 {} { +- global test +- global prompt +- if {! (( [principal_exists "$test/a"]) || +- [create_principal_pol "$test/a" test-pol-nopw])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PW_EXPIRATION} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 3\n" +- expect { +- -re "0\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test23 +- +-test "modify-principal 24" +-proc test24 {} { +- global test +- global prompt +- +- if {! (( [principal_exists "$test/a"]) || +- [create_principal_pol "$test/a" "test-pol" ])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- error_and_restart "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PW_EXPIRATION} +- } $test]]} { +- fail "$test: could not modify principal" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- if { ! [cmd [format { +- kadm5_get_policy $server_handle %s policy +- } test-pol]]} { +- error_and_restart "$test: cannot retrieve policy" +- return +- } +- send "lindex \$principal 2\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_mod_date $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting mod_date" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_mod_date" +- return +- } +- } +- +- send "lindex \$principal 3\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_expire $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting pw_expire" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_expire" +- return +- } +- } +- +- send "lindex \$policy 2\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_max_life $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting pw_max_life" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_max_life" +- return +- } +- } +- if { $pw_expire != 0 } { +- fail "$test: pw_expire $pw_expire should be 0" +- return +- } else { +- pass "$test" +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test24 +- +-test "modify-principal 25" +-proc test25 {} { +- global test +- global prompt +- +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_modify_principal $server_handle \ +- {"%s/a" 0 0 1234 0 0 0 0 0 0 0 0} {KADM5_PW_EXPIRATION} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 3\n" +- expect { +- -re "1234\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test25 +- +-test "modify-principal 26" +-proc test26 {} { +- global test +- global prompt +- +- if {! (( [principal_exists "$test/a"]) || +- [create_principal_pol "$test/a" "test-pol-nopw" ])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_modify_principal $server_handle \ +- {"%s/a" 0 0 1234 0 0 0 0 0 0 0 0} {KADM5_PW_EXPIRATION} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 3\n" +- expect { +- -re "1234\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test26 +- +-test "modify-principal 27" +-proc test27 {} { +- global test +- global prompt +- +- if {! (( [principal_exists "$test/a"]) || +- [create_principal_pol "$test/a" "test-pol" ])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_modify_principal $server_handle \ +- {"%s/a" 0 0 1234 0 0 0 0 0 0 0 0} {KADM5_PW_EXPIRATION} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 3\n" +- expect { +- -re "1234\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test27 +- +-test "modify-principal 28" +-proc test28 {} { +- global test +- global prompt +-# set prms_id 1358 +-# setup_xfail {*-*-*} $prms_id +- +- if {! (( [principal_exists "$test/a"]) || +- [create_principal_pol "$test/a" "test-pol" ])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_modify_principal $server_handle \ +- {"%s/a" 0 0 999999999 0 0 0 0 0 0 0 0} {KADM5_PW_EXPIRATION} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- if { ! [cmd {kadm5_get_policy $server_handle test-pol policy}]} { +- error_and_restart "$test: cannot retrieve policy" +- return +- } +- send "lindex \$principal 2\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_mod_date $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting pw_mod_date" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_mod_date" +- return +- } +- } +- +- send "lindex \$principal 3\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_expire $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting pw_expire" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_expire" +- return +- } +- } +- send "lindex \$policy 2\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_max_life $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting pw_max_life" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_max_life" +- return +- } +- } +- if { $pw_expire != 999999999 } { +- fail "$test: pw_expire $pw_expire should be 999999999" +- return +- } +- pass "$test" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test28 +- +-test "modify-principal 29" +-proc test29 {} { +- global test +- global prompt +- +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if { ! ([create_principal_pol "$test/a" test-pol])} { +- perror "$test: unexpected failure in creating principal" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_POLICY_CLR} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 3\n" +- expect { +- -re "0\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test29 +- +-test "modify-principal 30" +-proc test30 {} { +- global test +- global prompt +- +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! ([create_principal_pol "$test/a" test-pol])} { +- perror "$test: unexpected failure in creating principal" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_modify_principal $server_handle [princ_w_pol "%s/a" \ +- test-pol-nopw] {KADM5_POLICY} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 3\n" +- expect { +- -re "0\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test30 +- +-test "modify-principal 31" +-proc test31 {} { +- global test +- global prompt +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! ([create_principal "$test/a"])} { +- perror "$test: unexpected failure in creating principal" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_modify_principal $server_handle [princ_w_pol "%s/a" \ +- test-pol] {KADM5_POLICY} +- } $test]]} { +- fail "modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- if { ! [cmd {kadm5_get_policy $server_handle test-pol policy}]} { +- error_and_restart "$test: cannot retrieve policy" +- return +- } +- send "lindex \$principal 2\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_mod_date $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting pw_mod_date" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_mod_date" +- return +- } +- } +- +- send "lindex \$principal 3\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_expire $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting pw_expire" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_expire" +- return +- } +- } +- +- send "lindex \$policy 2\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" {set pw_max_life $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting pw_max_life" +- return +- } +- eof { +- error_and_restart "$test: eof getting pw_max_life" +- return +- } +- } +- if { [expr "$pw_mod_date + $pw_max_life"] != $pw_expire } { +- fail "$test: pw_expire is wrong" +- return +- } +- +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test31 +- +-test "modify-principal 32" +-proc test32 {} { +- global test +- global prompt +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! ([create_principal "$test/a"])} { +- perror "$test: unexpected failure in creating principal" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_principal $server_handle \ +- {"%s/a" 1234 0 0 0 0 0 0 0 0 0 0} \ +- {KADM5_PRINC_EXPIRE_TIME} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 1\n" +- expect { +- -re "1234\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test32 +- +-test "modify-principal 33" +-proc test33 {} { +- global test +- global prompt +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! ([create_principal "$test/a"])} { +- perror "$test: unexpected failure in creating principal" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_principal $server_handle \ +- {"%s/a" 0 0 0 0 0 0 KRB5_KDB_DISALLOW_ALL_TIX 0 0 0 0} \ +- {KADM5_ATTRIBUTES} +- } $test]]} { +- fail "$test: modified fail" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 7\n" +- expect { +- -re "KRB5_KDB_DISALLOW_ALL_TIX.*$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test33 +- +-test "modify-principal 33.25" +-proc test3325 {} { +- global test +- global prompt +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! ([create_principal "$test/a"])} { +- perror "$test: unexpected failure in creating principal" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_principal $server_handle \ +- {"%s/a" 0 0 0 0 0 0 KRB5_KDB_REQUIRES_PWCHANGE 0 0 0 0} \ +- {KADM5_ATTRIBUTES} +- } $test]]} { +- fail "$test: modified fail" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 7\n" +- expect { +- -re "KRB5_KDB_REQUIRES_PWCHANGE.*$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test3325 +- +-test "modify-principal 33.5" +-proc test335 {} { +- global test +- global prompt +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! ([create_principal "$test/a"])} { +- perror "$test: unexpected failure in creating principal" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_principal $server_handle \ +- {"%s/a" 0 0 0 0 0 0 KRB5_KDB_DISALLOW_TGT_BASED 0 0 0 0} \ +- {KADM5_ATTRIBUTES} +- } $test]]} { +- fail "$test: modified fail" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 7\n" +- expect { +- -re "KRB5_KDB_DISALLOW_TGT_BASED.*$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test335 +- +- +-test "modify-principal 34" +-proc test34 {} { +- global test +- global prompt +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! ([create_principal "$test/a"])} { +- perror "$test: unexpected failure in creating principal" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_modify_principal $server_handle \ +- {"%s/a" 0 0 0 3456 0 0 0 0 0 0 0} {KADM5_MAX_LIFE} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 4\n" +- expect { +- -re "3456\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test34 +- +-test "modify-principal 35" +-proc test35 {} { +- global prompt +- global test +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! ([create_principal "$test/a"])} { +- perror "$test: unexpected failure in creating principal" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd [format { +- kadm5_modify_principal $server_handle \ +- {"%s/a" 0 0 0 0 0 0 0 7 0 0 0} {KADM5_KVNO} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 8\n" +- expect { +- -re "7\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test35 +- +-test "modify-principal 36" +-proc test36 {} { +- global test +- global prompt +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if { !( [create_principal_pol "$test/a" "test-pol"])} { +- error_and_restart "$test: could not create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if { ! [cmd {kadm5_get_policy $server_handle test-pol pol}]} { +- perror "$test: unexpected failure on get policy" +- return +- } +- if {! [cmd [format { +- kadm5_modify_principal $server_handle [princ_w_pol "%s/a" \ +- test-pol] {KADM5_POLICY} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 10\n" +- expect { +- -re "test-pol\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- send "lindex \$pol 6\n" +- expect { +- -re "(\[0-9\]+)\n$prompt$" {set oldref $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting principal kvno (second time)" +- return +- } +- eof { +- error_and_restart "$test: eof getting principal kvno (second time)" +- return +- } +- } +- if { ! [cmd {kadm5_get_policy $server_handle test-pol pol2}]} { +- perror "$test: unexpected failure on get policy" +- return +- } +- send "lindex \$pol2 6\n" +- expect { +- -re "(\[0-9\]+)\n$prompt$" {set newref $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting principal kvno (second time)" +- return +- } +- eof { +- error_and_restart "$test: eof getting principal kvno (second time)" +- return +- } +- } +- if { $oldref != $newref } { +- fail "$test: policy reference count is wrong" +- return; +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test36 +- +-test "modify-principal 37" +-proc test37 {} { +- global test +- global prompt +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if { !( [create_principal "$test/a"])} { +- error_and_restart "$test: could not create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_POLICY_CLR} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test37 +- +-test "modify-principal 38" +-proc test38 {} { +- global test +- global prompt +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! ([create_principal "$test/a"])} { +- perror "$test: unexpected failure in creating principal" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_PRINC_EXPIRE_TIME} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 1\n" +- expect { +- -re "0\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test38 +- +-test "modify-principal 39" +-proc test39 {} { +- global test +- global prompt +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! ([create_principal "$test/a"])} { +- perror "$test: unexpected failure in creating principal" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ +- {KADM5_MAX_LIFE} +- } $test]]} { +- fail "$test: modify failed" +- return +- } +- if {! [cmd [format { +- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK +- } $test]]} { +- error_and_restart "$test: could not retrieve principal" +- return +- } +- send "lindex \$principal 4\n" +- expect { +- -re "0\n$prompt$" { pass "$test" } +- timeout { fail "$test" } +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test39 +- +-test "modify-principal 40" +-proc test40 {} { +- global test +- global prompt +- +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test { +- kadm5_modify_principal $server_handle null \ +- {KADM5_PRINC_EXPIRE_TIME} +- } "EINVAL" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test40 +- +-test "modify-principal 43" +-proc test43 {} { +- global test +- one_line_fail_test [format { +- kadm5_modify_principal null [simple_principal \ +- "%s/a"] {KADM5_PW_EXPIRATION} +- } $test] "BAD_SERVER_HANDLE" +-} +-test43 +- +-test "modify-principal 44" +-proc test44 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- # setting fail auth count to a non-zero value must fail +- one_line_fail_test [format { +- kadm5_modify_principal $server_handle \ +- {"%s/a" 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1234 0 0 {} {}} {KADM5_FAIL_AUTH_COUNT} +- } $test] "BAD_SERVER_PARAMS" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test44 +- +-return "" +diff --git a/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp +deleted file mode 100644 +index 2925c1c43..000000000 +--- a/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp ++++ /dev/null +@@ -1,61 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-test "randkey-principal 100" +-proc test100 {} { +- global test prompt +- +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [create_principal "$test/a"]} { +- error_and_restart "$test: creating principal" +- return +- } +- +- # I'd like to specify a long list of keysalt tuples and make sure that +- # randkey does the right thing, but we can only use those enctypes that +- # krbtgt has a key for: 3DES and AES, according to the prototype kdc.conf. +- if {! [cmd [format { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_randkey_principal $server_handle "%s/a" keys num_keys +- } $test]]} { +- perror "$test: unexpected failure in randkey_principal" +- } +- send "puts \$num_keys\n" +- expect { +- -re "(\[0-9\]+)\n$prompt" { set num_keys $expect_out(1,string) } +- timeout { +- error_and_restart "$test: timeout getting num_keys" +- return +- } +- eof { +- error_and_restart "$test: eof getting num_keys" +- return +- } +- } +- +- # XXX Perhaps I should actually check the key type returned. +- if {$num_keys == 5} { +- pass "$test" +- } else { +- fail "$test: $num_keys keys, should be 5" +- } +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test100 +- +-return "" +diff --git a/src/lib/kadm5/unit-test/api.current/randkey-principal.exp b/src/lib/kadm5/unit-test/api.current/randkey-principal.exp +deleted file mode 100644 +index 1484901fa..000000000 +--- a/src/lib/kadm5/unit-test/api.current/randkey-principal.exp ++++ /dev/null +@@ -1,297 +0,0 @@ +-load_lib lib.t +-api_exit +-api_start +- +-test "randkey-principal 1" +-proc test1 {} { +- global test +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [create_principal_pol "$test/a" once-a-min]} { +- error_and_restart "$test: creating principal" +- return +- } +- +- if {! [cmd [format { +- kadm5_init "%s/a" "%s/a" $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } $test $test]]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_randkey_principal $server_handle "%s/a" keys num_keys +- } $test] "PASS_TOOSOON" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test1 } +- +-test "randkey-principal 3" +-proc test3 {} { +- global test +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [create_principal_pol "$test/a" once-a-min]} { +- error_and_restart "$test: creating principal" +- return +- } +- +- if {! [cmd [format { +- kadm5_init "%s/a" "%s/a" $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } $test $test]]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_randkey_principal $server_handle "%s/a" keys num_keys +- } $test] "PASS_TOOSOON" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if ${RPC} { test3 } +- +-test "randkey-principal 13" +-proc test13 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- if {! [cmd [format { +- kadm5_modify_principal $server_handle [princ_w_pol "%s/a" \ +- once-a-min] KADM5_POLICY +- } $test]]} { +- perror "$test: failed modify" +- return +- } +- one_line_succeed_test [format { +- kadm5_randkey_principal $server_handle "%s/a" keys num_keys +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test13 +- +-test "randkey-principal 15" +-proc test15 {} { +- global test +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [create_principal_pol "$test/a" once-a-min]} { +- error_and_restart "$test: creating principal" +- return +- } +- +- if {! [cmd { +- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_randkey_principal $server_handle "%s/a" keys num_keys +- } $test] "AUTH_CHANGEPW" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if { $RPC } { test15 } +- +-test "randkey-principal 28" +-proc test28 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_randkey_principal $server_handle "%s/a" keys num_keys +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test28 +- +-test "randkey-principal 28.25" +-proc test2825 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_randkey_principal $server_handle "%s/a" keys num_keys +- } $test] "AUTH" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-if {$RPC} { test2825 } +- +-test "randkey-principal 28.5" +-proc test285 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [cmd { +- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_randkey_principal $server_handle "%s/a" keys num_keys +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test285 +- +-test "randkey-principal 30" +-proc test30 {} { +- global test +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't delete principal \"$test/a\"" +- return +- } +- if {! [create_principal "$test/a"]} { +- error_and_restart "$test: creating principal" +- return +- } +- if {! [cmd [format { +- kadm5_init "%s/a" "%s/a" $KADM5_CHANGEPW_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } $test $test]]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_randkey_principal $server_handle "%s/a" keys num_keys +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test30 +- +-test "randkey-principal 31" +-proc test31 {} { +- global test +- if {! (( ! [principal_exists "$test/a"]) || +- [delete_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if {! [create_principal "$test/a"]} { +- error_and_restart "$test: creating principal" +- return +- } +- +- if {! [cmd [format { +- kadm5_init "%s/a" "%s/a" $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- } $test $test]]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_succeed_test [format { +- kadm5_randkey_principal $server_handle "%s/a" keys num_keys +- } $test] +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +-test31 +- +-test "randkey-principal 33" +-proc test33 {} { +- global test +- if {! (( [principal_exists "$test/a"]) || +- [create_principal "$test/a"])} { +- error_and_restart "$test: couldn't create principal \"$test/a\"" +- return +- } +- if { ! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- server_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- one_line_fail_test [format { +- kadm5_randkey_principal null "%s/a" keys num_keys +- } $test] "BAD_SERVER_HANDLE" +- if { ! [cmd {kadm5_destroy $server_handle}]} { +- perror "$test: unexpected failure in destroy" +- return +- } +-} +- +-test33 +- +-return "" +diff --git a/src/lib/kadm5/unit-test/config/unix.exp b/src/lib/kadm5/unit-test/config/unix.exp +deleted file mode 100644 +index d7706ec53..000000000 +--- a/src/lib/kadm5/unit-test/config/unix.exp ++++ /dev/null +@@ -1,222 +0,0 @@ +-source runenv.exp +- +-set prompt "% " +-set stty_init {-onlcr -opost intr \^C kill \^U} +-set kadmin_local $KADMIN_LOCAL +- +-# Backward compatibility until we're using expect 5 everywhere +-if {[info exists exp_version_4]} { +- global wait_error_index wait_errno_index wait_status_index +- set wait_error_index 0 +- set wait_errno_index 1 +- set wait_status_index 1 +-} else { +- set wait_error_index 2 +- set wait_errno_index 3 +- set wait_status_index 3 +-} +- +-if { [string length $VALGRIND] } { +- rename spawn valgrind_aux_spawn +- proc spawn { args } { +- global VALGRIND +- upvar 1 spawn_id spawn_id +- set newargs {} +- set inflags 1 +- set eatnext 0 +- foreach arg $args { +- if { $arg == "-ignore" \ +- || $arg == "-open" \ +- || $arg == "-leaveopen" } { +- lappend newargs $arg +- set eatnext 1 +- continue +- } +- if [string match "-*" $arg] { +- lappend newargs $arg +- continue +- } +- if { $eatnext } { +- set eatnext 0 +- lappend newargs $arg +- continue +- } +- if { $inflags } { +- set inflags 0 +- # Only run valgrind for local programs, not +- # system ones. +-#&&![string match "/bin/sh" $arg] sh is used to start kadmind! +- if [string match "/" [string index $arg 0]]&&![string match "/bin/ls" $arg]&&![regexp {/kshd$} $arg] { +- set newargs [concat $newargs $VALGRIND] +- } +- } +- lappend newargs $arg +- } +- set pid [eval valgrind_aux_spawn $newargs] +- return $pid +- } +-} +- +-# Hack around Solaris 9 kernel race condition that causes last output +-# from a pty to get dropped. +-if { $PRIOCNTL_HACK } { +- catch {exec priocntl -s -c FX -m 30 -p 30 -i pid [getpid]} +- rename spawn oldspawn +- proc spawn { args } { +- upvar 1 spawn_id spawn_id +- set newargs {} +- set inflags 1 +- set eatnext 0 +- foreach arg $args { +- if { $arg == "-ignore" \ +- || $arg == "-open" \ +- || $arg == "-leaveopen" } { +- lappend newargs $arg +- set eatnext 1 +- continue +- } +- if [string match "-*" $arg] { +- lappend newargs $arg +- continue +- } +- if { $eatnext } { +- set eatnext 0 +- lappend newargs $arg +- continue +- } +- if { $inflags } { +- set inflags 0 +- set newargs [concat $newargs {priocntl -e -c FX -p 0}] +- } +- lappend newargs $arg +- } +- set pid [eval oldspawn $newargs] +- return $pid +- } +-} +- +-# Variables for keeping track of api process state +-set api_pid "0" +- +-proc api_exit {} { +- global spawn_id +- global api_pid +- +-# puts stdout "Starting api_exit (spawn_id $spawn_id)." +- catch {close} errMsg +- catch {wait} errMsg +-# puts stdout "Finishing api_exit for $api_pid." +- set api_pid "0" +-} +- +-proc api_isrunning {pid} { +- global api_pid +- +-# puts stdout "testing $pid, api_pid is $api_pid" +- if {$pid == $api_pid} { +- return 1; +- } else { +- return 0; +- } +-} +- +-proc api_version {} { +-} +- +-proc api_start {} { +- global API +- global env +- global spawn_id +- global prompt +- global api_pid +- +- set pid [spawn $API] +- expect { +- -re "$prompt$" {} +- eof { perror "EOF starting API" } +- timeout { perror "Timeout starting API" } +- } +- if {! [info exists env(TCLUTIL)]} { +- perror "TCLUTIL environment variable isn't set" +- } +- # tcl 8.4 for some reason screws up autodetection of output +- # EOL translation. Work around it for now. +- send "if { \[info commands fconfigure\] ne \"\" } { fconfigure stdout -translation lf }\n" +- expect { +- -re "$prompt$" {} +- eof { perror "EOF starting API" } +- timeout { perror "Timeout starting API" } +- } +- send "source $env(TCLUTIL)\n" +- expect { +- -re "$prompt$" {} +- eof { perror "EOF starting API" } +- timeout { perror "Timeout starting API" } +- } +- send "set current_struct_version \[expr \$KADM5_STRUCT_VERSION &~ \$KADM5_STRUCT_VERSION_MASK\]\n" +- expect { +- -re "$prompt$" {} +- eof { perror "EOF setting API variables"} +- timeout { perror "timeout setting API variables"} +- } +- send "set current_api_version \[expr \$KADM5_API_VERSION_3 &~ \$KADM5_API_VERSION_MASK\]\n" +- expect { +- -re "$prompt$" {} +- eof { perror "EOF setting API variables"} +- timeout { perror "timeout setting API variables"} +- } +- send "set bad_struct_version_mask \[expr 0x65432100 | \$current_struct_version\]\n" +- expect { +- -re "$prompt$" {} +- eof { perror "EOF setting API variables"} +- timeout { perror "timeout setting API variables"} +- } +- send "set bad_api_version_mask \[expr 0x65432100 | \$current_api_version\]\n" +- expect { +- -re "$prompt$" {} +- eof { perror "EOF setting API variables"} +- timeout { perror "timeout setting API variables"} +- } +- send "set no_api_version_mask \$current_api_version\n" +- expect { +- -re "$prompt$" {} +- eof { perror "EOF setting API variables"} +- timeout { perror "timeout setting API variables"} +- } +- send "set no_struct_version_mask \$current_struct_version\n" +- expect { +- -re "$prompt$" {} +- eof { perror "EOF setting API variables"} +- timeout { perror "timeout setting API variables"} +- } +- send "set old_api_version \[expr \$KADM5_API_VERSION_MASK | 0x00\]\n" +- expect { +- -re "$prompt$" {} +- eof { perror "EOF setting API variables"} +- timeout { perror "timeout setting API variables"} +- } +- send "set old_struct_version \[expr \$KADM5_STRUCT_VERSION_MASK | 0x00\]\n" +- expect { +- -re "$prompt$" {} +- eof { perror "EOF setting API variables"} +- timeout { perror "timeout setting API variables"} +- } +- send "set new_api_version \[expr \$KADM5_API_VERSION_MASK | 0xca\]\n" +- expect { +- -re "$prompt$" {} +- eof { perror "EOF setting API variables"} +- timeout { perror "timeout setting API variables"} +- } +- send "set new_struct_version \[expr \$KADM5_STRUCT_VERSION_MASK | 0xca\]\n" +- expect { +- -re "$prompt$" {} +- eof { perror "EOF setting API variables"} +- timeout { perror "timeout setting API variables"} +- } +- +- set api_pid $pid +-# puts stdout "Finishing api_start (spawn_id $spawn_id, pid $api_pid)." +- return $pid +-} +-api_start +- +diff --git a/src/lib/kadm5/unit-test/deps b/src/lib/kadm5/unit-test/deps +deleted file mode 100644 +index cf54f475b..000000000 +--- a/src/lib/kadm5/unit-test/deps ++++ /dev/null +@@ -1,86 +0,0 @@ +-# +-# Generated makefile dependencies follow. +-# +-$(OUTPRE)init-test.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ +- $(BUILDTOP)/include/gssrpc/types.h $(BUILDTOP)/include/kadm5/admin.h \ +- $(BUILDTOP)/include/kadm5/chpass_util_strings.h $(BUILDTOP)/include/kadm5/kadm_err.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ +- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ +- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ +- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ +- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ +- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/kdb.h \ +- $(top_srcdir)/include/krb5.h init-test.c +-$(OUTPRE)destroy-test.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ +- $(BUILDTOP)/include/gssrpc/types.h $(BUILDTOP)/include/kadm5/admin.h \ +- $(BUILDTOP)/include/kadm5/admin_internal.h $(BUILDTOP)/include/kadm5/chpass_util_strings.h \ +- $(BUILDTOP)/include/kadm5/client_internal.h $(BUILDTOP)/include/kadm5/kadm_err.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ +- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ +- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ +- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ +- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ +- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/kdb.h \ +- $(top_srcdir)/include/krb5.h destroy-test.c +-$(OUTPRE)handle-test.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/gssapi/gssapi.h $(BUILDTOP)/include/gssrpc/types.h \ +- $(BUILDTOP)/include/kadm5/admin.h $(BUILDTOP)/include/kadm5/admin_internal.h \ +- $(BUILDTOP)/include/kadm5/chpass_util_strings.h $(BUILDTOP)/include/kadm5/kadm_err.h \ +- $(BUILDTOP)/include/kadm5/server_internal.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ +- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ +- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ +- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ +- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ +- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/kdb.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/plugin.h \ +- handle-test.c +-$(OUTPRE)iter-test.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ +- $(BUILDTOP)/include/gssrpc/types.h $(BUILDTOP)/include/kadm5/admin.h \ +- $(BUILDTOP)/include/kadm5/chpass_util_strings.h $(BUILDTOP)/include/kadm5/kadm_err.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ +- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ +- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ +- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ +- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ +- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/kdb.h \ +- $(top_srcdir)/include/krb5.h iter-test.c +-$(OUTPRE)setkey-test.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/gssapi/gssapi.h $(BUILDTOP)/include/gssrpc/types.h \ +- $(BUILDTOP)/include/kadm5/admin.h $(BUILDTOP)/include/kadm5/chpass_util_strings.h \ +- $(BUILDTOP)/include/kadm5/kadm_err.h $(BUILDTOP)/include/krb5/krb5.h \ +- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ +- $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ +- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ +- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ +- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ +- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ +- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/kdb.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- setkey-test.c +-$(OUTPRE)randkey-test.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ +- $(BUILDTOP)/include/gssrpc/types.h $(BUILDTOP)/include/kadm5/admin.h \ +- $(BUILDTOP)/include/kadm5/chpass_util_strings.h $(BUILDTOP)/include/kadm5/kadm_err.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ +- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ +- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ +- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ +- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ +- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/kdb.h \ +- $(top_srcdir)/include/krb5.h randkey-test.c +-$(OUTPRE)lock-test.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ +- $(BUILDTOP)/include/gssrpc/types.h $(BUILDTOP)/include/kadm5/admin.h \ +- $(BUILDTOP)/include/kadm5/chpass_util_strings.h $(BUILDTOP)/include/kadm5/kadm_err.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ +- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ +- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ +- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ +- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ +- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/kdb.h \ +- $(top_srcdir)/include/krb5.h lock-test.c +diff --git a/src/lib/kadm5/unit-test/destroy-test.c b/src/lib/kadm5/unit-test/destroy-test.c +deleted file mode 100644 +index 738cfeb86..000000000 +--- a/src/lib/kadm5/unit-test/destroy-test.c ++++ /dev/null +@@ -1,48 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +- +-#define TEST_NUM 25 +- +-int main() +-{ +- kadm5_ret_t ret; +- char *cp; +- int x; +- void *server_handle; +- kadm5_server_handle_t handle; +- krb5_context context; +- +- ret = kadm5_init_krb5_context(&context); +- if (ret != 0) { +- com_err("test", ret, "context init"); +- exit(2); +- } +- for(x = 0; x < TEST_NUM; x++) { +- ret = kadm5_init(context, "admin", "admin", KADM5_ADMIN_SERVICE, 0, +- KADM5_STRUCT_VERSION, KADM5_API_VERSION_4, NULL, +- &server_handle); +- if(ret != KADM5_OK) { +- com_err("test", ret, "init"); +- exit(2); +- } +- handle = (kadm5_server_handle_t) server_handle; +- cp = strdup(strchr(handle->cache_name, ':') + 1); +- kadm5_destroy(server_handle); +- if(access(cp, F_OK) == 0) { +- puts("ticket cache not destroyed"); +- exit(2); +- } +- free(cp); +- } +- krb5_free_context(context); +- exit(0); +-} +diff --git a/src/lib/kadm5/unit-test/diff-files/destroy-1 b/src/lib/kadm5/unit-test/diff-files/destroy-1 +deleted file mode 100644 +index 593d67320..000000000 +--- a/src/lib/kadm5/unit-test/diff-files/destroy-1 ++++ /dev/null +@@ -1,2 +0,0 @@ +-##! nochanges +- +diff --git a/src/lib/kadm5/unit-test/diff-files/no-diffs b/src/lib/kadm5/unit-test/diff-files/no-diffs +deleted file mode 100644 +index 593d67320..000000000 +--- a/src/lib/kadm5/unit-test/diff-files/no-diffs ++++ /dev/null +@@ -1,2 +0,0 @@ +-##! nochanges +- +diff --git a/src/lib/kadm5/unit-test/handle-test.c b/src/lib/kadm5/unit-test/handle-test.c +deleted file mode 100644 +index 29bd2c9a1..000000000 +--- a/src/lib/kadm5/unit-test/handle-test.c ++++ /dev/null +@@ -1,140 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#ifdef CLIENT_TEST +-#include +-#else +-#include +-#include +-#endif +- +-int main(int argc, char *argv[]) +-{ +- kadm5_ret_t ret; +- void *server_handle; +- kadm5_server_handle_t handle; +- kadm5_server_handle_rec orig_handle; +- kadm5_policy_ent_rec pol; +- kadm5_principal_ent_t princ; +- kadm5_principal_ent_rec kprinc; +- krb5_keyblock *key; +- krb5_principal tprinc; +- krb5_context context; +- +- +- kadm5_init_krb5_context(&context); +- +- ret = kadm5_init(context, "admin/none", "admin", KADM5_ADMIN_SERVICE, NULL, +- KADM5_STRUCT_VERSION, KADM5_API_VERSION_4, NULL, +- &server_handle); +- if(ret != KADM5_OK) { +- com_err("test", ret, "init"); +- exit(2); +- } +- handle = (kadm5_server_handle_t) server_handle; +- orig_handle = *handle; +- handle->magic_number = KADM5_STRUCT_VERSION; +- krb5_parse_name(context, "testuser", &tprinc); +- ret = kadm5_get_principal(server_handle, tprinc, &kprinc, +- KADM5_PRINCIPAL_NORMAL_MASK); +- if(ret != KADM5_BAD_SERVER_HANDLE) { +- fprintf(stderr, "%s -- returned -- %s\n", "get-principal", +- error_message(ret)); +- exit(1); +- } +- +- ret = kadm5_get_policy(server_handle, "pol1", &pol); +- if(ret != KADM5_BAD_SERVER_HANDLE) { +- fprintf(stderr, "%s -- returned -- %s\n", "get-policy", +- error_message(ret)); +- exit(1); +- } +- +- princ = &kprinc; +- ret = kadm5_create_principal(server_handle, princ, KADM5_PRINCIPAL, "pass"); +- if(ret != KADM5_BAD_SERVER_HANDLE) { +- fprintf(stderr, "%s -- returned -- %s\n", "create-principal", +- error_message(ret)); +- exit(1); +- } +- +- ret = kadm5_create_policy(server_handle, &pol, KADM5_POLICY); +- if(ret != KADM5_BAD_SERVER_HANDLE) { +- fprintf(stderr, "%s -- returned -- %s\n", "create-policy", +- error_message(ret)); +- exit(1); +- } +- +- ret = kadm5_modify_principal(server_handle, princ, KADM5_PW_EXPIRATION); +- if(ret != KADM5_BAD_SERVER_HANDLE) { +- fprintf(stderr, "%s -- returned -- %s\n", "modify-principal", +- error_message(ret)); +- exit(1); +- } +- +- ret = kadm5_modify_policy(server_handle, &pol, KADM5_PW_MAX_LIFE); +- if(ret != KADM5_BAD_SERVER_HANDLE) { +- fprintf(stderr, "%s -- returned -- %s\n", "modify-policy", +- error_message(ret)); +- exit(1); +- } +- +- ret = kadm5_delete_principal(server_handle, tprinc); +- if(ret != KADM5_BAD_SERVER_HANDLE) { +- fprintf(stderr, "%s -- returned -- %s\n", "delete-principal", +- error_message(ret)); +- exit(1); +- } +- +- ret = kadm5_delete_policy(server_handle, "pol1"); +- if(ret != KADM5_BAD_SERVER_HANDLE) { +- fprintf(stderr, "%s -- returned -- %s\n", "delete-policy", +- error_message(ret)); +- exit(1); +- } +- +- ret = kadm5_chpass_principal(server_handle, tprinc, "FooBar"); +- if(ret != KADM5_BAD_SERVER_HANDLE) { +- fprintf(stderr, "%s -- returned -- %s\n", "chpass", +- error_message(ret)); +- exit(1); +- } +- ret = kadm5_randkey_principal(server_handle, tprinc, &key, NULL); +- if(ret != KADM5_BAD_SERVER_HANDLE) { +- fprintf(stderr, "%s -- returned -- %s\n", "randkey", +- error_message(ret)); +- exit(1); +- } +- +- ret = kadm5_rename_principal(server_handle, tprinc, tprinc); +- if(ret != KADM5_BAD_SERVER_HANDLE) { +- fprintf(stderr, "%s -- returned -- %s\n", "rename", +- error_message(ret)); +- exit(1); +- } +- +- ret = kadm5_destroy(server_handle); +- if(ret != KADM5_BAD_SERVER_HANDLE) { +- fprintf(stderr, "%s -- returned -- %s\n", "destroy", +- error_message(ret)); +- exit(1); +- } +- +- *handle = orig_handle; +- ret = kadm5_destroy(server_handle); +- if (ret != KADM5_OK) { +- fprintf(stderr, "valid %s -- returned -- %s\n", "destroy", +- error_message(ret)); +- exit(1); +- } +- +- krb5_free_principal(context, tprinc); +- krb5_free_context(context); +- exit(0); +-} +diff --git a/src/lib/kadm5/unit-test/init-test.c b/src/lib/kadm5/unit-test/init-test.c +deleted file mode 100644 +index 9f06621e8..000000000 +--- a/src/lib/kadm5/unit-test/init-test.c ++++ /dev/null +@@ -1,39 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-#include +-#include +-#include +-#include +-#include +-#include +- +-int main() +-{ +- kadm5_ret_t ret; +- void *server_handle; +- kadm5_config_params params; +- krb5_context context; +- +- memset(¶ms, 0, sizeof(params)); +- params.mask |= KADM5_CONFIG_NO_AUTH; +- ret = kadm5_init_krb5_context(&context); +- if (ret != 0) { +- com_err("init-test", ret, "while initializing krb5 context"); +- exit(1); +- } +- ret = kadm5_init(context, "admin", "admin", NULL, ¶ms, +- KADM5_STRUCT_VERSION, KADM5_API_VERSION_4, NULL, +- &server_handle); +- if (!ret) +- (void)kadm5_destroy(server_handle); +- krb5_free_context(context); +- if (ret == KADM5_RPC_ERROR) { +- exit(0); +- } +- else if (ret != 0) { +- com_err("init-test", ret, "while initializing without auth"); +- exit(1); +- } else { +- fprintf(stderr, "Unexpected success while initializing without auth!\n"); +- exit(1); +- } +-} +diff --git a/src/lib/kadm5/unit-test/iter-test.c b/src/lib/kadm5/unit-test/iter-test.c +deleted file mode 100644 +index cd85ebe4d..000000000 +--- a/src/lib/kadm5/unit-test/iter-test.c ++++ /dev/null +@@ -1,51 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-#include +-#include +-#include +- +-int main(int argc, char **argv) +-{ +- kadm5_ret_t ret; +- void *server_handle; +- char **names; +- int count, princ, i; +- krb5_context context; +- +- if (argc != 3) { +- fprintf(stderr, "Usage: %s [-princ|-pol] exp\n", argv[0]); +- exit(1); +- } +- princ = (strcmp(argv[1], "-princ") == 0); +- +- ret = kadm5_init_krb5_context(&context); +- if (ret != KADM5_OK) { +- com_err("iter-test", ret, "while initializing context"); +- exit(1); +- } +- ret = kadm5_init("admin", "admin", KADM5_ADMIN_SERVICE, 0, +- KADM5_STRUCT_VERSION, KADM5_API_VERSION_4, NULL, +- &server_handle); +- if (ret != KADM5_OK) { +- com_err("iter-test", ret, "while initializing"); +- exit(1); +- } +- +- if (princ) +- ret = kadm5_get_principals(server_handle, argv[2], &names, &count); +- else +- ret = kadm5_get_policies(server_handle, argv[2], &names, &count); +- +- if (ret != KADM5_OK) { +- com_err("iter-test", ret, "while retrieving list"); +- exit(1); +- } +- +- for (i = 0; i < count; i++) +- printf("%d: %s\n", i, names[i]); +- +- kadm5_free_name_list(server_handle, names, count); +- +- (void) kadm5_destroy(server_handle); +- +- return 0; +-} +diff --git a/src/lib/kadm5/unit-test/lib/lib.t b/src/lib/kadm5/unit-test/lib/lib.t +deleted file mode 100644 +index 3444775cf..000000000 +--- a/src/lib/kadm5/unit-test/lib/lib.t ++++ /dev/null +@@ -1,306 +0,0 @@ +-global timeout +-set timeout 60 +- +-set lib_pid 0 +- +-# +-# The functions in this library used to be responsible for bazillions +-# of wasted api_starts. Now, they all just use their own library +-# handle so they are not interrupted when the main tests call init or +-# destroy. They have to keep track of when the api exists and +-# restarts, though, since the lib_handle needs to be re-opened in that +-# case. +-# +-proc lib_start_api {} { +- global spawn_id lib_pid test +- +- if {! [api_isrunning $lib_pid]} { +- api_exit +- set lib_pid [api_start] +- if {! [cmd { +- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ +- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ +- lib_handle +- }]} { +- perror "$test: unexpected failure in init" +- return +- } +- verbose "+++ restarted api ($lib_pid) for lib" +- } else { +- verbose "+++ api $lib_pid already running for lib" +- } +-} +- +-proc cmd {command} { +- global prompt +- global spawn_id +- global test +- +- send "[string trim $command]\n" +- expect { +- -re "OK .*$prompt$" { return 1 } +- -re "ERROR .*$prompt$" { return 0 } +- "wrong # args" { perror "$test: wrong number args"; return 0 } +- timeout { fail "$test: timeout"; return 0 } +- eof { fail "$test: eof"; api_exit; lib_start_api; return 0 } +- } +-} +- +-proc tcl_cmd {command} { +- global prompt spawn_id test +- +- send "[string trim $command]\n" +- expect { +- -re "$prompt$" { return 1} +- "wrong # args" { perror "$test: wrong number args"; return 0 } +- timeout { error_and_restart "timeout" } +- eof { api_exit; lib_start_api; return 0 } +- } +-} +- +-proc one_line_succeed_test {command} { +- global prompt +- global spawn_id +- global test +- +- send "[string trim $command]\n" +- expect { +- -re "OK .*$prompt$" { pass "$test"; return 1 } +- -re "ERROR .*$prompt$" { +- fail "$test: $expect_out(buffer)"; return 0 +- } +- "wrong # args" { perror "$test: wrong number args"; return 0 } +- timeout { fail "$test: timeout"; return 0 } +- eof { fail "$test: eof"; api_exit; lib_start_api; return 0 } +- } +-} +- +-proc one_line_fail_test {command code} { +- global prompt +- global spawn_id +- global test +- +- send "[string trim $command]\n" +- expect { +- -re "ERROR .*$code.*$prompt$" { pass "$test"; return 1 } +- -re "ERROR .*$prompt$" { fail "$test: bad failure"; return 0 } +- -re "OK .*$prompt$" { fail "$test: bad success"; return 0 } +- "wrong # args" { perror "$test: wrong number args"; return 0 } +- timeout { fail "$test: timeout"; return 0 } +- eof { fail "$test: eof"; api_exit; lib_start_api; return 0 } +- } +-} +- +-proc one_line_fail_test_nochk {command} { +- global prompt +- global spawn_id +- global test +- +- send "[string trim $command]\n" +- expect { +- -re "ERROR .*$prompt$" { pass "$test:"; return 1 } +- -re "OK .*$prompt$" { fail "$test: bad success"; return 0 } +- "wrong # args" { perror "$test: wrong number args"; return 0 } +- timeout { fail "$test: timeout"; return 0 } +- eof { fail "$test: eof"; api_exit; lib_start_api; return 0 } +- } +-} +- +-proc resync {} { +- global prompt spawn_id test +- +- expect { +- -re "$prompt$" {} +- "wrong # args" { perror "$test: wrong number args"; return 0 } +- eof { api_exit; lib_start_api } +- } +-} +- +-proc create_principal {name} { +- lib_start_api +- +- set ret [cmd [format { +- kadm5_create_principal $lib_handle [simple_principal \ +- "%s"] {KADM5_PRINCIPAL} "%s" +- } $name $name]] +- +- return $ret +-} +- +-proc create_policy {name} { +- lib_start_api +- +- set ret [cmd [format { +- kadm5_create_policy $lib_handle [simple_policy "%s"] \ +- {KADM5_POLICY} +- } $name $name]] +- +- return $ret +-} +- +-proc create_principal_pol {name policy} { +- lib_start_api +- +- set ret [cmd [format { +- kadm5_create_principal $lib_handle [princ_w_pol "%s" \ +- "%s"] {KADM5_PRINCIPAL KADM5_POLICY} "%s" +- } $name $policy $name]] +- +- return $ret +-} +- +-proc delete_principal {name} { +- lib_start_api +- +- set ret [cmd [format { +- kadm5_delete_principal $lib_handle "%s" +- } $name]] +- +- return $ret +-} +- +-proc delete_policy {name} { +- lib_start_api +- +- set ret [cmd [format {kadm5_delete_policy $lib_handle "%s"} $name]] +- +- return $ret +-} +- +-proc principal_exists {name} { +-# puts stdout "Starting principal_exists." +- +- lib_start_api +- +- set ret [cmd [format { +- kadm5_get_principal $lib_handle "%s" principal \ +- KADM5_PRINCIPAL_NORMAL_MASK +- } $name]] +- +-# puts stdout "Finishing principal_exists." +- +- return $ret +-} +- +-proc policy_exists {name} { +- lib_start_api +- +-# puts stdout "Starting policy_exists." +- +- set ret [cmd [format { +- kadm5_get_policy $lib_handle "%s" policy +- } $name]] +- +-# puts stdout "Finishing policy_exists." +- +- return $ret +-} +- +-proc error_and_restart {error} { +- api_exit +- api_start +- perror $error +-} +- +-proc test {name} { +- global test verbose +- +- set test $name +- if {$verbose >= 1} { +- puts stdout "At $test" +- } +-} +- +-proc begin_dump {} { +- global TOP +- global RPC +- +- if { ! $RPC } { +-# exec $env(SIMPLE_DUMP) > /tmp/dump.before +- } +-} +- +-proc end_dump_compare {name} { +- global file +- global TOP +- global RPC +- +- if { ! $RPC } { +-# set file $TOP/admin/lib/unit-test/diff-files/$name +-# exec $env(SIMPLE_DUMP) > /tmp/dump.after +-# exec $env(COMPARE_DUMP) /tmp/dump.before /tmp/dump.after $file +- } +-} +- +-proc kinit { princ pass {opts ""} } { +- global env; +- global KINIT +- +- eval spawn $KINIT -5 $opts $princ +- expect { +- -re {Password for .*: $} +- {send "$pass\n"} +- timeout {puts "Timeout waiting for prompt" ; close } +- } +- +- # this necessary so close(1) in the child will not sleep waiting for +- # the parent, which is us, to read pending data. +- +- expect { +- "when initializing cache" { perror "kinit failed: $expect_out(buffer)" } +- eof {} +- } +- wait +-} +- +-proc kdestroy {} { +- global KDESTROY +- global errorCode errorInfo +- global env +- +- if {[info exists errorCode]} { +- set saveErrorCode $errorCode +- } +- if {[info exists errorInfo]} { +- set saveErrorInfo $errorInfo +- } +- catch "exec $KDESTROY -5 2>/dev/null" +- if {[info exists saveErrorCode]} { +- set errorCode $saveErrorCode +- } elseif {[info exists errorCode]} { +- unset errorCode +- } +- if {[info exists saveErrorInfo]} { +- set errorInfo $saveErrorInfo +- } elseif {[info exists errorInfo]} { +- unset errorInfo +- } +-} +- +-proc create_principal_with_keysalts {name keysalts} { +- global kadmin_local +- +- spawn $kadmin_local -e "$keysalts" +- expect { +- "kadmin.local:" {} +- default { perror "waiting for kadmin.local prompt"; return 1} +- } +- send "ank -pw \"$name\" \"$name\"\n" +- expect { +- -re "Principal \"$name.*\" created." {} +- "kadmin.local:" { +- perror "expecting principal created message"; +- return 1 +- } +- default { perror "waiting for principal created message"; return 1 } +- } +- expect { +- "kadmin.local:" {} +- default { perror "waiting for kadmin.local prompt"; return 1 } +- } +- close +- wait +- return 0 +-} +- +- +diff --git a/src/lib/kadm5/unit-test/lock-test.c b/src/lib/kadm5/unit-test/lock-test.c +deleted file mode 100644 +index 59f9d2609..000000000 +--- a/src/lib/kadm5/unit-test/lock-test.c ++++ /dev/null +@@ -1,105 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-#include +-#include +-#include +-#include +-#include +- +-char *whoami; +- +-static void usage() +-{ +- fprintf(stderr, +- "Usage: %s {shared|exclusive|permanent|release|" +- "get name|wait} ...\n", whoami); +- exit(1); +-} +- +-int main(int argc, char **argv) +-{ +- krb5_error_code ret; +- osa_policy_ent_t entry; +- krb5_context context; +- kadm5_config_params params; +- krb5_error_code kret; +- +- whoami = argv[0]; +- +- kret = kadm5_init_krb5_context(&context); +- if (kret) { +- com_err(whoami, kret, "while initializing krb5"); +- exit(1); +- } +- +- params.mask = 0; +- ret = kadm5_get_config_params(context, 1, ¶ms, ¶ms); +- if (ret) { +- com_err(whoami, ret, "while retrieving configuration parameters"); +- exit(1); +- } +- if (! (params.mask & KADM5_CONFIG_ADBNAME)) { +- com_err(whoami, KADM5_BAD_SERVER_PARAMS, +- "while retrieving configuration parameters"); +- exit(1); +- } +- +- ret = krb5_db_open( context, NULL, KRB5_KDB_OPEN_RW); +- if (ret) { +- com_err(whoami, ret, "while opening database"); +- exit(1); +- } +- +- argc--; argv++; +- while (argc) { +- if (strcmp(*argv, "shared") == 0) { +- ret = krb5_db_lock(context, KRB5_DB_LOCKMODE_SHARED); +- if (ret) +- com_err(whoami, ret, "while getting shared lock"); +- else +- printf("shared\n"); +- } else if (strcmp(*argv, "exclusive") == 0) { +- ret = krb5_db_lock(context, KRB5_DB_LOCKMODE_EXCLUSIVE ); +- if (ret) +- com_err(whoami, ret, "while getting exclusive lock"); +- else +- printf("exclusive\n"); +- } else if (strcmp(*argv, "permanent") == 0) { +- ret = krb5_db_lock(context, KRB5_DB_LOCKMODE_EXCLUSIVE ); +- if (ret) +- com_err(whoami, ret, "while getting permanent lock"); +- else +- printf("permanent\n"); +- } else if (strcmp(*argv, "release") == 0) { +- ret = krb5_db_unlock(context); +- if (ret) +- com_err(whoami, ret, "while releasing lock"); +- else +- printf("released\n"); +- } else if (strcmp(*argv, "get") == 0) { +- argc--; argv++; +- if (!argc) usage(); +- if ((ret = krb5_db_get_policy(context, *argv, &entry))) { +- com_err(whoami, ret, "while getting policy"); +- } else { +- printf("retrieved\n"); +- krb5_db_free_policy(context, entry); +- } +- } else if (strcmp(*argv, "wait") == 0) { +- getchar(); +- } else { +- fprintf(stderr, "%s: Invalid argument \"%s\"\n", +- whoami, *argv); +- usage(); +- } +- +- argc--; argv++; +- } +- +- ret = krb5_db_fini(context); +- if (ret) { +- com_err(whoami, ret, "while closing database"); +- exit(1); +- } +- +- return 0; +-} +diff --git a/src/lib/kadm5/unit-test/randkey-test.c b/src/lib/kadm5/unit-test/randkey-test.c +deleted file mode 100644 +index dbef88ac8..000000000 +--- a/src/lib/kadm5/unit-test/randkey-test.c ++++ /dev/null +@@ -1,42 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-#include +-#include +-#include +-#include +-#include +-#include +-#include +- +-#define TEST_NUM 1000 +- +-int main() +-{ +- kadm5_ret_t ret; +- krb5_keyblock *keys[TEST_NUM]; +- krb5_principal tprinc; +- krb5_keyblock *newkey; +- krb5_context context; +- void *server_handle; +- +- int x, i; +- +- kadm5_init_krb5_context(&context); +- +- krb5_parse_name(context, "testuser", &tprinc); +- ret = kadm5_init(context, "admin", "admin", KADM5_ADMIN_SERVICE, NULL, +- KADM5_STRUCT_VERSION, KADM5_API_VERSION_4, NULL, +- &server_handle); +- if(ret != KADM5_OK) { +- com_err("test", ret, "init"); +- exit(2); +- } +- for(x = 0; x < TEST_NUM; x++) { +- kadm5_randkey_principal(server_handle, tprinc, &keys[x], NULL); +- for(i = 0; i < x; i++) { +- if (!memcmp(newkey->contents, keys[i]->contents, newkey->length)) +- puts("match found"); +- } +- } +- kadm5_destroy(server_handle); +- exit(0); +-} +diff --git a/src/lib/kadm5/unit-test/setkey-test.c b/src/lib/kadm5/unit-test/setkey-test.c +deleted file mode 100644 +index 8e7df96e9..000000000 +--- a/src/lib/kadm5/unit-test/setkey-test.c ++++ /dev/null +@@ -1,246 +0,0 @@ +-/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ +-#include +-#include +- +-#if HAVE_SRAND48 +-#define RAND() lrand48() +-#define SRAND(a) srand48(a) +-#define RAND_TYPE long +-#elif HAVE_SRAND +-#define RAND() rand() +-#define SRAND(a) srand(a) +-#define RAND_TYPE int +-#elif HAVE_SRANDOM +-#define RAND() random() +-#define SRAND(a) srandom(a) +-#define RAND_TYPE long +-#else /* no random */ +-need a random number generator +-#endif /* no random */ +- +-krb5_keyblock test1[] = { +- {0, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0, 0}, +- {-1}, +-}; +-krb5_keyblock test2[] = { +- {0, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0, 0}, +- {-1}, +-}; +-krb5_keyblock test3[] = { +- {0, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0, 0}, +- {-1}, +-}; +- +-krb5_keyblock *tests[] = { +- test1, test2, test3, NULL +-}; +- +-krb5_data tgtname = { +- 0, +- KRB5_TGS_NAME_SIZE, +- KRB5_TGS_NAME +-}; +- +-krb5_enctype ktypes[] = { 0, 0 }; +- +-extern krb5_kt_ops krb5_ktf_writable_ops; +- +-int +-main(int argc, char **argv) +-{ +- krb5_context context; +- krb5_keytab kt; +- krb5_keytab_entry ktent; +- krb5_encrypt_block eblock; +- krb5_creds my_creds; +- krb5_get_init_creds_opt *opt; +- kadm5_principal_ent_rec princ_ent; +- krb5_principal princ, server; +- char pw[16]; +- char *whoami, *principal, *authprinc, *authpwd; +- krb5_data pwdata; +- void *handle; +- int ret, test, encnum; +- unsigned int i; +- +- whoami = argv[0]; +- +- if (argc < 2 || argc > 4) { +- fprintf(stderr, "Usage: %s principal [authuser] [authpwd]\n", whoami); +- exit(1); +- } +- principal = argv[1]; +- authprinc = (argc > 2) ? argv[2] : argv[0]; +- authpwd = (argc > 3) ? argv[3] : NULL; +- +- /* +- * Setup. Initialize data structures, open keytab, open connection +- * to kadm5 server. +- */ +- +- memset(&context, 0, sizeof(context)); +- kadm5_init_krb5_context(&context); +- +- ret = krb5_parse_name(context, principal, &princ); +- if (ret) { +- com_err(whoami, ret, "while parsing principal name %s", principal); +- exit(1); +- } +- +- if((ret = krb5_build_principal_ext(context, &server, +- krb5_princ_realm(kcontext, princ)->length, +- krb5_princ_realm(kcontext, princ)->data, +- tgtname.length, tgtname.data, +- krb5_princ_realm(kcontext, princ)->length, +- krb5_princ_realm(kcontext, princ)->data, +- 0))) { +- com_err(whoami, ret, "while building server name"); +- exit(1); +- } +- +- ret = krb5_kt_default(context, &kt); +- if (ret) { +- com_err(whoami, ret, "while opening keytab"); +- exit(1); +- } +- +- ret = kadm5_init(context, authprinc, authpwd, KADM5_ADMIN_SERVICE, NULL, +- KADM5_STRUCT_VERSION, KADM5_API_VERSION_4, NULL, +- &handle); +- if (ret) { +- com_err(whoami, ret, "while initializing connection"); +- exit(1); +- } +- +- /* these pw's don't need to be secure, just different every time */ +- SRAND((RAND_TYPE)time((void *) NULL)); +- pwdata.data = pw; +- pwdata.length = sizeof(pw); +- +- /* +- * For each test: +- * +- * For each enctype in the test, construct a random password/key. +- * Assign all keys to principal with kadm5_setkey_principal. Add +- * each key to the keytab, and acquire an initial ticket with the +- * keytab (XXX can I specify the kvno explicitly?). If +- * krb5_get_init_creds_keytab succeeds, then the keys were set +- * successfully. +- */ +- for (test = 0; tests[test] != NULL; test++) { +- krb5_keyblock *testp = tests[test]; +- kadm5_key_data *extracted; +- int n_extracted, match; +- printf("+ Test %d:\n", test); +- +- for (encnum = 0; testp[encnum].magic != -1; encnum++) { +- for (i = 0; i < sizeof(pw); i++) +- pw[i] = (RAND() % 26) + '0'; /* XXX */ +- +- krb5_use_enctype(context, &eblock, testp[encnum].enctype); +- ret = krb5_string_to_key(context, &eblock, &testp[encnum], +- &pwdata, NULL); +- if (ret) { +- com_err(whoami, ret, "while converting string to key"); +- exit(1); +- } +- } +- +- /* now, encnum == # of keyblocks in testp */ +- ret = kadm5_setkey_principal(handle, princ, testp, encnum); +- if (ret) { +- com_err(whoami, ret, "while setting keys"); +- exit(1); +- } +- +- ret = kadm5_get_principal(handle, princ, &princ_ent, KADM5_KVNO); +- if (ret) { +- com_err(whoami, ret, "while retrieving principal"); +- exit(1); +- } +- +- ret = kadm5_get_principal_keys(handle, princ, 0, &extracted, +- &n_extracted); +- if (ret) { +- com_err(whoami, ret, "while extracting keys"); +- exit(1); +- } +- +- for (encnum = 0; testp[encnum].magic != -1; encnum++) { +- printf("+ enctype %d\n", testp[encnum].enctype); +- +- for (match = 0; match < n_extracted; match++) { +- if (extracted[match].key.enctype == testp[encnum].enctype) +- break; +- } +- if (match >= n_extracted) { +- com_err(whoami, KRB5_WRONG_ETYPE, "while matching enctypes"); +- exit(1); +- } +- if (extracted[match].key.length != testp[encnum].length || +- memcmp(extracted[match].key.contents, testp[encnum].contents, +- testp[encnum].length) != 0) { +- com_err(whoami, KRB5_KDB_NO_MATCHING_KEY, "verifying keys"); +- exit(1); +- } +- +- memset(&ktent, 0, sizeof(ktent)); +- ktent.principal = princ; +- ktent.key = testp[encnum]; +- ktent.vno = princ_ent.kvno; +- +- ret = krb5_kt_add_entry(context, kt, &ktent); +- if (ret) { +- com_err(whoami, ret, "while adding keytab entry"); +- exit(1); +- } +- +- memset(&my_creds, 0, sizeof(my_creds)); +- my_creds.client = princ; +- my_creds.server = server; +- +- ktypes[0] = testp[encnum].enctype; +- ret = krb5_get_init_creds_opt_alloc(context, &opt); +- if (ret) { +- com_err(whoami, ret, "while allocating gic opts"); +- exit(1); +- } +- krb5_get_init_creds_opt_set_etype_list(opt, ktypes, 1); +- ret = krb5_get_init_creds_keytab(context, &my_creds, princ, +- kt, 0, NULL /* in_tkt_service */, +- opt); +- krb5_get_init_creds_opt_free(context, opt); +- if (ret) { +- com_err(whoami, ret, "while acquiring initial ticket"); +- exit(1); +- } +- krb5_free_cred_contents(context, &my_creds); +- +- /* since I can't specify enctype explicitly ... */ +- ret = krb5_kt_remove_entry(context, kt, &ktent); +- if (ret) { +- com_err(whoami, ret, "while removing keytab entry"); +- exit(1); +- } +- } +- +- (void)kadm5_free_kadm5_key_data(context, n_extracted, extracted); +- } +- +- ret = krb5_kt_close(context, kt); +- if (ret) { +- com_err(whoami, ret, "while closing keytab"); +- exit(1); +- } +- +- ret = kadm5_destroy(handle); +- if (ret) { +- com_err(whoami, ret, "while closing kadmin connection"); +- exit(1); +- } +- +- krb5_free_principal(context, princ); +- krb5_free_principal(context, server); +- krb5_free_context(context); +- return 0; +-} +diff --git a/src/lib/kadm5/unit-test/site.exp b/src/lib/kadm5/unit-test/site.exp +deleted file mode 100644 +index 7fe397463..000000000 +--- a/src/lib/kadm5/unit-test/site.exp ++++ /dev/null +@@ -1,2 +0,0 @@ +-set tool kadm5_srv_tcl +-set prompt "% " +-- +2.31.1 + diff --git a/Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch b/Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch index 429cf4d..3c90b97 100644 --- a/Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch +++ b/Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch @@ -1,4 +1,4 @@ -From 0a2778833d2f04a29fe9d7122913abe42299044a Mon Sep 17 00:00:00 2001 +From c99ecf1bb49e2fbd0bf30a7b357cf06407b9588a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Sat, 15 May 2021 18:04:58 -0400 Subject: [PATCH] Remove deprecated OpenSSL calls from softpkcs11 @@ -7,16 +7,17 @@ Rewrite add_pubkey_info() in terms of the EVP_PKEY interface. In this process, fix its unchecked allocations and fail fast for non-RSA keys. (cherry picked from commit d6bf42279675100e3e4fe7c6e08eef74d49624cb) +(cherry picked from commit 5072bfdfaddae762680d0f9d97afa6dbf8274760) --- src/configure.ac | 1 + src/tests/softpkcs11/main.c | 106 ++++++++++++++++++++++++------------ 2 files changed, 72 insertions(+), 35 deletions(-) diff --git a/src/configure.ac b/src/configure.ac -index ea708491b..477819091 100644 +index 3e1052db7..eb6307468 100644 --- a/src/configure.ac +++ b/src/configure.ac -@@ -1118,6 +1118,7 @@ int i = 1; +@@ -1114,6 +1114,7 @@ int i = 1; ])], k5_cv_openssl_version_okay=yes, k5_cv_openssl_version_okay=no)]) old_LIBS="$LIBS" AC_CHECK_LIB(crypto, PKCS7_get_signer_info) diff --git a/Use-OpenSSL-s-KBKDF-and-KRB5KDF-for-deriving-long-te.patch b/Use-OpenSSL-s-KBKDF-and-KRB5KDF-for-deriving-long-te.patch new file mode 100644 index 0000000..927b506 --- /dev/null +++ b/Use-OpenSSL-s-KBKDF-and-KRB5KDF-for-deriving-long-te.patch @@ -0,0 +1,482 @@ +From 21e3b9a4463f1d1aeb71de8a27c298f1307d186b Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 4 Oct 2019 14:49:29 -0400 +Subject: [PATCH] Use OpenSSL's KBKDF and KRB5KDF for deriving long-term keys + +If supported, use OpenSSL-provided KBKDF (aes-sha2 and camellia) and +KRB5KDF (3des and aes-sha1). We already use OpenSSL's PBKDF2 where +appropriate. OpenSSL added support for these KDFs in 3.0. + +(cherry picked from commit ef8d11f6fb1232201c9efd2ae2ed567023fb85d2) +[rharwood@redhat.com: 3des removal] +--- + src/lib/crypto/krb/derive.c | 409 ++++++++++++++++++++++++++++-------- + 1 file changed, 324 insertions(+), 85 deletions(-) + +diff --git a/src/lib/crypto/krb/derive.c b/src/lib/crypto/krb/derive.c +index 6707a7308..8e474b38e 100644 +--- a/src/lib/crypto/krb/derive.c ++++ b/src/lib/crypto/krb/derive.c +@@ -27,6 +27,12 @@ + + #include "crypto_int.h" + ++#ifdef HAVE_EVP_KDF_FETCH ++#include ++#include ++#include ++#endif ++ + static krb5_key + find_cached_dkey(struct derived_key *list, const krb5_data *constant) + { +@@ -77,55 +83,251 @@ cleanup: + return ENOMEM; + } + ++#ifdef HAVE_EVP_KDF_FETCH + static krb5_error_code +-derive_random_rfc3961(const struct krb5_enc_provider *enc, +- krb5_key inkey, krb5_data *outrnd, +- const krb5_data *in_constant) ++openssl_kbdkf_counter_hmac(const struct krb5_hash_provider *hash, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *label, const krb5_data *context) + { +- size_t blocksize, keybytes, n; + krb5_error_code ret; +- krb5_data block = empty_data(); ++ EVP_KDF *kdf = NULL; ++ EVP_KDF_CTX *kctx = NULL; ++ OSSL_PARAM params[6]; ++ size_t i = 0; ++ char *digest; + +- blocksize = enc->block_size; +- keybytes = enc->keybytes; ++ /* On NULL hash, preserve default behavior for pbkdf2_string_to_key(). */ ++ if (hash == NULL || !strcmp(hash->hash_name, "SHA1")) { ++ digest = "SHA1"; ++ } else if (!strcmp(hash->hash_name, "SHA-256")) { ++ digest = "SHA256"; ++ } else if (!strcmp(hash->hash_name, "SHA-384")) { ++ digest = "SHA384"; ++ } else { ++ ret = KRB5_CRYPTO_INTERNAL; ++ goto done; ++ } + +- if (blocksize == 1) +- return KRB5_BAD_ENCTYPE; +- if (inkey->keyblock.length != enc->keylength || outrnd->length != keybytes) ++ kdf = EVP_KDF_fetch(NULL, "KBKDF", NULL); ++ if (!kdf) { ++ ret = KRB5_CRYPTO_INTERNAL; ++ goto done; ++ } ++ ++ kctx = EVP_KDF_CTX_new(kdf); ++ if (!kctx) { ++ ret = KRB5_CRYPTO_INTERNAL; ++ goto done; ++ } ++ ++ params[i++] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, ++ digest, 0); ++ params[i++] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MAC, ++ "HMAC", 0); ++ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, ++ inkey->keyblock.contents, ++ inkey->keyblock.length); ++ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO, ++ context->data, ++ context->length); ++ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT, ++ label->data, ++ label->length); ++ params[i] = OSSL_PARAM_construct_end(); ++ if (EVP_KDF_derive(kctx, (unsigned char *)outrnd->data, outrnd->length, ++ params) <= 0) { ++ ret = KRB5_CRYPTO_INTERNAL; ++ goto done; ++ } ++ ++ ret = 0; ++done: ++ if (ret) ++ zap(outrnd->data, outrnd->length); ++ EVP_KDF_free(kdf); ++ EVP_KDF_CTX_free(kctx); ++ return ret; ++} ++ ++static krb5_error_code ++openssl_kbkdf_feedback_cmac(const struct krb5_enc_provider *enc, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *in_constant) ++{ ++ krb5_error_code ret; ++ EVP_KDF *kdf = NULL; ++ EVP_KDF_CTX *kctx = NULL; ++ OSSL_PARAM params[7]; ++ size_t i = 0; ++ char *cipher; ++ static unsigned char zeroes[16]; ++ ++ memset(zeroes, 0, sizeof(zeroes)); ++ ++ if (!memcmp(enc, &krb5int_enc_camellia128, sizeof(*enc))) { ++ cipher = "CAMELLIA-128-CBC"; ++ } else if (!memcmp(enc, &krb5int_enc_camellia256, sizeof(*enc))) { ++ cipher = "CAMELLIA-256-CBC"; ++ } else { ++ ret = KRB5_CRYPTO_INTERNAL; ++ goto done; ++ } ++ ++ kdf = EVP_KDF_fetch(NULL, "KBKDF", NULL); ++ if (!kdf) { ++ ret = KRB5_CRYPTO_INTERNAL; ++ goto done; ++ } ++ ++ kctx = EVP_KDF_CTX_new(kdf); ++ if (!kctx) { ++ ret = KRB5_CRYPTO_INTERNAL; ++ goto done; ++ } ++ ++ params[i++] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MODE, ++ "FEEDBACK", 0); ++ params[i++] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MAC, ++ "CMAC", 0); ++ params[i++] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_CIPHER, ++ cipher, 0); ++ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, ++ inkey->keyblock.contents, ++ inkey->keyblock.length); ++ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT, ++ in_constant->data, ++ in_constant->length); ++ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SEED, ++ zeroes, sizeof(zeroes)); ++ params[i] = OSSL_PARAM_construct_end(); ++ if (EVP_KDF_derive(kctx, (unsigned char *)outrnd->data, outrnd->length, ++ params) <= 0) { ++ ret = KRB5_CRYPTO_INTERNAL; ++ goto done; ++ } ++ ++ ret = 0; ++done: ++ if (ret) ++ zap(outrnd->data, outrnd->length); ++ EVP_KDF_free(kdf); ++ EVP_KDF_CTX_free(kctx); ++ return ret; ++} ++ ++static krb5_error_code ++openssl_krb5kdf(const struct krb5_enc_provider *enc, krb5_key inkey, ++ krb5_data *outrnd, const krb5_data *in_constant) ++{ ++ krb5_error_code ret; ++ EVP_KDF *kdf = NULL; ++ EVP_KDF_CTX *kctx = NULL; ++ OSSL_PARAM params[4]; ++ size_t i = 0; ++ char *cipher; ++ ++ if (inkey->keyblock.length != enc->keylength || ++ outrnd->length != enc->keybytes) { ++ return KRB5_CRYPTO_INTERNAL; ++ } ++ ++ if (!memcmp(enc, &krb5int_enc_aes128, sizeof(*enc))) { ++ cipher = "AES-128-CBC"; ++ } else if (!memcmp(enc, &krb5int_enc_aes256, sizeof(*enc))) { ++ cipher = "AES-256-CBC"; ++ } else { ++ ret = KRB5_CRYPTO_INTERNAL; ++ goto done; ++ } ++ ++ kdf = EVP_KDF_fetch(NULL, "KRB5KDF", NULL); ++ if (kdf == NULL) { ++ ret = KRB5_CRYPTO_INTERNAL; ++ goto done; ++ } ++ ++ kctx = EVP_KDF_CTX_new(kdf); ++ if (kctx == NULL) { ++ ret = KRB5_CRYPTO_INTERNAL; ++ goto done; ++ } ++ ++ params[i++] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_CIPHER, ++ cipher, 0); ++ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, ++ inkey->keyblock.contents, ++ inkey->keyblock.length); ++ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_CONSTANT, ++ in_constant->data, ++ in_constant->length); ++ params[i] = OSSL_PARAM_construct_end(); ++ if (EVP_KDF_derive(kctx, (unsigned char *)outrnd->data, outrnd->length, ++ params) <= 0) { ++ ret = KRB5_CRYPTO_INTERNAL; ++ goto done; ++ } ++ ++ ret = 0; ++done: ++ if (ret) ++ zap(outrnd->data, outrnd->length); ++ EVP_KDF_free(kdf); ++ EVP_KDF_CTX_free(kctx); ++ return ret; ++} ++ ++#else /* HAVE_EVP_KDF_FETCH */ ++ ++/* ++ * NIST SP800-108 KDF in counter mode (section 5.1). ++ * Parameters: ++ * - HMAC (with hash as the hash provider) is the PRF. ++ * - A block counter of four bytes is used. ++ * - Four bytes are used to encode the output length in the PRF input. ++ * ++ * There are no uses requiring more than a single PRF invocation. ++ */ ++static krb5_error_code ++builtin_sp800_108_counter_hmac(const struct krb5_hash_provider *hash, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *label, ++ const krb5_data *context) ++{ ++ krb5_crypto_iov iov[5]; ++ krb5_error_code ret; ++ krb5_data prf; ++ unsigned char ibuf[4], lbuf[4]; ++ ++ if (hash == NULL || outrnd->length > hash->hashsize) + return KRB5_CRYPTO_INTERNAL; + + /* Allocate encryption data buffer. */ +- ret = alloc_data(&block, blocksize); ++ ret = alloc_data(&prf, hash->hashsize); + if (ret) + return ret; + +- /* Initialize the input block. */ +- if (in_constant->length == blocksize) { +- memcpy(block.data, in_constant->data, blocksize); +- } else { +- krb5int_nfold(in_constant->length * 8, +- (unsigned char *) in_constant->data, +- blocksize * 8, (unsigned char *) block.data); +- } ++ /* [i]2: four-byte big-endian binary string giving the block counter (1) */ ++ iov[0].flags = KRB5_CRYPTO_TYPE_DATA; ++ iov[0].data = make_data(ibuf, sizeof(ibuf)); ++ store_32_be(1, ibuf); ++ /* Label */ ++ iov[1].flags = KRB5_CRYPTO_TYPE_DATA; ++ iov[1].data = *label; ++ /* 0x00: separator byte */ ++ iov[2].flags = KRB5_CRYPTO_TYPE_DATA; ++ iov[2].data = make_data("", 1); ++ /* Context */ ++ iov[3].flags = KRB5_CRYPTO_TYPE_DATA; ++ iov[3].data = *context; ++ /* [L]2: four-byte big-endian binary string giving the output length */ ++ iov[4].flags = KRB5_CRYPTO_TYPE_DATA; ++ iov[4].data = make_data(lbuf, sizeof(lbuf)); ++ store_32_be(outrnd->length * 8, lbuf); + +- /* Loop encrypting the blocks until enough key bytes are generated. */ +- n = 0; +- while (n < keybytes) { +- ret = encrypt_block(enc, inkey, &block); +- if (ret) +- goto cleanup; +- +- if ((keybytes - n) <= blocksize) { +- memcpy(outrnd->data + n, block.data, (keybytes - n)); +- break; +- } +- +- memcpy(outrnd->data + n, block.data, blocksize); +- n += blocksize; +- } +- +-cleanup: +- zapfree(block.data, blocksize); ++ ret = krb5int_hmac(hash, inkey, iov, 5, &prf); ++ if (!ret) ++ memcpy(outrnd->data, prf.data, outrnd->length); ++ zapfree(prf.data, prf.length); + return ret; + } + +@@ -139,9 +341,9 @@ cleanup: + * - Four bytes are used to encode the output length in the PRF input. + */ + static krb5_error_code +-derive_random_sp800_108_feedback_cmac(const struct krb5_enc_provider *enc, +- krb5_key inkey, krb5_data *outrnd, +- const krb5_data *in_constant) ++builtin_sp800_108_feedback_cmac(const struct krb5_enc_provider *enc, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *in_constant) + { + size_t blocksize, keybytes, n; + krb5_crypto_iov iov[6]; +@@ -204,56 +406,94 @@ cleanup: + return ret; + } + +-/* +- * NIST SP800-108 KDF in counter mode (section 5.1). +- * Parameters: +- * - HMAC (with hash as the hash provider) is the PRF. +- * - A block counter of four bytes is used. +- * - Four bytes are used to encode the output length in the PRF input. +- * +- * There are no uses requiring more than a single PRF invocation. +- */ ++static krb5_error_code ++builtin_derive_random_rfc3961(const struct krb5_enc_provider *enc, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *in_constant) ++{ ++ size_t blocksize, keybytes, n; ++ krb5_error_code ret; ++ krb5_data block = empty_data(); ++ ++ blocksize = enc->block_size; ++ keybytes = enc->keybytes; ++ ++ if (blocksize == 1) ++ return KRB5_BAD_ENCTYPE; ++ if (inkey->keyblock.length != enc->keylength || outrnd->length != keybytes) ++ return KRB5_CRYPTO_INTERNAL; ++ ++ /* Allocate encryption data buffer. */ ++ ret = alloc_data(&block, blocksize); ++ if (ret) ++ return ret; ++ ++ /* Initialize the input block. */ ++ if (in_constant->length == blocksize) { ++ memcpy(block.data, in_constant->data, blocksize); ++ } else { ++ krb5int_nfold(in_constant->length * 8, ++ (unsigned char *) in_constant->data, ++ blocksize * 8, (unsigned char *) block.data); ++ } ++ ++ /* Loop encrypting the blocks until enough key bytes are generated. */ ++ n = 0; ++ while (n < keybytes) { ++ ret = encrypt_block(enc, inkey, &block); ++ if (ret) ++ goto cleanup; ++ ++ if ((keybytes - n) <= blocksize) { ++ memcpy(outrnd->data + n, block.data, (keybytes - n)); ++ break; ++ } ++ ++ memcpy(outrnd->data + n, block.data, blocksize); ++ n += blocksize; ++ } ++ ++cleanup: ++ zapfree(block.data, blocksize); ++ return ret; ++} ++#endif /* HAVE_EVP_KDF_FETCH */ ++ + krb5_error_code + k5_sp800_108_counter_hmac(const struct krb5_hash_provider *hash, + krb5_key inkey, krb5_data *outrnd, + const krb5_data *label, const krb5_data *context) + { +- krb5_crypto_iov iov[5]; +- krb5_error_code ret; +- krb5_data prf; +- unsigned char ibuf[4], lbuf[4]; ++#ifdef HAVE_EVP_KDF_FETCH ++ return openssl_kbdkf_counter_hmac(hash, inkey, outrnd, label, context); ++#else ++ return builtin_sp800_108_counter_hmac(hash, inkey, outrnd, label, ++ context); ++#endif ++} + +- if (hash == NULL || outrnd->length > hash->hashsize) +- return KRB5_CRYPTO_INTERNAL; ++static krb5_error_code ++sp800_108_feedback_cmac(const struct krb5_enc_provider *enc, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *in_constant) ++{ ++#ifdef HAVE_EVP_KDF_FETCH ++ return openssl_kbkdf_feedback_cmac(enc, inkey, outrnd, in_constant); ++#else ++ return builtin_sp800_108_feedback_cmac(enc, inkey, outrnd, in_constant); ++#endif ++} + +- /* Allocate encryption data buffer. */ +- ret = alloc_data(&prf, hash->hashsize); +- if (ret) +- return ret; +- +- /* [i]2: four-byte big-endian binary string giving the block counter (1) */ +- iov[0].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[0].data = make_data(ibuf, sizeof(ibuf)); +- store_32_be(1, ibuf); +- /* Label */ +- iov[1].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[1].data = *label; +- /* 0x00: separator byte */ +- iov[2].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[2].data = make_data("", 1); +- /* Context */ +- iov[3].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[3].data = *context; +- /* [L]2: four-byte big-endian binary string giving the output length */ +- iov[4].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[4].data = make_data(lbuf, sizeof(lbuf)); +- store_32_be(outrnd->length * 8, lbuf); +- +- ret = krb5int_hmac(hash, inkey, iov, 5, &prf); +- if (!ret) +- memcpy(outrnd->data, prf.data, outrnd->length); +- zapfree(prf.data, prf.length); +- return ret; ++static krb5_error_code ++derive_random_rfc3961(const struct krb5_enc_provider *enc, ++ krb5_key inkey, krb5_data *outrnd, ++ const krb5_data *in_constant) ++{ ++#ifdef HAVE_EVP_KDF_FETCH ++ return openssl_krb5kdf(enc, inkey, outrnd, in_constant); ++#else ++ return builtin_derive_random_rfc3961(enc, inkey, outrnd, in_constant); ++#endif + } + + krb5_error_code +@@ -268,8 +508,7 @@ krb5int_derive_random(const struct krb5_enc_provider *enc, + case DERIVE_RFC3961: + return derive_random_rfc3961(enc, inkey, outrnd, in_constant); + case DERIVE_SP800_108_CMAC: +- return derive_random_sp800_108_feedback_cmac(enc, inkey, outrnd, +- in_constant); ++ return sp800_108_feedback_cmac(enc, inkey, outrnd, in_constant); + case DERIVE_SP800_108_HMAC: + return k5_sp800_108_counter_hmac(hash, inkey, outrnd, in_constant, + &empty); diff --git a/Use-OpenSSL-s-SSKDF-in-PKINIT-when-available.patch b/Use-OpenSSL-s-SSKDF-in-PKINIT-when-available.patch new file mode 100644 index 0000000..0a9cde1 --- /dev/null +++ b/Use-OpenSSL-s-SSKDF-in-PKINIT-when-available.patch @@ -0,0 +1,408 @@ +From 8bbb492f2be1418e1e4bb2cf197414810dac9589 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 20 Sep 2019 17:20:59 -0400 +Subject: [PATCH] Use OpenSSL's SSKDF in PKINIT when available + +Starting in 3.0, OpenSSL implements SSKDF, which is the basis of our +id-pkinit-kdf (RFC 8636). Factor out common setup code around +other_info. Adjust code to comply to existing style. + +(cherry picked from commit 4376a22e41fb639be31daf81275a332d3f930996) +--- + .../preauth/pkinit/pkinit_crypto_openssl.c | 294 +++++++++++------- + 1 file changed, 181 insertions(+), 113 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index e1153344e..350c2118a 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -38,6 +38,12 @@ + #include + #include + ++#ifdef HAVE_EVP_KDF_FETCH ++#include ++#include ++#include ++#endif ++ + static krb5_error_code pkinit_init_pkinit_oids(pkinit_plg_crypto_context ); + static void pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ); + +@@ -2294,15 +2300,16 @@ cleanup: + } + + +-/** ++/* + * Given an algorithm_identifier, this function returns the hash length + * and EVP function associated with that algorithm. ++ * ++ * RFC 8636 defines a SHA384 variant, but we don't use it. + */ + static krb5_error_code +-pkinit_alg_values(krb5_context context, +- const krb5_data *alg_id, +- size_t *hash_bytes, +- const EVP_MD *(**func)(void)) ++pkinit_alg_values(krb5_context context, const krb5_data *alg_id, ++ size_t *hash_bytes, const EVP_MD *(**func)(void), ++ char **hash_name) + { + *hash_bytes = 0; + *func = NULL; +@@ -2311,18 +2318,21 @@ pkinit_alg_values(krb5_context context, + krb5_pkinit_sha1_oid_len))) { + *hash_bytes = 20; + *func = &EVP_sha1; ++ *hash_name = strdup("SHA1"); + return 0; + } else if ((alg_id->length == krb5_pkinit_sha256_oid_len) && + (0 == memcmp(alg_id->data, krb5_pkinit_sha256_oid, + krb5_pkinit_sha256_oid_len))) { + *hash_bytes = 32; + *func = &EVP_sha256; ++ *hash_name = strdup("SHA256"); + return 0; + } else if ((alg_id->length == krb5_pkinit_sha512_oid_len) && + (0 == memcmp(alg_id->data, krb5_pkinit_sha512_oid, + krb5_pkinit_sha512_oid_len))) { + *hash_bytes = 64; + *func = &EVP_sha512; ++ *hash_name = strdup("SHA512"); + return 0; + } else { + krb5_set_error_message(context, KRB5_ERR_BAD_S2K_PARAMS, +@@ -2331,11 +2341,60 @@ pkinit_alg_values(krb5_context context, + } + } /* pkinit_alg_values() */ + ++#ifdef HAVE_EVP_KDF_FETCH ++static krb5_error_code ++openssl_sskdf(krb5_context context, size_t hash_bytes, krb5_data *key, ++ krb5_data *info, char *out, size_t out_len, char *digest) ++{ ++ krb5_error_code ret; ++ EVP_KDF *kdf = NULL; ++ EVP_KDF_CTX *kctx = NULL; ++ OSSL_PARAM params[4]; ++ size_t i = 0; + +-/* pkinit_alg_agility_kdf() -- +- * This function generates a key using the KDF described in +- * draft_ietf_krb_wg_pkinit_alg_agility-04.txt. The algorithm is +- * described as follows: ++ if (digest == NULL) { ++ ret = oerr(context, ENOMEM, ++ _("Failed to allocate space for digest algorithm name")); ++ goto done; ++ } ++ ++ kdf = EVP_KDF_fetch(NULL, "SSKDF", NULL); ++ if (kdf == NULL) { ++ ret = oerr(context, KRB5_CRYPTO_INTERNAL, _("Failed to fetch SSKDF")); ++ goto done; ++ } ++ ++ kctx = EVP_KDF_CTX_new(kdf); ++ if (!kctx) { ++ ret = oerr(context, KRB5_CRYPTO_INTERNAL, ++ _("Failed to instantiate SSKDF")); ++ goto done; ++ } ++ ++ params[i++] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, ++ digest, 0); ++ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, ++ key->data, key->length); ++ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO, ++ info->data, info->length); ++ params[i] = OSSL_PARAM_construct_end(); ++ if (EVP_KDF_derive(kctx, (unsigned char *)out, out_len, params) <= 0) { ++ ret = oerr(context, KRB5_CRYPTO_INTERNAL, ++ _("Failed to derive key using SSKDF")); ++ goto done; ++ } ++ ++ ret = 0; ++done: ++ EVP_KDF_free(kdf); ++ EVP_KDF_CTX_free(kctx); ++ return ret; ++} ++#else ++/* ++ * Generate a key using the KDF described in RFC 8636, also known as SSKDF ++ * (single-step kdf). Our caller precomputes `reps`, but otherwise the ++ * algorithm is as follows: + * + * 1. reps = keydatalen (K) / hash length (H) + * +@@ -2349,95 +2408,16 @@ pkinit_alg_values(krb5_context context, + * + * 4. Set key = Hash1 || Hash2 || ... so that length of key is K bytes. + */ +-krb5_error_code +-pkinit_alg_agility_kdf(krb5_context context, +- krb5_data *secret, +- krb5_data *alg_oid, +- krb5_const_principal party_u_info, +- krb5_const_principal party_v_info, +- krb5_enctype enctype, +- krb5_data *as_req, +- krb5_data *pk_as_rep, +- krb5_keyblock *key_block) ++static krb5_error_code ++builtin_sskdf(krb5_context context, unsigned int reps, size_t hash_len, ++ const EVP_MD *(*EVP_func)(void), krb5_data *secret, ++ krb5_data *other_info, char *out, size_t out_len) + { +- krb5_error_code retval = 0; ++ krb5_error_code ret = 0; + +- unsigned int reps = 0; +- uint32_t counter = 1; /* Does this type work on Windows? */ ++ uint32_t counter = 1; + size_t offset = 0; +- size_t hash_len = 0; +- size_t rand_len = 0; +- size_t key_len = 0; +- krb5_data random_data; +- krb5_sp80056a_other_info other_info_fields; +- krb5_pkinit_supp_pub_info supp_pub_info_fields; +- krb5_data *other_info = NULL; +- krb5_data *supp_pub_info = NULL; +- krb5_algorithm_identifier alg_id; + EVP_MD_CTX *ctx = NULL; +- const EVP_MD *(*EVP_func)(void); +- +- /* initialize random_data here to make clean-up safe */ +- random_data.length = 0; +- random_data.data = NULL; +- +- /* allocate and initialize the key block */ +- key_block->magic = 0; +- key_block->enctype = enctype; +- if (0 != (retval = krb5_c_keylengths(context, enctype, &rand_len, +- &key_len))) +- goto cleanup; +- +- random_data.length = rand_len; +- key_block->length = key_len; +- +- if (NULL == (key_block->contents = malloc(key_block->length))) { +- retval = ENOMEM; +- goto cleanup; +- } +- +- memset (key_block->contents, 0, key_block->length); +- +- /* If this is anonymous pkinit, use the anonymous principle for party_u_info */ +- if (party_u_info && krb5_principal_compare_any_realm(context, party_u_info, +- krb5_anonymous_principal())) +- party_u_info = (krb5_principal)krb5_anonymous_principal(); +- +- if (0 != (retval = pkinit_alg_values(context, alg_oid, &hash_len, &EVP_func))) +- goto cleanup; +- +- /* 1. reps = keydatalen (K) / hash length (H) */ +- reps = key_block->length/hash_len; +- +- /* ... and round up, if necessary */ +- if (key_block->length > (reps * hash_len)) +- reps++; +- +- /* Allocate enough space in the random data buffer to hash directly into +- * it, even if the last hash will make it bigger than the key length. */ +- if (NULL == (random_data.data = malloc(reps * hash_len))) { +- retval = ENOMEM; +- goto cleanup; +- } +- +- /* Encode the ASN.1 octet string for "SuppPubInfo" */ +- supp_pub_info_fields.enctype = enctype; +- supp_pub_info_fields.as_req = *as_req; +- supp_pub_info_fields.pk_as_rep = *pk_as_rep; +- if (0 != ((retval = encode_krb5_pkinit_supp_pub_info(&supp_pub_info_fields, +- &supp_pub_info)))) +- goto cleanup; +- +- /* Now encode the ASN.1 octet string for "OtherInfo" */ +- memset(&alg_id, 0, sizeof alg_id); +- alg_id.algorithm = *alg_oid; /*alias*/ +- +- other_info_fields.algorithm_identifier = alg_id; +- other_info_fields.party_u_info = (krb5_principal) party_u_info; +- other_info_fields.party_v_info = (krb5_principal) party_v_info; +- other_info_fields.supp_pub_info = *supp_pub_info; +- if (0 != (retval = encode_krb5_sp80056a_other_info(&other_info_fields, &other_info))) +- goto cleanup; + + /* 2. Initialize a 32-bit, big-endian bit string counter as 1. + * 3. For i = 1 to reps by 1, do the following: +@@ -2450,7 +2430,7 @@ pkinit_alg_agility_kdf(krb5_context context, + + ctx = EVP_MD_CTX_new(); + if (ctx == NULL) { +- retval = KRB5_CRYPTO_INTERNAL; ++ ret = KRB5_CRYPTO_INTERNAL; + goto cleanup; + } + +@@ -2458,7 +2438,7 @@ pkinit_alg_agility_kdf(krb5_context context, + if (!EVP_DigestInit(ctx, EVP_func())) { + krb5_set_error_message(context, KRB5_CRYPTO_INTERNAL, + "Call to OpenSSL EVP_DigestInit() returned an error."); +- retval = KRB5_CRYPTO_INTERNAL; ++ ret = KRB5_CRYPTO_INTERNAL; + goto cleanup; + } + +@@ -2467,15 +2447,16 @@ pkinit_alg_agility_kdf(krb5_context context, + !EVP_DigestUpdate(ctx, other_info->data, other_info->length)) { + krb5_set_error_message(context, KRB5_CRYPTO_INTERNAL, + "Call to OpenSSL EVP_DigestUpdate() returned an error."); +- retval = KRB5_CRYPTO_INTERNAL; ++ ret = KRB5_CRYPTO_INTERNAL; + goto cleanup; + } + +- /* 4. Set key = Hash1 || Hash2 || ... so that length of key is K bytes. */ +- if (!EVP_DigestFinal(ctx, (uint8_t *)random_data.data + offset, &s)) { ++ /* 4. Set key = Hash1 || Hash2 || ... so that length of key is K ++ * bytes. */ ++ if (!EVP_DigestFinal(ctx, (unsigned char *)out + offset, &s)) { + krb5_set_error_message(context, KRB5_CRYPTO_INTERNAL, + "Call to OpenSSL EVP_DigestUpdate() returned an error."); +- retval = KRB5_CRYPTO_INTERNAL; ++ ret = KRB5_CRYPTO_INTERNAL; + goto cleanup; + } + offset += s; +@@ -2484,26 +2465,113 @@ pkinit_alg_agility_kdf(krb5_context context, + EVP_MD_CTX_free(ctx); + ctx = NULL; + } +- +- retval = krb5_c_random_to_key(context, enctype, &random_data, +- key_block); +- + cleanup: + EVP_MD_CTX_free(ctx); ++ return ret; ++} /* builtin_sskdf() */ ++#endif /* HAVE_EVP_KDF_FETCH */ + +- /* If this has been an error, free the allocated key_block, if any */ +- if (retval) { +- krb5_free_keyblock_contents(context, key_block); ++/* id-pkinit-kdf family, as specified by RFC 8636. */ ++krb5_error_code ++pkinit_alg_agility_kdf(krb5_context context, krb5_data *secret, ++ krb5_data *alg_oid, krb5_const_principal party_u_info, ++ krb5_const_principal party_v_info, ++ krb5_enctype enctype, krb5_data *as_req, ++ krb5_data *pk_as_rep, krb5_keyblock *key_block) ++{ ++ krb5_error_code ret; ++ size_t hash_len = 0, rand_len = 0, key_len = 0; ++ const EVP_MD *(*EVP_func)(void); ++ krb5_sp80056a_other_info other_info_fields; ++ krb5_pkinit_supp_pub_info supp_pub_info_fields; ++ krb5_data *other_info = NULL, *supp_pub_info = NULL; ++ krb5_data random_data = empty_data(); ++ krb5_algorithm_identifier alg_id; ++ unsigned int reps; ++ char *hash_name = NULL; ++ ++ /* Allocate and initialize the key block. */ ++ key_block->magic = 0; ++ key_block->enctype = enctype; ++ ++ /* Use separate variables to avoid alignment restriction problems. */ ++ ret = krb5_c_keylengths(context, enctype, &rand_len, &key_len); ++ if (ret) ++ goto cleanup; ++ random_data.length = rand_len; ++ key_block->length = key_len; ++ ++ key_block->contents = k5calloc(key_block->length, 1, &ret); ++ if (key_block->contents == NULL) ++ goto cleanup; ++ ++ /* If this is anonymous pkinit, use the anonymous principle for ++ * party_u_info. */ ++ if (party_u_info && ++ krb5_principal_compare_any_realm(context, party_u_info, ++ krb5_anonymous_principal())) { ++ party_u_info = (krb5_principal)krb5_anonymous_principal(); + } + +- /* free other allocated resources, either way */ +- if (random_data.data) +- free(random_data.data); ++ ret = pkinit_alg_values(context, alg_oid, &hash_len, &EVP_func, ++ &hash_name); ++ if (ret) ++ goto cleanup; ++ ++ /* 1. reps = keydatalen (K) / hash length (H) */ ++ reps = key_block->length / hash_len; ++ ++ /* ... and round up, if necessary. */ ++ if (key_block->length > (reps * hash_len)) ++ reps++; ++ ++ /* Allocate enough space in the random data buffer to hash directly into ++ * it, even if the last hash will make it bigger than the key length. */ ++ random_data.data = k5alloc(reps * hash_len, &ret); ++ if (random_data.data == NULL) ++ goto cleanup; ++ ++ /* Encode the ASN.1 octet string for "SuppPubInfo". */ ++ supp_pub_info_fields.enctype = enctype; ++ supp_pub_info_fields.as_req = *as_req; ++ supp_pub_info_fields.pk_as_rep = *pk_as_rep; ++ ret = encode_krb5_pkinit_supp_pub_info(&supp_pub_info_fields, ++ &supp_pub_info); ++ if (ret) ++ goto cleanup; ++ ++ /* Now encode the ASN.1 octet string for "OtherInfo". */ ++ memset(&alg_id, 0, sizeof(alg_id)); ++ alg_id.algorithm = *alg_oid; ++ other_info_fields.algorithm_identifier = alg_id; ++ other_info_fields.party_u_info = (krb5_principal)party_u_info; ++ other_info_fields.party_v_info = (krb5_principal)party_v_info; ++ other_info_fields.supp_pub_info = *supp_pub_info; ++ ret = encode_krb5_sp80056a_other_info(&other_info_fields, &other_info); ++ if (ret) ++ goto cleanup; ++ ++#ifdef HAVE_EVP_KDF_FETCH ++ ret = openssl_sskdf(context, hash_len, secret, other_info, ++ random_data.data, key_block->length, hash_name); ++#else ++ ret = builtin_sskdf(context, reps, hash_len, EVP_func, secret, ++ other_info, random_data.data, key_block->length); ++#endif ++ if (ret) ++ goto cleanup; ++ ++ ret = krb5_c_random_to_key(context, enctype, &random_data, key_block); ++cleanup: ++ if (ret) ++ krb5_free_keyblock_contents(context, key_block); ++ ++ free(hash_name); ++ zapfree(random_data.data, random_data.length); + krb5_free_data(context, other_info); + krb5_free_data(context, supp_pub_info); +- +- return retval; +-} /*pkinit_alg_agility_kdf() */ ++ return ret; ++} + + /* Call DH_compute_key() and ensure that we left-pad short results instead of + * leaving junk bytes at the end of the buffer. */ diff --git a/downstream-Remove-3des-support.patch b/downstream-Remove-3des-support.patch index 9c29cdd..3d351eb 100644 --- a/downstream-Remove-3des-support.patch +++ b/downstream-Remove-3des-support.patch @@ -9,6 +9,12 @@ to user other enctypes. Mark the 3DES enctypes UNSUPPORTED and retain their constants. Last-updated: 1.19-beta1 +[antorres@redhat.com: remove diffs for: + - src/kdamin/testing/proto/kdc.conf.proto + - src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp + - src/lib/kadm5/unit-test/api.current/get-principal-v2.exp + - src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp + since they were removed by Remove-TCL-based-libkadm5-API-tests.patch] --- doc/admin/advanced/retiring-des.rst | 11 + doc/admin/conf_files/kdc_conf.rst | 7 +- @@ -350,19 +356,6 @@ index db80063eb..63e67a2ba 100644 #define CKSUMTYPE_HMAC_SHA1_96_AES128 0x000f /**< RFC 3962. Used with ENCTYPE_AES128_CTS_HMAC_SHA1_96 */ #define CKSUMTYPE_HMAC_SHA1_96_AES256 0x0010 /**< RFC 3962. Used with -diff --git a/src/kadmin/testing/proto/kdc.conf.proto b/src/kadmin/testing/proto/kdc.conf.proto -index 8a4b87de1..d7f1d076b 100644 ---- a/src/kadmin/testing/proto/kdc.conf.proto -+++ b/src/kadmin/testing/proto/kdc.conf.proto -@@ -11,6 +11,6 @@ - dict_file = __K5ROOT__/ovsec_adm.dict - kadmind_port = 1751 - kpasswd_port = 1752 -- master_key_type = des3-hmac-sha1 -- supported_enctypes = des3-hmac-sha1:normal aes256-cts:normal aes128-cts:normal aes256-sha2:normal aes128-sha2:normal -+ master_key_type = aes256-cts -+ supported_enctypes = aes256-cts:normal aes128-cts:normal aes256-sha2:normal aes128-sha2:normal - } diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c index 60f30c4f4..c65375aef 100644 --- a/src/kdc/kdc_util.c @@ -5575,55 +5568,6 @@ index 84f194988..32150f5e3 100644 case ENCTYPE_ARCFOUR_HMAC: case ENCTYPE_ARCFOUR_HMAC_EXP: /* RFC 4121 accidentally omits RC4-HMAC-EXP as a "not-newer" enctype, -diff --git a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp -index 740425c69..6b45f5f72 100644 ---- a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp -+++ b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp -@@ -53,10 +53,10 @@ proc test200 {} { - } - - # XXX Perhaps I should actually check the key type returned. -- if {$num_keys == 5} { -+ if {$num_keys == 4} { - pass "$test" - } else { -- fail "$test: $num_keys keys, should be 5" -+ fail "$test: $num_keys keys, should be 4" - } - if { ! [cmd {kadm5_destroy $server_handle}]} { - perror "$test: unexpected failure in destroy" -diff --git a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp -index 3ea1ba29b..d2c6d1afa 100644 ---- a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp -+++ b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp -@@ -143,8 +143,8 @@ proc test101_102 {rpc} { - } - - set failed 0 -- if {$num_keys != 5} { -- fail "$test: num_keys $num_keys should be 5" -+ if {$num_keys != 4} { -+ fail "$test: num_keys $num_keys should be 4" - set failed 1 - } - for {set i 0} {$i < $num_keys} {incr i} { -diff --git a/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp -index 2925c1c43..2f76c8b43 100644 ---- a/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp -+++ b/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp -@@ -46,10 +46,10 @@ proc test100 {} { - } - - # XXX Perhaps I should actually check the key type returned. -- if {$num_keys == 5} { -+ if {$num_keys == 4} { - pass "$test" - } else { -- fail "$test: $num_keys keys, should be 5" -+ fail "$test: $num_keys keys, should be 4" - } - if { ! [cmd {kadm5_destroy $server_handle}]} { - perror "$test: unexpected failure in destroy" diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c index aa35baa3c..bfa99d9eb 100644 --- a/src/lib/krb5/krb/init_ctx.c diff --git a/krb5.spec b/krb5.spec index 82c7d8a..41b4341 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}3%{?dist}.1 +Release: %{?zdpd}4%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -68,7 +68,6 @@ Patch1: downstream-SELinux-integration.patch Patch3: downstream-netlib-and-dns.patch Patch4: downstream-fix-debuginfo-with-y.tab.c.patch Patch5: downstream-Remove-3des-support.patch -Patch6: downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch Patch8: Add-APIs-for-marshalling-credentials.patch Patch9: Add-hostname-canonicalization-helper-to-k5test.py.patch @@ -90,6 +89,11 @@ Patch25: Clean-up-context-after-failed-open-in-libkdb5.patch Patch26: Use-asan-in-one-of-the-CI-builds.patch Patch29: Clean-up-gssapi_krb5-ccache-name-functions.patch Patch30: Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch +Patch32: Add-buildsystem-detection-of-the-OpenSSL-3-KDF-inter.patch +Patch33: Use-OpenSSL-s-SSKDF-in-PKINIT-when-available.patch +Patch34: Use-OpenSSL-s-KBKDF-and-KRB5KDF-for-deriving-long-te.patch +Patch35: Handle-OpenSSL-3-s-providers.patch +Patch36: Remove-TCL-based-libkadm5-API-tests.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -118,11 +122,11 @@ BuildRequires: net-tools, rpcbind BuildRequires: hostname BuildRequires: iproute BuildRequires: python3-pyrad +BuildRequires: procps-ng %endif -# Need KDFs. This is the backported version -BuildRequires: openssl-devel >= 1:1.1.1d-4 -BuildRequires: openssl-devel < 1:3.0.0 +# Need KDFs. This is the "real" version +BuildRequires: openssl-devel => 1:3.0.0 %description Kerberos V5 is a trusted-third-party network authentication system, @@ -148,7 +152,7 @@ to install this package. %package libs Summary: The non-admin shared libraries used by Kerberos 5 -Requires: openssl-libs >= 1:1.1.1d-4 +Requires: openssl-libs >= 1:3.0.0 Requires: coreutils, gawk, grep, sed Requires: keyutils-libs >= 1.5.8 Requires: /etc/crypto-policies/back-ends/krb5.config @@ -248,10 +252,7 @@ popd # Mess with some of the default ports that we use for testing, so that multiple # builds going on the same host don't step on each other. -cfg="src/kadmin/testing/proto/kdc.conf.proto \ - src/kadmin/testing/proto/krb5.conf.proto \ - src/lib/kadm5/unit-test/api.current/init-v2.exp \ - src/util/k5test.py" +cfg="src/util/k5test.py" LONG_BIT=`getconf LONG_BIT` PORT=`expr 61000 + $LONG_BIT - 48` sed -i -e s,61000,`expr "$PORT" + 0`,g $cfg @@ -647,6 +648,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Fri Dec 3 2021 Antonio Torres - 1.19.2-4 +- Add patches to support OpenSLL 3.0.0 +- Remove TCL-based libkadm5 API tests + * Tue Sep 14 2021 Sahana Prasad - 1.19.2-3.1 - Rebuilt with OpenSSL 3.0.0 From 75355e197a5a2e2981b3e65f3c4dab6e36e626e3 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 20 Jan 2022 15:08:32 +0000 Subject: [PATCH 252/304] - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 41b4341..8eb3e03 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}4%{?dist} +Release: %{?zdpd}4%{?dist}.1 # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -648,6 +648,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jan 20 2022 Fedora Release Engineering - 1.19.2-4.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + * Fri Dec 3 2021 Antonio Torres - 1.19.2-4 - Add patches to support OpenSLL 3.0.0 - Remove TCL-based libkadm5 API tests From b998554176f38ed9aefe1cd8b7fe2f4225b01171 Mon Sep 17 00:00:00 2001 From: Alexander Bokovoy Date: Thu, 3 Feb 2022 12:27:25 +0200 Subject: [PATCH 253/304] Temporarily remove package note to unblock krb5-dependent packages Resolves: rhbz#2048909 Signed-off-by: Alexander Bokovoy --- krb5.spec | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 8eb3e03..4d595fb 100644 --- a/krb5.spec +++ b/krb5.spec @@ -1,3 +1,8 @@ +# Force to not include the package note file +# the non-existing package note file is pulled into krb5-config +# and breaks any application that is using krb5 development libs +%undefine _package_note_file + %bcond_without check %if %{without check} %global skipcheck 1 @@ -42,7 +47,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}4%{?dist}.1 +Release: %{?zdpd}5%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -648,6 +653,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Feb 02 2022 Alexander Bokovoy - 1.19.2-5 +- Temporarily remove package note to unblock krb5-dependent packages +- Resolves: rhbz#2048909 + * Thu Jan 20 2022 Fedora Release Engineering - 1.19.2-4.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild From f858c7e550077b9183045cbaf36fdef2a3c2fa97 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= Date: Thu, 9 Sep 2021 22:10:28 +0200 Subject: [PATCH 254/304] Drop old trigger scriptlet 1.15.1 was ~2017, so there is no need to support upgrades from such old systemd. This allows the dependency on grep to be dropped. grep pulls in pcre, but most other programs in the core group depend on the newer pcre2, so it's nicer to avoid pulling in pcre in minimal installations. --- krb5.spec | 13 +++++-------- 1 file changed, 5 insertions(+), 8 deletions(-) diff --git a/krb5.spec b/krb5.spec index 4d595fb..8ccc583 100644 --- a/krb5.spec +++ b/krb5.spec @@ -47,7 +47,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}5%{?dist} +Release: %{?zdpd}6%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -158,7 +158,7 @@ to install this package. %package libs Summary: The non-admin shared libraries used by Kerberos 5 Requires: openssl-libs >= 1:3.0.0 -Requires: coreutils, gawk, grep, sed +Requires: coreutils, gawk, sed Requires: keyutils-libs >= 1.5.8 Requires: /etc/crypto-policies/back-ends/krb5.config @@ -465,12 +465,6 @@ rm -- "$RPM_BUILD_ROOT/%{_libdir}/krb5/plugins/preauth/test.so" %ldconfig_scriptlets libs -%triggerun libs -- krb5-libs < 1.15.1-5 -if ! grep -q 'includedir /etc/krb5.conf.d' /etc/krb5.conf ; then - sed -i '1i # To opt out of the system crypto-policies configuration of krb5, remove the\n# symlink at /etc/krb5.conf.d/crypto-policies which will not be recreated.\nincludedir /etc/krb5.conf.d/\n' /etc/krb5.conf -fi -exit 0 - %ldconfig_scriptlets server-ldap %post server @@ -653,6 +647,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Feb 8 2022 Zbigniew Jędrzejewski-Szmek - 1.19.2-6 +- Drop old trigger scriplet + * Wed Feb 02 2022 Alexander Bokovoy - 1.19.2-5 - Temporarily remove package note to unblock krb5-dependent packages - Resolves: rhbz#2048909 From 970430cbffb6170964d18fc96dee98d787f6ea49 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= Date: Tue, 8 Feb 2022 14:15:30 +0100 Subject: [PATCH 255/304] Drop link flags from krb5-config Introspecing krb5-config shows that all of the flags in LDFLAGS= are inappropriate for export, so just drop them all. --- krb5.spec | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/krb5.spec b/krb5.spec index 8ccc583..62d3292 100644 --- a/krb5.spec +++ b/krb5.spec @@ -1,8 +1,3 @@ -# Force to not include the package note file -# the non-existing package note file is pulled into krb5-config -# and breaks any application that is using krb5 development libs -%undefine _package_note_file - %bcond_without check %if %{without check} %global skipcheck 1 @@ -436,7 +431,8 @@ sed -r -i -e 's|^libdir=/usr/lib(64)?$|libdir=/usr/lib|g' $RPM_BUILD_ROOT%{_bind # Workaround krb5-config reading too much from LDFLAGS. # https://bugzilla.redhat.com/show_bug.cgi?id=1997021 -sed -i -e "s/-specs=[^ ]*//g" $RPM_BUILD_ROOT%{_bindir}/krb5-config +# https://bugzilla.redhat.com/show_bug.cgi?id=2048909 +sed -i -r -e 's/^(LDFLAGS=).*/\1/' $RPM_BUILD_ROOT%{_bindir}/krb5-config # Install processed man pages. for section in 1 5 8 ; do @@ -649,6 +645,7 @@ exit 0 %changelog * Tue Feb 8 2022 Zbigniew Jędrzejewski-Szmek - 1.19.2-6 - Drop old trigger scriplet +- Reenable package notes and strip LDFLAGS from krb5-config (rhbz#2048909) * Wed Feb 02 2022 Alexander Bokovoy - 1.19.2-5 - Temporarily remove package note to unblock krb5-dependent packages From 2ef37ab30d679328b361422aa40ec32f1fc138d3 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 23 Mar 2022 11:30:21 +0100 Subject: [PATCH 256/304] Use SHA-256 instead of SHA-1 for PKINIT CMS digest CMS digest and signature algorithm for the anonymous PKINIT is changed from SHA-1 to SHA-256. SHA-1 hasn't been considered secure anymore for this kind of purposes for some years already. Resolves: rhbz#2067121 Signed-off-by: Julien Rische --- ...nstead-of-SHA1-for-PKINIT-CMS-digest.patch | 113 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 118 insertions(+), 1 deletion(-) create mode 100644 Use-SHA256-instead-of-SHA1-for-PKINIT-CMS-digest.patch diff --git a/Use-SHA256-instead-of-SHA1-for-PKINIT-CMS-digest.patch b/Use-SHA256-instead-of-SHA1-for-PKINIT-CMS-digest.patch new file mode 100644 index 0000000..ace4da9 --- /dev/null +++ b/Use-SHA256-instead-of-SHA1-for-PKINIT-CMS-digest.patch @@ -0,0 +1,113 @@ +From 538be893707e2306e89f5e5ca92c0db0ee305e3e Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Fri, 11 Mar 2022 11:33:56 +0100 +Subject: [PATCH] Use SHA-256 instead of SHA-1 for PKINIT CMS digest + +Various organizations including NIST have been strongly recommending to +stop using SHA-1 for digital signatures for some years already. CMS +digest is used to generate such signatures, hence it should be upgraded +to use SHA-256. +--- + .../preauth/pkinit/pkinit_crypto_openssl.c | 27 ++++++++++--------- + 1 file changed, 14 insertions(+), 13 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 42e5c581d..2a6ef4aaa 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -1240,7 +1240,7 @@ cms_signeddata_create(krb5_context context, + /* will not fill-out EVP_PKEY because it's on the smartcard */ + + /* Set digest algs */ +- p7si->digest_alg->algorithm = OBJ_nid2obj(NID_sha1); ++ p7si->digest_alg->algorithm = OBJ_nid2obj(NID_sha256); + + if (p7si->digest_alg->parameter != NULL) + ASN1_TYPE_free(p7si->digest_alg->parameter); +@@ -1251,17 +1251,17 @@ cms_signeddata_create(krb5_context context, + /* Set sig algs */ + if (p7si->digest_enc_alg->parameter != NULL) + ASN1_TYPE_free(p7si->digest_enc_alg->parameter); +- p7si->digest_enc_alg->algorithm = OBJ_nid2obj(NID_sha1WithRSAEncryption); ++ p7si->digest_enc_alg->algorithm = OBJ_nid2obj(NID_sha256WithRSAEncryption); + if (!(p7si->digest_enc_alg->parameter = ASN1_TYPE_new())) + goto cleanup; + p7si->digest_enc_alg->parameter->type = V_ASN1_NULL; + + /* add signed attributes */ +- /* compute sha1 digest over the EncapsulatedContentInfo */ ++ /* compute sha256 digest over the EncapsulatedContentInfo */ + ctx = EVP_MD_CTX_new(); + if (ctx == NULL) + goto cleanup; +- EVP_DigestInit_ex(ctx, EVP_sha1(), NULL); ++ EVP_DigestInit_ex(ctx, EVP_sha256(), NULL); + EVP_DigestUpdate(ctx, data, data_len); + md_tmp = EVP_MD_CTX_md(ctx); + EVP_DigestFinal_ex(ctx, md_data, &md_len); +@@ -1289,9 +1289,10 @@ cms_signeddata_create(krb5_context context, + goto cleanup2; + + #ifndef WITHOUT_PKCS11 +- /* Some tokens can only do RSAEncryption without sha1 hash */ +- /* to compute sha1WithRSAEncryption, encode the algorithm ID for the hash +- * function and the hash value into an ASN.1 value of type DigestInfo ++ /* Some tokens can only do RSAEncryption without sha256 hash */ ++ /* to compute sha256WithRSAEncryption, encode the algorithm ID for the ++ * hash function and the hash value into an ASN.1 value of type ++ * DigestInfo + * DigestInfo::=SEQUENCE { + * digestAlgorithm AlgorithmIdentifier, + * digest OCTET STRING } +@@ -1310,7 +1311,7 @@ cms_signeddata_create(krb5_context context, + alg = X509_ALGOR_new(); + if (alg == NULL) + goto cleanup2; +- X509_ALGOR_set0(alg, OBJ_nid2obj(NID_sha1), V_ASN1_NULL, NULL); ++ X509_ALGOR_set0(alg, OBJ_nid2obj(NID_sha256), V_ASN1_NULL, NULL); + alg_len = i2d_X509_ALGOR(alg, NULL); + + digest = ASN1_OCTET_STRING_new(); +@@ -1339,7 +1340,7 @@ cms_signeddata_create(krb5_context context, + #endif + { + pkiDebug("mech = %s\n", +- id_cryptoctx->pkcs11_method == 1 ? "CKM_SHA1_RSA_PKCS" : "FS"); ++ id_cryptoctx->pkcs11_method == 1 ? "CKM_SHA256_RSA_PKCS" : "FS"); + retval = pkinit_sign_data(context, id_cryptoctx, abuf, alen, + &sig, &sig_len); + } +@@ -4189,7 +4190,7 @@ create_signature(unsigned char **sig, unsigned int *sig_len, + ctx = EVP_MD_CTX_new(); + if (ctx == NULL) + return ENOMEM; +- EVP_SignInit(ctx, EVP_sha1()); ++ EVP_SignInit(ctx, EVP_sha256()); + EVP_SignUpdate(ctx, data, data_len); + *sig_len = EVP_PKEY_size(pkey); + if ((*sig = malloc(*sig_len)) == NULL) +@@ -4663,10 +4664,10 @@ pkinit_get_certs_pkcs11(krb5_context context, + + #ifndef PKINIT_USE_MECH_LIST + /* +- * We'd like to use CKM_SHA1_RSA_PKCS for signing if it's available, but ++ * We'd like to use CKM_SHA256_RSA_PKCS for signing if it's available, but + * many cards seems to be confused about whether they are capable of + * this or not. The safe thing seems to be to ignore the mechanism list, +- * always use CKM_RSA_PKCS and calculate the sha1 digest ourselves. ++ * always use CKM_RSA_PKCS and calculate the sha256 digest ourselves. + */ + + id_cryptoctx->mech = CKM_RSA_PKCS; +@@ -4694,7 +4695,7 @@ pkinit_get_certs_pkcs11(krb5_context context, + if (mechp[i] == CKM_RSA_PKCS) { + /* This seems backwards... */ + id_cryptoctx->mech = +- (info.flags & CKF_SIGN) ? CKM_SHA1_RSA_PKCS : CKM_RSA_PKCS; ++ (info.flags & CKF_SIGN) ? CKM_SHA256_RSA_PKCS : CKM_RSA_PKCS; + } + } + free(mechp); +-- +2.35.1 + diff --git a/krb5.spec b/krb5.spec index 62d3292..4fd6248 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}6%{?dist} +Release: %{?zdpd}7%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -94,6 +94,7 @@ Patch33: Use-OpenSSL-s-SSKDF-in-PKINIT-when-available.patch Patch34: Use-OpenSSL-s-KBKDF-and-KRB5KDF-for-deriving-long-te.patch Patch35: Handle-OpenSSL-3-s-providers.patch Patch36: Remove-TCL-based-libkadm5-API-tests.patch +Patch37: Use-SHA256-instead-of-SHA1-for-PKINIT-CMS-digest.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -643,6 +644,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Mar 23 2022 Julien Rische - 1.19.2-7 +- Use SHA-256 instead of SHA-1 for PKINIT CMS digest + * Tue Feb 8 2022 Zbigniew Jędrzejewski-Szmek - 1.19.2-6 - Drop old trigger scriplet - Reenable package notes and strip LDFLAGS from krb5-config (rhbz#2048909) From 0ceb166d962e91314715d1167af9584f90020504 Mon Sep 17 00:00:00 2001 From: Alexander Bokovoy Date: Tue, 5 Apr 2022 16:50:01 +0300 Subject: [PATCH 257/304] Allow use of larger RADIUS attributes in krad library In kr_attrset_decode(), explicitly treat the length byte as unsigned. Otherwise attributes longer than 125 characters will be rejected with EBADMSG. Add a 253-character-long NAS-Identifier attribute to the tests to make sure that attributes with the maximal number of characters are working as expected. [ghudson@mit.edu: used uint8_t cast per current practices; edited commit message] ticket: 9036 (new) From upstream, needed in preparation for OAuth2 support for FreeIPA and SSSD. Signed-off-by: Alexander Bokovoy --- krb5-krad-larger-attrs.patch | 69 ++++++++++++++++++++++++++++++++++++ krb5.spec | 6 +++- 2 files changed, 74 insertions(+), 1 deletion(-) create mode 100644 krb5-krad-larger-attrs.patch diff --git a/krb5-krad-larger-attrs.patch b/krb5-krad-larger-attrs.patch new file mode 100644 index 0000000..32111ec --- /dev/null +++ b/krb5-krad-larger-attrs.patch @@ -0,0 +1,69 @@ +From f35077bfc570205092eca2a9d44e50ce265622f4 Mon Sep 17 00:00:00 2001 +From: Sumit Bose +Date: Mon, 8 Nov 2021 17:48:50 +0100 +Subject: [PATCH] Support larger RADIUS attributes in libkrad + +In kr_attrset_decode(), explicitly treat the length byte as unsigned. +Otherwise attributes longer than 125 characters will be rejected with +EBADMSG. + +Add a 253-character-long NAS-Identifier attribute to the tests to make +sure that attributes with the maximal number of characters are working +as expected. + +[ghudson@mit.edu: used uint8_t cast per current practices; edited +commit message] + +ticket: 9036 (new) +--- + src/lib/krad/attrset.c | 2 +- + src/lib/krad/t_packet.c | 13 +++++++++++++ + 2 files changed, 14 insertions(+), 1 deletion(-) + +diff --git a/src/lib/krad/attrset.c b/src/lib/krad/attrset.c +index 03c613716..f309f1581 100644 +--- a/src/lib/krad/attrset.c ++++ b/src/lib/krad/attrset.c +@@ -217,7 +217,7 @@ kr_attrset_decode(krb5_context ctx, const krb5_data *in, const char *secret, + + for (i = 0; i + 2 < in->length; ) { + type = in->data[i++]; +- tmp = make_data(&in->data[i + 1], in->data[i] - 2); ++ tmp = make_data(&in->data[i + 1], (uint8_t)in->data[i] - 2); + i += tmp.length + 1; + + retval = (in->length < i) ? EBADMSG : 0; +diff --git a/src/lib/krad/t_packet.c b/src/lib/krad/t_packet.c +index 0a92e9cc2..c22489144 100644 +--- a/src/lib/krad/t_packet.c ++++ b/src/lib/krad/t_packet.c +@@ -57,6 +57,14 @@ make_packet(krb5_context ctx, const krb5_data *username, + krb5_error_code retval; + const krb5_data *data; + int i = 0; ++ krb5_data nas_id; ++ ++ nas_id = string2data("12345678901234567890123456789012345678901234567890" ++ "12345678901234567890123456789012345678901234567890" ++ "12345678901234567890123456789012345678901234567890" ++ "12345678901234567890123456789012345678901234567890" ++ "12345678901234567890123456789012345678901234567890" ++ "123"); + + retval = krad_attrset_new(ctx, &set); + if (retval != 0) +@@ -71,6 +79,11 @@ make_packet(krb5_context ctx, const krb5_data *username, + if (retval != 0) + goto out; + ++ retval = krad_attrset_add(set, krad_attr_name2num("NAS-Identifier"), ++ &nas_id); ++ if (retval != 0) ++ goto out; ++ + retval = krad_packet_new_request(ctx, "foo", + krad_code_name2num("Access-Request"), + set, iterator, &i, &tmp); +-- +2.35.1 + diff --git a/krb5.spec b/krb5.spec index 4fd6248..cdd5f26 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}7%{?dist} +Release: %{?zdpd}8{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -95,6 +95,7 @@ Patch34: Use-OpenSSL-s-KBKDF-and-KRB5KDF-for-deriving-long-te.patch Patch35: Handle-OpenSSL-3-s-providers.patch Patch36: Remove-TCL-based-libkadm5-API-tests.patch Patch37: Use-SHA256-instead-of-SHA1-for-PKINIT-CMS-digest.patch +Patch38: krb5-krad-larger-attrs.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -644,6 +645,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Apr 05 2022 Alexander Bokovoy - 1.19.2-8 +- Allow use of larger RADIUS attributes in krad library + * Wed Mar 23 2022 Julien Rische - 1.19.2-7 - Use SHA-256 instead of SHA-1 for PKINIT CMS digest From 29a69aee06f339b74f9e1ffcb424b8766f54e8d0 Mon Sep 17 00:00:00 2001 From: Alexander Bokovoy Date: Tue, 5 Apr 2022 16:52:33 +0300 Subject: [PATCH 258/304] fix dist macro --- krb5.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index cdd5f26..b54534c 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}8{?dist} +Release: %{?zdpd}8%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz From fc958d47737fba99e4187562ac0ce2d445845798 Mon Sep 17 00:00:00 2001 From: Alexander Bokovoy Date: Tue, 5 Apr 2022 22:14:44 +0300 Subject: [PATCH 259/304] Fix libkrad client cleanup code Resolves: rhbz#2072059 Signed-off-by: Alexander Bokovoy --- krb5-krad-remote.patch | 209 +++++++++++++++++++++++++++++++++++++++++ krb5.spec | 9 +- 2 files changed, 216 insertions(+), 2 deletions(-) create mode 100644 krb5-krad-remote.patch diff --git a/krb5-krad-remote.patch b/krb5-krad-remote.patch new file mode 100644 index 0000000..42452ff --- /dev/null +++ b/krb5-krad-remote.patch @@ -0,0 +1,209 @@ +From ce160f8826bae223876a6527a731c36b6912db15 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 9 Nov 2021 13:00:43 -0500 +Subject: [PATCH 1/2] Avoid use after free during libkrad cleanup + +libkrad client requests contain a list of references to remotes, with +no back-references or reference counts. To prevent accesses to +dangling references during cleanup, cancel all requests on all remotes +before freeing any remotes. + +Remove the code for aging out unused servers. This code was fairly +safe as all requests referencing a remote should have completed or +timed out during an hour of disuse, but in the current design we have +no way to guarantee or check that. The set of addresses we send +RADIUS requests to will generally be small, so aging out servers is +unnecessary. + +ticket: 9035 (new) +--- + src/lib/krad/client.c | 42 ++++++++++++++--------------------------- + src/lib/krad/internal.h | 4 ++++ + src/lib/krad/remote.c | 11 ++++++++--- + 3 files changed, 26 insertions(+), 31 deletions(-) + +diff --git a/src/lib/krad/client.c b/src/lib/krad/client.c +index 6365dd1c6..810940afc 100644 +--- a/src/lib/krad/client.c ++++ b/src/lib/krad/client.c +@@ -64,7 +64,6 @@ struct request_st { + + struct server_st { + krad_remote *serv; +- time_t last; + K5_LIST_ENTRY(server_st) list; + }; + +@@ -81,15 +80,10 @@ get_server(krad_client *rc, const struct addrinfo *ai, const char *secret, + krad_remote **out) + { + krb5_error_code retval; +- time_t currtime; + server *srv; + +- if (time(&currtime) == (time_t)-1) +- return errno; +- + K5_LIST_FOREACH(srv, &rc->servers, list) { + if (kr_remote_equals(srv->serv, ai, secret)) { +- srv->last = currtime; + *out = srv->serv; + return 0; + } +@@ -98,7 +92,6 @@ get_server(krad_client *rc, const struct addrinfo *ai, const char *secret, + srv = calloc(1, sizeof(server)); + if (srv == NULL) + return ENOMEM; +- srv->last = currtime; + + retval = kr_remote_new(rc->kctx, rc->vctx, ai, secret, &srv->serv); + if (retval != 0) { +@@ -173,28 +166,12 @@ request_new(krad_client *rc, krad_code code, const krad_attrset *attrs, + return 0; + } + +-/* Close remotes that haven't been used in a while. */ +-static void +-age(struct server_head *head, time_t currtime) +-{ +- server *srv, *tmp; +- +- K5_LIST_FOREACH_SAFE(srv, head, list, tmp) { +- if (currtime == (time_t)-1 || currtime - srv->last > 60 * 60) { +- K5_LIST_REMOVE(srv, list); +- kr_remote_free(srv->serv); +- free(srv); +- } +- } +-} +- + /* Handle a response from a server (or related errors). */ + static void + on_response(krb5_error_code retval, const krad_packet *reqp, + const krad_packet *rspp, void *data) + { + request *req = data; +- time_t currtime; + size_t i; + + /* Do nothing if we are already completed. */ +@@ -221,10 +198,6 @@ on_response(krb5_error_code retval, const krad_packet *reqp, + for (i = 0; req->remotes[i].remote != NULL; i++) + kr_remote_cancel(req->remotes[i].remote, req->remotes[i].packet); + +- /* Age out servers that haven't been used in a while. */ +- if (time(&currtime) != (time_t)-1) +- age(&req->rc->servers, currtime); +- + request_free(req); + } + +@@ -247,10 +220,23 @@ krad_client_new(krb5_context kctx, verto_ctx *vctx, krad_client **out) + void + krad_client_free(krad_client *rc) + { ++ server *srv; ++ + if (rc == NULL) + return; + +- age(&rc->servers, -1); ++ /* Cancel all requests before freeing any remotes, since each request's ++ * callback data may contain references to multiple remotes. */ ++ K5_LIST_FOREACH(srv, &rc->servers, list) ++ kr_remote_cancel_all(srv->serv); ++ ++ while (!K5_LIST_EMPTY(&rc->servers)) { ++ srv = K5_LIST_FIRST(&rc->servers); ++ K5_LIST_REMOVE(srv, list); ++ kr_remote_free(srv->serv); ++ free(srv); ++ } ++ + free(rc); + } + +diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h +index 0143d155a..7619563fc 100644 +--- a/src/lib/krad/internal.h ++++ b/src/lib/krad/internal.h +@@ -109,6 +109,10 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs, + void + kr_remote_cancel(krad_remote *rr, const krad_packet *pkt); + ++/* Cancel all requests awaiting responses. */ ++void ++kr_remote_cancel_all(krad_remote *rr); ++ + /* Determine if this remote object refers to the remote resource identified + * by the addrinfo struct and the secret. */ + krb5_boolean +diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c +index 7e491e994..06ae751bc 100644 +--- a/src/lib/krad/remote.c ++++ b/src/lib/krad/remote.c +@@ -421,15 +421,20 @@ error: + return retval; + } + ++void ++kr_remote_cancel_all(krad_remote *rr) ++{ ++ while (!K5_TAILQ_EMPTY(&rr->list)) ++ request_finish(K5_TAILQ_FIRST(&rr->list), ECANCELED, NULL); ++} ++ + void + kr_remote_free(krad_remote *rr) + { + if (rr == NULL) + return; + +- while (!K5_TAILQ_EMPTY(&rr->list)) +- request_finish(K5_TAILQ_FIRST(&rr->list), ECANCELED, NULL); +- ++ kr_remote_cancel_all(rr); + free(rr->secret); + if (rr->info != NULL) + free(rr->info->ai_addr); +-- +2.35.1 + + +From e0084425df784952e76b3bcc8ae9d08300234733 Mon Sep 17 00:00:00 2001 +From: Sumit Bose +Date: Mon, 8 Nov 2021 17:47:17 +0100 +Subject: [PATCH 2/2] More python3 fixes for t_daemon.py + +[ghudson@mit.edu: use a list comprehension instead of map()] +--- + src/lib/krad/t_daemon.py | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/src/lib/krad/t_daemon.py b/src/lib/krad/t_daemon.py +index 7668cd7f8..4a3de079c 100755 +--- a/src/lib/krad/t_daemon.py ++++ b/src/lib/krad/t_daemon.py +@@ -50,7 +50,7 @@ class TestServer(server.Server): + + for key in pkt.keys(): + if key == "User-Password": +- passwd = map(pkt.PwDecrypt, pkt[key]) ++ passwd = [pkt.PwDecrypt(x) for x in pkt[key]] + + reply = self.CreateReplyPacket(pkt) + if passwd == ['accept']: +@@ -61,8 +61,8 @@ class TestServer(server.Server): + + srv = TestServer(addresses=["localhost"], + hosts={"127.0.0.1": +- server.RemoteHost("127.0.0.1", "foo", "localhost")}, +- dict=dictionary.Dictionary(StringIO.StringIO(DICTIONARY))) ++ server.RemoteHost("127.0.0.1", b"foo", "localhost")}, ++ dict=dictionary.Dictionary(StringIO(DICTIONARY))) + + # Write a sentinel character to let the parent process know we're listening. + sys.stdout.write("~") +-- +2.35.1 + diff --git a/krb5.spec b/krb5.spec index b54534c..cab77bb 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}8%{?dist} +Release: %{?zdpd}9%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -95,7 +95,8 @@ Patch34: Use-OpenSSL-s-KBKDF-and-KRB5KDF-for-deriving-long-te.patch Patch35: Handle-OpenSSL-3-s-providers.patch Patch36: Remove-TCL-based-libkadm5-API-tests.patch Patch37: Use-SHA256-instead-of-SHA1-for-PKINIT-CMS-digest.patch -Patch38: krb5-krad-larger-attrs.patch +Patch38: krb5-krad-remote.patch +Patch39: krb5-krad-larger-attrs.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -645,6 +646,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Apr 05 2022 Alexander Bokovoy - 1.19.2-9 +- Fix libkrad client cleanup +- Fixes rhbz#2072059 + * Tue Apr 05 2022 Alexander Bokovoy - 1.19.2-8 - Allow use of larger RADIUS attributes in krad library From 04513849e37aaad2eb9cacc9fad4e3abcdb724fc Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 20 Apr 2022 11:37:16 +0200 Subject: [PATCH 260/304] Try harder to avoid password change replay errors change_set_password() was changed to prefer TCP. However, because UDP_LAST falls back to UDP after one second, we can still get a replay error due to a dropped packet, before the TCP layer has a chance to retry. Instead, try k5_sendto() with NO_UDP, and only fall back to UDP after TCP fails completely without reaching a server. In sendto_kdc.c, implement an ONLY_UDP transport strategy to allow the UDP fallback. Resolves: rhbz#2076965 Signed-off-by: Julien Rische --- ...-avoid-password-change-replay-errors.patch | 91 +++++++++++++++++++ krb5.spec | 7 +- 2 files changed, 97 insertions(+), 1 deletion(-) create mode 100644 Try-harder-to-avoid-password-change-replay-errors.patch diff --git a/Try-harder-to-avoid-password-change-replay-errors.patch b/Try-harder-to-avoid-password-change-replay-errors.patch new file mode 100644 index 0000000..875ed9c --- /dev/null +++ b/Try-harder-to-avoid-password-change-replay-errors.patch @@ -0,0 +1,91 @@ +From 1f706852ee759160e763c355a3053ad5e045fa06 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 4 Mar 2022 00:45:00 -0500 +Subject: [PATCH] Try harder to avoid password change replay errors + +Commit d7b3018d338fc9c989c3fa17505870f23c3759a8 (ticket 7905) changed +change_set_password() to prefer TCP. However, because UDP_LAST falls +back to UDP after one second, we can still get a replay error due to a +dropped packet, before the TCP layer has a chance to retry. + +Instead, try k5_sendto() with NO_UDP, and only fall back to UDP after +TCP fails completely without reaching a server. In sendto_kdc.c, +implement an ONLY_UDP transport strategy to allow the UDP fallback. + +ticket: 9037 +--- + src/lib/krb5/os/changepw.c | 9 ++++++++- + src/lib/krb5/os/os-proto.h | 1 + + src/lib/krb5/os/sendto_kdc.c | 12 ++++++++---- + 3 files changed, 17 insertions(+), 5 deletions(-) + +diff --git a/src/lib/krb5/os/changepw.c b/src/lib/krb5/os/changepw.c +index 9f968da7f..c59232586 100644 +--- a/src/lib/krb5/os/changepw.c ++++ b/src/lib/krb5/os/changepw.c +@@ -255,9 +255,16 @@ change_set_password(krb5_context context, + callback_info.pfn_cleanup = kpasswd_sendto_msg_cleanup; + krb5_free_data_contents(callback_ctx.context, &chpw_rep); + ++ /* UDP retransmits may be seen as replays. Only try UDP after other ++ * transports fail completely. */ + code = k5_sendto(callback_ctx.context, NULL, &creds->server->realm, +- &sl, UDP_LAST, &callback_info, &chpw_rep, ++ &sl, NO_UDP, &callback_info, &chpw_rep, + ss2sa(&remote_addr), &addrlen, NULL, NULL, NULL); ++ if (code == KRB5_KDC_UNREACH) { ++ code = k5_sendto(callback_ctx.context, NULL, &creds->server->realm, ++ &sl, ONLY_UDP, &callback_info, &chpw_rep, ++ ss2sa(&remote_addr), &addrlen, NULL, NULL, NULL); ++ } + if (code) + goto cleanup; + +diff --git a/src/lib/krb5/os/os-proto.h b/src/lib/krb5/os/os-proto.h +index a985f2aec..91d2791ce 100644 +--- a/src/lib/krb5/os/os-proto.h ++++ b/src/lib/krb5/os/os-proto.h +@@ -49,6 +49,7 @@ typedef enum { + UDP_FIRST = 0, + UDP_LAST, + NO_UDP, ++ ONLY_UDP + } k5_transport_strategy; + + /* A single server hostname or address. */ +diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c +index 0eedec175..c7f5d861a 100644 +--- a/src/lib/krb5/os/sendto_kdc.c ++++ b/src/lib/krb5/os/sendto_kdc.c +@@ -802,11 +802,14 @@ resolve_server(krb5_context context, const krb5_data *realm, + int err, result; + char portbuf[PORT_LENGTH]; + +- /* Skip UDP entries if we don't want UDP. */ ++ /* Skip entries excluded by the strategy. */ + if (strategy == NO_UDP && entry->transport == UDP) + return 0; ++ if (strategy == ONLY_UDP && entry->transport != UDP && ++ entry->transport != TCP_OR_UDP) ++ return 0; + +- transport = (strategy == UDP_FIRST) ? UDP : TCP; ++ transport = (strategy == UDP_FIRST || strategy == ONLY_UDP) ? UDP : TCP; + if (entry->hostname == NULL) { + /* Added by a module, so transport is either TCP or UDP. */ + ai.ai_socktype = socktype_for_transport(entry->transport); +@@ -850,8 +853,9 @@ resolve_server(krb5_context context, const krb5_data *realm, + } + + /* For TCP_OR_UDP entries, add each address again with the non-preferred +- * transport, unless we are avoiding UDP. Flag these as deferred. */ +- if (retval == 0 && entry->transport == TCP_OR_UDP && strategy != NO_UDP) { ++ * transport, if there is one. Flag these as deferred. */ ++ if (retval == 0 && entry->transport == TCP_OR_UDP && ++ (strategy == UDP_FIRST || strategy == UDP_LAST)) { + transport = (strategy == UDP_FIRST) ? TCP : UDP; + for (a = addrs; a != 0 && retval == 0; a = a->ai_next) { + a->ai_socktype = socktype_for_transport(transport); +-- +2.35.1 + diff --git a/krb5.spec b/krb5.spec index cab77bb..35787ff 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}9%{?dist} +Release: %{?zdpd}10%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -97,6 +97,7 @@ Patch36: Remove-TCL-based-libkadm5-API-tests.patch Patch37: Use-SHA256-instead-of-SHA1-for-PKINIT-CMS-digest.patch Patch38: krb5-krad-remote.patch Patch39: krb5-krad-larger-attrs.patch +Patch40: Try-harder-to-avoid-password-change-replay-errors.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -646,6 +647,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Apr 20 2022 Julien Rische - 1.19.2-10 +- Try harder to avoid password change replay errors +- Resolves: rhbz#2072059 + * Tue Apr 05 2022 Alexander Bokovoy - 1.19.2-9 - Fix libkrad client cleanup - Fixes rhbz#2072059 From c25a51c9699ee8398345a3431f62c97c63390cb0 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Mon, 2 May 2022 11:04:06 +0200 Subject: [PATCH 261/304] Use p11-kit as default PKCS11 module Resolves: rhbz#2073274 Signed-off-by: Julien Rische --- ...-variable-for-default-PKCS-11-module.patch | 201 ++++++++++++++++++ krb5.spec | 6 +- 2 files changed, 206 insertions(+), 1 deletion(-) create mode 100644 Add-configure-variable-for-default-PKCS-11-module.patch diff --git a/Add-configure-variable-for-default-PKCS-11-module.patch b/Add-configure-variable-for-default-PKCS-11-module.patch new file mode 100644 index 0000000..724b707 --- /dev/null +++ b/Add-configure-variable-for-default-PKCS-11-module.patch @@ -0,0 +1,201 @@ +From 2a91dabd9752825b96faf3b25ea643d5282c5957 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Fri, 22 Apr 2022 14:12:37 +0200 +Subject: [PATCH] Add configure variable for default PKCS#11 module + +[ghudson@mit.edu: added documentation of configure variable and doc +substitution; shortened commit message] + +ticket: 9058 (new) +--- + doc/admin/conf_files/krb5_conf.rst | 2 +- + doc/build/options2configure.rst | 3 +++ + doc/conf.py | 3 +++ + doc/mitK5defaults.rst | 25 +++++++++++++------------ + src/configure.ac | 8 ++++++++ + src/doc/Makefile.in | 2 ++ + src/man/Makefile.in | 4 +++- + src/man/krb5.conf.man | 2 +- + src/plugins/preauth/pkinit/pkinit.h | 1 - + 9 files changed, 34 insertions(+), 16 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index adba8238d..3d25c9a12 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -1020,7 +1020,7 @@ information for PKINIT is as follows: + All keyword/values are optional. *modname* specifies the location + of a library implementing PKCS #11. If a value is encountered + with no keyword, it is assumed to be the *modname*. If no +- module-name is specified, the default is ``opensc-pkcs11.so``. ++ module-name is specified, the default is |pkcs11_modname|. + ``slotid=`` and/or ``token=`` may be specified to force the use of + a particular smard card reader or token if there is more than one + available. ``certid=`` and/or ``certlabel=`` may be specified to +diff --git a/doc/build/options2configure.rst b/doc/build/options2configure.rst +index a8959626d..8f8ac911c 100644 +--- a/doc/build/options2configure.rst ++++ b/doc/build/options2configure.rst +@@ -143,6 +143,9 @@ Environment variables + This option allows one to specify libraries to be passed to the + linker (e.g., ``-l``) + ++**PKCS11_MODNAME=**\ *library* ++ Override the built-in default PKCS11 library name. ++ + **SS_LIB=**\ *libs*... + If ``-lss`` is not the correct way to link in your installed ss + library, for example if additional support libraries are needed, +diff --git a/doc/conf.py b/doc/conf.py +index a876fd633..252ab891a 100644 +--- a/doc/conf.py ++++ b/doc/conf.py +@@ -242,6 +242,7 @@ if 'mansubs' in tags: + ccache = '``@CCNAME@``' + keytab = '``@KTNAME@``' + ckeytab = '``@CKTNAME@``' ++ pkcs11_modname = '``@PKCS11MOD@``' + elif 'pathsubs' in tags: + # Read configured paths from a file produced by the build system. + exec(open("paths.py").read()) +@@ -255,6 +256,7 @@ else: + ccache = ':ref:`DEFCCNAME `' + keytab = ':ref:`DEFKTNAME `' + ckeytab = ':ref:`DEFCKTNAME `' ++ pkcs11_modname = ':ref:`PKCS11_MODNAME `' + + rst_epilog = '\n' + +@@ -275,6 +277,7 @@ else: + rst_epilog += '.. |ccache| replace:: %s\n' % ccache + rst_epilog += '.. |keytab| replace:: %s\n' % keytab + rst_epilog += '.. |ckeytab| replace:: %s\n' % ckeytab ++ rst_epilog += '.. |pkcs11_modname| replace:: %s\n' % pkcs11_modname + rst_epilog += ''' + .. |krb5conf| replace:: ``/etc/krb5.conf`` + .. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal`` +diff --git a/doc/mitK5defaults.rst b/doc/mitK5defaults.rst +index 74e69f4ad..aea7af3db 100644 +--- a/doc/mitK5defaults.rst ++++ b/doc/mitK5defaults.rst +@@ -59,18 +59,19 @@ subdirectories of ``/usr/local``. When MIT krb5 is integrated into an + operating system, the paths are generally chosen to match the + operating system's filesystem layout. + +-========================== ============= =========================== =========================== +-Description Symbolic name Custom build path Typical OS path +-========================== ============= =========================== =========================== +-User programs BINDIR ``/usr/local/bin`` ``/usr/bin`` +-Libraries and plugins LIBDIR ``/usr/local/lib`` ``/usr/lib`` +-Parent of KDC state dir LOCALSTATEDIR ``/usr/local/var`` ``/var`` +-Parent of KDC runtime dir RUNSTATEDIR ``/usr/local/var/run`` ``/run`` +-Administrative programs SBINDIR ``/usr/local/sbin`` ``/usr/sbin`` +-Alternate krb5.conf dir SYSCONFDIR ``/usr/local/etc`` ``/etc`` +-Default ccache name DEFCCNAME ``FILE:/tmp/krb5cc_%{uid}`` ``FILE:/tmp/krb5cc_%{uid}`` +-Default keytab name DEFKTNAME ``FILE:/etc/krb5.keytab`` ``FILE:/etc/krb5.keytab`` +-========================== ============= =========================== =========================== ++========================== ============== =========================== =========================== ++Description Symbolic name Custom build path Typical OS path ++========================== ============== =========================== =========================== ++User programs BINDIR ``/usr/local/bin`` ``/usr/bin`` ++Libraries and plugins LIBDIR ``/usr/local/lib`` ``/usr/lib`` ++Parent of KDC state dir LOCALSTATEDIR ``/usr/local/var`` ``/var`` ++Parent of KDC runtime dir RUNSTATEDIR ``/usr/local/var/run`` ``/run`` ++Administrative programs SBINDIR ``/usr/local/sbin`` ``/usr/sbin`` ++Alternate krb5.conf dir SYSCONFDIR ``/usr/local/etc`` ``/etc`` ++Default ccache name DEFCCNAME ``FILE:/tmp/krb5cc_%{uid}`` ``FILE:/tmp/krb5cc_%{uid}`` ++Default keytab name DEFKTNAME ``FILE:/etc/krb5.keytab`` ``FILE:/etc/krb5.keytab`` ++Default PKCS11 module PKCS11_MODNAME ``opensc-pkcs11.so`` ``opensc-pkcs11.so`` ++========================== ============== =========================== =========================== + + The default client keytab name (DEFCKTNAME) typically defaults to + ``FILE:/usr/local/var/krb5/user/%{euid}/client.keytab`` for a custom +diff --git a/src/configure.ac b/src/configure.ac +index 82b049af9..52e6563da 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -1442,6 +1442,14 @@ AC_DEFINE_UNQUOTED(DEFKTNAME, ["$DEFKTNAME"], [Define to default keytab name]) + AC_DEFINE_UNQUOTED(DEFCKTNAME, ["$DEFCKTNAME"], + [Define to default client keytab name]) + ++AC_ARG_VAR(PKCS11_MODNAME, [Default PKCS11 module name]) ++if test "${PKCS11_MODNAME+set}" != set; then ++ PKCS11_MODNAME=opensc-pkcs11.so ++fi ++AC_MSG_NOTICE([Default PKCS11 module name: $PKCS11_MODNAME]) ++AC_DEFINE_UNQUOTED(PKCS11_MODNAME, ["$PKCS11_MODNAME"], ++ [Default PKCS11 module name]) ++ + AC_CONFIG_FILES([build-tools/krb5-config], [chmod +x build-tools/krb5-config]) + AC_CONFIG_FILES([build-tools/kadm-server.pc + build-tools/kadm-client.pc +diff --git a/src/doc/Makefile.in b/src/doc/Makefile.in +index 379bc3651..a1b0cff0a 100644 +--- a/src/doc/Makefile.in ++++ b/src/doc/Makefile.in +@@ -10,6 +10,7 @@ sysconfdir=@sysconfdir@ + DEFCCNAME=@DEFCCNAME@ + DEFKTNAME=@DEFKTNAME@ + DEFCKTNAME=@DEFCKTNAME@ ++PKCS11_MODNAME=@PKCS11_MODNAME@ + + RST_SOURCES= _static \ + _templates \ +@@ -118,6 +119,7 @@ paths.py: + echo 'ccache = "``$(DEFCCNAME)``"' >> $@ + echo 'keytab = "``$(DEFKTNAME)``"' >> $@ + echo 'ckeytab = "``$(DEFCKTNAME)``"' >> $@ ++ echo 'pkcs11_modname = "``$(PKCS11_MODNAME)``"' >> $@ + + # Dummy rule that man/Makefile can invoke + version.py: $(docsrc)/version.py +diff --git a/src/man/Makefile.in b/src/man/Makefile.in +index 00b1b2de0..85cae0914 100644 +--- a/src/man/Makefile.in ++++ b/src/man/Makefile.in +@@ -8,6 +8,7 @@ sysconfdir=@sysconfdir@ + DEFCCNAME=@DEFCCNAME@ + DEFKTNAME=@DEFKTNAME@ + DEFCKTNAME=@DEFCKTNAME@ ++PKCS11_MODNAME=@PKCS11_MODNAME@ + + MANSUBS=k5identity.sub k5login.sub k5srvutil.sub kadm5.acl.sub kadmin.sub \ + kadmind.sub kdb5_ldap_util.sub kdb5_util.sub kdc.conf.sub \ +@@ -47,7 +48,8 @@ $(docsrc)/version.py: $(top_srcdir)/patchlevel.h + -e 's|@SYSCONFDIR@|$(sysconfdir)|g' \ + -e 's|@CCNAME@|$(DEFCCNAME)|g' \ + -e 's|@KTNAME@|$(DEFKTNAME)|g' \ +- -e 's|@CKTNAME@|$(DEFCKTNAME)|g' $? > $@ ++ -e 's|@CKTNAME@|$(DEFCKTNAME)|g' \ ++ -e 's|@PKCS11MOD@|$(PKCS11_MODNAME)|g' $? > $@ + + all: $(MANSUBS) + +diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man +index e993d5c09..42f5ea4f9 100644 +--- a/src/man/krb5.conf.man ++++ b/src/man/krb5.conf.man +@@ -1151,7 +1151,7 @@ user\(aqs certificate and private key. + All keyword/values are optional. \fImodname\fP specifies the location + of a library implementing PKCS #11. If a value is encountered + with no keyword, it is assumed to be the \fImodname\fP\&. If no +-module\-name is specified, the default is \fBopensc\-pkcs11.so\fP\&. ++module\-name is specified, the default is \fB@PKCS11MOD@\fP\&. + \fBslotid=\fP and/or \fBtoken=\fP may be specified to force the use of + a particular smard card reader or token if there is more than one + available. \fBcertid=\fP and/or \fBcertlabel=\fP may be specified to +diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h +index b437fd53f..a2018cb10 100644 +--- a/src/plugins/preauth/pkinit/pkinit.h ++++ b/src/plugins/preauth/pkinit/pkinit.h +@@ -42,7 +42,6 @@ + #ifndef WITHOUT_PKCS11 + #include "pkcs11.h" + +-#define PKCS11_MODNAME "opensc-pkcs11.so" + #define PK_SIGLEN_GUESS 1000 + #define PK_NOSLOT 999999 + #endif +-- +2.35.1 + diff --git a/krb5.spec b/krb5.spec index 35787ff..c59f2d0 100644 --- a/krb5.spec +++ b/krb5.spec @@ -98,6 +98,7 @@ Patch37: Use-SHA256-instead-of-SHA1-for-PKINIT-CMS-digest.patch Patch38: krb5-krad-remote.patch Patch39: krb5-krad-larger-attrs.patch Patch40: Try-harder-to-avoid-password-change-replay-errors.patch +Patch41: Add-configure-variable-for-default-PKCS-11-module.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -289,6 +290,7 @@ CPPFLAGS="`echo $DEFINES $INCLUDES`" CFLAGS="$CFLAGS" \ CPPFLAGS="$CPPFLAGS" \ SS_LIB="-lss" \ + PKCS11_MODNAME="p11-kit-proxy.so" \ --enable-shared \ --runstatedir=/run \ --localstatedir=%{_var}/kerberos \ @@ -647,7 +649,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog -* Wed Apr 20 2022 Julien Rische - 1.19.2-10 +* Mon May 2 2022 Julien Rische - 1.19.2-10 +- Use p11-kit as default PKCS11 module +- Resolves: rhbz#2073274 - Try harder to avoid password change replay errors - Resolves: rhbz#2072059 From e9188f0caa13fb780f4b32fa6ac3f0eb625d4acb Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Tue, 10 May 2022 16:43:18 +0200 Subject: [PATCH 262/304] Allow krad UDP/TCP localhost connection with FIPS libkrad allows to establish connections only to UNIX socket in FIPS mode, because MD5 digest is not considered safe enough to be used for network communication. However, FreeRadius requires connection on TCP or UDP ports. This commit allows TCP or UDP connections in FIPS mode if destination is localhost. Resolves: rhbz#2082189 Signed-off-by: Julien Rische --- ...P-TCP-localhost-connection-with-FIPS.patch | 81 +++++++++++++++++++ krb5.spec | 7 +- 2 files changed, 87 insertions(+), 1 deletion(-) create mode 100644 downstream-Allow-krad-UDP-TCP-localhost-connection-with-FIPS.patch diff --git a/downstream-Allow-krad-UDP-TCP-localhost-connection-with-FIPS.patch b/downstream-Allow-krad-UDP-TCP-localhost-connection-with-FIPS.patch new file mode 100644 index 0000000..7455cb9 --- /dev/null +++ b/downstream-Allow-krad-UDP-TCP-localhost-connection-with-FIPS.patch @@ -0,0 +1,81 @@ +From a43d621ae83c89abb74764f0fd9d90a8e9992333 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Thu, 5 May 2022 17:15:12 +0200 +Subject: [PATCH] Allow krad UDP/TCP localhost connection with FIPS + +libkrad allows to establish connections only to UNIX socket in FIPS +mode, because MD5 digest is not considered safe enough to be used for +network communication. However, FreeRadius requires connection on TCP or +UDP ports. + +This commit allows TCP or UDP connections in FIPS mode if destination is +localhost. + +Resolves: rhbz#2082189 +--- + src/lib/krad/remote.c | 35 +++++++++++++++++++++++++++++++++-- + 1 file changed, 33 insertions(+), 2 deletions(-) + +diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c +index 7b5804b1d..e671bc5c2 100644 +--- a/src/lib/krad/remote.c ++++ b/src/lib/krad/remote.c +@@ -33,6 +33,7 @@ + + #include + #include ++#include + + #include + +@@ -74,6 +75,35 @@ on_io(verto_ctx *ctx, verto_ev *ev); + static void + on_timeout(verto_ctx *ctx, verto_ev *ev); + ++static in_addr_t get_in_addr(struct addrinfo *info) ++{ return ((struct sockaddr_in *)(info->ai_addr))->sin_addr.s_addr; } ++ ++static struct in6_addr *get_in6_addr(struct addrinfo *info) ++{ return &(((struct sockaddr_in6 *)(info->ai_addr))->sin6_addr); } ++ ++static bool is_inet_localhost(struct addrinfo *info) ++{ ++ struct addrinfo *p; ++ ++ for (p = info; p; p = p->ai_next) { ++ switch (p->ai_family) { ++ case AF_INET: ++ if (IN_LOOPBACKNET != (get_in_addr(p) & IN_CLASSA_NET ++ >> IN_CLASSA_NSHIFT)) ++ return false; ++ break; ++ case AF_INET6: ++ if (!IN6_IS_ADDR_LOOPBACK(get_in6_addr(p))) ++ return false; ++ break; ++ default: ++ return false; ++ } ++ } ++ ++ return true; ++} ++ + /* Iterate over the set of outstanding packets. */ + static const krad_packet * + iterator(request **out) +@@ -455,8 +485,9 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs, + (krad_packet_iter_cb)iterator, &r, &tmp); + if (retval != 0) + goto error; +- else if (tmp->is_fips && rr->info->ai_family != AF_LOCAL && +- rr->info->ai_family != AF_UNIX) { ++ else if (tmp->is_fips && rr->info->ai_family != AF_LOCAL ++ && rr->info->ai_family != AF_UNIX ++ && !is_inet_localhost(rr->info)) { + /* This would expose cleartext passwords, so abort. */ + retval = ESOCKTNOSUPPORT; + goto error; +-- +2.35.1 + diff --git a/krb5.spec b/krb5.spec index c59f2d0..89ed921 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}10%{?dist} +Release: %{?zdpd}11%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -99,6 +99,7 @@ Patch38: krb5-krad-remote.patch Patch39: krb5-krad-larger-attrs.patch Patch40: Try-harder-to-avoid-password-change-replay-errors.patch Patch41: Add-configure-variable-for-default-PKCS-11-module.patch +Patch42: downstream-Allow-krad-UDP-TCP-localhost-connection-with-FIPS.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -649,6 +650,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu May 12 2022 Julien Rische - 1.19.2-11 +- Allow libkrad UDP/TCP connection to localhost in FIPS mode +- Resolves: rhbz#2082189 + * Mon May 2 2022 Julien Rische - 1.19.2-10 - Use p11-kit as default PKCS11 module - Resolves: rhbz#2073274 From 601b89387bd1c41859001b731c2fcbb9b530d291 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 15 Jun 2022 15:37:30 +0200 Subject: [PATCH 263/304] Read GSS configuration files with mtime 0 There is at least one case (with flatpaks) where configuration files in the special read-only /etc all have an mtime of 0. Using an initial last modified time of 0 in g_initialize.c causes these files to never be read. Change the initial high value to the be the "invalid" value (time_t)-1. Since the C and POSIX standards do not require time_t to be signed, special-case the checks in load_if_changed() and updateMechList() to treat all mod times as newer than -1. Signed-off-by: Julien Rische --- ...GSS-configuration-files-with-mtime-0.patch | 71 +++++++++++++++++++ krb5.spec | 4 +- 2 files changed, 74 insertions(+), 1 deletion(-) create mode 100644 Read-GSS-configuration-files-with-mtime-0.patch diff --git a/Read-GSS-configuration-files-with-mtime-0.patch b/Read-GSS-configuration-files-with-mtime-0.patch new file mode 100644 index 0000000..5bcae39 --- /dev/null +++ b/Read-GSS-configuration-files-with-mtime-0.patch @@ -0,0 +1,71 @@ +From f8747c22fd159ad3556fdf6ec4f269c754c1eadb Mon Sep 17 00:00:00 2001 +From: Simo Sorce +Date: Thu, 19 May 2022 12:27:40 -0400 +Subject: [PATCH] Read GSS configuration files with mtime 0 + +There is at least one case (with flatpaks) where configuration files +in the special read-only /etc all have an mtime of 0. Using an +initial last modified time of 0 in g_initialize.c causes these files +to never be read. + +Change the initial high value to the be the "invalid" value +(time_t)-1. Since the C and POSIX standards do not require time_t to +be signed, special-case the checks in load_if_changed() and +updateMechList() to treat all mod times as newer than -1. + +[ghudson@mit.edu: edited commit message; slightly modified approach] + +ticket: 9060 (new) +target_version: 1.20 +tags: pullup +--- + src/lib/gssapi/mechglue/g_initialize.c | 11 ++++++----- + 1 file changed, 6 insertions(+), 5 deletions(-) + +diff --git a/src/lib/gssapi/mechglue/g_initialize.c b/src/lib/gssapi/mechglue/g_initialize.c +index 6d49700a5..857d4a4f2 100644 +--- a/src/lib/gssapi/mechglue/g_initialize.c ++++ b/src/lib/gssapi/mechglue/g_initialize.c +@@ -93,7 +93,7 @@ static void free_mechSet(void); + static gss_mech_info g_mechList = NULL; + static gss_mech_info g_mechListTail = NULL; + static k5_mutex_t g_mechListLock = K5_MUTEX_PARTIAL_INITIALIZER; +-static time_t g_confFileModTime = (time_t)0; ++static time_t g_confFileModTime = (time_t)-1; + static time_t g_confLastCall = (time_t)0; + + static gss_OID_set_desc g_mechSet = { 0, NULL }; +@@ -469,9 +469,9 @@ load_if_changed(const char *pathname, time_t last, time_t *highest) + mtime = check_link_mtime(pathname, &mtime); + if (mtime == (time_t)-1) + return; +- if (mtime > *highest) ++ if (mtime > *highest || *highest == (time_t)-1) + *highest = mtime; +- if (mtime > last) ++ if (mtime > last || last == (time_t)-1) + loadConfigFile(pathname); + } + +@@ -482,7 +482,7 @@ static void + loadConfigFiles() + { + glob_t globbuf; +- time_t highest = 0, now; ++ time_t highest = (time_t)-1, now; + char **path; + const char *val; + +@@ -522,7 +522,8 @@ updateMechList(void) + + #if defined(_WIN32) + time_t lastConfModTime = getRegConfigModTime(MECH_KEY); +- if (g_confFileModTime >= lastConfModTime) ++ if (g_confFileModTime >= lastConfModTime && ++ g_confFileModTime != (time_t)-1) + return; + g_confFileModTime = lastConfModTime; + loadConfigFromRegistry(HKEY_CURRENT_USER, MECH_KEY); +-- +2.35.3 + diff --git a/krb5.spec b/krb5.spec index 89ed921..a1a851e 100644 --- a/krb5.spec +++ b/krb5.spec @@ -100,6 +100,7 @@ Patch39: krb5-krad-larger-attrs.patch Patch40: Try-harder-to-avoid-password-change-replay-errors.patch Patch41: Add-configure-variable-for-default-PKCS-11-module.patch Patch42: downstream-Allow-krad-UDP-TCP-localhost-connection-with-FIPS.patch +Patch43: Read-GSS-configuration-files-with-mtime-0.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -650,9 +651,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog -* Thu May 12 2022 Julien Rische - 1.19.2-11 +* Wed Jun 15 2022 Julien Rische - 1.19.2-11 - Allow libkrad UDP/TCP connection to localhost in FIPS mode - Resolves: rhbz#2082189 +- Read GSS configuration files with mtime 0 * Mon May 2 2022 Julien Rische - 1.19.2-10 - Use p11-kit as default PKCS11 module From e138eb81254c03b9f61b74ecace323828d16a53f Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 21 Jul 2022 16:36:11 +0000 Subject: [PATCH 264/304] Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index a1a851e..4ac72a8 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,7 +42,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}11%{?dist} +Release: %{?zdpd}11%{?dist}.1 # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -651,6 +651,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Thu Jul 21 2022 Fedora Release Engineering - 1.19.2-11.1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + * Wed Jun 15 2022 Julien Rische - 1.19.2-11 - Allow libkrad UDP/TCP connection to localhost in FIPS mode - Resolves: rhbz#2082189 From 3907ec760c6da3179e0d4c20c758af692316383d Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Tue, 2 Aug 2022 11:17:13 +0200 Subject: [PATCH 265/304] Use baserelease to set the release number --- krb5.spec | 21 ++++++++++++++++----- 1 file changed, 16 insertions(+), 5 deletions(-) diff --git a/krb5.spec b/krb5.spec index 4ac72a8..80865ec 100644 --- a/krb5.spec +++ b/krb5.spec @@ -30,10 +30,18 @@ %global configure_default_ccache_name 1 %global configured_default_ccache_name KEYRING:persistent:%%{uid} -# for prereleases, % global prerelease beta1 -%if %{defined prerelease} -%global dashpre -%{prerelease} -%global zdpd 0.%{prerelease}. +# Use baserelease to set the release number! +# +# baserelease is what we have standardized across Fedora and what +# rpmdev-bumpspec knows how to handle. +%global baserelease 12 + +# This should be e.g. beta1 or %%nil +%global pre_release %nil + +%global krb5_release %{baserelease} +%if "x%{?pre_release}" != "x" +%global krb5_release 0.%{baserelease}.%{pre_release} %endif # Should be in form 5.0, 6.1, etc. @@ -42,7 +50,7 @@ Summary: The Kerberos network authentication system Name: krb5 Version: 1.19.2 -Release: %{?zdpd}11%{?dist}.1 +Release: %{krb5_release}%{?dist} # rharwood has trust path to signing key and verifies on check-in Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz @@ -651,6 +659,9 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Aug 02 2022 Andreas Schneider - 1.19.2-12 +- Use baserelease to set the release number + * Thu Jul 21 2022 Fedora Release Engineering - 1.19.2-11.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild From 440331a1e41116fa88674a211fa7fd81efb01f18 Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Wed, 3 Aug 2022 13:12:52 +0200 Subject: [PATCH 266/304] Fix the Source0 and Source1 variables --- krb5.spec | 18 +++++++++++++++--- 1 file changed, 15 insertions(+), 3 deletions(-) diff --git a/krb5.spec b/krb5.spec index 80865ec..ae1a948 100644 --- a/krb5.spec +++ b/krb5.spec @@ -42,6 +42,18 @@ %global krb5_release %{baserelease} %if "x%{?pre_release}" != "x" %global krb5_release 0.%{baserelease}.%{pre_release} +%global krb5_pre_release -%{pre_release} +%endif + +%global krb5_version_major 1 +%global krb5_version_minor 19 +# For a release without a patch number set to %%nil +%global krb5_version_patch 2 + +%global krb5_version_major_minor %{krb5_version_major}.%{krb5_version_minor} +%global krb5_version %{krb5_version_major_minor} +%if "x%{?krb5_version_patch}" != "x" +%global krb5_version %{krb5_version_major_minor}.%{krb5_version_patch} %endif # Should be in form 5.0, 6.1, etc. @@ -49,12 +61,12 @@ Summary: The Kerberos network authentication system Name: krb5 -Version: 1.19.2 +Version: %{krb5_version} Release: %{krb5_release}%{?dist} # rharwood has trust path to signing key and verifies on check-in -Source0: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz -Source1: https://web.mit.edu/kerberos/dist/krb5/%{version}/krb5-%{version}%{?dashpre}.tar.gz.asc +Source0: https://web.mit.edu/kerberos/dist/krb5/%{krb5_version_major_minor}/krb5-%{krb5_version}%{?krb5_pre_release}.tar.gz +Source1: https://web.mit.edu/kerberos/dist/krb5/%{krb5_version_major_minor}/krb5-%{krb5_version}%{?krb5_pre_release}.tar.gz.asc # Numbering is a relic of old init systems etc. It's easiest to just leave. Source2: kprop.service From f5aa40a4a20812fca640998fb740506383f16127 Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Tue, 2 Aug 2022 11:19:48 +0200 Subject: [PATCH 267/304] Do not define netlib, but use autoconf detection for res_* functions This looks like an ancient patch and is not needed anymore. --- downstream-netlib-and-dns.patch | 24 ------------------------ krb5.spec | 8 ++++++-- 2 files changed, 6 insertions(+), 26 deletions(-) delete mode 100644 downstream-netlib-and-dns.patch diff --git a/downstream-netlib-and-dns.patch b/downstream-netlib-and-dns.patch deleted file mode 100644 index d3ae129..0000000 --- a/downstream-netlib-and-dns.patch +++ /dev/null @@ -1,24 +0,0 @@ -From 2d7e197fa88dccd3ca051f9f7cb97937c35c55a8 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 23 Aug 2016 16:46:21 -0400 -Subject: [PATCH] [downstream] netlib and dns - -We want to be able to use --with-netlib and --enable-dns at the same time. - -Last-updated: krb5-1.3.1 ---- - src/aclocal.m4 | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 5afb96e58..4a4d460e3 100644 ---- a/src/aclocal.m4 -+++ b/src/aclocal.m4 -@@ -718,6 +718,7 @@ AC_HELP_STRING([--with-netlib=LIBS], use user defined resolver library), - LIBS="$LIBS $withval" - AC_MSG_RESULT("netlib will use \'$withval\'") - fi -+ KRB5_AC_ENABLE_DNS - ],dnl - [AC_LIBRARY_NET] - )])dnl diff --git a/krb5.spec b/krb5.spec index ae1a948..41e81e8 100644 --- a/krb5.spec +++ b/krb5.spec @@ -85,7 +85,6 @@ Source39: krb5-krb5kdc.conf Patch0: downstream-ksu-pam-integration.patch Patch1: downstream-SELinux-integration.patch -Patch3: downstream-netlib-and-dns.patch Patch4: downstream-fix-debuginfo-with-y.tab.c.patch Patch5: downstream-Remove-3des-support.patch Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -320,7 +319,6 @@ CPPFLAGS="`echo $DEFINES $INCLUDES`" --without-krb5-config \ --with-system-et \ --with-system-ss \ - --with-netlib=-lresolv \ --with-tcl \ --enable-dns-for-realm \ --with-ldap \ @@ -335,6 +333,11 @@ CPPFLAGS="`echo $DEFINES $INCLUDES`" --with-lmdb \ || (cat config.log; exit 1) +# Check we have required features enabled +for x in DNS_LOOKUP DNS_LOOKUP_REALM; do + grep -q "#define KRB5_${x} 1" include/autoconf.h +done + # Sanity check the KDC_RUN_DIR. pushd include make osconf.h @@ -673,6 +676,7 @@ exit 0 %changelog * Tue Aug 02 2022 Andreas Schneider - 1.19.2-12 - Use baserelease to set the release number +- Do not define netlib, but use autoconf detection for res_* functions * Thu Jul 21 2022 Fedora Release Engineering - 1.19.2-11.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild From 0c2f5dcbe51e58baf592f8c479dd6080055516da Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Tue, 2 Aug 2022 11:21:47 +0200 Subject: [PATCH 268/304] Add missing BR for resolv_wrapper to run t_discover_uri.py --- krb5.spec | 2 ++ 1 file changed, 2 insertions(+) diff --git a/krb5.spec b/krb5.spec index 41e81e8..4d0dffb 100644 --- a/krb5.spec +++ b/krb5.spec @@ -149,6 +149,7 @@ BuildRequires: hostname BuildRequires: iproute BuildRequires: python3-pyrad BuildRequires: procps-ng +BuildRequires: resolv_wrapper %endif # Need KDFs. This is the "real" version @@ -677,6 +678,7 @@ exit 0 * Tue Aug 02 2022 Andreas Schneider - 1.19.2-12 - Use baserelease to set the release number - Do not define netlib, but use autoconf detection for res_* functions +- Add missing BR for resolv_wrapper to run t_discover_uri.py * Thu Jul 21 2022 Fedora Release Engineering - 1.19.2-11.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild From c13bf943d82a1284cc233f81531e613d21b4592b Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 9 Nov 2022 11:38:44 +0100 Subject: [PATCH 269/304] Fix integer overflows in PAC parsing (CVE-2022-42898) Resolves: rhbz#2143011 Signed-off-by: Julien Rische --- Fix-integer-overflows-in-PAC-parsing.patch | 106 +++++++++++++++++++++ krb5.spec | 7 +- 2 files changed, 112 insertions(+), 1 deletion(-) create mode 100644 Fix-integer-overflows-in-PAC-parsing.patch diff --git a/Fix-integer-overflows-in-PAC-parsing.patch b/Fix-integer-overflows-in-PAC-parsing.patch new file mode 100644 index 0000000..272e34e --- /dev/null +++ b/Fix-integer-overflows-in-PAC-parsing.patch @@ -0,0 +1,106 @@ +From 06d30f43a41029d83248bbac1a9b65fc09987597 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 17 Oct 2022 20:25:11 -0400 +Subject: [PATCH] Fix integer overflows in PAC parsing + +In krb5_parse_pac(), check for buffer counts large enough to threaten +integer overflow in the header length and memory length calculations. +Avoid potential integer overflows when checking the length of each +buffer. + +CVE-2022-42898: + +In MIT krb5 releases 1.8 and later, an authenticated attacker may be +able to cause a KDC or kadmind process to crash by reading beyond the +bounds of allocated memory, creating a denial of service. A +privileged attacker may similarly be able to cause a Kerberos or GSS +application service to crash. On 32-bit platforms, an attacker can +also cause insufficient memory to be allocated for the result, +potentially leading to remote code execution in a KDC, kadmind, or GSS +or Kerberos application server process. An attacker with the +privileges of a cross-realm KDC may be able to extract secrets from +the KDC process's memory by having them copied into the PAC of a new +ticket. + +ticket: 9074 (new) +tags: pullup +target_version: 1.20-next +target_version: 1.19-next +--- + src/lib/krb5/krb/pac.c | 9 +++++++-- + src/lib/krb5/krb/t_pac.c | 18 ++++++++++++++++++ + 2 files changed, 25 insertions(+), 2 deletions(-) + +diff --git a/src/lib/krb5/krb/pac.c b/src/lib/krb5/krb/pac.c +index 950beda657..1b9ef12276 100644 +--- a/src/lib/krb5/krb/pac.c ++++ b/src/lib/krb5/krb/pac.c +@@ -27,6 +27,8 @@ + #include "k5-int.h" + #include "authdata.h" + ++#define MAX_BUFFERS 4096 ++ + /* draft-brezak-win2k-krb-authz-00 */ + + /* +@@ -316,6 +318,9 @@ krb5_pac_parse(krb5_context context, + if (version != 0) + return EINVAL; + ++ if (cbuffers < 1 || cbuffers > MAX_BUFFERS) ++ return ERANGE; ++ + header_len = PACTYPE_LENGTH + (cbuffers * PAC_INFO_BUFFER_LENGTH); + if (len < header_len) + return ERANGE; +@@ -348,8 +353,8 @@ krb5_pac_parse(krb5_context context, + krb5_pac_free(context, pac); + return EINVAL; + } +- if (buffer->Offset < header_len || +- buffer->Offset + buffer->cbBufferSize > len) { ++ if (buffer->Offset < header_len || buffer->Offset > len || ++ buffer->cbBufferSize > len - buffer->Offset) { + krb5_pac_free(context, pac); + return ERANGE; + } +diff --git a/src/lib/krb5/krb/t_pac.c b/src/lib/krb5/krb/t_pac.c +index ee47152ee4..ccd165380d 100644 +--- a/src/lib/krb5/krb/t_pac.c ++++ b/src/lib/krb5/krb/t_pac.c +@@ -431,6 +431,16 @@ static const unsigned char s4u_pac_ent_xrealm[] = { + 0x8a, 0x81, 0x9c, 0x9c, 0x00, 0x00, 0x00, 0x00 + }; + ++static const unsigned char fuzz1[] = { ++ 0x00, 0x00, 0x00, 0x10, 0x00, 0x00, 0x00, 0x00, ++ 0x06, 0xff, 0xff, 0xff, 0x00, 0x00, 0xf5 ++}; ++ ++static const unsigned char fuzz2[] = { ++ 0x00, 0x00, 0x00, 0x20, 0x00, 0x00, 0x00, 0x00, ++ 0x20, 0x20 ++}; ++ + static const char *s4u_principal = "w2k8u@ACME.COM"; + static const char *s4u_enterprise = "w2k8u@abc@ACME.COM"; + +@@ -646,6 +656,14 @@ main(int argc, char **argv) + krb5_free_principal(context, sep); + } + ++ /* Check problematic PACs found by fuzzing. */ ++ ret = krb5_pac_parse(context, fuzz1, sizeof(fuzz1), &pac); ++ if (!ret) ++ err(context, ret, "krb5_pac_parse should have failed"); ++ ret = krb5_pac_parse(context, fuzz2, sizeof(fuzz2), &pac); ++ if (!ret) ++ err(context, ret, "krb5_pac_parse should have failed"); ++ + /* + * Test empty free + */ +-- +2.37.3 + diff --git a/krb5.spec b/krb5.spec index 4d0dffb..c6039dc 100644 --- a/krb5.spec +++ b/krb5.spec @@ -34,7 +34,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 12 +%global baserelease 13 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -120,6 +120,7 @@ Patch40: Try-harder-to-avoid-password-change-replay-errors.patch Patch41: Add-configure-variable-for-default-PKCS-11-module.patch Patch42: downstream-Allow-krad-UDP-TCP-localhost-connection-with-FIPS.patch Patch43: Read-GSS-configuration-files-with-mtime-0.patch +Patch44: Fix-integer-overflows-in-PAC-parsing.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -675,6 +676,10 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Wed Nov 09 2022 Julien Rische - 1.19.2-13 +- Fix integer overflows in PAC parsing (CVE-2022-42898) +- Resolves: rhbz#2143011 + * Tue Aug 02 2022 Andreas Schneider - 1.19.2-12 - Use baserelease to set the release number - Do not define netlib, but use autoconf detection for res_* functions From 56cee506e7918e93bfe86bf2b7f960ab05cff0df Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 23 Nov 2022 18:27:49 +0100 Subject: [PATCH 270/304] New upstream version (1.20.1) Also set "supportedCMSTypes" to SHA-512/256 with RSA encryption Resolves: rhbz#2124463 Resolves: rhbz#2114766 Signed-off-by: Julien Rische --- .gitignore | 95 +- ... 0001-downstream-ksu-pam-integration.patch | 21 +- ... 0002-downstream-SELinux-integration.patch | 100 +- ...ownstream-fix-debuginfo-with-y.tab.c.patch | 9 +- ... 0004-downstream-Remove-3des-support.patch | 1015 +- ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 84 +- ...-krad-UDP-TCP-localhost-connection-w.patch | 11 +- ...-variable-for-default-PKCS-11-module.patch | 30 +- ...asonable-supportedCMSTypes-in-PKINIT.patch | 159 + 0009-Simplify-plugin-loading-code.patch | 622 + Add-APIs-for-marshalling-credentials.patch | 220 - ...P_GET_CRED_LIST-for-faster-iteration.patch | 358 - ...detection-of-the-OpenSSL-3-KDF-inter.patch | 25 - ...canonicalization-helper-to-k5test.py.patch | 84 - ...ith-keytab-to-defer-canonicalization.patch | 60 - ...context-after-failed-open-in-libkdb5.patch | 35 - ...up-gssapi_krb5-ccache-name-functions.patch | 193 - ...CM-flag-transmission-for-remove_cred.patch | 103 - Fix-KCM-retrieval-support-for-sssd.patch | 62 - ...-deref-on-TGS-inner-body-null-server.patch | 45 - Fix-integer-overflows-in-PAC-parsing.patch | 106 - Fix-k5tls-module-for-OpenSSL-3.patch | 58 - ...in-k-with-fallback-or-referral-realm.patch | 64 - ...aks-on-error-in-kadm5-init-functions.patch | 664 - ...pkcs11-build-issues-with-openssl-3.0.patch | 552 - ...incipal-realm-canonicalization-cases.patch | 96 - Handle-OpenSSL-3-s-providers.patch | 301 - ...teration-fallback-work-with-sssd-kcm.patch | 26 - ...dejagnu-kadmin-tests-to-Python-tests.patch | 1750 -- ...GSS-configuration-files-with-mtime-0.patch | 71 - Remove-TCL-based-libkadm5-API-tests.patch | 18229 ---------------- ...ecated-OpenSSL-calls-from-softpkcs11.patch | 150 - Support-host-based-GSS-initiator-names.patch | 578 - ...-avoid-password-change-replay-errors.patch | 91 - Use-KCM_OP_RETRIEVE-in-KCM-client.patch | 235 - ...KDF-and-KRB5KDF-for-deriving-long-te.patch | 482 - ...SSL-s-SSKDF-in-PKINIT-when-available.patch | 408 - ...nstead-of-SHA1-for-PKINIT-CMS-digest.patch | 113 - Use-asan-in-one-of-the-CI-builds.patch | 22 - ...ackported-version-of-OpenSSL-3-KDF-i.patch | 752 - krb5-krad-larger-attrs.patch | 69 - krb5-krad-remote.patch | 209 - krb5.spec | 127 +- sources | 4 +- 44 files changed, 1453 insertions(+), 27035 deletions(-) rename downstream-ksu-pam-integration.patch => 0001-downstream-ksu-pam-integration.patch (98%) rename downstream-SELinux-integration.patch => 0002-downstream-SELinux-integration.patch (94%) rename downstream-fix-debuginfo-with-y.tab.c.patch => 0003-downstream-fix-debuginfo-with-y.tab.c.patch (90%) rename downstream-Remove-3des-support.patch => 0004-downstream-Remove-3des-support.patch (92%) rename downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch => 0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch (91%) rename downstream-Allow-krad-UDP-TCP-localhost-connection-with-FIPS.patch => 0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch (90%) rename Add-configure-variable-for-default-PKCS-11-module.patch => 0007-Add-configure-variable-for-default-PKCS-11-module.patch (93%) create mode 100644 0008-Set-reasonable-supportedCMSTypes-in-PKINIT.patch create mode 100644 0009-Simplify-plugin-loading-code.patch delete mode 100644 Add-APIs-for-marshalling-credentials.patch delete mode 100644 Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch delete mode 100644 Add-buildsystem-detection-of-the-OpenSSL-3-KDF-inter.patch delete mode 100644 Add-hostname-canonicalization-helper-to-k5test.py.patch delete mode 100644 Allow-kinit-with-keytab-to-defer-canonicalization.patch delete mode 100644 Clean-up-context-after-failed-open-in-libkdb5.patch delete mode 100644 Clean-up-gssapi_krb5-ccache-name-functions.patch delete mode 100644 Fix-KCM-flag-transmission-for-remove_cred.patch delete mode 100644 Fix-KCM-retrieval-support-for-sssd.patch delete mode 100644 Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch delete mode 100644 Fix-integer-overflows-in-PAC-parsing.patch delete mode 100644 Fix-k5tls-module-for-OpenSSL-3.patch delete mode 100644 Fix-kadmin-k-with-fallback-or-referral-realm.patch delete mode 100644 Fix-leaks-on-error-in-kadm5-init-functions.patch delete mode 100644 Fix-softpkcs11-build-issues-with-openssl-3.0.patch delete mode 100644 Fix-some-principal-realm-canonicalization-cases.patch delete mode 100644 Handle-OpenSSL-3-s-providers.patch delete mode 100644 Make-KCM-iteration-fallback-work-with-sssd-kcm.patch delete mode 100644 Move-some-dejagnu-kadmin-tests-to-Python-tests.patch delete mode 100644 Read-GSS-configuration-files-with-mtime-0.patch delete mode 100644 Remove-TCL-based-libkadm5-API-tests.patch delete mode 100644 Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch delete mode 100644 Support-host-based-GSS-initiator-names.patch delete mode 100644 Try-harder-to-avoid-password-change-replay-errors.patch delete mode 100644 Use-KCM_OP_RETRIEVE-in-KCM-client.patch delete mode 100644 Use-OpenSSL-s-KBKDF-and-KRB5KDF-for-deriving-long-te.patch delete mode 100644 Use-OpenSSL-s-SSKDF-in-PKINIT-when-available.patch delete mode 100644 Use-SHA256-instead-of-SHA1-for-PKINIT-CMS-digest.patch delete mode 100644 Use-asan-in-one-of-the-CI-builds.patch delete mode 100644 downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch delete mode 100644 krb5-krad-larger-attrs.patch delete mode 100644 krb5-krad-remote.patch diff --git a/.gitignore b/.gitignore index c3c3cb9..7fa0027 100644 --- a/.gitignore +++ b/.gitignore @@ -1,49 +1,50 @@ -krb5-1.3.4.tar.gz -krb5-1.3.5.tar.gz -krb5-1.3.5.tar.gz.asc -krb5-1.3.6.tar.gz -krb5-1.3.6.tar.gz.asc -krb5-1.4.tar.gz -krb5-1.4.tar.gz.asc -krb5-1.4.1.tar.gz -krb5-1.4.1.tar.gz.asc -krb5-1.4.2.tar.gz -krb5-1.4.2.tar.gz.asc -krb5-1.4.3.tar.gz -krb5-1.4.3.tar.gz.asc -krb5-1.5.tar.gz -krb5-1.5.tar.gz.asc -krb5-1.6.tar.gz -krb5-1.6.tar.gz.asc -krb5-1.6-pdf.tar.gz -krb5-1.6.1.tar.gz -krb5-1.6.1.tar.gz.asc -krb5-1.6.1-pdf.tar.gz -krb5-1.6.2.tar.gz -krb5-1.6.2.tar.gz.asc -krb5-1.6.2-pdf.tar.gz -krb5-1.6.3.tar.gz -krb5-1.6.3.tar.gz.asc -krb5-1.6.3-pdf.tar.gz -krb5-1.7.tar.gz -krb5-1.7.tar.gz.asc -krb5-1.7-pdf.tar.gz -krb5-1.7.1.tar.gz -krb5-1.7.1.tar.gz.asc -krb5-1.7.1-pdf.tar.gz -krb5-1.8.tar.gz -krb5-1.8.tar.gz.asc -krb5-appl-1.0.tar.gz -krb5-appl-1.0.tar.gz.asc -krb5-1.8-pdf.tar.gz -krb5-1.8.1.tar.gz -krb5-1.8.1.tar.gz.asc -krb5-1.8.1-pdf.tar.gz -krb5-1.8.2.tar.gz.asc -krb5-1.8.2-pdf.tar.gz -krb5-1.8.3.tar.gz -krb5-1.8.3.tar.gz.asc -krb5-1.8.3-pdf.tar.gz +/results_krb5 +/krb5-1.3.4.tar.gz +/krb5-1.3.5.tar.gz +/krb5-1.3.5.tar.gz.asc +/krb5-1.3.6.tar.gz +/krb5-1.3.6.tar.gz.asc +/krb5-1.4.tar.gz +/krb5-1.4.tar.gz.asc +/krb5-1.4.1.tar.gz +/krb5-1.4.1.tar.gz.asc +/krb5-1.4.2.tar.gz +/krb5-1.4.2.tar.gz.asc +/krb5-1.4.3.tar.gz +/krb5-1.4.3.tar.gz.asc +/krb5-1.5.tar.gz +/krb5-1.5.tar.gz.asc +/krb5-1.6.tar.gz +/krb5-1.6.tar.gz.asc +/krb5-1.6-pdf.tar.gz +/krb5-1.6.1.tar.gz +/krb5-1.6.1.tar.gz.asc +/krb5-1.6.1-pdf.tar.gz +/krb5-1.6.2.tar.gz +/krb5-1.6.2.tar.gz.asc +/krb5-1.6.2-pdf.tar.gz +/krb5-1.6.3.tar.gz +/krb5-1.6.3.tar.gz.asc +/krb5-1.6.3-pdf.tar.gz +/krb5-1.7.tar.gz +/krb5-1.7.tar.gz.asc +/krb5-1.7-pdf.tar.gz +/krb5-1.7.1.tar.gz +/krb5-1.7.1.tar.gz.asc +/krb5-1.7.1-pdf.tar.gz +/krb5-1.8.tar.gz +/krb5-1.8.tar.gz.asc +/krb5-appl-1.0.tar.gz +/krb5-appl-1.0.tar.gz.asc +/krb5-1.8-pdf.tar.gz +/krb5-1.8.1.tar.gz +/krb5-1.8.1.tar.gz.asc +/krb5-1.8.1-pdf.tar.gz +/krb5-1.8.2.tar.gz.asc +/krb5-1.8.2-pdf.tar.gz +/krb5-1.8.3.tar.gz +/krb5-1.8.3.tar.gz.asc +/krb5-1.8.3-pdf.tar.gz /krb5-1.9-beta2.tar.gz /krb5-1.9-beta2.tar.gz.asc /krb5-1.9-beta2-pdf.tar.bz2 @@ -199,3 +200,5 @@ krb5-1.8.3-pdf.tar.gz /krb5-1.19.1.tar.gz.asc /krb5-1.19.2.tar.gz /krb5-1.19.2.tar.gz.asc +/krb5-1.20.1.tar.gz +/krb5-1.20.1.tar.gz.asc diff --git a/downstream-ksu-pam-integration.patch b/0001-downstream-ksu-pam-integration.patch similarity index 98% rename from downstream-ksu-pam-integration.patch rename to 0001-downstream-ksu-pam-integration.patch index bebe946..2b737c0 100644 --- a/downstream-ksu-pam-integration.patch +++ b/0001-downstream-ksu-pam-integration.patch @@ -1,4 +1,4 @@ -From 659b3b4a654b879ce84ad8fb4621dde5ae693385 Mon Sep 17 00:00:00 2001 +From 37d69135d0be7f46732c401cdbb3abc075bf4117 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] [downstream] ksu pam integration @@ -30,10 +30,10 @@ Last-updated: krb5-1.18-beta1 create mode 100644 src/clients/ksu/pam.h diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 024d6370c..ca9fcf664 100644 +index 9920476f91..bf9da35bbc 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 -@@ -1677,3 +1677,72 @@ if test "$with_ldap" = yes; then +@@ -1458,3 +1458,72 @@ if test "$with_ldap" = yes; then OPENLDAP_PLUGIN=yes fi ])dnl @@ -107,7 +107,7 @@ index 024d6370c..ca9fcf664 100644 +])dnl + diff --git a/src/clients/ksu/Makefile.in b/src/clients/ksu/Makefile.in -index 8b4edce4d..9d58f29b5 100644 +index 8b4edce4d8..9d58f29b5d 100644 --- a/src/clients/ksu/Makefile.in +++ b/src/clients/ksu/Makefile.in @@ -3,12 +3,14 @@ BUILDTOP=$(REL)..$(S).. @@ -145,7 +145,7 @@ index 8b4edce4d..9d58f29b5 100644 clean: $(RM) ksu diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c -index af1286172..931f05404 100644 +index af12861729..931f054041 100644 --- a/src/clients/ksu/main.c +++ b/src/clients/ksu/main.c @@ -26,6 +26,7 @@ @@ -303,7 +303,7 @@ index af1286172..931f05404 100644 } diff --git a/src/clients/ksu/pam.c b/src/clients/ksu/pam.c new file mode 100644 -index 000000000..cbfe48704 +index 0000000000..cbfe487047 --- /dev/null +++ b/src/clients/ksu/pam.c @@ -0,0 +1,389 @@ @@ -698,7 +698,7 @@ index 000000000..cbfe48704 +#endif diff --git a/src/clients/ksu/pam.h b/src/clients/ksu/pam.h new file mode 100644 -index 000000000..0ab76569c +index 0000000000..0ab76569cb --- /dev/null +++ b/src/clients/ksu/pam.h @@ -0,0 +1,57 @@ @@ -760,10 +760,10 @@ index 000000000..0ab76569c +void appl_pam_cleanup(void); +#endif diff --git a/src/configure.ac b/src/configure.ac -index 4eb080784..693f76a81 100644 +index f03028b5fd..aa970b0447 100644 --- a/src/configure.ac +++ b/src/configure.ac -@@ -1389,6 +1389,8 @@ AC_SUBST([VERTO_VERSION]) +@@ -1400,6 +1400,8 @@ AC_SUBST([VERTO_VERSION]) AC_PATH_PROG(GROFF, groff) @@ -772,3 +772,6 @@ index 4eb080784..693f76a81 100644 # Make localedir work in autoconf 2.5x. if test "${localedir+set}" != set; then localedir='$(datadir)/locale' +-- +2.38.1 + diff --git a/downstream-SELinux-integration.patch b/0002-downstream-SELinux-integration.patch similarity index 94% rename from downstream-SELinux-integration.patch rename to 0002-downstream-SELinux-integration.patch index 48b058b..4271d66 100644 --- a/downstream-SELinux-integration.patch +++ b/0002-downstream-SELinux-integration.patch @@ -1,4 +1,4 @@ -From 97966ffaac6bf9f2e09ac33a16b15794b31d51de Mon Sep 17 00:00:00 2001 +From c6b58ed180ed91b579d322ff5004f68750f1eb4f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] [downstream] SELinux integration @@ -36,7 +36,9 @@ The selabel APIs for looking up the context should be thread-safe (per Red Hat #273081), so switching to using them instead of matchpathcon(), which we used earlier, is some improvement. -Last-updated: krb5-1.18-beta1 +Last-updated: krb5-1.20.1 +[jrische@redhat.com: Replace deprecated security_context_t by char *: + - src/util/support/selinux.c] --- src/aclocal.m4 | 48 +++ src/build-tools/krb5-config.in | 3 +- @@ -61,13 +63,13 @@ Last-updated: krb5-1.18-beta1 .../kdb/ldap/ldap_util/kdb5_ldap_services.c | 11 +- src/util/profile/prof_file.c | 3 +- src/util/support/Makefile.in | 3 +- - src/util/support/selinux.c | 406 ++++++++++++++++++ - 24 files changed, 573 insertions(+), 21 deletions(-) + src/util/support/selinux.c | 405 ++++++++++++++++++ + 24 files changed, 572 insertions(+), 21 deletions(-) create mode 100644 src/include/k5-label.h create mode 100644 src/util/support/selinux.c diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index ca9fcf664..5afb96e58 100644 +index bf9da35bbc..01283f482e 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 @@ -85,6 +85,7 @@ AC_SUBST_FILE(libnodeps_frag) @@ -78,7 +80,7 @@ index ca9fcf664..5afb96e58 100644 KRB5_LIB_PARAMS KRB5_AC_INITFINI KRB5_AC_ENABLE_THREADS -@@ -1745,4 +1746,51 @@ AC_SUBST(PAM_LIBS) +@@ -1526,4 +1527,51 @@ AC_SUBST(PAM_LIBS) AC_SUBST(PAM_MAN) AC_SUBST(NON_PAM_MAN) ])dnl @@ -131,7 +133,7 @@ index ca9fcf664..5afb96e58 100644 +AC_SUBST(SELINUX_LIBS) +])dnl diff --git a/src/build-tools/krb5-config.in b/src/build-tools/krb5-config.in -index dead0dddc..fef3e054f 100755 +index dead0dddce..fef3e054fc 100755 --- a/src/build-tools/krb5-config.in +++ b/src/build-tools/krb5-config.in @@ -41,6 +41,7 @@ DL_LIB='@DL_LIB@' @@ -152,7 +154,7 @@ index dead0dddc..fef3e054f 100755 echo $lib_flags diff --git a/src/config/pre.in b/src/config/pre.in -index 3752174c7..0d2068575 100644 +index a0c60c70b3..7eaa2f351c 100644 --- a/src/config/pre.in +++ b/src/config/pre.in @@ -177,6 +177,7 @@ LD = $(PURE) @LD@ @@ -163,7 +165,7 @@ index 3752174c7..0d2068575 100644 INSTALL=@INSTALL@ INSTALL_STRIP= -@@ -403,7 +404,7 @@ SUPPORT_LIB = -l$(SUPPORT_LIBNAME) +@@ -379,7 +380,7 @@ SUPPORT_LIB = -l$(SUPPORT_LIBNAME) # HESIOD_LIBS is -lhesiod... HESIOD_LIBS = @HESIOD_LIBS@ @@ -173,10 +175,10 @@ index 3752174c7..0d2068575 100644 GSS_LIBS = $(GSS_KRB5_LIB) # needs fixing if ever used on macOS! diff --git a/src/configure.ac b/src/configure.ac -index 693f76a81..dd2cad3ee 100644 +index aa970b0447..40545f2bfc 100644 --- a/src/configure.ac +++ b/src/configure.ac -@@ -1391,6 +1391,8 @@ AC_PATH_PROG(GROFF, groff) +@@ -1402,6 +1402,8 @@ AC_PATH_PROG(GROFF, groff) KRB5_WITH_PAM @@ -186,7 +188,7 @@ index 693f76a81..dd2cad3ee 100644 if test "${localedir+set}" != set; then localedir='$(datadir)/locale' diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index cf524252f..efb523689 100644 +index 44dc1eeb3f..c3aecba7d4 100644 --- a/src/include/k5-int.h +++ b/src/include/k5-int.h @@ -128,6 +128,7 @@ typedef unsigned char u_char; @@ -199,7 +201,7 @@ index cf524252f..efb523689 100644 #define KRB5_KDB_MAX_RLIFE (60*60*24*7) /* one week */ diff --git a/src/include/k5-label.h b/src/include/k5-label.h new file mode 100644 -index 000000000..dfaaa847c +index 0000000000..dfaaa847cb --- /dev/null +++ b/src/include/k5-label.h @@ -0,0 +1,32 @@ @@ -236,7 +238,7 @@ index 000000000..dfaaa847c +#endif +#endif diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 045334a08..db80063eb 100644 +index c0194c3c94..7e1dea2cbf 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin @@ -87,6 +87,12 @@ @@ -253,7 +255,7 @@ index 045334a08..db80063eb 100644 #include diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c -index 634ba4a8b..cea7939f4 100644 +index a89b5144f6..4d6cc0bdf9 100644 --- a/src/kadmin/dbutil/dump.c +++ b/src/kadmin/dbutil/dump.c @@ -148,12 +148,21 @@ create_ofile(char *ofile, char **tmpname) @@ -288,10 +290,10 @@ index 634ba4a8b..cea7939f4 100644 com_err(progname, errno, _("while creating 'ok' file, '%s'"), file_ok); goto cleanup; diff --git a/src/kdc/main.c b/src/kdc/main.c -index 3be6dcb07..24d441e16 100644 +index 38b9299066..085afc9220 100644 --- a/src/kdc/main.c +++ b/src/kdc/main.c -@@ -872,7 +872,7 @@ write_pid_file(const char *path) +@@ -848,7 +848,7 @@ write_pid_file(const char *path) FILE *file; unsigned long pid; @@ -301,10 +303,10 @@ index 3be6dcb07..24d441e16 100644 return errno; pid = (unsigned long) getpid(); diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c -index 498ca599a..c6b8efc28 100644 +index f2341d720f..ffdac9f397 100644 --- a/src/kprop/kpropd.c +++ b/src/kprop/kpropd.c -@@ -487,6 +487,9 @@ doit(int fd) +@@ -488,6 +488,9 @@ doit(int fd) krb5_enctype etype; int database_fd; char host[INET6_ADDRSTRLEN + 1]; @@ -314,7 +316,7 @@ index 498ca599a..c6b8efc28 100644 signal_wrapper(SIGALRM, alarm_handler); alarm(params.iprop_resync_timeout); -@@ -542,9 +545,15 @@ doit(int fd) +@@ -543,9 +546,15 @@ doit(int fd) free(name); exit(1); } @@ -331,7 +333,7 @@ index 498ca599a..c6b8efc28 100644 KRB5_LOCKMODE_EXCLUSIVE | KRB5_LOCKMODE_DONTBLOCK); if (retval) { diff --git a/src/lib/kadm5/logger.c b/src/lib/kadm5/logger.c -index c6885edf2..9aec3c05e 100644 +index c6885edf2a..9aec3c05e8 100644 --- a/src/lib/kadm5/logger.c +++ b/src/lib/kadm5/logger.c @@ -309,7 +309,7 @@ krb5_klog_init(krb5_context kcontext, char *ename, char *whoami, krb5_boolean do @@ -353,7 +355,7 @@ index c6885edf2..9aec3c05e 100644 set_cloexec_file(f); log_control.log_entries[lindex].lfu_filep = f; diff --git a/src/lib/kdb/kdb_log.c b/src/lib/kdb/kdb_log.c -index 2659a2501..e9b95fce5 100644 +index 2659a25018..e9b95fce59 100644 --- a/src/lib/kdb/kdb_log.c +++ b/src/lib/kdb/kdb_log.c @@ -480,7 +480,7 @@ ulog_map(krb5_context context, const char *logname, uint32_t ulogentries) @@ -366,7 +368,7 @@ index 2659a2501..e9b95fce5 100644 retval = errno; goto cleanup; diff --git a/src/lib/krb5/ccache/cc_dir.c b/src/lib/krb5/ccache/cc_dir.c -index 7b100a0ec..5683a0433 100644 +index 1da40b51d0..f3ab7340a6 100644 --- a/src/lib/krb5/ccache/cc_dir.c +++ b/src/lib/krb5/ccache/cc_dir.c @@ -183,10 +183,19 @@ write_primary_file(const char *primary_path, const char *contents) @@ -416,7 +418,7 @@ index 7b100a0ec..5683a0433 100644 _("Credential cache directory %s does not exist"), dirname); diff --git a/src/lib/krb5/keytab/kt_file.c b/src/lib/krb5/keytab/kt_file.c -index e510211fc..f3ea28c8e 100644 +index e510211fc5..f3ea28c8ec 100644 --- a/src/lib/krb5/keytab/kt_file.c +++ b/src/lib/krb5/keytab/kt_file.c @@ -735,14 +735,14 @@ krb5_ktfileint_open(krb5_context context, krb5_keytab id, int mode) @@ -437,10 +439,10 @@ index e510211fc..f3ea28c8e 100644 goto report_errno; writevno = 1; diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c -index 7073459f0..e9b99f4ca 100644 +index 3369fc4ba6..95f82cda03 100644 --- a/src/lib/krb5/os/trace.c +++ b/src/lib/krb5/os/trace.c -@@ -458,7 +458,7 @@ krb5_set_trace_filename(krb5_context context, const char *filename) +@@ -459,7 +459,7 @@ krb5_set_trace_filename(krb5_context context, const char *filename) fd = malloc(sizeof(*fd)); if (fd == NULL) return ENOMEM; @@ -450,7 +452,7 @@ index 7073459f0..e9b99f4ca 100644 free(fd); return errno; diff --git a/src/plugins/kdb/db2/adb_openclose.c b/src/plugins/kdb/db2/adb_openclose.c -index 7db30a33b..2b9d01921 100644 +index 7db30a33b0..2b9d01921d 100644 --- a/src/plugins/kdb/db2/adb_openclose.c +++ b/src/plugins/kdb/db2/adb_openclose.c @@ -152,7 +152,7 @@ osa_adb_init_db(osa_adb_db_t *dbp, char *filename, char *lockfilename, @@ -463,7 +465,7 @@ index 7db30a33b..2b9d01921 100644 * maybe someone took away write permission so we could only * get shared locks? diff --git a/src/plugins/kdb/db2/kdb_db2.c b/src/plugins/kdb/db2/kdb_db2.c -index 1a476b586..b40bb2240 100644 +index 2c163d91cc..9a344a603e 100644 --- a/src/plugins/kdb/db2/kdb_db2.c +++ b/src/plugins/kdb/db2/kdb_db2.c @@ -694,8 +694,8 @@ ctx_create_db(krb5_context context, krb5_db2_context *dbc) @@ -478,7 +480,7 @@ index 1a476b586..b40bb2240 100644 retval = errno; goto cleanup; diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_open.c b/src/plugins/kdb/db2/libdb2/btree/bt_open.c -index 2977b17f3..d5809a5a9 100644 +index 2977b17f3a..d5809a5a93 100644 --- a/src/plugins/kdb/db2/libdb2/btree/bt_open.c +++ b/src/plugins/kdb/db2/libdb2/btree/bt_open.c @@ -60,6 +60,7 @@ static char sccsid[] = "@(#)bt_open.c 8.11 (Berkeley) 11/2/95"; @@ -499,7 +501,7 @@ index 2977b17f3..d5809a5a9 100644 } else { diff --git a/src/plugins/kdb/db2/libdb2/hash/hash.c b/src/plugins/kdb/db2/libdb2/hash/hash.c -index 862dbb164..686a960c9 100644 +index 862dbb1640..686a960c96 100644 --- a/src/plugins/kdb/db2/libdb2/hash/hash.c +++ b/src/plugins/kdb/db2/libdb2/hash/hash.c @@ -51,6 +51,7 @@ static char sccsid[] = "@(#)hash.c 8.12 (Berkeley) 11/7/95"; @@ -520,7 +522,7 @@ index 862dbb164..686a960c9 100644 (void)fcntl(hashp->fp, F_SETFD, 1); } diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_open.c b/src/plugins/kdb/db2/libdb2/recno/rec_open.c -index d8b26e701..b0daa7c02 100644 +index d8b26e7011..b0daa7c021 100644 --- a/src/plugins/kdb/db2/libdb2/recno/rec_open.c +++ b/src/plugins/kdb/db2/libdb2/recno/rec_open.c @@ -51,6 +51,7 @@ static char sccsid[] = "@(#)rec_open.c 8.12 (Berkeley) 11/18/94"; @@ -542,7 +544,7 @@ index d8b26e701..b0daa7c02 100644 if (fname != NULL && fcntl(rfd, F_SETFD, 1) == -1) { diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c -index e87688d66..30f7c00ab 100644 +index e87688d666..30f7c00ab5 100644 --- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c +++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_services.c @@ -190,7 +190,7 @@ kdb5_ldap_stash_service_password(int argc, char **argv) @@ -579,7 +581,7 @@ index e87688d66..30f7c00ab 100644 if (newfile == NULL) { com_err(me, errno, _("Error creating file %s"), tmp_file); diff --git a/src/util/profile/prof_file.c b/src/util/profile/prof_file.c -index aa951df05..79f9500f6 100644 +index aa951df05f..79f9500f69 100644 --- a/src/util/profile/prof_file.c +++ b/src/util/profile/prof_file.c @@ -33,6 +33,7 @@ @@ -600,7 +602,7 @@ index aa951df05..79f9500f6 100644 retval = errno; if (retval == 0) diff --git a/src/util/support/Makefile.in b/src/util/support/Makefile.in -index 86d5a950a..1052d53a1 100644 +index 86d5a950a6..1052d53a1e 100644 --- a/src/util/support/Makefile.in +++ b/src/util/support/Makefile.in @@ -74,6 +74,7 @@ IPC_SYMS= \ @@ -622,10 +624,10 @@ index 86d5a950a..1052d53a1 100644 diff --git a/src/util/support/selinux.c b/src/util/support/selinux.c new file mode 100644 -index 000000000..6d41f3244 +index 0000000000..807d039da3 --- /dev/null +++ b/src/util/support/selinux.c -@@ -0,0 +1,406 @@ +@@ -0,0 +1,405 @@ +/* + * Copyright 2007,2008,2009,2011,2012,2013,2016 Red Hat, Inc. All Rights Reserved. + * @@ -724,17 +726,16 @@ index 000000000..6d41f3244 + } +} + -+static security_context_t ++static char * +push_fscreatecon(const char *pathname, mode_t mode) +{ -+ security_context_t previous, configuredsc, currentsc, derivedsc; ++ char *previous, *configuredsc, *currentsc, *genpath; ++ const char *derivedsc, *fullpath, *currentuser; + context_t current, derived; -+ const char *fullpath, *currentuser; -+ char *genpath; + -+ previous = configuredsc = currentsc = derivedsc = NULL; ++ previous = configuredsc = currentsc = genpath = NULL; ++ derivedsc = NULL; + current = derived = NULL; -+ genpath = NULL; + + fullpath = pathname; + @@ -862,7 +863,7 @@ index 000000000..6d41f3244 +} + +static void -+pop_fscreatecon(security_context_t previous) ++pop_fscreatecon(char *previous) +{ + if (!is_selinux_enabled()) { + return; @@ -916,7 +917,7 @@ index 000000000..6d41f3244 +{ + FILE *fp; + int errno_save; -+ security_context_t ctx; ++ char *ctx; + + if ((strcmp(mode, "r") == 0) || + (strcmp(mode, "rb") == 0)) { @@ -942,7 +943,7 @@ index 000000000..6d41f3244 +{ + int fd; + int errno_save; -+ security_context_t ctx; ++ char *ctx; + + k5_once(&labeled_once, label_mutex_init); + k5_mutex_lock(&labeled_mutex); @@ -963,7 +964,7 @@ index 000000000..6d41f3244 +{ + int ret; + int errno_save; -+ security_context_t ctx; ++ char *ctx; + + k5_once(&labeled_once, label_mutex_init); + k5_mutex_lock(&labeled_mutex); @@ -984,7 +985,7 @@ index 000000000..6d41f3244 +{ + int ret; + int errno_save; -+ security_context_t ctx; ++ char *ctx; + + k5_once(&labeled_once, label_mutex_init); + k5_mutex_lock(&labeled_mutex); @@ -1005,7 +1006,7 @@ index 000000000..6d41f3244 +{ + int fd; + int errno_save; -+ security_context_t ctx; ++ char *ctx; + mode_t mode; + va_list ap; + @@ -1032,3 +1033,6 @@ index 000000000..6d41f3244 +} + +#endif /* USE_SELINUX */ +-- +2.38.1 + diff --git a/downstream-fix-debuginfo-with-y.tab.c.patch b/0003-downstream-fix-debuginfo-with-y.tab.c.patch similarity index 90% rename from downstream-fix-debuginfo-with-y.tab.c.patch rename to 0003-downstream-fix-debuginfo-with-y.tab.c.patch index 494152c..3c58cc1 100644 --- a/downstream-fix-debuginfo-with-y.tab.c.patch +++ b/0003-downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,4 +1,4 @@ -From 98b50683165089bf7bd9d91f953abbd79a8b1b08 Mon Sep 17 00:00:00 2001 +From c7fe7cbd61f7debf052ddcc6cc5f01bb7e4f5385 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] [downstream] fix debuginfo with y.tab.c @@ -14,7 +14,7 @@ Last-updated: krb5-1.9 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/src/kadmin/cli/Makefile.in b/src/kadmin/cli/Makefile.in -index adfea6e2b..d1327e400 100644 +index adfea6e2b5..d1327e400b 100644 --- a/src/kadmin/cli/Makefile.in +++ b/src/kadmin/cli/Makefile.in @@ -37,3 +37,8 @@ clean-unix:: @@ -27,7 +27,7 @@ index adfea6e2b..d1327e400 100644 + $(YACC.y) $< + $(CP) y.tab.c $@ diff --git a/src/plugins/kdb/ldap/ldap_util/Makefile.in b/src/plugins/kdb/ldap/ldap_util/Makefile.in -index 8669c2436..a22f23c02 100644 +index 8669c2436c..a22f23c02c 100644 --- a/src/plugins/kdb/ldap/ldap_util/Makefile.in +++ b/src/plugins/kdb/ldap/ldap_util/Makefile.in @@ -20,7 +20,7 @@ $(PROG): $(OBJS) $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIB) $(GETDATE) @@ -39,3 +39,6 @@ index 8669c2436..a22f23c02 100644 install: $(INSTALL_PROGRAM) $(PROG) ${DESTDIR}$(ADMIN_BINDIR)/$(PROG) +-- +2.38.1 + diff --git a/downstream-Remove-3des-support.patch b/0004-downstream-Remove-3des-support.patch similarity index 92% rename from downstream-Remove-3des-support.patch rename to 0004-downstream-Remove-3des-support.patch index 3d351eb..4ec3a0f 100644 --- a/downstream-Remove-3des-support.patch +++ b/0004-downstream-Remove-3des-support.patch @@ -1,4 +1,4 @@ -From defa8816e26ab9f5a8f0b61e7bebad67175c433e Mon Sep 17 00:00:00 2001 +From 7b40250066bbcc529b5348b68199c58fbad82376 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] [downstream] Remove 3des support @@ -8,13 +8,17 @@ des3-hmac-sha1, des3-cbc-sha1-kd). Update all tests and documentation to user other enctypes. Mark the 3DES enctypes UNSUPPORTED and retain their constants. -Last-updated: 1.19-beta1 +Last-updated: 1.20-final [antorres@redhat.com: remove diffs for: - src/kdamin/testing/proto/kdc.conf.proto - src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp - src/lib/kadm5/unit-test/api.current/get-principal-v2.exp - src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp since they were removed by Remove-TCL-based-libkadm5-API-tests.patch] +[jrische@redhat.com: restore supportedCMSTypes (not using 3DES any more): + - src/plugins/preauth/pkinit/pkinit_crypto.h + - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c + - src/plugins/preauth/pkinit/pkinit_clnt.c] --- doc/admin/advanced/retiring-des.rst | 11 + doc/admin/conf_files/kdc_conf.rst | 7 +- @@ -24,35 +28,34 @@ Last-updated: 1.19-beta1 doc/conf.py | 2 +- doc/mitK5features.rst | 2 +- src/Makefile.in | 4 +- - src/configure.ac | 1 - + src/configure.ac | 4 +- src/include/krb5/krb5.hin | 10 +- - src/kadmin/testing/proto/kdc.conf.proto | 4 +- src/kdc/kdc_util.c | 4 - src/lib/crypto/Makefile.in | 8 +- src/lib/crypto/builtin/Makefile.in | 6 +- src/lib/crypto/builtin/des/ISSUES | 13 - - src/lib/crypto/builtin/des/Makefile.in | 80 ---- - src/lib/crypto/builtin/des/d3_aead.c | 133 ------ - src/lib/crypto/builtin/des/d3_kysched.c | 51 --- - src/lib/crypto/builtin/des/deps | 150 ------- + src/lib/crypto/builtin/des/Makefile.in | 82 ---- + src/lib/crypto/builtin/des/d3_aead.c | 137 ------ + src/lib/crypto/builtin/des/d3_kysched.c | 55 --- + src/lib/crypto/builtin/des/deps | 146 ------- src/lib/crypto/builtin/des/des_int.h | 285 ------------- - src/lib/crypto/builtin/des/des_keys.c | 40 -- + src/lib/crypto/builtin/des/des_keys.c | 38 -- src/lib/crypto/builtin/des/destest.c | 240 ----------- src/lib/crypto/builtin/des/doc/libdes.doc | 208 --------- - src/lib/crypto/builtin/des/f_aead.c | 173 -------- + src/lib/crypto/builtin/des/f_aead.c | 177 -------- src/lib/crypto/builtin/des/f_cbc.c | 256 ------------ - src/lib/crypto/builtin/des/f_cksum.c | 136 ------ - src/lib/crypto/builtin/des/f_parity.c | 56 --- - src/lib/crypto/builtin/des/f_sched.c | 359 ---------------- - src/lib/crypto/builtin/des/f_tables.c | 370 ---------------- + src/lib/crypto/builtin/des/f_cksum.c | 141 ------- + src/lib/crypto/builtin/des/f_parity.c | 64 --- + src/lib/crypto/builtin/des/f_sched.c | 363 ---------------- + src/lib/crypto/builtin/des/f_tables.c | 375 ----------------- src/lib/crypto/builtin/des/f_tables.h | 285 ------------- - src/lib/crypto/builtin/des/key_sched.c | 62 --- + src/lib/crypto/builtin/des/key_sched.c | 66 --- src/lib/crypto/builtin/des/keytest.data | 171 -------- src/lib/crypto/builtin/des/t_verify.c | 395 ------------------ - src/lib/crypto/builtin/des/weak_key.c | 86 ---- - .../crypto/builtin/enc_provider/Makefile.in | 6 +- - src/lib/crypto/builtin/enc_provider/deps | 13 - - src/lib/crypto/builtin/enc_provider/des3.c | 105 ----- + src/lib/crypto/builtin/des/weak_key.c | 90 ---- + .../crypto/builtin/enc_provider/Makefile.in | 5 +- + src/lib/crypto/builtin/enc_provider/deps | 11 - + src/lib/crypto/builtin/enc_provider/des3.c | 109 ----- src/lib/crypto/crypto_tests/t_cf2.expected | 1 - src/lib/crypto/crypto_tests/t_cf2.in | 5 - src/lib/crypto/crypto_tests/t_cksums.c | 10 - @@ -61,45 +64,40 @@ Last-updated: 1.19-beta1 src/lib/crypto/crypto_tests/t_encrypt.c | 1 - src/lib/crypto/crypto_tests/t_short.c | 1 - src/lib/crypto/crypto_tests/t_str2key.c | 52 --- + src/lib/crypto/crypto_tests/vectors.c | 4 - src/lib/crypto/krb/Makefile.in | 3 - src/lib/crypto/krb/cksumtypes.c | 6 - - src/lib/crypto/krb/crypto_int.h | 16 - + src/lib/crypto/krb/crypto_int.h | 11 - src/lib/crypto/krb/default_state.c | 10 - src/lib/crypto/krb/enctype_util.c | 3 + src/lib/crypto/krb/etypes.c | 21 - src/lib/crypto/krb/prf_des.c | 47 --- - src/lib/crypto/krb/random_to_key.c | 45 -- + src/lib/crypto/krb/random_to_key.c | 28 -- src/lib/crypto/libk5crypto.exports | 1 - src/lib/crypto/openssl/Makefile.in | 8 +- src/lib/crypto/openssl/des/Makefile.in | 20 - - src/lib/crypto/openssl/des/deps | 15 - - src/lib/crypto/openssl/des/des_keys.c | 40 -- + src/lib/crypto/openssl/des/deps | 14 - + src/lib/crypto/openssl/des/des_keys.c | 39 -- .../crypto/openssl/enc_provider/Makefile.in | 3 - src/lib/crypto/openssl/enc_provider/deps | 11 - - src/lib/crypto/openssl/enc_provider/des3.c | 184 -------- + src/lib/crypto/openssl/enc_provider/des3.c | 188 --------- + src/lib/crypto/openssl/kdf.c | 2 - src/lib/gssapi/krb5/accept_sec_context.c | 1 - src/lib/gssapi/krb5/gssapiP_krb5.h | 6 +- src/lib/gssapi/krb5/k5seal.c | 35 +- src/lib/gssapi/krb5/k5sealiov.c | 27 +- - src/lib/gssapi/krb5/k5unseal.c | 102 ++--- + src/lib/gssapi/krb5/k5unseal.c | 88 ++-- src/lib/gssapi/krb5/k5unsealiov.c | 38 +- src/lib/gssapi/krb5/util_crypt.c | 11 - - .../api.current/chpass-principal-v2.exp | 4 +- - .../api.current/get-principal-v2.exp | 4 +- - .../api.current/randkey-principal-v2.exp | 4 +- src/lib/krb5/krb/init_ctx.c | 3 - src/lib/krb5/krb/s4u_creds.c | 2 - src/lib/krb5/krb/t_etypes.c | 48 +-- src/lib/krb5/os/t_trace.c | 4 +- src/lib/krb5/os/t_trace.ref | 2 +- src/plugins/preauth/pkinit/pkcs11.h | 6 +- - src/plugins/preauth/pkinit/pkinit_clnt.c | 8 - - src/plugins/preauth/pkinit/pkinit_crypto.h | 12 - - .../preauth/pkinit/pkinit_crypto_openssl.c | 38 -- - src/plugins/preauth/pkinit/pkinit_kdf_test.c | 31 -- + src/plugins/preauth/pkinit/pkinit_crypto.h | 10 +- + src/plugins/preauth/pkinit/pkinit_kdf_test.c | 30 -- src/plugins/preauth/spake/t_vectors.c | 25 -- - src/tests/dejagnu/config/default.exp | 78 ---- - src/tests/dejagnu/krb-standalone/kprop.exp | 2 +- src/tests/gssapi/t_enctypes.py | 33 +- src/tests/gssapi/t_invalid.c | 12 - src/tests/gssapi/t_pcontok.c | 16 +- @@ -111,7 +109,7 @@ Last-updated: 1.19-beta1 src/tests/t_salt.py | 5 +- src/util/k5test.py | 7 - .../leash/htmlhelp/html/Encryption_Types.htm | 13 - - 95 files changed, 160 insertions(+), 4835 deletions(-) + 89 files changed, 151 insertions(+), 4713 deletions(-) delete mode 100644 src/lib/crypto/builtin/des/ISSUES delete mode 100644 src/lib/crypto/builtin/des/Makefile.in delete mode 100644 src/lib/crypto/builtin/des/d3_aead.c @@ -140,7 +138,7 @@ Last-updated: 1.19-beta1 delete mode 100644 src/lib/crypto/openssl/enc_provider/des3.c diff --git a/doc/admin/advanced/retiring-des.rst b/doc/admin/advanced/retiring-des.rst -index 38f76d3f4..d5e3c30c0 100644 +index 38f76d3f45..d5e3c30c04 100644 --- a/doc/admin/advanced/retiring-des.rst +++ b/doc/admin/advanced/retiring-des.rst @@ -10,6 +10,13 @@ ability have rendered DES vulnerable to brute force attacks on its 56-bit @@ -169,10 +167,10 @@ index 38f76d3f4..d5e3c30c0 100644 ------------- diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst -index 1dc958d62..3a72aabef 100644 +index 74a0a2acef..846c58ed82 100644 --- a/doc/admin/conf_files/kdc_conf.rst +++ b/doc/admin/conf_files/kdc_conf.rst -@@ -848,8 +848,6 @@ Encryption types marked as "weak" and "deprecated" are available for +@@ -854,8 +854,6 @@ Encryption types marked as "weak" and "deprecated" are available for compatibility but not recommended for use. ==================================================== ========================================================= @@ -181,7 +179,7 @@ index 1dc958d62..3a72aabef 100644 aes256-cts-hmac-sha1-96 aes256-cts aes256-sha1 AES-256 CTS mode with 96-bit SHA-1 HMAC aes128-cts-hmac-sha1-96 aes128-cts aes128-sha1 AES-128 CTS mode with 96-bit SHA-1 HMAC aes256-cts-hmac-sha384-192 aes256-sha2 AES-256 CTS mode with 192-bit SHA-384 HMAC -@@ -858,7 +856,6 @@ arcfour-hmac rc4-hmac arcfour-hmac-md5 RC4 with HMAC/MD5 (deprecat +@@ -864,7 +862,6 @@ arcfour-hmac rc4-hmac arcfour-hmac-md5 RC4 with HMAC/MD5 (deprecat arcfour-hmac-exp rc4-hmac-exp arcfour-hmac-md5-exp Exportable RC4 with HMAC/MD5 (weak) camellia256-cts-cmac camellia256-cts Camellia-256 CTS mode with CMAC camellia128-cts-cmac camellia128-cts Camellia-128 CTS mode with CMAC @@ -189,7 +187,7 @@ index 1dc958d62..3a72aabef 100644 aes The AES family: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, aes256-cts-hmac-sha384-192, and aes128-cts-hmac-sha256-128 rc4 The RC4 family: arcfour-hmac camellia The Camellia family: camellia256-cts-cmac and camellia128-cts-cmac -@@ -870,8 +867,8 @@ from the current list by prefixing them with a minus sign ("-"). +@@ -876,8 +873,8 @@ from the current list by prefixing them with a minus sign ("-"). Types or families can be prefixed with a plus sign ("+") for symmetry; it has the same meaning as just listing the type or family. For example, "``DEFAULT -rc4``" would be the default set of encryption @@ -201,7 +199,7 @@ index 1dc958d62..3a72aabef 100644 While **aes128-cts** and **aes256-cts** are supported for all Kerberos diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst -index 694922c0d..c4d5499d3 100644 +index 694922c0d9..c4d5499d3b 100644 --- a/doc/admin/enctypes.rst +++ b/doc/admin/enctypes.rst @@ -129,7 +129,7 @@ enctype weak? krb5 Windows @@ -229,7 +227,7 @@ index 694922c0d..c4d5499d3 100644 Migrating away from older encryption types diff --git a/doc/admin/troubleshoot.rst b/doc/admin/troubleshoot.rst -index ade5e1f87..e4dc54f7e 100644 +index ade5e1f87a..e4dc54f7e5 100644 --- a/doc/admin/troubleshoot.rst +++ b/doc/admin/troubleshoot.rst @@ -73,11 +73,10 @@ credential verification failed: KDC has no support for encryption type @@ -249,7 +247,7 @@ index ade5e1f87..e4dc54f7e 100644 .. _err_cert_chain_cert_expired: diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst -index 5542d9850..0cb2e81bd 100644 +index a0d4f26701..5f34dea5e8 100644 --- a/doc/appdev/refs/macros/index.rst +++ b/doc/appdev/refs/macros/index.rst @@ -36,7 +36,6 @@ Public @@ -261,7 +259,7 @@ index 5542d9850..0cb2e81bd 100644 CKSUMTYPE_NIST_SHA.rst CKSUMTYPE_RSA_MD4.rst diff --git a/doc/conf.py b/doc/conf.py -index 14158ae81..a876fd633 100644 +index fa0eb80f1f..12168fa695 100644 --- a/doc/conf.py +++ b/doc/conf.py @@ -278,7 +278,7 @@ else: @@ -274,7 +272,7 @@ index 14158ae81..a876fd633 100644 .. |copy| unicode:: U+000A9 ''' diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst -index 4954bb3aa..92ce2a772 100644 +index ca2d6ef117..100c64a1c1 100644 --- a/doc/mitK5features.rst +++ b/doc/mitK5features.rst @@ -37,7 +37,7 @@ Database backends: LDAP, DB2, LMDB @@ -287,7 +285,7 @@ index 4954bb3aa..92ce2a772 100644 Interoperability ---------------- diff --git a/src/Makefile.in b/src/Makefile.in -index 7d2507ef8..c16715ac7 100644 +index 8f14e9bf2c..ba3bb18eec 100644 --- a/src/Makefile.in +++ b/src/Makefile.in @@ -130,7 +130,7 @@ WINMAKEFILES=Makefile \ @@ -309,19 +307,26 @@ index 7d2507ef8..c16715ac7 100644 ##DOS## $(WCONFIG) config < $@.in > $@ ##DOS##lib\crypto\builtin\camellia\Makefile: lib\crypto\builtin\camellia\Makefile.in $(MKFDEP) diff --git a/src/configure.ac b/src/configure.ac -index dd2cad3ee..3e1052db7 100644 +index 40545f2bfc..8dc864718d 100644 --- a/src/configure.ac +++ b/src/configure.ac -@@ -1480,7 +1480,6 @@ V5_AC_OUTPUT_MAKEFILE(. - lib/crypto lib/crypto/krb lib/crypto/$CRYPTO_IMPL - lib/crypto/$CRYPTO_IMPL/enc_provider - lib/crypto/$CRYPTO_IMPL/hash_provider -- lib/crypto/$CRYPTO_IMPL/des - lib/crypto/$CRYPTO_IMPL/md4 lib/crypto/$CRYPTO_IMPL/md5 - lib/crypto/$CRYPTO_IMPL/sha1 lib/crypto/$CRYPTO_IMPL/sha2 - lib/crypto/$CRYPTO_IMPL/aes lib/crypto/$CRYPTO_IMPL/camellia +@@ -1489,12 +1489,12 @@ V5_AC_OUTPUT_MAKEFILE(. + lib lib/kdb + + lib/crypto lib/crypto/krb lib/crypto/crypto_tests +- lib/crypto/builtin lib/crypto/builtin/des ++ lib/crypto/builtin + lib/crypto/builtin/aes lib/crypto/builtin/camellia + lib/crypto/builtin/md4 lib/crypto/builtin/md5 + lib/crypto/builtin/sha1 lib/crypto/builtin/sha2 + lib/crypto/builtin/enc_provider lib/crypto/builtin/hash_provider +- lib/crypto/openssl lib/crypto/openssl/des ++ lib/crypto/openssl + lib/crypto/openssl/enc_provider lib/crypto/openssl/hash_provider + + lib/krb5 lib/krb5/error_tables lib/krb5/asn.1 lib/krb5/ccache diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index db80063eb..63e67a2ba 100644 +index 7e1dea2cbf..fb9f2a366c 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin @@ -426,8 +426,8 @@ typedef struct _krb5_crypto_iov { @@ -347,20 +352,20 @@ index db80063eb..63e67a2ba 100644 #define ENCTYPE_AES128_CTS_HMAC_SHA1_96 0x0011 /**< RFC 3962 */ #define ENCTYPE_AES256_CTS_HMAC_SHA1_96 0x0012 /**< RFC 3962 */ #define ENCTYPE_AES128_CTS_HMAC_SHA256_128 0x0013 /**< RFC 8009 */ -@@ -458,7 +458,7 @@ typedef struct _krb5_crypto_iov { +@@ -463,7 +463,7 @@ typedef struct _krb5_crypto_iov { #define CKSUMTYPE_RSA_MD5 0x0007 #define CKSUMTYPE_RSA_MD5_DES 0x0008 #define CKSUMTYPE_NIST_SHA 0x0009 -#define CKSUMTYPE_HMAC_SHA1_DES3 0x000c +#define CKSUMTYPE_HMAC_SHA1_DES3 0x000c /* @deprecated removed */ + #define CKSUMTYPE_SHA1 0x000e /**< RFC 3961 */ #define CKSUMTYPE_HMAC_SHA1_96_AES128 0x000f /**< RFC 3962. Used with ENCTYPE_AES128_CTS_HMAC_SHA1_96 */ - #define CKSUMTYPE_HMAC_SHA1_96_AES256 0x0010 /**< RFC 3962. Used with diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index 60f30c4f4..c65375aef 100644 +index 9f2a67d189..b7a9aa4992 100644 --- a/src/kdc/kdc_util.c +++ b/src/kdc/kdc_util.c -@@ -1017,8 +1017,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) +@@ -1111,8 +1111,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) name = "rsaEncryption-EnvOID"; else if (ktype == ENCTYPE_RSA_ES_OAEP_ENV) name = "id-RSAES-OAEP-EnvOID"; @@ -369,7 +374,7 @@ index 60f30c4f4..c65375aef 100644 else return krb5_enctype_to_name(ktype, FALSE, buf, buflen); -@@ -1605,8 +1603,6 @@ krb5_boolean +@@ -1704,8 +1702,6 @@ krb5_boolean enctype_requires_etype_info_2(krb5_enctype enctype) { switch(enctype) { @@ -379,28 +384,25 @@ index 60f30c4f4..c65375aef 100644 case ENCTYPE_ARCFOUR_HMAC_EXP : return 0; diff --git a/src/lib/crypto/Makefile.in b/src/lib/crypto/Makefile.in -index c3fcfd7e8..890d54adf 100644 +index 10e8c74cf8..25c4f40cc3 100644 --- a/src/lib/crypto/Makefile.in +++ b/src/lib/crypto/Makefile.in -@@ -13,7 +13,7 @@ STOBJLISTS=$(CRYPTO_IMPL)/enc_provider/OBJS.ST \ - $(CRYPTO_IMPL)/hash_provider/OBJS.ST \ - $(CRYPTO_IMPL)/md4/OBJS.ST $(CRYPTO_IMPL)/md5/OBJS.ST \ - $(CRYPTO_IMPL)/sha1/OBJS.ST $(CRYPTO_IMPL)/sha2/OBJS.ST \ -- $(CRYPTO_IMPL)/aes/OBJS.ST $(CRYPTO_IMPL)/des/OBJS.ST \ -+ $(CRYPTO_IMPL)/aes/OBJS.ST \ - $(CRYPTO_IMPL)/camellia/OBJS.ST krb/OBJS.ST \ - $(CRYPTO_IMPL)/OBJS.ST +@@ -10,12 +10,12 @@ LIBMINOR=1 + RELDIR=crypto -@@ -21,7 +21,7 @@ SUBDIROBJLISTS=$(CRYPTO_IMPL)/enc_provider/OBJS.ST \ - $(CRYPTO_IMPL)/hash_provider/OBJS.ST \ - $(CRYPTO_IMPL)/md4/OBJS.ST $(CRYPTO_IMPL)/md5/OBJS.ST \ - $(CRYPTO_IMPL)/sha1/OBJS.ST $(CRYPTO_IMPL)/sha2/OBJS.ST \ -- $(CRYPTO_IMPL)/aes/OBJS.ST $(CRYPTO_IMPL)/des/OBJS.ST \ -+ $(CRYPTO_IMPL)/aes/OBJS.ST \ - $(CRYPTO_IMPL)/camellia/OBJS.ST krb/OBJS.ST \ - $(CRYPTO_IMPL)/OBJS.ST + STOBJLISTS=krb/OBJS.ST \ +- builtin/OBJS.ST builtin/des/OBJS.ST \ ++ builtin/OBJS.ST \ + builtin/aes/OBJS.ST builtin/camellia/OBJS.ST \ + builtin/md4/OBJS.ST builtin/md5/OBJS.ST \ + builtin/sha1/OBJS.ST builtin/sha2/OBJS.ST \ + builtin/enc_provider/OBJS.ST builtin/hash_provider/OBJS.ST \ +- openssl/OBJS.ST openssl/des/OBJS.ST \ ++ openssl/OBJS.ST \ + openssl/enc_provider/OBJS.ST openssl/hash_provider/OBJS.ST -@@ -34,8 +34,8 @@ SHLIB_EXPDEPLIBS= $(SUPPORT_DEPLIB) + SUBDIROBJLISTS=$(STOBJLISTS) +@@ -28,8 +28,8 @@ SHLIB_EXPDEPLIBS= $(SUPPORT_DEPLIB) SHLIB_LDFLAGS= $(LDFLAGS) @SHLIB_RPATH_DIRS@ ##DOS##LIBNAME=$(OUTPRE)crypto.lib @@ -412,7 +414,7 @@ index c3fcfd7e8..890d54adf 100644 all-unix: all-liblinks install-unix: install-libs diff --git a/src/lib/crypto/builtin/Makefile.in b/src/lib/crypto/builtin/Makefile.in -index baf5d974f..82adf1dec 100644 +index daf19da195..c9e967c807 100644 --- a/src/lib/crypto/builtin/Makefile.in +++ b/src/lib/crypto/builtin/Makefile.in @@ -1,6 +1,6 @@ @@ -420,11 +422,11 @@ index baf5d974f..82adf1dec 100644 BUILDTOP=$(REL)..$(S)..$(S).. -SUBDIRS=camellia des aes md4 md5 sha1 sha2 enc_provider hash_provider +SUBDIRS=camellia aes md4 md5 sha1 sha2 enc_provider hash_provider - LOCALINCLUDES = -I$(srcdir)/../krb -I$(srcdir) + LOCALINCLUDES=-I$(srcdir)/../krb $(CRYPTO_IMPL_CFLAGS) ##DOS##BUILDTOP = ..\..\.. -@@ -22,7 +22,7 @@ SRCS=\ - $(srcdir)/init.c \ +@@ -25,7 +25,7 @@ SRCS=\ + $(srcdir)/kdf.c \ $(srcdir)/pbkdf2.c -STOBJLISTS= des/OBJS.ST md4/OBJS.ST \ @@ -432,7 +434,7 @@ index baf5d974f..82adf1dec 100644 md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \ enc_provider/OBJS.ST \ hash_provider/OBJS.ST \ -@@ -30,7 +30,7 @@ STOBJLISTS= des/OBJS.ST md4/OBJS.ST \ +@@ -33,7 +33,7 @@ STOBJLISTS= des/OBJS.ST md4/OBJS.ST \ camellia/OBJS.ST \ OBJS.ST @@ -443,7 +445,7 @@ index baf5d974f..82adf1dec 100644 hash_provider/OBJS.ST \ diff --git a/src/lib/crypto/builtin/des/ISSUES b/src/lib/crypto/builtin/des/ISSUES deleted file mode 100644 -index 157891103..000000000 +index 1578911033..0000000000 --- a/src/lib/crypto/builtin/des/ISSUES +++ /dev/null @@ -1,13 +0,0 @@ @@ -462,13 +464,13 @@ index 157891103..000000000 -const? diff --git a/src/lib/crypto/builtin/des/Makefile.in b/src/lib/crypto/builtin/des/Makefile.in deleted file mode 100644 -index 54b329d0f..000000000 +index 397ac87ed4..0000000000 --- a/src/lib/crypto/builtin/des/Makefile.in +++ /dev/null -@@ -1,80 +0,0 @@ +@@ -1,82 +0,0 @@ -mydir=lib$(S)crypto$(S)builtin$(S)des -BUILDTOP=$(REL)..$(S)..$(S)..$(S).. --LOCALINCLUDES = -I$(srcdir)/.. -I$(srcdir)/../../krb +-LOCALINCLUDES=-I$(srcdir)/../../krb $(CRYPTO_IMPL_CFLAGS) - -##DOS##BUILDTOP = ..\..\..\.. -##DOS##PREFIXDIR = builtin\des @@ -526,7 +528,9 @@ index 54b329d0f..000000000 - -all-unix: all-libobjs - --check-unix: verify destest +-check-unix: check-unix-@CRYPTO_BUILTIN_TESTS@ +-check-unix-no: +-check-unix-yes: verify destest - $(RUN_TEST) ./verify -z - $(RUN_TEST) ./verify -m - $(RUN_TEST) ./verify @@ -548,10 +552,10 @@ index 54b329d0f..000000000 - diff --git a/src/lib/crypto/builtin/des/d3_aead.c b/src/lib/crypto/builtin/des/d3_aead.c deleted file mode 100644 -index bddf75a47..000000000 +index fb83f73b43..0000000000 --- a/src/lib/crypto/builtin/des/d3_aead.c +++ /dev/null -@@ -1,133 +0,0 @@ +@@ -1,137 +0,0 @@ -/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -/* - * Copyright (C) 2008 by the Massachusetts Institute of Technology. @@ -580,6 +584,8 @@ index bddf75a47..000000000 -#include "des_int.h" -#include "f_tables.h" - +-#ifdef K5_BUILTIN_DES +- -void -krb5int_des3_cbc_encrypt(krb5_crypto_iov *data, unsigned long num_data, - const mit_des_key_schedule ks1, @@ -685,12 +691,14 @@ index bddf75a47..000000000 - store_32_be(ocipherr, ivec + 4); - } -} +- +-#endif /* K5_BUILTIN_DES */ diff --git a/src/lib/crypto/builtin/des/d3_kysched.c b/src/lib/crypto/builtin/des/d3_kysched.c deleted file mode 100644 -index ebd1050b1..000000000 +index 55fb9449b5..0000000000 --- a/src/lib/crypto/builtin/des/d3_kysched.c +++ /dev/null -@@ -1,51 +0,0 @@ +@@ -1,55 +0,0 @@ -/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -/* - * Copyright 1995 by Richard P. Basch. All Rights Reserved. @@ -714,9 +722,11 @@ index ebd1050b1..000000000 - * express or implied warranty. - */ - --#include "k5-int.h" +-#include "crypto_int.h" -#include "des_int.h" - +-#ifdef K5_BUILTIN_DES +- -int -mit_des3_key_sched(mit_des3_cblock k, mit_des3_key_schedule schedule) -{ @@ -742,20 +752,20 @@ index ebd1050b1..000000000 - /* if key was good, return 0 */ - return 0; -} +- +-#endif /* K5_BUILTIN_DES */ diff --git a/src/lib/crypto/builtin/des/deps b/src/lib/crypto/builtin/des/deps deleted file mode 100644 -index a1db1f36e..000000000 +index 1c1239d696..0000000000 --- a/src/lib/crypto/builtin/des/deps +++ /dev/null -@@ -1,150 +0,0 @@ +@@ -1,146 +0,0 @@ -# -# Generated makefile dependencies follow. -# -d3_aead.so d3_aead.po $(OUTPRE)d3_aead.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ -- $(srcdir)/../aes/aes.h $(srcdir)/../aes/brg_types.h \ -- $(srcdir)/../crypto_mod.h $(srcdir)/../sha2/sha2.h \ - $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ - $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ - $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ @@ -767,20 +777,18 @@ index a1db1f36e..000000000 -d3_kysched.so d3_kysched.po $(OUTPRE)d3_kysched.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- d3_kysched.c des_int.h +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h d3_kysched.c des_int.h -des_keys.so des_keys.po $(OUTPRE)des_keys.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(srcdir)/../aes/aes.h \ -- $(srcdir)/../aes/brg_types.h $(srcdir)/../crypto_mod.h \ -- $(srcdir)/../sha2/sha2.h $(top_srcdir)/include/k5-buf.h \ +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ - $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ - $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ - $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ @@ -791,8 +799,6 @@ index a1db1f36e..000000000 -f_aead.so f_aead.po $(OUTPRE)f_aead.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ -- $(srcdir)/../aes/aes.h $(srcdir)/../aes/brg_types.h \ -- $(srcdir)/../crypto_mod.h $(srcdir)/../sha2/sha2.h \ - $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ - $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ - $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ @@ -803,69 +809,71 @@ index a1db1f36e..000000000 - des_int.h f_aead.c f_tables.h -f_cksum.so f_cksum.po $(OUTPRE)f_cksum.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ -- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h des_int.h f_cksum.c \ -- f_tables.h +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des_int.h f_cksum.c f_tables.h -f_parity.so f_parity.po $(OUTPRE)f_parity.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- des_int.h f_parity.c --f_sched.so f_sched.po $(OUTPRE)f_sched.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ -- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ - $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ - $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ - $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ - $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ - $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ - $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h des_int.h f_sched.c +- $(top_srcdir)/include/socket-utils.h des_int.h f_parity.c +-f_sched.so f_sched.po $(OUTPRE)f_sched.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ +- $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ +- $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des_int.h f_sched.c -f_tables.so f_tables.po $(OUTPRE)f_tables.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- des_int.h f_tables.c f_tables.h +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h f_tables.c \ +- f_tables.h -key_sched.so key_sched.po $(OUTPRE)key_sched.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- des_int.h key_sched.c +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h key_sched.c -weak_key.so weak_key.po $(OUTPRE)weak_key.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- des_int.h weak_key.c +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_int.h weak_key.c -destest.so destest.po $(OUTPRE)destest.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(top_srcdir)/include/k5-buf.h \ @@ -900,7 +908,7 @@ index a1db1f36e..000000000 - des_int.h t_verify.c diff --git a/src/lib/crypto/builtin/des/des_int.h b/src/lib/crypto/builtin/des/des_int.h deleted file mode 100644 -index f8dc6b296..000000000 +index f8dc6b296a..0000000000 --- a/src/lib/crypto/builtin/des/des_int.h +++ /dev/null @@ -1,285 +0,0 @@ @@ -1191,10 +1199,10 @@ index f8dc6b296..000000000 -#endif /*DES_INTERNAL_DEFS*/ diff --git a/src/lib/crypto/builtin/des/des_keys.c b/src/lib/crypto/builtin/des/des_keys.c deleted file mode 100644 -index 32b119aad..000000000 +index 027b09d728..0000000000 --- a/src/lib/crypto/builtin/des/des_keys.c +++ /dev/null -@@ -1,40 +0,0 @@ +@@ -1,38 +0,0 @@ -/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -/* lib/crypto/builtin/des/des_keys.c - Key functions used by Kerberos code */ -/* @@ -1224,20 +1232,18 @@ index 32b119aad..000000000 -#include "crypto_int.h" -#include "des_int.h" - +-#ifdef K5_BUILTIN_DES_KEY_PARITY +- -void -k5_des_fixup_key_parity(unsigned char *keybits) -{ - mit_des_fixup_key_parity(keybits); -} - --krb5_boolean --k5_des_is_weak_key(unsigned char *keybits) --{ -- return mit_des_is_weak_key(keybits); --} +-#endif /* K5_BUILTIN_DES_KEY_PARITY */ diff --git a/src/lib/crypto/builtin/des/destest.c b/src/lib/crypto/builtin/des/destest.c deleted file mode 100644 -index 52114304e..000000000 +index 52114304e3..0000000000 --- a/src/lib/crypto/builtin/des/destest.c +++ /dev/null @@ -1,240 +0,0 @@ @@ -1483,7 +1489,7 @@ index 52114304e..000000000 -} diff --git a/src/lib/crypto/builtin/des/doc/libdes.doc b/src/lib/crypto/builtin/des/doc/libdes.doc deleted file mode 100644 -index 6e9431ed2..000000000 +index 6e9431ed2e..0000000000 --- a/src/lib/crypto/builtin/des/doc/libdes.doc +++ /dev/null @@ -1,208 +0,0 @@ @@ -1697,10 +1703,10 @@ index 6e9431ed2..000000000 -string length desired. diff --git a/src/lib/crypto/builtin/des/f_aead.c b/src/lib/crypto/builtin/des/f_aead.c deleted file mode 100644 -index 71b8dff4d..000000000 +index f887735820..0000000000 --- a/src/lib/crypto/builtin/des/f_aead.c +++ /dev/null -@@ -1,173 +0,0 @@ +@@ -1,177 +0,0 @@ -/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -/* - * Copyright (C) 2008 by the Massachusetts Institute of Technology. @@ -1729,6 +1735,8 @@ index 71b8dff4d..000000000 -#include "des_int.h" -#include "f_tables.h" - +-#ifdef K5_BUILTIN_DES +- -const mit_des_cblock mit_des_zeroblock /* = all zero */; - -void @@ -1874,9 +1882,11 @@ index 71b8dff4d..000000000 - DES_DO_DECRYPT_1 (*left, *right, kp); -} -#endif +- +-#endif /* K5_BUILTIN_DES */ diff --git a/src/lib/crypto/builtin/des/f_cbc.c b/src/lib/crypto/builtin/des/f_cbc.c deleted file mode 100644 -index 84d5382f2..000000000 +index 84d5382f22..0000000000 --- a/src/lib/crypto/builtin/des/f_cbc.c +++ /dev/null @@ -1,256 +0,0 @@ @@ -2138,10 +2148,10 @@ index 84d5382f2..000000000 -} diff --git a/src/lib/crypto/builtin/des/f_cksum.c b/src/lib/crypto/builtin/des/f_cksum.c deleted file mode 100644 -index cb482b009..000000000 +index 615a947f4a..0000000000 --- a/src/lib/crypto/builtin/des/f_cksum.c +++ /dev/null -@@ -1,136 +0,0 @@ +@@ -1,141 +0,0 @@ -/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -/* lib/crypto/builtin/des/f_cksum.c */ -/* @@ -2173,9 +2183,12 @@ index cb482b009..000000000 -/* - * des_cbc_cksum.c - compute an 8 byte checksum using DES in CBC mode - */ +-#include "crypto_int.h" -#include "des_int.h" -#include "f_tables.h" - +-#ifdef K5_BUILTIN_DES +- -/* - * This routine performs DES cipher-block-chaining checksum operation, - * a.k.a. Message Authentication Code. It ALWAYS encrypts from input @@ -2278,12 +2291,14 @@ index cb482b009..000000000 - */ - return right & 0xFFFFFFFFUL; -} +- +-#endif /* K5_BUILTIN_DES */ diff --git a/src/lib/crypto/builtin/des/f_parity.c b/src/lib/crypto/builtin/des/f_parity.c deleted file mode 100644 -index 460b5061b..000000000 +index a658878f6f..0000000000 --- a/src/lib/crypto/builtin/des/f_parity.c +++ /dev/null -@@ -1,56 +0,0 @@ +@@ -1,64 +0,0 @@ -/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -/* - * These routines check and fix parity of encryption keys for the DES @@ -2295,9 +2310,11 @@ index 460b5061b..000000000 - * Mark Eichin -- Cygnus Support - */ - -- +-#include "crypto_int.h" -#include "des_int.h" - +-#ifdef K5_BUILTIN_DES_KEY_PARITY +- -/* - * des_fixup_key_parity: Forces odd parity per byte; parity is bits - * 8,16,...64 in des order, implies 0, 8, 16, ... @@ -2320,6 +2337,10 @@ index 460b5061b..000000000 - return; -} - +-#endif /* K5_BUILTIN_DES_KEY_PARITY */ +- +-#ifdef K5_BUILTIN_DES +- -/* - * des_check_key_parity: returns true iff key has the correct des parity. - * See des_fix_key_parity for the definition of @@ -2340,12 +2361,14 @@ index 460b5061b..000000000 - - return(1); -} +- +-#endif /* K5_BUILTIN_DES */ diff --git a/src/lib/crypto/builtin/des/f_sched.c b/src/lib/crypto/builtin/des/f_sched.c deleted file mode 100644 -index 666a510fb..000000000 +index bbc88a1c8d..0000000000 --- a/src/lib/crypto/builtin/des/f_sched.c +++ /dev/null -@@ -1,359 +0,0 @@ +@@ -1,363 +0,0 @@ -/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -/* lib/crypto/builtin/des/f_sched.c */ -/* @@ -2377,9 +2400,11 @@ index 666a510fb..000000000 -/* - * des_make_sched.c - permute a DES key, returning the resulting key schedule - */ --#include "k5-int.h" +-#include "crypto_int.h" -#include "des_int.h" - +-#ifdef K5_BUILTIN_DES +- -/* - * Permuted choice 1 tables. These are used to extract bits - * from the left and right parts of the key to form Ci and Di. @@ -2705,12 +2730,14 @@ index 666a510fb..000000000 - } - return (0); -} +- +-#endif /* K5_BUILTIN_DES */ diff --git a/src/lib/crypto/builtin/des/f_tables.c b/src/lib/crypto/builtin/des/f_tables.c deleted file mode 100644 -index 6308cb0d5..000000000 +index e50ab1fc60..0000000000 --- a/src/lib/crypto/builtin/des/f_tables.c +++ /dev/null -@@ -1,370 +0,0 @@ +@@ -1,375 +0,0 @@ -/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -/* lib/crypto/builtin/des/f_tables.c */ -/* @@ -2747,9 +2774,12 @@ index 6308cb0d5..000000000 - * Include the header file so something will complain if the - * declarations get out of sync - */ +-#include "crypto_int.h" -#include "des_int.h" -#include "f_tables.h" - +-#ifdef K5_BUILTIN_DES +- -/* - * These tables may be declared const if you want. Many compilers - * don't support this, though. @@ -3081,9 +3111,11 @@ index 6308cb0d5..000000000 - 0x40000000, 0x40080010, 0x40084010, 0x00084000 - }, -}; +- +-#endif /* K5_BUILTIN_DES */ diff --git a/src/lib/crypto/builtin/des/f_tables.h b/src/lib/crypto/builtin/des/f_tables.h deleted file mode 100644 -index fc91b566c..000000000 +index fc91b566cf..0000000000 --- a/src/lib/crypto/builtin/des/f_tables.h +++ /dev/null @@ -1,285 +0,0 @@ @@ -3374,10 +3406,10 @@ index fc91b566c..000000000 -#endif /* __DES_TABLES_H__ */ diff --git a/src/lib/crypto/builtin/des/key_sched.c b/src/lib/crypto/builtin/des/key_sched.c deleted file mode 100644 -index 87f02b6a9..000000000 +index d6dedd93c6..0000000000 --- a/src/lib/crypto/builtin/des/key_sched.c +++ /dev/null -@@ -1,62 +0,0 @@ +@@ -1,66 +0,0 @@ -/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -/* lib/crypto/builtin/des/key_sched.c */ -/* @@ -3423,9 +3455,11 @@ index 87f02b6a9..000000000 - * Originally written 6/85 by Steve Miller, MIT Project Athena. - */ - --#include "k5-int.h" +-#include "crypto_int.h" -#include "des_int.h" - +-#ifdef K5_BUILTIN_DES +- -int -mit_des_key_sched(mit_des_cblock k, mit_des_key_schedule schedule) -{ @@ -3440,9 +3474,11 @@ index 87f02b6a9..000000000 - /* if key was good, return 0 */ - return 0; -} +- +-#endif /* K5_BUILTIN_DES */ diff --git a/src/lib/crypto/builtin/des/keytest.data b/src/lib/crypto/builtin/des/keytest.data deleted file mode 100644 -index 7ff34eedc..000000000 +index 7ff34eedcf..0000000000 --- a/src/lib/crypto/builtin/des/keytest.data +++ /dev/null @@ -1,171 +0,0 @@ @@ -3619,7 +3655,7 @@ index 7ff34eedc..000000000 -1C587F1C13924FEF 305532286D6F295A 63FAC0D034D9F793 diff --git a/src/lib/crypto/builtin/des/t_verify.c b/src/lib/crypto/builtin/des/t_verify.c deleted file mode 100644 -index 4a19933ca..000000000 +index 4a19933cad..0000000000 --- a/src/lib/crypto/builtin/des/t_verify.c +++ /dev/null @@ -1,395 +0,0 @@ @@ -4020,10 +4056,10 @@ index 4a19933ca..000000000 -} diff --git a/src/lib/crypto/builtin/des/weak_key.c b/src/lib/crypto/builtin/des/weak_key.c deleted file mode 100644 -index eb41b267d..000000000 +index f8304a3638..0000000000 --- a/src/lib/crypto/builtin/des/weak_key.c +++ /dev/null -@@ -1,86 +0,0 @@ +@@ -1,90 +0,0 @@ -/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -/* lib/crypto/builtin/des/weak_key.c */ -/* @@ -4059,9 +4095,11 @@ index eb41b267d..000000000 - * Originally written 8/85 by Steve Miller, MIT Project Athena. - */ - --#include "k5-int.h" +-#include "crypto_int.h" -#include "des_int.h" - +-#ifdef K5_BUILTIN_DES +- -/* - * The following are the weak DES keys: - */ @@ -4110,20 +4148,21 @@ index eb41b267d..000000000 - - return 0; -} +- +-#endif /* K5_BUILTIN_DES */ diff --git a/src/lib/crypto/builtin/enc_provider/Makefile.in b/src/lib/crypto/builtin/enc_provider/Makefile.in -index 3459e1d0e..af6276b96 100644 +index 6ad7cbd4e0..655966b255 100644 --- a/src/lib/crypto/builtin/enc_provider/Makefile.in +++ b/src/lib/crypto/builtin/enc_provider/Makefile.in -@@ -1,7 +1,6 @@ +@@ -1,6 +1,6 @@ mydir=lib$(S)crypto$(S)builtin$(S)enc_provider BUILDTOP=$(REL)..$(S)..$(S)..$(S).. --LOCALINCLUDES = -I$(srcdir)/../des \ -- -I$(srcdir)/../aes \ -+LOCALINCLUDES = -I$(srcdir)/../aes \ - -I$(srcdir)/../camellia \ - -I$(srcdir)/../../krb \ - -I$(srcdir)/.. -@@ -11,19 +10,16 @@ LOCALINCLUDES = -I$(srcdir)/../des \ +-LOCALINCLUDES = -I$(srcdir)/../des -I$(srcdir)/../aes -I$(srcdir)/../camellia \ ++LOCALINCLUDES = -I$(srcdir)/../aes -I$(srcdir)/../camellia \ + -I$(srcdir)/../../krb $(CRYPTO_IMPL_CFLAGS) + + ##DOS##BUILDTOP = ..\..\..\.. +@@ -8,19 +8,16 @@ LOCALINCLUDES = -I$(srcdir)/../des -I$(srcdir)/../aes -I$(srcdir)/../camellia \ ##DOS##OBJFILE = ..\..\$(OUTPRE)enc_provider.lst STLIBOBJS= \ @@ -4144,19 +4183,17 @@ index 3459e1d0e..af6276b96 100644 $(srcdir)/camellia.c \ $(srcdir)/rc4.c diff --git a/src/lib/crypto/builtin/enc_provider/deps b/src/lib/crypto/builtin/enc_provider/deps -index ea4ffecd8..061289a91 100644 +index a3414a38ec..dc29d9fce8 100644 --- a/src/lib/crypto/builtin/enc_provider/deps +++ b/src/lib/crypto/builtin/enc_provider/deps -@@ -1,19 +1,6 @@ +@@ -1,17 +1,6 @@ # # Generated makefile dependencies follow. # -des3.so des3.po $(OUTPRE)des3.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ -- $(srcdir)/../aes/aes.h $(srcdir)/../aes/brg_types.h \ -- $(srcdir)/../crypto_mod.h $(srcdir)/../des/des_int.h \ -- $(srcdir)/../sha2/sha2.h $(top_srcdir)/include/k5-buf.h \ +- $(srcdir)/../des/des_int.h $(top_srcdir)/include/k5-buf.h \ - $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ - $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ - $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ @@ -4169,10 +4206,10 @@ index ea4ffecd8..061289a91 100644 $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ diff --git a/src/lib/crypto/builtin/enc_provider/des3.c b/src/lib/crypto/builtin/enc_provider/des3.c deleted file mode 100644 -index 9b8244223..000000000 +index c2634d5e10..0000000000 --- a/src/lib/crypto/builtin/enc_provider/des3.c +++ /dev/null -@@ -1,105 +0,0 @@ +@@ -1,109 +0,0 @@ -/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -/* - * Copyright (C) 1998 by the FundsXpress, INC. @@ -4203,6 +4240,8 @@ index 9b8244223..000000000 -#include "crypto_int.h" -#include "des_int.h" - +-#ifdef K5_BUILTIN_DES +- -static krb5_error_code -validate_and_schedule(krb5_key key, const krb5_data *ivec, - const krb5_crypto_iov *data, size_t num_data, @@ -4278,8 +4317,10 @@ index 9b8244223..000000000 - krb5int_des_init_state, - krb5int_default_free_state -}; +- +-#endif /* K5_BUILTIN_DES */ diff --git a/src/lib/crypto/crypto_tests/t_cf2.expected b/src/lib/crypto/crypto_tests/t_cf2.expected -index f8251a16c..bc6aa50c8 100644 +index f8251a16cb..bc6aa50c84 100644 --- a/src/lib/crypto/crypto_tests/t_cf2.expected +++ b/src/lib/crypto/crypto_tests/t_cf2.expected @@ -1,6 +1,5 @@ @@ -4290,7 +4331,7 @@ index f8251a16c..bc6aa50c8 100644 edd02a39d2dbde31611c16e610be062c 67f6ea530aea85a37dcbb23349ea52dcc61ca8493ff557252327fd8304341584 diff --git a/src/lib/crypto/crypto_tests/t_cf2.in b/src/lib/crypto/crypto_tests/t_cf2.in -index 73e2f8fbc..c4d23b506 100644 +index 73e2f8fbc9..c4d23b506b 100644 --- a/src/lib/crypto/crypto_tests/t_cf2.in +++ b/src/lib/crypto/crypto_tests/t_cf2.in @@ -8,11 +8,6 @@ key1 @@ -4306,7 +4347,7 @@ index 73e2f8fbc..c4d23b506 100644 key1 key2 diff --git a/src/lib/crypto/crypto_tests/t_cksums.c b/src/lib/crypto/crypto_tests/t_cksums.c -index 8297fcbf5..3063d12ec 100644 +index 557340ec5e..9f9a177ef0 100644 --- a/src/lib/crypto/crypto_tests/t_cksums.c +++ b/src/lib/crypto/crypto_tests/t_cksums.c @@ -59,16 +59,6 @@ struct test { @@ -4327,7 +4368,7 @@ index 8297fcbf5..3063d12ec 100644 { KV5M_DATA, 37, "eight nine ten eleven twelve thirteen" }, CKSUMTYPE_HMAC_SHA1_96_AES128, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 3, diff --git a/src/lib/crypto/crypto_tests/t_decrypt.c b/src/lib/crypto/crypto_tests/t_decrypt.c -index a40a85500..716f2c337 100644 +index a40a855007..716f2c337a 100644 --- a/src/lib/crypto/crypto_tests/t_decrypt.c +++ b/src/lib/crypto/crypto_tests/t_decrypt.c @@ -39,62 +39,6 @@ struct test { @@ -4402,7 +4443,7 @@ index a40a85500..716f2c337 100644 ENCTYPE_ARCFOUR_HMAC_EXP, ENCTYPE_AES128_CTS_HMAC_SHA1_96, diff --git a/src/lib/crypto/crypto_tests/t_derive.c b/src/lib/crypto/crypto_tests/t_derive.c -index afbf7477f..93ce30da2 100644 +index afbf7477f6..93ce30da20 100644 --- a/src/lib/crypto/crypto_tests/t_derive.c +++ b/src/lib/crypto/crypto_tests/t_derive.c @@ -38,41 +38,6 @@ struct test { @@ -4456,7 +4497,7 @@ index afbf7477f..93ce30da2 100644 case ENCTYPE_AES256_CTS_HMAC_SHA1_96: return &krb5int_enc_aes256; case ENCTYPE_CAMELLIA128_CTS_CMAC: return &krb5int_enc_camellia128; diff --git a/src/lib/crypto/crypto_tests/t_encrypt.c b/src/lib/crypto/crypto_tests/t_encrypt.c -index bd9b94691..290a72e1e 100644 +index bd9b94691c..290a72e1e0 100644 --- a/src/lib/crypto/crypto_tests/t_encrypt.c +++ b/src/lib/crypto/crypto_tests/t_encrypt.c @@ -37,7 +37,6 @@ @@ -4468,7 +4509,7 @@ index bd9b94691..290a72e1e 100644 ENCTYPE_ARCFOUR_HMAC_EXP, ENCTYPE_AES256_CTS_HMAC_SHA1_96, diff --git a/src/lib/crypto/crypto_tests/t_short.c b/src/lib/crypto/crypto_tests/t_short.c -index d4c2b97df..4466b7115 100644 +index d4c2b97dfd..4466b71158 100644 --- a/src/lib/crypto/crypto_tests/t_short.c +++ b/src/lib/crypto/crypto_tests/t_short.c @@ -34,7 +34,6 @@ @@ -4480,7 +4521,7 @@ index d4c2b97df..4466b7115 100644 ENCTYPE_ARCFOUR_HMAC_EXP, ENCTYPE_AES256_CTS_HMAC_SHA1_96, diff --git a/src/lib/crypto/crypto_tests/t_str2key.c b/src/lib/crypto/crypto_tests/t_str2key.c -index cdb1acc6d..ef4c4a7d3 100644 +index cdb1acc6d0..ef4c4a7d3b 100644 --- a/src/lib/crypto/crypto_tests/t_str2key.c +++ b/src/lib/crypto/crypto_tests/t_str2key.c @@ -35,58 +35,6 @@ struct test { @@ -4542,11 +4583,33 @@ index cdb1acc6d..ef4c4a7d3 100644 /* Test vectors from RFC 3962 appendix B. */ { ENCTYPE_AES128_CTS_HMAC_SHA1_96, +diff --git a/src/lib/crypto/crypto_tests/vectors.c b/src/lib/crypto/crypto_tests/vectors.c +index bcf5c9106f..eb107dbcd2 100644 +--- a/src/lib/crypto/crypto_tests/vectors.c ++++ b/src/lib/crypto/crypto_tests/vectors.c +@@ -190,8 +190,6 @@ test_s2k (krb5_enctype enctype) + } + } + +-static void test_des3_s2k () { test_s2k (ENCTYPE_DES3_CBC_SHA1); } +- + static void + keyToData (krb5_keyblock *k, krb5_data *d) + { +@@ -208,8 +206,6 @@ void check_error (int r, int line) { + } + #define CHECK check_error(r, __LINE__) + +-extern struct krb5_enc_provider krb5int_enc_des3; +-struct krb5_enc_provider *enc = &krb5int_enc_des3; + extern struct krb5_enc_provider krb5int_enc_aes128, krb5int_enc_aes256; + + void DK (krb5_keyblock *out, krb5_keyblock *in, const krb5_data *usage) { diff --git a/src/lib/crypto/krb/Makefile.in b/src/lib/crypto/krb/Makefile.in -index b74e6f7cc..2b0c4163d 100644 +index cb2e40a3a5..f66698bd53 100644 --- a/src/lib/crypto/krb/Makefile.in +++ b/src/lib/crypto/krb/Makefile.in -@@ -50,7 +50,6 @@ STLIBOBJS=\ +@@ -47,7 +47,6 @@ STLIBOBJS=\ prf.o \ prf_aes2.o \ prf_cmac.o \ @@ -4554,7 +4617,7 @@ index b74e6f7cc..2b0c4163d 100644 prf_dk.o \ prf_rc4.o \ prng.o \ -@@ -109,7 +108,6 @@ OBJS=\ +@@ -103,7 +102,6 @@ OBJS=\ $(OUTPRE)prf.$(OBJEXT) \ $(OUTPRE)prf_aes2.$(OBJEXT) \ $(OUTPRE)prf_cmac.$(OBJEXT) \ @@ -4562,7 +4625,7 @@ index b74e6f7cc..2b0c4163d 100644 $(OUTPRE)prf_dk.$(OBJEXT) \ $(OUTPRE)prf_rc4.$(OBJEXT) \ $(OUTPRE)prng.$(OBJEXT) \ -@@ -168,7 +166,6 @@ SRCS=\ +@@ -159,7 +157,6 @@ SRCS=\ $(srcdir)/prf.c \ $(srcdir)/prf_aes2.c \ $(srcdir)/prf_cmac.c \ @@ -4571,10 +4634,10 @@ index b74e6f7cc..2b0c4163d 100644 $(srcdir)/prf_rc4.c \ $(srcdir)/prng.c \ diff --git a/src/lib/crypto/krb/cksumtypes.c b/src/lib/crypto/krb/cksumtypes.c -index ecc2e08c9..f5fbe8a2a 100644 +index f7ba322f24..25a3ffd2d2 100644 --- a/src/lib/crypto/krb/cksumtypes.c +++ b/src/lib/crypto/krb/cksumtypes.c -@@ -46,12 +46,6 @@ const struct krb5_cksumtypes krb5int_cksumtypes_list[] = { +@@ -52,12 +52,6 @@ const struct krb5_cksumtypes krb5int_cksumtypes_list[] = { krb5int_unkeyed_checksum, NULL, 20, 20, CKSUM_UNKEYED }, @@ -4588,21 +4651,19 @@ index ecc2e08c9..f5fbe8a2a 100644 "hmac-md5-rc4", { "hmac-md5-enc", "hmac-md5-earcfour" }, "Microsoft HMAC MD5", diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h -index 19f808749..4bc430c7a 100644 +index 3629616d96..1ee4b30e02 100644 --- a/src/lib/crypto/krb/crypto_int.h +++ b/src/lib/crypto/krb/crypto_int.h -@@ -276,10 +276,6 @@ krb5_error_code krb5int_aes2_string_to_key(const struct krb5_keytypes *enc, +@@ -332,8 +332,6 @@ krb5_error_code krb5int_aes2_string_to_key(const struct krb5_keytypes *enc, /* Random to key */ krb5_error_code k5_rand2key_direct(const krb5_data *randombits, krb5_keyblock *keyblock); --krb5_error_code k5_rand2key_des(const krb5_data *randombits, -- krb5_keyblock *keyblock); -krb5_error_code k5_rand2key_des3(const krb5_data *randombits, - krb5_keyblock *keyblock); /* Pseudo-random function */ krb5_error_code krb5int_des_prf(const struct krb5_keytypes *ktp, -@@ -368,11 +364,6 @@ krb5_keyusage krb5int_arcfour_translate_usage(krb5_keyusage usage); +@@ -411,11 +409,6 @@ krb5_keyusage krb5int_arcfour_translate_usage(krb5_keyusage usage); /* Ensure library initialization has occurred. */ int krb5int_crypto_init(void); @@ -4614,7 +4675,7 @@ index 19f808749..4bc430c7a 100644 /* Default state cleanup handler (used by module enc providers). */ void krb5int_default_free_state(krb5_data *state); -@@ -425,7 +416,6 @@ void k5_iov_cursor_put(struct iov_cursor *cursor, unsigned char *block); +@@ -468,7 +461,6 @@ void k5_iov_cursor_put(struct iov_cursor *cursor, unsigned char *block); /* Modules must implement the k5_sha256() function prototyped in k5-int.h. */ /* Modules must implement the following enc_providers and hash_providers: */ @@ -4622,21 +4683,18 @@ index 19f808749..4bc430c7a 100644 extern const struct krb5_enc_provider krb5int_enc_arcfour; extern const struct krb5_enc_provider krb5int_enc_aes128; extern const struct krb5_enc_provider krb5int_enc_aes256; -@@ -442,12 +432,6 @@ extern const struct krb5_hash_provider krb5int_hash_sha384; +@@ -485,9 +477,6 @@ extern const struct krb5_hash_provider krb5int_hash_sha384; /* Modules must implement the following functions. */ -/* Set the parity bits to the correct values in keybits. */ -void k5_des_fixup_key_parity(unsigned char *keybits); -- --/* Return true if keybits is a weak or semi-weak DES key. */ --krb5_boolean k5_des_is_weak_key(unsigned char *keybits); - /* Compute an HMAC using the provided hash function, key, and data, storing the * result into output (caller-allocated). */ krb5_error_code krb5int_hmac(const struct krb5_hash_provider *hash, diff --git a/src/lib/crypto/krb/default_state.c b/src/lib/crypto/krb/default_state.c -index 0757c8b02..f89dc7902 100644 +index 0757c8b02c..f89dc79023 100644 --- a/src/lib/crypto/krb/default_state.c +++ b/src/lib/crypto/krb/default_state.c @@ -32,16 +32,6 @@ @@ -4657,7 +4715,7 @@ index 0757c8b02..f89dc7902 100644 krb5int_default_free_state(krb5_data *state) { diff --git a/src/lib/crypto/krb/enctype_util.c b/src/lib/crypto/krb/enctype_util.c -index 1542d4062..a0037912a 100644 +index 1542d40629..a0037912a7 100644 --- a/src/lib/crypto/krb/enctype_util.c +++ b/src/lib/crypto/krb/enctype_util.c @@ -45,6 +45,9 @@ struct { @@ -4671,7 +4729,7 @@ index 1542d4062..a0037912a 100644 }; diff --git a/src/lib/crypto/krb/etypes.c b/src/lib/crypto/krb/etypes.c -index fc278783b..7635393a4 100644 +index fc278783b9..7635393a41 100644 --- a/src/lib/crypto/krb/etypes.c +++ b/src/lib/crypto/krb/etypes.c @@ -35,27 +35,6 @@ @@ -4704,7 +4762,7 @@ index fc278783b..7635393a4 100644 { ENCTYPE_ARCFOUR_HMAC, diff --git a/src/lib/crypto/krb/prf_des.c b/src/lib/crypto/krb/prf_des.c deleted file mode 100644 -index 7a2d719c5..000000000 +index 7a2d719c5f..0000000000 --- a/src/lib/crypto/krb/prf_des.c +++ /dev/null @@ -1,47 +0,0 @@ @@ -4756,10 +4814,10 @@ index 7a2d719c5..000000000 - return ktp->enc->encrypt(key, NULL, &iov, 1); -} diff --git a/src/lib/crypto/krb/random_to_key.c b/src/lib/crypto/krb/random_to_key.c -index 157462526..863090beb 100644 +index 9394385aa0..863090beb2 100644 --- a/src/lib/crypto/krb/random_to_key.c +++ b/src/lib/crypto/krb/random_to_key.c -@@ -71,48 +71,3 @@ k5_rand2key_direct(const krb5_data *randombits, krb5_keyblock *keyblock) +@@ -71,31 +71,3 @@ k5_rand2key_direct(const krb5_data *randombits, krb5_keyblock *keyblock) memcpy(keyblock->contents, randombits->data, randombits->length); return 0; } @@ -4773,23 +4831,6 @@ index 157462526..863090beb 100644 -} - -krb5_error_code --k5_rand2key_des(const krb5_data *randombits, krb5_keyblock *keyblock) --{ -- if (randombits->length != 7) -- return(KRB5_CRYPTO_INTERNAL); -- -- keyblock->magic = KV5M_KEYBLOCK; -- -- /* Take the seven bytes, move them around into the top 7 bits of the -- * 8 key bytes, then compute the parity bits. */ -- memcpy(keyblock->contents, randombits->data, randombits->length); -- eighth_byte(keyblock->contents); -- k5_des_fixup_key_parity(keyblock->contents); -- -- return 0; --} -- --krb5_error_code -k5_rand2key_des3(const krb5_data *randombits, krb5_keyblock *keyblock) -{ - int i; @@ -4809,7 +4850,7 @@ index 157462526..863090beb 100644 - return 0; -} diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports -index d6cc1b423..f44cb9170 100644 +index 052f4d4b51..d8ffa63304 100644 --- a/src/lib/crypto/libk5crypto.exports +++ b/src/lib/crypto/libk5crypto.exports @@ -86,7 +86,6 @@ krb5_k_verify_checksum @@ -4818,23 +4859,23 @@ index d6cc1b423..f44cb9170 100644 krb5int_aes_decrypt -krb5int_enc_des3 krb5int_arcfour_gsscrypt - krb5int_camellia_cbc_mac + krb5int_camellia_encrypt krb5int_cmac_checksum diff --git a/src/lib/crypto/openssl/Makefile.in b/src/lib/crypto/openssl/Makefile.in -index aa434b168..234fc0e76 100644 +index 08de047d0a..88f7fd0a09 100644 --- a/src/lib/crypto/openssl/Makefile.in +++ b/src/lib/crypto/openssl/Makefile.in @@ -1,6 +1,6 @@ mydir=lib$(S)crypto$(S)openssl BUILDTOP=$(REL)..$(S)..$(S).. --SUBDIRS=camellia des aes md4 md5 sha1 sha2 enc_provider hash_provider -+SUBDIRS=camellia aes md4 md5 sha1 sha2 enc_provider hash_provider - LOCALINCLUDES = -I$(srcdir)/../krb -I$(srcdir) +-SUBDIRS=des enc_provider hash_provider ++SUBDIRS=enc_provider hash_provider + LOCALINCLUDES=-I$(srcdir)/../krb $(CRYPTO_IMPL_CFLAGS) STLIBOBJS=\ @@ -24,14 +24,14 @@ SRCS=\ - $(srcdir)/sha256.c \ - $(srcdir)/stubs.c + $(srcdir)/pbkdf2.c \ + $(srcdir)/sha256.c -STOBJLISTS= des/OBJS.ST md4/OBJS.ST \ +STOBJLISTS= md4/OBJS.ST \ @@ -4860,13 +4901,13 @@ index aa434b168..234fc0e76 100644 @libobj_frag@ diff --git a/src/lib/crypto/openssl/des/Makefile.in b/src/lib/crypto/openssl/des/Makefile.in deleted file mode 100644 -index 4392fb8ea..000000000 +index a6cece1dd1..0000000000 --- a/src/lib/crypto/openssl/des/Makefile.in +++ /dev/null @@ -1,20 +0,0 @@ -mydir=lib$(S)crypto$(S)openssl$(S)des -BUILDTOP=$(REL)..$(S)..$(S)..$(S).. --LOCALINCLUDES = -I$(srcdir)/../../krb -I$(srcdir)/.. +-LOCALINCLUDES = -I$(srcdir)/../../krb $(CRYPTO_IMPL_CFLAGS) - -STLIBOBJS= des_keys.o - @@ -4886,31 +4927,30 @@ index 4392fb8ea..000000000 - diff --git a/src/lib/crypto/openssl/des/deps b/src/lib/crypto/openssl/des/deps deleted file mode 100644 -index 21b904f89..000000000 +index 723c268082..0000000000 --- a/src/lib/crypto/openssl/des/deps +++ /dev/null -@@ -1,15 +0,0 @@ +@@ -1,14 +0,0 @@ -# -# Generated makefile dependencies follow. -# -des_keys.so des_keys.po $(OUTPRE)des_keys.$(OBJEXT): \ - $(BUILDTOP)/include/autoconf.h $(BUILDTOP)/include/krb5/krb5.h \ - $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(srcdir)/../crypto_mod.h \ -- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ -- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ -- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ -- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ -- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- des_keys.c +- $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h $(top_srcdir)/include/k5-buf.h \ +- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ +- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ +- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ +- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ +- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ +- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ +- $(top_srcdir)/include/socket-utils.h des_keys.c diff --git a/src/lib/crypto/openssl/des/des_keys.c b/src/lib/crypto/openssl/des/des_keys.c deleted file mode 100644 -index 51d9db216..000000000 +index 83f1cbf22a..0000000000 --- a/src/lib/crypto/openssl/des/des_keys.c +++ /dev/null -@@ -1,40 +0,0 @@ +@@ -1,39 +0,0 @@ -/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -/* lib/crypto/openssl/des/des_keys.c - Key functions used by Kerberos code */ -/* @@ -4938,6 +4978,9 @@ index 51d9db216..000000000 - */ - -#include "crypto_int.h" +- +-#ifdef K5_OPENSSL_DES_KEY_PARITY +- -#include - -void @@ -4946,17 +4989,13 @@ index 51d9db216..000000000 - DES_set_odd_parity((DES_cblock *)keybits); -} - --krb5_boolean --k5_des_is_weak_key(unsigned char *keybits) --{ -- return DES_is_weak_key((DES_cblock *)keybits); --} +-#endif diff --git a/src/lib/crypto/openssl/enc_provider/Makefile.in b/src/lib/crypto/openssl/enc_provider/Makefile.in -index a9069d22d..2b32c3ac4 100644 +index 26827cfed5..f0d37c1213 100644 --- a/src/lib/crypto/openssl/enc_provider/Makefile.in +++ b/src/lib/crypto/openssl/enc_provider/Makefile.in @@ -3,19 +3,16 @@ BUILDTOP=$(REL)..$(S)..$(S)..$(S).. - LOCALINCLUDES = -I$(srcdir)/../../krb -I$(srcdir)/.. + LOCALINCLUDES = -I$(srcdir)/../../krb $(CRYPTO_IMPL_CFLAGS) STLIBOBJS= \ - des3.o \ @@ -4976,7 +5015,7 @@ index a9069d22d..2b32c3ac4 100644 $(srcdir)/camellia.c \ $(srcdir)/rc4.c diff --git a/src/lib/crypto/openssl/enc_provider/deps b/src/lib/crypto/openssl/enc_provider/deps -index 1c28cc842..91ba48234 100644 +index 1c87a526d0..a502990a0c 100644 --- a/src/lib/crypto/openssl/enc_provider/deps +++ b/src/lib/crypto/openssl/enc_provider/deps @@ -1,17 +1,6 @@ @@ -4986,23 +5025,23 @@ index 1c28cc842..91ba48234 100644 -des3.so des3.po $(OUTPRE)des3.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ - $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ - $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ -- $(srcdir)/../crypto_mod.h $(top_srcdir)/include/k5-buf.h \ -- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/authdata_plugin.h \ -- $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/port-sockets.h \ -- $(top_srcdir)/include/socket-utils.h des3.c +- $(top_srcdir)/include/k5-buf.h $(top_srcdir)/include/k5-err.h \ +- $(top_srcdir)/include/k5-gmt_mktime.h $(top_srcdir)/include/k5-int-pkinit.h \ +- $(top_srcdir)/include/k5-int.h $(top_srcdir)/include/k5-platform.h \ +- $(top_srcdir)/include/k5-plugin.h $(top_srcdir)/include/k5-thread.h \ +- $(top_srcdir)/include/k5-trace.h $(top_srcdir)/include/krb5.h \ +- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ +- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ +- des3.c aes.so aes.po $(OUTPRE)aes.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ $(BUILDTOP)/include/krb5/krb5.h $(BUILDTOP)/include/osconf.h \ $(BUILDTOP)/include/profile.h $(COM_ERR_DEPS) $(srcdir)/../../krb/crypto_int.h \ diff --git a/src/lib/crypto/openssl/enc_provider/des3.c b/src/lib/crypto/openssl/enc_provider/des3.c deleted file mode 100644 -index 1c439c2cd..000000000 +index 90fcf9acb5..0000000000 --- a/src/lib/crypto/openssl/enc_provider/des3.c +++ /dev/null -@@ -1,184 +0,0 @@ +@@ -1,188 +0,0 @@ -/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -/* lib/crypto/openssl/enc_provider/des3.c */ -/* @@ -5055,8 +5094,10 @@ index 1c439c2cd..000000000 - */ - -#include "crypto_int.h" --#include - +-#ifdef K5_OPENSSL_DES +- +-#include - -#define DES3_BLOCK_SIZE 8 -#define DES3_KEY_SIZE 24 @@ -5187,11 +5228,26 @@ index 1c439c2cd..000000000 - krb5int_des_init_state, - krb5int_default_free_state -}; +- +-#endif /* K5_OPENSSL_DES */ +diff --git a/src/lib/crypto/openssl/kdf.c b/src/lib/crypto/openssl/kdf.c +index 41e845eae0..5a43c3d9eb 100644 +--- a/src/lib/crypto/openssl/kdf.c ++++ b/src/lib/crypto/openssl/kdf.c +@@ -60,8 +60,6 @@ enc_name(const struct krb5_enc_provider *enc) + return "AES-128-CBC"; + if (enc == &krb5int_enc_aes256) + return "AES-256-CBC"; +- if (enc == &krb5int_enc_des3) +- return "DES-EDE3-CBC"; + return NULL; + } + diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index 75f071c3e..fcf2c2152 100644 +index d4e90793f9..1bc807172b 100644 --- a/src/lib/gssapi/krb5/accept_sec_context.c +++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -1039,7 +1039,6 @@ kg_accept_krb5(minor_status, context_handle, +@@ -1030,7 +1030,6 @@ kg_accept_krb5(minor_status, context_handle, } switch (negotiated_etype) { @@ -5200,7 +5256,7 @@ index 75f071c3e..fcf2c2152 100644 case ENCTYPE_ARCFOUR_HMAC_EXP: /* RFC 4121 accidentally omits RC4-HMAC-EXP as a "not-newer" diff --git a/src/lib/gssapi/krb5/gssapiP_krb5.h b/src/lib/gssapi/krb5/gssapiP_krb5.h -index a7e0e63ec..3bacdcd35 100644 +index a4446530fc..88d41130a7 100644 --- a/src/lib/gssapi/krb5/gssapiP_krb5.h +++ b/src/lib/gssapi/krb5/gssapiP_krb5.h @@ -125,14 +125,14 @@ enum sgn_alg { @@ -5230,7 +5286,7 @@ index a7e0e63ec..3bacdcd35 100644 }; diff --git a/src/lib/gssapi/krb5/k5seal.c b/src/lib/gssapi/krb5/k5seal.c -index d1cdce486..7f7146a0a 100644 +index d1cdce486f..7f7146a0a2 100644 --- a/src/lib/gssapi/krb5/k5seal.c +++ b/src/lib/gssapi/krb5/k5seal.c @@ -136,19 +136,12 @@ make_seal_token_v1 (krb5_context context, @@ -5283,7 +5339,7 @@ index d1cdce486..7f7146a0a 100644 krb5_free_checksum_contents(context, &md5cksum); diff --git a/src/lib/gssapi/krb5/k5sealiov.c b/src/lib/gssapi/krb5/k5sealiov.c -index 9bb2ee109..9147bb2c7 100644 +index 9bb2ee1099..9147bb2c78 100644 --- a/src/lib/gssapi/krb5/k5sealiov.c +++ b/src/lib/gssapi/krb5/k5sealiov.c @@ -144,18 +144,11 @@ make_seal_token_v1_iov(krb5_context context, @@ -5328,7 +5384,7 @@ index 9bb2ee109..9147bb2c7 100644 /* create the seq_num */ code = kg_make_seq_num(context, ctx->seq, ctx->initiate ? 0 : 0xFF, diff --git a/src/lib/gssapi/krb5/k5unseal.c b/src/lib/gssapi/krb5/k5unseal.c -index 9b183bc33..f0cc4a680 100644 +index 9b183bc337..f0cc4a6809 100644 --- a/src/lib/gssapi/krb5/k5unseal.c +++ b/src/lib/gssapi/krb5/k5unseal.c @@ -131,28 +131,21 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, @@ -5393,13 +5449,15 @@ index 9b183bc33..f0cc4a680 100644 + if (signalg != SGN_ALG_HMAC_MD5) { *minor_status = 0; return(GSS_S_DEFECTIVE_TOKEN); -- ++ } + - case SGN_ALG_HMAC_SHA1_DES3_KD: - case SGN_ALG_HMAC_MD5: - /* compute the checksum of the message */ - - /* 8 = bytes of token body to be checksummed according to spec */ -- ++ /* compute the checksum of the message */ + - if (! (data_ptr = xmalloc(8 + plainlen))) { - if (sealalg != 0xffff) - xfree(plain); @@ -5408,33 +5466,9 @@ index 9b183bc33..f0cc4a680 100644 - *minor_status = ENOMEM; - return(GSS_S_FAILURE); - } -- -- (void) memcpy(data_ptr, ptr-2, 8); -- -- (void) memcpy(data_ptr+8, plain, plainlen); -- -- plaind.length = 8 + plainlen; -- plaind.data = data_ptr; -- code = krb5_k_make_checksum(context, md5cksum.checksum_type, -- ctx->seq, sign_usage, -- &plaind, &md5cksum); -- xfree(data_ptr); -- -- if (code) { -- if (toktype == KG_TOK_SEAL_MSG) -- gssalloc_free(token.value); -- *minor_status = code; -- return(GSS_S_FAILURE); -- } -- -- code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); -- break; - } - -+ /* compute the checksum of the message */ -+ + /* 8 = bytes of token body to be checksummed according to spec */ -+ + +- (void) memcpy(data_ptr, ptr-2, 8); + if (! (data_ptr = xmalloc(8 + plainlen))) { + if (sealalg != 0xffff) + xfree(plain); @@ -5443,32 +5477,47 @@ index 9b183bc33..f0cc4a680 100644 + *minor_status = ENOMEM; + return(GSS_S_FAILURE); + } -+ + +- (void) memcpy(data_ptr+8, plain, plainlen); + (void) memcpy(data_ptr, ptr-2, 8); -+ + +- plaind.length = 8 + plainlen; +- plaind.data = data_ptr; +- code = krb5_k_make_checksum(context, md5cksum.checksum_type, +- ctx->seq, sign_usage, +- &plaind, &md5cksum); +- xfree(data_ptr); + (void) memcpy(data_ptr+8, plain, plainlen); -+ + +- if (code) { +- if (toktype == KG_TOK_SEAL_MSG) +- gssalloc_free(token.value); +- *minor_status = code; +- return(GSS_S_FAILURE); +- } + plaind.length = 8 + plainlen; + plaind.data = data_ptr; + code = krb5_k_make_checksum(context, md5cksum.checksum_type, + ctx->seq, sign_usage, + &plaind, &md5cksum); + xfree(data_ptr); -+ + +- code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); +- break; + if (code) { + if (toktype == KG_TOK_SEAL_MSG) + gssalloc_free(token.value); + *minor_status = code; + return(GSS_S_FAILURE); -+ } -+ + } + + code = k5_bcmp(md5cksum.contents, ptr + 14, cksum_len); + krb5_free_checksum_contents(context, &md5cksum); if (sealalg != 0xffff) xfree(plain); diff --git a/src/lib/gssapi/krb5/k5unsealiov.c b/src/lib/gssapi/krb5/k5unsealiov.c -index 85a9574f3..3ce2a90ce 100644 +index 85a9574f36..3ce2a90ce9 100644 --- a/src/lib/gssapi/krb5/k5unsealiov.c +++ b/src/lib/gssapi/krb5/k5unsealiov.c @@ -102,28 +102,21 @@ kg_unseal_v1_iov(krb5_context context, @@ -5547,7 +5596,7 @@ index 85a9574f3..3ce2a90ce 100644 code = 0; retval = GSS_S_BAD_SIG; diff --git a/src/lib/gssapi/krb5/util_crypt.c b/src/lib/gssapi/krb5/util_crypt.c -index 84f194988..32150f5e3 100644 +index 84f1949887..32150f5e34 100644 --- a/src/lib/gssapi/krb5/util_crypt.c +++ b/src/lib/gssapi/krb5/util_crypt.c @@ -97,17 +97,6 @@ kg_setup_keys(krb5_context context, krb5_gss_ctx_id_rec *ctx, krb5_key subkey, @@ -5569,7 +5618,7 @@ index 84f194988..32150f5e3 100644 case ENCTYPE_ARCFOUR_HMAC_EXP: /* RFC 4121 accidentally omits RC4-HMAC-EXP as a "not-newer" enctype, diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index aa35baa3c..bfa99d9eb 100644 +index 87b486c53f..2b5abcd817 100644 --- a/src/lib/krb5/krb/init_ctx.c +++ b/src/lib/krb5/krb/init_ctx.c @@ -59,7 +59,6 @@ @@ -5580,7 +5629,7 @@ index aa35baa3c..bfa99d9eb 100644 ENCTYPE_ARCFOUR_HMAC, ENCTYPE_CAMELLIA128_CTS_CMAC, ENCTYPE_CAMELLIA256_CTS_CMAC, 0 -@@ -467,8 +466,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, +@@ -450,8 +449,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, /* Set all enctypes in the default list. */ for (i = 0; default_list[i]; i++) mod_list(default_list[i], sel, weak, &list); @@ -5590,7 +5639,7 @@ index aa35baa3c..bfa99d9eb 100644 mod_list(ENCTYPE_AES256_CTS_HMAC_SHA1_96, sel, weak, &list); mod_list(ENCTYPE_AES128_CTS_HMAC_SHA1_96, sel, weak, &list); diff --git a/src/lib/krb5/krb/s4u_creds.c b/src/lib/krb5/krb/s4u_creds.c -index 44d113e7c..966278578 100644 +index 44d113e7c5..9662785783 100644 --- a/src/lib/krb5/krb/s4u_creds.c +++ b/src/lib/krb5/krb/s4u_creds.c @@ -288,8 +288,6 @@ verify_s4u2self_reply(krb5_context context, @@ -5603,7 +5652,7 @@ index 44d113e7c..966278578 100644 case ENCTYPE_ARCFOUR_HMAC_EXP : not_newer = TRUE; diff --git a/src/lib/krb5/krb/t_etypes.c b/src/lib/krb5/krb/t_etypes.c -index 90c9f626c..935aca12f 100644 +index 90c9f626c6..935aca12f5 100644 --- a/src/lib/krb5/krb/t_etypes.c +++ b/src/lib/krb5/krb/t_etypes.c @@ -50,17 +50,6 @@ static struct { @@ -5675,7 +5724,7 @@ index 90c9f626c..935aca12f 100644 { NULL, { ENCTYPE_AES256_CTS_HMAC_SHA1_96, 0 }, diff --git a/src/lib/krb5/os/t_trace.c b/src/lib/krb5/os/t_trace.c -index 10ba8d0ac..24064ffcf 100644 +index 10ba8d0ac7..24064ffcfd 100644 --- a/src/lib/krb5/os/t_trace.c +++ b/src/lib/krb5/os/t_trace.c @@ -65,8 +65,8 @@ main (int argc, char *argv[]) @@ -5690,7 +5739,7 @@ index 10ba8d0ac..24064ffcf 100644 krb5_keytab keytab; krb5_creds creds; diff --git a/src/lib/krb5/os/t_trace.ref b/src/lib/krb5/os/t_trace.ref -index 044a66999..98fb14f3f 100644 +index 044a66999e..98fb14f3f7 100644 --- a/src/lib/krb5/os/t_trace.ref +++ b/src/lib/krb5/os/t_trace.ref @@ -41,7 +41,7 @@ int, krb5_principal type: ? @@ -5703,7 +5752,7 @@ index 044a66999..98fb14f3f 100644 krb5_ccache, display type:name: FILE:/path/to/ccache krb5_keytab, display name: FILE:/etc/krb5.keytab diff --git a/src/plugins/preauth/pkinit/pkcs11.h b/src/plugins/preauth/pkinit/pkcs11.h -index e3d284631..586661bb7 100644 +index e3d2846315..586661bb7e 100644 --- a/src/plugins/preauth/pkinit/pkcs11.h +++ b/src/plugins/preauth/pkinit/pkcs11.h @@ -339,9 +339,9 @@ typedef unsigned long ck_key_type_t; @@ -5719,99 +5768,29 @@ index e3d284631..586661bb7 100644 #define CKK_CAST (0x16) #define CKK_CAST3 (0x17) #define CKK_CAST128 (0x18) -diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c -index 2817cc213..a385da7c3 100644 ---- a/src/plugins/preauth/pkinit/pkinit_clnt.c -+++ b/src/plugins/preauth/pkinit/pkinit_clnt.c -@@ -212,14 +212,6 @@ pkinit_as_req_create(krb5_context context, - auth_pack.clientPublicValue = &info; - auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; - -- /* add List of CMS algorithms */ -- retval = create_krb5_supportedCMSTypes(context, plgctx->cryptoctx, -- reqctx->cryptoctx, -- reqctx->idctx, &cmstypes); -- auth_pack.supportedCMSTypes = cmstypes; -- if (retval) -- goto cleanup; -- - switch(protocol) { - case DH_PROTOCOL: - TRACE_PKINIT_CLIENT_REQ_DH(context); diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h -index 77d5c61fe..1f9868351 100644 +index 94a1b22fb1..65f6210727 100644 --- a/src/plugins/preauth/pkinit/pkinit_crypto.h +++ b/src/plugins/preauth/pkinit/pkinit_crypto.h -@@ -380,18 +380,6 @@ krb5_error_code server_process_dh - unsigned int *server_key_len_out); /* OUT - receives length of DH secret key */ - --/* -- * this functions takes in crypto specific representation of -- * supportedCMSTypes and creates a list of -- * krb5_algorithm_identifier -- */ --krb5_error_code create_krb5_supportedCMSTypes +@@ -376,11 +376,11 @@ krb5_error_code server_process_dh + * krb5_algorithm_identifier + */ + krb5_error_code create_krb5_supportedCMSTypes - (krb5_context context, /* IN */ - pkinit_plg_crypto_context plg_cryptoctx, /* IN */ - pkinit_req_crypto_context req_cryptoctx, /* IN */ - pkinit_identity_crypto_context id_cryptoctx, /* IN */ - krb5_algorithm_identifier ***supportedCMSTypes); /* OUT */ -- ++ (krb5_context context, /* IN */ ++ pkinit_plg_crypto_context plg_cryptoctx, /* IN */ ++ pkinit_req_crypto_context req_cryptoctx, /* IN */ ++ pkinit_identity_crypto_context id_cryptoctx, /* IN */ ++ krb5_algorithm_identifier ***supportedCMSTypes); /* OUT */ + /* * this functions takes in crypto specific representation of - * trustedCertifiers and creates a list of -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index e5940a513..e1153344e 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -5486,44 +5486,6 @@ cleanup: - return retval; - } - --krb5_error_code --create_krb5_supportedCMSTypes(krb5_context context, -- pkinit_plg_crypto_context plg_cryptoctx, -- pkinit_req_crypto_context req_cryptoctx, -- pkinit_identity_crypto_context id_cryptoctx, -- krb5_algorithm_identifier ***oids) --{ -- -- krb5_error_code retval = ENOMEM; -- krb5_algorithm_identifier **loids = NULL; -- krb5_data des3oid = {0, 8, "\x2A\x86\x48\x86\xF7\x0D\x03\x07" }; -- -- *oids = NULL; -- loids = malloc(2 * sizeof(krb5_algorithm_identifier *)); -- if (loids == NULL) -- goto cleanup; -- loids[1] = NULL; -- loids[0] = malloc(sizeof(krb5_algorithm_identifier)); -- if (loids[0] == NULL) { -- free(loids); -- goto cleanup; -- } -- retval = pkinit_copy_krb5_data(&loids[0]->algorithm, &des3oid); -- if (retval) { -- free(loids[0]); -- free(loids); -- goto cleanup; -- } -- loids[0]->parameters.length = 0; -- loids[0]->parameters.data = NULL; -- -- *oids = loids; -- retval = 0; --cleanup: -- -- return retval; --} -- - krb5_error_code - create_krb5_trustedCertifiers(krb5_context context, - pkinit_plg_crypto_context plg_cryptoctx, diff --git a/src/plugins/preauth/pkinit/pkinit_kdf_test.c b/src/plugins/preauth/pkinit/pkinit_kdf_test.c -index 7acbd0d28..cd998a29a 100644 +index 7f38e84910..99c93ac128 100644 --- a/src/plugins/preauth/pkinit/pkinit_kdf_test.c +++ b/src/plugins/preauth/pkinit/pkinit_kdf_test.c @@ -49,7 +49,6 @@ char eighteen_bs[9]; @@ -5822,14 +5801,13 @@ index 7acbd0d28..cd998a29a 100644 const krb5_data lha_data = DATA_FROM_STRING("lha"); krb5_octet key1_hex[] = -@@ -185,36 +184,6 @@ main(int argc, char **argv) +@@ -187,35 +186,6 @@ main(int argc, char **argv) goto cleanup; } - /* TEST 3: SHA-512/DES3 */ - /* set up algorithm id */ -- alg_id.algorithm.data = (char *)krb5_pkinit_sha512_oid; -- alg_id.algorithm.length = krb5_pkinit_sha512_oid_len; +- alg_id.algorithm = sha512_id; - - enctype = enctype_des3; - @@ -5839,7 +5817,7 @@ index 7acbd0d28..cd998a29a 100644 - u_principal, v_principal, - enctype, &as_req, &pk_as_rep, - &key_block))) { -- printf("ERROR in pkinit_kdf_test: kdf call failed, retval = %d", +- printf("ERROR in pkinit_kdf_test: kdf call failed, retval = %d\n", - retval); - goto cleanup; - } @@ -5860,7 +5838,7 @@ index 7acbd0d28..cd998a29a 100644 /* release all allocated resources, whether good or bad return */ free(secret.data); diff --git a/src/plugins/preauth/spake/t_vectors.c b/src/plugins/preauth/spake/t_vectors.c -index 2279202d3..96b0307d7 100644 +index 2279202d3a..96b0307d78 100644 --- a/src/plugins/preauth/spake/t_vectors.c +++ b/src/plugins/preauth/spake/t_vectors.c @@ -56,31 +56,6 @@ struct test { @@ -5895,158 +5873,8 @@ index 2279202d3..96b0307d7 100644 { ENCTYPE_ARCFOUR_HMAC, SPAKE_GROUP_EDWARDS25519, /* initial key, w, x, y, T, S, K */ "8846F7EAEE8FB117AD06BDD830B7586C", -diff --git a/src/tests/dejagnu/config/default.exp b/src/tests/dejagnu/config/default.exp -index 85bbf478a..302dee74c 100644 ---- a/src/tests/dejagnu/config/default.exp -+++ b/src/tests/dejagnu/config/default.exp -@@ -15,8 +15,6 @@ set timeout 100 - set stty_init {erase \^h kill \^u} - set env(TERM) dumb - --set des3_krbtgt 0 -- - if { [string length $VALGRIND] } { - rename spawn valgrind_aux_spawn - proc spawn { args } { -@@ -105,17 +103,9 @@ if { $PRIOCNTL_HACK } { - # particularly with regards to encryption types. - - set passes { -- { -- des3 -- mode=udp -- des3_krbtgt=1 -- {supported_enctypes=des3-cbc-sha1:normal} -- {dummy=[verbose -log "DES3 TGT, DES3 enctype"]} -- } - { - aes-only - mode=udp -- des3_krbtgt=0 - {supported_enctypes=aes256-cts-hmac-sha1-96:normal} - {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96} - {permitted_enctypes(client)=aes256-cts-hmac-sha1-96} -@@ -130,7 +120,6 @@ set passes { - { - aes-sha2-only - mode=udp -- des3_krbtgt=0 - {supported_enctypes=aes256-sha2:normal} - {permitted_enctypes(kdc)=aes256-sha2} - {permitted_enctypes(replica)=aes256-sha2} -@@ -146,7 +135,6 @@ set passes { - { - camellia-only - mode=udp -- des3_krbtgt=0 - {supported_enctypes=camellia256-cts:normal} - {permitted_enctypes(kdc)=camellia256-cts} - {permitted_enctypes(replica)=camellia256-cts} -@@ -159,32 +147,9 @@ set passes { - {master_key_type=camellia256-cts} - {dummy=[verbose -log "Camellia-256 enctype"]} - } -- { -- aes-des3 -- mode=udp -- des3_krbtgt=0 -- {supported_enctypes=aes256-cts-hmac-sha1-96:normal des3-cbc-sha1:normal} -- {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} -- {permitted_enctypes(client)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} -- {permitted_enctypes(server)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} -- {master_key_type=aes256-cts-hmac-sha1-96} -- {dummy=[verbose -log "AES + DES3 + DES enctypes"]} -- } -- { -- aes-des3tgt -- mode=udp -- des3_krbtgt=1 -- {supported_enctypes=aes256-cts-hmac-sha1-96:normal des3-cbc-sha1:normal} -- {permitted_enctypes(kdc)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} -- {permitted_enctypes(client)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} -- {permitted_enctypes(server)=aes256-cts-hmac-sha1-96 des3-cbc-sha1} -- {master_key_type=aes256-cts-hmac-sha1-96} -- {dummy=[verbose -log "AES enctypes, DES3 TGT"]} -- } - { - all-enctypes - mode=udp -- des3_krbtgt=0 - {allow_weak_crypto(kdc)=false} - {allow_weak_crypto(replica)=false} - {allow_weak_crypto(client)=false} -@@ -946,7 +911,6 @@ proc setup_kerberos_db { standalone } { - global REALMNAME KDB5_UTIL KADMIN_LOCAL KEY - global tmppwd hostname - global spawn_id -- global des3_krbtgt - global multipass_name last_passname_db - - set failall 0 -@@ -1143,48 +1107,6 @@ proc setup_kerberos_db { standalone } { - } - } - -- if $des3_krbtgt { -- # Set the TGT key to DES3. -- set test "kadmin.local TGT to DES3" -- set body { -- if $failall { -- break -- } -- spawn $KADMIN_LOCAL -r $REALMNAME -e des3-cbc-sha1:normal -- verbose "starting $test" -- expect_after $def_exp_after -- -- expect "kadmin.local: " -- send "cpw -randkey krbtgt/$REALMNAME@$REALMNAME\r" -- # It echos... -- expect "cpw -randkey krbtgt/$REALMNAME@$REALMNAME\r" -- expect { -- "Key for \"krbtgt/$REALMNAME@$REALMNAME\" randomized." { } -- } -- expect "kadmin.local: " -- send "quit\r" -- expect eof -- catch expect_after -- if ![check_exit_status kadmin_local] { -- break -- } -- } -- set ret [catch $body] -- catch "expect eof" -- catch expect_after -- if $ret { -- set failall 1 -- if $standalone { -- fail $test -- } else { -- delete_db -- } -- } else { -- if $standalone { -- pass $test -- } -- } -- } - envstack_pop - - # create the admin database lock file -diff --git a/src/tests/dejagnu/krb-standalone/kprop.exp b/src/tests/dejagnu/krb-standalone/kprop.exp -index 661e3fd9a..2b8f60045 100644 ---- a/src/tests/dejagnu/krb-standalone/kprop.exp -+++ b/src/tests/dejagnu/krb-standalone/kprop.exp -@@ -54,7 +54,7 @@ proc doit { } { - global REALMNAME KEY - global KADMIN_LOCAL KTUTIL KDB5_UTIL KPROPLOG KPROP kpropd_spawn_id - global hostname tmppwd spawn_id timeout -- global KRBIV supported_enctypes portbase mode ulog des3_krbtgt -+ global KRBIV supported_enctypes portbase mode ulog - - # Delete any db, ulog files - delete_db diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py -index 7494d7fcd..2f95d8996 100755 +index 7494d7fcdb..2f95d89967 100755 --- a/src/tests/gssapi/t_enctypes.py +++ b/src/tests/gssapi/t_enctypes.py @@ -1,24 +1,17 @@ @@ -6115,7 +5943,7 @@ index 7494d7fcd..2f95d8996 100755 # because the ticket session key and initiator subkey are # non-permitted. (This is unfortunate if the acceptor's restriction diff --git a/src/tests/gssapi/t_invalid.c b/src/tests/gssapi/t_invalid.c -index 9876a11e6..fb8fe5511 100644 +index 9876a11e67..fb8fe55111 100644 --- a/src/tests/gssapi/t_invalid.c +++ b/src/tests/gssapi/t_invalid.c @@ -84,18 +84,6 @@ struct test { @@ -6138,7 +5966,7 @@ index 9876a11e6..fb8fe5511 100644 ENCTYPE_ARCFOUR_HMAC, ENCTYPE_ARCFOUR_HMAC, SEAL_ALG_MICROSOFT_RC4, SGN_ALG_HMAC_MD5, 8, diff --git a/src/tests/gssapi/t_pcontok.c b/src/tests/gssapi/t_pcontok.c -index 7368f752f..bf22bd3da 100644 +index 7368f752f0..bf22bd3da1 100644 --- a/src/tests/gssapi/t_pcontok.c +++ b/src/tests/gssapi/t_pcontok.c @@ -43,7 +43,6 @@ @@ -6173,7 +6001,7 @@ index 7368f752f..bf22bd3da 100644 tlen = 20 + mech_krb5.length + cksize; token = malloc(tlen); diff --git a/src/tests/gssapi/t_prf.c b/src/tests/gssapi/t_prf.c -index f71774cdc..d1857c433 100644 +index f71774cdc9..d1857c433f 100644 --- a/src/tests/gssapi/t_prf.c +++ b/src/tests/gssapi/t_prf.c @@ -41,13 +41,6 @@ static struct { @@ -6191,10 +6019,10 @@ index f71774cdc..d1857c433 100644 "3BB3AE288C12B3B9D06B208A4151B3B6", "9AEA11A3BCF3C53F1F91F5A0BA2132E2501ADF5F3C28" diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py -index 3fa957ad2..2e01f46bc 100644 +index 97e2474bf8..47ea9e4b47 100644 --- a/src/tests/t_authdata.py +++ b/src/tests/t_authdata.py -@@ -174,7 +174,7 @@ realm.run([kvno, 'restricted']) +@@ -164,7 +164,7 @@ realm.run([kvno, 'restricted']) # preferred krbtgt enctype changes. mark('#8139 regression test') realm.kinit(realm.user_princ, password('user'), ['-f']) @@ -6204,7 +6032,7 @@ index 3fa957ad2..2e01f46bc 100644 realm.run(['./forward']) realm.run([kvno, realm.host_princ]) diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py -index c982508d8..96e90a69d 100644 +index c982508d8b..96e90a69d2 100644 --- a/src/tests/t_etype_info.py +++ b/src/tests/t_etype_info.py @@ -1,6 +1,6 @@ @@ -6253,7 +6081,7 @@ index c982508d8..96e90a69d 100644 # Verify that etype-info2 is included in a MORE_PREAUTH_DATA_REQUIRED # error if the client does optimistic preauth. diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py -index 2c825a692..f29e0d550 100755 +index 2c825a6922..f29e0d5500 100755 --- a/src/tests/t_keyrollover.py +++ b/src/tests/t_keyrollover.py @@ -37,9 +37,9 @@ realm.run([klist, '-e'], expected_msg=msg) @@ -6281,7 +6109,7 @@ index 2c825a692..f29e0d550 100755 realm.stop() diff --git a/src/tests/t_mkey.py b/src/tests/t_mkey.py -index 32f4070bc..da0ed1831 100755 +index 32f4070bcb..da0ed1831e 100755 --- a/src/tests/t_mkey.py +++ b/src/tests/t_mkey.py @@ -7,7 +7,6 @@ import struct @@ -6334,7 +6162,7 @@ index 32f4070bc..da0ed1831 100755 # master key fetch does not segfault. mark('#8395 regression test') diff --git a/src/tests/t_salt.py b/src/tests/t_salt.py -index 65084bbf3..55ca89745 100755 +index 65084bbf35..55ca897459 100755 --- a/src/tests/t_salt.py +++ b/src/tests/t_salt.py @@ -16,13 +16,12 @@ def test_salt(realm, e1, salt, e2): @@ -6354,10 +6182,10 @@ index 65084bbf3..55ca89745 100755 # Test using different salt types in a principal's key list. # Parameters from one key in the list must not leak over to later ones. diff --git a/src/util/k5test.py b/src/util/k5test.py -index 6afe4b92c..789b0f4b9 100644 +index 619f1995f8..771f82e3cc 100644 --- a/src/util/k5test.py +++ b/src/util/k5test.py -@@ -1278,13 +1278,6 @@ _passes = [ +@@ -1344,13 +1344,6 @@ _passes = [ # No special settings; exercises AES256. ('default', None, None, None), @@ -6372,7 +6200,7 @@ index 6afe4b92c..789b0f4b9 100644 ('arcfour', None, {'libdefaults': {'permitted_enctypes': 'rc4'}}, diff --git a/src/windows/leash/htmlhelp/html/Encryption_Types.htm b/src/windows/leash/htmlhelp/html/Encryption_Types.htm -index 1aebdd0b4..c38eefd2b 100644 +index 1aebdd0b4a..c38eefd2bd 100644 --- a/src/windows/leash/htmlhelp/html/Encryption_Types.htm +++ b/src/windows/leash/htmlhelp/html/Encryption_Types.htm @@ -79,19 +79,6 @@ will have an entry in the Encryption type column.
      @@ -6395,3 +6223,6 @@ index 1aebdd0b4..c38eefd2b 100644 aes The AES Advanced Encryption Standard family, like 3DES, is a symmetric block cipher and was designed +-- +2.38.1 + diff --git a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch similarity index 91% rename from downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch rename to 0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index 553dec9..ecf661d 100644 --- a/downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From 91e1d43858d90f59f5d9f45987cfca02c3175feb Mon Sep 17 00:00:00 2001 +From 239cd24624b801d4fc4bb4686bef8526e7675d77 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 @@ -21,10 +21,10 @@ post7 restores MD5 and adds radius_md5_fips_override. post8 silences a static analyzer warning. -Last-updated: krb5-1.17 +Last-updated: krb5-1.20 --- doc/admin/conf_files/krb5_conf.rst | 6 +++ - src/lib/crypto/krb/prng.c | 11 ++++- + src/lib/crypto/krb/prng.c | 15 +++++- .../crypto/openssl/enc_provider/camellia.c | 6 +++ src/lib/crypto/openssl/enc_provider/rc4.c | 13 +++++- .../crypto/openssl/hash_provider/hash_evp.c | 12 +++++ @@ -38,10 +38,10 @@ Last-updated: krb5-1.17 src/lib/krad/t_attrset.c | 4 +- src/plugins/preauth/spake/spake_client.c | 6 +++ src/plugins/preauth/spake/spake_kdc.c | 6 +++ - 15 files changed, 151 insertions(+), 33 deletions(-) + 15 files changed, 155 insertions(+), 33 deletions(-) diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 675175955..adba8238d 100644 +index d5d6e06ebb..2a4962069f 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst @@ -330,6 +330,12 @@ The libdefaults section may contain any of the following relations: @@ -58,22 +58,26 @@ index 675175955..adba8238d 100644 If this flag is true, reverse name lookup will be used in addition to forward name lookup to canonicalizing hostnames for use in diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c -index cb9ca9b98..f0e9984ca 100644 +index d6b79e2dea..9e80a03d21 100644 --- a/src/lib/crypto/krb/prng.c +++ b/src/lib/crypto/krb/prng.c -@@ -26,6 +26,8 @@ +@@ -26,6 +26,12 @@ #include "crypto_int.h" +#include ++ ++#if OPENSSL_VERSION_NUMBER < 0x30000000L ++#include ++#endif + krb5_error_code KRB5_CALLCONV krb5_c_random_seed(krb5_context context, krb5_data *data) { -@@ -99,9 +101,16 @@ krb5_boolean - k5_get_os_entropy(unsigned char *buf, size_t len, int strong) +@@ -96,9 +102,16 @@ cleanup: + static krb5_boolean + get_os_entropy(unsigned char *buf, size_t len) { - const char *device; -#if defined(__linux__) && defined(SYS_getrandom) int r; @@ -89,10 +93,10 @@ index cb9ca9b98..f0e9984ca 100644 /* * Pull from the /dev/urandom pool, but require it to have been seeded. diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c -index 2da691329..f79679a0b 100644 +index 01920e6ce1..d9f327add6 100644 --- a/src/lib/crypto/openssl/enc_provider/camellia.c +++ b/src/lib/crypto/openssl/enc_provider/camellia.c -@@ -304,6 +304,9 @@ krb5int_camellia_cbc_mac(krb5_key key, const krb5_crypto_iov *data, +@@ -387,6 +387,9 @@ krb5int_camellia_cbc_mac(krb5_key key, const krb5_crypto_iov *data, unsigned char blockY[CAMELLIA_BLOCK_SIZE], blockB[CAMELLIA_BLOCK_SIZE]; struct iov_cursor cursor; @@ -102,7 +106,7 @@ index 2da691329..f79679a0b 100644 if (output->length < CAMELLIA_BLOCK_SIZE) return KRB5_BAD_MSIZE; -@@ -331,6 +334,9 @@ static krb5_error_code +@@ -418,6 +421,9 @@ static krb5_error_code krb5int_camellia_init_state (const krb5_keyblock *key, krb5_keyusage usage, krb5_data *state) { @@ -113,10 +117,10 @@ index 2da691329..f79679a0b 100644 state->data = (void *) malloc(16); if (state->data == NULL) diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c -index bc87c6f42..9bf407899 100644 +index 448d563348..ce63cb5f1b 100644 --- a/src/lib/crypto/openssl/enc_provider/rc4.c +++ b/src/lib/crypto/openssl/enc_provider/rc4.c -@@ -66,6 +66,9 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, +@@ -69,6 +69,9 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, EVP_CIPHER_CTX *ctx = NULL; struct arcfour_state *arcstate; @@ -126,7 +130,7 @@ index bc87c6f42..9bf407899 100644 arcstate = (state != NULL) ? (void *)state->data : NULL; if (arcstate != NULL) { ctx = arcstate->ctx; -@@ -113,7 +116,12 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, +@@ -116,7 +119,12 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, static void k5_arcfour_free_state(krb5_data *state) { @@ -140,7 +144,7 @@ index bc87c6f42..9bf407899 100644 EVP_CIPHER_CTX_free(arcstate->ctx); free(arcstate); -@@ -125,6 +133,9 @@ k5_arcfour_init_state(const krb5_keyblock *key, +@@ -128,6 +136,9 @@ k5_arcfour_init_state(const krb5_keyblock *key, { struct arcfour_state *arcstate; @@ -151,10 +155,10 @@ index bc87c6f42..9bf407899 100644 * The cipher state here is a saved pointer to a struct arcfour_state * object, rather than a flat byte array as in most enc providers. The diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c -index 1e0fb8fc3..2eb5139c0 100644 +index f2fbffdb29..11659908bb 100644 --- a/src/lib/crypto/openssl/hash_provider/hash_evp.c +++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c -@@ -49,6 +49,11 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, +@@ -60,6 +60,11 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, if (ctx == NULL) return ENOMEM; @@ -166,7 +170,7 @@ index 1e0fb8fc3..2eb5139c0 100644 ok = EVP_DigestInit_ex(ctx, type, NULL); for (i = 0; i < num_data; i++) { if (!SIGN_IOV(&data[i])) -@@ -64,12 +69,19 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, +@@ -78,6 +83,11 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, static krb5_error_code hash_md4(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) { @@ -178,6 +182,7 @@ index 1e0fb8fc3..2eb5139c0 100644 return hash_evp(EVP_md4(), data, num_data, output); } +@@ -90,6 +100,8 @@ const struct krb5_hash_provider krb5int_hash_md4 = { static krb5_error_code hash_md5(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) { @@ -187,24 +192,24 @@ index 1e0fb8fc3..2eb5139c0 100644 } diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c -index 7dc59dcc0..769a50c00 100644 +index bf12b8d6a0..f21e268f7f 100644 --- a/src/lib/crypto/openssl/hmac.c +++ b/src/lib/crypto/openssl/hmac.c -@@ -103,7 +103,11 @@ map_digest(const struct krb5_hash_provider *hash) +@@ -111,7 +111,11 @@ map_digest(const struct krb5_hash_provider *hash) return EVP_sha256(); - else if (!strncmp(hash->hash_name, "SHA-384",7)) + else if (hash == &krb5int_hash_sha384) return EVP_sha384(); -- else if (!strncmp(hash->hash_name, "MD5", 3)) +- else if (hash == &krb5int_hash_md5) + + if (FIPS_mode()) + return NULL; + -+ if (!strncmp(hash->hash_name, "MD5", 3)) ++ if (hash == &krb5int_hash_md5) return EVP_md5(); - else if (!strncmp(hash->hash_name, "MD4", 3)) + else if (hash == &krb5int_hash_md4) return EVP_md4(); diff --git a/src/lib/krad/attr.c b/src/lib/krad/attr.c -index 9c13d9d75..42d354a3b 100644 +index 9c13d9d755..42d354a3b5 100644 --- a/src/lib/krad/attr.c +++ b/src/lib/krad/attr.c @@ -38,7 +38,8 @@ @@ -328,7 +333,7 @@ index 9c13d9d75..42d354a3b 100644 krad_attr diff --git a/src/lib/krad/attrset.c b/src/lib/krad/attrset.c -index 03c613716..d89982a13 100644 +index f309f1581c..6ec031e320 100644 --- a/src/lib/krad/attrset.c +++ b/src/lib/krad/attrset.c @@ -167,7 +167,8 @@ krad_attrset_copy(const krad_attrset *set, krad_attrset **copy) @@ -351,7 +356,7 @@ index 03c613716..d89982a13 100644 return retval; diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h -index 0143d155a..57672982f 100644 +index 7619563fc5..e123763954 100644 --- a/src/lib/krad/internal.h +++ b/src/lib/krad/internal.h @@ -39,6 +39,8 @@ @@ -397,7 +402,7 @@ index 0143d155a..57672982f 100644 /* Decode attributes from a buffer. */ krb5_error_code -@@ -152,4 +163,17 @@ gai_error_code(int err) +@@ -156,4 +167,17 @@ gai_error_code(int err) } } @@ -416,7 +421,7 @@ index 0143d155a..57672982f 100644 + #endif /* INTERNAL_H_ */ diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c -index c597174b6..fc2d24800 100644 +index c597174b65..fc2d248001 100644 --- a/src/lib/krad/packet.c +++ b/src/lib/krad/packet.c @@ -53,12 +53,6 @@ typedef unsigned char uchar; @@ -477,7 +482,7 @@ index c597174b6..fc2d24800 100644 } diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c -index a938665f6..7b5804b1d 100644 +index 06ae751bc8..929f1cef67 100644 --- a/src/lib/krad/remote.c +++ b/src/lib/krad/remote.c @@ -263,7 +263,7 @@ on_io_write(krad_remote *rr) @@ -498,7 +503,7 @@ index a938665f6..7b5804b1d 100644 request_finish(r, 0, rsp); break; } -@@ -455,6 +455,12 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs, +@@ -460,6 +460,12 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs, (krad_packet_iter_cb)iterator, &r, &tmp); if (retval != 0) goto error; @@ -512,7 +517,7 @@ index a938665f6..7b5804b1d 100644 K5_TAILQ_FOREACH(r, &rr->list, list) { if (r->request == tmp) { diff --git a/src/lib/krad/t_attr.c b/src/lib/krad/t_attr.c -index eb2a780c8..4d285ad9d 100644 +index eb2a780c89..4d285ad9de 100644 --- a/src/lib/krad/t_attr.c +++ b/src/lib/krad/t_attr.c @@ -50,6 +50,7 @@ main() @@ -533,7 +538,7 @@ index eb2a780c8..4d285ad9d 100644 insist(len == sizeof(encoded)); insist(memcmp(outbuf, encoded, len) == 0); diff --git a/src/lib/krad/t_attrset.c b/src/lib/krad/t_attrset.c -index 7928335ca..0f9576253 100644 +index 7928335ca4..0f95762534 100644 --- a/src/lib/krad/t_attrset.c +++ b/src/lib/krad/t_attrset.c @@ -49,6 +49,7 @@ main() @@ -555,7 +560,7 @@ index 7928335ca..0f9576253 100644 /* Manually encode User-Name. */ diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c -index 00734a13b..a3ce22b70 100644 +index 00734a13b5..a3ce22b70f 100644 --- a/src/plugins/preauth/spake/spake_client.c +++ b/src/plugins/preauth/spake/spake_client.c @@ -38,6 +38,8 @@ @@ -579,7 +584,7 @@ index 00734a13b..a3ce22b70 100644 vt->name = "spake"; vt->pa_type_list = pa_types; diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c -index 88c964ce1..c7df0392f 100644 +index 1a772d450f..232e78bc05 100644 --- a/src/plugins/preauth/spake/spake_kdc.c +++ b/src/plugins/preauth/spake/spake_kdc.c @@ -41,6 +41,8 @@ @@ -591,7 +596,7 @@ index 88c964ce1..c7df0392f 100644 /* * The SPAKE kdcpreauth module uses a secure cookie containing the following * concatenated fields (all integer fields are big-endian): -@@ -571,6 +573,10 @@ kdcpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, +@@ -551,6 +553,10 @@ kdcpreauth_spake_initvt(krb5_context context, int maj_ver, int min_ver, if (maj_ver != 1) return KRB5_PLUGIN_VER_NOTSUPP; @@ -602,3 +607,6 @@ index 88c964ce1..c7df0392f 100644 vt = (krb5_kdcpreauth_vtable)vtable; vt->name = "spake"; vt->pa_type_list = pa_types; +-- +2.38.1 + diff --git a/downstream-Allow-krad-UDP-TCP-localhost-connection-with-FIPS.patch b/0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch similarity index 90% rename from downstream-Allow-krad-UDP-TCP-localhost-connection-with-FIPS.patch rename to 0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch index 7455cb9..b8e5429 100644 --- a/downstream-Allow-krad-UDP-TCP-localhost-connection-with-FIPS.patch +++ b/0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch @@ -1,7 +1,8 @@ -From a43d621ae83c89abb74764f0fd9d90a8e9992333 Mon Sep 17 00:00:00 2001 +From 5587c755b6ca82bde093523e2d17b255158cd90e Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Thu, 5 May 2022 17:15:12 +0200 -Subject: [PATCH] Allow krad UDP/TCP localhost connection with FIPS +Subject: [PATCH] [downstream] Allow krad UDP/TCP localhost connection + with FIPS libkrad allows to establish connections only to UNIX socket in FIPS mode, because MD5 digest is not considered safe enough to be used for @@ -17,7 +18,7 @@ Resolves: rhbz#2082189 1 file changed, 33 insertions(+), 2 deletions(-) diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c -index 7b5804b1d..e671bc5c2 100644 +index 929f1cef67..063f17a613 100644 --- a/src/lib/krad/remote.c +++ b/src/lib/krad/remote.c @@ -33,6 +33,7 @@ @@ -64,7 +65,7 @@ index 7b5804b1d..e671bc5c2 100644 /* Iterate over the set of outstanding packets. */ static const krad_packet * iterator(request **out) -@@ -455,8 +485,9 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs, +@@ -460,8 +490,9 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs, (krad_packet_iter_cb)iterator, &r, &tmp); if (retval != 0) goto error; @@ -77,5 +78,5 @@ index 7b5804b1d..e671bc5c2 100644 retval = ESOCKTNOSUPPORT; goto error; -- -2.35.1 +2.38.1 diff --git a/Add-configure-variable-for-default-PKCS-11-module.patch b/0007-Add-configure-variable-for-default-PKCS-11-module.patch similarity index 93% rename from Add-configure-variable-for-default-PKCS-11-module.patch rename to 0007-Add-configure-variable-for-default-PKCS-11-module.patch index 724b707..1445133 100644 --- a/Add-configure-variable-for-default-PKCS-11-module.patch +++ b/0007-Add-configure-variable-for-default-PKCS-11-module.patch @@ -1,4 +1,4 @@ -From 2a91dabd9752825b96faf3b25ea643d5282c5957 Mon Sep 17 00:00:00 2001 +From 842b4c3b5695e2518e6f1a1545db78865c04b59c Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Fri, 22 Apr 2022 14:12:37 +0200 Subject: [PATCH] Add configure variable for default PKCS#11 module @@ -20,10 +20,10 @@ ticket: 9058 (new) 9 files changed, 34 insertions(+), 16 deletions(-) diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index adba8238d..3d25c9a12 100644 +index 2a4962069f..a33711d918 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst -@@ -1020,7 +1020,7 @@ information for PKINIT is as follows: +@@ -1017,7 +1017,7 @@ information for PKINIT is as follows: All keyword/values are optional. *modname* specifies the location of a library implementing PKCS #11. If a value is encountered with no keyword, it is assumed to be the *modname*. If no @@ -33,10 +33,10 @@ index adba8238d..3d25c9a12 100644 a particular smard card reader or token if there is more than one available. ``certid=`` and/or ``certlabel=`` may be specified to diff --git a/doc/build/options2configure.rst b/doc/build/options2configure.rst -index a8959626d..8f8ac911c 100644 +index 9e355dc2c5..e879b18bd2 100644 --- a/doc/build/options2configure.rst +++ b/doc/build/options2configure.rst -@@ -143,6 +143,9 @@ Environment variables +@@ -137,6 +137,9 @@ Environment variables This option allows one to specify libraries to be passed to the linker (e.g., ``-l``) @@ -47,7 +47,7 @@ index a8959626d..8f8ac911c 100644 If ``-lss`` is not the correct way to link in your installed ss library, for example if additional support libraries are needed, diff --git a/doc/conf.py b/doc/conf.py -index a876fd633..252ab891a 100644 +index 12168fa695..0ab5ff9606 100644 --- a/doc/conf.py +++ b/doc/conf.py @@ -242,6 +242,7 @@ if 'mansubs' in tags: @@ -75,7 +75,7 @@ index a876fd633..252ab891a 100644 .. |krb5conf| replace:: ``/etc/krb5.conf`` .. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal`` diff --git a/doc/mitK5defaults.rst b/doc/mitK5defaults.rst -index 74e69f4ad..aea7af3db 100644 +index 74e69f4ad0..aea7af3dbb 100644 --- a/doc/mitK5defaults.rst +++ b/doc/mitK5defaults.rst @@ -59,18 +59,19 @@ subdirectories of ``/usr/local``. When MIT krb5 is integrated into an @@ -111,10 +111,10 @@ index 74e69f4ad..aea7af3db 100644 The default client keytab name (DEFCKTNAME) typically defaults to ``FILE:/usr/local/var/krb5/user/%{euid}/client.keytab`` for a custom diff --git a/src/configure.ac b/src/configure.ac -index 82b049af9..52e6563da 100644 +index 8dc864718d..9774cb71ae 100644 --- a/src/configure.ac +++ b/src/configure.ac -@@ -1442,6 +1442,14 @@ AC_DEFINE_UNQUOTED(DEFKTNAME, ["$DEFKTNAME"], [Define to default keytab name]) +@@ -1471,6 +1471,14 @@ AC_DEFINE_UNQUOTED(DEFKTNAME, ["$DEFKTNAME"], [Define to default keytab name]) AC_DEFINE_UNQUOTED(DEFCKTNAME, ["$DEFCKTNAME"], [Define to default client keytab name]) @@ -130,7 +130,7 @@ index 82b049af9..52e6563da 100644 AC_CONFIG_FILES([build-tools/kadm-server.pc build-tools/kadm-client.pc diff --git a/src/doc/Makefile.in b/src/doc/Makefile.in -index 379bc3651..a1b0cff0a 100644 +index 379bc36511..a1b0cff0a4 100644 --- a/src/doc/Makefile.in +++ b/src/doc/Makefile.in @@ -10,6 +10,7 @@ sysconfdir=@sysconfdir@ @@ -150,7 +150,7 @@ index 379bc3651..a1b0cff0a 100644 # Dummy rule that man/Makefile can invoke version.py: $(docsrc)/version.py diff --git a/src/man/Makefile.in b/src/man/Makefile.in -index 00b1b2de0..85cae0914 100644 +index 00b1b2de06..85cae0914e 100644 --- a/src/man/Makefile.in +++ b/src/man/Makefile.in @@ -8,6 +8,7 @@ sysconfdir=@sysconfdir@ @@ -172,10 +172,10 @@ index 00b1b2de0..85cae0914 100644 all: $(MANSUBS) diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man -index e993d5c09..42f5ea4f9 100644 +index 51acb38815..fd2c6f2bc4 100644 --- a/src/man/krb5.conf.man +++ b/src/man/krb5.conf.man -@@ -1151,7 +1151,7 @@ user\(aqs certificate and private key. +@@ -1148,7 +1148,7 @@ user\(aqs certificate and private key. All keyword/values are optional. \fImodname\fP specifies the location of a library implementing PKCS #11. If a value is encountered with no keyword, it is assumed to be the \fImodname\fP\&. If no @@ -185,7 +185,7 @@ index e993d5c09..42f5ea4f9 100644 a particular smard card reader or token if there is more than one available. \fBcertid=\fP and/or \fBcertlabel=\fP may be specified to diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h -index b437fd53f..a2018cb10 100644 +index 8135535e2c..66f92d8f03 100644 --- a/src/plugins/preauth/pkinit/pkinit.h +++ b/src/plugins/preauth/pkinit/pkinit.h @@ -42,7 +42,6 @@ @@ -197,5 +197,5 @@ index b437fd53f..a2018cb10 100644 #define PK_NOSLOT 999999 #endif -- -2.35.1 +2.38.1 diff --git a/0008-Set-reasonable-supportedCMSTypes-in-PKINIT.patch b/0008-Set-reasonable-supportedCMSTypes-in-PKINIT.patch new file mode 100644 index 0000000..3755c15 --- /dev/null +++ b/0008-Set-reasonable-supportedCMSTypes-in-PKINIT.patch @@ -0,0 +1,159 @@ +From 3fb8c4c68274d2ff4addb44b7b95b4698c2c4f34 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Wed, 1 Jun 2022 18:02:04 +0200 +Subject: [PATCH] Set reasonable supportedCMSTypes in PKINIT + +The PKINIT client uses AuthPack.supportedCMSTypes to let the KDC know +the algorithms it supports for verification of the CMS data signature. +(The MIT krb5 KDC currently ignores this list, but other +implementations use it.) + +Replace 3DES with sha512WithRSAEncryption and sha256WithRSAEncryption. + +[ghudson@mit.edu: simplified code and used appropriate helpers; edited +commit message] + +ticket: 9066 (new) +--- + src/plugins/preauth/pkinit/pkinit_constants.c | 33 ++++++++++++- + src/plugins/preauth/pkinit/pkinit_crypto.h | 4 ++ + .../preauth/pkinit/pkinit_crypto_openssl.c | 49 ++++++++++--------- + 3 files changed, 60 insertions(+), 26 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_constants.c b/src/plugins/preauth/pkinit/pkinit_constants.c +index 652897fa14..1da482e0b4 100644 +--- a/src/plugins/preauth/pkinit/pkinit_constants.c ++++ b/src/plugins/preauth/pkinit/pkinit_constants.c +@@ -32,9 +32,14 @@ + + #include "pkinit.h" + +-/* statically declare OID constants for all three algorithms */ +-static char sha1_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x01}; ++/* RFC 8636 id-pkinit-kdf-ah-sha1: iso(1) identified-organization(3) dod(6) ++ * internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha1(1) */ ++static char sha1_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x01 }; ++/* RFC 8636 id-pkinit-kdf-ah-sha256: iso(1) identified-organization(3) dod(6) ++ * internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha256(2) */ + static char sha256_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x02 }; ++/* RFC 8636 id-pkinit-kdf-ah-sha512: iso(1) identified-organization(3) dod(6) ++ * internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha512(3) */ + static char sha512_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x03 }; + + const krb5_data sha1_id = { KV5M_DATA, sizeof(sha1_oid), sha1_oid }; +@@ -48,6 +53,30 @@ krb5_data const * const supported_kdf_alg_ids[] = { + NULL + }; + ++/* RFC 4055 sha256WithRSAEncryption: iso(1) member-body(2) us(840) ++ * rsadsi(113549) pkcs(1) 1 11 */ ++static char sha256WithRSAEncr_oid[9] = { ++ 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b ++}; ++/* RFC 4055 sha256WithRSAEncryption: iso(1) member-body(2) us(840) ++ * rsadsi(113549) pkcs(1) 1 13 */ ++static char sha512WithRSAEncr_oid[9] = { ++ 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0d ++}; ++ ++const krb5_data sha256WithRSAEncr_id = { ++ KV5M_DATA, sizeof(sha256WithRSAEncr_oid), sha256WithRSAEncr_oid ++}; ++const krb5_data sha512WithRSAEncr_id = { ++ KV5M_DATA, sizeof(sha512WithRSAEncr_oid), sha512WithRSAEncr_oid ++}; ++ ++krb5_data const * const supported_cms_algs[] = { ++ &sha512WithRSAEncr_id, ++ &sha256WithRSAEncr_id, ++ NULL ++}; ++ + /* RFC 2412 section E.2 (well-known group 2) parameters, DER-encoded as + * DomainParameters (RFC 3279 section 2.3.3). */ + static const uint8_t o1024[] = { +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index 65f6210727..64300da856 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -620,6 +620,10 @@ extern const krb5_data oakley_4096; + */ + extern krb5_data const * const supported_kdf_alg_ids[]; + ++/* CMS signature algorithms supported by this implementation, in order of ++ * decreasing preference. */ ++extern krb5_data const * const supported_cms_algs[]; ++ + krb5_error_code + crypto_encode_der_cert(krb5_context context, pkinit_req_crypto_context reqctx, + uint8_t **der_out, size_t *der_len); +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index d500455dec..1c2aa02827 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -5475,37 +5475,38 @@ create_krb5_supportedCMSTypes(krb5_context context, + pkinit_plg_crypto_context plg_cryptoctx, + pkinit_req_crypto_context req_cryptoctx, + pkinit_identity_crypto_context id_cryptoctx, +- krb5_algorithm_identifier ***oids) ++ krb5_algorithm_identifier ***algs_out) + { ++ krb5_error_code ret; ++ krb5_algorithm_identifier **algs = NULL; ++ size_t i, count; + +- krb5_error_code retval = ENOMEM; +- krb5_algorithm_identifier **loids = NULL; +- krb5_data des3oid = {0, 8, "\x2A\x86\x48\x86\xF7\x0D\x03\x07" }; ++ *algs_out = NULL; + +- *oids = NULL; +- loids = malloc(2 * sizeof(krb5_algorithm_identifier *)); +- if (loids == NULL) +- goto cleanup; +- loids[1] = NULL; +- loids[0] = malloc(sizeof(krb5_algorithm_identifier)); +- if (loids[0] == NULL) { +- free(loids); +- goto cleanup; +- } +- retval = pkinit_copy_krb5_data(&loids[0]->algorithm, &des3oid); +- if (retval) { +- free(loids[0]); +- free(loids); ++ /* Count supported OIDs and allocate list (including null terminator). */ ++ for (count = 0; supported_cms_algs[count] != NULL; count++); ++ algs = k5calloc(count + 1, sizeof(*algs), &ret); ++ if (algs == NULL) + goto cleanup; ++ ++ /* Add an algorithm identifier for each OID, with no parameters. */ ++ for (i = 0; i < count; i++) { ++ algs[i] = k5alloc(sizeof(*algs[i]), &ret); ++ if (algs[i] == NULL) ++ goto cleanup; ++ ret = krb5int_copy_data_contents(context, supported_cms_algs[i], ++ &algs[i]->algorithm); ++ if (ret) ++ goto cleanup; ++ algs[i]->parameters = empty_data(); + } +- loids[0]->parameters.length = 0; +- loids[0]->parameters.data = NULL; + +- *oids = loids; +- retval = 0; +-cleanup: ++ *algs_out = algs; ++ algs = NULL; + +- return retval; ++cleanup: ++ free_krb5_algorithm_identifiers(&algs); ++ return ret; + } + + krb5_error_code +-- +2.38.1 + diff --git a/0009-Simplify-plugin-loading-code.patch b/0009-Simplify-plugin-loading-code.patch new file mode 100644 index 0000000..42802e5 --- /dev/null +++ b/0009-Simplify-plugin-loading-code.patch @@ -0,0 +1,622 @@ +From ffb47e4120d68aef015453350a3a50a9bab1ec58 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 23 Jun 2022 16:41:40 -0400 +Subject: [PATCH] Simplify plugin loading code + +Remove the USE_CFBUNDLE code, which was only used by KfM. Handle +platform conditionals according to current practice. Use +k5_dir_filenames() instead of opendir() and remove the Windows +implementation of opendir(). +--- + src/util/support/plugins.c | 507 +++++++++++-------------------------- + 1 file changed, 150 insertions(+), 357 deletions(-) + +diff --git a/src/util/support/plugins.c b/src/util/support/plugins.c +index c6a9a21d57..0850565687 100644 +--- a/src/util/support/plugins.c ++++ b/src/util/support/plugins.c +@@ -29,16 +29,6 @@ + #if USE_DLOPEN + #include + #endif +-#include +-#ifdef HAVE_SYS_STAT_H +-#include +-#endif +-#ifdef HAVE_SYS_PARAM_H +-#include +-#endif +-#ifdef HAVE_UNISTD_H +-#include +-#endif + + #if USE_DLOPEN + #ifdef RTLD_GROUP +@@ -68,16 +58,6 @@ + #endif + #endif + +-#if USE_DLOPEN && USE_CFBUNDLE +-#include +- +-/* Currently CoreFoundation only exists on the Mac so we just use +- * pthreads directly to avoid creating empty function calls on other +- * platforms. If a thread initializer ever gets created in the common +- * plugin code, move this there */ +-static pthread_mutex_t krb5int_bundle_mutex = PTHREAD_MUTEX_INITIALIZER; +-#endif +- + #include + static void Tprintf (const char *fmt, ...) + { +@@ -90,374 +70,193 @@ static void Tprintf (const char *fmt, ...) + } + + struct plugin_file_handle { +-#if USE_DLOPEN ++#if defined(USE_DLOPEN) + void *dlhandle; +-#endif +-#ifdef _WIN32 +- HMODULE hinstPlugin; +-#endif +-#if !defined (USE_DLOPEN) && !defined (_WIN32) ++#elif defined(_WIN32) ++ HMODULE module; ++#else + char dummy; + #endif + }; + +-#ifdef _WIN32 +-struct dirent { +- long d_ino; /* inode (always 1 in WIN32) */ +- off_t d_off; /* offset to this dirent */ +- unsigned short d_reclen; /* length of d_name */ +- char d_name[_MAX_FNAME+1]; /* filename (null terminated) */ +-}; +- +-typedef struct { +- intptr_t handle; /* _findfirst/_findnext handle */ +- short offset; /* offset into directory */ +- short finished; /* 1 if there are not more files */ +- struct _finddata_t fileinfo;/* from _findfirst/_findnext */ +- char *dir; /* the dir we are reading */ +- struct dirent dent; /* the dirent to return */ +-} DIR; ++#if defined(USE_DLOPEN) + +-DIR * opendir(const char *dir) ++static long ++open_plugin_dlfcn(struct plugin_file_handle *h, const char *filename, ++ struct errinfo *ep) + { +- DIR *dp; +- char *filespec; +- intptr_t handle; +- int index; +- +- filespec = malloc(strlen(dir) + 2 + 1); +- strcpy(filespec, dir); +- index = strlen(filespec) - 1; +- if (index >= 0 && (filespec[index] == '/' || filespec[index] == '\\')) +- filespec[index] = '\0'; +- strcat(filespec, "/*"); +- +- dp = (DIR *)malloc(sizeof(DIR)); +- dp->offset = 0; +- dp->finished = 0; +- dp->dir = strdup(dir); +- +- if ((handle = _findfirst(filespec, &(dp->fileinfo))) < 0) { +- if (errno == ENOENT) +- dp->finished = 1; +- else { +- free(filespec); +- free(dp->dir); +- free(dp); +- return NULL; +- } ++ const char *e; ++ ++ h->dlhandle = dlopen(filename, PLUGIN_DLOPEN_FLAGS); ++ if (h->dlhandle == NULL) { ++ e = dlerror(); ++ if (e == NULL) ++ e = _("unknown failure"); ++ Tprintf("dlopen(%s): %s\n", filename, e); ++ k5_set_error(ep, ENOENT, _("unable to load plugin [%s]: %s"), ++ filename, e); ++ return ENOENT; + } +- +- dp->handle = handle; +- free(filespec); +- +- return dp; ++ return 0; + } ++#define open_plugin open_plugin_dlfcn + +-struct dirent * readdir(DIR *dp) ++static long ++get_sym_dlfcn(struct plugin_file_handle *h, const char *csymname, ++ void **sym_out, struct errinfo *ep) + { +- if (!dp || dp->finished) return NULL; +- +- if (dp->offset != 0) { +- if (_findnext(dp->handle, &(dp->fileinfo)) < 0) { +- dp->finished = 1; +- return NULL; +- } ++ const char *e; ++ ++ if (h->dlhandle == NULL) ++ return ENOENT; ++ *sym_out = dlsym(h->dlhandle, csymname); ++ if (*sym_out == NULL) { ++ e = dlerror(); ++ if (e == NULL) ++ e = _("unknown failure"); ++ Tprintf("dlsym(%s): %s\n", csymname, e); ++ k5_set_error(ep, ENOENT, "%s", e); ++ return ENOENT; + } +- dp->offset++; +- +- strncpy(dp->dent.d_name, dp->fileinfo.name, _MAX_FNAME); +- dp->dent.d_ino = 1; +- dp->dent.d_reclen = (unsigned short)strlen(dp->dent.d_name); +- dp->dent.d_off = dp->offset; +- +- return &(dp->dent); +-} +- +-int closedir(DIR *dp) +-{ +- if (!dp) return 0; +- _findclose(dp->handle); +- free(dp->dir); +- free(dp); +- + return 0; + } +-#endif ++#define get_sym get_sym_dlfcn + +-long KRB5_CALLCONV +-krb5int_open_plugin (const char *filepath, struct plugin_file_handle **h, struct errinfo *ep) ++static void ++close_plugin_dlfcn(struct plugin_file_handle *h) + { +- long err = 0; +- struct plugin_file_handle *htmp = NULL; +- int got_plugin = 0; +-#if defined(USE_CFBUNDLE) || defined(_WIN32) +- struct stat statbuf; +- +- if (!err) { +- if (stat (filepath, &statbuf) < 0) { +- err = errno; +- Tprintf ("stat(%s): %s\n", filepath, strerror (err)); +- k5_set_error(ep, err, _("unable to find plugin [%s]: %s"), +- filepath, strerror(err)); +- } +- } +-#endif +- +- if (!err) { +- htmp = calloc (1, sizeof (*htmp)); /* calloc initializes ptrs to NULL */ +- if (htmp == NULL) { err = ENOMEM; } +- } +- +-#if USE_DLOPEN +- if (!err +-#if USE_CFBUNDLE +- && ((statbuf.st_mode & S_IFMT) == S_IFREG +- || (statbuf.st_mode & S_IFMT) == S_IFDIR) +-#endif /* USE_CFBUNDLE */ +- ) { +- void *handle = NULL; +- +-#if USE_CFBUNDLE +- char executablepath[MAXPATHLEN]; +- +- if ((statbuf.st_mode & S_IFMT) == S_IFDIR) { +- int lock_err = 0; +- CFStringRef pluginString = NULL; +- CFURLRef pluginURL = NULL; +- CFBundleRef pluginBundle = NULL; +- CFURLRef executableURL = NULL; +- +- /* Lock around CoreFoundation calls since objects are refcounted +- * and the refcounts are not thread-safe. Using pthreads directly +- * because this code is Mac-specific */ +- lock_err = pthread_mutex_lock(&krb5int_bundle_mutex); +- if (lock_err) { err = lock_err; } +- +- if (!err) { +- pluginString = CFStringCreateWithCString (kCFAllocatorDefault, +- filepath, +- kCFStringEncodingASCII); +- if (pluginString == NULL) { err = ENOMEM; } +- } +- +- if (!err) { +- pluginURL = CFURLCreateWithFileSystemPath (kCFAllocatorDefault, +- pluginString, +- kCFURLPOSIXPathStyle, +- true); +- if (pluginURL == NULL) { err = ENOMEM; } +- } +- +- if (!err) { +- pluginBundle = CFBundleCreate (kCFAllocatorDefault, pluginURL); +- if (pluginBundle == NULL) { err = ENOENT; } /* XXX need better error */ +- } +- +- if (!err) { +- executableURL = CFBundleCopyExecutableURL (pluginBundle); +- if (executableURL == NULL) { err = ENOMEM; } +- } +- +- if (!err) { +- if (!CFURLGetFileSystemRepresentation (executableURL, +- true, /* absolute */ +- (UInt8 *)executablepath, +- sizeof (executablepath))) { +- err = ENOMEM; +- } +- } +- +- if (!err) { +- /* override the path the caller passed in */ +- filepath = executablepath; +- } +- +- if (executableURL != NULL) { CFRelease (executableURL); } +- if (pluginBundle != NULL) { CFRelease (pluginBundle); } +- if (pluginURL != NULL) { CFRelease (pluginURL); } +- if (pluginString != NULL) { CFRelease (pluginString); } +- +- /* unlock after CFRelease calls since they modify refcounts */ +- if (!lock_err) { pthread_mutex_unlock (&krb5int_bundle_mutex); } +- } +-#endif /* USE_CFBUNDLE */ +- +- if (!err) { +- handle = dlopen(filepath, PLUGIN_DLOPEN_FLAGS); +- if (handle == NULL) { +- const char *e = dlerror(); +- if (e == NULL) +- e = _("unknown failure"); +- Tprintf ("dlopen(%s): %s\n", filepath, e); +- err = ENOENT; /* XXX */ +- k5_set_error(ep, err, _("unable to load plugin [%s]: %s"), +- filepath, e); +- } +- } ++ if (h->dlhandle != NULL) ++ dlclose(h->dlhandle); ++} ++#define close_plugin close_plugin_dlfcn + +- if (!err) { +- got_plugin = 1; +- htmp->dlhandle = handle; +- handle = NULL; +- } ++#elif defined(_WIN32) + +- if (handle != NULL) { dlclose (handle); } ++static long ++open_plugin_win32(struct plugin_file_handle *h, const char *filename, ++ struct errinfo *ep) ++{ ++ h->module = LoadLibrary(filename); ++ if (h == NULL) { ++ Tprintf("Unable to load dll: %s\n", filename); ++ k5_set_error(ep, ENOENT, _("unable to load DLL [%s]"), filename); ++ return ENOENT; + } +-#endif /* USE_DLOPEN */ +- +-#ifdef _WIN32 +- if (!err && (statbuf.st_mode & S_IFMT) == S_IFREG) { +- HMODULE handle = NULL; ++ return 0; ++} ++#define open_plugin open_plugin_win32 + +- handle = LoadLibrary(filepath); +- if (handle == NULL) { +- Tprintf ("Unable to load dll: %s\n", filepath); +- err = ENOENT; /* XXX */ +- k5_set_error(ep, err, _("unable to load DLL [%s]"), filepath); +- } ++static long ++get_sym_win32(struct plugin_file_handle *h, const char *csymname, ++ void **sym_out, struct errinfo *ep) ++{ ++ LPVOID lpMsgBuf; ++ DWORD dw; + +- if (!err) { +- got_plugin = 1; +- htmp->hinstPlugin = handle; +- handle = NULL; ++ if (h->module == NULL) ++ return ENOENT; ++ *sym_out = GetProcAddress(h->module, csymname); ++ if (*sym_out == NULL) { ++ Tprintf("GetProcAddress(%s): %i\n", csymname, GetLastError()); ++ dw = GetLastError(); ++ if (FormatMessage(FORMAT_MESSAGE_ALLOCATE_BUFFER | ++ FORMAT_MESSAGE_FROM_SYSTEM, ++ NULL, dw, MAKELANGID(LANG_NEUTRAL, SUBLANG_DEFAULT), ++ (LPTSTR)&lpMsgBuf, 0, NULL)) { ++ k5_set_error(ep, ENOENT, _("unable to get DLL Symbol: %s"), ++ (char *)lpMsgBuf); ++ LocalFree(lpMsgBuf); + } +- +- if (handle != NULL) +- FreeLibrary(handle); +- } +-#endif +- +- if (!err && !got_plugin) { +- err = ENOENT; /* no plugin or no way to load plugins */ +- k5_set_error(ep, err, _("plugin unavailable: %s"), strerror(err)); ++ return ENOENT; + } ++ return 0; ++} ++#define get_sym get_sym_win32 + +- if (!err) { +- *h = htmp; +- htmp = NULL; /* h takes ownership */ +- } ++static void ++close_plugin_win32(struct plugin_file_handle *h) ++{ ++ if (h->module != NULL) ++ FreeLibrary(h->module); ++} ++#define close_plugin close_plugin_win32 + +- free(htmp); ++#else + +- return err; ++static long ++open_plugin_dummy(struct plugin_file_handle *h, const char *filename, ++ struct errinfo *ep) ++{ ++ k5_set_error(ep, ENOENT, _("plugin loading unavailable")); ++ return ENOENT; + } ++#define open_plugin open_plugin_dummy + + static long +-krb5int_get_plugin_sym (struct plugin_file_handle *h, +- const char *csymname, int isfunc, void **ptr, +- struct errinfo *ep) ++get_sym_dummy(struct plugin_file_handle *h, const char *csymname, ++ void **sym_out, struct errinfo *ep) + { +- long err = 0; +- void *sym = NULL; ++ return ENOENT; ++} ++#define get_sym get_sym_dummy ++ ++static void ++close_plugin_dummy(struct plugin_file_handle *h) ++{ ++} ++#define close_plugin close_plugin_dummy + +-#if USE_DLOPEN +- if (!err && !sym && (h->dlhandle != NULL)) { +- /* XXX Do we need to add a leading "_" to the symbol name on any +- modern platforms? */ +- sym = dlsym (h->dlhandle, csymname); +- if (sym == NULL) { +- const char *e = dlerror (); /* XXX copy and save away */ +- if (e == NULL) +- e = "unknown failure"; +- Tprintf ("dlsym(%s): %s\n", csymname, e); +- err = ENOENT; /* XXX */ +- k5_set_error(ep, err, "%s", e); +- } +- } + #endif + +-#ifdef _WIN32 +- LPVOID lpMsgBuf; +- DWORD dw; ++long KRB5_CALLCONV ++krb5int_open_plugin(const char *filename, ++ struct plugin_file_handle **handle_out, struct errinfo *ep) ++{ ++ long ret; ++ struct plugin_file_handle *h; + +- if (!err && !sym && (h->hinstPlugin != NULL)) { +- sym = GetProcAddress(h->hinstPlugin, csymname); +- if (sym == NULL) { +- const char *e = "unable to get dll symbol"; /* XXX copy and save away */ +- Tprintf ("GetProcAddress(%s): %i\n", csymname, GetLastError()); +- err = ENOENT; /* XXX */ +- k5_set_error(ep, err, "%s", e); +- +- dw = GetLastError(); +- if (FormatMessage(FORMAT_MESSAGE_ALLOCATE_BUFFER | +- FORMAT_MESSAGE_FROM_SYSTEM, +- NULL, +- dw, +- MAKELANGID(LANG_NEUTRAL, SUBLANG_DEFAULT), +- (LPTSTR) &lpMsgBuf, +- 0, NULL )) { +- +- fprintf (stderr, "unable to get dll symbol, %s\n", (LPCTSTR)lpMsgBuf); +- LocalFree(lpMsgBuf); +- } +- } +- } +-#endif ++ *handle_out = NULL; + +- if (!err && (sym == NULL)) { +- err = ENOENT; /* unimplemented */ +- } ++ h = calloc(1, sizeof(*h)); ++ if (h == NULL) ++ return ENOMEM; + +- if (!err) { +- *ptr = sym; ++ ret = open_plugin(h, filename, ep); ++ if (ret) { ++ free(h); ++ return ret; + } + +- return err; ++ *handle_out = h; ++ return 0; + } + + long KRB5_CALLCONV +-krb5int_get_plugin_data (struct plugin_file_handle *h, const char *csymname, +- void **ptr, struct errinfo *ep) ++krb5int_get_plugin_data(struct plugin_file_handle *h, const char *csymname, ++ void **sym_out, struct errinfo *ep) + { +- return krb5int_get_plugin_sym (h, csymname, 0, ptr, ep); ++ return get_sym(h, csymname, sym_out, ep); + } + + long KRB5_CALLCONV +-krb5int_get_plugin_func (struct plugin_file_handle *h, const char *csymname, +- void (**ptr)(), struct errinfo *ep) ++krb5int_get_plugin_func(struct plugin_file_handle *h, const char *csymname, ++ void (**sym_out)(), struct errinfo *ep) + { + void *dptr = NULL; +- long err = krb5int_get_plugin_sym (h, csymname, 1, &dptr, ep); +- if (!err) { +- /* Cast function pointers to avoid code duplication */ +- *ptr = (void (*)()) dptr; +- } +- return err; ++ long ret = get_sym(h, csymname, &dptr, ep); ++ ++ if (!ret) ++ *sym_out = (void (*)())dptr; ++ return ret; + } + + void KRB5_CALLCONV + krb5int_close_plugin (struct plugin_file_handle *h) + { +-#if USE_DLOPEN +- if (h->dlhandle != NULL) { dlclose(h->dlhandle); } +-#endif +-#ifdef _WIN32 +- if (h->hinstPlugin != NULL) { FreeLibrary(h->hinstPlugin); } +-#endif +- free (h); ++ close_plugin(h); ++ free(h); + } + +-/* autoconf docs suggest using this preference order */ +-#if HAVE_DIRENT_H || USE_DIRENT_H +-#include +-#define NAMELEN(D) strlen((D)->d_name) +-#else +-#ifndef _WIN32 +-#define dirent direct +-#define NAMELEN(D) ((D)->d->namlen) +-#else +-#define NAMELEN(D) strlen((D)->d_name) +-#endif +-#if HAVE_SYS_NDIR_H +-# include +-#elif HAVE_SYS_DIR_H +-# include +-#elif HAVE_NDIR_H +-# include +-#endif +-#endif +- + static long + krb5int_plugin_file_handle_array_init (struct plugin_file_handle ***harray) + { +@@ -619,42 +418,36 @@ krb5int_open_plugin_dirs (const char * const *dirnames, + if (handle != NULL) { krb5int_close_plugin (handle); } + } + } else { +- /* load all plugins in each directory */ +- DIR *dir = opendir (dirnames[i]); ++ char **fnames = NULL; ++ int j; + +- while (dir != NULL && !err) { +- struct dirent *d = NULL; ++ err = k5_dir_filenames(dirnames[i], &fnames); ++ for (j = 0; !err && fnames[j] != NULL; j++) { + char *filepath = NULL; + struct plugin_file_handle *handle = NULL; + +- d = readdir (dir); +- if (d == NULL) { break; } +- +- if ((strcmp (d->d_name, ".") == 0) || +- (strcmp (d->d_name, "..") == 0)) { ++ if (strcmp(fnames[j], ".") == 0 || ++ strcmp(fnames[j], "..") == 0) + continue; +- } + +- if (!err) { +- int len = NAMELEN (d); +- if (asprintf(&filepath, "%s/%*s", dirnames[i], len, d->d_name) < 0) { +- filepath = NULL; +- err = ENOMEM; +- } ++ if (asprintf(&filepath, "%s/%s", dirnames[i], fnames[j]) < 0) { ++ filepath = NULL; ++ err = ENOMEM; + } + +- if (!err) { +- if (krb5int_open_plugin (filepath, &handle, ep) == 0) { +- err = krb5int_plugin_file_handle_array_add (&h, &count, handle); +- if (!err) { handle = NULL; } /* h takes ownership */ +- } ++ if (!err && krb5int_open_plugin(filepath, &handle, ep) == 0) { ++ err = krb5int_plugin_file_handle_array_add(&h, &count, ++ handle); ++ if (!err) ++ handle = NULL; /* h takes ownership */ + } + + free(filepath); +- if (handle != NULL) { krb5int_close_plugin (handle); } ++ if (handle != NULL) ++ krb5int_close_plugin(handle); + } + +- if (dir != NULL) { closedir (dir); } ++ k5_free_filenames(fnames); + } + } + +-- +2.38.1 + diff --git a/Add-APIs-for-marshalling-credentials.patch b/Add-APIs-for-marshalling-credentials.patch deleted file mode 100644 index 8578721..0000000 --- a/Add-APIs-for-marshalling-credentials.patch +++ /dev/null @@ -1,220 +0,0 @@ -From 3a99832252755cf7e5fef2bd824459cea3eb823e Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 14 Jan 2021 18:13:09 -0500 -Subject: [PATCH] Add APIs for marshalling credentials - -Faciliate KCM daemon implementations by providing functions to -deserialize and reserialize credentials in the FILE v4 format. - -[ghudson@mit.edu: minor editorial changes] - -ticket: 8980 (new) -(cherry picked from commit 18ea3bd2fca55b789b7de9c663624bc11d348fa6) ---- - doc/appdev/refs/api/index.rst | 2 ++ - src/include/krb5/krb5.hin | 36 ++++++++++++++++++++++ - src/lib/krb5/ccache/ccmarshal.c | 53 +++++++++++++++++++++++++++++++++ - src/lib/krb5/ccache/t_marshal.c | 15 +++++++++- - src/lib/krb5/libkrb5.exports | 2 ++ - src/lib/krb5_32.def | 4 +++ - 6 files changed, 111 insertions(+), 1 deletion(-) - -diff --git a/doc/appdev/refs/api/index.rst b/doc/appdev/refs/api/index.rst -index 727d9b492..9e03fd386 100644 ---- a/doc/appdev/refs/api/index.rst -+++ b/doc/appdev/refs/api/index.rst -@@ -232,6 +232,7 @@ Rarely used public interfaces - krb5_kt_remove_entry.rst - krb5_kt_start_seq_get.rst - krb5_make_authdata_kdc_issued.rst -+ krb5_marshal_credentials.rst - krb5_merge_authdata.rst - krb5_mk_1cred.rst - krb5_mk_error.rst -@@ -285,6 +286,7 @@ Rarely used public interfaces - krb5_tkt_creds_get_times.rst - krb5_tkt_creds_init.rst - krb5_tkt_creds_step.rst -+ krb5_unmarshal_credentials.rst - krb5_verify_init_creds.rst - krb5_verify_init_creds_opt_init.rst - krb5_verify_init_creds_opt_set_ap_req_nofail.rst -diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 63e67a2ba..c26dde535 100644 ---- a/src/include/krb5/krb5.hin -+++ b/src/include/krb5/krb5.hin -@@ -3125,6 +3125,42 @@ krb5_get_credentials(krb5_context context, krb5_flags options, - krb5_ccache ccache, krb5_creds *in_creds, - krb5_creds **out_creds); - -+/** -+ * Serialize a @c krb5_creds object. -+ * -+ * @param [in] context Library context -+ * @param [in] creds The credentials object to serialize -+ * @param [out] data_out The serialized credentials -+ * -+ * Serialize @a creds in the format used by the FILE ccache format (vesion 4) -+ * and KCM ccache protocol. -+ * -+ * Use krb5_free_data() to free @a data_out when it is no longer needed. -+ * -+ * @retval 0 Success; otherwise - Kerberos error codes -+ */ -+krb5_error_code KRB5_CALLCONV -+krb5_marshal_credentials(krb5_context context, krb5_creds *in_creds, -+ krb5_data **data_out); -+ -+/** -+ * Deserialize a @c krb5_creds object. -+ * -+ * @param [in] context Library context -+ * @param [in] data The serialized credentials -+ * @param [out] creds_out The resulting creds object -+ * -+ * Deserialize @a data to credentials in the format used by the FILE ccache -+ * format (vesion 4) and KCM ccache protocol. -+ * -+ * Use krb5_free_creds() to free @a creds_out when it is no longer needed. -+ * -+ * @retval 0 Success; otherwise - Kerberos error codes -+ */ -+krb5_error_code KRB5_CALLCONV -+krb5_unmarshal_credentials(krb5_context context, const krb5_data *data, -+ krb5_creds **creds_out); -+ - /** @deprecated Replaced by krb5_get_validated_creds. */ - krb5_error_code KRB5_CALLCONV - krb5_get_credentials_validate(krb5_context context, krb5_flags options, -diff --git a/src/lib/krb5/ccache/ccmarshal.c b/src/lib/krb5/ccache/ccmarshal.c -index ae634ccab..ab284e721 100644 ---- a/src/lib/krb5/ccache/ccmarshal.c -+++ b/src/lib/krb5/ccache/ccmarshal.c -@@ -515,3 +515,56 @@ k5_marshal_mcred(struct k5buf *buf, krb5_creds *mcred) - if (mcred->second_ticket.length > 0) - put_data(buf, version, &mcred->second_ticket); - } -+ -+krb5_error_code KRB5_CALLCONV -+krb5_marshal_credentials(krb5_context context, krb5_creds *in_creds, -+ krb5_data **data_out) -+{ -+ krb5_error_code ret; -+ krb5_data *data; -+ struct k5buf buf; -+ -+ *data_out = NULL; -+ -+ data = k5alloc(sizeof(krb5_data), &ret); -+ if (ret) -+ return ret; -+ -+ k5_buf_init_dynamic(&buf); -+ k5_marshal_cred(&buf, 4, in_creds); -+ -+ ret = k5_buf_status(&buf); -+ if (ret) { -+ free(data); -+ return ret; -+ } -+ -+ /* Steal payload from buf. */ -+ *data = make_data(buf.data, buf.len); -+ *data_out = data; -+ return 0; -+} -+ -+krb5_error_code KRB5_CALLCONV -+krb5_unmarshal_credentials(krb5_context context, const krb5_data *data, -+ krb5_creds **creds_out) -+{ -+ krb5_error_code ret; -+ krb5_creds *creds; -+ -+ *creds_out = NULL; -+ -+ creds = k5alloc(sizeof(krb5_creds), &ret); -+ if (ret) -+ return ret; -+ -+ ret = k5_unmarshal_cred((unsigned char *)data->data, data->length, 4, -+ creds); -+ if (ret) { -+ free(creds); -+ return ret; -+ } -+ -+ *creds_out = creds; -+ return 0; -+} -diff --git a/src/lib/krb5/ccache/t_marshal.c b/src/lib/krb5/ccache/t_marshal.c -index bd0284afa..96e0931a2 100644 ---- a/src/lib/krb5/ccache/t_marshal.c -+++ b/src/lib/krb5/ccache/t_marshal.c -@@ -268,13 +268,14 @@ main(int argc, char **argv) - krb5_context context; - krb5_ccache cache; - krb5_principal princ; -- krb5_creds cred1, cred2; -+ krb5_creds cred1, cred2, *alloc_cred; - krb5_cc_cursor cursor; - const char *filename; - char *ccname, filebuf[256]; - int version, fd; - const struct test *t; - struct k5buf buf; -+ krb5_data ser_data, *alloc_data; - - if (argc != 2) - abort(); -@@ -285,6 +286,18 @@ main(int argc, char **argv) - if (krb5_init_context(&context) != 0) - abort(); - -+ /* Test public functions for unmarshalling and marshalling. */ -+ ser_data = make_data((char *)tests[3].cred1, tests[3].cred1len); -+ if (krb5_unmarshal_credentials(context, &ser_data, &alloc_cred) != 0) -+ abort(); -+ verify_cred1(alloc_cred); -+ if (krb5_marshal_credentials(context, alloc_cred, &alloc_data) != 0) -+ abort(); -+ assert(alloc_data->length == tests[3].cred1len); -+ assert(memcmp(tests[3].cred1, alloc_data->data, alloc_data->length) == 0); -+ krb5_free_data(context, alloc_data); -+ krb5_free_creds(context, alloc_cred); -+ - for (version = FIRST_VERSION; version <= 4; version++) { - t = &tests[version - 1]; - -diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports -index 2d9d56530..adbfa332b 100644 ---- a/src/lib/krb5/libkrb5.exports -+++ b/src/lib/krb5/libkrb5.exports -@@ -489,6 +489,7 @@ krb5_lock_file - krb5_make_authdata_kdc_issued - krb5_make_full_ipaddr - krb5_make_fulladdr -+krb5_marshal_credentials - krb5_mcc_ops - krb5_merge_authdata - krb5_mk_1cred -@@ -592,6 +593,7 @@ krb5_timeofday - krb5_timestamp_to_sfstring - krb5_timestamp_to_string - krb5_unlock_file -+krb5_unmarshal_credentials - krb5_unpack_full_ipaddr - krb5_unparse_name - krb5_unparse_name_ext -diff --git a/src/lib/krb5_32.def b/src/lib/krb5_32.def -index 4953907aa..60b8dd311 100644 ---- a/src/lib/krb5_32.def -+++ b/src/lib/krb5_32.def -@@ -503,3 +503,7 @@ EXPORTS - ; new in 1.19 - k5_cc_store_primary_cred @470 ; PRIVATE - k5_kt_have_match @471 ; PRIVATE GSSAPI -+ -+; new in 1.20 -+ krb5_marshal_credentials @472 -+ krb5_unmarshal_credentials @473 diff --git a/Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch b/Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch deleted file mode 100644 index 455e3e0..0000000 --- a/Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch +++ /dev/null @@ -1,358 +0,0 @@ -From 8772d8f47b7460a0eef48366881483fd9b3acfd3 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Pavel=20B=C5=99ezina?= -Date: Thu, 11 Feb 2021 15:33:10 +0100 -Subject: [PATCH] Add KCM_OP_GET_CRED_LIST for faster iteration - -For large caches, one IPC operation per credential dominates the cost -of iteration. Instead transfer the whole list of credentials to the -client in one IPC operation. - -Add optional support for the new opcode to the test KCM server to -allow testing of the main and fallback code paths. - -[ghudson@mit.edu: fixed memory leaks and potential memory errors; -adjusted code style and comments; rewrote commit message; added -kcmserver.py support and tests] - -ticket: 8990 (new) -(cherry picked from commit 81bdb47d8ded390263d8ee48f71d5c312b4f1736) ---- - src/include/kcm.h | 12 ++- - src/lib/krb5/ccache/cc_kcm.c | 144 ++++++++++++++++++++++++++++++++--- - src/tests/kcmserver.py | 28 ++++++- - src/tests/t_ccache.py | 10 ++- - 4 files changed, 175 insertions(+), 19 deletions(-) - -diff --git a/src/include/kcm.h b/src/include/kcm.h -index 5ea1447cd..e4140c3a0 100644 ---- a/src/include/kcm.h -+++ b/src/include/kcm.h -@@ -51,9 +51,9 @@ - * - * All replies begin with a 32-bit big-endian reply code. - * -- * Parameters are appended to the request or reply with no delimiters. Flags -- * and time offsets are stored as 32-bit big-endian integers. Names are -- * marshalled as zero-terminated strings. Principals and credentials are -+ * Parameters are appended to the request or reply with no delimiters. Flags, -+ * time offsets, and lengths are stored as 32-bit big-endian integers. Names -+ * are marshalled as zero-terminated strings. Principals and credentials are - * marshalled in the v4 FILE ccache format. UUIDs are 16 bytes. UUID lists - * are not delimited, so nothing can come after them. - */ -@@ -89,7 +89,11 @@ typedef enum kcm_opcode { - KCM_OP_HAVE_NTLM_CRED, - KCM_OP_DEL_NTLM_CRED, - KCM_OP_DO_NTLM_AUTH, -- KCM_OP_GET_NTLM_USER_LIST -+ KCM_OP_GET_NTLM_USER_LIST, -+ -+ /* MIT extensions */ -+ KCM_OP_MIT_EXTENSION_BASE = 13000, -+ KCM_OP_GET_CRED_LIST, /* (name) -> (count, count*{len, cred}) */ - } kcm_opcode; - - #endif /* KCM_H */ -diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c -index 9093f894d..772928e4d 100644 ---- a/src/lib/krb5/ccache/cc_kcm.c -+++ b/src/lib/krb5/ccache/cc_kcm.c -@@ -61,6 +61,17 @@ struct uuid_list { - size_t pos; - }; - -+struct cred_list { -+ krb5_creds *creds; -+ size_t count; -+ size_t pos; -+}; -+ -+struct kcm_cursor { -+ struct uuid_list *uuids; -+ struct cred_list *creds; -+}; -+ - struct kcmio { - SOCKET fd; - #ifdef __APPLE__ -@@ -489,6 +500,69 @@ free_uuid_list(struct uuid_list *uuids) - free(uuids); - } - -+static void -+free_cred_list(struct cred_list *list) -+{ -+ size_t i; -+ -+ if (list == NULL) -+ return; -+ -+ /* Creds are transferred to the caller as list->pos is incremented, so we -+ * can start freeing there. */ -+ for (i = list->pos; i < list->count; i++) -+ krb5_free_cred_contents(NULL, &list->creds[i]); -+ free(list->creds); -+ free(list); -+} -+ -+/* Fetch a cred list from req->reply. */ -+static krb5_error_code -+kcmreq_get_cred_list(struct kcmreq *req, struct cred_list **creds_out) -+{ -+ struct cred_list *list; -+ const unsigned char *data; -+ krb5_error_code ret = 0; -+ size_t count, len, i; -+ -+ *creds_out = NULL; -+ -+ /* Check a rough bound on the count to prevent very large allocations. */ -+ count = k5_input_get_uint32_be(&req->reply); -+ if (count > req->reply.len / 4) -+ return KRB5_KCM_MALFORMED_REPLY; -+ -+ list = malloc(sizeof(*list)); -+ if (list == NULL) -+ return ENOMEM; -+ -+ list->creds = NULL; -+ list->count = count; -+ list->pos = 0; -+ list->creds = k5calloc(count, sizeof(*list->creds), &ret); -+ if (list->creds == NULL) { -+ free(list); -+ return ret; -+ } -+ -+ for (i = 0; i < count; i++) { -+ len = k5_input_get_uint32_be(&req->reply); -+ data = k5_input_get_bytes(&req->reply, len); -+ if (data == NULL) -+ break; -+ ret = k5_unmarshal_cred(data, len, 4, &list->creds[i]); -+ if (ret) -+ break; -+ } -+ if (i < count) { -+ free_cred_list(list); -+ return (ret == ENOMEM) ? ENOMEM : KRB5_KCM_MALFORMED_REPLY; -+ } -+ -+ *creds_out = list; -+ return 0; -+} -+ - static void - kcmreq_free(struct kcmreq *req) - { -@@ -753,33 +827,53 @@ kcm_start_seq_get(krb5_context context, krb5_ccache cache, - { - krb5_error_code ret; - struct kcmreq req = EMPTY_KCMREQ; -- struct uuid_list *uuids; -+ struct uuid_list *uuids = NULL; -+ struct cred_list *creds = NULL; -+ struct kcm_cursor *cursor; - - *cursor_out = NULL; - - get_kdc_offset(context, cache); - -- kcmreq_init(&req, KCM_OP_GET_CRED_UUID_LIST, cache); -+ kcmreq_init(&req, KCM_OP_GET_CRED_LIST, cache); - ret = cache_call(context, cache, &req); -- if (ret) -+ if (ret == 0) { -+ /* GET_CRED_LIST is available. */ -+ ret = kcmreq_get_cred_list(&req, &creds); -+ if (ret) -+ goto cleanup; -+ } else if (ret == KRB5_FCC_INTERNAL) { -+ /* Fall back to GET_CRED_UUID_LIST. */ -+ kcmreq_free(&req); -+ kcmreq_init(&req, KCM_OP_GET_CRED_UUID_LIST, cache); -+ ret = cache_call(context, cache, &req); -+ if (ret) -+ goto cleanup; -+ ret = kcmreq_get_uuid_list(&req, &uuids); -+ if (ret) -+ goto cleanup; -+ } else { - goto cleanup; -- ret = kcmreq_get_uuid_list(&req, &uuids); -- if (ret) -+ } -+ -+ cursor = k5alloc(sizeof(*cursor), &ret); -+ if (cursor == NULL) - goto cleanup; -- *cursor_out = (krb5_cc_cursor)uuids; -+ cursor->uuids = uuids; -+ cursor->creds = creds; -+ *cursor_out = (krb5_cc_cursor)cursor; - - cleanup: - kcmreq_free(&req); - return ret; - } - --static krb5_error_code KRB5_CALLCONV --kcm_next_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor, -- krb5_creds *cred_out) -+static krb5_error_code -+next_cred_by_uuid(krb5_context context, krb5_ccache cache, -+ struct uuid_list *uuids, krb5_creds *cred_out) - { - krb5_error_code ret; - struct kcmreq req; -- struct uuid_list *uuids = (struct uuid_list *)*cursor; - - memset(cred_out, 0, sizeof(*cred_out)); - -@@ -797,11 +891,39 @@ kcm_next_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor, - return map_invalid(ret); - } - -+static krb5_error_code KRB5_CALLCONV -+kcm_next_cred(krb5_context context, krb5_ccache cache, krb5_cc_cursor *cursor, -+ krb5_creds *cred_out) -+{ -+ struct kcm_cursor *c = (struct kcm_cursor *)*cursor; -+ struct cred_list *list; -+ -+ if (c->uuids != NULL) -+ return next_cred_by_uuid(context, cache, c->uuids, cred_out); -+ -+ list = c->creds; -+ if (list->pos >= list->count) -+ return KRB5_CC_END; -+ -+ /* Transfer memory ownership of one cred to the caller. */ -+ *cred_out = list->creds[list->pos]; -+ memset(&list->creds[list->pos], 0, sizeof(*list->creds)); -+ list->pos++; -+ -+ return 0; -+} -+ - static krb5_error_code KRB5_CALLCONV - kcm_end_seq_get(krb5_context context, krb5_ccache cache, - krb5_cc_cursor *cursor) - { -- free_uuid_list((struct uuid_list *)*cursor); -+ struct kcm_cursor *c = *cursor; -+ -+ if (c == NULL) -+ return 0; -+ free_uuid_list(c->uuids); -+ free_cred_list(c->creds); -+ free(c); - *cursor = NULL; - return 0; - } -diff --git a/src/tests/kcmserver.py b/src/tests/kcmserver.py -index 57432e5a7..8c5e66ff1 100644 ---- a/src/tests/kcmserver.py -+++ b/src/tests/kcmserver.py -@@ -23,6 +23,7 @@ - # traceback.print_exception(etype, value, tb, file=f) - # sys.excepthook = ehook - -+import optparse - import select - import socket - import struct -@@ -49,12 +50,14 @@ class KCMOpcodes(object): - SET_DEFAULT_CACHE = 21 - GET_KDC_OFFSET = 22 - SET_KDC_OFFSET = 23 -+ GET_CRED_LIST = 13001 - - - class KRB5Errors(object): - KRB5_CC_END = -1765328242 - KRB5_CC_NOSUPP = -1765328137 - KRB5_FCC_NOFILE = -1765328189 -+ KRB5_FCC_INTERNAL = -1765328188 - - - def make_uuid(): -@@ -183,6 +186,14 @@ def op_set_kdc_offset(argbytes): - return 0, b'' - - -+def op_get_cred_list(argbytes): -+ name, rest = unmarshal_name(argbytes) -+ cache = get_cache(name) -+ creds = [cache.creds[u] for u in cache.cred_uuids] -+ return 0, (struct.pack('>L', len(creds)) + -+ b''.join(struct.pack('>L', len(c)) + c for c in creds)) -+ -+ - ophandlers = { - KCMOpcodes.GEN_NEW : op_gen_new, - KCMOpcodes.INITIALIZE : op_initialize, -@@ -197,7 +208,8 @@ ophandlers = { - KCMOpcodes.GET_DEFAULT_CACHE : op_get_default_cache, - KCMOpcodes.SET_DEFAULT_CACHE : op_set_default_cache, - KCMOpcodes.GET_KDC_OFFSET : op_get_kdc_offset, -- KCMOpcodes.SET_KDC_OFFSET : op_set_kdc_offset -+ KCMOpcodes.SET_KDC_OFFSET : op_set_kdc_offset, -+ KCMOpcodes.GET_CRED_LIST : op_get_cred_list - } - - # Read and respond to a request from the socket s. -@@ -215,7 +227,11 @@ def service_request(s): - - majver, minver, op = struct.unpack('>BBH', req[:4]) - argbytes = req[4:] -- code, payload = ophandlers[op](argbytes) -+ -+ if op in ophandlers: -+ code, payload = ophandlers[op](argbytes) -+ else: -+ code, payload = KRB5Errors.KRB5_FCC_INTERNAL, b'' - - # The KCM response is the code (4 bytes) and the response payload. - # The Heimdal IPC response is the length of the KCM response (4 -@@ -226,9 +242,15 @@ def service_request(s): - s.sendall(hipc_response) - return True - -+parser = optparse.OptionParser() -+parser.add_option('-c', '--credlist', action='store_true', dest='credlist', -+ default=False, help='Support KCM_OP_GET_CRED_LIST') -+(options, args) = parser.parse_args() -+if not options.credlist: -+ del ophandlers[KCMOpcodes.GET_CRED_LIST] - - server = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM) --server.bind(sys.argv[1]) -+server.bind(args[0]) - server.listen(5) - select_input = [server,] - sys.stderr.write('starting...\n') -diff --git a/src/tests/t_ccache.py b/src/tests/t_ccache.py -index 66804afa5..90040fb7b 100755 ---- a/src/tests/t_ccache.py -+++ b/src/tests/t_ccache.py -@@ -125,10 +125,18 @@ def collection_test(realm, ccname): - - - collection_test(realm, 'DIR:' + os.path.join(realm.testdir, 'cc')) -+ -+# Test KCM without and with GET_CRED_LIST support. - kcmserver_path = os.path.join(srctop, 'tests', 'kcmserver.py') --realm.start_server([sys.executable, kcmserver_path, kcm_socket_path], -+kcmd = realm.start_server([sys.executable, kcmserver_path, kcm_socket_path], -+ 'starting...') -+collection_test(realm, 'KCM:') -+stop_daemon(kcmd) -+os.remove(kcm_socket_path) -+realm.start_server([sys.executable, kcmserver_path, '-c', kcm_socket_path], - 'starting...') - collection_test(realm, 'KCM:') -+ - if test_keyring: - def cleanup_keyring(anchor, name): - out = realm.run(['keyctl', 'list', anchor]) diff --git a/Add-buildsystem-detection-of-the-OpenSSL-3-KDF-inter.patch b/Add-buildsystem-detection-of-the-OpenSSL-3-KDF-inter.patch deleted file mode 100644 index 269a457..0000000 --- a/Add-buildsystem-detection-of-the-OpenSSL-3-KDF-inter.patch +++ /dev/null @@ -1,25 +0,0 @@ -From 2f039fc910022c9569fe6941a194f0b26bd6c894 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 20 Sep 2019 16:11:29 -0400 -Subject: [PATCH] Add buildsystem detection of the OpenSSL-3 KDF interface - -(cherry picked from commit a3e03dfd40928c4615bd9b8546eac0c104377850) ---- - src/configure.ac | 4 ++++ - 1 file changed, 4 insertions(+) - -diff --git a/src/configure.ac b/src/configure.ac -index eb6307468..9c2e816fe 100644 ---- a/src/configure.ac -+++ b/src/configure.ac -@@ -282,6 +282,10 @@ AC_SUBST(CRYPTO_IMPL) - AC_SUBST(CRYPTO_IMPL_CFLAGS) - AC_SUBST(CRYPTO_IMPL_LIBS) - -+if test "$CRYPTO_IMPL" = openssl; then -+ AC_CHECK_FUNCS(EVP_KDF_fetch) -+fi -+ - AC_ARG_WITH([prng-alg], - AC_HELP_STRING([--with-prng-alg=ALG], [use specified PRNG algorithm. @<:@fortuna@:>@]), - [PRNG_ALG=$withval diff --git a/Add-hostname-canonicalization-helper-to-k5test.py.patch b/Add-hostname-canonicalization-helper-to-k5test.py.patch deleted file mode 100644 index 58179a2..0000000 --- a/Add-hostname-canonicalization-helper-to-k5test.py.patch +++ /dev/null @@ -1,84 +0,0 @@ -From e88f0319427cee7245fb05c97a25473297c9d2d6 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 15 Jan 2021 14:43:34 -0500 -Subject: [PATCH] Add hostname canonicalization helper to k5test.py - -To facilitate fallback tests, add a canonicalize_hostname() function -to k5test.py which works similarly to krb5_expand_hostname(). Use it -in t_gssapi.py for the recently-added acceptor name fallback test. - -(cherry picked from commit 225fffe4e912772acea3a01d45bafb60bfb80948) ---- - src/tests/gssapi/t_gssapi.py | 11 +++-------- - src/util/k5test.py | 22 ++++++++++++++++++++++ - 2 files changed, 25 insertions(+), 8 deletions(-) - -diff --git a/src/tests/gssapi/t_gssapi.py b/src/tests/gssapi/t_gssapi.py -index 1af6f31c2..e22cec427 100755 ---- a/src/tests/gssapi/t_gssapi.py -+++ b/src/tests/gssapi/t_gssapi.py -@@ -8,7 +8,7 @@ for realm in multipass_realms(): - realm.run(['./t_iov', '-s', 'p:' + realm.host_princ]) - realm.run(['./t_pcontok', 'p:' + realm.host_princ]) - --realm = K5Realm(krb5_conf={'libdefaults': {'rdns': 'false'}}) -+realm = K5Realm() - - # Test gss_add_cred(). - realm.run(['./t_add_cred']) -@@ -62,13 +62,8 @@ realm.run(['./t_accname', 'p:host/-nomatch-', - expected_msg=' not found in keytab') - - # If possible, test with an acceptor name requiring fallback to match --# against a keytab entry. Forward-canonicalize the hostname, relying --# on the rdns=false realm setting. --try: -- ai = socket.getaddrinfo(hostname, None, 0, 0, 0, socket.AI_CANONNAME) -- (family, socktype, proto, canonname, sockaddr) = ai[0] --except socket.gaierror: -- canonname = hostname -+# against a keytab entry. -+canonname = canonicalize_hostname(hostname) - if canonname != hostname: - os.rename(realm.keytab, realm.keytab + '.save') - canonprinc = 'host/' + canonname -diff --git a/src/util/k5test.py b/src/util/k5test.py -index 789b0f4b9..251d11a9d 100644 ---- a/src/util/k5test.py -+++ b/src/util/k5test.py -@@ -155,6 +155,10 @@ Scripts may use the following functions and variables: - * password(name): Return a weakly random password based on name. The - password will be consistent across calls with the same name. - -+* canonicalize_hostname(name, rdns=True): Return the DNS -+ canonicalization of name, optionally using reverse DNS. On error, -+ return name converted to lowercase. -+ - * stop_daemon(proc): Stop a daemon process started with - realm.start_server() or realm.start_in_inetd(). Only necessary if - the port needs to be reused; daemon processes will be stopped -@@ -458,6 +462,24 @@ def password(name): - return name + str(os.getpid()) - - -+def canonicalize_hostname(name, rdns=True): -+ """Canonicalize name using DNS, optionally with reverse DNS.""" -+ try: -+ ai = socket.getaddrinfo(name, None, 0, 0, 0, socket.AI_CANONNAME) -+ except socket.gaierror as e: -+ return name.lower() -+ (family, socktype, proto, canonname, sockaddr) = ai[0] -+ -+ if not rdns: -+ return canonname.lower() -+ -+ try: -+ rname = socket.getnameinfo(sockaddr, socket.NI_NAMEREQD) -+ except socket.gaierror: -+ return canonname.lower() -+ return rname[0].lower() -+ -+ - # Exit handler which ensures processes are cleaned up and, on failure, - # prints messages to help developers debug the problem. - def _onexit(): diff --git a/Allow-kinit-with-keytab-to-defer-canonicalization.patch b/Allow-kinit-with-keytab-to-defer-canonicalization.patch deleted file mode 100644 index eee7d1d..0000000 --- a/Allow-kinit-with-keytab-to-defer-canonicalization.patch +++ /dev/null @@ -1,60 +0,0 @@ -From fb4d9fa851b1d0d3375556d1cdc1fce72176df1e Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 3 Jun 2021 16:03:07 -0400 -Subject: [PATCH] Allow kinit with keytab to defer canonicalization - -[ghudson@mit.edu: added tests] - -ticket: 9012 (new) -(cherry picked from commit 5e6a6efc5df689d9fb8730d0227167ffbb6ece0e) ---- - src/clients/kinit/kinit.c | 11 ----------- - src/tests/t_keytab.py | 13 +++++++++++++ - 2 files changed, 13 insertions(+), 11 deletions(-) - -diff --git a/src/clients/kinit/kinit.c b/src/clients/kinit/kinit.c -index d1f5d74c3..5a6d7237c 100644 ---- a/src/clients/kinit/kinit.c -+++ b/src/clients/kinit/kinit.c -@@ -510,17 +510,6 @@ k5_begin(struct k_opts *opts, struct k5_data *k5) - _("when creating default server principal name")); - goto cleanup; - } -- if (k5->me->realm.data[0] == 0) { -- ret = krb5_unparse_name(k5->ctx, k5->me, &k5->name); -- if (ret == 0) { -- com_err(progname, KRB5_ERR_HOST_REALM_UNKNOWN, -- _("(principal %s)"), k5->name); -- } else { -- com_err(progname, KRB5_ERR_HOST_REALM_UNKNOWN, -- _("for local services")); -- } -- goto cleanup; -- } - } else if (k5->out_cc != NULL) { - /* If the output ccache is initialized, use its principal. */ - if (krb5_cc_get_principal(k5->ctx, k5->out_cc, &princ) == 0) -diff --git a/src/tests/t_keytab.py b/src/tests/t_keytab.py -index 850375c92..a9adebb26 100755 ---- a/src/tests/t_keytab.py -+++ b/src/tests/t_keytab.py -@@ -41,6 +41,19 @@ realm.kinit(realm.user_princ, flags=['-i'], - expected_msg='keytab specified, forcing -k') - realm.klist(realm.user_princ) - -+# Test default principal for -k. This operation requires -+# canonicalization against the keytab in krb5_get_init_creds_keytab() -+# as the krb5_sname_to_principal() result won't have a realm. Try -+# with and without without fallback processing since the code paths -+# are different. -+mark('default principal for -k') -+realm.run([kinit, '-k']) -+realm.klist(realm.host_princ) -+no_canon_conf = {'libdefaults': {'dns_canonicalize_hostname': 'false'}} -+no_canon = realm.special_env('no_canon', False, krb5_conf=no_canon_conf) -+realm.run([kinit, '-k'], env=no_canon) -+realm.klist(realm.host_princ) -+ - # Test extracting keys with multiple key versions present. - mark('multi-kvno extract') - os.remove(realm.keytab) diff --git a/Clean-up-context-after-failed-open-in-libkdb5.patch b/Clean-up-context-after-failed-open-in-libkdb5.patch deleted file mode 100644 index fca6a71..0000000 --- a/Clean-up-context-after-failed-open-in-libkdb5.patch +++ /dev/null @@ -1,35 +0,0 @@ -From 95547c12b39e62df55cef05cae890302834b7f98 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 23 Jun 2021 16:57:39 -0400 -Subject: [PATCH] Clean up context after failed open in libkdb5 - -If krb5_db_open() or krb5_db_create() fails, release the dal_handle, -as the caller is unlikely to call krb5_db_close() after a failure. - -(cherry picked from commit 849b7056e703bd3724d909263769ce190db59acc) ---- - src/lib/kdb/kdb5.c | 4 ++++ - 1 file changed, 4 insertions(+) - -diff --git a/src/lib/kdb/kdb5.c b/src/lib/kdb/kdb5.c -index 47e9b31a7..11e2430c4 100644 ---- a/src/lib/kdb/kdb5.c -+++ b/src/lib/kdb/kdb5.c -@@ -675,6 +675,8 @@ krb5_db_open(krb5_context kcontext, char **db_args, int mode) - return status; - status = v->init_module(kcontext, section, db_args, mode); - free(section); -+ if (status) -+ (void)krb5_db_fini(kcontext); - return status; - } - -@@ -702,6 +704,8 @@ krb5_db_create(krb5_context kcontext, char **db_args) - return status; - status = v->create(kcontext, section, db_args); - free(section); -+ if (status) -+ (void)krb5_db_fini(kcontext); - return status; - } - diff --git a/Clean-up-gssapi_krb5-ccache-name-functions.patch b/Clean-up-gssapi_krb5-ccache-name-functions.patch deleted file mode 100644 index 207f186..0000000 --- a/Clean-up-gssapi_krb5-ccache-name-functions.patch +++ /dev/null @@ -1,193 +0,0 @@ -From 5e5ea8e8345c8b2f3254b0d346b8e0de0df3a696 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 26 May 2021 18:22:10 -0400 -Subject: [PATCH] Clean up gssapi_krb5 ccache name functions - -Modernize kg_get_ccache_name() and kg_get_ccache_name(). Drop -unnecessary use of const in kg_get_ccache_name() so that its return -value can be properly freed. Fixes some static analyzer false -positives. - -(cherry picked from commit f573f7f8ee5269103a0492d6521a3242c5ffb63b) ---- - src/lib/gssapi/krb5/gssapiP_krb5.h | 3 +- - src/lib/gssapi/krb5/gssapi_krb5.c | 47 ++++++++-------------- - src/lib/gssapi/krb5/set_ccache.c | 64 ++++++++++++------------------ - 3 files changed, 42 insertions(+), 72 deletions(-) - -diff --git a/src/lib/gssapi/krb5/gssapiP_krb5.h b/src/lib/gssapi/krb5/gssapiP_krb5.h -index fd7abbd77..88d41130a 100644 ---- a/src/lib/gssapi/krb5/gssapiP_krb5.h -+++ b/src/lib/gssapi/krb5/gssapiP_krb5.h -@@ -380,8 +380,7 @@ OM_uint32 kg_sync_ccache_name (krb5_context context, OM_uint32 *minor_status); - OM_uint32 kg_caller_provided_ccache_name (OM_uint32 *minor_status, - int *out_caller_provided_name); - --OM_uint32 kg_get_ccache_name (OM_uint32 *minor_status, -- const char **out_name); -+OM_uint32 kg_get_ccache_name (OM_uint32 *minor_status, char **out_name); - - OM_uint32 kg_set_ccache_name (OM_uint32 *minor_status, - const char *name); -diff --git a/src/lib/gssapi/krb5/gssapi_krb5.c b/src/lib/gssapi/krb5/gssapi_krb5.c -index 46aa9b7a5..9915a8bb5 100644 ---- a/src/lib/gssapi/krb5/gssapi_krb5.c -+++ b/src/lib/gssapi/krb5/gssapi_krb5.c -@@ -253,46 +253,31 @@ kg_caller_provided_ccache_name (OM_uint32 *minor_status, - } - - OM_uint32 --kg_get_ccache_name (OM_uint32 *minor_status, const char **out_name) -+kg_get_ccache_name(OM_uint32 *minor_status, char **out_name) - { -- const char *name = NULL; -- OM_uint32 err = 0; - char *kg_ccache_name; -+ const char *def_name; -+ OM_uint32 err; -+ krb5_context context; -+ -+ *out_name = NULL; - - kg_ccache_name = k5_getspecific(K5_KEY_GSS_KRB5_CCACHE_NAME); -- - if (kg_ccache_name != NULL) { -- name = strdup(kg_ccache_name); -- if (name == NULL) -- err = ENOMEM; -+ *out_name = strdup(kg_ccache_name); -+ err = (*out_name == NULL) ? ENOMEM : 0; - } else { -- krb5_context context = NULL; -- -- /* Reset the context default ccache (see text above), and then -- retrieve it. */ -+ /* Use the default ccache name. */ - err = krb5_gss_init_context(&context); -- if (!err) -- err = krb5_cc_set_default_name (context, NULL); -- if (!err) { -- name = krb5_cc_default_name(context); -- if (name) { -- name = strdup(name); -- if (name == NULL) -- err = ENOMEM; -- } -- } -- if (err && context) -- save_error_info(err, context); -- if (context) -- krb5_free_context(context); -- } -- -- if (!err) { -- if (out_name) { -- *out_name = name; -- } -+ if (err) -+ goto cleanup; -+ def_name = krb5_cc_default_name(context); -+ *out_name = (def_name != NULL) ? strdup(def_name) : NULL; -+ err = (*out_name == NULL) ? ENOMEM : 0; -+ krb5_free_context(context); - } - -+cleanup: - *minor_status = err; - return (*minor_status == 0) ? GSS_S_COMPLETE : GSS_S_FAILURE; - } -diff --git a/src/lib/gssapi/krb5/set_ccache.c b/src/lib/gssapi/krb5/set_ccache.c -index 8acf3ec90..91c3462be 100644 ---- a/src/lib/gssapi/krb5/set_ccache.c -+++ b/src/lib/gssapi/krb5/set_ccache.c -@@ -26,7 +26,7 @@ - - /* - * Set ccache name used by gssapi, and optionally obtain old ccache -- * name. Caller should not free returned name. -+ * name. Caller must not free returned name. - */ - - #include -@@ -38,11 +38,9 @@ gss_krb5int_ccache_name(OM_uint32 *minor_status, - const gss_OID desired_object, - const gss_buffer_t value) - { -- char *old_name = NULL; - OM_uint32 err = 0; -- OM_uint32 minor = 0; -- char *gss_out_name; - struct krb5_gss_ccache_name_req *req; -+ char *old_name, *cur_name = NULL; - - err = gss_krb5int_initialize_library(); - if (err) { -@@ -57,45 +55,33 @@ gss_krb5int_ccache_name(OM_uint32 *minor_status, - - req = (struct krb5_gss_ccache_name_req *)value->value; - -- gss_out_name = k5_getspecific(K5_KEY_GSS_KRB5_SET_CCACHE_OLD_NAME); -+ /* Our job is simple if the caller doesn't want the current name. */ -+ if (req->out_name == NULL) -+ return kg_set_ccache_name(minor_status, req->name); - -- if (req->out_name) { -- const char *tmp_name = NULL; -+ /* Fetch the current name and change it. */ -+ kg_get_ccache_name(&err, &cur_name); -+ if (err) -+ goto cleanup; -+ kg_set_ccache_name(&err, req->name); -+ if (err) -+ goto cleanup; - -- if (!err) { -- kg_get_ccache_name (&err, &tmp_name); -- } -- if (!err) { -- old_name = gss_out_name; -- gss_out_name = (char *)tmp_name; -- } -- } -- /* If out_name was NULL, we keep the same gss_out_name value, and -- don't free up any storage (leave old_name NULL). */ -+ /* Store the current name in a thread-specific variable. Free that -+ * variable's previous contents. */ -+ old_name = k5_getspecific(K5_KEY_GSS_KRB5_SET_CCACHE_OLD_NAME); -+ err = k5_setspecific(K5_KEY_GSS_KRB5_SET_CCACHE_OLD_NAME, cur_name); -+ if (err) -+ goto cleanup; -+ free(old_name); - -- if (!err) -- kg_set_ccache_name (&err, req->name); -- -- minor = k5_setspecific(K5_KEY_GSS_KRB5_SET_CCACHE_OLD_NAME, gss_out_name); -- if (minor) { -- /* Um. Now what? */ -- if (err == 0) { -- err = minor; -- } -- free(gss_out_name); -- gss_out_name = NULL; -- } -- -- if (!err) { -- if (req->out_name) { -- *(req->out_name) = gss_out_name; -- } -- } -- -- if (old_name != NULL) { -- free (old_name); -- } -+ /* Give the caller an alias to the stored value. */ -+ *req->out_name = cur_name; -+ cur_name = NULL; -+ err = 0; - -+cleanup: -+ free(cur_name); - *minor_status = err; - return (*minor_status == 0) ? GSS_S_COMPLETE : GSS_S_FAILURE; - } diff --git a/Fix-KCM-flag-transmission-for-remove_cred.patch b/Fix-KCM-flag-transmission-for-remove_cred.patch deleted file mode 100644 index 77c383e..0000000 --- a/Fix-KCM-flag-transmission-for-remove_cred.patch +++ /dev/null @@ -1,103 +0,0 @@ -From 1528c264d0e1eebff34132c01f4f770f01f1d1c2 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 29 Mar 2021 14:32:56 -0400 -Subject: [PATCH] Fix KCM flag transmission for remove_cred - -MIT krb5 uses low bits for KRB5_TC flags, while Heimdal uses high bits -so that the same flag word can also hold KRB5_GC flags. Add a mapping -function and send the Heimdal flag values when performing a -remove_cred operation. - -ticket: 8995 -(cherry picked from commit 11a82cf424f9c905bb73680c64524f087090d4ef) ---- - src/include/kcm.h | 19 +++++++++++++++++++ - src/lib/krb5/ccache/cc_kcm.c | 36 +++++++++++++++++++++++++++++++++++- - 2 files changed, 54 insertions(+), 1 deletion(-) - -diff --git a/src/include/kcm.h b/src/include/kcm.h -index e4140c3a0..9b66f1cbd 100644 ---- a/src/include/kcm.h -+++ b/src/include/kcm.h -@@ -56,8 +56,27 @@ - * are marshalled as zero-terminated strings. Principals and credentials are - * marshalled in the v4 FILE ccache format. UUIDs are 16 bytes. UUID lists - * are not delimited, so nothing can come after them. -+ * -+ * Flag words must use Heimdal flag values, which are not the same as MIT krb5 -+ * values for KRB5_GC and KRB5_TC constants. The same flag word may contain -+ * both kinds of flags in Heimdal, but not in MIT krb5. Defines for the -+ * applicable Heimdal flag values are given below using KCM_GC and KCM_TC -+ * prefixes. - */ - -+#define KCM_GC_CACHED (1U << 0) -+ -+#define KCM_TC_DONT_MATCH_REALM (1U << 31) -+#define KCM_TC_MATCH_KEYTYPE (1U << 30) -+#define KCM_TC_MATCH_SRV_NAMEONLY (1U << 29) -+#define KCM_TC_MATCH_FLAGS_EXACT (1U << 28) -+#define KCM_TC_MATCH_FLAGS (1U << 27) -+#define KCM_TC_MATCH_TIMES_EXACT (1U << 26) -+#define KCM_TC_MATCH_TIMES (1U << 25) -+#define KCM_TC_MATCH_AUTHDATA (1U << 24) -+#define KCM_TC_MATCH_2ND_TKT (1U << 23) -+#define KCM_TC_MATCH_IS_SKEY (1U << 22) -+ - /* Opcodes without comments are currently unused in the MIT client - * implementation. */ - typedef enum kcm_opcode { -diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c -index 772928e4d..1f81a2190 100644 ---- a/src/lib/krb5/ccache/cc_kcm.c -+++ b/src/lib/krb5/ccache/cc_kcm.c -@@ -110,6 +110,40 @@ map_invalid(krb5_error_code code) - KRB5_KCM_MALFORMED_REPLY : code; - } - -+/* -+ * Map an MIT krb5 KRB5_TC flag word to the equivalent Heimdal flag word. Note -+ * that there is no MIT krb5 equivalent for Heimdal's KRB5_TC_DONT_MATCH_REALM -+ * (which is like KRB5_TC_MATCH_SRV_NAMEONLY but also applies to the client -+ * principal) and no Heimdal equivalent for MIT krb5's KRB5_TC_SUPPORTED_KTYPES -+ * (which matches against enctypes from the krb5_context rather than the -+ * matching cred). -+ */ -+static inline krb5_flags -+map_tcflags(krb5_flags mitflags) -+{ -+ krb5_flags heimflags = 0; -+ -+ if (mitflags & KRB5_TC_MATCH_TIMES) -+ heimflags |= KCM_TC_MATCH_TIMES; -+ if (mitflags & KRB5_TC_MATCH_IS_SKEY) -+ heimflags |= KCM_TC_MATCH_IS_SKEY; -+ if (mitflags & KRB5_TC_MATCH_FLAGS) -+ heimflags |= KCM_TC_MATCH_FLAGS; -+ if (mitflags & KRB5_TC_MATCH_TIMES_EXACT) -+ heimflags |= KCM_TC_MATCH_TIMES_EXACT; -+ if (mitflags & KRB5_TC_MATCH_FLAGS_EXACT) -+ heimflags |= KCM_TC_MATCH_FLAGS_EXACT; -+ if (mitflags & KRB5_TC_MATCH_AUTHDATA) -+ heimflags |= KCM_TC_MATCH_AUTHDATA; -+ if (mitflags & KRB5_TC_MATCH_SRV_NAMEONLY) -+ heimflags |= KCM_TC_MATCH_SRV_NAMEONLY; -+ if (mitflags & KRB5_TC_MATCH_2ND_TKT) -+ heimflags |= KCM_TC_MATCH_2ND_TKT; -+ if (mitflags & KRB5_TC_MATCH_KTYPE) -+ heimflags |= KCM_TC_MATCH_KEYTYPE; -+ return heimflags; -+} -+ - /* Begin a request for the given opcode. If cache is non-null, supply the - * cache name as a request parameter. */ - static void -@@ -936,7 +970,7 @@ kcm_remove_cred(krb5_context context, krb5_ccache cache, krb5_flags flags, - struct kcmreq req; - - kcmreq_init(&req, KCM_OP_REMOVE_CRED, cache); -- k5_buf_add_uint32_be(&req.reqbuf, flags); -+ k5_buf_add_uint32_be(&req.reqbuf, map_tcflags(flags)); - k5_marshal_mcred(&req.reqbuf, mcred); - ret = cache_call(context, cache, &req); - kcmreq_free(&req); diff --git a/Fix-KCM-retrieval-support-for-sssd.patch b/Fix-KCM-retrieval-support-for-sssd.patch deleted file mode 100644 index 9c09507..0000000 --- a/Fix-KCM-retrieval-support-for-sssd.patch +++ /dev/null @@ -1,62 +0,0 @@ -From 43be8fba5301d08fc4d5ddef14f8ae3d9655b0ba Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 11 May 2021 14:04:07 -0400 -Subject: [PATCH] Fix KCM retrieval support for sssd - -Commit 795ebba8c039be172ab93cd41105c73ffdba0fdb added a retrieval -handler using KCM_OP_RETRIEVE, falling back on the same error codes as -the previous KCM_OP_GET_CRED_LIST support. But sssd (as of 2.4) -returns KRB5_CC_NOSUPP instead of KRB5_CC_IO if it recognizes an -opcode but does not implement it. Add a helper function to recognize -all known unsupported-opcode error codes, and use it in kcm_retrieve() -and kcm_start_seq_get(). - -ticket: 8997 -(cherry picked from commit da103e36e13f3c846bcddbe38dd518a21e5260a0) ---- - src/lib/krb5/ccache/cc_kcm.c | 18 ++++++++++++++++-- - 1 file changed, 16 insertions(+), 2 deletions(-) - -diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c -index 23fcf13ea..18505cd3d 100644 ---- a/src/lib/krb5/ccache/cc_kcm.c -+++ b/src/lib/krb5/ccache/cc_kcm.c -@@ -144,6 +144,20 @@ map_tcflags(krb5_flags mitflags) - return heimflags; - } - -+/* -+ * Return true if code could indicate an unsupported operation. Heimdal's KCM -+ * returns KRB5_FCC_INTERNAL. sssd's KCM daemon (as of sssd 2.4) returns -+ * KRB5_CC_NO_SUPP if it recognizes the operation but does not implement it, -+ * and KRB5_CC_IO if it doesn't recognize the operation (which is unfortunate -+ * since it could also indicate a communication failure). -+ */ -+static krb5_boolean -+unsupported_op_error(krb5_error_code code) -+{ -+ return code == KRB5_FCC_INTERNAL || code == KRB5_CC_IO || -+ code == KRB5_CC_NOSUPP; -+} -+ - /* Begin a request for the given opcode. If cache is non-null, supply the - * cache name as a request parameter. */ - static void -@@ -841,7 +855,7 @@ kcm_retrieve(krb5_context context, krb5_ccache cache, krb5_flags flags, - ret = cache_call(context, cache, &req); - - /* Fall back to iteration if the server does not support retrieval. */ -- if (ret == KRB5_FCC_INTERNAL || ret == KRB5_CC_IO) { -+ if (unsupported_op_error(ret)) { - ret = k5_cc_retrieve_cred_default(context, cache, flags, mcred, - cred_out); - goto cleanup; -@@ -922,7 +936,7 @@ kcm_start_seq_get(krb5_context context, krb5_ccache cache, - ret = kcmreq_get_cred_list(&req, &creds); - if (ret) - goto cleanup; -- } else if (ret == KRB5_FCC_INTERNAL || ret == KRB5_CC_IO) { -+ } else if (unsupported_op_error(ret)) { - /* Fall back to GET_CRED_UUID_LIST. */ - kcmreq_free(&req); - kcmreq_init(&req, KCM_OP_GET_CRED_UUID_LIST, cache); diff --git a/Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch b/Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch deleted file mode 100644 index 24b9d95..0000000 --- a/Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch +++ /dev/null @@ -1,45 +0,0 @@ -From bb8fa495d00ccd931eec87a01b8920636cf7903e Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 3 Aug 2021 01:15:27 -0400 -Subject: [PATCH] Fix KDC null deref on TGS inner body null server - -After the KDC decodes a FAST inner body, it does not check for a null -server. Prior to commit 39548a5b17bbda9eeb63625a201cfd19b9de1c5b this -would typically result in an error from krb5_unparse_name(), but with -the addition of get_local_tgt() it results in a null dereference. Add -a null check. - -Reported by Joseph Sutton of Catalyst. - -CVE-2021-37750: - -In MIT krb5 releases 1.14 and later, an authenticated attacker can -cause a null dereference in the KDC by sending a FAST TGS request with -no server field. - -ticket: 9008 (new) -tags: pullup -target_version: 1.19-next -target_version: 1.18-next - -(cherry picked from commit d775c95af7606a51bf79547a94fa52ddd1cb7f49) ---- - src/kdc/do_tgs_req.c | 5 +++++ - 1 file changed, 5 insertions(+) - -diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c -index 6d244ffd4..39a504ca1 100644 ---- a/src/kdc/do_tgs_req.c -+++ b/src/kdc/do_tgs_req.c -@@ -207,6 +207,11 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt, - status = "FIND_FAST"; - goto cleanup; - } -+ if (sprinc == NULL) { -+ status = "NULL_SERVER"; -+ errcode = KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN; -+ goto cleanup; -+ } - - errcode = get_local_tgt(kdc_context, &sprinc->realm, header_server, - &local_tgt, &local_tgt_storage, &local_tgt_key); diff --git a/Fix-integer-overflows-in-PAC-parsing.patch b/Fix-integer-overflows-in-PAC-parsing.patch deleted file mode 100644 index 272e34e..0000000 --- a/Fix-integer-overflows-in-PAC-parsing.patch +++ /dev/null @@ -1,106 +0,0 @@ -From 06d30f43a41029d83248bbac1a9b65fc09987597 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 17 Oct 2022 20:25:11 -0400 -Subject: [PATCH] Fix integer overflows in PAC parsing - -In krb5_parse_pac(), check for buffer counts large enough to threaten -integer overflow in the header length and memory length calculations. -Avoid potential integer overflows when checking the length of each -buffer. - -CVE-2022-42898: - -In MIT krb5 releases 1.8 and later, an authenticated attacker may be -able to cause a KDC or kadmind process to crash by reading beyond the -bounds of allocated memory, creating a denial of service. A -privileged attacker may similarly be able to cause a Kerberos or GSS -application service to crash. On 32-bit platforms, an attacker can -also cause insufficient memory to be allocated for the result, -potentially leading to remote code execution in a KDC, kadmind, or GSS -or Kerberos application server process. An attacker with the -privileges of a cross-realm KDC may be able to extract secrets from -the KDC process's memory by having them copied into the PAC of a new -ticket. - -ticket: 9074 (new) -tags: pullup -target_version: 1.20-next -target_version: 1.19-next ---- - src/lib/krb5/krb/pac.c | 9 +++++++-- - src/lib/krb5/krb/t_pac.c | 18 ++++++++++++++++++ - 2 files changed, 25 insertions(+), 2 deletions(-) - -diff --git a/src/lib/krb5/krb/pac.c b/src/lib/krb5/krb/pac.c -index 950beda657..1b9ef12276 100644 ---- a/src/lib/krb5/krb/pac.c -+++ b/src/lib/krb5/krb/pac.c -@@ -27,6 +27,8 @@ - #include "k5-int.h" - #include "authdata.h" - -+#define MAX_BUFFERS 4096 -+ - /* draft-brezak-win2k-krb-authz-00 */ - - /* -@@ -316,6 +318,9 @@ krb5_pac_parse(krb5_context context, - if (version != 0) - return EINVAL; - -+ if (cbuffers < 1 || cbuffers > MAX_BUFFERS) -+ return ERANGE; -+ - header_len = PACTYPE_LENGTH + (cbuffers * PAC_INFO_BUFFER_LENGTH); - if (len < header_len) - return ERANGE; -@@ -348,8 +353,8 @@ krb5_pac_parse(krb5_context context, - krb5_pac_free(context, pac); - return EINVAL; - } -- if (buffer->Offset < header_len || -- buffer->Offset + buffer->cbBufferSize > len) { -+ if (buffer->Offset < header_len || buffer->Offset > len || -+ buffer->cbBufferSize > len - buffer->Offset) { - krb5_pac_free(context, pac); - return ERANGE; - } -diff --git a/src/lib/krb5/krb/t_pac.c b/src/lib/krb5/krb/t_pac.c -index ee47152ee4..ccd165380d 100644 ---- a/src/lib/krb5/krb/t_pac.c -+++ b/src/lib/krb5/krb/t_pac.c -@@ -431,6 +431,16 @@ static const unsigned char s4u_pac_ent_xrealm[] = { - 0x8a, 0x81, 0x9c, 0x9c, 0x00, 0x00, 0x00, 0x00 - }; - -+static const unsigned char fuzz1[] = { -+ 0x00, 0x00, 0x00, 0x10, 0x00, 0x00, 0x00, 0x00, -+ 0x06, 0xff, 0xff, 0xff, 0x00, 0x00, 0xf5 -+}; -+ -+static const unsigned char fuzz2[] = { -+ 0x00, 0x00, 0x00, 0x20, 0x00, 0x00, 0x00, 0x00, -+ 0x20, 0x20 -+}; -+ - static const char *s4u_principal = "w2k8u@ACME.COM"; - static const char *s4u_enterprise = "w2k8u@abc@ACME.COM"; - -@@ -646,6 +656,14 @@ main(int argc, char **argv) - krb5_free_principal(context, sep); - } - -+ /* Check problematic PACs found by fuzzing. */ -+ ret = krb5_pac_parse(context, fuzz1, sizeof(fuzz1), &pac); -+ if (!ret) -+ err(context, ret, "krb5_pac_parse should have failed"); -+ ret = krb5_pac_parse(context, fuzz2, sizeof(fuzz2), &pac); -+ if (!ret) -+ err(context, ret, "krb5_pac_parse should have failed"); -+ - /* - * Test empty free - */ --- -2.37.3 - diff --git a/Fix-k5tls-module-for-OpenSSL-3.patch b/Fix-k5tls-module-for-OpenSSL-3.patch deleted file mode 100644 index a2b9e34..0000000 --- a/Fix-k5tls-module-for-OpenSSL-3.patch +++ /dev/null @@ -1,58 +0,0 @@ -From 51938a8b731740299fe47d132b8840edba4141bc Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Sat, 29 May 2021 12:05:49 -0400 -Subject: [PATCH] Fix k5tls module for OpenSSL 3 - -Starting in OpenSSL 3, connection termination without a close_notify -alert causes SSL_read() to return SSL_ERROR_SSL instead of -SSL_ERROR_SYSCALL. OpenSSL 3 also provides a new option -SSL_OP_IGNORE_UNEXPECTED_EOF which allows an application to explicitly -ignore possible truncation attacks and receive SSL_ERROR_ZERO_RETURN -instead. - -Remove the call to SSL_CTX_get_options() since SSL_CTX_set_options() -doesn't clear existing options. - -[ghudson@mit.edu: edited commit message and comment] - -(cherry picked from commit aa9b4a2a64046afd2fab7cb49c346295874a5fb6) -(cherry picked from commit 201e38845e9f70234bcaa9ba7c25b28e38169b0a) ---- - src/plugins/tls/k5tls/openssl.c | 17 ++++++++++++++--- - 1 file changed, 14 insertions(+), 3 deletions(-) - -diff --git a/src/plugins/tls/k5tls/openssl.c b/src/plugins/tls/k5tls/openssl.c -index 76a43b3cd..99fda7ffc 100644 ---- a/src/plugins/tls/k5tls/openssl.c -+++ b/src/plugins/tls/k5tls/openssl.c -@@ -433,7 +433,7 @@ setup(krb5_context context, SOCKET fd, const char *servername, - char **anchors, k5_tls_handle *handle_out) - { - int e; -- long options; -+ long options = SSL_OP_NO_SSLv2; - SSL_CTX *ctx = NULL; - SSL *ssl = NULL; - k5_tls_handle handle = NULL; -@@ -448,8 +448,19 @@ setup(krb5_context context, SOCKET fd, const char *servername, - ctx = SSL_CTX_new(SSLv23_client_method()); - if (ctx == NULL) - goto error; -- options = SSL_CTX_get_options(ctx); -- SSL_CTX_set_options(ctx, options | SSL_OP_NO_SSLv2); -+ -+#ifdef SSL_OP_IGNORE_UNEXPECTED_EOF -+ /* -+ * For OpenSSL 3 and later, mark close_notify alerts as optional. We don't -+ * need to worry about truncation attacks because the protocols this module -+ * is used with (Kerberos and change-password) receive a single -+ * length-delimited message from the server. For prior versions of OpenSSL -+ * we check for SSL_ERROR_SYSCALL when reading instead (this error changes -+ * to SSL_ERROR_SSL in OpenSSL 3). -+ */ -+ options |= SSL_OP_IGNORE_UNEXPECTED_EOF; -+#endif -+ SSL_CTX_set_options(ctx, options); - - SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, verify_callback); - X509_STORE_set_flags(SSL_CTX_get_cert_store(ctx), 0); diff --git a/Fix-kadmin-k-with-fallback-or-referral-realm.patch b/Fix-kadmin-k-with-fallback-or-referral-realm.patch deleted file mode 100644 index a5162e7..0000000 --- a/Fix-kadmin-k-with-fallback-or-referral-realm.patch +++ /dev/null @@ -1,64 +0,0 @@ -From 2d2bb9a14613b3283dabdd40c3ee28e5b680cf93 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 7 Jun 2021 15:00:41 -0400 -Subject: [PATCH] Fix kadmin -k with fallback or referral realm - -kadmin -k produces a client principal name with -krb5_sname_to_principal(), but it gets converted to a string and back -due to the signature of kadm5_init_with_skey(), which loses track of -the name type, so no canonicalization is performed. - -In libkadm5clnt initialization, recognize the important subset of this -case--an empty realm indicates either fallback processing or the -referral realm--and restore the host-based name type so that the -client principal can be canonicalized against the keytab. - -ticket: 9013 (new) -(cherry picked from commit dcb79089276624d7ddf44e08d35bd6d7d7e557d2) ---- - src/lib/kadm5/clnt/client_init.c | 7 +++++++ - src/tests/t_kadmin.py | 12 ++++++++++++ - 2 files changed, 19 insertions(+) - -diff --git a/src/lib/kadm5/clnt/client_init.c b/src/lib/kadm5/clnt/client_init.c -index aa1223bb3..0aaca701f 100644 ---- a/src/lib/kadm5/clnt/client_init.c -+++ b/src/lib/kadm5/clnt/client_init.c -@@ -221,9 +221,16 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, - return KADM5_MISSING_KRB5_CONF_PARAMS; - } - -+ /* -+ * Parse the client name. If it has an empty realm, it is almost certainly -+ * a host-based principal using DNS fallback processing or the referral -+ * realm, so give it the appropriate name type for canonicalization. -+ */ - code = krb5_parse_name(handle->context, client_name, &client); - if (code) - goto error; -+ if (init_type == INIT_SKEY && client->realm.length == 0) -+ client->type = KRB5_NT_SRV_HST; - - /* - * Get credentials. Also does some fallbacks in case kadmin/fqdn -diff --git a/src/tests/t_kadmin.py b/src/tests/t_kadmin.py -index fe6a3cc2e..98453d92e 100644 ---- a/src/tests/t_kadmin.py -+++ b/src/tests/t_kadmin.py -@@ -51,4 +51,16 @@ for i in range(200): - realm.run_kadmin(['addprinc', '-randkey', 'foo%d' % i]) - realm.run_kadmin(['listprincs'], expected_msg='foo199') - -+# Test kadmin -k with the default principal, with and without -+# fallback. This operation requires canonicalization against the -+# keytab in krb5_get_init_creds_keytab() as the -+# krb5_sname_to_principal() result won't have a realm. Try with and -+# without without fallback processing since the code paths are -+# different. -+mark('kadmin -k') -+realm.run([kadmin, '-k', 'getprinc', realm.host_princ]) -+no_canon_conf = {'libdefaults': {'dns_canonicalize_hostname': 'false'}} -+no_canon = realm.special_env('no_canon', False, krb5_conf=no_canon_conf) -+realm.run([kadmin, '-k', 'getprinc', realm.host_princ], env=no_canon) -+ - success('kadmin and kpasswd tests') diff --git a/Fix-leaks-on-error-in-kadm5-init-functions.patch b/Fix-leaks-on-error-in-kadm5-init-functions.patch deleted file mode 100644 index bdacecb..0000000 --- a/Fix-leaks-on-error-in-kadm5-init-functions.patch +++ /dev/null @@ -1,664 +0,0 @@ -From a14e0fd3c1d00ba625e6d9eb72829f31527c6ad8 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Wed, 23 Jun 2021 16:53:16 -0400 -Subject: [PATCH] Fix leaks on error in kadm5 init functions - -In the GENERIC_CHECK_HANDLE function, separate out the -version-checking logic so we can call it in the init functions before -allocating resources. - -In the client and server library initialization functions, use a -single exit path after argument validation, and share the destruction -code with kadm5_destroy() via a helper. - -(cherry picked from commit 552d7b7626450f963b8e37345c472420c842402c) ---- - src/lib/kadm5/admin_internal.h | 39 ++++--- - src/lib/kadm5/clnt/client_init.c | 174 +++++++++++----------------- - src/lib/kadm5/srv/server_init.c | 191 ++++++++++--------------------- - 3 files changed, 145 insertions(+), 259 deletions(-) - -diff --git a/src/lib/kadm5/admin_internal.h b/src/lib/kadm5/admin_internal.h -index faf8e9c36..9be53883a 100644 ---- a/src/lib/kadm5/admin_internal.h -+++ b/src/lib/kadm5/admin_internal.h -@@ -11,29 +11,32 @@ - - #define KADM5_SERVER_HANDLE_MAGIC 0x12345800 - --#define GENERIC_CHECK_HANDLE(handle, old_api_version, new_api_version) \ -+#define CHECK_VERSIONS(struct_version, api_version, old_api_err, new_api_err) \ - { \ -- kadm5_server_handle_t srvr = \ -- (kadm5_server_handle_t) handle; \ -- \ -- if (! srvr) \ -- return KADM5_BAD_SERVER_HANDLE; \ -- if (srvr->magic_number != KADM5_SERVER_HANDLE_MAGIC) \ -- return KADM5_BAD_SERVER_HANDLE; \ -- if ((srvr->struct_version & KADM5_MASK_BITS) != \ -- KADM5_STRUCT_VERSION_MASK) \ -+ if ((struct_version & KADM5_MASK_BITS) != KADM5_STRUCT_VERSION_MASK) \ - return KADM5_BAD_STRUCT_VERSION; \ -- if (srvr->struct_version < KADM5_STRUCT_VERSION_1) \ -+ if (struct_version < KADM5_STRUCT_VERSION_1) \ - return KADM5_OLD_STRUCT_VERSION; \ -- if (srvr->struct_version > KADM5_STRUCT_VERSION_1) \ -+ if (struct_version > KADM5_STRUCT_VERSION_1) \ - return KADM5_NEW_STRUCT_VERSION; \ -- if ((srvr->api_version & KADM5_MASK_BITS) != \ -- KADM5_API_VERSION_MASK) \ -+ if ((api_version & KADM5_MASK_BITS) != KADM5_API_VERSION_MASK) \ - return KADM5_BAD_API_VERSION; \ -- if (srvr->api_version < KADM5_API_VERSION_2) \ -- return old_api_version; \ -- if (srvr->api_version > KADM5_API_VERSION_4) \ -- return new_api_version; \ -+ if (api_version < KADM5_API_VERSION_2) \ -+ return old_api_err; \ -+ if (api_version > KADM5_API_VERSION_4) \ -+ return new_api_err; \ -+ } -+ -+#define GENERIC_CHECK_HANDLE(handle, old_api_err, new_api_err) \ -+ { \ -+ kadm5_server_handle_t srvr = handle; \ -+ \ -+ if (srvr == NULL) \ -+ return KADM5_BAD_SERVER_HANDLE; \ -+ if (srvr->magic_number != KADM5_SERVER_HANDLE_MAGIC) \ -+ return KADM5_BAD_SERVER_HANDLE; \ -+ CHECK_VERSIONS(srvr->struct_version, srvr->api_version, \ -+ old_api_err, new_api_err); \ - } - - /* -diff --git a/src/lib/kadm5/clnt/client_init.c b/src/lib/kadm5/clnt/client_init.c -index 0aaca701f..75614bb19 100644 ---- a/src/lib/kadm5/clnt/client_init.c -+++ b/src/lib/kadm5/clnt/client_init.c -@@ -138,6 +138,36 @@ kadm5_init_with_skey(krb5_context context, char *client_name, - server_handle); - } - -+static kadm5_ret_t -+free_handle(kadm5_server_handle_t handle) -+{ -+ kadm5_ret_t ret = 0; -+ OM_uint32 minor_stat; -+ krb5_ccache ccache; -+ -+ if (handle == NULL) -+ return 0; -+ -+ if (handle->destroy_cache && handle->cache_name != NULL) { -+ ret = krb5_cc_resolve(handle->context, handle->cache_name, &ccache); -+ if (!ret) -+ ret = krb5_cc_destroy(handle->context, ccache); -+ } -+ free(handle->cache_name); -+ (void)gss_release_cred(&minor_stat, &handle->cred); -+ if (handle->clnt != NULL && handle->clnt->cl_auth != NULL) -+ AUTH_DESTROY(handle->clnt->cl_auth); -+ if (handle->clnt != NULL) -+ clnt_destroy(handle->clnt); -+ if (handle->client_socket != -1) -+ close(handle->client_socket); -+ free(handle->lhandle); -+ kadm5_free_config_params(handle->context, &handle->params); -+ free(handle); -+ -+ return ret; -+} -+ - static kadm5_ret_t - init_any(krb5_context context, char *client_name, enum init_type init_type, - char *pass, krb5_ccache ccache_in, char *service_name, -@@ -145,36 +175,34 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, - krb5_ui_4 api_version, char **db_args, void **server_handle) - { - int fd = -1; -- OM_uint32 minor_stat; - krb5_boolean iprop_enable; - int port; - rpcprog_t rpc_prog; - rpcvers_t rpc_vers; -- krb5_ccache ccache; - krb5_principal client = NULL, server = NULL; - struct timeval timeout; - -- kadm5_server_handle_t handle; -+ kadm5_server_handle_t handle = NULL; - kadm5_config_params params_local; - -- int code = 0; -+ krb5_error_code code; - generic_ret r = { 0, 0 }; - - initialize_ovk_error_table(); - initialize_ovku_error_table(); - -- if (! server_handle) { -+ if (server_handle == NULL || client_name == NULL) - return EINVAL; -- } - -- if (! (handle = malloc(sizeof(*handle)))) { -- return ENOMEM; -- } -- memset(handle, 0, sizeof(*handle)); -- if (! (handle->lhandle = malloc(sizeof(*handle)))) { -- free(handle); -- return ENOMEM; -- } -+ CHECK_VERSIONS(struct_version, api_version, KADM5_OLD_LIB_API_VERSION, -+ KADM5_NEW_LIB_API_VERSION); -+ -+ handle = k5alloc(sizeof(*handle), &code); -+ if (handle == NULL) -+ goto cleanup; -+ handle->lhandle = k5alloc(sizeof(*handle), &code); -+ if (handle->lhandle == NULL) -+ goto cleanup; - - handle->magic_number = KADM5_SERVER_HANDLE_MAGIC; - handle->struct_version = struct_version; -@@ -192,33 +220,20 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, - - handle->context = context; - -- if(client_name == NULL) { -- free(handle); -- return EINVAL; -- } -- -- /* -- * Verify the version numbers before proceeding; we can't use -- * CHECK_HANDLE because not all fields are set yet. -- */ -- GENERIC_CHECK_HANDLE(handle, KADM5_OLD_LIB_API_VERSION, -- KADM5_NEW_LIB_API_VERSION); -- - memset(¶ms_local, 0, sizeof(params_local)); - -- if ((code = kadm5_get_config_params(handle->context, 0, -- params_in, &handle->params))) { -- free(handle); -- return(code); -- } -+ code = kadm5_get_config_params(handle->context, 0, params_in, -+ &handle->params); -+ if (code) -+ goto cleanup; - - #define REQUIRED_PARAMS (KADM5_CONFIG_REALM | \ - KADM5_CONFIG_ADMIN_SERVER | \ - KADM5_CONFIG_KADMIND_PORT) - - if ((handle->params.mask & REQUIRED_PARAMS) != REQUIRED_PARAMS) { -- free(handle); -- return KADM5_MISSING_KRB5_CONF_PARAMS; -+ code = KADM5_MISSING_KRB5_CONF_PARAMS; -+ goto cleanup; - } - - /* -@@ -228,7 +243,7 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, - */ - code = krb5_parse_name(handle->context, client_name, &client); - if (code) -- goto error; -+ goto cleanup; - if (init_type == INIT_SKEY && client->realm.length == 0) - client->type = KRB5_NT_SRV_HST; - -@@ -239,7 +254,7 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, - code = get_init_creds(handle, client, init_type, pass, ccache_in, - service_name, handle->params.realm, &server); - if (code) -- goto error; -+ goto cleanup; - - /* If the service_name and client_name are iprop-centric, use the iprop - * port and RPC identifiers. */ -@@ -258,7 +273,7 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, - - code = connect_to_server(handle->params.admin_server, port, &fd); - if (code) -- goto error; -+ goto cleanup; - - handle->clnt = clnttcp_create(NULL, rpc_prog, rpc_vers, &fd, 0, 0); - if (handle->clnt == NULL) { -@@ -266,7 +281,7 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, - #ifdef DEBUG - clnt_pcreateerror("clnttcp_create"); - #endif -- goto error; -+ goto cleanup; - } - - /* Set a one-hour timeout. */ -@@ -278,10 +293,6 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, - handle->lhandle->clnt = handle->clnt; - handle->lhandle->client_socket = fd; - -- /* now that handle->clnt is set, we can check the handle */ -- if ((code = _kadm5_check_handle((void *) handle))) -- goto error; -- - /* - * The RPC connection is open; establish the GSS-API - * authentication context. -@@ -289,7 +300,7 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, - code = setup_gss(handle, params_in, - (init_type == INIT_CREDS) ? client : NULL, server); - if (code) -- goto error; -+ goto cleanup; - - /* - * Bypass the remainder of the code and return straight away -@@ -297,7 +308,8 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, - */ - if (iprop_enable) { - code = 0; -- *server_handle = (void *) handle; -+ *server_handle = handle; -+ handle = NULL; - goto cleanup; - } - -@@ -306,7 +318,7 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, - #ifdef DEBUG - clnt_perror(handle->clnt, "init_2 null resp"); - #endif -- goto error; -+ goto cleanup; - } - /* Drop down to v3 wire protocol if server does not support v4 */ - if (r.code == KADM5_NEW_SERVER_API_VERSION && -@@ -315,7 +327,7 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, - memset(&r, 0, sizeof(generic_ret)); - if (init_2(&handle->api_version, &r, handle->clnt)) { - code = KADM5_RPC_ERROR; -- goto error; -+ goto cleanup; - } - } - /* Drop down to v2 wire protocol if server does not support v3 */ -@@ -325,47 +337,21 @@ init_any(krb5_context context, char *client_name, enum init_type init_type, - memset(&r, 0, sizeof(generic_ret)); - if (init_2(&handle->api_version, &r, handle->clnt)) { - code = KADM5_RPC_ERROR; -- goto error; -+ goto cleanup; - } - } - if (r.code) { - code = r.code; -- goto error; -+ goto cleanup; - } - -- *server_handle = (void *) handle; -- -- goto cleanup; -- --error: -- /* -- * Note that it is illegal for this code to execute if "handle" -- * has not been allocated and initialized. I.e., don't use "goto -- * error" before the block of code at the top of the function -- * that allocates and initializes "handle". -- */ -- if (handle->destroy_cache && handle->cache_name) { -- if (krb5_cc_resolve(handle->context, -- handle->cache_name, &ccache) == 0) -- (void) krb5_cc_destroy (handle->context, ccache); -- } -- if (handle->cache_name) -- free(handle->cache_name); -- (void)gss_release_cred(&minor_stat, &handle->cred); -- if(handle->clnt && handle->clnt->cl_auth) -- AUTH_DESTROY(handle->clnt->cl_auth); -- if(handle->clnt) -- clnt_destroy(handle->clnt); -- if (fd != -1) -- close(fd); -- free(handle->lhandle); -- kadm5_free_config_params(handle->context, &handle->params); -+ *server_handle = handle; -+ handle = NULL; - - cleanup: -- krb5_free_principal(handle->context, client); -- krb5_free_principal(handle->context, server); -- if (code) -- free(handle); -+ krb5_free_principal(context, client); -+ krb5_free_principal(context, server); -+ (void)free_handle(handle); - - return code; - } -@@ -695,38 +681,8 @@ rpc_auth(kadm5_server_handle_t handle, kadm5_config_params *params_in, - kadm5_ret_t - kadm5_destroy(void *server_handle) - { -- OM_uint32 minor_stat; -- krb5_ccache ccache = NULL; -- int code = KADM5_OK; -- kadm5_server_handle_t handle = -- (kadm5_server_handle_t) server_handle; -- - CHECK_HANDLE(server_handle); -- -- if (handle->destroy_cache && handle->cache_name) { -- if ((code = krb5_cc_resolve(handle->context, -- handle->cache_name, &ccache)) == 0) -- code = krb5_cc_destroy (handle->context, ccache); -- } -- if (handle->cache_name) -- free(handle->cache_name); -- if (handle->cred) -- (void)gss_release_cred(&minor_stat, &handle->cred); -- if (handle->clnt && handle->clnt->cl_auth) -- AUTH_DESTROY(handle->clnt->cl_auth); -- if (handle->clnt) -- clnt_destroy(handle->clnt); -- if (handle->client_socket != -1) -- close(handle->client_socket); -- if (handle->lhandle) -- free (handle->lhandle); -- -- kadm5_free_config_params(handle->context, &handle->params); -- -- handle->magic_number = 0; -- free(handle); -- -- return code; -+ return free_handle(server_handle); - } - /* not supported on client */ - kadm5_ret_t kadm5_lock(void *server_handle) -diff --git a/src/lib/kadm5/srv/server_init.c b/src/lib/kadm5/srv/server_init.c -index 3adc4b57d..2c0d51efd 100644 ---- a/src/lib/kadm5/srv/server_init.c -+++ b/src/lib/kadm5/srv/server_init.c -@@ -19,23 +19,6 @@ - #include "osconf.h" - #include "iprop_hdr.h" - --/* -- * Function check_handle -- * -- * Purpose: Check a server handle and return a com_err code if it is -- * invalid or 0 if it is valid. -- * -- * Arguments: -- * -- * handle The server handle. -- */ -- --static int check_handle(void *handle) --{ -- CHECK_HANDLE(handle); -- return 0; --} -- - static int dup_db_args(kadm5_server_handle_t handle, char **db_args) - { - int count = 0; -@@ -84,6 +67,23 @@ static void free_db_args(kadm5_server_handle_t handle) - } - } - -+static void -+free_handle(kadm5_server_handle_t handle) -+{ -+ if (handle == NULL) -+ return; -+ -+ destroy_pwqual(handle); -+ k5_kadm5_hook_free_handles(handle->context, handle->hook_handles); -+ ulog_fini(handle->context); -+ krb5_db_fini(handle->context); -+ krb5_free_principal(handle->context, handle->current_caller); -+ kadm5_free_config_params(handle->context, &handle->params); -+ free(handle->lhandle); -+ free_db_args(handle); -+ free(handle); -+} -+ - kadm5_ret_t kadm5_init_with_password(krb5_context context, char *client_name, - char *pass, char *service_name, - kadm5_config_params *params, -@@ -163,8 +163,8 @@ kadm5_ret_t kadm5_init(krb5_context context, char *client_name, char *pass, - char **db_args, - void **server_handle) - { -- int ret; -- kadm5_server_handle_t handle; -+ krb5_error_code ret; -+ kadm5_server_handle_t handle = NULL; - kadm5_config_params params_local; /* for v1 compat */ - - if (! server_handle) -@@ -173,17 +173,17 @@ kadm5_ret_t kadm5_init(krb5_context context, char *client_name, char *pass, - if (! client_name) - return EINVAL; - -- if (! (handle = (kadm5_server_handle_t) malloc(sizeof *handle))) -- return ENOMEM; -- memset(handle, 0, sizeof(*handle)); -+ CHECK_VERSIONS(struct_version, api_version, KADM5_OLD_SERVER_API_VERSION, -+ KADM5_NEW_SERVER_API_VERSION); -+ -+ handle = k5alloc(sizeof(*handle), &ret); -+ if (handle == NULL) -+ goto cleanup; -+ handle->context = context; - - ret = dup_db_args(handle, db_args); -- if (ret) { -- free(handle); -- return ret; -- } -- -- handle->context = context; -+ if (ret) -+ goto cleanup; - - initialize_ovk_error_table(); - initialize_ovku_error_table(); -@@ -192,13 +192,6 @@ kadm5_ret_t kadm5_init(krb5_context context, char *client_name, char *pass, - handle->struct_version = struct_version; - handle->api_version = api_version; - -- /* -- * Verify the version numbers before proceeding; we can't use -- * CHECK_HANDLE because not all fields are set yet. -- */ -- GENERIC_CHECK_HANDLE(handle, KADM5_OLD_SERVER_API_VERSION, -- KADM5_NEW_SERVER_API_VERSION); -- - /* - * Acquire relevant profile entries. Merge values - * in params_in with values from profile, based on -@@ -208,11 +201,8 @@ kadm5_ret_t kadm5_init(krb5_context context, char *client_name, char *pass, - - ret = kadm5_get_config_params(handle->context, 1, params_in, - &handle->params); -- if (ret) { -- free_db_args(handle); -- free(handle); -- return(ret); -- } -+ if (ret) -+ goto cleanup; - - #define REQUIRED_PARAMS (KADM5_CONFIG_REALM | KADM5_CONFIG_DBNAME | \ - KADM5_CONFIG_ENCTYPE | \ -@@ -226,132 +216,69 @@ kadm5_ret_t kadm5_init(krb5_context context, char *client_name, char *pass, - KADM5_CONFIG_IPROP_PORT) - - if ((handle->params.mask & REQUIRED_PARAMS) != REQUIRED_PARAMS) { -- kadm5_free_config_params(handle->context, &handle->params); -- free_db_args(handle); -- free(handle); -- return KADM5_MISSING_CONF_PARAMS; -+ ret = KADM5_MISSING_CONF_PARAMS; -+ goto cleanup; - } - if ((handle->params.mask & KADM5_CONFIG_IPROP_ENABLED) == KADM5_CONFIG_IPROP_ENABLED - && handle->params.iprop_enabled) { - if ((handle->params.mask & IPROP_REQUIRED_PARAMS) != IPROP_REQUIRED_PARAMS) { -- kadm5_free_config_params(handle->context, &handle->params); -- free_db_args(handle); -- free(handle); -- return KADM5_MISSING_CONF_PARAMS; -+ ret = KADM5_MISSING_CONF_PARAMS; -+ goto cleanup; - } - } - - ret = krb5_set_default_realm(handle->context, handle->params.realm); -- if (ret) { -- kadm5_free_config_params(handle->context, &handle->params); -- free_db_args(handle); -- free(handle); -- return ret; -- } -+ if (ret) -+ goto cleanup; - - ret = krb5_db_open(handle->context, db_args, - KRB5_KDB_OPEN_RW | KRB5_KDB_SRV_TYPE_ADMIN); -- if (ret) { -- kadm5_free_config_params(handle->context, &handle->params); -- free_db_args(handle); -- free(handle); -- return(ret); -- } -+ if (ret) -+ goto cleanup; - -- if ((ret = krb5_parse_name(handle->context, client_name, -- &handle->current_caller))) { -- kadm5_free_config_params(handle->context, &handle->params); -- krb5_db_fini(handle->context); -- free_db_args(handle); -- free(handle); -- return ret; -- } -+ ret = krb5_parse_name(handle->context, client_name, -+ &handle->current_caller); -+ if (ret) -+ goto cleanup; - -- if (! (handle->lhandle = malloc(sizeof(*handle)))) { -- kadm5_free_config_params(handle->context, &handle->params); -- krb5_db_fini(handle->context); -- free_db_args(handle); -- free(handle); -- return ENOMEM; -- } -+ handle->lhandle = k5alloc(sizeof(*handle), &ret); -+ if (handle->lhandle == NULL) -+ goto cleanup; - *handle->lhandle = *handle; - handle->lhandle->api_version = KADM5_API_VERSION_4; - handle->lhandle->struct_version = KADM5_STRUCT_VERSION; - handle->lhandle->lhandle = handle->lhandle; - -- /* can't check the handle until current_caller is set */ -- ret = check_handle((void *) handle); -- if (ret) { -- kadm5_free_config_params(handle->context, &handle->params); -- free_db_args(handle); -- free(handle); -- return ret; -- } -- - ret = kdb_init_master(handle, handle->params.realm, - (handle->params.mask & KADM5_CONFIG_MKEY_FROM_KBD) - && handle->params.mkey_from_kbd); -- if (ret) { -- kadm5_free_config_params(handle->context, &handle->params); -- krb5_db_fini(handle->context); -- free_db_args(handle); -- free(handle); -- return ret; -- } -+ if (ret) -+ goto cleanup; - - ret = kdb_init_hist(handle, handle->params.realm); -- if (ret) { -- kadm5_free_config_params(handle->context, &handle->params); -- krb5_db_fini(handle->context); -- free_db_args(handle); -- free(handle); -- return ret; -- } -+ if (ret) -+ goto cleanup; - - ret = k5_kadm5_hook_load(context,&handle->hook_handles); -- if (ret) { -- kadm5_free_config_params(handle->context, &handle->params); -- krb5_db_fini(handle->context); -- krb5_free_principal(handle->context, handle->current_caller); -- free_db_args(handle); -- free(handle); -- return ret; -- } -+ if (ret) -+ goto cleanup; - - ret = init_pwqual(handle); -- if (ret) { -- kadm5_free_config_params(handle->context, &handle->params); -- k5_kadm5_hook_free_handles(context, handle->hook_handles); -- krb5_db_fini(handle->context); -- krb5_free_principal(handle->context, handle->current_caller); -- free_db_args(handle); -- free(handle); -- return ret; -- } -+ if (ret) -+ goto cleanup; - -- *server_handle = (void *) handle; -+ *server_handle = handle; -+ handle = NULL; - -- return KADM5_OK; -+cleanup: -+ free_handle(handle); -+ return ret; - } - - kadm5_ret_t kadm5_destroy(void *server_handle) - { -- kadm5_server_handle_t handle = server_handle; -- - CHECK_HANDLE(server_handle); -- -- destroy_pwqual(handle); -- -- k5_kadm5_hook_free_handles(handle->context, handle->hook_handles); -- ulog_fini(handle->context); -- krb5_db_fini(handle->context); -- krb5_free_principal(handle->context, handle->current_caller); -- kadm5_free_config_params(handle->context, &handle->params); -- handle->magic_number = 0; -- free(handle->lhandle); -- free_db_args(handle); -- free(handle); -- -+ free_handle(server_handle); - return KADM5_OK; - } - diff --git a/Fix-softpkcs11-build-issues-with-openssl-3.0.patch b/Fix-softpkcs11-build-issues-with-openssl-3.0.patch deleted file mode 100644 index ba5a8b5..0000000 --- a/Fix-softpkcs11-build-issues-with-openssl-3.0.patch +++ /dev/null @@ -1,552 +0,0 @@ -From f85a818fe1a7438db7e1ea579818da67e0be017d Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Sat, 15 May 2021 17:35:25 -0400 -Subject: [PATCH] Fix softpkcs11 build issues with openssl 3.0 - -EVP_PKEY_get0_RSA() has been modified to have const return type. Remove -its usages in favor of the EVP_PKEY interface. Also remove calls to -RSA_blinding_off(), which we don't need and would require a non-const -object. Similarly, remove RSA_set_method() calls that set a pre-existing -default. - -Since softpkcs11 doesn't link against krb5 and can't use zap(), allocate -buffers with OPENSSL_malloc() so can use OPENSSL_clear_free(). - -Move several argument validation checks to the top of their functions. - -Fix some incorrect/inconsistent log messages. - -(cherry picked from commit 00de1aad7b3647b91017c7009b0bc65cd0c8b2e0) -(cherry picked from commit a86b780ef275b35e8dc1e6d1886ec8e8d941f7c4) ---- - src/tests/softpkcs11/main.c | 360 ++++++++++++++---------------------- - 1 file changed, 141 insertions(+), 219 deletions(-) - -diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c -index 1cccdfb43..caa537b68 100644 ---- a/src/tests/softpkcs11/main.c -+++ b/src/tests/softpkcs11/main.c -@@ -375,10 +375,9 @@ add_st_object(void) - return NULL; - soft_token.object.objs = objs; - -- o = malloc(sizeof(*o)); -+ o = calloc(1, sizeof(*o)); - if (o == NULL) - return NULL; -- memset(o, 0, sizeof(*o)); - o->attrs = NULL; - o->num_attributes = 0; - o->object_handle = soft_token.object.num_objs; -@@ -424,7 +423,7 @@ add_pubkey_info(struct st_object *o, CK_KEY_TYPE key_type, EVP_PKEY *key) - CK_ULONG modulus_bits = 0; - CK_BYTE *exponent = NULL; - size_t exponent_len = 0; -- RSA *rsa; -+ const RSA *rsa; - const BIGNUM *n, *e; - - rsa = EVP_PKEY_get0_RSA(key); -@@ -445,8 +444,6 @@ add_pubkey_info(struct st_object *o, CK_KEY_TYPE key_type, EVP_PKEY *key) - add_object_attribute(o, 0, CKA_PUBLIC_EXPONENT, - exponent, exponent_len); - -- RSA_set_method(rsa, RSA_PKCS1_OpenSSL()); -- - free(modulus); - free(exponent); - } -@@ -679,10 +676,6 @@ add_certificate(char *label, - } else { - /* XXX verify keytype */ - -- if (key_type == CKK_RSA) -- RSA_set_method(EVP_PKEY_get0_RSA(o->u.private_key.key), -- RSA_PKCS1_OpenSSL()); -- - if (X509_check_private_key(cert, o->u.private_key.key) != 1) { - EVP_PKEY_free(o->u.private_key.key); - o->u.private_key.key = NULL; -@@ -695,7 +688,7 @@ add_certificate(char *label, - } - - ret = CKR_OK; -- out: -+out: - if (ret != CKR_OK) { - st_logf("something went wrong when adding cert!\n"); - -@@ -1224,8 +1217,6 @@ C_Login(CK_SESSION_HANDLE hSession, - } - - /* XXX check keytype */ -- RSA_set_method(EVP_PKEY_get0_RSA(o->u.private_key.key), -- RSA_PKCS1_OpenSSL()); - - if (X509_check_private_key(o->u.private_key.cert, o->u.private_key.key) != 1) { - EVP_PKEY_free(o->u.private_key.key); -@@ -1495,8 +1486,9 @@ C_Encrypt(CK_SESSION_HANDLE hSession, - struct st_object *o; - void *buffer = NULL; - CK_RV ret; -- RSA *rsa; -- int padding, len, buffer_len, padding_len; -+ size_t buffer_len = 0; -+ int padding; -+ EVP_PKEY_CTX *ctx = NULL; - - st_logf("Encrypt\n"); - -@@ -1512,70 +1504,58 @@ C_Encrypt(CK_SESSION_HANDLE hSession, - return CKR_ARGUMENTS_BAD; - } - -- rsa = EVP_PKEY_get0_RSA(o->u.public_key); -- -- if (rsa == NULL) -- return CKR_ARGUMENTS_BAD; -- -- RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ -- -- buffer_len = RSA_size(rsa); -- -- buffer = malloc(buffer_len); -- if (buffer == NULL) { -- ret = CKR_DEVICE_MEMORY; -- goto out; -- } -- -- ret = CKR_OK; -- switch(state->encrypt_mechanism->mechanism) { -- case CKM_RSA_PKCS: -- padding = RSA_PKCS1_PADDING; -- padding_len = RSA_PKCS1_PADDING_SIZE; -- break; -- case CKM_RSA_X_509: -- padding = RSA_NO_PADDING; -- padding_len = 0; -- break; -- default: -- ret = CKR_FUNCTION_NOT_SUPPORTED; -- goto out; -- } -- -- if ((CK_ULONG)buffer_len + padding_len < ulDataLen) { -- ret = CKR_ARGUMENTS_BAD; -- goto out; -- } -- - if (pulEncryptedDataLen == NULL) { - st_logf("pulEncryptedDataLen NULL\n"); - ret = CKR_ARGUMENTS_BAD; - goto out; - } - -- if (pData == NULL_PTR) { -+ if (pData == NULL) { - st_logf("data NULL\n"); - ret = CKR_ARGUMENTS_BAD; - goto out; - } - -- len = RSA_public_encrypt(ulDataLen, pData, buffer, rsa, padding); -- if (len <= 0) { -+ switch(state->encrypt_mechanism->mechanism) { -+ case CKM_RSA_PKCS: -+ padding = RSA_PKCS1_PADDING; -+ break; -+ case CKM_RSA_X_509: -+ padding = RSA_NO_PADDING; -+ break; -+ default: -+ ret = CKR_FUNCTION_NOT_SUPPORTED; -+ goto out; -+ } -+ -+ ctx = EVP_PKEY_CTX_new(o->u.public_key, NULL); -+ if (ctx == NULL || EVP_PKEY_encrypt_init(ctx) <= 0 || -+ EVP_PKEY_CTX_set_rsa_padding(ctx, padding) <= 0 || -+ EVP_PKEY_encrypt(ctx, NULL, &buffer_len, pData, ulDataLen) <= 0) { - ret = CKR_DEVICE_ERROR; - goto out; - } -- if (len > buffer_len) -- abort(); - -- if (pEncryptedData != NULL_PTR) -- memcpy(pEncryptedData, buffer, len); -- *pulEncryptedDataLen = len; -- -- out: -- if (buffer) { -- memset(buffer, 0, buffer_len); -- free(buffer); -+ buffer = OPENSSL_malloc(buffer_len); -+ if (buffer == NULL) { -+ ret = CKR_DEVICE_MEMORY; -+ goto out; - } -+ -+ if (EVP_PKEY_encrypt(ctx, buffer, &buffer_len, pData, ulDataLen) <= 0) { -+ ret = CKR_DEVICE_ERROR; -+ goto out; -+ } -+ st_logf("Encrypt done\n"); -+ -+ if (pEncryptedData != NULL) -+ memcpy(pEncryptedData, buffer, buffer_len); -+ *pulEncryptedDataLen = buffer_len; -+ -+ ret = CKR_OK; -+out: -+ OPENSSL_clear_free(buffer, buffer_len); -+ EVP_PKEY_CTX_free(ctx); - return ret; - } - -@@ -1646,8 +1626,9 @@ C_Decrypt(CK_SESSION_HANDLE hSession, - struct st_object *o; - void *buffer = NULL; - CK_RV ret; -- RSA *rsa; -- int padding, len, buffer_len, padding_len; -+ size_t buffer_len = 0; -+ int padding; -+ EVP_PKEY_CTX *ctx = NULL; - - st_logf("Decrypt\n"); - -@@ -1663,41 +1644,6 @@ C_Decrypt(CK_SESSION_HANDLE hSession, - return CKR_ARGUMENTS_BAD; - } - -- rsa = EVP_PKEY_get0_RSA(o->u.private_key.key); -- -- if (rsa == NULL) -- return CKR_ARGUMENTS_BAD; -- -- RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ -- -- buffer_len = RSA_size(rsa); -- -- buffer = malloc(buffer_len); -- if (buffer == NULL) { -- ret = CKR_DEVICE_MEMORY; -- goto out; -- } -- -- ret = CKR_OK; -- switch(state->decrypt_mechanism->mechanism) { -- case CKM_RSA_PKCS: -- padding = RSA_PKCS1_PADDING; -- padding_len = RSA_PKCS1_PADDING_SIZE; -- break; -- case CKM_RSA_X_509: -- padding = RSA_NO_PADDING; -- padding_len = 0; -- break; -- default: -- ret = CKR_FUNCTION_NOT_SUPPORTED; -- goto out; -- } -- -- if ((CK_ULONG)buffer_len + padding_len < ulEncryptedDataLen) { -- ret = CKR_ARGUMENTS_BAD; -- goto out; -- } -- - if (pulDataLen == NULL) { - st_logf("pulDataLen NULL\n"); - ret = CKR_ARGUMENTS_BAD; -@@ -1710,24 +1656,48 @@ C_Decrypt(CK_SESSION_HANDLE hSession, - goto out; - } - -- len = RSA_private_decrypt(ulEncryptedDataLen, pEncryptedData, buffer, -- rsa, padding); -- if (len <= 0) { -+ switch(state->decrypt_mechanism->mechanism) { -+ case CKM_RSA_PKCS: -+ padding = RSA_PKCS1_PADDING; -+ break; -+ case CKM_RSA_X_509: -+ padding = RSA_NO_PADDING; -+ break; -+ default: -+ ret = CKR_FUNCTION_NOT_SUPPORTED; -+ goto out; -+ } -+ -+ ctx = EVP_PKEY_CTX_new(o->u.private_key.key, NULL); -+ if (ctx == NULL || EVP_PKEY_decrypt_init(ctx) <= 0 || -+ EVP_PKEY_CTX_set_rsa_padding(ctx, padding) <= 0 || -+ EVP_PKEY_decrypt(ctx, NULL, &buffer_len, pEncryptedData, -+ ulEncryptedDataLen) <= 0) { - ret = CKR_DEVICE_ERROR; - goto out; - } -- if (len > buffer_len) -- abort(); -+ -+ buffer = OPENSSL_malloc(buffer_len); -+ if (buffer == NULL) { -+ ret = CKR_DEVICE_MEMORY; -+ goto out; -+ } -+ -+ if (EVP_PKEY_decrypt(ctx, buffer, &buffer_len, pEncryptedData, -+ ulEncryptedDataLen) <= 0) { -+ ret = CKR_DEVICE_ERROR; -+ goto out; -+ } -+ st_logf("Decrypt done\n"); - - if (pData != NULL_PTR) -- memcpy(pData, buffer, len); -- *pulDataLen = len; -+ memcpy(pData, buffer, buffer_len); -+ *pulDataLen = buffer_len; - -- out: -- if (buffer) { -- memset(buffer, 0, buffer_len); -- free(buffer); -- } -+ ret = CKR_OK; -+out: -+ OPENSSL_clear_free(buffer, buffer_len); -+ EVP_PKEY_CTX_free(ctx); - return ret; - } - -@@ -1806,8 +1776,9 @@ C_Sign(CK_SESSION_HANDLE hSession, - struct st_object *o; - void *buffer = NULL; - CK_RV ret; -- RSA *rsa; -- int padding, len, buffer_len, padding_len; -+ int padding; -+ size_t buffer_len = 0; -+ EVP_PKEY_CTX *ctx = NULL; - - st_logf("Sign\n"); - VERIFY_SESSION_HANDLE(hSession, &state); -@@ -1822,40 +1793,6 @@ C_Sign(CK_SESSION_HANDLE hSession, - return CKR_ARGUMENTS_BAD; - } - -- rsa = EVP_PKEY_get0_RSA(o->u.private_key.key); -- -- if (rsa == NULL) -- return CKR_ARGUMENTS_BAD; -- -- RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ -- -- buffer_len = RSA_size(rsa); -- -- buffer = malloc(buffer_len); -- if (buffer == NULL) { -- ret = CKR_DEVICE_MEMORY; -- goto out; -- } -- -- switch(state->sign_mechanism->mechanism) { -- case CKM_RSA_PKCS: -- padding = RSA_PKCS1_PADDING; -- padding_len = RSA_PKCS1_PADDING_SIZE; -- break; -- case CKM_RSA_X_509: -- padding = RSA_NO_PADDING; -- padding_len = 0; -- break; -- default: -- ret = CKR_FUNCTION_NOT_SUPPORTED; -- goto out; -- } -- -- if ((CK_ULONG)buffer_len < ulDataLen + padding_len) { -- ret = CKR_ARGUMENTS_BAD; -- goto out; -- } -- - if (pulSignatureLen == NULL) { - st_logf("signature len NULL\n"); - ret = CKR_ARGUMENTS_BAD; -@@ -1868,26 +1805,46 @@ C_Sign(CK_SESSION_HANDLE hSession, - goto out; - } - -- len = RSA_private_encrypt(ulDataLen, pData, buffer, rsa, padding); -- st_logf("private encrypt done\n"); -- if (len <= 0) { -+ switch(state->sign_mechanism->mechanism) { -+ case CKM_RSA_PKCS: -+ padding = RSA_PKCS1_PADDING; -+ break; -+ case CKM_RSA_X_509: -+ padding = RSA_NO_PADDING; -+ break; -+ default: -+ ret = CKR_FUNCTION_NOT_SUPPORTED; -+ goto out; -+ } -+ -+ ctx = EVP_PKEY_CTX_new(o->u.private_key.key, NULL); -+ if (ctx == NULL || EVP_PKEY_sign_init(ctx) <= 0 || -+ EVP_PKEY_CTX_set_rsa_padding(ctx, padding) <= 0 || -+ EVP_PKEY_sign(ctx, NULL, &buffer_len, pData, ulDataLen) <= 0) { - ret = CKR_DEVICE_ERROR; - goto out; - } -- if (len > buffer_len) -- abort(); - -- if (pSignature != NULL_PTR) -- memcpy(pSignature, buffer, len); -- *pulSignatureLen = len; -+ buffer = OPENSSL_malloc(buffer_len); -+ if (buffer == NULL) { -+ ret = CKR_DEVICE_MEMORY; -+ goto out; -+ } -+ -+ if (EVP_PKEY_sign(ctx, buffer, &buffer_len, pData, ulDataLen) <= 0) { -+ ret = CKR_DEVICE_ERROR; -+ goto out; -+ } -+ st_logf("Sign done\n"); -+ -+ if (pSignature != NULL) -+ memcpy(pSignature, buffer, buffer_len); -+ *pulSignatureLen = buffer_len; - - ret = CKR_OK; -- -- out: -- if (buffer) { -- memset(buffer, 0, buffer_len); -- free(buffer); -- } -+out: -+ OPENSSL_clear_free(buffer, buffer_len); -+ EVP_PKEY_CTX_free(ctx); - return ret; - } - -@@ -1951,10 +1908,9 @@ C_Verify(CK_SESSION_HANDLE hSession, - { - struct session_state *state; - struct st_object *o; -- void *buffer = NULL; - CK_RV ret; -- RSA *rsa; -- int padding, len, buffer_len; -+ int padding; -+ EVP_PKEY_CTX *ctx = NULL; - - st_logf("Verify\n"); - VERIFY_SESSION_HANDLE(hSession, &state); -@@ -1969,39 +1925,6 @@ C_Verify(CK_SESSION_HANDLE hSession, - return CKR_ARGUMENTS_BAD; - } - -- rsa = EVP_PKEY_get0_RSA(o->u.public_key); -- -- if (rsa == NULL) -- return CKR_ARGUMENTS_BAD; -- -- RSA_blinding_off(rsa); /* XXX RAND is broken while running in mozilla ? */ -- -- buffer_len = RSA_size(rsa); -- -- buffer = malloc(buffer_len); -- if (buffer == NULL) { -- ret = CKR_DEVICE_MEMORY; -- goto out; -- } -- -- ret = CKR_OK; -- switch(state->verify_mechanism->mechanism) { -- case CKM_RSA_PKCS: -- padding = RSA_PKCS1_PADDING; -- break; -- case CKM_RSA_X_509: -- padding = RSA_NO_PADDING; -- break; -- default: -- ret = CKR_FUNCTION_NOT_SUPPORTED; -- goto out; -- } -- -- if ((CK_ULONG)buffer_len < ulDataLen) { -- ret = CKR_ARGUMENTS_BAD; -- goto out; -- } -- - if (pSignature == NULL) { - st_logf("signature NULL\n"); - ret = CKR_ARGUMENTS_BAD; -@@ -2014,34 +1937,34 @@ C_Verify(CK_SESSION_HANDLE hSession, - goto out; - } - -- len = RSA_public_decrypt(ulDataLen, pData, buffer, rsa, padding); -- st_logf("private encrypt done\n"); -- if (len <= 0) { -+ switch(state->verify_mechanism->mechanism) { -+ case CKM_RSA_PKCS: -+ padding = RSA_PKCS1_PADDING; -+ break; -+ case CKM_RSA_X_509: -+ padding = RSA_NO_PADDING; -+ break; -+ default: -+ ret = CKR_FUNCTION_NOT_SUPPORTED; -+ goto out; -+ } -+ -+ ctx = EVP_PKEY_CTX_new(o->u.public_key, NULL); -+ if (ctx == NULL || EVP_PKEY_verify_init(ctx) <= 0 || -+ EVP_PKEY_CTX_set_rsa_padding(ctx, padding) <= 0 || -+ EVP_PKEY_verify(ctx, pSignature, ulSignatureLen, pData, -+ ulDataLen) <= 0) { - ret = CKR_DEVICE_ERROR; - goto out; - } -- if (len > buffer_len) -- abort(); -+ st_logf("Verify done\n"); - -- if ((CK_ULONG)len != ulSignatureLen) { -- ret = CKR_GENERAL_ERROR; -- goto out; -- } -- -- if (memcmp(pSignature, buffer, len) != 0) { -- ret = CKR_GENERAL_ERROR; -- goto out; -- } -- -- out: -- if (buffer) { -- memset(buffer, 0, buffer_len); -- free(buffer); -- } -+ ret = CKR_OK; -+out: -+ EVP_PKEY_CTX_free(ctx); - return ret; - } - -- - CK_RV - C_VerifyUpdate(CK_SESSION_HANDLE hSession, - CK_BYTE_PTR pPart, -@@ -2072,7 +1995,6 @@ C_GenerateRandom(CK_SESSION_HANDLE hSession, - return CKR_FUNCTION_NOT_SUPPORTED; - } - -- - CK_FUNCTION_LIST funcs = { - { 2, 11 }, - C_Initialize, diff --git a/Fix-some-principal-realm-canonicalization-cases.patch b/Fix-some-principal-realm-canonicalization-cases.patch deleted file mode 100644 index 81fde7f..0000000 --- a/Fix-some-principal-realm-canonicalization-cases.patch +++ /dev/null @@ -1,96 +0,0 @@ -From 0779309f52f4c05bb1f01f638261ef1b8ca82488 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 7 Jun 2021 13:27:29 -0400 -Subject: [PATCH] Fix some principal realm canonicalization cases - -The no_hostrealm and subst_defrealm flags in struct canonprinc were -only applied when dns_canonicalize_hostname=fallback; in the other -cases, the initial krb5_sname_to_principal() result is treated as -canonical. For no_hostrealm this limitation doesn't currently matter, -because all uses pass a principal with no realm as input. However, -subst_defrealm is used to convert the referral realm to the default -realm in krb5_get_init_creds_keytab(), krb5_cc_cache_match(), and -gss_acquire_cred() when it needs to check the desired name against a -specified ccache. - -In k5_canonprinc(), if the input principal is a -krb5_sname_to_principal() result and fallback isn't in effect, apply -subst_defrealm. Document in os-proto.h that no_hostrealm doesn't -remove an existing realm and that krb5_sname_to_principal() may -already have looked one up. - -ticket: 9011 (new) -(cherry picked from commit c077d0c6430c4ac163443aacc03d14d206a4cbb8) ---- - src/lib/krb5/os/os-proto.h | 13 +++++++++---- - src/lib/krb5/os/sn2princ.c | 24 +++++++++++++++++++++--- - 2 files changed, 30 insertions(+), 7 deletions(-) - -diff --git a/src/lib/krb5/os/os-proto.h b/src/lib/krb5/os/os-proto.h -index 7d5e7978f..a985f2aec 100644 ---- a/src/lib/krb5/os/os-proto.h -+++ b/src/lib/krb5/os/os-proto.h -@@ -85,10 +85,15 @@ struct sendto_callback_info { - - /* - * Initialize with all zeros except for princ. Set no_hostrealm to disable -- * host-to-realm lookup, which ordinarily happens after canonicalizing the host -- * part. Set subst_defrealm to substitute the default realm for the referral -- * realm after realm lookup (this has no effect if no_hostrealm is set). Free -- * with free_canonprinc() when done. -+ * host-to-realm lookup, which ordinarily happens during fallback processing -+ * after canonicalizing the host part. Set subst_defrealm to substitute the -+ * default realm for the referral realm after realm lookup. Do not set both -+ * flags. Free with free_canonprinc() when done. -+ * -+ * no_hostrealm only applies if fallback processing is in use -+ * (dns_canonicalize_hostname = fallback). It will not remove the realm if -+ * krb5_sname_to_principal() already canonicalized the hostname and looked up a -+ * realm. subst_defrealm applies whether or not fallback processing is in use. - */ - struct canonprinc { - krb5_const_principal princ; -diff --git a/src/lib/krb5/os/sn2princ.c b/src/lib/krb5/os/sn2princ.c -index c99b7da17..93c155932 100644 ---- a/src/lib/krb5/os/sn2princ.c -+++ b/src/lib/krb5/os/sn2princ.c -@@ -271,18 +271,36 @@ krb5_error_code - k5_canonprinc(krb5_context context, struct canonprinc *iter, - krb5_const_principal *princ_out) - { -+ krb5_error_code ret; - int step = ++iter->step; - - *princ_out = NULL; - -- /* If we're not doing fallback, the input principal is canonical. */ -- if (context->dns_canonicalize_hostname != CANONHOST_FALLBACK || -- iter->princ->type != KRB5_NT_SRV_HST || iter->princ->length != 2 || -+ /* If the hostname isn't from krb5_sname_to_principal(), the input -+ * principal is canonical. */ -+ if (iter->princ->type != KRB5_NT_SRV_HST || iter->princ->length != 2 || - iter->princ->data[1].length == 0) { - *princ_out = (step == 1) ? iter->princ : NULL; - return 0; - } - -+ /* If we're not doing fallback, the hostname is canonical, but we may need -+ * to substitute the default realm. */ -+ if (context->dns_canonicalize_hostname != CANONHOST_FALLBACK) { -+ if (step > 1) -+ return 0; -+ iter->copy = *iter->princ; -+ if (iter->subst_defrealm && iter->copy.realm.length == 0) { -+ ret = krb5_get_default_realm(context, &iter->realm); -+ if (ret) -+ return ret; -+ iter->copy = *iter->princ; -+ iter->copy.realm = string2data(iter->realm); -+ } -+ *princ_out = &iter->copy; -+ return 0; -+ } -+ - /* Canonicalize without DNS at step 1, with DNS at step 2. */ - if (step > 2) - return 0; diff --git a/Handle-OpenSSL-3-s-providers.patch b/Handle-OpenSSL-3-s-providers.patch deleted file mode 100644 index d7b0d90..0000000 --- a/Handle-OpenSSL-3-s-providers.patch +++ /dev/null @@ -1,301 +0,0 @@ -From e3f3d31a3db23f6c8437cd0efe45f67a7f4fc6aa Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Sat, 15 May 2021 21:18:06 -0400 -Subject: [PATCH] Handle OpenSSL 3's providers - -OpenSSL 3 compartmentalizes what algorithms it uses, which for us means -another hoop to jump through to use dubious cryptography. (Right now, -we need to load "legacy" in order to access MD4 and RC4.) - -Use our normal initializer logic to set up providers both in the OpenSSL -provider an the PKINIT plugin. Since DT_FINI is too late, release them -using atexit() as OpenSSL does. - -(cherry picked from commit bea5a703a06da1f1ab56821b77a2d3661cb0dda4) -[rharwood@redhat.com: work around des3 removal and rc4 fips changes] ---- - src/configure.ac | 1 + - src/lib/crypto/openssl/enc_provider/aes.c | 16 ++++++ - .../crypto/openssl/enc_provider/camellia.c | 16 ++++++ - src/lib/crypto/openssl/enc_provider/rc4.c | 4 ++ - .../crypto/openssl/hash_provider/hash_evp.c | 5 ++ - src/lib/crypto/openssl/init.c | 53 +++++++++++++++++++ - src/plugins/preauth/pkinit/Makefile.in | 1 + - .../preauth/pkinit/pkinit_crypto_openssl.c | 33 ++++++++++-- - 8 files changed, 126 insertions(+), 3 deletions(-) - -diff --git a/src/configure.ac b/src/configure.ac -index 9c2e816fe..20066918b 100644 ---- a/src/configure.ac -+++ b/src/configure.ac -@@ -284,6 +284,7 @@ AC_SUBST(CRYPTO_IMPL_LIBS) - - if test "$CRYPTO_IMPL" = openssl; then - AC_CHECK_FUNCS(EVP_KDF_fetch) -+ AC_CHECK_FUNCS(OSSL_PROVIDER_load) - fi - - AC_ARG_WITH([prng-alg], -diff --git a/src/lib/crypto/openssl/enc_provider/aes.c b/src/lib/crypto/openssl/enc_provider/aes.c -index 6b4622fe9..31c90a69d 100644 ---- a/src/lib/crypto/openssl/enc_provider/aes.c -+++ b/src/lib/crypto/openssl/enc_provider/aes.c -@@ -68,6 +68,10 @@ cbc_enc(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx; - struct iov_cursor cursor; - -+ ret = krb5int_crypto_init(); -+ if (ret) -+ return ret; -+ - ctx = EVP_CIPHER_CTX_new(); - if (ctx == NULL) - return ENOMEM; -@@ -102,6 +106,10 @@ cbc_decr(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx; - struct iov_cursor cursor; - -+ ret = krb5int_crypto_init(); -+ if (ret) -+ return ret; -+ - ctx = EVP_CIPHER_CTX_new(); - if (ctx == NULL) - return ENOMEM; -@@ -137,6 +145,10 @@ cts_encr(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - struct iov_cursor cursor; - AES_KEY enck; - -+ ret = krb5int_crypto_init(); -+ if (ret) -+ return ret; -+ - memset(iv_cts,0,sizeof(iv_cts)); - if (ivec && ivec->data){ - if (ivec->length != sizeof(iv_cts)) -@@ -190,6 +202,10 @@ cts_decr(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - struct iov_cursor cursor; - AES_KEY deck; - -+ ret = krb5int_crypto_init(); -+ if (ret) -+ return ret; -+ - memset(iv_cts,0,sizeof(iv_cts)); - if (ivec && ivec->data){ - if (ivec->length != sizeof(iv_cts)) -diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c -index f79679a0b..7cc7fc6fb 100644 ---- a/src/lib/crypto/openssl/enc_provider/camellia.c -+++ b/src/lib/crypto/openssl/enc_provider/camellia.c -@@ -92,6 +92,10 @@ cbc_enc(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx; - struct iov_cursor cursor; - -+ ret = krb5int_crypto_init(); -+ if (ret) -+ return ret; -+ - ctx = EVP_CIPHER_CTX_new(); - if (ctx == NULL) - return ENOMEM; -@@ -126,6 +130,10 @@ cbc_decr(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx; - struct iov_cursor cursor; - -+ ret = krb5int_crypto_init(); -+ if (ret) -+ return ret; -+ - ctx = EVP_CIPHER_CTX_new(); - if (ctx == NULL) - return ENOMEM; -@@ -161,6 +169,10 @@ cts_encr(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - struct iov_cursor cursor; - CAMELLIA_KEY enck; - -+ ret = krb5int_crypto_init(); -+ if (ret) -+ return ret; -+ - memset(iv_cts,0,sizeof(iv_cts)); - if (ivec && ivec->data){ - if (ivec->length != sizeof(iv_cts)) -@@ -214,6 +226,10 @@ cts_decr(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data, - struct iov_cursor cursor; - CAMELLIA_KEY deck; - -+ ret = krb5int_crypto_init(); -+ if (ret) -+ return ret; -+ - memset(iv_cts,0,sizeof(iv_cts)); - if (ivec && ivec->data){ - if (ivec->length != sizeof(iv_cts)) -diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c -index 9bf407899..a10cb5192 100644 ---- a/src/lib/crypto/openssl/enc_provider/rc4.c -+++ b/src/lib/crypto/openssl/enc_provider/rc4.c -@@ -66,6 +66,10 @@ k5_arcfour_docrypt(krb5_key key, const krb5_data *state, krb5_crypto_iov *data, - EVP_CIPHER_CTX *ctx = NULL; - struct arcfour_state *arcstate; - -+ ret = krb5int_crypto_init(); -+ if (ret) -+ return ret; -+ - if (FIPS_mode()) - return KRB5_CRYPTO_INTERNAL; - -diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c -index 2eb5139c0..09d7b3896 100644 ---- a/src/lib/crypto/openssl/hash_provider/hash_evp.c -+++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c -@@ -41,6 +41,11 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, - const krb5_data *d; - size_t i; - int ok; -+ krb5_error_code ret; -+ -+ ret = krb5int_crypto_init(); -+ if (ret) -+ return ret; - - if (output->length != (unsigned int)EVP_MD_size(type)) - return KRB5_CRYPTO_INTERNAL; -diff --git a/src/lib/crypto/openssl/init.c b/src/lib/crypto/openssl/init.c -index 1139bce53..f72dbfe81 100644 ---- a/src/lib/crypto/openssl/init.c -+++ b/src/lib/crypto/openssl/init.c -@@ -26,12 +26,65 @@ - - #include "crypto_int.h" - -+#ifdef HAVE_OSSL_PROVIDER_LOAD -+ -+/* -+ * Starting in OpenSSL 3, algorithms are grouped into containers called -+ * "providers", not all of which are loaded by default. At time of writing, -+ * we need MD4 and RC4 from the legacy provider. Oddly, 3DES is not in -+ * legacy. -+ */ -+ -+#include -+ -+static OSSL_PROVIDER *legacy_provider = NULL; -+static OSSL_PROVIDER *default_provider = NULL; -+ -+static void -+unload_providers(void) -+{ -+ if (default_provider != NULL) -+ (void)OSSL_PROVIDER_unload(default_provider); -+ if (legacy_provider != NULL) -+ (void)OSSL_PROVIDER_unload(legacy_provider); -+ default_provider = NULL; -+ legacy_provider = NULL; -+} -+ -+int -+krb5int_crypto_impl_init(void) -+{ -+ legacy_provider = OSSL_PROVIDER_load(NULL, "legacy"); -+ default_provider = OSSL_PROVIDER_load(NULL, "default"); -+ -+ /* -+ * Someone might build openssl without the legacy provider. They will -+ * have a bad time, but some things will still work. I don't know think -+ * this configuration is worth supporting. -+ */ -+ if (legacy_provider == NULL || default_provider == NULL) -+ abort(); -+ -+ /* -+ * If we attempt to do this with our normal LIBFINIFUNC logic (DT_FINI), -+ * OpenSSL will have cleaned itself up by the time we're invoked. OpenSSL -+ * registers its cleanup (OPENSSL_cleanup) with atexit() - do the same and -+ * we'll be higher on the stack. -+ */ -+ atexit(unload_providers); -+ return 0; -+} -+ -+#else /* !HAVE_OSSL_PROVIDER_LOAD */ -+ - int - krb5int_crypto_impl_init(void) - { - return 0; - } - -+#endif -+ - void - krb5int_crypto_impl_cleanup(void) - { -diff --git a/src/plugins/preauth/pkinit/Makefile.in b/src/plugins/preauth/pkinit/Makefile.in -index 15ca0eb48..d20fb18a8 100644 ---- a/src/plugins/preauth/pkinit/Makefile.in -+++ b/src/plugins/preauth/pkinit/Makefile.in -@@ -5,6 +5,7 @@ MODULE_INSTALL_DIR = $(KRB5_PA_MODULE_DIR) - LIBBASE=pkinit - LIBMAJOR=0 - LIBMINOR=0 -+LIBINITFUNC=pkinit_openssl_init - RELDIR=../plugins/preauth/pkinit - # Depends on libk5crypto and libkrb5 - SHLIB_EXPDEPS = \ -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 350c2118a..42e5c581d 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -44,6 +44,13 @@ - #include - #endif - -+#ifdef HAVE_OSSL_PROVIDER_LOAD -+#include -+ -+static OSSL_PROVIDER *legacy_provider = NULL; -+static OSSL_PROVIDER *default_provider = NULL; -+#endif -+ - static krb5_error_code pkinit_init_pkinit_oids(pkinit_plg_crypto_context ); - static void pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ); - -@@ -2937,12 +2944,32 @@ cleanup: - return retval; - } - -+/* pkinit_openssl_init() and unload_providers() are largely duplicated from -+ * lib/crypto/openssl/init.c - see explanations there. */ -+static void -+unload_providers(void) -+{ -+ if (default_provider != NULL) -+ (void)OSSL_PROVIDER_unload(default_provider); -+ if (legacy_provider != NULL) -+ (void)OSSL_PROVIDER_unload(legacy_provider); -+ default_provider = NULL; -+ legacy_provider = NULL; -+} -+ - int - pkinit_openssl_init() - { -- /* Initialize OpenSSL. */ -- ERR_load_crypto_strings(); -- OpenSSL_add_all_algorithms(); -+#ifdef HAVE_OSSL_PROVIDER_LOAD -+ legacy_provider = OSSL_PROVIDER_load(NULL, "legacy"); -+ default_provider = OSSL_PROVIDER_load(NULL, "default"); -+ -+ if (legacy_provider == NULL || default_provider == NULL) -+ abort(); -+ -+ atexit(unload_providers); -+#endif -+ - return 0; - } - diff --git a/Make-KCM-iteration-fallback-work-with-sssd-kcm.patch b/Make-KCM-iteration-fallback-work-with-sssd-kcm.patch deleted file mode 100644 index a0e28a9..0000000 --- a/Make-KCM-iteration-fallback-work-with-sssd-kcm.patch +++ /dev/null @@ -1,26 +0,0 @@ -From 32ee800fa31d3bbda660bb9270f9aa20718ab202 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Pavel=20B=C5=99ezina?= -Date: Tue, 30 Mar 2021 14:35:28 +0200 -Subject: [PATCH] Make KCM iteration fallback work with sssd-kcm - -sssd-kcm returns KRB5_CC_IO if the operation code is not known. - -ticket: 8990 -(cherry picked from commit 06afae820a44c1dc96ad88a0b16c3e50bc938b2a) ---- - src/lib/krb5/ccache/cc_kcm.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c -index 1f81a2190..46705f1da 100644 ---- a/src/lib/krb5/ccache/cc_kcm.c -+++ b/src/lib/krb5/ccache/cc_kcm.c -@@ -876,7 +876,7 @@ kcm_start_seq_get(krb5_context context, krb5_ccache cache, - ret = kcmreq_get_cred_list(&req, &creds); - if (ret) - goto cleanup; -- } else if (ret == KRB5_FCC_INTERNAL) { -+ } else if (ret == KRB5_FCC_INTERNAL || ret == KRB5_CC_IO) { - /* Fall back to GET_CRED_UUID_LIST. */ - kcmreq_free(&req); - kcmreq_init(&req, KCM_OP_GET_CRED_UUID_LIST, cache); diff --git a/Move-some-dejagnu-kadmin-tests-to-Python-tests.patch b/Move-some-dejagnu-kadmin-tests-to-Python-tests.patch deleted file mode 100644 index 1c97190..0000000 --- a/Move-some-dejagnu-kadmin-tests-to-Python-tests.patch +++ /dev/null @@ -1,1750 +0,0 @@ -From 2fd38805a159020722395e79213540d9bcfa6c71 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 22 Apr 2021 15:51:36 -0400 -Subject: [PATCH] Move some dejagnu kadmin tests to Python tests - -Remove the dejagnu scripts kadmin.exp, pwchange.exp, and pwhist.exp. - -Add a new Python test script t_kadmin.py for the miscellaneous kadmin -tests from kadmin.exp. - -In t_changepw.py, use modprinc +needchange for one of the kinit -password change tests to gain the same coverage as pwchange.exp had, -and add the "password changes are usable by kinit" tests from -kadmin.exp. - -In t_policy.py, add the ticket 929 regression tests from kadmin.exp -and the ticket 2841 regression tests from pwhist.exp. - -(cherry picked from commit 8027531caf6911bb07bf13de087da0e6bef5a348) ---- - src/tests/Makefile.in | 1 + - src/tests/dejagnu/krb-standalone/kadmin.exp | 1133 ----------------- - src/tests/dejagnu/krb-standalone/pwchange.exp | 145 --- - src/tests/dejagnu/krb-standalone/pwhist.exp | 217 ---- - src/tests/t_changepw.py | 34 +- - src/tests/t_kadmin.py | 54 + - src/tests/t_policy.py | 62 + - 7 files changed, 143 insertions(+), 1503 deletions(-) - delete mode 100644 src/tests/dejagnu/krb-standalone/kadmin.exp - delete mode 100644 src/tests/dejagnu/krb-standalone/pwchange.exp - delete mode 100644 src/tests/dejagnu/krb-standalone/pwhist.exp - create mode 100644 src/tests/t_kadmin.py - -diff --git a/src/tests/Makefile.in b/src/tests/Makefile.in -index fd714eedb..20f27d748 100644 ---- a/src/tests/Makefile.in -+++ b/src/tests/Makefile.in -@@ -147,6 +147,7 @@ check-pytests: unlockiter s4u2self - $(RUNPYTEST) $(srcdir)/t_referral.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_skew.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_keytab.py $(PYTESTFLAGS) -+ $(RUNPYTEST) $(srcdir)/t_kadmin.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_kadmin_acl.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_kadmin_parsing.py $(PYTESTFLAGS) - $(RUNPYTEST) $(srcdir)/t_kdb.py $(PYTESTFLAGS) -diff --git a/src/tests/dejagnu/krb-standalone/kadmin.exp b/src/tests/dejagnu/krb-standalone/kadmin.exp -deleted file mode 100644 -index fa50a61fb..000000000 ---- a/src/tests/dejagnu/krb-standalone/kadmin.exp -+++ /dev/null -@@ -1,1133 +0,0 @@ --# Kerberos kadmin test. --# This is a DejaGnu test script. --# This script tests Kerberos kadmin5 using kadmin.local as verification. -- --#++ --# kadmin_add - Test add new v5 principal function of kadmin. --# --# Adds principal $pname with password $password. Returns 1 on success. --#-- --proc kadmin_add { pname password } { -- global REALMNAME -- global KADMIN -- global KADMIN_LOCAL -- global KEY -- global spawn_id -- global tmppwd -- -- set good 0 -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "ank $pname" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin add $pname lost KDC" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin add $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin add $pname" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*:" { -- send "adminpass$KEY\r" -- } -- expect "Enter password for principal \"$pname@$REALMNAME\":" { send "$password\r" } -- expect "Re-enter password for principal \"$pname@$REALMNAME\":" { send "$password\r" } -- expect "Principal \"$pname@$REALMNAME\" created." { set good 1 } -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin add)" -- catch "close -i $spawn_id" -- if { $good == 1 } { -- # -- # use kadmin.local to verify that a principal was created and that its -- # salt types are 0 (normal). -- # -- envstack_push -- setup_kerberos_env kdc -- spawn $KADMIN_LOCAL -r $REALMNAME -- envstack_pop -- expect_after { -- -i $spawn_id -- timeout { -- fail "kadmin add $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin add $pname" -- catch "expect_after" -- return 0 -- } -- } -- set good 0 -- expect "kadmin.local: " { send "getprinc $pname\r" } -- expect "Principal: $pname@$REALMNAME" { set good 1 } -- expect "Expiration date:" { verbose "got expiration date" } -- expect "Last password change:" { verbose "got last pwchange" } -- expect "Password expiration date:" { verbose "got pwexpire date" } -- expect "Maximum ticket life:" { verbose "got max life" } -- expect "Maximum renewable life:" { verbose "got max rlife" } -- expect "Last modified:" { verbose "got last modified" } -- expect "Last successful authentication:" { verbose "last succ auth" } -- expect "Last failed authentication:" { verbose "last pw failed" } -- expect "Failed password attempts:" { verbose "num failed attempts" } -- expect "Number of keys:" { verbose "num keys"} -- expect { -- "Key: " { verbose "Key listed" -- exp_continue -- } -- "Attributes:" { verbose "attributes" } -- } -- expect "kadmin.local: " { send "q\r" } -- -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin.local show)" -- catch "close -i $spawn_id" -- if { $good == 1 } { -- pass "kadmin add $pname" -- return 1 -- } -- else { -- fail "kadmin add $pname" -- return 0 -- } -- } -- else { -- fail "kadmin add $pname" -- return 0 -- } --} -- --#++ --# kadmin_add_rnd - Test add new v5 principal with random key function. --# --# Adds principal $pname with random key. Returns 1 on success. --#-- --proc kadmin_add_rnd { pname { flags "" } } { -- global REALMNAME -- global KADMIN -- global KADMIN_LOCAL -- global KEY -- global spawn_id -- global tmppwd -- -- set good 0 -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "ank -randkey $flags $pname" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin add rnd $pname lost KDC" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin add_rnd $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin add_rnd $pname" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*: *" { -- send "adminpass$KEY\r" -- } -- expect "Principal \"$pname@$REALMNAME\" created." { set good 1 } -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin add_rnd)" -- catch "close -i $spawn_id" -- if { $good == 1 } { -- # -- # use kadmin.local to verify that a principal was created and that its -- # salt types are 0 (normal). -- # -- envstack_push -- setup_kerberos_env kdc -- spawn $KADMIN_LOCAL -r $REALMNAME -- envstack_pop -- expect_after { -- -i $spawn_id -- timeout { -- fail "kadmin add_rnd $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin add_rnd $pname" -- catch "expect_after" -- return 0 -- } -- } -- set good 0 -- expect "kadmin.local:" { send "getprinc $pname\r" } -- expect "Principal: $pname@$REALMNAME" { set good 1 } -- expect "kadmin.local:" { send "q\r" } -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin.local show)" -- catch "close -i $spawn_id" -- if { $good == 1 } { -- pass "kadmin add_rnd $pname" -- return 1 -- } -- else { -- fail "kadmin add_rnd $pname" -- return 0 -- } -- } -- else { -- fail "kadmin add_rnd $pname" -- return 0 -- } --} -- --#++ --# kadmin_show - Test show principal function of kadmin. --# --# Retrieves entry for $pname. Returns 1 on success. --#-- --proc kadmin_show { pname } { -- global REALMNAME -- global KADMIN -- global KEY -- global spawn_id -- -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "get_principal $pname" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin show $pname lost KDC" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin show $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin show $pname" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*: *" -- send "adminpass$KEY\r" -- expect -re "\r.*Principal: $pname@$REALMNAME.*Key: .*Attributes:.*Policy: .*\r" -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin show)" -- catch "close -i $spawn_id" -- pass "kadmin show $pname" -- return 1 --} -- --#++ --# kadmin_cpw - Test change password function of kadmin --# --# Change password of $pname to $password. Returns 1 on success. --#-- --proc kadmin_cpw { pname password } { -- global REALMNAME -- global KADMIN -- global KEY -- global spawn_id -- -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "cpw $pname" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin cpw $pname lost KDC" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin cpw $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin cpw $pname" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*: *" { -- send "adminpass$KEY\r" -- } -- -- expect "Enter password for principal \"$pname@$REALMNAME\":" { send "$password\r" } -- expect "Re-enter password for principal \"$pname@$REALMNAME\":" { send "$password\r" } -- # When in doubt, jam one of these in there. -- expect "\r" -- expect "Password for \"$pname@$REALMNAME\" changed." -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin cpw)" -- catch "close -i $spawn_id" -- pass "kadmin cpw $pname" -- return 1 --} -- --#++ --# kadmin_cpw_rnd - Test change random key function of kadmin. --# --# Changes principal $pname's key to a new random key. Returns 1 on success. --#-- --proc kadmin_cpw_rnd { pname } { -- global REALMNAME -- global KADMIN -- global KEY -- global spawn_id -- -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "cpw -randkey $pname" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin cpw_rnd $pname lost KDC" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin cpw_rnd $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin cpw_rnd $pname" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*: *" { -- send "adminpass$KEY\r" -- } -- # When in doubt, jam one of these in there. -- expect "\r" -- expect "Key for \"$pname@$REALMNAME\" randomized." -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin cpw_rnd)" -- catch "close -i $spawn_id" -- pass "kadmin cpw_rnd $pname" -- return 1 --} -- --#++ --# kadmin_modify - Test modify principal function of kadmin. --# --# Modifies principal $pname with flags $flags. Returns 1 on success. --#-- --proc kadmin_modify { pname flags } { -- global REALMNAME -- global KADMIN -- global KEY -- global spawn_id -- -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "modprinc $flags $pname" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin modify $pname ($flags) lost KDC" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin modify $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin modify $pname" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*: *" -- send "adminpass$KEY\r" -- # When in doubt, jam one of these in there. -- expect "\r" -- expect "Principal \"$pname@$REALMNAME\" modified." -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin modify)" -- catch "close -i $spawn_id" -- pass "kadmin modify $pname" -- return 1 --} -- -- --#++ --# kadmin_list - Test list database function of kadmin. --# --# Lists the database and verifies that output matches regular expression --# "(.*@$REALMNAME)*". Returns 1 on success. --#-- --proc kadmin_list { } { -- global REALMNAME -- global KADMIN -- global KEY -- global spawn_id -- -- # "*" would match everything -- # "*n" should match a few like kadmin/admin but see ticket 5667 -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "get_principals *n" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin ldb lost KDC" -- catch "expect_after" -- return 0 -- } -- "Communication failure" { -- fail "kadmin ldb got RPC error" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin ldb" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin ldb" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*: *" { -- send "adminpass$KEY\r" -- } -- expect -re "\(.*@$REALMNAME\r\n\)+" -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin list)" -- catch "close -i $spawn_id" -- pass "kadmin ldb" -- return 1 --} -- --#++ --# kadmin_extract - Test extract service key function of kadmin. --# --# Extracts service key for service name $name instance $instance. Returns --# 1 on success. --#-- --proc kadmin_extract { instance name } { -- global REALMNAME -- global KADMIN -- global KEY -- global spawn_id -- global tmppwd -- -- catch "exec rm -f $tmppwd/keytab" -- -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "xst -k $tmppwd/keytab $name/$instance" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin xst $instance $name lost KDC" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin xst $instance $name" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin xst $instance $name" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*: *" { -- send "adminpass$KEY\r" -- } -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin xst)" -- catch "close -i $spawn_id" -- catch "exec rm -f $instance-new-keytab" -- pass "kadmin xst $instance $name" -- return 1 --} -- --#++ --# kadmin_delete - Test delete principal function of kadmin. --# --# Deletes principal $pname. Returns 1 on success. --#-- --proc kadmin_delete { pname } { -- global REALMNAME -- global KADMIN -- global KADMIN_LOCAL -- global KEY -- global spawn_id -- global tmppwd -- -- set good 0 -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "delprinc -force $pname" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin_delete $pname lost KDC" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin delprinc $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin delprinc $pname" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*: *" { -- send "adminpass$KEY\r" -- } -- expect "Principal \"$pname@$REALMNAME\" deleted." { set good 1 } -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin delprinc)" -- catch "close -i $spawn_id" -- if { $good == 1 } { -- # -- # use kadmin.local to verify that the old principal is not present. -- # -- envstack_push -- setup_kerberos_env kdc -- spawn $KADMIN_LOCAL -r $REALMNAME -- envstack_pop -- expect_after { -- -i $spawn_id -- timeout { -- fail "kadmin delprinc $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin delprinc $pname" -- catch "expect_after" -- return 0 -- } -- } -- set good 0 -- expect "kadmin.local: " { send "getprinc $pname\r" } -- expect "Principal does not exist while retrieving \"$pname@$REALMNAME\"." { set good 1 } -- expect "kadmin.local: " { send "quit\r" } -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin.local show)" -- catch "close -i $spawn_id" -- if { $good == 1 } { -- pass "kadmin delprinc $pname" -- return 1 -- } -- else { -- fail "kadmin delprinc $pname" -- return 0 -- } -- } -- else { -- fail "kadmin delprinc $pname" -- return 0 -- } --} -- --#++ --# kadmin_delete - Test delete principal function of kadmin. --# --# Deletes principal $pname. Returns 1 on success. --#-- --proc kadmin_delete_locked_down { pname } { -- global REALMNAME -- global KADMIN -- global KADMIN_LOCAL -- global KEY -- global spawn_id -- global tmppwd -- -- # -- # First test that we fail, then unlock and retry -- # -- -- set good 0 -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "delprinc -force $pname" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin_delete $pname lost KDC" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin delprinc $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin delprinc $pname" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*: *" { -- send "adminpass$KEY\r" -- } -- expect "delete_principal: Operation requires ``delete'' privilege while deleting principal \"$pname@$REALMNAME\"" { set good 1 } -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin delprinc)" -- catch "close -i $spawn_id" -- if { $good == 1 } { -- # -- # use kadmin.local to remove lockdown. -- # -- envstack_push -- setup_kerberos_env kdc -- spawn $KADMIN_LOCAL -r $REALMNAME -- envstack_pop -- expect_after { -- -i $spawn_id -- timeout { -- fail "kadmin delprinc $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin delprinc $pname" -- catch "expect_after" -- return 0 -- } -- } -- set good 0 -- expect "kadmin.local: " { send "modprinc -lockdown_keys $pname\r" } -- expect "Principal \"$pname@$REALMNAME\" modified." { set good 1 } -- expect "kadmin.local: " { send "quit\r" } -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin.local show)" -- catch "close -i $spawn_id" -- if { $good == 1 } { -- set good 0 -- if {[kadmin_delete $pname]} { set good 1 } -- } -- if { $good == 1 } { -- pass "kadmin delprinc $pname" -- return 1 -- } -- else { -- fail "kadmin delprinc $pname" -- return 0 -- } -- } -- else { -- fail "kadmin delprinc $pname" -- return 0 -- } --} -- --#++ --# kpasswd_cpw - Test password changing using kpasswd. --# --# Change $princ's password from $opw to $npw. Returns 1 on success. --#-- --proc kpasswd_cpw { princ opw npw } { -- global KPASSWD -- global REALMNAME -- -- spawn $KPASSWD $princ -- expect_after { -- timeout { -- fail "kpasswd $princ $npw" --# catch "expect_after" -- return 0 -- } -- eof { -- fail "kpasswd $princ $npw" --# catch "expect_after" -- return 0 -- } -- } -- --# expect "Changing password for $princ." --# expect "Old password:" { send "$opw\r" } --# expect "New password:" { send "$npw\r" } --# expect "New password (again):" { send "$npw\r" } -- expect "Password for $princ@$REALMNAME:" { send "$opw\r" } -- expect "Enter new password:" { send "$npw\r" } -- expect "Enter it again:" { send "$npw\r" } --# expect "Kerberos password changed." -- expect "Password changed." -- expect_after -- expect eof -- -- if ![check_exit_status "kpasswd"] { -- fail "kpasswd $princ $npw" -- return 0 -- } -- pass "kpasswd $princ $npw" -- return 1 --} -- --#++ --# kadmin_addpol - Test add new policy function of kadmin. --# --# Adds policy $pname. Returns 1 on success. --#-- --proc kadmin_addpol { pname } { -- global REALMNAME -- global KADMIN -- global KADMIN_LOCAL -- global KEY -- global spawn_id -- global tmppwd -- -- set good 0 -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "addpol $pname" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin addpol $pname lost KDC" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin addpol $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin addpol $pname" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*: *" { -- send "adminpass$KEY\r" -- } -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin addpol)" -- catch "close -i $spawn_id" -- # -- # use kadmin.local to verify that a policy was created -- # -- envstack_push -- setup_kerberos_env kdc -- spawn $KADMIN_LOCAL -r $REALMNAME -- envstack_pop -- expect_after { -- -i $spawn_id -- timeout { -- fail "kadmin addpol $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin addpol $pname" -- catch "expect_after" -- return 0 -- } -- } -- set good 0 -- expect "kadmin.local: " { send "getpol $pname\r" } -- expect "Policy: $pname" { set good 1 } -- expect "Maximum password life:" { verbose "got max pw life" } -- expect "Minimum password life:" { verbose "got min pw life" } -- expect "Minimum password length:" { verbose "got min pw length" } -- expect "Minimum number of password character classes:" { -- verbose "got min pw character classes" } -- expect "Number of old keys kept:" { verbose "got num old keys kept" } -- expect "kadmin.local: " { send "q\r" } -- -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin.local showpol)" -- catch "close -i $spawn_id" -- if { $good == 1 } { -- pass "kadmin addpol $pname" -- return 1 -- } -- else { -- fail "kadmin addpol $pname" -- return 0 -- } --} -- --#++ --# kadmin_delpol - Test delete policy function of kadmin. --# --# Deletes policy $pname. Returns 1 on success. --#-- --proc kadmin_delpol { pname } { -- global REALMNAME -- global KADMIN -- global KADMIN_LOCAL -- global KEY -- global spawn_id -- global tmppwd -- -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "delpol -force $pname" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin_delpol $pname lost KDC" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin delpol $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin delpol $pname" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*: *" { -- send "adminpass$KEY\r" -- } -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin delpol)" -- catch "close -i $spawn_id" -- # -- # use kadmin.local to verify that the old policy is not present. -- # -- envstack_push -- setup_kerberos_env kdc -- spawn $KADMIN_LOCAL -r $REALMNAME -- envstack_pop -- expect_after { -- -i $spawn_id -- timeout { -- fail "kadmin delpol $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin delpol $pname" -- catch "expect_after" -- return 0 -- } -- } -- set good 0 -- expect "kadmin.local: " { send "getpol $pname\r" } -- expect "Policy does not exist while retrieving policy \"$pname\"." { -- set good 1 -- } -- expect "kadmin.local: " { send "quit\r" } -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin.local showpol)" -- catch "close -i $spawn_id" -- if { $good == 1 } { -- pass "kadmin delpol $pname" -- return 1 -- } -- else { -- fail "kadmin delpol $pname" -- return 0 -- } --} -- --#++ --# kadmin_listpols - Test list policy database function of kadmin. --# --# Lists the policies. Returns 1 on success. --#-- --proc kadmin_listpols { } { -- global REALMNAME -- global KADMIN -- global KEY -- global spawn_id -- -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "get_policies *" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin lpols lost KDC" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin lpols" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin lpols" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*: *" { -- send "adminpass$KEY\r" -- } -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin listpols)" -- catch "close -i $spawn_id" -- pass "kadmin lpols" -- return 1 --} -- --#++ --# kadmin_modpol - Test modify policy function of kadmin. --# --# Modifies policy $pname with flags $flags. Returns 1 on success. --#-- --proc kadmin_modpol { pname flags } { -- global REALMNAME -- global KADMIN -- global KEY -- global spawn_id -- -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "modpol $flags $pname" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin modpol $pname ($flags) lost KDC" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin modpol $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin modpol $pname" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*: *" -- send "adminpass$KEY\r" -- # When in doubt, jam one of these in there. -- expect "\r" -- # Sadly, kadmin doesn't print a confirmation message for policy operations. -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin modpol)" -- catch "close -i $spawn_id" -- pass "kadmin modpol $pname" -- return 1 --} -- --#++ --# kadmin_showpol - Test show policy function of kadmin. --# --# Retrieves entry for $pname. Returns 1 on success. --#-- --proc kadmin_showpol { pname } { -- global REALMNAME -- global KADMIN -- global KEY -- global spawn_id -- -- spawn $KADMIN -p krbtest/admin@$REALMNAME -q "get_policy $pname" -- expect_after { -- "Cannot contact any KDC" { -- fail "kadmin showpol $pname lost KDC" -- catch "expect_after" -- return 0 -- } -- timeout { -- fail "kadmin showpol $pname" -- catch "expect_after" -- return 0 -- } -- eof { -- fail "kadmin showpol $pname" -- catch "expect_after" -- return 0 -- } -- } -- expect -re "assword\[^\r\n\]*: *" -- send "adminpass$KEY\r" -- expect -re "\r.*Policy: $pname.*Number of old keys kept: .*\r" -- expect_after -- expect eof -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin showpol)" -- catch "close -i $spawn_id" -- pass "kadmin showpol $pname" -- return 1 --} -- --#++ --# kdestroy --#-- --proc kdestroy { } { -- global KDESTROY -- -- spawn $KDESTROY -5 -- if ![check_exit_status "kdestroy"] { -- return 0 -- } -- return 1 --} -- --# Wrap the tests in a procedure, so that we can kill the daemons if --# we get some sort of error. -- --proc kadmin_test { } { -- global hostname -- -- # Start up the kerberos and kadmind daemons -- if {![start_kerberos_daemons 0] } { -- return -- } -- -- # Test basic kadmin functions. -- if {![kadmin_add v5principal/instance1 v5principal] \ -- || ![kadmin_addpol standardpol] \ -- || ![kadmin_showpol standardpol] \ -- || ![kadmin_listpols] \ -- || ![kadmin_modpol standardpol "-minlength 5"] \ -- || ![kadmin_add v4principal/instance2 v4principal] \ -- || ![kadmin_add_rnd v5random] \ -- || ![kadmin_show v5principal/instance1] \ -- || ![kadmin_show v4principal/instance2] \ -- || ![kadmin_show v5random] \ -- || ![kadmin_cpw v5principal/instance1 faroutman] \ -- || ![kadmin_cpw v4principal/instance2 honkydory] \ -- || ![kadmin_cpw_rnd v5random] \ -- || ![kadmin_modify v5random -allow_tix] \ -- || ![kadmin_modify v5random +allow_tix] \ -- || ![kadmin_modify v5random "-policy standardpol"] \ -- || ![kadmin_list] \ -- || ![kadmin_extract instance1 v5principal] \ -- || ![kadmin_delete v5random] \ -- || ![kadmin_delete v4principal/instance2] \ -- || ![kadmin_delete v5principal/instance1] \ -- || ![kadmin_delpol standardpol]} { -- return -- } -- --# You cannot extract a v4 key... --# || ![kadmin_extractv4 instance2 v4principal] \ -- -- # now test kpasswd -- if {![kadmin_add testprinc/instance thisisatest] \ -- || ![kpasswd_cpw testprinc/instance thisisatest anothertest] \ -- || ![kpasswd_cpw testprinc/instance anothertest goredsox] \ -- || ![kadmin_delete testprinc/instance]} { -- return -- } -- -- # now test that we can kinit with principals/passwords. -- # We defer kdestroying until after kpasswd at least once to test FAST automatic use in kpasswd -- if {![kadmin_add testprinc1/instance thisisatest] \ -- || ![kinit testprinc1/instance thisisatest 0] \ -- || ![kpasswd_cpw testprinc1/instance thisisatest anothertest] \ -- || ![kdestroy] \ -- || ![kinit testprinc1/instance anothertest 0] \ -- || ![kdestroy] \ -- || ![kpasswd_cpw testprinc1/instance anothertest goredsox] \ -- || ![kinit testprinc1/instance goredsox 0] \ -- || ![kdestroy] \ -- || ![kadmin_cpw testprinc1/instance betterwork] \ -- || ![kinit testprinc1/instance betterwork 0] \ -- || ![kdestroy] \ -- || ![kadmin_delete testprinc1/instance]} { -- return -- } -- -- # now test modify changes. -- if {![kadmin_add testuser longtestpw] \ -- || ![kinit testuser longtestpw 0] \ -- || ![kdestroy] \ -- || ![kadmin_modify testuser "-maxlife \"2500 seconds\""] \ -- || ![kinit testuser longtestpw 0] \ -- || ![kdestroy] \ -- || ![kadmin_delete testuser]} { -- return -- } -- -- # now test that reducing the history number doesn't make kadmind vulnerable. -- if {![kadmin_addpol crashpol] \ -- || ![kadmin_modpol crashpol "-history 5"] \ -- || ![kadmin_add crash first] \ -- || ![kadmin_modify crash "-policy crashpol"] \ -- || ![kadmin_cpw crash second] \ -- || ![kadmin_cpw crash third] \ -- || ![kadmin_cpw crash fourth] \ -- || ![kadmin_modpol crashpol "-history 3"] \ -- || ![kadmin_cpw crash fifth] \ -- || ![kadmin_delete crash] \ -- || ![kadmin_delpol crashpol]} { -- return -- } -- -- # test retrieval of large number of principals -- # bug [2877] -- for { set i 0 } { $i < 200 } { incr i } { -- if { ![kadmin_add "foo$i" foopass] } { -- return -- } -- } -- -- if { ![kadmin_list] } { -- return -- } -- -- # test fallback to kadmin/hostname -- if {![kadmin_add_rnd kadmin/$hostname] \ -- || ![kadmin_delete_locked_down kadmin/admin] \ -- || ![kadmin_list] \ -- || ![kadmin_add_rnd kadmin/admin -allow_tgs_req] \ -- || ![kadmin_list]} { -- return -- } -- -- verbose "kadmin_test succeeded" --} -- --run_once kadmin { -- # Set up the kerberos database. -- if {![get_hostname] \ -- || ![setup_kerberos_files] \ -- || ![setup_kerberos_env] \ -- || ![setup_kerberos_db 0]} { -- return -- } -- -- # Run the test. -- set status [catch kadmin_test msg] -- -- # Shut down the kerberos daemons and the rsh daemon. -- stop_kerberos_daemons -- -- if { $status != 0 } { -- send_error "ERROR: error in kadmin.exp\n" -- send_error "$msg\n" -- exit 1 -- } --} -diff --git a/src/tests/dejagnu/krb-standalone/pwchange.exp b/src/tests/dejagnu/krb-standalone/pwchange.exp -deleted file mode 100644 -index 010e8344a..000000000 ---- a/src/tests/dejagnu/krb-standalone/pwchange.exp -+++ /dev/null -@@ -1,145 +0,0 @@ --# Password-changing Kerberos test. --# This is a DejaGnu test script. -- --# We are about to start up a couple of daemon processes. We do all --# the rest of the tests inside a proc, so that we can easily kill the --# processes when the procedure ends. -- --proc kinit_expecting_pwchange { name pass newpass } { -- global REALMNAME -- global KINIT -- global spawn_id -- -- # Use kinit to get a ticket. -- # -- # For now always get forwardable tickets. Later when we need to make -- # tests that distinguish between forwardable tickets and otherwise -- # we should but another option to this proc. --proven -- # -- spawn $KINIT -5 -f $name@$REALMNAME -- expect { -- "Password for $name@$REALMNAME:" { -- verbose "kinit started" -- } -- timeout { -- fail "kinit" -- return 0 -- } -- eof { -- fail "kinit" -- return 0 -- } -- } -- send "$pass\r" -- expect { -- "Enter new password: " { } -- timeout { -- fail "kinit (new password prompt)" -- return 0 -- } -- eof { -- fail "kinit (new password prompt)" -- return 0 -- } -- } -- send "$newpass\r" -- expect { -- " again: " { } -- timeout { -- fail "kinit (new password prompt2)" -- return 0 -- } -- eof { -- fail "kinit (new password prompt2)" -- return 0 -- } -- } -- send "$newpass\r" -- expect eof -- if ![check_exit_status kinit] { -- return 0 -- } -- -- return 1 --} -- --proc doit { } { -- global REALMNAME -- global KLIST -- global KDESTROY -- global KEY -- global KADMIN_LOCAL -- global KTUTIL -- global hostname -- global tmppwd -- global spawn_id -- global supported_enctypes -- global KRBIV -- global portbase -- global mode -- -- # Start up the kerberos and kadmind daemons. -- if ![start_kerberos_daemons 0] { -- return -- } -- -- # Use kadmin to add a key. -- if ![add_kerberos_key pwchanger 0] { -- return -- } -- -- setup_kerberos_env kdc -- spawn $KADMIN_LOCAL -q "modprinc +needchange pwchanger" -- catch expect_after -- expect { -- timeout { -- fail "kadmin.local modprinc +needchange" -- } -- eof { -- pass "kadmin.local modprinc +needchange" -- } -- } -- set k_stat [wait -i $spawn_id] -- verbose "wait -i $spawn_id returned $k_stat (kadmin modprinc +needchange)" -- catch "close -i $spawn_id" -- -- setup_kerberos_env client -- if ![kinit_expecting_pwchange pwchanger pwchanger$KEY floople] { -- return -- } -- pass "kinit (password change)" -- if ![kinit pwchanger floople 0] { -- return -- } -- pass "kinit (new password)" -- -- # Destroy the ticket. -- spawn $KDESTROY -5 -- if ![check_exit_status "kdestroy"] { -- return -- } -- pass "kdestroy" --} -- --run_once pwchange { -- # Set up the Kerberos files and environment. -- if {![get_hostname] || ![setup_kerberos_files] || ![setup_kerberos_env]} { -- return -- } -- -- # Initialize the Kerberos database. The argument tells -- # setup_kerberos_db that it is being called from here. -- if ![setup_kerberos_db 0] { -- return -- } -- -- set status [catch doit msg] -- -- stop_kerberos_daemons -- -- if { $status != 0 } { -- send_error "ERROR: error in pwchange.exp\n" -- send_error "$msg\n" -- exit 1 -- } --} -diff --git a/src/tests/dejagnu/krb-standalone/pwhist.exp b/src/tests/dejagnu/krb-standalone/pwhist.exp -deleted file mode 100644 -index ed7a3771a..000000000 ---- a/src/tests/dejagnu/krb-standalone/pwhist.exp -+++ /dev/null -@@ -1,217 +0,0 @@ --# password history tests -- --# one *non-interactive* kadmin.local request --proc onerq { rq pname str {flags ""} } { -- global REALMNAME -- global KADMIN_LOCAL -- -- spawn $KADMIN_LOCAL -r $REALMNAME -q "$rq $flags $pname" -- expect_after { -- timeout { -- verbose "kadmin.local $rq $flags $pname timed out" -- catch expect_after -- kill [exp_pid] -- close -- expect eof -- wait -- return 0 -- } eof { -- verbose "kadmin.local $rq $flags $pname got EOF" -- catch expect_after -- wait -- return 0 -- } -- } -- expect $str -- expect_after -- expect eof -- wait -- return 1 --} -- --proc addprinc { pname pw } { -- global REALMNAME -- -- return [onerq addprinc $pname \ -- "Principal \"$pname@$REALMNAME\" created." "-pw $pw"] --} -- --proc delprinc { pname } { -- global REALMNAME -- return [onerq delprinc $pname \ -- "Principal \"$pname@$REALMNAME\" deleted." "-force"] --} -- --proc cpw { pname pw } { -- global REALMNAME -- -- return [onerq cpw $pname \ -- "Password for \"$pname@$REALMNAME\" changed." "-pw $pw"] --} -- --proc modprinc { pname flags } { -- global REALMNAME -- -- return [onerq modprinc $pname \ -- "Principal \"$pname@$REALMNAME\" modified." $flags] --} -- --proc addpol { pname } { -- if ![onerq addpol $pname ""] { -- return 0 -- } -- return [onerq getpol $pname "Policy: $pname"] --} -- --proc delpol { pname } { -- onerq delpol $pname "" -force -- return [onerq getpol $pname \ -- "Policy does not exist while retrieving policy \"$pname\"."] --} -- --proc modpol { pname flags } { -- return [onerq modpol $pname "" $flags] --} -- --# Mandatory command must return true. --# Issues a break in its parent on failure. --proc mustrun { cmd } { -- if ![eval $cmd] { -- perror "mandatory command failed: $cmd" -- uplevel break -- } --} -- --# Fail test if command fails. --# Issues a break in its parent on failure. --proc chkpass { cmd } { -- upvar test test -- if ![eval $cmd] { -- verbose "unexpected failure: $cmd" -- fail $test -- uplevel break -- } --} -- --# Fail test if command succeeds. --# Issues a break in its parent on failure. --proc chkfail { cmd } { -- upvar test test -- if [eval $cmd] { -- verbose "unexpected success: $cmd" -- fail $test -- uplevel break -- } --} -- --# wrapper to run command (actually usually sequence of commands) --# --# If any part of CMD throws an exception, set failall, otherwise pass. --# If failall is already true, report unresolved. --proc wraptest { test cmd } { -- upvar failall failall -- if $failall { -- unresolved $test -- return -- } -- if [catch $cmd] { -- set failall 1 -- } else { -- pass $test -- } --} -- --run_once pwhist { -- # Set up the kerberos database. -- if {![get_hostname] \ -- || ![setup_kerberos_files] \ -- || ![setup_kerberos_env kdc] \ -- || ![setup_kerberos_db 0]} { -- return -- } -- -- set failall 0 -- wraptest "nkeys=1, nhist=3" { -- mustrun { addpol crashpol } -- mustrun { modpol crashpol "-history 3"} -- mustrun { addprinc crash 1111 } -- mustrun { modprinc crash "-policy crashpol" } -- chkpass { cpw crash 2222 } -- chkfail { cpw crash 2222 } -- chkfail { cpw crash 1111 } -- } -- verbose {old_keys [ 1111 ->[] ]} -- -- # The following will result in reading/writing past array bounds if -- # add_to_history() is not patched. -- # -- # NOTE: A pass from this test does not mean the bug isn't present; -- # check with Purify, valgrind, etc. -- wraptest "array bounds ok on nkeys=1, nhist 3->2" { -- mustrun { modpol crashpol "-history 2" } -- chkpass { cpw crash 3333 } -- } -- verbose {old_keys [ ->2222 ]} -- -- wraptest "verify nhist=2" { -- mustrun { delprinc crash } -- mustrun { addprinc crash 1111 } -- mustrun { modprinc crash "-policy crashpol" } -- chkpass { cpw crash 2222 } -- chkfail { cpw crash 2222 } -- chkfail { cpw crash 1111 } -- } -- verbose {old_keys [ ->1111 ]} -- -- # The following will fail if growing the history array causes an extra -- # key to be lost due to failure to shift entries. -- wraptest "grow nhist 2->3" { -- mustrun { modpol crashpol "-history 3" } -- chkpass { cpw crash 3333 } -- chkfail { cpw crash 3333 } -- chkfail { cpw crash 2222 } -- chkfail { cpw crash 1111 } -- } -- verbose {old_keys [ 2222 ->1111 ]} -- -- wraptest "grow nhist 3->4" { -- mustrun { modpol crashpol "-history 4" } -- chkfail { cpw crash 3333 } -- chkfail { cpw crash 2222 } -- chkfail { cpw crash 1111 } -- chkpass { cpw crash 4444 } -- chkfail { cpw crash 3333 } -- chkfail { cpw crash 2222 } -- chkfail { cpw crash 1111 } -- } -- verbose {old_keys [ 2222 3333 ->1111 ]} -- wraptest "shrink nhist 4->3" { -- mustrun { modpol crashpol "-history 3" } -- chkfail { cpw crash 4444 } -- chkfail { cpw crash 3333 } -- chkfail { cpw crash 2222 } -- chkfail { cpw crash 1111 } -- chkpass { cpw crash 5555 } -- } -- verbose {old_keys [ 4444 ->3333 ]} -- wraptest "verify nhist=3" { -- chkfail { cpw crash 5555 } -- chkfail { cpw crash 4444 } -- chkfail { cpw crash 3333 } -- chkpass { cpw crash 2222 } -- } -- verbose {old_keys [ ->4444 5555 ]} -- wraptest "shrink nhist 3->2" { -- mustrun { modpol crashpol "-history 2" } -- chkfail { cpw crash 2222 } -- chkfail { cpw crash 5555 } -- chkfail { cpw crash 4444 } -- chkpass { cpw crash 3333 } -- } -- verbose {old_keys [ ->2222 ]} -- -- delprinc crash -- delpol crashpol -- -- stop_kerberos_daemons --} -diff --git a/src/tests/t_changepw.py b/src/tests/t_changepw.py -index 573bdbd49..bf8e3a9eb 100755 ---- a/src/tests/t_changepw.py -+++ b/src/tests/t_changepw.py -@@ -1,23 +1,24 @@ - from k5test import * - --# This file is intended to cover any password-changing mechanism. For --# now it only contains a regression test for #7868. -- - realm = K5Realm(create_host=False, get_creds=False, start_kadmind=True) -+realm.prep_kadmin() - - # Mark a principal as expired and change its password through kinit. -+mark('password change via kinit') - realm.run([kadminl, 'modprinc', '-pwexpire', '1 day ago', 'user']) - pwinput = password('user') + '\nabcd\nabcd\n' - realm.run([kinit, realm.user_princ], input=pwinput) - --# Do the same thing with FAST, with tracing turned on. --realm.run([kadminl, 'modprinc', '-pwexpire', '1 day ago', 'user']) -+# Regression test for #7868 (preauth options ignored when -+# krb5_get_init_creds_password() initiates a password change). This -+# time use the REQUIRES_PWCHANGE bit instead of the password -+# expiration time. -+mark('password change via kinit with FAST') -+realm.run([kadminl, 'modprinc', '+needchange', 'user']) - pwinput = 'abcd\nefgh\nefgh\n' - out, trace = realm.run([kinit, '-T', realm.ccache, realm.user_princ], - input=pwinput, return_trace=True) -- --# Read the trace and check that FAST was used when getting the --# kadmin/changepw ticket. -+# Check that FAST was used when getting the kadmin/changepw ticket. - getting_changepw = fast_used_for_changepw = False - for line in trace.splitlines(): - if 'Getting initial credentials for user@' in line: -@@ -29,4 +30,21 @@ for line in trace.splitlines(): - if not fast_used_for_changepw: - fail('FAST was not used to get kadmin/changepw ticket') - -+# Test that passwords specified via kadmin and kpasswd are usable with -+# kinit. -+mark('password change usability by kinit') -+realm.run([kadminl, 'addprinc', '-pw', 'pw1', 'testprinc']) -+# Run kpasswd with an active cache to exercise automatic FAST use. -+realm.kinit('testprinc', 'pw1') -+realm.run([kpasswd, 'testprinc'], input='pw1\npw2\npw2\n') -+realm.kinit('testprinc', 'pw2') -+realm.run([kdestroy]) -+realm.run([kpasswd, 'testprinc'], input='pw2\npw3\npw3\n') -+realm.kinit('testprinc', 'pw3') -+realm.run([kdestroy]) -+realm.run_kadmin(['cpw', '-pw', 'pw4', 'testprinc']) -+realm.kinit('testprinc', 'pw4') -+realm.run([kdestroy]) -+realm.run([kadminl, 'delprinc', 'testprinc']) -+ - success('Password change tests') -diff --git a/src/tests/t_kadmin.py b/src/tests/t_kadmin.py -new file mode 100644 -index 000000000..fe6a3cc2e ---- /dev/null -+++ b/src/tests/t_kadmin.py -@@ -0,0 +1,54 @@ -+from k5test import * -+ -+realm = K5Realm(start_kadmind=True) -+ -+# Create a principal. Test -q option and keyboard entry of the admin -+# password and principal password. Verify creation with kadmin.local. -+realm.run([kadmin, '-q', 'addprinc princ/pw'], -+ input=password('admin') + '\npw1\npw1\n') -+realm.run([kadminl, 'getprinc', 'princ/pw'], -+ expected_msg='Principal: princ/pw@KRBTEST.COM') -+ -+# Run the remaining tests with a cache for efficiency. -+realm.prep_kadmin() -+ -+realm.run_kadmin(['addpol', 'standardpol']) -+realm.run_kadmin(['listpols'], expected_msg='standardpol') -+realm.run_kadmin(['modpol', '-minlength', '5', 'standardpol']) -+realm.run_kadmin(['getpol', 'standardpol'], -+ expected_msg='Minimum password length: 5') -+ -+realm.run_kadmin(['addprinc', '-randkey', 'princ/random']) -+realm.run([kadminl, 'getprinc', 'princ/random'], -+ expected_msg='Principal: princ/random@KRBTEST.COM') -+ -+realm.run_kadmin(['cpw', 'princ/pw'], input='newpw\nnewpw\n') -+realm.run_kadmin(['cpw', '-randkey', 'princ/random']) -+ -+realm.run_kadmin(['modprinc', '-allow_tix', 'princ/random']) -+realm.run_kadmin(['modprinc', '+allow_tix', 'princ/random']) -+realm.run_kadmin(['modprinc', '-policy', 'standardpol', 'princ/random']) -+ -+realm.run_kadmin(['listprincs'], expected_msg='princ/random@KRBTEST.COM') -+ -+realm.run_kadmin(['ktadd', 'princ/pw']) -+ -+realm.run_kadmin(['delprinc', 'princ/random']) -+realm.run([kadminl, 'getprinc', 'princ/random'], expected_code=1, -+ expected_msg='Principal does not exist') -+realm.run_kadmin(['delprinc', 'princ/pw']) -+realm.run([kadminl, 'getprinc', 'princ/pw'], expected_code=1, -+ expected_msg='Principal does not exist') -+ -+realm.run_kadmin(['delpol', 'standardpol']) -+realm.run([kadminl, 'getpol', 'standardpol'], expected_code=1, -+ expected_msg='Policy does not exist') -+ -+# Regression test for #2877 (fixed-sized GSSRPC buffers can't -+# accomodate large listprinc results). -+mark('large listprincs result') -+for i in range(200): -+ realm.run_kadmin(['addprinc', '-randkey', 'foo%d' % i]) -+realm.run_kadmin(['listprincs'], expected_msg='foo199') -+ -+success('kadmin and kpasswd tests') -diff --git a/src/tests/t_policy.py b/src/tests/t_policy.py -index 5a0c06b86..2bb4f5f18 100755 ---- a/src/tests/t_policy.py -+++ b/src/tests/t_policy.py -@@ -25,6 +25,68 @@ realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser'], expected_code=1, - realm.run([kadminl, 'cpw', '-pw', '3rdpassword', 'pwuser']) - realm.run([kadminl, 'cpw', '-pw', 'l0ngenough', 'pwuser']) - -+# Regression test for #929 (kadmind crash with more historical -+# passwords in a principal entry than current policy history setting). -+mark('password history (policy value reduced below current array size)') -+realm.run([kadminl, 'addpol', '-history', '5', 'histpol']) -+realm.addprinc('histprinc', 'first') -+realm.run([kadminl, 'modprinc', '-policy', 'histpol', 'histprinc']) -+realm.run([kadminl, 'cpw', '-pw', 'second', 'histprinc']) -+realm.run([kadminl, 'cpw', '-pw', 'third', 'histprinc']) -+realm.run([kadminl, 'cpw', '-pw', 'fourth', 'histprinc']) -+realm.run([kadminl, 'modpol', '-history', '3', 'histpol']) -+realm.run([kadminl, 'cpw', '-pw', 'fifth', 'histprinc']) -+realm.run([kadminl, 'delprinc', 'histprinc']) -+ -+# Regression test for #2841 (heap buffer overflow when policy history -+# value is reduced to match the number of historical passwords for a -+# principal). -+mark('password history (policy value reduced to current array size)') -+def histfail(*pwlist): -+ for pw in pwlist: -+ realm.run([kadminl, 'cpw', '-pw', pw, 'histprinc'], expected_code=1, -+ expected_msg='Cannot reuse password') -+realm.run([kadminl, 'modpol', '-history', '3', 'histpol']) -+realm.addprinc('histprinc', '1111') -+realm.run([kadminl, 'modprinc', '-policy', 'histpol', 'histprinc']) -+realm.run([kadminl, 'cpw', '-pw', '2222', 'histprinc']) -+histfail('2222', '1111') -+realm.run([kadminl, 'modpol', '-history', '2', 'histpol']) -+realm.run([kadminl, 'cpw', '-pw', '3333', 'histprinc']) -+ -+# Test that the history array is properly resized if the policy -+# history value is increased after the array is filled. -+mark('password history (policy value increase)') -+realm.run([kadminl, 'delprinc', 'histprinc']) -+realm.addprinc('histprinc', '1111') -+realm.run([kadminl, 'modprinc', '-policy', 'histpol', 'histprinc']) -+realm.run([kadminl, 'cpw', '-pw', '2222', 'histprinc']) -+histfail('2222', '1111') -+realm.run([kadminl, 'cpw', '-pw', '2222', 'histprinc'], expected_code=1, -+ expected_msg='Cannot reuse password') -+realm.run([kadminl, 'cpw', '-pw', '1111', 'histprinc'], expected_code=1, -+ expected_msg='Cannot reuse password') -+realm.run([kadminl, 'modpol', '-history', '3', 'histpol']) -+realm.run([kadminl, 'cpw', '-pw', '3333', 'histprinc']) -+histfail('3333', '2222', '1111') -+realm.run([kadminl, 'modpol', '-history', '4', 'histpol']) -+histfail('3333', '2222', '1111') -+realm.run([kadminl, 'cpw', '-pw', '4444', 'histprinc']) -+histfail('4444', '3333', '2222', '1111') -+ -+# Test that when the policy history value is reduced, all currently -+# known old passwords still fail until the next password change, after -+# which the new number of old passwords fails (but no more). -+mark('password history (policy value reduction)') -+realm.run([kadminl, 'modpol', '-history', '3', 'histpol']) -+histfail('4444', '3333', '2222', '1111') -+realm.run([kadminl, 'cpw', '-pw', '5555', 'histprinc']) -+histfail('5555', '3333', '3333') -+realm.run([kadminl, 'cpw', '-pw', '2222', 'histprinc']) -+realm.run([kadminl, 'modpol', '-history', '2', 'histpol']) -+histfail('2222', '5555', '4444') -+realm.run([kadminl, 'cpw', '-pw', '3333', 'histprinc']) -+ - # Test references to nonexistent policies. - mark('nonexistent policy references') - realm.run([kadminl, 'addprinc', '-randkey', '-policy', 'newpol', 'newuser']) diff --git a/Read-GSS-configuration-files-with-mtime-0.patch b/Read-GSS-configuration-files-with-mtime-0.patch deleted file mode 100644 index 5bcae39..0000000 --- a/Read-GSS-configuration-files-with-mtime-0.patch +++ /dev/null @@ -1,71 +0,0 @@ -From f8747c22fd159ad3556fdf6ec4f269c754c1eadb Mon Sep 17 00:00:00 2001 -From: Simo Sorce -Date: Thu, 19 May 2022 12:27:40 -0400 -Subject: [PATCH] Read GSS configuration files with mtime 0 - -There is at least one case (with flatpaks) where configuration files -in the special read-only /etc all have an mtime of 0. Using an -initial last modified time of 0 in g_initialize.c causes these files -to never be read. - -Change the initial high value to the be the "invalid" value -(time_t)-1. Since the C and POSIX standards do not require time_t to -be signed, special-case the checks in load_if_changed() and -updateMechList() to treat all mod times as newer than -1. - -[ghudson@mit.edu: edited commit message; slightly modified approach] - -ticket: 9060 (new) -target_version: 1.20 -tags: pullup ---- - src/lib/gssapi/mechglue/g_initialize.c | 11 ++++++----- - 1 file changed, 6 insertions(+), 5 deletions(-) - -diff --git a/src/lib/gssapi/mechglue/g_initialize.c b/src/lib/gssapi/mechglue/g_initialize.c -index 6d49700a5..857d4a4f2 100644 ---- a/src/lib/gssapi/mechglue/g_initialize.c -+++ b/src/lib/gssapi/mechglue/g_initialize.c -@@ -93,7 +93,7 @@ static void free_mechSet(void); - static gss_mech_info g_mechList = NULL; - static gss_mech_info g_mechListTail = NULL; - static k5_mutex_t g_mechListLock = K5_MUTEX_PARTIAL_INITIALIZER; --static time_t g_confFileModTime = (time_t)0; -+static time_t g_confFileModTime = (time_t)-1; - static time_t g_confLastCall = (time_t)0; - - static gss_OID_set_desc g_mechSet = { 0, NULL }; -@@ -469,9 +469,9 @@ load_if_changed(const char *pathname, time_t last, time_t *highest) - mtime = check_link_mtime(pathname, &mtime); - if (mtime == (time_t)-1) - return; -- if (mtime > *highest) -+ if (mtime > *highest || *highest == (time_t)-1) - *highest = mtime; -- if (mtime > last) -+ if (mtime > last || last == (time_t)-1) - loadConfigFile(pathname); - } - -@@ -482,7 +482,7 @@ static void - loadConfigFiles() - { - glob_t globbuf; -- time_t highest = 0, now; -+ time_t highest = (time_t)-1, now; - char **path; - const char *val; - -@@ -522,7 +522,8 @@ updateMechList(void) - - #if defined(_WIN32) - time_t lastConfModTime = getRegConfigModTime(MECH_KEY); -- if (g_confFileModTime >= lastConfModTime) -+ if (g_confFileModTime >= lastConfModTime && -+ g_confFileModTime != (time_t)-1) - return; - g_confFileModTime = lastConfModTime; - loadConfigFromRegistry(HKEY_CURRENT_USER, MECH_KEY); --- -2.35.3 - diff --git a/Remove-TCL-based-libkadm5-API-tests.patch b/Remove-TCL-based-libkadm5-API-tests.patch deleted file mode 100644 index 7819198..0000000 --- a/Remove-TCL-based-libkadm5-API-tests.patch +++ /dev/null @@ -1,18229 +0,0 @@ -From ddb189ff95350afc0e3e063016a0f0dd5213dc4c Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 16 Apr 2021 10:24:04 -0400 -Subject: [PATCH] Remove TCL-based libkadm5 API tests - -[antorres@redhat.com: remove diff for .gitignore] ---- - .gitignore | 20 - - doc/kadm5/api-unit-test.tex | 2680 ----------------- - src/config/pre.in | 18 +- - src/configure.ac | 31 +- - src/kadmin/Makefile.in | 2 +- - src/kadmin/testing/Makefile.in | 8 - - src/kadmin/testing/deps | 1 - - src/kadmin/testing/proto/kdc.conf.proto | 16 - - src/kadmin/testing/proto/krb5.conf.proto | 32 - - src/kadmin/testing/proto/ovsec_adm.dict | 3 - - src/kadmin/testing/scripts/Makefile.in | 18 - - src/kadmin/testing/scripts/deps | 1 - - src/kadmin/testing/scripts/env-setup.shin | 104 - - src/kadmin/testing/scripts/init_db | 229 -- - src/kadmin/testing/scripts/start_servers | 69 - - .../testing/scripts/start_servers_local | 157 - - src/kadmin/testing/scripts/stop_servers | 60 - - src/kadmin/testing/scripts/stop_servers_local | 44 - - src/kadmin/testing/tcl/util.t | 58 - - src/kadmin/testing/util/Makefile.in | 42 - - src/kadmin/testing/util/bsddb_dump.c | 65 - - src/kadmin/testing/util/deps | 16 - - src/kadmin/testing/util/tcl_kadm5.c | 2566 ---------------- - src/kadmin/testing/util/tcl_kadm5.h | 3 - - src/kadmin/testing/util/tcl_kadm5_syntax | 57 - - src/kadmin/testing/util/tcl_krb5_hash.c | 167 - - src/kadmin/testing/util/test.c | 38 - - src/lib/kadm5/Makefile.in | 3 +- - src/lib/kadm5/unit-test/Makefile.in | 143 - - src/lib/kadm5/unit-test/api.2/crte-policy.exp | 927 ------ - src/lib/kadm5/unit-test/api.2/get-policy.exp | 199 -- - src/lib/kadm5/unit-test/api.2/mod-policy.exp | 675 ----- - .../api.current/chpass-principal-v2.exp | 68 - - .../api.current/chpass-principal.exp | 176 -- - .../unit-test/api.current/crte-policy.exp | 927 ------ - .../unit-test/api.current/crte-principal.exp | 1336 -------- - .../kadm5/unit-test/api.current/destroy.exp | 203 -- - .../unit-test/api.current/dlte-policy.exp | 208 -- - .../unit-test/api.current/dlte-principal.exp | 253 -- - .../unit-test/api.current/get-policy.exp | 199 -- - .../api.current/get-principal-v2.exp | 250 -- - .../unit-test/api.current/get-principal.exp | 346 --- - .../kadm5/unit-test/api.current/init-v2.exp | 506 ---- - src/lib/kadm5/unit-test/api.current/init.exp | 699 ----- - .../unit-test/api.current/mod-policy.exp | 711 ----- - .../api.current/mod-principal-v2.exp | 115 - - .../unit-test/api.current/mod-principal.exp | 1606 ---------- - .../api.current/randkey-principal-v2.exp | 61 - - .../api.current/randkey-principal.exp | 297 -- - src/lib/kadm5/unit-test/config/unix.exp | 222 -- - src/lib/kadm5/unit-test/deps | 86 - - src/lib/kadm5/unit-test/destroy-test.c | 48 - - src/lib/kadm5/unit-test/diff-files/destroy-1 | 2 - - src/lib/kadm5/unit-test/diff-files/no-diffs | 2 - - src/lib/kadm5/unit-test/handle-test.c | 140 - - src/lib/kadm5/unit-test/init-test.c | 39 - - src/lib/kadm5/unit-test/iter-test.c | 51 - - src/lib/kadm5/unit-test/lib/lib.t | 306 -- - src/lib/kadm5/unit-test/lock-test.c | 105 - - src/lib/kadm5/unit-test/randkey-test.c | 42 - - src/lib/kadm5/unit-test/setkey-test.c | 246 -- - src/lib/kadm5/unit-test/site.exp | 2 - - 62 files changed, 7 insertions(+), 17697 deletions(-) - delete mode 100644 doc/kadm5/api-unit-test.tex - delete mode 100644 src/kadmin/testing/Makefile.in - delete mode 100644 src/kadmin/testing/deps - delete mode 100644 src/kadmin/testing/proto/kdc.conf.proto - delete mode 100644 src/kadmin/testing/proto/krb5.conf.proto - delete mode 100644 src/kadmin/testing/proto/ovsec_adm.dict - delete mode 100644 src/kadmin/testing/scripts/Makefile.in - delete mode 100644 src/kadmin/testing/scripts/deps - delete mode 100755 src/kadmin/testing/scripts/env-setup.shin - delete mode 100755 src/kadmin/testing/scripts/init_db - delete mode 100755 src/kadmin/testing/scripts/start_servers - delete mode 100755 src/kadmin/testing/scripts/start_servers_local - delete mode 100755 src/kadmin/testing/scripts/stop_servers - delete mode 100755 src/kadmin/testing/scripts/stop_servers_local - delete mode 100644 src/kadmin/testing/tcl/util.t - delete mode 100644 src/kadmin/testing/util/Makefile.in - delete mode 100644 src/kadmin/testing/util/bsddb_dump.c - delete mode 100644 src/kadmin/testing/util/deps - delete mode 100644 src/kadmin/testing/util/tcl_kadm5.c - delete mode 100644 src/kadmin/testing/util/tcl_kadm5.h - delete mode 100644 src/kadmin/testing/util/tcl_kadm5_syntax - delete mode 100644 src/kadmin/testing/util/tcl_krb5_hash.c - delete mode 100644 src/kadmin/testing/util/test.c - delete mode 100644 src/lib/kadm5/unit-test/Makefile.in - delete mode 100644 src/lib/kadm5/unit-test/api.2/crte-policy.exp - delete mode 100644 src/lib/kadm5/unit-test/api.2/get-policy.exp - delete mode 100644 src/lib/kadm5/unit-test/api.2/mod-policy.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/chpass-principal.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/crte-policy.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/crte-principal.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/destroy.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/dlte-policy.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/dlte-principal.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/get-policy.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/get-principal-v2.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/get-principal.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/init-v2.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/init.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/mod-policy.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/mod-principal-v2.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/mod-principal.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp - delete mode 100644 src/lib/kadm5/unit-test/api.current/randkey-principal.exp - delete mode 100644 src/lib/kadm5/unit-test/config/unix.exp - delete mode 100644 src/lib/kadm5/unit-test/deps - delete mode 100644 src/lib/kadm5/unit-test/destroy-test.c - delete mode 100644 src/lib/kadm5/unit-test/diff-files/destroy-1 - delete mode 100644 src/lib/kadm5/unit-test/diff-files/no-diffs - delete mode 100644 src/lib/kadm5/unit-test/handle-test.c - delete mode 100644 src/lib/kadm5/unit-test/init-test.c - delete mode 100644 src/lib/kadm5/unit-test/iter-test.c - delete mode 100644 src/lib/kadm5/unit-test/lib/lib.t - delete mode 100644 src/lib/kadm5/unit-test/lock-test.c - delete mode 100644 src/lib/kadm5/unit-test/randkey-test.c - delete mode 100644 src/lib/kadm5/unit-test/setkey-test.c - delete mode 100644 src/lib/kadm5/unit-test/site.exp - -diff --git a/doc/kadm5/api-unit-test.tex b/doc/kadm5/api-unit-test.tex -deleted file mode 100644 -index 014242037..000000000 ---- a/doc/kadm5/api-unit-test.tex -+++ /dev/null -@@ -1,2680 +0,0 @@ --% This document is included for historical purposes only, and does not --% apply to krb5 today. -- --\documentstyle[times,fullpage]{article} -- --%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% --%% Make _ actually generate an _, and allow line-breaking after it. --\let\underscore=\_ --\catcode`_=13 --\def_{\underscore\penalty75\relax} --%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% -- --\newcommand{\test}[1]{\begin{description} --\setlength{\itemsep}{0pt} --#1 --\end{description} -- --} -- --\newcommand{\numtest}[2]{\begin{description} --\setlength{\itemsep}{0pt} --\Number{#1} --#2 --\end{description} -- --} -- --\newcommand{\Number}[1]{\item[Number:] #1} --\newcommand{\Reason}[1]{\item[Reason:] #1} --\newcommand{\Expected}[1]{\item[Expected:] #1} --\newcommand{\Conditions}[1]{\item[Conditions:] #1} --\newcommand{\Priority}[1]{\item[Priority:] #1} --\newcommand{\Status}[1]{\item[Status:] #1} --\newcommand{\Vtwonote}[1]{\item[V2 note:] #1} --\newcommand{\Version}[1]{\item[Version:] #1} --\newcommand{\Call}[1]{} --%\newcommand{\Call}[1]{\item[Call:] #1} --%\newcommand{\Number}[1]{} --%\newcommand{\Reason}[1]{} --%\newcommand{\Expected}[1]{} --%\newcommand{\Conditions}[1]{} --%\newcommand{\Priority}[1]{} -- --\title{KADM5 Admin API\\ --Unit Test Description} --\author{Jonathan I. Kamens} -- --\begin{document} -- --\maketitle -- --%\tableofcontents -- --\section{Introduction} -- --The following is a description of a black-box unit test of the KADM5 --API. Each API function is listed, followed by the tests that should be --performed on it. -- --The tests described here are based on the ``Kerberos Administration --System KADM5 API Functional Specifications'', revision 1.68. This --document was originally written based on the OpenVision API functional --specifications, version 1.41, dated August 18, 1994, and many --indications of the original version remain. -- --All tests which test for success should verify, using some means other --than the return value of the function being tested, that the requested --operation was successfully performed. For example: for init, test --that other operations can be performed after init; for destroy, test --that other operations can't be performed after destroy; for modify --functions, verify that all modifications to the database which should --have taken place did, and that the new, modified data is in effect; --for get operations, verify that the data retrieved is the data that --should actually be in the database. -- --The tests would be better if they compared the actual contents of the --database before and after each test, rather than relying on the KADM5 --API to report the results of changes. -- --Similarly, all tests which test for failure should verify that the --no component of the requested operation took place. For example: if --init fails, other operations should not work. If a modify fails, all --data in the database should be the same as it was before the attempt --to modify, and the old data should still be what is enforced. --Furthermore, tests which test for failure should verify that the --failure code returned is correct for the specific failure condition --tested. -- --Most of the tests listed below should be run twice -- once locally on --the server after linking against the server API library, and once --talking to the server via authenticated Sun RPC after linking against --the client API library. Tests which should only be run locally or via --RPC are labelled with a ``local'' or ``RPC''. -- --Furthermore, in addition to the tests labelled below, a test should be --implemented to verify that a client can't perform operations on the --server through the client API library when it's linked against --standard Sun RPC instead of OpenV*Secure's authenticated Sun RPC. --This will require a client with a modified version of ovsec_kadm_init --which doesn't call auth_gssapi_create. This client should call this --modified ovsec_kadm_init and then call some other admin API function, --specifying arguments to both functions that would work if the --authenticated Sun RPC had been used, but shouldn't if authentication --wasn't used. The test should verify that the API function call after --the init doesn't succeed. -- --There is also another test to see if all the API functions handle getting an --invalid server handle correctly. This is not done as part of the tests that --are run through the TCL program cause the TCL program has no way of --invalidating a server handle. So there is a program that calls init and --changes the handle magic number, and then attempts to call each API function --with the corrupted server handle. -- --A number of tests have been added or changed to correspond with KADM5 --API version 2. Tests which are only performed against the newer --version specify the version number in the test description. -- --\section{ovsec_kadm_init} -- --\numtest{1}{ --\Reason{An empty string realm is rejected.} --\Status{Implemented} --\Vtwonote{The empty string is now passed as the realm field of the --parameters structure.} --} -- --\numtest{2}{ --\Reason{A realm containing invalid characters is rejected.} --\Status{Implemented} --\Vtwonote{The invalid character is now passed as the realm field of the --parameters structure.} --} -- --\numtest{2.5}{ --\Reason{A non-existent realm is rejected.} --\Status{Implemented} --\Vtwonote{The non-existent realm is now passed as the realm field of the --parameters structure.} --} -- --\numtest{3}{ --\Reason{A bad service name representing an existing principal -- (different from the client principal) is rejected.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{4}{ --\Reason{A bad service name representing a non-existent -- principal is rejected.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{5}{ --\Reason{A bad service name identical to the (existing) client -- name is rejected.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{6}{ --\Reason{A null password causes password prompting.} --\Status{Implemented} --} -- --\numtest{7}{ --\Reason{An empty-string causes password prompting} --\Status{Implemented} --} -- --\numtest{8}{ --\Reason{An incorrect password which is the password of another -- user is rejected.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{9}{ --\Reason{An incorrect password which isn't the password of any -- user is rejected.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{10}{ --\Reason{A null client_name is rejected.} --\Status{Implemented} --} -- --% Empty string client name is legal. --%\numtest{11}{ --%\Reason{An empty-string client_name is rejected.} --%} -- --\numtest{12}{ --\Reason{A client_name referring to a non-existent principal in -- the default realm is rejected.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{13}{ --\Reason{A client_name referring to a non-existent principal -- with the local realm specified explicitly is rejected.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{14}{ --\Reason{A client_name referring to a non-existent principal in -- a nonexistent realm is rejected.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{15}{ --\Reason{A client_name referring to an existing principal in a -- nonexistent realm is rejected.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{16}{ --\Reason{Valid invocation.} --\Status{Implemented} --} -- --\numtest{17}{ --\Reason{Valid invocation (explicit client realm).} --\Status{Implemented} --} -- --\numtest{18}{ --\Reason{Valid invocation (CHANGEPW_SERVICE).} --\Status{Implemented} --} -- --\numtest{19}{ --\Reason{Valid invocation (explicit service realm).} --\Status{Implemented} --\Vtwonote{The explicit realm is now passed as the realm field of the --configuration parameters.} --} -- --\numtest{20}{ --\Reason{Valid invocation (database access allowed after init).} --\Status{Implemented} --} -- --%\numtest{21}{ --%\Reason{Init fails when called twice in a row.} --%\Status{Implemented} --%} -- --\numtest{22}{ --\Reason{A null password causes master-key prompting.} --\Conditions{local} --\Status{Implemented} --\Vtwonote{Obsolete.} --} -- --\numtest{22.5}{ --\Reason{A empty string password causes master-key prompting.} --\Conditions{local} --\Status{Implemented} --\Vtwonote{Obsolete.} --} -- --%\numtest{23}{ --%\Reason{A non-null password causes reading from the kstash.} --%\Conditions{local} --%\Status{Implemented} --%} -- --\numtest{24}{ --\Reason{Null service name is ignored in local invocation.} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{25}{ --\Reason{Non-null service name is ignored in local invocation.} --\Conditions{local} --\Status{Implemented} --} -- --%\numtest{26}{ --%\Reason{Can't do ``get'' operation before calling init.} --%\Status{Implemented} --%} -- --%\numtest{27}{ --%\Reason{Can't do ``add'' operation before calling init.} --%\Status{Implemented} --%} -- --%\numtest{28}{ --%\Reason{Can't do ``modify'' operation before calling init.} --%\Status{Implemented} --%} -- --%\numtest{29}{ --%\Reason{Can't do ``delete'' operation before calling init.} --%\Status{Implemented} --%} -- --\numtest{30}{ --\Reason{Can init after failed init attempt.} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{31}{ --\Priority{High} --\Reason{Return BAD_STRUCT_VERSION when the mask bits are set to invalid values} --\Status{Implemented} --} -- --\numtest{32}{ --\Priority{High} --\Reason{Return BAD_STRUCT_VERSION when the mask bits are not set} --\Status{Implemented} --} -- --\numtest{33}{ --\Priority{High} --\Reason{Return OLD_STRUCT_VERSION when attempting to use an old/unsupported -- structure version} --\Status{Implemented} --} -- --\numtest{34}{ --\Priority{High} --\Reason{Return NEW_STRUCT_VERSION when attempting to use a newer version of -- of the structure then what is supported} --\Status{Implemented} --} -- --\numtest{35}{ --\Priority{High} --\Reason{Return BAD_API_VERSION when the mask bits are set to invalid values} --\Status{Implemented} --} -- --\numtest{36}{ --\Priority{High} --\Reason{Return BAD_API_VERSION when the mask bits are not set} --\Status{Implemented} --} -- --\numtest{37}{ --\Priority{High} --\Reason{Return OLD_LIB_API_VERSION when using an old/unsuppored -- api version number} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{38}{ --\Priority{High} --\Reason{Return OLD_SERVER_API_VERSION attempting to use an -- old/unsupported api version number} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{39}{ --\Priority{High} --\Reason{Return NEW_LIB_API_VERSION when using a newer api -- version number then supported} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{40}{ --\Priority{High} --\Reason{Return NEW_SERVER_API_VERSION when using a newer api version -- number then supported} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{41}{ --\Priority{High} --\Reason{Return BAD_XXX_VERSION when the API and the structure -- version numbers are reversed} --\Status{Implemented} --} -- --\numtest{42}{ --\Priority{High} --\Reason{Succeeds when using valid api and struct version numbers and masks} --\Status{Implemented} --} -- --\numtest{43}{ --\Priority{Low} --\Reason{Returns two different server handle when called twice with same info} --} -- --\numtest{44}{ --\Priority{Low} --\Reason{Returns two different server handles when called twice with -- different info} --} -- --\numtest{45}{ --\Priority{Bug fix, secure-install/3390} --\Reason{Returns SECURE_PRINC_MISSING when ADMIN_SERVICE does not --exist.} --\Status{Implemented} --} -- --\numtest{46}{ --\Priority{Bug fix, secure-install/3390} --\Reason{Returns SECURE_PRINC_MISSING when CHANGEPW_SERVICE does not --exist.} --\Status{Implemented} --} -- --\numtest{100}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the profile field of the configuration parameters, if --set.} --\Status{Implemented} --} -- --\numtest{101}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the kadmind_port field of the configuration parameters, --if set.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{102}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the admin_server field of the configuration parameters, --if set with only an admin server name.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{102.5}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the admin_server field of the configuration parameters, --if set with a host name and port number.} --\Conditions{RPC} --} -- --\numtest{103}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the dbname field of the configuration parameters, if --set.} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{104}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the admin_dbname field of the configuration parameters, if --set.} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{105}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the admin_lockfile field of the configuration parameters, if --set.} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{106}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the mkey_from_kbd field of the configuration parameters, if --set.} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{107}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the stash_file field of the configuration parameters, if --set.} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{108}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the mkey_name field of the configuration parameters, if --set.} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{109}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the max_life field of the configuration parameters, if --set.} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{110}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the max_rlife field of the configuration parameters, if --set.} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{111}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the expiration field of the configuration parameters, if --set.} --\Status{Implemented} --\Conditions{local} --} -- --\numtest{112}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the flags field of the configuration parameters, if --set.} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{113}{ --\Version{KADM5_API_VERSION_2} --\Reason{Obeys the keysalts and num_keysalts field of the configuration --parameters, if set.} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{114}{ --\Version{KADM5_API_VERSION_2} --\Reason{Returns KADM5_BAD_SERVER_PARAMS if any client-only parameters --are specified to server-side init.} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{115}{ --\Version{KADM5_API_VERSION_2} --\Reason{Returns KADM5_BAD_CLIENT_PARAMS if any client-only parameters --are specified to server-side init.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{116}{ --\Version{KADM5_API_VERSION_2} --\Reason{Two calls to init with clients having different privileges --succeeds, and both clients maintain their correct privileges.} --\Priority{Bug fix} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{117}{ --\Version{KADM5_API_VERSION_2} --\Reason{The max_life field defaults to value specified in the API --Functional Specification when kdc.conf is unreadable.} --\Priority{Bug fix, krb5-admin/18} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{150}{ --\Version{KADM5_API_VERSION_2} --\Reason{init_with_creds works when given an open ccache with a valid --credential for ADMIN_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{151}{ --\Version{KADM5_API_VERSION_2} --\Reason{init_with_creds works when given an open ccache with a valid --credential for CHANGEPW_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{152}{ --\Version{KADM5_API_VERSION_2} --\Reason{init_with_creds fails with KRB5_FCC_NOFILE (was -- KADM5_GSS_ERROR) when given an open --ccache with no credentials.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{153}{ --\Version{KADM5_API_VERSION_2} --\Reason{init_with_creds fails with KRB5_CC_NOTFOUND (was -- KADM5_GSS_ERROR) when given an open --ccache without credentials for ADMIN_SERVICE or CHANGEPW_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{154}{ --\Version{KADM5_API_VERSION_2} --\Reason{If the KRB5_KDC_PROFILE environment variable is set to a filename --that does not exist, init fails with ENOENT.} --\Conditions{RPC} --\Status{Implemented} --} -- --\section{ovsec_kadm_destroy} -- --\numtest{1}{ --\Reason{Valid invocation.} --\Status{Implemented} --} -- --%\numtest{2}{ --%\Reason{Valid invocation (``get'' not allowed after destroy).} --%\Status{Implemented} --%} -- --%\numtest{3}{ --%\Reason{Valid invocation (``add'' not allowed after destroy).} --%\Status{Implemented} --%} -- --%\numtest{4}{ --%\Reason{Valid invocation (``modify'' not allowed after destroy).} --%\Status{Implemented} --%} -- --%\numtest{5}{ --%\Reason{Valid invocation (``delete'' not allowed after destroy).} --%\Status{Implemented} --%} -- --%\numtest{6}{ --%\Reason{Fails if database not initialized.} --%\Status{Implemented} --%} -- --%\numtest{7}{ --%\Reason{Fails if invoked twice in a row.} --%\Status{Implemented} --%} -- --\numtest{8}{ --\Reason{Database can be reinitialized after destroy.} --\Status{Implemented} --} -- --\numtest{9}{ --\Priority{High} --\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} --\Status{Implemented} --} -- --\numtest{10}{ --\Priority{Low} --\Reason{Connects to correct server when multiple handles exist} --\Conditions{client} --} -- --\section{ovsec_kadm_create_principal} -- --%In the tests below, ``getu'' refers to a user who has only ``get'' access, --%''addu'' refers to a user who has only ``add'' access, ``modifyu'' refers to --%a user who has only ``modify'' access, and ``deleteu'' refers to a user --%who has only ``delete'' access. ``amu'' refers to a user with ``add'' and --%''modify'' access. ``new_princ'' refers to a principal entry structure --%filled in as follows: --% --% krb5_parse_name("newuser", \&new_princ.principal); --% krb5_timeofday(\&new_princ.princ_expire_time); --% new_princ.princ_expire_time += 130; --% krb5_timeofday(\&new_princ.last_pwd_change); --% new_princ.last_pwd_change += 140; --% krb5_timeofday(\&new_princ.pw_expiration); --% new_princ.pw_expiration += 150; --% new_princ.max_life = 160; --% krb5_parse_name("usera", \&new_princ.mod_name); --% krb5_timeofday(\&new_princ.mod_date); --% new_princ.mod_date += 170; --% new_princ.attributes = 0xabcdabcd; --% new_princ.kvno = 180; --% new_princ.mkvno = 190; --% new_princ.policy = null; --% new_princ.aux_attributes = 0xdeadbeef; --% --%The offsets of 130 through 190 above are used to ensure that the --%fields are all known to be different from each other, so that --%accidentally switched fields can be detected. Some of the fields in --%this structure may be changed by the tests, but they should clean up --%after themselves. -- --%\numtest{1}{ --%\Reason{Fails if database not initialized.} --%\Status{Implemented} --%} -- --\numtest{2}{ --\Reason{Fails on null princ argument.} --\Status{Implemented} --} -- --\numtest{3}{ --\Reason{Fails on null password argument.} --\Status{Implemented} --} -- --\numtest{4}{ --\Reason{Fails on empty-string password argument.} --\Status{Implemented} --} -- --\numtest{5}{ --\Reason{Fails when mask contains undefined bit.} --\Status{Implemented} --} -- --\numtest{6}{ --\Reason{Fails when mask contains LAST_PWD_CHANGE bit.} --\Status{Implemented} --} -- --\numtest{7}{ --\Reason{Fails when mask contains MOD_TIME bit.} --\Status{Implemented} --} -- --\numtest{8}{ --\Reason{Fails when mask contains MOD_NAME bit.} --\Status{Implemented} --} -- --\numtest{9}{ --\Reason{Fails when mask contains MKVNO bit.} --\Status{Implemented} --} -- --\numtest{10}{ --\Reason{Fails when mask contains AUX_ATTRIBUTES bit.} --\Status{Implemented} --} -- --\numtest{11}{ --\Reason{Fails when mask contains POLICY_CLR bit.} --\Status{Implemented} --} -- --\numtest{12}{ --\Reason{Fails for caller with no access bits.} --\Status{Implemented} --} -- --\numtest{13}{ --\Reason{Fails when caller has ``get'' access and not ``add''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{14}{ --\Reason{Fails when caller has ``modify'' access and not ``add''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{15}{ --\Reason{Fails when caller has ``delete'' access and not ``add''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{16}{ --\Reason{Fails when caller connected with CHANGEPW_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{17}{ --\Reason{Fails on attempt to create existing principal.} --\Status{Implemented} --} -- --\numtest{18}{ --\Reason{Fails when password is too short.} --\Status{Implemented} --} -- --\numtest{19}{ --\Reason{Fails when password has too few classes.} --\Status{Implemented} --} -- --\numtest{20}{ --\Reason{Fails when password is in dictionary.} --\Status{Implemented} --} -- --\numtest{21}{ --\Reason{Nonexistent policy is rejected.} --\Status{Implemented} --} -- --\numtest{22}{ --\Reason{Fails on invalid principal name.} --\Status{Implemented} --} -- --\numtest{23}{ --\Reason{Valid invocation.} --\Status{Implemented} --} -- --\numtest{24}{ --\Reason{Succeeds when caller has ``add'' access and another one.} --\Status{Implemented} --} -- --%\numtest{25}{ --%\Reason{Fails when password is too short, when override_qual is true.} --%} -- --%\numtest{26}{ --%\Reason{Fails when password has too few classes, when --% override_qual is true.} --%} -- --%\numtest{27}{ --%\Reason{Fails when password is in dictionary, when override_qual is --% true.} --%} -- --\numtest{28}{ --\Reason{Succeeds when assigning policy.} --\Status{Implemented} --} -- --\numtest{29}{ --\Priority{High} --\Reason{Allows 0 (never) for princ_expire_time.} --\Status{Implemented} --} -- --\numtest{30}{ --\Reason{Allows 0 (never) for pw_expiration when there's no policy.} --\Status{Implemented} --} -- --\numtest{31}{ --\Reason{Allows 0 (never) for pw_expiration when there's a policy with -- 0 for pw_max_life.} --\Status{Implemented} --} -- --\numtest{32}{ --\Reason{Accepts 0 (never) for pw_expiration when there's a policy with -- non-zero pw_max_life, and sets pw_expiration to zero.} --\Status{Implemented} --} -- --\numtest{33}{ --\Reason{Accepts and sets non-zero pw_expiration when no policy.} --\Status{Implemented} --} -- --\numtest{34}{ --\Reason{Accepts and sets non-zero pw_expiration when there's a policy -- with zero pw_max_life.} --\Status{Implemented} --} -- --\numtest{35}{ --\Reason{Accepts and sets non-zero pw_expiration when there's a policy -- with pw_max_life later than the specified pw_expiration.} --\Status{Implemented} --} -- --\numtest{36}{ --\Reason{Accepts and sets non-zero pw_expiration greater than now_pw_max_life.} --\Status{Implemented} --} -- --\numtest{37}{ --\Priority{High} --\Reason{Sets pw_expiration to 0 (never) if there's no policy and no -- specified pw_expiration.} --\Status{Implemented} --} -- --\numtest{38}{ --\Priority{High} --\Reason{Sets pw_expiration to 0 (never) if it isn't specified and the -- policy has a 0 (never) pw_max_life.} --\Status{Implemented} --} -- --\numtest{39}{ --\Priority{High} --\Reason{Sets pw_expiration to now + pw_max_life if it isn't specified -- and the policy has a non-zero pw_max_life.} --\Status{Implemented} --} -- --\numtest{40}{ --\Priority{High} --\Reason{Allows 0 (forever) for max_life.} --\Status{Implemented} --} -- --\numtest{41}{ --\Priority{High} --\Reason{Doesn't modify or free mod_name on success.} --} -- --\numtest{42}{ --\Priority{High} --\Reason{Doesn't modify or free mod_name on failure.} --} -- --\numtest{43}{ --\Priority{High} --\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} --\Status{Implemented} --} -- --\numtest{44}{ --\Priority{Low} --\Reason{Connects to correct server when multiple handles exist} --\Conditions{RPC} --} -- -- --\section{ovsec_kadm_delete_principal} -- --%\numtest{1}{ --%\Reason{Fails if database not initialized.} --%\Status{Implemented} --%} -- --\numtest{2}{ --\Reason{Fails on null principal.} --\Status{Implemented} --} -- --% Empty string principal is legal. --%\numtest{3}{ --%\Reason{Fails on empty-string principal.} --%} -- --% There is not invalid principal names --%\numtest{4}{ --%\Reason{Fails on invalid principal name.} --%} -- --\numtest{5}{ --\Priority{High} --\Reason{Fails on nonexistent principal.} --\Status{Implemented} --} -- --\numtest{6}{ --\Priority{High} --\Reason{Fails when caller connected with CHANGEPW_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{7}{ --\Priority{High} --\Reason{Fails if caller has ``add'' access and not ``delete''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{8}{ --\Priority{High} --\Reason{Fails if caller has ``modify'' access and not ``delete''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{9}{ --\Priority{High} --\Reason{Fails if caller has ``get'' access and not ``delete''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{10}{ --\Priority{High} --\Reason{Fails if caller has no access bits.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{11}{ --\Priority{High} --\Reason{Valid invocation.} --\Status{Implemented} --} -- --\numtest{12}{ --\Priority{High} --\Reason{Valid invocation (on principal with policy).} --\Status{Implemented} --} -- --\numtest{13}{ --\Priority{High} --\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} --\Status{Implemented} --} -- --\numtest{14}{ --\Priority{Low} --\Reason{Connects to correct server when multiple handles exist} --\Conditions{RPC} --} -- -- --\section{ovsec_kadm_modify_principal} -- --%\numtest{1}{ --%\Reason{Fails if database not initialized.} --%\Status{Implemented} --%} -- --\numtest{2}{ --\Priority{High} --\Reason{Fails if user connected with CHANGEPW_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{3}{ --\Reason{Fails on mask with undefined bit set.} --\Status{Implemented} --} -- --\numtest{4}{ --\Reason{Fails on mask with PRINCIPAL set.} --\Status{Implemented} --} -- --\numtest{5}{ --\Priority{High} --\Reason{Fails on mask with LAST_PWD_CHANGE set.} --\Status{Implemented} --} -- --\numtest{6}{ --\Reason{Fails on mask with MOD_TIME set.} --\Status{Implemented} --} -- --\numtest{7}{ --\Reason{Fails on mask with MOD_NAME set.} --\Status{Implemented} --} -- --\numtest{8}{ --\Reason{Fails on mask with MKVNO set.} --\Status{Implemented} --} -- --\numtest{9}{ --\Priority{High} --\Reason{Fails on mask with AUX_ATTRIBUTES set.} --\Status{Implemented} --} -- --\numtest{10}{ --\Reason{Fails on nonexistent principal.} --\Status{Implemented} --} -- --\numtest{11}{ --\Priority{High} --\Reason{Fails for user with no access bits.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{12}{ --\Priority{High} --\Reason{Fails for user with ``get'' access.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{13}{ --\Priority{High} --\Reason{Fails for user with ``add'' access.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{14}{ --\Priority{High} --\Reason{Fails for user with ``delete'' access.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{15}{ --\Priority{High} --\Reason{Succeeds for user with ``modify'' access.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{16}{ --\Reason{Succeeds for user with ``modify'' and another access.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{17}{ --\Priority{High} --\Reason{Fails when nonexistent policy is specified.} --\Status{Implemented} --} -- --\numtest{18}{ --\Priority{High} --\Reason{Succeeds when existent policy is specified.} --\Status{Implemented} --} -- --\numtest{19}{ --\Reason{Updates policy count when setting policy from none.} --\Status{Implemented} --} -- --\numtest{20}{ --\Reason{Updates policy count when clearing policy from set.} --\Status{Implemented} --} -- --\numtest{21}{ --\Reason{Updates policy count when setting policy from other policy.} --\Status{Implemented} --} -- --\numtest{21.5}{ --\Reason{Policy reference count remains unchanged when policy is -- changed to itself.} --\Status{Implemented.} --} -- --\numtest{22}{ --\Reason{Allows 0 (never) for pw_expiration when there's no policy.} --\Status{Implemented} --} -- --\numtest{23}{ --\Reason{Allows 0 (never) for pw_expiration when there's a policy with -- 0 for pw_max_life.} --\Status{Implemented} --} -- --\numtest{24}{ --\Reason{Accepts 0 (never) for pw_expiration when there's a policy with -- non-zero pw_max_life, but actually sets pw_expiration to -- last_pwd_change + pw_max_life.} --\Status{Implemented} --} -- --\numtest{25}{ --\Reason{Accepts and sets non-zero pw_expiration when no policy.} --\Status{Implemented} --} -- --\numtest{26}{ --\Reason{Accepts and sets non-zero pw_expiration when there's a policy -- with zero pw_max_life.} --\Status{Implemented} --} -- --\numtest{27}{ --\Reason{Accepts and sets non-zero pw_expiration when there's a policy -- with pw_max_life later than the specified pw_expiration.} --\Status{Implemented} --} -- --\numtest{28}{ --\Reason{Accepts non-zero pw_expiration and limits it to last_pwd_change + -- pw_max_life when it's later than last_pwd_change + non-zero -- pw_max_life in policy.} --\Status{Implemented} --} -- --\numtest{29}{ --\Priority{High} --\Reason{Sets pw_expiration to 0 (never) when a policy is cleared and --no pw_expiration is specified.} --\Status{Implemented} --} -- --\numtest{30}{ --\Priority{High} --\Reason{Sets pw_expiration to 0 (never) if it isn't specified and the -- new policy has a 0 (never) pw_max_life.} --\Status{Implemented} --} -- --\numtest{31}{ --\Priority{High} --\Reason{Sets pw_expiration to now + pw_max_life if it isn't specified -- and the new policy has a non-zero pw_max_life.} --\Status{Implemented} --} -- --\numtest{32}{ --\Priority{High} --\Reason{Accepts princ_expire_time change.} --\Status{Implemented} --} -- -- -- --\numtest{33}{ --\Priority{High} --\Reason{Accepts attributes change.} --\Status{Implemented} --} -- --\numtest{33.25}{ --\Priority{High} --\Reason{Accepts attributes change (KRB5_KDB_REQUIRES_PW_CHANGE).} --\Status{Implemented} --} -- --\numtest{33.5}{ --\Priority{High} --\Reason{Accepts attributes change (KRB5_DISALLOW_TGT_BASE).} --\Status{Implemented} --} -- --\numtest{33.75}{ --\Priority{High} --\Reason{Accepts attributes change (KRB5_PW_CHANGE_SERVICE).} --\Status{Implemented} --} -- --\numtest{34}{ --\Priority{High} --\Reason{Accepts max_life change.} --\Status{Implemented} --} -- --\numtest{35}{ --\Priority{High} --\Reason{Accepts kvno change.} --\Status{Implemented} --} -- --\numtest{36}{ --\Reason{Behaves correctly when policy is set to the same as it was -- before.} --\Status{Implemented} --} -- --\numtest{37}{ --\Reason{Behaves properly when POLICY_CLR is specified and there was no -- policy before.} --\Status{Implemented} --} -- --\numtest{38}{ --\Priority{High} --\Reason{Accepts 0 (never) for princ_expire_time.} --\Status{Implemented} --} -- --\numtest{39}{ --\Priority{High} --\Reason{Accepts 0 for max_life.} --\Status{Implemented} --} -- --\numtest{40}{ --\Reason{Rejects null principal argument.} --\Status{Implemented} --} -- --\numtest{41}{ --\Priority{High} --\Reason{Doesn't modify or free mod_name on success.} --} -- --\numtest{42}{ --\Priority{High} --\Reason{Doesn't modify or free mod_name on failure.} --} -- --\numtest{43}{ --\Priority{High} --\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} --\Status{Implemented} --} -- --\numtest{44}{ --\Priority{Low} --\Reason{Connects to correct server when multiple handles exist} --\Conditions{RPC} --} -- --\numtest{100}{ --\Version{KADM5_API_VERSION_2} --\Priority{bug-fix} --\Reason{Accepts max_rlife change.} --\Status{Implemented} --} -- --\numtest{101}{ --\Version{KADM5_API_VERSION_2} --\Reason{Rejects last_success change.} --\Status{Implemented} --} -- --\numtest{102}{ --\Version{KADM5_API_VERSION_2} --\Reason{Rejects last_failed change.} --\Status{Implemented} --} -- --\numtest{103}{ --\Version{KADM5_API_VERSION_2} --\Reason{Rejects fail_auth_count change.} --\Status{Implemented} --} -- --\numtest{103.5}{ --\Version{KADM5_API_VERSION_2} --\Reason{Rejects key_data change.} --\Status{Implemented} --} -- --\numtest{104}{ --\Version{KADM5_API_VERSION_2} --\Reason{Accepts tl_data change when all types are greater than 256.} --\Status{Implemented} --} -- --\numtest{105}{ --\Version{KADM5_API_VERSION_2} --\Reason{Returns KADM5_BAD_TL_TYPE when given tl_data with a type less --than 256.} --\Status{Implemented} --} -- --\section{ovsec_kadm_rename_principal} -- --%\numtest{1}{ --%\Reason{Fails if database not initialized.} --%\Status{Implemented} --%} -- --\numtest{2}{ --\Priority{High} --\Reason{Fails if user connected with CHANGEPW_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{3}{ --\Priority{High} --\Reason{Fails for user with no access bits.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{4}{ --\Reason{Fails for user with ``modify'' access and not ``add'' or --``delete''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{5}{ --\Reason{Fails for user with ``get'' access and not ``add'' or --``delete''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{6}{ --\Reason{Fails for user with ``modify'' and ``add'' but not ``delete''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{7}{ --\Reason{Fails for user with ``modify'' and ``delete'' but not ``add''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{8}{ --\Reason{Fails for user with ``get'' and ``add'' but not ``delete''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{9}{ --\Reason{Fails for user with ``get'' and ``delete'' but not ``add.''} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{10}{ --\Reason{Fails for user with ``modify'', ``get'' and ``add'', but not -- ``delete''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{11}{ --\Reason{Fails for user with ``modify'', ``get'' and ``delete'', but -- not ``add''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{12}{ --\Priority{High} --\Reason{Fails for user with ``add'' but not ``delete''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{13}{ --\Priority{High} --\Reason{Fails for user with ``delete'' but not ``add''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{14}{ --\Priority{High} --\Reason{Succeeds for user with ``add'' and ``delete'', when that user --has non-name-based salt.} --\Status{Implemented} --} -- --\numtest{15}{ --\Priority{High} --\Reason{Fails if target principal name exists.} --\Status{Implemented} --} -- --\numtest{16}{ --\Priority{High} --\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} --\Status{Implemented} --} -- --\numtest{17}{ --\Priority{Low} --\Reason{Connects to correct server when multiple handles exist} --\Conditions{RPC} --} -- --\numtest{18}{ --\Priority{bug fix} --\Reason{Returns NO_RENAME_SALT when asked to rename a principal whose --salt depends on the principal name.} --\Status{Implemented} --} -- --\section{ovsec_kadm_chpass_principal} --\label{ovseckadmchpassprincipal} -- --\subsection{Quality/history enforcement tests} -- --This section lists a series of tests which will be run a number of --times, with various parameter settings (e.g., which access bits user --has, whether user connected with ADMIN_SERVICE or CHANGEPW_SERVICE, --etc.). The table following the --list of tests gives the various parameter settings under which the --tests should be run, as well which should succeed and which should --fail for each choice of parameter settings. -- --\subsubsection{List of tests} -- --The test number of each of these tests is an offset from the base --given in the table below. -- --\numtest{1}{ --\Priority{High} --\Reason{With history setting of 1, change password to itself.} --} -- --\numtest{2}{ --\Reason{With history setting of 2 but no password changes since -- principal creation, change password to itself.} --} -- --\numtest{3}{ --\Reason{With history setting of 2 and one password change since -- principal creation, change password to itself -- and directly previous password.} --} -- --\numtest{4}{ --\Priority{High} --\Reason{With a history setting of 3 and no password changes, -- change password to itself.} --} -- --\numtest{5}{ --\Priority{High} --\Reason{With a history setting of 3 and 1 password change, -- change password to itself or previous password.} --} -- --\numtest{6}{ --\Priority{High} --\Reason{With a history setting of 3 and 2 password changes, -- change password to itself and the two previous passwords.} --} -- --\numtest{7}{ --\Priority{High} --\Reason{Change to previously unused password when now - -- last_pwd_change $<$ pw_min_life.} --} -- --\numtest{8}{ --\Priority{High} --\Reason{Change to previously unused password that doesn't contain enough -- character classes.} --} -- --\numtest{9}{ --\Priority{High} --\Reason{Change to previously unused password that's too short.} --} -- --\numtest{10}{ --\Priority{High} --\Reason{Change to previously unused password that's in the dictionary.} --} -- --\subsubsection{List of parameter settings} -- --In the table below, ``7 passes'' means that test 7 above passes and --the rest of the tests fail. -- --\begin{tabular}{llllll} --Base & Modify access? & Own password? & Service & Pass/Fail \\ \hline --0 & No & Yes & ADMIN & all fail \\ --20 & No & Yes & CHANGEPW & all fail \\ --40 & No & No & ADMIN & all fail \\ --60 & No & No & CHANGEPW & all fail \\ --80 & Yes & Yes & ADMIN & 7 passes \\ --100 & Yes & Yes & CHANGEPW & all fail \\ --120 & Yes & No & ADMIN & 7 passes \\ --140 & Yes & No & CHANGEPW & all fail \\ --\end{tabular} -- --\subsection{Other quality/history tests} -- --\numtest{161}{ --\Priority{High} --\Reason{With history of 1, can change password to anything other than -- itself that doesn't conflict with other quality -- rules.} --} -- --\numtest{162}{ --\Reason{With history of 2 and 2 password changes, can change password -- to original password.} --} -- --\numtest{163}{ --\Priority{High} --\Reason{With history of 3 and 3 password changes, can change password -- to original password.} --} -- --\numtest{164}{ --\Priority{High} --\Reason{Can change password when now - last_pwd_change $>$ pw_min_life.} --} -- --\numtest{165}{ --\Priority{High} --\Reason{Can change password when it contains exactly the number of -- classes required by the policy.} --} -- --\numtest{166}{ --\Priority{High} --\Reason{Can change password when it is exactly the length required by -- the policy.} --} -- --\numtest{167}{ --\Priority{High} --\Reason{Can change password to a word that isn't in the dictionary.} --} -- -- --\subsection{Other tests} -- --%\numtest{168}{ --%\Reason{Fails if database not initialized.} --%} -- --\numtest{169}{ --\Reason{Fails for non-existent principal.} --} -- --\numtest{170}{ --\Reason{Fails for null password.} --} -- --\numtest{171}{ --\Priority{High} --\Reason{Fails for empty-string password.} --} -- --\numtest{172}{ --\Priority{High} --\Reason{Pw_expiration is set to now + max_pw_life if policy exists and -- has non-zero max_pw_life.} --} -- --\numtest{173}{ --\Priority{High} --\Reason{Pw_expiration is set to 0 if policy exists and has zero -- max_pw_life.} --} -- --\numtest{174}{ --\Priority{High} --\Reason{Pw_expiration is set to 0 if no policy.} --} -- --\numtest{175}{ --\Priority{High} --\Reason{KRB5_KDC_REQUIRES_PWCHANGE bit is cleared when password is -- successfully changed.} --} -- --\numtest{176}{ --\Priority{High} --\Reason{Fails for user with no access bits, on other's password.} --} -- --\numtest{177}{ --\Priority{High} --\Reason{Fails for user with ``get'' but not ``modify'' access, on -- other's password.} --} -- --\numtest{178}{ --\Reason{Fails for user with ``delete'' but not ``modify'' access, on -- other's password.} --} -- --\numtest{179}{ --\Reason{Fails for user with ``add'' but not ``modify'' access, on -- other's password.} --} -- --\numtest{180}{ --\Reason{Succeeds for user with ``get'' and ``modify'' access, on -- other's password.} --\Status{Implemented} --} -- --\numtest{180.5}{ --\Priority{High} --\Reason{Succeeds for user with ``modify'' but not ``get'' access, on -- other's password.} --\Conditions{RPC} --\Status{Implemented} --} --\numtest{180.625}{ --\Priority{High} --\Reason{Fails for user with modify when connecting with CHANGEPW_SERVICE on -- others password} --\Conditions{RPC} --\Status{Implemented} --} --\numtest{180.75}{ --\Priority{High} --\Reason{Fails for user with modify when connecting with CHANGEPW_SERVICE -- on other's password which has expired} --\Conditions{RPC} --\Status{Implemented} --} -- --%\numtest{181}{ --%\Reason{Password that would succeed if override_qual were false fails --% if override_qual is true.} --%\Expected{Returns CANNOT_OVERRIDE.} --%} -- --\numtest{182}{ --\Priority{High} --\Reason{Can not change key of ovsec_adm/history principal.} --\Status{Implemented} --} -- --\numtest{183}{ --\Priority{High} --\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} --\Status{Implemented} --} -- --\numtest{184}{ --\Priority{Low} --\Reason{Connects to correct server when multiple handles exist} --\Conditions{RPC} --} -- --\numtest{200}{ --\Version{KADM5_API_VERSION_2} --\Reason{Creates a key for the principal for each unique encryption --type/salt type in use.} --\Status{Implemented} --} -- --\section{ovsec_kadm_chpass_principal_util} -- --Rerun all the tests listed for ovsec_kadm_chpass_principal above in --Section \ref{ovseckadmchpassprincipal}. Verify that they succeed --and fail in the same circumstances. Also verify that in each failure --case, the error message returned in msg_ret is as specified in the --functional specification. -- --Also, run the following additional tests. -- --\numtest{1}{ --\Reason{Null msg_ret is rejected.} --} -- --\numtest{2}{ --\Priority{High} --\Reason{New password is put into pw_ret, when it's prompted for.} --} -- --\numtest{3}{ --\Priority{High} --Reason{New password is put into pw_ret, when it's supplied by the -- caller.} --} -- --\numtest{4}{ --\Priority{High} --\Reason{Successful invocation when pw_ret is null.} --} -- -- -- --\section{ovsec_kadm_randkey_principal} -- --\subsection{TOOSOON enforcement tests} -- --This test should be run a number of times, as indicated in the table --following it. The table also indicates the expected result of each --run of the test. -- --\test{ --\Reason{Change key when now - last_pwd_change $<$ pw_min_life.} --} -- --\subsubsection{List of parameter settings} -- --\begin{tabular}{llllll} --Number & Modify Access? & Own Key? & Service & Pass/Fail & Implemented? \\ \hline --1 & No & Yes & ADMIN & fail & Yes \\ --3 & No & Yes & CHANGEPW & fail & Yes \\ --5 & No & No & ADMIN & fail \\ --7 & No & No & CHANGEPW & fail \\ --9 & Yes & Yes & ADMIN & pass \\ --11 & Yes & Yes & CHANGEPW & fail \\ --13 & Yes & No & ADMIN & pass & Yes \\ --15 & Yes & No & CHANGEPW & fail & Yes \\ --\end{tabular} -- --\subsection{Other tests} -- --\numtest{17}{ --\Reason{Fails if database not initialized.} --} -- --\numtest{18}{ --\Reason{Fails for non-existent principal.} --} -- --\numtest{19}{ --\Reason{Fails for null keyblock pointer.} --} -- --\numtest{20}{ --\Priority{High} --\Reason{Pw_expiration is set to now + max_pw_life if policy exists and -- has non-zero max_pw_life.} --} -- --\numtest{21}{ --\Priority{High} --\Reason{Pw_expiration is set to 0 if policy exists and has zero -- max_pw_life.} --} -- --\numtest{22}{ --\Priority{High} --\Reason{Pw_expiration is set to 0 if no policy.} --} -- --\numtest{23}{ --\Priority{High} --\Reason{KRB5_KDC_REQUIRES_PWCHANGE bit is cleared when key is -- successfully changed.} --} -- --\numtest{24}{ --\Priority{High} --\Reason{Fails for user with no access bits, on other's password.} --} -- --\numtest{25}{ --\Priority{High} --\Reason{Fails for user with ``get'' but not ``modify'' access, on -- other's password.} --\Vtwonote{Change-password instead of modify access.} --} -- --\numtest{26}{ --\Reason{Fails for user with ``delete'' but not ``modify'' access, on -- other's password.} --\Vtwonote{Change-password instead of modify access.} --} -- --\numtest{27}{ --\Reason{Fails for user with ``add'' but not ``modify'' access, on -- other's password.} --\Vtwonote{Change-password instead of modify access.} --} -- --\numtest{28}{ --\Reason{Succeeds for user with ``get'' and ``modify'' access, on -- other's password.} --\Status{Implemented} --\Vtwonote{Change-password instead of modify access.} --} -- --\numtest{28.25}{ --\Priority{High} --\Reason{Fails for user with get and modify access on others password -- When conneceted with CHANGEPW_SERVICE} --\Status{Implemented} --\Vtwonote{Change-password instead of modify access.} --} -- --\numtest{28.5}{ --\Priority{High} --\Reason{Succeeds for user with ``modify'' but not ``get'' access, on -- other's password.} --\Status{Implemented} --\Vtwonote{Change-password instead of modify access.} --} -- --\numtest{29}{ --\Reason{The new key that's assigned is truly random. XXX not sure how -- to test this.} --} -- --\numtest{30}{ --\Reason{Succeeds for own key, no other access bits when connecting with CHANGEPW service} --\Status{Implemented} --} --\numtest{31}{ --\Reason{Succeeds for own key, no other access bits when connecting with ADMIM service} --\Status{Implemented} --} -- --\numtest{32}{ --\Reason{Cannot change ovsec_adm/history key} --\Status{Implemented} --} -- --\numtest{33}{ --\Priority{High} --\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} --\Status{Implemented} --} -- --\numtest{34}{ --\Priority{Low} --\Reason{Connects to correct server when multiple handles exist} --\Conditions{RPC} --} -- --\numtest{100}{ --\Version{KADM5_API_VERSION_2} --\Reason{Returns a key for each unique encryption type specified in the --keysalts.} --} -- --\section{ovsec_kadm_get_principal} -- --\numtest{1}{ --\Reason{Fails for null ent.} --\Status{Implemented} --} -- --\numtest{2}{ --\Reason{Fails for non-existent principal.} --\Status{Implemented} --} -- --\numtest{3}{ --\Priority{High} --\Reason{Fails for user with no access bits, retrieving other principal.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{4}{ --\Priority{High} --\Reason{Fails for user with ``add'' but not ``get'', getting principal -- other than his own, using ADMIN_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{5}{ --\Reason{Fails for user with ``modify'' but not ``get'', getting -- principal other than his own, using ADMIN_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{6}{ --\Reason{Fails for user with ``delete'' but not ``get'', getting -- principal other than his own, using ADMIN_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{7}{ --\Reason{Fails for user with ``delete'' but not ``get'', getting -- principal other than his own, using CHANGEPW_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{8}{ --\Priority{High} --\Reason{Fails for user with ``get'', getting principal other than his -- own, using CHANGEPW_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{9}{ --\Priority{High} --\Reason{Succeeds for user without ``get'', retrieving self, using -- ADMIN_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{10}{ --\Reason{Succeeds for user without ``get'', retrieving self, using -- CHANGEPW_SERVICE.} --\Status{Implemented} --} -- --\numtest{11}{ --\Reason{Succeeds for user with ``get'', retrieving self, using -- ADMIN_SERVICE.} --\Status{Implemented} --} -- --\numtest{12}{ --\Reason{Succeeds for user with ``get'', retrieving self, using -- CHANGEPW_SERVICE.} --\Status{Implemented} --} -- --\numtest{13}{ --\Priority{High} --\Reason{Succeeds for user with ``get'', retrieving other user, using -- ADMIN_SERVICE.} --\Status{Implemented} --} -- --\numtest{14}{ --\Reason{Succeeds for user with ``get'' and ``modify'', retrieving -- other principal, using ADMIN_SERVICE.} --\Status{Implemented} --} -- --\numtest{15}{ --\Priority{High} --\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} --\Status{Implemented} --} -- --\numtest{16}{ --\Priority{Low} --\Reason{Connects to correct server when multiple handles exist} --\Conditions{RPC} --} -- --\numtest{100}{ --\Version{KADM5_API_VERSION_2} --\Reason{If KADM5_PRINCIPAL_NORMAL_MASK is specified, the key_data and --tl_data fields are NULL/zero.} --\Status{Implemented} --} -- --\numtest{101}{ --\Version{KADM5_API_VERSION_2} --\Reason{If KADM5_KEY_DATA is specified, the key_data fields contain --data but the contents are all NULL.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{102}{ --\Version{KADM5_API_VERSION_2} --\Reason{If KADM5_KEY_DATA is specified, the key_data fields contain --data and the contents are all non-NULL.} --\Conditions{local} --\Status{Implemented} --} -- --\numtest{103}{ --\Version{KADM5_API_VERSION_2} --\Reason{If KADM5_TL_DATA is specified, the tl_data field contains the --correct tl_data and no entries whose type is less than 256.} --\Status{Implemented} --} -- -- --\section{ovsec_kadm_create_policy} -- --\numtest{1}{ --\Reason{Fails for mask with undefined bit set.} --\Status{Implemented - untested} --} -- --\numtest{2}{ --\Priority{High} --\Reason{Fails if caller connected with CHANGEPW_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{3}{ --\Reason{Fails for mask without POLICY bit set.} --\Status{Implemented - untested} --} -- --\numtest{4}{ --\Reason{Fails for mask with REF_COUNT bit set.} --\Status{Implemented} --} -- --\numtest{5}{ --\Reason{Fails for invalid policy name.} --\Status{Implemented - untested} --} -- --\numtest{6}{ --\Priority{High} --\Reason{Fails for existing policy name.} --\Status{Implemented} --} -- --\numtest{7}{ --\Reason{Fails for null policy name.} --\Status{Implemented - untested} --} -- --\numtest{8}{ --\Priority{High} --\Reason{Fails for empty-string policy name.} --\Status{Implemented} --} -- --\numtest{9}{ --\Priority{High} --\Reason{Accepts 0 for pw_min_life.} --\Status{Implemented} --} -- --\numtest{10}{ --\Priority{High} --\Reason{Accepts non-zero for pw_min_life.} --\Status{Implemented} --} -- --\numtest{11}{ --\Priority{High} --\Reason{Accepts 0 for pw_max_life.} --\Status{Implemented} --} -- --\numtest{12}{ --\Priority{High} --\Reason{Accepts non-zero for pw_max_life.} --\Status{Implemented} --} -- --\numtest{13}{ --\Priority{High} --\Reason{Rejects 0 for pw_min_length.} --\Status{Implemented} --} -- --\numtest{14}{ --\Priority{High} --\Reason{Accepts non-zero for pw_min_length.} --\Status{Implemented} --} -- --\numtest{15}{ --\Priority{High} --\Reason{Rejects 0 for pw_min_classes.} --\Status{Implemented} --} -- --\numtest{16}{ --\Priority{High} --\Reason{Accepts 1 for pw_min_classes.} --\Status{Implemented} --} -- --\numtest{17}{ --\Priority{High} --\Reason{Accepts 4 for pw_min_classes.} --\Status{Implemented} --} -- --\numtest{18}{ --\Priority{High} --\Reason{Rejects 5 for pw_min_classes.} --\Status{Implemented} --} -- --\numtest{19}{ --\Priority{High} --\Reason{Rejects 0 for pw_history_num.} --\Status{Implemented} --} -- --\numtest{20}{ --\Priority{High} --\Reason{Accepts 1 for pw_history_num.} --\Status{Implemented} --} -- --\numtest{21}{ --\Priority{High} --\Reason{Accepts 10 for pw_history_num.} --\Status{Implemented} --} -- --\numtest{21.5}{ --\Reason{Rejects 11 for pw_history_num.} --\Status{Implemented - untested} --} -- --\numtest{22}{ --\Priority{High} --\Reason{Fails for user with no access bits.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{23}{ --\Priority{High} --\Reason{Fails for user with ``get'' but not ``add''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{24}{ --\Reason{Fails for user with ``modify'' but not ``add.''} --\Conditions{RPC} --\Status{Implemented - untested} --} -- --\numtest{25}{ --\Reason{Fails for user with ``delete'' but not ``add.''} --\Conditions{RPC} --\Status{Implemented - untested} --} -- --\numtest{26}{ --\Priority{High} --\Reason{Succeeds for user with ``add.''} --\Status{Implemented} --} -- --\numtest{27}{ --\Reason{Succeeds for user with ``get'' and ``add.''} --\Status{Implemented - untested} --} -- --\numtest{28}{ --\Reason{Rejects null policy argument.} --\Status{Implemented - untested} --} -- --\numtest{29}{ --\Reason{Rejects pw_min_life greater than pw_max_life.} --} -- --\numtest{30}{ --\Priority{High} --\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} --\Status{Implemented} --} -- --\numtest{31}{ --\Priority{Low} --\Reason{Connects to correct server when multiple handles exist} --\Conditions{RPC} --} -- -- --\section{ovsec_kadm_delete_policy} -- --\numtest{1}{ --\Reason{Fails for null policy name.} --} -- --\numtest{2}{ --\Priority{High} --\Reason{Fails for empty-string policy name.} --\Status{Implemented} --} -- --\numtest{3}{ --\Reason{Fails for non-existent policy name.} --} -- --\numtest{4}{ --\Reason{Fails for bad policy name.} --} -- --\numtest{5}{ --\Priority{High} --\Reason{Fails if caller connected with CHANGEPW_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{6}{ --\Priority{High} --\Reason{Fails for user with no access bits.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{7}{ --\Priority{High} --\Reason{Fails for user with ``add'' but not ``delete''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{8}{ --\Reason{Fails for user with ``modify'' but not ``delete''.} --\Conditions{RPC} --} -- --\numtest{9}{ --\Reason{Fails for user with ``get'' but not ``delete.''} --\Conditions{RPC} --} -- --\numtest{10}{ --\Priority{High} --\Reason{Succeeds for user with only ``delete''.} --\Status{Implemented} --} -- --\numtest{11}{ --\Reason{Succeeds for user with ``delete'' and ``add''.} --} -- --\numtest{12}{ --\Priority{High} --\Reason{Fails for policy with non-zero reference count.} --\Status{Implemented} --} -- --\numtest{13}{ --\Priority{High} --\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} --\Status{Implemented} --} -- --\numtest{14}{ --\Priority{Low} --\Reason{Connects to correct server when multiple handles exist} --\Conditions{RPC} --} -- -- --\section{ovsec_kadm_modify_policy} -- --\numtest{1}{ --\Reason{Fails for mask with undefined bit set.} --\Conditions{RPC} --} -- --\numtest{2}{ --\Priority{High} --\Reason{Fails if caller connected with CHANGEPW_SERVICE.} --\Status{Implemented} --} -- --\numtest{3}{ --\Reason{Fails for mask with POLICY bit set.} --} -- --\numtest{4}{ --\Reason{Fails for mask with REF_COUNT bit set.} --\Status{Implemented} --} -- --\numtest{5}{ --\Reason{Fails for invalid policy name.} --} -- --\numtest{6}{ --\Reason{Fails for non-existent policy name.} --} -- --\numtest{7}{ --\Reason{Fails for null policy name.} --} -- --\numtest{8}{ --\Priority{High} --\Reason{Fails for empty-string policy name.} --\Status{Implemented} --} -- --\numtest{9}{ --\Priority{High} --\Reason{Accepts 0 for pw_min_life.} --\Status{Implemented} --} -- --\numtest{10}{ --\Priority{High} --\Reason{Accepts non-zero for pw_min_life.} --\Status{Implemented} --} -- --\numtest{11}{ --\Priority{High} --\Reason{Accepts 0 for pw_max_life.} --\Status{Implemented} --} -- --\numtest{12}{ --\Priority{High} --\Reason{Accepts non-zero for pw_max_life.} --\Status{Implemented} --} -- --\numtest{13}{ --\Priority{High} --\Reason{Accepts 0 for pw_min_length.} --\Status{Implemented} --} -- --\numtest{14}{ --\Priority{High} --\Reason{Accepts non-zero for pw_min_length.} --\Status{Implemented} --} -- --\numtest{15}{ --\Priority{High} --\Reason{Rejects 0 for pw_min_classes.} --\Status{Implemented} --} -- --\numtest{16}{ --\Priority{High} --\Reason{Accepts 1 for pw_min_classes.} --\Status{Implemented} --} -- --\numtest{17}{ --\Priority{High} --\Reason{Accepts 4 for pw_min_classes.} --\Status{Implemented} --} -- --\numtest{18}{ --\Priority{High} --\Reason{Rejects 5 for pw_min_classes.} --\Status{Implemented} --} -- --\numtest{19}{ --\Priority{High} --\Reason{Rejects 0 for pw_history_num.} --\Status{Implemented} --} -- --\numtest{20}{ --\Priority{High} --\Reason{Accepts 1 for pw_history_num.} --\Status{Implemented} --} -- --\numtest{21}{ --\Priority{High} --\Reason{Accepts 10 for pw_history_num.} --\Status{Implemented} --} -- --\numtest{22}{ --\Priority{High} --\Reason{Fails for user with no access bits.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{23}{ --\Priority{High} --\Reason{Fails for user with ``get'' but not ``modify''.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{24}{ --\Reason{Fails for user with ``add'' but not ``modify.''} --\Conditions{RPC} --} -- --\numtest{25}{ --\Reason{Fails for user with ``delete'' but not ``modify.''} --\Conditions{RPC} --} -- --\numtest{26}{ --\Priority{High} --\Reason{Succeeds for user with ``modify.''} --\Status{Implemented} --} -- --\numtest{27}{ --\Reason{Succeeds for user with ``get'' and ``modify.''} --} -- --\numtest{28}{ --\Reason{Rejects null policy argument.} --} -- --\numtest{29}{ --\Reason{Rejects change which makes pw_min_life greater than -- pw_max_life.} --} -- --\numtest{30}{ --\Priority{High} --\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} --\Status{Implemented} --} -- --\numtest{31}{ --\Priority{Low} --\Reason{Connects to correct server when multiple handles exist} --\Conditions{RPC} --} -- --\section{ovsec_kadm_get_policy} -- --\numtest{1}{ --\Reason{Fails for null policy.} --} -- --\numtest{2}{ --\Reason{Fails for invalid policy name.} --} -- --\numtest{3}{ --\Priority{High} --\Reason{Fails for empty-string policy name.} --\Status{Implemented} --} -- --\numtest{4}{ --\Reason{Fails for non-existent policy name.} --} -- --\numtest{5}{ --\Reason{Fails for null ent.} --} -- --\numtest{6}{ --\Priority{High} --\Reason{Fails for user with no access bits trying to get other's -- policy, using ADMIN_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{7}{ --\Priority{High} --\Reason{Fails for user with ``add'' but not ``get'' trying to get -- other's policy, using ADMIN_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{8}{ --\Reason{Fails for user with ``modify'' but not ``get'' trying to get -- other's policy, using ADMIN_SERVICE.} --\Conditions{RPC} --} -- --\numtest{9}{ --\Reason{Fails for user with ``delete'' but not ``get'' trying to get -- other's policy, using ADMIN_SERVICE.} --\Conditions{RPC} --} -- --\numtest{10}{ --\Reason{Fails for user with ``delete'' but not ``get'' trying to get -- other's policy, using CHANGEPW_SERVICE.} --\Conditions{RPC} --} -- --\numtest{11}{ --\Priority{High} --\Reason{Succeeds for user with only ``get'', trying to get own policy, -- using ADMIN_SERVICE.} --\Status{Implemented} --} -- --\numtest{12}{ --\Priority{High} --\Reason{Succeeds for user with only ``get'', trying to get own policy, -- using CHANGEPW_SERVICE.} --\Status{Implemented} --} -- --\numtest{13}{ --\Reason{Succeeds for user with ``add'' and ``get'', trying to get own -- policy, using ADMIN_SERVICE.} --} -- --\numtest{14}{ --\Reason{Succeeds for user with ``add'' and ``get'', trying to get own -- policy, using CHANGEPW_SERVICE.} --} -- --\numtest{15}{ --\Reason{Succeeds for user without ``get'', trying to get own policy, -- using ADMIN_SERVICE.} --} -- --\numtest{16}{ --\Priority{High} --\Reason{Succeeds for user without ``get'', trying to get own policy, -- using CHANGEPW_SERVICE.} --\Status{Implemented} --} -- --\numtest{17}{ --\Priority{High} --\Reason{Succeeds for user with ``get'', trying to get other's policy, -- using ADMIN_SERVICE.} --\Status{Implemented} --} -- --\numtest{18}{ --\Priority{High} --\Reason{Fails for user with ``get'', trying to get other's policy, -- using CHANGEPW_SERVICE.} --\Conditions{RPC} --\Status{Implemented} --} -- --\numtest{19}{ --\Reason{Succeeds for user with ``modify'' and ``get'', trying to get -- other's policy, using ADMIN_SERVICE.} --} -- --\numtest{20}{ --\Reason{Fails for user with ``modify'' and ``get'', trying to get -- other's policy, using CHANGEPW_SERVICE.} --} -- --\numtest{21}{ --\Priority{High} --\Reason{Returns BAD_SERVER_HANDLE when a null server handle is passed in} --\Status{Implemented} --} -- --\numtest{22}{ --\Priority{Low} --\Reason{Connects to correct server when multiple handles exist} --\Conditions{RPC} --} -- -- --\section{ovsec_kadm_free_principal_ent} -- --In addition to the tests listed here, a memory-leak detector such as --TestCenter, Purify or dbmalloc should be used to verify that the --memory freed by this function is really freed. -- --\numtest{1}{ --\Reason{Null princ succeeds.} --} -- --\numtest{2}{ --\Reason{Non-null princ succeeds.} --} -- -- --\section{ovsec_kadm_free_policy_ent} -- --In addition to the tests listed here, a memory-leak detector such as --TestCenter, Purify or dbmalloc should be used to verify that the --memory freed by this function is really freed. -- --\numtest{1}{ --\Reason{Null policy succeeds.} --} -- --\numtest{2}{ --\Reason{Non-null policy succeeds.} --} -- -- -- --\section{ovsec_kadm_get_privs} -- --\numtest{1}{ --\Reason{Fails for null pointer argument.} --} -- --This test should be run with the 16 possible combinations of access --bits (since there are 4 access bits, there are $2^4 = 16$ possible --combinations of them): -- --\numtest{2}{ --\Priority{High} --\Reason{Returns correct bit mask for access bits of user.} --\Conditions{RPC} --} -- --This test should be run locally: -- --\numtest{3}{ --\Priority{High} --\Reason{Returns 0x0f.} --\Conditions{local} --} -- --\end{document} -diff --git a/src/config/pre.in b/src/config/pre.in -index 3752174c7..b2d17b077 100644 ---- a/src/config/pre.in -+++ b/src/config/pre.in -@@ -228,16 +228,8 @@ KRB5_INCSUBDIRS = \ - $(KRB5_INCDIR)/gssapi \ - $(KRB5_INCDIR)/gssrpc - --# --# Macros used by the KADM5 (OV-based) unit test system. --# XXX check which of these are actually used! --# - SKIPTESTS = $(BUILDTOP)/skiptests --TESTDIR = $(BUILDTOP)/kadmin/testing --STESTDIR = $(top_srcdir)/kadmin/testing --ENV_SETUP = $(TESTDIR)/scripts/env-setup.sh --CLNTTCL = $(TESTDIR)/util/kadm5_clnt_tcl --SRVTCL = $(TESTDIR)/util/kadm5_srv_tcl -+ - # Dejagnu variables. - # We have to set the host with --host so that setup_xfail will work. - # If we don't set it, then the host type used is "native", which -@@ -249,14 +241,6 @@ RUNTEST = runtest $(DEJAFLAGS) - RUNPYTEST = PYTHONPATH=$(top_srcdir)/util VALGRIND="$(VALGRIND)" \ - $(PYTHON) - --START_SERVERS = $(STESTDIR)/scripts/start_servers $(TEST_SERVER) $(TEST_PATH) --START_SERVERS_LOCAL = $(STESTDIR)/scripts/start_servers_local -- --STOP_SERVERS = $(STESTDIR)/scripts/stop_servers $(TEST_SERVER) $(TEST_PATH) --STOP_SERVERS_LOCAL = $(STESTDIR)/scripts/stop_servers_local --# --# End of macros for the KADM5 unit test system. --# - - transform = @program_transform_name@ - -diff --git a/src/configure.ac b/src/configure.ac -index 61778dcd0..4f16fee45 100644 ---- a/src/configure.ac -+++ b/src/configure.ac -@@ -991,33 +991,9 @@ ath_compat= - AC_ARG_ENABLE([athena], - [ --enable-athena build with MIT Project Athena configuration], - ath_compat=compat,) --# The following are tests for the presence of programs required for --# kadmin testing. --AC_CHECK_PROG(have_RUNTEST,runtest,runtest) --AC_CHECK_PROG(have_PERL,perl,perl) --if test "$have_PERL" = perl -a "$have_RUNTEST" = runtest -a "$TCL_LIBS" != ""; then -- DO_TEST=ok --fi --AC_SUBST(DO_TEST) -- --# The following are substituted into kadmin/testing/scripts/env-setup.sh --RBUILD=`pwd` --AC_SUBST(RBUILD) --case "$srcdir" in --/*) S_TOP=$srcdir ;; --*) S_TOP=`pwd`/$srcdir ;; --esac --AC_SUBST(S_TOP) --AC_PATH_PROG(EXPECT,expect) --# For kadmin/testing/util/Makefile.in --if test "$TCL_LIBS" != "" ; then -- DO_ALL=tcl --fi --AC_SUBST(DO_ALL) -+ - KRB5_AC_PRIOCNTL_HACK --K5_GEN_FILE(kadmin/testing/scripts/env-setup.sh:kadmin/testing/scripts/env-setup.shin) --# for lib/kadm5 --AC_CHECK_PROG(RUNTEST,runtest,runtest) -+ - AC_CHECK_PROG(PERL,perl,perl) - - # lib/gssapi -@@ -1552,7 +1528,7 @@ V5_AC_OUTPUT_MAKEFILE(. - - lib/rpc lib/rpc/unit-test - -- lib/kadm5 lib/kadm5/clnt lib/kadm5/srv lib/kadm5/unit-test -+ lib/kadm5 lib/kadm5/clnt lib/kadm5/srv - lib/krad - lib/apputils - -@@ -1588,7 +1564,6 @@ V5_AC_OUTPUT_MAKEFILE(. - clients/kdestroy clients/kpasswd clients/ksu clients/kswitch - - kadmin kadmin/cli kadmin/dbutil kadmin/ktutil kadmin/server -- kadmin/testing kadmin/testing/scripts kadmin/testing/util - - appl - appl/sample appl/sample/sclient appl/sample/sserver -diff --git a/src/kadmin/Makefile.in b/src/kadmin/Makefile.in -index f4061f4f7..87cfa43fd 100644 ---- a/src/kadmin/Makefile.in -+++ b/src/kadmin/Makefile.in -@@ -1,6 +1,6 @@ - mydir=kadmin - BUILDTOP=$(REL).. --SUBDIRS = cli dbutil ktutil server testing -+SUBDIRS = cli dbutil ktutil server - - all: - -diff --git a/src/kadmin/testing/Makefile.in b/src/kadmin/testing/Makefile.in -deleted file mode 100644 -index 5b803cb23..000000000 ---- a/src/kadmin/testing/Makefile.in -+++ /dev/null -@@ -1,8 +0,0 @@ --mydir=kadmin$(S)testing --BUILDTOP=$(REL)..$(S).. --SUBDIRS = scripts util -- --all: -- --clean: -- -$(RM) -r krb5-test-root admin_* init-* *.rcache2 ovsec-* -diff --git a/src/kadmin/testing/deps b/src/kadmin/testing/deps -deleted file mode 100644 -index 2feac3c9d..000000000 ---- a/src/kadmin/testing/deps -+++ /dev/null -@@ -1 +0,0 @@ --# No dependencies here. -diff --git a/src/kadmin/testing/proto/kdc.conf.proto b/src/kadmin/testing/proto/kdc.conf.proto -deleted file mode 100644 -index 8a4b87de1..000000000 ---- a/src/kadmin/testing/proto/kdc.conf.proto -+++ /dev/null -@@ -1,16 +0,0 @@ --[kdcdefaults] -- kdc_listen = 1750 -- kdc_tcp_listen = 1750 -- --[realms] -- __REALM__ = { -- profile = __K5ROOT__/krb5.conf -- database_name = __K5ROOT__/kdb5 -- key_stash_file = __K5ROOT__/.k5.__REALM__ -- acl_file = __K5ROOT__/ovsec_adm.acl -- dict_file = __K5ROOT__/ovsec_adm.dict -- kadmind_port = 1751 -- kpasswd_port = 1752 -- master_key_type = des3-hmac-sha1 -- supported_enctypes = des3-hmac-sha1:normal aes256-cts:normal aes128-cts:normal aes256-sha2:normal aes128-sha2:normal -- } -diff --git a/src/kadmin/testing/proto/krb5.conf.proto b/src/kadmin/testing/proto/krb5.conf.proto -deleted file mode 100644 -index a1c57119c..000000000 ---- a/src/kadmin/testing/proto/krb5.conf.proto -+++ /dev/null -@@ -1,32 +0,0 @@ --[libdefaults] -- default_realm = __REALM__ -- default_keytab_name = FILE:__K5ROOT__/keytab -- dns_fallback = no -- dns_canonicalize_hostname = fallback -- qualify_shortname = "" -- plugin_base_dir = __PLUGIN_DIR__ -- allow_weak_crypto = true -- --[realms] -- __REALM__ = { -- kdc = __HOSTNAME__:1750 -- admin_server = __HOSTNAME__:1751 -- database_module = foobar_db2_module_blah -- } -- --[domain_realm] -- __HOSTNAME__ = __REALM__ -- --[logging] -- admin_server = FILE:__K5ROOT__/syslog -- kdc = FILE:__K5ROOT__/syslog -- default = FILE:__K5ROOT__/syslog -- -- --# THIS SHOULD BE IN KDC.CONF INSTEAD! --[dbmodules] -- db_module_dir = __MODDIR__ -- foobar_db2_module_blah = { -- db_library = db2 -- database_name = __K5ROOT__/kdb5 -- } -diff --git a/src/kadmin/testing/proto/ovsec_adm.dict b/src/kadmin/testing/proto/ovsec_adm.dict -deleted file mode 100644 -index b54e3a85e..000000000 ---- a/src/kadmin/testing/proto/ovsec_adm.dict -+++ /dev/null -@@ -1,3 +0,0 @@ --Abyssinia --Discordianism --foo -diff --git a/src/kadmin/testing/scripts/Makefile.in b/src/kadmin/testing/scripts/Makefile.in -deleted file mode 100644 -index 635930511..000000000 ---- a/src/kadmin/testing/scripts/Makefile.in -+++ /dev/null -@@ -1,18 +0,0 @@ --mydir=kadmin$(S)testing$(S)scripts --BUILDTOP=$(REL)..$(S)..$(S).. -- --all: env-setup.sh runenv.sh $(GEN_SCRIPTS) -- --# Should only rebuild env_setup.sh here (use CONFIG_FILES=), but the weird krb5 --# makefile post-processing is unconditional and would trash the makefile. --env-setup.sh: env-setup.stamp --env-setup.stamp: $(srcdir)/env-setup.shin $(BUILDTOP)/config.status \ -- Makefile -- (cd $(BUILDTOP) && \ -- CONFIG_FILES=$(mydir)/env-setup.sh:$(mydir)/env-setup.shin $(SHELL) \ -- config.status) -- chmod +x env-setup.sh -- touch env-setup.stamp -- --clean: -- -rm -f env-setup.sh env-setup.stamp -diff --git a/src/kadmin/testing/scripts/deps b/src/kadmin/testing/scripts/deps -deleted file mode 100644 -index 2feac3c9d..000000000 ---- a/src/kadmin/testing/scripts/deps -+++ /dev/null -@@ -1 +0,0 @@ --# No dependencies here. -diff --git a/src/kadmin/testing/scripts/env-setup.shin b/src/kadmin/testing/scripts/env-setup.shin -deleted file mode 100755 -index 88f8ad1aa..000000000 ---- a/src/kadmin/testing/scripts/env-setup.shin -+++ /dev/null -@@ -1,104 +0,0 @@ --#!/bin/sh --# --# The KADM5 unit tests were developed to work under gmake. As a --# result, they expect to inherit a number of environment variables. --# Rather than rewrite the tests, we simply use this script as an --# execution wrapper that sets all the necessary environment variables --# before running the program specified on its command line. --# --# The variable settings all came from OV's config.mk. --# --# Usage: env-setup.sh --# -- --TOP=@RBUILD@/kadmin --STOP=@S_TOP@/kadmin --export TOP --export STOP --# These two may be needed in case $libdir references them. --prefix=@prefix@ --exec_prefix=@exec_prefix@ --libdir=@libdir@ ; eval "libdir=$libdir"; export libdir -- --# The shared library run time setup --TOPLIBD=@RBUILD@/lib --PROG_LIBPATH=-L@RBUILD@/lib --BUILDTOP=@RBUILD@ --# XXX kludge! --PROG_RPATH=@RBUILD@/lib --# This converts $(TOPLIBD) to $TOPLIBD --cat > /tmp/env_setup$$ <<\EOF --@KRB5_RUN_ENV@ --EOF -- --foo=`sed -e 's/(//g' -e 's/)//g' -e 's/\\\$\\\$/\$/g' /tmp/env_setup$$` --eval $foo --export @KRB5_RUN_VARS@ -- --# This will get put in setup.csh for convenience --KRB5_RUN_ENV_CSH=`eval echo "$foo" | \ -- sed -e 's/\([^=]*\)=\(.*\)/setenv \1 \2/g'` --export KRB5_RUN_ENV_CSH --rm /tmp/env_setup$$ -- --TESTDIR=$TOP/testing; export TESTDIR --STESTDIR=$STOP/testing; export STESTDIR --if [ "$K5ROOT" = "" ]; then -- K5ROOT="`cd $TESTDIR; pwd`/krb5-test-root" -- export K5ROOT --fi -- --# If $VERBOSE_TEST is non-null, enter verbose mode. Set $VERBOSE to --# true or false so its exit status identifies the mode. --if test x$VERBOSE_TEST = x; then -- VERBOSE=false --else -- VERBOSE=true --fi --export VERBOSE -- --REALM=SECURE-TEST.OV.COM; export REALM -- --if test x$EXPECT = x; then -- EXPECT=@EXPECT@; export EXPECT --fi -- --COMPARE_DUMP=$TESTDIR/scripts/compare_dump.pl; export COMPARE_DUMP --INITDB=$STESTDIR/scripts/init_db; export INITDB --SIMPLE_DUMP=$TESTDIR/scripts/simple_dump.pl; export SIMPLE_DUMP --TCLUTIL=$STESTDIR/tcl/util.t; export TCLUTIL --BSDDB_DUMP=$TESTDIR/util/bsddb_dump; export BSDDB_DUMP --CLNTTCL=$TESTDIR/util/kadm5_clnt_tcl; export CLNTTCL --SRVTCL=$TESTDIR/util/kadm5_srv_tcl; export SRVTCL -- --HOSTNAME=`hostname | tr '[A-Z]' '[a-z]'` --export HOSTNAME -- --KRB5_CONFIG=$K5ROOT/krb5.conf; export KRB5_CONFIG --KRB5_KDC_PROFILE=$K5ROOT/kdc.conf; export KRB5_KDC_PROFILE --KRB5_KTNAME=$K5ROOT/ovsec_adm.keytab; export KRB5_KTNAME --KRB5_CLIENT_KTNAME=$K5ROOT/client_keytab; export KRB5_CLIENT_KTNAME --KRB5CCNAME=$K5ROOT/krb5cc_unit-test; export KRB5CCNAME --GSS_MECH_CONFIG=$K5ROOT/mech.conf; export GSS_MECH_CONFIG -- --# Make sure we don't get confused by translated messages --# or localized times. --LC_ALL=C; export LC_ALL -- --if [ "x$PS_ALL" = "x" ]; then -- if ps auxww >/dev/null 2>&1; then -- PS_ALL="ps auxww" -- PS_PID="ps uwwp" -- elif ps -ef >/dev/null 2>&1; then -- PS_ALL="ps -ef" -- PS_PID="ps -fp" -- else -- PS_ALL="ps auxww" -- PS_PID="ps uwwp" -- echo "WARNING! Cannot auto-detect ps type, assuming BSD." -- fi -- -- export PS_ALL PS_PID --fi -- --exec ${1+"$@"} -diff --git a/src/kadmin/testing/scripts/init_db b/src/kadmin/testing/scripts/init_db -deleted file mode 100755 -index 216f62793..000000000 ---- a/src/kadmin/testing/scripts/init_db -+++ /dev/null -@@ -1,229 +0,0 @@ --#!/bin/sh -- --if $VERBOSE; then -- REDIRECT= --else -- REDIRECT='>/dev/null' --fi -- --# Requires that $K5ROOT, /etc/krb.conf, and .k5.$REALM be world-writeable. -- --if [ "$TOP" = "" ]; then -- echo "init_db: Environment variable \$TOP must point to top of build tree" 1>&2 -- exit 1 --fi -- --if [ "$STOP" = "" ]; then -- echo "init_db: Environment variable \$STOP must point to top of source tree" 1>&2 -- exit 1 --fi -- --if [ "$libdir" = "" ]; then -- echo "init_db: Environment variable \$libdir must point to library install directory" 1>&2 -- exit 1 --fi -- --IROOT=$TOP/.. --ADMIN=$TOP/dbutil --BIN=$IROOT/bin --ETC=$IROOT/etc --MODDIR=$TOP/../plugins/kdb --SBIN=$TOP/keytab:$TOP/server --DUMMY=${REALM=SECURE-TEST.OV.COM}; export REALM -- --. ./runenv.sh -- --if [ ! -d $MODDIR ]; then -- echo "+++" 1>&2 -- echo "+++ Error! $MODDIR does not exist!" 1>&2 -- echo "+++ The MODDIR variable should point to the directory in which" 1>&2 -- echo "+++ database modules have been installed for testing." 1>&2 -- echo "+++" 1>&2 -- exit 1 --fi -- --DUMMY=${TESTDIR=$TOP/testing}; export TESTDIR --DUMMY=${STESTDIR=$STOP/testing} --DUMMY=${SRVTCL=$TESTDIR/util/kadm5_srv_tcl}; export SRVTCL --DUMMY=${TCLUTIL=$STESTDIR/tcl/util.t}; export TCLUTIL -- --PATH=$ADMIN:$BIN:$ETC:$SBIN:$PATH; export PATH -- --if [ ! -x $SRVTCL ]; then -- echo "+++" 1>&2 -- echo "+++ Error! $SRVTCL does not exist!" 1>&2 -- echo "+++ It was probably not compiled because TCL was not available. If you" 1>&2 -- echo "+++ now have TCL installed, cd into that directory, re-run configure" 1>&2 -- echo "+++ with the --with-tcl option, and then re-run make." 1>&2 -- echo "+++" 1>&2 -- -- exit 1 --fi -- --rm -rf $K5ROOT/* --if [ -d $K5ROOT ]; then -- true --else -- mkdir $K5ROOT --fi -- --# touch $K5ROOT/syslog --# for pid in `$PS_ALL | awk '/syslogd/ && !/awk/ {print $2}'` ; do --# case "$pid" in --# xxx) ;; --# *) --# if $VERBOSE; then $PS_PID$pid | grep -v COMMAND; fi --# kill -1 $pid --# ;; --# esac --# done -- --sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ -- -e "s/__HOSTNAME__/$HOSTNAME/g" \ -- -e "s#__MODDIR__#$MODDIR#g" \ -- < $STESTDIR/proto/krb5.conf.proto > $K5ROOT/krb5.conf --sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ -- < $STESTDIR/proto/kdc.conf.proto > $K5ROOT/kdc.conf -- --eval kdb5_util -r $REALM create -W -P mrroot -s $REDIRECT || exit 1 -- --cp $STESTDIR/proto/ovsec_adm.dict $K5ROOT/ovsec_adm.dict -- --cat - > /tmp/init_db$$ <<\EOF --source $env(TCLUTIL) --set r $env(REALM) --if {[info exists env(USER)]} { -- set whoami $env(USER) --} else { -- set whoami [exec whoami] --} -- --set cmds { -- {kadm5_init $env(SRVTCL) mrroot null \ -- [config_params {KADM5_CONFIG_REALM} $r] $KADM5_STRUCT_VERSION \ -- $KADM5_API_VERSION_3 server_handle} -- -- {kadm5_create_policy $server_handle "test-pol 0 10000 8 2 3 0 2 90 180" \ -- {KADM5_POLICY KADM5_PW_MIN_LENGTH KADM5_PW_MIN_CLASSES KADM5_PW_MAX_LIFE KADM5_PW_HISTORY_NUM KADM5_PW_MAX_FAILURE KADM5_PW_FAILURE_COUNT_INTERVAL KADM5_PW_LOCKOUT_DURATION}} -- {kadm5_create_policy $server_handle "once-a-min 10 0 0 0 0 0 0 0 0" \ -- {KADM5_POLICY KADM5_PW_MIN_LIFE}} -- {kadm5_create_policy $server_handle "dict-only 0 0 0 0 0 0 0 0 0" \ -- {KADM5_POLICY}} -- {kadm5_create_policy $server_handle [simple_policy test-pol-nopw] \ -- {KADM5_POLICY}} -- -- {kadm5_create_principal $server_handle \ -- [simple_principal testuser@$r] {KADM5_PRINCIPAL} notathena} -- {kadm5_create_principal $server_handle \ -- [simple_principal test1@$r] {KADM5_PRINCIPAL} test1} -- {kadm5_create_principal $server_handle \ -- [simple_principal test2@$r] {KADM5_PRINCIPAL} test2} -- {kadm5_create_principal $server_handle \ -- [simple_principal test3@$r] {KADM5_PRINCIPAL} test3} -- {kadm5_create_principal $server_handle \ -- [simple_principal admin@$r] {KADM5_PRINCIPAL} admin} -- {kadm5_create_principal $server_handle \ -- [simple_principal admin/get@$r] {KADM5_PRINCIPAL} admin} -- {kadm5_create_principal $server_handle \ -- [simple_principal admin/modify@$r] {KADM5_PRINCIPAL} admin} -- {kadm5_create_principal $server_handle \ -- [simple_principal admin/delete@$r] {KADM5_PRINCIPAL} admin} -- {kadm5_create_principal $server_handle \ -- [simple_principal admin/add@$r] {KADM5_PRINCIPAL} admin} -- {kadm5_create_principal $server_handle \ -- [simple_principal admin/none@$r] {KADM5_PRINCIPAL} admin} -- {kadm5_create_principal $server_handle \ -- [simple_principal admin/rename@$r] {KADM5_PRINCIPAL} admin} -- {kadm5_create_principal $server_handle \ -- [simple_principal admin/mod-add@$r] {KADM5_PRINCIPAL} admin} -- {kadm5_create_principal $server_handle \ -- [simple_principal admin/mod-delete@$r] {KADM5_PRINCIPAL} \ -- admin} -- {kadm5_create_principal $server_handle \ -- [simple_principal admin/get-add@$r] {KADM5_PRINCIPAL} admin} -- {kadm5_create_principal $server_handle \ -- [simple_principal admin/get-delete@$r] {KADM5_PRINCIPAL} \ -- admin} -- {kadm5_create_principal $server_handle \ -- [simple_principal admin/get-mod@$r] {KADM5_PRINCIPAL} admin} -- {kadm5_create_principal $server_handle \ -- [simple_principal admin/no-add@$r] {KADM5_PRINCIPAL} admin} -- {kadm5_create_principal $server_handle \ -- [simple_principal admin/no-delete@$r] {KADM5_PRINCIPAL} admin} -- {kadm5_create_principal $server_handle \ -- [princ_w_pol pol1@$r test-pol] {KADM5_PRINCIPAL \ -- KADM5_POLICY} pol111111} -- {kadm5_create_principal $server_handle \ -- [princ_w_pol pol2@$r once-a-min] {KADM5_PRINCIPAL \ -- KADM5_POLICY} pol222222} -- {kadm5_create_principal $server_handle \ -- [princ_w_pol pol3@$r dict-only] {KADM5_PRINCIPAL \ -- KADM5_POLICY} pol333333} -- {kadm5_create_principal $server_handle \ -- [princ_w_pol admin/get-pol@$r test-pol-nopw] \ -- {KADM5_PRINCIPAL KADM5_POLICY} StupidAdmin} -- {kadm5_create_principal $server_handle \ -- [princ_w_pol admin/pol@$r test-pol-nopw] {KADM5_PRINCIPAL \ -- KADM5_POLICY} StupidAdmin} -- -- {kadm5_create_principal $server_handle \ -- [simple_principal changepw/kerberos] \ -- {KADM5_PRINCIPAL} {XXX THIS IS WRONG}} -- -- {kadm5_create_principal $server_handle \ -- [simple_principal $whoami] \ -- {KADM5_PRINCIPAL} $whoami} -- -- {kadm5_create_principal $server_handle \ -- [simple_principal testkeys@$r] {KADM5_PRINCIPAL} testkeys} -- -- {kadm5_destroy $server_handle} --} -- --foreach cmd $cmds { -- if {[catch $cmd output]} { -- puts stderr "Error! Command: $cmd\nError: $output" -- exit 1 -- } else { -- puts stdout $output -- } --} --EOF --eval "$SRVTCL < /tmp/init_db$$ $REDIRECT" --rm /tmp/init_db$$ -- --if [ $? -ne 0 ]; then -- echo "Error in $SRVTCL!" 1>&2 -- exit 1 --fi -- --cat > $K5ROOT/ovsec_adm.acl < $K5ROOT/setup.csh <&2 -- exit 1 -- fi -- -- local=0 -- hostname=$1 -- if [ $# = 1 ]; then -- rempath=`sh -c "cd $TOP && pwd"` -- else -- rempath=$2 -- fi --fi -- --if [ $local = 0 ]; then -- -- # Fix up the local krb5.conf to point to the remote -- sed -e "s/__REALM__/$REALM/g" -e "s#__K5ROOT__#$K5ROOT#g" \ -- -e "s/__HOSTNAME__/$HOSTNAME/g" \ -- -e "s#__MODDIR__#$TOP/../plugins/kdb#g"\ -- -e "s#__PLUGIN_DIR__#$TOP/../plugins#g"\ -- < $STESTDIR/proto/krb5.conf.proto > $K5ROOT/krb5.conf -- --# Using /usr/ucb/rsh and getting rid of "-k $REALM" until we get --# around to fixing the fact that Kerberos rsh doesn't strip out "-k --# REALM" when falling back. -- -- START_SERVERS_LOCAL=`echo $START_SERVERS_LOCAL|sed "s%$TOP%$rempath%"` -- CMD="$RSH_CMD $hostname -n \ -- \"sh -c 'VERBOSE_TEST=$VERBOSE_TEST TOP=$rempath \ -- $rempath/testing/scripts/env-setup.sh \ -- $START_SERVERS_LOCAL $rempath'\"" -- -- if $VERBOSE; then -- echo "+++" -- echo "+++ Begin execution of start_servers_local on $hostname" -- echo "+++" -- echo $CMD -- fi -- eval $CMD -- if $VERBOSE; then -- echo "+++" -- echo "+++ End execution of start_servers_local on $hostname" -- echo "+++" -- fi --else -- $START_SERVERS_LOCAL --fi -- -diff --git a/src/kadmin/testing/scripts/start_servers_local b/src/kadmin/testing/scripts/start_servers_local -deleted file mode 100755 -index 858e88031..000000000 ---- a/src/kadmin/testing/scripts/start_servers_local -+++ /dev/null -@@ -1,157 +0,0 @@ --#!/bin/sh -- --DUMMY=${TESTDIR=$TOP/testing} --DUMMY=${STESTDIR=$STOP/testing} --DUMMY=${INITDB=$STESTDIR/scripts/init_db} --DUMMY=${SRVTCL=$TESTDIR/util/kadm5_srv_tcl}; export SRVTCL --DUMMY=${STOP_SERVERS_LOCAL=$STESTDIR/scripts/stop_servers_local} --DUMMY=${KRB5RCACHEDIR=$TESTDIR} ; export KRB5RCACHEDIR -- --. ./runenv.sh -- --if [ -d /usr/tmp ]; then -- usrtmp=/usr/tmp --else -- usrtmp=/var/tmp --fi -- --$STOP_SERVERS_LOCAL -start_servers -- --if $VERBOSE; then -- REDIRECT= --else -- REDIRECT='>/dev/null' --fi -- --while :; do -- case $1 in -- -keysalt) -- shift -- if [ $# -gt 0 ]; then -- keysalts="$keysalts $1" -- else -- break -- fi -- ;; -- -kdcport) -- shift -- if [ $# -gt 0 ]; then -- kdcport=$1 -- else -- break -- fi -- ;; -- *) -- break -- ;; -- esac -- shift --done -- --if [ $# -gt 1 ]; then -- echo "Usage: $0 [-kdcport port] [-keysalts tuple] ... [top]" 1>&2 -- exit 1 --elif [ $# = 1 ]; then -- TOP=$1 -- export TOP --fi -- --# create a fresh db -- --$INITDB "$keysalts" || exit 1 -- --# Post-process the config files based on our arguments --if [ "$keysalts" != "" ]; then -- sedcmd="s/\([ ]*supported_enctypes =\).*/\1 $keysalts/" -- sed -e "$sedcmd" < $K5ROOT/kdc.conf > $K5ROOT/kdc.conf.new -- mv $K5ROOT/kdc.conf.new $K5ROOT/kdc.conf --fi --if [ "$kdcport" != "" ] ; then -- sedcmd="s/\(kdc_ports = .*\)[ ]*/\1, $kdcport/" -- sed -e "$sedcmd" < $K5ROOT/kdc.conf > $K5ROOT/kdc.conf.new -- mv $K5ROOT/kdc.conf.new $K5ROOT/kdc.conf --fi -- --# allow admin to krlogin as root (for cleanup) --DUMMY=${REALM=SECURE-TEST.OV.COM}; export REALM -- --cat - > /tmp/start_servers_local$$ <<\EOF --if { [catch { -- source $env(STOP)/testing/tcl/util.t -- set r $env(REALM) -- set q $env(HOSTNAME) -- puts stdout [kadm5_init $env(SRVTCL) mrroot null \ -- [config_params {KADM5_CONFIG_REALM} $r] \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 server_handle] -- puts stdout [kadm5_create_principal $server_handle \ -- [simple_principal host/$q@$r] {KADM5_PRINCIPAL} notathena] -- puts stdout [kadm5_destroy $server_handle] --} err]} { -- puts stderr "initialization error: $err" -- exit 1 --} --exit 0 --EOF --eval "$SRVTCL < /tmp/start_servers_local$$ $REDIRECT" --x=$? --rm /tmp/start_servers_local$$ --if test $x != 0 ; then exit 1 ; fi -- --# run the servers (from the build tree) -- --adm_start_file=/tmp/adm_server_start.$$ --kdc_start_file=/tmp/kdc_server_start.$$ -- --rm -f $kdc_start_file -- --if test "x$USER" = x ; then -- USER=$LOGNAME ; export USER --fi -- --kdc_args="-R dfl:kdc_rcache.$USER" -- --(trap "" 2; $TOP/../kdc/krb5kdc $kdc_args; touch $kdc_start_file) \ -- < /dev/null > $usrtmp/kdc-log.$USER 2>&1 & -- --s=1 --max_s=60 --sofar_s=0 --timewait_s=300 -- --ovadm_args=-W -- --rm -f $adm_start_file -- --(sleep 1; $TOP/server/kadmind $ovadm_args; \ -- touch $adm_start_file) < /dev/null > $usrtmp/kadm-log.$USER 2>&1 & -- --# wait until they start -- --while [ $sofar_s -le $max_s ]; do -- if $VERBOSE; then -- echo "Sleeping for $s seconds to allow servers" \ -- "to start..." -- fi -- -- sofar_s=`expr $sofar_s + $s` -- -- sleep $s -- -- if [ -f $adm_start_file -a -f $kdc_start_file ]; then -- break -- fi --done -- --if [ $sofar_s -gt $max_s ]; then -- echo "Admin server or KDC failed to start after $sofar_s" \ -- "seconds." 1>&2 -- if [ ! -f $adm_start_file ]; then -- echo " No admin server start file $adm_start_file." 1>&2 -- fi -- if [ ! -f $kdc_start_file ]; then -- echo " No KDC start file $adm_start_file." 1>&2 -- fi -- exit 1 --fi -- --rm -f $kdc_start_file $adm_start_file -diff --git a/src/kadmin/testing/scripts/stop_servers b/src/kadmin/testing/scripts/stop_servers -deleted file mode 100755 -index b7f8384ca..000000000 ---- a/src/kadmin/testing/scripts/stop_servers -+++ /dev/null -@@ -1,60 +0,0 @@ --#!/bin/sh --# --# Usage: stop_servers [hostname [path]] --# --# This script turns a host into a OpenV*Secure primary server for the --# realm SECURE-TEST.OV.COM. If no arguments are specified, --# the local host is affected. Otherwise, the host hostname is --# affected; the path argument is the top of the Secure install tree on --# that host, and if it is not specified the current canonical value of --# TOP is used. -- --DUMMY=${TESTDIR=$TOP/testing} --DUMMY=${STESTDIR=$STOP/testing} --DUMMY=${STOP_SERVERS_LOCAL=$STESTDIR/scripts/stop_servers_local} --# This'll be wrong sometimes --DUMMY=${RSH_CMD=rsh} -- --local=1 -- --if [ $# -gt 0 ]; then -- if [ $# != 1 -a $# != 2 ]; then -- echo "Usage: $0 [hostname [path]]" 1>&2 -- exit 1 -- fi -- -- local=0 -- hostname=$1 -- if [ $# = 1 ]; then -- rempath=`sh -c "cd $TOP && pwd"` -- else -- rempath=$2 -- fi --fi -- --if [ $local = 0 ]; then -- if $VERBOSE; then -- echo "+++ Stopping servers on remote host $hostname..." -- fi -- -- STOP_SERVERS_LOCAL=`echo $STOP_SERVERS_LOCAL | sed "s%$TOP%$rempath%"` -- CMD="$RSH_CMD $hostname -n \ -- \"sh -c 'VERBOSE_TEST=$VERBOSE_TEST TOP=$rempath \ -- $rempath/testing/scripts/env-setup.sh \ -- $STOP_SERVERS_LOCAL $rempath'\"" -- -- if $VERBOSE; then -- echo "+++" -- echo "+++ Begin execution of stop_servers_local on $hostname" -- echo "+++" -- echo $CMD -- fi -- eval $CMD -- if $VERBOSE; then -- echo "+++" -- echo "+++ End execution of stop_servers_local on $hostname" -- echo "+++" -- fi --else -- $STOP_SERVERS_LOCAL --fi -diff --git a/src/kadmin/testing/scripts/stop_servers_local b/src/kadmin/testing/scripts/stop_servers_local -deleted file mode 100755 -index 24a9de7b3..000000000 ---- a/src/kadmin/testing/scripts/stop_servers_local -+++ /dev/null -@@ -1,44 +0,0 @@ --#!/bin/sh -- --DUMMY=${TESTDIR=$TOP/testing} --DUMMY=${KRB5RCACHEDIR=$TESTDIR} -- --while [ $# -gt 0 ] ; do -- case $1 in -- -start_servers) -- start_servers=$1 -- ;; -- *) -- TOP=$1 -- export TOP -- ;; -- esac -- shift --done -- --# kill any running servers. -- --if $VERBOSE; then echo "Killing servers:"; fi -- --for pid in xxx \ -- `$PS_ALL | grep krb5kdc | grep -v grep | awk '{print $2}'` \ -- `$PS_ALL | grep kadmind | grep -v grep | awk '{print $2}'` \ -- ; do -- case "$pid" in -- xxx) -- ;; -- *) -- if $VERBOSE; then $PS_PID$pid | grep -v COMMAND; fi -- kill $pid -- ;; -- esac --done -- --# Destroy the kdc replay cache so we don't lose if we try to run the --# KDC as another unix user. --if test "x$USER" = x ; then -- USER=$LOGNAME --fi --rm -f $KRB5RCACHEDIR/krb5kdc_rcache.$USER -- --exit 0 -diff --git a/src/kadmin/testing/tcl/util.t b/src/kadmin/testing/tcl/util.t -deleted file mode 100644 -index 6751f89e6..000000000 ---- a/src/kadmin/testing/tcl/util.t -+++ /dev/null -@@ -1,58 +0,0 @@ --proc simple_principal {name} { -- return "{$name} 0 0 0 0 {$name} 0 0 0 0 null 0" --} -- --proc princ_w_pol {name policy} { -- return "{$name} 0 0 0 0 {$name} 0 0 0 0 {$policy} 0" --} -- --proc simple_policy {name} { -- return "{$name} 0 0 0 0 0 0 0 0 0" --} -- --proc config_params {masks values} { -- if {[llength $masks] != [llength $values]} { -- error "config_params: length of mask and values differ" -- } -- -- set params [list $masks 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 {}] -- for {set i 0} {$i < [llength $masks]} {incr i} { -- set mask [lindex $masks $i] -- set value [lindex $values $i] -- switch -glob -- $mask { -- "KADM5_CONFIG_REALM" {set params [lreplace $params 1 1 $value]} -- "KADM5_CONFIG_KADMIND_PORT" { -- set params [lreplace $params 2 2 $value]} -- "KADM5_CONFIG_ADMIN_SERVER" { -- set params [lreplace $params 3 3 $value]} -- "KADM5_CONFIG_DBNAME" {set params [lreplace $params 4 4 $value]} -- "KADM5_CONFIG_ADBNAME" {set params [lreplace $params 5 5 $value]} -- "KADM5_CONFIG_ADB_LOCKFILE" { -- set params [lreplace $params 6 6 $value]} -- "KADM5_CONFIG_ACL_FILE" {set params [lreplace $params 8 8 $value]} -- "KADM5_CONFIG_DICT_FILE" { -- set params [lreplace $params 9 9 $value]} -- "KADM5_CONFIG_MKEY_FROM_KBD" { -- set params [lreplace $params 10 10 $value]} -- "KADM5_CONFIG_STASH_FILE" { -- set params [lreplace $params 11 11 $value]} -- "KADM5_CONFIG_MKEY_NAME" { -- set params [lreplace $params 12 12 $value]} -- "KADM5_CONFIG_ENCTYPE" {set params [lreplace $params 13 13 $value]} -- "KADM5_CONFIG_MAX_LIFE" { -- set params [lreplace $params 14 14 $value]} -- "KADM5_CONFIG_MAX_RLIFE" { -- set params [lreplace $params 15 15 $value]} -- "KADM5_CONFIG_EXPIRATION" { -- set params [lreplace $params 16 16 $value]} -- "KADM5_CONFIG_FLAGS" {set params [lreplace $params 17 17 $value]} -- "KADM5_CONFIG_ENCTYPES" { -- set params [lreplace $params 18 19 [llength $value] $value]} -- "*" {error "config_params: unknown mask $mask"} -- } -- } -- return $params --} -- -- -- -diff --git a/src/kadmin/testing/util/Makefile.in b/src/kadmin/testing/util/Makefile.in -deleted file mode 100644 -index 7785c742e..000000000 ---- a/src/kadmin/testing/util/Makefile.in -+++ /dev/null -@@ -1,42 +0,0 @@ --mydir=kadmin$(S)testing$(S)util --BUILDTOP=$(REL)..$(S)..$(S).. --LOCALINCLUDES = $(TCL_INCLUDES) -I$(BUILDTOP)/lib/kdb/ --# Force Tcl headers to use stdarg.h, because krb5 does too, and if --# Tcl uses varargs.h it'll just mess things up. --DEFINES= -DHAS_STDARG --KRB5_PTHREAD_LIB=$(THREAD_LINKOPTS) -- --PROG_LIBPATH=-L$(TOPLIBD) $(TCL_LIBPATH) --PROG_RPATH=$(KRB5_LIBDIR)$(TCL_RPATH) -- --SRCS = $(srcdir)/tcl_kadm5.c $(srcdir)/test.c --OBJS = tcl_kadm5.o test.o -- --CLNTPROG= kadm5_clnt_tcl --SRVPROG = kadm5_srv_tcl -- --DO_ALL=@DO_ALL@ -- --all: all-$(DO_ALL) -- --all-: -- @echo "+++" -- @echo "+++ WARNING: Tcl not available. The kadm5 tests will not be run." -- @echo "+++" -- @echo 'Skipped kadm5 tests: Tcl not found' >> $(SKIPTESTS) -- --all-tcl: $(CLNTPROG) $(SRVPROG) -- --$(SRVPROG): $(OBJS) $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIBS) -- $(CC_LINK) -o $(SRVPROG) $(OBJS) $(TCL_MAYBE_RPATH) \ -- $(KADMSRV_LIBS) $(KRB5_PTHREAD_LIB) $(KRB5_BASE_LIBS) $(TCL_LIBS) -- --$(CLNTPROG): $(OBJS) $(KADMCLNT_DEPLIBS) $(KRB5_BASE_DEPLIBS) -- $(CC_LINK) -o $(CLNTPROG) $(OBJS) $(TCL_MAYBE_RPATH) \ -- $(KRB5_PTHREAD_LIB) $(KADMCLNT_LIBS) $(KRB5_BASE_LIBS) $(TCL_LIBS) -- --bsddb_dump: bsddb_dump.o -- $(CC_LINK) -o bsddb_dump bsddb_dump.o $(KADMSRV_LIBS) -- --clean: -- $(RM) $(CLNTPROG) $(SRVPROG) -diff --git a/src/kadmin/testing/util/bsddb_dump.c b/src/kadmin/testing/util/bsddb_dump.c -deleted file mode 100644 -index 5dbe7ae9c..000000000 ---- a/src/kadmin/testing/util/bsddb_dump.c -+++ /dev/null -@@ -1,65 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* -- * $Id$ -- */ -- --#include --#include --#include --#include -- --main(int argc, char *argv[]) --{ -- char *file; -- DB *db; -- DBT dbkey, dbdata; -- int code, i; -- -- HASHINFO info; -- -- info.hash = NULL; -- info.bsize = 256; -- info.ffactor = 8; -- info.nelem = 25000; -- info.lorder = 0; -- -- if (argc != 2) { -- fprintf(stderr, "usage: argv[0] dbfile\n"); -- exit(2); -- } -- -- file = argv[1]; -- -- if((db = dbopen(file, O_RDWR, 0666, DB_HASH, &info)) == NULL) { -- perror("Opening db file"); -- exit(1); -- } -- -- if ((code = (*db->seq)(db, &dbkey, &dbdata, R_FIRST)) == -1) { -- perror("starting db iteration"); -- exit(1); -- } -- -- while (code == 0) { -- for (i=0; iseq)(db, &dbkey, &dbdata, R_NEXT); -- } -- -- if (code == -1) { -- perror("during db iteration"); -- exit(1); -- } -- -- if ((*db->close)(db) == -1) { -- perror("closing db"); -- exit(1); -- } -- -- exit(0); --} -diff --git a/src/kadmin/testing/util/deps b/src/kadmin/testing/util/deps -deleted file mode 100644 -index ca828a85c..000000000 ---- a/src/kadmin/testing/util/deps -+++ /dev/null -@@ -1,16 +0,0 @@ --# --# Generated makefile dependencies follow. --# --$(OUTPRE)tcl_kadm5.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(BUILDTOP)/include/gssapi/gssapi.h $(BUILDTOP)/include/gssrpc/types.h \ -- $(BUILDTOP)/include/kadm5/admin.h $(BUILDTOP)/include/kadm5/chpass_util_strings.h \ -- $(BUILDTOP)/include/kadm5/kadm_err.h $(BUILDTOP)/include/krb5/krb5.h \ -- $(BUILDTOP)/lib/kdb/adb_err.h $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ -- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ -- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ -- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ -- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ -- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/kdb.h \ -- $(top_srcdir)/include/krb5.h tcl_kadm5.c tcl_kadm5.h --$(OUTPRE)test.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- tcl_kadm5.h test.c -diff --git a/src/kadmin/testing/util/tcl_kadm5.c b/src/kadmin/testing/util/tcl_kadm5.c -deleted file mode 100644 -index 864a929c8..000000000 ---- a/src/kadmin/testing/util/tcl_kadm5.c -+++ /dev/null -@@ -1,2566 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --#include "autoconf.h" --#include --#include --#if HAVE_TCL_H --#include --#elif HAVE_TCL_TCL_H --#include --#endif --#define USE_KADM5_API_VERSION 2 --#include --#include --#include --#include --#include --#include "tcl_kadm5.h" -- --struct flagval { -- char *name; -- krb5_flags val; --}; -- --/* XXX This should probably be in the hash table like server_handle */ --static krb5_context context; -- --static struct flagval krb5_flags_array[] = { -- {"KRB5_KDB_DISALLOW_POSTDATED", KRB5_KDB_DISALLOW_POSTDATED}, -- {"KRB5_KDB_DISALLOW_FORWARDABLE", KRB5_KDB_DISALLOW_FORWARDABLE}, -- {"KRB5_KDB_DISALLOW_TGT_BASED", KRB5_KDB_DISALLOW_TGT_BASED}, -- {"KRB5_KDB_DISALLOW_RENEWABLE", KRB5_KDB_DISALLOW_RENEWABLE}, -- {"KRB5_KDB_DISALLOW_PROXIABLE", KRB5_KDB_DISALLOW_PROXIABLE}, -- {"KRB5_KDB_DISALLOW_DUP_SKEY", KRB5_KDB_DISALLOW_DUP_SKEY}, -- {"KRB5_KDB_DISALLOW_ALL_TIX", KRB5_KDB_DISALLOW_ALL_TIX}, -- {"KRB5_KDB_REQUIRES_PRE_AUTH", KRB5_KDB_REQUIRES_PRE_AUTH}, -- {"KRB5_KDB_REQUIRES_HW_AUTH", KRB5_KDB_REQUIRES_HW_AUTH}, -- {"KRB5_KDB_REQUIRES_PWCHANGE", KRB5_KDB_REQUIRES_PWCHANGE}, -- {"KRB5_KDB_DISALLOW_SVR", KRB5_KDB_DISALLOW_SVR}, -- {"KRB5_KDB_PWCHANGE_SERVICE", KRB5_KDB_PWCHANGE_SERVICE} --}; -- --static struct flagval aux_attributes[] = { -- {"KADM5_POLICY", KADM5_POLICY} --}; -- --static struct flagval principal_mask_flags[] = { -- {"KADM5_PRINCIPAL", KADM5_PRINCIPAL}, -- {"KADM5_PRINC_EXPIRE_TIME", KADM5_PRINC_EXPIRE_TIME}, -- {"KADM5_PW_EXPIRATION", KADM5_PW_EXPIRATION}, -- {"KADM5_LAST_PWD_CHANGE", KADM5_LAST_PWD_CHANGE}, -- {"KADM5_ATTRIBUTES", KADM5_ATTRIBUTES}, -- {"KADM5_MAX_LIFE", KADM5_MAX_LIFE}, -- {"KADM5_MOD_TIME", KADM5_MOD_TIME}, -- {"KADM5_MOD_NAME", KADM5_MOD_NAME}, -- {"KADM5_KVNO", KADM5_KVNO}, -- {"KADM5_MKVNO", KADM5_MKVNO}, -- {"KADM5_AUX_ATTRIBUTES", KADM5_AUX_ATTRIBUTES}, -- {"KADM5_POLICY", KADM5_POLICY}, -- {"KADM5_POLICY_CLR", KADM5_POLICY_CLR}, -- {"KADM5_MAX_RLIFE", KADM5_MAX_RLIFE}, -- {"KADM5_LAST_SUCCESS", KADM5_LAST_SUCCESS}, -- {"KADM5_LAST_FAILED", KADM5_LAST_FAILED}, -- {"KADM5_FAIL_AUTH_COUNT", KADM5_FAIL_AUTH_COUNT}, -- {"KADM5_KEY_DATA", KADM5_KEY_DATA}, -- {"KADM5_TL_DATA", KADM5_TL_DATA}, -- {"KADM5_PRINCIPAL_NORMAL_MASK", KADM5_PRINCIPAL_NORMAL_MASK} --}; -- --static struct flagval policy_mask_flags[] = { -- {"KADM5_POLICY", KADM5_POLICY}, -- {"KADM5_PW_MAX_LIFE", KADM5_PW_MAX_LIFE}, -- {"KADM5_PW_MIN_LIFE", KADM5_PW_MIN_LIFE}, -- {"KADM5_PW_MIN_LENGTH", KADM5_PW_MIN_LENGTH}, -- {"KADM5_PW_MIN_CLASSES", KADM5_PW_MIN_CLASSES}, -- {"KADM5_PW_HISTORY_NUM", KADM5_PW_HISTORY_NUM}, -- {"KADM5_REF_COUNT", KADM5_REF_COUNT}, -- {"KADM5_PW_MAX_FAILURE", KADM5_PW_MAX_FAILURE}, -- {"KADM5_PW_FAILURE_COUNT_INTERVAL", KADM5_PW_FAILURE_COUNT_INTERVAL}, -- {"KADM5_PW_LOCKOUT_DURATION", KADM5_PW_LOCKOUT_DURATION}, --}; -- --static struct flagval config_mask_flags[] = { -- {"KADM5_CONFIG_REALM", KADM5_CONFIG_REALM}, -- {"KADM5_CONFIG_DBNAME", KADM5_CONFIG_DBNAME}, -- {"KADM5_CONFIG_MKEY_NAME", KADM5_CONFIG_MKEY_NAME}, -- {"KADM5_CONFIG_MAX_LIFE", KADM5_CONFIG_MAX_LIFE}, -- {"KADM5_CONFIG_MAX_RLIFE", KADM5_CONFIG_MAX_RLIFE}, -- {"KADM5_CONFIG_EXPIRATION", KADM5_CONFIG_EXPIRATION}, -- {"KADM5_CONFIG_FLAGS", KADM5_CONFIG_FLAGS}, -- {"KADM5_CONFIG_STASH_FILE", KADM5_CONFIG_STASH_FILE}, -- {"KADM5_CONFIG_ENCTYPE", KADM5_CONFIG_ENCTYPE}, -- {"KADM5_CONFIG_ADBNAME", KADM5_CONFIG_ADBNAME}, -- {"KADM5_CONFIG_ADB_LOCKFILE", KADM5_CONFIG_ADB_LOCKFILE}, -- {"KADM5_CONFIG_ACL_FILE", KADM5_CONFIG_ACL_FILE}, -- {"KADM5_CONFIG_KADMIND_PORT", KADM5_CONFIG_KADMIND_PORT}, -- {"KADM5_CONFIG_ENCTYPES", KADM5_CONFIG_ENCTYPES}, -- {"KADM5_CONFIG_ADMIN_SERVER", KADM5_CONFIG_ADMIN_SERVER}, -- {"KADM5_CONFIG_DICT_FILE", KADM5_CONFIG_DICT_FILE}, -- {"KADM5_CONFIG_MKEY_FROM_KBD", KADM5_CONFIG_MKEY_FROM_KBD}, --}; -- --static struct flagval priv_flags[] = { -- {"KADM5_PRIV_GET", KADM5_PRIV_GET}, -- {"KADM5_PRIV_ADD", KADM5_PRIV_ADD}, -- {"KADM5_PRIV_MODIFY", KADM5_PRIV_MODIFY}, -- {"KADM5_PRIV_DELETE", KADM5_PRIV_DELETE} --}; -- -- --static char *arg_error = "wrong # args"; -- --static Tcl_HashTable *struct_table = 0; -- --static int put_server_handle(Tcl_Interp *interp, void *handle, char **name) --{ -- int i = 1, newPtr = 0; -- static char buf[20]; -- Tcl_HashEntry *entry; -- -- if (! struct_table) { -- if (! (struct_table = -- malloc(sizeof(*struct_table)))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- Tcl_InitHashTable(struct_table, TCL_STRING_KEYS); -- } -- -- do { -- sprintf(buf, "kadm5_handle%d", i); -- entry = Tcl_CreateHashEntry(struct_table, buf, &newPtr); -- i++; -- } while (! newPtr); -- -- Tcl_SetHashValue(entry, handle); -- -- *name = buf; -- -- return TCL_OK; --} -- --static int get_server_handle(Tcl_Interp *interp, const char *name, -- void **handle) --{ -- Tcl_HashEntry *entry; -- -- if(!strcasecmp(name, "null")) -- *handle = 0; -- else { -- if (! (struct_table && -- (entry = Tcl_FindHashEntry(struct_table, name)))) { -- Tcl_AppendResult(interp, "unknown server handle ", name, 0); -- return TCL_ERROR; -- } -- *handle = (void *) Tcl_GetHashValue(entry); -- } -- return TCL_OK; --} -- --static int remove_server_handle(Tcl_Interp *interp, const char *name) --{ -- Tcl_HashEntry *entry; -- -- if (! (struct_table && -- (entry = Tcl_FindHashEntry(struct_table, name)))) { -- Tcl_AppendResult(interp, "unknown server handle ", name, 0); -- return TCL_ERROR; -- } -- -- Tcl_SetHashValue(entry, NULL); -- return TCL_OK; --} -- --#define GET_HANDLE(num_args, ignored) \ -- void *server_handle; \ -- const char *whoami = argv[0]; \ -- argv++, argc--; \ -- if (argc != num_args + 1) { \ -- Tcl_AppendResult(interp, whoami, ": ", arg_error, 0); \ -- return TCL_ERROR; \ -- } \ -- { \ -- int ltcl_ret; \ -- if ((ltcl_ret = get_server_handle(interp, argv[0], &server_handle)) \ -- != TCL_OK) { \ -- return ltcl_ret; \ -- } \ -- } \ -- argv++, argc--; -- --static Tcl_HashTable *create_flag_table(struct flagval *flags, int size) --{ -- Tcl_HashTable *table; -- Tcl_HashEntry *entry; -- int i; -- -- if (! (table = (Tcl_HashTable *) malloc(sizeof(Tcl_HashTable)))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- -- Tcl_InitHashTable(table, TCL_STRING_KEYS); -- -- for (i = 0; i < size; i++) { -- int newPtr; -- -- if (! (entry = Tcl_CreateHashEntry(table, flags[i].name, &newPtr))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- -- Tcl_SetHashValue(entry, &flags[i].val); -- } -- -- return table; --} -- -- --static Tcl_DString *unparse_str(char *in_str) --{ -- Tcl_DString *str; -- -- if (! (str = malloc(sizeof(*str)))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- -- Tcl_DStringInit(str); -- -- if (! in_str) { -- Tcl_DStringAppend(str, "null", -1); -- } -- else { -- Tcl_DStringAppend(str, in_str, -1); -- } -- -- return str; --} -- -- -- --static int parse_str(Tcl_Interp *interp, const char *in_str, char **out_str) --{ -- if (! in_str) { -- *out_str = 0; -- } -- else if (! strcasecmp(in_str, "null")) { -- *out_str = 0; -- } -- else { -- *out_str = (char *) in_str; -- } -- return TCL_OK; --} -- -- --static void set_ok(Tcl_Interp *interp, char *string) --{ -- Tcl_SetResult(interp, "OK", TCL_STATIC); -- Tcl_AppendElement(interp, "KADM5_OK"); -- Tcl_AppendElement(interp, string); --} -- -- -- --static Tcl_DString *unparse_err(kadm5_ret_t code) --{ -- char *code_string; -- const char *error_string; -- Tcl_DString *dstring; -- -- switch (code) { -- case KADM5_FAILURE: code_string = "KADM5_FAILURE"; break; -- case KADM5_AUTH_GET: code_string = "KADM5_AUTH_GET"; break; -- case KADM5_AUTH_ADD: code_string = "KADM5_AUTH_ADD"; break; -- case KADM5_AUTH_MODIFY: -- code_string = "KADM5_AUTH_MODIFY"; break; -- case KADM5_AUTH_DELETE: -- code_string = "KADM5_AUTH_DELETE"; break; -- case KADM5_AUTH_INSUFFICIENT: -- code_string = "KADM5_AUTH_INSUFFICIENT"; break; -- case KADM5_BAD_DB: code_string = "KADM5_BAD_DB"; break; -- case KADM5_DUP: code_string = "KADM5_DUP"; break; -- case KADM5_RPC_ERROR: code_string = "KADM5_RPC_ERROR"; break; -- case KADM5_NO_SRV: code_string = "KADM5_NO_SRV"; break; -- case KADM5_BAD_HIST_KEY: -- code_string = "KADM5_BAD_HIST_KEY"; break; -- case KADM5_NOT_INIT: code_string = "KADM5_NOT_INIT"; break; -- case KADM5_INIT: code_string = "KADM5_INIT"; break; -- case KADM5_BAD_PASSWORD: -- code_string = "KADM5_BAD_PASSWORD"; break; -- case KADM5_UNK_PRINC: code_string = "KADM5_UNK_PRINC"; break; -- case KADM5_UNK_POLICY: code_string = "KADM5_UNK_POLICY"; break; -- case KADM5_BAD_MASK: code_string = "KADM5_BAD_MASK"; break; -- case KADM5_BAD_CLASS: code_string = "KADM5_BAD_CLASS"; break; -- case KADM5_BAD_LENGTH: code_string = "KADM5_BAD_LENGTH"; break; -- case KADM5_BAD_POLICY: code_string = "KADM5_BAD_POLICY"; break; -- case KADM5_BAD_HISTORY: code_string = "KADM5_BAD_HISTORY"; break; -- case KADM5_BAD_PRINCIPAL: -- code_string = "KADM5_BAD_PRINCIPAL"; break; -- case KADM5_BAD_AUX_ATTR: -- code_string = "KADM5_BAD_AUX_ATTR"; break; -- case KADM5_PASS_Q_TOOSHORT: -- code_string = "KADM5_PASS_Q_TOOSHORT"; break; -- case KADM5_PASS_Q_CLASS: -- code_string = "KADM5_PASS_Q_CLASS"; break; -- case KADM5_PASS_Q_DICT: -- code_string = "KADM5_PASS_Q_DICT"; break; -- case KADM5_PASS_REUSE: code_string = "KADM5_PASS_REUSE"; break; -- case KADM5_PASS_TOOSOON: -- code_string = "KADM5_PASS_TOOSOON"; break; -- case KADM5_POLICY_REF: -- code_string = "KADM5_POLICY_REF"; break; -- case KADM5_PROTECT_PRINCIPAL: -- code_string = "KADM5_PROTECT_PRINCIPAL"; break; -- case KADM5_BAD_SERVER_HANDLE: -- code_string = "KADM5_BAD_SERVER_HANDLE"; break; -- case KADM5_BAD_STRUCT_VERSION: -- code_string = "KADM5_BAD_STRUCT_VERSION"; break; -- case KADM5_OLD_STRUCT_VERSION: -- code_string = "KADM5_OLD_STRUCT_VERSION"; break; -- case KADM5_NEW_STRUCT_VERSION: -- code_string = "KADM5_NEW_STRUCT_VERSION"; break; -- case KADM5_BAD_API_VERSION: -- code_string = "KADM5_BAD_API_VERSION"; break; -- case KADM5_OLD_LIB_API_VERSION: -- code_string = "KADM5_OLD_LIB_API_VERSION"; break; -- case KADM5_OLD_SERVER_API_VERSION: -- code_string = "KADM5_OLD_SERVER_API_VERSION"; break; -- case KADM5_NEW_LIB_API_VERSION: -- code_string = "KADM5_NEW_LIB_API_VERSION"; break; -- case KADM5_NEW_SERVER_API_VERSION: -- code_string = "KADM5_NEW_SERVER_API_VERSION"; break; -- case KADM5_SECURE_PRINC_MISSING: -- code_string = "KADM5_SECURE_PRINC_MISSING"; break; -- case KADM5_NO_RENAME_SALT: -- code_string = "KADM5_NO_RENAME_SALT"; break; -- case KADM5_BAD_CLIENT_PARAMS: -- code_string = "KADM5_BAD_CLIENT_PARAMS"; break; -- case KADM5_BAD_SERVER_PARAMS: -- code_string = "KADM5_BAD_SERVER_PARAMS"; break; -- case KADM5_AUTH_LIST: -- code_string = "KADM5_AUTH_LIST"; break; -- case KADM5_AUTH_CHANGEPW: -- code_string = "KADM5_AUTH_CHANGEPW"; break; -- case KADM5_GSS_ERROR: code_string = "KADM5_GSS_ERROR"; break; -- case KADM5_BAD_TL_TYPE: code_string = "KADM5_BAD_TL_TYPE"; break; -- case KADM5_MISSING_CONF_PARAMS: -- code_string = "KADM5_MISSING_CONF_PARAMS"; break; -- case KADM5_BAD_SERVER_NAME: -- code_string = "KADM5_BAD_SERVER_NAME"; break; -- case KADM5_MISSING_KRB5_CONF_PARAMS: -- code_string = "KADM5_MISSING_KRB5_CONF_PARAMS"; break; -- case KADM5_XDR_FAILURE: code_string = "KADM5_XDR_FAILURE"; break; -- case KADM5_CANT_RESOLVE: code_string = "KADM5_CANT_RESOLVE"; break; -- -- -- case OSA_ADB_DUP: code_string = "OSA_ADB_DUP"; break; -- case OSA_ADB_NOENT: code_string = "ENOENT"; break; -- case OSA_ADB_DBINIT: code_string = "OSA_ADB_DBINIT"; break; -- case OSA_ADB_BAD_POLICY: code_string = "Bad policy name"; break; -- case OSA_ADB_BAD_PRINC: code_string = "Bad principal name"; break; -- case OSA_ADB_BAD_DB: code_string = "Invalid database."; break; -- case OSA_ADB_XDR_FAILURE: code_string = "OSA_ADB_XDR_FAILURE"; break; -- case OSA_ADB_BADLOCKMODE: code_string = "OSA_ADB_BADLOCKMODE"; break; -- case OSA_ADB_CANTLOCK_DB: code_string = "OSA_ADB_CANTLOCK_DB"; break; -- case OSA_ADB_NOTLOCKED: code_string = "OSA_ADB_NOTLOCKED"; break; -- case OSA_ADB_NOLOCKFILE: code_string = "OSA_ADB_NOLOCKFILE"; break; -- case OSA_ADB_NOEXCL_PERM: code_string = "OSA_ADB_NOEXCL_PERM"; break; -- -- case KRB5_KDB_INUSE: code_string = "KRB5_KDB_INUSE"; break; -- case KRB5_KDB_UK_SERROR: code_string = "KRB5_KDB_UK_SERROR"; break; -- case KRB5_KDB_UK_RERROR: code_string = "KRB5_KDB_UK_RERROR"; break; -- case KRB5_KDB_UNAUTH: code_string = "KRB5_KDB_UNAUTH"; break; -- case KRB5_KDB_NOENTRY: code_string = "KRB5_KDB_NOENTRY"; break; -- case KRB5_KDB_ILL_WILDCARD: code_string = "KRB5_KDB_ILL_WILDCARD"; break; -- case KRB5_KDB_DB_INUSE: code_string = "KRB5_KDB_DB_INUSE"; break; -- case KRB5_KDB_DB_CHANGED: code_string = "KRB5_KDB_DB_CHANGED"; break; -- case KRB5_KDB_TRUNCATED_RECORD: -- code_string = "KRB5_KDB_TRUNCATED_RECORD"; break; -- case KRB5_KDB_RECURSIVELOCK: -- code_string = "KRB5_KDB_RECURSIVELOCK"; break; -- case KRB5_KDB_NOTLOCKED: code_string = "KRB5_KDB_NOTLOCKED"; break; -- case KRB5_KDB_BADLOCKMODE: code_string = "KRB5_KDB_BADLOCKMODE"; break; -- case KRB5_KDB_DBNOTINITED: code_string = "KRB5_KDB_DBNOTINITED"; break; -- case KRB5_KDB_DBINITED: code_string = "KRB5_KDB_DBINITED"; break; -- case KRB5_KDB_ILLDIRECTION: code_string = "KRB5_KDB_ILLDIRECTION"; break; -- case KRB5_KDB_NOMASTERKEY: code_string = "KRB5_KDB_NOMASTERKEY"; break; -- case KRB5_KDB_BADMASTERKEY: code_string = "KRB5_KDB_BADMASTERKEY"; break; -- case KRB5_KDB_INVALIDKEYSIZE: -- code_string = "KRB5_KDB_INVALIDKEYSIZE"; break; -- case KRB5_KDB_CANTREAD_STORED: -- code_string = "KRB5_KDB_CANTREAD_STORED"; break; -- case KRB5_KDB_BADSTORED_MKEY: -- code_string = "KRB5_KDB_BADSTORED_MKEY"; break; -- case KRB5_KDB_CANTLOCK_DB: code_string = "KRB5_KDB_CANTLOCK_DB"; break; -- case KRB5_KDB_DB_CORRUPT: code_string = "KRB5_KDB_DB_CORRUPT"; break; -- -- case KRB5_PARSE_ILLCHAR: code_string = "KRB5_PARSE_ILLCHAR"; break; -- case KRB5_PARSE_MALFORMED: code_string = "KRB5_PARSE_MALFORMED"; break; -- case KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN: code_string = "KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN"; break; -- case KRB5_REALM_UNKNOWN: code_string = "KRB5_REALM_UNKNOWN"; break; -- case KRB5_KDC_UNREACH: code_string = "KRB5_KDC_UNREACH"; break; -- case KRB5_KDCREP_MODIFIED: code_string = "KRB5_KDCREP_MODIFIED"; break; -- case KRB5KRB_AP_ERR_BAD_INTEGRITY: code_string = "KRB5KRB_AP_ERR_BAD_INTEGRITY"; break; -- case KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN: code_string = "KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN"; break; -- case KRB5_CONFIG_BADFORMAT: code_string = "KRB5_CONFIG_BADFORMAT"; break; -- -- case KRB5_CC_NOTFOUND: code_string = "KRB5_CC_NOTFOUND"; break; -- case KRB5_FCC_NOFILE: code_string = "KRB5_FCC_NOFILE"; break; -- -- case EINVAL: code_string = "EINVAL"; break; -- case ENOENT: code_string = "ENOENT"; break; -- -- default: -- fprintf(stderr, "**** CODE %ld (%s) ***\n", (long) code, -- error_message (code)); -- code_string = "UNKNOWN"; -- break; -- } -- -- error_string = error_message(code); -- -- if (! (dstring = (Tcl_DString *) malloc(sizeof(Tcl_DString)))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX Do we really want to exit? Ok if this is */ -- /* just a test program, but what about if it gets */ -- /* used for other things later? */ -- } -- -- Tcl_DStringInit(dstring); -- -- if (! (Tcl_DStringAppendElement(dstring, "ERROR") && -- Tcl_DStringAppendElement(dstring, code_string) && -- Tcl_DStringAppendElement(dstring, error_string))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- -- return dstring; --} -- -- -- --static void stash_error(Tcl_Interp *interp, krb5_error_code code) --{ -- Tcl_DString *dstring = unparse_err(code); -- Tcl_DStringResult(interp, dstring); -- Tcl_DStringFree(dstring); -- free(dstring); --} -- --static Tcl_DString *unparse_key_data(krb5_key_data *key_data, int n_key_data) --{ -- Tcl_DString *str; -- char buf[2048]; -- int i, j; -- -- if (! (str = malloc(sizeof(*str)))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- -- Tcl_DStringInit(str); -- for (i = 0; i < n_key_data; i++) { -- krb5_key_data *key = &key_data[i]; -- -- Tcl_DStringStartSublist(str); -- sprintf(buf, "%d", key->key_data_type[0]); -- Tcl_DStringAppendElement(str, buf); -- sprintf(buf, "%d", key->key_data_ver > 1 ? -- key->key_data_type[1] : -1); -- Tcl_DStringAppendElement(str, buf); -- if (key->key_data_contents[0]) { -- sprintf(buf, "0x"); -- for (j = 0; j < key->key_data_length[0]; j++) { -- sprintf(buf + 2*(j+1), "%02x", -- key->key_data_contents[0][j]); -- } -- } else *buf = '\0'; -- Tcl_DStringAppendElement(str, buf); -- Tcl_DStringEndSublist(str); -- } -- -- return str; --} -- --static Tcl_DString *unparse_tl_data(krb5_tl_data *tl_data, int n_tl_data) --{ -- Tcl_DString *str; -- char buf[2048]; -- -- if (! (str = malloc(sizeof(*str)))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- -- Tcl_DStringInit(str); -- Tcl_DStringStartSublist(str); -- for (; tl_data; tl_data = tl_data->tl_data_next) { -- Tcl_DStringStartSublist(str); -- sprintf(buf, "%d", tl_data->tl_data_type); -- Tcl_DStringAppendElement(str, buf); -- sprintf(buf, "%d", tl_data->tl_data_length); -- Tcl_DStringAppendElement(str, buf); -- Tcl_DStringAppend(str, " ", 1); -- Tcl_DStringAppend(str, (char *) tl_data->tl_data_contents, -- tl_data->tl_data_length); -- Tcl_DStringEndSublist(str); -- } -- Tcl_DStringEndSublist(str); -- -- return str; --} -- --static Tcl_DString *unparse_flags(struct flagval *array, int size, -- krb5_int32 flags) --{ -- int i; -- Tcl_DString *str; -- -- if (! (str = malloc(sizeof(*str)))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- -- Tcl_DStringInit(str); -- -- for (i = 0; i < size; i++) { -- if (flags & array[i].val) { -- Tcl_DStringAppendElement(str, array[i].name); -- } -- } -- -- return str; --} -- -- --static int parse_flags(Tcl_Interp *interp, Tcl_HashTable *table, -- struct flagval *array, int size, const char *str, -- krb5_flags *flags) --{ -- int tmp, argc, i, retcode = TCL_OK; -- const char **argv; -- Tcl_HashEntry *entry; -- -- if (Tcl_GetInt(interp, str, &tmp) == TCL_OK) { -- *flags = tmp; -- return TCL_OK; -- } -- Tcl_ResetResult(interp); -- -- if (Tcl_SplitList(interp, str, &argc, &argv) != TCL_OK) { -- return TCL_ERROR; -- } -- -- if (! table) { -- table = create_flag_table(array, size); -- } -- -- *flags = 0; -- -- for (i = 0; i < argc; i++) { -- if (! (entry = Tcl_FindHashEntry(table, argv[i]))) { -- Tcl_AppendResult(interp, "unknown krb5 flag ", argv[i], 0); -- retcode = TCL_ERROR; -- break; -- } -- *flags |= *(krb5_flags *) Tcl_GetHashValue(entry); -- } -- -- Tcl_Free((char *) argv); -- return(retcode); --} -- --static Tcl_DString *unparse_privs(krb5_flags flags) --{ -- return unparse_flags(priv_flags, sizeof(priv_flags) / -- sizeof(struct flagval), flags); --} -- -- --static Tcl_DString *unparse_krb5_flags(krb5_flags flags) --{ -- return unparse_flags(krb5_flags_array, sizeof(krb5_flags_array) / -- sizeof(struct flagval), flags); --} -- --static int parse_krb5_flags(Tcl_Interp *interp, const char *str, -- krb5_flags *flags) --{ -- krb5_flags tmp; -- static Tcl_HashTable *table = 0; -- int tcl_ret; -- -- if ((tcl_ret = parse_flags(interp, table, krb5_flags_array, -- sizeof(krb5_flags_array) / -- sizeof(struct flagval), -- str, &tmp)) != TCL_OK) { -- return tcl_ret; -- } -- -- *flags = tmp; -- return TCL_OK; --} -- --static Tcl_DString *unparse_aux_attributes(krb5_int32 flags) --{ -- return unparse_flags(aux_attributes, sizeof(aux_attributes) / -- sizeof(struct flagval), flags); --} -- -- --static int parse_aux_attributes(Tcl_Interp *interp, const char *str, -- long *flags) --{ -- krb5_flags tmp; -- static Tcl_HashTable *table = 0; -- int tcl_ret; -- -- if ((tcl_ret = parse_flags(interp, table, aux_attributes, -- sizeof(aux_attributes) / -- sizeof(struct flagval), -- str, &tmp)) != TCL_OK) { -- return tcl_ret; -- } -- -- *flags = tmp; -- return TCL_OK; --} -- --static int parse_principal_mask(Tcl_Interp *interp, const char *str, -- krb5_int32 *flags) --{ -- krb5_flags tmp; -- static Tcl_HashTable *table = 0; -- int tcl_ret; -- -- if ((tcl_ret = parse_flags(interp, table, principal_mask_flags, -- sizeof(principal_mask_flags) / -- sizeof(struct flagval), -- str, &tmp)) != TCL_OK) { -- return tcl_ret; -- } -- -- *flags = tmp; -- return TCL_OK; --} -- --static int parse_policy_mask(Tcl_Interp *interp, const char *str, -- krb5_int32 *flags) --{ -- krb5_flags tmp; -- static Tcl_HashTable *table = 0; -- int tcl_ret; -- -- if ((tcl_ret = parse_flags(interp, table, policy_mask_flags, -- sizeof(policy_mask_flags) / -- sizeof(struct flagval), -- str, &tmp)) != TCL_OK) { -- return tcl_ret; -- } -- -- *flags = tmp; -- return TCL_OK; --} -- -- --static Tcl_DString *unparse_principal_ent(kadm5_principal_ent_t princ, -- krb5_int32 mask) --{ -- Tcl_DString *str, *tmp_dstring; -- char *tmp; -- char buf[20]; -- krb5_error_code krb5_ret; -- -- if (! (str = malloc(sizeof(*str)))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- -- Tcl_DStringInit(str); -- -- tmp = 0; /* It looks to me from looking at the library source */ -- /* code for krb5_parse_name that the pointer passed into */ -- /* it should be initialized to 0 if I want it do be */ -- /* allocated automatically. */ -- if (mask & KADM5_PRINCIPAL) { -- krb5_ret = krb5_unparse_name(context, princ->principal, &tmp); -- if (krb5_ret) { -- /* XXX Do we want to return an error? Not sure. */ -- Tcl_DStringAppendElement(str, "[unparsable principal]"); -- } -- else { -- Tcl_DStringAppendElement(str, tmp); -- free(tmp); -- } -- } else -- Tcl_DStringAppendElement(str, "null"); -- -- sprintf(buf, "%u", (unsigned int)princ->princ_expire_time); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%u", (unsigned int)princ->last_pwd_change); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%u", (unsigned int)princ->pw_expiration); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%d", princ->max_life); -- Tcl_DStringAppendElement(str, buf); -- -- tmp = 0; -- if (mask & KADM5_MOD_NAME) { -- if ((krb5_ret = krb5_unparse_name(context, princ->mod_name, &tmp))) { -- /* XXX */ -- Tcl_DStringAppendElement(str, "[unparsable principal]"); -- } -- else { -- Tcl_DStringAppendElement(str, tmp); -- free(tmp); -- } -- } else -- Tcl_DStringAppendElement(str, "null"); -- -- sprintf(buf, "%u", (unsigned int)princ->mod_date); -- Tcl_DStringAppendElement(str, buf); -- -- if (mask & KADM5_ATTRIBUTES) { -- tmp_dstring = unparse_krb5_flags(princ->attributes); -- Tcl_DStringAppendElement(str, tmp_dstring->string); -- Tcl_DStringFree(tmp_dstring); -- free(tmp_dstring); -- } else -- Tcl_DStringAppendElement(str, "null"); -- -- sprintf(buf, "%d", princ->kvno); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%d", princ->mkvno); -- Tcl_DStringAppendElement(str, buf); -- -- /* XXX This may be dangerous, because the contents of the policy */ -- /* field are undefined if the POLICY bit isn't set. However, I */ -- /* think it's a bug for the field not to be null in that case */ -- /* anyway, so we should assume that it will be null so that we'll */ -- /* catch it if it isn't. */ -- -- tmp_dstring = unparse_str(princ->policy); -- Tcl_DStringAppendElement(str, tmp_dstring->string); -- Tcl_DStringFree(tmp_dstring); -- free(tmp_dstring); -- -- tmp_dstring = unparse_aux_attributes(princ->aux_attributes); -- Tcl_DStringAppendElement(str, tmp_dstring->string); -- Tcl_DStringFree(tmp_dstring); -- free(tmp_dstring); -- -- sprintf(buf, "%d", princ->max_renewable_life); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%u", (unsigned int)princ->last_success); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%u", (unsigned int)princ->last_failed); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%d", princ->fail_auth_count); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%d", princ->n_key_data); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%d", princ->n_tl_data); -- Tcl_DStringAppendElement(str, buf); -- -- tmp_dstring = unparse_key_data(princ->key_data, princ->n_key_data); -- Tcl_DStringAppendElement(str, tmp_dstring->string); -- Tcl_DStringFree(tmp_dstring); -- free(tmp_dstring); -- -- tmp_dstring = unparse_tl_data(princ->tl_data, princ->n_tl_data); -- Tcl_DStringAppendElement(str, tmp_dstring->string); -- Tcl_DStringFree(tmp_dstring); -- free(tmp_dstring); -- -- return str; --} -- --static int parse_keysalts(Tcl_Interp *interp, const char *list, -- krb5_key_salt_tuple **keysalts, -- int num_keysalts) --{ -- const char **argv, **argv1 = NULL; -- int i, tmp, argc, argc1, retcode; -- -- *keysalts = NULL; -- if (list == NULL) -- return TCL_OK; -- -- if ((retcode = Tcl_SplitList(interp, list, &argc, &argv)) != TCL_OK) { -- return retcode; -- } -- if (argc != num_keysalts) { -- Tcl_SetResult(interp, "wrong number of keysalts", TCL_STATIC); -- retcode = TCL_ERROR; -- goto finished; -- } -- *keysalts = (krb5_key_salt_tuple *) -- malloc(sizeof(krb5_key_salt_tuple)*num_keysalts); -- for (i = 0; i < num_keysalts; i++) { -- if ((retcode = Tcl_SplitList(interp, argv[i], &argc1, &argv1)) != -- TCL_OK) { -- goto finished; -- } -- if (argc1 != 2) { -- Tcl_SetResult(interp, "wrong # of fields in keysalt", TCL_STATIC); -- retcode = TCL_ERROR; -- goto finished; -- } -- /* XXX this used to be argv1[1] too! */ -- if ((retcode = Tcl_GetInt(interp, argv1[0], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing ks_enctype"); -- retcode = TCL_ERROR; -- goto finished; -- } -- (*keysalts)[i].ks_enctype = tmp; -- if ((retcode = Tcl_GetInt(interp, argv1[1], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing ks_salttype"); -- goto finished; -- } -- (*keysalts)[i].ks_salttype = tmp; -- -- Tcl_Free((char *) argv1); -- argv1 = NULL; -- } -- --finished: -- if (argv1) { -- Tcl_Free((char *) argv1); -- } -- Tcl_Free((char *) argv); -- return retcode; --} -- --static int parse_key_data(Tcl_Interp *interp, const char *list, -- krb5_key_data **key_data, -- int n_key_data) --{ -- const char **argv = NULL; -- int argc, retcode; -- -- *key_data = NULL; -- if (list == NULL) { -- if (n_key_data != 0) { -- Tcl_SetResult(interp, "wrong number of key_datas", TCL_STATIC); -- retcode = TCL_ERROR; -- goto finished; -- } else -- return TCL_OK; -- } -- -- if ((retcode = Tcl_SplitList(interp, list, &argc, &argv)) != TCL_OK) { -- return retcode; -- } -- if (argc != n_key_data) { -- Tcl_SetResult(interp, "wrong number of key_datas", TCL_STATIC); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- if (argc != 0) { -- Tcl_SetResult(interp, "cannot parse key_data yet", TCL_STATIC); -- retcode = TCL_ERROR; -- goto finished; -- } -- --finished: -- Tcl_Free((char *) argv); -- return retcode; --} -- --static int parse_tl_data(Tcl_Interp *interp, const char *list, -- krb5_tl_data **tlp, -- int n_tl_data) --{ -- krb5_tl_data *tl, *tl2; -- const char **argv = NULL, **argv1 = NULL; -- int i, tmp, argc, argc1, retcode; -- -- *tlp = NULL; -- if (list == NULL) { -- if (n_tl_data != 0) { -- Tcl_SetResult(interp, "wrong number of tl_datas", TCL_STATIC); -- retcode = TCL_ERROR; -- goto finished; -- } else -- return TCL_OK; -- } -- -- if ((retcode = Tcl_SplitList(interp, list, &argc, &argv)) != TCL_OK) { -- return retcode; -- } -- if (argc != n_tl_data) { -- Tcl_SetResult(interp, "wrong number of tl_datas", TCL_STATIC); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- tl = tl2 = NULL; -- for (i = 0; i < n_tl_data; i++) { -- tl2 = (krb5_tl_data *) malloc(sizeof(krb5_tl_data)); -- memset(tl2, 0, sizeof(krb5_tl_data)); -- tl2->tl_data_next = tl; -- tl = tl2; -- } -- tl2 = tl; -- -- for (i = 0; i < n_tl_data; i++) { -- if ((retcode = Tcl_SplitList(interp, argv[i], &argc1, &argv1)) != -- TCL_OK) { -- goto finished; -- } -- if (argc1 != 3) { -- Tcl_SetResult(interp, "wrong # of fields in tl_data", TCL_STATIC); -- retcode = TCL_ERROR; -- goto finished; -- } -- if ((retcode = Tcl_GetInt(interp, argv1[0], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing tl_data_type"); -- retcode = TCL_ERROR; -- goto finished; -- } -- tl->tl_data_type = tmp; -- if ((retcode = Tcl_GetInt(interp, argv1[1], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing tl_data_length"); -- retcode = TCL_ERROR; -- goto finished; -- } -- tl->tl_data_length = tmp; -- if (tl->tl_data_length != strlen(argv1[2])) { -- Tcl_SetResult(interp, "length != string length", TCL_STATIC); -- retcode = TCL_ERROR; -- goto finished; -- } -- tl->tl_data_contents = (krb5_octet *) strdup(argv1[2]); -- -- Tcl_Free((char *) argv1); -- argv1 = NULL; -- tl = tl->tl_data_next; -- } -- if (tl != NULL) { -- Tcl_SetResult(interp, "tl is not NULL!", TCL_STATIC); -- retcode = TCL_ERROR; -- goto finished; -- } -- *tlp = tl2; -- --finished: -- if (argv1) { -- Tcl_Free((char *) argv1); -- } -- Tcl_Free((char *) argv); -- return retcode; --} -- --static int parse_config_params(Tcl_Interp *interp, char *list, -- kadm5_config_params *params) --{ -- static Tcl_HashTable *table = 0; -- const char **argv = NULL; -- int tmp, argc, retcode; -- -- memset(params, 0, sizeof(kadm5_config_params)); -- if (list == NULL) -- return TCL_OK; -- -- if ((retcode = Tcl_SplitList(interp, list, &argc, &argv)) != TCL_OK) { -- return retcode; -- } -- -- if (argc != 20) { -- Tcl_SetResult(interp, "wrong # args in config params structure", -- TCL_STATIC); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- if ((retcode = parse_flags(interp, table, config_mask_flags, -- sizeof(config_mask_flags) / -- sizeof(struct flagval), -- argv[0], &tmp)) != TCL_OK) { -- goto finished; -- } -- params->mask = tmp; -- -- if ((retcode = parse_str(interp, argv[1], ¶ms->realm)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing realm name"); -- retcode = TCL_ERROR; -- goto finished; -- } -- if ((retcode = Tcl_GetInt(interp, argv[2], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing kadmind_port"); -- retcode = TCL_ERROR; -- goto finished; -- } -- params->kadmind_port = tmp; -- if ((retcode = parse_str(interp, argv[3], ¶ms->admin_server)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing profile name"); -- retcode = TCL_ERROR; -- goto finished; -- } -- if ((retcode = parse_str(interp, argv[4], ¶ms->dbname)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing profile name"); -- retcode = TCL_ERROR; -- goto finished; -- } -- /* Ignore argv[5], which used to set the admin_dbname field. */ -- /* Ignore argv[6], which used to set the admin_lockfile field. */ -- /* Ignore argv[7], which used to set the admin_keytab field. */ -- if ((retcode = parse_str(interp, argv[8], ¶ms->acl_file)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing acl_file name"); -- retcode = TCL_ERROR; -- goto finished; -- } -- if ((retcode = parse_str(interp, argv[9], ¶ms->dict_file)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing dict_file name"); -- retcode = TCL_ERROR; -- goto finished; -- } -- if ((retcode = Tcl_GetInt(interp, argv[10], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing mkey_from_kbd"); -- retcode = TCL_ERROR; -- goto finished; -- } -- params->mkey_from_kbd = tmp; -- if ((retcode = parse_str(interp, argv[11], ¶ms->stash_file)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing stash_file name"); -- retcode = TCL_ERROR; -- goto finished; -- } -- if ((retcode = parse_str(interp, argv[12], ¶ms->mkey_name)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing mkey_name name"); -- retcode = TCL_ERROR; -- goto finished; -- } -- if ((retcode = Tcl_GetInt(interp, argv[13], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing enctype"); -- retcode = TCL_ERROR; -- goto finished; -- } -- params->enctype = tmp; -- if ((retcode = Tcl_GetInt(interp, argv[14], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing max_life"); -- retcode = TCL_ERROR; -- goto finished; -- } -- params->max_life = tmp; -- if ((retcode = Tcl_GetInt(interp, argv[15], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing max_rlife"); -- retcode = TCL_ERROR; -- goto finished; -- } -- params->max_rlife = tmp; -- if ((retcode = Tcl_GetInt(interp, argv[16], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing expiration"); -- retcode = TCL_ERROR; -- goto finished; -- } -- params->expiration = tmp; -- if ((retcode = parse_krb5_flags(interp, argv[17], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing flags"); -- retcode = TCL_ERROR; -- goto finished; -- } -- params->flags = tmp; -- if ((retcode = Tcl_GetInt(interp, argv[18], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing num_keysalts"); -- retcode = TCL_ERROR; -- goto finished; -- } -- params->num_keysalts = tmp; -- if ((retcode = parse_keysalts(interp, argv[19], ¶ms->keysalts, -- params->num_keysalts)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing keysalts"); -- retcode = TCL_ERROR; -- goto finished; -- } -- --finished: -- return retcode; --} -- --static int parse_principal_ent(Tcl_Interp *interp, char *list, -- kadm5_principal_ent_t *out_princ) --{ -- kadm5_principal_ent_t princ = 0; -- krb5_error_code krb5_ret; -- int tcl_ret; -- int argc; -- const char **argv; -- int tmp; -- int retcode = TCL_OK; -- -- if ((tcl_ret = Tcl_SplitList(interp, list, &argc, &argv)) != TCL_OK) { -- return tcl_ret; -- } -- -- if (argc != 12 && argc != 20) { -- Tcl_SetResult(interp, "wrong # args in principal structure", -- TCL_STATIC); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- if (! (princ = malloc(sizeof *princ))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- memset(princ, 0, sizeof(*princ)); -- -- if ((krb5_ret = krb5_parse_name(context, argv[0], &princ->principal)) != 0) { -- stash_error(interp, krb5_ret); -- Tcl_AppendElement(interp, "while parsing principal"); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- /* -- * All of the numerical values parsed here are parsed into an -- * "int" and then assigned into the structure in case the actual -- * width of the field in the Kerberos structure is different from -- * the width of an integer. -- */ -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[1], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing princ_expire_time"); -- retcode = TCL_ERROR; -- goto finished; -- } -- princ->princ_expire_time = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[2], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing last_pwd_change"); -- retcode = TCL_ERROR; -- goto finished; -- } -- princ->last_pwd_change = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[3], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing pw_expiration"); -- retcode = TCL_ERROR; -- goto finished; -- } -- princ->pw_expiration = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[4], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing max_life"); -- retcode = TCL_ERROR; -- goto finished; -- } -- princ->max_life = tmp; -- -- if ((krb5_ret = krb5_parse_name(context, argv[5], &princ->mod_name)) != 0) { -- stash_error(interp, krb5_ret); -- Tcl_AppendElement(interp, "while parsing mod_name"); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[6], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing mod_date"); -- retcode = TCL_ERROR; -- goto finished; -- } -- princ->mod_date = tmp; -- -- if ((tcl_ret = parse_krb5_flags(interp, argv[7], &princ->attributes)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing attributes"); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[8], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing kvno"); -- retcode = TCL_ERROR; -- goto finished; -- } -- princ->kvno = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[9], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing mkvno"); -- retcode = TCL_ERROR; -- goto finished; -- } -- princ->mkvno = tmp; -- -- if ((tcl_ret = parse_str(interp, argv[10], &princ->policy)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing policy"); -- retcode = TCL_ERROR; -- goto finished; -- } -- if(princ->policy != NULL) { -- if(!(princ->policy = strdup(princ->policy))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); -- } -- } -- -- if ((tcl_ret = parse_aux_attributes(interp, argv[11], -- &princ->aux_attributes)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing aux_attributes"); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- if (argc == 12) goto finished; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[12], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing max_renewable_life"); -- retcode = TCL_ERROR; -- goto finished; -- } -- princ->max_renewable_life = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[13], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing last_success"); -- retcode = TCL_ERROR; -- goto finished; -- } -- princ->last_success = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[14], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing last_failed"); -- retcode = TCL_ERROR; -- goto finished; -- } -- princ->last_failed = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[15], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing fail_auth_count"); -- retcode = TCL_ERROR; -- goto finished; -- } -- princ->fail_auth_count = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[16], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing n_key_data"); -- retcode = TCL_ERROR; -- goto finished; -- } -- princ->n_key_data = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[17], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing n_tl_data"); -- retcode = TCL_ERROR; -- goto finished; -- } -- princ->n_tl_data = tmp; -- -- if ((tcl_ret = parse_key_data(interp, argv[18], -- &princ->key_data, -- princ->n_key_data)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing key_data"); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- if ((tcl_ret = parse_tl_data(interp, argv[19], -- &princ->tl_data, -- princ->n_tl_data)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing tl_data"); -- retcode = TCL_ERROR; -- goto finished; -- } -- princ->n_tl_data = tmp; -- --finished: -- Tcl_Free((char *) argv); -- *out_princ = princ; -- return retcode; --} -- -- --static void free_principal_ent(kadm5_principal_ent_t *princ) --{ -- krb5_free_principal(context, (*princ)->principal); -- krb5_free_principal(context, (*princ)->mod_name); -- free((*princ)->policy); -- free(*princ); -- *princ = 0; --} -- --static Tcl_DString *unparse_policy_ent(kadm5_policy_ent_t policy) --{ -- Tcl_DString *str, *tmp_dstring; -- char buf[20]; -- -- if (! (str = malloc(sizeof(*str)))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- -- Tcl_DStringInit(str); -- -- tmp_dstring = unparse_str(policy->policy); -- Tcl_DStringAppendElement(str, tmp_dstring->string); -- Tcl_DStringFree(tmp_dstring); -- free(tmp_dstring); -- -- sprintf(buf, "%ld", policy->pw_min_life); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%ld", policy->pw_max_life); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%ld", policy->pw_min_length); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%ld", policy->pw_min_classes); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%ld", policy->pw_history_num); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%ld", policy->policy_refcnt); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%d", policy->pw_max_fail); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%d", policy->pw_failcnt_interval); -- Tcl_DStringAppendElement(str, buf); -- -- sprintf(buf, "%d", policy->pw_lockout_duration); -- Tcl_DStringAppendElement(str, buf); -- -- return str; --} -- -- -- --static int parse_policy_ent(Tcl_Interp *interp, char *list, -- kadm5_policy_ent_t *out_policy) --{ -- kadm5_policy_ent_t policy = 0; -- int tcl_ret; -- int argc; -- const char **argv; -- int tmp; -- int retcode = TCL_OK; -- -- if ((tcl_ret = Tcl_SplitList(interp, list, &argc, &argv)) != TCL_OK) { -- return tcl_ret; -- } -- -- if (argc != 7 && argc != 10) { -- Tcl_SetResult(interp, "wrong # args in policy structure", TCL_STATIC); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- if (! (policy = malloc(sizeof *policy))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- -- if ((tcl_ret = parse_str(interp, argv[0], &policy->policy)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing policy name"); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- if(policy->policy != NULL) { -- if (! (policy->policy = strdup(policy->policy))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- } -- -- /* -- * All of the numerical values parsed here are parsed into an -- * "int" and then assigned into the structure in case the actual -- * width of the field in the Kerberos structure is different from -- * the width of an integer. -- */ -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[1], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing pw_min_life"); -- retcode = TCL_ERROR; -- goto finished; -- } -- policy->pw_min_life = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[2], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing pw_max_life"); -- retcode = TCL_ERROR; -- goto finished; -- } -- policy->pw_max_life = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[3], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing pw_min_length"); -- retcode = TCL_ERROR; -- goto finished; -- } -- policy->pw_min_length = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[4], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing pw_min_classes"); -- retcode = TCL_ERROR; -- goto finished; -- } -- policy->pw_min_classes = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[5], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing pw_history_num"); -- retcode = TCL_ERROR; -- goto finished; -- } -- policy->pw_history_num = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[6], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing policy_refcnt"); -- retcode = TCL_ERROR; -- goto finished; -- } -- policy->policy_refcnt = tmp; -- -- if (argc == 7) goto finished; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[7], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing pw_max_fail"); -- retcode = TCL_ERROR; -- goto finished; -- } -- policy->pw_max_fail = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[8], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing pw_failcnt_interval"); -- retcode = TCL_ERROR; -- goto finished; -- } -- policy->pw_failcnt_interval = tmp; -- -- if ((tcl_ret = Tcl_GetInt(interp, argv[9], &tmp)) -- != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing pw_lockout_duration"); -- retcode = TCL_ERROR; -- goto finished; -- } -- policy->pw_lockout_duration = tmp; -- --finished: -- Tcl_Free((char *) argv); -- *out_policy = policy; -- return retcode; --} -- -- --static void free_policy_ent(kadm5_policy_ent_t *policy) --{ -- free((*policy)->policy); -- free(*policy); -- *policy = 0; --} -- --static Tcl_DString *unparse_keytype(krb5_enctype enctype) --{ -- Tcl_DString *str; -- char buf[50]; -- -- if (! (str = malloc(sizeof(*str)))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- -- Tcl_DStringInit(str); -- -- switch (enctype) { -- /* XXX is this right? */ -- case ENCTYPE_NULL: Tcl_DStringAppend(str, "ENCTYPE_NULL", -1); break; -- default: -- sprintf(buf, "UNKNOWN KEYTYPE (0x%x)", enctype); -- Tcl_DStringAppend(str, buf, -1); -- break; -- } -- -- return str; --} -- -- --static Tcl_DString *unparse_keyblocks(krb5_keyblock *keyblocks, int num_keys) --{ -- Tcl_DString *str; -- Tcl_DString *keytype; -- unsigned int i; -- int j; -- -- if (! (str = malloc(sizeof(*str)))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- -- Tcl_DStringInit(str); -- -- for (j = 0; j < num_keys; j++) { -- krb5_keyblock *keyblock = &keyblocks[j]; -- -- Tcl_DStringStartSublist(str); -- -- keytype = unparse_keytype(keyblock->enctype); -- Tcl_DStringAppendElement(str, keytype->string); -- Tcl_DStringFree(keytype); -- free(keytype); -- if (keyblock->length == 0) { -- Tcl_DStringAppendElement(str, "0x00"); -- } -- else { -- Tcl_DStringAppendElement(str, "0x"); -- for (i = 0; i < keyblock->length; i++) { -- char buf[3]; -- sprintf(buf, "%02x", (int) keyblock->contents[i]); -- Tcl_DStringAppend(str, buf, -1); -- } -- } -- -- Tcl_DStringEndSublist(str); -- } -- -- -- return str; --} -- --enum init_type { INIT_NONE, INIT_PASS, INIT_CREDS }; -- --static int _tcl_kadm5_init_any(enum init_type init_type, ClientData clientData, -- Tcl_Interp *interp, int argc, const char *argv[]) --{ -- kadm5_ret_t ret; -- char *client_name, *pass, *service_name; -- int tcl_ret; -- krb5_ui_4 struct_version, api_version; -- const char *handle_var; -- void *server_handle; -- char *handle_name, *params_str; -- const char *whoami = argv[0]; -- kadm5_config_params params; -- -- argv++, argc--; -- -- kadm5_init_krb5_context(&context); -- -- if (argc != 7) { -- Tcl_AppendResult(interp, whoami, ": ", arg_error, 0); -- return TCL_ERROR; -- } -- -- if (((tcl_ret = parse_str(interp, argv[0], &client_name)) != TCL_OK) || -- ((tcl_ret = parse_str(interp, argv[1], &pass)) != TCL_OK) || -- ((tcl_ret = parse_str(interp, argv[2], &service_name)) != TCL_OK) || -- ((tcl_ret = parse_str(interp, argv[3], ¶ms_str)) != TCL_OK) || -- ((tcl_ret = parse_config_params(interp, params_str, ¶ms)) -- != TCL_OK) || -- ((tcl_ret = Tcl_GetInt(interp, argv[4], (int *) &struct_version)) != -- TCL_OK) || -- ((tcl_ret = Tcl_GetInt(interp, argv[5], (int *) &api_version)) != -- TCL_OK)) { -- return tcl_ret; -- } -- -- handle_var = argv[6]; -- -- if (! (handle_var && *handle_var)) { -- Tcl_SetResult(interp, "must specify server handle variable name", -- TCL_STATIC); -- return TCL_ERROR; -- } -- -- if (init_type == INIT_CREDS) { -- krb5_ccache cc; -- -- if (pass == NULL) { -- if ((ret = krb5_cc_default(context, &cc))) { -- stash_error(interp, ret); -- return TCL_ERROR; -- } -- } else { -- if ((ret = krb5_cc_resolve(context, pass, &cc))) { -- stash_error(interp, ret); -- return TCL_ERROR; -- } -- } -- -- ret = kadm5_init_with_creds(context, client_name, cc, service_name, -- ¶ms, struct_version, -- api_version, NULL, &server_handle); -- -- (void) krb5_cc_close(context, cc); -- } else -- ret = kadm5_init(context, client_name, pass, service_name, ¶ms, -- struct_version, api_version, NULL, &server_handle); -- -- /* The string fields of params are aliases into argv[3], but -- * params.keysalts is allocated, so clean it up. */ -- free(params.keysalts); -- -- if (ret != KADM5_OK) { -- stash_error(interp, ret); -- return TCL_ERROR; -- } -- -- if ((tcl_ret = put_server_handle(interp, server_handle, &handle_name)) -- != TCL_OK) { -- return tcl_ret; -- } -- -- if (! Tcl_SetVar(interp, handle_var, handle_name, TCL_LEAVE_ERR_MSG)) { -- return TCL_ERROR; -- } -- -- set_ok(interp, "KADM5 API initialized."); -- return TCL_OK; --} -- --static int tcl_kadm5_init(ClientData clientData, Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- return _tcl_kadm5_init_any(INIT_PASS, clientData, interp, argc, argv); --} -- --static int tcl_kadm5_init_with_creds(ClientData clientData, Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- return _tcl_kadm5_init_any(INIT_CREDS, clientData, interp, argc, argv); --} -- --static int tcl_kadm5_destroy(ClientData clientData, Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- kadm5_ret_t ret; -- int tcl_ret; -- -- GET_HANDLE(0, 0); -- -- ret = kadm5_destroy(server_handle); -- -- if (ret != KADM5_OK) { -- stash_error(interp, ret); -- return TCL_ERROR; -- } -- -- if ((tcl_ret = remove_server_handle(interp, argv[-1])) != TCL_OK) { -- return tcl_ret; -- } -- -- set_ok(interp, "KADM5 API deinitialized."); -- return TCL_OK; --} -- --static int tcl_kadm5_create_principal(ClientData clientData, -- Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- int tcl_ret; -- kadm5_ret_t ret; -- int retcode = TCL_OK; -- char *princ_string; -- kadm5_principal_ent_t princ = 0; -- krb5_int32 mask; -- char *pw; --#ifdef OVERRIDE -- int override_qual; --#endif -- -- GET_HANDLE(3, 0); -- -- if ((tcl_ret = parse_str(interp, argv[0], &princ_string)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing principal"); -- return tcl_ret; -- } -- -- if (princ_string && -- ((tcl_ret = parse_principal_ent(interp, princ_string, &princ)) -- != TCL_OK)) { -- return tcl_ret; -- } -- -- if ((tcl_ret = parse_principal_mask(interp, argv[1], &mask)) != TCL_OK) { -- retcode = tcl_ret; -- goto finished; -- } -- -- if ((tcl_ret = parse_str(interp, argv[2], &pw)) != TCL_OK) { -- retcode = tcl_ret; -- goto finished; -- } --#ifdef OVERRIDE -- if ((tcl_ret = Tcl_GetBoolean(interp, argv[3], &override_qual)) != -- TCL_OK) { -- retcode = tcl_ret; -- goto finished; -- } --#endif -- --#ifdef OVERRIDE -- ret = kadm5_create_principal(server_handle, princ, mask, pw, -- override_qual); --#else -- ret = kadm5_create_principal(server_handle, princ, mask, pw); --#endif -- -- if (ret != KADM5_OK) { -- stash_error(interp, ret); -- retcode = TCL_ERROR; -- goto finished; -- } -- else { -- set_ok(interp, "Principal created."); -- } -- --finished: -- if (princ) { -- free_principal_ent(&princ); -- } -- return retcode; --} -- -- -- --static int tcl_kadm5_delete_principal(ClientData clientData, -- Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- krb5_principal princ; -- krb5_error_code krb5_ret; -- kadm5_ret_t ret; -- int tcl_ret; -- char *name; -- -- GET_HANDLE(1, 0); -- -- if((tcl_ret = parse_str(interp, argv[0], &name)) != TCL_OK) -- return tcl_ret; -- if(name != NULL) { -- if ((krb5_ret = krb5_parse_name(context, name, &princ))) { -- stash_error(interp, krb5_ret); -- Tcl_AppendElement(interp, "while parsing principal"); -- return TCL_ERROR; -- } -- } else princ = NULL; -- ret = kadm5_delete_principal(server_handle, princ); -- -- if(princ != NULL) -- krb5_free_principal(context, princ); -- -- if (ret != KADM5_OK) { -- stash_error(interp, ret); -- return TCL_ERROR; -- } -- else { -- set_ok(interp, "Principal deleted."); -- return TCL_OK; -- } --} -- -- -- --static int tcl_kadm5_modify_principal(ClientData clientData, -- Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- char *princ_string; -- kadm5_principal_ent_t princ = 0; -- int tcl_ret; -- krb5_int32 mask; -- int retcode = TCL_OK; -- kadm5_ret_t ret; -- -- GET_HANDLE(2, 0); -- -- if ((tcl_ret = parse_str(interp, argv[0], &princ_string)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing principal"); -- return tcl_ret; -- } -- -- if (princ_string && -- ((tcl_ret = parse_principal_ent(interp, princ_string, &princ)) -- != TCL_OK)) { -- return tcl_ret; -- } -- -- if ((tcl_ret = parse_principal_mask(interp, argv[1], &mask)) != TCL_OK) { -- retcode = TCL_ERROR; -- goto finished; -- } -- -- ret = kadm5_modify_principal(server_handle, princ, mask); -- -- if (ret != KADM5_OK) { -- stash_error(interp, ret); -- retcode = TCL_ERROR; -- } -- else { -- set_ok(interp, "Principal modified."); -- } -- --finished: -- if (princ) { -- free_principal_ent(&princ); -- } -- return retcode; --} -- -- --static int tcl_kadm5_rename_principal(ClientData clientData, -- Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- krb5_principal source, target; -- krb5_error_code krb5_ret; -- kadm5_ret_t ret; -- int retcode = TCL_OK; -- -- GET_HANDLE(2, 0); -- -- if ((krb5_ret = krb5_parse_name(context, argv[0], &source)) != 0) { -- stash_error(interp, krb5_ret); -- Tcl_AppendElement(interp, "while parsing source"); -- return TCL_ERROR; -- } -- -- if ((krb5_ret = krb5_parse_name(context, argv[1], &target)) != 0) { -- stash_error(interp, krb5_ret); -- Tcl_AppendElement(interp, "while parsing target"); -- krb5_free_principal(context, source); -- return TCL_ERROR; -- } -- -- ret = kadm5_rename_principal(server_handle, source, target); -- -- if (ret == KADM5_OK) { -- set_ok(interp, "Principal renamed."); -- } -- else { -- stash_error(interp, ret); -- retcode = TCL_ERROR; -- } -- -- krb5_free_principal(context, source); -- krb5_free_principal(context, target); -- return retcode; --} -- -- -- --static int tcl_kadm5_chpass_principal(ClientData clientData, -- Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- krb5_principal princ; -- char *pw; --#ifdef OVERRIDE -- int override_qual; --#endif -- krb5_error_code krb5_ret; -- int retcode = TCL_OK; -- kadm5_ret_t ret; -- -- GET_HANDLE(2, 0); -- -- if ((krb5_ret = krb5_parse_name(context, argv[0], &princ)) != 0) { -- stash_error(interp, krb5_ret); -- Tcl_AppendElement(interp, "while parsing principal name"); -- return TCL_ERROR; -- } -- -- if (parse_str(interp, argv[1], &pw) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing password"); -- retcode = TCL_ERROR; -- goto finished; -- } -- --#ifdef OVERRIDE -- if (Tcl_GetBoolean(interp, argv[2], &override_qual) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing override_qual"); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- ret = kadm5_chpass_principal(server_handle, -- princ, pw, override_qual); --#else -- ret = kadm5_chpass_principal(server_handle, princ, pw); --#endif -- -- if (ret == KADM5_OK) { -- set_ok(interp, "Password changed."); -- goto finished; -- } -- else { -- stash_error(interp, ret); -- retcode = TCL_ERROR; -- } -- --finished: -- krb5_free_principal(context, princ); -- return retcode; --} -- -- -- --static int tcl_kadm5_chpass_principal_util(ClientData clientData, -- Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- krb5_principal princ; -- char *new_pw; --#ifdef OVERRIDE -- int override_qual; --#endif -- char *pw_ret, *pw_ret_var; -- char msg_ret[1024], *msg_ret_var; -- krb5_error_code krb5_ret; -- kadm5_ret_t ret; -- int retcode = TCL_OK; -- -- GET_HANDLE(4, 0); -- -- if ((krb5_ret = krb5_parse_name(context, argv[0], &princ)) != 0) { -- stash_error(interp, krb5_ret); -- Tcl_AppendElement(interp, "while parsing principal name"); -- return TCL_ERROR; -- } -- -- if (parse_str(interp, argv[1], &new_pw) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing new password"); -- retcode = TCL_ERROR; -- goto finished; -- } --#ifdef OVERRIDE -- if (Tcl_GetBoolean(interp, argv[2], &override_qual) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing override_qual"); -- retcode = TCL_ERROR; -- goto finished; -- } --#endif -- if (parse_str(interp, argv[3], &pw_ret_var) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing pw_ret variable name"); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- if (parse_str(interp, argv[4], &msg_ret_var) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing msg_ret variable name"); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- ret = kadm5_chpass_principal_util(server_handle, princ, new_pw, --#ifdef OVERRIDE -- override_qual, --#endif -- pw_ret_var ? &pw_ret : 0, -- msg_ret_var ? msg_ret : 0, -- msg_ret_var ? sizeof(msg_ret) : 0); -- -- if (ret == KADM5_OK) { -- if (pw_ret_var && -- (! Tcl_SetVar(interp, pw_ret_var, pw_ret, -- TCL_LEAVE_ERR_MSG))) { -- Tcl_AppendElement(interp, "while setting pw_ret variable"); -- retcode = TCL_ERROR; -- goto finished; -- } -- if (msg_ret_var && -- (! Tcl_SetVar(interp, msg_ret_var, msg_ret, -- TCL_LEAVE_ERR_MSG))) { -- Tcl_AppendElement(interp, -- "while setting msg_ret variable"); -- retcode = TCL_ERROR; -- goto finished; -- } -- set_ok(interp, "Password changed."); -- } -- else { -- stash_error(interp, ret); -- retcode = TCL_ERROR; -- } -- --finished: -- krb5_free_principal(context, princ); -- return retcode; --} -- -- -- --static int tcl_kadm5_randkey_principal(ClientData clientData, -- Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- krb5_principal princ; -- krb5_keyblock *keyblocks; -- int num_keys; -- char *keyblock_var, *num_var, buf[50]; -- Tcl_DString *keyblock_dstring = 0; -- krb5_error_code krb5_ret; -- kadm5_ret_t ret; -- int retcode = TCL_OK; -- -- GET_HANDLE(3, 0); -- -- if ((krb5_ret = krb5_parse_name(context, argv[0], &princ)) != 0) { -- stash_error(interp, krb5_ret); -- Tcl_AppendElement(interp, "while parsing principal name"); -- return TCL_ERROR; -- } -- -- if (parse_str(interp, argv[1], &keyblock_var) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing keyblock variable name"); -- retcode = TCL_ERROR; -- goto finished; -- } -- if (parse_str(interp, argv[2], &num_var) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing keyblock variable name"); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- ret = kadm5_randkey_principal(server_handle, -- princ, keyblock_var ? &keyblocks : 0, -- &num_keys); -- -- if (ret == KADM5_OK) { -- if (keyblock_var) { -- keyblock_dstring = unparse_keyblocks(keyblocks, num_keys); -- if (! Tcl_SetVar(interp, keyblock_var, -- keyblock_dstring->string, -- TCL_LEAVE_ERR_MSG)) { -- Tcl_AppendElement(interp, -- "while setting keyblock variable"); -- retcode = TCL_ERROR; -- goto finished; -- } -- } -- if (num_var) { -- sprintf(buf, "%d", num_keys); -- if (! Tcl_SetVar(interp, num_var, buf, -- TCL_LEAVE_ERR_MSG)) { -- Tcl_AppendElement(interp, -- "while setting num_keys variable"); -- } -- } -- set_ok(interp, "Key randomized."); -- } -- else { -- stash_error(interp, ret); -- retcode = TCL_ERROR; -- } -- --finished: -- krb5_free_principal(context, princ); -- if (keyblock_dstring) { -- Tcl_DStringFree(keyblock_dstring); -- free(keyblock_dstring); -- } -- return retcode; --} -- -- -- --static int tcl_kadm5_get_principal(ClientData clientData, Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- krb5_principal princ; -- kadm5_principal_ent_rec ent; -- Tcl_DString *ent_dstring = 0; -- char *ent_var; -- char *name; -- krb5_error_code krb5_ret; -- int tcl_ret; -- kadm5_ret_t ret = -1; -- krb5_int32 mask; -- int retcode = TCL_OK; -- -- GET_HANDLE(3, 1); -- -- if((tcl_ret = parse_str(interp, argv[0], &name)) != TCL_OK) -- return tcl_ret; -- if(name != NULL) { -- if ((krb5_ret = krb5_parse_name(context, name, &princ)) != 0) { -- stash_error(interp, krb5_ret); -- Tcl_AppendElement(interp, "while parsing principal name"); -- return TCL_ERROR; -- } -- } else princ = NULL; -- -- if ((tcl_ret = parse_str(interp, argv[1], &ent_var)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing entry variable name"); -- retcode = TCL_ERROR; -- goto finished; -- } -- if ((tcl_ret = parse_principal_mask(interp, argv[2], &mask)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing principal mask"); -- retcode = TCL_ERROR; -- goto finished; -- } -- -- ret = kadm5_get_principal(server_handle, princ, ent_var ? &ent : 0, -- mask); -- -- if (ret == KADM5_OK) { -- if (ent_var) { -- ent_dstring = unparse_principal_ent(&ent, mask); -- if (! Tcl_SetVar(interp, ent_var, ent_dstring->string, -- TCL_LEAVE_ERR_MSG)) { -- Tcl_AppendElement(interp, -- "while setting entry variable"); -- retcode = TCL_ERROR; -- goto finished; -- } -- set_ok(interp, "Principal retrieved."); -- } -- } -- else { -- stash_error(interp, ret); -- retcode = TCL_ERROR; -- } -- --finished: -- if (ent_dstring) { -- Tcl_DStringFree(ent_dstring); -- free(ent_dstring); -- } -- if(princ != NULL) -- krb5_free_principal(context, princ); -- if (ret == KADM5_OK && ent_var && -- (ret = kadm5_free_principal_ent(server_handle, &ent)) && -- (retcode == TCL_OK)) { -- stash_error(interp, ret); -- retcode = TCL_ERROR; -- } -- return retcode; --} -- --static int tcl_kadm5_create_policy(ClientData clientData, Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- int tcl_ret; -- kadm5_ret_t ret; -- int retcode = TCL_OK; -- char *policy_string; -- kadm5_policy_ent_t policy = 0; -- krb5_int32 mask; -- -- GET_HANDLE(2, 0); -- -- if ((tcl_ret = parse_str(interp, argv[0], &policy_string)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing policy"); -- return tcl_ret; -- } -- -- if (policy_string && -- ((tcl_ret = parse_policy_ent(interp, policy_string, &policy)) -- != TCL_OK)) { -- return tcl_ret; -- } -- -- if ((tcl_ret = parse_policy_mask(interp, argv[1], &mask)) != TCL_OK) { -- retcode = tcl_ret; -- goto finished; -- } -- -- ret = kadm5_create_policy(server_handle, policy, mask); -- -- if (ret != KADM5_OK) { -- stash_error(interp, ret); -- retcode = TCL_ERROR; -- goto finished; -- } -- else { -- set_ok(interp, "Policy created."); -- } -- --finished: -- if (policy) { -- free_policy_ent(&policy); -- } -- return retcode; --} -- -- -- --static int tcl_kadm5_delete_policy(ClientData clientData, Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- kadm5_ret_t ret; -- char *policy; -- -- GET_HANDLE(1, 0); -- -- if (parse_str(interp, argv[0], &policy) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing policy name"); -- return TCL_ERROR; -- } -- -- ret = kadm5_delete_policy(server_handle, policy); -- -- if (ret != KADM5_OK) { -- stash_error(interp, ret); -- return TCL_ERROR; -- } -- else { -- set_ok(interp, "Policy deleted."); -- return TCL_OK; -- } --} -- -- -- --static int tcl_kadm5_modify_policy(ClientData clientData, Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- char *policy_string; -- kadm5_policy_ent_t policy = 0; -- int tcl_ret; -- krb5_int32 mask; -- int retcode = TCL_OK; -- kadm5_ret_t ret; -- -- GET_HANDLE(2, 0); -- -- if ((tcl_ret = parse_str(interp, argv[0], &policy_string)) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing policy"); -- return tcl_ret; -- } -- -- if (policy_string && -- ((tcl_ret = parse_policy_ent(interp, policy_string, &policy)) -- != TCL_OK)) { -- return tcl_ret; -- } -- -- if ((tcl_ret = parse_policy_mask(interp, argv[1], &mask)) != TCL_OK) { -- retcode = TCL_ERROR; -- goto finished; -- } -- -- ret = kadm5_modify_policy(server_handle, policy, mask); -- -- if (ret != KADM5_OK) { -- stash_error(interp, ret); -- retcode = TCL_ERROR; -- } -- else { -- set_ok(interp, "Policy modified."); -- } -- --finished: -- if (policy) { -- free_policy_ent(&policy); -- } -- return retcode; --} -- -- --static int tcl_kadm5_get_policy(ClientData clientData, Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- kadm5_policy_ent_rec ent; -- Tcl_DString *ent_dstring = 0; -- char *policy; -- char *ent_var; -- kadm5_ret_t ret; -- int retcode = TCL_OK; -- -- GET_HANDLE(2, 1); -- -- if (parse_str(interp, argv[0], &policy) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing policy name"); -- return TCL_ERROR; -- } -- -- if (parse_str(interp, argv[1], &ent_var) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing entry variable name"); -- return TCL_ERROR; -- } -- -- ret = kadm5_get_policy(server_handle, policy, ent_var ? &ent : 0); -- -- if (ret == KADM5_OK) { -- if (ent_var) { -- ent_dstring = unparse_policy_ent(&ent); -- if (! Tcl_SetVar(interp, ent_var, ent_dstring->string, -- TCL_LEAVE_ERR_MSG)) { -- Tcl_AppendElement(interp, -- "while setting entry variable"); -- retcode = TCL_ERROR; -- goto finished; -- } -- set_ok(interp, "Policy retrieved."); -- } -- } -- else { -- stash_error(interp, ret); -- retcode = TCL_ERROR; -- } -- --finished: -- if (ent_dstring) { -- Tcl_DStringFree(ent_dstring); -- free(ent_dstring); -- } -- if (ent_var && ret == KADM5_OK && -- (ret = kadm5_free_policy_ent(server_handle, &ent)) && -- (retcode == TCL_OK)) { -- stash_error(interp, ret); -- retcode = TCL_ERROR; -- } -- return retcode; --} -- -- -- --static int tcl_kadm5_free_principal_ent(ClientData clientData, -- Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- char *ent_name; -- kadm5_principal_ent_t ent; -- kadm5_ret_t ret; -- -- GET_HANDLE(1, 0); -- -- if (parse_str(interp, argv[0], &ent_name) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing entry name"); -- return TCL_ERROR; -- } -- -- if ((! ent_name) && -- (ret = kadm5_free_principal_ent(server_handle, 0))) { -- stash_error(interp, ret); -- return TCL_ERROR; -- } -- else { -- Tcl_HashEntry *entry; -- -- if (strncmp(ent_name, "principal", sizeof("principal")-1)) { -- Tcl_AppendResult(interp, "invalid principal handle \"", -- ent_name, "\"", 0); -- return TCL_ERROR; -- } -- if (! struct_table) { -- if (! (struct_table = malloc(sizeof(*struct_table)))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- Tcl_InitHashTable(struct_table, TCL_STRING_KEYS); -- } -- -- if (! (entry = Tcl_FindHashEntry(struct_table, ent_name))) { -- Tcl_AppendResult(interp, "principal handle \"", ent_name, -- "\" not found", 0); -- return TCL_ERROR; -- } -- -- ent = (kadm5_principal_ent_t) Tcl_GetHashValue(entry); -- -- ret = kadm5_free_principal_ent(server_handle, ent); -- if (ret != KADM5_OK) { -- stash_error(interp, ret); -- return TCL_ERROR; -- } -- Tcl_DeleteHashEntry(entry); -- } -- set_ok(interp, "Principal freed."); -- return TCL_OK; --} -- -- --static int tcl_kadm5_free_policy_ent(ClientData clientData, -- Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- char *ent_name; -- kadm5_policy_ent_t ent; -- kadm5_ret_t ret; -- -- GET_HANDLE(1, 0); -- -- if (parse_str(interp, argv[0], &ent_name) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing entry name"); -- return TCL_ERROR; -- } -- -- if ((! ent_name) && -- (ret = kadm5_free_policy_ent(server_handle, 0))) { -- stash_error(interp, ret); -- return TCL_ERROR; -- } -- else { -- Tcl_HashEntry *entry; -- -- if (strncmp(ent_name, "policy", sizeof("policy")-1)) { -- Tcl_AppendResult(interp, "invalid principal handle \"", -- ent_name, "\"", 0); -- return TCL_ERROR; -- } -- if (! struct_table) { -- if (! (struct_table = malloc(sizeof(*struct_table)))) { -- fprintf(stderr, "Out of memory!\n"); -- exit(1); /* XXX */ -- } -- Tcl_InitHashTable(struct_table, TCL_STRING_KEYS); -- } -- -- if (! (entry = Tcl_FindHashEntry(struct_table, ent_name))) { -- Tcl_AppendResult(interp, "policy handle \"", ent_name, -- "\" not found", 0); -- return TCL_ERROR; -- } -- -- ent = (kadm5_policy_ent_t) Tcl_GetHashValue(entry); -- -- if ((ret = kadm5_free_policy_ent(server_handle, ent)) != KADM5_OK) { -- stash_error(interp, ret); -- return TCL_ERROR; -- } -- Tcl_DeleteHashEntry(entry); -- } -- set_ok(interp, "Policy freed."); -- return TCL_OK; --} -- -- --static int tcl_kadm5_get_privs(ClientData clientData, Tcl_Interp *interp, -- int argc, const char *argv[]) --{ -- const char *set_ret; -- kadm5_ret_t ret; -- char *priv_var; -- long privs; -- -- GET_HANDLE(1, 0); -- -- if (parse_str(interp, argv[0], &priv_var) != TCL_OK) { -- Tcl_AppendElement(interp, "while parsing privs variable name"); -- return TCL_ERROR; -- } -- -- ret = kadm5_get_privs(server_handle, priv_var ? &privs : 0); -- -- if (ret == KADM5_OK) { -- if (priv_var) { -- Tcl_DString *str = unparse_privs(privs); -- set_ret = Tcl_SetVar(interp, priv_var, str->string, -- TCL_LEAVE_ERR_MSG); -- Tcl_DStringFree(str); -- free(str); -- if (! set_ret) { -- Tcl_AppendElement(interp, "while setting priv variable"); -- return TCL_ERROR; -- } -- } -- set_ok(interp, "Privileges retrieved."); -- return TCL_OK; -- } -- else { -- stash_error(interp, ret); -- return TCL_ERROR; -- } --} -- -- --void Tcl_kadm5_init(Tcl_Interp *interp) --{ -- char buf[20]; -- -- Tcl_SetVar(interp, "KADM5_ADMIN_SERVICE", -- KADM5_ADMIN_SERVICE, TCL_GLOBAL_ONLY); -- Tcl_SetVar(interp, "KADM5_CHANGEPW_SERVICE", -- KADM5_CHANGEPW_SERVICE, TCL_GLOBAL_ONLY); -- (void) sprintf(buf, "%d", KADM5_STRUCT_VERSION); -- Tcl_SetVar(interp, "KADM5_STRUCT_VERSION", buf, TCL_GLOBAL_ONLY); -- (void) sprintf(buf, "%d", KADM5_API_VERSION_2); -- Tcl_SetVar(interp, "KADM5_API_VERSION_2", buf, TCL_GLOBAL_ONLY); -- (void) sprintf(buf, "%d", KADM5_API_VERSION_3); -- Tcl_SetVar(interp, "KADM5_API_VERSION_3", buf, TCL_GLOBAL_ONLY); -- (void) sprintf(buf, "%d", KADM5_API_VERSION_4); -- Tcl_SetVar(interp, "KADM5_API_VERSION_4", buf, TCL_GLOBAL_ONLY); -- (void) sprintf(buf, "%d", KADM5_API_VERSION_MASK); -- Tcl_SetVar(interp, "KADM5_API_VERSION_MASK", buf, TCL_GLOBAL_ONLY); -- (void) sprintf(buf, "%d", KADM5_STRUCT_VERSION_MASK); -- Tcl_SetVar(interp, "KADM5_STRUCT_VERSION_MASK", buf, -- TCL_GLOBAL_ONLY); -- -- Tcl_CreateCommand(interp, "kadm5_init", tcl_kadm5_init, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_init_with_creds", -- tcl_kadm5_init_with_creds, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_destroy", tcl_kadm5_destroy, 0, -- 0); -- Tcl_CreateCommand(interp, "kadm5_create_principal", -- tcl_kadm5_create_principal, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_delete_principal", -- tcl_kadm5_delete_principal, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_modify_principal", -- tcl_kadm5_modify_principal, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_rename_principal", -- tcl_kadm5_rename_principal, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_chpass_principal", -- tcl_kadm5_chpass_principal, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_chpass_principal_util", -- tcl_kadm5_chpass_principal_util, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_randkey_principal", -- tcl_kadm5_randkey_principal, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_get_principal", -- tcl_kadm5_get_principal, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_create_policy", -- tcl_kadm5_create_policy, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_delete_policy", -- tcl_kadm5_delete_policy, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_modify_policy", -- tcl_kadm5_modify_policy, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_get_policy", -- tcl_kadm5_get_policy, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_free_principal_ent", -- tcl_kadm5_free_principal_ent, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_free_policy_ent", -- tcl_kadm5_free_policy_ent, 0, 0); -- Tcl_CreateCommand(interp, "kadm5_get_privs", -- tcl_kadm5_get_privs, 0, 0); --} -diff --git a/src/kadmin/testing/util/tcl_kadm5.h b/src/kadmin/testing/util/tcl_kadm5.h -deleted file mode 100644 -index 1f91a11a1..000000000 ---- a/src/kadmin/testing/util/tcl_kadm5.h -+++ /dev/null -@@ -1,3 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ -- --void Tcl_kadm5_init(Tcl_Interp *interp); -diff --git a/src/kadmin/testing/util/tcl_kadm5_syntax b/src/kadmin/testing/util/tcl_kadm5_syntax -deleted file mode 100644 -index 5f16e58e0..000000000 ---- a/src/kadmin/testing/util/tcl_kadm5_syntax -+++ /dev/null -@@ -1,57 +0,0 @@ --Here's a brief summary of the syntax of the tcl versions of the --kadm5 functions: -- --string Can be a string or "null" which will turn into a null pointer --principal_ent A 12-field list in the order of the principal_ent -- structure: {string number number number number string -- number mask number number string mask} -- It can also be "null", like a string, to indicate that -- a null structure pointer should be used. --mask Either a number, representing the actual value of the -- mask, or a sequence of symbols in a list. Example: -- {PRINCIPAL ATTRIBUTES} is a valid principal mask. --boolean "1", "0", "true", "false", etc. --varname The name of a Tcl variable, or "null" to not assign. --policy_ent Similar to principal_ent, but with seven fields, -- instead of 12. The first is a string, and the rest -- are numbers. -- --init -- client_name:string pass:string service_name:string -- realm:string struct_version:int api_version:int -- server_handle_ret:varname --destroy -- server_handle:string --create_principal -- server_handle:string principal:principal_ent -- mask:principal_mask password:string --delete_principal -- server_handle:string name:string --modify_principal -- server_handle:string principal_principal_ent -- mask:principal_mask --rename_principal -- server_handle:string source:string target:string --chpass_principal -- server_handle:string name:string password:string --chpass_principal_util -- server_handle:string name:string password:string -- pw_ret:varname msg_ret:varname --randkey_principal -- server_handle:string name:string keyblock_var:varname --get_principal [-struct] -- server_handle:string name:string princ_var:varname --create_policy -- server_handle:string policy:policy_ent mask:policy_mask --delete_policy -- server_handle:string name:string --modify_policy -- server_handle:string policy:policy_ent mask:policy_mask --get_policy [-struct] -- server_handle:string name:string policy_var:varname --free_principal_ent -- server_handle:string handle:string --free_policy_ent -- server_handle:string handle:string --get_privs -- server_handle:string privs:priv_var -diff --git a/src/kadmin/testing/util/tcl_krb5_hash.c b/src/kadmin/testing/util/tcl_krb5_hash.c -deleted file mode 100644 -index 35c6bb0b3..000000000 ---- a/src/kadmin/testing/util/tcl_krb5_hash.c -+++ /dev/null -@@ -1,167 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --/* -- * All of the TCL krb5 functions which return (or place into output -- * variables) structures or pointers to structures that can't be -- * represented as tcl native types, do so by returning a handle for -- * the appropriate structure. The handle is a string of the form -- * "type$id", where "type" is the type of datum represented by the -- * handle and "id" is a unique identifier for it. This handle can -- * then be used later by the caller to refer to the object, and -- * internally to retrieve the actually datum from the appropriate hash -- * table. -- * -- * The functions in this file do four things: -- * -- * 1) Given a pointer to a datum and a string representing the type of -- * datum to which the pointer refers, create a new handle for the -- * datum, store the datum in the hash table using the new handle as -- * its key, and return the new handle. -- * -- * 2) Given a handle, locate and return the appropriate hash table -- * datum. -- * -- * 3) Given a handle, look through a table of types and unparse -- * functions to figure out what function to call to get a string -- * representation of the datum, call it with the appropriate pointer -- * (obtained from the hash table) as an argument, and return the -- * resulting string as the unparsed form of the datum. -- * -- * 4) Given a handle, remove that handle and its associated datum from -- * the hash table (but don't free it -- it's assumed to have already -- * been freed by the caller). -- */ -- --#if HAVE_TCL_H --#include --#elif HAVE_TCL_TCL_H --#include --#endif --#include -- --#define SEP_STR "$" -- --static char *memory_error = "out of memory"; -- --/* -- * Right now, we're only using one hash table. However, at some point -- * in the future, we might decide to use a separate hash table for -- * every type. Therefore, I'm putting this function in as an -- * abstraction so it's the only thing we'll have to change if we -- * decide to do that. -- * -- * Also, this function allows us to put in just one place the code for -- * checking to make sure that the hash table exists and initializing -- * it if it doesn't. -- */ -- --static TclHashTable *get_hash_table(Tcl_Interp *interp, -- char *type) --{ -- static Tcl_HashTable *hash_table = 0; -- -- if (! hash_table) { -- if (! (hash_table = malloc(sizeof(*hash_table)))) { -- Tcl_SetResult(interp, memory_error, TCL_STATIC); -- return 0; -- } -- Tcl_InitHashTable(hash_table, TCL_STRING_KEYS); -- } -- return hash_table; --} -- --#define MAX_ID 999999999 --#define ID_BUF_SIZE 10 -- --static Tcl_HashEntry *get_new_handle(Tcl_Interp *interp, -- char *type) --{ -- static unsigned long int id_counter = 0; -- Tcl_DString *handle; -- char int_buf[ID_BUF_SIZE]; -- -- if (! (handle = malloc(sizeof(*handle)))) { -- Tcl_SetResult(interp, memory_error, TCL_STATIC); -- return 0; -- } -- Tcl_DStringInit(handle); -- -- assert(id_counter <= MAX_ID); -- -- sprintf(int_buf, "%d", id_counter++); -- -- Tcl_DStringAppend(handle, type, -1); -- Tcl_DStringAppend(handle, SEP_STR, -1); -- Tcl_DStringAppend(handle, int_buf, -1); -- -- return handle; --} -- -- --Tcl_DString *tcl_krb5_create_object(Tcl_Interp *interp, -- char *type, -- ClientData datum) --{ -- Tcl_HashTable *table; -- Tcl_DString *handle; -- Tcl_HashEntry *entry; -- int entry_created = 0; -- -- if (! (table = get_hash_table(interp, type))) { -- return 0; -- } -- -- if (! (handle = get_new_handle(interp, type))) { -- return 0; -- } -- -- if (! (entry = Tcl_CreateHashEntry(table, handle, &entry_created))) { -- Tcl_SetResult(interp, "error creating hash entry", TCL_STATIC); -- Tcl_DStringFree(handle); -- return TCL_ERROR; -- } -- -- assert(entry_created); -- -- Tcl_SetHashValue(entry, datum); -- -- return handle; --} -- --ClientData tcl_krb5_get_object(Tcl_Interp *interp, -- char *handle) --{ -- char *myhandle, *id_ptr; -- Tcl_HashTable *table; -- Tcl_HashEntry *entry; -- -- if (! (myhandle = strdup(handle))) { -- Tcl_SetResult(interp, memory_error, TCL_STATIC); -- return 0; -- } -- -- if (! (id_ptr = index(myhandle, *SEP_STR))) { -- free(myhandle); -- Tcl_ResetResult(interp); -- Tcl_AppendResult(interp, "malformatted handle \"", handle, -- "\"", 0); -- return 0; -- } -- -- *id_ptr = '\0'; -- -- if (! (table = get_hash_table(interp, myhandle))) { -- free(myhandle); -- return 0; -- } -- -- free(myhandle); -- -- if (! (entry = Tcl_FindHashEntry(table, handle))) { -- Tcl_ResetResult(interp); -- Tcl_AppendResult(interp, "no object corresponding to handle \"", -- handle, "\"", 0); -- return 0; -- } -- -- return(Tcl_GetHashValue(entry)); --} -diff --git a/src/kadmin/testing/util/test.c b/src/kadmin/testing/util/test.c -deleted file mode 100644 -index 37e49d680..000000000 ---- a/src/kadmin/testing/util/test.c -+++ /dev/null -@@ -1,38 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --#include "autoconf.h" --#if HAVE_TCL_H --#include --#elif HAVE_TCL_TCL_H --#include --#endif --#include "tcl_kadm5.h" -- --#define _TCL_MAIN ((TCL_MAJOR_VERSION * 100 + TCL_MINOR_VERSION) >= 704) -- --#if _TCL_MAIN --int --main(argc, argv) -- int argc; /* Number of command-line arguments. */ -- char **argv; /* Values of command-line arguments. */ --{ -- Tcl_Main(argc, argv, Tcl_AppInit); -- return 0; /* Needed only to prevent compiler warning. */ --} --#else --/* -- * The following variable is a special hack that allows applications -- * to be linked using the procedure "main" from the Tcl library. The -- * variable generates a reference to "main", which causes main to -- * be brought in from the library (and all of Tcl with it). -- */ -- --extern int main(); --int *tclDummyMainPtr = (int *) main; --#endif -- --int Tcl_AppInit(Tcl_Interp *interp) --{ -- Tcl_kadm5_init(interp); -- -- return(TCL_OK); --} -diff --git a/src/lib/kadm5/Makefile.in b/src/lib/kadm5/Makefile.in -index f94c0a7da..3ff71c42b 100644 ---- a/src/lib/kadm5/Makefile.in -+++ b/src/lib/kadm5/Makefile.in -@@ -1,6 +1,6 @@ - mydir=lib$(S)kadm5 - BUILDTOP=$(REL)..$(S).. --SUBDIRS = clnt srv unit-test -+SUBDIRS = clnt srv - - ##DOSBUILDTOP = ..\.. - -@@ -98,6 +98,7 @@ generate-files-mac-prerecurse: includes - check-windows: - - clean-unix:: clean-libobjs -+ $(RM) t_kadm5clnt t_kadm5srv t_kadm5.o - - clean-windows:: - -diff --git a/src/lib/kadm5/unit-test/Makefile.in b/src/lib/kadm5/unit-test/Makefile.in -deleted file mode 100644 -index 68fa097ff..000000000 ---- a/src/lib/kadm5/unit-test/Makefile.in -+++ /dev/null -@@ -1,143 +0,0 @@ --mydir=lib$(S)kadm5$(S)unit-test --BUILDTOP=$(REL)..$(S)..$(S).. --KDB_DEP_LIB=$(DL_LIB) $(THREAD_LINKOPTS) -- --SRCS= init-test.c destroy-test.c handle-test.c iter-test.c setkey-test.c \ -- randkey-test.c lock-test.c -- --# --# The client-side test programs. --# -- --init-test: init-test.o $(KADMCLNT_DEPLIBS) $(KRB5_BASE_DEPLIBS) -- $(CC_LINK) -o init-test init-test.o \ -- $(KADMCLNT_LIBS) $(KRB5_BASE_LIBS) -- --destroy-test: destroy-test.o $(KADMCLNT_DEPLIBS) $(KRB5_BASE_DEPLIBS) -- $(CC_LINK) -o destroy-test destroy-test.o \ -- $(KADMCLNT_LIBS) $(KRB5_BASE_LIBS) -- --client-handle-test: client-handle-test.o $(KADMCLNT_DEPLIBS) $(KRB5_BASE_DEPLIBS) -- $(CC_LINK) -o client-handle-test client-handle-test.o \ -- $(KADMCLNT_LIBS) $(KRB5_BASE_LIBS) -- --client-handle-test.o: handle-test.c -- $(CC) $(ALL_CFLAGS) -DCLIENT_TEST -o client-handle-test.o -c $(srcdir)/handle-test.c -- --client-iter-test: iter-test.o $(KADMLCNT_DEPLIBS) $(KRB5_BASE_DEPLIBS) -- $(CC_LINK) -o client-iter-test iter-test.o \ -- $(KADMCLNT_LIBS) $(KRB5_BASE_LIBS) -- --client-setkey-test: setkey-test.o $(KADMCLNT_DEPLIBS) $(KRB5_BASE_DEPLIBS) -- $(CC_LINK) -o client-setkey-test setkey-test.o \ -- $(KADMCLNT_LIBS) $(KRB5_BASE_LIBS) -- --# --# The server-side test programs. --# -- --randkey-test: randkey-test.o $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIBS) -- $(CC_LINK) -o randkey-test randkey-test.o \ -- $(KADMSRV_LIBS) $(KDB_DEP_LIB) $(KRB5_BASE_LIBS) -- --server-handle-test: handle-test.o $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIBS) -- $(CC_LINK) -o server-handle-test handle-test.o \ -- $(KADMSRV_LIBS) $(KDB_DEP_LIB) $(KRB5_BASE_LIBS) -- --lock-test: lock-test.o $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIBS) -- $(CC_LINK) -o lock-test lock-test.o \ -- $(KADMSRV_LIBS) $(KDB_DEP_LIB) $(KRB5_BASE_LIBS) -- --server-iter-test: iter-test.o $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIBS) -- $(CC_LINK) -o server-iter-test iter-test.o \ -- $(KADMSRV_LIBS) $(KDB_DEP_LIB) $(KRB5_BASE_LIBS) -- --server-setkey-test: setkey-test.o $(KADMSRV_DEPLIBS) $(KRB5_BASE_DEPLIBS) -- $(CC_LINK) -o server-setkey-test setkey-test.o \ -- $(KADMSRV_LIBS) $(KDB_DEP_LIB) $(KRB5_BASE_LIBS) -- --runenv.exp: Makefile -- $(RUN_SETUP); for i in $(RUN_VARS); do \ -- eval echo "set env\($$i\) \$$$$i"; done > runenv.exp -- --# --# The unit-test targets --# -- --check: check-@DO_TEST@ -- --check-: -- @echo "+++" -- @echo "+++ WARNING: lib/kadm5 unit tests not run." -- @echo "+++ Either tcl, runtest, or Perl is unavailable." -- @echo "+++" -- --check-ok unit-test: unit-test-client unit-test-server -- --unit-test-client: unit-test-client-setup unit-test-client-body \ -- unit-test-client-cleanup -- --unit-test-server: unit-test-server-setup unit-test-server-body \ -- unit-test-server-cleanup -- --test-randkey: randkey-test -- $(ENV_SETUP) $(VALGRIND) ./randkey-test -- --test-handle-server: server-handle-test -- $(ENV_SETUP) $(VALGRIND) ./server-handle-test -- --test-handle-client: client-handle-test -- $(ENV_SETUP) $(VALGRIND) ./client-handle-test -- --test-noauth: init-test -- $(ENV_SETUP) $(VALGRIND) ./init-test -- --test-destroy: destroy-test -- $(ENV_SETUP) $(VALGRIND) ./destroy-test -- --test-setkey-client: client-setkey-test -- $(ENV_SETUP) $(VALGRIND) ./client-setkey-test testkeys admin admin -- --unit-test-client-setup: runenv.sh -- $(ENV_SETUP) $(VALGRIND) $(START_SERVERS) -- --unit-test-client-cleanup: -- $(ENV_SETUP) $(STOP_SERVERS) -- --unit-test-server-setup: runenv.sh -- $(ENV_SETUP) $(VALGRIND) $(START_SERVERS_LOCAL) -- --unit-test-server-cleanup: -- $(ENV_SETUP) $(STOP_SERVERS_LOCAL) -- --unit-test-client-body: site.exp test-noauth test-destroy test-handle-client \ -- test-setkey-client runenv.exp -- $(ENV_SETUP) $(RUNTEST) --tool api RPC=1 API=$(CLNTTCL) \ -- KINIT=$(BUILDTOP)/clients/kinit/kinit \ -- KDESTROY=$(BUILDTOP)/clients/kdestroy/kdestroy \ -- KADMIN_LOCAL=$(BUILDTOP)/kadmin/cli/kadmin.local \ -- PRIOCNTL_HACK=@PRIOCNTL_HACK@ VALGRIND="$(VALGRIND)" \ -- $(RUNTESTFLAGS) -- -mv api.log capi.log -- -mv api.sum capi.sum -- --unit-test-server-body: site.exp test-handle-server lock-test -- $(ENV_SETUP) $(RUNTEST) --tool api RPC=0 API=$(SRVTCL) \ -- LOCKTEST=./lock-test \ -- KADMIN_LOCAL=$(BUILDTOP)/kadmin/cli/kadmin.local \ -- PRIOCNTL_HACK=@PRIOCNTL_HACK@ VALGRIND="$(VALGRIND)" \ -- $(RUNTESTFLAGS) -- -mv api.log sapi.log -- -mv api.sum sapi.sum -- --clean: -- $(RM) init-test client_init.o init-test.o -- $(RM) destroy-test destroy-test.o -- $(RM) client-handle-test handle-test.o client-handle-test.o -- $(RM) client-iter-test iter-test.o -- $(RM) randkey-test randkey-test.o -- $(RM) server-handle-test handle-test.o -- $(RM) lock-test lock-test.o -- $(RM) server-iter-test iter-test.o -- $(RM) server-setkey-test client-setkey-test setkey-test.o -- $(RM) *.log *.plog *.sum *.psum unit-test-log.* runenv.exp -diff --git a/src/lib/kadm5/unit-test/api.2/crte-policy.exp b/src/lib/kadm5/unit-test/api.2/crte-policy.exp -deleted file mode 100644 -index 4902ea59f..000000000 ---- a/src/lib/kadm5/unit-test/api.2/crte-policy.exp -+++ /dev/null -@@ -1,927 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --# Description: (1) Fails for mask with undefined bit set. --# 01/24/94: pshuang: untried. --test "create-policy 1" --proc test1 {} { -- global test -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete policy \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- 0xF01000 -- } $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test1 -- --# Description: (2) Fails if caller connected with CHANGEPW_SERVICE. --test "create-policy 2" --proc test2 {} { -- global test -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy"; -- return -- } --} --if {$RPC} { test2 } -- --# Description: (3) Fails for mask without POLICY bit set. --# 01/24/94: pshuang: untried. --test "create-policy 3" --proc test3 {} { -- global test -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete policy \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- 0x000000 -- } $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test3 -- --# Description: (5) Fails for invalid policy name. --# 01/24/94: pshuang: untried. --test "create-policy 5" --proc test5 {} { -- global test -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/"] \ -- {KADM5_POLICY} -- } $test] "BAD_POLICY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test5 -- --# Description: (6) Fails for existing policy name. --test "create-policy 6" --proc test6 {} { -- global test --# set prms_id 777 --# setup_xfail {*-*-*} $prms_id -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test { -- kadm5_create_policy $server_handle [simple_policy test-pol] \ -- {KADM5_POLICY} -- } "DUP" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test6 -- --# Description: (7) Fails for null policy name. --# 01/24/94: pshuang: untried. --test "create-policy 7" --proc test7 {} { -- global test --# set prms_id 1977 --# setup_xfail {*-*-*} $prms_id -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test { -- kadm5_create_policy $server_handle [simple_policy null] \ -- {KADM5_POLICY} -- } "EINVAL" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test7 -- --# Description: (8) Fails for empty-string policy name. --test "create-policy 8" --proc test8 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test { -- kadm5_create_policy $server_handle [simple_policy ""] \ -- {KADM5_POLICY} -- } "BAD_POLICY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test8 -- --# Description: (9) Accepts 0 for pw_min_life. --test "create-policy 9" --proc test9 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY KADM5_PW_MIN_LIFE} -- } $test]]} { -- fail "$test: create failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 1\n" -- expect { -- -re "0\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test9 -- --# Description: (10) Accepts non-zero for pw_min_life. --test "create-policy 10" --proc test10 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_create_policy $server_handle {"%s/a" 32 0 0 0 0 0 } \ -- {KADM5_POLICY KADM5_PW_MIN_LIFE} -- } $test]]} { -- fail "$test" -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retreuve policy" -- return -- } -- send "lindex \$policy 1\n" -- expect { -- -re "32\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test10 -- --# Description: (11) Accepts 0 for pw_max_life. --test "create-policy 11" --proc test11 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY KADM5_PW_MAX_LIFE} -- } $test]]} { -- fail "$test" -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retreuve policy" -- return -- } -- send "lindex \$policy 2\n" -- expect { -- -re "0\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test11 -- --# Description: (12) Accepts non-zero for pw_max_life. --test "create-policy 12" --proc test12 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_policy $server_handle {"%s/a" 0 32 0 0 0 0 } \ -- {KADM5_POLICY KADM5_PW_MAX_LIFE} -- } $test]]} { -- fail "$test" -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retreuve policy" -- return -- } -- send "lindex \$policy 2\n" -- expect { -- -re "32\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test12 -- --# Description: (13) Rejects 0 for pw_min_length. --test "create-policy 13" --proc test13 {} { -- global test -- global prompt -- -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY KADM5_PW_MIN_LENGTH} -- } $test] "BAD_LENGTH" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test13 -- --# Description: (14) Accepts non-zero for pw_min_length. --test "create-policy 14" --proc test14 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_policy $server_handle {"%s/a" 0 0 8 0 0 0 } \ -- {KADM5_POLICY KADM5_PW_MIN_LENGTH} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retreuve policy" -- return -- } -- send "lindex \$policy 3\n" -- expect { -- -re "8\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test14 -- --# Description: (15) Rejects 0 for pw_min_classes. --test "create-policy 15" --proc test15 {} { -- global test -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY KADM5_PW_MIN_CLASSES} -- } $test] "BAD_CLASS" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test15 -- --# Description: (16) Accepts 1 for pw_min_classes. --test "create-policy 16" --proc test16 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_policy $server_handle {"%s/a" 0 0 0 1 0 0 } \ -- {KADM5_POLICY KADM5_PW_MIN_CLASSES} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retreuve policy" -- return -- } -- send "lindex \$policy 4\n" -- expect { -- -re "1\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test16 -- --# Description: (17) Accepts 4 for pw_min_classes. --test "create-policy 17" --proc test17 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_policy $server_handle {"%s/a" 0 0 0 5 0 0} \ -- {KADM5_POLICY KADM5_PW_MIN_CLASSES} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retreuve policy" -- return -- } -- send "lindex \$policy 4\n" -- expect { -- -re "5\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test17 -- --# Description: (18) Rejects 5 for pw_min_classes. --test "create-policy 18" --proc test18 {} { -- global test -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle {"%s/a" 0 0 0 6 0 0} \ -- {KADM5_POLICY KADM5_PW_MIN_CLASSES} -- } $test] "BAD_CLASS" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test18 -- --# Description: (19) Rejects 0 for pw_history_num. --test "create-policy 19" --proc test19 {} { -- global test -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY KADM5_PW_HISTORY_NUM} -- } $test] "BAD_HISTORY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test19 -- --# Description: (20) Accepts 1 for pw_history_num. --test "create-policy 20" --proc test20 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_policy $server_handle {"%s/a" 0 0 0 0 1 0} \ -- {KADM5_POLICY KADM5_PW_HISTORY_NUM} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retreuve policy" -- return -- } -- send "lindex \$policy 5\n" -- expect { -- -re "1\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test20 -- --# Description: (21) Accepts 10 for pw_history_num. --test "create-policy 21" --proc test21 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_policy $server_handle {"%s/a" 0 0 0 0 10 0} \ -- {KADM5_POLICY KADM5_PW_HISTORY_NUM} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 5\n" -- expect { -- -re "10\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test21 -- --# Description: (22) Fails for user with no access bits. --test "create-policy 22" --proc test22 {} { -- global test -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} test22 -- --# Description: (23) Fails for user with "get" but not "add". --test "create-policy 23" --proc test23 {} { -- global test -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} test23 -- --# Description: (24) Fails for user with "modify" but not "add". --# 01/24/94: pshuang: untried. --test "create-policy 24" --proc test24 {} { -- global test -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} test24 -- --# Description: (25) Fails for user with "delete" but not "add". --# 01/24/94: pshuang: untried. --test "create-policy 25" --proc test25 {} { -- global test -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} test25 -- --# Description: Succeeds for user with "add". --test "create-policy 26" --proc test26 {} { -- global test -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test26 -- --# Description: Succeeds for user with "get" and "add". --# 01/24/94: pshuang: untried. --test "create-policy 27" --proc test27 {} { -- global test -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/get-add admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test27 -- --# Description: (28) Rejects null policy argument. --# 01/24/94: pshuang: untried. --test "create-policy 28" --proc test28 {} { -- global test -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test { -- kadm5_create_policy $server_handle null {KADM5_POLICY} -- } "EINVAL" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test28 -- --test "create-policy 30" --proc test30 {} { -- global test -- one_line_fail_test [format { -- kadm5_create_policy null [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] "BAD_SERVER_HANDLE" --} --test30 -- --return "" -diff --git a/src/lib/kadm5/unit-test/api.2/get-policy.exp b/src/lib/kadm5/unit-test/api.2/get-policy.exp -deleted file mode 100644 -index 83aef80e8..000000000 ---- a/src/lib/kadm5/unit-test/api.2/get-policy.exp -+++ /dev/null -@@ -1,199 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --test "get-policy 3" --proc test3 {} { -- global test --# set prms_id 744 --# setup_xfail {*-*-*} $prms_id -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test {kadm5_get_policy $server_handle "" p} "BAD_POLICY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test3 -- --test "get-policy 6" --proc test6 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test {kadm5_get_policy $server_handle test-pol p} \ -- "AUTH_GET" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if { $RPC } test6 -- --test "get-policy 7" --proc test7 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test {kadm5_get_policy $server_handle test-pol p} \ -- "AUTH_GET" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if { $RPC } test7 -- --test "get-policy 11" --proc test11 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/get-pol StupidAdmin $KADM5_ADMIN_SERVICE \ -- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test {kadm5_get_policy $server_handle test-pol p} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test11 -- --test "get-policy 12" --proc test12 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/get-pol StupidAdmin \ -- $KADM5_CHANGEPW_SERVICE null $KADM5_STRUCT_VERSION \ -- $KADM5_API_VERSION_2 server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test \ -- {kadm5_get_policy $server_handle test-pol-nopw p} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test12 -- --test "get-policy 15" --proc test15 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/pol StupidAdmin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test \ -- {kadm5_get_policy $server_handle test-pol-nopw p} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test15 -- --test "get-policy 16" --proc test16 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/pol StupidAdmin $KADM5_CHANGEPW_SERVICE \ -- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test \ -- {kadm5_get_policy $server_handle test-pol-nopw p} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test16 -- --test "get-policy 17" --proc test17 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test {kadm5_get_policy $server_handle test-pol p} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test17 -- --test "get-policy 18" --proc test18 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test {kadm5_get_policy $server_handle test-pol p} \ -- "AUTH_GET" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if { $RPC } test18 -- --test "get-policy 21" --proc test21 {} { -- global test -- -- one_line_fail_test {kadm5_get_policy null "pol1" p} "BAD_SERVER_HANDLE" --} --test21 -diff --git a/src/lib/kadm5/unit-test/api.2/mod-policy.exp b/src/lib/kadm5/unit-test/api.2/mod-policy.exp -deleted file mode 100644 -index 904edca8a..000000000 ---- a/src/lib/kadm5/unit-test/api.2/mod-policy.exp -+++ /dev/null -@@ -1,675 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --test "modify-policy 2" --proc test2 {} { -- global test -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MAX_LIFE} -- } $test] "AUTH_MODIFY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test2 } -- --test "modify-policy 8" --proc test8 {} { -- global test --# set prms_id 744 --# setup_xfail {*-*-*} $prms_id -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test { -- kadm5_modify_policy $server_handle [simple_policy ""] \ -- {KADM5_PW_MAX_LIFE} -- } "BAD_POLICY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test8 -- --test "modify-policy 9" --proc test9 {} { -- global test -- global prompt -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MIN_LIFE} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 1\n" -- expect { -- -re "0\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test9 -- --test "modify-policy 10" --proc test10 {} { -- global test -- global prompt -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle {"%s/a" 32 0 0 0 0 0} \ -- {KADM5_PW_MIN_LIFE} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 1\n" -- expect { -- -re "32\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test10 -- -- --test "modify-policy 11" --proc test11 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MAX_LIFE} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 2\n" -- expect { -- -re "0\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test11 -- --test "modify-policy 12" --proc test12 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 32 0 0 0 0} \ -- {KADM5_PW_MAX_LIFE} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 2\n" -- expect { -- -re "32\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test12 -- --test "modify-policy 13" --proc test13 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MIN_LENGTH} -- } $test] "BAD_LENGTH" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test13 -- --test "modify-policy 14" --proc test14 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 8 0 0 0} \ -- {KADM5_PW_MIN_LENGTH} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 3\n" -- expect { -- -re "8\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test14 -- --test "modify-policy 15" --proc test15 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MIN_CLASSES} -- } $test] "BAD_CLASS" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test15 -- --test "modify-policy 16" --proc test16 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 1 0 0} \ -- {KADM5_PW_MIN_CLASSES} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 4\n" -- expect { -- -re "1\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test16 -- --test "modify-policy 17" --proc test17 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 5 0 0} \ -- {KADM5_PW_MIN_CLASSES} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 4\n" -- expect { -- -re "5\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test17 -- --test "modify-policy 18" --proc test18 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 6 0 0} \ -- {KADM5_PW_MIN_CLASSES} -- } $test] "BAD_CLASS" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test18 -- --test "modify-policy 19" --proc test19 {} { -- global test -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_HISTORY_NUM} -- } $test] "BAD_HISTORY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test19 -- --test "modify-policy 20" --proc test20 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 0 1 0} \ -- {KADM5_PW_HISTORY_NUM} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 5\n" -- expect { -- -re "1\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test20 -- --test "modify-policy 21" --proc test21 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 0 10 0} \ -- {KADM5_PW_HISTORY_NUM} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 5\n" -- expect { -- -re "10\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test21 -- --test "modify-policy 22" --proc test22 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MAX_LIFE} -- } $test] "AUTH_MODIFY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} test22 -- --test "modify-policy 23" --proc test23 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MAX_LIFE} -- } $test] "AUTH_MODIFY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} test23 -- --test "modify-policy 26" --proc test26 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_2 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MAX_LIFE} -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test26 -- --test "modify-policy 30" --proc test30 {} { -- global test -- -- one_line_fail_test [format { -- kadm5_modify_policy null [simple_policy "%s/a"] \ -- {KADM5_PW_MAX_LIFE} -- } $test] "BAD_SERVER_HANDLE" --} --test30 -- --return "" -diff --git a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp -deleted file mode 100644 -index 740425c69..000000000 ---- a/src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp -+++ /dev/null -@@ -1,68 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --test "chpass-principal 200" --proc test200 {} { -- global test prompt -- -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [create_principal "$test/a"]} { -- error_and_restart "$test: creating principal" -- return -- } -- -- # I'd like to specify a long list of keysalt tuples and make sure -- # that chpass does the right thing, but we can only use those -- # enctypes that krbtgt has a key for: the AES enctypes, according to -- # the prototype kdc.conf. -- if {! [cmd [format { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_chpass_principal $server_handle "%s/a" newpassword -- } $test]]} { -- perror "$test: unexpected failure in chpass_principal" -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" p \ -- {KADM5_PRINCIPAL_NORMAL_MASK KADM5_KEY_DATA} -- } $test]]} { -- perror "$test: unexpected failure in get_principal" -- } -- send "lindex \$p 16\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" { set num_keys $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting num_keys" -- return -- } -- eof { -- error_and_restart "$test: eof getting num_keys" -- return -- } -- } -- -- # XXX Perhaps I should actually check the key type returned. -- if {$num_keys == 5} { -- pass "$test" -- } else { -- fail "$test: $num_keys keys, should be 5" -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test200 -- --return "" -diff --git a/src/lib/kadm5/unit-test/api.current/chpass-principal.exp b/src/lib/kadm5/unit-test/api.current/chpass-principal.exp -deleted file mode 100644 -index 47a19dc20..000000000 ---- a/src/lib/kadm5/unit-test/api.current/chpass-principal.exp -+++ /dev/null -@@ -1,176 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --test "chpass-principal 180" --proc test180 {} { -- global test -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [create_principal_pol "$test/a" once-a-min]} { -- error_and_restart "$test: creating principal" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_chpass_principal $server_handle "%s/a" FoobarBax -- } $test] -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if { $RPC } { test180 } -- --test "chpass-principal 180.5" --proc test1805 {} { -- global test -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [create_principal_pol "$test/a" once-a-min]} { -- error_and_restart "$test: creating principal" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_chpass_principal $server_handle "%s/a" FoobarBax -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if { $RPC } { test1805 } -- --# --# admin with changepw service tickets try to change other principals --# password, fails with AUTH error --test "chpass-principal 180.625" --proc test180625 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_chpass_principal $server_handle "%s/a" password -- } $test] "AUTH" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test180625 } -- --test "chpass-principal 180.75" --proc test18075 {} { -- global test -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [create_principal_pol "$test/a" once-a-min]} { -- error_and_restart "$test: creating principal" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_chpass_principal $server_handle "%s/a" Foobar -- } $test] "AUTH_CHANGEPW" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if { $RPC } { test18075 } -- --test "chpass-principal 182" --proc test182 {} { -- global test -- -- if { ! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test { -- kadm5_chpass_principal $server_handle kadmin/history password -- } "PROTECT" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test182 -- --test "chpass-principal 183" --proc test183 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if { ! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_chpass_principal null "%s/a" password -- } $test] "BAD_SERVER_HANDLE" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test183 -- --return "" -diff --git a/src/lib/kadm5/unit-test/api.current/crte-policy.exp b/src/lib/kadm5/unit-test/api.current/crte-policy.exp -deleted file mode 100644 -index 7e1eda63f..000000000 ---- a/src/lib/kadm5/unit-test/api.current/crte-policy.exp -+++ /dev/null -@@ -1,927 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --# Description: (1) Fails for mask with undefined bit set. --# 01/24/94: pshuang: untried. --test "create-policy 1" --proc test1 {} { -- global test -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete policy \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- 0xF01000 -- } $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test1 -- --# Description: (2) Fails if caller connected with CHANGEPW_SERVICE. --test "create-policy 2" --proc test2 {} { -- global test -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy"; -- return -- } --} --if {$RPC} { test2 } -- --# Description: (3) Fails for mask without POLICY bit set. --# 01/24/94: pshuang: untried. --test "create-policy 3" --proc test3 {} { -- global test -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete policy \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- 0x000000 -- } $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test3 -- --# Description: (5) Fails for invalid policy name. --# 01/24/94: pshuang: untried. --test "create-policy 5" --proc test5 {} { -- global test -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/"] \ -- {KADM5_POLICY} -- } $test] "BAD_POLICY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test5 -- --# Description: (6) Fails for existing policy name. --test "create-policy 6" --proc test6 {} { -- global test --# set prms_id 777 --# setup_xfail {*-*-*} $prms_id -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test { -- kadm5_create_policy $server_handle [simple_policy test-pol] \ -- {KADM5_POLICY} -- } "DUP" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test6 -- --# Description: (7) Fails for null policy name. --# 01/24/94: pshuang: untried. --test "create-policy 7" --proc test7 {} { -- global test --# set prms_id 1977 --# setup_xfail {*-*-*} $prms_id -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test { -- kadm5_create_policy $server_handle [simple_policy null] \ -- {KADM5_POLICY} -- } "EINVAL" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test7 -- --# Description: (8) Fails for empty-string policy name. --test "create-policy 8" --proc test8 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test { -- kadm5_create_policy $server_handle [simple_policy ""] \ -- {KADM5_POLICY} -- } "BAD_POLICY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test8 -- --# Description: (9) Accepts 0 for pw_min_life. --test "create-policy 9" --proc test9 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY KADM5_PW_MIN_LIFE} -- } $test]]} { -- fail "$test: create failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 1\n" -- expect { -- -re "0\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test9 -- --# Description: (10) Accepts non-zero for pw_min_life. --test "create-policy 10" --proc test10 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_create_policy $server_handle {"%s/a" 32 0 0 0 0 0 } \ -- {KADM5_POLICY KADM5_PW_MIN_LIFE} -- } $test]]} { -- fail "$test" -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retreuve policy" -- return -- } -- send "lindex \$policy 1\n" -- expect { -- -re "32\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test10 -- --# Description: (11) Accepts 0 for pw_max_life. --test "create-policy 11" --proc test11 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY KADM5_PW_MAX_LIFE} -- } $test]]} { -- fail "$test" -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retreuve policy" -- return -- } -- send "lindex \$policy 2\n" -- expect { -- -re "0\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test11 -- --# Description: (12) Accepts non-zero for pw_max_life. --test "create-policy 12" --proc test12 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_policy $server_handle {"%s/a" 0 32 0 0 0 0 } \ -- {KADM5_POLICY KADM5_PW_MAX_LIFE} -- } $test]]} { -- fail "$test" -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retreuve policy" -- return -- } -- send "lindex \$policy 2\n" -- expect { -- -re "32\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test12 -- --# Description: (13) Rejects 0 for pw_min_length. --test "create-policy 13" --proc test13 {} { -- global test -- global prompt -- -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY KADM5_PW_MIN_LENGTH} -- } $test] "BAD_LENGTH" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test13 -- --# Description: (14) Accepts non-zero for pw_min_length. --test "create-policy 14" --proc test14 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_policy $server_handle {"%s/a" 0 0 8 0 0 0 } \ -- {KADM5_POLICY KADM5_PW_MIN_LENGTH} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retreuve policy" -- return -- } -- send "lindex \$policy 3\n" -- expect { -- -re "8\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test14 -- --# Description: (15) Rejects 0 for pw_min_classes. --test "create-policy 15" --proc test15 {} { -- global test -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY KADM5_PW_MIN_CLASSES} -- } $test] "BAD_CLASS" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test15 -- --# Description: (16) Accepts 1 for pw_min_classes. --test "create-policy 16" --proc test16 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_policy $server_handle {"%s/a" 0 0 0 1 0 0 } \ -- {KADM5_POLICY KADM5_PW_MIN_CLASSES} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retreuve policy" -- return -- } -- send "lindex \$policy 4\n" -- expect { -- -re "1\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test16 -- --# Description: (17) Accepts 4 for pw_min_classes. --test "create-policy 17" --proc test17 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_policy $server_handle {"%s/a" 0 0 0 5 0 0} \ -- {KADM5_POLICY KADM5_PW_MIN_CLASSES} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retreuve policy" -- return -- } -- send "lindex \$policy 4\n" -- expect { -- -re "5\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test17 -- --# Description: (18) Rejects 5 for pw_min_classes. --test "create-policy 18" --proc test18 {} { -- global test -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle {"%s/a" 0 0 0 6 0 0} \ -- {KADM5_POLICY KADM5_PW_MIN_CLASSES} -- } $test] "BAD_CLASS" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test18 -- --# Description: (19) Rejects 0 for pw_history_num. --test "create-policy 19" --proc test19 {} { -- global test -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY KADM5_PW_HISTORY_NUM} -- } $test] "BAD_HISTORY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test19 -- --# Description: (20) Accepts 1 for pw_history_num. --test "create-policy 20" --proc test20 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_policy $server_handle {"%s/a" 0 0 0 0 1 0} \ -- {KADM5_POLICY KADM5_PW_HISTORY_NUM} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retreuve policy" -- return -- } -- send "lindex \$policy 5\n" -- expect { -- -re "1\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test20 -- --# Description: (21) Accepts 10 for pw_history_num. --test "create-policy 21" --proc test21 {} { -- global test -- global prompt -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_policy $server_handle {"%s/a" 0 0 0 0 10 0} \ -- {KADM5_POLICY KADM5_PW_HISTORY_NUM} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 5\n" -- expect { -- -re "10\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test21 -- --# Description: (22) Fails for user with no access bits. --test "create-policy 22" --proc test22 {} { -- global test -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} test22 -- --# Description: (23) Fails for user with "get" but not "add". --test "create-policy 23" --proc test23 {} { -- global test -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} test23 -- --# Description: (24) Fails for user with "modify" but not "add". --# 01/24/94: pshuang: untried. --test "create-policy 24" --proc test24 {} { -- global test -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} test24 -- --# Description: (25) Fails for user with "delete" but not "add". --# 01/24/94: pshuang: untried. --test "create-policy 25" --proc test25 {} { -- global test -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} test25 -- --# Description: Succeeds for user with "add". --test "create-policy 26" --proc test26 {} { -- global test -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test26 -- --# Description: Succeeds for user with "get" and "add". --# 01/24/94: pshuang: untried. --test "create-policy 27" --proc test27 {} { -- global test -- -- if {! (( ! [policy_exists "$test/a"]) || -- [delete_policy "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/get-add admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_create_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test27 -- --# Description: (28) Rejects null policy argument. --# 01/24/94: pshuang: untried. --test "create-policy 28" --proc test28 {} { -- global test -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test { -- kadm5_create_policy $server_handle null {KADM5_POLICY} -- } "EINVAL" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test28 -- --test "create-policy 30" --proc test30 {} { -- global test -- one_line_fail_test [format { -- kadm5_create_policy null [simple_policy "%s/a"] \ -- {KADM5_POLICY} -- } $test] "BAD_SERVER_HANDLE" --} --test30 -- --return "" -diff --git a/src/lib/kadm5/unit-test/api.current/crte-principal.exp b/src/lib/kadm5/unit-test/api.current/crte-principal.exp -deleted file mode 100644 -index d6d6809ec..000000000 ---- a/src/lib/kadm5/unit-test/api.current/crte-principal.exp -+++ /dev/null -@@ -1,1336 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --#test "create-principal 1" --# --#proc test1 {} { --# global test --# begin_dump --# one_line_fail_test [format { --# kadm5_create_principal $server_handle \ --# [simple_principal "%s/a"] {KADM5_PRINCIPAL} "%s/a" --# } $test $test] "NOT_INIT" --# end_dump_compare "no-diffs" --#} --#test1 -- --# v2 create-principal 3 test, to avoid name conflict --test "create-principal 1" --proc test1 {} { -- global test --# set prms_id 777 --# setup_xfail {*-*-*} $prms_id -- begin_dump -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} null -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test1 -- --test "create-principal 2" -- --proc test2 {} { -- global test -- begin_dump -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test { -- kadm5_create_principal $server_handle null \ -- {KADM5_PRINCIPAL} testpass -- } "EINVAL" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test2 -- --test "create-principal 4" --proc test4 {} { -- global test -- -- begin_dump -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} "" -- } $test] "_Q_TOOSHORT" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test4 -- --test "create-principal 5" --proc test5 {} { -- global test -- begin_dump -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle \ -- [simple_principal "%s/a"] {0x100001} "%s/a" -- } $test $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test5 -- --test "create-principal 6" --proc test6 {} { -- global test -- begin_dump -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_LAST_PWD_CHANGE} "%s/a" -- } $test $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test6 -- --test "create-principal 7" --proc test7 {} { -- global test -- begin_dump -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_MOD_TIME} "%s/a" -- } $test $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test7 -- --test "create-principal 8" --proc test8 {} { -- global test -- begin_dump -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_MOD_NAME} "%s/a" -- } $test $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test8 -- --test "create-principal 9" --proc test9 {} { -- global test -- begin_dump -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_MKVNO} "%s/a" -- } $test $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test9 -- --test "create-principal 10" --proc test10 {} { -- global test -- begin_dump -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_AUX_ATTRIBUTES} "%s/a" -- } $test $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test10 -- --test "create-principal 11" --proc test11 {} { -- global test -- begin_dump -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_POLICY_CLR} "%s/a" -- } $test $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test11 -- --test "create-principal 12" --proc test12 {} { -- global test -- begin_dump -- if {! [cmd { -- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} testpass -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" -- --} --if {$RPC} { test12 } -- --test "create-principal 13" --proc test13 {} { -- global test -- begin_dump -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} testpass -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --if {$RPC} { test13 } -- --test "create-principal 14" --proc test14 {} { -- global test -- begin_dump -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} testpass -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --if {$RPC} { test14 } -- --test "create-principal 15" --proc test15 {} { -- global test -- begin_dump -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} testpass -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --if {$RPC} { test15 } -- --test "create-principal 16" --proc test16 {} { -- global test -- begin_dump -- if {! [cmd { -- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} testpass -- } $test] "AUTH_ADD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --if {$RPC} { test16 } -- --test "create-principal 17" --proc test17 {} { -- global test -- -- begin_dump -- if {! (( [principal_exists "$test/a"]) || [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} testpass -- } $test] "DUP" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test17 -- --test "create-principal 18" --proc test18 {} { -- global test -- -- begin_dump -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle \ -- [princ_w_pol "%s/a" test-pol] \ -- {KADM5_PRINCIPAL KADM5_POLICY} tP -- } $test] "_Q_TOOSHORT" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test18 -- --test "create-principal 19" --proc test19 {} { -- global test -- -- begin_dump -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle \ -- [princ_w_pol "%s/a" test-pol] \ -- {KADM5_PRINCIPAL KADM5_POLICY} testpassword -- } $test] "_Q_CLASS" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test19 -- --test "create-principal 20" --proc test20 {} { -- global test -- -- begin_dump -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_create_principal $server_handle \ -- [princ_w_pol "%s/a" test-pol] \ -- {KADM5_PRINCIPAL KADM5_POLICY} Abyssinia -- } $test] "_Q_DICT" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test20 -- --test "create-principal 21" --proc test21 {} { -- global test -- -- begin_dump -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_create_principal $server_handle \ -- [princ_w_pol "%s/a" non-existant-pol] \ -- {KADM5_PRINCIPAL KADM5_POLICY} NotinTheDictionary -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- end_dump_compare "no-diffs" --} --test21 -- --test "create-principal 23" --proc test23 {} { -- global test -- -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} NotinTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- one_line_succeed_test \ -- [format {kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK} $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test23 -- --test "create-principal 24" --proc test24 {} { -- global test -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/rename admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} NotinTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- one_line_succeed_test \ -- [format {kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK} $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test24 } -- -- --test "create-principal 28" --proc test28 {} { -- global test -- global prompt -- -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- -- if {! [cmd [format { -- kadm5_create_principal $server_handle \ -- [princ_w_pol "%s/a" test-pol] \ -- {KADM5_PRINCIPAL KADM5_POLICY} NotinTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- fail "$test: can not retrieve principal" -- return -- } -- send "lindex \$principal 10\n" -- expect { -- -re "test-pol.*$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test28 -- --test "create-principal 29" --proc test29 {} { -- global test -- global prompt -- -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL KADM5_PRINC_EXPIRE_TIME} \ -- inTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- fail "$test: can not retrieve principal" -- return; -- } -- send "lindex \$principal 1\n" -- expect { -- -re "0.*$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test29 -- --test "create-principal 30" --proc test30 {} { -- global test -- global prompt -- -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL KADM5_PW_EXPIRATION} \ -- NotinTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- fail "$test: can not retrieve principal" -- return; -- } -- send "lindex \$principal 3\n" -- expect { -- -re "0.*$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test30 -- --test "create-principal 31" --proc test31 {} { -- global test -- global prompt -- -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle \ -- [princ_w_pol "%s/a" test-pol-nopw] \ -- {KADM5_PRINCIPAL KADM5_POLICY \ -- KADM5_PW_EXPIRATION} NotinTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- fail "$test: can not retrieve principal" -- return; -- } -- send "lindex \$principal 3\n" -- expect { -- -re "0.*$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test31 -- --test "create-principal 32" --proc test32 {} { -- global test -- global prompt -- -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle \ -- [princ_w_pol "%s/a" test-pol] \ -- {KADM5_PRINCIPAL KADM5_POLICY \ -- KADM5_PW_EXPIRATION} NotinTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- fail "$test: can not retrieve principal" -- return; -- } -- if { ! [cmd {kadm5_get_policy $server_handle test-pol policy}]} { -- error_and_restart "$test: cannot retrieve policy" -- return -- } -- -- send "lindex \$principal 6\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set mod_date $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting mod_date" -- return -- } -- eof { -- error_and_restart "$test: eof getting mod_date" -- return -- } -- } -- -- send "lindex \$principal 3\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_expire $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting pw_expire" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_expire" -- return -- } -- } -- -- send "lindex \$policy 2\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_max_life $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting pw_max_life" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_max_life" -- return -- } -- } -- if { $pw_expire != 0 } { -- fail "$test: pw_expire $pw_expire should be 0" -- return -- } else { -- pass "$test" -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test32 -- --test "create-principal 33" --proc test33 {} { -- global test -- global prompt -- -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle \ -- {"%s/a" 0 0 1234 0 null 0 0 0 0 null 0} \ -- {KADM5_PRINCIPAL KADM5_PW_EXPIRATION} \ -- NotinTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- fail "$test: can not retrieve principal" -- return; -- } -- send "lindex \$principal 3\n" -- expect { -- -re "1234.*$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test33 -- --test "create-principal 34" --proc test34 {} { -- global test -- global prompt -- -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle \ -- { "%s/a" 0 0 1234 0 null 0 0 0 0 test-pol-nopw 0} \ -- {KADM5_PRINCIPAL KADM5_POLICY \ -- KADM5_PW_EXPIRATION} NotinTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- fail "$test: can not retrieve principal" -- return; -- } -- send "lindex \$principal 3\n" -- expect { -- -re "1234.*$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test34 -- --test "create-principal 35" --proc test35 {} { -- global test -- global prompt -- -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle \ -- {"%s/a" 0 0 1234 0 null 0 0 0 0 test-pol 0} \ -- {KADM5_PRINCIPAL KADM5_POLICY \ -- KADM5_PW_EXPIRATION} NotinTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- fail "$test: can not retrieve principal" -- return; -- } -- send "lindex \$principal 3\n" -- expect { -- -re "1234.*$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test35 -- --test "create-principal 36" --proc test36 {} { -- global test -- global prompt -- -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle \ -- {"%s/a" 0 0 999999999 0 null 0 0 0 0 test-pol 0} \ -- {KADM5_PRINCIPAL KADM5_POLICY \ -- KADM5_PW_EXPIRATION} NotinTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- fail "$test: can not retrieve principal" -- return; -- } -- if { ! [cmd {kadm5_get_policy $server_handle test-pol policy} ]} { -- error_and_restart "$test: cannot retrieve policy" -- return -- } -- -- send "lindex \$principal 6\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set mod_date $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting mod_date" -- return -- } -- eof { -- error_and_restart "$test: eof getting mod_date" -- return -- } -- } -- -- send "lindex \$principal 3\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_expire $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting pw_expire" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_expire" -- return -- } -- } -- -- send "lindex \$policy 2\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_max_life $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting pw_max_life" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_max_life" -- return -- } -- } -- if { $pw_expire != 999999999 } { -- fail "$test: pw_expire is wrong" -- return -- } else { -- pass "$test" -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test36 -- --test "create-principal 37" --proc test37 {} { -- global test -- global prompt -- -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} NotinTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- fail "$test: can not retrieve principal" -- return; -- } -- send "lindex \$principal 3\n" -- expect { -- -re "0.*$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test37 -- --test "create-principal 38" --proc test38 {} { -- global test -- global prompt -- -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle [princ_w_pol "%s/a" \ -- test-pol-nopw] {KADM5_PRINCIPAL KADM5_POLICY} \ -- NotinTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- fail "$test: can not retrieve principal" -- return; -- } -- send "lindex \$principal 3\n" -- expect { -- -re "0.*$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test38 -- --test "create-principal 39" --proc test39 {} { -- global test -- global prompt -- -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle [princ_w_pol "%s/a" \ -- test-pol] {KADM5_PRINCIPAL KADM5_POLICY} \ -- NotinTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if { ! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: cannot not retrieve principal" -- return -- } -- if { ! [cmd {kadm5_get_policy $server_handle test-pol policy}]} { -- error_and_restart "$test: cannot retrieve policy" -- return -- } -- send "lindex \$principal 6\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set mod_date $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting mod_date" -- return -- } -- eof { -- error_and_restart "$test: eof getting mod_date" -- return -- } -- } -- -- send "lindex \$principal 3\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_expire $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting pw_expire" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_expire" -- return -- } -- } -- -- send "lindex \$policy 2\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_max_life $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting pw_max_life" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_max_life" -- return -- } -- } -- if { [expr "$mod_date + $pw_max_life - $pw_expire"] > 5 } { -- fail "$test: pw_expire is wrong" -- return -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test39 -- --test "create-principal 40" --proc test40 {} { -- global test -- global prompt -- -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL KADM5_PW_EXPIRATION} \ -- NotinTheDictionary -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- fail "$test: can not retrieve principal" -- return; -- } -- send "lindex \$principal 4\n" -- expect { -- -re "0.*$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test40 -- --test "create-principal 43" --proc test43 {} { -- global test -- one_line_fail_test [format { -- kadm5_create_principal null \ -- [simple_principal "%s/a"] {KADM5_PRINCIPAL} "%s/a" -- } $test $test] "BAD_SERVER_HANDLE" --} --test43 -- --return "" -diff --git a/src/lib/kadm5/unit-test/api.current/destroy.exp b/src/lib/kadm5/unit-test/api.current/destroy.exp -deleted file mode 100644 -index a3e2bfc59..000000000 ---- a/src/lib/kadm5/unit-test/api.current/destroy.exp -+++ /dev/null -@@ -1,203 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --test "destroy 1" -- --proc test1 {} { -- global test -- begin_dump -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test {kadm5_destroy $server_handle} -- end_dump_compare "no-diffs" --} --test1 -- --#test "destroy 2" --# --#proc test2 {} { --# global test --# begin_dump --# if {! [cmd { --# kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ --# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ --# server_handle --# }]} { --# perror "$test: unexpected failure on init" --# return --# } --# if {! [cmd {kadm5_destroy $server_handle}]} { --# error_and_restart "$test: couldn't close database" --# return --# } --# one_line_fail_test \ --# {kadm5_get_principal $server_handle admin principal} \ --# "NOT_INIT" --# end_dump_compare "no-diffs" --#} --#test2 -- --#test "destroy 3" --#proc test3 {} { --# global test --# --# begin_dump --# if {! (( ! [principal_exists "$test/a"]) || [delete_principal "$test/a"])} { --# error_and_restart "$test couldn't delete principal \"$test/a\"" --# return --# } --# if {! [cmd { --# kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ --# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ --# server_handle --# }]} { --# perror "$test: unexpected failure on init" --# return --# } --# if {! [cmd {kadm5_destroy $server_handle}]} { --# error_and_restart "$test: couldn't close database" --# return --# } --# one_line_fail_test [format { --# kadm5_create_principal $server_handle \ --# [simple_principal "%s/a"] {KADM5_PRINCIPAL} "%s/a" --# } $test $test] "NOT_INIT" --# end_dump_compare "no-diffs" --#} --#test3 -- --#test "destroy 4" --#proc test4 {} { --# global test prompt --# --# if {! (([principal_exists "$test/a"]) || [create_principal "$test/a"])} { --# error_and_restart "$test: couldn't create principal \"$test/a\"" --# return --# } --# begin_dump --# if {! ([cmd { --# kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ --# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ --# server_handle --# }] && --# [cmd [format { --# kadm5_get_principal $server_handle "%s/a" principal --# } $test]])} { --# error_and_restart "$test: error getting principal" --# return; --# } --# if {! [cmd {kadm5_destroy $server_handle}]} { --# error_and_restart "$test: couldn't close database" --# return --# } --# one_line_fail_test [format { --# kadm5_modify_principal $server_handle \ --# {"%s/a" 0 0 0 0 0 0 0 %d 0 0 0} {KADM5_KVNO} --# } $test "77"] "NOT_INIT" --# end_dump_compare "no-diffs" --#} --#test4 -- --#test "destroy 5" --# --#proc test5 {} { --# global test --# --# if {! ([principal_exists "$test/a"] || [create_principal "$test/a"])} { --# error_and_restart "$test: couldn't create principal \"$test/a\"" --# return --# } --# begin_dump --# if {! [cmd { --# kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ --# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ --# server_handle --# }]} { --# perror "$test: unexpected failure on init" --# return --# } --# if {! [cmd {kadm5_destroy $server_handle}]} { --# error_and_restart "$test: couldn't close database" --# return --# } --# one_line_fail_test [format { --# kadm5_delete_principal $server_handle "%s/a" --# } $test] "NOT_INIT" --# end_dump_compare "no-diffs" --#} --#test5 -- --#test "destroy 6" --# --#proc test6 {} { --# global test --# begin_dump --# one_line_fail_test {kadm5_destroy $server_handle} "NOT_INIT" --# end_dump_compare "no-diffs" --#} --#test6 -- -- --#test "destroy 7" --# --#proc test7 {} { --# global test --# begin_dump --# if {! [cmd { --# kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ --# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ --# server_handle --# }]} { --# perror "$test: unexpected failure in init" --# return --# } --# if {! [cmd {kadm5_destroy $server_handle}]} { --# error_and_restart "$test: couldn't close database" --# } --# one_line_fail_test {kadm5_destroy $server_handle} "NOT_INIT" --# end_dump_compare "no-diffs" --#} --#test7 -- --test "destroy 8" --proc test8 {} { -- global test -- begin_dump -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close database" -- } -- one_line_succeed_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close database" -- } -- end_dump_compare "no-diffs" --} --test8 -- --test "destroy 9" --proc test9 {} { -- global test -- one_line_fail_test {kadm5_destroy null} "BAD_SERVER_HANDLE" --} --test9 -- --return "" -diff --git a/src/lib/kadm5/unit-test/api.current/dlte-policy.exp b/src/lib/kadm5/unit-test/api.current/dlte-policy.exp -deleted file mode 100644 -index ad2863d0f..000000000 ---- a/src/lib/kadm5/unit-test/api.current/dlte-policy.exp -+++ /dev/null -@@ -1,208 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --test "delete-policy 2" --proc test2 {} { -- global test --# set prms_id 744 --# setup_xfail {*-*-*} $prms_id -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test \ -- {kadm5_delete_policy $server_handle ""} "BAD_POL" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test2 -- --test "delete-policy 5" --proc test5 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_delete_policy $server_handle "%s/a" -- } $test] "AUTH_DELETE" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if ${RPC} test5 -- --test "delete-policy 6" --proc test6 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_delete_policy $server_handle "%s/a" -- } $test] "AUTH_DELETE" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if ${RPC} test6 -- --test "delete-policy 7" --proc test7 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_delete_policy $server_handle "%s/a" -- } $test] "AUTH_DELETE" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} test7 -- --test "delete-policy 10" --proc test10 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_delete_policy $server_handle "%s/a" -- } $test]]} { -- fail "$test" -- return -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- if { [policy_exists "$test/a"]} { -- fail "$test" -- return -- } --} --test10 -- --test "delete-policy 12" --proc test12 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle [princ_w_pol "%s/a" \ -- "%s/a"] {KADM5_PRINCIPAL KADM5_POLICY} \ -- NotinTheDictionary -- } $test $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- if {! [cmd { -- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_delete_policy $server_handle "%s/a" -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test12 -- --test "delete-policy 13" --proc test13 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- one_line_fail_test [format { -- kadm5_delete_policy null "%s/a" -- } $test] "BAD_SERVER_HANDLE" --} --test13 -- --return "" -diff --git a/src/lib/kadm5/unit-test/api.current/dlte-principal.exp b/src/lib/kadm5/unit-test/api.current/dlte-principal.exp -deleted file mode 100644 -index 660468534..000000000 ---- a/src/lib/kadm5/unit-test/api.current/dlte-principal.exp -+++ /dev/null -@@ -1,253 +0,0 @@ --load_lib lib.t -- --api_exit --api_start -- --#test "delete-principal 1" --#proc test1 {} { --# global test --# one_line_fail_test [format { --# kadm5_delete_principal $server_handle "%s/a" --# } $test] "NOT_INIT" --#} --#test1 -- --test "delete-principal 2" --proc test2 {} { -- global test -- -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test \ -- {kadm5_delete_principal $server_handle null} "EINVAL" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: unexpected failure in destroy" -- return -- } --} --test2 -- --test "delete-principal 5" --proc test5 {} { -- global test -- -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_delete_principal $server_handle "%s/a" -- } $test] "UNK_PRINC" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test5 -- --test "delete-principal 6" --proc test6 {} { -- global test -- -- if {! (( [principal_exists "$test/a"]) || -- [create_principal_pol "$test/a" test-pol])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/delete admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_delete_principal $server_handle "%s/a" -- } $test] "AUTH_DELETE" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test6 } -- -- --test "delete-principal 7" --proc test7 {} { -- global test -- -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_delete_principal $server_handle "%s/a" -- } $test] "AUTH_DELETE" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test7 } -- -- --test "delete-principal 8" --proc test8 {} { -- global test -- -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_delete_principal $server_handle "%s/a" -- } $test] "AUTH_DELETE" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test8 } -- --test "delete-principal 9" --proc test9 {} { -- global test -- -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_delete_principal $server_handle "%s/a" -- } $test] "AUTH_DELETE" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test9 } -- --test "delete-principal 10" --proc test10 {} { -- global test -- -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_delete_principal $server_handle "%s/a" -- } $test] "AUTH_DELETE" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test10 } -- --test "delete-principal 11" --proc test11 {} { -- global test -- -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_delete_principal $server_handle "%s/a" -- } $test]]} { -- fail "$test: delete failed" -- return; -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- if { [principal_exists "$test/a"] } { -- fail "$test" -- return -- } --} --test11 -- --test "delete-principal 13" --proc test13 {} { -- global test -- one_line_fail_test [format { -- kadm5_delete_principal null "%s/a" -- } $test] "BAD_SERVER_HANDLE" --} --test13 -- --return "" -- -- -- -- -- -diff --git a/src/lib/kadm5/unit-test/api.current/get-policy.exp b/src/lib/kadm5/unit-test/api.current/get-policy.exp -deleted file mode 100644 -index c15ef0ca2..000000000 ---- a/src/lib/kadm5/unit-test/api.current/get-policy.exp -+++ /dev/null -@@ -1,199 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --test "get-policy 3" --proc test3 {} { -- global test --# set prms_id 744 --# setup_xfail {*-*-*} $prms_id -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test {kadm5_get_policy $server_handle "" p} "BAD_POLICY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test3 -- --test "get-policy 6" --proc test6 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test {kadm5_get_policy $server_handle test-pol p} \ -- "AUTH_GET" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if { $RPC } test6 -- --test "get-policy 7" --proc test7 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test {kadm5_get_policy $server_handle test-pol p} \ -- "AUTH_GET" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if { $RPC } test7 -- --test "get-policy 11" --proc test11 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/get-pol StupidAdmin $KADM5_ADMIN_SERVICE \ -- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test {kadm5_get_policy $server_handle test-pol p} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test11 -- --test "get-policy 12" --proc test12 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/get-pol StupidAdmin \ -- $KADM5_CHANGEPW_SERVICE null $KADM5_STRUCT_VERSION \ -- $KADM5_API_VERSION_3 server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test \ -- {kadm5_get_policy $server_handle test-pol-nopw p} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test12 -- --test "get-policy 15" --proc test15 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/pol StupidAdmin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test \ -- {kadm5_get_policy $server_handle test-pol-nopw p} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test15 -- --test "get-policy 16" --proc test16 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/pol StupidAdmin $KADM5_CHANGEPW_SERVICE \ -- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test \ -- {kadm5_get_policy $server_handle test-pol-nopw p} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test16 -- --test "get-policy 17" --proc test17 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test {kadm5_get_policy $server_handle test-pol p} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test17 -- --test "get-policy 18" --proc test18 {} { -- global test -- -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test {kadm5_get_policy $server_handle test-pol p} \ -- "AUTH_GET" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if { $RPC } test18 -- --test "get-policy 21" --proc test21 {} { -- global test -- -- one_line_fail_test {kadm5_get_policy null "pol1" p} "BAD_SERVER_HANDLE" --} --test21 -diff --git a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp -deleted file mode 100644 -index 3ea1ba29b..000000000 ---- a/src/lib/kadm5/unit-test/api.current/get-principal-v2.exp -+++ /dev/null -@@ -1,250 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --test "get-principal 100" --proc test100 {} { -- global test prompt -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd { -- kadm5_get_principal $server_handle testuser p \ -- {KADM5_PRINCIPAL_NORMAL_MASK} -- }]} { -- perror "$test: unexpected failure in get_principal" -- } -- send "lindex \$p 16\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" { set num_keys $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting num_keys" -- return -- } -- eof { -- error_and_restart "$test: eof getting num_keys" -- return -- } -- } -- send "lindex \$p 17\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" { set num_tl $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting num_tl" -- return -- } -- eof { -- error_and_restart "$test: eof getting num_tl" -- return -- } -- } -- send "lindex \$p 18\n" -- expect { -- -re "({.*})\n$prompt" {set key_data $expect_out(1,string) } -- -re "\n$prompt" { set key_data {} } -- timeout { -- error_and_restart "$test: timeout getting key_data" -- return -- } -- eof { -- error_and_restart "$test: eof getting key_data" -- return -- } -- } -- send "lindex \$p 19\n" -- expect { -- -re "({.*})\n$prompt" {set tl_data $expect_out(1,string) } -- -re "\n$prompt" { set tl_data {} } -- timeout { -- error_and_restart "$test: timeout getting tl_data" -- return -- } -- eof { -- error_and_restart "$test: eof getting tl_data" -- return -- } -- } -- -- set failed 0 -- if {$num_keys != 0} { -- fail "$test: num_keys $num_keys should be 0" -- set failed 1 -- } -- if {$num_tl != 0} { -- fail "$test: num_tl $num_tl should be 0" -- set failed 1 -- } -- if {$key_data != {}} { -- fail "$test: key_data $key_data should be {}" -- set failed 1 -- } -- if {$tl_data != "{}"} { -- fail "$test: tl_data $tl_data should be empty" -- set failed 1 -- } -- if {$failed == 0} { -- pass "$test" -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test100 -- --proc test101_102 {rpc} { -- global test prompt -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd { -- kadm5_get_principal $server_handle testuser p \ -- {KADM5_PRINCIPAL_NORMAL_MASK KADM5_KEY_DATA} -- }]} { -- perror "$test: unexpected failure in get_principal" -- } -- send "lindex \$p 16\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" { set num_keys $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting num_keys" -- return -- } -- eof { -- error_and_restart "$test: eof getting num_keys" -- return -- } -- } -- send "lindex \$p 18\n" -- expect { -- -re "({.*})\n$prompt" {set key_data $expect_out(1,string) } -- -re "\n$prompt" { set key_data {} } -- timeout { -- error_and_restart "$test: timeout getting key_data" -- return -- } -- eof { -- error_and_restart "$test: eof getting key_data" -- return -- } -- } -- -- set failed 0 -- if {$num_keys != 5} { -- fail "$test: num_keys $num_keys should be 5" -- set failed 1 -- } -- for {set i 0} {$i < $num_keys} {incr i} { -- set key "[lindex [lindex $key_data $i] 2]" -- if {($rpc && [string compare $key ""] != 0) || -- ((! $rpc) && [string compare $key ""] == 0)} { -- fail "$test: key_data $key is wrong" -- set failed 1 -- -- } -- } -- if {$failed == 0} { pass "$test" } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test "get-principal 101" --if {$RPC} {test101_102 $RPC} --test "get-principal 102" --if {! $RPC} {test101_102 $RPC} -- --test "get-principal 103" --proc test103 {} { -- global test prompt -- -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- -- if { ! [cmd [format { -- kadm5_modify_principal $server_handle \ -- "{%s/a} 0 0 0 0 {%s/a} 0 0 0 0 null 0 0 0 0 0 0 1 {} {{999 6 foobar}}" \ -- {KADM5_TL_DATA} -- } $test $test]]} { -- fail "$test: cannot set TL_DATA" -- return -- } -- -- if {! [cmd [format { -- kadm5_get_principal $server_handle {%s/a} p \ -- {KADM5_PRINCIPAL_NORMAL_MASK KADM5_TL_DATA} -- } $test]]} { -- perror "$test: unexpected failure in get_principal" -- } -- send "lindex \$p 17\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" { set num_tl $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting num_tl" -- return -- } -- eof { -- error_and_restart "$test: eof getting num_tl" -- return -- } -- } -- send "lindex \$p 19\n" -- expect { -- -re "({.*})\n$prompt" {set tl_data $expect_out(1,string) } -- -re "\n$prompt" { set tl_data {} } -- timeout { -- error_and_restart "$test: timeout getting tl_data" -- return -- } -- eof { -- error_and_restart "$test: eof getting tl_data" -- return -- } -- } -- -- if {$num_tl == 0} { -- fail "$test: num_tl $num_tl should not be 0" -- } elseif {$tl_data == "{{999 6 foobar}}"} { -- pass "$test" -- } else { -- fail "$test: tl_data $tl_data should be {{999 6 foobar}}" -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test103 -- --return "" -- -- -- -- -diff --git a/src/lib/kadm5/unit-test/api.current/get-principal.exp b/src/lib/kadm5/unit-test/api.current/get-principal.exp -deleted file mode 100644 -index a33fdfe8c..000000000 ---- a/src/lib/kadm5/unit-test/api.current/get-principal.exp -+++ /dev/null -@@ -1,346 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --test "get-principal 1" --proc test1 {} { -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test \ -- {kadm5_get_principal $server_handle null p KADM5_PRINCIPAL_NORMAL_MASK} "EINVAL" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test1 -- --test "get-principal 2" --proc test2 {} { -- global test -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK -- } $test] "UNK_PRINC" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test2 -- --test "get-principal 3" --proc test3 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK -- } $test] "AUTH_GET" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test3 } -- --test "get-principal 4" --proc test4 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK -- } $test] "AUTH_GET" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test4 } -- --test "get-principal 5" --proc test5 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK -- } $test] "AUTH_GET" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test5 } -- --test "get-principal 6" --proc test6 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK -- } $test] "AUTH_GET" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test6 } -- --test "get-principal 7" --proc test7 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/delete admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK -- } $test] "AUTH_GET" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test7 } -- -- --test "get-principal 8" --proc test8 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_get_principal $server_handle "%s/a" p KADM5_PRINCIPAL_NORMAL_MASK -- } $test] "AUTH_GET" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test8 } -- -- --test "get-principal 9" --proc test9 {} { -- global test -- if {! [cmd { -- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test \ -- {kadm5_get_principal $server_handle admin/none p KADM5_PRINCIPAL_NORMAL_MASK} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test9 -- --test "get-principal 10" --proc test10 {} { -- global test -- if {! [cmd { -- kadm5_init admin/none admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test \ -- {kadm5_get_principal $server_handle admin/none p KADM5_PRINCIPAL_NORMAL_MASK} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test10 -- --test "get-principal 11" --proc test11 {} { -- global test -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test {kadm5_get_principal $server_handle admin/get p KADM5_PRINCIPAL_NORMAL_MASK} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test11 -- --test "get-principal 12" --proc test12 {} { -- global test -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test {kadm5_get_principal $server_handle admin/get p KADM5_PRINCIPAL_NORMAL_MASK} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test12 -- --test "get-principal 13" --proc test13 {} { -- global test -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test {kadm5_get_principal $server_handle admin/add p KADM5_PRINCIPAL_NORMAL_MASK} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test13 -- --test "get-principal 14" --proc test14 {} { -- global test -- if {! [cmd { -- kadm5_init admin/get-mod admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test {kadm5_get_principal $server_handle admin/add p KADM5_PRINCIPAL_NORMAL_MASK} -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test14 -- --test "get-principal 15" --proc test15 {} { -- one_line_fail_test \ -- {kadm5_get_principal null "admin" p KADM5_PRINCIPAL_NORMAL_MASK} "BAD_SERVER_HANDLE" --} --test15 -- --return "" -- -- -- -- -diff --git a/src/lib/kadm5/unit-test/api.current/init-v2.exp b/src/lib/kadm5/unit-test/api.current/init-v2.exp -deleted file mode 100644 -index 47764c212..000000000 ---- a/src/lib/kadm5/unit-test/api.current/init-v2.exp -+++ /dev/null -@@ -1,506 +0,0 @@ --load_lib lib.t -- --api_exit --api_start -- --proc get_hostname { } { -- global hostname -- -- if {[info exists hostname]} { -- return 1 -- } -- -- catch "exec hostname >myname" exec_output -- if ![string match "" $exec_output] { -- send_log "$exec_output\n" -- verbose $exec_output -- send_error "ERROR: can't get hostname\n" -- return 0 -- } -- set file [open myname r] -- if { [ gets $file hostname ] == -1 } { -- send_error "ERROR: no output from hostname\n" -- return 0 -- } -- close $file -- catch "exec rm -f myname" exec_output -- -- set hostname [string tolower $hostname] -- verbose "hostname: $hostname" -- -- return 1 --} -- -- --test "init 101" --proc test101 {} { -- global test -- global hostname -- -- get_hostname -- tcl_cmd "set hostname $hostname" -- -- # XXX Fix to work with a remote TEST_SERVER. For now, make sure -- # it fails in that case. -- one_line_succeed_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ -- [config_params {KADM5_CONFIG_ADMIN_SERVER KADM5_CONFIG_KADMIND_PORT} [list $hostname 1751]] \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ -- [config_params {KADM5_CONFIG_ADMIN_SERVER KADM5_CONFIG_KADMIND_PORT} [list $hostname 4]] \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } "RPC_ERROR" --} --if {$RPC} test101 -- --test "init 102" --proc test102 {} { -- global test -- -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ -- [config_params {KADM5_CONFIG_ADMIN_SERVER} does.not.exist] \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } "CANT_RESOLVE" --} --if {$RPC} test102 -- --test "init 103" --proc test103 {} { -- global test -- -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ -- [config_params {KADM5_CONFIG_DBNAME} /does-not-exist] \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } "ENOENT" --} --#if {! $RPC} test103 --if {! $RPC} { -- send_user "UNTESTED: test103: test needs updating for DAL changes (see MIT RT ticket 3202)\n" -- untested "test103: test needs updating for DAL changes (see MIT RT ticket 3202)" --} -- -- --test "init 106" --proc test106 {} { -- global test prompt -- -- set prompting 0 -- send [string trim { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ -- [config_params {KADM5_CONFIG_MKEY_FROM_KBD} 1] \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }] -- send "\n" -- expect { -- -re "\n\[^\n\]+:\[^\n\]*$" { set prompting 1} -- -re "\nOK .*$prompt$" { fail "$test: premature success" } -- -re "\nERROR .*$prompt$" { fail "$test: premature failure" } -- timeout { fail "$test: timeout" } -- eof { fail "$test: eof" } -- } -- if {$prompting} { -- one_line_succeed_test mrroot -- } -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close database" -- } --} --if {! $RPC} test106 -- --test "init 107" --proc test107 {} { -- global test -- -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ -- [config_params {KADM5_CONFIG_STASH_FILE} /does-not-exist] \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } "KDB_CANTREAD_STORED" --} --if {! $RPC} test107 -- --test "init 108" --proc test108 {} { -- global test -- -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ -- [config_params {KADM5_CONFIG_MKEY_NAME} does/not/exist] \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } "KRB5_KDB_CANTREAD_STORED" --} --if {! $RPC} test108 -- --test "init 109-113" --proc test109 {} { -- global test prompt -- -- delete_principal "$test/a" -- -- # I'd like to specify flags explicitly and check them, as in the -- # following config_params, but tcl gets mighty confused if I do and -- # I have no idea why. --# [config_params {KADM5_CONFIG_MAX_LIFE KADM5_CONFIG_MAX_RLIFE KADM5_CONFIG_EXPIRATION KADM5_CONFIG_FLAGS KADM5_CONFIG_ENCTYPES} {10 20 30 KRB5_KDB_DISALLOW_TGT_BASED {}} ] -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE \ -- [config_params {KADM5_CONFIG_MAX_LIFE KADM5_CONFIG_MAX_RLIFE KADM5_CONFIG_EXPIRATION KADM5_CONFIG_ENCTYPES} {10 20 30 {}} ] \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- fail "$test: cannot init with max_life" -- return -- } -- if {! [cmd [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} testpass -- } $test]]} { -- fail "$test: can not create principal" -- return; -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" p \ -- {KADM5_PRINCIPAL_NORMAL_MASK KADM5_KEY_DATA} -- } $test]]} { -- fail "$test: can not get principal" -- return; -- } -- send "puts \$p\n" -- expect { -- -re "$prompt" { } -- timeout { -- error_and_restart "$test: timeout getting prompt" -- return -- } -- eof { -- error_and_restart "$test: eof getting prompt" -- return -- } -- } -- send "lindex \$p 4\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set max_life $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting max_life" -- return -- } -- eof { -- error_and_restart "$test: eof getting max_life" -- return -- } -- } -- send "lindex \$p 12\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set max_rlife $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting max_rlife" -- return -- } -- eof { -- error_and_restart "$test: eof getting max_rlife" -- return -- } -- } -- send "lindex \$p 1\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set expiration $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting expiration" -- return -- } -- eof { -- error_and_restart "$test: eof getting expiration" -- return -- } -- } -- send "lindex \$p 7\n" -- expect { -- -re "(\[A-Z_\]*)\n$prompt" {set flags $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting flags" -- return -- } -- eof { -- error_and_restart "$test: eof getting flags" -- return -- } -- } -- # This sorta worries me. Since the test is setting ENCTYPES to -- # nothing, the principal has no keys. That means that nothing is -- # printed for the keys in the correct case; but it feels too -- # likely that nothing will be printed in the case of some problem. -- send "lindex \$p 18\n" -- expect { -- -re "({.*})\n$prompt" {set key_data $expect_out(1,string) } -- -re "\n$prompt" { set key_data {} } -- timeout { -- error_and_restart "$test: timeout getting flags" -- return -- } -- eof { -- error_and_restart "$test: eof getting flags" -- return -- } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } -- if {$max_life == 10} { -- pass "$test" -- } else { -- fail "$test: $max_life is not 10" -- } -- if {$max_rlife == 20} { -- pass "$test" -- } else { -- fail "$test: $max_rlife is not 20" -- } -- if {$expiration == 30} { -- pass "$test" -- } else { -- fail "$test: $expiration is not 30" -- } -- if {$flags == ""} { -- pass "$test" -- } else { -- fail "$test: flags $flags are wrong" -- } -- if {$key_data == {}} { -- pass "$test" -- } else { -- fail "$test: key_data $key_data is wrong" -- } --} --if {! $RPC} test109 -- --test "init 116" --proc test116 {} { -- global test -- -- delete_principal "$test/a" -- -- if {! [cmd {kadm5_init admin/get-add admin $KADM5_ADMIN_SERVICE \ -- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- get_add_handle}]} { -- error_and_restart "$test: couldn't init with admin/get-add" -- } -- -- if {! [cmd {kadm5_init admin/mod-delete admin $KADM5_ADMIN_SERVICE \ -- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- mod_delete_handle}]} { -- error_and_restart "$test: couldn't init with admin/get-add" -- } -- -- one_line_succeed_test { -- kadm5_get_principal $get_add_handle testuser p \ -- KADM5_PRINCIPAL_NORMAL_MASK -- } -- one_line_succeed_test [format { -- kadm5_create_principal $get_add_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} testpass -- } $test] -- one_line_fail_test { -- kadm5_modify_principal $get_add_handle [simple_principal testuser] \ -- {KADM5_PRINC_EXPIRE_TIME} -- } "AUTH_MODIFY" -- one_line_fail_test { -- kadm5_delete_principal $get_add_handle testuser -- } "AUTH_DELETE" -- -- one_line_fail_test { -- kadm5_get_principal $mod_delete_handle testuser p \ -- KADM5_PRINCIPAL_NORMAL_MASK -- } "AUTH_GET" -- one_line_fail_test [format { -- kadm5_create_principal $mod_delete_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} testpass -- } $test] "AUTH_ADD" -- one_line_succeed_test { -- kadm5_modify_principal $mod_delete_handle [simple_principal testuser] \ -- {KADM5_PRINC_EXPIRE_TIME} -- } -- one_line_succeed_test [format { -- kadm5_delete_principal $mod_delete_handle "%s/a" -- } $test] -- -- if {! [cmd {kadm5_destroy $get_add_handle}]} { -- error_and_restart "$test: couldn't close get_add_handle" -- } -- if {! [cmd {kadm5_destroy $mod_delete_handle}]} { -- error_and_restart "$test: couldn't close mod_delete_handle" -- } --} --if {$RPC} test116 -- --test "init 117" --proc test117 {} { -- global test env prompt -- -- if {[catch "exec grep max_life $env(KRB5_KDC_PROFILE)"] != 1} { -- warning \ -- "$test: max_life in $env(KRB5_KDC_PROFILE), cannot perform test" -- return -- } -- -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- fail "$test: unexpected failure in init" -- return -- } -- -- if {! [cmd [format { -- kadm5_create_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} "%s/a" -- } $test $test]]} { -- perror "$test: unexpected failure creating principal" -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_MAX_LIFE -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 4\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set max_life $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting max_life" -- return -- } -- eof { -- error_and_restart "$test: eof getting max_life" -- return -- } -- } -- -- if {$max_life == 86400} { -- pass "$test" -- } else { -- fail "$test: max_life $max_life should be 86400" -- } -- -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close server_handle" -- } --} --test117 -- --send "puts \$KADM5_ADMIN_SERVICE\n" --expect { -- -re "(\[a-zA-Z/@\]+)\n$prompt" { -- set KADM5_ADMIN_SERVICE $expect_out(1,string) -- } -- default { -- error_and_restart "$test: timeout/eof getting admin_service" -- return -- } --} -- --send "puts \$KADM5_CHANGEPW_SERVICE\n" --expect { -- -re "(\[a-zA-Z/@\]+)\n$prompt" { -- set KADM5_CHANGEPW_SERVICE $expect_out(1,string) -- } -- default { -- error_and_restart "$test: timeout/eof getting changepw_service" -- return -- } --} -- --test "init 150" --proc test150 {} { -- global test KADM5_ADMIN_SERVICE -- -- kdestroy -- kinit testuser notathena "-S $KADM5_ADMIN_SERVICE" -- one_line_succeed_test { -- kadm5_init_with_creds testuser null $KADM5_ADMIN_SERVICE \ -- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } -- kdestroy --} --if {$RPC} test150 -- --test "init 151" --proc test151 {} { -- global test KADM5_CHANGEPW_SERVICE -- -- kdestroy -- kinit testuser notathena "-S $KADM5_CHANGEPW_SERVICE" -- one_line_succeed_test { -- kadm5_init_with_creds testuser null $KADM5_CHANGEPW_SERVICE \ -- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } -- kdestroy --} --if {$RPC} test151 -- --test "init 152" --proc test152 {} { -- global test KADM5_ADMIN_SERVICE -- -- kdestroy -- one_line_fail_test { -- kadm5_init_with_creds testuser null $KADM5_ADMIN_SERVICE \ -- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } "KRB5_FCC_NOFILE" --} --if {$RPC} test152 -- --test "init 153" --proc test153 {} { -- global test KADM5_ADMIN_SERVICE -- -- kinit testuser notathena -- one_line_fail_test { -- kadm5_init_with_creds testuser null $KADM5_ADMIN_SERVICE \ -- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } "KRB5_CC_NOTFOUND" --} --if {$RPC} test153 -- --test "init 154" --proc test154 {} { -- global test env -- -- set orig $env(KRB5_KDC_PROFILE) -- set env(KRB5_KDC_PROFILE) /does-not-exist -- api_exit; api_start -- set env(KRB5_KDC_PROFILE) $orig -- -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } "ENOENT" -- -- api_exit; lib_start_api --} --if {0 && ! $RPC} test154 -- --return "" -diff --git a/src/lib/kadm5/unit-test/api.current/init.exp b/src/lib/kadm5/unit-test/api.current/init.exp -deleted file mode 100644 -index 8390b9cfa..000000000 ---- a/src/lib/kadm5/unit-test/api.current/init.exp -+++ /dev/null -@@ -1,699 +0,0 @@ --load_lib lib.t -- --# Assumptions: --# --# Principal "admin" exists, with "get", "add", "modify" and "delete" --# access bits and password "admin". --# The string "not-the-password" isn't the password of any user in the database. --# Database master password is "mrroot". -- --api_exit --api_start --test "init 1" -- --one_line_fail_test_nochk \ -- {kadm5_init admin admin $KADM5_ADMIN_SERVICE \ -- [config_params {KADM5_CONFIG_REALM} {""}] \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 server_handle} -- --test "init 2" -- --one_line_fail_test_nochk \ -- {kadm5_init admin admin $KADM5_ADMIN_SERVICE \ -- [config_params {KADM5_CONFIG_REALM} {@}] \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 server_handle} -- --test "init 2.5" -- --one_line_fail_test_nochk \ -- {kadm5_init admin admin $KADM5_ADMIN_SERVICE \ -- [config_params {KADM5_CONFIG_REALM} {BAD.REALM}] \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 server_handle} -- --test "init 3" -- --proc test3 {} { -- global test -- if {! ([principal_exists "$test/a"] || [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- one_line_fail_test_nochk [format { -- kadm5_init admin admin "%s/a" null $KADM5_STRUCT_VERSION \ -- $KADM5_API_VERSION_3 server_handle -- } $test] --} --if {$RPC} { test3 } -- --test "init 4" -- --proc test4 {} { -- global test -- if {! ((! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- -- one_line_fail_test_nochk [format { -- kadm5_init admin admin "%s/a" null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } $test] --} --if {$RPC} { test4 } -- --test "init 5" -- --if {$RPC} { -- one_line_fail_test_nochk { -- kadm5_init admin admin admin null $KADM5_STRUCT_VERSION \ -- $KADM5_API_VERSION_3 server_handle -- } --} -- --test "init 6" -- --proc test6 {} { -- global test -- -- send "kadm5_init admin null \$KADM5_ADMIN_SERVICE null \$KADM5_STRUCT_VERSION \$KADM5_API_VERSION_3 server_handle\n" -- -- expect { -- -re "assword\[^\r\n\]*:" { } -- eof { -- fail "$test: eof instead of password prompt" -- api_exit -- api_start -- return -- } -- timeout { -- fail "$test: timeout instead of password prompt" -- return -- } -- } -- one_line_succeed_test "admin" -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close database" -- } --} --if { $RPC } { test6 } -- --test "init 8" -- --proc test8 {} { -- global test -- if {! ([principal_exists "$test/a"] || [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- one_line_fail_test_nochk [format { -- kadm5_init "%s/a" admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } $test] --} --if {$RPC} { test8 } -- --test "init 9" -- --if {$RPC} { -- global test -- one_line_fail_test_nochk { -- kadm5_init admin not-the-password $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } --} -- --test "init 10" -- --proc test10 {} { -- global test --# set prms_id 562 --# setup_xfail {*-*-*} $prms_id -- one_line_fail_test_nochk { -- kadm5_init null admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } --} --test10 -- --#test "init 11" --# --#proc test11 {} { --# global test --# set prms_id 563 --# setup_xfail {*-*-*} $prms_id --# one_line_fail_test_nochk { --# kadm5_init "" admin $KADM5_ADMIN_SERVICE null \ --# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ --# server_handle --# } --#} --#test11 -- --test "init 12" -- --proc test12 {} { -- global test -- one_line_fail_test_nochk [format { -- kadm5_init "%s/a" admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } $test] --} --if {$RPC} { test12 } -- --test "init 13" -- --proc test13 {} { -- global test -- one_line_fail_test_nochk [format { -- kadm5_init "%s/a@SECURE-TEST.OV.COM" admin \ -- $KADM5_ADMIN_SERVICE null $KADM5_STRUCT_VERSION \ -- $KADM5_API_VERSION_3 server_handle -- } $test] --} --if {$RPC} { test13 } -- --test "init 14" -- --proc test14 {} { -- global test -- one_line_fail_test_nochk [format { -- kadm5_init "%s/a@BAD.REALM" admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } $test] --} --if {$RPC} { test14 } -- --test "init 15" -- --if {$RPC} { -- one_line_fail_test_nochk { -- kadm5_init admin@BAD.REALM admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } --} -- --test "init 16" -- --proc test16 {} { -- global test -- one_line_succeed_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close database" -- } --} --test16 -- --test "init 17" -- --proc test17 {} { -- global test -- one_line_succeed_test { -- kadm5_init admin@SECURE-TEST.OV.COM admin \ -- $KADM5_ADMIN_SERVICE null $KADM5_STRUCT_VERSION \ -- $KADM5_API_VERSION_3 server_handle -- } -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close database" -- } --} --test17 -- --test "init 18" -- --proc test18 {} { -- global test -- one_line_succeed_test { -- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close database" -- } --} --test18 -- --test "init 19" -- --proc test19 {} { -- global test -- one_line_succeed_test { -- kadm5_init admin@SECURE-TEST.OV.COM admin \ -- $KADM5_ADMIN_SERVICE \ -- [config_params {KADM5_CONFIG_REALM} {SECURE-TEST.OV.COM}] \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close database" -- } --} --test19 -- --test "init 20" -- --proc test20 {} { -- global test -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- error_and_restart "$test: couldn't init database" -- return -- } -- one_line_succeed_test \ -- {kadm5_get_principal $server_handle admin principal KADM5_PRINCIPAL_NORMAL_MASK} -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close database" -- } --} --test20 -- --#test "init 21" --# --#proc test21 {} { --# global test --# if {! [cmd { --# kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ --# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ --# server_handle --# }]} { --# error_and_restart "$test: couldn't init database" --# return --# } --# one_line_fail_test_nochk { --# kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ --# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ --# server_handle --# } --# if {! [cmd {kadm5_destroy $server_handle}]} { --# error_and_restart "$test: couldn't close database" --# } --#} --#test21 -- -- --# proc test22 {} { --# global test prompt --# set prompting 0 --# send [string trim { --# kadm5_init admin null null null $KADM5_STRUCT_VERSION \ --# $KADM5_API_VERSION_3 server_handle --# }] --# send "\n" --# expect { --# -re ":$" { set prompting 1} --# -re "\nOK .*$prompt$" { fail "$test: premature success" } --# -re "\nERROR .*$prompt$" { fail "$test: premature failure" } --# timeout { fail "$test: timeout" } --# eof { fail "$test: eof" } --# } --# if {$prompting} { --# one_line_succeed_test mrroot --# } --# if {! [cmd {kadm5_destroy $server_handle}]} { --# error_and_restart "$test: couldn't close database" --# } --# } --# if {! $RPC} { test22 } --# --# test "init 22.5" --# proc test225 {} { --# global test prompt --# set prompting 0 --# send [string trim { --# kadm5_init admin null null null $KADM5_STRUCT_VERSION \ --# $KADM5_API_VERSION_3 server_handle --# }] --# send "\n" --# expect { --# -re ":$" { set prompting 1} --# -re "\nOK .*$prompt$" { fail "$test: premature success" } --# -re "\nERROR .*$prompt$" { fail "$test: premature failure" } --# timeout { fail "$test: timeout" } --# eof { fail "$test: eof" } --# } --# if {$prompting} { --# one_line_succeed_test mrroot --# } --# if {! [cmd {kadm5_destroy $server_handle}]} { --# error_and_restart "$test: couldn't close database" --# } --# } --# if {! $RPC} { test225 } -- --test "init 23" -- --proc test23 {} { -- global test -- one_line_succeed_test { -- kadm5_init admin not-the-password $KADM5_ADMIN_SERVICE \ -- null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close database" -- } --} --if {! $RPC} { test23 } -- --test "init 24" -- --proc test24 {} { -- global test -- one_line_succeed_test { -- kadm5_init admin admin null null $KADM5_STRUCT_VERSION \ -- $KADM5_API_VERSION_3 server_handle -- } -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close database" -- } --} --if {! $RPC} { test24 } -- --test "init 25" -- --proc test25 {} { -- global test -- one_line_succeed_test { -- kadm5_init admin admin foobar null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close database" -- } --} --if {! $RPC} { test25 } -- --test "init 26" -- --#proc test26 {} { --# global test --# --# api_exit --# api_start --# one_line_fail_test_nochk { --# kadm5_get_principal $server_handle admin principal --# } --#} --#test26 -- --#test "init 27" --# --#proc test27 {} { --# global test --# --# if {! ((! [principal_exists "$test/a"]) || [delete_principal "$test/a"])} { --# error_and_restart "$test: couldn't delete principal \"$test/a\"" --# return --# } --# begin_dump --# if {[cmd [format { --# kadm5_create_principal $server_handle [simple_principal \ --# "%s/a"] {KADM5_PRINCIPAL} "%s/a" --# } $test $test]]} { --# fail "$test: unexpected success in add" --# return --# } --# end_dump_compare "no-diffs" --#} --#test27 -- --#test "init 28" --# --#proc test28 {} { --# global test prompt --# --# if {! ([principal_exists "$test/a"] || [create_principal "$test/a"])} { --# error_and_restart "$test: couldn't create principal \"$test/a\"" --# return --# } --# begin_dump --# if {! ([cmd { --# kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ --# $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ --# server_handle --# }] && [cmd [format { --# kadm5_get_principal $server_handle "%s/a" principal --# } $test]])} { --# error_and_restart "$test: error getting principal" --# return; --# } --# send "lindex \$principal 8\n" --# expect { --# -re "\n(\[0-9\]+).*$prompt$" {set kvno $expect_out(1,string) } --# timeout { --# error_and_restart "$test: timeout getting principal kvno" --# return --# } --# eof { --# error_and_restart "$test: eof getting principal kvno" --# return --# } --# } --# api_exit --# api_start --# set new_kvno [expr "$kvno + 1"] --# if {[cmd [format { --# kadm5_modify_principal $server_handle \ --# {"%s/a" 0 0 0 0 0 0 0 %d 0 0 0} {KADM5_KVNO} --# } $test $new_kvno]]} { --# fail "$test: unexpected success in modify" --# return; --# } --# end_dump_compare "no-diffs" --#} --#test28 -- --#test "init 29" --# --#proc test29 {} { --# global test --# --# if {! ([principal_exists "$test/a"] || [create_principal "$test/a"])} { --# error_and_restart "$test: couldn't create principal \"$test/a\"" --# return --# } --# begin_dump --# if {[cmd [format { --# kadm5_delete_principal $server_handle "%s/a" --# } $test]]} { --# fail "$test: unexpected success in delete" --# return --# } --# end_dump_compare "no-diffs" --#} --#test29 -- --test "init 30" --proc test30 {} { -- global test -- if {[cmd { -- kadm5_init admin foobar $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- error_and_restart "$test: unexpected success" -- return -- } -- one_line_succeed_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close database" -- } --} --if ${RPC} { test30 } -- --test "init 31" --proc test31 {} { -- global test -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $bad_struct_version_mask $KADM5_API_VERSION_3 \ -- server_handle -- } "BAD_STRUCT_VERSION" --} --test31 -- --test "init 32" --proc test32 {} { -- global test -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $no_struct_version_mask $KADM5_API_VERSION_3 \ -- server_handle -- } "BAD_STRUCT_VERSION" --} --test32 -- --test "init 33" --proc test33 {} { -- global test -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $old_struct_version $KADM5_API_VERSION_3 \ -- server_handle -- } "OLD_STRUCT_VERSION" --} --test33 -- --test "init 34" --proc test34 {} { -- global test -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $new_struct_version $KADM5_API_VERSION_3 \ -- server_handle -- } "NEW_STRUCT_VERSION" --} --test34 -- --test "init 35" --proc test35 {} { -- global test -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $bad_api_version_mask \ -- server_handle -- } "BAD_API_VERSION" --} --test35 -- --test "init 36" --proc test36 {} { -- global test -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $no_api_version_mask \ -- server_handle -- } "BAD_API_VERSION" --} --test36 -- --test "init 37" --proc test37 {} { -- global test -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $old_api_version \ -- server_handle -- } "OLD_LIB_API_VERSION" --} --if { $RPC } test37 -- --test "init 38" --proc test38 {} { -- global test -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $old_api_version \ -- server_handle -- } "OLD_SERVER_API_VERSION" --} --if { ! $RPC } test38 -- --test "init 39" --proc test39 {} { -- global test -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $new_api_version \ -- server_handle -- } "NEW_LIB_API_VERSION" --} --if { $RPC } test39 -- --test "init 40" --proc test40 {} { -- global test -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $new_api_version \ -- server_handle -- } "NEW_SERVER_API_VERSION" --} --if { ! $RPC } test40 -- --test "init 41" --proc test41 {} { -- global test -- one_line_fail_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_API_VERSION_3 $KADM5_STRUCT_VERSION \ -- server_handle -- } "BAD_" --} --test41 -- --test "init 42" --proc test42 {} { -- global test -- one_line_succeed_test { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } -- if {! [cmd {kadm5_destroy $server_handle}]} { -- error_and_restart "$test: couldn't close database" -- } --} --test42 -- -- --proc test45_46 {service} { -- global test kadmin_local env -- -- spawn $kadmin_local -q "delprinc -force $service" -- expect { -- -re "Principal .* deleted." {} -- default { -- perror "kadmin.local delprinc failed\n"; -- } -- } -- expect eof -- wait -- -- one_line_fail_test [concat {kadm5_init admin admin } \ -- $service \ -- { null $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle}] "SECURE_PRINC_MISSING" -- -- # this leaves the keytab with an incorrect entry -- spawn $kadmin_local -q "ank -randkey $service" -- expect eof -- wait -- -- # restart the api so it gets a new ccache -- api_exit -- api_start --} -- --if {$RPC} { -- test "init 45" -- -- test45_46 kadmin/admin -- -- test "init 46" -- -- test45_46 kadmin/changepw --} -- --return "" -- -diff --git a/src/lib/kadm5/unit-test/api.current/mod-policy.exp b/src/lib/kadm5/unit-test/api.current/mod-policy.exp -deleted file mode 100644 -index 1bf00b524..000000000 ---- a/src/lib/kadm5/unit-test/api.current/mod-policy.exp -+++ /dev/null -@@ -1,711 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --test "modify-policy 2" --proc test2 {} { -- global test -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MAX_LIFE} -- } $test] "AUTH_MODIFY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test2 } -- --test "modify-policy 8" --proc test8 {} { -- global test --# set prms_id 744 --# setup_xfail {*-*-*} $prms_id -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test { -- kadm5_modify_policy $server_handle [simple_policy ""] \ -- {KADM5_PW_MAX_LIFE} -- } "BAD_POLICY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test8 -- --test "modify-policy 9" --proc test9 {} { -- global test -- global prompt -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MIN_LIFE} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 1\n" -- expect { -- -re "0\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test9 -- --test "modify-policy 10" --proc test10 {} { -- global test -- global prompt -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle {"%s/a" 32 0 0 0 0 0 0 0 0} \ -- {KADM5_PW_MIN_LIFE} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 1\n" -- expect { -- -re "32\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test10 -- -- --test "modify-policy 11" --proc test11 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MAX_LIFE} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 2\n" -- expect { -- -re "0\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test11 -- --test "modify-policy 12" --proc test12 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 32 0 0 0 0 0 0 0} \ -- {KADM5_PW_MAX_LIFE} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 2\n" -- expect { -- -re "32\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test12 -- --test "modify-policy 13" --proc test13 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MIN_LENGTH} -- } $test] "BAD_LENGTH" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test13 -- --test "modify-policy 14" --proc test14 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 8 0 0 0 0 0 0} \ -- {KADM5_PW_MIN_LENGTH} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 3\n" -- expect { -- -re "8\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test14 -- --test "modify-policy 15" --proc test15 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MIN_CLASSES} -- } $test] "BAD_CLASS" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test15 -- --test "modify-policy 16" --proc test16 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 1 0 0 0 0 0} \ -- {KADM5_PW_MIN_CLASSES} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 4\n" -- expect { -- -re "1\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test16 -- --test "modify-policy 17" --proc test17 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a"])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 5 0 0 0 0 0} \ -- {KADM5_PW_MIN_CLASSES} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 4\n" -- expect { -- -re "5\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test17 -- --test "modify-policy 18" --proc test18 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 6 0 0 0 0 0} \ -- {KADM5_PW_MIN_CLASSES} -- } $test] "BAD_CLASS" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test18 -- --test "modify-policy 19" --proc test19 {} { -- global test -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_HISTORY_NUM} -- } $test] "BAD_HISTORY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test19 -- --test "modify-policy 20" --proc test20 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 0 1 0 0 0 0} \ -- {KADM5_PW_HISTORY_NUM} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 5\n" -- expect { -- -re "1\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test20 -- --test "modify-policy 21" --proc test21 {} { -- global test -- global prompt -- -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 0 10 0 0 0 0} \ -- {KADM5_PW_HISTORY_NUM} -- } $test]]} { -- fail $test -- return -- } -- if {! [cmd [format { -- kadm5_get_policy $server_handle "%s/a" policy -- } $test]]} { -- fail "$test: can not retrieve policy" -- return -- } -- send "lindex \$policy 5\n" -- expect { -- -re "10\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test21 -- --test "modify-policy 22" --proc test22 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MAX_LIFE} -- } $test] "AUTH_MODIFY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} test22 -- --test "modify-policy 23" --proc test23 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MAX_LIFE} -- } $test] "AUTH_MODIFY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} test23 -- --test "modify-policy 26" --proc test26 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_modify_policy $server_handle [simple_policy "%s/a"] \ -- {KADM5_PW_MAX_LIFE} -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test26 -- --test "modify-policy 30" --proc test30 {} { -- global test -- -- one_line_fail_test [format { -- kadm5_modify_policy null [simple_policy "%s/a"] \ -- {KADM5_PW_MAX_LIFE} -- } $test] "BAD_SERVER_HANDLE" --} --test30 -- --test "modify-policy 31" --proc test31 {} { -- global test -- if {! (( [policy_exists "$test/a"]) || -- [create_policy "$test/a" ])} { -- error_and_restart "$test: couldn't create policy \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 0 0 0 2 0 0} \ -- {KADM5_PW_MAX_FAILURE} -- } $test] -- one_line_succeed_test [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 1 0 0 0 90 0} \ -- {KADM5_PW_FAILURE_COUNT_INTERVAL} -- } $test] -- one_line_succeed_test [format { -- kadm5_modify_policy $server_handle {"%s/a" 0 0 0 1 0 0 0 0 180} \ -- {KADM5_PW_LOCKOUT_DURATION} -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test31 -- --return "" -diff --git a/src/lib/kadm5/unit-test/api.current/mod-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/mod-principal-v2.exp -deleted file mode 100644 -index 4abbeb52d..000000000 ---- a/src/lib/kadm5/unit-test/api.current/mod-principal-v2.exp -+++ /dev/null -@@ -1,115 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --test "modify-principal 100-105" --proc test100_104 {} { -- global test -- global prompt -- -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- -- set origtest "$test" -- -- test "modify-principal 100" -- one_line_succeed_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_MAX_RLIFE} -- } $origtest] -- -- test "modify-principal 101" -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_LAST_SUCCESS} -- } $origtest] "BAD_MASK" -- -- test "modify-principal 102" -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_LAST_FAILED} -- } $origtest] "BAD_MASK" -- --# This is now permitted to reset lockout count --# test "modify-principal 103" --# one_line_fail_test [format { --# kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ --# {KADM5_FAIL_AUTH_COUNT} --# } $origtest] "BAD_MASK" -- -- test "modify-principal 103.5" -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_KEY_DATA} -- } $origtest] "BAD_MASK" -- -- test "modify-principal 105" -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle \ -- "{%s/a} 0 0 0 0 {%s/a} 0 0 0 0 null 0 0 0 0 0 0 1 {} {{1 1 x}}" \ -- {KADM5_TL_DATA} -- } $origtest $origtest] "BAD_TL_TYPE" -- -- test "modify-principal 100,104" -- if { ! [cmd [format { -- kadm5_modify_principal $server_handle \ -- "{%s/a} 0 0 0 0 {%s/a} 0 0 0 0 null 0 88 0 0 0 0 1 {} {{990 6 foobar}}" \ -- {KADM5_MAX_RLIFE KADM5_TL_DATA} -- } $origtest $origtest]]} { -- fail "$test: cannot set MAX_RLIFE or TL_DATA" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal {KADM5_PRINCIPAL_NORMAL_MASK KADM5_TL_DATA} -- } $origtest]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 12\n" -- expect { -- -re "(\[0-9\]+)\n$prompt$" {set rlife $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting rlife" -- return -- } -- eof { -- error_and_restart "$test: eof getting rlife" -- return -- } -- } -- send "lindex \$principal 19\n" -- expect { -- -re "\(\{.*\}\)\n$prompt$" {set tl $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting tl_data" -- return -- } -- eof { -- error_and_restart "$test: eof getting tl_data" -- return -- } -- } -- if {($rlife == 88) && ($tl == "{{990 6 foobar}}")} { -- pass "$test" -- } else { -- fail "$test: $rlife should be 88, $tl should be {{990 6 foobar}}" -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test100_104 -diff --git a/src/lib/kadm5/unit-test/api.current/mod-principal.exp b/src/lib/kadm5/unit-test/api.current/mod-principal.exp -deleted file mode 100644 -index ac9f96845..000000000 ---- a/src/lib/kadm5/unit-test/api.current/mod-principal.exp -+++ /dev/null -@@ -1,1606 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --#test "modify-principal 1" --#proc test1 {} { --# global test --# one_line_fail_test [format { --# kadm5_modify_principal $server_handle [simple_principal \ --# "%s/a"] {KADM5_PW_EXPIRATION} --# } $test] "NOT_INIT" --#} --#test1 -- --test "modify-principal 2" --proc test2 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINC_EXPIRE_TIME} -- } $test] "AUTH_MODIFY" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test2 } -- --test "modify-principal 4" --proc test4 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINCIPAL} -- } $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test4 -- -- --test "modify-principal 5" --proc test5 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_LAST_PWD_CHANGE} -- } $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test5 -- --test "modify-principal 6" --proc test6 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_MOD_TIME} -- } $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test6 -- --test "modify-principal 7" --proc test7 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_MOD_NAME} -- } $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test7 -- --test "modify-principal 8" --proc test8 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_MKVNO} -- } $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test8 -- --test "modify-principal 9" --proc test9 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_AUX_ATTRIBUTES} -- } $test] "BAD_MASK" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test9 -- --test "modify-principal 10" --proc test10 {} { -- global test -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINC_EXPIRE_TIME} -- } $test] "UNK_PRINC" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test10 -- --test "modify-principal 11" --proc test11 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/none admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINC_EXPIRE_TIME} -- } $test] "AUTH_MOD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if { $RPC } { test11 } -- --test "modify-principal 12" --proc test12 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/get admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINC_EXPIRE_TIME} -- } $test] "AUTH_MOD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if { $RPC } { test12 } -- --test "modify-principal 13" --proc test13 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/add admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINC_EXPIRE_TIME} -- } $test] "AUTH_MOD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if { $RPC } { test13 } -- --test "modify-principal 14" --proc test14 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/delete admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINC_EXPIRE_TIME} -- } $test] "AUTH_MOD" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if { $RPC } { test14 } -- --test "modify-principal 15" --proc test15 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINC_EXPIRE_TIME} -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test15 -- --test "modify-principal 17" --proc test17 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_modify_principal $server_handle [princ_w_pol "%s/a" \ -- no-policy] {KADM5_POLICY} -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test17 -- --test "modify-principal 21.5" --proc test21.5 {} { -- global test -- global prompt -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if { !( [create_principal_pol "$test/a" "test-pol"])} { -- error_and_restart "$test: could not create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd {kadm5_get_policy $server_handle test-pol old_p1}]} { -- perror "$test: unexpected failure on get policy" -- return -- } -- if {! [cmd [format { -- kadm5_modify_principal $server_handle [princ_w_pol "%s/a" \ -- test-pol] {KADM5_POLICY} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$old_p1 6\n" -- expect { -- -re "(\[0-9\]+)\n$prompt$" {set old_p1_ref $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting principal kvno (second time)" -- return -- } -- eof { -- error_and_restart "$test: eof getting principal kvno (second time)" -- return -- } -- } -- -- if { ! [cmd {kadm5_get_policy $server_handle test-pol new_p1}]} { -- perror "$test: unexpected failure on get policy" -- return -- } -- -- send "lindex \$new_p1 6\n" -- expect { -- -re "(\[0-9\]+)\n$prompt$" {set new_p1_ref $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting principal kvno (second time)" -- return -- } -- eof { -- error_and_restart "$test: eof getting principal kvno (second time)" -- return -- } -- } -- -- if {$old_p1_ref != $new_p1_ref} { -- fail "$test: policy reference count changed ($old_p1_ref to $new_p1_ref)" -- return -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test21.5 -- --test "modify-principal 22" --proc test22 {} { -- global test -- global prompt -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PW_EXPIRATION} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 3\n" -- expect { -- -re "0\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test22 -- --test "modify-principal 23" --proc test23 {} { -- global test -- global prompt -- if {! (( [principal_exists "$test/a"]) || -- [create_principal_pol "$test/a" test-pol-nopw])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PW_EXPIRATION} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 3\n" -- expect { -- -re "0\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test23 -- --test "modify-principal 24" --proc test24 {} { -- global test -- global prompt -- -- if {! (( [principal_exists "$test/a"]) || -- [create_principal_pol "$test/a" "test-pol" ])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- error_and_restart "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PW_EXPIRATION} -- } $test]]} { -- fail "$test: could not modify principal" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- if { ! [cmd [format { -- kadm5_get_policy $server_handle %s policy -- } test-pol]]} { -- error_and_restart "$test: cannot retrieve policy" -- return -- } -- send "lindex \$principal 2\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_mod_date $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting mod_date" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_mod_date" -- return -- } -- } -- -- send "lindex \$principal 3\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_expire $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting pw_expire" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_expire" -- return -- } -- } -- -- send "lindex \$policy 2\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_max_life $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting pw_max_life" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_max_life" -- return -- } -- } -- if { $pw_expire != 0 } { -- fail "$test: pw_expire $pw_expire should be 0" -- return -- } else { -- pass "$test" -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test24 -- --test "modify-principal 25" --proc test25 {} { -- global test -- global prompt -- -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_modify_principal $server_handle \ -- {"%s/a" 0 0 1234 0 0 0 0 0 0 0 0} {KADM5_PW_EXPIRATION} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 3\n" -- expect { -- -re "1234\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test25 -- --test "modify-principal 26" --proc test26 {} { -- global test -- global prompt -- -- if {! (( [principal_exists "$test/a"]) || -- [create_principal_pol "$test/a" "test-pol-nopw" ])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_modify_principal $server_handle \ -- {"%s/a" 0 0 1234 0 0 0 0 0 0 0 0} {KADM5_PW_EXPIRATION} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 3\n" -- expect { -- -re "1234\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test26 -- --test "modify-principal 27" --proc test27 {} { -- global test -- global prompt -- -- if {! (( [principal_exists "$test/a"]) || -- [create_principal_pol "$test/a" "test-pol" ])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_modify_principal $server_handle \ -- {"%s/a" 0 0 1234 0 0 0 0 0 0 0 0} {KADM5_PW_EXPIRATION} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 3\n" -- expect { -- -re "1234\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test27 -- --test "modify-principal 28" --proc test28 {} { -- global test -- global prompt --# set prms_id 1358 --# setup_xfail {*-*-*} $prms_id -- -- if {! (( [principal_exists "$test/a"]) || -- [create_principal_pol "$test/a" "test-pol" ])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_modify_principal $server_handle \ -- {"%s/a" 0 0 999999999 0 0 0 0 0 0 0 0} {KADM5_PW_EXPIRATION} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- if { ! [cmd {kadm5_get_policy $server_handle test-pol policy}]} { -- error_and_restart "$test: cannot retrieve policy" -- return -- } -- send "lindex \$principal 2\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_mod_date $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting pw_mod_date" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_mod_date" -- return -- } -- } -- -- send "lindex \$principal 3\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_expire $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting pw_expire" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_expire" -- return -- } -- } -- send "lindex \$policy 2\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_max_life $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting pw_max_life" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_max_life" -- return -- } -- } -- if { $pw_expire != 999999999 } { -- fail "$test: pw_expire $pw_expire should be 999999999" -- return -- } -- pass "$test" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test28 -- --test "modify-principal 29" --proc test29 {} { -- global test -- global prompt -- -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if { ! ([create_principal_pol "$test/a" test-pol])} { -- perror "$test: unexpected failure in creating principal" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_POLICY_CLR} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 3\n" -- expect { -- -re "0\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test29 -- --test "modify-principal 30" --proc test30 {} { -- global test -- global prompt -- -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! ([create_principal_pol "$test/a" test-pol])} { -- perror "$test: unexpected failure in creating principal" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_modify_principal $server_handle [princ_w_pol "%s/a" \ -- test-pol-nopw] {KADM5_POLICY} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 3\n" -- expect { -- -re "0\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test30 -- --test "modify-principal 31" --proc test31 {} { -- global test -- global prompt -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! ([create_principal "$test/a"])} { -- perror "$test: unexpected failure in creating principal" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_modify_principal $server_handle [princ_w_pol "%s/a" \ -- test-pol] {KADM5_POLICY} -- } $test]]} { -- fail "modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- if { ! [cmd {kadm5_get_policy $server_handle test-pol policy}]} { -- error_and_restart "$test: cannot retrieve policy" -- return -- } -- send "lindex \$principal 2\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_mod_date $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting pw_mod_date" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_mod_date" -- return -- } -- } -- -- send "lindex \$principal 3\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_expire $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting pw_expire" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_expire" -- return -- } -- } -- -- send "lindex \$policy 2\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" {set pw_max_life $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting pw_max_life" -- return -- } -- eof { -- error_and_restart "$test: eof getting pw_max_life" -- return -- } -- } -- if { [expr "$pw_mod_date + $pw_max_life"] != $pw_expire } { -- fail "$test: pw_expire is wrong" -- return -- } -- -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test31 -- --test "modify-principal 32" --proc test32 {} { -- global test -- global prompt -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! ([create_principal "$test/a"])} { -- perror "$test: unexpected failure in creating principal" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_principal $server_handle \ -- {"%s/a" 1234 0 0 0 0 0 0 0 0 0 0} \ -- {KADM5_PRINC_EXPIRE_TIME} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 1\n" -- expect { -- -re "1234\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test32 -- --test "modify-principal 33" --proc test33 {} { -- global test -- global prompt -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! ([create_principal "$test/a"])} { -- perror "$test: unexpected failure in creating principal" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_principal $server_handle \ -- {"%s/a" 0 0 0 0 0 0 KRB5_KDB_DISALLOW_ALL_TIX 0 0 0 0} \ -- {KADM5_ATTRIBUTES} -- } $test]]} { -- fail "$test: modified fail" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 7\n" -- expect { -- -re "KRB5_KDB_DISALLOW_ALL_TIX.*$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test33 -- --test "modify-principal 33.25" --proc test3325 {} { -- global test -- global prompt -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! ([create_principal "$test/a"])} { -- perror "$test: unexpected failure in creating principal" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_principal $server_handle \ -- {"%s/a" 0 0 0 0 0 0 KRB5_KDB_REQUIRES_PWCHANGE 0 0 0 0} \ -- {KADM5_ATTRIBUTES} -- } $test]]} { -- fail "$test: modified fail" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 7\n" -- expect { -- -re "KRB5_KDB_REQUIRES_PWCHANGE.*$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test3325 -- --test "modify-principal 33.5" --proc test335 {} { -- global test -- global prompt -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! ([create_principal "$test/a"])} { -- perror "$test: unexpected failure in creating principal" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_principal $server_handle \ -- {"%s/a" 0 0 0 0 0 0 KRB5_KDB_DISALLOW_TGT_BASED 0 0 0 0} \ -- {KADM5_ATTRIBUTES} -- } $test]]} { -- fail "$test: modified fail" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 7\n" -- expect { -- -re "KRB5_KDB_DISALLOW_TGT_BASED.*$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test335 -- -- --test "modify-principal 34" --proc test34 {} { -- global test -- global prompt -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! ([create_principal "$test/a"])} { -- perror "$test: unexpected failure in creating principal" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_modify_principal $server_handle \ -- {"%s/a" 0 0 0 3456 0 0 0 0 0 0 0} {KADM5_MAX_LIFE} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 4\n" -- expect { -- -re "3456\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test34 -- --test "modify-principal 35" --proc test35 {} { -- global prompt -- global test -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! ([create_principal "$test/a"])} { -- perror "$test: unexpected failure in creating principal" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd [format { -- kadm5_modify_principal $server_handle \ -- {"%s/a" 0 0 0 0 0 0 0 7 0 0 0} {KADM5_KVNO} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 8\n" -- expect { -- -re "7\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test35 -- --test "modify-principal 36" --proc test36 {} { -- global test -- global prompt -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if { !( [create_principal_pol "$test/a" "test-pol"])} { -- error_and_restart "$test: could not create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if { ! [cmd {kadm5_get_policy $server_handle test-pol pol}]} { -- perror "$test: unexpected failure on get policy" -- return -- } -- if {! [cmd [format { -- kadm5_modify_principal $server_handle [princ_w_pol "%s/a" \ -- test-pol] {KADM5_POLICY} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 10\n" -- expect { -- -re "test-pol\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- send "lindex \$pol 6\n" -- expect { -- -re "(\[0-9\]+)\n$prompt$" {set oldref $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting principal kvno (second time)" -- return -- } -- eof { -- error_and_restart "$test: eof getting principal kvno (second time)" -- return -- } -- } -- if { ! [cmd {kadm5_get_policy $server_handle test-pol pol2}]} { -- perror "$test: unexpected failure on get policy" -- return -- } -- send "lindex \$pol2 6\n" -- expect { -- -re "(\[0-9\]+)\n$prompt$" {set newref $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting principal kvno (second time)" -- return -- } -- eof { -- error_and_restart "$test: eof getting principal kvno (second time)" -- return -- } -- } -- if { $oldref != $newref } { -- fail "$test: policy reference count is wrong" -- return; -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test36 -- --test "modify-principal 37" --proc test37 {} { -- global test -- global prompt -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if { !( [create_principal "$test/a"])} { -- error_and_restart "$test: could not create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_POLICY_CLR} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test37 -- --test "modify-principal 38" --proc test38 {} { -- global test -- global prompt -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! ([create_principal "$test/a"])} { -- perror "$test: unexpected failure in creating principal" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_PRINC_EXPIRE_TIME} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 1\n" -- expect { -- -re "0\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test38 -- --test "modify-principal 39" --proc test39 {} { -- global test -- global prompt -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! ([create_principal "$test/a"])} { -- perror "$test: unexpected failure in creating principal" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_principal $server_handle [simple_principal "%s/a"] \ -- {KADM5_MAX_LIFE} -- } $test]]} { -- fail "$test: modify failed" -- return -- } -- if {! [cmd [format { -- kadm5_get_principal $server_handle "%s/a" principal KADM5_PRINCIPAL_NORMAL_MASK -- } $test]]} { -- error_and_restart "$test: could not retrieve principal" -- return -- } -- send "lindex \$principal 4\n" -- expect { -- -re "0\n$prompt$" { pass "$test" } -- timeout { fail "$test" } -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test39 -- --test "modify-principal 40" --proc test40 {} { -- global test -- global prompt -- -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test { -- kadm5_modify_principal $server_handle null \ -- {KADM5_PRINC_EXPIRE_TIME} -- } "EINVAL" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test40 -- --test "modify-principal 43" --proc test43 {} { -- global test -- one_line_fail_test [format { -- kadm5_modify_principal null [simple_principal \ -- "%s/a"] {KADM5_PW_EXPIRATION} -- } $test] "BAD_SERVER_HANDLE" --} --test43 -- --test "modify-principal 44" --proc test44 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- # setting fail auth count to a non-zero value must fail -- one_line_fail_test [format { -- kadm5_modify_principal $server_handle \ -- {"%s/a" 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1234 0 0 {} {}} {KADM5_FAIL_AUTH_COUNT} -- } $test] "BAD_SERVER_PARAMS" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test44 -- --return "" -diff --git a/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp b/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp -deleted file mode 100644 -index 2925c1c43..000000000 ---- a/src/lib/kadm5/unit-test/api.current/randkey-principal-v2.exp -+++ /dev/null -@@ -1,61 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --test "randkey-principal 100" --proc test100 {} { -- global test prompt -- -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [create_principal "$test/a"]} { -- error_and_restart "$test: creating principal" -- return -- } -- -- # I'd like to specify a long list of keysalt tuples and make sure that -- # randkey does the right thing, but we can only use those enctypes that -- # krbtgt has a key for: 3DES and AES, according to the prototype kdc.conf. -- if {! [cmd [format { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_randkey_principal $server_handle "%s/a" keys num_keys -- } $test]]} { -- perror "$test: unexpected failure in randkey_principal" -- } -- send "puts \$num_keys\n" -- expect { -- -re "(\[0-9\]+)\n$prompt" { set num_keys $expect_out(1,string) } -- timeout { -- error_and_restart "$test: timeout getting num_keys" -- return -- } -- eof { -- error_and_restart "$test: eof getting num_keys" -- return -- } -- } -- -- # XXX Perhaps I should actually check the key type returned. -- if {$num_keys == 5} { -- pass "$test" -- } else { -- fail "$test: $num_keys keys, should be 5" -- } -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test100 -- --return "" -diff --git a/src/lib/kadm5/unit-test/api.current/randkey-principal.exp b/src/lib/kadm5/unit-test/api.current/randkey-principal.exp -deleted file mode 100644 -index 1484901fa..000000000 ---- a/src/lib/kadm5/unit-test/api.current/randkey-principal.exp -+++ /dev/null -@@ -1,297 +0,0 @@ --load_lib lib.t --api_exit --api_start -- --test "randkey-principal 1" --proc test1 {} { -- global test -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [create_principal_pol "$test/a" once-a-min]} { -- error_and_restart "$test: creating principal" -- return -- } -- -- if {! [cmd [format { -- kadm5_init "%s/a" "%s/a" $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } $test $test]]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_randkey_principal $server_handle "%s/a" keys num_keys -- } $test] "PASS_TOOSOON" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test1 } -- --test "randkey-principal 3" --proc test3 {} { -- global test -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [create_principal_pol "$test/a" once-a-min]} { -- error_and_restart "$test: creating principal" -- return -- } -- -- if {! [cmd [format { -- kadm5_init "%s/a" "%s/a" $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } $test $test]]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_randkey_principal $server_handle "%s/a" keys num_keys -- } $test] "PASS_TOOSOON" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if ${RPC} { test3 } -- --test "randkey-principal 13" --proc test13 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- if {! [cmd [format { -- kadm5_modify_principal $server_handle [princ_w_pol "%s/a" \ -- once-a-min] KADM5_POLICY -- } $test]]} { -- perror "$test: failed modify" -- return -- } -- one_line_succeed_test [format { -- kadm5_randkey_principal $server_handle "%s/a" keys num_keys -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test13 -- --test "randkey-principal 15" --proc test15 {} { -- global test -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [create_principal_pol "$test/a" once-a-min]} { -- error_and_restart "$test: creating principal" -- return -- } -- -- if {! [cmd { -- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_randkey_principal $server_handle "%s/a" keys num_keys -- } $test] "AUTH_CHANGEPW" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if { $RPC } { test15 } -- --test "randkey-principal 28" --proc test28 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_randkey_principal $server_handle "%s/a" keys num_keys -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test28 -- --test "randkey-principal 28.25" --proc test2825 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin admin $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_randkey_principal $server_handle "%s/a" keys num_keys -- } $test] "AUTH" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --if {$RPC} { test2825 } -- --test "randkey-principal 28.5" --proc test285 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [cmd { -- kadm5_init admin/modify admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_randkey_principal $server_handle "%s/a" keys num_keys -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test285 -- --test "randkey-principal 30" --proc test30 {} { -- global test -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't delete principal \"$test/a\"" -- return -- } -- if {! [create_principal "$test/a"]} { -- error_and_restart "$test: creating principal" -- return -- } -- if {! [cmd [format { -- kadm5_init "%s/a" "%s/a" $KADM5_CHANGEPW_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } $test $test]]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_randkey_principal $server_handle "%s/a" keys num_keys -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test30 -- --test "randkey-principal 31" --proc test31 {} { -- global test -- if {! (( ! [principal_exists "$test/a"]) || -- [delete_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if {! [create_principal "$test/a"]} { -- error_and_restart "$test: creating principal" -- return -- } -- -- if {! [cmd [format { -- kadm5_init "%s/a" "%s/a" $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- } $test $test]]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_succeed_test [format { -- kadm5_randkey_principal $server_handle "%s/a" keys num_keys -- } $test] -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} --test31 -- --test "randkey-principal 33" --proc test33 {} { -- global test -- if {! (( [principal_exists "$test/a"]) || -- [create_principal "$test/a"])} { -- error_and_restart "$test: couldn't create principal \"$test/a\"" -- return -- } -- if { ! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- server_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- one_line_fail_test [format { -- kadm5_randkey_principal null "%s/a" keys num_keys -- } $test] "BAD_SERVER_HANDLE" -- if { ! [cmd {kadm5_destroy $server_handle}]} { -- perror "$test: unexpected failure in destroy" -- return -- } --} -- --test33 -- --return "" -diff --git a/src/lib/kadm5/unit-test/config/unix.exp b/src/lib/kadm5/unit-test/config/unix.exp -deleted file mode 100644 -index d7706ec53..000000000 ---- a/src/lib/kadm5/unit-test/config/unix.exp -+++ /dev/null -@@ -1,222 +0,0 @@ --source runenv.exp -- --set prompt "% " --set stty_init {-onlcr -opost intr \^C kill \^U} --set kadmin_local $KADMIN_LOCAL -- --# Backward compatibility until we're using expect 5 everywhere --if {[info exists exp_version_4]} { -- global wait_error_index wait_errno_index wait_status_index -- set wait_error_index 0 -- set wait_errno_index 1 -- set wait_status_index 1 --} else { -- set wait_error_index 2 -- set wait_errno_index 3 -- set wait_status_index 3 --} -- --if { [string length $VALGRIND] } { -- rename spawn valgrind_aux_spawn -- proc spawn { args } { -- global VALGRIND -- upvar 1 spawn_id spawn_id -- set newargs {} -- set inflags 1 -- set eatnext 0 -- foreach arg $args { -- if { $arg == "-ignore" \ -- || $arg == "-open" \ -- || $arg == "-leaveopen" } { -- lappend newargs $arg -- set eatnext 1 -- continue -- } -- if [string match "-*" $arg] { -- lappend newargs $arg -- continue -- } -- if { $eatnext } { -- set eatnext 0 -- lappend newargs $arg -- continue -- } -- if { $inflags } { -- set inflags 0 -- # Only run valgrind for local programs, not -- # system ones. --#&&![string match "/bin/sh" $arg] sh is used to start kadmind! -- if [string match "/" [string index $arg 0]]&&![string match "/bin/ls" $arg]&&![regexp {/kshd$} $arg] { -- set newargs [concat $newargs $VALGRIND] -- } -- } -- lappend newargs $arg -- } -- set pid [eval valgrind_aux_spawn $newargs] -- return $pid -- } --} -- --# Hack around Solaris 9 kernel race condition that causes last output --# from a pty to get dropped. --if { $PRIOCNTL_HACK } { -- catch {exec priocntl -s -c FX -m 30 -p 30 -i pid [getpid]} -- rename spawn oldspawn -- proc spawn { args } { -- upvar 1 spawn_id spawn_id -- set newargs {} -- set inflags 1 -- set eatnext 0 -- foreach arg $args { -- if { $arg == "-ignore" \ -- || $arg == "-open" \ -- || $arg == "-leaveopen" } { -- lappend newargs $arg -- set eatnext 1 -- continue -- } -- if [string match "-*" $arg] { -- lappend newargs $arg -- continue -- } -- if { $eatnext } { -- set eatnext 0 -- lappend newargs $arg -- continue -- } -- if { $inflags } { -- set inflags 0 -- set newargs [concat $newargs {priocntl -e -c FX -p 0}] -- } -- lappend newargs $arg -- } -- set pid [eval oldspawn $newargs] -- return $pid -- } --} -- --# Variables for keeping track of api process state --set api_pid "0" -- --proc api_exit {} { -- global spawn_id -- global api_pid -- --# puts stdout "Starting api_exit (spawn_id $spawn_id)." -- catch {close} errMsg -- catch {wait} errMsg --# puts stdout "Finishing api_exit for $api_pid." -- set api_pid "0" --} -- --proc api_isrunning {pid} { -- global api_pid -- --# puts stdout "testing $pid, api_pid is $api_pid" -- if {$pid == $api_pid} { -- return 1; -- } else { -- return 0; -- } --} -- --proc api_version {} { --} -- --proc api_start {} { -- global API -- global env -- global spawn_id -- global prompt -- global api_pid -- -- set pid [spawn $API] -- expect { -- -re "$prompt$" {} -- eof { perror "EOF starting API" } -- timeout { perror "Timeout starting API" } -- } -- if {! [info exists env(TCLUTIL)]} { -- perror "TCLUTIL environment variable isn't set" -- } -- # tcl 8.4 for some reason screws up autodetection of output -- # EOL translation. Work around it for now. -- send "if { \[info commands fconfigure\] ne \"\" } { fconfigure stdout -translation lf }\n" -- expect { -- -re "$prompt$" {} -- eof { perror "EOF starting API" } -- timeout { perror "Timeout starting API" } -- } -- send "source $env(TCLUTIL)\n" -- expect { -- -re "$prompt$" {} -- eof { perror "EOF starting API" } -- timeout { perror "Timeout starting API" } -- } -- send "set current_struct_version \[expr \$KADM5_STRUCT_VERSION &~ \$KADM5_STRUCT_VERSION_MASK\]\n" -- expect { -- -re "$prompt$" {} -- eof { perror "EOF setting API variables"} -- timeout { perror "timeout setting API variables"} -- } -- send "set current_api_version \[expr \$KADM5_API_VERSION_3 &~ \$KADM5_API_VERSION_MASK\]\n" -- expect { -- -re "$prompt$" {} -- eof { perror "EOF setting API variables"} -- timeout { perror "timeout setting API variables"} -- } -- send "set bad_struct_version_mask \[expr 0x65432100 | \$current_struct_version\]\n" -- expect { -- -re "$prompt$" {} -- eof { perror "EOF setting API variables"} -- timeout { perror "timeout setting API variables"} -- } -- send "set bad_api_version_mask \[expr 0x65432100 | \$current_api_version\]\n" -- expect { -- -re "$prompt$" {} -- eof { perror "EOF setting API variables"} -- timeout { perror "timeout setting API variables"} -- } -- send "set no_api_version_mask \$current_api_version\n" -- expect { -- -re "$prompt$" {} -- eof { perror "EOF setting API variables"} -- timeout { perror "timeout setting API variables"} -- } -- send "set no_struct_version_mask \$current_struct_version\n" -- expect { -- -re "$prompt$" {} -- eof { perror "EOF setting API variables"} -- timeout { perror "timeout setting API variables"} -- } -- send "set old_api_version \[expr \$KADM5_API_VERSION_MASK | 0x00\]\n" -- expect { -- -re "$prompt$" {} -- eof { perror "EOF setting API variables"} -- timeout { perror "timeout setting API variables"} -- } -- send "set old_struct_version \[expr \$KADM5_STRUCT_VERSION_MASK | 0x00\]\n" -- expect { -- -re "$prompt$" {} -- eof { perror "EOF setting API variables"} -- timeout { perror "timeout setting API variables"} -- } -- send "set new_api_version \[expr \$KADM5_API_VERSION_MASK | 0xca\]\n" -- expect { -- -re "$prompt$" {} -- eof { perror "EOF setting API variables"} -- timeout { perror "timeout setting API variables"} -- } -- send "set new_struct_version \[expr \$KADM5_STRUCT_VERSION_MASK | 0xca\]\n" -- expect { -- -re "$prompt$" {} -- eof { perror "EOF setting API variables"} -- timeout { perror "timeout setting API variables"} -- } -- -- set api_pid $pid --# puts stdout "Finishing api_start (spawn_id $spawn_id, pid $api_pid)." -- return $pid --} --api_start -- -diff --git a/src/lib/kadm5/unit-test/deps b/src/lib/kadm5/unit-test/deps -deleted file mode 100644 -index cf54f475b..000000000 ---- a/src/lib/kadm5/unit-test/deps -+++ /dev/null -@@ -1,86 +0,0 @@ --# --# Generated makefile dependencies follow. --# --$(OUTPRE)init-test.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ -- $(BUILDTOP)/include/gssrpc/types.h $(BUILDTOP)/include/kadm5/admin.h \ -- $(BUILDTOP)/include/kadm5/chpass_util_strings.h $(BUILDTOP)/include/kadm5/kadm_err.h \ -- $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ -- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ -- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ -- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ -- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ -- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/kdb.h \ -- $(top_srcdir)/include/krb5.h init-test.c --$(OUTPRE)destroy-test.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ -- $(BUILDTOP)/include/gssrpc/types.h $(BUILDTOP)/include/kadm5/admin.h \ -- $(BUILDTOP)/include/kadm5/admin_internal.h $(BUILDTOP)/include/kadm5/chpass_util_strings.h \ -- $(BUILDTOP)/include/kadm5/client_internal.h $(BUILDTOP)/include/kadm5/kadm_err.h \ -- $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ -- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ -- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ -- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ -- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ -- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/kdb.h \ -- $(top_srcdir)/include/krb5.h destroy-test.c --$(OUTPRE)handle-test.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(BUILDTOP)/include/gssapi/gssapi.h $(BUILDTOP)/include/gssrpc/types.h \ -- $(BUILDTOP)/include/kadm5/admin.h $(BUILDTOP)/include/kadm5/admin_internal.h \ -- $(BUILDTOP)/include/kadm5/chpass_util_strings.h $(BUILDTOP)/include/kadm5/kadm_err.h \ -- $(BUILDTOP)/include/kadm5/server_internal.h $(BUILDTOP)/include/krb5/krb5.h \ -- $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ -- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ -- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ -- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ -- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ -- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/kdb.h \ -- $(top_srcdir)/include/krb5.h $(top_srcdir)/include/krb5/plugin.h \ -- handle-test.c --$(OUTPRE)iter-test.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ -- $(BUILDTOP)/include/gssrpc/types.h $(BUILDTOP)/include/kadm5/admin.h \ -- $(BUILDTOP)/include/kadm5/chpass_util_strings.h $(BUILDTOP)/include/kadm5/kadm_err.h \ -- $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ -- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ -- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ -- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ -- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ -- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/kdb.h \ -- $(top_srcdir)/include/krb5.h iter-test.c --$(OUTPRE)setkey-test.$(OBJEXT): $(BUILDTOP)/include/autoconf.h \ -- $(BUILDTOP)/include/gssapi/gssapi.h $(BUILDTOP)/include/gssrpc/types.h \ -- $(BUILDTOP)/include/kadm5/admin.h $(BUILDTOP)/include/kadm5/chpass_util_strings.h \ -- $(BUILDTOP)/include/kadm5/kadm_err.h $(BUILDTOP)/include/krb5/krb5.h \ -- $(BUILDTOP)/include/osconf.h $(BUILDTOP)/include/profile.h \ -- $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ -- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ -- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ -- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ -- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ -- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/k5-buf.h \ -- $(top_srcdir)/include/k5-err.h $(top_srcdir)/include/k5-gmt_mktime.h \ -- $(top_srcdir)/include/k5-int-pkinit.h $(top_srcdir)/include/k5-int.h \ -- $(top_srcdir)/include/k5-platform.h $(top_srcdir)/include/k5-plugin.h \ -- $(top_srcdir)/include/k5-thread.h $(top_srcdir)/include/k5-trace.h \ -- $(top_srcdir)/include/kdb.h $(top_srcdir)/include/krb5.h \ -- $(top_srcdir)/include/krb5/authdata_plugin.h $(top_srcdir)/include/krb5/plugin.h \ -- $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ -- setkey-test.c --$(OUTPRE)randkey-test.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ -- $(BUILDTOP)/include/gssrpc/types.h $(BUILDTOP)/include/kadm5/admin.h \ -- $(BUILDTOP)/include/kadm5/chpass_util_strings.h $(BUILDTOP)/include/kadm5/kadm_err.h \ -- $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ -- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ -- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ -- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ -- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ -- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/kdb.h \ -- $(top_srcdir)/include/krb5.h randkey-test.c --$(OUTPRE)lock-test.$(OBJEXT): $(BUILDTOP)/include/gssapi/gssapi.h \ -- $(BUILDTOP)/include/gssrpc/types.h $(BUILDTOP)/include/kadm5/admin.h \ -- $(BUILDTOP)/include/kadm5/chpass_util_strings.h $(BUILDTOP)/include/kadm5/kadm_err.h \ -- $(BUILDTOP)/include/krb5/krb5.h $(COM_ERR_DEPS) $(top_srcdir)/include/gssrpc/auth.h \ -- $(top_srcdir)/include/gssrpc/auth_gss.h $(top_srcdir)/include/gssrpc/auth_unix.h \ -- $(top_srcdir)/include/gssrpc/clnt.h $(top_srcdir)/include/gssrpc/rename.h \ -- $(top_srcdir)/include/gssrpc/rpc.h $(top_srcdir)/include/gssrpc/rpc_msg.h \ -- $(top_srcdir)/include/gssrpc/svc.h $(top_srcdir)/include/gssrpc/svc_auth.h \ -- $(top_srcdir)/include/gssrpc/xdr.h $(top_srcdir)/include/kdb.h \ -- $(top_srcdir)/include/krb5.h lock-test.c -diff --git a/src/lib/kadm5/unit-test/destroy-test.c b/src/lib/kadm5/unit-test/destroy-test.c -deleted file mode 100644 -index 738cfeb86..000000000 ---- a/src/lib/kadm5/unit-test/destroy-test.c -+++ /dev/null -@@ -1,48 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --#include --#include --#include --#include --#include --#include --#include --#include --#include --#include -- --#define TEST_NUM 25 -- --int main() --{ -- kadm5_ret_t ret; -- char *cp; -- int x; -- void *server_handle; -- kadm5_server_handle_t handle; -- krb5_context context; -- -- ret = kadm5_init_krb5_context(&context); -- if (ret != 0) { -- com_err("test", ret, "context init"); -- exit(2); -- } -- for(x = 0; x < TEST_NUM; x++) { -- ret = kadm5_init(context, "admin", "admin", KADM5_ADMIN_SERVICE, 0, -- KADM5_STRUCT_VERSION, KADM5_API_VERSION_4, NULL, -- &server_handle); -- if(ret != KADM5_OK) { -- com_err("test", ret, "init"); -- exit(2); -- } -- handle = (kadm5_server_handle_t) server_handle; -- cp = strdup(strchr(handle->cache_name, ':') + 1); -- kadm5_destroy(server_handle); -- if(access(cp, F_OK) == 0) { -- puts("ticket cache not destroyed"); -- exit(2); -- } -- free(cp); -- } -- krb5_free_context(context); -- exit(0); --} -diff --git a/src/lib/kadm5/unit-test/diff-files/destroy-1 b/src/lib/kadm5/unit-test/diff-files/destroy-1 -deleted file mode 100644 -index 593d67320..000000000 ---- a/src/lib/kadm5/unit-test/diff-files/destroy-1 -+++ /dev/null -@@ -1,2 +0,0 @@ --##! nochanges -- -diff --git a/src/lib/kadm5/unit-test/diff-files/no-diffs b/src/lib/kadm5/unit-test/diff-files/no-diffs -deleted file mode 100644 -index 593d67320..000000000 ---- a/src/lib/kadm5/unit-test/diff-files/no-diffs -+++ /dev/null -@@ -1,2 +0,0 @@ --##! nochanges -- -diff --git a/src/lib/kadm5/unit-test/handle-test.c b/src/lib/kadm5/unit-test/handle-test.c -deleted file mode 100644 -index 29bd2c9a1..000000000 ---- a/src/lib/kadm5/unit-test/handle-test.c -+++ /dev/null -@@ -1,140 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --#include --#include --#include --#include --#include --#include --#include --#include --#ifdef CLIENT_TEST --#include --#else --#include --#include --#endif -- --int main(int argc, char *argv[]) --{ -- kadm5_ret_t ret; -- void *server_handle; -- kadm5_server_handle_t handle; -- kadm5_server_handle_rec orig_handle; -- kadm5_policy_ent_rec pol; -- kadm5_principal_ent_t princ; -- kadm5_principal_ent_rec kprinc; -- krb5_keyblock *key; -- krb5_principal tprinc; -- krb5_context context; -- -- -- kadm5_init_krb5_context(&context); -- -- ret = kadm5_init(context, "admin/none", "admin", KADM5_ADMIN_SERVICE, NULL, -- KADM5_STRUCT_VERSION, KADM5_API_VERSION_4, NULL, -- &server_handle); -- if(ret != KADM5_OK) { -- com_err("test", ret, "init"); -- exit(2); -- } -- handle = (kadm5_server_handle_t) server_handle; -- orig_handle = *handle; -- handle->magic_number = KADM5_STRUCT_VERSION; -- krb5_parse_name(context, "testuser", &tprinc); -- ret = kadm5_get_principal(server_handle, tprinc, &kprinc, -- KADM5_PRINCIPAL_NORMAL_MASK); -- if(ret != KADM5_BAD_SERVER_HANDLE) { -- fprintf(stderr, "%s -- returned -- %s\n", "get-principal", -- error_message(ret)); -- exit(1); -- } -- -- ret = kadm5_get_policy(server_handle, "pol1", &pol); -- if(ret != KADM5_BAD_SERVER_HANDLE) { -- fprintf(stderr, "%s -- returned -- %s\n", "get-policy", -- error_message(ret)); -- exit(1); -- } -- -- princ = &kprinc; -- ret = kadm5_create_principal(server_handle, princ, KADM5_PRINCIPAL, "pass"); -- if(ret != KADM5_BAD_SERVER_HANDLE) { -- fprintf(stderr, "%s -- returned -- %s\n", "create-principal", -- error_message(ret)); -- exit(1); -- } -- -- ret = kadm5_create_policy(server_handle, &pol, KADM5_POLICY); -- if(ret != KADM5_BAD_SERVER_HANDLE) { -- fprintf(stderr, "%s -- returned -- %s\n", "create-policy", -- error_message(ret)); -- exit(1); -- } -- -- ret = kadm5_modify_principal(server_handle, princ, KADM5_PW_EXPIRATION); -- if(ret != KADM5_BAD_SERVER_HANDLE) { -- fprintf(stderr, "%s -- returned -- %s\n", "modify-principal", -- error_message(ret)); -- exit(1); -- } -- -- ret = kadm5_modify_policy(server_handle, &pol, KADM5_PW_MAX_LIFE); -- if(ret != KADM5_BAD_SERVER_HANDLE) { -- fprintf(stderr, "%s -- returned -- %s\n", "modify-policy", -- error_message(ret)); -- exit(1); -- } -- -- ret = kadm5_delete_principal(server_handle, tprinc); -- if(ret != KADM5_BAD_SERVER_HANDLE) { -- fprintf(stderr, "%s -- returned -- %s\n", "delete-principal", -- error_message(ret)); -- exit(1); -- } -- -- ret = kadm5_delete_policy(server_handle, "pol1"); -- if(ret != KADM5_BAD_SERVER_HANDLE) { -- fprintf(stderr, "%s -- returned -- %s\n", "delete-policy", -- error_message(ret)); -- exit(1); -- } -- -- ret = kadm5_chpass_principal(server_handle, tprinc, "FooBar"); -- if(ret != KADM5_BAD_SERVER_HANDLE) { -- fprintf(stderr, "%s -- returned -- %s\n", "chpass", -- error_message(ret)); -- exit(1); -- } -- ret = kadm5_randkey_principal(server_handle, tprinc, &key, NULL); -- if(ret != KADM5_BAD_SERVER_HANDLE) { -- fprintf(stderr, "%s -- returned -- %s\n", "randkey", -- error_message(ret)); -- exit(1); -- } -- -- ret = kadm5_rename_principal(server_handle, tprinc, tprinc); -- if(ret != KADM5_BAD_SERVER_HANDLE) { -- fprintf(stderr, "%s -- returned -- %s\n", "rename", -- error_message(ret)); -- exit(1); -- } -- -- ret = kadm5_destroy(server_handle); -- if(ret != KADM5_BAD_SERVER_HANDLE) { -- fprintf(stderr, "%s -- returned -- %s\n", "destroy", -- error_message(ret)); -- exit(1); -- } -- -- *handle = orig_handle; -- ret = kadm5_destroy(server_handle); -- if (ret != KADM5_OK) { -- fprintf(stderr, "valid %s -- returned -- %s\n", "destroy", -- error_message(ret)); -- exit(1); -- } -- -- krb5_free_principal(context, tprinc); -- krb5_free_context(context); -- exit(0); --} -diff --git a/src/lib/kadm5/unit-test/init-test.c b/src/lib/kadm5/unit-test/init-test.c -deleted file mode 100644 -index 9f06621e8..000000000 ---- a/src/lib/kadm5/unit-test/init-test.c -+++ /dev/null -@@ -1,39 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --#include --#include --#include --#include --#include --#include -- --int main() --{ -- kadm5_ret_t ret; -- void *server_handle; -- kadm5_config_params params; -- krb5_context context; -- -- memset(¶ms, 0, sizeof(params)); -- params.mask |= KADM5_CONFIG_NO_AUTH; -- ret = kadm5_init_krb5_context(&context); -- if (ret != 0) { -- com_err("init-test", ret, "while initializing krb5 context"); -- exit(1); -- } -- ret = kadm5_init(context, "admin", "admin", NULL, ¶ms, -- KADM5_STRUCT_VERSION, KADM5_API_VERSION_4, NULL, -- &server_handle); -- if (!ret) -- (void)kadm5_destroy(server_handle); -- krb5_free_context(context); -- if (ret == KADM5_RPC_ERROR) { -- exit(0); -- } -- else if (ret != 0) { -- com_err("init-test", ret, "while initializing without auth"); -- exit(1); -- } else { -- fprintf(stderr, "Unexpected success while initializing without auth!\n"); -- exit(1); -- } --} -diff --git a/src/lib/kadm5/unit-test/iter-test.c b/src/lib/kadm5/unit-test/iter-test.c -deleted file mode 100644 -index cd85ebe4d..000000000 ---- a/src/lib/kadm5/unit-test/iter-test.c -+++ /dev/null -@@ -1,51 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --#include --#include --#include -- --int main(int argc, char **argv) --{ -- kadm5_ret_t ret; -- void *server_handle; -- char **names; -- int count, princ, i; -- krb5_context context; -- -- if (argc != 3) { -- fprintf(stderr, "Usage: %s [-princ|-pol] exp\n", argv[0]); -- exit(1); -- } -- princ = (strcmp(argv[1], "-princ") == 0); -- -- ret = kadm5_init_krb5_context(&context); -- if (ret != KADM5_OK) { -- com_err("iter-test", ret, "while initializing context"); -- exit(1); -- } -- ret = kadm5_init("admin", "admin", KADM5_ADMIN_SERVICE, 0, -- KADM5_STRUCT_VERSION, KADM5_API_VERSION_4, NULL, -- &server_handle); -- if (ret != KADM5_OK) { -- com_err("iter-test", ret, "while initializing"); -- exit(1); -- } -- -- if (princ) -- ret = kadm5_get_principals(server_handle, argv[2], &names, &count); -- else -- ret = kadm5_get_policies(server_handle, argv[2], &names, &count); -- -- if (ret != KADM5_OK) { -- com_err("iter-test", ret, "while retrieving list"); -- exit(1); -- } -- -- for (i = 0; i < count; i++) -- printf("%d: %s\n", i, names[i]); -- -- kadm5_free_name_list(server_handle, names, count); -- -- (void) kadm5_destroy(server_handle); -- -- return 0; --} -diff --git a/src/lib/kadm5/unit-test/lib/lib.t b/src/lib/kadm5/unit-test/lib/lib.t -deleted file mode 100644 -index 3444775cf..000000000 ---- a/src/lib/kadm5/unit-test/lib/lib.t -+++ /dev/null -@@ -1,306 +0,0 @@ --global timeout --set timeout 60 -- --set lib_pid 0 -- --# --# The functions in this library used to be responsible for bazillions --# of wasted api_starts. Now, they all just use their own library --# handle so they are not interrupted when the main tests call init or --# destroy. They have to keep track of when the api exists and --# restarts, though, since the lib_handle needs to be re-opened in that --# case. --# --proc lib_start_api {} { -- global spawn_id lib_pid test -- -- if {! [api_isrunning $lib_pid]} { -- api_exit -- set lib_pid [api_start] -- if {! [cmd { -- kadm5_init admin admin $KADM5_ADMIN_SERVICE null \ -- $KADM5_STRUCT_VERSION $KADM5_API_VERSION_3 \ -- lib_handle -- }]} { -- perror "$test: unexpected failure in init" -- return -- } -- verbose "+++ restarted api ($lib_pid) for lib" -- } else { -- verbose "+++ api $lib_pid already running for lib" -- } --} -- --proc cmd {command} { -- global prompt -- global spawn_id -- global test -- -- send "[string trim $command]\n" -- expect { -- -re "OK .*$prompt$" { return 1 } -- -re "ERROR .*$prompt$" { return 0 } -- "wrong # args" { perror "$test: wrong number args"; return 0 } -- timeout { fail "$test: timeout"; return 0 } -- eof { fail "$test: eof"; api_exit; lib_start_api; return 0 } -- } --} -- --proc tcl_cmd {command} { -- global prompt spawn_id test -- -- send "[string trim $command]\n" -- expect { -- -re "$prompt$" { return 1} -- "wrong # args" { perror "$test: wrong number args"; return 0 } -- timeout { error_and_restart "timeout" } -- eof { api_exit; lib_start_api; return 0 } -- } --} -- --proc one_line_succeed_test {command} { -- global prompt -- global spawn_id -- global test -- -- send "[string trim $command]\n" -- expect { -- -re "OK .*$prompt$" { pass "$test"; return 1 } -- -re "ERROR .*$prompt$" { -- fail "$test: $expect_out(buffer)"; return 0 -- } -- "wrong # args" { perror "$test: wrong number args"; return 0 } -- timeout { fail "$test: timeout"; return 0 } -- eof { fail "$test: eof"; api_exit; lib_start_api; return 0 } -- } --} -- --proc one_line_fail_test {command code} { -- global prompt -- global spawn_id -- global test -- -- send "[string trim $command]\n" -- expect { -- -re "ERROR .*$code.*$prompt$" { pass "$test"; return 1 } -- -re "ERROR .*$prompt$" { fail "$test: bad failure"; return 0 } -- -re "OK .*$prompt$" { fail "$test: bad success"; return 0 } -- "wrong # args" { perror "$test: wrong number args"; return 0 } -- timeout { fail "$test: timeout"; return 0 } -- eof { fail "$test: eof"; api_exit; lib_start_api; return 0 } -- } --} -- --proc one_line_fail_test_nochk {command} { -- global prompt -- global spawn_id -- global test -- -- send "[string trim $command]\n" -- expect { -- -re "ERROR .*$prompt$" { pass "$test:"; return 1 } -- -re "OK .*$prompt$" { fail "$test: bad success"; return 0 } -- "wrong # args" { perror "$test: wrong number args"; return 0 } -- timeout { fail "$test: timeout"; return 0 } -- eof { fail "$test: eof"; api_exit; lib_start_api; return 0 } -- } --} -- --proc resync {} { -- global prompt spawn_id test -- -- expect { -- -re "$prompt$" {} -- "wrong # args" { perror "$test: wrong number args"; return 0 } -- eof { api_exit; lib_start_api } -- } --} -- --proc create_principal {name} { -- lib_start_api -- -- set ret [cmd [format { -- kadm5_create_principal $lib_handle [simple_principal \ -- "%s"] {KADM5_PRINCIPAL} "%s" -- } $name $name]] -- -- return $ret --} -- --proc create_policy {name} { -- lib_start_api -- -- set ret [cmd [format { -- kadm5_create_policy $lib_handle [simple_policy "%s"] \ -- {KADM5_POLICY} -- } $name $name]] -- -- return $ret --} -- --proc create_principal_pol {name policy} { -- lib_start_api -- -- set ret [cmd [format { -- kadm5_create_principal $lib_handle [princ_w_pol "%s" \ -- "%s"] {KADM5_PRINCIPAL KADM5_POLICY} "%s" -- } $name $policy $name]] -- -- return $ret --} -- --proc delete_principal {name} { -- lib_start_api -- -- set ret [cmd [format { -- kadm5_delete_principal $lib_handle "%s" -- } $name]] -- -- return $ret --} -- --proc delete_policy {name} { -- lib_start_api -- -- set ret [cmd [format {kadm5_delete_policy $lib_handle "%s"} $name]] -- -- return $ret --} -- --proc principal_exists {name} { --# puts stdout "Starting principal_exists." -- -- lib_start_api -- -- set ret [cmd [format { -- kadm5_get_principal $lib_handle "%s" principal \ -- KADM5_PRINCIPAL_NORMAL_MASK -- } $name]] -- --# puts stdout "Finishing principal_exists." -- -- return $ret --} -- --proc policy_exists {name} { -- lib_start_api -- --# puts stdout "Starting policy_exists." -- -- set ret [cmd [format { -- kadm5_get_policy $lib_handle "%s" policy -- } $name]] -- --# puts stdout "Finishing policy_exists." -- -- return $ret --} -- --proc error_and_restart {error} { -- api_exit -- api_start -- perror $error --} -- --proc test {name} { -- global test verbose -- -- set test $name -- if {$verbose >= 1} { -- puts stdout "At $test" -- } --} -- --proc begin_dump {} { -- global TOP -- global RPC -- -- if { ! $RPC } { --# exec $env(SIMPLE_DUMP) > /tmp/dump.before -- } --} -- --proc end_dump_compare {name} { -- global file -- global TOP -- global RPC -- -- if { ! $RPC } { --# set file $TOP/admin/lib/unit-test/diff-files/$name --# exec $env(SIMPLE_DUMP) > /tmp/dump.after --# exec $env(COMPARE_DUMP) /tmp/dump.before /tmp/dump.after $file -- } --} -- --proc kinit { princ pass {opts ""} } { -- global env; -- global KINIT -- -- eval spawn $KINIT -5 $opts $princ -- expect { -- -re {Password for .*: $} -- {send "$pass\n"} -- timeout {puts "Timeout waiting for prompt" ; close } -- } -- -- # this necessary so close(1) in the child will not sleep waiting for -- # the parent, which is us, to read pending data. -- -- expect { -- "when initializing cache" { perror "kinit failed: $expect_out(buffer)" } -- eof {} -- } -- wait --} -- --proc kdestroy {} { -- global KDESTROY -- global errorCode errorInfo -- global env -- -- if {[info exists errorCode]} { -- set saveErrorCode $errorCode -- } -- if {[info exists errorInfo]} { -- set saveErrorInfo $errorInfo -- } -- catch "exec $KDESTROY -5 2>/dev/null" -- if {[info exists saveErrorCode]} { -- set errorCode $saveErrorCode -- } elseif {[info exists errorCode]} { -- unset errorCode -- } -- if {[info exists saveErrorInfo]} { -- set errorInfo $saveErrorInfo -- } elseif {[info exists errorInfo]} { -- unset errorInfo -- } --} -- --proc create_principal_with_keysalts {name keysalts} { -- global kadmin_local -- -- spawn $kadmin_local -e "$keysalts" -- expect { -- "kadmin.local:" {} -- default { perror "waiting for kadmin.local prompt"; return 1} -- } -- send "ank -pw \"$name\" \"$name\"\n" -- expect { -- -re "Principal \"$name.*\" created." {} -- "kadmin.local:" { -- perror "expecting principal created message"; -- return 1 -- } -- default { perror "waiting for principal created message"; return 1 } -- } -- expect { -- "kadmin.local:" {} -- default { perror "waiting for kadmin.local prompt"; return 1 } -- } -- close -- wait -- return 0 --} -- -- -diff --git a/src/lib/kadm5/unit-test/lock-test.c b/src/lib/kadm5/unit-test/lock-test.c -deleted file mode 100644 -index 59f9d2609..000000000 ---- a/src/lib/kadm5/unit-test/lock-test.c -+++ /dev/null -@@ -1,105 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --#include --#include --#include --#include --#include -- --char *whoami; -- --static void usage() --{ -- fprintf(stderr, -- "Usage: %s {shared|exclusive|permanent|release|" -- "get name|wait} ...\n", whoami); -- exit(1); --} -- --int main(int argc, char **argv) --{ -- krb5_error_code ret; -- osa_policy_ent_t entry; -- krb5_context context; -- kadm5_config_params params; -- krb5_error_code kret; -- -- whoami = argv[0]; -- -- kret = kadm5_init_krb5_context(&context); -- if (kret) { -- com_err(whoami, kret, "while initializing krb5"); -- exit(1); -- } -- -- params.mask = 0; -- ret = kadm5_get_config_params(context, 1, ¶ms, ¶ms); -- if (ret) { -- com_err(whoami, ret, "while retrieving configuration parameters"); -- exit(1); -- } -- if (! (params.mask & KADM5_CONFIG_ADBNAME)) { -- com_err(whoami, KADM5_BAD_SERVER_PARAMS, -- "while retrieving configuration parameters"); -- exit(1); -- } -- -- ret = krb5_db_open( context, NULL, KRB5_KDB_OPEN_RW); -- if (ret) { -- com_err(whoami, ret, "while opening database"); -- exit(1); -- } -- -- argc--; argv++; -- while (argc) { -- if (strcmp(*argv, "shared") == 0) { -- ret = krb5_db_lock(context, KRB5_DB_LOCKMODE_SHARED); -- if (ret) -- com_err(whoami, ret, "while getting shared lock"); -- else -- printf("shared\n"); -- } else if (strcmp(*argv, "exclusive") == 0) { -- ret = krb5_db_lock(context, KRB5_DB_LOCKMODE_EXCLUSIVE ); -- if (ret) -- com_err(whoami, ret, "while getting exclusive lock"); -- else -- printf("exclusive\n"); -- } else if (strcmp(*argv, "permanent") == 0) { -- ret = krb5_db_lock(context, KRB5_DB_LOCKMODE_EXCLUSIVE ); -- if (ret) -- com_err(whoami, ret, "while getting permanent lock"); -- else -- printf("permanent\n"); -- } else if (strcmp(*argv, "release") == 0) { -- ret = krb5_db_unlock(context); -- if (ret) -- com_err(whoami, ret, "while releasing lock"); -- else -- printf("released\n"); -- } else if (strcmp(*argv, "get") == 0) { -- argc--; argv++; -- if (!argc) usage(); -- if ((ret = krb5_db_get_policy(context, *argv, &entry))) { -- com_err(whoami, ret, "while getting policy"); -- } else { -- printf("retrieved\n"); -- krb5_db_free_policy(context, entry); -- } -- } else if (strcmp(*argv, "wait") == 0) { -- getchar(); -- } else { -- fprintf(stderr, "%s: Invalid argument \"%s\"\n", -- whoami, *argv); -- usage(); -- } -- -- argc--; argv++; -- } -- -- ret = krb5_db_fini(context); -- if (ret) { -- com_err(whoami, ret, "while closing database"); -- exit(1); -- } -- -- return 0; --} -diff --git a/src/lib/kadm5/unit-test/randkey-test.c b/src/lib/kadm5/unit-test/randkey-test.c -deleted file mode 100644 -index dbef88ac8..000000000 ---- a/src/lib/kadm5/unit-test/randkey-test.c -+++ /dev/null -@@ -1,42 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --#include --#include --#include --#include --#include --#include --#include -- --#define TEST_NUM 1000 -- --int main() --{ -- kadm5_ret_t ret; -- krb5_keyblock *keys[TEST_NUM]; -- krb5_principal tprinc; -- krb5_keyblock *newkey; -- krb5_context context; -- void *server_handle; -- -- int x, i; -- -- kadm5_init_krb5_context(&context); -- -- krb5_parse_name(context, "testuser", &tprinc); -- ret = kadm5_init(context, "admin", "admin", KADM5_ADMIN_SERVICE, NULL, -- KADM5_STRUCT_VERSION, KADM5_API_VERSION_4, NULL, -- &server_handle); -- if(ret != KADM5_OK) { -- com_err("test", ret, "init"); -- exit(2); -- } -- for(x = 0; x < TEST_NUM; x++) { -- kadm5_randkey_principal(server_handle, tprinc, &keys[x], NULL); -- for(i = 0; i < x; i++) { -- if (!memcmp(newkey->contents, keys[i]->contents, newkey->length)) -- puts("match found"); -- } -- } -- kadm5_destroy(server_handle); -- exit(0); --} -diff --git a/src/lib/kadm5/unit-test/setkey-test.c b/src/lib/kadm5/unit-test/setkey-test.c -deleted file mode 100644 -index 8e7df96e9..000000000 ---- a/src/lib/kadm5/unit-test/setkey-test.c -+++ /dev/null -@@ -1,246 +0,0 @@ --/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */ --#include --#include -- --#if HAVE_SRAND48 --#define RAND() lrand48() --#define SRAND(a) srand48(a) --#define RAND_TYPE long --#elif HAVE_SRAND --#define RAND() rand() --#define SRAND(a) srand(a) --#define RAND_TYPE int --#elif HAVE_SRANDOM --#define RAND() random() --#define SRAND(a) srandom(a) --#define RAND_TYPE long --#else /* no random */ --need a random number generator --#endif /* no random */ -- --krb5_keyblock test1[] = { -- {0, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0, 0}, -- {-1}, --}; --krb5_keyblock test2[] = { -- {0, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0, 0}, -- {-1}, --}; --krb5_keyblock test3[] = { -- {0, ENCTYPE_AES128_CTS_HMAC_SHA1_96, 0, 0}, -- {-1}, --}; -- --krb5_keyblock *tests[] = { -- test1, test2, test3, NULL --}; -- --krb5_data tgtname = { -- 0, -- KRB5_TGS_NAME_SIZE, -- KRB5_TGS_NAME --}; -- --krb5_enctype ktypes[] = { 0, 0 }; -- --extern krb5_kt_ops krb5_ktf_writable_ops; -- --int --main(int argc, char **argv) --{ -- krb5_context context; -- krb5_keytab kt; -- krb5_keytab_entry ktent; -- krb5_encrypt_block eblock; -- krb5_creds my_creds; -- krb5_get_init_creds_opt *opt; -- kadm5_principal_ent_rec princ_ent; -- krb5_principal princ, server; -- char pw[16]; -- char *whoami, *principal, *authprinc, *authpwd; -- krb5_data pwdata; -- void *handle; -- int ret, test, encnum; -- unsigned int i; -- -- whoami = argv[0]; -- -- if (argc < 2 || argc > 4) { -- fprintf(stderr, "Usage: %s principal [authuser] [authpwd]\n", whoami); -- exit(1); -- } -- principal = argv[1]; -- authprinc = (argc > 2) ? argv[2] : argv[0]; -- authpwd = (argc > 3) ? argv[3] : NULL; -- -- /* -- * Setup. Initialize data structures, open keytab, open connection -- * to kadm5 server. -- */ -- -- memset(&context, 0, sizeof(context)); -- kadm5_init_krb5_context(&context); -- -- ret = krb5_parse_name(context, principal, &princ); -- if (ret) { -- com_err(whoami, ret, "while parsing principal name %s", principal); -- exit(1); -- } -- -- if((ret = krb5_build_principal_ext(context, &server, -- krb5_princ_realm(kcontext, princ)->length, -- krb5_princ_realm(kcontext, princ)->data, -- tgtname.length, tgtname.data, -- krb5_princ_realm(kcontext, princ)->length, -- krb5_princ_realm(kcontext, princ)->data, -- 0))) { -- com_err(whoami, ret, "while building server name"); -- exit(1); -- } -- -- ret = krb5_kt_default(context, &kt); -- if (ret) { -- com_err(whoami, ret, "while opening keytab"); -- exit(1); -- } -- -- ret = kadm5_init(context, authprinc, authpwd, KADM5_ADMIN_SERVICE, NULL, -- KADM5_STRUCT_VERSION, KADM5_API_VERSION_4, NULL, -- &handle); -- if (ret) { -- com_err(whoami, ret, "while initializing connection"); -- exit(1); -- } -- -- /* these pw's don't need to be secure, just different every time */ -- SRAND((RAND_TYPE)time((void *) NULL)); -- pwdata.data = pw; -- pwdata.length = sizeof(pw); -- -- /* -- * For each test: -- * -- * For each enctype in the test, construct a random password/key. -- * Assign all keys to principal with kadm5_setkey_principal. Add -- * each key to the keytab, and acquire an initial ticket with the -- * keytab (XXX can I specify the kvno explicitly?). If -- * krb5_get_init_creds_keytab succeeds, then the keys were set -- * successfully. -- */ -- for (test = 0; tests[test] != NULL; test++) { -- krb5_keyblock *testp = tests[test]; -- kadm5_key_data *extracted; -- int n_extracted, match; -- printf("+ Test %d:\n", test); -- -- for (encnum = 0; testp[encnum].magic != -1; encnum++) { -- for (i = 0; i < sizeof(pw); i++) -- pw[i] = (RAND() % 26) + '0'; /* XXX */ -- -- krb5_use_enctype(context, &eblock, testp[encnum].enctype); -- ret = krb5_string_to_key(context, &eblock, &testp[encnum], -- &pwdata, NULL); -- if (ret) { -- com_err(whoami, ret, "while converting string to key"); -- exit(1); -- } -- } -- -- /* now, encnum == # of keyblocks in testp */ -- ret = kadm5_setkey_principal(handle, princ, testp, encnum); -- if (ret) { -- com_err(whoami, ret, "while setting keys"); -- exit(1); -- } -- -- ret = kadm5_get_principal(handle, princ, &princ_ent, KADM5_KVNO); -- if (ret) { -- com_err(whoami, ret, "while retrieving principal"); -- exit(1); -- } -- -- ret = kadm5_get_principal_keys(handle, princ, 0, &extracted, -- &n_extracted); -- if (ret) { -- com_err(whoami, ret, "while extracting keys"); -- exit(1); -- } -- -- for (encnum = 0; testp[encnum].magic != -1; encnum++) { -- printf("+ enctype %d\n", testp[encnum].enctype); -- -- for (match = 0; match < n_extracted; match++) { -- if (extracted[match].key.enctype == testp[encnum].enctype) -- break; -- } -- if (match >= n_extracted) { -- com_err(whoami, KRB5_WRONG_ETYPE, "while matching enctypes"); -- exit(1); -- } -- if (extracted[match].key.length != testp[encnum].length || -- memcmp(extracted[match].key.contents, testp[encnum].contents, -- testp[encnum].length) != 0) { -- com_err(whoami, KRB5_KDB_NO_MATCHING_KEY, "verifying keys"); -- exit(1); -- } -- -- memset(&ktent, 0, sizeof(ktent)); -- ktent.principal = princ; -- ktent.key = testp[encnum]; -- ktent.vno = princ_ent.kvno; -- -- ret = krb5_kt_add_entry(context, kt, &ktent); -- if (ret) { -- com_err(whoami, ret, "while adding keytab entry"); -- exit(1); -- } -- -- memset(&my_creds, 0, sizeof(my_creds)); -- my_creds.client = princ; -- my_creds.server = server; -- -- ktypes[0] = testp[encnum].enctype; -- ret = krb5_get_init_creds_opt_alloc(context, &opt); -- if (ret) { -- com_err(whoami, ret, "while allocating gic opts"); -- exit(1); -- } -- krb5_get_init_creds_opt_set_etype_list(opt, ktypes, 1); -- ret = krb5_get_init_creds_keytab(context, &my_creds, princ, -- kt, 0, NULL /* in_tkt_service */, -- opt); -- krb5_get_init_creds_opt_free(context, opt); -- if (ret) { -- com_err(whoami, ret, "while acquiring initial ticket"); -- exit(1); -- } -- krb5_free_cred_contents(context, &my_creds); -- -- /* since I can't specify enctype explicitly ... */ -- ret = krb5_kt_remove_entry(context, kt, &ktent); -- if (ret) { -- com_err(whoami, ret, "while removing keytab entry"); -- exit(1); -- } -- } -- -- (void)kadm5_free_kadm5_key_data(context, n_extracted, extracted); -- } -- -- ret = krb5_kt_close(context, kt); -- if (ret) { -- com_err(whoami, ret, "while closing keytab"); -- exit(1); -- } -- -- ret = kadm5_destroy(handle); -- if (ret) { -- com_err(whoami, ret, "while closing kadmin connection"); -- exit(1); -- } -- -- krb5_free_principal(context, princ); -- krb5_free_principal(context, server); -- krb5_free_context(context); -- return 0; --} -diff --git a/src/lib/kadm5/unit-test/site.exp b/src/lib/kadm5/unit-test/site.exp -deleted file mode 100644 -index 7fe397463..000000000 ---- a/src/lib/kadm5/unit-test/site.exp -+++ /dev/null -@@ -1,2 +0,0 @@ --set tool kadm5_srv_tcl --set prompt "% " --- -2.31.1 - diff --git a/Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch b/Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch deleted file mode 100644 index 3c90b97..0000000 --- a/Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch +++ /dev/null @@ -1,150 +0,0 @@ -From c99ecf1bb49e2fbd0bf30a7b357cf06407b9588a Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Sat, 15 May 2021 18:04:58 -0400 -Subject: [PATCH] Remove deprecated OpenSSL calls from softpkcs11 - -Rewrite add_pubkey_info() in terms of the EVP_PKEY interface. In this -process, fix its unchecked allocations and fail fast for non-RSA keys. - -(cherry picked from commit d6bf42279675100e3e4fe7c6e08eef74d49624cb) -(cherry picked from commit 5072bfdfaddae762680d0f9d97afa6dbf8274760) ---- - src/configure.ac | 1 + - src/tests/softpkcs11/main.c | 106 ++++++++++++++++++++++++------------ - 2 files changed, 72 insertions(+), 35 deletions(-) - -diff --git a/src/configure.ac b/src/configure.ac -index 3e1052db7..eb6307468 100644 ---- a/src/configure.ac -+++ b/src/configure.ac -@@ -1114,6 +1114,7 @@ int i = 1; - ])], k5_cv_openssl_version_okay=yes, k5_cv_openssl_version_okay=no)]) - old_LIBS="$LIBS" - AC_CHECK_LIB(crypto, PKCS7_get_signer_info) -+ AC_CHECK_FUNCS(EVP_PKEY_get_bn_param) - LIBS="$old_LIBS" - fi - if test "$k5_cv_openssl_version_okay" = yes && (test "$enable_pkinit" = yes || test "$enable_pkinit" = try); then -diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c -index caa537b68..86b4ef711 100644 ---- a/src/tests/softpkcs11/main.c -+++ b/src/tests/softpkcs11/main.c -@@ -413,47 +413,83 @@ add_object_attribute(struct st_object *o, - return CKR_OK; - } - -+#ifdef HAVE_EVP_PKEY_GET_BN_PARAM -+ -+/* Declare owner pointers since EVP_PKEY_get_bn_param() gives us copies. */ -+#define DECLARE_BIGNUM(name) BIGNUM *name = NULL -+#define RELEASE_BIGNUM(bn) BN_clear_free(bn) - static CK_RV --add_pubkey_info(struct st_object *o, CK_KEY_TYPE key_type, EVP_PKEY *key) -+get_bignums(EVP_PKEY *key, BIGNUM **n, BIGNUM **e) - { -- switch (key_type) { -- case CKK_RSA: { -- CK_BYTE *modulus = NULL; -- size_t modulus_len = 0; -- CK_ULONG modulus_bits = 0; -- CK_BYTE *exponent = NULL; -- size_t exponent_len = 0; -- const RSA *rsa; -- const BIGNUM *n, *e; -+ if (EVP_PKEY_get_bn_param(key, "n", n) == 0 || -+ EVP_PKEY_get_bn_param(key, "e", e) == 0) -+ return CKR_DEVICE_ERROR; - -- rsa = EVP_PKEY_get0_RSA(key); -- RSA_get0_key(rsa, &n, &e, NULL); -- modulus_bits = BN_num_bits(n); -- -- modulus_len = BN_num_bytes(n); -- modulus = malloc(modulus_len); -- BN_bn2bin(n, modulus); -- -- exponent_len = BN_num_bytes(e); -- exponent = malloc(exponent_len); -- BN_bn2bin(e, exponent); -- -- add_object_attribute(o, 0, CKA_MODULUS, modulus, modulus_len); -- add_object_attribute(o, 0, CKA_MODULUS_BITS, -- &modulus_bits, sizeof(modulus_bits)); -- add_object_attribute(o, 0, CKA_PUBLIC_EXPONENT, -- exponent, exponent_len); -- -- free(modulus); -- free(exponent); -- } -- default: -- /* XXX */ -- break; -- } - return CKR_OK; - } - -+#else -+ -+/* Declare const pointers since the old API gives us aliases. */ -+#define DECLARE_BIGNUM(name) const BIGNUM *name -+#define RELEASE_BIGNUM(bn) -+static CK_RV -+get_bignums(EVP_PKEY *key, const BIGNUM **n, const BIGNUM **e) -+{ -+ const RSA *rsa; -+ -+ rsa = EVP_PKEY_get0_RSA(key); -+ RSA_get0_key(rsa, n, e, NULL); -+ -+ return CKR_OK; -+} -+ -+#endif -+ -+static CK_RV -+add_pubkey_info(struct st_object *o, CK_KEY_TYPE key_type, EVP_PKEY *key) -+{ -+ CK_BYTE *modulus = NULL, *exponent = 0; -+ size_t modulus_len = 0, exponent_len = 0; -+ CK_ULONG modulus_bits = 0; -+ CK_RV ret; -+ DECLARE_BIGNUM(n); -+ DECLARE_BIGNUM(e); -+ -+ if (key_type != CKK_RSA) -+ abort(); -+ -+ ret = get_bignums(key, &n, &e); -+ if (ret != CKR_OK) -+ goto done; -+ -+ modulus_bits = BN_num_bits(n); -+ modulus_len = BN_num_bytes(n); -+ exponent_len = BN_num_bytes(e); -+ -+ modulus = malloc(modulus_len); -+ exponent = malloc(exponent_len); -+ if (modulus == NULL || exponent == NULL) { -+ ret = CKR_DEVICE_MEMORY; -+ goto done; -+ } -+ -+ BN_bn2bin(n, modulus); -+ BN_bn2bin(e, exponent); -+ -+ add_object_attribute(o, 0, CKA_MODULUS, modulus, modulus_len); -+ add_object_attribute(o, 0, CKA_MODULUS_BITS, &modulus_bits, -+ sizeof(modulus_bits)); -+ add_object_attribute(o, 0, CKA_PUBLIC_EXPONENT, exponent, exponent_len); -+ -+ ret = CKR_OK; -+done: -+ free(modulus); -+ free(exponent); -+ RELEASE_BIGNUM(n); -+ RELEASE_BIGNUM(e); -+ return ret; -+} - - static int - pem_callback(char *buf, int num, int w, void *key) diff --git a/Support-host-based-GSS-initiator-names.patch b/Support-host-based-GSS-initiator-names.patch deleted file mode 100644 index cd7450c..0000000 --- a/Support-host-based-GSS-initiator-names.patch +++ /dev/null @@ -1,578 +0,0 @@ -From 818a777822658d44ce647fe975011a5ea25e8250 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 15 Jan 2021 13:51:34 -0500 -Subject: [PATCH] Support host-based GSS initiator names - -When checking if we can get initial credentials in the GSS krb5 mech, -use krb5_kt_have_match() to support fallback iteration. When scanning -the ccache or getting initial credentials, rewrite cred->name->princ -to the canonical client name. When a name check is necessary (such as -when the caller specifies both a name and ccache), use a new internal -API k5_sname_compare() to support fallback iteration. Add fallback -iteration to krb5_cc_cache_match() to allow host-based names to be -canonicalized against the cache collection. - -Create and store the matching principal for acceptor names in -acquire_accept_cred() so that it isn't affected by changes in -cred->name->princ during acquire_init_cred(). - -ticket: 8978 (new) -(cherry picked from commit c374ab40dd059a5938ffc0440d87457ac5da3a46) ---- - src/include/k5-int.h | 9 +++ - src/include/k5-trace.h | 3 + - src/lib/gssapi/krb5/accept_sec_context.c | 15 +--- - src/lib/gssapi/krb5/acquire_cred.c | 89 ++++++++++++++---------- - src/lib/gssapi/krb5/gssapiP_krb5.h | 1 + - src/lib/gssapi/krb5/rel_cred.c | 1 + - src/lib/krb5/ccache/cccursor.c | 57 +++++++++++---- - src/lib/krb5/libkrb5.exports | 1 + - src/lib/krb5/os/sn2princ.c | 23 +++++- - src/lib/krb5_32.def | 1 + - src/tests/gssapi/t_client_keytab.py | 44 ++++++++++++ - src/tests/gssapi/t_credstore.py | 32 +++++++++ - 12 files changed, 214 insertions(+), 62 deletions(-) - -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index efb523689..46f2ce2d3 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -2411,4 +2411,13 @@ void k5_change_error_message_code(krb5_context ctx, krb5_error_code oldcode, - #define k5_prependmsg krb5_prepend_error_message - #define k5_wrapmsg krb5_wrap_error_message - -+/* -+ * Like krb5_principal_compare(), but with canonicalization of sname if -+ * fallback is enabled. This function should be avoided if multiple matches -+ * are required, since repeated canonicalization is inefficient. -+ */ -+krb5_boolean -+k5_sname_compare(krb5_context context, krb5_const_principal sname, -+ krb5_const_principal princ); -+ - #endif /* _KRB5_INT_H */ -diff --git a/src/include/k5-trace.h b/src/include/k5-trace.h -index b3e039dc8..79b5a7a85 100644 ---- a/src/include/k5-trace.h -+++ b/src/include/k5-trace.h -@@ -105,6 +105,9 @@ void krb5int_trace(krb5_context context, const char *fmt, ...); - - #endif /* DISABLE_TRACING */ - -+#define TRACE_CC_CACHE_MATCH(c, princ, ret) \ -+ TRACE(c, "Matching {princ} in collection with result: {kerr}", \ -+ princ, ret) - #define TRACE_CC_DESTROY(c, cache) \ - TRACE(c, "Destroying ccache {ccache}", cache) - #define TRACE_CC_GEN_NEW(c, cache) \ -diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index fcf2c2152..a1d7e0d96 100644 ---- a/src/lib/gssapi/krb5/accept_sec_context.c -+++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -683,7 +683,6 @@ kg_accept_krb5(minor_status, context_handle, - krb5_flags ap_req_options = 0; - krb5_enctype negotiated_etype; - krb5_authdata_context ad_context = NULL; -- krb5_principal accprinc = NULL; - krb5_ap_req *request = NULL; - - code = krb5int_accessor (&kaccess, KRB5INT_ACCESS_VERSION); -@@ -849,17 +848,9 @@ kg_accept_krb5(minor_status, context_handle, - } - } - -- if (!cred->default_identity) { -- if ((code = kg_acceptor_princ(context, cred->name, &accprinc))) { -- major_status = GSS_S_FAILURE; -- goto fail; -- } -- } -- -- code = krb5_rd_req_decoded(context, &auth_context, request, accprinc, -- cred->keytab, &ap_req_options, NULL); -- -- krb5_free_principal(context, accprinc); -+ code = krb5_rd_req_decoded(context, &auth_context, request, -+ cred->acceptor_mprinc, cred->keytab, -+ &ap_req_options, NULL); - if (code) { - major_status = GSS_S_FAILURE; - goto fail; -diff --git a/src/lib/gssapi/krb5/acquire_cred.c b/src/lib/gssapi/krb5/acquire_cred.c -index 632ee7def..e226a0269 100644 ---- a/src/lib/gssapi/krb5/acquire_cred.c -+++ b/src/lib/gssapi/krb5/acquire_cred.c -@@ -123,11 +123,11 @@ gss_krb5int_register_acceptor_identity(OM_uint32 *minor_status, - /* Try to verify that keytab contains at least one entry for name. Return 0 if - * it does, KRB5_KT_NOTFOUND if it doesn't, or another error as appropriate. */ - static krb5_error_code --check_keytab(krb5_context context, krb5_keytab kt, krb5_gss_name_t name) -+check_keytab(krb5_context context, krb5_keytab kt, krb5_gss_name_t name, -+ krb5_principal mprinc) - { - krb5_error_code code; - krb5_keytab_entry ent; -- krb5_principal accprinc = NULL; - char *princname; - - if (name->service == NULL) { -@@ -141,21 +141,15 @@ check_keytab(krb5_context context, krb5_keytab kt, krb5_gss_name_t name) - if (kt->ops->start_seq_get == NULL) - return 0; - -- /* Get the partial principal for the acceptor name. */ -- code = kg_acceptor_princ(context, name, &accprinc); -- if (code) -- return code; -- -- /* Scan the keytab for host-based entries matching accprinc. */ -- code = k5_kt_have_match(context, kt, accprinc); -+ /* Scan the keytab for host-based entries matching mprinc. */ -+ code = k5_kt_have_match(context, kt, mprinc); - if (code == KRB5_KT_NOTFOUND) { -- if (krb5_unparse_name(context, accprinc, &princname) == 0) { -+ if (krb5_unparse_name(context, mprinc, &princname) == 0) { - k5_setmsg(context, code, _("No key table entry found matching %s"), - princname); - free(princname); - } - } -- krb5_free_principal(context, accprinc); - return code; - } - -@@ -202,8 +196,14 @@ acquire_accept_cred(krb5_context context, OM_uint32 *minor_status, - } - - if (cred->name != NULL) { -+ code = kg_acceptor_princ(context, cred->name, &cred->acceptor_mprinc); -+ if (code) { -+ major = GSS_S_FAILURE; -+ goto cleanup; -+ } -+ - /* Make sure we have keys matching the desired name in the keytab. */ -- code = check_keytab(context, kt, cred->name); -+ code = check_keytab(context, kt, cred->name, cred->acceptor_mprinc); - if (code) { - if (code == KRB5_KT_NOTFOUND) { - k5_change_error_message_code(context, code, KG_KEYTAB_NOMATCH); -@@ -324,7 +324,6 @@ static krb5_boolean - can_get_initial_creds(krb5_context context, krb5_gss_cred_id_rec *cred) - { - krb5_error_code code; -- krb5_keytab_entry entry; - - if (cred->password != NULL) - return TRUE; -@@ -336,20 +335,21 @@ can_get_initial_creds(krb5_context context, krb5_gss_cred_id_rec *cred) - if (cred->name == NULL) - return !krb5_kt_have_content(context, cred->client_keytab); - -- /* Check if we have a keytab key for the client principal. */ -- code = krb5_kt_get_entry(context, cred->client_keytab, cred->name->princ, -- 0, 0, &entry); -- if (code) { -- krb5_clear_error_message(context); -- return FALSE; -- } -- krb5_free_keytab_entry_contents(context, &entry); -- return TRUE; -+ /* -+ * Check if we have a keytab key for the client principal. This is a bit -+ * more permissive than we really want because krb5_kt_have_match() -+ * supports wildcarding and obeys ignore_acceptor_hostname, but that should -+ * generally be harmless. -+ */ -+ code = k5_kt_have_match(context, cred->client_keytab, cred->name->princ); -+ return code == 0; - } - --/* Scan cred->ccache for name, expiry time, impersonator, refresh time. */ -+/* Scan cred->ccache for name, expiry time, impersonator, refresh time. If -+ * check_name is true, verify the cache name against the credential name. */ - static krb5_error_code --scan_ccache(krb5_context context, krb5_gss_cred_id_rec *cred) -+scan_ccache(krb5_context context, krb5_gss_cred_id_rec *cred, -+ krb5_boolean check_name) - { - krb5_error_code code; - krb5_ccache ccache = cred->ccache; -@@ -365,23 +365,31 @@ scan_ccache(krb5_context context, krb5_gss_cred_id_rec *cred) - if (code) - return code; - -- /* Credentials cache principal must match the initiator name. */ - code = krb5_cc_get_principal(context, ccache, &ccache_princ); - if (code != 0) - goto cleanup; -- if (cred->name != NULL && -- !krb5_principal_compare(context, ccache_princ, cred->name->princ)) { -- code = KG_CCACHE_NOMATCH; -- goto cleanup; -- } - -- /* Save the ccache principal as the credential name if not already set. */ -- if (!cred->name) { -+ if (cred->name == NULL) { -+ /* Save the ccache principal as the credential name. */ - code = kg_init_name(context, ccache_princ, NULL, NULL, NULL, - KG_INIT_NAME_NO_COPY, &cred->name); - if (code) - goto cleanup; - ccache_princ = NULL; -+ } else { -+ /* Check against the desired name if needed. */ -+ if (check_name) { -+ if (!k5_sname_compare(context, cred->name->princ, ccache_princ)) { -+ code = KG_CCACHE_NOMATCH; -+ goto cleanup; -+ } -+ } -+ -+ /* Replace the credential name principal with the canonical client -+ * principal, retaining acceptor_mprinc if set. */ -+ krb5_free_principal(context, cred->name->princ); -+ cred->name->princ = ccache_princ; -+ ccache_princ = NULL; - } - - assert(cred->name->princ != NULL); -@@ -447,7 +455,7 @@ get_cache_for_name(krb5_context context, krb5_gss_cred_id_rec *cred) - assert(cred->name != NULL && cred->ccache == NULL); - #ifdef USE_LEASH - code = get_ccache_leash(context, cred->name->princ, &cred->ccache); -- return code ? code : scan_ccache(context, cred); -+ return code ? code : scan_ccache(context, cred, TRUE); - #else - /* Check first whether we can acquire tickets, to avoid overwriting the - * extended error message from krb5_cc_cache_match. */ -@@ -456,7 +464,7 @@ get_cache_for_name(krb5_context context, krb5_gss_cred_id_rec *cred) - /* Look for an existing cache for the client principal. */ - code = krb5_cc_cache_match(context, cred->name->princ, &cred->ccache); - if (code == 0) -- return scan_ccache(context, cred); -+ return scan_ccache(context, cred, FALSE); - if (code != KRB5_CC_NOTFOUND || !can_get) - return code; - krb5_clear_error_message(context); -@@ -633,6 +641,13 @@ get_initial_cred(krb5_context context, const struct verify_params *verify, - kg_cred_set_initial_refresh(context, cred, &creds.times); - cred->have_tgt = TRUE; - cred->expire = creds.times.endtime; -+ -+ /* Steal the canonical client principal name from creds and save it in the -+ * credential name, retaining acceptor_mprinc if set. */ -+ krb5_free_principal(context, cred->name->princ); -+ cred->name->princ = creds.client; -+ creds.client = NULL; -+ - krb5_free_cred_contents(context, &creds); - cleanup: - krb5_get_init_creds_opt_free(context, opt); -@@ -721,7 +736,7 @@ acquire_init_cred(krb5_context context, OM_uint32 *minor_status, - - if (cred->ccache != NULL) { - /* The caller specified a ccache; check what's in it. */ -- code = scan_ccache(context, cred); -+ code = scan_ccache(context, cred, TRUE); - if (code == KRB5_FCC_NOFILE) { - /* See if we can get initial creds. If the caller didn't specify - * a name, pick one from the client keytab. */ -@@ -984,7 +999,7 @@ kg_cred_resolve(OM_uint32 *minor_status, krb5_context context, - } - } - if (cred->ccache != NULL) { -- code = scan_ccache(context, cred); -+ code = scan_ccache(context, cred, FALSE); - if (code) - goto kerr; - } -@@ -996,7 +1011,7 @@ kg_cred_resolve(OM_uint32 *minor_status, krb5_context context, - code = krb5int_cc_default(context, &cred->ccache); - if (code) - goto kerr; -- code = scan_ccache(context, cred); -+ code = scan_ccache(context, cred, FALSE); - if (code == KRB5_FCC_NOFILE) { - /* Default ccache doesn't exist; fall through to client keytab. */ - krb5_cc_close(context, cred->ccache); -diff --git a/src/lib/gssapi/krb5/gssapiP_krb5.h b/src/lib/gssapi/krb5/gssapiP_krb5.h -index 3bacdcd35..fd7abbd77 100644 ---- a/src/lib/gssapi/krb5/gssapiP_krb5.h -+++ b/src/lib/gssapi/krb5/gssapiP_krb5.h -@@ -175,6 +175,7 @@ typedef struct _krb5_gss_cred_id_rec { - /* name/type of credential */ - gss_cred_usage_t usage; - krb5_gss_name_t name; -+ krb5_principal acceptor_mprinc; - krb5_principal impersonator; - unsigned int default_identity : 1; - unsigned int iakerb_mech : 1; -diff --git a/src/lib/gssapi/krb5/rel_cred.c b/src/lib/gssapi/krb5/rel_cred.c -index a9515daf7..0da6c1b95 100644 ---- a/src/lib/gssapi/krb5/rel_cred.c -+++ b/src/lib/gssapi/krb5/rel_cred.c -@@ -72,6 +72,7 @@ krb5_gss_release_cred(minor_status, cred_handle) - if (cred->name) - kg_release_name(context, &cred->name); - -+ krb5_free_principal(context, cred->acceptor_mprinc); - krb5_free_principal(context, cred->impersonator); - - if (cred->req_enctypes) -diff --git a/src/lib/krb5/ccache/cccursor.c b/src/lib/krb5/ccache/cccursor.c -index 8f5872116..760216d05 100644 ---- a/src/lib/krb5/ccache/cccursor.c -+++ b/src/lib/krb5/ccache/cccursor.c -@@ -30,6 +30,7 @@ - - #include "cc-int.h" - #include "../krb/int-proto.h" -+#include "../os/os-proto.h" - - #include - -@@ -141,18 +142,18 @@ krb5_cccol_cursor_free(krb5_context context, - return 0; - } - --krb5_error_code KRB5_CALLCONV --krb5_cc_cache_match(krb5_context context, krb5_principal client, -- krb5_ccache *cache_out) -+static krb5_error_code -+match_caches(krb5_context context, krb5_const_principal client, -+ krb5_ccache *cache_out) - { - krb5_error_code ret; - krb5_cccol_cursor cursor; - krb5_ccache cache = NULL; - krb5_principal princ; -- char *name; - krb5_boolean eq; - - *cache_out = NULL; -+ - ret = krb5_cccol_cursor_new(context, &cursor); - if (ret) - return ret; -@@ -169,20 +170,52 @@ krb5_cc_cache_match(krb5_context context, krb5_principal client, - krb5_cc_close(context, cache); - } - krb5_cccol_cursor_free(context, &cursor); -+ - if (ret) - return ret; -- if (cache == NULL) { -- ret = krb5_unparse_name(context, client, &name); -- if (ret == 0) { -- k5_setmsg(context, KRB5_CC_NOTFOUND, -+ if (cache == NULL) -+ return KRB5_CC_NOTFOUND; -+ -+ *cache_out = cache; -+ return 0; -+} -+ -+krb5_error_code KRB5_CALLCONV -+krb5_cc_cache_match(krb5_context context, krb5_principal client, -+ krb5_ccache *cache_out) -+{ -+ krb5_error_code ret; -+ struct canonprinc iter = { client, .subst_defrealm = TRUE }; -+ krb5_const_principal canonprinc = NULL; -+ krb5_ccache cache = NULL; -+ char *name; -+ -+ *cache_out = NULL; -+ -+ while ((ret = k5_canonprinc(context, &iter, &canonprinc)) == 0 && -+ canonprinc != NULL) { -+ ret = match_caches(context, canonprinc, &cache); -+ if (ret != KRB5_CC_NOTFOUND) -+ break; -+ } -+ free_canonprinc(&iter); -+ -+ if (ret == 0 && canonprinc == NULL) { -+ ret = KRB5_CC_NOTFOUND; -+ if (krb5_unparse_name(context, client, &name) == 0) { -+ k5_setmsg(context, ret, - _("Can't find client principal %s in cache collection"), - name); - krb5_free_unparsed_name(context, name); - } -- ret = KRB5_CC_NOTFOUND; -- } else -- *cache_out = cache; -- return ret; -+ } -+ -+ TRACE_CC_CACHE_MATCH(context, client, ret); -+ if (ret) -+ return ret; -+ -+ *cache_out = cache; -+ return 0; - } - - /* Store the error state for code from context into errsave, but only if code -diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports -index adbfa332b..df6e2ffbe 100644 ---- a/src/lib/krb5/libkrb5.exports -+++ b/src/lib/krb5/libkrb5.exports -@@ -181,6 +181,7 @@ k5_size_authdata_context - k5_size_context - k5_size_keyblock - k5_size_principal -+k5_sname_compare - k5_unmarshal_cred - k5_unmarshal_princ - k5_unwrap_cammac_svc -diff --git a/src/lib/krb5/os/sn2princ.c b/src/lib/krb5/os/sn2princ.c -index 8b7214189..c99b7da17 100644 ---- a/src/lib/krb5/os/sn2princ.c -+++ b/src/lib/krb5/os/sn2princ.c -@@ -277,7 +277,8 @@ k5_canonprinc(krb5_context context, struct canonprinc *iter, - - /* If we're not doing fallback, the input principal is canonical. */ - if (context->dns_canonicalize_hostname != CANONHOST_FALLBACK || -- iter->princ->type != KRB5_NT_SRV_HST || iter->princ->length != 2) { -+ iter->princ->type != KRB5_NT_SRV_HST || iter->princ->length != 2 || -+ iter->princ->data[1].length == 0) { - *princ_out = (step == 1) ? iter->princ : NULL; - return 0; - } -@@ -288,6 +289,26 @@ k5_canonprinc(krb5_context context, struct canonprinc *iter, - return canonicalize_princ(context, iter, step == 2, princ_out); - } - -+krb5_boolean -+k5_sname_compare(krb5_context context, krb5_const_principal sname, -+ krb5_const_principal princ) -+{ -+ krb5_error_code ret; -+ struct canonprinc iter = { sname, .subst_defrealm = TRUE }; -+ krb5_const_principal canonprinc = NULL; -+ krb5_boolean match = FALSE; -+ -+ while ((ret = k5_canonprinc(context, &iter, &canonprinc)) == 0 && -+ canonprinc != NULL) { -+ if (krb5_principal_compare(context, canonprinc, princ)) { -+ match = TRUE; -+ break; -+ } -+ } -+ free_canonprinc(&iter); -+ return match; -+} -+ - krb5_error_code KRB5_CALLCONV - krb5_sname_to_principal(krb5_context context, const char *hostname, - const char *sname, krb5_int32 type, -diff --git a/src/lib/krb5_32.def b/src/lib/krb5_32.def -index 60b8dd311..cf690dbe4 100644 ---- a/src/lib/krb5_32.def -+++ b/src/lib/krb5_32.def -@@ -507,3 +507,4 @@ EXPORTS - ; new in 1.20 - krb5_marshal_credentials @472 - krb5_unmarshal_credentials @473 -+ k5_sname_compare @474 ; PRIVATE GSSAPI -diff --git a/src/tests/gssapi/t_client_keytab.py b/src/tests/gssapi/t_client_keytab.py -index 7847b3ecd..9a61d53b8 100755 ---- a/src/tests/gssapi/t_client_keytab.py -+++ b/src/tests/gssapi/t_client_keytab.py -@@ -141,5 +141,49 @@ msgs = ('Getting initial credentials for user/admin@KRBTEST.COM', - '/Matching credential not found') - realm.run(['./t_ccselect', phost], expected_code=1, - expected_msg='Ticket expired', expected_trace=msgs) -+realm.run([kdestroy, '-A']) -+ -+# Test 19: host-based initiator name -+mark('host-based initiator name') -+hsvc = 'h:svc@' + hostname -+svcprinc = 'svc/%s@%s' % (hostname, realm.realm) -+realm.addprinc(svcprinc) -+realm.extract_keytab(svcprinc, realm.client_keytab) -+# On the first run we match against the keytab while getting tickets, -+# substituting the default realm. -+msgs = ('/Can\'t find client principal svc/%s@ in' % hostname, -+ 'Getting initial credentials for svc/%s@' % hostname, -+ 'Found entries for %s in keytab' % svcprinc, -+ 'Retrieving %s from FILE:%s' % (svcprinc, realm.client_keytab), -+ 'Storing %s -> %s in' % (svcprinc, realm.krbtgt_princ), -+ 'Retrieving %s -> %s from' % (svcprinc, realm.krbtgt_princ), -+ 'authenticator for %s -> %s' % (svcprinc, realm.host_princ)) -+realm.run(['./t_ccselect', phost, hsvc], expected_trace=msgs) -+# On the second run we match against the collection. -+msgs = ('Matching svc/%s@ in collection with result: 0' % hostname, -+ 'Getting credentials %s -> %s' % (svcprinc, realm.host_princ), -+ 'authenticator for %s -> %s' % (svcprinc, realm.host_princ)) -+realm.run(['./t_ccselect', phost, hsvc], expected_trace=msgs) -+realm.run([kdestroy, '-A']) -+ -+# Test 20: host-based initiator name with fallback -+mark('host-based fallback initiator name') -+canonname = canonicalize_hostname(hostname) -+if canonname != hostname: -+ hfsvc = 'h:fsvc@' + hostname -+ canonprinc = 'fsvc/%s@%s' % (canonname, realm.realm) -+ realm.addprinc(canonprinc) -+ realm.extract_keytab(canonprinc, realm.client_keytab) -+ msgs = ('/Can\'t find client principal fsvc/%s@ in' % hostname, -+ 'Found entries for %s in keytab' % canonprinc, -+ 'authenticator for %s -> %s' % (canonprinc, realm.host_princ)) -+ realm.run(['./t_ccselect', phost, hfsvc], expected_trace=msgs) -+ msgs = ('Matching fsvc/%s@ in collection with result: 0' % hostname, -+ 'Getting credentials %s -> %s' % (canonprinc, realm.host_princ)) -+ realm.run(['./t_ccselect', phost, hfsvc], expected_trace=msgs) -+ realm.run([kdestroy, '-A']) -+else: -+ skipped('GSS initiator name fallback test', -+ '%s does not canonicalize to a different name' % hostname) - - success('Client keytab tests') -diff --git a/src/tests/gssapi/t_credstore.py b/src/tests/gssapi/t_credstore.py -index c11975bf5..9be57bb82 100644 ---- a/src/tests/gssapi/t_credstore.py -+++ b/src/tests/gssapi/t_credstore.py -@@ -15,6 +15,38 @@ msgs = ('Storing %s -> %s in %s' % (service_cs, realm.krbtgt_princ, - realm.run(['./t_credstore', '-s', 'p:' + service_cs, 'ccache', storagecache, - 'keytab', servicekeytab], expected_trace=msgs) - -+mark('matching') -+scc = 'FILE:' + os.path.join(realm.testdir, 'service_cache') -+realm.kinit(realm.host_princ, flags=['-k', '-c', scc]) -+realm.run(['./t_credstore', '-i', 'p:' + realm.host_princ, 'ccache', scc]) -+realm.run(['./t_credstore', '-i', 'h:host', 'ccache', scc]) -+realm.run(['./t_credstore', '-i', 'h:host@' + hostname, 'ccache', scc]) -+realm.run(['./t_credstore', '-i', 'p:wrong', 'ccache', scc], -+ expected_code=1, expected_msg='does not match desired name') -+realm.run(['./t_credstore', '-i', 'h:host@-nomatch-', 'ccache', scc], -+ expected_code=1, expected_msg='does not match desired name') -+realm.run(['./t_credstore', '-i', 'h:svc', 'ccache', scc], -+ expected_code=1, expected_msg='does not match desired name') -+ -+mark('matching (fallback)') -+canonname = canonicalize_hostname(hostname) -+if canonname != hostname: -+ canonprinc = 'host/%s@%s' % (canonname, realm.realm) -+ realm.addprinc(canonprinc) -+ realm.extract_keytab(canonprinc, realm.keytab) -+ realm.kinit(canonprinc, flags=['-k', '-c', scc]) -+ realm.run(['./t_credstore', '-i', 'h:host', 'ccache', scc]) -+ realm.run(['./t_credstore', '-i', 'h:host@' + hostname, 'ccache', scc]) -+ realm.run(['./t_credstore', '-i', 'h:host@' + canonname, 'ccache', scc]) -+ realm.run(['./t_credstore', '-i', 'p:' + canonprinc, 'ccache', scc]) -+ realm.run(['./t_credstore', '-i', 'p:' + realm.host_princ, 'ccache', scc], -+ expected_code=1, expected_msg='does not match desired name') -+ realm.run(['./t_credstore', '-i', 'h:host@-nomatch-', 'ccache', scc], -+ expected_code=1, expected_msg='does not match desired name') -+else: -+ skipped('fallback matching test', -+ '%s does not canonicalize to a different name' % hostname) -+ - mark('rcache') - # t_credstore -r should produce a replay error normally, but not with - # rcache set to "none:". diff --git a/Try-harder-to-avoid-password-change-replay-errors.patch b/Try-harder-to-avoid-password-change-replay-errors.patch deleted file mode 100644 index 875ed9c..0000000 --- a/Try-harder-to-avoid-password-change-replay-errors.patch +++ /dev/null @@ -1,91 +0,0 @@ -From 1f706852ee759160e763c355a3053ad5e045fa06 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 4 Mar 2022 00:45:00 -0500 -Subject: [PATCH] Try harder to avoid password change replay errors - -Commit d7b3018d338fc9c989c3fa17505870f23c3759a8 (ticket 7905) changed -change_set_password() to prefer TCP. However, because UDP_LAST falls -back to UDP after one second, we can still get a replay error due to a -dropped packet, before the TCP layer has a chance to retry. - -Instead, try k5_sendto() with NO_UDP, and only fall back to UDP after -TCP fails completely without reaching a server. In sendto_kdc.c, -implement an ONLY_UDP transport strategy to allow the UDP fallback. - -ticket: 9037 ---- - src/lib/krb5/os/changepw.c | 9 ++++++++- - src/lib/krb5/os/os-proto.h | 1 + - src/lib/krb5/os/sendto_kdc.c | 12 ++++++++---- - 3 files changed, 17 insertions(+), 5 deletions(-) - -diff --git a/src/lib/krb5/os/changepw.c b/src/lib/krb5/os/changepw.c -index 9f968da7f..c59232586 100644 ---- a/src/lib/krb5/os/changepw.c -+++ b/src/lib/krb5/os/changepw.c -@@ -255,9 +255,16 @@ change_set_password(krb5_context context, - callback_info.pfn_cleanup = kpasswd_sendto_msg_cleanup; - krb5_free_data_contents(callback_ctx.context, &chpw_rep); - -+ /* UDP retransmits may be seen as replays. Only try UDP after other -+ * transports fail completely. */ - code = k5_sendto(callback_ctx.context, NULL, &creds->server->realm, -- &sl, UDP_LAST, &callback_info, &chpw_rep, -+ &sl, NO_UDP, &callback_info, &chpw_rep, - ss2sa(&remote_addr), &addrlen, NULL, NULL, NULL); -+ if (code == KRB5_KDC_UNREACH) { -+ code = k5_sendto(callback_ctx.context, NULL, &creds->server->realm, -+ &sl, ONLY_UDP, &callback_info, &chpw_rep, -+ ss2sa(&remote_addr), &addrlen, NULL, NULL, NULL); -+ } - if (code) - goto cleanup; - -diff --git a/src/lib/krb5/os/os-proto.h b/src/lib/krb5/os/os-proto.h -index a985f2aec..91d2791ce 100644 ---- a/src/lib/krb5/os/os-proto.h -+++ b/src/lib/krb5/os/os-proto.h -@@ -49,6 +49,7 @@ typedef enum { - UDP_FIRST = 0, - UDP_LAST, - NO_UDP, -+ ONLY_UDP - } k5_transport_strategy; - - /* A single server hostname or address. */ -diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c -index 0eedec175..c7f5d861a 100644 ---- a/src/lib/krb5/os/sendto_kdc.c -+++ b/src/lib/krb5/os/sendto_kdc.c -@@ -802,11 +802,14 @@ resolve_server(krb5_context context, const krb5_data *realm, - int err, result; - char portbuf[PORT_LENGTH]; - -- /* Skip UDP entries if we don't want UDP. */ -+ /* Skip entries excluded by the strategy. */ - if (strategy == NO_UDP && entry->transport == UDP) - return 0; -+ if (strategy == ONLY_UDP && entry->transport != UDP && -+ entry->transport != TCP_OR_UDP) -+ return 0; - -- transport = (strategy == UDP_FIRST) ? UDP : TCP; -+ transport = (strategy == UDP_FIRST || strategy == ONLY_UDP) ? UDP : TCP; - if (entry->hostname == NULL) { - /* Added by a module, so transport is either TCP or UDP. */ - ai.ai_socktype = socktype_for_transport(entry->transport); -@@ -850,8 +853,9 @@ resolve_server(krb5_context context, const krb5_data *realm, - } - - /* For TCP_OR_UDP entries, add each address again with the non-preferred -- * transport, unless we are avoiding UDP. Flag these as deferred. */ -- if (retval == 0 && entry->transport == TCP_OR_UDP && strategy != NO_UDP) { -+ * transport, if there is one. Flag these as deferred. */ -+ if (retval == 0 && entry->transport == TCP_OR_UDP && -+ (strategy == UDP_FIRST || strategy == UDP_LAST)) { - transport = (strategy == UDP_FIRST) ? TCP : UDP; - for (a = addrs; a != 0 && retval == 0; a = a->ai_next) { - a->ai_socktype = socktype_for_transport(transport); --- -2.35.1 - diff --git a/Use-KCM_OP_RETRIEVE-in-KCM-client.patch b/Use-KCM_OP_RETRIEVE-in-KCM-client.patch deleted file mode 100644 index 2af5676..0000000 --- a/Use-KCM_OP_RETRIEVE-in-KCM-client.patch +++ /dev/null @@ -1,235 +0,0 @@ -From 336f744403baa5dfaffcc5bd226fdd8f14a0200b Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 26 Mar 2021 23:38:54 -0400 -Subject: [PATCH] Use KCM_OP_RETRIEVE in KCM client - -In kcm_retrieve(), try KCM_OP_RETRIEVE. Fall back to iteration if the -server doesn't implement it, or if we can an answer incompatible with -KRB5_TC_SUPPORTED_KTYPES. - -In kcmserver.py, implement partial decoding for creds and cred tags so -that we can do a basic principal name match. - -ticket: 8997 (new) -(cherry picked from commit 795ebba8c039be172ab93cd41105c73ffdba0fdb) ---- - src/include/kcm.h | 2 +- - src/lib/krb5/ccache/cc_kcm.c | 52 +++++++++++++++++++++++++++++++++--- - src/tests/kcmserver.py | 44 +++++++++++++++++++++++++++--- - src/tests/t_ccache.py | 11 +++++--- - 4 files changed, 99 insertions(+), 10 deletions(-) - -diff --git a/src/include/kcm.h b/src/include/kcm.h -index 9b66f1cbd..85c20d345 100644 ---- a/src/include/kcm.h -+++ b/src/include/kcm.h -@@ -87,7 +87,7 @@ typedef enum kcm_opcode { - KCM_OP_INITIALIZE, /* (name, princ) -> () */ - KCM_OP_DESTROY, /* (name) -> () */ - KCM_OP_STORE, /* (name, cred) -> () */ -- KCM_OP_RETRIEVE, -+ KCM_OP_RETRIEVE, /* (name, flags, credtag) -> (cred) */ - KCM_OP_GET_PRINCIPAL, /* (name) -> (princ) */ - KCM_OP_GET_CRED_UUID_LIST, /* (name) -> (uuid, ...) */ - KCM_OP_GET_CRED_BY_UUID, /* (name, uuid) -> (cred) */ -diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c -index 46705f1da..23fcf13ea 100644 ---- a/src/lib/krb5/ccache/cc_kcm.c -+++ b/src/lib/krb5/ccache/cc_kcm.c -@@ -826,9 +826,55 @@ static krb5_error_code KRB5_CALLCONV - kcm_retrieve(krb5_context context, krb5_ccache cache, krb5_flags flags, - krb5_creds *mcred, krb5_creds *cred_out) - { -- /* There is a KCM opcode for retrieving creds, but Heimdal's client doesn't -- * use it. It causes the KCM daemon to actually make a TGS request. */ -- return k5_cc_retrieve_cred_default(context, cache, flags, mcred, cred_out); -+ krb5_error_code ret; -+ struct kcmreq req = EMPTY_KCMREQ; -+ krb5_creds cred; -+ krb5_enctype *enctypes = NULL; -+ -+ memset(&cred, 0, sizeof(cred)); -+ -+ /* Include KCM_GC_CACHED in flags to prevent Heimdal's sssd from making a -+ * TGS request itself. */ -+ kcmreq_init(&req, KCM_OP_RETRIEVE, cache); -+ k5_buf_add_uint32_be(&req.reqbuf, map_tcflags(flags) | KCM_GC_CACHED); -+ k5_marshal_mcred(&req.reqbuf, mcred); -+ ret = cache_call(context, cache, &req); -+ -+ /* Fall back to iteration if the server does not support retrieval. */ -+ if (ret == KRB5_FCC_INTERNAL || ret == KRB5_CC_IO) { -+ ret = k5_cc_retrieve_cred_default(context, cache, flags, mcred, -+ cred_out); -+ goto cleanup; -+ } -+ if (ret) -+ goto cleanup; -+ -+ ret = k5_unmarshal_cred(req.reply.ptr, req.reply.len, 4, &cred); -+ if (ret) -+ goto cleanup; -+ -+ /* In rare cases we might retrieve a credential with a session key this -+ * context can't support, in which case we must retry using iteration. */ -+ if (flags & KRB5_TC_SUPPORTED_KTYPES) { -+ ret = krb5_get_tgs_ktypes(context, cred.server, &enctypes); -+ if (ret) -+ goto cleanup; -+ if (!k5_etypes_contains(enctypes, cred.keyblock.enctype)) { -+ ret = k5_cc_retrieve_cred_default(context, cache, flags, mcred, -+ cred_out); -+ goto cleanup; -+ } -+ } -+ -+ *cred_out = cred; -+ memset(&cred, 0, sizeof(cred)); -+ -+cleanup: -+ kcmreq_free(&req); -+ krb5_free_cred_contents(context, &cred); -+ free(enctypes); -+ /* Heimdal's KCM returns KRB5_CC_END if no cred is found. */ -+ return (ret == KRB5_CC_END) ? KRB5_CC_NOTFOUND : map_invalid(ret); - } - - static krb5_error_code KRB5_CALLCONV -diff --git a/src/tests/kcmserver.py b/src/tests/kcmserver.py -index 8c5e66ff1..25e6f2bbe 100644 ---- a/src/tests/kcmserver.py -+++ b/src/tests/kcmserver.py -@@ -40,6 +40,7 @@ class KCMOpcodes(object): - INITIALIZE = 4 - DESTROY = 5 - STORE = 6 -+ RETRIEVE = 7 - GET_PRINCIPAL = 8 - GET_CRED_UUID_LIST = 9 - GET_CRED_BY_UUID = 10 -@@ -54,6 +55,7 @@ class KCMOpcodes(object): - - - class KRB5Errors(object): -+ KRB5_CC_NOTFOUND = -1765328243 - KRB5_CC_END = -1765328242 - KRB5_CC_NOSUPP = -1765328137 - KRB5_FCC_NOFILE = -1765328189 -@@ -86,11 +88,29 @@ def get_cache(name): - return cache - - -+def unpack_data(argbytes): -+ dlen, = struct.unpack('>L', argbytes[:4]) -+ return argbytes[4:dlen+4], argbytes[dlen+4:] -+ -+ - def unmarshal_name(argbytes): - offset = argbytes.find(b'\0') - return argbytes[0:offset], argbytes[offset+1:] - - -+def unmarshal_princ(argbytes): -+ # Ignore the type at argbytes[0:4]. -+ ncomps, = struct.unpack('>L', argbytes[4:8]) -+ realm, rest = unpack_data(argbytes[8:]) -+ comps = [] -+ for i in range(ncomps): -+ comp, rest = unpack_data(rest) -+ comps.append(comp) -+ # Asssume no quoting is needed. -+ princ = b'/'.join(comps) + b'@' + realm -+ return princ, rest -+ -+ - def op_gen_new(argbytes): - # Does not actually check for uniqueness. - global next_unique -@@ -126,6 +146,22 @@ def op_store(argbytes): - return 0, b'' - - -+def op_retrieve(argbytes): -+ name, rest = unmarshal_name(argbytes) -+ # Ignore the flags at rest[0:4] and the header at rest[4:8]. -+ # Assume there are client and server creds in the tag and match -+ # only against them. -+ cprinc, rest = unmarshal_princ(rest[8:]) -+ sprinc, rest = unmarshal_princ(rest) -+ cache = get_cache(name) -+ for cred in (cache.creds[u] for u in cache.cred_uuids): -+ cred_cprinc, rest = unmarshal_princ(cred) -+ cred_sprinc, rest = unmarshal_princ(rest) -+ if cred_cprinc == cprinc and cred_sprinc == sprinc: -+ return 0, cred -+ return KRB5Errors.KRB5_CC_NOTFOUND, b'' -+ -+ - def op_get_principal(argbytes): - name, rest = unmarshal_name(argbytes) - cache = get_cache(name) -@@ -199,6 +235,7 @@ ophandlers = { - KCMOpcodes.INITIALIZE : op_initialize, - KCMOpcodes.DESTROY : op_destroy, - KCMOpcodes.STORE : op_store, -+ KCMOpcodes.RETRIEVE : op_retrieve, - KCMOpcodes.GET_PRINCIPAL : op_get_principal, - KCMOpcodes.GET_CRED_UUID_LIST : op_get_cred_uuid_list, - KCMOpcodes.GET_CRED_BY_UUID : op_get_cred_by_uuid, -@@ -243,10 +280,11 @@ def service_request(s): - return True - - parser = optparse.OptionParser() --parser.add_option('-c', '--credlist', action='store_true', dest='credlist', -- default=False, help='Support KCM_OP_GET_CRED_LIST') -+parser.add_option('-f', '--fallback', action='store_true', dest='fallback', -+ default=False, help='Do not support RETRIEVE/GET_CRED_LIST') - (options, args) = parser.parse_args() --if not options.credlist: -+if options.fallback: -+ del ophandlers[KCMOpcodes.RETRIEVE] - del ophandlers[KCMOpcodes.GET_CRED_LIST] - - server = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM) -diff --git a/src/tests/t_ccache.py b/src/tests/t_ccache.py -index 90040fb7b..6ea9fb969 100755 ---- a/src/tests/t_ccache.py -+++ b/src/tests/t_ccache.py -@@ -25,7 +25,7 @@ from k5test import * - kcm_socket_path = os.path.join(os.getcwd(), 'testdir', 'kcm') - conf = {'libdefaults': {'kcm_socket': kcm_socket_path, - 'kcm_mach_service': '-'}} --realm = K5Realm(create_host=False, krb5_conf=conf) -+realm = K5Realm(krb5_conf=conf) - - keyctl = which('keyctl') - out = realm.run([klist, '-c', 'KEYRING:process:abcd'], expected_code=1) -@@ -71,6 +71,11 @@ def collection_test(realm, ccname): - realm.kinit('alice', password('alice')) - realm.run([klist], expected_msg='Default principal: alice@') - realm.run([klist, '-A', '-s']) -+ realm.run([kvno, realm.host_princ], expected_msg = 'kvno = 1') -+ realm.run([kvno, realm.host_princ], expected_msg = 'kvno = 1') -+ out = realm.run([klist]) -+ if out.count(realm.host_princ) != 1: -+ fail('Wrong number of service tickets in cache') - realm.run([kdestroy]) - output = realm.run([klist], expected_code=1) - if 'No credentials cache' not in output and 'not found' not in output: -@@ -126,14 +131,14 @@ def collection_test(realm, ccname): - - collection_test(realm, 'DIR:' + os.path.join(realm.testdir, 'cc')) - --# Test KCM without and with GET_CRED_LIST support. -+# Test KCM with and without RETRIEVE and GET_CRED_LIST support. - kcmserver_path = os.path.join(srctop, 'tests', 'kcmserver.py') - kcmd = realm.start_server([sys.executable, kcmserver_path, kcm_socket_path], - 'starting...') - collection_test(realm, 'KCM:') - stop_daemon(kcmd) - os.remove(kcm_socket_path) --realm.start_server([sys.executable, kcmserver_path, '-c', kcm_socket_path], -+realm.start_server([sys.executable, kcmserver_path, '-f', kcm_socket_path], - 'starting...') - collection_test(realm, 'KCM:') - diff --git a/Use-OpenSSL-s-KBKDF-and-KRB5KDF-for-deriving-long-te.patch b/Use-OpenSSL-s-KBKDF-and-KRB5KDF-for-deriving-long-te.patch deleted file mode 100644 index 927b506..0000000 --- a/Use-OpenSSL-s-KBKDF-and-KRB5KDF-for-deriving-long-te.patch +++ /dev/null @@ -1,482 +0,0 @@ -From 21e3b9a4463f1d1aeb71de8a27c298f1307d186b Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 4 Oct 2019 14:49:29 -0400 -Subject: [PATCH] Use OpenSSL's KBKDF and KRB5KDF for deriving long-term keys - -If supported, use OpenSSL-provided KBKDF (aes-sha2 and camellia) and -KRB5KDF (3des and aes-sha1). We already use OpenSSL's PBKDF2 where -appropriate. OpenSSL added support for these KDFs in 3.0. - -(cherry picked from commit ef8d11f6fb1232201c9efd2ae2ed567023fb85d2) -[rharwood@redhat.com: 3des removal] ---- - src/lib/crypto/krb/derive.c | 409 ++++++++++++++++++++++++++++-------- - 1 file changed, 324 insertions(+), 85 deletions(-) - -diff --git a/src/lib/crypto/krb/derive.c b/src/lib/crypto/krb/derive.c -index 6707a7308..8e474b38e 100644 ---- a/src/lib/crypto/krb/derive.c -+++ b/src/lib/crypto/krb/derive.c -@@ -27,6 +27,12 @@ - - #include "crypto_int.h" - -+#ifdef HAVE_EVP_KDF_FETCH -+#include -+#include -+#include -+#endif -+ - static krb5_key - find_cached_dkey(struct derived_key *list, const krb5_data *constant) - { -@@ -77,55 +83,251 @@ cleanup: - return ENOMEM; - } - -+#ifdef HAVE_EVP_KDF_FETCH - static krb5_error_code --derive_random_rfc3961(const struct krb5_enc_provider *enc, -- krb5_key inkey, krb5_data *outrnd, -- const krb5_data *in_constant) -+openssl_kbdkf_counter_hmac(const struct krb5_hash_provider *hash, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *label, const krb5_data *context) - { -- size_t blocksize, keybytes, n; - krb5_error_code ret; -- krb5_data block = empty_data(); -+ EVP_KDF *kdf = NULL; -+ EVP_KDF_CTX *kctx = NULL; -+ OSSL_PARAM params[6]; -+ size_t i = 0; -+ char *digest; - -- blocksize = enc->block_size; -- keybytes = enc->keybytes; -+ /* On NULL hash, preserve default behavior for pbkdf2_string_to_key(). */ -+ if (hash == NULL || !strcmp(hash->hash_name, "SHA1")) { -+ digest = "SHA1"; -+ } else if (!strcmp(hash->hash_name, "SHA-256")) { -+ digest = "SHA256"; -+ } else if (!strcmp(hash->hash_name, "SHA-384")) { -+ digest = "SHA384"; -+ } else { -+ ret = KRB5_CRYPTO_INTERNAL; -+ goto done; -+ } - -- if (blocksize == 1) -- return KRB5_BAD_ENCTYPE; -- if (inkey->keyblock.length != enc->keylength || outrnd->length != keybytes) -+ kdf = EVP_KDF_fetch(NULL, "KBKDF", NULL); -+ if (!kdf) { -+ ret = KRB5_CRYPTO_INTERNAL; -+ goto done; -+ } -+ -+ kctx = EVP_KDF_CTX_new(kdf); -+ if (!kctx) { -+ ret = KRB5_CRYPTO_INTERNAL; -+ goto done; -+ } -+ -+ params[i++] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, -+ digest, 0); -+ params[i++] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MAC, -+ "HMAC", 0); -+ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, -+ inkey->keyblock.contents, -+ inkey->keyblock.length); -+ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO, -+ context->data, -+ context->length); -+ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT, -+ label->data, -+ label->length); -+ params[i] = OSSL_PARAM_construct_end(); -+ if (EVP_KDF_derive(kctx, (unsigned char *)outrnd->data, outrnd->length, -+ params) <= 0) { -+ ret = KRB5_CRYPTO_INTERNAL; -+ goto done; -+ } -+ -+ ret = 0; -+done: -+ if (ret) -+ zap(outrnd->data, outrnd->length); -+ EVP_KDF_free(kdf); -+ EVP_KDF_CTX_free(kctx); -+ return ret; -+} -+ -+static krb5_error_code -+openssl_kbkdf_feedback_cmac(const struct krb5_enc_provider *enc, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *in_constant) -+{ -+ krb5_error_code ret; -+ EVP_KDF *kdf = NULL; -+ EVP_KDF_CTX *kctx = NULL; -+ OSSL_PARAM params[7]; -+ size_t i = 0; -+ char *cipher; -+ static unsigned char zeroes[16]; -+ -+ memset(zeroes, 0, sizeof(zeroes)); -+ -+ if (!memcmp(enc, &krb5int_enc_camellia128, sizeof(*enc))) { -+ cipher = "CAMELLIA-128-CBC"; -+ } else if (!memcmp(enc, &krb5int_enc_camellia256, sizeof(*enc))) { -+ cipher = "CAMELLIA-256-CBC"; -+ } else { -+ ret = KRB5_CRYPTO_INTERNAL; -+ goto done; -+ } -+ -+ kdf = EVP_KDF_fetch(NULL, "KBKDF", NULL); -+ if (!kdf) { -+ ret = KRB5_CRYPTO_INTERNAL; -+ goto done; -+ } -+ -+ kctx = EVP_KDF_CTX_new(kdf); -+ if (!kctx) { -+ ret = KRB5_CRYPTO_INTERNAL; -+ goto done; -+ } -+ -+ params[i++] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MODE, -+ "FEEDBACK", 0); -+ params[i++] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MAC, -+ "CMAC", 0); -+ params[i++] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_CIPHER, -+ cipher, 0); -+ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, -+ inkey->keyblock.contents, -+ inkey->keyblock.length); -+ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT, -+ in_constant->data, -+ in_constant->length); -+ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SEED, -+ zeroes, sizeof(zeroes)); -+ params[i] = OSSL_PARAM_construct_end(); -+ if (EVP_KDF_derive(kctx, (unsigned char *)outrnd->data, outrnd->length, -+ params) <= 0) { -+ ret = KRB5_CRYPTO_INTERNAL; -+ goto done; -+ } -+ -+ ret = 0; -+done: -+ if (ret) -+ zap(outrnd->data, outrnd->length); -+ EVP_KDF_free(kdf); -+ EVP_KDF_CTX_free(kctx); -+ return ret; -+} -+ -+static krb5_error_code -+openssl_krb5kdf(const struct krb5_enc_provider *enc, krb5_key inkey, -+ krb5_data *outrnd, const krb5_data *in_constant) -+{ -+ krb5_error_code ret; -+ EVP_KDF *kdf = NULL; -+ EVP_KDF_CTX *kctx = NULL; -+ OSSL_PARAM params[4]; -+ size_t i = 0; -+ char *cipher; -+ -+ if (inkey->keyblock.length != enc->keylength || -+ outrnd->length != enc->keybytes) { -+ return KRB5_CRYPTO_INTERNAL; -+ } -+ -+ if (!memcmp(enc, &krb5int_enc_aes128, sizeof(*enc))) { -+ cipher = "AES-128-CBC"; -+ } else if (!memcmp(enc, &krb5int_enc_aes256, sizeof(*enc))) { -+ cipher = "AES-256-CBC"; -+ } else { -+ ret = KRB5_CRYPTO_INTERNAL; -+ goto done; -+ } -+ -+ kdf = EVP_KDF_fetch(NULL, "KRB5KDF", NULL); -+ if (kdf == NULL) { -+ ret = KRB5_CRYPTO_INTERNAL; -+ goto done; -+ } -+ -+ kctx = EVP_KDF_CTX_new(kdf); -+ if (kctx == NULL) { -+ ret = KRB5_CRYPTO_INTERNAL; -+ goto done; -+ } -+ -+ params[i++] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_CIPHER, -+ cipher, 0); -+ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, -+ inkey->keyblock.contents, -+ inkey->keyblock.length); -+ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_CONSTANT, -+ in_constant->data, -+ in_constant->length); -+ params[i] = OSSL_PARAM_construct_end(); -+ if (EVP_KDF_derive(kctx, (unsigned char *)outrnd->data, outrnd->length, -+ params) <= 0) { -+ ret = KRB5_CRYPTO_INTERNAL; -+ goto done; -+ } -+ -+ ret = 0; -+done: -+ if (ret) -+ zap(outrnd->data, outrnd->length); -+ EVP_KDF_free(kdf); -+ EVP_KDF_CTX_free(kctx); -+ return ret; -+} -+ -+#else /* HAVE_EVP_KDF_FETCH */ -+ -+/* -+ * NIST SP800-108 KDF in counter mode (section 5.1). -+ * Parameters: -+ * - HMAC (with hash as the hash provider) is the PRF. -+ * - A block counter of four bytes is used. -+ * - Four bytes are used to encode the output length in the PRF input. -+ * -+ * There are no uses requiring more than a single PRF invocation. -+ */ -+static krb5_error_code -+builtin_sp800_108_counter_hmac(const struct krb5_hash_provider *hash, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *label, -+ const krb5_data *context) -+{ -+ krb5_crypto_iov iov[5]; -+ krb5_error_code ret; -+ krb5_data prf; -+ unsigned char ibuf[4], lbuf[4]; -+ -+ if (hash == NULL || outrnd->length > hash->hashsize) - return KRB5_CRYPTO_INTERNAL; - - /* Allocate encryption data buffer. */ -- ret = alloc_data(&block, blocksize); -+ ret = alloc_data(&prf, hash->hashsize); - if (ret) - return ret; - -- /* Initialize the input block. */ -- if (in_constant->length == blocksize) { -- memcpy(block.data, in_constant->data, blocksize); -- } else { -- krb5int_nfold(in_constant->length * 8, -- (unsigned char *) in_constant->data, -- blocksize * 8, (unsigned char *) block.data); -- } -+ /* [i]2: four-byte big-endian binary string giving the block counter (1) */ -+ iov[0].flags = KRB5_CRYPTO_TYPE_DATA; -+ iov[0].data = make_data(ibuf, sizeof(ibuf)); -+ store_32_be(1, ibuf); -+ /* Label */ -+ iov[1].flags = KRB5_CRYPTO_TYPE_DATA; -+ iov[1].data = *label; -+ /* 0x00: separator byte */ -+ iov[2].flags = KRB5_CRYPTO_TYPE_DATA; -+ iov[2].data = make_data("", 1); -+ /* Context */ -+ iov[3].flags = KRB5_CRYPTO_TYPE_DATA; -+ iov[3].data = *context; -+ /* [L]2: four-byte big-endian binary string giving the output length */ -+ iov[4].flags = KRB5_CRYPTO_TYPE_DATA; -+ iov[4].data = make_data(lbuf, sizeof(lbuf)); -+ store_32_be(outrnd->length * 8, lbuf); - -- /* Loop encrypting the blocks until enough key bytes are generated. */ -- n = 0; -- while (n < keybytes) { -- ret = encrypt_block(enc, inkey, &block); -- if (ret) -- goto cleanup; -- -- if ((keybytes - n) <= blocksize) { -- memcpy(outrnd->data + n, block.data, (keybytes - n)); -- break; -- } -- -- memcpy(outrnd->data + n, block.data, blocksize); -- n += blocksize; -- } -- --cleanup: -- zapfree(block.data, blocksize); -+ ret = krb5int_hmac(hash, inkey, iov, 5, &prf); -+ if (!ret) -+ memcpy(outrnd->data, prf.data, outrnd->length); -+ zapfree(prf.data, prf.length); - return ret; - } - -@@ -139,9 +341,9 @@ cleanup: - * - Four bytes are used to encode the output length in the PRF input. - */ - static krb5_error_code --derive_random_sp800_108_feedback_cmac(const struct krb5_enc_provider *enc, -- krb5_key inkey, krb5_data *outrnd, -- const krb5_data *in_constant) -+builtin_sp800_108_feedback_cmac(const struct krb5_enc_provider *enc, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *in_constant) - { - size_t blocksize, keybytes, n; - krb5_crypto_iov iov[6]; -@@ -204,56 +406,94 @@ cleanup: - return ret; - } - --/* -- * NIST SP800-108 KDF in counter mode (section 5.1). -- * Parameters: -- * - HMAC (with hash as the hash provider) is the PRF. -- * - A block counter of four bytes is used. -- * - Four bytes are used to encode the output length in the PRF input. -- * -- * There are no uses requiring more than a single PRF invocation. -- */ -+static krb5_error_code -+builtin_derive_random_rfc3961(const struct krb5_enc_provider *enc, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *in_constant) -+{ -+ size_t blocksize, keybytes, n; -+ krb5_error_code ret; -+ krb5_data block = empty_data(); -+ -+ blocksize = enc->block_size; -+ keybytes = enc->keybytes; -+ -+ if (blocksize == 1) -+ return KRB5_BAD_ENCTYPE; -+ if (inkey->keyblock.length != enc->keylength || outrnd->length != keybytes) -+ return KRB5_CRYPTO_INTERNAL; -+ -+ /* Allocate encryption data buffer. */ -+ ret = alloc_data(&block, blocksize); -+ if (ret) -+ return ret; -+ -+ /* Initialize the input block. */ -+ if (in_constant->length == blocksize) { -+ memcpy(block.data, in_constant->data, blocksize); -+ } else { -+ krb5int_nfold(in_constant->length * 8, -+ (unsigned char *) in_constant->data, -+ blocksize * 8, (unsigned char *) block.data); -+ } -+ -+ /* Loop encrypting the blocks until enough key bytes are generated. */ -+ n = 0; -+ while (n < keybytes) { -+ ret = encrypt_block(enc, inkey, &block); -+ if (ret) -+ goto cleanup; -+ -+ if ((keybytes - n) <= blocksize) { -+ memcpy(outrnd->data + n, block.data, (keybytes - n)); -+ break; -+ } -+ -+ memcpy(outrnd->data + n, block.data, blocksize); -+ n += blocksize; -+ } -+ -+cleanup: -+ zapfree(block.data, blocksize); -+ return ret; -+} -+#endif /* HAVE_EVP_KDF_FETCH */ -+ - krb5_error_code - k5_sp800_108_counter_hmac(const struct krb5_hash_provider *hash, - krb5_key inkey, krb5_data *outrnd, - const krb5_data *label, const krb5_data *context) - { -- krb5_crypto_iov iov[5]; -- krb5_error_code ret; -- krb5_data prf; -- unsigned char ibuf[4], lbuf[4]; -+#ifdef HAVE_EVP_KDF_FETCH -+ return openssl_kbdkf_counter_hmac(hash, inkey, outrnd, label, context); -+#else -+ return builtin_sp800_108_counter_hmac(hash, inkey, outrnd, label, -+ context); -+#endif -+} - -- if (hash == NULL || outrnd->length > hash->hashsize) -- return KRB5_CRYPTO_INTERNAL; -+static krb5_error_code -+sp800_108_feedback_cmac(const struct krb5_enc_provider *enc, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *in_constant) -+{ -+#ifdef HAVE_EVP_KDF_FETCH -+ return openssl_kbkdf_feedback_cmac(enc, inkey, outrnd, in_constant); -+#else -+ return builtin_sp800_108_feedback_cmac(enc, inkey, outrnd, in_constant); -+#endif -+} - -- /* Allocate encryption data buffer. */ -- ret = alloc_data(&prf, hash->hashsize); -- if (ret) -- return ret; -- -- /* [i]2: four-byte big-endian binary string giving the block counter (1) */ -- iov[0].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[0].data = make_data(ibuf, sizeof(ibuf)); -- store_32_be(1, ibuf); -- /* Label */ -- iov[1].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[1].data = *label; -- /* 0x00: separator byte */ -- iov[2].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[2].data = make_data("", 1); -- /* Context */ -- iov[3].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[3].data = *context; -- /* [L]2: four-byte big-endian binary string giving the output length */ -- iov[4].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[4].data = make_data(lbuf, sizeof(lbuf)); -- store_32_be(outrnd->length * 8, lbuf); -- -- ret = krb5int_hmac(hash, inkey, iov, 5, &prf); -- if (!ret) -- memcpy(outrnd->data, prf.data, outrnd->length); -- zapfree(prf.data, prf.length); -- return ret; -+static krb5_error_code -+derive_random_rfc3961(const struct krb5_enc_provider *enc, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *in_constant) -+{ -+#ifdef HAVE_EVP_KDF_FETCH -+ return openssl_krb5kdf(enc, inkey, outrnd, in_constant); -+#else -+ return builtin_derive_random_rfc3961(enc, inkey, outrnd, in_constant); -+#endif - } - - krb5_error_code -@@ -268,8 +508,7 @@ krb5int_derive_random(const struct krb5_enc_provider *enc, - case DERIVE_RFC3961: - return derive_random_rfc3961(enc, inkey, outrnd, in_constant); - case DERIVE_SP800_108_CMAC: -- return derive_random_sp800_108_feedback_cmac(enc, inkey, outrnd, -- in_constant); -+ return sp800_108_feedback_cmac(enc, inkey, outrnd, in_constant); - case DERIVE_SP800_108_HMAC: - return k5_sp800_108_counter_hmac(hash, inkey, outrnd, in_constant, - &empty); diff --git a/Use-OpenSSL-s-SSKDF-in-PKINIT-when-available.patch b/Use-OpenSSL-s-SSKDF-in-PKINIT-when-available.patch deleted file mode 100644 index 0a9cde1..0000000 --- a/Use-OpenSSL-s-SSKDF-in-PKINIT-when-available.patch +++ /dev/null @@ -1,408 +0,0 @@ -From 8bbb492f2be1418e1e4bb2cf197414810dac9589 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 20 Sep 2019 17:20:59 -0400 -Subject: [PATCH] Use OpenSSL's SSKDF in PKINIT when available - -Starting in 3.0, OpenSSL implements SSKDF, which is the basis of our -id-pkinit-kdf (RFC 8636). Factor out common setup code around -other_info. Adjust code to comply to existing style. - -(cherry picked from commit 4376a22e41fb639be31daf81275a332d3f930996) ---- - .../preauth/pkinit/pkinit_crypto_openssl.c | 294 +++++++++++------- - 1 file changed, 181 insertions(+), 113 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index e1153344e..350c2118a 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -38,6 +38,12 @@ - #include - #include - -+#ifdef HAVE_EVP_KDF_FETCH -+#include -+#include -+#include -+#endif -+ - static krb5_error_code pkinit_init_pkinit_oids(pkinit_plg_crypto_context ); - static void pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ); - -@@ -2294,15 +2300,16 @@ cleanup: - } - - --/** -+/* - * Given an algorithm_identifier, this function returns the hash length - * and EVP function associated with that algorithm. -+ * -+ * RFC 8636 defines a SHA384 variant, but we don't use it. - */ - static krb5_error_code --pkinit_alg_values(krb5_context context, -- const krb5_data *alg_id, -- size_t *hash_bytes, -- const EVP_MD *(**func)(void)) -+pkinit_alg_values(krb5_context context, const krb5_data *alg_id, -+ size_t *hash_bytes, const EVP_MD *(**func)(void), -+ char **hash_name) - { - *hash_bytes = 0; - *func = NULL; -@@ -2311,18 +2318,21 @@ pkinit_alg_values(krb5_context context, - krb5_pkinit_sha1_oid_len))) { - *hash_bytes = 20; - *func = &EVP_sha1; -+ *hash_name = strdup("SHA1"); - return 0; - } else if ((alg_id->length == krb5_pkinit_sha256_oid_len) && - (0 == memcmp(alg_id->data, krb5_pkinit_sha256_oid, - krb5_pkinit_sha256_oid_len))) { - *hash_bytes = 32; - *func = &EVP_sha256; -+ *hash_name = strdup("SHA256"); - return 0; - } else if ((alg_id->length == krb5_pkinit_sha512_oid_len) && - (0 == memcmp(alg_id->data, krb5_pkinit_sha512_oid, - krb5_pkinit_sha512_oid_len))) { - *hash_bytes = 64; - *func = &EVP_sha512; -+ *hash_name = strdup("SHA512"); - return 0; - } else { - krb5_set_error_message(context, KRB5_ERR_BAD_S2K_PARAMS, -@@ -2331,11 +2341,60 @@ pkinit_alg_values(krb5_context context, - } - } /* pkinit_alg_values() */ - -+#ifdef HAVE_EVP_KDF_FETCH -+static krb5_error_code -+openssl_sskdf(krb5_context context, size_t hash_bytes, krb5_data *key, -+ krb5_data *info, char *out, size_t out_len, char *digest) -+{ -+ krb5_error_code ret; -+ EVP_KDF *kdf = NULL; -+ EVP_KDF_CTX *kctx = NULL; -+ OSSL_PARAM params[4]; -+ size_t i = 0; - --/* pkinit_alg_agility_kdf() -- -- * This function generates a key using the KDF described in -- * draft_ietf_krb_wg_pkinit_alg_agility-04.txt. The algorithm is -- * described as follows: -+ if (digest == NULL) { -+ ret = oerr(context, ENOMEM, -+ _("Failed to allocate space for digest algorithm name")); -+ goto done; -+ } -+ -+ kdf = EVP_KDF_fetch(NULL, "SSKDF", NULL); -+ if (kdf == NULL) { -+ ret = oerr(context, KRB5_CRYPTO_INTERNAL, _("Failed to fetch SSKDF")); -+ goto done; -+ } -+ -+ kctx = EVP_KDF_CTX_new(kdf); -+ if (!kctx) { -+ ret = oerr(context, KRB5_CRYPTO_INTERNAL, -+ _("Failed to instantiate SSKDF")); -+ goto done; -+ } -+ -+ params[i++] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, -+ digest, 0); -+ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, -+ key->data, key->length); -+ params[i++] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO, -+ info->data, info->length); -+ params[i] = OSSL_PARAM_construct_end(); -+ if (EVP_KDF_derive(kctx, (unsigned char *)out, out_len, params) <= 0) { -+ ret = oerr(context, KRB5_CRYPTO_INTERNAL, -+ _("Failed to derive key using SSKDF")); -+ goto done; -+ } -+ -+ ret = 0; -+done: -+ EVP_KDF_free(kdf); -+ EVP_KDF_CTX_free(kctx); -+ return ret; -+} -+#else -+/* -+ * Generate a key using the KDF described in RFC 8636, also known as SSKDF -+ * (single-step kdf). Our caller precomputes `reps`, but otherwise the -+ * algorithm is as follows: - * - * 1. reps = keydatalen (K) / hash length (H) - * -@@ -2349,95 +2408,16 @@ pkinit_alg_values(krb5_context context, - * - * 4. Set key = Hash1 || Hash2 || ... so that length of key is K bytes. - */ --krb5_error_code --pkinit_alg_agility_kdf(krb5_context context, -- krb5_data *secret, -- krb5_data *alg_oid, -- krb5_const_principal party_u_info, -- krb5_const_principal party_v_info, -- krb5_enctype enctype, -- krb5_data *as_req, -- krb5_data *pk_as_rep, -- krb5_keyblock *key_block) -+static krb5_error_code -+builtin_sskdf(krb5_context context, unsigned int reps, size_t hash_len, -+ const EVP_MD *(*EVP_func)(void), krb5_data *secret, -+ krb5_data *other_info, char *out, size_t out_len) - { -- krb5_error_code retval = 0; -+ krb5_error_code ret = 0; - -- unsigned int reps = 0; -- uint32_t counter = 1; /* Does this type work on Windows? */ -+ uint32_t counter = 1; - size_t offset = 0; -- size_t hash_len = 0; -- size_t rand_len = 0; -- size_t key_len = 0; -- krb5_data random_data; -- krb5_sp80056a_other_info other_info_fields; -- krb5_pkinit_supp_pub_info supp_pub_info_fields; -- krb5_data *other_info = NULL; -- krb5_data *supp_pub_info = NULL; -- krb5_algorithm_identifier alg_id; - EVP_MD_CTX *ctx = NULL; -- const EVP_MD *(*EVP_func)(void); -- -- /* initialize random_data here to make clean-up safe */ -- random_data.length = 0; -- random_data.data = NULL; -- -- /* allocate and initialize the key block */ -- key_block->magic = 0; -- key_block->enctype = enctype; -- if (0 != (retval = krb5_c_keylengths(context, enctype, &rand_len, -- &key_len))) -- goto cleanup; -- -- random_data.length = rand_len; -- key_block->length = key_len; -- -- if (NULL == (key_block->contents = malloc(key_block->length))) { -- retval = ENOMEM; -- goto cleanup; -- } -- -- memset (key_block->contents, 0, key_block->length); -- -- /* If this is anonymous pkinit, use the anonymous principle for party_u_info */ -- if (party_u_info && krb5_principal_compare_any_realm(context, party_u_info, -- krb5_anonymous_principal())) -- party_u_info = (krb5_principal)krb5_anonymous_principal(); -- -- if (0 != (retval = pkinit_alg_values(context, alg_oid, &hash_len, &EVP_func))) -- goto cleanup; -- -- /* 1. reps = keydatalen (K) / hash length (H) */ -- reps = key_block->length/hash_len; -- -- /* ... and round up, if necessary */ -- if (key_block->length > (reps * hash_len)) -- reps++; -- -- /* Allocate enough space in the random data buffer to hash directly into -- * it, even if the last hash will make it bigger than the key length. */ -- if (NULL == (random_data.data = malloc(reps * hash_len))) { -- retval = ENOMEM; -- goto cleanup; -- } -- -- /* Encode the ASN.1 octet string for "SuppPubInfo" */ -- supp_pub_info_fields.enctype = enctype; -- supp_pub_info_fields.as_req = *as_req; -- supp_pub_info_fields.pk_as_rep = *pk_as_rep; -- if (0 != ((retval = encode_krb5_pkinit_supp_pub_info(&supp_pub_info_fields, -- &supp_pub_info)))) -- goto cleanup; -- -- /* Now encode the ASN.1 octet string for "OtherInfo" */ -- memset(&alg_id, 0, sizeof alg_id); -- alg_id.algorithm = *alg_oid; /*alias*/ -- -- other_info_fields.algorithm_identifier = alg_id; -- other_info_fields.party_u_info = (krb5_principal) party_u_info; -- other_info_fields.party_v_info = (krb5_principal) party_v_info; -- other_info_fields.supp_pub_info = *supp_pub_info; -- if (0 != (retval = encode_krb5_sp80056a_other_info(&other_info_fields, &other_info))) -- goto cleanup; - - /* 2. Initialize a 32-bit, big-endian bit string counter as 1. - * 3. For i = 1 to reps by 1, do the following: -@@ -2450,7 +2430,7 @@ pkinit_alg_agility_kdf(krb5_context context, - - ctx = EVP_MD_CTX_new(); - if (ctx == NULL) { -- retval = KRB5_CRYPTO_INTERNAL; -+ ret = KRB5_CRYPTO_INTERNAL; - goto cleanup; - } - -@@ -2458,7 +2438,7 @@ pkinit_alg_agility_kdf(krb5_context context, - if (!EVP_DigestInit(ctx, EVP_func())) { - krb5_set_error_message(context, KRB5_CRYPTO_INTERNAL, - "Call to OpenSSL EVP_DigestInit() returned an error."); -- retval = KRB5_CRYPTO_INTERNAL; -+ ret = KRB5_CRYPTO_INTERNAL; - goto cleanup; - } - -@@ -2467,15 +2447,16 @@ pkinit_alg_agility_kdf(krb5_context context, - !EVP_DigestUpdate(ctx, other_info->data, other_info->length)) { - krb5_set_error_message(context, KRB5_CRYPTO_INTERNAL, - "Call to OpenSSL EVP_DigestUpdate() returned an error."); -- retval = KRB5_CRYPTO_INTERNAL; -+ ret = KRB5_CRYPTO_INTERNAL; - goto cleanup; - } - -- /* 4. Set key = Hash1 || Hash2 || ... so that length of key is K bytes. */ -- if (!EVP_DigestFinal(ctx, (uint8_t *)random_data.data + offset, &s)) { -+ /* 4. Set key = Hash1 || Hash2 || ... so that length of key is K -+ * bytes. */ -+ if (!EVP_DigestFinal(ctx, (unsigned char *)out + offset, &s)) { - krb5_set_error_message(context, KRB5_CRYPTO_INTERNAL, - "Call to OpenSSL EVP_DigestUpdate() returned an error."); -- retval = KRB5_CRYPTO_INTERNAL; -+ ret = KRB5_CRYPTO_INTERNAL; - goto cleanup; - } - offset += s; -@@ -2484,26 +2465,113 @@ pkinit_alg_agility_kdf(krb5_context context, - EVP_MD_CTX_free(ctx); - ctx = NULL; - } -- -- retval = krb5_c_random_to_key(context, enctype, &random_data, -- key_block); -- - cleanup: - EVP_MD_CTX_free(ctx); -+ return ret; -+} /* builtin_sskdf() */ -+#endif /* HAVE_EVP_KDF_FETCH */ - -- /* If this has been an error, free the allocated key_block, if any */ -- if (retval) { -- krb5_free_keyblock_contents(context, key_block); -+/* id-pkinit-kdf family, as specified by RFC 8636. */ -+krb5_error_code -+pkinit_alg_agility_kdf(krb5_context context, krb5_data *secret, -+ krb5_data *alg_oid, krb5_const_principal party_u_info, -+ krb5_const_principal party_v_info, -+ krb5_enctype enctype, krb5_data *as_req, -+ krb5_data *pk_as_rep, krb5_keyblock *key_block) -+{ -+ krb5_error_code ret; -+ size_t hash_len = 0, rand_len = 0, key_len = 0; -+ const EVP_MD *(*EVP_func)(void); -+ krb5_sp80056a_other_info other_info_fields; -+ krb5_pkinit_supp_pub_info supp_pub_info_fields; -+ krb5_data *other_info = NULL, *supp_pub_info = NULL; -+ krb5_data random_data = empty_data(); -+ krb5_algorithm_identifier alg_id; -+ unsigned int reps; -+ char *hash_name = NULL; -+ -+ /* Allocate and initialize the key block. */ -+ key_block->magic = 0; -+ key_block->enctype = enctype; -+ -+ /* Use separate variables to avoid alignment restriction problems. */ -+ ret = krb5_c_keylengths(context, enctype, &rand_len, &key_len); -+ if (ret) -+ goto cleanup; -+ random_data.length = rand_len; -+ key_block->length = key_len; -+ -+ key_block->contents = k5calloc(key_block->length, 1, &ret); -+ if (key_block->contents == NULL) -+ goto cleanup; -+ -+ /* If this is anonymous pkinit, use the anonymous principle for -+ * party_u_info. */ -+ if (party_u_info && -+ krb5_principal_compare_any_realm(context, party_u_info, -+ krb5_anonymous_principal())) { -+ party_u_info = (krb5_principal)krb5_anonymous_principal(); - } - -- /* free other allocated resources, either way */ -- if (random_data.data) -- free(random_data.data); -+ ret = pkinit_alg_values(context, alg_oid, &hash_len, &EVP_func, -+ &hash_name); -+ if (ret) -+ goto cleanup; -+ -+ /* 1. reps = keydatalen (K) / hash length (H) */ -+ reps = key_block->length / hash_len; -+ -+ /* ... and round up, if necessary. */ -+ if (key_block->length > (reps * hash_len)) -+ reps++; -+ -+ /* Allocate enough space in the random data buffer to hash directly into -+ * it, even if the last hash will make it bigger than the key length. */ -+ random_data.data = k5alloc(reps * hash_len, &ret); -+ if (random_data.data == NULL) -+ goto cleanup; -+ -+ /* Encode the ASN.1 octet string for "SuppPubInfo". */ -+ supp_pub_info_fields.enctype = enctype; -+ supp_pub_info_fields.as_req = *as_req; -+ supp_pub_info_fields.pk_as_rep = *pk_as_rep; -+ ret = encode_krb5_pkinit_supp_pub_info(&supp_pub_info_fields, -+ &supp_pub_info); -+ if (ret) -+ goto cleanup; -+ -+ /* Now encode the ASN.1 octet string for "OtherInfo". */ -+ memset(&alg_id, 0, sizeof(alg_id)); -+ alg_id.algorithm = *alg_oid; -+ other_info_fields.algorithm_identifier = alg_id; -+ other_info_fields.party_u_info = (krb5_principal)party_u_info; -+ other_info_fields.party_v_info = (krb5_principal)party_v_info; -+ other_info_fields.supp_pub_info = *supp_pub_info; -+ ret = encode_krb5_sp80056a_other_info(&other_info_fields, &other_info); -+ if (ret) -+ goto cleanup; -+ -+#ifdef HAVE_EVP_KDF_FETCH -+ ret = openssl_sskdf(context, hash_len, secret, other_info, -+ random_data.data, key_block->length, hash_name); -+#else -+ ret = builtin_sskdf(context, reps, hash_len, EVP_func, secret, -+ other_info, random_data.data, key_block->length); -+#endif -+ if (ret) -+ goto cleanup; -+ -+ ret = krb5_c_random_to_key(context, enctype, &random_data, key_block); -+cleanup: -+ if (ret) -+ krb5_free_keyblock_contents(context, key_block); -+ -+ free(hash_name); -+ zapfree(random_data.data, random_data.length); - krb5_free_data(context, other_info); - krb5_free_data(context, supp_pub_info); -- -- return retval; --} /*pkinit_alg_agility_kdf() */ -+ return ret; -+} - - /* Call DH_compute_key() and ensure that we left-pad short results instead of - * leaving junk bytes at the end of the buffer. */ diff --git a/Use-SHA256-instead-of-SHA1-for-PKINIT-CMS-digest.patch b/Use-SHA256-instead-of-SHA1-for-PKINIT-CMS-digest.patch deleted file mode 100644 index ace4da9..0000000 --- a/Use-SHA256-instead-of-SHA1-for-PKINIT-CMS-digest.patch +++ /dev/null @@ -1,113 +0,0 @@ -From 538be893707e2306e89f5e5ca92c0db0ee305e3e Mon Sep 17 00:00:00 2001 -From: Julien Rische -Date: Fri, 11 Mar 2022 11:33:56 +0100 -Subject: [PATCH] Use SHA-256 instead of SHA-1 for PKINIT CMS digest - -Various organizations including NIST have been strongly recommending to -stop using SHA-1 for digital signatures for some years already. CMS -digest is used to generate such signatures, hence it should be upgraded -to use SHA-256. ---- - .../preauth/pkinit/pkinit_crypto_openssl.c | 27 ++++++++++--------- - 1 file changed, 14 insertions(+), 13 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 42e5c581d..2a6ef4aaa 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -1240,7 +1240,7 @@ cms_signeddata_create(krb5_context context, - /* will not fill-out EVP_PKEY because it's on the smartcard */ - - /* Set digest algs */ -- p7si->digest_alg->algorithm = OBJ_nid2obj(NID_sha1); -+ p7si->digest_alg->algorithm = OBJ_nid2obj(NID_sha256); - - if (p7si->digest_alg->parameter != NULL) - ASN1_TYPE_free(p7si->digest_alg->parameter); -@@ -1251,17 +1251,17 @@ cms_signeddata_create(krb5_context context, - /* Set sig algs */ - if (p7si->digest_enc_alg->parameter != NULL) - ASN1_TYPE_free(p7si->digest_enc_alg->parameter); -- p7si->digest_enc_alg->algorithm = OBJ_nid2obj(NID_sha1WithRSAEncryption); -+ p7si->digest_enc_alg->algorithm = OBJ_nid2obj(NID_sha256WithRSAEncryption); - if (!(p7si->digest_enc_alg->parameter = ASN1_TYPE_new())) - goto cleanup; - p7si->digest_enc_alg->parameter->type = V_ASN1_NULL; - - /* add signed attributes */ -- /* compute sha1 digest over the EncapsulatedContentInfo */ -+ /* compute sha256 digest over the EncapsulatedContentInfo */ - ctx = EVP_MD_CTX_new(); - if (ctx == NULL) - goto cleanup; -- EVP_DigestInit_ex(ctx, EVP_sha1(), NULL); -+ EVP_DigestInit_ex(ctx, EVP_sha256(), NULL); - EVP_DigestUpdate(ctx, data, data_len); - md_tmp = EVP_MD_CTX_md(ctx); - EVP_DigestFinal_ex(ctx, md_data, &md_len); -@@ -1289,9 +1289,10 @@ cms_signeddata_create(krb5_context context, - goto cleanup2; - - #ifndef WITHOUT_PKCS11 -- /* Some tokens can only do RSAEncryption without sha1 hash */ -- /* to compute sha1WithRSAEncryption, encode the algorithm ID for the hash -- * function and the hash value into an ASN.1 value of type DigestInfo -+ /* Some tokens can only do RSAEncryption without sha256 hash */ -+ /* to compute sha256WithRSAEncryption, encode the algorithm ID for the -+ * hash function and the hash value into an ASN.1 value of type -+ * DigestInfo - * DigestInfo::=SEQUENCE { - * digestAlgorithm AlgorithmIdentifier, - * digest OCTET STRING } -@@ -1310,7 +1311,7 @@ cms_signeddata_create(krb5_context context, - alg = X509_ALGOR_new(); - if (alg == NULL) - goto cleanup2; -- X509_ALGOR_set0(alg, OBJ_nid2obj(NID_sha1), V_ASN1_NULL, NULL); -+ X509_ALGOR_set0(alg, OBJ_nid2obj(NID_sha256), V_ASN1_NULL, NULL); - alg_len = i2d_X509_ALGOR(alg, NULL); - - digest = ASN1_OCTET_STRING_new(); -@@ -1339,7 +1340,7 @@ cms_signeddata_create(krb5_context context, - #endif - { - pkiDebug("mech = %s\n", -- id_cryptoctx->pkcs11_method == 1 ? "CKM_SHA1_RSA_PKCS" : "FS"); -+ id_cryptoctx->pkcs11_method == 1 ? "CKM_SHA256_RSA_PKCS" : "FS"); - retval = pkinit_sign_data(context, id_cryptoctx, abuf, alen, - &sig, &sig_len); - } -@@ -4189,7 +4190,7 @@ create_signature(unsigned char **sig, unsigned int *sig_len, - ctx = EVP_MD_CTX_new(); - if (ctx == NULL) - return ENOMEM; -- EVP_SignInit(ctx, EVP_sha1()); -+ EVP_SignInit(ctx, EVP_sha256()); - EVP_SignUpdate(ctx, data, data_len); - *sig_len = EVP_PKEY_size(pkey); - if ((*sig = malloc(*sig_len)) == NULL) -@@ -4663,10 +4664,10 @@ pkinit_get_certs_pkcs11(krb5_context context, - - #ifndef PKINIT_USE_MECH_LIST - /* -- * We'd like to use CKM_SHA1_RSA_PKCS for signing if it's available, but -+ * We'd like to use CKM_SHA256_RSA_PKCS for signing if it's available, but - * many cards seems to be confused about whether they are capable of - * this or not. The safe thing seems to be to ignore the mechanism list, -- * always use CKM_RSA_PKCS and calculate the sha1 digest ourselves. -+ * always use CKM_RSA_PKCS and calculate the sha256 digest ourselves. - */ - - id_cryptoctx->mech = CKM_RSA_PKCS; -@@ -4694,7 +4695,7 @@ pkinit_get_certs_pkcs11(krb5_context context, - if (mechp[i] == CKM_RSA_PKCS) { - /* This seems backwards... */ - id_cryptoctx->mech = -- (info.flags & CKF_SIGN) ? CKM_SHA1_RSA_PKCS : CKM_RSA_PKCS; -+ (info.flags & CKF_SIGN) ? CKM_SHA256_RSA_PKCS : CKM_RSA_PKCS; - } - } - free(mechp); --- -2.35.1 - diff --git a/Use-asan-in-one-of-the-CI-builds.patch b/Use-asan-in-one-of-the-CI-builds.patch deleted file mode 100644 index 4964d2f..0000000 --- a/Use-asan-in-one-of-the-CI-builds.patch +++ /dev/null @@ -1,22 +0,0 @@ -From 37e1fe755c6e976253a7f40ec7a9e740e4329789 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 21 Jun 2021 19:15:26 -0400 -Subject: [PATCH] Use asan in one of the CI builds - -(cherry picked from commit 7368354bcd0b58480a88b1fb81e63bd6aae7edf2) ---- - .github/workflows/build.yml | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml -index 8d1042b7b..06a35b7b9 100644 ---- a/.github/workflows/build.yml -+++ b/.github/workflows/build.yml -@@ -17,6 +17,7 @@ jobs: - os: ubuntu-18.04 - compiler: clang - makevars: CPPFLAGS=-Werror -+ configureopts: --enable-asan - - name: linux-clang-openssl - os: ubuntu-18.04 - compiler: clang diff --git a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch b/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch deleted file mode 100644 index 4a9f664..0000000 --- a/downstream-Use-backported-version-of-OpenSSL-3-KDF-i.patch +++ /dev/null @@ -1,752 +0,0 @@ -From 86d606e33439fd0511c5154be7f32b0df2c72e54 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 15 Nov 2019 20:05:16 +0000 -Subject: [PATCH] [downstream] Use backported version of OpenSSL-3 KDF - interface - -Last-updated: krb5-1.17 ---- - src/configure.ac | 4 + - src/lib/crypto/krb/derive.c | 356 +++++++++++++----- - .../preauth/pkinit/pkinit_crypto_openssl.c | 257 ++++++++----- - 3 files changed, 428 insertions(+), 189 deletions(-) - -diff --git a/src/configure.ac b/src/configure.ac -index 3e1052db7..ea708491b 100644 ---- a/src/configure.ac -+++ b/src/configure.ac -@@ -282,6 +282,10 @@ AC_SUBST(CRYPTO_IMPL) - AC_SUBST(CRYPTO_IMPL_CFLAGS) - AC_SUBST(CRYPTO_IMPL_LIBS) - -+AC_CHECK_FUNCS(EVP_KDF_CTX_new_id EVP_KDF_ctrl EVP_KDF_derive, -+ AC_DEFINE(OSSL_KDFS, 1, [Define if using OpenSSL KDFs]), -+ AC_MSG_ERROR([backported OpenSSL KDFs not found])) -+ - AC_ARG_WITH([prng-alg], - AC_HELP_STRING([--with-prng-alg=ALG], [use specified PRNG algorithm. @<:@fortuna@:>@]), - [PRNG_ALG=$withval -diff --git a/src/lib/crypto/krb/derive.c b/src/lib/crypto/krb/derive.c -index 6707a7308..915a173dd 100644 ---- a/src/lib/crypto/krb/derive.c -+++ b/src/lib/crypto/krb/derive.c -@@ -27,6 +27,13 @@ - - #include "crypto_int.h" - -+#ifdef OSSL_KDFS -+#include -+#include -+#else -+#error "Refusing to build without OpenSSL KDFs!" -+#endif -+ - static krb5_key - find_cached_dkey(struct derived_key *list, const krb5_data *constant) - { -@@ -77,55 +84,193 @@ cleanup: - return ENOMEM; - } - -+#ifdef OSSL_KDFS - static krb5_error_code --derive_random_rfc3961(const struct krb5_enc_provider *enc, -- krb5_key inkey, krb5_data *outrnd, -- const krb5_data *in_constant) -+openssl_kbdkf_counter_hmac(const struct krb5_hash_provider *hash, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *label, const krb5_data *context) - { -- size_t blocksize, keybytes, n; -+ krb5_error_code ret = KRB5_CRYPTO_INTERNAL; -+ EVP_KDF_CTX *ctx = NULL; -+ const EVP_MD *digest; -+ -+ if (!strcmp(hash->hash_name, "SHA1")) -+ digest = EVP_sha1(); -+ else if (!strcmp(hash->hash_name, "SHA-256")) -+ digest = EVP_sha256(); -+ else if (!strcmp(hash->hash_name, "SHA-384")) -+ digest = EVP_sha384(); -+ else -+ goto done; -+ -+ ctx = EVP_KDF_CTX_new_id(EVP_KDF_KB); -+ if (!ctx) -+ goto done; -+ -+ if (EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_MD, digest) != 1 || -+ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KB_MAC_TYPE, -+ EVP_KDF_KB_MAC_TYPE_HMAC) != 1 || -+ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KEY, inkey->keyblock.contents, -+ inkey->keyblock.length) != 1 || -+ (context->length > 0 && -+ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KB_INFO, context->data, -+ context->length) != 1) || -+ (label->length > 0 && -+ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_SALT, label->data, -+ label->length) != 1) || -+ EVP_KDF_derive(ctx, (unsigned char *)outrnd->data, -+ outrnd->length) != 1) -+ goto done; -+ -+ ret = 0; -+done: -+ if (ret) -+ zap(outrnd->data, outrnd->length); -+ EVP_KDF_CTX_free(ctx); -+ return ret; -+} -+ -+static krb5_error_code -+openssl_kbkdf_feedback_cmac(const struct krb5_enc_provider *enc, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *in_constant) -+{ -+ krb5_error_code ret = KRB5_CRYPTO_INTERNAL; -+ EVP_KDF_CTX *ctx = NULL; -+ const EVP_CIPHER *cipher; -+ static unsigned char zeroes[16]; -+ -+ memset(zeroes, 0, sizeof(zeroes)); -+ -+ if (enc->keylength == 16) -+ cipher = EVP_camellia_128_cbc(); -+ else if (enc->keylength == 32) -+ cipher = EVP_camellia_256_cbc(); -+ else -+ goto done; -+ -+ ctx = EVP_KDF_CTX_new_id(EVP_KDF_KB); -+ if (!ctx) -+ goto done; -+ -+ if (EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KB_MODE, -+ EVP_KDF_KB_MODE_FEEDBACK) != 1 || -+ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KB_MAC_TYPE, -+ EVP_KDF_KB_MAC_TYPE_CMAC) != 1 || -+ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_CIPHER, cipher) != 1 || -+ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KEY, inkey->keyblock.contents, -+ inkey->keyblock.length) != 1 || -+ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_SALT, in_constant->data, -+ in_constant->length) != 1 || -+ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KB_SEED, zeroes, -+ sizeof(zeroes)) != 1 || -+ EVP_KDF_derive(ctx, (unsigned char *)outrnd->data, -+ outrnd->length) != 1) -+ goto done; -+ -+ ret = 0; -+done: -+ if (ret) -+ zap(outrnd->data, outrnd->length); -+ EVP_KDF_CTX_free(ctx); -+ return ret; -+} -+ -+static krb5_error_code -+openssl_krb5kdf(const struct krb5_enc_provider *enc, krb5_key inkey, -+ krb5_data *outrnd, const krb5_data *in_constant) -+{ -+ krb5_error_code ret = KRB5_CRYPTO_INTERNAL; -+ EVP_KDF_CTX *ctx = NULL; -+ const EVP_CIPHER *cipher; -+ -+ if (inkey->keyblock.length != enc->keylength || -+ outrnd->length != enc->keybytes) { -+ return KRB5_CRYPTO_INTERNAL; -+ } -+ -+ if (enc->encrypt == krb5int_aes_encrypt && enc->keylength == 16) -+ cipher = EVP_aes_128_cbc(); -+ else if (enc->encrypt == krb5int_aes_encrypt && enc->keylength == 32) -+ cipher = EVP_aes_256_cbc(); -+ else if (enc->keylength == 24) -+ cipher = EVP_des_ede3_cbc(); -+ else -+ goto done; -+ -+ ctx = EVP_KDF_CTX_new_id(EVP_KDF_KRB5KDF); -+ if (ctx == NULL) -+ goto done; -+ -+ if (EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_CIPHER, cipher) != 1 || -+ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KEY, inkey->keyblock.contents, -+ inkey->keyblock.length) != 1 || -+ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KRB5KDF_CONSTANT, -+ in_constant->data, in_constant->length) != 1 || -+ EVP_KDF_derive(ctx, (unsigned char *)outrnd->data, -+ outrnd->length) != 1) -+ goto done; -+ -+ ret = 0; -+done: -+ if (ret) -+ zap(outrnd->data, outrnd->length); -+ EVP_KDF_CTX_free(ctx); -+ return ret; -+} -+ -+#else /* OSSL_KDFS */ -+ -+/* -+ * NIST SP800-108 KDF in counter mode (section 5.1). -+ * Parameters: -+ * - HMAC (with hash as the hash provider) is the PRF. -+ * - A block counter of four bytes is used. -+ * - Four bytes are used to encode the output length in the PRF input. -+ * -+ * There are no uses requiring more than a single PRF invocation. -+ */ -+static krb5_error_code -+builtin_sp800_108_counter_hmac(const struct krb5_hash_provider *hash, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *label, -+ const krb5_data *context) -+{ -+ krb5_crypto_iov iov[5]; - krb5_error_code ret; -- krb5_data block = empty_data(); -+ krb5_data prf; -+ unsigned char ibuf[4], lbuf[4]; - -- blocksize = enc->block_size; -- keybytes = enc->keybytes; -- -- if (blocksize == 1) -- return KRB5_BAD_ENCTYPE; -- if (inkey->keyblock.length != enc->keylength || outrnd->length != keybytes) -+ if (hash == NULL || outrnd->length > hash->hashsize) - return KRB5_CRYPTO_INTERNAL; - - /* Allocate encryption data buffer. */ -- ret = alloc_data(&block, blocksize); -+ ret = alloc_data(&prf, hash->hashsize); - if (ret) - return ret; - -- /* Initialize the input block. */ -- if (in_constant->length == blocksize) { -- memcpy(block.data, in_constant->data, blocksize); -- } else { -- krb5int_nfold(in_constant->length * 8, -- (unsigned char *) in_constant->data, -- blocksize * 8, (unsigned char *) block.data); -- } -+ /* [i]2: four-byte big-endian binary string giving the block counter (1) */ -+ iov[0].flags = KRB5_CRYPTO_TYPE_DATA; -+ iov[0].data = make_data(ibuf, sizeof(ibuf)); -+ store_32_be(1, ibuf); -+ /* Label */ -+ iov[1].flags = KRB5_CRYPTO_TYPE_DATA; -+ iov[1].data = *label; -+ /* 0x00: separator byte */ -+ iov[2].flags = KRB5_CRYPTO_TYPE_DATA; -+ iov[2].data = make_data("", 1); -+ /* Context */ -+ iov[3].flags = KRB5_CRYPTO_TYPE_DATA; -+ iov[3].data = *context; -+ /* [L]2: four-byte big-endian binary string giving the output length */ -+ iov[4].flags = KRB5_CRYPTO_TYPE_DATA; -+ iov[4].data = make_data(lbuf, sizeof(lbuf)); -+ store_32_be(outrnd->length * 8, lbuf); - -- /* Loop encrypting the blocks until enough key bytes are generated. */ -- n = 0; -- while (n < keybytes) { -- ret = encrypt_block(enc, inkey, &block); -- if (ret) -- goto cleanup; -- -- if ((keybytes - n) <= blocksize) { -- memcpy(outrnd->data + n, block.data, (keybytes - n)); -- break; -- } -- -- memcpy(outrnd->data + n, block.data, blocksize); -- n += blocksize; -- } -- --cleanup: -- zapfree(block.data, blocksize); -+ ret = krb5int_hmac(hash, inkey, iov, 5, &prf); -+ if (!ret) -+ memcpy(outrnd->data, prf.data, outrnd->length); -+ zapfree(prf.data, prf.length); - return ret; - } - -@@ -139,9 +284,9 @@ cleanup: - * - Four bytes are used to encode the output length in the PRF input. - */ - static krb5_error_code --derive_random_sp800_108_feedback_cmac(const struct krb5_enc_provider *enc, -- krb5_key inkey, krb5_data *outrnd, -- const krb5_data *in_constant) -+builtin_sp800_108_feedback_cmac(const struct krb5_enc_provider *enc, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *in_constant) - { - size_t blocksize, keybytes, n; - krb5_crypto_iov iov[6]; -@@ -204,56 +349,94 @@ cleanup: - return ret; - } - --/* -- * NIST SP800-108 KDF in counter mode (section 5.1). -- * Parameters: -- * - HMAC (with hash as the hash provider) is the PRF. -- * - A block counter of four bytes is used. -- * - Four bytes are used to encode the output length in the PRF input. -- * -- * There are no uses requiring more than a single PRF invocation. -- */ -+static krb5_error_code -+builtin_derive_random_rfc3961(const struct krb5_enc_provider *enc, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *in_constant) -+{ -+ size_t blocksize, keybytes, n; -+ krb5_error_code ret; -+ krb5_data block = empty_data(); -+ -+ blocksize = enc->block_size; -+ keybytes = enc->keybytes; -+ -+ if (blocksize == 1) -+ return KRB5_BAD_ENCTYPE; -+ if (inkey->keyblock.length != enc->keylength || outrnd->length != keybytes) -+ return KRB5_CRYPTO_INTERNAL; -+ -+ /* Allocate encryption data buffer. */ -+ ret = alloc_data(&block, blocksize); -+ if (ret) -+ return ret; -+ -+ /* Initialize the input block. */ -+ if (in_constant->length == blocksize) { -+ memcpy(block.data, in_constant->data, blocksize); -+ } else { -+ krb5int_nfold(in_constant->length * 8, -+ (unsigned char *) in_constant->data, -+ blocksize * 8, (unsigned char *) block.data); -+ } -+ -+ /* Loop encrypting the blocks until enough key bytes are generated. */ -+ n = 0; -+ while (n < keybytes) { -+ ret = encrypt_block(enc, inkey, &block); -+ if (ret) -+ goto cleanup; -+ -+ if ((keybytes - n) <= blocksize) { -+ memcpy(outrnd->data + n, block.data, (keybytes - n)); -+ break; -+ } -+ -+ memcpy(outrnd->data + n, block.data, blocksize); -+ n += blocksize; -+ } -+ -+cleanup: -+ zapfree(block.data, blocksize); -+ return ret; -+} -+#endif /* OSSL_KDFS */ -+ - krb5_error_code - k5_sp800_108_counter_hmac(const struct krb5_hash_provider *hash, - krb5_key inkey, krb5_data *outrnd, - const krb5_data *label, const krb5_data *context) - { -- krb5_crypto_iov iov[5]; -- krb5_error_code ret; -- krb5_data prf; -- unsigned char ibuf[4], lbuf[4]; -+#ifdef OSSL_KDFS -+ return openssl_kbdkf_counter_hmac(hash, inkey, outrnd, label, context); -+#else -+ return builtin_sp800_108_counter_hmac(hash, inkey, outrnd, label, -+ context); -+#endif -+} - -- if (hash == NULL || outrnd->length > hash->hashsize) -- return KRB5_CRYPTO_INTERNAL; -+static krb5_error_code -+k5_sp800_108_feedback_cmac(const struct krb5_enc_provider *enc, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *in_constant) -+{ -+#ifdef OSSL_KDFS -+ return openssl_kbkdf_feedback_cmac(enc, inkey, outrnd, in_constant); -+#else -+ return builtin_sp800_108_feedback_cmac(enc, inkey, outrnd, in_constant); -+#endif -+} - -- /* Allocate encryption data buffer. */ -- ret = alloc_data(&prf, hash->hashsize); -- if (ret) -- return ret; -- -- /* [i]2: four-byte big-endian binary string giving the block counter (1) */ -- iov[0].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[0].data = make_data(ibuf, sizeof(ibuf)); -- store_32_be(1, ibuf); -- /* Label */ -- iov[1].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[1].data = *label; -- /* 0x00: separator byte */ -- iov[2].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[2].data = make_data("", 1); -- /* Context */ -- iov[3].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[3].data = *context; -- /* [L]2: four-byte big-endian binary string giving the output length */ -- iov[4].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[4].data = make_data(lbuf, sizeof(lbuf)); -- store_32_be(outrnd->length * 8, lbuf); -- -- ret = krb5int_hmac(hash, inkey, iov, 5, &prf); -- if (!ret) -- memcpy(outrnd->data, prf.data, outrnd->length); -- zapfree(prf.data, prf.length); -- return ret; -+static krb5_error_code -+k5_derive_random_rfc3961(const struct krb5_enc_provider *enc, -+ krb5_key inkey, krb5_data *outrnd, -+ const krb5_data *in_constant) -+{ -+#ifdef OSSL_KDFS -+ return openssl_krb5kdf(enc, inkey, outrnd, in_constant); -+#else -+ return builtin_derive_random_rfc3961(enc, inkey, outrnd, in_constant); -+#endif - } - - krb5_error_code -@@ -266,10 +449,9 @@ krb5int_derive_random(const struct krb5_enc_provider *enc, - - switch (alg) { - case DERIVE_RFC3961: -- return derive_random_rfc3961(enc, inkey, outrnd, in_constant); -+ return k5_derive_random_rfc3961(enc, inkey, outrnd, in_constant); - case DERIVE_SP800_108_CMAC: -- return derive_random_sp800_108_feedback_cmac(enc, inkey, outrnd, -- in_constant); -+ return k5_sp800_108_feedback_cmac(enc, inkey, outrnd, in_constant); - case DERIVE_SP800_108_HMAC: - return k5_sp800_108_counter_hmac(hash, inkey, outrnd, in_constant, - &empty); -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index e1153344e..911e74fd9 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -38,6 +38,13 @@ - #include - #include - -+#ifdef OSSL_KDFS -+#include -+#include -+#else -+#error "Refusing to build without OpenSSL KDFs!" -+#endif -+ - static krb5_error_code pkinit_init_pkinit_oids(pkinit_plg_crypto_context ); - static void pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ); - -@@ -2331,11 +2338,51 @@ pkinit_alg_values(krb5_context context, - } - } /* pkinit_alg_values() */ - -+#ifdef OSSL_KDFS -+static krb5_error_code -+openssl_sskdf(krb5_context context, size_t hash_bytes, krb5_data *key, -+ krb5_data *info, char *out, size_t out_len) -+{ -+ krb5_error_code ret = KRB5_CRYPTO_INTERNAL; -+ EVP_KDF_CTX *ctx = NULL; -+ const EVP_MD *digest; - --/* pkinit_alg_agility_kdf() -- -- * This function generates a key using the KDF described in -- * draft_ietf_krb_wg_pkinit_alg_agility-04.txt. The algorithm is -- * described as follows: -+ /* RFC 8636 defines a SHA384 variant, but we don't use it. */ -+ if (hash_bytes == 20) { -+ digest = EVP_sha1(); -+ } else if (hash_bytes == 32) { -+ digest = EVP_sha256(); -+ } else if (hash_bytes == 64) { -+ digest = EVP_sha512(); -+ } else { -+ krb5_set_error_message(context, ret, "Bad hash type for SSKDF"); -+ goto done; -+ } -+ -+ ctx = EVP_KDF_CTX_new_id(EVP_KDF_SS); -+ if (!ctx) { -+ oerr(context, ret, _("Failed to instantiate SSKDF")); -+ goto done; -+ } -+ -+ if (EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_MD, digest) != 1 || -+ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_KEY, key->data, -+ key->length) != 1 || -+ EVP_KDF_ctrl(ctx, EVP_KDF_CTRL_SET_SSKDF_INFO, info->data, -+ info->length) != 1 || -+ EVP_KDF_derive(ctx, (unsigned char *)out, out_len) != 1) -+ goto done; -+ -+ ret = 0; -+done: -+ EVP_KDF_CTX_free(ctx); -+ return ret; -+} -+#else -+/* -+ * Generate a key using the KDF described in RFC 8636, also known as SSKDF -+ * (single-step kdf). Our caller precomputes `reps`, but otherwise the -+ * algorithm is as follows: - * - * 1. reps = keydatalen (K) / hash length (H) - * -@@ -2349,95 +2396,16 @@ pkinit_alg_values(krb5_context context, - * - * 4. Set key = Hash1 || Hash2 || ... so that length of key is K bytes. - */ --krb5_error_code --pkinit_alg_agility_kdf(krb5_context context, -- krb5_data *secret, -- krb5_data *alg_oid, -- krb5_const_principal party_u_info, -- krb5_const_principal party_v_info, -- krb5_enctype enctype, -- krb5_data *as_req, -- krb5_data *pk_as_rep, -- krb5_keyblock *key_block) -+static krb5_error_code -+builtin_sskdf(krb5_context context, unsigned int reps, size_t hash_len, -+ const EVP_MD *(*EVP_func)(void), krb5_data *secret, -+ krb5_data *other_info, char *out, size_t out_len) - { - krb5_error_code retval = 0; - -- unsigned int reps = 0; -- uint32_t counter = 1; /* Does this type work on Windows? */ -+ uint32_t counter = 1; - size_t offset = 0; -- size_t hash_len = 0; -- size_t rand_len = 0; -- size_t key_len = 0; -- krb5_data random_data; -- krb5_sp80056a_other_info other_info_fields; -- krb5_pkinit_supp_pub_info supp_pub_info_fields; -- krb5_data *other_info = NULL; -- krb5_data *supp_pub_info = NULL; -- krb5_algorithm_identifier alg_id; - EVP_MD_CTX *ctx = NULL; -- const EVP_MD *(*EVP_func)(void); -- -- /* initialize random_data here to make clean-up safe */ -- random_data.length = 0; -- random_data.data = NULL; -- -- /* allocate and initialize the key block */ -- key_block->magic = 0; -- key_block->enctype = enctype; -- if (0 != (retval = krb5_c_keylengths(context, enctype, &rand_len, -- &key_len))) -- goto cleanup; -- -- random_data.length = rand_len; -- key_block->length = key_len; -- -- if (NULL == (key_block->contents = malloc(key_block->length))) { -- retval = ENOMEM; -- goto cleanup; -- } -- -- memset (key_block->contents, 0, key_block->length); -- -- /* If this is anonymous pkinit, use the anonymous principle for party_u_info */ -- if (party_u_info && krb5_principal_compare_any_realm(context, party_u_info, -- krb5_anonymous_principal())) -- party_u_info = (krb5_principal)krb5_anonymous_principal(); -- -- if (0 != (retval = pkinit_alg_values(context, alg_oid, &hash_len, &EVP_func))) -- goto cleanup; -- -- /* 1. reps = keydatalen (K) / hash length (H) */ -- reps = key_block->length/hash_len; -- -- /* ... and round up, if necessary */ -- if (key_block->length > (reps * hash_len)) -- reps++; -- -- /* Allocate enough space in the random data buffer to hash directly into -- * it, even if the last hash will make it bigger than the key length. */ -- if (NULL == (random_data.data = malloc(reps * hash_len))) { -- retval = ENOMEM; -- goto cleanup; -- } -- -- /* Encode the ASN.1 octet string for "SuppPubInfo" */ -- supp_pub_info_fields.enctype = enctype; -- supp_pub_info_fields.as_req = *as_req; -- supp_pub_info_fields.pk_as_rep = *pk_as_rep; -- if (0 != ((retval = encode_krb5_pkinit_supp_pub_info(&supp_pub_info_fields, -- &supp_pub_info)))) -- goto cleanup; -- -- /* Now encode the ASN.1 octet string for "OtherInfo" */ -- memset(&alg_id, 0, sizeof alg_id); -- alg_id.algorithm = *alg_oid; /*alias*/ -- -- other_info_fields.algorithm_identifier = alg_id; -- other_info_fields.party_u_info = (krb5_principal) party_u_info; -- other_info_fields.party_v_info = (krb5_principal) party_v_info; -- other_info_fields.supp_pub_info = *supp_pub_info; -- if (0 != (retval = encode_krb5_sp80056a_other_info(&other_info_fields, &other_info))) -- goto cleanup; - - /* 2. Initialize a 32-bit, big-endian bit string counter as 1. - * 3. For i = 1 to reps by 1, do the following: -@@ -2471,8 +2439,9 @@ pkinit_alg_agility_kdf(krb5_context context, - goto cleanup; - } - -- /* 4. Set key = Hash1 || Hash2 || ... so that length of key is K bytes. */ -- if (!EVP_DigestFinal(ctx, (uint8_t *)random_data.data + offset, &s)) { -+ /* 4. Set key = Hash1 || Hash2 || ... so that length of key is K -+ * bytes. */ -+ if (!EVP_DigestFinal(ctx, (unsigned char *)out + offset, &s)) { - krb5_set_error_message(context, KRB5_CRYPTO_INTERNAL, - "Call to OpenSSL EVP_DigestUpdate() returned an error."); - retval = KRB5_CRYPTO_INTERNAL; -@@ -2484,26 +2453,110 @@ pkinit_alg_agility_kdf(krb5_context context, - EVP_MD_CTX_free(ctx); - ctx = NULL; - } -- -- retval = krb5_c_random_to_key(context, enctype, &random_data, -- key_block); -- - cleanup: - EVP_MD_CTX_free(ctx); -+ return retval; -+} /* builtin_sskdf() */ -+#endif /* OSSL_KDFS */ - -- /* If this has been an error, free the allocated key_block, if any */ -- if (retval) { -- krb5_free_keyblock_contents(context, key_block); -+/* id-pkinit-kdf family, as specified by RFC 8636. */ -+krb5_error_code -+pkinit_alg_agility_kdf(krb5_context context, krb5_data *secret, -+ krb5_data *alg_oid, krb5_const_principal party_u_info, -+ krb5_const_principal party_v_info, -+ krb5_enctype enctype, krb5_data *as_req, -+ krb5_data *pk_as_rep, krb5_keyblock *key_block) -+{ -+ krb5_error_code retval; -+ size_t hash_len = 0, rand_len = 0, key_len = 0; -+ const EVP_MD *(*EVP_func)(void); -+ krb5_sp80056a_other_info other_info_fields; -+ krb5_pkinit_supp_pub_info supp_pub_info_fields; -+ krb5_data *other_info = NULL, *supp_pub_info = NULL; -+ krb5_data random_data = empty_data(); -+ krb5_algorithm_identifier alg_id; -+ unsigned int reps; -+ -+ /* Allocate and initialize the key block. */ -+ key_block->magic = 0; -+ key_block->enctype = enctype; -+ -+ /* Use separate variables to avoid alignment restriction problems. */ -+ retval = krb5_c_keylengths(context, enctype, &rand_len, &key_len); -+ if (retval) -+ goto cleanup; -+ random_data.length = rand_len; -+ key_block->length = key_len; -+ -+ key_block->contents = k5calloc(key_block->length, 1, &retval); -+ if (key_block->contents == NULL) -+ goto cleanup; -+ -+ /* If this is anonymous pkinit, use the anonymous principle for -+ * party_u_info. */ -+ if (party_u_info && -+ krb5_principal_compare_any_realm(context, party_u_info, -+ krb5_anonymous_principal())) { -+ party_u_info = (krb5_principal)krb5_anonymous_principal(); - } - -- /* free other allocated resources, either way */ -- if (random_data.data) -- free(random_data.data); -+ retval = pkinit_alg_values(context, alg_oid, &hash_len, &EVP_func); -+ if (retval) -+ goto cleanup; -+ -+ /* 1. reps = keydatalen (K) / hash length (H) */ -+ reps = key_block->length / hash_len; -+ -+ /* ... and round up, if necessary. */ -+ if (key_block->length > (reps * hash_len)) -+ reps++; -+ -+ /* Allocate enough space in the random data buffer to hash directly into -+ * it, even if the last hash will make it bigger than the key length. */ -+ random_data.data = k5alloc(reps * hash_len, &retval); -+ if (random_data.data == NULL) -+ goto cleanup; -+ -+ /* Encode the ASN.1 octet string for "SuppPubInfo". */ -+ supp_pub_info_fields.enctype = enctype; -+ supp_pub_info_fields.as_req = *as_req; -+ supp_pub_info_fields.pk_as_rep = *pk_as_rep; -+ retval = encode_krb5_pkinit_supp_pub_info(&supp_pub_info_fields, -+ &supp_pub_info); -+ if (retval) -+ goto cleanup; -+ -+ /* Now encode the ASN.1 octet string for "OtherInfo". */ -+ memset(&alg_id, 0, sizeof(alg_id)); -+ alg_id.algorithm = *alg_oid; -+ other_info_fields.algorithm_identifier = alg_id; -+ other_info_fields.party_u_info = (krb5_principal)party_u_info; -+ other_info_fields.party_v_info = (krb5_principal)party_v_info; -+ other_info_fields.supp_pub_info = *supp_pub_info; -+ retval = encode_krb5_sp80056a_other_info(&other_info_fields, &other_info); -+ if (retval) -+ goto cleanup; -+ -+#ifdef OSSL_KDFS -+ retval = openssl_sskdf(context, hash_len, secret, other_info, -+ random_data.data, key_block->length); -+#else -+ retval = builtin_sskdf(context, reps, hash_len, EVP_func, secret, -+ other_info, random_data.data, key_block->length); -+#endif -+ if (retval) -+ goto cleanup; -+ -+ retval = krb5_c_random_to_key(context, enctype, &random_data, key_block); -+cleanup: -+ if (retval) -+ krb5_free_keyblock_contents(context, key_block); -+ -+ zapfree(random_data.data, random_data.length); - krb5_free_data(context, other_info); - krb5_free_data(context, supp_pub_info); -- - return retval; --} /*pkinit_alg_agility_kdf() */ -+} - - /* Call DH_compute_key() and ensure that we left-pad short results instead of - * leaving junk bytes at the end of the buffer. */ diff --git a/krb5-krad-larger-attrs.patch b/krb5-krad-larger-attrs.patch deleted file mode 100644 index 32111ec..0000000 --- a/krb5-krad-larger-attrs.patch +++ /dev/null @@ -1,69 +0,0 @@ -From f35077bfc570205092eca2a9d44e50ce265622f4 Mon Sep 17 00:00:00 2001 -From: Sumit Bose -Date: Mon, 8 Nov 2021 17:48:50 +0100 -Subject: [PATCH] Support larger RADIUS attributes in libkrad - -In kr_attrset_decode(), explicitly treat the length byte as unsigned. -Otherwise attributes longer than 125 characters will be rejected with -EBADMSG. - -Add a 253-character-long NAS-Identifier attribute to the tests to make -sure that attributes with the maximal number of characters are working -as expected. - -[ghudson@mit.edu: used uint8_t cast per current practices; edited -commit message] - -ticket: 9036 (new) ---- - src/lib/krad/attrset.c | 2 +- - src/lib/krad/t_packet.c | 13 +++++++++++++ - 2 files changed, 14 insertions(+), 1 deletion(-) - -diff --git a/src/lib/krad/attrset.c b/src/lib/krad/attrset.c -index 03c613716..f309f1581 100644 ---- a/src/lib/krad/attrset.c -+++ b/src/lib/krad/attrset.c -@@ -217,7 +217,7 @@ kr_attrset_decode(krb5_context ctx, const krb5_data *in, const char *secret, - - for (i = 0; i + 2 < in->length; ) { - type = in->data[i++]; -- tmp = make_data(&in->data[i + 1], in->data[i] - 2); -+ tmp = make_data(&in->data[i + 1], (uint8_t)in->data[i] - 2); - i += tmp.length + 1; - - retval = (in->length < i) ? EBADMSG : 0; -diff --git a/src/lib/krad/t_packet.c b/src/lib/krad/t_packet.c -index 0a92e9cc2..c22489144 100644 ---- a/src/lib/krad/t_packet.c -+++ b/src/lib/krad/t_packet.c -@@ -57,6 +57,14 @@ make_packet(krb5_context ctx, const krb5_data *username, - krb5_error_code retval; - const krb5_data *data; - int i = 0; -+ krb5_data nas_id; -+ -+ nas_id = string2data("12345678901234567890123456789012345678901234567890" -+ "12345678901234567890123456789012345678901234567890" -+ "12345678901234567890123456789012345678901234567890" -+ "12345678901234567890123456789012345678901234567890" -+ "12345678901234567890123456789012345678901234567890" -+ "123"); - - retval = krad_attrset_new(ctx, &set); - if (retval != 0) -@@ -71,6 +79,11 @@ make_packet(krb5_context ctx, const krb5_data *username, - if (retval != 0) - goto out; - -+ retval = krad_attrset_add(set, krad_attr_name2num("NAS-Identifier"), -+ &nas_id); -+ if (retval != 0) -+ goto out; -+ - retval = krad_packet_new_request(ctx, "foo", - krad_code_name2num("Access-Request"), - set, iterator, &i, &tmp); --- -2.35.1 - diff --git a/krb5-krad-remote.patch b/krb5-krad-remote.patch deleted file mode 100644 index 42452ff..0000000 --- a/krb5-krad-remote.patch +++ /dev/null @@ -1,209 +0,0 @@ -From ce160f8826bae223876a6527a731c36b6912db15 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Tue, 9 Nov 2021 13:00:43 -0500 -Subject: [PATCH 1/2] Avoid use after free during libkrad cleanup - -libkrad client requests contain a list of references to remotes, with -no back-references or reference counts. To prevent accesses to -dangling references during cleanup, cancel all requests on all remotes -before freeing any remotes. - -Remove the code for aging out unused servers. This code was fairly -safe as all requests referencing a remote should have completed or -timed out during an hour of disuse, but in the current design we have -no way to guarantee or check that. The set of addresses we send -RADIUS requests to will generally be small, so aging out servers is -unnecessary. - -ticket: 9035 (new) ---- - src/lib/krad/client.c | 42 ++++++++++++++--------------------------- - src/lib/krad/internal.h | 4 ++++ - src/lib/krad/remote.c | 11 ++++++++--- - 3 files changed, 26 insertions(+), 31 deletions(-) - -diff --git a/src/lib/krad/client.c b/src/lib/krad/client.c -index 6365dd1c6..810940afc 100644 ---- a/src/lib/krad/client.c -+++ b/src/lib/krad/client.c -@@ -64,7 +64,6 @@ struct request_st { - - struct server_st { - krad_remote *serv; -- time_t last; - K5_LIST_ENTRY(server_st) list; - }; - -@@ -81,15 +80,10 @@ get_server(krad_client *rc, const struct addrinfo *ai, const char *secret, - krad_remote **out) - { - krb5_error_code retval; -- time_t currtime; - server *srv; - -- if (time(&currtime) == (time_t)-1) -- return errno; -- - K5_LIST_FOREACH(srv, &rc->servers, list) { - if (kr_remote_equals(srv->serv, ai, secret)) { -- srv->last = currtime; - *out = srv->serv; - return 0; - } -@@ -98,7 +92,6 @@ get_server(krad_client *rc, const struct addrinfo *ai, const char *secret, - srv = calloc(1, sizeof(server)); - if (srv == NULL) - return ENOMEM; -- srv->last = currtime; - - retval = kr_remote_new(rc->kctx, rc->vctx, ai, secret, &srv->serv); - if (retval != 0) { -@@ -173,28 +166,12 @@ request_new(krad_client *rc, krad_code code, const krad_attrset *attrs, - return 0; - } - --/* Close remotes that haven't been used in a while. */ --static void --age(struct server_head *head, time_t currtime) --{ -- server *srv, *tmp; -- -- K5_LIST_FOREACH_SAFE(srv, head, list, tmp) { -- if (currtime == (time_t)-1 || currtime - srv->last > 60 * 60) { -- K5_LIST_REMOVE(srv, list); -- kr_remote_free(srv->serv); -- free(srv); -- } -- } --} -- - /* Handle a response from a server (or related errors). */ - static void - on_response(krb5_error_code retval, const krad_packet *reqp, - const krad_packet *rspp, void *data) - { - request *req = data; -- time_t currtime; - size_t i; - - /* Do nothing if we are already completed. */ -@@ -221,10 +198,6 @@ on_response(krb5_error_code retval, const krad_packet *reqp, - for (i = 0; req->remotes[i].remote != NULL; i++) - kr_remote_cancel(req->remotes[i].remote, req->remotes[i].packet); - -- /* Age out servers that haven't been used in a while. */ -- if (time(&currtime) != (time_t)-1) -- age(&req->rc->servers, currtime); -- - request_free(req); - } - -@@ -247,10 +220,23 @@ krad_client_new(krb5_context kctx, verto_ctx *vctx, krad_client **out) - void - krad_client_free(krad_client *rc) - { -+ server *srv; -+ - if (rc == NULL) - return; - -- age(&rc->servers, -1); -+ /* Cancel all requests before freeing any remotes, since each request's -+ * callback data may contain references to multiple remotes. */ -+ K5_LIST_FOREACH(srv, &rc->servers, list) -+ kr_remote_cancel_all(srv->serv); -+ -+ while (!K5_LIST_EMPTY(&rc->servers)) { -+ srv = K5_LIST_FIRST(&rc->servers); -+ K5_LIST_REMOVE(srv, list); -+ kr_remote_free(srv->serv); -+ free(srv); -+ } -+ - free(rc); - } - -diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h -index 0143d155a..7619563fc 100644 ---- a/src/lib/krad/internal.h -+++ b/src/lib/krad/internal.h -@@ -109,6 +109,10 @@ kr_remote_send(krad_remote *rr, krad_code code, krad_attrset *attrs, - void - kr_remote_cancel(krad_remote *rr, const krad_packet *pkt); - -+/* Cancel all requests awaiting responses. */ -+void -+kr_remote_cancel_all(krad_remote *rr); -+ - /* Determine if this remote object refers to the remote resource identified - * by the addrinfo struct and the secret. */ - krb5_boolean -diff --git a/src/lib/krad/remote.c b/src/lib/krad/remote.c -index 7e491e994..06ae751bc 100644 ---- a/src/lib/krad/remote.c -+++ b/src/lib/krad/remote.c -@@ -421,15 +421,20 @@ error: - return retval; - } - -+void -+kr_remote_cancel_all(krad_remote *rr) -+{ -+ while (!K5_TAILQ_EMPTY(&rr->list)) -+ request_finish(K5_TAILQ_FIRST(&rr->list), ECANCELED, NULL); -+} -+ - void - kr_remote_free(krad_remote *rr) - { - if (rr == NULL) - return; - -- while (!K5_TAILQ_EMPTY(&rr->list)) -- request_finish(K5_TAILQ_FIRST(&rr->list), ECANCELED, NULL); -- -+ kr_remote_cancel_all(rr); - free(rr->secret); - if (rr->info != NULL) - free(rr->info->ai_addr); --- -2.35.1 - - -From e0084425df784952e76b3bcc8ae9d08300234733 Mon Sep 17 00:00:00 2001 -From: Sumit Bose -Date: Mon, 8 Nov 2021 17:47:17 +0100 -Subject: [PATCH 2/2] More python3 fixes for t_daemon.py - -[ghudson@mit.edu: use a list comprehension instead of map()] ---- - src/lib/krad/t_daemon.py | 6 +++--- - 1 file changed, 3 insertions(+), 3 deletions(-) - -diff --git a/src/lib/krad/t_daemon.py b/src/lib/krad/t_daemon.py -index 7668cd7f8..4a3de079c 100755 ---- a/src/lib/krad/t_daemon.py -+++ b/src/lib/krad/t_daemon.py -@@ -50,7 +50,7 @@ class TestServer(server.Server): - - for key in pkt.keys(): - if key == "User-Password": -- passwd = map(pkt.PwDecrypt, pkt[key]) -+ passwd = [pkt.PwDecrypt(x) for x in pkt[key]] - - reply = self.CreateReplyPacket(pkt) - if passwd == ['accept']: -@@ -61,8 +61,8 @@ class TestServer(server.Server): - - srv = TestServer(addresses=["localhost"], - hosts={"127.0.0.1": -- server.RemoteHost("127.0.0.1", "foo", "localhost")}, -- dict=dictionary.Dictionary(StringIO.StringIO(DICTIONARY))) -+ server.RemoteHost("127.0.0.1", b"foo", "localhost")}, -+ dict=dictionary.Dictionary(StringIO(DICTIONARY))) - - # Write a sentinel character to let the parent process know we're listening. - sys.stdout.write("~") --- -2.35.1 - diff --git a/krb5.spec b/krb5.spec index c6039dc..b14c9c9 100644 --- a/krb5.spec +++ b/krb5.spec @@ -34,7 +34,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 13 +%global baserelease 0.1 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -46,9 +46,9 @@ %endif %global krb5_version_major 1 -%global krb5_version_minor 19 +%global krb5_version_minor 20 # For a release without a patch number set to %%nil -%global krb5_version_patch 2 +%global krb5_version_patch 1 %global krb5_version_major_minor %{krb5_version_major}.%{krb5_version_minor} %global krb5_version %{krb5_version_major_minor} @@ -68,59 +68,29 @@ Release: %{krb5_release}%{?dist} Source0: https://web.mit.edu/kerberos/dist/krb5/%{krb5_version_major_minor}/krb5-%{krb5_version}%{?krb5_pre_release}.tar.gz Source1: https://web.mit.edu/kerberos/dist/krb5/%{krb5_version_major_minor}/krb5-%{krb5_version}%{?krb5_pre_release}.tar.gz.asc -# Numbering is a relic of old init systems etc. It's easiest to just leave. Source2: kprop.service -Source4: kadmin.service -Source5: krb5kdc.service -Source6: krb5.conf -Source10: kdc.conf -Source11: kadm5.acl -Source19: krb5kdc.sysconfig -Source20: kadmin.sysconfig -Source21: kprop.sysconfig -Source29: ksu.pamd -Source33: krb5kdc.logrotate -Source34: kadmind.logrotate -Source39: krb5-krb5kdc.conf +Source3: kadmin.service +Source4: krb5kdc.service +Source5: krb5.conf +Source6: kdc.conf +Source7: kadm5.acl +Source8: krb5kdc.sysconfig +Source9: kadmin.sysconfig +Source10: kprop.sysconfig +Source11: ksu.pamd +Source12: krb5kdc.logrotate +Source13: kadmind.logrotate +Source14: krb5-krb5kdc.conf -Patch0: downstream-ksu-pam-integration.patch -Patch1: downstream-SELinux-integration.patch -Patch4: downstream-fix-debuginfo-with-y.tab.c.patch -Patch5: downstream-Remove-3des-support.patch -Patch7: downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch -Patch8: Add-APIs-for-marshalling-credentials.patch -Patch9: Add-hostname-canonicalization-helper-to-k5test.py.patch -Patch10: Support-host-based-GSS-initiator-names.patch -Patch11: Add-KCM_OP_GET_CRED_LIST-for-faster-iteration.patch -Patch12: Fix-KCM-flag-transmission-for-remove_cred.patch -Patch13: Make-KCM-iteration-fallback-work-with-sssd-kcm.patch -Patch14: Use-KCM_OP_RETRIEVE-in-KCM-client.patch -Patch15: Fix-KCM-retrieval-support-for-sssd.patch -Patch17: Move-some-dejagnu-kadmin-tests-to-Python-tests.patch -Patch18: Fix-some-principal-realm-canonicalization-cases.patch -Patch19: Allow-kinit-with-keytab-to-defer-canonicalization.patch -Patch20: Fix-kadmin-k-with-fallback-or-referral-realm.patch -Patch21: Fix-softpkcs11-build-issues-with-openssl-3.0.patch -Patch22: Remove-deprecated-OpenSSL-calls-from-softpkcs11.patch -Patch23: Fix-k5tls-module-for-OpenSSL-3.patch -Patch24: Fix-leaks-on-error-in-kadm5-init-functions.patch -Patch25: Clean-up-context-after-failed-open-in-libkdb5.patch -Patch26: Use-asan-in-one-of-the-CI-builds.patch -Patch29: Clean-up-gssapi_krb5-ccache-name-functions.patch -Patch30: Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch -Patch32: Add-buildsystem-detection-of-the-OpenSSL-3-KDF-inter.patch -Patch33: Use-OpenSSL-s-SSKDF-in-PKINIT-when-available.patch -Patch34: Use-OpenSSL-s-KBKDF-and-KRB5KDF-for-deriving-long-te.patch -Patch35: Handle-OpenSSL-3-s-providers.patch -Patch36: Remove-TCL-based-libkadm5-API-tests.patch -Patch37: Use-SHA256-instead-of-SHA1-for-PKINIT-CMS-digest.patch -Patch38: krb5-krad-remote.patch -Patch39: krb5-krad-larger-attrs.patch -Patch40: Try-harder-to-avoid-password-change-replay-errors.patch -Patch41: Add-configure-variable-for-default-PKCS-11-module.patch -Patch42: downstream-Allow-krad-UDP-TCP-localhost-connection-with-FIPS.patch -Patch43: Read-GSS-configuration-files-with-mtime-0.patch -Patch44: Fix-integer-overflows-in-PAC-parsing.patch +Patch1: 0001-downstream-ksu-pam-integration.patch +Patch2: 0002-downstream-SELinux-integration.patch +Patch3: 0003-downstream-fix-debuginfo-with-y.tab.c.patch +Patch4: 0004-downstream-Remove-3des-support.patch +Patch5: 0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +Patch6: 0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch +Patch7: 0007-Add-configure-variable-for-default-PKCS-11-module.patch +Patch8: 0008-Set-reasonable-supportedCMSTypes-in-PKINIT.patch +Patch9: 0009-Simplify-plugin-loading-code.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -153,8 +123,14 @@ BuildRequires: procps-ng BuildRequires: resolv_wrapper %endif +%if 0%{?fedora} > 35 # Need KDFs. This is the "real" version BuildRequires: openssl-devel => 1:3.0.0 +%else +# Need KDFs. This is the backported version +BuildRequires: openssl-devel >= 1:1.1.1d-4 +BuildRequires: openssl-devel < 1:3.0.0 +%endif %description Kerberos V5 is a trusted-third-party network authentication system, @@ -180,7 +156,12 @@ to install this package. %package libs Summary: The non-admin shared libraries used by Kerberos 5 +%if 0%{?fedora} > 35 Requires: openssl-libs >= 1:3.0.0 +%else +Requires: openssl-libs >= 1:1.1.1d-4 +Requires: openssl-libs < 1:3.0.0 +%endif Requires: coreutils, gawk, sed Requires: keyutils-libs >= 1.5.8 Requires: /etc/crypto-policies/back-ends/krb5.config @@ -296,6 +277,13 @@ PORT=`expr 7777 + $LONG_BIT - 48` sed -i -e s,7777,`expr "$PORT" + 0`,g $cfg sed -i -e s,7778,`expr "$PORT" + 1`,g $cfg +# Fix kadmind port hard-coded in tests +PORT=`expr 61000 + $LONG_BIT - 48` +sed -i -e \ + "s,params.kadmind_port = 61001;,params.kadmind_port = $((PORT + 1));," \ + src/lib/kadm5/t_kadm5.c + + %build # Go ahead and supply tcl info, because configure doesn't know how to find it. source %{_libdir}/tclConfig.sh @@ -379,15 +367,15 @@ popd # Sample KDC config files (bundled kdc.conf and kadm5.acl). mkdir -p $RPM_BUILD_ROOT%{_var}/kerberos/krb5kdc -install -pm 600 %{SOURCE10} $RPM_BUILD_ROOT%{_var}/kerberos/krb5kdc/ -install -pm 600 %{SOURCE11} $RPM_BUILD_ROOT%{_var}/kerberos/krb5kdc/ +install -pm 600 %{SOURCE6} $RPM_BUILD_ROOT%{_var}/kerberos/krb5kdc/ +install -pm 600 %{SOURCE7} $RPM_BUILD_ROOT%{_var}/kerberos/krb5kdc/ # Where per-user keytabs live by default. mkdir -p $RPM_BUILD_ROOT%{_var}/kerberos/krb5/user # Default configuration file for everything. mkdir -p $RPM_BUILD_ROOT/etc -install -pm 644 %{SOURCE6} $RPM_BUILD_ROOT/etc/krb5.conf +install -pm 644 %{SOURCE5} $RPM_BUILD_ROOT/etc/krb5.conf # Default include on this directory mkdir -p $RPM_BUILD_ROOT/etc/krb5.conf.d @@ -407,16 +395,16 @@ mkdir -m 755 -p $RPM_BUILD_ROOT/etc/gss/mech.d export DEFCCNAME="%{configured_default_ccache_name}" awk '{print} /^# default_realm/{print " default_ccache_name =", ENVIRON["DEFCCNAME"]}' \ - %{SOURCE6} > $RPM_BUILD_ROOT/etc/krb5.conf -touch -r %{SOURCE6} $RPM_BUILD_ROOT/etc/krb5.conf + %{SOURCE5} > $RPM_BUILD_ROOT/etc/krb5.conf +touch -r %{SOURCE5} $RPM_BUILD_ROOT/etc/krb5.conf grep default_ccache_name $RPM_BUILD_ROOT/etc/krb5.conf %endif # Server init scripts (krb5kdc,kadmind,kpropd) and their sysconfig files. mkdir -p $RPM_BUILD_ROOT%{_unitdir} for unit in \ - %{SOURCE5}\ - %{SOURCE4} \ + %{SOURCE4}\ + %{SOURCE3} \ %{SOURCE2} ; do # In the past, the init script was supposed to be named after the service # that the started daemon provided. Changing their names is an @@ -424,11 +412,11 @@ for unit in \ install -pm 644 ${unit} $RPM_BUILD_ROOT%{_unitdir} done mkdir -p $RPM_BUILD_ROOT/%{_tmpfilesdir} -install -pm 644 %{SOURCE39} $RPM_BUILD_ROOT/%{_tmpfilesdir}/ +install -pm 644 %{SOURCE14} $RPM_BUILD_ROOT/%{_tmpfilesdir}/ mkdir -p $RPM_BUILD_ROOT/%{_localstatedir}/run/krb5kdc mkdir -p $RPM_BUILD_ROOT/etc/sysconfig -for sysconfig in %{SOURCE19} %{SOURCE20} %{SOURCE21} ; do +for sysconfig in %{SOURCE8} %{SOURCE9} %{SOURCE10} ; do install -pm 644 ${sysconfig} \ $RPM_BUILD_ROOT/etc/sysconfig/`basename ${sysconfig} .sysconfig` done @@ -436,15 +424,15 @@ done # logrotate configuration files mkdir -p $RPM_BUILD_ROOT/etc/logrotate.d/ for logrotate in \ - %{SOURCE33} \ - %{SOURCE34} ; do + %{SOURCE12} \ + %{SOURCE13} ; do install -pm 644 ${logrotate} \ $RPM_BUILD_ROOT/etc/logrotate.d/`basename ${logrotate} .logrotate` done # PAM configuration files. mkdir -p $RPM_BUILD_ROOT/etc/pam.d/ -for pam in %{SOURCE29} ; do +for pam in %{SOURCE11} ; do install -pm 644 ${pam} \ $RPM_BUILD_ROOT/etc/pam.d/`basename ${pam} .pamd` done @@ -676,6 +664,13 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog +* Tue Nov 22 2022 Julien Rische - 1.20.1-0.1 +- New upstream version (1.20.1) +- Resolves: rhbz#2124463 +- Restore "supportedCMSTypes" attribute in PKINIT preauth requests +- Set SHA-512 or SHA-256 with RSA as preferred CMS signature algorithms +- Resolves: rhbz#2114766 + * Wed Nov 09 2022 Julien Rische - 1.19.2-13 - Fix integer overflows in PAC parsing (CVE-2022-42898) - Resolves: rhbz#2143011 diff --git a/sources b/sources index 16c7a8d..9bc9770 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.19.2.tar.gz) = b90d6ed0e1e8a87eb5cb2c36d88b823a6a6caabf85e5d419adb8a930f7eea09a5f8491464e7e454cca7ba88be09d19415962fe0036ad2e31fc584f9fc0bbd470 -SHA512 (krb5-1.19.2.tar.gz.asc) = 87c4d096dbb6821401125b8f8a315ce1aac029744ba9670a4f8a2a680e6dd5798e1c6d5d2b68b17fd9a4b3b9c6ff111cd1dcac42f934d48fb20381b3765e0f64 +SHA512 (krb5-1.20.1.tar.gz) = 6f57479f13f107cd84f30de5c758eb6b9fc59171329c13e5da6073b806755f8d163eb7bd84767ea861ad6458ea0c9eeb00ee044d3bcad01ef136e9888564b6a2 +SHA512 (krb5-1.20.1.tar.gz.asc) = 1d3312bd67581e07adfdadf2c5fe394179631d8add8bd075efefe982a0de22369004e60a14422d426382c8c591e4181b9897088afe9d4e86f0b5a97e5954c67a From 603ad7099ee5bad5c587d8f0260395eae1c6d5fa Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 23 Nov 2022 19:25:05 +0100 Subject: [PATCH 271/304] Update error checking for OpenSSL CMS_verify Resolves: rhbz#2119704 Signed-off-by: Julien Rische --- ...rror-checking-for-OpenSSL-CMS_verify.patch | 48 +++++++++++++++++++ ...-SHA-1-digest-disallowed-error-for-P.patch | 28 +++++++++++ krb5.spec | 8 +++- 3 files changed, 82 insertions(+), 2 deletions(-) create mode 100644 0010-Update-error-checking-for-OpenSSL-CMS_verify.patch create mode 100644 0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch diff --git a/0010-Update-error-checking-for-OpenSSL-CMS_verify.patch b/0010-Update-error-checking-for-OpenSSL-CMS_verify.patch new file mode 100644 index 0000000..0fbd529 --- /dev/null +++ b/0010-Update-error-checking-for-OpenSSL-CMS_verify.patch @@ -0,0 +1,48 @@ +From 963314f4f449e136195232bdada3109af65d0881 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Thu, 28 Jul 2022 15:20:12 +0200 +Subject: [PATCH] Update error checking for OpenSSL CMS_verify + +The code for CMS data verification was initially written for OpenSSL's +PKCS7_verify() function. It now uses CMS_verify(), but error handling +is still done using PKCS7_verify() error identifiers. Update the +recognized error codes so that the KDC generates +KDC_ERR_DIGEST_IN_SIGNED_DATA_NOT_ACCEPTED errors when appropriate. +Use ERR_peek_last_error() to observe the error generated closest to +the API surface. + +[ghudson@mit.edu: edited commit message] + +ticket: 9069 (new) +tags: pullup +target_version: 1.20-next +--- + src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 9 ++++++--- + 1 file changed, 6 insertions(+), 3 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 1c2aa02827..16edf15cb2 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -2102,12 +2102,15 @@ cms_signeddata_verify(krb5_context context, + goto cleanup; + out = BIO_new(BIO_s_mem()); + if (CMS_verify(cms, NULL, store, NULL, out, flags) == 0) { +- unsigned long err = ERR_peek_error(); ++ unsigned long err = ERR_peek_last_error(); + switch(ERR_GET_REASON(err)) { +- case PKCS7_R_DIGEST_FAILURE: ++ case RSA_R_DIGEST_NOT_ALLOWED: ++ case CMS_R_UNKNOWN_DIGEST_ALGORITHM: ++ case CMS_R_NO_MATCHING_DIGEST: ++ case CMS_R_NO_MATCHING_SIGNATURE: + retval = KRB5KDC_ERR_DIGEST_IN_SIGNED_DATA_NOT_ACCEPTED; + break; +- case PKCS7_R_SIGNATURE_FAILURE: ++ case CMS_R_VERIFICATION_FAILURE: + default: + retval = KRB5KDC_ERR_INVALID_SIG; + } +-- +2.38.1 + diff --git a/0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch b/0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch new file mode 100644 index 0000000..373cd1a --- /dev/null +++ b/0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch @@ -0,0 +1,28 @@ +From c7d2d7c090bc000acd67b358150b9487f606ff20 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Fri, 19 Aug 2022 10:34:52 +0200 +Subject: [PATCH] [downstream] Catch SHA-1 digest disallowed error for + PKINIT + +An OpenSSL patch causes EVP_R_INVALID_DIGEST error to be raised if +CMS_verify is called to verify a SHA-1 signature. If this error is +caught, it will now return KDC_ERR_DIGEST_IN_SIGNED_DATA_NOT_ACCEPTED. +--- + src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 16edf15cb2..bfa3fe8e91 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -2104,6 +2104,7 @@ cms_signeddata_verify(krb5_context context, + if (CMS_verify(cms, NULL, store, NULL, out, flags) == 0) { + unsigned long err = ERR_peek_last_error(); + switch(ERR_GET_REASON(err)) { ++ case EVP_R_INVALID_DIGEST: + case RSA_R_DIGEST_NOT_ALLOWED: + case CMS_R_UNKNOWN_DIGEST_ALGORITHM: + case CMS_R_NO_MATCHING_DIGEST: +-- +2.38.1 + diff --git a/krb5.spec b/krb5.spec index b14c9c9..5d8587e 100644 --- a/krb5.spec +++ b/krb5.spec @@ -34,7 +34,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 0.1 +%global baserelease 0.2 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -91,6 +91,8 @@ Patch6: 0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch Patch7: 0007-Add-configure-variable-for-default-PKCS-11-module.patch Patch8: 0008-Set-reasonable-supportedCMSTypes-in-PKINIT.patch Patch9: 0009-Simplify-plugin-loading-code.patch +Patch10: 0010-Update-error-checking-for-OpenSSL-CMS_verify.patch +Patch11: 0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -664,12 +666,14 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog -* Tue Nov 22 2022 Julien Rische - 1.20.1-0.1 +* Wed Nov 23 2022 Julien Rische - 1.20.1-0.2 - New upstream version (1.20.1) - Resolves: rhbz#2124463 - Restore "supportedCMSTypes" attribute in PKINIT preauth requests - Set SHA-512 or SHA-256 with RSA as preferred CMS signature algorithms - Resolves: rhbz#2114766 +- Update error checking for OpenSSL CMS_verify +- Resolves: rhbz#2119704 * Wed Nov 09 2022 Julien Rische - 1.19.2-13 - Fix integer overflows in PAC parsing (CVE-2022-42898) From 3668746b8fd3a4b5a42eb16cd70bbe308dbc8934 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 23 Nov 2022 19:31:12 +0100 Subject: [PATCH 272/304] Remove invalid password expiry warning Resolves: rhbz#2129113 Signed-off-by: Julien Rische --- 0012-Add-and-use-ts_interval-helper.patch | 239 ++++++++++++++++++++++ krb5.spec | 7 +- 2 files changed, 244 insertions(+), 2 deletions(-) create mode 100644 0012-Add-and-use-ts_interval-helper.patch diff --git a/0012-Add-and-use-ts_interval-helper.patch b/0012-Add-and-use-ts_interval-helper.patch new file mode 100644 index 0000000..5f9647e --- /dev/null +++ b/0012-Add-and-use-ts_interval-helper.patch @@ -0,0 +1,239 @@ +From 07ec260c65ec036d44362868df0f796a53495f27 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 19 Sep 2022 15:18:50 -0400 +Subject: [PATCH] Add and use ts_interval() helper + +ts_delta() returns a signed result, which cannot hold an interval +larger than 2^31-1 seconds. Intervals like this have been seen when +admins set password expiration dates more than 68 years in the future. + +Add a second helper ts_interval() which returns a signed result, and +has the arguments reversed so that the start time is first. Use it in +warn_pw_expiry() to handle the password expiration case, in the GSS +krb5 mech where we return an unsigned context or credential lifetime +to the caller, and in the KEYRING ccache type where we compute an +unsigned keyring timeout. + +ticket: 9071 (new) +--- + src/include/k5-int.h | 9 +++++++++ + src/lib/gssapi/krb5/accept_sec_context.c | 10 ++++++---- + src/lib/gssapi/krb5/acquire_cred.c | 3 +-- + src/lib/gssapi/krb5/context_time.c | 2 +- + src/lib/gssapi/krb5/init_sec_context.c | 4 ++-- + src/lib/gssapi/krb5/inq_context.c | 2 +- + src/lib/gssapi/krb5/inq_cred.c | 2 +- + src/lib/gssapi/krb5/s4u_gss_glue.c | 2 +- + src/lib/krb5/ccache/cc_keyring.c | 4 ++-- + src/lib/krb5/krb/get_in_tkt.c | 15 +++++++-------- + 10 files changed, 31 insertions(+), 22 deletions(-) + +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index c3aecba7d4..768110e5ef 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -2325,6 +2325,15 @@ ts_delta(krb5_timestamp a, krb5_timestamp b) + return (krb5_deltat)((uint32_t)a - (uint32_t)b); + } + ++/* Return (end - start) as an unsigned 32-bit value, or 0 if start > end. */ ++static inline uint32_t ++ts_interval(krb5_timestamp start, krb5_timestamp end) ++{ ++ if ((uint32_t)start > (uint32_t)end) ++ return 0; ++ return (uint32_t)end - (uint32_t)start; ++} ++ + /* Increment a timestamp by a signed 32-bit interval, without relying on + * undefined behavior. */ + static inline krb5_timestamp +diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c +index 1bc807172b..7de2c9fd77 100644 +--- a/src/lib/gssapi/krb5/accept_sec_context.c ++++ b/src/lib/gssapi/krb5/accept_sec_context.c +@@ -353,8 +353,8 @@ kg_accept_dce(minor_status, context_handle, verifier_cred_handle, + *mech_type = ctx->mech_used; + + if (time_rec) { +- *time_rec = ts_delta(ctx->krb_times.endtime, now) + +- ctx->k5_context->clockskew; ++ *time_rec = ts_interval(now - ctx->k5_context->clockskew, ++ ctx->krb_times.endtime); + } + + /* Never return GSS_C_DELEG_FLAG since we don't support DCE credential +@@ -1151,8 +1151,10 @@ kg_accept_krb5(minor_status, context_handle, + + /* Add the maximum allowable clock skew as a grace period for context + * expiration, just as we do for the ticket. */ +- if (time_rec) +- *time_rec = ts_delta(ctx->krb_times.endtime, now) + context->clockskew; ++ if (time_rec) { ++ *time_rec = ts_interval(now - context->clockskew, ++ ctx->krb_times.endtime); ++ } + + if (ret_flags) + *ret_flags = ctx->gss_flags; +diff --git a/src/lib/gssapi/krb5/acquire_cred.c b/src/lib/gssapi/krb5/acquire_cred.c +index e226a02692..006eba114d 100644 +--- a/src/lib/gssapi/krb5/acquire_cred.c ++++ b/src/lib/gssapi/krb5/acquire_cred.c +@@ -879,8 +879,7 @@ acquire_cred_context(krb5_context context, OM_uint32 *minor_status, + GSS_C_NO_NAME); + if (GSS_ERROR(ret)) + goto error_out; +- *time_rec = ts_after(cred->expire, now) ? +- ts_delta(cred->expire, now) : 0; ++ *time_rec = ts_interval(now, cred->expire); + k5_mutex_unlock(&cred->lock); + } + } +diff --git a/src/lib/gssapi/krb5/context_time.c b/src/lib/gssapi/krb5/context_time.c +index 1fdb5a16f2..5469d8154c 100644 +--- a/src/lib/gssapi/krb5/context_time.c ++++ b/src/lib/gssapi/krb5/context_time.c +@@ -51,7 +51,7 @@ krb5_gss_context_time(minor_status, context_handle, time_rec) + return(GSS_S_FAILURE); + } + +- lifetime = ts_delta(ctx->krb_times.endtime, now); ++ lifetime = ts_interval(now, ctx->krb_times.endtime); + if (!ctx->initiate) + lifetime += ctx->k5_context->clockskew; + if (lifetime <= 0) { +diff --git a/src/lib/gssapi/krb5/init_sec_context.c b/src/lib/gssapi/krb5/init_sec_context.c +index ea87cf6432..f0f094ccb7 100644 +--- a/src/lib/gssapi/krb5/init_sec_context.c ++++ b/src/lib/gssapi/krb5/init_sec_context.c +@@ -664,7 +664,7 @@ kg_new_connection( + if (time_rec) { + if ((code = krb5_timeofday(context, &now))) + goto cleanup; +- *time_rec = ts_delta(ctx->krb_times.endtime, now); ++ *time_rec = ts_interval(now, ctx->krb_times.endtime); + } + + /* set the other returns */ +@@ -878,7 +878,7 @@ mutual_auth( + if (time_rec) { + if ((code = krb5_timeofday(context, &now))) + goto fail; +- *time_rec = ts_delta(ctx->krb_times.endtime, now); ++ *time_rec = ts_interval(now, ctx->krb_times.endtime); + } + + if (ret_flags) +diff --git a/src/lib/gssapi/krb5/inq_context.c b/src/lib/gssapi/krb5/inq_context.c +index cac024da1f..51c484fdfe 100644 +--- a/src/lib/gssapi/krb5/inq_context.c ++++ b/src/lib/gssapi/krb5/inq_context.c +@@ -120,7 +120,7 @@ krb5_gss_inquire_context(minor_status, context_handle, initiator_name, + + /* Add the maximum allowable clock skew as a grace period for context + * expiration, just as we do for the ticket during authentication. */ +- lifetime = ts_delta(ctx->krb_times.endtime, now); ++ lifetime = ts_interval(now, ctx->krb_times.endtime); + if (!ctx->initiate) + lifetime += context->clockskew; + if (lifetime < 0) +diff --git a/src/lib/gssapi/krb5/inq_cred.c b/src/lib/gssapi/krb5/inq_cred.c +index bb63b726c8..0e675959a3 100644 +--- a/src/lib/gssapi/krb5/inq_cred.c ++++ b/src/lib/gssapi/krb5/inq_cred.c +@@ -131,7 +131,7 @@ krb5_gss_inquire_cred(minor_status, cred_handle, name, lifetime_ret, + } + + if (cred->expire != 0) { +- lifetime = ts_delta(cred->expire, now); ++ lifetime = ts_interval(now, cred->expire); + if (lifetime < 0) + lifetime = 0; + } +diff --git a/src/lib/gssapi/krb5/s4u_gss_glue.c b/src/lib/gssapi/krb5/s4u_gss_glue.c +index 7dcfe4e1eb..fa7f980af7 100644 +--- a/src/lib/gssapi/krb5/s4u_gss_glue.c ++++ b/src/lib/gssapi/krb5/s4u_gss_glue.c +@@ -279,7 +279,7 @@ kg_compose_deleg_cred(OM_uint32 *minor_status, + if (code != 0) + goto cleanup; + +- *time_rec = ts_delta(cred->expire, now); ++ *time_rec = ts_interval(now, cred->expire); + } + + major_status = GSS_S_COMPLETE; +diff --git a/src/lib/krb5/ccache/cc_keyring.c b/src/lib/krb5/ccache/cc_keyring.c +index ebef37d607..1dadeef64f 100644 +--- a/src/lib/krb5/ccache/cc_keyring.c ++++ b/src/lib/krb5/ccache/cc_keyring.c +@@ -762,7 +762,7 @@ update_keyring_expiration(krb5_context context, krb5_ccache id) + + /* Setting the timeout to zero would reset the timeout, so we set it to one + * second instead if creds are already expired. */ +- timeout = ts_after(endtime, now) ? ts_delta(endtime, now) : 1; ++ timeout = ts_after(endtime, now) ? ts_interval(now, endtime) : 1; + (void)keyctl_set_timeout(data->cache_id, timeout); + } + +@@ -1343,7 +1343,7 @@ krcc_store(krb5_context context, krb5_ccache id, krb5_creds *creds) + + if (ts_after(creds->times.endtime, now)) { + (void)keyctl_set_timeout(cred_key, +- ts_delta(creds->times.endtime, now)); ++ ts_interval(now, creds->times.endtime)); + } + + update_keyring_expiration(context, id); +diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c +index 8b5ab595e9..1b420a3ac2 100644 +--- a/src/lib/krb5/krb/get_in_tkt.c ++++ b/src/lib/krb5/krb/get_in_tkt.c +@@ -1522,7 +1522,7 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, + void *expire_data; + krb5_timestamp pw_exp, acct_exp, now; + krb5_boolean is_last_req; +- krb5_deltat delta; ++ uint32_t interval; + char ts[256], banner[1024]; + + if (as_reply == NULL || as_reply->enc_part2 == NULL) +@@ -1553,8 +1553,8 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, + ret = krb5_timeofday(context, &now); + if (ret != 0) + return; +- if (!is_last_req && +- (ts_after(now, pw_exp) || ts_delta(pw_exp, now) > 7 * 24 * 60 * 60)) ++ interval = ts_interval(now, pw_exp); ++ if (!is_last_req && (!interval || interval > 7 * 24 * 60 * 60)) + return; + + if (!prompter) +@@ -1564,19 +1564,18 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, + if (ret != 0) + return; + +- delta = ts_delta(pw_exp, now); +- if (delta < 3600) { ++ if (interval < 3600) { + snprintf(banner, sizeof(banner), + _("Warning: Your password will expire in less than one hour " + "on %s"), ts); +- } else if (delta < 86400 * 2) { ++ } else if (interval < 86400 * 2) { + snprintf(banner, sizeof(banner), + _("Warning: Your password will expire in %d hour%s on %s"), +- delta / 3600, delta < 7200 ? "" : "s", ts); ++ interval / 3600, interval < 7200 ? "" : "s", ts); + } else { + snprintf(banner, sizeof(banner), + _("Warning: Your password will expire in %d days on %s"), +- delta / 86400, ts); ++ interval / 86400, ts); + } + + /* PROMPTER_INVOCATION */ +-- +2.38.1 + diff --git a/krb5.spec b/krb5.spec index 5d8587e..113a81c 100644 --- a/krb5.spec +++ b/krb5.spec @@ -34,7 +34,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 0.2 +%global baserelease 1 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -93,6 +93,7 @@ Patch8: 0008-Set-reasonable-supportedCMSTypes-in-PKINIT.patch Patch9: 0009-Simplify-plugin-loading-code.patch Patch10: 0010-Update-error-checking-for-OpenSSL-CMS_verify.patch Patch11: 0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch +Patch12: 0012-Add-and-use-ts_interval-helper.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -666,7 +667,7 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %changelog -* Wed Nov 23 2022 Julien Rische - 1.20.1-0.2 +* Wed Nov 23 2022 Julien Rische - 1.20.1-1 - New upstream version (1.20.1) - Resolves: rhbz#2124463 - Restore "supportedCMSTypes" attribute in PKINIT preauth requests @@ -674,6 +675,8 @@ exit 0 - Resolves: rhbz#2114766 - Update error checking for OpenSSL CMS_verify - Resolves: rhbz#2119704 +- Remove invalid password expiry warning +- Resolves: rhbz#2129113 * Wed Nov 09 2022 Julien Rische - 1.19.2-13 - Fix integer overflows in PAC parsing (CVE-2022-42898) From 95288a2fb92899c39c8ea11f395bebc2cb1bb766 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Tue, 29 Nov 2022 16:41:27 +0100 Subject: [PATCH 273/304] Use TMT for gating tests Signed-off-by: Julien Rische --- .fmf/version | 1 + gating.yaml | 8 ++ krb5-tests | 14 ++ krb5.spec | 135 ++++++++++++------ plans/tests.fmf | 9 ++ .../Makefile | 0 .../PURPOSE | 0 tests/inplace-upgrade-sanity/TC#0378369.fmf | 21 +++ tests/inplace-upgrade-sanity/TC#0552039.fmf | 17 +++ tests/inplace-upgrade-sanity/TC#0608992.fmf | 14 ++ .../kdc.conf | 0 .../krb5.conf | 0 tests/inplace-upgrade-sanity/main.fmf | 19 +++ .../runtest.sh | 13 +- tests/tests.yml | 16 --- tests/upstream/main.fmf | 7 + tests/upstream/test.sh | 2 + 17 files changed, 210 insertions(+), 66 deletions(-) create mode 100644 .fmf/version create mode 100644 gating.yaml create mode 100644 krb5-tests create mode 100644 plans/tests.fmf rename tests/{inplace-upgrade-sanity-test => inplace-upgrade-sanity}/Makefile (100%) rename tests/{inplace-upgrade-sanity-test => inplace-upgrade-sanity}/PURPOSE (100%) create mode 100644 tests/inplace-upgrade-sanity/TC#0378369.fmf create mode 100644 tests/inplace-upgrade-sanity/TC#0552039.fmf create mode 100644 tests/inplace-upgrade-sanity/TC#0608992.fmf rename tests/{inplace-upgrade-sanity-test => inplace-upgrade-sanity}/kdc.conf (100%) rename tests/{inplace-upgrade-sanity-test => inplace-upgrade-sanity}/krb5.conf (100%) create mode 100644 tests/inplace-upgrade-sanity/main.fmf rename tests/{inplace-upgrade-sanity-test => inplace-upgrade-sanity}/runtest.sh (97%) delete mode 100644 tests/tests.yml create mode 100644 tests/upstream/main.fmf create mode 100755 tests/upstream/test.sh diff --git a/.fmf/version b/.fmf/version new file mode 100644 index 0000000..d00491f --- /dev/null +++ b/.fmf/version @@ -0,0 +1 @@ +1 diff --git a/gating.yaml b/gating.yaml new file mode 100644 index 0000000..af37a4c --- /dev/null +++ b/gating.yaml @@ -0,0 +1,8 @@ +--- !Policy +product_versions: +- fedora-* +decision_contexts: +- bodhi_update_push_stable +subject_type: koji_build +rules: +- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/tests.functional} diff --git a/krb5-tests b/krb5-tests new file mode 100644 index 0000000..cbbb302 --- /dev/null +++ b/krb5-tests @@ -0,0 +1,14 @@ +#!/bin/sh +set -e + +export RPM_PACKAGE_NAME={{ name }} +export RPM_PACKAGE_VERSION={{ version }} +export RPM_PACKAGE_RELEASE={{ release }} +export RPM_ARCH={{ arch }} + +testdir="$(mktemp -d)" +trap "rm -rf ${testdir}" EXIT + +cp -rp /usr/share/{{ name }}-tests "${testdir}/" +make -C "${testdir}/{{ name }}-tests" $(rpm --eval '%{_smp_mflags}') +keyctl session - make -C "${testdir}/{{ name }}-tests" check diff --git a/krb5.spec b/krb5.spec index 113a81c..cc8bc17 100644 --- a/krb5.spec +++ b/krb5.spec @@ -1,27 +1,3 @@ -%bcond_without check -%if %{without check} -%global skipcheck 1 -%endif - -# COPR doesn't work right with the tests. I suspect keyring issues, -# but can't actually debug, so... -%if 0%{?copr_username:1} -%global skipcheck 1 -%endif - -# There are 0 test machines for this architecture, very few builders, and -# they're not very well provisioned / maintained. I can't support it. -# Patches welcome, but there's nothing I can do - it fails more than half the -# for "infrastructure issues" that I can't hope to debug. -%ifarch s390x -%global skipcheck 1 -%endif - -# RHEL runs upstream's test suite in a separate pass after build. -%if 0%{?rhel} -%global skipcheck 1 -%endif - # Set this so that find-lang.sh will recognize the .po files. %global gettext_domain mit-krb5 # Guess where the -libs subpackage's docs are going to go. @@ -81,6 +57,7 @@ Source11: ksu.pamd Source12: krb5kdc.logrotate Source13: kadmind.logrotate Source14: krb5-krb5kdc.conf +Source15: %{name}-tests Patch1: 0001-downstream-ksu-pam-integration.patch Patch2: 0002-downstream-SELinux-integration.patch @@ -115,17 +92,6 @@ BuildRequires: perl-interpreter # For autosetup BuildRequires: git -%if 0%{?skipcheck} -%else -BuildRequires: dejagnu -BuildRequires: net-tools, rpcbind -BuildRequires: hostname -BuildRequires: iproute -BuildRequires: python3-pyrad -BuildRequires: procps-ng -BuildRequires: resolv_wrapper -%endif - %if 0%{?fedora} > 35 # Need KDFs. This is the "real" version BuildRequires: openssl-devel => 1:3.0.0 @@ -135,6 +101,10 @@ BuildRequires: openssl-devel >= 1:1.1.1d-4 BuildRequires: openssl-devel < 1:3.0.0 %endif +# Enable compilation of optional tests +BuildRequires: resolv_wrapper +BuildRequires: libcmocka-devel + %description Kerberos V5 is a trusted-third-party network authentication system, which can improve your network's security by eliminating the insecure @@ -244,6 +214,53 @@ Kerberos is a network authentication system. The libkadm5 package contains only the libkadm5clnt and libkadm5serv shared objects. This interface is not considered stable. +%package tests +Summary: Test sources for krb5 build + +# Build dependencies +Requires: coreutils, gawk, sed +Requires: gcc-c++ +Requires: gettext +Requires: libcom_err-devel +Requires: libselinux-devel +Requires: libss-devel +Requires: libverto-devel +Requires: lmdb-devel +Requires: openldap-devel +Requires: pam-devel +Requires: redhat-rpm-config +%if 0%{?fedora} > 35 +Requires: openssl-devel => 1:3.0.0 +%else +Requires: openssl-devel >= 1:1.1.1d-4 +Requires: openssl-devel < 1:3.0.0 +%endif + +# Test dependencies +Requires: dejagnu +Requires: hostname +Requires: iproute +Requires: keyutils, keyutils-libs-devel >= 1.5.8 +Requires: libcmocka-devel +Requires: libverto-module-base +Requires: logrotate +Requires: net-tools, rpcbind +Requires: perl-interpreter +Requires: procps-ng +Requires: python3-kdcproxy +Requires: python3-pyrad +Requires: resolv_wrapper +Requires: /etc/crypto-policies/back-ends/krb5.config +Requires: /usr/share/dict/words +#Requires: openldap-servers, openldap-clients + +# sssd_krb5_locator_plugin.so conflicts with t_discover_uri.py +Conflicts: sssd-client + +%description tests +FOR TESTING PURPOSE ONLY +Test sources for krb5 build, with pre-defined compilation parameters + %prep %autosetup -S git_am -n %{name}-%{version}%{?dashpre} ln NOTICE LICENSE @@ -354,17 +371,6 @@ sphinx-build -a -b man -t pathsubs doc build-man sphinx-build -a -b html -t pathsubs doc build-html rm -fr build-html/_sources -%if 0%{?skipcheck} -%else -%check -pushd src - -# The build system may give us a revoked session keyring, so run affected -# tests with a new one. -keyctl session - make check OFFLINE=yes TMPDIR=%{_tmppath} -popd -%endif - %install [ "$RPM_BUILD_ROOT" != '/' ] && rm -rf -- "$RPM_BUILD_ROOT" @@ -481,6 +487,39 @@ rm -- "$RPM_BUILD_ROOT/%{_docdir}/krb5-libs/examples/services.append" # This is only needed for tests rm -- "$RPM_BUILD_ROOT/%{_libdir}/krb5/plugins/preauth/test.so" +# Generate tests launching script +sed -e 's/{{ name }}/%{name}/' \ + -e 's/{{ version }}/%{krb5_version}/' \ + -e 's/{{ release }}/%{krb5_release}/' \ + -e 's/{{ arch }}/%{_arch}/' \ + -i %{SOURCE15} +mkdir -p $RPM_BUILD_ROOT%{_libexecdir} +install -pm 755 %{SOURCE15} $RPM_BUILD_ROOT%{_libexecdir}/ + +# Copy source files from build folder to system data folder +install -pdm 755 $RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests +pushd src +cp -p --parents -t "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/" \ + $(find . -type f -exec file -i "{}" + \ + | sed -ne 's|^\./\([^:]\+\): \+text/.\+$|\1|p') +popd + +# Copy binary test files +install -pm 644 src/tests/pkinit-certs/*.p12 \ + "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/tests/pkinit-certs/" +install -pm 644 src/tests/au_dict.json \ + "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/tests/" + +# Unset executable bit if no shebang in script +for f in $(find "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/" -type f -executable) +do + head -n1 "$f" | grep -Eq '^#!' || chmod a-x "$f" +done + +# Remove broken shebang Perl scripts +rm -- "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/config/wconfig.pl" +rm -- "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/kadmin/kdbkeys/do-test.pl" + %find_lang %{gettext_domain} %ldconfig_scriptlets libs @@ -666,6 +705,10 @@ exit 0 %{_libdir}/libkadm5clnt_mit.so.* %{_libdir}/libkadm5srv_mit.so.* +%files tests +%{_libexecdir}/%{name}-tests +%{_datarootdir}/%{name}-tests/ + %changelog * Wed Nov 23 2022 Julien Rische - 1.20.1-1 - New upstream version (1.20.1) diff --git a/plans/tests.fmf b/plans/tests.fmf new file mode 100644 index 0000000..9d368f3 --- /dev/null +++ b/plans/tests.fmf @@ -0,0 +1,9 @@ +summary: Tests +discover: + how: fmf +prepare: +- how: shell + script: + - dnf remove -y sssd-client +execute: + how: tmt diff --git a/tests/inplace-upgrade-sanity-test/Makefile b/tests/inplace-upgrade-sanity/Makefile similarity index 100% rename from tests/inplace-upgrade-sanity-test/Makefile rename to tests/inplace-upgrade-sanity/Makefile diff --git a/tests/inplace-upgrade-sanity-test/PURPOSE b/tests/inplace-upgrade-sanity/PURPOSE similarity index 100% rename from tests/inplace-upgrade-sanity-test/PURPOSE rename to tests/inplace-upgrade-sanity/PURPOSE diff --git a/tests/inplace-upgrade-sanity/TC#0378369.fmf b/tests/inplace-upgrade-sanity/TC#0378369.fmf new file mode 100644 index 0000000..8d54d68 --- /dev/null +++ b/tests/inplace-upgrade-sanity/TC#0378369.fmf @@ -0,0 +1,21 @@ +tag: + - CI-Tier-1 + - CI-Tier-1-krb5 + - Fedora 31 + - Fedora 32 + - FedoraReady + - IDM-CI-gating + - NoRHEL4 + - NoRHEL5 + - TIPpass + - TIPpass_Security + - Tier1 + - Tier1security + - rhel_upgrade +tier: '1' +adjust: + - enabled: false + when: distro == rhel-4, rhel-5 + continue: false +extra-nitrate: TC#0378369 +extra-summary: /CoreOS/krb5/Sanity/inplace-upgrade-sanity-test diff --git a/tests/inplace-upgrade-sanity/TC#0552039.fmf b/tests/inplace-upgrade-sanity/TC#0552039.fmf new file mode 100644 index 0000000..7f2731d --- /dev/null +++ b/tests/inplace-upgrade-sanity/TC#0552039.fmf @@ -0,0 +1,17 @@ +link: + - relates: https://bugzilla.redhat.com/show_bug.cgi?id=1394908 +tag: + - NoRHEL4 + - NoRHEL5 + - TIPpass + - TIPpass_Security + - Tier2 +tier: '2' +adjust: + - enabled: false + when: distro == rhel-4, rhel-5, rhel-6 + continue: false +environment: + TEST_ENTROPY_SOURCE: yes +extra-nitrate: TC#0552039 +extra-summary: 'BZ#1394908: Enable faster getrandom-based entropy system' diff --git a/tests/inplace-upgrade-sanity/TC#0608992.fmf b/tests/inplace-upgrade-sanity/TC#0608992.fmf new file mode 100644 index 0000000..440308f --- /dev/null +++ b/tests/inplace-upgrade-sanity/TC#0608992.fmf @@ -0,0 +1,14 @@ +tag: + - Fedora 31 + - Fedora 32 + - FedoraReady + - NoRHEL4 + - NoRHEL5 + - rhel_upgrade +adjust: + - enabled: false + when: distro == rhel-4, rhel-5 + continue: false +manual: true +extra-nitrate: TC#0608992 +extra-summary: /CoreOS/krb5/Sanity/inplace-upgrade-sanity-test-manual diff --git a/tests/inplace-upgrade-sanity-test/kdc.conf b/tests/inplace-upgrade-sanity/kdc.conf similarity index 100% rename from tests/inplace-upgrade-sanity-test/kdc.conf rename to tests/inplace-upgrade-sanity/kdc.conf diff --git a/tests/inplace-upgrade-sanity-test/krb5.conf b/tests/inplace-upgrade-sanity/krb5.conf similarity index 100% rename from tests/inplace-upgrade-sanity-test/krb5.conf rename to tests/inplace-upgrade-sanity/krb5.conf diff --git a/tests/inplace-upgrade-sanity/main.fmf b/tests/inplace-upgrade-sanity/main.fmf new file mode 100644 index 0000000..40e0a0e --- /dev/null +++ b/tests/inplace-upgrade-sanity/main.fmf @@ -0,0 +1,19 @@ +summary: Verifies basic scenarios which should work after inplace upgrade. +enabled: true +contact: Filip Dvorak +component: +- krb5 +test: ./runtest.sh +path: /tests/inplace-upgrade-sanity +framework: beakerlib +require: +- expect +- krb5-server +- krb5-workstation +- openssh-clients +- openssh-server +- rng-tools +- setools-console +duration: 20m +extra-summary: /CoreOS/krb5/Sanity/inplace-upgrade-sanity-test +extra-task: /CoreOS/krb5/Sanity/inplace-upgrade-sanity-test diff --git a/tests/inplace-upgrade-sanity-test/runtest.sh b/tests/inplace-upgrade-sanity/runtest.sh similarity index 97% rename from tests/inplace-upgrade-sanity-test/runtest.sh rename to tests/inplace-upgrade-sanity/runtest.sh index 7454540..c6e3d45 100755 --- a/tests/inplace-upgrade-sanity-test/runtest.sh +++ b/tests/inplace-upgrade-sanity/runtest.sh @@ -27,7 +27,6 @@ # ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ # Include Beaker environment -. /usr/bin/rhts-environment.sh . /usr/share/beakerlib/beakerlib.sh || exit 1 PACKAGE="krb5" @@ -89,11 +88,17 @@ rlJournalStart if rlIsRHEL 6; then rlRun "sed -i \"s/EXAMPLE.COM/$krb5REALM1/\" $krb5conf" rlRun "sed -i \"s/kerberos.example.com/$krb5HostName/\" $krb5conf" - rlRun "sed -i \"s/example.com/$krb5DomainName/\" $krb5conf" + if [ "$krb5DomainName" ]; then + rlRun "sed -i \"s/example.com/$krb5DomainName/\" $krb5conf" + fi else rlRun "sed -i \"s/\[libdefaults\]/[libdefaults]\n default_realm = $krb5REALM1/\" $krb5conf" rlRun "sed -i \"s/\[realms\]/[realms]\n $krb5REALM1 = {\n kdc = $krb5HostName\n admin_server = $krb5HostName\n }/\" $krb5conf" - rlRun "sed -i \"s/\[domain_realm\]/[domain_realm]\n .$krb5DomainName = $krb5REALM1\n $krb5DomainName = $krb5REALM1/\" $krb5conf" + if [ "$krb5DomainName" ]; then + rlRun "sed -i \"s/\[domain_realm\]/[domain_realm]\n .$krb5DomainName = $krb5REALM1\n $krb5DomainName = $krb5REALM1/\" $krb5conf" + else + rlRun "sed -i \"s/\[domain_realm\]/[domain_realm]\n $krb5HostName = $krb5REALM1/\" $krb5conf" + fi fi rlRun "sed -i s/EXAMPLE.COM/$krb5REALM1/ $krb5kdcconf" # Configure the kadmin ACL @@ -368,4 +373,4 @@ _EOF rlRun "rm -r $TmpDir" rlPhaseEnd rlJournalPrintText -rlJournalEnd \ No newline at end of file +rlJournalEnd diff --git a/tests/tests.yml b/tests/tests.yml deleted file mode 100644 index 6ebc417..0000000 --- a/tests/tests.yml +++ /dev/null @@ -1,16 +0,0 @@ ---- -# This first play always runs on the local staging system -- hosts: localhost - roles: - - role: standard-test-beakerlib - tags: - - classic - tests: - - inplace-upgrade-sanity-test - required_packages: - - expect # Required for inplace-upgrade-sanity-test - - krb5-server # Required for inplace-upgrade-sanity-test - - krb5-workstation # Required for inplace-upgrade-sanity-test - - openssh-clients # Required for inplace-upgrade-sanity-test - - openssh-server # Required for inplace-upgrade-sanity-test - - rng-tools # Required for inplace-upgrade-sanity-test diff --git a/tests/upstream/main.fmf b/tests/upstream/main.fmf new file mode 100644 index 0000000..66718fa --- /dev/null +++ b/tests/upstream/main.fmf @@ -0,0 +1,7 @@ +summary: Run upstream tests +test: ./test.sh +enabled: true +path: /tests/upstream +require: +- krb5-tests +duration: 20m diff --git a/tests/upstream/test.sh b/tests/upstream/test.sh new file mode 100755 index 0000000..9c5abc5 --- /dev/null +++ b/tests/upstream/test.sh @@ -0,0 +1,2 @@ +#!/bin/sh -eux +/usr/libexec/krb5-tests From a206938c15db2bd32c66c63695cfb2caa34df0f7 Mon Sep 17 00:00:00 2001 From: Alexander Bokovoy Date: Thu, 1 Dec 2022 17:57:01 +0200 Subject: [PATCH 274/304] Bump KDB version to 9.0 Signed-off-by: Alexander Bokovoy --- krb5.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/krb5.spec b/krb5.spec index cc8bc17..45bfdc2 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 1 +%global baserelease 2 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -33,7 +33,7 @@ %endif # Should be in form 5.0, 6.1, etc. -%global kdbversion 8.0 +%global kdbversion 9.0 Summary: The Kerberos network authentication system Name: krb5 @@ -710,6 +710,9 @@ exit 0 %{_datarootdir}/%{name}-tests/ %changelog +* Thu Dec 1 2022 Alexander Bokovoy - 1.20.1-2 +- Bump KDB ABI version provide to 9.0 + * Wed Nov 23 2022 Julien Rische - 1.20.1-1 - New upstream version (1.20.1) - Resolves: rhbz#2124463 From f003c0755c1c27d658f974faa72ed3e7b6375686 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Tue, 6 Dec 2022 11:51:10 +0100 Subject: [PATCH 275/304] Enable TMT integration with Fedora CI Signed-off-by: Julien Rische --- ci.fmf | 1 + krb5.spec | 5 ++++- 2 files changed, 5 insertions(+), 1 deletion(-) create mode 100644 ci.fmf diff --git a/ci.fmf b/ci.fmf new file mode 100644 index 0000000..c5aa0e0 --- /dev/null +++ b/ci.fmf @@ -0,0 +1 @@ +resultsdb-testcase: separate diff --git a/krb5.spec b/krb5.spec index 45bfdc2..082fb42 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 2 +%global baserelease 3 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -710,6 +710,9 @@ exit 0 %{_datarootdir}/%{name}-tests/ %changelog +* Tue Dec 06 2022 Julien Rische - 1.20.1-3 +- Enable TMT integration with Fedora CI + * Thu Dec 1 2022 Alexander Bokovoy - 1.20.1-2 - Bump KDB ABI version provide to 9.0 From ba968605e78ef538c23aa391202de8a286ca55b8 Mon Sep 17 00:00:00 2001 From: Yaakov Selkowitz Date: Wed, 7 Dec 2022 19:18:54 -0500 Subject: [PATCH 276/304] Fix openssl dependencies for RHEL/ELN --- krb5.spec | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/krb5.spec b/krb5.spec index 082fb42..b197f0b 100644 --- a/krb5.spec +++ b/krb5.spec @@ -92,9 +92,9 @@ BuildRequires: perl-interpreter # For autosetup BuildRequires: git -%if 0%{?fedora} > 35 +%if 0%{?fedora} > 35 || 0%{?rhel} >= 9 # Need KDFs. This is the "real" version -BuildRequires: openssl-devel => 1:3.0.0 +BuildRequires: openssl-devel >= 1:3.0.0 %else # Need KDFs. This is the backported version BuildRequires: openssl-devel >= 1:1.1.1d-4 @@ -129,7 +129,7 @@ to install this package. %package libs Summary: The non-admin shared libraries used by Kerberos 5 -%if 0%{?fedora} > 35 +%if 0%{?fedora} > 35 || 0%{?rhel} >= 9 Requires: openssl-libs >= 1:3.0.0 %else Requires: openssl-libs >= 1:1.1.1d-4 @@ -229,8 +229,8 @@ Requires: lmdb-devel Requires: openldap-devel Requires: pam-devel Requires: redhat-rpm-config -%if 0%{?fedora} > 35 -Requires: openssl-devel => 1:3.0.0 +%if 0%{?fedora} > 35 || 0%{?rhel} >= 9 +Requires: openssl-devel >= 1:3.0.0 %else Requires: openssl-devel >= 1:1.1.1d-4 Requires: openssl-devel < 1:3.0.0 From f29ff7186e1bc6902997e779103474351b2290ba Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Tue, 20 Dec 2022 16:25:16 +0100 Subject: [PATCH 277/304] Make tests compatible with sssd_krb5_locator_plugin.so --- ...tests-compatible-with-sssd_krb5_loca.patch | 41 +++++++++++++++++++ krb5.spec | 9 ++-- plans/tests.fmf | 4 -- 3 files changed, 46 insertions(+), 8 deletions(-) create mode 100644 0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch diff --git a/0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch b/0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch new file mode 100644 index 0000000..5840faa --- /dev/null +++ b/0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch @@ -0,0 +1,41 @@ +From 9a536113196d8b32e3143964a655356ac8af1347 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Wed, 7 Dec 2022 13:22:42 +0100 +Subject: [PATCH] [downstream] Make tests compatible with + sssd_krb5_locator_plugin.so + +The sssd_krb5_locator_plugin.so plugin provided by sssd-client conflicts +with the upstream test t_discover_uri.py. The test has to be modified in +order to avoid false positive. +--- + src/lib/krb5/os/t_discover_uri.py | 9 ++++++++- + 1 file changed, 8 insertions(+), 1 deletion(-) + +diff --git a/src/lib/krb5/os/t_discover_uri.py b/src/lib/krb5/os/t_discover_uri.py +index 87bac17929..26bc95a8dc 100644 +--- a/src/lib/krb5/os/t_discover_uri.py ++++ b/src/lib/krb5/os/t_discover_uri.py +@@ -1,3 +1,4 @@ ++from os.path import exists + from k5test import * + + entries = ('URI _kerberos.TEST krb5srv::kkdcp:https://kdc1 1 1\n', +@@ -37,8 +38,14 @@ realm.env['RESOLV_WRAPPER_HOSTS'] = hosts_filename + out = realm.run(['./t_locate_kdc', 'TEST'], env=realm.env) + l = out.splitlines() + ++if (exists('/usr/lib/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so') ++ or exists('/usr/lib64/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so')): ++ line_range = range(6, 14) ++else: ++ line_range = range(4, 12) ++ + j = 0 +-for i in range(4, 12): ++for i in line_range: + if l[i].strip() != expected[j]: + fail('URI answers do not match') + j += 1 +-- +2.38.1 + diff --git a/krb5.spec b/krb5.spec index b197f0b..44696f6 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 3 +%global baserelease 4 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -71,6 +71,7 @@ Patch9: 0009-Simplify-plugin-loading-code.patch Patch10: 0010-Update-error-checking-for-OpenSSL-CMS_verify.patch Patch11: 0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch Patch12: 0012-Add-and-use-ts_interval-helper.patch +Patch13: 0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -254,9 +255,6 @@ Requires: /etc/crypto-policies/back-ends/krb5.config Requires: /usr/share/dict/words #Requires: openldap-servers, openldap-clients -# sssd_krb5_locator_plugin.so conflicts with t_discover_uri.py -Conflicts: sssd-client - %description tests FOR TESTING PURPOSE ONLY Test sources for krb5 build, with pre-defined compilation parameters @@ -710,6 +708,9 @@ exit 0 %{_datarootdir}/%{name}-tests/ %changelog +* Tue Dec 20 2022 Julien Rische - 1.20.1-4 +- Make tests compatible with sssd_krb5_locator_plugin.so + * Tue Dec 06 2022 Julien Rische - 1.20.1-3 - Enable TMT integration with Fedora CI diff --git a/plans/tests.fmf b/plans/tests.fmf index 9d368f3..970ae2e 100644 --- a/plans/tests.fmf +++ b/plans/tests.fmf @@ -1,9 +1,5 @@ summary: Tests discover: how: fmf -prepare: -- how: shell - script: - - dnf remove -y sssd-client execute: how: tmt From f0b4f85e9e3715cf90d634cd4cd21452fda2620a Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Thu, 5 Jan 2023 20:18:20 +0100 Subject: [PATCH 278/304] Include missing OpenSSL FIPS header Signed-off-by: Julien Rische --- ...-Include-missing-OpenSSL-FIPS-header.patch | 120 ++++++++++++++++++ krb5.spec | 4 +- 2 files changed, 123 insertions(+), 1 deletion(-) create mode 100644 0014-downstream-Include-missing-OpenSSL-FIPS-header.patch diff --git a/0014-downstream-Include-missing-OpenSSL-FIPS-header.patch b/0014-downstream-Include-missing-OpenSSL-FIPS-header.patch new file mode 100644 index 0000000..24ba48a --- /dev/null +++ b/0014-downstream-Include-missing-OpenSSL-FIPS-header.patch @@ -0,0 +1,120 @@ +From d57a804136c5ebf473ce053a9517edd71a56389f Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Thu, 5 Jan 2023 20:06:47 +0100 +Subject: [PATCH] [downstream] Include missing OpenSSL FIPS header + +The inclusion of openssl/fips.h, which provides the declaration of +FIPS_mode(), was removed from openssl/crypto.h. As a consequence, this +header file has to be included explicitly in krb5 code. +--- + src/lib/crypto/krb/prng.c | 4 +++- + src/lib/crypto/openssl/enc_provider/camellia.c | 1 + + src/lib/crypto/openssl/enc_provider/rc4.c | 4 ++++ + src/lib/crypto/openssl/hmac.c | 1 + + src/lib/krad/internal.h | 4 ++++ + src/plugins/preauth/spake/spake_client.c | 4 ++++ + src/plugins/preauth/spake/spake_kdc.c | 4 ++++ + 7 files changed, 21 insertions(+), 1 deletion(-) + +diff --git a/src/lib/crypto/krb/prng.c b/src/lib/crypto/krb/prng.c +index 9e80a03d21..ae37c77518 100644 +--- a/src/lib/crypto/krb/prng.c ++++ b/src/lib/crypto/krb/prng.c +@@ -28,7 +28,9 @@ + + #include + +-#if OPENSSL_VERSION_NUMBER < 0x30000000L ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++#include ++#else + #include + #endif + +diff --git a/src/lib/crypto/openssl/enc_provider/camellia.c b/src/lib/crypto/openssl/enc_provider/camellia.c +index d9f327add6..3dd3b0624f 100644 +--- a/src/lib/crypto/openssl/enc_provider/camellia.c ++++ b/src/lib/crypto/openssl/enc_provider/camellia.c +@@ -32,6 +32,7 @@ + #include + #if OPENSSL_VERSION_NUMBER >= 0x30000000L + #include ++#include + #else + #include + #endif +diff --git a/src/lib/crypto/openssl/enc_provider/rc4.c b/src/lib/crypto/openssl/enc_provider/rc4.c +index ce63cb5f1b..6a83f10d27 100644 +--- a/src/lib/crypto/openssl/enc_provider/rc4.c ++++ b/src/lib/crypto/openssl/enc_provider/rc4.c +@@ -38,6 +38,10 @@ + + #include + ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++#include ++#endif ++ + /* + * The loopback field is a pointer to the structure. If the application copies + * the state (not a valid operation, but one which happens to works with some +diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c +index f21e268f7f..25a419d73a 100644 +--- a/src/lib/crypto/openssl/hmac.c ++++ b/src/lib/crypto/openssl/hmac.c +@@ -59,6 +59,7 @@ + #if OPENSSL_VERSION_NUMBER >= 0x30000000L + #include + #include ++#include + #else + #include + #endif +diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h +index e123763954..a17b6f39b1 100644 +--- a/src/lib/krad/internal.h ++++ b/src/lib/krad/internal.h +@@ -41,6 +41,10 @@ + + #include + ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++#include ++#endif ++ + #ifndef UCHAR_MAX + #define UCHAR_MAX 255 + #endif +diff --git a/src/plugins/preauth/spake/spake_client.c b/src/plugins/preauth/spake/spake_client.c +index a3ce22b70f..13c699071f 100644 +--- a/src/plugins/preauth/spake/spake_client.c ++++ b/src/plugins/preauth/spake/spake_client.c +@@ -40,6 +40,10 @@ + + #include + ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++#include ++#endif ++ + typedef struct reqstate_st { + krb5_pa_spake *msg; /* set in prep_questions, used in process */ + krb5_keyblock *initial_key; +diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c +index 232e78bc05..3394f8a58e 100644 +--- a/src/plugins/preauth/spake/spake_kdc.c ++++ b/src/plugins/preauth/spake/spake_kdc.c +@@ -43,6 +43,10 @@ + + #include + ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++#include ++#endif ++ + /* + * The SPAKE kdcpreauth module uses a secure cookie containing the following + * concatenated fields (all integer fields are big-endian): +-- +2.38.1 + diff --git a/krb5.spec b/krb5.spec index 44696f6..3593e7d 100644 --- a/krb5.spec +++ b/krb5.spec @@ -72,6 +72,7 @@ Patch10: 0010-Update-error-checking-for-OpenSSL-CMS_verify.patch Patch11: 0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch Patch12: 0012-Add-and-use-ts_interval-helper.patch Patch13: 0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch +Patch14: 0014-downstream-Include-missing-OpenSSL-FIPS-header.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -708,7 +709,8 @@ exit 0 %{_datarootdir}/%{name}-tests/ %changelog -* Tue Dec 20 2022 Julien Rische - 1.20.1-4 +* Thu Jan 05 2023 Julien Rische - 1.20.1-4 +- Include missing OpenSSL FIPS header - Make tests compatible with sssd_krb5_locator_plugin.so * Tue Dec 06 2022 Julien Rische - 1.20.1-3 From 4eee9bbb506af4f436832fb9b2778716d10849d0 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Mon, 9 Jan 2023 22:46:10 +0100 Subject: [PATCH 279/304] Strip debugging data from ksu executable file Signed-off-by: Julien Rische --- ...am-Do-not-set-root-as-ksu-file-owner.patch | 31 +++++++++++++++++++ krb5.spec | 6 +++- 2 files changed, 36 insertions(+), 1 deletion(-) create mode 100644 0015-downstream-Do-not-set-root-as-ksu-file-owner.patch diff --git a/0015-downstream-Do-not-set-root-as-ksu-file-owner.patch b/0015-downstream-Do-not-set-root-as-ksu-file-owner.patch new file mode 100644 index 0000000..5c53868 --- /dev/null +++ b/0015-downstream-Do-not-set-root-as-ksu-file-owner.patch @@ -0,0 +1,31 @@ +From 59d3ecdab7210e87ec475f4ae0d64888d5416b29 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Mon, 9 Jan 2023 22:39:52 +0100 +Subject: [PATCH] [downstream] Do not set root as ksu file owner + +Upstream Makefile uses the install command to set root as owner of the +ksu executable file. However, this is no longer supported on latest +versions of the Mock build environment. + +In case of ksu, the owner, group, and mode are already set using %attr() +in the specfile. +--- + src/config/pre.in | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/config/pre.in b/src/config/pre.in +index 7eaa2f351c..e9ae71471e 100644 +--- a/src/config/pre.in ++++ b/src/config/pre.in +@@ -185,7 +185,7 @@ INSTALL_PROGRAM=@INSTALL_PROGRAM@ $(INSTALL_STRIP) + INSTALL_SCRIPT=@INSTALL_PROGRAM@ + INSTALL_DATA=@INSTALL_DATA@ + INSTALL_SHLIB=@INSTALL_SHLIB@ +-INSTALL_SETUID=$(INSTALL) $(INSTALL_STRIP) -m 4755 -o root ++INSTALL_SETUID=$(INSTALL) + ## This is needed because autoconf will sometimes define @exec_prefix@ to be + ## ${prefix}. + prefix=@prefix@ +-- +2.38.1 + diff --git a/krb5.spec b/krb5.spec index 3593e7d..0f6e58d 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 4 +%global baserelease 5 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -73,6 +73,7 @@ Patch11: 0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch Patch12: 0012-Add-and-use-ts_interval-helper.patch Patch13: 0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch Patch14: 0014-downstream-Include-missing-OpenSSL-FIPS-header.patch +Patch15: 0015-downstream-Do-not-set-root-as-ksu-file-owner.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -709,6 +710,9 @@ exit 0 %{_datarootdir}/%{name}-tests/ %changelog +* Mon Jan 09 2023 Julien Rische - 1.20.1-5 +- Strip debugging data from ksu executable file + * Thu Jan 05 2023 Julien Rische - 1.20.1-4 - Include missing OpenSSL FIPS header - Make tests compatible with sssd_krb5_locator_plugin.so From 4a4fd39d5e74d2f06b6ab51d336433058baa8017 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 18 Jan 2023 16:01:02 +0100 Subject: [PATCH 280/304] Add AES SHA-2 HMAC family as default KDC etypes Resolves: rhbz#2114771 Signed-off-by: Julien Rische --- kdc.conf | 6 ++++-- krb5.spec | 7 ++++++- 2 files changed, 10 insertions(+), 3 deletions(-) diff --git a/kdc.conf b/kdc.conf index 5d1571d..c504e58 100644 --- a/kdc.conf +++ b/kdc.conf @@ -5,10 +5,12 @@ [realms] EXAMPLE.COM = { - #master_key_type = aes256-cts + master_key_type = aes256-cts-hmac-sha384-192 acl_file = /var/kerberos/krb5kdc/kadm5.acl dict_file = /usr/share/dict/words default_principal_flags = +preauth admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab - supported_enctypes = aes256-cts:normal aes128-cts:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal + supported_enctypes = aes256-cts-hmac-sha384-192:normal aes128-cts-hmac-sha256-128:normal aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal camellia256-cts-cmac:normal camellia128-cts-cmac:normal arcfour-hmac-md5:normal + # Supported encryption types for FIPS mode: + #supported_enctypes = aes256-cts-hmac-sha384-192:normal aes128-cts-hmac-sha256-128:normal } diff --git a/krb5.spec b/krb5.spec index 0f6e58d..96d61b3 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 5 +%global baserelease 6 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -710,6 +710,11 @@ exit 0 %{_datarootdir}/%{name}-tests/ %changelog +* Wed Jan 18 2023 Julien Rische - 1.20.1-6 +- Set aes256-cts-hmac-sha384-192 as EXAMLE.COM master key in kdc.conf +- Add AES SHA-2 HMAC family as EXAMPLE.COM supported etypes in kdc.conf +- Resolves: rhbz#2114771 + * Mon Jan 09 2023 Julien Rische - 1.20.1-5 - Strip debugging data from ksu executable file From dca288bae2ddcaf521b06ebc20a39993a4c17c91 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 19 Jan 2023 15:08:24 +0000 Subject: [PATCH 281/304] Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 96d61b3..eff2a84 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 6 +%global baserelease 7 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -710,6 +710,9 @@ exit 0 %{_datarootdir}/%{name}-tests/ %changelog +* Thu Jan 19 2023 Fedora Release Engineering - 1.20.1-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + * Wed Jan 18 2023 Julien Rische - 1.20.1-6 - Set aes256-cts-hmac-sha384-192 as EXAMLE.COM master key in kdc.conf - Add AES SHA-2 HMAC family as EXAMPLE.COM supported etypes in kdc.conf From ec957f57110521e222ea30d3916fd521b2ded7ce Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Mon, 30 Jan 2023 11:51:31 +0100 Subject: [PATCH 282/304] Do not block KRB5KDF and MD4/5 in FIPS mode Bypass OpenSSL's restrictions to use KRB5KDF in FIPS mode in case at least one of AES SHA-1 HMAC encryption types are used. Use OpenSSL 3.0 library context to access MD4 and MD5 lazily from legacy provider if RADIUS is being used or RC4 encryption type is enabled, without affecting global context. Such exceptions should not be allowed by the default FIPS crypto policy. Signed-off-by: Julien Rische --- ...low-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch | 165 ++++++++++++++++++ krb5.spec | 7 +- 2 files changed, 171 insertions(+), 1 deletion(-) create mode 100644 0016-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch diff --git a/0016-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch b/0016-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch new file mode 100644 index 0000000..227650e --- /dev/null +++ b/0016-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch @@ -0,0 +1,165 @@ +From d8f67df42efd68142aa904040f9e8cc0f9138c10 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Thu, 19 Jan 2023 19:22:27 +0100 +Subject: [PATCH] [downstream] Allow KRB5KDF, MD5, and MD4 in FIPS mode + +OpenSSL's restrictions to use KRB5KDF, MD5, and MD4 in FIPS mode are +bypassed in case AES SHA-1 HMAC or RC4 encryption types are allowed by +the crypto policy. +--- + .../crypto/openssl/hash_provider/hash_evp.c | 97 +++++++++++++++++-- + src/lib/crypto/openssl/kdf.c | 2 +- + 2 files changed, 89 insertions(+), 10 deletions(-) + +diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c +index 11659908bb..eb2e693e9f 100644 +--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c ++++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c +@@ -44,6 +44,49 @@ + #define EVP_MD_CTX_free EVP_MD_CTX_destroy + #endif + ++#include ++#include ++#include ++ ++typedef struct ossl_lib_md_context { ++ OSSL_LIB_CTX *libctx; ++ OSSL_PROVIDER *default_provider; ++ OSSL_PROVIDER *legacy_provider; ++} ossl_md_context_t; ++ ++static thread_local ossl_md_context_t *ossl_md_ctx = NULL; ++ ++static krb5_error_code ++init_ossl_md_ctx(ossl_md_context_t *ctx, const char *algo) ++{ ++ ctx->libctx = OSSL_LIB_CTX_new(); ++ if (!ctx->libctx) ++ return KRB5_CRYPTO_INTERNAL; ++ ++ /* Load both legacy and default provider as both may be needed. */ ++ ctx->default_provider = OSSL_PROVIDER_load(ctx->libctx, "default"); ++ ctx->legacy_provider = OSSL_PROVIDER_load(ctx->libctx, "legacy"); ++ ++ if (!(ctx->default_provider && ctx->legacy_provider)) ++ return KRB5_CRYPTO_INTERNAL; ++ ++ return 0; ++} ++ ++static void ++deinit_ossl_ctx(ossl_md_context_t *ctx) ++{ ++ if (ctx->legacy_provider) ++ OSSL_PROVIDER_unload(ctx->legacy_provider); ++ ++ if (ctx->default_provider) ++ OSSL_PROVIDER_unload(ctx->default_provider); ++ ++ if (ctx->libctx) ++ OSSL_LIB_CTX_free(ctx->libctx); ++} ++ ++ + static krb5_error_code + hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, + krb5_data *output) +@@ -60,11 +103,6 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, + if (ctx == NULL) + return ENOMEM; + +- if (type == EVP_md4() || type == EVP_md5()) { +- /* See comments below in hash_md4() and hash_md5(). */ +- EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_NON_FIPS_ALLOW); +- } +- + ok = EVP_DigestInit_ex(ctx, type, NULL); + for (i = 0; i < num_data; i++) { + if (!SIGN_IOV(&data[i])) +@@ -77,6 +115,43 @@ hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, + return ok ? 0 : KRB5_CRYPTO_INTERNAL; + } + ++static krb5_error_code ++hash_legacy_evp(const char *algo, const krb5_crypto_iov *data, size_t num_data, ++ krb5_data *output) ++{ ++ krb5_error_code err; ++ EVP_MD *md = NULL; ++ ++ if (!ossl_md_ctx) { ++ ossl_md_ctx = malloc(sizeof(ossl_md_context_t)); ++ if (!ossl_md_ctx) { ++ err = ENOMEM; ++ goto end; ++ } ++ ++ err = init_ossl_md_ctx(ossl_md_ctx, algo); ++ if (err) { ++ deinit_ossl_ctx(ossl_md_ctx); ++ free(ossl_md_ctx); ++ ossl_md_ctx = NULL; ++ goto end; ++ } ++ } ++ ++ md = EVP_MD_fetch(ossl_md_ctx->libctx, algo, NULL); ++ if (!md) { ++ err = KRB5_CRYPTO_INTERNAL; ++ goto end; ++ } ++ ++ err = hash_evp(md, data, num_data, output); ++ ++end: ++ if (md) ++ EVP_MD_free(md); ++ ++ return err; ++} + #endif + + #ifdef K5_OPENSSL_MD4 +@@ -88,7 +163,8 @@ hash_md4(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) + * by IPA. These keys are only used along a (separately) secured channel + * for legacy reasons when performing trusts to Active Directory. + */ +- return hash_evp(EVP_md4(), data, num_data, output); ++ return FIPS_mode() ? hash_legacy_evp("MD4", data, num_data, output) ++ : hash_evp(EVP_md4(), data, num_data, output); + } + + const struct krb5_hash_provider krb5int_hash_md4 = { +@@ -100,9 +176,12 @@ const struct krb5_hash_provider krb5int_hash_md4 = { + static krb5_error_code + hash_md5(const krb5_crypto_iov *data, size_t num_data, krb5_data *output) + { +- /* MD5 is needed in FIPS mode for communication with RADIUS servers. This +- * is gated in libkrad by libdefaults->radius_md5_fips_override. */ +- return hash_evp(EVP_md5(), data, num_data, output); ++ /* ++ * MD5 is needed in FIPS mode for communication with RADIUS servers. This ++ * is gated in libkrad by libdefaults->radius_md5_fips_override. ++ */ ++ return FIPS_mode() ? hash_legacy_evp("MD5", data, num_data, output) ++ : hash_evp(EVP_md5(), data, num_data, output); + } + + const struct krb5_hash_provider krb5int_hash_md5 = { +diff --git a/src/lib/crypto/openssl/kdf.c b/src/lib/crypto/openssl/kdf.c +index 5a43c3d9eb..8528ddc4a9 100644 +--- a/src/lib/crypto/openssl/kdf.c ++++ b/src/lib/crypto/openssl/kdf.c +@@ -198,7 +198,7 @@ k5_derive_random_rfc3961(const struct krb5_enc_provider *enc, krb5_key key, + goto done; + } + +- kdf = EVP_KDF_fetch(NULL, "KRB5KDF", NULL); ++ kdf = EVP_KDF_fetch(NULL, "KRB5KDF", "-fips"); + if (kdf == NULL) { + ret = KRB5_CRYPTO_INTERNAL; + goto done; +-- +2.39.1 + diff --git a/krb5.spec b/krb5.spec index eff2a84..3592f20 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 7 +%global baserelease 8 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -74,6 +74,7 @@ Patch12: 0012-Add-and-use-ts_interval-helper.patch Patch13: 0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch Patch14: 0014-downstream-Include-missing-OpenSSL-FIPS-header.patch Patch15: 0015-downstream-Do-not-set-root-as-ksu-file-owner.patch +Patch16: 0016-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -710,6 +711,10 @@ exit 0 %{_datarootdir}/%{name}-tests/ %changelog +* Mon Jan 30 2023 Julien Rische - 1.20.1-8 +- Bypass FIPS restrictions to use KRB5KDF in case AES SHA-1 HMAC is enabled +- Lazily load MD4/5 from OpenSSL if using RADIUS or RC4 enctype in FIPS mode + * Thu Jan 19 2023 Fedora Release Engineering - 1.20.1-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild From 7058594eabc7495d1ec82717da6e752720418304 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Tue, 31 Jan 2023 17:56:02 +0100 Subject: [PATCH 283/304] Add support for MS-PAC extended KDC signature (CVE-2022-37967) Resolves: rhbz#2166001 Signed-off-by: Julien Rische --- 0017-Add-PAC-full-checksums.patch | 672 ++++++++++++++++++++++++++++++ krb5.spec | 7 +- 2 files changed, 678 insertions(+), 1 deletion(-) create mode 100644 0017-Add-PAC-full-checksums.patch diff --git a/0017-Add-PAC-full-checksums.patch b/0017-Add-PAC-full-checksums.patch new file mode 100644 index 0000000..f0a20f6 --- /dev/null +++ b/0017-Add-PAC-full-checksums.patch @@ -0,0 +1,672 @@ +From 5801da1ddc3b0984ad6997bb7a692eac85ff7dd3 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 22 Dec 2022 03:05:23 -0500 +Subject: [PATCH] Add PAC full checksums + +A paper by Tom Tervoort noted that computing the PAC privsvr checksum +over only the server checksum is vulnerable to collision attacks +(CVE-2022-37967). In response, Microsoft has added a second KDC +checksum over the full contents of the PAC. Generate and verify full +KDC checksums in PACs for service tickets. Update the t_pac.c ticket +test case to use a ticket issued by a recent version of Active +Directory (provided by Stefan Metzmacher). + +ticket: 9084 (new) +--- + doc/appdev/refs/macros/index.rst | 1 + + src/include/krb5/krb5.hin | 1 + + src/lib/krb5/krb/pac.c | 92 +++++++++-------- + src/lib/krb5/krb/pac_sign.c | 146 +++++++++++++++----------- + src/lib/krb5/krb/t_pac.c | 171 ++++++++++++++++++------------- + src/tests/t_authdata.py | 4 +- + 6 files changed, 240 insertions(+), 175 deletions(-) + +diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst +index 5f34dea5e8..3eeee25593 100644 +--- a/doc/appdev/refs/macros/index.rst ++++ b/doc/appdev/refs/macros/index.rst +@@ -247,6 +247,7 @@ Public + KRB5_PAC_SERVER_CHECKSUM.rst + KRB5_PAC_TICKET_CHECKSUM.rst + KRB5_PAC_UPN_DNS_INFO.rst ++ KRB5_PAC_FULL_CHECKSUM.rst + KRB5_PADATA_AFS3_SALT.rst + KRB5_PADATA_AP_REQ.rst + KRB5_PADATA_AS_CHECKSUM.rst +diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin +index fb9f2a366c..2ba4010514 100644 +--- a/src/include/krb5/krb5.hin ++++ b/src/include/krb5/krb5.hin +@@ -8164,6 +8164,7 @@ krb5_verify_authdata_kdc_issued(krb5_context context, + #define KRB5_PAC_TICKET_CHECKSUM 16 /**< Ticket checksum */ + #define KRB5_PAC_ATTRIBUTES_INFO 17 /**< PAC attributes */ + #define KRB5_PAC_REQUESTOR 18 /**< PAC requestor SID */ ++#define KRB5_PAC_FULL_CHECKSUM 19 /**< KDC full checksum */ + + struct krb5_pac_data; + /** PAC data structure to convey authorization information */ +diff --git a/src/lib/krb5/krb/pac.c b/src/lib/krb5/krb/pac.c +index f6c4373de0..954482e0c7 100644 +--- a/src/lib/krb5/krb/pac.c ++++ b/src/lib/krb5/krb/pac.c +@@ -490,7 +490,8 @@ zero_signature(krb5_context context, const krb5_pac pac, krb5_ui_4 type, + size_t i; + + assert(type == KRB5_PAC_SERVER_CHECKSUM || +- type == KRB5_PAC_PRIVSVR_CHECKSUM); ++ type == KRB5_PAC_PRIVSVR_CHECKSUM || ++ type == KRB5_PAC_FULL_CHECKSUM); + assert(data->length >= pac->data.length); + + for (i = 0; i < pac->pac->cBuffers; i++) { +@@ -557,17 +558,17 @@ verify_checksum(krb5_context context, const krb5_pac pac, uint32_t buffer_type, + } + + static krb5_error_code +-verify_server_checksum(krb5_context context, const krb5_pac pac, +- const krb5_keyblock *server) ++verify_pac_checksums(krb5_context context, const krb5_pac pac, ++ krb5_boolean expect_full_checksum, ++ const krb5_keyblock *server, const krb5_keyblock *privsvr) + { + krb5_error_code ret; +- krb5_data copy; /* PAC with zeroed checksums */ ++ krb5_data copy, server_checksum; + ++ /* Make a copy of the PAC with zeroed out server and privsvr checksums. */ + ret = krb5int_copy_data_contents(context, &pac->data, ©); + if (ret) + return ret; +- +- /* Zero out both checksum buffers */ + ret = zero_signature(context, pac, KRB5_PAC_SERVER_CHECKSUM, ©); + if (ret) + goto cleanup; +@@ -575,32 +576,46 @@ verify_server_checksum(krb5_context context, const krb5_pac pac, + if (ret) + goto cleanup; + +- ret = verify_checksum(context, pac, KRB5_PAC_SERVER_CHECKSUM, server, +- KRB5_KEYUSAGE_APP_DATA_CKSUM, ©); ++ if (server != NULL) { ++ /* Verify the server checksum over the PAC copy. */ ++ ret = verify_checksum(context, pac, KRB5_PAC_SERVER_CHECKSUM, server, ++ KRB5_KEYUSAGE_APP_DATA_CKSUM, ©); ++ } + +-cleanup: +- free(copy.data); +- return ret; +-} ++ if (privsvr != NULL && expect_full_checksum) { ++ /* Zero the full checksum buffer in the copy and verify the full ++ * checksum over the copy with all three checksums zeroed. */ ++ ret = zero_signature(context, pac, KRB5_PAC_FULL_CHECKSUM, ©); ++ if (ret) ++ goto cleanup; ++ ret = verify_checksum(context, pac, KRB5_PAC_FULL_CHECKSUM, privsvr, ++ KRB5_KEYUSAGE_APP_DATA_CKSUM, ©); ++ if (ret) ++ goto cleanup; ++ } + +-static krb5_error_code +-verify_kdc_checksum(krb5_context context, const krb5_pac pac, +- const krb5_keyblock *privsvr) +-{ +- krb5_error_code ret; +- krb5_data server_checksum; ++ if (privsvr != NULL) { ++ /* Verify the privsvr checksum over the server checksum. */ ++ ret = k5_pac_locate_buffer(context, pac, KRB5_PAC_SERVER_CHECKSUM, ++ &server_checksum); ++ if (ret) ++ return ret; ++ if (server_checksum.length < PAC_SIGNATURE_DATA_LENGTH) ++ return KRB5_BAD_MSIZE; ++ server_checksum.data += PAC_SIGNATURE_DATA_LENGTH; ++ server_checksum.length -= PAC_SIGNATURE_DATA_LENGTH; + +- ret = k5_pac_locate_buffer(context, pac, KRB5_PAC_SERVER_CHECKSUM, +- &server_checksum); +- if (ret) +- return ret; +- if (server_checksum.length < PAC_SIGNATURE_DATA_LENGTH) +- return KRB5_BAD_MSIZE; +- server_checksum.data += PAC_SIGNATURE_DATA_LENGTH; +- server_checksum.length -= PAC_SIGNATURE_DATA_LENGTH; ++ ret = verify_checksum(context, pac, KRB5_PAC_PRIVSVR_CHECKSUM, privsvr, ++ KRB5_KEYUSAGE_APP_DATA_CKSUM, &server_checksum); ++ if (ret) ++ goto cleanup; ++ } ++ ++ pac->verified = TRUE; + +- return verify_checksum(context, pac, KRB5_PAC_PRIVSVR_CHECKSUM, privsvr, +- KRB5_KEYUSAGE_APP_DATA_CKSUM, &server_checksum); ++cleanup: ++ free(copy.data); ++ return ret; + } + + /* Per MS-PAC 2.8.3, tickets encrypted to TGS and password change principals +@@ -628,6 +643,7 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + krb5_authdata **authdata, *orig, **ifrel = NULL, **recoded_ifrel = NULL; + uint8_t z = 0; + krb5_authdata zpac = { KV5M_AUTHDATA, KRB5_AUTHDATA_WIN2K_PAC, 1, &z }; ++ krb5_boolean is_service_tkt; + size_t i, j; + + *pac_out = NULL; +@@ -669,7 +685,8 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + if (ret) + goto cleanup; + +- if (privsvr != NULL && k5_pac_should_have_ticket_signature(server_princ)) { ++ is_service_tkt = k5_pac_should_have_ticket_signature(server_princ); ++ if (privsvr != NULL && is_service_tkt) { + /* To check the PAC ticket signatures, re-encode the ticket with the + * PAC contents replaced by a single zero. */ + orig = ifrel[j]; +@@ -693,8 +710,9 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + goto cleanup; + } + +- ret = krb5_pac_verify_ext(context, pac, enc_tkt->times.authtime, NULL, +- server, privsvr, FALSE); ++ ret = verify_pac_checksums(context, pac, is_service_tkt, server, privsvr); ++ if (ret) ++ goto cleanup; + + *pac_out = pac; + pac = NULL; +@@ -730,14 +748,8 @@ krb5_pac_verify_ext(krb5_context context, + { + krb5_error_code ret; + +- if (server != NULL) { +- ret = verify_server_checksum(context, pac, server); +- if (ret != 0) +- return ret; +- } +- +- if (privsvr != NULL) { +- ret = verify_kdc_checksum(context, pac, privsvr); ++ if (server != NULL || privsvr != NULL) { ++ ret = verify_pac_checksums(context, pac, FALSE, server, privsvr); + if (ret != 0) + return ret; + } +@@ -749,8 +761,6 @@ krb5_pac_verify_ext(krb5_context context, + return ret; + } + +- pac->verified = TRUE; +- + return 0; + } + +diff --git a/src/lib/krb5/krb/pac_sign.c b/src/lib/krb5/krb/pac_sign.c +index 0f9581abbb..8ea61ac17b 100644 +--- a/src/lib/krb5/krb/pac_sign.c ++++ b/src/lib/krb5/krb/pac_sign.c +@@ -187,26 +187,41 @@ k5_pac_encode_header(krb5_context context, krb5_pac pac) + return 0; + } + +-krb5_error_code KRB5_CALLCONV +-krb5_pac_sign(krb5_context context, krb5_pac pac, krb5_timestamp authtime, +- krb5_const_principal principal, const krb5_keyblock *server_key, +- const krb5_keyblock *privsvr_key, krb5_data *data) ++/* Find the buffer of type buftype in pac and write within it a checksum of ++ * type cksumtype over data. Set *cksum_out to the checksum. */ ++static krb5_error_code ++compute_pac_checksum(krb5_context context, krb5_pac pac, uint32_t buftype, ++ const krb5_keyblock *key, krb5_cksumtype cksumtype, ++ const krb5_data *data, krb5_data *cksum_out) + { +- return krb5_pac_sign_ext(context, pac, authtime, principal, server_key, +- privsvr_key, FALSE, data); ++ krb5_error_code ret; ++ krb5_data buf; ++ krb5_crypto_iov iov[2]; ++ ++ ret = k5_pac_locate_buffer(context, pac, buftype, &buf); ++ if (ret) ++ return ret; ++ ++ assert(buf.length > PAC_SIGNATURE_DATA_LENGTH); ++ *cksum_out = make_data(buf.data + PAC_SIGNATURE_DATA_LENGTH, ++ buf.length - PAC_SIGNATURE_DATA_LENGTH); ++ iov[0].flags = KRB5_CRYPTO_TYPE_DATA; ++ iov[0].data = *data; ++ iov[1].flags = KRB5_CRYPTO_TYPE_CHECKSUM; ++ iov[1].data = *cksum_out; ++ return krb5_c_make_checksum_iov(context, cksumtype, key, ++ KRB5_KEYUSAGE_APP_DATA_CKSUM, iov, 2); + } + +-krb5_error_code KRB5_CALLCONV +-krb5_pac_sign_ext(krb5_context context, krb5_pac pac, krb5_timestamp authtime, +- krb5_const_principal principal, +- const krb5_keyblock *server_key, +- const krb5_keyblock *privsvr_key, krb5_boolean with_realm, +- krb5_data *data) ++static krb5_error_code ++sign_pac(krb5_context context, krb5_pac pac, krb5_timestamp authtime, ++ krb5_const_principal principal, const krb5_keyblock *server_key, ++ const krb5_keyblock *privsvr_key, krb5_boolean with_realm, ++ krb5_boolean is_service_tkt, krb5_data *data) + { + krb5_error_code ret; +- krb5_data server_cksum, privsvr_cksum; ++ krb5_data full_cksum, server_cksum, privsvr_cksum; + krb5_cksumtype server_cksumtype, privsvr_cksumtype; +- krb5_crypto_iov iov[2]; + + data->length = 0; + data->data = NULL; +@@ -214,67 +229,53 @@ krb5_pac_sign_ext(krb5_context context, krb5_pac pac, krb5_timestamp authtime, + if (principal != NULL) { + ret = k5_insert_client_info(context, pac, authtime, principal, + with_realm); +- if (ret != 0) ++ if (ret) + return ret; + } + +- /* Create zeroed buffers for both checksums */ ++ /* Create zeroed buffers for all checksums. */ + ret = k5_insert_checksum(context, pac, KRB5_PAC_SERVER_CHECKSUM, + server_key, &server_cksumtype); +- if (ret != 0) ++ if (ret) + return ret; +- + ret = k5_insert_checksum(context, pac, KRB5_PAC_PRIVSVR_CHECKSUM, + privsvr_key, &privsvr_cksumtype); +- if (ret != 0) ++ if (ret) + return ret; ++ if (is_service_tkt) { ++ ret = k5_insert_checksum(context, pac, KRB5_PAC_FULL_CHECKSUM, ++ privsvr_key, &privsvr_cksumtype); ++ if (ret) ++ return ret; ++ } + +- /* Now, encode the PAC header so that the checksums will include it */ ++ /* Encode the PAC header so that the checksums will include it. */ + ret = k5_pac_encode_header(context, pac); +- if (ret != 0) +- return ret; +- +- /* Generate the server checksum over the entire PAC */ +- ret = k5_pac_locate_buffer(context, pac, KRB5_PAC_SERVER_CHECKSUM, +- &server_cksum); +- if (ret != 0) ++ if (ret) + return ret; + +- assert(server_cksum.length > PAC_SIGNATURE_DATA_LENGTH); +- +- iov[0].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[0].data = pac->data; +- +- iov[1].flags = KRB5_CRYPTO_TYPE_CHECKSUM; +- iov[1].data.data = server_cksum.data + PAC_SIGNATURE_DATA_LENGTH; +- iov[1].data.length = server_cksum.length - PAC_SIGNATURE_DATA_LENGTH; ++ if (is_service_tkt) { ++ /* Generate a full KDC checksum over the whole PAC. */ ++ ret = compute_pac_checksum(context, pac, KRB5_PAC_FULL_CHECKSUM, ++ privsvr_key, privsvr_cksumtype, ++ &pac->data, &full_cksum); ++ if (ret) ++ return ret; ++ } + +- ret = krb5_c_make_checksum_iov(context, server_cksumtype, +- server_key, KRB5_KEYUSAGE_APP_DATA_CKSUM, +- iov, sizeof(iov)/sizeof(iov[0])); +- if (ret != 0) ++ /* Generate the server checksum over the whole PAC, including the full KDC ++ * checksum if we added one. */ ++ ret = compute_pac_checksum(context, pac, KRB5_PAC_SERVER_CHECKSUM, ++ server_key, server_cksumtype, &pac->data, ++ &server_cksum); ++ if (ret) + return ret; + +- /* Generate the privsvr checksum over the server checksum buffer */ +- ret = k5_pac_locate_buffer(context, pac, KRB5_PAC_PRIVSVR_CHECKSUM, ++ /* Generate the privsvr checksum over the server checksum buffer. */ ++ ret = compute_pac_checksum(context, pac, KRB5_PAC_PRIVSVR_CHECKSUM, ++ privsvr_key, privsvr_cksumtype, &server_cksum, + &privsvr_cksum); +- if (ret != 0) +- return ret; +- +- assert(privsvr_cksum.length > PAC_SIGNATURE_DATA_LENGTH); +- +- iov[0].flags = KRB5_CRYPTO_TYPE_DATA; +- iov[0].data.data = server_cksum.data + PAC_SIGNATURE_DATA_LENGTH; +- iov[0].data.length = server_cksum.length - PAC_SIGNATURE_DATA_LENGTH; +- +- iov[1].flags = KRB5_CRYPTO_TYPE_CHECKSUM; +- iov[1].data.data = privsvr_cksum.data + PAC_SIGNATURE_DATA_LENGTH; +- iov[1].data.length = privsvr_cksum.length - PAC_SIGNATURE_DATA_LENGTH; +- +- ret = krb5_c_make_checksum_iov(context, privsvr_cksumtype, +- privsvr_key, KRB5_KEYUSAGE_APP_DATA_CKSUM, +- iov, sizeof(iov)/sizeof(iov[0])); +- if (ret != 0) ++ if (ret) + return ret; + + data->data = k5memdup(pac->data.data, pac->data.length, &ret); +@@ -288,6 +289,26 @@ krb5_pac_sign_ext(krb5_context context, krb5_pac pac, krb5_timestamp authtime, + return 0; + } + ++krb5_error_code KRB5_CALLCONV ++krb5_pac_sign(krb5_context context, krb5_pac pac, krb5_timestamp authtime, ++ krb5_const_principal principal, const krb5_keyblock *server_key, ++ const krb5_keyblock *privsvr_key, krb5_data *data) ++{ ++ return sign_pac(context, pac, authtime, principal, server_key, ++ privsvr_key, FALSE, FALSE, data); ++} ++ ++krb5_error_code KRB5_CALLCONV ++krb5_pac_sign_ext(krb5_context context, krb5_pac pac, krb5_timestamp authtime, ++ krb5_const_principal principal, ++ const krb5_keyblock *server_key, ++ const krb5_keyblock *privsvr_key, krb5_boolean with_realm, ++ krb5_data *data) ++{ ++ return sign_pac(context, pac, authtime, principal, server_key, privsvr_key, ++ with_realm, FALSE, data); ++} ++ + /* Add a signature over der_enc_tkt in privsvr to pac. der_enc_tkt should be + * encoded with a dummy PAC authdata element containing a single zero byte. */ + static krb5_error_code +@@ -359,6 +380,7 @@ krb5_kdc_sign_ticket(krb5_context context, krb5_enc_tkt_part *enc_tkt, + krb5_error_code ret; + krb5_data *der_enc_tkt = NULL, pac_data = empty_data(); + krb5_authdata **list, *pac_ad; ++ krb5_boolean is_service_tkt; + size_t count; + + /* Reallocate space for another authdata element in enc_tkt. */ +@@ -377,7 +399,8 @@ krb5_kdc_sign_ticket(krb5_context context, krb5_enc_tkt_part *enc_tkt, + memmove(list + 1, list, (count + 1) * sizeof(*list)); + list[0] = pac_ad; + +- if (k5_pac_should_have_ticket_signature(server_princ)) { ++ is_service_tkt = k5_pac_should_have_ticket_signature(server_princ); ++ if (is_service_tkt) { + ret = encode_krb5_enc_tkt_part(enc_tkt, &der_enc_tkt); + if (ret) + goto cleanup; +@@ -388,9 +411,8 @@ krb5_kdc_sign_ticket(krb5_context context, krb5_enc_tkt_part *enc_tkt, + goto cleanup; + } + +- ret = krb5_pac_sign_ext(context, pac, enc_tkt->times.authtime, +- client_princ, server, privsvr, with_realm, +- &pac_data); ++ ret = sign_pac(context, pac, enc_tkt->times.authtime, client_princ, server, ++ privsvr, with_realm, is_service_tkt, &pac_data); + if (ret) + goto cleanup; + +diff --git a/src/lib/krb5/krb/t_pac.c b/src/lib/krb5/krb/t_pac.c +index 173bde7bab..81f1642ab0 100644 +--- a/src/lib/krb5/krb/t_pac.c ++++ b/src/lib/krb5/krb/t_pac.c +@@ -607,78 +607,102 @@ check_pac(krb5_context context, int index, const unsigned char *pdata, + + static const krb5_keyblock ticket_sig_krbtgt_key = { + 0, ENCTYPE_AES256_CTS_HMAC_SHA1_96, +- 32, U("\x7a\x58\x98\xd2\xaf\xa6\xaf\xc0\x6a\xce\x06\x04\x4b\xc2\x70\x84" +- "\x9b\x8e\x0a\x6c\x4c\x07\xdc\x6f\xbb\x48\x43\xe1\xd2\xaa\x97\xf7") ++ 32, U("\x03\x73\x81\xEC\x43\x96\x7B\xC2\xAC\x3D\xF5\x2A\xAE\x95\xA6\x8E" ++ "\xBE\x24\x58\xDB\xCE\x52\x28\x20\xAF\x5E\xB7\x04\xA2\x22\x71\x4F") + }; + + static const krb5_keyblock ticket_sig_server_key = { +- 0, ENCTYPE_ARCFOUR_HMAC, +- 16, U("\xed\x23\x11\x20\x7a\x21\x44\x20\xbf\xc0\x8d\x36\xf7\xf6\xb2\x3e") ++ 0, ENCTYPE_AES256_CTS_HMAC_SHA1_96, ++ 32, U("\x11\x4A\x84\xE3\x14\x8F\xAA\xB1\xFA\x7B\x53\x51\xB2\x8A\xC2\xF1" ++ "\xFD\x19\x6D\x61\xE0\xF3\xF2\x3E\x1F\xDB\xD3\xC1\x79\x7D\xC1\xEE") + }; + ++/* A ticket issued by an Active Directory KDC (Windows Server 2022), containing ++ * a PAC with a full checksum. */ + static const krb5_data ticket_data = { +- .length = 972, .data = +- "\x61\x82\x03\xC8\x30\x82\x03\xC4\xA0\x03\x02\x01\x05\xA1\x0A\x1B" +- "\x08\x43\x44\x4F\x4D\x2E\x43\x4F\x4D\xA2\x0F\x30\x0D\xA0\x03\x02" +- "\x01\x01\xA1\x06\x30\x04\x1B\x02\x73\x31\xA3\x82\x03\x9E\x30\x82" +- "\x03\x9A\xA0\x03\x02\x01\x17\xA1\x03\x02\x01\x03\xA2\x82\x03\x8C" +- "\x04\x82\x03\x88\x44\x31\x61\x20\x17\xC9\xFE\xBC\xAC\x46\xB5\x77" +- "\xE9\x68\x04\x4C\x9B\x31\x91\x0C\xC1\xD4\xDD\xEF\xC7\x34\x20\x08" +- "\x90\x91\xE8\x79\xE0\xB5\x03\x26\xA4\x65\xDE\xEC\x47\x03\x2A\x8F" +- "\x61\xE7\x4D\x38\x5A\x42\x95\x5A\xF9\x2F\x41\x2C\x2A\x6E\x60\xA1" +- "\xEB\x51\xB3\xBD\x4C\x00\x41\x2A\x44\x76\x08\x37\x1A\x51\xFD\x65" +- "\x67\x7E\xBF\x3D\x90\x86\xE3\x9A\x54\x6B\x67\xA8\x08\x7A\x73\xCC" +- "\xC3\xB7\x4B\xD5\x5C\x3A\x14\x6C\xC1\x5F\x54\x4B\x92\x55\xB4\xB7" +- "\x92\x23\x3F\x53\x89\x47\x8E\x1F\x8B\xB9\xDB\x3B\x93\xE8\x70\xE4" +- "\x24\xB8\x9D\xF0\x0E\x35\x28\xF8\x7A\x27\x5D\xF7\x25\x97\x9C\xF5" +- "\x9F\x9F\x64\x04\xF2\xA3\xAB\x11\x15\xB6\xDA\x18\xD6\x46\xD5\xE6" +- "\xB8\x08\xDE\x0A\x62\xFD\xF8\xAA\x52\x90\xD9\x67\x29\xB2\xCD\x06" +- "\xB6\xB0\x50\x2B\x3F\x0F\xA3\xA5\xBF\xAA\x6E\x40\x03\xD6\x5F\x02" +- "\xBC\xD8\x18\x47\x97\x09\xD7\xE4\x96\x3B\xCB\xEB\x92\x2C\x3C\x49" +- "\xFF\x1F\x71\xE0\x52\x94\x0F\x8B\x9F\xB8\x2A\xBB\x9C\xE2\xA3\xDD" +- "\x38\x89\xE2\xB1\x0B\x9E\x1F\x7A\xB3\xE3\xD2\xB0\x94\xDC\x87\xBE" +- "\x37\xA6\xD3\xB3\x29\x35\x9A\x72\xC3\x7A\xF1\xA9\xE6\xC5\xD1\x26" +- "\x83\x65\x44\x17\xBA\x55\xA8\x5E\x94\x26\xED\xE9\x8A\x93\x11\x5D" +- "\x7E\x20\x1B\x9C\x15\x9E\x13\x37\x03\x4D\xDD\x99\x51\xD8\x66\x29" +- "\x6A\xB9\xFB\x49\xFE\x52\x78\xDA\x86\x85\xA9\xA3\xB9\xEF\xEC\xAD" +- "\x35\xA6\x8D\xAC\x0F\x75\x22\xBB\x0B\x49\x1C\x13\x52\x40\xC9\x52" +- "\x69\x09\x54\xD1\x0F\x94\x3F\x22\x48\x67\xB0\x96\x28\xAA\xE6\x28" +- "\xD9\x0C\x08\xEF\x51\xED\x15\x5E\xA2\x53\x59\xA5\x03\xB4\x06\x20" +- "\x3D\xCC\xB4\xC5\xF8\x8C\x73\x67\xA3\x21\x3D\x19\xCD\xD4\x12\x28" +- "\xD2\x93\xDE\x0D\xF0\x71\x10\x50\xD6\x33\x35\x04\x11\x64\x43\x39" +- "\xC3\xDF\x96\xE3\x66\xE3\x85\xCA\xE7\x67\x14\x3A\xF0\x43\xAA\xBB" +- "\xD4\x1D\xB5\x24\xB5\x74\x90\x25\xA7\x87\x7E\xDB\xD3\x83\x8A\x3A" +- "\x69\xA8\x2D\xAF\xB7\xB8\xF3\xDC\x13\xAF\x45\x61\x3F\x59\x39\x7E" +- "\x69\xDE\x0C\x04\xF1\x10\x6B\xB4\x56\xFA\x21\x9F\x72\x2B\x60\x86" +- "\xE3\x23\x0E\xC4\x51\xF6\xBE\xD8\xE1\x5F\xEE\x73\x4C\x17\x4C\x2C" +- "\x1B\xFB\x9F\x1F\x7A\x3B\x07\x5B\x8E\xF1\x01\xAC\xD6\x30\x94\x8A" +- "\x5D\x22\x6F\x08\xCE\xED\x5E\xB6\xDB\x86\x8C\x87\xEB\x8D\x91\xFF" +- "\x0A\x86\x30\xBD\xC0\xF8\x25\xE7\xAE\x24\x35\xF2\xFC\xE5\xFD\x1B" +- "\xB0\x05\x4A\xA3\xE5\xEB\x2E\x05\xAD\x99\x67\x49\x87\xE6\xB3\x87" +- "\x82\xA4\x59\xA7\x6E\xDD\xF2\xB6\x66\xE8\xF7\x70\xF5\xBD\xC9\x0E" +- "\xFA\x9C\x79\x84\xD4\x9B\x05\x0E\xBB\xF5\xDB\xEF\xFC\xCC\x26\xF2" +- "\x93\xCF\xD2\x04\x3C\xA9\x2C\x65\x42\x97\x86\xD8\x38\x0A\x1E\xF6" +- "\xD6\xCA\x30\xB5\x1A\xEC\xFB\xBA\x3B\x84\x57\xB0\xFD\xFB\xE6\xBC" +- "\xF2\x76\xF6\x4C\xBB\xAB\xB1\x31\xA1\x27\x7C\xE6\xE6\x81\xB6\xCE" +- "\x84\x86\x40\xB6\x40\x33\xC4\xF8\xB4\x15\xCF\xAA\xA5\x51\x78\xB9" +- "\x8B\x50\x25\xB2\x88\x86\x96\x72\x8C\x71\x4D\xB5\x3A\x94\x86\x77" +- "\x0E\x95\x9B\x16\x93\xEF\x3A\x11\x79\xBA\x83\xF7\x74\xD3\x8D\xBA" +- "\x15\xE1\x2C\x04\x57\xA8\x92\x1E\x9D\x00\x8E\x20\xFD\x30\x70\xE7" +- "\xF5\x65\x2F\x19\x0C\x94\xBA\x03\x71\x12\x96\xCD\xC8\xB4\x96\xDB" +- "\xCE\x19\xC2\xDF\x3C\xC2\xF6\x3D\x53\xED\x98\xA5\x41\x72\x2A\x22" +- "\x7B\xF3\x2B\x17\x6C\xE1\x39\x7D\xAE\x9B\x11\xF9\xC1\xA6\x9E\x9F" +- "\x89\x3C\x12\xAA\x94\x74\xA7\x4F\x70\xE8\xB9\xDE\x04\xF0\x9D\x39" +- "\x24\x2D\x92\xE8\x46\x2D\x2E\xF0\x40\x66\x1A\xD9\x27\xF9\x98\xF1" +- "\x81\x1D\x70\x62\x63\x30\x6D\xCD\x84\x04\x5F\xFA\x83\xD3\xEC\x8D" +- "\x86\xFB\x40\x61\xC1\x8A\x45\xFF\x7B\xD9\xD4\x18\x61\x7F\x51\xE3" +- "\xFC\x1E\x18\xF0\xAF\xC6\x18\x2C\xE1\x6D\x5D\xF9\x62\xFC\x20\xA3" +- "\xB2\x8A\x5F\xE5\xBB\x29\x0F\x99\x63\x07\x88\x38\x3A\x3B\x73\x2A" +- "\x6D\xDA\x3D\xA8\x0D\x8F\x56\x41\x89\x82\xE5\xB8\x61\x00\x64\x7D" +- "\x17\x0C\xCE\x03\x55\x8F\xF4\x5B\x0D\x50\xF2\xEB\x05\x67\xBE\xDB" +- "\x7B\x75\xC5\xEA\xA1\xAB\x1D\xB0\x3C\x6D\x42\x08\x0B\x9A\x45\x20" +- "\xA8\x8F\xE5\x67\x47\x30\xDE\x93\x5F\x43\x05\xEB\xA8\x2D\x80\xF5" +- "\x1A\xB8\x4A\x4E\x42\x2D\x0B\x7A\xDC\x46\x20\x2D\x13\x17\xDD\x4B" +- "\x94\x96\xAA\x1F\x06\x0C\x1F\x62\x07\x9C\x40\xA1" ++ .length = 1307, .data = ++ "\x61\x82\x05\x17\x30\x82\x05\x13\xA0\x03\x02\x01\x05\xA1\x0F\x1B" ++ "\x0D\x57\x32\x30\x32\x32\x2D\x4C\x37\x2E\x42\x41\x53\x45\xA2\x2A" ++ "\x30\x28\xA0\x03\x02\x01\x01\xA1\x21\x30\x1F\x1B\x04\x63\x69\x66" ++ "\x73\x1B\x17\x77\x32\x30\x32\x32\x2D\x31\x31\x38\x2E\x77\x32\x30" ++ "\x32\x32\x2D\x6C\x37\x2E\x62\x61\x73\x65\xA3\x82\x04\xCD\x30\x82" ++ "\x04\xC9\xA0\x03\x02\x01\x12\xA1\x03\x02\x01\x05\xA2\x82\x04\xBB" ++ "\x04\x82\x04\xB7\x44\x5C\x7B\x5A\x3F\x2E\xA3\x50\x34\xDE\xB0\x69" ++ "\x23\x2D\x47\x89\x2C\xC0\xA3\xF9\xDD\x70\xAA\xA5\x1E\xFE\x74\xE5" ++ "\x19\xA2\x4F\x65\x6C\x9E\x00\xB4\x60\x00\x7C\x0C\x29\x43\x31\x99" ++ "\x77\x02\x73\xED\xB9\x40\xF5\xD2\xD1\xC9\x20\x0F\xE3\x38\xF9\xCC" ++ "\x5E\x2A\xBD\x1F\x91\x66\x1A\xD8\x2A\x80\x3C\x2C\x00\x3C\x1E\xC9" ++ "\x2A\x29\x19\x19\x96\x18\x54\x03\x97\x8F\x1D\x5F\xDB\xE9\x66\x68" ++ "\xCD\xB1\xD5\x00\x35\x69\x49\x45\xF1\x6A\x78\x7B\x37\x71\x87\x14" ++ "\x1C\x98\x4D\x69\xCB\x1B\xD8\xF5\xA3\xD8\x53\x4A\x75\x76\x62\xBA" ++ "\x6C\x3F\xEA\x8B\x97\x21\xCA\x8A\x46\x4B\x38\xDA\x09\x9F\x5A\xC8" ++ "\x38\xFF\x34\x97\x5B\xA2\xE5\xBA\xC9\x87\x17\xD8\x08\x05\x7A\x83" ++ "\x04\xD6\x02\x8E\x9B\x18\xB6\x40\x1A\xF7\x47\x25\x24\x3E\x37\x1E" ++ "\xF6\xC1\x3A\x1F\xCA\xB3\x43\x5A\xAE\x94\x83\x31\xAF\xFB\xEE\xED" ++ "\x46\x71\xEF\xE2\x37\x37\x15\xFE\x1B\x0B\x9E\xF8\x3E\x0C\x43\x96" ++ "\xB6\x0A\x04\x78\xF8\x5E\xAA\x33\x1F\xE2\x07\x5A\x8D\xC4\x4E\x32" ++ "\x6D\xD6\xA0\xC5\xEA\x3D\x12\x59\xD4\x41\x40\x4E\xA1\xD8\xBE\xED" ++ "\x17\xCB\x68\xCC\x59\xCB\x53\xB2\x0E\x58\x8A\xA9\x33\x7F\x6F\x2B" ++ "\x37\x89\x08\x44\xBA\xC7\x67\x17\xBB\x91\xF7\xC3\x0F\x00\xF8\xAA" ++ "\xA1\x33\xA6\x08\x47\xCA\xFA\xE8\x49\x27\x45\x46\xF1\xC1\xC3\x5F" ++ "\xE2\x45\x0A\x7D\x64\x52\x8C\x2E\xE1\xDE\xFF\xB2\x64\xEC\x69\x98" ++ "\x15\xDF\x9E\xB1\xEB\xD6\x9D\x08\x06\x4E\x73\xC1\x0B\x71\x21\x05" ++ "\x9E\xBC\xA2\x17\xCF\xB3\x70\xF4\xEF\xB8\x69\xA9\x94\x27\xFD\x5E" ++ "\x72\xB1\x2D\xD2\x20\x1B\x57\x80\xAB\x38\x97\xCF\x22\x68\x4F\xB8" ++ "\xB7\x17\x53\x25\x67\x0B\xED\xD1\x58\x20\x0D\x45\xF9\x09\xFA\xE7" ++ "\x61\x3E\xDB\xC2\x59\x7B\x3A\x3B\x59\x81\x51\xAA\xA4\x81\xF4\x96" ++ "\x3B\xE1\x6F\x6F\xF4\x8E\x68\x9E\xBA\x1E\x0F\xF2\x44\x68\x11\xFC" ++ "\x2B\x5F\xBE\xF2\xEA\x07\x80\xB9\xCA\x9E\x41\xBD\x2F\x81\xF5\x11" ++ "\x2A\x12\xF3\x4F\xD6\x12\x16\x0F\x21\x90\xF1\xD3\x1E\xF1\xA4\x94" ++ "\x46\xEA\x30\xF3\x84\x06\xC1\xA4\x51\xFC\x43\x35\xBD\xEF\x4D\x89" ++ "\x1D\xA5\x44\xB2\x69\xC4\x0F\xBF\x86\x01\x08\x44\x77\xD5\xB4\xB7" ++ "\x5C\x3F\xA7\xD4\x2F\x39\x73\x85\x88\xEE\xB1\x64\x1D\x80\x6C\xEE" ++ "\x6E\x31\x90\x92\x0D\xA1\xB7\xC4\x5C\xCC\xEE\x91\xC8\xCB\x11\x2D" ++ "\x4A\x1A\x7D\x43\x8F\xEB\x60\x09\xED\x1B\x07\x58\xBE\xBC\xBD\x29" ++ "\xF3\xB3\xA3\x4F\xC5\x8A\x30\x33\xB9\xA9\x9F\x43\x08\x27\x15\xC4" ++ "\x9C\x5D\x8E\xBD\x5C\x05\xC6\x05\x9C\x87\x60\x08\x1E\xE2\x52\xB8" ++ "\x45\x8D\x28\xB6\x2C\x15\x46\x74\x9F\x0E\xAA\x6B\x70\x3A\x2A\x55" ++ "\x45\x26\xB2\x58\x4D\x35\xA6\xF1\x96\xBE\x60\xB2\x71\x7B\xF8\x54" ++ "\xB9\x90\x21\x8E\xB9\x0F\x35\x98\x5E\x88\xEB\x1A\x53\xB4\x59\x7F" ++ "\xAF\x69\x1C\x61\x67\xF4\xF6\xBD\xAC\x24\xCD\xB7\xA9\x67\xE8\xA1" ++ "\x83\x85\x5F\x11\x74\x1F\xF7\x4C\x78\x36\xEF\x50\x74\x88\x58\x4B" ++ "\x1A\x9F\x84\x9A\x9A\x05\x92\xEC\x1D\xD5\xF3\xC4\x95\x51\x28\xE2" ++ "\x3F\x32\x87\xB2\xFD\x21\x27\x66\xE4\x6B\x85\x2F\xDC\x7B\xC0\x22" ++ "\xEB\x7A\x94\x20\x5A\x7B\xD3\x7A\xB9\x5B\xF8\x1A\x5A\x84\x4E\xA1" ++ "\x73\x41\x53\xD2\x60\xF7\x7C\xEE\x68\x59\x85\x80\xFC\x3D\x70\x4B" ++ "\x04\x32\xE7\xF2\xFD\xBD\xB3\xD9\x21\xE2\x37\x56\xA2\x16\xCC\xDE" ++ "\x8A\xD3\xBC\x71\xEF\x58\x19\x0E\x45\x8A\x5B\x53\xD6\x77\x30\x6A" ++ "\xA7\xF8\x68\x06\x4E\x07\xCA\xCE\x30\xD7\x35\xAB\x1A\xC7\x18\xD4" ++ "\xC6\x2F\x1A\xFF\xE9\x7A\x94\x0B\x76\x5E\x7E\x29\x0C\xE6\xD3\x3B" ++ "\x5B\x44\x96\xA8\xF1\x29\x23\x95\xD9\x79\xB3\x39\xFC\x76\xED\xE1" ++ "\x1E\x67\x4E\xF7\xE8\x7B\x7A\x12\x9E\xD8\x4B\x35\x09\x0A\xF2\xC1" ++ "\x63\x5B\xEE\xFD\x2A\xC2\xA6\x66\x30\x3C\x1F\x95\xAF\x65\x22\x95" ++ "\x14\x1D\xF5\xD5\xDC\x38\x79\x35\x1C\xCD\x24\x47\xE0\xFD\x08\xC8" ++ "\xF4\x15\x55\x9F\xD9\xC7\xAC\x3F\x67\xB3\x4F\xEB\x26\x7C\x8E\xD6" ++ "\x74\xB3\x0A\xCD\xE7\xFA\xBE\x7E\xA3\x3E\xEC\x61\x50\x77\x52\x56" ++ "\xCF\x90\x5D\x48\xFB\xD4\x2C\x6C\x61\x8B\xDD\x2B\xF5\x92\x1F\x30" ++ "\xBF\x3F\x80\x0D\x31\xDB\xB2\x0B\x7D\x84\xE3\xA6\x42\x7F\x00\x38" ++ "\x44\x02\xC5\xB8\xD9\x58\x29\x9D\x68\x5C\x32\x8B\x76\xAE\xED\x15" ++ "\xF9\x7C\xAE\x7B\xB6\x8E\xD6\x54\x24\xFF\xFA\x87\x05\xEF\x15\x08" ++ "\x5E\x4B\x21\xA2\x2F\x49\xE7\x0F\xC3\xD0\xB9\x49\x22\xEF\xD5\xCA" ++ "\xB2\x11\xF2\x17\xB6\x77\x24\x68\x76\xB2\x07\xF8\x0A\x73\xDD\x65" ++ "\x9C\x75\x64\xF7\xA1\xC6\x23\x08\x84\x72\x3E\x54\x2E\xEB\x9B\x40" ++ "\xA6\x83\x87\xEB\xB5\x00\x40\x4F\xE1\x72\x2A\x59\x3A\x06\x60\x29" ++ "\x7E\x25\x2F\xD8\x80\x40\x8C\x59\xCA\xCF\x8E\x44\xE4\x2D\x84\x7E" ++ "\xCB\xFD\x1E\x3B\xD5\xFF\x9A\xB9\x66\x93\x6D\x5E\xC8\xB7\x13\x26" ++ "\xD6\x38\x1B\x2B\xE1\x87\x96\x05\xD5\xF3\xAB\x68\xF7\x12\x62\x2C" ++ "\x58\xC1\xC9\x85\x3C\x72\xF1\x26\xEE\xC0\x09\x5F\x1D\x4B\xAC\x01" ++ "\x41\xC8\x12\xF8\xF3\x93\x43\x41\xFF\xEC\x0B\x80\xE2\xEE\x20\x85" ++ "\x25\xCD\x6C\x30\x8C\x0D\x24\x2E\xBA\x19\xEA\x28\x7F\xCF\xD5\x10" ++ "\x5C\xE9\xB2\x9D\x5F\x16\xE4\xC0\xF3\xCC\xD9\x68\x4A\x05\x08\x70" ++ "\x17\x26\xC8\x5C\x4A\xBF\x94\x6A\x0E\xD5\xDA\x67\x47\x4B\xAF\x44" ++ "\xE3\x94\xAA\x05\xDB\xA2\x49\x74\xFA\x5C\x69\xAB\x44\xB7\xF7\xBA" ++ "\xAE\x7A\x23\x87\xEB\x54\x7E\x80\xF1\x5B\x60\xA5\x93\xE5\xD4\x24" ++ "\x84\xF7\x0A\x16\x10\xBE\xE9\x4D\xD8\x6B\x15\x40\x5D\x74\xDA\x1B" ++ "\xFF\x2E\x4D\x17\x9D\x35\xF7\x0D\xCF\x66\x38\x0D\x8A\xE4\xDD\x6B" ++ "\xE1\x0F\x1F\xBD\xFD\x4F\x30\x37\x3F\x96\xB4\x92\x54\xD3\x9A\x7A" ++ "\xD1\x5B\x5B\xA9\x54\x16\xE6\x24\xAB\xD4\x23\x39\x7D\xD2\xC7\x09" ++ "\xFA\xD4\x86\x55\x4D\x60\xC2\x87\x67\x6B\xE6" + }; + + static void +@@ -686,7 +710,7 @@ test_pac_ticket_signature(krb5_context context) + { + krb5_error_code ret; + krb5_ticket *ticket; +- krb5_principal sprinc; ++ krb5_principal cprinc, sprinc; + krb5_authdata **authdata1, **authdata2; + krb5_pac pac, pac2, pac3; + uint32_t *list; +@@ -701,7 +725,13 @@ test_pac_ticket_signature(krb5_context context) + if (ret) + err(context, ret, "while decrypting ticket"); + +- ret = krb5_parse_name(context, "s1@CDOM.COM", &sprinc); ++ ret = krb5_parse_name(context, "administrator@W2022-L7.BASE", &cprinc); ++ if (ret) ++ err(context, ret, "krb5_parse_name"); ++ ++ ret = krb5_parse_name(context, ++ "cifs/w2022-118.w2022-l7.base@W2022-L7.BASE", ++ &sprinc); + if (ret) + err(context, ret, "krb5_parse_name"); + +@@ -713,7 +743,7 @@ test_pac_ticket_signature(krb5_context context) + + /* In this test, the server is also the client. */ + ret = krb5_pac_verify(context, pac, ticket->enc_part2->times.authtime, +- ticket->server, NULL, NULL); ++ cprinc, NULL, NULL); + if (ret) + err(context, ret, "while verifying PAC client info"); + +@@ -722,7 +752,7 @@ test_pac_ticket_signature(krb5_context context) + ticket->enc_part2->authorization_data = NULL; + + ret = krb5_kdc_sign_ticket(context, ticket->enc_part2, pac, sprinc, +- sprinc, &ticket_sig_server_key, ++ cprinc, &ticket_sig_server_key, + &ticket_sig_krbtgt_key, FALSE); + if (ret) + err(context, ret, "while signing ticket"); +@@ -781,6 +811,7 @@ test_pac_ticket_signature(krb5_context context) + krb5_pac_free(context, pac); + krb5_pac_free(context, pac2); + krb5_pac_free(context, pac3); ++ krb5_free_principal(context, cprinc); + krb5_free_principal(context, sprinc); + krb5_free_ticket(context, ticket); + } +diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py +index 47ea9e4b47..e934799268 100644 +--- a/src/tests/t_authdata.py ++++ b/src/tests/t_authdata.py +@@ -11,7 +11,7 @@ realm = K5Realm(krb5_conf=conf) + # container. + mark('baseline authdata') + out = realm.run(['./adata', realm.host_princ]) +-if '?128: [6, 7, 10, 16]' not in out or '^-42: Hello' not in out: ++if '?128: [6, 7, 10, 16, 19]' not in out or '^-42: Hello' not in out: + fail('expected authdata not seen for basic request') + + # Requested authdata is copied into the ticket, with KDC-only types +@@ -243,7 +243,7 @@ out = realm.run(['./adata', '-p', realm.user_princ, 'service/2']) + if '+97: [indcl]' not in out or '[inds1]' in out: + fail('correct auth-indicator not seen for S4U2Proxy req') + # Make sure a PAC with an S4U_DELEGATION_INFO(11) buffer is included. +-if '?128: [1, 6, 7, 10, 11, 16]' not in out: ++if '?128: [1, 6, 7, 10, 11, 16, 19]' not in out: + fail('PAC with delegation info not seen for S4U2Proxy req') + + # Get another S4U2Proxy ticket including request-authdata. +-- +2.39.1 + diff --git a/krb5.spec b/krb5.spec index 3592f20..7800eea 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 8 +%global baserelease 9 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -75,6 +75,7 @@ Patch13: 0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch Patch14: 0014-downstream-Include-missing-OpenSSL-FIPS-header.patch Patch15: 0015-downstream-Do-not-set-root-as-ksu-file-owner.patch Patch16: 0016-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch +Patch17: 0017-Add-PAC-full-checksums.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -711,6 +712,10 @@ exit 0 %{_datarootdir}/%{name}-tests/ %changelog +* Tue Jan 31 2023 Julien Rische - 1.20.1-9 +- Add support for MS-PAC extended KDC signature (CVE-2022-37967) +- Resolves: rhbz#2166001 + * Mon Jan 30 2023 Julien Rische - 1.20.1-8 - Bypass FIPS restrictions to use KRB5KDF in case AES SHA-1 HMAC is enabled - Lazily load MD4/5 from OpenSSL if using RADIUS or RC4 enctype in FIPS mode From 0b340d0ef341c3e83f88fd931ea21d24eb9cd051 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Mon, 12 Jun 2023 16:21:32 +0200 Subject: [PATCH 284/304] New upstream version (1.21) Do not disable PKINIT if some of the well-known DH groups are unavailable Resolves: rhbz#2214297 Make PKINIT CMS SHA-1 signature verification available in FIPS mode Resolves: rhbz#2214300 Allow to set PAC ticket signature as optional Resolves: rhbz#2181311 Add support for MS-PAC extended KDC signature (CVE-2022-37967) Resolves: rhbz#2166001 Fix syntax error in aclocal.m4 Resolves: rhbz#2143306 Signed-off-by: Julien Rische --- .gitignore | 2 + 0001-downstream-ksu-pam-integration.patch | 10 +- 0002-downstream-SELinux-integration.patch | 38 +- ...ownstream-fix-debuginfo-with-y.tab.c.patch | 4 +- 0004-downstream-Remove-3des-support.patch | 172 ++--- ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 8 +- ...-krad-UDP-TCP-localhost-connection-w.patch | 7 +- ...-variable-for-default-PKCS-11-module.patch | 201 ------ ...tests-compatible-with-sssd_krb5_loca.patch | 4 +- ...asonable-supportedCMSTypes-in-PKINIT.patch | 159 ----- ...-Include-missing-OpenSSL-FIPS-header.patch | 4 +- 0009-Simplify-plugin-loading-code.patch | 622 ---------------- ...am-Do-not-set-root-as-ksu-file-owner.patch | 4 +- ...rror-checking-for-OpenSSL-CMS_verify.patch | 48 -- ...low-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch | 4 +- ...-to-set-PAC-ticket-signature-as-opti.patch | 279 ++++++++ ...-SHA-1-digest-disallowed-error-for-P.patch | 28 - 0012-Add-and-use-ts_interval-helper.patch | 239 ------- ...PKINIT-CMS-SHA-1-signature-verificat.patch | 47 ++ ...T-if-at-least-one-group-is-available.patch | 218 ++++++ 0017-Add-PAC-full-checksums.patch | 672 ------------------ krb5-tests | 5 +- krb5.spec | 165 +++-- sources | 4 +- 24 files changed, 768 insertions(+), 2176 deletions(-) delete mode 100644 0007-Add-configure-variable-for-default-PKCS-11-module.patch rename 0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch => 0007-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch (94%) delete mode 100644 0008-Set-reasonable-supportedCMSTypes-in-PKINIT.patch rename 0014-downstream-Include-missing-OpenSSL-FIPS-header.patch => 0008-downstream-Include-missing-OpenSSL-FIPS-header.patch (98%) delete mode 100644 0009-Simplify-plugin-loading-code.patch rename 0015-downstream-Do-not-set-root-as-ksu-file-owner.patch => 0009-downstream-Do-not-set-root-as-ksu-file-owner.patch (93%) delete mode 100644 0010-Update-error-checking-for-OpenSSL-CMS_verify.patch rename 0016-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch => 0010-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch (98%) create mode 100644 0011-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch delete mode 100644 0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch delete mode 100644 0012-Add-and-use-ts_interval-helper.patch create mode 100644 0012-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch create mode 100644 0013-Enable-PKINIT-if-at-least-one-group-is-available.patch delete mode 100644 0017-Add-PAC-full-checksums.patch diff --git a/.gitignore b/.gitignore index 7fa0027..7db6eaa 100644 --- a/.gitignore +++ b/.gitignore @@ -202,3 +202,5 @@ /krb5-1.19.2.tar.gz.asc /krb5-1.20.1.tar.gz /krb5-1.20.1.tar.gz.asc +/krb5-1.21.tar.gz +/krb5-1.21.tar.gz.asc diff --git a/0001-downstream-ksu-pam-integration.patch b/0001-downstream-ksu-pam-integration.patch index 2b737c0..d33704a 100644 --- a/0001-downstream-ksu-pam-integration.patch +++ b/0001-downstream-ksu-pam-integration.patch @@ -1,4 +1,4 @@ -From 37d69135d0be7f46732c401cdbb3abc075bf4117 Mon Sep 17 00:00:00 2001 +From 67c82a09c6c53713c281045cd55de2720cd06907 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] [downstream] ksu pam integration @@ -30,7 +30,7 @@ Last-updated: krb5-1.18-beta1 create mode 100644 src/clients/ksu/pam.h diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index 9920476f91..bf9da35bbc 100644 +index 3d66a876b3..ce3c5a9bac 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 @@ -1458,3 +1458,72 @@ if test "$with_ldap" = yes; then @@ -760,10 +760,10 @@ index 0000000000..0ab76569cb +void appl_pam_cleanup(void); +#endif diff --git a/src/configure.ac b/src/configure.ac -index f03028b5fd..aa970b0447 100644 +index 77be7a2025..587221936e 100644 --- a/src/configure.ac +++ b/src/configure.ac -@@ -1400,6 +1400,8 @@ AC_SUBST([VERTO_VERSION]) +@@ -1399,6 +1399,8 @@ AC_SUBST([VERTO_VERSION]) AC_PATH_PROG(GROFF, groff) @@ -773,5 +773,5 @@ index f03028b5fd..aa970b0447 100644 if test "${localedir+set}" != set; then localedir='$(datadir)/locale' -- -2.38.1 +2.40.1 diff --git a/0002-downstream-SELinux-integration.patch b/0002-downstream-SELinux-integration.patch index 4271d66..840c2a3 100644 --- a/0002-downstream-SELinux-integration.patch +++ b/0002-downstream-SELinux-integration.patch @@ -1,4 +1,4 @@ -From c6b58ed180ed91b579d322ff5004f68750f1eb4f Mon Sep 17 00:00:00 2001 +From dfbac76ab7bb7e6e2c3171eefcaa93573e6b630e Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] [downstream] SELinux integration @@ -69,7 +69,7 @@ Last-updated: krb5-1.20.1 create mode 100644 src/util/support/selinux.c diff --git a/src/aclocal.m4 b/src/aclocal.m4 -index bf9da35bbc..01283f482e 100644 +index ce3c5a9bac..3331970930 100644 --- a/src/aclocal.m4 +++ b/src/aclocal.m4 @@ -85,6 +85,7 @@ AC_SUBST_FILE(libnodeps_frag) @@ -133,10 +133,10 @@ index bf9da35bbc..01283f482e 100644 +AC_SUBST(SELINUX_LIBS) +])dnl diff --git a/src/build-tools/krb5-config.in b/src/build-tools/krb5-config.in -index dead0dddce..fef3e054fc 100755 +index 8e6eb86601..7677f37359 100755 --- a/src/build-tools/krb5-config.in +++ b/src/build-tools/krb5-config.in -@@ -41,6 +41,7 @@ DL_LIB='@DL_LIB@' +@@ -40,6 +40,7 @@ DL_LIB='@DL_LIB@' DEFCCNAME='@DEFCCNAME@' DEFKTNAME='@DEFKTNAME@' DEFCKTNAME='@DEFCKTNAME@' @@ -144,7 +144,7 @@ index dead0dddce..fef3e054fc 100755 LIBS='@LIBS@' GEN_LIB=@GEN_LIB@ -@@ -254,7 +255,7 @@ if test -n "$do_libs"; then +@@ -253,7 +254,7 @@ if test -n "$do_libs"; then fi # If we ever support a flag to generate output suitable for static @@ -175,10 +175,10 @@ index a0c60c70b3..7eaa2f351c 100644 GSS_LIBS = $(GSS_KRB5_LIB) # needs fixing if ever used on macOS! diff --git a/src/configure.ac b/src/configure.ac -index aa970b0447..40545f2bfc 100644 +index 587221936e..69be9030f8 100644 --- a/src/configure.ac +++ b/src/configure.ac -@@ -1402,6 +1402,8 @@ AC_PATH_PROG(GROFF, groff) +@@ -1401,6 +1401,8 @@ AC_PATH_PROG(GROFF, groff) KRB5_WITH_PAM @@ -188,7 +188,7 @@ index aa970b0447..40545f2bfc 100644 if test "${localedir+set}" != set; then localedir='$(datadir)/locale' diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 44dc1eeb3f..c3aecba7d4 100644 +index 2f7791b775..9c534faa8a 100644 --- a/src/include/k5-int.h +++ b/src/include/k5-int.h @@ -128,6 +128,7 @@ typedef unsigned char u_char; @@ -238,7 +238,7 @@ index 0000000000..dfaaa847cb +#endif +#endif diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index c0194c3c94..7e1dea2cbf 100644 +index 9c76780181..dd6430ece8 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin @@ -87,6 +87,12 @@ @@ -290,10 +290,10 @@ index a89b5144f6..4d6cc0bdf9 100644 com_err(progname, errno, _("while creating 'ok' file, '%s'"), file_ok); goto cleanup; diff --git a/src/kdc/main.c b/src/kdc/main.c -index 38b9299066..085afc9220 100644 +index bfdfef5c48..b43fe9a082 100644 --- a/src/kdc/main.c +++ b/src/kdc/main.c -@@ -848,7 +848,7 @@ write_pid_file(const char *path) +@@ -844,7 +844,7 @@ write_pid_file(const char *path) FILE *file; unsigned long pid; @@ -303,7 +303,7 @@ index 38b9299066..085afc9220 100644 return errno; pid = (unsigned long) getpid(); diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c -index f2341d720f..ffdac9f397 100644 +index aa3c81ea30..cb9785aaeb 100644 --- a/src/kprop/kpropd.c +++ b/src/kprop/kpropd.c @@ -488,6 +488,9 @@ doit(int fd) @@ -333,10 +333,10 @@ index f2341d720f..ffdac9f397 100644 KRB5_LOCKMODE_EXCLUSIVE | KRB5_LOCKMODE_DONTBLOCK); if (retval) { diff --git a/src/lib/kadm5/logger.c b/src/lib/kadm5/logger.c -index c6885edf2a..9aec3c05e8 100644 +index e14da53790..b879a4049b 100644 --- a/src/lib/kadm5/logger.c +++ b/src/lib/kadm5/logger.c -@@ -309,7 +309,7 @@ krb5_klog_init(krb5_context kcontext, char *ename, char *whoami, krb5_boolean do +@@ -310,7 +310,7 @@ krb5_klog_init(krb5_context kcontext, char *ename, char *whoami, krb5_boolean do */ append = (cp[4] == ':') ? O_APPEND : 0; if (append || cp[4] == '=') { @@ -345,7 +345,7 @@ index c6885edf2a..9aec3c05e8 100644 S_IRUSR | S_IWUSR | S_IRGRP); if (fd != -1) f = fdopen(fd, append ? "a" : "w"); -@@ -776,7 +776,7 @@ krb5_klog_reopen(krb5_context kcontext) +@@ -777,7 +777,7 @@ krb5_klog_reopen(krb5_context kcontext) * In case the old logfile did not get moved out of the * way, open for append to prevent squashing the old logs. */ @@ -439,10 +439,10 @@ index e510211fc5..f3ea28c8ec 100644 goto report_errno; writevno = 1; diff --git a/src/lib/krb5/os/trace.c b/src/lib/krb5/os/trace.c -index 3369fc4ba6..95f82cda03 100644 +index 4cbbbb270a..c4058ddc96 100644 --- a/src/lib/krb5/os/trace.c +++ b/src/lib/krb5/os/trace.c -@@ -459,7 +459,7 @@ krb5_set_trace_filename(krb5_context context, const char *filename) +@@ -460,7 +460,7 @@ krb5_set_trace_filename(krb5_context context, const char *filename) fd = malloc(sizeof(*fd)); if (fd == NULL) return ENOMEM; @@ -452,7 +452,7 @@ index 3369fc4ba6..95f82cda03 100644 free(fd); return errno; diff --git a/src/plugins/kdb/db2/adb_openclose.c b/src/plugins/kdb/db2/adb_openclose.c -index 7db30a33b0..2b9d01921d 100644 +index 9a506e9d44..f92ab47143 100644 --- a/src/plugins/kdb/db2/adb_openclose.c +++ b/src/plugins/kdb/db2/adb_openclose.c @@ -152,7 +152,7 @@ osa_adb_init_db(osa_adb_db_t *dbp, char *filename, char *lockfilename, @@ -1034,5 +1034,5 @@ index 0000000000..807d039da3 + +#endif /* USE_SELINUX */ -- -2.38.1 +2.40.1 diff --git a/0003-downstream-fix-debuginfo-with-y.tab.c.patch b/0003-downstream-fix-debuginfo-with-y.tab.c.patch index 3c58cc1..40361ac 100644 --- a/0003-downstream-fix-debuginfo-with-y.tab.c.patch +++ b/0003-downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,4 +1,4 @@ -From c7fe7cbd61f7debf052ddcc6cc5f01bb7e4f5385 Mon Sep 17 00:00:00 2001 +From a9c463ed5988c860ebb18de212d6c56da1cb1169 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] [downstream] fix debuginfo with y.tab.c @@ -40,5 +40,5 @@ index 8669c2436c..a22f23c02c 100644 install: $(INSTALL_PROGRAM) $(PROG) ${DESTDIR}$(ADMIN_BINDIR)/$(PROG) -- -2.38.1 +2.40.1 diff --git a/0004-downstream-Remove-3des-support.patch b/0004-downstream-Remove-3des-support.patch index 4ec3a0f..f7b5134 100644 --- a/0004-downstream-Remove-3des-support.patch +++ b/0004-downstream-Remove-3des-support.patch @@ -1,4 +1,4 @@ -From 7b40250066bbcc529b5348b68199c58fbad82376 Mon Sep 17 00:00:00 2001 +From 0691db92e13e0d224c2c9dd72c1421d8f7c3c078 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] [downstream] Remove 3des support @@ -32,7 +32,7 @@ Last-updated: 1.20-final src/include/krb5/krb5.hin | 10 +- src/kdc/kdc_util.c | 4 - src/lib/crypto/Makefile.in | 8 +- - src/lib/crypto/builtin/Makefile.in | 6 +- + src/lib/crypto/builtin/Makefile.in | 4 +- src/lib/crypto/builtin/des/ISSUES | 13 - src/lib/crypto/builtin/des/Makefile.in | 82 ---- src/lib/crypto/builtin/des/d3_aead.c | 137 ------ @@ -74,7 +74,7 @@ Last-updated: 1.20-final src/lib/crypto/krb/prf_des.c | 47 --- src/lib/crypto/krb/random_to_key.c | 28 -- src/lib/crypto/libk5crypto.exports | 1 - - src/lib/crypto/openssl/Makefile.in | 8 +- + src/lib/crypto/openssl/Makefile.in | 4 +- src/lib/crypto/openssl/des/Makefile.in | 20 - src/lib/crypto/openssl/des/deps | 14 - src/lib/crypto/openssl/des/des_keys.c | 39 -- @@ -98,18 +98,19 @@ Last-updated: 1.20-final src/plugins/preauth/pkinit/pkinit_crypto.h | 10 +- src/plugins/preauth/pkinit/pkinit_kdf_test.c | 30 -- src/plugins/preauth/spake/t_vectors.c | 25 -- - src/tests/gssapi/t_enctypes.py | 33 +- + src/tests/gssapi/t_enctypes.py | 34 +- src/tests/gssapi/t_invalid.c | 12 - src/tests/gssapi/t_pcontok.c | 16 +- src/tests/gssapi/t_prf.c | 7 - src/tests/t_authdata.py | 2 +- - src/tests/t_etype_info.py | 18 +- + src/tests/t_etype_info.py | 20 +- src/tests/t_keyrollover.py | 8 +- src/tests/t_mkey.py | 35 -- src/tests/t_salt.py | 5 +- + src/tests/t_sesskeynego.py | 8 - src/util/k5test.py | 7 - .../leash/htmlhelp/html/Encryption_Types.htm | 13 - - 89 files changed, 151 insertions(+), 4713 deletions(-) + 90 files changed, 149 insertions(+), 4720 deletions(-) delete mode 100644 src/lib/crypto/builtin/des/ISSUES delete mode 100644 src/lib/crypto/builtin/des/Makefile.in delete mode 100644 src/lib/crypto/builtin/des/d3_aead.c @@ -199,10 +200,10 @@ index 74a0a2acef..846c58ed82 100644 While **aes128-cts** and **aes256-cts** are supported for all Kerberos diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst -index 694922c0d9..c4d5499d3b 100644 +index dce19ad43e..2b4ed7da0b 100644 --- a/doc/admin/enctypes.rst +++ b/doc/admin/enctypes.rst -@@ -129,7 +129,7 @@ enctype weak? krb5 Windows +@@ -146,7 +146,7 @@ enctype weak? krb5 Windows des-cbc-crc weak <1.18 >=2000 des-cbc-md4 weak <1.18 ? des-cbc-md5 weak <1.18 >=2000 @@ -211,7 +212,7 @@ index 694922c0d9..c4d5499d3b 100644 arcfour-hmac deprecated >=1.3 >=2000 arcfour-hmac-exp weak >=1.3 >=2000 aes128-cts-hmac-sha1-96 >=1.3 >=Vista -@@ -148,9 +148,11 @@ default. +@@ -165,9 +165,11 @@ default. krb5 releases 1.17 and later flag deprecated encryption types (including ``des3-cbc-sha1`` and ``arcfour-hmac``) in KDC logs and kadmin output. krb5 release 1.19 issues a warning during initial @@ -247,7 +248,7 @@ index ade5e1f87a..e4dc54f7e5 100644 .. _err_cert_chain_cert_expired: diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst -index a0d4f26701..5f34dea5e8 100644 +index 45fe160d7f..b4b1f3bd93 100644 --- a/doc/appdev/refs/macros/index.rst +++ b/doc/appdev/refs/macros/index.rst @@ -36,7 +36,6 @@ Public @@ -259,10 +260,10 @@ index a0d4f26701..5f34dea5e8 100644 CKSUMTYPE_NIST_SHA.rst CKSUMTYPE_RSA_MD4.rst diff --git a/doc/conf.py b/doc/conf.py -index fa0eb80f1f..12168fa695 100644 +index cd76f5999f..1e1cfce80c 100644 --- a/doc/conf.py +++ b/doc/conf.py -@@ -278,7 +278,7 @@ else: +@@ -281,7 +281,7 @@ else: rst_epilog += ''' .. |krb5conf| replace:: ``/etc/krb5.conf`` .. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal`` @@ -272,7 +273,7 @@ index fa0eb80f1f..12168fa695 100644 .. |copy| unicode:: U+000A9 ''' diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst -index ca2d6ef117..100c64a1c1 100644 +index 10effcf175..cad0855724 100644 --- a/doc/mitK5features.rst +++ b/doc/mitK5features.rst @@ -37,7 +37,7 @@ Database backends: LDAP, DB2, LMDB @@ -307,10 +308,10 @@ index 8f14e9bf2c..ba3bb18eec 100644 ##DOS## $(WCONFIG) config < $@.in > $@ ##DOS##lib\crypto\builtin\camellia\Makefile: lib\crypto\builtin\camellia\Makefile.in $(MKFDEP) diff --git a/src/configure.ac b/src/configure.ac -index 40545f2bfc..8dc864718d 100644 +index 69be9030f8..2561e917a2 100644 --- a/src/configure.ac +++ b/src/configure.ac -@@ -1489,12 +1489,12 @@ V5_AC_OUTPUT_MAKEFILE(. +@@ -1513,12 +1513,12 @@ V5_AC_OUTPUT_MAKEFILE(. lib lib/kdb lib/crypto lib/crypto/krb lib/crypto/crypto_tests @@ -326,7 +327,7 @@ index 40545f2bfc..8dc864718d 100644 lib/krb5 lib/krb5/error_tables lib/krb5/asn.1 lib/krb5/ccache diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 7e1dea2cbf..fb9f2a366c 100644 +index dd6430ece8..350bcf86f2 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin @@ -426,8 +426,8 @@ typedef struct _krb5_crypto_iov { @@ -362,10 +363,10 @@ index 7e1dea2cbf..fb9f2a366c 100644 #define CKSUMTYPE_HMAC_SHA1_96_AES128 0x000f /**< RFC 3962. Used with ENCTYPE_AES128_CTS_HMAC_SHA1_96 */ diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index 9f2a67d189..b7a9aa4992 100644 +index e54cc751f9..ea10e23a95 100644 --- a/src/kdc/kdc_util.c +++ b/src/kdc/kdc_util.c -@@ -1111,8 +1111,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) +@@ -1164,8 +1164,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) name = "rsaEncryption-EnvOID"; else if (ktype == ENCTYPE_RSA_ES_OAEP_ENV) name = "id-RSAES-OAEP-EnvOID"; @@ -374,7 +375,7 @@ index 9f2a67d189..b7a9aa4992 100644 else return krb5_enctype_to_name(ktype, FALSE, buf, buflen); -@@ -1704,8 +1702,6 @@ krb5_boolean +@@ -1657,8 +1655,6 @@ krb5_boolean enctype_requires_etype_info_2(krb5_enctype enctype) { switch(enctype) { @@ -414,7 +415,7 @@ index 10e8c74cf8..25c4f40cc3 100644 all-unix: all-liblinks install-unix: install-libs diff --git a/src/lib/crypto/builtin/Makefile.in b/src/lib/crypto/builtin/Makefile.in -index daf19da195..c9e967c807 100644 +index 243bb17ba3..30bfcd30c0 100644 --- a/src/lib/crypto/builtin/Makefile.in +++ b/src/lib/crypto/builtin/Makefile.in @@ -1,6 +1,6 @@ @@ -429,15 +430,6 @@ index daf19da195..c9e967c807 100644 $(srcdir)/kdf.c \ $(srcdir)/pbkdf2.c --STOBJLISTS= des/OBJS.ST md4/OBJS.ST \ -+STOBJLISTS= md4/OBJS.ST \ - md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \ - enc_provider/OBJS.ST \ - hash_provider/OBJS.ST \ -@@ -33,7 +33,7 @@ STOBJLISTS= des/OBJS.ST md4/OBJS.ST \ - camellia/OBJS.ST \ - OBJS.ST - -SUBDIROBJLISTS= des/OBJS.ST md4/OBJS.ST \ +SUBDIROBJLISTS= md4/OBJS.ST \ md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \ @@ -4862,7 +4854,7 @@ index 052f4d4b51..d8ffa63304 100644 krb5int_camellia_encrypt krb5int_cmac_checksum diff --git a/src/lib/crypto/openssl/Makefile.in b/src/lib/crypto/openssl/Makefile.in -index 08de047d0a..88f7fd0a09 100644 +index cf11f6847b..8e4cdb8bbf 100644 --- a/src/lib/crypto/openssl/Makefile.in +++ b/src/lib/crypto/openssl/Makefile.in @@ -1,6 +1,6 @@ @@ -4873,32 +4865,15 @@ index 08de047d0a..88f7fd0a09 100644 LOCALINCLUDES=-I$(srcdir)/../krb $(CRYPTO_IMPL_CFLAGS) STLIBOBJS=\ -@@ -24,14 +24,14 @@ SRCS=\ +@@ -24,7 +24,7 @@ SRCS=\ $(srcdir)/pbkdf2.c \ $(srcdir)/sha256.c --STOBJLISTS= des/OBJS.ST md4/OBJS.ST \ -+STOBJLISTS= md4/OBJS.ST \ - md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \ - enc_provider/OBJS.ST \ - hash_provider/OBJS.ST \ - aes/OBJS.ST \ - OBJS.ST - -SUBDIROBJLISTS= des/OBJS.ST md4/OBJS.ST \ +SUBDIROBJLISTS= md4/OBJS.ST \ md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \ enc_provider/OBJS.ST \ hash_provider/OBJS.ST \ -@@ -42,7 +42,7 @@ includes: depend - - depend: $(SRCS) - --clean-unix:: clean-libobjs -+clean-unix:: clean-libobjsn - - @lib_frag@ - @libobj_frag@ diff --git a/src/lib/crypto/openssl/des/Makefile.in b/src/lib/crypto/openssl/des/Makefile.in deleted file mode 100644 index a6cece1dd1..0000000000 @@ -5244,10 +5219,10 @@ index 41e845eae0..5a43c3d9eb 100644 } diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index d4e90793f9..1bc807172b 100644 +index b35e11bfb6..d7c2ad321e 100644 --- a/src/lib/gssapi/krb5/accept_sec_context.c +++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -1030,7 +1030,6 @@ kg_accept_krb5(minor_status, context_handle, +@@ -1026,7 +1026,6 @@ kg_accept_krb5(minor_status, context_handle, } switch (negotiated_etype) { @@ -5256,7 +5231,7 @@ index d4e90793f9..1bc807172b 100644 case ENCTYPE_ARCFOUR_HMAC_EXP: /* RFC 4121 accidentally omits RC4-HMAC-EXP as a "not-newer" diff --git a/src/lib/gssapi/krb5/gssapiP_krb5.h b/src/lib/gssapi/krb5/gssapiP_krb5.h -index a4446530fc..88d41130a7 100644 +index 7364607198..5aeb69aebc 100644 --- a/src/lib/gssapi/krb5/gssapiP_krb5.h +++ b/src/lib/gssapi/krb5/gssapiP_krb5.h @@ -125,14 +125,14 @@ enum sgn_alg { @@ -5286,10 +5261,10 @@ index a4446530fc..88d41130a7 100644 }; diff --git a/src/lib/gssapi/krb5/k5seal.c b/src/lib/gssapi/krb5/k5seal.c -index d1cdce486f..7f7146a0a2 100644 +index 99275be53a..0e5d10b115 100644 --- a/src/lib/gssapi/krb5/k5seal.c +++ b/src/lib/gssapi/krb5/k5seal.c -@@ -136,19 +136,12 @@ make_seal_token_v1 (krb5_context context, +@@ -142,19 +142,12 @@ make_seal_token_v1 (krb5_context context, /* pad the plaintext, encrypt if needed, and stick it in the token */ @@ -5315,7 +5290,7 @@ index d1cdce486f..7f7146a0a2 100644 code = krb5_c_checksum_length(context, md5cksum.checksum_type, &sumlen); if (code) { -@@ -196,20 +189,8 @@ make_seal_token_v1 (krb5_context context, +@@ -203,20 +196,8 @@ make_seal_token_v1 (krb5_context context, gssalloc_free(t); return(code); } @@ -5327,22 +5302,22 @@ index d1cdce486f..7f7146a0a2 100644 - */ - if (md5cksum.length != cksum_size) - abort (); -- memcpy (ptr+14, md5cksum.contents, md5cksum.length); +- memcpy(checksum, md5cksum.contents, md5cksum.length); - break; - case SGN_ALG_HMAC_MD5: -- memcpy (ptr+14, md5cksum.contents, cksum_size); +- memcpy(checksum, md5cksum.contents, cksum_size); - break; - } + -+ memcpy (ptr+14, md5cksum.contents, cksum_size); ++ memcpy(checksum, md5cksum.contents, cksum_size); krb5_free_checksum_contents(context, &md5cksum); diff --git a/src/lib/gssapi/krb5/k5sealiov.c b/src/lib/gssapi/krb5/k5sealiov.c -index 9bb2ee1099..9147bb2c78 100644 +index 7bf7609a48..d5e12cb436 100644 --- a/src/lib/gssapi/krb5/k5sealiov.c +++ b/src/lib/gssapi/krb5/k5sealiov.c -@@ -144,18 +144,11 @@ make_seal_token_v1_iov(krb5_context context, +@@ -147,18 +147,11 @@ make_seal_token_v1_iov(krb5_context context, /* pad the plaintext, encrypt if needed, and stick it in the token */ /* initialize the checksum */ @@ -5366,20 +5341,20 @@ index 9bb2ee1099..9147bb2c78 100644 code = krb5_c_checksum_length(context, md5cksum.checksum_type, &k5_trailerlen); if (code != 0) -@@ -177,15 +170,7 @@ make_seal_token_v1_iov(krb5_context context, +@@ -182,15 +175,7 @@ make_seal_token_v1_iov(krb5_context context, if (code != 0) goto cleanup; - switch (ctx->signalg) { - case SGN_ALG_HMAC_SHA1_DES3_KD: - assert(md5cksum.length == ctx->cksum_size); -- memcpy(ptr + 14, md5cksum.contents, md5cksum.length); +- memcpy(checksum, md5cksum.contents, md5cksum.length); - break; - case SGN_ALG_HMAC_MD5: -- memcpy(ptr + 14, md5cksum.contents, ctx->cksum_size); +- memcpy(checksum, md5cksum.contents, ctx->cksum_size); - break; - } -+ memcpy(ptr + 14, md5cksum.contents, ctx->cksum_size); ++ memcpy(checksum, md5cksum.contents, ctx->cksum_size); /* create the seq_num */ code = kg_make_seq_num(context, ctx->seq, ctx->initiate ? 0 : 0xFF, @@ -5618,7 +5593,7 @@ index 84f1949887..32150f5e34 100644 case ENCTYPE_ARCFOUR_HMAC_EXP: /* RFC 4121 accidentally omits RC4-HMAC-EXP as a "not-newer" enctype, diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index 87b486c53f..2b5abcd817 100644 +index a6c2bbeb54..18290b764b 100644 --- a/src/lib/krb5/krb/init_ctx.c +++ b/src/lib/krb5/krb/init_ctx.c @@ -59,7 +59,6 @@ @@ -5629,7 +5604,7 @@ index 87b486c53f..2b5abcd817 100644 ENCTYPE_ARCFOUR_HMAC, ENCTYPE_CAMELLIA128_CTS_CMAC, ENCTYPE_CAMELLIA256_CTS_CMAC, 0 -@@ -450,8 +449,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, +@@ -460,8 +459,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, /* Set all enctypes in the default list. */ for (i = 0; default_list[i]; i++) mod_list(default_list[i], sel, weak, &list); @@ -5769,10 +5744,10 @@ index e3d2846315..586661bb7e 100644 #define CKK_CAST3 (0x17) #define CKK_CAST128 (0x18) diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h -index 94a1b22fb1..65f6210727 100644 +index e22798f668..9fa315d7a0 100644 --- a/src/plugins/preauth/pkinit/pkinit_crypto.h +++ b/src/plugins/preauth/pkinit/pkinit_crypto.h -@@ -376,11 +376,11 @@ krb5_error_code server_process_dh +@@ -370,11 +370,11 @@ krb5_error_code server_process_dh * krb5_algorithm_identifier */ krb5_error_code create_krb5_supportedCMSTypes @@ -5874,10 +5849,10 @@ index 2279202d3a..96b0307d78 100644 /* initial key, w, x, y, T, S, K */ "8846F7EAEE8FB117AD06BDD830B7586C", diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py -index 7494d7fcdb..2f95d89967 100755 +index f5f11842e2..1bb8c40b6b 100755 --- a/src/tests/gssapi/t_enctypes.py +++ b/src/tests/gssapi/t_enctypes.py -@@ -1,24 +1,17 @@ +@@ -1,25 +1,17 @@ from k5test import * -# Define some convenience abbreviations for enctypes we will see in @@ -5901,13 +5876,14 @@ index 7494d7fcdb..2f95d89967 100755 # These tests make assumptions about the default enctype lists, so set # them explicitly rather than relying on the library defaults. -supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal' --conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4'}, +-conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4', +- 'allow_des3': 'true', 'allow_rc4': 'true'}, +supp='aes256-cts:normal aes128-cts:normal rc4-hmac:normal' -+conf = {'libdefaults': {'permitted_enctypes': 'aes rc4'}, ++conf = {'libdefaults': {'permitted_enctypes': 'aes rc4', 'allow_rc4': 'true'}, 'realms': {'$realm': {'supported_enctypes': supp}}} realm = K5Realm(krb5_conf=conf) shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save')) -@@ -87,19 +80,12 @@ test('both aes128', 'aes128-cts', 'aes128-cts', +@@ -88,19 +80,12 @@ test('both aes128', 'aes128-cts', 'aes128-cts', test_err('acc aes128', None, 'aes128-cts', 'Encryption type aes256-cts-hmac-sha1-96 not permitted') @@ -5928,7 +5904,7 @@ index 7494d7fcdb..2f95d89967 100755 # subkey. test('upgrade noargs', None, None, tktenc=aes256, tktsession=d_rc4, -@@ -115,13 +101,6 @@ test('upgrade init aes128+rc4', 'aes128-cts rc4', None, +@@ -116,13 +101,6 @@ test('upgrade init aes128+rc4', 'aes128-cts rc4', None, tktenc=aes256, tktsession=d_rc4, proto='cfx', isubkey=rc4, asubkey=aes128) @@ -6019,10 +5995,10 @@ index f71774cdc9..d1857c433f 100644 "3BB3AE288C12B3B9D06B208A4151B3B6", "9AEA11A3BCF3C53F1F91F5A0BA2132E2501ADF5F3C28" diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py -index 97e2474bf8..47ea9e4b47 100644 +index bde1c36844..8fcd30db51 100644 --- a/src/tests/t_authdata.py +++ b/src/tests/t_authdata.py -@@ -164,7 +164,7 @@ realm.run([kvno, 'restricted']) +@@ -179,7 +179,7 @@ realm.run([kvno, 'restricted']) # preferred krbtgt enctype changes. mark('#8139 regression test') realm.kinit(realm.user_princ, password('user'), ['-f']) @@ -6032,17 +6008,19 @@ index 97e2474bf8..47ea9e4b47 100644 realm.run(['./forward']) realm.run([kvno, realm.host_princ]) diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py -index c982508d8b..96e90a69d2 100644 +index 38cf96ca8f..e82ff7ff07 100644 --- a/src/tests/t_etype_info.py +++ b/src/tests/t_etype_info.py -@@ -1,6 +1,6 @@ +@@ -1,7 +1,7 @@ from k5test import * -supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac' +-conf = {'libdefaults': {'allow_des3': 'true', 'allow_rc4': 'true'}, +supported_enctypes = 'aes128-cts rc4-hmac' - conf = {'libdefaults': {'allow_weak_crypto': 'true'}, ++conf = {'libdefaults': {'allow_rc4': 'true'}, 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) + @@ -26,9 +26,9 @@ def test_etinfo(princ, enctypes, expected_lines): # With no newer enctypes in the request, PA-ETYPE-INFO2, # PA-ETYPE-INFO, and PA-PW-SALT appear in the AS-REP, each listing one @@ -6081,7 +6059,7 @@ index c982508d8b..96e90a69d2 100644 # Verify that etype-info2 is included in a MORE_PREAUTH_DATA_REQUIRED # error if the client does optimistic preauth. diff --git a/src/tests/t_keyrollover.py b/src/tests/t_keyrollover.py -index 2c825a6922..f29e0d5500 100755 +index e9840dfae8..583c2fa27e 100755 --- a/src/tests/t_keyrollover.py +++ b/src/tests/t_keyrollover.py @@ -37,9 +37,9 @@ realm.run([klist, '-e'], expected_msg=msg) @@ -6181,24 +6159,50 @@ index 65084bbf35..55ca897459 100755 # Test using different salt types in a principal's key list. # Parameters from one key in the list must not leak over to later ones. +diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py +index 5a213617b5..c7dba0ff5b 100755 +--- a/src/tests/t_sesskeynego.py ++++ b/src/tests/t_sesskeynego.py +@@ -26,7 +26,6 @@ conf3 = {'libdefaults': { + 'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}} + conf4 = {'libdefaults': {'permitted_enctypes': 'aes256-cts'}} + conf5 = {'libdefaults': {'allow_rc4': 'true'}} +-conf6 = {'libdefaults': {'allow_des3': 'true'}} + # Test with client request and session_enctypes preferring aes128, but + # aes256 long-term key. + realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False) +@@ -78,13 +77,6 @@ realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'rc4-hmac']) + test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') + realm.stop() + +-# 6: allow_des3 permits negotiation of des3-cbc-sha1 session key. +-realm = K5Realm(krb5_conf=conf6, create_host=False, get_creds=False) +-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server']) +-realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'des3-cbc-sha1']) +-test_kvno(realm, 'DEPRECATED:des3-cbc-sha1', 'aes256-cts-hmac-sha1-96') +-realm.stop() +- + # 7: default config negotiates aes256-sha1 session key for RC4-only service. + realm = K5Realm(create_host=False, get_creds=False) + realm.run([kadminl, 'addprinc', '-randkey', '-e', 'rc4-hmac', 'server']) diff --git a/src/util/k5test.py b/src/util/k5test.py -index 619f1995f8..771f82e3cc 100644 +index 8e5f5ba8e9..b953827018 100644 --- a/src/util/k5test.py +++ b/src/util/k5test.py -@@ -1344,13 +1344,6 @@ _passes = [ +@@ -1338,13 +1338,6 @@ _passes = [ # No special settings; exercises AES256. ('default', None, None, None), - # Exercise the DES3 enctype. - ('des3', None, -- {'libdefaults': {'permitted_enctypes': 'des3'}}, +- {'libdefaults': {'permitted_enctypes': 'des3 aes256-sha1'}}, - {'realms': {'$realm': { - 'supported_enctypes': 'des3-cbc-sha1:normal', - 'master_key_type': 'des3-cbc-sha1'}}}), - # Exercise the arcfour enctype. ('arcfour', None, - {'libdefaults': {'permitted_enctypes': 'rc4'}}, + {'libdefaults': {'permitted_enctypes': 'rc4 aes256-sha1'}}, diff --git a/src/windows/leash/htmlhelp/html/Encryption_Types.htm b/src/windows/leash/htmlhelp/html/Encryption_Types.htm index 1aebdd0b4a..c38eefd2bd 100644 --- a/src/windows/leash/htmlhelp/html/Encryption_Types.htm @@ -6224,5 +6228,5 @@ index 1aebdd0b4a..c38eefd2bd 100644 The AES Advanced Encryption Standard family, like 3DES, is a symmetric block cipher and was designed -- -2.38.1 +2.40.1 diff --git a/0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index ecf661d..e575b79 100644 --- a/0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From 239cd24624b801d4fc4bb4686bef8526e7675d77 Mon Sep 17 00:00:00 2001 +From 53191fd3a1acfeefa8e5c26e7e9d130688daf745 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 @@ -41,10 +41,10 @@ Last-updated: krb5-1.20 15 files changed, 155 insertions(+), 33 deletions(-) diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index d5d6e06ebb..2a4962069f 100644 +index ecdf917501..b78a3faf0a 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst -@@ -330,6 +330,12 @@ The libdefaults section may contain any of the following relations: +@@ -342,6 +342,12 @@ The libdefaults section may contain any of the following relations: qualification of shortnames, set this relation to the empty string with ``qualify_shortname = ""``. (New in release 1.18.) @@ -608,5 +608,5 @@ index 1a772d450f..232e78bc05 100644 vt->name = "spake"; vt->pa_type_list = pa_types; -- -2.38.1 +2.40.1 diff --git a/0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch b/0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch index b8e5429..68f10a0 100644 --- a/0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch +++ b/0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch @@ -1,8 +1,7 @@ -From 5587c755b6ca82bde093523e2d17b255158cd90e Mon Sep 17 00:00:00 2001 +From c19d0bd35cde40172118c67c38a44f164bce1e16 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Thu, 5 May 2022 17:15:12 +0200 -Subject: [PATCH] [downstream] Allow krad UDP/TCP localhost connection - with FIPS +Subject: [PATCH] [downstream] Allow krad UDP/TCP localhost connection with FIPS libkrad allows to establish connections only to UNIX socket in FIPS mode, because MD5 digest is not considered safe enough to be used for @@ -78,5 +77,5 @@ index 929f1cef67..063f17a613 100644 retval = ESOCKTNOSUPPORT; goto error; -- -2.38.1 +2.40.1 diff --git a/0007-Add-configure-variable-for-default-PKCS-11-module.patch b/0007-Add-configure-variable-for-default-PKCS-11-module.patch deleted file mode 100644 index 1445133..0000000 --- a/0007-Add-configure-variable-for-default-PKCS-11-module.patch +++ /dev/null @@ -1,201 +0,0 @@ -From 842b4c3b5695e2518e6f1a1545db78865c04b59c Mon Sep 17 00:00:00 2001 -From: Julien Rische -Date: Fri, 22 Apr 2022 14:12:37 +0200 -Subject: [PATCH] Add configure variable for default PKCS#11 module - -[ghudson@mit.edu: added documentation of configure variable and doc -substitution; shortened commit message] - -ticket: 9058 (new) ---- - doc/admin/conf_files/krb5_conf.rst | 2 +- - doc/build/options2configure.rst | 3 +++ - doc/conf.py | 3 +++ - doc/mitK5defaults.rst | 25 +++++++++++++------------ - src/configure.ac | 8 ++++++++ - src/doc/Makefile.in | 2 ++ - src/man/Makefile.in | 4 +++- - src/man/krb5.conf.man | 2 +- - src/plugins/preauth/pkinit/pkinit.h | 1 - - 9 files changed, 34 insertions(+), 16 deletions(-) - -diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index 2a4962069f..a33711d918 100644 ---- a/doc/admin/conf_files/krb5_conf.rst -+++ b/doc/admin/conf_files/krb5_conf.rst -@@ -1017,7 +1017,7 @@ information for PKINIT is as follows: - All keyword/values are optional. *modname* specifies the location - of a library implementing PKCS #11. If a value is encountered - with no keyword, it is assumed to be the *modname*. If no -- module-name is specified, the default is ``opensc-pkcs11.so``. -+ module-name is specified, the default is |pkcs11_modname|. - ``slotid=`` and/or ``token=`` may be specified to force the use of - a particular smard card reader or token if there is more than one - available. ``certid=`` and/or ``certlabel=`` may be specified to -diff --git a/doc/build/options2configure.rst b/doc/build/options2configure.rst -index 9e355dc2c5..e879b18bd2 100644 ---- a/doc/build/options2configure.rst -+++ b/doc/build/options2configure.rst -@@ -137,6 +137,9 @@ Environment variables - This option allows one to specify libraries to be passed to the - linker (e.g., ``-l``) - -+**PKCS11_MODNAME=**\ *library* -+ Override the built-in default PKCS11 library name. -+ - **SS_LIB=**\ *libs*... - If ``-lss`` is not the correct way to link in your installed ss - library, for example if additional support libraries are needed, -diff --git a/doc/conf.py b/doc/conf.py -index 12168fa695..0ab5ff9606 100644 ---- a/doc/conf.py -+++ b/doc/conf.py -@@ -242,6 +242,7 @@ if 'mansubs' in tags: - ccache = '``@CCNAME@``' - keytab = '``@KTNAME@``' - ckeytab = '``@CKTNAME@``' -+ pkcs11_modname = '``@PKCS11MOD@``' - elif 'pathsubs' in tags: - # Read configured paths from a file produced by the build system. - exec(open("paths.py").read()) -@@ -255,6 +256,7 @@ else: - ccache = ':ref:`DEFCCNAME `' - keytab = ':ref:`DEFKTNAME `' - ckeytab = ':ref:`DEFCKTNAME `' -+ pkcs11_modname = ':ref:`PKCS11_MODNAME `' - - rst_epilog = '\n' - -@@ -275,6 +277,7 @@ else: - rst_epilog += '.. |ccache| replace:: %s\n' % ccache - rst_epilog += '.. |keytab| replace:: %s\n' % keytab - rst_epilog += '.. |ckeytab| replace:: %s\n' % ckeytab -+ rst_epilog += '.. |pkcs11_modname| replace:: %s\n' % pkcs11_modname - rst_epilog += ''' - .. |krb5conf| replace:: ``/etc/krb5.conf`` - .. |defkeysalts| replace:: ``aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal`` -diff --git a/doc/mitK5defaults.rst b/doc/mitK5defaults.rst -index 74e69f4ad0..aea7af3dbb 100644 ---- a/doc/mitK5defaults.rst -+++ b/doc/mitK5defaults.rst -@@ -59,18 +59,19 @@ subdirectories of ``/usr/local``. When MIT krb5 is integrated into an - operating system, the paths are generally chosen to match the - operating system's filesystem layout. - --========================== ============= =========================== =========================== --Description Symbolic name Custom build path Typical OS path --========================== ============= =========================== =========================== --User programs BINDIR ``/usr/local/bin`` ``/usr/bin`` --Libraries and plugins LIBDIR ``/usr/local/lib`` ``/usr/lib`` --Parent of KDC state dir LOCALSTATEDIR ``/usr/local/var`` ``/var`` --Parent of KDC runtime dir RUNSTATEDIR ``/usr/local/var/run`` ``/run`` --Administrative programs SBINDIR ``/usr/local/sbin`` ``/usr/sbin`` --Alternate krb5.conf dir SYSCONFDIR ``/usr/local/etc`` ``/etc`` --Default ccache name DEFCCNAME ``FILE:/tmp/krb5cc_%{uid}`` ``FILE:/tmp/krb5cc_%{uid}`` --Default keytab name DEFKTNAME ``FILE:/etc/krb5.keytab`` ``FILE:/etc/krb5.keytab`` --========================== ============= =========================== =========================== -+========================== ============== =========================== =========================== -+Description Symbolic name Custom build path Typical OS path -+========================== ============== =========================== =========================== -+User programs BINDIR ``/usr/local/bin`` ``/usr/bin`` -+Libraries and plugins LIBDIR ``/usr/local/lib`` ``/usr/lib`` -+Parent of KDC state dir LOCALSTATEDIR ``/usr/local/var`` ``/var`` -+Parent of KDC runtime dir RUNSTATEDIR ``/usr/local/var/run`` ``/run`` -+Administrative programs SBINDIR ``/usr/local/sbin`` ``/usr/sbin`` -+Alternate krb5.conf dir SYSCONFDIR ``/usr/local/etc`` ``/etc`` -+Default ccache name DEFCCNAME ``FILE:/tmp/krb5cc_%{uid}`` ``FILE:/tmp/krb5cc_%{uid}`` -+Default keytab name DEFKTNAME ``FILE:/etc/krb5.keytab`` ``FILE:/etc/krb5.keytab`` -+Default PKCS11 module PKCS11_MODNAME ``opensc-pkcs11.so`` ``opensc-pkcs11.so`` -+========================== ============== =========================== =========================== - - The default client keytab name (DEFCKTNAME) typically defaults to - ``FILE:/usr/local/var/krb5/user/%{euid}/client.keytab`` for a custom -diff --git a/src/configure.ac b/src/configure.ac -index 8dc864718d..9774cb71ae 100644 ---- a/src/configure.ac -+++ b/src/configure.ac -@@ -1471,6 +1471,14 @@ AC_DEFINE_UNQUOTED(DEFKTNAME, ["$DEFKTNAME"], [Define to default keytab name]) - AC_DEFINE_UNQUOTED(DEFCKTNAME, ["$DEFCKTNAME"], - [Define to default client keytab name]) - -+AC_ARG_VAR(PKCS11_MODNAME, [Default PKCS11 module name]) -+if test "${PKCS11_MODNAME+set}" != set; then -+ PKCS11_MODNAME=opensc-pkcs11.so -+fi -+AC_MSG_NOTICE([Default PKCS11 module name: $PKCS11_MODNAME]) -+AC_DEFINE_UNQUOTED(PKCS11_MODNAME, ["$PKCS11_MODNAME"], -+ [Default PKCS11 module name]) -+ - AC_CONFIG_FILES([build-tools/krb5-config], [chmod +x build-tools/krb5-config]) - AC_CONFIG_FILES([build-tools/kadm-server.pc - build-tools/kadm-client.pc -diff --git a/src/doc/Makefile.in b/src/doc/Makefile.in -index 379bc36511..a1b0cff0a4 100644 ---- a/src/doc/Makefile.in -+++ b/src/doc/Makefile.in -@@ -10,6 +10,7 @@ sysconfdir=@sysconfdir@ - DEFCCNAME=@DEFCCNAME@ - DEFKTNAME=@DEFKTNAME@ - DEFCKTNAME=@DEFCKTNAME@ -+PKCS11_MODNAME=@PKCS11_MODNAME@ - - RST_SOURCES= _static \ - _templates \ -@@ -118,6 +119,7 @@ paths.py: - echo 'ccache = "``$(DEFCCNAME)``"' >> $@ - echo 'keytab = "``$(DEFKTNAME)``"' >> $@ - echo 'ckeytab = "``$(DEFCKTNAME)``"' >> $@ -+ echo 'pkcs11_modname = "``$(PKCS11_MODNAME)``"' >> $@ - - # Dummy rule that man/Makefile can invoke - version.py: $(docsrc)/version.py -diff --git a/src/man/Makefile.in b/src/man/Makefile.in -index 00b1b2de06..85cae0914e 100644 ---- a/src/man/Makefile.in -+++ b/src/man/Makefile.in -@@ -8,6 +8,7 @@ sysconfdir=@sysconfdir@ - DEFCCNAME=@DEFCCNAME@ - DEFKTNAME=@DEFKTNAME@ - DEFCKTNAME=@DEFCKTNAME@ -+PKCS11_MODNAME=@PKCS11_MODNAME@ - - MANSUBS=k5identity.sub k5login.sub k5srvutil.sub kadm5.acl.sub kadmin.sub \ - kadmind.sub kdb5_ldap_util.sub kdb5_util.sub kdc.conf.sub \ -@@ -47,7 +48,8 @@ $(docsrc)/version.py: $(top_srcdir)/patchlevel.h - -e 's|@SYSCONFDIR@|$(sysconfdir)|g' \ - -e 's|@CCNAME@|$(DEFCCNAME)|g' \ - -e 's|@KTNAME@|$(DEFKTNAME)|g' \ -- -e 's|@CKTNAME@|$(DEFCKTNAME)|g' $? > $@ -+ -e 's|@CKTNAME@|$(DEFCKTNAME)|g' \ -+ -e 's|@PKCS11MOD@|$(PKCS11_MODNAME)|g' $? > $@ - - all: $(MANSUBS) - -diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man -index 51acb38815..fd2c6f2bc4 100644 ---- a/src/man/krb5.conf.man -+++ b/src/man/krb5.conf.man -@@ -1148,7 +1148,7 @@ user\(aqs certificate and private key. - All keyword/values are optional. \fImodname\fP specifies the location - of a library implementing PKCS #11. If a value is encountered - with no keyword, it is assumed to be the \fImodname\fP\&. If no --module\-name is specified, the default is \fBopensc\-pkcs11.so\fP\&. -+module\-name is specified, the default is \fB@PKCS11MOD@\fP\&. - \fBslotid=\fP and/or \fBtoken=\fP may be specified to force the use of - a particular smard card reader or token if there is more than one - available. \fBcertid=\fP and/or \fBcertlabel=\fP may be specified to -diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h -index 8135535e2c..66f92d8f03 100644 ---- a/src/plugins/preauth/pkinit/pkinit.h -+++ b/src/plugins/preauth/pkinit/pkinit.h -@@ -42,7 +42,6 @@ - #ifndef WITHOUT_PKCS11 - #include "pkcs11.h" - --#define PKCS11_MODNAME "opensc-pkcs11.so" - #define PK_SIGLEN_GUESS 1000 - #define PK_NOSLOT 999999 - #endif --- -2.38.1 - diff --git a/0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch b/0007-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch similarity index 94% rename from 0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch rename to 0007-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch index 5840faa..f1c3ed6 100644 --- a/0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch +++ b/0007-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch @@ -1,4 +1,4 @@ -From 9a536113196d8b32e3143964a655356ac8af1347 Mon Sep 17 00:00:00 2001 +From 0366e8b5b2f960cb8305fd95839376b6c18aae42 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 7 Dec 2022 13:22:42 +0100 Subject: [PATCH] [downstream] Make tests compatible with @@ -37,5 +37,5 @@ index 87bac17929..26bc95a8dc 100644 fail('URI answers do not match') j += 1 -- -2.38.1 +2.40.1 diff --git a/0008-Set-reasonable-supportedCMSTypes-in-PKINIT.patch b/0008-Set-reasonable-supportedCMSTypes-in-PKINIT.patch deleted file mode 100644 index 3755c15..0000000 --- a/0008-Set-reasonable-supportedCMSTypes-in-PKINIT.patch +++ /dev/null @@ -1,159 +0,0 @@ -From 3fb8c4c68274d2ff4addb44b7b95b4698c2c4f34 Mon Sep 17 00:00:00 2001 -From: Julien Rische -Date: Wed, 1 Jun 2022 18:02:04 +0200 -Subject: [PATCH] Set reasonable supportedCMSTypes in PKINIT - -The PKINIT client uses AuthPack.supportedCMSTypes to let the KDC know -the algorithms it supports for verification of the CMS data signature. -(The MIT krb5 KDC currently ignores this list, but other -implementations use it.) - -Replace 3DES with sha512WithRSAEncryption and sha256WithRSAEncryption. - -[ghudson@mit.edu: simplified code and used appropriate helpers; edited -commit message] - -ticket: 9066 (new) ---- - src/plugins/preauth/pkinit/pkinit_constants.c | 33 ++++++++++++- - src/plugins/preauth/pkinit/pkinit_crypto.h | 4 ++ - .../preauth/pkinit/pkinit_crypto_openssl.c | 49 ++++++++++--------- - 3 files changed, 60 insertions(+), 26 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_constants.c b/src/plugins/preauth/pkinit/pkinit_constants.c -index 652897fa14..1da482e0b4 100644 ---- a/src/plugins/preauth/pkinit/pkinit_constants.c -+++ b/src/plugins/preauth/pkinit/pkinit_constants.c -@@ -32,9 +32,14 @@ - - #include "pkinit.h" - --/* statically declare OID constants for all three algorithms */ --static char sha1_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x01}; -+/* RFC 8636 id-pkinit-kdf-ah-sha1: iso(1) identified-organization(3) dod(6) -+ * internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha1(1) */ -+static char sha1_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x01 }; -+/* RFC 8636 id-pkinit-kdf-ah-sha256: iso(1) identified-organization(3) dod(6) -+ * internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha256(2) */ - static char sha256_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x02 }; -+/* RFC 8636 id-pkinit-kdf-ah-sha512: iso(1) identified-organization(3) dod(6) -+ * internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha512(3) */ - static char sha512_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x03 }; - - const krb5_data sha1_id = { KV5M_DATA, sizeof(sha1_oid), sha1_oid }; -@@ -48,6 +53,30 @@ krb5_data const * const supported_kdf_alg_ids[] = { - NULL - }; - -+/* RFC 4055 sha256WithRSAEncryption: iso(1) member-body(2) us(840) -+ * rsadsi(113549) pkcs(1) 1 11 */ -+static char sha256WithRSAEncr_oid[9] = { -+ 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b -+}; -+/* RFC 4055 sha256WithRSAEncryption: iso(1) member-body(2) us(840) -+ * rsadsi(113549) pkcs(1) 1 13 */ -+static char sha512WithRSAEncr_oid[9] = { -+ 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0d -+}; -+ -+const krb5_data sha256WithRSAEncr_id = { -+ KV5M_DATA, sizeof(sha256WithRSAEncr_oid), sha256WithRSAEncr_oid -+}; -+const krb5_data sha512WithRSAEncr_id = { -+ KV5M_DATA, sizeof(sha512WithRSAEncr_oid), sha512WithRSAEncr_oid -+}; -+ -+krb5_data const * const supported_cms_algs[] = { -+ &sha512WithRSAEncr_id, -+ &sha256WithRSAEncr_id, -+ NULL -+}; -+ - /* RFC 2412 section E.2 (well-known group 2) parameters, DER-encoded as - * DomainParameters (RFC 3279 section 2.3.3). */ - static const uint8_t o1024[] = { -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h -index 65f6210727..64300da856 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto.h -+++ b/src/plugins/preauth/pkinit/pkinit_crypto.h -@@ -620,6 +620,10 @@ extern const krb5_data oakley_4096; - */ - extern krb5_data const * const supported_kdf_alg_ids[]; - -+/* CMS signature algorithms supported by this implementation, in order of -+ * decreasing preference. */ -+extern krb5_data const * const supported_cms_algs[]; -+ - krb5_error_code - crypto_encode_der_cert(krb5_context context, pkinit_req_crypto_context reqctx, - uint8_t **der_out, size_t *der_len); -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index d500455dec..1c2aa02827 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -5475,37 +5475,38 @@ create_krb5_supportedCMSTypes(krb5_context context, - pkinit_plg_crypto_context plg_cryptoctx, - pkinit_req_crypto_context req_cryptoctx, - pkinit_identity_crypto_context id_cryptoctx, -- krb5_algorithm_identifier ***oids) -+ krb5_algorithm_identifier ***algs_out) - { -+ krb5_error_code ret; -+ krb5_algorithm_identifier **algs = NULL; -+ size_t i, count; - -- krb5_error_code retval = ENOMEM; -- krb5_algorithm_identifier **loids = NULL; -- krb5_data des3oid = {0, 8, "\x2A\x86\x48\x86\xF7\x0D\x03\x07" }; -+ *algs_out = NULL; - -- *oids = NULL; -- loids = malloc(2 * sizeof(krb5_algorithm_identifier *)); -- if (loids == NULL) -- goto cleanup; -- loids[1] = NULL; -- loids[0] = malloc(sizeof(krb5_algorithm_identifier)); -- if (loids[0] == NULL) { -- free(loids); -- goto cleanup; -- } -- retval = pkinit_copy_krb5_data(&loids[0]->algorithm, &des3oid); -- if (retval) { -- free(loids[0]); -- free(loids); -+ /* Count supported OIDs and allocate list (including null terminator). */ -+ for (count = 0; supported_cms_algs[count] != NULL; count++); -+ algs = k5calloc(count + 1, sizeof(*algs), &ret); -+ if (algs == NULL) - goto cleanup; -+ -+ /* Add an algorithm identifier for each OID, with no parameters. */ -+ for (i = 0; i < count; i++) { -+ algs[i] = k5alloc(sizeof(*algs[i]), &ret); -+ if (algs[i] == NULL) -+ goto cleanup; -+ ret = krb5int_copy_data_contents(context, supported_cms_algs[i], -+ &algs[i]->algorithm); -+ if (ret) -+ goto cleanup; -+ algs[i]->parameters = empty_data(); - } -- loids[0]->parameters.length = 0; -- loids[0]->parameters.data = NULL; - -- *oids = loids; -- retval = 0; --cleanup: -+ *algs_out = algs; -+ algs = NULL; - -- return retval; -+cleanup: -+ free_krb5_algorithm_identifiers(&algs); -+ return ret; - } - - krb5_error_code --- -2.38.1 - diff --git a/0014-downstream-Include-missing-OpenSSL-FIPS-header.patch b/0008-downstream-Include-missing-OpenSSL-FIPS-header.patch similarity index 98% rename from 0014-downstream-Include-missing-OpenSSL-FIPS-header.patch rename to 0008-downstream-Include-missing-OpenSSL-FIPS-header.patch index 24ba48a..43648a7 100644 --- a/0014-downstream-Include-missing-OpenSSL-FIPS-header.patch +++ b/0008-downstream-Include-missing-OpenSSL-FIPS-header.patch @@ -1,4 +1,4 @@ -From d57a804136c5ebf473ce053a9517edd71a56389f Mon Sep 17 00:00:00 2001 +From a567b9de563cd8ad262f77cf97a8bc528a884745 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Thu, 5 Jan 2023 20:06:47 +0100 Subject: [PATCH] [downstream] Include missing OpenSSL FIPS header @@ -116,5 +116,5 @@ index 232e78bc05..3394f8a58e 100644 * The SPAKE kdcpreauth module uses a secure cookie containing the following * concatenated fields (all integer fields are big-endian): -- -2.38.1 +2.40.1 diff --git a/0009-Simplify-plugin-loading-code.patch b/0009-Simplify-plugin-loading-code.patch deleted file mode 100644 index 42802e5..0000000 --- a/0009-Simplify-plugin-loading-code.patch +++ /dev/null @@ -1,622 +0,0 @@ -From ffb47e4120d68aef015453350a3a50a9bab1ec58 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 23 Jun 2022 16:41:40 -0400 -Subject: [PATCH] Simplify plugin loading code - -Remove the USE_CFBUNDLE code, which was only used by KfM. Handle -platform conditionals according to current practice. Use -k5_dir_filenames() instead of opendir() and remove the Windows -implementation of opendir(). ---- - src/util/support/plugins.c | 507 +++++++++++-------------------------- - 1 file changed, 150 insertions(+), 357 deletions(-) - -diff --git a/src/util/support/plugins.c b/src/util/support/plugins.c -index c6a9a21d57..0850565687 100644 ---- a/src/util/support/plugins.c -+++ b/src/util/support/plugins.c -@@ -29,16 +29,6 @@ - #if USE_DLOPEN - #include - #endif --#include --#ifdef HAVE_SYS_STAT_H --#include --#endif --#ifdef HAVE_SYS_PARAM_H --#include --#endif --#ifdef HAVE_UNISTD_H --#include --#endif - - #if USE_DLOPEN - #ifdef RTLD_GROUP -@@ -68,16 +58,6 @@ - #endif - #endif - --#if USE_DLOPEN && USE_CFBUNDLE --#include -- --/* Currently CoreFoundation only exists on the Mac so we just use -- * pthreads directly to avoid creating empty function calls on other -- * platforms. If a thread initializer ever gets created in the common -- * plugin code, move this there */ --static pthread_mutex_t krb5int_bundle_mutex = PTHREAD_MUTEX_INITIALIZER; --#endif -- - #include - static void Tprintf (const char *fmt, ...) - { -@@ -90,374 +70,193 @@ static void Tprintf (const char *fmt, ...) - } - - struct plugin_file_handle { --#if USE_DLOPEN -+#if defined(USE_DLOPEN) - void *dlhandle; --#endif --#ifdef _WIN32 -- HMODULE hinstPlugin; --#endif --#if !defined (USE_DLOPEN) && !defined (_WIN32) -+#elif defined(_WIN32) -+ HMODULE module; -+#else - char dummy; - #endif - }; - --#ifdef _WIN32 --struct dirent { -- long d_ino; /* inode (always 1 in WIN32) */ -- off_t d_off; /* offset to this dirent */ -- unsigned short d_reclen; /* length of d_name */ -- char d_name[_MAX_FNAME+1]; /* filename (null terminated) */ --}; -- --typedef struct { -- intptr_t handle; /* _findfirst/_findnext handle */ -- short offset; /* offset into directory */ -- short finished; /* 1 if there are not more files */ -- struct _finddata_t fileinfo;/* from _findfirst/_findnext */ -- char *dir; /* the dir we are reading */ -- struct dirent dent; /* the dirent to return */ --} DIR; -+#if defined(USE_DLOPEN) - --DIR * opendir(const char *dir) -+static long -+open_plugin_dlfcn(struct plugin_file_handle *h, const char *filename, -+ struct errinfo *ep) - { -- DIR *dp; -- char *filespec; -- intptr_t handle; -- int index; -- -- filespec = malloc(strlen(dir) + 2 + 1); -- strcpy(filespec, dir); -- index = strlen(filespec) - 1; -- if (index >= 0 && (filespec[index] == '/' || filespec[index] == '\\')) -- filespec[index] = '\0'; -- strcat(filespec, "/*"); -- -- dp = (DIR *)malloc(sizeof(DIR)); -- dp->offset = 0; -- dp->finished = 0; -- dp->dir = strdup(dir); -- -- if ((handle = _findfirst(filespec, &(dp->fileinfo))) < 0) { -- if (errno == ENOENT) -- dp->finished = 1; -- else { -- free(filespec); -- free(dp->dir); -- free(dp); -- return NULL; -- } -+ const char *e; -+ -+ h->dlhandle = dlopen(filename, PLUGIN_DLOPEN_FLAGS); -+ if (h->dlhandle == NULL) { -+ e = dlerror(); -+ if (e == NULL) -+ e = _("unknown failure"); -+ Tprintf("dlopen(%s): %s\n", filename, e); -+ k5_set_error(ep, ENOENT, _("unable to load plugin [%s]: %s"), -+ filename, e); -+ return ENOENT; - } -- -- dp->handle = handle; -- free(filespec); -- -- return dp; -+ return 0; - } -+#define open_plugin open_plugin_dlfcn - --struct dirent * readdir(DIR *dp) -+static long -+get_sym_dlfcn(struct plugin_file_handle *h, const char *csymname, -+ void **sym_out, struct errinfo *ep) - { -- if (!dp || dp->finished) return NULL; -- -- if (dp->offset != 0) { -- if (_findnext(dp->handle, &(dp->fileinfo)) < 0) { -- dp->finished = 1; -- return NULL; -- } -+ const char *e; -+ -+ if (h->dlhandle == NULL) -+ return ENOENT; -+ *sym_out = dlsym(h->dlhandle, csymname); -+ if (*sym_out == NULL) { -+ e = dlerror(); -+ if (e == NULL) -+ e = _("unknown failure"); -+ Tprintf("dlsym(%s): %s\n", csymname, e); -+ k5_set_error(ep, ENOENT, "%s", e); -+ return ENOENT; - } -- dp->offset++; -- -- strncpy(dp->dent.d_name, dp->fileinfo.name, _MAX_FNAME); -- dp->dent.d_ino = 1; -- dp->dent.d_reclen = (unsigned short)strlen(dp->dent.d_name); -- dp->dent.d_off = dp->offset; -- -- return &(dp->dent); --} -- --int closedir(DIR *dp) --{ -- if (!dp) return 0; -- _findclose(dp->handle); -- free(dp->dir); -- free(dp); -- - return 0; - } --#endif -+#define get_sym get_sym_dlfcn - --long KRB5_CALLCONV --krb5int_open_plugin (const char *filepath, struct plugin_file_handle **h, struct errinfo *ep) -+static void -+close_plugin_dlfcn(struct plugin_file_handle *h) - { -- long err = 0; -- struct plugin_file_handle *htmp = NULL; -- int got_plugin = 0; --#if defined(USE_CFBUNDLE) || defined(_WIN32) -- struct stat statbuf; -- -- if (!err) { -- if (stat (filepath, &statbuf) < 0) { -- err = errno; -- Tprintf ("stat(%s): %s\n", filepath, strerror (err)); -- k5_set_error(ep, err, _("unable to find plugin [%s]: %s"), -- filepath, strerror(err)); -- } -- } --#endif -- -- if (!err) { -- htmp = calloc (1, sizeof (*htmp)); /* calloc initializes ptrs to NULL */ -- if (htmp == NULL) { err = ENOMEM; } -- } -- --#if USE_DLOPEN -- if (!err --#if USE_CFBUNDLE -- && ((statbuf.st_mode & S_IFMT) == S_IFREG -- || (statbuf.st_mode & S_IFMT) == S_IFDIR) --#endif /* USE_CFBUNDLE */ -- ) { -- void *handle = NULL; -- --#if USE_CFBUNDLE -- char executablepath[MAXPATHLEN]; -- -- if ((statbuf.st_mode & S_IFMT) == S_IFDIR) { -- int lock_err = 0; -- CFStringRef pluginString = NULL; -- CFURLRef pluginURL = NULL; -- CFBundleRef pluginBundle = NULL; -- CFURLRef executableURL = NULL; -- -- /* Lock around CoreFoundation calls since objects are refcounted -- * and the refcounts are not thread-safe. Using pthreads directly -- * because this code is Mac-specific */ -- lock_err = pthread_mutex_lock(&krb5int_bundle_mutex); -- if (lock_err) { err = lock_err; } -- -- if (!err) { -- pluginString = CFStringCreateWithCString (kCFAllocatorDefault, -- filepath, -- kCFStringEncodingASCII); -- if (pluginString == NULL) { err = ENOMEM; } -- } -- -- if (!err) { -- pluginURL = CFURLCreateWithFileSystemPath (kCFAllocatorDefault, -- pluginString, -- kCFURLPOSIXPathStyle, -- true); -- if (pluginURL == NULL) { err = ENOMEM; } -- } -- -- if (!err) { -- pluginBundle = CFBundleCreate (kCFAllocatorDefault, pluginURL); -- if (pluginBundle == NULL) { err = ENOENT; } /* XXX need better error */ -- } -- -- if (!err) { -- executableURL = CFBundleCopyExecutableURL (pluginBundle); -- if (executableURL == NULL) { err = ENOMEM; } -- } -- -- if (!err) { -- if (!CFURLGetFileSystemRepresentation (executableURL, -- true, /* absolute */ -- (UInt8 *)executablepath, -- sizeof (executablepath))) { -- err = ENOMEM; -- } -- } -- -- if (!err) { -- /* override the path the caller passed in */ -- filepath = executablepath; -- } -- -- if (executableURL != NULL) { CFRelease (executableURL); } -- if (pluginBundle != NULL) { CFRelease (pluginBundle); } -- if (pluginURL != NULL) { CFRelease (pluginURL); } -- if (pluginString != NULL) { CFRelease (pluginString); } -- -- /* unlock after CFRelease calls since they modify refcounts */ -- if (!lock_err) { pthread_mutex_unlock (&krb5int_bundle_mutex); } -- } --#endif /* USE_CFBUNDLE */ -- -- if (!err) { -- handle = dlopen(filepath, PLUGIN_DLOPEN_FLAGS); -- if (handle == NULL) { -- const char *e = dlerror(); -- if (e == NULL) -- e = _("unknown failure"); -- Tprintf ("dlopen(%s): %s\n", filepath, e); -- err = ENOENT; /* XXX */ -- k5_set_error(ep, err, _("unable to load plugin [%s]: %s"), -- filepath, e); -- } -- } -+ if (h->dlhandle != NULL) -+ dlclose(h->dlhandle); -+} -+#define close_plugin close_plugin_dlfcn - -- if (!err) { -- got_plugin = 1; -- htmp->dlhandle = handle; -- handle = NULL; -- } -+#elif defined(_WIN32) - -- if (handle != NULL) { dlclose (handle); } -+static long -+open_plugin_win32(struct plugin_file_handle *h, const char *filename, -+ struct errinfo *ep) -+{ -+ h->module = LoadLibrary(filename); -+ if (h == NULL) { -+ Tprintf("Unable to load dll: %s\n", filename); -+ k5_set_error(ep, ENOENT, _("unable to load DLL [%s]"), filename); -+ return ENOENT; - } --#endif /* USE_DLOPEN */ -- --#ifdef _WIN32 -- if (!err && (statbuf.st_mode & S_IFMT) == S_IFREG) { -- HMODULE handle = NULL; -+ return 0; -+} -+#define open_plugin open_plugin_win32 - -- handle = LoadLibrary(filepath); -- if (handle == NULL) { -- Tprintf ("Unable to load dll: %s\n", filepath); -- err = ENOENT; /* XXX */ -- k5_set_error(ep, err, _("unable to load DLL [%s]"), filepath); -- } -+static long -+get_sym_win32(struct plugin_file_handle *h, const char *csymname, -+ void **sym_out, struct errinfo *ep) -+{ -+ LPVOID lpMsgBuf; -+ DWORD dw; - -- if (!err) { -- got_plugin = 1; -- htmp->hinstPlugin = handle; -- handle = NULL; -+ if (h->module == NULL) -+ return ENOENT; -+ *sym_out = GetProcAddress(h->module, csymname); -+ if (*sym_out == NULL) { -+ Tprintf("GetProcAddress(%s): %i\n", csymname, GetLastError()); -+ dw = GetLastError(); -+ if (FormatMessage(FORMAT_MESSAGE_ALLOCATE_BUFFER | -+ FORMAT_MESSAGE_FROM_SYSTEM, -+ NULL, dw, MAKELANGID(LANG_NEUTRAL, SUBLANG_DEFAULT), -+ (LPTSTR)&lpMsgBuf, 0, NULL)) { -+ k5_set_error(ep, ENOENT, _("unable to get DLL Symbol: %s"), -+ (char *)lpMsgBuf); -+ LocalFree(lpMsgBuf); - } -- -- if (handle != NULL) -- FreeLibrary(handle); -- } --#endif -- -- if (!err && !got_plugin) { -- err = ENOENT; /* no plugin or no way to load plugins */ -- k5_set_error(ep, err, _("plugin unavailable: %s"), strerror(err)); -+ return ENOENT; - } -+ return 0; -+} -+#define get_sym get_sym_win32 - -- if (!err) { -- *h = htmp; -- htmp = NULL; /* h takes ownership */ -- } -+static void -+close_plugin_win32(struct plugin_file_handle *h) -+{ -+ if (h->module != NULL) -+ FreeLibrary(h->module); -+} -+#define close_plugin close_plugin_win32 - -- free(htmp); -+#else - -- return err; -+static long -+open_plugin_dummy(struct plugin_file_handle *h, const char *filename, -+ struct errinfo *ep) -+{ -+ k5_set_error(ep, ENOENT, _("plugin loading unavailable")); -+ return ENOENT; - } -+#define open_plugin open_plugin_dummy - - static long --krb5int_get_plugin_sym (struct plugin_file_handle *h, -- const char *csymname, int isfunc, void **ptr, -- struct errinfo *ep) -+get_sym_dummy(struct plugin_file_handle *h, const char *csymname, -+ void **sym_out, struct errinfo *ep) - { -- long err = 0; -- void *sym = NULL; -+ return ENOENT; -+} -+#define get_sym get_sym_dummy -+ -+static void -+close_plugin_dummy(struct plugin_file_handle *h) -+{ -+} -+#define close_plugin close_plugin_dummy - --#if USE_DLOPEN -- if (!err && !sym && (h->dlhandle != NULL)) { -- /* XXX Do we need to add a leading "_" to the symbol name on any -- modern platforms? */ -- sym = dlsym (h->dlhandle, csymname); -- if (sym == NULL) { -- const char *e = dlerror (); /* XXX copy and save away */ -- if (e == NULL) -- e = "unknown failure"; -- Tprintf ("dlsym(%s): %s\n", csymname, e); -- err = ENOENT; /* XXX */ -- k5_set_error(ep, err, "%s", e); -- } -- } - #endif - --#ifdef _WIN32 -- LPVOID lpMsgBuf; -- DWORD dw; -+long KRB5_CALLCONV -+krb5int_open_plugin(const char *filename, -+ struct plugin_file_handle **handle_out, struct errinfo *ep) -+{ -+ long ret; -+ struct plugin_file_handle *h; - -- if (!err && !sym && (h->hinstPlugin != NULL)) { -- sym = GetProcAddress(h->hinstPlugin, csymname); -- if (sym == NULL) { -- const char *e = "unable to get dll symbol"; /* XXX copy and save away */ -- Tprintf ("GetProcAddress(%s): %i\n", csymname, GetLastError()); -- err = ENOENT; /* XXX */ -- k5_set_error(ep, err, "%s", e); -- -- dw = GetLastError(); -- if (FormatMessage(FORMAT_MESSAGE_ALLOCATE_BUFFER | -- FORMAT_MESSAGE_FROM_SYSTEM, -- NULL, -- dw, -- MAKELANGID(LANG_NEUTRAL, SUBLANG_DEFAULT), -- (LPTSTR) &lpMsgBuf, -- 0, NULL )) { -- -- fprintf (stderr, "unable to get dll symbol, %s\n", (LPCTSTR)lpMsgBuf); -- LocalFree(lpMsgBuf); -- } -- } -- } --#endif -+ *handle_out = NULL; - -- if (!err && (sym == NULL)) { -- err = ENOENT; /* unimplemented */ -- } -+ h = calloc(1, sizeof(*h)); -+ if (h == NULL) -+ return ENOMEM; - -- if (!err) { -- *ptr = sym; -+ ret = open_plugin(h, filename, ep); -+ if (ret) { -+ free(h); -+ return ret; - } - -- return err; -+ *handle_out = h; -+ return 0; - } - - long KRB5_CALLCONV --krb5int_get_plugin_data (struct plugin_file_handle *h, const char *csymname, -- void **ptr, struct errinfo *ep) -+krb5int_get_plugin_data(struct plugin_file_handle *h, const char *csymname, -+ void **sym_out, struct errinfo *ep) - { -- return krb5int_get_plugin_sym (h, csymname, 0, ptr, ep); -+ return get_sym(h, csymname, sym_out, ep); - } - - long KRB5_CALLCONV --krb5int_get_plugin_func (struct plugin_file_handle *h, const char *csymname, -- void (**ptr)(), struct errinfo *ep) -+krb5int_get_plugin_func(struct plugin_file_handle *h, const char *csymname, -+ void (**sym_out)(), struct errinfo *ep) - { - void *dptr = NULL; -- long err = krb5int_get_plugin_sym (h, csymname, 1, &dptr, ep); -- if (!err) { -- /* Cast function pointers to avoid code duplication */ -- *ptr = (void (*)()) dptr; -- } -- return err; -+ long ret = get_sym(h, csymname, &dptr, ep); -+ -+ if (!ret) -+ *sym_out = (void (*)())dptr; -+ return ret; - } - - void KRB5_CALLCONV - krb5int_close_plugin (struct plugin_file_handle *h) - { --#if USE_DLOPEN -- if (h->dlhandle != NULL) { dlclose(h->dlhandle); } --#endif --#ifdef _WIN32 -- if (h->hinstPlugin != NULL) { FreeLibrary(h->hinstPlugin); } --#endif -- free (h); -+ close_plugin(h); -+ free(h); - } - --/* autoconf docs suggest using this preference order */ --#if HAVE_DIRENT_H || USE_DIRENT_H --#include --#define NAMELEN(D) strlen((D)->d_name) --#else --#ifndef _WIN32 --#define dirent direct --#define NAMELEN(D) ((D)->d->namlen) --#else --#define NAMELEN(D) strlen((D)->d_name) --#endif --#if HAVE_SYS_NDIR_H --# include --#elif HAVE_SYS_DIR_H --# include --#elif HAVE_NDIR_H --# include --#endif --#endif -- - static long - krb5int_plugin_file_handle_array_init (struct plugin_file_handle ***harray) - { -@@ -619,42 +418,36 @@ krb5int_open_plugin_dirs (const char * const *dirnames, - if (handle != NULL) { krb5int_close_plugin (handle); } - } - } else { -- /* load all plugins in each directory */ -- DIR *dir = opendir (dirnames[i]); -+ char **fnames = NULL; -+ int j; - -- while (dir != NULL && !err) { -- struct dirent *d = NULL; -+ err = k5_dir_filenames(dirnames[i], &fnames); -+ for (j = 0; !err && fnames[j] != NULL; j++) { - char *filepath = NULL; - struct plugin_file_handle *handle = NULL; - -- d = readdir (dir); -- if (d == NULL) { break; } -- -- if ((strcmp (d->d_name, ".") == 0) || -- (strcmp (d->d_name, "..") == 0)) { -+ if (strcmp(fnames[j], ".") == 0 || -+ strcmp(fnames[j], "..") == 0) - continue; -- } - -- if (!err) { -- int len = NAMELEN (d); -- if (asprintf(&filepath, "%s/%*s", dirnames[i], len, d->d_name) < 0) { -- filepath = NULL; -- err = ENOMEM; -- } -+ if (asprintf(&filepath, "%s/%s", dirnames[i], fnames[j]) < 0) { -+ filepath = NULL; -+ err = ENOMEM; - } - -- if (!err) { -- if (krb5int_open_plugin (filepath, &handle, ep) == 0) { -- err = krb5int_plugin_file_handle_array_add (&h, &count, handle); -- if (!err) { handle = NULL; } /* h takes ownership */ -- } -+ if (!err && krb5int_open_plugin(filepath, &handle, ep) == 0) { -+ err = krb5int_plugin_file_handle_array_add(&h, &count, -+ handle); -+ if (!err) -+ handle = NULL; /* h takes ownership */ - } - - free(filepath); -- if (handle != NULL) { krb5int_close_plugin (handle); } -+ if (handle != NULL) -+ krb5int_close_plugin(handle); - } - -- if (dir != NULL) { closedir (dir); } -+ k5_free_filenames(fnames); - } - } - --- -2.38.1 - diff --git a/0015-downstream-Do-not-set-root-as-ksu-file-owner.patch b/0009-downstream-Do-not-set-root-as-ksu-file-owner.patch similarity index 93% rename from 0015-downstream-Do-not-set-root-as-ksu-file-owner.patch rename to 0009-downstream-Do-not-set-root-as-ksu-file-owner.patch index 5c53868..0dd8834 100644 --- a/0015-downstream-Do-not-set-root-as-ksu-file-owner.patch +++ b/0009-downstream-Do-not-set-root-as-ksu-file-owner.patch @@ -1,4 +1,4 @@ -From 59d3ecdab7210e87ec475f4ae0d64888d5416b29 Mon Sep 17 00:00:00 2001 +From 6adfd97a3558aae4ace346685266bac9dae8bba9 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Mon, 9 Jan 2023 22:39:52 +0100 Subject: [PATCH] [downstream] Do not set root as ksu file owner @@ -27,5 +27,5 @@ index 7eaa2f351c..e9ae71471e 100644 ## ${prefix}. prefix=@prefix@ -- -2.38.1 +2.40.1 diff --git a/0010-Update-error-checking-for-OpenSSL-CMS_verify.patch b/0010-Update-error-checking-for-OpenSSL-CMS_verify.patch deleted file mode 100644 index 0fbd529..0000000 --- a/0010-Update-error-checking-for-OpenSSL-CMS_verify.patch +++ /dev/null @@ -1,48 +0,0 @@ -From 963314f4f449e136195232bdada3109af65d0881 Mon Sep 17 00:00:00 2001 -From: Julien Rische -Date: Thu, 28 Jul 2022 15:20:12 +0200 -Subject: [PATCH] Update error checking for OpenSSL CMS_verify - -The code for CMS data verification was initially written for OpenSSL's -PKCS7_verify() function. It now uses CMS_verify(), but error handling -is still done using PKCS7_verify() error identifiers. Update the -recognized error codes so that the KDC generates -KDC_ERR_DIGEST_IN_SIGNED_DATA_NOT_ACCEPTED errors when appropriate. -Use ERR_peek_last_error() to observe the error generated closest to -the API surface. - -[ghudson@mit.edu: edited commit message] - -ticket: 9069 (new) -tags: pullup -target_version: 1.20-next ---- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 9 ++++++--- - 1 file changed, 6 insertions(+), 3 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 1c2aa02827..16edf15cb2 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2102,12 +2102,15 @@ cms_signeddata_verify(krb5_context context, - goto cleanup; - out = BIO_new(BIO_s_mem()); - if (CMS_verify(cms, NULL, store, NULL, out, flags) == 0) { -- unsigned long err = ERR_peek_error(); -+ unsigned long err = ERR_peek_last_error(); - switch(ERR_GET_REASON(err)) { -- case PKCS7_R_DIGEST_FAILURE: -+ case RSA_R_DIGEST_NOT_ALLOWED: -+ case CMS_R_UNKNOWN_DIGEST_ALGORITHM: -+ case CMS_R_NO_MATCHING_DIGEST: -+ case CMS_R_NO_MATCHING_SIGNATURE: - retval = KRB5KDC_ERR_DIGEST_IN_SIGNED_DATA_NOT_ACCEPTED; - break; -- case PKCS7_R_SIGNATURE_FAILURE: -+ case CMS_R_VERIFICATION_FAILURE: - default: - retval = KRB5KDC_ERR_INVALID_SIG; - } --- -2.38.1 - diff --git a/0016-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch b/0010-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch similarity index 98% rename from 0016-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch rename to 0010-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch index 227650e..a78d09c 100644 --- a/0016-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch +++ b/0010-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch @@ -1,4 +1,4 @@ -From d8f67df42efd68142aa904040f9e8cc0f9138c10 Mon Sep 17 00:00:00 2001 +From 73640dc4899494d010b83b080b3a65bd3e69177c Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Thu, 19 Jan 2023 19:22:27 +0100 Subject: [PATCH] [downstream] Allow KRB5KDF, MD5, and MD4 in FIPS mode @@ -161,5 +161,5 @@ index 5a43c3d9eb..8528ddc4a9 100644 ret = KRB5_CRYPTO_INTERNAL; goto done; -- -2.39.1 +2.40.1 diff --git a/0011-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch b/0011-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch new file mode 100644 index 0000000..8109a84 --- /dev/null +++ b/0011-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch @@ -0,0 +1,279 @@ +From f47c9eb8618006012600a906367295ed53c558d0 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Wed, 15 Mar 2023 15:56:34 +0100 +Subject: [PATCH] [downstream] Allow to set PAC ticket signature as optional + +MS-PAC states that "The ticket signature SHOULD be included in tickets +that are not encrypted to the krbtgt account". However, the +implementation of krb5_kdc_verify_ticket() will require the ticket +signature to be present in case the target of the request is a service +principal. + +In gradual upgrade environments, it results in S4U2Proxy requests +against a 1.20 KDC using a service ticket generated by an older version +KDC to fail. + +This commit adds a krb5_kdc_verify_ticket_ext() function with an extra +switch parameter to tolerate the absence of ticket signature in this +scenario. If the ticket signature is present, it has to be valid, +regardless of this parameter. + +This parameter is set based on the "optional_pac_tkt_chksum" string +attribute of the TGT KDB entry. +--- + doc/admin/admin_commands/kadmin_local.rst | 6 ++++ + doc/appdev/refs/api/index.rst | 1 + + src/include/kdb.h | 1 + + src/include/krb5/krb5.hin | 40 +++++++++++++++++++++++ + src/kdc/kdc_util.c | 32 ++++++++++++++---- + src/lib/krb5/krb/pac.c | 31 +++++++++++++++--- + src/lib/krb5/libkrb5.exports | 1 + + src/man/kadmin.man | 6 ++++ + 8 files changed, 108 insertions(+), 10 deletions(-) + +diff --git a/doc/admin/admin_commands/kadmin_local.rst b/doc/admin/admin_commands/kadmin_local.rst +index 2435b3c361..58ac79549f 100644 +--- a/doc/admin/admin_commands/kadmin_local.rst ++++ b/doc/admin/admin_commands/kadmin_local.rst +@@ -658,6 +658,12 @@ KDC: + Directory realm when using aes-sha2 keys on the local krbtgt + entry. + ++**optional_pac_tkt_chksum** ++ Boolean value defining the behavior of the KDC in case an expected ++ ticket checksum signed with one of this principal keys is not ++ present in the PAC. This is typically the case for TGS or ++ cross-realm TGS principals when processing S4U2Proxy requests. ++ + This command requires the **modify** privilege. + + Alias: **setstr** +diff --git a/doc/appdev/refs/api/index.rst b/doc/appdev/refs/api/index.rst +index d12be47c3c..9b95ebd0f9 100644 +--- a/doc/appdev/refs/api/index.rst ++++ b/doc/appdev/refs/api/index.rst +@@ -225,6 +225,7 @@ Rarely used public interfaces + krb5_is_referral_realm.rst + krb5_kdc_sign_ticket.rst + krb5_kdc_verify_ticket.rst ++ krb5_kdc_verify_ticket_ext.rst + krb5_kt_add_entry.rst + krb5_kt_end_seq_get.rst + krb5_kt_get_entry.rst +diff --git a/src/include/kdb.h b/src/include/kdb.h +index 745b24f351..6075349e5e 100644 +--- a/src/include/kdb.h ++++ b/src/include/kdb.h +@@ -136,6 +136,7 @@ + #define KRB5_KDB_SK_PAC_PRIVSVR_ENCTYPE "pac_privsvr_enctype" + #define KRB5_KDB_SK_SESSION_ENCTYPES "session_enctypes" + #define KRB5_KDB_SK_REQUIRE_AUTH "require_auth" ++#define KRB5_KDB_SK_OPTIONAL_PAC_TKT_CHKSUM "optional_pac_tkt_chksum" + + #if !defined(_WIN32) + +diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin +index 350bcf86f2..17e1b52266 100644 +--- a/src/include/krb5/krb5.hin ++++ b/src/include/krb5/krb5.hin +@@ -8356,6 +8356,46 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + const krb5_keyblock *server, + const krb5_keyblock *privsvr, krb5_pac *pac_out); + ++/** ++ * Verify a PAC, possibly including ticket signature ++ * ++ * @param [in] context Library context ++ * @param [in] enc_tkt Ticket enc-part, possibly containing a PAC ++ * @param [in] server_princ Canonicalized name of ticket server ++ * @param [in] server Key to validate server checksum (or NULL) ++ * @param [in] privsvr Key to validate KDC checksum (or NULL) ++ * @paran [in] optional_tkt_chksum Whether to require a ticket checksum ++ * @param [out] pac_out Verified PAC (NULL if no PAC included) ++ * ++ * This function is an extension of krb5_kdc_verify_ticket(), adding the @a ++ * optional_tkt_chksum parameter allowing to tolerate the absence of the PAC ++ * ticket signature. ++ * ++ * If a PAC is present in @a enc_tkt, verify its signatures. If @a privsvr is ++ * not NULL and @a server_princ is not a krbtgt or kadmin/changepw service and ++ * @a optional_tkt_chksum is FALSE, require a ticket signature over @a enc_tkt ++ * in addition to the KDC signature. Place the verified PAC in @a pac_out. If ++ * an invalid PAC signature is found, return an error matching the Windows KDC ++ * protocol code for that condition as closely as possible. ++ * ++ * If no PAC is present in @a enc_tkt, set @a pac_out to NULL and return ++ * successfully. ++ * ++ * @note This function does not validate the PAC_CLIENT_INFO buffer. If a ++ * specific value is expected, the caller can make a separate call to ++ * krb5_pac_verify_ext() with a principal but no keys. ++ * ++ * @retval 0 Success; otherwise - Kerberos error codes ++ */ ++krb5_error_code KRB5_CALLCONV ++krb5_kdc_verify_ticket_ext(krb5_context context, ++ const krb5_enc_tkt_part *enc_tkt, ++ krb5_const_principal server_princ, ++ const krb5_keyblock *server, ++ const krb5_keyblock *privsvr, ++ krb5_boolean optional_tkt_chksum, ++ krb5_pac *pac_out); ++ + /** @deprecated Use krb5_kdc_sign_ticket() instead. */ + krb5_error_code KRB5_CALLCONV + krb5_pac_sign(krb5_context context, krb5_pac pac, krb5_timestamp authtime, +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index ea10e23a95..c7b6e4090d 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -560,16 +560,36 @@ cleanup: + static krb5_error_code + try_verify_pac(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + krb5_db_entry *server, krb5_keyblock *server_key, +- const krb5_keyblock *tgt_key, krb5_pac *pac_out) ++ krb5_db_entry *tgt, const krb5_keyblock *tgt_key, ++ krb5_pac *pac_out) + { + krb5_error_code ret; ++ krb5_boolean optional_tkt_chksum; ++ char *str = NULL; + krb5_keyblock *privsvr_key; + + ret = pac_privsvr_key(context, server, tgt_key, &privsvr_key); + if (ret) + return ret; +- ret = krb5_kdc_verify_ticket(context, enc_tkt, server->princ, server_key, +- privsvr_key, pac_out); ++ ++ /* Check if the absence of ticket signature is tolerated for this realm */ ++ ret = krb5_dbe_get_string(context, tgt, ++ KRB5_KDB_SK_OPTIONAL_PAC_TKT_CHKSUM, &str); ++ /* TODO: should be using _krb5_conf_boolean(), but os-proto.h is not ++ * available here. ++ */ ++ optional_tkt_chksum = !ret && str && (strncasecmp(str, "true", 4) == 0 ++ || strncasecmp(str, "t", 1) == 0 ++ || strncasecmp(str, "yes", 3) == 0 ++ || strncasecmp(str, "y", 1) == 0 ++ || strncasecmp(str, "1", 1) == 0 ++ || strncasecmp(str, "on", 2) == 0); ++ ++ krb5_dbe_free_string(context, str); ++ ++ ret = krb5_kdc_verify_ticket_ext(context, enc_tkt, server->princ, ++ server_key, privsvr_key, ++ optional_tkt_chksum, pac_out); + krb5_free_keyblock(context, privsvr_key); + return ret; + } +@@ -599,7 +619,7 @@ get_verified_pac(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + server_key, NULL, pac_out); + } + +- ret = try_verify_pac(context, enc_tkt, server, server_key, tgt_key, ++ ret = try_verify_pac(context, enc_tkt, server, server_key, tgt, tgt_key, + pac_out); + if (ret != KRB5KRB_AP_ERR_MODIFIED && ret != KRB5_BAD_ENCTYPE) + return ret; +@@ -613,8 +633,8 @@ get_verified_pac(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + ret = krb5_dbe_decrypt_key_data(context, NULL, kd, &old_key, NULL); + if (ret) + return ret; +- ret = try_verify_pac(context, enc_tkt, server, server_key, &old_key, +- pac_out); ++ ret = try_verify_pac(context, enc_tkt, server, server_key, tgt, ++ &old_key, pac_out); + krb5_free_keyblock_contents(context, &old_key); + if (!ret) + return 0; +diff --git a/src/lib/krb5/krb/pac.c b/src/lib/krb5/krb/pac.c +index 5d1fdf1ba0..0c0e2ada68 100644 +--- a/src/lib/krb5/krb/pac.c ++++ b/src/lib/krb5/krb/pac.c +@@ -594,6 +594,19 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + krb5_const_principal server_princ, + const krb5_keyblock *server, + const krb5_keyblock *privsvr, krb5_pac *pac_out) ++{ ++ return krb5_kdc_verify_ticket_ext(context, enc_tkt, server_princ, server, ++ privsvr, FALSE, pac_out); ++} ++ ++krb5_error_code KRB5_CALLCONV ++krb5_kdc_verify_ticket_ext(krb5_context context, ++ const krb5_enc_tkt_part *enc_tkt, ++ krb5_const_principal server_princ, ++ const krb5_keyblock *server, ++ const krb5_keyblock *privsvr, ++ krb5_boolean optional_tkt_chksum, ++ krb5_pac *pac_out) + { + krb5_error_code ret; + krb5_pac pac = NULL; +@@ -602,7 +615,7 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + krb5_authdata *orig, **ifrel = NULL, **recoded_ifrel = NULL; + uint8_t z = 0; + krb5_authdata zpac = { KV5M_AUTHDATA, KRB5_AUTHDATA_WIN2K_PAC, 1, &z }; +- krb5_boolean is_service_tkt; ++ krb5_boolean is_service_tkt, has_tkt_chksum = FALSE; + size_t i, j; + + *pac_out = NULL; +@@ -667,11 +680,21 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, + + ret = verify_checksum(context, pac, KRB5_PAC_TICKET_CHECKSUM, privsvr, + KRB5_KEYUSAGE_APP_DATA_CKSUM, recoded_tkt); +- if (ret) +- goto cleanup; ++ if (ret) { ++ if (!optional_tkt_chksum) ++ goto cleanup; ++ else if (ret != ENOENT) ++ goto cleanup; ++ /* Otherwise ticket signature is absent but optional. Proceed... */ ++ } else { ++ has_tkt_chksum = TRUE; ++ } + } ++ /* Else, we make the assumption the ticket signature is absent in case this ++ * is not a service ticket. ++ */ + +- ret = verify_pac_checksums(context, pac, is_service_tkt, server, privsvr); ++ ret = verify_pac_checksums(context, pac, has_tkt_chksum, server, privsvr); + if (ret) + goto cleanup; + +diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports +index 4c50e935a2..d4b0455c8c 100644 +--- a/src/lib/krb5/libkrb5.exports ++++ b/src/lib/krb5/libkrb5.exports +@@ -463,6 +463,7 @@ krb5_is_thread_safe + krb5_kdc_rep_decrypt_proc + krb5_kdc_sign_ticket + krb5_kdc_verify_ticket ++krb5_kdc_verify_ticket_ext + krb5_kt_add_entry + krb5_kt_client_default + krb5_kt_close +diff --git a/src/man/kadmin.man b/src/man/kadmin.man +index d028dc2975..2c8d10067f 100644 +--- a/src/man/kadmin.man ++++ b/src/man/kadmin.man +@@ -724,6 +724,12 @@ encryption type. It may be necessary to set this value to + "aes256\-sha1" on the cross\-realm krbtgt entry for an Active + Directory realm when using aes\-sha2 keys on the local krbtgt + entry. ++.TP ++\fBoptional_pac_tkt_chksum\fP ++Boolean value defining the behavior of the KDC in case an expected ticket ++checksum signed with one of this principal keys is not present in the PAC. This ++is typically the case for TGS or cross-realm TGS principals when processing ++S4U2Proxy requests. + .UNINDENT + .sp + This command requires the \fBmodify\fP privilege. +-- +2.40.1 + diff --git a/0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch b/0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch deleted file mode 100644 index 373cd1a..0000000 --- a/0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch +++ /dev/null @@ -1,28 +0,0 @@ -From c7d2d7c090bc000acd67b358150b9487f606ff20 Mon Sep 17 00:00:00 2001 -From: Julien Rische -Date: Fri, 19 Aug 2022 10:34:52 +0200 -Subject: [PATCH] [downstream] Catch SHA-1 digest disallowed error for - PKINIT - -An OpenSSL patch causes EVP_R_INVALID_DIGEST error to be raised if -CMS_verify is called to verify a SHA-1 signature. If this error is -caught, it will now return KDC_ERR_DIGEST_IN_SIGNED_DATA_NOT_ACCEPTED. ---- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 16edf15cb2..bfa3fe8e91 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2104,6 +2104,7 @@ cms_signeddata_verify(krb5_context context, - if (CMS_verify(cms, NULL, store, NULL, out, flags) == 0) { - unsigned long err = ERR_peek_last_error(); - switch(ERR_GET_REASON(err)) { -+ case EVP_R_INVALID_DIGEST: - case RSA_R_DIGEST_NOT_ALLOWED: - case CMS_R_UNKNOWN_DIGEST_ALGORITHM: - case CMS_R_NO_MATCHING_DIGEST: --- -2.38.1 - diff --git a/0012-Add-and-use-ts_interval-helper.patch b/0012-Add-and-use-ts_interval-helper.patch deleted file mode 100644 index 5f9647e..0000000 --- a/0012-Add-and-use-ts_interval-helper.patch +++ /dev/null @@ -1,239 +0,0 @@ -From 07ec260c65ec036d44362868df0f796a53495f27 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Mon, 19 Sep 2022 15:18:50 -0400 -Subject: [PATCH] Add and use ts_interval() helper - -ts_delta() returns a signed result, which cannot hold an interval -larger than 2^31-1 seconds. Intervals like this have been seen when -admins set password expiration dates more than 68 years in the future. - -Add a second helper ts_interval() which returns a signed result, and -has the arguments reversed so that the start time is first. Use it in -warn_pw_expiry() to handle the password expiration case, in the GSS -krb5 mech where we return an unsigned context or credential lifetime -to the caller, and in the KEYRING ccache type where we compute an -unsigned keyring timeout. - -ticket: 9071 (new) ---- - src/include/k5-int.h | 9 +++++++++ - src/lib/gssapi/krb5/accept_sec_context.c | 10 ++++++---- - src/lib/gssapi/krb5/acquire_cred.c | 3 +-- - src/lib/gssapi/krb5/context_time.c | 2 +- - src/lib/gssapi/krb5/init_sec_context.c | 4 ++-- - src/lib/gssapi/krb5/inq_context.c | 2 +- - src/lib/gssapi/krb5/inq_cred.c | 2 +- - src/lib/gssapi/krb5/s4u_gss_glue.c | 2 +- - src/lib/krb5/ccache/cc_keyring.c | 4 ++-- - src/lib/krb5/krb/get_in_tkt.c | 15 +++++++-------- - 10 files changed, 31 insertions(+), 22 deletions(-) - -diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index c3aecba7d4..768110e5ef 100644 ---- a/src/include/k5-int.h -+++ b/src/include/k5-int.h -@@ -2325,6 +2325,15 @@ ts_delta(krb5_timestamp a, krb5_timestamp b) - return (krb5_deltat)((uint32_t)a - (uint32_t)b); - } - -+/* Return (end - start) as an unsigned 32-bit value, or 0 if start > end. */ -+static inline uint32_t -+ts_interval(krb5_timestamp start, krb5_timestamp end) -+{ -+ if ((uint32_t)start > (uint32_t)end) -+ return 0; -+ return (uint32_t)end - (uint32_t)start; -+} -+ - /* Increment a timestamp by a signed 32-bit interval, without relying on - * undefined behavior. */ - static inline krb5_timestamp -diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c -index 1bc807172b..7de2c9fd77 100644 ---- a/src/lib/gssapi/krb5/accept_sec_context.c -+++ b/src/lib/gssapi/krb5/accept_sec_context.c -@@ -353,8 +353,8 @@ kg_accept_dce(minor_status, context_handle, verifier_cred_handle, - *mech_type = ctx->mech_used; - - if (time_rec) { -- *time_rec = ts_delta(ctx->krb_times.endtime, now) + -- ctx->k5_context->clockskew; -+ *time_rec = ts_interval(now - ctx->k5_context->clockskew, -+ ctx->krb_times.endtime); - } - - /* Never return GSS_C_DELEG_FLAG since we don't support DCE credential -@@ -1151,8 +1151,10 @@ kg_accept_krb5(minor_status, context_handle, - - /* Add the maximum allowable clock skew as a grace period for context - * expiration, just as we do for the ticket. */ -- if (time_rec) -- *time_rec = ts_delta(ctx->krb_times.endtime, now) + context->clockskew; -+ if (time_rec) { -+ *time_rec = ts_interval(now - context->clockskew, -+ ctx->krb_times.endtime); -+ } - - if (ret_flags) - *ret_flags = ctx->gss_flags; -diff --git a/src/lib/gssapi/krb5/acquire_cred.c b/src/lib/gssapi/krb5/acquire_cred.c -index e226a02692..006eba114d 100644 ---- a/src/lib/gssapi/krb5/acquire_cred.c -+++ b/src/lib/gssapi/krb5/acquire_cred.c -@@ -879,8 +879,7 @@ acquire_cred_context(krb5_context context, OM_uint32 *minor_status, - GSS_C_NO_NAME); - if (GSS_ERROR(ret)) - goto error_out; -- *time_rec = ts_after(cred->expire, now) ? -- ts_delta(cred->expire, now) : 0; -+ *time_rec = ts_interval(now, cred->expire); - k5_mutex_unlock(&cred->lock); - } - } -diff --git a/src/lib/gssapi/krb5/context_time.c b/src/lib/gssapi/krb5/context_time.c -index 1fdb5a16f2..5469d8154c 100644 ---- a/src/lib/gssapi/krb5/context_time.c -+++ b/src/lib/gssapi/krb5/context_time.c -@@ -51,7 +51,7 @@ krb5_gss_context_time(minor_status, context_handle, time_rec) - return(GSS_S_FAILURE); - } - -- lifetime = ts_delta(ctx->krb_times.endtime, now); -+ lifetime = ts_interval(now, ctx->krb_times.endtime); - if (!ctx->initiate) - lifetime += ctx->k5_context->clockskew; - if (lifetime <= 0) { -diff --git a/src/lib/gssapi/krb5/init_sec_context.c b/src/lib/gssapi/krb5/init_sec_context.c -index ea87cf6432..f0f094ccb7 100644 ---- a/src/lib/gssapi/krb5/init_sec_context.c -+++ b/src/lib/gssapi/krb5/init_sec_context.c -@@ -664,7 +664,7 @@ kg_new_connection( - if (time_rec) { - if ((code = krb5_timeofday(context, &now))) - goto cleanup; -- *time_rec = ts_delta(ctx->krb_times.endtime, now); -+ *time_rec = ts_interval(now, ctx->krb_times.endtime); - } - - /* set the other returns */ -@@ -878,7 +878,7 @@ mutual_auth( - if (time_rec) { - if ((code = krb5_timeofday(context, &now))) - goto fail; -- *time_rec = ts_delta(ctx->krb_times.endtime, now); -+ *time_rec = ts_interval(now, ctx->krb_times.endtime); - } - - if (ret_flags) -diff --git a/src/lib/gssapi/krb5/inq_context.c b/src/lib/gssapi/krb5/inq_context.c -index cac024da1f..51c484fdfe 100644 ---- a/src/lib/gssapi/krb5/inq_context.c -+++ b/src/lib/gssapi/krb5/inq_context.c -@@ -120,7 +120,7 @@ krb5_gss_inquire_context(minor_status, context_handle, initiator_name, - - /* Add the maximum allowable clock skew as a grace period for context - * expiration, just as we do for the ticket during authentication. */ -- lifetime = ts_delta(ctx->krb_times.endtime, now); -+ lifetime = ts_interval(now, ctx->krb_times.endtime); - if (!ctx->initiate) - lifetime += context->clockskew; - if (lifetime < 0) -diff --git a/src/lib/gssapi/krb5/inq_cred.c b/src/lib/gssapi/krb5/inq_cred.c -index bb63b726c8..0e675959a3 100644 ---- a/src/lib/gssapi/krb5/inq_cred.c -+++ b/src/lib/gssapi/krb5/inq_cred.c -@@ -131,7 +131,7 @@ krb5_gss_inquire_cred(minor_status, cred_handle, name, lifetime_ret, - } - - if (cred->expire != 0) { -- lifetime = ts_delta(cred->expire, now); -+ lifetime = ts_interval(now, cred->expire); - if (lifetime < 0) - lifetime = 0; - } -diff --git a/src/lib/gssapi/krb5/s4u_gss_glue.c b/src/lib/gssapi/krb5/s4u_gss_glue.c -index 7dcfe4e1eb..fa7f980af7 100644 ---- a/src/lib/gssapi/krb5/s4u_gss_glue.c -+++ b/src/lib/gssapi/krb5/s4u_gss_glue.c -@@ -279,7 +279,7 @@ kg_compose_deleg_cred(OM_uint32 *minor_status, - if (code != 0) - goto cleanup; - -- *time_rec = ts_delta(cred->expire, now); -+ *time_rec = ts_interval(now, cred->expire); - } - - major_status = GSS_S_COMPLETE; -diff --git a/src/lib/krb5/ccache/cc_keyring.c b/src/lib/krb5/ccache/cc_keyring.c -index ebef37d607..1dadeef64f 100644 ---- a/src/lib/krb5/ccache/cc_keyring.c -+++ b/src/lib/krb5/ccache/cc_keyring.c -@@ -762,7 +762,7 @@ update_keyring_expiration(krb5_context context, krb5_ccache id) - - /* Setting the timeout to zero would reset the timeout, so we set it to one - * second instead if creds are already expired. */ -- timeout = ts_after(endtime, now) ? ts_delta(endtime, now) : 1; -+ timeout = ts_after(endtime, now) ? ts_interval(now, endtime) : 1; - (void)keyctl_set_timeout(data->cache_id, timeout); - } - -@@ -1343,7 +1343,7 @@ krcc_store(krb5_context context, krb5_ccache id, krb5_creds *creds) - - if (ts_after(creds->times.endtime, now)) { - (void)keyctl_set_timeout(cred_key, -- ts_delta(creds->times.endtime, now)); -+ ts_interval(now, creds->times.endtime)); - } - - update_keyring_expiration(context, id); -diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c -index 8b5ab595e9..1b420a3ac2 100644 ---- a/src/lib/krb5/krb/get_in_tkt.c -+++ b/src/lib/krb5/krb/get_in_tkt.c -@@ -1522,7 +1522,7 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, - void *expire_data; - krb5_timestamp pw_exp, acct_exp, now; - krb5_boolean is_last_req; -- krb5_deltat delta; -+ uint32_t interval; - char ts[256], banner[1024]; - - if (as_reply == NULL || as_reply->enc_part2 == NULL) -@@ -1553,8 +1553,8 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, - ret = krb5_timeofday(context, &now); - if (ret != 0) - return; -- if (!is_last_req && -- (ts_after(now, pw_exp) || ts_delta(pw_exp, now) > 7 * 24 * 60 * 60)) -+ interval = ts_interval(now, pw_exp); -+ if (!is_last_req && (!interval || interval > 7 * 24 * 60 * 60)) - return; - - if (!prompter) -@@ -1564,19 +1564,18 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, - if (ret != 0) - return; - -- delta = ts_delta(pw_exp, now); -- if (delta < 3600) { -+ if (interval < 3600) { - snprintf(banner, sizeof(banner), - _("Warning: Your password will expire in less than one hour " - "on %s"), ts); -- } else if (delta < 86400 * 2) { -+ } else if (interval < 86400 * 2) { - snprintf(banner, sizeof(banner), - _("Warning: Your password will expire in %d hour%s on %s"), -- delta / 3600, delta < 7200 ? "" : "s", ts); -+ interval / 3600, interval < 7200 ? "" : "s", ts); - } else { - snprintf(banner, sizeof(banner), - _("Warning: Your password will expire in %d days on %s"), -- delta / 86400, ts); -+ interval / 86400, ts); - } - - /* PROMPTER_INVOCATION */ --- -2.38.1 - diff --git a/0012-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch b/0012-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch new file mode 100644 index 0000000..c40ed12 --- /dev/null +++ b/0012-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch @@ -0,0 +1,47 @@ +From d1322546dca51100759eac318ce554bd301c50c3 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Tue, 23 May 2023 12:19:54 +0200 +Subject: [PATCH] [downstream] Make PKINIT CMS SHA-1 signature verification + available in FIPS mode + +We recommend using the SHA1 crypto-module in order to allow the +verification of SHA-1 signature for CMS messages. However, this module +does not work in FIPS mode, because the SHA-1 algorithm is absent from +the OpenSSL FIPS provider. + +This commit enables the signature verification process to fetch the +algorithm from a non-FIPS OpenSSL provider. + +Support for SHA-1 CMS signature is still required, especially in order +to interoperate with Active Directory. At least it is until elliptic +curve cryptography is implemented for PKINIT in MIT krb5. +--- + src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 11 ++++++++++- + 1 file changed, 10 insertions(+), 1 deletion(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index f41328763e..263ef7845e 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -1844,8 +1844,17 @@ cms_signeddata_verify(krb5_context context, + if (oid == NULL) + goto cleanup; + ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++ /* Do not use FIPS provider (even in FIPS mode) because it keeps from ++ * allowing SHA-1 signature verification using the SHA1 crypto-module ++ */ ++ cms = CMS_ContentInfo_new_ex(NULL, "-fips"); ++ if (!cms) ++ goto cleanup; ++#endif ++ + /* decode received CMS message */ +- if ((cms = d2i_CMS_ContentInfo(NULL, &p, (int)signed_data_len)) == NULL) { ++ if (!d2i_CMS_ContentInfo(&cms, &p, (int)signed_data_len)) { + retval = oerr(context, 0, _("Failed to decode CMS message")); + goto cleanup; + } +-- +2.40.1 + diff --git a/0013-Enable-PKINIT-if-at-least-one-group-is-available.patch b/0013-Enable-PKINIT-if-at-least-one-group-is-available.patch new file mode 100644 index 0000000..ebfa323 --- /dev/null +++ b/0013-Enable-PKINIT-if-at-least-one-group-is-available.patch @@ -0,0 +1,218 @@ +From a378b1970d92692baeddf6a8681f47efb13e343d Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 30 May 2023 01:21:48 -0400 +Subject: [PATCH] Enable PKINIT if at least one group is available + +OpenSSL may no longer allow decoding of non-well-known Diffie-Hellman +group parameters as EVP_PKEY objects in FIPS mode. However, OpenSSL +does not know about MODP group 2 (1024-bit), which is considered as a +custom group. As a consequence, the PKINIT kdcpreauth module fails to +load in FIPS mode. + +Allow initialization of PKINIT plugin if at least one of the MODP +well-known group parameters successfully decodes. + +[ghudson@mit.edu: minor commit message and code edits] + +ticket: 9096 (new) +(cherry picked from commit 509d8db922e9ad6f108883838473b6178f89874a) +--- + src/plugins/preauth/pkinit/pkinit_clnt.c | 2 +- + src/plugins/preauth/pkinit/pkinit_crypto.h | 3 +- + .../preauth/pkinit/pkinit_crypto_openssl.c | 76 +++++++++++-------- + src/plugins/preauth/pkinit/pkinit_srv.c | 2 +- + src/plugins/preauth/pkinit/pkinit_trace.h | 3 + + 5 files changed, 51 insertions(+), 35 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c +index 725d5bc438..ea9ba454df 100644 +--- a/src/plugins/preauth/pkinit/pkinit_clnt.c ++++ b/src/plugins/preauth/pkinit/pkinit_clnt.c +@@ -1378,7 +1378,7 @@ pkinit_client_plugin_init(krb5_context context, + if (retval) + goto errout; + +- retval = pkinit_init_plg_crypto(&ctx->cryptoctx); ++ retval = pkinit_init_plg_crypto(context, &ctx->cryptoctx); + if (retval) + goto errout; + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index 9fa315d7a0..8bdbea8e95 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -103,7 +103,8 @@ typedef struct _pkinit_cert_matching_data { + /* + * Functions to initialize and cleanup crypto contexts + */ +-krb5_error_code pkinit_init_plg_crypto(pkinit_plg_crypto_context *); ++krb5_error_code pkinit_init_plg_crypto(krb5_context, ++ pkinit_plg_crypto_context *); + void pkinit_fini_plg_crypto(pkinit_plg_crypto_context); + + krb5_error_code pkinit_init_req_crypto(pkinit_req_crypto_context *); +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 263ef7845e..d646073d55 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -47,7 +47,8 @@ + static krb5_error_code pkinit_init_pkinit_oids(pkinit_plg_crypto_context ); + static void pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ); + +-static krb5_error_code pkinit_init_dh_params(pkinit_plg_crypto_context ); ++static krb5_error_code pkinit_init_dh_params(krb5_context, ++ pkinit_plg_crypto_context); + static void pkinit_fini_dh_params(pkinit_plg_crypto_context ); + + static krb5_error_code pkinit_init_certs(pkinit_identity_crypto_context ctx); +@@ -951,7 +952,8 @@ oerr_cert(krb5_context context, krb5_error_code code, X509_STORE_CTX *certctx, + } + + krb5_error_code +-pkinit_init_plg_crypto(pkinit_plg_crypto_context *cryptoctx) ++pkinit_init_plg_crypto(krb5_context context, ++ pkinit_plg_crypto_context *cryptoctx) + { + krb5_error_code retval = ENOMEM; + pkinit_plg_crypto_context ctx = NULL; +@@ -969,7 +971,7 @@ pkinit_init_plg_crypto(pkinit_plg_crypto_context *cryptoctx) + if (retval) + goto out; + +- retval = pkinit_init_dh_params(ctx); ++ retval = pkinit_init_dh_params(context, ctx); + if (retval) + goto out; + +@@ -1278,30 +1280,36 @@ pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ctx) + ASN1_OBJECT_free(ctx->id_kp_serverAuth); + } + +-static krb5_error_code +-pkinit_init_dh_params(pkinit_plg_crypto_context plgctx) ++static int ++try_import_group(krb5_context context, const krb5_data *params, ++ const char *name, EVP_PKEY **pkey_out) + { +- krb5_error_code retval = ENOMEM; +- +- plgctx->dh_1024 = decode_dh_params(&oakley_1024); +- if (plgctx->dh_1024 == NULL) +- goto cleanup; +- +- plgctx->dh_2048 = decode_dh_params(&oakley_2048); +- if (plgctx->dh_2048 == NULL) +- goto cleanup; ++ *pkey_out = decode_dh_params(params); ++ if (*pkey_out == NULL) ++ TRACE_PKINIT_DH_GROUP_UNAVAILABLE(context, name); ++ return (*pkey_out != NULL) ? 1 : 0; ++} + +- plgctx->dh_4096 = decode_dh_params(&oakley_4096); +- if (plgctx->dh_4096 == NULL) +- goto cleanup; ++static krb5_error_code ++pkinit_init_dh_params(krb5_context context, pkinit_plg_crypto_context plgctx) ++{ ++ int n = 0; + +- retval = 0; ++ n += try_import_group(context, &oakley_1024, "MODP 2 (1024-bit)", ++ &plgctx->dh_1024); ++ n += try_import_group(context, &oakley_2048, "MODP 14 (2048-bit)", ++ &plgctx->dh_2048); ++ n += try_import_group(context, &oakley_4096, "MODP 16 (4096-bit)", ++ &plgctx->dh_4096); + +-cleanup: +- if (retval) ++ if (n == 0) { + pkinit_fini_dh_params(plgctx); ++ k5_setmsg(context, ENOMEM, ++ _("PKINIT cannot initialize any key exchange groups")); ++ return ENOMEM; ++ } + +- return retval; ++ return 0; + } + + static void +@@ -2910,11 +2918,11 @@ client_create_dh(krb5_context context, + + if (cryptoctx->received_params != NULL) + params = cryptoctx->received_params; +- else if (dh_size == 1024) ++ else if (plg_cryptoctx->dh_1024 != NULL && dh_size == 1024) + params = plg_cryptoctx->dh_1024; +- else if (dh_size == 2048) ++ else if (plg_cryptoctx->dh_2048 != NULL && dh_size == 2048) + params = plg_cryptoctx->dh_2048; +- else if (dh_size == 4096) ++ else if (plg_cryptoctx->dh_4096 != NULL && dh_size == 4096) + params = plg_cryptoctx->dh_4096; + else + goto cleanup; +@@ -3210,19 +3218,23 @@ pkinit_create_td_dh_parameters(krb5_context context, + krb5_algorithm_identifier alg_4096 = { dh_oid, oakley_4096 }; + krb5_algorithm_identifier *alglist[4]; + +- if (opts->dh_min_bits > 4096) { +- ret = KRB5KRB_ERR_GENERIC; +- goto cleanup; +- } +- + i = 0; +- if (opts->dh_min_bits <= 2048) ++ if (plg_cryptoctx->dh_2048 != NULL && opts->dh_min_bits <= 2048) + alglist[i++] = &alg_2048; +- alglist[i++] = &alg_4096; +- if (opts->dh_min_bits <= 1024) ++ if (plg_cryptoctx->dh_4096 != NULL && opts->dh_min_bits <= 4096) ++ alglist[i++] = &alg_4096; ++ if (plg_cryptoctx->dh_1024 != NULL && opts->dh_min_bits <= 1024) + alglist[i++] = &alg_1024; + alglist[i] = NULL; + ++ if (i == 0) { ++ ret = KRB5KRB_ERR_GENERIC; ++ k5_setmsg(context, ret, ++ _("OpenSSL has no supported key exchange groups for " ++ "pkinit_dh_min_bits=%d"), opts->dh_min_bits); ++ goto cleanup; ++ } ++ + ret = k5int_encode_krb5_td_dh_parameters(alglist, &der_alglist); + if (ret) + goto cleanup; +diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c +index 1b3bf6d4d0..768a4e559f 100644 +--- a/src/plugins/preauth/pkinit/pkinit_srv.c ++++ b/src/plugins/preauth/pkinit/pkinit_srv.c +@@ -1222,7 +1222,7 @@ pkinit_server_plugin_init_realm(krb5_context context, const char *realmname, + goto errout; + plgctx->realmname_len = strlen(plgctx->realmname); + +- retval = pkinit_init_plg_crypto(&plgctx->cryptoctx); ++ retval = pkinit_init_plg_crypto(context, &plgctx->cryptoctx); + if (retval) + goto errout; + +diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h +index 259e95c6c2..5ee39c085c 100644 +--- a/src/plugins/preauth/pkinit/pkinit_trace.h ++++ b/src/plugins/preauth/pkinit/pkinit_trace.h +@@ -90,6 +90,9 @@ + #define TRACE_PKINIT_CLIENT_TRYAGAIN(c) \ + TRACE(c, "PKINIT client trying again with KDC-provided parameters") + ++#define TRACE_PKINIT_DH_GROUP_UNAVAILABLE(c, name) \ ++ TRACE(c, "PKINIT key exchange group {str} unsupported", name) ++ + #define TRACE_PKINIT_OPENSSL_ERROR(c, msg) \ + TRACE(c, "PKINIT OpenSSL error: {str}", msg) + +-- +2.40.1 + diff --git a/0017-Add-PAC-full-checksums.patch b/0017-Add-PAC-full-checksums.patch deleted file mode 100644 index f0a20f6..0000000 --- a/0017-Add-PAC-full-checksums.patch +++ /dev/null @@ -1,672 +0,0 @@ -From 5801da1ddc3b0984ad6997bb7a692eac85ff7dd3 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Thu, 22 Dec 2022 03:05:23 -0500 -Subject: [PATCH] Add PAC full checksums - -A paper by Tom Tervoort noted that computing the PAC privsvr checksum -over only the server checksum is vulnerable to collision attacks -(CVE-2022-37967). In response, Microsoft has added a second KDC -checksum over the full contents of the PAC. Generate and verify full -KDC checksums in PACs for service tickets. Update the t_pac.c ticket -test case to use a ticket issued by a recent version of Active -Directory (provided by Stefan Metzmacher). - -ticket: 9084 (new) ---- - doc/appdev/refs/macros/index.rst | 1 + - src/include/krb5/krb5.hin | 1 + - src/lib/krb5/krb/pac.c | 92 +++++++++-------- - src/lib/krb5/krb/pac_sign.c | 146 +++++++++++++++----------- - src/lib/krb5/krb/t_pac.c | 171 ++++++++++++++++++------------- - src/tests/t_authdata.py | 4 +- - 6 files changed, 240 insertions(+), 175 deletions(-) - -diff --git a/doc/appdev/refs/macros/index.rst b/doc/appdev/refs/macros/index.rst -index 5f34dea5e8..3eeee25593 100644 ---- a/doc/appdev/refs/macros/index.rst -+++ b/doc/appdev/refs/macros/index.rst -@@ -247,6 +247,7 @@ Public - KRB5_PAC_SERVER_CHECKSUM.rst - KRB5_PAC_TICKET_CHECKSUM.rst - KRB5_PAC_UPN_DNS_INFO.rst -+ KRB5_PAC_FULL_CHECKSUM.rst - KRB5_PADATA_AFS3_SALT.rst - KRB5_PADATA_AP_REQ.rst - KRB5_PADATA_AS_CHECKSUM.rst -diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index fb9f2a366c..2ba4010514 100644 ---- a/src/include/krb5/krb5.hin -+++ b/src/include/krb5/krb5.hin -@@ -8164,6 +8164,7 @@ krb5_verify_authdata_kdc_issued(krb5_context context, - #define KRB5_PAC_TICKET_CHECKSUM 16 /**< Ticket checksum */ - #define KRB5_PAC_ATTRIBUTES_INFO 17 /**< PAC attributes */ - #define KRB5_PAC_REQUESTOR 18 /**< PAC requestor SID */ -+#define KRB5_PAC_FULL_CHECKSUM 19 /**< KDC full checksum */ - - struct krb5_pac_data; - /** PAC data structure to convey authorization information */ -diff --git a/src/lib/krb5/krb/pac.c b/src/lib/krb5/krb/pac.c -index f6c4373de0..954482e0c7 100644 ---- a/src/lib/krb5/krb/pac.c -+++ b/src/lib/krb5/krb/pac.c -@@ -490,7 +490,8 @@ zero_signature(krb5_context context, const krb5_pac pac, krb5_ui_4 type, - size_t i; - - assert(type == KRB5_PAC_SERVER_CHECKSUM || -- type == KRB5_PAC_PRIVSVR_CHECKSUM); -+ type == KRB5_PAC_PRIVSVR_CHECKSUM || -+ type == KRB5_PAC_FULL_CHECKSUM); - assert(data->length >= pac->data.length); - - for (i = 0; i < pac->pac->cBuffers; i++) { -@@ -557,17 +558,17 @@ verify_checksum(krb5_context context, const krb5_pac pac, uint32_t buffer_type, - } - - static krb5_error_code --verify_server_checksum(krb5_context context, const krb5_pac pac, -- const krb5_keyblock *server) -+verify_pac_checksums(krb5_context context, const krb5_pac pac, -+ krb5_boolean expect_full_checksum, -+ const krb5_keyblock *server, const krb5_keyblock *privsvr) - { - krb5_error_code ret; -- krb5_data copy; /* PAC with zeroed checksums */ -+ krb5_data copy, server_checksum; - -+ /* Make a copy of the PAC with zeroed out server and privsvr checksums. */ - ret = krb5int_copy_data_contents(context, &pac->data, ©); - if (ret) - return ret; -- -- /* Zero out both checksum buffers */ - ret = zero_signature(context, pac, KRB5_PAC_SERVER_CHECKSUM, ©); - if (ret) - goto cleanup; -@@ -575,32 +576,46 @@ verify_server_checksum(krb5_context context, const krb5_pac pac, - if (ret) - goto cleanup; - -- ret = verify_checksum(context, pac, KRB5_PAC_SERVER_CHECKSUM, server, -- KRB5_KEYUSAGE_APP_DATA_CKSUM, ©); -+ if (server != NULL) { -+ /* Verify the server checksum over the PAC copy. */ -+ ret = verify_checksum(context, pac, KRB5_PAC_SERVER_CHECKSUM, server, -+ KRB5_KEYUSAGE_APP_DATA_CKSUM, ©); -+ } - --cleanup: -- free(copy.data); -- return ret; --} -+ if (privsvr != NULL && expect_full_checksum) { -+ /* Zero the full checksum buffer in the copy and verify the full -+ * checksum over the copy with all three checksums zeroed. */ -+ ret = zero_signature(context, pac, KRB5_PAC_FULL_CHECKSUM, ©); -+ if (ret) -+ goto cleanup; -+ ret = verify_checksum(context, pac, KRB5_PAC_FULL_CHECKSUM, privsvr, -+ KRB5_KEYUSAGE_APP_DATA_CKSUM, ©); -+ if (ret) -+ goto cleanup; -+ } - --static krb5_error_code --verify_kdc_checksum(krb5_context context, const krb5_pac pac, -- const krb5_keyblock *privsvr) --{ -- krb5_error_code ret; -- krb5_data server_checksum; -+ if (privsvr != NULL) { -+ /* Verify the privsvr checksum over the server checksum. */ -+ ret = k5_pac_locate_buffer(context, pac, KRB5_PAC_SERVER_CHECKSUM, -+ &server_checksum); -+ if (ret) -+ return ret; -+ if (server_checksum.length < PAC_SIGNATURE_DATA_LENGTH) -+ return KRB5_BAD_MSIZE; -+ server_checksum.data += PAC_SIGNATURE_DATA_LENGTH; -+ server_checksum.length -= PAC_SIGNATURE_DATA_LENGTH; - -- ret = k5_pac_locate_buffer(context, pac, KRB5_PAC_SERVER_CHECKSUM, -- &server_checksum); -- if (ret) -- return ret; -- if (server_checksum.length < PAC_SIGNATURE_DATA_LENGTH) -- return KRB5_BAD_MSIZE; -- server_checksum.data += PAC_SIGNATURE_DATA_LENGTH; -- server_checksum.length -= PAC_SIGNATURE_DATA_LENGTH; -+ ret = verify_checksum(context, pac, KRB5_PAC_PRIVSVR_CHECKSUM, privsvr, -+ KRB5_KEYUSAGE_APP_DATA_CKSUM, &server_checksum); -+ if (ret) -+ goto cleanup; -+ } -+ -+ pac->verified = TRUE; - -- return verify_checksum(context, pac, KRB5_PAC_PRIVSVR_CHECKSUM, privsvr, -- KRB5_KEYUSAGE_APP_DATA_CKSUM, &server_checksum); -+cleanup: -+ free(copy.data); -+ return ret; - } - - /* Per MS-PAC 2.8.3, tickets encrypted to TGS and password change principals -@@ -628,6 +643,7 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, - krb5_authdata **authdata, *orig, **ifrel = NULL, **recoded_ifrel = NULL; - uint8_t z = 0; - krb5_authdata zpac = { KV5M_AUTHDATA, KRB5_AUTHDATA_WIN2K_PAC, 1, &z }; -+ krb5_boolean is_service_tkt; - size_t i, j; - - *pac_out = NULL; -@@ -669,7 +685,8 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, - if (ret) - goto cleanup; - -- if (privsvr != NULL && k5_pac_should_have_ticket_signature(server_princ)) { -+ is_service_tkt = k5_pac_should_have_ticket_signature(server_princ); -+ if (privsvr != NULL && is_service_tkt) { - /* To check the PAC ticket signatures, re-encode the ticket with the - * PAC contents replaced by a single zero. */ - orig = ifrel[j]; -@@ -693,8 +710,9 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, - goto cleanup; - } - -- ret = krb5_pac_verify_ext(context, pac, enc_tkt->times.authtime, NULL, -- server, privsvr, FALSE); -+ ret = verify_pac_checksums(context, pac, is_service_tkt, server, privsvr); -+ if (ret) -+ goto cleanup; - - *pac_out = pac; - pac = NULL; -@@ -730,14 +748,8 @@ krb5_pac_verify_ext(krb5_context context, - { - krb5_error_code ret; - -- if (server != NULL) { -- ret = verify_server_checksum(context, pac, server); -- if (ret != 0) -- return ret; -- } -- -- if (privsvr != NULL) { -- ret = verify_kdc_checksum(context, pac, privsvr); -+ if (server != NULL || privsvr != NULL) { -+ ret = verify_pac_checksums(context, pac, FALSE, server, privsvr); - if (ret != 0) - return ret; - } -@@ -749,8 +761,6 @@ krb5_pac_verify_ext(krb5_context context, - return ret; - } - -- pac->verified = TRUE; -- - return 0; - } - -diff --git a/src/lib/krb5/krb/pac_sign.c b/src/lib/krb5/krb/pac_sign.c -index 0f9581abbb..8ea61ac17b 100644 ---- a/src/lib/krb5/krb/pac_sign.c -+++ b/src/lib/krb5/krb/pac_sign.c -@@ -187,26 +187,41 @@ k5_pac_encode_header(krb5_context context, krb5_pac pac) - return 0; - } - --krb5_error_code KRB5_CALLCONV --krb5_pac_sign(krb5_context context, krb5_pac pac, krb5_timestamp authtime, -- krb5_const_principal principal, const krb5_keyblock *server_key, -- const krb5_keyblock *privsvr_key, krb5_data *data) -+/* Find the buffer of type buftype in pac and write within it a checksum of -+ * type cksumtype over data. Set *cksum_out to the checksum. */ -+static krb5_error_code -+compute_pac_checksum(krb5_context context, krb5_pac pac, uint32_t buftype, -+ const krb5_keyblock *key, krb5_cksumtype cksumtype, -+ const krb5_data *data, krb5_data *cksum_out) - { -- return krb5_pac_sign_ext(context, pac, authtime, principal, server_key, -- privsvr_key, FALSE, data); -+ krb5_error_code ret; -+ krb5_data buf; -+ krb5_crypto_iov iov[2]; -+ -+ ret = k5_pac_locate_buffer(context, pac, buftype, &buf); -+ if (ret) -+ return ret; -+ -+ assert(buf.length > PAC_SIGNATURE_DATA_LENGTH); -+ *cksum_out = make_data(buf.data + PAC_SIGNATURE_DATA_LENGTH, -+ buf.length - PAC_SIGNATURE_DATA_LENGTH); -+ iov[0].flags = KRB5_CRYPTO_TYPE_DATA; -+ iov[0].data = *data; -+ iov[1].flags = KRB5_CRYPTO_TYPE_CHECKSUM; -+ iov[1].data = *cksum_out; -+ return krb5_c_make_checksum_iov(context, cksumtype, key, -+ KRB5_KEYUSAGE_APP_DATA_CKSUM, iov, 2); - } - --krb5_error_code KRB5_CALLCONV --krb5_pac_sign_ext(krb5_context context, krb5_pac pac, krb5_timestamp authtime, -- krb5_const_principal principal, -- const krb5_keyblock *server_key, -- const krb5_keyblock *privsvr_key, krb5_boolean with_realm, -- krb5_data *data) -+static krb5_error_code -+sign_pac(krb5_context context, krb5_pac pac, krb5_timestamp authtime, -+ krb5_const_principal principal, const krb5_keyblock *server_key, -+ const krb5_keyblock *privsvr_key, krb5_boolean with_realm, -+ krb5_boolean is_service_tkt, krb5_data *data) - { - krb5_error_code ret; -- krb5_data server_cksum, privsvr_cksum; -+ krb5_data full_cksum, server_cksum, privsvr_cksum; - krb5_cksumtype server_cksumtype, privsvr_cksumtype; -- krb5_crypto_iov iov[2]; - - data->length = 0; - data->data = NULL; -@@ -214,67 +229,53 @@ krb5_pac_sign_ext(krb5_context context, krb5_pac pac, krb5_timestamp authtime, - if (principal != NULL) { - ret = k5_insert_client_info(context, pac, authtime, principal, - with_realm); -- if (ret != 0) -+ if (ret) - return ret; - } - -- /* Create zeroed buffers for both checksums */ -+ /* Create zeroed buffers for all checksums. */ - ret = k5_insert_checksum(context, pac, KRB5_PAC_SERVER_CHECKSUM, - server_key, &server_cksumtype); -- if (ret != 0) -+ if (ret) - return ret; -- - ret = k5_insert_checksum(context, pac, KRB5_PAC_PRIVSVR_CHECKSUM, - privsvr_key, &privsvr_cksumtype); -- if (ret != 0) -+ if (ret) - return ret; -+ if (is_service_tkt) { -+ ret = k5_insert_checksum(context, pac, KRB5_PAC_FULL_CHECKSUM, -+ privsvr_key, &privsvr_cksumtype); -+ if (ret) -+ return ret; -+ } - -- /* Now, encode the PAC header so that the checksums will include it */ -+ /* Encode the PAC header so that the checksums will include it. */ - ret = k5_pac_encode_header(context, pac); -- if (ret != 0) -- return ret; -- -- /* Generate the server checksum over the entire PAC */ -- ret = k5_pac_locate_buffer(context, pac, KRB5_PAC_SERVER_CHECKSUM, -- &server_cksum); -- if (ret != 0) -+ if (ret) - return ret; - -- assert(server_cksum.length > PAC_SIGNATURE_DATA_LENGTH); -- -- iov[0].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[0].data = pac->data; -- -- iov[1].flags = KRB5_CRYPTO_TYPE_CHECKSUM; -- iov[1].data.data = server_cksum.data + PAC_SIGNATURE_DATA_LENGTH; -- iov[1].data.length = server_cksum.length - PAC_SIGNATURE_DATA_LENGTH; -+ if (is_service_tkt) { -+ /* Generate a full KDC checksum over the whole PAC. */ -+ ret = compute_pac_checksum(context, pac, KRB5_PAC_FULL_CHECKSUM, -+ privsvr_key, privsvr_cksumtype, -+ &pac->data, &full_cksum); -+ if (ret) -+ return ret; -+ } - -- ret = krb5_c_make_checksum_iov(context, server_cksumtype, -- server_key, KRB5_KEYUSAGE_APP_DATA_CKSUM, -- iov, sizeof(iov)/sizeof(iov[0])); -- if (ret != 0) -+ /* Generate the server checksum over the whole PAC, including the full KDC -+ * checksum if we added one. */ -+ ret = compute_pac_checksum(context, pac, KRB5_PAC_SERVER_CHECKSUM, -+ server_key, server_cksumtype, &pac->data, -+ &server_cksum); -+ if (ret) - return ret; - -- /* Generate the privsvr checksum over the server checksum buffer */ -- ret = k5_pac_locate_buffer(context, pac, KRB5_PAC_PRIVSVR_CHECKSUM, -+ /* Generate the privsvr checksum over the server checksum buffer. */ -+ ret = compute_pac_checksum(context, pac, KRB5_PAC_PRIVSVR_CHECKSUM, -+ privsvr_key, privsvr_cksumtype, &server_cksum, - &privsvr_cksum); -- if (ret != 0) -- return ret; -- -- assert(privsvr_cksum.length > PAC_SIGNATURE_DATA_LENGTH); -- -- iov[0].flags = KRB5_CRYPTO_TYPE_DATA; -- iov[0].data.data = server_cksum.data + PAC_SIGNATURE_DATA_LENGTH; -- iov[0].data.length = server_cksum.length - PAC_SIGNATURE_DATA_LENGTH; -- -- iov[1].flags = KRB5_CRYPTO_TYPE_CHECKSUM; -- iov[1].data.data = privsvr_cksum.data + PAC_SIGNATURE_DATA_LENGTH; -- iov[1].data.length = privsvr_cksum.length - PAC_SIGNATURE_DATA_LENGTH; -- -- ret = krb5_c_make_checksum_iov(context, privsvr_cksumtype, -- privsvr_key, KRB5_KEYUSAGE_APP_DATA_CKSUM, -- iov, sizeof(iov)/sizeof(iov[0])); -- if (ret != 0) -+ if (ret) - return ret; - - data->data = k5memdup(pac->data.data, pac->data.length, &ret); -@@ -288,6 +289,26 @@ krb5_pac_sign_ext(krb5_context context, krb5_pac pac, krb5_timestamp authtime, - return 0; - } - -+krb5_error_code KRB5_CALLCONV -+krb5_pac_sign(krb5_context context, krb5_pac pac, krb5_timestamp authtime, -+ krb5_const_principal principal, const krb5_keyblock *server_key, -+ const krb5_keyblock *privsvr_key, krb5_data *data) -+{ -+ return sign_pac(context, pac, authtime, principal, server_key, -+ privsvr_key, FALSE, FALSE, data); -+} -+ -+krb5_error_code KRB5_CALLCONV -+krb5_pac_sign_ext(krb5_context context, krb5_pac pac, krb5_timestamp authtime, -+ krb5_const_principal principal, -+ const krb5_keyblock *server_key, -+ const krb5_keyblock *privsvr_key, krb5_boolean with_realm, -+ krb5_data *data) -+{ -+ return sign_pac(context, pac, authtime, principal, server_key, privsvr_key, -+ with_realm, FALSE, data); -+} -+ - /* Add a signature over der_enc_tkt in privsvr to pac. der_enc_tkt should be - * encoded with a dummy PAC authdata element containing a single zero byte. */ - static krb5_error_code -@@ -359,6 +380,7 @@ krb5_kdc_sign_ticket(krb5_context context, krb5_enc_tkt_part *enc_tkt, - krb5_error_code ret; - krb5_data *der_enc_tkt = NULL, pac_data = empty_data(); - krb5_authdata **list, *pac_ad; -+ krb5_boolean is_service_tkt; - size_t count; - - /* Reallocate space for another authdata element in enc_tkt. */ -@@ -377,7 +399,8 @@ krb5_kdc_sign_ticket(krb5_context context, krb5_enc_tkt_part *enc_tkt, - memmove(list + 1, list, (count + 1) * sizeof(*list)); - list[0] = pac_ad; - -- if (k5_pac_should_have_ticket_signature(server_princ)) { -+ is_service_tkt = k5_pac_should_have_ticket_signature(server_princ); -+ if (is_service_tkt) { - ret = encode_krb5_enc_tkt_part(enc_tkt, &der_enc_tkt); - if (ret) - goto cleanup; -@@ -388,9 +411,8 @@ krb5_kdc_sign_ticket(krb5_context context, krb5_enc_tkt_part *enc_tkt, - goto cleanup; - } - -- ret = krb5_pac_sign_ext(context, pac, enc_tkt->times.authtime, -- client_princ, server, privsvr, with_realm, -- &pac_data); -+ ret = sign_pac(context, pac, enc_tkt->times.authtime, client_princ, server, -+ privsvr, with_realm, is_service_tkt, &pac_data); - if (ret) - goto cleanup; - -diff --git a/src/lib/krb5/krb/t_pac.c b/src/lib/krb5/krb/t_pac.c -index 173bde7bab..81f1642ab0 100644 ---- a/src/lib/krb5/krb/t_pac.c -+++ b/src/lib/krb5/krb/t_pac.c -@@ -607,78 +607,102 @@ check_pac(krb5_context context, int index, const unsigned char *pdata, - - static const krb5_keyblock ticket_sig_krbtgt_key = { - 0, ENCTYPE_AES256_CTS_HMAC_SHA1_96, -- 32, U("\x7a\x58\x98\xd2\xaf\xa6\xaf\xc0\x6a\xce\x06\x04\x4b\xc2\x70\x84" -- "\x9b\x8e\x0a\x6c\x4c\x07\xdc\x6f\xbb\x48\x43\xe1\xd2\xaa\x97\xf7") -+ 32, U("\x03\x73\x81\xEC\x43\x96\x7B\xC2\xAC\x3D\xF5\x2A\xAE\x95\xA6\x8E" -+ "\xBE\x24\x58\xDB\xCE\x52\x28\x20\xAF\x5E\xB7\x04\xA2\x22\x71\x4F") - }; - - static const krb5_keyblock ticket_sig_server_key = { -- 0, ENCTYPE_ARCFOUR_HMAC, -- 16, U("\xed\x23\x11\x20\x7a\x21\x44\x20\xbf\xc0\x8d\x36\xf7\xf6\xb2\x3e") -+ 0, ENCTYPE_AES256_CTS_HMAC_SHA1_96, -+ 32, U("\x11\x4A\x84\xE3\x14\x8F\xAA\xB1\xFA\x7B\x53\x51\xB2\x8A\xC2\xF1" -+ "\xFD\x19\x6D\x61\xE0\xF3\xF2\x3E\x1F\xDB\xD3\xC1\x79\x7D\xC1\xEE") - }; - -+/* A ticket issued by an Active Directory KDC (Windows Server 2022), containing -+ * a PAC with a full checksum. */ - static const krb5_data ticket_data = { -- .length = 972, .data = -- "\x61\x82\x03\xC8\x30\x82\x03\xC4\xA0\x03\x02\x01\x05\xA1\x0A\x1B" -- "\x08\x43\x44\x4F\x4D\x2E\x43\x4F\x4D\xA2\x0F\x30\x0D\xA0\x03\x02" -- "\x01\x01\xA1\x06\x30\x04\x1B\x02\x73\x31\xA3\x82\x03\x9E\x30\x82" -- "\x03\x9A\xA0\x03\x02\x01\x17\xA1\x03\x02\x01\x03\xA2\x82\x03\x8C" -- "\x04\x82\x03\x88\x44\x31\x61\x20\x17\xC9\xFE\xBC\xAC\x46\xB5\x77" -- "\xE9\x68\x04\x4C\x9B\x31\x91\x0C\xC1\xD4\xDD\xEF\xC7\x34\x20\x08" -- "\x90\x91\xE8\x79\xE0\xB5\x03\x26\xA4\x65\xDE\xEC\x47\x03\x2A\x8F" -- "\x61\xE7\x4D\x38\x5A\x42\x95\x5A\xF9\x2F\x41\x2C\x2A\x6E\x60\xA1" -- "\xEB\x51\xB3\xBD\x4C\x00\x41\x2A\x44\x76\x08\x37\x1A\x51\xFD\x65" -- "\x67\x7E\xBF\x3D\x90\x86\xE3\x9A\x54\x6B\x67\xA8\x08\x7A\x73\xCC" -- "\xC3\xB7\x4B\xD5\x5C\x3A\x14\x6C\xC1\x5F\x54\x4B\x92\x55\xB4\xB7" -- "\x92\x23\x3F\x53\x89\x47\x8E\x1F\x8B\xB9\xDB\x3B\x93\xE8\x70\xE4" -- "\x24\xB8\x9D\xF0\x0E\x35\x28\xF8\x7A\x27\x5D\xF7\x25\x97\x9C\xF5" -- "\x9F\x9F\x64\x04\xF2\xA3\xAB\x11\x15\xB6\xDA\x18\xD6\x46\xD5\xE6" -- "\xB8\x08\xDE\x0A\x62\xFD\xF8\xAA\x52\x90\xD9\x67\x29\xB2\xCD\x06" -- "\xB6\xB0\x50\x2B\x3F\x0F\xA3\xA5\xBF\xAA\x6E\x40\x03\xD6\x5F\x02" -- "\xBC\xD8\x18\x47\x97\x09\xD7\xE4\x96\x3B\xCB\xEB\x92\x2C\x3C\x49" -- "\xFF\x1F\x71\xE0\x52\x94\x0F\x8B\x9F\xB8\x2A\xBB\x9C\xE2\xA3\xDD" -- "\x38\x89\xE2\xB1\x0B\x9E\x1F\x7A\xB3\xE3\xD2\xB0\x94\xDC\x87\xBE" -- "\x37\xA6\xD3\xB3\x29\x35\x9A\x72\xC3\x7A\xF1\xA9\xE6\xC5\xD1\x26" -- "\x83\x65\x44\x17\xBA\x55\xA8\x5E\x94\x26\xED\xE9\x8A\x93\x11\x5D" -- "\x7E\x20\x1B\x9C\x15\x9E\x13\x37\x03\x4D\xDD\x99\x51\xD8\x66\x29" -- "\x6A\xB9\xFB\x49\xFE\x52\x78\xDA\x86\x85\xA9\xA3\xB9\xEF\xEC\xAD" -- "\x35\xA6\x8D\xAC\x0F\x75\x22\xBB\x0B\x49\x1C\x13\x52\x40\xC9\x52" -- "\x69\x09\x54\xD1\x0F\x94\x3F\x22\x48\x67\xB0\x96\x28\xAA\xE6\x28" -- "\xD9\x0C\x08\xEF\x51\xED\x15\x5E\xA2\x53\x59\xA5\x03\xB4\x06\x20" -- "\x3D\xCC\xB4\xC5\xF8\x8C\x73\x67\xA3\x21\x3D\x19\xCD\xD4\x12\x28" -- "\xD2\x93\xDE\x0D\xF0\x71\x10\x50\xD6\x33\x35\x04\x11\x64\x43\x39" -- "\xC3\xDF\x96\xE3\x66\xE3\x85\xCA\xE7\x67\x14\x3A\xF0\x43\xAA\xBB" -- "\xD4\x1D\xB5\x24\xB5\x74\x90\x25\xA7\x87\x7E\xDB\xD3\x83\x8A\x3A" -- "\x69\xA8\x2D\xAF\xB7\xB8\xF3\xDC\x13\xAF\x45\x61\x3F\x59\x39\x7E" -- "\x69\xDE\x0C\x04\xF1\x10\x6B\xB4\x56\xFA\x21\x9F\x72\x2B\x60\x86" -- "\xE3\x23\x0E\xC4\x51\xF6\xBE\xD8\xE1\x5F\xEE\x73\x4C\x17\x4C\x2C" -- "\x1B\xFB\x9F\x1F\x7A\x3B\x07\x5B\x8E\xF1\x01\xAC\xD6\x30\x94\x8A" -- "\x5D\x22\x6F\x08\xCE\xED\x5E\xB6\xDB\x86\x8C\x87\xEB\x8D\x91\xFF" -- "\x0A\x86\x30\xBD\xC0\xF8\x25\xE7\xAE\x24\x35\xF2\xFC\xE5\xFD\x1B" -- "\xB0\x05\x4A\xA3\xE5\xEB\x2E\x05\xAD\x99\x67\x49\x87\xE6\xB3\x87" -- "\x82\xA4\x59\xA7\x6E\xDD\xF2\xB6\x66\xE8\xF7\x70\xF5\xBD\xC9\x0E" -- "\xFA\x9C\x79\x84\xD4\x9B\x05\x0E\xBB\xF5\xDB\xEF\xFC\xCC\x26\xF2" -- "\x93\xCF\xD2\x04\x3C\xA9\x2C\x65\x42\x97\x86\xD8\x38\x0A\x1E\xF6" -- "\xD6\xCA\x30\xB5\x1A\xEC\xFB\xBA\x3B\x84\x57\xB0\xFD\xFB\xE6\xBC" -- "\xF2\x76\xF6\x4C\xBB\xAB\xB1\x31\xA1\x27\x7C\xE6\xE6\x81\xB6\xCE" -- "\x84\x86\x40\xB6\x40\x33\xC4\xF8\xB4\x15\xCF\xAA\xA5\x51\x78\xB9" -- "\x8B\x50\x25\xB2\x88\x86\x96\x72\x8C\x71\x4D\xB5\x3A\x94\x86\x77" -- "\x0E\x95\x9B\x16\x93\xEF\x3A\x11\x79\xBA\x83\xF7\x74\xD3\x8D\xBA" -- "\x15\xE1\x2C\x04\x57\xA8\x92\x1E\x9D\x00\x8E\x20\xFD\x30\x70\xE7" -- "\xF5\x65\x2F\x19\x0C\x94\xBA\x03\x71\x12\x96\xCD\xC8\xB4\x96\xDB" -- "\xCE\x19\xC2\xDF\x3C\xC2\xF6\x3D\x53\xED\x98\xA5\x41\x72\x2A\x22" -- "\x7B\xF3\x2B\x17\x6C\xE1\x39\x7D\xAE\x9B\x11\xF9\xC1\xA6\x9E\x9F" -- "\x89\x3C\x12\xAA\x94\x74\xA7\x4F\x70\xE8\xB9\xDE\x04\xF0\x9D\x39" -- "\x24\x2D\x92\xE8\x46\x2D\x2E\xF0\x40\x66\x1A\xD9\x27\xF9\x98\xF1" -- "\x81\x1D\x70\x62\x63\x30\x6D\xCD\x84\x04\x5F\xFA\x83\xD3\xEC\x8D" -- "\x86\xFB\x40\x61\xC1\x8A\x45\xFF\x7B\xD9\xD4\x18\x61\x7F\x51\xE3" -- "\xFC\x1E\x18\xF0\xAF\xC6\x18\x2C\xE1\x6D\x5D\xF9\x62\xFC\x20\xA3" -- "\xB2\x8A\x5F\xE5\xBB\x29\x0F\x99\x63\x07\x88\x38\x3A\x3B\x73\x2A" -- "\x6D\xDA\x3D\xA8\x0D\x8F\x56\x41\x89\x82\xE5\xB8\x61\x00\x64\x7D" -- "\x17\x0C\xCE\x03\x55\x8F\xF4\x5B\x0D\x50\xF2\xEB\x05\x67\xBE\xDB" -- "\x7B\x75\xC5\xEA\xA1\xAB\x1D\xB0\x3C\x6D\x42\x08\x0B\x9A\x45\x20" -- "\xA8\x8F\xE5\x67\x47\x30\xDE\x93\x5F\x43\x05\xEB\xA8\x2D\x80\xF5" -- "\x1A\xB8\x4A\x4E\x42\x2D\x0B\x7A\xDC\x46\x20\x2D\x13\x17\xDD\x4B" -- "\x94\x96\xAA\x1F\x06\x0C\x1F\x62\x07\x9C\x40\xA1" -+ .length = 1307, .data = -+ "\x61\x82\x05\x17\x30\x82\x05\x13\xA0\x03\x02\x01\x05\xA1\x0F\x1B" -+ "\x0D\x57\x32\x30\x32\x32\x2D\x4C\x37\x2E\x42\x41\x53\x45\xA2\x2A" -+ "\x30\x28\xA0\x03\x02\x01\x01\xA1\x21\x30\x1F\x1B\x04\x63\x69\x66" -+ "\x73\x1B\x17\x77\x32\x30\x32\x32\x2D\x31\x31\x38\x2E\x77\x32\x30" -+ "\x32\x32\x2D\x6C\x37\x2E\x62\x61\x73\x65\xA3\x82\x04\xCD\x30\x82" -+ "\x04\xC9\xA0\x03\x02\x01\x12\xA1\x03\x02\x01\x05\xA2\x82\x04\xBB" -+ "\x04\x82\x04\xB7\x44\x5C\x7B\x5A\x3F\x2E\xA3\x50\x34\xDE\xB0\x69" -+ "\x23\x2D\x47\x89\x2C\xC0\xA3\xF9\xDD\x70\xAA\xA5\x1E\xFE\x74\xE5" -+ "\x19\xA2\x4F\x65\x6C\x9E\x00\xB4\x60\x00\x7C\x0C\x29\x43\x31\x99" -+ "\x77\x02\x73\xED\xB9\x40\xF5\xD2\xD1\xC9\x20\x0F\xE3\x38\xF9\xCC" -+ "\x5E\x2A\xBD\x1F\x91\x66\x1A\xD8\x2A\x80\x3C\x2C\x00\x3C\x1E\xC9" -+ "\x2A\x29\x19\x19\x96\x18\x54\x03\x97\x8F\x1D\x5F\xDB\xE9\x66\x68" -+ "\xCD\xB1\xD5\x00\x35\x69\x49\x45\xF1\x6A\x78\x7B\x37\x71\x87\x14" -+ "\x1C\x98\x4D\x69\xCB\x1B\xD8\xF5\xA3\xD8\x53\x4A\x75\x76\x62\xBA" -+ "\x6C\x3F\xEA\x8B\x97\x21\xCA\x8A\x46\x4B\x38\xDA\x09\x9F\x5A\xC8" -+ "\x38\xFF\x34\x97\x5B\xA2\xE5\xBA\xC9\x87\x17\xD8\x08\x05\x7A\x83" -+ "\x04\xD6\x02\x8E\x9B\x18\xB6\x40\x1A\xF7\x47\x25\x24\x3E\x37\x1E" -+ "\xF6\xC1\x3A\x1F\xCA\xB3\x43\x5A\xAE\x94\x83\x31\xAF\xFB\xEE\xED" -+ "\x46\x71\xEF\xE2\x37\x37\x15\xFE\x1B\x0B\x9E\xF8\x3E\x0C\x43\x96" -+ "\xB6\x0A\x04\x78\xF8\x5E\xAA\x33\x1F\xE2\x07\x5A\x8D\xC4\x4E\x32" -+ "\x6D\xD6\xA0\xC5\xEA\x3D\x12\x59\xD4\x41\x40\x4E\xA1\xD8\xBE\xED" -+ "\x17\xCB\x68\xCC\x59\xCB\x53\xB2\x0E\x58\x8A\xA9\x33\x7F\x6F\x2B" -+ "\x37\x89\x08\x44\xBA\xC7\x67\x17\xBB\x91\xF7\xC3\x0F\x00\xF8\xAA" -+ "\xA1\x33\xA6\x08\x47\xCA\xFA\xE8\x49\x27\x45\x46\xF1\xC1\xC3\x5F" -+ "\xE2\x45\x0A\x7D\x64\x52\x8C\x2E\xE1\xDE\xFF\xB2\x64\xEC\x69\x98" -+ "\x15\xDF\x9E\xB1\xEB\xD6\x9D\x08\x06\x4E\x73\xC1\x0B\x71\x21\x05" -+ "\x9E\xBC\xA2\x17\xCF\xB3\x70\xF4\xEF\xB8\x69\xA9\x94\x27\xFD\x5E" -+ "\x72\xB1\x2D\xD2\x20\x1B\x57\x80\xAB\x38\x97\xCF\x22\x68\x4F\xB8" -+ "\xB7\x17\x53\x25\x67\x0B\xED\xD1\x58\x20\x0D\x45\xF9\x09\xFA\xE7" -+ "\x61\x3E\xDB\xC2\x59\x7B\x3A\x3B\x59\x81\x51\xAA\xA4\x81\xF4\x96" -+ "\x3B\xE1\x6F\x6F\xF4\x8E\x68\x9E\xBA\x1E\x0F\xF2\x44\x68\x11\xFC" -+ "\x2B\x5F\xBE\xF2\xEA\x07\x80\xB9\xCA\x9E\x41\xBD\x2F\x81\xF5\x11" -+ "\x2A\x12\xF3\x4F\xD6\x12\x16\x0F\x21\x90\xF1\xD3\x1E\xF1\xA4\x94" -+ "\x46\xEA\x30\xF3\x84\x06\xC1\xA4\x51\xFC\x43\x35\xBD\xEF\x4D\x89" -+ "\x1D\xA5\x44\xB2\x69\xC4\x0F\xBF\x86\x01\x08\x44\x77\xD5\xB4\xB7" -+ "\x5C\x3F\xA7\xD4\x2F\x39\x73\x85\x88\xEE\xB1\x64\x1D\x80\x6C\xEE" -+ "\x6E\x31\x90\x92\x0D\xA1\xB7\xC4\x5C\xCC\xEE\x91\xC8\xCB\x11\x2D" -+ "\x4A\x1A\x7D\x43\x8F\xEB\x60\x09\xED\x1B\x07\x58\xBE\xBC\xBD\x29" -+ "\xF3\xB3\xA3\x4F\xC5\x8A\x30\x33\xB9\xA9\x9F\x43\x08\x27\x15\xC4" -+ "\x9C\x5D\x8E\xBD\x5C\x05\xC6\x05\x9C\x87\x60\x08\x1E\xE2\x52\xB8" -+ "\x45\x8D\x28\xB6\x2C\x15\x46\x74\x9F\x0E\xAA\x6B\x70\x3A\x2A\x55" -+ "\x45\x26\xB2\x58\x4D\x35\xA6\xF1\x96\xBE\x60\xB2\x71\x7B\xF8\x54" -+ "\xB9\x90\x21\x8E\xB9\x0F\x35\x98\x5E\x88\xEB\x1A\x53\xB4\x59\x7F" -+ "\xAF\x69\x1C\x61\x67\xF4\xF6\xBD\xAC\x24\xCD\xB7\xA9\x67\xE8\xA1" -+ "\x83\x85\x5F\x11\x74\x1F\xF7\x4C\x78\x36\xEF\x50\x74\x88\x58\x4B" -+ "\x1A\x9F\x84\x9A\x9A\x05\x92\xEC\x1D\xD5\xF3\xC4\x95\x51\x28\xE2" -+ "\x3F\x32\x87\xB2\xFD\x21\x27\x66\xE4\x6B\x85\x2F\xDC\x7B\xC0\x22" -+ "\xEB\x7A\x94\x20\x5A\x7B\xD3\x7A\xB9\x5B\xF8\x1A\x5A\x84\x4E\xA1" -+ "\x73\x41\x53\xD2\x60\xF7\x7C\xEE\x68\x59\x85\x80\xFC\x3D\x70\x4B" -+ "\x04\x32\xE7\xF2\xFD\xBD\xB3\xD9\x21\xE2\x37\x56\xA2\x16\xCC\xDE" -+ "\x8A\xD3\xBC\x71\xEF\x58\x19\x0E\x45\x8A\x5B\x53\xD6\x77\x30\x6A" -+ "\xA7\xF8\x68\x06\x4E\x07\xCA\xCE\x30\xD7\x35\xAB\x1A\xC7\x18\xD4" -+ "\xC6\x2F\x1A\xFF\xE9\x7A\x94\x0B\x76\x5E\x7E\x29\x0C\xE6\xD3\x3B" -+ "\x5B\x44\x96\xA8\xF1\x29\x23\x95\xD9\x79\xB3\x39\xFC\x76\xED\xE1" -+ "\x1E\x67\x4E\xF7\xE8\x7B\x7A\x12\x9E\xD8\x4B\x35\x09\x0A\xF2\xC1" -+ "\x63\x5B\xEE\xFD\x2A\xC2\xA6\x66\x30\x3C\x1F\x95\xAF\x65\x22\x95" -+ "\x14\x1D\xF5\xD5\xDC\x38\x79\x35\x1C\xCD\x24\x47\xE0\xFD\x08\xC8" -+ "\xF4\x15\x55\x9F\xD9\xC7\xAC\x3F\x67\xB3\x4F\xEB\x26\x7C\x8E\xD6" -+ "\x74\xB3\x0A\xCD\xE7\xFA\xBE\x7E\xA3\x3E\xEC\x61\x50\x77\x52\x56" -+ "\xCF\x90\x5D\x48\xFB\xD4\x2C\x6C\x61\x8B\xDD\x2B\xF5\x92\x1F\x30" -+ "\xBF\x3F\x80\x0D\x31\xDB\xB2\x0B\x7D\x84\xE3\xA6\x42\x7F\x00\x38" -+ "\x44\x02\xC5\xB8\xD9\x58\x29\x9D\x68\x5C\x32\x8B\x76\xAE\xED\x15" -+ "\xF9\x7C\xAE\x7B\xB6\x8E\xD6\x54\x24\xFF\xFA\x87\x05\xEF\x15\x08" -+ "\x5E\x4B\x21\xA2\x2F\x49\xE7\x0F\xC3\xD0\xB9\x49\x22\xEF\xD5\xCA" -+ "\xB2\x11\xF2\x17\xB6\x77\x24\x68\x76\xB2\x07\xF8\x0A\x73\xDD\x65" -+ "\x9C\x75\x64\xF7\xA1\xC6\x23\x08\x84\x72\x3E\x54\x2E\xEB\x9B\x40" -+ "\xA6\x83\x87\xEB\xB5\x00\x40\x4F\xE1\x72\x2A\x59\x3A\x06\x60\x29" -+ "\x7E\x25\x2F\xD8\x80\x40\x8C\x59\xCA\xCF\x8E\x44\xE4\x2D\x84\x7E" -+ "\xCB\xFD\x1E\x3B\xD5\xFF\x9A\xB9\x66\x93\x6D\x5E\xC8\xB7\x13\x26" -+ "\xD6\x38\x1B\x2B\xE1\x87\x96\x05\xD5\xF3\xAB\x68\xF7\x12\x62\x2C" -+ "\x58\xC1\xC9\x85\x3C\x72\xF1\x26\xEE\xC0\x09\x5F\x1D\x4B\xAC\x01" -+ "\x41\xC8\x12\xF8\xF3\x93\x43\x41\xFF\xEC\x0B\x80\xE2\xEE\x20\x85" -+ "\x25\xCD\x6C\x30\x8C\x0D\x24\x2E\xBA\x19\xEA\x28\x7F\xCF\xD5\x10" -+ "\x5C\xE9\xB2\x9D\x5F\x16\xE4\xC0\xF3\xCC\xD9\x68\x4A\x05\x08\x70" -+ "\x17\x26\xC8\x5C\x4A\xBF\x94\x6A\x0E\xD5\xDA\x67\x47\x4B\xAF\x44" -+ "\xE3\x94\xAA\x05\xDB\xA2\x49\x74\xFA\x5C\x69\xAB\x44\xB7\xF7\xBA" -+ "\xAE\x7A\x23\x87\xEB\x54\x7E\x80\xF1\x5B\x60\xA5\x93\xE5\xD4\x24" -+ "\x84\xF7\x0A\x16\x10\xBE\xE9\x4D\xD8\x6B\x15\x40\x5D\x74\xDA\x1B" -+ "\xFF\x2E\x4D\x17\x9D\x35\xF7\x0D\xCF\x66\x38\x0D\x8A\xE4\xDD\x6B" -+ "\xE1\x0F\x1F\xBD\xFD\x4F\x30\x37\x3F\x96\xB4\x92\x54\xD3\x9A\x7A" -+ "\xD1\x5B\x5B\xA9\x54\x16\xE6\x24\xAB\xD4\x23\x39\x7D\xD2\xC7\x09" -+ "\xFA\xD4\x86\x55\x4D\x60\xC2\x87\x67\x6B\xE6" - }; - - static void -@@ -686,7 +710,7 @@ test_pac_ticket_signature(krb5_context context) - { - krb5_error_code ret; - krb5_ticket *ticket; -- krb5_principal sprinc; -+ krb5_principal cprinc, sprinc; - krb5_authdata **authdata1, **authdata2; - krb5_pac pac, pac2, pac3; - uint32_t *list; -@@ -701,7 +725,13 @@ test_pac_ticket_signature(krb5_context context) - if (ret) - err(context, ret, "while decrypting ticket"); - -- ret = krb5_parse_name(context, "s1@CDOM.COM", &sprinc); -+ ret = krb5_parse_name(context, "administrator@W2022-L7.BASE", &cprinc); -+ if (ret) -+ err(context, ret, "krb5_parse_name"); -+ -+ ret = krb5_parse_name(context, -+ "cifs/w2022-118.w2022-l7.base@W2022-L7.BASE", -+ &sprinc); - if (ret) - err(context, ret, "krb5_parse_name"); - -@@ -713,7 +743,7 @@ test_pac_ticket_signature(krb5_context context) - - /* In this test, the server is also the client. */ - ret = krb5_pac_verify(context, pac, ticket->enc_part2->times.authtime, -- ticket->server, NULL, NULL); -+ cprinc, NULL, NULL); - if (ret) - err(context, ret, "while verifying PAC client info"); - -@@ -722,7 +752,7 @@ test_pac_ticket_signature(krb5_context context) - ticket->enc_part2->authorization_data = NULL; - - ret = krb5_kdc_sign_ticket(context, ticket->enc_part2, pac, sprinc, -- sprinc, &ticket_sig_server_key, -+ cprinc, &ticket_sig_server_key, - &ticket_sig_krbtgt_key, FALSE); - if (ret) - err(context, ret, "while signing ticket"); -@@ -781,6 +811,7 @@ test_pac_ticket_signature(krb5_context context) - krb5_pac_free(context, pac); - krb5_pac_free(context, pac2); - krb5_pac_free(context, pac3); -+ krb5_free_principal(context, cprinc); - krb5_free_principal(context, sprinc); - krb5_free_ticket(context, ticket); - } -diff --git a/src/tests/t_authdata.py b/src/tests/t_authdata.py -index 47ea9e4b47..e934799268 100644 ---- a/src/tests/t_authdata.py -+++ b/src/tests/t_authdata.py -@@ -11,7 +11,7 @@ realm = K5Realm(krb5_conf=conf) - # container. - mark('baseline authdata') - out = realm.run(['./adata', realm.host_princ]) --if '?128: [6, 7, 10, 16]' not in out or '^-42: Hello' not in out: -+if '?128: [6, 7, 10, 16, 19]' not in out or '^-42: Hello' not in out: - fail('expected authdata not seen for basic request') - - # Requested authdata is copied into the ticket, with KDC-only types -@@ -243,7 +243,7 @@ out = realm.run(['./adata', '-p', realm.user_princ, 'service/2']) - if '+97: [indcl]' not in out or '[inds1]' in out: - fail('correct auth-indicator not seen for S4U2Proxy req') - # Make sure a PAC with an S4U_DELEGATION_INFO(11) buffer is included. --if '?128: [1, 6, 7, 10, 11, 16]' not in out: -+if '?128: [1, 6, 7, 10, 11, 16, 19]' not in out: - fail('PAC with delegation info not seen for S4U2Proxy req') - - # Get another S4U2Proxy ticket including request-authdata. --- -2.39.1 - diff --git a/krb5-tests b/krb5-tests index cbbb302..beaeb2b 100644 --- a/krb5-tests +++ b/krb5-tests @@ -5,10 +5,13 @@ export RPM_PACKAGE_NAME={{ name }} export RPM_PACKAGE_VERSION={{ version }} export RPM_PACKAGE_RELEASE={{ release }} export RPM_ARCH={{ arch }} +export RPM_BUILD_NCPUS="$(getconf _NPROCESSORS_ONLN)" testdir="$(mktemp -d)" trap "rm -rf ${testdir}" EXIT +build_flags="$(eval "echo $(rpm --eval '%{_smp_mflags}')")" + cp -rp /usr/share/{{ name }}-tests "${testdir}/" -make -C "${testdir}/{{ name }}-tests" $(rpm --eval '%{_smp_mflags}') +make -C "${testdir}/{{ name }}-tests" $build_flags keyctl session - make -C "${testdir}/{{ name }}-tests" check diff --git a/krb5.spec b/krb5.spec index 7800eea..a16e111 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 9 +%global baserelease 1 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -22,9 +22,9 @@ %endif %global krb5_version_major 1 -%global krb5_version_minor 20 +%global krb5_version_minor 21 # For a release without a patch number set to %%nil -%global krb5_version_patch 1 +%global krb5_version_patch %nil %global krb5_version_major_minor %{krb5_version_major}.%{krb5_version_minor} %global krb5_version %{krb5_version_major_minor} @@ -59,23 +59,19 @@ Source13: kadmind.logrotate Source14: krb5-krb5kdc.conf Source15: %{name}-tests -Patch1: 0001-downstream-ksu-pam-integration.patch -Patch2: 0002-downstream-SELinux-integration.patch -Patch3: 0003-downstream-fix-debuginfo-with-y.tab.c.patch -Patch4: 0004-downstream-Remove-3des-support.patch -Patch5: 0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch -Patch6: 0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch -Patch7: 0007-Add-configure-variable-for-default-PKCS-11-module.patch -Patch8: 0008-Set-reasonable-supportedCMSTypes-in-PKINIT.patch -Patch9: 0009-Simplify-plugin-loading-code.patch -Patch10: 0010-Update-error-checking-for-OpenSSL-CMS_verify.patch -Patch11: 0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch -Patch12: 0012-Add-and-use-ts_interval-helper.patch -Patch13: 0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch -Patch14: 0014-downstream-Include-missing-OpenSSL-FIPS-header.patch -Patch15: 0015-downstream-Do-not-set-root-as-ksu-file-owner.patch -Patch16: 0016-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch -Patch17: 0017-Add-PAC-full-checksums.patch +Patch0001: 0001-downstream-ksu-pam-integration.patch +Patch0002: 0002-downstream-SELinux-integration.patch +Patch0003: 0003-downstream-fix-debuginfo-with-y.tab.c.patch +Patch0004: 0004-downstream-Remove-3des-support.patch +Patch0005: 0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +Patch0006: 0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch +Patch0007: 0007-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch +Patch0008: 0008-downstream-Include-missing-OpenSSL-FIPS-header.patch +Patch0009: 0009-downstream-Do-not-set-root-as-ksu-file-owner.patch +Patch0010: 0010-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch +Patch0011: 0011-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch +Patch0012: 0012-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch +Patch0013: 0013-Enable-PKINIT-if-at-least-one-group-is-available.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -712,9 +708,22 @@ exit 0 %{_datarootdir}/%{name}-tests/ %changelog +* Mon Jun 12 2023 Julien Rische - 1.21-1 +- New upstream version (1.21) +- Do not disable PKINIT if some of the well-known DH groups are unavailable + Resolves: rhbz#2214297 +- Make PKINIT CMS SHA-1 signature verification available in FIPS mode + Resolves: rhbz#2214300 +- Allow to set PAC ticket signature as optional + Resolves: rhbz#2181311 +- Add support for MS-PAC extended KDC signature (CVE-2022-37967) + Resolves: rhbz#2166001 +- Fix syntax error in aclocal.m4 + Resolves: rhbz#2143306 + * Tue Jan 31 2023 Julien Rische - 1.20.1-9 - Add support for MS-PAC extended KDC signature (CVE-2022-37967) -- Resolves: rhbz#2166001 + Resolves: rhbz#2166001 * Mon Jan 30 2023 Julien Rische - 1.20.1-8 - Bypass FIPS restrictions to use KRB5KDF in case AES SHA-1 HMAC is enabled @@ -726,7 +735,7 @@ exit 0 * Wed Jan 18 2023 Julien Rische - 1.20.1-6 - Set aes256-cts-hmac-sha384-192 as EXAMLE.COM master key in kdc.conf - Add AES SHA-2 HMAC family as EXAMPLE.COM supported etypes in kdc.conf -- Resolves: rhbz#2114771 + Resolves: rhbz#2114771 * Mon Jan 09 2023 Julien Rische - 1.20.1-5 - Strip debugging data from ksu executable file @@ -743,18 +752,18 @@ exit 0 * Wed Nov 23 2022 Julien Rische - 1.20.1-1 - New upstream version (1.20.1) -- Resolves: rhbz#2124463 + Resolves: rhbz#2124463 - Restore "supportedCMSTypes" attribute in PKINIT preauth requests - Set SHA-512 or SHA-256 with RSA as preferred CMS signature algorithms -- Resolves: rhbz#2114766 + Resolves: rhbz#2114766 - Update error checking for OpenSSL CMS_verify -- Resolves: rhbz#2119704 + Resolves: rhbz#2119704 - Remove invalid password expiry warning -- Resolves: rhbz#2129113 + Resolves: rhbz#2129113 * Wed Nov 09 2022 Julien Rische - 1.19.2-13 - Fix integer overflows in PAC parsing (CVE-2022-42898) -- Resolves: rhbz#2143011 + Resolves: rhbz#2143011 * Tue Aug 02 2022 Andreas Schneider - 1.19.2-12 - Use baserelease to set the release number @@ -766,14 +775,14 @@ exit 0 * Wed Jun 15 2022 Julien Rische - 1.19.2-11 - Allow libkrad UDP/TCP connection to localhost in FIPS mode -- Resolves: rhbz#2082189 + Resolves: rhbz#2082189 - Read GSS configuration files with mtime 0 * Mon May 2 2022 Julien Rische - 1.19.2-10 - Use p11-kit as default PKCS11 module -- Resolves: rhbz#2073274 + Resolves: rhbz#2073274 - Try harder to avoid password change replay errors -- Resolves: rhbz#2072059 + Resolves: rhbz#2072059 * Tue Apr 05 2022 Alexander Bokovoy - 1.19.2-9 - Fix libkrad client cleanup @@ -791,7 +800,7 @@ exit 0 * Wed Feb 02 2022 Alexander Bokovoy - 1.19.2-5 - Temporarily remove package note to unblock krb5-dependent packages -- Resolves: rhbz#2048909 + Resolves: rhbz#2048909 * Thu Jan 20 2022 Fedora Release Engineering - 1.19.2-4.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild @@ -909,7 +918,7 @@ exit 0 * Tue Nov 17 2020 Robbie Harwood - 1.18.2-30 - Migrate /var/run to /run, an exercise in pointlessness -- Resolves: #1898410 + Resolves: rhbz#1898410 * Thu Nov 05 2020 Robbie Harwood - 1.18.2-29 - Add recursion limit for ASN.1 indefinite lengths (CVE-2020-28196) @@ -931,14 +940,14 @@ exit 0 * Thu Sep 10 2020 Robbie Harwood - 1.18.2-23 - Use `systemctl reload` to HUP the KDC during logrotate -- Resolves: #1877692 + Resolves: rhbz#1877692 * Wed Sep 09 2020 Robbie Harwood - 1.18.2-22 - Fix input length checking in SPNEGO DER decoding * Fri Aug 28 2020 Robbie Harwood - 1.18.2-21 - Mark crypto-polices snippet as missingok -- Resolves: #1868379 + Resolves: rhbz#1868379 * Thu Aug 13 2020 Robbie Harwood - 1.18.2-20 - Temporarily dns_canonicalize_hostname=fallback changes @@ -955,7 +964,7 @@ exit 0 * Mon Aug 03 2020 Robbie Harwood - 1.18.2-16 - Disable tests on s390x -- Resolves: #1863952 + Resolves: rhbz#1863952 * Sat Aug 01 2020 Fedora Release Engineering - 1.18.2-15 - Second attempt - Rebuilt for @@ -976,7 +985,7 @@ exit 0 * Wed Jul 08 2020 Robbie Harwood - 1.18.2-10 - Set qualify_shortname empty in default configuration -- Resolves: #1852041 + Resolves: rhbz#1852041 * Mon Jun 15 2020 Robbie Harwood - 1.18.2-9 - Use two queues for concurrent t_otp.py daemons @@ -1150,7 +1159,7 @@ exit 0 * Mon Jul 15 2019 Robbie Harwood - 1.17-35 - Don't error on invalid enctypes in keytab -- Resolves: #1724380 + Resolves: rhbz#1724380 * Tue Jul 02 2019 Robbie Harwood - 1.17-34 - Remove now-unused checksum functions @@ -1235,7 +1244,7 @@ exit 0 * Thu Apr 11 2019 Robbie Harwood - 1.17-8 - Implement krb5_cc_remove_cred for remaining types -- Resolves: #1693836 + Resolves: rhbz#1693836 * Mon Apr 01 2019 Robbie Harwood - 1.17-7 - FIPS-aware SPAKE group negotiation @@ -1270,7 +1279,7 @@ exit 0 * Mon Dec 17 2018 Robbie Harwood - 1.17-1.beta2.2 - Restore pdfs source file -- Resolves: #1659716 + Resolves: rhbz#1659716 * Thu Dec 06 2018 Robbie Harwood - 1.17-1.beta2.1 - New upstream release (1.17-beta2) @@ -1284,26 +1293,26 @@ exit 0 * Thu Nov 08 2018 Robbie Harwood - 1.17-1.beta1.1 - Fix spurious errors from kcmio_unix_socket_write -- Resolves: #1645912 + Resolves: rhbz#1645912 * Thu Nov 01 2018 Robbie Harwood - 1.17-0.beta1.1 - New upstream beta release * Wed Oct 24 2018 Robbie Harwood - 1.16.1-25 - Update man pages to reference kerberos(7) -- Resolves: #1143767 + Resolves: rhbz#1143767 * Wed Oct 17 2018 Robbie Harwood - 1.16.1-24 - Use port-sockets.h macros in cc_kcm, sendto_kdc -- Resolves: #1631998 + Resolves: rhbz#1631998 * Wed Oct 17 2018 Robbie Harwood - 1.16.1-23 - Correct kpasswd_server description in krb5.conf(5) -- Resolves: #1640272 + Resolves: rhbz#1640272 * Mon Oct 15 2018 Robbie Harwood - 1.16.1-22 - Prefer TCP to UDP for password changes -- Resolves: #1637611 + Resolves: rhbz#1637611 * Tue Oct 09 2018 Adam Williamson - 1.16.1-21 - Revert the patch from -20 for now as it seems to make FreeIPA worse @@ -1352,18 +1361,18 @@ exit 0 * Thu Jun 14 2018 Robbie Harwood - 1.16.1-6 - Switch to python3-sphinx for docs -- Resolves: #1590928 + Resolves: rhbz#1590928 * Thu Jun 14 2018 Robbie Harwood - 1.16.1-5 - Make docs build python3-compatible -- Resolves: #1590928 + Resolves: rhbz#1590928 * Thu Jun 07 2018 Robbie Harwood - 1.16.1-4 - Update includedir processing to match upstream * Fri Jun 01 2018 Robbie Harwood - 1.16.1-3 - Log when non-root ksu authorization fails -- Resolves: #1575771 + Resolves: rhbz#1575771 * Fri May 04 2018 Robbie Harwood - 1.16.1-2 - Remove "-nodes" option from make-certs scripts @@ -1385,7 +1394,7 @@ exit 0 * Mon Apr 23 2018 Robbie Harwood - 1.16-23 - Explicitly use openssl rather than builtin crypto -- Resolves: #1570910 + Resolves: rhbz#1570910 * Tue Apr 17 2018 Robbie Harwood - 1.16-22 - Merge duplicate subsections in profile library @@ -1435,7 +1444,7 @@ exit 0 * Wed Mar 07 2018 Robbie Harwood - 1.16-8 - Fix capaths "." values on client -- Resolves: 1551099 + Resolves: 1551099 * Tue Feb 13 2018 Robbie Harwood - 1.16-7 - Fix flaws in LDAP DN checking @@ -1444,7 +1453,7 @@ exit 0 * Mon Feb 12 2018 Robbie Harwood - 1.16-6 - Fix a leak in the previous commit - Restore dist macro that was accidentally removed -- Resolves: #1540939 + Resolves: rhbz#1540939 * Wed Feb 07 2018 Fedora Release Engineering - 1.16-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild @@ -1457,7 +1466,7 @@ exit 0 * Tue Dec 12 2017 Robbie Harwood - 1.16-2 - Fix network service dependencies -- Resolves: #1525230 + Resolves: rhbz#1525230 * Wed Dec 06 2017 Robbie Harwood - 1.16-1 - New upstream release (1.16) @@ -1487,12 +1496,12 @@ exit 0 * Wed Sep 06 2017 Robbie Harwood - 1.15.1-28 - Save other programs from worrying about CVE-2017-11462 -- Resolves: #1488873 -- Resolves: #1488874 + Resolves: rhbz#1488873 + Resolves: rhbz#1488874 * Tue Sep 05 2017 Robbie Harwood - 1.15.1-27 - Add hostname-based ccselect module -- Resolves: #1463665 + Resolves: rhbz#1463665 * Tue Sep 05 2017 Robbie Harwood - 1.15.1-26 - Backport upstream certauth EKU fixes @@ -1543,7 +1552,7 @@ exit 0 * Fri Jun 23 2017 Robbie Harwood - 1.15.1-11 - Include more test suite changes from upstream -- Resolves: #1464381 + Resolves: rhbz#1464381 * Wed Jun 07 2017 Robbie Harwood - 1.15.1-10 - Fix custom build with -DDEBUG @@ -1559,12 +1568,12 @@ exit 0 * Thu Apr 13 2017 Robbie Harwood - 1.15.1-6 - Include fixes for previous commit -- Resolves: #1433083 + Resolves: rhbz#1433083 * Thu Apr 13 2017 Robbie Harwood - 1.15.1-5 - Automatically add includedir where not present - Try removing sleep statement to see if it is still needed -- Resolves: #1433083 + Resolves: rhbz#1433083 * Fri Apr 07 2017 Robbie Harwood - 1.15.1-4 - Fix use of enterprise principals with forwarding @@ -1574,7 +1583,7 @@ exit 0 * Tue Mar 07 2017 Robbie Harwood - 1.15.1-2 - Remove duplication between subpackages -- Resolves: #1250228 + Resolves: rhbz#1250228 * Fri Mar 03 2017 Robbie Harwood - 1.15.1-1 - New upstream release - 1.15.1 @@ -1608,14 +1617,14 @@ exit 0 * Thu Oct 20 2016 Robbie Harwood - 1.15-beta1-1 - New upstream release - Update selinux with RHEL hygene -- Resolves: #1314096 + Resolves: rhbz#1314096 * Tue Oct 11 2016 Tomáš Mráz - 1.14.4-6 - rebuild with OpenSSL 1.1.0, added backported upstream patch * Fri Sep 30 2016 Robbie Harwood - 1.14.4-5 - Properly close krad sockets -- Resolves: #1380836 + Resolves: rhbz#1380836 * Fri Sep 30 2016 Robbie Harwood - 1.14.4-4 - Fix backward check in kprop.service @@ -1634,42 +1643,42 @@ exit 0 * Mon Sep 19 2016 Robbie Harwood - 1.14.3-9 - Add krb5_db_register_keytab -- Resolves: #1376812 + Resolves: rhbz#1376812 * Mon Aug 29 2016 Robbie Harwood - 1.14.3-8 - Use responder for non-preauth AS requests -- Resolves: #1370622 + Resolves: rhbz#1370622 * Mon Aug 29 2016 Robbie Harwood - 1.14.3-7 - Guess Samba client mutual flag using ap_option -- Resolves: #1370980 + Resolves: rhbz#1370980 * Thu Aug 25 2016 Robbie Harwood - 1.14.3-6 - Fix KDC return code and set prompt types for OTP client preauth -- Resolves: #1370072 + Resolves: rhbz#1370072 * Mon Aug 15 2016 Robbie Harwood - 1.14.3-5 - Turn OFD locks back on with glibc workaround -- Resolves: #1274922 + Resolves: rhbz#1274922 * Wed Aug 10 2016 Robbie Harwood - 1.14.3-4 - Fix use of KKDCPP with SNI -- Resolves: #1365027 + Resolves: rhbz#1365027 * Fri Aug 05 2016 Robbie Harwood - 1.14.3-3 - Make krb5-devel depend on libkadm5 -- Resolves: #1364487 + Resolves: rhbz#1364487 * Wed Aug 03 2016 Robbie Harwood - 1.14.3-2 - Up-port a bunch of stuff from the el-7.3 cycle -- Resolves: #1255450, #1314989 + Resolves: rhbz#1255450, rhbz#1314989 * Mon Aug 01 2016 Robbie Harwood - 1.14.3-1 - New upstream version 1.14.3 * Thu Jul 28 2016 Robbie Harwood - 1.14.1-9 - Fix CVE-2016-3120 -- Resolves: #1361051 + Resolves: rhbz#1361051 * Wed Jun 22 2016 Robbie Harwood - 1.14.1-8 - Fix incorrect recv() size calculation in libkrad @@ -1682,18 +1691,18 @@ exit 0 * Tue Apr 05 2016 Robbie Harwood - 1.14.1-5 - Use the correct patches this time. -- Resolves: #1321135 + Resolves: rhbz#1321135 * Mon Apr 04 2016 Robbie Harwood - 1.14.1-4 - Add send/receive sendto_kdc hooks and corresponding tests -- Resolves: #1321135 + Resolves: rhbz#1321135 * Fri Mar 18 2016 Robbie Harwood - 1.14.1-3 - Fix CVE-2016-3119 (NULL deref in LDAP module) * Thu Mar 17 2016 Robbie Harwood - 1.14.1-2 - Backport OID mech fix -- Resolves: #1317609 + Resolves: rhbz#1317609 * Mon Feb 29 2016 Robbie Harwood - 1.14.1-1 - New rawhide, new upstream version @@ -1703,7 +1712,7 @@ exit 0 * Mon Feb 22 2016 Robbie Harwood - 1.14-23 - Fix log file permissions patch with our selinux -- Resolves: #1309421 + Resolves: rhbz#1309421 * Fri Feb 19 2016 Robbie Harwood - 1.14-22 - Backport my interposer fixes from upstream @@ -1712,7 +1721,7 @@ exit 0 * Tue Feb 16 2016 Robbie Harwood - 1.14-21 - Adjust dependency on crypto-polices to be just the file we want - Patch courtesy of lslebodn -- Resolves: #1308984 + Resolves: rhbz#1308984 * Thu Feb 04 2016 Fedora Release Engineering - 1.14-20 - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild @@ -1720,21 +1729,21 @@ exit 0 * Thu Jan 28 2016 Robbie Harwood - 1.14-19 - Replace _kadmin/_kprop with systemd macros - Remove traces of upstart from fedora package per policy -- Resolves: #1290185 + Resolves: rhbz#1290185 * Wed Jan 27 2016 Robbie Harwood - 1.14-18 - Fix CVE-2015-8629, CVE-2015-8630, CVE-2015-8631 * Thu Jan 21 2016 Robbie Harwood - 1.14-17 - Make krb5kdc.log not world-readable by default -- Resolves: #1276484 + Resolves: rhbz#1276484 * Thu Jan 21 2016 Robbie Harwood - 1.14-16 - Allow verification of attributes on krb5.conf * Wed Jan 20 2016 Robbie Harwood - 1.14-15 - Use "new" systemd macros for service handling. (Thanks vpavlin!) -- Resolves: #850399 + Resolves: rhbz#850399 * Wed Jan 20 2016 Robbie Harwood - 1.14-14 - Remove WITH_NSS macro (always false) @@ -1744,7 +1753,7 @@ exit 0 * Fri Jan 08 2016 Robbie Harwood - 1.14-13 - Backport fix for chrome crash in spnego_gss_inquire_context -- Resolves: #1295893 + Resolves: rhbz#1295893 * Wed Dec 16 2015 Robbie Harwood - 1.14-12 - Backport patch to fix mechglue for gss_inqure_attrs_for_mech() diff --git a/sources b/sources index 9bc9770..d6c0df1 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.20.1.tar.gz) = 6f57479f13f107cd84f30de5c758eb6b9fc59171329c13e5da6073b806755f8d163eb7bd84767ea861ad6458ea0c9eeb00ee044d3bcad01ef136e9888564b6a2 -SHA512 (krb5-1.20.1.tar.gz.asc) = 1d3312bd67581e07adfdadf2c5fe394179631d8add8bd075efefe982a0de22369004e60a14422d426382c8c591e4181b9897088afe9d4e86f0b5a97e5954c67a +SHA512 (krb5-1.21.tar.gz) = 8ee2366888f6d553a44fc642a89c69a57dbc1ec4c89a36b9ba8b00584a9a32c73a2b0566ba5f21852ad9617046666c276dac402393bf8eb19fbe0c07a838071a +SHA512 (krb5-1.21.tar.gz.asc) = 7147a44a13f4f26c5c1d9aba738b32892b50e351ad149dcaf0b6f2c010e3c51d7d51540d0a51b085450ffa31d5027b5f2e5841109d7af8bdaddbdd3a569582d5 From a2c04215f003875c12fa2bd2caeba7c46dd0d04c Mon Sep 17 00:00:00 2001 From: Marek Blaha Date: Thu, 29 Jun 2023 08:12:27 +0200 Subject: [PATCH 285/304] Replace file dependency by package name By default, dnf5 does not download the filelists repository metadata required to resolve file dependencies outside of /usr/(s)bin or /etc. This causes the krb5-server file to become uninstallable. $ dnf5 install krb5-server Repositories loaded. Failed to resolve the transaction: Problem: conflicting requests - nothing provides /usr/share/dict/words needed by krb5-server-1.21-1.fc39.x86_64 This change aligns with the Fedora packaging guidelines, as stated here: https://docs.fedoraproject.org/en-US/packaging-guidelines/#_file_and_directory_dependencies Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2216903 --- krb5.spec | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/krb5.spec b/krb5.spec index a16e111..f67b1a5 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 1 +%global baserelease 2 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -154,8 +154,8 @@ Requires(preun): systemd-units Requires(postun): systemd-units # we drop files in its directory, but we don't want to own that directory Requires: logrotate -# we specify /usr/share/dict/words as the default dict_file in kdc.conf -Requires: /usr/share/dict/words +# we specify /usr/share/dict/words (provided by words) as the default dict_file in kdc.conf +Requires: words # for run-time, and for parts of the test suite BuildRequires: libverto-module-base Requires: libverto-module-base @@ -252,7 +252,7 @@ Requires: python3-kdcproxy Requires: python3-pyrad Requires: resolv_wrapper Requires: /etc/crypto-policies/back-ends/krb5.config -Requires: /usr/share/dict/words +Requires: words #Requires: openldap-servers, openldap-clients %description tests @@ -708,6 +708,10 @@ exit 0 %{_datarootdir}/%{name}-tests/ %changelog +* Thu Jun 29 2023 Marek Blaha - 1.21-2 +- Replace file dependency with package name + Resolves: rhbz#2216903 + * Mon Jun 12 2023 Julien Rische - 1.21-1 - New upstream version (1.21) - Do not disable PKINIT if some of the well-known DH groups are unavailable From ae2cf9bef37cecb11eeb4c1d094a894340b711a7 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 20 Jul 2023 09:33:35 +0000 Subject: [PATCH 286/304] Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index f67b1a5..4932c63 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 2 +%global baserelease 3 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -708,6 +708,9 @@ exit 0 %{_datarootdir}/%{name}-tests/ %changelog +* Thu Jul 20 2023 Fedora Release Engineering - 1.21-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + * Thu Jun 29 2023 Marek Blaha - 1.21-2 - Replace file dependency with package name Resolves: rhbz#2216903 From f5676fd2337e1b89f2147be08ef013f821930702 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 16 Aug 2023 10:54:48 +0200 Subject: [PATCH 287/304] New upstream version (1.21.2) - Fix double-free in KDC TGS processing (CVE-2023-39975) Resolves: rhbz#2229113 - Make tests compatible with Python 3.12 Resolves: rhbz#2224013 Signed-off-by: Julien Rische --- .gitignore | 2 + ...ue-session-keys-with-deprecated-enct.patch | 309 +++++++++ ... 0002-downstream-ksu-pam-integration.patch | 4 +- ... 0003-downstream-SELinux-integration.patch | 6 +- ...ownstream-fix-debuginfo-with-y.tab.c.patch | 4 +- ... 0005-downstream-Remove-3des-support.patch | 91 +-- ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 8 +- ...-krad-UDP-TCP-localhost-connection-w.patch | 4 +- ...tests-compatible-with-sssd_krb5_loca.patch | 4 +- ...-Include-missing-OpenSSL-FIPS-header.patch | 4 +- ...am-Do-not-set-root-as-ksu-file-owner.patch | 4 +- ...low-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch | 4 +- ...-to-set-PAC-ticket-signature-as-opti.patch | 8 +- ...PKINIT-CMS-SHA-1-signature-verificat.patch | 4 +- ...T-if-at-least-one-group-is-available.patch | 4 +- 0015-Replace-ssl.wrap_socket-for-tests.patch | 64 ++ krb5.spec | 601 +++++++++--------- sources | 4 +- 18 files changed, 743 insertions(+), 386 deletions(-) create mode 100644 0001-Revert-Don-t-issue-session-keys-with-deprecated-enct.patch rename 0001-downstream-ksu-pam-integration.patch => 0002-downstream-ksu-pam-integration.patch (99%) rename 0002-downstream-SELinux-integration.patch => 0003-downstream-SELinux-integration.patch (99%) rename 0003-downstream-fix-debuginfo-with-y.tab.c.patch => 0004-downstream-fix-debuginfo-with-y.tab.c.patch (95%) rename 0004-downstream-Remove-3des-support.patch => 0005-downstream-Remove-3des-support.patch (98%) rename 0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch => 0006-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch (99%) rename 0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch => 0007-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch (97%) rename 0007-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch => 0008-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch (94%) rename 0008-downstream-Include-missing-OpenSSL-FIPS-header.patch => 0009-downstream-Include-missing-OpenSSL-FIPS-header.patch (98%) rename 0009-downstream-Do-not-set-root-as-ksu-file-owner.patch => 0010-downstream-Do-not-set-root-as-ksu-file-owner.patch (93%) rename 0010-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch => 0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch (98%) rename 0011-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch => 0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch (98%) rename 0012-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch => 0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch (96%) rename 0013-Enable-PKINIT-if-at-least-one-group-is-available.patch => 0014-Enable-PKINIT-if-at-least-one-group-is-available.patch (99%) create mode 100644 0015-Replace-ssl.wrap_socket-for-tests.patch diff --git a/.gitignore b/.gitignore index 7db6eaa..7057bf9 100644 --- a/.gitignore +++ b/.gitignore @@ -204,3 +204,5 @@ /krb5-1.20.1.tar.gz.asc /krb5-1.21.tar.gz /krb5-1.21.tar.gz.asc +/krb5-1.21.2.tar.gz +/krb5-1.21.2.tar.gz.asc diff --git a/0001-Revert-Don-t-issue-session-keys-with-deprecated-enct.patch b/0001-Revert-Don-t-issue-session-keys-with-deprecated-enct.patch new file mode 100644 index 0000000..cc457ae --- /dev/null +++ b/0001-Revert-Don-t-issue-session-keys-with-deprecated-enct.patch @@ -0,0 +1,309 @@ +From 087d150e4afe47a8d269d5e80dcef2204b007ceb Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Wed, 16 Aug 2023 10:00:30 +0200 +Subject: [PATCH] Revert "Don't issue session keys with deprecated enctypes" + +This reverts commit 1b57a4d134bbd0e7c52d5885a92eccc815726463. +--- + doc/admin/conf_files/krb5_conf.rst | 12 ------------ + doc/admin/enctypes.rst | 23 +++------------------- + src/include/k5-int.h | 4 ---- + src/kdc/kdc_util.c | 10 ---------- + src/lib/krb5/krb/get_in_tkt.c | 31 +++++++++++------------------- + src/lib/krb5/krb/init_ctx.c | 10 ---------- + src/tests/gssapi/t_enctypes.py | 3 +-- + src/tests/t_etype_info.py | 2 +- + src/tests/t_sesskeynego.py | 28 ++------------------------- + src/util/k5test.py | 4 ++-- + 10 files changed, 20 insertions(+), 107 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index ecdf917501..f22d5db11b 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -95,18 +95,6 @@ Additionally, krb5.conf may include any of the relations described in + + The libdefaults section may contain any of the following relations: + +-**allow_des3** +- Permit the KDC to issue tickets with des3-cbc-sha1 session keys. +- In future releases, this flag will allow des3-cbc-sha1 to be used +- at all. The default value for this tag is false. (Added in +- release 1.21.) +- +-**allow_rc4** +- Permit the KDC to issue tickets with arcfour-hmac session keys. +- In future releases, this flag will allow arcfour-hmac to be used +- at all. The default value for this tag is false. (Added in +- release 1.21.) +- + **allow_weak_crypto** + If this flag is set to false, then weak encryption types (as noted + in :ref:`Encryption_types` in :ref:`kdc.conf(5)`) will be filtered +diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst +index dce19ad43e..694922c0d9 100644 +--- a/doc/admin/enctypes.rst ++++ b/doc/admin/enctypes.rst +@@ -48,15 +48,12 @@ Session key selection + The KDC chooses the session key enctype by taking the intersection of + its **permitted_enctypes** list, the list of long-term keys for the + most recent kvno of the service, and the client's requested list of +-enctypes. Starting in krb5-1.21, all services are assumed to support +-aes256-cts-hmac-sha1-96; also, des3-cbc-sha1 and arcfour-hmac session +-keys will not be issued by default. ++enctypes. + + Starting in krb5-1.11, it is possible to set a string attribute on a + service principal to control what session key enctypes the KDC may +-issue for service tickets for that principal, overriding the service's +-long-term keys and the assumption of aes256-cts-hmac-sha1-96 support. +-See :ref:`set_string` in :ref:`kadmin(1)` for details. ++issue for service tickets for that principal. See :ref:`set_string` ++in :ref:`kadmin(1)` for details. + + + Choosing enctypes for a service +@@ -90,20 +87,6 @@ affect how enctypes are chosen. + acceptable risk for your environment and the weak enctypes are + required for backward compatibility. + +-**allow_des3** +- was added in release 1.21 and defaults to *false*. Unless this +- flag is set to *true*, the KDC will not issue tickets with +- des3-cbc-sha1 session keys. In a future release, this flag will +- control whether des3-cbc-sha1 is permitted in similar fashion to +- weak enctypes. +- +-**allow_rc4** +- was added in release 1.21 and defaults to *false*. Unless this +- flag is set to *true*, the KDC will not issue tickets with +- arcfour-hmac session keys. In a future release, this flag will +- control whether arcfour-hmac is permitted in similar fashion to +- weak enctypes. +- + **permitted_enctypes** + controls the set of enctypes that a service will permit for + session keys and for ticket and authenticator encryption. The KDC +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 2f7791b775..1d1c8293f4 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -180,8 +180,6 @@ typedef unsigned char u_char; + * matches the variable name. Keep these alphabetized. */ + #define KRB5_CONF_ACL_FILE "acl_file" + #define KRB5_CONF_ADMIN_SERVER "admin_server" +-#define KRB5_CONF_ALLOW_DES3 "allow_des3" +-#define KRB5_CONF_ALLOW_RC4 "allow_rc4" + #define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto" + #define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local" + #define KRB5_CONF_AUTH_TO_LOCAL_NAMES "auth_to_local_names" +@@ -1240,8 +1238,6 @@ struct _krb5_context { + struct _kdb_log_context *kdblog_context; + + krb5_boolean allow_weak_crypto; +- krb5_boolean allow_des3; +- krb5_boolean allow_rc4; + krb5_boolean ignore_acceptor_hostname; + krb5_boolean enforce_ok_as_delegate; + enum dns_canonhost dns_canonicalize_hostname; +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index e54cc751f9..75e04b73db 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1088,16 +1088,6 @@ select_session_keytype(krb5_context context, krb5_db_entry *server, + if (!krb5_is_permitted_enctype(context, ktype[i])) + continue; + +- /* +- * Prevent these deprecated enctypes from being used as session keys +- * unless they are explicitly allowed. In the future they will be more +- * comprehensively disabled and eventually removed. +- */ +- if (ktype[i] == ENCTYPE_DES3_CBC_SHA1 && !context->allow_des3) +- continue; +- if (ktype[i] == ENCTYPE_ARCFOUR_HMAC && !context->allow_rc4) +- continue; +- + if (dbentry_supports_enctype(context, server, ktype[i])) + return ktype[i]; + } +diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c +index ea089f0fcc..1b420a3ac2 100644 +--- a/src/lib/krb5/krb/get_in_tkt.c ++++ b/src/lib/krb5/krb/get_in_tkt.c +@@ -1582,31 +1582,22 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, + (*prompter)(context, data, 0, banner, 0, 0); + } + +-/* Display a warning via the prompter if a deprecated enctype was used for +- * either the reply key or the session key. */ ++/* Display a warning via the prompter if des3-cbc-sha1 was used for either the ++ * reply key or the session key. */ + static void +-warn_deprecated(krb5_context context, krb5_init_creds_context ctx, +- krb5_enctype as_key_enctype) ++warn_des3(krb5_context context, krb5_init_creds_context ctx, ++ krb5_enctype as_key_enctype) + { +- krb5_enctype etype; +- char encbuf[128], banner[256]; ++ const char *banner; + +- if (ctx->prompter == NULL) +- return; +- +- if (krb5int_c_deprecated_enctype(as_key_enctype)) +- etype = as_key_enctype; +- else if (krb5int_c_deprecated_enctype(ctx->cred.keyblock.enctype)) +- etype = ctx->cred.keyblock.enctype; +- else ++ if (as_key_enctype != ENCTYPE_DES3_CBC_SHA1 && ++ ctx->cred.keyblock.enctype != ENCTYPE_DES3_CBC_SHA1) + return; +- +- if (krb5_enctype_to_name(etype, FALSE, encbuf, sizeof(encbuf)) != 0) ++ if (ctx->prompter == NULL) + return; +- snprintf(banner, sizeof(banner), +- _("Warning: encryption type %s used for authentication is " +- "deprecated and will be disabled"), encbuf); + ++ banner = _("Warning: encryption type des3-cbc-sha1 used for " ++ "authentication is weak and will be disabled"); + /* PROMPTER_INVOCATION */ + (*ctx->prompter)(context, ctx->prompter_data, NULL, banner, 0, NULL); + } +@@ -1857,7 +1848,7 @@ init_creds_step_reply(krb5_context context, + ctx->complete = TRUE; + warn_pw_expiry(context, ctx->opt, ctx->prompter, ctx->prompter_data, + ctx->in_tkt_service, ctx->reply); +- warn_deprecated(context, ctx, encrypting_key.enctype); ++ warn_des3(context, ctx, encrypting_key.enctype); + + cleanup: + krb5_free_pa_data(context, kdc_padata); +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index a6c2bbeb54..87b486c53f 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -221,16 +221,6 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + goto cleanup; + ctx->allow_weak_crypto = tmp; + +- retval = get_boolean(ctx, KRB5_CONF_ALLOW_DES3, 0, &tmp); +- if (retval) +- goto cleanup; +- ctx->allow_des3 = tmp; +- +- retval = get_boolean(ctx, KRB5_CONF_ALLOW_RC4, 0, &tmp); +- if (retval) +- goto cleanup; +- ctx->allow_rc4 = tmp; +- + retval = get_boolean(ctx, KRB5_CONF_IGNORE_ACCEPTOR_HOSTNAME, 0, &tmp); + if (retval) + goto cleanup; +diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py +index f5f11842e2..7494d7fcdb 100755 +--- a/src/tests/gssapi/t_enctypes.py ++++ b/src/tests/gssapi/t_enctypes.py +@@ -18,8 +18,7 @@ d_rc4 = 'DEPRECATED:arcfour-hmac' + # These tests make assumptions about the default enctype lists, so set + # them explicitly rather than relying on the library defaults. + supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal' +-conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4', +- 'allow_des3': 'true', 'allow_rc4': 'true'}, ++conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4'}, + 'realms': {'$realm': {'supported_enctypes': supp}}} + realm = K5Realm(krb5_conf=conf) + shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save')) +diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py +index 38cf96ca8f..c982508d8b 100644 +--- a/src/tests/t_etype_info.py ++++ b/src/tests/t_etype_info.py +@@ -1,7 +1,7 @@ + from k5test import * + + supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac' +-conf = {'libdefaults': {'allow_des3': 'true', 'allow_rc4': 'true'}, ++conf = {'libdefaults': {'allow_weak_crypto': 'true'}, + 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} + realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) + +diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py +index 5a213617b5..9024aee838 100755 +--- a/src/tests/t_sesskeynego.py ++++ b/src/tests/t_sesskeynego.py +@@ -25,8 +25,6 @@ conf3 = {'libdefaults': { + 'default_tkt_enctypes': 'aes128-cts', + 'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}} + conf4 = {'libdefaults': {'permitted_enctypes': 'aes256-cts'}} +-conf5 = {'libdefaults': {'allow_rc4': 'true'}} +-conf6 = {'libdefaults': {'allow_des3': 'true'}} + # Test with client request and session_enctypes preferring aes128, but + # aes256 long-term key. + realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False) +@@ -56,12 +54,10 @@ realm.run([kadminl, 'setstr', 'server', 'session_enctypes', + 'aes128-cts,aes256-cts']) + test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96') + +-# 3b: Skip RC4 (as the KDC does not allow it for session keys by +-# default) and negotiate aes128-cts session key, with only an aes256 +-# long-term service key. ++# 3b: Negotiate rc4-hmac session key when principal only has aes256 long-term. + realm.run([kadminl, 'setstr', 'server', 'session_enctypes', + 'rc4-hmac,aes128-cts,aes256-cts']) +-test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96') ++test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') + realm.stop() + + # 4: Check that permitted_enctypes is a default for session key enctypes. +@@ -71,24 +67,4 @@ realm.run([kvno, 'user'], + expected_trace=('etypes requested in TGS request: aes256-cts',)) + realm.stop() + +-# 5: allow_rc4 permits negotiation of rc4-hmac session key. +-realm = K5Realm(krb5_conf=conf5, create_host=False, get_creds=False) +-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server']) +-realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'rc4-hmac']) +-test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') +-realm.stop() +- +-# 6: allow_des3 permits negotiation of des3-cbc-sha1 session key. +-realm = K5Realm(krb5_conf=conf6, create_host=False, get_creds=False) +-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server']) +-realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'des3-cbc-sha1']) +-test_kvno(realm, 'DEPRECATED:des3-cbc-sha1', 'aes256-cts-hmac-sha1-96') +-realm.stop() +- +-# 7: default config negotiates aes256-sha1 session key for RC4-only service. +-realm = K5Realm(create_host=False, get_creds=False) +-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'rc4-hmac', 'server']) +-test_kvno(realm, 'aes256-cts-hmac-sha1-96', 'DEPRECATED:arcfour-hmac') +-realm.stop() +- + success('sesskeynego') +diff --git a/src/util/k5test.py b/src/util/k5test.py +index 8e5f5ba8e9..2a86c5cdfc 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -1340,14 +1340,14 @@ _passes = [ + + # Exercise the DES3 enctype. + ('des3', None, +- {'libdefaults': {'permitted_enctypes': 'des3 aes256-sha1'}}, ++ {'libdefaults': {'permitted_enctypes': 'des3'}}, + {'realms': {'$realm': { + 'supported_enctypes': 'des3-cbc-sha1:normal', + 'master_key_type': 'des3-cbc-sha1'}}}), + + # Exercise the arcfour enctype. + ('arcfour', None, +- {'libdefaults': {'permitted_enctypes': 'rc4 aes256-sha1'}}, ++ {'libdefaults': {'permitted_enctypes': 'rc4'}}, + {'realms': {'$realm': { + 'supported_enctypes': 'arcfour-hmac:normal', + 'master_key_type': 'arcfour-hmac'}}}), +-- +2.41.0 + diff --git a/0001-downstream-ksu-pam-integration.patch b/0002-downstream-ksu-pam-integration.patch similarity index 99% rename from 0001-downstream-ksu-pam-integration.patch rename to 0002-downstream-ksu-pam-integration.patch index d33704a..08bfeab 100644 --- a/0001-downstream-ksu-pam-integration.patch +++ b/0002-downstream-ksu-pam-integration.patch @@ -1,4 +1,4 @@ -From 67c82a09c6c53713c281045cd55de2720cd06907 Mon Sep 17 00:00:00 2001 +From 2080ff4c57d29e74466987d673aaf25273160534 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] [downstream] ksu pam integration @@ -773,5 +773,5 @@ index 77be7a2025..587221936e 100644 if test "${localedir+set}" != set; then localedir='$(datadir)/locale' -- -2.40.1 +2.41.0 diff --git a/0002-downstream-SELinux-integration.patch b/0003-downstream-SELinux-integration.patch similarity index 99% rename from 0002-downstream-SELinux-integration.patch rename to 0003-downstream-SELinux-integration.patch index 840c2a3..cac0604 100644 --- a/0002-downstream-SELinux-integration.patch +++ b/0003-downstream-SELinux-integration.patch @@ -1,4 +1,4 @@ -From dfbac76ab7bb7e6e2c3171eefcaa93573e6b630e Mon Sep 17 00:00:00 2001 +From 3efc0e3ce4ccc8a89700f35bef041794982d95ca Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] [downstream] SELinux integration @@ -188,7 +188,7 @@ index 587221936e..69be9030f8 100644 if test "${localedir+set}" != set; then localedir='$(datadir)/locale' diff --git a/src/include/k5-int.h b/src/include/k5-int.h -index 2f7791b775..9c534faa8a 100644 +index 1d1c8293f4..768110e5ef 100644 --- a/src/include/k5-int.h +++ b/src/include/k5-int.h @@ -128,6 +128,7 @@ typedef unsigned char u_char; @@ -1034,5 +1034,5 @@ index 0000000000..807d039da3 + +#endif /* USE_SELINUX */ -- -2.40.1 +2.41.0 diff --git a/0003-downstream-fix-debuginfo-with-y.tab.c.patch b/0004-downstream-fix-debuginfo-with-y.tab.c.patch similarity index 95% rename from 0003-downstream-fix-debuginfo-with-y.tab.c.patch rename to 0004-downstream-fix-debuginfo-with-y.tab.c.patch index 40361ac..9368aa6 100644 --- a/0003-downstream-fix-debuginfo-with-y.tab.c.patch +++ b/0004-downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,4 +1,4 @@ -From a9c463ed5988c860ebb18de212d6c56da1cb1169 Mon Sep 17 00:00:00 2001 +From 28677b932c200eba07576358b4e5df2ae22c8ecd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] [downstream] fix debuginfo with y.tab.c @@ -40,5 +40,5 @@ index 8669c2436c..a22f23c02c 100644 install: $(INSTALL_PROGRAM) $(PROG) ${DESTDIR}$(ADMIN_BINDIR)/$(PROG) -- -2.40.1 +2.41.0 diff --git a/0004-downstream-Remove-3des-support.patch b/0005-downstream-Remove-3des-support.patch similarity index 98% rename from 0004-downstream-Remove-3des-support.patch rename to 0005-downstream-Remove-3des-support.patch index f7b5134..6c8ce3b 100644 --- a/0004-downstream-Remove-3des-support.patch +++ b/0005-downstream-Remove-3des-support.patch @@ -1,4 +1,4 @@ -From 0691db92e13e0d224c2c9dd72c1421d8f7c3c078 Mon Sep 17 00:00:00 2001 +From 6734a067c600ea6ad81d08fcc481609c2bad9fbb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] [downstream] Remove 3des support @@ -8,7 +8,7 @@ des3-hmac-sha1, des3-cbc-sha1-kd). Update all tests and documentation to user other enctypes. Mark the 3DES enctypes UNSUPPORTED and retain their constants. -Last-updated: 1.20-final +Last-updated: 1.21.1-final [antorres@redhat.com: remove diffs for: - src/kdamin/testing/proto/kdc.conf.proto - src/lib/kadm5/unit-test/api.current/chpass-principal-v2.exp @@ -98,19 +98,18 @@ Last-updated: 1.20-final src/plugins/preauth/pkinit/pkinit_crypto.h | 10 +- src/plugins/preauth/pkinit/pkinit_kdf_test.c | 30 -- src/plugins/preauth/spake/t_vectors.c | 25 -- - src/tests/gssapi/t_enctypes.py | 34 +- + src/tests/gssapi/t_enctypes.py | 33 +- src/tests/gssapi/t_invalid.c | 12 - src/tests/gssapi/t_pcontok.c | 16 +- src/tests/gssapi/t_prf.c | 7 - src/tests/t_authdata.py | 2 +- - src/tests/t_etype_info.py | 20 +- + src/tests/t_etype_info.py | 21 +- src/tests/t_keyrollover.py | 8 +- src/tests/t_mkey.py | 35 -- src/tests/t_salt.py | 5 +- - src/tests/t_sesskeynego.py | 8 - src/util/k5test.py | 7 - .../leash/htmlhelp/html/Encryption_Types.htm | 13 - - 90 files changed, 149 insertions(+), 4720 deletions(-) + 89 files changed, 149 insertions(+), 4712 deletions(-) delete mode 100644 src/lib/crypto/builtin/des/ISSUES delete mode 100644 src/lib/crypto/builtin/des/Makefile.in delete mode 100644 src/lib/crypto/builtin/des/d3_aead.c @@ -200,10 +199,10 @@ index 74a0a2acef..846c58ed82 100644 While **aes128-cts** and **aes256-cts** are supported for all Kerberos diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst -index dce19ad43e..2b4ed7da0b 100644 +index 694922c0d9..c4d5499d3b 100644 --- a/doc/admin/enctypes.rst +++ b/doc/admin/enctypes.rst -@@ -146,7 +146,7 @@ enctype weak? krb5 Windows +@@ -129,7 +129,7 @@ enctype weak? krb5 Windows des-cbc-crc weak <1.18 >=2000 des-cbc-md4 weak <1.18 ? des-cbc-md5 weak <1.18 >=2000 @@ -212,7 +211,7 @@ index dce19ad43e..2b4ed7da0b 100644 arcfour-hmac deprecated >=1.3 >=2000 arcfour-hmac-exp weak >=1.3 >=2000 aes128-cts-hmac-sha1-96 >=1.3 >=Vista -@@ -165,9 +165,11 @@ default. +@@ -148,9 +148,11 @@ default. krb5 releases 1.17 and later flag deprecated encryption types (including ``des3-cbc-sha1`` and ``arcfour-hmac``) in KDC logs and kadmin output. krb5 release 1.19 issues a warning during initial @@ -363,10 +362,10 @@ index dd6430ece8..350bcf86f2 100644 #define CKSUMTYPE_HMAC_SHA1_96_AES128 0x000f /**< RFC 3962. Used with ENCTYPE_AES128_CTS_HMAC_SHA1_96 */ diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index e54cc751f9..ea10e23a95 100644 +index 75e04b73db..fe4e48209a 100644 --- a/src/kdc/kdc_util.c +++ b/src/kdc/kdc_util.c -@@ -1164,8 +1164,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) +@@ -1154,8 +1154,6 @@ enctype_name(krb5_enctype ktype, char *buf, size_t buflen) name = "rsaEncryption-EnvOID"; else if (ktype == ENCTYPE_RSA_ES_OAEP_ENV) name = "id-RSAES-OAEP-EnvOID"; @@ -375,7 +374,7 @@ index e54cc751f9..ea10e23a95 100644 else return krb5_enctype_to_name(ktype, FALSE, buf, buflen); -@@ -1657,8 +1655,6 @@ krb5_boolean +@@ -1647,8 +1645,6 @@ krb5_boolean enctype_requires_etype_info_2(krb5_enctype enctype) { switch(enctype) { @@ -5593,7 +5592,7 @@ index 84f1949887..32150f5e34 100644 case ENCTYPE_ARCFOUR_HMAC_EXP: /* RFC 4121 accidentally omits RC4-HMAC-EXP as a "not-newer" enctype, diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c -index a6c2bbeb54..18290b764b 100644 +index 87b486c53f..2b5abcd817 100644 --- a/src/lib/krb5/krb/init_ctx.c +++ b/src/lib/krb5/krb/init_ctx.c @@ -59,7 +59,6 @@ @@ -5604,7 +5603,7 @@ index a6c2bbeb54..18290b764b 100644 ENCTYPE_ARCFOUR_HMAC, ENCTYPE_CAMELLIA128_CTS_CMAC, ENCTYPE_CAMELLIA256_CTS_CMAC, 0 -@@ -460,8 +459,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, +@@ -450,8 +449,6 @@ krb5int_parse_enctype_list(krb5_context context, const char *profkey, /* Set all enctypes in the default list. */ for (i = 0; default_list[i]; i++) mod_list(default_list[i], sel, weak, &list); @@ -5849,10 +5848,10 @@ index 2279202d3a..96b0307d78 100644 /* initial key, w, x, y, T, S, K */ "8846F7EAEE8FB117AD06BDD830B7586C", diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py -index f5f11842e2..1bb8c40b6b 100755 +index 7494d7fcdb..2f95d89967 100755 --- a/src/tests/gssapi/t_enctypes.py +++ b/src/tests/gssapi/t_enctypes.py -@@ -1,25 +1,17 @@ +@@ -1,24 +1,17 @@ from k5test import * -# Define some convenience abbreviations for enctypes we will see in @@ -5876,14 +5875,13 @@ index f5f11842e2..1bb8c40b6b 100755 # These tests make assumptions about the default enctype lists, so set # them explicitly rather than relying on the library defaults. -supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal' --conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4', -- 'allow_des3': 'true', 'allow_rc4': 'true'}, +-conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4'}, +supp='aes256-cts:normal aes128-cts:normal rc4-hmac:normal' -+conf = {'libdefaults': {'permitted_enctypes': 'aes rc4', 'allow_rc4': 'true'}, ++conf = {'libdefaults': {'permitted_enctypes': 'aes rc4'}, 'realms': {'$realm': {'supported_enctypes': supp}}} realm = K5Realm(krb5_conf=conf) shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save')) -@@ -88,19 +80,12 @@ test('both aes128', 'aes128-cts', 'aes128-cts', +@@ -87,19 +80,12 @@ test('both aes128', 'aes128-cts', 'aes128-cts', test_err('acc aes128', None, 'aes128-cts', 'Encryption type aes256-cts-hmac-sha1-96 not permitted') @@ -5904,7 +5902,7 @@ index f5f11842e2..1bb8c40b6b 100755 # subkey. test('upgrade noargs', None, None, tktenc=aes256, tktsession=d_rc4, -@@ -116,13 +101,6 @@ test('upgrade init aes128+rc4', 'aes128-cts rc4', None, +@@ -115,13 +101,6 @@ test('upgrade init aes128+rc4', 'aes128-cts rc4', None, tktenc=aes256, tktsession=d_rc4, proto='cfx', isubkey=rc4, asubkey=aes128) @@ -6008,20 +6006,21 @@ index bde1c36844..8fcd30db51 100644 realm.run(['./forward']) realm.run([kvno, realm.host_princ]) diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py -index 38cf96ca8f..e82ff7ff07 100644 +index c982508d8b..a6f538b66d 100644 --- a/src/tests/t_etype_info.py +++ b/src/tests/t_etype_info.py -@@ -1,7 +1,7 @@ +@@ -1,8 +1,7 @@ from k5test import * -supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac' --conf = {'libdefaults': {'allow_des3': 'true', 'allow_rc4': 'true'}, +-conf = {'libdefaults': {'allow_weak_crypto': 'true'}, +- 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} +supported_enctypes = 'aes128-cts rc4-hmac' -+conf = {'libdefaults': {'allow_rc4': 'true'}, - 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} ++conf = {'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) -@@ -26,9 +26,9 @@ def test_etinfo(princ, enctypes, expected_lines): + realm.run([kadminl, 'addprinc', '-pw', 'pw', '+requires_preauth', +@@ -26,9 +25,9 @@ def test_etinfo(princ, enctypes, expected_lines): # With no newer enctypes in the request, PA-ETYPE-INFO2, # PA-ETYPE-INFO, and PA-PW-SALT appear in the AS-REP, each listing one # key for the most preferred matching enctype. @@ -6034,7 +6033,7 @@ index 38cf96ca8f..e82ff7ff07 100644 'asrep pw_salt KRBTEST.COMuser']) # With a newer enctype in the request (even if it is not the most -@@ -39,9 +39,9 @@ test_etinfo('user', 'rc4 aes256-cts', +@@ -39,9 +38,9 @@ test_etinfo('user', 'rc4 aes256-cts', # In preauth-required errors, PA-PW-SALT does not appear, but the same # etype-info2 values are expected. @@ -6047,7 +6046,7 @@ index 38cf96ca8f..e82ff7ff07 100644 test_etinfo('preauthuser', 'rc4 aes256-cts', ['error etype_info2 rc4-hmac KRBTEST.COMpreauthuser']) -@@ -50,8 +50,8 @@ test_etinfo('preauthuser', 'rc4 aes256-cts', +@@ -50,8 +49,8 @@ test_etinfo('preauthuser', 'rc4 aes256-cts', # (to allow for preauth mechs which don't depend on long-term keys). # An AS-REP cannot be generated without preauth as there is no reply # key. @@ -6159,34 +6158,8 @@ index 65084bbf35..55ca897459 100755 # Test using different salt types in a principal's key list. # Parameters from one key in the list must not leak over to later ones. -diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py -index 5a213617b5..c7dba0ff5b 100755 ---- a/src/tests/t_sesskeynego.py -+++ b/src/tests/t_sesskeynego.py -@@ -26,7 +26,6 @@ conf3 = {'libdefaults': { - 'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}} - conf4 = {'libdefaults': {'permitted_enctypes': 'aes256-cts'}} - conf5 = {'libdefaults': {'allow_rc4': 'true'}} --conf6 = {'libdefaults': {'allow_des3': 'true'}} - # Test with client request and session_enctypes preferring aes128, but - # aes256 long-term key. - realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False) -@@ -78,13 +77,6 @@ realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'rc4-hmac']) - test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') - realm.stop() - --# 6: allow_des3 permits negotiation of des3-cbc-sha1 session key. --realm = K5Realm(krb5_conf=conf6, create_host=False, get_creds=False) --realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server']) --realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'des3-cbc-sha1']) --test_kvno(realm, 'DEPRECATED:des3-cbc-sha1', 'aes256-cts-hmac-sha1-96') --realm.stop() -- - # 7: default config negotiates aes256-sha1 session key for RC4-only service. - realm = K5Realm(create_host=False, get_creds=False) - realm.run([kadminl, 'addprinc', '-randkey', '-e', 'rc4-hmac', 'server']) diff --git a/src/util/k5test.py b/src/util/k5test.py -index 8e5f5ba8e9..b953827018 100644 +index 2a86c5cdfc..d823653aa0 100644 --- a/src/util/k5test.py +++ b/src/util/k5test.py @@ -1338,13 +1338,6 @@ _passes = [ @@ -6195,14 +6168,14 @@ index 8e5f5ba8e9..b953827018 100644 - # Exercise the DES3 enctype. - ('des3', None, -- {'libdefaults': {'permitted_enctypes': 'des3 aes256-sha1'}}, +- {'libdefaults': {'permitted_enctypes': 'des3'}}, - {'realms': {'$realm': { - 'supported_enctypes': 'des3-cbc-sha1:normal', - 'master_key_type': 'des3-cbc-sha1'}}}), - # Exercise the arcfour enctype. ('arcfour', None, - {'libdefaults': {'permitted_enctypes': 'rc4 aes256-sha1'}}, + {'libdefaults': {'permitted_enctypes': 'rc4'}}, diff --git a/src/windows/leash/htmlhelp/html/Encryption_Types.htm b/src/windows/leash/htmlhelp/html/Encryption_Types.htm index 1aebdd0b4a..c38eefd2bd 100644 --- a/src/windows/leash/htmlhelp/html/Encryption_Types.htm @@ -6228,5 +6201,5 @@ index 1aebdd0b4a..c38eefd2bd 100644 The AES Advanced Encryption Standard family, like 3DES, is a symmetric block cipher and was designed -- -2.40.1 +2.41.0 diff --git a/0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/0006-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch similarity index 99% rename from 0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch rename to 0006-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index e575b79..d59a5bf 100644 --- a/0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/0006-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From 53191fd3a1acfeefa8e5c26e7e9d130688daf745 Mon Sep 17 00:00:00 2001 +From dc3fd927ccd5b7b40049145c3fc7c610d72e9502 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 @@ -41,10 +41,10 @@ Last-updated: krb5-1.20 15 files changed, 155 insertions(+), 33 deletions(-) diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst -index ecdf917501..b78a3faf0a 100644 +index f22d5db11b..a33711d918 100644 --- a/doc/admin/conf_files/krb5_conf.rst +++ b/doc/admin/conf_files/krb5_conf.rst -@@ -342,6 +342,12 @@ The libdefaults section may contain any of the following relations: +@@ -330,6 +330,12 @@ The libdefaults section may contain any of the following relations: qualification of shortnames, set this relation to the empty string with ``qualify_shortname = ""``. (New in release 1.18.) @@ -608,5 +608,5 @@ index 1a772d450f..232e78bc05 100644 vt->name = "spake"; vt->pa_type_list = pa_types; -- -2.40.1 +2.41.0 diff --git a/0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch b/0007-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch similarity index 97% rename from 0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch rename to 0007-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch index 68f10a0..2602e7a 100644 --- a/0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch +++ b/0007-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch @@ -1,4 +1,4 @@ -From c19d0bd35cde40172118c67c38a44f164bce1e16 Mon Sep 17 00:00:00 2001 +From 19db7e5b5d13732c2dfd08b35e2ad3f311553d54 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Thu, 5 May 2022 17:15:12 +0200 Subject: [PATCH] [downstream] Allow krad UDP/TCP localhost connection with FIPS @@ -77,5 +77,5 @@ index 929f1cef67..063f17a613 100644 retval = ESOCKTNOSUPPORT; goto error; -- -2.40.1 +2.41.0 diff --git a/0007-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch b/0008-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch similarity index 94% rename from 0007-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch rename to 0008-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch index f1c3ed6..844890e 100644 --- a/0007-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch +++ b/0008-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch @@ -1,4 +1,4 @@ -From 0366e8b5b2f960cb8305fd95839376b6c18aae42 Mon Sep 17 00:00:00 2001 +From 16d3f9a54d4707ae9de18f108a7b61965e83ceaf Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 7 Dec 2022 13:22:42 +0100 Subject: [PATCH] [downstream] Make tests compatible with @@ -37,5 +37,5 @@ index 87bac17929..26bc95a8dc 100644 fail('URI answers do not match') j += 1 -- -2.40.1 +2.41.0 diff --git a/0008-downstream-Include-missing-OpenSSL-FIPS-header.patch b/0009-downstream-Include-missing-OpenSSL-FIPS-header.patch similarity index 98% rename from 0008-downstream-Include-missing-OpenSSL-FIPS-header.patch rename to 0009-downstream-Include-missing-OpenSSL-FIPS-header.patch index 43648a7..ea123f7 100644 --- a/0008-downstream-Include-missing-OpenSSL-FIPS-header.patch +++ b/0009-downstream-Include-missing-OpenSSL-FIPS-header.patch @@ -1,4 +1,4 @@ -From a567b9de563cd8ad262f77cf97a8bc528a884745 Mon Sep 17 00:00:00 2001 +From 511a6260f0dadc3fe5ebe075f8b548eae026a1cc Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Thu, 5 Jan 2023 20:06:47 +0100 Subject: [PATCH] [downstream] Include missing OpenSSL FIPS header @@ -116,5 +116,5 @@ index 232e78bc05..3394f8a58e 100644 * The SPAKE kdcpreauth module uses a secure cookie containing the following * concatenated fields (all integer fields are big-endian): -- -2.40.1 +2.41.0 diff --git a/0009-downstream-Do-not-set-root-as-ksu-file-owner.patch b/0010-downstream-Do-not-set-root-as-ksu-file-owner.patch similarity index 93% rename from 0009-downstream-Do-not-set-root-as-ksu-file-owner.patch rename to 0010-downstream-Do-not-set-root-as-ksu-file-owner.patch index 0dd8834..46e759e 100644 --- a/0009-downstream-Do-not-set-root-as-ksu-file-owner.patch +++ b/0010-downstream-Do-not-set-root-as-ksu-file-owner.patch @@ -1,4 +1,4 @@ -From 6adfd97a3558aae4ace346685266bac9dae8bba9 Mon Sep 17 00:00:00 2001 +From 1b0bb0c3e5575559ea9135af5b9a1e91fe0f79f3 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Mon, 9 Jan 2023 22:39:52 +0100 Subject: [PATCH] [downstream] Do not set root as ksu file owner @@ -27,5 +27,5 @@ index 7eaa2f351c..e9ae71471e 100644 ## ${prefix}. prefix=@prefix@ -- -2.40.1 +2.41.0 diff --git a/0010-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch b/0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch similarity index 98% rename from 0010-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch rename to 0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch index a78d09c..2d34be0 100644 --- a/0010-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch +++ b/0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch @@ -1,4 +1,4 @@ -From 73640dc4899494d010b83b080b3a65bd3e69177c Mon Sep 17 00:00:00 2001 +From 6e239888cdb938ddda2bf49ec03ad2af3923c381 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Thu, 19 Jan 2023 19:22:27 +0100 Subject: [PATCH] [downstream] Allow KRB5KDF, MD5, and MD4 in FIPS mode @@ -161,5 +161,5 @@ index 5a43c3d9eb..8528ddc4a9 100644 ret = KRB5_CRYPTO_INTERNAL; goto done; -- -2.40.1 +2.41.0 diff --git a/0011-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch b/0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch similarity index 98% rename from 0011-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch rename to 0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch index 8109a84..00d2d0b 100644 --- a/0011-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch +++ b/0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch @@ -1,4 +1,4 @@ -From f47c9eb8618006012600a906367295ed53c558d0 Mon Sep 17 00:00:00 2001 +From 640492ecb4ee42edf33c343c08c01a549ed68a52 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 15 Mar 2023 15:56:34 +0100 Subject: [PATCH] [downstream] Allow to set PAC ticket signature as optional @@ -124,7 +124,7 @@ index 350bcf86f2..17e1b52266 100644 krb5_error_code KRB5_CALLCONV krb5_pac_sign(krb5_context context, krb5_pac pac, krb5_timestamp authtime, diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c -index ea10e23a95..c7b6e4090d 100644 +index fe4e48209a..93415ba862 100644 --- a/src/kdc/kdc_util.c +++ b/src/kdc/kdc_util.c @@ -560,16 +560,36 @@ cleanup: @@ -258,7 +258,7 @@ index 4c50e935a2..d4b0455c8c 100644 krb5_kt_client_default krb5_kt_close diff --git a/src/man/kadmin.man b/src/man/kadmin.man -index d028dc2975..2c8d10067f 100644 +index 461207021b..e8d78309cb 100644 --- a/src/man/kadmin.man +++ b/src/man/kadmin.man @@ -724,6 +724,12 @@ encryption type. It may be necessary to set this value to @@ -275,5 +275,5 @@ index d028dc2975..2c8d10067f 100644 .sp This command requires the \fBmodify\fP privilege. -- -2.40.1 +2.41.0 diff --git a/0012-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch b/0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch similarity index 96% rename from 0012-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch rename to 0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch index c40ed12..ba2c6af 100644 --- a/0012-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch +++ b/0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch @@ -1,4 +1,4 @@ -From d1322546dca51100759eac318ce554bd301c50c3 Mon Sep 17 00:00:00 2001 +From 1b2f64d66e01c1abeefdb7cbef7b04035c2128c0 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Tue, 23 May 2023 12:19:54 +0200 Subject: [PATCH] [downstream] Make PKINIT CMS SHA-1 signature verification @@ -43,5 +43,5 @@ index f41328763e..263ef7845e 100644 goto cleanup; } -- -2.40.1 +2.41.0 diff --git a/0013-Enable-PKINIT-if-at-least-one-group-is-available.patch b/0014-Enable-PKINIT-if-at-least-one-group-is-available.patch similarity index 99% rename from 0013-Enable-PKINIT-if-at-least-one-group-is-available.patch rename to 0014-Enable-PKINIT-if-at-least-one-group-is-available.patch index ebfa323..717eb43 100644 --- a/0013-Enable-PKINIT-if-at-least-one-group-is-available.patch +++ b/0014-Enable-PKINIT-if-at-least-one-group-is-available.patch @@ -1,4 +1,4 @@ -From a378b1970d92692baeddf6a8681f47efb13e343d Mon Sep 17 00:00:00 2001 +From d2b061bea524012edde2915aa95fc4cb6a6f3ae9 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 30 May 2023 01:21:48 -0400 Subject: [PATCH] Enable PKINIT if at least one group is available @@ -214,5 +214,5 @@ index 259e95c6c2..5ee39c085c 100644 TRACE(c, "PKINIT OpenSSL error: {str}", msg) -- -2.40.1 +2.41.0 diff --git a/0015-Replace-ssl.wrap_socket-for-tests.patch b/0015-Replace-ssl.wrap_socket-for-tests.patch new file mode 100644 index 0000000..d5eb3f4 --- /dev/null +++ b/0015-Replace-ssl.wrap_socket-for-tests.patch @@ -0,0 +1,64 @@ +From 42e831da09bd196068aeb7fe6bfe380bb46b846c Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Wed, 19 Jul 2023 13:43:17 +0200 +Subject: [PATCH] Replace ssl.wrap_socket() for tests + +The ssl.wrap_socket() function was deprecated in Python 3.7 and is +removed in Python 3.12. The ssl.SSLContext.wrap_socket() method +replaces it. + +Bump the required Python version for tests to 3.4 for +ssl.create_default_context(). + +[ghudson@mit.edu: changed minimum Python version] + +(cherry picked from commit 0ceab6c363e65fb21d3312a663f2b9b569ecc415) +--- + src/configure.ac | 9 ++++----- + src/util/wsgiref-kdcproxy.py | 4 +++- + 2 files changed, 7 insertions(+), 6 deletions(-) + +diff --git a/src/configure.ac b/src/configure.ac +index 2561e917a2..487f393146 100644 +--- a/src/configure.ac ++++ b/src/configure.ac +@@ -1157,10 +1157,9 @@ AC_SUBST(PKINIT) + # for lib/apputils + AC_REPLACE_FUNCS(daemon) + +-# For Python tests. Python version 3.2.4 is required as prior +-# versions do not accept string input to subprocess.Popen.communicate +-# when universal_newlines is set. +-PYTHON_MINVERSION=3.2.4 ++# For Python tests. Python version 3.4 is required for ++# ssl.create_default_context(). ++PYTHON_MINVERSION=3.4 + AC_SUBST(PYTHON_MINVERSION) + AC_CHECK_PROG(PYTHON,python3,python3) + if test x"$PYTHON" = x; then +@@ -1168,7 +1167,7 @@ if test x"$PYTHON" = x; then + fi + HAVE_PYTHON=no + if test x"$PYTHON" != x; then +- wantver="(sys.hexversion >= 0x30204F0)" ++ wantver="(sys.hexversion >= 0x30400F0)" + if "$PYTHON" -c "import sys; sys.exit(not $wantver and 1 or 0)"; then + HAVE_PYTHON=yes + fi +diff --git a/src/util/wsgiref-kdcproxy.py b/src/util/wsgiref-kdcproxy.py +index 58759696b6..d1d10d733c 100755 +--- a/src/util/wsgiref-kdcproxy.py ++++ b/src/util/wsgiref-kdcproxy.py +@@ -14,6 +14,8 @@ else: + pem = '*' + + server = make_server('localhost', port, kdcproxy.Application()) +-server.socket = ssl.wrap_socket(server.socket, certfile=pem, server_side=True) ++sslctx = ssl.create_default_context(purpose=ssl.Purpose.CLIENT_AUTH) ++sslctx.load_cert_chain(certfile=pem) ++server.socket = sslctx.wrap_socket(server.socket, server_side=True) + os.write(sys.stdout.fileno(), b'proxy server ready\n') + server.serve_forever() +-- +2.41.0 + diff --git a/krb5.spec b/krb5.spec index 4932c63..03498cb 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 3 +%global baserelease 1 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -24,7 +24,7 @@ %global krb5_version_major 1 %global krb5_version_minor 21 # For a release without a patch number set to %%nil -%global krb5_version_patch %nil +%global krb5_version_patch 2 %global krb5_version_major_minor %{krb5_version_major}.%{krb5_version_minor} %global krb5_version %{krb5_version_major_minor} @@ -59,19 +59,21 @@ Source13: kadmind.logrotate Source14: krb5-krb5kdc.conf Source15: %{name}-tests -Patch0001: 0001-downstream-ksu-pam-integration.patch -Patch0002: 0002-downstream-SELinux-integration.patch -Patch0003: 0003-downstream-fix-debuginfo-with-y.tab.c.patch -Patch0004: 0004-downstream-Remove-3des-support.patch -Patch0005: 0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch -Patch0006: 0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch -Patch0007: 0007-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch -Patch0008: 0008-downstream-Include-missing-OpenSSL-FIPS-header.patch -Patch0009: 0009-downstream-Do-not-set-root-as-ksu-file-owner.patch -Patch0010: 0010-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch -Patch0011: 0011-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch -Patch0012: 0012-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch -Patch0013: 0013-Enable-PKINIT-if-at-least-one-group-is-available.patch +Patch0001: 0001-Revert-Don-t-issue-session-keys-with-deprecated-enct.patch +Patch0002: 0002-downstream-ksu-pam-integration.patch +Patch0003: 0003-downstream-SELinux-integration.patch +Patch0004: 0004-downstream-fix-debuginfo-with-y.tab.c.patch +Patch0005: 0005-downstream-Remove-3des-support.patch +Patch0006: 0006-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +Patch0007: 0007-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch +Patch0008: 0008-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch +Patch0009: 0009-downstream-Include-missing-OpenSSL-FIPS-header.patch +Patch0010: 0010-downstream-Do-not-set-root-as-ksu-file-owner.patch +Patch0011: 0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch +Patch0012: 0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch +Patch0013: 0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch +Patch0014: 0014-Enable-PKINIT-if-at-least-one-group-is-available.patch +Patch0015: 0015-Replace-ssl.wrap_socket-for-tests.patch License: MIT URL: https://web.mit.edu/kerberos/www/ @@ -708,6 +710,13 @@ exit 0 %{_datarootdir}/%{name}-tests/ %changelog +* Wed Aug 16 2023 Julien Rische - 1.21.2-1 +- New upstream version (1.21.2) +- Fix double-free in KDC TGS processing (CVE-2023-39975) + Resolves: rhbz#2229113 +- Make tests compatible with Python 3.12 + Resolves: rhbz#2224013 + * Thu Jul 20 2023 Fedora Release Engineering - 1.21-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild @@ -937,7 +946,7 @@ exit 0 - Fix build of previous * Wed Oct 21 2020 Robbie Harwood - 1.18.2-26 -- Cross-realm s4u fixes for samba (#1836630) +- Cross-realm s4u fixes for samba (rhbz#1836630) * Thu Oct 15 2020 Robbie Harwood - 1.18.2-25 - Unify kvno option documentation @@ -1551,11 +1560,11 @@ exit 0 * Mon Jun 26 2017 Robbie Harwood - 1.15.1-13 - Fix arch name (ppc64le, not ppc64el) -- Related-to: #1464381 +- Related-to: rhbz#1464381 * Mon Jun 26 2017 Robbie Harwood - 1.15.1-12 - Skip test suite on ppc64el -- Related-to: #1464381 +- Related-to: rhbz#1464381 * Fri Jun 23 2017 Robbie Harwood - 1.15.1-11 - Include more test suite changes from upstream @@ -1766,7 +1775,7 @@ exit 0 - Backport patch to fix mechglue for gss_inqure_attrs_for_mech() * Thu Dec 03 2015 Robbie Harwood - 1.14-11 -- Backport interposer fix (#1284985) +- Backport interposer fix (rhbz#1284985) - Drop workaround pwsize initialization patch (gcc has been fixed) * Tue Nov 24 2015 Robbie Harwood - 1.14-10 @@ -1801,7 +1810,7 @@ exit 0 - New upstream beta version * Thu Oct 08 2015 Robbie Harwood - 1.13.2-13 -- Work around KDC client prinicipal in referrals issue (#1259844) +- Work around KDC client prinicipal in referrals issue (rhbz#1259844) * Thu Oct 01 2015 Robbie Harwood - 1.13.2-12 - Enable building with bad system /etc/krb5.conf @@ -1814,7 +1823,7 @@ exit 0 - Nix /usr/share/krb5.conf.d to reduce complexity * Wed Sep 23 2015 Robbie Harwood - 1.13.2-9 -- Depend on crypto-policies which provides /etc/krb5.conf.d (#1225792) +- Depend on crypto-policies which provides /etc/krb5.conf.d (rhbz#1225792) * Thu Sep 10 2015 Robbie Harwood - 1.13.2-8 - Remove dependency on systemd-sysv which is no longer needed for fedora > 20 @@ -1823,7 +1832,7 @@ exit 0 * Thu Sep 10 2015 Robbie Harwood - 1.13.2-7 - Support config snippets in /etc/krb5.conf.d/ and /usr/share/krb5.conf.d/ - (#1225792, #1146370, #1145808) + (rhbz#1225792, rhbz#1146370, rhbz#1145808) * Thu Jun 25 2015 Roland Mainz - 1.13.2-6 - Use system nss_wrapper and socket_wrapper for testing. @@ -1831,8 +1840,8 @@ exit 0 * Thu Jun 25 2015 Roland Mainz - 1.13.2-5 - Remove Zanata test glue and related workarounds - - Bug #1234292 ("IPA server cannot be run in container due to incorrect /usr/sbin/_kadmind") - - Bug #1234326 ("krb5-server introduces new rpm dependency on ksh") + - rhbz#1234292 ("IPA server cannot be run in container due to incorrect /usr/sbin/_kadmind") + - rhbz#1234326 ("krb5-server introduces new rpm dependency on ksh") * Thu Jun 18 2015 Roland Mainz - 1.13.2-4 - Fix dependicy on binfmt.service @@ -1841,12 +1850,12 @@ exit 0 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Tue Jun 2 2015 Roland Mainz - 1.13.2-2 -- Add patch to fix Redhat Bug #1227542 ("[SELinux] AVC denials may appear +- Add patch to fix Redhat rhbz#1227542 ("[SELinux] AVC denials may appear when kadmind starts"). The issue was caused by an unneeded |htons()| which triggered SELinux AVC denials due to the "random" port usage. * Thu May 21 2015 Roland Mainz - 1.13.2-1 -- Add fix for RedHat Bug #1164304 ("Upstream unit tests loads +- Add fix for RedHat rhbz#1164304 ("Upstream unit tests loads the installed shared libraries instead the ones from the build") * Thu May 14 2015 Roland Mainz - 1.13.2-0 @@ -1857,7 +1866,7 @@ exit 0 - Minor spec cleanup * Mon May 4 2015 Roland Mainz - 1.13.1-4 -- fix for CVE-2015-2694 (#1216133) "requires_preauth bypass +- fix for CVE-2015-2694 (rhbz#1216133) "requires_preauth bypass in PKINIT-enabled KDC". In MIT krb5 1.12 and later, when the KDC is configured with PKINIT support, an unauthenticated remote attacker can @@ -1867,13 +1876,13 @@ exit 0 dictionary attack against the user's password. * Wed Mar 25 2015 Roland Mainz - 1.13.1-3 -- Add temporay workaround for RH bug #1204646 ("krb5-config +- Add temporay workaround for RH rhbz#1204646 ("krb5-config returns wrong -specs path") which modifies krb5-config post build so that development of krb5 dependicies gets unstuck. This MUST be removed before rawhide becomes F23 ... * Thu Mar 19 2015 Roland Mainz - 1.13.1-2 -- fix for CVE-2014-5355 (#1193939) "krb5: unauthenticated +- fix for CVE-2014-5355 (rhbz#1193939) "krb5: unauthenticated denial of service in recvauth_common() and others" * Fri Feb 13 2015 Roland Mainz - 1.13.1-1 @@ -1884,13 +1893,13 @@ exit 0 - Minor spec cleanup * Wed Feb 4 2015 Roland Mainz - 1.13-8 -- fix for CVE-2014-5352 (#1179856) "gss_process_context_token() +- fix for CVE-2014-5352 (rhbz#1179856) "gss_process_context_token() incorrectly frees context (MITKRB5-SA-2015-001)" -- fix for CVE-2014-9421 (#1179857) "kadmind doubly frees partial +- fix for CVE-2014-9421 (rhbz#1179857) "kadmind doubly frees partial deserialization results (MITKRB5-SA-2015-001)" -- fix for CVE-2014-9422 (#1179861) "kadmind incorrectly +- fix for CVE-2014-9422 (rhbz#1179861) "kadmind incorrectly validates server principal name (MITKRB5-SA-2015-001)" -- fix for CVE-2014-9423 (#1179863) "libgssrpc server applications +- fix for CVE-2014-9423 (rhbz#1179863) "libgssrpc server applications leak uninitialized bytes (MITKRB5-SA-2015-001)" * Wed Feb 4 2015 Roland Mainz - 1.13-7 @@ -1902,17 +1911,17 @@ exit 0 - Support KDC_ERR_MORE_PREAUTH_DATA_REQUIRED (RT#8063) * Mon Jan 26 2015 Roland Mainz - 1.13-5 -- fix for kinit -C loops (#1184629, MIT/krb5 issue 243, "Do not +- fix for kinit -C loops (rhbz#1184629, MIT/krb5 issue 243, "Do not loop on principal unknown errors"). - Added "python-sphinx-latex" to the build requirements to fix build failures on F22 machines. * Thu Dec 18 2014 Roland Mainz - 1.13-4 -- fix for CVE-2014-5354 (#1174546) "krb5: NULL pointer +- fix for CVE-2014-5354 (rhbz#1174546) "krb5: NULL pointer dereference when using keyless entries" * Wed Dec 17 2014 Roland Mainz - 1.13-3 -- fix for CVE-2014-5353 (#1174543) "Fix LDAP misused policy +- fix for CVE-2014-5353 (rhbz#1174543) "Fix LDAP misused policy name crash" * Wed Oct 29 2014 Roland Mainz - 1.13-2 @@ -1922,18 +1931,18 @@ exit 0 * Wed Oct 29 2014 Roland Mainz - 1.13-1 - Update from krb5-1.13-alpha1 to final krb5-1.13 -- Removed patch for CVE-2014-5351 (#1145425) "krb5: current +- Removed patch for CVE-2014-5351 (rhbz#1145425) "krb5: current keys returned when randomizing the keys for a service principal" - now part of upstream sources -- Use patch for glibc |eventfd()| prototype mismatch (#1147887) only +- Use patch for glibc |eventfd()| prototype mismatch (rhbz#1147887) only for Fedora > 20 * Tue Sep 30 2014 Roland Mainz - 1.13-0.alpha1.3 - fix build failure caused by change of prototype for glibc - |eventfd()| (#1147887) + |eventfd()| (rhbz#1147887) * Mon Sep 29 2014 Roland Mainz - 1.13-0.alpha1.3 -- fix for CVE-2014-5351 (#1145425) "krb5: current keys returned when +- fix for CVE-2014-5351 (rhbz#1145425) "krb5: current keys returned when randomizing the keys for a service principal" * Mon Sep 8 2014 Nalin Dahyabhai - 1.13-0.alpha1.3 @@ -1949,7 +1958,7 @@ exit 0 * Wed Aug 20 2014 Nalin Dahyabhai - 1.12.2-3 - pull in upstream fix for an incorrect check on the value returned by a - strdup() call (#1132062) + strdup() call (rhbz#1132062) * Sun Aug 17 2014 Fedora Release Engineering - 1.12.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild @@ -1957,7 +1966,7 @@ exit 0 * Fri Aug 15 2014 Nalin Dahyabhai - 1.12.2-1 - update to 1.12.2 - drop patch for RT#7820, fixed in 1.12.2 - - drop patch for #231147, fixed as RT#3277 in 1.12.2 + - drop patch for rhbz#231147, fixed as RT#3277 in 1.12.2 - drop patch for RT#7818, fixed in 1.12.2 - drop patch for RT#7836, fixed in 1.12.2 - drop patch for RT#7858, fixed in 1.12.2 @@ -1968,7 +1977,7 @@ exit 0 - drop patch for CVE-2014-4344, included in 1.12.2 - drop patch for CVE-2014-4345, included in 1.12.2 - replace older proposed changes for ksu with backports of the changes - after review and merging upstream (#1015559, #1026099, #1118347) + after review and merging upstream (rhbz#1015559, rhbz#1026099, rhbz#1118347) * Thu Aug 7 2014 Nalin Dahyabhai - 1.12.1-14 - incorporate fix for MITKRB5-SA-2014-001 (CVE-2014-4345) @@ -1979,21 +1988,21 @@ exit 0 * Wed Jul 16 2014 Nalin Dahyabhai - 1.12.1-12 - gssapi: pull in proposed fix for a double free in initiators (David - Woodhouse, CVE-2014-4343, #1117963) + Woodhouse, CVE-2014-4343, rhbz#1117963) * Sat Jul 12 2014 Tom Callaway - 1.12.1-11 - fix license handling * Mon Jul 7 2014 Nalin Dahyabhai - 1.12.1-10 - pull in fix for denial of service by injection of malformed GSSAPI tokens - (CVE-2014-4341, CVE-2014-4342, #1116181) + (CVE-2014-4341, CVE-2014-4342, rhbz#1116181) * Tue Jun 24 2014 Nalin Dahyabhai - 1.12.1-9 - pull in changes from upstream which add processing of the contents of - /etc/gss/mech.d/*.conf when loading GSS modules (#1102839) + /etc/gss/mech.d/*.conf when loading GSS modules (rhbz#1102839) * Thu Jun 12 2014 Nalin Dahyabhai - 1.12.1-8 -- pull in fix for building against tcl 8.6 (#1107061) +- pull in fix for building against tcl 8.6 (rhbz#1107061) * Sun Jun 08 2014 Fedora Release Engineering - 1.12.1-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild @@ -2005,14 +2014,14 @@ exit 0 - spnego: pull in patch from master to restore preserving the OID of the mechanism the initiator requested when we have multiple OIDs for the same mechanism, so that we reply using the same mechanism OID and the initiator - doesn't get confused (#1066000, RT#7858) + doesn't get confused (rhbz#1066000, RT#7858) * Fri Feb 7 2014 Nalin Dahyabhai - 1.12.1-4 - pull in patch from master to move the default directory which the KDC uses when computing the socket path for a local OTP daemon from the database directory (/var/kerberos/krb5kdc) to the newly-added run directory (/run/krb5kdc), in line with what we're expecting in 1.13 (RT#7859, more - of #1040056 as #1063905) + of rhbz#1040056 as rhbz#1063905) - add a tmpfiles.d configuration file to have /run/krb5kdc created at boot-time - own /var/run/krb5kdc @@ -2022,12 +2031,12 @@ exit 0 * Fri Jan 31 2014 Nalin Dahyabhai - add currently-proposed changes to teach ksu about credential cache - collections and the default_ccache_name setting (#1015559,#1026099) + collections and the default_ccache_name setting (rhbz#1015559,rhbz#1026099) * Tue Jan 21 2014 Nalin Dahyabhai - 1.12.1-2 - pull in multiple changes to allow replay caches to be added to a GSS - credential store as "rcache"-type credentials (RT#7818/#7819/#7836, - #1056078/#1056080) + credential store as "rcache"-type credentials (RT#7818/rhbz#7819/rhbz#7836, + rhbz#1056078/rhbz#1056080) * Fri Jan 17 2014 Nalin Dahyabhai - 1.12.1-1 - update to 1.12.1 @@ -2040,11 +2049,11 @@ exit 0 - drop patches for RT#7813 and RT#7815, included now - add patch to always retrieve the KDC time offsets from keyring caches, so that we don't mistakenly interpret creds as expired before their - time when our clock is ahead of the KDC's (RT#7820, #1030607) + time when our clock is ahead of the KDC's (RT#7820, rhbz#1030607) * Mon Jan 13 2014 Nalin Dahyabhai - 1.12-11 - update the PIC patch for iaesx86.s to not use ELF relocations to the version - that landed upstream (RT#7815, #1045699) + that landed upstream (RT#7815, rhbz#1045699) * Thu Jan 9 2014 Nalin Dahyabhai - pass -Wl,--warn-shared-textrel to the compiler when we're creating shared @@ -2059,16 +2068,16 @@ exit 0 master - make a guess at making the 32-bit AES-NI implementation sufficiently position-independent to not require execmod permissions for libk5crypto - (more of #1045699) + (more of rhbz#1045699) * Thu Jan 2 2014 Nalin Dahyabhai - 1.12-8 - add patch from Dhiru Kholia for the AES-NI implementations to allow libk5crypto to be properly marked as not needing an executable stack - on arches where they're used (#1045699, and so many others) + on arches where they're used (rhbz#1045699, and so many others) * Thu Jan 2 2014 Nalin Dahyabhai - 1.12-7 - revert that last change for a bit while sorting out execstack when we - use AES-NI (#1045699) + use AES-NI (rhbz#1045699) * Thu Dec 19 2013 Nalin Dahyabhai - 1.12-6 - add yasm as a build requirement for AES-NI support, on arches that have @@ -2076,7 +2085,7 @@ exit 0 * Thu Dec 19 2013 Nalin Dahyabhai - 1.12-5 - pull in fix from master to make reporting of errors encountered by - the SPNEGO mechanism work better (RT#7045, part of #1043962) + the SPNEGO mechanism work better (RT#7045, part of rhbz#1043962) * Thu Dec 19 2013 Nalin Dahyabhai - update a test wrapper to properly handle things that the new libkrad does, @@ -2086,19 +2095,19 @@ exit 0 - revise previous patch to initialize one more element * Wed Dec 18 2013 Nalin Dahyabhai - 1.12-3 -- backport fixes to krb5_copy_context (RT#7807, #1044735/#1044739) +- backport fixes to krb5_copy_context (RT#7807, rhbz#1044735/rhbz#1044739) * Wed Dec 18 2013 Nalin Dahyabhai - 1.12-2 - pull in fix from master to return a NULL pointer rather than allocating zero bytes of memory if we read a zero-length input token (RT#7794, part of - #1043962) + rhbz#1043962) - pull in fix from master to ignore an empty token from an acceptor if - we've already finished authenticating (RT#7797, part of #1043962) + we've already finished authenticating (RT#7797, part of rhbz#1043962) - pull in fix from master to avoid a memory leak when a mechanism's - init_sec_context function fails (RT#7803, part of #1043962) + init_sec_context function fails (RT#7803, part of rhbz#1043962) - pull in fix from master to avoid a memory leak in a couple of error cases which could occur while obtaining acceptor credentials (RT#7805, part - of #1043962) + of rhbz#1043962) * Wed Dec 11 2013 Nalin Dahyabhai - 1.12-1 - update to 1.12 final @@ -2115,9 +2124,9 @@ exit 0 * Mon Nov 18 2013 Nalin Dahyabhai - 1.11.4-2 - pull in fix to store KDC time offsets in keyring credential caches (RT#7768, - #1030607) + rhbz#1030607) - pull in fix to set expiration times on credentials stored in keyring - credential caches (RT#7769, #1031724) + credential caches (RT#7769, rhbz#1031724) * Tue Nov 12 2013 Nalin Dahyabhai - 1.11.4-1 - update to 1.11.4 @@ -2126,21 +2135,21 @@ exit 0 - drop patch for CVE-2013-1418/CVE-2013-6800, included in 1.11.4 * Tue Nov 12 2013 Nalin Dahyabhai - 1.11.3-31 -- switch to the simplified version of the patch for #1029110 (RT#7764) +- switch to the simplified version of the patch for rhbz#1029110 (RT#7764) * Mon Nov 11 2013 Nalin Dahyabhai - 1.11.3-30 - check more thoroughly for errors when resolving KEYRING ccache names of type "persistent", which should only have a numeric UID as the next part of the - name (#1029110) + name (rhbz#1029110) * Tue Nov 5 2013 Nalin Dahyabhai - 1.11.3-29 - incorporate upstream patch for remote crash of KDCs which serve multiple realms simultaneously (RT#7756, CVE-2013-1418/CVE-2013-6800, - #1026997/#1031501) + rhbz#1026997/rhbz#1031501) * Mon Nov 4 2013 Nalin Dahyabhai - 1.11.3-28 - drop patch to add additional access() checks to ksu - they add to breakage - when non-FILE: caches are in use (#1026099), shouldn't be resulting in any + when non-FILE: caches are in use (rhbz#1026099), shouldn't be resulting in any benefit, and clash with proposed changes to fix its cache handling * Tue Oct 22 2013 Nalin Dahyabhai - 1.11.3-27 @@ -2169,22 +2178,22 @@ exit 0 - BuildRequires: pkgconfig, since configure uses it * Wed Oct 16 2013 Nalin Dahyabhai - 1.11.3-26 -- create and own /etc/gss (#1019937) +- create and own /etc/gss (rhbz#1019937) * Tue Oct 15 2013 Nalin Dahyabhai - 1.11.3-25 - pull up fix for importing previously-exported credential caches in the - gssapi library (RT# 7706, #1019420) + gssapi library (RT# 7706, rhbz#1019420) * Mon Oct 14 2013 Nalin Dahyabhai - 1.11.3-24 - backport the callback to use the libkrb5 prompter when we can't load PEM - files for PKINIT (RT#7590, includes part of #965721/#1016690) -- extract the rest of the fix #965721/#1016690 from the changes for RT#7680 + files for PKINIT (RT#7590, includes part of rhbz#965721/rhbz#1016690) +- extract the rest of the fix rhbz#965721/rhbz#1016690 from the changes for RT#7680 * Mon Oct 14 2013 Nalin Dahyabhai - 1.11.3-23 -- fix trigger scriptlet's invocation of sed (#1016945) +- fix trigger scriptlet's invocation of sed (rhbz#1016945) * Fri Oct 4 2013 Nalin Dahyabhai - 1.11.3-22 -- rebuild with keyutils 1.5.8 (part of #1012043) +- rebuild with keyutils 1.5.8 (part of rhbz#1012043) * Wed Oct 2 2013 Nalin Dahyabhai - 1.11.3-21 - switch to the version of persistent-keyring that was just merged to @@ -2194,7 +2203,7 @@ exit 0 * Mon Sep 30 2013 Nalin Dahyabhai - 1.11.3-20 - pull up fix for not calling a kdb plugin's check-transited-path method before calling the library's default version, which only knows - how to read what's in the configuration file (RT#7709, #1013664) + how to read what's in the configuration file (RT#7709, rhbz#1013664) * Thu Sep 26 2013 Nalin Dahyabhai - 1.11.3-19 - configure --without-krb5-config so that we don't pull in the old default @@ -2205,7 +2214,7 @@ exit 0 - fix broken dependency on awk (should be gawk, rdieter) * Wed Sep 25 2013 Nalin Dahyabhai - 1.11.3-17 -- add missing dependency on newer keyutils-libs (#1012034) +- add missing dependency on newer keyutils-libs (rhbz#1012034) * Tue Sep 24 2013 Nalin Dahyabhai - 1.11.3-16 - back out setting default_ccache_name to the new default for now, resetting @@ -2213,11 +2222,11 @@ exit 0 * Mon Sep 23 2013 Nalin Dahyabhai - 1.11.3-15 - add explicit build-time dependency on a version of keyutils that's new - enough to include keyctl_get_persistent() (more of #991148) + enough to include keyctl_get_persistent() (more of rhbz#991148) * Thu Sep 19 2013 Nalin Dahyabhai - 1.11.3-14 - incorporate Simo's updated backport of his updated persistent-keyring changes - (more of #991148) + (more of rhbz#991148) * Fri Sep 13 2013 Nalin Dahyabhai - 1.11.3-13 - don't break during %%check when the session keyring is revoked @@ -2231,17 +2240,17 @@ exit 0 * Mon Sep 9 2013 Nalin Dahyabhai 1.11.3-11 - don't let comments intended for one scriptlet become part of the "script" - that gets passed to ldconfig as part of another one (Mattias Ellert, #1005675) + that gets passed to ldconfig as part of another one (Mattias Ellert, rhbz#1005675) * Fri Sep 6 2013 Nalin Dahyabhai 1.11.3-10 -- incorporate Simo's backport of his persistent-keyring changes (#991148) +- incorporate Simo's backport of his persistent-keyring changes (rhbz#991148) - restore build-time default DEFCCNAME on Fedora 21 and later and EL, and instead set default_ccache_name in the default krb5.conf's [libdefaults] - section (#991148) + section (rhbz#991148) - on releases where we expect krb5.conf to be configured with a default_ccache_name, add it whenever we upgrade from an older version of the package that wouldn't have included it in its default configuration - file (#991148) + file (rhbz#991148) * Fri Aug 23 2013 Nalin Dahyabhai 1.11.3-9 - take another stab at accounting for UnversionedDocdirs for the -libs @@ -2256,7 +2265,7 @@ exit 0 of files which dictate particular exit codes before exec'ing the actual binaries, instead of trying to use ConditionPathExists in the unit files to accomplish that, so that we exit with failure properly when what we - expect isn't actually in effect on the system (#800343) + expect isn't actually in effect on the system (rhbz#800343) * Mon Jul 29 2013 Nalin Dahyabhai 1.11.3-7 - attempt to account for UnversionedDocdirs for the -libs subpackage @@ -2268,11 +2277,11 @@ exit 0 * Mon Jul 22 2013 Nalin Dahyabhai 1.11.3-5 - pull up changes to allow GSSAPI modules to provide more functions - (RT#7682, #986564/#986565) + (RT#7682, rhbz#986564/rhbz#986565) * Fri Jul 19 2013 Nalin Dahyabhai 1.11.3-4 - use (a bundled, for now, copy of) nss_wrapper to let us run some of the - self-tests at build-time in more places than we could previously (#978756) + self-tests at build-time in more places than we could previously (rhbz#978756) - cover inconsistencies in whether or not there's a local caching nameserver that's willing to answer when the build environment doesn't have a resolver configuration, so that nss_wrapper's faking of the local @@ -2280,23 +2289,23 @@ exit 0 * Mon Jul 1 2013 Nalin Dahyabhai 1.11.3-3 - specify dependencies on the same arch of krb5-libs by using the %%{?_isa} - suffix, to avoid dragging 32-bit libraries onto 64-bit systems (#980155) + suffix, to avoid dragging 32-bit libraries onto 64-bit systems (rhbz#980155) * Thu Jun 13 2013 Nalin Dahyabhai 1.11.3-2 - special-case /run/user/0, attempting to create it when resolving a directory cache below it fails due to ENOENT and we find that it doesn't already exist, either, before attempting to create the directory cache - (maybe helping, maybe just making things more confusing for #961235) + (maybe helping, maybe just making things more confusing for rhbz#961235) * Tue Jun 4 2013 Nalin Dahyabhai 1.11.3-1 - update to 1.11.3 - drop patch for RT#7605, fixed in this release - drop patch for CVE-2002-2443, fixed in this release - drop patch for RT#7369, fixed in this release -- pull upstream fix for breaking t_skew.py by adding the patch for #961221 +- pull upstream fix for breaking t_skew.py by adding the patch for rhbz#961221 * Fri May 31 2013 Nalin Dahyabhai 1.11.2-10 -- respin with updated version of patch for RT#7650 (#969331) +- respin with updated version of patch for RT#7650 (rhbz#969331) * Thu May 30 2013 Nalin Dahyabhai 1.11.2-9 - don't forget to set the SELinux label when creating the directory for @@ -2312,22 +2321,22 @@ exit 0 * Tue May 28 2013 Nalin Dahyabhai 1.11.2-7 - backport fix for not being able to verify the list of transited realms - in GSS acceptors (RT#7639, #959685) + in GSS acceptors (RT#7639, rhbz#959685) - backport fix for not being able to pass an empty password to the - get-init-creds APIs and have them actually use it (RT#7642, #960001) + get-init-creds APIs and have them actually use it (RT#7642, rhbz#960001) - add backported proposed fix to use the unauthenticated server time as the basis for computing the requested credential expiration times, rather than the client's idea of the current time, which could be - significantly incorrect (#961221) + significantly incorrect (rhbz#961221) * Tue May 21 2013 Nalin Dahyabhai 1.11.2-6 - pull in upstream fix to start treating a KRB5CCNAME value that begins with DIR:: the same as it would a DIR: value with just one ccache file - in it (RT#7172, #965574) + in it (RT#7172, rhbz#965574) * Mon May 13 2013 Nalin Dahyabhai 1.11.2-5 - pull up fix for UDP ping-pong flaw in kpasswd service (CVE-2002-2443, - #962531,#962534) + rhbz#962531,rhbz#962534) * Mon Apr 29 2013 Nathaniel McCallum 1.11.2-4 - Update otp patches @@ -2347,11 +2356,11 @@ exit 0 - drop pulled in patch for RT#7586, included in this release - drop pulled in patch for RT#7592, included in this release - pull in fix for keeping track of the message type when parsing FAST requests - in the KDC (RT#7605, #951843) (also #951965) + in the KDC (RT#7605, rhbz#951843) (also rhbz#951965) * Fri Apr 12 2013 Nalin Dahyabhai 1.11.1-9 - move the compiled-in default ccache location from the previous default of - FILE:/tmp/krb5cc_%%{uid} to DIR:/run/user/%%{uid}/krb5cc (part of #949588) + FILE:/tmp/krb5cc_%%{uid} to DIR:/run/user/%%{uid}/krb5cc (part of rhbz#949588) * Tue Apr 09 2013 Nathaniel McCallum - 1.11.1-8 - Update otp backport patches (libk5radius => libkrad) @@ -2372,8 +2381,8 @@ exit 0 * Tue Mar 26 2013 Nalin Dahyabhai 1.11.1-5 - pull up Simo's patch to mark the correct mechanism on imported GSSAPI contexts (RT#7592) -- go back to using reconf to run autoconf and autoheader (part of #925640) -- add temporary patch to use newer config.guess/config.sub (more of #925640) +- go back to using reconf to run autoconf and autoheader (part of rhbz#925640) +- add temporary patch to use newer config.guess/config.sub (more of rhbz#925640) * Mon Mar 18 2013 Nalin Dahyabhai - fix a version comparison to expect newer texlive build requirements when @@ -2384,12 +2393,12 @@ exit 0 - Add otp support * Thu Feb 28 2013 Nalin Dahyabhai 1.11.1-3 -- fix a memory leak when acquiring credentials using a keytab (RT#7586, #911110) +- fix a memory leak when acquiring credentials using a keytab (RT#7586, rhbz#911110) * Wed Feb 27 2013 Nalin Dahyabhai 1.11.1-2 -- prebuild PDF docs to reduce multilib differences (internal tooling, #884065) +- prebuild PDF docs to reduce multilib differences (internal tooling, rhbz#884065) - drop the kerberos-iv portreserve file, and drop the rest on systemd systems -- escape uses of macros in comments (more of #884065) +- escape uses of macros in comments (more of rhbz#884065) * Mon Feb 25 2013 Nalin Dahyabhai 1.11.1-1 - update to 1.11.1 @@ -2397,7 +2406,7 @@ exit 0 wrapper in the client transmit functions * Fri Feb 8 2013 Nalin Dahyabhai 1.11-2 -- set "rdns = false" in the default krb5.conf (#908323,#908324) +- set "rdns = false" in the default krb5.conf (rhbz#908323,rhbz#908324) * Tue Dec 18 2012 Nalin Dahyabhai 1.11-1 - update to 1.11 release @@ -2407,7 +2416,7 @@ exit 0 * Thu Dec 13 2012 Nalin Dahyabhai - when building with our bundled copy of libverto, package it in with -libs - rather than with -server (#886049) + rather than with -server (rhbz#886049) * Wed Nov 21 2012 Nalin Dahyabhai 1.11-0.beta1.0 - update to 1.11 beta 1 @@ -2429,9 +2438,9 @@ exit 0 * Thu Nov 15 2012 Nalin Dahyabhai - update to 1.11 alpha 1 - - drop backported patch for RT #7406 - - drop backported patch for RT #7407 - - drop backported patch for RT #7408 + - drop backported patch for RT rhbz#7406 + - drop backported patch for RT rhbz#7407 + - drop backported patch for RT rhbz#7408 - the new docs system generates PDFs, so stop including them as sources - drop backported patch to allow deltat.y to build with the usual warning flags and the current gcc @@ -2455,27 +2464,27 @@ exit 0 %%{?_rawbuild} builds (zmraz) * Tue Sep 25 2012 Nalin Dahyabhai 1.10.3-6 -- actually pull up the patch for RT#7063, and not some other ticket (#773496) +- actually pull up the patch for RT#7063, and not some other ticket (rhbz#773496) * Mon Sep 10 2012 Nalin Dahyabhai 1.10.3-5 - add patch based on one from Filip Krska to not call poll() with a negative - timeout when the caller's intent is for us to just stop calling it (#838548) + timeout when the caller's intent is for us to just stop calling it (rhbz#838548) * Fri Sep 7 2012 Nalin Dahyabhai - on EL6, conflict with libsmbclient before 3.5.10-124, which is when it - stopped linking with a symbol which we no longer export (#771687) + stopped linking with a symbol which we no longer export (rhbz#771687) - pull up patch for RT#7063, in which not noticing a prompt for a long time throws the client library's idea of the time difference between it - and the KDC really far out of whack (#773496) + and the KDC really far out of whack (rhbz#773496) - add a backport of more patches to set the client's list of supported enctypes when using a keytab to be the list of types of keys in the keytab, plus the list of other types the client supports but for which it doesn't have keys, in that order, so that KDCs have a better chance of being able to issue - tickets with session keys of types that the client can use (#837855) + tickets with session keys of types that the client can use (rhbz#837855) * Thu Sep 6 2012 Nalin Dahyabhai 1.10.3-4 - cut down the number of times we load SELinux labeling configuration from - a minimum of two times to actually one (more of #845125) + a minimum of two times to actually one (more of rhbz#845125) * Thu Aug 30 2012 Nalin Dahyabhai 1.10.3-3 - backport patch to disable replay detection in krb5_verify_init_creds() @@ -2493,7 +2502,7 @@ exit 0 * Thu Aug 2 2012 Nalin Dahyabhai 1.10.2-7 - selinux: hang on to the list of selinux contexts, freeing and reloading it only when the file we read it from is modified, freeing it when the - shared library is being unloaded (#845125) + shared library is being unloaded (rhbz#845125) * Thu Aug 2 2012 Nalin Dahyabhai 1.10.2-6 - go back to not messing with library file paths on Fedora 17: it breaks @@ -2503,7 +2512,7 @@ exit 0 * Tue Jul 31 2012 Nalin Dahyabhai 1.10.2-5 - add upstream patch to fix freeing an uninitialized pointer and dereferencing another uninitialized pointer in the KDC (MITKRB5-SA-2012-001, CVE-2012-1014 - and CVE-2012-1015, #844779 and #844777) + and CVE-2012-1015, rhbz#844779 and rhbz#844777) - fix a thinko in whether or not we mess around with devel .so symlinks on systems without a separate /usr (sbose) @@ -2529,7 +2538,7 @@ exit 0 - add a backport of Stef's patch to set the client's list of supported enctypes to match the types of keys that we have when we are using a keytab to try to get initial credentials, so that a KDC won't send us - an AS reply that we can't encrypt (RT#2131, #748528) + an AS reply that we can't encrypt (RT#2131, rhbz#748528) - don't shuffle around any shared libraries on releases with no-separate-/usr, since /usr/lib is the same place as /lib - add explicit buildrequires: on 'hostname', for the tests, on systems where @@ -2538,15 +2547,15 @@ exit 0 * Mon May 7 2012 Nalin Dahyabhai - skip the setfscreatecon() if fopen() is passed "rb" as the open mode (part - of #819115) + of rhbz#819115) * Tue May 1 2012 Nalin Dahyabhai 1.10.1-3 - have -server require /usr/share/dict/words, which we set as the default - dict_file in kdc.conf (#817089) + dict_file in kdc.conf (rhbz#817089) * Tue Mar 20 2012 Nalin Dahyabhai 1.10.1-2 -- change back dns_lookup_kdc to the default setting (Stef Walter, #805318) -- comment out example.com examples in default krb5.conf (Stef Walter, #805320) +- change back dns_lookup_kdc to the default setting (Stef Walter, rhbz#805318) +- comment out example.com examples in default krb5.conf (Stef Walter, rhbz#805320) * Fri Mar 9 2012 Nalin Dahyabhai 1.10.1-1 - update to 1.10.1 @@ -2557,7 +2566,7 @@ exit 0 * Wed Mar 7 2012 Nalin Dahyabhai 1.10-5 - when removing -workstation, remove our files from the info index while the file is still there, in %%preun, rather than %%postun, and use the - compressed file's name (#801035) + compressed file's name (rhbz#801035) * Tue Feb 21 2012 Nathaniel McCallum - 1.10-4 - Fix string RPC ACLs (RT#7093); CVE-2012-1012 @@ -2567,7 +2576,7 @@ exit 0 * Mon Jan 30 2012 Nalin Dahyabhai 1.10-2 - add patch to accept keytab entries with vno==0 as matches when we're - searching for an entry with a specific name/kvno (#230382/#782211,RT#3349) + searching for an entry with a specific name/kvno (rhbz#230382/rhbz#782211,RT#3349) * Mon Jan 30 2012 Nalin Dahyabhai 1.10-1 - update to 1.10 final @@ -2592,21 +2601,21 @@ exit 0 * Tue Dec 13 2011 Nalin Dahyabhai 1.10-0.alpha1.3 - pull in patch for RT#7046: tag a ccache containing credentials obtained via - S4U2Proxy with the principal name of the proxying principal (part of #761317) + S4U2Proxy with the principal name of the proxying principal (part of rhbz#761317) so that the default principal name can be set to that of the client for which it is proxying, which results in the ccache looking more normal to consumers of the ccache that don't care that there's proxying going on - pull in patch for RT#7047: allow tickets obtained via S4U2Proxy to be cached - (more of #761317) + (more of rhbz#761317) - pull in patch for RT#7048: allow PAC verification to only bother trying to - verify the signature with keys that it's given (still more of #761317) + verify the signature with keys that it's given (still more of rhbz#761317) * Tue Dec 6 2011 Nalin Dahyabhai 1.10-0.alpha1.2 - apply upstream patch to fix a null pointer dereference when processing - TGS requests (CVE-2011-1530, #753748) + TGS requests (CVE-2011-1530, rhbz#753748) * Wed Nov 30 2011 Nalin Dahyabhai 1.10-0.alpha1.1 -- correct a bug in the fix for #754001 so that the file creation context is +- correct a bug in the fix for rhbz#754001 so that the file creation context is consistently reset * Tue Nov 15 2011 Nalin Dahyabhai 1.10-0.alpha1.0 @@ -2621,27 +2630,27 @@ exit 0 should be able to run inside of the build system without issue * Wed Oct 26 2011 Fedora Release Engineering - 1.9.1-19 -- Rebuilt for glibc bug#747377 +- Rebuilt for glibc rhbz#747377 * Tue Oct 18 2011 Nalin Dahyabhai 1.9.1-18 - apply upstream patch to fix a null pointer dereference with the LDAP kdb - backend (CVE-2011-1527, #744125), an assertion failure with multiple kdb + backend (CVE-2011-1527, rhbz#744125), an assertion failure with multiple kdb backends (CVE-2011-1528), and a null pointer dereference with multiple kdb - backends (CVE-2011-1529) (#737711) + backends (CVE-2011-1529) (rhbz#737711) * Thu Oct 13 2011 Nalin Dahyabhai 1.9.1-17 - pull in patch from trunk to rename krb5int_pac_sign() to krb5_pac_sign() and - make it public (#745533) + make it public (rhbz#745533) * Fri Oct 7 2011 Nalin Dahyabhai 1.9.1-16 -- kadmin.service: fix #723723 again +- kadmin.service: fix rhbz#723723 again - kadmin.service,krb5kdc.service: remove optional use of $KRB5REALM in command lines, because systemd parsing doesn't handle alternate value shell variable syntax - kprop.service: add missing Type=forking so that systemd doesn't assume simple - kprop.service: expect the ACL configuration to be there, not absent - handle a harder-to-trigger assertion failure that starts cropping up when we - exit the transmit loop on time (#739853) + exit the transmit loop on time (rhbz#739853) * Sun Oct 2 2011 Tom Callaway 1.9.1-15 - hardcode pid file as option in krb5kdc.service @@ -2654,50 +2663,50 @@ exit 0 * Tue Sep 6 2011 Nalin Dahyabhai 1.9.1-12 - pull in upstream patch for RT#6952, confusion following referrals for - cross-realm auth (#734341) + cross-realm auth (rhbz#734341) - pull in build-time deps for the tests * Thu Sep 1 2011 Nalin Dahyabhai 1.9.1-11 -- switch to the upstream patch for #727829 +- switch to the upstream patch for rhbz#727829 * Wed Aug 31 2011 Nalin Dahyabhai 1.9.1-10 - handle an assertion failure that starts cropping up when the patch for - using poll (#701446) meets servers that aren't running KDCs or against - which the connection fails for other reasons (#727829, #734172) + using poll (rhbz#701446) meets servers that aren't running KDCs or against + which the connection fails for other reasons (rhbz#727829, rhbz#734172) * Mon Aug 8 2011 Nalin Dahyabhai 1.9.1-9 - override the default build rules to not delete temporary y.tab.c files, so that they can be packaged, allowing debuginfo files which point to them - do so usefully (#729044) + do so usefully (rhbz#729044) * Fri Jul 22 2011 Nalin Dahyabhai 1.9.1-8 -- build shared libraries with partial RELRO support (#723995) +- build shared libraries with partial RELRO support (rhbz#723995) - filter out potentially multiple instances of -Wl,-z,relro from krb5-config output, now that it's in the buildroot's default LDFLAGS - pull in a patch to fix losing track of the replay cache FD, from SVN by way of Kevin Coffman * Wed Jul 20 2011 Nalin Dahyabhai 1.9.1-7 -- kadmind.init: drop the attempt to detect no-database-present errors (#723723), +- kadmind.init: drop the attempt to detect no-database-present errors (rhbz#723723), which is too fragile in cases where the database has been manually moved or is accessed through another kdb plugin * Tue Jul 19 2011 Nalin Dahyabhai 1.9.1-6 - backport fixes to teach libkrb5 to use descriptors higher than FD_SETSIZE - to talk to a KDC by using poll() if it's detected at compile-time (#701446, + to talk to a KDC by using poll() if it's detected at compile-time (rhbz#701446, RT#6905) * Thu Jun 23 2011 Nalin Dahyabhai 1.9.1-5 - pull a fix from SVN to try to avoid triggering a PTR lookup in getaddrinfo() during krb5_sname_to_principal(), and to let getaddrinfo() decide whether or not to ask for an IPv6 address based on the set of configured interfaces - (#717378, RT#6922) + (rhbz#717378, RT#6922) - pull a fix from SVN to use AI_ADDRCONFIG more often (RT#6923) * Mon Jun 20 2011 Nalin Dahyabhai 1.9.1-4 - apply upstream patch by way of Burt Holzman to fall back to a non-referral method in cases where we might be derailed by a KDC that rejects the - canonicalize option (for example, those from the RHEL 2.1 or 3 era) (#715074) + canonicalize option (for example, those from the RHEL 2.1 or 3 era) (rhbz#715074) * Tue Jun 14 2011 Nalin Dahyabhai 1.9.1-3 - pull a fix from SVN to get libgssrpc clients (e.g. kadmin) authenticating @@ -2705,13 +2714,13 @@ exit 0 * Tue Jun 14 2011 Nalin Dahyabhai - incorporate a fix to teach the file labeling bits about when replay caches - are expunged (#576093) + are expunged (rhbz#576093) * Thu May 26 2011 Nalin Dahyabhai -- switch to the upstream patch for #707145 +- switch to the upstream patch for rhbz#707145 * Wed May 25 2011 Nalin Dahyabhai 1.9.1-2 -- klist: don't trip over referral entries when invoked with -s (#707145, +- klist: don't trip over referral entries when invoked with -s (rhbz#707145, RT#6915) * Fri May 6 2011 Nalin Dahyabhai @@ -2724,26 +2733,26 @@ exit 0 CVE-2011-0282, CVE-2011-0283, CVE-2011-0284, CVE-2011-0285 * Wed Apr 13 2011 Nalin Dahyabhai 1.9-9 -- kadmind: add upstream patch to fix free() on an invalid pointer (#696343, +- kadmind: add upstream patch to fix free() on an invalid pointer (rhbz#696343, MITKRB5-SA-2011-004, CVE-2011-0285) * Mon Apr 4 2011 Nalin Dahyabhai - don't discard the error code from an error message received in response - to a change-password request (#658871, RT#6893) + to a change-password request (rhbz#658871, RT#6893) * Fri Apr 1 2011 Nalin Dahyabhai - override INSTALL_SETUID at build-time so that ksu is installed into - the buildroot with the right permissions (part of #225974) + the buildroot with the right permissions (part of rhbz#225974) * Fri Mar 18 2011 Nalin Dahyabhai 1.9-8 - backport change from SVN to fix a computed-value-not-used warning in - kpropd (#684065) + kpropd (rhbz#684065) * Tue Mar 15 2011 Nalin Dahyabhai 1.9-7 - turn off NSS as the backend for libk5crypto for now to work around its - DES string2key not working (#679012) + DES string2key not working (rhbz#679012) - add revised upstream patch to fix double-free in KDC while returning - typed-data with errors (MITKRB5-SA-2011-003, CVE-2011-0284, #674325) + typed-data with errors (MITKRB5-SA-2011-003, CVE-2011-0284, rhbz#674325) * Thu Feb 17 2011 Nalin Dahyabhai - throw in a not-applied-by-default patch to try to make pkinit debugging @@ -2756,14 +2765,14 @@ exit 0 * Wed Feb 9 2011 Nalin Dahyabhai 1.9-5 - krb5kdc init script: prototype some changes to do a quick spot-check of the TGS and kadmind keys and warn if there aren't any non-weak keys - on file for them (to flush out parts of #651466) + on file for them (to flush out parts of rhbz#651466) * Tue Feb 8 2011 Nalin Dahyabhai 1.9-4 - add upstream patches to fix standalone kpropd exiting if the per-client child process exits with an error (MITKRB5-SA-2011-001), a hang or crash in the KDC when using the LDAP kdb backend, and an uninitialized pointer - use in the KDC (MITKRB5-SA-2011-002) (CVE-2010-4022, #664009, - CVE-2011-0281, #668719, CVE-2011-0282, #668726, CVE-2011-0283, #676126) + use in the KDC (MITKRB5-SA-2011-002) (CVE-2010-4022, rhbz#664009, + CVE-2011-0281, rhbz#668719, CVE-2011-0282, rhbz#668726, CVE-2011-0283, rhbz#676126) * Mon Feb 07 2011 Fedora Release Engineering - 1.9-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild @@ -2774,11 +2783,11 @@ exit 0 * Tue Feb 1 2011 Nalin Dahyabhai - properly advertise that the kpropd init script now supports force-reload - (Zbysek Mraz, #630587) + (Zbysek Mraz, rhbz#630587) * Wed Jan 26 2011 Nalin Dahyabhai 1.9-2 - pkinit: when verifying signed data, use the CMS APIs for better - interoperability (#636985, RT#6851) + interoperability (rhbz#636985, RT#6851) * Wed Dec 22 2010 Nalin Dahyabhai 1.9-1 - update to 1.9 final @@ -2798,56 +2807,56 @@ exit 0 * Fri Nov 5 2010 Nalin Dahyabhai 1.9-0.beta1.0 - start moving to 1.9 with beta 1 - drop patches for RT#5755, RT#6762, RT#6774, RT#6775 - - drop no-longer-needed backport patch for #539423 + - drop no-longer-needed backport patch for rhbz#539423 - drop no-longer-needed patch for CVE-2010-1322 - if WITH_NSS is set, built with --with-crypto-impl=nss (requires NSS 3.12.9) * Tue Oct 5 2010 Nalin Dahyabhai 1.8.3-8 - incorporate upstream patch to fix uninitialized pointer crash in the KDC's - authorization data handling (CVE-2010-1322, #636335) + authorization data handling (CVE-2010-1322, rhbz#636335) * Mon Oct 4 2010 Nalin Dahyabhai 1.8.3-7 - rebuild * Mon Oct 4 2010 Nalin Dahyabhai 1.8.3-6 - pull down patches from trunk to implement k5login_authoritative and - k5login_directory settings for krb5.conf (#539423) + k5login_directory settings for krb5.conf (rhbz#539423) * Wed Sep 29 2010 jkeating - 1.8.3-5 -- Rebuilt for gcc bug 634757 +- Rebuilt for gcc rhbz#634757 * Wed Sep 15 2010 Nalin Dahyabhai 1.8.3-4 - fix reading of keyUsage extensions when attempting to select pkinit client - certs (part of #629022, RT#6775) + certs (part of rhbz#629022, RT#6775) - fix selection of pkinit client certs when one or more don't include a - subjectAltName extension (part of #629022, RT#6774) + subjectAltName extension (part of rhbz#629022, RT#6774) * Fri Sep 3 2010 Nalin Dahyabhai 1.8.3-3 - build with -fstack-protector-all instead of the default -fstack-protector, - so that we add checking to more functions (i.e., all of them) (#629950) -- also link binaries with -Wl,-z,relro,-z,now (part of #629950) + so that we add checking to more functions (i.e., all of them) (rhbz#629950) +- also link binaries with -Wl,-z,relro,-z,now (part of rhbz#629950) * Tue Aug 24 2010 Nalin Dahyabhai 1.8.3-2 -- fix a logic bug in computing key expiration times (RT#6762, #627022) +- fix a logic bug in computing key expiration times (RT#6762, rhbz#627022) * Wed Aug 4 2010 Nalin Dahyabhai 1.8.3-1 - update to 1.8.3 - drop backports of fixes for gss context expiration and error table registration/deregistration mismatch - - drop patch for upstream #6750 + - drop patch for upstream rhbz#6750 * Wed Jul 7 2010 Nalin Dahyabhai 1.8.2-3 - tell krb5kdc and kadmind to create pid files, since they can -- add logrotate configuration files for krb5kdc and kadmind (#462658) -- fix parsing of the pidfile option in the KDC (upstream #6750) +- add logrotate configuration files for krb5kdc and kadmind (rhbz#462658) +- fix parsing of the pidfile option in the KDC (upstream rhbz#6750) * Mon Jun 21 2010 Nalin Dahyabhai 1.8.2-2 - libgssapi: pull in patch from svn to stop returning context-expired errors - when the ticket which was used to set up the context expires (#605366, - upstream #6739) + when the ticket which was used to set up the context expires (rhbz#605366, + upstream rhbz#6739) * Mon Jun 21 2010 Nalin Dahyabhai -- pull up fix for upstream #6745, in which the gssapi library would add the +- pull up fix for upstream rhbz#6745, in which the gssapi library would add the wrong error table but subsequently attempt to unload the right one * Thu Jun 10 2010 Nalin Dahyabhai 1.8.2-1 @@ -2859,8 +2868,8 @@ exit 0 * Thu May 27 2010 Nalin Dahyabhai - ksu: move session management calls to before we drop privileges, like - su does (#596887), and don't skip the PAM account check for root or the - same user (more of #540769) + su does (rhbz#596887), and don't skip the PAM account check for root or the + same user (more of rhbz#540769) * Mon May 24 2010 Nalin Dahyabhai 1.8.1-6 - make krb5-server-ldap also depend on the same version-release of krb5-libs, @@ -2873,20 +2882,20 @@ exit 0 * Tue May 18 2010 Nalin Dahyabhai 1.8.1-5 - add patch to correct GSSAPI library null pointer dereference which could be - triggered by malformed client requests (CVE-2010-1321, #582466) + triggered by malformed client requests (CVE-2010-1321, rhbz#582466) * Tue May 4 2010 Nalin Dahyabhai 1.8.1-4 -- fix output of kprop's init script's "status" and "reload" commands (#588222) +- fix output of kprop's init script's "status" and "reload" commands (rhbz#588222) * Tue Apr 20 2010 Nalin Dahyabhai 1.8.1-3 -- incorporate patch to fix double-free in the KDC (CVE-2010-1320, #581922) +- incorporate patch to fix double-free in the KDC (CVE-2010-1320, rhbz#581922) * Wed Apr 14 2010 Nalin Dahyabhai 1.8.1-2 - fix a typo in kerberos.ldif * Fri Apr 9 2010 Nalin Dahyabhai 1.8.1-1 - update to 1.8.1 - - no longer need patches for #555875, #561174, #563431, RT#6661, CVE-2010-0628 + - no longer need patches for rhbz#555875, rhbz#561174, rhbz#563431, RT#6661, CVE-2010-0628 - replace buildrequires on tetex-latex with one on texlive-latex, which is the package that provides it now @@ -2896,21 +2905,21 @@ exit 0 * Thu Apr 8 2010 Nalin Dahyabhai - drop patch to suppress key expiration warnings sent from the KDC in the last-req field, as the KDC is expected to just be configured to either - send them or not as a particular key approaches expiration (#556495) + send them or not as a particular key approaches expiration (rhbz#556495) * Tue Mar 23 2010 Nalin Dahyabhai - 1.8-5 -- add upstream fix for denial-of-service in SPNEGO (CVE-2010-0628, #576325) +- add upstream fix for denial-of-service in SPNEGO (CVE-2010-0628, rhbz#576325) - kdc.conf: no more need to suggest keeping keys with v4-compatible salting * Fri Mar 19 2010 Nalin Dahyabhai - 1.8-4 - remove the krb5-appl bits (the -workstation-clients and -workstation-servers subpackages) now that krb5-appl is its own package -- replace our patch for #563431 (kpasswd doesn't fall back to guessing your +- replace our patch for rhbz#563431 (kpasswd doesn't fall back to guessing your principal name using your user name if you don't have a ccache) with the one upstream uses * Fri Mar 12 2010 Nalin Dahyabhai - 1.8-3 -- add documentation for the ticket_lifetime option (#561174) +- add documentation for the ticket_lifetime option (rhbz#561174) * Mon Mar 8 2010 Nalin Dahyabhai - 1.8-2 - pull up patch to get the client libraries to correctly perform password @@ -2930,10 +2939,10 @@ exit 0 - fix a null pointer dereference and crash introduced in our PAM patch that would happen if ftpd was given the name of a user who wasn't known to the local system, limited to being triggerable by gssapi-authenticated clients by - the default xinetd config (Olivier Fourdan, #569472) + the default xinetd config (Olivier Fourdan, rhbz#569472) * Tue Mar 2 2010 Nalin Dahyabhai - 1.7.1-5 -- fix a regression (not labeling a kdb database lock file correctly, #569902) +- fix a regression (not labeling a kdb database lock file correctly, rhbz#569902) * Thu Feb 25 2010 Nalin Dahyabhai - 1.7.1-4 - move the package changelog to the end to match the usual style (jdennis) @@ -2943,15 +2952,15 @@ exit 0 * Wed Feb 17 2010 Nalin Dahyabhai - 1.7.1-3 - pull up the change to make kpasswd's behavior better match the docs - when there's no ccache (#563431) + when there's no ccache (rhbz#563431) * Tue Feb 16 2010 Nalin Dahyabhai - 1.7.1-2 - apply patch from upstream to fix KDC denial of service (CVE-2010-0283, - #566002) + rhbz#566002) * Wed Feb 3 2010 Nalin Dahyabhai - 1.7.1-1 - update to 1.7.1 - - don't trip AD lockout on wrong password (#542687, #554351) + - don't trip AD lockout on wrong password (rhbz#542687, rhbz#554351) - incorporates fixes for CVE-2009-4212 and CVE-2009-3295 - fixes gss_krb5_copy_ccache() when SPNEGO is used - move sim_client/sim_server, gss-client/gss-server, uuclient/uuserver to @@ -2961,7 +2970,7 @@ exit 0 depends on -workstation which also includes them * Mon Jan 25 2010 Nalin Dahyabhai - 1.7-23 -- tighten up default permissions on kdc.conf and kadm5.acl (#558343) +- tighten up default permissions on kdc.conf and kadm5.acl (rhbz#558343) * Fri Jan 22 2010 Nalin Dahyabhai - 1.7-22 - use portreserve correctly -- portrelease takes the basename of the file @@ -2970,47 +2979,47 @@ exit 0 * Mon Jan 18 2010 Nalin Dahyabhai - 1.7-21 - suppress warnings of impending password expiration if expiration is more than seven days away when the KDC reports it via the last-req field, just as we - already do when it reports expiration via the key-expiration field (#556495) + already do when it reports expiration via the key-expiration field (rhbz#556495) - link with libtinfo rather than libncurses, when we can, in future RHEL * Fri Jan 15 2010 Nalin Dahyabhai - 1.7-20 - krb5_get_init_creds_password: check opte->flags instead of options->flags - when checking whether or not we get to use the prompter callback (#555875) + when checking whether or not we get to use the prompter callback (rhbz#555875) * Thu Jan 14 2010 Nalin Dahyabhai - 1.7-19 - use portreserve to make sure the KDC can always bind to the kerberos-iv port, kpropd can always bind to the krb5_prop port, and that kadmind can - always bind to the kerberos-adm port (#555279) + always bind to the kerberos-adm port (rhbz#555279) - correct inadvertent use of macros in the changelog (rpmlint) * Tue Jan 12 2010 Nalin Dahyabhai - 1.7-18 - add upstream patch for integer underflow during AES and RC4 decryption - (CVE-2009-4212), via Tom Yu (#545015) + (CVE-2009-4212), via Tom Yu (rhbz#545015) * Wed Jan 6 2010 Nalin Dahyabhai - 1.7-17 - put the conditional back for the -devel subpackage -- back down to the earlier version of the patch for #551764; the backported +- back down to the earlier version of the patch for rhbz#551764; the backported alternate version was incomplete * Tue Jan 5 2010 Nalin Dahyabhai - 1.7-16 - use %%global instead of %%define - pull up proposed patch for creating previously-not-there lock files for - kdb databases when 'kdb5_util' is called to 'load' (#551764) + kdb databases when 'kdb5_util' is called to 'load' (rhbz#551764) * Mon Jan 4 2010 Dennis Gregorovic - fix conditional for future RHEL * Mon Jan 4 2010 Nalin Dahyabhai - 1.7-15 - add upstream patch for KDC crash during referral processing (CVE-2009-3295), - via Tom Yu (#545002) + via Tom Yu (rhbz#545002) * Mon Dec 21 2009 Nalin Dahyabhai - 1.7-14 -- refresh patch for #542868 from trunk +- refresh patch for rhbz#542868 from trunk * Thu Dec 10 2009 Nalin Dahyabhai - move man pages that live in the -libs subpackage into the regular %%{_mandir} tree where they'll still be found if that package is the - only one installed (#529319) + only one installed (rhbz#529319) * Wed Dec 9 2009 Nalin Dahyabhai - 1.7-13 - and put it back in @@ -3019,14 +3028,14 @@ exit 0 - back that last change out * Tue Dec 8 2009 Nalin Dahyabhai - 1.7-12 -- try to make gss_krb5_copy_ccache() work correctly for spnego (#542868) +- try to make gss_krb5_copy_ccache() work correctly for spnego (rhbz#542868) * Fri Dec 4 2009 Nalin Dahyabhai -- make krb5-config suppress CFLAGS output when called with --libs (#544391) +- make krb5-config suppress CFLAGS output when called with --libs (rhbz#544391) * Thu Dec 3 2009 Nalin Dahyabhai - 1.7-11 - ksu: move account management checks to before we drop privileges, like - su does (#540769) + su does (rhbz#540769) - selinux: set the user part of file creation contexts to match the current context instead of what we looked up - configure with --enable-dns-for-realm instead of --enable-dns, which isn't @@ -3034,7 +3043,7 @@ exit 0 * Fri Nov 20 2009 Nalin Dahyabhai - 1.7-10 - move /etc/pam.d/ksu from krb5-workstation-servers to krb5-workstation, - where it's actually needed (#538703) + where it's actually needed (rhbz#538703) * Fri Oct 23 2009 Nalin Dahyabhai - 1.7-9 - add some conditional logic to simplify building on older Fedora releases @@ -3045,11 +3054,11 @@ exit 0 * Mon Sep 14 2009 Nalin Dahyabhai - 1.7-8 - specify the location of the subsystem lock when using the status() function in the kadmind and kpropd init scripts, so that we get the right error when - we're dead but have a lock file - requires initscripts 8.99 (#521772) + we're dead but have a lock file - requires initscripts 8.99 (rhbz#521772) * Tue Sep 8 2009 Nalin Dahyabhai - if the init script fails to start krb5kdc/kadmind/kpropd because it's already - running (according to status()), return 0 (part of #521772) + running (according to status()), return 0 (part of rhbz#521772) * Mon Aug 24 2009 Nalin Dahyabhai - 1.7-7 - work around a compile problem with new openssl @@ -3108,7 +3117,7 @@ exit 0 - drop static build logic - drop pam_krb5-specific configuration from the default krb5.conf - drop only-use-v5 flags being passed to various things started by xinetd -- put %%{krb5prefix}/sbin in everyone's path, too (#504525) +- put %%{krb5prefix}/sbin in everyone's path, too (rhbz#504525) * Tue May 19 2009 Nalin Dahyabhai 1.6.3-106 - add an auth stack to ksu's PAM configuration so that pam_setcred() calls @@ -3132,7 +3141,7 @@ exit 0 - add LSB-style init script info * Fri Apr 17 2009 Nalin Dahyabhai -- explicitly run the pdf generation script using sh (part of #225974) +- explicitly run the pdf generation script using sh (part of rhbz#225974) * Tue Apr 7 2009 Nalin Dahyabhai 1.6.3-101 - add patches for read overflow and null pointer dereference in the @@ -3148,14 +3157,14 @@ exit 0 - use triggeruns to properly shut down and disable krb524d when -server and -workstation-servers gets upgraded, because it's gone now - move the libraries to /%%{_lib}, but leave --libdir alone so that plugins - get installed and are searched for in the same locations (#473333) + get installed and are searched for in the same locations (rhbz#473333) - clean up buildprereq/prereqs, explicit mktemp requires, and add the - ldconfig for the -server-ldap subpackage (part of #225974) -- escape possible macros in the changelog (part of #225974) -- fixup summary texts (part of #225974) -- take the execute bit off of the protocol docs (part of #225974) -- unflag init scripts as configuration files (part of #225974) -- make the kpropd init script treat 'reload' as 'restart' (part of #225974) + ldconfig for the -server-ldap subpackage (part of rhbz#225974) +- escape possible macros in the changelog (part of rhbz#225974) +- fixup summary texts (part of rhbz#225974) +- take the execute bit off of the protocol docs (part of rhbz#225974) +- unflag init scripts as configuration files (part of rhbz#225974) +- make the kpropd init script treat 'reload' as 'restart' (part of rhbz#225974) * Tue Mar 17 2009 Nalin Dahyabhai 1.6.3-19 - libgssapi_krb5: backport fix for some errors which can occur when @@ -3170,7 +3179,7 @@ exit 0 * Thu Sep 4 2008 Nalin Dahyabhai - if we successfully change the user's password during an attempt to get initial credentials, but then fail to get initial creds from a non-master - using the new password, retry against the master (#432334) + using the new password, retry against the master (rhbz#432334) * Tue Aug 5 2008 Tom "spot" Callaway 1.6.3-16 - fix license tag @@ -3193,7 +3202,7 @@ exit 0 * Wed Apr 16 2008 Nalin Dahyabhai 1.6.3-13 - ftp: use the correct local filename during mget when the 'case' option is - enabled (#442713) + enabled (rhbz#442713) * Fri Apr 4 2008 Nalin Dahyabhai 1.6.3-12 - stop exporting kadmin keys to a keytab file when kadmind starts -- the @@ -3207,17 +3216,17 @@ exit 0 * Tue Mar 18 2008 Nalin Dahyabhai 1.6.3-10 - add fixes from MITKRB5-SA-2008-001 for use of null or dangling pointer when v4 compatibility is enabled on the KDC (CVE-2008-0062, CVE-2008-0063, - #432620, #432621) + rhbz#432620, rhbz#432621) - add fixes from MITKRB5-SA-2008-002 for array out-of-bounds accesses when - high-numbered descriptors are used (CVE-2008-0947, #433596) + high-numbered descriptors are used (CVE-2008-0947, rhbz#433596) - add backport bug fix for an attempt to free non-heap memory in - libgssapi_krb5 (CVE-2007-5901, #415321) + libgssapi_krb5 (CVE-2007-5901, rhbz#415321) - add backport bug fix for a double-free in out-of-memory situations in - libgssapi_krb5 (CVE-2007-5971, #415351) + libgssapi_krb5 (CVE-2007-5971, rhbz#415351) * Tue Mar 18 2008 Nalin Dahyabhai 1.6.3-9 - rework file labeling patch to not depend on fragile preprocessor trickery, - in another attempt at fixing #428355 and friends + in another attempt at fixing rhbz#428355 and friends * Tue Feb 26 2008 Nalin Dahyabhai 1.6.3-8 - ftp: add patch to fix "runique on" case when globbing fixes applied @@ -3225,12 +3234,12 @@ exit 0 * Mon Feb 25 2008 Nalin Dahyabhai - add patch to suppress double-processing of /etc/krb5.conf when we build - with --sysconfdir=/etc, thereby suppressing double-logging (#231147) + with --sysconfdir=/etc, thereby suppressing double-logging (rhbz#231147) * Mon Feb 25 2008 Nalin Dahyabhai - remove a patch, to fix problems with interfaces which are "up" but which have no address assigned, which conflicted with a different fix for the same - problem in 1.5 (#200979) + problem in 1.5 (rhbz#200979) * Mon Feb 25 2008 Nalin Dahyabhai - ftp: don't lose track of a descriptor on passive get when the server fails to @@ -3254,22 +3263,22 @@ exit 0 * Tue Feb 12 2008 Nalin Dahyabhai 1.6.3-5 - enable patch for key-expiration reporting -- enable patch to make kpasswd fall back to TCP if UDP fails (#251206) +- enable patch to make kpasswd fall back to TCP if UDP fails (rhbz#251206) - enable patch to make kpasswd use the right sequence number on retransmit - enable patch to allow mech-specific creds delegated under spnego to be found when searching for creds * Wed Jan 2 2008 Nalin Dahyabhai 1.6.3-4 - some init script cleanups - - drop unquoted check and silent exit for "$NETWORKING" (#426852, #242502) + - drop unquoted check and silent exit for "$NETWORKING" (rhbz#426852, rhbz#242502) - krb524: don't barf on missing database if it looks like we're using kldap, same as for kadmin - return non-zero status for missing files which cause startup to - fail (#242502) + fail (rhbz#242502) * Tue Dec 18 2007 Nalin Dahyabhai 1.6.3-3 - allocate space for the nul-terminator in the local pathname when looking up - a file context, and properly free a previous context (Jose Plans, #426085) + a file context, and properly free a previous context (Jose Plans, rhbz#426085) * Wed Dec 5 2007 Nalin Dahyabhai 1.6.3-2 - rebuild @@ -3285,7 +3294,7 @@ exit 0 * Fri Oct 12 2007 Nalin Dahyabhai - make krb5.conf %%verify(not md5 size mtime) in addition to - %%config(noreplace), like /etc/nsswitch.conf (#329811) + %%config(noreplace), like /etc/nsswitch.conf (rhbz#329811) * Mon Oct 1 2007 Nalin Dahyabhai 1.6.2-9 - apply the fix for CVE-2007-4000 instead of the experimental patch for @@ -3302,7 +3311,7 @@ exit 0 * Thu Sep 6 2007 Nalin Dahyabhai 1.6.2-6 - incorporate updated fix for CVE-2007-3999 (CVE-2007-4743) -- fix incorrect call to "test" in the kadmin init script (#252322,#287291) +- fix incorrect call to "test" in the kadmin init script (rhbz#252322,rhbz#287291) * Tue Sep 4 2007 Nalin Dahyabhai 1.6.2-5 - incorporate fixes for MITKRB5-SA-2007-006 (CVE-2007-3999, CVE-2007-4000) @@ -3315,7 +3324,7 @@ exit 0 - rebuild * Thu Jul 26 2007 Nalin Dahyabhai 1.6.2-2 -- kdc.conf: default to listening for TCP clients, too (#248415) +- kdc.conf: default to listening for TCP clients, too (rhbz#248415) * Thu Jul 19 2007 Nalin Dahyabhai 1.6.2-1 - update to 1.6.2 @@ -3341,13 +3350,13 @@ exit 0 - rebuild * Sun Jun 24 2007 Nalin Dahyabhai 1.6.1-3 -- label all files at creation-time according to the SELinux policy (#228157) +- label all files at creation-time according to the SELinux policy (rhbz#228157) * Fri Jun 22 2007 Nalin Dahyabhai -- perform PAM account / session management in krshd (#182195,#195922) +- perform PAM account / session management in krshd (rhbz#182195,rhbz#195922) - perform PAM authentication and account / session management in ftpd - perform PAM authentication, account / session management, and password- - changing in login.krb5 (#182195,#195922) + changing in login.krb5 (rhbz#182195,rhbz#195922) * Fri Jun 22 2007 Nalin Dahyabhai - preprocess kerberos.ldif into a format FDS will like better, and include @@ -3357,7 +3366,7 @@ exit 0 - switch man pages to being generated with the right paths in them - drop old, incomplete SELinux patch - add patch from Greg Hudson to make srvtab routines report missing-file errors - at same point that keytab routines do (#241805) + at same point that keytab routines do (rhbz#241805) * Thu May 24 2007 Nalin Dahyabhai 1.6.1-2 - pull patch from svn to undo unintentional chattiness in ftp @@ -3378,7 +3387,7 @@ exit 0 * Wed May 16 2007 Nalin Dahyabhai 1.6-6 - omit dependent libraries from the krb5-config --libs output, as using shared libraries (no more static libraries) makes them unnecessary and - they're not part of the libkrb5 interface (patch by Rex Dieter, #240220) + they're not part of the libkrb5 interface (patch by Rex Dieter, rhbz#240220) (strips out libkeyutils, libresolv, libdl) * Fri May 4 2007 Nalin Dahyabhai 1.6-5 @@ -3393,17 +3402,17 @@ exit 0 * Fri Apr 13 2007 Nalin Dahyabhai - move the default acl_file, dict_file, and admin_keytab settings to the part of the default/example kdc.conf where they'll actually have - an effect (#236417) + an effect (rhbz#236417) * Thu Apr 5 2007 Nalin Dahyabhai 1.5-24 - merge security fixes from RHSA-2007:0095 * Tue Apr 3 2007 Nalin Dahyabhai 1.6-3 - add patch to correct unauthorized access via krb5-aware telnet - daemon (#229782, CVE-2007-0956) + daemon (rhbz#229782, CVE-2007-0956) - add patch to fix buffer overflow in krb5kdc and kadmind - (#231528, CVE-2007-0957) -- add patch to fix double-free in kadmind (#231537, CVE-2007-1216) + (rhbz#231528, CVE-2007-0957) +- add patch to fix double-free in kadmind (rhbz#231537, CVE-2007-1216) * Thu Mar 22 2007 Nalin Dahyabhai - back out buildrequires: keyutils-libs-devel for now @@ -3419,19 +3428,19 @@ exit 0 * Thu Mar 15 2007 Nalin Dahyabhai 1.5-21 - add preliminary patch to fix buffer overflow in krb5kdc and kadmind - (#231528, CVE-2007-0957) -- add preliminary patch to fix double-free in kadmind (#231537, CVE-2007-1216) + (rhbz#231528, CVE-2007-0957) +- add preliminary patch to fix double-free in kadmind (rhbz#231537, CVE-2007-1216) * Wed Feb 28 2007 Nalin Dahyabhai - add patch to build semi-useful static libraries, but don't apply it unless we need them * Tue Feb 27 2007 Nalin Dahyabhai - 1.5-20 -- temporarily back out %%post changes, fix for #143289 for security update +- temporarily back out %%post changes, fix for rhbz#143289 for security update - add preliminary patch to correct unauthorized access via krb5-aware telnet * Mon Feb 19 2007 Nalin Dahyabhai -- make profile.d scriptlets mode 644 instead of 755 (part of #225974) +- make profile.d scriptlets mode 644 instead of 755 (part of rhbz#225974) * Tue Jan 30 2007 Nalin Dahyabhai 1.6-1 - clean up quoting of command-line arguments passed to the krsh/krlogin @@ -3439,22 +3448,22 @@ exit 0 * Mon Jan 22 2007 Nalin Dahyabhai - initial update to 1.6, pre-package-reorg -- move workstation daemons to a new subpackage (#81836, #216356, #217301), and - make the new subpackage require xinetd (#211885) +- move workstation daemons to a new subpackage (rhbz#81836, rhbz#216356, rhbz#217301), and + make the new subpackage require xinetd (rhbz#211885) * Mon Jan 22 2007 Nalin Dahyabhai - 1.5-18 -- make use of install-info more failsafe (Ville Skyttä, #223704) +- make use of install-info more failsafe (Ville Skyttä, rhbz#223704) - preserve timestamps on shell scriptlets at %%install-time * Tue Jan 16 2007 Nalin Dahyabhai - 1.5-17 -- move to using pregenerated PDF docs to cure multilib conflicts (#222721) +- move to using pregenerated PDF docs to cure multilib conflicts (rhbz#222721) * Fri Jan 12 2007 Nalin Dahyabhai - 1.5-16 -- update backport of the preauth module interface (part of #194654) +- update backport of the preauth module interface (part of rhbz#194654) * Tue Jan 9 2007 Nalin Dahyabhai - 1.5-14 -- apply fixes from Tom Yu for MITKRB5-SA-2006-002 (CVE-2006-6143) (#218456) -- apply fixes from Tom Yu for MITKRB5-SA-2006-003 (CVE-2006-6144) (#218456) +- apply fixes from Tom Yu for MITKRB5-SA-2006-002 (CVE-2006-6143) (rhbz#218456) +- apply fixes from Tom Yu for MITKRB5-SA-2006-003 (CVE-2006-6144) (rhbz#218456) * Wed Dec 20 2006 Nalin Dahyabhai - 1.5-12 - update backport of the preauth module interface @@ -3472,21 +3481,21 @@ exit 0 been applicable for a while * Wed Oct 18 2006 Nalin Dahyabhai - 1.5-10 -- rename krb5.sh and krb5.csh so that they don't overlap (#210623) -- way-late application of added error info in kadmind.init (#65853) +- rename krb5.sh and krb5.csh so that they don't overlap (rhbz#210623) +- way-late application of added error info in kadmind.init (rhbz#65853) * Wed Oct 18 2006 Nalin Dahyabhai - 1.5-9.pal_18695 -- add backport of in-development preauth module interface (#208643) +- add backport of in-development preauth module interface (rhbz#208643) * Mon Oct 9 2006 Nalin Dahyabhai - 1.5-9 -- provide docs in PDF format instead of as tex source (Enrico Scholz, #209943) +- provide docs in PDF format instead of as tex source (Enrico Scholz, rhbz#209943) * Wed Oct 4 2006 Nalin Dahyabhai - 1.5-8 -- add missing shebang headers to krsh and krlogin wrapper scripts (#209238) +- add missing shebang headers to krsh and krlogin wrapper scripts (rhbz#209238) * Wed Sep 6 2006 Nalin Dahyabhai - 1.5-7 - set SS_LIB at configure-time so that libss-using apps get working readline - support (#197044) + support (rhbz#197044) * Fri Aug 18 2006 Nalin Dahyabhai - 1.5-6 - switch to the updated patch for MITKRB-SA-2006-001 @@ -3497,7 +3506,7 @@ exit 0 * Mon Aug 7 2006 Nalin Dahyabhai - 1.5-4 - ensure that the gssapi library's been initialized before walking the internal mechanism list in gss_release_oid(), needed if called from - gss_release_name() right after a gss_import_name() (#198092) + gss_release_name() right after a gss_import_name() (rhbz#198092) * Tue Jul 25 2006 Nalin Dahyabhai - 1.5-3 - rebuild @@ -3518,7 +3527,7 @@ exit 0 - update to 1.5 * Fri Jun 23 2006 Nalin Dahyabhai 1.4.3-9 -- mark profile.d config files noreplace (Laurent Rineau, #196447) +- mark profile.d config files noreplace (Laurent Rineau, rhbz#196447) * Thu Jun 8 2006 Nalin Dahyabhai 1.4.3-8 - add buildprereq for autoconf @@ -3526,11 +3535,11 @@ exit 0 * Mon May 22 2006 Nalin Dahyabhai 1.4.3-7 - further munge krb5-config so that 'libdir=/usr/lib' is given even on 64-bit architectures, to avoid multilib conflicts; other changes will conspire to - strip out the -L flag which uses this, so it should be harmless (#192692) + strip out the -L flag which uses this, so it should be harmless (rhbz#192692) * Fri Apr 28 2006 Nalin Dahyabhai 1.4.3-6 - adjust the patch which removes the use of rpath to also produce a - krb5-config which is okay in multilib environments (#190118) + krb5-config which is okay in multilib environments (rhbz#190118) - make the name-of-the-tempfile comment which compile_et adds to error code headers always list the same file to avoid conflicts on multilib installations - strip SIZEOF_LONG out of krb5.h so that it doesn't conflict on multilib boxes @@ -3545,7 +3554,7 @@ exit 0 * Mon Feb 6 2006 Nalin Dahyabhai 1.4.3-4 - give a little bit more information to the user when kinit gets the catch-all - I/O error (#180175) + I/O error (rhbz#180175) * Thu Jan 19 2006 Nalin Dahyabhai 1.4.3-3 - rebuild properly when pthread_mutexattr_setrobust_np() is defined but not @@ -3559,23 +3568,23 @@ exit 0 * Thu Dec 1 2005 Nalin Dahyabhai - login: don't truncate passwords before passing them into crypt(), in - case they're significant (#149476) + case they're significant (rhbz#149476) * Thu Nov 17 2005 Nalin Dahyabhai 1.4.3-1 - update to 1.4.3 -- make ksu setuid again (#137934, others) +- make ksu setuid again (rhbz#137934, others) * Tue Sep 13 2005 Nalin Dahyabhai 1.4.2-4 - mark %%{krb5prefix}/man so that files which are packaged within it are - flagged as %%doc (#168163) + flagged as %%doc (rhbz#168163) * Tue Sep 6 2005 Nalin Dahyabhai 1.4.2-3 - add an xinetd configuration file for encryption-only telnetd, parallelling - the kshell/ekshell pair (#167535) + the kshell/ekshell pair (rhbz#167535) * Wed Aug 31 2005 Nalin Dahyabhai 1.4.2-2 - change the default configured encryption type for KDC databases to the - compiled-in default of des3-hmac-sha1 (#57847) + compiled-in default of des3-hmac-sha1 (rhbz#57847) * Thu Aug 11 2005 Nalin Dahyabhai 1.4.2-1 - update to 1.4.2, incorporating the fixes for MIT-KRB5-SA-2005-002 and @@ -3586,23 +3595,23 @@ exit 0 * Wed Jun 29 2005 Nalin Dahyabhai 1.4.1-5 - fix telnet client environment variable disclosure the same way NetKit's - telnet client did (CAN-2005-0488) (#159305) + telnet client did (CAN-2005-0488) (rhbz#159305) - keep apps which call krb5_principal_compare() or krb5_realm_compare() with malformed or NULL principal structures from crashing outright (Thomas Biege) - (#161475) + (rhbz#161475) * Tue Jun 28 2005 Nalin Dahyabhai - apply fixes from draft of MIT-KRB5-SA-2005-002 (CAN-2005-1174,CAN-2005-1175) - (#157104) -- apply fixes from draft of MIT-KRB5-SA-2005-003 (CAN-2005-1689) (#159755) + (rhbz#157104) +- apply fixes from draft of MIT-KRB5-SA-2005-003 (CAN-2005-1689) (rhbz#159755) * Fri Jun 24 2005 Nalin Dahyabhai 1.4.1-4 - fix double-close in keytab handling -- add port of fixes for CAN-2004-0175 to krb5-aware rcp (#151612) +- add port of fixes for CAN-2004-0175 to krb5-aware rcp (rhbz#151612) * Fri May 13 2005 Nalin Dahyabhai 1.4.1-3 - prevent spurious EBADF in krshd when stdin is closed by the client while - the command is running (#151111) + the command is running (rhbz#151111) * Fri May 13 2005 Martin Stransky 1.4.1-2 - add deadlock patch, removed old patch @@ -3661,18 +3670,18 @@ exit 0 - rebuild * Mon Nov 22 2004 Nalin Dahyabhai 1.3.5-3 -- fix predictable-tempfile-name bug in krb5-send-pr (CAN-2004-0971, #140036) +- fix predictable-tempfile-name bug in krb5-send-pr (CAN-2004-0971, rhbz#140036) * Tue Nov 16 2004 Nalin Dahyabhai - silence compiler warning in kprop by using an in-memory ccache with a fixed name instead of an on-disk ccache with a name generated by tmpnam() * Tue Nov 16 2004 Nalin Dahyabhai 1.3.5-2 -- fix globbing patch port mode (#139075) +- fix globbing patch port mode (rhbz#139075) * Mon Nov 1 2004 Nalin Dahyabhai 1.3.5-1 - fix segfault in telnet due to incorrect checking of gethostbyname_r result - codes (#129059) + codes (rhbz#129059) * Fri Oct 15 2004 Nalin Dahyabhai - remove rc4-hmac:norealm and rc4-hmac:onlyrealm from the default list of @@ -3697,11 +3706,11 @@ exit 0 * Mon Aug 23 2004 Nalin Dahyabhai 1.3.4-3 - incorporate fixes from Tom Yu for CAN-2004-0642, CAN-2004-0772 - (MITKRB5-SA-2004-002, #130732) -- incorporate fixes from Tom Yu for CAN-2004-0644 (MITKRB5-SA-2004-003, #130732) + (MITKRB5-SA-2004-002, rhbz#130732) +- incorporate fixes from Tom Yu for CAN-2004-0644 (MITKRB5-SA-2004-003, rhbz#130732) * Tue Jul 27 2004 Nalin Dahyabhai 1.3.4-2 -- fix indexing error in server sorting patch (#127336) +- fix indexing error in server sorting patch (rhbz#127336) * Tue Jun 15 2004 Elliot Lee - rebuilt @@ -3726,7 +3735,7 @@ exit 0 - rebuild * Tue Jun 1 2004 Nalin Dahyabhai 1.3.3-4 -- apply patch from MITKRB5-SA-2004-001 (#125001) +- apply patch from MITKRB5-SA-2004-001 (rhbz#125001) * Wed May 12 2004 Thomas Woerner 1.3.3-3 - removed rpath @@ -3756,17 +3765,17 @@ exit 0 * Mon Feb 2 2004 Nalin Dahyabhai 1.3.1-9 - remove patch to set TERM in klogind which, combined with the upstream fix in - 1.3.1, actually produces the bug now (#114762) + 1.3.1, actually produces the bug now (rhbz#114762) * Mon Jan 19 2004 Nalin Dahyabhai 1.3.1-8 - when iterating over lists of interfaces which are "up" from getifaddrs(), - skip over those which have no address (#113347) + skip over those which have no address (rhbz#113347) * Mon Jan 12 2004 Nalin Dahyabhai - prefer the kdc which last replied to a request when sending requests to kdcs * Mon Nov 24 2003 Nalin Dahyabhai 1.3.1-7 -- fix combination of --with-netlib and --enable-dns (#82176) +- fix combination of --with-netlib and --enable-dns (rhbz#82176) * Tue Nov 18 2003 Nalin Dahyabhai - remove libdefault ticket_lifetime option from the default krb5.conf, it is @@ -3975,12 +3984,12 @@ exit 0 * Wed Jun 27 2001 Nalin Dahyabhai - add patch to support "ANY" keytab type (i.e., "default_keytab_name = ANY:FILE:/etc/krb5.keytab,SRVTAB:/etc/srvtab" - patch from Gerald Britton, #42551) -- build with -D_FILE_OFFSET_BITS=64 to get large file I/O in ftpd (#30697) + patch from Gerald Britton, rhbz#42551) +- build with -D_FILE_OFFSET_BITS=64 to get large file I/O in ftpd (rhbz#30697) - patch ftpd to use long long and %%lld format specifiers to support the SIZE - command on large files (also #30697) -- don't use LOG_AUTH as an option value when calling openlog() in ksu (#45965) -- implement reload in krb5kdc and kadmind init scripts (#41911) + command on large files (also rhbz#30697) +- don't use LOG_AUTH as an option value when calling openlog() in ksu (rhbz#45965) +- implement reload in krb5kdc and kadmind init scripts (rhbz#41911) - lose the krb5server init script (not using it any more) * Sun Jun 24 2001 Elliot Lee @@ -3993,7 +4002,7 @@ exit 0 - rebuild in new environment * Thu Apr 26 2001 Nalin Dahyabhai -- add patch from Tom Yu to fix ftpd overflows (#37731) +- add patch from Tom Yu to fix ftpd overflows (rhbz#37731) * Wed Apr 18 2001 Than Ngo - disable optimizations on the alpha again @@ -4017,7 +4026,7 @@ exit 0 - own %%{_var}/kerberos * Tue Feb 6 2001 Nalin Dahyabhai -- own the directories which are created for each package (#26342) +- own the directories which are created for each package (rhbz#26342) * Tue Jan 23 2001 Nalin Dahyabhai - gettextize init scripts @@ -4027,7 +4036,7 @@ exit 0 - re-enable optimization on alphas * Mon Jan 15 2001 Nalin Dahyabhai -- fix krb5-send-pr (#18932) and move it from -server to -workstation +- fix krb5-send-pr (rhbz#18932) and move it from -server to -workstation - buildprereq libtermcap-devel - temporariliy disable optimization on alphas - gettextize init scripts @@ -4039,29 +4048,29 @@ exit 0 - rebuild in new environment * Tue Oct 31 2000 Nalin Dahyabhai -- add bison as a BuildPrereq (#20091) +- add bison as a BuildPrereq (rhbz#20091) * Mon Oct 30 2000 Nalin Dahyabhai -- change /usr/dict/words to /usr/share/dict/words in default kdc.conf (#20000) +- change /usr/dict/words to /usr/share/dict/words in default kdc.conf (rhbz#20000) * Thu Oct 5 2000 Nalin Dahyabhai - apply kpasswd bug fixes from David Wragg * Wed Oct 4 2000 Nalin Dahyabhai -- make krb5-libs obsolete the old krb5-configs package (#18351) +- make krb5-libs obsolete the old krb5-configs package (rhbz#18351) - don't quit from the kpropd init script if there's no principal database so that you can propagate the first time without running kpropd manually - don't complain if /etc/ld.so.conf doesn't exist in the -libs %%post * Tue Sep 12 2000 Nalin Dahyabhai - fix credential forwarding problem in klogind (goof in KRB5CCNAME handling) - (#11588) -- fix heap corruption bug in FTP client (#14301) + (rhbz#11588) +- fix heap corruption bug in FTP client (rhbz#14301) * Wed Aug 16 2000 Nalin Dahyabhai - fix summaries and descriptions - switched the default transfer protocol from PORT to PASV as proposed on - bugzilla (#16134), and to match the regular ftp package's behavior + bugzilla (rhbz#16134), and to match the regular ftp package's behavior * Wed Jul 19 2000 Jeff Johnson - rebuild to compress man pages. @@ -4137,7 +4146,7 @@ exit 0 * Sat Jun 3 2000 Nalin Dahyabhai - use %%{_infodir} to better comply with FHS - move .so files to -devel subpackage -- tweak xinetd config files (bugs #11833, #11835, #11836, #11840) +- tweak xinetd config files (bugs rhbz#11833, rhbz#11835, rhbz#11836, rhbz#11840) - fix package descriptions again * Wed May 24 2000 Nalin Dahyabhai @@ -4174,7 +4183,7 @@ exit 0 - fix configure stuff for ia64 * Mon Apr 10 2000 Nalin Dahyabhai -- add LDCOMBINE=-lc to configure invocation to use libc versioning (bug #10653) +- add LDCOMBINE=-lc to configure invocation to use libc versioning (rhbz#10653) - change Requires: for/in subpackages to include %%{version} * Wed Apr 05 2000 Nalin Dahyabhai diff --git a/sources b/sources index d6c0df1..58dc8d0 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.21.tar.gz) = 8ee2366888f6d553a44fc642a89c69a57dbc1ec4c89a36b9ba8b00584a9a32c73a2b0566ba5f21852ad9617046666c276dac402393bf8eb19fbe0c07a838071a -SHA512 (krb5-1.21.tar.gz.asc) = 7147a44a13f4f26c5c1d9aba738b32892b50e351ad149dcaf0b6f2c010e3c51d7d51540d0a51b085450ffa31d5027b5f2e5841109d7af8bdaddbdd3a569582d5 +SHA512 (krb5-1.21.2.tar.gz) = 4e09296b412383d53872661718dbfaa90201e0d85f69db48e57a8d4bd73c95a90c7ec7b6f0f325f6bc967f8d203b256b071c0191facf080aca0e2caec5d0ac49 +SHA512 (krb5-1.21.2.tar.gz.asc) = 1cee1ed77047067d7b6fb3620ffa6f5807d4182ae7cfeec6d5cc847c99f30c6dd2a5c1a160d992a13eb6d84754b202895a982111618711f3c14f4aa33c07d9e9 From 0fe5c327ec4da592663de48b995b58c7796f1c55 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Tue, 10 Oct 2023 17:18:32 +0200 Subject: [PATCH 288/304] Fix memory leaks and use SPDX license expression - Use SPDX expression for license tag - Fix unimportant memory leaks Resolves: rhbz#2223274 Signed-off-by: Julien Rische --- 0016-Fix-unimportant-memory-leaks.patch | 2334 +++++++++++++++++++++++ krb5.spec | 10 +- 2 files changed, 2342 insertions(+), 2 deletions(-) create mode 100644 0016-Fix-unimportant-memory-leaks.patch diff --git a/0016-Fix-unimportant-memory-leaks.patch b/0016-Fix-unimportant-memory-leaks.patch new file mode 100644 index 0000000..3406316 --- /dev/null +++ b/0016-Fix-unimportant-memory-leaks.patch @@ -0,0 +1,2334 @@ +From f0414954d79283075d1f627dbb9fe6e4f43c1aae Mon Sep 17 00:00:00 2001 +From: Steve Grubb +Date: Thu, 13 Jul 2023 16:22:30 -0400 +Subject: [PATCH] Fix unimportant memory leaks + +Eliminate memory leaks detected through static analysis and manual +review. These leaks are unlikely to happen repeatedly in long-running +processes. + +[jrische@redhat.com: fixed many additional leaks] +[ghudson@mit.edu: fixed additional leaks; edited for style; removed +some unused ksu functions; rewrote commit message] + +(cherry picked from commit 6c5471176f5266564fbc8a7e02f03b4b042202f8) +--- + src/appl/gss-sample/gss-client.c | 367 ++++++++---------- + src/appl/gss-sample/gss-server.c | 3 +- + src/clients/klist/klist.c | 59 +-- + src/clients/ksu/authorization.c | 140 +++---- + src/clients/ksu/ccache.c | 289 +++++--------- + src/clients/ksu/heuristic.c | 128 +++--- + src/clients/ksu/krb_auth_su.c | 137 ++----- + src/clients/ksu/ksu.h | 6 - + src/clients/ksu/main.c | 3 +- + src/kadmin/cli/keytab.c | 6 +- + src/kadmin/ktutil/ktutil.c | 1 + + src/kprop/kpropd.c | 21 +- + src/lib/gssapi/krb5/export_cred.c | 4 +- + src/lib/gssapi/krb5/val_cred.c | 6 +- + src/lib/kadm5/srv/server_kdb.c | 7 +- + src/lib/krb5/ccache/cc_kcm.c | 4 + + src/lib/krb5/ccache/ccfns.c | 12 +- + src/lib/krb5/keytab/kt_file.c | 3 +- + src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c | 8 +- + 19 files changed, 520 insertions(+), 684 deletions(-) + +diff --git a/src/appl/gss-sample/gss-client.c b/src/appl/gss-sample/gss-client.c +index 6e2aa33690..cf94623d63 100644 +--- a/src/appl/gss-sample/gss-client.c ++++ b/src/appl/gss-sample/gss-client.c +@@ -182,180 +182,148 @@ client_establish_context(int s, char *service_name, OM_uint32 gss_flags, + char *username, char *password, + gss_ctx_id_t *gss_context, OM_uint32 *ret_flags) + { +- if (auth_flag) { +- gss_buffer_desc send_tok, recv_tok, *token_ptr; +- gss_name_t target_name; +- OM_uint32 maj_stat, min_stat, init_sec_min_stat; +- int token_flags; +- gss_cred_id_t cred = GSS_C_NO_CREDENTIAL; +- gss_name_t gss_username = GSS_C_NO_NAME; +- gss_OID_set_desc mechs, *mechsp = GSS_C_NO_OID_SET; +- +- if (spnego) { +- mechs.elements = &gss_spnego_mechanism_oid_desc; +- mechs.count = 1; +- mechsp = &mechs; +- } else if (oid != GSS_C_NO_OID) { +- mechs.elements = oid; +- mechs.count = 1; +- mechsp = &mechs; +- } else { +- mechs.elements = NULL; +- mechs.count = 0; +- } ++ int result = -1, st; ++ gss_buffer_desc send_tok, recv_tok, pwbuf, *token_ptr; ++ gss_name_t target_name = GSS_C_NO_NAME, gss_username = GSS_C_NO_NAME; ++ OM_uint32 maj_stat, min_stat, init_sec_min_stat; ++ int token_flags; ++ gss_cred_id_t cred = GSS_C_NO_CREDENTIAL; ++ gss_OID_set_desc mechs, neg_mechs, *mechsp = GSS_C_NO_OID_SET; ++ ++ if (!auth_flag) ++ return send_token(s, TOKEN_NOOP, empty_token); ++ ++ if (spnego) { ++ mechs.elements = &gss_spnego_mechanism_oid_desc; ++ mechs.count = 1; ++ mechsp = &mechs; ++ } else if (oid != GSS_C_NO_OID) { ++ mechs.elements = oid; ++ mechs.count = 1; ++ mechsp = &mechs; ++ } else { ++ mechs.elements = NULL; ++ mechs.count = 0; ++ } + +- if (username != NULL) { +- send_tok.value = username; +- send_tok.length = strlen(username); ++ if (username != NULL) { ++ send_tok.value = username; ++ send_tok.length = strlen(username); + +- maj_stat = gss_import_name(&min_stat, &send_tok, +- (gss_OID) gss_nt_user_name, +- &gss_username); +- if (maj_stat != GSS_S_COMPLETE) { +- display_status("parsing client name", maj_stat, min_stat); +- return -1; +- } +- } +- +- if (password != NULL) { +- gss_buffer_desc pwbuf; +- +- pwbuf.value = password; +- pwbuf.length = strlen(password); +- +- maj_stat = gss_acquire_cred_with_password(&min_stat, +- gss_username, +- &pwbuf, 0, +- mechsp, GSS_C_INITIATE, +- &cred, NULL, NULL); +- } else if (gss_username != GSS_C_NO_NAME) { +- maj_stat = gss_acquire_cred(&min_stat, +- gss_username, 0, +- mechsp, GSS_C_INITIATE, +- &cred, NULL, NULL); +- } else +- maj_stat = GSS_S_COMPLETE; ++ maj_stat = gss_import_name(&min_stat, &send_tok, ++ (gss_OID) gss_nt_user_name, &gss_username); + if (maj_stat != GSS_S_COMPLETE) { +- display_status("acquiring creds", maj_stat, min_stat); +- gss_release_name(&min_stat, &gss_username); +- return -1; ++ display_status("parsing client name", maj_stat, min_stat); ++ goto cleanup; + } +- if (spnego && oid != GSS_C_NO_OID) { +- gss_OID_set_desc neg_mechs; +- +- neg_mechs.elements = oid; +- neg_mechs.count = 1; ++ } + +- maj_stat = gss_set_neg_mechs(&min_stat, cred, &neg_mechs); +- if (maj_stat != GSS_S_COMPLETE) { +- display_status("setting neg mechs", maj_stat, min_stat); +- gss_release_name(&min_stat, &gss_username); +- gss_release_cred(&min_stat, &cred); +- return -1; +- } +- } +- gss_release_name(&min_stat, &gss_username); +- +- /* +- * Import the name into target_name. Use send_tok to save +- * local variable space. +- */ +- send_tok.value = service_name; +- send_tok.length = strlen(service_name); +- maj_stat = gss_import_name(&min_stat, &send_tok, +- (gss_OID) gss_nt_service_name, +- &target_name); ++ if (password != NULL) { ++ pwbuf.value = password; ++ pwbuf.length = strlen(password); ++ ++ maj_stat = gss_acquire_cred_with_password(&min_stat, gss_username, ++ &pwbuf, 0, mechsp, ++ GSS_C_INITIATE, &cred, NULL, ++ NULL); ++ } else if (gss_username != GSS_C_NO_NAME) { ++ maj_stat = gss_acquire_cred(&min_stat, gss_username, 0, mechsp, ++ GSS_C_INITIATE, &cred, NULL, NULL); ++ } else { ++ maj_stat = GSS_S_COMPLETE; ++ } ++ if (maj_stat != GSS_S_COMPLETE) { ++ display_status("acquiring creds", maj_stat, min_stat); ++ goto cleanup; ++ } ++ if (spnego && oid != GSS_C_NO_OID) { ++ neg_mechs.elements = oid; ++ neg_mechs.count = 1; ++ maj_stat = gss_set_neg_mechs(&min_stat, cred, &neg_mechs); + if (maj_stat != GSS_S_COMPLETE) { +- display_status("parsing name", maj_stat, min_stat); +- return -1; ++ display_status("setting neg mechs", maj_stat, min_stat); ++ goto cleanup; + } ++ } + +- if (!v1_format) { +- if (send_token(s, TOKEN_NOOP | TOKEN_CONTEXT_NEXT, empty_token) < +- 0) { +- (void) gss_release_name(&min_stat, &target_name); +- return -1; +- } +- } ++ /* Import the name into target_name. Use send_tok to save local variable ++ * space. */ ++ send_tok.value = service_name; ++ send_tok.length = strlen(service_name); ++ maj_stat = gss_import_name(&min_stat, &send_tok, ++ (gss_OID) gss_nt_service_name, &target_name); ++ if (maj_stat != GSS_S_COMPLETE) { ++ display_status("parsing name", maj_stat, min_stat); ++ goto cleanup; ++ } + +- /* +- * Perform the context-establishement loop. +- * +- * On each pass through the loop, token_ptr points to the token +- * to send to the server (or GSS_C_NO_BUFFER on the first pass). +- * Every generated token is stored in send_tok which is then +- * transmitted to the server; every received token is stored in +- * recv_tok, which token_ptr is then set to, to be processed by +- * the next call to gss_init_sec_context. +- * +- * GSS-API guarantees that send_tok's length will be non-zero +- * if and only if the server is expecting another token from us, +- * and that gss_init_sec_context returns GSS_S_CONTINUE_NEEDED if +- * and only if the server has another token to send us. +- */ +- +- token_ptr = GSS_C_NO_BUFFER; +- *gss_context = GSS_C_NO_CONTEXT; +- +- do { +- maj_stat = gss_init_sec_context(&init_sec_min_stat, +- cred, gss_context, +- target_name, mechs.elements, +- gss_flags, 0, +- NULL, /* channel bindings */ +- token_ptr, NULL, /* mech type */ +- &send_tok, ret_flags, +- NULL); /* time_rec */ +- +- if (token_ptr != GSS_C_NO_BUFFER) +- free(recv_tok.value); +- +- if (send_tok.length != 0) { +- if (verbose) +- printf("Sending init_sec_context token (size=%d)...", +- (int) send_tok.length); +- if (send_token(s, v1_format ? 0 : TOKEN_CONTEXT, &send_tok) < +- 0) { +- (void) gss_release_buffer(&min_stat, &send_tok); +- (void) gss_release_name(&min_stat, &target_name); +- return -1; +- } ++ if (!v1_format) { ++ if (send_token(s, TOKEN_NOOP | TOKEN_CONTEXT_NEXT, empty_token) < 0) ++ goto cleanup; ++ } ++ ++ /* ++ * Perform the context-establishment loop. ++ * ++ * On each pass through the loop, token_ptr points to the token to send to ++ * the server (or GSS_C_NO_BUFFER on the first pass). Every generated ++ * token is stored in send_tok which is then transmitted to the server; ++ * every received token is stored in recv_tok, which token_ptr is then set ++ * to, to be processed by the next call to gss_init_sec_context. ++ * ++ * GSS-API guarantees that send_tok's length will be non-zero if and only ++ * if the server is expecting another token from us, and that ++ * gss_init_sec_context returns GSS_S_CONTINUE_NEEDED if and only if the ++ * server has another token to send us. ++ */ ++ ++ token_ptr = GSS_C_NO_BUFFER; ++ *gss_context = GSS_C_NO_CONTEXT; ++ ++ do { ++ maj_stat = gss_init_sec_context(&init_sec_min_stat, cred, gss_context, ++ target_name, mechs.elements, gss_flags, ++ 0, NULL, token_ptr, NULL, &send_tok, ++ ret_flags, NULL); ++ ++ if (token_ptr != GSS_C_NO_BUFFER) ++ free(recv_tok.value); ++ ++ if (send_tok.length > 0) { ++ if (verbose) { ++ printf("Sending init_sec_context token (size=%d)...", ++ (int) send_tok.length); + } ++ st = send_token(s, v1_format ? 0 : TOKEN_CONTEXT, &send_tok); + (void) gss_release_buffer(&min_stat, &send_tok); ++ if (st < 0) ++ goto cleanup; ++ } + +- if (maj_stat != GSS_S_COMPLETE +- && maj_stat != GSS_S_CONTINUE_NEEDED) { +- display_status("initializing context", maj_stat, +- init_sec_min_stat); +- (void) gss_release_name(&min_stat, &target_name); +- (void) gss_release_cred(&min_stat, &cred); +- if (*gss_context != GSS_C_NO_CONTEXT) +- gss_delete_sec_context(&min_stat, gss_context, +- GSS_C_NO_BUFFER); +- return -1; +- } ++ if (maj_stat != GSS_S_COMPLETE && maj_stat != GSS_S_CONTINUE_NEEDED) { ++ display_status("initializing context", maj_stat, ++ init_sec_min_stat); ++ goto cleanup; ++ } + +- if (maj_stat == GSS_S_CONTINUE_NEEDED) { +- if (verbose) +- printf("continue needed..."); +- if (recv_token(s, &token_flags, &recv_tok) < 0) { +- (void) gss_release_name(&min_stat, &target_name); +- return -1; +- } +- token_ptr = &recv_tok; +- } ++ if (maj_stat == GSS_S_CONTINUE_NEEDED) { + if (verbose) +- printf("\n"); +- } while (maj_stat == GSS_S_CONTINUE_NEEDED); ++ printf("continue needed..."); ++ if (recv_token(s, &token_flags, &recv_tok) < 0) ++ goto cleanup; ++ token_ptr = &recv_tok; ++ } ++ if (verbose) ++ printf("\n"); ++ } while (maj_stat == GSS_S_CONTINUE_NEEDED); + +- (void) gss_release_cred(&min_stat, &cred); +- (void) gss_release_name(&min_stat, &target_name); +- } else { +- if (send_token(s, TOKEN_NOOP, empty_token) < 0) +- return -1; +- } ++ result = 0; + +- return 0; ++cleanup: ++ (void) gss_release_name(&min_stat, &gss_username); ++ (void) gss_release_cred(&min_stat, &cred); ++ (void) gss_release_name(&min_stat, &target_name); ++ return result; + } + + static void +@@ -449,11 +417,11 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, + { + gss_ctx_id_t context = GSS_C_NO_CONTEXT; + gss_buffer_desc in_buf, out_buf; +- int s, state; ++ int s = -1, result = -1, state; + OM_uint32 ret_flags; + OM_uint32 maj_stat, min_stat; +- gss_name_t src_name, targ_name; +- gss_buffer_desc sname, tname; ++ gss_name_t src_name = GSS_C_NO_NAME, targ_name = GSS_C_NO_NAME; ++ gss_buffer_desc sname = GSS_C_EMPTY_BUFFER, tname = GSS_C_EMPTY_BUFFER; + OM_uint32 lifetime; + gss_OID mechanism, name_type; + int is_local; +@@ -467,14 +435,13 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, + + /* Open connection */ + if ((s = connect_to_server(host, port)) < 0) +- return -1; ++ goto cleanup; + + /* Establish context */ + if (client_establish_context(s, service_name, gss_flags, auth_flag, + v1_format, oid, username, password, + &context, &ret_flags) < 0) { +- (void) closesocket(s); +- return -1; ++ goto cleanup; + } + + if (auth_flag && verbose) { +@@ -488,19 +455,19 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, + &is_local, &is_open); + if (maj_stat != GSS_S_COMPLETE) { + display_status("inquiring context", maj_stat, min_stat); +- return -1; ++ goto cleanup; + } + + maj_stat = gss_display_name(&min_stat, src_name, &sname, &name_type); + if (maj_stat != GSS_S_COMPLETE) { + display_status("displaying source name", maj_stat, min_stat); +- return -1; ++ goto cleanup; + } + maj_stat = gss_display_name(&min_stat, targ_name, &tname, + (gss_OID *) NULL); + if (maj_stat != GSS_S_COMPLETE) { + display_status("displaying target name", maj_stat, min_stat); +- return -1; ++ goto cleanup; + } + printf("\"%.*s\" to \"%.*s\", lifetime %d, flags %x, %s, %s\n", + (int) sname.length, (char *) sname.value, +@@ -509,15 +476,10 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, + (is_local) ? "locally initiated" : "remotely initiated", + (is_open) ? "open" : "closed"); + +- (void) gss_release_name(&min_stat, &src_name); +- (void) gss_release_name(&min_stat, &targ_name); +- (void) gss_release_buffer(&min_stat, &sname); +- (void) gss_release_buffer(&min_stat, &tname); +- + maj_stat = gss_oid_to_str(&min_stat, name_type, &oid_name); + if (maj_stat != GSS_S_COMPLETE) { + display_status("converting oid->string", maj_stat, min_stat); +- return -1; ++ goto cleanup; + } + printf("Name type of source name is %.*s.\n", + (int) oid_name.length, (char *) oid_name.value); +@@ -528,13 +490,13 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, + mechanism, &mech_names); + if (maj_stat != GSS_S_COMPLETE) { + display_status("inquiring mech names", maj_stat, min_stat); +- return -1; ++ goto cleanup; + } + + maj_stat = gss_oid_to_str(&min_stat, mechanism, &oid_name); + if (maj_stat != GSS_S_COMPLETE) { + display_status("converting oid->string", maj_stat, min_stat); +- return -1; ++ goto cleanup; + } + printf("Mechanism %.*s supports %d names\n", + (int) oid_name.length, (char *) oid_name.value, +@@ -546,7 +508,7 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, + &mech_names->elements[i], &oid_name); + if (maj_stat != GSS_S_COMPLETE) { + display_status("converting oid->string", maj_stat, min_stat); +- return -1; ++ goto cleanup; + } + printf(" %d: %.*s\n", (int) i, + (int) oid_name.length, (char *) oid_name.value); +@@ -571,10 +533,7 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, + &in_buf, &state, &out_buf); + if (maj_stat != GSS_S_COMPLETE) { + display_status("wrapping message", maj_stat, min_stat); +- (void) closesocket(s); +- (void) gss_delete_sec_context(&min_stat, &context, +- GSS_C_NO_BUFFER); +- return -1; ++ goto cleanup; + } else if (encrypt_flag && !state) { + fprintf(stderr, "Warning! Message not encrypted.\n"); + } +@@ -588,22 +547,15 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, + (wrap_flag ? TOKEN_WRAPPED : 0) | + (encrypt_flag ? TOKEN_ENCRYPTED : 0) | + (mic_flag ? TOKEN_SEND_MIC : 0))), +- &out_buf) < 0) { +- (void) closesocket(s); +- (void) gss_delete_sec_context(&min_stat, &context, +- GSS_C_NO_BUFFER); +- return -1; +- } ++ &out_buf) < 0) ++ goto cleanup; ++ + if (out_buf.value != in_buf.value) + (void) gss_release_buffer(&min_stat, &out_buf); + + /* Read signature block into out_buf */ +- if (recv_token(s, &token_flags, &out_buf) < 0) { +- (void) closesocket(s); +- (void) gss_delete_sec_context(&min_stat, &context, +- GSS_C_NO_BUFFER); +- return -1; +- } ++ if (recv_token(s, &token_flags, &out_buf) < 0) ++ goto cleanup; + + if (mic_flag) { + /* Verify signature block */ +@@ -611,10 +563,7 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, + &out_buf, &qop_state); + if (maj_stat != GSS_S_COMPLETE) { + display_status("verifying signature", maj_stat, min_stat); +- (void) closesocket(s); +- (void) gss_delete_sec_context(&min_stat, &context, +- GSS_C_NO_BUFFER); +- return -1; ++ goto cleanup; + } + + if (verbose) +@@ -634,23 +583,17 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, + if (!v1_format) + (void) send_token(s, TOKEN_NOOP, empty_token); + +- if (auth_flag) { +- /* Delete context */ +- maj_stat = gss_delete_sec_context(&min_stat, &context, &out_buf); +- if (maj_stat != GSS_S_COMPLETE) { +- display_status("deleting context", maj_stat, min_stat); +- (void) closesocket(s); +- (void) gss_delete_sec_context(&min_stat, &context, +- GSS_C_NO_BUFFER); +- return -1; +- } +- +- (void) gss_release_buffer(&min_stat, &out_buf); +- } +- +- (void) closesocket(s); ++ result = 0; + +- return 0; ++cleanup: ++ (void) gss_release_name(&min_stat, &src_name); ++ (void) gss_release_name(&min_stat, &targ_name); ++ (void) gss_release_buffer(&min_stat, &sname); ++ (void) gss_release_buffer(&min_stat, &tname); ++ (void) gss_delete_sec_context(&min_stat, &context, GSS_C_NO_BUFFER); ++ if (s >= 0) ++ (void) closesocket(s); ++ return result; + } + + static void +diff --git a/src/appl/gss-sample/gss-server.c b/src/appl/gss-sample/gss-server.c +index 9b6ce9ffb3..ce25df8b40 100644 +--- a/src/appl/gss-sample/gss-server.c ++++ b/src/appl/gss-sample/gss-server.c +@@ -138,13 +138,12 @@ server_acquire_creds(char *service_name, gss_OID mech, + } + maj_stat = gss_acquire_cred(&min_stat, server_name, 0, mechs, GSS_C_ACCEPT, + server_creds, NULL, NULL); ++ (void) gss_release_name(&min_stat, &server_name); + if (maj_stat != GSS_S_COMPLETE) { + display_status("acquiring credentials", maj_stat, min_stat); + return -1; + } + +- (void) gss_release_name(&min_stat, &server_name); +- + return 0; + } + +diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c +index dcdc5a2d59..43392d2337 100644 +--- a/src/clients/klist/klist.c ++++ b/src/clients/klist/klist.c +@@ -469,20 +469,21 @@ do_ccache() + static int + show_ccache(krb5_ccache cache) + { +- krb5_cc_cursor cur; ++ krb5_cc_cursor cur = NULL; + krb5_creds creds; +- krb5_principal princ; ++ krb5_principal princ = NULL; + krb5_error_code ret; ++ int status = 1; + + ret = krb5_cc_get_principal(context, cache, &princ); + if (ret) { + com_err(progname, ret, ""); +- return 1; ++ goto cleanup; + } + ret = krb5_unparse_name(context, princ, &defname); + if (ret) { + com_err(progname, ret, _("while unparsing principal name")); +- return 1; ++ goto cleanup; + } + + printf(_("Ticket cache: %s:%s\nDefault principal: %s\n\n"), +@@ -498,27 +499,33 @@ show_ccache(krb5_ccache cache) + ret = krb5_cc_start_seq_get(context, cache, &cur); + if (ret) { + com_err(progname, ret, _("while starting to retrieve tickets")); +- return 1; ++ goto cleanup; + } + while ((ret = krb5_cc_next_cred(context, cache, &cur, &creds)) == 0) { + if (show_config || !krb5_is_config_principal(context, creds.server)) + show_credential(&creds); + krb5_free_cred_contents(context, &creds); + } +- krb5_free_principal(context, princ); +- krb5_free_unparsed_name(context, defname); +- defname = NULL; + if (ret == KRB5_CC_END) { + ret = krb5_cc_end_seq_get(context, cache, &cur); ++ cur = NULL; + if (ret) { + com_err(progname, ret, _("while finishing ticket retrieval")); +- return 1; ++ goto cleanup; + } +- return 0; + } else { + com_err(progname, ret, _("while retrieving a ticket")); +- return 1; ++ goto cleanup; + } ++ ++ status = 0; ++ ++cleanup: ++ if (cur != NULL) ++ (void)krb5_cc_end_seq_get(context, cache, &cur); ++ krb5_free_principal(context, princ); ++ krb5_free_unparsed_name(context, defname); ++ return status; + } + + /* Return 0 if cache is accessible, present, and unexpired; return 1 if not. */ +@@ -526,15 +533,18 @@ static int + check_ccache(krb5_ccache cache) + { + krb5_error_code ret; +- krb5_cc_cursor cur; ++ krb5_cc_cursor cur = NULL; + krb5_creds creds; +- krb5_principal princ; +- krb5_boolean found_tgt, found_current_tgt, found_current_cred; ++ krb5_principal princ = NULL; ++ krb5_boolean found_tgt = FALSE, found_current_tgt = FALSE; ++ krb5_boolean found_current_cred = FALSE; + +- if (krb5_cc_get_principal(context, cache, &princ) != 0) +- return 1; +- if (krb5_cc_start_seq_get(context, cache, &cur) != 0) +- return 1; ++ ret = krb5_cc_get_principal(context, cache, &princ); ++ if (ret) ++ goto cleanup; ++ ret = krb5_cc_start_seq_get(context, cache, &cur); ++ if (ret) ++ goto cleanup; + found_tgt = found_current_tgt = found_current_cred = FALSE; + while ((ret = krb5_cc_next_cred(context, cache, &cur, &creds)) == 0) { + if (is_local_tgt(creds.server, &princ->realm)) { +@@ -547,12 +557,17 @@ check_ccache(krb5_ccache cache) + } + krb5_free_cred_contents(context, &creds); + } +- krb5_free_principal(context, princ); + if (ret != KRB5_CC_END) +- return 1; +- if (krb5_cc_end_seq_get(context, cache, &cur) != 0) +- return 1; ++ goto cleanup; ++ ret = krb5_cc_end_seq_get(context, cache, &cur); ++ cur = NULL; + ++cleanup: ++ if (cur != NULL) ++ (void)krb5_cc_end_seq_get(context, cache, &cur); ++ krb5_free_principal(context, princ); ++ if (ret) ++ return 1; + /* If the cache contains at least one local TGT, require that it be + * current. Otherwise accept any current cred. */ + if (found_tgt) +diff --git a/src/clients/ksu/authorization.c b/src/clients/ksu/authorization.c +index fb9d5d0942..6c6a2d007e 100644 +--- a/src/clients/ksu/authorization.c ++++ b/src/clients/ksu/authorization.c +@@ -28,7 +28,17 @@ + + #include "ksu.h" + +-static void auth_cleanup (FILE *, FILE *, char *); ++static void ++free_fcmd_list(char **list) ++{ ++ size_t i; ++ ++ if (list == NULL) ++ return; ++ for (i = 0; i < MAX_CMD && list[i] != NULL; i++) ++ free(list[i]); ++ free(list); ++} + + krb5_boolean fowner(fp, uid) + FILE *fp; +@@ -53,10 +63,10 @@ krb5_boolean fowner(fp, uid) + + /* + * Given a Kerberos principal "principal", and a local username "luser", +- * determine whether user is authorized to login according to the +- * authorization files ~luser/.k5login" and ~luser/.k5users. Returns TRUE +- * if authorized, FALSE if not authorized. +- * ++ * determine whether user is authorized to login according to the authorization ++ * files ~luser/.k5login" and ~luser/.k5users. Set *ok to TRUE if authorized, ++ * FALSE if not authorized. Return 0 if the authorization check succeeded ++ * (regardless of its result), non-zero if it encountered an error. + */ + + krb5_error_code krb5_authorization(context, principal, luser, +@@ -71,7 +81,7 @@ krb5_error_code krb5_authorization(context, principal, luser, + char **out_fcmd; + { + struct passwd *pwd; +- char *princname; ++ char *princname = NULL; + int k5login_flag =0; + int k5users_flag =0; + krb5_boolean retbool =FALSE; +@@ -83,7 +93,7 @@ krb5_error_code krb5_authorization(context, principal, luser, + + /* no account => no access */ + if ((pwd = getpwnam(luser)) == NULL) +- return 0; ++ goto cleanup; + + retval = krb5_unparse_name(context, principal, &princname); + if (retval) +@@ -100,22 +110,19 @@ krb5_error_code krb5_authorization(context, principal, luser, + + /* k5login and k5users must be owned by target user or root */ + if (!k5login_flag){ +- if ((login_fp = fopen(k5login_path, "r")) == NULL) +- return 0; +- if ( fowner(login_fp, pwd->pw_uid) == FALSE) { +- fclose(login_fp); +- return 0; +- } ++ login_fp = fopen(k5login_path, "r"); ++ if (login_fp == NULL) ++ goto cleanup; ++ if (fowner(login_fp, pwd->pw_uid) == FALSE) ++ goto cleanup; + } + + if (!k5users_flag){ +- if ((users_fp = fopen(k5users_path, "r")) == NULL) { +- return 0; +- } +- if ( fowner(users_fp, pwd->pw_uid) == FALSE){ +- fclose(users_fp); +- return 0; +- } ++ users_fp = fopen(k5users_path, "r"); ++ if (users_fp == NULL) ++ goto cleanup; ++ if (fowner(users_fp, pwd->pw_uid) == FALSE) ++ goto cleanup; + } + + if (auth_debug){ +@@ -134,10 +141,8 @@ krb5_error_code krb5_authorization(context, principal, luser, + princname); + + retval = k5login_lookup(login_fp, princname, &retbool); +- if (retval) { +- auth_cleanup(users_fp, login_fp, princname); +- return retval; +- } ++ if (retval) ++ goto cleanup; + if (retbool) { + if (cmd) + *out_fcmd = xstrdup(cmd); +@@ -147,10 +152,8 @@ krb5_error_code krb5_authorization(context, principal, luser, + if ((!k5users_flag) && (retbool == FALSE) ){ + retval = k5users_lookup (users_fp, princname, + cmd, &retbool, out_fcmd); +- if(retval) { +- auth_cleanup(users_fp, login_fp, princname); +- return retval; +- } ++ if (retval) ++ goto cleanup; + } + + if (k5login_flag && k5users_flag){ +@@ -166,8 +169,14 @@ krb5_error_code krb5_authorization(context, principal, luser, + } + + *ok =retbool; +- auth_cleanup(users_fp, login_fp, princname); +- return 0; ++ ++cleanup: ++ if (users_fp != NULL) ++ fclose(users_fp); ++ if (login_fp != NULL) ++ fclose(login_fp); ++ free(princname); ++ return retval; + } + + /*********************************************************** +@@ -334,10 +343,11 @@ krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) + char **out_err; + { + char * err; +- char ** tmp_fcmd; ++ char ** tmp_fcmd = NULL; + char * path_ptr, *path; + char * lp, * tc; + int i=0; ++ krb5_boolean ok = FALSE; + + tmp_fcmd = (char **) xcalloc (MAX_CMD, sizeof(char *)); + +@@ -345,7 +355,7 @@ krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) + tmp_fcmd[0] = xstrdup(fcmd); + tmp_fcmd[1] = NULL; + *out_fcmd = tmp_fcmd; +- return TRUE; ++ tmp_fcmd = NULL; + }else{ + /* must be either full path or just the cmd name */ + if (strchr(fcmd, '/')){ +@@ -353,7 +363,7 @@ krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) + "either full path or just the cmd name\n"), + fcmd, KRB5_USERS_NAME); + *out_err = err; +- return FALSE; ++ goto cleanup; + } + + #ifndef CMD_PATH +@@ -361,7 +371,7 @@ krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) + "the cmd name, CMD_PATH must be defined \n"), + fcmd, KRB5_USERS_NAME, fcmd); + *out_err = err; +- return FALSE; ++ goto cleanup; + #else + + path = xstrdup (CMD_PATH); +@@ -375,7 +385,7 @@ krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) + asprintf(&err, _("Error: bad entry - %s in %s file, CMD_PATH " + "contains no paths \n"), fcmd, KRB5_USERS_NAME); + *out_err = err; +- return FALSE; ++ goto cleanup; + } + + i=0; +@@ -384,7 +394,7 @@ krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) + asprintf(&err, _("Error: bad path %s in CMD_PATH for %s must " + "start with '/' \n"), tc, KRB5_USERS_NAME ); + *out_err = err; +- return FALSE; ++ goto cleanup; + } + + tmp_fcmd[i] = xasprintf("%s/%s", tc, fcmd); +@@ -395,10 +405,15 @@ krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) + + tmp_fcmd[i] = NULL; + *out_fcmd = tmp_fcmd; +- return TRUE; +- ++ tmp_fcmd = NULL; + #endif /* CMD_PATH */ + } ++ ++ ok = TRUE; ++ ++cleanup: ++ free_fcmd_list(tmp_fcmd); ++ return ok; + } + + /******************************************** +@@ -524,41 +539,42 @@ int match_commands (fcmd, cmd, match, cmd_out, err_out) + char **cmd_out; + char **err_out; + { +- char ** fcmd_arr; ++ char ** fcmd_arr = NULL; + char * err; + char * cmd_temp; ++ int result = 1; + + if(fcmd_resolve(fcmd, &fcmd_arr, &err )== FALSE ){ + *err_out = err; +- return 1; ++ goto cleanup; + } + + if (cmd_single( cmd ) == TRUE){ + if (!cmd_arr_cmp_postfix(fcmd_arr, cmd)){ /* found */ +- +- if(find_first_cmd_that_exists( fcmd_arr,&cmd_temp,&err)== TRUE){ +- *match = TRUE; +- *cmd_out = cmd_temp; +- return 0; +- }else{ ++ if (!find_first_cmd_that_exists(fcmd_arr, &cmd_temp, &err)) { + *err_out = err; +- return 1; ++ goto cleanup; + } +- }else{ ++ ++ *match = TRUE; ++ *cmd_out = cmd_temp; ++ } else { + *match = FALSE; +- return 0; + } + }else{ + if (!cmd_arr_cmp(fcmd_arr, cmd)){ /* found */ + *match = TRUE; + *cmd_out = xstrdup(cmd); +- return 0; + } else{ + *match = FALSE; +- return 0; + } + } + ++ result = 0; ++ ++cleanup: ++ free_fcmd_list(fcmd_arr); ++ return result; + } + + /********************************************************* +@@ -587,10 +603,7 @@ krb5_error_code get_line (fp, out_line) + } + else { + chunk_count ++; +- if(!( line = (char *) realloc( line, +- chunk_count * sizeof(char) * BUFSIZ))){ +- return ENOMEM; +- } ++ line = xrealloc(line, chunk_count * BUFSIZ); + + line_ptr = line + (BUFSIZ -1) *( chunk_count -1) ; + } +@@ -677,21 +690,8 @@ char * get_next_token (lnext) + return out_ptr; + } + +-static void auth_cleanup(users_fp, login_fp, princname) +- FILE *users_fp; +- FILE *login_fp; +- char *princname; +-{ +- +- free (princname); +- if (users_fp) +- fclose(users_fp); +- if (login_fp) +- fclose(login_fp); +-} +- +-void init_auth_names(pw_dir) +- char *pw_dir; ++void ++init_auth_names(char *pw_dir) + { + const char *sep; + int r1, r2; +diff --git a/src/clients/ksu/ccache.c b/src/clients/ksu/ccache.c +index cbb9aa2b85..45667dd24a 100644 +--- a/src/clients/ksu/ccache.c ++++ b/src/clients/ksu/ccache.c +@@ -40,7 +40,19 @@ copies the default cache into the secondary cache, + + ************************************************************************/ + +-void show_credential(); ++static void ++free_creds_list(krb5_context context, krb5_creds **list) ++{ ++ size_t i; ++ ++ if (list == NULL) ++ return; ++ for (i = 0; list[i]; i++) ++ krb5_free_creds(context, list[i]); ++ free(list); ++} ++ ++void show_credential(krb5_context, krb5_creds *, krb5_ccache); + + /* modifies only the cc_other, the algorithm may look a bit funny, + but I had to do it this way, since remove function did not come +@@ -59,20 +71,19 @@ krb5_error_code krb5_ccache_copy(context, cc_def, target_principal, cc_target, + /* OUT */ + krb5_boolean *stored; + { +- int i=0; + krb5_error_code retval=0; + krb5_creds ** cc_def_creds_arr = NULL; + krb5_creds ** cc_other_creds_arr = NULL; + + if (ks_ccache_is_initialized(context, cc_def)) { +- if((retval = krb5_get_nonexp_tkts(context,cc_def,&cc_def_creds_arr))){ +- return retval; +- } ++ retval = krb5_get_nonexp_tkts(context, cc_def, &cc_def_creds_arr); ++ if (retval) ++ goto cleanup; + } + + retval = krb5_cc_initialize(context, cc_target, target_principal); + if (retval) +- return retval; ++ goto cleanup; + + if (restrict_creds) { + retval = krb5_store_some_creds(context, cc_target, cc_def_creds_arr, +@@ -85,22 +96,9 @@ krb5_error_code krb5_ccache_copy(context, cc_def, target_principal, cc_target, + cc_other_creds_arr); + } + +- if (cc_def_creds_arr){ +- while (cc_def_creds_arr[i]){ +- krb5_free_creds(context, cc_def_creds_arr[i]); +- i++; +- } +- } +- +- i=0; +- +- if(cc_other_creds_arr){ +- while (cc_other_creds_arr[i]){ +- krb5_free_creds(context, cc_other_creds_arr[i]); +- i++; +- } +- } +- ++cleanup: ++ free_creds_list(context, cc_def_creds_arr); ++ free_creds_list(context, cc_other_creds_arr); + return retval; + } + +@@ -198,32 +196,29 @@ krb5_error_code krb5_get_nonexp_tkts(context, cc, creds_array) + { + + krb5_creds creds, temp_tktq, temp_tkt; +- krb5_creds **temp_creds; ++ krb5_creds **temp_creds = NULL; + krb5_error_code retval=0; + krb5_cc_cursor cur; + int count = 0; + int chunk_count = 1; + +- if ( ! ( temp_creds = (krb5_creds **) malloc( CHUNK * sizeof(krb5_creds *)))){ +- return ENOMEM; +- } +- +- ++ temp_creds = xcalloc(CHUNK, sizeof(*temp_creds)); + memset(&temp_tktq, 0, sizeof(temp_tktq)); + memset(&temp_tkt, 0, sizeof(temp_tkt)); + memset(&creds, 0, sizeof(creds)); + + /* initialize the cursor */ +- if ((retval = krb5_cc_start_seq_get(context, cc, &cur))) { +- return retval; +- } ++ retval = krb5_cc_start_seq_get(context, cc, &cur); ++ if (retval) ++ goto cleanup; + + while (!(retval = krb5_cc_next_cred(context, cc, &cur, &creds))){ + + if (!krb5_is_config_principal(context, creds.server) && + (retval = krb5_check_exp(context, creds.times))){ ++ krb5_free_cred_contents(context, &creds); + if (retval != KRB5KRB_AP_ERR_TKT_EXPIRED){ +- return retval; ++ goto cleanup; + } + if (auth_debug){ + fprintf(stderr,"krb5_ccache_copy: CREDS EXPIRED:\n"); +@@ -233,19 +228,19 @@ krb5_error_code krb5_get_nonexp_tkts(context, cc, creds_array) + } + } + else { /* these credentials didn't expire */ +- +- if ((retval = krb5_copy_creds(context, &creds, +- &temp_creds[count]))){ +- return retval; +- } ++ retval = krb5_copy_creds(context, &creds, &temp_creds[count]); ++ krb5_free_cred_contents(context, &creds); ++ temp_creds[count+1] = NULL; ++ if (retval) ++ goto cleanup; + count ++; + + if (count == (chunk_count * CHUNK -1)){ + chunk_count ++; +- if (!(temp_creds = (krb5_creds **) realloc(temp_creds, +- chunk_count * CHUNK * sizeof(krb5_creds *)))){ +- return ENOMEM; +- } ++ ++ temp_creds = xrealloc(temp_creds, ++ chunk_count * CHUNK * ++ sizeof(*temp_creds)); + } + } + +@@ -253,13 +248,15 @@ krb5_error_code krb5_get_nonexp_tkts(context, cc, creds_array) + + temp_creds[count] = NULL; + *creds_array = temp_creds; ++ temp_creds = NULL; + + if (retval == KRB5_CC_END) { + retval = krb5_cc_end_seq_get(context, cc, &cur); + } + ++cleanup: ++ free_creds_list(context, temp_creds); + return retval; +- + } + + +@@ -331,97 +328,6 @@ void printtime(krb5_timestamp ts) + printf("%s", fmtbuf); + } + +- +-krb5_error_code +-krb5_get_login_princ(luser, princ_list) +- const char *luser; +- char ***princ_list; +-{ +- struct stat sbuf; +- struct passwd *pwd; +- char pbuf[MAXPATHLEN]; +- FILE *fp; +- char * linebuf; +- char *newline; +- int gobble, result; +- char ** buf_out; +- struct stat st_temp; +- int count = 0, chunk_count = 1; +- +- /* no account => no access */ +- +- if ((pwd = getpwnam(luser)) == NULL) { +- return 0; +- } +- result = snprintf(pbuf, sizeof(pbuf), "%s/.k5login", pwd->pw_dir); +- if (SNPRINTF_OVERFLOW(result, sizeof(pbuf))) { +- fprintf(stderr, _("home directory path for %s too long\n"), luser); +- exit (1); +- } +- +- if (stat(pbuf, &st_temp)) { /* not accessible */ +- return 0; +- } +- +- +- /* open ~/.k5login */ +- if ((fp = fopen(pbuf, "r")) == NULL) { +- return 0; +- } +- /* +- * For security reasons, the .k5login file must be owned either by +- * the user himself, or by root. Otherwise, don't grant access. +- */ +- if (fstat(fileno(fp), &sbuf)) { +- fclose(fp); +- return 0; +- } +- if ((sbuf.st_uid != pwd->pw_uid) && sbuf.st_uid) { +- fclose(fp); +- return 0; +- } +- +- /* check each line */ +- +- +- if( !(linebuf = (char *) calloc (BUFSIZ, sizeof(char)))) return ENOMEM; +- +- if (!(buf_out = (char **) malloc( CHUNK * sizeof(char *)))) return ENOMEM; +- +- while ( fgets(linebuf, BUFSIZ, fp) != NULL) { +- /* null-terminate the input string */ +- linebuf[BUFSIZ-1] = '\0'; +- newline = NULL; +- /* nuke the newline if it exists */ +- if ((newline = strchr(linebuf, '\n'))) +- *newline = '\0'; +- +- buf_out[count] = linebuf; +- count ++; +- +- if (count == (chunk_count * CHUNK -1)){ +- chunk_count ++; +- if (!(buf_out = (char **) realloc(buf_out, +- chunk_count * CHUNK * sizeof(char *)))){ +- return ENOMEM; +- } +- } +- +- /* clean up the rest of the line if necessary */ +- if (!newline) +- while (((gobble = getc(fp)) != EOF) && gobble != '\n'); +- +- if( !(linebuf = (char *) calloc (BUFSIZ, sizeof(char)))) return ENOMEM; +- } +- +- buf_out[count] = NULL; +- *princ_list = buf_out; +- fclose(fp); +- return 0; +-} +- +- +- + void + show_credential(context, cred, cc) + krb5_context context; +@@ -429,31 +335,29 @@ show_credential(context, cred, cc) + krb5_ccache cc; + { + krb5_error_code retval; +- char *name, *sname, *flags; ++ char *name = NULL, *sname = NULL, *defname = NULL, *flags; + int first = 1; +- krb5_principal princ; +- char * defname; ++ krb5_principal princ = NULL; + int show_flags =1; + + retval = krb5_unparse_name(context, cred->client, &name); + if (retval) { + com_err(prog_name, retval, _("while unparsing client name")); +- return; ++ goto cleanup; + } + retval = krb5_unparse_name(context, cred->server, &sname); + if (retval) { + com_err(prog_name, retval, _("while unparsing server name")); +- free(name); +- return; ++ goto cleanup; + } + + if ((retval = krb5_cc_get_principal(context, cc, &princ))) { + com_err(prog_name, retval, _("while retrieving principal name")); +- return; ++ goto cleanup; + } + if ((retval = krb5_unparse_name(context, princ, &defname))) { + com_err(prog_name, retval, _("while unparsing principal name")); +- return; ++ goto cleanup; + } + + if (!cred->times.starttime) +@@ -491,8 +395,12 @@ show_credential(context, cred, cc) + } + } + putchar('\n'); ++ ++cleanup: + free(name); + free(sname); ++ free(defname); ++ krb5_free_principal(context, princ); + } + + /* Create a random string suitable for a filename extension. */ +@@ -526,37 +434,26 @@ krb5_error_code krb5_ccache_overwrite(context, ccs, cct, primary_principal) + krb5_principal primary_principal; + { + krb5_error_code retval=0; +- krb5_principal temp_principal; ++ krb5_principal defprinc = NULL, princ; + krb5_creds ** ccs_creds_arr = NULL; +- int i=0; + + if (ks_ccache_is_initialized(context, ccs)) { +- if ((retval = krb5_get_nonexp_tkts(context, ccs, &ccs_creds_arr))){ +- return retval; +- } ++ retval = krb5_get_nonexp_tkts(context, ccs, &ccs_creds_arr); ++ if (retval) ++ goto cleanup; + } + +- if (ks_ccache_is_initialized(context, cct)) { +- if ((retval = krb5_cc_get_principal(context, cct, &temp_principal))){ +- return retval; +- } +- }else{ +- temp_principal = primary_principal; +- } +- +- if ((retval = krb5_cc_initialize(context, cct, temp_principal))){ +- return retval; +- } ++ retval = krb5_cc_get_principal(context, cct, &defprinc); ++ princ = (retval == 0) ? defprinc : primary_principal; ++ retval = krb5_cc_initialize(context, cct, princ); ++ if (retval) ++ goto cleanup; + + retval = krb5_store_all_creds(context, cct, ccs_creds_arr, NULL); + +- if (ccs_creds_arr){ +- while (ccs_creds_arr[i]){ +- krb5_free_creds(context, ccs_creds_arr[i]); +- i++; +- } +- } +- ++cleanup: ++ free_creds_list(context, ccs_creds_arr); ++ krb5_free_principal(context, defprinc); + return retval; + } + +@@ -616,45 +513,40 @@ krb5_error_code krb5_ccache_filter (context, cc, prst) + krb5_principal prst; + { + +- int i=0; + krb5_error_code retval=0; +- krb5_principal temp_principal; ++ krb5_principal temp_principal = NULL; + krb5_creds ** cc_creds_arr = NULL; + const char * cc_name; + krb5_boolean stored; + +- cc_name = krb5_cc_get_name(context, cc); ++ if (!ks_ccache_is_initialized(context, cc)) ++ return 0; + +- if (ks_ccache_is_initialized(context, cc)) { +- if (auth_debug) { +- fprintf(stderr,"putting cache %s through a filter for -z option\n", cc_name); +- } ++ if (auth_debug) { ++ cc_name = krb5_cc_get_name(context, cc); ++ fprintf(stderr, "putting cache %s through a filter for -z option\n", ++ cc_name); ++ } + +- if ((retval = krb5_get_nonexp_tkts(context, cc, &cc_creds_arr))){ +- return retval; +- } ++ retval = krb5_get_nonexp_tkts(context, cc, &cc_creds_arr); ++ if (retval) ++ goto cleanup; + +- if ((retval = krb5_cc_get_principal(context, cc, &temp_principal))){ +- return retval; +- } ++ retval = krb5_cc_get_principal(context, cc, &temp_principal); ++ if (retval) ++ goto cleanup; + +- if ((retval = krb5_cc_initialize(context, cc, temp_principal))){ +- return retval; +- } ++ retval = krb5_cc_initialize(context, cc, temp_principal); ++ if (retval) ++ goto cleanup; + +- if ((retval = krb5_store_some_creds(context, cc, cc_creds_arr, +- NULL, prst, &stored))){ +- return retval; +- } ++ retval = krb5_store_some_creds(context, cc, cc_creds_arr, NULL, prst, ++ &stored); + +- if (cc_creds_arr){ +- while (cc_creds_arr[i]){ +- krb5_free_creds(context, cc_creds_arr[i]); +- i++; +- } +- } +- } +- return 0; ++cleanup: ++ free_creds_list(context, cc_creds_arr); ++ krb5_free_principal(context, temp_principal); ++ return retval; + } + + krb5_boolean krb5_find_princ_in_cred_list (context, creds_list, princ) +@@ -688,17 +580,20 @@ krb5_error_code krb5_find_princ_in_cache (context, cc, princ, found) + krb5_principal princ; + krb5_boolean *found; + { +- krb5_error_code retval; ++ krb5_error_code retval = 0; + krb5_creds ** creds_list = NULL; + + if (ks_ccache_is_initialized(context, cc)) { +- if ((retval = krb5_get_nonexp_tkts(context, cc, &creds_list))){ +- return retval; +- } ++ retval = krb5_get_nonexp_tkts(context, cc, &creds_list); ++ if (retval) ++ goto cleanup; + } + + *found = krb5_find_princ_in_cred_list(context, creds_list, princ); +- return 0; ++ ++cleanup: ++ free_creds_list(context, creds_list); ++ return retval; + } + + krb5_boolean +diff --git a/src/clients/ksu/heuristic.c b/src/clients/ksu/heuristic.c +index 4f7280f4cb..47baa785e5 100644 +--- a/src/clients/ksu/heuristic.c ++++ b/src/clients/ksu/heuristic.c +@@ -156,28 +156,31 @@ filter(fp, cmd, k5users_list, k5users_filt_list) + + *k5users_filt_list = NULL; + +- if (! k5users_list){ ++ if (k5users_list == NULL) + return 0; +- } + + while(k5users_list[i]){ ++ free(out_cmd); ++ out_cmd = NULL; + + retval= k5users_lookup(fp, k5users_list[i], cmd, &found, &out_cmd); + if (retval) +- return retval; ++ goto cleanup; + + if (found == FALSE){ + free (k5users_list[i]); + k5users_list[i] = NULL; +- if (out_cmd) gb_err = out_cmd; ++ if (out_cmd) { ++ gb_err = out_cmd; ++ out_cmd = NULL; ++ } + } else + found_count ++; + + i++; + } + +- if (! (temp_filt_list = (char **) calloc(found_count +1, sizeof (char*)))) +- return ENOMEM; ++ temp_filt_list = xcalloc(found_count + 1, sizeof(*temp_filt_list)); + + for(j= 0, k=0; j < i; j++ ) { + if (k5users_list[j]){ +@@ -191,7 +194,10 @@ filter(fp, cmd, k5users_list, k5users_filt_list) + free (k5users_list); + + *k5users_filt_list = temp_filt_list; +- return 0; ++ ++cleanup: ++ free(out_cmd); ++ return retval; + } + + krb5_error_code +@@ -335,7 +341,7 @@ krb5_error_code get_closest_principal(context, plist, client, found) + + retval = krb5_parse_name(context, plist[i], &temp_client); + if (retval) +- return retval; ++ goto cleanup; + + pnelem = krb5_princ_size(context, temp_client); + +@@ -363,6 +369,7 @@ krb5_error_code get_closest_principal(context, plist, client, found) + if(best_client){ + if(krb5_princ_size(context, best_client) > + krb5_princ_size(context, temp_client)){ ++ krb5_free_principal(context, best_client); + best_client = temp_client; + } + }else +@@ -375,9 +382,12 @@ krb5_error_code get_closest_principal(context, plist, client, found) + if (best_client) { + *found = TRUE; + *client = best_client; ++ best_client = NULL; + } + +- return 0; ++cleanup: ++ krb5_free_principal(context, best_client); ++ return retval; + } + + /**************************************************************** +@@ -499,6 +509,7 @@ krb5_error_code find_princ_in_list (context, princ, plist, found) + i++; + } + ++ free(princname); + return 0; + + } +@@ -534,11 +545,9 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, + { + + princ_info princ_trials[10]; +- krb5_principal cc_def_princ = NULL; +- krb5_principal temp_client; +- krb5_principal target_client; +- krb5_principal source_client; +- krb5_principal end_server; ++ krb5_principal cc_def_princ = NULL, temp_client = NULL; ++ krb5_principal target_client = NULL, source_client = NULL; ++ krb5_principal end_server = NULL; + krb5_error_code retval; + char ** aplist =NULL; + krb5_boolean found = FALSE; +@@ -555,54 +564,59 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, + if (ks_ccache_is_initialized(context, cc_source)) { + retval = krb5_cc_get_principal(context, cc_source, &cc_def_princ); + if (retval) +- return retval; ++ goto cleanup; + } + + retval=krb5_parse_name(context, target_user, &target_client); + if (retval) +- return retval; ++ goto cleanup; + + retval=krb5_parse_name(context, source_user, &source_client); + if (retval) +- return retval; ++ goto cleanup; + +- if (source_uid == 0){ +- if (target_uid != 0) +- *client = target_client; /* this will be used to restrict +- the cache copty */ +- else { +- if(cc_def_princ) +- *client = cc_def_princ; +- else +- *client = target_client; ++ if (source_uid == 0) { ++ if (target_uid != 0) { ++ /* This will be used to restrict the cache copy. */ ++ *client = target_client; ++ target_client = NULL; ++ } else if (cc_def_princ != NULL) { ++ *client = cc_def_princ; ++ cc_def_princ = NULL; ++ } else { ++ *client = target_client; ++ target_client = NULL; + } +- + if (auth_debug) + printf(" GET_best_princ_for_target: via source_uid == 0\n"); +- +- return 0; ++ goto cleanup; + } + + /* from here on, the code is for source_uid != 0 */ + + if (source_uid && (source_uid == target_uid)){ +- if(cc_def_princ) ++ if (cc_def_princ != NULL) { + *client = cc_def_princ; +- else ++ cc_def_princ = NULL; ++ } else { + *client = target_client; ++ target_client = NULL; ++ } + if (auth_debug) + printf("GET_best_princ_for_target: via source_uid == target_uid\n"); +- return 0; ++ goto cleanup; + } + + /* Become root, then target for looking at .k5login.*/ + if (krb5_seteuid(0) || krb5_seteuid(target_uid) ) { +- return errno; ++ retval = errno; ++ goto cleanup; + } + + /* if .k5users and .k5login do not exist */ + if (stat(k5login_path, &tb) && stat(k5users_path, &tb) ){ + *client = target_client; ++ target_client = NULL; + + if (cmd) + *path_out = NOT_AUTHORIZED; +@@ -610,26 +624,25 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, + if (auth_debug) + printf(" GET_best_princ_for_target: via no auth files path\n"); + +- return 0; ++ goto cleanup; + }else{ + retval = get_authorized_princ_names(target_user, cmd, &aplist); + if (retval) +- return retval; ++ goto cleanup; + + /* .k5users or .k5login exist, but no authorization */ + if ((!aplist) || (!aplist[0])) { + *path_out = NOT_AUTHORIZED; + if (auth_debug) + printf("GET_best_princ_for_target: via empty auth files path\n"); +- return 0; ++ goto cleanup; + } + } + + retval = krb5_sname_to_principal(context, hostname, NULL, + KRB5_NT_SRV_HST, &end_server); + if (retval) +- return retval; +- ++ goto cleanup; + + /* first see if default principal of the source cache + * can get us in, then the target_user@realm, then the +@@ -652,7 +665,7 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, + retval= find_princ_in_list(context, princ_trials[i].p, aplist, + &found); + if (retval) +- return retval; ++ goto cleanup; + + if (found == TRUE){ + princ_trials[i].found = TRUE; +@@ -661,12 +674,13 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, + princ_trials[i].p, + end_server, &found); + if (retval) +- return retval; ++ goto cleanup; + if (found == TRUE){ +- *client = princ_trials[i].p; ++ retval = krb5_copy_principal(context, princ_trials[i].p, ++ client); + if (auth_debug) + printf("GET_best_princ_for_target: via ticket file, choice #%d\n", i); +- return 0; ++ goto cleanup; + } + } + } +@@ -679,21 +693,23 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, + while (aplist[i]){ + retval = krb5_parse_name(context, aplist[i], &temp_client); + if (retval) +- return retval; ++ goto cleanup; + + retval = find_either_ticket (context, cc_source, temp_client, + end_server, &found); + if (retval) +- return retval; ++ goto cleanup; + + if (found == TRUE){ + if (auth_debug) + printf("GET_best_princ_for_target: via ticket file, choice: any ok ticket \n" ); + *client = temp_client; +- return 0; ++ temp_client = NULL; ++ goto cleanup; + } + + krb5_free_principal(context, temp_client); ++ temp_client = NULL; + + i++; + } +@@ -704,11 +720,11 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, + + for (i=0; i < count; i ++){ + if (princ_trials[i].found == TRUE){ +- *client = princ_trials[i].p; ++ retval = krb5_copy_principal(context, princ_trials[i].p, client); + + if (auth_debug) + printf("GET_best_princ_for_target: via prompt passwd list choice #%d \n",i); +- return 0; ++ goto cleanup; + } + } + +@@ -718,7 +734,7 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, + retval=krb5_copy_principal(context, princ_trials[i].p, + &temp_client); + if(retval) +- return retval; ++ goto cleanup; + + /* get the client name that is the closest + to the three princ in trials */ +@@ -726,15 +742,15 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, + retval=get_closest_principal(context, aplist, &temp_client, + &found); + if(retval) +- return retval; ++ goto cleanup; + + if (found == TRUE){ + *client = temp_client; ++ temp_client = NULL; + if (auth_debug) + printf("GET_best_princ_for_target: via prompt passwd list choice: approximation of princ in trials # %d \n",i); +- return 0; ++ goto cleanup; + } +- krb5_free_principal(context, temp_client); + } + } + +@@ -745,5 +761,13 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, + printf( "GET_best_princ_for_target: out of luck, can't get appropriate default principal\n"); + + *path_out = NOT_AUTHORIZED; +- return 0; ++ retval = 0; ++ ++cleanup: ++ krb5_free_principal(context, cc_def_princ); ++ krb5_free_principal(context, target_client); ++ krb5_free_principal(context, source_client); ++ krb5_free_principal(context, temp_client); ++ krb5_free_principal(context, end_server); ++ return retval; + } +diff --git a/src/clients/ksu/krb_auth_su.c b/src/clients/ksu/krb_auth_su.c +index fb848dcab1..a99c4c826c 100644 +--- a/src/clients/ksu/krb_auth_su.c ++++ b/src/clients/ksu/krb_auth_su.c +@@ -42,33 +42,31 @@ krb5_boolean krb5_auth_check(context, client_pname, hostname, options, + krb5_ccache cc; + int *path_passwd; + { +- krb5_principal client; ++ krb5_principal client = NULL; + krb5_verify_init_creds_opt vfy_opts; +- krb5_creds tgt, tgtq; ++ krb5_creds tgt = { 0 }, tgtq = { 0 }; + krb5_error_code retval =0; + int got_it = 0; + krb5_boolean zero_password; ++ krb5_boolean ok = FALSE; + + *path_passwd = 0; +- memset(&tgtq, 0, sizeof(tgtq)); +- memset(&tgt, 0, sizeof(tgt)); + + if ((retval= krb5_copy_principal(context, client_pname, &client))){ + com_err(prog_name, retval, _("while copying client principal")); +- return (FALSE) ; ++ goto cleanup; + } + + if ((retval= krb5_copy_principal(context, client, &tgtq.client))){ + com_err(prog_name, retval, _("while copying client principal")); +- return (FALSE) ; ++ goto cleanup; + } + + if ((retval = ksu_tgtname(context, krb5_princ_realm(context, client), + krb5_princ_realm(context, client), + &tgtq.server))){ + com_err(prog_name, retval, _("while creating tgt for local realm")); +- krb5_free_principal(context, client); +- return (FALSE) ; ++ goto cleanup; + } + + if (auth_debug){ dump_principal(context, "local tgt principal name", tgtq.server ); } +@@ -82,7 +80,7 @@ krb5_boolean krb5_auth_check(context, client_pname, hostname, options, + if ((retval != KRB5_CC_NOTFOUND) && + (retval != KRB5KRB_AP_ERR_TKT_EXPIRED)){ + com_err(prog_name, retval, _("while retrieving creds from cache")); +- return (FALSE) ; ++ goto cleanup; + } + } else{ + got_it = 1; +@@ -93,7 +91,7 @@ krb5_boolean krb5_auth_check(context, client_pname, hostname, options, + #ifdef GET_TGT_VIA_PASSWD + if (krb5_seteuid(0)||krb5_seteuid(target_uid)) { + com_err("ksu", errno, _("while switching to target uid")); +- return FALSE; ++ goto cleanup; + } + + +@@ -107,19 +105,19 @@ krb5_boolean krb5_auth_check(context, client_pname, hostname, options, + &tgt) == FALSE) { + krb5_seteuid(0); + +- return FALSE; ++ goto cleanup; + } + *path_passwd = 1; + if (krb5_seteuid(0)) { + com_err("ksu", errno, _("while reclaiming root uid")); +- return FALSE; ++ goto cleanup; + } + + #else + plain_dump_principal (context, client); + fprintf(stderr, + _("does not have any appropriate tickets in the cache.\n")); +- return FALSE; ++ goto cleanup; + + #endif /* GET_TGT_VIA_PASSWD */ + +@@ -131,10 +129,16 @@ krb5_boolean krb5_auth_check(context, client_pname, hostname, options, + &vfy_opts); + if (retval) { + com_err(prog_name, retval, _("while verifying ticket for server")); +- return (FALSE); ++ goto cleanup; + } + +- return (TRUE); ++ ok = TRUE; ++ ++cleanup: ++ krb5_free_principal(context, client); ++ krb5_free_cred_contents(context, &tgt); ++ krb5_free_cred_contents(context, &tgtq); ++ return ok; + } + + krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, +@@ -145,11 +149,12 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, + krb5_boolean *zero_password; + krb5_creds *creds_out; + { ++ krb5_boolean ok = FALSE; + krb5_error_code code; +- krb5_creds creds; ++ krb5_creds creds = { 0 }; + krb5_timestamp now; + unsigned int pwsize; +- char password[255], *client_name, prompt[255]; ++ char password[255], prompt[255], *client_name = NULL; + int result; + + *zero_password = FALSE; +@@ -158,14 +163,14 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, + + if ((code = krb5_unparse_name(context, client, &client_name))) { + com_err (prog_name, code, _("when unparsing name")); +- return (FALSE); ++ goto cleanup; + } + + memset(&creds, 0, sizeof(creds)); + + if ((code = krb5_timeofday(context, &now))) { + com_err(prog_name, code, _("while getting time of day")); +- return (FALSE); ++ goto cleanup; + } + + result = snprintf(prompt, sizeof(prompt), _("Kerberos password for %s: "), +@@ -174,7 +179,7 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, + fprintf(stderr, + _("principal name %s too long for internal buffer space\n"), + client_name); +- return FALSE; ++ goto cleanup; + } + + pwsize = sizeof(password); +@@ -183,13 +188,13 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, + if (code ) { + com_err(prog_name, code, _("while reading password for '%s'\n"), + client_name); +- return (FALSE); ++ goto cleanup; + } + + if ( pwsize == 0) { + fprintf(stderr, _("No password given\n")); + *zero_password = TRUE; +- return (FALSE); ++ goto cleanup; + } + + code = krb5_get_init_creds_password(context, &creds, client, password, +@@ -203,13 +208,19 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, + fprintf(stderr, _("%s: Password incorrect\n"), prog_name); + else + com_err(prog_name, code, _("while getting initial credentials")); +- return (FALSE); ++ goto cleanup; + } +- if (creds_out != NULL) ++ if (creds_out != NULL) { + *creds_out = creds; +- else +- krb5_free_cred_contents(context, &creds); +- return (TRUE); ++ memset(&creds, 0, sizeof(creds)); ++ } ++ ++ ok = TRUE; ++ ++cleanup: ++ krb5_free_cred_contents(context, &creds); ++ free(client_name); ++ return ok; + } + + +@@ -224,8 +235,10 @@ void dump_principal (context, str, p) + if ((retval = krb5_unparse_name(context, p, &stname))) { + fprintf(stderr, _(" %s while unparsing name\n"), + error_message(retval)); ++ return; + } + fprintf(stderr, " %s: %s\n", str, stname); ++ free(stname); + } + + void plain_dump_principal (context, p) +@@ -238,74 +251,8 @@ void plain_dump_principal (context, p) + if ((retval = krb5_unparse_name(context, p, &stname))) { + fprintf(stderr, _(" %s while unparsing name\n"), + error_message(retval)); ++ return; + } + fprintf(stderr, "%s ", stname); +-} +- +- +-/********************************************************************** +-returns the principal that is closest to client. plist contains +-a principal list obtained from .k5login and parhaps .k5users file. +-This routine gets called before getting the password for a tgt. +-A principal is picked that has the best chance of getting in. +- +-**********************************************************************/ +- +- +-krb5_error_code get_best_principal(context, plist, client) +- krb5_context context; +- char **plist; +- krb5_principal *client; +-{ +- krb5_error_code retval =0; +- krb5_principal temp_client, best_client = NULL; +- +- int i = 0, nelem; +- +- if (! plist ) return 0; +- +- nelem = krb5_princ_size(context, *client); +- +- while(plist[i]){ +- +- if ((retval = krb5_parse_name(context, plist[i], &temp_client))){ +- return retval; +- } +- +- if (data_eq(*krb5_princ_realm(context, *client), +- *krb5_princ_realm(context, temp_client))) { +- +- if (nelem && +- krb5_princ_size(context, *client) > 0 && +- krb5_princ_size(context, temp_client) > 0) { +- krb5_data *p1 = +- krb5_princ_component(context, *client, 0); +- krb5_data *p2 = +- krb5_princ_component(context, temp_client, 0); +- +- if (data_eq(*p1, *p2)) { +- +- if (auth_debug){ +- fprintf(stderr, +- "get_best_principal: compare with %s\n", +- plist[i]); +- } +- +- if(best_client){ +- if(krb5_princ_size(context, best_client) > +- krb5_princ_size(context, temp_client)){ +- best_client = temp_client; +- } +- }else{ +- best_client = temp_client; +- } +- } +- } +- +- } +- i++; +- } +- +- if (best_client) *client = best_client; +- return 0; ++ free(stname); + } +diff --git a/src/clients/ksu/ksu.h b/src/clients/ksu/ksu.h +index 66fb4bcc6a..32ce11cb85 100644 +--- a/src/clients/ksu/ksu.h ++++ b/src/clients/ksu/ksu.h +@@ -92,9 +92,6 @@ extern void plain_dump_principal + extern krb5_error_code krb5_parse_lifetime + (char *, long *); + +-extern krb5_error_code get_best_principal +-(krb5_context, char **, krb5_principal *); +- + /* ccache.c */ + extern krb5_error_code krb5_ccache_copy + (krb5_context, krb5_ccache, krb5_principal, krb5_ccache, +@@ -117,9 +114,6 @@ extern krb5_error_code krb5_check_exp + + extern char *flags_string (krb5_creds *); + +-extern krb5_error_code krb5_get_login_princ +-(const char *, char ***); +- + extern void show_credential + (krb5_context, krb5_creds *, krb5_ccache); + +diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c +index 931f054041..a7cb7ed3be 100644 +--- a/src/clients/ksu/main.c ++++ b/src/clients/ksu/main.c +@@ -1003,7 +1003,7 @@ resolve_target_cache(krb5_context context, krb5_principal princ, + if (retval) { + com_err(prog_name, retval, + _("while generating part of the target ccache name")); +- return retval; ++ goto cleanup; + } + if (asprintf(&ccname, "%s.%s", target, sym) < 0) { + retval = ENOMEM; +@@ -1015,6 +1015,7 @@ resolve_target_cache(krb5_context context, krb5_principal princ, + free(sym); + } while (ks_ccache_name_is_initialized(context, ccname)); + retval = krb5_cc_resolve(context, ccname, &ccache); ++ free(ccname); + } else { + /* Look for a cache in the collection that we can reuse. */ + retval = krb5_cc_cache_match(context, princ, &ccache); +diff --git a/src/kadmin/cli/keytab.c b/src/kadmin/cli/keytab.c +index b0c8378b40..8a59188216 100644 +--- a/src/kadmin/cli/keytab.c ++++ b/src/kadmin/cli/keytab.c +@@ -363,7 +363,7 @@ remove_principal(char *keytab_str, krb5_keytab keytab, + { + krb5_principal princ = NULL; + krb5_keytab_entry entry; +- krb5_kt_cursor cursor; ++ krb5_kt_cursor cursor = NULL; + enum { UNDEF, SPEC, HIGH, ALL, OLD } mode; + int code, did_something; + krb5_kvno kvno; +@@ -443,6 +443,7 @@ remove_principal(char *keytab_str, krb5_keytab keytab, + _("while temporarily ending keytab scan")); + goto cleanup; + } ++ cursor = NULL; + code = krb5_kt_remove_entry(context, keytab, &entry); + if (code != 0) { + com_err(whoami, code, _("while deleting entry from keytab")); +@@ -471,6 +472,7 @@ remove_principal(char *keytab_str, krb5_keytab keytab, + com_err(whoami, code, _("while ending keytab scan")); + goto cleanup; + } ++ cursor = NULL; + + /* + * If !did_someting then mode must be OLD or we would have +@@ -483,6 +485,8 @@ remove_principal(char *keytab_str, krb5_keytab keytab, + } + + cleanup: ++ if (cursor != NULL) ++ (void)krb5_kt_end_seq_get(context, keytab, &cursor); + krb5_free_principal(context, princ); + } + +diff --git a/src/kadmin/ktutil/ktutil.c b/src/kadmin/ktutil/ktutil.c +index 92d7023a4f..782c7289c5 100644 +--- a/src/kadmin/ktutil/ktutil.c ++++ b/src/kadmin/ktutil/ktutil.c +@@ -263,6 +263,7 @@ void ktutil_list(argc, argv) + buf, sizeof(buf)))) { + com_err(argv[0], retval, + _("While converting enctype to string")); ++ free(pname); + return; + } + printf(" (%s) ", buf); +diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c +index cb9785aaeb..286b3a655e 100644 +--- a/src/kprop/kpropd.c ++++ b/src/kprop/kpropd.c +@@ -1300,19 +1300,20 @@ static krb5_boolean + authorized_principal(krb5_context context, krb5_principal p, + krb5_enctype auth_etype) + { +- char *name, *ptr, buf[1024]; ++ krb5_boolean ok = FALSE; ++ char *name = NULL, *ptr, buf[1024]; + krb5_error_code retval; +- FILE *acl_file; ++ FILE *acl_file = NULL; + int end; + krb5_enctype acl_etype; + + retval = krb5_unparse_name(context, p, &name); + if (retval) +- return FALSE; ++ goto cleanup; + + acl_file = fopen(acl_file_name, "r"); + if (acl_file == NULL) +- return FALSE; ++ goto cleanup; + + while (!feof(acl_file)) { + if (!fgets(buf, sizeof(buf), acl_file)) +@@ -1342,14 +1343,16 @@ authorized_principal(krb5_context context, krb5_principal p, + (acl_etype != auth_etype))) + continue; + +- free(name); +- fclose(acl_file); +- return TRUE; ++ ok = TRUE; ++ goto cleanup; + } + } ++ ++cleanup: + free(name); +- fclose(acl_file); +- return FALSE; ++ if (acl_file != NULL) ++ fclose(acl_file); ++ return ok; + } + + static void +diff --git a/src/lib/gssapi/krb5/export_cred.c b/src/lib/gssapi/krb5/export_cred.c +index 96a408c237..bf5cede54a 100644 +--- a/src/lib/gssapi/krb5/export_cred.c ++++ b/src/lib/gssapi/krb5/export_cred.c +@@ -447,8 +447,10 @@ krb5_gss_export_cred(OM_uint32 *minor_status, gss_cred_id_t cred_handle, + + /* Validate and lock cred_handle. */ + status = krb5_gss_validate_cred_1(minor_status, cred_handle, context); +- if (status != GSS_S_COMPLETE) ++ if (status != GSS_S_COMPLETE) { ++ krb5_free_context(context); + return status; ++ } + cred = (krb5_gss_cred_id_t)cred_handle; + + if (json_kgcred(context, cred, &jcred)) +diff --git a/src/lib/gssapi/krb5/val_cred.c b/src/lib/gssapi/krb5/val_cred.c +index cb1cb9393a..87a46cd533 100644 +--- a/src/lib/gssapi/krb5/val_cred.c ++++ b/src/lib/gssapi/krb5/val_cred.c +@@ -35,6 +35,7 @@ krb5_gss_validate_cred_1(OM_uint32 *minor_status, gss_cred_id_t cred_handle, + krb5_gss_cred_id_t cred; + krb5_error_code code; + krb5_principal princ; ++ krb5_boolean same; + + cred = (krb5_gss_cred_id_t) cred_handle; + k5_mutex_lock(&cred->lock); +@@ -45,12 +46,13 @@ krb5_gss_validate_cred_1(OM_uint32 *minor_status, gss_cred_id_t cred_handle, + *minor_status = code; + return(GSS_S_DEFECTIVE_CREDENTIAL); + } +- if (!krb5_principal_compare(context, princ, cred->name->princ)) { ++ same = krb5_principal_compare(context, princ, cred->name->princ); ++ (void)krb5_free_principal(context, princ); ++ if (!same) { + k5_mutex_unlock(&cred->lock); + *minor_status = KG_CCACHE_NOMATCH; + return(GSS_S_DEFECTIVE_CREDENTIAL); + } +- (void)krb5_free_principal(context, princ); + } + *minor_status = 0; + return GSS_S_COMPLETE; +diff --git a/src/lib/kadm5/srv/server_kdb.c b/src/lib/kadm5/srv/server_kdb.c +index 2ec80a0f2b..4efcaf9941 100644 +--- a/src/lib/kadm5/srv/server_kdb.c ++++ b/src/lib/kadm5/srv/server_kdb.c +@@ -67,11 +67,10 @@ krb5_error_code kdb_init_master(kadm5_server_handle_t handle, + if (ret) + goto done; + +- if ((ret = krb5_db_fetch_mkey_list(handle->context, master_princ, +- &master_keyblock))) { ++ ret = krb5_db_fetch_mkey_list(handle->context, master_princ, ++ &master_keyblock); ++ if (ret) + krb5_db_fini(handle->context); +- return (ret); +- } + + done: + if (r == NULL) +diff --git a/src/lib/krb5/ccache/cc_kcm.c b/src/lib/krb5/ccache/cc_kcm.c +index c93e7c78e5..1f917d49bb 100644 +--- a/src/lib/krb5/ccache/cc_kcm.c ++++ b/src/lib/krb5/ccache/cc_kcm.c +@@ -992,10 +992,14 @@ kcm_start_seq_get(krb5_context context, krb5_ccache cache, + if (cursor == NULL) + goto cleanup; + cursor->uuids = uuids; ++ uuids = NULL; + cursor->creds = creds; ++ creds = NULL; + *cursor_out = (krb5_cc_cursor)cursor; + + cleanup: ++ free_cred_list(creds); ++ free_uuid_list(uuids); + kcmreq_free(&req); + return ret; + } +diff --git a/src/lib/krb5/ccache/ccfns.c b/src/lib/krb5/ccache/ccfns.c +index e0eb39a612..9b755f0e36 100644 +--- a/src/lib/krb5/ccache/ccfns.c ++++ b/src/lib/krb5/ccache/ccfns.c +@@ -198,18 +198,18 @@ k5_build_conf_principals(krb5_context context, krb5_ccache id, + if (principal) { + ret = krb5_unparse_name(context, principal, &pname); + if (ret) +- return ret; ++ goto cleanup; + } + + ret = krb5_build_principal(context, &cred->server, + sizeof(conf_realm) - 1, conf_realm, + conf_name, name, pname, (char *)NULL); +- krb5_free_unparsed_name(context, pname); +- if (ret) { +- krb5_free_principal(context, client); +- return ret; +- } ++ if (ret) ++ goto cleanup; + ret = krb5_copy_principal(context, client, &cred->client); ++ ++cleanup: ++ krb5_free_unparsed_name(context, pname); + krb5_free_principal(context, client); + return ret; + } +diff --git a/src/lib/krb5/keytab/kt_file.c b/src/lib/krb5/keytab/kt_file.c +index f3ea28c8ec..8fd1505115 100644 +--- a/src/lib/krb5/keytab/kt_file.c ++++ b/src/lib/krb5/keytab/kt_file.c +@@ -456,15 +456,16 @@ krb5_ktfile_start_seq_get(krb5_context context, krb5_keytab id, krb5_kt_cursor * + return ENOMEM; + } + *fileoff = KTSTARTOFF(id); +- *cursorp = (krb5_kt_cursor)fileoff; + KTITERS(id)++; + if (KTITERS(id) == 0) { + /* Wrapped?! */ + KTITERS(id)--; + KTUNLOCK(id); ++ free(fileoff); + k5_setmsg(context, KRB5_KT_IOERR, "Too many keytab iterators active"); + return KRB5_KT_IOERR; /* XXX */ + } ++ *cursorp = (krb5_kt_cursor)fileoff; + KTUNLOCK(id); + + return 0; +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c +index 753929b06d..f7fad27867 100644 +--- a/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c ++++ b/src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c +@@ -271,16 +271,18 @@ krb5_ldap_delete_realm (krb5_context context, char *lrealm) + for (ent = ldap_first_entry (ld, result); ent != NULL; + ent = ldap_next_entry (ld, ent)) { + if ((values = ldap_get_values(ld, ent, "krbPrincipalName")) != NULL) { +- for (i = 0; values[i] != NULL; ++i) { ++ for (i = 0; values[i] != NULL && !st; ++i) { + krb5_parse_name(context, values[i], &principal); + if (principal_in_realm_2(principal, lrealm) == 0) { + st=krb5_ldap_delete_principal(context, principal); +- if (st && st != KRB5_KDB_NOENTRY) +- goto cleanup; ++ if (st == KRB5_KDB_NOENTRY) ++ st = 0; + } + krb5_free_principal(context, principal); + } + ldap_value_free(values); ++ if (st) ++ goto cleanup; + } + } + } +-- +2.41.0 + diff --git a/krb5.spec b/krb5.spec index 03498cb..f86039c 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 1 +%global baserelease 2 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -74,8 +74,9 @@ Patch0012: 0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch Patch0013: 0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch Patch0014: 0014-Enable-PKINIT-if-at-least-one-group-is-available.patch Patch0015: 0015-Replace-ssl.wrap_socket-for-tests.patch +Patch0016: 0016-Fix-unimportant-memory-leaks.patch -License: MIT +License: BSD-2-Clause AND (BSD-2-Clause OR GPL-2.0-or-later) AND BSD-3-Clause AND BSD-4-Clause AND FSFULLRWD AND HPND-export-US AND HPND-export-US-modify AND ISC AND MIT AND MIT-CMU AND OLDAP-2.8 AND RSA-MD URL: https://web.mit.edu/kerberos/www/ BuildRequires: autoconf, bison, make, flex, gawk, gettext, pkgconfig, sed BuildRequires: gcc, gcc-c++ @@ -710,6 +711,11 @@ exit 0 %{_datarootdir}/%{name}-tests/ %changelog +* Tue Oct 10 2023 Julien Rische - 1.21.2-2 +- Use SPDX expression for license tag +- Fix unimportant memory leaks + Resolves: rhbz#2223274 + * Wed Aug 16 2023 Julien Rische - 1.21.2-1 - New upstream version (1.21.2) - Fix double-free in KDC TGS processing (CVE-2023-39975) From 1ed0e3a2d8c572e54bb3068ddc116a3d56034a99 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 17 Jan 2024 11:32:17 +0100 Subject: [PATCH 289/304] krb5 1.21.2-3 - Fix double free in klist's show_ccache() Resolves: rhbz#2257301 - Store krb5-tests files in architecture-specific directories Resolves: rhbz#2244601 Signed-off-by: Julien Rische --- ...move-klist-s-defname-global-variable.patch | 69 +++++++++++++++++++ krb5-tests | 7 +- krb5.spec | 36 ++++++---- tests/upstream/test.sh | 7 +- 4 files changed, 100 insertions(+), 19 deletions(-) create mode 100644 0017-Remove-klist-s-defname-global-variable.patch diff --git a/0017-Remove-klist-s-defname-global-variable.patch b/0017-Remove-klist-s-defname-global-variable.patch new file mode 100644 index 0000000..56beacc --- /dev/null +++ b/0017-Remove-klist-s-defname-global-variable.patch @@ -0,0 +1,69 @@ +From c5cdf6f71621569c6c389be720937ac97ace988f Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Mon, 8 Jan 2024 16:52:27 +0100 +Subject: [PATCH] Remove klist's defname global variable + +Addition of a "cleanup" section in kinit's show_ccache() function as +part of commit 6c5471176f5266564fbc8a7e02f03b4b042202f8 introduced a +double-free bug, because defname is a global variable. After the +first call, successive calls may take place with a dangling pointer in +defname, which will be freed if krb5_cc_get_principal() fails. + +Convert "defname" to a local variable initialized at the beginning of +show_ccache(). + +[ghudson@mit.edu: edited commit message] +--- + src/clients/klist/klist.c | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c +index 43392d2337..394c75b6b7 100644 +--- a/src/clients/klist/klist.c ++++ b/src/clients/klist/klist.c +@@ -53,7 +53,6 @@ int show_flags = 0, show_time = 0, status_only = 0, show_keys = 0; + int show_etype = 0, show_addresses = 0, no_resolve = 0, print_version = 0; + int show_adtype = 0, show_all = 0, list_all = 0, use_client_keytab = 0; + int show_config = 0; +-char *defname; + char *progname; + krb5_timestamp now; + unsigned int timestamp_width; +@@ -62,7 +61,7 @@ krb5_context context; + + static krb5_boolean is_local_tgt(krb5_principal princ, krb5_data *realm); + static char *etype_string(krb5_enctype ); +-static void show_credential(krb5_creds *); ++static void show_credential(krb5_creds *, const char *); + + static void list_all_ccaches(void); + static int list_ccache(krb5_ccache); +@@ -473,6 +472,7 @@ show_ccache(krb5_ccache cache) + krb5_creds creds; + krb5_principal princ = NULL; + krb5_error_code ret; ++ char *defname = NULL; + int status = 1; + + ret = krb5_cc_get_principal(context, cache, &princ); +@@ -503,7 +503,7 @@ show_ccache(krb5_ccache cache) + } + while ((ret = krb5_cc_next_cred(context, cache, &cur, &creds)) == 0) { + if (show_config || !krb5_is_config_principal(context, creds.server)) +- show_credential(&creds); ++ show_credential(&creds, defname); + krb5_free_cred_contents(context, &creds); + } + if (ret == KRB5_CC_END) { +@@ -676,7 +676,7 @@ print_config_data(int col, krb5_data *data) + } + + static void +-show_credential(krb5_creds *cred) ++show_credential(krb5_creds *cred, const char *defname) + { + krb5_error_code ret; + krb5_ticket *tkt = NULL; +-- +2.41.0 + diff --git a/krb5-tests b/krb5-tests index beaeb2b..6754f3f 100644 --- a/krb5-tests +++ b/krb5-tests @@ -12,6 +12,7 @@ trap "rm -rf ${testdir}" EXIT build_flags="$(eval "echo $(rpm --eval '%{_smp_mflags}')")" -cp -rp /usr/share/{{ name }}-tests "${testdir}/" -make -C "${testdir}/{{ name }}-tests" $build_flags -keyctl session - make -C "${testdir}/{{ name }}-tests" check +mkdir "${testdir}/{{ name }}-tests" +cp -rp /usr/share/{{ name }}-tests/{{ arch }} "${testdir}/{{ name }}-tests/" +make -C "${testdir}/{{ name }}-tests/{{ arch }}/" $build_flags +keyctl session - make -C "${testdir}/{{ name }}-tests/{{ arch }}/" check diff --git a/krb5.spec b/krb5.spec index f86039c..555ded5 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 2 +%global baserelease 3 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -489,37 +489,37 @@ rm -- "$RPM_BUILD_ROOT/%{_docdir}/krb5-libs/examples/services.append" rm -- "$RPM_BUILD_ROOT/%{_libdir}/krb5/plugins/preauth/test.so" # Generate tests launching script -sed -e 's/{{ name }}/%{name}/' \ - -e 's/{{ version }}/%{krb5_version}/' \ - -e 's/{{ release }}/%{krb5_release}/' \ - -e 's/{{ arch }}/%{_arch}/' \ +sed -e 's/{{ name }}/%{name}/g' \ + -e 's/{{ version }}/%{krb5_version}/g' \ + -e 's/{{ release }}/%{krb5_release}/g' \ + -e 's/{{ arch }}/%{_arch}/g' \ -i %{SOURCE15} mkdir -p $RPM_BUILD_ROOT%{_libexecdir} -install -pm 755 %{SOURCE15} $RPM_BUILD_ROOT%{_libexecdir}/ +install -pm 755 %{SOURCE15} $RPM_BUILD_ROOT%{_libexecdir}/%{name}-tests-%{_arch} # Copy source files from build folder to system data folder -install -pdm 755 $RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests +install -pdm 755 $RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch} pushd src -cp -p --parents -t "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/" \ +cp -p --parents -t "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/" \ $(find . -type f -exec file -i "{}" + \ | sed -ne 's|^\./\([^:]\+\): \+text/.\+$|\1|p') popd # Copy binary test files install -pm 644 src/tests/pkinit-certs/*.p12 \ - "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/tests/pkinit-certs/" + "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/tests/pkinit-certs/" install -pm 644 src/tests/au_dict.json \ - "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/tests/" + "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/tests/" # Unset executable bit if no shebang in script -for f in $(find "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/" -type f -executable) +for f in $(find "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/" -type f -executable) do head -n1 "$f" | grep -Eq '^#!' || chmod a-x "$f" done # Remove broken shebang Perl scripts -rm -- "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/config/wconfig.pl" -rm -- "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/kadmin/kdbkeys/do-test.pl" +rm -- "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/config/wconfig.pl" +rm -- "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/kadmin/kdbkeys/do-test.pl" %find_lang %{gettext_domain} @@ -707,10 +707,16 @@ exit 0 %{_libdir}/libkadm5srv_mit.so.* %files tests -%{_libexecdir}/%{name}-tests -%{_datarootdir}/%{name}-tests/ +%{_libexecdir}/%{name}-tests-%{_arch} +%{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Wed Jan 17 2024 Julien Rische - 1.21.2-3 +- Fix double free in klist's show_ccache() + Resolves: rhbz#2257301 +- Store krb5-tests files in architecture-specific directories + Resolves: rhbz#2244601 + * Tue Oct 10 2023 Julien Rische - 1.21.2-2 - Use SPDX expression for license tag - Fix unimportant memory leaks diff --git a/tests/upstream/test.sh b/tests/upstream/test.sh index 9c5abc5..fd4aeeb 100755 --- a/tests/upstream/test.sh +++ b/tests/upstream/test.sh @@ -1,2 +1,7 @@ #!/bin/sh -eux -/usr/libexec/krb5-tests +rc=0 +for test_exec in /usr/libexec/krb5-tests-* +do + "$test_exec" || rc=1 +done +exit $rc From 87d784ddd75cd1858aad341c6fd22eb6f33673f9 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sun, 21 Jan 2024 02:56:15 +0000 Subject: [PATCH 290/304] Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 555ded5..908eaf5 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 3 +%global baserelease 4 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -711,6 +711,9 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Sun Jan 21 2024 Fedora Release Engineering - 1.21.2-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + * Wed Jan 17 2024 Julien Rische - 1.21.2-3 - Fix double free in klist's show_ccache() Resolves: rhbz#2257301 From 5cc4a0d8bccc9092bb25007ca50b599b145df970 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 25 Jan 2024 00:53:41 +0000 Subject: [PATCH 291/304] Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 908eaf5..eb35a3b 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 4 +%global baserelease 5 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -711,6 +711,9 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Thu Jan 25 2024 Fedora Release Engineering - 1.21.2-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + * Sun Jan 21 2024 Fedora Release Engineering - 1.21.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild From b45374269bfb01262d8551dc212c0b88c6f556ce Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 3 Jul 2024 15:44:17 +0200 Subject: [PATCH 292/304] krb5 1.21.2-6 - CVE-2024-37370 CVE-2024-37371: GSS message token handling Resolves: rhbz#2294678 rhbz#2294680 - Fix double free in klist's show_ccache() Resolves: rhbz#2257301 - Do not include files with "~" termination in krb5-tests Signed-off-by: Julien Rische --- ...lities-in-GSS-message-token-handling.patch | 535 ++++++++++++++++++ krb5.spec | 13 +- 2 files changed, 546 insertions(+), 2 deletions(-) create mode 100644 0018-Fix-vulnerabilities-in-GSS-message-token-handling.patch diff --git a/0018-Fix-vulnerabilities-in-GSS-message-token-handling.patch b/0018-Fix-vulnerabilities-in-GSS-message-token-handling.patch new file mode 100644 index 0000000..4934355 --- /dev/null +++ b/0018-Fix-vulnerabilities-in-GSS-message-token-handling.patch @@ -0,0 +1,535 @@ +From 7b0e4a36b82b4ab388b520eaba396de365574774 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 14 Jun 2024 10:56:12 -0400 +Subject: [PATCH] Fix vulnerabilities in GSS message token handling + +In gss_krb5int_unseal_token_v3() and gss_krb5int_unseal_v3_iov(), +verify the Extra Count field of CFX wrap tokens against the encrypted +header. Reported by Jacob Champion. + +In gss_krb5int_unseal_token_v3(), check for a decrypted plaintext +length too short to contain the encrypted header and extra count +bytes. Reported by Jacob Champion. + +In kg_unseal_iov_token(), separately track the header IOV length and +complete token length when parsing the token's ASN.1 wrapper. This +fix contains modified versions of functions from k5-der.h and +util_token.c; this duplication will be cleaned up in a future commit. + +CVE-2024-37370: + +In MIT krb5 release 1.3 and later, an attacker can modify the +plaintext Extra Count field of a confidential GSS krb5 wrap token, +causing the unwrapped token to appear truncated to the application. + +CVE-2024-37371: + +In MIT krb5 release 1.3 and later, an attacker can cause invalid +memory reads by sending message tokens with invalid length fields. + +ticket: 9128 (new) +tags: pullup +target_version: 1.21-next + +(cherry picked from commit b0a2f8a5365f2eec3e27d78907de9f9d2c80505a) +--- + src/lib/gssapi/krb5/k5sealv3.c | 5 + + src/lib/gssapi/krb5/k5sealv3iov.c | 3 +- + src/lib/gssapi/krb5/k5unsealiov.c | 80 +++++++++- + src/tests/gssapi/t_invalid.c | 233 +++++++++++++++++++++++++----- + 4 files changed, 275 insertions(+), 46 deletions(-) + +diff --git a/src/lib/gssapi/krb5/k5sealv3.c b/src/lib/gssapi/krb5/k5sealv3.c +index 3b4f8cb837..1fcbdfbb87 100644 +--- a/src/lib/gssapi/krb5/k5sealv3.c ++++ b/src/lib/gssapi/krb5/k5sealv3.c +@@ -408,10 +408,15 @@ gss_krb5int_unseal_token_v3(krb5_context *contextptr, + /* Don't use bodysize here! Use the fact that + cipher.ciphertext.length has been adjusted to the + correct length. */ ++ if (plain.length < 16 + ec) { ++ free(plain.data); ++ goto defective; ++ } + althdr = (unsigned char *)plain.data + plain.length - 16; + if (load_16_be(althdr) != KG2_TOK_WRAP_MSG + || althdr[2] != ptr[2] + || althdr[3] != ptr[3] ++ || load_16_be(althdr+4) != ec + || memcmp(althdr+8, ptr+8, 8)) { + free(plain.data); + goto defective; +diff --git a/src/lib/gssapi/krb5/k5sealv3iov.c b/src/lib/gssapi/krb5/k5sealv3iov.c +index 333ee124dd..f8e90c35b4 100644 +--- a/src/lib/gssapi/krb5/k5sealv3iov.c ++++ b/src/lib/gssapi/krb5/k5sealv3iov.c +@@ -402,9 +402,10 @@ gss_krb5int_unseal_v3_iov(krb5_context context, + if (load_16_be(althdr) != KG2_TOK_WRAP_MSG + || althdr[2] != ptr[2] + || althdr[3] != ptr[3] ++ || load_16_be(althdr + 4) != ec + || memcmp(althdr + 8, ptr + 8, 8) != 0) { + *minor_status = 0; +- return GSS_S_BAD_SIG; ++ return GSS_S_DEFECTIVE_TOKEN; + } + } else { + /* Verify checksum: note EC is checksum size here, not padding */ +diff --git a/src/lib/gssapi/krb5/k5unsealiov.c b/src/lib/gssapi/krb5/k5unsealiov.c +index 3ce2a90ce9..6a6585d9af 100644 +--- a/src/lib/gssapi/krb5/k5unsealiov.c ++++ b/src/lib/gssapi/krb5/k5unsealiov.c +@@ -25,6 +25,7 @@ + */ + + #include "k5-int.h" ++#include "k5-der.h" + #include "gssapiP_krb5.h" + + static OM_uint32 +@@ -247,6 +248,73 @@ cleanup: + return retval; + } + ++/* Similar to k5_der_get_value(), but output an unchecked content length ++ * instead of a k5input containing the contents. */ ++static inline bool ++get_der_tag(struct k5input *in, uint8_t idbyte, size_t *len_out) ++{ ++ uint8_t lenbyte, i; ++ size_t len; ++ ++ /* Do nothing if in is empty or the next byte doesn't match idbyte. */ ++ if (in->status || in->len == 0 || *in->ptr != idbyte) ++ return false; ++ ++ /* Advance past the identifier byte and decode the length. */ ++ (void)k5_input_get_byte(in); ++ lenbyte = k5_input_get_byte(in); ++ if (lenbyte < 128) { ++ len = lenbyte; ++ } else { ++ len = 0; ++ for (i = 0; i < (lenbyte & 0x7F); i++) { ++ if (len > (SIZE_MAX >> 8)) { ++ k5_input_set_status(in, EOVERFLOW); ++ return false; ++ } ++ len = (len << 8) | k5_input_get_byte(in); ++ } ++ } ++ ++ if (in->status) ++ return false; ++ ++ *len_out = len; ++ return true; ++} ++ ++/* ++ * Similar to g_verify_token_header() without toktype or flags, but do not read ++ * more than *header_len bytes of ASN.1 wrapper, and on output set *header_len ++ * to the remaining number of header bytes. Verify the outer DER tag's length ++ * against token_len, which may be larger (but not smaller) than *header_len. ++ */ ++static gss_int32 ++verify_detached_wrapper(const gss_OID_desc *mech, size_t *header_len, ++ uint8_t **header_in, size_t token_len) ++{ ++ struct k5input in, mech_der; ++ gss_OID_desc toid; ++ size_t len; ++ ++ k5_input_init(&in, *header_in, *header_len); ++ ++ if (get_der_tag(&in, 0x60, &len)) { ++ if (len != token_len - (in.ptr - *header_in)) ++ return G_BAD_TOK_HEADER; ++ if (!k5_der_get_value(&in, 0x06, &mech_der)) ++ return G_BAD_TOK_HEADER; ++ toid.elements = (uint8_t *)mech_der.ptr; ++ toid.length = mech_der.len; ++ if (!g_OID_equal(&toid, mech)) ++ return G_WRONG_MECH; ++ } ++ ++ *header_in = (uint8_t *)in.ptr; ++ *header_len = in.len; ++ return 0; ++} ++ + /* + * Caller must provide TOKEN | DATA | PADDING | TRAILER, except + * for DCE in which case it can just provide TOKEN | DATA (must +@@ -267,8 +335,7 @@ kg_unseal_iov_token(OM_uint32 *minor_status, + gss_iov_buffer_t header; + gss_iov_buffer_t padding; + gss_iov_buffer_t trailer; +- size_t input_length; +- unsigned int bodysize; ++ size_t input_length, hlen; + int toktype2; + + header = kg_locate_header_iov(iov, iov_count, toktype); +@@ -298,15 +365,14 @@ kg_unseal_iov_token(OM_uint32 *minor_status, + input_length += trailer->buffer.length; + } + +- code = g_verify_token_header(ctx->mech_used, +- &bodysize, &ptr, -1, +- input_length, 0); ++ hlen = header->buffer.length; ++ code = verify_detached_wrapper(ctx->mech_used, &hlen, &ptr, input_length); + if (code != 0) { + *minor_status = code; + return GSS_S_DEFECTIVE_TOKEN; + } + +- if (bodysize < 2) { ++ if (hlen < 2) { + *minor_status = (OM_uint32)G_BAD_TOK_HEADER; + return GSS_S_DEFECTIVE_TOKEN; + } +@@ -314,7 +380,7 @@ kg_unseal_iov_token(OM_uint32 *minor_status, + toktype2 = load_16_be(ptr); + + ptr += 2; +- bodysize -= 2; ++ hlen -= 2; + + switch (toktype2) { + case KG2_TOK_MIC_MSG: +diff --git a/src/tests/gssapi/t_invalid.c b/src/tests/gssapi/t_invalid.c +index fb8fe55111..8192935099 100644 +--- a/src/tests/gssapi/t_invalid.c ++++ b/src/tests/gssapi/t_invalid.c +@@ -36,31 +36,41 @@ + * + * 1. A pre-CFX wrap or MIC token processed with a CFX-only context causes a + * null pointer dereference. (The token must use SEAL_ALG_NONE or it will +- * be rejected.) ++ * be rejected.) This vulnerability also applies to IOV unwrap. + * +- * 2. A pre-CFX wrap or MIC token with fewer than 24 bytes after the ASN.1 ++ * 2. A CFX wrap token with a different value of EC between the plaintext and ++ * encrypted copies will be erroneously accepted, which allows a message ++ * truncation attack. This vulnerability also applies to IOV unwrap. ++ * ++ * 3. A CFX wrap token with a plaintext length fewer than 16 bytes causes an ++ * access before the beginning of the input buffer, possibly leading to a ++ * crash. ++ * ++ * 4. A CFX wrap token with a plaintext EC value greater than the plaintext ++ * length - 16 causes an integer underflow when computing the result length, ++ * likely causing a crash. ++ * ++ * 5. An IOV unwrap operation will overrun the header buffer if an ASN.1 ++ * wrapper longer than the header buffer is present. ++ * ++ * 6. A pre-CFX wrap or MIC token with fewer than 24 bytes after the ASN.1 + * header causes an input buffer overrun, usually leading to either a segv + * or a GSS_S_DEFECTIVE_TOKEN error due to garbage algorithm, filler, or +- * sequence number values. ++ * sequence number values. This vulnerability also applies to IOV unwrap. + * +- * 3. A pre-CFX wrap token with fewer than 16 + cksumlen bytes after the ASN.1 ++ * 7. A pre-CFX wrap token with fewer than 16 + cksumlen bytes after the ASN.1 + * header causes an integer underflow when computing the ciphertext length, + * leading to an allocation error on 32-bit platforms or a segv on 64-bit + * platforms. A pre-CFX MIC token of this size causes an input buffer + * overrun when comparing the checksum, perhaps leading to a segv. + * +- * 4. A pre-CFX wrap token with fewer than conflen + padlen bytes in the ++ * 8. A pre-CFX wrap token with fewer than conflen + padlen bytes in the + * ciphertext (where padlen is the last byte of the decrypted ciphertext) + * causes an integer underflow when computing the original message length, + * leading to an allocation error. + * +- * 5. In the mechglue, truncated encapsulation in the initial context token can ++ * 9. In the mechglue, truncated encapsulation in the initial context token can + * cause input buffer overruns in gss_accept_sec_context(). +- * +- * Vulnerabilities #1 and #2 also apply to IOV unwrap, although tokens with +- * fewer than 16 bytes after the ASN.1 header will be rejected. +- * Vulnerabilities #2 and #5 can only be robustly detected using a +- * memory-checking environment such as valgrind. + */ + + #include "k5-int.h" +@@ -97,17 +107,25 @@ struct test { + } + }; + +-/* Fake up enough of a CFX GSS context for gss_unwrap, using an AES key. */ ++static void * ++ealloc(size_t len) ++{ ++ void *ptr = calloc(len, 1); ++ ++ if (ptr == NULL) ++ abort(); ++ return ptr; ++} ++ ++/* Fake up enough of a CFX GSS context for gss_unwrap, using an AES key. ++ * The context takes ownership of subkey. */ + static gss_ctx_id_t +-make_fake_cfx_context() ++make_fake_cfx_context(krb5_key subkey) + { + gss_union_ctx_id_t uctx; + krb5_gss_ctx_id_t kgctx; +- krb5_keyblock kb; + +- kgctx = calloc(1, sizeof(*kgctx)); +- if (kgctx == NULL) +- abort(); ++ kgctx = ealloc(sizeof(*kgctx)); + kgctx->established = 1; + kgctx->proto = 1; + if (g_seqstate_init(&kgctx->seqstate, 0, 0, 0, 0) != 0) +@@ -116,15 +134,10 @@ make_fake_cfx_context() + kgctx->sealalg = -1; + kgctx->signalg = -1; + +- kb.enctype = ENCTYPE_AES128_CTS_HMAC_SHA1_96; +- kb.length = 16; +- kb.contents = (unsigned char *)"1234567887654321"; +- if (krb5_k_create_key(NULL, &kb, &kgctx->subkey) != 0) +- abort(); ++ kgctx->subkey = subkey; ++ kgctx->cksumtype = CKSUMTYPE_HMAC_SHA1_96_AES128; + +- uctx = calloc(1, sizeof(*uctx)); +- if (uctx == NULL) +- abort(); ++ uctx = ealloc(sizeof(*uctx)); + uctx->mech_type = &mech_krb5; + uctx->internal_ctx_id = (gss_ctx_id_t)kgctx; + return (gss_ctx_id_t)uctx; +@@ -138,9 +151,7 @@ make_fake_context(const struct test *test) + krb5_gss_ctx_id_t kgctx; + krb5_keyblock kb; + +- kgctx = calloc(1, sizeof(*kgctx)); +- if (kgctx == NULL) +- abort(); ++ kgctx = ealloc(sizeof(*kgctx)); + kgctx->established = 1; + if (g_seqstate_init(&kgctx->seqstate, 0, 0, 0, 0) != 0) + abort(); +@@ -162,9 +173,7 @@ make_fake_context(const struct test *test) + if (krb5_k_create_key(NULL, &kb, &kgctx->enc) != 0) + abort(); + +- uctx = calloc(1, sizeof(*uctx)); +- if (uctx == NULL) +- abort(); ++ uctx = ealloc(sizeof(*uctx)); + uctx->mech_type = &mech_krb5; + uctx->internal_ctx_id = (gss_ctx_id_t)kgctx; + return (gss_ctx_id_t)uctx; +@@ -194,9 +203,7 @@ make_token(unsigned char *token, size_t len, gss_buffer_t out) + + assert(mech_krb5.length == 9); + assert(len + 11 < 128); +- wrapped = malloc(len + 13); +- if (wrapped == NULL) +- abort(); ++ wrapped = ealloc(len + 13); + wrapped[0] = 0x60; + wrapped[1] = len + 11; + wrapped[2] = 0x06; +@@ -207,6 +214,18 @@ make_token(unsigned char *token, size_t len, gss_buffer_t out) + out->value = wrapped; + } + ++/* Create a 16-byte header for a CFX confidential wrap token to be processed by ++ * the fake CFX context. */ ++static void ++write_cfx_header(uint16_t ec, uint8_t *out) ++{ ++ memset(out, 0, 16); ++ store_16_be(KG2_TOK_WRAP_MSG, out); ++ out[2] = FLAG_WRAP_CONFIDENTIAL; ++ out[3] = 0xFF; ++ store_16_be(ec, out + 4); ++} ++ + /* Unwrap a superficially valid RFC 1964 token with a CFX-only context, with + * regular and IOV unwrap. */ + static void +@@ -238,6 +257,134 @@ test_bogus_1964_token(gss_ctx_id_t ctx) + free(in.value); + } + ++static void ++test_cfx_altered_ec(gss_ctx_id_t ctx, krb5_key subkey) ++{ ++ OM_uint32 major, minor; ++ uint8_t tokbuf[128], plainbuf[24]; ++ krb5_data plain; ++ krb5_enc_data cipher; ++ gss_buffer_desc in, out; ++ gss_iov_buffer_desc iov[2]; ++ ++ /* Construct a header with a plaintext EC value of 3. */ ++ write_cfx_header(3, tokbuf); ++ ++ /* Encrypt a plaintext and a copy of the header with the EC value 0. */ ++ memcpy(plainbuf, "truncate", 8); ++ memcpy(plainbuf + 8, tokbuf, 16); ++ store_16_be(0, plainbuf + 12); ++ plain = make_data(plainbuf, 24); ++ cipher.ciphertext.data = (char *)tokbuf + 16; ++ cipher.ciphertext.length = sizeof(tokbuf) - 16; ++ cipher.enctype = subkey->keyblock.enctype; ++ if (krb5_k_encrypt(NULL, subkey, KG_USAGE_INITIATOR_SEAL, NULL, ++ &plain, &cipher) != 0) ++ abort(); ++ ++ /* Verify that the token is rejected by gss_unwrap(). */ ++ in.value = tokbuf; ++ in.length = 16 + cipher.ciphertext.length; ++ major = gss_unwrap(&minor, ctx, &in, &out, NULL, NULL); ++ if (major != GSS_S_DEFECTIVE_TOKEN) ++ abort(); ++ (void)gss_release_buffer(&minor, &out); ++ ++ /* Verify that the token is rejected by gss_unwrap_iov(). */ ++ iov[0].type = GSS_IOV_BUFFER_TYPE_STREAM; ++ iov[0].buffer = in; ++ iov[1].type = GSS_IOV_BUFFER_TYPE_DATA; ++ major = gss_unwrap_iov(&minor, ctx, NULL, NULL, iov, 2); ++ if (major != GSS_S_DEFECTIVE_TOKEN) ++ abort(); ++} ++ ++static void ++test_cfx_short_plaintext(gss_ctx_id_t ctx, krb5_key subkey) ++{ ++ OM_uint32 major, minor; ++ uint8_t tokbuf[128], zerobyte = 0; ++ krb5_data plain; ++ krb5_enc_data cipher; ++ gss_buffer_desc in, out; ++ ++ write_cfx_header(0, tokbuf); ++ ++ /* Encrypt a single byte, with no copy of the header. */ ++ plain = make_data(&zerobyte, 1); ++ cipher.ciphertext.data = (char *)tokbuf + 16; ++ cipher.ciphertext.length = sizeof(tokbuf) - 16; ++ cipher.enctype = subkey->keyblock.enctype; ++ if (krb5_k_encrypt(NULL, subkey, KG_USAGE_INITIATOR_SEAL, NULL, ++ &plain, &cipher) != 0) ++ abort(); ++ ++ /* Verify that the token is rejected by gss_unwrap(). */ ++ in.value = tokbuf; ++ in.length = 16 + cipher.ciphertext.length; ++ major = gss_unwrap(&minor, ctx, &in, &out, NULL, NULL); ++ if (major != GSS_S_DEFECTIVE_TOKEN) ++ abort(); ++ (void)gss_release_buffer(&minor, &out); ++} ++ ++static void ++test_cfx_large_ec(gss_ctx_id_t ctx, krb5_key subkey) ++{ ++ OM_uint32 major, minor; ++ uint8_t tokbuf[128] = { 0 }, plainbuf[20]; ++ krb5_data plain; ++ krb5_enc_data cipher; ++ gss_buffer_desc in, out; ++ ++ /* Construct a header with an EC value of 5. */ ++ write_cfx_header(5, tokbuf); ++ ++ /* Encrypt a 4-byte plaintext plus the header. */ ++ memcpy(plainbuf, "abcd", 4); ++ memcpy(plainbuf + 4, tokbuf, 16); ++ plain = make_data(plainbuf, 20); ++ cipher.ciphertext.data = (char *)tokbuf + 16; ++ cipher.ciphertext.length = sizeof(tokbuf) - 16; ++ cipher.enctype = subkey->keyblock.enctype; ++ if (krb5_k_encrypt(NULL, subkey, KG_USAGE_INITIATOR_SEAL, NULL, ++ &plain, &cipher) != 0) ++ abort(); ++ ++ /* Verify that the token is rejected by gss_unwrap(). */ ++ in.value = tokbuf; ++ in.length = 16 + cipher.ciphertext.length; ++ major = gss_unwrap(&minor, ctx, &in, &out, NULL, NULL); ++ if (major != GSS_S_DEFECTIVE_TOKEN) ++ abort(); ++ (void)gss_release_buffer(&minor, &out); ++} ++ ++static void ++test_iov_large_asn1_wrapper(gss_ctx_id_t ctx) ++{ ++ OM_uint32 minor, major; ++ uint8_t databuf[10] = { 0 }; ++ gss_iov_buffer_desc iov[2]; ++ ++ /* ++ * In this IOV array, the header contains a DER tag with a dangling eight ++ * bytes of length field. The data IOV indicates a total token length ++ * sufficient to contain the length bytes. ++ */ ++ iov[0].type = GSS_IOV_BUFFER_TYPE_HEADER; ++ iov[0].buffer.value = ealloc(2); ++ iov[0].buffer.length = 2; ++ memcpy(iov[0].buffer.value, "\x60\x88", 2); ++ iov[1].type = GSS_IOV_BUFFER_TYPE_DATA; ++ iov[1].buffer.value = databuf; ++ iov[1].buffer.length = 10; ++ major = gss_unwrap_iov(&minor, ctx, NULL, NULL, iov, 2); ++ if (major != GSS_S_DEFECTIVE_TOKEN) ++ abort(); ++ free(iov[0].buffer.value); ++} ++ + /* Process wrap and MIC tokens with incomplete headers. */ + static void + test_short_header(gss_ctx_id_t ctx) +@@ -387,9 +534,7 @@ try_accept(void *value, size_t len) + gss_ctx_id_t ctx = GSS_C_NO_CONTEXT; + + /* Copy the provided value to make input overruns more obvious. */ +- in.value = malloc(len); +- if (in.value == NULL) +- abort(); ++ in.value = ealloc(len); + memcpy(in.value, value, len); + in.length = len; + (void)gss_accept_sec_context(&minor, &ctx, GSS_C_NO_CREDENTIAL, &in, +@@ -424,11 +569,23 @@ test_short_encapsulation() + int + main(int argc, char **argv) + { ++ krb5_keyblock kb; ++ krb5_key cfx_subkey; + gss_ctx_id_t ctx; + size_t i; + +- ctx = make_fake_cfx_context(); ++ kb.enctype = ENCTYPE_AES128_CTS_HMAC_SHA1_96; ++ kb.length = 16; ++ kb.contents = (unsigned char *)"1234567887654321"; ++ if (krb5_k_create_key(NULL, &kb, &cfx_subkey) != 0) ++ abort(); ++ ++ ctx = make_fake_cfx_context(cfx_subkey); + test_bogus_1964_token(ctx); ++ test_cfx_altered_ec(ctx, cfx_subkey); ++ test_cfx_short_plaintext(ctx, cfx_subkey); ++ test_cfx_large_ec(ctx, cfx_subkey); ++ test_iov_large_asn1_wrapper(ctx); + free_fake_context(ctx); + + for (i = 0; i < sizeof(tests) / sizeof(*tests); i++) { +-- +2.45.1 + diff --git a/krb5.spec b/krb5.spec index eb35a3b..cc17078 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 5 +%global baserelease 6 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -75,6 +75,8 @@ Patch0013: 0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch Patch0014: 0014-Enable-PKINIT-if-at-least-one-group-is-available.patch Patch0015: 0015-Replace-ssl.wrap_socket-for-tests.patch Patch0016: 0016-Fix-unimportant-memory-leaks.patch +Patch0017: 0017-Remove-klist-s-defname-global-variable.patch +Patch0018: 0018-Fix-vulnerabilities-in-GSS-message-token-handling.patch License: BSD-2-Clause AND (BSD-2-Clause OR GPL-2.0-or-later) AND BSD-3-Clause AND BSD-4-Clause AND FSFULLRWD AND HPND-export-US AND HPND-export-US-modify AND ISC AND MIT AND MIT-CMU AND OLDAP-2.8 AND RSA-MD URL: https://web.mit.edu/kerberos/www/ @@ -502,7 +504,7 @@ install -pdm 755 $RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch} pushd src cp -p --parents -t "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/" \ $(find . -type f -exec file -i "{}" + \ - | sed -ne 's|^\./\([^:]\+\): \+text/.\+$|\1|p') + | sed -ne 's|^\./\([^:]\+\): \+text/.\+$|\1|p' | grep -Ev '~$') popd # Copy binary test files @@ -711,6 +713,13 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Mon Jul 08 2024 Julien Rische - 1.21.2-6 +- CVE-2024-37370 CVE-2024-37371: GSS message token handling + Resolves: rhbz#2294678 rhbz#2294680 +- Fix double free in klist's show_ccache() + Resolves: rhbz#2257301 +- Do not include files with "~" termination in krb5-tests + * Thu Jan 25 2024 Fedora Release Engineering - 1.21.2-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild From d71494ca6c6bb9949a5cb7bb966c1f7809994c37 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Tue, 9 Jul 2024 12:08:41 +0200 Subject: [PATCH 293/304] krb5 1.21.3-1 - New upstream version (1.21.3) - CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c Resolves: rhbz#2266732 - CVE-2024-26461: Memory leak in src/lib/gssapi/krb5/k5sealv3.c Resolves: rhbz#2266741 - CVE-2024-26462: Memory leak in src/kdc/ndr.c Resolves: rhbz#2266743 - Add missing SPDX license identifiers Resolves: rhbz#2265333 Signed-off-by: Julien Rische --- .gitignore | 2 + ...t-Don-t-issue-session-keys-with-depr.patch | 9 +- 0002-downstream-ksu-pam-integration.patch | 4 +- 0003-downstream-SELinux-integration.patch | 8 +- ...ownstream-fix-debuginfo-with-y.tab.c.patch | 4 +- 0005-downstream-Remove-3des-support.patch | 26 +- ...am-FIPS-with-PRNG-and-RADIUS-and-MD4.patch | 4 +- ...-krad-UDP-TCP-localhost-connection-w.patch | 7 +- ...tests-compatible-with-sssd_krb5_loca.patch | 4 +- ...-Include-missing-OpenSSL-FIPS-header.patch | 4 +- ...am-Do-not-set-root-as-ksu-file-owner.patch | 4 +- ...low-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch | 4 +- ...-to-set-PAC-ticket-signature-as-opti.patch | 13 +- ...PKINIT-CMS-SHA-1-signature-verificat.patch | 10 +- ...T-if-at-least-one-group-is-available.patch | 10 +- 0015-Replace-ssl.wrap_socket-for-tests.patch | 4 +- ...nate-old-style-function-declarations.patch | 10685 ++++++++++++++++ 0017-Fix-two-unlikely-memory-leaks.patch | 206 + ...=> 0018-Fix-unimportant-memory-leaks.patch | 254 +- ...lities-in-GSS-message-token-handling.patch | 535 - ...move-klist-s-defname-global-variable.patch | 8 +- krb5.spec | 26 +- sources | 4 +- 23 files changed, 11096 insertions(+), 739 deletions(-) rename 0001-Revert-Don-t-issue-session-keys-with-deprecated-enct.patch => 0001-downstream-Revert-Don-t-issue-session-keys-with-depr.patch (98%) create mode 100644 0016-Eliminate-old-style-function-declarations.patch create mode 100644 0017-Fix-two-unlikely-memory-leaks.patch rename 0016-Fix-unimportant-memory-leaks.patch => 0018-Fix-unimportant-memory-leaks.patch (90%) delete mode 100644 0018-Fix-vulnerabilities-in-GSS-message-token-handling.patch rename 0017-Remove-klist-s-defname-global-variable.patch => 0019-Remove-klist-s-defname-global-variable.patch (93%) diff --git a/.gitignore b/.gitignore index 7057bf9..40603ef 100644 --- a/.gitignore +++ b/.gitignore @@ -206,3 +206,5 @@ /krb5-1.21.tar.gz.asc /krb5-1.21.2.tar.gz /krb5-1.21.2.tar.gz.asc +/krb5-1.21.3.tar.gz +/krb5-1.21.3.tar.gz.asc diff --git a/0001-Revert-Don-t-issue-session-keys-with-deprecated-enct.patch b/0001-downstream-Revert-Don-t-issue-session-keys-with-depr.patch similarity index 98% rename from 0001-Revert-Don-t-issue-session-keys-with-deprecated-enct.patch rename to 0001-downstream-Revert-Don-t-issue-session-keys-with-depr.patch index cc457ae..84d04bf 100644 --- a/0001-Revert-Don-t-issue-session-keys-with-deprecated-enct.patch +++ b/0001-downstream-Revert-Don-t-issue-session-keys-with-depr.patch @@ -1,7 +1,8 @@ -From 087d150e4afe47a8d269d5e80dcef2204b007ceb Mon Sep 17 00:00:00 2001 +From 6f7fd964539dfe4a885068f43a91db9738661870 Mon Sep 17 00:00:00 2001 From: Julien Rische -Date: Wed, 16 Aug 2023 10:00:30 +0200 -Subject: [PATCH] Revert "Don't issue session keys with deprecated enctypes" +Date: Tue, 9 Jul 2024 11:15:33 +0200 +Subject: [PATCH] [downstream] Revert "Don't issue session keys with + deprecated enctypes" This reverts commit 1b57a4d134bbd0e7c52d5885a92eccc815726463. --- @@ -305,5 +306,5 @@ index 8e5f5ba8e9..2a86c5cdfc 100644 'supported_enctypes': 'arcfour-hmac:normal', 'master_key_type': 'arcfour-hmac'}}}), -- -2.41.0 +2.45.1 diff --git a/0002-downstream-ksu-pam-integration.patch b/0002-downstream-ksu-pam-integration.patch index 08bfeab..9afd094 100644 --- a/0002-downstream-ksu-pam-integration.patch +++ b/0002-downstream-ksu-pam-integration.patch @@ -1,4 +1,4 @@ -From 2080ff4c57d29e74466987d673aaf25273160534 Mon Sep 17 00:00:00 2001 +From de4205c45e310ceaaa7cd7958af7293322fa43a6 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:29:58 -0400 Subject: [PATCH] [downstream] ksu pam integration @@ -773,5 +773,5 @@ index 77be7a2025..587221936e 100644 if test "${localedir+set}" != set; then localedir='$(datadir)/locale' -- -2.41.0 +2.45.1 diff --git a/0003-downstream-SELinux-integration.patch b/0003-downstream-SELinux-integration.patch index cac0604..a3b32c3 100644 --- a/0003-downstream-SELinux-integration.patch +++ b/0003-downstream-SELinux-integration.patch @@ -1,4 +1,4 @@ -From 3efc0e3ce4ccc8a89700f35bef041794982d95ca Mon Sep 17 00:00:00 2001 +From 30ff501e4b519396f5aea25e24919be817863e7c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:30:53 -0400 Subject: [PATCH] [downstream] SELinux integration @@ -238,10 +238,10 @@ index 0000000000..dfaaa847cb +#endif +#endif diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 9c76780181..dd6430ece8 100644 +index 4e09ed345d..09f800be52 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin -@@ -87,6 +87,12 @@ +@@ -83,6 +83,12 @@ #define THREEPARAMOPEN(x,y,z) open(x,y,z) #endif @@ -1034,5 +1034,5 @@ index 0000000000..807d039da3 + +#endif /* USE_SELINUX */ -- -2.41.0 +2.45.1 diff --git a/0004-downstream-fix-debuginfo-with-y.tab.c.patch b/0004-downstream-fix-debuginfo-with-y.tab.c.patch index 9368aa6..c21b269 100644 --- a/0004-downstream-fix-debuginfo-with-y.tab.c.patch +++ b/0004-downstream-fix-debuginfo-with-y.tab.c.patch @@ -1,4 +1,4 @@ -From 28677b932c200eba07576358b4e5df2ae22c8ecd Mon Sep 17 00:00:00 2001 +From 393830d96000ed692aa9a99ef87187d6f2863931 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 23 Aug 2016 16:49:25 -0400 Subject: [PATCH] [downstream] fix debuginfo with y.tab.c @@ -40,5 +40,5 @@ index 8669c2436c..a22f23c02c 100644 install: $(INSTALL_PROGRAM) $(PROG) ${DESTDIR}$(ADMIN_BINDIR)/$(PROG) -- -2.41.0 +2.45.1 diff --git a/0005-downstream-Remove-3des-support.patch b/0005-downstream-Remove-3des-support.patch index 6c8ce3b..fcdb136 100644 --- a/0005-downstream-Remove-3des-support.patch +++ b/0005-downstream-Remove-3des-support.patch @@ -1,4 +1,4 @@ -From 6734a067c600ea6ad81d08fcc481609c2bad9fbb Mon Sep 17 00:00:00 2001 +From 7d697742abb370cfc7241c1faa78ba08d7650f6a Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 26 Mar 2019 18:51:10 -0400 Subject: [PATCH] [downstream] Remove 3des support @@ -259,7 +259,7 @@ index 45fe160d7f..b4b1f3bd93 100644 CKSUMTYPE_NIST_SHA.rst CKSUMTYPE_RSA_MD4.rst diff --git a/doc/conf.py b/doc/conf.py -index cd76f5999f..1e1cfce80c 100644 +index ecf9020a72..db7fa377ef 100644 --- a/doc/conf.py +++ b/doc/conf.py @@ -281,7 +281,7 @@ else: @@ -326,10 +326,10 @@ index 69be9030f8..2561e917a2 100644 lib/krb5 lib/krb5/error_tables lib/krb5/asn.1 lib/krb5/ccache diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index dd6430ece8..350bcf86f2 100644 +index 09f800be52..c5a625db8f 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin -@@ -426,8 +426,8 @@ typedef struct _krb5_crypto_iov { +@@ -422,8 +422,8 @@ typedef struct _krb5_crypto_iov { #define ENCTYPE_DES_CBC_MD4 0x0002 /**< @deprecated no longer supported */ #define ENCTYPE_DES_CBC_MD5 0x0003 /**< @deprecated no longer supported */ #define ENCTYPE_DES_CBC_RAW 0x0004 /**< @deprecated no longer supported */ @@ -340,7 +340,7 @@ index dd6430ece8..350bcf86f2 100644 #define ENCTYPE_DES_HMAC_SHA1 0x0008 /**< @deprecated no longer supported */ /* PKINIT */ #define ENCTYPE_DSA_SHA1_CMS 0x0009 /**< DSA with SHA1, CMS signature */ -@@ -436,9 +436,9 @@ typedef struct _krb5_crypto_iov { +@@ -432,9 +432,9 @@ typedef struct _krb5_crypto_iov { #define ENCTYPE_RC2_CBC_ENV 0x000c /**< RC2 cbc mode, CMS enveloped data */ #define ENCTYPE_RSA_ENV 0x000d /**< RSA encryption, CMS enveloped data */ #define ENCTYPE_RSA_ES_OAEP_ENV 0x000e /**< RSA w/OEAP encryption, CMS enveloped data */ @@ -352,7 +352,7 @@ index dd6430ece8..350bcf86f2 100644 #define ENCTYPE_AES128_CTS_HMAC_SHA1_96 0x0011 /**< RFC 3962 */ #define ENCTYPE_AES256_CTS_HMAC_SHA1_96 0x0012 /**< RFC 3962 */ #define ENCTYPE_AES128_CTS_HMAC_SHA256_128 0x0013 /**< RFC 8009 */ -@@ -463,7 +463,7 @@ typedef struct _krb5_crypto_iov { +@@ -459,7 +459,7 @@ typedef struct _krb5_crypto_iov { #define CKSUMTYPE_RSA_MD5 0x0007 #define CKSUMTYPE_RSA_MD5_DES 0x0008 #define CKSUMTYPE_NIST_SHA 0x0009 @@ -5491,10 +5491,10 @@ index 9b183bc337..f0cc4a6809 100644 if (sealalg != 0xffff) xfree(plain); diff --git a/src/lib/gssapi/krb5/k5unsealiov.c b/src/lib/gssapi/krb5/k5unsealiov.c -index 85a9574f36..3ce2a90ce9 100644 +index 21b501731e..6a6585d9af 100644 --- a/src/lib/gssapi/krb5/k5unsealiov.c +++ b/src/lib/gssapi/krb5/k5unsealiov.c -@@ -102,28 +102,21 @@ kg_unseal_v1_iov(krb5_context context, +@@ -103,28 +103,21 @@ kg_unseal_v1_iov(krb5_context context, } if ((ctx->sealalg == SEAL_ALG_NONE && signalg > 1) || @@ -5528,7 +5528,7 @@ index 85a9574f36..3ce2a90ce9 100644 /* get the token parameters */ code = kg_get_seq_num(context, ctx->seq, ptr + 14, ptr + 6, &direction, &seqnum); -@@ -181,16 +174,10 @@ kg_unseal_v1_iov(krb5_context context, +@@ -182,16 +175,10 @@ kg_unseal_v1_iov(krb5_context context, /* initialize the checksum */ @@ -5548,7 +5548,7 @@ index 85a9574f36..3ce2a90ce9 100644 code = krb5_c_checksum_length(context, md5cksum.checksum_type, &sumlen); if (code != 0) { -@@ -209,18 +196,13 @@ kg_unseal_v1_iov(krb5_context context, +@@ -210,18 +197,13 @@ kg_unseal_v1_iov(krb5_context context, goto cleanup; } @@ -5917,10 +5917,10 @@ index 7494d7fcdb..2f95d89967 100755 # because the ticket session key and initiator subkey are # non-permitted. (This is unfortunate if the acceptor's restriction diff --git a/src/tests/gssapi/t_invalid.c b/src/tests/gssapi/t_invalid.c -index 9876a11e67..fb8fe55111 100644 +index 882e163634..8192935099 100644 --- a/src/tests/gssapi/t_invalid.c +++ b/src/tests/gssapi/t_invalid.c -@@ -84,18 +84,6 @@ struct test { +@@ -94,18 +94,6 @@ struct test { size_t toklen; const char *token; } tests[] = { @@ -6201,5 +6201,5 @@ index 1aebdd0b4a..c38eefd2bd 100644 The AES Advanced Encryption Standard family, like 3DES, is a symmetric block cipher and was designed -- -2.41.0 +2.45.1 diff --git a/0006-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch b/0006-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch index d59a5bf..989b501 100644 --- a/0006-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch +++ b/0006-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch @@ -1,4 +1,4 @@ -From dc3fd927ccd5b7b40049145c3fc7c610d72e9502 Mon Sep 17 00:00:00 2001 +From 7b6453903c248a761d3ceb538dfacebbf3d3a9ff Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 9 Nov 2018 15:12:21 -0500 Subject: [PATCH] [downstream] FIPS with PRNG and RADIUS and MD4 @@ -608,5 +608,5 @@ index 1a772d450f..232e78bc05 100644 vt->name = "spake"; vt->pa_type_list = pa_types; -- -2.41.0 +2.45.1 diff --git a/0007-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch b/0007-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch index 2602e7a..b339700 100644 --- a/0007-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch +++ b/0007-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch @@ -1,7 +1,8 @@ -From 19db7e5b5d13732c2dfd08b35e2ad3f311553d54 Mon Sep 17 00:00:00 2001 +From 707fa7bd2be6327343dc8fc5c20dc77645524518 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Thu, 5 May 2022 17:15:12 +0200 -Subject: [PATCH] [downstream] Allow krad UDP/TCP localhost connection with FIPS +Subject: [PATCH] [downstream] Allow krad UDP/TCP localhost connection + with FIPS libkrad allows to establish connections only to UNIX socket in FIPS mode, because MD5 digest is not considered safe enough to be used for @@ -77,5 +78,5 @@ index 929f1cef67..063f17a613 100644 retval = ESOCKTNOSUPPORT; goto error; -- -2.41.0 +2.45.1 diff --git a/0008-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch b/0008-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch index 844890e..ceb9595 100644 --- a/0008-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch +++ b/0008-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch @@ -1,4 +1,4 @@ -From 16d3f9a54d4707ae9de18f108a7b61965e83ceaf Mon Sep 17 00:00:00 2001 +From 1da88bea558348be2974470774aa688f8be634c0 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 7 Dec 2022 13:22:42 +0100 Subject: [PATCH] [downstream] Make tests compatible with @@ -37,5 +37,5 @@ index 87bac17929..26bc95a8dc 100644 fail('URI answers do not match') j += 1 -- -2.41.0 +2.45.1 diff --git a/0009-downstream-Include-missing-OpenSSL-FIPS-header.patch b/0009-downstream-Include-missing-OpenSSL-FIPS-header.patch index ea123f7..ef6f825 100644 --- a/0009-downstream-Include-missing-OpenSSL-FIPS-header.patch +++ b/0009-downstream-Include-missing-OpenSSL-FIPS-header.patch @@ -1,4 +1,4 @@ -From 511a6260f0dadc3fe5ebe075f8b548eae026a1cc Mon Sep 17 00:00:00 2001 +From 775ed8588cc21385fb16a4cec4a861f0d578ce04 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Thu, 5 Jan 2023 20:06:47 +0100 Subject: [PATCH] [downstream] Include missing OpenSSL FIPS header @@ -116,5 +116,5 @@ index 232e78bc05..3394f8a58e 100644 * The SPAKE kdcpreauth module uses a secure cookie containing the following * concatenated fields (all integer fields are big-endian): -- -2.41.0 +2.45.1 diff --git a/0010-downstream-Do-not-set-root-as-ksu-file-owner.patch b/0010-downstream-Do-not-set-root-as-ksu-file-owner.patch index 46e759e..bd4ab77 100644 --- a/0010-downstream-Do-not-set-root-as-ksu-file-owner.patch +++ b/0010-downstream-Do-not-set-root-as-ksu-file-owner.patch @@ -1,4 +1,4 @@ -From 1b0bb0c3e5575559ea9135af5b9a1e91fe0f79f3 Mon Sep 17 00:00:00 2001 +From 4fd20741afcf76085ea62eb015cd589bb9392a7b Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Mon, 9 Jan 2023 22:39:52 +0100 Subject: [PATCH] [downstream] Do not set root as ksu file owner @@ -27,5 +27,5 @@ index 7eaa2f351c..e9ae71471e 100644 ## ${prefix}. prefix=@prefix@ -- -2.41.0 +2.45.1 diff --git a/0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch b/0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch index 2d34be0..5e45141 100644 --- a/0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch +++ b/0011-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch @@ -1,4 +1,4 @@ -From 6e239888cdb938ddda2bf49ec03ad2af3923c381 Mon Sep 17 00:00:00 2001 +From 16f90c007036789d8d9343e8a0cbabfd21853b5a Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Thu, 19 Jan 2023 19:22:27 +0100 Subject: [PATCH] [downstream] Allow KRB5KDF, MD5, and MD4 in FIPS mode @@ -161,5 +161,5 @@ index 5a43c3d9eb..8528ddc4a9 100644 ret = KRB5_CRYPTO_INTERNAL; goto done; -- -2.41.0 +2.45.1 diff --git a/0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch b/0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch index 00d2d0b..57b4a76 100644 --- a/0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch +++ b/0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch @@ -1,7 +1,8 @@ -From 640492ecb4ee42edf33c343c08c01a549ed68a52 Mon Sep 17 00:00:00 2001 +From 23b58199db429603802e338db530677b61561335 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 15 Mar 2023 15:56:34 +0100 -Subject: [PATCH] [downstream] Allow to set PAC ticket signature as optional +Subject: [PATCH] [downstream] Allow to set PAC ticket signature as + optional MS-PAC states that "The ticket signature SHOULD be included in tickets that are not encrypted to the krbtgt account". However, the @@ -73,10 +74,10 @@ index 745b24f351..6075349e5e 100644 #if !defined(_WIN32) diff --git a/src/include/krb5/krb5.hin b/src/include/krb5/krb5.hin -index 350bcf86f2..17e1b52266 100644 +index c5a625db8f..2d9b64dc85 100644 --- a/src/include/krb5/krb5.hin +++ b/src/include/krb5/krb5.hin -@@ -8356,6 +8356,46 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, +@@ -8329,6 +8329,46 @@ krb5_kdc_verify_ticket(krb5_context context, const krb5_enc_tkt_part *enc_tkt, const krb5_keyblock *server, const krb5_keyblock *privsvr, krb5_pac *pac_out); @@ -258,7 +259,7 @@ index 4c50e935a2..d4b0455c8c 100644 krb5_kt_client_default krb5_kt_close diff --git a/src/man/kadmin.man b/src/man/kadmin.man -index 461207021b..e8d78309cb 100644 +index 8413e70ccd..f68eb0569d 100644 --- a/src/man/kadmin.man +++ b/src/man/kadmin.man @@ -724,6 +724,12 @@ encryption type. It may be necessary to set this value to @@ -275,5 +276,5 @@ index 461207021b..e8d78309cb 100644 .sp This command requires the \fBmodify\fP privilege. -- -2.41.0 +2.45.1 diff --git a/0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch b/0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch index ba2c6af..68a2a6d 100644 --- a/0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch +++ b/0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch @@ -1,8 +1,8 @@ -From 1b2f64d66e01c1abeefdb7cbef7b04035c2128c0 Mon Sep 17 00:00:00 2001 +From 31b9debcf2cbd558f8f315fefb69fc8206b115b4 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Tue, 23 May 2023 12:19:54 +0200 -Subject: [PATCH] [downstream] Make PKINIT CMS SHA-1 signature verification - available in FIPS mode +Subject: [PATCH] [downstream] Make PKINIT CMS SHA-1 signature + verification available in FIPS mode We recommend using the SHA1 crypto-module in order to allow the verification of SHA-1 signature for CMS messages. However, this module @@ -20,7 +20,7 @@ curve cryptography is implemented for PKINIT in MIT krb5. 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index f41328763e..263ef7845e 100644 +index cb9c79626c..17dd18e37d 100644 --- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c @@ -1844,8 +1844,17 @@ cms_signeddata_verify(krb5_context context, @@ -43,5 +43,5 @@ index f41328763e..263ef7845e 100644 goto cleanup; } -- -2.41.0 +2.45.1 diff --git a/0014-Enable-PKINIT-if-at-least-one-group-is-available.patch b/0014-Enable-PKINIT-if-at-least-one-group-is-available.patch index 717eb43..30646aa 100644 --- a/0014-Enable-PKINIT-if-at-least-one-group-is-available.patch +++ b/0014-Enable-PKINIT-if-at-least-one-group-is-available.patch @@ -1,4 +1,4 @@ -From d2b061bea524012edde2915aa95fc4cb6a6f3ae9 Mon Sep 17 00:00:00 2001 +From c24c9faf859ddc04910a6bc591d8ddb2ada93e80 Mon Sep 17 00:00:00 2001 From: Greg Hudson Date: Tue, 30 May 2023 01:21:48 -0400 Subject: [PATCH] Enable PKINIT if at least one group is available @@ -52,7 +52,7 @@ index 9fa315d7a0..8bdbea8e95 100644 krb5_error_code pkinit_init_req_crypto(pkinit_req_crypto_context *); diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 263ef7845e..d646073d55 100644 +index 17dd18e37d..8cdc40bfb4 100644 --- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c @@ -47,7 +47,8 @@ @@ -139,7 +139,7 @@ index 263ef7845e..d646073d55 100644 } static void -@@ -2910,11 +2918,11 @@ client_create_dh(krb5_context context, +@@ -2912,11 +2920,11 @@ client_create_dh(krb5_context context, if (cryptoctx->received_params != NULL) params = cryptoctx->received_params; @@ -154,7 +154,7 @@ index 263ef7845e..d646073d55 100644 params = plg_cryptoctx->dh_4096; else goto cleanup; -@@ -3210,19 +3218,23 @@ pkinit_create_td_dh_parameters(krb5_context context, +@@ -3212,19 +3220,23 @@ pkinit_create_td_dh_parameters(krb5_context context, krb5_algorithm_identifier alg_4096 = { dh_oid, oakley_4096 }; krb5_algorithm_identifier *alglist[4]; @@ -214,5 +214,5 @@ index 259e95c6c2..5ee39c085c 100644 TRACE(c, "PKINIT OpenSSL error: {str}", msg) -- -2.41.0 +2.45.1 diff --git a/0015-Replace-ssl.wrap_socket-for-tests.patch b/0015-Replace-ssl.wrap_socket-for-tests.patch index d5eb3f4..34cef96 100644 --- a/0015-Replace-ssl.wrap_socket-for-tests.patch +++ b/0015-Replace-ssl.wrap_socket-for-tests.patch @@ -1,4 +1,4 @@ -From 42e831da09bd196068aeb7fe6bfe380bb46b846c Mon Sep 17 00:00:00 2001 +From e92365b510a2407eaceaec90836f5c713403d75f Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 19 Jul 2023 13:43:17 +0200 Subject: [PATCH] Replace ssl.wrap_socket() for tests @@ -60,5 +60,5 @@ index 58759696b6..d1d10d733c 100755 os.write(sys.stdout.fileno(), b'proxy server ready\n') server.serve_forever() -- -2.41.0 +2.45.1 diff --git a/0016-Eliminate-old-style-function-declarations.patch b/0016-Eliminate-old-style-function-declarations.patch new file mode 100644 index 0000000..2b07a72 --- /dev/null +++ b/0016-Eliminate-old-style-function-declarations.patch @@ -0,0 +1,10685 @@ +From 1ad0abf12b212d19ac7b3903deeaf7fff4e2c3cf Mon Sep 17 00:00:00 2001 +From: Ken Hornstein +Date: Fri, 9 Jun 2023 23:53:53 -0400 +Subject: [PATCH] Eliminate old-style function declarations + +The C2x standard removes support for non-prototype function +declarations, and clang 15 issues warnings for them +(https://reviews.llvm.org/D122895). Add -Werror=strict-prototypes to +the build and fix all of the non-prototype declarations and +definitions. + +For RPC code, try to be consistent with libtirpc and recent *BSD +versions of rpcgen. This includes casting each time a concrete +function is used as an xdrproc_t value, since each XDR per-type +function accepts a different object pointer type. A few invocations +of xdrproc_t values pass a third argument with value LASTUNSIGNED, +even though XDR per-type functions accept only two parameters. +libtirpc has removed these third arguments; do so here as well. + +[ghudson@mit.edu: added -Werror=strict-prototypes and fixed +declarations it breaks under gcc and clang; added xdrproc_t changes; +rewrote commit message; style changes] + +(cherry picked from commit 4b9d7f7c107f01a61600fddcd8cde3812d0366a2) +--- + src/aclocal.m4 | 2 +- + src/appl/gss-sample/gss-client.c | 29 +--- + src/appl/gss-sample/gss-misc.c | 26 +-- + src/appl/gss-sample/gss-server.c | 2 +- + src/appl/user_user/server.c | 5 +- + src/clients/kdestroy/kdestroy.c | 2 +- + src/clients/kinit/kinit.c | 4 +- + src/clients/klist/klist.c | 2 +- + src/clients/ksu/authorization.c | 95 ++++------ + src/clients/ksu/ccache.c | 108 ++++-------- + src/clients/ksu/heuristic.c | 94 ++++------ + src/clients/ksu/krb_auth_su.c | 49 ++---- + src/clients/ksu/main.c | 40 ++--- + src/clients/kvno/kvno.c | 2 +- + src/include/gssrpc/auth_gssapi.h | 10 +- + src/include/gssrpc/xdr.h | 3 +- + src/include/k5-int.h | 2 +- + src/include/k5-plugin.h | 2 +- + src/include/net-server.h | 6 +- + src/kadmin/cli/getdate.y | 3 - + src/kadmin/cli/kadmin.c | 6 +- + src/kadmin/cli/keytab.c | 4 +- + src/kadmin/dbutil/kdb5_create.c | 16 +- + src/kadmin/dbutil/kdb5_destroy.c | 4 +- + src/kadmin/dbutil/kdb5_stash.c | 4 +- + src/kadmin/dbutil/kdb5_util.c | 24 +-- + src/kadmin/dbutil/ovload.c | 14 +- + src/kadmin/dbutil/strtok.c | 4 +- + src/kadmin/ktutil/ktutil.c | 45 ++--- + src/kadmin/ktutil/ktutil_funcs.c | 37 ++-- + src/kadmin/server/ipropd_svc.c | 24 +-- + src/kadmin/server/kadm_rpc_svc.c | 162 +++++++++--------- + src/kadmin/server/ovsec_kadmd.c | 4 +- + src/kdc/t_ndr.c | 2 +- + src/kdc/t_replay.c | 6 +- + src/kprop/kpropd.c | 2 +- + src/kprop/kproplog.c | 4 +- + src/lib/apputils/net-server.c | 7 +- + src/lib/crypto/builtin/aes/aes-gen.c | 18 +- + .../crypto/builtin/camellia/camellia-gen.c | 18 +- + src/lib/crypto/builtin/sha1/t_shs.c | 7 +- + src/lib/crypto/builtin/sha1/t_shs3.c | 7 +- + src/lib/crypto/crypto_tests/aes-test.c | 8 +- + src/lib/crypto/crypto_tests/camellia-test.c | 8 +- + src/lib/crypto/crypto_tests/t_cf2.c | 4 +- + src/lib/crypto/crypto_tests/t_cts.c | 2 +- + src/lib/crypto/crypto_tests/t_encrypt.c | 2 +- + src/lib/crypto/crypto_tests/t_fork.c | 2 +- + src/lib/crypto/crypto_tests/t_hmac.c | 3 +- + src/lib/crypto/crypto_tests/t_mddriver.c | 25 ++- + src/lib/crypto/crypto_tests/t_nfold.c | 16 +- + src/lib/crypto/crypto_tests/t_prf.c | 2 +- + src/lib/crypto/crypto_tests/t_sha2.c | 2 +- + src/lib/gssapi/generic/t_seqstate.c | 2 +- + src/lib/gssapi/krb5/accept_sec_context.c | 76 +++----- + src/lib/gssapi/krb5/compare_name.c | 7 +- + src/lib/gssapi/krb5/context_time.c | 6 +- + src/lib/gssapi/krb5/delete_sec_context.c | 7 +- + src/lib/gssapi/krb5/disp_name.c | 9 +- + src/lib/gssapi/krb5/disp_status.c | 11 +- + src/lib/gssapi/krb5/export_sec_context.c | 7 +- + src/lib/gssapi/krb5/gssapi_krb5.c | 4 +- + src/lib/gssapi/krb5/import_name.c | 8 +- + src/lib/gssapi/krb5/import_sec_context.c | 10 +- + src/lib/gssapi/krb5/indicate_mechs.c | 4 +- + src/lib/gssapi/krb5/init_sec_context.c | 55 ++---- + src/lib/gssapi/krb5/inq_context.c | 17 +- + src/lib/gssapi/krb5/inq_cred.c | 26 +-- + src/lib/gssapi/krb5/inq_names.c | 6 +- + src/lib/gssapi/krb5/k5seal.c | 38 ++-- + src/lib/gssapi/krb5/k5unseal.c | 51 ++---- + src/lib/gssapi/krb5/process_context_token.c | 8 +- + src/lib/gssapi/krb5/rel_cred.c | 4 +- + src/lib/gssapi/krb5/rel_name.c | 4 +- + src/lib/gssapi/krb5/rel_oid.c | 8 +- + src/lib/gssapi/krb5/ser_sctx.c | 16 +- + src/lib/gssapi/krb5/util_cksum.c | 6 +- + src/lib/gssapi/krb5/util_seed.c | 5 +- + src/lib/gssapi/krb5/util_seqnum.c | 19 +- + src/lib/gssapi/krb5/val_cred.c | 4 +- + src/lib/gssapi/krb5/wrap_size_limit.c | 11 +- + .../gssapi/mechglue/g_accept_sec_context.c | 31 +--- + src/lib/gssapi/mechglue/g_acquire_cred.c | 95 +++------- + .../gssapi/mechglue/g_acquire_cred_with_pw.c | 56 ++---- + src/lib/gssapi/mechglue/g_canon_name.c | 10 +- + src/lib/gssapi/mechglue/g_compare_name.c | 12 +- + src/lib/gssapi/mechglue/g_context_time.c | 10 +- + .../gssapi/mechglue/g_delete_sec_context.c | 10 +- + src/lib/gssapi/mechglue/g_dsp_name.c | 12 +- + src/lib/gssapi/mechglue/g_dsp_status.c | 22 +-- + src/lib/gssapi/mechglue/g_dup_name.c | 8 +- + src/lib/gssapi/mechglue/g_exp_sec_context.c | 10 +- + src/lib/gssapi/mechglue/g_export_name.c | 8 +- + src/lib/gssapi/mechglue/g_glue.c | 75 +++----- + src/lib/gssapi/mechglue/g_imp_name.c | 18 +- + src/lib/gssapi/mechglue/g_imp_sec_context.c | 11 +- + src/lib/gssapi/mechglue/g_init_sec_context.c | 37 +--- + src/lib/gssapi/mechglue/g_initialize.c | 22 +-- + src/lib/gssapi/mechglue/g_inq_cred.c | 31 +--- + src/lib/gssapi/mechglue/g_inq_names.c | 8 +- + src/lib/gssapi/mechglue/g_mechname.c | 14 +- + src/lib/gssapi/mechglue/g_oid_ops.c | 27 +-- + src/lib/gssapi/mechglue/g_process_context.c | 10 +- + src/lib/gssapi/mechglue/g_rel_buffer.c | 6 +- + src/lib/gssapi/mechglue/g_rel_cred.c | 7 +- + src/lib/gssapi/mechglue/g_rel_name.c | 7 +- + src/lib/gssapi/mechglue/g_rel_oid_set.c | 6 +- + src/lib/gssapi/mechglue/g_sign.c | 29 +--- + src/lib/gssapi/mechglue/g_store_cred.c | 48 ++---- + src/lib/gssapi/mechglue/g_unseal.c | 35 +--- + src/lib/gssapi/mechglue/g_unwrap_aead.c | 19 +- + src/lib/gssapi/mechglue/g_unwrap_iov.c | 15 +- + src/lib/gssapi/mechglue/g_verify.c | 30 +--- + src/lib/gssapi/mechglue/g_wrap_aead.c | 39 ++--- + src/lib/gssapi/mechglue/g_wrap_iov.c | 43 +---- + src/lib/kadm5/clnt/client_rpc.c | 1 + + src/lib/kadm5/kadm_rpc.h | 45 ----- + src/lib/kadm5/kadm_rpc_xdr.c | 37 ++-- + src/lib/kadm5/misc_free.c | 5 +- + src/lib/kadm5/srv/adb_xdr.c | 6 +- + src/lib/kadm5/srv/svr_principal.c | 12 +- + src/lib/kadm5/str_conv.c | 18 +- + src/lib/kadm5/t_kadm5.c | 22 +-- + src/lib/kdb/kdb5.c | 8 +- + src/lib/kdb/kdb_cpw.c | 32 +--- + src/lib/kdb/keytab.c | 19 +- + src/lib/kdb/t_stringattr.c | 2 +- + src/lib/krad/packet.c | 2 +- + src/lib/krad/t_attr.c | 2 +- + src/lib/krad/t_attrset.c | 2 +- + src/lib/krad/t_code.c | 2 +- + src/lib/krb5/ccache/cc_keyring.c | 2 +- + src/lib/krb5/krb/plugin.c | 2 +- + src/lib/krb5/krb/t_authdata.c | 2 +- + src/lib/krb5/krb/t_response_items.c | 2 +- + src/lib/krb5/krb/t_ser.c | 8 +- + src/lib/krb5/krb/t_sname_match.c | 2 +- + src/lib/krb5/krb/t_valid_times.c | 2 +- + src/lib/krb5/rcache/t_memrcache.c | 2 +- + src/lib/rpc/auth_gss.c | 4 +- + src/lib/rpc/auth_gssapi.c | 14 +- + src/lib/rpc/auth_gssapi_misc.c | 4 +- + src/lib/rpc/authunix_prot.c | 3 +- + src/lib/rpc/clnt_perror.c | 1 - + src/lib/rpc/clnt_raw.c | 2 +- + src/lib/rpc/dyn.c | 85 ++++----- + src/lib/rpc/pmap_clnt.c | 9 +- + src/lib/rpc/pmap_getmaps.c | 5 +- + src/lib/rpc/pmap_getport.c | 6 +- + src/lib/rpc/pmap_prot2.c | 3 +- + src/lib/rpc/pmap_rmt.c | 10 +- + src/lib/rpc/rpc_prot.c | 4 +- + src/lib/rpc/svc.c | 4 +- + src/lib/rpc/svc_auth_gss.c | 10 +- + src/lib/rpc/svc_auth_gssapi.c | 28 +-- + src/lib/rpc/svc_simple.c | 4 +- + src/lib/rpc/unit-test/client.c | 18 +- + src/lib/rpc/unit-test/rpc_test_clnt.c | 4 +- + src/lib/rpc/unit-test/rpc_test_svc.c | 16 +- + src/lib/rpc/unit-test/server.c | 2 +- + src/lib/rpc/xdr.c | 4 +- + src/lib/rpc/xdr_array.c | 4 +- + src/lib/rpc/xdr_rec.c | 13 +- + src/lib/rpc/xdr_reference.c | 4 +- + src/lib/rpc/xdr_sizeof.c | 29 +--- + src/plugins/kdb/db2/db2_exp.c | 4 +- + src/plugins/kdb/db2/libdb2/btree/bt_close.c | 10 +- + src/plugins/kdb/db2/libdb2/btree/bt_conv.c | 13 +- + src/plugins/kdb/db2/libdb2/btree/bt_delete.c | 34 +--- + src/plugins/kdb/db2/libdb2/btree/bt_get.c | 6 +- + src/plugins/kdb/db2/libdb2/btree/bt_open.c | 12 +- + .../kdb/db2/libdb2/btree/bt_overflow.c | 16 +- + src/plugins/kdb/db2/libdb2/btree/bt_page.c | 8 +- + src/plugins/kdb/db2/libdb2/btree/bt_put.c | 11 +- + src/plugins/kdb/db2/libdb2/btree/bt_search.c | 17 +- + src/plugins/kdb/db2/libdb2/btree/bt_seq.c | 27 +-- + src/plugins/kdb/db2/libdb2/btree/bt_split.c | 42 +---- + src/plugins/kdb/db2/libdb2/btree/bt_utils.c | 18 +- + src/plugins/kdb/db2/libdb2/db/db.c | 26 ++- + src/plugins/kdb/db2/libdb2/hash/dbm.c | 50 ++---- + src/plugins/kdb/db2/libdb2/hash/hash.c | 94 +++------- + src/plugins/kdb/db2/libdb2/hash/hash_bigkey.c | 35 +--- + src/plugins/kdb/db2/libdb2/hash/hash_func.c | 16 +- + src/plugins/kdb/db2/libdb2/hash/hash_log2.c | 3 +- + src/plugins/kdb/db2/libdb2/hash/hash_page.c | 121 ++++--------- + src/plugins/kdb/db2/libdb2/hash/hsearch.c | 9 +- + src/plugins/kdb/db2/libdb2/mpool/mpool.c | 54 ++---- + src/plugins/kdb/db2/libdb2/recno/rec_close.c | 7 +- + src/plugins/kdb/db2/libdb2/recno/rec_delete.c | 14 +- + src/plugins/kdb/db2/libdb2/recno/rec_get.c | 22 +-- + src/plugins/kdb/db2/libdb2/recno/rec_open.c | 9 +- + src/plugins/kdb/db2/libdb2/recno/rec_put.c | 12 +- + src/plugins/kdb/db2/libdb2/recno/rec_search.c | 5 +- + src/plugins/kdb/db2/libdb2/recno/rec_seq.c | 5 +- + src/plugins/kdb/db2/libdb2/recno/rec_utils.c | 6 +- + src/plugins/kdb/db2/libdb2/test/dbtest.c | 59 ++----- + src/plugins/kdb/db2/pol_xdr.c | 2 +- + .../kdb/ldap/ldap_util/kdb5_ldap_util.c | 4 +- + src/plugins/kdb/lmdb/kdb_lmdb.c | 4 +- + src/plugins/kdb/test/kdb_test.c | 4 +- + .../preauth/pkinit/pkinit_crypto_openssl.c | 4 +- + src/plugins/preauth/spake/t_vectors.c | 2 +- + src/tests/asn.1/krb5_decode_test.c | 5 +- + src/tests/asn.1/krb5_encode_test.c | 13 +- + src/tests/asn.1/t_trval.c | 14 +- + src/tests/asn.1/trval.c | 73 +++----- + src/tests/conccache.c | 4 +- + src/tests/create/kdb5_mkdums.c | 16 +- + src/tests/forward.c | 2 +- + src/tests/gss-threads/gss-client.c | 4 +- + src/tests/gss-threads/gss-server.c | 2 +- + src/tests/gssapi/reload.c | 2 +- + src/tests/gssapi/t_add_cred.c | 2 +- + src/tests/gssapi/t_enctypes.c | 2 +- + src/tests/gssapi/t_invalid.c | 2 +- + src/tests/gssapi/t_oid.c | 2 +- + src/tests/gssapi/t_spnego.c | 2 +- + src/tests/hammer/kdc5_hammer.c | 36 ++-- + src/tests/kdbtest.c | 2 +- + src/tests/misc/test_getpw.c | 2 +- + src/tests/plugorder.c | 2 +- + src/tests/shlib/t_loader.c | 2 +- + src/tests/softpkcs11/main.c | 2 +- + src/tests/t_inetd.c | 7 +- + src/tests/test1.c | 4 +- + src/tests/verify/kdb5_verify.c | 17 +- + src/util/et/error_message.c | 2 +- + src/util/et/test_et.c | 3 +- + src/util/profile/prof_init.c | 2 +- + src/util/profile/t_profile.c | 22 +-- + src/util/profile/test_load.c | 2 +- + src/util/profile/test_parse.c | 5 +- + src/util/profile/test_profile.c | 10 +- + src/util/profile/test_vtable.c | 3 +- + src/util/ss/error.c | 13 +- + src/util/ss/execute_cmd.c | 23 +-- + src/util/ss/help.c | 115 ++++++------- + src/util/ss/invocation.c | 13 +- + src/util/ss/list_rqs.c | 11 +- + src/util/ss/listen.c | 32 ++-- + src/util/ss/pager.c | 10 +- + src/util/ss/parse.c | 6 +- + src/util/ss/prompt.c | 7 +- + src/util/ss/request_tbl.c | 11 +- + src/util/ss/requests.c | 2 +- + src/util/ss/ss.h | 1 - + src/util/ss/ss_internal.h | 3 +- + src/util/support/plugins.c | 10 +- + src/util/support/t_hashtab.c | 6 +- + src/util/support/t_hex.c | 3 +- + src/util/support/t_json.c | 2 +- + src/util/support/t_k5buf.c | 16 +- + src/util/support/t_unal.c | 3 +- + 253 files changed, 1379 insertions(+), 2717 deletions(-) + +diff --git a/src/aclocal.m4 b/src/aclocal.m4 +index 3331970930..040d5bdd0c 100644 +--- a/src/aclocal.m4 ++++ b/src/aclocal.m4 +@@ -546,7 +546,7 @@ if test "$GCC" = yes ; then + TRY_WARN_CC_FLAG(-Wno-format-zero-length) + # Other flags here may not be supported on some versions of + # gcc that people want to use. +- for flag in overflow strict-overflow missing-format-attribute missing-prototypes return-type missing-braces parentheses switch unused-function unused-label unused-variable unused-value unknown-pragmas sign-compare newline-eof error=uninitialized no-maybe-uninitialized error=pointer-arith error=int-conversion error=incompatible-pointer-types error=discarded-qualifiers error=implicit-int ; do ++ for flag in overflow strict-overflow missing-format-attribute missing-prototypes return-type missing-braces parentheses switch unused-function unused-label unused-variable unused-value unknown-pragmas sign-compare newline-eof error=uninitialized no-maybe-uninitialized error=pointer-arith error=int-conversion error=incompatible-pointer-types error=discarded-qualifiers error=implicit-int error=strict-prototypes; do + TRY_WARN_CC_FLAG(-W$flag) + done + # old-style-definition? generates many, many warnings +diff --git a/src/appl/gss-sample/gss-client.c b/src/appl/gss-sample/gss-client.c +index 6e2aa33690..0722ae196f 100644 +--- a/src/appl/gss-sample/gss-client.c ++++ b/src/appl/gss-sample/gss-client.c +@@ -75,7 +75,7 @@ static gss_OID_desc gss_spnego_mechanism_oid_desc = + {6, (void *)"\x2b\x06\x01\x05\x05\x02"}; + + static void +-usage() ++usage(void) + { + fprintf(stderr, "Usage: gss-client [-port port] [-mech mechanism] " + "[-spnego] [-d]\n"); +@@ -359,9 +359,7 @@ client_establish_context(int s, char *service_name, OM_uint32 gss_flags, + } + + static void +-read_file(file_name, in_buf) +- char *file_name; +- gss_buffer_t in_buf; ++read_file(char *file_name, gss_buffer_t in_buf) + { + int fd, count; + struct stat stat_buf; +@@ -431,21 +429,10 @@ read_file(file_name, in_buf) + * verifies it with gss_verify. -1 is returned if any step fails, + * otherwise 0 is returned. */ + static int +-call_server(host, port, oid, service_name, gss_flags, auth_flag, +- wrap_flag, encrypt_flag, mic_flag, v1_format, msg, use_file, +- mcount, username, password) +- char *host; +- u_short port; +- gss_OID oid; +- char *service_name; +- OM_uint32 gss_flags; +- int auth_flag, wrap_flag, encrypt_flag, mic_flag; +- int v1_format; +- char *msg; +- int use_file; +- int mcount; +- char *username; +- char *password; ++call_server(char *host, u_short port, gss_OID oid, char *service_name, ++ OM_uint32 gss_flags, int auth_flag, int wrap_flag, ++ int encrypt_flag, int mic_flag, int v1_format, char *msg, ++ int use_file, int mcount, char *username, char *password) + { + gss_ctx_id_t context = GSS_C_NO_CONTEXT; + gss_buffer_desc in_buf, out_buf; +@@ -774,9 +761,7 @@ worker_bee(void *unused) + } + + int +-main(argc, argv) +- int argc; +- char **argv; ++main(int argc, char **argv) + { + int i; + +diff --git a/src/appl/gss-sample/gss-misc.c b/src/appl/gss-sample/gss-misc.c +index 1d051edf1e..7eb4c7971d 100644 +--- a/src/appl/gss-sample/gss-misc.c ++++ b/src/appl/gss-sample/gss-misc.c +@@ -157,10 +157,7 @@ read_all(int fildes, void *data, unsigned int nbyte) + * if an error occurs or if it could not write all the data. + */ + int +-send_token(s, flags, tok) +- int s; +- int flags; +- gss_buffer_t tok; ++send_token(int s, int flags, gss_buffer_t tok) + { + int ret; + unsigned char char_flags = (unsigned char) flags; +@@ -230,10 +227,7 @@ send_token(s, flags, tok) + * and -1 if an error occurs or if it could not read all the data. + */ + int +-recv_token(s, flags, tok) +- int s; +- int *flags; +- gss_buffer_t tok; ++recv_token(int s, int *flags, gss_buffer_t tok) + { + int ret; + unsigned char char_flags; +@@ -303,10 +297,7 @@ recv_token(s, flags, tok) + } + + static void +-display_status_1(m, code, type) +- char *m; +- OM_uint32 code; +- int type; ++display_status_1(char *m, OM_uint32 code, int type) + { + OM_uint32 min_stat; + gss_buffer_desc msg; +@@ -344,10 +335,7 @@ display_status_1(m, code, type) + * followed by a newline. + */ + void +-display_status(msg, maj_stat, min_stat) +- char *msg; +- OM_uint32 maj_stat; +- OM_uint32 min_stat; ++display_status(char *msg, OM_uint32 maj_stat, OM_uint32 min_stat) + { + display_status_1(msg, maj_stat, GSS_C_GSS_CODE); + display_status_1(msg, min_stat, GSS_C_MECH_CODE); +@@ -370,8 +358,7 @@ display_status(msg, maj_stat, min_stat) + */ + + void +-display_ctx_flags(flags) +- OM_uint32 flags; ++display_ctx_flags(OM_uint32 flags) + { + if (flags & GSS_C_DELEG_FLAG) + fprintf(display_file, "context flag: GSS_C_DELEG_FLAG\n"); +@@ -388,8 +375,7 @@ display_ctx_flags(flags) + } + + void +-print_token(tok) +- gss_buffer_t tok; ++print_token(gss_buffer_t tok) + { + unsigned int i; + unsigned char *p = tok->value; +diff --git a/src/appl/gss-sample/gss-server.c b/src/appl/gss-sample/gss-server.c +index 9b6ce9ffb3..0e9c857e56 100644 +--- a/src/appl/gss-sample/gss-server.c ++++ b/src/appl/gss-sample/gss-server.c +@@ -73,7 +73,7 @@ static OM_uint32 + showLocalIdentity(OM_uint32 *minor, gss_name_t name); + + static void +-usage() ++usage(void) + { + fprintf(stderr, "Usage: gss-server [-port port] [-verbose] [-once]"); + #ifdef _WIN32 +diff --git a/src/appl/user_user/server.c b/src/appl/user_user/server.c +index f2b5b614e3..afb3d2bcba 100644 +--- a/src/appl/user_user/server.c ++++ b/src/appl/user_user/server.c +@@ -39,9 +39,8 @@ + + /* fd 0 is a tcp socket used to talk to the client */ + +-int main(argc, argv) +- int argc; +- char *argv[]; ++int ++main(int argc, char *argv[]) + { + krb5_data pname_data, tkt_data; + int sock = 0; +diff --git a/src/clients/kdestroy/kdestroy.c b/src/clients/kdestroy/kdestroy.c +index 774b729fdb..48f672a1e8 100644 +--- a/src/clients/kdestroy/kdestroy.c ++++ b/src/clients/kdestroy/kdestroy.c +@@ -47,7 +47,7 @@ char *progname; + + + static void +-usage() ++usage(void) + { + fprintf(stderr, _("Usage: %s [-A] [-q] [-c cache_name] [-p princ_name]\n"), + progname); +diff --git a/src/clients/kinit/kinit.c b/src/clients/kinit/kinit.c +index f4c7b2b842..7a33ffae59 100644 +--- a/src/clients/kinit/kinit.c ++++ b/src/clients/kinit/kinit.c +@@ -45,7 +45,7 @@ + #ifdef HAVE_PWD_H + #include + static char * +-get_name_from_os() ++get_name_from_os(void) + { + struct passwd *pw; + +@@ -137,7 +137,7 @@ const char *shopts = "r:fpFPn54aAVl:s:c:kit:T:RS:vX:CEI:"; + #define USAGE_BREAK "\n\t" + + static void +-usage() ++usage(void) + { + fprintf(stderr, + _("Usage: %s [-V] [-l lifetime] [-s start_time] " +diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c +index dcdc5a2d59..c797b1698f 100644 +--- a/src/clients/klist/klist.c ++++ b/src/clients/klist/klist.c +@@ -80,7 +80,7 @@ static void fillit(FILE *, unsigned int, int); + #define KEYTAB 2 + + static void +-usage() ++usage(void) + { + fprintf(stderr, _("Usage: %s [-e] [-V] [[-c] [-l] [-A] [-d] [-f] [-s] " + "[-a [-n]]] [-k [-i] [-t] [-K]] [-C] [name]\n"), +diff --git a/src/clients/ksu/authorization.c b/src/clients/ksu/authorization.c +index fb9d5d0942..17a8a8f2f0 100644 +--- a/src/clients/ksu/authorization.c ++++ b/src/clients/ksu/authorization.c +@@ -30,9 +30,8 @@ + + static void auth_cleanup (FILE *, FILE *, char *); + +-krb5_boolean fowner(fp, uid) +- FILE *fp; +- uid_t uid; ++krb5_boolean ++fowner(FILE *fp, uid_t uid) + { + struct stat sbuf; + +@@ -59,16 +58,10 @@ krb5_boolean fowner(fp, uid) + * + */ + +-krb5_error_code krb5_authorization(context, principal, luser, +- cmd, ok, out_fcmd) +-/* IN */ +- krb5_context context; +- krb5_principal principal; +- const char *luser; +- char *cmd; +- /* OUT */ +- krb5_boolean *ok; +- char **out_fcmd; ++krb5_error_code ++krb5_authorization(krb5_context context, krb5_principal principal, ++ const char *luser, char *cmd, krb5_boolean *ok, ++ char **out_fcmd) + { + struct passwd *pwd; + char *princname; +@@ -178,10 +171,8 @@ any tokens after the principal name FALSE is returned. + + ***********************************************************/ + +-krb5_error_code k5login_lookup (fp, princname, found) +- FILE *fp; +- char *princname; +- krb5_boolean *found; ++krb5_error_code ++k5login_lookup(FILE *fp, char *princname, krb5_boolean *found) + { + + krb5_error_code retval; +@@ -240,12 +231,9 @@ if princname is found{ + + + ***********************************************************/ +-krb5_error_code k5users_lookup (fp, princname, cmd, found, out_fcmd) +- FILE *fp; +- char *princname; +- char *cmd; +- krb5_boolean *found; +- char **out_fcmd; ++krb5_error_code ++k5users_lookup(FILE *fp, char *princname, char *cmd, ++ krb5_boolean *found, char **out_fcmd) + { + krb5_error_code retval; + char * line; +@@ -328,10 +316,8 @@ resolves it into a full path name. + + ************************************************/ + +-krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) +- char *fcmd; +- char ***out_fcmd; +- char **out_err; ++krb5_boolean ++fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) + { + char * err; + char ** tmp_fcmd; +@@ -407,8 +393,8 @@ cmd_single - checks if cmd consists of a path + + ********************************************/ + +-krb5_boolean cmd_single(cmd) +- char * cmd; ++krb5_boolean ++cmd_single(char *cmd) + { + + if ( ( strrchr( cmd, '/')) == NULL){ +@@ -423,9 +409,8 @@ cmd_arr_cmp_postfix - compares a command with the postfix + of fcmd + ********************************************/ + +-int cmd_arr_cmp_postfix(fcmd_arr, cmd) +- char **fcmd_arr; +- char *cmd; ++int ++cmd_arr_cmp_postfix(char **fcmd_arr, char *cmd) + { + char * temp_fcmd; + char *ptr; +@@ -457,9 +442,8 @@ cmd_arr_cmp - checks if cmd matches any + + **********************************************/ + +-int cmd_arr_cmp (fcmd_arr, cmd) +- char **fcmd_arr; +- char *cmd; ++int ++cmd_arr_cmp(char **fcmd_arr, char *cmd) + { + int result =1; + int i = 0; +@@ -475,10 +459,8 @@ int cmd_arr_cmp (fcmd_arr, cmd) + } + + +-krb5_boolean find_first_cmd_that_exists(fcmd_arr, cmd_out, err_out) +- char **fcmd_arr; +- char **cmd_out; +- char **err_out; ++krb5_boolean ++find_first_cmd_that_exists(char **fcmd_arr, char **cmd_out, char **err_out) + { + struct stat st_temp; + int i = 0; +@@ -517,12 +499,9 @@ returns 1 if there is an error, 0 if no error. + + ***************************************************************/ + +-int match_commands (fcmd, cmd, match, cmd_out, err_out) +- char *fcmd; +- char *cmd; +- krb5_boolean *match; +- char **cmd_out; +- char **err_out; ++int ++match_commands(char *fcmd, char *cmd, krb5_boolean *match, ++ char **cmd_out, char **err_out) + { + char ** fcmd_arr; + char * err; +@@ -566,11 +545,8 @@ int match_commands (fcmd, cmd, match, cmd_out, err_out) + is set to null if eof. + *********************************************************/ + +-krb5_error_code get_line (fp, out_line) +-/* IN */ +- FILE *fp; +- /* OUT */ +- char **out_line; ++krb5_error_code ++get_line(FILE *fp, char **out_line) + { + char * line, *r, *newline , *line_ptr; + int chunk_count = 1; +@@ -615,9 +591,8 @@ will be returned as part of the first token. + Note: this routine reuses the space pointed to by line + ******************************************************/ + +-char * get_first_token (line, lnext) +- char *line; +- char **lnext; ++char * ++get_first_token(char *line, char **lnext) + { + + char * lptr, * out_ptr; +@@ -651,8 +626,8 @@ Note: that this function modifies the stream + lnext to the next tocken. + **********************************************************/ + +-char * get_next_token (lnext) +- char **lnext; ++char * ++get_next_token (char **lnext) + { + char * lptr, * out_ptr; + +@@ -677,10 +652,8 @@ char * get_next_token (lnext) + return out_ptr; + } + +-static void auth_cleanup(users_fp, login_fp, princname) +- FILE *users_fp; +- FILE *login_fp; +- char *princname; ++static void ++auth_cleanup(FILE *users_fp, FILE *login_fp, char *princname) + { + + free (princname); +@@ -690,8 +663,8 @@ static void auth_cleanup(users_fp, login_fp, princname) + fclose(login_fp); + } + +-void init_auth_names(pw_dir) +- char *pw_dir; ++void ++init_auth_names(char *pw_dir) + { + const char *sep; + int r1, r2; +diff --git a/src/clients/ksu/ccache.c b/src/clients/ksu/ccache.c +index cbb9aa2b85..cca9ce2dfc 100644 +--- a/src/clients/ksu/ccache.c ++++ b/src/clients/ksu/ccache.c +@@ -40,24 +40,18 @@ copies the default cache into the secondary cache, + + ************************************************************************/ + +-void show_credential(); ++void show_credential(krb5_context, krb5_creds *, krb5_ccache); + + /* modifies only the cc_other, the algorithm may look a bit funny, + but I had to do it this way, since remove function did not come + with k5 beta 3 release. + */ + +-krb5_error_code krb5_ccache_copy(context, cc_def, target_principal, cc_target, +- restrict_creds, primary_principal, stored) +-/* IN */ +- krb5_context context; +- krb5_ccache cc_def; +- krb5_principal target_principal; +- krb5_ccache cc_target; +- krb5_boolean restrict_creds; +- krb5_principal primary_principal; +- /* OUT */ +- krb5_boolean *stored; ++krb5_error_code ++krb5_ccache_copy(krb5_context context, krb5_ccache cc_def, ++ krb5_principal target_principal, krb5_ccache cc_target, ++ krb5_boolean restrict_creds, krb5_principal primary_principal, ++ krb5_boolean *stored) + { + int i=0; + krb5_error_code retval=0; +@@ -105,11 +99,9 @@ krb5_error_code krb5_ccache_copy(context, cc_def, target_principal, cc_target, + } + + +-krb5_error_code krb5_store_all_creds(context, cc, creds_def, creds_other) +- krb5_context context; +- krb5_ccache cc; +- krb5_creds **creds_def; +- krb5_creds **creds_other; ++krb5_error_code ++krb5_store_all_creds(krb5_context context, krb5_ccache cc, ++ krb5_creds **creds_def, krb5_creds **creds_other) + { + + int i = 0; +@@ -173,10 +165,8 @@ krb5_error_code krb5_store_all_creds(context, cc, creds_def, creds_other) + return 0; + } + +-krb5_boolean compare_creds(context, cred1, cred2) +- krb5_context context; +- krb5_creds *cred1; +- krb5_creds *cred2; ++krb5_boolean ++compare_creds(krb5_context context, krb5_creds *cred1, krb5_creds *cred2) + { + krb5_boolean retval; + +@@ -188,13 +178,9 @@ krb5_boolean compare_creds(context, cred1, cred2) + return retval; + } + +- +- +- +-krb5_error_code krb5_get_nonexp_tkts(context, cc, creds_array) +- krb5_context context; +- krb5_ccache cc; +- krb5_creds ***creds_array; ++krb5_error_code ++krb5_get_nonexp_tkts(krb5_context context, krb5_ccache cc, ++ krb5_creds ***creds_array) + { + + krb5_creds creds, temp_tktq, temp_tkt; +@@ -262,10 +248,8 @@ krb5_error_code krb5_get_nonexp_tkts(context, cc, creds_array) + + } + +- +-krb5_error_code krb5_check_exp(context, tkt_time) +- krb5_context context; +- krb5_ticket_times tkt_time; ++krb5_error_code ++krb5_check_exp(krb5_context context, krb5_ticket_times tkt_time) + { + krb5_error_code retval =0; + krb5_timestamp currenttime; +@@ -290,9 +274,8 @@ krb5_error_code krb5_check_exp(context, tkt_time) + return 0; + } + +- +-char *flags_string(cred) +- krb5_creds *cred; ++char * ++flags_string(krb5_creds *cred) + { + static char buf[32]; + int i = 0; +@@ -323,7 +306,8 @@ char *flags_string(cred) + return(buf); + } + +-void printtime(krb5_timestamp ts) ++void ++printtime(krb5_timestamp ts) + { + char fmtbuf[18], fill = ' '; + +@@ -333,9 +317,7 @@ void printtime(krb5_timestamp ts) + + + krb5_error_code +-krb5_get_login_princ(luser, princ_list) +- const char *luser; +- char ***princ_list; ++krb5_get_login_princ(const char *luser, char ***princ_list) + { + struct stat sbuf; + struct passwd *pwd; +@@ -420,13 +402,8 @@ krb5_get_login_princ(luser, princ_list) + return 0; + } + +- +- + void +-show_credential(context, cred, cc) +- krb5_context context; +- krb5_creds *cred; +- krb5_ccache cc; ++show_credential(krb5_context context, krb5_creds *cred, krb5_ccache cc) + { + krb5_error_code retval; + char *name, *sname, *flags; +@@ -519,11 +496,9 @@ gen_sym(krb5_context context, char **sym_out) + return 0; + } + +-krb5_error_code krb5_ccache_overwrite(context, ccs, cct, primary_principal) +- krb5_context context; +- krb5_ccache ccs; +- krb5_ccache cct; +- krb5_principal primary_principal; ++krb5_error_code ++krb5_ccache_overwrite(krb5_context context, krb5_ccache ccs, krb5_ccache cct, ++ krb5_principal primary_principal) + { + krb5_error_code retval=0; + krb5_principal temp_principal; +@@ -560,14 +535,10 @@ krb5_error_code krb5_ccache_overwrite(context, ccs, cct, primary_principal) + return retval; + } + +-krb5_error_code krb5_store_some_creds(context, cc, creds_def, creds_other, prst, +- stored) +- krb5_context context; +- krb5_ccache cc; +- krb5_creds **creds_def; +- krb5_creds **creds_other; +- krb5_principal prst; +- krb5_boolean *stored; ++krb5_error_code ++krb5_store_some_creds(krb5_context context, krb5_ccache cc, ++ krb5_creds **creds_def, krb5_creds **creds_other, ++ krb5_principal prst, krb5_boolean *stored) + { + + int i = 0; +@@ -610,10 +581,8 @@ krb5_error_code krb5_store_some_creds(context, cc, creds_def, creds_other, prst, + return 0; + } + +-krb5_error_code krb5_ccache_filter (context, cc, prst) +- krb5_context context; +- krb5_ccache cc; +- krb5_principal prst; ++krb5_error_code ++krb5_ccache_filter(krb5_context context, krb5_ccache cc, krb5_principal prst) + { + + int i=0; +@@ -657,10 +626,9 @@ krb5_error_code krb5_ccache_filter (context, cc, prst) + return 0; + } + +-krb5_boolean krb5_find_princ_in_cred_list (context, creds_list, princ) +- krb5_context context; +- krb5_creds **creds_list; +- krb5_principal princ; ++krb5_boolean ++krb5_find_princ_in_cred_list(krb5_context context, krb5_creds **creds_list, ++ krb5_principal princ) + { + + int i = 0; +@@ -682,11 +650,9 @@ krb5_boolean krb5_find_princ_in_cred_list (context, creds_list, princ) + return temp_stored; + } + +-krb5_error_code krb5_find_princ_in_cache (context, cc, princ, found) +- krb5_context context; +- krb5_ccache cc; +- krb5_principal princ; +- krb5_boolean *found; ++krb5_error_code ++krb5_find_princ_in_cache(krb5_context context, krb5_ccache cc, ++ krb5_principal princ, krb5_boolean *found) + { + krb5_error_code retval; + krb5_creds ** creds_list = NULL; +diff --git a/src/clients/ksu/heuristic.c b/src/clients/ksu/heuristic.c +index 4f7280f4cb..e906de8ef0 100644 +--- a/src/clients/ksu/heuristic.c ++++ b/src/clients/ksu/heuristic.c +@@ -41,9 +41,8 @@ get_all_princ_from_file - retrieves all principal names + static void close_time (int, FILE *, int, FILE *); + static krb5_boolean find_str_in_list (char **, char *); + +-krb5_error_code get_all_princ_from_file (fp, plist) +- FILE *fp; +- char ***plist; ++krb5_error_code ++get_all_princ_from_file(FILE *fp, char ***plist) + { + + krb5_error_code retval; +@@ -92,10 +91,8 @@ list_union - combines list1 and list2 into combined_list. + or used by combined_list. + **************************************************************/ + +-krb5_error_code list_union(list1, list2, combined_list) +- char **list1; +- char **list2; +- char ***combined_list; ++krb5_error_code ++list_union(char **list1, char **list2, char ***combined_list) + { + + unsigned int c1 =0, c2 = 0, i=0, j=0; +@@ -141,11 +138,7 @@ krb5_error_code list_union(list1, list2, combined_list) + } + + krb5_error_code +-filter(fp, cmd, k5users_list, k5users_filt_list) +- FILE *fp; +- char *cmd; +- char **k5users_list; +- char ***k5users_filt_list; ++filter(FILE *fp, char *cmd, char **k5users_list, char ***k5users_filt_list) + { + + krb5_error_code retval =0; +@@ -195,10 +188,7 @@ filter(fp, cmd, k5users_list, k5users_filt_list) + } + + krb5_error_code +-get_authorized_princ_names(luser, cmd, princ_list) +- const char *luser; +- char *cmd; +- char ***princ_list; ++get_authorized_princ_names(const char *luser, char *cmd, char ***princ_list) + { + + struct passwd *pwd; +@@ -272,11 +262,8 @@ get_authorized_princ_names(luser, cmd, princ_list) + return 0; + } + +-static void close_time(k5users_flag, users_fp, k5login_flag, login_fp) +- int k5users_flag; +- FILE *users_fp; +- int k5login_flag; +- FILE *login_fp; ++static void ++close_time(int k5users_flag, FILE *users_fp, int k5login_flag, FILE *login_fp) + { + + if (!k5users_flag) fclose(users_fp); +@@ -284,9 +271,8 @@ static void close_time(k5users_flag, users_fp, k5login_flag, login_fp) + + } + +-static krb5_boolean find_str_in_list(list , elm) +- char **list; +- char *elm; ++static krb5_boolean ++find_str_in_list(char **list, char *elm) + { + + int i=0; +@@ -313,12 +299,9 @@ A principal is picked that has the best chance of getting in. + + **********************************************************************/ + +- +-krb5_error_code get_closest_principal(context, plist, client, found) +- krb5_context context; +- char **plist; +- krb5_principal *client; +- krb5_boolean *found; ++krb5_error_code ++get_closest_principal(krb5_context context, char **plist, ++ krb5_principal *client, krb5_boolean *found) + { + krb5_error_code retval =0; + krb5_principal temp_client, best_client = NULL; +@@ -385,12 +368,9 @@ find_either_ticket checks to see whether there is a ticket for the + end server or tgt, if neither is there the return FALSE, + *****************************************************************/ + +-krb5_error_code find_either_ticket (context, cc, client, end_server, found) +- krb5_context context; +- krb5_ccache cc; +- krb5_principal client; +- krb5_principal end_server; +- krb5_boolean *found; ++krb5_error_code ++find_either_ticket(krb5_context context, krb5_ccache cc, krb5_principal client, ++ krb5_principal end_server, krb5_boolean *found) + { + + krb5_principal kdc_server; +@@ -424,13 +404,9 @@ krb5_error_code find_either_ticket (context, cc, client, end_server, found) + return 0; + } + +- +-krb5_error_code find_ticket (context, cc, client, server, found) +- krb5_context context; +- krb5_ccache cc; +- krb5_principal client; +- krb5_principal server; +- krb5_boolean *found; ++krb5_error_code ++find_ticket(krb5_context context, krb5_ccache cc, krb5_principal client, ++ krb5_principal server, krb5_boolean *found) + { + + krb5_creds tgt, tgtq; +@@ -470,13 +446,9 @@ krb5_error_code find_ticket (context, cc, client, server, found) + return 0; + } + +- +- +-krb5_error_code find_princ_in_list (context, princ, plist, found) +- krb5_context context; +- krb5_principal princ; +- char **plist; +- krb5_boolean *found; ++krb5_error_code ++find_princ_in_list(krb5_context context, krb5_principal princ, char **plist, ++ krb5_boolean *found) + { + + int i=0; +@@ -516,21 +488,13 @@ path_out gets set to ... + + ***********************************************************************/ + +-krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, +- source_user, target_user, +- cc_source, options, cmd, +- hostname, client, path_out) +- krb5_context context; +- uid_t source_uid; +- uid_t target_uid; +- char *source_user; +- char *target_user; +- krb5_ccache cc_source; +- krb5_get_init_creds_opt *options; +- char *cmd; +- char *hostname; +- krb5_principal *client; +- int *path_out; ++krb5_error_code ++get_best_princ_for_target(krb5_context context, uid_t source_uid, ++ uid_t target_uid, char *source_user, ++ char *target_user, krb5_ccache cc_source, ++ krb5_get_init_creds_opt *options, char *cmd, ++ char *hostname, krb5_principal *client, ++ int *path_out) + { + + princ_info princ_trials[10]; +diff --git a/src/clients/ksu/krb_auth_su.c b/src/clients/ksu/krb_auth_su.c +index fb848dcab1..db10251f95 100644 +--- a/src/clients/ksu/krb_auth_su.c ++++ b/src/clients/ksu/krb_auth_su.c +@@ -29,18 +29,13 @@ + #include "ksu.h" + + +-void plain_dump_principal (); +- +-krb5_boolean krb5_auth_check(context, client_pname, hostname, options, +- target_user, cc, path_passwd, target_uid) +- krb5_context context; +- krb5_principal client_pname; +- char *hostname; +- krb5_get_init_creds_opt *options; +- char *target_user; +- uid_t target_uid; +- krb5_ccache cc; +- int *path_passwd; ++void plain_dump_principal(krb5_context, krb5_principal); ++ ++krb5_boolean ++krb5_auth_check(krb5_context context, krb5_principal client_pname, ++ char *hostname, krb5_get_init_creds_opt *options, ++ char *target_user, krb5_ccache cc, int *path_passwd, ++ uid_t target_uid) + { + krb5_principal client; + krb5_verify_init_creds_opt vfy_opts; +@@ -137,13 +132,10 @@ krb5_boolean krb5_auth_check(context, client_pname, hostname, options, + return (TRUE); + } + +-krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, +- creds_out) +- krb5_context context; +- krb5_principal client; +- krb5_get_init_creds_opt *options; +- krb5_boolean *zero_password; +- krb5_creds *creds_out; ++krb5_boolean ++ksu_get_tgt_via_passwd(krb5_context context, krb5_principal client, ++ krb5_get_init_creds_opt *options, ++ krb5_boolean *zero_password, krb5_creds *creds_out) + { + krb5_error_code code; + krb5_creds creds; +@@ -212,11 +204,8 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, + return (TRUE); + } + +- +-void dump_principal (context, str, p) +- krb5_context context; +- char *str; +- krb5_principal p; ++void ++dump_principal(krb5_context context, char *str, krb5_principal p) + { + char * stname; + krb5_error_code retval; +@@ -228,9 +217,8 @@ void dump_principal (context, str, p) + fprintf(stderr, " %s: %s\n", str, stname); + } + +-void plain_dump_principal (context, p) +- krb5_context context; +- krb5_principal p; ++void ++plain_dump_principal (krb5_context context, krb5_principal p) + { + char * stname; + krb5_error_code retval; +@@ -251,11 +239,8 @@ A principal is picked that has the best chance of getting in. + + **********************************************************************/ + +- +-krb5_error_code get_best_principal(context, plist, client) +- krb5_context context; +- char **plist; +- krb5_principal *client; ++krb5_error_code ++get_best_principal(krb5_context context, char **plist, krb5_principal *client) + { + krb5_error_code retval =0; + krb5_principal temp_client, best_client = NULL; +diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c +index 931f054041..2a351662c8 100644 +--- a/src/clients/ksu/main.c ++++ b/src/clients/ksu/main.c +@@ -70,7 +70,9 @@ static krb5_error_code resolve_target_cache(krb5_context ksu_context, + /* insure the proper specification of target user as well as catching + ill specified arguments to commands */ + +-void usage (){ ++void ++usage(void) ++{ + fprintf(stderr, + _("Usage: %s [target user] [-n principal] [-c source cachename] " + "[-k] [-r time] [-p|-P] [-f|-F] [-l lifetime] [-zZ] [-q] " +@@ -86,9 +88,7 @@ void usage (){ + static uid_t source_uid, target_uid; + + int +-main (argc, argv) +- int argc; +- char ** argv; ++main(int argc, char ** argv) + { + int hp =0; + int some_rest_copy = 0; +@@ -120,7 +120,6 @@ main (argc, argv) + char ** params; + int keep_target_cache = 0; + int child_pid, child_pgrp, ret_pid; +- extern char * getpass(), *crypt(); + int pargc; + char ** pargv; + krb5_boolean stored = FALSE, cc_reused = FALSE, given_princ = FALSE; +@@ -1049,11 +1048,10 @@ cleanup: + + #ifdef HAVE_GETUSERSHELL + +-int standard_shell(sh) +- char *sh; ++int ++standard_shell(char *sh) + { + char *cp; +- char *getusershell(); + + while ((cp = getusershell()) != NULL) + if (!strcmp(cp, sh)) +@@ -1063,7 +1061,8 @@ int standard_shell(sh) + + #endif /* HAVE_GETUSERSHELL */ + +-static char * ontty() ++static char * ++ontty(void) + { + char *p; + static char buf[MAXPATHLEN + 5]; +@@ -1080,10 +1079,8 @@ static char * ontty() + return (buf); + } + +- +-static int set_env_var(name, value) +- char *name; +- char *value; ++static int ++set_env_var(char *name, char *value) + { + char * env_var_buf; + +@@ -1092,9 +1089,8 @@ static int set_env_var(name, value) + + } + +-static void sweep_up(context, cc) +- krb5_context context; +- krb5_ccache cc; ++static void ++sweep_up(krb5_context context, krb5_ccache cc) + { + krb5_error_code retval; + +@@ -1122,11 +1118,7 @@ get_params is to be called for the -a option or -e option to + *****************************************************************/ + + krb5_error_code +-get_params(optindex, pargc, pargv, params) +- int *optindex; +- int pargc; +- char **pargv; +- char ***params; ++get_params(int *optindex, int pargc, char **pargv, char ***params) + { + + int i,j; +@@ -1159,10 +1151,8 @@ void print_status(const char *fmt, ...) + } + + krb5_error_code +-ksu_tgtname(context, server, client, tgtprinc) +- krb5_context context; +- const krb5_data *server, *client; +- krb5_principal *tgtprinc; ++ksu_tgtname(krb5_context context, const krb5_data *server, ++ const krb5_data *client, krb5_principal *tgtprinc) + { + return krb5_build_principal_ext(context, tgtprinc, client->length, client->data, + KRB5_TGS_NAME_SIZE, KRB5_TGS_NAME, +diff --git a/src/clients/kvno/kvno.c b/src/clients/kvno/kvno.c +index 03f72f596d..ac77a7d524 100644 +--- a/src/clients/kvno/kvno.c ++++ b/src/clients/kvno/kvno.c +@@ -39,7 +39,7 @@ static char *prog; + static int quiet = 0; + + static void +-xusage() ++xusage(void) + { + fprintf(stderr, _("usage: %s [-c ccache] [-e etype] [-k keytab] [-q] " + "[-u | -S sname]\n" +diff --git a/src/include/gssrpc/auth_gssapi.h b/src/include/gssrpc/auth_gssapi.h +index 9d94853228..63436a698a 100644 +--- a/src/include/gssrpc/auth_gssapi.h ++++ b/src/include/gssrpc/auth_gssapi.h +@@ -82,14 +82,12 @@ bool_t xdr_authgssapi_init_res(XDR *, auth_gssapi_init_res *); + + bool_t auth_gssapi_wrap_data + (OM_uint32 *major, OM_uint32 *minor, +- gss_ctx_id_t context, uint32_t seq_num, XDR +- *out_xdrs, bool_t (*xdr_func)(), caddr_t +- xdr_ptr); ++ gss_ctx_id_t context, uint32_t seq_num, ++ XDR *out_xdrs, xdrproc_t xdr_func, caddr_t xdr_ptr); + bool_t auth_gssapi_unwrap_data + (OM_uint32 *major, OM_uint32 *minor, +- gss_ctx_id_t context, uint32_t seq_num, XDR +- *in_xdrs, bool_t (*xdr_func)(), caddr_t +- xdr_ptr); ++ gss_ctx_id_t context, uint32_t seq_num, ++ XDR *in_xdrs, xdrproc_t xdr_func, caddr_t xdr_ptr); + + AUTH *auth_gssapi_create + (CLIENT *clnt, +diff --git a/src/include/gssrpc/xdr.h b/src/include/gssrpc/xdr.h +index da9e173782..4e5c29bdc2 100644 +--- a/src/include/gssrpc/xdr.h ++++ b/src/include/gssrpc/xdr.h +@@ -102,7 +102,6 @@ enum xdr_op { + * + * XXX can't actually prototype it, because some take three args!!! + */ +-typedef bool_t (*xdrproc_t)(); + + /* + * The XDR handle. +@@ -143,6 +142,8 @@ typedef struct XDR { + int x_handy; /* extra private word */ + } XDR; + ++typedef bool_t (*xdrproc_t)(XDR *, void *); ++ + /* + * Operations defined on a XDR handle + * +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 768110e5ef..b3e07945c1 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -2236,7 +2236,7 @@ make_data(void *data, unsigned int len) + } + + static inline krb5_data +-empty_data() ++empty_data(void) + { + return make_data(NULL, 0); + } +diff --git a/src/include/k5-plugin.h b/src/include/k5-plugin.h +index 90809e168e..5c5af586c5 100644 +--- a/src/include/k5-plugin.h ++++ b/src/include/k5-plugin.h +@@ -97,7 +97,7 @@ krb5int_get_plugin_data (struct plugin_file_handle *, const char *, void **, + + long KRB5_CALLCONV + krb5int_get_plugin_func (struct plugin_file_handle *, const char *, +- void (**)(), struct errinfo *); ++ void (**)(void), struct errinfo *); + + + long KRB5_CALLCONV +diff --git a/src/include/net-server.h b/src/include/net-server.h +index a30749d851..29b235eeb8 100644 +--- a/src/include/net-server.h ++++ b/src/include/net-server.h +@@ -30,6 +30,7 @@ + #define NET_SERVER_H + + #include ++#include + + /* The delimiter characters supported by the addresses string. */ + #define ADDRESSES_DELIM ",; " +@@ -64,13 +65,14 @@ krb5_error_code loop_add_udp_address(int default_port, const char *addresses); + krb5_error_code loop_add_tcp_address(int default_port, const char *addresses); + krb5_error_code loop_add_rpc_service(int default_port, const char *addresses, + u_long prognum, u_long versnum, +- void (*dispatchfn)()); ++ void (*dispatchfn)(struct svc_req *, ++ SVCXPRT *)); + + krb5_error_code loop_setup_network(verto_ctx *ctx, void *handle, + const char *progname, + int tcp_listen_backlog); + krb5_error_code loop_setup_signals(verto_ctx *ctx, void *handle, +- void (*reset)()); ++ void (*reset)(void *)); + void loop_free(verto_ctx *ctx); + + /* to be supplied by the server application */ +diff --git a/src/kadmin/cli/getdate.y b/src/kadmin/cli/getdate.y +index d14cf963c5..3d69f0b8a4 100644 +--- a/src/kadmin/cli/getdate.y ++++ b/src/kadmin/cli/getdate.y +@@ -100,9 +100,6 @@ struct my_timeb { + #define bcopy(from, to, len) memcpy ((to), (from), (len)) + #endif + +-extern struct tm *gmtime(); +-extern struct tm *localtime(); +- + #define yyparse getdate_yyparse + #define yylex getdate_yylex + #define yyerror getdate_yyerror +diff --git a/src/kadmin/cli/kadmin.c b/src/kadmin/cli/kadmin.c +index f3ea6fae17..23b64b0f58 100644 +--- a/src/kadmin/cli/kadmin.c ++++ b/src/kadmin/cli/kadmin.c +@@ -98,7 +98,7 @@ error(const char *fmt, ...) + } + + static void +-usage() ++usage(void) + { + error(_("Usage: %s [-r realm] [-p principal] [-q query] " + "[clnt|local args]\n" +@@ -1130,7 +1130,7 @@ kadmin_parse_princ_args(int argc, char *argv[], kadm5_principal_ent_t oprinc, + } + + static void +-kadmin_addprinc_usage() ++kadmin_addprinc_usage(void) + { + error(_("usage: add_principal [options] principal\n")); + error(_("\toptions are:\n")); +@@ -1154,7 +1154,7 @@ kadmin_addprinc_usage() + } + + static void +-kadmin_modprinc_usage() ++kadmin_modprinc_usage(void) + { + error(_("usage: modify_principal [options] principal\n")); + error(_("\toptions are:\n")); +diff --git a/src/kadmin/cli/keytab.c b/src/kadmin/cli/keytab.c +index b0c8378b40..26f340af31 100644 +--- a/src/kadmin/cli/keytab.c ++++ b/src/kadmin/cli/keytab.c +@@ -50,14 +50,14 @@ static int quiet; + static int norandkey; + + static void +-add_usage() ++add_usage(void) + { + fprintf(stderr, _("Usage: ktadd [-k[eytab] keytab] [-q] [-e keysaltlist] " + "[-norandkey] [principal | -glob princ-exp] [...]\n")); + } + + static void +-rem_usage() ++rem_usage(void) + { + fprintf(stderr, _("Usage: ktremove [-k[eytab] keytab] [-q] principal " + "[kvno|\"all\"|\"old\"]\n")); +diff --git a/src/kadmin/dbutil/kdb5_create.c b/src/kadmin/dbutil/kdb5_create.c +index 038a0b2190..9178fca6da 100644 +--- a/src/kadmin/dbutil/kdb5_create.c ++++ b/src/kadmin/dbutil/kdb5_create.c +@@ -139,9 +139,8 @@ extern int exit_status; + extern kadm5_config_params global_params; + extern krb5_context util_context; + +-void kdb5_create(argc, argv) +- int argc; +- char *argv[]; ++void ++kdb5_create(int argc, char *argv[]) + { + int optchar; + +@@ -337,9 +336,7 @@ void kdb5_create(argc, argv) + } + + static krb5_error_code +-tgt_keysalt_iterate(ksent, ptr) +- krb5_key_salt_tuple *ksent; +- krb5_pointer ptr; ++tgt_keysalt_iterate(krb5_key_salt_tuple *ksent, krb5_pointer ptr) + { + krb5_context context; + krb5_error_code kret; +@@ -378,11 +375,8 @@ tgt_keysalt_iterate(ksent, ptr) + } + + static krb5_error_code +-add_principal(context, princ, op, pblock) +- krb5_context context; +- krb5_principal princ; +- enum ap_op op; +- struct realm_info *pblock; ++add_principal(krb5_context context, krb5_principal princ, enum ap_op op, ++ struct realm_info *pblock) + { + krb5_error_code retval; + krb5_db_entry *entry = NULL; +diff --git a/src/kadmin/dbutil/kdb5_destroy.c b/src/kadmin/dbutil/kdb5_destroy.c +index fffce74296..556cf0b6bb 100644 +--- a/src/kadmin/dbutil/kdb5_destroy.c ++++ b/src/kadmin/dbutil/kdb5_destroy.c +@@ -39,9 +39,7 @@ char *yes = "yes\n"; /* \n to compare against result of + fgets */ + + void +-kdb5_destroy(argc, argv) +- int argc; +- char *argv[]; ++kdb5_destroy(int argc, char *argv[]) + { + extern int optind; + int optchar; +diff --git a/src/kadmin/dbutil/kdb5_stash.c b/src/kadmin/dbutil/kdb5_stash.c +index e05944f290..eaba6cd353 100644 +--- a/src/kadmin/dbutil/kdb5_stash.c ++++ b/src/kadmin/dbutil/kdb5_stash.c +@@ -63,9 +63,7 @@ extern int exit_status; + extern int close_policy_db; + + void +-kdb5_stash(argc, argv) +- int argc; +- char *argv[]; ++kdb5_stash(int argc, char *argv[]) + { + extern char *optarg; + extern int optind; +diff --git a/src/kadmin/dbutil/kdb5_util.c b/src/kadmin/dbutil/kdb5_util.c +index 19a59250ee..55d529fa4c 100644 +--- a/src/kadmin/dbutil/kdb5_util.c ++++ b/src/kadmin/dbutil/kdb5_util.c +@@ -143,8 +143,8 @@ struct _cmd_table { + {NULL, NULL, 0}, + }; + +-static struct _cmd_table *cmd_lookup(name) +- char *name; ++static struct _cmd_table * ++cmd_lookup(char *name) + { + struct _cmd_table *cmd = cmd_table; + while (cmd->name) { +@@ -162,8 +162,9 @@ static struct _cmd_table *cmd_lookup(name) + char **db5util_db_args = NULL; + int db5util_db_args_size = 0; + +-static void extended_com_err_fn (const char *myprog, errcode_t code, +- const char *fmt, va_list args) ++static void ++extended_com_err_fn(const char *myprog, errcode_t code, const char *fmt, ++ va_list args) + { + const char *emsg; + if (code) { +@@ -177,7 +178,8 @@ static void extended_com_err_fn (const char *myprog, errcode_t code, + fprintf (stderr, "\n"); + } + +-int add_db_arg(char *arg) ++int ++add_db_arg(char *arg) + { + char **temp; + db5util_db_args_size++; +@@ -191,9 +193,8 @@ int add_db_arg(char *arg) + return 1; + } + +-int main(argc, argv) +- int argc; +- char *argv[]; ++int ++main(int argc, char *argv[]) + { + struct _cmd_table *cmd = NULL; + char *koptarg, **cmd_argv; +@@ -365,7 +366,8 @@ int main(argc, argv) + * cannot be fetched (the master key stash file may not exist when the + * program is run). + */ +-static int open_db_and_mkey() ++static int ++open_db_and_mkey() + { + krb5_error_code retval; + krb5_data scratch, pwd, seed; +@@ -508,9 +510,7 @@ quit() + } + + static void +-add_random_key(argc, argv) +- int argc; +- char **argv; ++add_random_key(int argc, char **argv) + { + krb5_error_code ret; + krb5_principal princ; +diff --git a/src/kadmin/dbutil/ovload.c b/src/kadmin/dbutil/ovload.c +index 15a5ab3005..b2e6c00eac 100644 +--- a/src/kadmin/dbutil/ovload.c ++++ b/src/kadmin/dbutil/ovload.c +@@ -11,9 +11,8 @@ + + #define LINESIZE 32768 /* XXX */ + +-static int parse_pw_hist_ent(current, hist) +- char *current; +- osa_pw_hist_ent *hist; ++static int ++parse_pw_hist_ent(char *current, osa_pw_hist_ent *hist) + { + int tmp, i, j, ret; + char *cp; +@@ -90,12 +89,9 @@ done: + * [modifies] + * + */ +-int process_ov_principal(kcontext, fname, filep, verbose, linenop) +- krb5_context kcontext; +- const char *fname; +- FILE *filep; +- krb5_boolean verbose; +- int *linenop; ++int ++process_ov_principal(krb5_context kcontext, const char *fname, FILE *filep, ++ krb5_boolean verbose, int *linenop) + { + XDR xdrs; + osa_princ_ent_t rec; +diff --git a/src/kadmin/dbutil/strtok.c b/src/kadmin/dbutil/strtok.c +index dee466aea1..93f3e85a51 100644 +--- a/src/kadmin/dbutil/strtok.c ++++ b/src/kadmin/dbutil/strtok.c +@@ -50,9 +50,7 @@ + */ + + char * +-nstrtok(s, delim) +- char *s; +- const char *delim; ++nstrtok(char *s, const char *delim) + { + const char *spanp; + int c, sc; +diff --git a/src/kadmin/ktutil/ktutil.c b/src/kadmin/ktutil/ktutil.c +index 92d7023a4f..87a69ca145 100644 +--- a/src/kadmin/ktutil/ktutil.c ++++ b/src/kadmin/ktutil/ktutil.c +@@ -39,9 +39,8 @@ extern ss_request_table ktutil_cmds; + krb5_context kcontext; + krb5_kt_list ktlist = NULL; + +-int main(argc, argv) +- int argc; +- char *argv[]; ++int ++main(int argc, char *argv[]) + { + krb5_error_code retval; + int sci_idx; +@@ -63,9 +62,8 @@ int main(argc, argv) + exit(0); + } + +-void ktutil_clear_list(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_clear_list(int argc, char *argv[]) + { + krb5_error_code retval; + +@@ -79,9 +77,8 @@ void ktutil_clear_list(argc, argv) + ktlist = NULL; + } + +-void ktutil_read_v5(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_read_v5(int argc, char *argv[]) + { + krb5_error_code retval; + +@@ -94,17 +91,15 @@ void ktutil_read_v5(argc, argv) + com_err(argv[0], retval, _("while reading keytab \"%s\""), argv[1]); + } + +-void ktutil_read_v4(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_read_v4(int argc, char *argv[]) + { + fprintf(stderr, _("%s: reading srvtabs is no longer supported\n"), + argv[0]); + } + +-void ktutil_write_v5(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_write_v5(int argc, char *argv[]) + { + krb5_error_code retval; + +@@ -117,17 +112,15 @@ void ktutil_write_v5(argc, argv) + com_err(argv[0], retval, _("while writing keytab \"%s\""), argv[1]); + } + +-void ktutil_write_v4(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_write_v4(int argc, char *argv[]) + { + fprintf(stderr, _("%s: writing srvtabs is no longer supported\n"), + argv[0]); + } + +-void ktutil_add_entry(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_add_entry(int argc, char *argv[]) + { + krb5_error_code retval; + char *princ = NULL; +@@ -183,9 +176,8 @@ void ktutil_add_entry(argc, argv) + com_err(argv[0], retval, _("while adding new entry")); + } + +-void ktutil_delete_entry(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_delete_entry(int argc, char *argv[]) + { + krb5_error_code retval; + +@@ -198,9 +190,8 @@ void ktutil_delete_entry(argc, argv) + com_err(argv[0], retval, _("while deleting entry %d"), atoi(argv[1])); + } + +-void ktutil_list(argc, argv) +- int argc; +- char *argv[]; ++void ++ktutil_list(int argc, char *argv[]) + { + krb5_error_code retval; + krb5_kt_list lp; +diff --git a/src/kadmin/ktutil/ktutil_funcs.c b/src/kadmin/ktutil/ktutil_funcs.c +index 56bed1bbcc..e489b5b57a 100644 +--- a/src/kadmin/ktutil/ktutil_funcs.c ++++ b/src/kadmin/ktutil/ktutil_funcs.c +@@ -37,9 +37,8 @@ + /* + * Free a kt_list + */ +-krb5_error_code ktutil_free_kt_list(context, list) +- krb5_context context; +- krb5_kt_list list; ++krb5_error_code ++ktutil_free_kt_list(krb5_context context, krb5_kt_list list) + { + krb5_kt_list lp, prev; + krb5_error_code retval = 0; +@@ -60,10 +59,8 @@ krb5_error_code ktutil_free_kt_list(context, list) + * Delete a numbered entry in a kt_list. Takes a pointer to a kt_list + * in case head gets deleted. + */ +-krb5_error_code ktutil_delete(context, list, idx) +- krb5_context context; +- krb5_kt_list *list; +- int idx; ++krb5_error_code ++ktutil_delete(krb5_context context, krb5_kt_list *list, int idx) + { + krb5_kt_list lp, prev; + int i; +@@ -138,16 +135,10 @@ get_etype_info(krb5_context context, krb5_principal princ, int fetch, + * password or key. If the keytab list is NULL, allocate a new + * one first. + */ +-krb5_error_code ktutil_add(context, list, princ_str, fetch, kvno, +- enctype_str, use_pass, salt_str) +- krb5_context context; +- krb5_kt_list *list; +- char *princ_str; +- int fetch; +- krb5_kvno kvno; +- char *enctype_str; +- int use_pass; +- char *salt_str; ++krb5_error_code ++ktutil_add(krb5_context context, krb5_kt_list *list, char *princ_str, ++ int fetch, krb5_kvno kvno, char *enctype_str, int use_pass, ++ char *salt_str) + { + krb5_keytab_entry *entry = NULL; + krb5_kt_list lp, *last; +@@ -269,10 +260,8 @@ cleanup: + * Read in a keytab and append it to list. If list starts as NULL, + * allocate a new one if necessary. + */ +-krb5_error_code ktutil_read_keytab(context, name, list) +- krb5_context context; +- char *name; +- krb5_kt_list *list; ++krb5_error_code ++ktutil_read_keytab(krb5_context context, char *name, krb5_kt_list *list) + { + krb5_kt_list lp = NULL, tail = NULL, back = NULL; + krb5_keytab kt; +@@ -344,10 +333,8 @@ close_kt: + /* + * Takes a kt_list and writes it to the named keytab. + */ +-krb5_error_code ktutil_write_keytab(context, list, name) +- krb5_context context; +- krb5_kt_list list; +- char *name; ++krb5_error_code ++ktutil_write_keytab(krb5_context context, krb5_kt_list list, char *name) + { + krb5_kt_list lp; + krb5_keytab kt; +diff --git a/src/kadmin/server/ipropd_svc.c b/src/kadmin/server/ipropd_svc.c +index 56e9b90b20..e5dd233e81 100644 +--- a/src/kadmin/server/ipropd_svc.c ++++ b/src/kadmin/server/ipropd_svc.c +@@ -535,8 +535,8 @@ krb5_iprop_prog_1(struct svc_req *rqstp, + kdb_last_t iprop_get_updates_1_arg; + } argument; + void *result; +- bool_t (*_xdr_argument)(), (*_xdr_result)(); +- void *(*local)(/* union XXX *, struct svc_req * */); ++ xdrproc_t _xdr_argument, _xdr_result; ++ void *(*local)(char *, struct svc_req *); + char *whoami = "krb5_iprop_prog_1"; + + if (!check_iprop_rpcsec_auth(rqstp)) { +@@ -555,21 +555,21 @@ krb5_iprop_prog_1(struct svc_req *rqstp, + return; + + case IPROP_GET_UPDATES: +- _xdr_argument = xdr_kdb_last_t; +- _xdr_result = xdr_kdb_incr_result_t; +- local = (void *(*)()) iprop_get_updates_1_svc; ++ _xdr_argument = (xdrproc_t)xdr_kdb_last_t; ++ _xdr_result = (xdrproc_t)xdr_kdb_incr_result_t; ++ local = (void *(*)(char *, struct svc_req *))iprop_get_updates_1_svc; + break; + + case IPROP_FULL_RESYNC: +- _xdr_argument = xdr_void; +- _xdr_result = xdr_kdb_fullresync_result_t; +- local = (void *(*)()) iprop_full_resync_1_svc; ++ _xdr_argument = (xdrproc_t)xdr_void; ++ _xdr_result = (xdrproc_t)xdr_kdb_fullresync_result_t; ++ local = (void *(*)(char *, struct svc_req *))iprop_full_resync_1_svc; + break; + + case IPROP_FULL_RESYNC_EXT: +- _xdr_argument = xdr_u_int32; +- _xdr_result = xdr_kdb_fullresync_result_t; +- local = (void *(*)()) iprop_full_resync_ext_1_svc; ++ _xdr_argument = (xdrproc_t)xdr_u_int32; ++ _xdr_result = (xdrproc_t)xdr_kdb_fullresync_result_t; ++ local = (void *(*)(char *, struct svc_req *))iprop_full_resync_ext_1_svc; + break; + + default: +@@ -587,7 +587,7 @@ krb5_iprop_prog_1(struct svc_req *rqstp, + svcerr_decode(transp); + return; + } +- result = (*local)(&argument, rqstp); ++ result = (*local)((char *)&argument, rqstp); + + if (_xdr_result && result != NULL && + !svc_sendreply(transp, _xdr_result, result)) { +diff --git a/src/kadmin/server/kadm_rpc_svc.c b/src/kadmin/server/kadm_rpc_svc.c +index 8371fa76ca..f0e43d9aea 100644 +--- a/src/kadmin/server/kadm_rpc_svc.c ++++ b/src/kadmin/server/kadm_rpc_svc.c +@@ -9,6 +9,7 @@ + #include /* for gss_nt_krb5_name */ + #include + #include ++#include + #include + #include + #include +@@ -36,9 +37,8 @@ static int check_rpcsec_auth(struct svc_req *); + * Modifies: + */ + +-void kadm_1(rqstp, transp) +- struct svc_req *rqstp; +- SVCXPRT *transp; ++void ++kadm_1(struct svc_req *rqstp, SVCXPRT *transp) + { + union { + cprinc_arg create_principal_2_arg; +@@ -73,8 +73,8 @@ void kadm_1(rqstp, transp) + getpkeys_ret get_principal_keys_ret; + } result; + bool_t retval; +- bool_t (*xdr_argument)(), (*xdr_result)(); +- bool_t (*local)(); ++ xdrproc_t xdr_argument, xdr_result; ++ bool_t (*local)(char *, void *, struct svc_req *); + + if (rqstp->rq_cred.oa_flavor != AUTH_GSSAPI && + !check_rpcsec_auth(rqstp)) { +@@ -92,153 +92,153 @@ void kadm_1(rqstp, transp) + return; + + case CREATE_PRINCIPAL: +- xdr_argument = xdr_cprinc_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) create_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_cprinc_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))create_principal_2_svc; + break; + + case DELETE_PRINCIPAL: +- xdr_argument = xdr_dprinc_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) delete_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_dprinc_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))delete_principal_2_svc; + break; + + case MODIFY_PRINCIPAL: +- xdr_argument = xdr_mprinc_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) modify_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_mprinc_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))modify_principal_2_svc; + break; + + case RENAME_PRINCIPAL: +- xdr_argument = xdr_rprinc_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) rename_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_rprinc_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))rename_principal_2_svc; + break; + + case GET_PRINCIPAL: +- xdr_argument = xdr_gprinc_arg; +- xdr_result = xdr_gprinc_ret; +- local = (bool_t (*)()) get_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_gprinc_arg; ++ xdr_result = (xdrproc_t)xdr_gprinc_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))get_principal_2_svc; + break; + + case GET_PRINCS: +- xdr_argument = xdr_gprincs_arg; +- xdr_result = xdr_gprincs_ret; +- local = (bool_t (*)()) get_princs_2_svc; ++ xdr_argument = (xdrproc_t)xdr_gprincs_arg; ++ xdr_result = (xdrproc_t)xdr_gprincs_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))get_princs_2_svc; + break; + + case CHPASS_PRINCIPAL: +- xdr_argument = xdr_chpass_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) chpass_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_chpass_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))chpass_principal_2_svc; + break; + + case SETKEY_PRINCIPAL: +- xdr_argument = xdr_setkey_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) setkey_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_setkey_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))setkey_principal_2_svc; + break; + + case CHRAND_PRINCIPAL: +- xdr_argument = xdr_chrand_arg; +- xdr_result = xdr_chrand_ret; +- local = (bool_t (*)()) chrand_principal_2_svc; ++ xdr_argument = (xdrproc_t)xdr_chrand_arg; ++ xdr_result = (xdrproc_t)xdr_chrand_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))chrand_principal_2_svc; + break; + + case CREATE_POLICY: +- xdr_argument = xdr_cpol_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) create_policy_2_svc; ++ xdr_argument = (xdrproc_t)xdr_cpol_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))create_policy_2_svc; + break; + + case DELETE_POLICY: +- xdr_argument = xdr_dpol_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) delete_policy_2_svc; ++ xdr_argument = (xdrproc_t)xdr_dpol_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))delete_policy_2_svc; + break; + + case MODIFY_POLICY: +- xdr_argument = xdr_mpol_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) modify_policy_2_svc; ++ xdr_argument = (xdrproc_t)xdr_mpol_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))modify_policy_2_svc; + break; + + case GET_POLICY: +- xdr_argument = xdr_gpol_arg; +- xdr_result = xdr_gpol_ret; +- local = (bool_t (*)()) get_policy_2_svc; ++ xdr_argument = (xdrproc_t)xdr_gpol_arg; ++ xdr_result = (xdrproc_t)xdr_gpol_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))get_policy_2_svc; + break; + + case GET_POLS: +- xdr_argument = xdr_gpols_arg; +- xdr_result = xdr_gpols_ret; +- local = (bool_t (*)()) get_pols_2_svc; ++ xdr_argument = (xdrproc_t)xdr_gpols_arg; ++ xdr_result = (xdrproc_t)xdr_gpols_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))get_pols_2_svc; + break; + + case GET_PRIVS: +- xdr_argument = xdr_u_int32; +- xdr_result = xdr_getprivs_ret; +- local = (bool_t (*)()) get_privs_2_svc; ++ xdr_argument = (xdrproc_t)xdr_u_int32; ++ xdr_result = (xdrproc_t)xdr_getprivs_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))get_privs_2_svc; + break; + + case INIT: +- xdr_argument = xdr_u_int32; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) init_2_svc; ++ xdr_argument = (xdrproc_t)xdr_u_int32; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))init_2_svc; + break; + + case CREATE_PRINCIPAL3: +- xdr_argument = xdr_cprinc3_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) create_principal3_2_svc; ++ xdr_argument = (xdrproc_t)xdr_cprinc3_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))create_principal3_2_svc; + break; + + case CHPASS_PRINCIPAL3: +- xdr_argument = xdr_chpass3_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) chpass_principal3_2_svc; ++ xdr_argument = (xdrproc_t)xdr_chpass3_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))chpass_principal3_2_svc; + break; + + case CHRAND_PRINCIPAL3: +- xdr_argument = xdr_chrand3_arg; +- xdr_result = xdr_chrand_ret; +- local = (bool_t (*)()) chrand_principal3_2_svc; ++ xdr_argument = (xdrproc_t)xdr_chrand3_arg; ++ xdr_result = (xdrproc_t)xdr_chrand_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))chrand_principal3_2_svc; + break; + + case SETKEY_PRINCIPAL3: +- xdr_argument = xdr_setkey3_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) setkey_principal3_2_svc; ++ xdr_argument = (xdrproc_t)xdr_setkey3_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))setkey_principal3_2_svc; + break; + + case PURGEKEYS: +- xdr_argument = xdr_purgekeys_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) purgekeys_2_svc; ++ xdr_argument = (xdrproc_t)xdr_purgekeys_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))purgekeys_2_svc; + break; + + case GET_STRINGS: +- xdr_argument = xdr_gstrings_arg; +- xdr_result = xdr_gstrings_ret; +- local = (bool_t (*)()) get_strings_2_svc; ++ xdr_argument = (xdrproc_t)xdr_gstrings_arg; ++ xdr_result = (xdrproc_t)xdr_gstrings_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))get_strings_2_svc; + break; + + case SET_STRING: +- xdr_argument = xdr_sstring_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) set_string_2_svc; ++ xdr_argument = (xdrproc_t)xdr_sstring_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))set_string_2_svc; + break; + + case SETKEY_PRINCIPAL4: +- xdr_argument = xdr_setkey4_arg; +- xdr_result = xdr_generic_ret; +- local = (bool_t (*)()) setkey_principal4_2_svc; ++ xdr_argument = (xdrproc_t)xdr_setkey4_arg; ++ xdr_result = (xdrproc_t)xdr_generic_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))setkey_principal4_2_svc; + break; + + case EXTRACT_KEYS: +- xdr_argument = xdr_getpkeys_arg; +- xdr_result = xdr_getpkeys_ret; +- local = (bool_t (*)()) get_principal_keys_2_svc; ++ xdr_argument = (xdrproc_t)xdr_getpkeys_arg; ++ xdr_result = (xdrproc_t)xdr_getpkeys_ret; ++ local = (bool_t (*)(char *, void *, struct svc_req *))get_principal_keys_2_svc; + break; + + default: +@@ -253,7 +253,7 @@ void kadm_1(rqstp, transp) + return; + } + memset(&result, 0, sizeof(result)); +- retval = (*local)(&argument, &result, rqstp); ++ retval = (*local)((char *)&argument, &result, rqstp); + if (retval && !svc_sendreply(transp, xdr_result, (void *)&result)) { + krb5_klog_syslog(LOG_ERR, "WARNING! Unable to send function results, " + "continuing."); +diff --git a/src/kadmin/server/ovsec_kadmd.c b/src/kadmin/server/ovsec_kadmd.c +index b29a0f5b63..a9508af120 100644 +--- a/src/kadmin/server/ovsec_kadmd.c ++++ b/src/kadmin/server/ovsec_kadmd.c +@@ -77,7 +77,7 @@ static krb5_context context; + static char *progname; + + static void +-usage() ++usage(void) + { + fprintf(stderr, _("Usage: kadmind [-x db_args]* [-r realm] [-m] [-nofork] " + "[-port port-number]\n" +@@ -173,7 +173,7 @@ setup_loop(kadm5_config_params *params, int proponly, verto_ctx **ctx_out) + + /* Point GSSAPI at the KDB keytab so we don't need an actual file keytab. */ + static krb5_error_code +-setup_kdb_keytab() ++setup_kdb_keytab(void) + { + krb5_error_code ret; + +diff --git a/src/kdc/t_ndr.c b/src/kdc/t_ndr.c +index a3ac661bd0..c2a2414313 100644 +--- a/src/kdc/t_ndr.c ++++ b/src/kdc/t_ndr.c +@@ -173,7 +173,7 @@ test_dec_enc(uint8_t *blob, size_t len, char *name, int fail) + #define RUN_TEST_FAIL(blob) test_dec_enc(blob, sizeof(blob), #blob, 1) + + int +-main() ++main(void) + { + printf("Running NDR tests...\n"); + +diff --git a/src/kdc/t_replay.c b/src/kdc/t_replay.c +index 57aad886cd..c9c9d65946 100644 +--- a/src/kdc/t_replay.c ++++ b/src/kdc/t_replay.c +@@ -570,7 +570,8 @@ test_kdc_insert_lookaside_cache_expire(void **state) + assert_int_equal(total_size, e2_size); + } + +-int main() ++int ++main(void) + { + int ret; + +@@ -611,7 +612,8 @@ int main() + + #else /* NOCACHE */ + +-int main() ++int ++main(void) + { + return 0; + } +diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c +index cb9785aaeb..f883ae2df8 100644 +--- a/src/kprop/kpropd.c ++++ b/src/kprop/kpropd.c +@@ -165,7 +165,7 @@ static kadm5_ret_t kadm5_get_kiprop_host_srv_name(krb5_context context, + char **host_service_name); + + static void +-usage() ++usage(void) + { + fprintf(stderr, + _("\nUsage: %s [-r realm] [-s keytab] [-d] [-D] [-S]\n" +diff --git a/src/kprop/kproplog.c b/src/kprop/kproplog.c +index 06af2a1d60..1f10aa6dc7 100644 +--- a/src/kprop/kproplog.c ++++ b/src/kprop/kproplog.c +@@ -24,7 +24,7 @@ + static char *progname; + + static void +-usage() ++usage(void) + { + fprintf(stderr, _("\nUsage: %s [-h] [-v] [-v] [-e num]\n\t%s -R\n\n"), + progname, progname); +@@ -393,7 +393,7 @@ print_update(kdb_hlog_t *ulog, uint32_t entry, uint32_t ulogentries, + print_attr(&upd.kdb_update.kdbe_t_val[j], verbose > 1 ? 1 : 0); + } + +- xdr_free(xdr_kdb_incr_update_t, (char *)&upd); ++ xdr_free((xdrproc_t)xdr_kdb_incr_update_t, (char *)&upd); + free(dbprinc); + } + } +diff --git a/src/lib/apputils/net-server.c b/src/lib/apputils/net-server.c +index 1bdc7932b6..75372d8940 100644 +--- a/src/lib/apputils/net-server.c ++++ b/src/lib/apputils/net-server.c +@@ -203,7 +203,7 @@ struct connection { + struct rpc_svc_data { + u_long prognum; + u_long versnum; +- void (*dispatch)(); ++ void (*dispatch)(struct svc_req *, SVCXPRT *); + }; + + struct bind_address { +@@ -255,7 +255,7 @@ free_sighup_context(verto_ctx *ctx, verto_ev *ev) + } + + krb5_error_code +-loop_setup_signals(verto_ctx *ctx, void *handle, void (*reset)()) ++loop_setup_signals(verto_ctx *ctx, void *handle, void (*reset)(void *)) + { + struct sighup_context *sc; + verto_ev *ev; +@@ -434,7 +434,8 @@ loop_add_tcp_address(int default_port, const char *addresses) + + krb5_error_code + loop_add_rpc_service(int default_port, const char *addresses, u_long prognum, +- u_long versnum, void (*dispatchfn)()) ++ u_long versnum, ++ void (*dispatchfn)(struct svc_req *, SVCXPRT *)) + { + struct rpc_svc_data svc; + +diff --git a/src/lib/crypto/builtin/aes/aes-gen.c b/src/lib/crypto/builtin/aes/aes-gen.c +index b528d3796d..4d7a16ee9a 100644 +--- a/src/lib/crypto/builtin/aes/aes-gen.c ++++ b/src/lib/crypto/builtin/aes/aes-gen.c +@@ -54,7 +54,8 @@ uint8_t test_case[NTESTS][4 * B] = { + aes_encrypt_ctx ctx; + aes_decrypt_ctx dctx; + +-static void init () ++static void ++init (void) + { + AES_RETURN r; + +@@ -71,7 +72,8 @@ static void hexdump(const unsigned char *ptr, size_t len) + printf ("%s%02X", (i % 16 == 0) ? "\n " : " ", ptr[i]); + } + +-static void fips_test () ++static void ++fips_test (void) + { + static const unsigned char fipskey[16] = { + 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, +@@ -254,7 +256,8 @@ cts_dec (unsigned char *out, unsigned char *in, unsigned char *iv, + memcpy(out+B, pn, len-B); + } + +-static void ecb_test () ++static void ++ecb_test (void) + { + unsigned int testno; + uint8_t output[4 * B], tmp[4 * B]; +@@ -285,7 +288,8 @@ static void ecb_test () + + unsigned char ivec[16] = { 0 }; + +-static void cbc_test () ++static void ++cbc_test (void) + { + unsigned int testno; + uint8_t output[4 * B], tmp[4 * B]; +@@ -314,7 +318,8 @@ static void cbc_test () + printf ("\n"); + } + +-static void cts_test () ++static void ++cts_test (void) + { + unsigned int testno; + uint8_t output[4 * B], tmp[4 * B]; +@@ -339,7 +344,8 @@ static void cts_test () + printf ("\n"); + } + +-int main () ++int ++main (void) + { + init (); + fips_test (); +diff --git a/src/lib/crypto/builtin/camellia/camellia-gen.c b/src/lib/crypto/builtin/camellia/camellia-gen.c +index 23b69c1741..6eca0e0525 100644 +--- a/src/lib/crypto/builtin/camellia/camellia-gen.c ++++ b/src/lib/crypto/builtin/camellia/camellia-gen.c +@@ -19,7 +19,8 @@ struct { + } test_case[NTESTS]; + camellia_ctx ctx, dctx; + +-static void init () ++static void ++init (void) + { + size_t i, j; + cam_rval r; +@@ -46,7 +47,8 @@ static void hexdump(const unsigned char *ptr, size_t len) + printf ("%s%02X", (i % 16 == 0) ? "\n " : " ", ptr[i]); + } + +-static void fips_test () ++static void ++fips_test (void) + { + static const unsigned char fipskey[16] = { + 0x01, 0x23, 0x45, 0x67, 0x89, 0xab, 0xcd, 0xef, +@@ -234,7 +236,8 @@ cts_dec (unsigned char *out, unsigned char *in, unsigned char *iv, + memcpy(out+B, pn, len-B); + } + +-static void ecb_test () ++static void ++ecb_test (void) + { + size_t testno; + unsigned char tmp[4*B]; +@@ -265,7 +268,8 @@ static void ecb_test () + + unsigned char ivec[16] = { 0 }; + +-static void cbc_test () ++static void ++cbc_test (void) + { + size_t testno; + unsigned char tmp[4*B]; +@@ -294,7 +298,8 @@ static void cbc_test () + printf ("\n"); + } + +-static void cts_test () ++static void ++cts_test (void) + { + size_t testno; + unsigned char tmp[4*B]; +@@ -319,7 +324,8 @@ static void cts_test () + printf ("\n"); + } + +-int main () ++int ++main (void) + { + init (); + fips_test (); +diff --git a/src/lib/crypto/builtin/sha1/t_shs.c b/src/lib/crypto/builtin/sha1/t_shs.c +index c1d18f5571..a668cb0c06 100644 +--- a/src/lib/crypto/builtin/sha1/t_shs.c ++++ b/src/lib/crypto/builtin/sha1/t_shs.c +@@ -29,9 +29,8 @@ static SHS_LONG shsTestResults[][ 5 ] = { + }; + #endif /* NEW_SHS */ + +-static int compareSHSresults(shsInfo, shsTestLevel) +- SHS_INFO *shsInfo; +- int shsTestLevel; ++static int ++compareSHSresults(SHS_INFO *shsInfo, int shsTestLevel) + { + int i, fail = 0; + +@@ -55,7 +54,7 @@ static int compareSHSresults(shsInfo, shsTestLevel) + } + + int +-main() ++main(int argc, char *argv[]) + { + SHS_INFO shsInfo; + unsigned int i; +diff --git a/src/lib/crypto/builtin/sha1/t_shs3.c b/src/lib/crypto/builtin/sha1/t_shs3.c +index 7aa0bbdee3..87caf7fa37 100644 +--- a/src/lib/crypto/builtin/sha1/t_shs3.c ++++ b/src/lib/crypto/builtin/sha1/t_shs3.c +@@ -55,9 +55,7 @@ int mode; + int Dflag; + + int +-main(argc,argv) +- int argc; +- char **argv; ++main(int argc, char **argv) + { + char *argp; + +@@ -131,8 +129,7 @@ static void process(void) + + #ifndef shsDigest + static unsigned char * +-shsDigest(si) +- SHS_INFO *si; ++shsDigest(SHS_INFO *si) + { + longReverse(si->digest, SHS_DIGESTSIZE); + return (unsigned char*) si->digest; +diff --git a/src/lib/crypto/crypto_tests/aes-test.c b/src/lib/crypto/crypto_tests/aes-test.c +index a7382a48ad..d26f711b8d 100644 +--- a/src/lib/crypto/crypto_tests/aes-test.c ++++ b/src/lib/crypto/crypto_tests/aes-test.c +@@ -37,14 +37,14 @@ static char plain[16], cipher[16], zero[16]; + + static krb5_keyblock enc_key; + static krb5_data ivec; +-static void init() ++static void init(void) + { + enc_key.contents = (krb5_octet *)key; + enc_key.length = 16; + ivec.data = zero; + ivec.length = 16; + } +-static void enc() ++static void enc(void) + { + krb5_key k; + krb5_crypto_iov iov; +@@ -93,7 +93,7 @@ static void vk_test_1(int len, krb5_enctype etype) + } + printf("\n==========\n"); + } +-static void vk_test() ++static void vk_test(void) + { + vk_test_1(16, ENCTYPE_AES128_CTS_HMAC_SHA1_96); + vk_test_1(32, ENCTYPE_AES256_CTS_HMAC_SHA1_96); +@@ -119,7 +119,7 @@ static void vt_test_1(int len, krb5_enctype etype) + } + printf("\n==========\n"); + } +-static void vt_test() ++static void vt_test(void) + { + vt_test_1(16, ENCTYPE_AES128_CTS_HMAC_SHA1_96); + vt_test_1(32, ENCTYPE_AES256_CTS_HMAC_SHA1_96); +diff --git a/src/lib/crypto/crypto_tests/camellia-test.c b/src/lib/crypto/crypto_tests/camellia-test.c +index 23d14667e1..ca6579f7d1 100644 +--- a/src/lib/crypto/crypto_tests/camellia-test.c ++++ b/src/lib/crypto/crypto_tests/camellia-test.c +@@ -35,14 +35,14 @@ static char plain[16], cipher[16], zero[16]; + + static krb5_keyblock enc_key; + static krb5_data ivec; +-static void init() ++static void init(void) + { + enc_key.contents = (unsigned char *)key; + enc_key.length = 16; + ivec.data = zero; + ivec.length = 16; + } +-static void enc() ++static void enc(void) + { + krb5_key k; + krb5_crypto_iov iov; +@@ -91,7 +91,7 @@ static void vk_test_1(int len) + } + printf("\n==========\n"); + } +-static void vk_test() ++static void vk_test(void) + { + vk_test_1(16); + vk_test_1(32); +@@ -117,7 +117,7 @@ static void vt_test_1(int len, krb5_enctype etype) + } + printf("\n==========\n"); + } +-static void vt_test() ++static void vt_test(void) + { + vt_test_1(16, ENCTYPE_CAMELLIA128_CTS_CMAC); + vt_test_1(32, ENCTYPE_CAMELLIA256_CTS_CMAC); +diff --git a/src/lib/crypto/crypto_tests/t_cf2.c b/src/lib/crypto/crypto_tests/t_cf2.c +index 67c9dcdee2..4c894ad09c 100644 +--- a/src/lib/crypto/crypto_tests/t_cf2.c ++++ b/src/lib/crypto/crypto_tests/t_cf2.c +@@ -46,7 +46,9 @@ + #include + #include + +-int main () { ++int ++main(void) ++{ + krb5_error_code ret; + char pepper1[1025], pepper2[1025]; + krb5_keyblock *k1 = NULL, *k2 = NULL, *out = NULL; +diff --git a/src/lib/crypto/crypto_tests/t_cts.c b/src/lib/crypto/crypto_tests/t_cts.c +index fe505169f3..f8a5a534b2 100644 +--- a/src/lib/crypto/crypto_tests/t_cts.c ++++ b/src/lib/crypto/crypto_tests/t_cts.c +@@ -77,7 +77,7 @@ static void printk(const char *descr, krb5_keyblock *k) { + printd(descr, &d); + } + +-static void test_cts() ++static void test_cts(void) + { + static const char input[4*16] = + "I would like the General Gau's Chicken, please, and wonton soup."; +diff --git a/src/lib/crypto/crypto_tests/t_encrypt.c b/src/lib/crypto/crypto_tests/t_encrypt.c +index 290a72e1e0..83bc98a2f1 100644 +--- a/src/lib/crypto/crypto_tests/t_encrypt.c ++++ b/src/lib/crypto/crypto_tests/t_encrypt.c +@@ -87,7 +87,7 @@ display(const char *msg, const krb5_data *d) + } + + int +-main () ++main(void) + { + krb5_context context = 0; + krb5_data in, in2, out, out2, check, check2, state, signdata; +diff --git a/src/lib/crypto/crypto_tests/t_fork.c b/src/lib/crypto/crypto_tests/t_fork.c +index 428fc8a6a1..8be7474227 100644 +--- a/src/lib/crypto/crypto_tests/t_fork.c ++++ b/src/lib/crypto/crypto_tests/t_fork.c +@@ -55,7 +55,7 @@ prepare_enc_data(krb5_key key, size_t in_len, krb5_enc_data *enc_data) + } + + int +-main() ++main(void) + { + krb5_keyblock kb_aes, kb_rc4; + krb5_key key_aes, key_rc4; +diff --git a/src/lib/crypto/crypto_tests/t_hmac.c b/src/lib/crypto/crypto_tests/t_hmac.c +index da359cb494..e40136bff0 100644 +--- a/src/lib/crypto/crypto_tests/t_hmac.c ++++ b/src/lib/crypto/crypto_tests/t_hmac.c +@@ -122,7 +122,8 @@ static krb5_error_code hmac1(const struct krb5_hash_provider *h, + return err; + } + +-static void test_hmac() ++static void ++test_hmac(void) + { + krb5_keyblock key; + krb5_data in, out; +diff --git a/src/lib/crypto/crypto_tests/t_mddriver.c b/src/lib/crypto/crypto_tests/t_mddriver.c +index ad65d03156..035f825bbc 100644 +--- a/src/lib/crypto/crypto_tests/t_mddriver.c ++++ b/src/lib/crypto/crypto_tests/t_mddriver.c +@@ -111,9 +111,8 @@ struct md_test_entry md_test_suite[] = { + -t - runs time trial + -x - runs test script + */ +-int main (argc, argv) +- int argc; +- char *argv[]; ++int ++main(int argc, char *argv[]) + { + int i; + +@@ -128,10 +127,8 @@ int main (argc, argv) + return (0); + } + +-static void MDHash (bytes, len, count, out) +- char *bytes; +- size_t len, count; +- unsigned char *out; ++static void ++MDHash(char *bytes, size_t len, size_t count, unsigned char *out) + { + krb5_crypto_iov *iov; + krb5_data outdata = make_data (out, MDProvider.hashsize); +@@ -150,8 +147,8 @@ static void MDHash (bytes, len, count, out) + + /* Digests a string and prints the result. + */ +-static void MDString (string) +- char *string; ++static void ++MDString(char *string) + { + unsigned char digest[16]; + +@@ -164,7 +161,8 @@ static void MDString (string) + /* Measures the time to digest TEST_BLOCK_COUNT TEST_BLOCK_LEN-byte + blocks. + */ +-static void MDTimeTrial () ++static void ++MDTimeTrial(void) + { + time_t endTime, startTime; + unsigned char block[TEST_BLOCK_LEN], digest[16]; +@@ -197,7 +195,8 @@ static void MDTimeTrial () + + /* Digests a reference suite of strings and prints the results. + */ +-static void MDTestSuite () ++static void ++MDTestSuite(void) + { + #ifdef HAVE_TEST_SUITE + struct md_test_entry *entry; +@@ -246,8 +245,8 @@ static void MDTestSuite () + + /* Prints a message digest in hexadecimal. + */ +-static void MDPrint (digest) +- unsigned char digest[16]; ++static void ++MDPrint(unsigned char digest[16]) + { + unsigned int i; + +diff --git a/src/lib/crypto/crypto_tests/t_nfold.c b/src/lib/crypto/crypto_tests/t_nfold.c +index b94353c221..a741b61e0c 100644 +--- a/src/lib/crypto/crypto_tests/t_nfold.c ++++ b/src/lib/crypto/crypto_tests/t_nfold.c +@@ -33,17 +33,20 @@ + + #define ASIZE(ARRAY) (sizeof(ARRAY)/sizeof(ARRAY[0])) + +-static void printhex (size_t len, const unsigned char *p) ++static void ++printhex(size_t len, const unsigned char *p) + { + while (len--) + printf ("%02x", 0xff & *p++); + } + +-static void printstringhex (const unsigned char *p) { ++static void ++printstringhex(const unsigned char *p) { + printhex (strlen ((const char *) p), p); + } + +-static void rfc_tests () ++static void ++rfc_tests(void) + { + unsigned i; + struct { +@@ -92,7 +95,8 @@ static void rfc_tests () + } + } + +-static void fold_kerberos(unsigned int nbytes) ++static void ++fold_kerberos(unsigned int nbytes) + { + unsigned char cipher_text[300]; + unsigned int j; +@@ -125,9 +129,7 @@ unsigned char nfold_192[4][24] = { + }; + + int +-main(argc, argv) +- int argc; +- char *argv[]; ++main(int argc, char *argv[]) + { + unsigned char cipher_text[64]; + unsigned int i, j; +diff --git a/src/lib/crypto/crypto_tests/t_prf.c b/src/lib/crypto/crypto_tests/t_prf.c +index d9877bd1f7..6fa0afb183 100644 +--- a/src/lib/crypto/crypto_tests/t_prf.c ++++ b/src/lib/crypto/crypto_tests/t_prf.c +@@ -116,7 +116,7 @@ struct test { + }; + + int +-main() ++main(void) + { + krb5_error_code ret; + krb5_data output; +diff --git a/src/lib/crypto/crypto_tests/t_sha2.c b/src/lib/crypto/crypto_tests/t_sha2.c +index e6fa584982..776c4e964f 100644 +--- a/src/lib/crypto/crypto_tests/t_sha2.c ++++ b/src/lib/crypto/crypto_tests/t_sha2.c +@@ -137,7 +137,7 @@ hash_test(const struct krb5_hash_provider *hash, struct test *tests) + } + + int +-main() ++main(void) + { + hash_test(&krb5int_hash_sha256, sha256_tests); + hash_test(&krb5int_hash_sha384, sha384_tests); +diff --git a/src/lib/gssapi/generic/t_seqstate.c b/src/lib/gssapi/generic/t_seqstate.c +index 8f44fcf3ed..4df1ed6b9c 100644 +--- a/src/lib/gssapi/generic/t_seqstate.c ++++ b/src/lib/gssapi/generic/t_seqstate.c +@@ -164,7 +164,7 @@ struct test { + }; + + int +-main() ++main(void) + { + size_t i, j; + enum width w; +diff --git a/src/lib/gssapi/krb5/accept_sec_context.c b/src/lib/gssapi/krb5/accept_sec_context.c +index d7c2ad321e..90a9ad2d9d 100644 +--- a/src/lib/gssapi/krb5/accept_sec_context.c ++++ b/src/lib/gssapi/krb5/accept_sec_context.c +@@ -160,11 +160,8 @@ create_constrained_deleg_creds(OM_uint32 *minor_status, + + /* Decode, decrypt and store the forwarded creds in the local ccache. */ + static krb5_error_code +-rd_and_store_for_creds(context, auth_context, inbuf, out_cred) +- krb5_context context; +- krb5_auth_context auth_context; +- krb5_data *inbuf; +- krb5_gss_cred_id_t *out_cred; ++rd_and_store_for_creds(krb5_context context, krb5_auth_context auth_context, ++ krb5_data *inbuf, krb5_gss_cred_id_t *out_cred) + { + krb5_creds ** creds = NULL; + krb5_error_code retval; +@@ -286,20 +283,12 @@ cleanup: + * Performs third leg of DCE authentication + */ + static OM_uint32 +-kg_accept_dce(minor_status, context_handle, verifier_cred_handle, +- input_token, input_chan_bindings, src_name, mech_type, +- output_token, ret_flags, time_rec, delegated_cred_handle) +- OM_uint32 *minor_status; +- gss_ctx_id_t *context_handle; +- gss_cred_id_t verifier_cred_handle; +- gss_buffer_t input_token; +- gss_channel_bindings_t input_chan_bindings; +- gss_name_t *src_name; +- gss_OID *mech_type; +- gss_buffer_t output_token; +- OM_uint32 *ret_flags; +- OM_uint32 *time_rec; +- gss_cred_id_t *delegated_cred_handle; ++kg_accept_dce(OM_uint32 *minor_status, gss_ctx_id_t *context_handle, ++ gss_cred_id_t verifier_cred_handle, gss_buffer_t input_token, ++ gss_channel_bindings_t input_chan_bindings, gss_name_t *src_name, ++ gss_OID *mech_type, gss_buffer_t output_token, ++ OM_uint32 *ret_flags, OM_uint32 *time_rec, ++ gss_cred_id_t *delegated_cred_handle) + { + krb5_error_code code; + krb5_gss_ctx_id_rec *ctx = 0; +@@ -637,23 +626,13 @@ fail: + } + + static OM_uint32 +-kg_accept_krb5(minor_status, context_handle, +- verifier_cred_handle, input_token, +- input_chan_bindings, src_name, mech_type, +- output_token, ret_flags, time_rec, +- delegated_cred_handle, exts) +- OM_uint32 *minor_status; +- gss_ctx_id_t *context_handle; +- gss_cred_id_t verifier_cred_handle; +- gss_buffer_t input_token; +- gss_channel_bindings_t input_chan_bindings; +- gss_name_t *src_name; +- gss_OID *mech_type; +- gss_buffer_t output_token; +- OM_uint32 *ret_flags; +- OM_uint32 *time_rec; +- gss_cred_id_t *delegated_cred_handle; +- krb5_gss_ctx_ext_t exts; ++kg_accept_krb5(OM_uint32 *minor_status, gss_ctx_id_t *context_handle, ++ gss_cred_id_t verifier_cred_handle, gss_buffer_t input_token, ++ gss_channel_bindings_t input_chan_bindings, ++ gss_name_t *src_name, gss_OID *mech_type, ++ gss_buffer_t output_token, OM_uint32 *ret_flags, ++ OM_uint32 *time_rec, gss_cred_id_t *delegated_cred_handle, ++ krb5_gss_ctx_ext_t exts) + { + krb5_context context; + unsigned char *ptr; +@@ -1309,22 +1288,15 @@ krb5_gss_accept_sec_context_ext( + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_accept_sec_context(minor_status, context_handle, +- verifier_cred_handle, input_token, +- input_chan_bindings, src_name, mech_type, +- output_token, ret_flags, time_rec, +- delegated_cred_handle) +- OM_uint32 *minor_status; +- gss_ctx_id_t *context_handle; +- gss_cred_id_t verifier_cred_handle; +- gss_buffer_t input_token; +- gss_channel_bindings_t input_chan_bindings; +- gss_name_t *src_name; +- gss_OID *mech_type; +- gss_buffer_t output_token; +- OM_uint32 *ret_flags; +- OM_uint32 *time_rec; +- gss_cred_id_t *delegated_cred_handle; ++krb5_gss_accept_sec_context(OM_uint32 *minor_status, ++ gss_ctx_id_t *context_handle, ++ gss_cred_id_t verifier_cred_handle, ++ gss_buffer_t input_token, ++ gss_channel_bindings_t input_chan_bindings, ++ gss_name_t *src_name, gss_OID *mech_type, ++ gss_buffer_t output_token, OM_uint32 *ret_flags, ++ OM_uint32 *time_rec, ++ gss_cred_id_t *delegated_cred_handle) + { + krb5_gss_ctx_ext_rec exts; + +diff --git a/src/lib/gssapi/krb5/compare_name.c b/src/lib/gssapi/krb5/compare_name.c +index 3f3788d2bf..3aa5a0d79f 100644 +--- a/src/lib/gssapi/krb5/compare_name.c ++++ b/src/lib/gssapi/krb5/compare_name.c +@@ -28,11 +28,8 @@ + #include "gssapiP_krb5.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_compare_name(minor_status, name1, name2, name_equal) +- OM_uint32 *minor_status; +- gss_name_t name1; +- gss_name_t name2; +- int *name_equal; ++krb5_gss_compare_name(OM_uint32 *minor_status, gss_name_t name1, ++ gss_name_t name2, int *name_equal) + { + krb5_context context; + krb5_error_code code; +diff --git a/src/lib/gssapi/krb5/context_time.c b/src/lib/gssapi/krb5/context_time.c +index 226de05f51..0ab885deca 100644 +--- a/src/lib/gssapi/krb5/context_time.c ++++ b/src/lib/gssapi/krb5/context_time.c +@@ -28,10 +28,8 @@ + */ + + OM_uint32 KRB5_CALLCONV +-krb5_gss_context_time(minor_status, context_handle, time_rec) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- OM_uint32 *time_rec; ++krb5_gss_context_time(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ OM_uint32 *time_rec) + { + krb5_error_code code; + krb5_gss_ctx_id_rec *ctx; +diff --git a/src/lib/gssapi/krb5/delete_sec_context.c b/src/lib/gssapi/krb5/delete_sec_context.c +index 4b9dfae0d5..92e84b79c5 100644 +--- a/src/lib/gssapi/krb5/delete_sec_context.c ++++ b/src/lib/gssapi/krb5/delete_sec_context.c +@@ -28,10 +28,9 @@ + */ + + OM_uint32 KRB5_CALLCONV +-krb5_gss_delete_sec_context(minor_status, context_handle, output_token) +- OM_uint32 *minor_status; +- gss_ctx_id_t *context_handle; +- gss_buffer_t output_token; ++krb5_gss_delete_sec_context(OM_uint32 *minor_status, ++ gss_ctx_id_t *context_handle, ++ gss_buffer_t output_token) + { + krb5_context context; + krb5_gss_ctx_id_rec *ctx; +diff --git a/src/lib/gssapi/krb5/disp_name.c b/src/lib/gssapi/krb5/disp_name.c +index b097bf0e21..75fef01238 100644 +--- a/src/lib/gssapi/krb5/disp_name.c ++++ b/src/lib/gssapi/krb5/disp_name.c +@@ -24,12 +24,9 @@ + #include "gssapiP_krb5.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_display_name(minor_status, input_name, output_name_buffer, +- output_name_type) +- OM_uint32 *minor_status; +- gss_name_t input_name; +- gss_buffer_t output_name_buffer; +- gss_OID *output_name_type; ++krb5_gss_display_name(OM_uint32 *minor_status, gss_name_t input_name, ++ gss_buffer_t output_name_buffer, ++ gss_OID *output_name_type) + { + krb5_context context; + krb5_error_code code; +diff --git a/src/lib/gssapi/krb5/disp_status.c b/src/lib/gssapi/krb5/disp_status.c +index 6ff62a9d84..71000b7a45 100644 +--- a/src/lib/gssapi/krb5/disp_status.c ++++ b/src/lib/gssapi/krb5/disp_status.c +@@ -154,14 +154,9 @@ void krb5_gss_delete_error_info(void *p) + /**/ + + OM_uint32 KRB5_CALLCONV +-krb5_gss_display_status(minor_status, status_value, status_type, +- mech_type, message_context, status_string) +- OM_uint32 *minor_status; +- OM_uint32 status_value; +- int status_type; +- gss_OID mech_type; +- OM_uint32 *message_context; +- gss_buffer_t status_string; ++krb5_gss_display_status(OM_uint32 *minor_status, OM_uint32 status_value, ++ int status_type, gss_OID mech_type, ++ OM_uint32 *message_context, gss_buffer_t status_string) + { + status_string->length = 0; + status_string->value = NULL; +diff --git a/src/lib/gssapi/krb5/export_sec_context.c b/src/lib/gssapi/krb5/export_sec_context.c +index 44e50080ab..9730e0597f 100644 +--- a/src/lib/gssapi/krb5/export_sec_context.c ++++ b/src/lib/gssapi/krb5/export_sec_context.c +@@ -27,10 +27,9 @@ + #include "gssapiP_krb5.h" + #ifndef LEAN_CLIENT + OM_uint32 KRB5_CALLCONV +-krb5_gss_export_sec_context(minor_status, context_handle, interprocess_token) +- OM_uint32 *minor_status; +- gss_ctx_id_t *context_handle; +- gss_buffer_t interprocess_token; ++krb5_gss_export_sec_context(OM_uint32 *minor_status, ++ gss_ctx_id_t *context_handle, ++ gss_buffer_t interprocess_token) + { + krb5_context context = NULL; + krb5_error_code kret; +diff --git a/src/lib/gssapi/krb5/gssapi_krb5.c b/src/lib/gssapi/krb5/gssapi_krb5.c +index 1e62b07cde..370b7d152a 100644 +--- a/src/lib/gssapi/krb5/gssapi_krb5.c ++++ b/src/lib/gssapi/krb5/gssapi_krb5.c +@@ -197,9 +197,7 @@ g_set kg_vdb = G_SET_INIT; + * so handling the expiration/invalidation condition here isn't needed. + */ + OM_uint32 +-kg_get_defcred(minor_status, cred) +- OM_uint32 *minor_status; +- gss_cred_id_t *cred; ++kg_get_defcred(OM_uint32 *minor_status, gss_cred_id_t *cred) + { + OM_uint32 major; + +diff --git a/src/lib/gssapi/krb5/import_name.c b/src/lib/gssapi/krb5/import_name.c +index f64635a202..cc6883b5fe 100644 +--- a/src/lib/gssapi/krb5/import_name.c ++++ b/src/lib/gssapi/krb5/import_name.c +@@ -120,12 +120,8 @@ parse_hostbased(const char *str, size_t len, + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_import_name(minor_status, input_name_buffer, +- input_name_type, output_name) +- OM_uint32 *minor_status; +- gss_buffer_t input_name_buffer; +- gss_OID input_name_type; +- gss_name_t *output_name; ++krb5_gss_import_name(OM_uint32 *minor_status, gss_buffer_t input_name_buffer, ++ gss_OID input_name_type, gss_name_t *output_name) + { + krb5_context context; + krb5_principal princ = NULL; +diff --git a/src/lib/gssapi/krb5/import_sec_context.c b/src/lib/gssapi/krb5/import_sec_context.c +index 7d26f4df87..e39c036b80 100644 +--- a/src/lib/gssapi/krb5/import_sec_context.c ++++ b/src/lib/gssapi/krb5/import_sec_context.c +@@ -32,8 +32,7 @@ + * Fix up the OID of the mechanism so that uses the static version of + * the OID if possible. + */ +-gss_OID krb5_gss_convert_static_mech_oid(oid) +- gss_OID oid; ++gss_OID krb5_gss_convert_static_mech_oid(gss_OID oid) + { + const gss_OID_desc *p; + OM_uint32 minor_status; +@@ -49,10 +48,9 @@ gss_OID krb5_gss_convert_static_mech_oid(oid) + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_import_sec_context(minor_status, interprocess_token, context_handle) +- OM_uint32 *minor_status; +- gss_buffer_t interprocess_token; +- gss_ctx_id_t *context_handle; ++krb5_gss_import_sec_context(OM_uint32 *minor_status, ++ gss_buffer_t interprocess_token, ++ gss_ctx_id_t *context_handle) + { + krb5_context context; + krb5_error_code kret = 0; +diff --git a/src/lib/gssapi/krb5/indicate_mechs.c b/src/lib/gssapi/krb5/indicate_mechs.c +index 45538cb779..49d55e6217 100644 +--- a/src/lib/gssapi/krb5/indicate_mechs.c ++++ b/src/lib/gssapi/krb5/indicate_mechs.c +@@ -29,9 +29,7 @@ + #include "mglueP.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_indicate_mechs(minor_status, mech_set) +- OM_uint32 *minor_status; +- gss_OID_set *mech_set; ++krb5_gss_indicate_mechs(OM_uint32 *minor_status, gss_OID_set *mech_set) + { + return generic_gss_copy_oid_set(minor_status, kg_all_mechs, mech_set); + } +diff --git a/src/lib/gssapi/krb5/init_sec_context.c b/src/lib/gssapi/krb5/init_sec_context.c +index 5748b8434c..0397fe1dfd 100644 +--- a/src/lib/gssapi/krb5/init_sec_context.c ++++ b/src/lib/gssapi/krb5/init_sec_context.c +@@ -117,14 +117,10 @@ int krb5_gss_dbg_client_expcreds = 0; + * Common code which fetches the correct krb5 credentials from the + * ccache. + */ +-static krb5_error_code get_credentials(context, cred, server, now, +- endtime, out_creds) +- krb5_context context; +- krb5_gss_cred_id_t cred; +- krb5_gss_name_t server; +- krb5_timestamp now; +- krb5_timestamp endtime; +- krb5_creds **out_creds; ++static krb5_error_code ++get_credentials(krb5_context context, krb5_gss_cred_id_t cred, ++ krb5_gss_name_t server, krb5_timestamp now, ++ krb5_timestamp endtime, krb5_creds **out_creds) + { + krb5_error_code code; + krb5_creds in_creds, evidence_creds, mcreds, *result_creds = NULL; +@@ -365,17 +361,11 @@ cleanup: + } + + static krb5_error_code +-make_ap_req_v1(context, ctx, cred, k_cred, ad_context, +- chan_bindings, mech_type, token, exts) +- krb5_context context; +- krb5_gss_ctx_id_rec *ctx; +- krb5_gss_cred_id_t cred; +- krb5_creds *k_cred; +- krb5_authdata_context ad_context; +- gss_channel_bindings_t chan_bindings; +- gss_OID mech_type; +- gss_buffer_t token; +- krb5_gss_ctx_ext_t exts; ++make_ap_req_v1(krb5_context context, krb5_gss_ctx_id_rec *ctx, ++ krb5_gss_cred_id_t cred, krb5_creds *k_cred, ++ krb5_authdata_context ad_context, ++ gss_channel_bindings_t chan_bindings, gss_OID mech_type, ++ gss_buffer_t token, krb5_gss_ctx_ext_t exts) + { + krb5_flags mk_req_flags = 0; + krb5_error_code code; +@@ -1048,24 +1038,15 @@ krb5int_gss_use_kdc_context(OM_uint32 *minor_status, + #endif + + OM_uint32 KRB5_CALLCONV +-krb5_gss_init_sec_context(minor_status, claimant_cred_handle, +- context_handle, target_name, mech_type, +- req_flags, time_req, input_chan_bindings, +- input_token, actual_mech_type, output_token, +- ret_flags, time_rec) +- OM_uint32 *minor_status; +- gss_cred_id_t claimant_cred_handle; +- gss_ctx_id_t *context_handle; +- gss_name_t target_name; +- gss_OID mech_type; +- OM_uint32 req_flags; +- OM_uint32 time_req; +- gss_channel_bindings_t input_chan_bindings; +- gss_buffer_t input_token; +- gss_OID *actual_mech_type; +- gss_buffer_t output_token; +- OM_uint32 *ret_flags; +- OM_uint32 *time_rec; ++krb5_gss_init_sec_context(OM_uint32 *minor_status, ++ gss_cred_id_t claimant_cred_handle, ++ gss_ctx_id_t *context_handle, ++ gss_name_t target_name, gss_OID mech_type, ++ OM_uint32 req_flags, OM_uint32 time_req, ++ gss_channel_bindings_t input_chan_bindings, ++ gss_buffer_t input_token, gss_OID *actual_mech_type, ++ gss_buffer_t output_token, OM_uint32 *ret_flags, ++ OM_uint32 *time_rec) + { + krb5_gss_ctx_ext_rec exts; + +diff --git a/src/lib/gssapi/krb5/inq_context.c b/src/lib/gssapi/krb5/inq_context.c +index 97678e3ec5..f8229f9750 100644 +--- a/src/lib/gssapi/krb5/inq_context.c ++++ b/src/lib/gssapi/krb5/inq_context.c +@@ -78,18 +78,11 @@ + #include "gssapiP_krb5.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_inquire_context(minor_status, context_handle, initiator_name, +- acceptor_name, lifetime_rec, mech_type, ret_flags, +- locally_initiated, opened) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- gss_name_t *initiator_name; +- gss_name_t *acceptor_name; +- OM_uint32 *lifetime_rec; +- gss_OID *mech_type; +- OM_uint32 *ret_flags; +- int *locally_initiated; +- int *opened; ++krb5_gss_inquire_context(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_name_t *initiator_name, gss_name_t *acceptor_name, ++ OM_uint32 *lifetime_rec, gss_OID *mech_type, ++ OM_uint32 *ret_flags, int *locally_initiated, ++ int *opened) + { + krb5_context context; + krb5_error_code code; +diff --git a/src/lib/gssapi/krb5/inq_cred.c b/src/lib/gssapi/krb5/inq_cred.c +index 0e675959a3..e968f8ad32 100644 +--- a/src/lib/gssapi/krb5/inq_cred.c ++++ b/src/lib/gssapi/krb5/inq_cred.c +@@ -73,14 +73,9 @@ + #include "gssapiP_krb5.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_inquire_cred(minor_status, cred_handle, name, lifetime_ret, +- cred_usage, mechanisms) +- OM_uint32 *minor_status; +- gss_cred_id_t cred_handle; +- gss_name_t *name; +- OM_uint32 *lifetime_ret; +- gss_cred_usage_t *cred_usage; +- gss_OID_set *mechanisms; ++krb5_gss_inquire_cred(OM_uint32 *minor_status, gss_cred_id_t cred_handle, ++ gss_name_t *name, OM_uint32 *lifetime_ret, ++ gss_cred_usage_t *cred_usage, gss_OID_set *mechanisms) + { + krb5_context context; + gss_cred_id_t defcred = GSS_C_NO_CREDENTIAL; +@@ -209,16 +204,11 @@ cleanup: + + /* V2 interface */ + OM_uint32 KRB5_CALLCONV +-krb5_gss_inquire_cred_by_mech(minor_status, cred_handle, +- mech_type, name, initiator_lifetime, +- acceptor_lifetime, cred_usage) +- OM_uint32 *minor_status; +- gss_cred_id_t cred_handle; +- gss_OID mech_type; +- gss_name_t *name; +- OM_uint32 *initiator_lifetime; +- OM_uint32 *acceptor_lifetime; +- gss_cred_usage_t *cred_usage; ++krb5_gss_inquire_cred_by_mech(OM_uint32 *minor_status, ++ gss_cred_id_t cred_handle, gss_OID mech_type, ++ gss_name_t *name, OM_uint32 *initiator_lifetime, ++ OM_uint32 *acceptor_lifetime, ++ gss_cred_usage_t *cred_usage) + { + krb5_gss_cred_id_t cred; + OM_uint32 lifetime; +diff --git a/src/lib/gssapi/krb5/inq_names.c b/src/lib/gssapi/krb5/inq_names.c +index b326adbb5f..4a3709be4b 100644 +--- a/src/lib/gssapi/krb5/inq_names.c ++++ b/src/lib/gssapi/krb5/inq_names.c +@@ -27,10 +27,8 @@ + #include "gssapiP_krb5.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_inquire_names_for_mech(minor_status, mechanism, name_types) +- OM_uint32 *minor_status; +- gss_OID mechanism; +- gss_OID_set *name_types; ++krb5_gss_inquire_names_for_mech(OM_uint32 *minor_status, gss_OID mechanism, ++ gss_OID_set *name_types) + { + OM_uint32 major, minor; + +diff --git a/src/lib/gssapi/krb5/k5seal.c b/src/lib/gssapi/krb5/k5seal.c +index 0e5d10b115..1148f6929b 100644 +--- a/src/lib/gssapi/krb5/k5seal.c ++++ b/src/lib/gssapi/krb5/k5seal.c +@@ -271,16 +271,10 @@ make_seal_token_v1 (krb5_context context, + and do not encode the ENC_TYPE, MSG_LENGTH, or MSG_TEXT fields */ + + OM_uint32 +-kg_seal(minor_status, context_handle, conf_req_flag, qop_req, +- input_message_buffer, conf_state, output_message_buffer, toktype) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- int conf_req_flag; +- gss_qop_t qop_req; +- gss_buffer_t input_message_buffer; +- int *conf_state; +- gss_buffer_t output_message_buffer; +- int toktype; ++kg_seal(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ int conf_req_flag, gss_qop_t qop_req, ++ gss_buffer_t input_message_buffer, int *conf_state, ++ gss_buffer_t output_message_buffer, int toktype) + { + krb5_gss_ctx_id_rec *ctx; + krb5_error_code code; +@@ -342,16 +336,10 @@ kg_seal(minor_status, context_handle, conf_req_flag, qop_req, + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_wrap(minor_status, context_handle, conf_req_flag, +- qop_req, input_message_buffer, conf_state, +- output_message_buffer) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- int conf_req_flag; +- gss_qop_t qop_req; +- gss_buffer_t input_message_buffer; +- int *conf_state; +- gss_buffer_t output_message_buffer; ++krb5_gss_wrap(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ int conf_req_flag, gss_qop_t qop_req, ++ gss_buffer_t input_message_buffer, int *conf_state, ++ gss_buffer_t output_message_buffer) + { + return(kg_seal(minor_status, context_handle, conf_req_flag, + qop_req, input_message_buffer, conf_state, +@@ -359,13 +347,9 @@ krb5_gss_wrap(minor_status, context_handle, conf_req_flag, + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_get_mic(minor_status, context_handle, qop_req, +- message_buffer, message_token) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- gss_qop_t qop_req; +- gss_buffer_t message_buffer; +- gss_buffer_t message_token; ++krb5_gss_get_mic(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_qop_t qop_req, gss_buffer_t message_buffer, ++ gss_buffer_t message_token) + { + return(kg_seal(minor_status, context_handle, 0, + qop_req, message_buffer, NULL, +diff --git a/src/lib/gssapi/krb5/k5unseal.c b/src/lib/gssapi/krb5/k5unseal.c +index f0cc4a6809..e246365804 100644 +--- a/src/lib/gssapi/krb5/k5unseal.c ++++ b/src/lib/gssapi/krb5/k5unseal.c +@@ -58,17 +58,10 @@ + conf_state is only valid if SEAL. */ + + static OM_uint32 +-kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, +- conf_state, qop_state, toktype) +- krb5_context context; +- OM_uint32 *minor_status; +- krb5_gss_ctx_id_rec *ctx; +- unsigned char *ptr; +- int bodysize; +- gss_buffer_t message_buffer; +- int *conf_state; +- gss_qop_t *qop_state; +- int toktype; ++kg_unseal_v1(krb5_context context, OM_uint32 *minor_status, ++ krb5_gss_ctx_id_rec *ctx, unsigned char *ptr, int bodysize, ++ gss_buffer_t message_buffer, int *conf_state, ++ gss_qop_t *qop_state, int toktype) + { + krb5_error_code code; + int conflen = 0; +@@ -342,15 +335,9 @@ kg_unseal_v1(context, minor_status, ctx, ptr, bodysize, message_buffer, + conf_state is only valid if SEAL. */ + + OM_uint32 +-kg_unseal(minor_status, context_handle, input_token_buffer, +- message_buffer, conf_state, qop_state, toktype) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- gss_buffer_t input_token_buffer; +- gss_buffer_t message_buffer; +- int *conf_state; +- gss_qop_t *qop_state; +- int toktype; ++kg_unseal(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t input_token_buffer, gss_buffer_t message_buffer, ++ int *conf_state, gss_qop_t *qop_state, int toktype) + { + krb5_gss_ctx_id_rec *ctx; + unsigned char *ptr; +@@ -421,15 +408,10 @@ kg_unseal(minor_status, context_handle, input_token_buffer, + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_unwrap(minor_status, context_handle, +- input_message_buffer, output_message_buffer, +- conf_state, qop_state) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- gss_buffer_t input_message_buffer; +- gss_buffer_t output_message_buffer; +- int *conf_state; +- gss_qop_t *qop_state; ++krb5_gss_unwrap(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t input_message_buffer, ++ gss_buffer_t output_message_buffer, int *conf_state, ++ gss_qop_t *qop_state) + { + OM_uint32 rstat; + +@@ -440,14 +422,9 @@ krb5_gss_unwrap(minor_status, context_handle, + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_verify_mic(minor_status, context_handle, +- message_buffer, token_buffer, +- qop_state) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- gss_buffer_t message_buffer; +- gss_buffer_t token_buffer; +- gss_qop_t *qop_state; ++krb5_gss_verify_mic(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t message_buffer, gss_buffer_t token_buffer, ++ gss_qop_t *qop_state) + { + OM_uint32 rstat; + +diff --git a/src/lib/gssapi/krb5/process_context_token.c b/src/lib/gssapi/krb5/process_context_token.c +index a672f48c85..67805fba78 100644 +--- a/src/lib/gssapi/krb5/process_context_token.c ++++ b/src/lib/gssapi/krb5/process_context_token.c +@@ -28,11 +28,9 @@ + */ + + OM_uint32 KRB5_CALLCONV +-krb5_gss_process_context_token(minor_status, context_handle, +- token_buffer) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- gss_buffer_t token_buffer; ++krb5_gss_process_context_token(OM_uint32 *minor_status, ++ gss_ctx_id_t context_handle, ++ gss_buffer_t token_buffer) + { + krb5_gss_ctx_id_rec *ctx; + OM_uint32 majerr; +diff --git a/src/lib/gssapi/krb5/rel_cred.c b/src/lib/gssapi/krb5/rel_cred.c +index 0da6c1b950..9e04e2fa81 100644 +--- a/src/lib/gssapi/krb5/rel_cred.c ++++ b/src/lib/gssapi/krb5/rel_cred.c +@@ -24,9 +24,7 @@ + #include "gssapiP_krb5.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_release_cred(minor_status, cred_handle) +- OM_uint32 *minor_status; +- gss_cred_id_t *cred_handle; ++krb5_gss_release_cred(OM_uint32 *minor_status, gss_cred_id_t *cred_handle) + { + krb5_context context; + krb5_gss_cred_id_t cred; +diff --git a/src/lib/gssapi/krb5/rel_name.c b/src/lib/gssapi/krb5/rel_name.c +index 3dabe32f33..558bb6dbc5 100644 +--- a/src/lib/gssapi/krb5/rel_name.c ++++ b/src/lib/gssapi/krb5/rel_name.c +@@ -24,9 +24,7 @@ + #include "gssapiP_krb5.h" + + OM_uint32 KRB5_CALLCONV +-krb5_gss_release_name(minor_status, input_name) +- OM_uint32 *minor_status; +- gss_name_t *input_name; ++krb5_gss_release_name(OM_uint32 *minor_status, gss_name_t *input_name) + { + krb5_context context; + krb5_error_code code; +diff --git a/src/lib/gssapi/krb5/rel_oid.c b/src/lib/gssapi/krb5/rel_oid.c +index 739efe4680..900c4105f9 100644 +--- a/src/lib/gssapi/krb5/rel_oid.c ++++ b/src/lib/gssapi/krb5/rel_oid.c +@@ -27,9 +27,7 @@ + #include "gssapiP_krb5.h" + + OM_uint32 +-krb5_gss_release_oid(minor_status, oid) +- OM_uint32 *minor_status; +- gss_OID *oid; ++krb5_gss_release_oid(OM_uint32 *minor_status, gss_OID *oid) + { + /* + * The V2 API says the following! +@@ -52,9 +50,7 @@ krb5_gss_release_oid(minor_status, oid) + } + + OM_uint32 KRB5_CALLCONV +-krb5_gss_internal_release_oid(minor_status, oid) +- OM_uint32 *minor_status; +- gss_OID *oid; ++krb5_gss_internal_release_oid(OM_uint32 *minor_status, gss_OID *oid) + { + /* + * This function only knows how to release internal OIDs. It will +diff --git a/src/lib/gssapi/krb5/ser_sctx.c b/src/lib/gssapi/krb5/ser_sctx.c +index 9e2d32e98d..1129b6a1aa 100644 +--- a/src/lib/gssapi/krb5/ser_sctx.c ++++ b/src/lib/gssapi/krb5/ser_sctx.c +@@ -137,10 +137,8 @@ kg_oid_size(gss_OID oid, size_t *sizep) + } + + static krb5_error_code +-kg_seqstate_externalize(arg, buffer, lenremain) +- g_seqnum_state arg; +- krb5_octet **buffer; +- size_t *lenremain; ++kg_seqstate_externalize(g_seqnum_state arg, krb5_octet **buffer, ++ size_t *lenremain) + { + krb5_error_code err; + err = krb5_ser_pack_int32(KV5M_GSS_QUEUE, buffer, lenremain); +@@ -152,10 +150,8 @@ kg_seqstate_externalize(arg, buffer, lenremain) + } + + static krb5_error_code +-kg_seqstate_internalize(argp, buffer, lenremain) +- g_seqnum_state *argp; +- krb5_octet **buffer; +- size_t *lenremain; ++kg_seqstate_internalize(g_seqnum_state *argp, krb5_octet **buffer, ++ size_t *lenremain) + { + krb5_int32 ibuf; + krb5_octet *bp; +@@ -193,9 +189,7 @@ kg_seqstate_internalize(argp, buffer, lenremain) + } + + static krb5_error_code +-kg_seqstate_size(arg, sizep) +- g_seqnum_state arg; +- size_t *sizep; ++kg_seqstate_size(g_seqnum_state arg, size_t *sizep) + { + krb5_error_code kret; + size_t required; +diff --git a/src/lib/gssapi/krb5/util_cksum.c b/src/lib/gssapi/krb5/util_cksum.c +index 5b87956393..5f7694f5e6 100644 +--- a/src/lib/gssapi/krb5/util_cksum.c ++++ b/src/lib/gssapi/krb5/util_cksum.c +@@ -28,10 +28,8 @@ + + /* Checksumming the channel bindings always uses plain MD5. */ + krb5_error_code +-kg_checksum_channel_bindings(context, cb, cksum) +- krb5_context context; +- gss_channel_bindings_t cb; +- krb5_checksum *cksum; ++kg_checksum_channel_bindings(krb5_context context, gss_channel_bindings_t cb, ++ krb5_checksum *cksum) + { + struct k5buf buf; + size_t sumlen; +diff --git a/src/lib/gssapi/krb5/util_seed.c b/src/lib/gssapi/krb5/util_seed.c +index 6e1c9ac8ae..685736314c 100644 +--- a/src/lib/gssapi/krb5/util_seed.c ++++ b/src/lib/gssapi/krb5/util_seed.c +@@ -29,10 +29,7 @@ + static const unsigned char zeros[16] = {0,0,0,0, 0,0,0,0, 0,0,0,0, 0,0,0,0}; + + krb5_error_code +-kg_make_seed(context, key, seed) +- krb5_context context; +- krb5_key key; +- unsigned char *seed; ++kg_make_seed(krb5_context context, krb5_key key, unsigned char *seed) + { + krb5_error_code code; + krb5_key rkey = NULL; +diff --git a/src/lib/gssapi/krb5/util_seqnum.c b/src/lib/gssapi/krb5/util_seqnum.c +index bef631da9d..a5a4d5cf80 100644 +--- a/src/lib/gssapi/krb5/util_seqnum.c ++++ b/src/lib/gssapi/krb5/util_seqnum.c +@@ -30,13 +30,8 @@ + */ + + krb5_error_code +-kg_make_seq_num(context, key, direction, seqnum, cksum, buf) +- krb5_context context; +- krb5_key key; +- int direction; +- krb5_ui_4 seqnum; +- unsigned char *cksum; +- unsigned char *buf; ++kg_make_seq_num(krb5_context context, krb5_key key, int direction, ++ krb5_ui_4 seqnum, unsigned char *cksum, unsigned char *buf) + { + unsigned char plain[8]; + +@@ -59,13 +54,9 @@ kg_make_seq_num(context, key, direction, seqnum, cksum, buf) + return(kg_encrypt(context, key, KG_USAGE_SEQ, cksum, plain, buf, 8)); + } + +-krb5_error_code kg_get_seq_num(context, key, cksum, buf, direction, seqnum) +- krb5_context context; +- krb5_key key; +- unsigned char *cksum; +- unsigned char *buf; +- int *direction; +- krb5_ui_4 *seqnum; ++krb5_error_code ++kg_get_seq_num(krb5_context context, krb5_key key, unsigned char *cksum, ++ unsigned char *buf, int *direction, krb5_ui_4 *seqnum) + { + krb5_error_code code; + unsigned char plain[8]; +diff --git a/src/lib/gssapi/krb5/val_cred.c b/src/lib/gssapi/krb5/val_cred.c +index cb1cb9393a..83e7634106 100644 +--- a/src/lib/gssapi/krb5/val_cred.c ++++ b/src/lib/gssapi/krb5/val_cred.c +@@ -57,9 +57,7 @@ krb5_gss_validate_cred_1(OM_uint32 *minor_status, gss_cred_id_t cred_handle, + } + + OM_uint32 +-krb5_gss_validate_cred(minor_status, cred_handle) +- OM_uint32 *minor_status; +- gss_cred_id_t cred_handle; ++krb5_gss_validate_cred(OM_uint32 *minor_status, gss_cred_id_t cred_handle) + { + krb5_context context; + krb5_error_code code; +diff --git a/src/lib/gssapi/krb5/wrap_size_limit.c b/src/lib/gssapi/krb5/wrap_size_limit.c +index 7959f424ec..8ea6ce1ad3 100644 +--- a/src/lib/gssapi/krb5/wrap_size_limit.c ++++ b/src/lib/gssapi/krb5/wrap_size_limit.c +@@ -74,14 +74,9 @@ + + /* V2 interface */ + OM_uint32 KRB5_CALLCONV +-krb5_gss_wrap_size_limit(minor_status, context_handle, conf_req_flag, +- qop_req, req_output_size, max_input_size) +- OM_uint32 *minor_status; +- gss_ctx_id_t context_handle; +- int conf_req_flag; +- gss_qop_t qop_req; +- OM_uint32 req_output_size; +- OM_uint32 *max_input_size; ++krb5_gss_wrap_size_limit(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ int conf_req_flag, gss_qop_t qop_req, ++ OM_uint32 req_output_size, OM_uint32 *max_input_size) + { + krb5_gss_ctx_id_rec *ctx; + OM_uint32 data_size, conflen; +diff --git a/src/lib/gssapi/mechglue/g_accept_sec_context.c b/src/lib/gssapi/mechglue/g_accept_sec_context.c +index 4f2a66e26a..e4eff1f52c 100644 +--- a/src/lib/gssapi/mechglue/g_accept_sec_context.c ++++ b/src/lib/gssapi/mechglue/g_accept_sec_context.c +@@ -128,30 +128,13 @@ allow_mech_by_default(gss_OID mech) + } + + OM_uint32 KRB5_CALLCONV +-gss_accept_sec_context (minor_status, +- context_handle, +- verifier_cred_handle, +- input_token_buffer, +- input_chan_bindings, +- src_name, +- mech_type, +- output_token, +- ret_flags, +- time_rec, +- d_cred) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t * context_handle; +-gss_cred_id_t verifier_cred_handle; +-gss_buffer_t input_token_buffer; +-gss_channel_bindings_t input_chan_bindings; +-gss_name_t * src_name; +-gss_OID * mech_type; +-gss_buffer_t output_token; +-OM_uint32 * ret_flags; +-OM_uint32 * time_rec; +-gss_cred_id_t * d_cred; +- ++gss_accept_sec_context(OM_uint32 *minor_status, gss_ctx_id_t *context_handle, ++ gss_cred_id_t verifier_cred_handle, ++ gss_buffer_t input_token_buffer, ++ gss_channel_bindings_t input_chan_bindings, ++ gss_name_t *src_name, gss_OID *mech_type, ++ gss_buffer_t output_token, OM_uint32 *ret_flags, ++ OM_uint32 *time_rec, gss_cred_id_t *d_cred) + { + OM_uint32 status, temp_status, temp_minor_status; + OM_uint32 temp_ret_flags = 0; +diff --git a/src/lib/gssapi/mechglue/g_acquire_cred.c b/src/lib/gssapi/mechglue/g_acquire_cred.c +index c885f56279..2fc9c5c786 100644 +--- a/src/lib/gssapi/mechglue/g_acquire_cred.c ++++ b/src/lib/gssapi/mechglue/g_acquire_cred.c +@@ -85,24 +85,10 @@ val_acq_cred_args( + + + OM_uint32 KRB5_CALLCONV +-gss_acquire_cred(minor_status, +- desired_name, +- time_req, +- desired_mechs, +- cred_usage, +- output_cred_handle, +- actual_mechs, +- time_rec) +- +-OM_uint32 * minor_status; +-gss_name_t desired_name; +-OM_uint32 time_req; +-gss_OID_set desired_mechs; +-int cred_usage; +-gss_cred_id_t * output_cred_handle; +-gss_OID_set * actual_mechs; +-OM_uint32 * time_rec; +- ++gss_acquire_cred(OM_uint32 *minor_status, gss_name_t desired_name, ++ OM_uint32 time_req, gss_OID_set desired_mechs, ++ int cred_usage, gss_cred_id_t *output_cred_handle, ++ gss_OID_set *actual_mechs, OM_uint32 *time_rec) + { + return gss_acquire_cred_from(minor_status, desired_name, time_req, + desired_mechs, cred_usage, NULL, +@@ -110,26 +96,11 @@ OM_uint32 * time_rec; + } + + OM_uint32 KRB5_CALLCONV +-gss_acquire_cred_from(minor_status, +- desired_name, +- time_req, +- desired_mechs, +- cred_usage, +- cred_store, +- output_cred_handle, +- actual_mechs, +- time_rec) +- +-OM_uint32 * minor_status; +-gss_name_t desired_name; +-OM_uint32 time_req; +-gss_OID_set desired_mechs; +-int cred_usage; +-gss_const_key_value_set_t cred_store; +-gss_cred_id_t * output_cred_handle; +-gss_OID_set * actual_mechs; +-OM_uint32 * time_rec; +- ++gss_acquire_cred_from(OM_uint32 * minor_status, gss_name_t desired_name, ++ OM_uint32 time_req, gss_OID_set desired_mechs, ++ int cred_usage, gss_const_key_value_set_t cred_store, ++ gss_cred_id_t *output_cred_handle, ++ gss_OID_set *actual_mechs, OM_uint32 *time_rec) + { + OM_uint32 major = GSS_S_FAILURE, tmpMinor; + OM_uint32 first_major = GSS_S_COMPLETE, first_minor = 0; +@@ -397,22 +368,12 @@ error: + + /* V2 KRB5_CALLCONV */ + OM_uint32 KRB5_CALLCONV +-gss_add_cred(minor_status, input_cred_handle, +- desired_name, desired_mech, cred_usage, +- initiator_time_req, acceptor_time_req, +- output_cred_handle, actual_mechs, +- initiator_time_rec, acceptor_time_rec) +- OM_uint32 *minor_status; +- gss_cred_id_t input_cred_handle; +- gss_name_t desired_name; +- gss_OID desired_mech; +- gss_cred_usage_t cred_usage; +- OM_uint32 initiator_time_req; +- OM_uint32 acceptor_time_req; +- gss_cred_id_t *output_cred_handle; +- gss_OID_set *actual_mechs; +- OM_uint32 *initiator_time_rec; +- OM_uint32 *acceptor_time_rec; ++gss_add_cred(OM_uint32 *minor_status, gss_cred_id_t input_cred_handle, ++ gss_name_t desired_name, gss_OID desired_mech, ++ gss_cred_usage_t cred_usage, OM_uint32 initiator_time_req, ++ OM_uint32 acceptor_time_req, gss_cred_id_t *output_cred_handle, ++ gss_OID_set *actual_mechs, OM_uint32 *initiator_time_rec, ++ OM_uint32 *acceptor_time_rec) + { + return gss_add_cred_from(minor_status, input_cred_handle, desired_name, + desired_mech, cred_usage, initiator_time_req, +@@ -422,25 +383,13 @@ gss_add_cred(minor_status, input_cred_handle, + } + + OM_uint32 KRB5_CALLCONV +-gss_add_cred_from(minor_status, input_cred_handle, +- desired_name, desired_mech, +- cred_usage, +- initiator_time_req, acceptor_time_req, +- cred_store, +- output_cred_handle, actual_mechs, +- initiator_time_rec, acceptor_time_rec) +- OM_uint32 *minor_status; +- gss_cred_id_t input_cred_handle; +- gss_name_t desired_name; +- gss_OID desired_mech; +- gss_cred_usage_t cred_usage; +- OM_uint32 initiator_time_req; +- OM_uint32 acceptor_time_req; +- gss_const_key_value_set_t cred_store; +- gss_cred_id_t *output_cred_handle; +- gss_OID_set *actual_mechs; +- OM_uint32 *initiator_time_rec; +- OM_uint32 *acceptor_time_rec; ++gss_add_cred_from(OM_uint32 *minor_status, gss_cred_id_t input_cred_handle, ++ gss_name_t desired_name, gss_OID desired_mech, ++ gss_cred_usage_t cred_usage, OM_uint32 initiator_time_req, ++ OM_uint32 acceptor_time_req, ++ gss_const_key_value_set_t cred_store, ++ gss_cred_id_t *output_cred_handle, gss_OID_set *actual_mechs, ++ OM_uint32 *initiator_time_rec, OM_uint32 *acceptor_time_rec) + { + OM_uint32 status, temp_minor_status; + OM_uint32 time_req, time_rec = 0, *time_recp = NULL; +diff --git a/src/lib/gssapi/mechglue/g_acquire_cred_with_pw.c b/src/lib/gssapi/mechglue/g_acquire_cred_with_pw.c +index cc34acc2bf..86abf984dc 100644 +--- a/src/lib/gssapi/mechglue/g_acquire_cred_with_pw.c ++++ b/src/lib/gssapi/mechglue/g_acquire_cred_with_pw.c +@@ -98,26 +98,12 @@ val_acq_cred_pw_args( + + + OM_uint32 KRB5_CALLCONV +-gss_acquire_cred_with_password( +- minor_status, +- desired_name, +- password, +- time_req, +- desired_mechs, +- cred_usage, +- output_cred_handle, +- actual_mechs, +- time_rec) +- +-OM_uint32 * minor_status; +-const gss_name_t desired_name; +-const gss_buffer_t password; +-OM_uint32 time_req; +-const gss_OID_set desired_mechs; +-int cred_usage; +-gss_cred_id_t * output_cred_handle; +-gss_OID_set * actual_mechs; +-OM_uint32 * time_rec; ++gss_acquire_cred_with_password(OM_uint32 *minor_status, ++ const gss_name_t desired_name, ++ const gss_buffer_t password, OM_uint32 time_req, ++ const gss_OID_set desired_mechs, int cred_usage, ++ gss_cred_id_t *output_cred_handle, ++ gss_OID_set *actual_mechs, OM_uint32 *time_rec) + { + OM_uint32 major = GSS_S_FAILURE; + OM_uint32 initTimeOut, acceptTimeOut, outTime = GSS_C_INDEFINITE; +@@ -306,23 +292,19 @@ val_add_cred_pw_args( + + /* V2 KRB5_CALLCONV */ + OM_uint32 KRB5_CALLCONV +-gss_add_cred_with_password(minor_status, input_cred_handle, +- desired_name, desired_mech, password, cred_usage, +- initiator_time_req, acceptor_time_req, +- output_cred_handle, actual_mechs, +- initiator_time_rec, acceptor_time_rec) +- OM_uint32 *minor_status; +- const gss_cred_id_t input_cred_handle; +- const gss_name_t desired_name; +- const gss_OID desired_mech; +- const gss_buffer_t password; +- gss_cred_usage_t cred_usage; +- OM_uint32 initiator_time_req; +- OM_uint32 acceptor_time_req; +- gss_cred_id_t *output_cred_handle; +- gss_OID_set *actual_mechs; +- OM_uint32 *initiator_time_rec; +- OM_uint32 *acceptor_time_rec; ++gss_add_cred_with_password( ++ OM_uint32 *minor_status, ++ const gss_cred_id_t input_cred_handle, ++ const gss_name_t desired_name, ++ const gss_OID desired_mech, ++ const gss_buffer_t password, ++ gss_cred_usage_t cred_usage, ++ OM_uint32 initiator_time_req, ++ OM_uint32 acceptor_time_req, ++ gss_cred_id_t *output_cred_handle, ++ gss_OID_set *actual_mechs, ++ OM_uint32 *initiator_time_rec, ++ OM_uint32 *acceptor_time_rec) + { + OM_uint32 status, temp_minor_status; + OM_uint32 time_req, time_rec; +diff --git a/src/lib/gssapi/mechglue/g_canon_name.c b/src/lib/gssapi/mechglue/g_canon_name.c +index 61f657f91f..c5214db80a 100644 +--- a/src/lib/gssapi/mechglue/g_canon_name.c ++++ b/src/lib/gssapi/mechglue/g_canon_name.c +@@ -54,14 +54,8 @@ val_canon_name_args( + + + OM_uint32 KRB5_CALLCONV +-gss_canonicalize_name(minor_status, +- input_name, +- mech_type, +- output_name) +-OM_uint32 *minor_status; +-const gss_name_t input_name; +-const gss_OID mech_type; +-gss_name_t *output_name; ++gss_canonicalize_name(OM_uint32 *minor_status, const gss_name_t input_name, ++ const gss_OID mech_type, gss_name_t *output_name) + { + gss_union_name_t in_union, out_union = NULL, dest_union = NULL; + OM_uint32 major_status = GSS_S_FAILURE, tmpmin; +diff --git a/src/lib/gssapi/mechglue/g_compare_name.c b/src/lib/gssapi/mechglue/g_compare_name.c +index af2e76bbda..74a9529a35 100644 +--- a/src/lib/gssapi/mechglue/g_compare_name.c ++++ b/src/lib/gssapi/mechglue/g_compare_name.c +@@ -59,16 +59,8 @@ val_comp_name_args( + + + OM_uint32 KRB5_CALLCONV +-gss_compare_name (minor_status, +- name1, +- name2, +- name_equal) +- +-OM_uint32 * minor_status; +-gss_name_t name1; +-gss_name_t name2; +-int * name_equal; +- ++gss_compare_name(OM_uint32 * minor_status, gss_name_t name1, gss_name_t name2, ++ int * name_equal) + { + OM_uint32 major_status, temp_minor; + gss_union_name_t union_name1, union_name2; +diff --git a/src/lib/gssapi/mechglue/g_context_time.c b/src/lib/gssapi/mechglue/g_context_time.c +index c947e7646c..b11b32d6bb 100644 +--- a/src/lib/gssapi/mechglue/g_context_time.c ++++ b/src/lib/gssapi/mechglue/g_context_time.c +@@ -29,14 +29,8 @@ + #include "mglueP.h" + + OM_uint32 KRB5_CALLCONV +-gss_context_time (minor_status, +- context_handle, +- time_rec) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-OM_uint32 * time_rec; +- ++gss_context_time(OM_uint32 * minor_status, gss_ctx_id_t context_handle, ++ OM_uint32 * time_rec) + { + OM_uint32 status; + gss_union_ctx_id_t ctx; +diff --git a/src/lib/gssapi/mechglue/g_delete_sec_context.c b/src/lib/gssapi/mechglue/g_delete_sec_context.c +index 574ff02944..dc86cce3d3 100644 +--- a/src/lib/gssapi/mechglue/g_delete_sec_context.c ++++ b/src/lib/gssapi/mechglue/g_delete_sec_context.c +@@ -62,14 +62,8 @@ val_del_sec_ctx_args( + + + OM_uint32 KRB5_CALLCONV +-gss_delete_sec_context (minor_status, +- context_handle, +- output_token) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t * context_handle; +-gss_buffer_t output_token; +- ++gss_delete_sec_context(OM_uint32 *minor_status, gss_ctx_id_t *context_handle, ++ gss_buffer_t output_token) + { + OM_uint32 status; + gss_union_ctx_id_t ctx; +diff --git a/src/lib/gssapi/mechglue/g_dsp_name.c b/src/lib/gssapi/mechglue/g_dsp_name.c +index 21867c814e..fae64f712e 100644 +--- a/src/lib/gssapi/mechglue/g_dsp_name.c ++++ b/src/lib/gssapi/mechglue/g_dsp_name.c +@@ -70,16 +70,8 @@ val_dsp_name_args( + + + OM_uint32 KRB5_CALLCONV +-gss_display_name (minor_status, +- input_name, +- output_name_buffer, +- output_name_type) +- +-OM_uint32 * minor_status; +-gss_name_t input_name; +-gss_buffer_t output_name_buffer; +-gss_OID * output_name_type; +- ++gss_display_name(OM_uint32 *minor_status, gss_name_t input_name, ++ gss_buffer_t output_name_buffer, gss_OID *output_name_type) + { + OM_uint32 major_status; + gss_union_name_t union_name; +diff --git a/src/lib/gssapi/mechglue/g_dsp_status.c b/src/lib/gssapi/mechglue/g_dsp_status.c +index 70e8492636..14a7a8200c 100644 +--- a/src/lib/gssapi/mechglue/g_dsp_status.c ++++ b/src/lib/gssapi/mechglue/g_dsp_status.c +@@ -36,20 +36,9 @@ + static OM_uint32 displayMajor(OM_uint32, OM_uint32 *, gss_buffer_t); + + OM_uint32 KRB5_CALLCONV +-gss_display_status (minor_status, +- status_value, +- status_type, +- req_mech_type, +- message_context, +- status_string) +- +-OM_uint32 * minor_status; +-OM_uint32 status_value; +-int status_type; +-gss_OID req_mech_type; +-OM_uint32 * message_context; +-gss_buffer_t status_string; +- ++gss_display_status(OM_uint32 *minor_status, OM_uint32 status_value, ++ int status_type, gss_OID req_mech_type, ++ OM_uint32 *message_context, gss_buffer_t status_string) + { + gss_OID mech_type = (gss_OID) req_mech_type; + gss_mechanism mech; +@@ -147,10 +136,7 @@ gss_buffer_t status_string; + * >= 2 - the supplementary error code bit shifted by 1 + */ + static OM_uint32 +-displayMajor(status, msgCtxt, outStr) +-OM_uint32 status; +-OM_uint32 *msgCtxt; +-gss_buffer_t outStr; ++displayMajor(OM_uint32 status, OM_uint32 *msgCtxt, gss_buffer_t outStr) + { + OM_uint32 oneVal, mask = 0x1, currErr; + char *errStr = NULL; +diff --git a/src/lib/gssapi/mechglue/g_dup_name.c b/src/lib/gssapi/mechglue/g_dup_name.c +index ff01db27dc..bf6eb602ea 100644 +--- a/src/lib/gssapi/mechglue/g_dup_name.c ++++ b/src/lib/gssapi/mechglue/g_dup_name.c +@@ -51,12 +51,8 @@ val_dup_name_args( + + + OM_uint32 KRB5_CALLCONV +-gss_duplicate_name(minor_status, +- src_name, +- dest_name) +-OM_uint32 *minor_status; +-const gss_name_t src_name; +-gss_name_t *dest_name; ++gss_duplicate_name(OM_uint32 *minor_status, const gss_name_t src_name, ++ gss_name_t *dest_name) + { + gss_union_name_t src_union, dest_union; + OM_uint32 major_status = GSS_S_FAILURE; +diff --git a/src/lib/gssapi/mechglue/g_exp_sec_context.c b/src/lib/gssapi/mechglue/g_exp_sec_context.c +index a04afe3d1e..68a3267cf0 100644 +--- a/src/lib/gssapi/mechglue/g_exp_sec_context.c ++++ b/src/lib/gssapi/mechglue/g_exp_sec_context.c +@@ -68,14 +68,8 @@ val_exp_sec_ctx_args( + + + OM_uint32 KRB5_CALLCONV +-gss_export_sec_context(minor_status, +- context_handle, +- interprocess_token) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t * context_handle; +-gss_buffer_t interprocess_token; +- ++gss_export_sec_context(OM_uint32 *minor_status, gss_ctx_id_t *context_handle, ++ gss_buffer_t interprocess_token) + { + OM_uint32 status; + OM_uint32 length; +diff --git a/src/lib/gssapi/mechglue/g_export_name.c b/src/lib/gssapi/mechglue/g_export_name.c +index c845f8caf7..2e0611d2d5 100644 +--- a/src/lib/gssapi/mechglue/g_export_name.c ++++ b/src/lib/gssapi/mechglue/g_export_name.c +@@ -20,12 +20,8 @@ + #include + + OM_uint32 KRB5_CALLCONV +-gss_export_name(minor_status, +- input_name, +- exported_name) +-OM_uint32 * minor_status; +-const gss_name_t input_name; +-gss_buffer_t exported_name; ++gss_export_name(OM_uint32 *minor_status, const gss_name_t input_name, ++ gss_buffer_t exported_name) + { + gss_union_name_t union_name; + +diff --git a/src/lib/gssapi/mechglue/g_glue.c b/src/lib/gssapi/mechglue/g_glue.c +index 176fbe63eb..47f499307a 100644 +--- a/src/lib/gssapi/mechglue/g_glue.c ++++ b/src/lib/gssapi/mechglue/g_glue.c +@@ -75,9 +75,8 @@ static gss_OID_desc gss_krb5_mechanism_oid_desc = + + #define NTLMSSP_SIGNATURE "NTLMSSP" + +-OM_uint32 gssint_get_mech_type(OID, token) +- gss_OID OID; +- gss_buffer_t token; ++OM_uint32 ++gssint_get_mech_type(gss_OID OID, gss_buffer_t token) + { + /* Check for interoperability exceptions */ + if (token->length >= sizeof(NTLMSSP_SIGNATURE) && +@@ -163,12 +162,10 @@ import_internal_attributes(OM_uint32 *minor, + * Internal routines to get and release an internal mechanism name + */ + +-OM_uint32 gssint_import_internal_name (minor_status, mech_type, union_name, +- internal_name) +-OM_uint32 *minor_status; +-gss_OID mech_type; +-gss_union_name_t union_name; +-gss_name_t *internal_name; ++OM_uint32 ++gssint_import_internal_name(OM_uint32 *minor_status, gss_OID mech_type, ++ gss_union_name_t union_name, ++ gss_name_t *internal_name) + { + OM_uint32 status, tmpMinor; + gss_mechanism mech; +@@ -220,12 +217,10 @@ gss_name_t *internal_name; + return (status); + } + +-OM_uint32 gssint_export_internal_name(minor_status, mech_type, +- internal_name, name_buf) +- OM_uint32 *minor_status; +- const gss_OID mech_type; +- const gss_name_t internal_name; +- gss_buffer_t name_buf; ++OM_uint32 ++gssint_export_internal_name(OM_uint32 *minor_status, const gss_OID mech_type, ++ const gss_name_t internal_name, ++ gss_buffer_t name_buf) + { + OM_uint32 status; + gss_mechanism mech; +@@ -307,13 +302,10 @@ OM_uint32 gssint_export_internal_name(minor_status, mech_type, + return (GSS_S_COMPLETE); + } /* gssint_export_internal_name */ + +-OM_uint32 gssint_display_internal_name (minor_status, mech_type, internal_name, +- external_name, name_type) +-OM_uint32 *minor_status; +-gss_OID mech_type; +-gss_name_t internal_name; +-gss_buffer_t external_name; +-gss_OID *name_type; ++OM_uint32 ++gssint_display_internal_name(OM_uint32 *minor_status, gss_OID mech_type, ++ gss_name_t internal_name, ++ gss_buffer_t external_name, gss_OID *name_type) + { + OM_uint32 status; + gss_mechanism mech; +@@ -337,10 +329,9 @@ gss_OID *name_type; + return (GSS_S_BAD_MECH); + } + +-OM_uint32 gssint_release_internal_name (minor_status, mech_type, internal_name) +-OM_uint32 *minor_status; +-gss_OID mech_type; +-gss_name_t *internal_name; ++OM_uint32 ++gssint_release_internal_name(OM_uint32 *minor_status, gss_OID mech_type, ++ gss_name_t *internal_name) + { + OM_uint32 status; + gss_mechanism mech; +@@ -362,14 +353,10 @@ gss_name_t *internal_name; + return (GSS_S_BAD_MECH); + } + +-OM_uint32 gssint_delete_internal_sec_context (minor_status, +- mech_type, +- internal_ctx, +- output_token) +-OM_uint32 *minor_status; +-gss_OID mech_type; +-gss_ctx_id_t *internal_ctx; +-gss_buffer_t output_token; ++OM_uint32 ++gssint_delete_internal_sec_context(OM_uint32 *minor_status, gss_OID mech_type, ++ gss_ctx_id_t *internal_ctx, ++ gss_buffer_t output_token) + { + OM_uint32 status; + gss_mechanism mech; +@@ -394,12 +381,10 @@ gss_buffer_t output_token; + * name. Note that internal_name should be considered "consumed" by + * this call, whether or not we return an error. + */ +-OM_uint32 gssint_convert_name_to_union_name(minor_status, mech, +- internal_name, external_name) +- OM_uint32 *minor_status; +- gss_mechanism mech; +- gss_name_t internal_name; +- gss_name_t *external_name; ++OM_uint32 ++gssint_convert_name_to_union_name(OM_uint32 *minor_status, gss_mechanism mech, ++ gss_name_t internal_name, ++ gss_name_t *external_name) + { + OM_uint32 major_status,tmp; + gss_union_name_t union_name; +@@ -473,9 +458,7 @@ allocation_failure: + * external union credential. + */ + gss_cred_id_t +-gssint_get_mechanism_cred(union_cred, mech_type) +- gss_union_cred_t union_cred; +- gss_OID mech_type; ++gssint_get_mechanism_cred(gss_union_cred_t union_cred, gss_OID mech_type) + { + int i; + +@@ -494,10 +477,8 @@ gssint_get_mechanism_cred(union_cred, mech_type) + * Both space for the structure and the data is allocated. + */ + OM_uint32 +-gssint_create_copy_buffer(srcBuf, destBuf, addNullChar) +- const gss_buffer_t srcBuf; +- gss_buffer_t *destBuf; +- int addNullChar; ++gssint_create_copy_buffer(const gss_buffer_t srcBuf, gss_buffer_t *destBuf, ++ int addNullChar) + { + gss_buffer_t aBuf; + unsigned int len; +diff --git a/src/lib/gssapi/mechglue/g_imp_name.c b/src/lib/gssapi/mechglue/g_imp_name.c +index a805078a81..65fa6c0fb3 100644 +--- a/src/lib/gssapi/mechglue/g_imp_name.c ++++ b/src/lib/gssapi/mechglue/g_imp_name.c +@@ -81,16 +81,8 @@ val_imp_name_args( + static gss_buffer_desc emptyNameBuffer; + + OM_uint32 KRB5_CALLCONV +-gss_import_name(minor_status, +- input_name_buffer, +- input_name_type, +- output_name) +- +-OM_uint32 * minor_status; +-gss_buffer_t input_name_buffer; +-gss_OID input_name_type; +-gss_name_t * output_name; +- ++gss_import_name(OM_uint32 * minor_status, gss_buffer_t input_name_buffer, ++ gss_OID input_name_type, gss_name_t * output_name) + { + gss_union_name_t union_name; + OM_uint32 tmp, major_status = GSS_S_FAILURE; +@@ -183,10 +175,8 @@ allocation_failure: + } + + static OM_uint32 +-importExportName(minor, unionName, inputNameType) +- OM_uint32 *minor; +- gss_union_name_t unionName; +- gss_OID inputNameType; ++importExportName(OM_uint32 *minor, gss_union_name_t unionName, ++ gss_OID inputNameType) + { + gss_OID_desc mechOid; + gss_buffer_desc expName; +diff --git a/src/lib/gssapi/mechglue/g_imp_sec_context.c b/src/lib/gssapi/mechglue/g_imp_sec_context.c +index 6315201a5f..55a3136df1 100644 +--- a/src/lib/gssapi/mechglue/g_imp_sec_context.c ++++ b/src/lib/gssapi/mechglue/g_imp_sec_context.c +@@ -69,14 +69,9 @@ val_imp_sec_ctx_args( + + + OM_uint32 KRB5_CALLCONV +-gss_import_sec_context(minor_status, +- interprocess_token, +- context_handle) +- +-OM_uint32 * minor_status; +-gss_buffer_t interprocess_token; +-gss_ctx_id_t * context_handle; +- ++gss_import_sec_context(OM_uint32 *minor_status, ++ gss_buffer_t interprocess_token, ++ gss_ctx_id_t *context_handle) + { + OM_uint32 length = 0; + OM_uint32 status; +diff --git a/src/lib/gssapi/mechglue/g_init_sec_context.c b/src/lib/gssapi/mechglue/g_init_sec_context.c +index a58074c007..d639a8de3b 100644 +--- a/src/lib/gssapi/mechglue/g_init_sec_context.c ++++ b/src/lib/gssapi/mechglue/g_init_sec_context.c +@@ -88,34 +88,15 @@ val_init_sec_ctx_args( + + + OM_uint32 KRB5_CALLCONV +-gss_init_sec_context (minor_status, +- claimant_cred_handle, +- context_handle, +- target_name, +- req_mech_type, +- req_flags, +- time_req, +- input_chan_bindings, +- input_token, +- actual_mech_type, +- output_token, +- ret_flags, +- time_rec) +- +-OM_uint32 * minor_status; +-gss_cred_id_t claimant_cred_handle; +-gss_ctx_id_t * context_handle; +-gss_name_t target_name; +-gss_OID req_mech_type; +-OM_uint32 req_flags; +-OM_uint32 time_req; +-gss_channel_bindings_t input_chan_bindings; +-gss_buffer_t input_token; +-gss_OID * actual_mech_type; +-gss_buffer_t output_token; +-OM_uint32 * ret_flags; +-OM_uint32 * time_rec; +- ++gss_init_sec_context(OM_uint32 *minor_status, ++ gss_cred_id_t claimant_cred_handle, ++ gss_ctx_id_t *context_handle, gss_name_t target_name, ++ gss_OID req_mech_type, OM_uint32 req_flags, ++ OM_uint32 time_req, ++ gss_channel_bindings_t input_chan_bindings, ++ gss_buffer_t input_token, gss_OID *actual_mech_type, ++ gss_buffer_t output_token, OM_uint32 *ret_flags, ++ OM_uint32 *time_rec) + { + OM_uint32 status, temp_minor_status; + gss_union_name_t union_name; +diff --git a/src/lib/gssapi/mechglue/g_initialize.c b/src/lib/gssapi/mechglue/g_initialize.c +index 22f6c615c1..7e36c4a0d0 100644 +--- a/src/lib/gssapi/mechglue/g_initialize.c ++++ b/src/lib/gssapi/mechglue/g_initialize.c +@@ -169,9 +169,7 @@ gssint_mechglue_initialize_library(void) + * This routine requires direct access to the mechList. + */ + OM_uint32 KRB5_CALLCONV +-gss_release_oid(minor_status, oid) +-OM_uint32 *minor_status; +-gss_OID *oid; ++gss_release_oid(OM_uint32 *minor_status, gss_OID *oid) + { + OM_uint32 major; + gss_mech_info aMech; +@@ -267,9 +265,7 @@ prune_deprecated(gss_OID_set mech_set) + * a mech oid set, and only update it once the file has changed. + */ + OM_uint32 KRB5_CALLCONV +-gss_indicate_mechs(minorStatus, mechSet_out) +-OM_uint32 *minorStatus; +-gss_OID_set *mechSet_out; ++gss_indicate_mechs(OM_uint32 *minorStatus, gss_OID_set *mechSet_out) + { + OM_uint32 status; + +@@ -417,8 +413,7 @@ build_mechSet(void) + * caller is responsible for freeing the memory + */ + char * +-gssint_get_modOptions(oid) +-const gss_OID oid; ++gssint_get_modOptions(const gss_OID oid) + { + gss_mech_info aMech; + char *modOptions = NULL; +@@ -479,7 +474,7 @@ load_if_changed(const char *pathname, time_t last, time_t *highest) + /* Try to load any config files which have changed since the last call. Config + * files are MECH_CONF and any files matching MECH_CONF_PATTERN. */ + static void +-loadConfigFiles() ++loadConfigFiles(void) + { + glob_t globbuf; + time_t highest = (time_t)-1, now; +@@ -679,7 +674,8 @@ gssint_register_mechinfo(gss_mech_info template) + memset(&errinfo, 0, sizeof(errinfo)); \ + if (krb5int_get_plugin_func(_dl, \ + #_symbol, \ +- (void (**)())&(_mech)->_symbol, \ ++ (void (**)(void)) \ ++ &(_mech)->_symbol, \ + &errinfo) || errinfo.code) { \ + (_mech)->_symbol = NULL; \ + k5_clear_error(&errinfo); \ +@@ -801,7 +797,7 @@ build_dynamicMech(void *dl, const gss_OID mech_type) + memset(&errinfo, 0, sizeof(errinfo)); \ + if (krb5int_get_plugin_func(_dl, \ + "gssi" #_nsym, \ +- (void (**)())&(_mech)->_psym \ ++ (void (**)(void))&(_mech)->_psym \ + ## _nsym, \ + &errinfo) || errinfo.code) { \ + (_mech)->_psym ## _nsym = NULL; \ +@@ -948,7 +944,7 @@ loadInterMech(gss_mech_info minfo) + } + + if (krb5int_get_plugin_func(dl, MECH_INTERPOSER_SYM, +- (void (**)())&isym, &errinfo) != 0) ++ (void (**)(void))&isym, &errinfo) != 0) + goto cleanup; + + /* Get a list of mechs to interpose. */ +@@ -1184,7 +1180,7 @@ gssint_get_mechanism(gss_const_OID oid) + return ((gss_mechanism)NULL); + } + +- if (krb5int_get_plugin_func(dl, MECH_SYM, (void (**)())&sym, ++ if (krb5int_get_plugin_func(dl, MECH_SYM, (void (**)(void))&sym, + &errinfo) == 0) { + /* Call the symbol to get the mechanism table */ + aMech->mech = (*sym)(aMech->mech_type); +diff --git a/src/lib/gssapi/mechglue/g_inq_cred.c b/src/lib/gssapi/mechglue/g_inq_cred.c +index 4ed7774f1a..0aa9acc889 100644 +--- a/src/lib/gssapi/mechglue/g_inq_cred.c ++++ b/src/lib/gssapi/mechglue/g_inq_cred.c +@@ -35,20 +35,9 @@ + #include + + OM_uint32 KRB5_CALLCONV +-gss_inquire_cred(minor_status, +- cred_handle, +- name, +- lifetime, +- cred_usage, +- mechanisms) +- +-OM_uint32 * minor_status; +-gss_cred_id_t cred_handle; +-gss_name_t * name; +-OM_uint32 * lifetime; +-int * cred_usage; +-gss_OID_set * mechanisms; +- ++gss_inquire_cred(OM_uint32 *minor_status, gss_cred_id_t cred_handle, ++ gss_name_t *name, OM_uint32 *lifetime, int *cred_usage, ++ gss_OID_set *mechanisms) + { + OM_uint32 status, temp_minor_status; + gss_union_cred_t union_cred; +@@ -159,15 +148,11 @@ error: + } + + OM_uint32 KRB5_CALLCONV +-gss_inquire_cred_by_mech(minor_status, cred_handle, mech_type, name, +- initiator_lifetime, acceptor_lifetime, cred_usage) +- OM_uint32 *minor_status; +- gss_cred_id_t cred_handle; +- gss_OID mech_type; +- gss_name_t *name; +- OM_uint32 *initiator_lifetime; +- OM_uint32 *acceptor_lifetime; +- gss_cred_usage_t *cred_usage; ++gss_inquire_cred_by_mech(OM_uint32 *minor_status, gss_cred_id_t cred_handle, ++ gss_OID mech_type, gss_name_t *name, ++ OM_uint32 *initiator_lifetime, ++ OM_uint32 *acceptor_lifetime, ++ gss_cred_usage_t *cred_usage) + { + gss_union_cred_t union_cred; + gss_cred_id_t mech_cred; +diff --git a/src/lib/gssapi/mechglue/g_inq_names.c b/src/lib/gssapi/mechglue/g_inq_names.c +index d22af8bcf9..066c00c042 100644 +--- a/src/lib/gssapi/mechglue/g_inq_names.c ++++ b/src/lib/gssapi/mechglue/g_inq_names.c +@@ -32,12 +32,8 @@ + + /* Last argument new for V2 */ + OM_uint32 KRB5_CALLCONV +-gss_inquire_names_for_mech(minor_status, mechanism, name_types) +- +-OM_uint32 * minor_status; +-gss_OID mechanism; +-gss_OID_set * name_types; +- ++gss_inquire_names_for_mech(OM_uint32 *minor_status, gss_OID mechanism, ++ gss_OID_set *name_types) + { + OM_uint32 status; + gss_OID selected_mech = GSS_C_NO_OID, public_mech; +diff --git a/src/lib/gssapi/mechglue/g_mechname.c b/src/lib/gssapi/mechglue/g_mechname.c +index cfb0a0d2af..5664fa157e 100644 +--- a/src/lib/gssapi/mechglue/g_mechname.c ++++ b/src/lib/gssapi/mechglue/g_mechname.c +@@ -20,8 +20,8 @@ static gss_mech_spec_name name_list = NULL; + /* + * generic searching helper function. + */ +-static gss_mech_spec_name search_mech_spec(name_type) +- gss_OID name_type; ++static gss_mech_spec_name ++search_mech_spec(gss_OID name_type) + { + gss_mech_spec_name p; + +@@ -36,8 +36,8 @@ static gss_mech_spec_name search_mech_spec(name_type) + * Given a name_type, if it is specific to a mechanism, return the + * mechanism OID. Otherwise, return NULL. + */ +-gss_OID gss_find_mechanism_from_name_type(name_type) +- gss_OID name_type; ++gss_OID ++gss_find_mechanism_from_name_type(gss_OID name_type) + { + gss_mech_spec_name p; + +@@ -54,10 +54,8 @@ gss_OID gss_find_mechanism_from_name_type(name_type) + * Otherwise, enter the pair into the registry. + */ + OM_uint32 +-gss_add_mech_name_type(minor_status, name_type, mech) +- OM_uint32 *minor_status; +- gss_OID name_type; +- gss_OID mech; ++gss_add_mech_name_type(OM_uint32 *minor_status, gss_OID name_type, ++ gss_OID mech) + { + OM_uint32 major_status, tmp; + gss_mech_spec_name p; +diff --git a/src/lib/gssapi/mechglue/g_oid_ops.c b/src/lib/gssapi/mechglue/g_oid_ops.c +index 1d7970c5dd..f29fb3b33e 100644 +--- a/src/lib/gssapi/mechglue/g_oid_ops.c ++++ b/src/lib/gssapi/mechglue/g_oid_ops.c +@@ -33,9 +33,7 @@ + */ + + OM_uint32 KRB5_CALLCONV +-gss_create_empty_oid_set(minor_status, oid_set) +- OM_uint32 *minor_status; +- gss_OID_set *oid_set; ++gss_create_empty_oid_set(OM_uint32 *minor_status, gss_OID_set *oid_set) + { + OM_uint32 status; + status = generic_gss_create_empty_oid_set(minor_status, oid_set); +@@ -45,10 +43,8 @@ gss_create_empty_oid_set(minor_status, oid_set) + } + + OM_uint32 KRB5_CALLCONV +-gss_add_oid_set_member(minor_status, member_oid, oid_set) +- OM_uint32 *minor_status; +- gss_OID member_oid; +- gss_OID_set *oid_set; ++gss_add_oid_set_member(OM_uint32 *minor_status, gss_OID member_oid, ++ gss_OID_set *oid_set) + { + OM_uint32 status; + status = generic_gss_add_oid_set_member(minor_status, member_oid, oid_set); +@@ -58,20 +54,14 @@ gss_add_oid_set_member(minor_status, member_oid, oid_set) + } + + OM_uint32 KRB5_CALLCONV +-gss_test_oid_set_member(minor_status, member, set, present) +- OM_uint32 *minor_status; +- gss_OID member; +- gss_OID_set set; +- int *present; ++gss_test_oid_set_member(OM_uint32 *minor_status, gss_OID member, ++ gss_OID_set set, int *present) + { + return generic_gss_test_oid_set_member(minor_status, member, set, present); + } + + OM_uint32 KRB5_CALLCONV +-gss_oid_to_str(minor_status, oid, oid_str) +- OM_uint32 *minor_status; +- gss_OID oid; +- gss_buffer_t oid_str; ++gss_oid_to_str(OM_uint32 *minor_status, gss_OID oid, gss_buffer_t oid_str) + { + OM_uint32 status = generic_gss_oid_to_str(minor_status, oid, oid_str); + if (status != GSS_S_COMPLETE) +@@ -80,10 +70,7 @@ gss_oid_to_str(minor_status, oid, oid_str) + } + + OM_uint32 KRB5_CALLCONV +-gss_str_to_oid(minor_status, oid_str, oid) +- OM_uint32 *minor_status; +- gss_buffer_t oid_str; +- gss_OID *oid; ++gss_str_to_oid(OM_uint32 *minor_status, gss_buffer_t oid_str, gss_OID *oid) + { + OM_uint32 status = generic_gss_str_to_oid(minor_status, oid_str, oid); + if (status != GSS_S_COMPLETE) +diff --git a/src/lib/gssapi/mechglue/g_process_context.c b/src/lib/gssapi/mechglue/g_process_context.c +index 3968b5d9c6..2b3f6c704d 100644 +--- a/src/lib/gssapi/mechglue/g_process_context.c ++++ b/src/lib/gssapi/mechglue/g_process_context.c +@@ -29,14 +29,8 @@ + #include "mglueP.h" + + OM_uint32 KRB5_CALLCONV +-gss_process_context_token (minor_status, +- context_handle, +- token_buffer) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-gss_buffer_t token_buffer; +- ++gss_process_context_token(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t token_buffer) + { + OM_uint32 status; + gss_union_ctx_id_t ctx; +diff --git a/src/lib/gssapi/mechglue/g_rel_buffer.c b/src/lib/gssapi/mechglue/g_rel_buffer.c +index 8c3328acc5..60117bdb56 100644 +--- a/src/lib/gssapi/mechglue/g_rel_buffer.c ++++ b/src/lib/gssapi/mechglue/g_rel_buffer.c +@@ -33,11 +33,7 @@ + #endif + + OM_uint32 KRB5_CALLCONV +-gss_release_buffer (minor_status, +- buffer) +- +-OM_uint32 * minor_status; +-gss_buffer_t buffer; ++gss_release_buffer(OM_uint32 *minor_status, gss_buffer_t buffer) + { + if (minor_status) + *minor_status = 0; +diff --git a/src/lib/gssapi/mechglue/g_rel_cred.c b/src/lib/gssapi/mechglue/g_rel_cred.c +index ccdee05a56..ee3d1d71e3 100644 +--- a/src/lib/gssapi/mechglue/g_rel_cred.c ++++ b/src/lib/gssapi/mechglue/g_rel_cred.c +@@ -31,12 +31,7 @@ + #endif + + OM_uint32 KRB5_CALLCONV +-gss_release_cred(minor_status, +- cred_handle) +- +-OM_uint32 * minor_status; +-gss_cred_id_t * cred_handle; +- ++gss_release_cred(OM_uint32 *minor_status, gss_cred_id_t *cred_handle) + { + OM_uint32 status, temp_status; + int j; +diff --git a/src/lib/gssapi/mechglue/g_rel_name.c b/src/lib/gssapi/mechglue/g_rel_name.c +index e008692383..d490f9f290 100644 +--- a/src/lib/gssapi/mechglue/g_rel_name.c ++++ b/src/lib/gssapi/mechglue/g_rel_name.c +@@ -34,12 +34,7 @@ + #include + + OM_uint32 KRB5_CALLCONV +-gss_release_name (minor_status, +- input_name) +- +-OM_uint32 * minor_status; +-gss_name_t * input_name; +- ++gss_release_name(OM_uint32 *minor_status, gss_name_t *input_name) + { + gss_union_name_t union_name; + +diff --git a/src/lib/gssapi/mechglue/g_rel_oid_set.c b/src/lib/gssapi/mechglue/g_rel_oid_set.c +index fa008d6bb9..9151dd2e71 100644 +--- a/src/lib/gssapi/mechglue/g_rel_oid_set.c ++++ b/src/lib/gssapi/mechglue/g_rel_oid_set.c +@@ -33,11 +33,7 @@ + #endif + + OM_uint32 KRB5_CALLCONV +-gss_release_oid_set (minor_status, +- set) +- +-OM_uint32 * minor_status; +-gss_OID_set * set; ++gss_release_oid_set(OM_uint32 *minor_status, gss_OID_set *set) + { + return generic_gss_release_oid_set(minor_status, set); + } +diff --git a/src/lib/gssapi/mechglue/g_sign.c b/src/lib/gssapi/mechglue/g_sign.c +index 03fbd8c01f..c9af1da570 100644 +--- a/src/lib/gssapi/mechglue/g_sign.c ++++ b/src/lib/gssapi/mechglue/g_sign.c +@@ -66,18 +66,9 @@ val_get_mic_args( + + + OM_uint32 KRB5_CALLCONV +-gss_get_mic (minor_status, +- context_handle, +- qop_req, +- message_buffer, +- msg_token) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-gss_qop_t qop_req; +-gss_buffer_t message_buffer; +-gss_buffer_t msg_token; +- ++gss_get_mic(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_qop_t qop_req, gss_buffer_t message_buffer, ++ gss_buffer_t msg_token) + { + OM_uint32 status; + gss_union_ctx_id_t ctx; +@@ -118,18 +109,8 @@ gss_buffer_t msg_token; + } + + OM_uint32 KRB5_CALLCONV +-gss_sign (minor_status, +- context_handle, +- qop_req, +- message_buffer, +- msg_token) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-int qop_req; +-gss_buffer_t message_buffer; +-gss_buffer_t msg_token; +- ++gss_sign(OM_uint32 *minor_status, gss_ctx_id_t context_handle, int qop_req, ++ gss_buffer_t message_buffer, gss_buffer_t msg_token) + { + return (gss_get_mic(minor_status, context_handle, (gss_qop_t) qop_req, + message_buffer, msg_token)); +diff --git a/src/lib/gssapi/mechglue/g_store_cred.c b/src/lib/gssapi/mechglue/g_store_cred.c +index c2b6ddf3c0..231b3e81a0 100644 +--- a/src/lib/gssapi/mechglue/g_store_cred.c ++++ b/src/lib/gssapi/mechglue/g_store_cred.c +@@ -93,24 +93,10 @@ val_store_cred_args( + + + OM_uint32 KRB5_CALLCONV +-gss_store_cred(minor_status, +- input_cred_handle, +- cred_usage, +- desired_mech, +- overwrite_cred, +- default_cred, +- elements_stored, +- cred_usage_stored) +- +-OM_uint32 *minor_status; +-gss_cred_id_t input_cred_handle; +-gss_cred_usage_t cred_usage; +-const gss_OID desired_mech; +-OM_uint32 overwrite_cred; +-OM_uint32 default_cred; +-gss_OID_set *elements_stored; +-gss_cred_usage_t *cred_usage_stored; +- ++gss_store_cred(OM_uint32 *minor_status, gss_cred_id_t input_cred_handle, ++ gss_cred_usage_t cred_usage, const gss_OID desired_mech, ++ OM_uint32 overwrite_cred, OM_uint32 default_cred, ++ gss_OID_set *elements_stored, gss_cred_usage_t *cred_usage_stored) + { + return gss_store_cred_into(minor_status, input_cred_handle, cred_usage, + desired_mech, overwrite_cred, default_cred, +@@ -119,26 +105,12 @@ gss_cred_usage_t *cred_usage_stored; + } + + OM_uint32 KRB5_CALLCONV +-gss_store_cred_into(minor_status, +- input_cred_handle, +- cred_usage, +- desired_mech, +- overwrite_cred, +- default_cred, +- cred_store, +- elements_stored, +- cred_usage_stored) +- +-OM_uint32 *minor_status; +-gss_cred_id_t input_cred_handle; +-gss_cred_usage_t cred_usage; +-gss_OID desired_mech; +-OM_uint32 overwrite_cred; +-OM_uint32 default_cred; +-gss_const_key_value_set_t cred_store; +-gss_OID_set *elements_stored; +-gss_cred_usage_t *cred_usage_stored; +- ++gss_store_cred_into(OM_uint32 *minor_status, gss_cred_id_t input_cred_handle, ++ gss_cred_usage_t cred_usage, gss_OID desired_mech, ++ OM_uint32 overwrite_cred, OM_uint32 default_cred, ++ gss_const_key_value_set_t cred_store, ++ gss_OID_set *elements_stored, ++ gss_cred_usage_t *cred_usage_stored) + { + OM_uint32 major_status = GSS_S_FAILURE; + gss_union_cred_t union_cred; +diff --git a/src/lib/gssapi/mechglue/g_unseal.c b/src/lib/gssapi/mechglue/g_unseal.c +index c208635b67..2be3745d1f 100644 +--- a/src/lib/gssapi/mechglue/g_unseal.c ++++ b/src/lib/gssapi/mechglue/g_unseal.c +@@ -29,20 +29,10 @@ + #include "mglueP.h" + + OM_uint32 KRB5_CALLCONV +-gss_unwrap (minor_status, +- context_handle, +- input_message_buffer, +- output_message_buffer, +- conf_state, +- qop_state) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-gss_buffer_t input_message_buffer; +-gss_buffer_t output_message_buffer; +-int * conf_state; +-gss_qop_t * qop_state; +- ++gss_unwrap(OM_uint32 * minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t input_message_buffer, ++ gss_buffer_t output_message_buffer, ++ int *conf_state, gss_qop_t *qop_state) + { + /* EXPORT DELETE START */ + OM_uint32 status; +@@ -111,20 +101,9 @@ gss_qop_t * qop_state; + } + + OM_uint32 KRB5_CALLCONV +-gss_unseal (minor_status, +- context_handle, +- input_message_buffer, +- output_message_buffer, +- conf_state, +- qop_state) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-gss_buffer_t input_message_buffer; +-gss_buffer_t output_message_buffer; +-int * conf_state; +-int * qop_state; +- ++gss_unseal(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t input_message_buffer, ++ gss_buffer_t output_message_buffer, int *conf_state, int *qop_state) + { + return (gss_unwrap(minor_status, context_handle, + input_message_buffer, +diff --git a/src/lib/gssapi/mechglue/g_unwrap_aead.c b/src/lib/gssapi/mechglue/g_unwrap_aead.c +index 0682bd8998..5c9ff30031 100644 +--- a/src/lib/gssapi/mechglue/g_unwrap_aead.c ++++ b/src/lib/gssapi/mechglue/g_unwrap_aead.c +@@ -154,20 +154,11 @@ gssint_unwrap_aead (gss_mechanism mech, + } + + OM_uint32 KRB5_CALLCONV +-gss_unwrap_aead (minor_status, +- context_handle, +- input_message_buffer, +- input_assoc_buffer, +- output_payload_buffer, +- conf_state, +- qop_state) +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-gss_buffer_t input_message_buffer; +-gss_buffer_t input_assoc_buffer; +-gss_buffer_t output_payload_buffer; +-int *conf_state; +-gss_qop_t *qop_state; ++gss_unwrap_aead(OM_uint32 * minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t input_message_buffer, ++ gss_buffer_t input_assoc_buffer, ++ gss_buffer_t output_payload_buffer, ++ int *conf_state, gss_qop_t *qop_state) + { + + OM_uint32 status; +diff --git a/src/lib/gssapi/mechglue/g_unwrap_iov.c b/src/lib/gssapi/mechglue/g_unwrap_iov.c +index 599be2c7b2..bf9c3bcc33 100644 +--- a/src/lib/gssapi/mechglue/g_unwrap_iov.c ++++ b/src/lib/gssapi/mechglue/g_unwrap_iov.c +@@ -59,18 +59,9 @@ val_unwrap_iov_args( + + + OM_uint32 KRB5_CALLCONV +-gss_unwrap_iov (minor_status, +- context_handle, +- conf_state, +- qop_state, +- iov, +- iov_count) +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-int * conf_state; +-gss_qop_t *qop_state; +-gss_iov_buffer_desc * iov; +-int iov_count; ++gss_unwrap_iov(OM_uint32 * minor_status, gss_ctx_id_t context_handle, ++ int *conf_state, gss_qop_t *qop_state, ++ gss_iov_buffer_desc *iov, int iov_count) + { + /* EXPORT DELETE START */ + +diff --git a/src/lib/gssapi/mechglue/g_verify.c b/src/lib/gssapi/mechglue/g_verify.c +index 8996fce8d5..86ade66877 100644 +--- a/src/lib/gssapi/mechglue/g_verify.c ++++ b/src/lib/gssapi/mechglue/g_verify.c +@@ -29,18 +29,9 @@ + #include "mglueP.h" + + OM_uint32 KRB5_CALLCONV +-gss_verify_mic (minor_status, +- context_handle, +- message_buffer, +- token_buffer, +- qop_state) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-gss_buffer_t message_buffer; +-gss_buffer_t token_buffer; +-gss_qop_t * qop_state; +- ++gss_verify_mic(OM_uint32 * minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t message_buffer, gss_buffer_t token_buffer, ++ gss_qop_t *qop_state) + { + OM_uint32 status; + gss_union_ctx_id_t ctx; +@@ -89,18 +80,9 @@ gss_qop_t * qop_state; + } + + OM_uint32 KRB5_CALLCONV +-gss_verify (minor_status, +- context_handle, +- message_buffer, +- token_buffer, +- qop_state) +- +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-gss_buffer_t message_buffer; +-gss_buffer_t token_buffer; +-int * qop_state; +- ++gss_verify(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ gss_buffer_t message_buffer, gss_buffer_t token_buffer, ++ int *qop_state) + { + return (gss_verify_mic(minor_status, context_handle, + message_buffer, token_buffer, +diff --git a/src/lib/gssapi/mechglue/g_wrap_aead.c b/src/lib/gssapi/mechglue/g_wrap_aead.c +index 7fe3b7b35b..5a6570f7f9 100644 +--- a/src/lib/gssapi/mechglue/g_wrap_aead.c ++++ b/src/lib/gssapi/mechglue/g_wrap_aead.c +@@ -177,15 +177,11 @@ gssint_wrap_aead_iov_shim(gss_mechanism mech, + } + + OM_uint32 +-gssint_wrap_aead (gss_mechanism mech, +- OM_uint32 *minor_status, +- gss_union_ctx_id_t ctx, +- int conf_req_flag, +- gss_qop_t qop_req, +- gss_buffer_t input_assoc_buffer, +- gss_buffer_t input_payload_buffer, +- int *conf_state, +- gss_buffer_t output_message_buffer) ++gssint_wrap_aead(gss_mechanism mech, OM_uint32 *minor_status, ++ gss_union_ctx_id_t ctx, int conf_req_flag, gss_qop_t qop_req, ++ gss_buffer_t input_assoc_buffer, ++ gss_buffer_t input_payload_buffer, ++ int *conf_state, gss_buffer_t output_message_buffer) + { + /* EXPORT DELETE START */ + OM_uint32 status; +@@ -223,22 +219,15 @@ gssint_wrap_aead (gss_mechanism mech, + } + + OM_uint32 KRB5_CALLCONV +-gss_wrap_aead (minor_status, +- context_handle, +- conf_req_flag, +- qop_req, +- input_assoc_buffer, +- input_payload_buffer, +- conf_state, +- output_message_buffer) +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-int conf_req_flag; +-gss_qop_t qop_req; +-gss_buffer_t input_assoc_buffer; +-gss_buffer_t input_payload_buffer; +-int * conf_state; +-gss_buffer_t output_message_buffer; ++gss_wrap_aead ( ++ OM_uint32 * minor_status, ++ gss_ctx_id_t context_handle, ++ int conf_req_flag, ++ gss_qop_t qop_req, ++ gss_buffer_t input_assoc_buffer, ++ gss_buffer_t input_payload_buffer, ++ int * conf_state, ++ gss_buffer_t output_message_buffer) + { + OM_uint32 status; + gss_mechanism mech; +diff --git a/src/lib/gssapi/mechglue/g_wrap_iov.c b/src/lib/gssapi/mechglue/g_wrap_iov.c +index 14447c4ee1..aaf3a9308e 100644 +--- a/src/lib/gssapi/mechglue/g_wrap_iov.c ++++ b/src/lib/gssapi/mechglue/g_wrap_iov.c +@@ -60,20 +60,9 @@ val_wrap_iov_args( + + + OM_uint32 KRB5_CALLCONV +-gss_wrap_iov (minor_status, +- context_handle, +- conf_req_flag, +- qop_req, +- conf_state, +- iov, +- iov_count) +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-int conf_req_flag; +-gss_qop_t qop_req; +-int * conf_state; +-gss_iov_buffer_desc * iov; +-int iov_count; ++gss_wrap_iov(OM_uint32 * minor_status, gss_ctx_id_t context_handle, ++ int conf_req_flag, gss_qop_t qop_req, int *conf_state, ++ gss_iov_buffer_desc *iov, int iov_count) + { + /* EXPORT DELETE START */ + +@@ -120,20 +109,10 @@ int iov_count; + } + + OM_uint32 KRB5_CALLCONV +-gss_wrap_iov_length (minor_status, +- context_handle, +- conf_req_flag, +- qop_req, +- conf_state, +- iov, +- iov_count) +-OM_uint32 * minor_status; +-gss_ctx_id_t context_handle; +-int conf_req_flag; +-gss_qop_t qop_req; +-int * conf_state; +-gss_iov_buffer_desc * iov; +-int iov_count; ++gss_wrap_iov_length(OM_uint32 *minor_status, gss_ctx_id_t context_handle, ++ int conf_req_flag, gss_qop_t qop_req, ++ int *conf_state, gss_iov_buffer_desc *iov, ++ int iov_count) + { + /* EXPORT DELETE START */ + +@@ -239,12 +218,8 @@ gss_get_mic_iov_length(OM_uint32 *minor_status, gss_ctx_id_t context_handle, + } + + OM_uint32 KRB5_CALLCONV +-gss_release_iov_buffer (minor_status, +- iov, +- iov_count) +-OM_uint32 * minor_status; +-gss_iov_buffer_desc * iov; +-int iov_count; ++gss_release_iov_buffer(OM_uint32 * minor_status, gss_iov_buffer_desc *iov, ++ int iov_count) + { + OM_uint32 status = GSS_S_COMPLETE; + int i; +diff --git a/src/lib/kadm5/clnt/client_rpc.c b/src/lib/kadm5/clnt/client_rpc.c +index d84d158b46..c8d844e4c7 100644 +--- a/src/lib/kadm5/clnt/client_rpc.c ++++ b/src/lib/kadm5/clnt/client_rpc.c +@@ -1,6 +1,7 @@ + /* -*- mode: c; c-file-style: "bsd"; indent-tabs-mode: t -*- */ + #include + #include ++#include + #include + #include + #include /* for memset prototype */ +diff --git a/src/lib/kadm5/kadm_rpc.h b/src/lib/kadm5/kadm_rpc.h +index 5099c6c145..9efe49a373 100644 +--- a/src/lib/kadm5/kadm_rpc.h ++++ b/src/lib/kadm5/kadm_rpc.h +@@ -360,49 +360,4 @@ extern enum clnt_stat get_principal_keys_2(getpkeys_arg *, getpkeys_ret *, + CLIENT *); + extern bool_t get_principal_keys_2_svc(getpkeys_arg *, getpkeys_ret *, + struct svc_req *); +- +-extern bool_t xdr_cprinc_arg (); +-extern bool_t xdr_cprinc3_arg (); +-extern bool_t xdr_generic_ret (); +-extern bool_t xdr_dprinc_arg (); +-extern bool_t xdr_mprinc_arg (); +-extern bool_t xdr_rprinc_arg (); +-extern bool_t xdr_gprincs_arg (); +-extern bool_t xdr_gprincs_ret (); +-extern bool_t xdr_chpass_arg (); +-extern bool_t xdr_chpass3_arg (); +-extern bool_t xdr_setkey_arg (); +-extern bool_t xdr_setkey3_arg (); +-extern bool_t xdr_setkey4_arg (); +-extern bool_t xdr_chrand_arg (); +-extern bool_t xdr_chrand3_arg (); +-extern bool_t xdr_chrand_ret (); +-extern bool_t xdr_gprinc_arg (); +-extern bool_t xdr_gprinc_ret (); +-extern bool_t xdr_kadm5_ret_t (); +-extern bool_t xdr_kadm5_principal_ent_rec (); +-extern bool_t xdr_kadm5_policy_ent_rec (); +-extern bool_t xdr_krb5_keyblock (); +-extern bool_t xdr_krb5_principal (); +-extern bool_t xdr_krb5_enctype (); +-extern bool_t xdr_krb5_octet (); +-extern bool_t xdr_krb5_int32 (); +-extern bool_t xdr_u_int32 (); +-extern bool_t xdr_cpol_arg (); +-extern bool_t xdr_dpol_arg (); +-extern bool_t xdr_mpol_arg (); +-extern bool_t xdr_gpol_arg (); +-extern bool_t xdr_gpol_ret (); +-extern bool_t xdr_gpols_arg (); +-extern bool_t xdr_gpols_ret (); +-extern bool_t xdr_getprivs_ret (); +-extern bool_t xdr_purgekeys_arg (); +-extern bool_t xdr_gstrings_arg (); +-extern bool_t xdr_gstrings_ret (); +-extern bool_t xdr_sstring_arg (); +-extern bool_t xdr_krb5_string_attr (); +-extern bool_t xdr_kadm5_key_data (); +-extern bool_t xdr_getpkeys_arg (); +-extern bool_t xdr_getpkeys_ret (); +- + #endif /* __KADM_RPC_H__ */ +diff --git a/src/lib/kadm5/kadm_rpc_xdr.c b/src/lib/kadm5/kadm_rpc_xdr.c +index 287cae750f..5e052dd90c 100644 +--- a/src/lib/kadm5/kadm_rpc_xdr.c ++++ b/src/lib/kadm5/kadm_rpc_xdr.c +@@ -408,7 +408,7 @@ _xdr_kadm5_principal_ent_rec(XDR *xdrs, kadm5_principal_ent_rec *objp, + return (FALSE); + } + if (!xdr_nulltype(xdrs, (void **) &objp->mod_name, +- xdr_krb5_principal)) { ++ (xdrproc_t)xdr_krb5_principal)) { + return (FALSE); + } + if (!xdr_krb5_timestamp(xdrs, &objp->mod_date)) { +@@ -451,12 +451,13 @@ _xdr_kadm5_principal_ent_rec(XDR *xdrs, kadm5_principal_ent_rec *objp, + return (FALSE); + } + if (!xdr_nulltype(xdrs, (void **) &objp->tl_data, +- xdr_krb5_tl_data)) { ++ (xdrproc_t)xdr_krb5_tl_data)) { + return FALSE; + } + n = objp->n_key_data; + r = xdr_array(xdrs, (caddr_t *) &objp->key_data, &n, objp->n_key_data, +- sizeof(krb5_key_data), xdr_krb5_key_data_nocontents); ++ sizeof(krb5_key_data), ++ (xdrproc_t)xdr_krb5_key_data_nocontents); + objp->n_key_data = n; + if (!r) { + return (FALSE); +@@ -528,7 +529,7 @@ _xdr_kadm5_policy_ent_rec(XDR *xdrs, kadm5_policy_ent_rec *objp, int vers) + return (FALSE); + } + if (!xdr_nulltype(xdrs, (void **) &objp->tl_data, +- xdr_krb5_tl_data)) { ++ (xdrproc_t)xdr_krb5_tl_data)) { + return FALSE; + } + } +@@ -576,7 +577,7 @@ xdr_cprinc3_arg(XDR *xdrs, cprinc3_arg *objp) + if (!xdr_array(xdrs, (caddr_t *)&objp->ks_tuple, + (unsigned int *)&objp->n_ks_tuple, ~0, + sizeof(krb5_key_salt_tuple), +- xdr_krb5_key_salt_tuple)) { ++ (xdrproc_t)xdr_krb5_key_salt_tuple)) { + return (FALSE); + } + if (!xdr_nullstring(xdrs, &objp->passwd)) { +@@ -668,7 +669,7 @@ xdr_gprincs_ret(XDR *xdrs, gprincs_ret *objp) + } + if (!xdr_array(xdrs, (caddr_t *) &objp->princs, + (unsigned int *) &objp->count, ~0, +- sizeof(char *), xdr_nullstring)) { ++ sizeof(char *), (xdrproc_t)xdr_nullstring)) { + return (FALSE); + } + } +@@ -706,7 +707,7 @@ xdr_chpass3_arg(XDR *xdrs, chpass3_arg *objp) + if (!xdr_array(xdrs, (caddr_t *)&objp->ks_tuple, + (unsigned int*)&objp->n_ks_tuple, ~0, + sizeof(krb5_key_salt_tuple), +- xdr_krb5_key_salt_tuple)) { ++ (xdrproc_t)xdr_krb5_key_salt_tuple)) { + return (FALSE); + } + if (!xdr_nullstring(xdrs, &objp->pass)) { +@@ -726,7 +727,7 @@ xdr_setkey_arg(XDR *xdrs, setkey_arg *objp) + } + if (!xdr_array(xdrs, (caddr_t *) &objp->keyblocks, + (unsigned int *) &objp->n_keys, ~0, +- sizeof(krb5_keyblock), xdr_krb5_keyblock)) { ++ sizeof(krb5_keyblock), (xdrproc_t)xdr_krb5_keyblock)) { + return (FALSE); + } + return (TRUE); +@@ -746,12 +747,13 @@ xdr_setkey3_arg(XDR *xdrs, setkey3_arg *objp) + } + if (!xdr_array(xdrs, (caddr_t *) &objp->ks_tuple, + (unsigned int *) &objp->n_ks_tuple, ~0, +- sizeof(krb5_key_salt_tuple), xdr_krb5_key_salt_tuple)) { ++ sizeof(krb5_key_salt_tuple), ++ (xdrproc_t)xdr_krb5_key_salt_tuple)) { + return (FALSE); + } + if (!xdr_array(xdrs, (caddr_t *) &objp->keyblocks, + (unsigned int *) &objp->n_keys, ~0, +- sizeof(krb5_keyblock), xdr_krb5_keyblock)) { ++ sizeof(krb5_keyblock), (xdrproc_t)xdr_krb5_keyblock)) { + return (FALSE); + } + return (TRUE); +@@ -771,7 +773,8 @@ xdr_setkey4_arg(XDR *xdrs, setkey4_arg *objp) + } + if (!xdr_array(xdrs, (caddr_t *) &objp->key_data, + (unsigned int *) &objp->n_key_data, ~0, +- sizeof(kadm5_key_data), xdr_kadm5_key_data)) { ++ sizeof(kadm5_key_data), ++ (xdrproc_t)xdr_kadm5_key_data)) { + return FALSE; + } + return TRUE; +@@ -804,7 +807,7 @@ xdr_chrand3_arg(XDR *xdrs, chrand3_arg *objp) + if (!xdr_array(xdrs, (caddr_t *)&objp->ks_tuple, + (unsigned int*)&objp->n_ks_tuple, ~0, + sizeof(krb5_key_salt_tuple), +- xdr_krb5_key_salt_tuple)) { ++ (xdrproc_t)xdr_krb5_key_salt_tuple)) { + return (FALSE); + } + return (TRUE); +@@ -822,7 +825,8 @@ xdr_chrand_ret(XDR *xdrs, chrand_ret *objp) + if (objp->code == KADM5_OK) { + if (!xdr_array(xdrs, (char **)&objp->keys, + (unsigned int *)&objp->n_keys, ~0, +- sizeof(krb5_keyblock), xdr_krb5_keyblock)) ++ sizeof(krb5_keyblock), ++ (xdrproc_t)xdr_krb5_keyblock)) + return FALSE; + } + +@@ -965,7 +969,7 @@ xdr_gpols_ret(XDR *xdrs, gpols_ret *objp) + } + if (!xdr_array(xdrs, (caddr_t *) &objp->pols, + (unsigned int *) &objp->count, ~0, +- sizeof(char *), xdr_nullstring)) { ++ sizeof(char *), (xdrproc_t)xdr_nullstring)) { + return (FALSE); + } + } +@@ -1030,7 +1034,7 @@ xdr_gstrings_ret(XDR *xdrs, gstrings_ret *objp) + if (!xdr_array(xdrs, (caddr_t *) &objp->strings, + (unsigned int *) &objp->count, ~0, + sizeof(krb5_string_attr), +- xdr_krb5_string_attr)) { ++ (xdrproc_t)xdr_krb5_string_attr)) { + return (FALSE); + } + } +@@ -1198,7 +1202,8 @@ xdr_getpkeys_ret(XDR *xdrs, getpkeys_ret *objp) + if (objp->code == KADM5_OK) { + if (!xdr_array(xdrs, (caddr_t *) &objp->key_data, + (unsigned int *) &objp->n_key_data, ~0, +- sizeof(kadm5_key_data), xdr_kadm5_key_data)) { ++ sizeof(kadm5_key_data), ++ (xdrproc_t)xdr_kadm5_key_data)) { + return FALSE; + } + } +diff --git a/src/lib/kadm5/misc_free.c b/src/lib/kadm5/misc_free.c +index 74d23760fb..9ac47bb87f 100644 +--- a/src/lib/kadm5/misc_free.c ++++ b/src/lib/kadm5/misc_free.c +@@ -41,9 +41,8 @@ kadm5_free_name_list(void *server_handle, char **names, int count) + } + + /* XXX this ought to be in libkrb5.a, but isn't */ +-kadm5_ret_t krb5_free_key_data_contents(context, key) +- krb5_context context; +- krb5_key_data *key; ++kadm5_ret_t ++krb5_free_key_data_contents(krb5_context context, krb5_key_data *key) + { + int i, idx; + +diff --git a/src/lib/kadm5/srv/adb_xdr.c b/src/lib/kadm5/srv/adb_xdr.c +index fc732971d2..b6ffdb8c7a 100644 +--- a/src/lib/kadm5/srv/adb_xdr.c ++++ b/src/lib/kadm5/srv/adb_xdr.c +@@ -53,8 +53,7 @@ xdr_osa_pw_hist_ent(XDR *xdrs, osa_pw_hist_ent *objp) + { + if (!xdr_array(xdrs, (caddr_t *) &objp->key_data, + (u_int *) &objp->n_key_data, ~0, +- sizeof(krb5_key_data), +- xdr_krb5_key_data)) ++ sizeof(krb5_key_data), (xdrproc_t)xdr_krb5_key_data)) + return (FALSE); + return (TRUE); + } +@@ -88,8 +87,7 @@ xdr_osa_princ_ent_rec(XDR *xdrs, osa_princ_ent_t objp) + return (FALSE); + if (!xdr_array(xdrs, (caddr_t *) &objp->old_keys, + (unsigned int *) &objp->old_key_len, ~0, +- sizeof(osa_pw_hist_ent), +- xdr_osa_pw_hist_ent)) ++ sizeof(osa_pw_hist_ent), (xdrproc_t)xdr_osa_pw_hist_ent)) + return (FALSE); + return (TRUE); + } +diff --git a/src/lib/kadm5/srv/svr_principal.c b/src/lib/kadm5/srv/svr_principal.c +index 8c3ad3a691..d5bb0b167d 100644 +--- a/src/lib/kadm5/srv/svr_principal.c ++++ b/src/lib/kadm5/srv/svr_principal.c +@@ -30,9 +30,9 @@ static int decrypt_key_data(krb5_context context, + /* + * XXX Functions that ought to be in libkrb5.a, but aren't. + */ +-kadm5_ret_t krb5_copy_key_data_contents(context, from, to) +- krb5_context context; +- krb5_key_data *from, *to; ++kadm5_ret_t ++krb5_copy_key_data_contents(krb5_context context, krb5_key_data *from, ++ krb5_key_data *to) + { + int i, idx; + +@@ -75,10 +75,8 @@ static krb5_tl_data *dup_tl_data(krb5_tl_data *tl) + } + + /* This is in lib/kdb/kdb_cpw.c, but is static */ +-static void cleanup_key_data(context, count, data) +- krb5_context context; +- int count; +- krb5_key_data * data; ++static void ++cleanup_key_data(krb5_context context, int count, krb5_key_data *data) + { + int i; + +diff --git a/src/lib/kadm5/str_conv.c b/src/lib/kadm5/str_conv.c +index 7982956062..f2fae832eb 100644 +--- a/src/lib/kadm5/str_conv.c ++++ b/src/lib/kadm5/str_conv.c +@@ -267,11 +267,8 @@ cleanup: + * Salttype may be negative to indicate a search for only a enctype. + */ + krb5_boolean +-krb5_keysalt_is_present(ksaltlist, nksalts, enctype, salttype) +- krb5_key_salt_tuple *ksaltlist; +- krb5_int32 nksalts; +- krb5_enctype enctype; +- krb5_int32 salttype; ++krb5_keysalt_is_present(krb5_key_salt_tuple *ksaltlist, krb5_int32 nksalts, ++ krb5_enctype enctype, krb5_int32 salttype) + { + krb5_boolean foundit; + int i; +@@ -375,12 +372,11 @@ cleanup: + * If ignoresalt set, then salttype is ignored. + */ + krb5_error_code +-krb5_keysalt_iterate(ksaltlist, nksalt, ignoresalt, iterator, arg) +- krb5_key_salt_tuple *ksaltlist; +- krb5_int32 nksalt; +- krb5_boolean ignoresalt; +- krb5_error_code (*iterator) (krb5_key_salt_tuple *, krb5_pointer); +- krb5_pointer arg; ++krb5_keysalt_iterate(krb5_key_salt_tuple *ksaltlist, krb5_int32 nksalt, ++ krb5_boolean ignoresalt, ++ krb5_error_code (*iterator)(krb5_key_salt_tuple *, ++ void *), ++ void *arg) + { + int i; + krb5_error_code kret; +diff --git a/src/lib/kadm5/t_kadm5.c b/src/lib/kadm5/t_kadm5.c +index 153147ffbf..b3ab1004f3 100644 +--- a/src/lib/kadm5/t_kadm5.c ++++ b/src/lib/kadm5/t_kadm5.c +@@ -276,7 +276,7 @@ cpw_test_succeed(char *user, krb5_principal princ, char *pass) + } + + static void +-test_chpass() ++test_chpass(void) + { + krb5_principal princ = parse_princ("chpass-test"); + krb5_principal hist_princ = parse_princ("kadmin/history"); +@@ -334,7 +334,7 @@ cpol_test_compare(char *user, kadm5_policy_ent_t ent, uint32_t mask) + } + + static void +-test_create_policy() ++test_create_policy(void) + { + void *handle; + kadm5_policy_ent_rec ent; +@@ -440,7 +440,7 @@ cprinc_test_compare(char *user, kadm5_principal_ent_t ent, uint32_t mask, + } + + static void +-test_create_principal() ++test_create_principal(void) + { + void *handle; + kadm5_principal_ent_rec ent; +@@ -535,7 +535,7 @@ dpol_test_succeed(char *user, char *name) + } + + static void +-test_delete_policy() ++test_delete_policy(void) + { + krb5_principal princ = parse_princ("delete-policy-test-princ"); + +@@ -587,7 +587,7 @@ dprinc_test_succeed(char *user, krb5_principal princ) + } + + static void +-test_delete_principal() ++test_delete_principal(void) + { + krb5_principal princ = parse_princ("delete-principal-test"); + +@@ -638,7 +638,7 @@ gpol_test_fail(char *user, char *name, krb5_error_code code) + } + + static void +-test_get_policy() ++test_get_policy(void) + { + /* Fails with unknown policy. */ + dpol_test_fail("admin", "unknown-policy", KADM5_UNK_POLICY); +@@ -684,7 +684,7 @@ gprinc_test_fail(char *user, krb5_principal princ, krb5_error_code code) + } + + static void +-test_get_principal() ++test_get_principal(void) + { + void *handle; + kadm5_principal_ent_rec ent; +@@ -743,7 +743,7 @@ test_get_principal() + } + + static void +-test_init_destroy() ++test_init_destroy(void) + { + krb5_context ctx; + kadm5_ret_t ret; +@@ -1019,7 +1019,7 @@ mpol_test_compare(void *handle, kadm5_policy_ent_t ent, uint32_t mask) + } + + static void +-test_modify_policy() ++test_modify_policy(void) + { + kadm5_policy_ent_rec ent; + +@@ -1109,7 +1109,7 @@ mprinc_test_compare(char *user, kadm5_principal_ent_t ent, uint32_t mask) + } + + static void +-test_modify_principal() ++test_modify_principal(void) + { + void *handle; + krb5_principal princ = parse_princ("modify-principal-test"); +@@ -1233,7 +1233,7 @@ rnd_test_succeed(char *user, krb5_principal princ) + } + + static void +-test_randkey() ++test_randkey(void) + { + void *handle; + krb5_principal princ = parse_princ("randkey-principal-test"); +diff --git a/src/lib/kdb/kdb5.c b/src/lib/kdb/kdb5.c +index 415ae64e22..0837f567cc 100644 +--- a/src/lib/kdb/kdb5.c ++++ b/src/lib/kdb/kdb5.c +@@ -75,13 +75,13 @@ free_mkey_list(krb5_context context, krb5_keylist_node *mkey_list) + } + + int +-kdb_init_lock_list() ++kdb_init_lock_list(void) + { + return k5_mutex_finish_init(&db_lock); + } + + static int +-kdb_lock_list() ++kdb_lock_list(void) + { + int err; + err = CALL_INIT_FUNCTION (kdb_init_lock_list); +@@ -92,14 +92,14 @@ kdb_lock_list() + } + + void +-kdb_fini_lock_list() ++kdb_fini_lock_list(void) + { + if (INITIALIZER_RAN(kdb_init_lock_list)) + k5_mutex_destroy(&db_lock); + } + + static void +-kdb_unlock_list() ++kdb_unlock_list(void) + { + k5_mutex_unlock(&db_lock); + } +diff --git a/src/lib/kdb/kdb_cpw.c b/src/lib/kdb/kdb_cpw.c +index 450860f470..c33c7cf8d0 100644 +--- a/src/lib/kdb/kdb_cpw.c ++++ b/src/lib/kdb/kdb_cpw.c +@@ -57,10 +57,7 @@ + enum save { DISCARD_ALL, KEEP_LAST_KVNO, KEEP_ALL }; + + int +-krb5_db_get_key_data_kvno(context, count, data) +- krb5_context context; +- int count; +- krb5_key_data * data; ++krb5_db_get_key_data_kvno(krb5_context context, int count, krb5_key_data *data) + { + int i, kvno; + /* Find last key version number */ +@@ -73,10 +70,7 @@ krb5_db_get_key_data_kvno(context, count, data) + } + + static void +-cleanup_key_data(context, count, data) +- krb5_context context; +- int count; +- krb5_key_data * data; ++cleanup_key_data(krb5_context context, int count, krb5_key_data *data) + { + int i; + +@@ -149,13 +143,9 @@ preserve_old_keys(krb5_context context, krb5_keyblock *mkey, + } + + static krb5_error_code +-add_key_rnd(context, master_key, ks_tuple, ks_tuple_count, db_entry, kvno) +- krb5_context context; +- krb5_keyblock * master_key; +- krb5_key_salt_tuple * ks_tuple; +- int ks_tuple_count; +- krb5_db_entry * db_entry; +- int kvno; ++add_key_rnd(krb5_context context, krb5_keyblock *master_key, ++ krb5_key_salt_tuple *ks_tuple, int ks_tuple_count, ++ krb5_db_entry *db_entry, int kvno) + { + krb5_keyblock key; + int i, j; +@@ -246,15 +236,9 @@ make_random_salt(krb5_context context, krb5_keysalt *salt_out) + * If passwd is NULL the assumes that the caller wants a random password. + */ + static krb5_error_code +-add_key_pwd(context, master_key, ks_tuple, ks_tuple_count, passwd, +- db_entry, kvno) +- krb5_context context; +- krb5_keyblock * master_key; +- krb5_key_salt_tuple * ks_tuple; +- int ks_tuple_count; +- const char * passwd; +- krb5_db_entry * db_entry; +- int kvno; ++add_key_pwd(krb5_context context, krb5_keyblock *master_key, ++ krb5_key_salt_tuple *ks_tuple, int ks_tuple_count, ++ const char *passwd, krb5_db_entry *db_entry, int kvno) + { + krb5_error_code retval; + krb5_keysalt key_salt; +diff --git a/src/lib/kdb/keytab.c b/src/lib/kdb/keytab.c +index a623e001ec..346cf962e8 100644 +--- a/src/lib/kdb/keytab.c ++++ b/src/lib/kdb/keytab.c +@@ -71,10 +71,7 @@ krb5_db_register_keytab(krb5_context context) + } + + krb5_error_code +-krb5_ktkdb_resolve(context, name, id) +- krb5_context context; +- const char * name; +- krb5_keytab * id; ++krb5_ktkdb_resolve(krb5_context context, const char *name, krb5_keytab *id) + { + if ((*id = (krb5_keytab) malloc(sizeof(**id))) == NULL) + return(ENOMEM); +@@ -84,9 +81,7 @@ krb5_ktkdb_resolve(context, name, id) + } + + krb5_error_code +-krb5_ktkdb_close(context, kt) +- krb5_context context; +- krb5_keytab kt; ++krb5_ktkdb_close(krb5_context context, krb5_keytab kt) + { + /* + * This routine is responsible for freeing all memory allocated +@@ -119,13 +114,9 @@ krb5_ktkdb_set_context(krb5_context ctx) + } + + krb5_error_code +-krb5_ktkdb_get_entry(in_context, id, principal, kvno, enctype, entry) +- krb5_context in_context; +- krb5_keytab id; +- krb5_const_principal principal; +- krb5_kvno kvno; +- krb5_enctype enctype; +- krb5_keytab_entry * entry; ++krb5_ktkdb_get_entry(krb5_context in_context, krb5_keytab id, ++ krb5_const_principal principal, krb5_kvno kvno, ++ krb5_enctype enctype, krb5_keytab_entry *entry) + { + krb5_context context; + krb5_error_code kerror = 0; +diff --git a/src/lib/kdb/t_stringattr.c b/src/lib/kdb/t_stringattr.c +index 11740368ea..2c643018b5 100644 +--- a/src/lib/kdb/t_stringattr.c ++++ b/src/lib/kdb/t_stringattr.c +@@ -38,7 +38,7 @@ + */ + + int +-main() ++main(void) + { + krb5_db_entry *ent; + krb5_context context; +diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c +index fc2d248001..c5446b890c 100644 +--- a/src/lib/krad/packet.c ++++ b/src/lib/krad/packet.c +@@ -200,7 +200,7 @@ auth_generate_response(krb5_context ctx, const char *secret, + + /* Create a new packet. */ + static krad_packet * +-packet_new() ++packet_new(void) + { + krad_packet *pkt; + +diff --git a/src/lib/krad/t_attr.c b/src/lib/krad/t_attr.c +index 4d285ad9de..d5dd99a174 100644 +--- a/src/lib/krad/t_attr.c ++++ b/src/lib/krad/t_attr.c +@@ -40,7 +40,7 @@ const static unsigned char auth[] = { + }; + + int +-main() ++main(void) + { + unsigned char outbuf[MAX_ATTRSETSIZE]; + const char *decoded = "accept"; +diff --git a/src/lib/krad/t_attrset.c b/src/lib/krad/t_attrset.c +index 0f95762534..4cdb8b7d8e 100644 +--- a/src/lib/krad/t_attrset.c ++++ b/src/lib/krad/t_attrset.c +@@ -40,7 +40,7 @@ const static unsigned char encpass[] = { + }; + + int +-main() ++main(void) + { + unsigned char buffer[KRAD_PACKET_SIZE_MAX], encoded[MAX_ATTRSETSIZE]; + const char *username = "testUser", *password = "accept"; +diff --git a/src/lib/krad/t_code.c b/src/lib/krad/t_code.c +index b245a7efc0..6cd522af55 100644 +--- a/src/lib/krad/t_code.c ++++ b/src/lib/krad/t_code.c +@@ -30,7 +30,7 @@ + #include "t_test.h" + + int +-main() ++main(void) + { + const char *tmp; + +diff --git a/src/lib/krb5/ccache/cc_keyring.c b/src/lib/krb5/ccache/cc_keyring.c +index 1dadeef64f..ab3cda6fef 100644 +--- a/src/lib/krb5/ccache/cc_keyring.c ++++ b/src/lib/krb5/ccache/cc_keyring.c +@@ -314,7 +314,7 @@ get_persistent_real(uid_t uid) + * for the session anchor. + */ + static key_serial_t +-session_write_anchor() ++session_write_anchor(void) + { + key_serial_t s, u; + +diff --git a/src/lib/krb5/krb/plugin.c b/src/lib/krb5/krb/plugin.c +index 3bb7a38d44..1286e9e383 100644 +--- a/src/lib/krb5/krb/plugin.c ++++ b/src/lib/krb5/krb/plugin.c +@@ -355,7 +355,7 @@ load_if_needed(krb5_context context, struct plugin_mapping *map, + krb5_error_code ret; + char *symname = NULL; + struct plugin_file_handle *handle = NULL; +- void (*initvt_fn)(); ++ void (*initvt_fn)(void); + + if (map->module != NULL || map->dyn_path == NULL) + return; +diff --git a/src/lib/krb5/krb/t_authdata.c b/src/lib/krb5/krb/t_authdata.c +index dd834b9b0c..44f4a1cbd6 100644 +--- a/src/lib/krb5/krb/t_authdata.c ++++ b/src/lib/krb5/krb/t_authdata.c +@@ -74,7 +74,7 @@ static void compare_authdata(const krb5_authdata *adc1, krb5_authdata *adc2) { + } + + int +-main() ++main(void) + { + krb5_context context; + krb5_authdata **results; +diff --git a/src/lib/krb5/krb/t_response_items.c b/src/lib/krb5/krb/t_response_items.c +index 0deb9292a1..a6b02ca055 100644 +--- a/src/lib/krb5/krb/t_response_items.c ++++ b/src/lib/krb5/krb/t_response_items.c +@@ -61,7 +61,7 @@ nstrcmp(const char *a, const char *b) + } + + int +-main() ++main(void) + { + k5_response_items *ri; + +diff --git a/src/lib/krb5/krb/t_ser.c b/src/lib/krb5/krb/t_ser.c +index d6746b74bd..9780c2e564 100644 +--- a/src/lib/krb5/krb/t_ser.c ++++ b/src/lib/krb5/krb/t_ser.c +@@ -195,7 +195,7 @@ ser_checksum(krb5_checksum *cksum) + } + + static void +-ser_context_test() ++ser_context_test(void) + { + krb5_context context; + profile_t sprofile; +@@ -216,7 +216,7 @@ ser_context_test() + } + + static void +-ser_acontext_test() ++ser_acontext_test(void) + { + krb5_auth_context actx; + krb5_address local_address; +@@ -306,7 +306,7 @@ ser_acontext_test() + } + + static void +-ser_princ_test() ++ser_princ_test(void) + { + krb5_principal princ; + char pname[1024]; +@@ -320,7 +320,7 @@ ser_princ_test() + } + + static void +-ser_cksum_test() ++ser_cksum_test(void) + { + krb5_checksum checksum; + krb5_octet ckdata[24]; +diff --git a/src/lib/krb5/krb/t_sname_match.c b/src/lib/krb5/krb/t_sname_match.c +index 021b720d65..ee5623c158 100644 +--- a/src/lib/krb5/krb/t_sname_match.c ++++ b/src/lib/krb5/krb/t_sname_match.c +@@ -80,7 +80,7 @@ struct test { + }; + + int +-main() ++main(void) + { + size_t i; + struct test *t; +diff --git a/src/lib/krb5/krb/t_valid_times.c b/src/lib/krb5/krb/t_valid_times.c +index e4b5f1bce4..1a8036e811 100644 +--- a/src/lib/krb5/krb/t_valid_times.c ++++ b/src/lib/krb5/krb/t_valid_times.c +@@ -36,7 +36,7 @@ + #define BOUNDARY (uint32_t)INT32_MIN + + int +-main() ++main(void) + { + krb5_error_code ret; + krb5_context context; +diff --git a/src/lib/krb5/rcache/t_memrcache.c b/src/lib/krb5/rcache/t_memrcache.c +index 6f212b0ecd..665da75ea5 100644 +--- a/src/lib/krb5/rcache/t_memrcache.c ++++ b/src/lib/krb5/rcache/t_memrcache.c +@@ -33,7 +33,7 @@ + #include "memrcache.c" + + int +-main() ++main(void) + { + krb5_error_code ret; + krb5_context context; +diff --git a/src/lib/rpc/auth_gss.c b/src/lib/rpc/auth_gss.c +index 319bc759b1..f61322d82b 100644 +--- a/src/lib/rpc/auth_gss.c ++++ b/src/lib/rpc/auth_gss.c +@@ -445,9 +445,9 @@ authgss_refresh(AUTH *auth, struct rpc_msg *msg) + memset(&gr, 0, sizeof(gr)); + + call_stat = clnt_call(gd->clnt, NULLPROC, +- xdr_rpc_gss_init_args, ++ (xdrproc_t)xdr_rpc_gss_init_args, + &send_token, +- xdr_rpc_gss_init_res, ++ (xdrproc_t)xdr_rpc_gss_init_res, + (caddr_t)&gr, AUTH_TIMEOUT); + + gss_release_buffer(&min_stat, &send_token); +diff --git a/src/lib/rpc/auth_gssapi.c b/src/lib/rpc/auth_gssapi.c +index 8ab7ab5ba7..b5e03b9641 100644 +--- a/src/lib/rpc/auth_gssapi.c ++++ b/src/lib/rpc/auth_gssapi.c +@@ -283,11 +283,11 @@ next_token: + + PRINTF(("gssapi_create: calling GSSAPI_INIT (%d)\n", init_func)); + +- xdr_free(xdr_authgssapi_init_res, &call_res); ++ xdr_free((xdrproc_t)xdr_authgssapi_init_res, &call_res); + memset(&call_res, 0, sizeof(call_res)); + callstat = clnt_call(clnt, init_func, +- xdr_authgssapi_init_arg, &call_arg, +- xdr_authgssapi_init_res, &call_res, ++ (xdrproc_t)xdr_authgssapi_init_arg, &call_arg, ++ (xdrproc_t)xdr_authgssapi_init_res, &call_res, + timeout); + gss_release_buffer(minor_stat, &call_arg.token); + +@@ -436,7 +436,7 @@ next_token: + /* don't assume the caller will want to change clnt->cl_auth */ + clnt->cl_auth = save_auth; + +- xdr_free(xdr_authgssapi_init_res, &call_res); ++ xdr_free((xdrproc_t)xdr_authgssapi_init_res, &call_res); + return auth; + + /******************************************************************/ +@@ -458,7 +458,7 @@ cleanup: + if (rpc_createerr.cf_stat == 0) + rpc_createerr.cf_stat = RPC_AUTHERROR; + +- xdr_free(xdr_authgssapi_init_res, &call_res); ++ xdr_free((xdrproc_t)xdr_authgssapi_init_res, &call_res); + return auth; + } + +@@ -760,7 +760,7 @@ skip_call: + static bool_t auth_gssapi_wrap( + AUTH *auth, + XDR *out_xdrs, +- bool_t (*xdr_func)(), ++ xdrproc_t xdr_func, + caddr_t xdr_ptr) + { + OM_uint32 gssstat, minor_stat; +@@ -791,7 +791,7 @@ static bool_t auth_gssapi_wrap( + static bool_t auth_gssapi_unwrap( + AUTH *auth, + XDR *in_xdrs, +- bool_t (*xdr_func)(), ++ xdrproc_t xdr_func, + caddr_t xdr_ptr) + { + OM_uint32 gssstat, minor_stat; +diff --git a/src/lib/rpc/auth_gssapi_misc.c b/src/lib/rpc/auth_gssapi_misc.c +index a60eb7f7cb..57fc1fb39f 100644 +--- a/src/lib/rpc/auth_gssapi_misc.c ++++ b/src/lib/rpc/auth_gssapi_misc.c +@@ -199,7 +199,7 @@ bool_t auth_gssapi_wrap_data( + gss_ctx_id_t context, + uint32_t seq_num, + XDR *out_xdrs, +- bool_t (*xdr_func)(), ++ xdrproc_t xdr_func, + caddr_t xdr_ptr) + { + gss_buffer_desc in_buf, out_buf; +@@ -267,7 +267,7 @@ bool_t auth_gssapi_unwrap_data( + gss_ctx_id_t context, + uint32_t seq_num, + XDR *in_xdrs, +- bool_t (*xdr_func)(), ++ xdrproc_t xdr_func, + caddr_t xdr_ptr) + { + gss_buffer_desc in_buf, out_buf; +diff --git a/src/lib/rpc/authunix_prot.c b/src/lib/rpc/authunix_prot.c +index 512d5a51b7..92276c3ad4 100644 +--- a/src/lib/rpc/authunix_prot.c ++++ b/src/lib/rpc/authunix_prot.c +@@ -58,7 +58,8 @@ xdr_authunix_parms(XDR *xdrs, struct authunix_parms *p) + && xdr_int(xdrs, &(p->aup_uid)) + && xdr_int(xdrs, &(p->aup_gid)) + && xdr_array(xdrs, (caddr_t *)&(p->aup_gids), +- &(p->aup_len), NGRPS, sizeof(int), xdr_int) ) { ++ &(p->aup_len), NGRPS, sizeof(int), ++ (xdrproc_t)xdr_int)) { + return (TRUE); + } + return (FALSE); +diff --git a/src/lib/rpc/clnt_perror.c b/src/lib/rpc/clnt_perror.c +index fcc3657464..912b267867 100644 +--- a/src/lib/rpc/clnt_perror.c ++++ b/src/lib/rpc/clnt_perror.c +@@ -76,7 +76,6 @@ char * + clnt_sperror(CLIENT *rpch, char *s) + { + struct rpc_err e; +- void clnt_perrno(); + char *err; + char *bufstart = get_buf(); + char *str = bufstart; +diff --git a/src/lib/rpc/clnt_raw.c b/src/lib/rpc/clnt_raw.c +index dcbb5cf23d..7e62a5c776 100644 +--- a/src/lib/rpc/clnt_raw.c ++++ b/src/lib/rpc/clnt_raw.c +@@ -80,7 +80,7 @@ static struct clnt_ops client_ops = { + clntraw_control + }; + +-void svc_getreq(); ++void svc_getreq(int); + + /* + * Create a client handle for memory based rpc. +diff --git a/src/lib/rpc/dyn.c b/src/lib/rpc/dyn.c +index bce1fd2a7d..a505f34817 100644 +--- a/src/lib/rpc/dyn.c ++++ b/src/lib/rpc/dyn.c +@@ -30,10 +30,8 @@ + /* + * Made obsolete by DynInsert, now just a convenience function. + */ +-int DynAppend(obj, els, num) +- DynObjectP obj; +- DynPtr els; +- int num; ++int ++DynAppend(DynObjectP obj, DynPtr els, int num) + { + return DynInsert(obj, DynSize(obj), els, num); + } +@@ -52,8 +50,8 @@ int DynAppend(obj, els, num) + + static int default_increment = DEFAULT_INC; + +-DynObjectP DynCreate(el_size, inc) +- int el_size, inc; ++DynObjectP ++DynCreate(int el_size, int inc) + { + DynObjectP obj; + +@@ -77,8 +75,8 @@ DynObjectP DynCreate(el_size, inc) + return obj; + } + +-DynObjectP DynCopy(obj) +- DynObjectP obj; ++DynObjectP ++DynCopy(DynObjectP obj) + { + DynObjectP obj1; + +@@ -104,8 +102,8 @@ DynObjectP DynCopy(obj) + return obj1; + } + +-int DynDestroy(obj) +- /*@only@*/DynObjectP obj; ++int ++DynDestroy(/*@only@*/DynObjectP obj) + { + if (obj->paranoid) { + if (obj->debug) +@@ -118,8 +116,8 @@ int DynDestroy(obj) + return DYN_OK; + } + +-int DynRelease(obj) +- DynObjectP obj; ++int ++DynRelease(DynObjectP obj) + { + if (obj->debug) + fprintf(stderr, "dyn: release: freeing object structure.\n"); +@@ -134,9 +132,8 @@ int DynRelease(obj) + * contains the source code for the function DynDebug(). + */ + +-int DynDebug(obj, state) +- DynObjectP obj; +- int state; ++int ++DynDebug(DynObjectP obj, int state) + { + obj->debug = state; + +@@ -155,9 +152,8 @@ int DynDebug(obj, state) + * Checkers! Get away from that "hard disk erase" button! + * (Stupid dog. He almost did it to me again ...) + */ +-int DynDelete(obj, idx) +- DynObjectP obj; +- int idx; ++int ++DynDelete(DynObjectP obj, int idx) + { + if (idx < 0) { + if (obj->debug) +@@ -219,9 +215,8 @@ int DynDelete(obj, idx) + * contains the source code for the function DynInitZero(). + */ + +-int DynInitzero(obj, state) +- DynObjectP obj; +- int state; ++int ++DynInitzero(DynObjectP obj, int state) + { + obj->initzero = state; + +@@ -237,10 +232,8 @@ int DynInitzero(obj, state) + * contains the source code for the function DynInsert(). + */ + +-int DynInsert(obj, idx, els_in, num) +- DynObjectP obj; +- void *els_in; +- int idx, num; ++int ++DynInsert(DynObjectP obj, int idx, void *els_in, int num) + { + DynPtr els = (DynPtr) els_in; + int ret; +@@ -290,9 +283,8 @@ int DynInsert(obj, idx, els_in, num) + * contains the source code for the function DynDebug(). + */ + +-int DynParanoid(obj, state) +- DynObjectP obj; +- int state; ++int ++DynParanoid(DynObjectP obj, int state) + { + obj->paranoid = state; + +@@ -308,8 +300,8 @@ int DynParanoid(obj, state) + * contains the source code for the functions DynGet() and DynAdd(). + */ + +-DynPtr DynArray(obj) +- DynObjectP obj; ++DynPtr ++DynArray(DynObjectP obj) + { + if (obj->debug) + fprintf(stderr, "dyn: array: returning array pointer %p.\n", +@@ -318,9 +310,8 @@ DynPtr DynArray(obj) + return obj->array; + } + +-DynPtr DynGet(obj, num) +- DynObjectP obj; +- int num; ++DynPtr ++DynGet(DynObjectP obj, int num) + { + if (num < 0) { + if (obj->debug) +@@ -342,9 +333,7 @@ DynPtr DynGet(obj, num) + return (DynPtr) obj->array + obj->el_size*num; + } + +-int DynAdd(obj, el) +- DynObjectP obj; +- void *el; ++int DynAdd(DynObjectP obj, void *el) + { + int ret; + +@@ -364,10 +353,8 @@ int DynAdd(obj, el) + * obj->num_el) will not be updated properly and many other functions + * in the library will lose. Have a nice day. + */ +-int DynPut(obj, el_in, idx) +- DynObjectP obj; +- void *el_in; +- int idx; ++int ++DynPut(DynObjectP obj, void *el_in, int idx) + { + DynPtr el = (DynPtr) el_in; + int ret; +@@ -397,9 +384,8 @@ int DynPut(obj, el_in, idx) + /* + * Resize the array so that element req exists. + */ +-int _DynResize(obj, req) +- DynObjectP obj; +- int req; ++int ++_DynResize(DynObjectP obj, int req) + { + int size; + +@@ -430,9 +416,8 @@ int _DynResize(obj, req) + * Ideally, this function should not be called from outside the + * library. However, nothing will break if it is. + */ +-int _DynRealloc(obj, num_incs) +- DynObjectP obj; +- int num_incs; ++int ++_DynRealloc(DynObjectP obj, int num_incs) + { + DynPtr temp; + int new_size_in_bytes; +@@ -475,8 +460,8 @@ int _DynRealloc(obj, num_incs) + * contains the source code for the function DynSize(). + */ + +-int DynSize(obj) +- DynObjectP obj; ++int ++DynSize(DynObjectP obj) + { + if (obj->debug) + fprintf(stderr, "dyn: size: returning size %d.\n", obj->num_el); +@@ -484,8 +469,8 @@ int DynSize(obj) + return obj->num_el; + } + +-int DynCapacity(obj) +- DynObjectP obj; ++int ++DynCapacity(DynObjectP obj) + { + if (obj->debug) + fprintf(stderr, "dyn: capacity: returning cap of %d.\n", obj->size); +diff --git a/src/lib/rpc/pmap_clnt.c b/src/lib/rpc/pmap_clnt.c +index 952a251453..5c3bba3528 100644 +--- a/src/lib/rpc/pmap_clnt.c ++++ b/src/lib/rpc/pmap_clnt.c +@@ -54,8 +54,6 @@ static char sccsid[] = "@(#)pmap_clnt.c 1.37 87/08/11 Copyr 1984 Sun Micro"; + static struct timeval timeout = { 5, 0 }; + static struct timeval tottimeout = { 60, 0 }; + +-void clnt_perror(); +- + /* + * Set a mapping between program,version and port. + * Calls the pmap service remotely to do the mapping. +@@ -128,7 +126,8 @@ pmap_set( + } + } + #endif +- if (CLNT_CALL(client, PMAPPROC_SET, xdr_pmap, &parms, xdr_bool, &rslt, ++ if (CLNT_CALL(client, PMAPPROC_SET, (xdrproc_t)xdr_pmap, &parms, ++ (xdrproc_t)xdr_bool, &rslt, + tottimeout) != RPC_SUCCESS) { + clnt_perror(client, "Cannot register service"); + return (FALSE); +@@ -161,8 +160,8 @@ pmap_unset( + parms.pm_prog = program; + parms.pm_vers = version; + parms.pm_port = parms.pm_prot = 0; +- CLNT_CALL(client, PMAPPROC_UNSET, xdr_pmap, &parms, xdr_bool, &rslt, +- tottimeout); ++ CLNT_CALL(client, PMAPPROC_UNSET, (xdrproc_t)xdr_pmap, &parms, ++ (xdrproc_t)xdr_bool, &rslt, tottimeout); + CLNT_DESTROY(client); + (void)close(sock); + return (rslt); +diff --git a/src/lib/rpc/pmap_getmaps.c b/src/lib/rpc/pmap_getmaps.c +index b8a9cecf7e..a9c4c52906 100644 +--- a/src/lib/rpc/pmap_getmaps.c ++++ b/src/lib/rpc/pmap_getmaps.c +@@ -77,8 +77,9 @@ pmap_getmaps(struct sockaddr_in *address) + client = clnttcp_create(address, PMAPPROG, + PMAPVERS, &sock, 50, 500); + if (client != (CLIENT *)NULL) { +- if (CLNT_CALL(client, PMAPPROC_DUMP, xdr_void, NULL, xdr_pmaplist, +- &head, minutetimeout) != RPC_SUCCESS) { ++ if (CLNT_CALL(client, PMAPPROC_DUMP, xdr_void, NULL, ++ (xdrproc_t)xdr_pmaplist, &head, ++ minutetimeout) != RPC_SUCCESS) { + clnt_perror(client, "pmap_getmaps rpc problem"); + } + CLNT_DESTROY(client); +diff --git a/src/lib/rpc/pmap_getport.c b/src/lib/rpc/pmap_getport.c +index 66635a1034..2d0792b698 100644 +--- a/src/lib/rpc/pmap_getport.c ++++ b/src/lib/rpc/pmap_getport.c +@@ -79,8 +79,10 @@ pmap_getport( + parms.pm_vers = version; + parms.pm_prot = protocol; + parms.pm_port = 0; /* not needed or used */ +- if (CLNT_CALL(client, PMAPPROC_GETPORT, xdr_pmap, &parms, +- xdr_u_short, &port, tottimeout) != RPC_SUCCESS){ ++ if (CLNT_CALL(client, PMAPPROC_GETPORT, ++ (xdrproc_t)xdr_pmap, &parms, ++ (xdrproc_t)xdr_u_short, &port, ++ tottimeout) != RPC_SUCCESS){ + rpc_createerr.cf_stat = RPC_PMAPFAILURE; + clnt_geterr(client, &rpc_createerr.cf_error); + } else if (port == 0) { +diff --git a/src/lib/rpc/pmap_prot2.c b/src/lib/rpc/pmap_prot2.c +index aeccac6637..3c0c612bec 100644 +--- a/src/lib/rpc/pmap_prot2.c ++++ b/src/lib/rpc/pmap_prot2.c +@@ -109,7 +109,8 @@ xdr_pmaplist(XDR *xdrs, struct pmaplist **rp) + if (freeing) + next = &((*rp)->pml_next); + if (! xdr_reference(xdrs, (caddr_t *)rp, +- (u_int)sizeof(struct pmaplist), xdr_pmap)) ++ (u_int)sizeof(struct pmaplist), ++ (xdrproc_t)xdr_pmap)) + return (FALSE); + rp = (freeing) ? next : &((*rp)->pml_next); + } +diff --git a/src/lib/rpc/pmap_rmt.c b/src/lib/rpc/pmap_rmt.c +index 8c7e30c21a..434e4eea65 100644 +--- a/src/lib/rpc/pmap_rmt.c ++++ b/src/lib/rpc/pmap_rmt.c +@@ -105,8 +105,9 @@ pmap_rmtcall( + r.port_ptr = port_ptr; + r.results_ptr = resp; + r.xdr_results = xdrres; +- stat = CLNT_CALL(client, PMAPPROC_CALLIT, xdr_rmtcall_args, &a, +- xdr_rmtcallres, &r, tout); ++ stat = CLNT_CALL(client, PMAPPROC_CALLIT, ++ (xdrproc_t)xdr_rmtcall_args, &a, ++ (xdrproc_t)xdr_rmtcallres, &r, tout); + CLNT_DESTROY(client); + } else { + stat = RPC_FAILED; +@@ -161,7 +162,8 @@ xdr_rmtcallres( + + port_ptr = (caddr_t)(void *)crp->port_ptr; + if (xdr_reference(xdrs, &port_ptr, sizeof (uint32_t), +- xdr_u_int32) && xdr_u_int32(xdrs, &crp->resultslen)) { ++ (xdrproc_t)xdr_u_int32) && ++ xdr_u_int32(xdrs, &crp->resultslen)) { + crp->port_ptr = (uint32_t *)(void *)port_ptr; + return ((*(crp->xdr_results))(xdrs, crp->results_ptr)); + } +@@ -343,7 +345,7 @@ clnt_broadcast( + recv_again: + msg.acpted_rply.ar_verf = gssrpc__null_auth; + msg.acpted_rply.ar_results.where = (caddr_t)&r; +- msg.acpted_rply.ar_results.proc = xdr_rmtcallres; ++ msg.acpted_rply.ar_results.proc = (xdrproc_t)xdr_rmtcallres; + readfds = mask; + t2 = t; + switch (select(gssrpc__rpc_dtablesize(), &readfds, (fd_set *)NULL, +diff --git a/src/lib/rpc/rpc_prot.c b/src/lib/rpc/rpc_prot.c +index 9b82e12c34..296968b946 100644 +--- a/src/lib/rpc/rpc_prot.c ++++ b/src/lib/rpc/rpc_prot.c +@@ -132,8 +132,8 @@ xdr_rejected_reply(XDR *xdrs, struct rejected_reply *rr) + } + + static struct xdr_discrim reply_dscrm[3] = { +- { (int)MSG_ACCEPTED, xdr_accepted_reply }, +- { (int)MSG_DENIED, xdr_rejected_reply }, ++ { (int)MSG_ACCEPTED, (xdrproc_t)xdr_accepted_reply }, ++ { (int)MSG_DENIED, (xdrproc_t)xdr_rejected_reply }, + { __dontcare__, NULL_xdrproc_t } }; + + /* +diff --git a/src/lib/rpc/svc.c b/src/lib/rpc/svc.c +index cfbc7aad4d..0bcf04e8d4 100644 +--- a/src/lib/rpc/svc.c ++++ b/src/lib/rpc/svc.c +@@ -80,7 +80,7 @@ static struct svc_callout { + struct svc_callout *sc_next; + rpcprog_t sc_prog; + rpcprog_t sc_vers; +- void (*sc_dispatch)(); ++ void (*sc_dispatch)(struct svc_req *, SVCXPRT *); + } *svc_head; + + static struct svc_callout *svc_find(rpcprog_t, rpcvers_t, +@@ -162,7 +162,7 @@ svc_register( + SVCXPRT *xprt, + rpcprog_t prog, + rpcvers_t vers, +- void (*dispatch)(), ++ void (*dispatch)(struct svc_req *, SVCXPRT *), + int protocol) + { + struct svc_callout *prev; +diff --git a/src/lib/rpc/svc_auth_gss.c b/src/lib/rpc/svc_auth_gss.c +index aba7694807..98d601c8ab 100644 +--- a/src/lib/rpc/svc_auth_gss.c ++++ b/src/lib/rpc/svc_auth_gss.c +@@ -193,7 +193,7 @@ svcauth_gss_accept_sec_context(struct svc_req *rqst, + /* Deserialize arguments. */ + memset(&recv_tok, 0, sizeof(recv_tok)); + +- if (!svc_getargs(rqst->rq_xprt, xdr_rpc_gss_init_args, ++ if (!svc_getargs(rqst->rq_xprt, (xdrproc_t)xdr_rpc_gss_init_args, + (caddr_t)&recv_tok)) + return (FALSE); + +@@ -209,7 +209,8 @@ svcauth_gss_accept_sec_context(struct svc_req *rqst, + NULL, + NULL); + +- svc_freeargs(rqst->rq_xprt, xdr_rpc_gss_init_args, (caddr_t)&recv_tok); ++ svc_freeargs(rqst->rq_xprt, (xdrproc_t)xdr_rpc_gss_init_args, ++ (caddr_t)&recv_tok); + + log_status("accept_sec_context", gr->gr_major, gr->gr_minor); + if (gr->gr_major != GSS_S_COMPLETE && +@@ -495,7 +496,8 @@ gssrpc__svcauth_gss(struct svc_req *rqst, struct rpc_msg *msg, + } + *no_dispatch = TRUE; + +- call_stat = svc_sendreply(rqst->rq_xprt, xdr_rpc_gss_init_res, ++ call_stat = svc_sendreply(rqst->rq_xprt, ++ (xdrproc_t)xdr_rpc_gss_init_res, + (caddr_t)&gr); + + gss_release_buffer(&min_stat, &gr.gr_token); +@@ -544,7 +546,7 @@ gssrpc__svcauth_gss(struct svc_req *rqst, struct rpc_msg *msg, + } + retstat = AUTH_OK; + freegc: +- xdr_free(xdr_rpc_gss_cred, gc); ++ xdr_free((xdrproc_t)xdr_rpc_gss_cred, gc); + log_debug("returning %d from svcauth_gss()", retstat); + return (retstat); + } +diff --git a/src/lib/rpc/svc_auth_gssapi.c b/src/lib/rpc/svc_auth_gssapi.c +index b7ffee4515..267c1545bd 100644 +--- a/src/lib/rpc/svc_auth_gssapi.c ++++ b/src/lib/rpc/svc_auth_gssapi.c +@@ -201,7 +201,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + if (! xdr_authgssapi_creds(&xdrs, &creds)) { + PRINTF(("svcauth_gssapi: failed decoding creds\n")); + LOG_MISCERR("protocol error in client credentials"); +- xdr_free(xdr_authgssapi_creds, &creds); ++ xdr_free((xdrproc_t)xdr_authgssapi_creds, &creds); + XDR_DESTROY(&xdrs); + ret = AUTH_BADCRED; + goto error; +@@ -223,7 +223,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + if (creds.auth_msg && rqst->rq_proc == AUTH_GSSAPI_EXIT) { + PRINTF(("svcauth_gssapi: GSSAPI_EXIT, cleaning up\n")); + svc_sendreply(rqst->rq_xprt, xdr_void, NULL); +- xdr_free(xdr_authgssapi_creds, &creds); ++ xdr_free((xdrproc_t)xdr_authgssapi_creds, &creds); + cleanup(); + exit(0); + } +@@ -306,7 +306,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + + /* call is for us, deserialize arguments */ + memset(&call_arg, 0, sizeof(call_arg)); +- if (! svc_getargs(rqst->rq_xprt, xdr_authgssapi_init_arg, ++ if (! svc_getargs(rqst->rq_xprt, (xdrproc_t)xdr_authgssapi_init_arg, + &call_arg)) { + PRINTF(("svcauth_gssapi: cannot decode args\n")); + LOG_MISCERR("protocol error in procedure arguments"); +@@ -446,7 +446,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + minor_stat = call_res.gss_minor; + + /* done with call args */ +- xdr_free(xdr_authgssapi_init_arg, &call_arg); ++ xdr_free((xdrproc_t)xdr_authgssapi_init_arg, &call_arg); + + PRINTF(("svcauth_gssapi: accept_sec_context returned %#x %#x\n", + call_res.gss_major, call_res.gss_minor)); +@@ -459,7 +459,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + badauth(call_res.gss_major, call_res.gss_minor, rqst->rq_xprt); + + gss_release_buffer(&minor_stat, &output_token); +- svc_sendreply(rqst->rq_xprt, xdr_authgssapi_init_res, ++ svc_sendreply(rqst->rq_xprt, (xdrproc_t)xdr_authgssapi_init_res, + (caddr_t) &call_res); + *no_dispatch = TRUE; + ret = AUTH_OK; +@@ -492,7 +492,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + } + + PRINTF(("svcauth_gssapi: sending reply\n")); +- svc_sendreply(rqst->rq_xprt, xdr_authgssapi_init_res, ++ svc_sendreply(rqst->rq_xprt, (xdrproc_t)xdr_authgssapi_init_res, + (caddr_t) &call_res); + *no_dispatch = TRUE; + +@@ -583,11 +583,13 @@ enum auth_stat gssrpc__svcauth_gssapi( + case AUTH_GSSAPI_MSG: + PRINTF(("svcauth_gssapi: GSSAPI_MSG, getting args\n")); + memset(&call_arg, 0, sizeof(call_arg)); +- if (! svc_getargs(rqst->rq_xprt, xdr_authgssapi_init_arg, ++ if (! svc_getargs(rqst->rq_xprt, ++ (xdrproc_t)xdr_authgssapi_init_arg, + &call_arg)) { + PRINTF(("svcauth_gssapi: cannot decode args\n")); + LOG_MISCERR("protocol error in call arguments"); +- xdr_free(xdr_authgssapi_init_arg, &call_arg); ++ xdr_free((xdrproc_t)xdr_authgssapi_init_arg, ++ &call_arg); + ret = AUTH_BADCRED; + goto error; + } +@@ -598,7 +600,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + &call_arg.token); + + /* done with call args */ +- xdr_free(xdr_authgssapi_init_arg, &call_arg); ++ xdr_free((xdrproc_t)xdr_authgssapi_init_arg, &call_arg); + + if (gssstat != GSS_S_COMPLETE) { + AUTH_GSSAPI_DISPLAY_STATUS(("processing token", +@@ -641,7 +643,7 @@ enum auth_stat gssrpc__svcauth_gssapi( + if (creds.client_handle.length != 0) { + PRINTF(("svcauth_gssapi: freeing client_handle len %d\n", + (int) creds.client_handle.length)); +- xdr_free(xdr_authgssapi_creds, &creds); ++ xdr_free((xdrproc_t)xdr_authgssapi_creds, &creds); + } + + PRINTF(("\n")); +@@ -651,7 +653,7 @@ error: + if (creds.client_handle.length != 0) { + PRINTF(("svcauth_gssapi: freeing client_handle len %d\n", + (int) creds.client_handle.length)); +- xdr_free(xdr_authgssapi_creds, &creds); ++ xdr_free((xdrproc_t)xdr_authgssapi_creds, &creds); + } + + PRINTF(("\n")); +@@ -1079,7 +1081,7 @@ void svcauth_gssapi_set_log_miscerr_func( + static bool_t svc_auth_gssapi_wrap( + SVCAUTH *auth, + XDR *out_xdrs, +- bool_t (*xdr_func)(), ++ xdrproc_t xdr_func, + caddr_t xdr_ptr) + { + OM_uint32 gssstat, minor_stat; +@@ -1102,7 +1104,7 @@ static bool_t svc_auth_gssapi_wrap( + static bool_t svc_auth_gssapi_unwrap( + SVCAUTH *auth, + XDR *in_xdrs, +- bool_t (*xdr_func)(), ++ xdrproc_t xdr_func, + caddr_t xdr_ptr) + { + svc_auth_gssapi_data *client_data = SVCAUTH_PRIVATE(auth); +diff --git a/src/lib/rpc/svc_simple.c b/src/lib/rpc/svc_simple.c +index 315275f5fd..aa6c0a63d0 100644 +--- a/src/lib/rpc/svc_simple.c ++++ b/src/lib/rpc/svc_simple.c +@@ -48,7 +48,7 @@ static char sccsid[] = "@(#)svc_simple.c 1.18 87/08/11 Copyr 1984 Sun Micro"; + #include + + static struct proglst { +- char *(*p_progname)(); ++ char *(*p_progname)(void *); + int p_prognum; + int p_procnum; + xdrproc_t p_inproc, p_outproc; +@@ -62,7 +62,7 @@ registerrpc( + rpcprog_t prognum, + rpcvers_t versnum, + rpcproc_t procnum, +- char *(*progname)(), ++ char *(*progname)(void *), + xdrproc_t inproc, + xdrproc_t outproc) + { +diff --git a/src/lib/rpc/unit-test/client.c b/src/lib/rpc/unit-test/client.c +index c9a812bc5a..9b907bcdc6 100644 +--- a/src/lib/rpc/unit-test/client.c ++++ b/src/lib/rpc/unit-test/client.c +@@ -42,7 +42,7 @@ char *whoami; + #ifdef __GNUC__ + __attribute__((noreturn)) + #endif +-static void usage() ++static void usage(void) + { + fprintf(stderr, "usage: %s {-t|-u} [-a] [-s num] [-m num] host service [count]\n", + whoami); +@@ -50,9 +50,7 @@ static void usage() + } + + int +-main(argc, argv) +- int argc; +- char **argv; ++main(int argc, char **argv) + { + char *host, *port, *target, *echo_arg, **echo_resp, buf[BIG_BUF]; + CLIENT *clnt; +@@ -172,7 +170,7 @@ main(argc, argv) + strcmp(echo_arg, (*echo_resp) + 6) != 0) + fprintf(stderr, "RPC_TEST_ECHO call %d response wrong: " + "arg = %s, resp = %s\n", i, echo_arg, *echo_resp); +- gssrpc_xdr_free(xdr_wrapstring, echo_resp); ++ gssrpc_xdr_free((xdrproc_t)xdr_wrapstring, echo_resp); + } + + /* +@@ -194,7 +192,7 @@ main(argc, argv) + clnt_perror(clnt, whoami); + } else { + fprintf(stderr, "bad seq didn't cause failure\n"); +- gssrpc_xdr_free(xdr_wrapstring, echo_resp); ++ gssrpc_xdr_free((xdrproc_t)xdr_wrapstring, echo_resp); + } + + AUTH_PRIVATE(clnt->cl_auth)->seq_num -= 3; +@@ -207,7 +205,7 @@ main(argc, argv) + if (echo_resp == NULL) + clnt_perror(clnt, "Sequence number improperly reset"); + else +- gssrpc_xdr_free(xdr_wrapstring, echo_resp); ++ gssrpc_xdr_free((xdrproc_t)xdr_wrapstring, echo_resp); + + /* + * Now simulate a lost server response, and see if +@@ -219,7 +217,7 @@ main(argc, argv) + if (echo_resp == NULL) + clnt_perror(clnt, "Auto-resynchronization failed"); + else +- gssrpc_xdr_free(xdr_wrapstring, echo_resp); ++ gssrpc_xdr_free((xdrproc_t)xdr_wrapstring, echo_resp); + + /* + * Now make sure auto-resyncrhonization actually worked +@@ -229,7 +227,7 @@ main(argc, argv) + if (echo_resp == NULL) + clnt_perror(clnt, "Auto-resynchronization did not work"); + else +- gssrpc_xdr_free(xdr_wrapstring, echo_resp); ++ gssrpc_xdr_free((xdrproc_t)xdr_wrapstring, echo_resp); + + if (! auth_once) { + tmp_auth = clnt->cl_auth; +@@ -259,7 +257,7 @@ main(argc, argv) + strcmp(echo_arg, (*echo_resp) + 6) != 0) + fprintf(stderr, + "RPC_TEST_LENGTHS call %d response wrong\n", i); +- gssrpc_xdr_free(xdr_wrapstring, echo_resp); ++ gssrpc_xdr_free((xdrproc_t)xdr_wrapstring, echo_resp); + } + + /* cycle from 1 to 255 */ +diff --git a/src/lib/rpc/unit-test/rpc_test_clnt.c b/src/lib/rpc/unit-test/rpc_test_clnt.c +index 4e4a18a720..b9141672b1 100644 +--- a/src/lib/rpc/unit-test/rpc_test_clnt.c ++++ b/src/lib/rpc/unit-test/rpc_test_clnt.c +@@ -5,9 +5,7 @@ + static struct timeval TIMEOUT = { 25, 0 }; + + char ** +-rpc_test_echo_1(argp, clnt) +- char **argp; +- CLIENT *clnt; ++rpc_test_echo_1(char **argp, CLIENT *clnt) + { + static char *clnt_res; + +diff --git a/src/lib/rpc/unit-test/rpc_test_svc.c b/src/lib/rpc/unit-test/rpc_test_svc.c +index c54c0813db..3aa7674c51 100644 +--- a/src/lib/rpc/unit-test/rpc_test_svc.c ++++ b/src/lib/rpc/unit-test/rpc_test_svc.c +@@ -14,16 +14,14 @@ static int _rpcsvcstate = _IDLE; /* Set when a request is serviced */ + static int _rpcsvccount = 0; /* Number of requests being serviced */ + + void +-rpc_test_prog_1_svc(rqstp, transp) +- struct svc_req *rqstp; +- SVCXPRT *transp; ++rpc_test_prog_1_svc(struct svc_req *rqstp, SVCXPRT *transp) + { + union { + char *rpc_test_echo_1_arg; + } argument; + char *result; +- bool_t (*xdr_argument)(), (*xdr_result)(); +- char *(*local)(); ++ xdrproc_t xdr_argument, xdr_result; ++ char *(*local)(char *, struct svc_req *); + + _rpcsvccount++; + switch (rqstp->rq_proc) { +@@ -35,9 +33,9 @@ rpc_test_prog_1_svc(rqstp, transp) + return; + + case RPC_TEST_ECHO: +- xdr_argument = xdr_wrapstring; +- xdr_result = xdr_wrapstring; +- local = (char *(*)()) rpc_test_echo_1_svc; ++ xdr_argument = (xdrproc_t)xdr_wrapstring; ++ xdr_result = (xdrproc_t)xdr_wrapstring; ++ local = (char *(*)(char *, struct svc_req *)) rpc_test_echo_1_svc; + break; + + default: +@@ -53,7 +51,7 @@ rpc_test_prog_1_svc(rqstp, transp) + _rpcsvcstate = _SERVED; + return; + } +- result = (*local)(&argument, rqstp); ++ result = (*local)((char *)&argument, rqstp); + if (result != NULL && !svc_sendreply(transp, xdr_result, result)) { + svcerr_systemerr(transp); + } +diff --git a/src/lib/rpc/unit-test/server.c b/src/lib/rpc/unit-test/server.c +index c3bbcbf8cf..4400b969f6 100644 +--- a/src/lib/rpc/unit-test/server.c ++++ b/src/lib/rpc/unit-test/server.c +@@ -40,7 +40,7 @@ static void rpc_test_badverf(gss_name_t client, gss_name_t server, + #define SERVICE_NAME "host" + #endif + +-static void usage() ++static void usage(void) + { + fprintf(stderr, "Usage: server {-t|-u} [svc-debug] [misc-debug]\n"); + exit(1); +diff --git a/src/lib/rpc/xdr.c b/src/lib/rpc/xdr.c +index 24c3de4bd9..49c31b3d1b 100644 +--- a/src/lib/rpc/xdr.c ++++ b/src/lib/rpc/xdr.c +@@ -579,14 +579,14 @@ xdr_union( + */ + for (; choices->proc != NULL_xdrproc_t; choices++) { + if (choices->value == dscm) +- return ((*(choices->proc))(xdrs, unp, LASTUNSIGNED)); ++ return choices->proc(xdrs, unp); + } + + /* + * no match - execute the default xdr routine if there is one + */ + return ((dfault == NULL_xdrproc_t) ? FALSE : +- (*dfault)(xdrs, unp, LASTUNSIGNED)); ++ (*dfault)(xdrs, unp)); + } + + +diff --git a/src/lib/rpc/xdr_array.c b/src/lib/rpc/xdr_array.c +index aeaa7f2bb0..3507d53aef 100644 +--- a/src/lib/rpc/xdr_array.c ++++ b/src/lib/rpc/xdr_array.c +@@ -113,7 +113,7 @@ xdr_array( + * now we xdr each element of array + */ + for (i = 0; (i < c) && stat; i++) { +- stat = (*elproc)(xdrs, target, LASTUNSIGNED); ++ stat = (*elproc)(xdrs, target); + target += elsize; + } + +@@ -150,7 +150,7 @@ xdr_vector( + + elptr = basep; + for (i = 0; i < nelem; i++) { +- if (! (*xdr_elem)(xdrs, elptr, LASTUNSIGNED)) { ++ if (! (*xdr_elem)(xdrs, elptr)) { + return(FALSE); + } + elptr += elemsize; +diff --git a/src/lib/rpc/xdr_rec.c b/src/lib/rpc/xdr_rec.c +index 1f6a7762fd..185254018a 100644 +--- a/src/lib/rpc/xdr_rec.c ++++ b/src/lib/rpc/xdr_rec.c +@@ -99,7 +99,7 @@ typedef struct rec_strm { + /* + * out-goung bits + */ +- int (*writeit)(); ++ int (*writeit)(caddr_t, caddr_t, int); + caddr_t out_base; /* output buffer (points to frag header) */ + caddr_t out_finger; /* next output position */ + caddr_t out_boundry; /* data cannot up to this address */ +@@ -108,7 +108,7 @@ typedef struct rec_strm { + /* + * in-coming bits + */ +- int (*readit)(); ++ int (*readit)(caddr_t, caddr_t, int); + uint32_t in_size; /* fixed size of the input buffer */ + caddr_t in_base; + caddr_t in_finger; /* location of next byte to be had */ +@@ -140,8 +140,10 @@ xdrrec_create( + u_int sendsize, + u_int recvsize, + caddr_t tcp_handle, +- int (*readit)(), /* like read, but pass it a tcp_handle, not sock */ +- int (*writeit)() /* like write, but pass it a tcp_handle, not sock */ ++ /* like read, but pass it a tcp_handle, not sock */ ++ int (*readit)(caddr_t, caddr_t, int), ++ /* like write, but pass it a tcp_handle, not sock */ ++ int (*writeit)(caddr_t, caddr_t, int) + ) + { + RECSTREAM *rstrm = mem_alloc(sizeof(RECSTREAM)); +@@ -528,8 +530,7 @@ get_input_bytes(RECSTREAM *rstrm, caddr_t addr, int len) + } + + static bool_t /* next four bytes of input stream are treated as a header */ +-set_input_fragment(rstrm) +- RECSTREAM *rstrm; ++set_input_fragment(RECSTREAM *rstrm) + { + uint32_t header; + +diff --git a/src/lib/rpc/xdr_reference.c b/src/lib/rpc/xdr_reference.c +index eff279dadf..f3d4b7dfb8 100644 +--- a/src/lib/rpc/xdr_reference.c ++++ b/src/lib/rpc/xdr_reference.c +@@ -47,8 +47,6 @@ static char sccsid[] = "@(#)xdr_reference.c 1.11 87/08/11 SMI"; + #include + #include + +-#define LASTUNSIGNED ((u_int)0-1) +- + /* + * XDR an indirect pointer + * xdr_reference is for recursively translating a structure that is +@@ -88,7 +86,7 @@ xdr_reference( + break; + } + +- stat = (*proc)(xdrs, loc, LASTUNSIGNED); ++ stat = (*proc)(xdrs, loc); + + if (xdrs->x_op == XDR_FREE) { + mem_free(loc, size); +diff --git a/src/lib/rpc/xdr_sizeof.c b/src/lib/rpc/xdr_sizeof.c +index 5b77fa6ac0..0c460e7cdb 100644 +--- a/src/lib/rpc/xdr_sizeof.c ++++ b/src/lib/rpc/xdr_sizeof.c +@@ -43,9 +43,7 @@ + + /* ARGSUSED */ + static bool_t +-x_putlong(xdrs, longp) +- XDR *xdrs; +- long *longp; ++x_putlong(XDR *xdrs, long *longp) + { + xdrs->x_handy += BYTES_PER_XDR_UNIT; + return (TRUE); +@@ -53,10 +51,7 @@ x_putlong(xdrs, longp) + + /* ARGSUSED */ + static bool_t +-x_putbytes(xdrs, bp, len) +- XDR *xdrs; +- char *bp; +- int len; ++x_putbytes(XDR *xdrs, char *bp, u_int len) + { + xdrs->x_handy += len; + +@@ -64,26 +59,21 @@ x_putbytes(xdrs, bp, len) + } + + static u_int +-x_getpostn(xdrs) +- XDR *xdrs; ++x_getpostn(XDR *xdrs) + { + return (xdrs->x_handy); + } + + /* ARGSUSED */ + static bool_t +-x_setpostn(xdrs, pos) +- XDR *xdrs; +- u_int pos; ++x_setpostn(XDR *xdrs, u_int pos) + { + /* This is not allowed */ + return (FALSE); + } + + static rpc_inline_t * +-x_inline(xdrs, len) +- XDR *xdrs; +- int len; ++x_inline(XDR *xdrs, int len) + { + if (len == 0) { + return (NULL); +@@ -110,15 +100,14 @@ x_inline(xdrs, len) + } + + static int +-harmless() ++harmless(void) + { + /* Always return FALSE/NULL, as the case may be */ + return (0); + } + + static void +-x_destroy(xdrs) +- XDR *xdrs; ++x_destroy(XDR *xdrs) + { + xdrs->x_handy = 0; + xdrs->x_private = NULL; +@@ -130,9 +119,7 @@ x_destroy(xdrs) + } + + unsigned long +-xdr_sizeof(func, data) +- xdrproc_t func; +- void *data; ++xdr_sizeof(xdrproc_t func, void *data) + { + XDR x; + struct xdr_ops ops; +diff --git a/src/plugins/kdb/db2/db2_exp.c b/src/plugins/kdb/db2/db2_exp.c +index 7cf8aa4d99..9b75f34a11 100644 +--- a/src/plugins/kdb/db2/db2_exp.c ++++ b/src/plugins/kdb/db2/db2_exp.c +@@ -68,7 +68,7 @@ k5_mutex_t *krb5_db2_mutex; + return result; \ + } \ + /* hack: decl to allow a following ";" */ \ +- static TYPE wrap_##NAME () ++ static TYPE wrap_##NAME ARGLIST + + /* Two special cases: void (can't assign result), and krb5_error_code + (return error from locking code). */ +@@ -81,7 +81,7 @@ k5_mutex_t *krb5_db2_mutex; + k5_mutex_unlock (krb5_db2_mutex); \ + } \ + /* hack: decl to allow a following ";" */ \ +- static void wrap_##NAME () ++ static void wrap_##NAME ARGLIST + + #define WRAP_K(NAME,ARGLIST,ARGNAMES) \ + WRAP(NAME,krb5_error_code,ARGLIST,ARGNAMES) +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_close.c b/src/plugins/kdb/db2/libdb2/btree/bt_close.c +index 11be134113..f12d74ba32 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_close.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_close.c +@@ -61,8 +61,7 @@ static int bt_meta __P((BTREE *)); + * RET_ERROR, RET_SUCCESS + */ + int +-__bt_close(dbp) +- DB *dbp; ++__bt_close(DB *dbp) + { + BTREE *t; + int fd; +@@ -116,9 +115,7 @@ __bt_close(dbp) + * RET_SUCCESS, RET_ERROR. + */ + int +-__bt_sync(dbp, flags) +- const DB *dbp; +- u_int flags; ++__bt_sync(const DB *dbp, u_int flags) + { + BTREE *t; + int status; +@@ -160,8 +157,7 @@ __bt_sync(dbp, flags) + * RET_ERROR, RET_SUCCESS + */ + static int +-bt_meta(t) +- BTREE *t; ++bt_meta(BTREE *t) + { + BTMETA m; + void *p; +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_conv.c b/src/plugins/kdb/db2/libdb2/btree/bt_conv.c +index c0644ed713..99c4af56c0 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_conv.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_conv.c +@@ -59,10 +59,7 @@ static void mswap __P((PAGE *)); + * h: page to convert + */ + void +-__bt_pgin(t, pg, pp) +- void *t; +- db_pgno_t pg; +- void *pp; ++__bt_pgin(void *t, db_pgno_t pg, void *pp) + { + PAGE *h; + indx_t i, top; +@@ -128,10 +125,7 @@ __bt_pgin(t, pg, pp) + } + + void +-__bt_pgout(t, pg, pp) +- void *t; +- db_pgno_t pg; +- void *pp; ++__bt_pgout(void *t, db_pgno_t pg, void *pp) + { + PAGE *h; + indx_t i, top; +@@ -203,8 +197,7 @@ __bt_pgout(t, pg, pp) + * p: page to convert + */ + static void +-mswap(pg) +- PAGE *pg; ++mswap(PAGE *pg) + { + char *p; + +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_delete.c b/src/plugins/kdb/db2/libdb2/btree/bt_delete.c +index 28cc24d15a..f8dd59e85a 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_delete.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_delete.c +@@ -59,10 +59,7 @@ static int __bt_stkacq __P((BTREE *, PAGE **, CURSOR *)); + * Return RET_SPECIAL if the key is not found. + */ + int +-__bt_delete(dbp, key, flags) +- const DB *dbp; +- const DBT *key; +- u_int flags; ++__bt_delete(const DB *dbp, const DBT *key, u_int flags) + { + BTREE *t; + CURSOR *c; +@@ -140,10 +137,7 @@ __bt_delete(dbp, key, flags) + * 0 on success, 1 on failure + */ + static int +-__bt_stkacq(t, hp, c) +- BTREE *t; +- PAGE **hp; +- CURSOR *c; ++__bt_stkacq(BTREE *t, PAGE **hp, CURSOR *c) + { + BINTERNAL *bi; + EPG *e; +@@ -288,9 +282,7 @@ ret: mpool_put(t->bt_mp, h, 0); + * RET_ERROR, RET_SUCCESS and RET_SPECIAL if the key not found. + */ + static int +-__bt_bdelete(t, key) +- BTREE *t; +- const DBT *key; ++__bt_bdelete(BTREE *t, const DBT *key) + { + EPG *e; + PAGE *h; +@@ -375,9 +367,7 @@ loop: if ((e = __bt_search(t, key, &exact)) == NULL) + * mpool_put's the page + */ + static int +-__bt_pdelete(t, h) +- BTREE *t; +- PAGE *h; ++__bt_pdelete(BTREE *t, PAGE *h) + { + BINTERNAL *bi; + PAGE *pg; +@@ -471,11 +461,7 @@ __bt_pdelete(t, h) + * RET_SUCCESS, RET_ERROR. + */ + int +-__bt_dleaf(t, key, h, idx) +- BTREE *t; +- const DBT *key; +- PAGE *h; +- u_int idx; ++__bt_dleaf(BTREE *t, const DBT *key, PAGE *h, u_int idx) + { + BLEAF *bl; + indx_t cnt, *ip, offset; +@@ -536,11 +522,7 @@ __bt_dleaf(t, key, h, idx) + * RET_SUCCESS, RET_ERROR. + */ + static int +-__bt_curdel(t, key, h, idx) +- BTREE *t; +- const DBT *key; +- PAGE *h; +- u_int idx; ++__bt_curdel(BTREE *t, const DBT *key, PAGE *h, u_int idx) + { + CURSOR *c; + EPG e; +@@ -635,9 +617,7 @@ dup2: c->pg.pgno = e.page->pgno; + * h: page to be deleted + */ + int +-__bt_relink(t, h) +- BTREE *t; +- PAGE *h; ++__bt_relink(BTREE *t, PAGE *h) + { + PAGE *pg; + +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_get.c b/src/plugins/kdb/db2/libdb2/btree/bt_get.c +index b6318211a1..012a341b25 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_get.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_get.c +@@ -60,11 +60,7 @@ static char sccsid[] = "@(#)bt_get.c 8.6 (Berkeley) 7/20/94"; + * RET_ERROR, RET_SUCCESS and RET_SPECIAL if the key not found. + */ + int +-__bt_get(dbp, key, data, flags) +- const DB *dbp; +- const DBT *key; +- DBT *data; +- u_int flags; ++__bt_get(const DB *dbp, const DBT *key, DBT *data, u_int flags) + { + BTREE *t; + EPG *e; +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_open.c b/src/plugins/kdb/db2/libdb2/btree/bt_open.c +index d5809a5a93..a2910422eb 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_open.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_open.c +@@ -90,10 +90,8 @@ static int tmp __P((void)); + * + */ + DB * +-__bt_open(fname, flags, mode, openinfo, dflags) +- const char *fname; +- int flags, mode, dflags; +- const BTREEINFO *openinfo; ++__bt_open(const char *fname, int flags, int mode, const BTREEINFO *openinfo, ++ int dflags) + { + struct stat sb; + BTMETA m; +@@ -353,8 +351,7 @@ err: if (t) { + * RET_ERROR, RET_SUCCESS + */ + static int +-nroot(t) +- BTREE *t; ++nroot(BTREE *t) + { + PAGE *meta, *root; + db_pgno_t npg; +@@ -459,8 +456,7 @@ byteorder() + } + + int +-__bt_fd(dbp) +- const DB *dbp; ++__bt_fd(const DB *dbp) + { + BTREE *t; + +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_overflow.c b/src/plugins/kdb/db2/libdb2/btree/bt_overflow.c +index 8b1f597912..8301b5d19d 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_overflow.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_overflow.c +@@ -77,12 +77,7 @@ static char sccsid[] = "@(#)bt_overflow.c 8.5 (Berkeley) 7/16/94"; + * RET_ERROR, RET_SUCCESS + */ + int +-__ovfl_get(t, p, ssz, buf, bufsz) +- BTREE *t; +- void *p; +- size_t *ssz; +- void **buf; +- size_t *bufsz; ++__ovfl_get(BTREE *t, void *p, size_t *ssz, void **buf, size_t *bufsz) + { + PAGE *h; + db_pgno_t pg; +@@ -136,10 +131,7 @@ __ovfl_get(t, p, ssz, buf, bufsz) + * RET_ERROR, RET_SUCCESS + */ + int +-__ovfl_put(t, dbt, pg) +- BTREE *t; +- const DBT *dbt; +- db_pgno_t *pg; ++__ovfl_put(BTREE *t, const DBT *dbt, db_pgno_t *pg) + { + PAGE *h, *last; + void *p; +@@ -190,9 +182,7 @@ __ovfl_put(t, dbt, pg) + * RET_ERROR, RET_SUCCESS + */ + int +-__ovfl_delete(t, p) +- BTREE *t; +- void *p; ++__ovfl_delete(BTREE *t, void *p) + { + PAGE *h; + db_pgno_t pg; +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_page.c b/src/plugins/kdb/db2/libdb2/btree/bt_page.c +index 3663cf7f93..38aa39acfb 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_page.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_page.c +@@ -57,9 +57,7 @@ static char sccsid[] = "@(#)bt_page.c 8.4 (Berkeley) 11/2/95"; + * mpool_put's the page. + */ + int +-__bt_free(t, h) +- BTREE *t; +- PAGE *h; ++__bt_free(BTREE *t, PAGE *h) + { + /* Insert the page at the head of the free list. */ + h->prevpg = P_INVALID; +@@ -83,9 +81,7 @@ __bt_free(t, h) + * Pointer to a page, NULL on error. + */ + PAGE * +-__bt_new(t, npg) +- BTREE *t; +- db_pgno_t *npg; ++__bt_new(BTREE *t, db_pgno_t *npg) + { + PAGE *h; + +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_put.c b/src/plugins/kdb/db2/libdb2/btree/bt_put.c +index 7d6592841a..1303c0baef 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_put.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_put.c +@@ -64,11 +64,7 @@ static EPG *bt_fast __P((BTREE *, const DBT *, const DBT *, int *)); + * tree and R_NOOVERWRITE specified. + */ + int +-__bt_put(dbp, key, data, flags) +- const DB *dbp; +- DBT *key; +- const DBT *data; +- u_int flags; ++__bt_put(const DB *dbp, DBT *key, const DBT *data, u_int flags) + { + BTREE *t; + DBT tkey, tdata; +@@ -272,10 +268,7 @@ u_long bt_cache_hit, bt_cache_miss; + * EPG for new record or NULL if not found. + */ + static EPG * +-bt_fast(t, key, data, exactp) +- BTREE *t; +- const DBT *key, *data; +- int *exactp; ++bt_fast(BTREE *t, const DBT *key, const DBT *data, int *exactp) + { + PAGE *h; + u_int32_t nbytes; +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_search.c b/src/plugins/kdb/db2/libdb2/btree/bt_search.c +index c633d14dc6..ed512ccb65 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_search.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_search.c +@@ -63,10 +63,7 @@ static int __bt_sprev __P((BTREE *, PAGE *, const DBT *, int *)); + * the bt_cur field of the tree. A pointer to the field is returned. + */ + EPG * +-__bt_search(t, key, exactp) +- BTREE *t; +- const DBT *key; +- int *exactp; ++__bt_search(BTREE *t, const DBT *key, int *exactp) + { + PAGE *h; + indx_t base, idx, lim; +@@ -148,11 +145,7 @@ next: BT_PUSH(t, h->pgno, idx); + * If an exact match found. + */ + static int +-__bt_snext(t, h, key, exactp) +- BTREE *t; +- PAGE *h; +- const DBT *key; +- int *exactp; ++__bt_snext(BTREE *t, PAGE *h, const DBT *key, int *exactp) + { + BINTERNAL *bi; + EPG e; +@@ -228,11 +221,7 @@ __bt_snext(t, h, key, exactp) + * If an exact match found. + */ + static int +-__bt_sprev(t, h, key, exactp) +- BTREE *t; +- PAGE *h; +- const DBT *key; +- int *exactp; ++__bt_sprev(BTREE *t, PAGE *h, const DBT *key, int *exactp) + { + BINTERNAL *bi; + EPG e; +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_seq.c b/src/plugins/kdb/db2/libdb2/btree/bt_seq.c +index 2c8c2de96c..97db44abc8 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_seq.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_seq.c +@@ -102,10 +102,7 @@ static int bt_rseq_prev(BTREE *, EPG *); + * RET_ERROR, RET_SUCCESS or RET_SPECIAL if there's no next key. + */ + int +-__bt_seq(dbp, key, data, flags) +- const DB *dbp; +- DBT *key, *data; +- u_int flags; ++__bt_seq(const DB *dbp, DBT *key, DBT *data, u_int flags) + { + BTREE *t; + EPG e; +@@ -179,11 +176,7 @@ __bt_seq(dbp, key, data, flags) + * RET_ERROR, RET_SUCCESS or RET_SPECIAL if there's no next key. + */ + static int +-__bt_seqset(t, ep, key, flags) +- BTREE *t; +- EPG *ep; +- DBT *key; +- int flags; ++__bt_seqset(BTREE *t, EPG *ep, DBT *key, int flags) + { + PAGE *h; + db_pgno_t pg; +@@ -273,10 +266,7 @@ __bt_seqset(t, ep, key, flags) + * RET_ERROR, RET_SUCCESS or RET_SPECIAL if there's no next key. + */ + static int +-__bt_seqadv(t, ep, flags) +- BTREE *t; +- EPG *ep; +- int flags; ++__bt_seqadv(BTREE *t, EPG *ep, int flags) + { + CURSOR *c; + PAGE *h; +@@ -495,11 +485,7 @@ bt_rseq_prev(BTREE *t, EPG *ep) + * or RET_SPECIAL if no such key exists. + */ + static int +-__bt_first(t, key, erval, exactp) +- BTREE *t; +- const DBT *key; +- EPG *erval; +- int *exactp; ++__bt_first(BTREE *t, const DBT *key, EPG *erval, int *exactp) + { + PAGE *h, *hprev; + EPG *ep, save; +@@ -596,10 +582,7 @@ __bt_first(t, key, erval, exactp) + * index: page index + */ + void +-__bt_setcur(t, pgno, idx) +- BTREE *t; +- db_pgno_t pgno; +- u_int idx; ++__bt_setcur(BTREE *t, db_pgno_t pgno, u_int idx) + { + /* Lose any already deleted key. */ + if (t->bt_cursor.key.data != NULL) { +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_split.c b/src/plugins/kdb/db2/libdb2/btree/bt_split.c +index c7e4e72a90..8901bd64be 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_split.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_split.c +@@ -79,13 +79,8 @@ u_long bt_rootsplit, bt_split, bt_sortsplit, bt_pfxsaved; + * RET_ERROR, RET_SUCCESS + */ + int +-__bt_split(t, sp, key, data, flags, ilen, argskip) +- BTREE *t; +- PAGE *sp; +- const DBT *key, *data; +- int flags; +- size_t ilen; +- u_int32_t argskip; ++__bt_split(BTREE *t, PAGE *sp, const DBT *key, const DBT *data, int flags, ++ size_t ilen, u_int32_t argskip) + { + BINTERNAL *bi = NULL; + BLEAF *bl = NULL, *tbl; +@@ -345,11 +340,7 @@ err2: mpool_put(t->bt_mp, l, 0); + * Pointer to page in which to insert or NULL on error. + */ + static PAGE * +-bt_page(t, h, lp, rp, skip, ilen) +- BTREE *t; +- PAGE *h, **lp, **rp; +- indx_t *skip; +- size_t ilen; ++bt_page(BTREE *t, PAGE *h, PAGE **lp, PAGE **rp, indx_t *skip, size_t ilen) + { + PAGE *l, *r, *tp; + db_pgno_t npg; +@@ -450,11 +441,7 @@ bt_page(t, h, lp, rp, skip, ilen) + * Pointer to page in which to insert or NULL on error. + */ + static PAGE * +-bt_root(t, h, lp, rp, skip, ilen) +- BTREE *t; +- PAGE *h, **lp, **rp; +- indx_t *skip; +- size_t ilen; ++bt_root(BTREE *t, PAGE *h, PAGE **lp, PAGE **rp, indx_t *skip, size_t ilen) + { + PAGE *l, *r, *tp; + db_pgno_t lnpg, rnpg; +@@ -497,9 +484,7 @@ bt_root(t, h, lp, rp, skip, ilen) + * RET_ERROR, RET_SUCCESS + */ + static int +-bt_rroot(t, h, l, r) +- BTREE *t; +- PAGE *h, *l, *r; ++bt_rroot(BTREE *t, PAGE *h, PAGE *l, PAGE *r) + { + char *dest; + +@@ -537,9 +522,7 @@ bt_rroot(t, h, l, r) + * RET_ERROR, RET_SUCCESS + */ + static int +-bt_broot(t, h, l, r) +- BTREE *t; +- PAGE *h, *l, *r; ++bt_broot(BTREE *t, PAGE *h, PAGE *l, PAGE *r) + { + BINTERNAL *bi; + BLEAF *bl; +@@ -617,11 +600,7 @@ bt_broot(t, h, l, r) + * Pointer to page in which to insert. + */ + static PAGE * +-bt_psplit(t, h, l, r, pskip, ilen) +- BTREE *t; +- PAGE *h, *l, *r; +- indx_t *pskip; +- size_t ilen; ++bt_psplit(BTREE *t, PAGE *h, PAGE *l, PAGE *r, indx_t *pskip, size_t ilen) + { + BINTERNAL *bi; + BLEAF *bl; +@@ -796,9 +775,7 @@ bt_psplit(t, h, l, r, pskip, ilen) + * RET_SUCCESS, RET_ERROR. + */ + static int +-bt_preserve(t, pg) +- BTREE *t; +- db_pgno_t pg; ++bt_preserve(BTREE *t, db_pgno_t pg) + { + PAGE *h; + +@@ -824,8 +801,7 @@ bt_preserve(t, pg) + * all the way back to bt_split/bt_rroot and it's not very clean. + */ + static recno_t +-rec_total(h) +- PAGE *h; ++rec_total(PAGE *h) + { + recno_t recs; + indx_t nxt, top; +diff --git a/src/plugins/kdb/db2/libdb2/btree/bt_utils.c b/src/plugins/kdb/db2/libdb2/btree/bt_utils.c +index be2f24f219..13d1f2c84f 100644 +--- a/src/plugins/kdb/db2/libdb2/btree/bt_utils.c ++++ b/src/plugins/kdb/db2/libdb2/btree/bt_utils.c +@@ -64,11 +64,8 @@ static char sccsid[] = "@(#)bt_utils.c 8.8 (Berkeley) 7/20/94"; + * RET_SUCCESS, RET_ERROR. + */ + int +-__bt_ret(t, e, key, rkey, data, rdata, copy) +- BTREE *t; +- EPG *e; +- DBT *key, *rkey, *data, *rdata; +- int copy; ++__bt_ret(BTREE *t, EPG *e, DBT *key, DBT *rkey, DBT *data, DBT *rdata, ++ int copy) + { + BLEAF *bl; + void *p; +@@ -150,10 +147,7 @@ dataonly: + * > 0 if k1 is > record + */ + int +-__bt_cmp(t, k1, e) +- BTREE *t; +- const DBT *k1; +- EPG *e; ++__bt_cmp(BTREE *t, const DBT *k1, EPG *e) + { + BINTERNAL *bi; + BLEAF *bl; +@@ -213,8 +207,7 @@ __bt_cmp(t, k1, e) + * > 0 if a is > b + */ + int +-__bt_defcmp(a, b) +- const DBT *a, *b; ++__bt_defcmp(const DBT *a, const DBT *b) + { + size_t len; + u_char *p1, *p2; +@@ -243,8 +236,7 @@ __bt_defcmp(a, b) + * Number of bytes needed to distinguish b from a. + */ + size_t +-__bt_defpfx(a, b) +- const DBT *a, *b; ++__bt_defpfx(const DBT *a, const DBT *b) + { + u_char *p1, *p2; + size_t cnt, len; +diff --git a/src/plugins/kdb/db2/libdb2/db/db.c b/src/plugins/kdb/db2/libdb2/db/db.c +index fba7795342..f85484f077 100644 +--- a/src/plugins/kdb/db2/libdb2/db/db.c ++++ b/src/plugins/kdb/db2/libdb2/db/db.c +@@ -45,11 +45,8 @@ static char sccsid[] = "@(#)db.c 8.4 (Berkeley) 2/21/94"; + #include "db-int.h" + + DB * +-kdb2_dbopen(fname, flags, mode, type, openinfo) +- const char *fname; +- int flags, mode; +- DBTYPE type; +- const void *openinfo; ++kdb2_dbopen(const char *fname, int flags, int mode, DBTYPE type, ++ const void *openinfo) + { + + #define DB_FLAGS (DB_LOCK | DB_SHMEM | DB_TXN) +@@ -74,7 +71,7 @@ kdb2_dbopen(fname, flags, mode, type, openinfo) + } + + static int +-__dberr() ++__dberr(void) + { + return (RET_ERROR); + } +@@ -86,14 +83,15 @@ __dberr() + * dbp: pointer to the DB structure. + */ + void +-__dbpanic(dbp) +- DB *dbp; ++__dbpanic(DB *dbp) + { + /* The only thing that can succeed is a close. */ +- dbp->del = (int (*)())__dberr; +- dbp->fd = (int (*)())__dberr; +- dbp->get = (int (*)())__dberr; +- dbp->put = (int (*)())__dberr; +- dbp->seq = (int (*)())__dberr; +- dbp->sync = (int (*)())__dberr; ++ dbp->del = (int (*)(const struct __db *, const DBT *, u_int))__dberr; ++ dbp->fd = (int (*)(const struct __db *))__dberr; ++ dbp->get = (int (*)(const struct __db *, const DBT *, DBT *, ++ u_int))__dberr; ++ dbp->put = (int (*)(const struct __db *, DBT *, const DBT *, ++ u_int))__dberr; ++ dbp->seq = (int (*)(const struct __db *, DBT *, DBT *, u_int))__dberr; ++ dbp->sync = (int (*)(const struct __db *, u_int))__dberr; + } +diff --git a/src/plugins/kdb/db2/libdb2/hash/dbm.c b/src/plugins/kdb/db2/libdb2/hash/dbm.c +index 4878cbc0b6..2dca256dc3 100644 +--- a/src/plugins/kdb/db2/libdb2/hash/dbm.c ++++ b/src/plugins/kdb/db2/libdb2/hash/dbm.c +@@ -69,8 +69,7 @@ static DBM *__cur_db; + static void no_open_db __P((void)); + + int +-kdb2_dbminit(file) +- char *file; ++kdb2_dbminit(char *file) + { + if (__cur_db != NULL) + (void)kdb2_dbm_close(__cur_db); +@@ -82,8 +81,7 @@ kdb2_dbminit(file) + } + + datum +-kdb2_fetch(key) +- datum key; ++kdb2_fetch(datum key) + { + datum item; + +@@ -111,8 +109,7 @@ kdb2_firstkey() + } + + datum +-kdb2_nextkey(key) +- datum key; ++kdb2_nextkey(datum key) + { + datum item; + +@@ -126,8 +123,7 @@ kdb2_nextkey(key) + } + + int +-kdb2_delete(key) +- datum key; ++kdb2_delete(datum key) + { + if (__cur_db == NULL) { + no_open_db(); +@@ -137,8 +133,7 @@ kdb2_delete(key) + } + + int +-kdb2_store(key, dat) +- datum key, dat; ++kdb2_store(datum key, datum dat) + { + if (__cur_db == NULL) { + no_open_db(); +@@ -159,9 +154,7 @@ no_open_db() + * NULL on failure + */ + DBM * +-kdb2_dbm_open(file, flags, mode) +- const char *file; +- int flags, mode; ++kdb2_dbm_open(const char *file, int flags, int mode) + { + HASHINFO info; + char path[MAXPATHLEN]; +@@ -183,8 +176,7 @@ kdb2_dbm_open(file, flags, mode) + * Nothing. + */ + void +-kdb2_dbm_close(db) +- DBM *db; ++kdb2_dbm_close(DBM *db) + { + (void)(db->close)(db); + } +@@ -195,9 +187,7 @@ kdb2_dbm_close(db) + * NULL on failure + */ + datum +-kdb2_dbm_fetch(db, key) +- DBM *db; +- datum key; ++kdb2_dbm_fetch(DBM *db, datum key) + { + datum retval; + int status; +@@ -226,8 +216,7 @@ kdb2_dbm_fetch(db, key) + * NULL on failure + */ + datum +-kdb2_dbm_firstkey(db) +- DBM *db; ++kdb2_dbm_firstkey(DBM *db) + { + int status; + datum retkey; +@@ -254,8 +243,7 @@ kdb2_dbm_firstkey(db) + * NULL on failure + */ + datum +-kdb2_dbm_nextkey(db) +- DBM *db; ++kdb2_dbm_nextkey(DBM *db) + { + int status; + datum retkey; +@@ -282,9 +270,7 @@ kdb2_dbm_nextkey(db) + * <0 failure + */ + int +-kdb2_dbm_delete(db, key) +- DBM *db; +- datum key; ++kdb2_dbm_delete(DBM *db, datum key) + { + int status; + +@@ -310,10 +296,7 @@ kdb2_dbm_delete(db, key) + * 1 if DBM_INSERT and entry exists + */ + int +-kdb2_dbm_store(db, key, content, flags) +- DBM *db; +- datum key, content; +- int flags; ++kdb2_dbm_store(DBM *db, datum key, datum content, int flags) + { + #ifdef NEED_COPY + DBT k, c; +@@ -331,8 +314,7 @@ kdb2_dbm_store(db, key, content, flags) + } + + int +-kdb2_dbm_error(db) +- DBM *db; ++kdb2_dbm_error(DBM *db) + { + HTAB *hp; + +@@ -341,8 +323,7 @@ kdb2_dbm_error(db) + } + + int +-kdb2_dbm_clearerr(db) +- DBM *db; ++kdb2_dbm_clearerr(DBM *db) + { + HTAB *hp; + +@@ -352,8 +333,7 @@ kdb2_dbm_clearerr(db) + } + + int +-kdb2_dbm_dirfno(db) +- DBM *db; ++kdb2_dbm_dirfno(DBM *db) + { + return(((HTAB *)db->internal)->fp); + } +diff --git a/src/plugins/kdb/db2/libdb2/hash/hash.c b/src/plugins/kdb/db2/libdb2/hash/hash.c +index 686a960c96..9528b62538 100644 +--- a/src/plugins/kdb/db2/libdb2/hash/hash.c ++++ b/src/plugins/kdb/db2/libdb2/hash/hash.c +@@ -95,10 +95,8 @@ u_int32_t hash_accesses, hash_collisions, hash_expansions, hash_overflows, + /* OPEN/CLOSE */ + + extern DB * +-__kdb2_hash_open(file, flags, mode, info, dflags) +- const char *file; +- int flags, mode, dflags; +- const HASHINFO *info; /* Special directives for create */ ++__kdb2_hash_open(const char *file, int flags, int mode, const HASHINFO *info, ++ int dflags) + { + struct stat statbuf; + DB *dbp; +@@ -261,8 +259,7 @@ error0: + } + + static int32_t +-hash_close(dbp) +- DB *dbp; ++hash_close(DB *dbp) + { + HTAB *hashp; + int32_t retval; +@@ -277,8 +274,7 @@ hash_close(dbp) + } + + static int32_t +-hash_fd(dbp) +- const DB *dbp; ++hash_fd(const DB *dbp) + { + HTAB *hashp; + +@@ -295,10 +291,7 @@ hash_fd(dbp) + + /************************** LOCAL CREATION ROUTINES **********************/ + static HTAB * +-init_hash(hashp, file, info) +- HTAB *hashp; +- const char *file; +- const HASHINFO *info; ++init_hash(HTAB *hashp, const char *file, const HASHINFO *info) + { + struct stat statbuf; + +@@ -350,9 +343,7 @@ init_hash(hashp, file, info) + * Returns 0 on No Error + */ + static int32_t +-init_htab(hashp, nelem) +- HTAB *hashp; +- int32_t nelem; ++init_htab(HTAB *hashp, int32_t nelem) + { + int32_t l2, nbuckets; + +@@ -404,9 +395,7 @@ init_htab(hashp, nelem) + * Functions to get/put hash header. We access the file directly. + */ + static u_int32_t +-hget_header(hashp, page_size) +- HTAB *hashp; +- u_int32_t page_size; ++hget_header(HTAB *hashp, u_int32_t page_size) + { + u_int32_t num_copied; + u_int8_t *hdr_dest; +@@ -432,8 +421,7 @@ hget_header(hashp, page_size) + } + + static void +-hput_header(hashp) +- HTAB *hashp; ++hput_header(HTAB *hashp) + { + HASHHDR *whdrp; + #if DB_BYTE_ORDER == DB_LITTLE_ENDIAN +@@ -463,8 +451,7 @@ hput_header(hashp) + * structure, freeing all allocated space. + */ + static int32_t +-hdestroy(hashp) +- HTAB *hashp; ++hdestroy(HTAB *hashp) + { + int32_t save_errno; + +@@ -550,9 +537,7 @@ hdestroy(hashp) + * -1 ERROR + */ + static int32_t +-hash_sync(dbp, flags) +- const DB *dbp; +- u_int32_t flags; ++hash_sync(const DB *dbp, u_int32_t flags) + { + HTAB *hashp; + +@@ -571,8 +556,7 @@ hash_sync(dbp, flags) + * -1 indicates that errno should be set + */ + static int32_t +-flush_meta(hashp) +- HTAB *hashp; ++flush_meta(HTAB *hashp) + { + int32_t i; + +@@ -608,11 +592,7 @@ flush_meta(hashp) + /* *** make sure this is true! */ + + static int32_t +-hash_get(dbp, key, data, flag) +- const DB *dbp; +- const DBT *key; +- DBT *data; +- u_int32_t flag; ++hash_get(const DB *dbp, const DBT *key, DBT *data, u_int32_t flag) + { + HTAB *hashp; + +@@ -625,11 +605,7 @@ hash_get(dbp, key, data, flag) + } + + static int32_t +-hash_put(dbp, key, data, flag) +- const DB *dbp; +- DBT *key; +- const DBT *data; +- u_int32_t flag; ++hash_put(const DB *dbp, DBT *key, const DBT *data, u_int32_t flag) + { + HTAB *hashp; + +@@ -647,10 +623,7 @@ hash_put(dbp, key, data, flag) + } + + static int32_t +-hash_delete(dbp, key, flag) +- const DB *dbp; +- const DBT *key; +- u_int32_t flag; /* Ignored */ ++hash_delete(const DB *dbp, const DBT *key, u_int32_t flag) + { + HTAB *hashp; + +@@ -671,11 +644,7 @@ hash_delete(dbp, key, flag) + * Assume that hashp has been set in wrapper routine. + */ + static int32_t +-hash_access(hashp, action, key, val) +- HTAB *hashp; +- ACTION action; +- const DBT *key; +- DBT *val; ++hash_access(HTAB *hashp, ACTION action, const DBT *key, DBT *val) + { + DBT page_key, page_val; + CURSOR cursor; +@@ -792,8 +761,7 @@ found: __get_item_done(hashp, &cursor); + + /* ****************** CURSORS ********************************** */ + CURSOR * +-__cursor_creat(dbp) +- const DB *dbp; ++__cursor_creat(const DB *dbp) + { + CURSOR *new_curs; + HTAB *hashp; +@@ -824,11 +792,7 @@ __cursor_creat(dbp) + } + + static int32_t +-cursor_get(dbp, cursorp, key, val, flags) +- const DB *dbp; +- CURSOR *cursorp; +- DBT *key, *val; +- u_int32_t flags; ++cursor_get(const DB *dbp, CURSOR *cursorp, DBT *key, DBT *val, u_int32_t flags) + { + HTAB *hashp; + ITEM_INFO item_info; +@@ -897,10 +861,7 @@ cursor_get(dbp, cursorp, key, val, flags) + } + + static int32_t +-cursor_delete(dbp, cursor, flags) +- const DB *dbp; +- CURSOR *cursor; +- u_int32_t flags; ++cursor_delete(const DB *dbp, CURSOR *cursor, u_int32_t flags) + { + /* XXX this is empirically determined, so it might not be completely + correct, but it seems to work. At the very least it fixes +@@ -913,10 +874,7 @@ cursor_delete(dbp, cursor, flags) + } + + static int32_t +-hash_seq(dbp, key, val, flag) +- const DB *dbp; +- DBT *key, *val; +- u_int32_t flag; ++hash_seq(const DB *dbp, DBT *key, DBT *val, u_int32_t flag) + { + HTAB *hashp; + +@@ -940,8 +898,7 @@ hash_seq(dbp, key, val, flag) + * -1 ==> Error + */ + int32_t +-__expand_table(hashp) +- HTAB *hashp; ++__expand_table(HTAB *hashp) + { + u_int32_t old_bucket, new_bucket; + int32_t spare_ndx; +@@ -980,10 +937,7 @@ __expand_table(hashp) + } + + u_int32_t +-__call_hash(hashp, k, len) +- HTAB *hashp; +- int8_t *k; +- int32_t len; ++__call_hash(HTAB *hashp, int8_t *k, int32_t len) + { + u_int32_t n, bucket; + +@@ -999,8 +953,7 @@ __call_hash(hashp, k, len) + * Hashp->hdr needs to be byteswapped. + */ + static void +-swap_header_copy(srcp, destp) +- HASHHDR *srcp, *destp; ++swap_header_copy(HASHHDR *srcp, HASHHDR *destp) + { + int32_t i; + +@@ -1025,8 +978,7 @@ swap_header_copy(srcp, destp) + } + + static void +-swap_header(hashp) +- HTAB *hashp; ++swap_header(HTAB *hashp) + { + HASHHDR *hdrp; + int32_t i; +diff --git a/src/plugins/kdb/db2/libdb2/hash/hash_bigkey.c b/src/plugins/kdb/db2/libdb2/hash/hash_bigkey.c +index 4b95278f53..6befb7a57e 100644 +--- a/src/plugins/kdb/db2/libdb2/hash/hash_bigkey.c ++++ b/src/plugins/kdb/db2/libdb2/hash/hash_bigkey.c +@@ -83,10 +83,7 @@ static int32_t collect_data __P((HTAB *, PAGE16 *, int32_t)); + * -1 ==> ERROR + */ + int32_t +-__big_insert(hashp, pagep, key, val) +- HTAB *hashp; +- PAGE16 *pagep; +- const DBT *key, *val; ++__big_insert(HTAB *hashp, PAGE16 *pagep, const DBT *key, const DBT *val) + { + size_t key_size, val_size; + indx_t key_move_bytes, val_move_bytes; +@@ -185,11 +182,7 @@ __big_delete(hashp, pagep, ndx) + * -1 error + */ + int32_t +-__find_bigpair(hashp, cursorp, key, size) +- HTAB *hashp; +- CURSOR *cursorp; +- int8_t *key; +- int32_t size; ++__find_bigpair(HTAB *hashp, CURSOR *cursorp, int8_t *key, int32_t size) + { + PAGE16 *pagep, *hold_pagep; + db_pgno_t next_pgno; +@@ -257,11 +250,7 @@ __find_bigpair(hashp, cursorp, key, size) + * Fill in the key and data for this big pair. + */ + int32_t +-__big_keydata(hashp, pagep, key, val, ndx) +- HTAB *hashp; +- PAGE16 *pagep; +- DBT *key, *val; +- int32_t ndx; ++__big_keydata(HTAB *hashp, PAGE16 *pagep, DBT *key, DBT *val, int32_t ndx) + { + ITEM_INFO ii; + PAGE16 *key_pagep; +@@ -315,11 +304,8 @@ __get_bigkey(hashp, pagep, ndx, key) + * Return the big key and data indicated in item_info. + */ + int32_t +-__big_return(hashp, item_info, val, on_bigkey_page) +- HTAB *hashp; +- ITEM_INFO *item_info; +- DBT *val; +- int32_t on_bigkey_page; ++__big_return(HTAB *hashp, ITEM_INFO *item_info, DBT *val, ++ int32_t on_bigkey_page) + { + PAGE16 *pagep; + db_pgno_t next_pgno; +@@ -366,11 +352,7 @@ __big_return(hashp, item_info, val, on_bigkey_page) + * Return total length of data; -1 if error. + */ + static int32_t +-collect_key(hashp, pagep, len, last_page) +- HTAB *hashp; +- PAGE16 *pagep; +- int32_t len; +- db_pgno_t *last_page; ++collect_key(HTAB *hashp, PAGE16 *pagep, int32_t len, db_pgno_t *last_page) + { + PAGE16 *next_pagep; + int32_t totlen, retval; +@@ -434,10 +416,7 @@ collect_key(hashp, pagep, len, last_page) + * Return total length of data; -1 if error. + */ + static int32_t +-collect_data(hashp, pagep, len) +- HTAB *hashp; +- PAGE16 *pagep; +- int32_t len; ++collect_data(HTAB *hashp, PAGE16 *pagep, int32_t len) + { + PAGE16 *next_pagep; + int32_t totlen, retval; +diff --git a/src/plugins/kdb/db2/libdb2/hash/hash_func.c b/src/plugins/kdb/db2/libdb2/hash/hash_func.c +index 1dee694608..f169be685e 100644 +--- a/src/plugins/kdb/db2/libdb2/hash/hash_func.c ++++ b/src/plugins/kdb/db2/libdb2/hash/hash_func.c +@@ -66,9 +66,7 @@ u_int32_t (*__default_hash) __P((const void *, size_t)) = hash4; + + #if 0 + static u_int32_t +-hash1(key, len) +- const void *key; +- size_t len; ++hash1(const void *key, size_t len) + { + u_int32_t h; + u_int8_t *k; +@@ -88,9 +86,7 @@ hash1(key, len) + #define dcharhash(h, c) ((h) = 0x63c63cd9*(h) + 0x9c39c33d + (c)) + + static u_int32_t +-hash2(key, len) +- const void *key; +- size_t len; ++hash2(const void *key, size_t len) + { + u_int32_t h; + u_int8_t *e, c, *k; +@@ -116,9 +112,7 @@ hash2(key, len) + * Ozan Yigit's original sdbm hash. + */ + static u_int32_t +-hash3(key, len) +- const void *key; +- size_t len; ++hash3(const void *key, size_t len) + { + u_int32_t n, loop; + u_int8_t *k; +@@ -159,9 +153,7 @@ hash3(key, len) + + /* Chris Torek's hash function. */ + static u_int32_t +-hash4(key, len) +- const void *key; +- size_t len; ++hash4(const void *key, size_t len) + { + u_int32_t h, loop; + const u_int8_t *k; +diff --git a/src/plugins/kdb/db2/libdb2/hash/hash_log2.c b/src/plugins/kdb/db2/libdb2/hash/hash_log2.c +index 8c710e5d21..7fdfd854d2 100644 +--- a/src/plugins/kdb/db2/libdb2/hash/hash_log2.c ++++ b/src/plugins/kdb/db2/libdb2/hash/hash_log2.c +@@ -44,8 +44,7 @@ static char sccsid[] = "@(#)hash_log2.c 8.4 (Berkeley) 11/7/95"; + #include "extern.h" + + u_int32_t +-__kdb2_log2(num) +- u_int32_t num; ++__kdb2_log2(u_int32_t num) + { + u_int32_t i, limit; + +diff --git a/src/plugins/kdb/db2/libdb2/hash/hash_page.c b/src/plugins/kdb/db2/libdb2/hash/hash_page.c +index 0da357108a..dba29e0cb5 100644 +--- a/src/plugins/kdb/db2/libdb2/hash/hash_page.c ++++ b/src/plugins/kdb/db2/libdb2/hash/hash_page.c +@@ -84,11 +84,8 @@ static void account_page(HTAB *, db_pgno_t, int); + #endif + + u_int32_t +-__get_item(hashp, cursorp, key, val, item_info) +- HTAB *hashp; +- CURSOR *cursorp; +- DBT *key, *val; +- ITEM_INFO *item_info; ++__get_item(HTAB *hashp, CURSOR *cursorp, DBT *key, DBT *val, ++ ITEM_INFO *item_info) + { + db_pgno_t next_pgno; + int32_t i; +@@ -159,9 +156,7 @@ __get_item(hashp, cursorp, key, val, item_info) + } + + u_int32_t +-__get_item_reset(hashp, cursorp) +- HTAB *hashp; +- CURSOR *cursorp; ++__get_item_reset(HTAB *hashp, CURSOR *cursorp) + { + if (cursorp->pagep) + __put_page(hashp, cursorp->pagep, A_RAW, 0); +@@ -174,9 +169,7 @@ __get_item_reset(hashp, cursorp) + } + + u_int32_t +-__get_item_done(hashp, cursorp) +- HTAB *hashp; +- CURSOR *cursorp; ++__get_item_done(HTAB *hashp, CURSOR *cursorp) + { + if (cursorp->pagep) + __put_page(hashp, cursorp->pagep, A_RAW, 0); +@@ -190,11 +183,8 @@ __get_item_done(hashp, cursorp) + } + + u_int32_t +-__get_item_first(hashp, cursorp, key, val, item_info) +- HTAB *hashp; +- CURSOR *cursorp; +- DBT *key, *val; +- ITEM_INFO *item_info; ++__get_item_first(HTAB *hashp, CURSOR *cursorp, DBT *key, DBT *val, ++ ITEM_INFO *item_info) + { + __get_item_reset(hashp, cursorp); + cursorp->bucket = 0; +@@ -206,11 +196,8 @@ __get_item_first(hashp, cursorp, key, val, item_info) + * just returns the page number and index of the bigkey pointer pair. + */ + u_int32_t +-__get_item_next(hashp, cursorp, key, val, item_info) +- HTAB *hashp; +- CURSOR *cursorp; +- DBT *key, *val; +- ITEM_INFO *item_info; ++__get_item_next(HTAB *hashp, CURSOR *cursorp, DBT *key, DBT *val, ++ ITEM_INFO *item_info) + { + int status; + +@@ -224,9 +211,7 @@ __get_item_next(hashp, cursorp, key, val, item_info) + * Put a non-big pair on a page. + */ + static void +-putpair(p, key, val) +- PAGE8 *p; +- const DBT *key, *val; ++putpair(PAGE8 *p, const DBT *key, const DBT *val) + { + u_int16_t *pagep, n, off; + +@@ -275,10 +260,7 @@ prev_realkey(pagep, n) + * -1 error + */ + extern int32_t +-__delpair(hashp, cursorp, item_info) +- HTAB *hashp; +- CURSOR *cursorp; +- ITEM_INFO *item_info; ++__delpair(HTAB *hashp, CURSOR *cursorp, ITEM_INFO *item_info) + { + PAGE16 *pagep; + indx_t ndx; +@@ -412,9 +394,7 @@ __delpair(hashp, cursorp, item_info) + } + + extern int32_t +-__split_page(hashp, obucket, nbucket) +- HTAB *hashp; +- u_int32_t obucket, nbucket; ++__split_page(HTAB *hashp, u_int32_t obucket, u_int32_t nbucket) + { + DBT key, val; + ITEM_INFO old_ii, new_ii; +@@ -661,9 +641,7 @@ add_bigptr(hashp, item_info, big_pgno) + * NULL on error + */ + extern PAGE16 * +-__add_ovflpage(hashp, pagep) +- HTAB *hashp; +- PAGE16 *pagep; ++__add_ovflpage(HTAB *hashp, PAGE16 *pagep) + { + PAGE16 *new_pagep; + u_int16_t ovfl_num; +@@ -768,10 +746,7 @@ page_init(hashp, pagep, pgno, type) + } + + int32_t +-__new_page(hashp, addr, addr_type) +- HTAB *hashp; +- u_int32_t addr; +- int32_t addr_type; ++__new_page(HTAB *hashp, u_int32_t addr, int32_t addr_type) + { + db_pgno_t paddr; + PAGE16 *pagep; +@@ -804,10 +779,7 @@ __new_page(hashp, addr, addr_type) + } + + int32_t +-__delete_page(hashp, pagep, page_type) +- HTAB *hashp; +- PAGE16 *pagep; +- int32_t page_type; ++__delete_page(HTAB *hashp, PAGE16 *pagep, int32_t page_type) + { + if (page_type == A_OVFL) + __free_ovflpage(hashp, pagep); +@@ -815,9 +787,7 @@ __delete_page(hashp, pagep, page_type) + } + + static u_int8_t +-is_bitmap_pgno(hashp, pgno) +- HTAB *hashp; +- db_pgno_t pgno; ++is_bitmap_pgno(HTAB *hashp, db_pgno_t pgno) + { + int32_t i; + +@@ -828,10 +798,7 @@ is_bitmap_pgno(hashp, pgno) + } + + void +-__pgin_routine(pg_cookie, pgno, page) +- void *pg_cookie; +- db_pgno_t pgno; +- void *page; ++__pgin_routine(void *pg_cookie, db_pgno_t pgno, void *page) + { + HTAB *hashp; + PAGE16 *pagep; +@@ -868,10 +835,7 @@ __pgin_routine(pg_cookie, pgno, page) + } + + void +-__pgout_routine(pg_cookie, pgno, page) +- void *pg_cookie; +- db_pgno_t pgno; +- void *page; ++__pgout_routine(void *pg_cookie, db_pgno_t pgno, void *page) + { + HTAB *hashp; + PAGE16 *pagep; +@@ -905,10 +869,7 @@ __pgout_routine(pg_cookie, pgno, page) + * -1 ==>failure + */ + extern int32_t +-__put_page(hashp, pagep, addr_type, is_dirty) +- HTAB *hashp; +- PAGE16 *pagep; +- int32_t addr_type, is_dirty; ++__put_page(HTAB *hashp, PAGE16 *pagep, int32_t addr_type, int32_t is_dirty) + { + #if DEBUG_SLOW + account_page(hashp, +@@ -924,10 +885,7 @@ __put_page(hashp, pagep, addr_type, is_dirty) + * -1 indicates FAILURE + */ + extern PAGE16 * +-__get_page(hashp, addr, addr_type) +- HTAB *hashp; +- u_int32_t addr; +- int32_t addr_type; ++__get_page(HTAB *hashp, u_int32_t addr, int32_t addr_type) + { + PAGE16 *pagep; + db_pgno_t paddr; +@@ -958,8 +916,7 @@ __get_page(hashp, addr, addr_type) + } + + static void +-swap_page_header_in(pagep) +- PAGE16 *pagep; ++swap_page_header_in(PAGE16 *pagep) + { + u_int32_t i; + +@@ -977,8 +934,7 @@ swap_page_header_in(pagep) + } + + static void +-swap_page_header_out(pagep) +- PAGE16 *pagep; ++swap_page_header_out(PAGE16 *pagep) + { + u_int32_t i; + +@@ -1001,9 +957,7 @@ swap_page_header_out(pagep) + * once they are read in. + */ + extern int32_t +-__ibitmap(hashp, pnum, nbits, ndx) +- HTAB *hashp; +- int32_t pnum, nbits, ndx; ++__ibitmap(HTAB *hashp, int32_t pnum, int32_t nbits, int32_t ndx) + { + u_int32_t *ip; + int32_t clearbytes, clearints; +@@ -1027,8 +981,7 @@ __ibitmap(hashp, pnum, nbits, ndx) + } + + static u_int32_t +-first_free(map) +- u_int32_t map; ++first_free(u_int32_t map) + { + u_int32_t i, mask; + +@@ -1044,8 +997,7 @@ first_free(map) + * returns 0 on error + */ + static u_int16_t +-overflow_page(hashp) +- HTAB *hashp; ++overflow_page(HTAB *hashp) + { + u_int32_t *freep; + u_int32_t bit, first_page, free_bit, free_page, i, in_use_bits, j; +@@ -1206,9 +1158,7 @@ found: + + #ifdef DEBUG + int +-bucket_to_page(hashp, n) +- HTAB *hashp; +- int n; ++bucket_to_page(HTAB *hashp, int n) + { + int ret_val; + +@@ -1219,9 +1169,7 @@ bucket_to_page(hashp, n) + } + + int32_t +-oaddr_to_page(hashp, n) +- HTAB *hashp; +- int n; ++oaddr_to_page(HTAB *hashp, int n) + { + int ret_val, temp; + +@@ -1234,9 +1182,7 @@ oaddr_to_page(hashp, n) + #endif /* DEBUG */ + + static indx_t +-page_to_oaddr(hashp, pgno) +- HTAB *hashp; +- db_pgno_t pgno; ++page_to_oaddr(HTAB *hashp, db_pgno_t pgno) + { + int32_t sp, ret_val; + +@@ -1268,9 +1214,7 @@ page_to_oaddr(hashp, pgno) + * Mark this overflow page as free. + */ + extern void +-__free_ovflpage(hashp, pagep) +- HTAB *hashp; +- PAGE16 *pagep; ++__free_ovflpage(HTAB *hashp, PAGE16 *pagep) + { + u_int32_t *freep; + u_int32_t bit_address, free_page, free_bit; +@@ -1307,9 +1251,7 @@ __free_ovflpage(hashp, pagep) + } + + static u_int32_t * +-fetch_bitmap(hashp, ndx) +- HTAB *hashp; +- int32_t ndx; ++fetch_bitmap(HTAB *hashp, int32_t ndx) + { + if (ndx >= hashp->nmaps) + return (NULL); +@@ -1322,10 +1264,7 @@ fetch_bitmap(hashp, ndx) + + #ifdef DEBUG_SLOW + static void +-account_page(hashp, pgno, inout) +- HTAB *hashp; +- db_pgno_t pgno; +- int inout; ++account_page(HTAB *hashp, db_pgno_t pgno, int inout) + { + static struct { + db_pgno_t pgno; +diff --git a/src/plugins/kdb/db2/libdb2/hash/hsearch.c b/src/plugins/kdb/db2/libdb2/hash/hsearch.c +index 02ff7ef843..ffcdfcf294 100644 +--- a/src/plugins/kdb/db2/libdb2/hash/hsearch.c ++++ b/src/plugins/kdb/db2/libdb2/hash/hsearch.c +@@ -50,8 +50,7 @@ static DB *dbp = NULL; + static ENTRY retval; + + extern int +-hcreate(nel) +- u_int nel; ++hcreate(u_int nel) + { + HASHINFO info; + +@@ -66,9 +65,7 @@ hcreate(nel) + } + + extern ENTRY * +-hsearch(item, action) +- ENTRY item; +- ACTION action; ++hsearch(ENTRY item, ACTION action) + { + DBT key, val; + int status; +@@ -98,7 +95,7 @@ hsearch(item, action) + } + + extern void +-hdestroy() ++hdestroy(void) + { + if (dbp) { + (void)(dbp->close)(dbp); +diff --git a/src/plugins/kdb/db2/libdb2/mpool/mpool.c b/src/plugins/kdb/db2/libdb2/mpool/mpool.c +index 0fcfd4ac2b..028fb180ca 100644 +--- a/src/plugins/kdb/db2/libdb2/mpool/mpool.c ++++ b/src/plugins/kdb/db2/libdb2/mpool/mpool.c +@@ -56,10 +56,7 @@ static int mpool_write __P((MPOOL *, BKT *)); + * Initialize a memory pool. + */ + MPOOL * +-mpool_open(key, fd, pagesize, maxcache) +- void *key; +- int fd; +- db_pgno_t pagesize, maxcache; ++mpool_open(void *key, int fd, db_pgno_t pagesize, db_pgno_t maxcache) + { + struct stat sb; + MPOOL *mp; +@@ -96,11 +93,8 @@ mpool_open(key, fd, pagesize, maxcache) + * Initialize input/output filters. + */ + void +-mpool_filter(mp, pgin, pgout, pgcookie) +- MPOOL *mp; +- void (*pgin) __P((void *, db_pgno_t, void *)); +- void (*pgout) __P((void *, db_pgno_t, void *)); +- void *pgcookie; ++mpool_filter(MPOOL *mp, void (*pgin) __P((void *, db_pgno_t, void *)), ++ void (*pgout) __P((void *, db_pgno_t, void *)), void *pgcookie) + { + mp->pgin = pgin; + mp->pgout = pgout; +@@ -112,10 +106,7 @@ mpool_filter(mp, pgin, pgout, pgcookie) + * Get a new page of memory. + */ + void * +-mpool_new(mp, pgnoaddr, flags) +- MPOOL *mp; +- db_pgno_t *pgnoaddr; +- u_int flags; ++mpool_new(MPOOL *mp, db_pgno_t *pgnoaddr, u_int flags) + { + struct _hqh *head; + BKT *bp; +@@ -149,9 +140,7 @@ mpool_new(mp, pgnoaddr, flags) + } + + int +-mpool_delete(mp, page) +- MPOOL *mp; +- void *page; ++mpool_delete(MPOOL *mp, void *page) + { + struct _hqh *head; + BKT *bp; +@@ -180,10 +169,7 @@ mpool_delete(mp, page) + * Get a page. + */ + void * +-mpool_get(mp, pgno, flags) +- MPOOL *mp; +- db_pgno_t pgno; +- u_int flags; /* XXX not used? */ ++mpool_get(MPOOL *mp, db_pgno_t pgno, u_int flags) + { + struct _hqh *head; + BKT *bp; +@@ -278,10 +264,7 @@ mpool_get(mp, pgno, flags) + * Return a page. + */ + int +-mpool_put(mp, page, flags) +- MPOOL *mp; +- void *page; +- u_int flags; ++mpool_put(MPOOL *mp, void *page, u_int flags) + { + BKT *bp; + +@@ -307,8 +290,7 @@ mpool_put(mp, page, flags) + * Close the buffer pool. + */ + int +-mpool_close(mp) +- MPOOL *mp; ++mpool_close(MPOOL *mp) + { + BKT *bp; + +@@ -328,8 +310,7 @@ mpool_close(mp) + * Sync the pool to disk. + */ + int +-mpool_sync(mp) +- MPOOL *mp; ++mpool_sync(MPOOL *mp) + { + BKT *bp; + +@@ -348,8 +329,7 @@ mpool_sync(mp) + * Get a page from the cache (or create one). + */ + static BKT * +-mpool_bkt(mp) +- MPOOL *mp; ++mpool_bkt(MPOOL *mp) + { + struct _hqh *head; + BKT *bp; +@@ -407,9 +387,7 @@ new: if ((bp = (BKT *)malloc(sizeof(BKT) + mp->pagesize)) == NULL) + * Write a page to disk. + */ + static int +-mpool_write(mp, bp) +- MPOOL *mp; +- BKT *bp; ++mpool_write(MPOOL *mp, BKT *bp) + { + off_t off; + +@@ -451,9 +429,7 @@ mpool_write(mp, bp) + * Lookup a page in the cache. + */ + static BKT * +-mpool_look(mp, pgno) +- MPOOL *mp; +- db_pgno_t pgno; ++mpool_look(MPOOL *mp, db_pgno_t pgno) + { + struct _hqh *head; + BKT *bp; +@@ -478,8 +454,7 @@ mpool_look(mp, pgno) + * Print out cache statistics. + */ + void +-mpool_stat(mp) +- MPOOL *mp; ++mpool_stat(MPOOL *mp) + { + BKT *bp; + int cnt; +@@ -520,8 +495,7 @@ mpool_stat(mp) + } + #else + void +-mpool_stat(mp) +- MPOOL *mp; ++mpool_stat(MPOOL *mp) + { + } + #endif +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_close.c b/src/plugins/kdb/db2/libdb2/recno/rec_close.c +index 4ef4dd1bae..b858e5c909 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_close.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_close.c +@@ -59,8 +59,7 @@ static char sccsid[] = "@(#)rec_close.c 8.9 (Berkeley) 11/18/94"; + * RET_ERROR, RET_SUCCESS + */ + int +-__rec_close(dbp) +- DB *dbp; ++__rec_close(DB *dbp) + { + BTREE *t; + int status; +@@ -108,9 +107,7 @@ __rec_close(dbp) + * RET_SUCCESS, RET_ERROR. + */ + int +-__rec_sync(dbp, flags) +- const DB *dbp; +- u_int flags; ++__rec_sync(const DB *dbp, u_int flags) + { + struct iovec iov[2]; + BTREE *t; +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_delete.c b/src/plugins/kdb/db2/libdb2/recno/rec_delete.c +index b69c9ad742..7e574df28e 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_delete.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_delete.c +@@ -61,10 +61,7 @@ static int rec_rdelete __P((BTREE *, recno_t)); + * RET_ERROR, RET_SUCCESS and RET_SPECIAL if the key not found. + */ + int +-__rec_delete(dbp, key, flags) +- const DB *dbp; +- const DBT *key; +- u_int flags; ++__rec_delete(const DB *dbp, const DBT *key, u_int flags) + { + BTREE *t; + recno_t nrec; +@@ -117,9 +114,7 @@ einval: errno = EINVAL; + * RET_ERROR, RET_SUCCESS and RET_SPECIAL if the key not found. + */ + static int +-rec_rdelete(t, nrec) +- BTREE *t; +- recno_t nrec; ++rec_rdelete(BTREE *t, recno_t nrec) + { + EPG *e; + PAGE *h; +@@ -151,10 +146,7 @@ rec_rdelete(t, nrec) + * RET_SUCCESS, RET_ERROR. + */ + int +-__rec_dleaf(t, h, idx) +- BTREE *t; +- PAGE *h; +- u_int32_t idx; ++__rec_dleaf(BTREE *t, PAGE *h, u_int32_t idx) + { + RLEAF *rl; + indx_t *ip, cnt, offset; +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_get.c b/src/plugins/kdb/db2/libdb2/recno/rec_get.c +index 230b2d4f54..c89cb556fc 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_get.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_get.c +@@ -60,11 +60,7 @@ static char sccsid[] = "@(#)rec_get.c 8.9 (Berkeley) 8/18/94"; + * RET_ERROR, RET_SUCCESS and RET_SPECIAL if the key not found. + */ + int +-__rec_get(dbp, key, data, flags) +- const DB *dbp; +- const DBT *key; +- DBT *data; +- u_int flags; ++__rec_get(const DB *dbp, const DBT *key, DBT *data, u_int flags) + { + BTREE *t; + EPG *e; +@@ -119,9 +115,7 @@ __rec_get(dbp, key, data, flags) + * RET_ERROR, RET_SUCCESS + */ + int +-__rec_fpipe(t, top) +- BTREE *t; +- recno_t top; ++__rec_fpipe(BTREE *t, recno_t top) + { + DBT data; + recno_t nrec; +@@ -175,9 +169,7 @@ __rec_fpipe(t, top) + * RET_ERROR, RET_SUCCESS + */ + int +-__rec_vpipe(t, top) +- BTREE *t; +- recno_t top; ++__rec_vpipe(BTREE *t, recno_t top) + { + DBT data; + recno_t nrec; +@@ -232,9 +224,7 @@ __rec_vpipe(t, top) + * RET_ERROR, RET_SUCCESS + */ + int +-__rec_fmap(t, top) +- BTREE *t; +- recno_t top; ++__rec_fmap(BTREE *t, recno_t top) + { + DBT data; + recno_t nrec; +@@ -282,9 +272,7 @@ __rec_fmap(t, top) + * RET_ERROR, RET_SUCCESS + */ + int +-__rec_vmap(t, top) +- BTREE *t; +- recno_t top; ++__rec_vmap(BTREE *t, recno_t top) + { + DBT data; + u_char *sp, *ep; +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_open.c b/src/plugins/kdb/db2/libdb2/recno/rec_open.c +index b0daa7c021..de3fc3f4d0 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_open.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_open.c +@@ -56,10 +56,8 @@ static char sccsid[] = "@(#)rec_open.c 8.12 (Berkeley) 11/18/94"; + #include "recno.h" + + DB * +-__rec_open(fname, flags, mode, openinfo, dflags) +- const char *fname; +- int flags, mode, dflags; +- const RECNOINFO *openinfo; ++__rec_open(const char *fname, int flags, int mode, const RECNOINFO *openinfo, ++ int dflags) + { + BTREE *t; + BTREEINFO btopeninfo; +@@ -228,8 +226,7 @@ err: sverrno = errno; + } + + int +-__rec_fd(dbp) +- const DB *dbp; ++__rec_fd(const DB *dbp) + { + BTREE *t; + +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_put.c b/src/plugins/kdb/db2/libdb2/recno/rec_put.c +index c53c9578e5..8456f1dbf6 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_put.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_put.c +@@ -59,11 +59,7 @@ static char sccsid[] = "@(#)rec_put.c 8.7 (Berkeley) 8/18/94"; + * already in the tree and R_NOOVERWRITE specified. + */ + int +-__rec_put(dbp, key, data, flags) +- const DB *dbp; +- DBT *key; +- const DBT *data; +- u_int flags; ++__rec_put(const DB *dbp, DBT *key, const DBT *data, u_int flags) + { + BTREE *t; + DBT fdata, tdata; +@@ -187,11 +183,7 @@ einval: errno = EINVAL; + * RET_ERROR, RET_SUCCESS + */ + int +-__rec_iput(t, nrec, data, flags) +- BTREE *t; +- recno_t nrec; +- const DBT *data; +- u_int flags; ++__rec_iput(BTREE *t, recno_t nrec, const DBT *data, u_int flags) + { + DBT tdata; + EPG *e; +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_search.c b/src/plugins/kdb/db2/libdb2/recno/rec_search.c +index 244d79f36d..55e5ba879b 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_search.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_search.c +@@ -61,10 +61,7 @@ static char sccsid[] = "@(#)rec_search.c 8.4 (Berkeley) 7/14/94"; + * the bt_cur field of the tree. A pointer to the field is returned. + */ + EPG * +-__rec_search(t, recno, op) +- BTREE *t; +- recno_t recno; +- enum SRCHOP op; ++__rec_search(BTREE *t, recno_t recno, enum SRCHOP op) + { + indx_t idx; + PAGE *h; +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_seq.c b/src/plugins/kdb/db2/libdb2/recno/rec_seq.c +index 8af1378c34..cf48ea24d7 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_seq.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_seq.c +@@ -58,10 +58,7 @@ static char sccsid[] = "@(#)rec_seq.c 8.3 (Berkeley) 7/14/94"; + * RET_ERROR, RET_SUCCESS or RET_SPECIAL if there's no next key. + */ + int +-__rec_seq(dbp, key, data, flags) +- const DB *dbp; +- DBT *key, *data; +- u_int flags; ++__rec_seq(const DB *dbp, DBT *key, DBT *data, u_int flags) + { + BTREE *t; + EPG *e; +diff --git a/src/plugins/kdb/db2/libdb2/recno/rec_utils.c b/src/plugins/kdb/db2/libdb2/recno/rec_utils.c +index f757a724f5..2eaa39b4a3 100644 +--- a/src/plugins/kdb/db2/libdb2/recno/rec_utils.c ++++ b/src/plugins/kdb/db2/libdb2/recno/rec_utils.c +@@ -59,11 +59,7 @@ static char sccsid[] = "@(#)rec_utils.c 8.6 (Berkeley) 7/16/94"; + * RET_SUCCESS, RET_ERROR. + */ + int +-__rec_ret(t, e, nrec, key, data) +- BTREE *t; +- EPG *e; +- recno_t nrec; +- DBT *key, *data; ++__rec_ret(BTREE *t, EPG *e, recno_t nrec, DBT *key, DBT *data) + { + RLEAF *rl; + void *p; +diff --git a/src/plugins/kdb/db2/libdb2/test/dbtest.c b/src/plugins/kdb/db2/libdb2/test/dbtest.c +index 5d76b1ddf9..04bf34b90d 100644 +--- a/src/plugins/kdb/db2/libdb2/test/dbtest.c ++++ b/src/plugins/kdb/db2/libdb2/test/dbtest.c +@@ -121,9 +121,7 @@ DB *XXdbp; /* Global for gdb. */ + u_long XXlineno; /* Fast breakpoint for gdb. */ + + int +-main(argc, argv) +- int argc; +- char *argv[]; ++main(int argc, char *argv[]) + { + extern int optind; + extern char *optarg; +@@ -380,8 +378,7 @@ lkey: switch (command) { + #define NOOVERWRITE "put failed, would overwrite key\n" + + void +-compare(db1, db2) +- DBT *db1, *db2; ++compare(DBT *db1, DBT *db2) + { + size_t len; + u_char *p1, *p2; +@@ -402,9 +399,7 @@ compare(db1, db2) + } + + void +-get(dbp, kp) +- DB *dbp; +- DBT *kp; ++get(DB *dbp, DBT *kp) + { + DBT data; + +@@ -437,9 +432,7 @@ get(dbp, kp) + } + + void +-getdata(dbp, kp, dp) +- DB *dbp; +- DBT *kp, *dp; ++getdata(DB *dbp, DBT *kp, DBT *dp) + { + switch (dbp->get(dbp, kp, dp, flags)) { + case 0: +@@ -454,9 +447,7 @@ getdata(dbp, kp, dp) + } + + void +-put(dbp, kp, dp) +- DB *dbp; +- DBT *kp, *dp; ++put(DB *dbp, DBT *kp, DBT *dp) + { + switch (dbp->put(dbp, kp, dp, flags)) { + case 0: +@@ -473,9 +464,7 @@ put(dbp, kp, dp) + } + + void +-rem(dbp, kp) +- DB *dbp; +- DBT *kp; ++rem(DB *dbp, DBT *kp) + { + switch (dbp->del(dbp, kp, flags)) { + case 0: +@@ -502,8 +491,7 @@ rem(dbp, kp) + } + + void +-synk(dbp) +- DB *dbp; ++synk(DB *dbp) + { + switch (dbp->sync(dbp, flags)) { + case 0: +@@ -515,9 +503,7 @@ synk(dbp) + } + + void +-seq(dbp, kp) +- DB *dbp; +- DBT *kp; ++seq(DB *dbp, DBT *kp) + { + DBT data; + +@@ -551,10 +537,7 @@ seq(dbp, kp) + } + + void +-dump(dbp, rev, recurse) +- DB *dbp; +- int rev; +- int recurse; ++dump(DB *dbp, int rev, int recurse) + { + DBT key, data; + int lflags, nflags; +@@ -588,8 +571,7 @@ done: return; + } + + void +-unlinkpg(dbp) +- DB *dbp; ++unlinkpg(DB *dbp) + { + BTREE *t = dbp->internal; + PAGE *h = NULL; +@@ -623,8 +605,7 @@ cleanup: + } + + u_int +-setflags(s) +- char *s; ++setflags(char *s) + { + char *p; + +@@ -648,8 +629,7 @@ setflags(s) + } + + char * +-sflags(lflags) +- int lflags; ++sflags(int lflags) + { + switch (lflags) { + case R_CURSOR: return ("R_CURSOR"); +@@ -667,8 +647,7 @@ sflags(lflags) + } + + DBTYPE +-dbtype(s) +- char *s; ++dbtype(char *s) + { + if (!strcmp(s, "btree")) + return (DB_BTREE); +@@ -681,9 +660,7 @@ dbtype(s) + } + + void * +-setinfo(db_type, s) +- DBTYPE db_type; +- char *s; ++setinfo(DBTYPE db_type, char *s) + { + static BTREEINFO ib; + static HASHINFO ih; +@@ -777,9 +754,7 @@ setinfo(db_type, s) + } + + void * +-rfile(name, lenp) +- char *name; +- size_t *lenp; ++rfile(char *name, size_t *lenp) + { + struct stat sb; + void *p; +@@ -806,9 +781,7 @@ rfile(name, lenp) + } + + void * +-xmalloc(text, len) +- char *text; +- size_t len; ++xmalloc(char *text, size_t len) + { + void *p; + +diff --git a/src/plugins/kdb/db2/pol_xdr.c b/src/plugins/kdb/db2/pol_xdr.c +index e8576337c8..448d4b0f51 100644 +--- a/src/plugins/kdb/db2/pol_xdr.c ++++ b/src/plugins/kdb/db2/pol_xdr.c +@@ -82,7 +82,7 @@ xdr_osa_policy_ent_rec(XDR *xdrs, osa_policy_ent_t objp) + if (!xdr_short(xdrs, &objp->n_tl_data)) + return (FALSE); + if (!xdr_nulltype(xdrs, (void **) &objp->tl_data, +- xdr_krb5_tl_data)) ++ (xdrproc_t)xdr_krb5_tl_data)) + return FALSE; + } + return (TRUE); +diff --git a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c +index 0b56ba86a7..7ddea923a3 100644 +--- a/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c ++++ b/src/plugins/kdb/ldap/ldap_util/kdb5_ldap_util.c +@@ -186,8 +186,8 @@ static struct _cmd_table { + * The function cmd_lookup returns the structure matching the + * command name and returns NULL if nothing matches. + */ +-static struct _cmd_table *cmd_lookup(name) +- char *name; ++static struct _cmd_table * ++cmd_lookup(const char *name) + { + int i; + +diff --git a/src/plugins/kdb/lmdb/kdb_lmdb.c b/src/plugins/kdb/lmdb/kdb_lmdb.c +index bd288e2236..dbab7967c6 100644 +--- a/src/plugins/kdb/lmdb/kdb_lmdb.c ++++ b/src/plugins/kdb/lmdb/kdb_lmdb.c +@@ -468,13 +468,13 @@ error: + } + + static krb5_error_code +-klmdb_lib_init() ++klmdb_lib_init(void) + { + return 0; + } + + static krb5_error_code +-klmdb_lib_cleanup() ++klmdb_lib_cleanup(void) + { + return 0; + } +diff --git a/src/plugins/kdb/test/kdb_test.c b/src/plugins/kdb/test/kdb_test.c +index f4d4380d5b..8d14091f38 100644 +--- a/src/plugins/kdb/test/kdb_test.c ++++ b/src/plugins/kdb/test/kdb_test.c +@@ -312,13 +312,13 @@ make_strings(char **stringattrs, krb5_db_entry *ent) + } + + static krb5_error_code +-test_init() ++test_init(void) + { + return 0; + } + + static krb5_error_code +-test_cleanup() ++test_cleanup(void) + { + return 0; + } +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 8cdc40bfb4..f5aade34cc 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -3471,7 +3471,7 @@ load_pkcs11_module(krb5_context context, const char *modname, + CK_RV (*getflist)(CK_FUNCTION_LIST_PTR_PTR); + struct errinfo einfo = EMPTY_ERRINFO; + const char *errmsg = NULL; +- void (*sym)(); ++ void (*sym)(void); + long err; + CK_RV rv; + +@@ -3490,7 +3490,7 @@ load_pkcs11_module(krb5_context context, const char *modname, + goto error; + } + +- getflist = (CK_RV (*)())sym; ++ getflist = (CK_RV (*)(CK_FUNCTION_LIST_PTR_PTR))sym; + rv = (*getflist)(p11p); + if (rv != CKR_OK) { + TRACE_PKINIT_PKCS11_GETFLIST_FAILED(context, pkcs11err(rv)); +diff --git a/src/plugins/preauth/spake/t_vectors.c b/src/plugins/preauth/spake/t_vectors.c +index 96b0307d78..ecffd3d7ee 100644 +--- a/src/plugins/preauth/spake/t_vectors.c ++++ b/src/plugins/preauth/spake/t_vectors.c +@@ -439,7 +439,7 @@ run_test(const struct test *t) + } + + int +-main() ++main(void) + { + size_t i; + +diff --git a/src/tests/asn.1/krb5_decode_test.c b/src/tests/asn.1/krb5_decode_test.c +index 926aa94706..2fa6dce8eb 100644 +--- a/src/tests/asn.1/krb5_decode_test.c ++++ b/src/tests/asn.1/krb5_decode_test.c +@@ -54,9 +54,8 @@ static void ktest_free_reply_key_pack(krb5_context context, + static void ktest_free_kkdcp_message(krb5_context context, + krb5_kkdcp_message *val); + +-int main(argc, argv) +- int argc; +- char **argv; ++int ++main(int argc, char **argv) + { + krb5_data code; + krb5_error_code retval; +diff --git a/src/tests/asn.1/krb5_encode_test.c b/src/tests/asn.1/krb5_encode_test.c +index 26c064e67d..f4e754b1cc 100644 +--- a/src/tests/asn.1/krb5_encode_test.c ++++ b/src/tests/asn.1/krb5_encode_test.c +@@ -37,7 +37,7 @@ krb5_context test_context; + int error_count = 0; + int do_trval = 0; + int first_trval = 1; +-int trval2(); ++int trval2(FILE *, unsigned char *, int, int, int *); + + static void + encoder_print_results(krb5_data *code, char *typestring, char *description) +@@ -51,7 +51,7 @@ encoder_print_results(krb5_data *code, char *typestring, char *description) + else + printf("\n"); + printf("encode_krb5_%s%s:\n", typestring, description); +- r = trval2(stdout, code->data, code->length, 0, &rlen); ++ r = trval2(stdout, (uint8_t *)code->data, code->length, 0, &rlen); + printf("\n"); + if (rlen < 0 || (unsigned int) rlen != code->length) { + printf("Error: length mismatch: was %d, parsed %d\n", +@@ -72,9 +72,8 @@ encoder_print_results(krb5_data *code, char *typestring, char *description) + ktest_destroy_data(&code); + } + +-static void PRS(argc, argv) +- int argc; +- char **argv; ++static void ++PRS(int argc, char **argv) + { + extern char *optarg; + int optchar; +@@ -107,9 +106,7 @@ static void PRS(argc, argv) + } + + int +-main(argc, argv) +- int argc; +- char **argv; ++main(int argc, char **argv) + { + krb5_data *code; + krb5_error_code retval; +diff --git a/src/tests/asn.1/t_trval.c b/src/tests/asn.1/t_trval.c +index 57d8253880..009ed5bb9e 100644 +--- a/src/tests/asn.1/t_trval.c ++++ b/src/tests/asn.1/t_trval.c +@@ -36,7 +36,8 @@ + -DSTANDALONE code. */ + #include "trval.c" + +-static void usage() ++static void ++usage(void) + { + fprintf(stderr, "Usage: trval [--types] [--krb5] [--krb5decode] [--hex] [-notypebytes] [file]\n"); + exit(1); +@@ -46,10 +47,8 @@ static void usage() + * Returns true if the option was selected. Allow "-option" and + * "--option" syntax, since we used to accept only "-option" + */ +-static +-int check_option(word, option) +- char *word; +- char *option; ++static int ++check_option(char *word, char *option) + { + if (word[0] != '-') + return 0; +@@ -60,9 +59,8 @@ int check_option(word, option) + return 1; + } + +-int main(argc, argv) +- int argc; +- char **argv; ++int ++main(int argc, char **argv) + { + int optflg = 1; + FILE *fp; +diff --git a/src/tests/asn.1/trval.c b/src/tests/asn.1/trval.c +index c14bcdeb69..e0e58cc19e 100644 +--- a/src/tests/asn.1/trval.c ++++ b/src/tests/asn.1/trval.c +@@ -120,7 +120,8 @@ int trval2 (FILE *, unsigned char *, int, int, int *); + + /****************************************************************************/ + +-static int convert_nibble(int ch) ++static int ++convert_nibble(int ch) + { + if (isdigit(ch)) + return (ch - '0'); +@@ -131,9 +132,8 @@ static int convert_nibble(int ch) + return -1; + } + +-int trval(fin, fout) +- FILE *fin; +- FILE *fout; ++int ++trval(FILE *fin, FILE *fout) + { + unsigned char *p; + unsigned int maxlen; +@@ -169,12 +169,8 @@ int trval(fin, fout) + return(r); + } + +-int trval2(fp, enc, len, lev, rlen) +- FILE *fp; +- unsigned char *enc; +- int len; +- int lev; +- int *rlen; ++int ++trval2(FILE *fp, unsigned char *enc, int len, int lev, int *rlen) + { + int l, eid, elen, xlen, r, rlen2 = 0; + int rlen_ext = 0; +@@ -248,10 +244,8 @@ context_restart: + return(r); + } + +-int decode_len(fp, enc, len) +- FILE *fp; +- unsigned char *enc; +- int len; ++int ++decode_len(FILE *fp, unsigned char *enc, int len) + { + int rlen; + int i; +@@ -270,12 +264,8 @@ int decode_len(fp, enc, len) + /* + * This is the printing function for bit strings + */ +-int do_prim_bitstring(fp, tag, enc, len, lev) +- FILE *fp; +- int tag; +- unsigned char *enc; +- int len; +- int lev; ++int ++do_prim_bitstring(FILE *fp, int tag, unsigned char *enc, int len, int lev) + { + int i; + long num = 0; +@@ -297,12 +287,8 @@ int do_prim_bitstring(fp, tag, enc, len, lev) + /* + * This is the printing function for integers + */ +-int do_prim_int(fp, tag, enc, len, lev) +- FILE *fp; +- int tag; +- unsigned char *enc; +- int len; +- int lev; ++int ++do_prim_int(FILE *fp, int tag, unsigned char *enc, int len, int lev) + { + int i; + long num = 0; +@@ -327,12 +313,8 @@ int do_prim_int(fp, tag, enc, len, lev) + * This is the printing function which we use if it's a string or + * other other type which is best printed as a string + */ +-int do_prim_string(fp, tag, enc, len, lev) +- FILE *fp; +- int tag; +- unsigned char *enc; +- int len; +- int lev; ++int ++do_prim_string(FILE *fp, int tag, unsigned char *enc, int len, int lev) + { + int i; + +@@ -349,12 +331,8 @@ int do_prim_string(fp, tag, enc, len, lev) + return 1; + } + +-int do_prim(fp, tag, enc, len, lev) +- FILE *fp; +- int tag; +- unsigned char *enc; +- int len; +- int lev; ++int ++do_prim(FILE *fp, int tag, unsigned char *enc, int len, int lev) + { + int n; + int i; +@@ -396,12 +374,8 @@ int do_prim(fp, tag, enc, len, lev) + return(OK); + } + +-int do_cons(fp, enc, len, lev, rlen) +- FILE *fp; +- unsigned char *enc; +- int len; +- int lev; +- int *rlen; ++int ++do_cons(FILE *fp, unsigned char *enc, int len, int lev, int *rlen) + { + int n; + int r = 0; +@@ -430,9 +404,8 @@ struct typestring_table { + int new_appl; + }; + +-static char *lookup_typestring(table, key1, key2) +- struct typestring_table *table; +- int key1, key2; ++static char * ++lookup_typestring(struct typestring_table *table, int key1, int key2) + { + struct typestring_table *ent; + +@@ -700,10 +673,8 @@ struct typestring_table krb5_fields[] = { + }; + #endif + +-void print_tag_type(fp, eid, lev) +- FILE *fp; +- int eid; +- int lev; ++void ++print_tag_type(FILE *fp, int eid, int lev) + { + int tag = eid & ID_TAG; + int do_space = 1; +diff --git a/src/tests/conccache.c b/src/tests/conccache.c +index 7b0ca6300c..9fe5305761 100644 +--- a/src/tests/conccache.c ++++ b/src/tests/conccache.c +@@ -110,7 +110,7 @@ refresh_cache(krb5_context context) + } + + static pid_t +-spawn_cred_subprocess() ++spawn_cred_subprocess(void) + { + krb5_context context; + pid_t pid; +@@ -133,7 +133,7 @@ spawn_cred_subprocess() + } + + static pid_t +-spawn_refresh_subprocess() ++spawn_refresh_subprocess(void) + { + krb5_context context; + pid_t pid; +diff --git a/src/tests/create/kdb5_mkdums.c b/src/tests/create/kdb5_mkdums.c +index 7c0666601c..61ca9f67a2 100644 +--- a/src/tests/create/kdb5_mkdums.c ++++ b/src/tests/create/kdb5_mkdums.c +@@ -56,9 +56,7 @@ struct mblock { + int set_dbname_help (char *, char *); + + static void +-usage(who, status) +- char *who; +- int status; ++usage(char *who, int status) + { + fprintf(stderr, + "usage: %s -p prefix -n num_to_create [-d dbpathname] [-r realmname]\n", +@@ -83,9 +81,7 @@ static krb5_boolean manual_mkey = FALSE; + void add_princ (krb5_context, char *); + + int +-main(argc, argv) +- int argc; +- char *argv[]; ++main(int argc, char *argv[]) + { + extern char *optarg; + int optchar, i, n; +@@ -209,9 +205,7 @@ main(argc, argv) + } + + void +-add_princ(context, str_newprinc) +- krb5_context context; +- char * str_newprinc; ++add_princ(krb5_context context, char *str_newprinc) + { + krb5_error_code retval; + krb5_principal newprinc; +@@ -317,9 +311,7 @@ error: /* Do cleanup of newentry regardless of error */ + } + + int +-set_dbname_help(pname, dbname) +- char *pname; +- char *dbname; ++set_dbname_help(char *pname, char *dbname) + { + krb5_error_code retval; + krb5_data pwd, scratch; +diff --git a/src/tests/forward.c b/src/tests/forward.c +index 7327cc9e62..90f359a586 100644 +--- a/src/tests/forward.c ++++ b/src/tests/forward.c +@@ -51,7 +51,7 @@ check(krb5_error_code code) + } + + int +-main() ++main(void) + { + krb5_ccache cc; + krb5_creds mcred, tgt, *fcred; +diff --git a/src/tests/gss-threads/gss-client.c b/src/tests/gss-threads/gss-client.c +index c0cf25ddaa..8c006c2915 100644 +--- a/src/tests/gss-threads/gss-client.c ++++ b/src/tests/gss-threads/gss-client.c +@@ -68,7 +68,7 @@ + static int verbose = 1; + + static void +-usage() ++usage(void) + { + fprintf(stderr, "Usage: gss-client [-port port] [-mech mechanism] [-d]\n"); + fprintf(stderr, " [-seq] [-noreplay] [-nomutual]"); +@@ -134,7 +134,7 @@ get_server_info(char *host, u_short port) + * displayed and -1 is returned. + */ + static int +-connect_to_server() ++connect_to_server(void) + { + int s; + +diff --git a/src/tests/gss-threads/gss-server.c b/src/tests/gss-threads/gss-server.c +index a9f980edb2..e0a37738e4 100644 +--- a/src/tests/gss-threads/gss-server.c ++++ b/src/tests/gss-threads/gss-server.c +@@ -74,7 +74,7 @@ + #endif + + static void +-usage() ++usage(void) + { + fprintf(stderr, "Usage: gss-server [-port port] [-verbose] [-once]"); + #ifdef _WIN32 +diff --git a/src/tests/gssapi/reload.c b/src/tests/gssapi/reload.c +index 4fe3565406..00bda32330 100644 +--- a/src/tests/gssapi/reload.c ++++ b/src/tests/gssapi/reload.c +@@ -64,7 +64,7 @@ load_gssapi(void) + } + + int +-main() ++main(void) + { + void *support; + +diff --git a/src/tests/gssapi/t_add_cred.c b/src/tests/gssapi/t_add_cred.c +index 68b37e3ed9..7ab52d6449 100644 +--- a/src/tests/gssapi/t_add_cred.c ++++ b/src/tests/gssapi/t_add_cred.c +@@ -43,7 +43,7 @@ + #include "common.h" + + int +-main() ++main(void) + { + OM_uint32 minor, major; + gss_cred_id_t cred1, cred2; +diff --git a/src/tests/gssapi/t_enctypes.c b/src/tests/gssapi/t_enctypes.c +index 3fd31e2f8c..3325db7696 100644 +--- a/src/tests/gssapi/t_enctypes.c ++++ b/src/tests/gssapi/t_enctypes.c +@@ -47,7 +47,7 @@ + */ + + static void +-usage() ++usage(void) + { + errout("Usage: t_enctypes [-i initenctypes] [-a accenctypes] " + "targetname"); +diff --git a/src/tests/gssapi/t_invalid.c b/src/tests/gssapi/t_invalid.c +index 8192935099..a052b8ab6e 100644 +--- a/src/tests/gssapi/t_invalid.c ++++ b/src/tests/gssapi/t_invalid.c +@@ -547,7 +547,7 @@ try_accept(void *value, size_t len) + + /* Accept contexts using superficially valid but truncated encapsulations. */ + static void +-test_short_encapsulation() ++test_short_encapsulation(void) + { + /* Include just the initial application tag, to see if we overrun reading + * the sequence length. */ +diff --git a/src/tests/gssapi/t_oid.c b/src/tests/gssapi/t_oid.c +index 1c9d394167..64253133d2 100644 +--- a/src/tests/gssapi/t_oid.c ++++ b/src/tests/gssapi/t_oid.c +@@ -129,7 +129,7 @@ oid_equal(gss_OID o1, gss_OID o2) + } + + int +-main() ++main(void) + { + size_t i; + OM_uint32 major, minor; +diff --git a/src/tests/gssapi/t_spnego.c b/src/tests/gssapi/t_spnego.c +index 2483228b1b..4091739f83 100644 +--- a/src/tests/gssapi/t_spnego.c ++++ b/src/tests/gssapi/t_spnego.c +@@ -195,7 +195,7 @@ test_mskrb_oid(gss_name_t tname, gss_cred_id_t acred) + /* Check that we return a compatibility NegTokenInit2 message containing + * NegHints for an empty initiator token. */ + static void +-test_neghints() ++test_neghints(void) + { + OM_uint32 major, minor; + gss_buffer_desc itok = GSS_C_EMPTY_BUFFER, atok; +diff --git a/src/tests/hammer/kdc5_hammer.c b/src/tests/hammer/kdc5_hammer.c +index 8220fd97bd..76ef527ccf 100644 +--- a/src/tests/hammer/kdc5_hammer.c ++++ b/src/tests/hammer/kdc5_hammer.c +@@ -68,9 +68,7 @@ int get_tgt + krb5_ccache); + + static void +-usage(who, status) +-char *who; +-int status; ++usage(char *who, int status) + { + fprintf(stderr, + "usage: %s -p prefix -n num_to_check [-c cachename] [-r realmname]\n", +@@ -100,9 +98,7 @@ struct h_timer tgs_req_times = { 0.0, 1000000.0, -1.0, 0 }; + tstart_time.tv_usec))/1000000.0))) + + int +-main(argc, argv) +- int argc; +- char **argv; ++main(int argc, char **argv) + { + krb5_ccache ccache = NULL; + char *cache_name = NULL; /* -f option */ +@@ -271,11 +267,8 @@ main(argc, argv) + + + static krb5_error_code +-get_server_key(context, server, enctype, key) +- krb5_context context; +- krb5_principal server; +- krb5_enctype enctype; +- krb5_keyblock ** key; ++get_server_key(krb5_context context, krb5_principal server, ++ krb5_enctype enctype, krb5_keyblock **key) + { + krb5_error_code retval; + krb5_encrypt_block eblock; +@@ -311,15 +304,10 @@ cleanup_salt: + return retval; + } + +-int verify_cs_pair(context, p_client_str, p_client, service, hostname, +- p_num, c_depth, s_depth, ccache) +- krb5_context context; +- char *p_client_str; +- krb5_principal p_client; +- char * service; +- char * hostname; +- int p_num, c_depth, s_depth; +- krb5_ccache ccache; ++int ++verify_cs_pair(krb5_context context, char *p_client_str, ++ krb5_principal p_client, char *service, char *hostname, ++ int p_num, int c_depth, int s_depth, krb5_ccache ccache) + { + krb5_error_code retval; + krb5_creds creds; +@@ -433,11 +421,9 @@ cleanup: + return retval; + } + +-int get_tgt (context, p_client_str, p_client, ccache) +- krb5_context context; +- char *p_client_str; +- krb5_principal *p_client; +- krb5_ccache ccache; ++int ++get_tgt(krb5_context context, char *p_client_str, krb5_principal *p_client, ++ krb5_ccache ccache) + { + long lifetime = KRB5_DEFAULT_LIFE; /* -l option */ + krb5_error_code code; +diff --git a/src/tests/kdbtest.c b/src/tests/kdbtest.c +index 3f61f3e83b..6459c3390f 100644 +--- a/src/tests/kdbtest.c ++++ b/src/tests/kdbtest.c +@@ -271,7 +271,7 @@ iter_pol_handler(void *data, osa_policy_ent_t pol) + } + + int +-main() ++main(void) + { + krb5_db_entry *ent; + osa_policy_ent_t pol; +diff --git a/src/tests/misc/test_getpw.c b/src/tests/misc/test_getpw.c +index 6031e15035..59ff5d3a5d 100644 +--- a/src/tests/misc/test_getpw.c ++++ b/src/tests/misc/test_getpw.c +@@ -32,7 +32,7 @@ + #include + #include + +-int main() ++int main(void) + { + uid_t my_uid; + struct passwd *pwd, pwx; +diff --git a/src/tests/plugorder.c b/src/tests/plugorder.c +index e1245e4765..a2b7e34eea 100644 +--- a/src/tests/plugorder.c ++++ b/src/tests/plugorder.c +@@ -77,7 +77,7 @@ blt3(krb5_context context, int maj_ver, int min_ver, krb5_plugin_vtable vtable) + } + + int +-main() ++main(void) + { + krb5_plugin_initvt_fn *modules = NULL, *mod; + struct krb5_pwqual_vtable_st vt; +diff --git a/src/tests/shlib/t_loader.c b/src/tests/shlib/t_loader.c +index 29481a7be2..203f023f69 100644 +--- a/src/tests/shlib/t_loader.c ++++ b/src/tests/shlib/t_loader.c +@@ -180,7 +180,7 @@ static void do_close(void *libhandle) + + #endif + +-int main() ++int main(void) + { + void *celib, *k5lib, *gsslib, *celib2; + +diff --git a/src/tests/softpkcs11/main.c b/src/tests/softpkcs11/main.c +index 82b05ff0da..908f926405 100644 +--- a/src/tests/softpkcs11/main.c ++++ b/src/tests/softpkcs11/main.c +@@ -860,7 +860,7 @@ func_not_supported(void) + } + + static char * +-get_rcfilename() ++get_rcfilename(void) + { + struct passwd *pw; + const char *home = NULL; +diff --git a/src/tests/t_inetd.c b/src/tests/t_inetd.c +index d22cf31ffa..3790467c7b 100644 +--- a/src/tests/t_inetd.c ++++ b/src/tests/t_inetd.c +@@ -59,16 +59,15 @@ + + char *progname; + +-static void usage() ++static void ++usage(void) + { + fprintf(stderr, "%s: port program argv0 argv1 ...\n", progname); + exit(1); + } + + int +-main(argc, argv) +- int argc; +- char **argv; ++main(int argc, char **argv) + { + unsigned short port; + char *path; +diff --git a/src/tests/test1.c b/src/tests/test1.c +index aed656ebe3..b213a349bf 100644 +--- a/src/tests/test1.c ++++ b/src/tests/test1.c +@@ -31,7 +31,7 @@ unsigned char key_two[8] = { 0xea, 0x89, 0x57, 0x76, 0x5b, 0xcd, 0x0d, 0x34 }; + + extern void dump_data(); + +-tkt_test_1() ++tkt_test_1(void) + { + krb5_data *data; + krb5_ticket tk_in, *tk_out; +@@ -185,7 +185,7 @@ tkt_test_1() + + + +-main() ++main(void) + { + krb5_init_ets(); + tkt_test_1(); +diff --git a/src/tests/verify/kdb5_verify.c b/src/tests/verify/kdb5_verify.c +index 3b152baed6..d53e92ad45 100644 +--- a/src/tests/verify/kdb5_verify.c ++++ b/src/tests/verify/kdb5_verify.c +@@ -50,9 +50,7 @@ struct mblock { + int set_dbname_help (krb5_context, char *, char *); + + static void +-usage(who, status) +- char *who; +- int status; ++usage(char *who, int status) + { + fprintf(stderr, + "usage: %s -p prefix -n num_to_check [-d dbpathname] [-r realmname]\n", +@@ -78,9 +76,7 @@ static krb5_boolean manual_mkey = FALSE; + int check_princ (krb5_context, char *); + + int +-main(argc, argv) +- int argc; +- char *argv[]; ++main(int argc, char *argv[]) + { + extern char *optarg; + int optchar, i, n; +@@ -221,9 +217,7 @@ main(argc, argv) + } + + int +-check_princ(context, str_princ) +- krb5_context context; +- char * str_princ; ++check_princ(krb5_context context, char *str_princ) + { + krb5_error_code retval; + krb5_db_entry *kdbe = NULL; +@@ -343,10 +337,7 @@ out: + } + + int +-set_dbname_help(context, pname, dbname) +- krb5_context context; +- char *pname; +- char *dbname; ++set_dbname_help(krb5_context context, char *pname, char *dbname) + { + krb5_error_code retval; + krb5_data pwd, scratch; +diff --git a/src/util/et/error_message.c b/src/util/et/error_message.c +index 7dc02a34ea..13ad3af6a2 100644 +--- a/src/util/et/error_message.c ++++ b/src/util/et/error_message.c +@@ -82,7 +82,7 @@ void com_err_terminate(void) + #endif + + static char * +-get_thread_buffer () ++get_thread_buffer(void) + { + char *cp; + cp = k5_getspecific(K5_KEY_COM_ERR); +diff --git a/src/util/et/test_et.c b/src/util/et/test_et.c +index 9faf10f460..2002e5ff46 100644 +--- a/src/util/et/test_et.c ++++ b/src/util/et/test_et.c +@@ -17,7 +17,8 @@ extern const char *error_table_name (errcode_t); + extern int sys_nerr; + #endif + +-int main() ++int ++main(void) + { + printf("Before initiating error table:\n\n"); + #ifndef EXPORT_LIST +diff --git a/src/util/profile/prof_init.c b/src/util/profile/prof_init.c +index cc92248f42..077c852e49 100644 +--- a/src/util/profile/prof_init.c ++++ b/src/util/profile/prof_init.c +@@ -103,7 +103,7 @@ init_load_module(const char *modspec, profile_t *ret_profile) + struct errinfo einfo = { 0 }; + prf_lib_handle_t lib_handle = NULL; + struct plugin_file_handle *plhandle = NULL; +- void *cbdata = NULL, (*fptr)(); ++ void *cbdata = NULL, (*fptr)(void); + int have_lock = 0, have_cbdata = 0; + struct profile_vtable vtable = { 1 }; /* Set minor_ver to 1, rest null. */ + errcode_t err; +diff --git a/src/util/profile/t_profile.c b/src/util/profile/t_profile.c +index b0e715ba02..bffd115618 100644 +--- a/src/util/profile/t_profile.c ++++ b/src/util/profile/t_profile.c +@@ -72,7 +72,7 @@ write_file(const char *name, int nlines, ...) + /* Regression test for #2685 (profile iterator breaks when modifications + * made) */ + static void +-test_iterate() ++test_iterate(void) + { + profile_t p; + void *iter; +@@ -129,7 +129,7 @@ test_iterate() + * global shared profiles list. + */ + static void +-test_shared() ++test_shared(void) + { + profile_t a, b; + struct utimbuf times; +@@ -164,7 +164,7 @@ test_shared() + /* Regression test for #2950 (profile_clear_relation not reflected within + * handle where deletion is performed) */ + static void +-test_clear() ++test_clear(void) + { + profile_t p; + const char *names[] = { "test section 1", "quux", NULL }; +@@ -183,7 +183,7 @@ test_clear() + } + + static void +-test_include() ++test_include(void) + { + profile_t p; + const char *names[] = { "test section 1", "bar", NULL }; +@@ -237,7 +237,7 @@ test_include() + + /* Test syntactic independence of included profile files. */ + static void +-test_independence() ++test_independence(void) + { + profile_t p; + const char *names1[] = { "sec1", "var", "a", NULL }; +@@ -264,7 +264,7 @@ test_independence() + + /* Regression test for #7971 (deleted sections should not be iterable) */ + static void +-test_delete_section() ++test_delete_section(void) + { + profile_t p; + const char *sect[] = { "test section 1", NULL }; +@@ -290,7 +290,7 @@ test_delete_section() + /* Regression test for #7971 (profile_clear_relation() error with deleted node + * at end of value set) */ + static void +-test_delete_clear_relation() ++test_delete_clear_relation(void) + { + profile_t p; + const char *names[] = { "test section 1", "testkey", NULL }; +@@ -305,7 +305,7 @@ test_delete_clear_relation() + + /* Test that order of relations is preserved if some relations are deleted. */ + static void +-test_delete_ordering() ++test_delete_ordering(void) + { + profile_t p; + const char *names[] = { "test section 1", "testkey", NULL }; +@@ -329,7 +329,7 @@ test_delete_ordering() + /* Regression test for #8431 (profile_flush_to_file erroneously changes flag + * state on source object) */ + static void +-test_flush_to_file() ++test_flush_to_file(void) + { + profile_t p; + +@@ -349,7 +349,7 @@ test_flush_to_file() + /* Regression test for #7863 (multiply-specified subsections should + * be merged) */ + static void +-test_merge_subsections() ++test_merge_subsections(void) + { + profile_t p; + const char *n1[] = { "test section 2", "child_section2", "child", NULL }; +@@ -374,7 +374,7 @@ test_merge_subsections() + } + + int +-main() ++main(void) + { + test_iterate(); + test_shared(); +diff --git a/src/util/profile/test_load.c b/src/util/profile/test_load.c +index cb870eff93..fe2d1e3e72 100644 +--- a/src/util/profile/test_load.c ++++ b/src/util/profile/test_load.c +@@ -29,7 +29,7 @@ + #include "prof_int.h" + + int +-main() ++main(void) + { + profile_t pr, pr2; + const char *files[] = { "./modtest.conf", NULL }; +diff --git a/src/util/profile/test_parse.c b/src/util/profile/test_parse.c +index 9f2631e949..0532254e8c 100644 +--- a/src/util/profile/test_parse.c ++++ b/src/util/profile/test_parse.c +@@ -11,9 +11,8 @@ + + void dump_profile (struct profile_node *root, int level); + +-int main(argc, argv) +- int argc; +- char **argv; ++int ++main(int argc, char **argv) + { + struct profile_node *root; + unsigned long retval; +diff --git a/src/util/profile/test_profile.c b/src/util/profile/test_profile.c +index 6f6fcc7ac5..31b1063951 100644 +--- a/src/util/profile/test_profile.c ++++ b/src/util/profile/test_profile.c +@@ -19,8 +19,8 @@ const char *program_name = "test_profile"; + #define PRINT_VALUE 1 + #define PRINT_VALUES 2 + +-static void do_batchmode(profile) +- profile_t profile; ++static void ++do_batchmode(profile_t profile) + { + errcode_t retval; + int argc, ret; +@@ -108,10 +108,8 @@ static void do_batchmode(profile) + + } + +- +-int main(argc, argv) +- int argc; +- char **argv; ++int ++main(int argc, char **argv) + { + profile_t profile; + long retval; +diff --git a/src/util/profile/test_vtable.c b/src/util/profile/test_vtable.c +index 9a0b2278a7..a7b6f54ae9 100644 +--- a/src/util/profile/test_vtable.c ++++ b/src/util/profile/test_vtable.c +@@ -232,7 +232,8 @@ struct profile_vtable full_vtable = { + full_flush + }; + +-int main() ++int ++main(void) + { + profile_t profile; + char **values, *str, *name, *value; +diff --git a/src/util/ss/error.c b/src/util/ss/error.c +index b5768a62b7..e5cd1b2d12 100644 +--- a/src/util/ss/error.c ++++ b/src/util/ss/error.c +@@ -33,8 +33,8 @@ + #include "com_err.h" + #include "copyright.h" + +-char * ss_name(sci_idx) +- int sci_idx; ++char * ++ss_name(int sci_idx) + { + ss_data *infop; + +@@ -50,7 +50,8 @@ char * ss_name(sci_idx) + } + } + +-void ss_error (int sci_idx, long code, const char * fmt, ...) ++void ++ss_error(int sci_idx, long code, const char *fmt, ...) + { + char *whoami; + va_list pvar; +@@ -61,10 +62,8 @@ void ss_error (int sci_idx, long code, const char * fmt, ...) + va_end(pvar); + } + +-void ss_perror (sci_idx, code, msg) /* for compatibility */ +- int sci_idx; +- long code; +- char const *msg; ++void ++ss_perror(int sci_idx, long code, char const *msg) /* for compatibility */ + { + ss_error (sci_idx, code, "%s", msg); + } +diff --git a/src/util/ss/execute_cmd.c b/src/util/ss/execute_cmd.c +index c06ee56547..065c24148b 100644 +--- a/src/util/ss/execute_cmd.c ++++ b/src/util/ss/execute_cmd.c +@@ -52,11 +52,9 @@ + * Notes: + */ + +-static int check_request_table (rqtbl, argc, argv, sci_idx) +- ss_request_table *rqtbl; +- int argc; +- char *argv[]; +- int sci_idx; ++static int ++check_request_table(ss_request_table *rqtbl, int argc, char *argv[], ++ int sci_idx) + { + ss_request_entry *request; + ss_data *info; +@@ -101,10 +99,8 @@ static int check_request_table (rqtbl, argc, argv, sci_idx) + * Notes: + */ + +-static int really_execute_command (sci_idx, argc, argv) +- int sci_idx; +- int argc; +- char **argv[]; ++static int ++really_execute_command(int sci_idx, int argc, char **argv[]) + { + ss_request_table **rqtbl; + ss_data *info; +@@ -135,9 +131,7 @@ static int really_execute_command (sci_idx, argc, argv) + */ + + int +-ss_execute_command(sci_idx, argv) +- int sci_idx; +- char *argv[]; ++ss_execute_command(int sci_idx, char *argv[]) + { + unsigned int i, argc; + char **argp; +@@ -172,9 +166,8 @@ ss_execute_command(sci_idx, argv) + * Notes: + */ + +-int ss_execute_line (sci_idx, line_ptr) +- int sci_idx; +- char *line_ptr; ++int ++ss_execute_line(int sci_idx, char *line_ptr) + { + char **argv; + int argc, ret; +diff --git a/src/util/ss/help.c b/src/util/ss/help.c +index 6d333c9710..747fde5351 100644 +--- a/src/util/ss/help.c ++++ b/src/util/ss/help.c +@@ -15,11 +15,8 @@ + #include "copyright.h" + + +-void ss_help (argc, argv, sci_idx, info_ptr) +- int argc; +- char const * const *argv; +- int sci_idx; +- pointer info_ptr; ++void ++ss_help(int argc, char const * const *argv, int sci_idx, pointer info_ptr) + { + char buffer[MAXPATHLEN]; + char const *request_name; +@@ -81,15 +78,11 @@ got_it: + ss_page_stdin(); + default: + (void) close(fd); /* what can we do if it fails? */ +-#ifdef WAIT_USES_INT +- while (wait((int *)NULL) != child) { +-#else +- while (wait((union wait *)NULL) != child) { +-#endif +- /* do nothing if wrong pid */ +- }; +- } ++ while (wait(NULL) != child) { ++ /* do nothing if wrong pid */ ++ }; + } ++} + + #ifndef USE_DIRENT_H + #include +@@ -97,60 +90,56 @@ got_it: + #include + #endif + +- void ss_add_info_dir(sci_idx, info_dir, code_ptr) +- int sci_idx; +- char *info_dir; +- int *code_ptr; +- { +- ss_data *info; +- DIR *d; +- int n_dirs; +- char **dirs; ++void ++ss_add_info_dir(int sci_idx, char *info_dir, int *code_ptr) ++{ ++ ss_data *info; ++ DIR *d; ++ int n_dirs; ++ char **dirs; + +- info = ss_info(sci_idx); +- if ((info_dir == NULL) || (*info_dir == '\0')) { +- *code_ptr = SS_ET_NO_INFO_DIR; +- return; +- } +- if ((d = opendir(info_dir)) == (DIR *)NULL) { +- *code_ptr = errno; +- return; +- } +- closedir(d); +- dirs = info->info_dirs; +- for (n_dirs = 0; dirs[n_dirs] != (char *)NULL; n_dirs++) +- ; /* get number of non-NULL dir entries */ +- dirs = (char **)realloc((char *)dirs, +- (unsigned)(n_dirs + 2)*sizeof(char *)); +- if (dirs == (char **)NULL) { +- info->info_dirs = (char **)NULL; +- *code_ptr = errno; +- return; +- } +- info->info_dirs = dirs; +- dirs[n_dirs + 1] = (char *)NULL; +- dirs[n_dirs] = strdup(info_dir); +- *code_ptr = 0; ++ info = ss_info(sci_idx); ++ if ((info_dir == NULL) || (*info_dir == '\0')) { ++ *code_ptr = SS_ET_NO_INFO_DIR; ++ return; ++ } ++ if ((d = opendir(info_dir)) == (DIR *)NULL) { ++ *code_ptr = errno; ++ return; + } ++ closedir(d); ++ dirs = info->info_dirs; ++ for (n_dirs = 0; dirs[n_dirs] != (char *)NULL; n_dirs++) ++ ; /* get number of non-NULL dir entries */ ++ dirs = (char **)realloc((char *)dirs, ++ (unsigned)(n_dirs + 2)*sizeof(char *)); ++ if (dirs == (char **)NULL) { ++ info->info_dirs = (char **)NULL; ++ *code_ptr = errno; ++ return; ++ } ++ info->info_dirs = dirs; ++ dirs[n_dirs + 1] = (char *)NULL; ++ dirs[n_dirs] = strdup(info_dir); ++ *code_ptr = 0; ++} + +- void ss_delete_info_dir(sci_idx, info_dir, code_ptr) +- int sci_idx; +- char *info_dir; +- int *code_ptr; +- { +- char **i_d; +- char **info_dirs; ++void ++ss_delete_info_dir(int sci_idx, char *info_dir, int *code_ptr) ++{ ++ char **i_d; ++ char **info_dirs; + +- info_dirs = ss_info(sci_idx)->info_dirs; +- for (i_d = info_dirs; *i_d; i_d++) { +- if (!strcmp(*i_d, info_dir)) { +- while (*i_d) { +- *i_d = *(i_d+1); +- i_d++; +- } +- *code_ptr = 0; +- return; ++ info_dirs = ss_info(sci_idx)->info_dirs; ++ for (i_d = info_dirs; *i_d; i_d++) { ++ if (!strcmp(*i_d, info_dir)) { ++ while (*i_d) { ++ *i_d = *(i_d+1); ++ i_d++; + } ++ *code_ptr = 0; ++ return; + } +- *code_ptr = SS_ET_NO_INFO_DIR; + } ++ *code_ptr = SS_ET_NO_INFO_DIR; ++} +diff --git a/src/util/ss/invocation.c b/src/util/ss/invocation.c +index 378bc3e927..7736c957d4 100644 +--- a/src/util/ss/invocation.c ++++ b/src/util/ss/invocation.c +@@ -36,12 +36,10 @@ + _ss_table[sci_idx], make sure you change the allocation routine to + not assume there are no null pointers in the middle of the + array. */ +-int ss_create_invocation(subsystem_name, version_string, info_ptr, +- request_table_ptr, code_ptr) +- char *subsystem_name, *version_string; +- char *info_ptr; +- ss_request_table *request_table_ptr; +- int *code_ptr; ++int ++ss_create_invocation(char *subsystem_name, char *version_string, ++ char *info_ptr, ss_request_table *request_table_ptr, ++ int *code_ptr) + { + int sci_idx; + ss_data *new_table; +@@ -115,8 +113,7 @@ int ss_create_invocation(subsystem_name, version_string, info_ptr, + } + + void +-ss_delete_invocation(sci_idx) +- int sci_idx; ++ss_delete_invocation(int sci_idx) + { + ss_data *t; + int ignored_code; +diff --git a/src/util/ss/list_rqs.c b/src/util/ss/list_rqs.c +index c0882bf908..8376e21be8 100644 +--- a/src/util/ss/list_rqs.c ++++ b/src/util/ss/list_rqs.c +@@ -21,15 +21,8 @@ static char const twentyfive_spaces[26] = + static char const NL[2] = "\n"; + + void +-ss_list_requests(argc, argv, sci_idx, info_ptr) +- int argc; +- const char * const *argv; +- int sci_idx; +-#ifdef __STDC__ +- void *info_ptr; +-#else +- char *info_ptr; +-#endif ++ss_list_requests(int argc, const char * const *argv, int sci_idx, ++ void *info_ptr) + { + ss_request_entry *entry; + char const *const *name; +diff --git a/src/util/ss/listen.c b/src/util/ss/listen.c +index fe18475447..79f258fbc4 100644 +--- a/src/util/ss/listen.c ++++ b/src/util/ss/listen.c +@@ -28,7 +28,8 @@ static jmp_buf listen_jmpb; + + #ifdef NO_READLINE + /* Dumb replacement for readline when we don't have support for a real one. */ +-static char *readline(const char *prompt) ++static char * ++readline(const char *prompt) + { + struct termios termbuf; + char input[BUFSIZ]; +@@ -49,20 +50,21 @@ static char *readline(const char *prompt) + } + + /* No-op replacement for add_history() when we have no readline support. */ +-static void add_history(const char *line) ++static void ++add_history(const char *line) + { + } + #endif + +-static void listen_int_handler(signo) +- int signo; ++static void ++listen_int_handler(int signo) + { + putc('\n', stdout); + longjmp(listen_jmpb, 1); + } + +-int ss_listen (sci_idx) +- int sci_idx; ++int ++ss_listen(int sci_idx) + { + char *cp; + ss_data *info; +@@ -83,12 +85,12 @@ int ss_listen (sci_idx) + info->abort = 0; + + #ifdef POSIX_SIGNALS +- csig.sa_handler = (void (*)())0; ++ csig.sa_handler = (void (*)(int))0; + sigemptyset(&nmask); + sigaddset(&nmask, SIGINT); + sigprocmask(SIG_BLOCK, &nmask, &omask); + #else +- sig_cont = (void (*)())0; ++ sig_cont = (void (*)(int))0; + mask = sigblock(sigmask(SIGINT)); + #endif + +@@ -115,7 +117,7 @@ int ss_listen (sci_idx) + nsig.sa_handler = listen_int_handler; /* fgets is not signal-safe */ + osig = csig; + sigaction(SIGCONT, &nsig, &csig); +- if ((void (*)())csig.sa_handler==(void (*)())listen_int_handler) ++ if ((void (*)(int))csig.sa_handler==(void (*)(int))listen_int_handler) + csig = osig; + #else + old_sig_cont = sig_cont; +@@ -166,20 +168,16 @@ egress: + return code; + } + +-void ss_abort_subsystem(sci_idx, code) +- int sci_idx; +- int code; ++void ++ss_abort_subsystem(int sci_idx, int code) + { + ss_info(sci_idx)->abort = 1; + ss_info(sci_idx)->exit_status = code; + + } + +-void ss_quit(argc, argv, sci_idx, infop) +- int argc; +- char const * const *argv; +- int sci_idx; +- pointer infop; ++void ++ss_quit(int argc, char const * const *argv, int sci_idx, pointer infop) + { + ss_abort_subsystem(sci_idx, 0); + } +diff --git a/src/util/ss/pager.c b/src/util/ss/pager.c +index 3e47ed3993..255c721ad1 100644 +--- a/src/util/ss/pager.c ++++ b/src/util/ss/pager.c +@@ -10,13 +10,13 @@ + #include "copyright.h" + #include + #include ++#include + #include + #include + #include + + static char MORE[] = "more"; + extern char *_ss_pager_name; +-extern char *getenv(); + + /* + * this needs a *lot* of work.... +@@ -25,10 +25,10 @@ extern char *getenv(); + * handle SIGINT sensibly + * allow finer control -- put-page-break-here + */ +-void ss_page_stdin(); ++void ss_page_stdin(void); + + #ifndef NO_FORK +-int ss_pager_create() ++int ss_pager_create(void) + { + int filedes[2]; + +@@ -56,7 +56,7 @@ int ss_pager_create() + } + } + #else /* don't fork */ +-int ss_pager_create() ++int ss_pager_create(void) + { + int fd; + fd = open("/dev/tty", O_WRONLY, 0); +@@ -66,7 +66,7 @@ int ss_pager_create() + } + #endif + +-void ss_page_stdin() ++void ss_page_stdin(void) + { + int i; + #ifdef POSIX_SIGNALS +diff --git a/src/util/ss/parse.c b/src/util/ss/parse.c +index 78a831bf36..6fb031cdcd 100644 +--- a/src/util/ss/parse.c ++++ b/src/util/ss/parse.c +@@ -53,10 +53,8 @@ enum parse_mode { WHITESPACE, TOKEN, QUOTED_STRING }; + #define NEW_ARGV(old,n) (char **)realloc((char *)old, \ + (unsigned)(n+2)*sizeof(char*)) + +-char **ss_parse (sci_idx, line_ptr, argc_ptr) +- int sci_idx; +- char *line_ptr; +- int *argc_ptr; ++char ** ++ss_parse(int sci_idx, char *line_ptr, int *argc_ptr) + { + char **argv, *cp; + char **newargv; +diff --git a/src/util/ss/prompt.c b/src/util/ss/prompt.c +index 5aa2ad6140..48e57d6702 100644 +--- a/src/util/ss/prompt.c ++++ b/src/util/ss/prompt.c +@@ -11,16 +11,13 @@ + #include "ss_internal.h" + + void +-ss_set_prompt(sci_idx, new_prompt) +- int sci_idx; +- char *new_prompt; ++ss_set_prompt(int sci_idx, char *new_prompt) + { + ss_info(sci_idx)->prompt = new_prompt; + } + + char * +-ss_get_prompt(sci_idx) +- int sci_idx; ++ss_get_prompt(int sci_idx) + { + return(ss_info(sci_idx)->prompt); + } +diff --git a/src/util/ss/request_tbl.c b/src/util/ss/request_tbl.c +index 03cde1b7d0..fc4461bb00 100644 +--- a/src/util/ss/request_tbl.c ++++ b/src/util/ss/request_tbl.c +@@ -11,11 +11,7 @@ + #define ssrt ss_request_table /* for some readable code... */ + + void +-ss_add_request_table(sci_idx, rqtbl_ptr, position, code_ptr) +- int sci_idx; +- ssrt *rqtbl_ptr; +- int position; /* 1 -> becomes second... */ +- int *code_ptr; ++ss_add_request_table(int sci_idx, ssrt *rqtbl_ptr, int position, int *code_ptr) + { + ss_data *info; + int i, size; +@@ -44,10 +40,7 @@ ss_add_request_table(sci_idx, rqtbl_ptr, position, code_ptr) + } + + void +-ss_delete_request_table(sci_idx, rqtbl_ptr, code_ptr) +- int sci_idx; +- ssrt *rqtbl_ptr; +- int *code_ptr; ++ss_delete_request_table(int sci_idx, ssrt *rqtbl_ptr, int *code_ptr) + { + ss_data *info; + ssrt **rt1, **rt2; +diff --git a/src/util/ss/requests.c b/src/util/ss/requests.c +index aa6752fa11..651f2201d2 100644 +--- a/src/util/ss/requests.c ++++ b/src/util/ss/requests.c +@@ -9,7 +9,7 @@ + #include + #include "ss_internal.h" + +-#define DECLARE(name) void name(argc,argv,sci_idx,info_ptr)int argc,sci_idx;const char * const *argv; pointer info_ptr; ++#define DECLARE(name) void name(int argc, const char *const *argv, int sci_idx, pointer info_ptr) + + /* + * ss_self_identify -- assigned by default to the "." request +diff --git a/src/util/ss/ss.h b/src/util/ss/ss.h +index 38d8974e3c..faac0d97c1 100644 +--- a/src/util/ss/ss.h ++++ b/src/util/ss/ss.h +@@ -48,7 +48,6 @@ typedef struct _ss_rp_options { /* DEFAULT VALUES */ + void ss_help __SS_PROTO; + void ss_list_requests __SS_PROTO; + void ss_quit __SS_PROTO; +-char *ss_current_request(); + char *ss_name(int); + void ss_error (int, long, char const *, ...) + #if !defined(__cplusplus) && (__GNUC__ > 2) +diff --git a/src/util/ss/ss_internal.h b/src/util/ss/ss_internal.h +index 1f5ddfff91..cdd88af218 100644 +--- a/src/util/ss/ss_internal.h ++++ b/src/util/ss/ss_internal.h +@@ -84,8 +84,7 @@ typedef struct _ss_data { /* init values */ + #define ss_info(sci_idx) (_ss_table[sci_idx]) + #define ss_current_request(sci_idx,code_ptr) \ + (*code_ptr=0,ss_info(sci_idx)->current_request) +-void ss_unknown_function(); +-void ss_delete_info_dir(); ++void ss_delete_info_dir(int, char *, int *); + char **ss_parse (int, char *, int *); + ss_abbrev_info *ss_abbrev_initialize (char *, int *); + void ss_page_stdin (void); +diff --git a/src/util/support/plugins.c b/src/util/support/plugins.c +index 0850565687..253b118dcb 100644 +--- a/src/util/support/plugins.c ++++ b/src/util/support/plugins.c +@@ -240,13 +240,13 @@ krb5int_get_plugin_data(struct plugin_file_handle *h, const char *csymname, + + long KRB5_CALLCONV + krb5int_get_plugin_func(struct plugin_file_handle *h, const char *csymname, +- void (**sym_out)(), struct errinfo *ep) ++ void (**sym_out)(void), struct errinfo *ep) + { + void *dptr = NULL; + long ret = get_sym(h, csymname, &dptr, ep); + + if (!ret) +- *sym_out = (void (*)())dptr; ++ *sym_out = (void (*)(void))dptr; + return ret; + } + +@@ -552,7 +552,7 @@ krb5int_get_plugin_dir_func (struct plugin_dir_handle *dirhandle, + struct errinfo *ep) + { + long err = 0; +- void (**p)() = NULL; ++ void (**p)(void) = NULL; + size_t count = 0; + + /* XXX Do we need to add a leading "_" to the symbol name on any +@@ -569,10 +569,10 @@ krb5int_get_plugin_dir_func (struct plugin_dir_handle *dirhandle, + int i = 0; + + for (i = 0; !err && (dirhandle->files[i] != NULL); i++) { +- void (*sym)() = NULL; ++ void (*sym)(void) = NULL; + + if (krb5int_get_plugin_func (dirhandle->files[i], symname, &sym, ep) == 0) { +- void (**newp)() = NULL; ++ void (**newp)(void) = NULL; + + count++; + newp = realloc (p, ((count + 1) * sizeof (*p))); /* +1 for NULL */ +diff --git a/src/util/support/t_hashtab.c b/src/util/support/t_hashtab.c +index f51abc4f19..d90d5d9d02 100644 +--- a/src/util/support/t_hashtab.c ++++ b/src/util/support/t_hashtab.c +@@ -104,7 +104,7 @@ const uint64_t vectors[64] = { + }; + + static void +-test_siphash() ++test_siphash(void) + { + uint8_t seq[64]; + uint64_t k0, k1, hval; +@@ -122,7 +122,7 @@ test_siphash() + } + + static void +-test_hashtab() ++test_hashtab(void) + { + int st; + struct k5_hashtab *ht; +@@ -168,7 +168,7 @@ test_hashtab() + } + + int +-main() ++main(void) + { + test_siphash(); + test_hashtab(); +diff --git a/src/util/support/t_hex.c b/src/util/support/t_hex.c +index a586a1bc89..40e6aa2327 100644 +--- a/src/util/support/t_hex.c ++++ b/src/util/support/t_hex.c +@@ -137,7 +137,8 @@ struct { + { "F8F9FAFBFCFDFEFF", "\xF8\xF9\xFA\xFB\xFC\xFD\xFE\xFF", 8, 1 }, + }; + +-int main() ++int ++main(void) + { + size_t i; + char *hex; +diff --git a/src/util/support/t_json.c b/src/util/support/t_json.c +index 1f229247b4..bacca6f8da 100644 +--- a/src/util/support/t_json.c ++++ b/src/util/support/t_json.c +@@ -86,7 +86,7 @@ check(int pred, const char *str) + } + + static void +-test_array() ++test_array(void) + { + k5_json_string v1; + k5_json_number v2; +diff --git a/src/util/support/t_k5buf.c b/src/util/support/t_k5buf.c +index 734b2720c0..18e7e9b7be 100644 +--- a/src/util/support/t_k5buf.c ++++ b/src/util/support/t_k5buf.c +@@ -54,7 +54,7 @@ check_buf(struct k5buf *buf, const char *name) + } + + static void +-test_basic() ++test_basic(void) + { + struct k5buf buf; + char storage[1024]; +@@ -76,7 +76,7 @@ test_basic() + } + + static void +-test_realloc() ++test_realloc(void) + { + struct k5buf buf; + char data[1024]; +@@ -132,7 +132,7 @@ test_realloc() + } + + static void +-test_overflow() ++test_overflow(void) + { + struct k5buf buf; + char storage[10]; +@@ -153,7 +153,7 @@ test_overflow() + } + + static void +-test_error() ++test_error(void) + { + struct k5buf buf; + char storage[1]; +@@ -173,7 +173,7 @@ test_error() + } + + static void +-test_truncate() ++test_truncate(void) + { + struct k5buf buf; + +@@ -188,7 +188,7 @@ test_truncate() + } + + static void +-test_binary() ++test_binary(void) + { + struct k5buf buf; + char data[] = { 'a', 0, 'b' }, *s; +@@ -205,7 +205,7 @@ test_binary() + } + + static void +-test_fmt() ++test_fmt(void) + { + struct k5buf buf; + char storage[10], data[1024]; +@@ -246,7 +246,7 @@ test_fmt() + } + + int +-main() ++main(void) + { + test_basic(); + test_realloc(); +diff --git a/src/util/support/t_unal.c b/src/util/support/t_unal.c +index f67cd31edf..6d097f0f83 100644 +--- a/src/util/support/t_unal.c ++++ b/src/util/support/t_unal.c +@@ -2,7 +2,8 @@ + #undef NDEBUG + #include "k5-platform.h" + +-int main () ++int ++main(void) + { + /* Test some low-level assumptions the Kerberos code depends + on. */ +-- +2.45.1 + diff --git a/0017-Fix-two-unlikely-memory-leaks.patch b/0017-Fix-two-unlikely-memory-leaks.patch new file mode 100644 index 0000000..09fedb7 --- /dev/null +++ b/0017-Fix-two-unlikely-memory-leaks.patch @@ -0,0 +1,206 @@ +From ee66c1feedb57ce06ce51aaa823f9a61f564c58e Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Tue, 5 Mar 2024 19:53:07 -0500 +Subject: [PATCH] Fix two unlikely memory leaks + +In gss_krb5int_make_seal_token_v3(), one of the bounds checks (which +could probably never be triggered) leaks plain.data. Fix this leak +and use current practices for cleanup throughout the function. + +In xmt_rmtcallres() (unused within the tree and likely elsewhere), +store port_ptr into crp->port_ptr as soon as it is allocated; +otherwise it could leak if the subsequent xdr_u_int32() operation +fails. + +(cherry picked from commit c5f9c816107f70139de11b38aa02db2f1774ee0d) +--- + src/lib/gssapi/krb5/k5sealv3.c | 56 +++++++++++++++------------------- + src/lib/rpc/pmap_rmt.c | 10 +++--- + 2 files changed, 29 insertions(+), 37 deletions(-) + +diff --git a/src/lib/gssapi/krb5/k5sealv3.c b/src/lib/gssapi/krb5/k5sealv3.c +index 1fcbdfbb87..d3210c1107 100644 +--- a/src/lib/gssapi/krb5/k5sealv3.c ++++ b/src/lib/gssapi/krb5/k5sealv3.c +@@ -65,7 +65,7 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + int conf_req_flag, int toktype) + { + size_t bufsize = 16; +- unsigned char *outbuf = 0; ++ unsigned char *outbuf = NULL; + krb5_error_code err; + int key_usage; + unsigned char acceptor_flag; +@@ -75,9 +75,13 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + #endif + size_t ec; + unsigned short tok_id; +- krb5_checksum sum; ++ krb5_checksum sum = { 0 }; + krb5_key key; + krb5_cksumtype cksumtype; ++ krb5_data plain = empty_data(); ++ ++ token->value = NULL; ++ token->length = 0; + + acceptor_flag = ctx->initiate ? 0 : FLAG_SENDER_IS_ACCEPTOR; + key_usage = (toktype == KG_TOK_WRAP_MSG +@@ -107,14 +111,15 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + #endif + + if (toktype == KG_TOK_WRAP_MSG && conf_req_flag) { +- krb5_data plain; + krb5_enc_data cipher; + size_t ec_max; + size_t encrypt_size; + + /* 300: Adds some slop. */ +- if (SIZE_MAX - 300 < message->length) +- return ENOMEM; ++ if (SIZE_MAX - 300 < message->length) { ++ err = ENOMEM; ++ goto cleanup; ++ } + ec_max = SIZE_MAX - message->length - 300; + if (ec_max > 0xffff) + ec_max = 0xffff; +@@ -126,20 +131,20 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + #endif + err = alloc_data(&plain, message->length + 16 + ec); + if (err) +- return err; ++ goto cleanup; + + /* Get size of ciphertext. */ + encrypt_size = krb5_encrypt_size(plain.length, key->keyblock.enctype); + if (encrypt_size > SIZE_MAX / 2) { + err = ENOMEM; +- goto error; ++ goto cleanup; + } + bufsize = 16 + encrypt_size; + /* Allocate space for header plus encrypted data. */ + outbuf = gssalloc_malloc(bufsize); + if (outbuf == NULL) { +- free(plain.data); +- return ENOMEM; ++ err = ENOMEM; ++ goto cleanup; + } + + /* TOK_ID */ +@@ -164,11 +169,8 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + cipher.ciphertext.length = bufsize - 16; + cipher.enctype = key->keyblock.enctype; + err = krb5_k_encrypt(context, key, key_usage, 0, &plain, &cipher); +- zap(plain.data, plain.length); +- free(plain.data); +- plain.data = 0; + if (err) +- goto error; ++ goto cleanup; + + /* Now that we know we're returning a valid token.... */ + ctx->seq_send++; +@@ -181,7 +183,6 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + /* If the rotate fails, don't worry about it. */ + #endif + } else if (toktype == KG_TOK_WRAP_MSG && !conf_req_flag) { +- krb5_data plain; + size_t cksumsize; + + /* Here, message is the application-supplied data; message2 is +@@ -193,21 +194,19 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + wrap_with_checksum: + err = alloc_data(&plain, message->length + 16); + if (err) +- return err; ++ goto cleanup; + + err = krb5_c_checksum_length(context, cksumtype, &cksumsize); + if (err) +- goto error; ++ goto cleanup; + + assert(cksumsize <= 0xffff); + + bufsize = 16 + message2->length + cksumsize; + outbuf = gssalloc_malloc(bufsize); + if (outbuf == NULL) { +- free(plain.data); +- plain.data = 0; + err = ENOMEM; +- goto error; ++ goto cleanup; + } + + /* TOK_ID */ +@@ -239,23 +238,15 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + if (message2->length) + memcpy(outbuf + 16, message2->value, message2->length); + +- sum.contents = outbuf + 16 + message2->length; +- sum.length = cksumsize; +- + err = krb5_k_make_checksum(context, cksumtype, key, + key_usage, &plain, &sum); +- zap(plain.data, plain.length); +- free(plain.data); +- plain.data = 0; + if (err) { + zap(outbuf,bufsize); +- goto error; ++ goto cleanup; + } + if (sum.length != cksumsize) + abort(); + memcpy(outbuf + 16 + message2->length, sum.contents, cksumsize); +- krb5_free_checksum_contents(context, &sum); +- sum.contents = 0; + /* Now that we know we're actually generating the token... */ + ctx->seq_send++; + +@@ -285,12 +276,13 @@ gss_krb5int_make_seal_token_v3 (krb5_context context, + + token->value = outbuf; + token->length = bufsize; +- return 0; ++ outbuf = NULL; ++ err = 0; + +-error: ++cleanup: ++ krb5_free_checksum_contents(context, &sum); ++ zapfree(plain.data, plain.length); + gssalloc_free(outbuf); +- token->value = NULL; +- token->length = 0; + return err; + } + +diff --git a/src/lib/rpc/pmap_rmt.c b/src/lib/rpc/pmap_rmt.c +index 434e4eea65..f55ca46c60 100644 +--- a/src/lib/rpc/pmap_rmt.c ++++ b/src/lib/rpc/pmap_rmt.c +@@ -161,12 +161,12 @@ xdr_rmtcallres( + caddr_t port_ptr; + + port_ptr = (caddr_t)(void *)crp->port_ptr; +- if (xdr_reference(xdrs, &port_ptr, sizeof (uint32_t), +- (xdrproc_t)xdr_u_int32) && +- xdr_u_int32(xdrs, &crp->resultslen)) { +- crp->port_ptr = (uint32_t *)(void *)port_ptr; ++ if (!xdr_reference(xdrs, &port_ptr, sizeof (uint32_t), ++ (xdrproc_t)xdr_u_int32)) ++ return (FALSE); ++ crp->port_ptr = (uint32_t *)(void *)port_ptr; ++ if (xdr_u_int32(xdrs, &crp->resultslen)) + return ((*(crp->xdr_results))(xdrs, crp->results_ptr)); +- } + return (FALSE); + } + +-- +2.45.1 + diff --git a/0016-Fix-unimportant-memory-leaks.patch b/0018-Fix-unimportant-memory-leaks.patch similarity index 90% rename from 0016-Fix-unimportant-memory-leaks.patch rename to 0018-Fix-unimportant-memory-leaks.patch index 3406316..0697f06 100644 --- a/0016-Fix-unimportant-memory-leaks.patch +++ b/0018-Fix-unimportant-memory-leaks.patch @@ -1,4 +1,4 @@ -From f0414954d79283075d1f627dbb9fe6e4f43c1aae Mon Sep 17 00:00:00 2001 +From c8d8cab52172a934bdad1041448b43bc15acf441 Mon Sep 17 00:00:00 2001 From: Steve Grubb Date: Thu, 13 Jul 2023 16:22:30 -0400 Subject: [PATCH] Fix unimportant memory leaks @@ -16,10 +16,10 @@ some unused ksu functions; rewrote commit message] src/appl/gss-sample/gss-client.c | 367 ++++++++---------- src/appl/gss-sample/gss-server.c | 3 +- src/clients/klist/klist.c | 59 +-- - src/clients/ksu/authorization.c | 140 +++---- - src/clients/ksu/ccache.c | 289 +++++--------- + src/clients/ksu/authorization.c | 134 +++---- + src/clients/ksu/ccache.c | 283 +++++--------- src/clients/ksu/heuristic.c | 128 +++--- - src/clients/ksu/krb_auth_su.c | 137 ++----- + src/clients/ksu/krb_auth_su.c | 134 ++----- src/clients/ksu/ksu.h | 6 - src/clients/ksu/main.c | 3 +- src/kadmin/cli/keytab.c | 6 +- @@ -32,10 +32,10 @@ some unused ksu functions; rewrote commit message] src/lib/krb5/ccache/ccfns.c | 12 +- src/lib/krb5/keytab/kt_file.c | 3 +- src/plugins/kdb/ldap/libkdb_ldap/ldap_realm.c | 8 +- - 19 files changed, 520 insertions(+), 684 deletions(-) + 19 files changed, 517 insertions(+), 672 deletions(-) diff --git a/src/appl/gss-sample/gss-client.c b/src/appl/gss-sample/gss-client.c -index 6e2aa33690..cf94623d63 100644 +index 0722ae196f..2cfcfc6cc5 100644 --- a/src/appl/gss-sample/gss-client.c +++ b/src/appl/gss-sample/gss-client.c @@ -182,180 +182,148 @@ client_establish_context(int s, char *service_name, OM_uint32 gss_flags, @@ -345,7 +345,7 @@ index 6e2aa33690..cf94623d63 100644 } static void -@@ -449,11 +417,11 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, +@@ -436,11 +404,11 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, { gss_ctx_id_t context = GSS_C_NO_CONTEXT; gss_buffer_desc in_buf, out_buf; @@ -360,7 +360,7 @@ index 6e2aa33690..cf94623d63 100644 OM_uint32 lifetime; gss_OID mechanism, name_type; int is_local; -@@ -467,14 +435,13 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, +@@ -454,14 +422,13 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, /* Open connection */ if ((s = connect_to_server(host, port)) < 0) @@ -377,7 +377,7 @@ index 6e2aa33690..cf94623d63 100644 } if (auth_flag && verbose) { -@@ -488,19 +455,19 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, +@@ -475,19 +442,19 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, &is_local, &is_open); if (maj_stat != GSS_S_COMPLETE) { display_status("inquiring context", maj_stat, min_stat); @@ -400,7 +400,7 @@ index 6e2aa33690..cf94623d63 100644 } printf("\"%.*s\" to \"%.*s\", lifetime %d, flags %x, %s, %s\n", (int) sname.length, (char *) sname.value, -@@ -509,15 +476,10 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, +@@ -496,15 +463,10 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, (is_local) ? "locally initiated" : "remotely initiated", (is_open) ? "open" : "closed"); @@ -417,7 +417,7 @@ index 6e2aa33690..cf94623d63 100644 } printf("Name type of source name is %.*s.\n", (int) oid_name.length, (char *) oid_name.value); -@@ -528,13 +490,13 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, +@@ -515,13 +477,13 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, mechanism, &mech_names); if (maj_stat != GSS_S_COMPLETE) { display_status("inquiring mech names", maj_stat, min_stat); @@ -433,7 +433,7 @@ index 6e2aa33690..cf94623d63 100644 } printf("Mechanism %.*s supports %d names\n", (int) oid_name.length, (char *) oid_name.value, -@@ -546,7 +508,7 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, +@@ -533,7 +495,7 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, &mech_names->elements[i], &oid_name); if (maj_stat != GSS_S_COMPLETE) { display_status("converting oid->string", maj_stat, min_stat); @@ -442,7 +442,7 @@ index 6e2aa33690..cf94623d63 100644 } printf(" %d: %.*s\n", (int) i, (int) oid_name.length, (char *) oid_name.value); -@@ -571,10 +533,7 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, +@@ -558,10 +520,7 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, &in_buf, &state, &out_buf); if (maj_stat != GSS_S_COMPLETE) { display_status("wrapping message", maj_stat, min_stat); @@ -454,7 +454,7 @@ index 6e2aa33690..cf94623d63 100644 } else if (encrypt_flag && !state) { fprintf(stderr, "Warning! Message not encrypted.\n"); } -@@ -588,22 +547,15 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, +@@ -575,22 +534,15 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, (wrap_flag ? TOKEN_WRAPPED : 0) | (encrypt_flag ? TOKEN_ENCRYPTED : 0) | (mic_flag ? TOKEN_SEND_MIC : 0))), @@ -482,7 +482,7 @@ index 6e2aa33690..cf94623d63 100644 if (mic_flag) { /* Verify signature block */ -@@ -611,10 +563,7 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, +@@ -598,10 +550,7 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, &out_buf, &qop_state); if (maj_stat != GSS_S_COMPLETE) { display_status("verifying signature", maj_stat, min_stat); @@ -494,7 +494,7 @@ index 6e2aa33690..cf94623d63 100644 } if (verbose) -@@ -634,23 +583,17 @@ call_server(host, port, oid, service_name, gss_flags, auth_flag, +@@ -621,23 +570,17 @@ call_server(char *host, u_short port, gss_OID oid, char *service_name, if (!v1_format) (void) send_token(s, TOKEN_NOOP, empty_token); @@ -529,7 +529,7 @@ index 6e2aa33690..cf94623d63 100644 static void diff --git a/src/appl/gss-sample/gss-server.c b/src/appl/gss-sample/gss-server.c -index 9b6ce9ffb3..ce25df8b40 100644 +index 0e9c857e56..4ba864d9fb 100644 --- a/src/appl/gss-sample/gss-server.c +++ b/src/appl/gss-sample/gss-server.c @@ -138,13 +138,12 @@ server_acquire_creds(char *service_name, gss_OID mech, @@ -548,7 +548,7 @@ index 9b6ce9ffb3..ce25df8b40 100644 } diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c -index dcdc5a2d59..43392d2337 100644 +index c797b1698f..b5ae96a843 100644 --- a/src/clients/klist/klist.c +++ b/src/clients/klist/klist.c @@ -469,20 +469,21 @@ do_ccache() @@ -667,7 +667,7 @@ index dcdc5a2d59..43392d2337 100644 * current. Otherwise accept any current cred. */ if (found_tgt) diff --git a/src/clients/ksu/authorization.c b/src/clients/ksu/authorization.c -index fb9d5d0942..6c6a2d007e 100644 +index 17a8a8f2f0..1f2650c2ab 100644 --- a/src/clients/ksu/authorization.c +++ b/src/clients/ksu/authorization.c @@ -28,7 +28,17 @@ @@ -687,9 +687,9 @@ index fb9d5d0942..6c6a2d007e 100644 + free(list); +} - krb5_boolean fowner(fp, uid) - FILE *fp; -@@ -53,10 +63,10 @@ krb5_boolean fowner(fp, uid) + krb5_boolean + fowner(FILE *fp, uid_t uid) +@@ -52,10 +62,10 @@ fowner(FILE *fp, uid_t uid) /* * Given a Kerberos principal "principal", and a local username "luser", @@ -703,9 +703,9 @@ index fb9d5d0942..6c6a2d007e 100644 + * (regardless of its result), non-zero if it encountered an error. */ - krb5_error_code krb5_authorization(context, principal, luser, -@@ -71,7 +81,7 @@ krb5_error_code krb5_authorization(context, principal, luser, - char **out_fcmd; + krb5_error_code +@@ -64,7 +74,7 @@ krb5_authorization(krb5_context context, krb5_principal principal, + char **out_fcmd) { struct passwd *pwd; - char *princname; @@ -713,7 +713,7 @@ index fb9d5d0942..6c6a2d007e 100644 int k5login_flag =0; int k5users_flag =0; krb5_boolean retbool =FALSE; -@@ -83,7 +93,7 @@ krb5_error_code krb5_authorization(context, principal, luser, +@@ -76,7 +86,7 @@ krb5_authorization(krb5_context context, krb5_principal principal, /* no account => no access */ if ((pwd = getpwnam(luser)) == NULL) @@ -722,7 +722,7 @@ index fb9d5d0942..6c6a2d007e 100644 retval = krb5_unparse_name(context, principal, &princname); if (retval) -@@ -100,22 +110,19 @@ krb5_error_code krb5_authorization(context, principal, luser, +@@ -93,22 +103,19 @@ krb5_authorization(krb5_context context, krb5_principal principal, /* k5login and k5users must be owned by target user or root */ if (!k5login_flag){ @@ -755,7 +755,7 @@ index fb9d5d0942..6c6a2d007e 100644 } if (auth_debug){ -@@ -134,10 +141,8 @@ krb5_error_code krb5_authorization(context, principal, luser, +@@ -127,10 +134,8 @@ krb5_authorization(krb5_context context, krb5_principal principal, princname); retval = k5login_lookup(login_fp, princname, &retbool); @@ -768,7 +768,7 @@ index fb9d5d0942..6c6a2d007e 100644 if (retbool) { if (cmd) *out_fcmd = xstrdup(cmd); -@@ -147,10 +152,8 @@ krb5_error_code krb5_authorization(context, principal, luser, +@@ -140,10 +145,8 @@ krb5_authorization(krb5_context context, krb5_principal principal, if ((!k5users_flag) && (retbool == FALSE) ){ retval = k5users_lookup (users_fp, princname, cmd, &retbool, out_fcmd); @@ -781,7 +781,7 @@ index fb9d5d0942..6c6a2d007e 100644 } if (k5login_flag && k5users_flag){ -@@ -166,8 +169,14 @@ krb5_error_code krb5_authorization(context, principal, luser, +@@ -159,8 +162,14 @@ krb5_authorization(krb5_context context, krb5_principal principal, } *ok =retbool; @@ -798,8 +798,8 @@ index fb9d5d0942..6c6a2d007e 100644 } /*********************************************************** -@@ -334,10 +343,11 @@ krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) - char **out_err; +@@ -320,10 +329,11 @@ krb5_boolean + fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) { char * err; - char ** tmp_fcmd; @@ -811,7 +811,7 @@ index fb9d5d0942..6c6a2d007e 100644 tmp_fcmd = (char **) xcalloc (MAX_CMD, sizeof(char *)); -@@ -345,7 +355,7 @@ krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) +@@ -331,7 +341,7 @@ fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) tmp_fcmd[0] = xstrdup(fcmd); tmp_fcmd[1] = NULL; *out_fcmd = tmp_fcmd; @@ -820,7 +820,7 @@ index fb9d5d0942..6c6a2d007e 100644 }else{ /* must be either full path or just the cmd name */ if (strchr(fcmd, '/')){ -@@ -353,7 +363,7 @@ krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) +@@ -339,7 +349,7 @@ fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) "either full path or just the cmd name\n"), fcmd, KRB5_USERS_NAME); *out_err = err; @@ -829,7 +829,7 @@ index fb9d5d0942..6c6a2d007e 100644 } #ifndef CMD_PATH -@@ -361,7 +371,7 @@ krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) +@@ -347,7 +357,7 @@ fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) "the cmd name, CMD_PATH must be defined \n"), fcmd, KRB5_USERS_NAME, fcmd); *out_err = err; @@ -838,7 +838,7 @@ index fb9d5d0942..6c6a2d007e 100644 #else path = xstrdup (CMD_PATH); -@@ -375,7 +385,7 @@ krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) +@@ -361,7 +371,7 @@ fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) asprintf(&err, _("Error: bad entry - %s in %s file, CMD_PATH " "contains no paths \n"), fcmd, KRB5_USERS_NAME); *out_err = err; @@ -847,7 +847,7 @@ index fb9d5d0942..6c6a2d007e 100644 } i=0; -@@ -384,7 +394,7 @@ krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) +@@ -370,7 +380,7 @@ fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) asprintf(&err, _("Error: bad path %s in CMD_PATH for %s must " "start with '/' \n"), tc, KRB5_USERS_NAME ); *out_err = err; @@ -856,7 +856,7 @@ index fb9d5d0942..6c6a2d007e 100644 } tmp_fcmd[i] = xasprintf("%s/%s", tc, fcmd); -@@ -395,10 +405,15 @@ krb5_boolean fcmd_resolve(fcmd, out_fcmd, out_err) +@@ -381,10 +391,15 @@ fcmd_resolve(char *fcmd, char ***out_fcmd, char **out_err) tmp_fcmd[i] = NULL; *out_fcmd = tmp_fcmd; @@ -874,9 +874,9 @@ index fb9d5d0942..6c6a2d007e 100644 } /******************************************** -@@ -524,41 +539,42 @@ int match_commands (fcmd, cmd, match, cmd_out, err_out) - char **cmd_out; - char **err_out; +@@ -503,41 +518,42 @@ int + match_commands(char *fcmd, char *cmd, krb5_boolean *match, + char **cmd_out, char **err_out) { - char ** fcmd_arr; + char ** fcmd_arr = NULL; @@ -930,7 +930,7 @@ index fb9d5d0942..6c6a2d007e 100644 } /********************************************************* -@@ -587,10 +603,7 @@ krb5_error_code get_line (fp, out_line) +@@ -563,10 +579,7 @@ get_line(FILE *fp, char **out_line) } else { chunk_count ++; @@ -942,14 +942,12 @@ index fb9d5d0942..6c6a2d007e 100644 line_ptr = line + (BUFSIZ -1) *( chunk_count -1) ; } -@@ -677,21 +690,8 @@ char * get_next_token (lnext) +@@ -652,17 +665,6 @@ get_next_token (char **lnext) return out_ptr; } --static void auth_cleanup(users_fp, login_fp, princname) -- FILE *users_fp; -- FILE *login_fp; -- char *princname; +-static void +-auth_cleanup(FILE *users_fp, FILE *login_fp, char *princname) -{ - - free (princname); @@ -959,22 +957,17 @@ index fb9d5d0942..6c6a2d007e 100644 - fclose(login_fp); -} - --void init_auth_names(pw_dir) -- char *pw_dir; -+void -+init_auth_names(char *pw_dir) + void + init_auth_names(char *pw_dir) { - const char *sep; - int r1, r2; diff --git a/src/clients/ksu/ccache.c b/src/clients/ksu/ccache.c -index cbb9aa2b85..45667dd24a 100644 +index cca9ce2dfc..76cb1d6aa4 100644 --- a/src/clients/ksu/ccache.c +++ b/src/clients/ksu/ccache.c -@@ -40,7 +40,19 @@ copies the default cache into the secondary cache, +@@ -40,6 +40,18 @@ copies the default cache into the secondary cache, ************************************************************************/ --void show_credential(); +static void +free_creds_list(krb5_context context, krb5_creds **list) +{ @@ -987,13 +980,12 @@ index cbb9aa2b85..45667dd24a 100644 + free(list); +} + -+void show_credential(krb5_context, krb5_creds *, krb5_ccache); + void show_credential(krb5_context, krb5_creds *, krb5_ccache); /* modifies only the cc_other, the algorithm may look a bit funny, - but I had to do it this way, since remove function did not come -@@ -59,20 +71,19 @@ krb5_error_code krb5_ccache_copy(context, cc_def, target_principal, cc_target, - /* OUT */ - krb5_boolean *stored; +@@ -53,20 +65,19 @@ krb5_ccache_copy(krb5_context context, krb5_ccache cc_def, + krb5_boolean restrict_creds, krb5_principal primary_principal, + krb5_boolean *stored) { - int i=0; krb5_error_code retval=0; @@ -1016,7 +1008,7 @@ index cbb9aa2b85..45667dd24a 100644 if (restrict_creds) { retval = krb5_store_some_creds(context, cc_target, cc_def_creds_arr, -@@ -85,22 +96,9 @@ krb5_error_code krb5_ccache_copy(context, cc_def, target_principal, cc_target, +@@ -79,22 +90,9 @@ krb5_ccache_copy(krb5_context context, krb5_ccache cc_def, cc_other_creds_arr); } @@ -1042,7 +1034,7 @@ index cbb9aa2b85..45667dd24a 100644 return retval; } -@@ -198,32 +196,29 @@ krb5_error_code krb5_get_nonexp_tkts(context, cc, creds_array) +@@ -184,32 +182,29 @@ krb5_get_nonexp_tkts(krb5_context context, krb5_ccache cc, { krb5_creds creds, temp_tktq, temp_tkt; @@ -1082,7 +1074,7 @@ index cbb9aa2b85..45667dd24a 100644 } if (auth_debug){ fprintf(stderr,"krb5_ccache_copy: CREDS EXPIRED:\n"); -@@ -233,19 +228,19 @@ krb5_error_code krb5_get_nonexp_tkts(context, cc, creds_array) +@@ -219,19 +214,19 @@ krb5_get_nonexp_tkts(krb5_context context, krb5_ccache cc, } } else { /* these credentials didn't expire */ @@ -1111,7 +1103,7 @@ index cbb9aa2b85..45667dd24a 100644 } } -@@ -253,13 +248,15 @@ krb5_error_code krb5_get_nonexp_tkts(context, cc, creds_array) +@@ -239,13 +234,15 @@ krb5_get_nonexp_tkts(krb5_context context, krb5_ccache cc, temp_creds[count] = NULL; *creds_array = temp_creds; @@ -1127,16 +1119,14 @@ index cbb9aa2b85..45667dd24a 100644 - } - -@@ -331,97 +328,6 @@ void printtime(krb5_timestamp ts) + krb5_error_code +@@ -315,122 +312,33 @@ printtime(krb5_timestamp ts) printf("%s", fmtbuf); } - -krb5_error_code --krb5_get_login_princ(luser, princ_list) -- const char *luser; -- char ***princ_list; +-krb5_get_login_princ(const char *luser, char ***princ_list) -{ - struct stat sbuf; - struct passwd *pwd; @@ -1220,14 +1210,9 @@ index cbb9aa2b85..45667dd24a 100644 - fclose(fp); - return 0; -} -- -- - void - show_credential(context, cred, cc) - krb5_context context; -@@ -429,31 +335,29 @@ show_credential(context, cred, cc) - krb5_ccache cc; + show_credential(krb5_context context, krb5_creds *cred, krb5_ccache cc) { krb5_error_code retval; - char *name, *sname, *flags; @@ -1264,7 +1249,7 @@ index cbb9aa2b85..45667dd24a 100644 } if (!cred->times.starttime) -@@ -491,8 +395,12 @@ show_credential(context, cred, cc) +@@ -468,8 +376,12 @@ show_credential(krb5_context context, krb5_creds *cred, krb5_ccache cc) } } putchar('\n'); @@ -1277,8 +1262,8 @@ index cbb9aa2b85..45667dd24a 100644 } /* Create a random string suitable for a filename extension. */ -@@ -526,37 +434,26 @@ krb5_error_code krb5_ccache_overwrite(context, ccs, cct, primary_principal) - krb5_principal primary_principal; +@@ -501,37 +413,26 @@ krb5_ccache_overwrite(krb5_context context, krb5_ccache ccs, krb5_ccache cct, + krb5_principal primary_principal) { krb5_error_code retval=0; - krb5_principal temp_principal; @@ -1327,8 +1312,8 @@ index cbb9aa2b85..45667dd24a 100644 return retval; } -@@ -616,45 +513,40 @@ krb5_error_code krb5_ccache_filter (context, cc, prst) - krb5_principal prst; +@@ -585,45 +486,40 @@ krb5_error_code + krb5_ccache_filter(krb5_context context, krb5_ccache cc, krb5_principal prst) { - int i=0; @@ -1395,10 +1380,10 @@ index cbb9aa2b85..45667dd24a 100644 + return retval; } - krb5_boolean krb5_find_princ_in_cred_list (context, creds_list, princ) -@@ -688,17 +580,20 @@ krb5_error_code krb5_find_princ_in_cache (context, cc, princ, found) - krb5_principal princ; - krb5_boolean *found; + krb5_boolean +@@ -654,17 +550,20 @@ krb5_error_code + krb5_find_princ_in_cache(krb5_context context, krb5_ccache cc, + krb5_principal princ, krb5_boolean *found) { - krb5_error_code retval; + krb5_error_code retval = 0; @@ -1423,10 +1408,10 @@ index cbb9aa2b85..45667dd24a 100644 krb5_boolean diff --git a/src/clients/ksu/heuristic.c b/src/clients/ksu/heuristic.c -index 4f7280f4cb..47baa785e5 100644 +index e906de8ef0..6ed94eb887 100644 --- a/src/clients/ksu/heuristic.c +++ b/src/clients/ksu/heuristic.c -@@ -156,28 +156,31 @@ filter(fp, cmd, k5users_list, k5users_filt_list) +@@ -149,28 +149,31 @@ filter(FILE *fp, char *cmd, char **k5users_list, char ***k5users_filt_list) *k5users_filt_list = NULL; @@ -1464,7 +1449,7 @@ index 4f7280f4cb..47baa785e5 100644 for(j= 0, k=0; j < i; j++ ) { if (k5users_list[j]){ -@@ -191,7 +194,10 @@ filter(fp, cmd, k5users_list, k5users_filt_list) +@@ -184,7 +187,10 @@ filter(FILE *fp, char *cmd, char **k5users_list, char ***k5users_filt_list) free (k5users_list); *k5users_filt_list = temp_filt_list; @@ -1476,7 +1461,7 @@ index 4f7280f4cb..47baa785e5 100644 } krb5_error_code -@@ -335,7 +341,7 @@ krb5_error_code get_closest_principal(context, plist, client, found) +@@ -318,7 +324,7 @@ get_closest_principal(krb5_context context, char **plist, retval = krb5_parse_name(context, plist[i], &temp_client); if (retval) @@ -1485,7 +1470,7 @@ index 4f7280f4cb..47baa785e5 100644 pnelem = krb5_princ_size(context, temp_client); -@@ -363,6 +369,7 @@ krb5_error_code get_closest_principal(context, plist, client, found) +@@ -346,6 +352,7 @@ get_closest_principal(krb5_context context, char **plist, if(best_client){ if(krb5_princ_size(context, best_client) > krb5_princ_size(context, temp_client)){ @@ -1493,7 +1478,7 @@ index 4f7280f4cb..47baa785e5 100644 best_client = temp_client; } }else -@@ -375,9 +382,12 @@ krb5_error_code get_closest_principal(context, plist, client, found) +@@ -358,9 +365,12 @@ get_closest_principal(krb5_context context, char **plist, if (best_client) { *found = TRUE; *client = best_client; @@ -1507,7 +1492,7 @@ index 4f7280f4cb..47baa785e5 100644 } /**************************************************************** -@@ -499,6 +509,7 @@ krb5_error_code find_princ_in_list (context, princ, plist, found) +@@ -471,6 +481,7 @@ find_princ_in_list(krb5_context context, krb5_principal princ, char **plist, i++; } @@ -1515,7 +1500,7 @@ index 4f7280f4cb..47baa785e5 100644 return 0; } -@@ -534,11 +545,9 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, +@@ -498,11 +509,9 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, { princ_info princ_trials[10]; @@ -1530,7 +1515,7 @@ index 4f7280f4cb..47baa785e5 100644 krb5_error_code retval; char ** aplist =NULL; krb5_boolean found = FALSE; -@@ -555,54 +564,59 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, +@@ -519,54 +528,59 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, if (ks_ccache_is_initialized(context, cc_source)) { retval = krb5_cc_get_principal(context, cc_source, &cc_def_princ); if (retval) @@ -1609,7 +1594,7 @@ index 4f7280f4cb..47baa785e5 100644 if (cmd) *path_out = NOT_AUTHORIZED; -@@ -610,26 +624,25 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, +@@ -574,26 +588,25 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, if (auth_debug) printf(" GET_best_princ_for_target: via no auth files path\n"); @@ -1640,7 +1625,7 @@ index 4f7280f4cb..47baa785e5 100644 /* first see if default principal of the source cache * can get us in, then the target_user@realm, then the -@@ -652,7 +665,7 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, +@@ -616,7 +629,7 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, retval= find_princ_in_list(context, princ_trials[i].p, aplist, &found); if (retval) @@ -1649,7 +1634,7 @@ index 4f7280f4cb..47baa785e5 100644 if (found == TRUE){ princ_trials[i].found = TRUE; -@@ -661,12 +674,13 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, +@@ -625,12 +638,13 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, princ_trials[i].p, end_server, &found); if (retval) @@ -1666,7 +1651,7 @@ index 4f7280f4cb..47baa785e5 100644 } } } -@@ -679,21 +693,23 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, +@@ -643,21 +657,23 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, while (aplist[i]){ retval = krb5_parse_name(context, aplist[i], &temp_client); if (retval) @@ -1693,7 +1678,7 @@ index 4f7280f4cb..47baa785e5 100644 i++; } -@@ -704,11 +720,11 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, +@@ -668,11 +684,11 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, for (i=0; i < count; i ++){ if (princ_trials[i].found == TRUE){ @@ -1707,7 +1692,7 @@ index 4f7280f4cb..47baa785e5 100644 } } -@@ -718,7 +734,7 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, +@@ -682,7 +698,7 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, retval=krb5_copy_principal(context, princ_trials[i].p, &temp_client); if(retval) @@ -1716,7 +1701,7 @@ index 4f7280f4cb..47baa785e5 100644 /* get the client name that is the closest to the three princ in trials */ -@@ -726,15 +742,15 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, +@@ -690,15 +706,15 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, retval=get_closest_principal(context, aplist, &temp_client, &found); if(retval) @@ -1735,7 +1720,7 @@ index 4f7280f4cb..47baa785e5 100644 } } -@@ -745,5 +761,13 @@ krb5_error_code get_best_princ_for_target(context, source_uid, target_uid, +@@ -709,5 +725,13 @@ get_best_princ_for_target(krb5_context context, uid_t source_uid, printf( "GET_best_princ_for_target: out of luck, can't get appropriate default principal\n"); *path_out = NOT_AUTHORIZED; @@ -1751,12 +1736,12 @@ index 4f7280f4cb..47baa785e5 100644 + return retval; } diff --git a/src/clients/ksu/krb_auth_su.c b/src/clients/ksu/krb_auth_su.c -index fb848dcab1..a99c4c826c 100644 +index db10251f95..68cfe6b0ed 100644 --- a/src/clients/ksu/krb_auth_su.c +++ b/src/clients/ksu/krb_auth_su.c -@@ -42,33 +42,31 @@ krb5_boolean krb5_auth_check(context, client_pname, hostname, options, - krb5_ccache cc; - int *path_passwd; +@@ -37,33 +37,31 @@ krb5_auth_check(krb5_context context, krb5_principal client_pname, + char *target_user, krb5_ccache cc, int *path_passwd, + uid_t target_uid) { - krb5_principal client; + krb5_principal client = NULL; @@ -1794,7 +1779,7 @@ index fb848dcab1..a99c4c826c 100644 } if (auth_debug){ dump_principal(context, "local tgt principal name", tgtq.server ); } -@@ -82,7 +80,7 @@ krb5_boolean krb5_auth_check(context, client_pname, hostname, options, +@@ -77,7 +75,7 @@ krb5_auth_check(krb5_context context, krb5_principal client_pname, if ((retval != KRB5_CC_NOTFOUND) && (retval != KRB5KRB_AP_ERR_TKT_EXPIRED)){ com_err(prog_name, retval, _("while retrieving creds from cache")); @@ -1803,7 +1788,7 @@ index fb848dcab1..a99c4c826c 100644 } } else{ got_it = 1; -@@ -93,7 +91,7 @@ krb5_boolean krb5_auth_check(context, client_pname, hostname, options, +@@ -88,7 +86,7 @@ krb5_auth_check(krb5_context context, krb5_principal client_pname, #ifdef GET_TGT_VIA_PASSWD if (krb5_seteuid(0)||krb5_seteuid(target_uid)) { com_err("ksu", errno, _("while switching to target uid")); @@ -1812,7 +1797,7 @@ index fb848dcab1..a99c4c826c 100644 } -@@ -107,19 +105,19 @@ krb5_boolean krb5_auth_check(context, client_pname, hostname, options, +@@ -102,19 +100,19 @@ krb5_auth_check(krb5_context context, krb5_principal client_pname, &tgt) == FALSE) { krb5_seteuid(0); @@ -1835,7 +1820,7 @@ index fb848dcab1..a99c4c826c 100644 #endif /* GET_TGT_VIA_PASSWD */ -@@ -131,10 +129,16 @@ krb5_boolean krb5_auth_check(context, client_pname, hostname, options, +@@ -126,10 +124,16 @@ krb5_auth_check(krb5_context context, krb5_principal client_pname, &vfy_opts); if (retval) { com_err(prog_name, retval, _("while verifying ticket for server")); @@ -1853,10 +1838,10 @@ index fb848dcab1..a99c4c826c 100644 + return ok; } - krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, -@@ -145,11 +149,12 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, - krb5_boolean *zero_password; - krb5_creds *creds_out; + krb5_boolean +@@ -137,11 +141,12 @@ ksu_get_tgt_via_passwd(krb5_context context, krb5_principal client, + krb5_get_init_creds_opt *options, + krb5_boolean *zero_password, krb5_creds *creds_out) { + krb5_boolean ok = FALSE; krb5_error_code code; @@ -1869,7 +1854,7 @@ index fb848dcab1..a99c4c826c 100644 int result; *zero_password = FALSE; -@@ -158,14 +163,14 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, +@@ -150,14 +155,14 @@ ksu_get_tgt_via_passwd(krb5_context context, krb5_principal client, if ((code = krb5_unparse_name(context, client, &client_name))) { com_err (prog_name, code, _("when unparsing name")); @@ -1886,7 +1871,7 @@ index fb848dcab1..a99c4c826c 100644 } result = snprintf(prompt, sizeof(prompt), _("Kerberos password for %s: "), -@@ -174,7 +179,7 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, +@@ -166,7 +171,7 @@ ksu_get_tgt_via_passwd(krb5_context context, krb5_principal client, fprintf(stderr, _("principal name %s too long for internal buffer space\n"), client_name); @@ -1895,7 +1880,7 @@ index fb848dcab1..a99c4c826c 100644 } pwsize = sizeof(password); -@@ -183,13 +188,13 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, +@@ -175,13 +180,13 @@ ksu_get_tgt_via_passwd(krb5_context context, krb5_principal client, if (code ) { com_err(prog_name, code, _("while reading password for '%s'\n"), client_name); @@ -1911,7 +1896,7 @@ index fb848dcab1..a99c4c826c 100644 } code = krb5_get_init_creds_password(context, &creds, client, password, -@@ -203,13 +208,19 @@ krb5_boolean ksu_get_tgt_via_passwd(context, client, options, zero_password, +@@ -195,13 +200,19 @@ ksu_get_tgt_via_passwd(krb5_context context, krb5_principal client, fprintf(stderr, _("%s: Password incorrect\n"), prog_name); else com_err(prog_name, code, _("while getting initial credentials")); @@ -1935,8 +1920,8 @@ index fb848dcab1..a99c4c826c 100644 + return ok; } - -@@ -224,8 +235,10 @@ void dump_principal (context, str, p) + void +@@ -213,8 +224,10 @@ dump_principal(krb5_context context, char *str, krb5_principal p) if ((retval = krb5_unparse_name(context, p, &stname))) { fprintf(stderr, _(" %s while unparsing name\n"), error_message(retval)); @@ -1946,8 +1931,8 @@ index fb848dcab1..a99c4c826c 100644 + free(stname); } - void plain_dump_principal (context, p) -@@ -238,74 +251,8 @@ void plain_dump_principal (context, p) + void +@@ -226,71 +239,8 @@ plain_dump_principal (krb5_context context, krb5_principal p) if ((retval = krb5_unparse_name(context, p, &stname))) { fprintf(stderr, _(" %s while unparsing name\n"), error_message(retval)); @@ -1965,11 +1950,8 @@ index fb848dcab1..a99c4c826c 100644 - -**********************************************************************/ - -- --krb5_error_code get_best_principal(context, plist, client) -- krb5_context context; -- char **plist; -- krb5_principal *client; +-krb5_error_code +-get_best_principal(krb5_context context, char **plist, krb5_principal *client) -{ - krb5_error_code retval =0; - krb5_principal temp_client, best_client = NULL; @@ -2049,10 +2031,10 @@ index 66fb4bcc6a..32ce11cb85 100644 (krb5_context, krb5_creds *, krb5_ccache); diff --git a/src/clients/ksu/main.c b/src/clients/ksu/main.c -index 931f054041..a7cb7ed3be 100644 +index 2a351662c8..77703a6a2b 100644 --- a/src/clients/ksu/main.c +++ b/src/clients/ksu/main.c -@@ -1003,7 +1003,7 @@ resolve_target_cache(krb5_context context, krb5_principal princ, +@@ -1002,7 +1002,7 @@ resolve_target_cache(krb5_context context, krb5_principal princ, if (retval) { com_err(prog_name, retval, _("while generating part of the target ccache name")); @@ -2061,7 +2043,7 @@ index 931f054041..a7cb7ed3be 100644 } if (asprintf(&ccname, "%s.%s", target, sym) < 0) { retval = ENOMEM; -@@ -1015,6 +1015,7 @@ resolve_target_cache(krb5_context context, krb5_principal princ, +@@ -1014,6 +1014,7 @@ resolve_target_cache(krb5_context context, krb5_principal princ, free(sym); } while (ks_ccache_name_is_initialized(context, ccname)); retval = krb5_cc_resolve(context, ccname, &ccache); @@ -2070,7 +2052,7 @@ index 931f054041..a7cb7ed3be 100644 /* Look for a cache in the collection that we can reuse. */ retval = krb5_cc_cache_match(context, princ, &ccache); diff --git a/src/kadmin/cli/keytab.c b/src/kadmin/cli/keytab.c -index b0c8378b40..8a59188216 100644 +index 26f340af31..976c8969e8 100644 --- a/src/kadmin/cli/keytab.c +++ b/src/kadmin/cli/keytab.c @@ -363,7 +363,7 @@ remove_principal(char *keytab_str, krb5_keytab keytab, @@ -2108,10 +2090,10 @@ index b0c8378b40..8a59188216 100644 } diff --git a/src/kadmin/ktutil/ktutil.c b/src/kadmin/ktutil/ktutil.c -index 92d7023a4f..782c7289c5 100644 +index 87a69ca145..a1c17d154d 100644 --- a/src/kadmin/ktutil/ktutil.c +++ b/src/kadmin/ktutil/ktutil.c -@@ -263,6 +263,7 @@ void ktutil_list(argc, argv) +@@ -254,6 +254,7 @@ ktutil_list(int argc, char *argv[]) buf, sizeof(buf)))) { com_err(argv[0], retval, _("While converting enctype to string")); @@ -2120,7 +2102,7 @@ index 92d7023a4f..782c7289c5 100644 } printf(" (%s) ", buf); diff --git a/src/kprop/kpropd.c b/src/kprop/kpropd.c -index cb9785aaeb..286b3a655e 100644 +index f883ae2df8..9a4826e441 100644 --- a/src/kprop/kpropd.c +++ b/src/kprop/kpropd.c @@ -1300,19 +1300,20 @@ static krb5_boolean @@ -2187,7 +2169,7 @@ index 96a408c237..bf5cede54a 100644 if (json_kgcred(context, cred, &jcred)) diff --git a/src/lib/gssapi/krb5/val_cred.c b/src/lib/gssapi/krb5/val_cred.c -index cb1cb9393a..87a46cd533 100644 +index 83e7634106..d4b070f8c0 100644 --- a/src/lib/gssapi/krb5/val_cred.c +++ b/src/lib/gssapi/krb5/val_cred.c @@ -35,6 +35,7 @@ krb5_gss_validate_cred_1(OM_uint32 *minor_status, gss_cred_id_t cred_handle, @@ -2330,5 +2312,5 @@ index 753929b06d..f7fad27867 100644 } } -- -2.41.0 +2.45.1 diff --git a/0018-Fix-vulnerabilities-in-GSS-message-token-handling.patch b/0018-Fix-vulnerabilities-in-GSS-message-token-handling.patch deleted file mode 100644 index 4934355..0000000 --- a/0018-Fix-vulnerabilities-in-GSS-message-token-handling.patch +++ /dev/null @@ -1,535 +0,0 @@ -From 7b0e4a36b82b4ab388b520eaba396de365574774 Mon Sep 17 00:00:00 2001 -From: Greg Hudson -Date: Fri, 14 Jun 2024 10:56:12 -0400 -Subject: [PATCH] Fix vulnerabilities in GSS message token handling - -In gss_krb5int_unseal_token_v3() and gss_krb5int_unseal_v3_iov(), -verify the Extra Count field of CFX wrap tokens against the encrypted -header. Reported by Jacob Champion. - -In gss_krb5int_unseal_token_v3(), check for a decrypted plaintext -length too short to contain the encrypted header and extra count -bytes. Reported by Jacob Champion. - -In kg_unseal_iov_token(), separately track the header IOV length and -complete token length when parsing the token's ASN.1 wrapper. This -fix contains modified versions of functions from k5-der.h and -util_token.c; this duplication will be cleaned up in a future commit. - -CVE-2024-37370: - -In MIT krb5 release 1.3 and later, an attacker can modify the -plaintext Extra Count field of a confidential GSS krb5 wrap token, -causing the unwrapped token to appear truncated to the application. - -CVE-2024-37371: - -In MIT krb5 release 1.3 and later, an attacker can cause invalid -memory reads by sending message tokens with invalid length fields. - -ticket: 9128 (new) -tags: pullup -target_version: 1.21-next - -(cherry picked from commit b0a2f8a5365f2eec3e27d78907de9f9d2c80505a) ---- - src/lib/gssapi/krb5/k5sealv3.c | 5 + - src/lib/gssapi/krb5/k5sealv3iov.c | 3 +- - src/lib/gssapi/krb5/k5unsealiov.c | 80 +++++++++- - src/tests/gssapi/t_invalid.c | 233 +++++++++++++++++++++++++----- - 4 files changed, 275 insertions(+), 46 deletions(-) - -diff --git a/src/lib/gssapi/krb5/k5sealv3.c b/src/lib/gssapi/krb5/k5sealv3.c -index 3b4f8cb837..1fcbdfbb87 100644 ---- a/src/lib/gssapi/krb5/k5sealv3.c -+++ b/src/lib/gssapi/krb5/k5sealv3.c -@@ -408,10 +408,15 @@ gss_krb5int_unseal_token_v3(krb5_context *contextptr, - /* Don't use bodysize here! Use the fact that - cipher.ciphertext.length has been adjusted to the - correct length. */ -+ if (plain.length < 16 + ec) { -+ free(plain.data); -+ goto defective; -+ } - althdr = (unsigned char *)plain.data + plain.length - 16; - if (load_16_be(althdr) != KG2_TOK_WRAP_MSG - || althdr[2] != ptr[2] - || althdr[3] != ptr[3] -+ || load_16_be(althdr+4) != ec - || memcmp(althdr+8, ptr+8, 8)) { - free(plain.data); - goto defective; -diff --git a/src/lib/gssapi/krb5/k5sealv3iov.c b/src/lib/gssapi/krb5/k5sealv3iov.c -index 333ee124dd..f8e90c35b4 100644 ---- a/src/lib/gssapi/krb5/k5sealv3iov.c -+++ b/src/lib/gssapi/krb5/k5sealv3iov.c -@@ -402,9 +402,10 @@ gss_krb5int_unseal_v3_iov(krb5_context context, - if (load_16_be(althdr) != KG2_TOK_WRAP_MSG - || althdr[2] != ptr[2] - || althdr[3] != ptr[3] -+ || load_16_be(althdr + 4) != ec - || memcmp(althdr + 8, ptr + 8, 8) != 0) { - *minor_status = 0; -- return GSS_S_BAD_SIG; -+ return GSS_S_DEFECTIVE_TOKEN; - } - } else { - /* Verify checksum: note EC is checksum size here, not padding */ -diff --git a/src/lib/gssapi/krb5/k5unsealiov.c b/src/lib/gssapi/krb5/k5unsealiov.c -index 3ce2a90ce9..6a6585d9af 100644 ---- a/src/lib/gssapi/krb5/k5unsealiov.c -+++ b/src/lib/gssapi/krb5/k5unsealiov.c -@@ -25,6 +25,7 @@ - */ - - #include "k5-int.h" -+#include "k5-der.h" - #include "gssapiP_krb5.h" - - static OM_uint32 -@@ -247,6 +248,73 @@ cleanup: - return retval; - } - -+/* Similar to k5_der_get_value(), but output an unchecked content length -+ * instead of a k5input containing the contents. */ -+static inline bool -+get_der_tag(struct k5input *in, uint8_t idbyte, size_t *len_out) -+{ -+ uint8_t lenbyte, i; -+ size_t len; -+ -+ /* Do nothing if in is empty or the next byte doesn't match idbyte. */ -+ if (in->status || in->len == 0 || *in->ptr != idbyte) -+ return false; -+ -+ /* Advance past the identifier byte and decode the length. */ -+ (void)k5_input_get_byte(in); -+ lenbyte = k5_input_get_byte(in); -+ if (lenbyte < 128) { -+ len = lenbyte; -+ } else { -+ len = 0; -+ for (i = 0; i < (lenbyte & 0x7F); i++) { -+ if (len > (SIZE_MAX >> 8)) { -+ k5_input_set_status(in, EOVERFLOW); -+ return false; -+ } -+ len = (len << 8) | k5_input_get_byte(in); -+ } -+ } -+ -+ if (in->status) -+ return false; -+ -+ *len_out = len; -+ return true; -+} -+ -+/* -+ * Similar to g_verify_token_header() without toktype or flags, but do not read -+ * more than *header_len bytes of ASN.1 wrapper, and on output set *header_len -+ * to the remaining number of header bytes. Verify the outer DER tag's length -+ * against token_len, which may be larger (but not smaller) than *header_len. -+ */ -+static gss_int32 -+verify_detached_wrapper(const gss_OID_desc *mech, size_t *header_len, -+ uint8_t **header_in, size_t token_len) -+{ -+ struct k5input in, mech_der; -+ gss_OID_desc toid; -+ size_t len; -+ -+ k5_input_init(&in, *header_in, *header_len); -+ -+ if (get_der_tag(&in, 0x60, &len)) { -+ if (len != token_len - (in.ptr - *header_in)) -+ return G_BAD_TOK_HEADER; -+ if (!k5_der_get_value(&in, 0x06, &mech_der)) -+ return G_BAD_TOK_HEADER; -+ toid.elements = (uint8_t *)mech_der.ptr; -+ toid.length = mech_der.len; -+ if (!g_OID_equal(&toid, mech)) -+ return G_WRONG_MECH; -+ } -+ -+ *header_in = (uint8_t *)in.ptr; -+ *header_len = in.len; -+ return 0; -+} -+ - /* - * Caller must provide TOKEN | DATA | PADDING | TRAILER, except - * for DCE in which case it can just provide TOKEN | DATA (must -@@ -267,8 +335,7 @@ kg_unseal_iov_token(OM_uint32 *minor_status, - gss_iov_buffer_t header; - gss_iov_buffer_t padding; - gss_iov_buffer_t trailer; -- size_t input_length; -- unsigned int bodysize; -+ size_t input_length, hlen; - int toktype2; - - header = kg_locate_header_iov(iov, iov_count, toktype); -@@ -298,15 +365,14 @@ kg_unseal_iov_token(OM_uint32 *minor_status, - input_length += trailer->buffer.length; - } - -- code = g_verify_token_header(ctx->mech_used, -- &bodysize, &ptr, -1, -- input_length, 0); -+ hlen = header->buffer.length; -+ code = verify_detached_wrapper(ctx->mech_used, &hlen, &ptr, input_length); - if (code != 0) { - *minor_status = code; - return GSS_S_DEFECTIVE_TOKEN; - } - -- if (bodysize < 2) { -+ if (hlen < 2) { - *minor_status = (OM_uint32)G_BAD_TOK_HEADER; - return GSS_S_DEFECTIVE_TOKEN; - } -@@ -314,7 +380,7 @@ kg_unseal_iov_token(OM_uint32 *minor_status, - toktype2 = load_16_be(ptr); - - ptr += 2; -- bodysize -= 2; -+ hlen -= 2; - - switch (toktype2) { - case KG2_TOK_MIC_MSG: -diff --git a/src/tests/gssapi/t_invalid.c b/src/tests/gssapi/t_invalid.c -index fb8fe55111..8192935099 100644 ---- a/src/tests/gssapi/t_invalid.c -+++ b/src/tests/gssapi/t_invalid.c -@@ -36,31 +36,41 @@ - * - * 1. A pre-CFX wrap or MIC token processed with a CFX-only context causes a - * null pointer dereference. (The token must use SEAL_ALG_NONE or it will -- * be rejected.) -+ * be rejected.) This vulnerability also applies to IOV unwrap. - * -- * 2. A pre-CFX wrap or MIC token with fewer than 24 bytes after the ASN.1 -+ * 2. A CFX wrap token with a different value of EC between the plaintext and -+ * encrypted copies will be erroneously accepted, which allows a message -+ * truncation attack. This vulnerability also applies to IOV unwrap. -+ * -+ * 3. A CFX wrap token with a plaintext length fewer than 16 bytes causes an -+ * access before the beginning of the input buffer, possibly leading to a -+ * crash. -+ * -+ * 4. A CFX wrap token with a plaintext EC value greater than the plaintext -+ * length - 16 causes an integer underflow when computing the result length, -+ * likely causing a crash. -+ * -+ * 5. An IOV unwrap operation will overrun the header buffer if an ASN.1 -+ * wrapper longer than the header buffer is present. -+ * -+ * 6. A pre-CFX wrap or MIC token with fewer than 24 bytes after the ASN.1 - * header causes an input buffer overrun, usually leading to either a segv - * or a GSS_S_DEFECTIVE_TOKEN error due to garbage algorithm, filler, or -- * sequence number values. -+ * sequence number values. This vulnerability also applies to IOV unwrap. - * -- * 3. A pre-CFX wrap token with fewer than 16 + cksumlen bytes after the ASN.1 -+ * 7. A pre-CFX wrap token with fewer than 16 + cksumlen bytes after the ASN.1 - * header causes an integer underflow when computing the ciphertext length, - * leading to an allocation error on 32-bit platforms or a segv on 64-bit - * platforms. A pre-CFX MIC token of this size causes an input buffer - * overrun when comparing the checksum, perhaps leading to a segv. - * -- * 4. A pre-CFX wrap token with fewer than conflen + padlen bytes in the -+ * 8. A pre-CFX wrap token with fewer than conflen + padlen bytes in the - * ciphertext (where padlen is the last byte of the decrypted ciphertext) - * causes an integer underflow when computing the original message length, - * leading to an allocation error. - * -- * 5. In the mechglue, truncated encapsulation in the initial context token can -+ * 9. In the mechglue, truncated encapsulation in the initial context token can - * cause input buffer overruns in gss_accept_sec_context(). -- * -- * Vulnerabilities #1 and #2 also apply to IOV unwrap, although tokens with -- * fewer than 16 bytes after the ASN.1 header will be rejected. -- * Vulnerabilities #2 and #5 can only be robustly detected using a -- * memory-checking environment such as valgrind. - */ - - #include "k5-int.h" -@@ -97,17 +107,25 @@ struct test { - } - }; - --/* Fake up enough of a CFX GSS context for gss_unwrap, using an AES key. */ -+static void * -+ealloc(size_t len) -+{ -+ void *ptr = calloc(len, 1); -+ -+ if (ptr == NULL) -+ abort(); -+ return ptr; -+} -+ -+/* Fake up enough of a CFX GSS context for gss_unwrap, using an AES key. -+ * The context takes ownership of subkey. */ - static gss_ctx_id_t --make_fake_cfx_context() -+make_fake_cfx_context(krb5_key subkey) - { - gss_union_ctx_id_t uctx; - krb5_gss_ctx_id_t kgctx; -- krb5_keyblock kb; - -- kgctx = calloc(1, sizeof(*kgctx)); -- if (kgctx == NULL) -- abort(); -+ kgctx = ealloc(sizeof(*kgctx)); - kgctx->established = 1; - kgctx->proto = 1; - if (g_seqstate_init(&kgctx->seqstate, 0, 0, 0, 0) != 0) -@@ -116,15 +134,10 @@ make_fake_cfx_context() - kgctx->sealalg = -1; - kgctx->signalg = -1; - -- kb.enctype = ENCTYPE_AES128_CTS_HMAC_SHA1_96; -- kb.length = 16; -- kb.contents = (unsigned char *)"1234567887654321"; -- if (krb5_k_create_key(NULL, &kb, &kgctx->subkey) != 0) -- abort(); -+ kgctx->subkey = subkey; -+ kgctx->cksumtype = CKSUMTYPE_HMAC_SHA1_96_AES128; - -- uctx = calloc(1, sizeof(*uctx)); -- if (uctx == NULL) -- abort(); -+ uctx = ealloc(sizeof(*uctx)); - uctx->mech_type = &mech_krb5; - uctx->internal_ctx_id = (gss_ctx_id_t)kgctx; - return (gss_ctx_id_t)uctx; -@@ -138,9 +151,7 @@ make_fake_context(const struct test *test) - krb5_gss_ctx_id_t kgctx; - krb5_keyblock kb; - -- kgctx = calloc(1, sizeof(*kgctx)); -- if (kgctx == NULL) -- abort(); -+ kgctx = ealloc(sizeof(*kgctx)); - kgctx->established = 1; - if (g_seqstate_init(&kgctx->seqstate, 0, 0, 0, 0) != 0) - abort(); -@@ -162,9 +173,7 @@ make_fake_context(const struct test *test) - if (krb5_k_create_key(NULL, &kb, &kgctx->enc) != 0) - abort(); - -- uctx = calloc(1, sizeof(*uctx)); -- if (uctx == NULL) -- abort(); -+ uctx = ealloc(sizeof(*uctx)); - uctx->mech_type = &mech_krb5; - uctx->internal_ctx_id = (gss_ctx_id_t)kgctx; - return (gss_ctx_id_t)uctx; -@@ -194,9 +203,7 @@ make_token(unsigned char *token, size_t len, gss_buffer_t out) - - assert(mech_krb5.length == 9); - assert(len + 11 < 128); -- wrapped = malloc(len + 13); -- if (wrapped == NULL) -- abort(); -+ wrapped = ealloc(len + 13); - wrapped[0] = 0x60; - wrapped[1] = len + 11; - wrapped[2] = 0x06; -@@ -207,6 +214,18 @@ make_token(unsigned char *token, size_t len, gss_buffer_t out) - out->value = wrapped; - } - -+/* Create a 16-byte header for a CFX confidential wrap token to be processed by -+ * the fake CFX context. */ -+static void -+write_cfx_header(uint16_t ec, uint8_t *out) -+{ -+ memset(out, 0, 16); -+ store_16_be(KG2_TOK_WRAP_MSG, out); -+ out[2] = FLAG_WRAP_CONFIDENTIAL; -+ out[3] = 0xFF; -+ store_16_be(ec, out + 4); -+} -+ - /* Unwrap a superficially valid RFC 1964 token with a CFX-only context, with - * regular and IOV unwrap. */ - static void -@@ -238,6 +257,134 @@ test_bogus_1964_token(gss_ctx_id_t ctx) - free(in.value); - } - -+static void -+test_cfx_altered_ec(gss_ctx_id_t ctx, krb5_key subkey) -+{ -+ OM_uint32 major, minor; -+ uint8_t tokbuf[128], plainbuf[24]; -+ krb5_data plain; -+ krb5_enc_data cipher; -+ gss_buffer_desc in, out; -+ gss_iov_buffer_desc iov[2]; -+ -+ /* Construct a header with a plaintext EC value of 3. */ -+ write_cfx_header(3, tokbuf); -+ -+ /* Encrypt a plaintext and a copy of the header with the EC value 0. */ -+ memcpy(plainbuf, "truncate", 8); -+ memcpy(plainbuf + 8, tokbuf, 16); -+ store_16_be(0, plainbuf + 12); -+ plain = make_data(plainbuf, 24); -+ cipher.ciphertext.data = (char *)tokbuf + 16; -+ cipher.ciphertext.length = sizeof(tokbuf) - 16; -+ cipher.enctype = subkey->keyblock.enctype; -+ if (krb5_k_encrypt(NULL, subkey, KG_USAGE_INITIATOR_SEAL, NULL, -+ &plain, &cipher) != 0) -+ abort(); -+ -+ /* Verify that the token is rejected by gss_unwrap(). */ -+ in.value = tokbuf; -+ in.length = 16 + cipher.ciphertext.length; -+ major = gss_unwrap(&minor, ctx, &in, &out, NULL, NULL); -+ if (major != GSS_S_DEFECTIVE_TOKEN) -+ abort(); -+ (void)gss_release_buffer(&minor, &out); -+ -+ /* Verify that the token is rejected by gss_unwrap_iov(). */ -+ iov[0].type = GSS_IOV_BUFFER_TYPE_STREAM; -+ iov[0].buffer = in; -+ iov[1].type = GSS_IOV_BUFFER_TYPE_DATA; -+ major = gss_unwrap_iov(&minor, ctx, NULL, NULL, iov, 2); -+ if (major != GSS_S_DEFECTIVE_TOKEN) -+ abort(); -+} -+ -+static void -+test_cfx_short_plaintext(gss_ctx_id_t ctx, krb5_key subkey) -+{ -+ OM_uint32 major, minor; -+ uint8_t tokbuf[128], zerobyte = 0; -+ krb5_data plain; -+ krb5_enc_data cipher; -+ gss_buffer_desc in, out; -+ -+ write_cfx_header(0, tokbuf); -+ -+ /* Encrypt a single byte, with no copy of the header. */ -+ plain = make_data(&zerobyte, 1); -+ cipher.ciphertext.data = (char *)tokbuf + 16; -+ cipher.ciphertext.length = sizeof(tokbuf) - 16; -+ cipher.enctype = subkey->keyblock.enctype; -+ if (krb5_k_encrypt(NULL, subkey, KG_USAGE_INITIATOR_SEAL, NULL, -+ &plain, &cipher) != 0) -+ abort(); -+ -+ /* Verify that the token is rejected by gss_unwrap(). */ -+ in.value = tokbuf; -+ in.length = 16 + cipher.ciphertext.length; -+ major = gss_unwrap(&minor, ctx, &in, &out, NULL, NULL); -+ if (major != GSS_S_DEFECTIVE_TOKEN) -+ abort(); -+ (void)gss_release_buffer(&minor, &out); -+} -+ -+static void -+test_cfx_large_ec(gss_ctx_id_t ctx, krb5_key subkey) -+{ -+ OM_uint32 major, minor; -+ uint8_t tokbuf[128] = { 0 }, plainbuf[20]; -+ krb5_data plain; -+ krb5_enc_data cipher; -+ gss_buffer_desc in, out; -+ -+ /* Construct a header with an EC value of 5. */ -+ write_cfx_header(5, tokbuf); -+ -+ /* Encrypt a 4-byte plaintext plus the header. */ -+ memcpy(plainbuf, "abcd", 4); -+ memcpy(plainbuf + 4, tokbuf, 16); -+ plain = make_data(plainbuf, 20); -+ cipher.ciphertext.data = (char *)tokbuf + 16; -+ cipher.ciphertext.length = sizeof(tokbuf) - 16; -+ cipher.enctype = subkey->keyblock.enctype; -+ if (krb5_k_encrypt(NULL, subkey, KG_USAGE_INITIATOR_SEAL, NULL, -+ &plain, &cipher) != 0) -+ abort(); -+ -+ /* Verify that the token is rejected by gss_unwrap(). */ -+ in.value = tokbuf; -+ in.length = 16 + cipher.ciphertext.length; -+ major = gss_unwrap(&minor, ctx, &in, &out, NULL, NULL); -+ if (major != GSS_S_DEFECTIVE_TOKEN) -+ abort(); -+ (void)gss_release_buffer(&minor, &out); -+} -+ -+static void -+test_iov_large_asn1_wrapper(gss_ctx_id_t ctx) -+{ -+ OM_uint32 minor, major; -+ uint8_t databuf[10] = { 0 }; -+ gss_iov_buffer_desc iov[2]; -+ -+ /* -+ * In this IOV array, the header contains a DER tag with a dangling eight -+ * bytes of length field. The data IOV indicates a total token length -+ * sufficient to contain the length bytes. -+ */ -+ iov[0].type = GSS_IOV_BUFFER_TYPE_HEADER; -+ iov[0].buffer.value = ealloc(2); -+ iov[0].buffer.length = 2; -+ memcpy(iov[0].buffer.value, "\x60\x88", 2); -+ iov[1].type = GSS_IOV_BUFFER_TYPE_DATA; -+ iov[1].buffer.value = databuf; -+ iov[1].buffer.length = 10; -+ major = gss_unwrap_iov(&minor, ctx, NULL, NULL, iov, 2); -+ if (major != GSS_S_DEFECTIVE_TOKEN) -+ abort(); -+ free(iov[0].buffer.value); -+} -+ - /* Process wrap and MIC tokens with incomplete headers. */ - static void - test_short_header(gss_ctx_id_t ctx) -@@ -387,9 +534,7 @@ try_accept(void *value, size_t len) - gss_ctx_id_t ctx = GSS_C_NO_CONTEXT; - - /* Copy the provided value to make input overruns more obvious. */ -- in.value = malloc(len); -- if (in.value == NULL) -- abort(); -+ in.value = ealloc(len); - memcpy(in.value, value, len); - in.length = len; - (void)gss_accept_sec_context(&minor, &ctx, GSS_C_NO_CREDENTIAL, &in, -@@ -424,11 +569,23 @@ test_short_encapsulation() - int - main(int argc, char **argv) - { -+ krb5_keyblock kb; -+ krb5_key cfx_subkey; - gss_ctx_id_t ctx; - size_t i; - -- ctx = make_fake_cfx_context(); -+ kb.enctype = ENCTYPE_AES128_CTS_HMAC_SHA1_96; -+ kb.length = 16; -+ kb.contents = (unsigned char *)"1234567887654321"; -+ if (krb5_k_create_key(NULL, &kb, &cfx_subkey) != 0) -+ abort(); -+ -+ ctx = make_fake_cfx_context(cfx_subkey); - test_bogus_1964_token(ctx); -+ test_cfx_altered_ec(ctx, cfx_subkey); -+ test_cfx_short_plaintext(ctx, cfx_subkey); -+ test_cfx_large_ec(ctx, cfx_subkey); -+ test_iov_large_asn1_wrapper(ctx); - free_fake_context(ctx); - - for (i = 0; i < sizeof(tests) / sizeof(*tests); i++) { --- -2.45.1 - diff --git a/0017-Remove-klist-s-defname-global-variable.patch b/0019-Remove-klist-s-defname-global-variable.patch similarity index 93% rename from 0017-Remove-klist-s-defname-global-variable.patch rename to 0019-Remove-klist-s-defname-global-variable.patch index 56beacc..1cf7d80 100644 --- a/0017-Remove-klist-s-defname-global-variable.patch +++ b/0019-Remove-klist-s-defname-global-variable.patch @@ -1,4 +1,4 @@ -From c5cdf6f71621569c6c389be720937ac97ace988f Mon Sep 17 00:00:00 2001 +From 05bb6d9c729a3c6a4ba35270368bc0f6e1875ad0 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Mon, 8 Jan 2024 16:52:27 +0100 Subject: [PATCH] Remove klist's defname global variable @@ -13,12 +13,14 @@ Convert "defname" to a local variable initialized at the beginning of show_ccache(). [ghudson@mit.edu: edited commit message] + +(cherry picked from commit 5b00197227231943bd2305328c8260dd0b0dbcf0) --- src/clients/klist/klist.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c -index 43392d2337..394c75b6b7 100644 +index b5ae96a843..b5808e5c93 100644 --- a/src/clients/klist/klist.c +++ b/src/clients/klist/klist.c @@ -53,7 +53,6 @@ int show_flags = 0, show_time = 0, status_only = 0, show_keys = 0; @@ -65,5 +67,5 @@ index 43392d2337..394c75b6b7 100644 krb5_error_code ret; krb5_ticket *tkt = NULL; -- -2.41.0 +2.45.1 diff --git a/krb5.spec b/krb5.spec index cc17078..88e4de7 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 6 +%global baserelease 1 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -24,7 +24,7 @@ %global krb5_version_major 1 %global krb5_version_minor 21 # For a release without a patch number set to %%nil -%global krb5_version_patch 2 +%global krb5_version_patch 3 %global krb5_version_major_minor %{krb5_version_major}.%{krb5_version_minor} %global krb5_version %{krb5_version_major_minor} @@ -59,7 +59,7 @@ Source13: kadmind.logrotate Source14: krb5-krb5kdc.conf Source15: %{name}-tests -Patch0001: 0001-Revert-Don-t-issue-session-keys-with-deprecated-enct.patch +Patch0001: 0001-downstream-Revert-Don-t-issue-session-keys-with-depr.patch Patch0002: 0002-downstream-ksu-pam-integration.patch Patch0003: 0003-downstream-SELinux-integration.patch Patch0004: 0004-downstream-fix-debuginfo-with-y.tab.c.patch @@ -74,11 +74,12 @@ Patch0012: 0012-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch Patch0013: 0013-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch Patch0014: 0014-Enable-PKINIT-if-at-least-one-group-is-available.patch Patch0015: 0015-Replace-ssl.wrap_socket-for-tests.patch -Patch0016: 0016-Fix-unimportant-memory-leaks.patch -Patch0017: 0017-Remove-klist-s-defname-global-variable.patch -Patch0018: 0018-Fix-vulnerabilities-in-GSS-message-token-handling.patch +Patch0016: 0016-Eliminate-old-style-function-declarations.patch +Patch0017: 0017-Fix-two-unlikely-memory-leaks.patch +Patch0018: 0018-Fix-unimportant-memory-leaks.patch +Patch0019: 0019-Remove-klist-s-defname-global-variable.patch -License: BSD-2-Clause AND (BSD-2-Clause OR GPL-2.0-or-later) AND BSD-3-Clause AND BSD-4-Clause AND FSFULLRWD AND HPND-export-US AND HPND-export-US-modify AND ISC AND MIT AND MIT-CMU AND OLDAP-2.8 AND RSA-MD +License: Brian-Gladman-2-Clause AND BSD-2-Clause AND (BSD-2-Clause OR GPL-2.0-or-later) AND BSD-2-Clause-first-lines AND BSD-3-Clause AND BSD-4-Clause AND CMU-Mach-nodoc AND FSFULLRWD AND HPND AND HPND-export2-US AND HPND-export-US AND HPND-export-US-acknowledgement AND HPND-export-US-modify AND ISC AND MIT AND MIT-CMU AND OLDAP-2.8 AND OpenVision URL: https://web.mit.edu/kerberos/www/ BuildRequires: autoconf, bison, make, flex, gawk, gettext, pkgconfig, sed BuildRequires: gcc, gcc-c++ @@ -713,6 +714,17 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Tue Jul 09 2024 Julien Rische - 1.21.3-1 +- New upstream version (1.21.3) +- CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c + Resolves: rhbz#2266732 +- CVE-2024-26461: Memory leak in src/lib/gssapi/krb5/k5sealv3.c + Resolves: rhbz#2266741 +- CVE-2024-26462: Memory leak in src/kdc/ndr.c + Resolves: rhbz#2266743 +- Add missing SPDX license identifiers + Resolves: rhbz#2265333 + * Mon Jul 08 2024 Julien Rische - 1.21.2-6 - CVE-2024-37370 CVE-2024-37371: GSS message token handling Resolves: rhbz#2294678 rhbz#2294680 diff --git a/sources b/sources index 58dc8d0..e8b99ef 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (krb5-1.21.2.tar.gz) = 4e09296b412383d53872661718dbfaa90201e0d85f69db48e57a8d4bd73c95a90c7ec7b6f0f325f6bc967f8d203b256b071c0191facf080aca0e2caec5d0ac49 -SHA512 (krb5-1.21.2.tar.gz.asc) = 1cee1ed77047067d7b6fb3620ffa6f5807d4182ae7cfeec6d5cc847c99f30c6dd2a5c1a160d992a13eb6d84754b202895a982111618711f3c14f4aa33c07d9e9 +SHA512 (krb5-1.21.3.tar.gz) = 87bc06607f4d95ff604169cea22180703a42d667af05f66f1569b8bd592670c42820b335e5c279e8b4f066d1e7da20f1948a1e4def7c5d295c170cbfc7f49c71 +SHA512 (krb5-1.21.3.tar.gz.asc) = 8992a5f5247315b9846aa73be4ee1ea223c0231a52d5c6c28718b1f3e3b45d62e2dad4aa5543a83163d1369bb79886b6c1c22766f22d8aa2f6b2575c54d0075c From 9767c1c24e7e33d616e286f5b3cfb70dd4ac87d7 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 18 Jul 2024 12:40:10 +0000 Subject: [PATCH 294/304] Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index 88e4de7..9df5405 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 1 +%global baserelease 2 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -714,6 +714,9 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Thu Jul 18 2024 Fedora Release Engineering - 1.21.3-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + * Tue Jul 09 2024 Julien Rische - 1.21.3-1 - New upstream version (1.21.3) - CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c From 4c1f565dfadd698f3609de1b49745031c5ccdad6 Mon Sep 17 00:00:00 2001 From: Gordon Messmer Date: Sat, 3 Aug 2024 19:35:59 -0700 Subject: [PATCH 295/304] Examine the server process GOT for signs of tampering. --- tests/got-audit/got-audit.gdb | 2 + tests/got-audit/kdc.conf | 12 ++++ tests/got-audit/krb5.conf | 29 ++++++++ tests/got-audit/main.fmf | 12 ++++ tests/got-audit/runtest.sh | 121 ++++++++++++++++++++++++++++++++++ 5 files changed, 176 insertions(+) create mode 100644 tests/got-audit/got-audit.gdb create mode 100644 tests/got-audit/kdc.conf create mode 100644 tests/got-audit/krb5.conf create mode 100644 tests/got-audit/main.fmf create mode 100755 tests/got-audit/runtest.sh diff --git a/tests/got-audit/got-audit.gdb b/tests/got-audit/got-audit.gdb new file mode 100644 index 0000000..6661297 --- /dev/null +++ b/tests/got-audit/got-audit.gdb @@ -0,0 +1,2 @@ +gef config gef.disable_color True +got-audit --all diff --git a/tests/got-audit/kdc.conf b/tests/got-audit/kdc.conf new file mode 100644 index 0000000..ed7299f --- /dev/null +++ b/tests/got-audit/kdc.conf @@ -0,0 +1,12 @@ +[kdcdefaults] + kdc_ports = 88 + kdc_tcp_ports = 88 + +[realms] + ${krb5REALM1} = { + #master_key_type = aes256-cts + acl_file = /var/kerberos/krb5kdc/kadm5.acl + dict_file = /usr/share/dict/words + admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab + supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal + } diff --git a/tests/got-audit/krb5.conf b/tests/got-audit/krb5.conf new file mode 100644 index 0000000..6979cb7 --- /dev/null +++ b/tests/got-audit/krb5.conf @@ -0,0 +1,29 @@ +# To opt out of the system crypto-policies configuration of krb5, remove the +# symlink at /etc/krb5.conf.d/crypto-policies which will not be recreated. +includedir /etc/krb5.conf.d/ + +[logging] + default = FILE:/var/log/krb5libs.log + kdc = FILE:/var/log/krb5kdc.log + admin_server = FILE:/var/log/kadmind.log + +[libdefaults] + default_realm = ${krb5REALM1} + dns_lookup_realm = false + ticket_lifetime = 24h + renew_lifetime = 7d + forwardable = true + rdns = false + default_ccache_name = KEYRING:persistent:%{uid} + +[realms] + ${krb5REALM1} = { + kdc = localhost.localdomain + admin_server = localhost.localdomain + } + +[domain_realm] + ${krb5HostName} = ${krb5REALM1} + +[capaths] + ${krb5REALM1} = . diff --git a/tests/got-audit/main.fmf b/tests/got-audit/main.fmf new file mode 100644 index 0000000..f2c1f97 --- /dev/null +++ b/tests/got-audit/main.fmf @@ -0,0 +1,12 @@ +summary: Audit the GOT for signs of tampering +description: | + Pointers in the server process GOT will be checked to ensure that + each function pointer's value is within a shared object file + that exports a symbol of that name, and that no shared object + files export conflicting symbols. +contact: Gordon Messmer +require+: + - gdb-gef # needed to test got-audit + - krb5-server +test: ./runtest.sh +framework: beakerlib diff --git a/tests/got-audit/runtest.sh b/tests/got-audit/runtest.sh new file mode 100755 index 0000000..925a04e --- /dev/null +++ b/tests/got-audit/runtest.sh @@ -0,0 +1,121 @@ +#!/bin/bash +# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +# +# runtest.sh of /CoreOS/openssh/Sanity/got-audit +# Description: Check pointers in the server process GOT for signs of tampering +# Author: Gordon Messmer +# + +# Include Beaker environment +. /usr/share/beakerlib/beakerlib.sh || exit 1 + +krb5REALM1='TEST1.REDHAT.COM' +krb5HostName=`hostname` +krb5DomainName=`hostname -d` +krb5User='alice' +krb5UserPass='alice' +krb5UserKrbPass='aaa' +krb5User2='bob' +krb5User3='carl' +krb5KDCPass='qwe' +krb5RootPass='rrr' + +krb5conf="/etc/krb5.conf" +krb5confdir="/etc/krb5.conf.d" +krb5kdcconf="/var/kerberos/krb5kdc/kdc.conf" +krb5kadmacl="/var/kerberos/krb5kdc/kadm5.acl" + +rlJournalStart + rlPhaseStartSetup + rlServiceStart sshd + rlRun "TestDir=\$(pwd)" + rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" + rlRun "pushd $TmpDir" + rlRun "auditfile=\$(mktemp --tmpdir=${TmpDir})" + rlPhaseEnd + + rlPhaseStartSetup "KDC and kadmind setup" + # Stop and backup + rlRun "rlServiceStop kadmin krb5kdc" + rlRun "rm -f /var/kerberos/krb5kdc/principal* /var/kerberos/krb5kdc/.k5*" + rlFileBackup $krb5conf /var/kerberos/krb5kdc /etc/sysconfig/{kadmin,krb5kdc} /etc/hosts + rlFileBackup --clean /root/.k5login + [ -e /etc/krb5.keytab ] && rlFileBackup /etc/krb5.keytab + [ -e $krb5confdir ] && rlFileBackup $krb5confdir + # Basic setup of KDC and krb5.conf + rlRun "sed -i \"s/\[libdefaults\]/[libdefaults]\n default_realm = $krb5REALM1/\" $krb5conf" + rlRun "sed -i \"s/\[realms\]/[realms]\n $krb5REALM1 = {\n kdc = $krb5HostName\n admin_server = $krb5HostName\n }/\" $krb5conf" + if [ "$krb5DomainName" ]; then + rlRun "sed -i \"s/\[domain_realm\]/[domain_realm]\n .$krb5DomainName = $krb5REALM1\n $krb5DomainName = $krb5REALM1/\" $krb5conf" + else + rlRun "sed -i \"s/\[domain_realm\]/[domain_realm]\n $krb5HostName = $krb5REALM1/\" $krb5conf" + fi + rlRun "sed -i s/EXAMPLE.COM/$krb5REALM1/ $krb5kdcconf" + # Configure the kadmin ACL + rlRun "echo \"*/master@$krb5REALM1 *\" > $krb5kadmacl" + if rlIsFedora '>=31';then + rlLog "Modify supported_enctypes for Fedora >=31. Remove *DES ciphers." + rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal/\" /var/kerberos/krb5kdc/kdc.conf" + elif rlIsRHEL '8' && [ `rpm -q --qf '%{VERSION}' krb5-server | cut -d"." -f2` -lt 18 ];then + rlLog "Modify supported_enctypes for RHEL-8." + rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal/\" /var/kerberos/krb5kdc/kdc.conf" + else + #RHEL-8 Bug 1802334 - [Rebase] krb5: rebase to 1.18: + #- Removal of *DES encryption types + #https://bugzilla.redhat.com/show_bug.cgi?id=1802334 + rlLog "Modify supported_enctypes for RHEL-8 with krb-1.18. Remove *DES ciphers." + rlRun "sed -i \"s/supported_enctypes.*/supported_enctypes = aes256-cts:normal aes128-cts:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal/\" /var/kerberos/krb5kdc/kdc.conf" + fi + # Create the realm databases + rlRun "rngd -r /dev/urandom" + rlRun "kdb5_util create -s -r $krb5REALM1 -P $krb5KDCPass" + rlRun "rlServiceStart kadmin krb5kdc" + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -pw $krb5RootPass root/master\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -pw $krb5UserKrbPass $krb5User\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"addprinc -randkey host/$krb5HostName\"" + rlRun "kadmin.local -r $krb5REALM1 -q \"ktadd host/$krb5HostName\"" + # Create test system user + [ $krb5User != "root" ] && rlRun "useradd $krb5User" + rlRun "echo $krb5UserPass | passwd --stdin $krb5User" + rlPhaseEnd + + rlPhaseStartTest "Run GEF got-audit" + rlRun "systemctl restart krb5kdc.service" + rlRun "systemctl restart kadmin.service" + rlRun "systemctl --no-pager status krb5kdc.service" + rlRun "systemctl --no-pager status kadmin.service" + + rlRun "SERVICE_PID=\$( systemctl show --property=MainPID krb5kdc.service | cut -f2 -d= )" + rlRun "echo SERVICE_PID is '$SERVICE_PID'" + [ -n "$SERVICE_PID" ] || rlFail "No service pid was found" + rlRun "gdb-gef --pid '$SERVICE_PID' --command='$TestDir'/got-audit.gdb --batch > '$auditfile'" + # Basic test: ensure that at least one symbol is found in libc.so, + # to verify that the report looks plausible. + rlAssertGrep " : /.*/libc.so" "$auditfile" + # Ensure the got-audit did not report any errors + rlAssertNotGrep " :: ERROR" "$auditfile" + rlRun "cp '$auditfile' '$TMT_TEST_DATA'/krb5kdc-got-audit.txt" + + rlRun "SERVICE_PID=\$( systemctl show --property=MainPID kadmin.service | cut -f2 -d= )" + rlRun "echo SERVICE_PID is '$SERVICE_PID'" + [ -n "$SERVICE_PID" ] || rlFail "No service pid was found" + rlRun "gdb-gef --pid '$SERVICE_PID' --command='$TestDir'/got-audit.gdb --batch > '$auditfile'" + # Basic test: ensure that at least one symbol is found in libc.so, + # to verify that the report looks plausible. + rlAssertGrep " : /.*/libc.so" "$auditfile" + # Ensure the got-audit did not report any errors + rlAssertNotGrep " :: ERROR" "$auditfile" + rlRun "cp '$auditfile' '$TMT_TEST_DATA'/kadmin-got-audit.txt" + rlPhaseEnd + + rlPhaseStartCleanup + rlRun "rm -rf /var/kerberos/krb5kdc/* /var/kerberos/krb5kdc/.k5* /etc/krb5* /etc/sysconfig/{kadmin,krb5kdc}" + rlFileRestore + rlServiceRestore krb5kdc kadmin + [ $krb5User != "root" ] && rlRun "userdel -r -f $krb5User" + rlRun "popd" + rlRun "rm -r $TmpDir" 0 "Removing tmp directory" + rlPhaseEnd +rlJournalPrintText +rlJournalEnd From 9e0ac6c61688e049e1b9d2868eabe559bdefd27c Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 30 Oct 2024 12:30:57 +0100 Subject: [PATCH 296/304] krb5 1.21.3-3 - libkrad: implement support for Message-Authenticator (CVE-2024-3596) Resolves: rhbz#2304071 - Fix various issues detected by static analysis Resolves: rhbz#2322704 - Remove RSA protocol for PKINIT Resolves: rhbz#2322706 - Make TCP waiting time configurable Resolves: rhbz#2322711 Signed-off-by: Julien Rische --- ...onnection-on-KDC_ERR_SVC_UNAVAILABLE.patch | 34 + ...uest_timeout-configuration-parameter.patch | 226 +++ ...-indefinitely-on-KDC-TCP-connections.patch | 138 ++ 0023-Remove-PKINIT-RSA-support.patch | 1297 +++++++++++++++++ ...s-issues-detected-by-static-analysis.patch | 265 ++++ ...e-and-verify-message-MACs-in-libkrad.patch | 629 ++++++++ krb5.spec | 18 +- 7 files changed, 2606 insertions(+), 1 deletion(-) create mode 100644 0020-End-connection-on-KDC_ERR_SVC_UNAVAILABLE.patch create mode 100644 0021-Add-request_timeout-configuration-parameter.patch create mode 100644 0022-Wait-indefinitely-on-KDC-TCP-connections.patch create mode 100644 0023-Remove-PKINIT-RSA-support.patch create mode 100644 0024-Fix-various-issues-detected-by-static-analysis.patch create mode 100644 0025-Generate-and-verify-message-MACs-in-libkrad.patch diff --git a/0020-End-connection-on-KDC_ERR_SVC_UNAVAILABLE.patch b/0020-End-connection-on-KDC_ERR_SVC_UNAVAILABLE.patch new file mode 100644 index 0000000..1674fd6 --- /dev/null +++ b/0020-End-connection-on-KDC_ERR_SVC_UNAVAILABLE.patch @@ -0,0 +1,34 @@ +From d7bcca2a215de880f4419afc450a96a747d48560 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 27 Oct 2023 00:44:53 -0400 +Subject: [PATCH] End connection on KDC_ERR_SVC_UNAVAILABLE + +In sendto_kdc.c:service_fds(), if a message handler indicates that a +message should be discarded, kill the connection so we don't continue +waiting on it for more data. + +ticket: 7899 +(cherry picked from commit ca80f64c786341d5871ae1de18142e62af64f7b9) +--- + src/lib/krb5/os/sendto_kdc.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c +index 0f4bf23a95..262edf09b4 100644 +--- a/src/lib/krb5/os/sendto_kdc.c ++++ b/src/lib/krb5/os/sendto_kdc.c +@@ -1440,7 +1440,10 @@ service_fds(krb5_context context, struct select_state *selstate, + if (msg_handler != NULL) { + krb5_data reply = make_data(state->in.buf, state->in.pos); + +- stop = (msg_handler(context, &reply, msg_handler_data) != 0); ++ if (!msg_handler(context, &reply, msg_handler_data)) { ++ kill_conn(context, state, selstate); ++ stop = 0; ++ } + } + + if (stop) { +-- +2.46.0 + diff --git a/0021-Add-request_timeout-configuration-parameter.patch b/0021-Add-request_timeout-configuration-parameter.patch new file mode 100644 index 0000000..5b84513 --- /dev/null +++ b/0021-Add-request_timeout-configuration-parameter.patch @@ -0,0 +1,226 @@ +From a07b3ae29fd972c40e30b95f6bcc8fb3ed4d9991 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 26 Oct 2023 14:20:34 -0400 +Subject: [PATCH] Add request_timeout configuration parameter + +Add a parameter to limit the total amount of time taken for a KDC or +password change request. + +ticket: 9106 (new) +(cherry picked from commit 802318cda963456b3ed7856c836e89da891483be) +--- + doc/admin/conf_files/krb5_conf.rst | 9 ++++++ + src/include/k5-int.h | 2 ++ + src/lib/krb5/krb/init_ctx.c | 14 +++++++- + src/lib/krb5/os/sendto_kdc.c | 51 ++++++++++++++++++++---------- + 4 files changed, 58 insertions(+), 18 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index a33711d918..65fb592d98 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -356,6 +356,15 @@ The libdefaults section may contain any of the following relations: + (:ref:`duration` string.) Sets the default renewable lifetime + for initial ticket requests. The default value is 0. + ++**request_timeout** ++ (:ref:`duration` string.) Sets the maximum total time for KDC or ++ password change requests. This timeout does not affect the ++ intervals between requests, so setting a low timeout may result in ++ fewer requests being attempted and/or some servers not being ++ contacted. A value of 0 indicates no specific maximum, in which ++ case requests will time out if no server responds after several ++ tries. The default value is 0. (New in release 1.22.) ++ + **spake_preauth_groups** + A whitespace or comma-separated list of words which specifies the + groups allowed for SPAKE preauthentication. The possible values +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index b3e07945c1..69d6a6f569 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -296,6 +296,7 @@ typedef unsigned char u_char; + #define KRB5_CONF_SPAKE_PREAUTH_INDICATOR "spake_preauth_indicator" + #define KRB5_CONF_SPAKE_PREAUTH_KDC_CHALLENGE "spake_preauth_kdc_challenge" + #define KRB5_CONF_SPAKE_PREAUTH_GROUPS "spake_preauth_groups" ++#define KRB5_CONF_REQUEST_TIMEOUT "request_timeout" + #define KRB5_CONF_TICKET_LIFETIME "ticket_lifetime" + #define KRB5_CONF_UDP_PREFERENCE_LIMIT "udp_preference_limit" + #define KRB5_CONF_UNLOCKITER "unlockiter" +@@ -1200,6 +1201,7 @@ struct _krb5_context { + kdb5_dal_handle *dal_handle; + /* allowable clock skew */ + krb5_deltat clockskew; ++ krb5_deltat req_timeout; + krb5_flags kdc_default_options; + krb5_flags library_options; + krb5_boolean profile_secure; +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index 2b5abcd817..582a2945ff 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -157,7 +157,7 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + krb5_context ctx = 0; + krb5_error_code retval; + int tmp; +- char *plugin_dir = NULL; ++ char *plugin_dir = NULL, *timeout_str = NULL; + + /* Verify some assumptions. If the assumptions hold and the + compiler is optimizing, this should result in no code being +@@ -240,6 +240,17 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + get_integer(ctx, KRB5_CONF_CLOCKSKEW, DEFAULT_CLOCKSKEW, &tmp); + ctx->clockskew = tmp; + ++ retval = profile_get_string(ctx->profile, KRB5_CONF_LIBDEFAULTS, ++ KRB5_CONF_REQUEST_TIMEOUT, NULL, NULL, ++ &timeout_str); ++ if (retval) ++ goto cleanup; ++ if (timeout_str != NULL) { ++ retval = krb5_string_to_deltat(timeout_str, &ctx->req_timeout); ++ if (retval) ++ goto cleanup; ++ } ++ + get_integer(ctx, KRB5_CONF_KDC_DEFAULT_OPTIONS, KDC_OPT_RENEWABLE_OK, + &tmp); + ctx->kdc_default_options = tmp; +@@ -281,6 +292,7 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + + cleanup: + profile_release_string(plugin_dir); ++ profile_release_string(timeout_str); + krb5_free_context(ctx); + return retval; + } +diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c +index 262edf09b4..98247a1089 100644 +--- a/src/lib/krb5/os/sendto_kdc.c ++++ b/src/lib/krb5/os/sendto_kdc.c +@@ -1395,34 +1395,41 @@ get_endtime(time_ms endtime, struct conn_state *conns) + + static krb5_boolean + service_fds(krb5_context context, struct select_state *selstate, +- time_ms interval, struct conn_state *conns, ++ time_ms interval, time_ms timeout, struct conn_state *conns, + struct select_state *seltemp, const krb5_data *realm, + int (*msg_handler)(krb5_context, const krb5_data *, void *), + void *msg_handler_data, struct conn_state **winner_out) + { + int e, selret = 0; +- time_ms endtime; ++ time_ms curtime, interval_end, endtime; + struct conn_state *state; + + *winner_out = NULL; + +- e = get_curtime_ms(&endtime); ++ e = get_curtime_ms(&curtime); + if (e) + return TRUE; +- endtime += interval; ++ interval_end = curtime + interval; + + e = 0; + while (selstate->nfds > 0) { +- e = cm_select_or_poll(selstate, get_endtime(endtime, conns), +- seltemp, &selret); ++ endtime = get_endtime(interval_end, conns); ++ /* Don't wait longer than the whole request should last. */ ++ if (timeout && endtime > timeout) ++ endtime = timeout; ++ e = cm_select_or_poll(selstate, endtime, seltemp, &selret); + if (e == EINTR) + continue; + if (e != 0) + break; + +- if (selret == 0) +- /* Timeout, return to caller. */ ++ if (selret == 0) { ++ /* We timed out. Stop if we hit the overall request timeout. */ ++ if (timeout && (get_curtime_ms(&curtime) || curtime >= timeout)) ++ return TRUE; ++ /* Otherwise return to the caller to send the next request. */ + return FALSE; ++ } + + /* Got something on a socket, process it. */ + for (state = conns; state != NULL; state = state->next) { +@@ -1495,7 +1502,7 @@ k5_sendto(krb5_context context, const krb5_data *message, + void *msg_handler_data) + { + int pass; +- time_ms delay; ++ time_ms delay, timeout = 0; + krb5_error_code retval; + struct conn_state *conns = NULL, *state, **tailptr, *next, *winner; + size_t s; +@@ -1505,6 +1512,13 @@ k5_sendto(krb5_context context, const krb5_data *message, + + *reply = empty_data(); + ++ if (context->req_timeout) { ++ retval = get_curtime_ms(&timeout); ++ if (retval) ++ return retval; ++ timeout += 1000 * context->req_timeout; ++ } ++ + /* One for use here, listing all our fds in use, and one for + * temporary use in service_fds, for the fds of interest. */ + sel_state = malloc(2 * sizeof(*sel_state)); +@@ -1532,8 +1546,9 @@ k5_sendto(krb5_context context, const krb5_data *message, + if (maybe_send(context, state, message, sel_state, realm, + callback_info)) + continue; +- done = service_fds(context, sel_state, 1000, conns, seltemp, +- realm, msg_handler, msg_handler_data, &winner); ++ done = service_fds(context, sel_state, 1000, timeout, conns, ++ seltemp, realm, msg_handler, msg_handler_data, ++ &winner); + } + } + +@@ -1545,13 +1560,13 @@ k5_sendto(krb5_context context, const krb5_data *message, + if (maybe_send(context, state, message, sel_state, realm, + callback_info)) + continue; +- done = service_fds(context, sel_state, 1000, conns, seltemp, ++ done = service_fds(context, sel_state, 1000, timeout, conns, seltemp, + realm, msg_handler, msg_handler_data, &winner); + } + + /* Wait for two seconds at the end of the first pass. */ + if (!done) { +- done = service_fds(context, sel_state, 2000, conns, seltemp, ++ done = service_fds(context, sel_state, 2000, timeout, conns, seltemp, + realm, msg_handler, msg_handler_data, &winner); + } + +@@ -1562,15 +1577,17 @@ k5_sendto(krb5_context context, const krb5_data *message, + if (maybe_send(context, state, message, sel_state, realm, + callback_info)) + continue; +- done = service_fds(context, sel_state, 1000, conns, seltemp, +- realm, msg_handler, msg_handler_data, &winner); ++ done = service_fds(context, sel_state, 1000, timeout, conns, ++ seltemp, realm, msg_handler, msg_handler_data, ++ &winner); + if (sel_state->nfds == 0) + break; + } + /* Wait for the delay backoff at the end of this pass. */ + if (!done) { +- done = service_fds(context, sel_state, delay, conns, seltemp, +- realm, msg_handler, msg_handler_data, &winner); ++ done = service_fds(context, sel_state, delay, timeout, conns, ++ seltemp, realm, msg_handler, msg_handler_data, ++ &winner); + } + if (sel_state->nfds == 0) + break; +-- +2.46.0 + diff --git a/0022-Wait-indefinitely-on-KDC-TCP-connections.patch b/0022-Wait-indefinitely-on-KDC-TCP-connections.patch new file mode 100644 index 0000000..26b884b --- /dev/null +++ b/0022-Wait-indefinitely-on-KDC-TCP-connections.patch @@ -0,0 +1,138 @@ +From 1da153d97d7fb30a44fca35f9b71b8f4ed5385b9 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Thu, 26 Oct 2023 16:26:42 -0400 +Subject: [PATCH] Wait indefinitely on KDC TCP connections + +When making a KDC or password change request, wait indefinitely +(limited only by request_timeout if set) once a KDC has accepted a TCP +connection. + +ticket: 9105 (new) +(cherry picked from commit 6436a3808061da787a43c6810f5f0370cdfb6e36) +--- + doc/admin/conf_files/krb5_conf.rst | 2 +- + src/lib/krb5/os/sendto_kdc.c | 50 ++++++++++++++++-------------- + 2 files changed, 27 insertions(+), 25 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index 65fb592d98..b7284c47df 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -357,7 +357,7 @@ The libdefaults section may contain any of the following relations: + for initial ticket requests. The default value is 0. + + **request_timeout** +- (:ref:`duration` string.) Sets the maximum total time for KDC or ++ (:ref:`duration` string.) Sets the maximum total time for KDC and + password change requests. This timeout does not affect the + intervals between requests, so setting a low timeout may result in + fewer requests being attempted and/or some servers not being +diff --git a/src/lib/krb5/os/sendto_kdc.c b/src/lib/krb5/os/sendto_kdc.c +index 98247a1089..924f5b2d26 100644 +--- a/src/lib/krb5/os/sendto_kdc.c ++++ b/src/lib/krb5/os/sendto_kdc.c +@@ -134,7 +134,6 @@ struct conn_state { + krb5_data callback_buffer; + size_t server_index; + struct conn_state *next; +- time_ms endtime; + krb5_boolean defer; + struct { + const char *uri_path; +@@ -344,15 +343,19 @@ cm_select_or_poll(const struct select_state *in, time_ms endtime, + struct select_state *out, int *sret) + { + #ifndef USE_POLL +- struct timeval tv; ++ struct timeval tv, *tvp; + #endif + krb5_error_code retval; + time_ms curtime, interval; + +- retval = get_curtime_ms(&curtime); +- if (retval != 0) +- return retval; +- interval = (curtime < endtime) ? endtime - curtime : 0; ++ if (endtime != 0) { ++ retval = get_curtime_ms(&curtime); ++ if (retval != 0) ++ return retval; ++ interval = (curtime < endtime) ? endtime - curtime : 0; ++ } else { ++ interval = -1; ++ } + + /* We don't need a separate copy of the selstate for poll, but use one for + * consistency with how we use select. */ +@@ -361,9 +364,14 @@ cm_select_or_poll(const struct select_state *in, time_ms endtime, + #ifdef USE_POLL + *sret = poll(out->fds, out->nfds, interval); + #else +- tv.tv_sec = interval / 1000; +- tv.tv_usec = interval % 1000 * 1000; +- *sret = select(out->max, &out->rfds, &out->wfds, &out->xfds, &tv); ++ if (interval != -1) { ++ tv.tv_sec = interval / 1000; ++ tv.tv_usec = interval % 1000 * 1000; ++ tvp = &tv; ++ } else { ++ tvp = NULL; ++ } ++ *sret = select(out->max, &out->rfds, &out->wfds, &out->xfds, tvp); + #endif + + return (*sret < 0) ? SOCKET_ERRNO : 0; +@@ -1099,11 +1107,6 @@ service_tcp_connect(krb5_context context, const krb5_data *realm, + } + + conn->state = WRITING; +- +- /* Record this connection's timeout for service_fds. */ +- if (get_curtime_ms(&conn->endtime) == 0) +- conn->endtime += 10000; +- + return conn->service_write(context, realm, conn, selstate); + } + +@@ -1378,19 +1381,18 @@ kill_conn: + return FALSE; + } + +-/* Return the maximum of endtime and the endtime fields of all currently active +- * TCP connections. */ +-static time_ms +-get_endtime(time_ms endtime, struct conn_state *conns) ++/* Return true if conns contains any states with connected TCP sockets. */ ++static krb5_boolean ++any_tcp_connections(struct conn_state *conns) + { + struct conn_state *state; + + for (state = conns; state != NULL; state = state->next) { +- if ((state->state == READING || state->state == WRITING) && +- state->endtime > endtime) +- endtime = state->endtime; ++ if (state->addr.transport != UDP && ++ (state->state == READING || state->state == WRITING)) ++ return TRUE; + } +- return endtime; ++ return FALSE; + } + + static krb5_boolean +@@ -1413,9 +1415,9 @@ service_fds(krb5_context context, struct select_state *selstate, + + e = 0; + while (selstate->nfds > 0) { +- endtime = get_endtime(interval_end, conns); ++ endtime = any_tcp_connections(conns) ? 0 : interval_end; + /* Don't wait longer than the whole request should last. */ +- if (timeout && endtime > timeout) ++ if (timeout && (!endtime || endtime > timeout)) + endtime = timeout; + e = cm_select_or_poll(selstate, endtime, seltemp, &selret); + if (e == EINTR) +-- +2.46.0 + diff --git a/0023-Remove-PKINIT-RSA-support.patch b/0023-Remove-PKINIT-RSA-support.patch new file mode 100644 index 0000000..7672f02 --- /dev/null +++ b/0023-Remove-PKINIT-RSA-support.patch @@ -0,0 +1,1297 @@ +From 4f008362334dc2d66d67453448061e19feda889d Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sun, 26 Nov 2023 17:42:34 -0500 +Subject: [PATCH] Remove PKINIT RSA support + +RSA mode is no longer needed for interoperability. Reduce the attack +surface of clients and KDCs by removing support for it. + +ticket: 9108 (new) +(cherry picked from commit 401f584526e501b68e7516c17d8e467883f8f210) +--- + doc/user/user_commands/kinit.rst | 4 - + src/plugins/preauth/pkinit/pkinit.h | 2 - + src/plugins/preauth/pkinit/pkinit_clnt.c | 235 +++----- + src/plugins/preauth/pkinit/pkinit_crypto.h | 39 -- + .../preauth/pkinit/pkinit_crypto_openssl.c | 504 ------------------ + src/plugins/preauth/pkinit/pkinit_lib.c | 2 - + src/plugins/preauth/pkinit/pkinit_srv.c | 208 +++----- + src/plugins/preauth/pkinit/pkinit_trace.h | 9 - + src/tests/t_pkinit.py | 7 - + src/windows/leash/htmlhelp/html/KINIT.htm | 3 - + 10 files changed, 131 insertions(+), 882 deletions(-) + +diff --git a/doc/user/user_commands/kinit.rst b/doc/user/user_commands/kinit.rst +index 5b105e35a5..d947e83cc6 100644 +--- a/doc/user/user_commands/kinit.rst ++++ b/doc/user/user_commands/kinit.rst +@@ -193,10 +193,6 @@ OPTIONS + **X509_anchors**\ =\ *value* + specify where to find trusted X509 anchor information + +- **flag_RSA_PROTOCOL**\ [**=yes**] +- specify use of RSA, rather than the default Diffie-Hellman +- protocol +- + **disable_freshness**\ [**=yes**] + disable sending freshness tokens (for testing purposes only) + +diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h +index 66f92d8f03..5ab0f4bc28 100644 +--- a/src/plugins/preauth/pkinit/pkinit.h ++++ b/src/plugins/preauth/pkinit/pkinit.h +@@ -146,7 +146,6 @@ typedef struct _pkinit_plg_opts { + int require_eku; /* require EKU checking (default is true) */ + int accept_secondary_eku;/* accept secondary EKU (default is false) */ + int allow_upn; /* allow UPN-SAN instead of pkinit-SAN */ +- int dh_or_rsa; /* selects DH or RSA based pkinit */ + int require_crl_checking; /* require CRL for a CA (default is false) */ + int require_freshness; /* require freshness token (default is false) */ + int disable_freshness; /* disable freshness token on client for testing */ +@@ -160,7 +159,6 @@ typedef struct _pkinit_req_opts { + int require_eku; + int accept_secondary_eku; + int allow_upn; +- int dh_or_rsa; + int require_crl_checking; + int dh_size; /* initial request DH modulus size (default=1024) */ + int require_hostname_match; +diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c +index ea9ba454df..54e7537600 100644 +--- a/src/plugins/preauth/pkinit/pkinit_clnt.c ++++ b/src/plugins/preauth/pkinit/pkinit_clnt.c +@@ -191,7 +191,6 @@ pkinit_as_req_create(krb5_context context, + krb5_auth_pack auth_pack; + krb5_pa_pk_as_req *req = NULL; + krb5_algorithm_identifier **cmstypes = NULL; +- int protocol = reqctx->opts->dh_or_rsa; + + pkiDebug("pkinit_as_req_create pa_type = %d\n", reqctx->pa_type); + +@@ -214,29 +213,14 @@ pkinit_as_req_create(krb5_context context, + if (retval) + goto cleanup; + +- switch(protocol) { +- case DH_PROTOCOL: +- TRACE_PKINIT_CLIENT_REQ_DH(context); +- pkiDebug("as_req: DH key transport algorithm\n"); ++ TRACE_PKINIT_CLIENT_REQ_DH(context); + +- /* create client-side DH keys */ +- retval = client_create_dh(context, plgctx->cryptoctx, +- reqctx->cryptoctx, reqctx->idctx, +- reqctx->opts->dh_size, &spki); +- auth_pack.clientPublicValue = spki; +- if (retval != 0) { +- pkiDebug("failed to create dh parameters\n"); +- goto cleanup; +- } +- break; +- case RSA_PROTOCOL: +- TRACE_PKINIT_CLIENT_REQ_RSA(context); +- pkiDebug("as_req: RSA key transport algorithm\n"); +- break; +- default: +- pkiDebug("as_req: unknown key transport protocol %d\n", +- protocol); +- retval = -1; ++ /* create client-side DH keys */ ++ retval = client_create_dh(context, plgctx->cryptoctx, reqctx->cryptoctx, ++ reqctx->idctx, reqctx->opts->dh_size, &spki); ++ auth_pack.clientPublicValue = spki; ++ if (retval != 0) { ++ pkiDebug("failed to create dh parameters\n"); + goto cleanup; + } + +@@ -553,49 +537,34 @@ pkinit_as_rep_parse(krb5_context context, + return retval; + } + +- switch(kdc_reply->choice) { +- case choice_pa_pk_as_rep_dhInfo: +- pkiDebug("as_rep: DH key transport algorithm\n"); ++ if (kdc_reply->choice != choice_pa_pk_as_rep_dhInfo) { ++ pkiDebug("unknown as_rep type %d\n", kdc_reply->choice); ++ retval = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; ++ } ++ + #ifdef DEBUG_ASN1 +- print_buffer_bin(kdc_reply->u.dh_Info.dhSignedData.data, +- kdc_reply->u.dh_Info.dhSignedData.length, "/tmp/client_kdc_signeddata"); ++ print_buffer_bin(kdc_reply->u.dh_Info.dhSignedData.data, ++ kdc_reply->u.dh_Info.dhSignedData.length, ++ "/tmp/client_kdc_signeddata"); + #endif +- if ((retval = cms_signeddata_verify(context, plgctx->cryptoctx, +- reqctx->cryptoctx, reqctx->idctx, CMS_SIGN_SERVER, +- reqctx->opts->require_crl_checking, +- (unsigned char *) +- kdc_reply->u.dh_Info.dhSignedData.data, +- kdc_reply->u.dh_Info.dhSignedData.length, +- (unsigned char **)&dh_data.data, +- &dh_data.length, +- NULL, NULL, NULL)) != 0) { +- pkiDebug("failed to verify pkcs7 signed data\n"); +- TRACE_PKINIT_CLIENT_REP_DH_FAIL(context); +- goto cleanup; +- } +- TRACE_PKINIT_CLIENT_REP_DH(context); +- break; +- case choice_pa_pk_as_rep_encKeyPack: +- pkiDebug("as_rep: RSA key transport algorithm\n"); +- if ((retval = cms_envelopeddata_verify(context, plgctx->cryptoctx, +- reqctx->cryptoctx, reqctx->idctx, pa_type, +- reqctx->opts->require_crl_checking, +- (unsigned char *) +- kdc_reply->u.encKeyPack.data, +- kdc_reply->u.encKeyPack.length, +- (unsigned char **)&dh_data.data, +- &dh_data.length)) != 0) { +- pkiDebug("failed to verify pkcs7 enveloped data\n"); +- TRACE_PKINIT_CLIENT_REP_RSA_FAIL(context); +- goto cleanup; +- } +- TRACE_PKINIT_CLIENT_REP_RSA(context); +- break; +- default: +- pkiDebug("unknown as_rep type %d\n", kdc_reply->choice); +- retval = -1; ++ retval = cms_signeddata_verify(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, reqctx->idctx, ++ CMS_SIGN_SERVER, ++ reqctx->opts->require_crl_checking, ++ (unsigned char *) ++ kdc_reply->u.dh_Info.dhSignedData.data, ++ kdc_reply->u.dh_Info.dhSignedData.length, ++ (unsigned char **)&dh_data.data, ++ &dh_data.length, ++ NULL, NULL, NULL); ++ if (retval) { ++ pkiDebug("failed to verify pkcs7 signed data\n"); ++ TRACE_PKINIT_CLIENT_REP_DH_FAIL(context); + goto cleanup; + } ++ TRACE_PKINIT_CLIENT_REP_DH(context); ++ + retval = krb5_build_principal_ext(context, &kdc_princ, + request->server->realm.length, + request->server->realm.data, +@@ -632,116 +601,54 @@ pkinit_as_rep_parse(krb5_context context, + + OCTETDATA_TO_KRB5DATA(&dh_data, &k5data); + +- switch(kdc_reply->choice) { +- case choice_pa_pk_as_rep_dhInfo: + #ifdef DEBUG_ASN1 +- print_buffer_bin(dh_data.data, dh_data.length, +- "/tmp/client_dh_key"); ++ print_buffer_bin(dh_data.data, dh_data.length, "/tmp/client_dh_key"); + #endif +- if ((retval = k5int_decode_krb5_kdc_dh_key_info(&k5data, +- &kdc_dh)) != 0) { +- pkiDebug("failed to decode kdc_dh_key_info\n"); +- goto cleanup; +- } +- +- /* client after KDC reply */ +- if ((retval = client_process_dh(context, plgctx->cryptoctx, +- reqctx->cryptoctx, reqctx->idctx, +- (unsigned char *) +- kdc_dh->subjectPublicKey.data, +- kdc_dh->subjectPublicKey.length, +- &client_key, &client_key_len)) != 0) { +- pkiDebug("failed to process dh params\n"); +- goto cleanup; +- } +- +- /* If we have a KDF algorithm ID, call the algorithm agility KDF... */ +- if (kdc_reply->u.dh_Info.kdfID) { +- secret.length = client_key_len; +- secret.data = (char *)client_key; +- +- retval = pkinit_alg_agility_kdf(context, &secret, +- kdc_reply->u.dh_Info.kdfID, +- request->client, request->server, +- etype, encoded_request, +- (krb5_data *)as_rep, key_block); +- +- if (retval) { +- pkiDebug("failed to create key pkinit_alg_agility_kdf %s\n", +- error_message(retval)); +- goto cleanup; +- } +- TRACE_PKINIT_CLIENT_KDF_ALG(context, kdc_reply->u.dh_Info.kdfID, +- key_block); ++ retval = k5int_decode_krb5_kdc_dh_key_info(&k5data, &kdc_dh); ++ if (retval) { ++ pkiDebug("failed to decode kdc_dh_key_info\n"); ++ goto cleanup; ++ } + +- /* ...otherwise, use the older octetstring2key function. */ +- } else { ++ /* client after KDC reply */ ++ retval = client_process_dh(context, plgctx->cryptoctx, reqctx->cryptoctx, ++ reqctx->idctx, ++ (unsigned char *)kdc_dh->subjectPublicKey.data, ++ kdc_dh->subjectPublicKey.length, &client_key, ++ &client_key_len); ++ if (retval) { ++ pkiDebug("failed to process dh params\n"); ++ goto cleanup; ++ } + +- retval = pkinit_octetstring2key(context, etype, client_key, +- client_key_len, key_block); +- if (retval) { +- pkiDebug("failed to create key pkinit_octetstring2key %s\n", +- error_message(retval)); +- goto cleanup; +- } +- TRACE_PKINIT_CLIENT_KDF_OS2K(context, key_block); +- } ++ /* If we have a KDF algorithm ID, call the algorithm agility KDF. */ ++ if (kdc_reply->u.dh_Info.kdfID) { ++ secret.length = client_key_len; ++ secret.data = (char *)client_key; + +- break; +- case choice_pa_pk_as_rep_encKeyPack: +-#ifdef DEBUG_ASN1 +- print_buffer_bin(dh_data.data, dh_data.length, +- "/tmp/client_key_pack"); +-#endif +- retval = k5int_decode_krb5_reply_key_pack(&k5data, &key_pack); ++ retval = pkinit_alg_agility_kdf(context, &secret, ++ kdc_reply->u.dh_Info.kdfID, ++ request->client, request->server, ++ etype, encoded_request, ++ (krb5_data *)as_rep, key_block); + if (retval) { +- pkiDebug("failed to decode reply_key_pack\n"); ++ pkiDebug("failed to create key pkinit_alg_agility_kdf %s\n", ++ error_message(retval)); + goto cleanup; + } +- retval = krb5_c_make_checksum(context, +- key_pack->asChecksum.checksum_type, +- &key_pack->replyKey, +- KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, +- encoded_request, &cksum); ++ TRACE_PKINIT_CLIENT_KDF_ALG(context, kdc_reply->u.dh_Info.kdfID, ++ key_block); ++ ++ } else { ++ /* Otherwise, use the older octetstring2key function. */ ++ retval = pkinit_octetstring2key(context, etype, client_key, ++ client_key_len, key_block); + if (retval) { +- pkiDebug("failed to make a checksum\n"); ++ pkiDebug("failed to create key pkinit_octetstring2key %s\n", ++ error_message(retval)); + goto cleanup; + } +- +- if ((cksum.length != key_pack->asChecksum.length) || +- k5_bcmp(cksum.contents, key_pack->asChecksum.contents, +- cksum.length) != 0) { +- TRACE_PKINIT_CLIENT_REP_CHECKSUM_FAIL(context, &cksum, +- &key_pack->asChecksum); +- pkiDebug("failed to match the checksums\n"); +-#ifdef DEBUG_CKSUM +- pkiDebug("calculating checksum on buf size (%d)\n", +- encoded_request->length); +- print_buffer(encoded_request->data, encoded_request->length); +- pkiDebug("encrypting key (%d)\n", key_pack->replyKey.length); +- print_buffer(key_pack->replyKey.contents, +- key_pack->replyKey.length); +- pkiDebug("received checksum type=%d size=%d ", +- key_pack->asChecksum.checksum_type, +- key_pack->asChecksum.length); +- print_buffer(key_pack->asChecksum.contents, +- key_pack->asChecksum.length); +- pkiDebug("expected checksum type=%d size=%d ", +- cksum.checksum_type, cksum.length); +- print_buffer(cksum.contents, cksum.length); +-#endif +- goto cleanup; +- } else +- pkiDebug("checksums match\n"); +- +- krb5_copy_keyblock_contents(context, &key_pack->replyKey, +- key_block); +- TRACE_PKINIT_CLIENT_REP_RSA_KEY(context, key_block, &cksum); +- +- break; +- default: +- pkiDebug("unknown as_rep type %d\n", kdc_reply->choice); +- goto cleanup; ++ TRACE_PKINIT_CLIENT_KDF_OS2K(context, key_block); + } + + retval = 0; +@@ -1286,7 +1193,6 @@ pkinit_client_req_init(krb5_context context, + + reqctx->opts->require_eku = plgctx->opts->require_eku; + reqctx->opts->accept_secondary_eku = plgctx->opts->accept_secondary_eku; +- reqctx->opts->dh_or_rsa = plgctx->opts->dh_or_rsa; + reqctx->opts->allow_upn = plgctx->opts->allow_upn; + reqctx->opts->require_crl_checking = plgctx->opts->require_crl_checking; + reqctx->opts->disable_freshness = plgctx->opts->disable_freshness; +@@ -1457,11 +1363,6 @@ handle_gic_opt(krb5_context context, + retval = add_string_to_array(context, &plgctx->idopts->anchors, value); + if (retval) + return retval; +- } else if (strcmp(attr, "flag_RSA_PROTOCOL") == 0) { +- if (strcmp(value, "yes") == 0) { +- pkiDebug("Setting flag to use RSA_PROTOCOL\n"); +- plgctx->opts->dh_or_rsa = RSA_PROTOCOL; +- } + } else if (strcmp(attr, "disable_freshness") == 0) { + if (strcmp(value, "yes") == 0) + plgctx->opts->disable_freshness = 1; +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index 8bdbea8e95..04199b45a4 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -181,45 +181,6 @@ krb5_error_code cms_signeddata_verify + int *is_signed); /* OUT + receives whether message is signed */ + +-/* +- * this function creates a CMS message where eContentType is EnvelopedData +- */ +-krb5_error_code cms_envelopeddata_create +- (krb5_context context, /* IN */ +- pkinit_plg_crypto_context plg_cryptoctx, /* IN */ +- pkinit_req_crypto_context req_cryptoctx, /* IN */ +- pkinit_identity_crypto_context id_cryptoctx, /* IN */ +- krb5_preauthtype pa_type, /* IN */ +- unsigned char *key_pack, /* IN +- contains DER encoded ReplyKeyPack */ +- unsigned int key_pack_len, /* IN +- contains length of key_pack */ +- unsigned char **envel_data, /* OUT +- receives DER encoded encKeyPack */ +- unsigned int *envel_data_len); /* OUT +- receives length of envel_data */ +- +-/* +- * this function creates a CMS message where eContentType is EnvelopedData +- */ +-krb5_error_code cms_envelopeddata_verify +- (krb5_context context, /* IN */ +- pkinit_plg_crypto_context plg_cryptoctx, /* IN */ +- pkinit_req_crypto_context req_cryptoctx, /* IN */ +- pkinit_identity_crypto_context id_cryptoctx, /* IN */ +- krb5_preauthtype pa_type, /* IN */ +- int require_crl_checking, /* IN +- specifies whether CRL checking should be +- strictly enforced */ +- unsigned char *envel_data, /* IN +- contains DER encoded encKeyPack */ +- unsigned int envel_data_len, /* IN +- contains length of envel_data */ +- unsigned char **signed_data, /* OUT +- receives ReplyKeyPack */ +- unsigned int *signed_data_len); /* OUT +- receives length of signed_data */ +- + /* + * This function retrieves the signer's identity, in a form that could + * be passed back in to a future invocation of this module as a candidate +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index f5aade34cc..26fa9184b3 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -66,26 +66,14 @@ static krb5_error_code create_signature + (unsigned char **, unsigned int *, unsigned char *, unsigned int, + EVP_PKEY *pkey); + +-static krb5_error_code pkinit_decode_data +-(krb5_context context, pkinit_identity_crypto_context cryptoctx, +- const uint8_t *data, unsigned int data_len, uint8_t **decoded, +- unsigned int *decoded_len); +- + #ifdef DEBUG_DH + static void print_dh(DH *, char *); + static void print_pubkey(BIGNUM *, char *); + #endif + +-static int prepare_enc_data +-(const uint8_t *indata, int indata_len, uint8_t **outdata, int *outdata_len); +- + static int openssl_callback (int, X509_STORE_CTX *); + static int openssl_callback_ignore_crls (int, X509_STORE_CTX *); + +-static int pkcs7_decrypt +-(krb5_context context, pkinit_identity_crypto_context id_cryptoctx, PKCS7 *p7, +- unsigned char **data_out, unsigned int *len_out); +- + static ASN1_OBJECT * pkinit_pkcs7type2oid + (pkinit_plg_crypto_context plg_cryptoctx, int pkcs7_type); + +@@ -115,20 +103,12 @@ static krb5_error_code pkinit_sign_data_pkcs11 + (krb5_context context, pkinit_identity_crypto_context id_cryptoctx, + unsigned char *data, unsigned int data_len, + unsigned char **sig, unsigned int *sig_len); +-static krb5_error_code pkinit_decode_data_pkcs11 +-(krb5_context context, pkinit_identity_crypto_context id_cryptoctx, +- const uint8_t *data, unsigned int data_len, uint8_t **decoded_data, +- unsigned int *decoded_data_len); + #endif /* WITHOUT_PKCS11 */ + + static krb5_error_code pkinit_sign_data_fs + (krb5_context context, pkinit_identity_crypto_context id_cryptoctx, + unsigned char *data, unsigned int data_len, + unsigned char **sig, unsigned int *sig_len); +-static krb5_error_code pkinit_decode_data_fs +-(krb5_context context, pkinit_identity_crypto_context id_cryptoctx, +- const uint8_t *data, unsigned int data_len, uint8_t **decoded_data, +- unsigned int *decoded_data_len); + + static krb5_error_code + create_krb5_invalidCertificates(krb5_context context, +@@ -140,10 +120,6 @@ create_krb5_invalidCertificates(krb5_context context, + static krb5_error_code + create_identifiers_from_stack(STACK_OF(X509) *sk, + krb5_external_principal_identifier *** ids); +-static int +-wrap_signeddata(unsigned char *data, unsigned int data_len, +- unsigned char **out, unsigned int *out_len); +- + static const char * + pkcs11err(int err); + +@@ -2177,177 +2153,6 @@ cleanup: + return retval; + } + +-krb5_error_code +-cms_envelopeddata_create(krb5_context context, +- pkinit_plg_crypto_context plgctx, +- pkinit_req_crypto_context reqctx, +- pkinit_identity_crypto_context idctx, +- krb5_preauthtype pa_type, +- unsigned char *key_pack, +- unsigned int key_pack_len, +- unsigned char **out, +- unsigned int *out_len) +-{ +- +- krb5_error_code retval = ENOMEM; +- PKCS7 *p7 = NULL; +- BIO *in = NULL; +- unsigned char *p = NULL, *signed_data = NULL, *enc_data = NULL; +- int signed_data_len = 0, enc_data_len = 0, flags = PKCS7_BINARY; +- STACK_OF(X509) *encerts = NULL; +- const EVP_CIPHER *cipher = NULL; +- +- retval = cms_signeddata_create(context, plgctx, reqctx, idctx, +- CMS_ENVEL_SERVER, key_pack, key_pack_len, +- &signed_data, +- (unsigned int *)&signed_data_len); +- if (retval) { +- pkiDebug("failed to create pkcs7 signed data\n"); +- goto cleanup; +- } +- +- /* check we have client's certificate */ +- if (reqctx->received_cert == NULL) { +- retval = KRB5KDC_ERR_PREAUTH_FAILED; +- goto cleanup; +- } +- encerts = sk_X509_new_null(); +- sk_X509_push(encerts, reqctx->received_cert); +- +- cipher = EVP_des_ede3_cbc(); +- in = BIO_new(BIO_s_mem()); +- prepare_enc_data(signed_data, signed_data_len, &enc_data, +- &enc_data_len); +- retval = BIO_write(in, enc_data, enc_data_len); +- if (retval != enc_data_len) { +- pkiDebug("BIO_write only wrote %d\n", retval); +- goto cleanup; +- } +- +- p7 = PKCS7_encrypt(encerts, in, cipher, flags); +- if (p7 == NULL) { +- retval = oerr(context, 0, _("Failed to encrypt PKCS7 object")); +- goto cleanup; +- } +- p7->d.enveloped->enc_data->content_type = OBJ_nid2obj(NID_pkcs7_signed); +- +- *out_len = i2d_PKCS7(p7, NULL); +- if (!*out_len || (p = *out = malloc(*out_len)) == NULL) { +- retval = ENOMEM; +- goto cleanup; +- } +- retval = i2d_PKCS7(p7, &p); +- if (!retval) { +- retval = oerr(context, 0, _("Failed to DER encode PKCS7")); +- goto cleanup; +- } +- retval = 0; +- +-#ifdef DEBUG_ASN1 +- print_buffer_bin(*out, *out_len, "/tmp/kdc_enveloped_data"); +-#endif +- +-cleanup: +- if (p7 != NULL) +- PKCS7_free(p7); +- if (in != NULL) +- BIO_free(in); +- free(signed_data); +- free(enc_data); +- if (encerts != NULL) +- sk_X509_free(encerts); +- +- return retval; +-} +- +-krb5_error_code +-cms_envelopeddata_verify(krb5_context context, +- pkinit_plg_crypto_context plg_cryptoctx, +- pkinit_req_crypto_context req_cryptoctx, +- pkinit_identity_crypto_context id_cryptoctx, +- krb5_preauthtype pa_type, +- int require_crl_checking, +- unsigned char *enveloped_data, +- unsigned int enveloped_data_len, +- unsigned char **data, +- unsigned int *data_len) +-{ +- krb5_error_code retval = KRB5KDC_ERR_PREAUTH_FAILED; +- PKCS7 *p7 = NULL; +- const unsigned char *p = enveloped_data; +- unsigned int tmp_buf_len = 0, tmp_buf2_len = 0, vfy_buf_len = 0; +- unsigned char *tmp_buf = NULL, *tmp_buf2 = NULL, *vfy_buf = NULL; +- +-#ifdef DEBUG_ASN1 +- print_buffer_bin(enveloped_data, enveloped_data_len, +- "/tmp/client_envelopeddata"); +-#endif +- /* decode received PKCS7 message */ +- if ((p7 = d2i_PKCS7(NULL, &p, (int)enveloped_data_len)) == NULL) { +- retval = oerr(context, 0, _("Failed to decode PKCS7")); +- goto cleanup; +- } +- +- /* verify that the received message is PKCS7 EnvelopedData message */ +- if (OBJ_obj2nid(p7->type) != NID_pkcs7_enveloped || +- p7->d.enveloped == NULL || +- p7->d.enveloped->enc_data->enc_data == NULL) { +- pkiDebug("Expected id-enveloped PKCS7 msg (received type = %d)\n", +- OBJ_obj2nid(p7->type)); +- krb5_set_error_message(context, retval, "wrong oid\n"); +- goto cleanup; +- } +- +- /* decrypt received PKCS7 message */ +- if (pkcs7_decrypt(context, id_cryptoctx, p7, &tmp_buf, &tmp_buf_len)) { +- pkiDebug("PKCS7 decryption successful\n"); +- } else { +- retval = oerr(context, 0, _("Failed to decrypt PKCS7 message")); +- goto cleanup; +- } +- +-#ifdef DEBUG_ASN1 +- print_buffer_bin(tmp_buf, tmp_buf_len, "/tmp/client_enc_keypack"); +-#endif +- /* verify PKCS7 SignedData message */ +- /* Wrap the signed data to make decoding easier in the verify routine. */ +- retval = wrap_signeddata(tmp_buf, tmp_buf_len, &tmp_buf2, &tmp_buf2_len); +- if (retval) { +- pkiDebug("failed to encode signeddata\n"); +- goto cleanup; +- } +- vfy_buf = tmp_buf2; +- vfy_buf_len = tmp_buf2_len; +- +-#ifdef DEBUG_ASN1 +- print_buffer_bin(vfy_buf, vfy_buf_len, "/tmp/client_enc_keypack2"); +-#endif +- +- retval = cms_signeddata_verify(context, plg_cryptoctx, req_cryptoctx, +- id_cryptoctx, CMS_ENVEL_SERVER, +- require_crl_checking, +- vfy_buf, vfy_buf_len, +- data, data_len, NULL, NULL, NULL); +- +- if (!retval) +- pkiDebug("PKCS7 Verification Success\n"); +- else { +- pkiDebug("PKCS7 Verification Failure\n"); +- goto cleanup; +- } +- +- retval = 0; +- +-cleanup: +- +- if (p7 != NULL) +- PKCS7_free(p7); +- free(tmp_buf); +- free(tmp_buf2); +- +- return retval; +-} +- + static krb5_error_code + crypto_retrieve_X509_sans(krb5_context context, + pkinit_plg_crypto_context plgctx, +@@ -3398,70 +3203,6 @@ pkinit_pkcs7type2oid(pkinit_plg_crypto_context cryptoctx, int pkcs7_type) + + } + +-static int +-wrap_signeddata(unsigned char *data, unsigned int data_len, +- unsigned char **out, unsigned int *out_len) +-{ +- +- unsigned int orig_len = 0, oid_len = 0, tot_len = 0; +- ASN1_OBJECT *oid = NULL; +- unsigned char *p = NULL; +- +- /* Get length to wrap the original data with SEQUENCE tag */ +- tot_len = orig_len = ASN1_object_size(1, (int)data_len, V_ASN1_SEQUENCE); +- +- /* Add the signedData OID and adjust lengths */ +- oid = OBJ_nid2obj(NID_pkcs7_signed); +- oid_len = i2d_ASN1_OBJECT(oid, NULL); +- +- tot_len = ASN1_object_size(1, (int)(orig_len+oid_len), V_ASN1_SEQUENCE); +- +- p = *out = malloc(tot_len); +- if (p == NULL) return -1; +- +- ASN1_put_object(&p, 1, (int)(orig_len+oid_len), +- V_ASN1_SEQUENCE, V_ASN1_UNIVERSAL); +- +- i2d_ASN1_OBJECT(oid, &p); +- +- ASN1_put_object(&p, 1, (int)data_len, 0, V_ASN1_CONTEXT_SPECIFIC); +- memcpy(p, data, data_len); +- +- *out_len = tot_len; +- +- return 0; +-} +- +-static int +-prepare_enc_data(const uint8_t *indata, int indata_len, uint8_t **outdata, +- int *outdata_len) +-{ +- int tag, class; +- long tlen, slen; +- const uint8_t *p = indata, *oldp; +- +- if (ASN1_get_object(&p, &slen, &tag, &class, indata_len) & 0x80) +- return EINVAL; +- if (tag != V_ASN1_SEQUENCE) +- return EINVAL; +- +- oldp = p; +- if (ASN1_get_object(&p, &tlen, &tag, &class, slen) & 0x80) +- return EINVAL; +- p += tlen; +- slen -= (p - oldp); +- +- if (ASN1_get_object(&p, &tlen, &tag, &class, slen) & 0x80) +- return EINVAL; +- +- *outdata = malloc(tlen); +- if (*outdata == NULL) +- return ENOMEM; +- memcpy(*outdata, p, tlen); +- *outdata_len = tlen; +- return 0; +-} +- + #ifndef WITHOUT_PKCS11 + static struct plugin_file_handle * + load_pkcs11_module(krb5_context context, const char *modname, +@@ -3780,169 +3521,6 @@ pkinit_find_private_key(pkinit_identity_crypto_context id_cryptoctx, + } + #endif + +-static krb5_error_code +-pkinit_decode_data_fs(krb5_context context, +- pkinit_identity_crypto_context id_cryptoctx, +- const uint8_t *data, unsigned int data_len, +- uint8_t **decoded_data, unsigned int *decoded_data_len) +-{ +- X509 *cert = sk_X509_value(id_cryptoctx->my_certs, +- id_cryptoctx->cert_index); +- EVP_PKEY *pkey = id_cryptoctx->my_key; +- EVP_PKEY_CTX *ctx = NULL; +- uint8_t *buf = NULL; +- size_t buf_len = 0; +- int ok; +- +- *decoded_data = NULL; +- *decoded_data_len = 0; +- +- if (cert != NULL && !X509_check_private_key(cert, pkey)) { +- pkiDebug("private key does not match certificate\n"); +- return KRB5KDC_ERR_PREAUTH_FAILED; +- } +- +- ctx = EVP_PKEY_CTX_new(pkey, NULL); +- if (ctx == NULL) +- return KRB5KDC_ERR_PREAUTH_FAILED; +- +- ok = EVP_PKEY_decrypt_init(ctx); +- if (!ok) +- goto cleanup; +- +- /* Get the length of the eventual output. */ +- ok = EVP_PKEY_decrypt(ctx, NULL, &buf_len, data, data_len); +- if (!ok) { +- pkiDebug("unable to decrypt received data\n"); +- goto cleanup; +- } +- +- buf = malloc(buf_len); +- if (buf == NULL) { +- ok = 0; +- goto cleanup; +- } +- +- ok = EVP_PKEY_decrypt(ctx, buf, &buf_len, data, data_len); +- if (!ok) { +- pkiDebug("unable to decrypt received data\n"); +- goto cleanup; +- } +- +- *decoded_data = buf; +- *decoded_data_len = buf_len; +- buf = NULL; +-cleanup: +- zapfree(buf, buf_len); +- EVP_PKEY_CTX_free(ctx); +- return ok ? 0 : KRB5KDC_ERR_PREAUTH_FAILED; +-} +- +-#ifndef WITHOUT_PKCS11 +-/* +- * When using the ActivCard Linux pkcs11 library (v2.0.1), the decrypt function +- * fails. By inserting an extra function call, which serves nothing but to +- * change the stack, we were able to work around the issue. If the ActivCard +- * library is fixed in the future, this function can be inlined back into the +- * caller. +- */ +-static CK_RV +-pkinit_C_Decrypt(pkinit_identity_crypto_context id_cryptoctx, +- CK_BYTE_PTR pEncryptedData, +- CK_ULONG ulEncryptedDataLen, +- CK_BYTE_PTR pData, +- CK_ULONG_PTR pulDataLen) +-{ +- CK_RV rv = CKR_OK; +- +- rv = id_cryptoctx->p11->C_Decrypt(id_cryptoctx->session, pEncryptedData, +- ulEncryptedDataLen, pData, pulDataLen); +- if (rv == CKR_OK) { +- pkiDebug("pData %p *pulDataLen %d\n", (void *) pData, +- (int) *pulDataLen); +- } +- return rv; +-} +- +-static krb5_error_code +-pkinit_decode_data_pkcs11(krb5_context context, +- pkinit_identity_crypto_context id_cryptoctx, +- const uint8_t *data, unsigned int data_len, +- uint8_t **decoded_data, +- unsigned int *decoded_data_len) +-{ +- CK_OBJECT_HANDLE obj; +- CK_ULONG len; +- CK_MECHANISM mech; +- uint8_t *cp; +- int r; +- +- *decoded_data = NULL; +- *decoded_data_len = 0; +- +- if (pkinit_open_session(context, id_cryptoctx)) { +- pkiDebug("can't open pkcs11 session\n"); +- return KRB5KDC_ERR_PREAUTH_FAILED; +- } +- +- pkinit_find_private_key(id_cryptoctx, CKA_DECRYPT, &obj); +- +- mech.mechanism = CKM_RSA_PKCS; +- mech.pParameter = NULL; +- mech.ulParameterLen = 0; +- +- if ((r = id_cryptoctx->p11->C_DecryptInit(id_cryptoctx->session, &mech, +- obj)) != CKR_OK) { +- pkiDebug("C_DecryptInit: 0x%x\n", (int) r); +- return KRB5KDC_ERR_PREAUTH_FAILED; +- } +- pkiDebug("data_len = %d\n", data_len); +- cp = malloc((size_t) data_len); +- if (cp == NULL) +- return ENOMEM; +- len = data_len; +- pkiDebug("session %p edata %p edata_len %d data %p datalen @%p %d\n", +- (void *) id_cryptoctx->session, (void *) data, (int) data_len, +- (void *) cp, (void *) &len, (int) len); +- r = pkinit_C_Decrypt(id_cryptoctx, (CK_BYTE_PTR) data, (CK_ULONG) data_len, +- cp, &len); +- if (r != CKR_OK) { +- pkiDebug("C_Decrypt: %s\n", pkcs11err(r)); +- if (r == CKR_BUFFER_TOO_SMALL) +- pkiDebug("decrypt %d needs %d\n", (int) data_len, (int) len); +- return KRB5KDC_ERR_PREAUTH_FAILED; +- } +- pkiDebug("decrypt %d -> %d\n", (int) data_len, (int) len); +- *decoded_data_len = len; +- *decoded_data = cp; +- +- return 0; +-} +-#endif +- +-krb5_error_code +-pkinit_decode_data(krb5_context context, +- pkinit_identity_crypto_context id_cryptoctx, +- const uint8_t *data, unsigned int data_len, +- uint8_t **decoded_data, unsigned int *decoded_data_len) +-{ +- krb5_error_code retval = KRB5KDC_ERR_PREAUTH_FAILED; +- +- *decoded_data = NULL; +- *decoded_data_len = 0; +- +- if (id_cryptoctx->pkcs11_method != 1) +- retval = pkinit_decode_data_fs(context, id_cryptoctx, data, data_len, +- decoded_data, decoded_data_len); +-#ifndef WITHOUT_PKCS11 +- else +- retval = pkinit_decode_data_pkcs11(context, id_cryptoctx, data, +- data_len, decoded_data, decoded_data_len); +-#endif +- +- return retval; +-} +- + static krb5_error_code + pkinit_sign_data_fs(krb5_context context, + pkinit_identity_crypto_context id_cryptoctx, +@@ -5617,88 +5195,6 @@ cleanup: + return retval; + } + +-/* Originally based on OpenSSL's PKCS7_dataDecode(), now modified to remove the +- * use of BIO objects and to fit the PKINIT internal interfaces. */ +-static int +-pkcs7_decrypt(krb5_context context, +- pkinit_identity_crypto_context id_cryptoctx, PKCS7 *p7, +- unsigned char **data_out, unsigned int *len_out) +-{ +- krb5_error_code ret; +- int ok = 0, plaintext_len = 0, final_len; +- unsigned int keylen = 0, eklen = 0, blocksize; +- unsigned char *ek = NULL, *tkey = NULL, *plaintext = NULL, *use_key; +- ASN1_OCTET_STRING *data_body = p7->d.enveloped->enc_data->enc_data; +- const EVP_CIPHER *evp_cipher; +- EVP_CIPHER_CTX *evp_ctx = NULL; +- X509_ALGOR *enc_alg = p7->d.enveloped->enc_data->algorithm; +- STACK_OF(PKCS7_RECIP_INFO) *rsk = p7->d.enveloped->recipientinfo; +- PKCS7_RECIP_INFO *ri = NULL; +- +- *data_out = NULL; +- *len_out = 0; +- +- p7->state = PKCS7_S_HEADER; +- +- /* RFC 4556 section 3.2.3.2 requires that there be exactly one +- * recipientInfo. */ +- if (sk_PKCS7_RECIP_INFO_num(rsk) != 1) { +- pkiDebug("invalid number of EnvelopedData RecipientInfos\n"); +- return 0; +- } +- ri = sk_PKCS7_RECIP_INFO_value(rsk, 0); +- +- evp_cipher = EVP_get_cipherbyobj(enc_alg->algorithm); +- if (evp_cipher == NULL) +- goto cleanup; +- keylen = EVP_CIPHER_key_length(evp_cipher); +- blocksize = EVP_CIPHER_block_size(evp_cipher); +- +- evp_ctx = EVP_CIPHER_CTX_new(); +- if (evp_ctx == NULL) +- goto cleanup; +- if (!EVP_DecryptInit(evp_ctx, evp_cipher, NULL, NULL) || +- EVP_CIPHER_asn1_to_param(evp_ctx, enc_alg->parameter) <= 0) +- goto cleanup; +- +- /* Generate a random symmetric key to avoid exposing timing data if RSA +- * decryption fails the padding check. */ +- tkey = malloc(keylen); +- if (tkey == NULL || !EVP_CIPHER_CTX_rand_key(evp_ctx, tkey)) +- goto cleanup; +- +- /* Decrypt the secret key with the private key. */ +- ret = pkinit_decode_data(context, id_cryptoctx, +- ASN1_STRING_get0_data(ri->enc_key), +- ASN1_STRING_length(ri->enc_key), &ek, &eklen); +- use_key = (ret || eklen != keylen) ? tkey : ek; +- +- /* Allocate a plaintext buffer and decrypt data_body into it. */ +- plaintext = malloc(data_body->length + blocksize); +- if (plaintext == NULL) +- goto cleanup; +- if (!EVP_DecryptInit(evp_ctx, NULL, use_key, NULL)) +- goto cleanup; +- if (!EVP_DecryptUpdate(evp_ctx, plaintext, &plaintext_len, +- data_body->data, data_body->length)) +- goto cleanup; +- if (!EVP_DecryptFinal(evp_ctx, plaintext + plaintext_len, &final_len)) +- goto cleanup; +- plaintext_len += final_len; +- +- *len_out = plaintext_len; +- *data_out = plaintext; +- plaintext = NULL; +- ok = 1; +- +-cleanup: +- EVP_CIPHER_CTX_free(evp_ctx); +- zapfree(plaintext, plaintext_len); +- zapfree(ek, eklen); +- zapfree(tkey, keylen); +- return ok; +-} +- + #ifdef DEBUG_DH + static void + print_dh(DH * dh, char *msg) +diff --git a/src/plugins/preauth/pkinit/pkinit_lib.c b/src/plugins/preauth/pkinit/pkinit_lib.c +index 4c3d46bf5a..19db695a4d 100644 +--- a/src/plugins/preauth/pkinit/pkinit_lib.c ++++ b/src/plugins/preauth/pkinit/pkinit_lib.c +@@ -50,7 +50,6 @@ pkinit_init_req_opts(pkinit_req_opts **reqopts) + opts->require_eku = 1; + opts->accept_secondary_eku = 0; + opts->allow_upn = 0; +- opts->dh_or_rsa = DH_PROTOCOL; + opts->require_crl_checking = 0; + opts->dh_size = PKINIT_DEFAULT_DH_MIN_BITS; + +@@ -79,7 +78,6 @@ pkinit_init_plg_opts(pkinit_plg_opts **plgopts) + + opts->require_eku = 1; + opts->accept_secondary_eku = 0; +- opts->dh_or_rsa = DH_PROTOCOL; + opts->allow_upn = 0; + opts->require_crl_checking = 0; + opts->require_freshness = 0; +diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c +index 768a4e559f..aab21f951c 100644 +--- a/src/plugins/preauth/pkinit/pkinit_srv.c ++++ b/src/plugins/preauth/pkinit/pkinit_srv.c +@@ -821,132 +821,55 @@ pkinit_server_return_padata(krb5_context context, + retval = ENOMEM; + goto cleanup; + } +- /* let's assume it's RSA. we'll reset it to DH if needed */ +- rep->choice = choice_pa_pk_as_rep_encKeyPack; + +- if (reqctx->rcv_auth_pack != NULL && +- reqctx->rcv_auth_pack->clientPublicValue.length > 0) { +- rep->choice = choice_pa_pk_as_rep_dhInfo; +- +- pkiDebug("received DH key delivery AS REQ\n"); +- retval = server_process_dh(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, +- &dh_pubkey, &dh_pubkey_len, +- &server_key, &server_key_len); +- if (retval) { +- pkiDebug("failed to process/create dh parameters\n"); +- goto cleanup; +- } +- +- /* +- * This is DH, so don't generate the key until after we +- * encode the reply, because the encoded reply is needed +- * to generate the key in some cases. +- */ +- +- dhkey_info.subjectPublicKey.length = dh_pubkey_len; +- dhkey_info.subjectPublicKey.data = (char *)dh_pubkey; +- dhkey_info.nonce = request->nonce; +- dhkey_info.dhKeyExpiration = 0; +- +- retval = k5int_encode_krb5_kdc_dh_key_info(&dhkey_info, +- &encoded_dhkey_info); +- if (retval) { +- pkiDebug("encode_krb5_kdc_dh_key_info failed\n"); +- goto cleanup; +- } +-#ifdef DEBUG_ASN1 +- print_buffer_bin((unsigned char *)encoded_dhkey_info->data, +- encoded_dhkey_info->length, +- "/tmp/kdc_dh_key_info"); +-#endif +- +- retval = cms_signeddata_create(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, +- CMS_SIGN_SERVER, +- (unsigned char *) +- encoded_dhkey_info->data, +- encoded_dhkey_info->length, +- (unsigned char **) +- &rep->u.dh_Info.dhSignedData.data, +- &rep->u.dh_Info.dhSignedData.length); +- if (retval) { +- pkiDebug("failed to create pkcs7 signed data\n"); +- goto cleanup; +- } +- +- } else { +- pkiDebug("received RSA key delivery AS REQ\n"); +- +- init_krb5_reply_key_pack(&key_pack); +- if (key_pack == NULL) { +- retval = ENOMEM; +- goto cleanup; +- } ++ if (reqctx->rcv_auth_pack == NULL || ++ reqctx->rcv_auth_pack->clientPublicValue.length == 0) { ++ retval = KRB5KDC_ERR_PREAUTH_FAILED; ++ k5_setmsg(context, retval, _("Unsupported PKINIT RSA request")); ++ goto cleanup; ++ } + +- retval = krb5_c_make_random_key(context, enctype, &key_pack->replyKey); +- if (retval) { +- pkiDebug("unable to make a session key\n"); +- goto cleanup; +- } ++ rep->choice = choice_pa_pk_as_rep_dhInfo; + +- retval = krb5_c_make_checksum(context, 0, &key_pack->replyKey, +- KRB5_KEYUSAGE_TGS_REQ_AUTH_CKSUM, +- req_pkt, &key_pack->asChecksum); +- if (retval) { +- pkiDebug("unable to calculate AS REQ checksum\n"); +- goto cleanup; +- } +-#ifdef DEBUG_CKSUM +- pkiDebug("calculating checksum on buf size = %d\n", req_pkt->length); +- print_buffer(req_pkt->data, req_pkt->length); +- pkiDebug("checksum size = %d\n", key_pack->asChecksum.length); +- print_buffer(key_pack->asChecksum.contents, +- key_pack->asChecksum.length); +- pkiDebug("encrypting key (%d)\n", key_pack->replyKey.length); +- print_buffer(key_pack->replyKey.contents, key_pack->replyKey.length); +-#endif ++ retval = server_process_dh(context, plgctx->cryptoctx, reqctx->cryptoctx, ++ plgctx->idctx, &dh_pubkey, &dh_pubkey_len, ++ &server_key, &server_key_len); ++ if (retval) { ++ pkiDebug("failed to process/create dh parameters\n"); ++ goto cleanup; ++ } + +- retval = k5int_encode_krb5_reply_key_pack(key_pack, +- &encoded_key_pack); +- if (retval) { +- pkiDebug("failed to encode reply_key_pack\n"); +- goto cleanup; +- } ++ dhkey_info.subjectPublicKey.length = dh_pubkey_len; ++ dhkey_info.subjectPublicKey.data = (char *)dh_pubkey; ++ dhkey_info.nonce = request->nonce; ++ dhkey_info.dhKeyExpiration = 0; + +- rep->choice = choice_pa_pk_as_rep_encKeyPack; +- retval = cms_envelopeddata_create(context, plgctx->cryptoctx, +- reqctx->cryptoctx, plgctx->idctx, +- padata->pa_type, +- (unsigned char *) +- encoded_key_pack->data, +- encoded_key_pack->length, +- (unsigned char **) +- &rep->u.encKeyPack.data, +- &rep->u.encKeyPack.length); +- if (retval) { +- pkiDebug("failed to create pkcs7 enveloped data: %s\n", +- error_message(retval)); +- goto cleanup; +- } ++ retval = k5int_encode_krb5_kdc_dh_key_info(&dhkey_info, ++ &encoded_dhkey_info); ++ if (retval) { ++ pkiDebug("encode_krb5_kdc_dh_key_info failed\n"); ++ goto cleanup; ++ } + #ifdef DEBUG_ASN1 +- print_buffer_bin((unsigned char *)encoded_key_pack->data, +- encoded_key_pack->length, +- "/tmp/kdc_key_pack"); +- print_buffer_bin(rep->u.encKeyPack.data, rep->u.encKeyPack.length, +- "/tmp/kdc_enc_key_pack"); ++ print_buffer_bin((unsigned char *)encoded_dhkey_info->data, ++ encoded_dhkey_info->length, "/tmp/kdc_dh_key_info"); + #endif + +- retval = cb->replace_reply_key(context, rock, &key_pack->replyKey, +- FALSE); +- if (retval) +- goto cleanup; ++ retval = cms_signeddata_create(context, plgctx->cryptoctx, ++ reqctx->cryptoctx, plgctx->idctx, ++ CMS_SIGN_SERVER, ++ (unsigned char *)encoded_dhkey_info->data, ++ encoded_dhkey_info->length, ++ (unsigned char **) ++ &rep->u.dh_Info.dhSignedData.data, ++ &rep->u.dh_Info.dhSignedData.length); ++ if (retval) { ++ pkiDebug("failed to create pkcs7 signed data\n"); ++ goto cleanup; + } + +- if (rep->choice == choice_pa_pk_as_rep_dhInfo && +- ((reqctx->rcv_auth_pack != NULL && +- reqctx->rcv_auth_pack->supportedKDFs != NULL))) { +- ++ if (reqctx->rcv_auth_pack != NULL && ++ reqctx->rcv_auth_pack->supportedKDFs != NULL) { + /* If using the alg-agility KDF, put the algorithm in the reply + * before encoding it. + */ +@@ -973,41 +896,36 @@ pkinit_server_return_padata(krb5_context context, + "/tmp/kdc_as_rep"); + #endif + +- /* If this is DH, we haven't computed the key yet, so do it now. */ +- if (rep->choice == choice_pa_pk_as_rep_dhInfo) { +- +- /* If mutually supported KDFs were found, use the algorithm agility +- * KDF. */ +- if (rep->u.dh_Info.kdfID) { +- secret.data = (char *)server_key; +- secret.length = server_key_len; ++ /* If mutually supported KDFs were found, use the algorithm agility KDF. */ ++ if (rep->u.dh_Info.kdfID) { ++ secret.data = (char *)server_key; ++ secret.length = server_key_len; + +- retval = pkinit_alg_agility_kdf(context, &secret, +- rep->u.dh_Info.kdfID, +- request->client, request->server, +- enctype, req_pkt, out_data, +- &reply_key); +- if (retval) { +- pkiDebug("pkinit_alg_agility_kdf failed: %s\n", +- error_message(retval)); +- goto cleanup; +- } ++ retval = pkinit_alg_agility_kdf(context, &secret, rep->u.dh_Info.kdfID, ++ request->client, request->server, ++ enctype, req_pkt, out_data, ++ &reply_key); ++ if (retval) { ++ pkiDebug("pkinit_alg_agility_kdf failed: %s\n", ++ error_message(retval)); ++ goto cleanup; ++ } + +- /* Otherwise, use the older octetstring2key() function */ +- } else { +- retval = pkinit_octetstring2key(context, enctype, server_key, ++ /* Otherwise, use the older octetstring2key() function */ ++ } else { ++ retval = pkinit_octetstring2key(context, enctype, server_key, + server_key_len, &reply_key); +- if (retval) { +- pkiDebug("pkinit_octetstring2key failed: %s\n", +- error_message(retval)); +- goto cleanup; +- } +- } +- retval = cb->replace_reply_key(context, rock, &reply_key, FALSE); +- if (retval) ++ if (retval) { ++ pkiDebug("pkinit_octetstring2key failed: %s\n", ++ error_message(retval)); + goto cleanup; ++ } + } + ++ retval = cb->replace_reply_key(context, rock, &reply_key, FALSE); ++ if (retval) ++ goto cleanup; ++ + *send_pa = malloc(sizeof(krb5_pa_data)); + if (*send_pa == NULL) { + retval = ENOMEM; +diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h +index 5ee39c085c..d385759145 100644 +--- a/src/plugins/preauth/pkinit/pkinit_trace.h ++++ b/src/plugins/preauth/pkinit/pkinit_trace.h +@@ -58,19 +58,10 @@ + TRACE(c, "PKINIT client verified DH reply") + #define TRACE_PKINIT_CLIENT_REP_DH_FAIL(c) \ + TRACE(c, "PKINIT client could not verify DH reply") +-#define TRACE_PKINIT_CLIENT_REP_RSA(c) \ +- TRACE(c, "PKINIT client verified RSA reply") +-#define TRACE_PKINIT_CLIENT_REP_RSA_KEY(c, keyblock, cksum) \ +- TRACE(c, "PKINIT client retrieved reply key {keyblock} from RSA " \ +- "reply (checksum {cksum})", keyblock, cksum) +-#define TRACE_PKINIT_CLIENT_REP_RSA_FAIL(c) \ +- TRACE(c, "PKINIT client could not verify RSA reply") + #define TRACE_PKINIT_CLIENT_REQ_CHECKSUM(c, cksum) \ + TRACE(c, "PKINIT client computed kdc-req-body checksum {cksum}", cksum) + #define TRACE_PKINIT_CLIENT_REQ_DH(c) \ + TRACE(c, "PKINIT client making DH request") +-#define TRACE_PKINIT_CLIENT_REQ_RSA(c) \ +- TRACE(c, "PKINIT client making RSA request") + #define TRACE_PKINIT_CLIENT_SAN_CONFIG_DNSNAME(c, host) \ + TRACE(c, "PKINIT client config accepts KDC dNSName SAN {str}", host) + #define TRACE_PKINIT_CLIENT_SAN_MATCH_DNSNAME(c, host) \ +diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py +index ec2356ea22..62e6c426d3 100755 +--- a/src/tests/t_pkinit.py ++++ b/src/tests/t_pkinit.py +@@ -179,13 +179,6 @@ id_conf = {'realms': {'$realm': {'pkinit_identities': [file_identity + 'X', + id_env = realm.special_env('idconf', False, krb5_conf=id_conf) + realm.kinit(realm.user_princ, expected_trace=msgs, env=id_env) + +-# Try again using RSA instead of DH. +-mark('FILE identity, no password, RSA') +-realm.pkinit(realm.user_princ, flags=['-X', 'flag_RSA_PROTOCOL=yes'], +- expected_trace=('PKINIT client making RSA request', +- 'PKINIT client verified RSA reply')) +-realm.klist(realm.user_princ) +- + # Test a DH parameter renegotiation by temporarily setting a 4096-bit + # minimum on the KDC. (Preauth type 16 is PKINIT PA_PK_AS_REQ; + # 109 is PKINIT TD_DH_PARAMETERS; 133 is FAST PA-FX-COOKIE.) +diff --git a/src/windows/leash/htmlhelp/html/KINIT.htm b/src/windows/leash/htmlhelp/html/KINIT.htm +index eeee211a6e..46cb4a3ad8 100644 +--- a/src/windows/leash/htmlhelp/html/KINIT.htm ++++ b/src/windows/leash/htmlhelp/html/KINIT.htm +@@ -146,9 +146,6 @@ default credentials cache may vary between systems. If the KRB5CCNAME en + -S service_name + specify an alternate service name to use when getting initial + tickets. +- +- flag_RSA_PROTOCOL[=yes] +- specify use of RSA, rather than the default Diffie-Hellman protocol. + + +

      ENVIRONMENT

      +-- +2.46.0 + diff --git a/0024-Fix-various-issues-detected-by-static-analysis.patch b/0024-Fix-various-issues-detected-by-static-analysis.patch new file mode 100644 index 0000000..ebab90b --- /dev/null +++ b/0024-Fix-various-issues-detected-by-static-analysis.patch @@ -0,0 +1,265 @@ +From 3999883b9745bfd7065d41ff05b19e56bcb2e791 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Fri, 6 Sep 2024 17:18:11 +0200 +Subject: [PATCH] Fix various issues detected by static analysis + +In klists's show_credential(), ensure that the column counter doesn't +decrease if printf() fails. + +In process_k5beta7_princ(), bounds-check the e_length field. + +In ndr_enc_delegation_info(), initialize b so it is always valid for +the cleanup handler. + +In krb5_dbe_def_decrypt_key_data(), change the flow control so ret is +always set by the end of the function. Return KRB5_KDB_INVALIDKEYSIZE +if there isn't enough data in the first key_data_contents field or if +the serialized key length is invalid. + +In svcauth_gss_validate(), expand rpchdr to accomodate the header plus +MAX_AUTH_BYTES. + +In svcudp_reply(), change slen to unsigned to match the return type of +XDR_GETPOS() and eliminate an unnecessary check for slen >= 0. + +In krb5int_pthread_loaded()(), remove pthread_equal() from the weak +symbol checks. It is implemented as an inline function in some glibc +versions, which makes the comparison "&pthread_equal == 0" always +false. + +[ghudson@mit.edu: further modified krb5_dbe_def_decrypt_key_data() for +clarity; added detail to commit message] + +(cherry picked from commit a96541981ee34c8642ddeb6101b98e883e41c6e5) +--- + src/clients/klist/klist.c | 12 ++++----- + src/kadmin/dbutil/dump.c | 5 ++++ + src/kdc/ndr.c | 2 +- + src/lib/kdb/decrypt_key.c | 54 ++++++++++++++++++++------------------ + src/lib/rpc/svc_auth_gss.c | 5 +++- + src/lib/rpc/svc_udp.c | 13 ++++----- + src/util/support/threads.c | 2 -- + 7 files changed, 51 insertions(+), 42 deletions(-) + +diff --git a/src/clients/klist/klist.c b/src/clients/klist/klist.c +index b5808e5c93..ba9539fd23 100644 +--- a/src/clients/klist/klist.c ++++ b/src/clients/klist/klist.c +@@ -681,7 +681,7 @@ show_credential(krb5_creds *cred, const char *defname) + krb5_error_code ret; + krb5_ticket *tkt = NULL; + char *name = NULL, *sname = NULL, *tktsname, *flags; +- int extra_field = 0, ccol = 0, i; ++ int extra_field = 0, ccol = 0, i, r; + krb5_boolean is_config = krb5_is_config_principal(context, cred->server); + + ret = krb5_unparse_name(context, cred->client, &name); +@@ -711,11 +711,11 @@ show_credential(krb5_creds *cred, const char *defname) + fputs("config: ", stdout); + ccol = 8; + for (i = 1; i < cred->server->length; i++) { +- ccol += printf("%s%.*s%s", +- i > 1 ? "(" : "", +- (int)cred->server->data[i].length, +- cred->server->data[i].data, +- i > 1 ? ")" : ""); ++ r = printf("%s%.*s%s", i > 1 ? "(" : "", ++ (int)cred->server->data[i].length, ++ cred->server->data[i].data, i > 1 ? ")" : ""); ++ if (r >= 0) ++ ccol += r; + } + fputs(" = ", stdout); + ccol += 3; +diff --git a/src/kadmin/dbutil/dump.c b/src/kadmin/dbutil/dump.c +index 4d6cc0bdf9..feb053d834 100644 +--- a/src/kadmin/dbutil/dump.c ++++ b/src/kadmin/dbutil/dump.c +@@ -704,6 +704,11 @@ process_k5beta7_princ(krb5_context context, const char *fname, FILE *filep, + + dbentry->len = u1; + dbentry->n_key_data = u4; ++ ++ if (u5 > UINT16_MAX) { ++ load_err(fname, *linenop, _("invalid principal extra data size")); ++ goto fail; ++ } + dbentry->e_length = u5; + + if (kp != NULL) { +diff --git a/src/kdc/ndr.c b/src/kdc/ndr.c +index d438408ee2..38be9fe42a 100644 +--- a/src/kdc/ndr.c ++++ b/src/kdc/ndr.c +@@ -242,7 +242,7 @@ ndr_enc_delegation_info(struct pac_s4u_delegation_info *in, krb5_data *out) + { + krb5_error_code ret; + size_t i; +- struct k5buf b; ++ struct k5buf b = EMPTY_K5BUF; + struct encoded_wchars pt_encoded = { 0 }, *tss_encoded = NULL; + uint32_t pointer = 0; + +diff --git a/src/lib/kdb/decrypt_key.c b/src/lib/kdb/decrypt_key.c +index 82bbed6312..21aa3742b1 100644 +--- a/src/lib/kdb/decrypt_key.c ++++ b/src/lib/kdb/decrypt_key.c +@@ -60,7 +60,7 @@ krb5_dbe_def_decrypt_key_data(krb5_context context, const krb5_keyblock *mkey, + krb5_keyblock *dbkey_out, + krb5_keysalt *keysalt_out) + { +- krb5_error_code ret; ++ krb5_error_code ret = KRB5_CRYPTO_INTERNAL; + int16_t keylen; + krb5_enc_data cipher; + krb5_data plain = empty_data(); +@@ -74,36 +74,38 @@ krb5_dbe_def_decrypt_key_data(krb5_context context, const krb5_keyblock *mkey, + if (mkey == NULL) + return KRB5_KDB_BADSTORED_MKEY; + +- if (kd->key_data_contents[0] != NULL && kd->key_data_length[0] >= 2) { +- keylen = load_16_le(kd->key_data_contents[0]); +- if (keylen < 0) +- return EINVAL; +- cipher.enctype = ENCTYPE_UNKNOWN; +- cipher.ciphertext = make_data(kd->key_data_contents[0] + 2, +- kd->key_data_length[0] - 2); +- ret = alloc_data(&plain, kd->key_data_length[0] - 2); +- if (ret) +- goto cleanup; ++ if (kd->key_data_contents[0] == NULL || kd->key_data_length[0] < 2) ++ return KRB5_KDB_INVALIDKEYSIZE; + +- ret = krb5_c_decrypt(context, mkey, 0, 0, &cipher, &plain); +- if (ret) +- goto cleanup; ++ keylen = load_16_le(kd->key_data_contents[0]); ++ if (keylen < 0) ++ return KRB5_KDB_INVALIDKEYSIZE; + +- /* Make sure the plaintext has at least as many bytes as the true ke +- * length (it may have more due to padding). */ +- if ((unsigned int)keylen > plain.length) { +- ret = KRB5_CRYPTO_INTERNAL; +- if (ret) +- goto cleanup; +- } ++ cipher.enctype = ENCTYPE_UNKNOWN; ++ cipher.ciphertext = make_data(kd->key_data_contents[0] + 2, ++ kd->key_data_length[0] - 2); ++ ret = alloc_data(&plain, kd->key_data_length[0] - 2); ++ if (ret) ++ goto cleanup; + +- kb.magic = KV5M_KEYBLOCK; +- kb.enctype = kd->key_data_type[0]; +- kb.length = keylen; +- kb.contents = (uint8_t *)plain.data; +- plain = empty_data(); ++ ret = krb5_c_decrypt(context, mkey, 0, 0, &cipher, &plain); ++ if (ret) ++ goto cleanup; ++ ++ /* Make sure the plaintext has at least as many bytes as the true key ++ * length (it may have more due to padding). */ ++ if ((unsigned int)keylen > plain.length) { ++ ret = KRB5_CRYPTO_INTERNAL; ++ if (ret) ++ goto cleanup; + } + ++ kb.magic = KV5M_KEYBLOCK; ++ kb.enctype = kd->key_data_type[0]; ++ kb.length = keylen; ++ kb.contents = (uint8_t *)plain.data; ++ plain = empty_data(); ++ + /* Decode salt data. */ + if (keysalt_out != NULL) { + if (kd->key_data_ver == 2) { +diff --git a/src/lib/rpc/svc_auth_gss.c b/src/lib/rpc/svc_auth_gss.c +index 98d601c8ab..4f1d2911b0 100644 +--- a/src/lib/rpc/svc_auth_gss.c ++++ b/src/lib/rpc/svc_auth_gss.c +@@ -297,7 +297,7 @@ svcauth_gss_validate(struct svc_req *rqst, struct svc_rpc_gss_data *gd, struct r + struct opaque_auth *oa; + gss_buffer_desc rpcbuf, checksum; + OM_uint32 maj_stat, min_stat, qop_state; +- u_char rpchdr[128]; ++ u_char rpchdr[32 + MAX_AUTH_BYTES]; + int32_t *buf; + + log_debug("in svcauth_gss_validate()"); +@@ -315,6 +315,8 @@ svcauth_gss_validate(struct svc_req *rqst, struct svc_rpc_gss_data *gd, struct r + return (FALSE); + + buf = (int32_t *)(void *)rpchdr; ++ ++ /* Write the 32 first bytes of the header. */ + IXDR_PUT_LONG(buf, msg->rm_xid); + IXDR_PUT_ENUM(buf, msg->rm_direction); + IXDR_PUT_LONG(buf, msg->rm_call.cb_rpcvers); +@@ -323,6 +325,7 @@ svcauth_gss_validate(struct svc_req *rqst, struct svc_rpc_gss_data *gd, struct r + IXDR_PUT_LONG(buf, msg->rm_call.cb_proc); + IXDR_PUT_ENUM(buf, oa->oa_flavor); + IXDR_PUT_LONG(buf, oa->oa_length); ++ + if (oa->oa_length) { + memcpy((caddr_t)buf, oa->oa_base, oa->oa_length); + buf += RNDUP(oa->oa_length) / sizeof(int32_t); +diff --git a/src/lib/rpc/svc_udp.c b/src/lib/rpc/svc_udp.c +index 8ecbdf2b33..3aff277eb7 100644 +--- a/src/lib/rpc/svc_udp.c ++++ b/src/lib/rpc/svc_udp.c +@@ -248,8 +248,9 @@ static bool_t svcudp_reply( + { + struct svcudp_data *su = su_data(xprt); + XDR *xdrs = &su->su_xdrs; +- int slen; ++ u_int slen; + bool_t stat = FALSE; ++ ssize_t r; + + xdrproc_t xdr_results = NULL; + caddr_t xdr_location = 0; +@@ -272,12 +273,12 @@ static bool_t svcudp_reply( + if (xdr_replymsg(xdrs, msg) && + (!has_args || + (SVCAUTH_WRAP(xprt->xp_auth, xdrs, xdr_results, xdr_location)))) { +- slen = (int)XDR_GETPOS(xdrs); +- if (sendto(xprt->xp_sock, rpc_buffer(xprt), slen, 0, +- (struct sockaddr *)&(xprt->xp_raddr), xprt->xp_addrlen) +- == slen) { ++ slen = XDR_GETPOS(xdrs); ++ r = sendto(xprt->xp_sock, rpc_buffer(xprt), slen, 0, ++ (struct sockaddr *)&(xprt->xp_raddr), xprt->xp_addrlen); ++ if (r >= 0 && (u_int)r == slen) { + stat = TRUE; +- if (su->su_cache && slen >= 0) { ++ if (su->su_cache) { + cache_set(xprt, (uint32_t) slen); + } + } +diff --git a/src/util/support/threads.c b/src/util/support/threads.c +index be7e4c2e3f..4ded805b79 100644 +--- a/src/util/support/threads.c ++++ b/src/util/support/threads.c +@@ -118,7 +118,6 @@ struct tsd_block { + # pragma weak pthread_mutex_destroy + # pragma weak pthread_mutex_init + # pragma weak pthread_self +-# pragma weak pthread_equal + # pragma weak pthread_getspecific + # pragma weak pthread_setspecific + # pragma weak pthread_key_create +@@ -151,7 +150,6 @@ int krb5int_pthread_loaded (void) + || &pthread_mutex_destroy == 0 + || &pthread_mutex_init == 0 + || &pthread_self == 0 +- || &pthread_equal == 0 + /* Any program that's really multithreaded will have to be + able to create threads. */ + || &pthread_create == 0 +-- +2.46.0 + diff --git a/0025-Generate-and-verify-message-MACs-in-libkrad.patch b/0025-Generate-and-verify-message-MACs-in-libkrad.patch new file mode 100644 index 0000000..58c9352 --- /dev/null +++ b/0025-Generate-and-verify-message-MACs-in-libkrad.patch @@ -0,0 +1,629 @@ +From ea02fd7bb79861b8e36517c7c95af821a16657c4 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Thu, 22 Aug 2024 17:15:50 +0200 +Subject: [PATCH] Generate and verify message MACs in libkrad + +Implement some of the measures specified in +draft-ietf-radext-deprecating-radius-03 for mitigating the BlastRADIUS +attack (CVE-2024-3596): + +* Include a Message-Authenticator MAC as the first attribute when + generating a packet of type Access-Request, Access-Reject, + Access-Accept, or Access-Challenge (sections 5.2.1 and 5.2.4), if + the secret is non-empty. (An empty secret indicates the use of Unix + domain socket transport.) + +* Validate the Message-Authenticator MAC in received packets, if + present. + +FreeRADIUS enforces Message-Authenticator as of versions 3.2.5 and +3.0.27. libkrad must generate Message-Authenticator attributes in +order to remain compatible with these implementations. + +[ghudson@mit.edu: adjusted style and naming; simplified some +functions; edited commit message] + +ticket: 9142 (new) +tags: pullup +target_version: 1.21-next + +(cherry picked from commit 871125fea8ce0370a972bf65f7d1de63f619b06c) +--- + src/include/k5-int.h | 5 + + src/lib/crypto/krb/checksum_hmac_md5.c | 28 ++++ + src/lib/crypto/libk5crypto.exports | 1 + + src/lib/krad/attr.c | 17 ++ + src/lib/krad/attrset.c | 59 +++++-- + src/lib/krad/internal.h | 7 +- + src/lib/krad/packet.c | 206 +++++++++++++++++++++++-- + src/lib/krad/t_attrset.c | 2 +- + src/lib/krad/t_daemon.py | 3 +- + src/lib/krad/t_packet.c | 11 ++ + src/tests/t_otp.py | 3 + + 11 files changed, 311 insertions(+), 31 deletions(-) + +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index 69d6a6f569..b7789a2dd8 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -2403,4 +2403,9 @@ krb5_boolean + k5_sname_compare(krb5_context context, krb5_const_principal sname, + krb5_const_principal princ); + ++/* Generate an HMAC-MD5 keyed checksum as specified by RFC 2104. */ ++krb5_error_code ++k5_hmac_md5(const krb5_data *key, const krb5_crypto_iov *data, size_t num_data, ++ krb5_data *output); ++ + #endif /* _KRB5_INT_H */ +diff --git a/src/lib/crypto/krb/checksum_hmac_md5.c b/src/lib/crypto/krb/checksum_hmac_md5.c +index ec024f3966..a809388549 100644 +--- a/src/lib/crypto/krb/checksum_hmac_md5.c ++++ b/src/lib/crypto/krb/checksum_hmac_md5.c +@@ -92,3 +92,31 @@ cleanup: + free(hash_iov); + return ret; + } ++ ++krb5_error_code ++k5_hmac_md5(const krb5_data *key, const krb5_crypto_iov *data, size_t num_data, ++ krb5_data *output) ++{ ++ krb5_error_code ret; ++ const struct krb5_hash_provider *hash = &krb5int_hash_md5; ++ krb5_keyblock keyblock = { 0 }; ++ krb5_data hashed_key; ++ uint8_t hkeybuf[16]; ++ krb5_crypto_iov iov; ++ ++ /* Hash the key if it is longer than the block size. */ ++ if (key->length > hash->blocksize) { ++ hashed_key = make_data(hkeybuf, sizeof(hkeybuf)); ++ iov.flags = KRB5_CRYPTO_TYPE_DATA; ++ iov.data = *key; ++ ret = hash->hash(&iov, 1, &hashed_key); ++ if (ret) ++ return ret; ++ key = &hashed_key; ++ } ++ ++ keyblock.magic = KV5M_KEYBLOCK; ++ keyblock.length = key->length; ++ keyblock.contents = (uint8_t *)key->data; ++ return krb5int_hmac_keyblock(hash, &keyblock, data, num_data, output); ++} +diff --git a/src/lib/crypto/libk5crypto.exports b/src/lib/crypto/libk5crypto.exports +index d8ffa63304..00e0ce1812 100644 +--- a/src/lib/crypto/libk5crypto.exports ++++ b/src/lib/crypto/libk5crypto.exports +@@ -102,3 +102,4 @@ krb5_c_prfplus + krb5_c_derive_prfplus + k5_enctype_to_ssf + krb5int_c_deprecated_enctype ++k5_hmac_md5 +diff --git a/src/lib/krad/attr.c b/src/lib/krad/attr.c +index 42d354a3b5..65ed1d35e7 100644 +--- a/src/lib/krad/attr.c ++++ b/src/lib/krad/attr.c +@@ -125,6 +125,23 @@ static const attribute_record attributes[UCHAR_MAX] = { + {"NAS-Port-Type", 4, 4, NULL, NULL}, + {"Port-Limit", 4, 4, NULL, NULL}, + {"Login-LAT-Port", 1, MAX_ATTRSIZE, NULL, NULL}, ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for tunnelling */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */ ++ {NULL, 0, 0, NULL, NULL}, /* Reserved for Apple Remote Access Protocol */ ++ {NULL, 0, 0, NULL, NULL}, /* Password-Retry */ ++ {NULL, 0, 0, NULL, NULL}, /* Prompt */ ++ {NULL, 0, 0, NULL, NULL}, /* Connect-Info */ ++ {NULL, 0, 0, NULL, NULL}, /* Configuration-Token */ ++ {NULL, 0, 0, NULL, NULL}, /* EAP-Message */ ++ {"Message-Authenticator", MD5_DIGEST_SIZE, MD5_DIGEST_SIZE, NULL, NULL}, + }; + + /* Encode User-Password attribute. */ +diff --git a/src/lib/krad/attrset.c b/src/lib/krad/attrset.c +index 6ec031e320..e5457ebfd7 100644 +--- a/src/lib/krad/attrset.c ++++ b/src/lib/krad/attrset.c +@@ -164,15 +164,44 @@ krad_attrset_copy(const krad_attrset *set, krad_attrset **copy) + return 0; + } + ++/* Place an encoded attributes into outbuf at position *i. Increment *i by the ++ * length of the encoding. */ ++static krb5_error_code ++append_attr(krb5_context ctx, const char *secret, ++ const uint8_t *auth, krad_attr type, const krb5_data *data, ++ uint8_t outbuf[MAX_ATTRSETSIZE], size_t *i, krb5_boolean *is_fips) ++{ ++ uint8_t buffer[MAX_ATTRSIZE]; ++ size_t attrlen; ++ krb5_error_code retval; ++ ++ retval = kr_attr_encode(ctx, secret, auth, type, data, buffer, &attrlen, ++ is_fips); ++ if (retval) ++ return retval; ++ ++ if (attrlen > MAX_ATTRSETSIZE - *i - 2) ++ return EMSGSIZE; ++ ++ outbuf[(*i)++] = type; ++ outbuf[(*i)++] = attrlen + 2; ++ memcpy(outbuf + *i, buffer, attrlen); ++ *i += attrlen; ++ ++ return 0; ++} ++ + krb5_error_code + kr_attrset_encode(const krad_attrset *set, const char *secret, +- const unsigned char *auth, ++ const uint8_t *auth, krb5_boolean add_msgauth, + unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen, + krb5_boolean *is_fips) + { +- unsigned char buffer[MAX_ATTRSIZE]; + krb5_error_code retval; +- size_t i = 0, attrlen; ++ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator"); ++ const uint8_t zeroes[MD5_DIGEST_SIZE] = { 0 }; ++ krb5_data zerodata; ++ size_t i = 0; + attr *a; + + if (set == NULL) { +@@ -180,19 +209,21 @@ kr_attrset_encode(const krad_attrset *set, const char *secret, + return 0; + } + +- K5_TAILQ_FOREACH(a, &set->list, list) { +- retval = kr_attr_encode(set->ctx, secret, auth, a->type, &a->attr, +- buffer, &attrlen, is_fips); +- if (retval != 0) ++ if (add_msgauth) { ++ /* Encode Message-Authenticator as the first attribute, per ++ * draft-ietf-radext-deprecating-radius-03 section 5.2. */ ++ zerodata = make_data((uint8_t *)zeroes, MD5_DIGEST_SIZE); ++ retval = append_attr(set->ctx, secret, auth, msgauth_type, &zerodata, ++ outbuf, &i, is_fips); ++ if (retval) + return retval; ++ } + +- if (i + attrlen + 2 > MAX_ATTRSETSIZE) +- return EMSGSIZE; +- +- outbuf[i++] = a->type; +- outbuf[i++] = attrlen + 2; +- memcpy(&outbuf[i], buffer, attrlen); +- i += attrlen; ++ K5_TAILQ_FOREACH(a, &set->list, list) { ++ retval = append_attr(set->ctx, secret, auth, a->type, &a->attr, ++ outbuf, &i, is_fips); ++ if (retval) ++ return retval; + } + + *outlen = i; +diff --git a/src/lib/krad/internal.h b/src/lib/krad/internal.h +index a17b6f39b1..ca66f3ec68 100644 +--- a/src/lib/krad/internal.h ++++ b/src/lib/krad/internal.h +@@ -49,6 +49,8 @@ + #define UCHAR_MAX 255 + #endif + ++#define MD5_DIGEST_SIZE 16 ++ + /* RFC 2865 */ + #define MAX_ATTRSIZE (UCHAR_MAX - 2) + #define MAX_ATTRSETSIZE (KRAD_PACKET_SIZE_MAX - 20) +@@ -79,10 +81,11 @@ kr_attr_decode(krb5_context ctx, const char *secret, const unsigned char *auth, + krad_attr type, const krb5_data *in, + unsigned char outbuf[MAX_ATTRSIZE], size_t *outlen); + +-/* Encode the attributes into the buffer. */ ++/* Encode set into outbuf. If add_msgauth is true, include a zeroed ++ * Message-Authenticator as the first attribute. */ + krb5_error_code + kr_attrset_encode(const krad_attrset *set, const char *secret, +- const unsigned char *auth, ++ const uint8_t *auth, krb5_boolean add_msgauth, + unsigned char outbuf[MAX_ATTRSETSIZE], size_t *outlen, + krb5_boolean *is_fips); + +diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c +index c5446b890c..3c1a4d507e 100644 +--- a/src/lib/krad/packet.c ++++ b/src/lib/krad/packet.c +@@ -36,6 +36,7 @@ + typedef unsigned char uchar; + + /* RFC 2865 */ ++#define MSGAUTH_SIZE (2 + MD5_DIGEST_SIZE) + #define OFFSET_CODE 0 + #define OFFSET_ID 1 + #define OFFSET_LENGTH 2 +@@ -222,6 +223,106 @@ packet_set_attrset(krb5_context ctx, const char *secret, krad_packet *pkt) + return kr_attrset_decode(ctx, &tmp, secret, pkt_auth(pkt), &pkt->attrset); + } + ++/* Determine if a packet requires a Message-Authenticator attribute. */ ++static inline krb5_boolean ++requires_msgauth(const char *secret, krad_code code) ++{ ++ /* If no secret is provided, assume that the transport is a UNIX socket. ++ * Message-Authenticator is required only on UDP and TCP connections. */ ++ if (*secret == '\0') ++ return FALSE; ++ ++ /* ++ * Per draft-ietf-radext-deprecating-radius-03 sections 5.2.1 and 5.2.4, ++ * Message-Authenticator is required in Access-Request packets and all ++ * potential responses when UDP or TCP transport is used. ++ */ ++ return code == krad_code_name2num("Access-Request") || ++ code == krad_code_name2num("Access-Reject") || ++ code == krad_code_name2num("Access-Accept") || ++ code == krad_code_name2num("Access-Challenge"); ++} ++ ++/* Check if the packet has a Message-Authenticator attribute. */ ++static inline krb5_boolean ++has_pkt_msgauth(const krad_packet *pkt) ++{ ++ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator"); ++ ++ return krad_attrset_get(pkt->attrset, msgauth_type, 0) != NULL; ++} ++ ++/* Return the beginning of the Message-Authenticator attribute in pkt, or NULL ++ * if no such attribute is present. */ ++static const uint8_t * ++lookup_msgauth_addr(const krad_packet *pkt) ++{ ++ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator"); ++ size_t i; ++ uint8_t *p; ++ ++ i = OFFSET_ATTR; ++ while (i + 2 < pkt->pkt.length) { ++ p = (uint8_t *)offset(&pkt->pkt, i); ++ if (msgauth_type == *p) ++ return p; ++ i += p[1]; ++ } ++ ++ return NULL; ++} ++ ++/* ++ * Calculate the message authenticator MAC for pkt as specified in RFC 2869 ++ * section 5.14, placing the result in mac_out. Use the provided authenticator ++ * auth, which may be from pkt or from a corresponding request. ++ */ ++static krb5_error_code ++calculate_mac(const char *secret, const krad_packet *pkt, ++ const uint8_t auth[AUTH_FIELD_SIZE], ++ uint8_t mac_out[MD5_DIGEST_SIZE]) ++{ ++ uint8_t zeroed_msgauth[MSGAUTH_SIZE]; ++ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator"); ++ const uint8_t *msgauth_attr, *msgauth_end, *pkt_end; ++ krb5_crypto_iov input[5]; ++ krb5_data ksecr, mac; ++ ++ msgauth_attr = lookup_msgauth_addr(pkt); ++ if (msgauth_attr == NULL) ++ return EINVAL; ++ msgauth_end = msgauth_attr + MSGAUTH_SIZE; ++ pkt_end = (const uint8_t *)pkt->pkt.data + pkt->pkt.length; ++ ++ /* Read code, id, and length from the packet. */ ++ input[0].flags = KRB5_CRYPTO_TYPE_DATA; ++ input[0].data = make_data(pkt->pkt.data, OFFSET_AUTH); ++ ++ /* Read the provided authenticator. */ ++ input[1].flags = KRB5_CRYPTO_TYPE_DATA; ++ input[1].data = make_data((uint8_t *)auth, AUTH_FIELD_SIZE); ++ ++ /* Read any attributes before Message-Authenticator. */ ++ input[2].flags = KRB5_CRYPTO_TYPE_DATA; ++ input[2].data = make_data(pkt_attr(pkt), msgauth_attr - pkt_attr(pkt)); ++ ++ /* Read Message-Authenticator with the data bytes all set to zero, per RFC ++ * 2869 section 5.14. */ ++ zeroed_msgauth[0] = msgauth_type; ++ zeroed_msgauth[1] = MSGAUTH_SIZE; ++ memset(zeroed_msgauth + 2, 0, MD5_DIGEST_SIZE); ++ input[3].flags = KRB5_CRYPTO_TYPE_DATA; ++ input[3].data = make_data(zeroed_msgauth, MSGAUTH_SIZE); ++ ++ /* Read any attributes after Message-Authenticator. */ ++ input[4].flags = KRB5_CRYPTO_TYPE_DATA; ++ input[4].data = make_data((uint8_t *)msgauth_end, pkt_end - msgauth_end); ++ ++ mac = make_data(mac_out, MD5_DIGEST_SIZE); ++ ksecr = string2data((char *)secret); ++ return k5_hmac_md5(&ksecr, input, 5, &mac); ++} ++ + ssize_t + krad_packet_bytes_needed(const krb5_data *buffer) + { +@@ -255,6 +356,7 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code, + krad_packet *pkt; + uchar id; + size_t attrset_len; ++ krb5_boolean msgauth_required; + + pkt = packet_new(); + if (pkt == NULL) { +@@ -274,9 +376,13 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code, + if (retval != 0) + goto error; + ++ /* Determine if Message-Authenticator is required. */ ++ msgauth_required = (*secret != '\0' && ++ code == krad_code_name2num("Access-Request")); ++ + /* Encode the attributes. */ +- retval = kr_attrset_encode(set, secret, pkt_auth(pkt), pkt_attr(pkt), +- &attrset_len, &pkt->is_fips); ++ retval = kr_attrset_encode(set, secret, pkt_auth(pkt), msgauth_required, ++ pkt_attr(pkt), &attrset_len, &pkt->is_fips); + if (retval != 0) + goto error; + +@@ -285,6 +391,13 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code, + pkt_code_set(pkt, code); + pkt_len_set(pkt, pkt->pkt.length); + ++ if (msgauth_required) { ++ /* Calculate and set the Message-Authenticator MAC. */ ++ retval = calculate_mac(secret, pkt, pkt_auth(pkt), pkt_attr(pkt) + 2); ++ if (retval != 0) ++ goto error; ++ } ++ + /* Copy the attrset for future use. */ + retval = packet_set_attrset(ctx, secret, pkt); + if (retval != 0) +@@ -307,14 +420,19 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code, + krb5_error_code retval; + krad_packet *pkt; + size_t attrset_len; ++ krb5_boolean msgauth_required; + + pkt = packet_new(); + if (pkt == NULL) + return ENOMEM; + ++ /* Determine if Message-Authenticator is required. */ ++ msgauth_required = requires_msgauth(secret, code); ++ + /* Encode the attributes. */ +- retval = kr_attrset_encode(set, secret, pkt_auth(request), pkt_attr(pkt), +- &attrset_len, &pkt->is_fips); ++ retval = kr_attrset_encode(set, secret, pkt_auth(request), ++ msgauth_required, pkt_attr(pkt), &attrset_len, ++ &pkt->is_fips); + if (retval != 0) + goto error; + +@@ -330,6 +448,18 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code, + if (retval != 0) + goto error; + ++ if (msgauth_required) { ++ /* ++ * Calculate and replace the Message-Authenticator MAC. Per RFC 2869 ++ * section 5.14, use the authenticator from the request, not from the ++ * response. ++ */ ++ retval = calculate_mac(secret, pkt, pkt_auth(request), ++ pkt_attr(pkt) + 2); ++ if (retval != 0) ++ goto error; ++ } ++ + /* Copy the attrset for future use. */ + retval = packet_set_attrset(ctx, secret, pkt); + if (retval != 0) +@@ -343,6 +473,34 @@ error: + return retval; + } + ++/* Verify the Message-Authenticator value in pkt, using the provided ++ * authenticator (which may be from pkt or from a corresponding request). */ ++static krb5_error_code ++verify_msgauth(const char *secret, const krad_packet *pkt, ++ const uint8_t auth[AUTH_FIELD_SIZE]) ++{ ++ uint8_t mac[MD5_DIGEST_SIZE]; ++ krad_attr msgauth_type = krad_attr_name2num("Message-Authenticator"); ++ const krb5_data *msgauth; ++ krb5_error_code retval; ++ ++ msgauth = krad_packet_get_attr(pkt, msgauth_type, 0); ++ if (msgauth == NULL) ++ return ENODATA; ++ ++ retval = calculate_mac(secret, pkt, auth, mac); ++ if (retval) ++ return retval; ++ ++ if (msgauth->length != MD5_DIGEST_SIZE) ++ return EMSGSIZE; ++ ++ if (k5_bcmp(mac, msgauth->data, MD5_DIGEST_SIZE) != 0) ++ return EBADMSG; ++ ++ return 0; ++} ++ + /* Decode a packet. */ + static krb5_error_code + decode_packet(krb5_context ctx, const char *secret, const krb5_data *buffer, +@@ -394,21 +552,35 @@ krad_packet_decode_request(krb5_context ctx, const char *secret, + krad_packet **reqpkt) + { + const krad_packet *tmp = NULL; ++ krad_packet *req; + krb5_error_code retval; + +- retval = decode_packet(ctx, secret, buffer, reqpkt); +- if (cb != NULL && retval == 0) { ++ retval = decode_packet(ctx, secret, buffer, &req); ++ if (retval) ++ return retval; ++ ++ /* Verify Message-Authenticator if present. */ ++ if (has_pkt_msgauth(req)) { ++ retval = verify_msgauth(secret, req, pkt_auth(req)); ++ if (retval) { ++ krad_packet_free(req); ++ return retval; ++ } ++ } ++ ++ if (cb != NULL) { + for (tmp = (*cb)(data, FALSE); tmp != NULL; tmp = (*cb)(data, FALSE)) { + if (pkt_id_get(*reqpkt) == pkt_id_get(tmp)) + break; + } +- } + +- if (cb != NULL && (retval != 0 || tmp != NULL)) +- (*cb)(data, TRUE); ++ if (tmp != NULL) ++ (*cb)(data, TRUE); ++ } + ++ *reqpkt = req; + *duppkt = tmp; +- return retval; ++ return 0; + } + + krb5_error_code +@@ -435,9 +607,17 @@ krad_packet_decode_response(krb5_context ctx, const char *secret, + break; + } + +- /* If the authenticator matches, then the response is valid. */ +- if (memcmp(pkt_auth(*rsppkt), auth, sizeof(auth)) == 0) +- break; ++ /* Verify the response authenticator. */ ++ if (k5_bcmp(pkt_auth(*rsppkt), auth, sizeof(auth)) != 0) ++ continue; ++ ++ /* Verify Message-Authenticator if present. */ ++ if (has_pkt_msgauth(*rsppkt)) { ++ if (verify_msgauth(secret, *rsppkt, pkt_auth(tmp)) != 0) ++ continue; ++ } ++ ++ break; + } + } + +diff --git a/src/lib/krad/t_attrset.c b/src/lib/krad/t_attrset.c +index 4cdb8b7d8e..f9c66509bd 100644 +--- a/src/lib/krad/t_attrset.c ++++ b/src/lib/krad/t_attrset.c +@@ -63,7 +63,7 @@ main(void) + noerror(krad_attrset_add(set, krad_attr_name2num("User-Password"), &tmp)); + + /* Encode attrset. */ +- noerror(kr_attrset_encode(set, "foo", auth, buffer, &encode_len, ++ noerror(kr_attrset_encode(set, "foo", auth, FALSE, buffer, &encode_len, + &is_fips)); + krad_attrset_free(set); + +diff --git a/src/lib/krad/t_daemon.py b/src/lib/krad/t_daemon.py +index 4a3de079c7..647d4894eb 100755 +--- a/src/lib/krad/t_daemon.py ++++ b/src/lib/krad/t_daemon.py +@@ -40,6 +40,7 @@ DICTIONARY = """ + ATTRIBUTE\tUser-Name\t1\tstring + ATTRIBUTE\tUser-Password\t2\toctets + ATTRIBUTE\tNAS-Identifier\t32\tstring ++ATTRIBUTE\tMessage-Authenticator\t80\toctets + """ + + class TestServer(server.Server): +@@ -52,7 +53,7 @@ class TestServer(server.Server): + if key == "User-Password": + passwd = [pkt.PwDecrypt(x) for x in pkt[key]] + +- reply = self.CreateReplyPacket(pkt) ++ reply = self.CreateReplyPacket(pkt, message_authenticator=True) + if passwd == ['accept']: + reply.code = packet.AccessAccept + else: +diff --git a/src/lib/krad/t_packet.c b/src/lib/krad/t_packet.c +index c22489144f..104b6507a2 100644 +--- a/src/lib/krad/t_packet.c ++++ b/src/lib/krad/t_packet.c +@@ -172,6 +172,9 @@ main(int argc, const char **argv) + krb5_data username, password; + krb5_boolean auth = FALSE; + krb5_context ctx; ++ const krad_packet *dupreq; ++ const krb5_data *encpkt; ++ krad_packet *decreq; + + username = string2data("testUser"); + +@@ -184,9 +187,17 @@ main(int argc, const char **argv) + + password = string2data("accept"); + noerror(make_packet(ctx, &username, &password, &packets[ACCEPT_PACKET])); ++ encpkt = krad_packet_encode(packets[ACCEPT_PACKET]); ++ noerror(krad_packet_decode_request(ctx, "foo", encpkt, NULL, NULL, ++ &dupreq, &decreq)); ++ krad_packet_free(decreq); + + password = string2data("reject"); + noerror(make_packet(ctx, &username, &password, &packets[REJECT_PACKET])); ++ encpkt = krad_packet_encode(packets[REJECT_PACKET]); ++ noerror(krad_packet_decode_request(ctx, "foo", encpkt, NULL, NULL, ++ &dupreq, &decreq)); ++ krad_packet_free(decreq); + + memset(&hints, 0, sizeof(hints)); + hints.ai_family = AF_INET; +diff --git a/src/tests/t_otp.py b/src/tests/t_otp.py +index c3b820a411..dd5cdc5c26 100755 +--- a/src/tests/t_otp.py ++++ b/src/tests/t_otp.py +@@ -49,6 +49,7 @@ ATTRIBUTE User-Name 1 string + ATTRIBUTE User-Password 2 octets + ATTRIBUTE Service-Type 6 integer + ATTRIBUTE NAS-Identifier 32 string ++ATTRIBUTE Message-Authenticator 80 octets + ''' + + class RadiusDaemon(Process): +@@ -97,6 +98,8 @@ class RadiusDaemon(Process): + reply.code = packet.AccessReject + replyq['reply'] = False + ++ reply.add_message_authenticator() ++ + outq.put(replyq) + if addr is None: + sock.send(reply.ReplyPacket()) +-- +2.46.0 + diff --git a/krb5.spec b/krb5.spec index 9df5405..a7589a6 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 2 +%global baserelease 3 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -78,6 +78,12 @@ Patch0016: 0016-Eliminate-old-style-function-declarations.patch Patch0017: 0017-Fix-two-unlikely-memory-leaks.patch Patch0018: 0018-Fix-unimportant-memory-leaks.patch Patch0019: 0019-Remove-klist-s-defname-global-variable.patch +Patch0020: 0020-End-connection-on-KDC_ERR_SVC_UNAVAILABLE.patch +Patch0021: 0021-Add-request_timeout-configuration-parameter.patch +Patch0022: 0022-Wait-indefinitely-on-KDC-TCP-connections.patch +Patch0023: 0023-Remove-PKINIT-RSA-support.patch +Patch0024: 0024-Fix-various-issues-detected-by-static-analysis.patch +Patch0025: 0025-Generate-and-verify-message-MACs-in-libkrad.patch License: Brian-Gladman-2-Clause AND BSD-2-Clause AND (BSD-2-Clause OR GPL-2.0-or-later) AND BSD-2-Clause-first-lines AND BSD-3-Clause AND BSD-4-Clause AND CMU-Mach-nodoc AND FSFULLRWD AND HPND AND HPND-export2-US AND HPND-export-US AND HPND-export-US-acknowledgement AND HPND-export-US-modify AND ISC AND MIT AND MIT-CMU AND OLDAP-2.8 AND OpenVision URL: https://web.mit.edu/kerberos/www/ @@ -714,6 +720,16 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Wed Oct 30 2024 Julien Rische - 1.21.3-3 +- libkrad: implement support for Message-Authenticator (CVE-2024-3596) + Resolves: rhbz#2304071 +- Fix various issues detected by static analysis + Resolves: rhbz#2322704 +- Remove RSA protocol for PKINIT + Resolves: rhbz#2322706 +- Make TCP waiting time configurable + Resolves: rhbz#2322711 + * Thu Jul 18 2024 Fedora Release Engineering - 1.21.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild From 099df268cebf61ee23d3982c6874ef137d0358e1 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 17 Jan 2025 09:48:45 +0000 Subject: [PATCH 297/304] Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index a7589a6..12c9e25 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 3 +%global baserelease 4 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -720,6 +720,9 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Fri Jan 17 2025 Fedora Release Engineering - 1.21.3-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + * Wed Oct 30 2024 Julien Rische - 1.21.3-3 - libkrad: implement support for Message-Authenticator (CVE-2024-3596) Resolves: rhbz#2304071 From f2bc777d630ff93f1a3806a983cbdf69b2c02a81 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Thu, 19 Dec 2024 16:08:31 +0100 Subject: [PATCH 298/304] krb5 1.21.3-5 - Prevent overflow when calculating ulog block size (CVE-2025-24528) Resolves: rhbz#2342798 - Support PKCS11 EC client certs in PKINIT Resolves: rhbz#2341962 - kdb5_util: fix DB entry flags on modification Resolves: rhbz#2336555 - Add ECDH support for PKINIT (RFC5349) Resolves: rhbz#2214326 - Remove dependency of krb5-libs on gawk and sed Resolves: rhbz#2323859 Signed-off-by: Julien Rische --- 0026-PKINIT-ECDH-support.patch | 1027 ++++++++++ ...with-sha512-256-to-supportedCMSTypes.patch | 78 + 0028-Get-rid-of-pkinit_crypto_openssl.h.patch | 264 +++ ...se-SoftHSMv2-for-PKCS11-PKINIT-tests.patch | 157 ++ ...-Simplify-PKINIT-cert-representation.patch | 202 ++ ...ort-PKCS11-EC-client-certs-in-PKINIT.patch | 1768 +++++++++++++++++ ...ove-PKCS11-error-reporting-in-PKINIT.patch | 599 ++++++ ...-mask-flags-for-kdb5_util-operations.patch | 61 + ...low-when-calculating-ulog-block-size.patch | 64 + krb5.spec | 36 +- 10 files changed, 4252 insertions(+), 4 deletions(-) create mode 100644 0026-PKINIT-ECDH-support.patch create mode 100644 0027-Add-ecdsa-with-sha512-256-to-supportedCMSTypes.patch create mode 100644 0028-Get-rid-of-pkinit_crypto_openssl.h.patch create mode 100644 0029-Use-SoftHSMv2-for-PKCS11-PKINIT-tests.patch create mode 100644 0030-Simplify-PKINIT-cert-representation.patch create mode 100644 0031-Support-PKCS11-EC-client-certs-in-PKINIT.patch create mode 100644 0032-Improve-PKCS11-error-reporting-in-PKINIT.patch create mode 100644 0033-Set-missing-mask-flags-for-kdb5_util-operations.patch create mode 100644 0034-Prevent-overflow-when-calculating-ulog-block-size.patch diff --git a/0026-PKINIT-ECDH-support.patch b/0026-PKINIT-ECDH-support.patch new file mode 100644 index 0000000..14c86be --- /dev/null +++ b/0026-PKINIT-ECDH-support.patch @@ -0,0 +1,1027 @@ +From 5af8bb21de29e3b9a0d5b2001fab71ea102f7990 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 12 May 2023 15:38:46 -0400 +Subject: [PATCH] PKINIT ECDH support + +Add support for elliptic curve key exchange to PKINIT (RFC 5349 +section 4). Extend pkinit_dh_min_bits to allow the string values +"P-256", "P-384", and "P-521", using rough finite-field strength +equivalents to rank them relative to the Oakley Diffie-Hellman groups. + +When processing TD-DH-PARAMETERS on the client, only accept the three +Oakley groups or the three supported elliptic curve groups. +Previously we accepted any Diffie-Hellman parameters that passed +EVP_PKEY_param_check()/DH_check() and had equal or better bit strength +to the original proposal. + +ticket: 9095 (new) +(cherry picked from commit 0f870b1bcad960fd5319a3f97aafd7f4a289e2fb) +--- + doc/admin/conf_files/kdc_conf.rst | 7 +- + doc/admin/conf_files/krb5_conf.rst | 7 +- + src/plugins/preauth/pkinit/pkinit.h | 6 +- + src/plugins/preauth/pkinit/pkinit_clnt.c | 17 +- + src/plugins/preauth/pkinit/pkinit_constants.c | 27 + + src/plugins/preauth/pkinit/pkinit_crypto.h | 7 + + .../preauth/pkinit/pkinit_crypto_openssl.c | 470 ++++++++++++------ + .../preauth/pkinit/pkinit_crypto_openssl.h | 4 +- + src/plugins/preauth/pkinit/pkinit_lib.c | 3 - + src/plugins/preauth/pkinit/pkinit_srv.c | 17 +- + src/plugins/preauth/pkinit/pkinit_trace.h | 11 + + src/tests/t_pkinit.py | 12 + + 12 files changed, 405 insertions(+), 183 deletions(-) + +diff --git a/doc/admin/conf_files/kdc_conf.rst b/doc/admin/conf_files/kdc_conf.rst +index 846c58ed82..fb0593f281 100644 +--- a/doc/admin/conf_files/kdc_conf.rst ++++ b/doc/admin/conf_files/kdc_conf.rst +@@ -768,8 +768,11 @@ For information about the syntax of some of these options, see + be specified multiple times. + + **pkinit_dh_min_bits** +- Specifies the minimum number of bits the KDC is willing to accept +- for a client's Diffie-Hellman key. The default is 2048. ++ Specifies the minimum strength of Diffie-Hellman group the KDC is ++ willing to accept for key exchange. Valid values in order of ++ increasing strength are 1024, 2048, P-256, 4096, P-384, and P-521. ++ The default is 2048. (P-256, P-384, and P-521 are new in release ++ 1.22.) + + **pkinit_allow_upn** + Specifies that the KDC is willing to accept client certificates +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index b7284c47df..dca52e1426 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -1131,9 +1131,10 @@ PKINIT krb5.conf options + option is not recommended. + + **pkinit_dh_min_bits** +- Specifies the size of the Diffie-Hellman key the client will +- attempt to use. The acceptable values are 1024, 2048, and 4096. +- The default is 2048. ++ Specifies the group of the Diffie-Hellman key the client will ++ attempt to use. The acceptable values are 1024, 2048, P-256, ++ 4096, P-384, and P-521. The default is 2048. (P-256, P-384, and ++ P-521 are new in release 1.22.) + + **pkinit_identities** + Specifies the location(s) to be used to find the user's X.509 +diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h +index 5ab0f4bc28..7ba7155bb4 100644 +--- a/src/plugins/preauth/pkinit/pkinit.h ++++ b/src/plugins/preauth/pkinit/pkinit.h +@@ -59,6 +59,10 @@ + + #define PKINIT_DEFAULT_DH_MIN_BITS 2048 + #define PKINIT_DH_MIN_CONFIG_BITS 1024 ++/* Rough finite-field bit strength equivalents for the elliptic curve groups */ ++#define PKINIT_DH_P256_BITS 3072 ++#define PKINIT_DH_P384_BITS 7680 ++#define PKINIT_DH_P521_BITS 15360 + + #define KRB5_CONF_KDCDEFAULTS "kdcdefaults" + #define KRB5_CONF_LIBDEFAULTS "libdefaults" +@@ -101,8 +105,6 @@ static inline void pkiDebug (const char *fmt, ...) { } + #define OCTETDATA_TO_KRB5DATA(octd, k5d) \ + (k5d)->length = (octd)->length; (k5d)->data = (char *)(octd)->data; + +-extern const krb5_data dh_oid; +- + /* + * notes about crypto contexts: + * +diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c +index 54e7537600..b08022a214 100644 +--- a/src/plugins/preauth/pkinit/pkinit_clnt.c ++++ b/src/plugins/preauth/pkinit/pkinit_clnt.c +@@ -681,7 +681,7 @@ pkinit_client_profile(krb5_context context, + const krb5_data *realm) + { + const char *configured_identity; +- char *eku_string = NULL; ++ char *eku_string = NULL, *minbits = NULL; + + pkiDebug("pkinit_client_profile %p %p %p %p\n", + context, plgctx, reqctx, realm); +@@ -690,17 +690,10 @@ pkinit_client_profile(krb5_context context, + KRB5_CONF_PKINIT_REQUIRE_CRL_CHECKING, + reqctx->opts->require_crl_checking, + &reqctx->opts->require_crl_checking); +- pkinit_libdefault_integer(context, realm, +- KRB5_CONF_PKINIT_DH_MIN_BITS, +- reqctx->opts->dh_size, +- &reqctx->opts->dh_size); +- if (reqctx->opts->dh_size != 1024 && reqctx->opts->dh_size != 2048 +- && reqctx->opts->dh_size != 4096) { +- pkiDebug("%s: invalid value (%d) for pkinit_dh_min_bits, " +- "using default value (%d) instead\n", __FUNCTION__, +- reqctx->opts->dh_size, PKINIT_DEFAULT_DH_MIN_BITS); +- reqctx->opts->dh_size = PKINIT_DEFAULT_DH_MIN_BITS; +- } ++ pkinit_libdefault_string(context, realm, KRB5_CONF_PKINIT_DH_MIN_BITS, ++ &minbits); ++ reqctx->opts->dh_size = parse_dh_min_bits(context, minbits); ++ free(minbits); + pkinit_libdefault_string(context, realm, + KRB5_CONF_PKINIT_EKU_CHECKING, + &eku_string); +diff --git a/src/plugins/preauth/pkinit/pkinit_constants.c b/src/plugins/preauth/pkinit/pkinit_constants.c +index 1da482e0b4..10f8688ec2 100644 +--- a/src/plugins/preauth/pkinit/pkinit_constants.c ++++ b/src/plugins/preauth/pkinit/pkinit_constants.c +@@ -320,6 +320,33 @@ static const uint8_t o4096[] = { + 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF + }; + ++/* Named curve prime256v1 (1.2.840.10045.3.1.7) as parameters for RFC 3279 ++ * section 2.3.5 id-ecPublicKey */ ++static const uint8_t p256[] = { ++ 0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x03, 0x01, 0x07 ++}; ++ ++/* Named curve secp384r1 (1.3.132.0.34, from RFC 5480 section 2.1.1.1) as ++ * parameters for RFC 3279 section 2.3.5 id-ecPublicKey */ ++static const uint8_t p384[] = { ++ 0x06, 0x05, 0x2B, 0x81, 0x04, 0x00, 0x22 ++}; ++ ++/* Named curve secp521r1 (1.3.132.0.35, from RFC 5480 section 2.1.1.1) as ++ * parameters for RFC 3279 section 2.3.5 id-ecPublicKey */ ++static const uint8_t p521[] = { ++ 0x06, 0x05, 0x2B, 0x81, 0x04, 0x00, 0x23 ++}; ++ + const krb5_data oakley_1024 = { KV5M_DATA, sizeof(o1024), (char *)o1024 }; + const krb5_data oakley_2048 = { KV5M_DATA, sizeof(o2048), (char *)o2048 }; + const krb5_data oakley_4096 = { KV5M_DATA, sizeof(o4096), (char *)o4096 }; ++const krb5_data ec_p256 = { KV5M_DATA, sizeof(p256), (char *)p256 }; ++const krb5_data ec_p384 = { KV5M_DATA, sizeof(p384), (char *)p384 }; ++const krb5_data ec_p521 = { KV5M_DATA, sizeof(p521), (char *)p521 }; ++ ++/* RFC 3279 section 2.3.3 dhpublicnumber (1.2.840.10046.2.1) */ ++const krb5_data dh_oid = { 0, 7, "\x2A\x86\x48\xce\x3e\x02\x01" }; ++ ++/* RFC 3279 section 2.3.5 id-ecPublicKey (1.2.840.10045.2.1) */ ++const krb5_data ec_oid = { 0, 7, "\x2A\x86\x48\xCE\x3D\x02\x01" }; +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index 04199b45a4..fd876e4850 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -568,6 +568,11 @@ extern const krb5_data sha512_id; + extern const krb5_data oakley_1024; + extern const krb5_data oakley_2048; + extern const krb5_data oakley_4096; ++extern const krb5_data ec_p256; ++extern const krb5_data ec_p384; ++extern const krb5_data ec_p521; ++extern const krb5_data dh_oid; ++extern const krb5_data ec_oid; + + /** + * An ordered set of OIDs, stored as krb5_data, of KDF algorithms +@@ -590,4 +595,6 @@ crypto_req_cert_matching_data(krb5_context context, + pkinit_req_crypto_context reqctx, + pkinit_cert_matching_data **md_out); + ++int parse_dh_min_bits(krb5_context context, const char *str); ++ + #endif /* _PKINIT_CRYPTO_H */ +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 26fa9184b3..f6d494bd11 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -181,6 +181,15 @@ compat_get0_DH(const EVP_PKEY *pkey) + + } + ++#define EVP_PKEY_get0_EC_KEY compat_get0_EC ++static EC_KEY * ++compat_get0_EC(const EVP_PKEY *pkey) ++{ ++ if (pkey->type != EVP_PKEY_EC) ++ return NULL; ++ return pkey->pkey.ec; ++} ++ + /* Return true if the cert c includes a key usage which doesn't include u. + * Define using direct member access for pre-1.1. */ + #define ku_reject(c, u) \ +@@ -260,37 +269,11 @@ decode_bn_der(const uint8_t *der, size_t len) + return bn; + } + +-#if OPENSSL_VERSION_NUMBER >= 0x10100000L +-static int +-params_valid(EVP_PKEY *params) +-{ +- EVP_PKEY_CTX *ctx; +- int result; +- +- ctx = EVP_PKEY_CTX_new(params, NULL); +- if (ctx == NULL) +- return 0; +- result = EVP_PKEY_param_check(ctx); +- EVP_PKEY_CTX_free(ctx); +- return result == 1; +-} +-#else +-static int +-params_valid(EVP_PKEY *params) +-{ +- DH *dh; +- int codes; +- +- dh = EVP_PKEY_get0_DH(params); +- return (dh == NULL) ? 0 : (DH_check(dh, &codes) && codes == 0); +-} +-#endif +- + #if OPENSSL_VERSION_NUMBER >= 0x10100000L + + #if OPENSSL_VERSION_NUMBER >= 0x30000000L + static EVP_PKEY * +-decode_dh_params(const krb5_data *params_der) ++decode_params(const krb5_data *params_der, const char *type) + { + EVP_PKEY *pkey = NULL; + const uint8_t *inptr = (uint8_t *)params_der->data; +@@ -298,7 +281,7 @@ decode_dh_params(const krb5_data *params_der) + OSSL_DECODER_CTX *dctx; + int ok; + +- dctx = OSSL_DECODER_CTX_new_for_pkey(&pkey, "DER", "type-specific", "DHX", ++ dctx = OSSL_DECODER_CTX_new_for_pkey(&pkey, "DER", "type-specific", type, + EVP_PKEY_KEY_PARAMETERS, NULL, NULL); + if (dctx == NULL) + return NULL; +@@ -307,7 +290,15 @@ decode_dh_params(const krb5_data *params_der) + OSSL_DECODER_CTX_free(dctx); + return ok ? pkey : NULL; + } ++ ++static EVP_PKEY * ++decode_dh_params(const krb5_data *params_der) ++{ ++ return decode_params(params_der, "DHX"); ++} ++ + #else ++ + static EVP_PKEY * + decode_dh_params(const krb5_data *params_der) + { +@@ -320,6 +311,7 @@ decode_dh_params(const krb5_data *params_der) + DH_free(dh); + return pkey; + } ++ + #endif + + static krb5_error_code +@@ -520,6 +512,39 @@ cleanup: + + #endif /* OPENSSL_VERSION_NUMBER < 0x10100000L */ + ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++ ++static EVP_PKEY * ++decode_ec_params(const krb5_data *params_der) ++{ ++ return decode_params(params_der, "EC"); ++} ++ ++#else /* OPENSSL_VERSION_NUMBER < 0x30000000L */ ++ ++static EVP_PKEY * ++decode_ec_params(const krb5_data *params_der) ++{ ++ const uint8_t *p = (uint8_t *)params_der->data; ++ EC_KEY *eckey; ++ EVP_PKEY *pkey; ++ ++ eckey = d2i_ECParameters(NULL, &p, params_der->length); ++ if (eckey == NULL) ++ return NULL; ++ pkey = EVP_PKEY_new(); ++ if (pkey != NULL) { ++ if (!EVP_PKEY_set1_EC_KEY(pkey, eckey)) { ++ EVP_PKEY_free(pkey); ++ pkey = NULL; ++ } ++ } ++ EC_KEY_free(eckey); ++ return pkey; ++} ++ ++#endif /* OPENSSL_VERSION_NUMBER < 0x30000000L */ ++ + /* Attempt to specify padded Diffie-Hellman result derivation. Don't error out + * if this fails since we also detect short results and adjust them. */ + #if OPENSSL_VERSION_NUMBER >= 0x30000000L +@@ -551,7 +576,8 @@ dh_result(EVP_PKEY *pkey, EVP_PKEY *peer, + EVP_PKEY_CTX *derive_ctx = NULL; + int ok = 0; + uint8_t *buf = NULL; +- size_t len, dh_size = EVP_PKEY_get_size(pkey); ++ size_t len, result_size; ++ krb5_boolean ecc = (EVP_PKEY_id(pkey) == EVP_PKEY_EC); + + *result_out = NULL; + *len_out = 0; +@@ -561,24 +587,39 @@ dh_result(EVP_PKEY *pkey, EVP_PKEY *peer, + goto cleanup; + if (EVP_PKEY_derive_init(derive_ctx) <= 0) + goto cleanup; +- set_padded_derivation(derive_ctx); ++ if (!ecc) ++ set_padded_derivation(derive_ctx); + if (EVP_PKEY_derive_set_peer(derive_ctx, peer) <= 0) + goto cleanup; + +- buf = malloc(dh_size); ++ if (ecc) { ++ if (EVP_PKEY_derive(derive_ctx, NULL, &result_size) <= 0) ++ goto cleanup; ++ } else { ++ /* ++ * For finite-field Diffie-Hellman we must ensure that the result ++ * matches the key size (normally through padded derivation, but that ++ * isn't supported by OpenSSL 1.0 so we must check). ++ */ ++ result_size = EVP_PKEY_get_size(pkey); ++ } ++ buf = malloc(result_size); + if (buf == NULL) + goto cleanup; +- len = dh_size; ++ len = result_size; + if (EVP_PKEY_derive(derive_ctx, buf, &len) <= 0) + goto cleanup; +- if (len < dh_size) { /* only possible without padded derivation */ +- memmove(buf + (dh_size - len), buf, len); +- memset(buf, 0, dh_size - len); ++ ++ /* If we couldn't specify padded derivation for finite-field DH we may need ++ * to fix up the result by right-shifting it within the buffer. */ ++ if (len < result_size) { ++ memmove(buf + (result_size - len), buf, len); ++ memset(buf, 0, result_size - len); + } + + ok = 1; + *result_out = buf; +- *len_out = dh_size; ++ *len_out = result_size; + buf = NULL; + + cleanup: +@@ -592,13 +633,21 @@ static int + dh_pubkey_der(EVP_PKEY *pkey, uint8_t **pubkey_out, unsigned int *len_out) + { + BIGNUM *pubkey_bn = NULL; +- int len, ok; +- uint8_t *buf; +- +- if (!EVP_PKEY_get_bn_param(pkey, OSSL_PKEY_PARAM_PUB_KEY, &pubkey_bn)) +- return 0; +- ok = encode_bn_der(pubkey_bn, &buf, &len); +- BN_free(pubkey_bn); ++ int len, ok = 0; ++ uint8_t *buf, *outptr; ++ ++ if (EVP_PKEY_id(pkey) == EVP_PKEY_EC) { ++ len = i2d_PublicKey(pkey, NULL); ++ if (len > 0 && (outptr = buf = malloc(len)) != NULL) { ++ (void)i2d_PublicKey(pkey, &outptr); ++ ok = 1; ++ } ++ } else { ++ if (!EVP_PKEY_get_bn_param(pkey, OSSL_PKEY_PARAM_PUB_KEY, &pubkey_bn)) ++ return 0; ++ ok = encode_bn_der(pubkey_bn, &buf, &len); ++ BN_free(pubkey_bn); ++ } + if (ok) { + *pubkey_out = buf; + *len_out = len; +@@ -610,19 +659,33 @@ static int + dh_pubkey_der(EVP_PKEY *pkey, uint8_t **pubkey_out, unsigned int *len_out) + { + const DH *dh; ++ EC_KEY *eckey; /* can be const when OpenSSL 1.0 dropped */ + const BIGNUM *pubkey_bn; +- uint8_t *buf; ++ uint8_t *buf, *outptr; + int len; + + dh = EVP_PKEY_get0_DH(pkey); +- if (dh == NULL) +- return 0; +- DH_get0_key(dh, &pubkey_bn, NULL); +- if (!encode_bn_der(pubkey_bn, &buf, &len)) +- return 0; +- *pubkey_out = buf; +- *len_out = len; +- return 1; ++ if (dh != NULL) { ++ DH_get0_key(dh, &pubkey_bn, NULL); ++ if (!encode_bn_der(pubkey_bn, &buf, &len)) ++ return 0; ++ *pubkey_out = buf; ++ *len_out = len; ++ return 1; ++ } ++ ++ eckey = EVP_PKEY_get0_EC_KEY(pkey); ++ if (eckey != NULL) { ++ len = i2o_ECPublicKey(eckey, NULL); ++ if (len > 0 && (outptr = buf = malloc(len)) != NULL) { ++ (void)i2o_ECPublicKey(eckey, &outptr); ++ *pubkey_out = buf; ++ *len_out = len; ++ return 1; ++ } ++ } ++ ++ return 0; + } + #endif + +@@ -686,17 +749,23 @@ compose_dh_pkey(EVP_PKEY *params, const uint8_t *pubkey_der, size_t der_len) + if (pkey == NULL) + goto cleanup; + +- pubkey_bn = decode_bn_der(pubkey_der, der_len); +- if (pubkey_bn == NULL) +- goto cleanup; +- binlen = EVP_PKEY_get_size(pkey); +- pubkey_bin = malloc(binlen); +- if (pubkey_bin == NULL) +- goto cleanup; +- if (BN_bn2binpad(pubkey_bn, pubkey_bin, binlen) != binlen) +- goto cleanup; +- if (EVP_PKEY_set1_encoded_public_key(pkey, pubkey_bin, binlen) != 1) +- goto cleanup; ++ if (EVP_PKEY_id(params) == EVP_PKEY_EC) { ++ if (d2i_PublicKey(EVP_PKEY_id(params), &pkey, &pubkey_der, ++ der_len) == NULL) ++ goto cleanup; ++ } else { ++ pubkey_bn = decode_bn_der(pubkey_der, der_len); ++ if (pubkey_bn == NULL) ++ goto cleanup; ++ binlen = EVP_PKEY_get_size(pkey); ++ pubkey_bin = malloc(binlen); ++ if (pubkey_bin == NULL) ++ goto cleanup; ++ if (BN_bn2binpad(pubkey_bn, pubkey_bin, binlen) != binlen) ++ goto cleanup; ++ if (EVP_PKEY_set1_encoded_public_key(pkey, pubkey_bin, binlen) != 1) ++ goto cleanup; ++ } + + pkey_ret = pkey; + pkey = NULL; +@@ -741,29 +810,60 @@ static EVP_PKEY * + compose_dh_pkey(EVP_PKEY *params, const uint8_t *pubkey_der, size_t der_len) + { + DH *dhparams, *dh = NULL; +- EVP_PKEY *pkey = NULL; ++ EVP_PKEY *pkey = NULL, *pkey_ret = NULL; + BIGNUM *pubkey_bn = NULL; ++ EC_KEY *params_eckey, *eckey = NULL; ++ const EC_GROUP *group; ++ ++ if (EVP_PKEY_id(params) == EVP_PKEY_EC) { ++ /* We would like to use EVP_PKEY_copy_parameters() and d2i_PublicKey(), ++ * but the latter is broken in OpenSSL 1.1.0-1.1.1a for EC keys. */ ++ params_eckey = EVP_PKEY_get0_EC_KEY(params); ++ if (params_eckey == NULL) ++ goto cleanup; ++ group = EC_KEY_get0_group(params_eckey); ++ eckey = EC_KEY_new(); ++ if (eckey == NULL) ++ goto cleanup; ++ if (!EC_KEY_set_group(eckey, group)) ++ goto cleanup; ++ if (o2i_ECPublicKey(&eckey, &pubkey_der, der_len) == NULL) ++ goto cleanup; ++ pkey = EVP_PKEY_new(); ++ if (pkey == NULL) ++ return NULL; ++ if (!EVP_PKEY_assign(pkey, EVP_PKEY_EC, eckey)) { ++ EVP_PKEY_free(pkey); ++ return NULL; ++ } ++ eckey = NULL; ++ } else { ++ pubkey_bn = decode_bn_der(pubkey_der, der_len); ++ if (pubkey_bn == NULL) ++ goto cleanup; + +- pubkey_bn = decode_bn_der(pubkey_der, der_len); +- if (pubkey_bn == NULL) +- goto cleanup; ++ dhparams = EVP_PKEY_get0_DH(params); ++ if (dhparams == NULL) ++ goto cleanup; ++ dh = dup_dh_params(dhparams); ++ if (dh == NULL) ++ goto cleanup; ++ if (!DH_set0_key(dh, pubkey_bn, NULL)) ++ goto cleanup; ++ pubkey_bn = NULL; + +- dhparams = EVP_PKEY_get0_DH(params); +- if (dhparams == NULL) +- goto cleanup; +- dh = dup_dh_params(dhparams); +- if (dh == NULL) +- goto cleanup; +- if (!DH_set0_key(dh, pubkey_bn, NULL)) +- goto cleanup; +- pubkey_bn = NULL; ++ pkey = dh_to_pkey(&dh); ++ } + +- pkey = dh_to_pkey(&dh); ++ pkey_ret = pkey; ++ pkey = NULL; + + cleanup: + BN_free(pubkey_bn); + DH_free(dh); +- return pkey; ++ EC_KEY_free(eckey); ++ EVP_PKEY_free(pkey); ++ return pkey_ret; + } + + #endif /* OPENSSL_VERSION_NUMBER < 0x30000000L */ +@@ -1032,7 +1132,6 @@ pkinit_init_req_crypto(pkinit_req_crypto_context *cryptoctx) + memset(ctx, 0, sizeof(*ctx)); + + ctx->client_pkey = NULL; +- ctx->received_params = NULL; + ctx->received_cert = NULL; + + *cryptoctx = ctx; +@@ -1054,7 +1153,6 @@ pkinit_fini_req_crypto(pkinit_req_crypto_context req_cryptoctx) + + pkiDebug("%s: freeing ctx at %p\n", __FUNCTION__, req_cryptoctx); + EVP_PKEY_free(req_cryptoctx->client_pkey); +- EVP_PKEY_free(req_cryptoctx->received_params); + X509_free(req_cryptoctx->received_cert); + + free(req_cryptoctx); +@@ -1258,9 +1356,9 @@ pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ctx) + + static int + try_import_group(krb5_context context, const krb5_data *params, +- const char *name, EVP_PKEY **pkey_out) ++ const char *name, krb5_boolean ec, EVP_PKEY **pkey_out) + { +- *pkey_out = decode_dh_params(params); ++ *pkey_out = ec ? decode_ec_params(params) : decode_dh_params(params); + if (*pkey_out == NULL) + TRACE_PKINIT_DH_GROUP_UNAVAILABLE(context, name); + return (*pkey_out != NULL) ? 1 : 0; +@@ -1271,12 +1369,15 @@ pkinit_init_dh_params(krb5_context context, pkinit_plg_crypto_context plgctx) + { + int n = 0; + +- n += try_import_group(context, &oakley_1024, "MODP 2 (1024-bit)", ++ n += try_import_group(context, &oakley_1024, "MODP 2 (1024-bit)", FALSE, + &plgctx->dh_1024); +- n += try_import_group(context, &oakley_2048, "MODP 14 (2048-bit)", ++ n += try_import_group(context, &oakley_2048, "MODP 14 (2048-bit)", FALSE, + &plgctx->dh_2048); +- n += try_import_group(context, &oakley_4096, "MODP 16 (4096-bit)", ++ n += try_import_group(context, &oakley_4096, "MODP 16 (4096-bit)", FALSE, + &plgctx->dh_4096); ++ n += try_import_group(context, &ec_p256, "P-256", TRUE, &plgctx->ec_p256); ++ n += try_import_group(context, &ec_p384, "P-384", TRUE, &plgctx->ec_p384); ++ n += try_import_group(context, &ec_p521, "P-521", TRUE, &plgctx->ec_p521); + + if (n == 0) { + pkinit_fini_dh_params(plgctx); +@@ -1294,7 +1395,11 @@ pkinit_fini_dh_params(pkinit_plg_crypto_context plgctx) + EVP_PKEY_free(plgctx->dh_1024); + EVP_PKEY_free(plgctx->dh_2048); + EVP_PKEY_free(plgctx->dh_4096); ++ EVP_PKEY_free(plgctx->ec_p256); ++ EVP_PKEY_free(plgctx->ec_p384); ++ EVP_PKEY_free(plgctx->ec_p521); + plgctx->dh_1024 = plgctx->dh_2048 = plgctx->dh_4096 = NULL; ++ plgctx->ec_p256 = plgctx->ec_p384 = plgctx->ec_p521 = NULL; + } + + static krb5_error_code +@@ -2711,6 +2816,62 @@ cleanup: + return ret; + } + ++/* Return the equivalent finite-field bit strength of pkey if it matches a ++ * well-known group, or -1 if it doesn't. */ ++static int ++check_dh_wellknown(pkinit_plg_crypto_context cryptoctx, EVP_PKEY *pkey) ++{ ++ int nbits = EVP_PKEY_get_bits(pkey); ++ ++ if (nbits == 1024 && EVP_PKEY_parameters_eq(cryptoctx->dh_1024, pkey) == 1) ++ return nbits; ++ if (nbits == 2048 && EVP_PKEY_parameters_eq(cryptoctx->dh_2048, pkey) == 1) ++ return nbits; ++ if (nbits == 4096 && EVP_PKEY_parameters_eq(cryptoctx->dh_4096, pkey) == 1) ++ return nbits; ++ if (nbits == 256 && EVP_PKEY_parameters_eq(cryptoctx->ec_p256, pkey) == 1) ++ return PKINIT_DH_P256_BITS; ++ if (nbits == 384 && EVP_PKEY_parameters_eq(cryptoctx->ec_p384, pkey) == 1) ++ return PKINIT_DH_P384_BITS; ++ if (nbits == 521 && EVP_PKEY_parameters_eq(cryptoctx->ec_p521, pkey) == 1) ++ return PKINIT_DH_P521_BITS; ++ return -1; ++} ++ ++/* Return a short description of the Diffie-Hellman group with the given ++ * finite-field group size equivalent. */ ++static const char * ++group_desc(int dh_bits) ++{ ++ switch (dh_bits) { ++ case PKINIT_DH_P256_BITS: return "P-256"; ++ case PKINIT_DH_P384_BITS: return "P-384"; ++ case PKINIT_DH_P521_BITS: return "P-521"; ++ case 1024: return "1024-bit DH"; ++ case 2048: return "2048-bit DH"; ++ case 4096: return "4096-bit DH"; ++ } ++ return "(unknown)"; ++} ++ ++static EVP_PKEY * ++choose_dh_group(pkinit_plg_crypto_context plg_cryptoctx, int dh_size) ++{ ++ if (dh_size == 1024) ++ return plg_cryptoctx->dh_1024; ++ if (dh_size == 2048) ++ return plg_cryptoctx->dh_2048; ++ if (dh_size == 4096) ++ return plg_cryptoctx->dh_4096; ++ if (dh_size == PKINIT_DH_P256_BITS) ++ return plg_cryptoctx->ec_p256; ++ if (dh_size == PKINIT_DH_P384_BITS) ++ return plg_cryptoctx->ec_p384; ++ if (dh_size == PKINIT_DH_P521_BITS) ++ return plg_cryptoctx->ec_p521; ++ return NULL; ++} ++ + krb5_error_code + client_create_dh(krb5_context context, + pkinit_plg_crypto_context plg_cryptoctx, +@@ -2723,16 +2884,10 @@ client_create_dh(krb5_context context, + + *spki_out = empty_data(); + +- if (cryptoctx->received_params != NULL) +- params = cryptoctx->received_params; +- else if (plg_cryptoctx->dh_1024 != NULL && dh_size == 1024) +- params = plg_cryptoctx->dh_1024; +- else if (plg_cryptoctx->dh_2048 != NULL && dh_size == 2048) +- params = plg_cryptoctx->dh_2048; +- else if (plg_cryptoctx->dh_4096 != NULL && dh_size == 4096) +- params = plg_cryptoctx->dh_4096; +- else ++ params = choose_dh_group(plg_cryptoctx, dh_size); ++ if (params == NULL) + goto cleanup; ++ TRACE_PKINIT_DH_PROPOSING_GROUP(context, group_desc(dh_size)); + + pkey = generate_dh_pkey(params); + if (pkey == NULL) +@@ -2772,8 +2927,11 @@ client_process_dh(krb5_context context, + server_pkey = compose_dh_pkey(cryptoctx->client_pkey, + subjectPublicKey_data, + subjectPublicKey_length); +- if (server_pkey == NULL) ++ if (server_pkey == NULL) { ++ retval = KRB5_PREAUTH_FAILED; ++ k5_setmsg(context, retval, _("Cannot compose PKINIT KDC public key")); + goto cleanup; ++ } + + if (!dh_result(cryptoctx->client_pkey, server_pkey, + &client_key, &client_key_len)) +@@ -2797,20 +2955,6 @@ cleanup: + return retval; + } + +-/* Return 1 if dh is a permitted well-known group, otherwise return 0. */ +-static int +-check_dh_wellknown(pkinit_plg_crypto_context cryptoctx, EVP_PKEY *pkey, +- int nbits) +-{ +- if (nbits == 1024) +- return EVP_PKEY_parameters_eq(cryptoctx->dh_1024, pkey) == 1; +- else if (nbits == 2048) +- return EVP_PKEY_parameters_eq(cryptoctx->dh_2048, pkey) == 1; +- else if (nbits == 4096) +- return EVP_PKEY_parameters_eq(cryptoctx->dh_4096, pkey) == 1; +- return 0; +-} +- + krb5_error_code + server_check_dh(krb5_context context, + pkinit_plg_crypto_context cryptoctx, +@@ -2820,7 +2964,7 @@ server_check_dh(krb5_context context, + int minbits) + { + EVP_PKEY *client_pkey = NULL; +- int dh_prime_bits; ++ int dh_bits; + krb5_error_code retval = KRB5KDC_ERR_DH_KEY_PARAMETERS_NOT_ACCEPTED; + + client_pkey = decode_spki(client_spki); +@@ -2829,16 +2973,15 @@ server_check_dh(krb5_context context, + goto cleanup; + } + +- /* KDC SHOULD check to see if the key parameters satisfy its policy */ +- dh_prime_bits = EVP_PKEY_get_bits(client_pkey); +- if (minbits && dh_prime_bits < minbits) { +- pkiDebug("client sent dh params with %d bits, we require %d\n", +- dh_prime_bits, minbits); ++ dh_bits = check_dh_wellknown(cryptoctx, client_pkey); ++ if (dh_bits == -1 || dh_bits < minbits) { ++ TRACE_PKINIT_DH_REJECTING_GROUP(context, group_desc(dh_bits), ++ group_desc(minbits)); + goto cleanup; + } ++ TRACE_PKINIT_DH_RECEIVED_GROUP(context, group_desc(dh_bits)); + +- if (check_dh_wellknown(cryptoctx, client_pkey, dh_prime_bits)) +- retval = 0; ++ retval = 0; + + cleanup: + if (retval == 0) +@@ -3023,9 +3166,20 @@ pkinit_create_td_dh_parameters(krb5_context context, + krb5_algorithm_identifier alg_1024 = { dh_oid, oakley_1024 }; + krb5_algorithm_identifier alg_2048 = { dh_oid, oakley_2048 }; + krb5_algorithm_identifier alg_4096 = { dh_oid, oakley_4096 }; +- krb5_algorithm_identifier *alglist[4]; ++ krb5_algorithm_identifier alg_p256 = { ec_oid, ec_p256 }; ++ krb5_algorithm_identifier alg_p384 = { ec_oid, ec_p384 }; ++ krb5_algorithm_identifier alg_p521 = { ec_oid, ec_p521 }; ++ krb5_algorithm_identifier *alglist[7]; + + i = 0; ++ if (plg_cryptoctx->ec_p256 != NULL && ++ opts->dh_min_bits <= PKINIT_DH_P256_BITS) ++ alglist[i++] = &alg_p256; ++ if (plg_cryptoctx->ec_p384 != NULL && ++ opts->dh_min_bits <= PKINIT_DH_P384_BITS) ++ alglist[i++] = &alg_p384; ++ if (plg_cryptoctx->ec_p521 != NULL) ++ alglist[i++] = &alg_p521; + if (plg_cryptoctx->dh_2048 != NULL && opts->dh_min_bits <= 2048) + alglist[i++] = &alg_2048; + if (plg_cryptoctx->dh_4096 != NULL && opts->dh_min_bits <= 4096) +@@ -3110,13 +3264,10 @@ pkinit_process_td_dh_params(krb5_context context, + { + krb5_error_code retval = KRB5KDC_ERR_DH_KEY_PARAMETERS_NOT_ACCEPTED; + EVP_PKEY *params = NULL; +- int i, dh_prime_bits, old_dh_size; ++ int i, dh_bits, old_dh_size; + + pkiDebug("dh parameters\n"); + +- EVP_PKEY_free(req_cryptoctx->received_params); +- req_cryptoctx->received_params = NULL; +- + old_dh_size = *new_dh_size; + + for (i = 0; algId[i] != NULL; i++) { +@@ -3124,36 +3275,22 @@ pkinit_process_td_dh_params(krb5_context context, + EVP_PKEY_free(params); + params = NULL; + +- /* Skip any parameters for algorithms other than DH. */ +- if (algId[i]->algorithm.length != dh_oid.length || +- memcmp(algId[i]->algorithm.data, dh_oid.data, dh_oid.length)) +- continue; +- +- params = decode_dh_params(&algId[i]->parameters); ++ if (data_eq(algId[i]->algorithm, dh_oid)) ++ params = decode_dh_params(&algId[i]->parameters); ++ else if (data_eq(algId[i]->algorithm, ec_oid)) ++ params = decode_ec_params(&algId[i]->parameters); + if (params == NULL) + continue; +- dh_prime_bits = EVP_PKEY_get_bits(params); +- /* Skip any parameters shorter than the previous size. */ +- if (dh_prime_bits < old_dh_size) +- continue; +- pkiDebug("client sent %d DH bits server prefers %d DH bits\n", +- *new_dh_size, dh_prime_bits); + +- /* If this is one of our well-known groups, just save the new size; we +- * will use our own copy of the parameters. */ +- if (check_dh_wellknown(cryptoctx, params, dh_prime_bits)) { +- *new_dh_size = dh_prime_bits; +- retval = 0; +- goto cleanup; +- } ++ dh_bits = check_dh_wellknown(cryptoctx, params); ++ /* Skip any parameters shorter than the previous size or unknown. */ ++ if (dh_bits == -1 || dh_bits < old_dh_size) ++ continue; ++ TRACE_PKINIT_DH_NEGOTIATED_GROUP(context, group_desc(dh_bits)); + +- /* If the parameters aren't well-known but check out, save them. */ +- if (params_valid(params)) { +- req_cryptoctx->received_params = params; +- params = NULL; +- retval = 0; +- goto cleanup; +- } ++ *new_dh_size = dh_bits; ++ retval = 0; ++ goto cleanup; + } + + cleanup: +@@ -5329,3 +5466,40 @@ crypto_req_cert_matching_data(krb5_context context, + return get_matching_data(context, plgctx, reqctx, reqctx->received_cert, + md_out); + } ++ ++/* ++ * Historically, the strength of PKINIT key exchange has been determined by the ++ * pkinit_dh_min_bits variable, which gives a finite field size. With the ++ * addition of ECDH support, we allow the string values P-256, P-384, and P-521 ++ * for this config variable, represented with the rough equivalent bit ++ * strengths for finite fields. ++ */ ++int ++parse_dh_min_bits(krb5_context context, const char *str) ++{ ++ char *endptr; ++ long n; ++ ++ if (str == NULL) ++ return PKINIT_DEFAULT_DH_MIN_BITS; ++ ++ n = strtol(str, &endptr, 0); ++ if (endptr == str) { ++ if (strcasecmp(str, "P-256") == 0) ++ return PKINIT_DH_P256_BITS; ++ else if (strcasecmp(str, "P-384") == 0) ++ return PKINIT_DH_P384_BITS; ++ else if (strcasecmp(str, "P-521") == 0) ++ return PKINIT_DH_P521_BITS; ++ } else { ++ if (n == 1024) ++ return 1024; ++ else if (n > 1024 && n <= 2048) ++ return 2048; ++ else if (n > 2048 && n <= 4096) ++ return 4096; ++ } ++ ++ TRACE_PKINIT_DH_INVALID_MIN_BITS(context, str); ++ return PKINIT_DEFAULT_DH_MIN_BITS; ++} +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h +index c807f044ac..b7a3358800 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h +@@ -99,6 +99,9 @@ struct _pkinit_plg_crypto_context { + EVP_PKEY *dh_1024; + EVP_PKEY *dh_2048; + EVP_PKEY *dh_4096; ++ EVP_PKEY *ec_p256; ++ EVP_PKEY *ec_p384; ++ EVP_PKEY *ec_p521; + ASN1_OBJECT *id_pkinit_authData; + ASN1_OBJECT *id_pkinit_DHKeyData; + ASN1_OBJECT *id_pkinit_rkeyData; +@@ -113,7 +116,6 @@ struct _pkinit_plg_crypto_context { + struct _pkinit_req_crypto_context { + X509 *received_cert; + EVP_PKEY *client_pkey; +- EVP_PKEY *received_params; + }; + + #endif /* _PKINIT_CRYPTO_OPENSSL_H */ +diff --git a/src/plugins/preauth/pkinit/pkinit_lib.c b/src/plugins/preauth/pkinit/pkinit_lib.c +index 19db695a4d..25965eb5d2 100644 +--- a/src/plugins/preauth/pkinit/pkinit_lib.c ++++ b/src/plugins/preauth/pkinit/pkinit_lib.c +@@ -33,9 +33,6 @@ + + #define FAKECERT + +-const krb5_data dh_oid = { 0, 7, "\x2A\x86\x48\xce\x3e\x02\x01" }; +- +- + krb5_error_code + pkinit_init_req_opts(pkinit_req_opts **reqopts) + { +diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c +index aab21f951c..e22bcb195b 100644 +--- a/src/plugins/preauth/pkinit/pkinit_srv.c ++++ b/src/plugins/preauth/pkinit/pkinit_srv.c +@@ -988,7 +988,7 @@ static krb5_error_code + pkinit_init_kdc_profile(krb5_context context, pkinit_kdc_context plgctx) + { + krb5_error_code retval; +- char *eku_string = NULL, *ocsp_check = NULL; ++ char *eku_string = NULL, *ocsp_check = NULL, *minbits = NULL; + + pkiDebug("%s: entered for realm %s\n", __FUNCTION__, plgctx->realmname); + retval = pkinit_kdcdefault_string(context, plgctx->realmname, +@@ -1033,17 +1033,10 @@ pkinit_init_kdc_profile(krb5_context context, pkinit_kdc_context plgctx) + goto errout; + } + +- pkinit_kdcdefault_integer(context, plgctx->realmname, +- KRB5_CONF_PKINIT_DH_MIN_BITS, +- PKINIT_DEFAULT_DH_MIN_BITS, +- &plgctx->opts->dh_min_bits); +- if (plgctx->opts->dh_min_bits < PKINIT_DH_MIN_CONFIG_BITS) { +- pkiDebug("%s: invalid value (%d < %d) for pkinit_dh_min_bits, " +- "using default value (%d) instead\n", __FUNCTION__, +- plgctx->opts->dh_min_bits, PKINIT_DH_MIN_CONFIG_BITS, +- PKINIT_DEFAULT_DH_MIN_BITS); +- plgctx->opts->dh_min_bits = PKINIT_DEFAULT_DH_MIN_BITS; +- } ++ pkinit_kdcdefault_string(context, plgctx->realmname, ++ KRB5_CONF_PKINIT_DH_MIN_BITS, &minbits); ++ plgctx->opts->dh_min_bits = parse_dh_min_bits(context, minbits); ++ free(minbits); + + pkinit_kdcdefault_boolean(context, plgctx->realmname, + KRB5_CONF_PKINIT_ALLOW_UPN, +diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h +index d385759145..1c1ceb5a41 100644 +--- a/src/plugins/preauth/pkinit/pkinit_trace.h ++++ b/src/plugins/preauth/pkinit/pkinit_trace.h +@@ -83,6 +83,17 @@ + + #define TRACE_PKINIT_DH_GROUP_UNAVAILABLE(c, name) \ + TRACE(c, "PKINIT key exchange group {str} unsupported", name) ++#define TRACE_PKINIT_DH_INVALID_MIN_BITS(c, str) \ ++ TRACE(c, "Invalid pkinit_dh_min_bits value {str}, using default", str) ++#define TRACE_PKINIT_DH_NEGOTIATED_GROUP(c, desc) \ ++ TRACE(c, "PKINIT accepting KDC key exchange group preference {str}", desc) ++#define TRACE_PKINIT_DH_PROPOSING_GROUP(c, desc) \ ++ TRACE(c, "PKINIT using {str} key exchange group", desc) ++#define TRACE_PKINIT_DH_RECEIVED_GROUP(c, desc) \ ++ TRACE(c, "PKINIT received {str} key from client for key exchange", desc) ++#define TRACE_PKINIT_DH_REJECTING_GROUP(c, desc, mindesc) \ ++ TRACE(c, "PKINIT client key has group {str}, need at least {str}", \ ++ desc, mindesc) + + #define TRACE_PKINIT_OPENSSL_ERROR(c, msg) \ + TRACE(c, "PKINIT OpenSSL error: {str}", msg) +diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py +index 62e6c426d3..f8f2debc1b 100755 +--- a/src/tests/t_pkinit.py ++++ b/src/tests/t_pkinit.py +@@ -172,6 +172,15 @@ realm.pkinit(realm.user_princ, expected_trace=msgs) + realm.klist(realm.user_princ) + realm.run([kvno, realm.host_princ]) + ++# Test each Diffie-Hellman group except 1024-bit (which doesn't work ++# in OpenSSL 3.0) and the default 2048-bit group. ++for g in ('4096', 'P-256', 'P-384', 'P-521'): ++ mark('Diffie-Hellman group ' + g) ++ group_conf = {'realms': {'$realm': {'pkinit_dh_min_bits': g}}} ++ group_env = realm.special_env(g, True, krb5_conf=group_conf) ++ realm.pkinit(realm.user_princ, expected_trace=('PKINIT using ' + g,), ++ env=group_env) ++ + # Try using multiple configured pkinit_identities, to make sure we + # fall back to the second one when the first one cannot be read. + id_conf = {'realms': {'$realm': {'pkinit_identities': [file_identity + 'X', +@@ -190,11 +199,14 @@ realm.start_kdc(env=minbits_env) + msgs = ('Sending unauthenticated request', + '/Additional pre-authentication required', + 'Preauthenticating using KDC method data', ++ 'PKINIT using 2048-bit DH key exchange group', + 'Preauth module pkinit (16) (real) returned: 0/Success', + ' preauth for next request: PA-FX-COOKIE (133), PA-PK-AS-REQ (16)', + '/Key parameters not accepted', + 'Preauth tryagain input types (16): 109, PA-FX-COOKIE (133)', ++ 'PKINIT accepting KDC key exchange group preference P-384', + 'trying again with KDC-provided parameters', ++ 'PKINIT using P-384 key exchange group', + 'Preauth module pkinit (16) tryagain returned: 0/Success', + ' preauth for next request: PA-PK-AS-REQ (16), PA-FX-COOKIE (133)') + realm.pkinit(realm.user_princ, expected_trace=msgs) +-- +2.47.1 + diff --git a/0027-Add-ecdsa-with-sha512-256-to-supportedCMSTypes.patch b/0027-Add-ecdsa-with-sha512-256-to-supportedCMSTypes.patch new file mode 100644 index 0000000..140a2e5 --- /dev/null +++ b/0027-Add-ecdsa-with-sha512-256-to-supportedCMSTypes.patch @@ -0,0 +1,78 @@ +From 43d10f1580c033fe706470e7588c720ac7854918 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Wed, 21 Jun 2023 18:27:11 +0200 +Subject: [PATCH] Add ecdsa-with-sha512/256 to supportedCMSTypes + +Elliptic curve certificates are already supported for PKINIT +pre-authentication, but their associated signature types aren't +advertized. Add ecdsa-with-sha512 and ecdsa-with-sha256 OIDs to the +supportedCMSTypes list sent by the client. + +[ghudson@mit.edu: edited commit message] + +ticket: 9100 (new) +(cherry picked from commit 9913e5c92c4e5cb76d6ae58386f744766d2e6454) +--- + src/plugins/preauth/pkinit/pkinit_constants.c | 38 +++++++++++++++++++ + 1 file changed, 38 insertions(+) + +diff --git a/src/plugins/preauth/pkinit/pkinit_constants.c b/src/plugins/preauth/pkinit/pkinit_constants.c +index 10f8688ec2..905e90d29c 100644 +--- a/src/plugins/preauth/pkinit/pkinit_constants.c ++++ b/src/plugins/preauth/pkinit/pkinit_constants.c +@@ -64,14 +64,52 @@ static char sha512WithRSAEncr_oid[9] = { + 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0d + }; + ++/* RFC 3279 ecdsa-with-SHA1: iso(1) member-body(2) us(840) ansi-X9-62(10045) ++ * signatures(4) 1 */ ++static char ecdsaWithSha1_oid[] = { ++ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x01 ++}; ++ ++/* RFC 5758 ecdsa-with-SHA256: iso(1) member-body(2) us(840) ansi-X9-62(10045) ++ * signatures(4) ecdsa-with-SHA2(3) 2 */ ++static char ecdsaWithSha256_oid[] = { ++ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x03, 0x02 ++}; ++ ++/* RFC 5758 ecdsa-with-SHA384: iso(1) member-body(2) us(840) ansi-X9-62(10045) ++ * signatures(4) ecdsa-with-SHA2(3) 3 */ ++static char ecdsaWithSha384_oid[] = { ++ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x03, 0x03 ++}; ++ ++/* RFC 5758 ecdsa-with-SHA512: iso(1) member-body(2) us(840) ansi-X9-62(10045) ++ * signatures(4) ecdsa-with-SHA2(3) 4 */ ++static char ecdsaWithSha512_oid[] = { ++ 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x03, 0x04 ++}; ++ + const krb5_data sha256WithRSAEncr_id = { + KV5M_DATA, sizeof(sha256WithRSAEncr_oid), sha256WithRSAEncr_oid + }; + const krb5_data sha512WithRSAEncr_id = { + KV5M_DATA, sizeof(sha512WithRSAEncr_oid), sha512WithRSAEncr_oid + }; ++const krb5_data ecdsaWithSha1_id = { ++ KV5M_DATA, sizeof(ecdsaWithSha1_oid), ecdsaWithSha1_oid ++}; ++const krb5_data ecdsaWithSha256_id = { ++ KV5M_DATA, sizeof(ecdsaWithSha256_oid), ecdsaWithSha256_oid ++}; ++const krb5_data ecdsaWithSha384_id = { ++ KV5M_DATA, sizeof(ecdsaWithSha384_oid), ecdsaWithSha384_oid ++}; ++const krb5_data ecdsaWithSha512_id = { ++ KV5M_DATA, sizeof(ecdsaWithSha512_oid), ecdsaWithSha512_oid ++}; + + krb5_data const * const supported_cms_algs[] = { ++ &ecdsaWithSha512_id, ++ &ecdsaWithSha256_id, + &sha512WithRSAEncr_id, + &sha256WithRSAEncr_id, + NULL +-- +2.47.1 + diff --git a/0028-Get-rid-of-pkinit_crypto_openssl.h.patch b/0028-Get-rid-of-pkinit_crypto_openssl.h.patch new file mode 100644 index 0000000..993e823 --- /dev/null +++ b/0028-Get-rid-of-pkinit_crypto_openssl.h.patch @@ -0,0 +1,264 @@ +From fba4cbf0bc50569b8ea6d1e1c3303eaab84935e1 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Sun, 30 Jul 2023 01:07:38 -0400 +Subject: [PATCH] Get rid of pkinit_crypto_openssl.h + +Fold pkinit_crypto_openssl.h into the one source file where it was +used. Also clean up the include of , as htonl() is no +longer used after commit 1c87ce6c44a9de0824580a2d72a8a202237e01f4. + +(cherry picked from commit b3352945fb8836f8b4095e0b8aad04b54aca3152) +--- + src/plugins/preauth/pkinit/deps | 2 +- + .../preauth/pkinit/pkinit_crypto_openssl.c | 85 +++++++++++- + .../preauth/pkinit/pkinit_crypto_openssl.h | 121 ------------------ + 3 files changed, 83 insertions(+), 125 deletions(-) + delete mode 100644 src/plugins/preauth/pkinit/pkinit_crypto_openssl.h + +diff --git a/src/plugins/preauth/pkinit/deps b/src/plugins/preauth/pkinit/deps +index 58320aa801..b6f4476fe8 100644 +--- a/src/plugins/preauth/pkinit/deps ++++ b/src/plugins/preauth/pkinit/deps +@@ -112,4 +112,4 @@ pkinit_crypto_openssl.so pkinit_crypto_openssl.po $(OUTPRE)pkinit_crypto_openssl + $(top_srcdir)/include/krb5/plugin.h $(top_srcdir)/include/krb5/preauth_plugin.h \ + $(top_srcdir)/include/port-sockets.h $(top_srcdir)/include/socket-utils.h \ + pkcs11.h pkinit.h pkinit_accessor.h pkinit_crypto.h \ +- pkinit_crypto_openssl.c pkinit_crypto_openssl.h pkinit_trace.h ++ pkinit_crypto_openssl.c pkinit_trace.h +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index f6d494bd11..ae8599d5a2 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -30,20 +30,99 @@ + */ + + #include "k5-int.h" +-#include "pkinit_crypto_openssl.h" + #include "k5-buf.h" + #include "k5-err.h" + #include "k5-hex.h" +-#include ++#include "pkinit.h" + #include +-#include + ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include + #if OPENSSL_VERSION_NUMBER >= 0x30000000L + #include + #include ++#include + #include + #endif + ++#define DN_BUF_LEN 256 ++#define MAX_CREDS_ALLOWED 20 ++ ++struct _pkinit_cred_info { ++ char *name; ++ X509 *cert; ++ EVP_PKEY *key; ++#ifndef WITHOUT_PKCS11 ++ CK_BYTE_PTR cert_id; ++ int cert_id_len; ++#endif ++}; ++typedef struct _pkinit_cred_info *pkinit_cred_info; ++ ++struct _pkinit_identity_crypto_context { ++ pkinit_cred_info creds[MAX_CREDS_ALLOWED+1]; ++ STACK_OF(X509) *my_certs; /* available user certs */ ++ char *identity; /* identity name for user cert */ ++ int cert_index; /* cert to use out of available certs*/ ++ EVP_PKEY *my_key; /* available user keys if in filesystem */ ++ STACK_OF(X509) *trustedCAs; /* available trusted ca certs */ ++ STACK_OF(X509) *intermediateCAs; /* available intermediate ca certs */ ++ STACK_OF(X509_CRL) *revoked; /* available crls */ ++ int pkcs11_method; ++ krb5_prompter_fct prompter; ++ void *prompter_data; ++#ifndef WITHOUT_PKCS11 ++ char *p11_module_name; ++ CK_SLOT_ID slotid; ++ char *token_label; ++ char *cert_label; ++ /* These are crypto-specific. */ ++ struct plugin_file_handle *p11_module; ++ CK_SESSION_HANDLE session; ++ CK_FUNCTION_LIST_PTR p11; ++ uint8_t *cert_id; ++ size_t cert_id_len; ++ CK_MECHANISM_TYPE mech; ++#endif ++ krb5_boolean defer_id_prompt; ++ pkinit_deferred_id *deferred_ids; ++}; ++ ++struct _pkinit_plg_crypto_context { ++ EVP_PKEY *dh_1024; ++ EVP_PKEY *dh_2048; ++ EVP_PKEY *dh_4096; ++ EVP_PKEY *ec_p256; ++ EVP_PKEY *ec_p384; ++ EVP_PKEY *ec_p521; ++ ASN1_OBJECT *id_pkinit_authData; ++ ASN1_OBJECT *id_pkinit_DHKeyData; ++ ASN1_OBJECT *id_pkinit_rkeyData; ++ ASN1_OBJECT *id_pkinit_san; ++ ASN1_OBJECT *id_ms_san_upn; ++ ASN1_OBJECT *id_pkinit_KPClientAuth; ++ ASN1_OBJECT *id_pkinit_KPKdc; ++ ASN1_OBJECT *id_ms_kp_sc_logon; ++ ASN1_OBJECT *id_kp_serverAuth; ++}; ++ ++struct _pkinit_req_crypto_context { ++ X509 *received_cert; ++ EVP_PKEY *client_pkey; ++}; ++ + static krb5_error_code pkinit_init_pkinit_oids(pkinit_plg_crypto_context ); + static void pkinit_fini_pkinit_oids(pkinit_plg_crypto_context ); + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h +deleted file mode 100644 +index b7a3358800..0000000000 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.h ++++ /dev/null +@@ -1,121 +0,0 @@ +-/* +- * COPYRIGHT (C) 2006,2007 +- * THE REGENTS OF THE UNIVERSITY OF MICHIGAN +- * ALL RIGHTS RESERVED +- * +- * Permission is granted to use, copy, create derivative works +- * and redistribute this software and such derivative works +- * for any purpose, so long as the name of The University of +- * Michigan is not used in any advertising or publicity +- * pertaining to the use of distribution of this software +- * without specific, written prior authorization. If the +- * above copyright notice or any other identification of the +- * University of Michigan is included in any copy of any +- * portion of this software, then the disclaimer below must +- * also be included. +- * +- * THIS SOFTWARE IS PROVIDED AS IS, WITHOUT REPRESENTATION +- * FROM THE UNIVERSITY OF MICHIGAN AS TO ITS FITNESS FOR ANY +- * PURPOSE, AND WITHOUT WARRANTY BY THE UNIVERSITY OF +- * MICHIGAN OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING +- * WITHOUT LIMITATION THE IMPLIED WARRANTIES OF +- * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE +- * REGENTS OF THE UNIVERSITY OF MICHIGAN SHALL NOT BE LIABLE +- * FOR ANY DAMAGES, INCLUDING SPECIAL, INDIRECT, INCIDENTAL, OR +- * CONSEQUENTIAL DAMAGES, WITH RESPECT TO ANY CLAIM ARISING +- * OUT OF OR IN CONNECTION WITH THE USE OF THE SOFTWARE, EVEN +- * IF IT HAS BEEN OR IS HEREAFTER ADVISED OF THE POSSIBILITY OF +- * SUCH DAMAGES. +- */ +- +-#ifndef _PKINIT_CRYPTO_OPENSSL_H +-#define _PKINIT_CRYPTO_OPENSSL_H +- +-#include "pkinit.h" +- +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#include +-#if OPENSSL_VERSION_NUMBER >= 0x30000000L +-#include +-#include +-#endif +- +-#define DN_BUF_LEN 256 +-#define MAX_CREDS_ALLOWED 20 +- +-struct _pkinit_cred_info { +- char *name; +- X509 *cert; +- EVP_PKEY *key; +-#ifndef WITHOUT_PKCS11 +- CK_BYTE_PTR cert_id; +- int cert_id_len; +-#endif +-}; +-typedef struct _pkinit_cred_info * pkinit_cred_info; +- +-struct _pkinit_identity_crypto_context { +- pkinit_cred_info creds[MAX_CREDS_ALLOWED+1]; +- STACK_OF(X509) *my_certs; /* available user certs */ +- char *identity; /* identity name for user cert */ +- int cert_index; /* cert to use out of available certs*/ +- EVP_PKEY *my_key; /* available user keys if in filesystem */ +- STACK_OF(X509) *trustedCAs; /* available trusted ca certs */ +- STACK_OF(X509) *intermediateCAs; /* available intermediate ca certs */ +- STACK_OF(X509_CRL) *revoked; /* available crls */ +- int pkcs11_method; +- krb5_prompter_fct prompter; +- void *prompter_data; +-#ifndef WITHOUT_PKCS11 +- char *p11_module_name; +- CK_SLOT_ID slotid; +- char *token_label; +- char *cert_label; +- /* These are crypto-specific */ +- struct plugin_file_handle *p11_module; +- CK_SESSION_HANDLE session; +- CK_FUNCTION_LIST_PTR p11; +- uint8_t *cert_id; +- size_t cert_id_len; +- CK_MECHANISM_TYPE mech; +-#endif +- krb5_boolean defer_id_prompt; +- pkinit_deferred_id *deferred_ids; +-}; +- +-struct _pkinit_plg_crypto_context { +- EVP_PKEY *dh_1024; +- EVP_PKEY *dh_2048; +- EVP_PKEY *dh_4096; +- EVP_PKEY *ec_p256; +- EVP_PKEY *ec_p384; +- EVP_PKEY *ec_p521; +- ASN1_OBJECT *id_pkinit_authData; +- ASN1_OBJECT *id_pkinit_DHKeyData; +- ASN1_OBJECT *id_pkinit_rkeyData; +- ASN1_OBJECT *id_pkinit_san; +- ASN1_OBJECT *id_ms_san_upn; +- ASN1_OBJECT *id_pkinit_KPClientAuth; +- ASN1_OBJECT *id_pkinit_KPKdc; +- ASN1_OBJECT *id_ms_kp_sc_logon; +- ASN1_OBJECT *id_kp_serverAuth; +-}; +- +-struct _pkinit_req_crypto_context { +- X509 *received_cert; +- EVP_PKEY *client_pkey; +-}; +- +-#endif /* _PKINIT_CRYPTO_OPENSSL_H */ +-- +2.47.1 + diff --git a/0029-Use-SoftHSMv2-for-PKCS11-PKINIT-tests.patch b/0029-Use-SoftHSMv2-for-PKCS11-PKINIT-tests.patch new file mode 100644 index 0000000..a328431 --- /dev/null +++ b/0029-Use-SoftHSMv2-for-PKCS11-PKINIT-tests.patch @@ -0,0 +1,157 @@ +From 1b01057df4c2223fbf92be44f1e764207208ef03 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Mon, 26 Feb 2024 19:03:38 -0500 +Subject: [PATCH] Use SoftHSMv2 for PKCS11 PKINIT tests + +Instead of softpkcs11, use SoftHSMv2 to mock the PKCS11 token for +PKINIT tests. Use pkcs11-tool from OpenSC to initialize the token and +import a certificate and key. SoftHSM does not support PIN-less +tokens (see https://github.com/opendnssec/SoftHSMv2/issues/480) so +remove that test for now. + +(cherry picked from commit 8ab61608236883fdc5c2d43f4bd1ff2094401d19) +--- + .github/workflows/build.yml | 2 +- + src/tests/t_pkinit.py | 82 ++++++++++++++++++++----------------- + 2 files changed, 45 insertions(+), 39 deletions(-) + +diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml +index 68a4788adb..d7ae86b150 100644 +--- a/.github/workflows/build.yml ++++ b/.github/workflows/build.yml +@@ -33,7 +33,7 @@ jobs: + if: startsWith(matrix.os, 'ubuntu') + run: | + sudo apt-get update -qq +- sudo apt-get install -y bison gettext keyutils ldap-utils libcmocka-dev libldap2-dev libkeyutils-dev libsasl2-dev libssl-dev python3-kdcproxy python3-pip slapd tcsh ++ sudo apt-get install -y bison gettext keyutils ldap-utils libcmocka-dev libldap2-dev libkeyutils-dev libsasl2-dev libssl-dev python3-kdcproxy python3-pip slapd tcsh softhsm2 opensc + pip3 install pyrad + - name: Build + env: +diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py +index f8f2debc1b..4435746429 100755 +--- a/src/tests/t_pkinit.py ++++ b/src/tests/t_pkinit.py +@@ -1,11 +1,10 @@ + from k5test import * ++import re + + # Skip this test if pkinit wasn't built. + if not pkinit_enabled: + skip_rest('PKINIT tests', 'PKINIT module not built') + +-soft_pkcs11 = os.path.join(buildtop, 'tests', 'softpkcs11', 'softpkcs11.so') +- + # Construct a krb5.conf fragment configuring pkinit. + user_pem = os.path.join(pkinit_certs, 'user.pem') + privkey_pem = os.path.join(pkinit_certs, 'privkey.pem') +@@ -55,9 +54,6 @@ p12_upn2_identity = 'PKCS12:%s' % user_upn2_p12 + p12_upn3_identity = 'PKCS12:%s' % user_upn3_p12 + p12_generic_identity = 'PKCS12:%s' % generic_p12 + p12_enc_identity = 'PKCS12:%s' % user_enc_p12 +-p11_identity = 'PKCS11:' + soft_pkcs11 +-p11_token_identity = ('PKCS11:module_name=' + soft_pkcs11 + +- ':slotid=1:token=SoftToken (token)') + + # Start a realm with the test kdb module for the following UPN SAN tests. + realm = K5Realm(kdc_conf=alias_kdc_conf, create_kdb=False, pkinit=True) +@@ -389,53 +385,63 @@ realm.klist(realm.user_princ) + realm.kinit(realm.user_princ, flags=['-X', 'X509_user_identity=,'], + expected_code=1, expected_msg='Preauthentication failed while') + +-softpkcs11rc = os.path.join(os.getcwd(), 'testdir', 'soft-pkcs11.rc') +-realm.env['SOFTPKCS11RC'] = softpkcs11rc ++softhsm2 = '/usr/lib/softhsm/libsofthsm2.so' ++if not os.path.exists(softhsm2): ++ skip_rest('PKCS11 tests', 'SoftHSMv2 required') ++pkcs11_tool = which('pkcs11-tool') ++if not pkcs11_tool: ++ skip_rest('PKCS11 tests', 'pkcs11-tool from OpenSC required') ++tool_cmd = [pkcs11_tool, '--module', softhsm2] ++ ++# Prepare a SoftHSM token. ++softhsm2_conf = os.path.join(realm.testdir, 'softhsm2.conf') ++softhsm2_tokens = os.path.join(realm.testdir, 'tokens') ++os.mkdir(softhsm2_tokens) ++realm.env['SOFTHSM2_CONF'] = softhsm2_conf ++with open(softhsm2_conf, 'w') as f: ++ f.write('directories.tokendir = %s\n' % softhsm2_tokens) ++realm.run(tool_cmd + ['--init-token', '--label', 'user', ++ '--so-pin', 'sopin', '--init-pin', '--pin', 'userpin']) ++realm.run(tool_cmd + ['-w', user_pem, '-y', 'cert']) ++realm.run(tool_cmd + ['-w', privkey_pem, '-y', 'privkey', ++ '-l', '--pin', 'userpin']) ++ ++# Extract the slot ID generated by SoftHSM. ++out = realm.run(tool_cmd + ['-L']) ++m = re.search(r'slot ID 0x([0-9a-f]+)\n', out) ++if not m: ++ fail('could not extract slot ID from SoftHSM token') ++slot_id = int(m.group(1), 16) ++ ++p11_attr = 'X509_user_identity=PKCS11:' + softhsm2 ++p11_token_identity = ('PKCS11:module_name=%s:slotid=%d:token=user' % ++ (softhsm2, slot_id)) + +-# PKINIT with PKCS11: identity, with no need for a PIN. +-mark('PKCS11 identity, no PIN') +-conf = open(softpkcs11rc, 'w') +-conf.write("%s\t%s\t%s\t%s\n" % ('user', 'user token', user_pem, privkey_pem)) +-conf.close() +-# Expect to succeed without having to supply any more information. +-realm.kinit(realm.user_princ, +- flags=['-X', 'X509_user_identity=%s' % p11_identity]) ++mark('PKCS11 identity, with PIN (prompter)') ++realm.kinit(realm.user_princ, flags=['-X', p11_attr], password='userpin') + realm.klist(realm.user_princ) + realm.run([kvno, realm.host_princ]) + +-# PKINIT with PKCS11: identity, with a PIN supplied by the prompter. +-mark('PKCS11 identity, with PIN (prompter)') +-os.remove(softpkcs11rc) +-conf = open(softpkcs11rc, 'w') +-conf.write("%s\t%s\t%s\t%s\n" % ('user', 'user token', user_pem, +- privkey_enc_pem)) +-conf.close() +-# Expect failure if the responder does nothing, and there's no prompter ++mark('PKCS11 identity, unavailable PIN') + realm.run(['./responder', '-x', 'pkinit={"%s": 0}' % p11_token_identity, +- '-X', 'X509_user_identity=%s' % p11_identity, realm.user_princ], +- expected_code=2) +-realm.kinit(realm.user_princ, +- flags=['-X', 'X509_user_identity=%s' % p11_identity], +- password='encrypted') +-realm.klist(realm.user_princ) +-realm.run([kvno, realm.host_princ]) ++ '-X', p11_attr, realm.user_princ], expected_code=2) + +-# Supply the wrong PIN. + mark('PKCS11 identity, wrong PIN') + expected_trace = ('PKINIT client has no configured identity; giving up',) + realm.kinit(realm.user_princ, +- flags=['-X', 'X509_user_identity=%s' % p11_identity], ++ flags=['-X', p11_attr], + password='wrong', expected_code=1, expected_trace=expected_trace) + + # PKINIT with PKCS11: identity, with a PIN supplied by the responder. +-# Supply the response in raw form. ++# Supply the response in raw form. Expect the PIN_COUNT_LOW flag (1) ++# to be set due to the previous test. + mark('PKCS11 identity, with PIN (responder)') +-realm.run(['./responder', '-x', 'pkinit={"%s": 0}' % p11_token_identity, +- '-r', 'pkinit={"%s": "encrypted"}' % p11_token_identity, +- '-X', 'X509_user_identity=%s' % p11_identity, realm.user_princ]) ++realm.run(['./responder', '-x', 'pkinit={"%s": 1}' % p11_token_identity, ++ '-r', 'pkinit={"%s": "userpin"}' % p11_token_identity, ++ '-X', p11_attr, realm.user_princ]) + # Supply the response through the convenience API. +-realm.run(['./responder', '-X', 'X509_user_identity=%s' % p11_identity, +- '-p', '%s=%s' % (p11_token_identity, 'encrypted'), ++realm.run(['./responder', '-X', p11_attr, ++ '-p', '%s=%s' % (p11_token_identity, 'userpin'), + realm.user_princ]) + realm.klist(realm.user_princ) + realm.run([kvno, realm.host_princ]) +-- +2.47.1 + diff --git a/0030-Simplify-PKINIT-cert-representation.patch b/0030-Simplify-PKINIT-cert-representation.patch new file mode 100644 index 0000000..1bd8d64 --- /dev/null +++ b/0030-Simplify-PKINIT-cert-representation.patch @@ -0,0 +1,202 @@ +From b0315d30f066c4241fcecc33dd9e4d1c7c28b9d8 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 9 Feb 2024 17:32:40 -0500 +Subject: [PATCH] Simplify PKINIT cert representation + +In the _pkinit_identity_crypto_context structure, the my_certs field +is a stack which only ever contains one cert and is only ever used to +retrieve that one cert. The cert_index field is always 0. Replace +these fields with a my_cert field pointing directly to the X509 +certificate. + +Simplify crypto_cert_select_default() by making it call +crypto_cert_select() with index 0 after verifying the certificate +count. + +(cherry picked from commit f95dfb7908456f9563cee66706216a21df8d791f) +--- + .../preauth/pkinit/pkinit_crypto_openssl.c | 74 +++++-------------- + 1 file changed, 20 insertions(+), 54 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index ae8599d5a2..da59cb1e02 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -73,10 +73,9 @@ typedef struct _pkinit_cred_info *pkinit_cred_info; + + struct _pkinit_identity_crypto_context { + pkinit_cred_info creds[MAX_CREDS_ALLOWED+1]; +- STACK_OF(X509) *my_certs; /* available user certs */ ++ X509 *my_cert; /* selected user or KDC cert */ + char *identity; /* identity name for user cert */ +- int cert_index; /* cert to use out of available certs*/ +- EVP_PKEY *my_key; /* available user keys if in filesystem */ ++ EVP_PKEY *my_key; /* selected cert key if in filesystem */ + STACK_OF(X509) *trustedCAs; /* available trusted ca certs */ + STACK_OF(X509) *intermediateCAs; /* available intermediate ca certs */ + STACK_OF(X509_CRL) *revoked; /* available crls */ +@@ -1489,8 +1488,7 @@ pkinit_init_certs(pkinit_identity_crypto_context ctx) + + for (i = 0; i < MAX_CREDS_ALLOWED; i++) + ctx->creds[i] = NULL; +- ctx->my_certs = NULL; +- ctx->cert_index = 0; ++ ctx->my_cert = NULL; + ctx->my_key = NULL; + ctx->trustedCAs = NULL; + ctx->intermediateCAs = NULL; +@@ -1506,8 +1504,8 @@ pkinit_fini_certs(pkinit_identity_crypto_context ctx) + if (ctx == NULL) + return; + +- if (ctx->my_certs != NULL) +- sk_X509_pop_free(ctx->my_certs, X509_free); ++ if (ctx->my_cert != NULL) ++ X509_free(ctx->my_cert); + + if (ctx->my_key != NULL) + EVP_PKEY_free(ctx->my_key); +@@ -1696,7 +1694,6 @@ cms_signeddata_create(krb5_context context, + ASN1_OCTET_STRING *digest = NULL; + unsigned int alg_len = 0, digest_len = 0; + unsigned char *y = NULL; +- X509 *cert = NULL; + ASN1_OBJECT *oid = NULL, *oid_copy; + + /* Start creating PKCS7 data. */ +@@ -1715,7 +1712,7 @@ cms_signeddata_create(krb5_context context, + if (oid == NULL) + goto cleanup; + +- if (id_cryptoctx->my_certs != NULL) { ++ if (id_cryptoctx->my_cert != NULL) { + X509_STORE *certstore = NULL; + X509_STORE_CTX *certctx; + STACK_OF(X509) *certstack = NULL; +@@ -1726,8 +1723,6 @@ cms_signeddata_create(krb5_context context, + if ((cert_stack = sk_X509_new_null()) == NULL) + goto cleanup; + +- cert = sk_X509_value(id_cryptoctx->my_certs, id_cryptoctx->cert_index); +- + certstore = X509_STORE_new(); + if (certstore == NULL) + goto cleanup; +@@ -1736,7 +1731,7 @@ cms_signeddata_create(krb5_context context, + certctx = X509_STORE_CTX_new(); + if (certctx == NULL) + goto cleanup; +- X509_STORE_CTX_init(certctx, certstore, cert, ++ X509_STORE_CTX_init(certctx, certstore, id_cryptoctx->my_cert, + id_cryptoctx->intermediateCAs); + X509_STORE_CTX_trusted_stack(certctx, id_cryptoctx->trustedCAs); + if (!X509_verify_cert(certctx)) { +@@ -1764,13 +1759,13 @@ cms_signeddata_create(krb5_context context, + if (!ASN1_INTEGER_set(p7si->version, 1)) + goto cleanup; + if (!X509_NAME_set(&p7si->issuer_and_serial->issuer, +- X509_get_issuer_name(cert))) ++ X509_get_issuer_name(id_cryptoctx->my_cert))) + goto cleanup; + /* because ASN1_INTEGER_set is used to set a 'long' we will do + * things the ugly way. */ + ASN1_INTEGER_free(p7si->issuer_and_serial->serial); + if (!(p7si->issuer_and_serial->serial = +- ASN1_INTEGER_dup(X509_get_serialNumber(cert)))) ++ ASN1_INTEGER_dup(X509_get_serialNumber(id_cryptoctx->my_cert)))) + goto cleanup; + + /* will not fill-out EVP_PKEY because it's on the smartcard */ +@@ -3311,7 +3306,7 @@ pkinit_check_kdc_pkid(krb5_context context, + PKCS7_ISSUER_AND_SERIAL *is = NULL; + const unsigned char *p = pdid_buf; + int status = 1; +- X509 *kdc_cert = sk_X509_value(id_cryptoctx->my_certs, id_cryptoctx->cert_index); ++ X509 *kdc_cert = id_cryptoctx->my_cert; + + *valid_kdcPkId = 0; + pkiDebug("found kdcPkId in AS REQ\n"); +@@ -4783,7 +4778,8 @@ cleanup: + } + + /* +- * Set the certificate in idctx->creds[cred_index] as the selected certificate. ++ * Set the certificate in idctx->creds[cred_index] as the selected certificate, ++ * stealing pointers from it. + */ + krb5_error_code + crypto_cert_select(krb5_context context, pkinit_identity_crypto_context idctx, +@@ -4795,20 +4791,17 @@ crypto_cert_select(krb5_context context, pkinit_identity_crypto_context idctx, + return ENOENT; + + ci = idctx->creds[cred_index]; +- /* copy the selected cert into our id_cryptoctx */ +- if (idctx->my_certs != NULL) +- sk_X509_pop_free(idctx->my_certs, X509_free); +- idctx->my_certs = sk_X509_new_null(); +- sk_X509_push(idctx->my_certs, ci->cert); +- free(idctx->identity); ++ ++ idctx->my_cert = ci->cert; ++ ci->cert = NULL; ++ + /* hang on to the selected credential name */ ++ free(idctx->identity); + if (ci->name != NULL) + idctx->identity = strdup(ci->name); + else + idctx->identity = NULL; + +- ci->cert = NULL; /* Don't free it twice */ +- idctx->cert_index = 0; + if (idctx->pkcs11_method != 1) { + idctx->my_key = ci->key; + ci->key = NULL; /* Don't free it twice */ +@@ -4837,41 +4830,14 @@ crypto_cert_select_default(krb5_context context, + + retval = crypto_cert_get_count(id_cryptoctx, &cert_count); + if (retval) +- goto errout; ++ return retval; + + if (cert_count != 1) { + TRACE_PKINIT_NO_DEFAULT_CERT(context, cert_count); +- retval = EINVAL; +- goto errout; +- } +- /* copy the selected cert into our id_cryptoctx */ +- if (id_cryptoctx->my_certs != NULL) { +- sk_X509_pop_free(id_cryptoctx->my_certs, X509_free); ++ return EINVAL; + } +- id_cryptoctx->my_certs = sk_X509_new_null(); +- sk_X509_push(id_cryptoctx->my_certs, id_cryptoctx->creds[0]->cert); +- id_cryptoctx->creds[0]->cert = NULL; /* Don't free it twice */ +- id_cryptoctx->cert_index = 0; +- /* hang on to the selected credential name */ +- if (id_cryptoctx->creds[0]->name != NULL) +- id_cryptoctx->identity = strdup(id_cryptoctx->creds[0]->name); +- else +- id_cryptoctx->identity = NULL; + +- if (id_cryptoctx->pkcs11_method != 1) { +- id_cryptoctx->my_key = id_cryptoctx->creds[0]->key; +- id_cryptoctx->creds[0]->key = NULL; /* Don't free it twice */ +- } +-#ifndef WITHOUT_PKCS11 +- else { +- id_cryptoctx->cert_id = id_cryptoctx->creds[0]->cert_id; +- id_cryptoctx->creds[0]->cert_id = NULL; /* Don't free it twice */ +- id_cryptoctx->cert_id_len = id_cryptoctx->creds[0]->cert_id_len; +- } +-#endif +- retval = 0; +-errout: +- return retval; ++ return crypto_cert_select(context, id_cryptoctx, 0); + } + + +-- +2.47.1 + diff --git a/0031-Support-PKCS11-EC-client-certs-in-PKINIT.patch b/0031-Support-PKCS11-EC-client-certs-in-PKINIT.patch new file mode 100644 index 0000000..920a6a8 --- /dev/null +++ b/0031-Support-PKCS11-EC-client-certs-in-PKINIT.patch @@ -0,0 +1,1768 @@ +From e7172ce0283b06f5208237535a086424d71d846b Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Wed, 21 Feb 2024 15:29:02 -0500 +Subject: [PATCH] Support PKCS11 EC client certs in PKINIT + +Move the digest computation and DigestInfo encoding from +cms_signeddata_create() to pkinit_sign_data_pkcs11(), and +conditionalize the DigestInfo encoding on the key type. Use CKM_ECDSA +instead of CKM_RSA_PKCS for EC keys, and convert the resulting +signature from the PKS11 encoding to the ASN.1 encoding required by +CMS. + +Regenerate the test certificates with an additional EC client cert. +Add test cases for EC client certs with and without PKCS11. + +ticket: 9112 (new) +(cherry picked from commit f745c9a9bd6c0c73b944182173f1ac305d03dc3a) +--- + .../preauth/pkinit/pkinit_crypto_openssl.c | 319 +++++++++++------- + src/tests/pkinit-certs/ca.pem | 32 +- + src/tests/pkinit-certs/eckey.pem | 5 + + src/tests/pkinit-certs/ecuser.pem | 24 ++ + src/tests/pkinit-certs/generic.p12 | Bin 2469 -> 2560 bytes + src/tests/pkinit-certs/generic.pem | 38 +-- + src/tests/pkinit-certs/kdc.pem | 32 +- + src/tests/pkinit-certs/make-certs.sh | 11 +- + src/tests/pkinit-certs/privkey-enc.pem | 60 ++-- + src/tests/pkinit-certs/privkey.pem | 55 +-- + src/tests/pkinit-certs/user-enc.p12 | Bin 2829 -> 2920 bytes + src/tests/pkinit-certs/user-upn.p12 | Bin 2821 -> 2912 bytes + src/tests/pkinit-certs/user-upn.pem | 32 +- + src/tests/pkinit-certs/user-upn2.p12 | Bin 2805 -> 2896 bytes + src/tests/pkinit-certs/user-upn2.pem | 34 +- + src/tests/pkinit-certs/user-upn3.p12 | Bin 2821 -> 2912 bytes + src/tests/pkinit-certs/user-upn3.pem | 32 +- + src/tests/pkinit-certs/user.p12 | Bin 2829 -> 2920 bytes + src/tests/pkinit-certs/user.pem | 30 +- + src/tests/t_pkinit.py | 20 ++ + 20 files changed, 437 insertions(+), 287 deletions(-) + create mode 100644 src/tests/pkinit-certs/eckey.pem + create mode 100644 src/tests/pkinit-certs/ecuser.pem + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index da59cb1e02..4accfc2664 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -93,7 +93,6 @@ struct _pkinit_identity_crypto_context { + CK_FUNCTION_LIST_PTR p11; + uint8_t *cert_id; + size_t cert_id_len; +- CK_MECHANISM_TYPE mech; + #endif + krb5_boolean defer_id_prompt; + pkinit_deferred_id *deferred_ids; +@@ -283,7 +282,6 @@ compat_get0_EC(const EVP_PKEY *pkey) + #if OPENSSL_VERSION_NUMBER < 0x30000000L + /* OpenSSL 3.0 changes several preferred function names. */ + #define EVP_PKEY_parameters_eq EVP_PKEY_cmp_parameters +-#define EVP_MD_CTX_get0_md EVP_MD_CTX_md + #define EVP_PKEY_get_size EVP_PKEY_size + #define EVP_PKEY_get_bits EVP_PKEY_bits + +@@ -1683,17 +1681,12 @@ cms_signeddata_create(krb5_context context, + STACK_OF(X509) * cert_stack = NULL; + ASN1_OCTET_STRING *digest_attr = NULL; + EVP_MD_CTX *ctx; +- const EVP_MD *md_tmp = NULL; +- unsigned char md_data[EVP_MAX_MD_SIZE], md_data2[EVP_MAX_MD_SIZE]; +- unsigned char *digestInfo_buf = NULL, *abuf = NULL; +- unsigned int md_len, md_len2, alen, digestInfo_len; ++ unsigned char md_data[EVP_MAX_MD_SIZE], *abuf = NULL; ++ unsigned int md_len, alen; + STACK_OF(X509_ATTRIBUTE) * sk; + unsigned char *sig = NULL; + unsigned int sig_len = 0; + X509_ALGOR *alg = NULL; +- ASN1_OCTET_STRING *digest = NULL; +- unsigned int alg_len = 0, digest_len = 0; +- unsigned char *y = NULL; + ASN1_OBJECT *oid = NULL, *oid_copy; + + /* Start creating PKCS7 data. */ +@@ -1795,7 +1788,6 @@ cms_signeddata_create(krb5_context context, + goto cleanup; + EVP_DigestInit_ex(ctx, EVP_sha256(), NULL); + EVP_DigestUpdate(ctx, data, data_len); +- md_tmp = EVP_MD_CTX_get0_md(ctx); + EVP_DigestFinal_ex(ctx, md_data, &md_len); + EVP_MD_CTX_free(ctx); + +@@ -1820,63 +1812,8 @@ cms_signeddata_create(krb5_context context, + if (abuf == NULL) + goto cleanup2; + +-#ifndef WITHOUT_PKCS11 +- /* +- * Some tokens can only do RSAEncryption without a hash. To compute +- * sha256WithRSAEncryption, encode the algorithm ID for the hash +- * function and the hash value into an ASN.1 value of type DigestInfo: +- * DigestInfo ::= SEQUENCE { +- * digestAlgorithm AlgorithmIdentifier, +- * digest OCTET STRING +- * } +- */ +- if (id_cryptoctx->pkcs11_method == 1 && +- id_cryptoctx->mech == CKM_RSA_PKCS) { +- pkiDebug("mech = CKM_RSA_PKCS\n"); +- ctx = EVP_MD_CTX_new(); +- if (ctx == NULL) +- goto cleanup; +- EVP_DigestInit_ex(ctx, md_tmp, NULL); +- EVP_DigestUpdate(ctx, abuf, alen); +- EVP_DigestFinal_ex(ctx, md_data2, &md_len2); +- EVP_MD_CTX_free(ctx); +- +- alg = X509_ALGOR_new(); +- if (alg == NULL) +- goto cleanup2; +- X509_ALGOR_set0(alg, OBJ_nid2obj(NID_sha256), V_ASN1_NULL, NULL); +- alg_len = i2d_X509_ALGOR(alg, NULL); +- +- digest = ASN1_OCTET_STRING_new(); +- if (digest == NULL) +- goto cleanup2; +- ASN1_OCTET_STRING_set(digest, md_data2, (int)md_len2); +- digest_len = i2d_ASN1_OCTET_STRING(digest, NULL); +- +- digestInfo_len = ASN1_object_size(1, (int)(alg_len + digest_len), +- V_ASN1_SEQUENCE); +- y = digestInfo_buf = malloc(digestInfo_len); +- if (digestInfo_buf == NULL) +- goto cleanup2; +- ASN1_put_object(&y, 1, (int)(alg_len + digest_len), V_ASN1_SEQUENCE, +- V_ASN1_UNIVERSAL); +- i2d_X509_ALGOR(alg, &y); +- i2d_ASN1_OCTET_STRING(digest, &y); +-#ifdef DEBUG_SIG +- pkiDebug("signing buffer\n"); +- print_buffer(digestInfo_buf, digestInfo_len); +- print_buffer_bin(digestInfo_buf, digestInfo_len, "/tmp/pkcs7_tosign"); +-#endif +- retval = pkinit_sign_data(context, id_cryptoctx, digestInfo_buf, +- digestInfo_len, &sig, &sig_len); +- } else +-#endif +- { +- pkiDebug("mech = %s\n", +- id_cryptoctx->pkcs11_method == 1 ? "CKM_SHA256_RSA_PKCS" : "FS"); +- retval = pkinit_sign_data(context, id_cryptoctx, abuf, alen, +- &sig, &sig_len); +- } ++ retval = pkinit_sign_data(context, id_cryptoctx, abuf, alen, ++ &sig, &sig_len); + #ifdef DEBUG_SIG + print_buffer(sig, sig_len); + #endif +@@ -1930,14 +1867,6 @@ cms_signeddata_create(krb5_context context, + + cleanup2: + if (p7si) { +-#ifndef WITHOUT_PKCS11 +- if (id_cryptoctx->pkcs11_method == 1 && +- id_cryptoctx->mech == CKM_RSA_PKCS) { +- free(digestInfo_buf); +- if (digest != NULL) +- ASN1_OCTET_STRING_free(digest); +- } +-#endif + if (alg != NULL) + X509_ALGOR_free(alg); + } +@@ -3657,8 +3586,7 @@ cleanup: + * Look for a key that's: + * 1. private + * 2. capable of the specified operation (usually signing or decrypting) +- * 3. RSA (this may be wrong but it's all we can do for now) +- * 4. matches the id of the cert we chose ++ * 3. matches the id of the cert we chose + * + * You must call pkinit_get_certs before calling pkinit_find_private_key + * (that's because we need the ID of the private key) +@@ -3678,7 +3606,6 @@ pkinit_find_private_key(pkinit_identity_crypto_context id_cryptoctx, + CK_OBJECT_CLASS cls; + CK_ATTRIBUTE attrs[4]; + CK_ULONG count; +- CK_KEY_TYPE keytype; + unsigned int nattrs = 0; + int r; + #ifdef PKINIT_USE_KEY_USAGE +@@ -3705,12 +3632,6 @@ pkinit_find_private_key(pkinit_identity_crypto_context id_cryptoctx, + nattrs++; + #endif + +- keytype = CKK_RSA; +- attrs[nattrs].type = CKA_KEY_TYPE; +- attrs[nattrs].pValue = &keytype; +- attrs[nattrs].ulValueLen = sizeof keytype; +- nattrs++; +- + attrs[nattrs].type = CKA_ID; + attrs[nattrs].pValue = id_cryptoctx->cert_id; + attrs[nattrs].ulValueLen = id_cryptoctx->cert_id_len; +@@ -3749,6 +3670,116 @@ pkinit_sign_data_fs(krb5_context context, + } + + #ifndef WITHOUT_PKCS11 ++/* ++ * DER-encode a DigestInfo sequence containing the algorithm md and the digest ++ * mdbytes. ++ * ++ * DigestInfo ::= SEQUENCE { ++ * digestAlgorithm AlgorithmIdentifier, ++ * digest OCTET STRING ++ * } ++ */ ++static krb5_error_code ++encode_digestinfo(krb5_context context, const EVP_MD *md, ++ const uint8_t *mdbytes, size_t mdlen, ++ uint8_t **encoding_out, size_t *len_out) ++{ ++ krb5_boolean ok = FALSE; ++ X509_ALGOR *alg = NULL; ++ ASN1_OCTET_STRING *digest = NULL; ++ uint8_t *buf, *p; ++ int alg_len, digest_len, len; ++ ++ *encoding_out = NULL; ++ *len_out = 0; ++ ++ alg = X509_ALGOR_new(); ++ if (alg == NULL || ++ !X509_ALGOR_set0(alg, OBJ_nid2obj(EVP_MD_nid(md)), V_ASN1_NULL, NULL)) ++ goto cleanup; ++ alg_len = i2d_X509_ALGOR(alg, NULL); ++ if (alg_len < 0) ++ goto cleanup; ++ ++ digest = ASN1_OCTET_STRING_new(); ++ if (digest == NULL || !ASN1_OCTET_STRING_set(digest, mdbytes, mdlen)) ++ goto cleanup; ++ digest_len = i2d_ASN1_OCTET_STRING(digest, NULL); ++ if (digest_len < 0) ++ goto cleanup; ++ ++ len = ASN1_object_size(1, alg_len + digest_len, V_ASN1_SEQUENCE); ++ p = buf = malloc(len); ++ if (buf == NULL) ++ goto cleanup; ++ ASN1_put_object(&p, 1, alg_len + digest_len, V_ASN1_SEQUENCE, ++ V_ASN1_UNIVERSAL); ++ i2d_X509_ALGOR(alg, &p); ++ i2d_ASN1_OCTET_STRING(digest, &p); ++ ++ *encoding_out = buf; ++ *len_out = len; ++ ok = TRUE; ++ ++cleanup: ++ X509_ALGOR_free(alg); ++ ASN1_OCTET_STRING_free(digest); ++ if (!ok) ++ return oerr(context, 0, _("Failed to DER encode DigestInfo")); ++ return 0; ++} ++ ++/* Extract the r and s values from a PKCS11 ECDSA signature and re-encode them ++ * in the DER representation of an ECDSA-Sig-Value for use in CMS. */ ++static krb5_error_code ++convert_pkcs11_ecdsa_sig(krb5_context context, ++ const uint8_t *p11sig, unsigned int p11siglen, ++ uint8_t **sig_out, unsigned int *sig_len_out) ++{ ++ krb5_boolean ok = FALSE; ++ BIGNUM *r = NULL, *s = NULL; ++ ECDSA_SIG *sig = NULL; ++ int len; ++ uint8_t *p; ++ ++ *sig_out = NULL; ++ *sig_len_out = 0; ++ ++ if (p11siglen % 2 != 0) ++ return EINVAL; ++ ++ /* Extract the r and s values from the PKCS11 signature. */ ++ r = BN_bin2bn(p11sig, p11siglen / 2, NULL); ++ s = BN_bin2bn(p11sig + p11siglen / 2, p11siglen / 2, NULL); ++ if (r == NULL || s == NULL) ++ goto cleanup; ++ ++ /* Create an ECDSA-Sig-Value object and transfer ownership of r and s. */ ++ sig = ECDSA_SIG_new(); ++ if (sig == NULL || !ECDSA_SIG_set0(sig, r, s)) ++ goto cleanup; ++ r = s = NULL; ++ ++ /* DER-encode the ECDSA-Sig-Value object. */ ++ len = i2d_ECDSA_SIG(sig, NULL); ++ if (len < 0) ++ goto cleanup; ++ p = *sig_out = malloc(len); ++ if (*sig_out == NULL) ++ goto cleanup; ++ *sig_len_out = len; ++ i2d_ECDSA_SIG(sig, &p); ++ ok = TRUE; ++ ++cleanup: ++ BN_free(r); ++ BN_free(s); ++ ECDSA_SIG_free(sig); ++ if (!ok) ++ return oerr(context, 0, _("Failed to convert PKCS11 ECDSA signature")); ++ return 0; ++} ++ + static krb5_error_code + pkinit_sign_data_pkcs11(krb5_context context, + pkinit_identity_crypto_context id_cryptoctx, +@@ -3757,27 +3788,88 @@ pkinit_sign_data_pkcs11(krb5_context context, + unsigned char **sig, + unsigned int *sig_len) + { ++ krb5_error_code ret; + CK_OBJECT_HANDLE obj; + CK_ULONG len; + CK_MECHANISM mech; +- unsigned char *cp; ++ CK_SESSION_HANDLE session; ++ CK_FUNCTION_LIST_PTR p11; ++ CK_ATTRIBUTE attr; ++ CK_KEY_TYPE keytype; ++ EVP_MD_CTX *ctx; ++ const EVP_MD *md = EVP_sha256(); ++ unsigned int mdlen; ++ uint8_t mdbuf[EVP_MAX_MD_SIZE], *dinfo = NULL, *sigbuf = NULL, *input; ++ size_t dinfo_len, input_len; + int r; + ++ *sig = NULL; ++ *sig_len = 0; ++ + if (pkinit_open_session(context, id_cryptoctx)) { + pkiDebug("can't open pkcs11 session\n"); + return KRB5KDC_ERR_PREAUTH_FAILED; + } ++ p11 = id_cryptoctx->p11; ++ session = id_cryptoctx->session; + +- pkinit_find_private_key(id_cryptoctx, CKA_SIGN, &obj); ++ ret = pkinit_find_private_key(id_cryptoctx, CKA_SIGN, &obj); ++ if (ret) ++ return ret; ++ ++ attr.type = CKA_KEY_TYPE; ++ attr.pValue = &keytype; ++ attr.ulValueLen = sizeof(keytype); ++ r = p11->C_GetAttributeValue(session, obj, &attr, 1); ++ if (r) { ++ pkiDebug("C_GetAttributeValue: %s\n", pkcs11err(r)); ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; ++ } ++ ++ /* ++ * We would ideally use CKM_SHA256_RSA_PKCS and CKM_ECDSA_SHA256, but ++ * historically many cards seem to be confused about whether they are ++ * capable of mechanisms or not. To be safe we compute the digest ++ * ourselves and use CKM_RSA_PKCS and CKM_ECDSA. ++ */ ++ ctx = EVP_MD_CTX_new(); ++ if (ctx == NULL) { ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; ++ } ++ EVP_DigestInit_ex(ctx, EVP_sha256(), NULL); ++ EVP_DigestUpdate(ctx, data, data_len); ++ EVP_DigestFinal_ex(ctx, mdbuf, &mdlen); ++ EVP_MD_CTX_free(ctx); + +- mech.mechanism = id_cryptoctx->mech; ++ if (keytype == CKK_RSA) { ++ /* For RSA we must also encode the digest in a DigestInfo sequence. */ ++ mech.mechanism = CKM_RSA_PKCS; ++ ret = encode_digestinfo(context, md, mdbuf, mdlen, &dinfo, &dinfo_len); ++ if (ret) ++ goto cleanup; ++ input = dinfo; ++ input_len = dinfo_len; ++ } else if (keytype == CKK_EC) { ++ mech.mechanism = CKM_ECDSA; ++ input = mdbuf; ++ input_len = mdlen; ++ } else { ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ k5_setmsg(context, ret, ++ _("PKCS11 certificate has unsupported key type %lu"), ++ keytype); ++ goto cleanup; ++ } + mech.pParameter = NULL; + mech.ulParameterLen = 0; + +- if ((r = id_cryptoctx->p11->C_SignInit(id_cryptoctx->session, &mech, +- obj)) != CKR_OK) { ++ r = p11->C_SignInit(session, &mech, obj); ++ if (r != CKR_OK) { + pkiDebug("C_SignInit: %s\n", pkcs11err(r)); +- return KRB5KDC_ERR_PREAUTH_FAILED; ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; + } + + /* +@@ -3785,28 +3877,38 @@ pkinit_sign_data_pkcs11(krb5_context context, + * get that. So guess, and if it's too small, re-malloc. + */ + len = PK_SIGLEN_GUESS; +- cp = malloc((size_t) len); +- if (cp == NULL) +- return ENOMEM; ++ sigbuf = k5alloc(len, &ret); ++ if (sigbuf == NULL) ++ goto cleanup; + +- r = id_cryptoctx->p11->C_Sign(id_cryptoctx->session, data, +- (CK_ULONG) data_len, cp, &len); ++ r = p11->C_Sign(session, input, input_len, sigbuf, &len); + if (r == CKR_BUFFER_TOO_SMALL || (r == CKR_OK && len >= PK_SIGLEN_GUESS)) { +- free(cp); ++ free(sigbuf); + pkiDebug("C_Sign realloc %d\n", (int) len); +- cp = malloc((size_t) len); +- r = id_cryptoctx->p11->C_Sign(id_cryptoctx->session, data, +- (CK_ULONG) data_len, cp, &len); ++ sigbuf = k5alloc(len, &ret); ++ if (sigbuf == NULL) ++ goto cleanup; ++ r = p11->C_Sign(session, input, input_len, sigbuf, &len); + } + if (r != CKR_OK) { + pkiDebug("C_Sign: %s\n", pkcs11err(r)); +- return KRB5KDC_ERR_PREAUTH_FAILED; ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; + } +- pkiDebug("sign %d -> %d\n", (int) data_len, (int) len); +- *sig_len = len; +- *sig = cp; + +- return 0; ++ if (keytype == CKK_EC) { ++ /* PKCS11 ECDSA signatures must be re-encoded for CMS. */ ++ ret = convert_pkcs11_ecdsa_sig(context, sigbuf, len, sig, sig_len); ++ } else { ++ *sig_len = len; ++ *sig = sigbuf; ++ sigbuf = NULL; ++ } ++ ++cleanup: ++ free(dinfo); ++ free(sigbuf); ++ return ret; + } + #endif + +@@ -4388,15 +4490,6 @@ pkinit_get_certs_pkcs11(krb5_context context, + return 0; + } + +- /* +- * We'd like to use CKM_SHA256_RSA_PKCS for signing if it's available, but +- * historically many cards seem to be confused about whether they are +- * capable of mechanisms or not. The safe thing seems to be to ignore the +- * mechanism list, always use CKM_RSA_PKCS and calculate the sha256 digest +- * ourselves. +- */ +- id_cryptoctx->mech = CKM_RSA_PKCS; +- + cls = CKO_CERTIFICATE; + attrs[0].type = CKA_CLASS; + attrs[0].pValue = &cls; +diff --git a/src/tests/pkinit-certs/ca.pem b/src/tests/pkinit-certs/ca.pem +index 63d31c1f5f..6c782bcde5 100644 +--- a/src/tests/pkinit-certs/ca.pem ++++ b/src/tests/pkinit-certs/ca.pem +@@ -3,27 +3,27 @@ MIIE5TCCA82gAwIBAgIBATANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx + FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG + A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz + dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug +-b3RoZXJ3aXNlMB4XDTIxMTAwODIxMTEzMFoXDTMyMDkyMDIxMTEzMFowgacxCzAJ ++b3RoZXJ3aXNlMB4XDTI0MDIxNTA0NTkwN1oXDTM1MDEyODA0NTkwN1owgacxCzAJ + BgNVBAYTAlVTMRYwFAYDVQQIDA1NYXNzYWNodXNldHRzMRIwEAYDVQQHDAlDYW1i + cmlkZ2UxDDAKBgNVBAoMA01JVDEpMCcGA1UECwwgSW5zZWN1cmUgUEtJTklUIEtl + cmJlcm9zIHRlc3QgQ0ExMzAxBgNVBAMMKnBraW5pdCB0ZXN0IHN1aXRlIENBOyBk + byBub3QgdXNlIG90aGVyd2lzZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC +-ggEBAM+lV5iaVats0yBFN4FBe6bovloNe3d0F9qMuhKqlECv6cFra75gSGmHJz6t +-GTK8zITU7sni429azTZC9IQnUt/2lW8dWzpZD1T5Vt1DYvYFqVzjhNfzeEDK88ig +-ENfzaX/cY2P76arJr0cewGaauzaux8heYW1CjBxWmk6kWq4aD+5jggchvBeOGEE2 +-NkV3MPbXut8fu+3NzuuIG7Z0ilwQv+KUvQ8QQb9VCwdsDh/ERsQ4loC9P4jtuWCJ +-ikIE78GxDcOMoC1ftJtW/mBCS2iCHipXrp2BDDJMyHxZjHpl0VoDR7koWGtD3sos +-EwUkXVvWIuKs432h2dXQ+u8HaBsCAwEAAaOCARgwggEUMB0GA1UdDgQWBBT0F6X7 +-1QRftDiSeNSY3bks3nK0IzCB1AYDVR0jBIHMMIHJgBT0F6X71QRftDiSeNSY3bks +-3nK0I6GBraSBqjCBpzELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0 ++ggEBAJv9Sbc2QSbHWnZjk55JfeOdPGUsmKOcT/N7C0/0mOQq4tUCmha7ntpBoIJd ++UBDhMQayG3QHruQX7aogtOx8hoLoLUaNKgxzEZ0OLbDRMc2M+vTDpBROITGI1KPv ++QtthlS4ocqKvqBCze66N9LufzAju61CyKdB3pCykPrgDVVScfsZ1t2zCbK0SF2cf ++ZAdIyCLoGLeQ95/NL3SIx0CX9gU47AVmBkSQ+LExJRhbUSIg+puKbqJ0XVILR1B2 ++ezgik2ObFND0hsRUS4v8pKnIDz0HXR2AneTESY+atjbzzelGA2zH86p4tLg0PanQ ++4x4+gpkQhzSr5Cmi3QX4XahSrmUCAwEAAaOCARgwggEUMB0GA1UdDgQWBBSSP/pz ++leX5zVcZ9hpI5GG2eQ+pqjCB1AYDVR0jBIHMMIHJgBSSP/pzleX5zVcZ9hpI5GG2 ++eQ+pqqGBraSBqjCBpzELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0 + dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoGA1UECgwDTUlUMSkwJwYDVQQLDCBJ + bnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVzdCBDQTEzMDEGA1UEAwwqcGtpbml0 + IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlggEBMAsGA1UdDwQE +-AwIB/jAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBT2FJVPS+U +-0MXa1HUOETuUPrVff7VeIvyAPm9IgX1zNbCvktCc4d7ErNB3P5ng8aZz4MKqwzuX +-HVhUxbF7JKfyUI41lcixPG+k+U9mzBJaozWT+K1OhdUF//mGPxaxe5jyUhDiQArD +-/6vulX0/B+1iuIa1sCfoeelzqQcYHqhZdWn6bBdcDWNARHIXWs5zPeKA975+d5TW +-rofE7T8nNQJvcZoVjCSfcYXhP82D/0sA+wPCt3fgbBZdvJ89xwvIlzBtiwC++Zbe +-37Rt5av0+ykpR7nmh2jyG+ItzE73nYKdBrUI5J6JLSbUcQTw4jeXHwDULUHZ6fXg +-TBEM2v1VW4Df ++AwIB/jAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAfx04Uqh0D ++myOR1PSqEEbMWJxZXYoESnjjH4Co4doceVBTuKix/2lplD4wcvA7aMXpmkvGfP38 ++dPrN1jvGd4bi/djTuxab9qB7rOeswAt+NyVHReUmuIMwgcW1UD7HXErg4EsOMjGD ++2XGhJYxGnwdURmnFwoO3yLLwo5K+C4rqPm3PbnI3W0sCA+IXepQTxuXK3dSplMMm ++0Pejw3es2s3oI9WaD2JRXvFuylw4UWYX+cyFRb+wN55Gh0rPVdxDhKCkbWNt/gTi ++/DbC+5pyQXkmy07OEGrmh4+5ae9hwejr9AukF2IZJB+oFP4i1mt9xyAOXImnWOzB ++SdHD08WHl5Gq + -----END CERTIFICATE----- +diff --git a/src/tests/pkinit-certs/eckey.pem b/src/tests/pkinit-certs/eckey.pem +new file mode 100644 +index 0000000000..14c2efd2ac +--- /dev/null ++++ b/src/tests/pkinit-certs/eckey.pem +@@ -0,0 +1,5 @@ ++-----BEGIN PRIVATE KEY----- ++MIGHAgEAMBMGByqGSM49AgEGCCqGSM49AwEHBG0wawIBAQQgSB3T7ihe3JUeIKZI ++PCDqATKN/dNugQsaC5AKiBPC6ymhRANCAAQy0E88e1CX16/2wL2T+nE0pmlb7wBM ++0hOh6m3m2uDbVsAIRJfhEjHWsT2ODCoBvGDV6vBeIOUjE/Ro9EwnYBW5 ++-----END PRIVATE KEY----- +diff --git a/src/tests/pkinit-certs/ecuser.pem b/src/tests/pkinit-certs/ecuser.pem +new file mode 100644 +index 0000000000..585e53d8c5 +--- /dev/null ++++ b/src/tests/pkinit-certs/ecuser.pem +@@ -0,0 +1,24 @@ ++-----BEGIN CERTIFICATE----- ++MIIECDCCAvCgAwIBAgIBBDANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx ++FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG ++A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz ++dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug ++b3RoZXJ3aXNlMB4XDTI0MDIxNTA0NTkwN1oXDTM1MDEyODA0NTkwN1owSjELMAkG ++A1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxFDASBgNVBAoMC0tSQlRF ++U1QuQ09NMQ0wCwYDVQQDDAR1c2VyMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE ++MtBPPHtQl9ev9sC9k/pxNKZpW+8ATNIToept5trg21bACESX4RIx1rE9jgwqAbxg ++1erwXiDlIxP0aPRMJ2AVuaOCAWQwggFgMB0GA1UdDgQWBBR5MaRx7ub5YBwsS0CF ++Li18nsl49zCB1AYDVR0jBIHMMIHJgBSSP/pzleX5zVcZ9hpI5GG2eQ+pqqGBraSB ++qjCBpzELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNV ++BAcMCUNhbWJyaWRnZTEMMAoGA1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQ ++S0lOSVQgS2VyYmVyb3MgdGVzdCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3Vp ++dGUgQ0E7IGRvIG5vdCB1c2Ugb3RoZXJ3aXNlggEBMAsGA1UdDwQEAwID6DAMBgNV ++HRMBAf8EAjAAMDkGA1UdEQQyMDCgLgYGKwYBBQICoCQwIqANGwtLUkJURVNULkNP ++TaERMA+gAwIBAaEIMAYbBHVzZXIwEgYDVR0lBAswCQYHKwYBBQIDBDANBgkqhkiG ++9w0BAQsFAAOCAQEAfwlONLYPo0BNN2NyQZM3wkoldvFqidcoZiYALOcBcmllMP7H ++XQ/+en4TmbKR0RUJN6AjR9yEo92fHAYOB2L7AzR8AkOiRLjp/Pdg5kUHFTdKenTK ++DvpeiJELz9chk/vaMv1T9qvOwH2bVAyS8GrUc5n0ui5F61PrquLAmm+dpKyHDY60 ++DdFaebS2gYsmy4bBv0mgcMZ+ZXnzXYmLNtdVQ3SgVGO7M8eyCqPbe/o0Lw4Gz+l0 ++xgpFkptdlEogsOaJBzjrgWyBnWw6MkyyLiSY+iOxFpBGkwCxi1gtQwbcp4gMwaxc ++p5+JPM/JBfglBX1lpRhhxL8EGQvpryN9MT530w== ++-----END CERTIFICATE----- +diff --git a/src/tests/pkinit-certs/generic.p12 b/src/tests/pkinit-certs/generic.p12 +index 35c27415bcb07c479990133882655bce3fe3bd72..55a248137ca7b82654252808422e97337ed95a6a 100644 +GIT binary patch +delta 2529 +zcmV<72_E*P6Mz&VFoFsE0s#Xsf(fz)2`Yw2hW8Bt2LYgh38Msp37;^637e53JAbV+ +z63K|{jPm6S=lRhUG)C?|)hzs!}J6Z>esz%vM91VoEu)Pmv^_jw4QQ*{P;%zdH= +z8s3InWP5X2dL3JP%_r_AH_wr3!haB>cU&;sQHeY0h(*0{Urg+^g7yVKn`IE0+Y~a< +z<+xCb5BfX!dU%zZc~;wYZFOctxMS?Ch*eD^8-zy8#7*(m&=G8Yhq%X1&fk&#wqvO` +z_dV6f%Lq>$}y?fWJ0eZbaT_3xCB5v<1XX +zhesXP-h3le9uU$XQav@c@^ng6qjNOuTgo57tfg;nGUhmeDh5PY6l0w(`tmfVgVRd9 +zI*Dp$(4kaUY$_|u8*tJ)z~Krm!cf$))c$ks%D6w-z)!1oA_bqAdZA}A1PNl78+^by +zVRwaGflgdSeO1RqxQGi;-G4bE0H%>kz6g9{O9DNB5M5tLz%C?ula24llm} +zuabL^!h`a+uPu%ySk>~=QyaYKaBuM-cq;N~+Yx$45s+L!{%M=B-hZOqUNh4Z-0?vO-hD#{!>=(UZ$|e*T(Ppu?Da=)T;Z(vy(zB2AS5Op(0bOE%ijXo4T48j +zaWpTAg-^G1r}2Wp1*k*bZcWwf`iU-QS;py!e2L#5(1)IJP}}evf+~Y&;L^{uM-p#P +z$CG)Ic1TsdW7ZAj_9OvHhVSGr5Tr)o_wWooY?lqp0j8d)wxI&i!7%mWDC=nXromP*=gpE(B1cq6 +z@&j;>({0S<2hI|cciYPo@g%a*p@w1QGgUypb46QUs!RVP9)D=_dWE&lLg-u?xw~PV +z8h$a6Har0<@wSwfG;mYk()2u9489&2LgL1C(X*xX1j1|82eY!A`42Tp_64UG7SgBu +z%wrY}ctA8@Orn_s)L0sRiOYhfl{V{IX +zM*Nb94b`ZcV1L~qp38AGXFWP*5hp^{z@{c)LZAu9VXKJ{o5DhRdf!Y&dE}=hwC#io +zYZtdIiA~U5r(Up^;hSx%T>+Jy<}L55P1hamg|^{b1f$(AuO#g5sY1S!!RH0q+MJHB +z4KRWQga!#JhDe6@4FLxMpn?T;1cC)|FoFebFoFeX27e1GhDe6@4FL=a0Ro_c1u-y! +z1uZaF1_>&LNQUz5YzW6GvH2i8WJEF=@#Jf&|c95Qocq9uI_J +zuEKYIs(pnOmNhS39%39z*|>! +zQn!$n2&<*PQxpN5z%hjmlZIh7OhJBIERDLutbco%u}C>L6m-jbjU`E0z4N4hv7qv} +z^8gz +zK!5#Z(o{x~w1P9(r4Li1M%kTWTj4^9LM>3^D&+%>&>Wli9sfvq8guK6okCa1xutOKr6 +ze5ic%+9n`|zI{F%*l8Fr;ljDGAvLV0jf_)^F#+Z_s_@|PN(w%P!=LYJK87-dtKya2 +z-ou2tBdt^%>*Aqa4Oz$fR`pK-Kt1~8U({s7fQm9sgMRC|HbAW@!MkNsfz< +zs3^xE3`}tjOvaZ`mTy27G6T*&3x76}mvTS&uHM)V*>8 +zLvM!WSi)FK>L5EKYmVS=wl>j?$b4-)uQ5|+rMxsUIRUb~2(_i}gtCLG(Lj^DK^6HR +z9|Bvq^{Tc`3RDQ#EExyBL%EMeJ0A)4WmSkOXqfGF$5-3gA<;I^%nD!<^?!uBBky_h +zDtHZ3Hq?a{K8#>eqP`A1yryjk_q9*A{X2bwX11sbz$$Y)U2w$6y=G^r0u5K6r-Qq$ +zhmU#{eAbmCy5=l7y`BIj6sdNhVHC%_79bPl +ziqj1XqSWmBQHa9luW4F^7k`C(;)-1%xig{k$ZRTikT+J#^4~y14n$+@8>ZlRhjX@X +zGv{`|4XV@GM}bVDI$XXh4edI-nqiEw2@N*ip5xg23vTl~U@sV*_`HJxr#5B4$dV6v +zj=|^1mfn3wd(>scr_%*luv9D=!6_Jf0%mi@W8$z1!3`<@lUmc73wTM| +ztMxU2wp4lXT+wF?cD6j|rz=JhmfCBDAl-Ij#Q0W%F$P)3fwn}<2+d$G9GIQzMh!YN +zAmjmBVsnk6AgHmakbkjQY;aSX$`ujO5N8damZY7qviDEls~HZTCkILT#rJxJnsB*n +zR>-H**-OEFgmF#KsXF__e;4CL7kK-*wNi<+Exq~-VcGD9%`qh~BL)d7hDe6@4FL%i +zF%|?A!W!(19gkH}sK#VEJUUJdl+OXWFhMXeFbxI?V1`HmWi|r@0s#d81RywUr7PU4+J&7;H`yIZWU8rteK!mx%-j>llc3nny_xmpD&=el80aE%9m{fV68_AYFzhm@kKP%T=aiATz>)K7usww +z(0*{b68eczuAI2a3uHsb3Zn_F)9~g+LCvtun(x>N9_kuVVuYlA^cxgA()Q^}p{@VX +z(pQJ#h!L# +zvT%~2SR2lMq2|uvwt-65uo+g%PdM+yCR*0d3<~^2SWHuSkyu|U{2*phDUa6z^!f#K +z&e!gf!i)wC0}3Cr;t4QJ>qXxqtd29tYZ!QSIJXcb1=)#Zz@NztpMM)iLM4FN{(b4O +z7;Y8sDSuKgUUFZq^5D#5vcVSW7Jv7Yd(aBQZLxL`TMK);Odg}Pn?i_&$%=^rbRuT) +z1@-3i4P15rwSp}Q52aT>>NISAeYnh|qF(@TkGZY4j&#|GeCZ}Hv|Wo|3Ildq{En?` +z33W*|;8`HbhQf?M^M5j}nDMonW~5ihFn!pqa@$I}d3&;Sf_zYJf +zK3966V3l`s?KpMq7Xkws7rQ0uNx?O)nr5OZ&sjxPS8n6V!bbhl+S`tADP6n()KD|d +z-4;CP6oPK*x2YwH4h?UM!7FQ+S?s;2-TRK1t94vz+%<~h=YKH5b;L89yyIr-R20Xh +zS{BJAi-^$up9m8hh*-25HX~YLbxrHdA82beU_`X^W`y^J_2X$56A1j~=kc`==Z_+T +zu7n}%#;**bdW+$vg-Mi7)lR@16R`>eP+7#cXM{AT8(O1C6<8Jjm?oO_Dk+uOv3t&g +zP!zO+$`Utaxql8|%C$?vj}~CsWJnUybmONs+6V!t>=}LX3`Ea~#O_UYaY4adZ=6kJ +zWazr~1Ui&-TH9eCh?b{xL&MfNVV`KjC{9Nh#fgY%F57NeV`~Z=1e&f>y{fZPK8Y+& +z12BRGIR*(ThDe6@4FLxMpn?S|1cC)7FoFdlFoFdh27e1GhDe6@4FL=a0Ro_c1m-Y; +z1mZ9p1_~;MNQUxYm$0NS^prVcA%SO0uwo +zHTQ=?Wn+3w3*FrDC(OA-xz1k4gg0%e7 +zE|q{bGT1^9c;Po6)t2QAoislaez~##_3so3$~8c|6ThDALVuQ_`csrzZi7niVJ9&B&mxm=-_q))60k=1>ymZmg$D41NgWqT6$()f5qclF-{owN-!( +zDNM-9lt=)MEIj|1m8It)GAoJ%qaW@RZQc!WT>eKQbxMSUwCCXnn=J7dW==)=q%_QmbS-PsoBVmQ8#q>Z^57uw%&$COK#CU_J%s^HpCp-Pso +zsVG6ZqD#N95LV4&Mw?3o*)hrMz~EOMuzxqgdGzSOzDoDF?Pkop!&U7s;C7a9@Bi+r +zp!&vTiAsBFWBiz9fh!LHbIQHHOQPIy8weJzOs7nB3foOb*z7OelAz +zF$EsP@)6NmCAs=uFa;EVKna5xx0wGC#1`kHKO_2-y{6nHp9b*qZx8n~sZv2}KYy=9 +z;~-}X`6hf1FeQEp+V1&}(%k_e+XYC3sTNhk<2T!iAyy{PA(IYE9GAHj(LQE#V91#~ +zMpN1OiY)j(O~~5A3sooGn~qp$_FCm)P6?T^VJIP^FO{K4O+egG1sF_F)0>`OQOio4 +zjE6GDi!3W7g|OZ^z;M7OTLGbU+pY!hzrsCEIoUkENh3X5HhDb9>|ytO0Stc +z@^I;i)OpS|&hTxBQ&rT4S3nmdg~fDy@qjnF^LgIQbKcXMGfqm}?RX#B>Gf;lzxO}jM- +z^t@NcdY7+{Q-)q4=Ko$b^?&x{b!znTkhh!0ERCBt;t0ez_1?u1D*pnqDZ~gg>wdj_ +zDezCIv8*1y!-2=uWr$XJ4OSw>q5$^1c@yM?IK-sh^c19jqpxi*kgsE^^W-y_Nejad +zd3khp1|E-OCe?G*$q+&?|L(>VjwhpmXG}Pxk5vO(Qyn{y81;~`)PL~7xU*N-!)((Q +zs!t34$4XA5po!lQq66@%NADy&c}(Eg2(@_lQp3?MRq!|?PO=AXq;qSylg+*;=831x +zV?Dd^3!*hvgv4ud@Ta2hPE24|C@l*$Kh8kG4%2x!jBss%!yz?NiaKJR*V?l>TPY!I +zH_XRAWAxGcTje&~Pg*f0Fe3&DDuzgg_YDCF6)_eB6wv3{Iz-K-_+dQJ5g?!#l~?ug +zDljoHAutIB1uG5%0vZJX1QbP$4lejcX32OA_0p;gH()NMq7(!OS_-~il6^%c0s;sC +Dy- privkey.pem + openssl rsa -in privkey.pem -out privkey-enc.pem -des3 -passout pass:encrypted + ++# Generate an EC private key. ++openssl genpkey -algorithm EC -pkeyopt ec_paramgen_curve:P-256 > eckey.pem ++ + # Generate a "CA" certificate. + SUBJECT=ca openssl req -config openssl.cnf -new -x509 -extensions exts_ca \ + -set_serial 1 -days $DAYS -key privkey.pem -out ca.pem + + serial=2 + gen_cert() { +- SUBJECT=$1 openssl req -config openssl.cnf -new -key privkey.pem -out csr ++ keyfile=${4-privkey.pem} ++ SUBJECT=$1 openssl req -config openssl.cnf -new -key $keyfile -out csr + SUBJECT=$1 openssl x509 -extfile openssl.cnf -extensions $2 \ + -set_serial $serial -days $DAYS -req -CA ca.pem -CAkey privkey.pem \ + -in csr -out $3 +@@ -152,6 +156,9 @@ gen_cert user exts_client user.pem + gen_pkcs12 user.pem user.p12 + gen_pkcs12 user.pem user-enc.p12 encrypted + ++# Generate an EC client certificate. ++gen_cert user exts_client ecuser.pem eckey.pem ++ + # Generate a client certificate and PKCS#12 bundle with a UPN SAN. + gen_cert user exts_upn_client user-upn.pem + gen_pkcs12 user-upn.pem user-upn.p12 +diff --git a/src/tests/pkinit-certs/privkey-enc.pem b/src/tests/pkinit-certs/privkey-enc.pem +index 29d2f3d38c..fd36246ed4 100644 +--- a/src/tests/pkinit-certs/privkey-enc.pem ++++ b/src/tests/pkinit-certs/privkey-enc.pem +@@ -1,30 +1,30 @@ +------BEGIN RSA PRIVATE KEY----- +-Proc-Type: 4,ENCRYPTED +-DEK-Info: DES-EDE3-CBC,5FFF1E71BFFB65E3 +- +-p89x5YEL+Mb6IPZXEkkr0KC4Wj+JtgE3VKdTT0wEcRD74QVv+dbbZt62WgmpJtId +-ph0Ial2z5Mws8L/aTkPdW2H/bEroApLu4TfUV+w67KcWgrc8gOg73d6gEObqx8li +-qGbs7FC1cI1WfDfnNOnCbD66e5+bTI8fDuchaieNRqzROd9RHhmlBHgylTmf55us +-laGuwLq2cZk/+Xz0M8PPx07uauGkAK0fyfifn/JR3PsGsE9s334osVQMjbjyT0VE +-rm8HGm3PvZHHDUnkOh7AGKyEtsIa5fJAULUjugp2lQJqOigC4HVn8a33xfLI0F1+ +-2nH9MZ+Ap1rtI1cJX8CDn/Ij9oFt01scLxynYekYej11zFiR6qHC0sspxu0Yi8l0 +-puBPXCI0GzyF9I53ukjGeibTtssz5yw1r+2oVasR4bvfXczPjqTQCBsPSUayNNhw +-RgT7k4QTY2OlrK/5XdILBzBlsvfndXgGOwEDw4YE7PMzMmz69vPMK7CfedUqtuXq +-bGBks58tzeOa4NSfVDOuFLI+LMkoYWMSjPGD/I0trX41xCU+O6PZOnDyt5ZWl1Tm +-klJpsB7rUcwsP8d4w4QGhyyV6Mo2MTlnTILr4CwwvmDMBch3yzwbfKdeywsFQh0S +-NMrG3aYNO7csRRTD6aGvYcBCbavWq7Ujsb/fV7SOIS26f4VEqewvOFlFEXm66zaz +-GJ0IcjtNHYNIIIW4690djxPqlGgbIZTblBSBlT+iOW5HrhXvrLeMmwAPxInU5dK+ +-ypk2MGc4SzemkDi8H9jDW3dwbgcvVD9wn0glhVLQKWvP6F73UUdVEXMCZ+960xnR +-gxeEwDdIpzXNadWdON1kRbqI2KesRY/XQErGHDOvf2gNSM9V2gPz+5humvcu3mXY +-r4537On4+IdzetEVtI7D0slgojs+jN8waigpkLFB5RVl8PnzblMuWOkHNA86rrp+ +-h6wNqv9kHLgPjpAyB1l/7w4VqXLXeC4PdaGc2fcpdNWOncUnHROmDmYvdTocqhIF +-bAsEFV7QZoTgDB7J6vLsmbtfawtHMSb81V/wTJWRrtY/gJCrkJXR2pTYAZlPX6vK +-aK7K2NuhJFMnrQD+kxsrloSEyfsZmHtk0mAVXJw4wSxlH3eGQ+Jphb/M2wtsnWV1 +-w0fehxL2Vd5SyBBctAGhUirhRngbOO/E8IioymrziQ88vJZs2DxvbuNG4WKTuTwj +-CIggXohCNKdqrwL2HAynm2FVEWhbKrQwe4kjZc64WjccR4cy9vv+dxFfrKl+vZ1o +-Wvb0WXND7fiSBrPo7OfaYM5HjrcvIRP1AtMuArhuQYVARmawUG0l7dFLN97Rh9M+ +-Ud9vBIfQYlubnTGVVm/5xrUh2isQbp2vrZLfMrUNXMQm0vSxKgGkAxqNUuklJC06 +-LvCtEWMYXiBmB1zP4khwCHmHB+/E1gHBAutCzhpPu86ayEtNHBHIFkqKvZSg/UuZ +-+ygDdTJV00I2neIdeQcyG+vPg6huIDIHpG5u6eQn5sLqVkhr+apeNcskMWpdkpFS +-Lo62KUZDR3yB83ne63c3IGex0hWhVojJOAxykpGp6OD9uFn6Xn7x2Q== +------END RSA PRIVATE KEY----- ++-----BEGIN ENCRYPTED PRIVATE KEY----- ++MIIFHDBOBgkqhkiG9w0BBQ0wQTApBgkqhkiG9w0BBQwwHAQIBw7aG13XYxwCAggA ++MAwGCCqGSIb3DQIJBQAwFAYIKoZIhvcNAwcECPWyEPoKz4WhBIIEyKHdx+pkDxax ++dCCUZHsJ54boZxh+7f7xmO9Rjm+6+3cE+WCjPsiGHPUDtOXLxWwcrG0RAmA1GmrE ++yZbclwEMF8LcWQ3EUDMCJXBs7CEtA4XDH+EW1KsZwP+cA53ZFFikGj3sW6Ix5GLi ++Df311Eumhp3GABU57siNn+tMZJAorInth5lXBJFQoE3KJbBrSN9iQKZTOpgr4G3B ++G+qzBwrUKnZrGIp42t8op4VkB8sA6xoHh/huJB5pNygt9OZUQ+xdxvNQq+5/kJ2I ++mP/JRPSuN4GtnNA4fBB6tPv8t0L8hActkWlQ1rSJwWnWge3t4r5/3FBcAbl+zq3k ++t8A0LWgjsiQRmlKRN7GrzorOUKFv+7YAq6rc1Ek79qitUgEiFkwZZySt5+yPstMW ++vpaq2V0yDHf5Ds9uXffprhSAjnfXdT4NTg5eMeH65OEedUpVVzHauoGfFkDGaq8L ++8XgWPZPaz6GQFpU5SGk8FZn0OLLJHnHQDYo+ViL2XSuuqY8Jd7fmpzqVoHOU8k9Q ++/ONKW+E6uvkpNH6NbknceA/ip1bcdfwA/uRBckXjCc5uR0oB18M4UQPuKlcGev39 ++mcdlvzQJxl2EWbB8ULazzuzOVfCAEwKc96qOkDAY94CB69f/KhBOd2QqHzdxrQ+3 +++K+YduhbfP49Vxaq4NIklS/kSSv4GEBHzEwtFxX4oqN4Er+UkBSB423nvlkSLd1g ++tR4M30lJyzmHtOEpSOZYLakviz36ZOCV/DsxrfziNG/0RB/mPLm/B5L+StqjJrTY ++Pjo3QHKb+6ShhTi+jZ8tqXa68+TZO3Q7eTgqrcn8mq9jfama0KQF/13kmUsrFXTS ++wk/nbSP10z+MhO68z7o3j+Q0Co/cXkQke4slvc3DqLNvpQdDMPLKQVxtkPBq5czr ++dbk5K2GYFLNWO5Tv2RgBGomznoAGSolz5ozIqxffVHAK4NGfhihgLO/6GujDANVz ++EX/2/IacRg0L0x7//O/GHomiFvWYnDbHhRNicERe/ji1TCxJ5glqntFjOXDumwi6 ++f+mQWNWlQWtKq0IOnlHrBB+vqykAj+e+FROqJjuNI6hu4CNnrBK3Hf+NY+rXdn7l ++iCTD3ojdufqo0JDZe8dXea+B7Zu7WNAxnpW8D018DJxR2hoBvT4Po1CBaHLfxAkT ++ZGeXMjp1vZ348xBSppFpIpYjFRQBeBgSezzA66o3YIcDeHu2bTzg73DiUXNgV3RG ++OyJHmsOmN9Gax/Cx4z6/Ff7seisXpIMRU9TDrRCFKAcPHXAl3R4L6guK0I5OGwz3 ++GSMxsx3PGitj0x+1ynW/Tf+EJQD33ognc+kuQfNL0XW2tNJoibZIs1WgdbDwD9RD ++X7rbb9GfSJlQUnBFG/EKU7SGmFZUVMz7we8vckZ1PfeIKfH7OWrZ2i1WxIF2WO1K ++BX4TXp0KKt+aCwf1GInQ/6aYgh5g8W2iKuz2HJeZIN+ohciNmpOynsFmHGXdbvnO ++Kw+msZEQb5AvhXf4ToiSwZLSwq3qAILN8fOQQ9ta1DjJuUtITpe6ys9xhlnriUkm ++KrY50GkimLdD6XszC2uNulAuh3o0nZplqxC9IOLh+uasEU/+xqtwTaaYBljTpH2C ++8FPAEFFUVy6lsngJEQvdjw== ++-----END ENCRYPTED PRIVATE KEY----- +diff --git a/src/tests/pkinit-certs/privkey.pem b/src/tests/pkinit-certs/privkey.pem +index 007b6275df..2a25dc19cf 100644 +--- a/src/tests/pkinit-certs/privkey.pem ++++ b/src/tests/pkinit-certs/privkey.pem +@@ -1,27 +1,28 @@ +------BEGIN RSA PRIVATE KEY----- +-MIIEoAIBAAKCAQEAz6VXmJpVq2zTIEU3gUF7pui+Wg17d3QX2oy6EqqUQK/pwWtr +-vmBIaYcnPq0ZMrzMhNTuyeLjb1rNNkL0hCdS3/aVbx1bOlkPVPlW3UNi9gWpXOOE +-1/N4QMrzyKAQ1/Npf9xjY/vpqsmvRx7AZpq7Nq7HyF5hbUKMHFaaTqRarhoP7mOC +-ByG8F44YQTY2RXcw9te63x+77c3O64gbtnSKXBC/4pS9DxBBv1ULB2wOH8RGxDiW +-gL0/iO25YImKQgTvwbENw4ygLV+0m1b+YEJLaIIeKleunYEMMkzIfFmMemXRWgNH +-uShYa0PeyiwTBSRdW9Yi4qzjfaHZ1dD67wdoGwIDAQABAoIBAEpnKYMR0h6xyNjo +-VGIpT6BYB1UHPbVo0N9Ly6TCoIqpPe5DioDVyTye5A4OQlgu1G3ISqPme6478ApA +-ZZMw7/42QgdlknnOzbKaAWkZK02Sa8RP9hrXL8CvuDisOjzXCHd7RdXevzSmPfsS +-5sgdK3YFnKqMPwbCcKf61CHXvHJjWGuTIHIRh8P7gJelA4ahO0kYQ8aRXv3ldquO +-ukSI5gyk9CN+aAHqt25kEmt9oOgk+8kfKpnk+5gkOCY2YOFDDckD7nL1VIIrDxwG +-SmU598qjVwycDairWUY8uSuPCOLgbvDM9N8cERDMsyNQL63GE8ZZyHZsJ3Pbwdfs +-JVHh5ekCgYEA/CwhaT9D0WQ49GQdeI7aqazHEYDmqPdE2/qbmr67tPMZzX8AAk9j +-r4aMT+oIdtIMPdoQNNcBP6NYZLlAoMbLoAzHmWJnF5/YWLnS2Wg9OuXUOBn3jk1l +-SWelJfAKGeBld5fpSLTdHjRAwJrNCX+mc0IZIiEw2IvGUPgKGX08bX8CgYEA0swx +-xCDgvfoaKueInw/rUIcKxrSxK3pDhaR01Dg2pwSo7Vj9W01zf33qe+mjma6+U2SB +-fk+/O2VXDuEOmVDLwvp6PkmUeRE5PyH7urTMEjy5ELNGiZd9zHoG/zJnRgPwTjuW +-yguvjVGJwI1IvmODuA7Xc7iHFlvGNuxXZjPkS2UCgYA0nFxoIdvbTsaXLl/7rAow +-xixOGY+GBvil0HYwZcSxrtpeRjXRRZDtqOuTLKeRaqdFLD6fV5AaH9EsSn4STQdk +-n+XwuVf61M2FTVeRJi9IH3UUM06zsLAGDYqmDJt+5JMmzVnNYnaTe6FazbEjXy9x +-8oNd3IDdXOQGNomc4cT+rwKBgBbABOr25Wp7cJGK1XrdO/c/69DQNYLMujbVLeqt +-enCCFz0uaoGNFVcAHutqpsZyToYvha49KxVc9Y1cirfPOX58i+7nAAgk7Lm8kC9x +-Tcj2Fr8PqiA1YlVMIi8uoGi1Ch1XXwnFQxgMYcKPPPeXQ+L8bxJFKwcltnm8/h3A +-ofXlAn9AW6fYZLSzOfNQTMnuukhuAtZcEW9NlJHbej305zK89J66S8wroQs5iOla +-5GG+S4YaZh5sVGw+mnS+FCw7cQCUk40kXwX3yTrxlX1qGSCFCQnFdJow+5NVg4D+ +-dzDKzniH71OZZFxTqiiz76XxiaW/rS1uOfP/WSVR9NBLpV5n +------END RSA PRIVATE KEY----- ++-----BEGIN PRIVATE KEY----- ++MIIEvwIBADANBgkqhkiG9w0BAQEFAASCBKkwggSlAgEAAoIBAQCb/Um3NkEmx1p2 ++Y5OeSX3jnTxlLJijnE/zewtP9JjkKuLVApoWu57aQaCCXVAQ4TEGsht0B67kF+2q ++ILTsfIaC6C1GjSoMcxGdDi2w0THNjPr0w6QUTiExiNSj70LbYZUuKHKir6gQs3uu ++jfS7n8wI7utQsinQd6QspD64A1VUnH7GdbdswmytEhdnH2QHSMgi6Bi3kPefzS90 ++iMdAl/YFOOwFZgZEkPixMSUYW1EiIPqbim6idF1SC0dQdns4IpNjmxTQ9IbEVEuL ++/KSpyA89B10dgJ3kxEmPmrY2883pRgNsx/OqeLS4ND2p0OMePoKZEIc0q+Qpot0F +++F2oUq5lAgMBAAECggEADwzB9vY6FPa46KE01dm7VqGN+SjzVR24rQIbFkzAD4t/ ++tRN6MGVLrz0TsmA0YFyJsV6vvWMcYY9Zc8eSDRr6k1i5PYxTGT5k3aVHjT6xsmY+ ++tCzIANmE5FWSRnrIFYh1ry1h2gZejbXzYeT6TrvdIKOEepWl6SIR6eiy0Ggp7G7C ++SjlpT96ZtdE2RnlvcxcACtwhe3vPbkLmTCOEqeZ6LHCHIHiK4KdJgJ08OjU7Kgsr +++vmnwTJsH5s0b5IIznfWajO4JNOpqjzFDjDctGYBwp5xF4zu3u4bKe9aleM0q/jl ++ZkibxLsFAh3Xkh89nxr3E6oBLm0F8r8M7PK5wpMShQKBgQDAipf6T6XUY+ugkKw+ ++301LyoAch6WV9oT6uOJsAttmcUpUr6NXhRT3OM4oqyYsAc5JW2wbz+n6lED3j6Ez ++QEKSIFrYpjrYr9D7hqvISI9JT0PhVSPXECfifEyIR9xmLvV9WQq7NRCJMi26X9ab ++Grqpw1HNlPA/rdcc/dY0p25DlwKBgQDPZqxSnwnTa6X+r0UdR8l6kc9VuESotpbE ++0ziF222bpXmZ2GKiEU1buFORHih/e3yDvKvq+p2apyUKnEEVQg/TL8/Jzya7fEOI ++lTXcNQ/f78ef+nwEAxdRVQkWXFWHvvKUHm1rGCIY7zeOLnQ9JjBQkgG8zhUamAP1 ++owLBBTstYwKBgQC+yNX9Du0HvpbdfF1g0025OwekvXiDV0m/UnHxiwcxxDJeJceZ ++0mHK8nu9apGha4ynvbIrAOMdC8gwRh76NMOCHhNGt7h5vAU9Jt2S0OtCPgvJ/N5N ++nVGYJ4iCRYqLqh5QvWlXxSYEfDc5hPuWp26tBsBJEDrbLnuH27JkbD9jMwKBgQCM ++f1VFMw+I9WehvEHpr/PA4H2/5/A7ClXgR+YGZ7s8sUBLA9btSyNIevnBWNi+Y3za ++ETm1GMkjNw9UvL0qFXJ68eylHXtzjp6BK/MslZWHcfudWCYi4aUuJ5jcWPhn2Oaj ++iGk/Hz4Z/hN4cee0dOZN7lrW+BQ7y7cC88at00lfWQKBgQC7YeW02aUPw9jMJh1x ++lDfBh+E5sdRwRQIvh3BuyTd+m/LI+3b9RSy+LIL2KFJucwKm9zR9fy33tHF2S5En ++Q+inhyXfOEygal5Rzxe3Pfx+pGZbzr6IXkhquHtjuFBwJJCrSeR66V2xDmzJfCj4 ++TY+CzwOJ/EltH4ZjPwEmE0S7+w== ++-----END PRIVATE KEY----- +diff --git a/src/tests/pkinit-certs/user-enc.p12 b/src/tests/pkinit-certs/user-enc.p12 +index 1cc3aa3da67160fd9298b9e2d624a80c5225245b..69780bf82d1452d5dcac91e5be550f5eee876583 100644 +GIT binary patch +delta 2892 +zcmV-S3$yf%7U&itFoFwY0s#Xsf(sf32`Yw2hW8Bt2LYgh3kw8-3kNWQ3j>iNJAYJI +zdvzN7hNA)k2mpYB1u&JU7+xCwe0Kqqz8d_+6eNN5bCxnq;S}(P;s|YSOhpyniUDCM +z$(1g#xF>v`h_!Z%^c0Yt!ew3_&P4(J0{#(9L7ePjfyd?bB;_QXFR7CVbnjKE +zff_LH>L^0?(6j~#3lev>bjhWkNPqvbKN_||)xXx>C4@AfTFlZU&lEHPKi4d4nj{f+ +zP!qS+8ibCntvC-FbX2Bh1;e5rJ^2HAbUA`MID37ixE)(i7Ff}3>6U!A7&UF;M}TrV +zs}FygKNP+*;c1FU9mKlF^p}|GEw>3l&8?f;h5;kVci=EJL){2P?KXfBQh!XdFp%kd +z*Ocb%wx_0U2R5IZ6yZz5d98E>a-~6_Nzx7S^X30+Efi5p^xb?~9+l&zoMeqIyzty9 +zzsz@?=R*_{cx2I*TK8_AuFLy??NA&|dO~=b>}Z8gy-$;V6$A;>=0#FrJ9Jh^u8)2W +zt?+rI1Fh%@eL0#j)BLG)A3wR#E)w3fN%6wZm#@DhR=+YxKGK(9yT*!=-Ns++Ssg0N3T2 +zKq%m4iv@P~LQo^`Mo(vF<$H-+DTiQc__AMQ#@XpYeg-&|lK+0f`+xn?YDUnk!*m-S +z;3?iZQ;n6bCF)Qt5(ITP`w+u&Ly;u}uQ1cMO&(bc!cfKO(a7W1_to~F^2+x*NgW)a +zRgZ@G)H!U6`FfcAt1chDfZQqj=#Y%;epbIDezJsIK-L+yD*p{<_X+yO+c(edMB^wL)S(YO~>7lcBt24a8iz +z>BqxgH5kvEzcWp$^y>%zfu0v_^AWYG6ydYCMdBu*~jpcY$>CJvKJs_U)yy}@2d4 +zseJR~7;BP{vz-tmn*ed*fv=l$4IYo;0VNXLW0o&Q!hbzT8q!Cnf0=w_#lXRiI)uQh +zV%mHI&J^p_;AT_-H)BKz?DO2vN05+sYJzW4{Ma%7L9plT_fE45Nv3yqwF;+zhVQTO +zpOQc^lLD9bh12?4t8>L1*vVNL%HEQGQ^g7Iqzw08Z-Z}ai+*rY33XPO~LIe+^&!Lx#pTd1JNYDu^}EZyH0 +z$TBU>AwxbT4nFscHMfohn3#mbtq1>m!CLz7(PkxiHtbu7bgqiuh(zg{?jAs}eZzI% +zFoFey1_>&LNQU+thDZTr0|Wso1Q7OWhVDa0j>1F2`SnsQsFehQ1kfy2Q!4pK76IBl` +z;zFNdALdBbb<1BjS7BgZ(Uvwb_x)%e2gv`eSYyFYtolD-;4XL1$)~RR)=d7Pt9XT2 +z;H%o^nkJ=d$#!Bj@GdAIKg$I2neN|tFeWg{;Q5)7zZpSn;T1olS+KVY_lBjjwSTe) +zb)VtP1PSkBMrT6Ioku_4UD?1eYXo!w@)n$E=yr0DHeN_iT)WQ6>M^o-i+u>O9PoIg +zAGit!#=pHqe(^&@p}lf=ph>TGzR7daU+;xp%fM56%$^@8^LiN>2W8{#gG*mrwrQTCXiGT6C0P}9P +zs|HR1en}U7kxre1`Zf~z=zusxmp&0{@$79lWY4|Pg;*&g_Oe+p8NJOzK_L!6qxHN1 +z?Wo5%?qF-5mPXn6j1@^xU2U4-hu3KNU$R*4M1)ga?HW~OZ>B1>f>cal_H>l{EfYi(x*>vJWha%>%~F<{Y3;G~g=5W0 +zNP;AzGh~ceJN%XEcgTUHj%>^4C#ZxH?6p$Mqsj%0UB(oLJ@l>MUVqg|)dT=|$YBt( +zu2-yM-d8h1I*-*B1twRw?8)`M&%5?ZL)4|XXI)mEAX@=CT2zIQ?xLXZbZ=q$w|RNc +zZ>3Z*V+x9d8*W<~L~B*X-R_HY{J-_qK&HaBE?`9LaGp#ZD$Om(@(Ey?#+yaX4a>b#%;z-;9V$w~Zhztczb-lw^6M1A3tw?M@RWNlUS#ne~ROieMk?E65E{^AK +z7h#?hzu<-)YhJC=Yew$y%NLL*@kQxtPEqNegvafKM+CXxV1H3%kxZd0Z?KMjenWP2 +zDEQZC;eP=48N|TQyell~0OIZYWa1A0K=#U@plX6Lw4tVn=FBwtcl==!VhSZ>7a#GL +zeLF|Y>4kb43XBgD=c(8lo0cmG5qOT1mNt)#aYl&g8eo(_C@x%x=Z0?)2V4r^U|~%j +zwef5hK?t&1Cx5gs-#K!O$Fo6@oZR^_4{UsI +z_6exMhy7&>jRUy#zp9Kzw!Qn~s3Tj;OJ%7vk6=QC$ObT%xXiHLaQjioZwiaA<0ClW +zwggOa)Wf1nmF08GoHj59|z3`)c&@iDicIM+kgJ +zRISnBfo4M)P>kfKHzfzj!^f^60#?=KX|!FK2seV>)(=(-F(oh~1_>&LNQU+@7L67nFoFvS0s#Xsf(p+D2`Yw2hW8Bt2LYgh3cv({3cN6a3b>IXJAYaW +zkCdOgiwFV&2mpYB1u!3O<&^}aGBO*zs#A~w5-^3s&_cc&jq;YL57~y$hvIsVoE;K_ +z@z;j^#4S|l0+R+;ItHJprmPBs9a_CK@fJSNtw`GPWz{liz2|+I@@I=qN +zd*k07Kk-OlQ37X@O=rz$K8j9)sDGPk-J>07oO@p^2gA5p`z!5za|7wrxe^F4OVF>Xh1Hq{RgYQb-)_;_0(RzORrqP +zH-6>9rCa#pY~43l3lM}D^Of?GJR5SgvoXe*9$n}6%d~(8ikvS`(#B<(zkf$~%Lonm +zNfw1+O)XYi?faC|BPm2d9_|?t7S{=Ai6*tpKfHTW$n&0tGKGpq#c70A92fv&u=zpl +zndE=f^VVig+2W8a6z{qV5}E0L^?@yQ(w=_afPb8CzW<$heOh7oL&Bp!JVA(4`j!s% +zx?fmOzd<+D;8wY*a3Q5ymw&$?>x3h&8^CM`GvEb?bI<46b@_&FrCy5mUzL7?O +z75ZMcP~PA0fwL>T(tjNAt}i#t^{zcGAz$K1>g*LjbfwlZDxSI=f3@WTNBRvsniHoJ +zrf`Aw?(*vKOp;T9&*{>E?K{SpwH17yQf5N|SCfKDNiq!E!Kg0z0xGTa87-U-d{!(c +zOck-NH6ki*cGdv_BJYIDt1zG2GRSfp(v|3ukshay-y5XaAb(9oViC?Tq3k5i`Feri +zttHdosBb8hps5^^GXj>(m2-YD;2H7o=p>1+rtl&MShE!M2?ed!cM9FV+zrx08{dcg +z$P_4=1NVpARU=pkQzG@(0n8E$!qClc>?KM@^_=a-tr@90VCRgJK0TybnLc+Qssc&Z +zXfn=HIBPvYFn0)M_`f4e;hA?uo%xSz0OeW +zNFM_sq}piLP@uBVmRVni#!=stFR|Ks&x8Q}?A;OK`2ejw&Tj(Xhx_g=L!>2WVRs-z +zGh6W&y&1fnPPNbM)lHyo;rWG^)bHE>E{|PL^ +zqx$n%KM`zvAgWp^r!U~!wxypufmE8|);fuwpKp5XXz~8Je^dVJD= +zOMjqU-55=b#50HSV6Y3_+?CRuZf!2M)0P$P%bi%ACPtPF;+gqmM41S)bV{HH*6?l7 +zFoFd+1_>&LNQU?#%Ea+EPCb^EOHXH_=gdD)Xp+~Q2LY2kYjfS}$1nj95o?56!tflz0;}d?$ieK^6&}s%L3Jl^~}=VgTY4GhW%*_#a|; +zj@K33^y1^ +zK#A=G{dRZu_!rdMFb6QVMS(Ip`>W|< +z4z!ekC+@j>Qjlx8(qW-9zHdj|;^B76#Ng{%EWjRq(IuJ6<)&awN4K+UwwNJ;UgX}E +zcaJ_73k>u#l9eP;Li?1Szkl)Oo#2|EAHYvAy25&G%=FCq2i{a!yl36`>q*b8T+*;s +zGejdSSpV~R13c(;mCzMMN6iU9ob!=eBh3r+awrj_y=yEp3JoOQx6Z$xK1o|4KRZDM +zQBnXVwZ>=c$&42g?R^ZF45)g&{)y-{_@gyo?dqxX9ErtT{JxI*8-G*_P}pLrW-1E$ +zHaN5nvDs*jbx_bgcL_D@$4QnDKIv6ws`(`gn9V-+tiycOjA@wP5X_WY$OELGX +z5KUX5YQ@_olJG;^oZ2yRmCnEb1D`a+vxyqG-vy~yGiouy808|&S{7?MV?BdI~5 +z$r$t9jm4bXD^b)>rkVn3#X)v{8>DuBwKbv=IxjOWC+r+8lMwH&{W6*4g#n;A; +zO4M7AXKtNumgi-Bj**jJ?fCr5H|=aBrlV9HN^WPkhM=+(yMNVi^GonVr&qU7AC9>b +z49|BZN0T}tH2DM}@daN982O;;XiJbw%m1(>&0zStXTCHiqL~wKB?P27Kz?h){H&yT +z0a6!f5zd}BisU?Bf9`(d956SlCT>3gvm?yLEEgOHleI(q&4=!s~U)JFb`+L~}IiD*+*g0&iUOsbSGYgzb>NdTp +zqqUpm?qjji{*LRy^gF1p#_?VHi4*L7pt_M9egYpb2L19^P%~?_Q6MTIso>1niUlBz +z&LNQUXqJJ21=NG&!mOU3kJ +zFflM8FbM_)D-Ht!8U+9Z6sQzP_9i;N@>ZIW53D_

      e+>;wo&%Za_$K5C!>0tf)< +Cv^tIe + +diff --git a/src/tests/pkinit-certs/user-upn.p12 b/src/tests/pkinit-certs/user-upn.p12 +index bf47384a8a654fa77d9d9161c801292292ccf4ab..e91cc8a0c04869d6cf9d66f5b1b051e9f3f6ac58 100644 +GIT binary patch +delta 2884 +zcmV-K3%m4%7T^{lFoFwQ0s#Xsf(sG`2`Yw2hW8Bt2LYgh3j+j#3jZ*I3j2{FJAXS! +z*@zwch1miE2mpYB1t^994w-1MgeIP0Shaj_WdPD*<`ao4RB4%B;1!qUi4&p(CDJ;S)D+_sG5VV~ +zQ$)uegg-)nY>J@=`X=55yd*|FF1h2T?_^$o;jzHLsjhabCH_1ucm<4^|1)>iEPp)l +zr`fWM_jd&6^poG?mz%Xq#a40WKPFn(tA{`_dWfKHg0-O<52jv5Q93&va(_@T3CUj< +z0WY&G7%<~VqQ@)3_!$**I?b)=vizO@^WQRD>b+MudQ}{)4vvgomus3Di-i09fLtc+ +z-@6;hAFAv$JCwV0#Qwkzw4gup&uc9{IQXP*mmZ3|aHIBk1EhHL{5PG-IM}|iqFq*# +zTzie!)o?eYrcWJV8pynY)qg1cN-hb-i$7d|Xg&|At@X!`uGqu$VvXYj(63TzYiT*e +zzW?uzBT%#jm7P0PLD3XAQq9F4uLwUsBh?d!2y?u4^5CNAf!qRUU$VQVyK#iF_TP~B +z#onH-o7tzcO6Q^v7GcM`(gz_*e5VOL8@m5}KSnn=rP`yTs7AlY-G5#76XN2TW%<;| +zGoyMDsL9-cF4Xpe-W5T+Uth$S-ql98cUnVq>Fu!0m}q&99V|Vo@OB-Jqh;JGF3lTl +zvmeBJsI*#7V2pY%RTS&g!XUO!Vv>U!_Gxc&XQxd)6Vl|xvPV*NZcZ|!>8=+@_J^zd +z9wjwHLS)!-9u#h@0DrRg5ix4vy>8NYpgnyo-c>t$;4lh^dK4cFHi5Db5SD*&_r}nE +zb@WLfb~v1}6lu6hAY|QXKAGFH_e#O)?iYYb%+{9Gb~n3Lw910jG8+H1C+Si~eJNkt +zy{Cn@nO?tKx*Jc2CypM;3C5Z)4>l}6nPzpM+EoUGx1|H;+JBOrINg(y!@Qtu+=tKH +zmuO}7joP%Ttf`54n~u$-R@L^0b?dmZ8^S3-NKF-!Xh*$WxmaR*5M;R&u#Fl$H2hD{ +zwIM{B+CWT%(V?I^>XtmqmeR>KDCIFNHWpyaa|`t$5m}*g +zK>&|Ey{Z|rxBD#9Abq+Up(9cq2#O?&gp~B8mu@ +zAhNB4+O5c#8OB5Wub0v^LYpy+YvD>1~DmyCA^7g%D +zFAAxaq1oCJ*#e;kqPUvQB?{$)UCWtFos&tE6ngi`#J(zz5BT3#jp;8k^KwF}Mx&M%q=hNf(NuFoFey1_>&L +zNQU+thDZTr0|Wso1Q5U)0W`6LNiYv(7JIIJGrI(W1klCz!q3{|#X5KUyo}{Ke$8*4 +z&z8gsBnxa}BkX@Nu7*?GShxRsy(nf4M1NX$7U7f*_v;_v8QmAi1RA=90>Q6mk>K0H +z#oV_k5pRI;GVQ3j<_i&6FF@?OiYbr0)nN~B0s-eZp5E>oV_kZd6{)+kM5N6N?Ld3H +z)wfb0M94{)uRKzoHZUlqQQ{`;zEjVeTbOk-Mt}G& +z!k=6|Mjv480NzyfPdJIgH0@|a0zl$H>5Af0Dne8-zz4}2lHd!s3 +zxSf>)2GJi2L?K|q`h_O#om>P@(Vb=sW3vWx9xU|H8mxx +z6`(10w19d!;Gs`p2)_6Hl$RK`TEV!p)VPK! +zaxWY{)O03zer|)d_jRj(krvwkkSyN(Nh-WRmF#Qp>Jy!6>^RCj-Npj)j(_z>y@QU- +z@ZL#n!*Zsb&e&}8Rg@SJl5p|B7l(u1YJ(3tl-#D_t_yL08PNf15V2}X)#%GD2*o9PK3%fNCJ*_+= +z%xwkK;lE=s`le+~$?pnn34dok-|t4dj=d{~HrZq*Li94h5LRg+?=$WT*{8sh(pWO; +zx4S(^BW~+)O`Mt*c>{9;je)afv!lqC@}XAxj=mGhXt4NR2R;a7!SOWb$nSJCjeA_^ +z8`)x3k+zM~B(Pl+i3OFdw$_7b0uOA@8<-%=1$m2$wl7Ili8G~0T{II* +z)Mkvjg@Tuz5BIgMk9$ViI62{JqE>~?qz!0*3CZk477 +zouHyH@yBwvdw;FKYYH>yE~}|^QYs(;?8`w5)-WxH@SgoCFKDpSStZV*Oll+`gp&LNQU<5RG#b4BEJ^04G$AzyQk*SVS?I1uWrC}u~MGWb!KEd3HOLs +z1vIdCmj9fXy&snurXzgb$5TcD!>K45?spJD`)LcPDS6?a;V`RNpkjf`EoBh??RTlK +zh#hCXlH;295z7xk!RW`#2Q)Ldjem0>WbPylh7u9DMA``T!d19RnS;bk#uauLlP^WH +zKr2J}sUw8JM}#iNO|VH +zR4xW^b$*AM-mS+(-PO-kX_m@{K<)}Cx}IT^la`VVIVrkTV5%o6Ay#2R8Gm&i@n79z +zMbt?rY=qLv@A2$}MWsJj7#)`LB6Fc>iB5mgaDRksov6|o?YhvA=5QPUwqt8gPxXm@ +zR_v)ai(Uik*bb`DQSA(I#xt|$#v~V3ot*8sDww1rNSiodn=fVmod!NYECS3>?B`l4 +zC9_gt>z615h!;`Y)47ErO@DLZp?MNZ_5Ff_svYCM@Z87f#e9llSG=s7vqkKA{x@24 +zAVHwi9Lk{D(6=eEA%KS{p?QMBW;vLeF4d(a+;9T5J>N-hUruMt&Th(NZX; +zg;H3BzJdyILh*xPTJA$FnWa>4#A|v2o(ajRc^g2K@{+AKE$`~-#P(nh!v**PJe7C3 +z5_&Y5eczza5Qm@ocj@WYs%2J6H1Isdq_%)2l)_`knW#8;tT=){0p6uFqfI#J^T298IsQ +z>I$oO)gY?L%QiQOULxj$9;TxW2Y=Wjja17-rN}yw#1v{vNuhG1XVYTnq3NV0hn?>i +zO}u9T7vs~SBvUb7|BD&zbC>M(@O_=3VZdYIA-K57Xq{W +zgEb$eyZnkRT?lF3gg`Yn;`GqP_vCc{mR^{i!AHxKO^qcyAr#HKLym1G=Weg&=3^|K +z>rS<d`@~O{(9z`ZiTM?@dR*2yj!7Q3+L9Y=oJz%W-V7M76z? +z?R_NTw?*Y%k(hWGe-P+8Xyu18Tkzz-&8A65YgT>Eu^NU)aO;dKf+zvIh^!8ssUq`v +zG>S>q@Zu)SaYQJydZt+TmR>5$RB*L2L)*Iql1J@C5{SP9k06@-k=3HjQN5y=Z!6>M +z#MH3t|9_5JmWH8lzjUZp;8L7rnh;$az|w6Ql{t|{YprFA_j_1tr^r=ZC0*U&Vlo(SJ1cWrAPSUH^wc|vrE)kR +z?cXa(1TcEN!ANk0%zj|K^A`j$w&^r-JHUqN9e==jAPlP4|2}*i-^~N4H&WVuhuT%A +z4NMZ&L +zNQUwUr|R0tf&Ef&{?f0joUStwUh9&a46T=}L4X(YEZ)q{^&| +zq_O=fhFO=twxQ)i)ictPugP1)@GE?0LfiE&BG71HBSVhv4uLQHv@U5l-RAD{8y8ew +z$5lp>NU4?E)-f#wzD?C0;y)WCTktzeYkxwzZ6!-?eFHm^IZqD~<*I#5Nm>zFieKX4 +zO`ivDk`gO$>PnSjZ?5Mm(X-u4F30DqM2^|IdlXJ&GbBH20*}-6w#G^`AzC{)_^YHP +zYZO5Hp=lJ6h_}SZDxfLEq+N}72EF?itd)kRNzkGDZ$6hI%(z6HFW0v0u%S(N#D6-K +z^~oTy%zj-t7kvAJc2uses017pyZX<;A%Boo`8qmbTi-;1Y+P^ZT$r@+d$}-C_11}k +zfrtB;5(a*fFE1)5s&uvNSj+0tb8mv+xa%9e2KE^w+Ijx)k2w}!L7tY$fzGi}k&=h< +zHNO?Z#O9U!sJ_o|ao5U3273fijemRY*`f^vpTa)i2!~LXZU(As)(9D_7Y)|eqjCXJ +zH8YOtem%7=RzGk|{=Hx6<)X^22cHo>GlVeqnJ4Cx@&=xW$QMPWQH|mS>K3e?{2A4V +zo*wZS(hJ~bzc-m{j=qs!VdsL@a`-J2_N-Q!cSRq)_?OXZ9Cq+ +z&Ips&2Y!=ahQ?`+ayi9Cs0&Erow>HN1Zgtzvp0=9+&N9_eJYxc1dE89j*Yn +z)|1D*i0XXN?4up^9FyflGJn%K275);(YWZ@?;KEO!*;z)*ooRISbfMiBQXq+%Ya5T +zJ}?c3Bl?+2vj^j|HI{X2Bd}oimixhfqwh;U8G+h2>f0Q?OZ|!sc5U +zk@CXsqV9GQB7#ZXO#_4Tn4C|v7d;I#TrGIYR-@TSyxZGTI(6;mbh7%m!`Oh +zp?ib=*@9t{)p*Q@-+$p6e&>}M9yyg&uxh)h!YB_Wx&J(J9Zt>v*YcD7#86EfZ)P}{ +zCieiXHI$g@Tc?Mr?S&DO7lTDtTLZvS1~(hg>zX6ltsNC&M3bF!r(|O1P}3^VN`zT{ +zj0dB54PR&b<-8RtzF0iRs-tOYOm)n?zi-6OiEbwohaba|vVTXOL+zixO!r@D#@Cex +zyX_Fl^JboqR&${ijvoYRRO~gCD7Uux+4z?Z4iEO6kyED0K!0J(j;{pWhDVT)5y02p +z(W*ESKWz=@q+Gl;1SZiKkK*Ha*_1VSL(vd1!nf6TIjp87EpQ5&e%;PYJq4CDW2$Zw +zs|Uo6aqZ?yK!19mroKn~4oT|Yj&p^PpwjvlPv)oF(oKp%i`YpnX`Xl;*rBO(B|=NC +zcggoj46fA+7bww@VI%k0<Cb&LNQUZgIobWQ|@8X)gWKEkQls>5bGmj`vYHd#Y+?jX9h9+CF}@qc4jy(~E9 +zpC_weF&>28nIZ!*fA{&swafGQ*5rKdRYOSQdo8_GT-n@a>i2Yojm{FE2EOp-w)#9^ +z+aT%9DN95w(w!}IyA{L&Xyz6qPM(ESsd9zoJPs6@lICqC2}?Z4=_`B}1$DpDXlR6Z +zSTB419!46STDltqpl^sfG=FbYlwneSTp_q?8}f)xbZ9{O9-Wb>tHawa_MLqYC|2J( +zX)OGzDQLN~OEm}F`&j#osd(ZVMA*NvLxKFU0)G;xk^mpU!-s%mf}lN)*%Ltli!tr9 +zE2P3!^=Y1X$0i=iokHU795Xm8+ZSG3jrI$D6OR#Gi_?zXobn~Dh<^rWm1JEZEg?$5 +z2jamsVE$12jr9St4^>^4sZxh>LgApOHi}EckX77*F=0pDc-U~>y%iu+NFU#)8Rix% +zj&nnj7M?bw8Alfcj!W)BJm(gb?6>s(XYaUQ_e0D;+psl*K~&|egZI(KmpbQq0wwT9 +zu+AcxvTNZN-+??(+J80aN;}ltl455DT(q0J%D+wlDj+y7L=8bgAq=WQ>L{sB0*YzN +z^+)0y0b6gxGG?EN6$SD>CA-H2V0K*v!X1fNu4(}Oi)O+bk6x#Iq!&*=9o00PU5=iV +z9MlzT!gs3Lwxzi2AqC_9Br94g*UekyjX?7ZvMchRD&Y$WAyF$_0r*Rfw +zziFU*CGJps%QP4;8Fg?z(0J};G!9N(iOJ`lZqJ1!R)6#f9>qS&!Y@bPO-Ok?W#xQW +zfQA(`0ap?-cEq|o^9&yEt}k?4XkTLsZ#KZVcj^jx#{>xi(zUS;nlI2x9N{&<`LL++ +zcAEvFpE{Y%E#pxg!Od}^K)d-hGcmHExdQLw*v@q5`nes|RvFM|#ilZYbPU4$p^@y} +z&z#I@bANa=I5gyY{59I)|8d1yw6UzTq9rOIjx8o9I;El`(POGpLu=+>{f#2MwaY_3 +z7^25e>dIDS{ZBt#ai!_n5yXH~^tOBhr_@$CKi44oqzJAHl}~@&t0VqulbPSEcBF;k +z>2$wH5qqPbKawRqB4j9ttg?JOiH+o9>s|1qzke!$9d*3;%M7g +z29-{jz*kZ+Kcq{SjLN;n4Ber1K4yDXYzWr+FoFey1_>&LNQU+thDZTr0|Wso1Q6z? +zUxJolb~{rn@ALfyA$A0U1kj)Bvt1ZK@Ci6CVTSS$(6{2;mb9_6ogc%2c%FRB0Na)r +z*%_E<-(3CfoWq-JeM2LC3qAF09L +zg{J|A1^Xaq=epb>O)~!z=%%-`yOXl3%PjAvF)FBpL%PQ8wTn<)p=DR)-dB_0il)sdbjsGpBc)#n@$o$#SnZI(Vvx(l2?*rJ%SpcdNjjQlrd=@Beh+$_|6F +z8@Tz~KUJ!eZqW~?AV$XyLUVIO%YSv(JkC{tT#X%aYc-b9(YI*AI#| +z@MwIoBm5eVk#W`oKz6qodHvmIS>8*z%=9UmJ|M-{*v1k`kwThPN|G=ssmY6 +zdlK$V$NK_C^k`Q0!lno85{Vus_qos^`Lp0zfxv(h17en6C*u(a08qe@1AkqVn0)b} +z_Xt97qce$VS@%WK!5l~<&G+JOPggXM5_*(NH(7lp8{Jpo+{LndeBBFeK|Qn +z9UGVTdha8uxo_%X9MFciV&krC4;DpRftzbyI!nYxd{sPcCixi!0qFJckW+X*!~7dN +z#qLCJS{#C^lb%_p>cE3Gff5>B7@+UaH2G|x!e5o5P%R%B6vqemlYj0D+)w-FeI>(* +z0Z%64=+!6EARd(`dHMu&ZEii^ztJXgr@}do_>hq1`p{HS5F~=?zcN*LufsIudMT_~!-%1k2Z3CDO0m;OS8?o*&w56(0V%Y*=| +z&6KdgoIuBBWarFK(|-&5b6I2rue5K;BNY@TV|7>-A62B=7|2=;u_KME9kfRGO7R!8 +zk!=M>VYHe3w$voveBEaD`6q1-Cq1zx1)QL{#hAICUqkOdQrii@<%vvEX91z>D9Io3 +z3%c+cI9lYE^hh^AiBrSmRh~J=uQ6BwGHyUW)6{>GMKCjH$A4cY;o4ZsWe1;L-{B`) +zTrX5nB)#PSQGLx(y_osNPd*Bwj48Brqm=*ep +z7?tQkxb##(ZQ^)93Wc5!#dewm80kEjmklRcG6?}+1z!$p^Jk2Oe_JMX8L;k`RGGFE7$_Hv%ZKPxRiZAvez?hfXPXwNwRuE|3@d +zdj-&lv42j6S5hNDUC;L)_JH0QA@L78%wofg%ep^s#(#TzP%4Z8>ZGBHIXyyhuf+Yi +zM3xX3mKikVT7r?YF(oh~1_>&LNQU; +zK`=2e4F(BdhDZTr0|WvA1povfY+(!i_~~rbp^C#yt5i7iN(PLf-J39FdDrAamk=e% +S1PFt)bqU_LN^6M%0tf&&^grJK + +delta 2776 +zcmV;}3Mci@7WEY(FoFv40s#Xsf(o|=2`Yw2hW8Bt2LYgh3aA8v3ZyWC3ZRi9JAWcz +zf~^6)AbAJ`;A0$m*A;RX;&9P-0dy)<6ic +zG=h9$G2!QdbYEt*c?gO$3`@bOmrgFTNbozB-NlAbC*A{yONXB%C_apWVt=m9^0h7* +z*?3em;(mZ;7{UgE*^=bjWp>G~J#?Y+fR&bKOal3mkO%VC^-Ez^Tk8yxwt7m@$;k^;0mt_~ybp!1yQU@#i`pO1MtTs{ +zHabcX7Ry$2vhmv`Raz3Nzo_aqaaVrklIl$iB97R)5GILb_*Bm3(tkzSOZ)b5IhLV7 +z18HncR{#Q20j`Stv^2^zY5kap#QcGe)b@%+qc}wgP6{)5*#!`fl6PU3Upn+Y_>xI? +zfsjk#HF2&lV3}zfBU)o)!zbAoc4>XEe{teOdJ`-fdj_FqS(o2cJn=r>OJ5eFGs^UA +zapCv&3$#-VW8S6m_kSVO^*h@>eY1IxY_S>As<^a_01O26Sx}H}kyWj$CxawScc*|AAAe{9 +zE+JcamabwG8GPkvRP>l1i1{nU9ta}Wl71H(N-t0As?rI_ioj9#*!5o~ENbw6tO5hG +z$96!&YHs%wueZBZZw~*KH!_B$eD!={Sx&YtHN9{DcYo_^N`ke0kAu4+P79utHa89c +z)AD9LSXCcQk>ILDAq!Cfu$AR&MFu_)?2$ppSyA%@PB`#*g44cDw0%9-HQGd1v3Py +z!ce6Hu^TKIN5~#rt1B%m&$NZYd9MrmQl4b$k2uObMpm28DcZrrFKb0Ttm4Z2?`Q(F +zY^;>9Q8MHLYey(85vpj4+l32cdPWo+D)#OH>VIitq~FY;9jCJ6a<5avCVO;E08r5D +zSG1l{Im&na{@&BN_g=`GVh&oM-8}MDDtLe6FoFd+1_>&LNQUF0tf&Ef&{<-evNXlq#YlqN^2`ojQQ9HmKs6}GRF+G2Q)*HSg$iMnU<^r9LrFn +zxi_;d5j$8#-aZkrIi>3j7q|(a0XUem=tm>Nb}nNxMG>I*-+F&f%b8U(1IS|gXKI0z +zFqNT6(Uj?AS^2AJmXzFr2W;!B{>^Vx&VLDIh>r(e)E6P|2-iR>d>%7cst +z)|fk0e>A-5)~Ixb{jf)u9d~a@$;Ue2b^hwuq!?WlOW8*!jho)y!_O^q*bU7c_&t<0|Hy@G1@YR$7(n^F&19)$qXKz?Bqhq@W8l>{Q&u<#ZCP82KH)Zf>7(T?yuy +zXGoA2<9<3(Utt;Q&~`^Cg8(aT@!^O2o{iyARMlt@BwEh=#p{5sNEwe>u@1xM!xTPf +z{cjB@R6p(a@P3Tzkch>oX42R~BYzdsH}hF&%B1a4xaXUzQeob>0h-;WoL>f`C=2-_ +z+?HS_8A~=i`NAu?^bO3bj5;Q9@Gq7~^Ezf+@(rSg07VgwuECIbZu9FRm7ybGqUAL? +zR7yl-`Mf>i#7>75pi=AqG=Igf3~}5q2<2ovXnupwoF<{75Ez +zcV`RFb)ap&F4!IxgZ}Me7xPecHIT$;Q6FA-BMHlMvro#iGlRxRNtMA?I}Nif~s +z4xB9LTy+J=1(d(NNEkKNHx!^IF!m3CTL_mzG|Lm+qD#hqIO$qkUa<6w>vOZJ&Ak)9 +zN9Gi+Vr#_!jC`(#_W~`|?DPU%e!rq@$nOpuW~Fb(C(B{$pmqr(14Jj*1voMah#X2 +zmbl}dO-0R!J+{rgTo_kufNZGxL%bD_65DP2ItQG>BBz|#;LGers8fS6-vgfP3riv2 +zIZ5_@26Y$`o!RCwn1Axwp*XLPl>P=SHk2ynIw={bF+x}_sPmTws$a&G)P=(L9xEf; +zLPH|=&mn<~cDxN6=Po497XG1E?JW*UhV{X1RCR1iD1=jyWv0E3aE>pobEv=0<_32+ +zfoWJj=tC~)VmD*yV*N{+a=kfqsTn~yI}%5e#(gjwrk&Dk34dHu2g3JU_0P{wwL5KT +zZ@2G(NB2WIg(L2M;cy}50ifkZ_}n54Y{8^Ua&N;Qj_?d(r3t?4b6YK*80jMHh03Qu +zi&_K*!^0bGY=gwLu&4S_qj}z*{LmQ_iVGA~-#u+1D@-*0F=c?J48^)^MHR#YRH$6} +zb>a!@^}Ar-RDX?L8!uaR;urhhC76Vioep{Xi+w@7ilod#-zzV7IhLo*t)6x^n*!>% +z1_9G$)o=iRWiOWc!_9H_>^;Ksn0YIJakz9$%BFxPdh@PzCrU2PF(oh~1_>&LNQUgB +z!rN`BrcJ^Ohe`m!y#xb>NQ{#(`z%T5F!2#O*G>G~9Y1B$tAF^=D7^!~(#BjZx-F{G +z^x3%g?|7?Hkd{-0YH5t*Rdo2X?|+3mcuxvN;&S>5_1eT(qT(x52zq^KY|HMES@+&E +zp!Oqh18~73Vp*Jp3(0&@a@|uNWKk>z{D%AcItdZY^Q#tZFXI%q0IEm0FKXhy*5b$9 +z+GasSZ7Fl=*a3g~>TXLBMNrC1VdF*^x+r|ZH_Gzcqm)*qrnyv-YX?aX*MDZ~tFG0` +z^Ke2l!1Q9x;ujYQwbTgiZxgrgH`#P(qDO`2T*ft8T4RjoRc83{mS8JoxEB~7#0gjx +z+tive>B*VgSOs(>1U%w4T=s!cQ1y~?fv+v$>AJGg8w`s<(0GUVEe>-f_*GXPbEwZJ +z@TMDrtzx^BDv>4R!-4YvFn`WcgvasTcH1OTNqcoV8kt$B82tUtpRiX$PQ)wkp5{t} +z)?p3fYtv6h{E7BP@YDq^^hGRwEr+;3?2}{(tSvt7&zZ^>#H`F!949k<-xpr{{;9zp +zDtV?e)Ry1e!i7Jg&*k>7dmwW#q#n;eOt8Mx%Rd2aKpl4~ym)!RCx2F~-z|>d?Q54S +zbh=;Es8wX9H~AcxB!gd`Yv{dKYv3SYZtJFuhy-=%I~N%?7_12a2`8#qO9;)}q}s|? +z6Yq8WI{r_8M%lK?@{uRJ*8bV(rwV?^+S5(8saz4Wa{@(sx!?tewL#bxkvN$jInMZ<~N077QsX0f*s0n@MRO0ggV)O{+MYL52| +zD_Qu^Iq=$v;`lIbEE}^!yO4Pu2NTKNpCM~vyDd#ZW{_f=T68I`1G!n9V|6E;0xWK$ +zMVJJi5@$HHpOZKnrm+wnGJ%P0|5h5YAJ}NwwC8lGJ&%vDG=GT=v(9PE(Uw7P +z0!+ZeJmezUaISwf0TkR2jcE8>$`w#S7f_v0R974kk%QiJp8inpuCXe~j&U$j#DPM; +zvba{UI+?eG*q-}vzr1$h?MM(Ib!)FpJS;+BY&HpTa%DiJgy~x$CJp7`XQi8 +z*lml!5T65{Op0>wuHAP*c>)PwVIyE2gb)~?eZWlbJ!p2-RLHg)RE>m|lR|}Q{=U%0 +zo}D~Q!ZtM}jTp-co>k#HE^0ZnM*G{j*Xs{zpJAwD_6*z5T?7Wi +zypIqyqWoQX1?O<$Oww!WKN@+P0NUjRx;gnk&KISm<5rUiP7k`UFoFey1_>&L +zNQU+thDZTr0|Wso1P~jF*+0)PkEs!3QR2j6R$>H#1kglS1&YtSg;OpOm6~NrtV4vPWlld2Ews(yNbZxe(4nR+$T))-e8N?d$b$9^!ypWdooRD +z6pI1Qs15?;T?5@i>UJA=nyNu0m?ps+lm98_Zo0A+t+e}RpX+!f>G3{Hg^u6fo4LT1 +z4Y{a#T+mMYnY#W{qU{X@B!6T|m%Isc9UEo8>zV^Z9L9?17w>9Ujg30PUkpbf5*il) +z&|Zg>8MV)WoRDJd#ewUABq5SACj~6S38u#ULT-rG&N*DdJ@Hn+EX<9U)cEl5v2mVi +zmqUCjZU-u2d&A^l!nNL>Tjtf +zJkzy;9b{e}lVX%pscpa}CD|T&4_lG8*YS?dpSkncWepv2e&;2HS{*4*!|BT*m2A?f +zyjVW1HUQ(_M3rpp5R3I>q#~s-)|9FwJ%rOTwxl2FMp&4tsCFbTVXO2tVoG)vz`fmN +z)R<$E#pT35KAYbTw|@bcx$u3h{1odhts-|_3YJ4Ayla(y0OOI4`C7W%+BMtMu9DR +zLN@8T_7`usWF{4ezK+d|fuB@k4tw^8R!x#XZ^&}mz29aP_raW@!^P-{vLMa|@PF|S +zhs(}tr|&S{zJE{7YU?ak8oNr`=W`fgsS4~&^0h#~(VJRT +zNzH~lq@$yZ(W^@?`c_n0MVf0+f4^>KZJcWBRpBJ1NoZM-&i&-9Xoe! +zmv9edP|3x)fnY^m)?k@H>w04+$h`_@j98wtxMb_Y2{QVtv2Vhjf7qLrz^P +zzfCU6R%@{mG9Yn6kX(&PQbCcl4jzWK;LKYtF(oh~1_>&LNQUg +zWkVjqlI}v+>hWZNZUj*Kq67$ty|isR%^-9F0tf)%!(&YV + +delta 2792 +zcmV_>MN{htcbO{qC=J&uM?~NGanbgE-J*^bff< +zUL85U4k$LojjclJ{^#hk69ix0P=6p3{W=cW@;J}jXSEPY*K)tO5KXO= +zDp34gOZf$JI>T(od;fQLTl{d}D?LMSYm|boNM-&DpOI*gNxdhZ}bdPsP-V3jIx6 +zS#YC|Y%#Qcz2$cGZXgSwA( +zp^gh0BF&;oP;t5r`vDq}MSpv(oTT?XWo$BF3HTfG#Cm-G$X#COyar;r`l_yWRsuyp +zjrLZxM$trJR(FC|;&F1_fvv +zlT~jFp~Eovc#$rZ%#NJT+P;Ef80Oaf9R{ +zOpW_P@)6@t2VYKWW}3x8$#CYa;%anc&G^~Ur2V-rd#L>n7J)~*jORUD0N#m1LiDFl +zB&?Q*64N(fqjrGx*oF|qZ|R<>da*~kLSkj=XRG<@r3LG9Z`*3FTNX%lmC5B4T~(J> +zFv-n}iKXB3?7ZeYuYc&9GS74XBxDCRdBBF|yIE$fUxbe0K(Obu;3tumH)59PWVH*+ +zz+FmMZ^+~l+V!l1r0ZO}N2<6B_PMH&?VYqs=-LS%mX1X@sp)x{beSD;A)~7{YY~TU-k$-{C;hMVpNq;mVqC$gb{2Xtz#6@FT +z{VWSY?mme#0Q8+1Z2R$5&R0^uNckWNtn&l62raaz_Rv@fJ}H`6N6&t$-qmQZi`0V~WS +z!noU8xPAZ|(OodN!Y_ylW^%s>!I$n`^*O|{`Nql$VSjtzYgo;WtVGwfOGr;9?$|xB +zcs%xxE&&}izyxcgm)2gfVyWCAT`*z4tvURt&T~Yv;4D~@cMQ$sbGeT!7+;p0p5QBw +zMU{9IVf{eaHyT}&Q{kmv1!msC>y;CP;=8GdD!=>6MDu6%gpdLzN`zEs=jdV7SuMgm +zSef9I4u8xGa&@P0{hVpaizD*w9ysr@;s~)?UPY$$=xMStm%-8_cVQq(W*E)bMfTx~ +ztiPTUhk1JJr{K03MHZ?_uNADjS{qhZS>Plq2pIDcZSe +zpdVNTFx+6=J0GuhMj`dM%6hP&L +zNQUr;S>kF`=lUV`cN+L-;%3g5Ai66u6H%n +zyfg~`$Gs>R{QVz)tROl(k}JU-jqD62a~NzC212U{n)$nAgsnGjoPsM7R6NMA=VGH` +z1j%@$TqOIpqreVYF{_P#Ld?sZIQVS;Qh)J`TkyOxjU_HwSFW=@1+yU&O+4(~e1pZW +zdrC+`8zsTaGDfQt#7I&Pa#$O{DyBOl>_Jl1(9c*lL@BH;OO#5bXtm5nX3C~*Pn69s +z(^4r6qXFwhf*ZDy)ZtW;)ENRkjc|#NpZ6iLJ2cnU$Z46(*w{@+^tC{nR=N4%9T-0{S0Vv +zuITX0>W_bbsp#~8>rIdGj%n76kYuf?>yX)bEPeHczbHA2m#H;(n|w!Q4IVX6sU98{ +zOlrpj6Q_77iXS2=oFm3wmI_q=!GG|ZxMyJfm@W36)BqdDmFEysiCoWFs0h{Aeqqmk +z8T93$tHeqtTnPI#ZNj;&P@qq&2+!E8(q%k0HF{#(jwR}m)3Lz()!)7BPi*u-*p#b3 +zrLNe1(4tB%&d^e8d{#t$ImMt?Vq-)VFbRK@T_Yiahm~7)-B&pd8gxPtU4O8w+P>aQ +zP9X72&~lV9$Qpdl3;-#jyHYb%NM)NxL<$lo(9#%8c!mweqK8`i&|Ky0)}^G8PW(W%*6#;qkrM4%*TGa!?K +zU|cE2f76znLD#xzxyn;rmw)6%EH1ek2QS*J((#_RgTyYO#?@-CqoKDk8tM{t+BZ0R +zg9e9H38hKach1c+6Xf9Da}2?$V5Rk*R98)aLVp2^8bXx7{A@Q2pHfZvEV%u|jMOGg +z|5PWJ_$G1qmwVcOOVwerb<|Tx^TT^v%SaCo(O%3gTXbk?e!y16>VF;94g#dwH|PI- +z&D1MMKVRu0{ryL$acyjbc`LtxcnT{VX0HU%g2@&XrH+ZW=-~P-Jc7{3rh)|t*!EFi!P9*YBAtW +zbu`)yVVz9dAb+fy*IJEkVq7w={{*u3gh?3@!K+(YG^T3vjiU}7w=Z08`s6Gaw5p&LNQU^P7i4fG53N5i(Gig<+?Lnz6wQE*r&6Z2;KdIR$HEXY^tyJwjg4on9 +zMJuYqtgX~N&$;(J_uQAi7vJB@&r8m4oG3IN?nn)yLF3`vP&&~_t;i!r5G^PV4~K*C +za9T7TPLqI=2dt3wb?!M|9Ta8@$m(?5~;_Tn(<8A}joBO+BcSlahN)>Sb`>t=)-(^SR2L)txY=xAE~PHoHBCf4M{bH>2S9jw`4h +zp*y-jx&|=Tq_=vX$0AY-B-pr{O3}~!a^QKw^rZP3r!8E~<4%RzRnXkH>9XmKSZbP{ +zaaJ*AU$QA*L~%RS_EQGj1G`WJ7DmgunlvxDG={jJ?-epJse!y@ZR4+bx9Q?#sdYwy +z(7k9q)PNjgxszN|6iPwUknCR*%y^Qb?DE%DYvjQ3 +z;KupDH-(s?Jv+im0i-zOqS_h7X4{%q6B3|6&!@UWm^wW2r4xF|mkdExn4~66{`CzT4_Ik**^1`!x}fTzV|8m{TK6!0MWB(ZeY4tK0dLjcMvPD +z8=e*&*4XH*4v{Q1h2g%3Fjv;yT>}EoVd?9-HI&GSk%Pt~SySOzU&y5j-YW|H(ymTw +z1G_2NB0UR=mJj{oPOpv^O!d8MXu(!8&w(wML`8o+#dIfwKC>RJ9>RAeghupBEai$e +zDAKej36GGn{2TIG%!~-Q_PI^YR3oQST)AK%A#{^(z(2e>rf&a3&by;mOTa8+PRRHa +z-^wA_U+>r+QFr5+>p5s|pY~>EwSm#>qOt)Nqf@6CP_M$KA*G}bcej!gwJ3*zQPO)Q +zcE!oFOtiDpne0?jxphVJByH8c!ib0&g7|*$$1HXsrD_TFzB +zrG_#(dx(zjH@7`{%)6&?2CWGV#oyFiC}F9*)?V`SkA$n6*urPvef#ZVsuY@aE~mwi +zfLZVOxpYs34^{3ih{Iwt3J%MBwsDN@US3n{4IdSbxOu_vBq_M10eI@=J1FX`4=u}h +z7b!WZmn^TKx7NOwvR(EQJ?-AwVb|>(+HxQ(@}fss)htL6&IySIxFV|d4-b9Yvz_(c +zePf1g3;EKwCW`Pgu}r&Nwiw5>4p0$1R|F@Ad*9EUAwqU`H_$DzHS;+yy>Dy~SPv!$ +zmkq}>$Zz^V(#udwpnHpk)p-ziT_zvT@iwpeM(IX2bbCL*f55n1LQdori~D(0GUh8Zi4OfiR-)p|AgM +zGN5_DFy>1zgV-~8AVb3azHBo_up_yK-RX|#8f(whe3lu~8= +z>Rlx#>}5YmM^rEltM^1$Xx)9`wo{qb10o*m>Xy`;bHRtlM} +zZ;NN)^q}BNTvndhQ?@$yS|;Tr^u4BaFvdS%HZ>EM%wHSflx2KCj%7vqE=Pto+rN*9 +z21WA>{xOJ{T7d8o7MV7X>L|Ta>(!)@?25=6nd{r1Bn1O;w^^R6q@iNUl@~<5k`Grt +zt4cy_*okVY%WdtrNQM1KuBWpb4Qesv1*;K^T|9@TnSs3eA(Cz^54=Z((46M|;%oLh +zsGs_@Lgj^K@yCR&!=s>ti(hn0WJ!%oQvB59o(Pc&NTW!ES)k-IY(7i~q|CgZoa^hR +zQpq1!Sdc(15I4h>i5jn(4Ky68x6iUWOuL_jt-H+BCnoZ@!V6GiN0MNg=y}@`g*u-V +zC)cuzj#&nkk&<;b>Wyz$fnuR;6uI%S@#E=E`^qe-8I#gnaKxnOFO0(}fzq(wH~hi+ +zdekEzl#@Io`zB#+ajLT>%~{Ny&d-aFH~-)&gKw0$UWsSsw6{_YrsbR_+(F>MMOwP2 +zv?S-H0J1o)Pna!}jc7d%4wbSOX;bOs>ThE@)4%djgrNvZ>mhajjy`1?f&q|iuLRhg +zehh18kl}yP!G|X@Gm`KYlGDk1(~HZc=c<6J@dww{aY6Qrty97R-B72@4@2yDEvsVN +zO4TxnDDsD0ykJu8oaM>2W3)f`ZQz-jz(%KYh03WnD*OU=$~!l(X{Fk9?CXlr$jMxw +z&4YBg{$w3lr2MG!+jmk%$X#1C8hxEuGbq80I?zu!86*YbN3dx1@2fmAim6hvO+bIU +z#eRn3Ab^rg46S~M7s6vR<;i88WSP<^qe8v(HjtYp^i7<5*IA5%6fE#3@S1XdAl86m +zcpPdhk!Is}%eVyhaMQ}v|MGKVO_?U$M<;JZw1H8T)I+1KkgCQz*|>4xv5+eESa~~w +zV(ssuMzr>CN1hjN$@^xrtY35-fSQH~hi%0jk0IU8KN60+SAoZC8d-GF!Wx7^TelGeO~Jnmk|pA+8J`#v2b8;L#Ri&lNt +zFZi?Wu)s7TQiBF!^rGT_I1$NYEv&1L-zUwHU&}h&7dNZD3|-tI&0n9m0L_9i2rN6l +zDRGS|+@7L67nFoFvS0s#Xsf(p+D2`Yw2hW8Bt2LYgh3cv({3cN6a3b>IXJAc~$ +z04;L?h2;VQ2mpYB1u#k{e>HFuQb-0@)w8+8*DP{D$KG=;=xRl2uvKUP-SRRE%$NKP +z_D;2NCAhd^?|QhcbJ5E7c`-26TMzdlG-H?6^IBeoE0#e|QM2rw&&DIM3C+3&2a0ll +zpPL`9ji3aw?(A~Q_bH5QAB`HfT~I=G`cK>^k-~8=RAs!fh8npjTx1 +zio`$Z>ZF=$DSVbD4xi;!NC!?`eIqFD35= +zQc_8A~;(#IIWCvOKf`P&2)Js($WT +z1z-??Ow@SVupz2ChgP2^Y=0o#*~e?*$0TAcDclj?IADVt8o^gntLJZBu=o +zlRp{i%IZDaPfUE-$LP%)Ua~T(Bdt0G=DGbexi&hghHP;^^f<}zRlnJ3GgV60GtOPk +zcib>&Ab~e+Z6==732Fcs!<-3gh>(3UIWk_h>u`vv-;vJvM|KhjTN9G*@n5_xbZnmMK +zlqp0G!V*18sL0-95F*8PQnOybN@p#c%kb*&^aa55JSKbSAd@qO=Ht +z422L +zEQT%EbQpx1)#*Gv)47 +z!L`_0ZJB+>X&W4?m4Xpk&GUR45OCpS-Ac@br?bG$K5WOH27l@cvz6M|^4ikdCcj~? +z@A&ePKz3o=>_;pjNUjLI{a*i~A2Cm`&wy=Wnk}HZ!)%{@qd4Cdgv0g1#?}yCqq93|4$^$^+_&k +zJa~z}zH{53ynke+y3lMnjQq2xp0Aelu-HmWXLFfn2Zo%7n87xsG^uG}b2CZ*u1s9Z +zdy6l*(2{|l#uH(Fg~MQyrygWvH^>pmCkM|1n_(Oa%d6l_c*y)EJe|rcT48Q$4-q9{ +zd;$`4t5f-+&fM5}8vs44&d`E*VzZ!Kx~GhFv9KFoMt^WQmMpIlho1dt%_BO(+`2Lp +zatNwfJ+p4vZMjP*m8(};v7%^J>Z;rDPy{%kK4LhfuLy_D30LYt***zyVP-NnNeD<@ +zGY~g=yXsBrn_X=!tmk!)LM6?HS%;t(HMJ%Q_8-enJgcrn_sO6=M%6GmrDCuouDW~1p-LREA&0BHSeEKQnj3ME3_){Ru4kMWs9nx6eJ4`1vHrOoBO6WNZGR{?^ +zEfRoM=%swpDejYTaEFI0cJp^Ht@L%c+@lQy^nXs75zrK4$%sP!y)m<*xW9H%@fLjRzS +zFoFd+1_>&LNQUeJ7Gnm8p68cPkyaMp;ydm +z;5`lZ-8TBOTClg{8b2gEfR$AC$(l*<$HmjXkv +zk2XU*+fTwXqcsMYaZ3q-p;PK((PrSVUOgD!_f+ +zxEwhbf?;sTV9;{2qj=e+thVm4&q+rqRZvI3E$OXDELB<0qt8X4|WJgR& +zA;mly>0fgus?*HuYZkDa8&PzLYY`{)VN|6AD5DVz9hPB0H|cXeKd~iK$$60*1@6KW +z6781`Wt^~gq(V@LHV`!^8UF^$=qzP9Z~St~brXD2cffcLQ)%SW+3k{*m46rbsM@(z +zVmdvB5fH3}m=m^afNN7hu#6Tv465|&pl|0QVo8cOgDzsf96G6OAIc1>JH)_kiJ%CKS4>>XVItK +z0df&%Ir0A#%dzm{a-{xL-+y}K1k-jf%0*=Wi*tj00J0}10?%6)ypUZJ9ksJA^uCwA +zU5oo_6hE*n7H%zwo}j{S>kkC#VGo5P%uaH-y; +z9xeJ!zLp4E-us08h0F``IjL9Q%D-E<6S*Z@f^7;~n+PU-j1vc-W`Anul8%C=xSb5u +z7r0>5j^Of_V(=`5Jkb~jw{)rQzSz?lmA1B5fIF^AldA0&srn(q6$tx(<>kN35n4cE +z?Y`#QJY`_$YGKyHz0lTxyY@^*MkI>@K_P<$huaWnmtRl$s=QCNW>Q)%O~1b7x8OZa>s!LI}xafM3IiiEeV1X6v0v^m&_bRB7S;B9{kMdqBpB#o;WHIcK +zXZti{8yqh{hTB(4Q&s{4ZNd91F&>cQH%{n1i;7|BuXezD%73Buu9D%H$?>u=EQI*3@^(1e84N*6QZYbr+~cRYKueVXW#rd?}8~s6XVg0MS^}l +z>j!&zJjkZ0C0Bijh>6a2w@ocN@A@brXHXZn+AJ3kASY`zaQm-BZ>L{LVlV^$8R&lo +z$7k~Gs8nAN#(&H;;d!1sK~d&LNQUXqJJ21=NG&!mOU3kJ +zFflM8FbM_)D-Ht!8U+9Z6sSLOY_+{}*ZArxG2W!WZkmtKW&{Xzdz-Lrn>2+20tf&? +Cp*q$8 + +diff --git a/src/tests/pkinit-certs/user.pem b/src/tests/pkinit-certs/user.pem +index 182ea599ac..7493de52c1 100644 +--- a/src/tests/pkinit-certs/user.pem ++++ b/src/tests/pkinit-certs/user.pem +@@ -3,26 +3,26 @@ MIIE0zCCA7ugAwIBAgIBAzANBgkqhkiG9w0BAQsFADCBpzELMAkGA1UEBhMCVVMx + FjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxEjAQBgNVBAcMCUNhbWJyaWRnZTEMMAoG + A1UECgwDTUlUMSkwJwYDVQQLDCBJbnNlY3VyZSBQS0lOSVQgS2VyYmVyb3MgdGVz + dCBDQTEzMDEGA1UEAwwqcGtpbml0IHRlc3Qgc3VpdGUgQ0E7IGRvIG5vdCB1c2Ug +-b3RoZXJ3aXNlMB4XDTIxMTAwODIxMTEzMFoXDTMyMDkyMDIxMTEzMFowSjELMAkG ++b3RoZXJ3aXNlMB4XDTI0MDIxNTA0NTkwN1oXDTM1MDEyODA0NTkwN1owSjELMAkG + A1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxFDASBgNVBAoMC0tSQlRF + U1QuQ09NMQ0wCwYDVQQDDAR1c2VyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB +-CgKCAQEAz6VXmJpVq2zTIEU3gUF7pui+Wg17d3QX2oy6EqqUQK/pwWtrvmBIaYcn +-Pq0ZMrzMhNTuyeLjb1rNNkL0hCdS3/aVbx1bOlkPVPlW3UNi9gWpXOOE1/N4QMrz +-yKAQ1/Npf9xjY/vpqsmvRx7AZpq7Nq7HyF5hbUKMHFaaTqRarhoP7mOCByG8F44Y +-QTY2RXcw9te63x+77c3O64gbtnSKXBC/4pS9DxBBv1ULB2wOH8RGxDiWgL0/iO25 +-YImKQgTvwbENw4ygLV+0m1b+YEJLaIIeKleunYEMMkzIfFmMemXRWgNHuShYa0Pe +-yiwTBSRdW9Yi4qzjfaHZ1dD67wdoGwIDAQABo4IBZDCCAWAwHQYDVR0OBBYEFPQX +-pfvVBF+0OJJ41JjduSzecrQjMIHUBgNVHSMEgcwwgcmAFPQXpfvVBF+0OJJ41Jjd +-uSzecrQjoYGtpIGqMIGnMQswCQYDVQQGEwJVUzEWMBQGA1UECAwNTWFzc2FjaHVz ++CgKCAQEAm/1JtzZBJsdadmOTnkl94508ZSyYo5xP83sLT/SY5Cri1QKaFrue2kGg ++gl1QEOExBrIbdAeu5BftqiC07HyGgugtRo0qDHMRnQ4tsNExzYz69MOkFE4hMYjU ++o+9C22GVLihyoq+oELN7ro30u5/MCO7rULIp0HekLKQ+uANVVJx+xnW3bMJsrRIX ++Zx9kB0jIIugYt5D3n80vdIjHQJf2BTjsBWYGRJD4sTElGFtRIiD6m4puonRdUgtH ++UHZ7OCKTY5sU0PSGxFRLi/ykqcgPPQddHYCd5MRJj5q2NvPN6UYDbMfzqni0uDQ9 ++qdDjHj6CmRCHNKvkKaLdBfhdqFKuZQIDAQABo4IBZDCCAWAwHQYDVR0OBBYEFJI/ +++nOV5fnNVxn2GkjkYbZ5D6mqMIHUBgNVHSMEgcwwgcmAFJI/+nOV5fnNVxn2Gkjk ++YbZ5D6mqoYGtpIGqMIGnMQswCQYDVQQGEwJVUzEWMBQGA1UECAwNTWFzc2FjaHVz + ZXR0czESMBAGA1UEBwwJQ2FtYnJpZGdlMQwwCgYDVQQKDANNSVQxKTAnBgNVBAsM + IEluc2VjdXJlIFBLSU5JVCBLZXJiZXJvcyB0ZXN0IENBMTMwMQYDVQQDDCpwa2lu + aXQgdGVzdCBzdWl0ZSBDQTsgZG8gbm90IHVzZSBvdGhlcndpc2WCAQEwCwYDVR0P + BAQDAgPoMAwGA1UdEwEB/wQCMAAwOQYDVR0RBDIwMKAuBgYrBgEFAgKgJDAioA0b + C0tSQlRFU1QuQ09NoREwD6ADAgEBoQgwBhsEdXNlcjASBgNVHSUECzAJBgcrBgEF +-AgMEMA0GCSqGSIb3DQEBCwUAA4IBAQAOBeCDK6Eg6Cu8TZ7xeAw2AbTpaW04nNSV +-Fmm0aIskMgLl2a5KEmalG7rnArRXv5IZVYFjJ6X0MzjOx+BgaGUCvN8jz1fuO3Hp +-iGhxPDzKjFMWJeY/z5bQRueSI6RCC8DzH8iPdlPUQ8ZhnukhY1Vt47wqraf197uT +-0XP21qQr1uRY+ZcLSBKZuKe9ZP3ijh57MOLvYDdAFxVp77JLznpk+oU18ujAtYgZ +-7naIGYtSQRkIi970jk82hSpc9B/KN8UcDuo+DQHWPQaDf39s30qoxooZBoue5ipp +-LQHuVaX5Hoi83cWbsVluce/JsW8GfbuC8+8CosAmzJly183f8++9 ++AgMEMA0GCSqGSIb3DQEBCwUAA4IBAQBRWsxPb9miF9xf8rEIfVko0qBy8doEJsPE ++IVD9Jz/Ml/TBZRLbi1b94l15Fto/Z6XKf8jrnBs4krf6tU2D5PUZXZYZ6tr/2kkY ++IpmoOkEoQX8gtcZfaq2OJzsKHnAJT159EVydyYahHU66i4aNvho74oAafrVTyk8B ++PHCHFs0MUct8DoNwrbnfH0cjqEdVOmjjvBN0yA+RxOa543XnQqkSmCuIJKoD6pUa ++07rE372iERgIjDnzCogiEo9cCBBqDfgsbr0ah1QbWJTJvnsFuxT43tBNurRjNPoX ++Jj6xAzhQLCuvqtKtWlAUOHut18YbVGXVT+3tm7+C6iA44JvMl9m1 + -----END CERTIFICATE----- +diff --git a/src/tests/t_pkinit.py b/src/tests/t_pkinit.py +index 4435746429..91d4630a0a 100755 +--- a/src/tests/t_pkinit.py ++++ b/src/tests/t_pkinit.py +@@ -7,8 +7,10 @@ if not pkinit_enabled: + + # Construct a krb5.conf fragment configuring pkinit. + user_pem = os.path.join(pkinit_certs, 'user.pem') ++ecuser_pem = os.path.join(pkinit_certs, 'ecuser.pem') + privkey_pem = os.path.join(pkinit_certs, 'privkey.pem') + privkey_enc_pem = os.path.join(pkinit_certs, 'privkey-enc.pem') ++privkey_ec_pem = os.path.join(pkinit_certs, 'eckey.pem') + user_p12 = os.path.join(pkinit_certs, 'user.p12') + user_enc_p12 = os.path.join(pkinit_certs, 'user-enc.p12') + user_upn_p12 = os.path.join(pkinit_certs, 'user-upn.p12') +@@ -42,6 +44,7 @@ alias_kdc_conf = {'realms': {'$realm': { + + file_identity = 'FILE:%s,%s' % (user_pem, privkey_pem) + file_enc_identity = 'FILE:%s,%s' % (user_pem, privkey_enc_pem) ++ec_identity = 'FILE:%s,%s' % (ecuser_pem, privkey_ec_pem) + dir_identity = 'DIR:%s' % path + dir_enc_identity = 'DIR:%s' % path_enc + dir_file_identity = 'FILE:%s,%s' % (os.path.join(path, 'user.crt'), +@@ -177,6 +180,11 @@ for g in ('4096', 'P-256', 'P-384', 'P-521'): + realm.pkinit(realm.user_princ, expected_trace=('PKINIT using ' + g,), + env=group_env) + ++# Test with an EC client cert. ++mark('EC client cert') ++realm.kinit(realm.user_princ, ++ flags=['-X', 'X509_user_identity=%s' % ec_identity]) ++ + # Try using multiple configured pkinit_identities, to make sure we + # fall back to the second one when the first one cannot be read. + id_conf = {'realms': {'$realm': {'pkinit_identities': [file_identity + 'X', +@@ -446,4 +454,16 @@ realm.run(['./responder', '-X', p11_attr, + realm.klist(realm.user_princ) + realm.run([kvno, realm.host_princ]) + ++mark('PKCS11 identity, EC client cert') ++shutil.rmtree(softhsm2_tokens) ++os.mkdir(softhsm2_tokens) ++realm.run(tool_cmd + ['--init-token', '--label', 'user', ++ '--so-pin', 'sopin', '--init-pin', '--pin', 'userpin']) ++realm.run(tool_cmd + ['-w', ecuser_pem, '-y', 'cert']) ++realm.run(tool_cmd + ['-w', privkey_ec_pem, '-y', 'privkey', ++ '-l', '--pin', 'userpin']) ++realm.kinit(realm.user_princ, flags=['-X', p11_attr], password='userpin') ++realm.klist(realm.user_princ) ++realm.run([kvno, realm.host_princ]) ++ + success('PKINIT tests') +-- +2.47.1 + diff --git a/0032-Improve-PKCS11-error-reporting-in-PKINIT.patch b/0032-Improve-PKCS11-error-reporting-in-PKINIT.patch new file mode 100644 index 0000000..b529921 --- /dev/null +++ b/0032-Improve-PKCS11-error-reporting-in-PKINIT.patch @@ -0,0 +1,599 @@ +From e43c05e7b0b93401dd68fc3ec3186c3a455b04ea Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 23 Feb 2024 13:51:26 -0500 +Subject: [PATCH] Improve PKCS11 error reporting in PKINIT + +Create a helper p11err() to set extended error message for failed +PKCS11 operations, and use it instead of pkiDebug() and pkcs11error(). + +ticket: 9113 (new) +(cherry picked from commit 98afb314d13939cbee19c69885dcb655db8460da) +--- + .../preauth/pkinit/pkinit_crypto_openssl.c | 262 ++++++++++-------- + src/plugins/preauth/pkinit/pkinit_trace.h | 9 - + 2 files changed, 142 insertions(+), 129 deletions(-) + +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 4accfc2664..402bf1b9b3 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -161,9 +161,11 @@ static krb5_error_code pkinit_create_sequence_of_principal_identifiers + int type, krb5_pa_data ***e_data_out); + + #ifndef WITHOUT_PKCS11 +-static krb5_error_code pkinit_find_private_key +-(pkinit_identity_crypto_context, CK_ATTRIBUTE_TYPE usage, +- CK_OBJECT_HANDLE *objp); ++static krb5_error_code ++pkinit_find_private_key(krb5_context context, ++ pkinit_identity_crypto_context id_cryptoctx, ++ CK_ATTRIBUTE_TYPE usage, ++ CK_OBJECT_HANDLE *objp); + static krb5_error_code pkinit_login + (krb5_context context, pkinit_identity_crypto_context id_cryptoctx, + CK_TOKEN_INFO *tip, const char *password); +@@ -180,6 +182,8 @@ static krb5_error_code pkinit_sign_data_pkcs11 + (krb5_context context, pkinit_identity_crypto_context id_cryptoctx, + unsigned char *data, unsigned int data_len, + unsigned char **sig, unsigned int *sig_len); ++ ++static krb5_error_code p11err(krb5_context context, CK_RV rv, const char *op); + #endif /* WITHOUT_PKCS11 */ + + static krb5_error_code pkinit_sign_data_fs +@@ -197,9 +201,6 @@ create_krb5_invalidCertificates(krb5_context context, + static krb5_error_code + create_identifiers_from_stack(STACK_OF(X509) *sk, + krb5_external_principal_identifier *** ids); +-static const char * +-pkcs11err(int err); +- + + #if OPENSSL_VERSION_NUMBER < 0x10100000L + +@@ -944,8 +945,9 @@ cleanup: + + #endif /* OPENSSL_VERSION_NUMBER < 0x30000000L */ + ++#ifndef WITHOUT_PKC11 + static struct pkcs11_errstrings { +- short code; ++ CK_RV code; + char *text; + } pkcs11_errstrings[] = { + { 0x0, "ok" }, +@@ -1035,6 +1037,7 @@ static struct pkcs11_errstrings { + { 0x200, "function rejected" }, + { -1, NULL } + }; ++#endif + + MAKE_INIT_FUNCTION(pkinit_openssl_init); + +@@ -1563,6 +1566,8 @@ pkinit_fini_pkcs11(pkinit_identity_crypto_context ctx) + free(ctx->token_label); + free(ctx->cert_id); + free(ctx->cert_label); ++ ctx->p11_module_name = ctx->token_label = ctx->cert_label = NULL; ++ ctx->cert_id = NULL; + #endif + } + +@@ -3344,48 +3349,53 @@ pkinit_pkcs7type2oid(pkinit_plg_crypto_context cryptoctx, int pkcs7_type) + } + + #ifndef WITHOUT_PKCS11 +-static struct plugin_file_handle * ++static krb5_error_code + load_pkcs11_module(krb5_context context, const char *modname, +- CK_FUNCTION_LIST_PTR_PTR p11p) ++ struct plugin_file_handle **handle_out, ++ CK_FUNCTION_LIST_PTR_PTR p11_out) + { + struct plugin_file_handle *handle = NULL; +- CK_RV (*getflist)(CK_FUNCTION_LIST_PTR_PTR); ++ CK_RV rv, (*getflist)(CK_FUNCTION_LIST_PTR_PTR); + struct errinfo einfo = EMPTY_ERRINFO; +- const char *errmsg = NULL; ++ const char *errmsg = NULL, *failure; + void (*sym)(void); + long err; +- CK_RV rv; + + TRACE_PKINIT_PKCS11_OPEN(context, modname); + err = krb5int_open_plugin(modname, &handle, &einfo); + if (err) { +- errmsg = k5_get_error(&einfo, err); +- TRACE_PKINIT_PKCS11_OPEN_FAILED(context, errmsg); ++ failure = _("Cannot load PKCS11 module"); + goto error; + } + + err = krb5int_get_plugin_func(handle, "C_GetFunctionList", &sym, &einfo); + if (err) { +- errmsg = k5_get_error(&einfo, err); +- TRACE_PKINIT_PKCS11_GETSYM_FAILED(context, errmsg); ++ failure = _("Cannot find C_GetFunctionList in PKCS11 module"); + goto error; + } + + getflist = (CK_RV (*)(CK_FUNCTION_LIST_PTR_PTR))sym; +- rv = (*getflist)(p11p); ++ rv = (*getflist)(p11_out); + if (rv != CKR_OK) { +- TRACE_PKINIT_PKCS11_GETFLIST_FAILED(context, pkcs11err(rv)); ++ failure = _("Cannot retrieve function list in PKCS11 module"); + goto error; + } + +- return handle; ++ *handle_out = handle; ++ return 0; + + error: +- k5_free_error(&einfo, errmsg); ++ if (err) { ++ errmsg = k5_get_error(&einfo, err); ++ k5_setmsg(context, err, _("%s: %s"), failure, errmsg); ++ } else { ++ err = KRB5KDC_ERR_PREAUTH_FAILED; ++ k5_setmsg(context, err, "%s", failure); ++ } + k5_clear_error(&einfo); + if (handle != NULL) + krb5int_close_plugin(handle); +- return NULL; ++ return err; + } + + static krb5_error_code +@@ -3393,12 +3403,13 @@ pkinit_login(krb5_context context, + pkinit_identity_crypto_context id_cryptoctx, + CK_TOKEN_INFO *tip, const char *password) + { ++ krb5_error_code ret = 0; ++ CK_RV rv; + krb5_data rdat; + char *prompt; + const char *warning; + krb5_prompt kprompt; + krb5_prompt_type prompt_type; +- int r = 0; + + if (tip->flags & CKF_PROTECTED_AUTHENTICATION_PATH) { + rdat.data = NULL; +@@ -3407,7 +3418,7 @@ pkinit_login(krb5_context context, + rdat.data = strdup(password); + rdat.length = strlen(password); + } else if (id_cryptoctx->prompter == NULL) { +- r = KRB5_LIBOS_CANTREADPWD; ++ ret = KRB5_LIBOS_CANTREADPWD; + rdat.data = NULL; + } else { + if (tip->flags & CKF_USER_PIN_LOCKED) +@@ -3431,31 +3442,28 @@ pkinit_login(krb5_context context, + + /* PROMPTER_INVOCATION */ + k5int_set_prompt_types(context, &prompt_type); +- r = (*id_cryptoctx->prompter)(context, id_cryptoctx->prompter_data, +- NULL, NULL, 1, &kprompt); ++ ret = (*id_cryptoctx->prompter)(context, id_cryptoctx->prompter_data, ++ NULL, NULL, 1, &kprompt); + k5int_set_prompt_types(context, 0); + free(prompt); + } + +- if (r == 0) { +- r = id_cryptoctx->p11->C_Login(id_cryptoctx->session, CKU_USER, +- (u_char *) rdat.data, rdat.length); +- +- if (r != CKR_OK) { +- TRACE_PKINIT_PKCS11_LOGIN_FAILED(context, pkcs11err(r)); +- r = KRB5KDC_ERR_PREAUTH_FAILED; +- } ++ if (!ret) { ++ rv = id_cryptoctx->p11->C_Login(id_cryptoctx->session, CKU_USER, ++ (uint8_t *)rdat.data, rdat.length); ++ if (rv != CKR_OK) ++ ret = p11err(context, rv, "C_Login"); + } + free(rdat.data); + +- return r; ++ return ret; + } + + static krb5_error_code + pkinit_open_session(krb5_context context, + pkinit_identity_crypto_context cctx) + { +- CK_ULONG i, pret; ++ CK_ULONG i, rv; + unsigned char *cp; + size_t label_len; + CK_ULONG count = 0; +@@ -3469,30 +3477,35 @@ pkinit_open_session(krb5_context context, + return 0; /* session already open */ + + /* Load module */ +- cctx->p11_module = load_pkcs11_module(context, cctx->p11_module_name, +- &cctx->p11); +- if (cctx->p11_module == NULL) +- return KRB5KDC_ERR_PREAUTH_FAILED; ++ ret = load_pkcs11_module(context, cctx->p11_module_name, &cctx->p11_module, ++ &cctx->p11); ++ if (ret) ++ goto cleanup; + + /* Init */ +- pret = cctx->p11->C_Initialize(NULL); +- if (pret != CKR_OK) { +- pkiDebug("C_Initialize: %s\n", pkcs11err(pret)); +- return KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = cctx->p11->C_Initialize(NULL); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_Initialize"); ++ goto cleanup; + } + + /* Get the list of available slots */ +- if (cctx->p11->C_GetSlotList(TRUE, NULL, &count) != CKR_OK) +- return KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = cctx->p11->C_GetSlotList(TRUE, NULL, &count); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_GetSlotList"); ++ goto cleanup; ++ } + if (count == 0) { + TRACE_PKINIT_PKCS11_NO_TOKEN(context); +- return KRB5KDC_ERR_PREAUTH_FAILED; ++ ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; + } +- slotlist = calloc(count, sizeof(CK_SLOT_ID)); ++ slotlist = k5calloc(count, sizeof(CK_SLOT_ID), &ret); + if (slotlist == NULL) +- return ENOMEM; +- if (cctx->p11->C_GetSlotList(TRUE, slotlist, &count) != CKR_OK) { +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ goto cleanup; ++ rv = cctx->p11->C_GetSlotList(TRUE, slotlist, &count); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_GetSlotList"); + goto cleanup; + } + +@@ -3503,19 +3516,17 @@ pkinit_open_session(krb5_context context, + continue; + + /* Open session */ +- pret = cctx->p11->C_OpenSession(slotlist[i], CKF_SERIAL_SESSION, +- NULL, NULL, &cctx->session); +- if (pret != CKR_OK) { +- pkiDebug("C_OpenSession: %s\n", pkcs11err(pret)); +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = cctx->p11->C_OpenSession(slotlist[i], CKF_SERIAL_SESSION, ++ NULL, NULL, &cctx->session); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_OpenSession"); + goto cleanup; + } + + /* Get token info */ +- pret = cctx->p11->C_GetTokenInfo(slotlist[i], &tinfo); +- if (pret != CKR_OK) { +- pkiDebug("C_GetTokenInfo: %s\n", pkcs11err(pret)); +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = cctx->p11->C_GetTokenInfo(slotlist[i], &tinfo); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_GetTokenInfo"); + goto cleanup; + } + +@@ -3577,6 +3588,10 @@ pkinit_open_session(krb5_context context, + + ret = 0; + cleanup: ++ /* On error, finalize the PKCS11 fields to ensure that we don't mistakenly ++ * short-circuit with success on the next call. */ ++ if (ret) ++ pkinit_fini_pkcs11(cctx); + free(slotlist); + free(p11name); + return ret; +@@ -3598,16 +3613,17 @@ cleanup: + * If there are more than one, we just take the first one. + */ + +-krb5_error_code +-pkinit_find_private_key(pkinit_identity_crypto_context id_cryptoctx, ++static krb5_error_code ++pkinit_find_private_key(krb5_context context, ++ pkinit_identity_crypto_context id_cryptoctx, + CK_ATTRIBUTE_TYPE usage, + CK_OBJECT_HANDLE *objp) + { + CK_OBJECT_CLASS cls; + CK_ATTRIBUTE attrs[4]; + CK_ULONG count; ++ CK_RV rv; + unsigned int nattrs = 0; +- int r; + #ifdef PKINIT_USE_KEY_USAGE + CK_BBOOL true_false; + #endif +@@ -3637,18 +3653,21 @@ pkinit_find_private_key(pkinit_identity_crypto_context id_cryptoctx, + attrs[nattrs].ulValueLen = id_cryptoctx->cert_id_len; + nattrs++; + +- r = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs, nattrs); +- if (r != CKR_OK) { +- pkiDebug("krb5_pkinit_sign_data: C_FindObjectsInit: %s\n", +- pkcs11err(r)); +- return KRB5KDC_ERR_PREAUTH_FAILED; +- } ++ rv = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs, ++ nattrs); ++ if (rv != CKR_OK) ++ return p11err(context, rv, _("C_FindObjectsInit")); + +- r = id_cryptoctx->p11->C_FindObjects(id_cryptoctx->session, objp, 1, &count); ++ rv = id_cryptoctx->p11->C_FindObjects(id_cryptoctx->session, objp, 1, ++ &count); + id_cryptoctx->p11->C_FindObjectsFinal(id_cryptoctx->session); +- pkiDebug("found %d private keys (%s)\n", (int)count, pkcs11err(r)); +- if (r != CKR_OK || count < 1) ++ if (rv != CKR_OK) ++ return p11err(context, rv, _("C_FindObjects")); ++ if (count < 1) { ++ k5_setmsg(context, KRB5KDC_ERR_PREAUTH_FAILED, ++ _("Found no private keys in PKCS11 token")); + return KRB5KDC_ERR_PREAUTH_FAILED; ++ } + return 0; + } + #endif +@@ -3796,34 +3815,32 @@ pkinit_sign_data_pkcs11(krb5_context context, + CK_FUNCTION_LIST_PTR p11; + CK_ATTRIBUTE attr; + CK_KEY_TYPE keytype; ++ CK_RV rv; + EVP_MD_CTX *ctx; + const EVP_MD *md = EVP_sha256(); + unsigned int mdlen; + uint8_t mdbuf[EVP_MAX_MD_SIZE], *dinfo = NULL, *sigbuf = NULL, *input; + size_t dinfo_len, input_len; +- int r; + + *sig = NULL; + *sig_len = 0; + +- if (pkinit_open_session(context, id_cryptoctx)) { +- pkiDebug("can't open pkcs11 session\n"); +- return KRB5KDC_ERR_PREAUTH_FAILED; +- } ++ ret = pkinit_open_session(context, id_cryptoctx); ++ if (ret) ++ return ret; + p11 = id_cryptoctx->p11; + session = id_cryptoctx->session; + +- ret = pkinit_find_private_key(id_cryptoctx, CKA_SIGN, &obj); ++ ret = pkinit_find_private_key(context, id_cryptoctx, CKA_SIGN, &obj); + if (ret) + return ret; + + attr.type = CKA_KEY_TYPE; + attr.pValue = &keytype; + attr.ulValueLen = sizeof(keytype); +- r = p11->C_GetAttributeValue(session, obj, &attr, 1); +- if (r) { +- pkiDebug("C_GetAttributeValue: %s\n", pkcs11err(r)); +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = p11->C_GetAttributeValue(session, obj, &attr, 1); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_GetAttributeValue"); + goto cleanup; + } + +@@ -3865,10 +3882,9 @@ pkinit_sign_data_pkcs11(krb5_context context, + mech.pParameter = NULL; + mech.ulParameterLen = 0; + +- r = p11->C_SignInit(session, &mech, obj); +- if (r != CKR_OK) { +- pkiDebug("C_SignInit: %s\n", pkcs11err(r)); +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = p11->C_SignInit(session, &mech, obj); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_SignInit"); + goto cleanup; + } + +@@ -3881,18 +3897,17 @@ pkinit_sign_data_pkcs11(krb5_context context, + if (sigbuf == NULL) + goto cleanup; + +- r = p11->C_Sign(session, input, input_len, sigbuf, &len); +- if (r == CKR_BUFFER_TOO_SMALL || (r == CKR_OK && len >= PK_SIGLEN_GUESS)) { ++ rv = p11->C_Sign(session, input, input_len, sigbuf, &len); ++ if (rv == CKR_BUFFER_TOO_SMALL || ++ (rv == CKR_OK && len >= PK_SIGLEN_GUESS)) { + free(sigbuf); +- pkiDebug("C_Sign realloc %d\n", (int) len); + sigbuf = k5alloc(len, &ret); + if (sigbuf == NULL) + goto cleanup; +- r = p11->C_Sign(session, input, input_len, sigbuf, &len); ++ rv = p11->C_Sign(session, input, input_len, sigbuf, &len); + } +- if (r != CKR_OK) { +- pkiDebug("C_Sign: %s\n", pkcs11err(r)); +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_Sign"); + goto cleanup; + } + +@@ -4348,13 +4363,14 @@ reassemble_pkcs11_name(pkinit_identity_opts *idopts) + } + + static krb5_error_code +-load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session, +- pkinit_identity_opts *idopts, pkinit_cred_info *cred_out) ++load_one_cert(krb5_context context, CK_FUNCTION_LIST_PTR p11, ++ CK_SESSION_HANDLE session, pkinit_identity_opts *idopts, ++ pkinit_cred_info *cred_out) + { + krb5_error_code ret; + CK_ATTRIBUTE attrs[2]; + CK_BYTE_PTR cert = NULL, cert_id = NULL; +- CK_RV pret; ++ CK_RV rv; + const unsigned char *cp; + CK_OBJECT_HANDLE obj; + CK_ULONG count; +@@ -4364,8 +4380,8 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session, + *cred_out = NULL; + + /* Look for X.509 cert. */ +- pret = p11->C_FindObjects(session, &obj, 1, &count); +- if (pret != CKR_OK || count <= 0) ++ rv = p11->C_FindObjects(session, &obj, 1, &count); ++ if (rv != CKR_OK || count <= 0) + return 0; + + /* Get cert and id len. */ +@@ -4375,10 +4391,9 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session, + attrs[1].type = CKA_ID; + attrs[1].pValue = NULL; + attrs[1].ulValueLen = 0; +- pret = p11->C_GetAttributeValue(session, obj, attrs, 2); +- if (pret != CKR_OK && pret != CKR_BUFFER_TOO_SMALL) { +- pkiDebug("C_GetAttributeValue: %s\n", pkcs11err(pret)); +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = p11->C_GetAttributeValue(session, obj, attrs, 2); ++ if (rv != CKR_OK && rv != CKR_BUFFER_TOO_SMALL) { ++ ret = p11err(context, rv, "C_GetAttributeValue"); + goto cleanup; + } + +@@ -4393,10 +4408,9 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session, + attrs[0].pValue = cert; + attrs[1].type = CKA_ID; + attrs[1].pValue = cert_id; +- pret = p11->C_GetAttributeValue(session, obj, attrs, 2); +- if (pret != CKR_OK) { +- pkiDebug("C_GetAttributeValue: %s\n", pkcs11err(pret)); +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ rv = p11->C_GetAttributeValue(session, obj, attrs, 2); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_GetAttributeValue"); + goto cleanup; + } + +@@ -4406,7 +4420,8 @@ load_one_cert(CK_FUNCTION_LIST_PTR p11, CK_SESSION_HANDLE session, + cp = (unsigned char *)cert; + x = d2i_X509(NULL, &cp, (int)attrs[0].ulValueLen); + if (x == NULL) { +- ret = KRB5KDC_ERR_PREAUTH_FAILED; ++ ret = oerr(context, 0, ++ _("Failed to decode X509 certificate from PKCS11 token")); + goto cleanup; + } + +@@ -4444,7 +4459,7 @@ pkinit_get_certs_pkcs11(krb5_context context, + int i; + unsigned int nattrs; + krb5_error_code ret; +- CK_RV pret; ++ CK_RV rv; + + /* Copy stuff from idopts -> id_cryptoctx */ + if (idopts->p11_module_name != NULL) { +@@ -4516,16 +4531,16 @@ pkinit_get_certs_pkcs11(krb5_context context, + nattrs++; + } + +- pret = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs, +- nattrs); +- if (pret != CKR_OK) { +- pkiDebug("C_FindObjectsInit: %s\n", pkcs11err(pret)); ++ rv = id_cryptoctx->p11->C_FindObjectsInit(id_cryptoctx->session, attrs, ++ nattrs); ++ if (rv != CKR_OK) { ++ ret = p11err(context, rv, "C_FindObjectsInit"); + return KRB5KDC_ERR_PREAUTH_FAILED; + } + + for (i = 0; i < MAX_CREDS_ALLOWED; i++) { +- ret = load_one_cert(id_cryptoctx->p11, id_cryptoctx->session, idopts, +- &id_cryptoctx->creds[i]); ++ ret = load_one_cert(context, id_cryptoctx->p11, id_cryptoctx->session, ++ idopts, &id_cryptoctx->creds[i]); + if (ret) + return ret; + if (id_cryptoctx->creds[i] == NULL) +@@ -5510,19 +5525,26 @@ print_pubkey(BIGNUM * key, char *msg) + } + #endif + +-static const char * +-pkcs11err(int err) ++#ifndef WITHOUT_PKCS11 ++static krb5_error_code ++p11err(krb5_context context, CK_RV rv, const char *op) + { ++ krb5_error_code code = KRB5KDC_ERR_PREAUTH_FAILED; + int i; ++ const char *msg; + +- for (i = 0; pkcs11_errstrings[i].text != NULL; i++) +- if (pkcs11_errstrings[i].code == err) ++ for (i = 0; pkcs11_errstrings[i].text != NULL; i++) { ++ if (pkcs11_errstrings[i].code == rv) + break; +- if (pkcs11_errstrings[i].text != NULL) +- return (pkcs11_errstrings[i].text); ++ } ++ msg = pkcs11_errstrings[i].text; ++ if (msg == NULL) ++ msg = "unknown PKCS11 error"; + +- return "unknown PKCS11 error"; ++ krb5_set_error_message(context, code, _("PKCS11 error (%s): %s"), op, msg); ++ return code; + } ++#endif + + /* + * Add an item to the pkinit_identity_crypto_context's list of deferred +diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h +index 1c1ceb5a41..1faa6816d7 100644 +--- a/src/plugins/preauth/pkinit/pkinit_trace.h ++++ b/src/plugins/preauth/pkinit/pkinit_trace.h +@@ -98,21 +98,12 @@ + #define TRACE_PKINIT_OPENSSL_ERROR(c, msg) \ + TRACE(c, "PKINIT OpenSSL error: {str}", msg) + +-#define TRACE_PKINIT_PKCS11_GETFLIST_FAILED(c, errstr) \ +- TRACE(c, "PKINIT PKCS11 C_GetFunctionList failed: {str}", errstr) +-#define TRACE_PKINIT_PKCS11_GETSYM_FAILED(c, errstr) \ +- TRACE(c, "PKINIT unable to find PKCS11 plugin symbol " \ +- "C_GetFunctionList: {str}", errstr) +-#define TRACE_PKINIT_PKCS11_LOGIN_FAILED(c, errstr) \ +- TRACE(c, "PKINIT PKCS11 C_Login failed: {str}", errstr) + #define TRACE_PKINIT_PKCS11_NO_MATCH_TOKEN(c) \ + TRACE(c, "PKINIT PKCS#11 module has no matching tokens") + #define TRACE_PKINIT_PKCS11_NO_TOKEN(c) \ + TRACE(c, "PKINIT PKCS#11 module shows no slots with tokens") + #define TRACE_PKINIT_PKCS11_OPEN(c, name) \ + TRACE(c, "PKINIT opening PKCS#11 module \"{str}\"", name) +-#define TRACE_PKINIT_PKCS11_OPEN_FAILED(c, errstr) \ +- TRACE(c, "PKINIT PKCS#11 module open failed: {str}", errstr) + #define TRACE_PKINIT_PKCS11_SLOT(c, slot, len, label) \ + TRACE(c, "PKINIT PKCS#11 slotid {int} token {lenstr}", \ + slot, len, label) +-- +2.47.1 + diff --git a/0033-Set-missing-mask-flags-for-kdb5_util-operations.patch b/0033-Set-missing-mask-flags-for-kdb5_util-operations.patch new file mode 100644 index 0000000..71b30d1 --- /dev/null +++ b/0033-Set-missing-mask-flags-for-kdb5_util-operations.patch @@ -0,0 +1,61 @@ +From 946f7dba8cea3d2ed0e68c5e7594cbd7e1364609 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Thu, 1 Aug 2024 10:56:07 +0200 +Subject: [PATCH] Set missing mask flags for kdb5_util operations + +Set KADM5_TL_DATA for the use_mkey and update_princ_encryption +commands. (Commit c877f13c8985d820583b0d7ac1bb4c5dc36e677e did this +for the add_new_mkey and purge_mkeys commands.) Set appropriate flags +for the add_random_key command. + +[ghudson@mit.edu: combined two commits; pruned out proposed mask flag +additions for values represented within key data or tl-data (like +KADM5_MKVNO), as those flags are currently only used in the kadm5 +protocol, not to communicate with the KDB module] + +ticket: 9158 (new) +(cherry picked from commit 4ed7da378940198cf4415f86d4eb013de6ac6455) +--- + src/kadmin/dbutil/kdb5_mkey.c | 4 +++- + src/kadmin/dbutil/kdb5_util.c | 3 +++ + 2 files changed, 6 insertions(+), 1 deletion(-) + +diff --git a/src/kadmin/dbutil/kdb5_mkey.c b/src/kadmin/dbutil/kdb5_mkey.c +index aceb0a9b80..ac5c51d05e 100644 +--- a/src/kadmin/dbutil/kdb5_mkey.c ++++ b/src/kadmin/dbutil/kdb5_mkey.c +@@ -525,6 +525,8 @@ kdb5_use_mkey(int argc, char *argv[]) + goto cleanup_return; + } + ++ master_entry->mask |= KADM5_TL_DATA; ++ + if ((retval = krb5_db_put_principal(util_context, master_entry))) { + com_err(progname, retval, + _("while adding master key entry to the database")); +@@ -814,7 +816,7 @@ update_princ_encryption_1(void *cb, krb5_db_entry *ent) + goto fail; + } + +- ent->mask |= KADM5_KEY_DATA; ++ ent->mask |= KADM5_KEY_DATA | KADM5_TL_DATA; + + if ((retval = krb5_db_put_principal(util_context, ent))) { + com_err(progname, retval, _("while updating principal '%s' key data " +diff --git a/src/kadmin/dbutil/kdb5_util.c b/src/kadmin/dbutil/kdb5_util.c +index 55d529fa4c..afc817891b 100644 +--- a/src/kadmin/dbutil/kdb5_util.c ++++ b/src/kadmin/dbutil/kdb5_util.c +@@ -600,6 +600,9 @@ add_random_key(int argc, char **argv) + exit_status++; + return; + } ++ ++ dbent->mask |= KADM5_ATTRIBUTES | KADM5_KEY_DATA | KADM5_TL_DATA; ++ + ret = krb5_db_put_principal(util_context, dbent); + krb5_db_free_principal(util_context, dbent); + if (ret) { +-- +2.47.1 + diff --git a/0034-Prevent-overflow-when-calculating-ulog-block-size.patch b/0034-Prevent-overflow-when-calculating-ulog-block-size.patch new file mode 100644 index 0000000..d288951 --- /dev/null +++ b/0034-Prevent-overflow-when-calculating-ulog-block-size.patch @@ -0,0 +1,64 @@ +From 9b669dd42b28e7900f5ccac2816204e7d04ea23c Mon Sep 17 00:00:00 2001 +From: Zoltan Borbely +Date: Tue, 28 Jan 2025 16:39:25 -0500 +Subject: [PATCH] Prevent overflow when calculating ulog block size + +In kdb_log.c:resize(), log an error and fail if the update size is +larger than the largest possible block size (2^16-1). + +CVE-2025-24528: + +In MIT krb5 release 1.7 and later with incremental propagation +enabled, an authenticated attacker can cause kadmind to write beyond +the end of the mapped region for the iprop log file, likely causing a +process crash. + +[ghudson@mit.edu: edited commit message and added CVE description] + +ticket: 9159 (new) +tags: pullup +target_version: 1.21-next + +(cherry picked from commit 78ceba024b64d49612375be4a12d1c066b0bfbd0) +--- + src/lib/kdb/kdb_log.c | 10 ++++++++-- + 1 file changed, 8 insertions(+), 2 deletions(-) + +diff --git a/src/lib/kdb/kdb_log.c b/src/lib/kdb/kdb_log.c +index e9b95fce59..c805ebd988 100644 +--- a/src/lib/kdb/kdb_log.c ++++ b/src/lib/kdb/kdb_log.c +@@ -183,7 +183,7 @@ extend_file_to(int fd, unsigned int new_size) + */ + static krb5_error_code + resize(kdb_hlog_t *ulog, uint32_t ulogentries, int ulogfd, +- unsigned int recsize) ++ unsigned int recsize, const kdb_incr_update_t *upd) + { + unsigned int new_block, new_size; + +@@ -195,6 +195,12 @@ resize(kdb_hlog_t *ulog, uint32_t ulogentries, int ulogfd, + new_block *= ULOG_BLOCK; + new_size += ulogentries * new_block; + ++ if (new_block > UINT16_MAX) { ++ syslog(LOG_ERR, _("ulog overflow caused by principal %.*s"), ++ upd->kdb_princ_name.utf8str_t_len, ++ upd->kdb_princ_name.utf8str_t_val); ++ return KRB5_LOG_ERROR; ++ } + if (new_size > MAXLOGLEN) + return KRB5_LOG_ERROR; + +@@ -291,7 +297,7 @@ store_update(kdb_log_context *log_ctx, kdb_incr_update_t *upd) + recsize = sizeof(kdb_ent_header_t) + upd_size; + + if (recsize > ulog->kdb_block) { +- retval = resize(ulog, ulogentries, log_ctx->ulogfd, recsize); ++ retval = resize(ulog, ulogentries, log_ctx->ulogfd, recsize, upd); + if (retval) + return retval; + } +-- +2.48.1 + diff --git a/krb5.spec b/krb5.spec index 12c9e25..963df35 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 4 +%global baserelease 5 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -84,6 +84,15 @@ Patch0022: 0022-Wait-indefinitely-on-KDC-TCP-connections.patch Patch0023: 0023-Remove-PKINIT-RSA-support.patch Patch0024: 0024-Fix-various-issues-detected-by-static-analysis.patch Patch0025: 0025-Generate-and-verify-message-MACs-in-libkrad.patch +Patch0026: 0026-PKINIT-ECDH-support.patch +Patch0027: 0027-Add-ecdsa-with-sha512-256-to-supportedCMSTypes.patch +Patch0028: 0028-Get-rid-of-pkinit_crypto_openssl.h.patch +Patch0029: 0029-Use-SoftHSMv2-for-PKCS11-PKINIT-tests.patch +Patch0030: 0030-Simplify-PKINIT-cert-representation.patch +Patch0031: 0031-Support-PKCS11-EC-client-certs-in-PKINIT.patch +Patch0032: 0032-Improve-PKCS11-error-reporting-in-PKINIT.patch +Patch0033: 0033-Set-missing-mask-flags-for-kdb5_util-operations.patch +Patch0034: 0034-Prevent-overflow-when-calculating-ulog-block-size.patch License: Brian-Gladman-2-Clause AND BSD-2-Clause AND (BSD-2-Clause OR GPL-2.0-or-later) AND BSD-2-Clause-first-lines AND BSD-3-Clause AND BSD-4-Clause AND CMU-Mach-nodoc AND FSFULLRWD AND HPND AND HPND-export2-US AND HPND-export-US AND HPND-export-US-acknowledgement AND HPND-export-US-modify AND ISC AND MIT AND MIT-CMU AND OLDAP-2.8 AND OpenVision URL: https://web.mit.edu/kerberos/www/ @@ -117,6 +126,8 @@ BuildRequires: openssl-devel < 1:3.0.0 # Enable compilation of optional tests BuildRequires: resolv_wrapper BuildRequires: libcmocka-devel +BuildRequires: opensc +BuildRequires: softhsm %description Kerberos V5 is a trusted-third-party network authentication system, @@ -148,7 +159,7 @@ Requires: openssl-libs >= 1:3.0.0 Requires: openssl-libs >= 1:1.1.1d-4 Requires: openssl-libs < 1:3.0.0 %endif -Requires: coreutils, gawk, sed +Requires: coreutils Requires: keyutils-libs >= 1.5.8 Requires: /etc/crypto-policies/back-ends/krb5.config @@ -261,11 +272,16 @@ Requires: net-tools, rpcbind Requires: perl-interpreter Requires: procps-ng Requires: python3-kdcproxy -Requires: python3-pyrad Requires: resolv_wrapper Requires: /etc/crypto-policies/back-ends/krb5.config Requires: words -#Requires: openldap-servers, openldap-clients +Requires: opensc +Requires: softhsm +Recommends: python3-pyrad + +# Restore once openldap upstream tests are fixed +#Recommends: openldap-servers +#Recommends: openldap-clients %description tests FOR TESTING PURPOSE ONLY @@ -720,6 +736,18 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Wed Jan 29 2025 Julien Rische - 1.21.3-5 +- Prevent overflow when calculating ulog block size (CVE-2025-24528) + Resolves: rhbz#2342798 +- Support PKCS11 EC client certs in PKINIT + Resolves: rhbz#2341962 +- kdb5_util: fix DB entry flags on modification + Resolves: rhbz#2336555 +- Add ECDH support for PKINIT (RFC5349) + Resolves: rhbz#2214326 +- Remove dependency of krb5-libs on gawk and sed + Resolves: rhbz#2323859 + * Fri Jan 17 2025 Fedora Release Engineering - 1.21.3-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild From 5c0a0044940e427128ff060b4c03dd1246733f05 Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Thu, 3 Apr 2025 17:07:47 +0200 Subject: [PATCH 299/304] krb5 1.21.3-6 - Do not block HMAC-MD4/5 in FIPS mode Resolves: rhbz#2370259 - PKINIT: implement paChecksum2 from MS-PKCA v20230920 Resolves: rhbz#2357215 - Disallow RC4 HMAC-MD5 session keys by default (CVE-2025-3576) Resolves: rhbz#2359705 Signed-off-by: Julien Rische --- ...ession-keys-with-deprecated-enctypes.patch | 327 +++++++++ ...eam-Remove-3des-support-cumulative-1.patch | 260 +++++++ ...T-paChecksum2-from-MS-PKCA-v20230920.patch | 692 ++++++++++++++++++ ...Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch | 381 ++++++++++ kdc.conf | 4 + krb5.spec | 22 +- 6 files changed, 1682 insertions(+), 4 deletions(-) create mode 100644 0035-Don-t-issue-session-keys-with-deprecated-enctypes.patch create mode 100644 0036-downstream-Remove-3des-support-cumulative-1.patch create mode 100644 0037-Add-PKINIT-paChecksum2-from-MS-PKCA-v20230920.patch create mode 100644 0038-downstream-Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch diff --git a/0035-Don-t-issue-session-keys-with-deprecated-enctypes.patch b/0035-Don-t-issue-session-keys-with-deprecated-enctypes.patch new file mode 100644 index 0000000..4c2ba40 --- /dev/null +++ b/0035-Don-t-issue-session-keys-with-deprecated-enctypes.patch @@ -0,0 +1,327 @@ +From c617915958a5cb05463713adcf03b6a0e0512ac3 Mon Sep 17 00:00:00 2001 +From: Greg Hudson +Date: Fri, 16 Dec 2022 18:31:07 -0500 +Subject: [PATCH] Don't issue session keys with deprecated enctypes + +A paper by Tom Tervoort noted that rc4-hmac pre-hashes the input for +its checksum and GSS operations before applying HMAC, and is therefore +potentially vulnerable to hash collision attacks if a protocol +contains a restricted signing oracle. + +In light of these potential attacks, begin the functional deprecation +of DES3 and RC4 by disallowing their use as session key enctypes by +default. Add the variables allow_des3 and allow_rc4 in case +negotiability of these enctypes for session keys needs to be turned +back on, with the expectation that in future releases the enctypes +will be more comprehensively deprecated. + +ticket: 9081 +(cherry picked from commit 1b57a4d134bbd0e7c52d5885a92eccc815726463) +--- + doc/admin/conf_files/krb5_conf.rst | 12 ++++++++++++ + doc/admin/enctypes.rst | 23 +++++++++++++++++++--- + src/include/k5-int.h | 4 ++++ + src/kdc/kdc_util.c | 10 ++++++++++ + src/lib/krb5/krb/get_in_tkt.c | 31 +++++++++++++++++++----------- + src/lib/krb5/krb/init_ctx.c | 10 ++++++++++ + src/tests/gssapi/t_enctypes.py | 5 +++-- + src/tests/t_etype_info.py | 5 +++-- + src/tests/t_sesskeynego.py | 28 +++++++++++++++++++++++++-- + src/util/k5test.py | 9 ++++++++- + 10 files changed, 116 insertions(+), 21 deletions(-) + +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index dca52e1426..d51fd3ce7e 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -95,6 +95,18 @@ Additionally, krb5.conf may include any of the relations described in + + The libdefaults section may contain any of the following relations: + ++**allow_des3** ++ Permit the KDC to issue tickets with des3-cbc-sha1 session keys. ++ In future releases, this flag will allow des3-cbc-sha1 to be used ++ at all. The default value for this tag is false. (Added in ++ release 1.21.) ++ ++**allow_rc4** ++ Permit the KDC to issue tickets with arcfour-hmac session keys. ++ In future releases, this flag will allow arcfour-hmac to be used ++ at all. The default value for this tag is false. (Added in ++ release 1.21.) ++ + **allow_weak_crypto** + If this flag is set to false, then weak encryption types (as noted + in :ref:`Encryption_types` in :ref:`kdc.conf(5)`) will be filtered +diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst +index c4d5499d3b..2b4ed7da0b 100644 +--- a/doc/admin/enctypes.rst ++++ b/doc/admin/enctypes.rst +@@ -48,12 +48,15 @@ Session key selection + The KDC chooses the session key enctype by taking the intersection of + its **permitted_enctypes** list, the list of long-term keys for the + most recent kvno of the service, and the client's requested list of +-enctypes. ++enctypes. Starting in krb5-1.21, all services are assumed to support ++aes256-cts-hmac-sha1-96; also, des3-cbc-sha1 and arcfour-hmac session ++keys will not be issued by default. + + Starting in krb5-1.11, it is possible to set a string attribute on a + service principal to control what session key enctypes the KDC may +-issue for service tickets for that principal. See :ref:`set_string` +-in :ref:`kadmin(1)` for details. ++issue for service tickets for that principal, overriding the service's ++long-term keys and the assumption of aes256-cts-hmac-sha1-96 support. ++See :ref:`set_string` in :ref:`kadmin(1)` for details. + + + Choosing enctypes for a service +@@ -87,6 +90,20 @@ affect how enctypes are chosen. + acceptable risk for your environment and the weak enctypes are + required for backward compatibility. + ++**allow_des3** ++ was added in release 1.21 and defaults to *false*. Unless this ++ flag is set to *true*, the KDC will not issue tickets with ++ des3-cbc-sha1 session keys. In a future release, this flag will ++ control whether des3-cbc-sha1 is permitted in similar fashion to ++ weak enctypes. ++ ++**allow_rc4** ++ was added in release 1.21 and defaults to *false*. Unless this ++ flag is set to *true*, the KDC will not issue tickets with ++ arcfour-hmac session keys. In a future release, this flag will ++ control whether arcfour-hmac is permitted in similar fashion to ++ weak enctypes. ++ + **permitted_enctypes** + controls the set of enctypes that a service will permit for + session keys and for ticket and authenticator encryption. The KDC +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index b7789a2dd8..d0a263aa7d 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -181,6 +181,8 @@ typedef unsigned char u_char; + * matches the variable name. Keep these alphabetized. */ + #define KRB5_CONF_ACL_FILE "acl_file" + #define KRB5_CONF_ADMIN_SERVER "admin_server" ++#define KRB5_CONF_ALLOW_DES3 "allow_des3" ++#define KRB5_CONF_ALLOW_RC4 "allow_rc4" + #define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto" + #define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local" + #define KRB5_CONF_AUTH_TO_LOCAL_NAMES "auth_to_local_names" +@@ -1241,6 +1243,8 @@ struct _krb5_context { + struct _kdb_log_context *kdblog_context; + + krb5_boolean allow_weak_crypto; ++ krb5_boolean allow_des3; ++ krb5_boolean allow_rc4; + krb5_boolean ignore_acceptor_hostname; + krb5_boolean enforce_ok_as_delegate; + enum dns_canonhost dns_canonicalize_hostname; +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index 93415ba862..c7b6e4090d 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1108,6 +1108,16 @@ select_session_keytype(krb5_context context, krb5_db_entry *server, + if (!krb5_is_permitted_enctype(context, ktype[i])) + continue; + ++ /* ++ * Prevent these deprecated enctypes from being used as session keys ++ * unless they are explicitly allowed. In the future they will be more ++ * comprehensively disabled and eventually removed. ++ */ ++ if (ktype[i] == ENCTYPE_DES3_CBC_SHA1 && !context->allow_des3) ++ continue; ++ if (ktype[i] == ENCTYPE_ARCFOUR_HMAC && !context->allow_rc4) ++ continue; ++ + if (dbentry_supports_enctype(context, server, ktype[i])) + return ktype[i]; + } +diff --git a/src/lib/krb5/krb/get_in_tkt.c b/src/lib/krb5/krb/get_in_tkt.c +index 1b420a3ac2..ea089f0fcc 100644 +--- a/src/lib/krb5/krb/get_in_tkt.c ++++ b/src/lib/krb5/krb/get_in_tkt.c +@@ -1582,22 +1582,31 @@ warn_pw_expiry(krb5_context context, krb5_get_init_creds_opt *options, + (*prompter)(context, data, 0, banner, 0, 0); + } + +-/* Display a warning via the prompter if des3-cbc-sha1 was used for either the +- * reply key or the session key. */ ++/* Display a warning via the prompter if a deprecated enctype was used for ++ * either the reply key or the session key. */ + static void +-warn_des3(krb5_context context, krb5_init_creds_context ctx, +- krb5_enctype as_key_enctype) ++warn_deprecated(krb5_context context, krb5_init_creds_context ctx, ++ krb5_enctype as_key_enctype) + { +- const char *banner; ++ krb5_enctype etype; ++ char encbuf[128], banner[256]; + +- if (as_key_enctype != ENCTYPE_DES3_CBC_SHA1 && +- ctx->cred.keyblock.enctype != ENCTYPE_DES3_CBC_SHA1) +- return; + if (ctx->prompter == NULL) + return; + +- banner = _("Warning: encryption type des3-cbc-sha1 used for " +- "authentication is weak and will be disabled"); ++ if (krb5int_c_deprecated_enctype(as_key_enctype)) ++ etype = as_key_enctype; ++ else if (krb5int_c_deprecated_enctype(ctx->cred.keyblock.enctype)) ++ etype = ctx->cred.keyblock.enctype; ++ else ++ return; ++ ++ if (krb5_enctype_to_name(etype, FALSE, encbuf, sizeof(encbuf)) != 0) ++ return; ++ snprintf(banner, sizeof(banner), ++ _("Warning: encryption type %s used for authentication is " ++ "deprecated and will be disabled"), encbuf); ++ + /* PROMPTER_INVOCATION */ + (*ctx->prompter)(context, ctx->prompter_data, NULL, banner, 0, NULL); + } +@@ -1848,7 +1857,7 @@ init_creds_step_reply(krb5_context context, + ctx->complete = TRUE; + warn_pw_expiry(context, ctx->opt, ctx->prompter, ctx->prompter_data, + ctx->in_tkt_service, ctx->reply); +- warn_des3(context, ctx, encrypting_key.enctype); ++ warn_deprecated(context, ctx, encrypting_key.enctype); + + cleanup: + krb5_free_pa_data(context, kdc_padata); +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index 582a2945ff..a32f8dbf03 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -220,6 +220,16 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + goto cleanup; + ctx->allow_weak_crypto = tmp; + ++ retval = get_boolean(ctx, KRB5_CONF_ALLOW_DES3, 0, &tmp); ++ if (retval) ++ goto cleanup; ++ ctx->allow_des3 = tmp; ++ ++ retval = get_boolean(ctx, KRB5_CONF_ALLOW_RC4, 0, &tmp); ++ if (retval) ++ goto cleanup; ++ ctx->allow_rc4 = tmp; ++ + retval = get_boolean(ctx, KRB5_CONF_IGNORE_ACCEPTOR_HOSTNAME, 0, &tmp); + if (retval) + goto cleanup; +diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py +index 2f95d89967..e6bde47afc 100755 +--- a/src/tests/gssapi/t_enctypes.py ++++ b/src/tests/gssapi/t_enctypes.py +@@ -10,8 +10,9 @@ d_rc4 = 'DEPRECATED:arcfour-hmac' + + # These tests make assumptions about the default enctype lists, so set + # them explicitly rather than relying on the library defaults. +-supp='aes256-cts:normal aes128-cts:normal rc4-hmac:normal' +-conf = {'libdefaults': {'permitted_enctypes': 'aes rc4'}, ++supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal' ++conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4', ++ 'allow_des3': 'true', 'allow_rc4': 'true'}, + 'realms': {'$realm': {'supported_enctypes': supp}}} + realm = K5Realm(krb5_conf=conf) + shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save')) +diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py +index a6f538b66d..75d9621dd6 100644 +--- a/src/tests/t_etype_info.py ++++ b/src/tests/t_etype_info.py +@@ -1,7 +1,8 @@ + from k5test import * + +-supported_enctypes = 'aes128-cts rc4-hmac' +-conf = {'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} ++supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac' ++conf = {'libdefaults': {'allow_des3': 'true', 'allow_rc4': 'true'}, ++ 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} + realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) + + realm.run([kadminl, 'addprinc', '-pw', 'pw', '+requires_preauth', +diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py +index 9024aee838..5a213617b5 100755 +--- a/src/tests/t_sesskeynego.py ++++ b/src/tests/t_sesskeynego.py +@@ -25,6 +25,8 @@ conf3 = {'libdefaults': { + 'default_tkt_enctypes': 'aes128-cts', + 'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}} + conf4 = {'libdefaults': {'permitted_enctypes': 'aes256-cts'}} ++conf5 = {'libdefaults': {'allow_rc4': 'true'}} ++conf6 = {'libdefaults': {'allow_des3': 'true'}} + # Test with client request and session_enctypes preferring aes128, but + # aes256 long-term key. + realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False) +@@ -54,10 +56,12 @@ realm.run([kadminl, 'setstr', 'server', 'session_enctypes', + 'aes128-cts,aes256-cts']) + test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96') + +-# 3b: Negotiate rc4-hmac session key when principal only has aes256 long-term. ++# 3b: Skip RC4 (as the KDC does not allow it for session keys by ++# default) and negotiate aes128-cts session key, with only an aes256 ++# long-term service key. + realm.run([kadminl, 'setstr', 'server', 'session_enctypes', + 'rc4-hmac,aes128-cts,aes256-cts']) +-test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') ++test_kvno(realm, 'aes128-cts-hmac-sha1-96', 'aes256-cts-hmac-sha1-96') + realm.stop() + + # 4: Check that permitted_enctypes is a default for session key enctypes. +@@ -67,4 +71,24 @@ realm.run([kvno, 'user'], + expected_trace=('etypes requested in TGS request: aes256-cts',)) + realm.stop() + ++# 5: allow_rc4 permits negotiation of rc4-hmac session key. ++realm = K5Realm(krb5_conf=conf5, create_host=False, get_creds=False) ++realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server']) ++realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'rc4-hmac']) ++test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') ++realm.stop() ++ ++# 6: allow_des3 permits negotiation of des3-cbc-sha1 session key. ++realm = K5Realm(krb5_conf=conf6, create_host=False, get_creds=False) ++realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server']) ++realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'des3-cbc-sha1']) ++test_kvno(realm, 'DEPRECATED:des3-cbc-sha1', 'aes256-cts-hmac-sha1-96') ++realm.stop() ++ ++# 7: default config negotiates aes256-sha1 session key for RC4-only service. ++realm = K5Realm(create_host=False, get_creds=False) ++realm.run([kadminl, 'addprinc', '-randkey', '-e', 'rc4-hmac', 'server']) ++test_kvno(realm, 'aes256-cts-hmac-sha1-96', 'DEPRECATED:arcfour-hmac') ++realm.stop() ++ + success('sesskeynego') +diff --git a/src/util/k5test.py b/src/util/k5test.py +index d823653aa0..8e5f5ba8e9 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -1338,9 +1338,16 @@ _passes = [ + # No special settings; exercises AES256. + ('default', None, None, None), + ++ # Exercise the DES3 enctype. ++ ('des3', None, ++ {'libdefaults': {'permitted_enctypes': 'des3 aes256-sha1'}}, ++ {'realms': {'$realm': { ++ 'supported_enctypes': 'des3-cbc-sha1:normal', ++ 'master_key_type': 'des3-cbc-sha1'}}}), ++ + # Exercise the arcfour enctype. + ('arcfour', None, +- {'libdefaults': {'permitted_enctypes': 'rc4'}}, ++ {'libdefaults': {'permitted_enctypes': 'rc4 aes256-sha1'}}, + {'realms': {'$realm': { + 'supported_enctypes': 'arcfour-hmac:normal', + 'master_key_type': 'arcfour-hmac'}}}), +-- +2.49.0 + diff --git a/0036-downstream-Remove-3des-support-cumulative-1.patch b/0036-downstream-Remove-3des-support-cumulative-1.patch new file mode 100644 index 0000000..4911619 --- /dev/null +++ b/0036-downstream-Remove-3des-support-cumulative-1.patch @@ -0,0 +1,260 @@ +From b0993b57dbe584f9308cc7773b930efe76e19ba3 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Fri, 4 Apr 2025 15:08:36 +0200 +Subject: [PATCH] [downstream] Remove 3des support (cumulative 1) + +Remove mentions for the triple-DES encryption type which were added +since the previous downstream patch. +--- + README | 15 +++++++-------- + doc/admin/conf_files/krb5_conf.rst | 6 ------ + doc/admin/enctypes.rst | 11 ++--------- + doc/mitK5features.rst | 5 ++--- + src/include/k5-int.h | 2 -- + src/kdc/kdc_util.c | 2 -- + src/lib/krb5/krb/init_ctx.c | 5 ----- + src/man/krb5.conf.man | 6 ------ + src/tests/gssapi/t_enctypes.py | 5 ++--- + src/tests/t_etype_info.py | 4 ++-- + src/tests/t_sesskeynego.py | 8 -------- + src/util/k5test.py | 7 ------- + 12 files changed, 15 insertions(+), 61 deletions(-) + +diff --git a/README b/README +index 6d6f7f16e3..9341bd3dd8 100644 +--- a/README ++++ b/README +@@ -81,11 +81,11 @@ Triple-DES and RC4 transitions + ------------------------------ + + Beginning with the krb5-1.21 release, the KDC will not issue tickets +-with triple-DES or RC4 session keys unless explicitly configured using +-the new allow_des3 and allow_rc4 variables in [libdefaults]. To +-facilitate the negotiation of session keys, the KDC will assume that +-all services can handle aes256-sha1 session keys unless the service +-principal has a session_enctypes string attribute. ++with RC4 session keys unless explicitly configured using the new ++allow_rc4 variable in [libdefaults]. To facilitate the negotiation of ++session keys, the KDC will assume that all services can handle ++aes256-sha1 session keys unless the service principal has a ++session_enctypes string attribute. + + Beginning with the krb5-1.19 release, a warning will be issued if + initial credentials are acquired using the des3-cbc-sha1 encryption +@@ -164,9 +164,8 @@ Developer experience: + + Protocol evolution: + +-* The KDC will no longer issue tickets with RC4 or triple-DES session +- keys unless explicitly configured with the new allow_rc4 or +- allow_des3 variables respectively. ++* The KDC will no longer issue tickets with RC4 session keys unless ++ explicitly configured with the new allow_rc4 variable. + + * The KDC will assume that all services can handle aes256-sha1 session + keys unless the service principal has a session_enctypes string +diff --git a/doc/admin/conf_files/krb5_conf.rst b/doc/admin/conf_files/krb5_conf.rst +index d51fd3ce7e..d20dcf18e3 100644 +--- a/doc/admin/conf_files/krb5_conf.rst ++++ b/doc/admin/conf_files/krb5_conf.rst +@@ -95,12 +95,6 @@ Additionally, krb5.conf may include any of the relations described in + + The libdefaults section may contain any of the following relations: + +-**allow_des3** +- Permit the KDC to issue tickets with des3-cbc-sha1 session keys. +- In future releases, this flag will allow des3-cbc-sha1 to be used +- at all. The default value for this tag is false. (Added in +- release 1.21.) +- + **allow_rc4** + Permit the KDC to issue tickets with arcfour-hmac session keys. + In future releases, this flag will allow arcfour-hmac to be used +diff --git a/doc/admin/enctypes.rst b/doc/admin/enctypes.rst +index 2b4ed7da0b..6ce4638d5e 100644 +--- a/doc/admin/enctypes.rst ++++ b/doc/admin/enctypes.rst +@@ -49,8 +49,8 @@ The KDC chooses the session key enctype by taking the intersection of + its **permitted_enctypes** list, the list of long-term keys for the + most recent kvno of the service, and the client's requested list of + enctypes. Starting in krb5-1.21, all services are assumed to support +-aes256-cts-hmac-sha1-96; also, des3-cbc-sha1 and arcfour-hmac session +-keys will not be issued by default. ++aes256-cts-hmac-sha1-96; also, arcfour-hmac session keys will not be ++issued by default. + + Starting in krb5-1.11, it is possible to set a string attribute on a + service principal to control what session key enctypes the KDC may +@@ -90,13 +90,6 @@ affect how enctypes are chosen. + acceptable risk for your environment and the weak enctypes are + required for backward compatibility. + +-**allow_des3** +- was added in release 1.21 and defaults to *false*. Unless this +- flag is set to *true*, the KDC will not issue tickets with +- des3-cbc-sha1 session keys. In a future release, this flag will +- control whether des3-cbc-sha1 is permitted in similar fashion to +- weak enctypes. +- + **allow_rc4** + was added in release 1.21 and defaults to *false*. Unless this + flag is set to *true*, the KDC will not issue tickets with +diff --git a/doc/mitK5features.rst b/doc/mitK5features.rst +index cad0855724..64d746b0af 100644 +--- a/doc/mitK5features.rst ++++ b/doc/mitK5features.rst +@@ -659,9 +659,8 @@ Release 1.21 + + * Protocol evolution: + +- - The KDC will no longer issue tickets with RC4 or triple-DES +- session keys unless explicitly configured with the new allow_rc4 +- or allow_des3 variables respectively. ++ - The KDC will no longer issue tickets with RC4 session keys unless ++ explicitly configured with the new allow_rc4 variable. + + - The KDC will assume that all services can handle aes256-sha1 + session keys unless the service principal has a session_enctypes +diff --git a/src/include/k5-int.h b/src/include/k5-int.h +index d0a263aa7d..82a763298d 100644 +--- a/src/include/k5-int.h ++++ b/src/include/k5-int.h +@@ -181,7 +181,6 @@ typedef unsigned char u_char; + * matches the variable name. Keep these alphabetized. */ + #define KRB5_CONF_ACL_FILE "acl_file" + #define KRB5_CONF_ADMIN_SERVER "admin_server" +-#define KRB5_CONF_ALLOW_DES3 "allow_des3" + #define KRB5_CONF_ALLOW_RC4 "allow_rc4" + #define KRB5_CONF_ALLOW_WEAK_CRYPTO "allow_weak_crypto" + #define KRB5_CONF_AUTH_TO_LOCAL "auth_to_local" +@@ -1243,7 +1242,6 @@ struct _krb5_context { + struct _kdb_log_context *kdblog_context; + + krb5_boolean allow_weak_crypto; +- krb5_boolean allow_des3; + krb5_boolean allow_rc4; + krb5_boolean ignore_acceptor_hostname; + krb5_boolean enforce_ok_as_delegate; +diff --git a/src/kdc/kdc_util.c b/src/kdc/kdc_util.c +index c7b6e4090d..bafcf5f728 100644 +--- a/src/kdc/kdc_util.c ++++ b/src/kdc/kdc_util.c +@@ -1113,8 +1113,6 @@ select_session_keytype(krb5_context context, krb5_db_entry *server, + * unless they are explicitly allowed. In the future they will be more + * comprehensively disabled and eventually removed. + */ +- if (ktype[i] == ENCTYPE_DES3_CBC_SHA1 && !context->allow_des3) +- continue; + if (ktype[i] == ENCTYPE_ARCFOUR_HMAC && !context->allow_rc4) + continue; + +diff --git a/src/lib/krb5/krb/init_ctx.c b/src/lib/krb5/krb/init_ctx.c +index a32f8dbf03..82aba64c5e 100644 +--- a/src/lib/krb5/krb/init_ctx.c ++++ b/src/lib/krb5/krb/init_ctx.c +@@ -220,11 +220,6 @@ krb5_init_context_profile(profile_t profile, krb5_flags flags, + goto cleanup; + ctx->allow_weak_crypto = tmp; + +- retval = get_boolean(ctx, KRB5_CONF_ALLOW_DES3, 0, &tmp); +- if (retval) +- goto cleanup; +- ctx->allow_des3 = tmp; +- + retval = get_boolean(ctx, KRB5_CONF_ALLOW_RC4, 0, &tmp); + if (retval) + goto cleanup; +diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man +index 6c0e9aff8c..4b53988712 100644 +--- a/src/man/krb5.conf.man ++++ b/src/man/krb5.conf.man +@@ -178,12 +178,6 @@ kdc.conf(5), but it is not a recommended practice. + The libdefaults section may contain any of the following relations: + .INDENT 0.0 + .TP +-\fBallow_des3\fP +-Permit the KDC to issue tickets with des3\-cbc\-sha1 session keys. +-In future releases, this flag will allow des3\-cbc\-sha1 to be used +-at all. The default value for this tag is false. (Added in +-release 1.21.) +-.TP + \fBallow_rc4\fP + Permit the KDC to issue tickets with arcfour\-hmac session keys. + In future releases, this flag will allow arcfour\-hmac to be used +diff --git a/src/tests/gssapi/t_enctypes.py b/src/tests/gssapi/t_enctypes.py +index e6bde47afc..1bb8c40b6b 100755 +--- a/src/tests/gssapi/t_enctypes.py ++++ b/src/tests/gssapi/t_enctypes.py +@@ -10,9 +10,8 @@ d_rc4 = 'DEPRECATED:arcfour-hmac' + + # These tests make assumptions about the default enctype lists, so set + # them explicitly rather than relying on the library defaults. +-supp='aes256-cts:normal aes128-cts:normal des3-cbc-sha1:normal rc4-hmac:normal' +-conf = {'libdefaults': {'permitted_enctypes': 'aes des3 rc4', +- 'allow_des3': 'true', 'allow_rc4': 'true'}, ++supp='aes256-cts:normal aes128-cts:normal rc4-hmac:normal' ++conf = {'libdefaults': {'permitted_enctypes': 'aes rc4', 'allow_rc4': 'true'}, + 'realms': {'$realm': {'supported_enctypes': supp}}} + realm = K5Realm(krb5_conf=conf) + shutil.copyfile(realm.ccache, os.path.join(realm.testdir, 'save')) +diff --git a/src/tests/t_etype_info.py b/src/tests/t_etype_info.py +index 75d9621dd6..e82ff7ff07 100644 +--- a/src/tests/t_etype_info.py ++++ b/src/tests/t_etype_info.py +@@ -1,7 +1,7 @@ + from k5test import * + +-supported_enctypes = 'aes128-cts des3-cbc-sha1 rc4-hmac' +-conf = {'libdefaults': {'allow_des3': 'true', 'allow_rc4': 'true'}, ++supported_enctypes = 'aes128-cts rc4-hmac' ++conf = {'libdefaults': {'allow_rc4': 'true'}, + 'realms': {'$realm': {'supported_enctypes': supported_enctypes}}} + realm = K5Realm(create_host=False, get_creds=False, krb5_conf=conf) + +diff --git a/src/tests/t_sesskeynego.py b/src/tests/t_sesskeynego.py +index 5a213617b5..c7dba0ff5b 100755 +--- a/src/tests/t_sesskeynego.py ++++ b/src/tests/t_sesskeynego.py +@@ -26,7 +26,6 @@ conf3 = {'libdefaults': { + 'default_tgs_enctypes': 'rc4-hmac,aes128-cts'}} + conf4 = {'libdefaults': {'permitted_enctypes': 'aes256-cts'}} + conf5 = {'libdefaults': {'allow_rc4': 'true'}} +-conf6 = {'libdefaults': {'allow_des3': 'true'}} + # Test with client request and session_enctypes preferring aes128, but + # aes256 long-term key. + realm = K5Realm(krb5_conf=conf1, create_host=False, get_creds=False) +@@ -78,13 +77,6 @@ realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'rc4-hmac']) + test_kvno(realm, 'DEPRECATED:arcfour-hmac', 'aes256-cts-hmac-sha1-96') + realm.stop() + +-# 6: allow_des3 permits negotiation of des3-cbc-sha1 session key. +-realm = K5Realm(krb5_conf=conf6, create_host=False, get_creds=False) +-realm.run([kadminl, 'addprinc', '-randkey', '-e', 'aes256-cts', 'server']) +-realm.run([kadminl, 'setstr', 'server', 'session_enctypes', 'des3-cbc-sha1']) +-test_kvno(realm, 'DEPRECATED:des3-cbc-sha1', 'aes256-cts-hmac-sha1-96') +-realm.stop() +- + # 7: default config negotiates aes256-sha1 session key for RC4-only service. + realm = K5Realm(create_host=False, get_creds=False) + realm.run([kadminl, 'addprinc', '-randkey', '-e', 'rc4-hmac', 'server']) +diff --git a/src/util/k5test.py b/src/util/k5test.py +index 8e5f5ba8e9..b953827018 100644 +--- a/src/util/k5test.py ++++ b/src/util/k5test.py +@@ -1338,13 +1338,6 @@ _passes = [ + # No special settings; exercises AES256. + ('default', None, None, None), + +- # Exercise the DES3 enctype. +- ('des3', None, +- {'libdefaults': {'permitted_enctypes': 'des3 aes256-sha1'}}, +- {'realms': {'$realm': { +- 'supported_enctypes': 'des3-cbc-sha1:normal', +- 'master_key_type': 'des3-cbc-sha1'}}}), +- + # Exercise the arcfour enctype. + ('arcfour', None, + {'libdefaults': {'permitted_enctypes': 'rc4 aes256-sha1'}}, +-- +2.49.0 + diff --git a/0037-Add-PKINIT-paChecksum2-from-MS-PKCA-v20230920.patch b/0037-Add-PKINIT-paChecksum2-from-MS-PKCA-v20230920.patch new file mode 100644 index 0000000..2d9a6cc --- /dev/null +++ b/0037-Add-PKINIT-paChecksum2-from-MS-PKCA-v20230920.patch @@ -0,0 +1,692 @@ +From 9d03713af124c2096d071ba36893018da8d71655 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Tue, 14 Jan 2025 13:31:11 +0100 +Subject: [PATCH] Add PKINIT paChecksum2 from MS-PKCA v20230920 + +In 2023, Microsoft updated MS-PKCA to add the optional paChecksum2 +element in the PKAuthenticator sequence. This checksum accepts SHA-1, +SHA-256, SHA-384, and SHA-512 digests. + +In Windows Server 2025, this checksum becomes mandatory when using +PKINIT with FFDH (but strangely not with ECDH if SHA-1 is configured as +allowed). + +[ghudson@mit.edu: refactored crypto interfaces to reduce complexity of +calling code] + +ticket: 9166 (new) +(cherry picked from commit 310793ba63782af5ffa3a95d20e41f8f03ca7e00) +--- + src/include/k5-int-pkinit.h | 25 ++-- + src/lib/krb5/asn.1/asn1_k_encode.c | 18 ++- + src/plugins/preauth/pkinit/pkinit.h | 1 + + src/plugins/preauth/pkinit/pkinit_clnt.c | 41 +++---- + src/plugins/preauth/pkinit/pkinit_constants.c | 42 +++++-- + src/plugins/preauth/pkinit/pkinit_crypto.h | 24 +++- + .../preauth/pkinit/pkinit_crypto_openssl.c | 116 +++++++++++++++++- + src/plugins/preauth/pkinit/pkinit_kdf_test.c | 4 +- + src/plugins/preauth/pkinit/pkinit_lib.c | 16 ++- + src/plugins/preauth/pkinit/pkinit_srv.c | 38 ++---- + src/plugins/preauth/pkinit/pkinit_trace.h | 5 +- + src/tests/asn.1/krb5_decode_test.c | 2 +- + src/tests/asn.1/ktest.c | 7 +- + src/tests/asn.1/ktest_equal.c | 2 +- + src/tests/asn.1/pkinit_encode.out | 2 +- + src/tests/asn.1/pkinit_trval.out | 2 +- + 16 files changed, 250 insertions(+), 95 deletions(-) + +diff --git a/src/include/k5-int-pkinit.h b/src/include/k5-int-pkinit.h +index 915904e518..cf6b1f99c5 100644 +--- a/src/include/k5-int-pkinit.h ++++ b/src/include/k5-int-pkinit.h +@@ -36,21 +36,28 @@ + * pkinit structures + */ + +-/* PKAuthenticator */ +-typedef struct _krb5_pk_authenticator { +- krb5_int32 cusec; /* (0..999999) */ +- krb5_timestamp ctime; +- krb5_int32 nonce; /* (0..4294967295) */ +- krb5_checksum paChecksum; +- krb5_data *freshnessToken; +-} krb5_pk_authenticator; +- + /* AlgorithmIdentifier */ + typedef struct _krb5_algorithm_identifier { + krb5_data algorithm; /* OID */ + krb5_data parameters; /* Optional */ + } krb5_algorithm_identifier; + ++/* PAChecksum2 */ ++typedef struct _krb5_pachecksum2 { ++ krb5_data checksum; ++ krb5_algorithm_identifier algorithmIdentifier; ++} krb5_pachecksum2; ++ ++/* PKAuthenticator */ ++typedef struct _krb5_pk_authenticator { ++ krb5_int32 cusec; /* (0..999999) */ ++ krb5_timestamp ctime; ++ krb5_int32 nonce; /* (0..4294967295) */ ++ krb5_data paChecksum; ++ krb5_data *freshnessToken; /* Optional */ ++ krb5_pachecksum2 *paChecksum2; /* Optional */ ++} krb5_pk_authenticator; ++ + /** AuthPack from RFC 4556*/ + typedef struct _krb5_auth_pack { + krb5_pk_authenticator pkAuthenticator; +diff --git a/src/lib/krb5/asn.1/asn1_k_encode.c b/src/lib/krb5/asn.1/asn1_k_encode.c +index 5378b5c23b..cf7b500837 100644 +--- a/src/lib/krb5/asn.1/asn1_k_encode.c ++++ b/src/lib/krb5/asn.1/asn1_k_encode.c +@@ -1394,20 +1394,30 @@ DEFSEQTYPE(pkinit_supp_pub_info, krb5_pkinit_supp_pub_info, + MAKE_ENCODER(encode_krb5_pkinit_supp_pub_info, pkinit_supp_pub_info); + MAKE_ENCODER(encode_krb5_sp80056a_other_info, sp80056a_other_info); + +-/* A krb5_checksum encoded as an OCTET STRING, for PKAuthenticator. */ +-DEFCOUNTEDTYPE(ostring_checksum, krb5_checksum, contents, length, octetstring); ++DEFFIELD(pachecksum2_0, krb5_pachecksum2, checksum, 0, ostring_data); ++DEFFIELD(pachecksum2_1, krb5_pachecksum2, algorithmIdentifier, 1, ++ algorithm_identifier); ++static const struct atype_info *pachecksum2_fields[] = { ++ &k5_atype_pachecksum2_0, &k5_atype_pachecksum2_1 ++}; ++DEFSEQTYPE(pachecksum2, krb5_pachecksum2, pachecksum2_fields); ++ ++DEFPTRTYPE(pachecksum2_ptr, pachecksum2); ++DEFOPTIONALZEROTYPE(opt_pachecksum2_ptr, pachecksum2_ptr); + + DEFFIELD(pk_authenticator_0, krb5_pk_authenticator, cusec, 0, int32); + DEFFIELD(pk_authenticator_1, krb5_pk_authenticator, ctime, 1, kerberos_time); + DEFFIELD(pk_authenticator_2, krb5_pk_authenticator, nonce, 2, int32); + DEFFIELD(pk_authenticator_3, krb5_pk_authenticator, paChecksum, 3, +- ostring_checksum); ++ ostring_data); + DEFFIELD(pk_authenticator_4, krb5_pk_authenticator, freshnessToken, 4, + opt_ostring_data_ptr); ++DEFFIELD(pk_authenticator_5, krb5_pk_authenticator, paChecksum2, 5, ++ opt_pachecksum2_ptr); + static const struct atype_info *pk_authenticator_fields[] = { + &k5_atype_pk_authenticator_0, &k5_atype_pk_authenticator_1, + &k5_atype_pk_authenticator_2, &k5_atype_pk_authenticator_3, +- &k5_atype_pk_authenticator_4 ++ &k5_atype_pk_authenticator_4, &k5_atype_pk_authenticator_5 + }; + DEFSEQTYPE(pk_authenticator, krb5_pk_authenticator, pk_authenticator_fields); + +diff --git a/src/plugins/preauth/pkinit/pkinit.h b/src/plugins/preauth/pkinit/pkinit.h +index 7ba7155bb4..a1564b6df2 100644 +--- a/src/plugins/preauth/pkinit/pkinit.h ++++ b/src/plugins/preauth/pkinit/pkinit.h +@@ -338,6 +338,7 @@ void free_krb5_external_principal_identifier(krb5_external_principal_identifier + void free_krb5_algorithm_identifiers(krb5_algorithm_identifier ***in); + void free_krb5_algorithm_identifier(krb5_algorithm_identifier *in); + void free_krb5_kdc_dh_key_info(krb5_kdc_dh_key_info **in); ++void free_pachecksum2(krb5_context context, krb5_pachecksum2 **in); + krb5_error_code pkinit_copy_krb5_data(krb5_data *dst, const krb5_data *src); + + +diff --git a/src/plugins/preauth/pkinit/pkinit_clnt.c b/src/plugins/preauth/pkinit/pkinit_clnt.c +index b08022a214..433f477538 100644 +--- a/src/plugins/preauth/pkinit/pkinit_clnt.c ++++ b/src/plugins/preauth/pkinit/pkinit_clnt.c +@@ -56,10 +56,9 @@ use_content_info(krb5_context context, pkinit_req_context req, + static krb5_error_code + pkinit_as_req_create(krb5_context context, pkinit_context plgctx, + pkinit_req_context reqctx, krb5_timestamp ctsec, +- krb5_int32 cusec, krb5_ui_4 nonce, +- const krb5_checksum *cksum, +- krb5_principal client, krb5_principal server, +- krb5_data **as_req); ++ krb5_int32 cusec, krb5_ui_4 nonce, const krb5_data *cksum, ++ const krb5_pachecksum2 *cksum2, krb5_principal client, ++ krb5_principal server, krb5_data **as_req); + + static krb5_error_code + pkinit_as_rep_parse(krb5_context context, pkinit_context plgctx, +@@ -89,7 +88,8 @@ pa_pkinit_gen_req(krb5_context context, + krb5_timestamp ctsec = 0; + krb5_int32 cusec = 0; + krb5_ui_4 nonce = 0; +- krb5_checksum cksum; ++ krb5_data cksum = empty_data(); ++ krb5_pachecksum2 *cksum2 = NULL; + krb5_data *der_req = NULL; + krb5_pa_data **return_pa_data = NULL; + +@@ -118,15 +118,10 @@ pa_pkinit_gen_req(krb5_context context, + goto cleanup; + } + +- retval = krb5_c_make_checksum(context, CKSUMTYPE_SHA1, NULL, 0, der_req, +- &cksum); ++ retval = crypto_generate_checksums(context, der_req, &cksum, &cksum2); + if (retval) + goto cleanup; +- TRACE_PKINIT_CLIENT_REQ_CHECKSUM(context, &cksum); +-#ifdef DEBUG_CKSUM +- pkiDebug("calculating checksum on buf size (%d)\n", der_req->length); +- print_buffer(der_req->data, der_req->length); +-#endif ++ TRACE_PKINIT_CLIENT_REQ_CHECKSUMS(context, &cksum, cksum2); + + retval = cb->get_preauth_time(context, rock, TRUE, &ctsec, &cusec); + if (retval) +@@ -140,7 +135,8 @@ pa_pkinit_gen_req(krb5_context context, + nonce = request->nonce; + + retval = pkinit_as_req_create(context, plgctx, reqctx, ctsec, cusec, +- nonce, &cksum, request->client, request->server, &out_data); ++ nonce, &cksum, cksum2, request->client, ++ request->server, &out_data); + if (retval) { + pkiDebug("error %d on pkinit_as_req_create; aborting PKINIT\n", + (int) retval); +@@ -168,23 +164,19 @@ pa_pkinit_gen_req(krb5_context context, + + cleanup: + krb5_free_data(context, der_req); +- krb5_free_checksum_contents(context, &cksum); ++ krb5_free_data_contents(context, &cksum); ++ free_pachecksum2(context, &cksum2); + krb5_free_data(context, out_data); + krb5_free_pa_data(context, return_pa_data); + return retval; + } + + static krb5_error_code +-pkinit_as_req_create(krb5_context context, +- pkinit_context plgctx, +- pkinit_req_context reqctx, +- krb5_timestamp ctsec, +- krb5_int32 cusec, +- krb5_ui_4 nonce, +- const krb5_checksum * cksum, +- krb5_principal client, +- krb5_principal server, +- krb5_data ** as_req) ++pkinit_as_req_create(krb5_context context, pkinit_context plgctx, ++ pkinit_req_context reqctx, krb5_timestamp ctsec, ++ krb5_int32 cusec, krb5_ui_4 nonce, const krb5_data *cksum, ++ const krb5_pachecksum2 *cksum2, krb5_principal client, ++ krb5_principal server, krb5_data **as_req) + { + krb5_error_code retval = ENOMEM; + krb5_data spki = empty_data(), *coded_auth_pack = NULL; +@@ -202,6 +194,7 @@ pkinit_as_req_create(krb5_context context, + auth_pack.pkAuthenticator.paChecksum = *cksum; + if (!reqctx->opts->disable_freshness) + auth_pack.pkAuthenticator.freshnessToken = reqctx->freshness_token; ++ auth_pack.pkAuthenticator.paChecksum2 = (krb5_pachecksum2 *)cksum2; + auth_pack.clientDHNonce.length = 0; + auth_pack.supportedKDFs = (krb5_data **)supported_kdf_alg_ids; + +diff --git a/src/plugins/preauth/pkinit/pkinit_constants.c b/src/plugins/preauth/pkinit/pkinit_constants.c +index 905e90d29c..a32b373c32 100644 +--- a/src/plugins/preauth/pkinit/pkinit_constants.c ++++ b/src/plugins/preauth/pkinit/pkinit_constants.c +@@ -34,25 +34,49 @@ + + /* RFC 8636 id-pkinit-kdf-ah-sha1: iso(1) identified-organization(3) dod(6) + * internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha1(1) */ +-static char sha1_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x01 }; ++static char kdf_sha1[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x01 }; + /* RFC 8636 id-pkinit-kdf-ah-sha256: iso(1) identified-organization(3) dod(6) + * internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha256(2) */ +-static char sha256_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x02 }; ++static char kdf_sha256[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x02 }; + /* RFC 8636 id-pkinit-kdf-ah-sha512: iso(1) identified-organization(3) dod(6) + * internet(1) security(5) kerberosv5(2) pkinit(3) kdf(6) sha512(3) */ +-static char sha512_oid[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x03 }; ++static char kdf_sha512[8] = { 0x2B, 0x06, 0x01, 0x05, 0x02, 0x03, 0x06, 0x03 }; + +-const krb5_data sha1_id = { KV5M_DATA, sizeof(sha1_oid), sha1_oid }; +-const krb5_data sha256_id = { KV5M_DATA, sizeof(sha256_oid), sha256_oid }; +-const krb5_data sha512_id = { KV5M_DATA, sizeof(sha512_oid), sha512_oid }; ++const krb5_data kdf_sha1_id = { KV5M_DATA, sizeof(kdf_sha1), kdf_sha1 }; ++const krb5_data kdf_sha256_id = { KV5M_DATA, sizeof(kdf_sha256), kdf_sha256 }; ++const krb5_data kdf_sha512_id = { KV5M_DATA, sizeof(kdf_sha512), kdf_sha512 }; + + krb5_data const * const supported_kdf_alg_ids[] = { +- &sha256_id, +- &sha1_id, +- &sha512_id, ++ &kdf_sha256_id, ++ &kdf_sha1_id, ++ &kdf_sha512_id, + NULL + }; + ++/* RFC 3370 sha-1: iso(1) identified-organization(3) oiw(14) secsig(3) ++ * algorithm(2) 26 */ ++static char cms_sha1[] = { 0x2b, 0x0e, 0x03, 0x02, 0x1a }; ++/* RFC 5754 id-sha256: joint-iso-itu-t(2) country(16) us(840) organization(1) ++ * gov(101) csor(3) nistalgorithm(4) hashalgs(2) 1 */ ++static char cms_sha256[] = { ++ 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x01 ++}; ++/* RFC 5754 id-sha384: joint-iso-itu-t(2) country(16) us(840) organization(1) ++ * gov(101) csor(3) nistalgorithm(4) hashalgs(2) 2 */ ++static char cms_sha384[] = { ++ 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x02 ++}; ++/* RFC 5754 id-sha512: joint-iso-itu-t(2) country(16) us(840) organization(1) ++ * gov(101) csor(3) nistalgorithm(4) hashalgs(2) 3 */ ++static char cms_sha512[] = { ++ 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x03 ++}; ++ ++const krb5_data cms_sha1_id = { KV5M_DATA, sizeof(cms_sha1), cms_sha1 }; ++const krb5_data cms_sha256_id = { KV5M_DATA, sizeof(cms_sha256), cms_sha256 }; ++const krb5_data cms_sha384_id = { KV5M_DATA, sizeof(cms_sha384), cms_sha384 }; ++const krb5_data cms_sha512_id = { KV5M_DATA, sizeof(cms_sha512), cms_sha512 }; ++ + /* RFC 4055 sha256WithRSAEncryption: iso(1) member-body(2) us(840) + * rsadsi(113549) pkcs(1) 1 11 */ + static char sha256WithRSAEncr_oid[9] = { +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index fd876e4850..3b12e904b1 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -562,9 +562,13 @@ pkinit_alg_agility_kdf(krb5_context context, + krb5_data *pk_as_rep, + krb5_keyblock *key_block); + +-extern const krb5_data sha1_id; +-extern const krb5_data sha256_id; +-extern const krb5_data sha512_id; ++extern const krb5_data kdf_sha1_id; ++extern const krb5_data kdf_sha256_id; ++extern const krb5_data kdf_sha512_id; ++extern const krb5_data cms_sha1_id; ++extern const krb5_data cms_sha256_id; ++extern const krb5_data cms_sha384_id; ++extern const krb5_data cms_sha512_id; + extern const krb5_data oakley_1024; + extern const krb5_data oakley_2048; + extern const krb5_data oakley_4096; +@@ -597,4 +601,18 @@ crypto_req_cert_matching_data(krb5_context context, + + int parse_dh_min_bits(krb5_context context, const char *str); + ++/* Generate a SHA-1 checksum over body in *cksum1_out and a SHA-256 checksum ++ * over body in *cksum2_out with appropriate metadata. */ ++krb5_error_code ++crypto_generate_checksums(krb5_context context, const krb5_data *body, ++ krb5_data *cksum1_out, ++ krb5_pachecksum2 **cksum2_out); ++ ++/* Verify the SHA-1 checksum in cksum1 and the tagged checksum in cksum2. ++ * cksum2 may be NULL, in which case only cksum1 is verified. */ ++krb5_error_code ++crypto_verify_checksums(krb5_context context, krb5_data *body, ++ const krb5_data *cksum1, ++ const krb5_pachecksum2 *cksum2); ++ + #endif /* _PKINIT_CRYPTO_H */ +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 402bf1b9b3..429b7d202c 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -2616,11 +2616,11 @@ cleanup: + static const EVP_MD * + algid_to_md(const krb5_data *alg_id) + { +- if (data_eq(*alg_id, sha1_id)) ++ if (data_eq(*alg_id, kdf_sha1_id)) + return EVP_sha1(); +- if (data_eq(*alg_id, sha256_id)) ++ if (data_eq(*alg_id, kdf_sha256_id)) + return EVP_sha256(); +- if (data_eq(*alg_id, sha512_id)) ++ if (data_eq(*alg_id, kdf_sha512_id)) + return EVP_sha512(); + return NULL; + } +@@ -5663,3 +5663,113 @@ parse_dh_min_bits(krb5_context context, const char *str) + TRACE_PKINIT_DH_INVALID_MIN_BITS(context, str); + return PKINIT_DEFAULT_DH_MIN_BITS; + } ++ ++/* Return the OpenSSL message digest type matching the given CMS OID, or NULL ++ * if it doesn't match any of the CMS OIDs we know about. */ ++static const EVP_MD * ++md_from_cms_oid(const krb5_data *alg_id) ++{ ++ if (data_eq(*alg_id, cms_sha1_id)) ++ return EVP_sha1(); ++ if (data_eq(*alg_id, cms_sha256_id)) ++ return EVP_sha256(); ++ if (data_eq(*alg_id, cms_sha384_id)) ++ return EVP_sha384(); ++ if (data_eq(*alg_id, cms_sha512_id)) ++ return EVP_sha512(); ++ return NULL; ++} ++ ++/* Compute a message digest of the given type over body, placing the result in ++ * *digest_out in allocated storage. Return true on success. */ ++static krb5_boolean ++make_digest(const krb5_data *body, const EVP_MD *md, krb5_data *digest_out) ++{ ++ krb5_error_code ret; ++ krb5_data d; ++ ++ if (md == NULL) ++ return FALSE; ++ ret = alloc_data(&d, EVP_MD_size(md)); ++ if (ret) ++ return FALSE; ++ if (!EVP_Digest(body->data, body->length, (uint8_t *)d.data, &d.length, md, ++ NULL)) { ++ free(d.data); ++ return FALSE; ++ } ++ *digest_out = d; ++ return TRUE; ++} ++ ++/* Return true if digest verifies for the given body and message digest ++ * type. */ ++static krb5_boolean ++check_digest(const krb5_data *body, const EVP_MD *md, const krb5_data *digest) ++{ ++ unsigned int digest_len; ++ uint8_t buf[EVP_MAX_MD_SIZE]; ++ ++ if (md == NULL) ++ return FALSE; ++ if (!EVP_Digest(body->data, body->length, buf, &digest_len, md, NULL)) ++ return FALSE; ++ return (digest->length == digest_len && ++ CRYPTO_memcmp(digest->data, buf, digest_len) == 0); ++} ++ ++krb5_error_code ++crypto_generate_checksums(krb5_context context, const krb5_data *body, ++ krb5_data *cksum1_out, krb5_pachecksum2 **cksum2_out) ++{ ++ krb5_data cksum1 = empty_data(); ++ krb5_pachecksum2 *cksum2 = NULL; ++ krb5_error_code ret; ++ ++ if (!make_digest(body, EVP_sha1(), &cksum1)) ++ goto fail; ++ ++ cksum2 = k5alloc(sizeof(*cksum2), &ret); ++ if (cksum2 == NULL) ++ goto fail; ++ ++ if (!make_digest(body, EVP_sha256(), &cksum2->checksum)) ++ goto fail; ++ ++ if (krb5int_copy_data_contents(context, &cms_sha256_id, ++ &cksum2->algorithmIdentifier.algorithm)) ++ goto fail; ++ ++ cksum2->algorithmIdentifier.parameters = empty_data(); ++ ++ *cksum1_out = cksum1; ++ *cksum2_out = cksum2; ++ return 0; ++ ++fail: ++ krb5_free_data_contents(context, &cksum1); ++ free_pachecksum2(context, &cksum2); ++ return KRB5_CRYPTO_INTERNAL; ++} ++ ++krb5_error_code ++crypto_verify_checksums(krb5_context context, krb5_data *body, ++ const krb5_data *cksum1, ++ const krb5_pachecksum2 *cksum2) ++{ ++ const EVP_MD *md; ++ ++ /* RFC 4556 doesn't say what error to return if the checksum doesn't match. ++ * Windows returns this one. */ ++ if (!check_digest(body, EVP_sha1(), cksum1)) ++ return KRB5KRB_AP_ERR_MODIFIED; ++ ++ if (cksum2 == NULL) ++ return 0; ++ ++ md = md_from_cms_oid(&cksum2->algorithmIdentifier.algorithm); ++ if (!check_digest(body, md, &cksum2->checksum)) ++ return KRB5KRB_AP_ERR_MODIFIED; ++ ++ return 0; ++} +diff --git a/src/plugins/preauth/pkinit/pkinit_kdf_test.c b/src/plugins/preauth/pkinit/pkinit_kdf_test.c +index 99c93ac128..dd6e8d7503 100644 +--- a/src/plugins/preauth/pkinit/pkinit_kdf_test.c ++++ b/src/plugins/preauth/pkinit/pkinit_kdf_test.c +@@ -126,7 +126,7 @@ main(int argc, char **argv) + + /* TEST 1: SHA-1/AES */ + /* set up algorithm id */ +- alg_id.algorithm = sha1_id; ++ alg_id.algorithm = kdf_sha1_id; + + enctype = enctype_aes; + +@@ -157,7 +157,7 @@ main(int argc, char **argv) + + /* TEST 2: SHA-256/AES */ + /* set up algorithm id */ +- alg_id.algorithm = sha256_id; ++ alg_id.algorithm = kdf_sha256_id; + + enctype = enctype_aes; + +diff --git a/src/plugins/preauth/pkinit/pkinit_lib.c b/src/plugins/preauth/pkinit/pkinit_lib.c +index 25965eb5d2..891f47fd26 100644 +--- a/src/plugins/preauth/pkinit/pkinit_lib.c ++++ b/src/plugins/preauth/pkinit/pkinit_lib.c +@@ -29,6 +29,7 @@ + * SUCH DAMAGES. + */ + ++#include "k5-int.h" + #include "pkinit.h" + + #define FAKECERT +@@ -119,8 +120,9 @@ free_krb5_auth_pack(krb5_auth_pack **in) + { + if ((*in) == NULL) return; + krb5_free_data_contents(NULL, &(*in)->clientPublicValue); +- free((*in)->pkAuthenticator.paChecksum.contents); ++ free((*in)->pkAuthenticator.paChecksum.data); + krb5_free_data(NULL, (*in)->pkAuthenticator.freshnessToken); ++ free_pachecksum2(NULL, &(*in)->pkAuthenticator.paChecksum2); + if ((*in)->supportedCMSTypes != NULL) + free_krb5_algorithm_identifiers(&((*in)->supportedCMSTypes)); + if ((*in)->supportedKDFs) { +@@ -196,6 +198,18 @@ free_krb5_kdc_dh_key_info(krb5_kdc_dh_key_info **in) + free(*in); + } + ++void ++free_pachecksum2(krb5_context context, krb5_pachecksum2 **in) ++{ ++ if (*in == NULL) ++ return; ++ krb5_free_data_contents(context, &(*in)->checksum); ++ krb5_free_data_contents(context, &(*in)->algorithmIdentifier.algorithm); ++ krb5_free_data_contents(context, &(*in)->algorithmIdentifier.parameters); ++ free(*in); ++ *in = NULL; ++} ++ + void + init_krb5_pa_pk_as_req(krb5_pa_pk_as_req **in) + { +diff --git a/src/plugins/preauth/pkinit/pkinit_srv.c b/src/plugins/preauth/pkinit/pkinit_srv.c +index e22bcb195b..f558308483 100644 +--- a/src/plugins/preauth/pkinit/pkinit_srv.c ++++ b/src/plugins/preauth/pkinit/pkinit_srv.c +@@ -428,11 +428,12 @@ pkinit_server_verify_padata(krb5_context context, + krb5_data authp_data = {0, 0, NULL}, krb5_authz = {0, 0, NULL}; + krb5_pa_pk_as_req *reqp = NULL; + krb5_auth_pack *auth_pack = NULL; ++ krb5_pk_authenticator *pka; + pkinit_kdc_context plgctx = NULL; + pkinit_kdc_req_context reqctx = NULL; + krb5_checksum cksum = {0, 0, 0, NULL}; + krb5_data *der_req = NULL; +- krb5_data k5data, *ftoken; ++ krb5_data k5data; + int is_signed = 1; + krb5_pa_data **e_data = NULL; + krb5_kdcpreauth_modreq modreq = NULL; +@@ -524,8 +525,9 @@ pkinit_server_verify_padata(krb5_context context, + pkiDebug("failed to decode krb5_auth_pack\n"); + goto cleanup; + } ++ pka = &auth_pack->pkAuthenticator; + +- retval = krb5_check_clockskew(context, auth_pack->pkAuthenticator.ctime); ++ retval = krb5_check_clockskew(context, pka->ctime); + if (retval) + goto cleanup; + +@@ -548,36 +550,14 @@ pkinit_server_verify_padata(krb5_context context, + goto cleanup; + } + der_req = cb->request_body(context, rock); +- retval = krb5_c_make_checksum(context, CKSUMTYPE_SHA1, NULL, 0, der_req, +- &cksum); +- if (retval) { +- pkiDebug("unable to calculate AS REQ checksum\n"); +- goto cleanup; +- } +- if (cksum.length != auth_pack->pkAuthenticator.paChecksum.length || +- k5_bcmp(cksum.contents, auth_pack->pkAuthenticator.paChecksum.contents, +- cksum.length) != 0) { +- pkiDebug("failed to match the checksum\n"); +-#ifdef DEBUG_CKSUM +- pkiDebug("calculating checksum on buf size (%d)\n", req_pkt->length); +- print_buffer(req_pkt->data, req_pkt->length); +- pkiDebug("received checksum type=%d size=%d ", +- auth_pack->pkAuthenticator.paChecksum.checksum_type, +- auth_pack->pkAuthenticator.paChecksum.length); +- print_buffer(auth_pack->pkAuthenticator.paChecksum.contents, +- auth_pack->pkAuthenticator.paChecksum.length); +- pkiDebug("expected checksum type=%d size=%d ", +- cksum.checksum_type, cksum.length); +- print_buffer(cksum.contents, cksum.length); +-#endif + +- retval = KRB5KDC_ERR_PA_CHECKSUM_MUST_BE_INCLUDED; ++ retval = crypto_verify_checksums(context, der_req, &pka->paChecksum, ++ pka->paChecksum2); ++ if (retval) + goto cleanup; +- } + +- ftoken = auth_pack->pkAuthenticator.freshnessToken; +- if (ftoken != NULL) { +- retval = cb->check_freshness_token(context, rock, ftoken); ++ if (pka->freshnessToken != NULL) { ++ retval = cb->check_freshness_token(context, rock, pka->freshnessToken); + if (retval) + goto cleanup; + valid_freshness_token = TRUE; +diff --git a/src/plugins/preauth/pkinit/pkinit_trace.h b/src/plugins/preauth/pkinit/pkinit_trace.h +index 1faa6816d7..7b68d4b3b1 100644 +--- a/src/plugins/preauth/pkinit/pkinit_trace.h ++++ b/src/plugins/preauth/pkinit/pkinit_trace.h +@@ -58,8 +58,9 @@ + TRACE(c, "PKINIT client verified DH reply") + #define TRACE_PKINIT_CLIENT_REP_DH_FAIL(c) \ + TRACE(c, "PKINIT client could not verify DH reply") +-#define TRACE_PKINIT_CLIENT_REQ_CHECKSUM(c, cksum) \ +- TRACE(c, "PKINIT client computed kdc-req-body checksum {cksum}", cksum) ++#define TRACE_PKINIT_CLIENT_REQ_CHECKSUMS(c, ck1, ck2) \ ++ TRACE(c, "PKINIT client computed checksums: {hexdata} {hexdata}", \ ++ ck1, &(ck2)->checksum) + #define TRACE_PKINIT_CLIENT_REQ_DH(c) \ + TRACE(c, "PKINIT client making DH request") + #define TRACE_PKINIT_CLIENT_SAN_CONFIG_DNSNAME(c, host) \ +diff --git a/src/tests/asn.1/krb5_decode_test.c b/src/tests/asn.1/krb5_decode_test.c +index 2fa6dce8eb..f47849abad 100644 +--- a/src/tests/asn.1/krb5_decode_test.c ++++ b/src/tests/asn.1/krb5_decode_test.c +@@ -1174,7 +1174,7 @@ main(int argc, char **argv) + /* decode_krb5_auth_pack */ + { + setup(krb5_auth_pack,ktest_make_sample_auth_pack); +- decode_run("krb5_auth_pack","","30 81 85 A0 35 30 33 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61", ++ decode_run("krb5_auth_pack","","30 81 89 A0 39 30 37 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61", + acc.decode_krb5_auth_pack, + ktest_equal_auth_pack,ktest_free_auth_pack); + ktest_empty_auth_pack(&ref); +diff --git a/src/tests/asn.1/ktest.c b/src/tests/asn.1/ktest.c +index d37e4fa7e6..7f54aa3184 100644 +--- a/src/tests/asn.1/ktest.c ++++ b/src/tests/asn.1/ktest.c +@@ -700,9 +700,7 @@ ktest_make_sample_pk_authenticator(krb5_pk_authenticator *p) + p->cusec = SAMPLE_USEC; + p->ctime = SAMPLE_TIME; + p->nonce = SAMPLE_NONCE; +- ktest_make_sample_checksum(&p->paChecksum); +- /* We don't encode the checksum type, only the contents. */ +- p->paChecksum.checksum_type = 0; ++ ktest_make_sample_data(&p->paChecksum); + p->freshnessToken = ealloc(sizeof(krb5_data)); + ktest_make_sample_data(p->freshnessToken); + } +@@ -1604,8 +1602,7 @@ ktest_empty_pa_otp_req(krb5_pa_otp_req *p) + static void + ktest_empty_pk_authenticator(krb5_pk_authenticator *p) + { +- ktest_empty_checksum(&p->paChecksum); +- p->paChecksum.contents = NULL; ++ ktest_empty_data(&p->paChecksum); + krb5_free_data(NULL, p->freshnessToken); + p->freshnessToken = NULL; + } +diff --git a/src/tests/asn.1/ktest_equal.c b/src/tests/asn.1/ktest_equal.c +index b48a0285d2..13786dd1e5 100644 +--- a/src/tests/asn.1/ktest_equal.c ++++ b/src/tests/asn.1/ktest_equal.c +@@ -844,7 +844,7 @@ ktest_equal_pk_authenticator(krb5_pk_authenticator *ref, + p = p && scalar_equal(cusec); + p = p && scalar_equal(ctime); + p = p && scalar_equal(nonce); +- p = p && struct_equal(paChecksum, ktest_equal_checksum); ++ p = p && data_eq(ref->paChecksum, var->paChecksum); + return p; + } + +diff --git a/src/tests/asn.1/pkinit_encode.out b/src/tests/asn.1/pkinit_encode.out +index 6ec7aaa36a..a764182e15 100644 +--- a/src/tests/asn.1/pkinit_encode.out ++++ b/src/tests/asn.1/pkinit_encode.out +@@ -1,7 +1,7 @@ + encode_krb5_pa_pk_as_req: 30 38 80 08 6B 72 62 35 64 61 74 61 A1 22 30 20 30 1E 80 08 6B 72 62 35 64 61 74 61 81 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61 82 08 6B 72 62 35 64 61 74 61 + encode_krb5_pa_pk_as_rep(dhInfo): A0 28 30 26 80 08 6B 72 62 35 64 61 74 61 A1 0A 04 08 6B 72 62 35 64 61 74 61 A2 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61 + encode_krb5_pa_pk_as_rep(encKeyPack): 81 08 6B 72 62 35 64 61 74 61 +-encode_krb5_auth_pack: 30 81 85 A0 35 30 33 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 06 04 04 31 32 33 34 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61 ++encode_krb5_auth_pack: 30 81 89 A0 39 30 37 A0 05 02 03 01 E2 40 A1 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A A2 03 02 01 2A A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 0A 04 08 6B 72 62 35 64 61 74 61 A1 08 04 06 70 76 61 6C 75 65 A2 24 30 22 30 13 06 09 2A 86 48 86 F7 12 01 02 02 04 06 70 61 72 61 6D 73 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A3 0A 04 08 6B 72 62 35 64 61 74 61 A4 10 30 0E 30 0C A0 0A 06 08 6B 72 62 35 64 61 74 61 + encode_krb5_kdc_dh_key_info: 30 25 A0 0B 03 09 00 6B 72 62 35 64 61 74 61 A1 03 02 01 2A A2 11 18 0F 31 39 39 34 30 36 31 30 30 36 30 33 31 37 5A + encode_krb5_reply_key_pack: 30 26 A0 13 30 11 A0 03 02 01 01 A1 0A 04 08 31 32 33 34 35 36 37 38 A1 0F 30 0D A0 03 02 01 01 A1 06 04 04 31 32 33 34 + encode_krb5_sp80056a_other_info: 30 81 81 30 0B 06 09 2A 86 48 86 F7 12 01 02 02 A0 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A1 32 04 30 30 2E A0 10 1B 0E 41 54 48 45 4E 41 2E 4D 49 54 2E 45 44 55 A1 1A 30 18 A0 03 02 01 01 A1 11 30 0F 1B 06 68 66 74 73 61 69 1B 05 65 78 74 72 61 A2 0A 04 08 6B 72 62 35 64 61 74 61 +diff --git a/src/tests/asn.1/pkinit_trval.out b/src/tests/asn.1/pkinit_trval.out +index 46f4a34108..c47bd71f67 100644 +--- a/src/tests/asn.1/pkinit_trval.out ++++ b/src/tests/asn.1/pkinit_trval.out +@@ -38,7 +38,7 @@ encode_krb5_auth_pack: + . . [0] [Integer] 123456 + . . [1] [Generalized Time] "19940610060317Z" + . . [2] [Integer] 42 +-. . [3] [Octet String] "1234" ++. . [3] [Octet String] "krb5data" + . . [4] [Octet String] "krb5data" + . [1] [Octet String] "pvalue" + . [2] [Sequence/Sequence Of] +-- +2.49.0 + diff --git a/0038-downstream-Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch b/0038-downstream-Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch new file mode 100644 index 0000000..4b49867 --- /dev/null +++ b/0038-downstream-Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch @@ -0,0 +1,381 @@ +From 33afd2a6cfdf87d153170b41fbabfb92be49c422 Mon Sep 17 00:00:00 2001 +From: Julien Rische +Date: Thu, 10 Apr 2025 10:04:22 +0200 +Subject: [PATCH] [downstream] Do not block HMAC-MD4/5 in FIPS mode + +To ensure RC4 HMAC-MD5 was not used in FIPS mode, access to HMAC-MD4/5 +was not allowed in this mode. However, since we provide the +"radius_md5_fips_override" configuration parameter to allow using RADIUS +regardless to the FIPS restrictions, we should allow HMAC-MD5 to be used +too in this case, because it is required for the newly supported +Message-Authenticator attribute. + +A FIPS mode check is added in calculate_mac() which will fail if +"radius_md5_fips_override" is not true. It will not affect interactions +between krb5kdc and ipa-otpd, because the Message-Authenticator +attribute is not generated in this case. +--- + src/lib/crypto/krb/crypto_int.h | 9 +++ + src/lib/crypto/openssl/Makefile.in | 9 ++- + src/lib/crypto/openssl/common.c | 80 +++++++++++++++++++ + .../crypto/openssl/hash_provider/hash_evp.c | 62 ++------------ + src/lib/crypto/openssl/hmac.c | 15 ++-- + src/lib/krad/packet.c | 19 +++-- + 6 files changed, 120 insertions(+), 74 deletions(-) + create mode 100644 src/lib/crypto/openssl/common.c + +diff --git a/src/lib/crypto/krb/crypto_int.h b/src/lib/crypto/krb/crypto_int.h +index 1ee4b30e02..ff67b6bd35 100644 +--- a/src/lib/crypto/krb/crypto_int.h ++++ b/src/lib/crypto/krb/crypto_int.h +@@ -36,6 +36,9 @@ + + #include + #if OPENSSL_VERSION_NUMBER >= 0x30000000L ++ ++#include ++ + /* + * OpenSSL 3.0 relegates MD4 and RC4 to the legacy provider, which must be + * explicitly loaded into a library context. Performing this loading within a +@@ -660,4 +663,10 @@ iov_cursor_advance(struct iov_cursor *c, size_t nblocks) + c->out_pos += nblocks * c->block_size; + } + ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++ ++krb5_error_code k5_get_ossl_legacy_libctx(OSSL_LIB_CTX **libctx); ++ ++#endif /* OPENSSL_VERSION_NUMBER >= 0x30000000L */ ++ + #endif /* CRYPTO_INT_H */ +diff --git a/src/lib/crypto/openssl/Makefile.in b/src/lib/crypto/openssl/Makefile.in +index 8e4cdb8bbf..cc131000bd 100644 +--- a/src/lib/crypto/openssl/Makefile.in ++++ b/src/lib/crypto/openssl/Makefile.in +@@ -8,21 +8,24 @@ STLIBOBJS=\ + hmac.o \ + kdf.o \ + pbkdf2.o \ +- sha256.o ++ sha256.o \ ++ common.o + + OBJS=\ + $(OUTPRE)cmac.$(OBJEXT) \ + $(OUTPRE)hmac.$(OBJEXT) \ + $(OUTPRE)kdf.$(OBJEXT) \ + $(OUTPRE)pbkdf2.$(OBJEXT) \ +- $(OUTPRE)sha256.$(OBJEXT) ++ $(OUTPRE)sha256.$(OBJEXT) \ ++ $(OUTPRE)common.$(OBJEXT) + + SRCS=\ + $(srcdir)/cmac.c \ + $(srcdir)/hmac.c \ + $(srcdir)/kdf.c \ + $(srcdir)/pbkdf2.c \ +- $(srcdir)/sha256.c ++ $(srcdir)/sha256.c \ ++ $(srcdir)/common.c + + SUBDIROBJLISTS= md4/OBJS.ST \ + md5/OBJS.ST sha1/OBJS.ST sha2/OBJS.ST \ +diff --git a/src/lib/crypto/openssl/common.c b/src/lib/crypto/openssl/common.c +new file mode 100644 +index 0000000000..ced43fd54c +--- /dev/null ++++ b/src/lib/crypto/openssl/common.c +@@ -0,0 +1,80 @@ ++#include "crypto_int.h" ++ ++#if OPENSSL_VERSION_NUMBER >= 0x30000000L ++ ++#include ++#include ++#include ++#include ++ ++typedef struct ossl_legacy_context { ++ bool initialized; ++ OSSL_LIB_CTX *libctx; ++ OSSL_PROVIDER *default_provider; ++ OSSL_PROVIDER *legacy_provider; ++} ossl_legacy_context_t; ++ ++static thread_local ossl_legacy_context_t g_ossl_legacy_ctx; ++ ++static krb5_error_code ++init_ossl_legacy_ctx(ossl_legacy_context_t *ctx) ++{ ++ ctx->libctx = OSSL_LIB_CTX_new(); ++ if (!ctx->libctx) ++ return KRB5_CRYPTO_INTERNAL; ++ ++ /* Load both legacy and default provider as both may be needed. */ ++ ctx->default_provider = OSSL_PROVIDER_load(ctx->libctx, "default"); ++ ctx->legacy_provider = OSSL_PROVIDER_load(ctx->libctx, "legacy"); ++ ++ if (!(ctx->default_provider && ctx->legacy_provider)) ++ return KRB5_CRYPTO_INTERNAL; ++ ++ ctx->initialized = true; ++ return 0; ++} ++ ++static void ++deinit_ossl_legacy_ctx(ossl_legacy_context_t *ctx) ++{ ++ if (ctx->legacy_provider) ++ OSSL_PROVIDER_unload(ctx->legacy_provider); ++ ++ if (ctx->default_provider) ++ OSSL_PROVIDER_unload(ctx->default_provider); ++ ++ if (ctx->libctx) ++ OSSL_LIB_CTX_free(ctx->libctx); ++ ++ ctx->initialized = false; ++} ++ ++krb5_error_code ++k5_get_ossl_legacy_libctx(OSSL_LIB_CTX **libctx) ++{ ++ krb5_error_code err; ++ ++ if (!FIPS_mode()) { ++ if (libctx) ++ *libctx = NULL; ++ err = 0; ++ goto end; ++ } ++ ++ if (!g_ossl_legacy_ctx.initialized) { ++ err = init_ossl_legacy_ctx(&g_ossl_legacy_ctx); ++ if (err) { ++ deinit_ossl_legacy_ctx(&g_ossl_legacy_ctx); ++ goto end; ++ } ++ } ++ ++ if (libctx) ++ *libctx = g_ossl_legacy_ctx.libctx; ++ err = 0; ++ ++end: ++ return err; ++} ++ ++#endif /* OPENSSL_VERSION_NUMBER >= 0x30000000L */ +diff --git a/src/lib/crypto/openssl/hash_provider/hash_evp.c b/src/lib/crypto/openssl/hash_provider/hash_evp.c +index eb2e693e9f..2fd5d383d6 100644 +--- a/src/lib/crypto/openssl/hash_provider/hash_evp.c ++++ b/src/lib/crypto/openssl/hash_provider/hash_evp.c +@@ -44,48 +44,7 @@ + #define EVP_MD_CTX_free EVP_MD_CTX_destroy + #endif + +-#include + #include +-#include +- +-typedef struct ossl_lib_md_context { +- OSSL_LIB_CTX *libctx; +- OSSL_PROVIDER *default_provider; +- OSSL_PROVIDER *legacy_provider; +-} ossl_md_context_t; +- +-static thread_local ossl_md_context_t *ossl_md_ctx = NULL; +- +-static krb5_error_code +-init_ossl_md_ctx(ossl_md_context_t *ctx, const char *algo) +-{ +- ctx->libctx = OSSL_LIB_CTX_new(); +- if (!ctx->libctx) +- return KRB5_CRYPTO_INTERNAL; +- +- /* Load both legacy and default provider as both may be needed. */ +- ctx->default_provider = OSSL_PROVIDER_load(ctx->libctx, "default"); +- ctx->legacy_provider = OSSL_PROVIDER_load(ctx->libctx, "legacy"); +- +- if (!(ctx->default_provider && ctx->legacy_provider)) +- return KRB5_CRYPTO_INTERNAL; +- +- return 0; +-} +- +-static void +-deinit_ossl_ctx(ossl_md_context_t *ctx) +-{ +- if (ctx->legacy_provider) +- OSSL_PROVIDER_unload(ctx->legacy_provider); +- +- if (ctx->default_provider) +- OSSL_PROVIDER_unload(ctx->default_provider); +- +- if (ctx->libctx) +- OSSL_LIB_CTX_free(ctx->libctx); +-} +- + + static krb5_error_code + hash_evp(const EVP_MD *type, const krb5_crypto_iov *data, size_t num_data, +@@ -120,25 +79,14 @@ hash_legacy_evp(const char *algo, const krb5_crypto_iov *data, size_t num_data, + krb5_data *output) + { + krb5_error_code err; ++ OSSL_LIB_CTX *ossl_libctx; + EVP_MD *md = NULL; + +- if (!ossl_md_ctx) { +- ossl_md_ctx = malloc(sizeof(ossl_md_context_t)); +- if (!ossl_md_ctx) { +- err = ENOMEM; +- goto end; +- } +- +- err = init_ossl_md_ctx(ossl_md_ctx, algo); +- if (err) { +- deinit_ossl_ctx(ossl_md_ctx); +- free(ossl_md_ctx); +- ossl_md_ctx = NULL; +- goto end; +- } +- } ++ err = k5_get_ossl_legacy_libctx(&ossl_libctx); ++ if (err) ++ goto end; + +- md = EVP_MD_fetch(ossl_md_ctx->libctx, algo, NULL); ++ md = EVP_MD_fetch(ossl_libctx, algo, NULL); + if (!md) { + err = KRB5_CRYPTO_INTERNAL; + goto end; +diff --git a/src/lib/crypto/openssl/hmac.c b/src/lib/crypto/openssl/hmac.c +index 25a419d73a..8f9e88fec9 100644 +--- a/src/lib/crypto/openssl/hmac.c ++++ b/src/lib/crypto/openssl/hmac.c +@@ -59,7 +59,6 @@ + #if OPENSSL_VERSION_NUMBER >= 0x30000000L + #include + #include +-#include + #else + #include + #endif +@@ -112,11 +111,7 @@ map_digest(const struct krb5_hash_provider *hash) + return EVP_sha256(); + else if (hash == &krb5int_hash_sha384) + return EVP_sha384(); +- +- if (FIPS_mode()) +- return NULL; +- +- if (hash == &krb5int_hash_md5) ++ else if (hash == &krb5int_hash_md5) + return EVP_md5(); + else if (hash == &krb5int_hash_md4) + return EVP_md4(); +@@ -138,13 +133,19 @@ krb5int_hmac_keyblock(const struct krb5_hash_provider *hash, + EVP_MAC_CTX *ctx = NULL; + OSSL_PARAM params[2], *p = params; + size_t i = 0, md_len; ++ OSSL_LIB_CTX *ossl_libctx; ++ krb5_error_code err; + + if (md == NULL || keyblock->length > hash->blocksize) + return KRB5_CRYPTO_INTERNAL; + if (output->length < hash->hashsize) + return KRB5_BAD_MSIZE; + +- mac = EVP_MAC_fetch(NULL, "HMAC", NULL); ++ err = k5_get_ossl_legacy_libctx(&ossl_libctx); ++ if (err) ++ return err; ++ ++ mac = EVP_MAC_fetch(ossl_libctx, "HMAC", NULL); + if (mac == NULL) + return KRB5_CRYPTO_INTERNAL; + +diff --git a/src/lib/krad/packet.c b/src/lib/krad/packet.c +index 3c1a4d507e..b95c99df65 100644 +--- a/src/lib/krad/packet.c ++++ b/src/lib/krad/packet.c +@@ -278,7 +278,7 @@ lookup_msgauth_addr(const krad_packet *pkt) + * auth, which may be from pkt or from a corresponding request. + */ + static krb5_error_code +-calculate_mac(const char *secret, const krad_packet *pkt, ++calculate_mac(krb5_context ctx, const char *secret, const krad_packet *pkt, + const uint8_t auth[AUTH_FIELD_SIZE], + uint8_t mac_out[MD5_DIGEST_SIZE]) + { +@@ -288,6 +288,10 @@ calculate_mac(const char *secret, const krad_packet *pkt, + krb5_crypto_iov input[5]; + krb5_data ksecr, mac; + ++ /* Do not use HMAC-MD5 if not explicitly allowed */ ++ if (kr_use_fips(ctx)) ++ return KRB5_CRYPTO_INTERNAL; ++ + msgauth_attr = lookup_msgauth_addr(pkt); + if (msgauth_attr == NULL) + return EINVAL; +@@ -393,7 +397,8 @@ krad_packet_new_request(krb5_context ctx, const char *secret, krad_code code, + + if (msgauth_required) { + /* Calculate and set the Message-Authenticator MAC. */ +- retval = calculate_mac(secret, pkt, pkt_auth(pkt), pkt_attr(pkt) + 2); ++ retval = calculate_mac(ctx, secret, pkt, pkt_auth(pkt), ++ pkt_attr(pkt) + 2); + if (retval != 0) + goto error; + } +@@ -454,7 +459,7 @@ krad_packet_new_response(krb5_context ctx, const char *secret, krad_code code, + * section 5.14, use the authenticator from the request, not from the + * response. + */ +- retval = calculate_mac(secret, pkt, pkt_auth(request), ++ retval = calculate_mac(ctx, secret, pkt, pkt_auth(request), + pkt_attr(pkt) + 2); + if (retval != 0) + goto error; +@@ -476,7 +481,7 @@ error: + /* Verify the Message-Authenticator value in pkt, using the provided + * authenticator (which may be from pkt or from a corresponding request). */ + static krb5_error_code +-verify_msgauth(const char *secret, const krad_packet *pkt, ++verify_msgauth(krb5_context ctx, const char *secret, const krad_packet *pkt, + const uint8_t auth[AUTH_FIELD_SIZE]) + { + uint8_t mac[MD5_DIGEST_SIZE]; +@@ -488,7 +493,7 @@ verify_msgauth(const char *secret, const krad_packet *pkt, + if (msgauth == NULL) + return ENODATA; + +- retval = calculate_mac(secret, pkt, auth, mac); ++ retval = calculate_mac(ctx, secret, pkt, auth, mac); + if (retval) + return retval; + +@@ -561,7 +566,7 @@ krad_packet_decode_request(krb5_context ctx, const char *secret, + + /* Verify Message-Authenticator if present. */ + if (has_pkt_msgauth(req)) { +- retval = verify_msgauth(secret, req, pkt_auth(req)); ++ retval = verify_msgauth(ctx, secret, req, pkt_auth(req)); + if (retval) { + krad_packet_free(req); + return retval; +@@ -613,7 +618,7 @@ krad_packet_decode_response(krb5_context ctx, const char *secret, + + /* Verify Message-Authenticator if present. */ + if (has_pkt_msgauth(*rsppkt)) { +- if (verify_msgauth(secret, *rsppkt, pkt_auth(tmp)) != 0) ++ if (verify_msgauth(ctx, secret, *rsppkt, pkt_auth(tmp)) != 0) + continue; + } + +-- +2.49.0 + diff --git a/kdc.conf b/kdc.conf index c504e58..7b788e5 100644 --- a/kdc.conf +++ b/kdc.conf @@ -1,3 +1,7 @@ +[libdefaults] +# Allow RC4 HMAC-MD5 for session keys (see CVE-2022-37966) +#allow_rc4 = true + [kdcdefaults] kdc_ports = 88 kdc_tcp_ports = 88 diff --git a/krb5.spec b/krb5.spec index 963df35..ee6f6bc 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 5 +%global baserelease 6 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -93,6 +93,10 @@ Patch0031: 0031-Support-PKCS11-EC-client-certs-in-PKINIT.patch Patch0032: 0032-Improve-PKCS11-error-reporting-in-PKINIT.patch Patch0033: 0033-Set-missing-mask-flags-for-kdb5_util-operations.patch Patch0034: 0034-Prevent-overflow-when-calculating-ulog-block-size.patch +Patch0035: 0035-Don-t-issue-session-keys-with-deprecated-enctypes.patch +Patch0036: 0036-downstream-Remove-3des-support-cumulative-1.patch +Patch0037: 0037-Add-PKINIT-paChecksum2-from-MS-PKCA-v20230920.patch +Patch0038: 0038-downstream-Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch License: Brian-Gladman-2-Clause AND BSD-2-Clause AND (BSD-2-Clause OR GPL-2.0-or-later) AND BSD-2-Clause-first-lines AND BSD-3-Clause AND BSD-4-Clause AND CMU-Mach-nodoc AND FSFULLRWD AND HPND AND HPND-export2-US AND HPND-export-US AND HPND-export-US-acknowledgement AND HPND-export-US-modify AND ISC AND MIT AND MIT-CMU AND OLDAP-2.8 AND OpenVision URL: https://web.mit.edu/kerberos/www/ @@ -527,14 +531,16 @@ install -pdm 755 $RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch} pushd src cp -p --parents -t "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/" \ $(find . -type f -exec file -i "{}" + \ - | sed -ne 's|^\./\([^:]\+\): \+text/.\+$|\1|p' | grep -Ev '~$') + | sed -n \ + -e 's|^\./\([^:]\+\): \+text/.\+$|\1|p' \ + -e 's|^\./\([^:]\+\): \+application/x-pem-file.\+$|\1|p' \ + -e 's|^\./\([^:]\+\): \+application/json.\+$|\1|p' \ + | grep -Ev '~$') popd # Copy binary test files install -pm 644 src/tests/pkinit-certs/*.p12 \ "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/tests/pkinit-certs/" -install -pm 644 src/tests/au_dict.json \ - "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/tests/" # Unset executable bit if no shebang in script for f in $(find "$RPM_BUILD_ROOT%{_datarootdir}/%{name}-tests/%{_arch}/" -type f -executable) @@ -736,6 +742,14 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Wed Jun 04 2025 Julien Rische - 1.21.3-6 +- Do not block HMAC-MD4/5 in FIPS mode + Resolves: rhbz#2370259 +- PKINIT: implement paChecksum2 from MS-PKCA v20230920 + Resolves: rhbz#2357215 +- Disallow RC4 HMAC-MD5 session keys by default (CVE-2025-3576) + Resolves: rhbz#2359705 + * Wed Jan 29 2025 Julien Rische - 1.21.3-5 - Prevent overflow when calculating ulog block size (CVE-2025-24528) Resolves: rhbz#2342798 From a0a34794e3406590da2b40a34e2a0f976a2fdbdc Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 24 Jul 2025 18:57:33 +0000 Subject: [PATCH 300/304] Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild --- krb5.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/krb5.spec b/krb5.spec index ee6f6bc..a40d0d6 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 6 +%global baserelease 7 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -742,6 +742,9 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Thu Jul 24 2025 Fedora Release Engineering - 1.21.3-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + * Wed Jun 04 2025 Julien Rische - 1.21.3-6 - Do not block HMAC-MD4/5 in FIPS mode Resolves: rhbz#2370259 From fb94528750570f9ba4a7bba81780c37a329b1a16 Mon Sep 17 00:00:00 2001 From: Alexander Bokovoy Date: Sun, 21 Sep 2025 16:54:16 +0300 Subject: [PATCH 301/304] Test automated FAST channel acquisition during TGS-REQ Upstream PR: https://github.com/krb5/krb5/pull/1447 It can be tested by using fedora-packager-kerberos from Rawhide against Fedora KDC. If packagers have OTP tokens enabled, kinit will automatically propose to enter password+OTP token value. Signed-off-by: Alexander Bokovoy --- 0040-automated-fast.patch | 223 ++++++++++++++++++++++++++++++++++++++ krb5.spec | 8 +- 2 files changed, 230 insertions(+), 1 deletion(-) create mode 100644 0040-automated-fast.patch diff --git a/0040-automated-fast.patch b/0040-automated-fast.patch new file mode 100644 index 0000000..7094309 --- /dev/null +++ b/0040-automated-fast.patch @@ -0,0 +1,223 @@ +From 76d8eb3814067980cfad31b6c3cc653c5bfbbe9b Mon Sep 17 00:00:00 2001 +From: Alexander Bokovoy +Date: Sun, 21 Sep 2025 11:14:51 +0300 +Subject: [PATCH] libkrb5: in case PKINIT is configured, attempt Anonymous + PKINIT for FAST + +If auto_fast_armor is configured for the realm or globally, optimistically +assume that Anonymous PKINIT is supported as well and try to obtain it for +FAST use in case no pre-made FAST channel was established by the caller. + +This behavior will automatically enable use of passwordless pre-authentication +methods which rely on FAST channel presence in deployments such as FreeIPA. + +Notably, Microsoft Active Directory KDCs do not support Anonymous PKINIT. For +these deployments only a machine account (host keytab) can be used to build a +FAST channel. However, libkrb5 does not have access to /etc/krb5.keytab in a +general case. + +Signed-off-by: Alexander Bokovoy +--- + src/lib/krb5/krb/fast.c | 118 ++++++++++++++++++++++++++++++++++++++++ + src/lib/krb5/krb/fast.h | 2 + + src/man/krb5.conf.man | 13 +++++ + 3 files changed, 133 insertions(+) + +diff --git a/src/lib/krb5/krb/fast.c b/src/lib/krb5/krb/fast.c +index 62c9f0841f6..ee2e0818929 100644 +--- a/src/lib/krb5/krb/fast.c ++++ b/src/lib/krb5/krb/fast.c +@@ -168,6 +168,109 @@ krb5int_fast_prep_req_body(krb5_context context, + return retval; + } + ++static krb5_boolean ++fast_is_pkinit_allowed(krb5_context context, krb5_data *realm) ++{ ++ int value; ++ krb5_error_code retval = EINVAL; ++ char realmstr[1024]; ++ const char *option = "auto_fast_armor"; ++ const int def_value = FALSE; ++ ++ if (realm != NULL && realm->length > sizeof(realmstr)-1) ++ return FALSE; ++ ++ if (realm != NULL) { ++ strncpy(realmstr, realm->data, realm->length); ++ realmstr[realm->length] = '\0'; ++ ++ retval = profile_get_boolean(context->profile, ++ KRB5_CONF_REALMS, realmstr, ++ option, def_value, &value); ++ } ++ ++ return retval ? FALSE : value; ++ ++} ++ ++static krb5_error_code ++fast_acquire_pkinit_armor(krb5_context context, ++ struct krb5int_fast_request_state *state, ++ krb5_get_init_creds_opt *opt, krb5_kdc_req *request) ++{ ++ krb5_context ctx; ++ krb5_get_init_creds_opt *options = NULL; ++ krb5_error_code retval = 0; ++ krb5_data *target_realm = &request->server->realm; ++ krb5_creds creds; ++ krb5_principal anon_princ = NULL; ++ krb5_ccache out_cc; ++ ++ /* short circuit, we are asked to perform Anonymous PKINIT already */ ++ if (opt->flags & KRB5_GET_INIT_CREDS_OPT_ANONYMOUS) { ++ return EINVAL; ++ } ++ ++ /* skip realms which do not allow use of automated FAST armor */ ++ if (!fast_is_pkinit_allowed(context, target_realm)) { ++ return EINVAL; ++ } ++ ++ retval = krb5_init_context(&ctx); ++ if (retval != 0) { ++ return retval; ++ } ++ retval = krb5_get_init_creds_opt_alloc(ctx, &options); ++ if (retval != 0) { ++ goto cleanup; ++ } ++ krb5_get_init_creds_opt_set_anonymous(options, 1); ++ retval = krb5_cc_new_unique(ctx, "MEMORY", NULL, &out_cc); ++ if (retval != 0) { ++ goto cleanup; ++ } ++ ++ retval = krb5_get_init_creds_opt_set_out_ccache(ctx, options, out_cc); ++ if (retval != 0) { ++ goto cleanup; ++ } ++ ++ retval = krb5_build_principal_ext(ctx, &anon_princ, ++ target_realm->length, target_realm->data, ++ strlen(KRB5_WELLKNOWN_NAMESTR), ++ KRB5_WELLKNOWN_NAMESTR, ++ strlen(KRB5_ANONYMOUS_PRINCSTR), ++ KRB5_ANONYMOUS_PRINCSTR, 0); ++ if (retval != 0) { ++ goto cleanup; ++ } ++ ++ retval = krb5_get_init_creds_password(ctx, &creds, anon_princ, 0, ++ NULL /* no prompter */, NULL, ++ 0, NULL /* service name */, ++ options); ++ if (retval == 0) { ++ state->fast_state_flags |= KRB5INT_FAST_OWN_ARMOR; ++ state->armor_ccache = out_cc; ++ } ++cleanup: ++ if (retval != 0 && out_cc != NULL) { ++ (void) krb5_cc_destroy(ctx, out_cc); ++ } ++ if (retval == 0) { ++ krb5_free_cred_contents(ctx, &creds); ++ } ++ if (options != NULL) { ++ krb5_get_init_creds_opt_free(ctx, options); ++ } ++ if (anon_princ != NULL) { ++ krb5_free_principal(ctx, anon_princ); ++ } ++ krb5_free_context(ctx); ++ ++ return retval; ++} ++ + krb5_error_code + krb5int_fast_as_armor(krb5_context context, + struct krb5int_fast_request_state *state, +@@ -178,10 +281,20 @@ krb5int_fast_as_armor(krb5_context context, + krb5_principal target_principal = NULL; + krb5_data *target_realm; + const char *ccname = k5_gic_opt_get_fast_ccache_name(opt); ++ char *fast_ccname = NULL; + krb5_flags fast_flags; + + krb5_clear_error_message(context); + target_realm = &request->server->realm; ++ if (ccname == NULL) { ++ retval = fast_acquire_pkinit_armor(context, state, opt, request); ++ if (retval == 0) { ++ retval = krb5_cc_get_full_name(context, state->armor_ccache, &fast_ccname); ++ if (retval == 0 && fast_ccname != NULL) ++ ccname = fast_ccname; ++ } ++ retval = 0; ++ } + if (ccname != NULL) { + TRACE_FAST_ARMOR_CCACHE(context, ccname); + state->fast_state_flags |= KRB5INT_FAST_ARMOR_AVAIL; +@@ -220,6 +333,8 @@ krb5int_fast_as_armor(krb5_context context, + krb5_cc_close(context, ccache); + if (target_principal) + krb5_free_principal(context, target_principal); ++ if (fast_ccname) ++ free(fast_ccname); + return retval; + } + +@@ -615,6 +730,9 @@ krb5int_fast_free_state(krb5_context context, + /*We are responsible for none of the store in the fast_outer_req*/ + krb5_free_keyblock(context, state->armor_key); + krb5_free_fast_armor(context, state->armor); ++ if (state->fast_state_flags & KRB5INT_FAST_OWN_ARMOR) { ++ krb5_cc_destroy(context, state->armor_ccache); ++ } + free(state); + } + +diff --git a/src/lib/krb5/krb/fast.h b/src/lib/krb5/krb/fast.h +index 7156ea203f1..e5fe8bd5443 100644 +--- a/src/lib/krb5/krb/fast.h ++++ b/src/lib/krb5/krb/fast.h +@@ -34,6 +34,7 @@ struct krb5int_fast_request_state { + krb5_kdc_req fast_outer_request; + krb5_keyblock *armor_key; /*non-null means fast is in use*/ + krb5_fast_armor *armor; ++ krb5_ccache armor_ccache; + krb5_ui_4 fast_state_flags; + krb5_ui_4 fast_options; + krb5_int32 nonce; +@@ -41,6 +42,7 @@ struct krb5int_fast_request_state { + + #define KRB5INT_FAST_DO_FAST (1l<<0) /* Perform FAST */ + #define KRB5INT_FAST_ARMOR_AVAIL (1l<<1) ++#define KRB5INT_FAST_OWN_ARMOR (1l<<2) + + krb5_error_code + krb5int_fast_prep_req_body(krb5_context context, +diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man +index 6c0e9aff8c4..fc6ebec03a9 100644 +--- a/src/man/krb5.conf.man ++++ b/src/man/krb5.conf.man +@@ -650,6 +650,19 @@ primary KDC, in case the user\(aqs password has just been changed, and + the updated database has not been propagated to the replica + servers yet. New in release 1.19. + .TP ++\fBauto_fast_armor\fP ++If this flag is true, then initial ticket request will use Anonymous ++PKINIT to protect the communication as a FAST channel in case an application ++did not provide its own FAST channel.This is useful for deployments where ++pre-authentication methods require use of the FAST channel, such as ++passwordless methods provided by FreeIPA. Microsoft Active Directory ++implementation of PKINIT does not support Anonymous PKINIT feature. ++As a result, \fIauto_fast_armor\fP defaults to false. ++.sp ++Use of \fIauto_fast_armor = true\fP requires properly configured PKINIT and ++WELLKNOWN/ANONYMOUS principal defined on the KDC side. Consult KDC documentation ++for details. ++.TP + \fBv4_instance_convert\fP + This subsection allows the administrator to configure exceptions + to the \fBdefault_domain\fP mapping rule. It contains V4 instances diff --git a/krb5.spec b/krb5.spec index a40d0d6..bfdfbe4 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 7 +%global baserelease 8 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -97,6 +97,7 @@ Patch0035: 0035-Don-t-issue-session-keys-with-deprecated-enctypes.patch Patch0036: 0036-downstream-Remove-3des-support-cumulative-1.patch Patch0037: 0037-Add-PKINIT-paChecksum2-from-MS-PKCA-v20230920.patch Patch0038: 0038-downstream-Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch +Patch0040: 0040-automated-fast.patch License: Brian-Gladman-2-Clause AND BSD-2-Clause AND (BSD-2-Clause OR GPL-2.0-or-later) AND BSD-2-Clause-first-lines AND BSD-3-Clause AND BSD-4-Clause AND CMU-Mach-nodoc AND FSFULLRWD AND HPND AND HPND-export2-US AND HPND-export-US AND HPND-export-US-acknowledgement AND HPND-export-US-modify AND ISC AND MIT AND MIT-CMU AND OLDAP-2.8 AND OpenVision URL: https://web.mit.edu/kerberos/www/ @@ -742,6 +743,11 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Fri Sep 26 2025 Alexander Bokovoy - 1.21.3-8 +- Add automated FAST channel for kinit +- https://github.com/krb5/krb5/pull/1447 - work in progress + + * Thu Jul 24 2025 Fedora Release Engineering - 1.21.3-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild From 53c3b9de3c1fdac923a38c41b46b6cd2728ea0bc Mon Sep 17 00:00:00 2001 From: Alexander Bokovoy Date: Wed, 15 Oct 2025 08:44:31 +0300 Subject: [PATCH 302/304] Reject pre-authentication that requries a prompter if no prompter was provided Resolves: rhbz#2403513 Signed-off-by: Alexander Bokovoy --- 0040-automated-fast.patch | 64 +++++++++++++++++++++++++++++++++++---- krb5.spec | 6 +++- 2 files changed, 63 insertions(+), 7 deletions(-) diff --git a/0040-automated-fast.patch b/0040-automated-fast.patch index 7094309..e9665d5 100644 --- a/0040-automated-fast.patch +++ b/0040-automated-fast.patch @@ -1,7 +1,7 @@ -From 76d8eb3814067980cfad31b6c3cc653c5bfbbe9b Mon Sep 17 00:00:00 2001 +From 3baf9b93dc1dfe38585722c71d7268304cb4a01a Mon Sep 17 00:00:00 2001 From: Alexander Bokovoy Date: Sun, 21 Sep 2025 11:14:51 +0300 -Subject: [PATCH] libkrb5: in case PKINIT is configured, attempt Anonymous +Subject: [PATCH 1/2] libkrb5: in case PKINIT is configured, attempt Anonymous PKINIT for FAST If auto_fast_armor is configured for the realm or globally, optimistically @@ -24,7 +24,7 @@ Signed-off-by: Alexander Bokovoy 3 files changed, 133 insertions(+) diff --git a/src/lib/krb5/krb/fast.c b/src/lib/krb5/krb/fast.c -index 62c9f0841f6..ee2e0818929 100644 +index 62c9f0841..ee2e08189 100644 --- a/src/lib/krb5/krb/fast.c +++ b/src/lib/krb5/krb/fast.c @@ -168,6 +168,109 @@ krb5int_fast_prep_req_body(krb5_context context, @@ -178,7 +178,7 @@ index 62c9f0841f6..ee2e0818929 100644 } diff --git a/src/lib/krb5/krb/fast.h b/src/lib/krb5/krb/fast.h -index 7156ea203f1..e5fe8bd5443 100644 +index 7156ea203..e5fe8bd54 100644 --- a/src/lib/krb5/krb/fast.h +++ b/src/lib/krb5/krb/fast.h @@ -34,6 +34,7 @@ struct krb5int_fast_request_state { @@ -198,7 +198,7 @@ index 7156ea203f1..e5fe8bd5443 100644 krb5_error_code krb5int_fast_prep_req_body(krb5_context context, diff --git a/src/man/krb5.conf.man b/src/man/krb5.conf.man -index 6c0e9aff8c4..fc6ebec03a9 100644 +index d4caa2bd3..ac7649647 100644 --- a/src/man/krb5.conf.man +++ b/src/man/krb5.conf.man @@ -650,6 +650,19 @@ primary KDC, in case the user\(aqs password has just been changed, and @@ -208,7 +208,7 @@ index 6c0e9aff8c4..fc6ebec03a9 100644 +\fBauto_fast_armor\fP +If this flag is true, then initial ticket request will use Anonymous +PKINIT to protect the communication as a FAST channel in case an application -+did not provide its own FAST channel.This is useful for deployments where ++did not provide its own FAST channel. This is useful for deployments where +pre-authentication methods require use of the FAST channel, such as +passwordless methods provided by FreeIPA. Microsoft Active Directory +implementation of PKINIT does not support Anonymous PKINIT feature. @@ -221,3 +221,55 @@ index 6c0e9aff8c4..fc6ebec03a9 100644 \fBv4_instance_convert\fP This subsection allows the administrator to configure exceptions to the \fBdefault_domain\fP mapping rule. It contains V4 instances +-- +2.51.0 + + +From 0d23c5ddf61e8c4620e4af542079bbacf051fa12 Mon Sep 17 00:00:00 2001 +From: Alexander Bokovoy +Date: Wed, 15 Oct 2025 08:31:38 +0300 +Subject: [PATCH 2/2] otp: bail if prompter is not specified but required + +GSSAPI gss_init_sec_context() may trigger credential re-initialization +if the cred in ccache is expired. If automatic FAST armor is in use, +we'd request Anonymous PKINIT and use it as an armor and this will +enable seeing pre-authentication methods which require armor presence. + +OTP is one of such methods and its use requires prompter to be set, +but GSSAPI cannot specify a prompter and thus we should fail any +pre-auth where a prompter wasn't passed. + +Signed-off-by: Alexander Bokovoy +--- + src/lib/krb5/krb/preauth_otp.c | 8 +++++++- + 1 file changed, 7 insertions(+), 1 deletion(-) + +diff --git a/src/lib/krb5/krb/preauth_otp.c b/src/lib/krb5/krb/preauth_otp.c +index 07ffc15c2..070b1f74a 100644 +--- a/src/lib/krb5/krb/preauth_otp.c ++++ b/src/lib/krb5/krb/preauth_otp.c +@@ -1072,7 +1072,7 @@ otp_client_process(krb5_context context, krb5_clpreauth_moddata moddata, + krb5_keyblock *as_key = NULL; + krb5_pa_otp_req *req = NULL; + krb5_error_code retval = 0; +- krb5_data value, pin; ++ krb5_data value = {0}, pin = {0}; + const char *answer; + + if (modreq == NULL) +@@ -1094,6 +1094,12 @@ otp_client_process(krb5_context context, krb5_clpreauth_moddata moddata, + retval = codec_decode_answer(context, answer, chl->tokeninfo, &ti, &value, + &pin); + if (retval != 0) { ++ /* If caller didn't setup the prompter, bail out */ ++ if (prompter == NULL) { ++ retval = EINVAL; ++ goto error; ++ } ++ + /* If the responder doesn't have a token selection, + * we need to select the token via prompting. */ + retval = prompt_for_token(context, prompter, prompter_data, +-- +2.51.0 + diff --git a/krb5.spec b/krb5.spec index bfdfbe4..642f8f0 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 8 +%global baserelease 9 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -743,6 +743,10 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Wed Oct 15 2025 Alexander Bokovoy - 1.21.3-9 +- do not crash when prompter is not available in GSSAPI + Resolves: rhbz#243513 + * Fri Sep 26 2025 Alexander Bokovoy - 1.21.3-8 - Add automated FAST channel for kinit - https://github.com/krb5/krb5/pull/1447 - work in progress From fe6911cd3d84b4d3078af1454a3fcec506d8c074 Mon Sep 17 00:00:00 2001 From: Alexander Bokovoy Date: Mon, 20 Oct 2025 10:32:09 +0300 Subject: [PATCH 303/304] Update prompter patch to the upstream version Move the prompter patch to a separate one to avoid rebasing the automated FAST one as it is context-dependent in the documentation area. Signed-off-by: Alexander Bokovoy --- 0040-automated-fast.patch | 51 +------------------ ...ompter-is-not-specified-but-required.patch | 40 +++++++++++++++ krb5.spec | 9 +++- 3 files changed, 48 insertions(+), 52 deletions(-) create mode 100644 0041-bail-if-prompter-is-not-specified-but-required.patch diff --git a/0040-automated-fast.patch b/0040-automated-fast.patch index e9665d5..5a64233 100644 --- a/0040-automated-fast.patch +++ b/0040-automated-fast.patch @@ -1,7 +1,7 @@ From 3baf9b93dc1dfe38585722c71d7268304cb4a01a Mon Sep 17 00:00:00 2001 From: Alexander Bokovoy Date: Sun, 21 Sep 2025 11:14:51 +0300 -Subject: [PATCH 1/2] libkrb5: in case PKINIT is configured, attempt Anonymous +Subject: libkrb5: in case PKINIT is configured, attempt Anonymous PKINIT for FAST If auto_fast_armor is configured for the realm or globally, optimistically @@ -224,52 +224,3 @@ index d4caa2bd3..ac7649647 100644 -- 2.51.0 - -From 0d23c5ddf61e8c4620e4af542079bbacf051fa12 Mon Sep 17 00:00:00 2001 -From: Alexander Bokovoy -Date: Wed, 15 Oct 2025 08:31:38 +0300 -Subject: [PATCH 2/2] otp: bail if prompter is not specified but required - -GSSAPI gss_init_sec_context() may trigger credential re-initialization -if the cred in ccache is expired. If automatic FAST armor is in use, -we'd request Anonymous PKINIT and use it as an armor and this will -enable seeing pre-authentication methods which require armor presence. - -OTP is one of such methods and its use requires prompter to be set, -but GSSAPI cannot specify a prompter and thus we should fail any -pre-auth where a prompter wasn't passed. - -Signed-off-by: Alexander Bokovoy ---- - src/lib/krb5/krb/preauth_otp.c | 8 +++++++- - 1 file changed, 7 insertions(+), 1 deletion(-) - -diff --git a/src/lib/krb5/krb/preauth_otp.c b/src/lib/krb5/krb/preauth_otp.c -index 07ffc15c2..070b1f74a 100644 ---- a/src/lib/krb5/krb/preauth_otp.c -+++ b/src/lib/krb5/krb/preauth_otp.c -@@ -1072,7 +1072,7 @@ otp_client_process(krb5_context context, krb5_clpreauth_moddata moddata, - krb5_keyblock *as_key = NULL; - krb5_pa_otp_req *req = NULL; - krb5_error_code retval = 0; -- krb5_data value, pin; -+ krb5_data value = {0}, pin = {0}; - const char *answer; - - if (modreq == NULL) -@@ -1094,6 +1094,12 @@ otp_client_process(krb5_context context, krb5_clpreauth_moddata moddata, - retval = codec_decode_answer(context, answer, chl->tokeninfo, &ti, &value, - &pin); - if (retval != 0) { -+ /* If caller didn't setup the prompter, bail out */ -+ if (prompter == NULL) { -+ retval = EINVAL; -+ goto error; -+ } -+ - /* If the responder doesn't have a token selection, - * we need to select the token via prompting. */ - retval = prompt_for_token(context, prompter, prompter_data, --- -2.51.0 - diff --git a/0041-bail-if-prompter-is-not-specified-but-required.patch b/0041-bail-if-prompter-is-not-specified-but-required.patch new file mode 100644 index 0000000..d1a3dc7 --- /dev/null +++ b/0041-bail-if-prompter-is-not-specified-but-required.patch @@ -0,0 +1,40 @@ +From ff580d9cf86202d45454a6b6f53accc22cb40b62 Mon Sep 17 00:00:00 2001 +From: Alexander Bokovoy +Date: Sun, 19 Oct 2025 18:14:29 +0300 +Subject: [PATCH] bail if prompter is not specified but required + +GSSAPI gss_init_sec_context() may trigger credential re-initialization +if the cred in ccache is expired. If automatic FAST armor is in use, +we'd request Anonymous PKINIT and use it as an armor and this will +enable seeing pre-authentication methods which require armor presence. + +OTP is one of such methods and its use requires prompter to be set, +but GSSAPI cannot specify a prompter and thus we should fail any +pre-auth where a prompter wasn't passed. + +PKINIT PKCS11 and SAM-2 preauth methods use KRB5_LIBOS_CANTREADPWD while PKINIT +and gic_pwd.c use EIO. Use EIO here because we technically attempt to read a +PIN rather than a password. + +Signed-off-by: Alexander Bokovoy +--- + src/lib/krb5/krb/preauth_otp.c | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/src/lib/krb5/krb/preauth_otp.c b/src/lib/krb5/krb/preauth_otp.c +index 07ffc15c2..48003da62 100644 +--- a/src/lib/krb5/krb/preauth_otp.c ++++ b/src/lib/krb5/krb/preauth_otp.c +@@ -479,6 +479,9 @@ doprompt(krb5_context context, krb5_prompter_fct prompter, void *prompter_data, + krb5_error_code retval; + krb5_prompt_type prompt_type = KRB5_PROMPT_TYPE_PREAUTH; + ++ if (prompter == NULL) ++ return EIO; ++ + if (prompttxt == NULL || out == NULL) + return EINVAL; + +-- +2.51.0 + diff --git a/krb5.spec b/krb5.spec index 642f8f0..2a08b01 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 9 +%global baserelease 10 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -98,6 +98,7 @@ Patch0036: 0036-downstream-Remove-3des-support-cumulative-1.patch Patch0037: 0037-Add-PKINIT-paChecksum2-from-MS-PKCA-v20230920.patch Patch0038: 0038-downstream-Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch Patch0040: 0040-automated-fast.patch +Patch0041: 0041-bail-if-prompter-is-not-specified-but-required.patch License: Brian-Gladman-2-Clause AND BSD-2-Clause AND (BSD-2-Clause OR GPL-2.0-or-later) AND BSD-2-Clause-first-lines AND BSD-3-Clause AND BSD-4-Clause AND CMU-Mach-nodoc AND FSFULLRWD AND HPND AND HPND-export2-US AND HPND-export-US AND HPND-export-US-acknowledgement AND HPND-export-US-modify AND ISC AND MIT AND MIT-CMU AND OLDAP-2.8 AND OpenVision URL: https://web.mit.edu/kerberos/www/ @@ -743,9 +744,13 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Mon Oct 20 2025 Alexander Bokovoy - 1.21.3-10 +- Update the prompter patch to upstream version + Resolves: rhbz#2403513 + * Wed Oct 15 2025 Alexander Bokovoy - 1.21.3-9 - do not crash when prompter is not available in GSSAPI - Resolves: rhbz#243513 + Resolves: rhbz#2403513 * Fri Sep 26 2025 Alexander Bokovoy - 1.21.3-8 - Add automated FAST channel for kinit From c2ce5811ff90bf800aa4db73e08d3c4759c3007a Mon Sep 17 00:00:00 2001 From: Julien Rische Date: Wed, 10 Dec 2025 13:12:53 +0100 Subject: [PATCH 304/304] krb5 1.21.3-11 - Fix strchr() conformance to C23 --- 0039-Fix-strchr-conformance-to-C23.patch | 189 +++++++++++++++++++++++ krb5.spec | 7 +- 2 files changed, 194 insertions(+), 2 deletions(-) create mode 100644 0039-Fix-strchr-conformance-to-C23.patch diff --git a/0039-Fix-strchr-conformance-to-C23.patch b/0039-Fix-strchr-conformance-to-C23.patch new file mode 100644 index 0000000..ed2cfa7 --- /dev/null +++ b/0039-Fix-strchr-conformance-to-C23.patch @@ -0,0 +1,189 @@ +From 1761e06398e4f043e4f540f57131c37fcc53a1b9 Mon Sep 17 00:00:00 2001 +From: Alexander Bokovoy +Date: Wed, 10 Dec 2025 10:42:02 +0200 +Subject: [PATCH] Fix strchr() conformance to C23 + +C23 7.28.5.1 specifies search functions such as strchr() as generic, +returning const char * if the first argument is of type const char *. +Fix uses of strchr() to conform to this change. + +[jrische@redhat.com: altered changes to avoid casts; fixed an +additional case] +[ghudson@mit.edu: condensed some declarations; rewrote commit message] + +ticket: 9191 (new) +(cherry picked from commit 6cd8580d823585d50ee4f30efd9f7e855823a369) +--- + src/lib/krb5/ccache/ccbase.c | 4 ++-- + src/lib/krb5/os/expand_path.c | 3 ++- + src/lib/krb5/os/locate_kdc.c | 15 +++++++-------- + src/plugins/preauth/pkinit/pkinit_crypto.h | 2 +- + .../preauth/pkinit/pkinit_crypto_openssl.c | 6 +++--- + src/plugins/preauth/pkinit/pkinit_identity.c | 2 +- + src/plugins/preauth/pkinit/pkinit_matching.c | 2 +- + src/tests/responder.c | 3 +-- + 8 files changed, 18 insertions(+), 19 deletions(-) + +diff --git a/src/lib/krb5/ccache/ccbase.c b/src/lib/krb5/ccache/ccbase.c +index 5a01320832..1aada91b5e 100644 +--- a/src/lib/krb5/ccache/ccbase.c ++++ b/src/lib/krb5/ccache/ccbase.c +@@ -201,8 +201,8 @@ krb5_cc_register(krb5_context context, const krb5_cc_ops *ops, + krb5_error_code KRB5_CALLCONV + krb5_cc_resolve (krb5_context context, const char *name, krb5_ccache *cache) + { +- char *pfx, *cp; +- const char *resid; ++ char *pfx; ++ const char *cp, *resid; + unsigned int pfxlen; + krb5_error_code err; + const krb5_cc_ops *ops; +diff --git a/src/lib/krb5/os/expand_path.c b/src/lib/krb5/os/expand_path.c +index 5cbccf08c8..6569b8820b 100644 +--- a/src/lib/krb5/os/expand_path.c ++++ b/src/lib/krb5/os/expand_path.c +@@ -454,7 +454,8 @@ k5_expand_path_tokens_extra(krb5_context context, const char *path_in, + { + krb5_error_code ret; + struct k5buf buf; +- char *tok_begin, *tok_end, *tok_val, **extra_tokens = NULL, *path; ++ const char *tok_begin, *tok_end; ++ char *tok_val, **extra_tokens = NULL, *path; + const char *path_left; + size_t nargs = 0, i; + va_list ap; +diff --git a/src/lib/krb5/os/locate_kdc.c b/src/lib/krb5/os/locate_kdc.c +index edca5ac7eb..47e15c849f 100644 +--- a/src/lib/krb5/os/locate_kdc.c ++++ b/src/lib/krb5/os/locate_kdc.c +@@ -188,8 +188,8 @@ oom: + } + + static void +-parse_uri_if_https(const char *host_or_uri, k5_transport *transport, +- const char **host, const char **uri_path) ++parse_uri_if_https(char *host_or_uri, k5_transport *transport, ++ char **host, const char **uri_path) + { + char *cp; + +@@ -229,8 +229,7 @@ locate_srv_conf_1(krb5_context context, const krb5_data *realm, + k5_transport transport, int udpport) + { + const char *realm_srv_names[4]; +- char **hostlist = NULL, *realmstr = NULL, *host = NULL; +- const char *hostspec; ++ char **hostlist = NULL, *realmstr = NULL, *host = NULL, *hostspec; + krb5_error_code code; + int i, default_port; + +@@ -535,8 +534,8 @@ prof_locate_server(krb5_context context, const krb5_data *realm, + * Return a NULL *host_out if there are any problems parsing the URI. + */ + static void +-parse_uri_fields(const char *uri, k5_transport *transport_out, +- const char **host_out, int *primary_out) ++parse_uri_fields(char *uri, k5_transport *transport_out, ++ char **host_out, int *primary_out) + + { + k5_transport transport; +@@ -604,8 +603,8 @@ locate_uri(krb5_context context, const krb5_data *realm, + krb5_error_code ret; + k5_transport transport, host_trans; + struct srv_dns_entry *answers, *entry; +- char *host; +- const char *host_field, *path; ++ char *host, *host_field; ++ const char *path; + int port, def_port, primary; + + ret = k5_make_uri_query(context, realm, req_service, &answers); +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto.h b/src/plugins/preauth/pkinit/pkinit_crypto.h +index 3b12e904b1..99e2394040 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto.h ++++ b/src/plugins/preauth/pkinit/pkinit_crypto.h +@@ -456,7 +456,7 @@ krb5_error_code crypto_load_cas_and_crls + defines the storage type (file, directory, etc) */ + int catype, /* IN + defines the ca type (anchor, intermediate, crls) */ +- char *id); /* IN ++ const char *id); /* IN + defines the location (filename, directory name, etc) */ + + /* +diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +index 429b7d202c..6013080afc 100644 +--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c ++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c +@@ -4956,7 +4956,7 @@ load_cas_and_crls(krb5_context context, + pkinit_req_crypto_context req_cryptoctx, + pkinit_identity_crypto_context id_cryptoctx, + int catype, +- char *filename) ++ const char *filename) + { + STACK_OF(X509_INFO) *sk = NULL; + STACK_OF(X509) *ca_certs = NULL; +@@ -5114,7 +5114,7 @@ load_cas_and_crls_dir(krb5_context context, + pkinit_req_crypto_context req_cryptoctx, + pkinit_identity_crypto_context id_cryptoctx, + int catype, +- char *dirname) ++ const char *dirname) + { + krb5_error_code retval = EINVAL; + DIR *d = NULL; +@@ -5166,7 +5166,7 @@ crypto_load_cas_and_crls(krb5_context context, + pkinit_identity_crypto_context id_cryptoctx, + int idtype, + int catype, +- char *id) ++ const char *id) + { + switch (idtype) { + case IDTYPE_FILE: +diff --git a/src/plugins/preauth/pkinit/pkinit_identity.c b/src/plugins/preauth/pkinit/pkinit_identity.c +index a5a979f279..b06d519c66 100644 +--- a/src/plugins/preauth/pkinit/pkinit_identity.c ++++ b/src/plugins/preauth/pkinit/pkinit_identity.c +@@ -474,7 +474,7 @@ process_option_ca_crl(krb5_context context, + const char *value, + int catype) + { +- char *residual; ++ const char *residual; + unsigned int typelen; + int idtype; + +diff --git a/src/plugins/preauth/pkinit/pkinit_matching.c b/src/plugins/preauth/pkinit/pkinit_matching.c +index b42485a50a..5a7f2ba3fa 100644 +--- a/src/plugins/preauth/pkinit/pkinit_matching.c ++++ b/src/plugins/preauth/pkinit/pkinit_matching.c +@@ -263,7 +263,7 @@ parse_rule_component(krb5_context context, + char err_buf[128]; + int ret; + struct keyword_desc *kw, *nextkw; +- char *nk; ++ const char *nk; + int found_next_kw = 0; + char *value = NULL; + size_t len; +diff --git a/src/tests/responder.c b/src/tests/responder.c +index 82f870ea5d..4221a20283 100644 +--- a/src/tests/responder.c ++++ b/src/tests/responder.c +@@ -282,8 +282,7 @@ responder(krb5_context ctx, void *rawdata, krb5_responder_context rctx) + /* Provide a particular response for an OTP challenge. */ + if (data->otp_answer != NULL) { + if (krb5_responder_otp_get_challenge(ctx, rctx, &ochl) == 0) { +- key = strchr(data->otp_answer, '='); +- if (key != NULL) { ++ if (strchr(data->otp_answer, '=') != NULL) { + /* Make a copy of the answer that we can chop up. */ + key = strdup(data->otp_answer); + if (key == NULL) +-- +2.51.1 + diff --git a/krb5.spec b/krb5.spec index 2a08b01..4c5b542 100644 --- a/krb5.spec +++ b/krb5.spec @@ -10,7 +10,7 @@ # # baserelease is what we have standardized across Fedora and what # rpmdev-bumpspec knows how to handle. -%global baserelease 10 +%global baserelease 11 # This should be e.g. beta1 or %%nil %global pre_release %nil @@ -97,6 +97,7 @@ Patch0035: 0035-Don-t-issue-session-keys-with-deprecated-enctypes.patch Patch0036: 0036-downstream-Remove-3des-support-cumulative-1.patch Patch0037: 0037-Add-PKINIT-paChecksum2-from-MS-PKCA-v20230920.patch Patch0038: 0038-downstream-Do-not-block-HMAC-MD4-5-in-FIPS-mode.patch +Patch0039: 0039-Fix-strchr-conformance-to-C23.patch Patch0040: 0040-automated-fast.patch Patch0041: 0041-bail-if-prompter-is-not-specified-but-required.patch @@ -744,6 +745,9 @@ exit 0 %{_datarootdir}/%{name}-tests/%{_arch} %changelog +* Mon Jan 05 2026 Julien Rische - 1.21.3-11 +- Fix strchr() conformance to C23 + * Mon Oct 20 2025 Alexander Bokovoy - 1.21.3-10 - Update the prompter patch to upstream version Resolves: rhbz#2403513 @@ -756,7 +760,6 @@ exit 0 - Add automated FAST channel for kinit - https://github.com/krb5/krb5/pull/1447 - work in progress - * Thu Jul 24 2025 Fedora Release Engineering - 1.21.3-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild